From f988a8da9ab8433ddb9c1dcfff5b67bf8bf975cf Mon Sep 17 00:00:00 2001 From: Hosted Weblate Date: Mon, 5 Oct 2026 21:20:46 +0000 Subject: [PATCH] po: update translations MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit (Russian) currently translated at 100.0% (2889 of 2889 strings) Translation: SSSD/sssd-manpage Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/ru/ po: update translations (Portuguese) currently translated at 95.5% (2760 of 2889 strings) Translation: SSSD/sssd-manpage Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/pt/ po: update translations (Russian) currently translated at 100.0% (745 of 745 strings) Translation: SSSD/sssd Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/ru/ po: update translations (Portuguese) currently translated at 100.0% (745 of 745 strings) Translation: SSSD/sssd Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/pt/ po: update translations (Portuguese) currently translated at 100.0% (745 of 745 strings) Translation: SSSD/sssd Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/pt/ po: update translations (Portuguese) currently translated at 100.0% (745 of 745 strings) Translation: SSSD/sssd Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/pt/ Update translation files Updated by "Update PO files to match POT (msgmerge)" hook in Weblate. Translation: SSSD/sssd Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/ po: update translations (Romanian) currently translated at 0.2% (6 of 2838 strings) Translation: SSSD/sssd-manpage Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/ro/ po: update translations (Romanian) currently translated at 0.2% (6 of 2838 strings) Translation: SSSD/sssd-manpage Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/ro/ po: update translations (Romanian) currently translated at 0.0% (0 of 735 strings) Translation: SSSD/sssd Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/ro/ po: update translations (Turkish) currently translated at 0.0% (0 of 2838 strings) Translation: SSSD/sssd-manpage Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/tr/ po: update translations (Norwegian Bokmål) currently translated at 0.0% (0 of 2838 strings) Translation: SSSD/sssd-manpage Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/nb/ po: update translations (Italian) currently translated at 100.0% (2838 of 2838 strings) Translation: SSSD/sssd-manpage Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/it/ po: update translations (Italian) currently translated at 100.0% (2838 of 2838 strings) Translation: SSSD/sssd-manpage Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/it/ po: update translations (Indonesian) currently translated at 0.0% (0 of 2838 strings) Translation: SSSD/sssd-manpage Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/id/ po: update translations (Hungarian) currently translated at 0.0% (0 of 2838 strings) Translation: SSSD/sssd-manpage Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/hu/ po: update translations (Bulgarian) currently translated at 0.0% (0 of 2838 strings) Translation: SSSD/sssd-manpage Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/bg/ po: update translations (Latvian) currently translated at 0.0% (0 of 735 strings) Translation: SSSD/sssd Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/lv/ po: update translations (Breton) currently translated at 0.0% (0 of 735 strings) Translation: SSSD/sssd Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/br/ po: update translations (Georgian) currently translated at 37.5% (1061 of 2824 strings) Translation: SSSD/sssd-manpage Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/ka/ po: update translations (Georgian) currently translated at 37.5% (1061 of 2824 strings) Translation: SSSD/sssd-manpage Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/ka/ po: update translations (Georgian) currently translated at 37.5% (1061 of 2824 strings) Translation: SSSD/sssd-manpage Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/ka/ po: update translations (Chinese (Traditional) (zh_TW)) currently translated at 100.0% (2799 of 2799 strings) Translation: SSSD/sssd-manpage Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/zh_TW/ po: update translations (Chinese (Traditional) (zh_TW)) currently translated at 100.0% (2799 of 2799 strings) Translation: SSSD/sssd-manpage Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/zh_TW/ po: update translations (Polish) currently translated at 4.9% (133 of 2662 strings) Translation: SSSD/sssd-manpage Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/pl/ po: update translations (Polish) currently translated at 4.9% (133 of 2662 strings) Translation: SSSD/sssd-manpage Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/pl/ po: update translations (Polish) currently translated at 4.9% (133 of 2662 strings) Translation: SSSD/sssd-manpage Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/pl/ po: update translations (Polish) currently translated at 4.9% (133 of 2662 strings) Translation: SSSD/sssd-manpage Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/pl/ po: update translations (Georgian) currently translated at 15.5% (114 of 735 strings) Translation: SSSD/sssd Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/ka/ po: update translations (Georgian) currently translated at 15.5% (114 of 735 strings) Translation: SSSD/sssd Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/ka/ po: update translations (Georgian) currently translated at 15.5% (114 of 735 strings) Translation: SSSD/sssd Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/ka/ po: update translations (Korean) currently translated at 66.9% (1890 of 2821 strings) Translation: SSSD/sssd-manpage Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/ko/ po: update translations (Korean) currently translated at 66.9% (1890 of 2821 strings) Translation: SSSD/sssd-manpage Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/ko/ po: update translations (Korean) currently translated at 66.9% (1890 of 2821 strings) Translation: SSSD/sssd-manpage Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/ko/ po: update translations (Korean) currently translated at 66.9% (1890 of 2821 strings) Translation: SSSD/sssd-manpage Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/ko/ po: update translations (Korean) currently translated at 66.9% (1890 of 2821 strings) Translation: SSSD/sssd-manpage Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/ko/ po: update translations (Korean) currently translated at 66.9% (1890 of 2821 strings) Translation: SSSD/sssd-manpage Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/ko/ po: update translations (Korean) currently translated at 100.0% (735 of 735 strings) Translation: SSSD/sssd Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/ko/ po: update translations (Korean) currently translated at 100.0% (735 of 735 strings) Translation: SSSD/sssd Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/ko/ po: update translations (Korean) currently translated at 100.0% (735 of 735 strings) Translation: SSSD/sssd Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/ko/ po: update translations (Korean) currently translated at 100.0% (735 of 735 strings) Translation: SSSD/sssd Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/ko/ po: update translations (Korean) currently translated at 100.0% (735 of 735 strings) Translation: SSSD/sssd Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/ko/ po: update translations (Finnish) currently translated at 10.4% (77 of 735 strings) Translation: SSSD/sssd Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/fi/ po: update translations (Finnish) currently translated at 10.4% (77 of 735 strings) Translation: SSSD/sssd Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/fi/ po: update translations (Finnish) currently translated at 10.4% (77 of 735 strings) Translation: SSSD/sssd Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/fi/ po: update translations (Finnish) currently translated at 10.4% (77 of 735 strings) Translation: SSSD/sssd Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/fi/ po: update translations (Finnish) currently translated at 10.4% (77 of 735 strings) Translation: SSSD/sssd Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/fi/ po: update translations (Chinese (Simplified) (zh_CN)) currently translated at 0.4% (12 of 2838 strings) Translation: SSSD/sssd-manpage Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/zh_CN/ po: update translations (Ukrainian) currently translated at 98.3% (2792 of 2838 strings) Translation: SSSD/sssd-manpage Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/uk/ po: update translations (Ukrainian) currently translated at 98.3% (2792 of 2838 strings) Translation: SSSD/sssd-manpage Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/uk/ po: update translations (Tajik) currently translated at 1.2% (36 of 2838 strings) Translation: SSSD/sssd-manpage Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/tg/ po: update translations (Swedish) currently translated at 100.0% (2838 of 2838 strings) Translation: SSSD/sssd-manpage Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/sv/ po: update translations (Swedish) currently translated at 100.0% (2838 of 2838 strings) Translation: SSSD/sssd-manpage Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/sv/ po: update translations (Swedish) currently translated at 100.0% (2838 of 2838 strings) Translation: SSSD/sssd-manpage Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/sv/ po: update translations (Swedish) currently translated at 100.0% (2838 of 2838 strings) Translation: SSSD/sssd-manpage Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/sv/ po: update translations (Swedish) currently translated at 100.0% (2838 of 2838 strings) Translation: SSSD/sssd-manpage Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/sv/ po: update translations (Russian) currently translated at 100.0% (2838 of 2838 strings) Translation: SSSD/sssd-manpage Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/ru/ po: update translations (Russian) currently translated at 100.0% (2838 of 2838 strings) Translation: SSSD/sssd-manpage Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/ru/ po: update translations (Russian) currently translated at 100.0% (2838 of 2838 strings) Translation: SSSD/sssd-manpage Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/ru/ po: update translations (Russian) currently translated at 100.0% (2838 of 2838 strings) Translation: SSSD/sssd-manpage Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/ru/ po: update translations (Russian) currently translated at 100.0% (2838 of 2838 strings) Translation: SSSD/sssd-manpage Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/ru/ po: update translations (Portuguese (Brazil)) currently translated at 0.8% (25 of 2838 strings) Translation: SSSD/sssd-manpage Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/pt_BR/ po: update translations (Portuguese (Brazil)) currently translated at 0.8% (25 of 2838 strings) Translation: SSSD/sssd-manpage Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/pt_BR/ po: update translations (Portuguese (Brazil)) currently translated at 0.8% (25 of 2838 strings) Translation: SSSD/sssd-manpage Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/pt_BR/ po: update translations (Portuguese) currently translated at 100.0% (2838 of 2838 strings) Translation: SSSD/sssd-manpage Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/pt/ po: update translations (Portuguese) currently translated at 100.0% (2838 of 2838 strings) Translation: SSSD/sssd-manpage Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/pt/ po: update translations (Dutch) currently translated at 1.4% (41 of 2838 strings) Translation: SSSD/sssd-manpage Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/nl/ po: update translations (Latvian) currently translated at 1.6% (48 of 2838 strings) Translation: SSSD/sssd-manpage Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/lv/ po: update translations (Japanese) currently translated at 31.2% (888 of 2838 strings) Translation: SSSD/sssd-manpage Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/ja/ po: update translations (Japanese) currently translated at 31.2% (888 of 2838 strings) Translation: SSSD/sssd-manpage Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/ja/ po: update translations (French) currently translated at 55.9% (1589 of 2838 strings) Translation: SSSD/sssd-manpage Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/fr/ po: update translations (French) currently translated at 55.9% (1589 of 2838 strings) Translation: SSSD/sssd-manpage Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/fr/ po: update translations (French) currently translated at 55.9% (1589 of 2838 strings) Translation: SSSD/sssd-manpage Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/fr/ po: update translations (Finnish) currently translated at 3.4% (98 of 2838 strings) Translation: SSSD/sssd-manpage Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/fi/ po: update translations (Finnish) currently translated at 3.4% (98 of 2838 strings) Translation: SSSD/sssd-manpage Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/fi/ po: update translations (Finnish) currently translated at 3.4% (98 of 2838 strings) Translation: SSSD/sssd-manpage Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/fi/ po: update translations (Basque) currently translated at 0.0% (0 of 2838 strings) Translation: SSSD/sssd-manpage Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/eu/ po: update translations (Spanish) currently translated at 100.0% (2838 of 2838 strings) Translation: SSSD/sssd-manpage Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/es/ po: update translations (Spanish) currently translated at 100.0% (2838 of 2838 strings) Translation: SSSD/sssd-manpage Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/es/ po: update translations (Spanish) currently translated at 100.0% (2838 of 2838 strings) Translation: SSSD/sssd-manpage Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/es/ po: update translations (Spanish) currently translated at 100.0% (2838 of 2838 strings) Translation: SSSD/sssd-manpage Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/es/ po: update translations (Chinese (Traditional) (zh_TW)) currently translated at 100.0% (735 of 735 strings) Translation: SSSD/sssd Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/zh_TW/ po: update translations (Chinese (Traditional) (zh_TW)) currently translated at 100.0% (735 of 735 strings) Translation: SSSD/sssd Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/zh_TW/ po: update translations (Chinese (Traditional) (zh_TW)) currently translated at 100.0% (735 of 735 strings) Translation: SSSD/sssd Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/zh_TW/ po: update translations (Chinese (Simplified) (zh_CN)) currently translated at 92.1% (677 of 735 strings) Translation: SSSD/sssd Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/zh_CN/ po: update translations (Chinese (Simplified) (zh_CN)) currently translated at 92.1% (677 of 735 strings) Translation: SSSD/sssd Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/zh_CN/ po: update translations (Chinese (Simplified) (zh_CN)) currently translated at 92.1% (677 of 735 strings) Translation: SSSD/sssd Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/zh_CN/ po: update translations (Chinese (Simplified) (zh_CN)) currently translated at 92.1% (677 of 735 strings) Translation: SSSD/sssd Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/zh_CN/ po: update translations (Chinese (Simplified) (zh_CN)) currently translated at 92.1% (677 of 735 strings) Translation: SSSD/sssd Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/zh_CN/ po: update translations (Ukrainian) currently translated at 99.7% (733 of 735 strings) Translation: SSSD/sssd Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/uk/ po: update translations (Ukrainian) currently translated at 99.7% (733 of 735 strings) Translation: SSSD/sssd Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/uk/ po: update translations (Ukrainian) currently translated at 99.7% (733 of 735 strings) Translation: SSSD/sssd Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/uk/ po: update translations (German) currently translated at 40.3% (1144 of 2838 strings) Translation: SSSD/sssd-manpage Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/de/ po: update translations (German) currently translated at 40.3% (1144 of 2838 strings) Translation: SSSD/sssd-manpage Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/de/ po: update translations (Turkish) currently translated at 100.0% (735 of 735 strings) Translation: SSSD/sssd Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/tr/ po: update translations (Turkish) currently translated at 100.0% (735 of 735 strings) Translation: SSSD/sssd Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/tr/ po: update translations (Turkish) currently translated at 100.0% (735 of 735 strings) Translation: SSSD/sssd Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/tr/ po: update translations (Tajik) currently translated at 0.9% (7 of 735 strings) Translation: SSSD/sssd Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/tg/ po: update translations (Swedish) currently translated at 100.0% (735 of 735 strings) Translation: SSSD/sssd Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/sv/ po: update translations (Swedish) currently translated at 100.0% (735 of 735 strings) Translation: SSSD/sssd Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/sv/ po: update translations (Swedish) currently translated at 100.0% (735 of 735 strings) Translation: SSSD/sssd Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/sv/ po: update translations (Swedish) currently translated at 100.0% (735 of 735 strings) Translation: SSSD/sssd Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/sv/ po: update translations (Swedish) currently translated at 100.0% (735 of 735 strings) Translation: SSSD/sssd Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/sv/ po: update translations (Czech) currently translated at 8.8% (250 of 2838 strings) Translation: SSSD/sssd-manpage Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/cs/ po: update translations (Czech) currently translated at 8.8% (250 of 2838 strings) Translation: SSSD/sssd-manpage Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/cs/ po: update translations (Czech) currently translated at 8.8% (250 of 2838 strings) Translation: SSSD/sssd-manpage Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/cs/ po: update translations (Czech) currently translated at 8.8% (250 of 2838 strings) Translation: SSSD/sssd-manpage Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/cs/ po: update translations (Russian) currently translated at 100.0% (735 of 735 strings) Translation: SSSD/sssd Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/ru/ po: update translations (Russian) currently translated at 100.0% (735 of 735 strings) Translation: SSSD/sssd Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/ru/ po: update translations (Russian) currently translated at 100.0% (735 of 735 strings) Translation: SSSD/sssd Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/ru/ po: update translations (Russian) currently translated at 100.0% (735 of 735 strings) Translation: SSSD/sssd Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/ru/ po: update translations (Catalan) currently translated at 30.6% (871 of 2838 strings) Translation: SSSD/sssd-manpage Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/ca/ po: update translations (Portuguese (Brazil)) currently translated at 32.7% (241 of 735 strings) Translation: SSSD/sssd Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/pt_BR/ po: update translations (Portuguese (Brazil)) currently translated at 32.7% (241 of 735 strings) Translation: SSSD/sssd Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/pt_BR/ po: update translations (Portuguese (Brazil)) currently translated at 32.7% (241 of 735 strings) Translation: SSSD/sssd Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/pt_BR/ po: update translations (Portuguese (Brazil)) currently translated at 32.7% (241 of 735 strings) Translation: SSSD/sssd Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/pt_BR/ po: update translations (Portuguese) currently translated at 100.0% (735 of 735 strings) Translation: SSSD/sssd Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/pt/ po: update translations (Portuguese) currently translated at 100.0% (735 of 735 strings) Translation: SSSD/sssd Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/pt/ po: update translations (Portuguese) currently translated at 100.0% (735 of 735 strings) Translation: SSSD/sssd Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/pt/ po: update translations (Polish) currently translated at 100.0% (735 of 735 strings) Translation: SSSD/sssd Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/pl/ po: update translations (Polish) currently translated at 100.0% (735 of 735 strings) Translation: SSSD/sssd Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/pl/ po: update translations (Dutch) currently translated at 38.9% (286 of 735 strings) Translation: SSSD/sssd Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/nl/ po: update translations (Norwegian Bokmål) currently translated at 1.9% (14 of 735 strings) Translation: SSSD/sssd Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/nb/ po: update translations (Japanese) currently translated at 92.1% (677 of 735 strings) Translation: SSSD/sssd Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/ja/ po: update translations (Japanese) currently translated at 92.1% (677 of 735 strings) Translation: SSSD/sssd Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/ja/ po: update translations (Japanese) currently translated at 92.1% (677 of 735 strings) Translation: SSSD/sssd Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/ja/ po: update translations (Italian) currently translated at 100.0% (735 of 735 strings) Translation: SSSD/sssd Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/it/ po: update translations (Italian) currently translated at 100.0% (735 of 735 strings) Translation: SSSD/sssd Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/it/ po: update translations (Italian) currently translated at 100.0% (735 of 735 strings) Translation: SSSD/sssd Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/it/ po: update translations (Italian) currently translated at 100.0% (735 of 735 strings) Translation: SSSD/sssd Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/it/ po: update translations (Italian) currently translated at 100.0% (735 of 735 strings) Translation: SSSD/sssd Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/it/ po: update translations (Indonesian) currently translated at 7.6% (56 of 735 strings) Translation: SSSD/sssd Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/id/ po: update translations (Indonesian) currently translated at 7.6% (56 of 735 strings) Translation: SSSD/sssd Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/id/ po: update translations (Hungarian) currently translated at 5.9% (44 of 735 strings) Translation: SSSD/sssd Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/hu/ po: update translations (Hungarian) currently translated at 5.9% (44 of 735 strings) Translation: SSSD/sssd Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/hu/ po: update translations (Breton) currently translated at 0.8% (25 of 2838 strings) Translation: SSSD/sssd-manpage Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/br/ po: update translations (French) currently translated at 100.0% (735 of 735 strings) Translation: SSSD/sssd Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/fr/ po: update translations (French) currently translated at 100.0% (735 of 735 strings) Translation: SSSD/sssd Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/fr/ po: update translations (French) currently translated at 100.0% (735 of 735 strings) Translation: SSSD/sssd Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/fr/ po: update translations (French) currently translated at 100.0% (735 of 735 strings) Translation: SSSD/sssd Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/fr/ po: update translations (French) currently translated at 100.0% (735 of 735 strings) Translation: SSSD/sssd Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/fr/ po: update translations (French) currently translated at 100.0% (735 of 735 strings) Translation: SSSD/sssd Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/fr/ po: update translations (French) currently translated at 100.0% (735 of 735 strings) Translation: SSSD/sssd Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/fr/ po: update translations (Basque) currently translated at 5.5% (41 of 735 strings) Translation: SSSD/sssd Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/eu/ po: update translations (Spanish) currently translated at 100.0% (735 of 735 strings) Translation: SSSD/sssd Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/es/ po: update translations (Spanish) currently translated at 100.0% (735 of 735 strings) Translation: SSSD/sssd Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/es/ po: update translations (Spanish) currently translated at 100.0% (735 of 735 strings) Translation: SSSD/sssd Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/es/ po: update translations (Spanish) currently translated at 100.0% (735 of 735 strings) Translation: SSSD/sssd Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/es/ po: update translations (Spanish) currently translated at 100.0% (735 of 735 strings) Translation: SSSD/sssd Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/es/ po: update translations (German) currently translated at 42.4% (312 of 735 strings) Translation: SSSD/sssd Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/de/ po: update translations (German) currently translated at 42.4% (312 of 735 strings) Translation: SSSD/sssd Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/de/ po: update translations (German) currently translated at 42.4% (312 of 735 strings) Translation: SSSD/sssd Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/de/ po: update translations (Czech) currently translated at 100.0% (735 of 735 strings) Translation: SSSD/sssd Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/cs/ po: update translations (Czech) currently translated at 100.0% (735 of 735 strings) Translation: SSSD/sssd Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/cs/ po: update translations (Czech) currently translated at 100.0% (735 of 735 strings) Translation: SSSD/sssd Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/cs/ po: update translations (Czech) currently translated at 100.0% (735 of 735 strings) Translation: SSSD/sssd Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/cs/ po: update translations (Czech) currently translated at 100.0% (735 of 735 strings) Translation: SSSD/sssd Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/cs/ po: update translations (Catalan) currently translated at 45.0% (331 of 735 strings) Translation: SSSD/sssd Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/ca/ po: update translations (Bulgarian) currently translated at 12.3% (91 of 735 strings) Translation: SSSD/sssd Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/bg/ Added translation using Weblate (Romanian) Added translation using Weblate (Romanian) Release sssd-2-14-beta1 pot: update pot files --- po/LINGUAS | 1 + po/bg.po | 636 +- po/br.po | 631 +- po/ca.po | 664 +- po/cs.po | 660 +- po/de.po | 639 +- po/es.po | 692 +- po/eu.po | 631 +- po/fi.po | 634 +- po/fr.po | 729 +- po/hu.po | 631 +- po/id.po | 640 +- po/it.po | 691 +- po/ja.po | 731 +- po/ka.po | 660 +- po/ko.po | 785 +- po/lv.po | 631 +- po/nb.po | 633 +- po/nl.po | 644 +- po/pl.po | 701 +- po/pt.po | 672 +- po/pt_BR.po | 1099 ++- po/ro.po | 3287 +++++++ po/ru.po | 691 +- po/sssd.pot | 627 +- po/sv.po | 1461 +-- po/tg.po | 631 +- po/tr.po | 655 +- po/uk.po | 690 +- po/zh_CN.po | 660 +- po/zh_TW.po | 2013 ++-- src/man/po/bg.po | 4 +- src/man/po/br.po | 3308 ++++--- src/man/po/ca.po | 3599 ++++--- src/man/po/cs.po | 3302 ++++--- src/man/po/de.po | 3641 ++++--- src/man/po/es.po | 3906 +++++--- src/man/po/eu.po | 3215 ++++--- src/man/po/fi.po | 3346 ++++--- src/man/po/fr.po | 4856 ++++++---- src/man/po/hu.po | 4 +- src/man/po/id.po | 4 +- src/man/po/it.po | 4 +- src/man/po/ja.po | 3577 ++++--- src/man/po/ka.po | 2096 ++-- src/man/po/ko.po | 305 +- src/man/po/lv.po | 3280 ++++--- src/man/po/nb_NO.po | 6 +- src/man/po/nl.po | 3365 ++++--- src/man/po/pl.po | 4 +- src/man/po/pt.po | 3897 +++++--- src/man/po/pt_BR.po | 3280 ++++--- src/man/po/ro.po | 19231 +++++++++++++++++++++++++++++++++++++ src/man/po/ru.po | 3796 +++++--- src/man/po/sssd-docs.pot | 3207 ++++--- src/man/po/sv.po | 10545 ++++++++++---------- src/man/po/tg.po | 3253 ++++--- src/man/po/tr.po | 4 +- src/man/po/uk.po | 3861 +++++--- src/man/po/zh_CN.po | 3251 ++++--- src/man/po/zh_TW.po | 6506 +++++++++---- version.m4 | 2 +- 62 files changed, 83663 insertions(+), 44142 deletions(-) create mode 100644 po/ro.po create mode 100644 src/man/po/ro.po diff --git a/po/LINGUAS b/po/LINGUAS index 724bb868bf4..ef829f339a7 100644 --- a/po/LINGUAS +++ b/po/LINGUAS @@ -27,3 +27,4 @@ ko ka lv br +ro diff --git a/po/bg.po b/po/bg.po index b38fc1efd7e..ea13bffca99 100644 --- a/po/bg.po +++ b/po/bg.po @@ -8,8 +8,8 @@ msgid "" msgstr "" "Project-Id-Version: PACKAGE VERSION\n" "Report-Msgid-Bugs-To: sssd-devel@lists.fedorahosted.org\n" -"POT-Creation-Date: 2026-01-14 14:57+0000\n" -"PO-Revision-Date: 2026-04-23 16:25+0000\n" +"POT-Creation-Date: 2026-10-02 15:57+0000\n" +"PO-Revision-Date: 2026-10-05 16:36+0000\n" "Last-Translator: Anonymous \n" "Language-Team: Bulgarian \n" @@ -18,50 +18,50 @@ msgstr "" "Content-Type: text/plain; charset=UTF-8\n" "Content-Transfer-Encoding: 8bit\n" "Plural-Forms: nplurals=2; plural=n != 1;\n" -"X-Generator: Weblate 5.17\n" +"X-Generator: Weblate 2026.10\n" -#: src/config/SSSDConfig/sssdoptions.py:20 -#: src/config/SSSDConfig/sssdoptions.py:21 +#: src/config/SSSDConfig/sssdoptions.py:16 +#: src/config/SSSDConfig/sssdoptions.py:17 msgid "Set the verbosity of the debug logging" msgstr "Задава ниво на подробност на debug лог записите" -#: src/config/SSSDConfig/sssdoptions.py:22 +#: src/config/SSSDConfig/sssdoptions.py:18 msgid "Include timestamps in debug logs" msgstr "Включва час и дата в debug лога" -#: src/config/SSSDConfig/sssdoptions.py:23 +#: src/config/SSSDConfig/sssdoptions.py:19 msgid "Include microseconds in timestamps in debug logs" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:24 +#: src/config/SSSDConfig/sssdoptions.py:20 msgid "Enable/disable debug backtrace" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:25 +#: src/config/SSSDConfig/sssdoptions.py:21 msgid "Watchdog timeout before restarting service" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:26 +#: src/config/SSSDConfig/sssdoptions.py:22 msgid "Command to start service" msgstr "Команда за стартиране на услугата" -#: src/config/SSSDConfig/sssdoptions.py:27 +#: src/config/SSSDConfig/sssdoptions.py:23 msgid "The number of file descriptors that may be opened by this responder" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:28 +#: src/config/SSSDConfig/sssdoptions.py:24 msgid "Idle time before automatic disconnection of a client" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:29 +#: src/config/SSSDConfig/sssdoptions.py:25 msgid "Idle time before automatic shutdown of the responder" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:30 +#: src/config/SSSDConfig/sssdoptions.py:26 msgid "Always query all the caches before querying the Data Providers" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:31 +#: src/config/SSSDConfig/sssdoptions.py:27 msgid "" "When SSSD switches to offline mode the amount of time before it tries to go " "back online will increase based upon the time spent disconnected. This value " @@ -69,63 +69,63 @@ msgid "" "random_offset." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:36 +#: src/config/SSSDConfig/sssdoptions.py:32 msgid "SSSD Services to start" msgstr "SSSD услуги за стартиране" -#: src/config/SSSDConfig/sssdoptions.py:37 +#: src/config/SSSDConfig/sssdoptions.py:33 msgid "SSSD Domains to start" msgstr "SSSD домейни за стартиране" -#: src/config/SSSDConfig/sssdoptions.py:38 +#: src/config/SSSDConfig/sssdoptions.py:34 msgid "Regex to parse username and domain" msgstr "Regex за намиране на потребителско име и домейн" -#: src/config/SSSDConfig/sssdoptions.py:39 +#: src/config/SSSDConfig/sssdoptions.py:35 msgid "Printf-compatible format for displaying fully-qualified names" msgstr "Printf-съвместим формат за изобразяване на пълно-квалифицирани имена" -#: src/config/SSSDConfig/sssdoptions.py:40 +#: src/config/SSSDConfig/sssdoptions.py:36 msgid "" "Directory on the filesystem where SSSD should store Kerberos replay cache " "files." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:41 +#: src/config/SSSDConfig/sssdoptions.py:37 msgid "Domain to add to names without a domain component." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:42 +#: src/config/SSSDConfig/sssdoptions.py:38 msgid "The user to drop privileges to" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:43 +#: src/config/SSSDConfig/sssdoptions.py:39 msgid "Tune certificate verification" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:44 +#: src/config/SSSDConfig/sssdoptions.py:40 msgid "All spaces in group or user names will be replaced with this character" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:45 +#: src/config/SSSDConfig/sssdoptions.py:41 msgid "Tune sssd to honor or ignore netlink state changes" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:46 +#: src/config/SSSDConfig/sssdoptions.py:42 msgid "Enable or disable the implicit files domain" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:47 +#: src/config/SSSDConfig/sssdoptions.py:43 msgid "A specific order of the domains to be looked up" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:48 +#: src/config/SSSDConfig/sssdoptions.py:44 msgid "" "Controls if SSSD should monitor the state of resolv.conf to identify when it " "needs to update its internal DNS resolver." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:50 +#: src/config/SSSDConfig/sssdoptions.py:46 msgid "" "SSSD monitors the state of resolv.conf to identify when it needs to update " "its internal DNS resolver. By default, we will attempt to use inotify for " @@ -133,129 +133,129 @@ msgid "" "inotify cannot be used." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:53 +#: src/config/SSSDConfig/sssdoptions.py:49 msgid "Run PAC responder automatically for AD and IPA provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:54 +#: src/config/SSSDConfig/sssdoptions.py:50 msgid "Enable or disable core dumps for all SSSD processes." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:55 +#: src/config/SSSDConfig/sssdoptions.py:51 msgid "Tune passkey verification behavior" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:58 +#: src/config/SSSDConfig/sssdoptions.py:54 msgid "Enumeration cache timeout length (seconds)" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:59 +#: src/config/SSSDConfig/sssdoptions.py:55 msgid "Entry cache background update timeout length (seconds)" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:60 -#: src/config/SSSDConfig/sssdoptions.py:125 +#: src/config/SSSDConfig/sssdoptions.py:56 +#: src/config/SSSDConfig/sssdoptions.py:124 msgid "Negative cache timeout length (seconds)" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:61 +#: src/config/SSSDConfig/sssdoptions.py:57 msgid "Users that SSSD should explicitly ignore" msgstr "Потребители, които SSSD изрично трябва да игнорира" -#: src/config/SSSDConfig/sssdoptions.py:62 +#: src/config/SSSDConfig/sssdoptions.py:58 msgid "Groups that SSSD should explicitly ignore" msgstr "Групи, които SSSD изрично трябва да игнорира" -#: src/config/SSSDConfig/sssdoptions.py:63 +#: src/config/SSSDConfig/sssdoptions.py:59 msgid "Should filtered users appear in groups" msgstr "Да се показват ли филтрираните потребители в групи" -#: src/config/SSSDConfig/sssdoptions.py:64 +#: src/config/SSSDConfig/sssdoptions.py:60 msgid "The value of the password field the NSS provider should return" msgstr "Стойността на полето парола, което NSS доставчикът трябва да върне" -#: src/config/SSSDConfig/sssdoptions.py:65 +#: src/config/SSSDConfig/sssdoptions.py:61 msgid "Override homedir value from the identity provider with this value" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:66 +#: src/config/SSSDConfig/sssdoptions.py:62 msgid "" "Substitute empty homedir value from the identity provider with this value" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:67 +#: src/config/SSSDConfig/sssdoptions.py:63 msgid "Override shell value from the identity provider with this value" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:68 +#: src/config/SSSDConfig/sssdoptions.py:64 msgid "The list of shells users are allowed to log in with" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:69 +#: src/config/SSSDConfig/sssdoptions.py:65 msgid "" "The list of shells that will be vetoed, and replaced with the fallback shell" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:70 +#: src/config/SSSDConfig/sssdoptions.py:66 msgid "" "If a shell stored in central directory is allowed but not available, use " "this fallback" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:71 +#: src/config/SSSDConfig/sssdoptions.py:67 msgid "Shell to use if the provider does not list one" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:72 +#: src/config/SSSDConfig/sssdoptions.py:68 msgid "How long will be in-memory cache records valid" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:74 +#: src/config/SSSDConfig/sssdoptions.py:70 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for passwd requests" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:76 +#: src/config/SSSDConfig/sssdoptions.py:72 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for group requests" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:78 +#: src/config/SSSDConfig/sssdoptions.py:74 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for initgroups requests" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:79 +#: src/config/SSSDConfig/sssdoptions.py:75 msgid "" "The value of this option will be used in the expansion of the " "override_homedir option if the template contains the format string %H." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:81 +#: src/config/SSSDConfig/sssdoptions.py:77 msgid "" "Specifies time in seconds for which the list of subdomains will be " "considered valid." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:83 +#: src/config/SSSDConfig/sssdoptions.py:79 msgid "" "The entry cache can be set to automatically update entries in the background " "if they are requested beyond a percentage of the entry_cache_timeout value " "for the domain." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:88 +#: src/config/SSSDConfig/sssdoptions.py:84 msgid "How long to allow cached logins between online logins (days)" msgstr "Колко дни да се позволява кеширано влизане между влизания онлайн" -#: src/config/SSSDConfig/sssdoptions.py:89 +#: src/config/SSSDConfig/sssdoptions.py:85 msgid "How many failed logins attempts are allowed when offline" msgstr "Колко неуспешни опита за влизане са разрешени, когато сме офлайн" -#: src/config/SSSDConfig/sssdoptions.py:91 +#: src/config/SSSDConfig/sssdoptions.py:87 msgid "" "How long (minutes) to deny login after offline_failed_login_attempts has " "been reached" @@ -263,267 +263,274 @@ msgstr "" "Колко време (в минути) да е забранено влизането, след достигане броя " "неуспешни опити за влизане, когато сме офлайн" -#: src/config/SSSDConfig/sssdoptions.py:92 +#: src/config/SSSDConfig/sssdoptions.py:88 msgid "What kind of messages are displayed to the user during authentication" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:93 +#: src/config/SSSDConfig/sssdoptions.py:89 msgid "Filter PAM responses sent to the pam_sss" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:94 +#: src/config/SSSDConfig/sssdoptions.py:90 msgid "How many seconds to keep identity information cached for PAM requests" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:95 +#: src/config/SSSDConfig/sssdoptions.py:91 msgid "How many days before password expiration a warning should be displayed" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:96 +#: src/config/SSSDConfig/sssdoptions.py:92 msgid "List of trusted uids or user's name" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:97 +#: src/config/SSSDConfig/sssdoptions.py:93 msgid "List of domains accessible even for untrusted users." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:98 +#: src/config/SSSDConfig/sssdoptions.py:94 msgid "Message printed when user account is expired." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:99 +#: src/config/SSSDConfig/sssdoptions.py:95 msgid "Message printed when user account is locked." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:100 +#: src/config/SSSDConfig/sssdoptions.py:96 msgid "Allow certificate based/Smartcard authentication." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:101 +#: src/config/SSSDConfig/sssdoptions.py:97 msgid "Path to certificate database with PKCS#11 modules." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:102 +#: src/config/SSSDConfig/sssdoptions.py:98 #, fuzzy msgid "Tune certificate verification for PAM authentication." msgstr "Изисква TLS проверка на сертификат" -#: src/config/SSSDConfig/sssdoptions.py:103 +#: src/config/SSSDConfig/sssdoptions.py:99 msgid "How many seconds will pam_sss wait for p11_child to finish" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:104 +#: src/config/SSSDConfig/sssdoptions.py:100 msgid "Which PAM services are permitted to contact application domains" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:105 +#: src/config/SSSDConfig/sssdoptions.py:101 msgid "Allowed services for using smartcards" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:106 +#: src/config/SSSDConfig/sssdoptions.py:102 msgid "Additional timeout to wait for a card if requested" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:107 +#: src/config/SSSDConfig/sssdoptions.py:103 msgid "" "PKCS#11 URI to restrict the selection of devices for Smartcard authentication" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:108 +#: src/config/SSSDConfig/sssdoptions.py:104 msgid "When shall the PAM responder force an initgroups request" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:109 +#: src/config/SSSDConfig/sssdoptions.py:105 msgid "List of PAM services that are allowed to authenticate with GSSAPI." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:110 +#: src/config/SSSDConfig/sssdoptions.py:106 msgid "Whether to match authenticated UPN with target user" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:111 +#: src/config/SSSDConfig/sssdoptions.py:107 msgid "" "List of pairs : that must be enforced " "for PAM access with GSSAPI authentication" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:113 +#: src/config/SSSDConfig/sssdoptions.py:109 +msgid "" +"List of triples :: that assigns " +"additional information from the Kerberos ticket to an authentication " +"indicator." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:112 msgid "Allow passkey device authentication." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:114 +#: src/config/SSSDConfig/sssdoptions.py:113 msgid "How many seconds will pam_sss wait for passkey_child to finish" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:115 +#: src/config/SSSDConfig/sssdoptions.py:114 msgid "Enable debugging in the libfido2 library" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:116 +#: src/config/SSSDConfig/sssdoptions.py:115 msgid "Enable JSON protocol for authentication methods selection." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:119 +#: src/config/SSSDConfig/sssdoptions.py:118 msgid "Whether to evaluate the time-based attributes in sudo rules" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:120 +#: src/config/SSSDConfig/sssdoptions.py:119 msgid "If true, SSSD will switch back to lower-wins ordering logic" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:121 +#: src/config/SSSDConfig/sssdoptions.py:120 msgid "" "Maximum number of rules that can be refreshed at once. If this is exceeded, " "full refresh is performed." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:128 +#: src/config/SSSDConfig/sssdoptions.py:127 msgid "Whether to hash host names and addresses in the known_hosts file" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:129 +#: src/config/SSSDConfig/sssdoptions.py:128 msgid "" "How many seconds to keep a host in the known_hosts file after its host keys " "were requested" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:131 +#: src/config/SSSDConfig/sssdoptions.py:130 msgid "Path to storage of trusted CA certificates" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:132 +#: src/config/SSSDConfig/sssdoptions.py:131 msgid "Allow to generate ssh-keys from certificates" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:133 +#: src/config/SSSDConfig/sssdoptions.py:132 msgid "" "Use the following matching rules to filter the certificates for ssh-key " "generation" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:137 +#: src/config/SSSDConfig/sssdoptions.py:136 msgid "List of UIDs or user names allowed to access the PAC responder" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:138 +#: src/config/SSSDConfig/sssdoptions.py:137 msgid "How long the PAC data is considered valid" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:139 +#: src/config/SSSDConfig/sssdoptions.py:138 msgid "Validate the PAC" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:142 +#: src/config/SSSDConfig/sssdoptions.py:141 msgid "List of user attributes the InfoPipe is allowed to publish" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:145 +#: src/config/SSSDConfig/sssdoptions.py:144 msgid "" "One of the following strings specifying the scope of session recording: none " "- No users are recorded. some - Users/groups specified by users and groups " "options are recorded. all - All users are recorded." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:148 +#: src/config/SSSDConfig/sssdoptions.py:147 msgid "" "A comma-separated list of users which should have session recording enabled. " "Matches user names as returned by NSS. I.e. after the possible space " "replacement, case changes, etc." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:150 +#: src/config/SSSDConfig/sssdoptions.py:149 msgid "" "A comma-separated list of groups, members of which should have session " "recording enabled. Matches group names as returned by NSS. I.e. after the " "possible space replacement, case changes, etc." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:153 +#: src/config/SSSDConfig/sssdoptions.py:152 msgid "" "A comma-separated list of users to be excluded from recording, only when " "scope=all" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:154 +#: src/config/SSSDConfig/sssdoptions.py:153 msgid "" "A comma-separated list of groups, members of which should be excluded from " "recording, only when scope=all. " msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:158 +#: src/config/SSSDConfig/sssdoptions.py:157 msgid "Identity provider" msgstr "Доставчик на самоличност" -#: src/config/SSSDConfig/sssdoptions.py:159 +#: src/config/SSSDConfig/sssdoptions.py:158 msgid "Authentication provider" msgstr "Доставчик на удостоверяване" -#: src/config/SSSDConfig/sssdoptions.py:160 +#: src/config/SSSDConfig/sssdoptions.py:159 msgid "Access control provider" msgstr "Доставчик на контрол на достъп" -#: src/config/SSSDConfig/sssdoptions.py:161 +#: src/config/SSSDConfig/sssdoptions.py:160 msgid "Password change provider" msgstr "Доставчик на смяна на парола" -#: src/config/SSSDConfig/sssdoptions.py:162 +#: src/config/SSSDConfig/sssdoptions.py:161 msgid "SUDO provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:163 +#: src/config/SSSDConfig/sssdoptions.py:162 msgid "Autofs provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:164 +#: src/config/SSSDConfig/sssdoptions.py:163 msgid "Host identity provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:165 +#: src/config/SSSDConfig/sssdoptions.py:164 msgid "SELinux provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:166 +#: src/config/SSSDConfig/sssdoptions.py:165 msgid "Session management provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:167 +#: src/config/SSSDConfig/sssdoptions.py:166 msgid "Resolver provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:170 +#: src/config/SSSDConfig/sssdoptions.py:169 msgid "Whether the domain is usable by the OS or by applications" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:171 +#: src/config/SSSDConfig/sssdoptions.py:170 #, fuzzy msgid "Enable or disable the domain" msgstr "Разреши проверката на данните за удостоверяване" -#: src/config/SSSDConfig/sssdoptions.py:172 +#: src/config/SSSDConfig/sssdoptions.py:171 msgid "Minimum user ID" msgstr "Минимално ID на потребител" -#: src/config/SSSDConfig/sssdoptions.py:173 +#: src/config/SSSDConfig/sssdoptions.py:172 msgid "Maximum user ID" msgstr "Максимално ID на потребител" -#: src/config/SSSDConfig/sssdoptions.py:174 +#: src/config/SSSDConfig/sssdoptions.py:173 msgid "Enable enumerating all users/groups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:175 +#: src/config/SSSDConfig/sssdoptions.py:174 msgid "Cache credentials for offline login" msgstr "Кеширай идентификационни данни за офлайн влизане" -#: src/config/SSSDConfig/sssdoptions.py:176 +#: src/config/SSSDConfig/sssdoptions.py:175 msgid "Display users/groups in fully-qualified form" msgstr "Показвай потребители/групи в пълно -валифицирана форма" -#: src/config/SSSDConfig/sssdoptions.py:177 +#: src/config/SSSDConfig/sssdoptions.py:176 msgid "Don't include group members in group lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:178 +#: src/config/SSSDConfig/sssdoptions.py:177 #: src/config/SSSDConfig/sssdoptions.py:190 #: src/config/SSSDConfig/sssdoptions.py:191 #: src/config/SSSDConfig/sssdoptions.py:192 @@ -534,49 +541,54 @@ msgstr "" msgid "Entry cache timeout length (seconds)" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:179 +#: src/config/SSSDConfig/sssdoptions.py:178 msgid "" "Restrict or prefer a specific address family when performing DNS lookups" msgstr "Ограничава или предпочита определена фамилия адреси при DNS търсения" -#: src/config/SSSDConfig/sssdoptions.py:180 +#: src/config/SSSDConfig/sssdoptions.py:179 msgid "How long to keep cached entries after last successful login (days)" -msgstr "Колко дни да се пазят кешираните записи след последното успешно влизане" +msgstr "" +"Колко дни да се пазят кешираните записи след последното успешно влизане" -#: src/config/SSSDConfig/sssdoptions.py:181 +#: src/config/SSSDConfig/sssdoptions.py:180 msgid "" "How long should SSSD talk to single DNS server before trying next server " "(miliseconds)" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:183 +#: src/config/SSSDConfig/sssdoptions.py:182 msgid "How long should keep trying to resolve single DNS query (seconds)" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:184 +#: src/config/SSSDConfig/sssdoptions.py:183 msgid "How long to wait for replies from DNS when resolving servers (seconds)" msgstr "" "Колко време да чакам за отговори от DNS при търсене на сървъри (секунди)" -#: src/config/SSSDConfig/sssdoptions.py:185 +#: src/config/SSSDConfig/sssdoptions.py:184 msgid "The domain part of service discovery DNS query" msgstr "Частта Домейн от DNS заявката за откриване на услуга" -#: src/config/SSSDConfig/sssdoptions.py:186 +#: src/config/SSSDConfig/sssdoptions.py:185 msgid "" "Specifies the interval, in seconds, that SSSD waits before attempting to " "reconnect to the primary server after a successful connection to the backup " "server" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:188 +#: src/config/SSSDConfig/sssdoptions.py:187 msgid "Override GID value from the identity provider with this value" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:189 +#: src/config/SSSDConfig/sssdoptions.py:188 msgid "Treat usernames as case sensitive" msgstr "" +#: src/config/SSSDConfig/sssdoptions.py:189 +msgid "Lookups by ID are expensive or do not work at all" +msgstr "" + #: src/config/SSSDConfig/sssdoptions.py:197 msgid "How often should expired entries be refreshed in background" msgstr "" @@ -798,7 +810,7 @@ msgid "Search base for SUBID ranges" msgstr "" #: src/config/SSSDConfig/sssdoptions.py:259 -#: src/config/SSSDConfig/sssdoptions.py:506 +#: src/config/SSSDConfig/sssdoptions.py:512 msgid "Which rules should be used to evaluate access control" msgstr "" @@ -940,7 +952,7 @@ msgid "Enable DNS sites - location based service discovery" msgstr "" #: src/config/SSSDConfig/sssdoptions.py:301 -#: src/config/SSSDConfig/sssdoptions.py:504 +#: src/config/SSSDConfig/sssdoptions.py:510 msgid "LDAP filter to determine access privileges" msgstr "LDAP филтър за определяне права на достъп" @@ -1361,7 +1373,7 @@ msgid "UUID attribute" msgstr "" #: src/config/SSSDConfig/sssdoptions.py:423 -#: src/config/SSSDConfig/sssdoptions.py:464 +#: src/config/SSSDConfig/sssdoptions.py:470 msgid "objectSID attribute" msgstr "" @@ -1485,385 +1497,411 @@ msgstr "" msgid "A list of extra attributes to download along with the user entry" msgstr "" +#: src/config/SSSDConfig/sssdoptions.py:456 +msgid "The object class of an subid entry in LDAP." +msgstr "" + #: src/config/SSSDConfig/sssdoptions.py:457 +#, fuzzy +msgid "Subordinate user ID count attribute" +msgstr "атрибут Първичен GID" + +#: src/config/SSSDConfig/sssdoptions.py:458 +msgid "Subordinate group ID count attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:459 +#, fuzzy +msgid "User ID range start value attribute" +msgstr "атрибут Потребителско име" + +#: src/config/SSSDConfig/sssdoptions.py:460 +msgid "Group ID range start value attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:461 +msgid "Owner of an entry" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:463 msgid "Base DN for group lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:458 +#: src/config/SSSDConfig/sssdoptions.py:464 msgid "Objectclass for groups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:459 +#: src/config/SSSDConfig/sssdoptions.py:465 msgid "Group name" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:460 +#: src/config/SSSDConfig/sssdoptions.py:466 msgid "Group password" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:461 +#: src/config/SSSDConfig/sssdoptions.py:467 msgid "GID attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:462 +#: src/config/SSSDConfig/sssdoptions.py:468 msgid "Group member attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:463 +#: src/config/SSSDConfig/sssdoptions.py:469 msgid "Group UUID attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:465 +#: src/config/SSSDConfig/sssdoptions.py:471 msgid "Modification time attribute for groups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:466 +#: src/config/SSSDConfig/sssdoptions.py:472 msgid "Type of the group and other flags" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:467 +#: src/config/SSSDConfig/sssdoptions.py:473 msgid "The LDAP group external member attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:468 +#: src/config/SSSDConfig/sssdoptions.py:474 msgid "Maximum nesting level SSSD will follow" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:469 +#: src/config/SSSDConfig/sssdoptions.py:475 msgid "Filter for group lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:470 +#: src/config/SSSDConfig/sssdoptions.py:476 msgid "Scope of group lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:472 +#: src/config/SSSDConfig/sssdoptions.py:478 msgid "Base DN for netgroup lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:473 +#: src/config/SSSDConfig/sssdoptions.py:479 msgid "Objectclass for netgroups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:474 +#: src/config/SSSDConfig/sssdoptions.py:480 msgid "Netgroup name" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:475 +#: src/config/SSSDConfig/sssdoptions.py:481 msgid "Netgroups members attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:476 +#: src/config/SSSDConfig/sssdoptions.py:482 msgid "Netgroup triple attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:477 +#: src/config/SSSDConfig/sssdoptions.py:483 msgid "Modification time attribute for netgroups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:479 +#: src/config/SSSDConfig/sssdoptions.py:485 msgid "Base DN for service lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:480 +#: src/config/SSSDConfig/sssdoptions.py:486 msgid "Objectclass for services" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:481 +#: src/config/SSSDConfig/sssdoptions.py:487 msgid "Service name attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:482 +#: src/config/SSSDConfig/sssdoptions.py:488 msgid "Service port attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:483 +#: src/config/SSSDConfig/sssdoptions.py:489 msgid "Service protocol attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:485 +#: src/config/SSSDConfig/sssdoptions.py:491 msgid "Lower bound for ID-mapping" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:486 +#: src/config/SSSDConfig/sssdoptions.py:492 msgid "Upper bound for ID-mapping" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:487 +#: src/config/SSSDConfig/sssdoptions.py:493 msgid "Number of IDs for each slice when ID-mapping" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:488 +#: src/config/SSSDConfig/sssdoptions.py:494 msgid "Use autorid-compatible algorithm for ID-mapping" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:489 +#: src/config/SSSDConfig/sssdoptions.py:495 msgid "Name of the default domain for ID-mapping" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:490 +#: src/config/SSSDConfig/sssdoptions.py:496 msgid "SID of the default domain for ID-mapping" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:491 +#: src/config/SSSDConfig/sssdoptions.py:497 msgid "Number of secondary slices" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:493 +#: src/config/SSSDConfig/sssdoptions.py:499 msgid "Whether to use Token-Groups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:494 +#: src/config/SSSDConfig/sssdoptions.py:500 msgid "Set lower boundary for allowed IDs from the LDAP server" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:495 +#: src/config/SSSDConfig/sssdoptions.py:501 msgid "Set upper boundary for allowed IDs from the LDAP server" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:496 +#: src/config/SSSDConfig/sssdoptions.py:502 msgid "DN for ppolicy queries" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:497 +#: src/config/SSSDConfig/sssdoptions.py:503 msgid "How many maximum entries to fetch during a wildcard request" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:498 +#: src/config/SSSDConfig/sssdoptions.py:504 msgid "Set libldap debug level" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:501 +#: src/config/SSSDConfig/sssdoptions.py:507 msgid "Policy to evaluate the password expiration" msgstr "Политика за определяне срок на валидност на парола" -#: src/config/SSSDConfig/sssdoptions.py:505 +#: src/config/SSSDConfig/sssdoptions.py:511 msgid "Which attributes shall be used to evaluate if an account is expired" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:509 +#: src/config/SSSDConfig/sssdoptions.py:515 msgid "URI of an LDAP server where password changes are allowed" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:510 +#: src/config/SSSDConfig/sssdoptions.py:516 msgid "URI of a backup LDAP server where password changes are allowed" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:511 +#: src/config/SSSDConfig/sssdoptions.py:517 msgid "DNS service name for LDAP password change server" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:512 +#: src/config/SSSDConfig/sssdoptions.py:518 msgid "" "Whether to update the ldap_user_shadow_last_change attribute after a " "password change" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:516 +#: src/config/SSSDConfig/sssdoptions.py:522 msgid "Base DN for sudo rules lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:517 +#: src/config/SSSDConfig/sssdoptions.py:523 msgid "Automatic full refresh period" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:518 +#: src/config/SSSDConfig/sssdoptions.py:524 msgid "Automatic smart refresh period" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:519 +#: src/config/SSSDConfig/sssdoptions.py:525 msgid "Smart and full refresh random offset" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:520 +#: src/config/SSSDConfig/sssdoptions.py:526 msgid "Whether to filter rules by hostname, IP addresses and network" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:521 +#: src/config/SSSDConfig/sssdoptions.py:527 msgid "" "Hostnames and/or fully qualified domain names of this machine to filter sudo " "rules" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:522 +#: src/config/SSSDConfig/sssdoptions.py:528 msgid "IPv4 or IPv6 addresses or network of this machine to filter sudo rules" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:523 +#: src/config/SSSDConfig/sssdoptions.py:529 msgid "Whether to include rules that contains netgroup in host attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:524 +#: src/config/SSSDConfig/sssdoptions.py:530 msgid "" "Whether to include rules that contains regular expression in host attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:525 +#: src/config/SSSDConfig/sssdoptions.py:531 msgid "Object class for sudo rules" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:526 +#: src/config/SSSDConfig/sssdoptions.py:532 msgid "Name of attribute that is used as object class for sudo rules" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:527 +#: src/config/SSSDConfig/sssdoptions.py:533 msgid "Sudo rule name" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:528 +#: src/config/SSSDConfig/sssdoptions.py:534 msgid "Sudo rule command attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:529 +#: src/config/SSSDConfig/sssdoptions.py:535 msgid "Sudo rule host attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:530 +#: src/config/SSSDConfig/sssdoptions.py:536 msgid "Sudo rule user attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:531 +#: src/config/SSSDConfig/sssdoptions.py:537 msgid "Sudo rule option attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:532 +#: src/config/SSSDConfig/sssdoptions.py:538 msgid "Sudo rule runas attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:533 +#: src/config/SSSDConfig/sssdoptions.py:539 msgid "Sudo rule runasuser attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:534 +#: src/config/SSSDConfig/sssdoptions.py:540 msgid "Sudo rule runasgroup attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:535 +#: src/config/SSSDConfig/sssdoptions.py:541 msgid "Sudo rule notbefore attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:536 +#: src/config/SSSDConfig/sssdoptions.py:542 msgid "Sudo rule notafter attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:537 +#: src/config/SSSDConfig/sssdoptions.py:543 msgid "Sudo rule order attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:540 +#: src/config/SSSDConfig/sssdoptions.py:546 msgid "Object class for automounter maps" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:541 +#: src/config/SSSDConfig/sssdoptions.py:547 msgid "Automounter map name attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:542 +#: src/config/SSSDConfig/sssdoptions.py:548 msgid "Object class for automounter map entries" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:543 +#: src/config/SSSDConfig/sssdoptions.py:549 msgid "Automounter map entry key attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:544 +#: src/config/SSSDConfig/sssdoptions.py:550 msgid "Automounter map entry value attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:545 +#: src/config/SSSDConfig/sssdoptions.py:551 msgid "Base DN for automounter map lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:546 +#: src/config/SSSDConfig/sssdoptions.py:552 msgid "The name of the automount master map in LDAP." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:549 +#: src/config/SSSDConfig/sssdoptions.py:555 msgid "Base DN for IP hosts lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:550 +#: src/config/SSSDConfig/sssdoptions.py:556 msgid "Object class for IP hosts" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:551 +#: src/config/SSSDConfig/sssdoptions.py:557 msgid "IP host name attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:552 +#: src/config/SSSDConfig/sssdoptions.py:558 msgid "IP host number (address) attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:553 +#: src/config/SSSDConfig/sssdoptions.py:559 msgid "IP host entryUSN attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:554 +#: src/config/SSSDConfig/sssdoptions.py:560 msgid "Base DN for IP networks lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:555 +#: src/config/SSSDConfig/sssdoptions.py:561 msgid "Object class for IP networks" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:556 +#: src/config/SSSDConfig/sssdoptions.py:562 msgid "IP network name attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:557 +#: src/config/SSSDConfig/sssdoptions.py:563 msgid "IP network number (address) attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:558 +#: src/config/SSSDConfig/sssdoptions.py:564 msgid "IP network entryUSN attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:561 +#: src/config/SSSDConfig/sssdoptions.py:567 msgid "Comma separated list of allowed users" msgstr "Списък разрешени потребители, разделени със запетая" -#: src/config/SSSDConfig/sssdoptions.py:562 +#: src/config/SSSDConfig/sssdoptions.py:568 msgid "Comma separated list of prohibited users" msgstr "Списък забранени потребители, разделени със запетая" -#: src/config/SSSDConfig/sssdoptions.py:563 +#: src/config/SSSDConfig/sssdoptions.py:569 msgid "" "Comma separated list of groups that are allowed to log in. This applies only " "to groups within this SSSD domain. Local groups are not evaluated." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:565 +#: src/config/SSSDConfig/sssdoptions.py:571 msgid "" "Comma separated list of groups that are explicitly denied access. This " "applies only to groups within this SSSD domain. Local groups are not " "evaluated." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:569 +#: src/config/SSSDConfig/sssdoptions.py:575 msgid "The number of preforked proxy children." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:572 +#: src/config/SSSDConfig/sssdoptions.py:578 msgid "The name of the NSS library to use" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:573 +#: src/config/SSSDConfig/sssdoptions.py:579 msgid "The name of the NSS library to use for hosts and networks lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:574 +#: src/config/SSSDConfig/sssdoptions.py:580 msgid "Whether to look up canonical group name from cache if possible" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:577 +#: src/config/SSSDConfig/sssdoptions.py:583 msgid "PAM stack to use" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:580 +#: src/config/SSSDConfig/sssdoptions.py:586 msgid "Path of passwd file sources." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:581 +#: src/config/SSSDConfig/sssdoptions.py:587 msgid "Path of group file sources." msgstr "" @@ -1891,226 +1929,234 @@ msgstr "" msgid "Option -i|--interactive is not allowed together with -D|--daemon\n" msgstr "" -#: src/monitor/monitor.c:1836 +#: src/monitor/monitor.c:1838 msgid "Failed to get initial capabilities\n" msgstr "" -#: src/monitor/monitor.c:1847 +#: src/monitor/monitor.c:1849 msgid "Non-root service user support isn't built. Can't run under %" msgstr "" -#: src/monitor/monitor.c:1864 +#: src/monitor/monitor.c:1866 #, c-format msgid "Can't read config: '%s'\n" msgstr "" -#: src/monitor/monitor.c:1876 +#: src/monitor/monitor.c:1878 #, c-format -msgid "Failed to boostrap SSSD 'monitor' process: %s" +msgid "Failed to bootstrap SSSD 'monitor' process: %s" msgstr "" -#: src/monitor/monitor.c:1971 +#: src/monitor/monitor.c:1973 msgid "Out of memory\n" msgstr "" -#: src/providers/krb5/krb5_child.c:4221 +#: src/providers/krb5/krb5_child.c:4316 msgid "Use anonymous PKINIT to request FAST armor ticket" msgstr "" -#: src/providers/krb5/krb5_child.c:4223 +#: src/providers/krb5/krb5_child.c:4318 msgid "Kerberos realm to use" msgstr "" -#: src/providers/krb5/krb5_child.c:4225 +#: src/providers/krb5/krb5_child.c:4320 msgid "Requested lifetime of the ticket" msgstr "" -#: src/providers/krb5/krb5_child.c:4227 +#: src/providers/krb5/krb5_child.c:4322 msgid "Requested renewable lifetime of the ticket" msgstr "" -#: src/providers/krb5/krb5_child.c:4229 +#: src/providers/krb5/krb5_child.c:4324 msgid "FAST options ('never', 'try', 'demand')" msgstr "" -#: src/providers/krb5/krb5_child.c:4232 +#: src/providers/krb5/krb5_child.c:4327 msgid "Specifies the server principal to use for FAST" msgstr "" -#: src/providers/krb5/krb5_child.c:4234 +#: src/providers/krb5/krb5_child.c:4329 msgid "Requests canonicalization of the principal name" msgstr "" -#: src/providers/krb5/krb5_child.c:4236 +#: src/providers/krb5/krb5_child.c:4331 msgid "Use custom version of krb5_get_init_creds_password" msgstr "" -#: src/providers/krb5/krb5_child.c:4238 +#: src/providers/krb5/krb5_child.c:4333 msgid "Check PAC flags" msgstr "" -#: src/providers/data_provider_be.c:790 +#: src/providers/krb5/krb5_child.c:4335 +msgid "Set environment variable (KEY=VALUE)" +msgstr "" + +#: src/providers/data_provider_be.c:786 msgid "Domain of the information provider (mandatory)" msgstr "" -#: src/sss_client/common.c:1165 +#: src/sss_client/common.c:1208 msgid "Socket has wrong ownership or permissions." msgstr "" -#: src/sss_client/common.c:1168 +#: src/sss_client/common.c:1211 msgid "Unexpected format of the server credential message." msgstr "" -#: src/sss_client/common.c:1171 +#: src/sss_client/common.c:1214 #, fuzzy msgid "SSSD is not run by trusted user." msgstr "SSSD не е стартиран като root." -#: src/sss_client/common.c:1174 +#: src/sss_client/common.c:1217 msgid "SSSD socket does not exist." msgstr "" -#: src/sss_client/common.c:1177 +#: src/sss_client/common.c:1220 msgid "Cannot get stat of SSSD socket." msgstr "" -#: src/sss_client/common.c:1182 +#: src/sss_client/common.c:1225 msgid "An error occurred, but no description can be found." msgstr "Възникнала е грешка, но не може да се намери описание." -#: src/sss_client/common.c:1188 +#: src/sss_client/common.c:1231 msgid "Unexpected error while looking for an error description" msgstr "Неочаквана грешка при търсене на описание на грешка" -#: src/sss_client/pam_sss.c:74 +#: src/sss_client/pam_sss.c:135 msgid "Permission denied. " msgstr "" -#: src/sss_client/pam_sss.c:75 src/sss_client/pam_sss.c:843 -#: src/sss_client/pam_sss.c:854 +#: src/sss_client/pam_sss.c:136 src/sss_client/pam_sss.c:921 +#: src/sss_client/pam_sss.c:932 msgid "Server message: " msgstr "Съобщение от сървъра:" -#: src/sss_client/pam_sss.c:76 +#: src/sss_client/pam_sss.c:137 msgid "" "Kerberos TGT will not be granted upon login, user experience will be " "affected." msgstr "" -#: src/sss_client/pam_sss.c:77 +#: src/sss_client/pam_sss.c:138 msgid "Enter PIN:" msgstr "" -#: src/sss_client/pam_sss.c:320 +#: src/sss_client/pam_sss.c:385 msgid "Passwords do not match" msgstr "Паролите не съвпадат" -#: src/sss_client/pam_sss.c:508 +#: src/sss_client/pam_sss.c:584 msgid "Password reset by root is not supported." msgstr "Промяна на паролата от root не се поддържа." -#: src/sss_client/pam_sss.c:549 +#: src/sss_client/pam_sss.c:625 msgid "Authenticated with cached credentials" msgstr "Удостоверен с кеширани идентификационни данни" -#: src/sss_client/pam_sss.c:550 +#: src/sss_client/pam_sss.c:626 msgid ", your cached password will expire at: " msgstr ", кешираната парола ще изтече на: " -#: src/sss_client/pam_sss.c:580 +#: src/sss_client/pam_sss.c:656 #, c-format msgid "Your password has expired. You have %1$d grace login(s) remaining." msgstr "" -#: src/sss_client/pam_sss.c:630 +#: src/sss_client/pam_sss.c:706 #, c-format msgid "Your password will expire in %1$d %2$s." msgstr "" -#: src/sss_client/pam_sss.c:633 +#: src/sss_client/pam_sss.c:709 #, fuzzy, c-format msgid "Your password has expired." msgstr ", кешираната парола ще изтече на: " -#: src/sss_client/pam_sss.c:684 +#: src/sss_client/pam_sss.c:760 msgid "Authentication is denied until: " msgstr "Удостоверяването е забранено до: " -#: src/sss_client/pam_sss.c:705 +#: src/sss_client/pam_sss.c:781 msgid "System is offline, password change not possible" msgstr "Системата е офлайн, промяна на паролата не е възможна" -#: src/sss_client/pam_sss.c:720 +#: src/sss_client/pam_sss.c:796 msgid "" "After changing the OTP password, you need to log out and back in order to " "acquire a ticket" msgstr "" -#: src/sss_client/pam_sss.c:735 +#: src/sss_client/pam_sss.c:813 msgid "PIN locked" msgstr "" -#: src/sss_client/pam_sss.c:750 +#: src/sss_client/pam_sss.c:828 msgid "" "No Kerberos TGT granted as the server does not support this method. Your " "single-sign on(SSO) experience will be affected." msgstr "" -#: src/sss_client/pam_sss.c:840 src/sss_client/pam_sss.c:853 +#: src/sss_client/pam_sss.c:918 src/sss_client/pam_sss.c:931 msgid "Password change failed. " msgstr "Промяната на паролата не успя." -#: src/sss_client/pam_sss.c:1859 +#: src/sss_client/pam_sss.c:2028 #, c-format -msgid "Authenticate at %1$s and press ENTER." +msgid "Authenticate at \"%1$s\"." msgstr "" -#: src/sss_client/pam_sss.c:1862 +#: src/sss_client/pam_sss.c:2031 #, c-format -msgid "Authenticate with PIN %1$s at %2$s and press ENTER." +msgid "Authenticate with PIN \"%1$s\" at \"%2$s\"." msgstr "" -#: src/sss_client/pam_sss.c:2281 +#: src/sss_client/pam_sss.c:2470 msgid "Please (re)insert (different) Smartcard" msgstr "" -#: src/sss_client/pam_sss.c:2482 +#: src/sss_client/pam_sss.c:2700 msgid "New Password: " msgstr "Нова парола:" -#: src/sss_client/pam_sss.c:2483 +#: src/sss_client/pam_sss.c:2701 msgid "Reenter new Password: " msgstr "Отново новата парола:" -#: src/sss_client/pam_sss.c:2676 src/sss_client/pam_sss.c:2679 +#: src/sss_client/pam_sss.c:2890 +msgid "Press ENTER to continue." +msgstr "" + +#: src/sss_client/pam_sss.c:2913 src/sss_client/pam_sss.c:2916 msgid "First Factor: " msgstr "" -#: src/sss_client/pam_sss.c:2677 src/sss_client/pam_sss.c:2851 +#: src/sss_client/pam_sss.c:2914 src/sss_client/pam_sss.c:3088 msgid "Second Factor (optional): " msgstr "" -#: src/sss_client/pam_sss.c:2680 src/sss_client/pam_sss.c:2855 +#: src/sss_client/pam_sss.c:2917 src/sss_client/pam_sss.c:3092 msgid "Second Factor: " msgstr "" -#: src/sss_client/pam_sss.c:2684 +#: src/sss_client/pam_sss.c:2921 msgid "Insert your passkey device, then press ENTER." msgstr "" -#: src/sss_client/pam_sss.c:2688 src/sss_client/pam_sss.c:2696 +#: src/sss_client/pam_sss.c:2925 src/sss_client/pam_sss.c:2933 msgid "Password: " msgstr "Парола:" -#: src/sss_client/pam_sss.c:2850 src/sss_client/pam_sss.c:2854 +#: src/sss_client/pam_sss.c:3087 src/sss_client/pam_sss.c:3091 msgid "First Factor (Current Password): " msgstr "" -#: src/sss_client/pam_sss.c:2874 +#: src/sss_client/pam_sss.c:3111 msgid "Current Password: " msgstr "Текуща парола:" -#: src/sss_client/pam_sss.c:3248 +#: src/sss_client/pam_sss.c:3485 msgid "Password expired. Change your password now." msgstr "Паролата Ви е остаряла. Сменете я сега." @@ -2545,9 +2591,9 @@ msgstr "" #: src/tools/sssctl/sssctl_cache.c:835 src/tools/sssctl/sssctl_cache.c:918 #: src/tools/sssctl/sssctl_cache.c:950 src/tools/sssctl/sssctl_cache.c:956 #: src/tools/sssctl/sssctl_cache.c:1010 src/tools/sssctl/sssctl_cache.c:1034 -#: src/tools/sssctl/sssctl_cache.c:1085 src/tools/sssctl/sssctl_cache.c:1194 -#: src/tools/sssctl/sssctl_cache.c:1229 src/tools/sssctl/sssctl_cache.c:1235 -#: src/tools/sssctl/sssctl_cache.c:1244 +#: src/tools/sssctl/sssctl_cache.c:1085 src/tools/sssctl/sssctl_cache.c:1195 +#: src/tools/sssctl/sssctl_cache.c:1230 src/tools/sssctl/sssctl_cache.c:1236 +#: src/tools/sssctl/sssctl_cache.c:1245 msgid "talloc failed\n" msgstr "" @@ -2621,25 +2667,25 @@ msgstr "" msgid "Unable to remove downloaded GPO files: %s\n" msgstr "" -#: src/tools/sssctl/sssctl_cache.c:1165 +#: src/tools/sssctl/sssctl_cache.c:1166 #, c-format msgid "Failed to fetch cache entry: %s\n" msgstr "" -#: src/tools/sssctl/sssctl_cache.c:1170 +#: src/tools/sssctl/sssctl_cache.c:1171 msgid "Could not determine object domain\n" msgstr "" -#: src/tools/sssctl/sssctl_cache.c:1200 +#: src/tools/sssctl/sssctl_cache.c:1201 msgid "Could not find GUID attribute in GPO entry\n" msgstr "" -#: src/tools/sssctl/sssctl_cache.c:1206 +#: src/tools/sssctl/sssctl_cache.c:1207 #, c-format msgid "Failed to delete GPO: %s\n" msgstr "" -#: src/tools/sssctl/sssctl_cache.c:1210 +#: src/tools/sssctl/sssctl_cache.c:1211 #, c-format msgid "%s removed from cache\n" msgstr "" @@ -2727,39 +2773,39 @@ msgid "" "\"/my/path/sssd.conf\", the snippet dir \"/my/path/conf.d\" is used)" msgstr "" -#: src/tools/sssctl/sssctl_config.c:114 +#: src/tools/sssctl/sssctl_config.c:126 #, c-format msgid "File %1$s does not exist.\n" msgstr "" -#: src/tools/sssctl/sssctl_config.c:115 +#: src/tools/sssctl/sssctl_config.c:127 msgid "There is no configuration.\n" msgstr "" -#: src/tools/sssctl/sssctl_config.c:120 +#: src/tools/sssctl/sssctl_config.c:132 #, c-format msgid "Configuration validation failed: %s\n" msgstr "" -#: src/tools/sssctl/sssctl_config.c:121 +#: src/tools/sssctl/sssctl_config.c:133 msgid "Run with high debug level to see details.\n" msgstr "" -#: src/tools/sssctl/sssctl_config.c:130 -msgid "Failed to run validators" +#: src/tools/sssctl/sssctl_config.c:142 +msgid "Failed to run validators\n" msgstr "" -#: src/tools/sssctl/sssctl_config.c:134 +#: src/tools/sssctl/sssctl_config.c:146 #, c-format msgid "Issues identified by validators: %zu\n" msgstr "" -#: src/tools/sssctl/sssctl_config.c:145 +#: src/tools/sssctl/sssctl_config.c:157 #, c-format msgid "Messages generated during configuration merging: %zu\n" msgstr "" -#: src/tools/sssctl/sssctl_config.c:158 +#: src/tools/sssctl/sssctl_config.c:170 #, c-format msgid "Used configuration snippet files: %zu\n" msgstr "" diff --git a/po/br.po b/po/br.po index d533e70c1aa..7515c3d9754 100644 --- a/po/br.po +++ b/po/br.po @@ -6,8 +6,8 @@ msgid "" msgstr "" "Project-Id-Version: PACKAGE VERSION\n" "Report-Msgid-Bugs-To: sssd-devel@lists.fedorahosted.org\n" -"POT-Creation-Date: 2026-01-14 14:57+0000\n" -"PO-Revision-Date: 2026-04-23 16:47+0000\n" +"POT-Creation-Date: 2026-10-02 15:57+0000\n" +"PO-Revision-Date: 2026-10-05 17:17+0000\n" "Last-Translator: Anonymous \n" "Language-Team: Breton \n" @@ -20,50 +20,50 @@ msgstr "" "&& n % 100 != 92) ? 1 : ((((n % 10 == 3 || n % 10 == 4) || n % 10 == 9) && " "(n % 100 < 10 || n % 100 > 19) && (n % 100 < 70 || n % 100 > 79) && (n % 100 " "< 90 || n % 100 > 99)) ? 2 : ((n != 0 && n % 1000000 == 0) ? 3 : 4)));\n" -"X-Generator: Weblate 5.17\n" +"X-Generator: Weblate 2026.10\n" -#: src/config/SSSDConfig/sssdoptions.py:20 -#: src/config/SSSDConfig/sssdoptions.py:21 +#: src/config/SSSDConfig/sssdoptions.py:16 +#: src/config/SSSDConfig/sssdoptions.py:17 msgid "Set the verbosity of the debug logging" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:22 +#: src/config/SSSDConfig/sssdoptions.py:18 msgid "Include timestamps in debug logs" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:23 +#: src/config/SSSDConfig/sssdoptions.py:19 msgid "Include microseconds in timestamps in debug logs" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:24 +#: src/config/SSSDConfig/sssdoptions.py:20 msgid "Enable/disable debug backtrace" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:25 +#: src/config/SSSDConfig/sssdoptions.py:21 msgid "Watchdog timeout before restarting service" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:26 +#: src/config/SSSDConfig/sssdoptions.py:22 msgid "Command to start service" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:27 +#: src/config/SSSDConfig/sssdoptions.py:23 msgid "The number of file descriptors that may be opened by this responder" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:28 +#: src/config/SSSDConfig/sssdoptions.py:24 msgid "Idle time before automatic disconnection of a client" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:29 +#: src/config/SSSDConfig/sssdoptions.py:25 msgid "Idle time before automatic shutdown of the responder" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:30 +#: src/config/SSSDConfig/sssdoptions.py:26 msgid "Always query all the caches before querying the Data Providers" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:31 +#: src/config/SSSDConfig/sssdoptions.py:27 msgid "" "When SSSD switches to offline mode the amount of time before it tries to go " "back online will increase based upon the time spent disconnected. This value " @@ -71,63 +71,63 @@ msgid "" "random_offset." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:36 +#: src/config/SSSDConfig/sssdoptions.py:32 msgid "SSSD Services to start" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:37 +#: src/config/SSSDConfig/sssdoptions.py:33 msgid "SSSD Domains to start" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:38 +#: src/config/SSSDConfig/sssdoptions.py:34 msgid "Regex to parse username and domain" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:39 +#: src/config/SSSDConfig/sssdoptions.py:35 msgid "Printf-compatible format for displaying fully-qualified names" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:40 +#: src/config/SSSDConfig/sssdoptions.py:36 msgid "" "Directory on the filesystem where SSSD should store Kerberos replay cache " "files." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:41 +#: src/config/SSSDConfig/sssdoptions.py:37 msgid "Domain to add to names without a domain component." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:42 +#: src/config/SSSDConfig/sssdoptions.py:38 msgid "The user to drop privileges to" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:43 +#: src/config/SSSDConfig/sssdoptions.py:39 msgid "Tune certificate verification" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:44 +#: src/config/SSSDConfig/sssdoptions.py:40 msgid "All spaces in group or user names will be replaced with this character" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:45 +#: src/config/SSSDConfig/sssdoptions.py:41 msgid "Tune sssd to honor or ignore netlink state changes" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:46 +#: src/config/SSSDConfig/sssdoptions.py:42 msgid "Enable or disable the implicit files domain" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:47 +#: src/config/SSSDConfig/sssdoptions.py:43 msgid "A specific order of the domains to be looked up" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:48 +#: src/config/SSSDConfig/sssdoptions.py:44 msgid "" "Controls if SSSD should monitor the state of resolv.conf to identify when it " "needs to update its internal DNS resolver." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:50 +#: src/config/SSSDConfig/sssdoptions.py:46 msgid "" "SSSD monitors the state of resolv.conf to identify when it needs to update " "its internal DNS resolver. By default, we will attempt to use inotify for " @@ -135,393 +135,400 @@ msgid "" "inotify cannot be used." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:53 +#: src/config/SSSDConfig/sssdoptions.py:49 msgid "Run PAC responder automatically for AD and IPA provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:54 +#: src/config/SSSDConfig/sssdoptions.py:50 msgid "Enable or disable core dumps for all SSSD processes." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:55 +#: src/config/SSSDConfig/sssdoptions.py:51 msgid "Tune passkey verification behavior" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:58 +#: src/config/SSSDConfig/sssdoptions.py:54 msgid "Enumeration cache timeout length (seconds)" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:59 +#: src/config/SSSDConfig/sssdoptions.py:55 msgid "Entry cache background update timeout length (seconds)" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:60 -#: src/config/SSSDConfig/sssdoptions.py:125 +#: src/config/SSSDConfig/sssdoptions.py:56 +#: src/config/SSSDConfig/sssdoptions.py:124 msgid "Negative cache timeout length (seconds)" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:61 +#: src/config/SSSDConfig/sssdoptions.py:57 msgid "Users that SSSD should explicitly ignore" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:62 +#: src/config/SSSDConfig/sssdoptions.py:58 msgid "Groups that SSSD should explicitly ignore" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:63 +#: src/config/SSSDConfig/sssdoptions.py:59 msgid "Should filtered users appear in groups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:64 +#: src/config/SSSDConfig/sssdoptions.py:60 msgid "The value of the password field the NSS provider should return" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:65 +#: src/config/SSSDConfig/sssdoptions.py:61 msgid "Override homedir value from the identity provider with this value" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:66 +#: src/config/SSSDConfig/sssdoptions.py:62 msgid "" "Substitute empty homedir value from the identity provider with this value" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:67 +#: src/config/SSSDConfig/sssdoptions.py:63 msgid "Override shell value from the identity provider with this value" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:68 +#: src/config/SSSDConfig/sssdoptions.py:64 msgid "The list of shells users are allowed to log in with" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:69 +#: src/config/SSSDConfig/sssdoptions.py:65 msgid "" "The list of shells that will be vetoed, and replaced with the fallback shell" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:70 +#: src/config/SSSDConfig/sssdoptions.py:66 msgid "" "If a shell stored in central directory is allowed but not available, use " "this fallback" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:71 +#: src/config/SSSDConfig/sssdoptions.py:67 msgid "Shell to use if the provider does not list one" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:72 +#: src/config/SSSDConfig/sssdoptions.py:68 msgid "How long will be in-memory cache records valid" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:74 +#: src/config/SSSDConfig/sssdoptions.py:70 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for passwd requests" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:76 +#: src/config/SSSDConfig/sssdoptions.py:72 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for group requests" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:78 +#: src/config/SSSDConfig/sssdoptions.py:74 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for initgroups requests" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:79 +#: src/config/SSSDConfig/sssdoptions.py:75 msgid "" "The value of this option will be used in the expansion of the " "override_homedir option if the template contains the format string %H." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:81 +#: src/config/SSSDConfig/sssdoptions.py:77 msgid "" "Specifies time in seconds for which the list of subdomains will be " "considered valid." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:83 +#: src/config/SSSDConfig/sssdoptions.py:79 msgid "" "The entry cache can be set to automatically update entries in the background " "if they are requested beyond a percentage of the entry_cache_timeout value " "for the domain." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:88 +#: src/config/SSSDConfig/sssdoptions.py:84 msgid "How long to allow cached logins between online logins (days)" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:89 +#: src/config/SSSDConfig/sssdoptions.py:85 msgid "How many failed logins attempts are allowed when offline" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:91 +#: src/config/SSSDConfig/sssdoptions.py:87 msgid "" "How long (minutes) to deny login after offline_failed_login_attempts has " "been reached" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:92 +#: src/config/SSSDConfig/sssdoptions.py:88 msgid "What kind of messages are displayed to the user during authentication" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:93 +#: src/config/SSSDConfig/sssdoptions.py:89 msgid "Filter PAM responses sent to the pam_sss" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:94 +#: src/config/SSSDConfig/sssdoptions.py:90 msgid "How many seconds to keep identity information cached for PAM requests" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:95 +#: src/config/SSSDConfig/sssdoptions.py:91 msgid "How many days before password expiration a warning should be displayed" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:96 +#: src/config/SSSDConfig/sssdoptions.py:92 msgid "List of trusted uids or user's name" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:97 +#: src/config/SSSDConfig/sssdoptions.py:93 msgid "List of domains accessible even for untrusted users." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:98 +#: src/config/SSSDConfig/sssdoptions.py:94 msgid "Message printed when user account is expired." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:99 +#: src/config/SSSDConfig/sssdoptions.py:95 msgid "Message printed when user account is locked." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:100 +#: src/config/SSSDConfig/sssdoptions.py:96 msgid "Allow certificate based/Smartcard authentication." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:101 +#: src/config/SSSDConfig/sssdoptions.py:97 msgid "Path to certificate database with PKCS#11 modules." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:102 +#: src/config/SSSDConfig/sssdoptions.py:98 msgid "Tune certificate verification for PAM authentication." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:103 +#: src/config/SSSDConfig/sssdoptions.py:99 msgid "How many seconds will pam_sss wait for p11_child to finish" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:104 +#: src/config/SSSDConfig/sssdoptions.py:100 msgid "Which PAM services are permitted to contact application domains" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:105 +#: src/config/SSSDConfig/sssdoptions.py:101 msgid "Allowed services for using smartcards" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:106 +#: src/config/SSSDConfig/sssdoptions.py:102 msgid "Additional timeout to wait for a card if requested" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:107 +#: src/config/SSSDConfig/sssdoptions.py:103 msgid "" "PKCS#11 URI to restrict the selection of devices for Smartcard authentication" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:108 +#: src/config/SSSDConfig/sssdoptions.py:104 msgid "When shall the PAM responder force an initgroups request" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:109 +#: src/config/SSSDConfig/sssdoptions.py:105 msgid "List of PAM services that are allowed to authenticate with GSSAPI." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:110 +#: src/config/SSSDConfig/sssdoptions.py:106 msgid "Whether to match authenticated UPN with target user" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:111 +#: src/config/SSSDConfig/sssdoptions.py:107 msgid "" "List of pairs : that must be enforced " "for PAM access with GSSAPI authentication" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:113 +#: src/config/SSSDConfig/sssdoptions.py:109 +msgid "" +"List of triples :: that assigns " +"additional information from the Kerberos ticket to an authentication " +"indicator." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:112 msgid "Allow passkey device authentication." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:114 +#: src/config/SSSDConfig/sssdoptions.py:113 msgid "How many seconds will pam_sss wait for passkey_child to finish" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:115 +#: src/config/SSSDConfig/sssdoptions.py:114 msgid "Enable debugging in the libfido2 library" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:116 +#: src/config/SSSDConfig/sssdoptions.py:115 msgid "Enable JSON protocol for authentication methods selection." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:119 +#: src/config/SSSDConfig/sssdoptions.py:118 msgid "Whether to evaluate the time-based attributes in sudo rules" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:120 +#: src/config/SSSDConfig/sssdoptions.py:119 msgid "If true, SSSD will switch back to lower-wins ordering logic" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:121 +#: src/config/SSSDConfig/sssdoptions.py:120 msgid "" "Maximum number of rules that can be refreshed at once. If this is exceeded, " "full refresh is performed." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:128 +#: src/config/SSSDConfig/sssdoptions.py:127 msgid "Whether to hash host names and addresses in the known_hosts file" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:129 +#: src/config/SSSDConfig/sssdoptions.py:128 msgid "" "How many seconds to keep a host in the known_hosts file after its host keys " "were requested" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:131 +#: src/config/SSSDConfig/sssdoptions.py:130 msgid "Path to storage of trusted CA certificates" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:132 +#: src/config/SSSDConfig/sssdoptions.py:131 msgid "Allow to generate ssh-keys from certificates" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:133 +#: src/config/SSSDConfig/sssdoptions.py:132 msgid "" "Use the following matching rules to filter the certificates for ssh-key " "generation" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:137 +#: src/config/SSSDConfig/sssdoptions.py:136 msgid "List of UIDs or user names allowed to access the PAC responder" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:138 +#: src/config/SSSDConfig/sssdoptions.py:137 msgid "How long the PAC data is considered valid" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:139 +#: src/config/SSSDConfig/sssdoptions.py:138 msgid "Validate the PAC" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:142 +#: src/config/SSSDConfig/sssdoptions.py:141 msgid "List of user attributes the InfoPipe is allowed to publish" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:145 +#: src/config/SSSDConfig/sssdoptions.py:144 msgid "" "One of the following strings specifying the scope of session recording: none " "- No users are recorded. some - Users/groups specified by users and groups " "options are recorded. all - All users are recorded." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:148 +#: src/config/SSSDConfig/sssdoptions.py:147 msgid "" "A comma-separated list of users which should have session recording enabled. " "Matches user names as returned by NSS. I.e. after the possible space " "replacement, case changes, etc." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:150 +#: src/config/SSSDConfig/sssdoptions.py:149 msgid "" "A comma-separated list of groups, members of which should have session " "recording enabled. Matches group names as returned by NSS. I.e. after the " "possible space replacement, case changes, etc." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:153 +#: src/config/SSSDConfig/sssdoptions.py:152 msgid "" "A comma-separated list of users to be excluded from recording, only when " "scope=all" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:154 +#: src/config/SSSDConfig/sssdoptions.py:153 msgid "" "A comma-separated list of groups, members of which should be excluded from " "recording, only when scope=all. " msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:158 +#: src/config/SSSDConfig/sssdoptions.py:157 msgid "Identity provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:159 +#: src/config/SSSDConfig/sssdoptions.py:158 msgid "Authentication provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:160 +#: src/config/SSSDConfig/sssdoptions.py:159 msgid "Access control provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:161 +#: src/config/SSSDConfig/sssdoptions.py:160 msgid "Password change provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:162 +#: src/config/SSSDConfig/sssdoptions.py:161 msgid "SUDO provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:163 +#: src/config/SSSDConfig/sssdoptions.py:162 msgid "Autofs provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:164 +#: src/config/SSSDConfig/sssdoptions.py:163 msgid "Host identity provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:165 +#: src/config/SSSDConfig/sssdoptions.py:164 msgid "SELinux provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:166 +#: src/config/SSSDConfig/sssdoptions.py:165 msgid "Session management provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:167 +#: src/config/SSSDConfig/sssdoptions.py:166 msgid "Resolver provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:170 +#: src/config/SSSDConfig/sssdoptions.py:169 msgid "Whether the domain is usable by the OS or by applications" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:171 +#: src/config/SSSDConfig/sssdoptions.py:170 msgid "Enable or disable the domain" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:172 +#: src/config/SSSDConfig/sssdoptions.py:171 msgid "Minimum user ID" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:173 +#: src/config/SSSDConfig/sssdoptions.py:172 msgid "Maximum user ID" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:174 +#: src/config/SSSDConfig/sssdoptions.py:173 msgid "Enable enumerating all users/groups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:175 +#: src/config/SSSDConfig/sssdoptions.py:174 msgid "Cache credentials for offline login" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:176 +#: src/config/SSSDConfig/sssdoptions.py:175 msgid "Display users/groups in fully-qualified form" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:177 +#: src/config/SSSDConfig/sssdoptions.py:176 msgid "Don't include group members in group lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:178 +#: src/config/SSSDConfig/sssdoptions.py:177 #: src/config/SSSDConfig/sssdoptions.py:190 #: src/config/SSSDConfig/sssdoptions.py:191 #: src/config/SSSDConfig/sssdoptions.py:192 @@ -532,48 +539,52 @@ msgstr "" msgid "Entry cache timeout length (seconds)" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:179 +#: src/config/SSSDConfig/sssdoptions.py:178 msgid "" "Restrict or prefer a specific address family when performing DNS lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:180 +#: src/config/SSSDConfig/sssdoptions.py:179 msgid "How long to keep cached entries after last successful login (days)" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:181 +#: src/config/SSSDConfig/sssdoptions.py:180 msgid "" "How long should SSSD talk to single DNS server before trying next server " "(miliseconds)" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:183 +#: src/config/SSSDConfig/sssdoptions.py:182 msgid "How long should keep trying to resolve single DNS query (seconds)" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:184 +#: src/config/SSSDConfig/sssdoptions.py:183 msgid "How long to wait for replies from DNS when resolving servers (seconds)" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:185 +#: src/config/SSSDConfig/sssdoptions.py:184 msgid "The domain part of service discovery DNS query" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:186 +#: src/config/SSSDConfig/sssdoptions.py:185 msgid "" "Specifies the interval, in seconds, that SSSD waits before attempting to " "reconnect to the primary server after a successful connection to the backup " "server" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:188 +#: src/config/SSSDConfig/sssdoptions.py:187 msgid "Override GID value from the identity provider with this value" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:189 +#: src/config/SSSDConfig/sssdoptions.py:188 msgid "Treat usernames as case sensitive" msgstr "" +#: src/config/SSSDConfig/sssdoptions.py:189 +msgid "Lookups by ID are expensive or do not work at all" +msgstr "" + #: src/config/SSSDConfig/sssdoptions.py:197 msgid "How often should expired entries be refreshed in background" msgstr "" @@ -793,7 +804,7 @@ msgid "Search base for SUBID ranges" msgstr "" #: src/config/SSSDConfig/sssdoptions.py:259 -#: src/config/SSSDConfig/sssdoptions.py:506 +#: src/config/SSSDConfig/sssdoptions.py:512 msgid "Which rules should be used to evaluate access control" msgstr "" @@ -935,7 +946,7 @@ msgid "Enable DNS sites - location based service discovery" msgstr "" #: src/config/SSSDConfig/sssdoptions.py:301 -#: src/config/SSSDConfig/sssdoptions.py:504 +#: src/config/SSSDConfig/sssdoptions.py:510 msgid "LDAP filter to determine access privileges" msgstr "" @@ -1355,7 +1366,7 @@ msgid "UUID attribute" msgstr "" #: src/config/SSSDConfig/sssdoptions.py:423 -#: src/config/SSSDConfig/sssdoptions.py:464 +#: src/config/SSSDConfig/sssdoptions.py:470 msgid "objectSID attribute" msgstr "" @@ -1479,385 +1490,409 @@ msgstr "" msgid "A list of extra attributes to download along with the user entry" msgstr "" +#: src/config/SSSDConfig/sssdoptions.py:456 +msgid "The object class of an subid entry in LDAP." +msgstr "" + #: src/config/SSSDConfig/sssdoptions.py:457 -msgid "Base DN for group lookups" +msgid "Subordinate user ID count attribute" msgstr "" #: src/config/SSSDConfig/sssdoptions.py:458 -msgid "Objectclass for groups" +msgid "Subordinate group ID count attribute" msgstr "" #: src/config/SSSDConfig/sssdoptions.py:459 -msgid "Group name" +msgid "User ID range start value attribute" msgstr "" #: src/config/SSSDConfig/sssdoptions.py:460 -msgid "Group password" +msgid "Group ID range start value attribute" msgstr "" #: src/config/SSSDConfig/sssdoptions.py:461 +msgid "Owner of an entry" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:463 +msgid "Base DN for group lookups" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:464 +msgid "Objectclass for groups" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:465 +msgid "Group name" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:466 +msgid "Group password" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:467 msgid "GID attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:462 +#: src/config/SSSDConfig/sssdoptions.py:468 msgid "Group member attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:463 +#: src/config/SSSDConfig/sssdoptions.py:469 msgid "Group UUID attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:465 +#: src/config/SSSDConfig/sssdoptions.py:471 msgid "Modification time attribute for groups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:466 +#: src/config/SSSDConfig/sssdoptions.py:472 msgid "Type of the group and other flags" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:467 +#: src/config/SSSDConfig/sssdoptions.py:473 msgid "The LDAP group external member attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:468 +#: src/config/SSSDConfig/sssdoptions.py:474 msgid "Maximum nesting level SSSD will follow" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:469 +#: src/config/SSSDConfig/sssdoptions.py:475 msgid "Filter for group lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:470 +#: src/config/SSSDConfig/sssdoptions.py:476 msgid "Scope of group lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:472 +#: src/config/SSSDConfig/sssdoptions.py:478 msgid "Base DN for netgroup lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:473 +#: src/config/SSSDConfig/sssdoptions.py:479 msgid "Objectclass for netgroups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:474 +#: src/config/SSSDConfig/sssdoptions.py:480 msgid "Netgroup name" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:475 +#: src/config/SSSDConfig/sssdoptions.py:481 msgid "Netgroups members attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:476 +#: src/config/SSSDConfig/sssdoptions.py:482 msgid "Netgroup triple attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:477 +#: src/config/SSSDConfig/sssdoptions.py:483 msgid "Modification time attribute for netgroups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:479 +#: src/config/SSSDConfig/sssdoptions.py:485 msgid "Base DN for service lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:480 +#: src/config/SSSDConfig/sssdoptions.py:486 msgid "Objectclass for services" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:481 +#: src/config/SSSDConfig/sssdoptions.py:487 msgid "Service name attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:482 +#: src/config/SSSDConfig/sssdoptions.py:488 msgid "Service port attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:483 +#: src/config/SSSDConfig/sssdoptions.py:489 msgid "Service protocol attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:485 +#: src/config/SSSDConfig/sssdoptions.py:491 msgid "Lower bound for ID-mapping" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:486 +#: src/config/SSSDConfig/sssdoptions.py:492 msgid "Upper bound for ID-mapping" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:487 +#: src/config/SSSDConfig/sssdoptions.py:493 msgid "Number of IDs for each slice when ID-mapping" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:488 +#: src/config/SSSDConfig/sssdoptions.py:494 msgid "Use autorid-compatible algorithm for ID-mapping" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:489 +#: src/config/SSSDConfig/sssdoptions.py:495 msgid "Name of the default domain for ID-mapping" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:490 +#: src/config/SSSDConfig/sssdoptions.py:496 msgid "SID of the default domain for ID-mapping" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:491 +#: src/config/SSSDConfig/sssdoptions.py:497 msgid "Number of secondary slices" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:493 +#: src/config/SSSDConfig/sssdoptions.py:499 msgid "Whether to use Token-Groups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:494 +#: src/config/SSSDConfig/sssdoptions.py:500 msgid "Set lower boundary for allowed IDs from the LDAP server" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:495 +#: src/config/SSSDConfig/sssdoptions.py:501 msgid "Set upper boundary for allowed IDs from the LDAP server" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:496 +#: src/config/SSSDConfig/sssdoptions.py:502 msgid "DN for ppolicy queries" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:497 +#: src/config/SSSDConfig/sssdoptions.py:503 msgid "How many maximum entries to fetch during a wildcard request" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:498 +#: src/config/SSSDConfig/sssdoptions.py:504 msgid "Set libldap debug level" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:501 +#: src/config/SSSDConfig/sssdoptions.py:507 msgid "Policy to evaluate the password expiration" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:505 +#: src/config/SSSDConfig/sssdoptions.py:511 msgid "Which attributes shall be used to evaluate if an account is expired" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:509 +#: src/config/SSSDConfig/sssdoptions.py:515 msgid "URI of an LDAP server where password changes are allowed" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:510 +#: src/config/SSSDConfig/sssdoptions.py:516 msgid "URI of a backup LDAP server where password changes are allowed" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:511 +#: src/config/SSSDConfig/sssdoptions.py:517 msgid "DNS service name for LDAP password change server" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:512 +#: src/config/SSSDConfig/sssdoptions.py:518 msgid "" "Whether to update the ldap_user_shadow_last_change attribute after a " "password change" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:516 +#: src/config/SSSDConfig/sssdoptions.py:522 msgid "Base DN for sudo rules lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:517 +#: src/config/SSSDConfig/sssdoptions.py:523 msgid "Automatic full refresh period" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:518 +#: src/config/SSSDConfig/sssdoptions.py:524 msgid "Automatic smart refresh period" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:519 +#: src/config/SSSDConfig/sssdoptions.py:525 msgid "Smart and full refresh random offset" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:520 +#: src/config/SSSDConfig/sssdoptions.py:526 msgid "Whether to filter rules by hostname, IP addresses and network" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:521 +#: src/config/SSSDConfig/sssdoptions.py:527 msgid "" "Hostnames and/or fully qualified domain names of this machine to filter sudo " "rules" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:522 +#: src/config/SSSDConfig/sssdoptions.py:528 msgid "IPv4 or IPv6 addresses or network of this machine to filter sudo rules" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:523 +#: src/config/SSSDConfig/sssdoptions.py:529 msgid "Whether to include rules that contains netgroup in host attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:524 +#: src/config/SSSDConfig/sssdoptions.py:530 msgid "" "Whether to include rules that contains regular expression in host attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:525 +#: src/config/SSSDConfig/sssdoptions.py:531 msgid "Object class for sudo rules" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:526 +#: src/config/SSSDConfig/sssdoptions.py:532 msgid "Name of attribute that is used as object class for sudo rules" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:527 +#: src/config/SSSDConfig/sssdoptions.py:533 msgid "Sudo rule name" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:528 +#: src/config/SSSDConfig/sssdoptions.py:534 msgid "Sudo rule command attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:529 +#: src/config/SSSDConfig/sssdoptions.py:535 msgid "Sudo rule host attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:530 +#: src/config/SSSDConfig/sssdoptions.py:536 msgid "Sudo rule user attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:531 +#: src/config/SSSDConfig/sssdoptions.py:537 msgid "Sudo rule option attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:532 +#: src/config/SSSDConfig/sssdoptions.py:538 msgid "Sudo rule runas attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:533 +#: src/config/SSSDConfig/sssdoptions.py:539 msgid "Sudo rule runasuser attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:534 +#: src/config/SSSDConfig/sssdoptions.py:540 msgid "Sudo rule runasgroup attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:535 +#: src/config/SSSDConfig/sssdoptions.py:541 msgid "Sudo rule notbefore attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:536 +#: src/config/SSSDConfig/sssdoptions.py:542 msgid "Sudo rule notafter attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:537 +#: src/config/SSSDConfig/sssdoptions.py:543 msgid "Sudo rule order attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:540 +#: src/config/SSSDConfig/sssdoptions.py:546 msgid "Object class for automounter maps" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:541 +#: src/config/SSSDConfig/sssdoptions.py:547 msgid "Automounter map name attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:542 +#: src/config/SSSDConfig/sssdoptions.py:548 msgid "Object class for automounter map entries" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:543 +#: src/config/SSSDConfig/sssdoptions.py:549 msgid "Automounter map entry key attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:544 +#: src/config/SSSDConfig/sssdoptions.py:550 msgid "Automounter map entry value attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:545 +#: src/config/SSSDConfig/sssdoptions.py:551 msgid "Base DN for automounter map lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:546 +#: src/config/SSSDConfig/sssdoptions.py:552 msgid "The name of the automount master map in LDAP." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:549 +#: src/config/SSSDConfig/sssdoptions.py:555 msgid "Base DN for IP hosts lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:550 +#: src/config/SSSDConfig/sssdoptions.py:556 msgid "Object class for IP hosts" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:551 +#: src/config/SSSDConfig/sssdoptions.py:557 msgid "IP host name attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:552 +#: src/config/SSSDConfig/sssdoptions.py:558 msgid "IP host number (address) attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:553 +#: src/config/SSSDConfig/sssdoptions.py:559 msgid "IP host entryUSN attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:554 +#: src/config/SSSDConfig/sssdoptions.py:560 msgid "Base DN for IP networks lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:555 +#: src/config/SSSDConfig/sssdoptions.py:561 msgid "Object class for IP networks" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:556 +#: src/config/SSSDConfig/sssdoptions.py:562 msgid "IP network name attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:557 +#: src/config/SSSDConfig/sssdoptions.py:563 msgid "IP network number (address) attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:558 +#: src/config/SSSDConfig/sssdoptions.py:564 msgid "IP network entryUSN attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:561 +#: src/config/SSSDConfig/sssdoptions.py:567 msgid "Comma separated list of allowed users" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:562 +#: src/config/SSSDConfig/sssdoptions.py:568 msgid "Comma separated list of prohibited users" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:563 +#: src/config/SSSDConfig/sssdoptions.py:569 msgid "" "Comma separated list of groups that are allowed to log in. This applies only " "to groups within this SSSD domain. Local groups are not evaluated." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:565 +#: src/config/SSSDConfig/sssdoptions.py:571 msgid "" "Comma separated list of groups that are explicitly denied access. This " "applies only to groups within this SSSD domain. Local groups are not " "evaluated." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:569 +#: src/config/SSSDConfig/sssdoptions.py:575 msgid "The number of preforked proxy children." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:572 +#: src/config/SSSDConfig/sssdoptions.py:578 msgid "The name of the NSS library to use" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:573 +#: src/config/SSSDConfig/sssdoptions.py:579 msgid "The name of the NSS library to use for hosts and networks lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:574 +#: src/config/SSSDConfig/sssdoptions.py:580 msgid "Whether to look up canonical group name from cache if possible" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:577 +#: src/config/SSSDConfig/sssdoptions.py:583 msgid "PAM stack to use" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:580 +#: src/config/SSSDConfig/sssdoptions.py:586 msgid "Path of passwd file sources." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:581 +#: src/config/SSSDConfig/sssdoptions.py:587 msgid "Path of group file sources." msgstr "" @@ -1885,225 +1920,233 @@ msgstr "" msgid "Option -i|--interactive is not allowed together with -D|--daemon\n" msgstr "" -#: src/monitor/monitor.c:1836 +#: src/monitor/monitor.c:1838 msgid "Failed to get initial capabilities\n" msgstr "" -#: src/monitor/monitor.c:1847 +#: src/monitor/monitor.c:1849 msgid "Non-root service user support isn't built. Can't run under %" msgstr "" -#: src/monitor/monitor.c:1864 +#: src/monitor/monitor.c:1866 #, c-format msgid "Can't read config: '%s'\n" msgstr "" -#: src/monitor/monitor.c:1876 +#: src/monitor/monitor.c:1878 #, c-format -msgid "Failed to boostrap SSSD 'monitor' process: %s" +msgid "Failed to bootstrap SSSD 'monitor' process: %s" msgstr "" -#: src/monitor/monitor.c:1971 +#: src/monitor/monitor.c:1973 msgid "Out of memory\n" msgstr "" -#: src/providers/krb5/krb5_child.c:4221 +#: src/providers/krb5/krb5_child.c:4316 msgid "Use anonymous PKINIT to request FAST armor ticket" msgstr "" -#: src/providers/krb5/krb5_child.c:4223 +#: src/providers/krb5/krb5_child.c:4318 msgid "Kerberos realm to use" msgstr "" -#: src/providers/krb5/krb5_child.c:4225 +#: src/providers/krb5/krb5_child.c:4320 msgid "Requested lifetime of the ticket" msgstr "" -#: src/providers/krb5/krb5_child.c:4227 +#: src/providers/krb5/krb5_child.c:4322 msgid "Requested renewable lifetime of the ticket" msgstr "" -#: src/providers/krb5/krb5_child.c:4229 +#: src/providers/krb5/krb5_child.c:4324 msgid "FAST options ('never', 'try', 'demand')" msgstr "" -#: src/providers/krb5/krb5_child.c:4232 +#: src/providers/krb5/krb5_child.c:4327 msgid "Specifies the server principal to use for FAST" msgstr "" -#: src/providers/krb5/krb5_child.c:4234 +#: src/providers/krb5/krb5_child.c:4329 msgid "Requests canonicalization of the principal name" msgstr "" -#: src/providers/krb5/krb5_child.c:4236 +#: src/providers/krb5/krb5_child.c:4331 msgid "Use custom version of krb5_get_init_creds_password" msgstr "" -#: src/providers/krb5/krb5_child.c:4238 +#: src/providers/krb5/krb5_child.c:4333 msgid "Check PAC flags" msgstr "" -#: src/providers/data_provider_be.c:790 +#: src/providers/krb5/krb5_child.c:4335 +msgid "Set environment variable (KEY=VALUE)" +msgstr "" + +#: src/providers/data_provider_be.c:786 msgid "Domain of the information provider (mandatory)" msgstr "" -#: src/sss_client/common.c:1165 +#: src/sss_client/common.c:1208 msgid "Socket has wrong ownership or permissions." msgstr "" -#: src/sss_client/common.c:1168 +#: src/sss_client/common.c:1211 msgid "Unexpected format of the server credential message." msgstr "" -#: src/sss_client/common.c:1171 +#: src/sss_client/common.c:1214 msgid "SSSD is not run by trusted user." msgstr "" -#: src/sss_client/common.c:1174 +#: src/sss_client/common.c:1217 msgid "SSSD socket does not exist." msgstr "" -#: src/sss_client/common.c:1177 +#: src/sss_client/common.c:1220 msgid "Cannot get stat of SSSD socket." msgstr "" -#: src/sss_client/common.c:1182 +#: src/sss_client/common.c:1225 msgid "An error occurred, but no description can be found." msgstr "" -#: src/sss_client/common.c:1188 +#: src/sss_client/common.c:1231 msgid "Unexpected error while looking for an error description" msgstr "" -#: src/sss_client/pam_sss.c:74 +#: src/sss_client/pam_sss.c:135 msgid "Permission denied. " msgstr "" -#: src/sss_client/pam_sss.c:75 src/sss_client/pam_sss.c:843 -#: src/sss_client/pam_sss.c:854 +#: src/sss_client/pam_sss.c:136 src/sss_client/pam_sss.c:921 +#: src/sss_client/pam_sss.c:932 msgid "Server message: " msgstr "" -#: src/sss_client/pam_sss.c:76 +#: src/sss_client/pam_sss.c:137 msgid "" "Kerberos TGT will not be granted upon login, user experience will be " "affected." msgstr "" -#: src/sss_client/pam_sss.c:77 +#: src/sss_client/pam_sss.c:138 msgid "Enter PIN:" msgstr "" -#: src/sss_client/pam_sss.c:320 +#: src/sss_client/pam_sss.c:385 msgid "Passwords do not match" msgstr "" -#: src/sss_client/pam_sss.c:508 +#: src/sss_client/pam_sss.c:584 msgid "Password reset by root is not supported." msgstr "" -#: src/sss_client/pam_sss.c:549 +#: src/sss_client/pam_sss.c:625 msgid "Authenticated with cached credentials" msgstr "" -#: src/sss_client/pam_sss.c:550 +#: src/sss_client/pam_sss.c:626 msgid ", your cached password will expire at: " msgstr "" -#: src/sss_client/pam_sss.c:580 +#: src/sss_client/pam_sss.c:656 #, c-format msgid "Your password has expired. You have %1$d grace login(s) remaining." msgstr "" -#: src/sss_client/pam_sss.c:630 +#: src/sss_client/pam_sss.c:706 #, c-format msgid "Your password will expire in %1$d %2$s." msgstr "" -#: src/sss_client/pam_sss.c:633 +#: src/sss_client/pam_sss.c:709 #, c-format msgid "Your password has expired." msgstr "" -#: src/sss_client/pam_sss.c:684 +#: src/sss_client/pam_sss.c:760 msgid "Authentication is denied until: " msgstr "" -#: src/sss_client/pam_sss.c:705 +#: src/sss_client/pam_sss.c:781 msgid "System is offline, password change not possible" msgstr "" -#: src/sss_client/pam_sss.c:720 +#: src/sss_client/pam_sss.c:796 msgid "" "After changing the OTP password, you need to log out and back in order to " "acquire a ticket" msgstr "" -#: src/sss_client/pam_sss.c:735 +#: src/sss_client/pam_sss.c:813 msgid "PIN locked" msgstr "" -#: src/sss_client/pam_sss.c:750 +#: src/sss_client/pam_sss.c:828 msgid "" "No Kerberos TGT granted as the server does not support this method. Your " "single-sign on(SSO) experience will be affected." msgstr "" -#: src/sss_client/pam_sss.c:840 src/sss_client/pam_sss.c:853 +#: src/sss_client/pam_sss.c:918 src/sss_client/pam_sss.c:931 msgid "Password change failed. " msgstr "" -#: src/sss_client/pam_sss.c:1859 +#: src/sss_client/pam_sss.c:2028 #, c-format -msgid "Authenticate at %1$s and press ENTER." +msgid "Authenticate at \"%1$s\"." msgstr "" -#: src/sss_client/pam_sss.c:1862 +#: src/sss_client/pam_sss.c:2031 #, c-format -msgid "Authenticate with PIN %1$s at %2$s and press ENTER." +msgid "Authenticate with PIN \"%1$s\" at \"%2$s\"." msgstr "" -#: src/sss_client/pam_sss.c:2281 +#: src/sss_client/pam_sss.c:2470 msgid "Please (re)insert (different) Smartcard" msgstr "" -#: src/sss_client/pam_sss.c:2482 +#: src/sss_client/pam_sss.c:2700 msgid "New Password: " msgstr "" -#: src/sss_client/pam_sss.c:2483 +#: src/sss_client/pam_sss.c:2701 msgid "Reenter new Password: " msgstr "" -#: src/sss_client/pam_sss.c:2676 src/sss_client/pam_sss.c:2679 +#: src/sss_client/pam_sss.c:2890 +msgid "Press ENTER to continue." +msgstr "" + +#: src/sss_client/pam_sss.c:2913 src/sss_client/pam_sss.c:2916 msgid "First Factor: " msgstr "" -#: src/sss_client/pam_sss.c:2677 src/sss_client/pam_sss.c:2851 +#: src/sss_client/pam_sss.c:2914 src/sss_client/pam_sss.c:3088 msgid "Second Factor (optional): " msgstr "" -#: src/sss_client/pam_sss.c:2680 src/sss_client/pam_sss.c:2855 +#: src/sss_client/pam_sss.c:2917 src/sss_client/pam_sss.c:3092 msgid "Second Factor: " msgstr "" -#: src/sss_client/pam_sss.c:2684 +#: src/sss_client/pam_sss.c:2921 msgid "Insert your passkey device, then press ENTER." msgstr "" -#: src/sss_client/pam_sss.c:2688 src/sss_client/pam_sss.c:2696 +#: src/sss_client/pam_sss.c:2925 src/sss_client/pam_sss.c:2933 msgid "Password: " msgstr "" -#: src/sss_client/pam_sss.c:2850 src/sss_client/pam_sss.c:2854 +#: src/sss_client/pam_sss.c:3087 src/sss_client/pam_sss.c:3091 msgid "First Factor (Current Password): " msgstr "" -#: src/sss_client/pam_sss.c:2874 +#: src/sss_client/pam_sss.c:3111 msgid "Current Password: " msgstr "" -#: src/sss_client/pam_sss.c:3248 +#: src/sss_client/pam_sss.c:3485 msgid "Password expired. Change your password now." msgstr "" @@ -2535,9 +2578,9 @@ msgstr "" #: src/tools/sssctl/sssctl_cache.c:835 src/tools/sssctl/sssctl_cache.c:918 #: src/tools/sssctl/sssctl_cache.c:950 src/tools/sssctl/sssctl_cache.c:956 #: src/tools/sssctl/sssctl_cache.c:1010 src/tools/sssctl/sssctl_cache.c:1034 -#: src/tools/sssctl/sssctl_cache.c:1085 src/tools/sssctl/sssctl_cache.c:1194 -#: src/tools/sssctl/sssctl_cache.c:1229 src/tools/sssctl/sssctl_cache.c:1235 -#: src/tools/sssctl/sssctl_cache.c:1244 +#: src/tools/sssctl/sssctl_cache.c:1085 src/tools/sssctl/sssctl_cache.c:1195 +#: src/tools/sssctl/sssctl_cache.c:1230 src/tools/sssctl/sssctl_cache.c:1236 +#: src/tools/sssctl/sssctl_cache.c:1245 msgid "talloc failed\n" msgstr "" @@ -2611,25 +2654,25 @@ msgstr "" msgid "Unable to remove downloaded GPO files: %s\n" msgstr "" -#: src/tools/sssctl/sssctl_cache.c:1165 +#: src/tools/sssctl/sssctl_cache.c:1166 #, c-format msgid "Failed to fetch cache entry: %s\n" msgstr "" -#: src/tools/sssctl/sssctl_cache.c:1170 +#: src/tools/sssctl/sssctl_cache.c:1171 msgid "Could not determine object domain\n" msgstr "" -#: src/tools/sssctl/sssctl_cache.c:1200 +#: src/tools/sssctl/sssctl_cache.c:1201 msgid "Could not find GUID attribute in GPO entry\n" msgstr "" -#: src/tools/sssctl/sssctl_cache.c:1206 +#: src/tools/sssctl/sssctl_cache.c:1207 #, c-format msgid "Failed to delete GPO: %s\n" msgstr "" -#: src/tools/sssctl/sssctl_cache.c:1210 +#: src/tools/sssctl/sssctl_cache.c:1211 #, c-format msgid "%s removed from cache\n" msgstr "" @@ -2717,39 +2760,39 @@ msgid "" "\"/my/path/sssd.conf\", the snippet dir \"/my/path/conf.d\" is used)" msgstr "" -#: src/tools/sssctl/sssctl_config.c:114 +#: src/tools/sssctl/sssctl_config.c:126 #, c-format msgid "File %1$s does not exist.\n" msgstr "" -#: src/tools/sssctl/sssctl_config.c:115 +#: src/tools/sssctl/sssctl_config.c:127 msgid "There is no configuration.\n" msgstr "" -#: src/tools/sssctl/sssctl_config.c:120 +#: src/tools/sssctl/sssctl_config.c:132 #, c-format msgid "Configuration validation failed: %s\n" msgstr "" -#: src/tools/sssctl/sssctl_config.c:121 +#: src/tools/sssctl/sssctl_config.c:133 msgid "Run with high debug level to see details.\n" msgstr "" -#: src/tools/sssctl/sssctl_config.c:130 -msgid "Failed to run validators" +#: src/tools/sssctl/sssctl_config.c:142 +msgid "Failed to run validators\n" msgstr "" -#: src/tools/sssctl/sssctl_config.c:134 +#: src/tools/sssctl/sssctl_config.c:146 #, c-format msgid "Issues identified by validators: %zu\n" msgstr "" -#: src/tools/sssctl/sssctl_config.c:145 +#: src/tools/sssctl/sssctl_config.c:157 #, c-format msgid "Messages generated during configuration merging: %zu\n" msgstr "" -#: src/tools/sssctl/sssctl_config.c:158 +#: src/tools/sssctl/sssctl_config.c:170 #, c-format msgid "Used configuration snippet files: %zu\n" msgstr "" diff --git a/po/ca.po b/po/ca.po index 793ffe65ab0..98fcd26b553 100644 --- a/po/ca.po +++ b/po/ca.po @@ -14,8 +14,8 @@ msgid "" msgstr "" "Project-Id-Version: PACKAGE VERSION\n" "Report-Msgid-Bugs-To: sssd-devel@lists.fedorahosted.org\n" -"POT-Creation-Date: 2026-01-14 14:57+0000\n" -"PO-Revision-Date: 2026-04-23 17:02+0000\n" +"POT-Creation-Date: 2026-10-02 15:57+0000\n" +"PO-Revision-Date: 2026-10-05 16:36+0000\n" "Last-Translator: Anonymous \n" "Language-Team: Catalan \n" @@ -24,53 +24,53 @@ msgstr "" "Content-Type: text/plain; charset=UTF-8\n" "Content-Transfer-Encoding: 8bit\n" "Plural-Forms: nplurals=2; plural=n != 1;\n" -"X-Generator: Weblate 5.17\n" +"X-Generator: Weblate 2026.10\n" -#: src/config/SSSDConfig/sssdoptions.py:20 -#: src/config/SSSDConfig/sssdoptions.py:21 +#: src/config/SSSDConfig/sssdoptions.py:16 +#: src/config/SSSDConfig/sssdoptions.py:17 msgid "Set the verbosity of the debug logging" msgstr "Estableix la verbositat del registre de depuració" -#: src/config/SSSDConfig/sssdoptions.py:22 +#: src/config/SSSDConfig/sssdoptions.py:18 msgid "Include timestamps in debug logs" msgstr "Inclou les marques temporals als registres de depuració" -#: src/config/SSSDConfig/sssdoptions.py:23 +#: src/config/SSSDConfig/sssdoptions.py:19 msgid "Include microseconds in timestamps in debug logs" msgstr "" "Inclou els mil·lisegons a les marques temporals als registres de depuració" -#: src/config/SSSDConfig/sssdoptions.py:24 +#: src/config/SSSDConfig/sssdoptions.py:20 msgid "Enable/disable debug backtrace" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:25 +#: src/config/SSSDConfig/sssdoptions.py:21 msgid "Watchdog timeout before restarting service" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:26 +#: src/config/SSSDConfig/sssdoptions.py:22 msgid "Command to start service" msgstr "L'ordre per iniciar el servei" -#: src/config/SSSDConfig/sssdoptions.py:27 +#: src/config/SSSDConfig/sssdoptions.py:23 msgid "The number of file descriptors that may be opened by this responder" msgstr "" "El nombre de descriptors de fitxers que poden estar oberts per aquest " "contestador" -#: src/config/SSSDConfig/sssdoptions.py:28 +#: src/config/SSSDConfig/sssdoptions.py:24 msgid "Idle time before automatic disconnection of a client" msgstr "El temps d'inactivitat abans de la desconnexió automàtica d'un client" -#: src/config/SSSDConfig/sssdoptions.py:29 +#: src/config/SSSDConfig/sssdoptions.py:25 msgid "Idle time before automatic shutdown of the responder" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:30 +#: src/config/SSSDConfig/sssdoptions.py:26 msgid "Always query all the caches before querying the Data Providers" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:31 +#: src/config/SSSDConfig/sssdoptions.py:27 msgid "" "When SSSD switches to offline mode the amount of time before it tries to go " "back online will increase based upon the time spent disconnected. This value " @@ -78,23 +78,23 @@ msgid "" "random_offset." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:36 +#: src/config/SSSDConfig/sssdoptions.py:32 msgid "SSSD Services to start" msgstr "Els serveis del SSSD a iniciar" -#: src/config/SSSDConfig/sssdoptions.py:37 +#: src/config/SSSDConfig/sssdoptions.py:33 msgid "SSSD Domains to start" msgstr "Els dominis del SSSD a iniciar" -#: src/config/SSSDConfig/sssdoptions.py:38 +#: src/config/SSSDConfig/sssdoptions.py:34 msgid "Regex to parse username and domain" msgstr "L'expressió regular per analitzar el nom d'usuari i el domini" -#: src/config/SSSDConfig/sssdoptions.py:39 +#: src/config/SSSDConfig/sssdoptions.py:35 msgid "Printf-compatible format for displaying fully-qualified names" msgstr "Format compatible amb printf per mostrar els FQN" -#: src/config/SSSDConfig/sssdoptions.py:40 +#: src/config/SSSDConfig/sssdoptions.py:36 msgid "" "Directory on the filesystem where SSSD should store Kerberos replay cache " "files." @@ -102,43 +102,43 @@ msgstr "" "El directori del sistema de fitxers on el SSSD ha d'emmagatzemar els fitxers " "de la memòria cau de repetició de Kerberos." -#: src/config/SSSDConfig/sssdoptions.py:41 +#: src/config/SSSDConfig/sssdoptions.py:37 msgid "Domain to add to names without a domain component." msgstr "El domini per afegir als noms sense un component de domini." -#: src/config/SSSDConfig/sssdoptions.py:42 +#: src/config/SSSDConfig/sssdoptions.py:38 msgid "The user to drop privileges to" msgstr "L'usuari a qui se li disminueixen els permisos" -#: src/config/SSSDConfig/sssdoptions.py:43 +#: src/config/SSSDConfig/sssdoptions.py:39 msgid "Tune certificate verification" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:44 +#: src/config/SSSDConfig/sssdoptions.py:40 msgid "All spaces in group or user names will be replaced with this character" msgstr "" "Tots els espais, als noms dels grups o dels usuaris, se substituiran amb " "aquest caràcter" -#: src/config/SSSDConfig/sssdoptions.py:45 +#: src/config/SSSDConfig/sssdoptions.py:41 msgid "Tune sssd to honor or ignore netlink state changes" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:46 +#: src/config/SSSDConfig/sssdoptions.py:42 msgid "Enable or disable the implicit files domain" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:47 +#: src/config/SSSDConfig/sssdoptions.py:43 msgid "A specific order of the domains to be looked up" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:48 +#: src/config/SSSDConfig/sssdoptions.py:44 msgid "" "Controls if SSSD should monitor the state of resolv.conf to identify when it " "needs to update its internal DNS resolver." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:50 +#: src/config/SSSDConfig/sssdoptions.py:46 msgid "" "SSSD monitors the state of resolv.conf to identify when it needs to update " "its internal DNS resolver. By default, we will attempt to use inotify for " @@ -146,82 +146,83 @@ msgid "" "inotify cannot be used." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:53 +#: src/config/SSSDConfig/sssdoptions.py:49 msgid "Run PAC responder automatically for AD and IPA provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:54 +#: src/config/SSSDConfig/sssdoptions.py:50 msgid "Enable or disable core dumps for all SSSD processes." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:55 +#: src/config/SSSDConfig/sssdoptions.py:51 msgid "Tune passkey verification behavior" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:58 +#: src/config/SSSDConfig/sssdoptions.py:54 msgid "Enumeration cache timeout length (seconds)" msgstr "" "Període de temps per a l'expiració de la memòria cau de les enumeracions (en " "segons)" -#: src/config/SSSDConfig/sssdoptions.py:59 +#: src/config/SSSDConfig/sssdoptions.py:55 msgid "Entry cache background update timeout length (seconds)" msgstr "" "Període de temps per a l'expiració de l'actualització en rerefons de les " "entrades de la memòria cau (en segons)" -#: src/config/SSSDConfig/sssdoptions.py:60 -#: src/config/SSSDConfig/sssdoptions.py:125 +#: src/config/SSSDConfig/sssdoptions.py:56 +#: src/config/SSSDConfig/sssdoptions.py:124 msgid "Negative cache timeout length (seconds)" msgstr "" "Període de temps per a l'expiració de la memòria cau negativa (en segons)" -#: src/config/SSSDConfig/sssdoptions.py:61 +#: src/config/SSSDConfig/sssdoptions.py:57 msgid "Users that SSSD should explicitly ignore" msgstr "Els usuaris que l'SSSD hauria d'ignorar explícitament" -#: src/config/SSSDConfig/sssdoptions.py:62 +#: src/config/SSSDConfig/sssdoptions.py:58 msgid "Groups that SSSD should explicitly ignore" msgstr "Els grups que l'SSSD hauria d'ignorar explícitament" -#: src/config/SSSDConfig/sssdoptions.py:63 +#: src/config/SSSDConfig/sssdoptions.py:59 msgid "Should filtered users appear in groups" msgstr "Si els usuaris filtrats han d'aparèixer als grups" -#: src/config/SSSDConfig/sssdoptions.py:64 +#: src/config/SSSDConfig/sssdoptions.py:60 msgid "The value of the password field the NSS provider should return" -msgstr "El valor del camp de la contrasenya que ha de retornar el proveïdor NSS" +msgstr "" +"El valor del camp de la contrasenya que ha de retornar el proveïdor NSS" -#: src/config/SSSDConfig/sssdoptions.py:65 +#: src/config/SSSDConfig/sssdoptions.py:61 msgid "Override homedir value from the identity provider with this value" msgstr "" "Substitueix el valor de homedir del proveïdor d'identitat amb aquest valor" -#: src/config/SSSDConfig/sssdoptions.py:66 +#: src/config/SSSDConfig/sssdoptions.py:62 msgid "" "Substitute empty homedir value from the identity provider with this value" msgstr "" "Substitueix el valor buit de homedir del proveïdor d'identitat amb aquest " "valor" -#: src/config/SSSDConfig/sssdoptions.py:67 +#: src/config/SSSDConfig/sssdoptions.py:63 msgid "Override shell value from the identity provider with this value" msgstr "" "Substitueix el valor del shell del proveïdor d'identitat amb aquest valor" -#: src/config/SSSDConfig/sssdoptions.py:68 +#: src/config/SSSDConfig/sssdoptions.py:64 msgid "The list of shells users are allowed to log in with" msgstr "" "La llista dels shells que els usuaris poden utilitzar per iniciar la sessió" -#: src/config/SSSDConfig/sssdoptions.py:69 +#: src/config/SSSDConfig/sssdoptions.py:65 msgid "" "The list of shells that will be vetoed, and replaced with the fallback shell" msgstr "" "La llista dels shells que es vetaran i se substituiran amb el shell " "alternatiu" -#: src/config/SSSDConfig/sssdoptions.py:70 +#: src/config/SSSDConfig/sssdoptions.py:66 msgid "" "If a shell stored in central directory is allowed but not available, use " "this fallback" @@ -229,64 +230,64 @@ msgstr "" "Si un shell emmagatzemat al directori central està permès però no es troba " "disponible, utilitza aquesta alternativa" -#: src/config/SSSDConfig/sssdoptions.py:71 +#: src/config/SSSDConfig/sssdoptions.py:67 msgid "Shell to use if the provider does not list one" msgstr "El shell a utilitzar si el proveïdor no en llista cap" -#: src/config/SSSDConfig/sssdoptions.py:72 +#: src/config/SSSDConfig/sssdoptions.py:68 msgid "How long will be in-memory cache records valid" msgstr "Quant de temps seran vàlids els registres a la memòria cau" -#: src/config/SSSDConfig/sssdoptions.py:74 +#: src/config/SSSDConfig/sssdoptions.py:70 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for passwd requests" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:76 +#: src/config/SSSDConfig/sssdoptions.py:72 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for group requests" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:78 +#: src/config/SSSDConfig/sssdoptions.py:74 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for initgroups requests" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:79 +#: src/config/SSSDConfig/sssdoptions.py:75 msgid "" "The value of this option will be used in the expansion of the " "override_homedir option if the template contains the format string %H." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:81 +#: src/config/SSSDConfig/sssdoptions.py:77 msgid "" "Specifies time in seconds for which the list of subdomains will be " "considered valid." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:83 +#: src/config/SSSDConfig/sssdoptions.py:79 msgid "" "The entry cache can be set to automatically update entries in the background " "if they are requested beyond a percentage of the entry_cache_timeout value " "for the domain." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:88 +#: src/config/SSSDConfig/sssdoptions.py:84 msgid "How long to allow cached logins between online logins (days)" msgstr "" "Quant de temps s'ha de permetre entre els inicis de sessions en memòria cau " "i els inicis de sessions en línia (en dies)" -#: src/config/SSSDConfig/sssdoptions.py:89 +#: src/config/SSSDConfig/sssdoptions.py:85 msgid "How many failed logins attempts are allowed when offline" msgstr "" "Quants intents fallits d'inicis de sessió es permeten quan s'està " "desconnectat" -#: src/config/SSSDConfig/sssdoptions.py:91 +#: src/config/SSSDConfig/sssdoptions.py:87 msgid "" "How long (minutes) to deny login after offline_failed_login_attempts has " "been reached" @@ -294,132 +295,139 @@ msgstr "" "Quant de temps (en minuts) s'ha de denegar l'inici de sessió després d'haver " "assolit offline_failed_login_attempts" -#: src/config/SSSDConfig/sssdoptions.py:92 +#: src/config/SSSDConfig/sssdoptions.py:88 msgid "What kind of messages are displayed to the user during authentication" msgstr "Quins tipus de missatges es mostren a l'usuari durant l'autenticació" -#: src/config/SSSDConfig/sssdoptions.py:93 +#: src/config/SSSDConfig/sssdoptions.py:89 msgid "Filter PAM responses sent to the pam_sss" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:94 +#: src/config/SSSDConfig/sssdoptions.py:90 msgid "How many seconds to keep identity information cached for PAM requests" msgstr "" "Quants segons s'ha de mantenir la informació en la memòria cau per a les " "peticions PAM" -#: src/config/SSSDConfig/sssdoptions.py:95 +#: src/config/SSSDConfig/sssdoptions.py:91 msgid "How many days before password expiration a warning should be displayed" msgstr "" "Quants dies abans del venciment de la contrasenya s'hauria de mostrar una " "advertència" -#: src/config/SSSDConfig/sssdoptions.py:96 +#: src/config/SSSDConfig/sssdoptions.py:92 msgid "List of trusted uids or user's name" msgstr "La llista dels uid o dels noms d'usuari de confiança" -#: src/config/SSSDConfig/sssdoptions.py:97 +#: src/config/SSSDConfig/sssdoptions.py:93 msgid "List of domains accessible even for untrusted users." msgstr "" "La llista dels dominis accessibles fins i tot per als usuaris que no són de " "confiança." -#: src/config/SSSDConfig/sssdoptions.py:98 +#: src/config/SSSDConfig/sssdoptions.py:94 msgid "Message printed when user account is expired." msgstr "El missatge que es mostra quan venç el compte de l'usuari." -#: src/config/SSSDConfig/sssdoptions.py:99 +#: src/config/SSSDConfig/sssdoptions.py:95 msgid "Message printed when user account is locked." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:100 +#: src/config/SSSDConfig/sssdoptions.py:96 msgid "Allow certificate based/Smartcard authentication." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:101 +#: src/config/SSSDConfig/sssdoptions.py:97 msgid "Path to certificate database with PKCS#11 modules." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:102 +#: src/config/SSSDConfig/sssdoptions.py:98 #, fuzzy msgid "Tune certificate verification for PAM authentication." msgstr "Requereix verificació de certificat TLS" -#: src/config/SSSDConfig/sssdoptions.py:103 +#: src/config/SSSDConfig/sssdoptions.py:99 msgid "How many seconds will pam_sss wait for p11_child to finish" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:104 +#: src/config/SSSDConfig/sssdoptions.py:100 msgid "Which PAM services are permitted to contact application domains" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:105 +#: src/config/SSSDConfig/sssdoptions.py:101 msgid "Allowed services for using smartcards" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:106 +#: src/config/SSSDConfig/sssdoptions.py:102 msgid "Additional timeout to wait for a card if requested" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:107 +#: src/config/SSSDConfig/sssdoptions.py:103 msgid "" "PKCS#11 URI to restrict the selection of devices for Smartcard authentication" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:108 +#: src/config/SSSDConfig/sssdoptions.py:104 msgid "When shall the PAM responder force an initgroups request" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:109 +#: src/config/SSSDConfig/sssdoptions.py:105 msgid "List of PAM services that are allowed to authenticate with GSSAPI." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:110 +#: src/config/SSSDConfig/sssdoptions.py:106 msgid "Whether to match authenticated UPN with target user" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:111 +#: src/config/SSSDConfig/sssdoptions.py:107 msgid "" "List of pairs : that must be enforced " "for PAM access with GSSAPI authentication" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:113 +#: src/config/SSSDConfig/sssdoptions.py:109 +msgid "" +"List of triples :: that assigns " +"additional information from the Kerberos ticket to an authentication " +"indicator." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:112 msgid "Allow passkey device authentication." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:114 +#: src/config/SSSDConfig/sssdoptions.py:113 msgid "How many seconds will pam_sss wait for passkey_child to finish" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:115 +#: src/config/SSSDConfig/sssdoptions.py:114 msgid "Enable debugging in the libfido2 library" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:116 +#: src/config/SSSDConfig/sssdoptions.py:115 msgid "Enable JSON protocol for authentication methods selection." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:119 +#: src/config/SSSDConfig/sssdoptions.py:118 msgid "Whether to evaluate the time-based attributes in sudo rules" msgstr "Si s'avaluen els atributs basats en temps a les regles sudo" -#: src/config/SSSDConfig/sssdoptions.py:120 +#: src/config/SSSDConfig/sssdoptions.py:119 msgid "If true, SSSD will switch back to lower-wins ordering logic" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:121 +#: src/config/SSSDConfig/sssdoptions.py:120 msgid "" "Maximum number of rules that can be refreshed at once. If this is exceeded, " "full refresh is performed." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:128 +#: src/config/SSSDConfig/sssdoptions.py:127 msgid "Whether to hash host names and addresses in the known_hosts file" msgstr "" "Si s'esbocinen els noms i les adreces dels amfitrions al fitxer known_hosts" -#: src/config/SSSDConfig/sssdoptions.py:129 +#: src/config/SSSDConfig/sssdoptions.py:128 msgid "" "How many seconds to keep a host in the known_hosts file after its host keys " "were requested" @@ -427,145 +435,145 @@ msgstr "" "Quants segons s'ha de mantenir un amfitrió al fitxer known_hosts després que " "s'hagi sol·licitat la seva clau" -#: src/config/SSSDConfig/sssdoptions.py:131 +#: src/config/SSSDConfig/sssdoptions.py:130 msgid "Path to storage of trusted CA certificates" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:132 +#: src/config/SSSDConfig/sssdoptions.py:131 msgid "Allow to generate ssh-keys from certificates" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:133 +#: src/config/SSSDConfig/sssdoptions.py:132 msgid "" "Use the following matching rules to filter the certificates for ssh-key " "generation" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:137 +#: src/config/SSSDConfig/sssdoptions.py:136 msgid "List of UIDs or user names allowed to access the PAC responder" msgstr "" "La llista dels UID o dels noms d'usuari que poden accedir al contestador del " "PAC" -#: src/config/SSSDConfig/sssdoptions.py:138 +#: src/config/SSSDConfig/sssdoptions.py:137 msgid "How long the PAC data is considered valid" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:139 +#: src/config/SSSDConfig/sssdoptions.py:138 msgid "Validate the PAC" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:142 +#: src/config/SSSDConfig/sssdoptions.py:141 msgid "List of user attributes the InfoPipe is allowed to publish" msgstr "La llista dels atributs de l'usuari que l'InfoPipe pot publicar" -#: src/config/SSSDConfig/sssdoptions.py:145 +#: src/config/SSSDConfig/sssdoptions.py:144 msgid "" "One of the following strings specifying the scope of session recording: none " "- No users are recorded. some - Users/groups specified by users and groups " "options are recorded. all - All users are recorded." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:148 +#: src/config/SSSDConfig/sssdoptions.py:147 msgid "" "A comma-separated list of users which should have session recording enabled. " "Matches user names as returned by NSS. I.e. after the possible space " "replacement, case changes, etc." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:150 +#: src/config/SSSDConfig/sssdoptions.py:149 msgid "" "A comma-separated list of groups, members of which should have session " "recording enabled. Matches group names as returned by NSS. I.e. after the " "possible space replacement, case changes, etc." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:153 +#: src/config/SSSDConfig/sssdoptions.py:152 msgid "" "A comma-separated list of users to be excluded from recording, only when " "scope=all" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:154 +#: src/config/SSSDConfig/sssdoptions.py:153 msgid "" "A comma-separated list of groups, members of which should be excluded from " "recording, only when scope=all. " msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:158 +#: src/config/SSSDConfig/sssdoptions.py:157 msgid "Identity provider" msgstr "Proveïdor d'identitat" -#: src/config/SSSDConfig/sssdoptions.py:159 +#: src/config/SSSDConfig/sssdoptions.py:158 msgid "Authentication provider" msgstr "Proveïdor d'autenticació" -#: src/config/SSSDConfig/sssdoptions.py:160 +#: src/config/SSSDConfig/sssdoptions.py:159 msgid "Access control provider" msgstr "Proveïdor de control d'accés" -#: src/config/SSSDConfig/sssdoptions.py:161 +#: src/config/SSSDConfig/sssdoptions.py:160 msgid "Password change provider" msgstr "Proveïdor de canvi de contrasenya" -#: src/config/SSSDConfig/sssdoptions.py:162 +#: src/config/SSSDConfig/sssdoptions.py:161 msgid "SUDO provider" msgstr "Proveïdor de SUDO" -#: src/config/SSSDConfig/sssdoptions.py:163 +#: src/config/SSSDConfig/sssdoptions.py:162 msgid "Autofs provider" msgstr "Proveïdor d'Autofs" -#: src/config/SSSDConfig/sssdoptions.py:164 +#: src/config/SSSDConfig/sssdoptions.py:163 msgid "Host identity provider" msgstr "Proveïdor d'identitat d'amfitrions" -#: src/config/SSSDConfig/sssdoptions.py:165 +#: src/config/SSSDConfig/sssdoptions.py:164 msgid "SELinux provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:166 +#: src/config/SSSDConfig/sssdoptions.py:165 msgid "Session management provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:167 +#: src/config/SSSDConfig/sssdoptions.py:166 msgid "Resolver provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:170 +#: src/config/SSSDConfig/sssdoptions.py:169 msgid "Whether the domain is usable by the OS or by applications" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:171 +#: src/config/SSSDConfig/sssdoptions.py:170 #, fuzzy msgid "Enable or disable the domain" msgstr "Habilita la validació de credencials" -#: src/config/SSSDConfig/sssdoptions.py:172 +#: src/config/SSSDConfig/sssdoptions.py:171 msgid "Minimum user ID" msgstr "Id. mínim d'usuari" -#: src/config/SSSDConfig/sssdoptions.py:173 +#: src/config/SSSDConfig/sssdoptions.py:172 msgid "Maximum user ID" msgstr "Id. màxim d'usuari" -#: src/config/SSSDConfig/sssdoptions.py:174 +#: src/config/SSSDConfig/sssdoptions.py:173 msgid "Enable enumerating all users/groups" msgstr "Habilita l'enumeració de tots els usuaris/grups" -#: src/config/SSSDConfig/sssdoptions.py:175 +#: src/config/SSSDConfig/sssdoptions.py:174 msgid "Cache credentials for offline login" msgstr "Credencials en memòria cau per als inicis de sessions sense connexió" -#: src/config/SSSDConfig/sssdoptions.py:176 +#: src/config/SSSDConfig/sssdoptions.py:175 msgid "Display users/groups in fully-qualified form" msgstr "Mostra els usuaris/grups en format plenament qualificat" -#: src/config/SSSDConfig/sssdoptions.py:177 +#: src/config/SSSDConfig/sssdoptions.py:176 msgid "Don't include group members in group lookups" msgstr "No incloure als membres dels grups en la recerca del grup" -#: src/config/SSSDConfig/sssdoptions.py:178 +#: src/config/SSSDConfig/sssdoptions.py:177 #: src/config/SSSDConfig/sssdoptions.py:190 #: src/config/SSSDConfig/sssdoptions.py:191 #: src/config/SSSDConfig/sssdoptions.py:192 @@ -578,54 +586,59 @@ msgstr "" "Període de temps per a l'expiració de les entrades de la memòria cau (en " "segons)" -#: src/config/SSSDConfig/sssdoptions.py:179 +#: src/config/SSSDConfig/sssdoptions.py:178 msgid "" "Restrict or prefer a specific address family when performing DNS lookups" msgstr "" "Restringeix o prefereix una família específica d'adreces quan es realitzi la " "recerca del DNS" -#: src/config/SSSDConfig/sssdoptions.py:180 +#: src/config/SSSDConfig/sssdoptions.py:179 msgid "How long to keep cached entries after last successful login (days)" msgstr "" "Quant de temps s'han de mantenir les entrades en la memòria cau després de " "l'últim inici de sessió reeixit (en dies)" -#: src/config/SSSDConfig/sssdoptions.py:181 +#: src/config/SSSDConfig/sssdoptions.py:180 msgid "" "How long should SSSD talk to single DNS server before trying next server " "(miliseconds)" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:183 +#: src/config/SSSDConfig/sssdoptions.py:182 msgid "How long should keep trying to resolve single DNS query (seconds)" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:184 +#: src/config/SSSDConfig/sssdoptions.py:183 msgid "How long to wait for replies from DNS when resolving servers (seconds)" msgstr "" "Temps d'expiració per a les respostes del DNS en la resolució dels servidors " "(en segons)" -#: src/config/SSSDConfig/sssdoptions.py:185 +#: src/config/SSSDConfig/sssdoptions.py:184 msgid "The domain part of service discovery DNS query" msgstr "La part del domini de la consulta DNS del descobriment del servei" -#: src/config/SSSDConfig/sssdoptions.py:186 +#: src/config/SSSDConfig/sssdoptions.py:185 msgid "" "Specifies the interval, in seconds, that SSSD waits before attempting to " "reconnect to the primary server after a successful connection to the backup " "server" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:188 +#: src/config/SSSDConfig/sssdoptions.py:187 msgid "Override GID value from the identity provider with this value" -msgstr "Substitueix el valor del GID del proveïdor d'identitat amb aquest valor" +msgstr "" +"Substitueix el valor del GID del proveïdor d'identitat amb aquest valor" -#: src/config/SSSDConfig/sssdoptions.py:189 +#: src/config/SSSDConfig/sssdoptions.py:188 msgid "Treat usernames as case sensitive" msgstr "Distingeix entre majúscules i minúscules als noms d'usuari" +#: src/config/SSSDConfig/sssdoptions.py:189 +msgid "Lookups by ID are expensive or do not work at all" +msgstr "" + #: src/config/SSSDConfig/sssdoptions.py:197 msgid "How often should expired entries be refreshed in background" msgstr "Amb quina freqüència les entrades vençudes s'actualitzen al rerefons" @@ -866,7 +879,7 @@ msgid "Search base for SUBID ranges" msgstr "Base de cerca per als contenidors de la vista" #: src/config/SSSDConfig/sssdoptions.py:259 -#: src/config/SSSDConfig/sssdoptions.py:506 +#: src/config/SSSDConfig/sssdoptions.py:512 msgid "Which rules should be used to evaluate access control" msgstr "Quines regles s'haurien d'utilitzar per avaluar el control d'accés" @@ -1009,7 +1022,7 @@ msgstr "" "Habilita els llocs DNS - el descobriment del servei es basa en la ubicació" #: src/config/SSSDConfig/sssdoptions.py:301 -#: src/config/SSSDConfig/sssdoptions.py:504 +#: src/config/SSSDConfig/sssdoptions.py:510 msgid "LDAP filter to determine access privileges" msgstr "Filtre LDAP per determinar els privilegis d'accés" @@ -1034,37 +1047,37 @@ msgid "" "PAM service names that map to the GPO (Deny)InteractiveLogonRight policy " "settings" msgstr "" -"Noms dels serveis del PAM que s'assignen als ajusts de les polítiques (Deny)" -"InteractiveLogonRight del GPO" +"Noms dels serveis del PAM que s'assignen als ajusts de les polítiques " +"(Deny)InteractiveLogonRight del GPO" #: src/config/SSSDConfig/sssdoptions.py:307 msgid "" "PAM service names that map to the GPO (Deny)RemoteInteractiveLogonRight " "policy settings" msgstr "" -"Noms dels serveis del PAM que s'assignen als ajusts de les polítiques (Deny)" -"RemoteInteractiveLogonRight del GPO" +"Noms dels serveis del PAM que s'assignen als ajusts de les polítiques " +"(Deny)RemoteInteractiveLogonRight del GPO" #: src/config/SSSDConfig/sssdoptions.py:309 msgid "" "PAM service names that map to the GPO (Deny)NetworkLogonRight policy settings" msgstr "" -"Noms dels serveis del PAM que s'assignen als ajusts de les polítiques (Deny)" -"NetworkLogonRight del GPO" +"Noms dels serveis del PAM que s'assignen als ajusts de les polítiques " +"(Deny)NetworkLogonRight del GPO" #: src/config/SSSDConfig/sssdoptions.py:310 msgid "" "PAM service names that map to the GPO (Deny)BatchLogonRight policy settings" msgstr "" -"Noms dels serveis del PAM que s'assignen als ajusts de les polítiques (Deny)" -"BatchLogonRight del GPO" +"Noms dels serveis del PAM que s'assignen als ajusts de les polítiques " +"(Deny)BatchLogonRight del GPO" #: src/config/SSSDConfig/sssdoptions.py:311 msgid "" "PAM service names that map to the GPO (Deny)ServiceLogonRight policy settings" msgstr "" -"Noms dels serveis del PAM que s'assignen als ajusts de les polítiques (Deny)" -"ServiceLogonRight del GPO" +"Noms dels serveis del PAM que s'assignen als ajusts de les polítiques " +"(Deny)ServiceLogonRight del GPO" #: src/config/SSSDConfig/sssdoptions.py:312 msgid "PAM service names for which GPO-based access is always granted" @@ -1461,7 +1474,7 @@ msgid "UUID attribute" msgstr "L'atribut UUID" #: src/config/SSSDConfig/sssdoptions.py:423 -#: src/config/SSSDConfig/sssdoptions.py:464 +#: src/config/SSSDConfig/sssdoptions.py:470 msgid "objectSID attribute" msgstr "L'atribut objectSID" @@ -1589,176 +1602,205 @@ msgstr "" "Una llista dels atributs extres per baixar juntament amb l'entrada de " "l'usuari" +#: src/config/SSSDConfig/sssdoptions.py:456 +msgid "The object class of an subid entry in LDAP." +msgstr "" + #: src/config/SSSDConfig/sssdoptions.py:457 +#, fuzzy +msgid "Subordinate user ID count attribute" +msgstr "L'atribut user de la regla sudo" + +#: src/config/SSSDConfig/sssdoptions.py:458 +#, fuzzy +msgid "Subordinate group ID count attribute" +msgstr "L'atribut option de la regla sudo" + +#: src/config/SSSDConfig/sssdoptions.py:459 +#, fuzzy +msgid "User ID range start value attribute" +msgstr "L'atribut nom d'usuari" + +#: src/config/SSSDConfig/sssdoptions.py:460 +#, fuzzy +msgid "Group ID range start value attribute" +msgstr "L'atribut UUID del grup" + +#: src/config/SSSDConfig/sssdoptions.py:461 +msgid "Owner of an entry" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:463 msgid "Base DN for group lookups" msgstr "DN base per a la recerca del grup" -#: src/config/SSSDConfig/sssdoptions.py:458 +#: src/config/SSSDConfig/sssdoptions.py:464 msgid "Objectclass for groups" msgstr "L'objectclass per als grups" -#: src/config/SSSDConfig/sssdoptions.py:459 +#: src/config/SSSDConfig/sssdoptions.py:465 msgid "Group name" msgstr "Nom del grup" -#: src/config/SSSDConfig/sssdoptions.py:460 +#: src/config/SSSDConfig/sssdoptions.py:466 msgid "Group password" msgstr "Contrasenya del grup" -#: src/config/SSSDConfig/sssdoptions.py:461 +#: src/config/SSSDConfig/sssdoptions.py:467 msgid "GID attribute" msgstr "L'atribut GID" -#: src/config/SSSDConfig/sssdoptions.py:462 +#: src/config/SSSDConfig/sssdoptions.py:468 msgid "Group member attribute" msgstr "L'atribut membre del grup" -#: src/config/SSSDConfig/sssdoptions.py:463 +#: src/config/SSSDConfig/sssdoptions.py:469 msgid "Group UUID attribute" msgstr "L'atribut UUID del grup" -#: src/config/SSSDConfig/sssdoptions.py:465 +#: src/config/SSSDConfig/sssdoptions.py:471 msgid "Modification time attribute for groups" msgstr "L'atribut data de modificació per als grups" -#: src/config/SSSDConfig/sssdoptions.py:466 +#: src/config/SSSDConfig/sssdoptions.py:472 msgid "Type of the group and other flags" msgstr "Tipus del grup i altres senyals" -#: src/config/SSSDConfig/sssdoptions.py:467 +#: src/config/SSSDConfig/sssdoptions.py:473 msgid "The LDAP group external member attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:468 +#: src/config/SSSDConfig/sssdoptions.py:474 msgid "Maximum nesting level SSSD will follow" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:469 +#: src/config/SSSDConfig/sssdoptions.py:475 msgid "Filter for group lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:470 +#: src/config/SSSDConfig/sssdoptions.py:476 msgid "Scope of group lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:472 +#: src/config/SSSDConfig/sssdoptions.py:478 msgid "Base DN for netgroup lookups" msgstr "DN base per a la recerca del grup de xarxa" -#: src/config/SSSDConfig/sssdoptions.py:473 +#: src/config/SSSDConfig/sssdoptions.py:479 msgid "Objectclass for netgroups" msgstr "L'objectclass per als grups de xarxa" -#: src/config/SSSDConfig/sssdoptions.py:474 +#: src/config/SSSDConfig/sssdoptions.py:480 msgid "Netgroup name" msgstr "Nom de grup de xarxa" -#: src/config/SSSDConfig/sssdoptions.py:475 +#: src/config/SSSDConfig/sssdoptions.py:481 msgid "Netgroups members attribute" msgstr "L'atribut membres del grup de xarxa" -#: src/config/SSSDConfig/sssdoptions.py:476 +#: src/config/SSSDConfig/sssdoptions.py:482 msgid "Netgroup triple attribute" msgstr "L'atribut triple del grup de xarxa" -#: src/config/SSSDConfig/sssdoptions.py:477 +#: src/config/SSSDConfig/sssdoptions.py:483 msgid "Modification time attribute for netgroups" msgstr "L'atribut data de modificació per als grups de xarxa" -#: src/config/SSSDConfig/sssdoptions.py:479 +#: src/config/SSSDConfig/sssdoptions.py:485 msgid "Base DN for service lookups" msgstr "DN base per a la recerca del servei" -#: src/config/SSSDConfig/sssdoptions.py:480 +#: src/config/SSSDConfig/sssdoptions.py:486 msgid "Objectclass for services" msgstr "Objectclass per als serveis" -#: src/config/SSSDConfig/sssdoptions.py:481 +#: src/config/SSSDConfig/sssdoptions.py:487 msgid "Service name attribute" msgstr "L'atribut nom del servei" -#: src/config/SSSDConfig/sssdoptions.py:482 +#: src/config/SSSDConfig/sssdoptions.py:488 msgid "Service port attribute" msgstr "L'atribut port del servei" -#: src/config/SSSDConfig/sssdoptions.py:483 +#: src/config/SSSDConfig/sssdoptions.py:489 msgid "Service protocol attribute" msgstr "L'atribut protocol del servei" -#: src/config/SSSDConfig/sssdoptions.py:485 +#: src/config/SSSDConfig/sssdoptions.py:491 msgid "Lower bound for ID-mapping" msgstr "Límit inferior per a l'assignació d'id." -#: src/config/SSSDConfig/sssdoptions.py:486 +#: src/config/SSSDConfig/sssdoptions.py:492 msgid "Upper bound for ID-mapping" msgstr "Límit superior per a l'assignació d'id." -#: src/config/SSSDConfig/sssdoptions.py:487 +#: src/config/SSSDConfig/sssdoptions.py:493 msgid "Number of IDs for each slice when ID-mapping" msgstr "Nombres d'id. per cada porció en l'assignació d'id." -#: src/config/SSSDConfig/sssdoptions.py:488 +#: src/config/SSSDConfig/sssdoptions.py:494 msgid "Use autorid-compatible algorithm for ID-mapping" msgstr "Utilitza l'algoritme compatible d'autorid per a l'assignació d'id." -#: src/config/SSSDConfig/sssdoptions.py:489 +#: src/config/SSSDConfig/sssdoptions.py:495 msgid "Name of the default domain for ID-mapping" msgstr "Nom del domini per defecte per a l'assignació d'id." -#: src/config/SSSDConfig/sssdoptions.py:490 +#: src/config/SSSDConfig/sssdoptions.py:496 msgid "SID of the default domain for ID-mapping" msgstr "SID del domini per defecte per a l'assignació d'id." -#: src/config/SSSDConfig/sssdoptions.py:491 +#: src/config/SSSDConfig/sssdoptions.py:497 msgid "Number of secondary slices" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:493 +#: src/config/SSSDConfig/sssdoptions.py:499 msgid "Whether to use Token-Groups" msgstr "Si s'utilitzen els grups amb testimonis" -#: src/config/SSSDConfig/sssdoptions.py:494 +#: src/config/SSSDConfig/sssdoptions.py:500 msgid "Set lower boundary for allowed IDs from the LDAP server" msgstr "Estableix el límit inferior per als id. permesos del servidor LDAP" -#: src/config/SSSDConfig/sssdoptions.py:495 +#: src/config/SSSDConfig/sssdoptions.py:501 msgid "Set upper boundary for allowed IDs from the LDAP server" msgstr "Estableix el límit superior per als id. permesos del servidor LDAP" -#: src/config/SSSDConfig/sssdoptions.py:496 +#: src/config/SSSDConfig/sssdoptions.py:502 msgid "DN for ppolicy queries" msgstr "DN per a les consultes ppolicy" -#: src/config/SSSDConfig/sssdoptions.py:497 +#: src/config/SSSDConfig/sssdoptions.py:503 msgid "How many maximum entries to fetch during a wildcard request" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:498 +#: src/config/SSSDConfig/sssdoptions.py:504 msgid "Set libldap debug level" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:501 +#: src/config/SSSDConfig/sssdoptions.py:507 msgid "Policy to evaluate the password expiration" msgstr "Política per avaluar el venciment de la contrasenya" -#: src/config/SSSDConfig/sssdoptions.py:505 +#: src/config/SSSDConfig/sssdoptions.py:511 msgid "Which attributes shall be used to evaluate if an account is expired" -msgstr "Quins atributs s'haurien d'utilitzar per avaluar si el compte ha vençut" +msgstr "" +"Quins atributs s'haurien d'utilitzar per avaluar si el compte ha vençut" -#: src/config/SSSDConfig/sssdoptions.py:509 +#: src/config/SSSDConfig/sssdoptions.py:515 msgid "URI of an LDAP server where password changes are allowed" msgstr "URI d'un servidor LDAP on es permeten els canvis de contrasenya" -#: src/config/SSSDConfig/sssdoptions.py:510 +#: src/config/SSSDConfig/sssdoptions.py:516 msgid "URI of a backup LDAP server where password changes are allowed" msgstr "" "URI d'un servidor LDAP de reserva on es permeten els canvis de contrasenya" -#: src/config/SSSDConfig/sssdoptions.py:511 +#: src/config/SSSDConfig/sssdoptions.py:517 msgid "DNS service name for LDAP password change server" msgstr "Nom del servei DNS pel servidor LDAP de canvi de contrasenyes" -#: src/config/SSSDConfig/sssdoptions.py:512 +#: src/config/SSSDConfig/sssdoptions.py:518 msgid "" "Whether to update the ldap_user_shadow_last_change attribute after a " "password change" @@ -1766,27 +1808,27 @@ msgstr "" "Si s'actualitza l'atribut ldap_user_shadow_last_change després d'un canvi de " "contrasenya" -#: src/config/SSSDConfig/sssdoptions.py:516 +#: src/config/SSSDConfig/sssdoptions.py:522 msgid "Base DN for sudo rules lookups" msgstr "DN base per a la recerca de les regles sudo" -#: src/config/SSSDConfig/sssdoptions.py:517 +#: src/config/SSSDConfig/sssdoptions.py:523 msgid "Automatic full refresh period" msgstr "Període d'actualització automàtica completa" -#: src/config/SSSDConfig/sssdoptions.py:518 +#: src/config/SSSDConfig/sssdoptions.py:524 msgid "Automatic smart refresh period" msgstr "Període d'actualització automàtica intel·ligent" -#: src/config/SSSDConfig/sssdoptions.py:519 +#: src/config/SSSDConfig/sssdoptions.py:525 msgid "Smart and full refresh random offset" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:520 +#: src/config/SSSDConfig/sssdoptions.py:526 msgid "Whether to filter rules by hostname, IP addresses and network" msgstr "Si es filtren les regles per nom d'amfitrió, adreça IP i xarxa" -#: src/config/SSSDConfig/sssdoptions.py:521 +#: src/config/SSSDConfig/sssdoptions.py:527 msgid "" "Hostnames and/or fully qualified domain names of this machine to filter sudo " "rules" @@ -1794,196 +1836,196 @@ msgstr "" "Noms d'amfitrió i/o noms de domini plenament qualificat d'aquesta màquina " "per filtrar les regles de sudo" -#: src/config/SSSDConfig/sssdoptions.py:522 +#: src/config/SSSDConfig/sssdoptions.py:528 msgid "IPv4 or IPv6 addresses or network of this machine to filter sudo rules" msgstr "" "Adreces IPv4 o IPv6 o xarxa d'aquesta màquina per filtrar regles de sudo" -#: src/config/SSSDConfig/sssdoptions.py:523 +#: src/config/SSSDConfig/sssdoptions.py:529 msgid "Whether to include rules that contains netgroup in host attribute" msgstr "" "Si s'inclouen les regles que contenen el grup de xarxa a l'atribut de " "l'amfitrió" -#: src/config/SSSDConfig/sssdoptions.py:524 +#: src/config/SSSDConfig/sssdoptions.py:530 msgid "" "Whether to include rules that contains regular expression in host attribute" msgstr "" "Si s'inclouen les regles que contenen expressions regulars a l'atribut de " "l'amfitrió" -#: src/config/SSSDConfig/sssdoptions.py:525 +#: src/config/SSSDConfig/sssdoptions.py:531 msgid "Object class for sudo rules" msgstr "Objectclass de les regles sudo" -#: src/config/SSSDConfig/sssdoptions.py:526 +#: src/config/SSSDConfig/sssdoptions.py:532 msgid "Name of attribute that is used as object class for sudo rules" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:527 +#: src/config/SSSDConfig/sssdoptions.py:533 msgid "Sudo rule name" msgstr "Nom de la regla sudo" -#: src/config/SSSDConfig/sssdoptions.py:528 +#: src/config/SSSDConfig/sssdoptions.py:534 msgid "Sudo rule command attribute" msgstr "Attribut command de la regla sudo" -#: src/config/SSSDConfig/sssdoptions.py:529 +#: src/config/SSSDConfig/sssdoptions.py:535 msgid "Sudo rule host attribute" msgstr "L'atribut host de la regla sudo" -#: src/config/SSSDConfig/sssdoptions.py:530 +#: src/config/SSSDConfig/sssdoptions.py:536 msgid "Sudo rule user attribute" msgstr "L'atribut user de la regla sudo" -#: src/config/SSSDConfig/sssdoptions.py:531 +#: src/config/SSSDConfig/sssdoptions.py:537 msgid "Sudo rule option attribute" msgstr "L'atribut option de la regla sudo" -#: src/config/SSSDConfig/sssdoptions.py:532 +#: src/config/SSSDConfig/sssdoptions.py:538 msgid "Sudo rule runas attribute" msgstr "L'atribut runas de la regla sudo" -#: src/config/SSSDConfig/sssdoptions.py:533 +#: src/config/SSSDConfig/sssdoptions.py:539 msgid "Sudo rule runasuser attribute" msgstr "L'atribut runasuser de la regla sudo" -#: src/config/SSSDConfig/sssdoptions.py:534 +#: src/config/SSSDConfig/sssdoptions.py:540 msgid "Sudo rule runasgroup attribute" msgstr "L'atribut runasgroup de la regla sudo" -#: src/config/SSSDConfig/sssdoptions.py:535 +#: src/config/SSSDConfig/sssdoptions.py:541 msgid "Sudo rule notbefore attribute" msgstr "L'atribut notbefore de la regla sudo" -#: src/config/SSSDConfig/sssdoptions.py:536 +#: src/config/SSSDConfig/sssdoptions.py:542 msgid "Sudo rule notafter attribute" msgstr "L'atribut notafter de la regla sudo" -#: src/config/SSSDConfig/sssdoptions.py:537 +#: src/config/SSSDConfig/sssdoptions.py:543 msgid "Sudo rule order attribute" msgstr "L'atribut order de la regla sudo" -#: src/config/SSSDConfig/sssdoptions.py:540 +#: src/config/SSSDConfig/sssdoptions.py:546 msgid "Object class for automounter maps" msgstr "Objectclass per a les assignacions de l'eina de muntatge automàtic" -#: src/config/SSSDConfig/sssdoptions.py:541 +#: src/config/SSSDConfig/sssdoptions.py:547 msgid "Automounter map name attribute" msgstr "L'atribut nom de l'assignació de l'eina de muntatge automàtic" -#: src/config/SSSDConfig/sssdoptions.py:542 +#: src/config/SSSDConfig/sssdoptions.py:548 msgid "Object class for automounter map entries" msgstr "" "Objectclass per a les entrades de les assignacions de l'eina de muntatge " "automàtic" -#: src/config/SSSDConfig/sssdoptions.py:543 +#: src/config/SSSDConfig/sssdoptions.py:549 msgid "Automounter map entry key attribute" msgstr "" "L'atribut clau d'entrada de l'assignació de l'eina de muntatge automàtic" -#: src/config/SSSDConfig/sssdoptions.py:544 +#: src/config/SSSDConfig/sssdoptions.py:550 msgid "Automounter map entry value attribute" msgstr "" "L'atribut valor de l'entrada de l'assignació l'eina de muntatge automàtic" -#: src/config/SSSDConfig/sssdoptions.py:545 +#: src/config/SSSDConfig/sssdoptions.py:551 msgid "Base DN for automounter map lookups" msgstr "" "DN base per a la recerca de l'assignació de l'eina de muntatge automàtic" -#: src/config/SSSDConfig/sssdoptions.py:546 +#: src/config/SSSDConfig/sssdoptions.py:552 msgid "The name of the automount master map in LDAP." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:549 +#: src/config/SSSDConfig/sssdoptions.py:555 msgid "Base DN for IP hosts lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:550 +#: src/config/SSSDConfig/sssdoptions.py:556 msgid "Object class for IP hosts" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:551 +#: src/config/SSSDConfig/sssdoptions.py:557 msgid "IP host name attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:552 +#: src/config/SSSDConfig/sssdoptions.py:558 msgid "IP host number (address) attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:553 +#: src/config/SSSDConfig/sssdoptions.py:559 msgid "IP host entryUSN attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:554 +#: src/config/SSSDConfig/sssdoptions.py:560 msgid "Base DN for IP networks lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:555 +#: src/config/SSSDConfig/sssdoptions.py:561 msgid "Object class for IP networks" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:556 +#: src/config/SSSDConfig/sssdoptions.py:562 msgid "IP network name attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:557 +#: src/config/SSSDConfig/sssdoptions.py:563 msgid "IP network number (address) attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:558 +#: src/config/SSSDConfig/sssdoptions.py:564 msgid "IP network entryUSN attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:561 +#: src/config/SSSDConfig/sssdoptions.py:567 msgid "Comma separated list of allowed users" msgstr "Llista separada per comes dels usuaris autoritzats" -#: src/config/SSSDConfig/sssdoptions.py:562 +#: src/config/SSSDConfig/sssdoptions.py:568 msgid "Comma separated list of prohibited users" msgstr "Llista separada per comes dels usuaris no autoritzats" -#: src/config/SSSDConfig/sssdoptions.py:563 +#: src/config/SSSDConfig/sssdoptions.py:569 msgid "" "Comma separated list of groups that are allowed to log in. This applies only " "to groups within this SSSD domain. Local groups are not evaluated." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:565 +#: src/config/SSSDConfig/sssdoptions.py:571 msgid "" "Comma separated list of groups that are explicitly denied access. This " "applies only to groups within this SSSD domain. Local groups are not " "evaluated." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:569 +#: src/config/SSSDConfig/sssdoptions.py:575 msgid "The number of preforked proxy children." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:572 +#: src/config/SSSDConfig/sssdoptions.py:578 msgid "The name of the NSS library to use" msgstr "El nom de la biblioteca NSS a utilitzar" -#: src/config/SSSDConfig/sssdoptions.py:573 +#: src/config/SSSDConfig/sssdoptions.py:579 msgid "The name of the NSS library to use for hosts and networks lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:574 +#: src/config/SSSDConfig/sssdoptions.py:580 msgid "Whether to look up canonical group name from cache if possible" msgstr "" "Si se cerca el nom del grup canònic des de la memòria cau, si és possible" -#: src/config/SSSDConfig/sssdoptions.py:577 +#: src/config/SSSDConfig/sssdoptions.py:583 msgid "PAM stack to use" msgstr "Pila PAM a utilitzar" -#: src/config/SSSDConfig/sssdoptions.py:580 +#: src/config/SSSDConfig/sssdoptions.py:586 msgid "Path of passwd file sources." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:581 +#: src/config/SSSDConfig/sssdoptions.py:587 msgid "Path of group file sources." msgstr "" @@ -2011,159 +2053,163 @@ msgstr "L'ordre post-delete ha fallat: %1$s\n" msgid "Option -i|--interactive is not allowed together with -D|--daemon\n" msgstr "" -#: src/monitor/monitor.c:1836 +#: src/monitor/monitor.c:1838 msgid "Failed to get initial capabilities\n" msgstr "" -#: src/monitor/monitor.c:1847 +#: src/monitor/monitor.c:1849 msgid "Non-root service user support isn't built. Can't run under %" msgstr "" -#: src/monitor/monitor.c:1864 +#: src/monitor/monitor.c:1866 #, c-format msgid "Can't read config: '%s'\n" msgstr "" -#: src/monitor/monitor.c:1876 +#: src/monitor/monitor.c:1878 #, c-format -msgid "Failed to boostrap SSSD 'monitor' process: %s" +msgid "Failed to bootstrap SSSD 'monitor' process: %s" msgstr "" -#: src/monitor/monitor.c:1971 +#: src/monitor/monitor.c:1973 msgid "Out of memory\n" msgstr "Sense memòria\n" -#: src/providers/krb5/krb5_child.c:4221 +#: src/providers/krb5/krb5_child.c:4316 msgid "Use anonymous PKINIT to request FAST armor ticket" msgstr "" -#: src/providers/krb5/krb5_child.c:4223 +#: src/providers/krb5/krb5_child.c:4318 msgid "Kerberos realm to use" msgstr "" -#: src/providers/krb5/krb5_child.c:4225 +#: src/providers/krb5/krb5_child.c:4320 msgid "Requested lifetime of the ticket" msgstr "" -#: src/providers/krb5/krb5_child.c:4227 +#: src/providers/krb5/krb5_child.c:4322 msgid "Requested renewable lifetime of the ticket" msgstr "" -#: src/providers/krb5/krb5_child.c:4229 +#: src/providers/krb5/krb5_child.c:4324 msgid "FAST options ('never', 'try', 'demand')" msgstr "" -#: src/providers/krb5/krb5_child.c:4232 +#: src/providers/krb5/krb5_child.c:4327 msgid "Specifies the server principal to use for FAST" msgstr "" -#: src/providers/krb5/krb5_child.c:4234 +#: src/providers/krb5/krb5_child.c:4329 msgid "Requests canonicalization of the principal name" msgstr "" -#: src/providers/krb5/krb5_child.c:4236 +#: src/providers/krb5/krb5_child.c:4331 msgid "Use custom version of krb5_get_init_creds_password" msgstr "" -#: src/providers/krb5/krb5_child.c:4238 +#: src/providers/krb5/krb5_child.c:4333 msgid "Check PAC flags" msgstr "" -#: src/providers/data_provider_be.c:790 +#: src/providers/krb5/krb5_child.c:4335 +msgid "Set environment variable (KEY=VALUE)" +msgstr "" + +#: src/providers/data_provider_be.c:786 msgid "Domain of the information provider (mandatory)" msgstr "Domini del proveïdor d'informació (obligatori)" -#: src/sss_client/common.c:1165 +#: src/sss_client/common.c:1208 #, fuzzy msgid "Socket has wrong ownership or permissions." msgstr "El sòcol públic té malament els permisos o el propietari." -#: src/sss_client/common.c:1168 +#: src/sss_client/common.c:1211 msgid "Unexpected format of the server credential message." msgstr "Format inesperat del missatge de les credencials del servidor." -#: src/sss_client/common.c:1171 +#: src/sss_client/common.c:1214 #, fuzzy msgid "SSSD is not run by trusted user." msgstr "L'SSSD no s'està executant com a root." -#: src/sss_client/common.c:1174 +#: src/sss_client/common.c:1217 msgid "SSSD socket does not exist." msgstr "" -#: src/sss_client/common.c:1177 +#: src/sss_client/common.c:1220 msgid "Cannot get stat of SSSD socket." msgstr "" -#: src/sss_client/common.c:1182 +#: src/sss_client/common.c:1225 msgid "An error occurred, but no description can be found." msgstr "S'ha produït un error però no s'ha pogut trobar cap descripció." -#: src/sss_client/common.c:1188 +#: src/sss_client/common.c:1231 msgid "Unexpected error while looking for an error description" msgstr "Error inesperat en cercar una descripció de l'error" -#: src/sss_client/pam_sss.c:74 +#: src/sss_client/pam_sss.c:135 msgid "Permission denied. " msgstr "Permís denegat." -#: src/sss_client/pam_sss.c:75 src/sss_client/pam_sss.c:843 -#: src/sss_client/pam_sss.c:854 +#: src/sss_client/pam_sss.c:136 src/sss_client/pam_sss.c:921 +#: src/sss_client/pam_sss.c:932 msgid "Server message: " msgstr "Missatge del servidor: " -#: src/sss_client/pam_sss.c:76 +#: src/sss_client/pam_sss.c:137 msgid "" "Kerberos TGT will not be granted upon login, user experience will be " "affected." msgstr "" -#: src/sss_client/pam_sss.c:77 +#: src/sss_client/pam_sss.c:138 msgid "Enter PIN:" msgstr "" -#: src/sss_client/pam_sss.c:320 +#: src/sss_client/pam_sss.c:385 msgid "Passwords do not match" msgstr "Les contrasenyes no coincideixen" -#: src/sss_client/pam_sss.c:508 +#: src/sss_client/pam_sss.c:584 msgid "Password reset by root is not supported." msgstr "No s'admet el restabliment de la contrasenya pel root." -#: src/sss_client/pam_sss.c:549 +#: src/sss_client/pam_sss.c:625 msgid "Authenticated with cached credentials" msgstr "S'ha autenticat amb credencials de la memòria cau" -#: src/sss_client/pam_sss.c:550 +#: src/sss_client/pam_sss.c:626 msgid ", your cached password will expire at: " msgstr ", la vostra contrasenya en memòria cau vencerà el: " -#: src/sss_client/pam_sss.c:580 +#: src/sss_client/pam_sss.c:656 #, c-format msgid "Your password has expired. You have %1$d grace login(s) remaining." msgstr "" "La vostra contrasenya ha vençut. Teniu %1$d inicis de sessió restants de " "cortesia." -#: src/sss_client/pam_sss.c:630 +#: src/sss_client/pam_sss.c:706 #, c-format msgid "Your password will expire in %1$d %2$s." msgstr "La vostra contrasenya vencerà en %1$d %2$s." -#: src/sss_client/pam_sss.c:633 +#: src/sss_client/pam_sss.c:709 #, fuzzy, c-format msgid "Your password has expired." msgstr "La vostra contrasenya vencerà en %1$d %2$s." -#: src/sss_client/pam_sss.c:684 +#: src/sss_client/pam_sss.c:760 msgid "Authentication is denied until: " msgstr "S'ha denegat l'autenticació fins: " -#: src/sss_client/pam_sss.c:705 +#: src/sss_client/pam_sss.c:781 msgid "System is offline, password change not possible" msgstr "El sistema està desconnectat, el canvi de contrasenya no és possible" -#: src/sss_client/pam_sss.c:720 +#: src/sss_client/pam_sss.c:796 msgid "" "After changing the OTP password, you need to log out and back in order to " "acquire a ticket" @@ -2171,71 +2217,75 @@ msgstr "" "Després de canviar la contrasenya OTP, heu de tancar la sessió i tornar-la a " "iniciar per tal d'adquirir un tiquet" -#: src/sss_client/pam_sss.c:735 +#: src/sss_client/pam_sss.c:813 msgid "PIN locked" msgstr "" -#: src/sss_client/pam_sss.c:750 +#: src/sss_client/pam_sss.c:828 msgid "" "No Kerberos TGT granted as the server does not support this method. Your " "single-sign on(SSO) experience will be affected." msgstr "" -#: src/sss_client/pam_sss.c:840 src/sss_client/pam_sss.c:853 +#: src/sss_client/pam_sss.c:918 src/sss_client/pam_sss.c:931 msgid "Password change failed. " msgstr "Ha fallat el canvi de contrasenya." -#: src/sss_client/pam_sss.c:1859 +#: src/sss_client/pam_sss.c:2028 #, c-format -msgid "Authenticate at %1$s and press ENTER." +msgid "Authenticate at \"%1$s\"." msgstr "" -#: src/sss_client/pam_sss.c:1862 +#: src/sss_client/pam_sss.c:2031 #, c-format -msgid "Authenticate with PIN %1$s at %2$s and press ENTER." +msgid "Authenticate with PIN \"%1$s\" at \"%2$s\"." msgstr "" -#: src/sss_client/pam_sss.c:2281 +#: src/sss_client/pam_sss.c:2470 msgid "Please (re)insert (different) Smartcard" msgstr "" -#: src/sss_client/pam_sss.c:2482 +#: src/sss_client/pam_sss.c:2700 msgid "New Password: " msgstr "Nova contrasenya: " -#: src/sss_client/pam_sss.c:2483 +#: src/sss_client/pam_sss.c:2701 msgid "Reenter new Password: " msgstr "Torneu a introduir la nova contrasenya: " -#: src/sss_client/pam_sss.c:2676 src/sss_client/pam_sss.c:2679 +#: src/sss_client/pam_sss.c:2890 +msgid "Press ENTER to continue." +msgstr "" + +#: src/sss_client/pam_sss.c:2913 src/sss_client/pam_sss.c:2916 msgid "First Factor: " msgstr "Primer factor:" -#: src/sss_client/pam_sss.c:2677 src/sss_client/pam_sss.c:2851 +#: src/sss_client/pam_sss.c:2914 src/sss_client/pam_sss.c:3088 msgid "Second Factor (optional): " msgstr "" -#: src/sss_client/pam_sss.c:2680 src/sss_client/pam_sss.c:2855 +#: src/sss_client/pam_sss.c:2917 src/sss_client/pam_sss.c:3092 msgid "Second Factor: " msgstr "Segon factor:" -#: src/sss_client/pam_sss.c:2684 +#: src/sss_client/pam_sss.c:2921 msgid "Insert your passkey device, then press ENTER." msgstr "" -#: src/sss_client/pam_sss.c:2688 src/sss_client/pam_sss.c:2696 +#: src/sss_client/pam_sss.c:2925 src/sss_client/pam_sss.c:2933 msgid "Password: " msgstr "Contrasenya: " -#: src/sss_client/pam_sss.c:2850 src/sss_client/pam_sss.c:2854 +#: src/sss_client/pam_sss.c:3087 src/sss_client/pam_sss.c:3091 msgid "First Factor (Current Password): " msgstr "" -#: src/sss_client/pam_sss.c:2874 +#: src/sss_client/pam_sss.c:3111 msgid "Current Password: " msgstr "Contrasenya actual: " -#: src/sss_client/pam_sss.c:3248 +#: src/sss_client/pam_sss.c:3485 msgid "Password expired. Change your password now." msgstr "La contrasenya ha vençut. Canvieu ara la vostra contrasenya." @@ -2675,9 +2725,9 @@ msgstr "" #: src/tools/sssctl/sssctl_cache.c:835 src/tools/sssctl/sssctl_cache.c:918 #: src/tools/sssctl/sssctl_cache.c:950 src/tools/sssctl/sssctl_cache.c:956 #: src/tools/sssctl/sssctl_cache.c:1010 src/tools/sssctl/sssctl_cache.c:1034 -#: src/tools/sssctl/sssctl_cache.c:1085 src/tools/sssctl/sssctl_cache.c:1194 -#: src/tools/sssctl/sssctl_cache.c:1229 src/tools/sssctl/sssctl_cache.c:1235 -#: src/tools/sssctl/sssctl_cache.c:1244 +#: src/tools/sssctl/sssctl_cache.c:1085 src/tools/sssctl/sssctl_cache.c:1195 +#: src/tools/sssctl/sssctl_cache.c:1230 src/tools/sssctl/sssctl_cache.c:1236 +#: src/tools/sssctl/sssctl_cache.c:1245 msgid "talloc failed\n" msgstr "" @@ -2751,26 +2801,26 @@ msgstr "" msgid "Unable to remove downloaded GPO files: %s\n" msgstr "" -#: src/tools/sssctl/sssctl_cache.c:1165 +#: src/tools/sssctl/sssctl_cache.c:1166 #, c-format msgid "Failed to fetch cache entry: %s\n" msgstr "" -#: src/tools/sssctl/sssctl_cache.c:1170 +#: src/tools/sssctl/sssctl_cache.c:1171 #, fuzzy msgid "Could not determine object domain\n" msgstr "No s'han pogut obrir els dominis disponibles\n" -#: src/tools/sssctl/sssctl_cache.c:1200 +#: src/tools/sssctl/sssctl_cache.c:1201 msgid "Could not find GUID attribute in GPO entry\n" msgstr "" -#: src/tools/sssctl/sssctl_cache.c:1206 +#: src/tools/sssctl/sssctl_cache.c:1207 #, c-format msgid "Failed to delete GPO: %s\n" msgstr "" -#: src/tools/sssctl/sssctl_cache.c:1210 +#: src/tools/sssctl/sssctl_cache.c:1211 #, c-format msgid "%s removed from cache\n" msgstr "" @@ -2858,39 +2908,39 @@ msgid "" "\"/my/path/sssd.conf\", the snippet dir \"/my/path/conf.d\" is used)" msgstr "" -#: src/tools/sssctl/sssctl_config.c:114 +#: src/tools/sssctl/sssctl_config.c:126 #, c-format msgid "File %1$s does not exist.\n" msgstr "" -#: src/tools/sssctl/sssctl_config.c:115 +#: src/tools/sssctl/sssctl_config.c:127 msgid "There is no configuration.\n" msgstr "" -#: src/tools/sssctl/sssctl_config.c:120 +#: src/tools/sssctl/sssctl_config.c:132 #, fuzzy, c-format msgid "Configuration validation failed: %s\n" msgstr "L'ordre post-delete ha fallat: %1$s\n" -#: src/tools/sssctl/sssctl_config.c:121 +#: src/tools/sssctl/sssctl_config.c:133 msgid "Run with high debug level to see details.\n" msgstr "" -#: src/tools/sssctl/sssctl_config.c:130 -msgid "Failed to run validators" +#: src/tools/sssctl/sssctl_config.c:142 +msgid "Failed to run validators\n" msgstr "" -#: src/tools/sssctl/sssctl_config.c:134 +#: src/tools/sssctl/sssctl_config.c:146 #, c-format msgid "Issues identified by validators: %zu\n" msgstr "" -#: src/tools/sssctl/sssctl_config.c:145 +#: src/tools/sssctl/sssctl_config.c:157 #, c-format msgid "Messages generated during configuration merging: %zu\n" msgstr "" -#: src/tools/sssctl/sssctl_config.c:158 +#: src/tools/sssctl/sssctl_config.c:170 #, c-format msgid "Used configuration snippet files: %zu\n" msgstr "" diff --git a/po/cs.po b/po/cs.po index 6611cffd452..5a2423dc20c 100644 --- a/po/cs.po +++ b/po/cs.po @@ -8,8 +8,8 @@ msgid "" msgstr "" "Project-Id-Version: PACKAGE VERSION\n" "Report-Msgid-Bugs-To: sssd-devel@lists.fedorahosted.org\n" -"POT-Creation-Date: 2026-01-14 14:57+0000\n" -"PO-Revision-Date: 2026-04-23 16:22+0000\n" +"POT-Creation-Date: 2026-10-02 15:57+0000\n" +"PO-Revision-Date: 2026-10-05 16:36+0000\n" "Last-Translator: Pavel Brezina \n" "Language-Team: Czech \n" @@ -18,52 +18,52 @@ msgstr "" "Content-Type: text/plain; charset=UTF-8\n" "Content-Transfer-Encoding: 8bit\n" "Plural-Forms: nplurals=3; plural=(n==1) ? 0 : (n>=2 && n<=4) ? 1 : 2;\n" -"X-Generator: Weblate 5.17\n" +"X-Generator: Weblate 2026.10\n" -#: src/config/SSSDConfig/sssdoptions.py:20 -#: src/config/SSSDConfig/sssdoptions.py:21 +#: src/config/SSSDConfig/sssdoptions.py:16 +#: src/config/SSSDConfig/sssdoptions.py:17 msgid "Set the verbosity of the debug logging" msgstr "Nastavit úroveň podrobnosti zaznamenávání ladících informací" -#: src/config/SSSDConfig/sssdoptions.py:22 +#: src/config/SSSDConfig/sssdoptions.py:18 msgid "Include timestamps in debug logs" msgstr "Zahrnout do ladících záznam časové značky" -#: src/config/SSSDConfig/sssdoptions.py:23 +#: src/config/SSSDConfig/sssdoptions.py:19 msgid "Include microseconds in timestamps in debug logs" msgstr "Zahrnout do časových značek v ladících záznamech mikrosekundy" -#: src/config/SSSDConfig/sssdoptions.py:24 +#: src/config/SSSDConfig/sssdoptions.py:20 msgid "Enable/disable debug backtrace" msgstr "Zap/vyp. ladící zpětné volání funkce (backtrace)" -#: src/config/SSSDConfig/sssdoptions.py:25 +#: src/config/SSSDConfig/sssdoptions.py:21 msgid "Watchdog timeout before restarting service" msgstr "Časová prodleva resetátoru (watchdog) před restartováním služby" -#: src/config/SSSDConfig/sssdoptions.py:26 +#: src/config/SSSDConfig/sssdoptions.py:22 msgid "Command to start service" msgstr "Příkaz pro spouštění služy" -#: src/config/SSSDConfig/sssdoptions.py:27 +#: src/config/SSSDConfig/sssdoptions.py:23 msgid "The number of file descriptors that may be opened by this responder" msgstr "Počet popisovačů souborů, které mohou tímto odpovídačem být otevřeny" -#: src/config/SSSDConfig/sssdoptions.py:28 +#: src/config/SSSDConfig/sssdoptions.py:24 msgid "Idle time before automatic disconnection of a client" msgstr "Doba nečinnosti, po které dojde k automatickému odpojení klienta" -#: src/config/SSSDConfig/sssdoptions.py:29 +#: src/config/SSSDConfig/sssdoptions.py:25 msgid "Idle time before automatic shutdown of the responder" msgstr "Doba nečinnosti, po které dojde k vypnutí odpovídače" -#: src/config/SSSDConfig/sssdoptions.py:30 +#: src/config/SSSDConfig/sssdoptions.py:26 msgid "Always query all the caches before querying the Data Providers" msgstr "" "Vždy dotazovat všechny vyrovnávací paměti před dotazováním poskytovatelů " "údajů" -#: src/config/SSSDConfig/sssdoptions.py:31 +#: src/config/SSSDConfig/sssdoptions.py:27 msgid "" "When SSSD switches to offline mode the amount of time before it tries to go " "back online will increase based upon the time spent disconnected. This value " @@ -75,23 +75,23 @@ msgstr "" "hodnota je v sekundách a je vypočítávána takto: offilne_timeout (časový " "limit pro bez připojení + random_offset (náhodný posun)." -#: src/config/SSSDConfig/sssdoptions.py:36 +#: src/config/SSSDConfig/sssdoptions.py:32 msgid "SSSD Services to start" msgstr "SSSD služby které spustit" -#: src/config/SSSDConfig/sssdoptions.py:37 +#: src/config/SSSDConfig/sssdoptions.py:33 msgid "SSSD Domains to start" msgstr "SSSD domény které spustit" -#: src/config/SSSDConfig/sssdoptions.py:38 +#: src/config/SSSDConfig/sssdoptions.py:34 msgid "Regex to parse username and domain" msgstr "Regulární výraz pro zpracování uživatelského jména a domény" -#: src/config/SSSDConfig/sssdoptions.py:39 +#: src/config/SSSDConfig/sssdoptions.py:35 msgid "Printf-compatible format for displaying fully-qualified names" msgstr "Formát kompatibilní s printf pro zobrazování úplných názvů" -#: src/config/SSSDConfig/sssdoptions.py:40 +#: src/config/SSSDConfig/sssdoptions.py:36 msgid "" "Directory on the filesystem where SSSD should store Kerberos replay cache " "files." @@ -99,37 +99,37 @@ msgstr "" "Složka na souborovém systému kde by SSSD mělo ukládat soubory pro kerberos " "replay." -#: src/config/SSSDConfig/sssdoptions.py:41 +#: src/config/SSSDConfig/sssdoptions.py:37 msgid "Domain to add to names without a domain component." msgstr "Doména kterou přidat k názvům bez doménové části." -#: src/config/SSSDConfig/sssdoptions.py:42 +#: src/config/SSSDConfig/sssdoptions.py:38 msgid "The user to drop privileges to" msgstr "Uživatel na kterého se stáhnout z oprávnění" -#: src/config/SSSDConfig/sssdoptions.py:43 +#: src/config/SSSDConfig/sssdoptions.py:39 msgid "Tune certificate verification" msgstr "Vyladit ověřování certifikátu" -#: src/config/SSSDConfig/sssdoptions.py:44 +#: src/config/SSSDConfig/sssdoptions.py:40 msgid "All spaces in group or user names will be replaced with this character" msgstr "" "Všechny mezery v názvech skupin a uživatelských jménech budou nahrazeny " "tímto znakem" -#: src/config/SSSDConfig/sssdoptions.py:45 +#: src/config/SSSDConfig/sssdoptions.py:41 msgid "Tune sssd to honor or ignore netlink state changes" msgstr "Vyladit sssd aby respektovalo nebo ignorovalo změny stavu netlink" -#: src/config/SSSDConfig/sssdoptions.py:46 +#: src/config/SSSDConfig/sssdoptions.py:42 msgid "Enable or disable the implicit files domain" msgstr "Zapnout nebo vypnout implicitní doménu založenou na souborech" -#: src/config/SSSDConfig/sssdoptions.py:47 +#: src/config/SSSDConfig/sssdoptions.py:43 msgid "A specific order of the domains to be looked up" msgstr "Konkrétní pořadí domén ve které je hledat" -#: src/config/SSSDConfig/sssdoptions.py:48 +#: src/config/SSSDConfig/sssdoptions.py:44 msgid "" "Controls if SSSD should monitor the state of resolv.conf to identify when it " "needs to update its internal DNS resolver." @@ -137,7 +137,7 @@ msgstr "" "Ovládá zda SSSD má sledovat stav resolv.conf a zjišťovat tak, zda je " "zapotřebí aktualizovat svůj vestavěný překlad DNS názvů." -#: src/config/SSSDConfig/sssdoptions.py:50 +#: src/config/SSSDConfig/sssdoptions.py:46 msgid "" "SSSD monitors the state of resolv.conf to identify when it needs to update " "its internal DNS resolver. By default, we will attempt to use inotify for " @@ -149,79 +149,79 @@ msgstr "" "používat pro toto inotify a pokud toto není možné, náhradně se resolv.conf " "dotazovat každých 5 sekund." -#: src/config/SSSDConfig/sssdoptions.py:53 +#: src/config/SSSDConfig/sssdoptions.py:49 msgid "Run PAC responder automatically for AD and IPA provider" msgstr "Pro AD a IPA poskytovatele spouštět PAC odpovídač automaticky" -#: src/config/SSSDConfig/sssdoptions.py:54 +#: src/config/SSSDConfig/sssdoptions.py:50 msgid "Enable or disable core dumps for all SSSD processes." msgstr "" "Zapnout nebo vypnout diagnostickému zapisování obsahu paměti pro všechny " "procesy SSSD." -#: src/config/SSSDConfig/sssdoptions.py:55 +#: src/config/SSSDConfig/sssdoptions.py:51 msgid "Tune passkey verification behavior" msgstr "Vyladění chování ověřování přístupových klíčů" -#: src/config/SSSDConfig/sssdoptions.py:58 +#: src/config/SSSDConfig/sssdoptions.py:54 msgid "Enumeration cache timeout length (seconds)" msgstr "Délka časového limitu mezipaměti vyčíslování (v sekundách)" -#: src/config/SSSDConfig/sssdoptions.py:59 +#: src/config/SSSDConfig/sssdoptions.py:55 msgid "Entry cache background update timeout length (seconds)" msgstr "" "Délka časového limitu aktualizace mezipaměti položek na pozadí (v sekundách)" -#: src/config/SSSDConfig/sssdoptions.py:60 -#: src/config/SSSDConfig/sssdoptions.py:125 +#: src/config/SSSDConfig/sssdoptions.py:56 +#: src/config/SSSDConfig/sssdoptions.py:124 msgid "Negative cache timeout length (seconds)" msgstr "Délka časového limitu záporné mezipaměti (v sekundách)" -#: src/config/SSSDConfig/sssdoptions.py:61 +#: src/config/SSSDConfig/sssdoptions.py:57 msgid "Users that SSSD should explicitly ignore" msgstr "Uživatelé, které by SSSD mělo výslovně ignorovat" -#: src/config/SSSDConfig/sssdoptions.py:62 +#: src/config/SSSDConfig/sssdoptions.py:58 msgid "Groups that SSSD should explicitly ignore" msgstr "Skupiny, které by SSSD mělo výslovně ignorovat" -#: src/config/SSSDConfig/sssdoptions.py:63 +#: src/config/SSSDConfig/sssdoptions.py:59 msgid "Should filtered users appear in groups" msgstr "Mají se filtrovaní uživatelé objevovat ve skupinách" -#: src/config/SSSDConfig/sssdoptions.py:64 +#: src/config/SSSDConfig/sssdoptions.py:60 msgid "The value of the password field the NSS provider should return" msgstr "Hodnota kolonky hesla kterou by poskytovatel NSS měl vrátit" -#: src/config/SSSDConfig/sssdoptions.py:65 +#: src/config/SSSDConfig/sssdoptions.py:61 msgid "Override homedir value from the identity provider with this value" msgstr "" "Přepsat hodnotu homedir (domovská složka), obdrženou z poskytovatele " "identit, touto hodnotou" -#: src/config/SSSDConfig/sssdoptions.py:66 +#: src/config/SSSDConfig/sssdoptions.py:62 msgid "" "Substitute empty homedir value from the identity provider with this value" msgstr "" "Nahradit prázdnou hodnotu homedir z poskytovatele identit touto hodnotou" -#: src/config/SSSDConfig/sssdoptions.py:67 +#: src/config/SSSDConfig/sssdoptions.py:63 msgid "Override shell value from the identity provider with this value" msgstr "" "Přepsat hodnotu shell, obdrženou z poskytovatele identit, touto hodnotou" -#: src/config/SSSDConfig/sssdoptions.py:68 +#: src/config/SSSDConfig/sssdoptions.py:64 msgid "The list of shells users are allowed to log in with" msgstr "" "Seznam uživatelů s přístupem do shellu, kterým je umožněno se přihlásit " "pomocí" -#: src/config/SSSDConfig/sssdoptions.py:69 +#: src/config/SSSDConfig/sssdoptions.py:65 msgid "" "The list of shells that will be vetoed, and replaced with the fallback shell" msgstr "Seznam shellů, které budou vetovány a nahrazeny náhradním" -#: src/config/SSSDConfig/sssdoptions.py:70 +#: src/config/SSSDConfig/sssdoptions.py:66 msgid "" "If a shell stored in central directory is allowed but not available, use " "this fallback" @@ -229,15 +229,15 @@ msgstr "" "Pokud shell uložený v centrálním adresáři je dovolen ale není k dispozici, " "použít tuto náhradu" -#: src/config/SSSDConfig/sssdoptions.py:71 +#: src/config/SSSDConfig/sssdoptions.py:67 msgid "Shell to use if the provider does not list one" msgstr "Shell který použít pokud poskytovatel žádný neuvádí" -#: src/config/SSSDConfig/sssdoptions.py:72 +#: src/config/SSSDConfig/sssdoptions.py:68 msgid "How long will be in-memory cache records valid" msgstr "Jak dlouho budou záznamy mezipaměti v paměti platné" -#: src/config/SSSDConfig/sssdoptions.py:74 +#: src/config/SSSDConfig/sssdoptions.py:70 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for passwd requests" @@ -245,7 +245,7 @@ msgstr "" "Velikost (v megabajtech) datové tabulky přidělené v rychlé mezipaměti v " "operační paměti pro požadavky z passwd" -#: src/config/SSSDConfig/sssdoptions.py:76 +#: src/config/SSSDConfig/sssdoptions.py:72 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for group requests" @@ -253,7 +253,7 @@ msgstr "" "Velikost (v megabajtech) datové tabulky přidělené v rychlé mezipaměti v " "operační paměti pro požadavky z group" -#: src/config/SSSDConfig/sssdoptions.py:78 +#: src/config/SSSDConfig/sssdoptions.py:74 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for initgroups requests" @@ -261,7 +261,7 @@ msgstr "" "Velikost (v megabajtech) datové tabulky přidělené v rychlé mezipaměti v " "operační paměti pro požadavky z initgroups" -#: src/config/SSSDConfig/sssdoptions.py:79 +#: src/config/SSSDConfig/sssdoptions.py:75 msgid "" "The value of this option will be used in the expansion of the " "override_homedir option if the template contains the format string %H." @@ -269,7 +269,7 @@ msgstr "" "Hodnota této volby bude použita v rozšíření volby override_homedir, pokud " "šablona obsahuje formátovací řetězec %H." -#: src/config/SSSDConfig/sssdoptions.py:81 +#: src/config/SSSDConfig/sssdoptions.py:77 msgid "" "Specifies time in seconds for which the list of subdomains will be " "considered valid." @@ -277,7 +277,7 @@ msgstr "" "Určuje dobu (v sekundách) po které bude seznam dílčích domén považován za " "platný." -#: src/config/SSSDConfig/sssdoptions.py:83 +#: src/config/SSSDConfig/sssdoptions.py:79 msgid "" "The entry cache can be set to automatically update entries in the background " "if they are requested beyond a percentage of the entry_cache_timeout value " @@ -287,17 +287,17 @@ msgstr "" "pozadí, pokud jsou požadovány za procentem hodnoty entry_cache_timeout pro " "doménu." -#: src/config/SSSDConfig/sssdoptions.py:88 +#: src/config/SSSDConfig/sssdoptions.py:84 msgid "How long to allow cached logins between online logins (days)" msgstr "" "Po jak dlouho umožnit přihlášení vůči mezipaměti do přihlášení při připojení " "(dny)" -#: src/config/SSSDConfig/sssdoptions.py:89 +#: src/config/SSSDConfig/sssdoptions.py:85 msgid "How many failed logins attempts are allowed when offline" msgstr "Kolik nezdařených pokusů o přihlášení je dovoleno bez připojení" -#: src/config/SSSDConfig/sssdoptions.py:91 +#: src/config/SSSDConfig/sssdoptions.py:87 msgid "" "How long (minutes) to deny login after offline_failed_login_attempts has " "been reached" @@ -305,86 +305,86 @@ msgstr "" "Jak dlouho (v minutách) odpírat přihlášení po dosažení " "offline_failed_login_attempts" -#: src/config/SSSDConfig/sssdoptions.py:92 +#: src/config/SSSDConfig/sssdoptions.py:88 msgid "What kind of messages are displayed to the user during authentication" msgstr "Jaký druh zpráv je zobrazován při ověřování uživatele" -#: src/config/SSSDConfig/sssdoptions.py:93 +#: src/config/SSSDConfig/sssdoptions.py:89 msgid "Filter PAM responses sent to the pam_sss" msgstr "Filtrovat PAM odpovědi poslané pam_sss" -#: src/config/SSSDConfig/sssdoptions.py:94 +#: src/config/SSSDConfig/sssdoptions.py:90 msgid "How many seconds to keep identity information cached for PAM requests" msgstr "" "Kolik sekund si ponechávat informace o identitě v mezipaměti pro PAM " "požadavky" -#: src/config/SSSDConfig/sssdoptions.py:95 +#: src/config/SSSDConfig/sssdoptions.py:91 msgid "How many days before password expiration a warning should be displayed" msgstr "Kolik dnů před skončením platnosti hesla má být zobrazováno varování" -#: src/config/SSSDConfig/sssdoptions.py:96 +#: src/config/SSSDConfig/sssdoptions.py:92 msgid "List of trusted uids or user's name" msgstr "Seznam důvěryhodných identifikátorů uživatelů nebo uživatelských jmen" -#: src/config/SSSDConfig/sssdoptions.py:97 +#: src/config/SSSDConfig/sssdoptions.py:93 msgid "List of domains accessible even for untrusted users." msgstr "Seznam domén přístupných i nedůvěryhodným uživatelům." -#: src/config/SSSDConfig/sssdoptions.py:98 +#: src/config/SSSDConfig/sssdoptions.py:94 msgid "Message printed when user account is expired." msgstr "Zpráva vypsaná když platnost uživatelského účtu skončila." -#: src/config/SSSDConfig/sssdoptions.py:99 +#: src/config/SSSDConfig/sssdoptions.py:95 msgid "Message printed when user account is locked." msgstr "Zpráva vypisovaná když je účet uživatele uzamčen." -#: src/config/SSSDConfig/sssdoptions.py:100 +#: src/config/SSSDConfig/sssdoptions.py:96 msgid "Allow certificate based/Smartcard authentication." msgstr "Umožnit ověřování založené na certifikátu/Smartcard." -#: src/config/SSSDConfig/sssdoptions.py:101 +#: src/config/SSSDConfig/sssdoptions.py:97 msgid "Path to certificate database with PKCS#11 modules." msgstr "Popis umístění databáze certifikátů s PKCS#11 moduly." -#: src/config/SSSDConfig/sssdoptions.py:102 +#: src/config/SSSDConfig/sssdoptions.py:98 msgid "Tune certificate verification for PAM authentication." msgstr "Vyladit ověřování certifikátu pro PAM ověřování." -#: src/config/SSSDConfig/sssdoptions.py:103 +#: src/config/SSSDConfig/sssdoptions.py:99 msgid "How many seconds will pam_sss wait for p11_child to finish" msgstr "Kolik sekund bude pam_sss čekat na dokončení p11_child" -#: src/config/SSSDConfig/sssdoptions.py:104 +#: src/config/SSSDConfig/sssdoptions.py:100 msgid "Which PAM services are permitted to contact application domains" msgstr "Kterým PAM službám je umožněno kontaktovat aplikační domény" -#: src/config/SSSDConfig/sssdoptions.py:105 +#: src/config/SSSDConfig/sssdoptions.py:101 msgid "Allowed services for using smartcards" msgstr "Aplikace které je možné použít se SmartCard kartami" -#: src/config/SSSDConfig/sssdoptions.py:106 +#: src/config/SSSDConfig/sssdoptions.py:102 msgid "Additional timeout to wait for a card if requested" msgstr "Dodatečný časový limit po který čekat pokud je vyžádána karta" -#: src/config/SSSDConfig/sssdoptions.py:107 +#: src/config/SSSDConfig/sssdoptions.py:103 msgid "" "PKCS#11 URI to restrict the selection of devices for Smartcard authentication" msgstr "PKCS#11 URI pro omezení výběru zařízení pro ověřování pomocí Smartcard" -#: src/config/SSSDConfig/sssdoptions.py:108 +#: src/config/SSSDConfig/sssdoptions.py:104 msgid "When shall the PAM responder force an initgroups request" msgstr "Kdy má PAM odpovídač vynutit initgroups požadavek" -#: src/config/SSSDConfig/sssdoptions.py:109 +#: src/config/SSSDConfig/sssdoptions.py:105 msgid "List of PAM services that are allowed to authenticate with GSSAPI." msgstr "Seznam PAM služeb, kterým je dovoleno ověřovat pomocí GSSAPI." -#: src/config/SSSDConfig/sssdoptions.py:110 +#: src/config/SSSDConfig/sssdoptions.py:106 msgid "Whether to match authenticated UPN with target user" msgstr "Zda hledat shodu ověřených UPN a cílového uživatele" -#: src/config/SSSDConfig/sssdoptions.py:111 +#: src/config/SSSDConfig/sssdoptions.py:107 msgid "" "List of pairs : that must be enforced " "for PAM access with GSSAPI authentication" @@ -393,31 +393,42 @@ msgstr "" "ověření), které je třeba vynutit pro přístup prostřednictvím PAM s GSSAPI " "ověřováním" -#: src/config/SSSDConfig/sssdoptions.py:113 +#: src/config/SSSDConfig/sssdoptions.py:109 +#, fuzzy +msgid "" +"List of triples :: that assigns " +"additional information from the Kerberos ticket to an authentication " +"indicator." +msgstr "" +"Seznam dvojic : (PAM služba:indikátor " +"ověření), které je třeba vynutit pro přístup prostřednictvím PAM s GSSAPI " +"ověřováním" + +#: src/config/SSSDConfig/sssdoptions.py:112 msgid "Allow passkey device authentication." msgstr "Umožnit ověřování založené na certifikátu/Smartcard." -#: src/config/SSSDConfig/sssdoptions.py:114 +#: src/config/SSSDConfig/sssdoptions.py:113 msgid "How many seconds will pam_sss wait for passkey_child to finish" msgstr "Kolik sekund bude pam_sss čekat na dokončení passkey_child" -#: src/config/SSSDConfig/sssdoptions.py:115 +#: src/config/SSSDConfig/sssdoptions.py:114 msgid "Enable debugging in the libfido2 library" msgstr "Povolení ladění v knihovně libfido2" -#: src/config/SSSDConfig/sssdoptions.py:116 +#: src/config/SSSDConfig/sssdoptions.py:115 msgid "Enable JSON protocol for authentication methods selection." msgstr "Zapnout JSON protokol pro výběr způsobů ověřování se." -#: src/config/SSSDConfig/sssdoptions.py:119 +#: src/config/SSSDConfig/sssdoptions.py:118 msgid "Whether to evaluate the time-based attributes in sudo rules" msgstr "Zda vyhodnocovat na času založené atributy v pravidlech sudo" -#: src/config/SSSDConfig/sssdoptions.py:120 +#: src/config/SSSDConfig/sssdoptions.py:119 msgid "If true, SSSD will switch back to lower-wins ordering logic" msgstr "Pokud je zapnuto, SSSD přepne zpět na logiku řazení nižší vyhrává" -#: src/config/SSSDConfig/sssdoptions.py:121 +#: src/config/SSSDConfig/sssdoptions.py:120 msgid "" "Maximum number of rules that can be refreshed at once. If this is exceeded, " "full refresh is performed." @@ -425,11 +436,11 @@ msgstr "" "Nejvyšší umožněný počet pravidel, aktualizovaných naráz. Pokud je toto " "překročeno, je provedena úplná aktualizace." -#: src/config/SSSDConfig/sssdoptions.py:128 +#: src/config/SSSDConfig/sssdoptions.py:127 msgid "Whether to hash host names and addresses in the known_hosts file" msgstr "Zda v souboru known_hosts vytvářet otisk názvů strojů a adres" -#: src/config/SSSDConfig/sssdoptions.py:129 +#: src/config/SSSDConfig/sssdoptions.py:128 msgid "" "How many seconds to keep a host in the known_hosts file after its host keys " "were requested" @@ -437,15 +448,15 @@ msgstr "" "Kolik sekund ponechávat stroj v souboru known_hosts poté, co byly vyžádány " "klíče stroje" -#: src/config/SSSDConfig/sssdoptions.py:131 +#: src/config/SSSDConfig/sssdoptions.py:130 msgid "Path to storage of trusted CA certificates" msgstr "Popis umístění úložiště certifikátů důvěryhodných cert. autorit" -#: src/config/SSSDConfig/sssdoptions.py:132 +#: src/config/SSSDConfig/sssdoptions.py:131 msgid "Allow to generate ssh-keys from certificates" msgstr "Umožnit vytváření ssh klíčů z certifikátů" -#: src/config/SSSDConfig/sssdoptions.py:133 +#: src/config/SSSDConfig/sssdoptions.py:132 msgid "" "Use the following matching rules to filter the certificates for ssh-key " "generation" @@ -453,25 +464,25 @@ msgstr "" "Použít následující pravidla pro hledání shod pro filtrování certifikátů pro " "vytváření ssh-klíče" -#: src/config/SSSDConfig/sssdoptions.py:137 +#: src/config/SSSDConfig/sssdoptions.py:136 msgid "List of UIDs or user names allowed to access the PAC responder" msgstr "" "Seznam UID nebo uživatelských jmen, kterým je umožněn přístup k PAC " "odpovídači" -#: src/config/SSSDConfig/sssdoptions.py:138 +#: src/config/SSSDConfig/sssdoptions.py:137 msgid "How long the PAC data is considered valid" msgstr "Po jak dlouho jsou PAC data považována za platná" -#: src/config/SSSDConfig/sssdoptions.py:139 +#: src/config/SSSDConfig/sssdoptions.py:138 msgid "Validate the PAC" msgstr "Ověřovat PAC" -#: src/config/SSSDConfig/sssdoptions.py:142 +#: src/config/SSSDConfig/sssdoptions.py:141 msgid "List of user attributes the InfoPipe is allowed to publish" msgstr "Seznam atributů uživatele, které InfoPipe bude moci zveřejnit" -#: src/config/SSSDConfig/sssdoptions.py:145 +#: src/config/SSSDConfig/sssdoptions.py:144 msgid "" "One of the following strings specifying the scope of session recording: none " "- No users are recorded. some - Users/groups specified by users and groups " @@ -482,7 +493,7 @@ msgstr "" "skupiny, určení volbou uživatelů a skupiny jsou zaznamenání. all (vše) – " "zaznamenáni jsou všichni uživatelé." -#: src/config/SSSDConfig/sssdoptions.py:148 +#: src/config/SSSDConfig/sssdoptions.py:147 msgid "" "A comma-separated list of users which should have session recording enabled. " "Matches user names as returned by NSS. I.e. after the possible space " @@ -492,7 +503,7 @@ msgstr "" "Shodující se uživatelská jména jsou vrácena z NSS. T.j. po možném nahrazení " "mezer, změně velikosti písmen, atd." -#: src/config/SSSDConfig/sssdoptions.py:150 +#: src/config/SSSDConfig/sssdoptions.py:149 msgid "" "A comma-separated list of groups, members of which should have session " "recording enabled. Matches group names as returned by NSS. I.e. after the " @@ -502,7 +513,7 @@ msgstr "" "relace. Odpovídající názvy skupin jsou vráceny z NSS. Tj. po možném " "nahrazení mezer, změn velikosti písmen, atd." -#: src/config/SSSDConfig/sssdoptions.py:153 +#: src/config/SSSDConfig/sssdoptions.py:152 msgid "" "A comma-separated list of users to be excluded from recording, only when " "scope=all" @@ -510,7 +521,7 @@ msgstr "" "Čárkou oddělovaný seznam uživatelů, které vyjmout ze zaznamenávání, pouze " "pokud scope=all (rozsah=vše)" -#: src/config/SSSDConfig/sssdoptions.py:154 +#: src/config/SSSDConfig/sssdoptions.py:153 msgid "" "A comma-separated list of groups, members of which should be excluded from " "recording, only when scope=all. " @@ -518,80 +529,80 @@ msgstr "" "Čárkou oddělovaný seznam skupin, dále členů, které vyjmout ze zaznamenávání, " "pouze pokud je scope=all (rozsah=vše). " -#: src/config/SSSDConfig/sssdoptions.py:158 +#: src/config/SSSDConfig/sssdoptions.py:157 msgid "Identity provider" msgstr "Poskytovatel identity" -#: src/config/SSSDConfig/sssdoptions.py:159 +#: src/config/SSSDConfig/sssdoptions.py:158 msgid "Authentication provider" msgstr "Poskytovatel ověřování" -#: src/config/SSSDConfig/sssdoptions.py:160 +#: src/config/SSSDConfig/sssdoptions.py:159 msgid "Access control provider" msgstr "Poskytovatel řízení přístupu" -#: src/config/SSSDConfig/sssdoptions.py:161 +#: src/config/SSSDConfig/sssdoptions.py:160 msgid "Password change provider" msgstr "Poskytovatel změny hesel" -#: src/config/SSSDConfig/sssdoptions.py:162 +#: src/config/SSSDConfig/sssdoptions.py:161 msgid "SUDO provider" msgstr "Poskytovatel SUDO" -#: src/config/SSSDConfig/sssdoptions.py:163 +#: src/config/SSSDConfig/sssdoptions.py:162 msgid "Autofs provider" msgstr "Poskytovatel autofs" -#: src/config/SSSDConfig/sssdoptions.py:164 +#: src/config/SSSDConfig/sssdoptions.py:163 msgid "Host identity provider" msgstr "Poskytovatel identity strojů" -#: src/config/SSSDConfig/sssdoptions.py:165 +#: src/config/SSSDConfig/sssdoptions.py:164 msgid "SELinux provider" msgstr "Poskytovatel SELinux" -#: src/config/SSSDConfig/sssdoptions.py:166 +#: src/config/SSSDConfig/sssdoptions.py:165 msgid "Session management provider" msgstr "Poskytovatel správy sezení" -#: src/config/SSSDConfig/sssdoptions.py:167 +#: src/config/SSSDConfig/sssdoptions.py:166 msgid "Resolver provider" msgstr "Poskytovatel překladu (resolver)" -#: src/config/SSSDConfig/sssdoptions.py:170 +#: src/config/SSSDConfig/sssdoptions.py:169 msgid "Whether the domain is usable by the OS or by applications" msgstr "Zda je doména použitelná pro operační systém nebo aplikace" -#: src/config/SSSDConfig/sssdoptions.py:171 +#: src/config/SSSDConfig/sssdoptions.py:170 msgid "Enable or disable the domain" msgstr "Povolit nebo zakázat doménu" -#: src/config/SSSDConfig/sssdoptions.py:172 +#: src/config/SSSDConfig/sssdoptions.py:171 msgid "Minimum user ID" msgstr "Nejnižší identif. uživatele" -#: src/config/SSSDConfig/sssdoptions.py:173 +#: src/config/SSSDConfig/sssdoptions.py:172 msgid "Maximum user ID" msgstr "Nejvyšší identif. uživatele" -#: src/config/SSSDConfig/sssdoptions.py:174 +#: src/config/SSSDConfig/sssdoptions.py:173 msgid "Enable enumerating all users/groups" msgstr "Zapnout vyčíslování všech uživatelů/skupin" -#: src/config/SSSDConfig/sssdoptions.py:175 +#: src/config/SSSDConfig/sssdoptions.py:174 msgid "Cache credentials for offline login" msgstr "" "Ukládat přihlašovací údaje do mezipaměti pro přihlašování se bez připojení" -#: src/config/SSSDConfig/sssdoptions.py:176 +#: src/config/SSSDConfig/sssdoptions.py:175 msgid "Display users/groups in fully-qualified form" msgstr "Zobrazovat uživatele/skupiny v úplné podobě" -#: src/config/SSSDConfig/sssdoptions.py:177 +#: src/config/SSSDConfig/sssdoptions.py:176 msgid "Don't include group members in group lookups" msgstr "Nezahrnovat členy skupiny do hledání skupiny" -#: src/config/SSSDConfig/sssdoptions.py:178 +#: src/config/SSSDConfig/sssdoptions.py:177 #: src/config/SSSDConfig/sssdoptions.py:190 #: src/config/SSSDConfig/sssdoptions.py:191 #: src/config/SSSDConfig/sssdoptions.py:192 @@ -602,19 +613,19 @@ msgstr "Nezahrnovat členy skupiny do hledání skupiny" msgid "Entry cache timeout length (seconds)" msgstr "Délka časového limitu položky (v sekundách)" -#: src/config/SSSDConfig/sssdoptions.py:179 +#: src/config/SSSDConfig/sssdoptions.py:178 msgid "" "Restrict or prefer a specific address family when performing DNS lookups" msgstr "" "Omezit nebo upřednostnit konkrétní generaci adres při provádění DNS hledání" -#: src/config/SSSDConfig/sssdoptions.py:180 +#: src/config/SSSDConfig/sssdoptions.py:179 msgid "How long to keep cached entries after last successful login (days)" msgstr "" "Jak dlouho si ponechávat položky v mezipaměti po posledním úspěšném " "přihlášení (dny)" -#: src/config/SSSDConfig/sssdoptions.py:181 +#: src/config/SSSDConfig/sssdoptions.py:180 msgid "" "How long should SSSD talk to single DNS server before trying next server " "(miliseconds)" @@ -622,19 +633,19 @@ msgstr "" "Jak dlouho se má SSSD pokoušet komunikovat s jedním DNS serverem, než " "vyzkouší další server (v milisekundách)" -#: src/config/SSSDConfig/sssdoptions.py:183 +#: src/config/SSSDConfig/sssdoptions.py:182 msgid "How long should keep trying to resolve single DNS query (seconds)" msgstr "Jak dlouho se pokoušet přeložit jeden DNS dotaz (sekundy)" -#: src/config/SSSDConfig/sssdoptions.py:184 +#: src/config/SSSDConfig/sssdoptions.py:183 msgid "How long to wait for replies from DNS when resolving servers (seconds)" msgstr "Jak dlouho čekat na odpovědi z DNS při překládání serverů (sekundy)" -#: src/config/SSSDConfig/sssdoptions.py:185 +#: src/config/SSSDConfig/sssdoptions.py:184 msgid "The domain part of service discovery DNS query" msgstr "Doménová část DNS dotazu pro objevování služby" -#: src/config/SSSDConfig/sssdoptions.py:186 +#: src/config/SSSDConfig/sssdoptions.py:185 msgid "" "Specifies the interval, in seconds, that SSSD waits before attempting to " "reconnect to the primary server after a successful connection to the backup " @@ -643,14 +654,18 @@ msgstr "" "Určuje interval v sekundách, po kterém SSSD čeká, než se pokusí znovu " "připojit k primárnímu serveru po úspěšném připojení k záložnímu serveru" -#: src/config/SSSDConfig/sssdoptions.py:188 +#: src/config/SSSDConfig/sssdoptions.py:187 msgid "Override GID value from the identity provider with this value" msgstr "Přebít hodnotu GID z poskytovatele identit touto hodnotou" -#: src/config/SSSDConfig/sssdoptions.py:189 +#: src/config/SSSDConfig/sssdoptions.py:188 msgid "Treat usernames as case sensitive" msgstr "U uživatelských jmen rozlišovat velká a malá písmena" +#: src/config/SSSDConfig/sssdoptions.py:189 +msgid "Lookups by ID are expensive or do not work at all" +msgstr "" + #: src/config/SSSDConfig/sssdoptions.py:197 msgid "How often should expired entries be refreshed in background" msgstr "" @@ -684,7 +699,8 @@ msgstr "Rozhraní, kterého IP adresu použít pro dynamickou aktualizaci DNS" #: src/config/SSSDConfig/sssdoptions.py:204 msgid "The list of IP addresses that should be used for dynamic DNS updates" -msgstr "Seznam IP adres, které mají být použity pro aktualizace dynamického DNS" +msgstr "" +"Seznam IP adres, které mají být použity pro aktualizace dynamického DNS" #: src/config/SSSDConfig/sssdoptions.py:205 msgid "How often to periodically update the client's DNS entry" @@ -895,7 +911,7 @@ msgid "Search base for SUBID ranges" msgstr "Základ hledání pro SUBID rozsahy" #: src/config/SSSDConfig/sssdoptions.py:259 -#: src/config/SSSDConfig/sssdoptions.py:506 +#: src/config/SSSDConfig/sssdoptions.py:512 msgid "Which rules should be used to evaluate access control" msgstr "Která pravidla by měla být použita pro vyhodnocení řízení přístupu" @@ -1056,7 +1072,7 @@ msgid "Enable DNS sites - location based service discovery" msgstr "Zapnout DNS sites – na umístění založené objevování služby" #: src/config/SSSDConfig/sssdoptions.py:301 -#: src/config/SSSDConfig/sssdoptions.py:504 +#: src/config/SSSDConfig/sssdoptions.py:510 msgid "LDAP filter to determine access privileges" msgstr "LDAP filtr pro zjišťování přístupových oprávnění" @@ -1182,7 +1198,8 @@ msgstr "Umístění mezipaměti přihlašovacích údajů uživatele" #: src/config/SSSDConfig/sssdoptions.py:335 msgid "Location of the keytab to validate credentials" -msgstr "Umístění uložených přihlašovacích údajů pro ověřování ověřovacích údajů" +msgstr "" +"Umístění uložených přihlašovacích údajů pro ověřování ověřovacích údajů" #: src/config/SSSDConfig/sssdoptions.py:336 msgid "Enable credential validation" @@ -1497,7 +1514,7 @@ msgid "UUID attribute" msgstr "Atribut obsahující UUID" #: src/config/SSSDConfig/sssdoptions.py:423 -#: src/config/SSSDConfig/sssdoptions.py:464 +#: src/config/SSSDConfig/sssdoptions.py:470 msgid "objectSID attribute" msgstr "Atribut obsahující objectSID" @@ -1623,202 +1640,231 @@ msgstr "atribut obsahující data mapování passkey uživatele" msgid "A list of extra attributes to download along with the user entry" msgstr "Seznam dalších atributů, které stáhnout společně s položkou uživatele" +#: src/config/SSSDConfig/sssdoptions.py:456 +#, fuzzy +msgid "The object class of an subid entry in LDAP." +msgstr "Třída objektu položky hostitele v LDAP." + #: src/config/SSSDConfig/sssdoptions.py:457 +#, fuzzy +msgid "Subordinate user ID count attribute" +msgstr "Atribut uživatel sudo pravidla" + +#: src/config/SSSDConfig/sssdoptions.py:458 +#, fuzzy +msgid "Subordinate group ID count attribute" +msgstr "Atribut volba sudo pravidla" + +#: src/config/SSSDConfig/sssdoptions.py:459 +#, fuzzy +msgid "User ID range start value attribute" +msgstr "Atribut uživatelské jméno" + +#: src/config/SSSDConfig/sssdoptions.py:460 +#, fuzzy +msgid "Group ID range start value attribute" +msgstr "atribut UUID skupiny" + +#: src/config/SSSDConfig/sssdoptions.py:461 +msgid "Owner of an entry" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:463 msgid "Base DN for group lookups" msgstr "Základ rozliš. názvu pro vyhledávání skupin" -#: src/config/SSSDConfig/sssdoptions.py:458 +#: src/config/SSSDConfig/sssdoptions.py:464 msgid "Objectclass for groups" msgstr "Objektová třída pro skupiny" -#: src/config/SSSDConfig/sssdoptions.py:459 +#: src/config/SSSDConfig/sssdoptions.py:465 msgid "Group name" msgstr "Název skupiny" -#: src/config/SSSDConfig/sssdoptions.py:460 +#: src/config/SSSDConfig/sssdoptions.py:466 msgid "Group password" msgstr "Heslo skupiny" -#: src/config/SSSDConfig/sssdoptions.py:461 +#: src/config/SSSDConfig/sssdoptions.py:467 msgid "GID attribute" msgstr "Atribut GID" -#: src/config/SSSDConfig/sssdoptions.py:462 +#: src/config/SSSDConfig/sssdoptions.py:468 msgid "Group member attribute" msgstr "Atribut člen skupin" -#: src/config/SSSDConfig/sssdoptions.py:463 +#: src/config/SSSDConfig/sssdoptions.py:469 msgid "Group UUID attribute" msgstr "atribut UUID skupiny" -#: src/config/SSSDConfig/sssdoptions.py:465 +#: src/config/SSSDConfig/sssdoptions.py:471 msgid "Modification time attribute for groups" msgstr "Atribut okamžik úpravy pro skupiny" -#: src/config/SSSDConfig/sssdoptions.py:466 +#: src/config/SSSDConfig/sssdoptions.py:472 msgid "Type of the group and other flags" msgstr "Typ skupiny a ostatní příznaky" -#: src/config/SSSDConfig/sssdoptions.py:467 +#: src/config/SSSDConfig/sssdoptions.py:473 msgid "The LDAP group external member attribute" msgstr "Atribut externí člen LDAP skupiny" -#: src/config/SSSDConfig/sssdoptions.py:468 +#: src/config/SSSDConfig/sssdoptions.py:474 msgid "Maximum nesting level SSSD will follow" msgstr "Do kolikáté úrovně vnoření bude SSSD následovat" -#: src/config/SSSDConfig/sssdoptions.py:469 +#: src/config/SSSDConfig/sssdoptions.py:475 msgid "Filter for group lookups" msgstr "Filtr pro hledání skupin" -#: src/config/SSSDConfig/sssdoptions.py:470 +#: src/config/SSSDConfig/sssdoptions.py:476 msgid "Scope of group lookups" msgstr "Rozsah hledání skupin" -#: src/config/SSSDConfig/sssdoptions.py:472 +#: src/config/SSSDConfig/sssdoptions.py:478 msgid "Base DN for netgroup lookups" msgstr "Základ rozlišeného názvu pro vyhledávání negroup" -#: src/config/SSSDConfig/sssdoptions.py:473 +#: src/config/SSSDConfig/sssdoptions.py:479 msgid "Objectclass for netgroups" msgstr "Objektová třída pro netgroup" -#: src/config/SSSDConfig/sssdoptions.py:474 +#: src/config/SSSDConfig/sssdoptions.py:480 msgid "Netgroup name" msgstr "Negroup název" -#: src/config/SSSDConfig/sssdoptions.py:475 +#: src/config/SSSDConfig/sssdoptions.py:481 msgid "Netgroups members attribute" msgstr "Atribut členové negroup" -#: src/config/SSSDConfig/sssdoptions.py:476 +#: src/config/SSSDConfig/sssdoptions.py:482 msgid "Netgroup triple attribute" msgstr "Atribut trojitý netgroup" -#: src/config/SSSDConfig/sssdoptions.py:477 +#: src/config/SSSDConfig/sssdoptions.py:483 msgid "Modification time attribute for netgroups" msgstr "Atribut okamžik změny pro netgroup" -#: src/config/SSSDConfig/sssdoptions.py:479 +#: src/config/SSSDConfig/sssdoptions.py:485 msgid "Base DN for service lookups" msgstr "Základ rozliš. názvu pro hledání služeb" -#: src/config/SSSDConfig/sssdoptions.py:480 +#: src/config/SSSDConfig/sssdoptions.py:486 msgid "Objectclass for services" msgstr "Objektová třída pro služby" -#: src/config/SSSDConfig/sssdoptions.py:481 +#: src/config/SSSDConfig/sssdoptions.py:487 msgid "Service name attribute" msgstr "Atribut název služby" -#: src/config/SSSDConfig/sssdoptions.py:482 +#: src/config/SSSDConfig/sssdoptions.py:488 msgid "Service port attribute" msgstr "Atribut port služby" -#: src/config/SSSDConfig/sssdoptions.py:483 +#: src/config/SSSDConfig/sssdoptions.py:489 msgid "Service protocol attribute" msgstr "Atribut protokol služby" -#: src/config/SSSDConfig/sssdoptions.py:485 +#: src/config/SSSDConfig/sssdoptions.py:491 msgid "Lower bound for ID-mapping" msgstr "Spodní spojení pro mapování identifikátorů" -#: src/config/SSSDConfig/sssdoptions.py:486 +#: src/config/SSSDConfig/sssdoptions.py:492 msgid "Upper bound for ID-mapping" msgstr "Horní spojení pro mapování identifikátorů" -#: src/config/SSSDConfig/sssdoptions.py:487 +#: src/config/SSSDConfig/sssdoptions.py:493 msgid "Number of IDs for each slice when ID-mapping" msgstr "Počet identifikátorů pro každý plátek při mapování identifikátorů" -#: src/config/SSSDConfig/sssdoptions.py:488 +#: src/config/SSSDConfig/sssdoptions.py:494 msgid "Use autorid-compatible algorithm for ID-mapping" msgstr "Použít pro mapování identifikátorů algoritmus kompatibilní s autorid" -#: src/config/SSSDConfig/sssdoptions.py:489 +#: src/config/SSSDConfig/sssdoptions.py:495 msgid "Name of the default domain for ID-mapping" msgstr "Název výchozí domény pro mapování identifikátorů" -#: src/config/SSSDConfig/sssdoptions.py:490 +#: src/config/SSSDConfig/sssdoptions.py:496 msgid "SID of the default domain for ID-mapping" msgstr "SID výchozí domény pro mapování identifikátorů" -#: src/config/SSSDConfig/sssdoptions.py:491 +#: src/config/SSSDConfig/sssdoptions.py:497 msgid "Number of secondary slices" msgstr "Počet sekundárních plátků" -#: src/config/SSSDConfig/sssdoptions.py:493 +#: src/config/SSSDConfig/sssdoptions.py:499 msgid "Whether to use Token-Groups" msgstr "Zda používat skupiny tokenu" -#: src/config/SSSDConfig/sssdoptions.py:494 +#: src/config/SSSDConfig/sssdoptions.py:500 msgid "Set lower boundary for allowed IDs from the LDAP server" msgstr "Nastavit spodní hranici pro umožněné identifikátory z LDAP serveru" -#: src/config/SSSDConfig/sssdoptions.py:495 +#: src/config/SSSDConfig/sssdoptions.py:501 msgid "Set upper boundary for allowed IDs from the LDAP server" msgstr "Nastavit horní hranici pro umožněné identifikátory z LDAP serveru" -#: src/config/SSSDConfig/sssdoptions.py:496 +#: src/config/SSSDConfig/sssdoptions.py:502 msgid "DN for ppolicy queries" msgstr "Rozlišený název pro ppolicy dotazy" -#: src/config/SSSDConfig/sssdoptions.py:497 +#: src/config/SSSDConfig/sssdoptions.py:503 msgid "How many maximum entries to fetch during a wildcard request" msgstr "Kolik nejvýše položek získat při požadavku se zástupnými znaky" -#: src/config/SSSDConfig/sssdoptions.py:498 +#: src/config/SSSDConfig/sssdoptions.py:504 msgid "Set libldap debug level" msgstr "Nastavit úroveň podrobností ladících informací z knihovny libldap" -#: src/config/SSSDConfig/sssdoptions.py:501 +#: src/config/SSSDConfig/sssdoptions.py:507 msgid "Policy to evaluate the password expiration" msgstr "Pravidlo pro vyhodnocení skončení platnosti hesla" -#: src/config/SSSDConfig/sssdoptions.py:505 +#: src/config/SSSDConfig/sssdoptions.py:511 msgid "Which attributes shall be used to evaluate if an account is expired" msgstr "" "Jaké atributy mají být použity pro vyhodnocování zda platnost účtu skončila" -#: src/config/SSSDConfig/sssdoptions.py:509 +#: src/config/SSSDConfig/sssdoptions.py:515 msgid "URI of an LDAP server where password changes are allowed" msgstr "URI adresa LDAP serveru na kterém je dovoleno provádět změny hesel" -#: src/config/SSSDConfig/sssdoptions.py:510 +#: src/config/SSSDConfig/sssdoptions.py:516 msgid "URI of a backup LDAP server where password changes are allowed" msgstr "URI záložního LDAP serveru, na kterém je možné měnit hesla" -#: src/config/SSSDConfig/sssdoptions.py:511 +#: src/config/SSSDConfig/sssdoptions.py:517 msgid "DNS service name for LDAP password change server" msgstr "Název DNS služby pro LDAP server změny hesel" -#: src/config/SSSDConfig/sssdoptions.py:512 +#: src/config/SSSDConfig/sssdoptions.py:518 msgid "" "Whether to update the ldap_user_shadow_last_change attribute after a " "password change" msgstr "Zda aktualizovat atribut ldap_user_shadow_last_change po změně hesla" -#: src/config/SSSDConfig/sssdoptions.py:516 +#: src/config/SSSDConfig/sssdoptions.py:522 msgid "Base DN for sudo rules lookups" msgstr "Základ rozliš. názvu pro vyhledávání sudo pravidel" -#: src/config/SSSDConfig/sssdoptions.py:517 +#: src/config/SSSDConfig/sssdoptions.py:523 msgid "Automatic full refresh period" msgstr "Perioda automatického úplného znovunačtení" -#: src/config/SSSDConfig/sssdoptions.py:518 +#: src/config/SSSDConfig/sssdoptions.py:524 msgid "Automatic smart refresh period" msgstr "Perioda chytrého automatického opětovného načtení" -#: src/config/SSSDConfig/sssdoptions.py:519 +#: src/config/SSSDConfig/sssdoptions.py:525 msgid "Smart and full refresh random offset" msgstr "Náhodný posun pro inteligentní a úplné opětovné načtení" -#: src/config/SSSDConfig/sssdoptions.py:520 +#: src/config/SSSDConfig/sssdoptions.py:526 msgid "Whether to filter rules by hostname, IP addresses and network" msgstr "Zda filtrovat pravidla podle názvů strojů, IP adres a sítě" -#: src/config/SSSDConfig/sssdoptions.py:521 +#: src/config/SSSDConfig/sssdoptions.py:527 msgid "" "Hostnames and/or fully qualified domain names of this machine to filter sudo " "rules" @@ -1826,151 +1872,151 @@ msgstr "" "Názvy strojů a/nebo úplné doménové názvy tohoto stroje pro filtrování sudo " "pravidel" -#: src/config/SSSDConfig/sssdoptions.py:522 +#: src/config/SSSDConfig/sssdoptions.py:528 msgid "IPv4 or IPv6 addresses or network of this machine to filter sudo rules" msgstr "" "IPv4 nebo IPv6 adresy nebo sítě tohoto stroje pro filtrování sudo pravidel" -#: src/config/SSSDConfig/sssdoptions.py:523 +#: src/config/SSSDConfig/sssdoptions.py:529 msgid "Whether to include rules that contains netgroup in host attribute" msgstr "" "Zda zahrnout pravidla která obsahují v atributu stroj síťovou skupinu " "(netgroup)" -#: src/config/SSSDConfig/sssdoptions.py:524 +#: src/config/SSSDConfig/sssdoptions.py:530 msgid "" "Whether to include rules that contains regular expression in host attribute" msgstr "Zda zahrnout pravidla, která obsahují v atributu stroj regulární výraz" -#: src/config/SSSDConfig/sssdoptions.py:525 +#: src/config/SSSDConfig/sssdoptions.py:531 msgid "Object class for sudo rules" msgstr "Objektová třída pro sudo pravidla" -#: src/config/SSSDConfig/sssdoptions.py:526 +#: src/config/SSSDConfig/sssdoptions.py:532 msgid "Name of attribute that is used as object class for sudo rules" msgstr "Název atributu, který slouží jako třída objektů pro sudo pravidla" -#: src/config/SSSDConfig/sssdoptions.py:527 +#: src/config/SSSDConfig/sssdoptions.py:533 msgid "Sudo rule name" msgstr "Název sudo pravidla" -#: src/config/SSSDConfig/sssdoptions.py:528 +#: src/config/SSSDConfig/sssdoptions.py:534 msgid "Sudo rule command attribute" msgstr "Atribut příkaz sudo pravidla" -#: src/config/SSSDConfig/sssdoptions.py:529 +#: src/config/SSSDConfig/sssdoptions.py:535 msgid "Sudo rule host attribute" msgstr "Atribut stroj sudo pravidla" -#: src/config/SSSDConfig/sssdoptions.py:530 +#: src/config/SSSDConfig/sssdoptions.py:536 msgid "Sudo rule user attribute" msgstr "Atribut uživatel sudo pravidla" -#: src/config/SSSDConfig/sssdoptions.py:531 +#: src/config/SSSDConfig/sssdoptions.py:537 msgid "Sudo rule option attribute" msgstr "Atribut volba sudo pravidla" -#: src/config/SSSDConfig/sssdoptions.py:532 +#: src/config/SSSDConfig/sssdoptions.py:538 msgid "Sudo rule runas attribute" msgstr "Atribut runas (spustit jako) sudo pravidla" -#: src/config/SSSDConfig/sssdoptions.py:533 +#: src/config/SSSDConfig/sssdoptions.py:539 msgid "Sudo rule runasuser attribute" msgstr "Atribut runasuser (spustit jako uživatel) sudo pravidla" -#: src/config/SSSDConfig/sssdoptions.py:534 +#: src/config/SSSDConfig/sssdoptions.py:540 msgid "Sudo rule runasgroup attribute" msgstr "Atribut runasgroup (spustit jako skupina) sudo pravidla" -#: src/config/SSSDConfig/sssdoptions.py:535 +#: src/config/SSSDConfig/sssdoptions.py:541 msgid "Sudo rule notbefore attribute" msgstr "Atribut notbefore (ne před) sudo pravidla" -#: src/config/SSSDConfig/sssdoptions.py:536 +#: src/config/SSSDConfig/sssdoptions.py:542 msgid "Sudo rule notafter attribute" msgstr "Atribut notafter (ne po) sudo pravidla" -#: src/config/SSSDConfig/sssdoptions.py:537 +#: src/config/SSSDConfig/sssdoptions.py:543 msgid "Sudo rule order attribute" msgstr "Atribut order (pořadí) sudo pravidla" -#: src/config/SSSDConfig/sssdoptions.py:540 +#: src/config/SSSDConfig/sssdoptions.py:546 msgid "Object class for automounter maps" msgstr "Objektová třída pro mapy automatického připojování" -#: src/config/SSSDConfig/sssdoptions.py:541 +#: src/config/SSSDConfig/sssdoptions.py:547 msgid "Automounter map name attribute" msgstr "Atribut název mapy automatického připojování" -#: src/config/SSSDConfig/sssdoptions.py:542 +#: src/config/SSSDConfig/sssdoptions.py:548 msgid "Object class for automounter map entries" msgstr "Objektová třída pro položky mapy automatického připojování" -#: src/config/SSSDConfig/sssdoptions.py:543 +#: src/config/SSSDConfig/sssdoptions.py:549 msgid "Automounter map entry key attribute" msgstr "Atribut klíč položky mapy automatického připojování" -#: src/config/SSSDConfig/sssdoptions.py:544 +#: src/config/SSSDConfig/sssdoptions.py:550 msgid "Automounter map entry value attribute" msgstr "Atribut hodnoty položky mapy automatického připojování" -#: src/config/SSSDConfig/sssdoptions.py:545 +#: src/config/SSSDConfig/sssdoptions.py:551 msgid "Base DN for automounter map lookups" msgstr "Základ rozlišeného názvu pro vyhledávání map automounter" -#: src/config/SSSDConfig/sssdoptions.py:546 +#: src/config/SSSDConfig/sssdoptions.py:552 msgid "The name of the automount master map in LDAP." msgstr "Název v LDAP hlavní mapy pro automatické připojování." -#: src/config/SSSDConfig/sssdoptions.py:549 +#: src/config/SSSDConfig/sssdoptions.py:555 msgid "Base DN for IP hosts lookups" msgstr "Základ DN pro hledání IP hostitelů" -#: src/config/SSSDConfig/sssdoptions.py:550 +#: src/config/SSSDConfig/sssdoptions.py:556 msgid "Object class for IP hosts" msgstr "Třída objektů pro IP hostitele" -#: src/config/SSSDConfig/sssdoptions.py:551 +#: src/config/SSSDConfig/sssdoptions.py:557 msgid "IP host name attribute" msgstr "Atribut název IP hostitele" -#: src/config/SSSDConfig/sssdoptions.py:552 +#: src/config/SSSDConfig/sssdoptions.py:558 msgid "IP host number (address) attribute" msgstr "Atribut číslo IP hostitele (adresa)" -#: src/config/SSSDConfig/sssdoptions.py:553 +#: src/config/SSSDConfig/sssdoptions.py:559 msgid "IP host entryUSN attribute" msgstr "Atribut IP hostitele entryUSN" -#: src/config/SSSDConfig/sssdoptions.py:554 +#: src/config/SSSDConfig/sssdoptions.py:560 msgid "Base DN for IP networks lookups" msgstr "Základ DN pro hledání IP sítí" -#: src/config/SSSDConfig/sssdoptions.py:555 +#: src/config/SSSDConfig/sssdoptions.py:561 msgid "Object class for IP networks" msgstr "Třída objektu pro IP sítě" -#: src/config/SSSDConfig/sssdoptions.py:556 +#: src/config/SSSDConfig/sssdoptions.py:562 msgid "IP network name attribute" msgstr "Atribut název IP sítě" -#: src/config/SSSDConfig/sssdoptions.py:557 +#: src/config/SSSDConfig/sssdoptions.py:563 msgid "IP network number (address) attribute" msgstr "Atribut IP síťové číslo (adresa)" -#: src/config/SSSDConfig/sssdoptions.py:558 +#: src/config/SSSDConfig/sssdoptions.py:564 msgid "IP network entryUSN attribute" msgstr "Atribut entryUSN IP sítě" -#: src/config/SSSDConfig/sssdoptions.py:561 +#: src/config/SSSDConfig/sssdoptions.py:567 msgid "Comma separated list of allowed users" msgstr "Čárkou oddělovaný seznam uživatelů, kterým je umožněn přístup" -#: src/config/SSSDConfig/sssdoptions.py:562 +#: src/config/SSSDConfig/sssdoptions.py:568 msgid "Comma separated list of prohibited users" msgstr "Čárkou oddělovaný seznam uživatelů, kterým je odepřen přístup" -#: src/config/SSSDConfig/sssdoptions.py:563 +#: src/config/SSSDConfig/sssdoptions.py:569 msgid "" "Comma separated list of groups that are allowed to log in. This applies only " "to groups within this SSSD domain. Local groups are not evaluated." @@ -1979,7 +2025,7 @@ msgstr "" "uplatní pouze na skupiny v rámci SSSD domény. Místní skupiny nejsou takto " "vyhodnocovány." -#: src/config/SSSDConfig/sssdoptions.py:565 +#: src/config/SSSDConfig/sssdoptions.py:571 msgid "" "Comma separated list of groups that are explicitly denied access. This " "applies only to groups within this SSSD domain. Local groups are not " @@ -1989,31 +2035,31 @@ msgstr "" "uplatní pouze na skupiny v rámci SSSD domény. Místní skupiny nejsou takto " "vyhodnocovány." -#: src/config/SSSDConfig/sssdoptions.py:569 +#: src/config/SSSDConfig/sssdoptions.py:575 msgid "The number of preforked proxy children." msgstr "Počet předrozvětvených dílčích procesů proxy." -#: src/config/SSSDConfig/sssdoptions.py:572 +#: src/config/SSSDConfig/sssdoptions.py:578 msgid "The name of the NSS library to use" msgstr "Název NSS knihovny, kterou použít" -#: src/config/SSSDConfig/sssdoptions.py:573 +#: src/config/SSSDConfig/sssdoptions.py:579 msgid "The name of the NSS library to use for hosts and networks lookups" msgstr "Název NSS knihovny kterou použít pro hledání hostitelů a sítí" -#: src/config/SSSDConfig/sssdoptions.py:574 +#: src/config/SSSDConfig/sssdoptions.py:580 msgid "Whether to look up canonical group name from cache if possible" msgstr "Zda vyhledávat kanonický název skupiny z mezipaměti, pokud je to možné" -#: src/config/SSSDConfig/sssdoptions.py:577 +#: src/config/SSSDConfig/sssdoptions.py:583 msgid "PAM stack to use" msgstr "PAM vrstvy, které použít" -#: src/config/SSSDConfig/sssdoptions.py:580 +#: src/config/SSSDConfig/sssdoptions.py:586 msgid "Path of passwd file sources." msgstr "Popis umístění souborových zdrojů passwd." -#: src/config/SSSDConfig/sssdoptions.py:581 +#: src/config/SSSDConfig/sssdoptions.py:587 msgid "Path of group file sources." msgstr "Popis umístění souborových zdrojů group." @@ -2046,169 +2092,173 @@ msgstr "" "Volbu -i|--interactive (interaktivní) není možné použít současně s -D|--" "daemon (proces služby)\n" -#: src/monitor/monitor.c:1836 +#: src/monitor/monitor.c:1838 msgid "Failed to get initial capabilities\n" msgstr "Nepodařilo se získat počáteční schopnosti\n" -#: src/monitor/monitor.c:1847 +#: src/monitor/monitor.c:1849 msgid "Non-root service user support isn't built. Can't run under %" msgstr "Podpora služeb non-root uživatele není vytvořena. Nelze spustit pod %" -#: src/monitor/monitor.c:1864 +#: src/monitor/monitor.c:1866 #, c-format msgid "Can't read config: '%s'\n" msgstr "Nelze přečíst konfiguraci: '%s'\n" -#: src/monitor/monitor.c:1876 -#, c-format -msgid "Failed to boostrap SSSD 'monitor' process: %s" +#: src/monitor/monitor.c:1878 +#, fuzzy, c-format +msgid "Failed to bootstrap SSSD 'monitor' process: %s" msgstr "Nepodařilo se bootstrap proces SSSD 'monitor': %s" -#: src/monitor/monitor.c:1971 +#: src/monitor/monitor.c:1973 msgid "Out of memory\n" msgstr "Došla paměť\n" -#: src/providers/krb5/krb5_child.c:4221 +#: src/providers/krb5/krb5_child.c:4316 msgid "Use anonymous PKINIT to request FAST armor ticket" msgstr "K vyžádání FAST chráněného tiketu použít anonymní PKINIT" -#: src/providers/krb5/krb5_child.c:4223 +#: src/providers/krb5/krb5_child.c:4318 msgid "Kerberos realm to use" msgstr "Kerberos oblast (realm) kterou použít" -#: src/providers/krb5/krb5_child.c:4225 +#: src/providers/krb5/krb5_child.c:4320 msgid "Requested lifetime of the ticket" msgstr "Požadovaná životnost lístku" -#: src/providers/krb5/krb5_child.c:4227 +#: src/providers/krb5/krb5_child.c:4322 msgid "Requested renewable lifetime of the ticket" msgstr "Požadovaná obnovitelná životnosti lístku" -#: src/providers/krb5/krb5_child.c:4229 +#: src/providers/krb5/krb5_child.c:4324 msgid "FAST options ('never', 'try', 'demand')" msgstr "FAST volby („never“, „try“, „demand“)" -#: src/providers/krb5/krb5_child.c:4232 +#: src/providers/krb5/krb5_child.c:4327 msgid "Specifies the server principal to use for FAST" msgstr "Určuje principal serveru které použít pro FAST" -#: src/providers/krb5/krb5_child.c:4234 +#: src/providers/krb5/krb5_child.c:4329 msgid "Requests canonicalization of the principal name" msgstr "Požaduje kanonizaci názvu principalu" -#: src/providers/krb5/krb5_child.c:4236 +#: src/providers/krb5/krb5_child.c:4331 msgid "Use custom version of krb5_get_init_creds_password" msgstr "Použít uživatelsky určenou verzi krb5_get_init_creds_password" -#: src/providers/krb5/krb5_child.c:4238 +#: src/providers/krb5/krb5_child.c:4333 msgid "Check PAC flags" msgstr "Zkontrolovat PAC příznaky" -#: src/providers/data_provider_be.c:790 +#: src/providers/krb5/krb5_child.c:4335 +msgid "Set environment variable (KEY=VALUE)" +msgstr "" + +#: src/providers/data_provider_be.c:786 msgid "Domain of the information provider (mandatory)" msgstr "Doména poskytovatele informace (povinné)" -#: src/sss_client/common.c:1165 +#: src/sss_client/common.c:1208 msgid "Socket has wrong ownership or permissions." msgstr "Soket má nesprávné vlastnictví nebo oprávnění." -#: src/sss_client/common.c:1168 +#: src/sss_client/common.c:1211 msgid "Unexpected format of the server credential message." msgstr "Neočekávaný formát zprávy o pověřeních serveru." -#: src/sss_client/common.c:1171 +#: src/sss_client/common.c:1214 msgid "SSSD is not run by trusted user." msgstr "SSSD není spouštěno důvěryhodným uživatelským účtem." -#: src/sss_client/common.c:1174 +#: src/sss_client/common.c:1217 msgid "SSSD socket does not exist." msgstr "SSSD soket neexistuje." -#: src/sss_client/common.c:1177 +#: src/sss_client/common.c:1220 msgid "Cannot get stat of SSSD socket." msgstr "Nedaří se získat stav SSSD soketu." -#: src/sss_client/common.c:1182 +#: src/sss_client/common.c:1225 msgid "An error occurred, but no description can be found." msgstr "Došlo k chybě, ale nedaří se najít popis." -#: src/sss_client/common.c:1188 +#: src/sss_client/common.c:1231 msgid "Unexpected error while looking for an error description" msgstr "Neočekávaná chyba při hledání popisu chyby" -#: src/sss_client/pam_sss.c:74 +#: src/sss_client/pam_sss.c:135 msgid "Permission denied. " msgstr "Přístup odepřen. " -#: src/sss_client/pam_sss.c:75 src/sss_client/pam_sss.c:843 -#: src/sss_client/pam_sss.c:854 +#: src/sss_client/pam_sss.c:136 src/sss_client/pam_sss.c:921 +#: src/sss_client/pam_sss.c:932 msgid "Server message: " msgstr "Zpráva ze serveru: " -#: src/sss_client/pam_sss.c:76 +#: src/sss_client/pam_sss.c:137 msgid "" "Kerberos TGT will not be granted upon login, user experience will be " "affected." msgstr "" "Kerberos TGT nebude při přihlášení udělen, což ovlivní uživatelské prostředí." -#: src/sss_client/pam_sss.c:77 +#: src/sss_client/pam_sss.c:138 msgid "Enter PIN:" msgstr "Zadat PIN:" # auto translated by TM merge from project: FreeIPA, version: ipa-4-5, DocId: # po/ipa -#: src/sss_client/pam_sss.c:320 +#: src/sss_client/pam_sss.c:385 msgid "Passwords do not match" msgstr "Zadání hesla se neshodují" -#: src/sss_client/pam_sss.c:508 +#: src/sss_client/pam_sss.c:584 msgid "Password reset by root is not supported." msgstr "Reset hesla správcem není podporován." -#: src/sss_client/pam_sss.c:549 +#: src/sss_client/pam_sss.c:625 msgid "Authenticated with cached credentials" msgstr "Přihlášeni přihlašovacími údaji z mezipaměti" -#: src/sss_client/pam_sss.c:550 +#: src/sss_client/pam_sss.c:626 msgid ", your cached password will expire at: " msgstr ", platnost mezipaměti hesel skončí v: " -#: src/sss_client/pam_sss.c:580 +#: src/sss_client/pam_sss.c:656 #, c-format msgid "Your password has expired. You have %1$d grace login(s) remaining." msgstr "Platnost vašeho hesla skončila. Zbývá vám %1$d přihlášení." -#: src/sss_client/pam_sss.c:630 +#: src/sss_client/pam_sss.c:706 #, c-format msgid "Your password will expire in %1$d %2$s." msgstr "Platnost vašeho hesla skončí v %1$d %2$s." -#: src/sss_client/pam_sss.c:633 +#: src/sss_client/pam_sss.c:709 #, c-format msgid "Your password has expired." msgstr "Vaše heslo vypršelo." -#: src/sss_client/pam_sss.c:684 +#: src/sss_client/pam_sss.c:760 msgid "Authentication is denied until: " msgstr "Ověření odepřeno do: " -#: src/sss_client/pam_sss.c:705 +#: src/sss_client/pam_sss.c:781 msgid "System is offline, password change not possible" msgstr "Systém není dostupný, změna hesla není možná" -#: src/sss_client/pam_sss.c:720 +#: src/sss_client/pam_sss.c:796 msgid "" "After changing the OTP password, you need to log out and back in order to " "acquire a ticket" msgstr "" "Po změně OTP hesla, je třeba se odhlásit/přihlásit aby byl získán lístek" -#: src/sss_client/pam_sss.c:735 +#: src/sss_client/pam_sss.c:813 msgid "PIN locked" msgstr "Uzamčeno PIN" -#: src/sss_client/pam_sss.c:750 +#: src/sss_client/pam_sss.c:828 msgid "" "No Kerberos TGT granted as the server does not support this method. Your " "single-sign on(SSO) experience will be affected." @@ -2216,63 +2266,67 @@ msgstr "" "Kerberos TGT nebyl udělen, protože server tuto metodu nepodporuje. Vaše " "zkušenosti s jednotným přihlášením (SSO) budou ovlivněny." -#: src/sss_client/pam_sss.c:840 src/sss_client/pam_sss.c:853 +#: src/sss_client/pam_sss.c:918 src/sss_client/pam_sss.c:931 msgid "Password change failed. " msgstr "Změna hesla se nezdařila. " -#: src/sss_client/pam_sss.c:1859 -#, c-format -msgid "Authenticate at %1$s and press ENTER." +#: src/sss_client/pam_sss.c:2028 +#, fuzzy, c-format +msgid "Authenticate at \"%1$s\"." msgstr "Ověřit na %1$s a stisknout ENTER." -#: src/sss_client/pam_sss.c:1862 -#, c-format -msgid "Authenticate with PIN %1$s at %2$s and press ENTER." +#: src/sss_client/pam_sss.c:2031 +#, fuzzy, c-format +msgid "Authenticate with PIN \"%1$s\" at \"%2$s\"." msgstr "Ověřte se PIN kódem %1$s na %2$s a stiskněte Enter." -#: src/sss_client/pam_sss.c:2281 +#: src/sss_client/pam_sss.c:2470 msgid "Please (re)insert (different) Smartcard" msgstr "(Znovu) vložte (jinou?) Smartcard kartu" -#: src/sss_client/pam_sss.c:2482 +#: src/sss_client/pam_sss.c:2700 msgid "New Password: " msgstr "Nové heslo: " -#: src/sss_client/pam_sss.c:2483 +#: src/sss_client/pam_sss.c:2701 msgid "Reenter new Password: " msgstr "Zopakování nového hesla: " -#: src/sss_client/pam_sss.c:2676 src/sss_client/pam_sss.c:2679 +#: src/sss_client/pam_sss.c:2890 +msgid "Press ENTER to continue." +msgstr "" + +#: src/sss_client/pam_sss.c:2913 src/sss_client/pam_sss.c:2916 msgid "First Factor: " msgstr "Hlavní faktor: " -#: src/sss_client/pam_sss.c:2677 src/sss_client/pam_sss.c:2851 +#: src/sss_client/pam_sss.c:2914 src/sss_client/pam_sss.c:3088 msgid "Second Factor (optional): " msgstr "Druhý faktor (volitelné): " -#: src/sss_client/pam_sss.c:2680 src/sss_client/pam_sss.c:2855 +#: src/sss_client/pam_sss.c:2917 src/sss_client/pam_sss.c:3092 msgid "Second Factor: " msgstr "Druhý faktor: " -#: src/sss_client/pam_sss.c:2684 +#: src/sss_client/pam_sss.c:2921 msgid "Insert your passkey device, then press ENTER." msgstr "Vložte zařízení s přístupovým klíčem a stiskněte klávesu ENTER." # auto translated by TM merge from project: anaconda, version: f25, DocId: # main -#: src/sss_client/pam_sss.c:2688 src/sss_client/pam_sss.c:2696 +#: src/sss_client/pam_sss.c:2925 src/sss_client/pam_sss.c:2933 msgid "Password: " msgstr "Heslo: " -#: src/sss_client/pam_sss.c:2850 src/sss_client/pam_sss.c:2854 +#: src/sss_client/pam_sss.c:3087 src/sss_client/pam_sss.c:3091 msgid "First Factor (Current Password): " msgstr "Hlavní faktor (stávající heslo): " -#: src/sss_client/pam_sss.c:2874 +#: src/sss_client/pam_sss.c:3111 msgid "Current Password: " msgstr "Stávající heslo: " -#: src/sss_client/pam_sss.c:3248 +#: src/sss_client/pam_sss.c:3485 msgid "Password expired. Change your password now." msgstr "Platnost hesla skončila. Změňte si ho." @@ -2725,9 +2779,9 @@ msgstr "Nepodařilo se vypsat objekt: %s\n" #: src/tools/sssctl/sssctl_cache.c:835 src/tools/sssctl/sssctl_cache.c:918 #: src/tools/sssctl/sssctl_cache.c:950 src/tools/sssctl/sssctl_cache.c:956 #: src/tools/sssctl/sssctl_cache.c:1010 src/tools/sssctl/sssctl_cache.c:1034 -#: src/tools/sssctl/sssctl_cache.c:1085 src/tools/sssctl/sssctl_cache.c:1194 -#: src/tools/sssctl/sssctl_cache.c:1229 src/tools/sssctl/sssctl_cache.c:1235 -#: src/tools/sssctl/sssctl_cache.c:1244 +#: src/tools/sssctl/sssctl_cache.c:1085 src/tools/sssctl/sssctl_cache.c:1195 +#: src/tools/sssctl/sssctl_cache.c:1230 src/tools/sssctl/sssctl_cache.c:1236 +#: src/tools/sssctl/sssctl_cache.c:1245 msgid "talloc failed\n" msgstr "talloc se nezdařilo\n" @@ -2803,25 +2857,25 @@ msgstr "Cachovaná GPO cesta [%s] není pod [%s], ignoruje se.\n" msgid "Unable to remove downloaded GPO files: %s\n" msgstr "Nelze odstranit stažené soubory GPO: %s\n" -#: src/tools/sssctl/sssctl_cache.c:1165 +#: src/tools/sssctl/sssctl_cache.c:1166 #, c-format msgid "Failed to fetch cache entry: %s\n" msgstr "Nepodařilo se získat položku mezipaměti: %s\n" -#: src/tools/sssctl/sssctl_cache.c:1170 +#: src/tools/sssctl/sssctl_cache.c:1171 msgid "Could not determine object domain\n" msgstr "Nedaří se zjistit doménu objektu\n" -#: src/tools/sssctl/sssctl_cache.c:1200 +#: src/tools/sssctl/sssctl_cache.c:1201 msgid "Could not find GUID attribute in GPO entry\n" msgstr "Nepodařilo se najít atribut GUID v položce GPO\n" -#: src/tools/sssctl/sssctl_cache.c:1206 +#: src/tools/sssctl/sssctl_cache.c:1207 #, c-format msgid "Failed to delete GPO: %s\n" msgstr "Nepodařilo se smazat GPO objekt: %s\n" -#: src/tools/sssctl/sssctl_cache.c:1210 +#: src/tools/sssctl/sssctl_cache.c:1211 #, c-format msgid "%s removed from cache\n" msgstr "%s odstraněno z mezipaměti\n" @@ -2872,8 +2926,8 @@ msgstr "Nepodařilo se nastavit kontext mapování certifikátů.\n" #, c-format msgid "Failed to add mapping and matching rules with error [%d][%s].\n" msgstr "" -"Nepodařilo se přidat mapování a pravidla pro hledání shody. Chyba byla " -"[%d][%s].\n" +"Nepodařilo se přidat mapování a pravidla pro hledání shody. Chyba byla [%d]" +"[%s].\n" #: src/tools/sssctl/sssctl_cert.c:251 msgid "Failed to decode base64 string.\n" @@ -2921,41 +2975,42 @@ msgstr "" "nastavení směřováno do „/moje/umisteni/sssd.conf“, pak je předpokládána " "složka s útržky nastavení v „/moje/umisteni/conf.d)" -#: src/tools/sssctl/sssctl_config.c:114 +#: src/tools/sssctl/sssctl_config.c:126 #, c-format msgid "File %1$s does not exist.\n" msgstr "soubor %1$s neexistuje.\n" -#: src/tools/sssctl/sssctl_config.c:115 +#: src/tools/sssctl/sssctl_config.c:127 msgid "There is no configuration.\n" msgstr "Není zde žádné nastavení.\n" -#: src/tools/sssctl/sssctl_config.c:120 +#: src/tools/sssctl/sssctl_config.c:132 #, c-format msgid "Configuration validation failed: %s\n" msgstr "Ověřování správnosti nastavení se nezdařilo: %s\n" -#: src/tools/sssctl/sssctl_config.c:121 +#: src/tools/sssctl/sssctl_config.c:133 msgid "Run with high debug level to see details.\n" msgstr "" "Pro zobrazení podrobností spusťte s vysokým stupněm podrobnosti ladících " "zpráv.\n" -#: src/tools/sssctl/sssctl_config.c:130 -msgid "Failed to run validators" +#: src/tools/sssctl/sssctl_config.c:142 +#, fuzzy +msgid "Failed to run validators\n" msgstr "Nepodařilo se spustit nástroje pro ověření správnosti" -#: src/tools/sssctl/sssctl_config.c:134 +#: src/tools/sssctl/sssctl_config.c:146 #, c-format msgid "Issues identified by validators: %zu\n" msgstr "Problémy identifikované nástroji pro ověření správnosti: %zu\n" -#: src/tools/sssctl/sssctl_config.c:145 +#: src/tools/sssctl/sssctl_config.c:157 #, c-format msgid "Messages generated during configuration merging: %zu\n" msgstr "Zprávy vytvořené při slučování nastavení: %zu\n" -#: src/tools/sssctl/sssctl_config.c:158 +#: src/tools/sssctl/sssctl_config.c:170 #, c-format msgid "Used configuration snippet files: %zu\n" msgstr "Použité soubory s útržky nastavení: %zu\n" @@ -3100,7 +3155,8 @@ msgstr "Operace vytvoření rejstříku se nezdařila: %1$s\n" #: src/tools/sssctl/sssctl_data.c:483 msgid "Don't forget to also update the indexes on the remote providers.\n" -msgstr "Nezapomínejte aktualizovat také rejstříky na vzdáleném poskytovateli.\n" +msgstr "" +"Nezapomínejte aktualizovat také rejstříky na vzdáleném poskytovateli.\n" #: src/tools/sssctl/sssctl_domains.c:82 msgid "Show domain list including primary or trusted domain type" diff --git a/po/de.po b/po/de.po index 0a8be3a76a5..5c7218e3e42 100644 --- a/po/de.po +++ b/po/de.po @@ -13,8 +13,8 @@ msgid "" msgstr "" "Project-Id-Version: PACKAGE VERSION\n" "Report-Msgid-Bugs-To: sssd-devel@lists.fedorahosted.org\n" -"POT-Creation-Date: 2026-01-14 14:57+0000\n" -"PO-Revision-Date: 2026-04-23 16:22+0000\n" +"POT-Creation-Date: 2026-10-02 15:57+0000\n" +"PO-Revision-Date: 2026-10-05 16:37+0000\n" "Last-Translator: Joachim Philipp \n" "Language-Team: German \n" @@ -23,52 +23,52 @@ msgstr "" "Content-Type: text/plain; charset=UTF-8\n" "Content-Transfer-Encoding: 8bit\n" "Plural-Forms: nplurals=2; plural=n != 1;\n" -"X-Generator: Weblate 5.17\n" +"X-Generator: Weblate 2026.10\n" -#: src/config/SSSDConfig/sssdoptions.py:20 -#: src/config/SSSDConfig/sssdoptions.py:21 +#: src/config/SSSDConfig/sssdoptions.py:16 +#: src/config/SSSDConfig/sssdoptions.py:17 msgid "Set the verbosity of the debug logging" msgstr "Ausführlichkeitsstufe der Fehlerdiagnose festlegen" -#: src/config/SSSDConfig/sssdoptions.py:22 +#: src/config/SSSDConfig/sssdoptions.py:18 msgid "Include timestamps in debug logs" msgstr "Zeitstempel in Fehlerdiagnoseprotokollen einschließen" -#: src/config/SSSDConfig/sssdoptions.py:23 +#: src/config/SSSDConfig/sssdoptions.py:19 msgid "Include microseconds in timestamps in debug logs" msgstr "Mikrosekunden in Zeitstempeln der Debug-Protokolle einschließen" -#: src/config/SSSDConfig/sssdoptions.py:24 +#: src/config/SSSDConfig/sssdoptions.py:20 msgid "Enable/disable debug backtrace" msgstr "Fehlerdiagnose Rückverfolgung ein-/ausschalten" -#: src/config/SSSDConfig/sssdoptions.py:25 +#: src/config/SSSDConfig/sssdoptions.py:21 msgid "Watchdog timeout before restarting service" msgstr "Timeout beim Watchdog vor Neustart des Dienstes" -#: src/config/SSSDConfig/sssdoptions.py:26 +#: src/config/SSSDConfig/sssdoptions.py:22 msgid "Command to start service" msgstr "Befehl zum Starten des Dienstes" -#: src/config/SSSDConfig/sssdoptions.py:27 +#: src/config/SSSDConfig/sssdoptions.py:23 msgid "The number of file descriptors that may be opened by this responder" msgstr "" "Die Anzahl der Dateideskriptoren, die durch diesen Responder geöffnet werden " "dürfen" -#: src/config/SSSDConfig/sssdoptions.py:28 +#: src/config/SSSDConfig/sssdoptions.py:24 msgid "Idle time before automatic disconnection of a client" msgstr "Untätige Zeit vor der automatischen Verbindungstrennung eines Clients " -#: src/config/SSSDConfig/sssdoptions.py:29 +#: src/config/SSSDConfig/sssdoptions.py:25 msgid "Idle time before automatic shutdown of the responder" msgstr "Inaktivitätszeit bis zum automatischen Herunterfahren des Responders" -#: src/config/SSSDConfig/sssdoptions.py:30 +#: src/config/SSSDConfig/sssdoptions.py:26 msgid "Always query all the caches before querying the Data Providers" msgstr "Immer alle Zwischenspeicher abfragen vor Abfrage der Datenprovider" -#: src/config/SSSDConfig/sssdoptions.py:31 +#: src/config/SSSDConfig/sssdoptions.py:27 msgid "" "When SSSD switches to offline mode the amount of time before it tries to go " "back online will increase based upon the time spent disconnected. This value " @@ -76,65 +76,65 @@ msgid "" "random_offset." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:36 +#: src/config/SSSDConfig/sssdoptions.py:32 msgid "SSSD Services to start" msgstr "SSSD-Dienste zum Starten" -#: src/config/SSSDConfig/sssdoptions.py:37 +#: src/config/SSSDConfig/sssdoptions.py:33 msgid "SSSD Domains to start" msgstr "SSSD-Domains zum Starten" -#: src/config/SSSDConfig/sssdoptions.py:38 +#: src/config/SSSDConfig/sssdoptions.py:34 msgid "Regex to parse username and domain" msgstr "Regulärer Ausdruck zum Verarbeiten von Benutzername und Domain" -#: src/config/SSSDConfig/sssdoptions.py:39 +#: src/config/SSSDConfig/sssdoptions.py:35 msgid "Printf-compatible format for displaying fully-qualified names" msgstr "" "Printf-kompatibles Format für die Darstellung voll ausgeschriebener Namen" -#: src/config/SSSDConfig/sssdoptions.py:40 +#: src/config/SSSDConfig/sssdoptions.py:36 msgid "" "Directory on the filesystem where SSSD should store Kerberos replay cache " "files." msgstr "" "Verzeichnis im Dateisystem, in welchem SSSD den Kerberos Replay-Cache ablegt." -#: src/config/SSSDConfig/sssdoptions.py:41 +#: src/config/SSSDConfig/sssdoptions.py:37 msgid "Domain to add to names without a domain component." msgstr "Domain, die zu Namen ohne Domain-Komponente hinzugefügt werden soll." -#: src/config/SSSDConfig/sssdoptions.py:42 +#: src/config/SSSDConfig/sssdoptions.py:38 msgid "The user to drop privileges to" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:43 +#: src/config/SSSDConfig/sssdoptions.py:39 msgid "Tune certificate verification" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:44 +#: src/config/SSSDConfig/sssdoptions.py:40 msgid "All spaces in group or user names will be replaced with this character" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:45 +#: src/config/SSSDConfig/sssdoptions.py:41 msgid "Tune sssd to honor or ignore netlink state changes" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:46 +#: src/config/SSSDConfig/sssdoptions.py:42 msgid "Enable or disable the implicit files domain" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:47 +#: src/config/SSSDConfig/sssdoptions.py:43 msgid "A specific order of the domains to be looked up" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:48 +#: src/config/SSSDConfig/sssdoptions.py:44 msgid "" "Controls if SSSD should monitor the state of resolv.conf to identify when it " "needs to update its internal DNS resolver." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:50 +#: src/config/SSSDConfig/sssdoptions.py:46 msgid "" "SSSD monitors the state of resolv.conf to identify when it needs to update " "its internal DNS resolver. By default, we will attempt to use inotify for " @@ -147,79 +147,79 @@ msgstr "" "kann, werden wir darauf zurückgreifen, alle fünf Sekunden »resolv.conf« " "abzufragen." -#: src/config/SSSDConfig/sssdoptions.py:53 +#: src/config/SSSDConfig/sssdoptions.py:49 msgid "Run PAC responder automatically for AD and IPA provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:54 +#: src/config/SSSDConfig/sssdoptions.py:50 msgid "Enable or disable core dumps for all SSSD processes." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:55 +#: src/config/SSSDConfig/sssdoptions.py:51 msgid "Tune passkey verification behavior" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:58 +#: src/config/SSSDConfig/sssdoptions.py:54 msgid "Enumeration cache timeout length (seconds)" msgstr "Zeitspanne für den Aufzählungs-Zwischenspeicher (Sekunden)" -#: src/config/SSSDConfig/sssdoptions.py:59 +#: src/config/SSSDConfig/sssdoptions.py:55 msgid "Entry cache background update timeout length (seconds)" msgstr "" "Zeitspanne für die Aktualisierung des Eintrags-Zwischenspeichers (Sekunden)" -#: src/config/SSSDConfig/sssdoptions.py:60 -#: src/config/SSSDConfig/sssdoptions.py:125 +#: src/config/SSSDConfig/sssdoptions.py:56 +#: src/config/SSSDConfig/sssdoptions.py:124 msgid "Negative cache timeout length (seconds)" msgstr "Zeitspanne für den negativen Zwischenspeicher (Sekunden)" -#: src/config/SSSDConfig/sssdoptions.py:61 +#: src/config/SSSDConfig/sssdoptions.py:57 msgid "Users that SSSD should explicitly ignore" msgstr "Benutzer, die SSSD ausdrücklich ignorieren soll" -#: src/config/SSSDConfig/sssdoptions.py:62 +#: src/config/SSSDConfig/sssdoptions.py:58 msgid "Groups that SSSD should explicitly ignore" msgstr "Gruppen, die SSSD ausdrücklich ignorieren soll" -#: src/config/SSSDConfig/sssdoptions.py:63 +#: src/config/SSSDConfig/sssdoptions.py:59 msgid "Should filtered users appear in groups" msgstr "Anzeige von gefilterten Benutzern in Gruppen" -#: src/config/SSSDConfig/sssdoptions.py:64 +#: src/config/SSSDConfig/sssdoptions.py:60 msgid "The value of the password field the NSS provider should return" msgstr "" "Der Wert des Passwort-Feldes, das der NSS-Dienstanbieter zurückgeben sollte" -#: src/config/SSSDConfig/sssdoptions.py:65 +#: src/config/SSSDConfig/sssdoptions.py:61 msgid "Override homedir value from the identity provider with this value" msgstr "" "homedir-Wert des Identitäts-Anbieters wird durch diesen Wert außer Kraft " "gesetzt" -#: src/config/SSSDConfig/sssdoptions.py:66 +#: src/config/SSSDConfig/sssdoptions.py:62 msgid "" "Substitute empty homedir value from the identity provider with this value" msgstr "" "Leerer homedir-Wert des Identitäts-Anbieters wird durch diesen Wert ersetzt" -#: src/config/SSSDConfig/sssdoptions.py:67 +#: src/config/SSSDConfig/sssdoptions.py:63 msgid "Override shell value from the identity provider with this value" msgstr "" "Shell-Wert des Identitäts-Anbieters wird durch diesen Wert außer Kraft " "gesetzt" -#: src/config/SSSDConfig/sssdoptions.py:68 +#: src/config/SSSDConfig/sssdoptions.py:64 msgid "The list of shells users are allowed to log in with" msgstr "Liste der Shells, mit denen sich der Benutzer anmelden darf" -#: src/config/SSSDConfig/sssdoptions.py:69 +#: src/config/SSSDConfig/sssdoptions.py:65 msgid "" "The list of shells that will be vetoed, and replaced with the fallback shell" msgstr "" "Die Liste der Shells, die abgewiesen und durch eine Ausweich-Shell ersetzt " "werden" -#: src/config/SSSDConfig/sssdoptions.py:70 +#: src/config/SSSDConfig/sssdoptions.py:66 msgid "" "If a shell stored in central directory is allowed but not available, use " "this fallback" @@ -227,39 +227,39 @@ msgstr "" "Falls eine Shell im zentralen Verzeichnis zugelassen, aber nicht verfügbar " "ist, wird auf diese ausgewichen" -#: src/config/SSSDConfig/sssdoptions.py:71 +#: src/config/SSSDConfig/sssdoptions.py:67 msgid "Shell to use if the provider does not list one" msgstr "Zu verwendende Shell, wenn der Anbieter keine auflistet" -#: src/config/SSSDConfig/sssdoptions.py:72 +#: src/config/SSSDConfig/sssdoptions.py:68 msgid "How long will be in-memory cache records valid" msgstr "Gültigkeitsdauer der speichereigenen Zwischenspeicher-Datensätze" -#: src/config/SSSDConfig/sssdoptions.py:74 +#: src/config/SSSDConfig/sssdoptions.py:70 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for passwd requests" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:76 +#: src/config/SSSDConfig/sssdoptions.py:72 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for group requests" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:78 +#: src/config/SSSDConfig/sssdoptions.py:74 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for initgroups requests" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:79 +#: src/config/SSSDConfig/sssdoptions.py:75 msgid "" "The value of this option will be used in the expansion of the " "override_homedir option if the template contains the format string %H." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:81 +#: src/config/SSSDConfig/sssdoptions.py:77 msgid "" "Specifies time in seconds for which the list of subdomains will be " "considered valid." @@ -267,24 +267,24 @@ msgstr "" "gibt die Zeit in Sekunden an, während der die Liste der Subdomains als " "gültig erachtet wird." -#: src/config/SSSDConfig/sssdoptions.py:83 +#: src/config/SSSDConfig/sssdoptions.py:79 msgid "" "The entry cache can be set to automatically update entries in the background " "if they are requested beyond a percentage of the entry_cache_timeout value " "for the domain." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:88 +#: src/config/SSSDConfig/sssdoptions.py:84 msgid "How long to allow cached logins between online logins (days)" msgstr "" "Gibt die Anzahl der Tage an, für die zwischengespeicherte Anmeldungen " "zwischen Online-Anmeldungen zulässig sind" -#: src/config/SSSDConfig/sssdoptions.py:89 +#: src/config/SSSDConfig/sssdoptions.py:85 msgid "How many failed logins attempts are allowed when offline" msgstr "Anzahl der zulässigen fehlgeschlagenen Anmeldungen im Offline-Modus" -#: src/config/SSSDConfig/sssdoptions.py:91 +#: src/config/SSSDConfig/sssdoptions.py:87 msgid "" "How long (minutes) to deny login after offline_failed_login_attempts has " "been reached" @@ -292,134 +292,141 @@ msgstr "" "Zeitspanne in Minuten, nach der die Anmeldung verweigert wird, wenn " "offline_failed_login_attempts erreicht wurde" -#: src/config/SSSDConfig/sssdoptions.py:92 +#: src/config/SSSDConfig/sssdoptions.py:88 msgid "What kind of messages are displayed to the user during authentication" msgstr "" "Gibt die Art der Meldungen an, die dem Benutzer während der " "Authentifizierung angezeigt werden" -#: src/config/SSSDConfig/sssdoptions.py:93 +#: src/config/SSSDConfig/sssdoptions.py:89 msgid "Filter PAM responses sent to the pam_sss" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:94 +#: src/config/SSSDConfig/sssdoptions.py:90 msgid "How many seconds to keep identity information cached for PAM requests" msgstr "" "Anzahl der Sekunden, die zwischengespeicherte PAM-Anfragen aufbewahrt werden " "sollen" -#: src/config/SSSDConfig/sssdoptions.py:95 +#: src/config/SSSDConfig/sssdoptions.py:91 msgid "How many days before password expiration a warning should be displayed" msgstr "" "Gibt die Anzahl der Tage vor dem Ablauf des Passworts an, bis eine Warnung " "angezeigt wird" -#: src/config/SSSDConfig/sssdoptions.py:96 +#: src/config/SSSDConfig/sssdoptions.py:92 msgid "List of trusted uids or user's name" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:97 +#: src/config/SSSDConfig/sssdoptions.py:93 msgid "List of domains accessible even for untrusted users." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:98 +#: src/config/SSSDConfig/sssdoptions.py:94 msgid "Message printed when user account is expired." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:99 +#: src/config/SSSDConfig/sssdoptions.py:95 msgid "Message printed when user account is locked." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:100 +#: src/config/SSSDConfig/sssdoptions.py:96 msgid "Allow certificate based/Smartcard authentication." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:101 +#: src/config/SSSDConfig/sssdoptions.py:97 msgid "Path to certificate database with PKCS#11 modules." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:102 +#: src/config/SSSDConfig/sssdoptions.py:98 #, fuzzy msgid "Tune certificate verification for PAM authentication." msgstr "TLS-Zertifikatüberprüfung erforderlich machen" -#: src/config/SSSDConfig/sssdoptions.py:103 +#: src/config/SSSDConfig/sssdoptions.py:99 msgid "How many seconds will pam_sss wait for p11_child to finish" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:104 +#: src/config/SSSDConfig/sssdoptions.py:100 msgid "Which PAM services are permitted to contact application domains" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:105 +#: src/config/SSSDConfig/sssdoptions.py:101 msgid "Allowed services for using smartcards" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:106 +#: src/config/SSSDConfig/sssdoptions.py:102 msgid "Additional timeout to wait for a card if requested" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:107 +#: src/config/SSSDConfig/sssdoptions.py:103 msgid "" "PKCS#11 URI to restrict the selection of devices for Smartcard authentication" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:108 +#: src/config/SSSDConfig/sssdoptions.py:104 msgid "When shall the PAM responder force an initgroups request" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:109 +#: src/config/SSSDConfig/sssdoptions.py:105 msgid "List of PAM services that are allowed to authenticate with GSSAPI." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:110 +#: src/config/SSSDConfig/sssdoptions.py:106 msgid "Whether to match authenticated UPN with target user" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:111 +#: src/config/SSSDConfig/sssdoptions.py:107 msgid "" "List of pairs : that must be enforced " "for PAM access with GSSAPI authentication" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:113 +#: src/config/SSSDConfig/sssdoptions.py:109 +msgid "" +"List of triples :: that assigns " +"additional information from the Kerberos ticket to an authentication " +"indicator." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:112 msgid "Allow passkey device authentication." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:114 +#: src/config/SSSDConfig/sssdoptions.py:113 msgid "How many seconds will pam_sss wait for passkey_child to finish" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:115 +#: src/config/SSSDConfig/sssdoptions.py:114 msgid "Enable debugging in the libfido2 library" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:116 +#: src/config/SSSDConfig/sssdoptions.py:115 msgid "Enable JSON protocol for authentication methods selection." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:119 +#: src/config/SSSDConfig/sssdoptions.py:118 msgid "Whether to evaluate the time-based attributes in sudo rules" msgstr "" "Gibt an, ob zeitbasierte Attribute in Sudo-Regeln berechnet werden sollen" -#: src/config/SSSDConfig/sssdoptions.py:120 +#: src/config/SSSDConfig/sssdoptions.py:119 msgid "If true, SSSD will switch back to lower-wins ordering logic" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:121 +#: src/config/SSSDConfig/sssdoptions.py:120 msgid "" "Maximum number of rules that can be refreshed at once. If this is exceeded, " "full refresh is performed." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:128 +#: src/config/SSSDConfig/sssdoptions.py:127 msgid "Whether to hash host names and addresses in the known_hosts file" msgstr "" "Gibt an, ob Prüfsummen von Hostnamen und Adressen in der Datei known_hosts " "gespeichert werden" -#: src/config/SSSDConfig/sssdoptions.py:129 +#: src/config/SSSDConfig/sssdoptions.py:128 msgid "" "How many seconds to keep a host in the known_hosts file after its host keys " "were requested" @@ -427,145 +434,145 @@ msgstr "" "Anzahl der Sekunden, die ein Rechner in der Datei known_host behalten werden " "soll, nachdem dessen Schlüssel abgefragt wurden" -#: src/config/SSSDConfig/sssdoptions.py:131 +#: src/config/SSSDConfig/sssdoptions.py:130 msgid "Path to storage of trusted CA certificates" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:132 +#: src/config/SSSDConfig/sssdoptions.py:131 msgid "Allow to generate ssh-keys from certificates" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:133 +#: src/config/SSSDConfig/sssdoptions.py:132 msgid "" "Use the following matching rules to filter the certificates for ssh-key " "generation" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:137 +#: src/config/SSSDConfig/sssdoptions.py:136 msgid "List of UIDs or user names allowed to access the PAC responder" msgstr "" "Liste von Benutzer-IDs oder Benutzernamen für den Zugriff auf den PAC-" "Responder" -#: src/config/SSSDConfig/sssdoptions.py:138 +#: src/config/SSSDConfig/sssdoptions.py:137 msgid "How long the PAC data is considered valid" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:139 +#: src/config/SSSDConfig/sssdoptions.py:138 msgid "Validate the PAC" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:142 +#: src/config/SSSDConfig/sssdoptions.py:141 msgid "List of user attributes the InfoPipe is allowed to publish" msgstr "Liste der Benutzerattribute, die InfoPipe veröffentlichen darf" -#: src/config/SSSDConfig/sssdoptions.py:145 +#: src/config/SSSDConfig/sssdoptions.py:144 msgid "" "One of the following strings specifying the scope of session recording: none " "- No users are recorded. some - Users/groups specified by users and groups " "options are recorded. all - All users are recorded." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:148 +#: src/config/SSSDConfig/sssdoptions.py:147 msgid "" "A comma-separated list of users which should have session recording enabled. " "Matches user names as returned by NSS. I.e. after the possible space " "replacement, case changes, etc." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:150 +#: src/config/SSSDConfig/sssdoptions.py:149 msgid "" "A comma-separated list of groups, members of which should have session " "recording enabled. Matches group names as returned by NSS. I.e. after the " "possible space replacement, case changes, etc." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:153 +#: src/config/SSSDConfig/sssdoptions.py:152 msgid "" "A comma-separated list of users to be excluded from recording, only when " "scope=all" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:154 +#: src/config/SSSDConfig/sssdoptions.py:153 msgid "" "A comma-separated list of groups, members of which should be excluded from " "recording, only when scope=all. " msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:158 +#: src/config/SSSDConfig/sssdoptions.py:157 msgid "Identity provider" msgstr "Identitäts-Anbieter" -#: src/config/SSSDConfig/sssdoptions.py:159 +#: src/config/SSSDConfig/sssdoptions.py:158 msgid "Authentication provider" msgstr "Authentifizierungs-Anbieter" -#: src/config/SSSDConfig/sssdoptions.py:160 +#: src/config/SSSDConfig/sssdoptions.py:159 msgid "Access control provider" msgstr "Zugriffskontroll-Anbieter" -#: src/config/SSSDConfig/sssdoptions.py:161 +#: src/config/SSSDConfig/sssdoptions.py:160 msgid "Password change provider" msgstr "Passwortänderungs-Anbieter" -#: src/config/SSSDConfig/sssdoptions.py:162 +#: src/config/SSSDConfig/sssdoptions.py:161 msgid "SUDO provider" msgstr "SUDO-Anbieter" -#: src/config/SSSDConfig/sssdoptions.py:163 +#: src/config/SSSDConfig/sssdoptions.py:162 msgid "Autofs provider" msgstr "Autofs-Anbieter" -#: src/config/SSSDConfig/sssdoptions.py:164 +#: src/config/SSSDConfig/sssdoptions.py:163 msgid "Host identity provider" msgstr "Rechner-Identitäts-Anbieter" -#: src/config/SSSDConfig/sssdoptions.py:165 +#: src/config/SSSDConfig/sssdoptions.py:164 msgid "SELinux provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:166 +#: src/config/SSSDConfig/sssdoptions.py:165 msgid "Session management provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:167 +#: src/config/SSSDConfig/sssdoptions.py:166 msgid "Resolver provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:170 +#: src/config/SSSDConfig/sssdoptions.py:169 msgid "Whether the domain is usable by the OS or by applications" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:171 +#: src/config/SSSDConfig/sssdoptions.py:170 #, fuzzy msgid "Enable or disable the domain" msgstr "Validierung der Anmeldedaten aktivieren" -#: src/config/SSSDConfig/sssdoptions.py:172 +#: src/config/SSSDConfig/sssdoptions.py:171 msgid "Minimum user ID" msgstr "Minimale Benutzer‐ID" -#: src/config/SSSDConfig/sssdoptions.py:173 +#: src/config/SSSDConfig/sssdoptions.py:172 msgid "Maximum user ID" msgstr "Maximale Benutzer‐ID" -#: src/config/SSSDConfig/sssdoptions.py:174 +#: src/config/SSSDConfig/sssdoptions.py:173 msgid "Enable enumerating all users/groups" msgstr "Auflistung aller Benutzer/Gruppen aktivieren" -#: src/config/SSSDConfig/sssdoptions.py:175 +#: src/config/SSSDConfig/sssdoptions.py:174 msgid "Cache credentials for offline login" msgstr "Zwischengespeicherte Anmeldedaten für Offline-Anmeldung" -#: src/config/SSSDConfig/sssdoptions.py:176 +#: src/config/SSSDConfig/sssdoptions.py:175 msgid "Display users/groups in fully-qualified form" msgstr "Benutzer/Gruppen in voll ausgeschriebener Form anzeigen" -#: src/config/SSSDConfig/sssdoptions.py:177 +#: src/config/SSSDConfig/sssdoptions.py:176 msgid "Don't include group members in group lookups" msgstr "Gruppenmitglieder in Gruppen-Suchanfragen nicht einschließen" -#: src/config/SSSDConfig/sssdoptions.py:178 +#: src/config/SSSDConfig/sssdoptions.py:177 #: src/config/SSSDConfig/sssdoptions.py:190 #: src/config/SSSDConfig/sssdoptions.py:191 #: src/config/SSSDConfig/sssdoptions.py:192 @@ -576,55 +583,59 @@ msgstr "Gruppenmitglieder in Gruppen-Suchanfragen nicht einschließen" msgid "Entry cache timeout length (seconds)" msgstr "Zeitspanne für den Eintrags-Zwischenspeicher (Sekunden)" -#: src/config/SSSDConfig/sssdoptions.py:179 +#: src/config/SSSDConfig/sssdoptions.py:178 msgid "" "Restrict or prefer a specific address family when performing DNS lookups" msgstr "" "Eine spezifische Adressfamilie beim Ausführen von DNS-Suchanfragen " "beschränken oder bevorzugen" -#: src/config/SSSDConfig/sssdoptions.py:180 +#: src/config/SSSDConfig/sssdoptions.py:179 msgid "How long to keep cached entries after last successful login (days)" msgstr "" "Gibt die Anzahl der Tage an, wie lange zwischengespeicherte Einträge nach " "der letzten Anmeldung aufbewahrt werden" -#: src/config/SSSDConfig/sssdoptions.py:181 +#: src/config/SSSDConfig/sssdoptions.py:180 msgid "" "How long should SSSD talk to single DNS server before trying next server " "(miliseconds)" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:183 +#: src/config/SSSDConfig/sssdoptions.py:182 msgid "How long should keep trying to resolve single DNS query (seconds)" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:184 +#: src/config/SSSDConfig/sssdoptions.py:183 msgid "How long to wait for replies from DNS when resolving servers (seconds)" msgstr "" "Gibt die Anzahl Sekunden an, wie lange beim Auflösen von Servernamen auf " "Antworten vom DNS-Dienst gewartet werden soll" -#: src/config/SSSDConfig/sssdoptions.py:185 +#: src/config/SSSDConfig/sssdoptions.py:184 msgid "The domain part of service discovery DNS query" msgstr "Der Domain-Teil der DNS-Abfrage zur Dienstsuche" -#: src/config/SSSDConfig/sssdoptions.py:186 +#: src/config/SSSDConfig/sssdoptions.py:185 msgid "" "Specifies the interval, in seconds, that SSSD waits before attempting to " "reconnect to the primary server after a successful connection to the backup " "server" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:188 +#: src/config/SSSDConfig/sssdoptions.py:187 msgid "Override GID value from the identity provider with this value" msgstr "" "Den Gruppen-ID-Wert des Identitäts-Anbieters mit diesem Wert überschreiben" -#: src/config/SSSDConfig/sssdoptions.py:189 +#: src/config/SSSDConfig/sssdoptions.py:188 msgid "Treat usernames as case sensitive" msgstr "Groß-/Kleinschreibung in Benutzernamen berücksichtigen" +#: src/config/SSSDConfig/sssdoptions.py:189 +msgid "Lookups by ID are expensive or do not work at all" +msgstr "" + #: src/config/SSSDConfig/sssdoptions.py:197 msgid "How often should expired entries be refreshed in background" msgstr "Anzahl der Auffrischung abgelaufener Einträge im Hintergrund" @@ -811,7 +822,8 @@ msgstr "Der Automounter-Ort, den dieser IPA-Client verwendet" #: src/config/SSSDConfig/sssdoptions.py:243 msgid "Search base for object containing info about IPA domain" -msgstr "Suchbasis für Objekte, die Informationen über eine IPA-Domain enthalten" +msgstr "" +"Suchbasis für Objekte, die Informationen über eine IPA-Domain enthalten" #: src/config/SSSDConfig/sssdoptions.py:244 msgid "Search base for objects containing info about ID ranges" @@ -868,7 +880,7 @@ msgid "Search base for SUBID ranges" msgstr "Suchbasis für HBAC-bezogene Objekte" #: src/config/SSSDConfig/sssdoptions.py:259 -#: src/config/SSSDConfig/sssdoptions.py:506 +#: src/config/SSSDConfig/sssdoptions.py:512 msgid "Which rules should be used to evaluate access control" msgstr "Regeln für die Ermittlung der Zugriffskontrolle" @@ -1010,7 +1022,7 @@ msgid "Enable DNS sites - location based service discovery" msgstr "DNS-Sites aktivieren – standortbasierte Dienstsuche" #: src/config/SSSDConfig/sssdoptions.py:301 -#: src/config/SSSDConfig/sssdoptions.py:504 +#: src/config/SSSDConfig/sssdoptions.py:510 msgid "LDAP filter to determine access privileges" msgstr "LDAP-Filter zum Bestimmen der Zugriffsprivilegien" @@ -1442,7 +1454,7 @@ msgid "UUID attribute" msgstr "" #: src/config/SSSDConfig/sssdoptions.py:423 -#: src/config/SSSDConfig/sssdoptions.py:464 +#: src/config/SSSDConfig/sssdoptions.py:470 msgid "objectSID attribute" msgstr "objectSID -Attribut" @@ -1569,177 +1581,206 @@ msgstr "" "Eine Liste der zusätzlich herunterzuladender Attribute zusammen mit dem " "Benutzereintrag" +#: src/config/SSSDConfig/sssdoptions.py:456 +#, fuzzy +msgid "The object class of an subid entry in LDAP." +msgstr "die Objektklasse eines Netzgruppeneintrags in LDAP" + #: src/config/SSSDConfig/sssdoptions.py:457 +#, fuzzy +msgid "Subordinate user ID count attribute" +msgstr "Benutzer-Attribut der Sudo-Regel" + +#: src/config/SSSDConfig/sssdoptions.py:458 +#, fuzzy +msgid "Subordinate group ID count attribute" +msgstr "Optionsattribut der Sudo-Regel" + +#: src/config/SSSDConfig/sssdoptions.py:459 +#, fuzzy +msgid "User ID range start value attribute" +msgstr "Benutzername-Attribut" + +#: src/config/SSSDConfig/sssdoptions.py:460 +#, fuzzy +msgid "Group ID range start value attribute" +msgstr "Wert-Attribut des Automounter-Zuweisungseintrags" + +#: src/config/SSSDConfig/sssdoptions.py:461 +msgid "Owner of an entry" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:463 msgid "Base DN for group lookups" msgstr "Basis-DN für Gruppen-Suchanfragen" -#: src/config/SSSDConfig/sssdoptions.py:458 +#: src/config/SSSDConfig/sssdoptions.py:464 msgid "Objectclass for groups" msgstr "Objektklasse für Gruppen" -#: src/config/SSSDConfig/sssdoptions.py:459 +#: src/config/SSSDConfig/sssdoptions.py:465 msgid "Group name" msgstr "Gruppenname" -#: src/config/SSSDConfig/sssdoptions.py:460 +#: src/config/SSSDConfig/sssdoptions.py:466 msgid "Group password" msgstr "Gruppenpasswort" -#: src/config/SSSDConfig/sssdoptions.py:461 +#: src/config/SSSDConfig/sssdoptions.py:467 msgid "GID attribute" msgstr "Gruppen-ID-Attribut" -#: src/config/SSSDConfig/sssdoptions.py:462 +#: src/config/SSSDConfig/sssdoptions.py:468 msgid "Group member attribute" msgstr "Gruppen-Mitgliedschafts-Attribut" -#: src/config/SSSDConfig/sssdoptions.py:463 +#: src/config/SSSDConfig/sssdoptions.py:469 msgid "Group UUID attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:465 +#: src/config/SSSDConfig/sssdoptions.py:471 msgid "Modification time attribute for groups" msgstr "Änderungszeit-Attribut für Gruppen" -#: src/config/SSSDConfig/sssdoptions.py:466 +#: src/config/SSSDConfig/sssdoptions.py:472 msgid "Type of the group and other flags" msgstr "Typ der Gruppe und weitere Flags" -#: src/config/SSSDConfig/sssdoptions.py:467 +#: src/config/SSSDConfig/sssdoptions.py:473 msgid "The LDAP group external member attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:468 +#: src/config/SSSDConfig/sssdoptions.py:474 msgid "Maximum nesting level SSSD will follow" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:469 +#: src/config/SSSDConfig/sssdoptions.py:475 msgid "Filter for group lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:470 +#: src/config/SSSDConfig/sssdoptions.py:476 msgid "Scope of group lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:472 +#: src/config/SSSDConfig/sssdoptions.py:478 msgid "Base DN for netgroup lookups" msgstr "Basis-DN für Netzgruppen-Suchanfragen" -#: src/config/SSSDConfig/sssdoptions.py:473 +#: src/config/SSSDConfig/sssdoptions.py:479 msgid "Objectclass for netgroups" msgstr "Objektklasse für Netzgruppen" -#: src/config/SSSDConfig/sssdoptions.py:474 +#: src/config/SSSDConfig/sssdoptions.py:480 msgid "Netgroup name" msgstr "Netzgruppenname" -#: src/config/SSSDConfig/sssdoptions.py:475 +#: src/config/SSSDConfig/sssdoptions.py:481 msgid "Netgroups members attribute" msgstr "Netzgruppen-Mitglieder-Attribut" -#: src/config/SSSDConfig/sssdoptions.py:476 +#: src/config/SSSDConfig/sssdoptions.py:482 msgid "Netgroup triple attribute" msgstr "Netzgruppen-Tripel-Attribut" -#: src/config/SSSDConfig/sssdoptions.py:477 +#: src/config/SSSDConfig/sssdoptions.py:483 msgid "Modification time attribute for netgroups" msgstr "Änderungszeit-Attribut für Netzgruppen" -#: src/config/SSSDConfig/sssdoptions.py:479 +#: src/config/SSSDConfig/sssdoptions.py:485 msgid "Base DN for service lookups" msgstr "Basis-DN für Dienste-Suchanfragen" -#: src/config/SSSDConfig/sssdoptions.py:480 +#: src/config/SSSDConfig/sssdoptions.py:486 msgid "Objectclass for services" msgstr "Objektklasse für Dienste" -#: src/config/SSSDConfig/sssdoptions.py:481 +#: src/config/SSSDConfig/sssdoptions.py:487 msgid "Service name attribute" msgstr "Name-Attribut des Dienstes" -#: src/config/SSSDConfig/sssdoptions.py:482 +#: src/config/SSSDConfig/sssdoptions.py:488 msgid "Service port attribute" msgstr "Port-Attribut des Dienstes" -#: src/config/SSSDConfig/sssdoptions.py:483 +#: src/config/SSSDConfig/sssdoptions.py:489 msgid "Service protocol attribute" msgstr "Protokoll-Attribut des Dienstes" -#: src/config/SSSDConfig/sssdoptions.py:485 +#: src/config/SSSDConfig/sssdoptions.py:491 msgid "Lower bound for ID-mapping" msgstr "Untere Grenze für ID-Zuweisung" -#: src/config/SSSDConfig/sssdoptions.py:486 +#: src/config/SSSDConfig/sssdoptions.py:492 msgid "Upper bound for ID-mapping" msgstr "Obere Grenze für ID-Zuweisung" -#: src/config/SSSDConfig/sssdoptions.py:487 +#: src/config/SSSDConfig/sssdoptions.py:493 msgid "Number of IDs for each slice when ID-mapping" msgstr "Anzahl der IDs für jeden Teil bei der ID-Zuweisung" -#: src/config/SSSDConfig/sssdoptions.py:488 +#: src/config/SSSDConfig/sssdoptions.py:494 msgid "Use autorid-compatible algorithm for ID-mapping" msgstr "autorid-kompatiblen Algorithmus für ID-Zuweisung verwenden" -#: src/config/SSSDConfig/sssdoptions.py:489 +#: src/config/SSSDConfig/sssdoptions.py:495 msgid "Name of the default domain for ID-mapping" msgstr "Name der Vorgabe-Domain für ID-Zuweisung" -#: src/config/SSSDConfig/sssdoptions.py:490 +#: src/config/SSSDConfig/sssdoptions.py:496 msgid "SID of the default domain for ID-mapping" msgstr "SID der Vorgabedomain für ID-Zuweisung" -#: src/config/SSSDConfig/sssdoptions.py:491 +#: src/config/SSSDConfig/sssdoptions.py:497 msgid "Number of secondary slices" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:493 +#: src/config/SSSDConfig/sssdoptions.py:499 msgid "Whether to use Token-Groups" msgstr "Verwendung von Token-Gruppen" -#: src/config/SSSDConfig/sssdoptions.py:494 +#: src/config/SSSDConfig/sssdoptions.py:500 msgid "Set lower boundary for allowed IDs from the LDAP server" msgstr "Untere Grenze für zulässige IDs des LDAP-Servers angeben" -#: src/config/SSSDConfig/sssdoptions.py:495 +#: src/config/SSSDConfig/sssdoptions.py:501 msgid "Set upper boundary for allowed IDs from the LDAP server" msgstr "Obere Grenze für zulässige IDs des LDAP-Servers angeben" -#: src/config/SSSDConfig/sssdoptions.py:496 +#: src/config/SSSDConfig/sssdoptions.py:502 msgid "DN for ppolicy queries" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:497 +#: src/config/SSSDConfig/sssdoptions.py:503 msgid "How many maximum entries to fetch during a wildcard request" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:498 +#: src/config/SSSDConfig/sssdoptions.py:504 msgid "Set libldap debug level" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:501 +#: src/config/SSSDConfig/sssdoptions.py:507 msgid "Policy to evaluate the password expiration" msgstr "Regel zum Ermitteln der Ablaufzeit des Passworts" -#: src/config/SSSDConfig/sssdoptions.py:505 +#: src/config/SSSDConfig/sssdoptions.py:511 msgid "Which attributes shall be used to evaluate if an account is expired" msgstr "" "Attribute, die bei der Ermittlung verwendet werden, ob ein Konto abgelaufen " "ist" -#: src/config/SSSDConfig/sssdoptions.py:509 +#: src/config/SSSDConfig/sssdoptions.py:515 msgid "URI of an LDAP server where password changes are allowed" msgstr "URI eines LDAP-Servers, wo Passwortänderungen zulässig sind" -#: src/config/SSSDConfig/sssdoptions.py:510 +#: src/config/SSSDConfig/sssdoptions.py:516 msgid "URI of a backup LDAP server where password changes are allowed" msgstr "URI eines Ersatz-LDAP-Servers, wo Passwortänderungen zulässig sind" -#: src/config/SSSDConfig/sssdoptions.py:511 +#: src/config/SSSDConfig/sssdoptions.py:517 msgid "DNS service name for LDAP password change server" msgstr "DNS-Dienstname für den LDAP-Passwortänderungsserver" -#: src/config/SSSDConfig/sssdoptions.py:512 +#: src/config/SSSDConfig/sssdoptions.py:518 msgid "" "Whether to update the ldap_user_shadow_last_change attribute after a " "password change" @@ -1747,29 +1788,29 @@ msgstr "" "Gibt an, ob das Attribut ldap_user_shadow_last_change nach einer " "Passwortänderung aktualisiert werden soll" -#: src/config/SSSDConfig/sssdoptions.py:516 +#: src/config/SSSDConfig/sssdoptions.py:522 msgid "Base DN for sudo rules lookups" msgstr "Basis-DN für Suchanfragen nach Sudo-Regeln" -#: src/config/SSSDConfig/sssdoptions.py:517 +#: src/config/SSSDConfig/sssdoptions.py:523 msgid "Automatic full refresh period" msgstr "Periode für automatische vollständige Aktualisierung" -#: src/config/SSSDConfig/sssdoptions.py:518 +#: src/config/SSSDConfig/sssdoptions.py:524 msgid "Automatic smart refresh period" msgstr "Periode für bedingte vollständige Aktualisierung" -#: src/config/SSSDConfig/sssdoptions.py:519 +#: src/config/SSSDConfig/sssdoptions.py:525 msgid "Smart and full refresh random offset" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:520 +#: src/config/SSSDConfig/sssdoptions.py:526 msgid "Whether to filter rules by hostname, IP addresses and network" msgstr "" "Gibt an, ob Regeln nach Hostnamen, IP-Adressen oder Netzwerken gefiltert " "werden sollen" -#: src/config/SSSDConfig/sssdoptions.py:521 +#: src/config/SSSDConfig/sssdoptions.py:527 msgid "" "Hostnames and/or fully qualified domain names of this machine to filter sudo " "rules" @@ -1777,193 +1818,193 @@ msgstr "" "Hostnamen und/oder voll ausgeschriebene Domain-Namen dieses Rechners zum " "Filtern von Sudo-Regeln" -#: src/config/SSSDConfig/sssdoptions.py:522 +#: src/config/SSSDConfig/sssdoptions.py:528 msgid "IPv4 or IPv6 addresses or network of this machine to filter sudo rules" msgstr "" "IPv4- oder IPv6-Adressen oder Netzwerk dieses Rechners zum Filtern von sudo-" "Regeln" -#: src/config/SSSDConfig/sssdoptions.py:523 +#: src/config/SSSDConfig/sssdoptions.py:529 msgid "Whether to include rules that contains netgroup in host attribute" msgstr "" "Gibt an, ob Regeln im Host-Attribut einbezogen werden sollen, die " "Netzgruppen enthalten" -#: src/config/SSSDConfig/sssdoptions.py:524 +#: src/config/SSSDConfig/sssdoptions.py:530 msgid "" "Whether to include rules that contains regular expression in host attribute" msgstr "" "Gibt an, ob Regeln im Host-Attribut einbezogen werden sollen, die reguläre " "Ausdrücke enthalten" -#: src/config/SSSDConfig/sssdoptions.py:525 +#: src/config/SSSDConfig/sssdoptions.py:531 msgid "Object class for sudo rules" msgstr "Objektklasse für Sudo-Regeln" -#: src/config/SSSDConfig/sssdoptions.py:526 +#: src/config/SSSDConfig/sssdoptions.py:532 msgid "Name of attribute that is used as object class for sudo rules" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:527 +#: src/config/SSSDConfig/sssdoptions.py:533 msgid "Sudo rule name" msgstr "Sudo-Regelname" -#: src/config/SSSDConfig/sssdoptions.py:528 +#: src/config/SSSDConfig/sssdoptions.py:534 msgid "Sudo rule command attribute" msgstr "Befehlsattribut der Sudo-Regel" -#: src/config/SSSDConfig/sssdoptions.py:529 +#: src/config/SSSDConfig/sssdoptions.py:535 msgid "Sudo rule host attribute" msgstr "Host-Attribut der Sudo-Regel" -#: src/config/SSSDConfig/sssdoptions.py:530 +#: src/config/SSSDConfig/sssdoptions.py:536 msgid "Sudo rule user attribute" msgstr "Benutzer-Attribut der Sudo-Regel" -#: src/config/SSSDConfig/sssdoptions.py:531 +#: src/config/SSSDConfig/sssdoptions.py:537 msgid "Sudo rule option attribute" msgstr "Optionsattribut der Sudo-Regel" -#: src/config/SSSDConfig/sssdoptions.py:532 +#: src/config/SSSDConfig/sssdoptions.py:538 msgid "Sudo rule runas attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:533 +#: src/config/SSSDConfig/sssdoptions.py:539 msgid "Sudo rule runasuser attribute" msgstr "runasuser-Attribut der Sudo-Regel" -#: src/config/SSSDConfig/sssdoptions.py:534 +#: src/config/SSSDConfig/sssdoptions.py:540 msgid "Sudo rule runasgroup attribute" msgstr "runasgroup-Attribut der Sudo-Regel" -#: src/config/SSSDConfig/sssdoptions.py:535 +#: src/config/SSSDConfig/sssdoptions.py:541 msgid "Sudo rule notbefore attribute" msgstr "notbefore-Attribut der Sudo-Regel" -#: src/config/SSSDConfig/sssdoptions.py:536 +#: src/config/SSSDConfig/sssdoptions.py:542 msgid "Sudo rule notafter attribute" msgstr "notafter-Attribut der sudo-Regel" -#: src/config/SSSDConfig/sssdoptions.py:537 +#: src/config/SSSDConfig/sssdoptions.py:543 msgid "Sudo rule order attribute" msgstr "Reihenfolge-Attribut der Sudo-Regel" -#: src/config/SSSDConfig/sssdoptions.py:540 +#: src/config/SSSDConfig/sssdoptions.py:546 msgid "Object class for automounter maps" msgstr "Objektklasse für Automounter-Zuweisungen" -#: src/config/SSSDConfig/sssdoptions.py:541 +#: src/config/SSSDConfig/sssdoptions.py:547 msgid "Automounter map name attribute" msgstr "Name-Attribut der Automounter-Zuweisung" -#: src/config/SSSDConfig/sssdoptions.py:542 +#: src/config/SSSDConfig/sssdoptions.py:548 msgid "Object class for automounter map entries" msgstr "Objektklasse für Einträge von Automounter-Zuweisungen" -#: src/config/SSSDConfig/sssdoptions.py:543 +#: src/config/SSSDConfig/sssdoptions.py:549 msgid "Automounter map entry key attribute" msgstr "Schlüssel-Attribut des Automounter-Zuweisungseintrags" -#: src/config/SSSDConfig/sssdoptions.py:544 +#: src/config/SSSDConfig/sssdoptions.py:550 msgid "Automounter map entry value attribute" msgstr "Wert-Attribut des Automounter-Zuweisungseintrags" -#: src/config/SSSDConfig/sssdoptions.py:545 +#: src/config/SSSDConfig/sssdoptions.py:551 msgid "Base DN for automounter map lookups" msgstr "Basis-DN für Suchanfragen nach Automounter-Zuweisungen" -#: src/config/SSSDConfig/sssdoptions.py:546 +#: src/config/SSSDConfig/sssdoptions.py:552 msgid "The name of the automount master map in LDAP." msgstr "Der Name der Automount-Master-Abbildung in LDAP." -#: src/config/SSSDConfig/sssdoptions.py:549 +#: src/config/SSSDConfig/sssdoptions.py:555 msgid "Base DN for IP hosts lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:550 +#: src/config/SSSDConfig/sssdoptions.py:556 msgid "Object class for IP hosts" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:551 +#: src/config/SSSDConfig/sssdoptions.py:557 msgid "IP host name attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:552 +#: src/config/SSSDConfig/sssdoptions.py:558 msgid "IP host number (address) attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:553 +#: src/config/SSSDConfig/sssdoptions.py:559 msgid "IP host entryUSN attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:554 +#: src/config/SSSDConfig/sssdoptions.py:560 msgid "Base DN for IP networks lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:555 +#: src/config/SSSDConfig/sssdoptions.py:561 msgid "Object class for IP networks" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:556 +#: src/config/SSSDConfig/sssdoptions.py:562 msgid "IP network name attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:557 +#: src/config/SSSDConfig/sssdoptions.py:563 msgid "IP network number (address) attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:558 +#: src/config/SSSDConfig/sssdoptions.py:564 msgid "IP network entryUSN attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:561 +#: src/config/SSSDConfig/sssdoptions.py:567 msgid "Comma separated list of allowed users" msgstr "Durch Kommata getrennte Liste der erlaubten Benutzer" -#: src/config/SSSDConfig/sssdoptions.py:562 +#: src/config/SSSDConfig/sssdoptions.py:568 msgid "Comma separated list of prohibited users" msgstr "Durch Kommata getrennte Liste der verbotenen Benutzer" -#: src/config/SSSDConfig/sssdoptions.py:563 +#: src/config/SSSDConfig/sssdoptions.py:569 msgid "" "Comma separated list of groups that are allowed to log in. This applies only " "to groups within this SSSD domain. Local groups are not evaluated." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:565 +#: src/config/SSSDConfig/sssdoptions.py:571 msgid "" "Comma separated list of groups that are explicitly denied access. This " "applies only to groups within this SSSD domain. Local groups are not " "evaluated." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:569 +#: src/config/SSSDConfig/sssdoptions.py:575 msgid "The number of preforked proxy children." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:572 +#: src/config/SSSDConfig/sssdoptions.py:578 msgid "The name of the NSS library to use" msgstr "Name der zu verwendenden NSS-Bibliothek" -#: src/config/SSSDConfig/sssdoptions.py:573 +#: src/config/SSSDConfig/sssdoptions.py:579 msgid "The name of the NSS library to use for hosts and networks lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:574 +#: src/config/SSSDConfig/sssdoptions.py:580 msgid "Whether to look up canonical group name from cache if possible" msgstr "" "Gibt an, ob wenn möglich im Zwischenspeicher nach dem kanonischen " "Gruppennamen gesucht werden soll" -#: src/config/SSSDConfig/sssdoptions.py:577 +#: src/config/SSSDConfig/sssdoptions.py:583 msgid "PAM stack to use" msgstr "Zu verwendender PAM-Stapel" -#: src/config/SSSDConfig/sssdoptions.py:580 +#: src/config/SSSDConfig/sssdoptions.py:586 msgid "Path of passwd file sources." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:581 +#: src/config/SSSDConfig/sssdoptions.py:587 msgid "Path of group file sources." msgstr "" @@ -1991,159 +2032,163 @@ msgstr "Der nach dem Löschen auszuführende Befehl ist fehlgeschlagen: %1$s\n" msgid "Option -i|--interactive is not allowed together with -D|--daemon\n" msgstr "" -#: src/monitor/monitor.c:1836 +#: src/monitor/monitor.c:1838 msgid "Failed to get initial capabilities\n" msgstr "" -#: src/monitor/monitor.c:1847 +#: src/monitor/monitor.c:1849 msgid "Non-root service user support isn't built. Can't run under %" msgstr "" -#: src/monitor/monitor.c:1864 +#: src/monitor/monitor.c:1866 #, c-format msgid "Can't read config: '%s'\n" msgstr "" -#: src/monitor/monitor.c:1876 +#: src/monitor/monitor.c:1878 #, c-format -msgid "Failed to boostrap SSSD 'monitor' process: %s" +msgid "Failed to bootstrap SSSD 'monitor' process: %s" msgstr "" -#: src/monitor/monitor.c:1971 +#: src/monitor/monitor.c:1973 msgid "Out of memory\n" msgstr "Nicht genügend Speicher\n" -#: src/providers/krb5/krb5_child.c:4221 +#: src/providers/krb5/krb5_child.c:4316 msgid "Use anonymous PKINIT to request FAST armor ticket" msgstr "" -#: src/providers/krb5/krb5_child.c:4223 +#: src/providers/krb5/krb5_child.c:4318 msgid "Kerberos realm to use" msgstr "" -#: src/providers/krb5/krb5_child.c:4225 +#: src/providers/krb5/krb5_child.c:4320 msgid "Requested lifetime of the ticket" msgstr "" -#: src/providers/krb5/krb5_child.c:4227 +#: src/providers/krb5/krb5_child.c:4322 msgid "Requested renewable lifetime of the ticket" msgstr "" -#: src/providers/krb5/krb5_child.c:4229 +#: src/providers/krb5/krb5_child.c:4324 msgid "FAST options ('never', 'try', 'demand')" msgstr "" -#: src/providers/krb5/krb5_child.c:4232 +#: src/providers/krb5/krb5_child.c:4327 msgid "Specifies the server principal to use for FAST" msgstr "" -#: src/providers/krb5/krb5_child.c:4234 +#: src/providers/krb5/krb5_child.c:4329 msgid "Requests canonicalization of the principal name" msgstr "" -#: src/providers/krb5/krb5_child.c:4236 +#: src/providers/krb5/krb5_child.c:4331 msgid "Use custom version of krb5_get_init_creds_password" msgstr "" -#: src/providers/krb5/krb5_child.c:4238 +#: src/providers/krb5/krb5_child.c:4333 msgid "Check PAC flags" msgstr "" -#: src/providers/data_provider_be.c:790 +#: src/providers/krb5/krb5_child.c:4335 +msgid "Set environment variable (KEY=VALUE)" +msgstr "" + +#: src/providers/data_provider_be.c:786 msgid "Domain of the information provider (mandatory)" msgstr "Domain des Informationsanbieters (obligatorisch)" -#: src/sss_client/common.c:1165 +#: src/sss_client/common.c:1208 #, fuzzy msgid "Socket has wrong ownership or permissions." msgstr "Öffentlicher Socket hat falsche Eigentums- oder Zugriffsrechte." -#: src/sss_client/common.c:1168 +#: src/sss_client/common.c:1211 msgid "Unexpected format of the server credential message." msgstr "Unerwartetes Format der Server-Anmeldenachricht." -#: src/sss_client/common.c:1171 +#: src/sss_client/common.c:1214 #, fuzzy msgid "SSSD is not run by trusted user." msgstr "SSSD wird nicht durch Root ausgeführt." -#: src/sss_client/common.c:1174 +#: src/sss_client/common.c:1217 msgid "SSSD socket does not exist." msgstr "" -#: src/sss_client/common.c:1177 +#: src/sss_client/common.c:1220 msgid "Cannot get stat of SSSD socket." msgstr "" -#: src/sss_client/common.c:1182 +#: src/sss_client/common.c:1225 msgid "An error occurred, but no description can be found." msgstr "" "Ein Fehler ist aufgetreten, aber es kann keine Beschreibung gefunden werden." -#: src/sss_client/common.c:1188 +#: src/sss_client/common.c:1231 msgid "Unexpected error while looking for an error description" msgstr "Unerwarteter Fehler beim Suchen nach einer Fehlerbeschreibung" -#: src/sss_client/pam_sss.c:74 +#: src/sss_client/pam_sss.c:135 msgid "Permission denied. " msgstr "" -#: src/sss_client/pam_sss.c:75 src/sss_client/pam_sss.c:843 -#: src/sss_client/pam_sss.c:854 +#: src/sss_client/pam_sss.c:136 src/sss_client/pam_sss.c:921 +#: src/sss_client/pam_sss.c:932 msgid "Server message: " msgstr "Server-Meldung: " -#: src/sss_client/pam_sss.c:76 +#: src/sss_client/pam_sss.c:137 msgid "" "Kerberos TGT will not be granted upon login, user experience will be " "affected." msgstr "" -#: src/sss_client/pam_sss.c:77 +#: src/sss_client/pam_sss.c:138 msgid "Enter PIN:" msgstr "" -#: src/sss_client/pam_sss.c:320 +#: src/sss_client/pam_sss.c:385 msgid "Passwords do not match" msgstr "Passwörter stimmen nicht überein" -#: src/sss_client/pam_sss.c:508 +#: src/sss_client/pam_sss.c:584 msgid "Password reset by root is not supported." msgstr "Das Zurücksetzen des Passworts durch Root wird nicht unterstützt." -#: src/sss_client/pam_sss.c:549 +#: src/sss_client/pam_sss.c:625 msgid "Authenticated with cached credentials" msgstr "Authentifiziert mit zwischengespeicherten Anmeldedaten" -#: src/sss_client/pam_sss.c:550 +#: src/sss_client/pam_sss.c:626 msgid ", your cached password will expire at: " msgstr ", Ihr zwischengespeichertes Passwort läuft ab am: " -#: src/sss_client/pam_sss.c:580 +#: src/sss_client/pam_sss.c:656 #, c-format msgid "Your password has expired. You have %1$d grace login(s) remaining." msgstr "" "Ihr Passwort ist abgelaufen. Ihnen verbleiben nur noch %1$d Anmeldungen." -#: src/sss_client/pam_sss.c:630 +#: src/sss_client/pam_sss.c:706 #, c-format msgid "Your password will expire in %1$d %2$s." msgstr "Ihr Passwort wird in %1$d %2$s ablaufen." -#: src/sss_client/pam_sss.c:633 +#: src/sss_client/pam_sss.c:709 #, fuzzy, c-format msgid "Your password has expired." msgstr "Ihr Passwort wird in %1$d %2$s ablaufen." -#: src/sss_client/pam_sss.c:684 +#: src/sss_client/pam_sss.c:760 msgid "Authentication is denied until: " msgstr "Authentifizierung wird verweigert bis: " -#: src/sss_client/pam_sss.c:705 +#: src/sss_client/pam_sss.c:781 msgid "System is offline, password change not possible" msgstr "System ist offline, Änderung des Passworts ist nicht möglich" -#: src/sss_client/pam_sss.c:720 +#: src/sss_client/pam_sss.c:796 msgid "" "After changing the OTP password, you need to log out and back in order to " "acquire a ticket" @@ -2151,71 +2196,75 @@ msgstr "" "Nach dem Ändern des OTP-Passworts müssen Sie sich ab- und wieder anmelden, " "um ein Ticket erhalten zu können" -#: src/sss_client/pam_sss.c:735 +#: src/sss_client/pam_sss.c:813 msgid "PIN locked" msgstr "" -#: src/sss_client/pam_sss.c:750 +#: src/sss_client/pam_sss.c:828 msgid "" "No Kerberos TGT granted as the server does not support this method. Your " "single-sign on(SSO) experience will be affected." msgstr "" -#: src/sss_client/pam_sss.c:840 src/sss_client/pam_sss.c:853 +#: src/sss_client/pam_sss.c:918 src/sss_client/pam_sss.c:931 msgid "Password change failed. " msgstr "Änderung des Passworts fehlgeschlagen. " -#: src/sss_client/pam_sss.c:1859 +#: src/sss_client/pam_sss.c:2028 #, c-format -msgid "Authenticate at %1$s and press ENTER." +msgid "Authenticate at \"%1$s\"." msgstr "" -#: src/sss_client/pam_sss.c:1862 +#: src/sss_client/pam_sss.c:2031 #, c-format -msgid "Authenticate with PIN %1$s at %2$s and press ENTER." +msgid "Authenticate with PIN \"%1$s\" at \"%2$s\"." msgstr "" -#: src/sss_client/pam_sss.c:2281 +#: src/sss_client/pam_sss.c:2470 msgid "Please (re)insert (different) Smartcard" msgstr "" -#: src/sss_client/pam_sss.c:2482 +#: src/sss_client/pam_sss.c:2700 msgid "New Password: " msgstr "Neues Passwort: " -#: src/sss_client/pam_sss.c:2483 +#: src/sss_client/pam_sss.c:2701 msgid "Reenter new Password: " msgstr "Neues Passwort wiederholen: " -#: src/sss_client/pam_sss.c:2676 src/sss_client/pam_sss.c:2679 +#: src/sss_client/pam_sss.c:2890 +msgid "Press ENTER to continue." +msgstr "" + +#: src/sss_client/pam_sss.c:2913 src/sss_client/pam_sss.c:2916 msgid "First Factor: " msgstr "Erster Faktor (Passwort): " -#: src/sss_client/pam_sss.c:2677 src/sss_client/pam_sss.c:2851 +#: src/sss_client/pam_sss.c:2914 src/sss_client/pam_sss.c:3088 msgid "Second Factor (optional): " msgstr "Zweiter Faktor (optional): " -#: src/sss_client/pam_sss.c:2680 src/sss_client/pam_sss.c:2855 +#: src/sss_client/pam_sss.c:2917 src/sss_client/pam_sss.c:3092 msgid "Second Factor: " msgstr "Zweiter Faktor (OTP Token): " -#: src/sss_client/pam_sss.c:2684 +#: src/sss_client/pam_sss.c:2921 msgid "Insert your passkey device, then press ENTER." msgstr "" -#: src/sss_client/pam_sss.c:2688 src/sss_client/pam_sss.c:2696 +#: src/sss_client/pam_sss.c:2925 src/sss_client/pam_sss.c:2933 msgid "Password: " msgstr "Passwort: " -#: src/sss_client/pam_sss.c:2850 src/sss_client/pam_sss.c:2854 +#: src/sss_client/pam_sss.c:3087 src/sss_client/pam_sss.c:3091 msgid "First Factor (Current Password): " msgstr "Erster Faktor (aktuelles Passwort): " -#: src/sss_client/pam_sss.c:2874 +#: src/sss_client/pam_sss.c:3111 msgid "Current Password: " msgstr "Aktuelles Passwort: " -#: src/sss_client/pam_sss.c:3248 +#: src/sss_client/pam_sss.c:3485 msgid "Password expired. Change your password now." msgstr "Passwort ist abgelaufen. Ändern Sie Ihr Passwort jetzt." @@ -2657,9 +2706,9 @@ msgstr "" #: src/tools/sssctl/sssctl_cache.c:835 src/tools/sssctl/sssctl_cache.c:918 #: src/tools/sssctl/sssctl_cache.c:950 src/tools/sssctl/sssctl_cache.c:956 #: src/tools/sssctl/sssctl_cache.c:1010 src/tools/sssctl/sssctl_cache.c:1034 -#: src/tools/sssctl/sssctl_cache.c:1085 src/tools/sssctl/sssctl_cache.c:1194 -#: src/tools/sssctl/sssctl_cache.c:1229 src/tools/sssctl/sssctl_cache.c:1235 -#: src/tools/sssctl/sssctl_cache.c:1244 +#: src/tools/sssctl/sssctl_cache.c:1085 src/tools/sssctl/sssctl_cache.c:1195 +#: src/tools/sssctl/sssctl_cache.c:1230 src/tools/sssctl/sssctl_cache.c:1236 +#: src/tools/sssctl/sssctl_cache.c:1245 msgid "talloc failed\n" msgstr "" @@ -2733,26 +2782,26 @@ msgstr "" msgid "Unable to remove downloaded GPO files: %s\n" msgstr "" -#: src/tools/sssctl/sssctl_cache.c:1165 +#: src/tools/sssctl/sssctl_cache.c:1166 #, c-format msgid "Failed to fetch cache entry: %s\n" msgstr "" -#: src/tools/sssctl/sssctl_cache.c:1170 +#: src/tools/sssctl/sssctl_cache.c:1171 #, fuzzy msgid "Could not determine object domain\n" msgstr "Verfügbare Domains konnten nicht geöffnet werden\n" -#: src/tools/sssctl/sssctl_cache.c:1200 +#: src/tools/sssctl/sssctl_cache.c:1201 msgid "Could not find GUID attribute in GPO entry\n" msgstr "" -#: src/tools/sssctl/sssctl_cache.c:1206 +#: src/tools/sssctl/sssctl_cache.c:1207 #, c-format msgid "Failed to delete GPO: %s\n" msgstr "" -#: src/tools/sssctl/sssctl_cache.c:1210 +#: src/tools/sssctl/sssctl_cache.c:1211 #, c-format msgid "%s removed from cache\n" msgstr "" @@ -2840,39 +2889,39 @@ msgid "" "\"/my/path/sssd.conf\", the snippet dir \"/my/path/conf.d\" is used)" msgstr "" -#: src/tools/sssctl/sssctl_config.c:114 +#: src/tools/sssctl/sssctl_config.c:126 #, c-format msgid "File %1$s does not exist.\n" msgstr "" -#: src/tools/sssctl/sssctl_config.c:115 +#: src/tools/sssctl/sssctl_config.c:127 msgid "There is no configuration.\n" msgstr "" -#: src/tools/sssctl/sssctl_config.c:120 +#: src/tools/sssctl/sssctl_config.c:132 #, fuzzy, c-format msgid "Configuration validation failed: %s\n" msgstr "Der nach dem Löschen auszuführende Befehl ist fehlgeschlagen: %1$s\n" -#: src/tools/sssctl/sssctl_config.c:121 +#: src/tools/sssctl/sssctl_config.c:133 msgid "Run with high debug level to see details.\n" msgstr "" -#: src/tools/sssctl/sssctl_config.c:130 -msgid "Failed to run validators" +#: src/tools/sssctl/sssctl_config.c:142 +msgid "Failed to run validators\n" msgstr "" -#: src/tools/sssctl/sssctl_config.c:134 +#: src/tools/sssctl/sssctl_config.c:146 #, c-format msgid "Issues identified by validators: %zu\n" msgstr "" -#: src/tools/sssctl/sssctl_config.c:145 +#: src/tools/sssctl/sssctl_config.c:157 #, c-format msgid "Messages generated during configuration merging: %zu\n" msgstr "" -#: src/tools/sssctl/sssctl_config.c:158 +#: src/tools/sssctl/sssctl_config.c:170 #, c-format msgid "Used configuration snippet files: %zu\n" msgstr "" diff --git a/po/es.po b/po/es.po index be4e08071d7..16c360748ef 100644 --- a/po/es.po +++ b/po/es.po @@ -22,8 +22,8 @@ msgid "" msgstr "" "Project-Id-Version: PACKAGE VERSION\n" "Report-Msgid-Bugs-To: sssd-devel@lists.fedorahosted.org\n" -"POT-Creation-Date: 2026-01-14 14:57+0000\n" -"PO-Revision-Date: 2026-04-23 16:39+0000\n" +"POT-Creation-Date: 2026-10-02 15:57+0000\n" +"PO-Revision-Date: 2026-10-05 16:37+0000\n" "Last-Translator: Weblate Translation Memory \n" "Language-Team: Spanish : that must be enforced " "for PAM access with GSSAPI authentication" @@ -415,31 +416,41 @@ msgstr "" "La lista de pares : que se debe hacer " "cumplir para el acceso PAM con autenticación GSSAPI" -#: src/config/SSSDConfig/sssdoptions.py:113 +#: src/config/SSSDConfig/sssdoptions.py:109 +#, fuzzy +msgid "" +"List of triples :: that assigns " +"additional information from the Kerberos ticket to an authentication " +"indicator." +msgstr "" +"La lista de pares : que se debe hacer " +"cumplir para el acceso PAM con autenticación GSSAPI" + +#: src/config/SSSDConfig/sssdoptions.py:112 msgid "Allow passkey device authentication." -msgstr "Permitir la autentificación del dispositivo con clave de acceso." +msgstr "Permitir la autenticación del dispositivo con clave de acceso." -#: src/config/SSSDConfig/sssdoptions.py:114 +#: src/config/SSSDConfig/sssdoptions.py:113 msgid "How many seconds will pam_sss wait for passkey_child to finish" msgstr "Cuantos segundos esperará pam_sss a que termine passkey_child" -#: src/config/SSSDConfig/sssdoptions.py:115 +#: src/config/SSSDConfig/sssdoptions.py:114 msgid "Enable debugging in the libfido2 library" msgstr "Habilitar la depuración en la librería libfido2" -#: src/config/SSSDConfig/sssdoptions.py:116 +#: src/config/SSSDConfig/sssdoptions.py:115 msgid "Enable JSON protocol for authentication methods selection." msgstr "Habilita protocolo JSON para selección de métodos de autenticación." -#: src/config/SSSDConfig/sssdoptions.py:119 +#: src/config/SSSDConfig/sssdoptions.py:118 msgid "Whether to evaluate the time-based attributes in sudo rules" msgstr "Ya sea para evaluar los atributos basados en el tiempo en reglas sudo" -#: src/config/SSSDConfig/sssdoptions.py:120 +#: src/config/SSSDConfig/sssdoptions.py:119 msgid "If true, SSSD will switch back to lower-wins ordering logic" msgstr "Si cierto, SSSD volverá a la lógica de ordenación de triunfos menores" -#: src/config/SSSDConfig/sssdoptions.py:121 +#: src/config/SSSDConfig/sssdoptions.py:120 msgid "" "Maximum number of rules that can be refreshed at once. If this is exceeded, " "full refresh is performed." @@ -447,13 +458,13 @@ msgstr "" "Número máximo de reglas que se pueden refrescar de una vez. Si esto se " "excede, se llevará a cabo un refresco total." -#: src/config/SSSDConfig/sssdoptions.py:128 +#: src/config/SSSDConfig/sssdoptions.py:127 msgid "Whether to hash host names and addresses in the known_hosts file" msgstr "" "Si se deben picar los nombres de host y las direcciones en el archivo known-" "hosts" -#: src/config/SSSDConfig/sssdoptions.py:129 +#: src/config/SSSDConfig/sssdoptions.py:128 msgid "" "How many seconds to keep a host in the known_hosts file after its host keys " "were requested" @@ -461,15 +472,15 @@ msgstr "" "Cuantos segundos mantener un host en el archivos known_host después de que " "se haya pedido su clave de host" -#: src/config/SSSDConfig/sssdoptions.py:131 +#: src/config/SSSDConfig/sssdoptions.py:130 msgid "Path to storage of trusted CA certificates" msgstr "Ruta al almacenamiento de los certificados CA de confianza" -#: src/config/SSSDConfig/sssdoptions.py:132 +#: src/config/SSSDConfig/sssdoptions.py:131 msgid "Allow to generate ssh-keys from certificates" msgstr "Permite generar claves ssh desde certificados" -#: src/config/SSSDConfig/sssdoptions.py:133 +#: src/config/SSSDConfig/sssdoptions.py:132 msgid "" "Use the following matching rules to filter the certificates for ssh-key " "generation" @@ -477,25 +488,25 @@ msgstr "" "Usar las siguientes reglas de coincidencia para filtrar los certificados " "para la generación de clave ssh" -#: src/config/SSSDConfig/sssdoptions.py:137 +#: src/config/SSSDConfig/sssdoptions.py:136 msgid "List of UIDs or user names allowed to access the PAC responder" msgstr "" "Lista de UIDs o nombres de usuario que tienen permitido acceder al " "contestador PAC" -#: src/config/SSSDConfig/sssdoptions.py:138 +#: src/config/SSSDConfig/sssdoptions.py:137 msgid "How long the PAC data is considered valid" msgstr "Longitud de datos PAC considerados válidos" -#: src/config/SSSDConfig/sssdoptions.py:139 +#: src/config/SSSDConfig/sssdoptions.py:138 msgid "Validate the PAC" msgstr "Validar el PAC" -#: src/config/SSSDConfig/sssdoptions.py:142 +#: src/config/SSSDConfig/sssdoptions.py:141 msgid "List of user attributes the InfoPipe is allowed to publish" msgstr "Lista de atributos de usuario que InforPipe tiene permitido publicar" -#: src/config/SSSDConfig/sssdoptions.py:145 +#: src/config/SSSDConfig/sssdoptions.py:144 msgid "" "One of the following strings specifying the scope of session recording: none " "- No users are recorded. some - Users/groups specified by users and groups " @@ -506,7 +517,7 @@ msgstr "" "por las opciones usuarios y grupos se registran. all - Se registran todos " "los usuarios." -#: src/config/SSSDConfig/sssdoptions.py:148 +#: src/config/SSSDConfig/sssdoptions.py:147 msgid "" "A comma-separated list of users which should have session recording enabled. " "Matches user names as returned by NSS. I.e. after the possible space " @@ -517,7 +528,7 @@ msgstr "" "NSS. I.e. después de las posibles sustituciones de espacios, cambios de " "mayúsculas/minúsculas, etc." -#: src/config/SSSDConfig/sssdoptions.py:150 +#: src/config/SSSDConfig/sssdoptions.py:149 msgid "" "A comma-separated list of groups, members of which should have session " "recording enabled. Matches group names as returned by NSS. I.e. after the " @@ -528,7 +539,7 @@ msgstr "" "I.e. después de los posibles cambios de espacio, cambios de mayúsculas/" "minúsculas, etc." -#: src/config/SSSDConfig/sssdoptions.py:153 +#: src/config/SSSDConfig/sssdoptions.py:152 msgid "" "A comma-separated list of users to be excluded from recording, only when " "scope=all" @@ -536,7 +547,7 @@ msgstr "" "Una lista separada por comas de usuarios a ser excluidos de la grabación, " "sólo cuando scope=all" -#: src/config/SSSDConfig/sssdoptions.py:154 +#: src/config/SSSDConfig/sssdoptions.py:153 msgid "" "A comma-separated list of groups, members of which should be excluded from " "recording, only when scope=all. " @@ -544,79 +555,79 @@ msgstr "" "Una lista separada de grupos, cuyos miembros serían excluidos de la " "grabación, sólo cuando scope=all. " -#: src/config/SSSDConfig/sssdoptions.py:158 +#: src/config/SSSDConfig/sssdoptions.py:157 msgid "Identity provider" msgstr "Proveedor de identidad" -#: src/config/SSSDConfig/sssdoptions.py:159 +#: src/config/SSSDConfig/sssdoptions.py:158 msgid "Authentication provider" msgstr "Proveedor de Autenticación" -#: src/config/SSSDConfig/sssdoptions.py:160 +#: src/config/SSSDConfig/sssdoptions.py:159 msgid "Access control provider" msgstr "Proveedor de control de acceso" -#: src/config/SSSDConfig/sssdoptions.py:161 +#: src/config/SSSDConfig/sssdoptions.py:160 msgid "Password change provider" msgstr "Proveedor de cambio de contraseña" -#: src/config/SSSDConfig/sssdoptions.py:162 +#: src/config/SSSDConfig/sssdoptions.py:161 msgid "SUDO provider" msgstr "Proveedor de SUDO" -#: src/config/SSSDConfig/sssdoptions.py:163 +#: src/config/SSSDConfig/sssdoptions.py:162 msgid "Autofs provider" msgstr "Proveedor de Autofs" -#: src/config/SSSDConfig/sssdoptions.py:164 +#: src/config/SSSDConfig/sssdoptions.py:163 msgid "Host identity provider" msgstr "Suministrador de identidad de host" -#: src/config/SSSDConfig/sssdoptions.py:165 +#: src/config/SSSDConfig/sssdoptions.py:164 msgid "SELinux provider" msgstr "Proveedor SELinux" -#: src/config/SSSDConfig/sssdoptions.py:166 +#: src/config/SSSDConfig/sssdoptions.py:165 msgid "Session management provider" msgstr "Proveedor de gestión de sesión" -#: src/config/SSSDConfig/sssdoptions.py:167 +#: src/config/SSSDConfig/sssdoptions.py:166 msgid "Resolver provider" msgstr "Proveedor de resolución" -#: src/config/SSSDConfig/sssdoptions.py:170 +#: src/config/SSSDConfig/sssdoptions.py:169 msgid "Whether the domain is usable by the OS or by applications" msgstr "Si el dominio es utilizable por el SO o por las aplicaciones" -#: src/config/SSSDConfig/sssdoptions.py:171 +#: src/config/SSSDConfig/sssdoptions.py:170 msgid "Enable or disable the domain" msgstr "Habilitar o deshabilitar el dominio" -#: src/config/SSSDConfig/sssdoptions.py:172 +#: src/config/SSSDConfig/sssdoptions.py:171 msgid "Minimum user ID" msgstr "ID mínimo de usuario" -#: src/config/SSSDConfig/sssdoptions.py:173 +#: src/config/SSSDConfig/sssdoptions.py:172 msgid "Maximum user ID" msgstr "ID máximo de usuario" -#: src/config/SSSDConfig/sssdoptions.py:174 +#: src/config/SSSDConfig/sssdoptions.py:173 msgid "Enable enumerating all users/groups" msgstr "Habilitar la enumeración de todos los usuarios/grupos" -#: src/config/SSSDConfig/sssdoptions.py:175 +#: src/config/SSSDConfig/sssdoptions.py:174 msgid "Cache credentials for offline login" msgstr "Hacer caché de las credenciales para ingresos fuera de línea" -#: src/config/SSSDConfig/sssdoptions.py:176 +#: src/config/SSSDConfig/sssdoptions.py:175 msgid "Display users/groups in fully-qualified form" msgstr "Mostrar los usuarios/grupos en un formato completamente calificado" -#: src/config/SSSDConfig/sssdoptions.py:177 +#: src/config/SSSDConfig/sssdoptions.py:176 msgid "Don't include group members in group lookups" msgstr "No incluye a los miembros del grupo en las búsquedas de grupo" -#: src/config/SSSDConfig/sssdoptions.py:178 +#: src/config/SSSDConfig/sssdoptions.py:177 #: src/config/SSSDConfig/sssdoptions.py:190 #: src/config/SSSDConfig/sssdoptions.py:191 #: src/config/SSSDConfig/sssdoptions.py:192 @@ -627,18 +638,18 @@ msgstr "No incluye a los miembros del grupo en las búsquedas de grupo" msgid "Entry cache timeout length (seconds)" msgstr "Tiempo máximo de una entrada del caché (segundos)" -#: src/config/SSSDConfig/sssdoptions.py:179 +#: src/config/SSSDConfig/sssdoptions.py:178 msgid "" "Restrict or prefer a specific address family when performing DNS lookups" msgstr "" "Restringir o preferir una familia de direcciones específica, cuando se " "realicen búsquedas DNS" -#: src/config/SSSDConfig/sssdoptions.py:180 +#: src/config/SSSDConfig/sssdoptions.py:179 msgid "How long to keep cached entries after last successful login (days)" msgstr "Por cuánto tiempo permitir ingresos cacheados luego del último (días)" -#: src/config/SSSDConfig/sssdoptions.py:181 +#: src/config/SSSDConfig/sssdoptions.py:180 msgid "" "How long should SSSD talk to single DNS server before trying next server " "(miliseconds)" @@ -646,23 +657,23 @@ msgstr "" "Cuanto debería SSSD hablar con un único servidor DNS antes de intentar el " "siguiente servidor (milisegundos)" -#: src/config/SSSDConfig/sssdoptions.py:183 +#: src/config/SSSDConfig/sssdoptions.py:182 msgid "How long should keep trying to resolve single DNS query (seconds)" msgstr "" "Cuanto debería mantenerse intentando resolver una única petición DNS " "(segundos)" -#: src/config/SSSDConfig/sssdoptions.py:184 +#: src/config/SSSDConfig/sssdoptions.py:183 msgid "How long to wait for replies from DNS when resolving servers (seconds)" msgstr "" "Cantidad de tiempo (en segundos) a esperar respuestas desde DNS cuando se " "estén resolviendo servidores" -#: src/config/SSSDConfig/sssdoptions.py:185 +#: src/config/SSSDConfig/sssdoptions.py:184 msgid "The domain part of service discovery DNS query" msgstr "La sección del dominio de la consulta para descubrir servicios DNS" -#: src/config/SSSDConfig/sssdoptions.py:186 +#: src/config/SSSDConfig/sssdoptions.py:185 msgid "" "Specifies the interval, in seconds, that SSSD waits before attempting to " "reconnect to the primary server after a successful connection to the backup " @@ -672,14 +683,18 @@ msgstr "" "volver a conector con el servidor principal después de una conexión con " "éxito al servidor de respaldo" -#: src/config/SSSDConfig/sssdoptions.py:188 +#: src/config/SSSDConfig/sssdoptions.py:187 msgid "Override GID value from the identity provider with this value" msgstr "Sustituye valor GID del proveedor de la identidad con este valor" -#: src/config/SSSDConfig/sssdoptions.py:189 +#: src/config/SSSDConfig/sssdoptions.py:188 msgid "Treat usernames as case sensitive" msgstr "Trate al nombre de usuario con mayúsculas y minúsculas" +#: src/config/SSSDConfig/sssdoptions.py:189 +msgid "Lookups by ID are expensive or do not work at all" +msgstr "" + #: src/config/SSSDConfig/sssdoptions.py:197 msgid "How often should expired entries be refreshed in background" msgstr "" @@ -938,7 +953,7 @@ msgid "Search base for SUBID ranges" msgstr "Buscar base para rangos SUBID" #: src/config/SSSDConfig/sssdoptions.py:259 -#: src/config/SSSDConfig/sssdoptions.py:506 +#: src/config/SSSDConfig/sssdoptions.py:512 msgid "Which rules should be used to evaluate access control" msgstr "Las reglas que deberían ser utilizadas para evaluar control de acceso" @@ -1102,7 +1117,7 @@ msgstr "" "Habilita la localización de sitios DNS en base al servicio de descubrimiento" #: src/config/SSSDConfig/sssdoptions.py:301 -#: src/config/SSSDConfig/sssdoptions.py:504 +#: src/config/SSSDConfig/sssdoptions.py:510 msgid "LDAP filter to determine access privileges" msgstr "Filtro LDAP para determinar privilegios de acceso" @@ -1127,37 +1142,37 @@ msgid "" "PAM service names that map to the GPO (Deny)InteractiveLogonRight policy " "settings" msgstr "" -"Servicio de nombres PAM que mapea a los ajustes de política GPO (Deny)" -"InteractiveLogonRight" +"Servicio de nombres PAM que mapea a los ajustes de política GPO " +"(Deny)InteractiveLogonRight" #: src/config/SSSDConfig/sssdoptions.py:307 msgid "" "PAM service names that map to the GPO (Deny)RemoteInteractiveLogonRight " "policy settings" msgstr "" -"Servicio de nombres PAM que mapea a los ajustes de política GPO (Deny)" -"RemoteInteractiveLogonRight" +"Servicio de nombres PAM que mapea a los ajustes de política GPO " +"(Deny)RemoteInteractiveLogonRight" #: src/config/SSSDConfig/sssdoptions.py:309 msgid "" "PAM service names that map to the GPO (Deny)NetworkLogonRight policy settings" msgstr "" -"Servicio de nombres PAM que mapea a los ajustes de política GPO (Deny)" -"NetworkLogonRight" +"Servicio de nombres PAM que mapea a los ajustes de política GPO " +"(Deny)NetworkLogonRight" #: src/config/SSSDConfig/sssdoptions.py:310 msgid "" "PAM service names that map to the GPO (Deny)BatchLogonRight policy settings" msgstr "" -"Servicio de nombres PAM que mapea a los ajustes de política GPO (Deny)" -"BatchLogonRight" +"Servicio de nombres PAM que mapea a los ajustes de política GPO " +"(Deny)BatchLogonRight" #: src/config/SSSDConfig/sssdoptions.py:311 msgid "" "PAM service names that map to the GPO (Deny)ServiceLogonRight policy settings" msgstr "" -"Servicio de nombres PAM que mapea a los ajustes de política GPO (Deny)" -"ServiceLogonRight" +"Servicio de nombres PAM que mapea a los ajustes de política GPO " +"(Deny)ServiceLogonRight" #: src/config/SSSDConfig/sssdoptions.py:312 msgid "PAM service names for which GPO-based access is always granted" @@ -1557,7 +1572,7 @@ msgid "UUID attribute" msgstr "Atributo UUID" #: src/config/SSSDConfig/sssdoptions.py:423 -#: src/config/SSSDConfig/sssdoptions.py:464 +#: src/config/SSSDConfig/sssdoptions.py:470 msgid "objectSID attribute" msgstr "Atributo objectSID" @@ -1665,7 +1680,8 @@ msgstr "Atributo de clave pública SSH" #: src/config/SSSDConfig/sssdoptions.py:449 msgid "attribute listing allowed authentication types for a user" -msgstr "atributo listando los tipos de autenticación permitidos para un usuario" +msgstr "" +"atributo listando los tipos de autenticación permitidos para un usuario" #: src/config/SSSDConfig/sssdoptions.py:450 msgid "attribute containing the X509 certificate of the user" @@ -1685,180 +1701,211 @@ msgid "A list of extra attributes to download along with the user entry" msgstr "" "Una lista de los atributos extra a descargar junto con la entrada del usuario" +#: src/config/SSSDConfig/sssdoptions.py:456 +#, fuzzy +msgid "The object class of an subid entry in LDAP." +msgstr "La clase de objeto de una entrada de host en LDAP." + #: src/config/SSSDConfig/sssdoptions.py:457 +#, fuzzy +msgid "Subordinate user ID count attribute" +msgstr "Atributo de la regla usuario de sudo" + +#: src/config/SSSDConfig/sssdoptions.py:458 +#, fuzzy +msgid "Subordinate group ID count attribute" +msgstr "Atributo de la regla opción de sudo" + +#: src/config/SSSDConfig/sssdoptions.py:459 +#, fuzzy +msgid "User ID range start value attribute" +msgstr "Atributo Username" + +#: src/config/SSSDConfig/sssdoptions.py:460 +#, fuzzy +msgid "Group ID range start value attribute" +msgstr "Atributo UUID de grupo" + +#: src/config/SSSDConfig/sssdoptions.py:461 +msgid "Owner of an entry" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:463 msgid "Base DN for group lookups" msgstr "DN base para busqueda de grupos" -#: src/config/SSSDConfig/sssdoptions.py:458 +#: src/config/SSSDConfig/sssdoptions.py:464 msgid "Objectclass for groups" msgstr "clase objeto para" -#: src/config/SSSDConfig/sssdoptions.py:459 +#: src/config/SSSDConfig/sssdoptions.py:465 msgid "Group name" msgstr "Nombre del grupo" -#: src/config/SSSDConfig/sssdoptions.py:460 +#: src/config/SSSDConfig/sssdoptions.py:466 msgid "Group password" msgstr "Contraseña del grupo" -#: src/config/SSSDConfig/sssdoptions.py:461 +#: src/config/SSSDConfig/sssdoptions.py:467 msgid "GID attribute" msgstr "Atributo GID" -#: src/config/SSSDConfig/sssdoptions.py:462 +#: src/config/SSSDConfig/sssdoptions.py:468 msgid "Group member attribute" msgstr "Atributo de miembro del grupo" -#: src/config/SSSDConfig/sssdoptions.py:463 +#: src/config/SSSDConfig/sssdoptions.py:469 msgid "Group UUID attribute" msgstr "Atributo UUID de grupo" -#: src/config/SSSDConfig/sssdoptions.py:465 +#: src/config/SSSDConfig/sssdoptions.py:471 msgid "Modification time attribute for groups" msgstr "Atributo de modificación de tiempo para los grupos" -#: src/config/SSSDConfig/sssdoptions.py:466 +#: src/config/SSSDConfig/sssdoptions.py:472 msgid "Type of the group and other flags" msgstr "Tipo del grupo y otros indicadores" -#: src/config/SSSDConfig/sssdoptions.py:467 +#: src/config/SSSDConfig/sssdoptions.py:473 msgid "The LDAP group external member attribute" msgstr "Atributo de miembro de grupo externo LDAP" -#: src/config/SSSDConfig/sssdoptions.py:468 +#: src/config/SSSDConfig/sssdoptions.py:474 msgid "Maximum nesting level SSSD will follow" msgstr "Máximo nivel de anidamiento que seguirá SSSD" -#: src/config/SSSDConfig/sssdoptions.py:469 +#: src/config/SSSDConfig/sssdoptions.py:475 msgid "Filter for group lookups" msgstr "Filtro para búsquedas de grupos" -#: src/config/SSSDConfig/sssdoptions.py:470 +#: src/config/SSSDConfig/sssdoptions.py:476 msgid "Scope of group lookups" msgstr "Alcance de la búsqueda de grupos" -#: src/config/SSSDConfig/sssdoptions.py:472 +#: src/config/SSSDConfig/sssdoptions.py:478 msgid "Base DN for netgroup lookups" msgstr "DN base para búsquedas de grupos de red" -#: src/config/SSSDConfig/sssdoptions.py:473 +#: src/config/SSSDConfig/sssdoptions.py:479 msgid "Objectclass for netgroups" msgstr "Clases de objetos para grupos de red" -#: src/config/SSSDConfig/sssdoptions.py:474 +#: src/config/SSSDConfig/sssdoptions.py:480 msgid "Netgroup name" msgstr "Nombre de grupo de red" -#: src/config/SSSDConfig/sssdoptions.py:475 +#: src/config/SSSDConfig/sssdoptions.py:481 msgid "Netgroups members attribute" msgstr "Atributo de miembros de grupos de red" -#: src/config/SSSDConfig/sssdoptions.py:476 +#: src/config/SSSDConfig/sssdoptions.py:482 msgid "Netgroup triple attribute" msgstr "Atributo triple de grupo de red" -#: src/config/SSSDConfig/sssdoptions.py:477 +#: src/config/SSSDConfig/sssdoptions.py:483 msgid "Modification time attribute for netgroups" msgstr "Atributo de modificación de tiempo para grupos de red" -#: src/config/SSSDConfig/sssdoptions.py:479 +#: src/config/SSSDConfig/sssdoptions.py:485 msgid "Base DN for service lookups" msgstr "Base DN para servicio de búsquedas" -#: src/config/SSSDConfig/sssdoptions.py:480 +#: src/config/SSSDConfig/sssdoptions.py:486 msgid "Objectclass for services" msgstr "Clase de objeto para servicio" -#: src/config/SSSDConfig/sssdoptions.py:481 +#: src/config/SSSDConfig/sssdoptions.py:487 msgid "Service name attribute" msgstr "Atributo de nombre de servicio" -#: src/config/SSSDConfig/sssdoptions.py:482 +#: src/config/SSSDConfig/sssdoptions.py:488 msgid "Service port attribute" msgstr "Atributo de puerto de servicio" -#: src/config/SSSDConfig/sssdoptions.py:483 +#: src/config/SSSDConfig/sssdoptions.py:489 msgid "Service protocol attribute" msgstr "Atributo de protocolo de servidor" -#: src/config/SSSDConfig/sssdoptions.py:485 +#: src/config/SSSDConfig/sssdoptions.py:491 msgid "Lower bound for ID-mapping" msgstr "Acotado más bajo para la relación de ID" -#: src/config/SSSDConfig/sssdoptions.py:486 +#: src/config/SSSDConfig/sssdoptions.py:492 msgid "Upper bound for ID-mapping" msgstr "Acotado más alto para la relación de ID" -#: src/config/SSSDConfig/sssdoptions.py:487 +#: src/config/SSSDConfig/sssdoptions.py:493 msgid "Number of IDs for each slice when ID-mapping" msgstr "Número de ID por cada trozo cuando se relacionan con ID" -#: src/config/SSSDConfig/sssdoptions.py:488 +#: src/config/SSSDConfig/sssdoptions.py:494 msgid "Use autorid-compatible algorithm for ID-mapping" msgstr "Usar el algoritmo compatible con autorid para el mapeo de ID" -#: src/config/SSSDConfig/sssdoptions.py:489 +#: src/config/SSSDConfig/sssdoptions.py:495 msgid "Name of the default domain for ID-mapping" msgstr "Nombre del dominio por defecto para el mapeo de ID" -#: src/config/SSSDConfig/sssdoptions.py:490 +#: src/config/SSSDConfig/sssdoptions.py:496 msgid "SID of the default domain for ID-mapping" msgstr "SID del dominio por defecto para el mapeo de ID" -#: src/config/SSSDConfig/sssdoptions.py:491 +#: src/config/SSSDConfig/sssdoptions.py:497 msgid "Number of secondary slices" msgstr "Número de rodajas secundarias" -#: src/config/SSSDConfig/sssdoptions.py:493 +#: src/config/SSSDConfig/sssdoptions.py:499 msgid "Whether to use Token-Groups" msgstr "Si usar Token-Groups" -#: src/config/SSSDConfig/sssdoptions.py:494 +#: src/config/SSSDConfig/sssdoptions.py:500 msgid "Set lower boundary for allowed IDs from the LDAP server" msgstr "Fijar el límite más bajo de IDs permitidas desde el servidor LDAP" -#: src/config/SSSDConfig/sssdoptions.py:495 +#: src/config/SSSDConfig/sssdoptions.py:501 msgid "Set upper boundary for allowed IDs from the LDAP server" -msgstr "Fijar el límite más alto para las IDs permitidas desde el servidor LDAP" +msgstr "" +"Fijar el límite más alto para las IDs permitidas desde el servidor LDAP" -#: src/config/SSSDConfig/sssdoptions.py:496 +#: src/config/SSSDConfig/sssdoptions.py:502 msgid "DN for ppolicy queries" msgstr "DN para consultas ppolicy" -#: src/config/SSSDConfig/sssdoptions.py:497 +#: src/config/SSSDConfig/sssdoptions.py:503 msgid "How many maximum entries to fetch during a wildcard request" msgstr "Máximas entradas a recuperar durante una solicitud de comodín" -#: src/config/SSSDConfig/sssdoptions.py:498 +#: src/config/SSSDConfig/sssdoptions.py:504 msgid "Set libldap debug level" msgstr "Fija el nivel de depuración de libldap" -#: src/config/SSSDConfig/sssdoptions.py:501 +#: src/config/SSSDConfig/sssdoptions.py:507 msgid "Policy to evaluate the password expiration" msgstr "Política para evaluar el vencimiento de la contraseña" -#: src/config/SSSDConfig/sssdoptions.py:505 +#: src/config/SSSDConfig/sssdoptions.py:511 msgid "Which attributes shall be used to evaluate if an account is expired" msgstr "" "Los atributos que deberán ser utilizados para evaluar si una cuenta ha " "expirado" -#: src/config/SSSDConfig/sssdoptions.py:509 +#: src/config/SSSDConfig/sssdoptions.py:515 msgid "URI of an LDAP server where password changes are allowed" -msgstr "URI de un servidor LDAP donde se permite la modificación de contraseñas" +msgstr "" +"URI de un servidor LDAP donde se permite la modificación de contraseñas" -#: src/config/SSSDConfig/sssdoptions.py:510 +#: src/config/SSSDConfig/sssdoptions.py:516 msgid "URI of a backup LDAP server where password changes are allowed" msgstr "" "URI de un servidor de respaldo LDAP donde están permitidos los cambios de " "contraseña" -#: src/config/SSSDConfig/sssdoptions.py:511 +#: src/config/SSSDConfig/sssdoptions.py:517 msgid "DNS service name for LDAP password change server" msgstr "" "Nombre del servicio DNS para el servidor de modificación de contraseñas LDAP" -#: src/config/SSSDConfig/sssdoptions.py:512 +#: src/config/SSSDConfig/sssdoptions.py:518 msgid "" "Whether to update the ldap_user_shadow_last_change attribute after a " "password change" @@ -1866,27 +1913,27 @@ msgstr "" "Si actualizar el atributo ldap_user_shadow_last_change después de un cambio " "de contraseña" -#: src/config/SSSDConfig/sssdoptions.py:516 +#: src/config/SSSDConfig/sssdoptions.py:522 msgid "Base DN for sudo rules lookups" msgstr "Base DN para búsquedas de reglas sudo" -#: src/config/SSSDConfig/sssdoptions.py:517 +#: src/config/SSSDConfig/sssdoptions.py:523 msgid "Automatic full refresh period" msgstr "Período de refresco total automático" -#: src/config/SSSDConfig/sssdoptions.py:518 +#: src/config/SSSDConfig/sssdoptions.py:524 msgid "Automatic smart refresh period" msgstr "Período de refresco inteligente automático" -#: src/config/SSSDConfig/sssdoptions.py:519 +#: src/config/SSSDConfig/sssdoptions.py:525 msgid "Smart and full refresh random offset" msgstr "Desplazamiento aleatorio de actualización completa e inteligente" -#: src/config/SSSDConfig/sssdoptions.py:520 +#: src/config/SSSDConfig/sssdoptions.py:526 msgid "Whether to filter rules by hostname, IP addresses and network" msgstr "Si filtrar la reglas por nombre de host, direcciones IP y red" -#: src/config/SSSDConfig/sssdoptions.py:521 +#: src/config/SSSDConfig/sssdoptions.py:527 msgid "" "Hostnames and/or fully qualified domain names of this machine to filter sudo " "rules" @@ -1894,149 +1941,149 @@ msgstr "" "Nombres de host y/o nombres de dominio totalmente cualificado de esta " "máquina para filtrar las reglas sudo" -#: src/config/SSSDConfig/sssdoptions.py:522 +#: src/config/SSSDConfig/sssdoptions.py:528 msgid "IPv4 or IPv6 addresses or network of this machine to filter sudo rules" msgstr "Direcciones o red IPv4 o IPv6 de esta máquina para filtrar reglas sudo" -#: src/config/SSSDConfig/sssdoptions.py:523 +#: src/config/SSSDConfig/sssdoptions.py:529 msgid "Whether to include rules that contains netgroup in host attribute" msgstr "Si incluir reglas que contienen netgroup en el atributo de host" -#: src/config/SSSDConfig/sssdoptions.py:524 +#: src/config/SSSDConfig/sssdoptions.py:530 msgid "" "Whether to include rules that contains regular expression in host attribute" msgstr "" "Si incluir reglas que contengan expresiones regulares en el atributo de host" -#: src/config/SSSDConfig/sssdoptions.py:525 +#: src/config/SSSDConfig/sssdoptions.py:531 msgid "Object class for sudo rules" msgstr "Objeto clase para reglas sudo" -#: src/config/SSSDConfig/sssdoptions.py:526 +#: src/config/SSSDConfig/sssdoptions.py:532 msgid "Name of attribute that is used as object class for sudo rules" msgstr "Nombre del atributo que se usa como objeto clase para reglas sudo" -#: src/config/SSSDConfig/sssdoptions.py:527 +#: src/config/SSSDConfig/sssdoptions.py:533 msgid "Sudo rule name" msgstr "Nombre de regla sudo" -#: src/config/SSSDConfig/sssdoptions.py:528 +#: src/config/SSSDConfig/sssdoptions.py:534 msgid "Sudo rule command attribute" msgstr "Atributo de regla de comando sudo" -#: src/config/SSSDConfig/sssdoptions.py:529 +#: src/config/SSSDConfig/sssdoptions.py:535 msgid "Sudo rule host attribute" msgstr "Atributo de la regla host de sudo" -#: src/config/SSSDConfig/sssdoptions.py:530 +#: src/config/SSSDConfig/sssdoptions.py:536 msgid "Sudo rule user attribute" msgstr "Atributo de la regla usuario de sudo" -#: src/config/SSSDConfig/sssdoptions.py:531 +#: src/config/SSSDConfig/sssdoptions.py:537 msgid "Sudo rule option attribute" msgstr "Atributo de la regla opción de sudo" -#: src/config/SSSDConfig/sssdoptions.py:532 +#: src/config/SSSDConfig/sssdoptions.py:538 msgid "Sudo rule runas attribute" msgstr "Atributo runas de regla sudo" -#: src/config/SSSDConfig/sssdoptions.py:533 +#: src/config/SSSDConfig/sssdoptions.py:539 msgid "Sudo rule runasuser attribute" msgstr "Atributo de la regla suda runasuser" -#: src/config/SSSDConfig/sssdoptions.py:534 +#: src/config/SSSDConfig/sssdoptions.py:540 msgid "Sudo rule runasgroup attribute" msgstr "Atributo de regla runasgroup de sudo" -#: src/config/SSSDConfig/sssdoptions.py:535 +#: src/config/SSSDConfig/sssdoptions.py:541 msgid "Sudo rule notbefore attribute" msgstr "Atributo de regla notbefore de sudo" -#: src/config/SSSDConfig/sssdoptions.py:536 +#: src/config/SSSDConfig/sssdoptions.py:542 msgid "Sudo rule notafter attribute" msgstr "Atributo de regla noafter de sudo" -#: src/config/SSSDConfig/sssdoptions.py:537 +#: src/config/SSSDConfig/sssdoptions.py:543 msgid "Sudo rule order attribute" msgstr "Atributo de regla orden de sudo" -#: src/config/SSSDConfig/sssdoptions.py:540 +#: src/config/SSSDConfig/sssdoptions.py:546 msgid "Object class for automounter maps" msgstr "Objeto clase para mapas automontador" -#: src/config/SSSDConfig/sssdoptions.py:541 +#: src/config/SSSDConfig/sssdoptions.py:547 msgid "Automounter map name attribute" msgstr "Atributo de nombre de mapa de automontador" -#: src/config/SSSDConfig/sssdoptions.py:542 +#: src/config/SSSDConfig/sssdoptions.py:548 msgid "Object class for automounter map entries" msgstr "Objeto clase para entradas de mapa de automontador" -#: src/config/SSSDConfig/sssdoptions.py:543 +#: src/config/SSSDConfig/sssdoptions.py:549 msgid "Automounter map entry key attribute" msgstr "Atributo de clave de entrada para mapa de automontador" -#: src/config/SSSDConfig/sssdoptions.py:544 +#: src/config/SSSDConfig/sssdoptions.py:550 msgid "Automounter map entry value attribute" msgstr "Atributo de valor de entrada para mapa de automontador" -#: src/config/SSSDConfig/sssdoptions.py:545 +#: src/config/SSSDConfig/sssdoptions.py:551 msgid "Base DN for automounter map lookups" msgstr "Base DN para búsquedas de mapa de automontador" -#: src/config/SSSDConfig/sssdoptions.py:546 +#: src/config/SSSDConfig/sssdoptions.py:552 msgid "The name of the automount master map in LDAP." msgstr "El nombre del mapa maestro de montaje automático en LDAP." -#: src/config/SSSDConfig/sssdoptions.py:549 +#: src/config/SSSDConfig/sssdoptions.py:555 msgid "Base DN for IP hosts lookups" msgstr "DN base para búsquedas de IP de hosts" -#: src/config/SSSDConfig/sssdoptions.py:550 +#: src/config/SSSDConfig/sssdoptions.py:556 msgid "Object class for IP hosts" msgstr "Objeto clase para IP de hosts" -#: src/config/SSSDConfig/sssdoptions.py:551 +#: src/config/SSSDConfig/sssdoptions.py:557 msgid "IP host name attribute" msgstr "Atributo nombre de host IP" -#: src/config/SSSDConfig/sssdoptions.py:552 +#: src/config/SSSDConfig/sssdoptions.py:558 msgid "IP host number (address) attribute" msgstr "Atributo número (dirección) de host IP" -#: src/config/SSSDConfig/sssdoptions.py:553 +#: src/config/SSSDConfig/sssdoptions.py:559 msgid "IP host entryUSN attribute" msgstr "Atributo entryUSN de host IP" -#: src/config/SSSDConfig/sssdoptions.py:554 +#: src/config/SSSDConfig/sssdoptions.py:560 msgid "Base DN for IP networks lookups" msgstr "DN base para búsquedas de redes IP" -#: src/config/SSSDConfig/sssdoptions.py:555 +#: src/config/SSSDConfig/sssdoptions.py:561 msgid "Object class for IP networks" msgstr "Objeto clase para redes IP" -#: src/config/SSSDConfig/sssdoptions.py:556 +#: src/config/SSSDConfig/sssdoptions.py:562 msgid "IP network name attribute" msgstr "Atributo nombre de red IP" -#: src/config/SSSDConfig/sssdoptions.py:557 +#: src/config/SSSDConfig/sssdoptions.py:563 msgid "IP network number (address) attribute" msgstr "Atributo número (dirección) de red IP" -#: src/config/SSSDConfig/sssdoptions.py:558 +#: src/config/SSSDConfig/sssdoptions.py:564 msgid "IP network entryUSN attribute" msgstr "Atributo entryUSN de red IP" -#: src/config/SSSDConfig/sssdoptions.py:561 +#: src/config/SSSDConfig/sssdoptions.py:567 msgid "Comma separated list of allowed users" msgstr "Lista separada por comas de usuarios autorizados" -#: src/config/SSSDConfig/sssdoptions.py:562 +#: src/config/SSSDConfig/sssdoptions.py:568 msgid "Comma separated list of prohibited users" msgstr "Lista separada por comas de usuarios prohibidos" -#: src/config/SSSDConfig/sssdoptions.py:563 +#: src/config/SSSDConfig/sssdoptions.py:569 msgid "" "Comma separated list of groups that are allowed to log in. This applies only " "to groups within this SSSD domain. Local groups are not evaluated." @@ -2045,7 +2092,7 @@ msgstr "" "aplica sólo a los grupos dentro del dominio SSSD. Los grupos locales no " "serán evaluados." -#: src/config/SSSDConfig/sssdoptions.py:565 +#: src/config/SSSDConfig/sssdoptions.py:571 msgid "" "Comma separated list of groups that are explicitly denied access. This " "applies only to groups within this SSSD domain. Local groups are not " @@ -2055,32 +2102,32 @@ msgstr "" "el acceso. Esto se aplica sólo a los grupos dentro del dominio SSSD. Los " "grupos locales no serán evaluados." -#: src/config/SSSDConfig/sssdoptions.py:569 +#: src/config/SSSDConfig/sssdoptions.py:575 msgid "The number of preforked proxy children." msgstr "El número de herederos proxy pre-bifurcados." -#: src/config/SSSDConfig/sssdoptions.py:572 +#: src/config/SSSDConfig/sssdoptions.py:578 msgid "The name of the NSS library to use" msgstr "El nombre de la biblioteca NSS a usar" -#: src/config/SSSDConfig/sssdoptions.py:573 +#: src/config/SSSDConfig/sssdoptions.py:579 msgid "The name of the NSS library to use for hosts and networks lookups" msgstr "" "El nombre de la biblioteca NSS a usar para búsquedas de hospedajes y redes" -#: src/config/SSSDConfig/sssdoptions.py:574 +#: src/config/SSSDConfig/sssdoptions.py:580 msgid "Whether to look up canonical group name from cache if possible" msgstr "Si buscar el nombre canónico del grupo desde el caché si es posible" -#: src/config/SSSDConfig/sssdoptions.py:577 +#: src/config/SSSDConfig/sssdoptions.py:583 msgid "PAM stack to use" msgstr "Pila PAM a usar" -#: src/config/SSSDConfig/sssdoptions.py:580 +#: src/config/SSSDConfig/sssdoptions.py:586 msgid "Path of passwd file sources." msgstr "Ruta de las fuentes del archivo passwd." -#: src/config/SSSDConfig/sssdoptions.py:581 +#: src/config/SSSDConfig/sssdoptions.py:587 msgid "Path of group file sources." msgstr "Ruta de las fuentes del archivo group." @@ -2111,109 +2158,113 @@ msgstr "" msgid "Option -i|--interactive is not allowed together with -D|--daemon\n" msgstr "La opción -i|--interactive no está permitida junto con -D|--daemon\n" -#: src/monitor/monitor.c:1836 +#: src/monitor/monitor.c:1838 msgid "Failed to get initial capabilities\n" msgstr "Ha fallado al obtener capacidades iniciales\n" -#: src/monitor/monitor.c:1847 +#: src/monitor/monitor.c:1849 msgid "Non-root service user support isn't built. Can't run under %" msgstr "" "Usuario de servicio distinto de root admite no estar compilado. No puede " "ejecutar bajo %" -#: src/monitor/monitor.c:1864 +#: src/monitor/monitor.c:1866 #, c-format msgid "Can't read config: '%s'\n" msgstr "No puede leer config: '%s'\n" -#: src/monitor/monitor.c:1876 -#, c-format -msgid "Failed to boostrap SSSD 'monitor' process: %s" +#: src/monitor/monitor.c:1878 +#, fuzzy, c-format +msgid "Failed to bootstrap SSSD 'monitor' process: %s" msgstr "Ha fallado el proceso 'monitor' de arranque SSSD: %s" -#: src/monitor/monitor.c:1971 +#: src/monitor/monitor.c:1973 msgid "Out of memory\n" msgstr "Falta memoria\n" -#: src/providers/krb5/krb5_child.c:4221 +#: src/providers/krb5/krb5_child.c:4316 msgid "Use anonymous PKINIT to request FAST armor ticket" msgstr "Usar PKINIT anónimo para peticiones de boleto de armada FAST" -#: src/providers/krb5/krb5_child.c:4223 +#: src/providers/krb5/krb5_child.c:4318 msgid "Kerberos realm to use" msgstr "Reino Kerberos a usar" -#: src/providers/krb5/krb5_child.c:4225 +#: src/providers/krb5/krb5_child.c:4320 msgid "Requested lifetime of the ticket" msgstr "Tiempo de vida pedido del ticket" -#: src/providers/krb5/krb5_child.c:4227 +#: src/providers/krb5/krb5_child.c:4322 msgid "Requested renewable lifetime of the ticket" msgstr "Teimpo de vida renovable pedido del ticket" -#: src/providers/krb5/krb5_child.c:4229 +#: src/providers/krb5/krb5_child.c:4324 msgid "FAST options ('never', 'try', 'demand')" msgstr "Opciones FAST ('never', 'try', 'demand')" -#: src/providers/krb5/krb5_child.c:4232 +#: src/providers/krb5/krb5_child.c:4327 msgid "Specifies the server principal to use for FAST" msgstr "Especifica el servidor principal a usar por FAST" -#: src/providers/krb5/krb5_child.c:4234 +#: src/providers/krb5/krb5_child.c:4329 msgid "Requests canonicalization of the principal name" msgstr "Solicita la canonización del nombre principal" -#: src/providers/krb5/krb5_child.c:4236 +#: src/providers/krb5/krb5_child.c:4331 msgid "Use custom version of krb5_get_init_creds_password" msgstr "Usar versión personal de krb5_get_init_creds_password" -#: src/providers/krb5/krb5_child.c:4238 +#: src/providers/krb5/krb5_child.c:4333 msgid "Check PAC flags" msgstr "Compruebe indicadores de PAC" -#: src/providers/data_provider_be.c:790 +#: src/providers/krb5/krb5_child.c:4335 +msgid "Set environment variable (KEY=VALUE)" +msgstr "" + +#: src/providers/data_provider_be.c:786 msgid "Domain of the information provider (mandatory)" msgstr "Dominio del proveedor de información (obligatorio)" -#: src/sss_client/common.c:1165 +#: src/sss_client/common.c:1208 msgid "Socket has wrong ownership or permissions." msgstr "El zócalo tiene propiedad o permisos incorrectos." -#: src/sss_client/common.c:1168 +#: src/sss_client/common.c:1211 msgid "Unexpected format of the server credential message." msgstr "Formato no esperado del mensaje de la credencial del servidor." -#: src/sss_client/common.c:1171 +#: src/sss_client/common.c:1214 msgid "SSSD is not run by trusted user." msgstr "SSSD no está siendo ejecutado por el usuario confiado." -#: src/sss_client/common.c:1174 +#: src/sss_client/common.c:1217 msgid "SSSD socket does not exist." msgstr "El socket SSSD no existe." -#: src/sss_client/common.c:1177 +#: src/sss_client/common.c:1220 msgid "Cannot get stat of SSSD socket." msgstr "No se pueden obtener estadísticas del socket SSSD." -#: src/sss_client/common.c:1182 +#: src/sss_client/common.c:1225 msgid "An error occurred, but no description can be found." msgstr "Ha ocurrido un error, pero no se ha podido encontrar una descripción." -#: src/sss_client/common.c:1188 +#: src/sss_client/common.c:1231 msgid "Unexpected error while looking for an error description" msgstr "" "Ha ocurrido un error no esperado mientras se buscaba la descripción del error" -#: src/sss_client/pam_sss.c:74 +#: src/sss_client/pam_sss.c:135 msgid "Permission denied. " msgstr "Permiso denegado. " -#: src/sss_client/pam_sss.c:75 src/sss_client/pam_sss.c:843 -#: src/sss_client/pam_sss.c:854 +#: src/sss_client/pam_sss.c:136 src/sss_client/pam_sss.c:921 +#: src/sss_client/pam_sss.c:932 msgid "Server message: " msgstr "Mensaje del servidor: " -#: src/sss_client/pam_sss.c:76 +#: src/sss_client/pam_sss.c:137 msgid "" "Kerberos TGT will not be granted upon login, user experience will be " "affected." @@ -2221,50 +2272,50 @@ msgstr "" "TGT Kerberos no será otorgado hasta acceder, la experiencia de usuario será " "afectada." -#: src/sss_client/pam_sss.c:77 +#: src/sss_client/pam_sss.c:138 msgid "Enter PIN:" msgstr "Introduzca el PIN:" -#: src/sss_client/pam_sss.c:320 +#: src/sss_client/pam_sss.c:385 msgid "Passwords do not match" msgstr "Las contraseñas no coinciden" -#: src/sss_client/pam_sss.c:508 +#: src/sss_client/pam_sss.c:584 msgid "Password reset by root is not supported." msgstr "No existe soporte para restaurar la contraseña por el usuario root." -#: src/sss_client/pam_sss.c:549 +#: src/sss_client/pam_sss.c:625 msgid "Authenticated with cached credentials" msgstr "Autenticado mediante credenciales cacheada" -#: src/sss_client/pam_sss.c:550 +#: src/sss_client/pam_sss.c:626 msgid ", your cached password will expire at: " msgstr ", su contraseña cacheada vencerá el: " -#: src/sss_client/pam_sss.c:580 +#: src/sss_client/pam_sss.c:656 #, c-format msgid "Your password has expired. You have %1$d grace login(s) remaining." msgstr "Su contraseña ha expirado. Usted tiene %1$d accesos restantes." -#: src/sss_client/pam_sss.c:630 +#: src/sss_client/pam_sss.c:706 #, c-format msgid "Your password will expire in %1$d %2$s." msgstr "Su contraseña caducará en %1$d %2$s." -#: src/sss_client/pam_sss.c:633 +#: src/sss_client/pam_sss.c:709 #, c-format msgid "Your password has expired." msgstr "Su contraseña ha caducado." -#: src/sss_client/pam_sss.c:684 +#: src/sss_client/pam_sss.c:760 msgid "Authentication is denied until: " msgstr "La autenticación ha sido denegada hasta: " -#: src/sss_client/pam_sss.c:705 +#: src/sss_client/pam_sss.c:781 msgid "System is offline, password change not possible" msgstr "El sistema está fuera de línea, no se puede cambiar la contraseña" -#: src/sss_client/pam_sss.c:720 +#: src/sss_client/pam_sss.c:796 msgid "" "After changing the OTP password, you need to log out and back in order to " "acquire a ticket" @@ -2272,11 +2323,11 @@ msgstr "" "Después de cambiar la contraseña OTP, usted debe salir y volver a entrar con " "el objetivo de fijarla" -#: src/sss_client/pam_sss.c:735 +#: src/sss_client/pam_sss.c:813 msgid "PIN locked" msgstr "PIN bloqueado" -#: src/sss_client/pam_sss.c:750 +#: src/sss_client/pam_sss.c:828 msgid "" "No Kerberos TGT granted as the server does not support this method. Your " "single-sign on(SSO) experience will be affected." @@ -2284,61 +2335,65 @@ msgstr "" "No concedió Kerberos TGT como el servidor no admite este método. Su única " "firma en experiencia (SSO) será afectada." -#: src/sss_client/pam_sss.c:840 src/sss_client/pam_sss.c:853 +#: src/sss_client/pam_sss.c:918 src/sss_client/pam_sss.c:931 msgid "Password change failed. " msgstr "Falló el cambio de contraseña. " -#: src/sss_client/pam_sss.c:1859 -#, c-format -msgid "Authenticate at %1$s and press ENTER." +#: src/sss_client/pam_sss.c:2028 +#, fuzzy, c-format +msgid "Authenticate at \"%1$s\"." msgstr "Autenticar en %1$s y presione ENTRAR." -#: src/sss_client/pam_sss.c:1862 -#, c-format -msgid "Authenticate with PIN %1$s at %2$s and press ENTER." +#: src/sss_client/pam_sss.c:2031 +#, fuzzy, c-format +msgid "Authenticate with PIN \"%1$s\" at \"%2$s\"." msgstr "Autenticar con %1$s en %2$s y presione INTRO." -#: src/sss_client/pam_sss.c:2281 +#: src/sss_client/pam_sss.c:2470 msgid "Please (re)insert (different) Smartcard" msgstr "(Re)introduzca Smartcard (diferente)" -#: src/sss_client/pam_sss.c:2482 +#: src/sss_client/pam_sss.c:2700 msgid "New Password: " msgstr "Nueva contraseña: " -#: src/sss_client/pam_sss.c:2483 +#: src/sss_client/pam_sss.c:2701 msgid "Reenter new Password: " msgstr "Reingrese la contraseña nueva: " -#: src/sss_client/pam_sss.c:2676 src/sss_client/pam_sss.c:2679 +#: src/sss_client/pam_sss.c:2890 +msgid "Press ENTER to continue." +msgstr "" + +#: src/sss_client/pam_sss.c:2913 src/sss_client/pam_sss.c:2916 msgid "First Factor: " msgstr "Primer factor: " -#: src/sss_client/pam_sss.c:2677 src/sss_client/pam_sss.c:2851 +#: src/sss_client/pam_sss.c:2914 src/sss_client/pam_sss.c:3088 msgid "Second Factor (optional): " msgstr "Segundo Factor (opcional): " -#: src/sss_client/pam_sss.c:2680 src/sss_client/pam_sss.c:2855 +#: src/sss_client/pam_sss.c:2917 src/sss_client/pam_sss.c:3092 msgid "Second Factor: " msgstr "Segundo factor: " -#: src/sss_client/pam_sss.c:2684 +#: src/sss_client/pam_sss.c:2921 msgid "Insert your passkey device, then press ENTER." msgstr "Introduzca su dispositivo de llave de paso, después pulse INTRO." -#: src/sss_client/pam_sss.c:2688 src/sss_client/pam_sss.c:2696 +#: src/sss_client/pam_sss.c:2925 src/sss_client/pam_sss.c:2933 msgid "Password: " msgstr "Contraseña: " -#: src/sss_client/pam_sss.c:2850 src/sss_client/pam_sss.c:2854 +#: src/sss_client/pam_sss.c:3087 src/sss_client/pam_sss.c:3091 msgid "First Factor (Current Password): " msgstr "Primer Factor (Contraseña Actual): " -#: src/sss_client/pam_sss.c:2874 +#: src/sss_client/pam_sss.c:3111 msgid "Current Password: " msgstr "Contraseña actual: " -#: src/sss_client/pam_sss.c:3248 +#: src/sss_client/pam_sss.c:3485 msgid "Password expired. Change your password now." msgstr "La contraseña ha expirado. Modifíquela en este preciso momento." @@ -2387,7 +2442,8 @@ msgstr "" #: src/tools/sss_cache.c:229 msgid "No cache object matched the specified search\n" -msgstr "No hay objetos en el cache que coincidan con la búsqueda especificada\n" +msgstr "" +"No hay objetos en el cache que coincidan con la búsqueda especificada\n" #: src/tools/sss_cache.c:520 #, c-format @@ -2784,9 +2840,9 @@ msgstr "Ha fallado al declarar objeto: %s\n" #: src/tools/sssctl/sssctl_cache.c:835 src/tools/sssctl/sssctl_cache.c:918 #: src/tools/sssctl/sssctl_cache.c:950 src/tools/sssctl/sssctl_cache.c:956 #: src/tools/sssctl/sssctl_cache.c:1010 src/tools/sssctl/sssctl_cache.c:1034 -#: src/tools/sssctl/sssctl_cache.c:1085 src/tools/sssctl/sssctl_cache.c:1194 -#: src/tools/sssctl/sssctl_cache.c:1229 src/tools/sssctl/sssctl_cache.c:1235 -#: src/tools/sssctl/sssctl_cache.c:1244 +#: src/tools/sssctl/sssctl_cache.c:1085 src/tools/sssctl/sssctl_cache.c:1195 +#: src/tools/sssctl/sssctl_cache.c:1230 src/tools/sssctl/sssctl_cache.c:1236 +#: src/tools/sssctl/sssctl_cache.c:1245 msgid "talloc failed\n" msgstr "talloc incorrecto.\n" @@ -2855,32 +2911,33 @@ msgstr "No pudo determinar la ruta real para [%s]: %s\n" #: src/tools/sssctl/sssctl_cache.c:1073 #, c-format msgid "The cached GPO path [%s] is not under [%s], ignoring.\n" -msgstr "La ruta GPO cacheada [%s] no está debajo de [%s], se hace caso omiso.\n" +msgstr "" +"La ruta GPO cacheada [%s] no está debajo de [%s], se hace caso omiso.\n" #: src/tools/sssctl/sssctl_cache.c:1098 #, c-format msgid "Unable to remove downloaded GPO files: %s\n" msgstr "Incapaz de eliminar los archivos de registro: %s\n" -#: src/tools/sssctl/sssctl_cache.c:1165 +#: src/tools/sssctl/sssctl_cache.c:1166 #, c-format msgid "Failed to fetch cache entry: %s\n" msgstr "Falló al obtener apunte caché: %s\n" -#: src/tools/sssctl/sssctl_cache.c:1170 +#: src/tools/sssctl/sssctl_cache.c:1171 msgid "Could not determine object domain\n" msgstr "No pudo determinar dominio de objeto\n" -#: src/tools/sssctl/sssctl_cache.c:1200 +#: src/tools/sssctl/sssctl_cache.c:1201 msgid "Could not find GUID attribute in GPO entry\n" msgstr "No pudo encontrar atributo GUID en apunte GPO\n" -#: src/tools/sssctl/sssctl_cache.c:1206 +#: src/tools/sssctl/sssctl_cache.c:1207 #, c-format msgid "Failed to delete GPO: %s\n" msgstr "Falló al borrar GPO: %s\n" -#: src/tools/sssctl/sssctl_cache.c:1210 +#: src/tools/sssctl/sssctl_cache.c:1211 #, c-format msgid "%s removed from cache\n" msgstr "%s retirado desde caché\n" @@ -2929,8 +2986,8 @@ msgstr "Incorrecto al configurar contexto certmap.\n" #, c-format msgid "Failed to add mapping and matching rules with error [%d][%s].\n" msgstr "" -"Incorrecto al añadir reglas de asignación y coincidencia con error " -"[%d][%s].\n" +"Incorrecto al añadir reglas de asignación y coincidencia con error [%d]" +"[%s].\n" #: src/tools/sssctl/sssctl_cert.c:251 msgid "Failed to decode base64 string.\n" @@ -2978,39 +3035,40 @@ msgstr "" "configuración principal. Por ejemplo si la configuración está establecida a " "\"/my/path/sssd.conf\", se usa el directorio retazo \"/my/path/conf.d\")" -#: src/tools/sssctl/sssctl_config.c:114 +#: src/tools/sssctl/sssctl_config.c:126 #, c-format msgid "File %1$s does not exist.\n" msgstr "El archivo %1$s no existe.\n" -#: src/tools/sssctl/sssctl_config.c:115 +#: src/tools/sssctl/sssctl_config.c:127 msgid "There is no configuration.\n" msgstr "No hay ninguna configuración.\n" -#: src/tools/sssctl/sssctl_config.c:120 +#: src/tools/sssctl/sssctl_config.c:132 #, c-format msgid "Configuration validation failed: %s\n" msgstr "Validación de configuración incorrecta: %s\n" -#: src/tools/sssctl/sssctl_config.c:121 +#: src/tools/sssctl/sssctl_config.c:133 msgid "Run with high debug level to see details.\n" msgstr "Ejecute con nivel depurador alto para ver detalles.\n" -#: src/tools/sssctl/sssctl_config.c:130 -msgid "Failed to run validators" +#: src/tools/sssctl/sssctl_config.c:142 +#, fuzzy +msgid "Failed to run validators\n" msgstr "Falló al ejecutar los validadores" -#: src/tools/sssctl/sssctl_config.c:134 +#: src/tools/sssctl/sssctl_config.c:146 #, c-format msgid "Issues identified by validators: %zu\n" msgstr "Cuestiones identificadas por los validadores: %zu\n" -#: src/tools/sssctl/sssctl_config.c:145 +#: src/tools/sssctl/sssctl_config.c:157 #, c-format msgid "Messages generated during configuration merging: %zu\n" msgstr "Mensajes generados durante la configuración de la fusión: %zu\n" -#: src/tools/sssctl/sssctl_config.c:158 +#: src/tools/sssctl/sssctl_config.c:170 #, c-format msgid "Used configuration snippet files: %zu\n" msgstr "Configuración usada ficheros retazos: %zu\n" diff --git a/po/eu.po b/po/eu.po index 02205f90110..c484e650aa7 100644 --- a/po/eu.po +++ b/po/eu.po @@ -8,8 +8,8 @@ msgid "" msgstr "" "Project-Id-Version: PACKAGE VERSION\n" "Report-Msgid-Bugs-To: sssd-devel@lists.fedorahosted.org\n" -"POT-Creation-Date: 2026-01-14 14:57+0000\n" -"PO-Revision-Date: 2026-04-23 17:02+0000\n" +"POT-Creation-Date: 2026-10-02 15:57+0000\n" +"PO-Revision-Date: 2026-10-05 16:38+0000\n" "Last-Translator: Anonymous \n" "Language-Team: Basque \n" @@ -18,50 +18,50 @@ msgstr "" "Content-Type: text/plain; charset=UTF-8\n" "Content-Transfer-Encoding: 8bit\n" "Plural-Forms: nplurals=2; plural=n != 1;\n" -"X-Generator: Weblate 5.17\n" +"X-Generator: Weblate 2026.10\n" -#: src/config/SSSDConfig/sssdoptions.py:20 -#: src/config/SSSDConfig/sssdoptions.py:21 +#: src/config/SSSDConfig/sssdoptions.py:16 +#: src/config/SSSDConfig/sssdoptions.py:17 msgid "Set the verbosity of the debug logging" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:22 +#: src/config/SSSDConfig/sssdoptions.py:18 msgid "Include timestamps in debug logs" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:23 +#: src/config/SSSDConfig/sssdoptions.py:19 msgid "Include microseconds in timestamps in debug logs" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:24 +#: src/config/SSSDConfig/sssdoptions.py:20 msgid "Enable/disable debug backtrace" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:25 +#: src/config/SSSDConfig/sssdoptions.py:21 msgid "Watchdog timeout before restarting service" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:26 +#: src/config/SSSDConfig/sssdoptions.py:22 msgid "Command to start service" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:27 +#: src/config/SSSDConfig/sssdoptions.py:23 msgid "The number of file descriptors that may be opened by this responder" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:28 +#: src/config/SSSDConfig/sssdoptions.py:24 msgid "Idle time before automatic disconnection of a client" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:29 +#: src/config/SSSDConfig/sssdoptions.py:25 msgid "Idle time before automatic shutdown of the responder" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:30 +#: src/config/SSSDConfig/sssdoptions.py:26 msgid "Always query all the caches before querying the Data Providers" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:31 +#: src/config/SSSDConfig/sssdoptions.py:27 msgid "" "When SSSD switches to offline mode the amount of time before it tries to go " "back online will increase based upon the time spent disconnected. This value " @@ -69,63 +69,63 @@ msgid "" "random_offset." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:36 +#: src/config/SSSDConfig/sssdoptions.py:32 msgid "SSSD Services to start" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:37 +#: src/config/SSSDConfig/sssdoptions.py:33 msgid "SSSD Domains to start" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:38 +#: src/config/SSSDConfig/sssdoptions.py:34 msgid "Regex to parse username and domain" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:39 +#: src/config/SSSDConfig/sssdoptions.py:35 msgid "Printf-compatible format for displaying fully-qualified names" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:40 +#: src/config/SSSDConfig/sssdoptions.py:36 msgid "" "Directory on the filesystem where SSSD should store Kerberos replay cache " "files." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:41 +#: src/config/SSSDConfig/sssdoptions.py:37 msgid "Domain to add to names without a domain component." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:42 +#: src/config/SSSDConfig/sssdoptions.py:38 msgid "The user to drop privileges to" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:43 +#: src/config/SSSDConfig/sssdoptions.py:39 msgid "Tune certificate verification" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:44 +#: src/config/SSSDConfig/sssdoptions.py:40 msgid "All spaces in group or user names will be replaced with this character" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:45 +#: src/config/SSSDConfig/sssdoptions.py:41 msgid "Tune sssd to honor or ignore netlink state changes" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:46 +#: src/config/SSSDConfig/sssdoptions.py:42 msgid "Enable or disable the implicit files domain" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:47 +#: src/config/SSSDConfig/sssdoptions.py:43 msgid "A specific order of the domains to be looked up" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:48 +#: src/config/SSSDConfig/sssdoptions.py:44 msgid "" "Controls if SSSD should monitor the state of resolv.conf to identify when it " "needs to update its internal DNS resolver." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:50 +#: src/config/SSSDConfig/sssdoptions.py:46 msgid "" "SSSD monitors the state of resolv.conf to identify when it needs to update " "its internal DNS resolver. By default, we will attempt to use inotify for " @@ -133,393 +133,400 @@ msgid "" "inotify cannot be used." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:53 +#: src/config/SSSDConfig/sssdoptions.py:49 msgid "Run PAC responder automatically for AD and IPA provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:54 +#: src/config/SSSDConfig/sssdoptions.py:50 msgid "Enable or disable core dumps for all SSSD processes." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:55 +#: src/config/SSSDConfig/sssdoptions.py:51 msgid "Tune passkey verification behavior" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:58 +#: src/config/SSSDConfig/sssdoptions.py:54 msgid "Enumeration cache timeout length (seconds)" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:59 +#: src/config/SSSDConfig/sssdoptions.py:55 msgid "Entry cache background update timeout length (seconds)" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:60 -#: src/config/SSSDConfig/sssdoptions.py:125 +#: src/config/SSSDConfig/sssdoptions.py:56 +#: src/config/SSSDConfig/sssdoptions.py:124 msgid "Negative cache timeout length (seconds)" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:61 +#: src/config/SSSDConfig/sssdoptions.py:57 msgid "Users that SSSD should explicitly ignore" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:62 +#: src/config/SSSDConfig/sssdoptions.py:58 msgid "Groups that SSSD should explicitly ignore" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:63 +#: src/config/SSSDConfig/sssdoptions.py:59 msgid "Should filtered users appear in groups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:64 +#: src/config/SSSDConfig/sssdoptions.py:60 msgid "The value of the password field the NSS provider should return" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:65 +#: src/config/SSSDConfig/sssdoptions.py:61 msgid "Override homedir value from the identity provider with this value" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:66 +#: src/config/SSSDConfig/sssdoptions.py:62 msgid "" "Substitute empty homedir value from the identity provider with this value" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:67 +#: src/config/SSSDConfig/sssdoptions.py:63 msgid "Override shell value from the identity provider with this value" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:68 +#: src/config/SSSDConfig/sssdoptions.py:64 msgid "The list of shells users are allowed to log in with" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:69 +#: src/config/SSSDConfig/sssdoptions.py:65 msgid "" "The list of shells that will be vetoed, and replaced with the fallback shell" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:70 +#: src/config/SSSDConfig/sssdoptions.py:66 msgid "" "If a shell stored in central directory is allowed but not available, use " "this fallback" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:71 +#: src/config/SSSDConfig/sssdoptions.py:67 msgid "Shell to use if the provider does not list one" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:72 +#: src/config/SSSDConfig/sssdoptions.py:68 msgid "How long will be in-memory cache records valid" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:74 +#: src/config/SSSDConfig/sssdoptions.py:70 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for passwd requests" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:76 +#: src/config/SSSDConfig/sssdoptions.py:72 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for group requests" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:78 +#: src/config/SSSDConfig/sssdoptions.py:74 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for initgroups requests" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:79 +#: src/config/SSSDConfig/sssdoptions.py:75 msgid "" "The value of this option will be used in the expansion of the " "override_homedir option if the template contains the format string %H." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:81 +#: src/config/SSSDConfig/sssdoptions.py:77 msgid "" "Specifies time in seconds for which the list of subdomains will be " "considered valid." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:83 +#: src/config/SSSDConfig/sssdoptions.py:79 msgid "" "The entry cache can be set to automatically update entries in the background " "if they are requested beyond a percentage of the entry_cache_timeout value " "for the domain." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:88 +#: src/config/SSSDConfig/sssdoptions.py:84 msgid "How long to allow cached logins between online logins (days)" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:89 +#: src/config/SSSDConfig/sssdoptions.py:85 msgid "How many failed logins attempts are allowed when offline" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:91 +#: src/config/SSSDConfig/sssdoptions.py:87 msgid "" "How long (minutes) to deny login after offline_failed_login_attempts has " "been reached" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:92 +#: src/config/SSSDConfig/sssdoptions.py:88 msgid "What kind of messages are displayed to the user during authentication" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:93 +#: src/config/SSSDConfig/sssdoptions.py:89 msgid "Filter PAM responses sent to the pam_sss" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:94 +#: src/config/SSSDConfig/sssdoptions.py:90 msgid "How many seconds to keep identity information cached for PAM requests" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:95 +#: src/config/SSSDConfig/sssdoptions.py:91 msgid "How many days before password expiration a warning should be displayed" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:96 +#: src/config/SSSDConfig/sssdoptions.py:92 msgid "List of trusted uids or user's name" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:97 +#: src/config/SSSDConfig/sssdoptions.py:93 msgid "List of domains accessible even for untrusted users." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:98 +#: src/config/SSSDConfig/sssdoptions.py:94 msgid "Message printed when user account is expired." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:99 +#: src/config/SSSDConfig/sssdoptions.py:95 msgid "Message printed when user account is locked." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:100 +#: src/config/SSSDConfig/sssdoptions.py:96 msgid "Allow certificate based/Smartcard authentication." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:101 +#: src/config/SSSDConfig/sssdoptions.py:97 msgid "Path to certificate database with PKCS#11 modules." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:102 +#: src/config/SSSDConfig/sssdoptions.py:98 msgid "Tune certificate verification for PAM authentication." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:103 +#: src/config/SSSDConfig/sssdoptions.py:99 msgid "How many seconds will pam_sss wait for p11_child to finish" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:104 +#: src/config/SSSDConfig/sssdoptions.py:100 msgid "Which PAM services are permitted to contact application domains" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:105 +#: src/config/SSSDConfig/sssdoptions.py:101 msgid "Allowed services for using smartcards" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:106 +#: src/config/SSSDConfig/sssdoptions.py:102 msgid "Additional timeout to wait for a card if requested" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:107 +#: src/config/SSSDConfig/sssdoptions.py:103 msgid "" "PKCS#11 URI to restrict the selection of devices for Smartcard authentication" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:108 +#: src/config/SSSDConfig/sssdoptions.py:104 msgid "When shall the PAM responder force an initgroups request" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:109 +#: src/config/SSSDConfig/sssdoptions.py:105 msgid "List of PAM services that are allowed to authenticate with GSSAPI." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:110 +#: src/config/SSSDConfig/sssdoptions.py:106 msgid "Whether to match authenticated UPN with target user" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:111 +#: src/config/SSSDConfig/sssdoptions.py:107 msgid "" "List of pairs : that must be enforced " "for PAM access with GSSAPI authentication" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:113 +#: src/config/SSSDConfig/sssdoptions.py:109 +msgid "" +"List of triples :: that assigns " +"additional information from the Kerberos ticket to an authentication " +"indicator." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:112 msgid "Allow passkey device authentication." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:114 +#: src/config/SSSDConfig/sssdoptions.py:113 msgid "How many seconds will pam_sss wait for passkey_child to finish" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:115 +#: src/config/SSSDConfig/sssdoptions.py:114 msgid "Enable debugging in the libfido2 library" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:116 +#: src/config/SSSDConfig/sssdoptions.py:115 msgid "Enable JSON protocol for authentication methods selection." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:119 +#: src/config/SSSDConfig/sssdoptions.py:118 msgid "Whether to evaluate the time-based attributes in sudo rules" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:120 +#: src/config/SSSDConfig/sssdoptions.py:119 msgid "If true, SSSD will switch back to lower-wins ordering logic" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:121 +#: src/config/SSSDConfig/sssdoptions.py:120 msgid "" "Maximum number of rules that can be refreshed at once. If this is exceeded, " "full refresh is performed." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:128 +#: src/config/SSSDConfig/sssdoptions.py:127 msgid "Whether to hash host names and addresses in the known_hosts file" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:129 +#: src/config/SSSDConfig/sssdoptions.py:128 msgid "" "How many seconds to keep a host in the known_hosts file after its host keys " "were requested" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:131 +#: src/config/SSSDConfig/sssdoptions.py:130 msgid "Path to storage of trusted CA certificates" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:132 +#: src/config/SSSDConfig/sssdoptions.py:131 msgid "Allow to generate ssh-keys from certificates" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:133 +#: src/config/SSSDConfig/sssdoptions.py:132 msgid "" "Use the following matching rules to filter the certificates for ssh-key " "generation" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:137 +#: src/config/SSSDConfig/sssdoptions.py:136 msgid "List of UIDs or user names allowed to access the PAC responder" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:138 +#: src/config/SSSDConfig/sssdoptions.py:137 msgid "How long the PAC data is considered valid" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:139 +#: src/config/SSSDConfig/sssdoptions.py:138 msgid "Validate the PAC" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:142 +#: src/config/SSSDConfig/sssdoptions.py:141 msgid "List of user attributes the InfoPipe is allowed to publish" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:145 +#: src/config/SSSDConfig/sssdoptions.py:144 msgid "" "One of the following strings specifying the scope of session recording: none " "- No users are recorded. some - Users/groups specified by users and groups " "options are recorded. all - All users are recorded." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:148 +#: src/config/SSSDConfig/sssdoptions.py:147 msgid "" "A comma-separated list of users which should have session recording enabled. " "Matches user names as returned by NSS. I.e. after the possible space " "replacement, case changes, etc." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:150 +#: src/config/SSSDConfig/sssdoptions.py:149 msgid "" "A comma-separated list of groups, members of which should have session " "recording enabled. Matches group names as returned by NSS. I.e. after the " "possible space replacement, case changes, etc." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:153 +#: src/config/SSSDConfig/sssdoptions.py:152 msgid "" "A comma-separated list of users to be excluded from recording, only when " "scope=all" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:154 +#: src/config/SSSDConfig/sssdoptions.py:153 msgid "" "A comma-separated list of groups, members of which should be excluded from " "recording, only when scope=all. " msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:158 +#: src/config/SSSDConfig/sssdoptions.py:157 msgid "Identity provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:159 +#: src/config/SSSDConfig/sssdoptions.py:158 msgid "Authentication provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:160 +#: src/config/SSSDConfig/sssdoptions.py:159 msgid "Access control provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:161 +#: src/config/SSSDConfig/sssdoptions.py:160 msgid "Password change provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:162 +#: src/config/SSSDConfig/sssdoptions.py:161 msgid "SUDO provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:163 +#: src/config/SSSDConfig/sssdoptions.py:162 msgid "Autofs provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:164 +#: src/config/SSSDConfig/sssdoptions.py:163 msgid "Host identity provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:165 +#: src/config/SSSDConfig/sssdoptions.py:164 msgid "SELinux provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:166 +#: src/config/SSSDConfig/sssdoptions.py:165 msgid "Session management provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:167 +#: src/config/SSSDConfig/sssdoptions.py:166 msgid "Resolver provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:170 +#: src/config/SSSDConfig/sssdoptions.py:169 msgid "Whether the domain is usable by the OS or by applications" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:171 +#: src/config/SSSDConfig/sssdoptions.py:170 msgid "Enable or disable the domain" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:172 +#: src/config/SSSDConfig/sssdoptions.py:171 msgid "Minimum user ID" msgstr "Gutxienezko erabiltzaile IDa" -#: src/config/SSSDConfig/sssdoptions.py:173 +#: src/config/SSSDConfig/sssdoptions.py:172 msgid "Maximum user ID" msgstr "Gehienezko erabiltzaile IDa" -#: src/config/SSSDConfig/sssdoptions.py:174 +#: src/config/SSSDConfig/sssdoptions.py:173 msgid "Enable enumerating all users/groups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:175 +#: src/config/SSSDConfig/sssdoptions.py:174 msgid "Cache credentials for offline login" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:176 +#: src/config/SSSDConfig/sssdoptions.py:175 msgid "Display users/groups in fully-qualified form" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:177 +#: src/config/SSSDConfig/sssdoptions.py:176 msgid "Don't include group members in group lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:178 +#: src/config/SSSDConfig/sssdoptions.py:177 #: src/config/SSSDConfig/sssdoptions.py:190 #: src/config/SSSDConfig/sssdoptions.py:191 #: src/config/SSSDConfig/sssdoptions.py:192 @@ -530,48 +537,52 @@ msgstr "" msgid "Entry cache timeout length (seconds)" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:179 +#: src/config/SSSDConfig/sssdoptions.py:178 msgid "" "Restrict or prefer a specific address family when performing DNS lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:180 +#: src/config/SSSDConfig/sssdoptions.py:179 msgid "How long to keep cached entries after last successful login (days)" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:181 +#: src/config/SSSDConfig/sssdoptions.py:180 msgid "" "How long should SSSD talk to single DNS server before trying next server " "(miliseconds)" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:183 +#: src/config/SSSDConfig/sssdoptions.py:182 msgid "How long should keep trying to resolve single DNS query (seconds)" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:184 +#: src/config/SSSDConfig/sssdoptions.py:183 msgid "How long to wait for replies from DNS when resolving servers (seconds)" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:185 +#: src/config/SSSDConfig/sssdoptions.py:184 msgid "The domain part of service discovery DNS query" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:186 +#: src/config/SSSDConfig/sssdoptions.py:185 msgid "" "Specifies the interval, in seconds, that SSSD waits before attempting to " "reconnect to the primary server after a successful connection to the backup " "server" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:188 +#: src/config/SSSDConfig/sssdoptions.py:187 msgid "Override GID value from the identity provider with this value" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:189 +#: src/config/SSSDConfig/sssdoptions.py:188 msgid "Treat usernames as case sensitive" msgstr "" +#: src/config/SSSDConfig/sssdoptions.py:189 +msgid "Lookups by ID are expensive or do not work at all" +msgstr "" + #: src/config/SSSDConfig/sssdoptions.py:197 msgid "How often should expired entries be refreshed in background" msgstr "" @@ -791,7 +802,7 @@ msgid "Search base for SUBID ranges" msgstr "" #: src/config/SSSDConfig/sssdoptions.py:259 -#: src/config/SSSDConfig/sssdoptions.py:506 +#: src/config/SSSDConfig/sssdoptions.py:512 msgid "Which rules should be used to evaluate access control" msgstr "" @@ -933,7 +944,7 @@ msgid "Enable DNS sites - location based service discovery" msgstr "" #: src/config/SSSDConfig/sssdoptions.py:301 -#: src/config/SSSDConfig/sssdoptions.py:504 +#: src/config/SSSDConfig/sssdoptions.py:510 msgid "LDAP filter to determine access privileges" msgstr "" @@ -1353,7 +1364,7 @@ msgid "UUID attribute" msgstr "" #: src/config/SSSDConfig/sssdoptions.py:423 -#: src/config/SSSDConfig/sssdoptions.py:464 +#: src/config/SSSDConfig/sssdoptions.py:470 msgid "objectSID attribute" msgstr "objectSID atributua" @@ -1477,385 +1488,409 @@ msgstr "" msgid "A list of extra attributes to download along with the user entry" msgstr "" +#: src/config/SSSDConfig/sssdoptions.py:456 +msgid "The object class of an subid entry in LDAP." +msgstr "" + #: src/config/SSSDConfig/sssdoptions.py:457 -msgid "Base DN for group lookups" +msgid "Subordinate user ID count attribute" msgstr "" #: src/config/SSSDConfig/sssdoptions.py:458 -msgid "Objectclass for groups" +msgid "Subordinate group ID count attribute" msgstr "" #: src/config/SSSDConfig/sssdoptions.py:459 +msgid "User ID range start value attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:460 +msgid "Group ID range start value attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:461 +msgid "Owner of an entry" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:463 +msgid "Base DN for group lookups" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:464 +msgid "Objectclass for groups" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:465 msgid "Group name" msgstr "Talde-izena" -#: src/config/SSSDConfig/sssdoptions.py:460 +#: src/config/SSSDConfig/sssdoptions.py:466 msgid "Group password" msgstr "Taldearen pasahitza" -#: src/config/SSSDConfig/sssdoptions.py:461 +#: src/config/SSSDConfig/sssdoptions.py:467 msgid "GID attribute" msgstr "GID atributua" -#: src/config/SSSDConfig/sssdoptions.py:462 +#: src/config/SSSDConfig/sssdoptions.py:468 msgid "Group member attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:463 +#: src/config/SSSDConfig/sssdoptions.py:469 msgid "Group UUID attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:465 +#: src/config/SSSDConfig/sssdoptions.py:471 msgid "Modification time attribute for groups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:466 +#: src/config/SSSDConfig/sssdoptions.py:472 msgid "Type of the group and other flags" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:467 +#: src/config/SSSDConfig/sssdoptions.py:473 msgid "The LDAP group external member attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:468 +#: src/config/SSSDConfig/sssdoptions.py:474 msgid "Maximum nesting level SSSD will follow" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:469 +#: src/config/SSSDConfig/sssdoptions.py:475 msgid "Filter for group lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:470 +#: src/config/SSSDConfig/sssdoptions.py:476 msgid "Scope of group lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:472 +#: src/config/SSSDConfig/sssdoptions.py:478 msgid "Base DN for netgroup lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:473 +#: src/config/SSSDConfig/sssdoptions.py:479 msgid "Objectclass for netgroups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:474 +#: src/config/SSSDConfig/sssdoptions.py:480 msgid "Netgroup name" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:475 +#: src/config/SSSDConfig/sssdoptions.py:481 msgid "Netgroups members attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:476 +#: src/config/SSSDConfig/sssdoptions.py:482 msgid "Netgroup triple attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:477 +#: src/config/SSSDConfig/sssdoptions.py:483 msgid "Modification time attribute for netgroups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:479 +#: src/config/SSSDConfig/sssdoptions.py:485 msgid "Base DN for service lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:480 +#: src/config/SSSDConfig/sssdoptions.py:486 msgid "Objectclass for services" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:481 +#: src/config/SSSDConfig/sssdoptions.py:487 msgid "Service name attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:482 +#: src/config/SSSDConfig/sssdoptions.py:488 msgid "Service port attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:483 +#: src/config/SSSDConfig/sssdoptions.py:489 msgid "Service protocol attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:485 +#: src/config/SSSDConfig/sssdoptions.py:491 msgid "Lower bound for ID-mapping" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:486 +#: src/config/SSSDConfig/sssdoptions.py:492 msgid "Upper bound for ID-mapping" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:487 +#: src/config/SSSDConfig/sssdoptions.py:493 msgid "Number of IDs for each slice when ID-mapping" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:488 +#: src/config/SSSDConfig/sssdoptions.py:494 msgid "Use autorid-compatible algorithm for ID-mapping" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:489 +#: src/config/SSSDConfig/sssdoptions.py:495 msgid "Name of the default domain for ID-mapping" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:490 +#: src/config/SSSDConfig/sssdoptions.py:496 msgid "SID of the default domain for ID-mapping" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:491 +#: src/config/SSSDConfig/sssdoptions.py:497 msgid "Number of secondary slices" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:493 +#: src/config/SSSDConfig/sssdoptions.py:499 msgid "Whether to use Token-Groups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:494 +#: src/config/SSSDConfig/sssdoptions.py:500 msgid "Set lower boundary for allowed IDs from the LDAP server" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:495 +#: src/config/SSSDConfig/sssdoptions.py:501 msgid "Set upper boundary for allowed IDs from the LDAP server" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:496 +#: src/config/SSSDConfig/sssdoptions.py:502 msgid "DN for ppolicy queries" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:497 +#: src/config/SSSDConfig/sssdoptions.py:503 msgid "How many maximum entries to fetch during a wildcard request" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:498 +#: src/config/SSSDConfig/sssdoptions.py:504 msgid "Set libldap debug level" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:501 +#: src/config/SSSDConfig/sssdoptions.py:507 msgid "Policy to evaluate the password expiration" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:505 +#: src/config/SSSDConfig/sssdoptions.py:511 msgid "Which attributes shall be used to evaluate if an account is expired" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:509 +#: src/config/SSSDConfig/sssdoptions.py:515 msgid "URI of an LDAP server where password changes are allowed" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:510 +#: src/config/SSSDConfig/sssdoptions.py:516 msgid "URI of a backup LDAP server where password changes are allowed" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:511 +#: src/config/SSSDConfig/sssdoptions.py:517 msgid "DNS service name for LDAP password change server" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:512 +#: src/config/SSSDConfig/sssdoptions.py:518 msgid "" "Whether to update the ldap_user_shadow_last_change attribute after a " "password change" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:516 +#: src/config/SSSDConfig/sssdoptions.py:522 msgid "Base DN for sudo rules lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:517 +#: src/config/SSSDConfig/sssdoptions.py:523 msgid "Automatic full refresh period" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:518 +#: src/config/SSSDConfig/sssdoptions.py:524 msgid "Automatic smart refresh period" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:519 +#: src/config/SSSDConfig/sssdoptions.py:525 msgid "Smart and full refresh random offset" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:520 +#: src/config/SSSDConfig/sssdoptions.py:526 msgid "Whether to filter rules by hostname, IP addresses and network" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:521 +#: src/config/SSSDConfig/sssdoptions.py:527 msgid "" "Hostnames and/or fully qualified domain names of this machine to filter sudo " "rules" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:522 +#: src/config/SSSDConfig/sssdoptions.py:528 msgid "IPv4 or IPv6 addresses or network of this machine to filter sudo rules" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:523 +#: src/config/SSSDConfig/sssdoptions.py:529 msgid "Whether to include rules that contains netgroup in host attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:524 +#: src/config/SSSDConfig/sssdoptions.py:530 msgid "" "Whether to include rules that contains regular expression in host attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:525 +#: src/config/SSSDConfig/sssdoptions.py:531 msgid "Object class for sudo rules" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:526 +#: src/config/SSSDConfig/sssdoptions.py:532 msgid "Name of attribute that is used as object class for sudo rules" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:527 +#: src/config/SSSDConfig/sssdoptions.py:533 msgid "Sudo rule name" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:528 +#: src/config/SSSDConfig/sssdoptions.py:534 msgid "Sudo rule command attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:529 +#: src/config/SSSDConfig/sssdoptions.py:535 msgid "Sudo rule host attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:530 +#: src/config/SSSDConfig/sssdoptions.py:536 msgid "Sudo rule user attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:531 +#: src/config/SSSDConfig/sssdoptions.py:537 msgid "Sudo rule option attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:532 +#: src/config/SSSDConfig/sssdoptions.py:538 msgid "Sudo rule runas attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:533 +#: src/config/SSSDConfig/sssdoptions.py:539 msgid "Sudo rule runasuser attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:534 +#: src/config/SSSDConfig/sssdoptions.py:540 msgid "Sudo rule runasgroup attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:535 +#: src/config/SSSDConfig/sssdoptions.py:541 msgid "Sudo rule notbefore attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:536 +#: src/config/SSSDConfig/sssdoptions.py:542 msgid "Sudo rule notafter attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:537 +#: src/config/SSSDConfig/sssdoptions.py:543 msgid "Sudo rule order attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:540 +#: src/config/SSSDConfig/sssdoptions.py:546 msgid "Object class for automounter maps" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:541 +#: src/config/SSSDConfig/sssdoptions.py:547 msgid "Automounter map name attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:542 +#: src/config/SSSDConfig/sssdoptions.py:548 msgid "Object class for automounter map entries" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:543 +#: src/config/SSSDConfig/sssdoptions.py:549 msgid "Automounter map entry key attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:544 +#: src/config/SSSDConfig/sssdoptions.py:550 msgid "Automounter map entry value attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:545 +#: src/config/SSSDConfig/sssdoptions.py:551 msgid "Base DN for automounter map lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:546 +#: src/config/SSSDConfig/sssdoptions.py:552 msgid "The name of the automount master map in LDAP." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:549 +#: src/config/SSSDConfig/sssdoptions.py:555 msgid "Base DN for IP hosts lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:550 +#: src/config/SSSDConfig/sssdoptions.py:556 msgid "Object class for IP hosts" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:551 +#: src/config/SSSDConfig/sssdoptions.py:557 msgid "IP host name attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:552 +#: src/config/SSSDConfig/sssdoptions.py:558 msgid "IP host number (address) attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:553 +#: src/config/SSSDConfig/sssdoptions.py:559 msgid "IP host entryUSN attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:554 +#: src/config/SSSDConfig/sssdoptions.py:560 msgid "Base DN for IP networks lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:555 +#: src/config/SSSDConfig/sssdoptions.py:561 msgid "Object class for IP networks" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:556 +#: src/config/SSSDConfig/sssdoptions.py:562 msgid "IP network name attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:557 +#: src/config/SSSDConfig/sssdoptions.py:563 msgid "IP network number (address) attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:558 +#: src/config/SSSDConfig/sssdoptions.py:564 msgid "IP network entryUSN attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:561 +#: src/config/SSSDConfig/sssdoptions.py:567 msgid "Comma separated list of allowed users" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:562 +#: src/config/SSSDConfig/sssdoptions.py:568 msgid "Comma separated list of prohibited users" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:563 +#: src/config/SSSDConfig/sssdoptions.py:569 msgid "" "Comma separated list of groups that are allowed to log in. This applies only " "to groups within this SSSD domain. Local groups are not evaluated." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:565 +#: src/config/SSSDConfig/sssdoptions.py:571 msgid "" "Comma separated list of groups that are explicitly denied access. This " "applies only to groups within this SSSD domain. Local groups are not " "evaluated." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:569 +#: src/config/SSSDConfig/sssdoptions.py:575 msgid "The number of preforked proxy children." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:572 +#: src/config/SSSDConfig/sssdoptions.py:578 msgid "The name of the NSS library to use" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:573 +#: src/config/SSSDConfig/sssdoptions.py:579 msgid "The name of the NSS library to use for hosts and networks lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:574 +#: src/config/SSSDConfig/sssdoptions.py:580 msgid "Whether to look up canonical group name from cache if possible" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:577 +#: src/config/SSSDConfig/sssdoptions.py:583 msgid "PAM stack to use" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:580 +#: src/config/SSSDConfig/sssdoptions.py:586 msgid "Path of passwd file sources." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:581 +#: src/config/SSSDConfig/sssdoptions.py:587 msgid "Path of group file sources." msgstr "" @@ -1883,225 +1918,233 @@ msgstr "" msgid "Option -i|--interactive is not allowed together with -D|--daemon\n" msgstr "" -#: src/monitor/monitor.c:1836 +#: src/monitor/monitor.c:1838 msgid "Failed to get initial capabilities\n" msgstr "" -#: src/monitor/monitor.c:1847 +#: src/monitor/monitor.c:1849 msgid "Non-root service user support isn't built. Can't run under %" msgstr "" -#: src/monitor/monitor.c:1864 +#: src/monitor/monitor.c:1866 #, c-format msgid "Can't read config: '%s'\n" msgstr "" -#: src/monitor/monitor.c:1876 +#: src/monitor/monitor.c:1878 #, c-format -msgid "Failed to boostrap SSSD 'monitor' process: %s" +msgid "Failed to bootstrap SSSD 'monitor' process: %s" msgstr "" -#: src/monitor/monitor.c:1971 +#: src/monitor/monitor.c:1973 msgid "Out of memory\n" msgstr "" -#: src/providers/krb5/krb5_child.c:4221 +#: src/providers/krb5/krb5_child.c:4316 msgid "Use anonymous PKINIT to request FAST armor ticket" msgstr "" -#: src/providers/krb5/krb5_child.c:4223 +#: src/providers/krb5/krb5_child.c:4318 msgid "Kerberos realm to use" msgstr "" -#: src/providers/krb5/krb5_child.c:4225 +#: src/providers/krb5/krb5_child.c:4320 msgid "Requested lifetime of the ticket" msgstr "" -#: src/providers/krb5/krb5_child.c:4227 +#: src/providers/krb5/krb5_child.c:4322 msgid "Requested renewable lifetime of the ticket" msgstr "" -#: src/providers/krb5/krb5_child.c:4229 +#: src/providers/krb5/krb5_child.c:4324 msgid "FAST options ('never', 'try', 'demand')" msgstr "" -#: src/providers/krb5/krb5_child.c:4232 +#: src/providers/krb5/krb5_child.c:4327 msgid "Specifies the server principal to use for FAST" msgstr "" -#: src/providers/krb5/krb5_child.c:4234 +#: src/providers/krb5/krb5_child.c:4329 msgid "Requests canonicalization of the principal name" msgstr "" -#: src/providers/krb5/krb5_child.c:4236 +#: src/providers/krb5/krb5_child.c:4331 msgid "Use custom version of krb5_get_init_creds_password" msgstr "" -#: src/providers/krb5/krb5_child.c:4238 +#: src/providers/krb5/krb5_child.c:4333 msgid "Check PAC flags" msgstr "" -#: src/providers/data_provider_be.c:790 +#: src/providers/krb5/krb5_child.c:4335 +msgid "Set environment variable (KEY=VALUE)" +msgstr "" + +#: src/providers/data_provider_be.c:786 msgid "Domain of the information provider (mandatory)" msgstr "" -#: src/sss_client/common.c:1165 +#: src/sss_client/common.c:1208 msgid "Socket has wrong ownership or permissions." msgstr "" -#: src/sss_client/common.c:1168 +#: src/sss_client/common.c:1211 msgid "Unexpected format of the server credential message." msgstr "" -#: src/sss_client/common.c:1171 +#: src/sss_client/common.c:1214 msgid "SSSD is not run by trusted user." msgstr "" -#: src/sss_client/common.c:1174 +#: src/sss_client/common.c:1217 msgid "SSSD socket does not exist." msgstr "" -#: src/sss_client/common.c:1177 +#: src/sss_client/common.c:1220 msgid "Cannot get stat of SSSD socket." msgstr "" -#: src/sss_client/common.c:1182 +#: src/sss_client/common.c:1225 msgid "An error occurred, but no description can be found." msgstr "" -#: src/sss_client/common.c:1188 +#: src/sss_client/common.c:1231 msgid "Unexpected error while looking for an error description" msgstr "" -#: src/sss_client/pam_sss.c:74 +#: src/sss_client/pam_sss.c:135 msgid "Permission denied. " msgstr "" -#: src/sss_client/pam_sss.c:75 src/sss_client/pam_sss.c:843 -#: src/sss_client/pam_sss.c:854 +#: src/sss_client/pam_sss.c:136 src/sss_client/pam_sss.c:921 +#: src/sss_client/pam_sss.c:932 msgid "Server message: " msgstr "" -#: src/sss_client/pam_sss.c:76 +#: src/sss_client/pam_sss.c:137 msgid "" "Kerberos TGT will not be granted upon login, user experience will be " "affected." msgstr "" -#: src/sss_client/pam_sss.c:77 +#: src/sss_client/pam_sss.c:138 msgid "Enter PIN:" msgstr "" -#: src/sss_client/pam_sss.c:320 +#: src/sss_client/pam_sss.c:385 msgid "Passwords do not match" msgstr "" -#: src/sss_client/pam_sss.c:508 +#: src/sss_client/pam_sss.c:584 msgid "Password reset by root is not supported." msgstr "" -#: src/sss_client/pam_sss.c:549 +#: src/sss_client/pam_sss.c:625 msgid "Authenticated with cached credentials" msgstr "" -#: src/sss_client/pam_sss.c:550 +#: src/sss_client/pam_sss.c:626 msgid ", your cached password will expire at: " msgstr "" -#: src/sss_client/pam_sss.c:580 +#: src/sss_client/pam_sss.c:656 #, c-format msgid "Your password has expired. You have %1$d grace login(s) remaining." msgstr "" -#: src/sss_client/pam_sss.c:630 +#: src/sss_client/pam_sss.c:706 #, c-format msgid "Your password will expire in %1$d %2$s." msgstr "" -#: src/sss_client/pam_sss.c:633 +#: src/sss_client/pam_sss.c:709 #, fuzzy, c-format msgid "Your password has expired." msgstr "Huts egin du pasahitza aldatzeak. " -#: src/sss_client/pam_sss.c:684 +#: src/sss_client/pam_sss.c:760 msgid "Authentication is denied until: " msgstr "" -#: src/sss_client/pam_sss.c:705 +#: src/sss_client/pam_sss.c:781 msgid "System is offline, password change not possible" msgstr "" -#: src/sss_client/pam_sss.c:720 +#: src/sss_client/pam_sss.c:796 msgid "" "After changing the OTP password, you need to log out and back in order to " "acquire a ticket" msgstr "" -#: src/sss_client/pam_sss.c:735 +#: src/sss_client/pam_sss.c:813 msgid "PIN locked" msgstr "" -#: src/sss_client/pam_sss.c:750 +#: src/sss_client/pam_sss.c:828 msgid "" "No Kerberos TGT granted as the server does not support this method. Your " "single-sign on(SSO) experience will be affected." msgstr "" -#: src/sss_client/pam_sss.c:840 src/sss_client/pam_sss.c:853 +#: src/sss_client/pam_sss.c:918 src/sss_client/pam_sss.c:931 msgid "Password change failed. " msgstr "Huts egin du pasahitza aldatzeak. " -#: src/sss_client/pam_sss.c:1859 +#: src/sss_client/pam_sss.c:2028 #, c-format -msgid "Authenticate at %1$s and press ENTER." +msgid "Authenticate at \"%1$s\"." msgstr "" -#: src/sss_client/pam_sss.c:1862 +#: src/sss_client/pam_sss.c:2031 #, c-format -msgid "Authenticate with PIN %1$s at %2$s and press ENTER." +msgid "Authenticate with PIN \"%1$s\" at \"%2$s\"." msgstr "" -#: src/sss_client/pam_sss.c:2281 +#: src/sss_client/pam_sss.c:2470 msgid "Please (re)insert (different) Smartcard" msgstr "" -#: src/sss_client/pam_sss.c:2482 +#: src/sss_client/pam_sss.c:2700 msgid "New Password: " msgstr "Pasahitz berria: " -#: src/sss_client/pam_sss.c:2483 +#: src/sss_client/pam_sss.c:2701 msgid "Reenter new Password: " msgstr "Berriz sartu pasahitz berria: " -#: src/sss_client/pam_sss.c:2676 src/sss_client/pam_sss.c:2679 +#: src/sss_client/pam_sss.c:2890 +msgid "Press ENTER to continue." +msgstr "" + +#: src/sss_client/pam_sss.c:2913 src/sss_client/pam_sss.c:2916 msgid "First Factor: " msgstr "" -#: src/sss_client/pam_sss.c:2677 src/sss_client/pam_sss.c:2851 +#: src/sss_client/pam_sss.c:2914 src/sss_client/pam_sss.c:3088 msgid "Second Factor (optional): " msgstr "" -#: src/sss_client/pam_sss.c:2680 src/sss_client/pam_sss.c:2855 +#: src/sss_client/pam_sss.c:2917 src/sss_client/pam_sss.c:3092 msgid "Second Factor: " msgstr "" -#: src/sss_client/pam_sss.c:2684 +#: src/sss_client/pam_sss.c:2921 msgid "Insert your passkey device, then press ENTER." msgstr "" -#: src/sss_client/pam_sss.c:2688 src/sss_client/pam_sss.c:2696 +#: src/sss_client/pam_sss.c:2925 src/sss_client/pam_sss.c:2933 msgid "Password: " msgstr "Pasahitza: " -#: src/sss_client/pam_sss.c:2850 src/sss_client/pam_sss.c:2854 +#: src/sss_client/pam_sss.c:3087 src/sss_client/pam_sss.c:3091 msgid "First Factor (Current Password): " msgstr "" -#: src/sss_client/pam_sss.c:2874 +#: src/sss_client/pam_sss.c:3111 msgid "Current Password: " msgstr "Uneko pasahitza: " -#: src/sss_client/pam_sss.c:3248 +#: src/sss_client/pam_sss.c:3485 msgid "Password expired. Change your password now." msgstr "Pasahitza iraungita. Aldatu zure pasahitza orain." @@ -2535,9 +2578,9 @@ msgstr "" #: src/tools/sssctl/sssctl_cache.c:835 src/tools/sssctl/sssctl_cache.c:918 #: src/tools/sssctl/sssctl_cache.c:950 src/tools/sssctl/sssctl_cache.c:956 #: src/tools/sssctl/sssctl_cache.c:1010 src/tools/sssctl/sssctl_cache.c:1034 -#: src/tools/sssctl/sssctl_cache.c:1085 src/tools/sssctl/sssctl_cache.c:1194 -#: src/tools/sssctl/sssctl_cache.c:1229 src/tools/sssctl/sssctl_cache.c:1235 -#: src/tools/sssctl/sssctl_cache.c:1244 +#: src/tools/sssctl/sssctl_cache.c:1085 src/tools/sssctl/sssctl_cache.c:1195 +#: src/tools/sssctl/sssctl_cache.c:1230 src/tools/sssctl/sssctl_cache.c:1236 +#: src/tools/sssctl/sssctl_cache.c:1245 msgid "talloc failed\n" msgstr "" @@ -2611,25 +2654,25 @@ msgstr "" msgid "Unable to remove downloaded GPO files: %s\n" msgstr "" -#: src/tools/sssctl/sssctl_cache.c:1165 +#: src/tools/sssctl/sssctl_cache.c:1166 #, c-format msgid "Failed to fetch cache entry: %s\n" msgstr "" -#: src/tools/sssctl/sssctl_cache.c:1170 +#: src/tools/sssctl/sssctl_cache.c:1171 msgid "Could not determine object domain\n" msgstr "" -#: src/tools/sssctl/sssctl_cache.c:1200 +#: src/tools/sssctl/sssctl_cache.c:1201 msgid "Could not find GUID attribute in GPO entry\n" msgstr "" -#: src/tools/sssctl/sssctl_cache.c:1206 +#: src/tools/sssctl/sssctl_cache.c:1207 #, c-format msgid "Failed to delete GPO: %s\n" msgstr "" -#: src/tools/sssctl/sssctl_cache.c:1210 +#: src/tools/sssctl/sssctl_cache.c:1211 #, c-format msgid "%s removed from cache\n" msgstr "" @@ -2717,39 +2760,39 @@ msgid "" "\"/my/path/sssd.conf\", the snippet dir \"/my/path/conf.d\" is used)" msgstr "" -#: src/tools/sssctl/sssctl_config.c:114 +#: src/tools/sssctl/sssctl_config.c:126 #, c-format msgid "File %1$s does not exist.\n" msgstr "" -#: src/tools/sssctl/sssctl_config.c:115 +#: src/tools/sssctl/sssctl_config.c:127 msgid "There is no configuration.\n" msgstr "" -#: src/tools/sssctl/sssctl_config.c:120 +#: src/tools/sssctl/sssctl_config.c:132 #, c-format msgid "Configuration validation failed: %s\n" msgstr "" -#: src/tools/sssctl/sssctl_config.c:121 +#: src/tools/sssctl/sssctl_config.c:133 msgid "Run with high debug level to see details.\n" msgstr "" -#: src/tools/sssctl/sssctl_config.c:130 -msgid "Failed to run validators" +#: src/tools/sssctl/sssctl_config.c:142 +msgid "Failed to run validators\n" msgstr "" -#: src/tools/sssctl/sssctl_config.c:134 +#: src/tools/sssctl/sssctl_config.c:146 #, c-format msgid "Issues identified by validators: %zu\n" msgstr "" -#: src/tools/sssctl/sssctl_config.c:145 +#: src/tools/sssctl/sssctl_config.c:157 #, c-format msgid "Messages generated during configuration merging: %zu\n" msgstr "" -#: src/tools/sssctl/sssctl_config.c:158 +#: src/tools/sssctl/sssctl_config.c:170 #, c-format msgid "Used configuration snippet files: %zu\n" msgstr "" diff --git a/po/fi.po b/po/fi.po index 0ed319df374..302c7149167 100644 --- a/po/fi.po +++ b/po/fi.po @@ -10,8 +10,8 @@ msgid "" msgstr "" "Project-Id-Version: PACKAGE VERSION\n" "Report-Msgid-Bugs-To: sssd-devel@lists.fedorahosted.org\n" -"POT-Creation-Date: 2026-01-14 14:57+0000\n" -"PO-Revision-Date: 2026-04-23 16:28+0000\n" +"POT-Creation-Date: 2026-10-02 15:57+0000\n" +"PO-Revision-Date: 2026-10-05 17:11+0000\n" "Last-Translator: Anttijussi Karjalainen \n" "Language-Team: Finnish \n" @@ -20,50 +20,50 @@ msgstr "" "Content-Type: text/plain; charset=UTF-8\n" "Content-Transfer-Encoding: 8bit\n" "Plural-Forms: nplurals=2; plural=n != 1;\n" -"X-Generator: Weblate 5.17\n" +"X-Generator: Weblate 2026.10\n" -#: src/config/SSSDConfig/sssdoptions.py:20 -#: src/config/SSSDConfig/sssdoptions.py:21 +#: src/config/SSSDConfig/sssdoptions.py:16 +#: src/config/SSSDConfig/sssdoptions.py:17 msgid "Set the verbosity of the debug logging" msgstr "Määritä virheenkorjauksen kirjaamisen vuolaus" -#: src/config/SSSDConfig/sssdoptions.py:22 +#: src/config/SSSDConfig/sssdoptions.py:18 msgid "Include timestamps in debug logs" msgstr "Sisällytä aikaleimat virheenkorjauslokeihin" -#: src/config/SSSDConfig/sssdoptions.py:23 +#: src/config/SSSDConfig/sssdoptions.py:19 msgid "Include microseconds in timestamps in debug logs" msgstr "Sisällytä mikrosekunnit virheenkorjauslokien aikaleimoihin" -#: src/config/SSSDConfig/sssdoptions.py:24 +#: src/config/SSSDConfig/sssdoptions.py:20 msgid "Enable/disable debug backtrace" msgstr "Ota käyttöön/poista käytöstä virheenjäljitys" -#: src/config/SSSDConfig/sssdoptions.py:25 +#: src/config/SSSDConfig/sssdoptions.py:21 msgid "Watchdog timeout before restarting service" msgstr "Vahtikoiran aikakatkaisu ennen palvelun käynnistämistä uudelleen" -#: src/config/SSSDConfig/sssdoptions.py:26 +#: src/config/SSSDConfig/sssdoptions.py:22 msgid "Command to start service" msgstr "Komento, jolla palvelu käynnistetään" -#: src/config/SSSDConfig/sssdoptions.py:27 +#: src/config/SSSDConfig/sssdoptions.py:23 msgid "The number of file descriptors that may be opened by this responder" msgstr "Tiedostokuvaajien määrä, jonka tämä vastaaja voi avata" -#: src/config/SSSDConfig/sssdoptions.py:28 +#: src/config/SSSDConfig/sssdoptions.py:24 msgid "Idle time before automatic disconnection of a client" msgstr "Joutilasaika ennen asiakkaan automaattista yhteyden katkaisua" -#: src/config/SSSDConfig/sssdoptions.py:29 +#: src/config/SSSDConfig/sssdoptions.py:25 msgid "Idle time before automatic shutdown of the responder" msgstr "Joutilasaika ennen vastaajan automaattista sammutusta" -#: src/config/SSSDConfig/sssdoptions.py:30 +#: src/config/SSSDConfig/sssdoptions.py:26 msgid "Always query all the caches before querying the Data Providers" msgstr "Kysele aina kaikki välimuistit, ennen kuin kysyt tietojen tarjoajilta" -#: src/config/SSSDConfig/sssdoptions.py:31 +#: src/config/SSSDConfig/sssdoptions.py:27 msgid "" "When SSSD switches to offline mode the amount of time before it tries to go " "back online will increase based upon the time spent disconnected. This value " @@ -75,23 +75,23 @@ msgstr "" "Tämä arvo on sekunteina ja se lasketaan seuraavasti: yhteydettömän tilan " "aikakatkaisu + satunnainen_poikkeama." -#: src/config/SSSDConfig/sssdoptions.py:36 +#: src/config/SSSDConfig/sssdoptions.py:32 msgid "SSSD Services to start" msgstr "Käynnistettävät SSSD-palvelut" -#: src/config/SSSDConfig/sssdoptions.py:37 +#: src/config/SSSDConfig/sssdoptions.py:33 msgid "SSSD Domains to start" msgstr "Käynnistettävät SSSD-toimialueet" -#: src/config/SSSDConfig/sssdoptions.py:38 +#: src/config/SSSDConfig/sssdoptions.py:34 msgid "Regex to parse username and domain" msgstr "Käyttäjänimen ja toimialueen jäsentävä säännöllinen lauseke" -#: src/config/SSSDConfig/sssdoptions.py:39 +#: src/config/SSSDConfig/sssdoptions.py:35 msgid "Printf-compatible format for displaying fully-qualified names" msgstr "Printf-yhteensopiva muoto täysin pätevien nimien näyttämiseen" -#: src/config/SSSDConfig/sssdoptions.py:40 +#: src/config/SSSDConfig/sssdoptions.py:36 msgid "" "Directory on the filesystem where SSSD should store Kerberos replay cache " "files." @@ -99,37 +99,37 @@ msgstr "" "Tiedostojärjestelmän hakemisto, johon SSSD: n tulisi tallentaa Kerberos-" "toiston välimuistitiedostot." -#: src/config/SSSDConfig/sssdoptions.py:41 +#: src/config/SSSDConfig/sssdoptions.py:37 msgid "Domain to add to names without a domain component." msgstr "Toimialue, joka lisätään nimiin ilman toimialuekomponenttia." -#: src/config/SSSDConfig/sssdoptions.py:42 +#: src/config/SSSDConfig/sssdoptions.py:38 msgid "The user to drop privileges to" msgstr "Käyttäjä, jolle luovutetaan oikeudet" -#: src/config/SSSDConfig/sssdoptions.py:43 +#: src/config/SSSDConfig/sssdoptions.py:39 msgid "Tune certificate verification" msgstr "Viritä varmenteen vahvistus" -#: src/config/SSSDConfig/sssdoptions.py:44 +#: src/config/SSSDConfig/sssdoptions.py:40 msgid "All spaces in group or user names will be replaced with this character" msgstr "" "Kaikki välilyönnit ryhmien nimissä tai käyttäjätunnuksissa korvataan tällä " "merkillä" -#: src/config/SSSDConfig/sssdoptions.py:45 +#: src/config/SSSDConfig/sssdoptions.py:41 msgid "Tune sssd to honor or ignore netlink state changes" msgstr "Viritä sssd kunnioittamaan tai ohittamaan netlinkin tilan muutokset" -#: src/config/SSSDConfig/sssdoptions.py:46 +#: src/config/SSSDConfig/sssdoptions.py:42 msgid "Enable or disable the implicit files domain" msgstr "Ota käyttöön tai poista käytöstä implisiittinen tiedostojen toimialue" -#: src/config/SSSDConfig/sssdoptions.py:47 +#: src/config/SSSDConfig/sssdoptions.py:43 msgid "A specific order of the domains to be looked up" msgstr "Haettavien toimialueiden määritetty järjestys" -#: src/config/SSSDConfig/sssdoptions.py:48 +#: src/config/SSSDConfig/sssdoptions.py:44 msgid "" "Controls if SSSD should monitor the state of resolv.conf to identify when it " "needs to update its internal DNS resolver." @@ -137,7 +137,7 @@ msgstr "" "Määrittää, pitäisikö SSSD:n valvoa resolv.conf-tiedoston tilaa " "tunnistaakseen, milloin sen on päivitettävä sisäinen DNS-selvittäjä." -#: src/config/SSSDConfig/sssdoptions.py:50 +#: src/config/SSSDConfig/sssdoptions.py:46 msgid "" "SSSD monitors the state of resolv.conf to identify when it needs to update " "its internal DNS resolver. By default, we will attempt to use inotify for " @@ -149,73 +149,73 @@ msgstr "" "tähän ja palaamme tarkkailemaan resolv.conf-tiedostoa viiden sekunnin " "välein, jos inotifyta ei voida käyttää." -#: src/config/SSSDConfig/sssdoptions.py:53 +#: src/config/SSSDConfig/sssdoptions.py:49 msgid "Run PAC responder automatically for AD and IPA provider" msgstr "Suorita PAC-vastaaja automaattisesti AD- ja IPA-palveluntarjoajalle" -#: src/config/SSSDConfig/sssdoptions.py:54 +#: src/config/SSSDConfig/sssdoptions.py:50 msgid "Enable or disable core dumps for all SSSD processes." msgstr "" "Ota ytimen tyhjennys käyttöön tai poista se käytöstä kaikissa SSSD-" "prosesseissa." -#: src/config/SSSDConfig/sssdoptions.py:55 +#: src/config/SSSDConfig/sssdoptions.py:51 msgid "Tune passkey verification behavior" msgstr "Säädä salasanan vahvistuskäyttäytymistä" -#: src/config/SSSDConfig/sssdoptions.py:58 +#: src/config/SSSDConfig/sssdoptions.py:54 msgid "Enumeration cache timeout length (seconds)" msgstr "Luettelovälimuistin aikakatkaisun pituus (sekunteina)" -#: src/config/SSSDConfig/sssdoptions.py:59 +#: src/config/SSSDConfig/sssdoptions.py:55 msgid "Entry cache background update timeout length (seconds)" msgstr "Syötevälimuistin taustapäivityksen aikakatkaisun pituus (sekunteina)" -#: src/config/SSSDConfig/sssdoptions.py:60 -#: src/config/SSSDConfig/sssdoptions.py:125 +#: src/config/SSSDConfig/sssdoptions.py:56 +#: src/config/SSSDConfig/sssdoptions.py:124 msgid "Negative cache timeout length (seconds)" msgstr "Negatiivinen välimuistin aikakatkaisun pituus (sekunteina)" -#: src/config/SSSDConfig/sssdoptions.py:61 +#: src/config/SSSDConfig/sssdoptions.py:57 msgid "Users that SSSD should explicitly ignore" msgstr "Käyttäjät, jotka SSSD:n tulee jättää huomiotta" -#: src/config/SSSDConfig/sssdoptions.py:62 +#: src/config/SSSDConfig/sssdoptions.py:58 msgid "Groups that SSSD should explicitly ignore" msgstr "Ryhmät, jotka SSSD:n tulee jättää huomiotta" -#: src/config/SSSDConfig/sssdoptions.py:63 +#: src/config/SSSDConfig/sssdoptions.py:59 msgid "Should filtered users appear in groups" msgstr "Pitäisikö suodatettujen käyttäjien näkyä ryhmissä" -#: src/config/SSSDConfig/sssdoptions.py:64 +#: src/config/SSSDConfig/sssdoptions.py:60 msgid "The value of the password field the NSS provider should return" msgstr "Salasanakentän arvo, joka NSS-palveluntarjoajan tulee palauttaa" -#: src/config/SSSDConfig/sssdoptions.py:65 +#: src/config/SSSDConfig/sssdoptions.py:61 msgid "Override homedir value from the identity provider with this value" msgstr "Korvaa identiteetintarjoajan homedir-arvo tällä arvolla" -#: src/config/SSSDConfig/sssdoptions.py:66 +#: src/config/SSSDConfig/sssdoptions.py:62 msgid "" "Substitute empty homedir value from the identity provider with this value" msgstr "Korvaa identiteetintarjoajan tyhjä homedir-arvo tällä arvolla" -#: src/config/SSSDConfig/sssdoptions.py:67 +#: src/config/SSSDConfig/sssdoptions.py:63 msgid "Override shell value from the identity provider with this value" msgstr "Korvaa identiteetintarjoajan komentotulkki-arvo tällä arvolla" -#: src/config/SSSDConfig/sssdoptions.py:68 +#: src/config/SSSDConfig/sssdoptions.py:64 msgid "The list of shells users are allowed to log in with" msgstr "Luettelo komentotulkeista, joilla käyttäjät voivat kirjautua sisään" -#: src/config/SSSDConfig/sssdoptions.py:69 +#: src/config/SSSDConfig/sssdoptions.py:65 msgid "" "The list of shells that will be vetoed, and replaced with the fallback shell" msgstr "" "Luettelo komentotulkeista, jotka estetään ja korvataan peruskomentotulkilla" -#: src/config/SSSDConfig/sssdoptions.py:70 +#: src/config/SSSDConfig/sssdoptions.py:66 msgid "" "If a shell stored in central directory is allowed but not available, use " "this fallback" @@ -223,324 +223,331 @@ msgstr "" "Jos keskushakemistoon tallennettu komentotulkki on sallittu, mutta se ei ole " "käytettävissä, käytä tätä varavaihtoehtoa" -#: src/config/SSSDConfig/sssdoptions.py:71 +#: src/config/SSSDConfig/sssdoptions.py:67 msgid "Shell to use if the provider does not list one" msgstr "Käytettävä komentotulkki, jos tarjoaja ei luettele sellaista" -#: src/config/SSSDConfig/sssdoptions.py:72 +#: src/config/SSSDConfig/sssdoptions.py:68 msgid "How long will be in-memory cache records valid" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:74 +#: src/config/SSSDConfig/sssdoptions.py:70 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for passwd requests" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:76 +#: src/config/SSSDConfig/sssdoptions.py:72 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for group requests" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:78 +#: src/config/SSSDConfig/sssdoptions.py:74 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for initgroups requests" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:79 +#: src/config/SSSDConfig/sssdoptions.py:75 msgid "" "The value of this option will be used in the expansion of the " "override_homedir option if the template contains the format string %H." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:81 +#: src/config/SSSDConfig/sssdoptions.py:77 msgid "" "Specifies time in seconds for which the list of subdomains will be " "considered valid." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:83 +#: src/config/SSSDConfig/sssdoptions.py:79 msgid "" "The entry cache can be set to automatically update entries in the background " "if they are requested beyond a percentage of the entry_cache_timeout value " "for the domain." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:88 +#: src/config/SSSDConfig/sssdoptions.py:84 msgid "How long to allow cached logins between online logins (days)" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:89 +#: src/config/SSSDConfig/sssdoptions.py:85 msgid "How many failed logins attempts are allowed when offline" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:91 +#: src/config/SSSDConfig/sssdoptions.py:87 msgid "" "How long (minutes) to deny login after offline_failed_login_attempts has " "been reached" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:92 +#: src/config/SSSDConfig/sssdoptions.py:88 msgid "What kind of messages are displayed to the user during authentication" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:93 +#: src/config/SSSDConfig/sssdoptions.py:89 msgid "Filter PAM responses sent to the pam_sss" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:94 +#: src/config/SSSDConfig/sssdoptions.py:90 msgid "How many seconds to keep identity information cached for PAM requests" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:95 +#: src/config/SSSDConfig/sssdoptions.py:91 msgid "How many days before password expiration a warning should be displayed" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:96 +#: src/config/SSSDConfig/sssdoptions.py:92 msgid "List of trusted uids or user's name" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:97 +#: src/config/SSSDConfig/sssdoptions.py:93 msgid "List of domains accessible even for untrusted users." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:98 +#: src/config/SSSDConfig/sssdoptions.py:94 msgid "Message printed when user account is expired." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:99 +#: src/config/SSSDConfig/sssdoptions.py:95 msgid "Message printed when user account is locked." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:100 +#: src/config/SSSDConfig/sssdoptions.py:96 msgid "Allow certificate based/Smartcard authentication." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:101 +#: src/config/SSSDConfig/sssdoptions.py:97 msgid "Path to certificate database with PKCS#11 modules." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:102 +#: src/config/SSSDConfig/sssdoptions.py:98 msgid "Tune certificate verification for PAM authentication." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:103 +#: src/config/SSSDConfig/sssdoptions.py:99 msgid "How many seconds will pam_sss wait for p11_child to finish" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:104 +#: src/config/SSSDConfig/sssdoptions.py:100 msgid "Which PAM services are permitted to contact application domains" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:105 +#: src/config/SSSDConfig/sssdoptions.py:101 msgid "Allowed services for using smartcards" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:106 +#: src/config/SSSDConfig/sssdoptions.py:102 msgid "Additional timeout to wait for a card if requested" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:107 +#: src/config/SSSDConfig/sssdoptions.py:103 msgid "" "PKCS#11 URI to restrict the selection of devices for Smartcard authentication" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:108 +#: src/config/SSSDConfig/sssdoptions.py:104 msgid "When shall the PAM responder force an initgroups request" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:109 +#: src/config/SSSDConfig/sssdoptions.py:105 msgid "List of PAM services that are allowed to authenticate with GSSAPI." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:110 +#: src/config/SSSDConfig/sssdoptions.py:106 msgid "Whether to match authenticated UPN with target user" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:111 +#: src/config/SSSDConfig/sssdoptions.py:107 msgid "" "List of pairs : that must be enforced " "for PAM access with GSSAPI authentication" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:113 +#: src/config/SSSDConfig/sssdoptions.py:109 +msgid "" +"List of triples :: that assigns " +"additional information from the Kerberos ticket to an authentication " +"indicator." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:112 msgid "Allow passkey device authentication." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:114 +#: src/config/SSSDConfig/sssdoptions.py:113 msgid "How many seconds will pam_sss wait for passkey_child to finish" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:115 +#: src/config/SSSDConfig/sssdoptions.py:114 msgid "Enable debugging in the libfido2 library" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:116 +#: src/config/SSSDConfig/sssdoptions.py:115 msgid "Enable JSON protocol for authentication methods selection." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:119 +#: src/config/SSSDConfig/sssdoptions.py:118 msgid "Whether to evaluate the time-based attributes in sudo rules" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:120 +#: src/config/SSSDConfig/sssdoptions.py:119 msgid "If true, SSSD will switch back to lower-wins ordering logic" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:121 +#: src/config/SSSDConfig/sssdoptions.py:120 msgid "" "Maximum number of rules that can be refreshed at once. If this is exceeded, " "full refresh is performed." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:128 +#: src/config/SSSDConfig/sssdoptions.py:127 msgid "Whether to hash host names and addresses in the known_hosts file" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:129 +#: src/config/SSSDConfig/sssdoptions.py:128 msgid "" "How many seconds to keep a host in the known_hosts file after its host keys " "were requested" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:131 +#: src/config/SSSDConfig/sssdoptions.py:130 msgid "Path to storage of trusted CA certificates" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:132 +#: src/config/SSSDConfig/sssdoptions.py:131 msgid "Allow to generate ssh-keys from certificates" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:133 +#: src/config/SSSDConfig/sssdoptions.py:132 msgid "" "Use the following matching rules to filter the certificates for ssh-key " "generation" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:137 +#: src/config/SSSDConfig/sssdoptions.py:136 msgid "List of UIDs or user names allowed to access the PAC responder" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:138 +#: src/config/SSSDConfig/sssdoptions.py:137 msgid "How long the PAC data is considered valid" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:139 +#: src/config/SSSDConfig/sssdoptions.py:138 msgid "Validate the PAC" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:142 +#: src/config/SSSDConfig/sssdoptions.py:141 msgid "List of user attributes the InfoPipe is allowed to publish" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:145 +#: src/config/SSSDConfig/sssdoptions.py:144 msgid "" "One of the following strings specifying the scope of session recording: none " "- No users are recorded. some - Users/groups specified by users and groups " "options are recorded. all - All users are recorded." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:148 +#: src/config/SSSDConfig/sssdoptions.py:147 msgid "" "A comma-separated list of users which should have session recording enabled. " "Matches user names as returned by NSS. I.e. after the possible space " "replacement, case changes, etc." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:150 +#: src/config/SSSDConfig/sssdoptions.py:149 msgid "" "A comma-separated list of groups, members of which should have session " "recording enabled. Matches group names as returned by NSS. I.e. after the " "possible space replacement, case changes, etc." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:153 +#: src/config/SSSDConfig/sssdoptions.py:152 msgid "" "A comma-separated list of users to be excluded from recording, only when " "scope=all" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:154 +#: src/config/SSSDConfig/sssdoptions.py:153 msgid "" "A comma-separated list of groups, members of which should be excluded from " "recording, only when scope=all. " msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:158 +#: src/config/SSSDConfig/sssdoptions.py:157 msgid "Identity provider" msgstr "Tunnistustietojen tarjoaja" -#: src/config/SSSDConfig/sssdoptions.py:159 +#: src/config/SSSDConfig/sssdoptions.py:158 msgid "Authentication provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:160 +#: src/config/SSSDConfig/sssdoptions.py:159 msgid "Access control provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:161 +#: src/config/SSSDConfig/sssdoptions.py:160 msgid "Password change provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:162 +#: src/config/SSSDConfig/sssdoptions.py:161 msgid "SUDO provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:163 +#: src/config/SSSDConfig/sssdoptions.py:162 msgid "Autofs provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:164 +#: src/config/SSSDConfig/sssdoptions.py:163 msgid "Host identity provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:165 +#: src/config/SSSDConfig/sssdoptions.py:164 msgid "SELinux provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:166 +#: src/config/SSSDConfig/sssdoptions.py:165 msgid "Session management provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:167 +#: src/config/SSSDConfig/sssdoptions.py:166 msgid "Resolver provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:170 +#: src/config/SSSDConfig/sssdoptions.py:169 msgid "Whether the domain is usable by the OS or by applications" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:171 +#: src/config/SSSDConfig/sssdoptions.py:170 msgid "Enable or disable the domain" msgstr "Ota toimialue käyttöön tai poista se käytöstä" -#: src/config/SSSDConfig/sssdoptions.py:172 +#: src/config/SSSDConfig/sssdoptions.py:171 msgid "Minimum user ID" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:173 +#: src/config/SSSDConfig/sssdoptions.py:172 msgid "Maximum user ID" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:174 +#: src/config/SSSDConfig/sssdoptions.py:173 msgid "Enable enumerating all users/groups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:175 +#: src/config/SSSDConfig/sssdoptions.py:174 msgid "Cache credentials for offline login" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:176 +#: src/config/SSSDConfig/sssdoptions.py:175 msgid "Display users/groups in fully-qualified form" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:177 +#: src/config/SSSDConfig/sssdoptions.py:176 msgid "Don't include group members in group lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:178 +#: src/config/SSSDConfig/sssdoptions.py:177 #: src/config/SSSDConfig/sssdoptions.py:190 #: src/config/SSSDConfig/sssdoptions.py:191 #: src/config/SSSDConfig/sssdoptions.py:192 @@ -551,48 +558,52 @@ msgstr "" msgid "Entry cache timeout length (seconds)" msgstr "Välimuistin aikakatkaisun pituus (sekunteina)" -#: src/config/SSSDConfig/sssdoptions.py:179 +#: src/config/SSSDConfig/sssdoptions.py:178 msgid "" "Restrict or prefer a specific address family when performing DNS lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:180 +#: src/config/SSSDConfig/sssdoptions.py:179 msgid "How long to keep cached entries after last successful login (days)" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:181 +#: src/config/SSSDConfig/sssdoptions.py:180 msgid "" "How long should SSSD talk to single DNS server before trying next server " "(miliseconds)" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:183 +#: src/config/SSSDConfig/sssdoptions.py:182 msgid "How long should keep trying to resolve single DNS query (seconds)" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:184 +#: src/config/SSSDConfig/sssdoptions.py:183 msgid "How long to wait for replies from DNS when resolving servers (seconds)" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:185 +#: src/config/SSSDConfig/sssdoptions.py:184 msgid "The domain part of service discovery DNS query" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:186 +#: src/config/SSSDConfig/sssdoptions.py:185 msgid "" "Specifies the interval, in seconds, that SSSD waits before attempting to " "reconnect to the primary server after a successful connection to the backup " "server" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:188 +#: src/config/SSSDConfig/sssdoptions.py:187 msgid "Override GID value from the identity provider with this value" msgstr "Korvaa identiteetintarjoajan GID-arvo tällä arvolla" -#: src/config/SSSDConfig/sssdoptions.py:189 +#: src/config/SSSDConfig/sssdoptions.py:188 msgid "Treat usernames as case sensitive" msgstr "" +#: src/config/SSSDConfig/sssdoptions.py:189 +msgid "Lookups by ID are expensive or do not work at all" +msgstr "" + #: src/config/SSSDConfig/sssdoptions.py:197 msgid "How often should expired entries be refreshed in background" msgstr "" @@ -812,7 +823,7 @@ msgid "Search base for SUBID ranges" msgstr "" #: src/config/SSSDConfig/sssdoptions.py:259 -#: src/config/SSSDConfig/sssdoptions.py:506 +#: src/config/SSSDConfig/sssdoptions.py:512 msgid "Which rules should be used to evaluate access control" msgstr "" @@ -954,7 +965,7 @@ msgid "Enable DNS sites - location based service discovery" msgstr "" #: src/config/SSSDConfig/sssdoptions.py:301 -#: src/config/SSSDConfig/sssdoptions.py:504 +#: src/config/SSSDConfig/sssdoptions.py:510 msgid "LDAP filter to determine access privileges" msgstr "" @@ -1374,7 +1385,7 @@ msgid "UUID attribute" msgstr "" #: src/config/SSSDConfig/sssdoptions.py:423 -#: src/config/SSSDConfig/sssdoptions.py:464 +#: src/config/SSSDConfig/sssdoptions.py:470 msgid "objectSID attribute" msgstr "" @@ -1498,385 +1509,409 @@ msgstr "" msgid "A list of extra attributes to download along with the user entry" msgstr "" +#: src/config/SSSDConfig/sssdoptions.py:456 +msgid "The object class of an subid entry in LDAP." +msgstr "" + #: src/config/SSSDConfig/sssdoptions.py:457 -msgid "Base DN for group lookups" +msgid "Subordinate user ID count attribute" msgstr "" #: src/config/SSSDConfig/sssdoptions.py:458 -msgid "Objectclass for groups" +msgid "Subordinate group ID count attribute" msgstr "" #: src/config/SSSDConfig/sssdoptions.py:459 +msgid "User ID range start value attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:460 +msgid "Group ID range start value attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:461 +msgid "Owner of an entry" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:463 +msgid "Base DN for group lookups" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:464 +msgid "Objectclass for groups" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:465 msgid "Group name" msgstr "Ryhmän nimi" -#: src/config/SSSDConfig/sssdoptions.py:460 +#: src/config/SSSDConfig/sssdoptions.py:466 msgid "Group password" msgstr "Ryhmän salasana" -#: src/config/SSSDConfig/sssdoptions.py:461 +#: src/config/SSSDConfig/sssdoptions.py:467 msgid "GID attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:462 +#: src/config/SSSDConfig/sssdoptions.py:468 msgid "Group member attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:463 +#: src/config/SSSDConfig/sssdoptions.py:469 msgid "Group UUID attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:465 +#: src/config/SSSDConfig/sssdoptions.py:471 msgid "Modification time attribute for groups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:466 +#: src/config/SSSDConfig/sssdoptions.py:472 msgid "Type of the group and other flags" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:467 +#: src/config/SSSDConfig/sssdoptions.py:473 msgid "The LDAP group external member attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:468 +#: src/config/SSSDConfig/sssdoptions.py:474 msgid "Maximum nesting level SSSD will follow" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:469 +#: src/config/SSSDConfig/sssdoptions.py:475 msgid "Filter for group lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:470 +#: src/config/SSSDConfig/sssdoptions.py:476 msgid "Scope of group lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:472 +#: src/config/SSSDConfig/sssdoptions.py:478 msgid "Base DN for netgroup lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:473 +#: src/config/SSSDConfig/sssdoptions.py:479 msgid "Objectclass for netgroups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:474 +#: src/config/SSSDConfig/sssdoptions.py:480 msgid "Netgroup name" msgstr "Verkkoryhmän nimi" -#: src/config/SSSDConfig/sssdoptions.py:475 +#: src/config/SSSDConfig/sssdoptions.py:481 msgid "Netgroups members attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:476 +#: src/config/SSSDConfig/sssdoptions.py:482 msgid "Netgroup triple attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:477 +#: src/config/SSSDConfig/sssdoptions.py:483 msgid "Modification time attribute for netgroups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:479 +#: src/config/SSSDConfig/sssdoptions.py:485 msgid "Base DN for service lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:480 +#: src/config/SSSDConfig/sssdoptions.py:486 msgid "Objectclass for services" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:481 +#: src/config/SSSDConfig/sssdoptions.py:487 msgid "Service name attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:482 +#: src/config/SSSDConfig/sssdoptions.py:488 msgid "Service port attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:483 +#: src/config/SSSDConfig/sssdoptions.py:489 msgid "Service protocol attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:485 +#: src/config/SSSDConfig/sssdoptions.py:491 msgid "Lower bound for ID-mapping" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:486 +#: src/config/SSSDConfig/sssdoptions.py:492 msgid "Upper bound for ID-mapping" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:487 +#: src/config/SSSDConfig/sssdoptions.py:493 msgid "Number of IDs for each slice when ID-mapping" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:488 +#: src/config/SSSDConfig/sssdoptions.py:494 msgid "Use autorid-compatible algorithm for ID-mapping" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:489 +#: src/config/SSSDConfig/sssdoptions.py:495 msgid "Name of the default domain for ID-mapping" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:490 +#: src/config/SSSDConfig/sssdoptions.py:496 msgid "SID of the default domain for ID-mapping" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:491 +#: src/config/SSSDConfig/sssdoptions.py:497 msgid "Number of secondary slices" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:493 +#: src/config/SSSDConfig/sssdoptions.py:499 msgid "Whether to use Token-Groups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:494 +#: src/config/SSSDConfig/sssdoptions.py:500 msgid "Set lower boundary for allowed IDs from the LDAP server" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:495 +#: src/config/SSSDConfig/sssdoptions.py:501 msgid "Set upper boundary for allowed IDs from the LDAP server" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:496 +#: src/config/SSSDConfig/sssdoptions.py:502 msgid "DN for ppolicy queries" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:497 +#: src/config/SSSDConfig/sssdoptions.py:503 msgid "How many maximum entries to fetch during a wildcard request" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:498 +#: src/config/SSSDConfig/sssdoptions.py:504 msgid "Set libldap debug level" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:501 +#: src/config/SSSDConfig/sssdoptions.py:507 msgid "Policy to evaluate the password expiration" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:505 +#: src/config/SSSDConfig/sssdoptions.py:511 msgid "Which attributes shall be used to evaluate if an account is expired" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:509 +#: src/config/SSSDConfig/sssdoptions.py:515 msgid "URI of an LDAP server where password changes are allowed" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:510 +#: src/config/SSSDConfig/sssdoptions.py:516 msgid "URI of a backup LDAP server where password changes are allowed" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:511 +#: src/config/SSSDConfig/sssdoptions.py:517 msgid "DNS service name for LDAP password change server" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:512 +#: src/config/SSSDConfig/sssdoptions.py:518 msgid "" "Whether to update the ldap_user_shadow_last_change attribute after a " "password change" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:516 +#: src/config/SSSDConfig/sssdoptions.py:522 msgid "Base DN for sudo rules lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:517 +#: src/config/SSSDConfig/sssdoptions.py:523 msgid "Automatic full refresh period" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:518 +#: src/config/SSSDConfig/sssdoptions.py:524 msgid "Automatic smart refresh period" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:519 +#: src/config/SSSDConfig/sssdoptions.py:525 msgid "Smart and full refresh random offset" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:520 +#: src/config/SSSDConfig/sssdoptions.py:526 msgid "Whether to filter rules by hostname, IP addresses and network" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:521 +#: src/config/SSSDConfig/sssdoptions.py:527 msgid "" "Hostnames and/or fully qualified domain names of this machine to filter sudo " "rules" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:522 +#: src/config/SSSDConfig/sssdoptions.py:528 msgid "IPv4 or IPv6 addresses or network of this machine to filter sudo rules" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:523 +#: src/config/SSSDConfig/sssdoptions.py:529 msgid "Whether to include rules that contains netgroup in host attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:524 +#: src/config/SSSDConfig/sssdoptions.py:530 msgid "" "Whether to include rules that contains regular expression in host attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:525 +#: src/config/SSSDConfig/sssdoptions.py:531 msgid "Object class for sudo rules" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:526 +#: src/config/SSSDConfig/sssdoptions.py:532 msgid "Name of attribute that is used as object class for sudo rules" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:527 +#: src/config/SSSDConfig/sssdoptions.py:533 msgid "Sudo rule name" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:528 +#: src/config/SSSDConfig/sssdoptions.py:534 msgid "Sudo rule command attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:529 +#: src/config/SSSDConfig/sssdoptions.py:535 msgid "Sudo rule host attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:530 +#: src/config/SSSDConfig/sssdoptions.py:536 msgid "Sudo rule user attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:531 +#: src/config/SSSDConfig/sssdoptions.py:537 msgid "Sudo rule option attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:532 +#: src/config/SSSDConfig/sssdoptions.py:538 msgid "Sudo rule runas attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:533 +#: src/config/SSSDConfig/sssdoptions.py:539 msgid "Sudo rule runasuser attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:534 +#: src/config/SSSDConfig/sssdoptions.py:540 msgid "Sudo rule runasgroup attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:535 +#: src/config/SSSDConfig/sssdoptions.py:541 msgid "Sudo rule notbefore attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:536 +#: src/config/SSSDConfig/sssdoptions.py:542 msgid "Sudo rule notafter attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:537 +#: src/config/SSSDConfig/sssdoptions.py:543 msgid "Sudo rule order attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:540 +#: src/config/SSSDConfig/sssdoptions.py:546 msgid "Object class for automounter maps" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:541 +#: src/config/SSSDConfig/sssdoptions.py:547 msgid "Automounter map name attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:542 +#: src/config/SSSDConfig/sssdoptions.py:548 msgid "Object class for automounter map entries" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:543 +#: src/config/SSSDConfig/sssdoptions.py:549 msgid "Automounter map entry key attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:544 +#: src/config/SSSDConfig/sssdoptions.py:550 msgid "Automounter map entry value attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:545 +#: src/config/SSSDConfig/sssdoptions.py:551 msgid "Base DN for automounter map lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:546 +#: src/config/SSSDConfig/sssdoptions.py:552 msgid "The name of the automount master map in LDAP." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:549 +#: src/config/SSSDConfig/sssdoptions.py:555 msgid "Base DN for IP hosts lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:550 +#: src/config/SSSDConfig/sssdoptions.py:556 msgid "Object class for IP hosts" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:551 +#: src/config/SSSDConfig/sssdoptions.py:557 msgid "IP host name attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:552 +#: src/config/SSSDConfig/sssdoptions.py:558 msgid "IP host number (address) attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:553 +#: src/config/SSSDConfig/sssdoptions.py:559 msgid "IP host entryUSN attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:554 +#: src/config/SSSDConfig/sssdoptions.py:560 msgid "Base DN for IP networks lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:555 +#: src/config/SSSDConfig/sssdoptions.py:561 msgid "Object class for IP networks" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:556 +#: src/config/SSSDConfig/sssdoptions.py:562 msgid "IP network name attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:557 +#: src/config/SSSDConfig/sssdoptions.py:563 msgid "IP network number (address) attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:558 +#: src/config/SSSDConfig/sssdoptions.py:564 msgid "IP network entryUSN attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:561 +#: src/config/SSSDConfig/sssdoptions.py:567 msgid "Comma separated list of allowed users" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:562 +#: src/config/SSSDConfig/sssdoptions.py:568 msgid "Comma separated list of prohibited users" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:563 +#: src/config/SSSDConfig/sssdoptions.py:569 msgid "" "Comma separated list of groups that are allowed to log in. This applies only " "to groups within this SSSD domain. Local groups are not evaluated." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:565 +#: src/config/SSSDConfig/sssdoptions.py:571 msgid "" "Comma separated list of groups that are explicitly denied access. This " "applies only to groups within this SSSD domain. Local groups are not " "evaluated." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:569 +#: src/config/SSSDConfig/sssdoptions.py:575 msgid "The number of preforked proxy children." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:572 +#: src/config/SSSDConfig/sssdoptions.py:578 msgid "The name of the NSS library to use" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:573 +#: src/config/SSSDConfig/sssdoptions.py:579 msgid "The name of the NSS library to use for hosts and networks lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:574 +#: src/config/SSSDConfig/sssdoptions.py:580 msgid "Whether to look up canonical group name from cache if possible" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:577 +#: src/config/SSSDConfig/sssdoptions.py:583 msgid "PAM stack to use" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:580 +#: src/config/SSSDConfig/sssdoptions.py:586 msgid "Path of passwd file sources." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:581 +#: src/config/SSSDConfig/sssdoptions.py:587 msgid "Path of group file sources." msgstr "" @@ -1904,225 +1939,233 @@ msgstr "" msgid "Option -i|--interactive is not allowed together with -D|--daemon\n" msgstr "" -#: src/monitor/monitor.c:1836 +#: src/monitor/monitor.c:1838 msgid "Failed to get initial capabilities\n" msgstr "" -#: src/monitor/monitor.c:1847 +#: src/monitor/monitor.c:1849 msgid "Non-root service user support isn't built. Can't run under %" msgstr "" -#: src/monitor/monitor.c:1864 +#: src/monitor/monitor.c:1866 #, c-format msgid "Can't read config: '%s'\n" msgstr "" -#: src/monitor/monitor.c:1876 +#: src/monitor/monitor.c:1878 #, c-format -msgid "Failed to boostrap SSSD 'monitor' process: %s" +msgid "Failed to bootstrap SSSD 'monitor' process: %s" msgstr "" -#: src/monitor/monitor.c:1971 +#: src/monitor/monitor.c:1973 msgid "Out of memory\n" msgstr "Muisti loppui!\n" -#: src/providers/krb5/krb5_child.c:4221 +#: src/providers/krb5/krb5_child.c:4316 msgid "Use anonymous PKINIT to request FAST armor ticket" msgstr "" -#: src/providers/krb5/krb5_child.c:4223 +#: src/providers/krb5/krb5_child.c:4318 msgid "Kerberos realm to use" msgstr "" -#: src/providers/krb5/krb5_child.c:4225 +#: src/providers/krb5/krb5_child.c:4320 msgid "Requested lifetime of the ticket" msgstr "" -#: src/providers/krb5/krb5_child.c:4227 +#: src/providers/krb5/krb5_child.c:4322 msgid "Requested renewable lifetime of the ticket" msgstr "" -#: src/providers/krb5/krb5_child.c:4229 +#: src/providers/krb5/krb5_child.c:4324 msgid "FAST options ('never', 'try', 'demand')" msgstr "" -#: src/providers/krb5/krb5_child.c:4232 +#: src/providers/krb5/krb5_child.c:4327 msgid "Specifies the server principal to use for FAST" msgstr "" -#: src/providers/krb5/krb5_child.c:4234 +#: src/providers/krb5/krb5_child.c:4329 msgid "Requests canonicalization of the principal name" msgstr "" -#: src/providers/krb5/krb5_child.c:4236 +#: src/providers/krb5/krb5_child.c:4331 msgid "Use custom version of krb5_get_init_creds_password" msgstr "" -#: src/providers/krb5/krb5_child.c:4238 +#: src/providers/krb5/krb5_child.c:4333 msgid "Check PAC flags" msgstr "" -#: src/providers/data_provider_be.c:790 +#: src/providers/krb5/krb5_child.c:4335 +msgid "Set environment variable (KEY=VALUE)" +msgstr "" + +#: src/providers/data_provider_be.c:786 msgid "Domain of the information provider (mandatory)" msgstr "" -#: src/sss_client/common.c:1165 +#: src/sss_client/common.c:1208 msgid "Socket has wrong ownership or permissions." msgstr "" -#: src/sss_client/common.c:1168 +#: src/sss_client/common.c:1211 msgid "Unexpected format of the server credential message." msgstr "" -#: src/sss_client/common.c:1171 +#: src/sss_client/common.c:1214 msgid "SSSD is not run by trusted user." msgstr "" -#: src/sss_client/common.c:1174 +#: src/sss_client/common.c:1217 msgid "SSSD socket does not exist." msgstr "" -#: src/sss_client/common.c:1177 +#: src/sss_client/common.c:1220 msgid "Cannot get stat of SSSD socket." msgstr "" -#: src/sss_client/common.c:1182 +#: src/sss_client/common.c:1225 msgid "An error occurred, but no description can be found." msgstr "" -#: src/sss_client/common.c:1188 +#: src/sss_client/common.c:1231 msgid "Unexpected error while looking for an error description" msgstr "" -#: src/sss_client/pam_sss.c:74 +#: src/sss_client/pam_sss.c:135 msgid "Permission denied. " msgstr "Käyttö estetty " -#: src/sss_client/pam_sss.c:75 src/sss_client/pam_sss.c:843 -#: src/sss_client/pam_sss.c:854 +#: src/sss_client/pam_sss.c:136 src/sss_client/pam_sss.c:921 +#: src/sss_client/pam_sss.c:932 msgid "Server message: " msgstr "" -#: src/sss_client/pam_sss.c:76 +#: src/sss_client/pam_sss.c:137 msgid "" "Kerberos TGT will not be granted upon login, user experience will be " "affected." msgstr "" -#: src/sss_client/pam_sss.c:77 +#: src/sss_client/pam_sss.c:138 msgid "Enter PIN:" msgstr "" -#: src/sss_client/pam_sss.c:320 +#: src/sss_client/pam_sss.c:385 msgid "Passwords do not match" msgstr "Salasanat eivät täsmää" -#: src/sss_client/pam_sss.c:508 +#: src/sss_client/pam_sss.c:584 msgid "Password reset by root is not supported." msgstr "" -#: src/sss_client/pam_sss.c:549 +#: src/sss_client/pam_sss.c:625 msgid "Authenticated with cached credentials" msgstr "" -#: src/sss_client/pam_sss.c:550 +#: src/sss_client/pam_sss.c:626 msgid ", your cached password will expire at: " msgstr "" -#: src/sss_client/pam_sss.c:580 +#: src/sss_client/pam_sss.c:656 #, c-format msgid "Your password has expired. You have %1$d grace login(s) remaining." msgstr "" -#: src/sss_client/pam_sss.c:630 +#: src/sss_client/pam_sss.c:706 #, c-format msgid "Your password will expire in %1$d %2$s." msgstr "" -#: src/sss_client/pam_sss.c:633 +#: src/sss_client/pam_sss.c:709 #, c-format msgid "Your password has expired." msgstr "" -#: src/sss_client/pam_sss.c:684 +#: src/sss_client/pam_sss.c:760 msgid "Authentication is denied until: " msgstr "" -#: src/sss_client/pam_sss.c:705 +#: src/sss_client/pam_sss.c:781 msgid "System is offline, password change not possible" msgstr "" -#: src/sss_client/pam_sss.c:720 +#: src/sss_client/pam_sss.c:796 msgid "" "After changing the OTP password, you need to log out and back in order to " "acquire a ticket" msgstr "" -#: src/sss_client/pam_sss.c:735 +#: src/sss_client/pam_sss.c:813 msgid "PIN locked" msgstr "" -#: src/sss_client/pam_sss.c:750 +#: src/sss_client/pam_sss.c:828 msgid "" "No Kerberos TGT granted as the server does not support this method. Your " "single-sign on(SSO) experience will be affected." msgstr "" -#: src/sss_client/pam_sss.c:840 src/sss_client/pam_sss.c:853 +#: src/sss_client/pam_sss.c:918 src/sss_client/pam_sss.c:931 msgid "Password change failed. " msgstr "Salasanan vaihtaminen epäonnistui. " -#: src/sss_client/pam_sss.c:1859 +#: src/sss_client/pam_sss.c:2028 #, c-format -msgid "Authenticate at %1$s and press ENTER." +msgid "Authenticate at \"%1$s\"." msgstr "" -#: src/sss_client/pam_sss.c:1862 +#: src/sss_client/pam_sss.c:2031 #, c-format -msgid "Authenticate with PIN %1$s at %2$s and press ENTER." +msgid "Authenticate with PIN \"%1$s\" at \"%2$s\"." msgstr "" -#: src/sss_client/pam_sss.c:2281 +#: src/sss_client/pam_sss.c:2470 msgid "Please (re)insert (different) Smartcard" msgstr "" -#: src/sss_client/pam_sss.c:2482 +#: src/sss_client/pam_sss.c:2700 msgid "New Password: " msgstr "Uusi salasana: " -#: src/sss_client/pam_sss.c:2483 +#: src/sss_client/pam_sss.c:2701 msgid "Reenter new Password: " msgstr "" -#: src/sss_client/pam_sss.c:2676 src/sss_client/pam_sss.c:2679 +#: src/sss_client/pam_sss.c:2890 +msgid "Press ENTER to continue." +msgstr "" + +#: src/sss_client/pam_sss.c:2913 src/sss_client/pam_sss.c:2916 msgid "First Factor: " msgstr "" -#: src/sss_client/pam_sss.c:2677 src/sss_client/pam_sss.c:2851 +#: src/sss_client/pam_sss.c:2914 src/sss_client/pam_sss.c:3088 msgid "Second Factor (optional): " msgstr "" -#: src/sss_client/pam_sss.c:2680 src/sss_client/pam_sss.c:2855 +#: src/sss_client/pam_sss.c:2917 src/sss_client/pam_sss.c:3092 msgid "Second Factor: " msgstr "" -#: src/sss_client/pam_sss.c:2684 +#: src/sss_client/pam_sss.c:2921 msgid "Insert your passkey device, then press ENTER." msgstr "" -#: src/sss_client/pam_sss.c:2688 src/sss_client/pam_sss.c:2696 +#: src/sss_client/pam_sss.c:2925 src/sss_client/pam_sss.c:2933 msgid "Password: " msgstr "Salasana: " -#: src/sss_client/pam_sss.c:2850 src/sss_client/pam_sss.c:2854 +#: src/sss_client/pam_sss.c:3087 src/sss_client/pam_sss.c:3091 msgid "First Factor (Current Password): " msgstr "" -#: src/sss_client/pam_sss.c:2874 +#: src/sss_client/pam_sss.c:3111 msgid "Current Password: " msgstr "Nykyinen salasana: " -#: src/sss_client/pam_sss.c:3248 +#: src/sss_client/pam_sss.c:3485 msgid "Password expired. Change your password now." msgstr "" @@ -2555,9 +2598,9 @@ msgstr "Objektin tulostus epäonnistui: %s\n" #: src/tools/sssctl/sssctl_cache.c:835 src/tools/sssctl/sssctl_cache.c:918 #: src/tools/sssctl/sssctl_cache.c:950 src/tools/sssctl/sssctl_cache.c:956 #: src/tools/sssctl/sssctl_cache.c:1010 src/tools/sssctl/sssctl_cache.c:1034 -#: src/tools/sssctl/sssctl_cache.c:1085 src/tools/sssctl/sssctl_cache.c:1194 -#: src/tools/sssctl/sssctl_cache.c:1229 src/tools/sssctl/sssctl_cache.c:1235 -#: src/tools/sssctl/sssctl_cache.c:1244 +#: src/tools/sssctl/sssctl_cache.c:1085 src/tools/sssctl/sssctl_cache.c:1195 +#: src/tools/sssctl/sssctl_cache.c:1230 src/tools/sssctl/sssctl_cache.c:1236 +#: src/tools/sssctl/sssctl_cache.c:1245 msgid "talloc failed\n" msgstr "" @@ -2631,25 +2674,25 @@ msgstr "" msgid "Unable to remove downloaded GPO files: %s\n" msgstr "" -#: src/tools/sssctl/sssctl_cache.c:1165 +#: src/tools/sssctl/sssctl_cache.c:1166 #, c-format msgid "Failed to fetch cache entry: %s\n" msgstr "Välimuistimerkinnän nouto epäonnistui: %s\n" -#: src/tools/sssctl/sssctl_cache.c:1170 +#: src/tools/sssctl/sssctl_cache.c:1171 msgid "Could not determine object domain\n" msgstr "" -#: src/tools/sssctl/sssctl_cache.c:1200 +#: src/tools/sssctl/sssctl_cache.c:1201 msgid "Could not find GUID attribute in GPO entry\n" msgstr "" -#: src/tools/sssctl/sssctl_cache.c:1206 +#: src/tools/sssctl/sssctl_cache.c:1207 #, c-format msgid "Failed to delete GPO: %s\n" msgstr "GPO:n poistaminen epäonnistui: %s\n" -#: src/tools/sssctl/sssctl_cache.c:1210 +#: src/tools/sssctl/sssctl_cache.c:1211 #, c-format msgid "%s removed from cache\n" msgstr "" @@ -2737,39 +2780,40 @@ msgid "" "\"/my/path/sssd.conf\", the snippet dir \"/my/path/conf.d\" is used)" msgstr "" -#: src/tools/sssctl/sssctl_config.c:114 +#: src/tools/sssctl/sssctl_config.c:126 #, c-format msgid "File %1$s does not exist.\n" msgstr "Tiedostoa %1$s ei ole olemassa.\n" -#: src/tools/sssctl/sssctl_config.c:115 +#: src/tools/sssctl/sssctl_config.c:127 msgid "There is no configuration.\n" msgstr "" -#: src/tools/sssctl/sssctl_config.c:120 +#: src/tools/sssctl/sssctl_config.c:132 #, c-format msgid "Configuration validation failed: %s\n" msgstr "" -#: src/tools/sssctl/sssctl_config.c:121 +#: src/tools/sssctl/sssctl_config.c:133 msgid "Run with high debug level to see details.\n" msgstr "" -#: src/tools/sssctl/sssctl_config.c:130 -msgid "Failed to run validators" -msgstr "" +#: src/tools/sssctl/sssctl_config.c:142 +#, fuzzy +msgid "Failed to run validators\n" +msgstr "Objektin tulostus epäonnistui: %s\n" -#: src/tools/sssctl/sssctl_config.c:134 +#: src/tools/sssctl/sssctl_config.c:146 #, c-format msgid "Issues identified by validators: %zu\n" msgstr "" -#: src/tools/sssctl/sssctl_config.c:145 +#: src/tools/sssctl/sssctl_config.c:157 #, c-format msgid "Messages generated during configuration merging: %zu\n" msgstr "" -#: src/tools/sssctl/sssctl_config.c:158 +#: src/tools/sssctl/sssctl_config.c:170 #, c-format msgid "Used configuration snippet files: %zu\n" msgstr "" diff --git a/po/fr.po b/po/fr.po index 4f36b648661..68fd29f87c3 100644 --- a/po/fr.po +++ b/po/fr.po @@ -15,12 +15,13 @@ # Transtats , 2022, 2026. # grimst , 2023, 2026. # Léane GRASSER , 2024, 2025, 2026. +# Mattia Sasselli , 2026. msgid "" msgstr "" "Project-Id-Version: PACKAGE VERSION\n" "Report-Msgid-Bugs-To: sssd-devel@lists.fedorahosted.org\n" -"POT-Creation-Date: 2026-01-14 14:57+0000\n" -"PO-Revision-Date: 2026-04-23 17:00+0000\n" +"POT-Creation-Date: 2026-10-02 15:57+0000\n" +"PO-Revision-Date: 2026-10-05 16:38+0000\n" "Last-Translator: Jean-Baptiste Holcroft \n" "Language-Team: French \n" @@ -29,55 +30,55 @@ msgstr "" "Content-Type: text/plain; charset=UTF-8\n" "Content-Transfer-Encoding: 8bit\n" "Plural-Forms: nplurals=2; plural=n > 1;\n" -"X-Generator: Weblate 5.17\n" +"X-Generator: Weblate 2026.10\n" -#: src/config/SSSDConfig/sssdoptions.py:20 -#: src/config/SSSDConfig/sssdoptions.py:21 +#: src/config/SSSDConfig/sssdoptions.py:16 +#: src/config/SSSDConfig/sssdoptions.py:17 msgid "Set the verbosity of the debug logging" msgstr "Définir le niveau de détails de la sortie de débogage" -#: src/config/SSSDConfig/sssdoptions.py:22 +#: src/config/SSSDConfig/sssdoptions.py:18 msgid "Include timestamps in debug logs" msgstr "Ajouter l'horodatage dans les fichiers de débogage" -#: src/config/SSSDConfig/sssdoptions.py:23 +#: src/config/SSSDConfig/sssdoptions.py:19 msgid "Include microseconds in timestamps in debug logs" msgstr "" "Ajouter les microsecondes pour l'horodatage dans les journaux de débogage" -#: src/config/SSSDConfig/sssdoptions.py:24 +#: src/config/SSSDConfig/sssdoptions.py:20 msgid "Enable/disable debug backtrace" msgstr "Activer/Désactiver Backtrace débogage" -#: src/config/SSSDConfig/sssdoptions.py:25 +#: src/config/SSSDConfig/sssdoptions.py:21 msgid "Watchdog timeout before restarting service" msgstr "Délai de surveillance avant le redémarrage du service" -#: src/config/SSSDConfig/sssdoptions.py:26 +#: src/config/SSSDConfig/sssdoptions.py:22 msgid "Command to start service" msgstr "Commande pour démarrer le service" -#: src/config/SSSDConfig/sssdoptions.py:27 +#: src/config/SSSDConfig/sssdoptions.py:23 msgid "The number of file descriptors that may be opened by this responder" msgstr "" "Le nombre de descripteurs de fichiers qui peuvent être ouverts par ce " "répondeur" -#: src/config/SSSDConfig/sssdoptions.py:28 +#: src/config/SSSDConfig/sssdoptions.py:24 msgid "Idle time before automatic disconnection of a client" msgstr "durée d'inactivité avant la déconnexion automatique d'un client" -#: src/config/SSSDConfig/sssdoptions.py:29 +#: src/config/SSSDConfig/sssdoptions.py:25 msgid "Idle time before automatic shutdown of the responder" msgstr "Temps d'inactivité avant l'arrêt automatique du répondeur" -#: src/config/SSSDConfig/sssdoptions.py:30 +#: src/config/SSSDConfig/sssdoptions.py:26 msgid "Always query all the caches before querying the Data Providers" msgstr "" "Interrogez toujours tous les caches avant d'interroger les fournisseurs de " "données" -#: src/config/SSSDConfig/sssdoptions.py:31 +#: src/config/SSSDConfig/sssdoptions.py:27 msgid "" "When SSSD switches to offline mode the amount of time before it tries to go " "back online will increase based upon the time spent disconnected. This value " @@ -89,23 +90,23 @@ msgstr "" "Cette valeur est exprimée en secondes et calculée comme suit : " "offline_timeout + random_offset." -#: src/config/SSSDConfig/sssdoptions.py:36 +#: src/config/SSSDConfig/sssdoptions.py:32 msgid "SSSD Services to start" msgstr "Services SSSD à démarrer" -#: src/config/SSSDConfig/sssdoptions.py:37 +#: src/config/SSSDConfig/sssdoptions.py:33 msgid "SSSD Domains to start" msgstr "Domaines SSSD à démarrer" -#: src/config/SSSDConfig/sssdoptions.py:38 +#: src/config/SSSDConfig/sssdoptions.py:34 msgid "Regex to parse username and domain" msgstr "Expression rationnelle d'analyse des noms d'utilisateur et de domaine" -#: src/config/SSSDConfig/sssdoptions.py:39 +#: src/config/SSSDConfig/sssdoptions.py:35 msgid "Printf-compatible format for displaying fully-qualified names" msgstr "Format compatible printf d'affichage des noms complétement qualifiés" -#: src/config/SSSDConfig/sssdoptions.py:40 +#: src/config/SSSDConfig/sssdoptions.py:36 msgid "" "Directory on the filesystem where SSSD should store Kerberos replay cache " "files." @@ -113,45 +114,45 @@ msgstr "" "Répertoire du système de fichiers où SSSD doit stocker les fichiers de " "relecture de Kerberos." -#: src/config/SSSDConfig/sssdoptions.py:41 +#: src/config/SSSDConfig/sssdoptions.py:37 msgid "Domain to add to names without a domain component." msgstr "Domaine à ajouter aux noms sans composant de nom de domaine." -#: src/config/SSSDConfig/sssdoptions.py:42 +#: src/config/SSSDConfig/sssdoptions.py:38 msgid "The user to drop privileges to" msgstr "L'utilisation vers lequel abandonner les privilèges" -#: src/config/SSSDConfig/sssdoptions.py:43 +#: src/config/SSSDConfig/sssdoptions.py:39 msgid "Tune certificate verification" msgstr "Régler la vérification du certificat" -#: src/config/SSSDConfig/sssdoptions.py:44 +#: src/config/SSSDConfig/sssdoptions.py:40 msgid "All spaces in group or user names will be replaced with this character" msgstr "" "Tous les espaces dans les noms de groupes ou d'utilisateurs seront remplacés " "par ce caractère" -#: src/config/SSSDConfig/sssdoptions.py:45 +#: src/config/SSSDConfig/sssdoptions.py:41 msgid "Tune sssd to honor or ignore netlink state changes" msgstr "Régler sssd pour honorer ou ignorer les changements d'état du netlink" -#: src/config/SSSDConfig/sssdoptions.py:46 +#: src/config/SSSDConfig/sssdoptions.py:42 msgid "Enable or disable the implicit files domain" msgstr "Activer ou désactiver le domaine des fichiers implicites" -#: src/config/SSSDConfig/sssdoptions.py:47 +#: src/config/SSSDConfig/sssdoptions.py:43 msgid "A specific order of the domains to be looked up" msgstr "Un ordre spécifique des domaines à rechercher" -#: src/config/SSSDConfig/sssdoptions.py:48 +#: src/config/SSSDConfig/sssdoptions.py:44 msgid "" "Controls if SSSD should monitor the state of resolv.conf to identify when it " "needs to update its internal DNS resolver." msgstr "" -"Contrôle si le SSSD doit surveiller l'état de resolv.conf pour identifier " -"quand il doit mettre à jour son résolveur DNS interne." +"Contrôle si SSSD doit surveiller l'état de resolv.conf pour identifier quand " +"il doit mettre à jour son résolveur DNS interne." -#: src/config/SSSDConfig/sssdoptions.py:50 +#: src/config/SSSDConfig/sssdoptions.py:46 msgid "" "SSSD monitors the state of resolv.conf to identify when it needs to update " "its internal DNS resolver. By default, we will attempt to use inotify for " @@ -163,79 +164,79 @@ msgstr "" "d'utiliser inotify pour cela, et par défaut, resolv.conf sera interrogé " "toutes les cinq secondes si inotify ne peut pas être utilisé." -#: src/config/SSSDConfig/sssdoptions.py:53 +#: src/config/SSSDConfig/sssdoptions.py:49 msgid "Run PAC responder automatically for AD and IPA provider" msgstr "Exécution automatique du répondeur PAC pour le fournisseur AD et IPA" -#: src/config/SSSDConfig/sssdoptions.py:54 +#: src/config/SSSDConfig/sssdoptions.py:50 msgid "Enable or disable core dumps for all SSSD processes." msgstr "" "Activer ou désactiver les vidages de noyau pour tous les processus SSSD." -#: src/config/SSSDConfig/sssdoptions.py:55 +#: src/config/SSSDConfig/sssdoptions.py:51 msgid "Tune passkey verification behavior" msgstr "Ajustez le comportement de la vérification de la clé de sécurité" -#: src/config/SSSDConfig/sssdoptions.py:58 +#: src/config/SSSDConfig/sssdoptions.py:54 msgid "Enumeration cache timeout length (seconds)" msgstr "Délai d'attente du cache d'énumération (en secondes)" -#: src/config/SSSDConfig/sssdoptions.py:59 +#: src/config/SSSDConfig/sssdoptions.py:55 msgid "Entry cache background update timeout length (seconds)" msgstr "" "Délai d'attente de mise à jour en arrière-plan de l'entrée de cache (en " "secondes)" -#: src/config/SSSDConfig/sssdoptions.py:60 -#: src/config/SSSDConfig/sssdoptions.py:125 +#: src/config/SSSDConfig/sssdoptions.py:56 +#: src/config/SSSDConfig/sssdoptions.py:124 msgid "Negative cache timeout length (seconds)" msgstr "Délai d'attente du cache négatif (en secondes)" -#: src/config/SSSDConfig/sssdoptions.py:61 +#: src/config/SSSDConfig/sssdoptions.py:57 msgid "Users that SSSD should explicitly ignore" msgstr "Utilisateurs que SSSD doit explicitement ignorer" -#: src/config/SSSDConfig/sssdoptions.py:62 +#: src/config/SSSDConfig/sssdoptions.py:58 msgid "Groups that SSSD should explicitly ignore" msgstr "Groupes que SSSD doit explicitement ignorer" -#: src/config/SSSDConfig/sssdoptions.py:63 +#: src/config/SSSDConfig/sssdoptions.py:59 msgid "Should filtered users appear in groups" msgstr "Les utilisateurs filtrés doivent-ils apparaître dans les groupes" -#: src/config/SSSDConfig/sssdoptions.py:64 +#: src/config/SSSDConfig/sssdoptions.py:60 msgid "The value of the password field the NSS provider should return" msgstr "Valeur du champ de mot de passe que le fournisseur NSS doit renvoyer" -#: src/config/SSSDConfig/sssdoptions.py:65 +#: src/config/SSSDConfig/sssdoptions.py:61 msgid "Override homedir value from the identity provider with this value" msgstr "" "Remplacer par cette valeur celle du répertoire personnel obtenu avec le " "fournisseur d'identité" -#: src/config/SSSDConfig/sssdoptions.py:66 +#: src/config/SSSDConfig/sssdoptions.py:62 msgid "" "Substitute empty homedir value from the identity provider with this value" msgstr "" "Substitution de la valeur homedir vide du fournisseur d'identité avec cette " "valeur" -#: src/config/SSSDConfig/sssdoptions.py:67 +#: src/config/SSSDConfig/sssdoptions.py:63 msgid "Override shell value from the identity provider with this value" msgstr "Écraser le shell donné par le fournisseur d'identité avec cette valeur" -#: src/config/SSSDConfig/sssdoptions.py:68 +#: src/config/SSSDConfig/sssdoptions.py:64 msgid "The list of shells users are allowed to log in with" msgstr "" "Liste des interpréteurs de commandes utilisateurs autorisés pour se connecter" -#: src/config/SSSDConfig/sssdoptions.py:69 +#: src/config/SSSDConfig/sssdoptions.py:65 msgid "" "The list of shells that will be vetoed, and replaced with the fallback shell" msgstr "" "Liste des interpréteurs de commandes bannis et remplacés par celui par défaut" -#: src/config/SSSDConfig/sssdoptions.py:70 +#: src/config/SSSDConfig/sssdoptions.py:66 msgid "" "If a shell stored in central directory is allowed but not available, use " "this fallback" @@ -243,15 +244,15 @@ msgstr "" "Si un interpréteur de commandes stocké dans l'annuaire central est autorisé " "mais indisponible, utiliser à défaut celui-ci" -#: src/config/SSSDConfig/sssdoptions.py:71 +#: src/config/SSSDConfig/sssdoptions.py:67 msgid "Shell to use if the provider does not list one" msgstr "Shell à utiliser si le fournisseur n'en propose aucun" -#: src/config/SSSDConfig/sssdoptions.py:72 +#: src/config/SSSDConfig/sssdoptions.py:68 msgid "How long will be in-memory cache records valid" msgstr "Durée de maintien en cache des enregistrements valides" -#: src/config/SSSDConfig/sssdoptions.py:74 +#: src/config/SSSDConfig/sssdoptions.py:70 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for passwd requests" @@ -259,7 +260,7 @@ msgstr "" "Taille (en mégaoctets) de la table de données allouée dans le cache en " "mémoire rapide pour les demandes de mots de passe" -#: src/config/SSSDConfig/sssdoptions.py:76 +#: src/config/SSSDConfig/sssdoptions.py:72 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for group requests" @@ -267,7 +268,7 @@ msgstr "" "Taille (en mégaoctets) de la table de données allouée dans le cache en " "mémoire rapide pour les requêtes de groupe" -#: src/config/SSSDConfig/sssdoptions.py:78 +#: src/config/SSSDConfig/sssdoptions.py:74 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for initgroups requests" @@ -275,7 +276,7 @@ msgstr "" "Taille (en mégaoctets) de la table de données allouée dans le cache en " "mémoire rapide pour les demandes d'initgroups" -#: src/config/SSSDConfig/sssdoptions.py:79 +#: src/config/SSSDConfig/sssdoptions.py:75 msgid "" "The value of this option will be used in the expansion of the " "override_homedir option if the template contains the format string %H." @@ -283,7 +284,7 @@ msgstr "" "La valeur de cette option sera utilisée dans l'extension de l'option " "override_homedir si le modèle contient la chaîne de format %H." -#: src/config/SSSDConfig/sssdoptions.py:81 +#: src/config/SSSDConfig/sssdoptions.py:77 msgid "" "Specifies time in seconds for which the list of subdomains will be " "considered valid." @@ -291,7 +292,7 @@ msgstr "" "Spécifie la durée en secondes pendant laquelle la liste de sous-domaines est " "jugée valide." -#: src/config/SSSDConfig/sssdoptions.py:83 +#: src/config/SSSDConfig/sssdoptions.py:79 msgid "" "The entry cache can be set to automatically update entries in the background " "if they are requested beyond a percentage of the entry_cache_timeout value " @@ -301,17 +302,17 @@ msgstr "" "entrées en arrière plan si la requête ne dépasse pas un pourcentage de la " "valeur de entry_cache_timeout pour le domaine." -#: src/config/SSSDConfig/sssdoptions.py:88 +#: src/config/SSSDConfig/sssdoptions.py:84 msgid "How long to allow cached logins between online logins (days)" msgstr "" "Délai pendant lequel les connexions utilisant le cache sont autorisées entre " "deux connexions en ligne (en jours)" -#: src/config/SSSDConfig/sssdoptions.py:89 +#: src/config/SSSDConfig/sssdoptions.py:85 msgid "How many failed logins attempts are allowed when offline" msgstr "Nombre d'échecs de connexions hors-ligne autorisés" -#: src/config/SSSDConfig/sssdoptions.py:91 +#: src/config/SSSDConfig/sssdoptions.py:87 msgid "" "How long (minutes) to deny login after offline_failed_login_attempts has " "been reached" @@ -319,96 +320,98 @@ msgstr "" "Durée d'interdiction de connexion après que offline_failed_login_attempts " "est atteint (en minutes)" -#: src/config/SSSDConfig/sssdoptions.py:92 +#: src/config/SSSDConfig/sssdoptions.py:88 msgid "What kind of messages are displayed to the user during authentication" msgstr "" "Quels types de messages sont affichés à l'utilisateur pendant " "l'authentification" -#: src/config/SSSDConfig/sssdoptions.py:93 +#: src/config/SSSDConfig/sssdoptions.py:89 msgid "Filter PAM responses sent to the pam_sss" msgstr "Filtrez les réponses PAM envoyées à l'adresse pam_sss" -#: src/config/SSSDConfig/sssdoptions.py:94 +#: src/config/SSSDConfig/sssdoptions.py:90 msgid "How many seconds to keep identity information cached for PAM requests" msgstr "" "Durée en secondes pendant laquelle les informations d'identité sont gardées " "en cache pour les requêtes PAM" -#: src/config/SSSDConfig/sssdoptions.py:95 +#: src/config/SSSDConfig/sssdoptions.py:91 msgid "How many days before password expiration a warning should be displayed" msgstr "" "Nombre de jours précédent l'expiration du mot de passe avant lesquels un " "avertissement doit être affiché" -#: src/config/SSSDConfig/sssdoptions.py:96 +#: src/config/SSSDConfig/sssdoptions.py:92 msgid "List of trusted uids or user's name" msgstr "Liste des uid ou noms d'utilisateurs dignes de confiance" -#: src/config/SSSDConfig/sssdoptions.py:97 +#: src/config/SSSDConfig/sssdoptions.py:93 msgid "List of domains accessible even for untrusted users." msgstr "" "Liste des domaines accessibles y compris par les utilisateurs non dignes de " "confiance." -#: src/config/SSSDConfig/sssdoptions.py:98 +#: src/config/SSSDConfig/sssdoptions.py:94 msgid "Message printed when user account is expired." msgstr "Message affiché lorsque le compte a expiré." -#: src/config/SSSDConfig/sssdoptions.py:99 +#: src/config/SSSDConfig/sssdoptions.py:95 msgid "Message printed when user account is locked." msgstr "Message affiché lorsque le compte a expiré." -#: src/config/SSSDConfig/sssdoptions.py:100 +#: src/config/SSSDConfig/sssdoptions.py:96 msgid "Allow certificate based/Smartcard authentication." msgstr "Autoriser l'authentification par certificat/carte à puce." -#: src/config/SSSDConfig/sssdoptions.py:101 +#: src/config/SSSDConfig/sssdoptions.py:97 msgid "Path to certificate database with PKCS#11 modules." msgstr "" "Chemin d'accès à la base de données des certificats des modules PKCS#11." -#: src/config/SSSDConfig/sssdoptions.py:102 +#: src/config/SSSDConfig/sssdoptions.py:98 msgid "Tune certificate verification for PAM authentication." msgstr "Régler la vérification du certificat d’authentification PAM." -#: src/config/SSSDConfig/sssdoptions.py:103 +#: src/config/SSSDConfig/sssdoptions.py:99 msgid "How many seconds will pam_sss wait for p11_child to finish" msgstr "Combien de secondes pam_sss attendra-t-il la fin de p11_child" -#: src/config/SSSDConfig/sssdoptions.py:104 +#: src/config/SSSDConfig/sssdoptions.py:100 msgid "Which PAM services are permitted to contact application domains" msgstr "" "Quels services PAM sont autorisés à contacter les domaines d'application" -#: src/config/SSSDConfig/sssdoptions.py:105 +#: src/config/SSSDConfig/sssdoptions.py:101 msgid "Allowed services for using smartcards" msgstr "Services autorisés pour l'utilisation de cartes à puce" -#: src/config/SSSDConfig/sssdoptions.py:106 +#: src/config/SSSDConfig/sssdoptions.py:102 msgid "Additional timeout to wait for a card if requested" msgstr "Délai d'attente supplémentaire pour l'obtention d'une carte si demandé" -#: src/config/SSSDConfig/sssdoptions.py:107 +#: src/config/SSSDConfig/sssdoptions.py:103 msgid "" "PKCS#11 URI to restrict the selection of devices for Smartcard authentication" msgstr "" "URI PKCS#11 pour limiter la sélection des périphériques pour " "l'authentification par carte à puce" -#: src/config/SSSDConfig/sssdoptions.py:108 +#: src/config/SSSDConfig/sssdoptions.py:104 msgid "When shall the PAM responder force an initgroups request" msgstr "Quand le répondeur de PAM doit-il forcer une demande d'initgroupes" -#: src/config/SSSDConfig/sssdoptions.py:109 +#: src/config/SSSDConfig/sssdoptions.py:105 msgid "List of PAM services that are allowed to authenticate with GSSAPI." -msgstr "Liste des services PAM qui sont autorisés à s'authentifier avec GSSAPI." +msgstr "" +"Liste des services PAM qui sont autorisés à s'authentifier avec GSSAPI." -#: src/config/SSSDConfig/sssdoptions.py:110 +#: src/config/SSSDConfig/sssdoptions.py:106 msgid "Whether to match authenticated UPN with target user" -msgstr "S'il faut faire correspondre l'UPN authentifié avec l'utilisateur cible" +msgstr "" +"S'il faut faire correspondre l'UPN authentifié avec l'utilisateur cible" -#: src/config/SSSDConfig/sssdoptions.py:111 +#: src/config/SSSDConfig/sssdoptions.py:107 msgid "" "List of pairs : that must be enforced " "for PAM access with GSSAPI authentication" @@ -416,33 +419,43 @@ msgstr "" "Liste des paires : qui doivent être " "appliquées pour l'accès PAM avec authentification GSSAPI" -#: src/config/SSSDConfig/sssdoptions.py:113 +#: src/config/SSSDConfig/sssdoptions.py:109 +#, fuzzy +msgid "" +"List of triples :: that assigns " +"additional information from the Kerberos ticket to an authentication " +"indicator." +msgstr "" +"Liste des paires : qui doivent être " +"appliquées pour l'accès PAM avec authentification GSSAPI" + +#: src/config/SSSDConfig/sssdoptions.py:112 msgid "Allow passkey device authentication." msgstr "Autoriser l'authentification des périphériques par mot de passe." -#: src/config/SSSDConfig/sssdoptions.py:114 +#: src/config/SSSDConfig/sssdoptions.py:113 msgid "How many seconds will pam_sss wait for passkey_child to finish" msgstr "" "Durée en secondes pendant laquelle pam_sss attendra la fin de passkey_child" -#: src/config/SSSDConfig/sssdoptions.py:115 +#: src/config/SSSDConfig/sssdoptions.py:114 msgid "Enable debugging in the libfido2 library" msgstr "Activer le débogage dans la bibliothèque libfido2" -#: src/config/SSSDConfig/sssdoptions.py:116 +#: src/config/SSSDConfig/sssdoptions.py:115 msgid "Enable JSON protocol for authentication methods selection." msgstr "" "Activer le protocole JSON pour la sélection de méthodes d'authentification." -#: src/config/SSSDConfig/sssdoptions.py:119 +#: src/config/SSSDConfig/sssdoptions.py:118 msgid "Whether to evaluate the time-based attributes in sudo rules" msgstr "Faut-il évaluer les attributs dépendants du temps dans les règles sudo" -#: src/config/SSSDConfig/sssdoptions.py:120 +#: src/config/SSSDConfig/sssdoptions.py:119 msgid "If true, SSSD will switch back to lower-wins ordering logic" msgstr "Si sur true, SSSD repasse en logique de commande à faible gain" -#: src/config/SSSDConfig/sssdoptions.py:121 +#: src/config/SSSDConfig/sssdoptions.py:120 msgid "" "Maximum number of rules that can be refreshed at once. If this is exceeded, " "full refresh is performed." @@ -450,12 +463,12 @@ msgstr "" "Nombre maximum de règles pouvant être rafraîchies en même temps. En cas de " "dépassement, un rafraîchissement complet est effectué." -#: src/config/SSSDConfig/sssdoptions.py:128 +#: src/config/SSSDConfig/sssdoptions.py:127 msgid "Whether to hash host names and addresses in the known_hosts file" msgstr "" "Condenser ou non les noms de systèmes et adresses du fichier known_hosts" -#: src/config/SSSDConfig/sssdoptions.py:129 +#: src/config/SSSDConfig/sssdoptions.py:128 msgid "" "How many seconds to keep a host in the known_hosts file after its host keys " "were requested" @@ -463,15 +476,15 @@ msgstr "" "Le nombre de secondes pour garder un hôte dans le fichier known_hosts après " "que ses clés d'hôte ont été demandées" -#: src/config/SSSDConfig/sssdoptions.py:131 +#: src/config/SSSDConfig/sssdoptions.py:130 msgid "Path to storage of trusted CA certificates" msgstr "Chemin d'accès au stockage des certificats d'AC de confiance" -#: src/config/SSSDConfig/sssdoptions.py:132 +#: src/config/SSSDConfig/sssdoptions.py:131 msgid "Allow to generate ssh-keys from certificates" msgstr "Permet de générer des ssh-keys à partir de certificats" -#: src/config/SSSDConfig/sssdoptions.py:133 +#: src/config/SSSDConfig/sssdoptions.py:132 msgid "" "Use the following matching rules to filter the certificates for ssh-key " "generation" @@ -479,24 +492,24 @@ msgstr "" "Utilisez les règles de correspondance suivantes pour filtrer les certificats " "pour la génération de clés ssh" -#: src/config/SSSDConfig/sssdoptions.py:137 +#: src/config/SSSDConfig/sssdoptions.py:136 msgid "List of UIDs or user names allowed to access the PAC responder" msgstr "" "Listes des UID ou nom d'utilisateurs autorisés à accéder le répondeur PAC" -#: src/config/SSSDConfig/sssdoptions.py:138 +#: src/config/SSSDConfig/sssdoptions.py:137 msgid "How long the PAC data is considered valid" msgstr "Durée de validité des données du PAC" -#: src/config/SSSDConfig/sssdoptions.py:139 +#: src/config/SSSDConfig/sssdoptions.py:138 msgid "Validate the PAC" msgstr "Valider le PAC" -#: src/config/SSSDConfig/sssdoptions.py:142 +#: src/config/SSSDConfig/sssdoptions.py:141 msgid "List of user attributes the InfoPipe is allowed to publish" msgstr "Liste des attributs utilisateur que l'InfoPipe est autorisé à publier" -#: src/config/SSSDConfig/sssdoptions.py:145 +#: src/config/SSSDConfig/sssdoptions.py:144 msgid "" "One of the following strings specifying the scope of session recording: none " "- No users are recorded. some - Users/groups specified by users and groups " @@ -507,29 +520,29 @@ msgstr "" "groupes spécifiés par les options des utilisateurs et des groupes sont " "enregistrés. all - Tous les utilisateurs sont enregistrés." -#: src/config/SSSDConfig/sssdoptions.py:148 +#: src/config/SSSDConfig/sssdoptions.py:147 msgid "" "A comma-separated list of users which should have session recording enabled. " "Matches user names as returned by NSS. I.e. after the possible space " "replacement, case changes, etc." msgstr "" -"Une liste d'utilisateurs, séparés par des virgules, dont l'enregistrement de " -"session devrait être activé. Correspond aux noms d'utilisateurs renvoyés par " -"le NSS. C'est-à-dire après le remplacement éventuel de l'espace, les " -"changements de casse, etc." +"Liste d'utilisateurs, séparés par des virgules, pour lesquels " +"l'enregistrement de session doit être activé. Les noms d'utilisateur doivent " +"correspondre à ceux renvoyés par NSS, c'est-à-dire après les éventuelles " +"modifications d'espaces, de casse, etc." -#: src/config/SSSDConfig/sssdoptions.py:150 +#: src/config/SSSDConfig/sssdoptions.py:149 msgid "" "A comma-separated list of groups, members of which should have session " "recording enabled. Matches group names as returned by NSS. I.e. after the " "possible space replacement, case changes, etc." msgstr "" -"Une liste de groupes séparés par des virgules, dont les membres doivent " -"avoir l'enregistrement de session activé. Correspond aux noms des groupes " -"renvoyés par le NSS, c-à-d après le remplacement éventuel de l'espace, les " -"changements de cas, etc." +"Liste de groupes, séparés par des virgules, dont les membres doivent avoir " +"l'enregistrement de session activé. Les noms de groupes doivent correspondre " +"à ceux renvoyés par NSS, c'est-à-dire après les éventuelles modifications " +"d'espaces, de casse, etc." -#: src/config/SSSDConfig/sssdoptions.py:153 +#: src/config/SSSDConfig/sssdoptions.py:152 msgid "" "A comma-separated list of users to be excluded from recording, only when " "scope=all" @@ -537,7 +550,7 @@ msgstr "" "Une liste d'utilisateurs à exclure de l'enregistrement, séparés par des " "virgules, uniquement lorsque scope=all" -#: src/config/SSSDConfig/sssdoptions.py:154 +#: src/config/SSSDConfig/sssdoptions.py:153 msgid "" "A comma-separated list of groups, members of which should be excluded from " "recording, only when scope=all. " @@ -545,79 +558,79 @@ msgstr "" "Une liste de groupes séparés par des virgules, dont les membres doivent être " "exclus de l'enregistrement, uniquement lorsque scope=all. " -#: src/config/SSSDConfig/sssdoptions.py:158 +#: src/config/SSSDConfig/sssdoptions.py:157 msgid "Identity provider" msgstr "Fournisseur d'identité" -#: src/config/SSSDConfig/sssdoptions.py:159 +#: src/config/SSSDConfig/sssdoptions.py:158 msgid "Authentication provider" msgstr "Fournisseur d'authentification" -#: src/config/SSSDConfig/sssdoptions.py:160 +#: src/config/SSSDConfig/sssdoptions.py:159 msgid "Access control provider" msgstr "Fournisseur de contrôle d'accès" -#: src/config/SSSDConfig/sssdoptions.py:161 +#: src/config/SSSDConfig/sssdoptions.py:160 msgid "Password change provider" msgstr "Fournisseur de changement de mot de passe" -#: src/config/SSSDConfig/sssdoptions.py:162 +#: src/config/SSSDConfig/sssdoptions.py:161 msgid "SUDO provider" msgstr "Fournisseur SUDO" -#: src/config/SSSDConfig/sssdoptions.py:163 +#: src/config/SSSDConfig/sssdoptions.py:162 msgid "Autofs provider" msgstr "Fournisseur autofs" -#: src/config/SSSDConfig/sssdoptions.py:164 +#: src/config/SSSDConfig/sssdoptions.py:163 msgid "Host identity provider" msgstr "Fournisseur d'identité de l'hôte" -#: src/config/SSSDConfig/sssdoptions.py:165 +#: src/config/SSSDConfig/sssdoptions.py:164 msgid "SELinux provider" msgstr "Fournisseur SELinux" -#: src/config/SSSDConfig/sssdoptions.py:166 +#: src/config/SSSDConfig/sssdoptions.py:165 msgid "Session management provider" msgstr "Fournisseur de gestion de session" -#: src/config/SSSDConfig/sssdoptions.py:167 +#: src/config/SSSDConfig/sssdoptions.py:166 msgid "Resolver provider" msgstr "Fournisseur de résolveurs" -#: src/config/SSSDConfig/sssdoptions.py:170 +#: src/config/SSSDConfig/sssdoptions.py:169 msgid "Whether the domain is usable by the OS or by applications" msgstr "Si le domaine est utilisable par l'OS ou par des applications" -#: src/config/SSSDConfig/sssdoptions.py:171 +#: src/config/SSSDConfig/sssdoptions.py:170 msgid "Enable or disable the domain" msgstr "Activer ou désactiver le domaine" -#: src/config/SSSDConfig/sssdoptions.py:172 +#: src/config/SSSDConfig/sssdoptions.py:171 msgid "Minimum user ID" msgstr "Identifiant utilisateur minimum" -#: src/config/SSSDConfig/sssdoptions.py:173 +#: src/config/SSSDConfig/sssdoptions.py:172 msgid "Maximum user ID" msgstr "Identifiant utilisateur maximum" -#: src/config/SSSDConfig/sssdoptions.py:174 +#: src/config/SSSDConfig/sssdoptions.py:173 msgid "Enable enumerating all users/groups" msgstr "Activer l'énumération de tous les utilisateurs/groupes" -#: src/config/SSSDConfig/sssdoptions.py:175 +#: src/config/SSSDConfig/sssdoptions.py:174 msgid "Cache credentials for offline login" msgstr "Mettre en cache les crédits pour une connexion hors-ligne" -#: src/config/SSSDConfig/sssdoptions.py:176 +#: src/config/SSSDConfig/sssdoptions.py:175 msgid "Display users/groups in fully-qualified form" msgstr "Afficher les utilisateurs/groupes dans un format complétement qualifié" -#: src/config/SSSDConfig/sssdoptions.py:177 +#: src/config/SSSDConfig/sssdoptions.py:176 msgid "Don't include group members in group lookups" msgstr "Ne pas inclure les membres des groupes dans les recherches de groupes" -#: src/config/SSSDConfig/sssdoptions.py:178 +#: src/config/SSSDConfig/sssdoptions.py:177 #: src/config/SSSDConfig/sssdoptions.py:190 #: src/config/SSSDConfig/sssdoptions.py:191 #: src/config/SSSDConfig/sssdoptions.py:192 @@ -628,18 +641,18 @@ msgstr "Ne pas inclure les membres des groupes dans les recherches de groupes" msgid "Entry cache timeout length (seconds)" msgstr "Durée de validité des entrées en cache (en secondes)" -#: src/config/SSSDConfig/sssdoptions.py:179 +#: src/config/SSSDConfig/sssdoptions.py:178 msgid "" "Restrict or prefer a specific address family when performing DNS lookups" msgstr "Restreindre ou préférer une famille d'adresses lors des recherches DNS" -#: src/config/SSSDConfig/sssdoptions.py:180 +#: src/config/SSSDConfig/sssdoptions.py:179 msgid "How long to keep cached entries after last successful login (days)" msgstr "" "Durée de validité des entrées en cache après la dernière connexion réussie " "(en jours)" -#: src/config/SSSDConfig/sssdoptions.py:181 +#: src/config/SSSDConfig/sssdoptions.py:180 msgid "" "How long should SSSD talk to single DNS server before trying next server " "(miliseconds)" @@ -647,23 +660,23 @@ msgstr "" "Combien de temps le SSSD doit-il parler à un seul serveur DNS avant " "d'essayer le serveur suivant (en millisecondes)" -#: src/config/SSSDConfig/sssdoptions.py:183 +#: src/config/SSSDConfig/sssdoptions.py:182 msgid "How long should keep trying to resolve single DNS query (seconds)" msgstr "" "Combien de temps faut-il continuer à essayer de résoudre une seule requête " "DNS (en secondes)" -#: src/config/SSSDConfig/sssdoptions.py:184 +#: src/config/SSSDConfig/sssdoptions.py:183 msgid "How long to wait for replies from DNS when resolving servers (seconds)" msgstr "" "Délai d'attente des réponses du DNS lors de la résolution des serveurs (en " "secondes)" -#: src/config/SSSDConfig/sssdoptions.py:185 +#: src/config/SSSDConfig/sssdoptions.py:184 msgid "The domain part of service discovery DNS query" msgstr "La partie domaine de la requête de découverte de service DNS" -#: src/config/SSSDConfig/sssdoptions.py:186 +#: src/config/SSSDConfig/sssdoptions.py:185 msgid "" "Specifies the interval, in seconds, that SSSD waits before attempting to " "reconnect to the primary server after a successful connection to the backup " @@ -673,14 +686,18 @@ msgstr "" "d'essayer de se reconnecter au serveur principal après une connexion réussie " "au serveur de secours" -#: src/config/SSSDConfig/sssdoptions.py:188 +#: src/config/SSSDConfig/sssdoptions.py:187 msgid "Override GID value from the identity provider with this value" msgstr "Écraser la valeur du GID du fournisseur d'identité avec cette valeur" -#: src/config/SSSDConfig/sssdoptions.py:189 +#: src/config/SSSDConfig/sssdoptions.py:188 msgid "Treat usernames as case sensitive" msgstr "Considère les noms d'utilisateur comme casse dépendant" +#: src/config/SSSDConfig/sssdoptions.py:189 +msgid "Lookups by ID are expensive or do not work at all" +msgstr "" + #: src/config/SSSDConfig/sssdoptions.py:197 msgid "How often should expired entries be refreshed in background" msgstr "Fréquence de rafraîchissement en arrière plan des entrées expirées" @@ -820,11 +837,11 @@ msgid "" "this value determines the minimal length the first authentication factor " "(long term password) must have to be saved as SHA512 hash into the cache." msgstr "" -"Si l'authentification à 2 facteurs (2FA) est utilisée et que les " -"informations d'identification sont sauvegardées, cette valeur détermine la " -"longueur minimale à laquelle le premier facteur d'authentification (mot de " -"passe à long terme) doit être sauvegardé en tant que hachage SHA512 dans le " -"cache." +"Si l'authentification à deux facteurs (2FA) est utilisée et que les " +"informations d'identification doivent être enregistrées, cette valeur " +"détermine la longueur minimale que le premier facteur d'authentification " +"(mot de passe à long terme) doit avoir pour être enregistré sous forme de " +"hachage SHA512 dans le cache." #: src/config/SSSDConfig/sssdoptions.py:230 msgid "Local authentication methods policy " @@ -936,7 +953,7 @@ msgid "Search base for SUBID ranges" msgstr "Base de recherche pour les plages SUBID" #: src/config/SSSDConfig/sssdoptions.py:259 -#: src/config/SSSDConfig/sssdoptions.py:506 +#: src/config/SSSDConfig/sssdoptions.py:512 msgid "Which rules should be used to evaluate access control" msgstr "Quelles règles utiliser pour évaluer le contrôle d'accès" @@ -1048,7 +1065,8 @@ msgstr "" #: src/config/SSSDConfig/sssdoptions.py:287 msgid "The LDAP attribute that contains SELinux user string itself." -msgstr "L'attribut LDAP qui contient la chaîne d'utilisateur SELinux elle-même." +msgstr "" +"L'attribut LDAP qui contient la chaîne d'utilisateur SELinux elle-même." #: src/config/SSSDConfig/sssdoptions.py:288 msgid "The LDAP attribute that contains user category such as 'all'." @@ -1099,7 +1117,7 @@ msgid "Enable DNS sites - location based service discovery" msgstr "Activer les sites DNS - découverte de service basée sur l'emplacement" #: src/config/SSSDConfig/sssdoptions.py:301 -#: src/config/SSSDConfig/sssdoptions.py:504 +#: src/config/SSSDConfig/sssdoptions.py:510 msgid "LDAP filter to determine access privileges" msgstr "Filtre LDAP pour déterminer les autorisations d'accès" @@ -1123,37 +1141,37 @@ msgid "" "PAM service names that map to the GPO (Deny)InteractiveLogonRight policy " "settings" msgstr "" -"Nom des services PAM correspondant à la configuration de la stratégie (Deny)" -"InteractiveLogonRight de la GPO" +"Nom des services PAM correspondant à la configuration de la stratégie " +"(Deny)InteractiveLogonRight de la GPO" #: src/config/SSSDConfig/sssdoptions.py:307 msgid "" "PAM service names that map to the GPO (Deny)RemoteInteractiveLogonRight " "policy settings" msgstr "" -"Nom des services PAM correspondant à la configuration de la stratégie (Deny)" -"RemoteInteractiveLogonRight de la GPO" +"Nom des services PAM correspondant à la configuration de la stratégie " +"(Deny)RemoteInteractiveLogonRight de la GPO" #: src/config/SSSDConfig/sssdoptions.py:309 msgid "" "PAM service names that map to the GPO (Deny)NetworkLogonRight policy settings" msgstr "" -"Nom des services PAM correspondant à la configuration de la stratégie (Deny)" -"NetworkLogonRight de la GPO" +"Nom des services PAM correspondant à la configuration de la stratégie " +"(Deny)NetworkLogonRight de la GPO" #: src/config/SSSDConfig/sssdoptions.py:310 msgid "" "PAM service names that map to the GPO (Deny)BatchLogonRight policy settings" msgstr "" -"Nom des services PAM correspondant à la configuration de la stratégie (Deny)" -"BatchLogonRight de la GPO" +"Nom des services PAM correspondant à la configuration de la stratégie " +"(Deny)BatchLogonRight de la GPO" #: src/config/SSSDConfig/sssdoptions.py:311 msgid "" "PAM service names that map to the GPO (Deny)ServiceLogonRight policy settings" msgstr "" -"Nom des services PAM correspondant à la configuration de la stratégie (Deny)" -"ServiceLogonRight de la GPO" +"Nom des services PAM correspondant à la configuration de la stratégie " +"(Deny)ServiceLogonRight de la GPO" #: src/config/SSSDConfig/sssdoptions.py:312 msgid "PAM service names for which GPO-based access is always granted" @@ -1282,11 +1300,13 @@ msgstr "Active les principals d'entreprise" #: src/config/SSSDConfig/sssdoptions.py:346 msgid "Enables using of subdomains realms for authentication" -msgstr "Permet d'utiliser les domaines de sous-domaines pour l'authentification" +msgstr "" +"Permet d'utiliser les domaines de sous-domaines pour l'authentification" #: src/config/SSSDConfig/sssdoptions.py:347 msgid "A mapping from user names to Kerberos principal names" -msgstr "Un mappage des noms d'utilisateurs vers les noms de principaux Kerberos" +msgstr "" +"Un mappage des noms d'utilisateurs vers les noms de principaux Kerberos" #: src/config/SSSDConfig/sssdoptions.py:350 #: src/config/SSSDConfig/sssdoptions.py:351 @@ -1558,7 +1578,7 @@ msgid "UUID attribute" msgstr "attribut UUID" #: src/config/SSSDConfig/sssdoptions.py:423 -#: src/config/SSSDConfig/sssdoptions.py:464 +#: src/config/SSSDConfig/sssdoptions.py:470 msgid "objectSID attribute" msgstr "attribut objectSID" @@ -1686,180 +1706,209 @@ msgstr "" "Une liste des attributs supplémentaires à télécharger avec l'entrée de " "l'utilisateur" +#: src/config/SSSDConfig/sssdoptions.py:456 +#, fuzzy +msgid "The object class of an subid entry in LDAP." +msgstr "La classe d'objet d'une entrée utilisateur dans LDAP." + #: src/config/SSSDConfig/sssdoptions.py:457 +#, fuzzy +msgid "Subordinate user ID count attribute" +msgstr "Attribut utilisateur de la règle sudo" + +#: src/config/SSSDConfig/sssdoptions.py:458 +#, fuzzy +msgid "Subordinate group ID count attribute" +msgstr "Attribut option de la règle sudo" + +#: src/config/SSSDConfig/sssdoptions.py:459 +#, fuzzy +msgid "User ID range start value attribute" +msgstr "Attribut de nom d'utilisateur" + +#: src/config/SSSDConfig/sssdoptions.py:460 +#, fuzzy +msgid "Group ID range start value attribute" +msgstr "attribut de l'UUID du groupe" + +#: src/config/SSSDConfig/sssdoptions.py:461 +msgid "Owner of an entry" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:463 msgid "Base DN for group lookups" msgstr "DN de base pour les recherches de groupes" -#: src/config/SSSDConfig/sssdoptions.py:458 +#: src/config/SSSDConfig/sssdoptions.py:464 msgid "Objectclass for groups" msgstr "Classe d'objet pour les groupes" -#: src/config/SSSDConfig/sssdoptions.py:459 +#: src/config/SSSDConfig/sssdoptions.py:465 msgid "Group name" msgstr "Nom du groupe" -#: src/config/SSSDConfig/sssdoptions.py:460 +#: src/config/SSSDConfig/sssdoptions.py:466 msgid "Group password" msgstr "Mot de passe du groupe" -#: src/config/SSSDConfig/sssdoptions.py:461 +#: src/config/SSSDConfig/sssdoptions.py:467 msgid "GID attribute" msgstr "Attribut GID" -#: src/config/SSSDConfig/sssdoptions.py:462 +#: src/config/SSSDConfig/sssdoptions.py:468 msgid "Group member attribute" msgstr "Attribut membre du groupe" -#: src/config/SSSDConfig/sssdoptions.py:463 +#: src/config/SSSDConfig/sssdoptions.py:469 msgid "Group UUID attribute" msgstr "attribut de l'UUID du groupe" -#: src/config/SSSDConfig/sssdoptions.py:465 +#: src/config/SSSDConfig/sssdoptions.py:471 msgid "Modification time attribute for groups" msgstr "Attribut de date de modification pour les groupes" -#: src/config/SSSDConfig/sssdoptions.py:466 +#: src/config/SSSDConfig/sssdoptions.py:472 msgid "Type of the group and other flags" msgstr "Type de groupe et autres indicateurs" -#: src/config/SSSDConfig/sssdoptions.py:467 +#: src/config/SSSDConfig/sssdoptions.py:473 msgid "The LDAP group external member attribute" msgstr "L'attribut de membre externe du groupe LDAP" -#: src/config/SSSDConfig/sssdoptions.py:468 +#: src/config/SSSDConfig/sssdoptions.py:474 msgid "Maximum nesting level SSSD will follow" msgstr "Le niveau d'imbrication maximal du SSSD suivra" -#: src/config/SSSDConfig/sssdoptions.py:469 +#: src/config/SSSDConfig/sssdoptions.py:475 msgid "Filter for group lookups" msgstr "Filtre pour les recherches de groupes" -#: src/config/SSSDConfig/sssdoptions.py:470 +#: src/config/SSSDConfig/sssdoptions.py:476 msgid "Scope of group lookups" msgstr "Portée des recherches de groupe" -#: src/config/SSSDConfig/sssdoptions.py:472 +#: src/config/SSSDConfig/sssdoptions.py:478 msgid "Base DN for netgroup lookups" msgstr "DN de base pour les recherches de netgroup" -#: src/config/SSSDConfig/sssdoptions.py:473 +#: src/config/SSSDConfig/sssdoptions.py:479 msgid "Objectclass for netgroups" msgstr "Classe d'objet pour les groupes réseau" -#: src/config/SSSDConfig/sssdoptions.py:474 +#: src/config/SSSDConfig/sssdoptions.py:480 msgid "Netgroup name" msgstr "Nom du groupe réseau" -#: src/config/SSSDConfig/sssdoptions.py:475 +#: src/config/SSSDConfig/sssdoptions.py:481 msgid "Netgroups members attribute" msgstr "Attribut des membres des groupes réseau" -#: src/config/SSSDConfig/sssdoptions.py:476 +#: src/config/SSSDConfig/sssdoptions.py:482 msgid "Netgroup triple attribute" msgstr "Attribut triplet du groupe réseau" -#: src/config/SSSDConfig/sssdoptions.py:477 +#: src/config/SSSDConfig/sssdoptions.py:483 msgid "Modification time attribute for netgroups" msgstr "Attribut date de modification pour les groupes réseau" -#: src/config/SSSDConfig/sssdoptions.py:479 +#: src/config/SSSDConfig/sssdoptions.py:485 msgid "Base DN for service lookups" msgstr "Nom de domaine (DN) de base pour les recherches de service" -#: src/config/SSSDConfig/sssdoptions.py:480 +#: src/config/SSSDConfig/sssdoptions.py:486 msgid "Objectclass for services" msgstr "Classe objet pour les services" -#: src/config/SSSDConfig/sssdoptions.py:481 +#: src/config/SSSDConfig/sssdoptions.py:487 msgid "Service name attribute" msgstr "Attribut de nom de service" -#: src/config/SSSDConfig/sssdoptions.py:482 +#: src/config/SSSDConfig/sssdoptions.py:488 msgid "Service port attribute" msgstr "Attribut de port du service" -#: src/config/SSSDConfig/sssdoptions.py:483 +#: src/config/SSSDConfig/sssdoptions.py:489 msgid "Service protocol attribute" msgstr "Attribut de service du protocole" -#: src/config/SSSDConfig/sssdoptions.py:485 +#: src/config/SSSDConfig/sssdoptions.py:491 msgid "Lower bound for ID-mapping" msgstr "Limite inférieure pour la correspondance d'ID" -#: src/config/SSSDConfig/sssdoptions.py:486 +#: src/config/SSSDConfig/sssdoptions.py:492 msgid "Upper bound for ID-mapping" msgstr "Limite supérieure pour la correspondance d'ID" -#: src/config/SSSDConfig/sssdoptions.py:487 +#: src/config/SSSDConfig/sssdoptions.py:493 msgid "Number of IDs for each slice when ID-mapping" msgstr "Nombre d'ID par tranche pour la correspondance d'ID" -#: src/config/SSSDConfig/sssdoptions.py:488 +#: src/config/SSSDConfig/sssdoptions.py:494 msgid "Use autorid-compatible algorithm for ID-mapping" msgstr "" "Utilisation d'un algorithme compatible autorid pour la correspondance d'ID" -#: src/config/SSSDConfig/sssdoptions.py:489 +#: src/config/SSSDConfig/sssdoptions.py:495 msgid "Name of the default domain for ID-mapping" msgstr "Nom du domaine par défaut pour la correspondance d'ID" -#: src/config/SSSDConfig/sssdoptions.py:490 +#: src/config/SSSDConfig/sssdoptions.py:496 msgid "SID of the default domain for ID-mapping" msgstr "SID du domaine par défaut pour la correspondance d'ID" -#: src/config/SSSDConfig/sssdoptions.py:491 +#: src/config/SSSDConfig/sssdoptions.py:497 msgid "Number of secondary slices" msgstr "Nombre de tranches secondaires" -#: src/config/SSSDConfig/sssdoptions.py:493 +#: src/config/SSSDConfig/sssdoptions.py:499 msgid "Whether to use Token-Groups" msgstr "Choisir d'utiliser ou non les groupes de jetons" -#: src/config/SSSDConfig/sssdoptions.py:494 +#: src/config/SSSDConfig/sssdoptions.py:500 msgid "Set lower boundary for allowed IDs from the LDAP server" msgstr "" "Définir la limite inférieure d'identifiants autorisés pour l'annuaire LDAP" -#: src/config/SSSDConfig/sssdoptions.py:495 +#: src/config/SSSDConfig/sssdoptions.py:501 msgid "Set upper boundary for allowed IDs from the LDAP server" msgstr "" "Définir la limite supérieure d'identifiants autorisés pour l'annuaire LDAP" -#: src/config/SSSDConfig/sssdoptions.py:496 +#: src/config/SSSDConfig/sssdoptions.py:502 msgid "DN for ppolicy queries" msgstr "DN pour les requêtes ppolicy" -#: src/config/SSSDConfig/sssdoptions.py:497 +#: src/config/SSSDConfig/sssdoptions.py:503 msgid "How many maximum entries to fetch during a wildcard request" msgstr "Combien d'entrées maximum à récupérer lors d'une demande de wildcard" -#: src/config/SSSDConfig/sssdoptions.py:498 +#: src/config/SSSDConfig/sssdoptions.py:504 msgid "Set libldap debug level" msgstr "Définir le niveau de débogage de libldap" -#: src/config/SSSDConfig/sssdoptions.py:501 +#: src/config/SSSDConfig/sssdoptions.py:507 msgid "Policy to evaluate the password expiration" msgstr "Stratégie d'évaluation de l'expiration du mot de passe" -#: src/config/SSSDConfig/sssdoptions.py:505 +#: src/config/SSSDConfig/sssdoptions.py:511 msgid "Which attributes shall be used to evaluate if an account is expired" msgstr "Quels attributs utiliser pour déterminer si un compte a expiré" -#: src/config/SSSDConfig/sssdoptions.py:509 +#: src/config/SSSDConfig/sssdoptions.py:515 msgid "URI of an LDAP server where password changes are allowed" msgstr "URI d'un serveur LDAP où les changements de mot de passe sont acceptés" -#: src/config/SSSDConfig/sssdoptions.py:510 +#: src/config/SSSDConfig/sssdoptions.py:516 msgid "URI of a backup LDAP server where password changes are allowed" msgstr "" "URI d'un serveur LDAP de secours où sont autorisées les modifications de mot " "de passe" -#: src/config/SSSDConfig/sssdoptions.py:511 +#: src/config/SSSDConfig/sssdoptions.py:517 msgid "DNS service name for LDAP password change server" msgstr "Nom du service DNS pour le serveur de changement de mot de passe LDAP" -#: src/config/SSSDConfig/sssdoptions.py:512 +#: src/config/SSSDConfig/sssdoptions.py:518 msgid "" "Whether to update the ldap_user_shadow_last_change attribute after a " "password change" @@ -1867,27 +1916,27 @@ msgstr "" "Choix de mise à jour de l'attribut ldap_user_shadow_last_change après un " "changement de mot de passe" -#: src/config/SSSDConfig/sssdoptions.py:516 +#: src/config/SSSDConfig/sssdoptions.py:522 msgid "Base DN for sudo rules lookups" msgstr "Nom de domaine (DN) de base pour les recherches de règles sudo" -#: src/config/SSSDConfig/sssdoptions.py:517 +#: src/config/SSSDConfig/sssdoptions.py:523 msgid "Automatic full refresh period" msgstr "Périodicité de rafraichissement total" -#: src/config/SSSDConfig/sssdoptions.py:518 +#: src/config/SSSDConfig/sssdoptions.py:524 msgid "Automatic smart refresh period" msgstr "Périodicité de rafraichissement intelligent" -#: src/config/SSSDConfig/sssdoptions.py:519 +#: src/config/SSSDConfig/sssdoptions.py:525 msgid "Smart and full refresh random offset" msgstr "Décalage aléatoire Smart ou de Rafraîchissement total" -#: src/config/SSSDConfig/sssdoptions.py:520 +#: src/config/SSSDConfig/sssdoptions.py:526 msgid "Whether to filter rules by hostname, IP addresses and network" msgstr "Filter ou non sur les noms de systèmes, adresses IP et réseaux" -#: src/config/SSSDConfig/sssdoptions.py:521 +#: src/config/SSSDConfig/sssdoptions.py:527 msgid "" "Hostnames and/or fully qualified domain names of this machine to filter sudo " "rules" @@ -1895,154 +1944,154 @@ msgstr "" "Noms de systèmes et/ou noms pleinement qualifiés de cette machine pour " "filtrer les règles sudo" -#: src/config/SSSDConfig/sssdoptions.py:522 +#: src/config/SSSDConfig/sssdoptions.py:528 msgid "IPv4 or IPv6 addresses or network of this machine to filter sudo rules" msgstr "" "Adresses ou réseaux IPv4 ou IPv6 de cette machine pour filtrer les règles " "sudo" -#: src/config/SSSDConfig/sssdoptions.py:523 +#: src/config/SSSDConfig/sssdoptions.py:529 msgid "Whether to include rules that contains netgroup in host attribute" msgstr "" "Inclure ou non les règles qui contiennent un netgroup dans l'attribut host" -#: src/config/SSSDConfig/sssdoptions.py:524 +#: src/config/SSSDConfig/sssdoptions.py:530 msgid "" "Whether to include rules that contains regular expression in host attribute" msgstr "" "Inclure ou non les règles qui contiennent une expression rationnelle dans " "l'attribut host" -#: src/config/SSSDConfig/sssdoptions.py:525 +#: src/config/SSSDConfig/sssdoptions.py:531 msgid "Object class for sudo rules" msgstr "Classe objet pour les règles sudo" -#: src/config/SSSDConfig/sssdoptions.py:526 +#: src/config/SSSDConfig/sssdoptions.py:532 msgid "Name of attribute that is used as object class for sudo rules" msgstr "" "Nom de l'attribut qui est utilisé comme classe d'objet pour les règles sudo" -#: src/config/SSSDConfig/sssdoptions.py:527 +#: src/config/SSSDConfig/sssdoptions.py:533 msgid "Sudo rule name" msgstr "Règle de nom sudo" -#: src/config/SSSDConfig/sssdoptions.py:528 +#: src/config/SSSDConfig/sssdoptions.py:534 msgid "Sudo rule command attribute" msgstr "Attribut de commande de règle sudo" -#: src/config/SSSDConfig/sssdoptions.py:529 +#: src/config/SSSDConfig/sssdoptions.py:535 msgid "Sudo rule host attribute" msgstr "Attribut hôte de la règle sudo" -#: src/config/SSSDConfig/sssdoptions.py:530 +#: src/config/SSSDConfig/sssdoptions.py:536 msgid "Sudo rule user attribute" msgstr "Attribut utilisateur de la règle sudo" -#: src/config/SSSDConfig/sssdoptions.py:531 +#: src/config/SSSDConfig/sssdoptions.py:537 msgid "Sudo rule option attribute" msgstr "Attribut option de la règle sudo" -#: src/config/SSSDConfig/sssdoptions.py:532 +#: src/config/SSSDConfig/sssdoptions.py:538 msgid "Sudo rule runas attribute" msgstr "Attribut de règle sudo runas" -#: src/config/SSSDConfig/sssdoptions.py:533 +#: src/config/SSSDConfig/sssdoptions.py:539 msgid "Sudo rule runasuser attribute" msgstr "Attribut runasuser de la règle sudo" -#: src/config/SSSDConfig/sssdoptions.py:534 +#: src/config/SSSDConfig/sssdoptions.py:540 msgid "Sudo rule runasgroup attribute" msgstr "Attribut runasgroup de la règle sudo" -#: src/config/SSSDConfig/sssdoptions.py:535 +#: src/config/SSSDConfig/sssdoptions.py:541 msgid "Sudo rule notbefore attribute" msgstr "Attribut notbefore de la règle sudo" -#: src/config/SSSDConfig/sssdoptions.py:536 +#: src/config/SSSDConfig/sssdoptions.py:542 msgid "Sudo rule notafter attribute" msgstr "Attribut notafter de règle sudo" -#: src/config/SSSDConfig/sssdoptions.py:537 +#: src/config/SSSDConfig/sssdoptions.py:543 msgid "Sudo rule order attribute" msgstr "Attribut d'ordre de règle sudo" -#: src/config/SSSDConfig/sssdoptions.py:540 +#: src/config/SSSDConfig/sssdoptions.py:546 msgid "Object class for automounter maps" msgstr "Classe objet pour la carte de montage automatique" -#: src/config/SSSDConfig/sssdoptions.py:541 +#: src/config/SSSDConfig/sssdoptions.py:547 msgid "Automounter map name attribute" msgstr "Nom de l'attribut de carte de montage automatique" -#: src/config/SSSDConfig/sssdoptions.py:542 +#: src/config/SSSDConfig/sssdoptions.py:548 msgid "Object class for automounter map entries" msgstr "Classe objet pour l'entrée de référence de montage automatique" -#: src/config/SSSDConfig/sssdoptions.py:543 +#: src/config/SSSDConfig/sssdoptions.py:549 msgid "Automounter map entry key attribute" msgstr "Attribut de clé d'entrée pour la carte de montage automatique" -#: src/config/SSSDConfig/sssdoptions.py:544 +#: src/config/SSSDConfig/sssdoptions.py:550 msgid "Automounter map entry value attribute" msgstr "Attribut de valeur pour la carte de montage automatique" -#: src/config/SSSDConfig/sssdoptions.py:545 +#: src/config/SSSDConfig/sssdoptions.py:551 msgid "Base DN for automounter map lookups" msgstr "Base DN pour les requêtes de carte de montage automatique" -#: src/config/SSSDConfig/sssdoptions.py:546 +#: src/config/SSSDConfig/sssdoptions.py:552 msgid "The name of the automount master map in LDAP." msgstr "Le nom de la table de montage automatique maîtresse dans LDAP." -#: src/config/SSSDConfig/sssdoptions.py:549 +#: src/config/SSSDConfig/sssdoptions.py:555 msgid "Base DN for IP hosts lookups" msgstr "DN de base pour la recherche d'hôtes IP" -#: src/config/SSSDConfig/sssdoptions.py:550 +#: src/config/SSSDConfig/sssdoptions.py:556 msgid "Object class for IP hosts" msgstr "Classe d'objet pour les hôtes IP" -#: src/config/SSSDConfig/sssdoptions.py:551 +#: src/config/SSSDConfig/sssdoptions.py:557 msgid "IP host name attribute" msgstr "Attribut du nom d'hôte IP" -#: src/config/SSSDConfig/sssdoptions.py:552 +#: src/config/SSSDConfig/sssdoptions.py:558 msgid "IP host number (address) attribute" msgstr "Attribut (adresse) du numéro d'hôte IP" -#: src/config/SSSDConfig/sssdoptions.py:553 +#: src/config/SSSDConfig/sssdoptions.py:559 msgid "IP host entryUSN attribute" msgstr "Attribut entryUSN d’hôte IP" -#: src/config/SSSDConfig/sssdoptions.py:554 +#: src/config/SSSDConfig/sssdoptions.py:560 msgid "Base DN for IP networks lookups" msgstr "DN de base pour la recherche de réseaux IP" -#: src/config/SSSDConfig/sssdoptions.py:555 +#: src/config/SSSDConfig/sssdoptions.py:561 msgid "Object class for IP networks" msgstr "Classe d'objets pour les réseaux IP" -#: src/config/SSSDConfig/sssdoptions.py:556 +#: src/config/SSSDConfig/sssdoptions.py:562 msgid "IP network name attribute" msgstr "Attribut du nom du réseau IP" -#: src/config/SSSDConfig/sssdoptions.py:557 +#: src/config/SSSDConfig/sssdoptions.py:563 msgid "IP network number (address) attribute" msgstr "Attribut (adresse) du numéro de réseau IP" -#: src/config/SSSDConfig/sssdoptions.py:558 +#: src/config/SSSDConfig/sssdoptions.py:564 msgid "IP network entryUSN attribute" msgstr "Attribut entryUSN de réseau IP" -#: src/config/SSSDConfig/sssdoptions.py:561 +#: src/config/SSSDConfig/sssdoptions.py:567 msgid "Comma separated list of allowed users" msgstr "Liste, séparée par des virgules, d'utilisateurs autorisés" -#: src/config/SSSDConfig/sssdoptions.py:562 +#: src/config/SSSDConfig/sssdoptions.py:568 msgid "Comma separated list of prohibited users" msgstr "Liste, séparée par des virgules, d'utilisateurs interdits" -#: src/config/SSSDConfig/sssdoptions.py:563 +#: src/config/SSSDConfig/sssdoptions.py:569 msgid "" "Comma separated list of groups that are allowed to log in. This applies only " "to groups within this SSSD domain. Local groups are not evaluated." @@ -2051,7 +2100,7 @@ msgstr "" "s'applique qu'à des groupes dans un domaine SSSD. Les groupes locaux ne sont " "pas pris en compte." -#: src/config/SSSDConfig/sssdoptions.py:565 +#: src/config/SSSDConfig/sssdoptions.py:571 msgid "" "Comma separated list of groups that are explicitly denied access. This " "applies only to groups within this SSSD domain. Local groups are not " @@ -2061,33 +2110,33 @@ msgstr "" "s'applique qu'à des groupes dans un domaine SSSD. Les groupes locaux ne sont " "pas pris en compte." -#: src/config/SSSDConfig/sssdoptions.py:569 +#: src/config/SSSDConfig/sssdoptions.py:575 msgid "The number of preforked proxy children." msgstr "Le nombre d'enfants proxy pré-fourche." -#: src/config/SSSDConfig/sssdoptions.py:572 +#: src/config/SSSDConfig/sssdoptions.py:578 msgid "The name of the NSS library to use" msgstr "Nom de la bibliothèque NSS à utiliser" -#: src/config/SSSDConfig/sssdoptions.py:573 +#: src/config/SSSDConfig/sssdoptions.py:579 msgid "The name of the NSS library to use for hosts and networks lookups" msgstr "" "Le nom de la bibliothèque du NSS à utiliser pour les recherches réseaux et " "hôtes" -#: src/config/SSSDConfig/sssdoptions.py:574 +#: src/config/SSSDConfig/sssdoptions.py:580 msgid "Whether to look up canonical group name from cache if possible" msgstr "Rechercher le nom canonique du groupe dans le cache si possible" -#: src/config/SSSDConfig/sssdoptions.py:577 +#: src/config/SSSDConfig/sssdoptions.py:583 msgid "PAM stack to use" msgstr "Pile PAM à utiliser" -#: src/config/SSSDConfig/sssdoptions.py:580 +#: src/config/SSSDConfig/sssdoptions.py:586 msgid "Path of passwd file sources." msgstr "Chemin des sources des fichiers passwd." -#: src/config/SSSDConfig/sssdoptions.py:581 +#: src/config/SSSDConfig/sssdoptions.py:587 msgid "Path of group file sources." msgstr "Chemin des sources des fichiers de groupe." @@ -2118,108 +2167,112 @@ msgstr "" msgid "Option -i|--interactive is not allowed together with -D|--daemon\n" msgstr "Option -i|--interactive non authorisée avec -D|--daemon\n" -#: src/monitor/monitor.c:1836 +#: src/monitor/monitor.c:1838 msgid "Failed to get initial capabilities\n" msgstr "Échec de l'obtention des capacités initiales\n" -#: src/monitor/monitor.c:1847 +#: src/monitor/monitor.c:1849 msgid "Non-root service user support isn't built. Can't run under %" msgstr "" "Le programme n'a pas été compilé avec la prise en charge de l'utilisateur de " "service non root. Impossible de s'exécuter en tant que %" -#: src/monitor/monitor.c:1864 +#: src/monitor/monitor.c:1866 #, c-format msgid "Can't read config: '%s'\n" msgstr "Impossible de lire la configuration : '%s'\n" -#: src/monitor/monitor.c:1876 -#, c-format -msgid "Failed to boostrap SSSD 'monitor' process: %s" +#: src/monitor/monitor.c:1878 +#, fuzzy, c-format +msgid "Failed to bootstrap SSSD 'monitor' process: %s" msgstr "Échec du démarrage du processus SSSD 'monitor' : %s" -#: src/monitor/monitor.c:1971 +#: src/monitor/monitor.c:1973 msgid "Out of memory\n" msgstr "Mémoire saturée\n" -#: src/providers/krb5/krb5_child.c:4221 +#: src/providers/krb5/krb5_child.c:4316 msgid "Use anonymous PKINIT to request FAST armor ticket" msgstr "Utilisez le PKINIT anonyme pour obtenir un ticket FAST armor" -#: src/providers/krb5/krb5_child.c:4223 +#: src/providers/krb5/krb5_child.c:4318 msgid "Kerberos realm to use" msgstr "Domaine Kerberos à utiliser" -#: src/providers/krb5/krb5_child.c:4225 +#: src/providers/krb5/krb5_child.c:4320 msgid "Requested lifetime of the ticket" msgstr "Demande de renouvellement à vie du billet" -#: src/providers/krb5/krb5_child.c:4227 +#: src/providers/krb5/krb5_child.c:4322 msgid "Requested renewable lifetime of the ticket" msgstr "Demande de renouvellement à vie du billet" -#: src/providers/krb5/krb5_child.c:4229 +#: src/providers/krb5/krb5_child.c:4324 msgid "FAST options ('never', 'try', 'demand')" msgstr "Options FAST ('never', 'try', 'demand')" -#: src/providers/krb5/krb5_child.c:4232 +#: src/providers/krb5/krb5_child.c:4327 msgid "Specifies the server principal to use for FAST" msgstr "Spécifie le principal de serveur afin d'utiliser FAST" -#: src/providers/krb5/krb5_child.c:4234 +#: src/providers/krb5/krb5_child.c:4329 msgid "Requests canonicalization of the principal name" msgstr "Demande la canonisation du nom principal" -#: src/providers/krb5/krb5_child.c:4236 +#: src/providers/krb5/krb5_child.c:4331 msgid "Use custom version of krb5_get_init_creds_password" msgstr "Utiliser la version personnalisée de krb5_get_init_creds_password" -#: src/providers/krb5/krb5_child.c:4238 +#: src/providers/krb5/krb5_child.c:4333 msgid "Check PAC flags" msgstr "Vérifier les indicateurs PAC" -#: src/providers/data_provider_be.c:790 +#: src/providers/krb5/krb5_child.c:4335 +msgid "Set environment variable (KEY=VALUE)" +msgstr "" + +#: src/providers/data_provider_be.c:786 msgid "Domain of the information provider (mandatory)" msgstr "Domaine du fournisseur d'informations (obligatoire)" -#: src/sss_client/common.c:1165 +#: src/sss_client/common.c:1208 msgid "Socket has wrong ownership or permissions." msgstr "Les autorisations d'accès ou le propriétaire du socket est incorrect." -#: src/sss_client/common.c:1168 +#: src/sss_client/common.c:1211 msgid "Unexpected format of the server credential message." msgstr "Le message du serveur de crédits a un format inattendu." -#: src/sss_client/common.c:1171 +#: src/sss_client/common.c:1214 msgid "SSSD is not run by trusted user." msgstr "SSSD n'est pas exécuté par un utilisateur de confiance." -#: src/sss_client/common.c:1174 +#: src/sss_client/common.c:1217 msgid "SSSD socket does not exist." msgstr "La socket SSSD n'existe pas." -#: src/sss_client/common.c:1177 +#: src/sss_client/common.c:1220 msgid "Cannot get stat of SSSD socket." msgstr "Impossible d'obtenir le stat du socket SSSD." -#: src/sss_client/common.c:1182 +#: src/sss_client/common.c:1225 msgid "An error occurred, but no description can be found." msgstr "Une erreur est survenue mais aucune description n'est trouvée." -#: src/sss_client/common.c:1188 +#: src/sss_client/common.c:1231 msgid "Unexpected error while looking for an error description" msgstr "Erreur inattendue lors de la recherche de la description de l'erreur" -#: src/sss_client/pam_sss.c:74 +#: src/sss_client/pam_sss.c:135 msgid "Permission denied. " msgstr "Accès refusé. " -#: src/sss_client/pam_sss.c:75 src/sss_client/pam_sss.c:843 -#: src/sss_client/pam_sss.c:854 +#: src/sss_client/pam_sss.c:136 src/sss_client/pam_sss.c:921 +#: src/sss_client/pam_sss.c:932 msgid "Server message: " msgstr "Message du serveur : " -#: src/sss_client/pam_sss.c:76 +#: src/sss_client/pam_sss.c:137 msgid "" "Kerberos TGT will not be granted upon login, user experience will be " "affected." @@ -2227,52 +2280,53 @@ msgstr "" "Le TGT Kerberos ne sera pas accordé lors de la connexion ; cela affectera " "l'expérience utilisateur." -#: src/sss_client/pam_sss.c:77 +#: src/sss_client/pam_sss.c:138 msgid "Enter PIN:" msgstr "Saisissez le code PIN :" -#: src/sss_client/pam_sss.c:320 +#: src/sss_client/pam_sss.c:385 msgid "Passwords do not match" msgstr "Les mots de passe ne correspondent pas" -#: src/sss_client/pam_sss.c:508 +#: src/sss_client/pam_sss.c:584 msgid "Password reset by root is not supported." -msgstr "La réinitialisation du mot de passe par root n'est pas prise en charge." +msgstr "" +"La réinitialisation du mot de passe par root n'est pas prise en charge." -#: src/sss_client/pam_sss.c:549 +#: src/sss_client/pam_sss.c:625 msgid "Authenticated with cached credentials" msgstr "Authentifié avec les crédits mis en cache" -#: src/sss_client/pam_sss.c:550 +#: src/sss_client/pam_sss.c:626 msgid ", your cached password will expire at: " msgstr ", votre mot de passe en cache expirera à : " -#: src/sss_client/pam_sss.c:580 +#: src/sss_client/pam_sss.c:656 #, c-format msgid "Your password has expired. You have %1$d grace login(s) remaining." msgstr "" "Votre mot de passe a expiré. Il vous reste %1$d connexion(s) autorisée(s)." -#: src/sss_client/pam_sss.c:630 +#: src/sss_client/pam_sss.c:706 #, c-format msgid "Your password will expire in %1$d %2$s." msgstr "Votre mot de passe expirera dans %1$d %2$s." -#: src/sss_client/pam_sss.c:633 +#: src/sss_client/pam_sss.c:709 #, c-format msgid "Your password has expired." msgstr "Votre mot de passe a expiré." -#: src/sss_client/pam_sss.c:684 +#: src/sss_client/pam_sss.c:760 msgid "Authentication is denied until: " msgstr "L'authentification est refusée jusque : " -#: src/sss_client/pam_sss.c:705 +#: src/sss_client/pam_sss.c:781 msgid "System is offline, password change not possible" msgstr "" "Le système est hors-ligne, les modifications du mot de passe sont impossibles" -#: src/sss_client/pam_sss.c:720 +#: src/sss_client/pam_sss.c:796 msgid "" "After changing the OTP password, you need to log out and back in order to " "acquire a ticket" @@ -2280,11 +2334,11 @@ msgstr "" "Après avoir modifié le mot de passe OTP, vous devez vous déconnecter et vous " "reconnecter afin d'acquérir un ticket" -#: src/sss_client/pam_sss.c:735 +#: src/sss_client/pam_sss.c:813 msgid "PIN locked" msgstr "PIN verrouillé" -#: src/sss_client/pam_sss.c:750 +#: src/sss_client/pam_sss.c:828 msgid "" "No Kerberos TGT granted as the server does not support this method. Your " "single-sign on(SSO) experience will be affected." @@ -2292,61 +2346,65 @@ msgstr "" "Aucun TGT Kerberos accordé car le serveur ne prend pas en charge cette " "méthode. Cela affectera votre expérience d'authentification unique (SSO)." -#: src/sss_client/pam_sss.c:840 src/sss_client/pam_sss.c:853 +#: src/sss_client/pam_sss.c:918 src/sss_client/pam_sss.c:931 msgid "Password change failed. " msgstr "Échec du changement de mot de passe. " -#: src/sss_client/pam_sss.c:1859 -#, c-format -msgid "Authenticate at %1$s and press ENTER." +#: src/sss_client/pam_sss.c:2028 +#, fuzzy, c-format +msgid "Authenticate at \"%1$s\"." msgstr "Authentifiez-vous sur %1$s et appuyez sur ENTRÉE." -#: src/sss_client/pam_sss.c:1862 -#, c-format -msgid "Authenticate with PIN %1$s at %2$s and press ENTER." +#: src/sss_client/pam_sss.c:2031 +#, fuzzy, c-format +msgid "Authenticate with PIN \"%1$s\" at \"%2$s\"." msgstr "Authentifiez-vous avec le PIN %1$s à %2$s et appuyez sur ENTRÉE." -#: src/sss_client/pam_sss.c:2281 +#: src/sss_client/pam_sss.c:2470 msgid "Please (re)insert (different) Smartcard" msgstr "Veuillez (ré)insérer une carte à puce (différente)" -#: src/sss_client/pam_sss.c:2482 +#: src/sss_client/pam_sss.c:2700 msgid "New Password: " msgstr "Nouveau mot de passe : " -#: src/sss_client/pam_sss.c:2483 +#: src/sss_client/pam_sss.c:2701 msgid "Reenter new Password: " msgstr "Retaper le nouveau mot de passe : " -#: src/sss_client/pam_sss.c:2676 src/sss_client/pam_sss.c:2679 +#: src/sss_client/pam_sss.c:2890 +msgid "Press ENTER to continue." +msgstr "" + +#: src/sss_client/pam_sss.c:2913 src/sss_client/pam_sss.c:2916 msgid "First Factor: " msgstr "Premier facteur : " -#: src/sss_client/pam_sss.c:2677 src/sss_client/pam_sss.c:2851 +#: src/sss_client/pam_sss.c:2914 src/sss_client/pam_sss.c:3088 msgid "Second Factor (optional): " msgstr "Deuxième facteur (facultatif) : " -#: src/sss_client/pam_sss.c:2680 src/sss_client/pam_sss.c:2855 +#: src/sss_client/pam_sss.c:2917 src/sss_client/pam_sss.c:3092 msgid "Second Factor: " msgstr "Second facteur : " -#: src/sss_client/pam_sss.c:2684 +#: src/sss_client/pam_sss.c:2921 msgid "Insert your passkey device, then press ENTER." msgstr "Insérez votre passe-partout, puis appuyez sur la touche ENTER." -#: src/sss_client/pam_sss.c:2688 src/sss_client/pam_sss.c:2696 +#: src/sss_client/pam_sss.c:2925 src/sss_client/pam_sss.c:2933 msgid "Password: " msgstr "Mot de passe : " -#: src/sss_client/pam_sss.c:2850 src/sss_client/pam_sss.c:2854 +#: src/sss_client/pam_sss.c:3087 src/sss_client/pam_sss.c:3091 msgid "First Factor (Current Password): " msgstr "Premier facteur (mot de passe actuel) : " -#: src/sss_client/pam_sss.c:2874 +#: src/sss_client/pam_sss.c:3111 msgid "Current Password: " msgstr "Mot de passe actuel : " -#: src/sss_client/pam_sss.c:3248 +#: src/sss_client/pam_sss.c:3485 msgid "Password expired. Change your password now." msgstr "Mot de passe expiré. Changez votre mot de passe maintenant." @@ -2495,8 +2553,8 @@ msgid "" "use fully qualified name instead of --domain/-d parameter.\n" msgstr "" "Impossible d'ouvrir le domaine %1$s. Si le domaine est un sous-domaine " -"(domaine approuvé), utiliser le nom pleinement qualifié au lieu du " -"paramètre --domain/-d.\n" +"(domaine approuvé), utiliser le nom pleinement qualifié au lieu du paramètre " +"--domain/-d.\n" #: src/tools/sss_cache.c:897 msgid "Could not open available domains\n" @@ -2634,7 +2692,8 @@ msgstr "Archiver les fichiers journaux SSSD dans un tarball" #: src/tools/sssctl/sssctl.c:340 msgid "Change or print information about SSSD debug level" -msgstr "Modifier ou imprimer les informations sur le niveau de débogage de SSSD" +msgstr "" +"Modifier ou imprimer les informations sur le niveau de débogage de SSSD" #: src/tools/sssctl/sssctl.c:341 msgid "Analyze logged data" @@ -2794,9 +2853,9 @@ msgstr "Impossible d'afficher l'objet : %s\n" #: src/tools/sssctl/sssctl_cache.c:835 src/tools/sssctl/sssctl_cache.c:918 #: src/tools/sssctl/sssctl_cache.c:950 src/tools/sssctl/sssctl_cache.c:956 #: src/tools/sssctl/sssctl_cache.c:1010 src/tools/sssctl/sssctl_cache.c:1034 -#: src/tools/sssctl/sssctl_cache.c:1085 src/tools/sssctl/sssctl_cache.c:1194 -#: src/tools/sssctl/sssctl_cache.c:1229 src/tools/sssctl/sssctl_cache.c:1235 -#: src/tools/sssctl/sssctl_cache.c:1244 +#: src/tools/sssctl/sssctl_cache.c:1085 src/tools/sssctl/sssctl_cache.c:1195 +#: src/tools/sssctl/sssctl_cache.c:1230 src/tools/sssctl/sssctl_cache.c:1236 +#: src/tools/sssctl/sssctl_cache.c:1245 msgid "talloc failed\n" msgstr "talloc échoué\n" @@ -2865,32 +2924,33 @@ msgstr "Impossible de déterminer le chemin d'accès réel pour [%s] : %s\n" #: src/tools/sssctl/sssctl_cache.c:1073 #, c-format msgid "The cached GPO path [%s] is not under [%s], ignoring.\n" -msgstr "Le chemin d'accès à la GPO en cache [%s] n'est pas sous [%s], ignoré.\n" +msgstr "" +"Le chemin d'accès à la GPO en cache [%s] n'est pas sous [%s], ignoré.\n" #: src/tools/sssctl/sssctl_cache.c:1098 #, c-format msgid "Unable to remove downloaded GPO files: %s\n" msgstr "Impossible de supprimer les fichiers GPO téléchargés : %s\n" -#: src/tools/sssctl/sssctl_cache.c:1165 +#: src/tools/sssctl/sssctl_cache.c:1166 #, c-format msgid "Failed to fetch cache entry: %s\n" msgstr "Échec de l'ouverture de l'entrée dans le cache : %s\n" -#: src/tools/sssctl/sssctl_cache.c:1170 +#: src/tools/sssctl/sssctl_cache.c:1171 msgid "Could not determine object domain\n" msgstr "Impossible de déterminer le domaine de l'objet\n" -#: src/tools/sssctl/sssctl_cache.c:1200 +#: src/tools/sssctl/sssctl_cache.c:1201 msgid "Could not find GUID attribute in GPO entry\n" msgstr "Impossible de trouver l'attribut GUID dans l'entrée GPO\n" -#: src/tools/sssctl/sssctl_cache.c:1206 +#: src/tools/sssctl/sssctl_cache.c:1207 #, c-format msgid "Failed to delete GPO: %s\n" msgstr "Impossible de supprimer la GPO : %s\n" -#: src/tools/sssctl/sssctl_cache.c:1210 +#: src/tools/sssctl/sssctl_cache.c:1211 #, c-format msgid "%s removed from cache\n" msgstr "%s supprimé du cache\n" @@ -2939,8 +2999,8 @@ msgstr "Échec de la configuration du contexte de la carte de certification.\n" #, c-format msgid "Failed to add mapping and matching rules with error [%d][%s].\n" msgstr "" -"Échec de l'ajout de règles de mappage et de correspondance avec l'erreur " -"[%d][%s].\n" +"Échec de l'ajout de règles de mappage et de correspondance avec l'erreur [%d]" +"[%s].\n" #: src/tools/sssctl/sssctl_cert.c:251 msgid "Failed to decode base64 string.\n" @@ -2988,41 +3048,42 @@ msgstr "" "exemple, si la configuration est définie sur \"/my/path/sssd.conf\", le " "répertoire d'extrait \"/my/path/conf.d\" sera utilisé)" -#: src/tools/sssctl/sssctl_config.c:114 +#: src/tools/sssctl/sssctl_config.c:126 #, c-format msgid "File %1$s does not exist.\n" msgstr "Le fichier %1$s n’existe pas.\n" -#: src/tools/sssctl/sssctl_config.c:115 +#: src/tools/sssctl/sssctl_config.c:127 msgid "There is no configuration.\n" msgstr "Il n'y a pas de configuration.\n" -#: src/tools/sssctl/sssctl_config.c:120 +#: src/tools/sssctl/sssctl_config.c:132 #, c-format msgid "Configuration validation failed: %s\n" msgstr "Validation de la configuration échouée : %s\n" -#: src/tools/sssctl/sssctl_config.c:121 +#: src/tools/sssctl/sssctl_config.c:133 msgid "Run with high debug level to see details.\n" msgstr "" "Exécutez le programme avec un niveau de débogage élevé pour voir les " "détails.\n" -#: src/tools/sssctl/sssctl_config.c:130 -msgid "Failed to run validators" +#: src/tools/sssctl/sssctl_config.c:142 +#, fuzzy +msgid "Failed to run validators\n" msgstr "Échec de l'exécution des validateurs" -#: src/tools/sssctl/sssctl_config.c:134 +#: src/tools/sssctl/sssctl_config.c:146 #, c-format msgid "Issues identified by validators: %zu\n" msgstr "Problèmes identifiés par les validateurs : %zu\n" -#: src/tools/sssctl/sssctl_config.c:145 +#: src/tools/sssctl/sssctl_config.c:157 #, c-format msgid "Messages generated during configuration merging: %zu\n" msgstr "Messages générés lors de la fusion des configurations : %zu\n" -#: src/tools/sssctl/sssctl_config.c:158 +#: src/tools/sssctl/sssctl_config.c:170 #, c-format msgid "Used configuration snippet files: %zu\n" msgstr "Fichiers de configuration utilisés : %zu\n" diff --git a/po/hu.po b/po/hu.po index 4103e06340d..0fe7eaace45 100644 --- a/po/hu.po +++ b/po/hu.po @@ -11,8 +11,8 @@ msgid "" msgstr "" "Project-Id-Version: PACKAGE VERSION\n" "Report-Msgid-Bugs-To: sssd-devel@lists.fedorahosted.org\n" -"POT-Creation-Date: 2026-01-14 14:57+0000\n" -"PO-Revision-Date: 2026-04-23 17:04+0000\n" +"POT-Creation-Date: 2026-10-02 15:57+0000\n" +"PO-Revision-Date: 2026-10-05 16:40+0000\n" "Last-Translator: \"Dankaházi (ifj.) István\" \n" "Language-Team: Hungarian \n" @@ -21,50 +21,50 @@ msgstr "" "Content-Type: text/plain; charset=UTF-8\n" "Content-Transfer-Encoding: 8bit\n" "Plural-Forms: nplurals=2; plural=n != 1;\n" -"X-Generator: Weblate 5.17\n" +"X-Generator: Weblate 2026.10\n" -#: src/config/SSSDConfig/sssdoptions.py:20 -#: src/config/SSSDConfig/sssdoptions.py:21 +#: src/config/SSSDConfig/sssdoptions.py:16 +#: src/config/SSSDConfig/sssdoptions.py:17 msgid "Set the verbosity of the debug logging" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:22 +#: src/config/SSSDConfig/sssdoptions.py:18 msgid "Include timestamps in debug logs" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:23 +#: src/config/SSSDConfig/sssdoptions.py:19 msgid "Include microseconds in timestamps in debug logs" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:24 +#: src/config/SSSDConfig/sssdoptions.py:20 msgid "Enable/disable debug backtrace" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:25 +#: src/config/SSSDConfig/sssdoptions.py:21 msgid "Watchdog timeout before restarting service" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:26 +#: src/config/SSSDConfig/sssdoptions.py:22 msgid "Command to start service" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:27 +#: src/config/SSSDConfig/sssdoptions.py:23 msgid "The number of file descriptors that may be opened by this responder" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:28 +#: src/config/SSSDConfig/sssdoptions.py:24 msgid "Idle time before automatic disconnection of a client" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:29 +#: src/config/SSSDConfig/sssdoptions.py:25 msgid "Idle time before automatic shutdown of the responder" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:30 +#: src/config/SSSDConfig/sssdoptions.py:26 msgid "Always query all the caches before querying the Data Providers" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:31 +#: src/config/SSSDConfig/sssdoptions.py:27 msgid "" "When SSSD switches to offline mode the amount of time before it tries to go " "back online will increase based upon the time spent disconnected. This value " @@ -72,63 +72,63 @@ msgid "" "random_offset." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:36 +#: src/config/SSSDConfig/sssdoptions.py:32 msgid "SSSD Services to start" msgstr "Elindítandó SSSD szolgáltatások" -#: src/config/SSSDConfig/sssdoptions.py:37 +#: src/config/SSSDConfig/sssdoptions.py:33 msgid "SSSD Domains to start" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:38 +#: src/config/SSSDConfig/sssdoptions.py:34 msgid "Regex to parse username and domain" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:39 +#: src/config/SSSDConfig/sssdoptions.py:35 msgid "Printf-compatible format for displaying fully-qualified names" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:40 +#: src/config/SSSDConfig/sssdoptions.py:36 msgid "" "Directory on the filesystem where SSSD should store Kerberos replay cache " "files." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:41 +#: src/config/SSSDConfig/sssdoptions.py:37 msgid "Domain to add to names without a domain component." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:42 +#: src/config/SSSDConfig/sssdoptions.py:38 msgid "The user to drop privileges to" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:43 +#: src/config/SSSDConfig/sssdoptions.py:39 msgid "Tune certificate verification" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:44 +#: src/config/SSSDConfig/sssdoptions.py:40 msgid "All spaces in group or user names will be replaced with this character" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:45 +#: src/config/SSSDConfig/sssdoptions.py:41 msgid "Tune sssd to honor or ignore netlink state changes" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:46 +#: src/config/SSSDConfig/sssdoptions.py:42 msgid "Enable or disable the implicit files domain" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:47 +#: src/config/SSSDConfig/sssdoptions.py:43 msgid "A specific order of the domains to be looked up" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:48 +#: src/config/SSSDConfig/sssdoptions.py:44 msgid "" "Controls if SSSD should monitor the state of resolv.conf to identify when it " "needs to update its internal DNS resolver." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:50 +#: src/config/SSSDConfig/sssdoptions.py:46 msgid "" "SSSD monitors the state of resolv.conf to identify when it needs to update " "its internal DNS resolver. By default, we will attempt to use inotify for " @@ -136,394 +136,401 @@ msgid "" "inotify cannot be used." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:53 +#: src/config/SSSDConfig/sssdoptions.py:49 msgid "Run PAC responder automatically for AD and IPA provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:54 +#: src/config/SSSDConfig/sssdoptions.py:50 msgid "Enable or disable core dumps for all SSSD processes." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:55 +#: src/config/SSSDConfig/sssdoptions.py:51 msgid "Tune passkey verification behavior" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:58 +#: src/config/SSSDConfig/sssdoptions.py:54 msgid "Enumeration cache timeout length (seconds)" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:59 +#: src/config/SSSDConfig/sssdoptions.py:55 msgid "Entry cache background update timeout length (seconds)" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:60 -#: src/config/SSSDConfig/sssdoptions.py:125 +#: src/config/SSSDConfig/sssdoptions.py:56 +#: src/config/SSSDConfig/sssdoptions.py:124 msgid "Negative cache timeout length (seconds)" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:61 +#: src/config/SSSDConfig/sssdoptions.py:57 msgid "Users that SSSD should explicitly ignore" msgstr "SSSD által figyelmen kívül hagyott felhasználók" -#: src/config/SSSDConfig/sssdoptions.py:62 +#: src/config/SSSDConfig/sssdoptions.py:58 msgid "Groups that SSSD should explicitly ignore" msgstr "SSSD által figyelmen kívül hagyott csoportok" -#: src/config/SSSDConfig/sssdoptions.py:63 +#: src/config/SSSDConfig/sssdoptions.py:59 msgid "Should filtered users appear in groups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:64 +#: src/config/SSSDConfig/sssdoptions.py:60 msgid "The value of the password field the NSS provider should return" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:65 +#: src/config/SSSDConfig/sssdoptions.py:61 msgid "Override homedir value from the identity provider with this value" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:66 +#: src/config/SSSDConfig/sssdoptions.py:62 msgid "" "Substitute empty homedir value from the identity provider with this value" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:67 +#: src/config/SSSDConfig/sssdoptions.py:63 msgid "Override shell value from the identity provider with this value" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:68 +#: src/config/SSSDConfig/sssdoptions.py:64 msgid "The list of shells users are allowed to log in with" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:69 +#: src/config/SSSDConfig/sssdoptions.py:65 msgid "" "The list of shells that will be vetoed, and replaced with the fallback shell" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:70 +#: src/config/SSSDConfig/sssdoptions.py:66 msgid "" "If a shell stored in central directory is allowed but not available, use " "this fallback" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:71 +#: src/config/SSSDConfig/sssdoptions.py:67 msgid "Shell to use if the provider does not list one" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:72 +#: src/config/SSSDConfig/sssdoptions.py:68 msgid "How long will be in-memory cache records valid" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:74 +#: src/config/SSSDConfig/sssdoptions.py:70 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for passwd requests" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:76 +#: src/config/SSSDConfig/sssdoptions.py:72 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for group requests" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:78 +#: src/config/SSSDConfig/sssdoptions.py:74 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for initgroups requests" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:79 +#: src/config/SSSDConfig/sssdoptions.py:75 msgid "" "The value of this option will be used in the expansion of the " "override_homedir option if the template contains the format string %H." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:81 +#: src/config/SSSDConfig/sssdoptions.py:77 msgid "" "Specifies time in seconds for which the list of subdomains will be " "considered valid." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:83 +#: src/config/SSSDConfig/sssdoptions.py:79 msgid "" "The entry cache can be set to automatically update entries in the background " "if they are requested beyond a percentage of the entry_cache_timeout value " "for the domain." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:88 +#: src/config/SSSDConfig/sssdoptions.py:84 msgid "How long to allow cached logins between online logins (days)" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:89 +#: src/config/SSSDConfig/sssdoptions.py:85 msgid "How many failed logins attempts are allowed when offline" msgstr "Hány sikertelen bejelentkezés engedélyezett offline állapotban" -#: src/config/SSSDConfig/sssdoptions.py:91 +#: src/config/SSSDConfig/sssdoptions.py:87 msgid "" "How long (minutes) to deny login after offline_failed_login_attempts has " "been reached" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:92 +#: src/config/SSSDConfig/sssdoptions.py:88 msgid "What kind of messages are displayed to the user during authentication" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:93 +#: src/config/SSSDConfig/sssdoptions.py:89 msgid "Filter PAM responses sent to the pam_sss" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:94 +#: src/config/SSSDConfig/sssdoptions.py:90 msgid "How many seconds to keep identity information cached for PAM requests" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:95 +#: src/config/SSSDConfig/sssdoptions.py:91 msgid "How many days before password expiration a warning should be displayed" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:96 +#: src/config/SSSDConfig/sssdoptions.py:92 msgid "List of trusted uids or user's name" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:97 +#: src/config/SSSDConfig/sssdoptions.py:93 msgid "List of domains accessible even for untrusted users." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:98 +#: src/config/SSSDConfig/sssdoptions.py:94 msgid "Message printed when user account is expired." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:99 +#: src/config/SSSDConfig/sssdoptions.py:95 msgid "Message printed when user account is locked." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:100 +#: src/config/SSSDConfig/sssdoptions.py:96 msgid "Allow certificate based/Smartcard authentication." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:101 +#: src/config/SSSDConfig/sssdoptions.py:97 msgid "Path to certificate database with PKCS#11 modules." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:102 +#: src/config/SSSDConfig/sssdoptions.py:98 #, fuzzy msgid "Tune certificate verification for PAM authentication." msgstr "TLS tanusítvány ellenőrzése" -#: src/config/SSSDConfig/sssdoptions.py:103 +#: src/config/SSSDConfig/sssdoptions.py:99 msgid "How many seconds will pam_sss wait for p11_child to finish" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:104 +#: src/config/SSSDConfig/sssdoptions.py:100 msgid "Which PAM services are permitted to contact application domains" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:105 +#: src/config/SSSDConfig/sssdoptions.py:101 msgid "Allowed services for using smartcards" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:106 +#: src/config/SSSDConfig/sssdoptions.py:102 msgid "Additional timeout to wait for a card if requested" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:107 +#: src/config/SSSDConfig/sssdoptions.py:103 msgid "" "PKCS#11 URI to restrict the selection of devices for Smartcard authentication" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:108 +#: src/config/SSSDConfig/sssdoptions.py:104 msgid "When shall the PAM responder force an initgroups request" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:109 +#: src/config/SSSDConfig/sssdoptions.py:105 msgid "List of PAM services that are allowed to authenticate with GSSAPI." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:110 +#: src/config/SSSDConfig/sssdoptions.py:106 msgid "Whether to match authenticated UPN with target user" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:111 +#: src/config/SSSDConfig/sssdoptions.py:107 msgid "" "List of pairs : that must be enforced " "for PAM access with GSSAPI authentication" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:113 +#: src/config/SSSDConfig/sssdoptions.py:109 +msgid "" +"List of triples :: that assigns " +"additional information from the Kerberos ticket to an authentication " +"indicator." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:112 msgid "Allow passkey device authentication." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:114 +#: src/config/SSSDConfig/sssdoptions.py:113 msgid "How many seconds will pam_sss wait for passkey_child to finish" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:115 +#: src/config/SSSDConfig/sssdoptions.py:114 msgid "Enable debugging in the libfido2 library" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:116 +#: src/config/SSSDConfig/sssdoptions.py:115 msgid "Enable JSON protocol for authentication methods selection." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:119 +#: src/config/SSSDConfig/sssdoptions.py:118 msgid "Whether to evaluate the time-based attributes in sudo rules" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:120 +#: src/config/SSSDConfig/sssdoptions.py:119 msgid "If true, SSSD will switch back to lower-wins ordering logic" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:121 +#: src/config/SSSDConfig/sssdoptions.py:120 msgid "" "Maximum number of rules that can be refreshed at once. If this is exceeded, " "full refresh is performed." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:128 +#: src/config/SSSDConfig/sssdoptions.py:127 msgid "Whether to hash host names and addresses in the known_hosts file" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:129 +#: src/config/SSSDConfig/sssdoptions.py:128 msgid "" "How many seconds to keep a host in the known_hosts file after its host keys " "were requested" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:131 +#: src/config/SSSDConfig/sssdoptions.py:130 msgid "Path to storage of trusted CA certificates" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:132 +#: src/config/SSSDConfig/sssdoptions.py:131 msgid "Allow to generate ssh-keys from certificates" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:133 +#: src/config/SSSDConfig/sssdoptions.py:132 msgid "" "Use the following matching rules to filter the certificates for ssh-key " "generation" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:137 +#: src/config/SSSDConfig/sssdoptions.py:136 msgid "List of UIDs or user names allowed to access the PAC responder" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:138 +#: src/config/SSSDConfig/sssdoptions.py:137 msgid "How long the PAC data is considered valid" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:139 +#: src/config/SSSDConfig/sssdoptions.py:138 msgid "Validate the PAC" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:142 +#: src/config/SSSDConfig/sssdoptions.py:141 msgid "List of user attributes the InfoPipe is allowed to publish" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:145 +#: src/config/SSSDConfig/sssdoptions.py:144 msgid "" "One of the following strings specifying the scope of session recording: none " "- No users are recorded. some - Users/groups specified by users and groups " "options are recorded. all - All users are recorded." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:148 +#: src/config/SSSDConfig/sssdoptions.py:147 msgid "" "A comma-separated list of users which should have session recording enabled. " "Matches user names as returned by NSS. I.e. after the possible space " "replacement, case changes, etc." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:150 +#: src/config/SSSDConfig/sssdoptions.py:149 msgid "" "A comma-separated list of groups, members of which should have session " "recording enabled. Matches group names as returned by NSS. I.e. after the " "possible space replacement, case changes, etc." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:153 +#: src/config/SSSDConfig/sssdoptions.py:152 msgid "" "A comma-separated list of users to be excluded from recording, only when " "scope=all" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:154 +#: src/config/SSSDConfig/sssdoptions.py:153 msgid "" "A comma-separated list of groups, members of which should be excluded from " "recording, only when scope=all. " msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:158 +#: src/config/SSSDConfig/sssdoptions.py:157 msgid "Identity provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:159 +#: src/config/SSSDConfig/sssdoptions.py:158 msgid "Authentication provider" msgstr "Azonosító-kiszolgáló" -#: src/config/SSSDConfig/sssdoptions.py:160 +#: src/config/SSSDConfig/sssdoptions.py:159 msgid "Access control provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:161 +#: src/config/SSSDConfig/sssdoptions.py:160 msgid "Password change provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:162 +#: src/config/SSSDConfig/sssdoptions.py:161 msgid "SUDO provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:163 +#: src/config/SSSDConfig/sssdoptions.py:162 msgid "Autofs provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:164 +#: src/config/SSSDConfig/sssdoptions.py:163 msgid "Host identity provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:165 +#: src/config/SSSDConfig/sssdoptions.py:164 msgid "SELinux provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:166 +#: src/config/SSSDConfig/sssdoptions.py:165 msgid "Session management provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:167 +#: src/config/SSSDConfig/sssdoptions.py:166 msgid "Resolver provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:170 +#: src/config/SSSDConfig/sssdoptions.py:169 msgid "Whether the domain is usable by the OS or by applications" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:171 +#: src/config/SSSDConfig/sssdoptions.py:170 msgid "Enable or disable the domain" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:172 +#: src/config/SSSDConfig/sssdoptions.py:171 msgid "Minimum user ID" msgstr "Legkisebb felhasználói azonosító" -#: src/config/SSSDConfig/sssdoptions.py:173 +#: src/config/SSSDConfig/sssdoptions.py:172 msgid "Maximum user ID" msgstr "Legnagyobb felhasználói azonosító" -#: src/config/SSSDConfig/sssdoptions.py:174 +#: src/config/SSSDConfig/sssdoptions.py:173 msgid "Enable enumerating all users/groups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:175 +#: src/config/SSSDConfig/sssdoptions.py:174 msgid "Cache credentials for offline login" msgstr "Azonosítók gyorsítótárazása offline használathoz" -#: src/config/SSSDConfig/sssdoptions.py:176 +#: src/config/SSSDConfig/sssdoptions.py:175 msgid "Display users/groups in fully-qualified form" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:177 +#: src/config/SSSDConfig/sssdoptions.py:176 msgid "Don't include group members in group lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:178 +#: src/config/SSSDConfig/sssdoptions.py:177 #: src/config/SSSDConfig/sssdoptions.py:190 #: src/config/SSSDConfig/sssdoptions.py:191 #: src/config/SSSDConfig/sssdoptions.py:192 @@ -534,48 +541,52 @@ msgstr "" msgid "Entry cache timeout length (seconds)" msgstr "Bejegyzés-gyorsítótár érvényessége (másodperc)" -#: src/config/SSSDConfig/sssdoptions.py:179 +#: src/config/SSSDConfig/sssdoptions.py:178 msgid "" "Restrict or prefer a specific address family when performing DNS lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:180 +#: src/config/SSSDConfig/sssdoptions.py:179 msgid "How long to keep cached entries after last successful login (days)" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:181 +#: src/config/SSSDConfig/sssdoptions.py:180 msgid "" "How long should SSSD talk to single DNS server before trying next server " "(miliseconds)" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:183 +#: src/config/SSSDConfig/sssdoptions.py:182 msgid "How long should keep trying to resolve single DNS query (seconds)" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:184 +#: src/config/SSSDConfig/sssdoptions.py:183 msgid "How long to wait for replies from DNS when resolving servers (seconds)" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:185 +#: src/config/SSSDConfig/sssdoptions.py:184 msgid "The domain part of service discovery DNS query" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:186 +#: src/config/SSSDConfig/sssdoptions.py:185 msgid "" "Specifies the interval, in seconds, that SSSD waits before attempting to " "reconnect to the primary server after a successful connection to the backup " "server" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:188 +#: src/config/SSSDConfig/sssdoptions.py:187 msgid "Override GID value from the identity provider with this value" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:189 +#: src/config/SSSDConfig/sssdoptions.py:188 msgid "Treat usernames as case sensitive" msgstr "" +#: src/config/SSSDConfig/sssdoptions.py:189 +msgid "Lookups by ID are expensive or do not work at all" +msgstr "" + #: src/config/SSSDConfig/sssdoptions.py:197 msgid "How often should expired entries be refreshed in background" msgstr "" @@ -796,7 +807,7 @@ msgid "Search base for SUBID ranges" msgstr "" #: src/config/SSSDConfig/sssdoptions.py:259 -#: src/config/SSSDConfig/sssdoptions.py:506 +#: src/config/SSSDConfig/sssdoptions.py:512 msgid "Which rules should be used to evaluate access control" msgstr "" @@ -938,7 +949,7 @@ msgid "Enable DNS sites - location based service discovery" msgstr "" #: src/config/SSSDConfig/sssdoptions.py:301 -#: src/config/SSSDConfig/sssdoptions.py:504 +#: src/config/SSSDConfig/sssdoptions.py:510 msgid "LDAP filter to determine access privileges" msgstr "" @@ -1358,7 +1369,7 @@ msgid "UUID attribute" msgstr "" #: src/config/SSSDConfig/sssdoptions.py:423 -#: src/config/SSSDConfig/sssdoptions.py:464 +#: src/config/SSSDConfig/sssdoptions.py:470 msgid "objectSID attribute" msgstr "" @@ -1482,385 +1493,409 @@ msgstr "" msgid "A list of extra attributes to download along with the user entry" msgstr "" +#: src/config/SSSDConfig/sssdoptions.py:456 +msgid "The object class of an subid entry in LDAP." +msgstr "" + #: src/config/SSSDConfig/sssdoptions.py:457 -msgid "Base DN for group lookups" +msgid "Subordinate user ID count attribute" msgstr "" #: src/config/SSSDConfig/sssdoptions.py:458 -msgid "Objectclass for groups" +msgid "Subordinate group ID count attribute" msgstr "" #: src/config/SSSDConfig/sssdoptions.py:459 +msgid "User ID range start value attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:460 +msgid "Group ID range start value attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:461 +msgid "Owner of an entry" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:463 +msgid "Base DN for group lookups" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:464 +msgid "Objectclass for groups" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:465 msgid "Group name" msgstr "Csoport neve" -#: src/config/SSSDConfig/sssdoptions.py:460 +#: src/config/SSSDConfig/sssdoptions.py:466 msgid "Group password" msgstr "Csoport jelszava" -#: src/config/SSSDConfig/sssdoptions.py:461 +#: src/config/SSSDConfig/sssdoptions.py:467 msgid "GID attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:462 +#: src/config/SSSDConfig/sssdoptions.py:468 msgid "Group member attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:463 +#: src/config/SSSDConfig/sssdoptions.py:469 msgid "Group UUID attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:465 +#: src/config/SSSDConfig/sssdoptions.py:471 msgid "Modification time attribute for groups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:466 +#: src/config/SSSDConfig/sssdoptions.py:472 msgid "Type of the group and other flags" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:467 +#: src/config/SSSDConfig/sssdoptions.py:473 msgid "The LDAP group external member attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:468 +#: src/config/SSSDConfig/sssdoptions.py:474 msgid "Maximum nesting level SSSD will follow" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:469 +#: src/config/SSSDConfig/sssdoptions.py:475 msgid "Filter for group lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:470 +#: src/config/SSSDConfig/sssdoptions.py:476 msgid "Scope of group lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:472 +#: src/config/SSSDConfig/sssdoptions.py:478 msgid "Base DN for netgroup lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:473 +#: src/config/SSSDConfig/sssdoptions.py:479 msgid "Objectclass for netgroups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:474 +#: src/config/SSSDConfig/sssdoptions.py:480 msgid "Netgroup name" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:475 +#: src/config/SSSDConfig/sssdoptions.py:481 msgid "Netgroups members attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:476 +#: src/config/SSSDConfig/sssdoptions.py:482 msgid "Netgroup triple attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:477 +#: src/config/SSSDConfig/sssdoptions.py:483 msgid "Modification time attribute for netgroups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:479 +#: src/config/SSSDConfig/sssdoptions.py:485 msgid "Base DN for service lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:480 +#: src/config/SSSDConfig/sssdoptions.py:486 msgid "Objectclass for services" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:481 +#: src/config/SSSDConfig/sssdoptions.py:487 msgid "Service name attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:482 +#: src/config/SSSDConfig/sssdoptions.py:488 msgid "Service port attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:483 +#: src/config/SSSDConfig/sssdoptions.py:489 msgid "Service protocol attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:485 +#: src/config/SSSDConfig/sssdoptions.py:491 msgid "Lower bound for ID-mapping" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:486 +#: src/config/SSSDConfig/sssdoptions.py:492 msgid "Upper bound for ID-mapping" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:487 +#: src/config/SSSDConfig/sssdoptions.py:493 msgid "Number of IDs for each slice when ID-mapping" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:488 +#: src/config/SSSDConfig/sssdoptions.py:494 msgid "Use autorid-compatible algorithm for ID-mapping" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:489 +#: src/config/SSSDConfig/sssdoptions.py:495 msgid "Name of the default domain for ID-mapping" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:490 +#: src/config/SSSDConfig/sssdoptions.py:496 msgid "SID of the default domain for ID-mapping" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:491 +#: src/config/SSSDConfig/sssdoptions.py:497 msgid "Number of secondary slices" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:493 +#: src/config/SSSDConfig/sssdoptions.py:499 msgid "Whether to use Token-Groups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:494 +#: src/config/SSSDConfig/sssdoptions.py:500 msgid "Set lower boundary for allowed IDs from the LDAP server" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:495 +#: src/config/SSSDConfig/sssdoptions.py:501 msgid "Set upper boundary for allowed IDs from the LDAP server" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:496 +#: src/config/SSSDConfig/sssdoptions.py:502 msgid "DN for ppolicy queries" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:497 +#: src/config/SSSDConfig/sssdoptions.py:503 msgid "How many maximum entries to fetch during a wildcard request" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:498 +#: src/config/SSSDConfig/sssdoptions.py:504 msgid "Set libldap debug level" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:501 +#: src/config/SSSDConfig/sssdoptions.py:507 msgid "Policy to evaluate the password expiration" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:505 +#: src/config/SSSDConfig/sssdoptions.py:511 msgid "Which attributes shall be used to evaluate if an account is expired" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:509 +#: src/config/SSSDConfig/sssdoptions.py:515 msgid "URI of an LDAP server where password changes are allowed" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:510 +#: src/config/SSSDConfig/sssdoptions.py:516 msgid "URI of a backup LDAP server where password changes are allowed" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:511 +#: src/config/SSSDConfig/sssdoptions.py:517 msgid "DNS service name for LDAP password change server" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:512 +#: src/config/SSSDConfig/sssdoptions.py:518 msgid "" "Whether to update the ldap_user_shadow_last_change attribute after a " "password change" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:516 +#: src/config/SSSDConfig/sssdoptions.py:522 msgid "Base DN for sudo rules lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:517 +#: src/config/SSSDConfig/sssdoptions.py:523 msgid "Automatic full refresh period" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:518 +#: src/config/SSSDConfig/sssdoptions.py:524 msgid "Automatic smart refresh period" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:519 +#: src/config/SSSDConfig/sssdoptions.py:525 msgid "Smart and full refresh random offset" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:520 +#: src/config/SSSDConfig/sssdoptions.py:526 msgid "Whether to filter rules by hostname, IP addresses and network" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:521 +#: src/config/SSSDConfig/sssdoptions.py:527 msgid "" "Hostnames and/or fully qualified domain names of this machine to filter sudo " "rules" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:522 +#: src/config/SSSDConfig/sssdoptions.py:528 msgid "IPv4 or IPv6 addresses or network of this machine to filter sudo rules" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:523 +#: src/config/SSSDConfig/sssdoptions.py:529 msgid "Whether to include rules that contains netgroup in host attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:524 +#: src/config/SSSDConfig/sssdoptions.py:530 msgid "" "Whether to include rules that contains regular expression in host attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:525 +#: src/config/SSSDConfig/sssdoptions.py:531 msgid "Object class for sudo rules" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:526 +#: src/config/SSSDConfig/sssdoptions.py:532 msgid "Name of attribute that is used as object class for sudo rules" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:527 +#: src/config/SSSDConfig/sssdoptions.py:533 msgid "Sudo rule name" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:528 +#: src/config/SSSDConfig/sssdoptions.py:534 msgid "Sudo rule command attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:529 +#: src/config/SSSDConfig/sssdoptions.py:535 msgid "Sudo rule host attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:530 +#: src/config/SSSDConfig/sssdoptions.py:536 msgid "Sudo rule user attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:531 +#: src/config/SSSDConfig/sssdoptions.py:537 msgid "Sudo rule option attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:532 +#: src/config/SSSDConfig/sssdoptions.py:538 msgid "Sudo rule runas attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:533 +#: src/config/SSSDConfig/sssdoptions.py:539 msgid "Sudo rule runasuser attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:534 +#: src/config/SSSDConfig/sssdoptions.py:540 msgid "Sudo rule runasgroup attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:535 +#: src/config/SSSDConfig/sssdoptions.py:541 msgid "Sudo rule notbefore attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:536 +#: src/config/SSSDConfig/sssdoptions.py:542 msgid "Sudo rule notafter attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:537 +#: src/config/SSSDConfig/sssdoptions.py:543 msgid "Sudo rule order attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:540 +#: src/config/SSSDConfig/sssdoptions.py:546 msgid "Object class for automounter maps" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:541 +#: src/config/SSSDConfig/sssdoptions.py:547 msgid "Automounter map name attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:542 +#: src/config/SSSDConfig/sssdoptions.py:548 msgid "Object class for automounter map entries" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:543 +#: src/config/SSSDConfig/sssdoptions.py:549 msgid "Automounter map entry key attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:544 +#: src/config/SSSDConfig/sssdoptions.py:550 msgid "Automounter map entry value attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:545 +#: src/config/SSSDConfig/sssdoptions.py:551 msgid "Base DN for automounter map lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:546 +#: src/config/SSSDConfig/sssdoptions.py:552 msgid "The name of the automount master map in LDAP." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:549 +#: src/config/SSSDConfig/sssdoptions.py:555 msgid "Base DN for IP hosts lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:550 +#: src/config/SSSDConfig/sssdoptions.py:556 msgid "Object class for IP hosts" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:551 +#: src/config/SSSDConfig/sssdoptions.py:557 msgid "IP host name attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:552 +#: src/config/SSSDConfig/sssdoptions.py:558 msgid "IP host number (address) attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:553 +#: src/config/SSSDConfig/sssdoptions.py:559 msgid "IP host entryUSN attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:554 +#: src/config/SSSDConfig/sssdoptions.py:560 msgid "Base DN for IP networks lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:555 +#: src/config/SSSDConfig/sssdoptions.py:561 msgid "Object class for IP networks" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:556 +#: src/config/SSSDConfig/sssdoptions.py:562 msgid "IP network name attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:557 +#: src/config/SSSDConfig/sssdoptions.py:563 msgid "IP network number (address) attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:558 +#: src/config/SSSDConfig/sssdoptions.py:564 msgid "IP network entryUSN attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:561 +#: src/config/SSSDConfig/sssdoptions.py:567 msgid "Comma separated list of allowed users" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:562 +#: src/config/SSSDConfig/sssdoptions.py:568 msgid "Comma separated list of prohibited users" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:563 +#: src/config/SSSDConfig/sssdoptions.py:569 msgid "" "Comma separated list of groups that are allowed to log in. This applies only " "to groups within this SSSD domain. Local groups are not evaluated." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:565 +#: src/config/SSSDConfig/sssdoptions.py:571 msgid "" "Comma separated list of groups that are explicitly denied access. This " "applies only to groups within this SSSD domain. Local groups are not " "evaluated." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:569 +#: src/config/SSSDConfig/sssdoptions.py:575 msgid "The number of preforked proxy children." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:572 +#: src/config/SSSDConfig/sssdoptions.py:578 msgid "The name of the NSS library to use" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:573 +#: src/config/SSSDConfig/sssdoptions.py:579 msgid "The name of the NSS library to use for hosts and networks lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:574 +#: src/config/SSSDConfig/sssdoptions.py:580 msgid "Whether to look up canonical group name from cache if possible" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:577 +#: src/config/SSSDConfig/sssdoptions.py:583 msgid "PAM stack to use" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:580 +#: src/config/SSSDConfig/sssdoptions.py:586 msgid "Path of passwd file sources." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:581 +#: src/config/SSSDConfig/sssdoptions.py:587 msgid "Path of group file sources." msgstr "" @@ -1888,226 +1923,234 @@ msgstr "" msgid "Option -i|--interactive is not allowed together with -D|--daemon\n" msgstr "" -#: src/monitor/monitor.c:1836 +#: src/monitor/monitor.c:1838 msgid "Failed to get initial capabilities\n" msgstr "" -#: src/monitor/monitor.c:1847 +#: src/monitor/monitor.c:1849 msgid "Non-root service user support isn't built. Can't run under %" msgstr "" -#: src/monitor/monitor.c:1864 +#: src/monitor/monitor.c:1866 #, c-format msgid "Can't read config: '%s'\n" msgstr "" -#: src/monitor/monitor.c:1876 +#: src/monitor/monitor.c:1878 #, c-format -msgid "Failed to boostrap SSSD 'monitor' process: %s" +msgid "Failed to bootstrap SSSD 'monitor' process: %s" msgstr "" -#: src/monitor/monitor.c:1971 +#: src/monitor/monitor.c:1973 msgid "Out of memory\n" msgstr "Elfogyott a memória\n" -#: src/providers/krb5/krb5_child.c:4221 +#: src/providers/krb5/krb5_child.c:4316 msgid "Use anonymous PKINIT to request FAST armor ticket" msgstr "" -#: src/providers/krb5/krb5_child.c:4223 +#: src/providers/krb5/krb5_child.c:4318 msgid "Kerberos realm to use" msgstr "" -#: src/providers/krb5/krb5_child.c:4225 +#: src/providers/krb5/krb5_child.c:4320 msgid "Requested lifetime of the ticket" msgstr "" -#: src/providers/krb5/krb5_child.c:4227 +#: src/providers/krb5/krb5_child.c:4322 msgid "Requested renewable lifetime of the ticket" msgstr "" -#: src/providers/krb5/krb5_child.c:4229 +#: src/providers/krb5/krb5_child.c:4324 msgid "FAST options ('never', 'try', 'demand')" msgstr "" -#: src/providers/krb5/krb5_child.c:4232 +#: src/providers/krb5/krb5_child.c:4327 msgid "Specifies the server principal to use for FAST" msgstr "" -#: src/providers/krb5/krb5_child.c:4234 +#: src/providers/krb5/krb5_child.c:4329 msgid "Requests canonicalization of the principal name" msgstr "" -#: src/providers/krb5/krb5_child.c:4236 +#: src/providers/krb5/krb5_child.c:4331 msgid "Use custom version of krb5_get_init_creds_password" msgstr "" -#: src/providers/krb5/krb5_child.c:4238 +#: src/providers/krb5/krb5_child.c:4333 msgid "Check PAC flags" msgstr "" -#: src/providers/data_provider_be.c:790 +#: src/providers/krb5/krb5_child.c:4335 +msgid "Set environment variable (KEY=VALUE)" +msgstr "" + +#: src/providers/data_provider_be.c:786 msgid "Domain of the information provider (mandatory)" msgstr "" -#: src/sss_client/common.c:1165 +#: src/sss_client/common.c:1208 msgid "Socket has wrong ownership or permissions." msgstr "" -#: src/sss_client/common.c:1168 +#: src/sss_client/common.c:1211 msgid "Unexpected format of the server credential message." msgstr "" -#: src/sss_client/common.c:1171 +#: src/sss_client/common.c:1214 #, fuzzy msgid "SSSD is not run by trusted user." msgstr "Az SSSD nem root-ként fut." -#: src/sss_client/common.c:1174 +#: src/sss_client/common.c:1217 msgid "SSSD socket does not exist." msgstr "" -#: src/sss_client/common.c:1177 +#: src/sss_client/common.c:1220 msgid "Cannot get stat of SSSD socket." msgstr "" -#: src/sss_client/common.c:1182 +#: src/sss_client/common.c:1225 msgid "An error occurred, but no description can be found." msgstr "Hiba lépett fel, de nem érhetőek el részletek." -#: src/sss_client/common.c:1188 +#: src/sss_client/common.c:1231 msgid "Unexpected error while looking for an error description" msgstr "" -#: src/sss_client/pam_sss.c:74 +#: src/sss_client/pam_sss.c:135 msgid "Permission denied. " msgstr "" -#: src/sss_client/pam_sss.c:75 src/sss_client/pam_sss.c:843 -#: src/sss_client/pam_sss.c:854 +#: src/sss_client/pam_sss.c:136 src/sss_client/pam_sss.c:921 +#: src/sss_client/pam_sss.c:932 msgid "Server message: " msgstr "Szerver üzenete: " -#: src/sss_client/pam_sss.c:76 +#: src/sss_client/pam_sss.c:137 msgid "" "Kerberos TGT will not be granted upon login, user experience will be " "affected." msgstr "" -#: src/sss_client/pam_sss.c:77 +#: src/sss_client/pam_sss.c:138 msgid "Enter PIN:" msgstr "" -#: src/sss_client/pam_sss.c:320 +#: src/sss_client/pam_sss.c:385 msgid "Passwords do not match" msgstr "A jelszavak nem egyeznek" -#: src/sss_client/pam_sss.c:508 +#: src/sss_client/pam_sss.c:584 msgid "Password reset by root is not supported." msgstr "A jelszó root általi visszaállítása nem támogatott." -#: src/sss_client/pam_sss.c:549 +#: src/sss_client/pam_sss.c:625 msgid "Authenticated with cached credentials" msgstr "Azonosítva gyorsítótárazott adatbázisból" -#: src/sss_client/pam_sss.c:550 +#: src/sss_client/pam_sss.c:626 msgid ", your cached password will expire at: " msgstr ", a gyorsítótárazott jelszó lejár ekkor: " -#: src/sss_client/pam_sss.c:580 +#: src/sss_client/pam_sss.c:656 #, c-format msgid "Your password has expired. You have %1$d grace login(s) remaining." msgstr "" -#: src/sss_client/pam_sss.c:630 +#: src/sss_client/pam_sss.c:706 #, c-format msgid "Your password will expire in %1$d %2$s." msgstr "" -#: src/sss_client/pam_sss.c:633 +#: src/sss_client/pam_sss.c:709 #, fuzzy, c-format msgid "Your password has expired." msgstr ", a gyorsítótárazott jelszó lejár ekkor: " -#: src/sss_client/pam_sss.c:684 +#: src/sss_client/pam_sss.c:760 msgid "Authentication is denied until: " msgstr "A hitelesítés megtagadva, amíg: " -#: src/sss_client/pam_sss.c:705 +#: src/sss_client/pam_sss.c:781 msgid "System is offline, password change not possible" msgstr "A rendszer nem érhető el, a jelszó megváltoztatása nem lehetséges" -#: src/sss_client/pam_sss.c:720 +#: src/sss_client/pam_sss.c:796 msgid "" "After changing the OTP password, you need to log out and back in order to " "acquire a ticket" msgstr "" -#: src/sss_client/pam_sss.c:735 +#: src/sss_client/pam_sss.c:813 msgid "PIN locked" msgstr "" -#: src/sss_client/pam_sss.c:750 +#: src/sss_client/pam_sss.c:828 msgid "" "No Kerberos TGT granted as the server does not support this method. Your " "single-sign on(SSO) experience will be affected." msgstr "" -#: src/sss_client/pam_sss.c:840 src/sss_client/pam_sss.c:853 +#: src/sss_client/pam_sss.c:918 src/sss_client/pam_sss.c:931 msgid "Password change failed. " msgstr "A jelszó megváltoztatása nem sikerült. " -#: src/sss_client/pam_sss.c:1859 +#: src/sss_client/pam_sss.c:2028 #, c-format -msgid "Authenticate at %1$s and press ENTER." +msgid "Authenticate at \"%1$s\"." msgstr "" -#: src/sss_client/pam_sss.c:1862 +#: src/sss_client/pam_sss.c:2031 #, c-format -msgid "Authenticate with PIN %1$s at %2$s and press ENTER." +msgid "Authenticate with PIN \"%1$s\" at \"%2$s\"." msgstr "" -#: src/sss_client/pam_sss.c:2281 +#: src/sss_client/pam_sss.c:2470 msgid "Please (re)insert (different) Smartcard" msgstr "" -#: src/sss_client/pam_sss.c:2482 +#: src/sss_client/pam_sss.c:2700 msgid "New Password: " msgstr "Új jelszó: " -#: src/sss_client/pam_sss.c:2483 +#: src/sss_client/pam_sss.c:2701 msgid "Reenter new Password: " msgstr "Jelszó mégegyszer: " -#: src/sss_client/pam_sss.c:2676 src/sss_client/pam_sss.c:2679 +#: src/sss_client/pam_sss.c:2890 +msgid "Press ENTER to continue." +msgstr "" + +#: src/sss_client/pam_sss.c:2913 src/sss_client/pam_sss.c:2916 msgid "First Factor: " msgstr "" -#: src/sss_client/pam_sss.c:2677 src/sss_client/pam_sss.c:2851 +#: src/sss_client/pam_sss.c:2914 src/sss_client/pam_sss.c:3088 msgid "Second Factor (optional): " msgstr "" -#: src/sss_client/pam_sss.c:2680 src/sss_client/pam_sss.c:2855 +#: src/sss_client/pam_sss.c:2917 src/sss_client/pam_sss.c:3092 msgid "Second Factor: " msgstr "" -#: src/sss_client/pam_sss.c:2684 +#: src/sss_client/pam_sss.c:2921 msgid "Insert your passkey device, then press ENTER." msgstr "" -#: src/sss_client/pam_sss.c:2688 src/sss_client/pam_sss.c:2696 +#: src/sss_client/pam_sss.c:2925 src/sss_client/pam_sss.c:2933 msgid "Password: " msgstr "Jelszó: " -#: src/sss_client/pam_sss.c:2850 src/sss_client/pam_sss.c:2854 +#: src/sss_client/pam_sss.c:3087 src/sss_client/pam_sss.c:3091 msgid "First Factor (Current Password): " msgstr "" -#: src/sss_client/pam_sss.c:2874 +#: src/sss_client/pam_sss.c:3111 msgid "Current Password: " msgstr "Jelenlegi jelszó: " -#: src/sss_client/pam_sss.c:3248 +#: src/sss_client/pam_sss.c:3485 msgid "Password expired. Change your password now." msgstr "A jelszava lejárt, változtass meg most." @@ -2542,9 +2585,9 @@ msgstr "" #: src/tools/sssctl/sssctl_cache.c:835 src/tools/sssctl/sssctl_cache.c:918 #: src/tools/sssctl/sssctl_cache.c:950 src/tools/sssctl/sssctl_cache.c:956 #: src/tools/sssctl/sssctl_cache.c:1010 src/tools/sssctl/sssctl_cache.c:1034 -#: src/tools/sssctl/sssctl_cache.c:1085 src/tools/sssctl/sssctl_cache.c:1194 -#: src/tools/sssctl/sssctl_cache.c:1229 src/tools/sssctl/sssctl_cache.c:1235 -#: src/tools/sssctl/sssctl_cache.c:1244 +#: src/tools/sssctl/sssctl_cache.c:1085 src/tools/sssctl/sssctl_cache.c:1195 +#: src/tools/sssctl/sssctl_cache.c:1230 src/tools/sssctl/sssctl_cache.c:1236 +#: src/tools/sssctl/sssctl_cache.c:1245 msgid "talloc failed\n" msgstr "" @@ -2618,25 +2661,25 @@ msgstr "" msgid "Unable to remove downloaded GPO files: %s\n" msgstr "" -#: src/tools/sssctl/sssctl_cache.c:1165 +#: src/tools/sssctl/sssctl_cache.c:1166 #, c-format msgid "Failed to fetch cache entry: %s\n" msgstr "" -#: src/tools/sssctl/sssctl_cache.c:1170 +#: src/tools/sssctl/sssctl_cache.c:1171 msgid "Could not determine object domain\n" msgstr "" -#: src/tools/sssctl/sssctl_cache.c:1200 +#: src/tools/sssctl/sssctl_cache.c:1201 msgid "Could not find GUID attribute in GPO entry\n" msgstr "" -#: src/tools/sssctl/sssctl_cache.c:1206 +#: src/tools/sssctl/sssctl_cache.c:1207 #, c-format msgid "Failed to delete GPO: %s\n" msgstr "" -#: src/tools/sssctl/sssctl_cache.c:1210 +#: src/tools/sssctl/sssctl_cache.c:1211 #, c-format msgid "%s removed from cache\n" msgstr "" @@ -2724,39 +2767,39 @@ msgid "" "\"/my/path/sssd.conf\", the snippet dir \"/my/path/conf.d\" is used)" msgstr "" -#: src/tools/sssctl/sssctl_config.c:114 +#: src/tools/sssctl/sssctl_config.c:126 #, c-format msgid "File %1$s does not exist.\n" msgstr "" -#: src/tools/sssctl/sssctl_config.c:115 +#: src/tools/sssctl/sssctl_config.c:127 msgid "There is no configuration.\n" msgstr "" -#: src/tools/sssctl/sssctl_config.c:120 +#: src/tools/sssctl/sssctl_config.c:132 #, c-format msgid "Configuration validation failed: %s\n" msgstr "" -#: src/tools/sssctl/sssctl_config.c:121 +#: src/tools/sssctl/sssctl_config.c:133 msgid "Run with high debug level to see details.\n" msgstr "" -#: src/tools/sssctl/sssctl_config.c:130 -msgid "Failed to run validators" +#: src/tools/sssctl/sssctl_config.c:142 +msgid "Failed to run validators\n" msgstr "" -#: src/tools/sssctl/sssctl_config.c:134 +#: src/tools/sssctl/sssctl_config.c:146 #, c-format msgid "Issues identified by validators: %zu\n" msgstr "" -#: src/tools/sssctl/sssctl_config.c:145 +#: src/tools/sssctl/sssctl_config.c:157 #, c-format msgid "Messages generated during configuration merging: %zu\n" msgstr "" -#: src/tools/sssctl/sssctl_config.c:158 +#: src/tools/sssctl/sssctl_config.c:170 #, c-format msgid "Used configuration snippet files: %zu\n" msgstr "" diff --git a/po/id.po b/po/id.po index 05dd4f0218b..bca09f52e76 100644 --- a/po/id.po +++ b/po/id.po @@ -3,13 +3,14 @@ # This file is distributed under the same license as the PACKAGE package. # # Translators: +# Glenn Mandagi , 2026. msgid "" msgstr "" "Project-Id-Version: PACKAGE VERSION\n" "Report-Msgid-Bugs-To: sssd-devel@lists.fedorahosted.org\n" -"POT-Creation-Date: 2026-01-14 14:57+0000\n" -"PO-Revision-Date: 2026-04-23 16:47+0000\n" -"Last-Translator: Anonymous \n" +"POT-Creation-Date: 2026-10-02 15:57+0000\n" +"PO-Revision-Date: 2026-10-05 16:40+0000\n" +"Last-Translator: Glenn Mandagi \n" "Language-Team: Indonesian \n" "Language: id\n" @@ -17,50 +18,50 @@ msgstr "" "Content-Type: text/plain; charset=UTF-8\n" "Content-Transfer-Encoding: 8bit\n" "Plural-Forms: nplurals=1; plural=0;\n" -"X-Generator: Weblate 5.17\n" +"X-Generator: Weblate 2026.10\n" -#: src/config/SSSDConfig/sssdoptions.py:20 -#: src/config/SSSDConfig/sssdoptions.py:21 +#: src/config/SSSDConfig/sssdoptions.py:16 +#: src/config/SSSDConfig/sssdoptions.py:17 msgid "Set the verbosity of the debug logging" msgstr "Mengatur verbosity dari pencatatan debug" -#: src/config/SSSDConfig/sssdoptions.py:22 +#: src/config/SSSDConfig/sssdoptions.py:18 msgid "Include timestamps in debug logs" msgstr "Sertakan cap waktu di pencatatan debug" -#: src/config/SSSDConfig/sssdoptions.py:23 +#: src/config/SSSDConfig/sssdoptions.py:19 msgid "Include microseconds in timestamps in debug logs" -msgstr "" +msgstr "Sertakan mikrosekon dalam timestamp di log debug." -#: src/config/SSSDConfig/sssdoptions.py:24 +#: src/config/SSSDConfig/sssdoptions.py:20 msgid "Enable/disable debug backtrace" -msgstr "" +msgstr "Aktifkan/nonaktifkan debug backtrace" -#: src/config/SSSDConfig/sssdoptions.py:25 +#: src/config/SSSDConfig/sssdoptions.py:21 msgid "Watchdog timeout before restarting service" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:26 +#: src/config/SSSDConfig/sssdoptions.py:22 msgid "Command to start service" msgstr "Perintah untuk memulai layanan" -#: src/config/SSSDConfig/sssdoptions.py:27 +#: src/config/SSSDConfig/sssdoptions.py:23 msgid "The number of file descriptors that may be opened by this responder" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:28 +#: src/config/SSSDConfig/sssdoptions.py:24 msgid "Idle time before automatic disconnection of a client" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:29 +#: src/config/SSSDConfig/sssdoptions.py:25 msgid "Idle time before automatic shutdown of the responder" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:30 +#: src/config/SSSDConfig/sssdoptions.py:26 msgid "Always query all the caches before querying the Data Providers" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:31 +#: src/config/SSSDConfig/sssdoptions.py:27 msgid "" "When SSSD switches to offline mode the amount of time before it tries to go " "back online will increase based upon the time spent disconnected. This value " @@ -68,63 +69,63 @@ msgid "" "random_offset." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:36 +#: src/config/SSSDConfig/sssdoptions.py:32 msgid "SSSD Services to start" msgstr "Layanan SSSD akan dijalankan" -#: src/config/SSSDConfig/sssdoptions.py:37 +#: src/config/SSSDConfig/sssdoptions.py:33 msgid "SSSD Domains to start" msgstr "Domain SSSD akan dijalankan" -#: src/config/SSSDConfig/sssdoptions.py:38 +#: src/config/SSSDConfig/sssdoptions.py:34 msgid "Regex to parse username and domain" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:39 +#: src/config/SSSDConfig/sssdoptions.py:35 msgid "Printf-compatible format for displaying fully-qualified names" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:40 +#: src/config/SSSDConfig/sssdoptions.py:36 msgid "" "Directory on the filesystem where SSSD should store Kerberos replay cache " "files." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:41 +#: src/config/SSSDConfig/sssdoptions.py:37 msgid "Domain to add to names without a domain component." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:42 +#: src/config/SSSDConfig/sssdoptions.py:38 msgid "The user to drop privileges to" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:43 +#: src/config/SSSDConfig/sssdoptions.py:39 msgid "Tune certificate verification" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:44 +#: src/config/SSSDConfig/sssdoptions.py:40 msgid "All spaces in group or user names will be replaced with this character" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:45 +#: src/config/SSSDConfig/sssdoptions.py:41 msgid "Tune sssd to honor or ignore netlink state changes" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:46 +#: src/config/SSSDConfig/sssdoptions.py:42 msgid "Enable or disable the implicit files domain" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:47 +#: src/config/SSSDConfig/sssdoptions.py:43 msgid "A specific order of the domains to be looked up" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:48 +#: src/config/SSSDConfig/sssdoptions.py:44 msgid "" "Controls if SSSD should monitor the state of resolv.conf to identify when it " "needs to update its internal DNS resolver." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:50 +#: src/config/SSSDConfig/sssdoptions.py:46 msgid "" "SSSD monitors the state of resolv.conf to identify when it needs to update " "its internal DNS resolver. By default, we will attempt to use inotify for " @@ -132,394 +133,401 @@ msgid "" "inotify cannot be used." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:53 +#: src/config/SSSDConfig/sssdoptions.py:49 msgid "Run PAC responder automatically for AD and IPA provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:54 +#: src/config/SSSDConfig/sssdoptions.py:50 msgid "Enable or disable core dumps for all SSSD processes." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:55 +#: src/config/SSSDConfig/sssdoptions.py:51 msgid "Tune passkey verification behavior" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:58 +#: src/config/SSSDConfig/sssdoptions.py:54 msgid "Enumeration cache timeout length (seconds)" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:59 +#: src/config/SSSDConfig/sssdoptions.py:55 msgid "Entry cache background update timeout length (seconds)" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:60 -#: src/config/SSSDConfig/sssdoptions.py:125 +#: src/config/SSSDConfig/sssdoptions.py:56 +#: src/config/SSSDConfig/sssdoptions.py:124 msgid "Negative cache timeout length (seconds)" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:61 +#: src/config/SSSDConfig/sssdoptions.py:57 msgid "Users that SSSD should explicitly ignore" msgstr "Pengguna yang diabaikan secara eksplisit oleh SSSD" -#: src/config/SSSDConfig/sssdoptions.py:62 +#: src/config/SSSDConfig/sssdoptions.py:58 msgid "Groups that SSSD should explicitly ignore" msgstr "Grup yang diabaikan secara eksplisit oleh SSSD" -#: src/config/SSSDConfig/sssdoptions.py:63 +#: src/config/SSSDConfig/sssdoptions.py:59 msgid "Should filtered users appear in groups" msgstr "Haruskah pengguna yang disaring muncul dalam grup" -#: src/config/SSSDConfig/sssdoptions.py:64 +#: src/config/SSSDConfig/sssdoptions.py:60 msgid "The value of the password field the NSS provider should return" msgstr "Nilai kolom kata sandi yang harus dikembalikan oleh penyedia NSS" -#: src/config/SSSDConfig/sssdoptions.py:65 +#: src/config/SSSDConfig/sssdoptions.py:61 msgid "Override homedir value from the identity provider with this value" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:66 +#: src/config/SSSDConfig/sssdoptions.py:62 msgid "" "Substitute empty homedir value from the identity provider with this value" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:67 +#: src/config/SSSDConfig/sssdoptions.py:63 msgid "Override shell value from the identity provider with this value" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:68 +#: src/config/SSSDConfig/sssdoptions.py:64 msgid "The list of shells users are allowed to log in with" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:69 +#: src/config/SSSDConfig/sssdoptions.py:65 msgid "" "The list of shells that will be vetoed, and replaced with the fallback shell" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:70 +#: src/config/SSSDConfig/sssdoptions.py:66 msgid "" "If a shell stored in central directory is allowed but not available, use " "this fallback" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:71 +#: src/config/SSSDConfig/sssdoptions.py:67 msgid "Shell to use if the provider does not list one" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:72 +#: src/config/SSSDConfig/sssdoptions.py:68 msgid "How long will be in-memory cache records valid" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:74 +#: src/config/SSSDConfig/sssdoptions.py:70 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for passwd requests" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:76 +#: src/config/SSSDConfig/sssdoptions.py:72 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for group requests" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:78 +#: src/config/SSSDConfig/sssdoptions.py:74 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for initgroups requests" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:79 +#: src/config/SSSDConfig/sssdoptions.py:75 msgid "" "The value of this option will be used in the expansion of the " "override_homedir option if the template contains the format string %H." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:81 +#: src/config/SSSDConfig/sssdoptions.py:77 msgid "" "Specifies time in seconds for which the list of subdomains will be " "considered valid." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:83 +#: src/config/SSSDConfig/sssdoptions.py:79 msgid "" "The entry cache can be set to automatically update entries in the background " "if they are requested beyond a percentage of the entry_cache_timeout value " "for the domain." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:88 +#: src/config/SSSDConfig/sssdoptions.py:84 msgid "How long to allow cached logins between online logins (days)" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:89 +#: src/config/SSSDConfig/sssdoptions.py:85 msgid "How many failed logins attempts are allowed when offline" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:91 +#: src/config/SSSDConfig/sssdoptions.py:87 msgid "" "How long (minutes) to deny login after offline_failed_login_attempts has " "been reached" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:92 +#: src/config/SSSDConfig/sssdoptions.py:88 msgid "What kind of messages are displayed to the user during authentication" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:93 +#: src/config/SSSDConfig/sssdoptions.py:89 msgid "Filter PAM responses sent to the pam_sss" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:94 +#: src/config/SSSDConfig/sssdoptions.py:90 msgid "How many seconds to keep identity information cached for PAM requests" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:95 +#: src/config/SSSDConfig/sssdoptions.py:91 msgid "How many days before password expiration a warning should be displayed" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:96 +#: src/config/SSSDConfig/sssdoptions.py:92 msgid "List of trusted uids or user's name" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:97 +#: src/config/SSSDConfig/sssdoptions.py:93 msgid "List of domains accessible even for untrusted users." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:98 +#: src/config/SSSDConfig/sssdoptions.py:94 msgid "Message printed when user account is expired." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:99 +#: src/config/SSSDConfig/sssdoptions.py:95 msgid "Message printed when user account is locked." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:100 +#: src/config/SSSDConfig/sssdoptions.py:96 msgid "Allow certificate based/Smartcard authentication." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:101 +#: src/config/SSSDConfig/sssdoptions.py:97 msgid "Path to certificate database with PKCS#11 modules." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:102 +#: src/config/SSSDConfig/sssdoptions.py:98 #, fuzzy msgid "Tune certificate verification for PAM authentication." msgstr "Membutuhkan verifikasi sertifikat TLS" -#: src/config/SSSDConfig/sssdoptions.py:103 +#: src/config/SSSDConfig/sssdoptions.py:99 msgid "How many seconds will pam_sss wait for p11_child to finish" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:104 +#: src/config/SSSDConfig/sssdoptions.py:100 msgid "Which PAM services are permitted to contact application domains" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:105 +#: src/config/SSSDConfig/sssdoptions.py:101 msgid "Allowed services for using smartcards" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:106 +#: src/config/SSSDConfig/sssdoptions.py:102 msgid "Additional timeout to wait for a card if requested" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:107 +#: src/config/SSSDConfig/sssdoptions.py:103 msgid "" "PKCS#11 URI to restrict the selection of devices for Smartcard authentication" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:108 +#: src/config/SSSDConfig/sssdoptions.py:104 msgid "When shall the PAM responder force an initgroups request" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:109 +#: src/config/SSSDConfig/sssdoptions.py:105 msgid "List of PAM services that are allowed to authenticate with GSSAPI." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:110 +#: src/config/SSSDConfig/sssdoptions.py:106 msgid "Whether to match authenticated UPN with target user" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:111 +#: src/config/SSSDConfig/sssdoptions.py:107 msgid "" "List of pairs : that must be enforced " "for PAM access with GSSAPI authentication" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:113 +#: src/config/SSSDConfig/sssdoptions.py:109 +msgid "" +"List of triples :: that assigns " +"additional information from the Kerberos ticket to an authentication " +"indicator." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:112 msgid "Allow passkey device authentication." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:114 +#: src/config/SSSDConfig/sssdoptions.py:113 msgid "How many seconds will pam_sss wait for passkey_child to finish" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:115 +#: src/config/SSSDConfig/sssdoptions.py:114 msgid "Enable debugging in the libfido2 library" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:116 +#: src/config/SSSDConfig/sssdoptions.py:115 msgid "Enable JSON protocol for authentication methods selection." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:119 +#: src/config/SSSDConfig/sssdoptions.py:118 msgid "Whether to evaluate the time-based attributes in sudo rules" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:120 +#: src/config/SSSDConfig/sssdoptions.py:119 msgid "If true, SSSD will switch back to lower-wins ordering logic" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:121 +#: src/config/SSSDConfig/sssdoptions.py:120 msgid "" "Maximum number of rules that can be refreshed at once. If this is exceeded, " "full refresh is performed." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:128 +#: src/config/SSSDConfig/sssdoptions.py:127 msgid "Whether to hash host names and addresses in the known_hosts file" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:129 +#: src/config/SSSDConfig/sssdoptions.py:128 msgid "" "How many seconds to keep a host in the known_hosts file after its host keys " "were requested" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:131 +#: src/config/SSSDConfig/sssdoptions.py:130 msgid "Path to storage of trusted CA certificates" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:132 +#: src/config/SSSDConfig/sssdoptions.py:131 msgid "Allow to generate ssh-keys from certificates" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:133 +#: src/config/SSSDConfig/sssdoptions.py:132 msgid "" "Use the following matching rules to filter the certificates for ssh-key " "generation" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:137 +#: src/config/SSSDConfig/sssdoptions.py:136 msgid "List of UIDs or user names allowed to access the PAC responder" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:138 +#: src/config/SSSDConfig/sssdoptions.py:137 msgid "How long the PAC data is considered valid" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:139 +#: src/config/SSSDConfig/sssdoptions.py:138 msgid "Validate the PAC" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:142 +#: src/config/SSSDConfig/sssdoptions.py:141 msgid "List of user attributes the InfoPipe is allowed to publish" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:145 +#: src/config/SSSDConfig/sssdoptions.py:144 msgid "" "One of the following strings specifying the scope of session recording: none " "- No users are recorded. some - Users/groups specified by users and groups " "options are recorded. all - All users are recorded." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:148 +#: src/config/SSSDConfig/sssdoptions.py:147 msgid "" "A comma-separated list of users which should have session recording enabled. " "Matches user names as returned by NSS. I.e. after the possible space " "replacement, case changes, etc." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:150 +#: src/config/SSSDConfig/sssdoptions.py:149 msgid "" "A comma-separated list of groups, members of which should have session " "recording enabled. Matches group names as returned by NSS. I.e. after the " "possible space replacement, case changes, etc." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:153 +#: src/config/SSSDConfig/sssdoptions.py:152 msgid "" "A comma-separated list of users to be excluded from recording, only when " "scope=all" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:154 +#: src/config/SSSDConfig/sssdoptions.py:153 msgid "" "A comma-separated list of groups, members of which should be excluded from " "recording, only when scope=all. " msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:158 +#: src/config/SSSDConfig/sssdoptions.py:157 msgid "Identity provider" msgstr "Penyedia identitas" -#: src/config/SSSDConfig/sssdoptions.py:159 +#: src/config/SSSDConfig/sssdoptions.py:158 msgid "Authentication provider" msgstr "Penyedia otentikasi" -#: src/config/SSSDConfig/sssdoptions.py:160 +#: src/config/SSSDConfig/sssdoptions.py:159 msgid "Access control provider" msgstr "Penyedia kontrol akses" -#: src/config/SSSDConfig/sssdoptions.py:161 +#: src/config/SSSDConfig/sssdoptions.py:160 msgid "Password change provider" msgstr "Penyedia pengubah kata sandi" -#: src/config/SSSDConfig/sssdoptions.py:162 +#: src/config/SSSDConfig/sssdoptions.py:161 msgid "SUDO provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:163 +#: src/config/SSSDConfig/sssdoptions.py:162 msgid "Autofs provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:164 +#: src/config/SSSDConfig/sssdoptions.py:163 msgid "Host identity provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:165 +#: src/config/SSSDConfig/sssdoptions.py:164 msgid "SELinux provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:166 +#: src/config/SSSDConfig/sssdoptions.py:165 msgid "Session management provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:167 +#: src/config/SSSDConfig/sssdoptions.py:166 msgid "Resolver provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:170 +#: src/config/SSSDConfig/sssdoptions.py:169 msgid "Whether the domain is usable by the OS or by applications" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:171 +#: src/config/SSSDConfig/sssdoptions.py:170 msgid "Enable or disable the domain" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:172 +#: src/config/SSSDConfig/sssdoptions.py:171 msgid "Minimum user ID" msgstr "ID pengguna minimum" -#: src/config/SSSDConfig/sssdoptions.py:173 +#: src/config/SSSDConfig/sssdoptions.py:172 msgid "Maximum user ID" msgstr "ID pengguna maksimum" -#: src/config/SSSDConfig/sssdoptions.py:174 +#: src/config/SSSDConfig/sssdoptions.py:173 msgid "Enable enumerating all users/groups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:175 +#: src/config/SSSDConfig/sssdoptions.py:174 msgid "Cache credentials for offline login" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:176 +#: src/config/SSSDConfig/sssdoptions.py:175 msgid "Display users/groups in fully-qualified form" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:177 +#: src/config/SSSDConfig/sssdoptions.py:176 msgid "Don't include group members in group lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:178 +#: src/config/SSSDConfig/sssdoptions.py:177 #: src/config/SSSDConfig/sssdoptions.py:190 #: src/config/SSSDConfig/sssdoptions.py:191 #: src/config/SSSDConfig/sssdoptions.py:192 @@ -530,48 +538,52 @@ msgstr "" msgid "Entry cache timeout length (seconds)" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:179 +#: src/config/SSSDConfig/sssdoptions.py:178 msgid "" "Restrict or prefer a specific address family when performing DNS lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:180 +#: src/config/SSSDConfig/sssdoptions.py:179 msgid "How long to keep cached entries after last successful login (days)" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:181 +#: src/config/SSSDConfig/sssdoptions.py:180 msgid "" "How long should SSSD talk to single DNS server before trying next server " "(miliseconds)" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:183 +#: src/config/SSSDConfig/sssdoptions.py:182 msgid "How long should keep trying to resolve single DNS query (seconds)" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:184 +#: src/config/SSSDConfig/sssdoptions.py:183 msgid "How long to wait for replies from DNS when resolving servers (seconds)" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:185 +#: src/config/SSSDConfig/sssdoptions.py:184 msgid "The domain part of service discovery DNS query" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:186 +#: src/config/SSSDConfig/sssdoptions.py:185 msgid "" "Specifies the interval, in seconds, that SSSD waits before attempting to " "reconnect to the primary server after a successful connection to the backup " "server" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:188 +#: src/config/SSSDConfig/sssdoptions.py:187 msgid "Override GID value from the identity provider with this value" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:189 +#: src/config/SSSDConfig/sssdoptions.py:188 msgid "Treat usernames as case sensitive" msgstr "" +#: src/config/SSSDConfig/sssdoptions.py:189 +msgid "Lookups by ID are expensive or do not work at all" +msgstr "" + #: src/config/SSSDConfig/sssdoptions.py:197 msgid "How often should expired entries be refreshed in background" msgstr "" @@ -792,7 +804,7 @@ msgid "Search base for SUBID ranges" msgstr "" #: src/config/SSSDConfig/sssdoptions.py:259 -#: src/config/SSSDConfig/sssdoptions.py:506 +#: src/config/SSSDConfig/sssdoptions.py:512 msgid "Which rules should be used to evaluate access control" msgstr "" @@ -934,7 +946,7 @@ msgid "Enable DNS sites - location based service discovery" msgstr "" #: src/config/SSSDConfig/sssdoptions.py:301 -#: src/config/SSSDConfig/sssdoptions.py:504 +#: src/config/SSSDConfig/sssdoptions.py:510 msgid "LDAP filter to determine access privileges" msgstr "" @@ -1354,7 +1366,7 @@ msgid "UUID attribute" msgstr "" #: src/config/SSSDConfig/sssdoptions.py:423 -#: src/config/SSSDConfig/sssdoptions.py:464 +#: src/config/SSSDConfig/sssdoptions.py:470 msgid "objectSID attribute" msgstr "" @@ -1478,385 +1490,411 @@ msgstr "" msgid "A list of extra attributes to download along with the user entry" msgstr "" +#: src/config/SSSDConfig/sssdoptions.py:456 +msgid "The object class of an subid entry in LDAP." +msgstr "" + #: src/config/SSSDConfig/sssdoptions.py:457 +#, fuzzy +msgid "Subordinate user ID count attribute" +msgstr "Atribut GID Primer" + +#: src/config/SSSDConfig/sssdoptions.py:458 +msgid "Subordinate group ID count attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:459 +#, fuzzy +msgid "User ID range start value attribute" +msgstr "Atribut Nama pengguna" + +#: src/config/SSSDConfig/sssdoptions.py:460 +msgid "Group ID range start value attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:461 +msgid "Owner of an entry" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:463 msgid "Base DN for group lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:458 +#: src/config/SSSDConfig/sssdoptions.py:464 msgid "Objectclass for groups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:459 +#: src/config/SSSDConfig/sssdoptions.py:465 msgid "Group name" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:460 +#: src/config/SSSDConfig/sssdoptions.py:466 msgid "Group password" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:461 +#: src/config/SSSDConfig/sssdoptions.py:467 msgid "GID attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:462 +#: src/config/SSSDConfig/sssdoptions.py:468 msgid "Group member attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:463 +#: src/config/SSSDConfig/sssdoptions.py:469 msgid "Group UUID attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:465 +#: src/config/SSSDConfig/sssdoptions.py:471 msgid "Modification time attribute for groups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:466 +#: src/config/SSSDConfig/sssdoptions.py:472 msgid "Type of the group and other flags" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:467 +#: src/config/SSSDConfig/sssdoptions.py:473 msgid "The LDAP group external member attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:468 +#: src/config/SSSDConfig/sssdoptions.py:474 msgid "Maximum nesting level SSSD will follow" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:469 +#: src/config/SSSDConfig/sssdoptions.py:475 msgid "Filter for group lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:470 +#: src/config/SSSDConfig/sssdoptions.py:476 msgid "Scope of group lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:472 +#: src/config/SSSDConfig/sssdoptions.py:478 msgid "Base DN for netgroup lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:473 +#: src/config/SSSDConfig/sssdoptions.py:479 msgid "Objectclass for netgroups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:474 +#: src/config/SSSDConfig/sssdoptions.py:480 msgid "Netgroup name" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:475 +#: src/config/SSSDConfig/sssdoptions.py:481 msgid "Netgroups members attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:476 +#: src/config/SSSDConfig/sssdoptions.py:482 msgid "Netgroup triple attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:477 +#: src/config/SSSDConfig/sssdoptions.py:483 msgid "Modification time attribute for netgroups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:479 +#: src/config/SSSDConfig/sssdoptions.py:485 msgid "Base DN for service lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:480 +#: src/config/SSSDConfig/sssdoptions.py:486 msgid "Objectclass for services" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:481 +#: src/config/SSSDConfig/sssdoptions.py:487 msgid "Service name attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:482 +#: src/config/SSSDConfig/sssdoptions.py:488 msgid "Service port attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:483 +#: src/config/SSSDConfig/sssdoptions.py:489 msgid "Service protocol attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:485 +#: src/config/SSSDConfig/sssdoptions.py:491 msgid "Lower bound for ID-mapping" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:486 +#: src/config/SSSDConfig/sssdoptions.py:492 msgid "Upper bound for ID-mapping" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:487 +#: src/config/SSSDConfig/sssdoptions.py:493 msgid "Number of IDs for each slice when ID-mapping" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:488 +#: src/config/SSSDConfig/sssdoptions.py:494 msgid "Use autorid-compatible algorithm for ID-mapping" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:489 +#: src/config/SSSDConfig/sssdoptions.py:495 msgid "Name of the default domain for ID-mapping" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:490 +#: src/config/SSSDConfig/sssdoptions.py:496 msgid "SID of the default domain for ID-mapping" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:491 +#: src/config/SSSDConfig/sssdoptions.py:497 msgid "Number of secondary slices" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:493 +#: src/config/SSSDConfig/sssdoptions.py:499 msgid "Whether to use Token-Groups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:494 +#: src/config/SSSDConfig/sssdoptions.py:500 msgid "Set lower boundary for allowed IDs from the LDAP server" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:495 +#: src/config/SSSDConfig/sssdoptions.py:501 msgid "Set upper boundary for allowed IDs from the LDAP server" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:496 +#: src/config/SSSDConfig/sssdoptions.py:502 msgid "DN for ppolicy queries" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:497 +#: src/config/SSSDConfig/sssdoptions.py:503 msgid "How many maximum entries to fetch during a wildcard request" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:498 +#: src/config/SSSDConfig/sssdoptions.py:504 msgid "Set libldap debug level" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:501 +#: src/config/SSSDConfig/sssdoptions.py:507 msgid "Policy to evaluate the password expiration" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:505 +#: src/config/SSSDConfig/sssdoptions.py:511 msgid "Which attributes shall be used to evaluate if an account is expired" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:509 +#: src/config/SSSDConfig/sssdoptions.py:515 msgid "URI of an LDAP server where password changes are allowed" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:510 +#: src/config/SSSDConfig/sssdoptions.py:516 msgid "URI of a backup LDAP server where password changes are allowed" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:511 +#: src/config/SSSDConfig/sssdoptions.py:517 msgid "DNS service name for LDAP password change server" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:512 +#: src/config/SSSDConfig/sssdoptions.py:518 msgid "" "Whether to update the ldap_user_shadow_last_change attribute after a " "password change" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:516 +#: src/config/SSSDConfig/sssdoptions.py:522 msgid "Base DN for sudo rules lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:517 +#: src/config/SSSDConfig/sssdoptions.py:523 msgid "Automatic full refresh period" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:518 +#: src/config/SSSDConfig/sssdoptions.py:524 msgid "Automatic smart refresh period" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:519 +#: src/config/SSSDConfig/sssdoptions.py:525 msgid "Smart and full refresh random offset" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:520 +#: src/config/SSSDConfig/sssdoptions.py:526 msgid "Whether to filter rules by hostname, IP addresses and network" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:521 +#: src/config/SSSDConfig/sssdoptions.py:527 msgid "" "Hostnames and/or fully qualified domain names of this machine to filter sudo " "rules" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:522 +#: src/config/SSSDConfig/sssdoptions.py:528 msgid "IPv4 or IPv6 addresses or network of this machine to filter sudo rules" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:523 +#: src/config/SSSDConfig/sssdoptions.py:529 msgid "Whether to include rules that contains netgroup in host attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:524 +#: src/config/SSSDConfig/sssdoptions.py:530 msgid "" "Whether to include rules that contains regular expression in host attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:525 +#: src/config/SSSDConfig/sssdoptions.py:531 msgid "Object class for sudo rules" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:526 +#: src/config/SSSDConfig/sssdoptions.py:532 msgid "Name of attribute that is used as object class for sudo rules" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:527 +#: src/config/SSSDConfig/sssdoptions.py:533 msgid "Sudo rule name" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:528 +#: src/config/SSSDConfig/sssdoptions.py:534 msgid "Sudo rule command attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:529 +#: src/config/SSSDConfig/sssdoptions.py:535 msgid "Sudo rule host attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:530 +#: src/config/SSSDConfig/sssdoptions.py:536 msgid "Sudo rule user attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:531 +#: src/config/SSSDConfig/sssdoptions.py:537 msgid "Sudo rule option attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:532 +#: src/config/SSSDConfig/sssdoptions.py:538 msgid "Sudo rule runas attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:533 +#: src/config/SSSDConfig/sssdoptions.py:539 msgid "Sudo rule runasuser attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:534 +#: src/config/SSSDConfig/sssdoptions.py:540 msgid "Sudo rule runasgroup attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:535 +#: src/config/SSSDConfig/sssdoptions.py:541 msgid "Sudo rule notbefore attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:536 +#: src/config/SSSDConfig/sssdoptions.py:542 msgid "Sudo rule notafter attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:537 +#: src/config/SSSDConfig/sssdoptions.py:543 msgid "Sudo rule order attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:540 +#: src/config/SSSDConfig/sssdoptions.py:546 msgid "Object class for automounter maps" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:541 +#: src/config/SSSDConfig/sssdoptions.py:547 msgid "Automounter map name attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:542 +#: src/config/SSSDConfig/sssdoptions.py:548 msgid "Object class for automounter map entries" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:543 +#: src/config/SSSDConfig/sssdoptions.py:549 msgid "Automounter map entry key attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:544 +#: src/config/SSSDConfig/sssdoptions.py:550 msgid "Automounter map entry value attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:545 +#: src/config/SSSDConfig/sssdoptions.py:551 msgid "Base DN for automounter map lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:546 +#: src/config/SSSDConfig/sssdoptions.py:552 msgid "The name of the automount master map in LDAP." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:549 +#: src/config/SSSDConfig/sssdoptions.py:555 msgid "Base DN for IP hosts lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:550 +#: src/config/SSSDConfig/sssdoptions.py:556 msgid "Object class for IP hosts" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:551 +#: src/config/SSSDConfig/sssdoptions.py:557 msgid "IP host name attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:552 +#: src/config/SSSDConfig/sssdoptions.py:558 msgid "IP host number (address) attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:553 +#: src/config/SSSDConfig/sssdoptions.py:559 msgid "IP host entryUSN attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:554 +#: src/config/SSSDConfig/sssdoptions.py:560 msgid "Base DN for IP networks lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:555 +#: src/config/SSSDConfig/sssdoptions.py:561 msgid "Object class for IP networks" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:556 +#: src/config/SSSDConfig/sssdoptions.py:562 msgid "IP network name attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:557 +#: src/config/SSSDConfig/sssdoptions.py:563 msgid "IP network number (address) attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:558 +#: src/config/SSSDConfig/sssdoptions.py:564 msgid "IP network entryUSN attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:561 +#: src/config/SSSDConfig/sssdoptions.py:567 msgid "Comma separated list of allowed users" msgstr "Daftar pengguna yang diijinkan dalam format yang dipisahkan koma" -#: src/config/SSSDConfig/sssdoptions.py:562 +#: src/config/SSSDConfig/sssdoptions.py:568 msgid "Comma separated list of prohibited users" msgstr "Daftar pengguna yang tidak diijinkan dalam format yang dipisahkan koma" -#: src/config/SSSDConfig/sssdoptions.py:563 +#: src/config/SSSDConfig/sssdoptions.py:569 msgid "" "Comma separated list of groups that are allowed to log in. This applies only " "to groups within this SSSD domain. Local groups are not evaluated." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:565 +#: src/config/SSSDConfig/sssdoptions.py:571 msgid "" "Comma separated list of groups that are explicitly denied access. This " "applies only to groups within this SSSD domain. Local groups are not " "evaluated." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:569 +#: src/config/SSSDConfig/sssdoptions.py:575 msgid "The number of preforked proxy children." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:572 +#: src/config/SSSDConfig/sssdoptions.py:578 msgid "The name of the NSS library to use" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:573 +#: src/config/SSSDConfig/sssdoptions.py:579 msgid "The name of the NSS library to use for hosts and networks lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:574 +#: src/config/SSSDConfig/sssdoptions.py:580 msgid "Whether to look up canonical group name from cache if possible" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:577 +#: src/config/SSSDConfig/sssdoptions.py:583 msgid "PAM stack to use" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:580 +#: src/config/SSSDConfig/sssdoptions.py:586 msgid "Path of passwd file sources." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:581 +#: src/config/SSSDConfig/sssdoptions.py:587 msgid "Path of group file sources." msgstr "" @@ -1884,225 +1922,233 @@ msgstr "" msgid "Option -i|--interactive is not allowed together with -D|--daemon\n" msgstr "" -#: src/monitor/monitor.c:1836 +#: src/monitor/monitor.c:1838 msgid "Failed to get initial capabilities\n" msgstr "" -#: src/monitor/monitor.c:1847 +#: src/monitor/monitor.c:1849 msgid "Non-root service user support isn't built. Can't run under %" msgstr "" -#: src/monitor/monitor.c:1864 +#: src/monitor/monitor.c:1866 #, c-format msgid "Can't read config: '%s'\n" msgstr "" -#: src/monitor/monitor.c:1876 +#: src/monitor/monitor.c:1878 #, c-format -msgid "Failed to boostrap SSSD 'monitor' process: %s" +msgid "Failed to bootstrap SSSD 'monitor' process: %s" msgstr "" -#: src/monitor/monitor.c:1971 +#: src/monitor/monitor.c:1973 msgid "Out of memory\n" msgstr "Kehabisan memori\n" -#: src/providers/krb5/krb5_child.c:4221 +#: src/providers/krb5/krb5_child.c:4316 msgid "Use anonymous PKINIT to request FAST armor ticket" msgstr "" -#: src/providers/krb5/krb5_child.c:4223 +#: src/providers/krb5/krb5_child.c:4318 msgid "Kerberos realm to use" msgstr "" -#: src/providers/krb5/krb5_child.c:4225 +#: src/providers/krb5/krb5_child.c:4320 msgid "Requested lifetime of the ticket" msgstr "" -#: src/providers/krb5/krb5_child.c:4227 +#: src/providers/krb5/krb5_child.c:4322 msgid "Requested renewable lifetime of the ticket" msgstr "" -#: src/providers/krb5/krb5_child.c:4229 +#: src/providers/krb5/krb5_child.c:4324 msgid "FAST options ('never', 'try', 'demand')" msgstr "" -#: src/providers/krb5/krb5_child.c:4232 +#: src/providers/krb5/krb5_child.c:4327 msgid "Specifies the server principal to use for FAST" msgstr "" -#: src/providers/krb5/krb5_child.c:4234 +#: src/providers/krb5/krb5_child.c:4329 msgid "Requests canonicalization of the principal name" msgstr "" -#: src/providers/krb5/krb5_child.c:4236 +#: src/providers/krb5/krb5_child.c:4331 msgid "Use custom version of krb5_get_init_creds_password" msgstr "" -#: src/providers/krb5/krb5_child.c:4238 +#: src/providers/krb5/krb5_child.c:4333 msgid "Check PAC flags" msgstr "" -#: src/providers/data_provider_be.c:790 +#: src/providers/krb5/krb5_child.c:4335 +msgid "Set environment variable (KEY=VALUE)" +msgstr "" + +#: src/providers/data_provider_be.c:786 msgid "Domain of the information provider (mandatory)" msgstr "" -#: src/sss_client/common.c:1165 +#: src/sss_client/common.c:1208 msgid "Socket has wrong ownership or permissions." msgstr "" -#: src/sss_client/common.c:1168 +#: src/sss_client/common.c:1211 msgid "Unexpected format of the server credential message." msgstr "" -#: src/sss_client/common.c:1171 +#: src/sss_client/common.c:1214 msgid "SSSD is not run by trusted user." msgstr "" -#: src/sss_client/common.c:1174 +#: src/sss_client/common.c:1217 msgid "SSSD socket does not exist." msgstr "" -#: src/sss_client/common.c:1177 +#: src/sss_client/common.c:1220 msgid "Cannot get stat of SSSD socket." msgstr "" -#: src/sss_client/common.c:1182 +#: src/sss_client/common.c:1225 msgid "An error occurred, but no description can be found." msgstr "" -#: src/sss_client/common.c:1188 +#: src/sss_client/common.c:1231 msgid "Unexpected error while looking for an error description" msgstr "" -#: src/sss_client/pam_sss.c:74 +#: src/sss_client/pam_sss.c:135 msgid "Permission denied. " msgstr "" -#: src/sss_client/pam_sss.c:75 src/sss_client/pam_sss.c:843 -#: src/sss_client/pam_sss.c:854 +#: src/sss_client/pam_sss.c:136 src/sss_client/pam_sss.c:921 +#: src/sss_client/pam_sss.c:932 msgid "Server message: " msgstr "Pesan server:" -#: src/sss_client/pam_sss.c:76 +#: src/sss_client/pam_sss.c:137 msgid "" "Kerberos TGT will not be granted upon login, user experience will be " "affected." msgstr "" -#: src/sss_client/pam_sss.c:77 +#: src/sss_client/pam_sss.c:138 msgid "Enter PIN:" msgstr "" -#: src/sss_client/pam_sss.c:320 +#: src/sss_client/pam_sss.c:385 msgid "Passwords do not match" msgstr "Kata sandi tidak cocok" -#: src/sss_client/pam_sss.c:508 +#: src/sss_client/pam_sss.c:584 msgid "Password reset by root is not supported." msgstr "" -#: src/sss_client/pam_sss.c:549 +#: src/sss_client/pam_sss.c:625 msgid "Authenticated with cached credentials" msgstr "" -#: src/sss_client/pam_sss.c:550 +#: src/sss_client/pam_sss.c:626 msgid ", your cached password will expire at: " msgstr "" -#: src/sss_client/pam_sss.c:580 +#: src/sss_client/pam_sss.c:656 #, c-format msgid "Your password has expired. You have %1$d grace login(s) remaining." msgstr "" -#: src/sss_client/pam_sss.c:630 +#: src/sss_client/pam_sss.c:706 #, c-format msgid "Your password will expire in %1$d %2$s." msgstr "" -#: src/sss_client/pam_sss.c:633 +#: src/sss_client/pam_sss.c:709 #, fuzzy, c-format msgid "Your password has expired." msgstr "Perubahan kata sandi gagal." -#: src/sss_client/pam_sss.c:684 +#: src/sss_client/pam_sss.c:760 msgid "Authentication is denied until: " msgstr "" -#: src/sss_client/pam_sss.c:705 +#: src/sss_client/pam_sss.c:781 msgid "System is offline, password change not possible" msgstr "Sistem sedang luring, perubahan kata sandi tidak dimungkinkan" -#: src/sss_client/pam_sss.c:720 +#: src/sss_client/pam_sss.c:796 msgid "" "After changing the OTP password, you need to log out and back in order to " "acquire a ticket" msgstr "" -#: src/sss_client/pam_sss.c:735 +#: src/sss_client/pam_sss.c:813 msgid "PIN locked" msgstr "" -#: src/sss_client/pam_sss.c:750 +#: src/sss_client/pam_sss.c:828 msgid "" "No Kerberos TGT granted as the server does not support this method. Your " "single-sign on(SSO) experience will be affected." msgstr "" -#: src/sss_client/pam_sss.c:840 src/sss_client/pam_sss.c:853 +#: src/sss_client/pam_sss.c:918 src/sss_client/pam_sss.c:931 msgid "Password change failed. " msgstr "Perubahan kata sandi gagal." -#: src/sss_client/pam_sss.c:1859 +#: src/sss_client/pam_sss.c:2028 #, c-format -msgid "Authenticate at %1$s and press ENTER." +msgid "Authenticate at \"%1$s\"." msgstr "" -#: src/sss_client/pam_sss.c:1862 +#: src/sss_client/pam_sss.c:2031 #, c-format -msgid "Authenticate with PIN %1$s at %2$s and press ENTER." +msgid "Authenticate with PIN \"%1$s\" at \"%2$s\"." msgstr "" -#: src/sss_client/pam_sss.c:2281 +#: src/sss_client/pam_sss.c:2470 msgid "Please (re)insert (different) Smartcard" msgstr "" -#: src/sss_client/pam_sss.c:2482 +#: src/sss_client/pam_sss.c:2700 msgid "New Password: " msgstr "Kata Sandi Baru: " -#: src/sss_client/pam_sss.c:2483 +#: src/sss_client/pam_sss.c:2701 msgid "Reenter new Password: " msgstr "Masukkan lagi kata sandi baru:" -#: src/sss_client/pam_sss.c:2676 src/sss_client/pam_sss.c:2679 +#: src/sss_client/pam_sss.c:2890 +msgid "Press ENTER to continue." +msgstr "" + +#: src/sss_client/pam_sss.c:2913 src/sss_client/pam_sss.c:2916 msgid "First Factor: " msgstr "" -#: src/sss_client/pam_sss.c:2677 src/sss_client/pam_sss.c:2851 +#: src/sss_client/pam_sss.c:2914 src/sss_client/pam_sss.c:3088 msgid "Second Factor (optional): " msgstr "" -#: src/sss_client/pam_sss.c:2680 src/sss_client/pam_sss.c:2855 +#: src/sss_client/pam_sss.c:2917 src/sss_client/pam_sss.c:3092 msgid "Second Factor: " msgstr "" -#: src/sss_client/pam_sss.c:2684 +#: src/sss_client/pam_sss.c:2921 msgid "Insert your passkey device, then press ENTER." msgstr "" -#: src/sss_client/pam_sss.c:2688 src/sss_client/pam_sss.c:2696 +#: src/sss_client/pam_sss.c:2925 src/sss_client/pam_sss.c:2933 msgid "Password: " msgstr "Kata sandi:" -#: src/sss_client/pam_sss.c:2850 src/sss_client/pam_sss.c:2854 +#: src/sss_client/pam_sss.c:3087 src/sss_client/pam_sss.c:3091 msgid "First Factor (Current Password): " msgstr "" -#: src/sss_client/pam_sss.c:2874 +#: src/sss_client/pam_sss.c:3111 msgid "Current Password: " msgstr "Kata sandi saat ini:" -#: src/sss_client/pam_sss.c:3248 +#: src/sss_client/pam_sss.c:3485 msgid "Password expired. Change your password now." msgstr "" @@ -2537,9 +2583,9 @@ msgstr "" #: src/tools/sssctl/sssctl_cache.c:835 src/tools/sssctl/sssctl_cache.c:918 #: src/tools/sssctl/sssctl_cache.c:950 src/tools/sssctl/sssctl_cache.c:956 #: src/tools/sssctl/sssctl_cache.c:1010 src/tools/sssctl/sssctl_cache.c:1034 -#: src/tools/sssctl/sssctl_cache.c:1085 src/tools/sssctl/sssctl_cache.c:1194 -#: src/tools/sssctl/sssctl_cache.c:1229 src/tools/sssctl/sssctl_cache.c:1235 -#: src/tools/sssctl/sssctl_cache.c:1244 +#: src/tools/sssctl/sssctl_cache.c:1085 src/tools/sssctl/sssctl_cache.c:1195 +#: src/tools/sssctl/sssctl_cache.c:1230 src/tools/sssctl/sssctl_cache.c:1236 +#: src/tools/sssctl/sssctl_cache.c:1245 msgid "talloc failed\n" msgstr "" @@ -2613,25 +2659,25 @@ msgstr "" msgid "Unable to remove downloaded GPO files: %s\n" msgstr "" -#: src/tools/sssctl/sssctl_cache.c:1165 +#: src/tools/sssctl/sssctl_cache.c:1166 #, c-format msgid "Failed to fetch cache entry: %s\n" msgstr "" -#: src/tools/sssctl/sssctl_cache.c:1170 +#: src/tools/sssctl/sssctl_cache.c:1171 msgid "Could not determine object domain\n" msgstr "" -#: src/tools/sssctl/sssctl_cache.c:1200 +#: src/tools/sssctl/sssctl_cache.c:1201 msgid "Could not find GUID attribute in GPO entry\n" msgstr "" -#: src/tools/sssctl/sssctl_cache.c:1206 +#: src/tools/sssctl/sssctl_cache.c:1207 #, c-format msgid "Failed to delete GPO: %s\n" msgstr "" -#: src/tools/sssctl/sssctl_cache.c:1210 +#: src/tools/sssctl/sssctl_cache.c:1211 #, c-format msgid "%s removed from cache\n" msgstr "" @@ -2719,39 +2765,39 @@ msgid "" "\"/my/path/sssd.conf\", the snippet dir \"/my/path/conf.d\" is used)" msgstr "" -#: src/tools/sssctl/sssctl_config.c:114 +#: src/tools/sssctl/sssctl_config.c:126 #, c-format msgid "File %1$s does not exist.\n" msgstr "" -#: src/tools/sssctl/sssctl_config.c:115 +#: src/tools/sssctl/sssctl_config.c:127 msgid "There is no configuration.\n" msgstr "" -#: src/tools/sssctl/sssctl_config.c:120 +#: src/tools/sssctl/sssctl_config.c:132 #, c-format msgid "Configuration validation failed: %s\n" msgstr "" -#: src/tools/sssctl/sssctl_config.c:121 +#: src/tools/sssctl/sssctl_config.c:133 msgid "Run with high debug level to see details.\n" msgstr "" -#: src/tools/sssctl/sssctl_config.c:130 -msgid "Failed to run validators" +#: src/tools/sssctl/sssctl_config.c:142 +msgid "Failed to run validators\n" msgstr "" -#: src/tools/sssctl/sssctl_config.c:134 +#: src/tools/sssctl/sssctl_config.c:146 #, c-format msgid "Issues identified by validators: %zu\n" msgstr "" -#: src/tools/sssctl/sssctl_config.c:145 +#: src/tools/sssctl/sssctl_config.c:157 #, c-format msgid "Messages generated during configuration merging: %zu\n" msgstr "" -#: src/tools/sssctl/sssctl_config.c:158 +#: src/tools/sssctl/sssctl_config.c:170 #, c-format msgid "Used configuration snippet files: %zu\n" msgstr "" diff --git a/po/it.po b/po/it.po index 70734dc13e6..ff1bf22ded2 100644 --- a/po/it.po +++ b/po/it.po @@ -14,8 +14,8 @@ msgid "" msgstr "" "Project-Id-Version: PACKAGE VERSION\n" "Report-Msgid-Bugs-To: sssd-devel@lists.fedorahosted.org\n" -"POT-Creation-Date: 2026-01-14 14:57+0000\n" -"PO-Revision-Date: 2026-04-23 17:04+0000\n" +"POT-Creation-Date: 2026-10-02 15:57+0000\n" +"PO-Revision-Date: 2026-10-05 16:41+0000\n" "Last-Translator: Milo Casagrande \n" "Language-Team: Italian \n" @@ -24,51 +24,51 @@ msgstr "" "Content-Type: text/plain; charset=UTF-8\n" "Content-Transfer-Encoding: 8bit\n" "Plural-Forms: nplurals=2; plural=n != 1;\n" -"X-Generator: Weblate 5.17\n" +"X-Generator: Weblate 2026.10\n" -#: src/config/SSSDConfig/sssdoptions.py:20 -#: src/config/SSSDConfig/sssdoptions.py:21 +#: src/config/SSSDConfig/sssdoptions.py:16 +#: src/config/SSSDConfig/sssdoptions.py:17 msgid "Set the verbosity of the debug logging" msgstr "Imposta il livello di dettaglio dei messaggi di debug" -#: src/config/SSSDConfig/sssdoptions.py:22 +#: src/config/SSSDConfig/sssdoptions.py:18 msgid "Include timestamps in debug logs" msgstr "Include marcatura temporale nei messaggi di registro" -#: src/config/SSSDConfig/sssdoptions.py:23 +#: src/config/SSSDConfig/sssdoptions.py:19 msgid "Include microseconds in timestamps in debug logs" msgstr "Include i microsecondi nella marcatura temporale per il debug" -#: src/config/SSSDConfig/sssdoptions.py:24 +#: src/config/SSSDConfig/sssdoptions.py:20 msgid "Enable/disable debug backtrace" msgstr "Abilita/disabilita il backtrace del debug" -#: src/config/SSSDConfig/sssdoptions.py:25 +#: src/config/SSSDConfig/sssdoptions.py:21 msgid "Watchdog timeout before restarting service" msgstr "Timeout di controllo prima di riavviare il servizio" -#: src/config/SSSDConfig/sssdoptions.py:26 +#: src/config/SSSDConfig/sssdoptions.py:22 msgid "Command to start service" msgstr "Comando per avviare il servizio" -#: src/config/SSSDConfig/sssdoptions.py:27 +#: src/config/SSSDConfig/sssdoptions.py:23 msgid "The number of file descriptors that may be opened by this responder" msgstr "" "Il numero di descrittori file che possono essere aperti da questo responder" -#: src/config/SSSDConfig/sssdoptions.py:28 +#: src/config/SSSDConfig/sssdoptions.py:24 msgid "Idle time before automatic disconnection of a client" msgstr "Tempo di inattività prima della disconnessione automatica di un client" -#: src/config/SSSDConfig/sssdoptions.py:29 +#: src/config/SSSDConfig/sssdoptions.py:25 msgid "Idle time before automatic shutdown of the responder" msgstr "Tempo di inattività prima della disconnessione automatica di un client" -#: src/config/SSSDConfig/sssdoptions.py:30 +#: src/config/SSSDConfig/sssdoptions.py:26 msgid "Always query all the caches before querying the Data Providers" msgstr "Interrogare tutte le cache prima dei provider dati" -#: src/config/SSSDConfig/sssdoptions.py:31 +#: src/config/SSSDConfig/sssdoptions.py:27 msgid "" "When SSSD switches to offline mode the amount of time before it tries to go " "back online will increase based upon the time spent disconnected. This value " @@ -80,60 +80,60 @@ msgstr "" "espresso in secondi ed è calcolato come segue: offline_timeout + " "random_offset." -#: src/config/SSSDConfig/sssdoptions.py:36 +#: src/config/SSSDConfig/sssdoptions.py:32 msgid "SSSD Services to start" msgstr "Servizi SSSD da avviare" -#: src/config/SSSDConfig/sssdoptions.py:37 +#: src/config/SSSDConfig/sssdoptions.py:33 msgid "SSSD Domains to start" msgstr "Domini SSSD da avviare" -#: src/config/SSSDConfig/sssdoptions.py:38 +#: src/config/SSSDConfig/sssdoptions.py:34 msgid "Regex to parse username and domain" msgstr "Espressione regolare per leggere nome utente e dominio" -#: src/config/SSSDConfig/sssdoptions.py:39 +#: src/config/SSSDConfig/sssdoptions.py:35 msgid "Printf-compatible format for displaying fully-qualified names" msgstr "Formato compatibile con printf per la visualizzazione di nomi completi" -#: src/config/SSSDConfig/sssdoptions.py:40 +#: src/config/SSSDConfig/sssdoptions.py:36 msgid "" "Directory on the filesystem where SSSD should store Kerberos replay cache " "files." msgstr "Directory dove salvare file di cache delle risposte Kerberos" -#: src/config/SSSDConfig/sssdoptions.py:41 +#: src/config/SSSDConfig/sssdoptions.py:37 msgid "Domain to add to names without a domain component." msgstr "Dominio da aggiungere ai nomi senza una componente di dominio." -#: src/config/SSSDConfig/sssdoptions.py:42 +#: src/config/SSSDConfig/sssdoptions.py:38 msgid "The user to drop privileges to" msgstr "L'utente a cui abbassare i privilegi" -#: src/config/SSSDConfig/sssdoptions.py:43 +#: src/config/SSSDConfig/sssdoptions.py:39 msgid "Tune certificate verification" msgstr "Regola il controllo del certificato" -#: src/config/SSSDConfig/sssdoptions.py:44 +#: src/config/SSSDConfig/sssdoptions.py:40 msgid "All spaces in group or user names will be replaced with this character" msgstr "" "Tutti gli spazi nei nomi di gruppo o utente verranno sostituiti con questo " "carattere" -#: src/config/SSSDConfig/sssdoptions.py:45 +#: src/config/SSSDConfig/sssdoptions.py:41 msgid "Tune sssd to honor or ignore netlink state changes" msgstr "" "Configura sssd per rispettare o ignorare le modifiche di stato di netlink" -#: src/config/SSSDConfig/sssdoptions.py:46 +#: src/config/SSSDConfig/sssdoptions.py:42 msgid "Enable or disable the implicit files domain" msgstr "Abilita o disabilita il dominio implicito dei file" -#: src/config/SSSDConfig/sssdoptions.py:47 +#: src/config/SSSDConfig/sssdoptions.py:43 msgid "A specific order of the domains to be looked up" msgstr "Un ordine specifico dei domini da interrogare" -#: src/config/SSSDConfig/sssdoptions.py:48 +#: src/config/SSSDConfig/sssdoptions.py:44 msgid "" "Controls if SSSD should monitor the state of resolv.conf to identify when it " "needs to update its internal DNS resolver." @@ -141,7 +141,7 @@ msgstr "" "Controlla se SSSD debba monitorare lo stato di resolv.conf per identificare " "quando ha bisogno di aggiornare il suo resolver DNS interno." -#: src/config/SSSDConfig/sssdoptions.py:50 +#: src/config/SSSDConfig/sssdoptions.py:46 msgid "" "SSSD monitors the state of resolv.conf to identify when it needs to update " "its internal DNS resolver. By default, we will attempt to use inotify for " @@ -153,76 +153,77 @@ msgstr "" "tenteremo di usare inotify per questo, e passeremo al polling di resolv.conf " "ogni cinque secondi se inotify non può essere utilizzato." -#: src/config/SSSDConfig/sssdoptions.py:53 +#: src/config/SSSDConfig/sssdoptions.py:49 msgid "Run PAC responder automatically for AD and IPA provider" msgstr "Esegue automaticamente il PAC responder per i provider AD e IPA" -#: src/config/SSSDConfig/sssdoptions.py:54 +#: src/config/SSSDConfig/sssdoptions.py:50 msgid "Enable or disable core dumps for all SSSD processes." msgstr "Abilita o disabilita i core dump per tutti i processi SSSD." -#: src/config/SSSDConfig/sssdoptions.py:55 +#: src/config/SSSDConfig/sssdoptions.py:51 msgid "Tune passkey verification behavior" msgstr "Regola il comportamento della verifica della passkey" -#: src/config/SSSDConfig/sssdoptions.py:58 +#: src/config/SSSDConfig/sssdoptions.py:54 msgid "Enumeration cache timeout length (seconds)" msgstr "Durata del timeout della cache di enumerazione (secondi)" -#: src/config/SSSDConfig/sssdoptions.py:59 +#: src/config/SSSDConfig/sssdoptions.py:55 msgid "Entry cache background update timeout length (seconds)" msgstr "Durata timeout aggiornamento cache in background (secondi)" -#: src/config/SSSDConfig/sssdoptions.py:60 -#: src/config/SSSDConfig/sssdoptions.py:125 +#: src/config/SSSDConfig/sssdoptions.py:56 +#: src/config/SSSDConfig/sssdoptions.py:124 msgid "Negative cache timeout length (seconds)" msgstr "Durata timeout negative cache (secondi)" -#: src/config/SSSDConfig/sssdoptions.py:61 +#: src/config/SSSDConfig/sssdoptions.py:57 msgid "Users that SSSD should explicitly ignore" msgstr "Utenti che SSSD dovrebbe ignorare esplicitamente" -#: src/config/SSSDConfig/sssdoptions.py:62 +#: src/config/SSSDConfig/sssdoptions.py:58 msgid "Groups that SSSD should explicitly ignore" msgstr "Gruppi che SSSD dovrebbe ignorare esplicitamente" -#: src/config/SSSDConfig/sssdoptions.py:63 +#: src/config/SSSDConfig/sssdoptions.py:59 msgid "Should filtered users appear in groups" msgstr "Indica se mostrare gli utenti filtrati nei gruppi" -#: src/config/SSSDConfig/sssdoptions.py:64 +#: src/config/SSSDConfig/sssdoptions.py:60 msgid "The value of the password field the NSS provider should return" -msgstr "Il valore del campo password che deve essere ritornato dal provider NSS" +msgstr "" +"Il valore del campo password che deve essere ritornato dal provider NSS" -#: src/config/SSSDConfig/sssdoptions.py:65 +#: src/config/SSSDConfig/sssdoptions.py:61 msgid "Override homedir value from the identity provider with this value" msgstr "" "Sovrascrive il valore homedir dal provider di identità con questo valore" -#: src/config/SSSDConfig/sssdoptions.py:66 +#: src/config/SSSDConfig/sssdoptions.py:62 msgid "" "Substitute empty homedir value from the identity provider with this value" msgstr "" "Sostituisce il valore homedir vuoto dal provider di identità con questo " "valore" -#: src/config/SSSDConfig/sssdoptions.py:67 +#: src/config/SSSDConfig/sssdoptions.py:63 msgid "Override shell value from the identity provider with this value" msgstr "" "Sovrascrive il valore della shell dal provider di identità con questo valore" -#: src/config/SSSDConfig/sssdoptions.py:68 +#: src/config/SSSDConfig/sssdoptions.py:64 msgid "The list of shells users are allowed to log in with" msgstr "L'elenco delle shell con cui gli utenti sono autorizzati ad accedere" -#: src/config/SSSDConfig/sssdoptions.py:69 +#: src/config/SSSDConfig/sssdoptions.py:65 msgid "" "The list of shells that will be vetoed, and replaced with the fallback shell" msgstr "" "L'elenco delle shell che verranno bloccate e sostituite con la shell di " "fallback" -#: src/config/SSSDConfig/sssdoptions.py:70 +#: src/config/SSSDConfig/sssdoptions.py:66 msgid "" "If a shell stored in central directory is allowed but not available, use " "this fallback" @@ -230,15 +231,15 @@ msgstr "" "Se una shell memorizzata nella directory centrale è consentita ma non " "disponibile, usa questa fallback" -#: src/config/SSSDConfig/sssdoptions.py:71 +#: src/config/SSSDConfig/sssdoptions.py:67 msgid "Shell to use if the provider does not list one" msgstr "Shell da usare se il provider non ne specifica una" -#: src/config/SSSDConfig/sssdoptions.py:72 +#: src/config/SSSDConfig/sssdoptions.py:68 msgid "How long will be in-memory cache records valid" msgstr "Per quanto tempo saranno validi i record nella cache in memoria" -#: src/config/SSSDConfig/sssdoptions.py:74 +#: src/config/SSSDConfig/sssdoptions.py:70 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for passwd requests" @@ -246,7 +247,7 @@ msgstr "" "Dimensione (in megabyte) della tabella dati allocata nella cache veloce in " "memoria per le richieste passwd" -#: src/config/SSSDConfig/sssdoptions.py:76 +#: src/config/SSSDConfig/sssdoptions.py:72 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for group requests" @@ -254,7 +255,7 @@ msgstr "" "Dimensione (in megabyte) della tabella dati allocata nella cache veloce in " "memoria per le richieste group" -#: src/config/SSSDConfig/sssdoptions.py:78 +#: src/config/SSSDConfig/sssdoptions.py:74 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for initgroups requests" @@ -262,7 +263,7 @@ msgstr "" "Dimensione (in megabyte) della tabella dati allocata nella cache veloce in " "memoria per le richieste initgroups" -#: src/config/SSSDConfig/sssdoptions.py:79 +#: src/config/SSSDConfig/sssdoptions.py:75 msgid "" "The value of this option will be used in the expansion of the " "override_homedir option if the template contains the format string %H." @@ -270,7 +271,7 @@ msgstr "" "Il valore di questa opzione verrà utilizzato nell'espansione dell'opzione " "override_homedir se il template contiene la stringa di formato %H." -#: src/config/SSSDConfig/sssdoptions.py:81 +#: src/config/SSSDConfig/sssdoptions.py:77 msgid "" "Specifies time in seconds for which the list of subdomains will be " "considered valid." @@ -278,7 +279,7 @@ msgstr "" "Specifica il tempo in secondi per cui l'elenco dei sottodomini sarà " "considerato valido." -#: src/config/SSSDConfig/sssdoptions.py:83 +#: src/config/SSSDConfig/sssdoptions.py:79 msgid "" "The entry cache can be set to automatically update entries in the background " "if they are requested beyond a percentage of the entry_cache_timeout value " @@ -288,15 +289,15 @@ msgstr "" "voci in background se vengono richieste oltre una percentuale del valore " "entry_cache_timeout per il dominio." -#: src/config/SSSDConfig/sssdoptions.py:88 +#: src/config/SSSDConfig/sssdoptions.py:84 msgid "How long to allow cached logins between online logins (days)" msgstr "Per quanto tempo accettare login in cache tra login online (giorni)" -#: src/config/SSSDConfig/sssdoptions.py:89 +#: src/config/SSSDConfig/sssdoptions.py:85 msgid "How many failed logins attempts are allowed when offline" msgstr "Numero di tentativi di login falliti quando offline" -#: src/config/SSSDConfig/sssdoptions.py:91 +#: src/config/SSSDConfig/sssdoptions.py:87 msgid "" "How long (minutes) to deny login after offline_failed_login_attempts has " "been reached" @@ -304,91 +305,91 @@ msgstr "" "Per quanto tempo (minuti) negare i tentativi di login dopo che " "offline_failed_login_attemps è stato raggiunto" -#: src/config/SSSDConfig/sssdoptions.py:92 +#: src/config/SSSDConfig/sssdoptions.py:88 msgid "What kind of messages are displayed to the user during authentication" msgstr "" "Quale tipo di messaggi viene mostrato all'utente durante l'autenticazione" -#: src/config/SSSDConfig/sssdoptions.py:93 +#: src/config/SSSDConfig/sssdoptions.py:89 msgid "Filter PAM responses sent to the pam_sss" msgstr "Filtra le risposte PAM inviate a pam_sss" -#: src/config/SSSDConfig/sssdoptions.py:94 +#: src/config/SSSDConfig/sssdoptions.py:90 msgid "How many seconds to keep identity information cached for PAM requests" msgstr "" "Per quanti secondi mantenere le informazioni di identità nella cache per le " "richieste PAM" -#: src/config/SSSDConfig/sssdoptions.py:95 +#: src/config/SSSDConfig/sssdoptions.py:91 msgid "How many days before password expiration a warning should be displayed" msgstr "" "Quanti giorni prima della scadenza della password deve essere mostrato un " "avviso" -#: src/config/SSSDConfig/sssdoptions.py:96 +#: src/config/SSSDConfig/sssdoptions.py:92 msgid "List of trusted uids or user's name" msgstr "Elenco di UID o nomi utente fidati" -#: src/config/SSSDConfig/sssdoptions.py:97 +#: src/config/SSSDConfig/sssdoptions.py:93 msgid "List of domains accessible even for untrusted users." msgstr "Elenco dei domini accessibili anche per utenti non fidati." -#: src/config/SSSDConfig/sssdoptions.py:98 +#: src/config/SSSDConfig/sssdoptions.py:94 msgid "Message printed when user account is expired." msgstr "Messaggio stampato quando l'account utente è scaduto." -#: src/config/SSSDConfig/sssdoptions.py:99 +#: src/config/SSSDConfig/sssdoptions.py:95 msgid "Message printed when user account is locked." msgstr "Messaggio stampato quando l'account utente è bloccato." -#: src/config/SSSDConfig/sssdoptions.py:100 +#: src/config/SSSDConfig/sssdoptions.py:96 msgid "Allow certificate based/Smartcard authentication." msgstr "Consenti l'autenticazione basata su certificato/Smartcard." -#: src/config/SSSDConfig/sssdoptions.py:101 +#: src/config/SSSDConfig/sssdoptions.py:97 msgid "Path to certificate database with PKCS#11 modules." msgstr "Percorso del database dei certificati con moduli PKCS#11." -#: src/config/SSSDConfig/sssdoptions.py:102 +#: src/config/SSSDConfig/sssdoptions.py:98 msgid "Tune certificate verification for PAM authentication." msgstr "Regola la verifica del certificato per l'autenticazione PAM." -#: src/config/SSSDConfig/sssdoptions.py:103 +#: src/config/SSSDConfig/sssdoptions.py:99 msgid "How many seconds will pam_sss wait for p11_child to finish" msgstr "Quanti secondi pam_sss attenderà che p11_child termini" -#: src/config/SSSDConfig/sssdoptions.py:104 +#: src/config/SSSDConfig/sssdoptions.py:100 msgid "Which PAM services are permitted to contact application domains" msgstr "Quali servizi PAM sono autorizzati a contattare i domini applicativi" -#: src/config/SSSDConfig/sssdoptions.py:105 +#: src/config/SSSDConfig/sssdoptions.py:101 msgid "Allowed services for using smartcards" msgstr "Servizi consentiti per l'utilizzo delle smartcard" -#: src/config/SSSDConfig/sssdoptions.py:106 +#: src/config/SSSDConfig/sssdoptions.py:102 msgid "Additional timeout to wait for a card if requested" msgstr "Timeout aggiuntivo per attendere una card se richiesta" -#: src/config/SSSDConfig/sssdoptions.py:107 +#: src/config/SSSDConfig/sssdoptions.py:103 msgid "" "PKCS#11 URI to restrict the selection of devices for Smartcard authentication" msgstr "" "URI PKCS#11 per limitare la selezione dei dispositivi per l'autenticazione " "Smartcard" -#: src/config/SSSDConfig/sssdoptions.py:108 +#: src/config/SSSDConfig/sssdoptions.py:104 msgid "When shall the PAM responder force an initgroups request" msgstr "Quando il responder PAM deve forzare una richiesta initgroups" -#: src/config/SSSDConfig/sssdoptions.py:109 +#: src/config/SSSDConfig/sssdoptions.py:105 msgid "List of PAM services that are allowed to authenticate with GSSAPI." msgstr "Elenco dei servizi PAM autorizzati ad autenticarsi con GSSAPI." -#: src/config/SSSDConfig/sssdoptions.py:110 +#: src/config/SSSDConfig/sssdoptions.py:106 msgid "Whether to match authenticated UPN with target user" msgstr "Se confrontare l'UPN autenticato con l'utente di destinazione" -#: src/config/SSSDConfig/sssdoptions.py:111 +#: src/config/SSSDConfig/sssdoptions.py:107 msgid "" "List of pairs : that must be enforced " "for PAM access with GSSAPI authentication" @@ -396,31 +397,41 @@ msgstr "" "Elenco di coppie : che devono " "essere applicate per l'accesso PAM con autenticazione GSSAPI" -#: src/config/SSSDConfig/sssdoptions.py:113 +#: src/config/SSSDConfig/sssdoptions.py:109 +#, fuzzy +msgid "" +"List of triples :: that assigns " +"additional information from the Kerberos ticket to an authentication " +"indicator." +msgstr "" +"Elenco di coppie : che devono " +"essere applicate per l'accesso PAM con autenticazione GSSAPI" + +#: src/config/SSSDConfig/sssdoptions.py:112 msgid "Allow passkey device authentication." msgstr "Consenti l'autenticazione del dispositivo passkey." -#: src/config/SSSDConfig/sssdoptions.py:114 +#: src/config/SSSDConfig/sssdoptions.py:113 msgid "How many seconds will pam_sss wait for passkey_child to finish" msgstr "Quanti secondi pam_sss attenderà che passkey_child termini" -#: src/config/SSSDConfig/sssdoptions.py:115 +#: src/config/SSSDConfig/sssdoptions.py:114 msgid "Enable debugging in the libfido2 library" msgstr "Abilita il debug nella libreria libfido2" -#: src/config/SSSDConfig/sssdoptions.py:116 +#: src/config/SSSDConfig/sssdoptions.py:115 msgid "Enable JSON protocol for authentication methods selection." msgstr "Abiltà i protocolli JSON per i sistemi di autenticazione selezionati." -#: src/config/SSSDConfig/sssdoptions.py:119 +#: src/config/SSSDConfig/sssdoptions.py:118 msgid "Whether to evaluate the time-based attributes in sudo rules" msgstr "Se valutare gli attributi basati sul tempo nelle regole sudo" -#: src/config/SSSDConfig/sssdoptions.py:120 +#: src/config/SSSDConfig/sssdoptions.py:119 msgid "If true, SSSD will switch back to lower-wins ordering logic" msgstr "Se vero, SSSD tornerà alla logica di ordinamento lower-wins" -#: src/config/SSSDConfig/sssdoptions.py:121 +#: src/config/SSSDConfig/sssdoptions.py:120 msgid "" "Maximum number of rules that can be refreshed at once. If this is exceeded, " "full refresh is performed." @@ -428,11 +439,12 @@ msgstr "" "Numero massimo di regole che possono essere aggiornate contemporaneamente. " "Se questo viene superato, viene eseguito un aggiornamento completo." -#: src/config/SSSDConfig/sssdoptions.py:128 +#: src/config/SSSDConfig/sssdoptions.py:127 msgid "Whether to hash host names and addresses in the known_hosts file" -msgstr "Se eseguire l'hash dei nomi host e degli indirizzi nel file known_hosts" +msgstr "" +"Se eseguire l'hash dei nomi host e degli indirizzi nel file known_hosts" -#: src/config/SSSDConfig/sssdoptions.py:129 +#: src/config/SSSDConfig/sssdoptions.py:128 msgid "" "How many seconds to keep a host in the known_hosts file after its host keys " "were requested" @@ -440,15 +452,15 @@ msgstr "" "Per quanti secondi mantenere un host nel file known_hosts dopo che le sue " "chiavi host sono state richieste" -#: src/config/SSSDConfig/sssdoptions.py:131 +#: src/config/SSSDConfig/sssdoptions.py:130 msgid "Path to storage of trusted CA certificates" msgstr "Percorso dell'archivio dei certificati CA attendibili" -#: src/config/SSSDConfig/sssdoptions.py:132 +#: src/config/SSSDConfig/sssdoptions.py:131 msgid "Allow to generate ssh-keys from certificates" msgstr "Consenti di generare chiavi ssh dai certificati" -#: src/config/SSSDConfig/sssdoptions.py:133 +#: src/config/SSSDConfig/sssdoptions.py:132 msgid "" "Use the following matching rules to filter the certificates for ssh-key " "generation" @@ -456,23 +468,23 @@ msgstr "" "Usa le seguenti regole di corrispondenza per filtrare i certificati per la " "generazione delle chiavi ssh" -#: src/config/SSSDConfig/sssdoptions.py:137 +#: src/config/SSSDConfig/sssdoptions.py:136 msgid "List of UIDs or user names allowed to access the PAC responder" msgstr "Elenco di UID o nomi utente autorizzati ad accedere al PAC responder" -#: src/config/SSSDConfig/sssdoptions.py:138 +#: src/config/SSSDConfig/sssdoptions.py:137 msgid "How long the PAC data is considered valid" msgstr "Per quanto tempo i dati PAC sono considerati validi" -#: src/config/SSSDConfig/sssdoptions.py:139 +#: src/config/SSSDConfig/sssdoptions.py:138 msgid "Validate the PAC" msgstr "Valida il PAC" -#: src/config/SSSDConfig/sssdoptions.py:142 +#: src/config/SSSDConfig/sssdoptions.py:141 msgid "List of user attributes the InfoPipe is allowed to publish" msgstr "Elenco degli attributi utente che InfoPipe è autorizzato a pubblicare" -#: src/config/SSSDConfig/sssdoptions.py:145 +#: src/config/SSSDConfig/sssdoptions.py:144 msgid "" "One of the following strings specifying the scope of session recording: none " "- No users are recorded. some - Users/groups specified by users and groups " @@ -483,7 +495,7 @@ msgstr "" "gruppi specificati dalle opzioni users e groups vengono registrati. all - " "Tutti gli utenti vengono registrati." -#: src/config/SSSDConfig/sssdoptions.py:148 +#: src/config/SSSDConfig/sssdoptions.py:147 msgid "" "A comma-separated list of users which should have session recording enabled. " "Matches user names as returned by NSS. I.e. after the possible space " @@ -494,7 +506,7 @@ msgstr "" "NSS. Cioè dopo la possibile sostituzione degli spazi, cambiamenti di " "maiuscolo/minuscolo, ecc." -#: src/config/SSSDConfig/sssdoptions.py:150 +#: src/config/SSSDConfig/sssdoptions.py:149 msgid "" "A comma-separated list of groups, members of which should have session " "recording enabled. Matches group names as returned by NSS. I.e. after the " @@ -505,7 +517,7 @@ msgstr "" "restituiti da NSS. Cioè dopo la possibile sostituzione degli spazi, " "cambiamenti di maiuscolo/minuscolo, ecc." -#: src/config/SSSDConfig/sssdoptions.py:153 +#: src/config/SSSDConfig/sssdoptions.py:152 msgid "" "A comma-separated list of users to be excluded from recording, only when " "scope=all" @@ -513,7 +525,7 @@ msgstr "" "Un elenco separato da virgole di utenti da escludere dalla registrazione, " "solo quando scope=all" -#: src/config/SSSDConfig/sssdoptions.py:154 +#: src/config/SSSDConfig/sssdoptions.py:153 msgid "" "A comma-separated list of groups, members of which should be excluded from " "recording, only when scope=all. " @@ -521,79 +533,80 @@ msgstr "" "Un elenco separato da virgole di gruppi, i cui membri dovrebbero essere " "esclusi dalla registrazione, solo quando scope=all. " -#: src/config/SSSDConfig/sssdoptions.py:158 +#: src/config/SSSDConfig/sssdoptions.py:157 msgid "Identity provider" msgstr "Provider di identità" -#: src/config/SSSDConfig/sssdoptions.py:159 +#: src/config/SSSDConfig/sssdoptions.py:158 msgid "Authentication provider" msgstr "Provider di autenticazione" -#: src/config/SSSDConfig/sssdoptions.py:160 +#: src/config/SSSDConfig/sssdoptions.py:159 msgid "Access control provider" msgstr "Provider di access control" -#: src/config/SSSDConfig/sssdoptions.py:161 +#: src/config/SSSDConfig/sssdoptions.py:160 msgid "Password change provider" msgstr "Provider di cambio password" -#: src/config/SSSDConfig/sssdoptions.py:162 +#: src/config/SSSDConfig/sssdoptions.py:161 msgid "SUDO provider" msgstr "Provider SUDO" -#: src/config/SSSDConfig/sssdoptions.py:163 +#: src/config/SSSDConfig/sssdoptions.py:162 msgid "Autofs provider" msgstr "Provider Autofs" -#: src/config/SSSDConfig/sssdoptions.py:164 +#: src/config/SSSDConfig/sssdoptions.py:163 msgid "Host identity provider" msgstr "Provider di identità host" -#: src/config/SSSDConfig/sssdoptions.py:165 +#: src/config/SSSDConfig/sssdoptions.py:164 msgid "SELinux provider" msgstr "Provider SELinux" -#: src/config/SSSDConfig/sssdoptions.py:166 +#: src/config/SSSDConfig/sssdoptions.py:165 msgid "Session management provider" msgstr "Provider di gestione sessione" -#: src/config/SSSDConfig/sssdoptions.py:167 +#: src/config/SSSDConfig/sssdoptions.py:166 msgid "Resolver provider" msgstr "Provider resolver" -#: src/config/SSSDConfig/sssdoptions.py:170 +#: src/config/SSSDConfig/sssdoptions.py:169 msgid "Whether the domain is usable by the OS or by applications" -msgstr "Se il dominio è utilizzabile dal sistema operativo o dalle applicazioni" +msgstr "" +"Se il dominio è utilizzabile dal sistema operativo o dalle applicazioni" -#: src/config/SSSDConfig/sssdoptions.py:171 +#: src/config/SSSDConfig/sssdoptions.py:170 msgid "Enable or disable the domain" msgstr "Abilita o disabilita il dominio" -#: src/config/SSSDConfig/sssdoptions.py:172 +#: src/config/SSSDConfig/sssdoptions.py:171 msgid "Minimum user ID" msgstr "ID utente minimo" -#: src/config/SSSDConfig/sssdoptions.py:173 +#: src/config/SSSDConfig/sssdoptions.py:172 msgid "Maximum user ID" msgstr "ID utente massimo" -#: src/config/SSSDConfig/sssdoptions.py:174 +#: src/config/SSSDConfig/sssdoptions.py:173 msgid "Enable enumerating all users/groups" msgstr "Consentire l'enumerazione di tutti gli utenti/gruppi" -#: src/config/SSSDConfig/sssdoptions.py:175 +#: src/config/SSSDConfig/sssdoptions.py:174 msgid "Cache credentials for offline login" msgstr "Salvare in cache le credenziali per login offline" -#: src/config/SSSDConfig/sssdoptions.py:176 +#: src/config/SSSDConfig/sssdoptions.py:175 msgid "Display users/groups in fully-qualified form" msgstr "Mostrare utenti/gruppi in formato fully-qualified" -#: src/config/SSSDConfig/sssdoptions.py:177 +#: src/config/SSSDConfig/sssdoptions.py:176 msgid "Don't include group members in group lookups" msgstr "Non includere i membri del gruppo nelle ricerche di gruppo" -#: src/config/SSSDConfig/sssdoptions.py:178 +#: src/config/SSSDConfig/sssdoptions.py:177 #: src/config/SSSDConfig/sssdoptions.py:190 #: src/config/SSSDConfig/sssdoptions.py:191 #: src/config/SSSDConfig/sssdoptions.py:192 @@ -604,20 +617,20 @@ msgstr "Non includere i membri del gruppo nelle ricerche di gruppo" msgid "Entry cache timeout length (seconds)" msgstr "Durata timeout elementi in cache (secondi)" -#: src/config/SSSDConfig/sssdoptions.py:179 +#: src/config/SSSDConfig/sssdoptions.py:178 msgid "" "Restrict or prefer a specific address family when performing DNS lookups" msgstr "" "Restringere o preferire una specifica famiglia di indirizzi per l'esecuzione " "di lookup DNS" -#: src/config/SSSDConfig/sssdoptions.py:180 +#: src/config/SSSDConfig/sssdoptions.py:179 msgid "How long to keep cached entries after last successful login (days)" msgstr "" "Per quanto tempo tenere in cache gli elementi dopo un login che ha avuto " "successo (giorni)" -#: src/config/SSSDConfig/sssdoptions.py:181 +#: src/config/SSSDConfig/sssdoptions.py:180 msgid "" "How long should SSSD talk to single DNS server before trying next server " "(miliseconds)" @@ -625,21 +638,21 @@ msgstr "" "Per quanto tempo SSSD dovrebbe comunicare con un singolo server DNS prima di " "provare il server successivo (millisecondi)" -#: src/config/SSSDConfig/sssdoptions.py:183 +#: src/config/SSSDConfig/sssdoptions.py:182 msgid "How long should keep trying to resolve single DNS query (seconds)" msgstr "" "Per quanto tempo continuare a provare a risolvere una singola query DNS " "(secondi)" -#: src/config/SSSDConfig/sssdoptions.py:184 +#: src/config/SSSDConfig/sssdoptions.py:183 msgid "How long to wait for replies from DNS when resolving servers (seconds)" msgstr "Il tempo di attesa per le richieste DNS (secondi)" -#: src/config/SSSDConfig/sssdoptions.py:185 +#: src/config/SSSDConfig/sssdoptions.py:184 msgid "The domain part of service discovery DNS query" msgstr "La parte del dominio della query DNS di individuazione del servizio" -#: src/config/SSSDConfig/sssdoptions.py:186 +#: src/config/SSSDConfig/sssdoptions.py:185 msgid "" "Specifies the interval, in seconds, that SSSD waits before attempting to " "reconnect to the primary server after a successful connection to the backup " @@ -649,14 +662,18 @@ msgstr "" "riconnettersi al server primario dopo una connessione riuscita al server di " "backup" -#: src/config/SSSDConfig/sssdoptions.py:188 +#: src/config/SSSDConfig/sssdoptions.py:187 msgid "Override GID value from the identity provider with this value" msgstr "Sovrascrive il valore GID dal provider di identità con questo valore" -#: src/config/SSSDConfig/sssdoptions.py:189 +#: src/config/SSSDConfig/sssdoptions.py:188 msgid "Treat usernames as case sensitive" msgstr "Tratta i nomi utente come sensibili alle maiuscole/minuscole" +#: src/config/SSSDConfig/sssdoptions.py:189 +msgid "Lookups by ID are expensive or do not work at all" +msgstr "" + #: src/config/SSSDConfig/sssdoptions.py:197 msgid "How often should expired entries be refreshed in background" msgstr "" @@ -712,7 +729,8 @@ msgstr "Se il provider debba aggiornare esplicitamente anche il record PTR" #: src/config/SSSDConfig/sssdoptions.py:208 msgid "Whether the nsupdate utility should default to using TCP" -msgstr "Se l'utilità nsupdate debba utilizzare TCP per impostazione predefinita" +msgstr "" +"Se l'utilità nsupdate debba utilizzare TCP per impostazione predefinita" #: src/config/SSSDConfig/sssdoptions.py:209 msgid "What kind of authentication should be used to perform the DNS update" @@ -855,7 +873,8 @@ msgstr "Base di ricerca per l'oggetto contenente informazioni sul dominio IPA" #: src/config/SSSDConfig/sssdoptions.py:244 msgid "Search base for objects containing info about ID ranges" -msgstr "Base di ricerca per oggetti contenenti informazioni sugli intervalli ID" +msgstr "" +"Base di ricerca per oggetti contenenti informazioni sugli intervalli ID" #: src/config/SSSDConfig/sssdoptions.py:245 msgid "Search base for view containers" @@ -911,7 +930,7 @@ msgid "Search base for SUBID ranges" msgstr "Base di ricerca per intervalli SUBID" #: src/config/SSSDConfig/sssdoptions.py:259 -#: src/config/SSSDConfig/sssdoptions.py:506 +#: src/config/SSSDConfig/sssdoptions.py:512 msgid "Which rules should be used to evaluate access control" msgstr "" "Quali regole dovrebbero essere usate per valutare il controllo degli accessi" @@ -1068,7 +1087,7 @@ msgid "Enable DNS sites - location based service discovery" msgstr "Abilita siti DNS - individuazione del servizio basata sulla posizione" #: src/config/SSSDConfig/sssdoptions.py:301 -#: src/config/SSSDConfig/sssdoptions.py:504 +#: src/config/SSSDConfig/sssdoptions.py:510 msgid "LDAP filter to determine access privileges" msgstr "Filtro LDAP per determinare i privilegi di accesso" @@ -1092,37 +1111,37 @@ msgid "" "PAM service names that map to the GPO (Deny)InteractiveLogonRight policy " "settings" msgstr "" -"Nomi dei servizi PAM che mappano alle impostazioni della policy GPO (Deny)" -"InteractiveLogonRight" +"Nomi dei servizi PAM che mappano alle impostazioni della policy GPO " +"(Deny)InteractiveLogonRight" #: src/config/SSSDConfig/sssdoptions.py:307 msgid "" "PAM service names that map to the GPO (Deny)RemoteInteractiveLogonRight " "policy settings" msgstr "" -"Nomi dei servizi PAM che mappano alle impostazioni della policy GPO (Deny)" -"RemoteInteractiveLogonRight" +"Nomi dei servizi PAM che mappano alle impostazioni della policy GPO " +"(Deny)RemoteInteractiveLogonRight" #: src/config/SSSDConfig/sssdoptions.py:309 msgid "" "PAM service names that map to the GPO (Deny)NetworkLogonRight policy settings" msgstr "" -"Nomi dei servizi PAM che mappano alle impostazioni della policy GPO (Deny)" -"NetworkLogonRight" +"Nomi dei servizi PAM che mappano alle impostazioni della policy GPO " +"(Deny)NetworkLogonRight" #: src/config/SSSDConfig/sssdoptions.py:310 msgid "" "PAM service names that map to the GPO (Deny)BatchLogonRight policy settings" msgstr "" -"Nomi dei servizi PAM che mappano alle impostazioni della policy GPO (Deny)" -"BatchLogonRight" +"Nomi dei servizi PAM che mappano alle impostazioni della policy GPO " +"(Deny)BatchLogonRight" #: src/config/SSSDConfig/sssdoptions.py:311 msgid "" "PAM service names that map to the GPO (Deny)ServiceLogonRight policy settings" msgstr "" -"Nomi dei servizi PAM che mappano alle impostazioni della policy GPO (Deny)" -"ServiceLogonRight" +"Nomi dei servizi PAM che mappano alle impostazioni della policy GPO " +"(Deny)ServiceLogonRight" #: src/config/SSSDConfig/sssdoptions.py:312 msgid "PAM service names for which GPO-based access is always granted" @@ -1207,7 +1226,8 @@ msgstr "Abilita la validazione delle credenziali" #: src/config/SSSDConfig/sssdoptions.py:337 msgid "Store password if offline for later online authentication" -msgstr "Memorizza la password se offline per l'autenticazione online successiva" +msgstr "" +"Memorizza la password se offline per l'autenticazione online successiva" #: src/config/SSSDConfig/sssdoptions.py:338 msgid "Renewable lifetime of the TGT" @@ -1514,7 +1534,7 @@ msgid "UUID attribute" msgstr "Attributo UUID" #: src/config/SSSDConfig/sssdoptions.py:423 -#: src/config/SSSDConfig/sssdoptions.py:464 +#: src/config/SSSDConfig/sssdoptions.py:470 msgid "objectSID attribute" msgstr "Attributo objectSID" @@ -1638,178 +1658,207 @@ msgstr "attributo contenente i dati di mappatura della passkey dell'utente" msgid "A list of extra attributes to download along with the user entry" msgstr "Un elenco di attributi extra da scaricare insieme alla voce utente" +#: src/config/SSSDConfig/sssdoptions.py:456 +#, fuzzy +msgid "The object class of an subid entry in LDAP." +msgstr "La classe oggetto di una voce host in LDAP." + #: src/config/SSSDConfig/sssdoptions.py:457 +#, fuzzy +msgid "Subordinate user ID count attribute" +msgstr "Attributo utente regola sudo" + +#: src/config/SSSDConfig/sssdoptions.py:458 +#, fuzzy +msgid "Subordinate group ID count attribute" +msgstr "Attributo opzione regola sudo" + +#: src/config/SSSDConfig/sssdoptions.py:459 +#, fuzzy +msgid "User ID range start value attribute" +msgstr "Attributo del nome utente" + +#: src/config/SSSDConfig/sssdoptions.py:460 +#, fuzzy +msgid "Group ID range start value attribute" +msgstr "Attributo UUID gruppo" + +#: src/config/SSSDConfig/sssdoptions.py:461 +msgid "Owner of an entry" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:463 msgid "Base DN for group lookups" msgstr "DN base per le ricerche di gruppo" -#: src/config/SSSDConfig/sssdoptions.py:458 +#: src/config/SSSDConfig/sssdoptions.py:464 msgid "Objectclass for groups" msgstr "Objectclass per i gruppi" -#: src/config/SSSDConfig/sssdoptions.py:459 +#: src/config/SSSDConfig/sssdoptions.py:465 msgid "Group name" msgstr "Nome gruppo" -#: src/config/SSSDConfig/sssdoptions.py:460 +#: src/config/SSSDConfig/sssdoptions.py:466 msgid "Group password" msgstr "Password gruppo" -#: src/config/SSSDConfig/sssdoptions.py:461 +#: src/config/SSSDConfig/sssdoptions.py:467 msgid "GID attribute" msgstr "Attributo GID" -#: src/config/SSSDConfig/sssdoptions.py:462 +#: src/config/SSSDConfig/sssdoptions.py:468 msgid "Group member attribute" msgstr "Attributo membro gruppo" -#: src/config/SSSDConfig/sssdoptions.py:463 +#: src/config/SSSDConfig/sssdoptions.py:469 msgid "Group UUID attribute" msgstr "Attributo UUID gruppo" -#: src/config/SSSDConfig/sssdoptions.py:465 +#: src/config/SSSDConfig/sssdoptions.py:471 msgid "Modification time attribute for groups" msgstr "Attributo tempo di modifica per i gruppi" -#: src/config/SSSDConfig/sssdoptions.py:466 +#: src/config/SSSDConfig/sssdoptions.py:472 msgid "Type of the group and other flags" msgstr "Tipo del gruppo e altri flag" -#: src/config/SSSDConfig/sssdoptions.py:467 +#: src/config/SSSDConfig/sssdoptions.py:473 msgid "The LDAP group external member attribute" msgstr "L'attributo membro esterno del gruppo LDAP" -#: src/config/SSSDConfig/sssdoptions.py:468 +#: src/config/SSSDConfig/sssdoptions.py:474 msgid "Maximum nesting level SSSD will follow" msgstr "Livello massimo di annidamento che SSSD seguirà" -#: src/config/SSSDConfig/sssdoptions.py:469 +#: src/config/SSSDConfig/sssdoptions.py:475 msgid "Filter for group lookups" msgstr "Filtro per le ricerche di gruppo" -#: src/config/SSSDConfig/sssdoptions.py:470 +#: src/config/SSSDConfig/sssdoptions.py:476 msgid "Scope of group lookups" msgstr "Ambito delle ricerche di gruppo" -#: src/config/SSSDConfig/sssdoptions.py:472 +#: src/config/SSSDConfig/sssdoptions.py:478 msgid "Base DN for netgroup lookups" msgstr "DN base per le ricerche di netgroup" -#: src/config/SSSDConfig/sssdoptions.py:473 +#: src/config/SSSDConfig/sssdoptions.py:479 msgid "Objectclass for netgroups" msgstr "Objectclass per i netgroup" -#: src/config/SSSDConfig/sssdoptions.py:474 +#: src/config/SSSDConfig/sssdoptions.py:480 msgid "Netgroup name" msgstr "Nome netgroup" -#: src/config/SSSDConfig/sssdoptions.py:475 +#: src/config/SSSDConfig/sssdoptions.py:481 msgid "Netgroups members attribute" msgstr "Attributo membri netgroup" -#: src/config/SSSDConfig/sssdoptions.py:476 +#: src/config/SSSDConfig/sssdoptions.py:482 msgid "Netgroup triple attribute" msgstr "Attributo tripletta netgroup" -#: src/config/SSSDConfig/sssdoptions.py:477 +#: src/config/SSSDConfig/sssdoptions.py:483 msgid "Modification time attribute for netgroups" msgstr "Attributo tempo di modifica per i netgroup" -#: src/config/SSSDConfig/sssdoptions.py:479 +#: src/config/SSSDConfig/sssdoptions.py:485 msgid "Base DN for service lookups" msgstr "DN base per le ricerche di servizio" -#: src/config/SSSDConfig/sssdoptions.py:480 +#: src/config/SSSDConfig/sssdoptions.py:486 msgid "Objectclass for services" msgstr "Objectclass per i servizi" -#: src/config/SSSDConfig/sssdoptions.py:481 +#: src/config/SSSDConfig/sssdoptions.py:487 msgid "Service name attribute" msgstr "Attributo nome servizio" -#: src/config/SSSDConfig/sssdoptions.py:482 +#: src/config/SSSDConfig/sssdoptions.py:488 msgid "Service port attribute" msgstr "Attributo porta servizio" -#: src/config/SSSDConfig/sssdoptions.py:483 +#: src/config/SSSDConfig/sssdoptions.py:489 msgid "Service protocol attribute" msgstr "Attributo protocollo servizio" -#: src/config/SSSDConfig/sssdoptions.py:485 +#: src/config/SSSDConfig/sssdoptions.py:491 msgid "Lower bound for ID-mapping" msgstr "Limite inferiore per la mappatura ID" -#: src/config/SSSDConfig/sssdoptions.py:486 +#: src/config/SSSDConfig/sssdoptions.py:492 msgid "Upper bound for ID-mapping" msgstr "Limite superiore per la mappatura ID" -#: src/config/SSSDConfig/sssdoptions.py:487 +#: src/config/SSSDConfig/sssdoptions.py:493 msgid "Number of IDs for each slice when ID-mapping" msgstr "Numero di ID per ogni slice durante la mappatura ID" -#: src/config/SSSDConfig/sssdoptions.py:488 +#: src/config/SSSDConfig/sssdoptions.py:494 msgid "Use autorid-compatible algorithm for ID-mapping" msgstr "Utilizza algoritmo compatibile con autorid per la mappatura ID" -#: src/config/SSSDConfig/sssdoptions.py:489 +#: src/config/SSSDConfig/sssdoptions.py:495 msgid "Name of the default domain for ID-mapping" msgstr "Nome del dominio predefinito per la mappatura ID" -#: src/config/SSSDConfig/sssdoptions.py:490 +#: src/config/SSSDConfig/sssdoptions.py:496 msgid "SID of the default domain for ID-mapping" msgstr "SID del dominio predefinito per la mappatura ID" -#: src/config/SSSDConfig/sssdoptions.py:491 +#: src/config/SSSDConfig/sssdoptions.py:497 msgid "Number of secondary slices" msgstr "Numero di slice secondarie" -#: src/config/SSSDConfig/sssdoptions.py:493 +#: src/config/SSSDConfig/sssdoptions.py:499 msgid "Whether to use Token-Groups" msgstr "Se utilizzare i Token-Groups" -#: src/config/SSSDConfig/sssdoptions.py:494 +#: src/config/SSSDConfig/sssdoptions.py:500 msgid "Set lower boundary for allowed IDs from the LDAP server" msgstr "Imposta il limite inferiore per gli ID consentiti dal server LDAP" -#: src/config/SSSDConfig/sssdoptions.py:495 +#: src/config/SSSDConfig/sssdoptions.py:501 msgid "Set upper boundary for allowed IDs from the LDAP server" msgstr "Imposta il limite superiore per gli ID consentiti dal server LDAP" -#: src/config/SSSDConfig/sssdoptions.py:496 +#: src/config/SSSDConfig/sssdoptions.py:502 msgid "DN for ppolicy queries" msgstr "DN per le query ppolicy" -#: src/config/SSSDConfig/sssdoptions.py:497 +#: src/config/SSSDConfig/sssdoptions.py:503 msgid "How many maximum entries to fetch during a wildcard request" msgstr "Quante voci massime recuperare durante una richiesta wildcard" -#: src/config/SSSDConfig/sssdoptions.py:498 +#: src/config/SSSDConfig/sssdoptions.py:504 msgid "Set libldap debug level" msgstr "Imposta il livello di debug di libldap" -#: src/config/SSSDConfig/sssdoptions.py:501 +#: src/config/SSSDConfig/sssdoptions.py:507 msgid "Policy to evaluate the password expiration" msgstr "Politica per controllare la scadenza della password" -#: src/config/SSSDConfig/sssdoptions.py:505 +#: src/config/SSSDConfig/sssdoptions.py:511 msgid "Which attributes shall be used to evaluate if an account is expired" msgstr "" "Quali attributi devono essere utilizzati per valutare se un account è scaduto" -#: src/config/SSSDConfig/sssdoptions.py:509 +#: src/config/SSSDConfig/sssdoptions.py:515 msgid "URI of an LDAP server where password changes are allowed" msgstr "URI di un server LDAP dove sono consentite le modifiche della password" -#: src/config/SSSDConfig/sssdoptions.py:510 +#: src/config/SSSDConfig/sssdoptions.py:516 msgid "URI of a backup LDAP server where password changes are allowed" msgstr "" "URI di un server LDAP di backup dove sono consentite le modifiche della " "password" -#: src/config/SSSDConfig/sssdoptions.py:511 +#: src/config/SSSDConfig/sssdoptions.py:517 msgid "DNS service name for LDAP password change server" msgstr "Nome del servizio DNS per il server di modifica password LDAP" -#: src/config/SSSDConfig/sssdoptions.py:512 +#: src/config/SSSDConfig/sssdoptions.py:518 msgid "" "Whether to update the ldap_user_shadow_last_change attribute after a " "password change" @@ -1817,27 +1866,27 @@ msgstr "" "Se aggiornare l'attributo ldap_user_shadow_last_change dopo un cambio " "password" -#: src/config/SSSDConfig/sssdoptions.py:516 +#: src/config/SSSDConfig/sssdoptions.py:522 msgid "Base DN for sudo rules lookups" msgstr "DN base per le ricerche delle regole sudo" -#: src/config/SSSDConfig/sssdoptions.py:517 +#: src/config/SSSDConfig/sssdoptions.py:523 msgid "Automatic full refresh period" msgstr "Periodo di aggiornamento completo automatico" -#: src/config/SSSDConfig/sssdoptions.py:518 +#: src/config/SSSDConfig/sssdoptions.py:524 msgid "Automatic smart refresh period" msgstr "Periodo di aggiornamento intelligente automatico" -#: src/config/SSSDConfig/sssdoptions.py:519 +#: src/config/SSSDConfig/sssdoptions.py:525 msgid "Smart and full refresh random offset" msgstr "Offset casuale per aggiornamento intelligente e completo" -#: src/config/SSSDConfig/sssdoptions.py:520 +#: src/config/SSSDConfig/sssdoptions.py:526 msgid "Whether to filter rules by hostname, IP addresses and network" msgstr "Se filtrare le regole per nome host, indirizzi IP e rete" -#: src/config/SSSDConfig/sssdoptions.py:521 +#: src/config/SSSDConfig/sssdoptions.py:527 msgid "" "Hostnames and/or fully qualified domain names of this machine to filter sudo " "rules" @@ -1845,150 +1894,150 @@ msgstr "" "Nomi host e/o nomi di dominio completi di questa macchina per filtrare le " "regole sudo" -#: src/config/SSSDConfig/sssdoptions.py:522 +#: src/config/SSSDConfig/sssdoptions.py:528 msgid "IPv4 or IPv6 addresses or network of this machine to filter sudo rules" msgstr "" "Indirizzi IPv4 o IPv6 o rete di questa macchina per filtrare le regole sudo" -#: src/config/SSSDConfig/sssdoptions.py:523 +#: src/config/SSSDConfig/sssdoptions.py:529 msgid "Whether to include rules that contains netgroup in host attribute" msgstr "Se includere regole che contengono netgroup nell'attributo host" -#: src/config/SSSDConfig/sssdoptions.py:524 +#: src/config/SSSDConfig/sssdoptions.py:530 msgid "" "Whether to include rules that contains regular expression in host attribute" msgstr "" "Se includere regole che contengono espressioni regolari nell'attributo host" -#: src/config/SSSDConfig/sssdoptions.py:525 +#: src/config/SSSDConfig/sssdoptions.py:531 msgid "Object class for sudo rules" msgstr "Classe oggetto per le regole sudo" -#: src/config/SSSDConfig/sssdoptions.py:526 +#: src/config/SSSDConfig/sssdoptions.py:532 msgid "Name of attribute that is used as object class for sudo rules" msgstr "Nome dell'attributo utilizzato come classe oggetto per le regole sudo" -#: src/config/SSSDConfig/sssdoptions.py:527 +#: src/config/SSSDConfig/sssdoptions.py:533 msgid "Sudo rule name" msgstr "Nome regola sudo" -#: src/config/SSSDConfig/sssdoptions.py:528 +#: src/config/SSSDConfig/sssdoptions.py:534 msgid "Sudo rule command attribute" msgstr "Attributo comando regola sudo" -#: src/config/SSSDConfig/sssdoptions.py:529 +#: src/config/SSSDConfig/sssdoptions.py:535 msgid "Sudo rule host attribute" msgstr "Attributo host regola sudo" -#: src/config/SSSDConfig/sssdoptions.py:530 +#: src/config/SSSDConfig/sssdoptions.py:536 msgid "Sudo rule user attribute" msgstr "Attributo utente regola sudo" -#: src/config/SSSDConfig/sssdoptions.py:531 +#: src/config/SSSDConfig/sssdoptions.py:537 msgid "Sudo rule option attribute" msgstr "Attributo opzione regola sudo" -#: src/config/SSSDConfig/sssdoptions.py:532 +#: src/config/SSSDConfig/sssdoptions.py:538 msgid "Sudo rule runas attribute" msgstr "Attributo runas regola sudo" -#: src/config/SSSDConfig/sssdoptions.py:533 +#: src/config/SSSDConfig/sssdoptions.py:539 msgid "Sudo rule runasuser attribute" msgstr "Attributo runasuser regola sudo" -#: src/config/SSSDConfig/sssdoptions.py:534 +#: src/config/SSSDConfig/sssdoptions.py:540 msgid "Sudo rule runasgroup attribute" msgstr "Attributo runasgroup regola sudo" -#: src/config/SSSDConfig/sssdoptions.py:535 +#: src/config/SSSDConfig/sssdoptions.py:541 msgid "Sudo rule notbefore attribute" msgstr "Attributo notbefore regola sudo" -#: src/config/SSSDConfig/sssdoptions.py:536 +#: src/config/SSSDConfig/sssdoptions.py:542 msgid "Sudo rule notafter attribute" msgstr "Attributo notafter regola sudo" -#: src/config/SSSDConfig/sssdoptions.py:537 +#: src/config/SSSDConfig/sssdoptions.py:543 msgid "Sudo rule order attribute" msgstr "Attributo ordine regola sudo" -#: src/config/SSSDConfig/sssdoptions.py:540 +#: src/config/SSSDConfig/sssdoptions.py:546 msgid "Object class for automounter maps" msgstr "Classe oggetto per le mappe automounter" -#: src/config/SSSDConfig/sssdoptions.py:541 +#: src/config/SSSDConfig/sssdoptions.py:547 msgid "Automounter map name attribute" msgstr "Attributo nome mappa automounter" -#: src/config/SSSDConfig/sssdoptions.py:542 +#: src/config/SSSDConfig/sssdoptions.py:548 msgid "Object class for automounter map entries" msgstr "Classe oggetto per le voci della mappa automounter" -#: src/config/SSSDConfig/sssdoptions.py:543 +#: src/config/SSSDConfig/sssdoptions.py:549 msgid "Automounter map entry key attribute" msgstr "Attributo chiave voce mappa automounter" -#: src/config/SSSDConfig/sssdoptions.py:544 +#: src/config/SSSDConfig/sssdoptions.py:550 msgid "Automounter map entry value attribute" msgstr "Attributo valore voce mappa automounter" -#: src/config/SSSDConfig/sssdoptions.py:545 +#: src/config/SSSDConfig/sssdoptions.py:551 msgid "Base DN for automounter map lookups" msgstr "DN base per le ricerche della mappa automounter" -#: src/config/SSSDConfig/sssdoptions.py:546 +#: src/config/SSSDConfig/sssdoptions.py:552 msgid "The name of the automount master map in LDAP." msgstr "Il nome della mappa master automount in LDAP." -#: src/config/SSSDConfig/sssdoptions.py:549 +#: src/config/SSSDConfig/sssdoptions.py:555 msgid "Base DN for IP hosts lookups" msgstr "DN base per le ricerche degli host IP" -#: src/config/SSSDConfig/sssdoptions.py:550 +#: src/config/SSSDConfig/sssdoptions.py:556 msgid "Object class for IP hosts" msgstr "Classe oggetto per gli host IP" -#: src/config/SSSDConfig/sssdoptions.py:551 +#: src/config/SSSDConfig/sssdoptions.py:557 msgid "IP host name attribute" msgstr "Attributo nome host IP" -#: src/config/SSSDConfig/sssdoptions.py:552 +#: src/config/SSSDConfig/sssdoptions.py:558 msgid "IP host number (address) attribute" msgstr "Attributo numero (indirizzo) host IP" -#: src/config/SSSDConfig/sssdoptions.py:553 +#: src/config/SSSDConfig/sssdoptions.py:559 msgid "IP host entryUSN attribute" msgstr "Attributo entryUSN host IP" -#: src/config/SSSDConfig/sssdoptions.py:554 +#: src/config/SSSDConfig/sssdoptions.py:560 msgid "Base DN for IP networks lookups" msgstr "DN base per le ricerche delle reti IP" -#: src/config/SSSDConfig/sssdoptions.py:555 +#: src/config/SSSDConfig/sssdoptions.py:561 msgid "Object class for IP networks" msgstr "Classe oggetto per le reti IP" -#: src/config/SSSDConfig/sssdoptions.py:556 +#: src/config/SSSDConfig/sssdoptions.py:562 msgid "IP network name attribute" msgstr "Attributo nome rete IP" -#: src/config/SSSDConfig/sssdoptions.py:557 +#: src/config/SSSDConfig/sssdoptions.py:563 msgid "IP network number (address) attribute" msgstr "Attributo numero (indirizzo) rete IP" -#: src/config/SSSDConfig/sssdoptions.py:558 +#: src/config/SSSDConfig/sssdoptions.py:564 msgid "IP network entryUSN attribute" msgstr "Attributo entryUSN rete IP" -#: src/config/SSSDConfig/sssdoptions.py:561 +#: src/config/SSSDConfig/sssdoptions.py:567 msgid "Comma separated list of allowed users" msgstr "Lista separata da virgola degli utenti abilitati" -#: src/config/SSSDConfig/sssdoptions.py:562 +#: src/config/SSSDConfig/sssdoptions.py:568 msgid "Comma separated list of prohibited users" msgstr "Lista separata da virgola degli utenti non abilitati" -#: src/config/SSSDConfig/sssdoptions.py:563 +#: src/config/SSSDConfig/sssdoptions.py:569 msgid "" "Comma separated list of groups that are allowed to log in. This applies only " "to groups within this SSSD domain. Local groups are not evaluated." @@ -1997,7 +2046,7 @@ msgstr "" "applica solo ai gruppi all'interno di questo dominio SSSD. I gruppi locali " "non vengono valutati." -#: src/config/SSSDConfig/sssdoptions.py:565 +#: src/config/SSSDConfig/sssdoptions.py:571 msgid "" "Comma separated list of groups that are explicitly denied access. This " "applies only to groups within this SSSD domain. Local groups are not " @@ -2007,31 +2056,32 @@ msgstr "" "l'accesso. Questo si applica solo ai gruppi all'interno di questo dominio " "SSSD. I gruppi locali non vengono valutati." -#: src/config/SSSDConfig/sssdoptions.py:569 +#: src/config/SSSDConfig/sssdoptions.py:575 msgid "The number of preforked proxy children." msgstr "Il numero di figli proxy preforked." -#: src/config/SSSDConfig/sssdoptions.py:572 +#: src/config/SSSDConfig/sssdoptions.py:578 msgid "The name of the NSS library to use" msgstr "Il nome della libreria NSS da usare" -#: src/config/SSSDConfig/sssdoptions.py:573 +#: src/config/SSSDConfig/sssdoptions.py:579 msgid "The name of the NSS library to use for hosts and networks lookups" -msgstr "Il nome della libreria NSS da utilizzare per le ricerche di host e reti" +msgstr "" +"Il nome della libreria NSS da utilizzare per le ricerche di host e reti" -#: src/config/SSSDConfig/sssdoptions.py:574 +#: src/config/SSSDConfig/sssdoptions.py:580 msgid "Whether to look up canonical group name from cache if possible" msgstr "Se cercare il nome canonico del gruppo dalla cache, se possibile" -#: src/config/SSSDConfig/sssdoptions.py:577 +#: src/config/SSSDConfig/sssdoptions.py:583 msgid "PAM stack to use" msgstr "Stack PAM da usare" -#: src/config/SSSDConfig/sssdoptions.py:580 +#: src/config/SSSDConfig/sssdoptions.py:586 msgid "Path of passwd file sources." msgstr "Percorso delle sorgenti del file passwd." -#: src/config/SSSDConfig/sssdoptions.py:581 +#: src/config/SSSDConfig/sssdoptions.py:587 msgid "Path of group file sources." msgstr "Percorso delle sorgenti del file group." @@ -2062,109 +2112,113 @@ msgstr "" msgid "Option -i|--interactive is not allowed together with -D|--daemon\n" msgstr "L'opzione -i|--interactive non è consentita insieme a -D|--daemon\n" -#: src/monitor/monitor.c:1836 +#: src/monitor/monitor.c:1838 msgid "Failed to get initial capabilities\n" msgstr "Impossibile ottenere le capability iniziali\n" -#: src/monitor/monitor.c:1847 +#: src/monitor/monitor.c:1849 msgid "Non-root service user support isn't built. Can't run under %" msgstr "" "Il supporto per utente di servizio non root non è compilato. Impossibile " "eseguire come %" -#: src/monitor/monitor.c:1864 +#: src/monitor/monitor.c:1866 #, c-format msgid "Can't read config: '%s'\n" msgstr "Impossibile leggere la configurazione: '%s'\n" -#: src/monitor/monitor.c:1876 -#, c-format -msgid "Failed to boostrap SSSD 'monitor' process: %s" +#: src/monitor/monitor.c:1878 +#, fuzzy, c-format +msgid "Failed to bootstrap SSSD 'monitor' process: %s" msgstr "Fallito il bootstrap del processo 'monitor' di SSSD: %s" -#: src/monitor/monitor.c:1971 +#: src/monitor/monitor.c:1973 msgid "Out of memory\n" msgstr "Memoria esaurita\n" -#: src/providers/krb5/krb5_child.c:4221 +#: src/providers/krb5/krb5_child.c:4316 msgid "Use anonymous PKINIT to request FAST armor ticket" msgstr "Utilizza PKINIT anonimo per richiedere il ticket armatura FAST" -#: src/providers/krb5/krb5_child.c:4223 +#: src/providers/krb5/krb5_child.c:4318 msgid "Kerberos realm to use" msgstr "Realm Kerberos da utilizzare" -#: src/providers/krb5/krb5_child.c:4225 +#: src/providers/krb5/krb5_child.c:4320 msgid "Requested lifetime of the ticket" msgstr "Durata richiesta del ticket" -#: src/providers/krb5/krb5_child.c:4227 +#: src/providers/krb5/krb5_child.c:4322 msgid "Requested renewable lifetime of the ticket" msgstr "Durata rinnovabile richiesta del ticket" -#: src/providers/krb5/krb5_child.c:4229 +#: src/providers/krb5/krb5_child.c:4324 msgid "FAST options ('never', 'try', 'demand')" msgstr "Opzioni FAST ('never', 'try', 'demand')" -#: src/providers/krb5/krb5_child.c:4232 +#: src/providers/krb5/krb5_child.c:4327 msgid "Specifies the server principal to use for FAST" msgstr "Specifica il principal del server da utilizzare per FAST" -#: src/providers/krb5/krb5_child.c:4234 +#: src/providers/krb5/krb5_child.c:4329 msgid "Requests canonicalization of the principal name" msgstr "Richiede la canonicalizzazione del nome del principal" -#: src/providers/krb5/krb5_child.c:4236 +#: src/providers/krb5/krb5_child.c:4331 msgid "Use custom version of krb5_get_init_creds_password" msgstr "Usa versione personalizzata di krb5_get_init_creds_password" -#: src/providers/krb5/krb5_child.c:4238 +#: src/providers/krb5/krb5_child.c:4333 msgid "Check PAC flags" msgstr "Controlla flag PAC" -#: src/providers/data_provider_be.c:790 +#: src/providers/krb5/krb5_child.c:4335 +msgid "Set environment variable (KEY=VALUE)" +msgstr "" + +#: src/providers/data_provider_be.c:786 msgid "Domain of the information provider (mandatory)" msgstr "Dominio del provider di informazioni (obbligatorio)" -#: src/sss_client/common.c:1165 +#: src/sss_client/common.c:1208 msgid "Socket has wrong ownership or permissions." msgstr "Il socket ha proprietario o permessi non validi." -#: src/sss_client/common.c:1168 +#: src/sss_client/common.c:1211 msgid "Unexpected format of the server credential message." msgstr "Formato inatteso del messaggio di credenziali del server." -#: src/sss_client/common.c:1171 +#: src/sss_client/common.c:1214 msgid "SSSD is not run by trusted user." msgstr "SSSD non è eseguito da un utente fidato." -#: src/sss_client/common.c:1174 +#: src/sss_client/common.c:1217 msgid "SSSD socket does not exist." msgstr "Il socket SSSD non esiste." -#: src/sss_client/common.c:1177 +#: src/sss_client/common.c:1220 msgid "Cannot get stat of SSSD socket." msgstr "Impossibile ottenere lo stat del socket SSSD." -#: src/sss_client/common.c:1182 +#: src/sss_client/common.c:1225 msgid "An error occurred, but no description can be found." msgstr "" "Si è verificato un errore, ma non è possibile trovare alcuna descrizione." -#: src/sss_client/common.c:1188 +#: src/sss_client/common.c:1231 msgid "Unexpected error while looking for an error description" msgstr "Errore inatteso durante la ricerca di una descrizione dell'errore" -#: src/sss_client/pam_sss.c:74 +#: src/sss_client/pam_sss.c:135 msgid "Permission denied. " msgstr "Permesso negato. " -#: src/sss_client/pam_sss.c:75 src/sss_client/pam_sss.c:843 -#: src/sss_client/pam_sss.c:854 +#: src/sss_client/pam_sss.c:136 src/sss_client/pam_sss.c:921 +#: src/sss_client/pam_sss.c:932 msgid "Server message: " msgstr "Messaggio del server:" -#: src/sss_client/pam_sss.c:76 +#: src/sss_client/pam_sss.c:137 msgid "" "Kerberos TGT will not be granted upon login, user experience will be " "affected." @@ -2172,50 +2226,50 @@ msgstr "" "Il TGT Kerberos non verrà concesso al login, l'esperienza utente ne " "risentirà." -#: src/sss_client/pam_sss.c:77 +#: src/sss_client/pam_sss.c:138 msgid "Enter PIN:" msgstr "Inserire PIN:" -#: src/sss_client/pam_sss.c:320 +#: src/sss_client/pam_sss.c:385 msgid "Passwords do not match" msgstr "Le password non coincidono" -#: src/sss_client/pam_sss.c:508 +#: src/sss_client/pam_sss.c:584 msgid "Password reset by root is not supported." msgstr "Il reset della password da parte di root non è supportato." -#: src/sss_client/pam_sss.c:549 +#: src/sss_client/pam_sss.c:625 msgid "Authenticated with cached credentials" msgstr "Autenticato con le credenziali nella cache" -#: src/sss_client/pam_sss.c:550 +#: src/sss_client/pam_sss.c:626 msgid ", your cached password will expire at: " msgstr ", la password in cache scadrà il: " -#: src/sss_client/pam_sss.c:580 +#: src/sss_client/pam_sss.c:656 #, c-format msgid "Your password has expired. You have %1$d grace login(s) remaining." msgstr "La tua password è scaduta. Hai %1$d login di cortesia rimanenti." -#: src/sss_client/pam_sss.c:630 +#: src/sss_client/pam_sss.c:706 #, c-format msgid "Your password will expire in %1$d %2$s." msgstr "La tua password scadrà tra %1$d %2$s." -#: src/sss_client/pam_sss.c:633 +#: src/sss_client/pam_sss.c:709 #, c-format msgid "Your password has expired." msgstr "La tua password è scaduta." -#: src/sss_client/pam_sss.c:684 +#: src/sss_client/pam_sss.c:760 msgid "Authentication is denied until: " msgstr "L'autenticazione verrà negata fino al: " -#: src/sss_client/pam_sss.c:705 +#: src/sss_client/pam_sss.c:781 msgid "System is offline, password change not possible" msgstr "Il sistema è offline, non è possibile richiedere un cambio password" -#: src/sss_client/pam_sss.c:720 +#: src/sss_client/pam_sss.c:796 msgid "" "After changing the OTP password, you need to log out and back in order to " "acquire a ticket" @@ -2223,11 +2277,11 @@ msgstr "" "Dopo aver cambiato la password OTP, è necessario disconnettersi e " "riconnettersi per acquisire un ticket" -#: src/sss_client/pam_sss.c:735 +#: src/sss_client/pam_sss.c:813 msgid "PIN locked" msgstr "PIN bloccato" -#: src/sss_client/pam_sss.c:750 +#: src/sss_client/pam_sss.c:828 msgid "" "No Kerberos TGT granted as the server does not support this method. Your " "single-sign on(SSO) experience will be affected." @@ -2235,61 +2289,65 @@ msgstr "" "Nessun TGT Kerberos concesso poiché il server non supporta questo metodo. La " "tua esperienza di single-sign on (SSO) ne risentirà." -#: src/sss_client/pam_sss.c:840 src/sss_client/pam_sss.c:853 +#: src/sss_client/pam_sss.c:918 src/sss_client/pam_sss.c:931 msgid "Password change failed. " msgstr "Cambio password fallito." -#: src/sss_client/pam_sss.c:1859 -#, c-format -msgid "Authenticate at %1$s and press ENTER." +#: src/sss_client/pam_sss.c:2028 +#, fuzzy, c-format +msgid "Authenticate at \"%1$s\"." msgstr "Autenticati su %1$s e premi INVIO." -#: src/sss_client/pam_sss.c:1862 -#, c-format -msgid "Authenticate with PIN %1$s at %2$s and press ENTER." +#: src/sss_client/pam_sss.c:2031 +#, fuzzy, c-format +msgid "Authenticate with PIN \"%1$s\" at \"%2$s\"." msgstr "Autenticati con il PIN %1$s su %2$s e premi INVIO." -#: src/sss_client/pam_sss.c:2281 +#: src/sss_client/pam_sss.c:2470 msgid "Please (re)insert (different) Smartcard" msgstr "Per favore (re)inserisci (un'altra) Smartcard" -#: src/sss_client/pam_sss.c:2482 +#: src/sss_client/pam_sss.c:2700 msgid "New Password: " msgstr "Nuova password: " -#: src/sss_client/pam_sss.c:2483 +#: src/sss_client/pam_sss.c:2701 msgid "Reenter new Password: " msgstr "Conferma nuova password: " -#: src/sss_client/pam_sss.c:2676 src/sss_client/pam_sss.c:2679 +#: src/sss_client/pam_sss.c:2890 +msgid "Press ENTER to continue." +msgstr "" + +#: src/sss_client/pam_sss.c:2913 src/sss_client/pam_sss.c:2916 msgid "First Factor: " msgstr "Primo Fattore: " -#: src/sss_client/pam_sss.c:2677 src/sss_client/pam_sss.c:2851 +#: src/sss_client/pam_sss.c:2914 src/sss_client/pam_sss.c:3088 msgid "Second Factor (optional): " msgstr "Secondo Fattore (opzionale): " -#: src/sss_client/pam_sss.c:2680 src/sss_client/pam_sss.c:2855 +#: src/sss_client/pam_sss.c:2917 src/sss_client/pam_sss.c:3092 msgid "Second Factor: " msgstr "Secondo Fattore: " -#: src/sss_client/pam_sss.c:2684 +#: src/sss_client/pam_sss.c:2921 msgid "Insert your passkey device, then press ENTER." msgstr "Inserisci il tuo dispositivo passkey, quindi premi INVIO." -#: src/sss_client/pam_sss.c:2688 src/sss_client/pam_sss.c:2696 +#: src/sss_client/pam_sss.c:2925 src/sss_client/pam_sss.c:2933 msgid "Password: " msgstr "Password: " -#: src/sss_client/pam_sss.c:2850 src/sss_client/pam_sss.c:2854 +#: src/sss_client/pam_sss.c:3087 src/sss_client/pam_sss.c:3091 msgid "First Factor (Current Password): " msgstr "Primo Fattore (Password attuale): " -#: src/sss_client/pam_sss.c:2874 +#: src/sss_client/pam_sss.c:3111 msgid "Current Password: " msgstr "Password corrente: " -#: src/sss_client/pam_sss.c:3248 +#: src/sss_client/pam_sss.c:3485 msgid "Password expired. Change your password now." msgstr "Password scaduta. Cambiare la password ora." @@ -2735,9 +2793,9 @@ msgstr "Fallita la stampa dell'oggetto: %s\n" #: src/tools/sssctl/sssctl_cache.c:835 src/tools/sssctl/sssctl_cache.c:918 #: src/tools/sssctl/sssctl_cache.c:950 src/tools/sssctl/sssctl_cache.c:956 #: src/tools/sssctl/sssctl_cache.c:1010 src/tools/sssctl/sssctl_cache.c:1034 -#: src/tools/sssctl/sssctl_cache.c:1085 src/tools/sssctl/sssctl_cache.c:1194 -#: src/tools/sssctl/sssctl_cache.c:1229 src/tools/sssctl/sssctl_cache.c:1235 -#: src/tools/sssctl/sssctl_cache.c:1244 +#: src/tools/sssctl/sssctl_cache.c:1085 src/tools/sssctl/sssctl_cache.c:1195 +#: src/tools/sssctl/sssctl_cache.c:1230 src/tools/sssctl/sssctl_cache.c:1236 +#: src/tools/sssctl/sssctl_cache.c:1245 msgid "talloc failed\n" msgstr "talloc fallito\n" @@ -2813,25 +2871,25 @@ msgstr "Il percorso GPO nella cache [%s] non è sotto [%s], ignorando.\n" msgid "Unable to remove downloaded GPO files: %s\n" msgstr "Impossibile rimuovere i file GPO scaricati: %s\n" -#: src/tools/sssctl/sssctl_cache.c:1165 +#: src/tools/sssctl/sssctl_cache.c:1166 #, c-format msgid "Failed to fetch cache entry: %s\n" msgstr "Fallito il recupero della voce cache: %s\n" -#: src/tools/sssctl/sssctl_cache.c:1170 +#: src/tools/sssctl/sssctl_cache.c:1171 msgid "Could not determine object domain\n" msgstr "Impossibile determinare il dominio dell'oggetto\n" -#: src/tools/sssctl/sssctl_cache.c:1200 +#: src/tools/sssctl/sssctl_cache.c:1201 msgid "Could not find GUID attribute in GPO entry\n" msgstr "Impossibile trovare l'attributo GUID nella voce GPO\n" -#: src/tools/sssctl/sssctl_cache.c:1206 +#: src/tools/sssctl/sssctl_cache.c:1207 #, c-format msgid "Failed to delete GPO: %s\n" msgstr "Fallita l'eliminazione della GPO: %s\n" -#: src/tools/sssctl/sssctl_cache.c:1210 +#: src/tools/sssctl/sssctl_cache.c:1211 #, c-format msgid "%s removed from cache\n" msgstr "%s rimosso dalla cache\n" @@ -2880,8 +2938,8 @@ msgstr "Fallita l'impostazione del contesto certmap.\n" #, c-format msgid "Failed to add mapping and matching rules with error [%d][%s].\n" msgstr "" -"Fallita l'aggiunta delle regole di mappatura e corrispondenza con errore " -"[%d][%s].\n" +"Fallita l'aggiunta delle regole di mappatura e corrispondenza con errore [%d]" +"[%s].\n" #: src/tools/sssctl/sssctl_cert.c:251 msgid "Failed to decode base64 string.\n" @@ -2929,39 +2987,40 @@ msgstr "" "principale. Ad esempio, se la configurazione è impostata su \"/mio/percorso/" "sssd.conf\", viene utilizzata la directory snippet \"/mio/percorso/conf.d\")" -#: src/tools/sssctl/sssctl_config.c:114 +#: src/tools/sssctl/sssctl_config.c:126 #, c-format msgid "File %1$s does not exist.\n" msgstr "File %1$s non esiste.\n" -#: src/tools/sssctl/sssctl_config.c:115 +#: src/tools/sssctl/sssctl_config.c:127 msgid "There is no configuration.\n" msgstr "Non c'è configurazione.\n" -#: src/tools/sssctl/sssctl_config.c:120 +#: src/tools/sssctl/sssctl_config.c:132 #, c-format msgid "Configuration validation failed: %s\n" msgstr "Operazione di configurazione fallita %s\n" -#: src/tools/sssctl/sssctl_config.c:121 +#: src/tools/sssctl/sssctl_config.c:133 msgid "Run with high debug level to see details.\n" msgstr "Esegui con un livello di debug elevato per visualizzare i dettagli\n" -#: src/tools/sssctl/sssctl_config.c:130 -msgid "Failed to run validators" +#: src/tools/sssctl/sssctl_config.c:142 +#, fuzzy +msgid "Failed to run validators\n" msgstr "Fallita l'esecuzione dei validatori" -#: src/tools/sssctl/sssctl_config.c:134 +#: src/tools/sssctl/sssctl_config.c:146 #, c-format msgid "Issues identified by validators: %zu\n" msgstr "Problemi identificati dai validatori: %zu\n" -#: src/tools/sssctl/sssctl_config.c:145 +#: src/tools/sssctl/sssctl_config.c:157 #, c-format msgid "Messages generated during configuration merging: %zu\n" msgstr "Messaggi generati durante l'unione della configurazione: %zu\n" -#: src/tools/sssctl/sssctl_config.c:158 +#: src/tools/sssctl/sssctl_config.c:170 #, c-format msgid "Used configuration snippet files: %zu\n" msgstr "File snippet di configurazione utilizzati: %zu\n" diff --git a/po/ja.po b/po/ja.po index af22a26470e..92f6b750d9c 100644 --- a/po/ja.po +++ b/po/ja.po @@ -14,8 +14,8 @@ msgid "" msgstr "" "Project-Id-Version: PACKAGE VERSION\n" "Report-Msgid-Bugs-To: sssd-devel@lists.fedorahosted.org\n" -"POT-Creation-Date: 2026-01-14 14:57+0000\n" -"PO-Revision-Date: 2026-04-23 16:38+0000\n" +"POT-Creation-Date: 2026-10-02 15:57+0000\n" +"PO-Revision-Date: 2026-10-05 16:41+0000\n" "Last-Translator: Transtats \n" "Language-Team: Japanese \n" @@ -24,50 +24,51 @@ msgstr "" "Content-Type: text/plain; charset=UTF-8\n" "Content-Transfer-Encoding: 8bit\n" "Plural-Forms: nplurals=1; plural=0;\n" -"X-Generator: Weblate 5.17\n" +"X-Generator: Weblate 2026.10\n" -#: src/config/SSSDConfig/sssdoptions.py:20 -#: src/config/SSSDConfig/sssdoptions.py:21 +#: src/config/SSSDConfig/sssdoptions.py:16 +#: src/config/SSSDConfig/sssdoptions.py:17 msgid "Set the verbosity of the debug logging" msgstr "デバッグのロギングの冗長性を設定する" -#: src/config/SSSDConfig/sssdoptions.py:22 +#: src/config/SSSDConfig/sssdoptions.py:18 msgid "Include timestamps in debug logs" msgstr "デバッグログにタイムスタンプを含める" -#: src/config/SSSDConfig/sssdoptions.py:23 +#: src/config/SSSDConfig/sssdoptions.py:19 msgid "Include microseconds in timestamps in debug logs" msgstr "デバッグログにミリ秒単位のタイムスタンプを含める" -#: src/config/SSSDConfig/sssdoptions.py:24 +#: src/config/SSSDConfig/sssdoptions.py:20 msgid "Enable/disable debug backtrace" msgstr "デバッグバックトレースの有効化/無効化" -#: src/config/SSSDConfig/sssdoptions.py:25 +#: src/config/SSSDConfig/sssdoptions.py:21 msgid "Watchdog timeout before restarting service" msgstr "サービス再起動前の Watchdog タイムアウト" -#: src/config/SSSDConfig/sssdoptions.py:26 +#: src/config/SSSDConfig/sssdoptions.py:22 msgid "Command to start service" msgstr "サービス開始のコマンド" -#: src/config/SSSDConfig/sssdoptions.py:27 +#: src/config/SSSDConfig/sssdoptions.py:23 msgid "The number of file descriptors that may be opened by this responder" msgstr "このレスポンダーににより開かれるファイル記述子の数" -#: src/config/SSSDConfig/sssdoptions.py:28 +#: src/config/SSSDConfig/sssdoptions.py:24 msgid "Idle time before automatic disconnection of a client" msgstr "クライアントの自動切断までのアイドル時間" -#: src/config/SSSDConfig/sssdoptions.py:29 +#: src/config/SSSDConfig/sssdoptions.py:25 msgid "Idle time before automatic shutdown of the responder" msgstr "レスポンダーの自動シャットダウンまでのアイドル時間" -#: src/config/SSSDConfig/sssdoptions.py:30 +#: src/config/SSSDConfig/sssdoptions.py:26 msgid "Always query all the caches before querying the Data Providers" -msgstr "データプロバイダーをクエリーする前に、常にすべてのキャッシュをクエリーします" +msgstr "" +"データプロバイダーをクエリーする前に、常にすべてのキャッシュをクエリーします" -#: src/config/SSSDConfig/sssdoptions.py:31 +#: src/config/SSSDConfig/sssdoptions.py:27 msgid "" "When SSSD switches to offline mode the amount of time before it tries to go " "back online will increase based upon the time spent disconnected. This value " @@ -78,59 +79,60 @@ msgstr "" "切断の時間に基づいて長くなります。この値は秒単位で、offline_timeout + " "random_offset で計算されます。" -#: src/config/SSSDConfig/sssdoptions.py:36 +#: src/config/SSSDConfig/sssdoptions.py:32 msgid "SSSD Services to start" msgstr "開始する SSSD サービス" -#: src/config/SSSDConfig/sssdoptions.py:37 +#: src/config/SSSDConfig/sssdoptions.py:33 msgid "SSSD Domains to start" msgstr "開始する SSSD ドメイン" -#: src/config/SSSDConfig/sssdoptions.py:38 +#: src/config/SSSDConfig/sssdoptions.py:34 msgid "Regex to parse username and domain" msgstr "ユーザー名とドメインを構文解析する正規表現" -#: src/config/SSSDConfig/sssdoptions.py:39 +#: src/config/SSSDConfig/sssdoptions.py:35 msgid "Printf-compatible format for displaying fully-qualified names" msgstr "完全修飾名を表示するための printf 互換の形式" -#: src/config/SSSDConfig/sssdoptions.py:40 +#: src/config/SSSDConfig/sssdoptions.py:36 msgid "" "Directory on the filesystem where SSSD should store Kerberos replay cache " "files." msgstr "" -"SSSD が Kerberos リプレイキャッシュファイルを保存するファイルシステムの" -"ディレクトリーです。" +"SSSD が Kerberos リプレイキャッシュファイルを保存するファイルシステムのディレ" +"クトリーです。" -#: src/config/SSSDConfig/sssdoptions.py:41 +#: src/config/SSSDConfig/sssdoptions.py:37 msgid "Domain to add to names without a domain component." msgstr "domain 要素なしで追加するドメインの名前。" -#: src/config/SSSDConfig/sssdoptions.py:42 +#: src/config/SSSDConfig/sssdoptions.py:38 msgid "The user to drop privileges to" msgstr "ユーザーが特権を停止します" -#: src/config/SSSDConfig/sssdoptions.py:43 +#: src/config/SSSDConfig/sssdoptions.py:39 msgid "Tune certificate verification" msgstr "証明書検証の調整" -#: src/config/SSSDConfig/sssdoptions.py:44 +#: src/config/SSSDConfig/sssdoptions.py:40 msgid "All spaces in group or user names will be replaced with this character" -msgstr "グループ名またはユーザー名のすべてのスペースは、この文字に置き換えられます" +msgstr "" +"グループ名またはユーザー名のすべてのスペースは、この文字に置き換えられます" -#: src/config/SSSDConfig/sssdoptions.py:45 +#: src/config/SSSDConfig/sssdoptions.py:41 msgid "Tune sssd to honor or ignore netlink state changes" msgstr "SSSD を調整し、netlink の状態変更を尊重するか、または無視します" -#: src/config/SSSDConfig/sssdoptions.py:46 +#: src/config/SSSDConfig/sssdoptions.py:42 msgid "Enable or disable the implicit files domain" msgstr "暗黙のファイルドメインを有効化または無効化する" -#: src/config/SSSDConfig/sssdoptions.py:47 +#: src/config/SSSDConfig/sssdoptions.py:43 msgid "A specific order of the domains to be looked up" msgstr "検索するドメインの特定の順番" -#: src/config/SSSDConfig/sssdoptions.py:48 +#: src/config/SSSDConfig/sssdoptions.py:44 msgid "" "Controls if SSSD should monitor the state of resolv.conf to identify when it " "needs to update its internal DNS resolver." @@ -138,7 +140,7 @@ msgstr "" "内部 DNS リゾルバーを更新する必要があるときを判断するために SSSD が " "resolv.conf の状態を監視するかどうかを制御します。" -#: src/config/SSSDConfig/sssdoptions.py:50 +#: src/config/SSSDConfig/sssdoptions.py:46 msgid "" "SSSD monitors the state of resolv.conf to identify when it needs to update " "its internal DNS resolver. By default, we will attempt to use inotify for " @@ -150,72 +152,72 @@ msgstr "" "また、inotify が使用できない場合は、5 秒ごとに resolv.conf のポーリングに" "フォールバックします。" -#: src/config/SSSDConfig/sssdoptions.py:53 +#: src/config/SSSDConfig/sssdoptions.py:49 msgid "Run PAC responder automatically for AD and IPA provider" msgstr "AD および IPA プロバイダーに対して PAC レスポンダーを自動的に実行する" -#: src/config/SSSDConfig/sssdoptions.py:54 +#: src/config/SSSDConfig/sssdoptions.py:50 msgid "Enable or disable core dumps for all SSSD processes." msgstr "すべての SSSD プロセスのコアダンプを有効または無効にします。" -#: src/config/SSSDConfig/sssdoptions.py:55 +#: src/config/SSSDConfig/sssdoptions.py:51 msgid "Tune passkey verification behavior" msgstr "パスキー検証の動作をチューニングする" -#: src/config/SSSDConfig/sssdoptions.py:58 +#: src/config/SSSDConfig/sssdoptions.py:54 msgid "Enumeration cache timeout length (seconds)" msgstr "列挙キャッシュのタイムアウト (秒)" -#: src/config/SSSDConfig/sssdoptions.py:59 +#: src/config/SSSDConfig/sssdoptions.py:55 msgid "Entry cache background update timeout length (seconds)" msgstr "エントリーキャッシュのバックグラウンド更新のタイムアウト時間 (秒)" -#: src/config/SSSDConfig/sssdoptions.py:60 -#: src/config/SSSDConfig/sssdoptions.py:125 +#: src/config/SSSDConfig/sssdoptions.py:56 +#: src/config/SSSDConfig/sssdoptions.py:124 msgid "Negative cache timeout length (seconds)" msgstr "ネガティブキャッシュのタイムアウト (秒)" -#: src/config/SSSDConfig/sssdoptions.py:61 +#: src/config/SSSDConfig/sssdoptions.py:57 msgid "Users that SSSD should explicitly ignore" msgstr "SSSD が明示的に無視するユーザー" -#: src/config/SSSDConfig/sssdoptions.py:62 +#: src/config/SSSDConfig/sssdoptions.py:58 msgid "Groups that SSSD should explicitly ignore" msgstr "SSSD が明示的に無視するグループ" -#: src/config/SSSDConfig/sssdoptions.py:63 +#: src/config/SSSDConfig/sssdoptions.py:59 msgid "Should filtered users appear in groups" msgstr "フィルターされたユーザーをグループに表示する" -#: src/config/SSSDConfig/sssdoptions.py:64 +#: src/config/SSSDConfig/sssdoptions.py:60 msgid "The value of the password field the NSS provider should return" msgstr "NSS プロバイダーが返すパスワード項目の値" -#: src/config/SSSDConfig/sssdoptions.py:65 +#: src/config/SSSDConfig/sssdoptions.py:61 msgid "Override homedir value from the identity provider with this value" msgstr "識別プロバイダーからのホームディレクトリーの値をこの値で上書きする" -#: src/config/SSSDConfig/sssdoptions.py:66 +#: src/config/SSSDConfig/sssdoptions.py:62 msgid "" "Substitute empty homedir value from the identity provider with this value" msgstr "" "アイデンティティープロバイダーからの空のホームディレクトリーをこの値で置き換" "えます" -#: src/config/SSSDConfig/sssdoptions.py:67 +#: src/config/SSSDConfig/sssdoptions.py:63 msgid "Override shell value from the identity provider with this value" msgstr "アイデンティティープロバイダーからのシェル値をこの値で上書きします" -#: src/config/SSSDConfig/sssdoptions.py:68 +#: src/config/SSSDConfig/sssdoptions.py:64 msgid "The list of shells users are allowed to log in with" msgstr "ユーザーがログインを許可されるシェルの一覧" -#: src/config/SSSDConfig/sssdoptions.py:69 +#: src/config/SSSDConfig/sssdoptions.py:65 msgid "" "The list of shells that will be vetoed, and replaced with the fallback shell" msgstr "拒否されてフォールバックシェルで置き換えられるシェルの一覧" -#: src/config/SSSDConfig/sssdoptions.py:70 +#: src/config/SSSDConfig/sssdoptions.py:66 msgid "" "If a shell stored in central directory is allowed but not available, use " "this fallback" @@ -223,15 +225,15 @@ msgstr "" "中央ディレクトリーに保存されたシェルが許可されるが、利用できない場合、この" "フォールバックを使用する" -#: src/config/SSSDConfig/sssdoptions.py:71 +#: src/config/SSSDConfig/sssdoptions.py:67 msgid "Shell to use if the provider does not list one" msgstr "プロバイダーが一覧に持っていないとき使用するシェル" -#: src/config/SSSDConfig/sssdoptions.py:72 +#: src/config/SSSDConfig/sssdoptions.py:68 msgid "How long will be in-memory cache records valid" msgstr "メモリー内のキャッシュレコードが有効な期間" -#: src/config/SSSDConfig/sssdoptions.py:74 +#: src/config/SSSDConfig/sssdoptions.py:70 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for passwd requests" @@ -239,15 +241,15 @@ msgstr "" "パスワード要求の高速インメモリーキャッシュ内で割り当てられるデータテーブルの" "サイズ (メガバイト)" -#: src/config/SSSDConfig/sssdoptions.py:76 +#: src/config/SSSDConfig/sssdoptions.py:72 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for group requests" msgstr "" -"グループ要求の高速インメモリーキャッシュ内で割り当てられるデータテーブルの" -"サイズ (メガバイト)" +"グループ要求の高速インメモリーキャッシュ内で割り当てられるデータテーブルのサ" +"イズ (メガバイト)" -#: src/config/SSSDConfig/sssdoptions.py:78 +#: src/config/SSSDConfig/sssdoptions.py:74 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for initgroups requests" @@ -255,7 +257,7 @@ msgstr "" "initgroups 要求の高速インメモリーキャッシュ内で割り当てられるデータテーブルの" "サイズ (メガバイト)" -#: src/config/SSSDConfig/sssdoptions.py:79 +#: src/config/SSSDConfig/sssdoptions.py:75 msgid "" "The value of this option will be used in the expansion of the " "override_homedir option if the template contains the format string %H." @@ -263,13 +265,13 @@ msgstr "" "このオプションの値は、テンプレートに書式文字列 %H を含んでいる場合に " "override_homedir オプションの拡張で使用されます。" -#: src/config/SSSDConfig/sssdoptions.py:81 +#: src/config/SSSDConfig/sssdoptions.py:77 msgid "" "Specifies time in seconds for which the list of subdomains will be " "considered valid." msgstr "サブドメインのリストが有効とみなされる時間を秒単位で指定します。" -#: src/config/SSSDConfig/sssdoptions.py:83 +#: src/config/SSSDConfig/sssdoptions.py:79 msgid "" "The entry cache can be set to automatically update entries in the background " "if they are requested beyond a percentage of the entry_cache_timeout value " @@ -279,130 +281,140 @@ msgstr "" "リクエストが行われた場合に、バックグラウンドでエントリーを自動的に更新するよ" "うに設定できます。" -#: src/config/SSSDConfig/sssdoptions.py:88 +#: src/config/SSSDConfig/sssdoptions.py:84 msgid "How long to allow cached logins between online logins (days)" msgstr "オンラインログイン中にキャッシュによるログインが許容される期間 (日数)" -#: src/config/SSSDConfig/sssdoptions.py:89 +#: src/config/SSSDConfig/sssdoptions.py:85 msgid "How many failed logins attempts are allowed when offline" msgstr "オフラインの時に許容されるログイン試行失敗回数" -#: src/config/SSSDConfig/sssdoptions.py:91 +#: src/config/SSSDConfig/sssdoptions.py:87 msgid "" "How long (minutes) to deny login after offline_failed_login_attempts has " "been reached" msgstr "offline_failed_login_attempts に達した後にログインを拒否する時間 (分)" -#: src/config/SSSDConfig/sssdoptions.py:92 +#: src/config/SSSDConfig/sssdoptions.py:88 msgid "What kind of messages are displayed to the user during authentication" msgstr "認証中にユーザーに表示されるメッセージの種類" -#: src/config/SSSDConfig/sssdoptions.py:93 +#: src/config/SSSDConfig/sssdoptions.py:89 msgid "Filter PAM responses sent to the pam_sss" msgstr "pam_sss へ送信された PAM のレスポンスをフィルタリングします" -#: src/config/SSSDConfig/sssdoptions.py:94 +#: src/config/SSSDConfig/sssdoptions.py:90 msgid "How many seconds to keep identity information cached for PAM requests" msgstr "PAM 要求に対してキャッシュされた認証情報を保持する秒数" -#: src/config/SSSDConfig/sssdoptions.py:95 +#: src/config/SSSDConfig/sssdoptions.py:91 msgid "How many days before password expiration a warning should be displayed" msgstr "警告が表示されるパスワード失効前の日数" -#: src/config/SSSDConfig/sssdoptions.py:96 +#: src/config/SSSDConfig/sssdoptions.py:92 msgid "List of trusted uids or user's name" msgstr "信頼できる UID またはユーザー名の一覧" -#: src/config/SSSDConfig/sssdoptions.py:97 +#: src/config/SSSDConfig/sssdoptions.py:93 msgid "List of domains accessible even for untrusted users." msgstr "信頼できないユーザーでさえアクセス可能なドメインの一覧。" -#: src/config/SSSDConfig/sssdoptions.py:98 +#: src/config/SSSDConfig/sssdoptions.py:94 msgid "Message printed when user account is expired." msgstr "ユーザーアカウントの有効期限が切れると、メッセージが印刷されます。" -#: src/config/SSSDConfig/sssdoptions.py:99 +#: src/config/SSSDConfig/sssdoptions.py:95 msgid "Message printed when user account is locked." msgstr "ユーザーアカウントがロックされると、メッセージが印刷されます。" -#: src/config/SSSDConfig/sssdoptions.py:100 +#: src/config/SSSDConfig/sssdoptions.py:96 msgid "Allow certificate based/Smartcard authentication." msgstr "証明書ベースまたはスマートカードによる認証を許可します。" -#: src/config/SSSDConfig/sssdoptions.py:101 +#: src/config/SSSDConfig/sssdoptions.py:97 msgid "Path to certificate database with PKCS#11 modules." msgstr "PKCS#11 モジュールでの証明書データベースへのパス。" -#: src/config/SSSDConfig/sssdoptions.py:102 +#: src/config/SSSDConfig/sssdoptions.py:98 msgid "Tune certificate verification for PAM authentication." msgstr "PAM 認証の証明書検証の調整。" -#: src/config/SSSDConfig/sssdoptions.py:103 +#: src/config/SSSDConfig/sssdoptions.py:99 msgid "How many seconds will pam_sss wait for p11_child to finish" msgstr "p11_child が完了するまでに pam_sss が待つ秒数" -#: src/config/SSSDConfig/sssdoptions.py:104 +#: src/config/SSSDConfig/sssdoptions.py:100 msgid "Which PAM services are permitted to contact application domains" msgstr "アプリケーションドメインへの接続を許可される PAM サービスはどれか" -#: src/config/SSSDConfig/sssdoptions.py:105 +#: src/config/SSSDConfig/sssdoptions.py:101 msgid "Allowed services for using smartcards" msgstr "スマートカードの使用が許可されたサービス" -#: src/config/SSSDConfig/sssdoptions.py:106 +#: src/config/SSSDConfig/sssdoptions.py:102 msgid "Additional timeout to wait for a card if requested" msgstr "要求された場合に、カードが待つ追加のタイムアウト" -#: src/config/SSSDConfig/sssdoptions.py:107 +#: src/config/SSSDConfig/sssdoptions.py:103 msgid "" "PKCS#11 URI to restrict the selection of devices for Smartcard authentication" msgstr "スマートカード認証向けのデバイスの選択を PKCS#11 URI が制限" -#: src/config/SSSDConfig/sssdoptions.py:108 +#: src/config/SSSDConfig/sssdoptions.py:104 msgid "When shall the PAM responder force an initgroups request" msgstr "PAM レスポンダーが initgroups リクエストを強制するとき" -#: src/config/SSSDConfig/sssdoptions.py:109 +#: src/config/SSSDConfig/sssdoptions.py:105 msgid "List of PAM services that are allowed to authenticate with GSSAPI." msgstr "GSSAPI での認証が許可される PAM サービスの一覧。" -#: src/config/SSSDConfig/sssdoptions.py:110 +#: src/config/SSSDConfig/sssdoptions.py:106 msgid "Whether to match authenticated UPN with target user" msgstr "ターゲットユーザーと認証された UPN に一致するかどうか" -#: src/config/SSSDConfig/sssdoptions.py:111 +#: src/config/SSSDConfig/sssdoptions.py:107 msgid "" "List of pairs : that must be enforced " "for PAM access with GSSAPI authentication" msgstr "" -"GSSAPI 認証で PAM アクセスを強制する必要があるペア " -": のリスト" +"GSSAPI 認証で PAM アクセスを強制する必要があるペア :" +" のリスト" -#: src/config/SSSDConfig/sssdoptions.py:113 +#: src/config/SSSDConfig/sssdoptions.py:109 +#, fuzzy +msgid "" +"List of triples :: that assigns " +"additional information from the Kerberos ticket to an authentication " +"indicator." +msgstr "" +"GSSAPI 認証で PAM アクセスを強制する必要があるペア :" +" のリスト" + +#: src/config/SSSDConfig/sssdoptions.py:112 msgid "Allow passkey device authentication." msgstr "パスキーデバイス認証を許可します。" -#: src/config/SSSDConfig/sssdoptions.py:114 +#: src/config/SSSDConfig/sssdoptions.py:113 msgid "How many seconds will pam_sss wait for passkey_child to finish" msgstr "pam_sss が passkey_child の終了を待機する秒数" -#: src/config/SSSDConfig/sssdoptions.py:115 +#: src/config/SSSDConfig/sssdoptions.py:114 msgid "Enable debugging in the libfido2 library" msgstr "lifido2 ライブラリーでデバッグを有効にする" -#: src/config/SSSDConfig/sssdoptions.py:116 +#: src/config/SSSDConfig/sssdoptions.py:115 msgid "Enable JSON protocol for authentication methods selection." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:119 +#: src/config/SSSDConfig/sssdoptions.py:118 msgid "Whether to evaluate the time-based attributes in sudo rules" msgstr "sudo ルールにおいて時間による属性を評価するかどうか" -#: src/config/SSSDConfig/sssdoptions.py:120 +#: src/config/SSSDConfig/sssdoptions.py:119 msgid "If true, SSSD will switch back to lower-wins ordering logic" msgstr "正しい場合、SSSD は小さい番号が優先される順位付けのロジックへ戻ります" -#: src/config/SSSDConfig/sssdoptions.py:121 +#: src/config/SSSDConfig/sssdoptions.py:120 msgid "" "Maximum number of rules that can be refreshed at once. If this is exceeded, " "full refresh is performed." @@ -410,57 +422,58 @@ msgstr "" "一度にリフレッシュ可能なルールの最大数。最大数を超えると、フルリフレッシュが" "実行されます。" -#: src/config/SSSDConfig/sssdoptions.py:128 +#: src/config/SSSDConfig/sssdoptions.py:127 msgid "Whether to hash host names and addresses in the known_hosts file" msgstr "known_hosts ファイルにおいてホスト名とアドレスをハッシュ化するかどうか" -#: src/config/SSSDConfig/sssdoptions.py:129 +#: src/config/SSSDConfig/sssdoptions.py:128 msgid "" "How many seconds to keep a host in the known_hosts file after its host keys " "were requested" msgstr "ホスト鍵が要求された後 known_hosts ファイルにホストを保持する秒数" -#: src/config/SSSDConfig/sssdoptions.py:131 +#: src/config/SSSDConfig/sssdoptions.py:130 msgid "Path to storage of trusted CA certificates" msgstr "信頼された CA 証明書のストレージへのパス" -#: src/config/SSSDConfig/sssdoptions.py:132 +#: src/config/SSSDConfig/sssdoptions.py:131 msgid "Allow to generate ssh-keys from certificates" msgstr "証明書からの ssh-key の生成を許可します" -#: src/config/SSSDConfig/sssdoptions.py:133 +#: src/config/SSSDConfig/sssdoptions.py:132 msgid "" "Use the following matching rules to filter the certificates for ssh-key " "generation" -msgstr "以下の一致するルールを使用して、ssh-key 生成用の証明書をフィルタリングします" +msgstr "" +"以下の一致するルールを使用して、ssh-key 生成用の証明書をフィルタリングします" -#: src/config/SSSDConfig/sssdoptions.py:137 +#: src/config/SSSDConfig/sssdoptions.py:136 msgid "List of UIDs or user names allowed to access the PAC responder" msgstr "PAC レスポンダーへのアクセスが許可された UID またはユーザー名の一覧" -#: src/config/SSSDConfig/sssdoptions.py:138 +#: src/config/SSSDConfig/sssdoptions.py:137 msgid "How long the PAC data is considered valid" msgstr "PAC データが有効とされる期間" -#: src/config/SSSDConfig/sssdoptions.py:139 +#: src/config/SSSDConfig/sssdoptions.py:138 msgid "Validate the PAC" msgstr "PAC を検証する" -#: src/config/SSSDConfig/sssdoptions.py:142 +#: src/config/SSSDConfig/sssdoptions.py:141 msgid "List of user attributes the InfoPipe is allowed to publish" msgstr "InfoPipe がパブリッシュを許可されたユーザー属性の一覧" -#: src/config/SSSDConfig/sssdoptions.py:145 +#: src/config/SSSDConfig/sssdoptions.py:144 msgid "" "One of the following strings specifying the scope of session recording: none " "- No users are recorded. some - Users/groups specified by users and groups " "options are recorded. all - All users are recorded." msgstr "" "セッション記録の範囲を指定する以下の文字列の 1 つ: none: 記録されたユーザーは" -"いません。some: ユーザーとグループオプションによって指定されているユーザー/" -"グループが記録されています。all: すべてのユーザーが記録されます。" +"いません。some: ユーザーとグループオプションによって指定されているユーザー/グ" +"ループが記録されています。all: すべてのユーザーが記録されます。" -#: src/config/SSSDConfig/sssdoptions.py:148 +#: src/config/SSSDConfig/sssdoptions.py:147 msgid "" "A comma-separated list of users which should have session recording enabled. " "Matches user names as returned by NSS. I.e. after the possible space " @@ -470,23 +483,23 @@ msgstr "" "返すユーザー名にマッチします。つまり、スペースの置換、大文字小文字の変更など" "の可能性がある場合には、その後になります。" -#: src/config/SSSDConfig/sssdoptions.py:150 +#: src/config/SSSDConfig/sssdoptions.py:149 msgid "" "A comma-separated list of groups, members of which should have session " "recording enabled. Matches group names as returned by NSS. I.e. after the " "possible space replacement, case changes, etc." msgstr "" -"セッション記録を有効にしておくべきユーザーのグループごとのカンマ区切りの" -"リストです。NSS が返すグループ名にマッチします。つまり、スペースの置換、大文" -"字小文字の変更などの可能性がある場合には、その後になります。" +"セッション記録を有効にしておくべきユーザーのグループごとのカンマ区切りのリス" +"トです。NSS が返すグループ名にマッチします。つまり、スペースの置換、大文字小" +"文字の変更などの可能性がある場合には、その後になります。" -#: src/config/SSSDConfig/sssdoptions.py:153 +#: src/config/SSSDConfig/sssdoptions.py:152 msgid "" "A comma-separated list of users to be excluded from recording, only when " "scope=all" msgstr "録画から除外されるユーザーのコンマ区切りリスト。scope=all の場合のみ" -#: src/config/SSSDConfig/sssdoptions.py:154 +#: src/config/SSSDConfig/sssdoptions.py:153 msgid "" "A comma-separated list of groups, members of which should be excluded from " "recording, only when scope=all. " @@ -494,79 +507,79 @@ msgstr "" "scope=all の場合にのみ記録から除外されるべきメンバーから成るグループのコンマ" "区切りリスト。 " -#: src/config/SSSDConfig/sssdoptions.py:158 +#: src/config/SSSDConfig/sssdoptions.py:157 msgid "Identity provider" msgstr "アイデンティティープロバイダー" -#: src/config/SSSDConfig/sssdoptions.py:159 +#: src/config/SSSDConfig/sssdoptions.py:158 msgid "Authentication provider" msgstr "認証プロバイダー" -#: src/config/SSSDConfig/sssdoptions.py:160 +#: src/config/SSSDConfig/sssdoptions.py:159 msgid "Access control provider" msgstr "アクセス制御プロバイダー" -#: src/config/SSSDConfig/sssdoptions.py:161 +#: src/config/SSSDConfig/sssdoptions.py:160 msgid "Password change provider" msgstr "パスワード変更プロバイダー" -#: src/config/SSSDConfig/sssdoptions.py:162 +#: src/config/SSSDConfig/sssdoptions.py:161 msgid "SUDO provider" msgstr "SUDO プロバイダー" -#: src/config/SSSDConfig/sssdoptions.py:163 +#: src/config/SSSDConfig/sssdoptions.py:162 msgid "Autofs provider" msgstr "Autofs プロバイダー" -#: src/config/SSSDConfig/sssdoptions.py:164 +#: src/config/SSSDConfig/sssdoptions.py:163 msgid "Host identity provider" msgstr "ホスト識別プロバイダー" -#: src/config/SSSDConfig/sssdoptions.py:165 +#: src/config/SSSDConfig/sssdoptions.py:164 msgid "SELinux provider" msgstr "SELinux プロバイダー" -#: src/config/SSSDConfig/sssdoptions.py:166 +#: src/config/SSSDConfig/sssdoptions.py:165 msgid "Session management provider" msgstr "セッションマネージャーのプロバイダー" -#: src/config/SSSDConfig/sssdoptions.py:167 +#: src/config/SSSDConfig/sssdoptions.py:166 msgid "Resolver provider" msgstr "リゾルバープロバイダ" -#: src/config/SSSDConfig/sssdoptions.py:170 +#: src/config/SSSDConfig/sssdoptions.py:169 msgid "Whether the domain is usable by the OS or by applications" msgstr "OS またはアプリケーションがドメインを使用できるかどうか" -#: src/config/SSSDConfig/sssdoptions.py:171 +#: src/config/SSSDConfig/sssdoptions.py:170 msgid "Enable or disable the domain" msgstr "ドメインを有効または無効にする" -#: src/config/SSSDConfig/sssdoptions.py:172 +#: src/config/SSSDConfig/sssdoptions.py:171 msgid "Minimum user ID" msgstr "最小ユーザー ID" -#: src/config/SSSDConfig/sssdoptions.py:173 +#: src/config/SSSDConfig/sssdoptions.py:172 msgid "Maximum user ID" msgstr "最大ユーザー ID" -#: src/config/SSSDConfig/sssdoptions.py:174 +#: src/config/SSSDConfig/sssdoptions.py:173 msgid "Enable enumerating all users/groups" msgstr "すべてのユーザー・グループの列挙を有効にする" -#: src/config/SSSDConfig/sssdoptions.py:175 +#: src/config/SSSDConfig/sssdoptions.py:174 msgid "Cache credentials for offline login" msgstr "オフラインログインのためにクレデンシャルをキャッシュする" -#: src/config/SSSDConfig/sssdoptions.py:176 +#: src/config/SSSDConfig/sssdoptions.py:175 msgid "Display users/groups in fully-qualified form" msgstr "ユーザー・グループを完全修飾形式で表示する" -#: src/config/SSSDConfig/sssdoptions.py:177 +#: src/config/SSSDConfig/sssdoptions.py:176 msgid "Don't include group members in group lookups" msgstr "グループ検索にグループメンバーを含めない" -#: src/config/SSSDConfig/sssdoptions.py:178 +#: src/config/SSSDConfig/sssdoptions.py:177 #: src/config/SSSDConfig/sssdoptions.py:190 #: src/config/SSSDConfig/sssdoptions.py:191 #: src/config/SSSDConfig/sssdoptions.py:192 @@ -577,16 +590,16 @@ msgstr "グループ検索にグループメンバーを含めない" msgid "Entry cache timeout length (seconds)" msgstr "エントリーキャッシュのタイムアウト長 (秒)" -#: src/config/SSSDConfig/sssdoptions.py:179 +#: src/config/SSSDConfig/sssdoptions.py:178 msgid "" "Restrict or prefer a specific address family when performing DNS lookups" msgstr "DNS 検索を実行する時に特定のアドレスファミリーを制限または優先します" -#: src/config/SSSDConfig/sssdoptions.py:180 +#: src/config/SSSDConfig/sssdoptions.py:179 msgid "How long to keep cached entries after last successful login (days)" msgstr "最終ログイン成功時からキャッシュエントリーを保持する日数" -#: src/config/SSSDConfig/sssdoptions.py:181 +#: src/config/SSSDConfig/sssdoptions.py:180 msgid "" "How long should SSSD talk to single DNS server before trying next server " "(miliseconds)" @@ -594,33 +607,37 @@ msgstr "" "次のサーバーを試行するまでに SSSD が単一の DNS サーバーと通信する時間 (ミリ" "秒)" -#: src/config/SSSDConfig/sssdoptions.py:183 +#: src/config/SSSDConfig/sssdoptions.py:182 msgid "How long should keep trying to resolve single DNS query (seconds)" msgstr "単一の DNS クエリーの解決を試行する時間 (秒)" -#: src/config/SSSDConfig/sssdoptions.py:184 +#: src/config/SSSDConfig/sssdoptions.py:183 msgid "How long to wait for replies from DNS when resolving servers (seconds)" msgstr "サーバーを名前解決する時に DNS から応答を待つ時間 (秒)" -#: src/config/SSSDConfig/sssdoptions.py:185 +#: src/config/SSSDConfig/sssdoptions.py:184 msgid "The domain part of service discovery DNS query" msgstr "サービス検索 DNS クエリーのドメイン部分" -#: src/config/SSSDConfig/sssdoptions.py:186 +#: src/config/SSSDConfig/sssdoptions.py:185 msgid "" "Specifies the interval, in seconds, that SSSD waits before attempting to " "reconnect to the primary server after a successful connection to the backup " "server" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:188 +#: src/config/SSSDConfig/sssdoptions.py:187 msgid "Override GID value from the identity provider with this value" msgstr "識別プロバイダーからの GID 値をこの値で上書きする" -#: src/config/SSSDConfig/sssdoptions.py:189 +#: src/config/SSSDConfig/sssdoptions.py:188 msgid "Treat usernames as case sensitive" msgstr "ユーザー名が大文字小文字を区別するよう取り扱う" +#: src/config/SSSDConfig/sssdoptions.py:189 +msgid "Lookups by ID are expensive or do not work at all" +msgstr "" + #: src/config/SSSDConfig/sssdoptions.py:197 msgid "How often should expired entries be refreshed in background" msgstr "期限切れのエントリーがバックグラウンドで更新される頻度" @@ -662,7 +679,8 @@ msgstr "クライアントの DNS エントリーを更新するときの最大 #: src/config/SSSDConfig/sssdoptions.py:207 msgid "Whether the provider should explicitly update the PTR record as well" -msgstr "プロバイダーが同じように PTR レコードを明示的に更新する必要があるかどうか" +msgstr "" +"プロバイダーが同じように PTR レコードを明示的に更新する必要があるかどうか" #: src/config/SSSDConfig/sssdoptions.py:208 msgid "Whether the nsupdate utility should default to using TCP" @@ -845,8 +863,8 @@ msgid "" "The amount of time in minutes between lookups of Desktop Profiles rules " "against the IPA server when the last request did not find any rule" msgstr "" -"最後の要求がルールを何も見つけなかった場合の IPA サーバーに対する" -"デスクトッププロファイルルールを検索している間の分単位の合計時間" +"最後の要求がルールを何も見つけなかった場合の IPA サーバーに対するデスクトップ" +"プロファイルルールを検索している間の分単位の合計時間" #: src/config/SSSDConfig/sssdoptions.py:258 #: src/config/SSSDConfig/sssdoptions.py:455 @@ -854,7 +872,7 @@ msgid "Search base for SUBID ranges" msgstr "SUBID 範囲の検索ベース" #: src/config/SSSDConfig/sssdoptions.py:259 -#: src/config/SSSDConfig/sssdoptions.py:506 +#: src/config/SSSDConfig/sssdoptions.py:512 msgid "Which rules should be used to evaluate access control" msgstr "どのルールがアクセス制御を評価するために使用されるか" @@ -975,12 +993,13 @@ msgid "" "lookups of users and groups from trusted domains differently." msgstr "" "このオプションは、SSSD が IPA サーバー上で実行されており、信頼されたドメイン" -"からのユーザーとグループの検索を異なる方法で実行する必要があることを示します" -"。" +"からのユーザーとグループの検索を異なる方法で実行する必要があることを示しま" +"す。" #: src/config/SSSDConfig/sssdoptions.py:292 msgid "Use the given string as search base for trusted domains." -msgstr "信頼されたドメインに対する検索ベースとして、与えられた文字列を使用します。" +msgstr "" +"信頼されたドメインに対する検索ベースとして、与えられた文字列を使用します。" #: src/config/SSSDConfig/sssdoptions.py:295 msgid "Active Directory domain" @@ -1007,7 +1026,7 @@ msgid "Enable DNS sites - location based service discovery" msgstr "DNS サイトの有効化 - 位置ベースのサービス検索" #: src/config/SSSDConfig/sssdoptions.py:301 -#: src/config/SSSDConfig/sssdoptions.py:504 +#: src/config/SSSDConfig/sssdoptions.py:510 msgid "LDAP filter to determine access privileges" msgstr "アクセス権限を決めるための LDAP フィルター" @@ -1029,25 +1048,28 @@ msgstr "AD サーバーに対する GPO ポリシーファイルを検索して msgid "" "PAM service names that map to the GPO (Deny)InteractiveLogonRight policy " "settings" -msgstr "GPO (Deny)InteractiveLogonRight のポリシー設定にマッピングした PAM サービス名" +msgstr "" +"GPO (Deny)InteractiveLogonRight のポリシー設定にマッピングした PAM サービス名" #: src/config/SSSDConfig/sssdoptions.py:307 msgid "" "PAM service names that map to the GPO (Deny)RemoteInteractiveLogonRight " "policy settings" msgstr "" -"GPO (Deny)RemoteInteractiveLogonRight のポリシー設定にマッピングした PAM " -"サービス名" +"GPO (Deny)RemoteInteractiveLogonRight のポリシー設定にマッピングした PAM サー" +"ビス名" #: src/config/SSSDConfig/sssdoptions.py:309 msgid "" "PAM service names that map to the GPO (Deny)NetworkLogonRight policy settings" -msgstr "GPO (Deny)NetworkLogonRight のポリシー設定にマッピングした PAM サービス名" +msgstr "" +"GPO (Deny)NetworkLogonRight のポリシー設定にマッピングした PAM サービス名" #: src/config/SSSDConfig/sssdoptions.py:310 msgid "" "PAM service names that map to the GPO (Deny)BatchLogonRight policy settings" -msgstr "GPO (Deny)BatchLogonRight のポリシー設定にマッピングした PAM サービス名" +msgstr "" +"GPO (Deny)BatchLogonRight のポリシー設定にマッピングした PAM サービス名" #: src/config/SSSDConfig/sssdoptions.py:311 msgid "" @@ -1325,8 +1347,8 @@ msgid "" "Allows to retain local users as members of an LDAP group for servers that " "use the RFC2307 schema." msgstr "" -"RFC2307 スキーマを使用するサーバーの LDAP グループのメンバーとして" -"ローカルユーザーを保持することができます。" +"RFC2307 スキーマを使用するサーバーの LDAP グループのメンバーとしてローカル" +"ユーザーを保持することができます。" #: src/config/SSSDConfig/sssdoptions.py:392 msgid "entryUSN attribute" @@ -1435,7 +1457,7 @@ msgid "UUID attribute" msgstr "UUID 属性" #: src/config/SSSDConfig/sssdoptions.py:423 -#: src/config/SSSDConfig/sssdoptions.py:464 +#: src/config/SSSDConfig/sssdoptions.py:470 msgid "objectSID attribute" msgstr "objectSID 属性" @@ -1559,203 +1581,232 @@ msgstr "ユーザーのパスキーマッピングデータを含む属性" msgid "A list of extra attributes to download along with the user entry" msgstr "ユーザーエントリーと共にダウンロードする追加的な属性の一覧" +#: src/config/SSSDConfig/sssdoptions.py:456 +#, fuzzy +msgid "The object class of an subid entry in LDAP." +msgstr "LDAP にあるホストエントリーのオブジェクトクラスです。" + #: src/config/SSSDConfig/sssdoptions.py:457 +#, fuzzy +msgid "Subordinate user ID count attribute" +msgstr "sudo ルールのユーザーの属性" + +#: src/config/SSSDConfig/sssdoptions.py:458 +#, fuzzy +msgid "Subordinate group ID count attribute" +msgstr "sudo ルールのオプションの属性" + +#: src/config/SSSDConfig/sssdoptions.py:459 +#, fuzzy +msgid "User ID range start value attribute" +msgstr "ユーザー名の属性" + +#: src/config/SSSDConfig/sssdoptions.py:460 +#, fuzzy +msgid "Group ID range start value attribute" +msgstr "グループ UUID 属性" + +#: src/config/SSSDConfig/sssdoptions.py:461 +msgid "Owner of an entry" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:463 msgid "Base DN for group lookups" msgstr "グループ検索のベース DN" -#: src/config/SSSDConfig/sssdoptions.py:458 +#: src/config/SSSDConfig/sssdoptions.py:464 msgid "Objectclass for groups" msgstr "グループのオブジェクトクラス" -#: src/config/SSSDConfig/sssdoptions.py:459 +#: src/config/SSSDConfig/sssdoptions.py:465 msgid "Group name" msgstr "グループ名" -#: src/config/SSSDConfig/sssdoptions.py:460 +#: src/config/SSSDConfig/sssdoptions.py:466 msgid "Group password" msgstr "グループのパスワード" -#: src/config/SSSDConfig/sssdoptions.py:461 +#: src/config/SSSDConfig/sssdoptions.py:467 msgid "GID attribute" msgstr "GID 属性" -#: src/config/SSSDConfig/sssdoptions.py:462 +#: src/config/SSSDConfig/sssdoptions.py:468 msgid "Group member attribute" msgstr "グループメンバー属性" -#: src/config/SSSDConfig/sssdoptions.py:463 +#: src/config/SSSDConfig/sssdoptions.py:469 msgid "Group UUID attribute" msgstr "グループ UUID 属性" -#: src/config/SSSDConfig/sssdoptions.py:465 +#: src/config/SSSDConfig/sssdoptions.py:471 msgid "Modification time attribute for groups" msgstr "グループの変更日時の属性" -#: src/config/SSSDConfig/sssdoptions.py:466 +#: src/config/SSSDConfig/sssdoptions.py:472 msgid "Type of the group and other flags" msgstr "グループおよび他のフラグのタイプ" -#: src/config/SSSDConfig/sssdoptions.py:467 +#: src/config/SSSDConfig/sssdoptions.py:473 msgid "The LDAP group external member attribute" msgstr "LDAP グループの外部メンバーの属性" -#: src/config/SSSDConfig/sssdoptions.py:468 +#: src/config/SSSDConfig/sssdoptions.py:474 msgid "Maximum nesting level SSSD will follow" msgstr "SSSD が従う最大ネストレベル" -#: src/config/SSSDConfig/sssdoptions.py:469 +#: src/config/SSSDConfig/sssdoptions.py:475 msgid "Filter for group lookups" msgstr "グループ検索のフィルター" -#: src/config/SSSDConfig/sssdoptions.py:470 +#: src/config/SSSDConfig/sssdoptions.py:476 msgid "Scope of group lookups" msgstr "グループ検索の範囲" -#: src/config/SSSDConfig/sssdoptions.py:472 +#: src/config/SSSDConfig/sssdoptions.py:478 msgid "Base DN for netgroup lookups" msgstr "ネットグループ検索のベース DN" -#: src/config/SSSDConfig/sssdoptions.py:473 +#: src/config/SSSDConfig/sssdoptions.py:479 msgid "Objectclass for netgroups" msgstr "ネットグループのオブジェクトクラス" -#: src/config/SSSDConfig/sssdoptions.py:474 +#: src/config/SSSDConfig/sssdoptions.py:480 msgid "Netgroup name" msgstr "ネットグループ名" -#: src/config/SSSDConfig/sssdoptions.py:475 +#: src/config/SSSDConfig/sssdoptions.py:481 msgid "Netgroups members attribute" msgstr "ネットグループメンバーの属性" -#: src/config/SSSDConfig/sssdoptions.py:476 +#: src/config/SSSDConfig/sssdoptions.py:482 msgid "Netgroup triple attribute" msgstr "ネットグループの三つ組の属性" -#: src/config/SSSDConfig/sssdoptions.py:477 +#: src/config/SSSDConfig/sssdoptions.py:483 msgid "Modification time attribute for netgroups" msgstr "ネットグループの変更日時の属性" -#: src/config/SSSDConfig/sssdoptions.py:479 +#: src/config/SSSDConfig/sssdoptions.py:485 msgid "Base DN for service lookups" msgstr "サービス検索のベース DN" -#: src/config/SSSDConfig/sssdoptions.py:480 +#: src/config/SSSDConfig/sssdoptions.py:486 msgid "Objectclass for services" msgstr "サービスのオブジェクトクラス" -#: src/config/SSSDConfig/sssdoptions.py:481 +#: src/config/SSSDConfig/sssdoptions.py:487 msgid "Service name attribute" msgstr "サービス名の属性" -#: src/config/SSSDConfig/sssdoptions.py:482 +#: src/config/SSSDConfig/sssdoptions.py:488 msgid "Service port attribute" msgstr "サービスポートの属性" -#: src/config/SSSDConfig/sssdoptions.py:483 +#: src/config/SSSDConfig/sssdoptions.py:489 msgid "Service protocol attribute" msgstr "サービスプロトコルの属性" -#: src/config/SSSDConfig/sssdoptions.py:485 +#: src/config/SSSDConfig/sssdoptions.py:491 msgid "Lower bound for ID-mapping" msgstr "ID マッピングの下限" -#: src/config/SSSDConfig/sssdoptions.py:486 +#: src/config/SSSDConfig/sssdoptions.py:492 msgid "Upper bound for ID-mapping" msgstr "ID マッピングの上限" -#: src/config/SSSDConfig/sssdoptions.py:487 +#: src/config/SSSDConfig/sssdoptions.py:493 msgid "Number of IDs for each slice when ID-mapping" msgstr "ID マッピングするとき、各スライスに対する ID の数" -#: src/config/SSSDConfig/sssdoptions.py:488 +#: src/config/SSSDConfig/sssdoptions.py:494 msgid "Use autorid-compatible algorithm for ID-mapping" msgstr "ID マッピングに対する autorid 互換アルゴリズムを使用します" -#: src/config/SSSDConfig/sssdoptions.py:489 +#: src/config/SSSDConfig/sssdoptions.py:495 msgid "Name of the default domain for ID-mapping" msgstr "ID マッピングに対するデフォルトドメインの名前" -#: src/config/SSSDConfig/sssdoptions.py:490 +#: src/config/SSSDConfig/sssdoptions.py:496 msgid "SID of the default domain for ID-mapping" msgstr "ID マッピングに対するデフォルトドメインの SID" -#: src/config/SSSDConfig/sssdoptions.py:491 +#: src/config/SSSDConfig/sssdoptions.py:497 msgid "Number of secondary slices" msgstr "セカンダリースライスの数" -#: src/config/SSSDConfig/sssdoptions.py:493 +#: src/config/SSSDConfig/sssdoptions.py:499 msgid "Whether to use Token-Groups" msgstr "Token-Group を使うかどうか" -#: src/config/SSSDConfig/sssdoptions.py:494 +#: src/config/SSSDConfig/sssdoptions.py:500 msgid "Set lower boundary for allowed IDs from the LDAP server" msgstr "LDAP サーバーから許可される ID の下限の設定" -#: src/config/SSSDConfig/sssdoptions.py:495 +#: src/config/SSSDConfig/sssdoptions.py:501 msgid "Set upper boundary for allowed IDs from the LDAP server" msgstr "LDAP サーバーから許可される ID の上限の設定" -#: src/config/SSSDConfig/sssdoptions.py:496 +#: src/config/SSSDConfig/sssdoptions.py:502 msgid "DN for ppolicy queries" msgstr "ppolicy クエリーの DN" -#: src/config/SSSDConfig/sssdoptions.py:497 +#: src/config/SSSDConfig/sssdoptions.py:503 msgid "How many maximum entries to fetch during a wildcard request" msgstr "ワイルドカードの要求の間に取得する最大エントリーの数" -#: src/config/SSSDConfig/sssdoptions.py:498 +#: src/config/SSSDConfig/sssdoptions.py:504 msgid "Set libldap debug level" msgstr "libldap デバッグレベルの設定" -#: src/config/SSSDConfig/sssdoptions.py:501 +#: src/config/SSSDConfig/sssdoptions.py:507 msgid "Policy to evaluate the password expiration" msgstr "パスワード失効の評価のポリシー" -#: src/config/SSSDConfig/sssdoptions.py:505 +#: src/config/SSSDConfig/sssdoptions.py:511 msgid "Which attributes shall be used to evaluate if an account is expired" msgstr "どの属性がアカウントが失効しているかを評価するために使用されるか" -#: src/config/SSSDConfig/sssdoptions.py:509 +#: src/config/SSSDConfig/sssdoptions.py:515 msgid "URI of an LDAP server where password changes are allowed" msgstr "パスワードの変更が許可される LDAP サーバーの URI" -#: src/config/SSSDConfig/sssdoptions.py:510 +#: src/config/SSSDConfig/sssdoptions.py:516 msgid "URI of a backup LDAP server where password changes are allowed" msgstr "パスワードの変更が許可されるバックアップ LDAP サーバーの URI" -#: src/config/SSSDConfig/sssdoptions.py:511 +#: src/config/SSSDConfig/sssdoptions.py:517 msgid "DNS service name for LDAP password change server" msgstr "LDAP パスワードの変更サーバーの DNS サービス名" -#: src/config/SSSDConfig/sssdoptions.py:512 +#: src/config/SSSDConfig/sssdoptions.py:518 msgid "" "Whether to update the ldap_user_shadow_last_change attribute after a " "password change" msgstr "パスワード変更後 ldap_user_shadow_last_change 属性を更新するかどうか" -#: src/config/SSSDConfig/sssdoptions.py:516 +#: src/config/SSSDConfig/sssdoptions.py:522 msgid "Base DN for sudo rules lookups" msgstr "sudo ルール検索のベース DN" -#: src/config/SSSDConfig/sssdoptions.py:517 +#: src/config/SSSDConfig/sssdoptions.py:523 msgid "Automatic full refresh period" msgstr "自動的な完全更新間隔" -#: src/config/SSSDConfig/sssdoptions.py:518 +#: src/config/SSSDConfig/sssdoptions.py:524 msgid "Automatic smart refresh period" msgstr "自動的なスマート更新間隔" -#: src/config/SSSDConfig/sssdoptions.py:519 +#: src/config/SSSDConfig/sssdoptions.py:525 msgid "Smart and full refresh random offset" msgstr "スマートおよびフル更新ランダムオフセット" -#: src/config/SSSDConfig/sssdoptions.py:520 +#: src/config/SSSDConfig/sssdoptions.py:526 msgid "Whether to filter rules by hostname, IP addresses and network" msgstr "" "ホスト名、IP アドレスおよびネットワークによるフィルタールールを使用するかどう" "か" -#: src/config/SSSDConfig/sssdoptions.py:521 +#: src/config/SSSDConfig/sssdoptions.py:527 msgid "" "Hostnames and/or fully qualified domain names of this machine to filter sudo " "rules" @@ -1763,158 +1814,158 @@ msgstr "" "sudo ルールをフィルターするこのマシンのホスト名および/または完全修飾ドメイン" "名" -#: src/config/SSSDConfig/sssdoptions.py:522 +#: src/config/SSSDConfig/sssdoptions.py:528 msgid "IPv4 or IPv6 addresses or network of this machine to filter sudo rules" msgstr "" -"sudo ルールをフィルターするこのマシンの IPv4 または IPv6 アドレスまたは" -"ネットワーク" +"sudo ルールをフィルターするこのマシンの IPv4 または IPv6 アドレスまたはネット" +"ワーク" -#: src/config/SSSDConfig/sssdoptions.py:523 +#: src/config/SSSDConfig/sssdoptions.py:529 msgid "Whether to include rules that contains netgroup in host attribute" msgstr "ホスト属性にネットワークグループを含むルールを含めるかどうか" -#: src/config/SSSDConfig/sssdoptions.py:524 +#: src/config/SSSDConfig/sssdoptions.py:530 msgid "" "Whether to include rules that contains regular expression in host attribute" msgstr "ホスト属性に正規表現を含むルールを含めるかどうか" -#: src/config/SSSDConfig/sssdoptions.py:525 +#: src/config/SSSDConfig/sssdoptions.py:531 msgid "Object class for sudo rules" msgstr "sudo ルールのオブジェクトクラス" -#: src/config/SSSDConfig/sssdoptions.py:526 +#: src/config/SSSDConfig/sssdoptions.py:532 msgid "Name of attribute that is used as object class for sudo rules" msgstr "sudo ルールのオブジェクトクラスとして使用される属性の名前" -#: src/config/SSSDConfig/sssdoptions.py:527 +#: src/config/SSSDConfig/sssdoptions.py:533 msgid "Sudo rule name" msgstr "sudo ルール名" -#: src/config/SSSDConfig/sssdoptions.py:528 +#: src/config/SSSDConfig/sssdoptions.py:534 msgid "Sudo rule command attribute" msgstr "sudo ルールのコマンドの属性" -#: src/config/SSSDConfig/sssdoptions.py:529 +#: src/config/SSSDConfig/sssdoptions.py:535 msgid "Sudo rule host attribute" msgstr "sudo ルールのホストの属性" -#: src/config/SSSDConfig/sssdoptions.py:530 +#: src/config/SSSDConfig/sssdoptions.py:536 msgid "Sudo rule user attribute" msgstr "sudo ルールのユーザーの属性" -#: src/config/SSSDConfig/sssdoptions.py:531 +#: src/config/SSSDConfig/sssdoptions.py:537 msgid "Sudo rule option attribute" msgstr "sudo ルールのオプションの属性" -#: src/config/SSSDConfig/sssdoptions.py:532 +#: src/config/SSSDConfig/sssdoptions.py:538 msgid "Sudo rule runas attribute" msgstr "sudo ルールの runas の属性" -#: src/config/SSSDConfig/sssdoptions.py:533 +#: src/config/SSSDConfig/sssdoptions.py:539 msgid "Sudo rule runasuser attribute" msgstr "sudo ルールの runasuser の属性" -#: src/config/SSSDConfig/sssdoptions.py:534 +#: src/config/SSSDConfig/sssdoptions.py:540 msgid "Sudo rule runasgroup attribute" msgstr "sudo ルールの runasgroup の属性" -#: src/config/SSSDConfig/sssdoptions.py:535 +#: src/config/SSSDConfig/sssdoptions.py:541 msgid "Sudo rule notbefore attribute" msgstr "sudo ルールの notbefore の属性" -#: src/config/SSSDConfig/sssdoptions.py:536 +#: src/config/SSSDConfig/sssdoptions.py:542 msgid "Sudo rule notafter attribute" msgstr "sudo ルールの notafter の属性" -#: src/config/SSSDConfig/sssdoptions.py:537 +#: src/config/SSSDConfig/sssdoptions.py:543 msgid "Sudo rule order attribute" msgstr "sudo ルールの order の属性" -#: src/config/SSSDConfig/sssdoptions.py:540 +#: src/config/SSSDConfig/sssdoptions.py:546 msgid "Object class for automounter maps" msgstr "automounter マップのオブジェクトクラス" -#: src/config/SSSDConfig/sssdoptions.py:541 +#: src/config/SSSDConfig/sssdoptions.py:547 msgid "Automounter map name attribute" msgstr "オートマウントのマップ名の属性" -#: src/config/SSSDConfig/sssdoptions.py:542 +#: src/config/SSSDConfig/sssdoptions.py:548 msgid "Object class for automounter map entries" msgstr "automounter マップエントリーのオブジェクトクラス" -#: src/config/SSSDConfig/sssdoptions.py:543 +#: src/config/SSSDConfig/sssdoptions.py:549 msgid "Automounter map entry key attribute" msgstr "automounter マップエントリーの鍵属性" -#: src/config/SSSDConfig/sssdoptions.py:544 +#: src/config/SSSDConfig/sssdoptions.py:550 msgid "Automounter map entry value attribute" msgstr "automounter マップエントリーの値属性" -#: src/config/SSSDConfig/sssdoptions.py:545 +#: src/config/SSSDConfig/sssdoptions.py:551 msgid "Base DN for automounter map lookups" msgstr "automonter のマップ検索のベース DN" -#: src/config/SSSDConfig/sssdoptions.py:546 +#: src/config/SSSDConfig/sssdoptions.py:552 msgid "The name of the automount master map in LDAP." msgstr "LDAP のオートマウントマスターマップの名前。" -#: src/config/SSSDConfig/sssdoptions.py:549 +#: src/config/SSSDConfig/sssdoptions.py:555 msgid "Base DN for IP hosts lookups" msgstr "IP ホストのルックアップのためのベース DN" -#: src/config/SSSDConfig/sssdoptions.py:550 +#: src/config/SSSDConfig/sssdoptions.py:556 msgid "Object class for IP hosts" msgstr "IP ホストのオブジェクトクラス" -#: src/config/SSSDConfig/sssdoptions.py:551 +#: src/config/SSSDConfig/sssdoptions.py:557 msgid "IP host name attribute" msgstr "IP ホスト名属性" -#: src/config/SSSDConfig/sssdoptions.py:552 +#: src/config/SSSDConfig/sssdoptions.py:558 msgid "IP host number (address) attribute" msgstr "IP ホスト番号 (アドレス) 属性" -#: src/config/SSSDConfig/sssdoptions.py:553 +#: src/config/SSSDConfig/sssdoptions.py:559 msgid "IP host entryUSN attribute" msgstr "IP ホストエントリー USN 属性" -#: src/config/SSSDConfig/sssdoptions.py:554 +#: src/config/SSSDConfig/sssdoptions.py:560 msgid "Base DN for IP networks lookups" msgstr "IP ネットワーク検索のためのベース DN" -#: src/config/SSSDConfig/sssdoptions.py:555 +#: src/config/SSSDConfig/sssdoptions.py:561 msgid "Object class for IP networks" msgstr "IP ネットワークのオブジェクトクラス" -#: src/config/SSSDConfig/sssdoptions.py:556 +#: src/config/SSSDConfig/sssdoptions.py:562 msgid "IP network name attribute" msgstr "IP ネットワーク名属性" -#: src/config/SSSDConfig/sssdoptions.py:557 +#: src/config/SSSDConfig/sssdoptions.py:563 msgid "IP network number (address) attribute" msgstr "IP ネットワーク番号 (アドレス) 属性" -#: src/config/SSSDConfig/sssdoptions.py:558 +#: src/config/SSSDConfig/sssdoptions.py:564 msgid "IP network entryUSN attribute" msgstr "IP ネットワークエントリー USN 属性" -#: src/config/SSSDConfig/sssdoptions.py:561 +#: src/config/SSSDConfig/sssdoptions.py:567 msgid "Comma separated list of allowed users" msgstr "許可ユーザーのカンマ区切り一覧" -#: src/config/SSSDConfig/sssdoptions.py:562 +#: src/config/SSSDConfig/sssdoptions.py:568 msgid "Comma separated list of prohibited users" msgstr "禁止ユーザーのカンマ区切り一覧" -#: src/config/SSSDConfig/sssdoptions.py:563 +#: src/config/SSSDConfig/sssdoptions.py:569 msgid "" "Comma separated list of groups that are allowed to log in. This applies only " "to groups within this SSSD domain. Local groups are not evaluated." msgstr "" -"ログインが許可されるグループのカンマ区切りの一覧。これは、SSSDドメイン内の" -"グループにのみ適用されます。ローカルグループは評価されません。" +"ログインが許可されるグループのカンマ区切りの一覧。これは、SSSDドメイン内のグ" +"ループにのみ適用されます。ローカルグループは評価されません。" -#: src/config/SSSDConfig/sssdoptions.py:565 +#: src/config/SSSDConfig/sssdoptions.py:571 msgid "" "Comma separated list of groups that are explicitly denied access. This " "applies only to groups within this SSSD domain. Local groups are not " @@ -1923,31 +1974,31 @@ msgstr "" "排他的にアクセスが拒否されたグループのカンマ区切りの一覧。これは、この SSSD " "ドメイン内のグループにのみ適用されます。ローカルグループは評価されません。" -#: src/config/SSSDConfig/sssdoptions.py:569 +#: src/config/SSSDConfig/sssdoptions.py:575 msgid "The number of preforked proxy children." msgstr "事前にフォークされた子プロキシーの数。" -#: src/config/SSSDConfig/sssdoptions.py:572 +#: src/config/SSSDConfig/sssdoptions.py:578 msgid "The name of the NSS library to use" msgstr "使用する NSS ライブラリーの名前" -#: src/config/SSSDConfig/sssdoptions.py:573 +#: src/config/SSSDConfig/sssdoptions.py:579 msgid "The name of the NSS library to use for hosts and networks lookups" msgstr "ホストやネットワークの検索に使用する NSS ライブラリの名前" -#: src/config/SSSDConfig/sssdoptions.py:574 +#: src/config/SSSDConfig/sssdoptions.py:580 msgid "Whether to look up canonical group name from cache if possible" msgstr "可能ならばキャッシュから正規化されたグループ名を検索するかどうか" -#: src/config/SSSDConfig/sssdoptions.py:577 +#: src/config/SSSDConfig/sssdoptions.py:583 msgid "PAM stack to use" msgstr "使用する PAM スタック" -#: src/config/SSSDConfig/sssdoptions.py:580 +#: src/config/SSSDConfig/sssdoptions.py:586 msgid "Path of passwd file sources." msgstr "passwd ファイルソースへのパス。" -#: src/config/SSSDConfig/sssdoptions.py:581 +#: src/config/SSSDConfig/sssdoptions.py:587 msgid "Path of group file sources." msgstr "グループファイルソースへのパス。" @@ -1975,157 +2026,161 @@ msgstr "インデックス操作に失敗しました: %1$s\n" msgid "Option -i|--interactive is not allowed together with -D|--daemon\n" msgstr "Option -i|--interactive iは、 -D|--daemon とは使用できません\n" -#: src/monitor/monitor.c:1836 +#: src/monitor/monitor.c:1838 msgid "Failed to get initial capabilities\n" msgstr "" -#: src/monitor/monitor.c:1847 +#: src/monitor/monitor.c:1849 msgid "Non-root service user support isn't built. Can't run under %" msgstr "" -#: src/monitor/monitor.c:1864 +#: src/monitor/monitor.c:1866 #, c-format msgid "Can't read config: '%s'\n" msgstr "" -#: src/monitor/monitor.c:1876 +#: src/monitor/monitor.c:1878 #, c-format -msgid "Failed to boostrap SSSD 'monitor' process: %s" +msgid "Failed to bootstrap SSSD 'monitor' process: %s" msgstr "" -#: src/monitor/monitor.c:1971 +#: src/monitor/monitor.c:1973 msgid "Out of memory\n" msgstr "メモリー不足\n" -#: src/providers/krb5/krb5_child.c:4221 +#: src/providers/krb5/krb5_child.c:4316 msgid "Use anonymous PKINIT to request FAST armor ticket" msgstr "匿名の PKINIT を使用して FAST の armo チケットを要求する" -#: src/providers/krb5/krb5_child.c:4223 +#: src/providers/krb5/krb5_child.c:4318 msgid "Kerberos realm to use" msgstr "使用する Kerberos レルム" -#: src/providers/krb5/krb5_child.c:4225 +#: src/providers/krb5/krb5_child.c:4320 msgid "Requested lifetime of the ticket" msgstr "チケットの要求された有効期間" -#: src/providers/krb5/krb5_child.c:4227 +#: src/providers/krb5/krb5_child.c:4322 msgid "Requested renewable lifetime of the ticket" msgstr "チケットの要求された更新可能な有効期間" -#: src/providers/krb5/krb5_child.c:4229 +#: src/providers/krb5/krb5_child.c:4324 msgid "FAST options ('never', 'try', 'demand')" msgstr "FAST のオプション ('never'、'try'、'demand')" -#: src/providers/krb5/krb5_child.c:4232 +#: src/providers/krb5/krb5_child.c:4327 msgid "Specifies the server principal to use for FAST" msgstr "FAST で使用するサーバープリンシパルを指定します" -#: src/providers/krb5/krb5_child.c:4234 +#: src/providers/krb5/krb5_child.c:4329 msgid "Requests canonicalization of the principal name" msgstr "プリンシパル名の正規化を要求します" -#: src/providers/krb5/krb5_child.c:4236 +#: src/providers/krb5/krb5_child.c:4331 msgid "Use custom version of krb5_get_init_creds_password" msgstr "krb5_get_init_creds_password のカスタムバージョンを使用します" -#: src/providers/krb5/krb5_child.c:4238 +#: src/providers/krb5/krb5_child.c:4333 msgid "Check PAC flags" msgstr "PAC フラグを確認する" -#: src/providers/data_provider_be.c:790 +#: src/providers/krb5/krb5_child.c:4335 +msgid "Set environment variable (KEY=VALUE)" +msgstr "" + +#: src/providers/data_provider_be.c:786 msgid "Domain of the information provider (mandatory)" msgstr "情報プロバイダーのドメイン (必須)" -#: src/sss_client/common.c:1165 +#: src/sss_client/common.c:1208 #, fuzzy msgid "Socket has wrong ownership or permissions." msgstr "公開ソケットの所有者またはパーミッションが誤っています。" -#: src/sss_client/common.c:1168 +#: src/sss_client/common.c:1211 msgid "Unexpected format of the server credential message." msgstr "サーバーのクレデンシャルメッセージの予期しない形式です。" -#: src/sss_client/common.c:1171 +#: src/sss_client/common.c:1214 #, fuzzy msgid "SSSD is not run by trusted user." msgstr "SSSD は root により実行されません。" -#: src/sss_client/common.c:1174 +#: src/sss_client/common.c:1217 msgid "SSSD socket does not exist." msgstr "SSSD ソケットは存在しません。" -#: src/sss_client/common.c:1177 +#: src/sss_client/common.c:1220 msgid "Cannot get stat of SSSD socket." msgstr "SSSD ソケットの統計を取得できません。" -#: src/sss_client/common.c:1182 +#: src/sss_client/common.c:1225 msgid "An error occurred, but no description can be found." msgstr "エラーが発生しましたが、説明がありませんでした。" -#: src/sss_client/common.c:1188 +#: src/sss_client/common.c:1231 msgid "Unexpected error while looking for an error description" msgstr "エラーの説明を検索中に予期しないエラーが発生しました" -#: src/sss_client/pam_sss.c:74 +#: src/sss_client/pam_sss.c:135 msgid "Permission denied. " msgstr "パーミッションが拒否されました。 " -#: src/sss_client/pam_sss.c:75 src/sss_client/pam_sss.c:843 -#: src/sss_client/pam_sss.c:854 +#: src/sss_client/pam_sss.c:136 src/sss_client/pam_sss.c:921 +#: src/sss_client/pam_sss.c:932 msgid "Server message: " msgstr "サーバーのメッセージ: " -#: src/sss_client/pam_sss.c:76 +#: src/sss_client/pam_sss.c:137 msgid "" "Kerberos TGT will not be granted upon login, user experience will be " "affected." msgstr "" -#: src/sss_client/pam_sss.c:77 +#: src/sss_client/pam_sss.c:138 msgid "Enter PIN:" msgstr "PIN の入力:" -#: src/sss_client/pam_sss.c:320 +#: src/sss_client/pam_sss.c:385 msgid "Passwords do not match" msgstr "パスワードが一致しません" -#: src/sss_client/pam_sss.c:508 +#: src/sss_client/pam_sss.c:584 msgid "Password reset by root is not supported." msgstr "root によるパスワードのリセットはサポートされません。" -#: src/sss_client/pam_sss.c:549 +#: src/sss_client/pam_sss.c:625 msgid "Authenticated with cached credentials" msgstr "キャッシュされているクレデンシャルを用いて認証されました" -#: src/sss_client/pam_sss.c:550 +#: src/sss_client/pam_sss.c:626 msgid ", your cached password will expire at: " msgstr "、キャッシュされたパスワードが失効します: " -#: src/sss_client/pam_sss.c:580 +#: src/sss_client/pam_sss.c:656 #, c-format msgid "Your password has expired. You have %1$d grace login(s) remaining." msgstr "パスワードの期限が切れています。あと %1$d 回ログインできます。" -#: src/sss_client/pam_sss.c:630 +#: src/sss_client/pam_sss.c:706 #, c-format msgid "Your password will expire in %1$d %2$s." msgstr "あなたのパスワードは %1$d %2$s に期限切れになります。" -#: src/sss_client/pam_sss.c:633 +#: src/sss_client/pam_sss.c:709 #, c-format msgid "Your password has expired." msgstr "パスワードの有効期限が切れています。" -#: src/sss_client/pam_sss.c:684 +#: src/sss_client/pam_sss.c:760 msgid "Authentication is denied until: " msgstr "次まで認証が拒否されます: " -#: src/sss_client/pam_sss.c:705 +#: src/sss_client/pam_sss.c:781 msgid "System is offline, password change not possible" msgstr "システムがオフラインです、パスワード変更ができません" -#: src/sss_client/pam_sss.c:720 +#: src/sss_client/pam_sss.c:796 msgid "" "After changing the OTP password, you need to log out and back in order to " "acquire a ticket" @@ -2133,71 +2188,75 @@ msgstr "" "OTP パスワードの変更後、チケットを取得するためにログアウト後に再びログインす" "る必要があります" -#: src/sss_client/pam_sss.c:735 +#: src/sss_client/pam_sss.c:813 msgid "PIN locked" msgstr "PIN がロックされました" -#: src/sss_client/pam_sss.c:750 +#: src/sss_client/pam_sss.c:828 msgid "" "No Kerberos TGT granted as the server does not support this method. Your " "single-sign on(SSO) experience will be affected." msgstr "" -#: src/sss_client/pam_sss.c:840 src/sss_client/pam_sss.c:853 +#: src/sss_client/pam_sss.c:918 src/sss_client/pam_sss.c:931 msgid "Password change failed. " msgstr "パスワードの変更に失敗しました。 " -#: src/sss_client/pam_sss.c:1859 -#, c-format -msgid "Authenticate at %1$s and press ENTER." +#: src/sss_client/pam_sss.c:2028 +#, fuzzy, c-format +msgid "Authenticate at \"%1$s\"." msgstr "%1$s で認証し、ENTER を押します。" -#: src/sss_client/pam_sss.c:1862 -#, c-format -msgid "Authenticate with PIN %1$s at %2$s and press ENTER." +#: src/sss_client/pam_sss.c:2031 +#, fuzzy, c-format +msgid "Authenticate with PIN \"%1$s\" at \"%2$s\"." msgstr "%2$s で PIN %1$s を使用して認証し、ENTER を押します。" -#: src/sss_client/pam_sss.c:2281 +#: src/sss_client/pam_sss.c:2470 msgid "Please (re)insert (different) Smartcard" msgstr "(別の)スマートカードを挿入(し直)してください" -#: src/sss_client/pam_sss.c:2482 +#: src/sss_client/pam_sss.c:2700 msgid "New Password: " msgstr "新しいパスワード: " -#: src/sss_client/pam_sss.c:2483 +#: src/sss_client/pam_sss.c:2701 msgid "Reenter new Password: " msgstr "新しいパスワードの再入力: " -#: src/sss_client/pam_sss.c:2676 src/sss_client/pam_sss.c:2679 +#: src/sss_client/pam_sss.c:2890 +msgid "Press ENTER to continue." +msgstr "" + +#: src/sss_client/pam_sss.c:2913 src/sss_client/pam_sss.c:2916 msgid "First Factor: " msgstr "1 番目の要素: " -#: src/sss_client/pam_sss.c:2677 src/sss_client/pam_sss.c:2851 +#: src/sss_client/pam_sss.c:2914 src/sss_client/pam_sss.c:3088 msgid "Second Factor (optional): " msgstr "2 番目の要素 (オプション): " -#: src/sss_client/pam_sss.c:2680 src/sss_client/pam_sss.c:2855 +#: src/sss_client/pam_sss.c:2917 src/sss_client/pam_sss.c:3092 msgid "Second Factor: " msgstr "2 番目の要素: " -#: src/sss_client/pam_sss.c:2684 +#: src/sss_client/pam_sss.c:2921 msgid "Insert your passkey device, then press ENTER." msgstr "パスキーデバイスを挿入し、ENTER キーを押します。" -#: src/sss_client/pam_sss.c:2688 src/sss_client/pam_sss.c:2696 +#: src/sss_client/pam_sss.c:2925 src/sss_client/pam_sss.c:2933 msgid "Password: " msgstr "パスワード: " -#: src/sss_client/pam_sss.c:2850 src/sss_client/pam_sss.c:2854 +#: src/sss_client/pam_sss.c:3087 src/sss_client/pam_sss.c:3091 msgid "First Factor (Current Password): " msgstr "1 番目の要素 (現在のパスワード): " -#: src/sss_client/pam_sss.c:2874 +#: src/sss_client/pam_sss.c:3111 msgid "Current Password: " msgstr "現在のパスワード: " -#: src/sss_client/pam_sss.c:3248 +#: src/sss_client/pam_sss.c:3485 msgid "Password expired. Change your password now." msgstr "パスワードの期限が切れました。いますぐパスワードを変更してください。" @@ -2371,7 +2430,8 @@ msgstr "ユーザーインプットの読み込みができませんでした\n" #: src/tools/sssctl/sssctl.c:91 #, c-format msgid "Invalid input, please provide either '%s' or '%s'.\n" -msgstr "無効なインプットです。'%s' または '%s' のいずれかを提供してください。\n" +msgstr "" +"無効なインプットです。'%s' または '%s' のいずれかを提供してください。\n" #: src/tools/sssctl/sssctl.c:151 src/tools/sssctl/sssctl.c:161 msgid "Error while executing external command\n" @@ -2637,9 +2697,9 @@ msgstr "%s を開くことに失敗しました\n" #: src/tools/sssctl/sssctl_cache.c:835 src/tools/sssctl/sssctl_cache.c:918 #: src/tools/sssctl/sssctl_cache.c:950 src/tools/sssctl/sssctl_cache.c:956 #: src/tools/sssctl/sssctl_cache.c:1010 src/tools/sssctl/sssctl_cache.c:1034 -#: src/tools/sssctl/sssctl_cache.c:1085 src/tools/sssctl/sssctl_cache.c:1194 -#: src/tools/sssctl/sssctl_cache.c:1229 src/tools/sssctl/sssctl_cache.c:1235 -#: src/tools/sssctl/sssctl_cache.c:1244 +#: src/tools/sssctl/sssctl_cache.c:1085 src/tools/sssctl/sssctl_cache.c:1195 +#: src/tools/sssctl/sssctl_cache.c:1230 src/tools/sssctl/sssctl_cache.c:1236 +#: src/tools/sssctl/sssctl_cache.c:1245 #, fuzzy msgid "talloc failed\n" msgstr "malloc は失敗しました。\n" @@ -2717,26 +2777,26 @@ msgstr "" msgid "Unable to remove downloaded GPO files: %s\n" msgstr "ログファイルを削除できません\n" -#: src/tools/sssctl/sssctl_cache.c:1165 +#: src/tools/sssctl/sssctl_cache.c:1166 #, fuzzy, c-format msgid "Failed to fetch cache entry: %s\n" msgstr "%s を開くことに失敗しました\n" -#: src/tools/sssctl/sssctl_cache.c:1170 +#: src/tools/sssctl/sssctl_cache.c:1171 #, fuzzy msgid "Could not determine object domain\n" msgstr "利用可能なドメインを開けませんでした\n" -#: src/tools/sssctl/sssctl_cache.c:1200 +#: src/tools/sssctl/sssctl_cache.c:1201 msgid "Could not find GUID attribute in GPO entry\n" msgstr "" -#: src/tools/sssctl/sssctl_cache.c:1206 +#: src/tools/sssctl/sssctl_cache.c:1207 #, fuzzy, c-format msgid "Failed to delete GPO: %s\n" msgstr "%s を開くことに失敗しました\n" -#: src/tools/sssctl/sssctl_cache.c:1210 +#: src/tools/sssctl/sssctl_cache.c:1211 #, c-format msgid "%s removed from cache\n" msgstr "" @@ -2834,39 +2894,40 @@ msgstr "" "path/sssd.conf\" に設定されている場合は、スニペット dir \"/my/path/conf.d\" " "が使用されます" -#: src/tools/sssctl/sssctl_config.c:114 +#: src/tools/sssctl/sssctl_config.c:126 #, c-format msgid "File %1$s does not exist.\n" msgstr "ファイル %1$s は存在しません。\n" -#: src/tools/sssctl/sssctl_config.c:115 +#: src/tools/sssctl/sssctl_config.c:127 msgid "There is no configuration.\n" msgstr "設定はありません。\n" -#: src/tools/sssctl/sssctl_config.c:120 +#: src/tools/sssctl/sssctl_config.c:132 #, fuzzy, c-format msgid "Configuration validation failed: %s\n" msgstr "インデックス操作に失敗しました: %1$s\n" -#: src/tools/sssctl/sssctl_config.c:121 +#: src/tools/sssctl/sssctl_config.c:133 msgid "Run with high debug level to see details.\n" msgstr "" -#: src/tools/sssctl/sssctl_config.c:130 -msgid "Failed to run validators" +#: src/tools/sssctl/sssctl_config.c:142 +#, fuzzy +msgid "Failed to run validators\n" msgstr "バリデーターの実行に失敗しました" -#: src/tools/sssctl/sssctl_config.c:134 +#: src/tools/sssctl/sssctl_config.c:146 #, c-format msgid "Issues identified by validators: %zu\n" msgstr "バリデーターで特定された問題: %zu\n" -#: src/tools/sssctl/sssctl_config.c:145 +#: src/tools/sssctl/sssctl_config.c:157 #, c-format msgid "Messages generated during configuration merging: %zu\n" msgstr "設定のマージ中に生成されたメッセージ: %zu\n" -#: src/tools/sssctl/sssctl_config.c:158 +#: src/tools/sssctl/sssctl_config.c:170 #, c-format msgid "Used configuration snippet files: %zu\n" msgstr "使用された設定スニペットファイル: %zu\n" @@ -2878,7 +2939,8 @@ msgstr "バックアップディレクトリー [%d] を作成できません: % #: src/tools/sssctl/sssctl_data.c:97 msgid "SSSD backup of local data already exists, override?" -msgstr "ローカルデータの SSSD バックアップはすでに存在しますが、上書きしますか?" +msgstr "" +"ローカルデータの SSSD バックアップはすでに存在しますが、上書きしますか?" #: src/tools/sssctl/sssctl_data.c:113 msgid "Unable to export user overrides\n" @@ -2928,8 +2990,8 @@ msgstr "ローカルデータのバックアップを作成中...\n" #: src/tools/sssctl/sssctl_data.c:237 msgid "Unable to create backup of local data, can not remove the cache.\n" msgstr "" -"ローカルデータのバックアップの作成ができません。キャッシュを削除できません" -"。\n" +"ローカルデータのバックアップの作成ができません。キャッシュを削除できませ" +"ん。\n" #: src/tools/sssctl/sssctl_data.c:242 msgid "Removing cache files...\n" @@ -3017,7 +3079,8 @@ msgstr "リモートプロバイダーのインデックスも忘れず更新し #: src/tools/sssctl/sssctl_domains.c:82 msgid "Show domain list including primary or trusted domain type" -msgstr "プライマリーまたは信頼されたドメインタイプを含むドメインリストを表示します" +msgstr "" +"プライマリーまたは信頼されたドメインタイプを含むドメインリストを表示します" #: src/tools/sssctl/sssctl_domains.c:166 msgid "Online" @@ -3168,8 +3231,8 @@ msgstr "設定するデバッグレベルを指定します" #: src/tools/sssctl/sssctl_logs.c:593 msgid "ERROR: Tevent chain ID support missing, log analyzer is unsupported.\n" msgstr "" -"エラー: Tevent chain ID サポートがなく、ログアナライザーはサポートされません" -"。\n" +"エラー: Tevent chain ID サポートがなく、ログアナライザーはサポートされませ" +"ん。\n" #: src/tools/sssctl/sssctl_user_checks.c:121 msgid "SSSD InfoPipe user lookup result:\n" diff --git a/po/ka.po b/po/ka.po index 21068ce2abf..a0eea766950 100644 --- a/po/ka.po +++ b/po/ka.po @@ -7,8 +7,8 @@ msgid "" msgstr "" "Project-Id-Version: PACKAGE VERSION\n" "Report-Msgid-Bugs-To: sssd-devel@lists.fedorahosted.org\n" -"POT-Creation-Date: 2026-01-14 14:57+0000\n" -"PO-Revision-Date: 2026-04-23 16:48+0000\n" +"POT-Creation-Date: 2026-10-02 15:57+0000\n" +"PO-Revision-Date: 2026-10-05 17:13+0000\n" "Last-Translator: Weblate Translation Memory \n" "Language-Team: Georgian : that must be enforced " "for PAM access with GSSAPI authentication" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:113 +#: src/config/SSSDConfig/sssdoptions.py:109 +msgid "" +"List of triples :: that assigns " +"additional information from the Kerberos ticket to an authentication " +"indicator." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:112 msgid "Allow passkey device authentication." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:114 +#: src/config/SSSDConfig/sssdoptions.py:113 msgid "How many seconds will pam_sss wait for passkey_child to finish" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:115 +#: src/config/SSSDConfig/sssdoptions.py:114 msgid "Enable debugging in the libfido2 library" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:116 +#: src/config/SSSDConfig/sssdoptions.py:115 msgid "Enable JSON protocol for authentication methods selection." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:119 +#: src/config/SSSDConfig/sssdoptions.py:118 msgid "Whether to evaluate the time-based attributes in sudo rules" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:120 +#: src/config/SSSDConfig/sssdoptions.py:119 msgid "If true, SSSD will switch back to lower-wins ordering logic" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:121 +#: src/config/SSSDConfig/sssdoptions.py:120 msgid "" "Maximum number of rules that can be refreshed at once. If this is exceeded, " "full refresh is performed." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:128 +#: src/config/SSSDConfig/sssdoptions.py:127 msgid "Whether to hash host names and addresses in the known_hosts file" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:129 +#: src/config/SSSDConfig/sssdoptions.py:128 msgid "" "How many seconds to keep a host in the known_hosts file after its host keys " "were requested" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:131 +#: src/config/SSSDConfig/sssdoptions.py:130 msgid "Path to storage of trusted CA certificates" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:132 +#: src/config/SSSDConfig/sssdoptions.py:131 msgid "Allow to generate ssh-keys from certificates" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:133 +#: src/config/SSSDConfig/sssdoptions.py:132 msgid "" "Use the following matching rules to filter the certificates for ssh-key " "generation" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:137 +#: src/config/SSSDConfig/sssdoptions.py:136 msgid "List of UIDs or user names allowed to access the PAC responder" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:138 +#: src/config/SSSDConfig/sssdoptions.py:137 msgid "How long the PAC data is considered valid" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:139 +#: src/config/SSSDConfig/sssdoptions.py:138 msgid "Validate the PAC" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:142 +#: src/config/SSSDConfig/sssdoptions.py:141 msgid "List of user attributes the InfoPipe is allowed to publish" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:145 +#: src/config/SSSDConfig/sssdoptions.py:144 msgid "" "One of the following strings specifying the scope of session recording: none " "- No users are recorded. some - Users/groups specified by users and groups " "options are recorded. all - All users are recorded." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:148 +#: src/config/SSSDConfig/sssdoptions.py:147 msgid "" "A comma-separated list of users which should have session recording enabled. " "Matches user names as returned by NSS. I.e. after the possible space " "replacement, case changes, etc." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:150 +#: src/config/SSSDConfig/sssdoptions.py:149 msgid "" "A comma-separated list of groups, members of which should have session " "recording enabled. Matches group names as returned by NSS. I.e. after the " "possible space replacement, case changes, etc." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:153 +#: src/config/SSSDConfig/sssdoptions.py:152 msgid "" "A comma-separated list of users to be excluded from recording, only when " "scope=all" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:154 +#: src/config/SSSDConfig/sssdoptions.py:153 msgid "" "A comma-separated list of groups, members of which should be excluded from " "recording, only when scope=all. " msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:158 +#: src/config/SSSDConfig/sssdoptions.py:157 msgid "Identity provider" msgstr "იდენტიფიკაციის მომწოდებელი" -#: src/config/SSSDConfig/sssdoptions.py:159 +#: src/config/SSSDConfig/sssdoptions.py:158 msgid "Authentication provider" msgstr "ავთენტიკაციის მომწოდებელი" -#: src/config/SSSDConfig/sssdoptions.py:160 +#: src/config/SSSDConfig/sssdoptions.py:159 msgid "Access control provider" msgstr "წვდომის კონტროლის მომწოდებელი" -#: src/config/SSSDConfig/sssdoptions.py:161 +#: src/config/SSSDConfig/sssdoptions.py:160 msgid "Password change provider" msgstr "პაროლის შეცვლის მომწოდებელი" -#: src/config/SSSDConfig/sssdoptions.py:162 +#: src/config/SSSDConfig/sssdoptions.py:161 msgid "SUDO provider" msgstr "SUDO -ის მომწოდებელი" -#: src/config/SSSDConfig/sssdoptions.py:163 +#: src/config/SSSDConfig/sssdoptions.py:162 msgid "Autofs provider" msgstr "Autofs -ის მომწოდებელი" -#: src/config/SSSDConfig/sssdoptions.py:164 +#: src/config/SSSDConfig/sssdoptions.py:163 msgid "Host identity provider" msgstr "ჰოსტის იდენტიფიკაციის მომწოდებელი" -#: src/config/SSSDConfig/sssdoptions.py:165 +#: src/config/SSSDConfig/sssdoptions.py:164 msgid "SELinux provider" msgstr "SELinux -ის მომწოდებელი" -#: src/config/SSSDConfig/sssdoptions.py:166 +#: src/config/SSSDConfig/sssdoptions.py:165 msgid "Session management provider" msgstr "სესიის მართვის მომწოდებელი" -#: src/config/SSSDConfig/sssdoptions.py:167 +#: src/config/SSSDConfig/sssdoptions.py:166 msgid "Resolver provider" msgstr "ამომხსნელის მომწოდებელი" -#: src/config/SSSDConfig/sssdoptions.py:170 +#: src/config/SSSDConfig/sssdoptions.py:169 msgid "Whether the domain is usable by the OS or by applications" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:171 +#: src/config/SSSDConfig/sssdoptions.py:170 msgid "Enable or disable the domain" msgstr "დომენის ჩართვა ან გამორთვა" -#: src/config/SSSDConfig/sssdoptions.py:172 +#: src/config/SSSDConfig/sssdoptions.py:171 msgid "Minimum user ID" msgstr "მომხმარებლის მინიმალური ID" -#: src/config/SSSDConfig/sssdoptions.py:173 +#: src/config/SSSDConfig/sssdoptions.py:172 msgid "Maximum user ID" msgstr "მომხმარებლის მაქსიმალური ID" -#: src/config/SSSDConfig/sssdoptions.py:174 +#: src/config/SSSDConfig/sssdoptions.py:173 msgid "Enable enumerating all users/groups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:175 +#: src/config/SSSDConfig/sssdoptions.py:174 msgid "Cache credentials for offline login" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:176 +#: src/config/SSSDConfig/sssdoptions.py:175 msgid "Display users/groups in fully-qualified form" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:177 +#: src/config/SSSDConfig/sssdoptions.py:176 msgid "Don't include group members in group lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:178 +#: src/config/SSSDConfig/sssdoptions.py:177 #: src/config/SSSDConfig/sssdoptions.py:190 #: src/config/SSSDConfig/sssdoptions.py:191 #: src/config/SSSDConfig/sssdoptions.py:192 @@ -530,48 +537,52 @@ msgstr "" msgid "Entry cache timeout length (seconds)" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:179 +#: src/config/SSSDConfig/sssdoptions.py:178 msgid "" "Restrict or prefer a specific address family when performing DNS lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:180 +#: src/config/SSSDConfig/sssdoptions.py:179 msgid "How long to keep cached entries after last successful login (days)" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:181 +#: src/config/SSSDConfig/sssdoptions.py:180 msgid "" "How long should SSSD talk to single DNS server before trying next server " "(miliseconds)" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:183 +#: src/config/SSSDConfig/sssdoptions.py:182 msgid "How long should keep trying to resolve single DNS query (seconds)" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:184 +#: src/config/SSSDConfig/sssdoptions.py:183 msgid "How long to wait for replies from DNS when resolving servers (seconds)" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:185 +#: src/config/SSSDConfig/sssdoptions.py:184 msgid "The domain part of service discovery DNS query" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:186 +#: src/config/SSSDConfig/sssdoptions.py:185 msgid "" "Specifies the interval, in seconds, that SSSD waits before attempting to " "reconnect to the primary server after a successful connection to the backup " "server" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:188 +#: src/config/SSSDConfig/sssdoptions.py:187 msgid "Override GID value from the identity provider with this value" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:189 +#: src/config/SSSDConfig/sssdoptions.py:188 msgid "Treat usernames as case sensitive" msgstr "" +#: src/config/SSSDConfig/sssdoptions.py:189 +msgid "Lookups by ID are expensive or do not work at all" +msgstr "" + #: src/config/SSSDConfig/sssdoptions.py:197 msgid "How often should expired entries be refreshed in background" msgstr "" @@ -791,7 +802,7 @@ msgid "Search base for SUBID ranges" msgstr "" #: src/config/SSSDConfig/sssdoptions.py:259 -#: src/config/SSSDConfig/sssdoptions.py:506 +#: src/config/SSSDConfig/sssdoptions.py:512 msgid "Which rules should be used to evaluate access control" msgstr "" @@ -933,7 +944,7 @@ msgid "Enable DNS sites - location based service discovery" msgstr "" #: src/config/SSSDConfig/sssdoptions.py:301 -#: src/config/SSSDConfig/sssdoptions.py:504 +#: src/config/SSSDConfig/sssdoptions.py:510 msgid "LDAP filter to determine access privileges" msgstr "" @@ -1353,7 +1364,7 @@ msgid "UUID attribute" msgstr "UUID ატრიბუტი" #: src/config/SSSDConfig/sssdoptions.py:423 -#: src/config/SSSDConfig/sssdoptions.py:464 +#: src/config/SSSDConfig/sssdoptions.py:470 msgid "objectSID attribute" msgstr "ატრიბუტ objectSID" @@ -1477,385 +1488,413 @@ msgstr "" msgid "A list of extra attributes to download along with the user entry" msgstr "" +#: src/config/SSSDConfig/sssdoptions.py:456 +msgid "The object class of an subid entry in LDAP." +msgstr "" + #: src/config/SSSDConfig/sssdoptions.py:457 +#, fuzzy +msgid "Subordinate user ID count attribute" +msgstr "პირველადი GID ატრიბუტი" + +#: src/config/SSSDConfig/sssdoptions.py:458 +#, fuzzy +msgid "Subordinate group ID count attribute" +msgstr "სერვისის პორტის ატრიბუტი" + +#: src/config/SSSDConfig/sssdoptions.py:459 +#, fuzzy +msgid "User ID range start value attribute" +msgstr "მომხმარებლის სახელის ატრიბუტი" + +#: src/config/SSSDConfig/sssdoptions.py:460 +#, fuzzy +msgid "Group ID range start value attribute" +msgstr "ჯგუფი UUID ატრიბუტი" + +#: src/config/SSSDConfig/sssdoptions.py:461 +msgid "Owner of an entry" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:463 msgid "Base DN for group lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:458 +#: src/config/SSSDConfig/sssdoptions.py:464 msgid "Objectclass for groups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:459 +#: src/config/SSSDConfig/sssdoptions.py:465 msgid "Group name" msgstr "ჯგუფის სახელი" -#: src/config/SSSDConfig/sssdoptions.py:460 +#: src/config/SSSDConfig/sssdoptions.py:466 msgid "Group password" msgstr "ჯგუფის პაროლი" -#: src/config/SSSDConfig/sssdoptions.py:461 +#: src/config/SSSDConfig/sssdoptions.py:467 msgid "GID attribute" msgstr "GID ატრიბუტი" -#: src/config/SSSDConfig/sssdoptions.py:462 +#: src/config/SSSDConfig/sssdoptions.py:468 msgid "Group member attribute" msgstr "ჯგუფის წევრის ატრიბუტი" -#: src/config/SSSDConfig/sssdoptions.py:463 +#: src/config/SSSDConfig/sssdoptions.py:469 msgid "Group UUID attribute" msgstr "ჯგუფი UUID ატრიბუტი" -#: src/config/SSSDConfig/sssdoptions.py:465 +#: src/config/SSSDConfig/sssdoptions.py:471 msgid "Modification time attribute for groups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:466 +#: src/config/SSSDConfig/sssdoptions.py:472 msgid "Type of the group and other flags" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:467 +#: src/config/SSSDConfig/sssdoptions.py:473 msgid "The LDAP group external member attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:468 +#: src/config/SSSDConfig/sssdoptions.py:474 msgid "Maximum nesting level SSSD will follow" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:469 +#: src/config/SSSDConfig/sssdoptions.py:475 msgid "Filter for group lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:470 +#: src/config/SSSDConfig/sssdoptions.py:476 msgid "Scope of group lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:472 +#: src/config/SSSDConfig/sssdoptions.py:478 msgid "Base DN for netgroup lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:473 +#: src/config/SSSDConfig/sssdoptions.py:479 msgid "Objectclass for netgroups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:474 +#: src/config/SSSDConfig/sssdoptions.py:480 msgid "Netgroup name" msgstr "ქსელური ჯგუფის სახელი" -#: src/config/SSSDConfig/sssdoptions.py:475 +#: src/config/SSSDConfig/sssdoptions.py:481 msgid "Netgroups members attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:476 +#: src/config/SSSDConfig/sssdoptions.py:482 msgid "Netgroup triple attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:477 +#: src/config/SSSDConfig/sssdoptions.py:483 msgid "Modification time attribute for netgroups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:479 +#: src/config/SSSDConfig/sssdoptions.py:485 msgid "Base DN for service lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:480 +#: src/config/SSSDConfig/sssdoptions.py:486 msgid "Objectclass for services" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:481 +#: src/config/SSSDConfig/sssdoptions.py:487 msgid "Service name attribute" msgstr "სერვისის სახელის ატრიბუტი" -#: src/config/SSSDConfig/sssdoptions.py:482 +#: src/config/SSSDConfig/sssdoptions.py:488 msgid "Service port attribute" msgstr "სერვისის პორტის ატრიბუტი" -#: src/config/SSSDConfig/sssdoptions.py:483 +#: src/config/SSSDConfig/sssdoptions.py:489 msgid "Service protocol attribute" msgstr "სერვისის პროტოკოლის ატრიბუტი" -#: src/config/SSSDConfig/sssdoptions.py:485 +#: src/config/SSSDConfig/sssdoptions.py:491 msgid "Lower bound for ID-mapping" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:486 +#: src/config/SSSDConfig/sssdoptions.py:492 msgid "Upper bound for ID-mapping" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:487 +#: src/config/SSSDConfig/sssdoptions.py:493 msgid "Number of IDs for each slice when ID-mapping" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:488 +#: src/config/SSSDConfig/sssdoptions.py:494 msgid "Use autorid-compatible algorithm for ID-mapping" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:489 +#: src/config/SSSDConfig/sssdoptions.py:495 msgid "Name of the default domain for ID-mapping" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:490 +#: src/config/SSSDConfig/sssdoptions.py:496 msgid "SID of the default domain for ID-mapping" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:491 +#: src/config/SSSDConfig/sssdoptions.py:497 msgid "Number of secondary slices" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:493 +#: src/config/SSSDConfig/sssdoptions.py:499 msgid "Whether to use Token-Groups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:494 +#: src/config/SSSDConfig/sssdoptions.py:500 msgid "Set lower boundary for allowed IDs from the LDAP server" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:495 +#: src/config/SSSDConfig/sssdoptions.py:501 msgid "Set upper boundary for allowed IDs from the LDAP server" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:496 +#: src/config/SSSDConfig/sssdoptions.py:502 msgid "DN for ppolicy queries" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:497 +#: src/config/SSSDConfig/sssdoptions.py:503 msgid "How many maximum entries to fetch during a wildcard request" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:498 +#: src/config/SSSDConfig/sssdoptions.py:504 msgid "Set libldap debug level" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:501 +#: src/config/SSSDConfig/sssdoptions.py:507 msgid "Policy to evaluate the password expiration" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:505 +#: src/config/SSSDConfig/sssdoptions.py:511 msgid "Which attributes shall be used to evaluate if an account is expired" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:509 +#: src/config/SSSDConfig/sssdoptions.py:515 msgid "URI of an LDAP server where password changes are allowed" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:510 +#: src/config/SSSDConfig/sssdoptions.py:516 msgid "URI of a backup LDAP server where password changes are allowed" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:511 +#: src/config/SSSDConfig/sssdoptions.py:517 msgid "DNS service name for LDAP password change server" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:512 +#: src/config/SSSDConfig/sssdoptions.py:518 msgid "" "Whether to update the ldap_user_shadow_last_change attribute after a " "password change" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:516 +#: src/config/SSSDConfig/sssdoptions.py:522 msgid "Base DN for sudo rules lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:517 +#: src/config/SSSDConfig/sssdoptions.py:523 msgid "Automatic full refresh period" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:518 +#: src/config/SSSDConfig/sssdoptions.py:524 msgid "Automatic smart refresh period" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:519 +#: src/config/SSSDConfig/sssdoptions.py:525 msgid "Smart and full refresh random offset" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:520 +#: src/config/SSSDConfig/sssdoptions.py:526 msgid "Whether to filter rules by hostname, IP addresses and network" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:521 +#: src/config/SSSDConfig/sssdoptions.py:527 msgid "" "Hostnames and/or fully qualified domain names of this machine to filter sudo " "rules" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:522 +#: src/config/SSSDConfig/sssdoptions.py:528 msgid "IPv4 or IPv6 addresses or network of this machine to filter sudo rules" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:523 +#: src/config/SSSDConfig/sssdoptions.py:529 msgid "Whether to include rules that contains netgroup in host attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:524 +#: src/config/SSSDConfig/sssdoptions.py:530 msgid "" "Whether to include rules that contains regular expression in host attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:525 +#: src/config/SSSDConfig/sssdoptions.py:531 msgid "Object class for sudo rules" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:526 +#: src/config/SSSDConfig/sssdoptions.py:532 msgid "Name of attribute that is used as object class for sudo rules" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:527 +#: src/config/SSSDConfig/sssdoptions.py:533 msgid "Sudo rule name" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:528 +#: src/config/SSSDConfig/sssdoptions.py:534 msgid "Sudo rule command attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:529 +#: src/config/SSSDConfig/sssdoptions.py:535 msgid "Sudo rule host attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:530 +#: src/config/SSSDConfig/sssdoptions.py:536 msgid "Sudo rule user attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:531 +#: src/config/SSSDConfig/sssdoptions.py:537 msgid "Sudo rule option attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:532 +#: src/config/SSSDConfig/sssdoptions.py:538 msgid "Sudo rule runas attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:533 +#: src/config/SSSDConfig/sssdoptions.py:539 msgid "Sudo rule runasuser attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:534 +#: src/config/SSSDConfig/sssdoptions.py:540 msgid "Sudo rule runasgroup attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:535 +#: src/config/SSSDConfig/sssdoptions.py:541 msgid "Sudo rule notbefore attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:536 +#: src/config/SSSDConfig/sssdoptions.py:542 msgid "Sudo rule notafter attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:537 +#: src/config/SSSDConfig/sssdoptions.py:543 msgid "Sudo rule order attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:540 +#: src/config/SSSDConfig/sssdoptions.py:546 msgid "Object class for automounter maps" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:541 +#: src/config/SSSDConfig/sssdoptions.py:547 msgid "Automounter map name attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:542 +#: src/config/SSSDConfig/sssdoptions.py:548 msgid "Object class for automounter map entries" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:543 +#: src/config/SSSDConfig/sssdoptions.py:549 msgid "Automounter map entry key attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:544 +#: src/config/SSSDConfig/sssdoptions.py:550 msgid "Automounter map entry value attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:545 +#: src/config/SSSDConfig/sssdoptions.py:551 msgid "Base DN for automounter map lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:546 +#: src/config/SSSDConfig/sssdoptions.py:552 msgid "The name of the automount master map in LDAP." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:549 +#: src/config/SSSDConfig/sssdoptions.py:555 msgid "Base DN for IP hosts lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:550 +#: src/config/SSSDConfig/sssdoptions.py:556 msgid "Object class for IP hosts" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:551 +#: src/config/SSSDConfig/sssdoptions.py:557 msgid "IP host name attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:552 +#: src/config/SSSDConfig/sssdoptions.py:558 msgid "IP host number (address) attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:553 +#: src/config/SSSDConfig/sssdoptions.py:559 msgid "IP host entryUSN attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:554 +#: src/config/SSSDConfig/sssdoptions.py:560 msgid "Base DN for IP networks lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:555 +#: src/config/SSSDConfig/sssdoptions.py:561 msgid "Object class for IP networks" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:556 +#: src/config/SSSDConfig/sssdoptions.py:562 msgid "IP network name attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:557 +#: src/config/SSSDConfig/sssdoptions.py:563 msgid "IP network number (address) attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:558 +#: src/config/SSSDConfig/sssdoptions.py:564 msgid "IP network entryUSN attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:561 +#: src/config/SSSDConfig/sssdoptions.py:567 msgid "Comma separated list of allowed users" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:562 +#: src/config/SSSDConfig/sssdoptions.py:568 msgid "Comma separated list of prohibited users" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:563 +#: src/config/SSSDConfig/sssdoptions.py:569 msgid "" "Comma separated list of groups that are allowed to log in. This applies only " "to groups within this SSSD domain. Local groups are not evaluated." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:565 +#: src/config/SSSDConfig/sssdoptions.py:571 msgid "" "Comma separated list of groups that are explicitly denied access. This " "applies only to groups within this SSSD domain. Local groups are not " "evaluated." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:569 +#: src/config/SSSDConfig/sssdoptions.py:575 msgid "The number of preforked proxy children." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:572 +#: src/config/SSSDConfig/sssdoptions.py:578 msgid "The name of the NSS library to use" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:573 +#: src/config/SSSDConfig/sssdoptions.py:579 msgid "The name of the NSS library to use for hosts and networks lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:574 +#: src/config/SSSDConfig/sssdoptions.py:580 msgid "Whether to look up canonical group name from cache if possible" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:577 +#: src/config/SSSDConfig/sssdoptions.py:583 msgid "PAM stack to use" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:580 +#: src/config/SSSDConfig/sssdoptions.py:586 msgid "Path of passwd file sources." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:581 +#: src/config/SSSDConfig/sssdoptions.py:587 msgid "Path of group file sources." msgstr "" @@ -1869,7 +1908,7 @@ msgstr "" #: src/monitor/monitor.c:1761 msgid "Print version number and exit" -msgstr "" +msgstr "ვერსიის ჩვენება და გასვლა" #: src/monitor/monitor.c:1772 #, c-format @@ -1886,225 +1925,233 @@ msgstr "" msgid "Option -i|--interactive is not allowed together with -D|--daemon\n" msgstr "" -#: src/monitor/monitor.c:1836 +#: src/monitor/monitor.c:1838 msgid "Failed to get initial capabilities\n" msgstr "" -#: src/monitor/monitor.c:1847 +#: src/monitor/monitor.c:1849 msgid "Non-root service user support isn't built. Can't run under %" msgstr "" -#: src/monitor/monitor.c:1864 +#: src/monitor/monitor.c:1866 #, c-format msgid "Can't read config: '%s'\n" msgstr "" -#: src/monitor/monitor.c:1876 +#: src/monitor/monitor.c:1878 #, c-format -msgid "Failed to boostrap SSSD 'monitor' process: %s" +msgid "Failed to bootstrap SSSD 'monitor' process: %s" msgstr "" -#: src/monitor/monitor.c:1971 +#: src/monitor/monitor.c:1973 msgid "Out of memory\n" msgstr "მეხსიერება გადახარჯულია\n" -#: src/providers/krb5/krb5_child.c:4221 +#: src/providers/krb5/krb5_child.c:4316 msgid "Use anonymous PKINIT to request FAST armor ticket" msgstr "" -#: src/providers/krb5/krb5_child.c:4223 +#: src/providers/krb5/krb5_child.c:4318 msgid "Kerberos realm to use" msgstr "" -#: src/providers/krb5/krb5_child.c:4225 +#: src/providers/krb5/krb5_child.c:4320 msgid "Requested lifetime of the ticket" msgstr "" -#: src/providers/krb5/krb5_child.c:4227 +#: src/providers/krb5/krb5_child.c:4322 msgid "Requested renewable lifetime of the ticket" msgstr "" -#: src/providers/krb5/krb5_child.c:4229 +#: src/providers/krb5/krb5_child.c:4324 msgid "FAST options ('never', 'try', 'demand')" msgstr "" -#: src/providers/krb5/krb5_child.c:4232 +#: src/providers/krb5/krb5_child.c:4327 msgid "Specifies the server principal to use for FAST" msgstr "" -#: src/providers/krb5/krb5_child.c:4234 +#: src/providers/krb5/krb5_child.c:4329 msgid "Requests canonicalization of the principal name" msgstr "" -#: src/providers/krb5/krb5_child.c:4236 +#: src/providers/krb5/krb5_child.c:4331 msgid "Use custom version of krb5_get_init_creds_password" msgstr "" -#: src/providers/krb5/krb5_child.c:4238 +#: src/providers/krb5/krb5_child.c:4333 msgid "Check PAC flags" msgstr "" -#: src/providers/data_provider_be.c:790 +#: src/providers/krb5/krb5_child.c:4335 +msgid "Set environment variable (KEY=VALUE)" +msgstr "" + +#: src/providers/data_provider_be.c:786 msgid "Domain of the information provider (mandatory)" msgstr "" -#: src/sss_client/common.c:1165 +#: src/sss_client/common.c:1208 msgid "Socket has wrong ownership or permissions." msgstr "" -#: src/sss_client/common.c:1168 +#: src/sss_client/common.c:1211 msgid "Unexpected format of the server credential message." msgstr "" -#: src/sss_client/common.c:1171 +#: src/sss_client/common.c:1214 msgid "SSSD is not run by trusted user." msgstr "" -#: src/sss_client/common.c:1174 +#: src/sss_client/common.c:1217 msgid "SSSD socket does not exist." msgstr "" -#: src/sss_client/common.c:1177 +#: src/sss_client/common.c:1220 msgid "Cannot get stat of SSSD socket." msgstr "" -#: src/sss_client/common.c:1182 +#: src/sss_client/common.c:1225 msgid "An error occurred, but no description can be found." msgstr "" -#: src/sss_client/common.c:1188 +#: src/sss_client/common.c:1231 msgid "Unexpected error while looking for an error description" msgstr "" -#: src/sss_client/pam_sss.c:74 +#: src/sss_client/pam_sss.c:135 msgid "Permission denied. " msgstr "წვდომა აკრძალულია. " -#: src/sss_client/pam_sss.c:75 src/sss_client/pam_sss.c:843 -#: src/sss_client/pam_sss.c:854 +#: src/sss_client/pam_sss.c:136 src/sss_client/pam_sss.c:921 +#: src/sss_client/pam_sss.c:932 msgid "Server message: " msgstr "" -#: src/sss_client/pam_sss.c:76 +#: src/sss_client/pam_sss.c:137 msgid "" "Kerberos TGT will not be granted upon login, user experience will be " "affected." msgstr "" -#: src/sss_client/pam_sss.c:77 +#: src/sss_client/pam_sss.c:138 msgid "Enter PIN:" -msgstr "" +msgstr "შეიყვანეთ PIN-კოდი:" -#: src/sss_client/pam_sss.c:320 +#: src/sss_client/pam_sss.c:385 msgid "Passwords do not match" msgstr "პაროლები არ ემთხვევა" -#: src/sss_client/pam_sss.c:508 +#: src/sss_client/pam_sss.c:584 msgid "Password reset by root is not supported." msgstr "" -#: src/sss_client/pam_sss.c:549 +#: src/sss_client/pam_sss.c:625 msgid "Authenticated with cached credentials" msgstr "" -#: src/sss_client/pam_sss.c:550 +#: src/sss_client/pam_sss.c:626 msgid ", your cached password will expire at: " msgstr "" -#: src/sss_client/pam_sss.c:580 +#: src/sss_client/pam_sss.c:656 #, c-format msgid "Your password has expired. You have %1$d grace login(s) remaining." msgstr "" -#: src/sss_client/pam_sss.c:630 +#: src/sss_client/pam_sss.c:706 #, c-format msgid "Your password will expire in %1$d %2$s." msgstr "" -#: src/sss_client/pam_sss.c:633 +#: src/sss_client/pam_sss.c:709 #, c-format msgid "Your password has expired." msgstr "თქვენს პაროლს ვადა გაუვიდა." -#: src/sss_client/pam_sss.c:684 +#: src/sss_client/pam_sss.c:760 msgid "Authentication is denied until: " msgstr "" -#: src/sss_client/pam_sss.c:705 +#: src/sss_client/pam_sss.c:781 msgid "System is offline, password change not possible" msgstr "" -#: src/sss_client/pam_sss.c:720 +#: src/sss_client/pam_sss.c:796 msgid "" "After changing the OTP password, you need to log out and back in order to " "acquire a ticket" msgstr "" -#: src/sss_client/pam_sss.c:735 +#: src/sss_client/pam_sss.c:813 msgid "PIN locked" msgstr "" -#: src/sss_client/pam_sss.c:750 +#: src/sss_client/pam_sss.c:828 msgid "" "No Kerberos TGT granted as the server does not support this method. Your " "single-sign on(SSO) experience will be affected." msgstr "" -#: src/sss_client/pam_sss.c:840 src/sss_client/pam_sss.c:853 +#: src/sss_client/pam_sss.c:918 src/sss_client/pam_sss.c:931 msgid "Password change failed. " msgstr "პაროლის შეცვლის შეცდომა. " -#: src/sss_client/pam_sss.c:1859 +#: src/sss_client/pam_sss.c:2028 #, c-format -msgid "Authenticate at %1$s and press ENTER." +msgid "Authenticate at \"%1$s\"." msgstr "" -#: src/sss_client/pam_sss.c:1862 +#: src/sss_client/pam_sss.c:2031 #, c-format -msgid "Authenticate with PIN %1$s at %2$s and press ENTER." +msgid "Authenticate with PIN \"%1$s\" at \"%2$s\"." msgstr "" -#: src/sss_client/pam_sss.c:2281 +#: src/sss_client/pam_sss.c:2470 msgid "Please (re)insert (different) Smartcard" msgstr "" -#: src/sss_client/pam_sss.c:2482 +#: src/sss_client/pam_sss.c:2700 msgid "New Password: " msgstr "ახალი პაროლი: " -#: src/sss_client/pam_sss.c:2483 +#: src/sss_client/pam_sss.c:2701 msgid "Reenter new Password: " +msgstr "გაიმეორეთ ახალი პაროლი: " + +#: src/sss_client/pam_sss.c:2890 +msgid "Press ENTER to continue." msgstr "" -#: src/sss_client/pam_sss.c:2676 src/sss_client/pam_sss.c:2679 +#: src/sss_client/pam_sss.c:2913 src/sss_client/pam_sss.c:2916 msgid "First Factor: " msgstr "" -#: src/sss_client/pam_sss.c:2677 src/sss_client/pam_sss.c:2851 +#: src/sss_client/pam_sss.c:2914 src/sss_client/pam_sss.c:3088 msgid "Second Factor (optional): " msgstr "" -#: src/sss_client/pam_sss.c:2680 src/sss_client/pam_sss.c:2855 +#: src/sss_client/pam_sss.c:2917 src/sss_client/pam_sss.c:3092 msgid "Second Factor: " msgstr "" -#: src/sss_client/pam_sss.c:2684 +#: src/sss_client/pam_sss.c:2921 msgid "Insert your passkey device, then press ENTER." msgstr "" -#: src/sss_client/pam_sss.c:2688 src/sss_client/pam_sss.c:2696 +#: src/sss_client/pam_sss.c:2925 src/sss_client/pam_sss.c:2933 msgid "Password: " msgstr "პაროლი: " -#: src/sss_client/pam_sss.c:2850 src/sss_client/pam_sss.c:2854 +#: src/sss_client/pam_sss.c:3087 src/sss_client/pam_sss.c:3091 msgid "First Factor (Current Password): " msgstr "" -#: src/sss_client/pam_sss.c:2874 +#: src/sss_client/pam_sss.c:3111 msgid "Current Password: " msgstr "მიმდინარე პაროლი: " -#: src/sss_client/pam_sss.c:3248 +#: src/sss_client/pam_sss.c:3485 msgid "Password expired. Change your password now." msgstr "" @@ -2526,7 +2573,7 @@ msgstr "ბრძანების სტრიქონის დამუშ #: src/tools/sssctl/sssctl_cache.c:790 src/tools/sssctl/sssctl_cache.c:1148 #, c-format msgid "%s\n" -msgstr "" +msgstr "%s\n" #: src/tools/sssctl/sssctl_cache.c:803 #, c-format @@ -2536,9 +2583,9 @@ msgstr "ობიექტის დაბეჭდვა ჩავარდა: #: src/tools/sssctl/sssctl_cache.c:835 src/tools/sssctl/sssctl_cache.c:918 #: src/tools/sssctl/sssctl_cache.c:950 src/tools/sssctl/sssctl_cache.c:956 #: src/tools/sssctl/sssctl_cache.c:1010 src/tools/sssctl/sssctl_cache.c:1034 -#: src/tools/sssctl/sssctl_cache.c:1085 src/tools/sssctl/sssctl_cache.c:1194 -#: src/tools/sssctl/sssctl_cache.c:1229 src/tools/sssctl/sssctl_cache.c:1235 -#: src/tools/sssctl/sssctl_cache.c:1244 +#: src/tools/sssctl/sssctl_cache.c:1085 src/tools/sssctl/sssctl_cache.c:1195 +#: src/tools/sssctl/sssctl_cache.c:1230 src/tools/sssctl/sssctl_cache.c:1236 +#: src/tools/sssctl/sssctl_cache.c:1245 msgid "talloc failed\n" msgstr "talloc ჩავარდა\n" @@ -2572,7 +2619,7 @@ msgstr "" #: src/tools/sssctl/sssctl_cache.c:931 #, c-format msgid "\t%s: %s\n" -msgstr "" +msgstr "\t%s: %s\n" #: src/tools/sssctl/sssctl_cache.c:933 src/tools/sssctl/sssctl_logs.c:50 msgid "\n" @@ -2612,25 +2659,25 @@ msgstr "" msgid "Unable to remove downloaded GPO files: %s\n" msgstr "" -#: src/tools/sssctl/sssctl_cache.c:1165 +#: src/tools/sssctl/sssctl_cache.c:1166 #, c-format msgid "Failed to fetch cache entry: %s\n" msgstr "კეშის ჩანაწერის გამოთხოვა ჩავარდა: %s\n" -#: src/tools/sssctl/sssctl_cache.c:1170 +#: src/tools/sssctl/sssctl_cache.c:1171 msgid "Could not determine object domain\n" msgstr "" -#: src/tools/sssctl/sssctl_cache.c:1200 +#: src/tools/sssctl/sssctl_cache.c:1201 msgid "Could not find GUID attribute in GPO entry\n" msgstr "" -#: src/tools/sssctl/sssctl_cache.c:1206 +#: src/tools/sssctl/sssctl_cache.c:1207 #, c-format msgid "Failed to delete GPO: %s\n" msgstr "GPO-ის წაშლა ჩავარდა: %s\n" -#: src/tools/sssctl/sssctl_cache.c:1210 +#: src/tools/sssctl/sssctl_cache.c:1211 #, c-format msgid "%s removed from cache\n" msgstr "" @@ -2638,7 +2685,7 @@ msgstr "" #: src/tools/sssctl/sssctl_cert.c:50 src/tools/sssctl/sssctl_cert.c:108 #: src/tools/sssctl/sssctl_cert.c:214 msgid "Show debug information" -msgstr "" +msgstr "გამართვის ინფორმაციის ჩვენება" #: src/tools/sssctl/sssctl_cert.c:56 src/tools/sssctl/sssctl_cert.c:114 #: src/tools/sssctl/sssctl_cert.c:220 @@ -2718,39 +2765,40 @@ msgid "" "\"/my/path/sssd.conf\", the snippet dir \"/my/path/conf.d\" is used)" msgstr "" -#: src/tools/sssctl/sssctl_config.c:114 +#: src/tools/sssctl/sssctl_config.c:126 #, c-format msgid "File %1$s does not exist.\n" msgstr "ფაილი %1$s არ არსებობს.\n" -#: src/tools/sssctl/sssctl_config.c:115 +#: src/tools/sssctl/sssctl_config.c:127 msgid "There is no configuration.\n" msgstr "" -#: src/tools/sssctl/sssctl_config.c:120 +#: src/tools/sssctl/sssctl_config.c:132 #, c-format msgid "Configuration validation failed: %s\n" msgstr "" -#: src/tools/sssctl/sssctl_config.c:121 +#: src/tools/sssctl/sssctl_config.c:133 msgid "Run with high debug level to see details.\n" msgstr "" -#: src/tools/sssctl/sssctl_config.c:130 -msgid "Failed to run validators" -msgstr "" +#: src/tools/sssctl/sssctl_config.c:142 +#, fuzzy +msgid "Failed to run validators\n" +msgstr "ობიექტის დაბეჭდვა ჩავარდა: %s\n" -#: src/tools/sssctl/sssctl_config.c:134 +#: src/tools/sssctl/sssctl_config.c:146 #, c-format msgid "Issues identified by validators: %zu\n" msgstr "" -#: src/tools/sssctl/sssctl_config.c:145 +#: src/tools/sssctl/sssctl_config.c:157 #, c-format msgid "Messages generated during configuration merging: %zu\n" msgstr "" -#: src/tools/sssctl/sssctl_config.c:158 +#: src/tools/sssctl/sssctl_config.c:170 #, c-format msgid "Used configuration snippet files: %zu\n" msgstr "" @@ -3161,6 +3209,8 @@ msgid "" "pam_authenticate for user [%s]: %s\n" "\n" msgstr "" +"pam_authenticate for user [%s]: %s\n" +"\n" #: src/tools/sssctl/sssctl_user_checks.c:282 msgid "" @@ -3174,6 +3224,8 @@ msgid "" "pam_chauthtok: %s\n" "\n" msgstr "" +"pam_chauthtok: %s\n" +"\n" #: src/tools/sssctl/sssctl_user_checks.c:286 msgid "" @@ -3187,6 +3239,8 @@ msgid "" "pam_acct_mgmt: %s\n" "\n" msgstr "" +"pam_acct_mgmt: %s\n" +"\n" #: src/tools/sssctl/sssctl_user_checks.c:290 msgid "" @@ -3200,6 +3254,8 @@ msgid "" "pam_setcred: [%s]\n" "\n" msgstr "" +"pam_setcred: [%s]\n" +"\n" #: src/tools/sssctl/sssctl_user_checks.c:294 msgid "" @@ -3213,6 +3269,8 @@ msgid "" "pam_open_session: %s\n" "\n" msgstr "" +"pam_open_session: %s\n" +"\n" #: src/tools/sssctl/sssctl_user_checks.c:298 msgid "" @@ -3226,6 +3284,8 @@ msgid "" "pam_close_session: %s\n" "\n" msgstr "" +"pam_close_session: %s\n" +"\n" #: src/tools/sssctl/sssctl_user_checks.c:302 msgid "unknown action\n" diff --git a/po/ko.po b/po/ko.po index 3bc9ed2c01c..82e199519be 100644 --- a/po/ko.po +++ b/po/ko.po @@ -10,8 +10,8 @@ msgid "" msgstr "" "Project-Id-Version: PACKAGE VERSION\n" "Report-Msgid-Bugs-To: sssd-devel@lists.fedorahosted.org\n" -"POT-Creation-Date: 2026-01-14 14:57+0000\n" -"PO-Revision-Date: 2026-04-23 17:02+0000\n" +"POT-Creation-Date: 2026-10-02 15:57+0000\n" +"PO-Revision-Date: 2026-10-05 17:11+0000\n" "Last-Translator: Transtats \n" "Language-Team: Korean \n" @@ -20,121 +20,121 @@ msgstr "" "Content-Type: text/plain; charset=UTF-8\n" "Content-Transfer-Encoding: 8bit\n" "Plural-Forms: nplurals=1; plural=0;\n" -"X-Generator: Weblate 5.17\n" +"X-Generator: Weblate 2026.10\n" -#: src/config/SSSDConfig/sssdoptions.py:20 -#: src/config/SSSDConfig/sssdoptions.py:21 +#: src/config/SSSDConfig/sssdoptions.py:16 +#: src/config/SSSDConfig/sssdoptions.py:17 msgid "Set the verbosity of the debug logging" msgstr "디버그 로깅의 자세한 정보 설정" -#: src/config/SSSDConfig/sssdoptions.py:22 +#: src/config/SSSDConfig/sssdoptions.py:18 msgid "Include timestamps in debug logs" msgstr "디버그 기록에 시간표시 포함" -#: src/config/SSSDConfig/sssdoptions.py:23 +#: src/config/SSSDConfig/sssdoptions.py:19 msgid "Include microseconds in timestamps in debug logs" msgstr "디버그 기록에서 시간표기에는 마이크로초를 표시합니다" -#: src/config/SSSDConfig/sssdoptions.py:24 +#: src/config/SSSDConfig/sssdoptions.py:20 msgid "Enable/disable debug backtrace" msgstr "디버그 역추적 활성화/비활성화" -#: src/config/SSSDConfig/sssdoptions.py:25 +#: src/config/SSSDConfig/sssdoptions.py:21 msgid "Watchdog timeout before restarting service" msgstr "서비스를 재시작 하기 전에 와치독 시간초과" -#: src/config/SSSDConfig/sssdoptions.py:26 +#: src/config/SSSDConfig/sssdoptions.py:22 msgid "Command to start service" msgstr "서비스 시작 명령" -#: src/config/SSSDConfig/sssdoptions.py:27 +#: src/config/SSSDConfig/sssdoptions.py:23 msgid "The number of file descriptors that may be opened by this responder" msgstr "이 응답자에 의해 열 수 있는 파일 설명자 수" -#: src/config/SSSDConfig/sssdoptions.py:28 +#: src/config/SSSDConfig/sssdoptions.py:24 msgid "Idle time before automatic disconnection of a client" msgstr "클라이언트의 자동 연결 해제 전 유휴 시간" -#: src/config/SSSDConfig/sssdoptions.py:29 +#: src/config/SSSDConfig/sssdoptions.py:25 msgid "Idle time before automatic shutdown of the responder" msgstr "응답자의 자동 종료 전 유휴 시간" -#: src/config/SSSDConfig/sssdoptions.py:30 +#: src/config/SSSDConfig/sssdoptions.py:26 msgid "Always query all the caches before querying the Data Providers" msgstr "자료 공급자를 질의(쿼리)하기 전에 항상 모든 캐쉬를 질의합니다" -#: src/config/SSSDConfig/sssdoptions.py:31 +#: src/config/SSSDConfig/sssdoptions.py:27 msgid "" "When SSSD switches to offline mode the amount of time before it tries to go " "back online will increase based upon the time spent disconnected. This value " "is in seconds and calculated by the following: offline_timeout + " "random_offset." msgstr "" -"SSSD가 오프라인 방식으로 전환되면 연결이 끊긴 시간에 따라 온라인으로 " -"돌아가기 전에 시간이 늘어납니다. 이 값은 초 단위이며 다음에 의해 계산됩니다: " +"SSSD가 오프라인 방식으로 전환되면 연결이 끊긴 시간에 따라 온라인으로 돌아가" +"기 전에 시간이 늘어납니다. 이 값은 초 단위이며 다음에 의해 계산됩니다: " "offline_timeout + random_offset." -#: src/config/SSSDConfig/sssdoptions.py:36 +#: src/config/SSSDConfig/sssdoptions.py:32 msgid "SSSD Services to start" msgstr "시작 하려는 SSD 서비스" -#: src/config/SSSDConfig/sssdoptions.py:37 +#: src/config/SSSDConfig/sssdoptions.py:33 msgid "SSSD Domains to start" msgstr "시작하려는 SSSD 도메인" -#: src/config/SSSDConfig/sssdoptions.py:38 +#: src/config/SSSDConfig/sssdoptions.py:34 msgid "Regex to parse username and domain" msgstr "사용자 이름과 도메인을 구문 분석하는 정규식" -#: src/config/SSSDConfig/sssdoptions.py:39 +#: src/config/SSSDConfig/sssdoptions.py:35 msgid "Printf-compatible format for displaying fully-qualified names" msgstr "완전히-인증된 이름을 표시하기 위한 출력-호환 형식" -#: src/config/SSSDConfig/sssdoptions.py:40 +#: src/config/SSSDConfig/sssdoptions.py:36 msgid "" "Directory on the filesystem where SSSD should store Kerberos replay cache " "files." msgstr "" -"SSSD가 커버러스(Kerberos) 재생 캐쉬 파일을 저장해야 하는 파일 시스템의 " -"디렉토리." +"SSSD가 커버러스(Kerberos) 재생 캐쉬 파일을 저장해야 하는 파일 시스템의 디렉토" +"리." -#: src/config/SSSDConfig/sssdoptions.py:41 +#: src/config/SSSDConfig/sssdoptions.py:37 msgid "Domain to add to names without a domain component." msgstr "도메인 구성 요소가 없는 명칭이 추가되는 도메인." -#: src/config/SSSDConfig/sssdoptions.py:42 +#: src/config/SSSDConfig/sssdoptions.py:38 msgid "The user to drop privileges to" msgstr "사용자의 권한을 제거하는" -#: src/config/SSSDConfig/sssdoptions.py:43 +#: src/config/SSSDConfig/sssdoptions.py:39 msgid "Tune certificate verification" msgstr "인증 확인을 조정합니다" -#: src/config/SSSDConfig/sssdoptions.py:44 +#: src/config/SSSDConfig/sssdoptions.py:40 msgid "All spaces in group or user names will be replaced with this character" msgstr "그룹과 사용자 이름에서 모든 공간은 이와 같은 문자로 대체 될 것입니다" -#: src/config/SSSDConfig/sssdoptions.py:45 +#: src/config/SSSDConfig/sssdoptions.py:41 msgid "Tune sssd to honor or ignore netlink state changes" msgstr "sssd를 netlink 상태 변경을 존중하거나 무시하도록 조정합니다" -#: src/config/SSSDConfig/sssdoptions.py:46 +#: src/config/SSSDConfig/sssdoptions.py:42 msgid "Enable or disable the implicit files domain" msgstr "절대적인 파일 도메인을 활성화 또는 비활성화" -#: src/config/SSSDConfig/sssdoptions.py:47 +#: src/config/SSSDConfig/sssdoptions.py:43 msgid "A specific order of the domains to be looked up" msgstr "조회 할 도메인의 특정 순서" -#: src/config/SSSDConfig/sssdoptions.py:48 +#: src/config/SSSDConfig/sssdoptions.py:44 msgid "" "Controls if SSSD should monitor the state of resolv.conf to identify when it " "needs to update its internal DNS resolver." msgstr "" -"SSSD가 내부 DNS resolver를 최신화해야 하는 시기를 식별하기 위해 " -"resolv.conf의 상태를 모니터링 해야 하는지 여부를 제어합니다." +"SSSD가 내부 DNS resolver를 최신화해야 하는 시기를 식별하기 위해 resolv.conf" +"의 상태를 모니터링 해야 하는지 여부를 제어합니다." -#: src/config/SSSDConfig/sssdoptions.py:50 +#: src/config/SSSDConfig/sssdoptions.py:46 msgid "" "SSSD monitors the state of resolv.conf to identify when it needs to update " "its internal DNS resolver. By default, we will attempt to use inotify for " @@ -142,108 +142,110 @@ msgid "" "inotify cannot be used." msgstr "" "SSSD는 내부 DNS resolver를 최신화가 필요 할 때를 식별하기 위해 resolv.conf의 " -"상태를 관리합니다. 기본적으로, 우리는 이를 위해 inotify를 사용하려고 " -"시도하고, 만약 inotify를 사용 할 수 없는 경우에 매 5초마다 resolv.conf " -"투표로 되돌아 갈 것입니다." +"상태를 관리합니다. 기본적으로, 우리는 이를 위해 inotify를 사용하려고 시도하" +"고, 만약 inotify를 사용 할 수 없는 경우에 매 5초마다 resolv.conf 투표로 되돌" +"아 갈 것입니다." -#: src/config/SSSDConfig/sssdoptions.py:53 +#: src/config/SSSDConfig/sssdoptions.py:49 msgid "Run PAC responder automatically for AD and IPA provider" msgstr "AD와 IPA 공급자를 위해 자동으로 PAC 응답자 실행" -#: src/config/SSSDConfig/sssdoptions.py:54 +#: src/config/SSSDConfig/sssdoptions.py:50 msgid "Enable or disable core dumps for all SSSD processes." msgstr "SSSD 프로세서를 위한 코어 덤프 활성화 또는 비활성화." -#: src/config/SSSDConfig/sssdoptions.py:55 +#: src/config/SSSDConfig/sssdoptions.py:51 msgid "Tune passkey verification behavior" msgstr "패스키 확인 동작을 조정합니다" -#: src/config/SSSDConfig/sssdoptions.py:58 +#: src/config/SSSDConfig/sssdoptions.py:54 msgid "Enumeration cache timeout length (seconds)" msgstr "열거된 캐쉬 시간 초과 길이(초)" -#: src/config/SSSDConfig/sssdoptions.py:59 +#: src/config/SSSDConfig/sssdoptions.py:55 msgid "Entry cache background update timeout length (seconds)" msgstr "항목 캐쉬 백그라운드 최신화 시간 초과 길이(초)" -#: src/config/SSSDConfig/sssdoptions.py:60 -#: src/config/SSSDConfig/sssdoptions.py:125 +#: src/config/SSSDConfig/sssdoptions.py:56 +#: src/config/SSSDConfig/sssdoptions.py:124 msgid "Negative cache timeout length (seconds)" msgstr "네거티브 캐쉬 시간 초과 길이(초)" -#: src/config/SSSDConfig/sssdoptions.py:61 +#: src/config/SSSDConfig/sssdoptions.py:57 msgid "Users that SSSD should explicitly ignore" msgstr "SSSD가 명시적으로 무시해야 하는 사용자" -#: src/config/SSSDConfig/sssdoptions.py:62 +#: src/config/SSSDConfig/sssdoptions.py:58 msgid "Groups that SSSD should explicitly ignore" msgstr "SSSD가 명시적으로 무시해야 하는 그룹" -#: src/config/SSSDConfig/sssdoptions.py:63 +#: src/config/SSSDConfig/sssdoptions.py:59 msgid "Should filtered users appear in groups" msgstr "그룹에서 필터링된 사용자가 표시되어야 합니다" -#: src/config/SSSDConfig/sssdoptions.py:64 +#: src/config/SSSDConfig/sssdoptions.py:60 msgid "The value of the password field the NSS provider should return" msgstr "NSS 공급자가 반환해야 하는 비밀번호 입력 값" -#: src/config/SSSDConfig/sssdoptions.py:65 +#: src/config/SSSDConfig/sssdoptions.py:61 msgid "Override homedir value from the identity provider with this value" msgstr "이 값으로 식별 공급자에서 homedir 값을 재정의합니다" -#: src/config/SSSDConfig/sssdoptions.py:66 +#: src/config/SSSDConfig/sssdoptions.py:62 msgid "" "Substitute empty homedir value from the identity provider with this value" msgstr "이 값과 함께 식별 공급자에서 빈 homedir 값을 이 값으로 대체합니다" -#: src/config/SSSDConfig/sssdoptions.py:67 +#: src/config/SSSDConfig/sssdoptions.py:63 msgid "Override shell value from the identity provider with this value" msgstr "이 값과 함께 식별 공급자에서 쉘 값을 재정의 합니다" -#: src/config/SSSDConfig/sssdoptions.py:68 +#: src/config/SSSDConfig/sssdoptions.py:64 msgid "The list of shells users are allowed to log in with" msgstr "사용자가 접속할 수 있는 shells 목록" -#: src/config/SSSDConfig/sssdoptions.py:69 +#: src/config/SSSDConfig/sssdoptions.py:65 msgid "" "The list of shells that will be vetoed, and replaced with the fallback shell" msgstr "거부되어서 대체될 쉘 목록" -#: src/config/SSSDConfig/sssdoptions.py:70 +#: src/config/SSSDConfig/sssdoptions.py:66 msgid "" "If a shell stored in central directory is allowed but not available, use " "this fallback" msgstr "" -"중앙 디렉토리에 저장된 쉘이 허용되지만 사용할 수 없는 경우 이 대체를 " -"사용하십시오" +"중앙 디렉토리에 저장된 쉘이 허용되지만 사용할 수 없는 경우 이 대체를 사용하십" +"시오" -#: src/config/SSSDConfig/sssdoptions.py:71 +#: src/config/SSSDConfig/sssdoptions.py:67 msgid "Shell to use if the provider does not list one" msgstr "공급자가 목록을 나열하지 않는 경우 사용할 쉘" -#: src/config/SSSDConfig/sssdoptions.py:72 +#: src/config/SSSDConfig/sssdoptions.py:68 msgid "How long will be in-memory cache records valid" msgstr "캐쉬 메모리에 기록의 유효 기간" -#: src/config/SSSDConfig/sssdoptions.py:74 +#: src/config/SSSDConfig/sssdoptions.py:70 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for passwd requests" msgstr "비밀번호 요청을 위해 빠른 캐쉬 메모리에 할당된 자료 테이블의 크기(MB)" -#: src/config/SSSDConfig/sssdoptions.py:76 +#: src/config/SSSDConfig/sssdoptions.py:72 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for group requests" -msgstr "그룹 요청을 위한 고속 캐쉬 메모리에 내부에 할당된자료 테이블의 크기(MB)" +msgstr "" +"그룹 요청을 위한 고속 캐쉬 메모리에 내부에 할당된자료 테이블의 크기(MB)" -#: src/config/SSSDConfig/sssdoptions.py:78 +#: src/config/SSSDConfig/sssdoptions.py:74 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for initgroups requests" -msgstr "initgroups 요청을 위해 빠른 캐쉬 메모리에 할당된 자료 테이블의 크기(MB)" +msgstr "" +"initgroups 요청을 위해 빠른 캐쉬 메모리에 할당된 자료 테이블의 크기(MB)" -#: src/config/SSSDConfig/sssdoptions.py:79 +#: src/config/SSSDConfig/sssdoptions.py:75 msgid "" "The value of this option will be used in the expansion of the " "override_homedir option if the template contains the format string %H." @@ -251,114 +253,114 @@ msgstr "" "템플릿에 형식 문자열 %H가 포함된 경우 이 옵션의 값은 override_homedir 옵션의 " "확장에 사용됩니다." -#: src/config/SSSDConfig/sssdoptions.py:81 +#: src/config/SSSDConfig/sssdoptions.py:77 msgid "" "Specifies time in seconds for which the list of subdomains will be " "considered valid." msgstr "하위 도메인 목록이 유효한 것으로 간주되는 시간(초) 지정합니다." -#: src/config/SSSDConfig/sssdoptions.py:83 +#: src/config/SSSDConfig/sssdoptions.py:79 msgid "" "The entry cache can be set to automatically update entries in the background " "if they are requested beyond a percentage of the entry_cache_timeout value " "for the domain." msgstr "" -"항목 캐쉬는 도메인에 대한 entry_cache_timeout 값의 백분율을 초과하여 " -"요청되는 경우 백그라운드에서 항목을 자동으로 최신화 하도록 설정 할 수 " -"있습니다." +"항목 캐쉬는 도메인에 대한 entry_cache_timeout 값의 백분율을 초과하여 요청되" +"는 경우 백그라운드에서 항목을 자동으로 최신화 하도록 설정 할 수 있습니다." -#: src/config/SSSDConfig/sssdoptions.py:88 +#: src/config/SSSDConfig/sssdoptions.py:84 msgid "How long to allow cached logins between online logins (days)" msgstr "온라인 접속과 캐쉬 사이의 접속을 허용하는 기간(일)" -#: src/config/SSSDConfig/sssdoptions.py:89 +#: src/config/SSSDConfig/sssdoptions.py:85 msgid "How many failed logins attempts are allowed when offline" msgstr "오프라인일 때 허용되는 접속 시도 실패 횟수" -#: src/config/SSSDConfig/sssdoptions.py:91 +#: src/config/SSSDConfig/sssdoptions.py:87 msgid "" "How long (minutes) to deny login after offline_failed_login_attempts has " "been reached" -msgstr "offline_failed_login_attempts에 도달한 후 접속을 거부하는 데 걸리는 시간(분)" +msgstr "" +"offline_failed_login_attempts에 도달한 후 접속을 거부하는 데 걸리는 시간(분)" -#: src/config/SSSDConfig/sssdoptions.py:92 +#: src/config/SSSDConfig/sssdoptions.py:88 msgid "What kind of messages are displayed to the user during authentication" msgstr "인증 시 사용자에게 표시되는 정보의 종류" -#: src/config/SSSDConfig/sssdoptions.py:93 +#: src/config/SSSDConfig/sssdoptions.py:89 msgid "Filter PAM responses sent to the pam_sss" msgstr "pam_sss로 전송된 PAM 응답 필터링" -#: src/config/SSSDConfig/sssdoptions.py:94 +#: src/config/SSSDConfig/sssdoptions.py:90 msgid "How many seconds to keep identity information cached for PAM requests" msgstr "PAM 요청에 대해 캐쉬된 ID 정보를 유지하는 데 걸리는 시간(초)" -#: src/config/SSSDConfig/sssdoptions.py:95 +#: src/config/SSSDConfig/sssdoptions.py:91 msgid "How many days before password expiration a warning should be displayed" msgstr "암호 만료 경고를 표시해야 하는 일 수" -#: src/config/SSSDConfig/sssdoptions.py:96 +#: src/config/SSSDConfig/sssdoptions.py:92 msgid "List of trusted uids or user's name" msgstr "신뢰할 수 있는 uid 또는 사용자 이름 목록" -#: src/config/SSSDConfig/sssdoptions.py:97 +#: src/config/SSSDConfig/sssdoptions.py:93 msgid "List of domains accessible even for untrusted users." msgstr "신뢰할 수 없는 사용자도 액세스할 수 있는 도메인 목록입니다." -#: src/config/SSSDConfig/sssdoptions.py:98 +#: src/config/SSSDConfig/sssdoptions.py:94 msgid "Message printed when user account is expired." msgstr "사용자 계정이 만료되면 정보가 출력됩니다." -#: src/config/SSSDConfig/sssdoptions.py:99 +#: src/config/SSSDConfig/sssdoptions.py:95 msgid "Message printed when user account is locked." msgstr "사용자 계정이 잠겨 있을 때 출력되는 정보입니다." -#: src/config/SSSDConfig/sssdoptions.py:100 +#: src/config/SSSDConfig/sssdoptions.py:96 msgid "Allow certificate based/Smartcard authentication." msgstr "인증서 기반/스마트 카드 인증을 허용합니다." -#: src/config/SSSDConfig/sssdoptions.py:101 +#: src/config/SSSDConfig/sssdoptions.py:97 msgid "Path to certificate database with PKCS#11 modules." msgstr "PKCS#11 모듈은 인증서가 있는 데이터베이스의 경로입니다." -#: src/config/SSSDConfig/sssdoptions.py:102 +#: src/config/SSSDConfig/sssdoptions.py:98 msgid "Tune certificate verification for PAM authentication." msgstr "PAM 인증하기 위해서 인증서를 확인 조정합니다." -#: src/config/SSSDConfig/sssdoptions.py:103 +#: src/config/SSSDConfig/sssdoptions.py:99 msgid "How many seconds will pam_sss wait for p11_child to finish" msgstr "p11_child가 완료될 때까지 pam_ss가 몇 초 동안 대기합니까" -#: src/config/SSSDConfig/sssdoptions.py:104 +#: src/config/SSSDConfig/sssdoptions.py:100 msgid "Which PAM services are permitted to contact application domains" msgstr "응용프로그램 도메인에 접속 할 수 있는 PAM 서비스" -#: src/config/SSSDConfig/sssdoptions.py:105 +#: src/config/SSSDConfig/sssdoptions.py:101 msgid "Allowed services for using smartcards" msgstr "스마트카드 사용을 허용 서비스" -#: src/config/SSSDConfig/sssdoptions.py:106 +#: src/config/SSSDConfig/sssdoptions.py:102 msgid "Additional timeout to wait for a card if requested" msgstr "요청 시 카드를 기다리는 추가 시간 초과" -#: src/config/SSSDConfig/sssdoptions.py:107 +#: src/config/SSSDConfig/sssdoptions.py:103 msgid "" "PKCS#11 URI to restrict the selection of devices for Smartcard authentication" msgstr "스마트 카드 인증을 위한 장치 선택을 제한하는 PKCS#11 URI" -#: src/config/SSSDConfig/sssdoptions.py:108 +#: src/config/SSSDConfig/sssdoptions.py:104 msgid "When shall the PAM responder force an initgroups request" msgstr "PAM 응답자는 언제 initgroups 요청을 강제 실행합니까" -#: src/config/SSSDConfig/sssdoptions.py:109 +#: src/config/SSSDConfig/sssdoptions.py:105 msgid "List of PAM services that are allowed to authenticate with GSSAPI." msgstr "GSSAPI 인증할 수 있는 PAM 서비스 목록입니다." -#: src/config/SSSDConfig/sssdoptions.py:110 +#: src/config/SSSDConfig/sssdoptions.py:106 msgid "Whether to match authenticated UPN with target user" msgstr "인증된 UPN과 대상 사용자와 일치시킬지 여부" -#: src/config/SSSDConfig/sssdoptions.py:111 +#: src/config/SSSDConfig/sssdoptions.py:107 msgid "" "List of pairs : that must be enforced " "for PAM access with GSSAPI authentication" @@ -366,31 +368,41 @@ msgstr "" "GSSAPI 인증을 사용하여 PAM 접근 허용해야 하는 :<인증 표시기> 쌍 " "목록" -#: src/config/SSSDConfig/sssdoptions.py:113 +#: src/config/SSSDConfig/sssdoptions.py:109 +#, fuzzy +msgid "" +"List of triples :: that assigns " +"additional information from the Kerberos ticket to an authentication " +"indicator." +msgstr "" +"GSSAPI 인증을 사용하여 PAM 접근 허용해야 하는 :<인증 표시기> 쌍 " +"목록" + +#: src/config/SSSDConfig/sssdoptions.py:112 msgid "Allow passkey device authentication." msgstr "패스키 장치 인증을 허용합니다." -#: src/config/SSSDConfig/sssdoptions.py:114 +#: src/config/SSSDConfig/sssdoptions.py:113 msgid "How many seconds will pam_sss wait for passkey_child to finish" msgstr "passkey_child가 완료될 때까지 pam_sss가 몇 초 동안 대기합니까" -#: src/config/SSSDConfig/sssdoptions.py:115 +#: src/config/SSSDConfig/sssdoptions.py:114 msgid "Enable debugging in the libfido2 library" msgstr "libfido2 라이브러리에서 디버깅 활성화" -#: src/config/SSSDConfig/sssdoptions.py:116 +#: src/config/SSSDConfig/sssdoptions.py:115 msgid "Enable JSON protocol for authentication methods selection." msgstr "인증 방법 선택을 위한 JSON 통신규약 활성화." -#: src/config/SSSDConfig/sssdoptions.py:119 +#: src/config/SSSDConfig/sssdoptions.py:118 msgid "Whether to evaluate the time-based attributes in sudo rules" msgstr "sudo 규칙에서 시간 기반 속성을 평가할지 여부" -#: src/config/SSSDConfig/sssdoptions.py:120 +#: src/config/SSSDConfig/sssdoptions.py:119 msgid "If true, SSSD will switch back to lower-wins ordering logic" msgstr "true인 경우 SSSD는 낮은 승률의 주문 논리로 다시 전환합니다" -#: src/config/SSSDConfig/sssdoptions.py:121 +#: src/config/SSSDConfig/sssdoptions.py:120 msgid "" "Maximum number of rules that can be refreshed at once. If this is exceeded, " "full refresh is performed." @@ -398,57 +410,58 @@ msgstr "" "한 번에 새로 고칠 수 있는 최대 규칙 수입니다. 이를 초과하면 전체 새로 고침이 " "수행됩니다." -#: src/config/SSSDConfig/sssdoptions.py:128 +#: src/config/SSSDConfig/sssdoptions.py:127 msgid "Whether to hash host names and addresses in the known_hosts file" msgstr "known_hosts 파일에서 호스트 이름과 주소를 해시(hash)할지 여부" -#: src/config/SSSDConfig/sssdoptions.py:129 +#: src/config/SSSDConfig/sssdoptions.py:128 msgid "" "How many seconds to keep a host in the known_hosts file after its host keys " "were requested" -msgstr "호스트 키가 요청된 후 호스트를 known_hosts 파일에 유지하는 데 걸리는 시간(초)" +msgstr "" +"호스트 키가 요청된 후 호스트를 known_hosts 파일에 유지하는 데 걸리는 시간(초)" -#: src/config/SSSDConfig/sssdoptions.py:131 +#: src/config/SSSDConfig/sssdoptions.py:130 msgid "Path to storage of trusted CA certificates" msgstr "신뢰할 수 있는 CA 인증서 저장 경로" -#: src/config/SSSDConfig/sssdoptions.py:132 +#: src/config/SSSDConfig/sssdoptions.py:131 msgid "Allow to generate ssh-keys from certificates" msgstr "인증서에서 ssh 키 생성 허용" -#: src/config/SSSDConfig/sssdoptions.py:133 +#: src/config/SSSDConfig/sssdoptions.py:132 msgid "" "Use the following matching rules to filter the certificates for ssh-key " "generation" msgstr "다음 일치 규칙을 사용하여 ssh 키 생성을 위한 인증서를 필터링합니다" -#: src/config/SSSDConfig/sssdoptions.py:137 +#: src/config/SSSDConfig/sssdoptions.py:136 msgid "List of UIDs or user names allowed to access the PAC responder" msgstr "PAC 응답자에 접근할 수 있는 UID 또는 사용자 이름 목록" -#: src/config/SSSDConfig/sssdoptions.py:138 +#: src/config/SSSDConfig/sssdoptions.py:137 msgid "How long the PAC data is considered valid" msgstr "PAC 데이터가 유효한 것으로 간주되는 기간" -#: src/config/SSSDConfig/sssdoptions.py:139 +#: src/config/SSSDConfig/sssdoptions.py:138 msgid "Validate the PAC" msgstr "PAC 검증" -#: src/config/SSSDConfig/sssdoptions.py:142 +#: src/config/SSSDConfig/sssdoptions.py:141 msgid "List of user attributes the InfoPipe is allowed to publish" msgstr "InfoPipe가 게시할 수 있는 사용자 속성 목록" -#: src/config/SSSDConfig/sssdoptions.py:145 +#: src/config/SSSDConfig/sssdoptions.py:144 msgid "" "One of the following strings specifying the scope of session recording: none " "- No users are recorded. some - Users/groups specified by users and groups " "options are recorded. all - All users are recorded." msgstr "" -"세션 기록 범위를 지정하는 다음 문자열 중 하나: 없음 - 기록된 사용자가 " -"없습니다. 일부 - 사용자 및 그룹 옵션에서 지정한 사용자/그룹이 기록됩니다. " -"all - 모든 사용자가 기록됩니다." +"세션 기록 범위를 지정하는 다음 문자열 중 하나: 없음 - 기록된 사용자가 없습니" +"다. 일부 - 사용자 및 그룹 옵션에서 지정한 사용자/그룹이 기록됩니다. all - 모" +"든 사용자가 기록됩니다." -#: src/config/SSSDConfig/sssdoptions.py:148 +#: src/config/SSSDConfig/sssdoptions.py:147 msgid "" "A comma-separated list of users which should have session recording enabled. " "Matches user names as returned by NSS. I.e. after the possible space " @@ -457,100 +470,101 @@ msgstr "" "세션 기록을 활성화해야 하는 쉼표로 구분된 사용자 목록입니다. NSS에서 반환된 " "사용자 이름과 일치합니다. 가능한 공간 교체 후, 케이스 변경 등." -#: src/config/SSSDConfig/sssdoptions.py:150 +#: src/config/SSSDConfig/sssdoptions.py:149 msgid "" "A comma-separated list of groups, members of which should have session " "recording enabled. Matches group names as returned by NSS. I.e. after the " "possible space replacement, case changes, etc." msgstr "" -"쉼표로 구분된 그룹 목록으로, 그 구성원은 세션 기록을 활성화해야 합니다. " -"NSS에서 반환된 그룹 이름과 일치합니다. 가능한 공간 교체 후, 케이스 변경 등." +"쉼표로 구분된 그룹 목록으로, 그 구성원은 세션 기록을 활성화해야 합니다. NSS에" +"서 반환된 그룹 이름과 일치합니다. 가능한 공간 교체 후, 케이스 변경 등." -#: src/config/SSSDConfig/sssdoptions.py:153 +#: src/config/SSSDConfig/sssdoptions.py:152 msgid "" "A comma-separated list of users to be excluded from recording, only when " "scope=all" msgstr "scope=all인 경우에만 기록에서 제외할 쉼표로 구분된 사용자 목록" -#: src/config/SSSDConfig/sssdoptions.py:154 +#: src/config/SSSDConfig/sssdoptions.py:153 msgid "" "A comma-separated list of groups, members of which should be excluded from " "recording, only when scope=all. " -msgstr "scope=all인 경우에만 기록에서 제외되어야 하는 쉼표로 구분된 그룹 목록입니다. " +msgstr "" +"scope=all인 경우에만 기록에서 제외되어야 하는 쉼표로 구분된 그룹 목록입니다. " -#: src/config/SSSDConfig/sssdoptions.py:158 +#: src/config/SSSDConfig/sssdoptions.py:157 msgid "Identity provider" msgstr "ID 공급자" -#: src/config/SSSDConfig/sssdoptions.py:159 +#: src/config/SSSDConfig/sssdoptions.py:158 msgid "Authentication provider" msgstr "인증 공급자" -#: src/config/SSSDConfig/sssdoptions.py:160 +#: src/config/SSSDConfig/sssdoptions.py:159 msgid "Access control provider" msgstr "접근 제어 공급자" -#: src/config/SSSDConfig/sssdoptions.py:161 +#: src/config/SSSDConfig/sssdoptions.py:160 msgid "Password change provider" msgstr "비밀번호 변경 공급자" -#: src/config/SSSDConfig/sssdoptions.py:162 +#: src/config/SSSDConfig/sssdoptions.py:161 msgid "SUDO provider" msgstr "SUDO 공급자" -#: src/config/SSSDConfig/sssdoptions.py:163 +#: src/config/SSSDConfig/sssdoptions.py:162 msgid "Autofs provider" msgstr "autofs 공급자" -#: src/config/SSSDConfig/sssdoptions.py:164 +#: src/config/SSSDConfig/sssdoptions.py:163 msgid "Host identity provider" msgstr "호스트 ID 공급자" -#: src/config/SSSDConfig/sssdoptions.py:165 +#: src/config/SSSDConfig/sssdoptions.py:164 msgid "SELinux provider" msgstr "SELinux 공급자" -#: src/config/SSSDConfig/sssdoptions.py:166 +#: src/config/SSSDConfig/sssdoptions.py:165 msgid "Session management provider" msgstr "세션 관리 공급자" -#: src/config/SSSDConfig/sssdoptions.py:167 +#: src/config/SSSDConfig/sssdoptions.py:166 msgid "Resolver provider" msgstr "해결 공급자" -#: src/config/SSSDConfig/sssdoptions.py:170 +#: src/config/SSSDConfig/sssdoptions.py:169 msgid "Whether the domain is usable by the OS or by applications" msgstr "도메인이 OS 또는 응용프로그램에서 사용 가능한지 여부" -#: src/config/SSSDConfig/sssdoptions.py:171 +#: src/config/SSSDConfig/sssdoptions.py:170 msgid "Enable or disable the domain" msgstr "도메인 활성화 또는 비활성화" -#: src/config/SSSDConfig/sssdoptions.py:172 +#: src/config/SSSDConfig/sssdoptions.py:171 msgid "Minimum user ID" msgstr "최소 사용자 ID" -#: src/config/SSSDConfig/sssdoptions.py:173 +#: src/config/SSSDConfig/sssdoptions.py:172 msgid "Maximum user ID" msgstr "최대 사용자 ID" -#: src/config/SSSDConfig/sssdoptions.py:174 +#: src/config/SSSDConfig/sssdoptions.py:173 msgid "Enable enumerating all users/groups" msgstr "모든 사용자/그룹 활성화" -#: src/config/SSSDConfig/sssdoptions.py:175 +#: src/config/SSSDConfig/sssdoptions.py:174 msgid "Cache credentials for offline login" msgstr "오프라인 접속을 위한 캐쉬 자격 증명" -#: src/config/SSSDConfig/sssdoptions.py:176 +#: src/config/SSSDConfig/sssdoptions.py:175 msgid "Display users/groups in fully-qualified form" msgstr "정규화된 형식으로 사용자/그룹 표시" -#: src/config/SSSDConfig/sssdoptions.py:177 +#: src/config/SSSDConfig/sssdoptions.py:176 msgid "Don't include group members in group lookups" msgstr "그룹 검색에 그룹 구성원을 포함하지 마십시오" -#: src/config/SSSDConfig/sssdoptions.py:178 +#: src/config/SSSDConfig/sssdoptions.py:177 #: src/config/SSSDConfig/sssdoptions.py:190 #: src/config/SSSDConfig/sssdoptions.py:191 #: src/config/SSSDConfig/sssdoptions.py:192 @@ -561,50 +575,55 @@ msgstr "그룹 검색에 그룹 구성원을 포함하지 마십시오" msgid "Entry cache timeout length (seconds)" msgstr "항목 캐쉬 시간 초과 길이(초)" -#: src/config/SSSDConfig/sssdoptions.py:179 +#: src/config/SSSDConfig/sssdoptions.py:178 msgid "" "Restrict or prefer a specific address family when performing DNS lookups" msgstr "DNS 검색을 수행할 때 특정 주소 계열을 제한하거나 선호합니다" -#: src/config/SSSDConfig/sssdoptions.py:180 +#: src/config/SSSDConfig/sssdoptions.py:179 msgid "How long to keep cached entries after last successful login (days)" msgstr "마지막 접속 성공 후 캐쉬된 항목을 보관할 기간(일)" -#: src/config/SSSDConfig/sssdoptions.py:181 +#: src/config/SSSDConfig/sssdoptions.py:180 msgid "" "How long should SSSD talk to single DNS server before trying next server " "(miliseconds)" -msgstr "다음 서버를 시도하기 전에 SSSD가 단일 DNS 서버와 통신해야 하는 시간(밀리초)" +msgstr "" +"다음 서버를 시도하기 전에 SSSD가 단일 DNS 서버와 통신해야 하는 시간(밀리초)" -#: src/config/SSSDConfig/sssdoptions.py:183 +#: src/config/SSSDConfig/sssdoptions.py:182 msgid "How long should keep trying to resolve single DNS query (seconds)" msgstr "단일 DNS 쿼리를 해결하기 위해 계속 시도해야 하는 시간(초)" -#: src/config/SSSDConfig/sssdoptions.py:184 +#: src/config/SSSDConfig/sssdoptions.py:183 msgid "How long to wait for replies from DNS when resolving servers (seconds)" msgstr "서버를 확인할 때 DNS의 응답을 기다리는 시간(초)" -#: src/config/SSSDConfig/sssdoptions.py:185 +#: src/config/SSSDConfig/sssdoptions.py:184 msgid "The domain part of service discovery DNS query" msgstr "서비스 검색 DNS 쿼리의 도메인 부분" -#: src/config/SSSDConfig/sssdoptions.py:186 +#: src/config/SSSDConfig/sssdoptions.py:185 msgid "" "Specifies the interval, in seconds, that SSSD waits before attempting to " "reconnect to the primary server after a successful connection to the backup " "server" msgstr "" -"백업 서버로 성공적으로 연결 후에 주 서버로 재연결을 시도하기 전에 SSSD가 " -"대기하는 간격(초)을 지정합니다" +"백업 서버로 성공적으로 연결 후에 주 서버로 재연결을 시도하기 전에 SSSD가 대기" +"하는 간격(초)을 지정합니다" -#: src/config/SSSDConfig/sssdoptions.py:188 +#: src/config/SSSDConfig/sssdoptions.py:187 msgid "Override GID value from the identity provider with this value" msgstr "이 값으로 ID 공급자의 GID 값 재정의" -#: src/config/SSSDConfig/sssdoptions.py:189 +#: src/config/SSSDConfig/sssdoptions.py:188 msgid "Treat usernames as case sensitive" msgstr "사용자 이름을 대소문자 구분" +#: src/config/SSSDConfig/sssdoptions.py:189 +msgid "Lookups by ID are expensive or do not work at all" +msgstr "" + #: src/config/SSSDConfig/sssdoptions.py:197 msgid "How often should expired entries be refreshed in background" msgstr "만료된 항목을 백그라운드에서 새로고침하는 빈도" @@ -711,8 +730,8 @@ msgid "" "The provider which should handle fetching of subdomains. This value should " "be always the same as id_provider." msgstr "" -"하위 도메인 가져오기를 처리해야 하는 공급자. 이와 같은 값은 항상 " -"id_provider와 같아야 합니다." +"하위 도메인 가져오기를 처리해야 하는 공급자. 이와 같은 값은 항상 id_provider" +"와 같아야 합니다." #: src/config/SSSDConfig/sssdoptions.py:224 msgid "" @@ -729,8 +748,8 @@ msgid "" "(long term password) must have to be saved as SHA512 hash into the cache." msgstr "" "만약 2-Factor-Authentication(2FA)가 사용되고 자격 증명을 저장해야 하는 경우 " -"이 값은 첫 번째 인증 요소(장기 비밀번호)가 SHA512 해쉬로 캐쉬에 저장되어야 " -"하는 최소 길이를 결정합니다." +"이 값은 첫 번째 인증 요소(장기 비밀번호)가 SHA512 해쉬로 캐쉬에 저장되어야 하" +"는 최소 길이를 결정합니다." #: src/config/SSSDConfig/sssdoptions.py:230 msgid "Local authentication methods policy " @@ -819,15 +838,16 @@ msgstr "데스크탑 프로필 관련 개체 검색 기준" msgid "" "The amount of time in seconds between lookups of the Desktop Profile rules " "against the IPA server" -msgstr "IPA 서버에 대응하는 데스크탑 프로파일 규칙의 검색 사이에서 초 단위 시간의 양" +msgstr "" +"IPA 서버에 대응하는 데스크탑 프로파일 규칙의 검색 사이에서 초 단위 시간의 양" #: src/config/SSSDConfig/sssdoptions.py:255 msgid "" "The amount of time in minutes between lookups of Desktop Profiles rules " "against the IPA server when the last request did not find any rule" msgstr "" -"마지막 요청이 규칙을 찾지 못한 경우 IPA 서버에 대한 데스크탑 프로필 규칙 " -"검색 간격(분)입니다" +"마지막 요청이 규칙을 찾지 못한 경우 IPA 서버에 대한 데스크탑 프로필 규칙 검" +"색 간격(분)입니다" #: src/config/SSSDConfig/sssdoptions.py:258 #: src/config/SSSDConfig/sssdoptions.py:455 @@ -835,7 +855,7 @@ msgid "Search base for SUBID ranges" msgstr "SUBID 범위를 위한 기반 검색" #: src/config/SSSDConfig/sssdoptions.py:259 -#: src/config/SSSDConfig/sssdoptions.py:506 +#: src/config/SSSDConfig/sssdoptions.py:512 msgid "Which rules should be used to evaluate access control" msgstr "액세스 제어를 평가하기 위해 사용해야 하는 규칙" @@ -868,13 +888,15 @@ msgstr "netgroup 멤버의 이름이 포함된 LDAP 속성입니다." msgid "" "The LDAP attribute that lists FQDNs of hosts and host groups that are " "members of the netgroup." -msgstr "netgroup의 멤버인 호스트 및 호스트 그룹의 FQDN을 나열하는 LDAP 속성입니다." +msgstr "" +"netgroup의 멤버인 호스트 및 호스트 그룹의 FQDN을 나열하는 LDAP 속성입니다." #: src/config/SSSDConfig/sssdoptions.py:268 msgid "" "The LDAP attribute that lists hosts and host groups that are direct members " "of the netgroup." -msgstr "netgroup의 직접 구성원인 호스트 및 호스트 그룹을 나열하는 LDAP 속성입니다." +msgstr "" +"netgroup의 직접 구성원인 호스트 및 호스트 그룹을 나열하는 LDAP 속성입니다." #: src/config/SSSDConfig/sssdoptions.py:270 msgid "The LDAP attribute that lists netgroup's memberships." @@ -884,7 +906,8 @@ msgstr "netgroup의 멤버십을 나열하는 LDAP 속성입니다." msgid "" "The LDAP attribute that lists system users and groups that are direct " "members of the netgroup." -msgstr "netgroup의 직접 구성원인 시스템 사용자 및 그룹을 나열하는 LDAP 속성입니다." +msgstr "" +"netgroup의 직접 구성원인 시스템 사용자 및 그룹을 나열하는 LDAP 속성입니다." #: src/config/SSSDConfig/sssdoptions.py:273 msgid "The LDAP attribute that corresponds to the netgroup name." @@ -929,8 +952,8 @@ msgid "" "The LDAP attribute that contains DN of HBAC rule which can be used for " "matching instead of memberUser and memberHost." msgstr "" -"memberUser 및 memberHost 대신 일치하는 데 사용할 수 있는 HBAC 규칙의 DN이 " -"포함된 LDAP 속성입니다." +"memberUser 및 memberHost 대신 일치하는 데 사용할 수 있는 HBAC 규칙의 DN이 포" +"함된 LDAP 속성입니다." #: src/config/SSSDConfig/sssdoptions.py:287 msgid "The LDAP attribute that contains SELinux user string itself." @@ -981,7 +1004,7 @@ msgid "Enable DNS sites - location based service discovery" msgstr "DNS 사이트 활성화 - 위치 기반 서비스 검색" #: src/config/SSSDConfig/sssdoptions.py:301 -#: src/config/SSSDConfig/sssdoptions.py:504 +#: src/config/SSSDConfig/sssdoptions.py:510 msgid "LDAP filter to determine access privileges" msgstr "액세스 권한을 결정하는 LDAP 필터" @@ -1009,7 +1032,8 @@ msgstr "GPO(거부)InteractiveLogonRight 정책 설정에 매핑되는 PAM 서 msgid "" "PAM service names that map to the GPO (Deny)RemoteInteractiveLogonRight " "policy settings" -msgstr "GPO(거부)RemoteInteractiveLogonRight 정책 설정에 매핑되는 PAM 서비스 이름" +msgstr "" +"GPO(거부)RemoteInteractiveLogonRight 정책 설정에 매핑되는 PAM 서비스 이름" #: src/config/SSSDConfig/sssdoptions.py:309 msgid "" @@ -1037,7 +1061,8 @@ msgstr "GPO 기반 액세스가 항상 거부되는 PAM 서비스 이름" #: src/config/SSSDConfig/sssdoptions.py:314 msgid "" "Default logon right (or permit/deny) to use for unmapped PAM service names" -msgstr "매핑되지 않은 PAM 서비스 이름에 사용할 기본 로그온 권한 (또는 허용/거부)" +msgstr "" +"매핑되지 않은 PAM 서비스 이름에 사용할 기본 로그온 권한 (또는 허용/거부)" #: src/config/SSSDConfig/sssdoptions.py:315 msgid "a particular site to be used by the client" @@ -1287,8 +1312,8 @@ msgid "" "Whether the LDAP library should perform a reverse lookup to canonicalize the " "host name during a SASL bind" msgstr "" -"LDAP 라이브러리에서 SASL 바인드 중에 호스트 이름을 정식화하기 위해 역방향 " -"검색을 수행해야 하는지 여부" +"LDAP 라이브러리에서 SASL 바인드 중에 호스트 이름을 정식화하기 위해 역방향 검" +"색을 수행해야 하는지 여부" #: src/config/SSSDConfig/sssdoptions.py:389 msgid "" @@ -1327,8 +1352,8 @@ msgid "" "Force a password change when remaining grace logins reach or go below this " "threshold" msgstr "" -"임시 허용 로그인이 해당 임계값에 도달하거나 그 아래로 갈 때에 비밀번호를 " -"변경을 강제합니다" +"임시 허용 로그인이 해당 임계값에 도달하거나 그 아래로 갈 때에 비밀번호를 변경" +"을 강제합니다" #: src/config/SSSDConfig/sssdoptions.py:404 msgid "Length of time to wait for a search request" @@ -1407,7 +1432,7 @@ msgid "UUID attribute" msgstr "UUID 속성" #: src/config/SSSDConfig/sssdoptions.py:423 -#: src/config/SSSDConfig/sssdoptions.py:464 +#: src/config/SSSDConfig/sssdoptions.py:470 msgid "objectSID attribute" msgstr "objectSID 속성" @@ -1531,201 +1556,231 @@ msgstr "사용자의 패스키 대응 자료를 포함하는 속성" msgid "A list of extra attributes to download along with the user entry" msgstr "사용자 항목과 함께 내려받기 하려는 추가 속성의 목록" +#: src/config/SSSDConfig/sssdoptions.py:456 +#, fuzzy +msgid "The object class of an subid entry in LDAP." +msgstr "LDAP에서 호스트 항목의 개체 클래스입니다." + #: src/config/SSSDConfig/sssdoptions.py:457 +#, fuzzy +msgid "Subordinate user ID count attribute" +msgstr "sudo 규칙 사용자 속성" + +#: src/config/SSSDConfig/sssdoptions.py:458 +#, fuzzy +msgid "Subordinate group ID count attribute" +msgstr "sudo 규칙 옵션 속성" + +#: src/config/SSSDConfig/sssdoptions.py:459 +#, fuzzy +msgid "User ID range start value attribute" +msgstr "사용자 이름 속성" + +#: src/config/SSSDConfig/sssdoptions.py:460 +#, fuzzy +msgid "Group ID range start value attribute" +msgstr "그룹 UUID 속성" + +#: src/config/SSSDConfig/sssdoptions.py:461 +msgid "Owner of an entry" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:463 msgid "Base DN for group lookups" msgstr "그룹 검색의 기본 DN" -#: src/config/SSSDConfig/sssdoptions.py:458 +#: src/config/SSSDConfig/sssdoptions.py:464 msgid "Objectclass for groups" msgstr "그룹용 개체 클래스" -#: src/config/SSSDConfig/sssdoptions.py:459 +#: src/config/SSSDConfig/sssdoptions.py:465 msgid "Group name" msgstr "그룹 이름" -#: src/config/SSSDConfig/sssdoptions.py:460 +#: src/config/SSSDConfig/sssdoptions.py:466 msgid "Group password" msgstr "그룹 비밀번호" -#: src/config/SSSDConfig/sssdoptions.py:461 +#: src/config/SSSDConfig/sssdoptions.py:467 msgid "GID attribute" msgstr "GID 속성" -#: src/config/SSSDConfig/sssdoptions.py:462 +#: src/config/SSSDConfig/sssdoptions.py:468 msgid "Group member attribute" msgstr "그룹 멤버 속성" -#: src/config/SSSDConfig/sssdoptions.py:463 +#: src/config/SSSDConfig/sssdoptions.py:469 msgid "Group UUID attribute" msgstr "그룹 UUID 속성" -#: src/config/SSSDConfig/sssdoptions.py:465 +#: src/config/SSSDConfig/sssdoptions.py:471 msgid "Modification time attribute for groups" msgstr "그룹의 수정 시간 속성" -#: src/config/SSSDConfig/sssdoptions.py:466 +#: src/config/SSSDConfig/sssdoptions.py:472 msgid "Type of the group and other flags" msgstr "그룹 유형 및 기타 플래그" -#: src/config/SSSDConfig/sssdoptions.py:467 +#: src/config/SSSDConfig/sssdoptions.py:473 msgid "The LDAP group external member attribute" msgstr "LDAP 그룹 외부 멤버 속성" -#: src/config/SSSDConfig/sssdoptions.py:468 +#: src/config/SSSDConfig/sssdoptions.py:474 msgid "Maximum nesting level SSSD will follow" msgstr "SSSD가 따르는 최대 중첩 수준" -#: src/config/SSSDConfig/sssdoptions.py:469 +#: src/config/SSSDConfig/sssdoptions.py:475 msgid "Filter for group lookups" msgstr "그룹 검색 필터링" -#: src/config/SSSDConfig/sssdoptions.py:470 +#: src/config/SSSDConfig/sssdoptions.py:476 msgid "Scope of group lookups" msgstr "그룹 검색 범위" -#: src/config/SSSDConfig/sssdoptions.py:472 +#: src/config/SSSDConfig/sssdoptions.py:478 msgid "Base DN for netgroup lookups" msgstr "netgroup 검색의 기본 DN" -#: src/config/SSSDConfig/sssdoptions.py:473 +#: src/config/SSSDConfig/sssdoptions.py:479 msgid "Objectclass for netgroups" msgstr "netgroup의 오브젝트 클래스" -#: src/config/SSSDConfig/sssdoptions.py:474 +#: src/config/SSSDConfig/sssdoptions.py:480 msgid "Netgroup name" msgstr "Netgroup 이름" -#: src/config/SSSDConfig/sssdoptions.py:475 +#: src/config/SSSDConfig/sssdoptions.py:481 msgid "Netgroups members attribute" msgstr "netgroups 멤버 속성" -#: src/config/SSSDConfig/sssdoptions.py:476 +#: src/config/SSSDConfig/sssdoptions.py:482 msgid "Netgroup triple attribute" msgstr "Netgroup Triple 속성" -#: src/config/SSSDConfig/sssdoptions.py:477 +#: src/config/SSSDConfig/sssdoptions.py:483 msgid "Modification time attribute for netgroups" msgstr "netgroups의 수정 시간 속성" -#: src/config/SSSDConfig/sssdoptions.py:479 +#: src/config/SSSDConfig/sssdoptions.py:485 msgid "Base DN for service lookups" msgstr "서비스 검색의 기본 DN" -#: src/config/SSSDConfig/sssdoptions.py:480 +#: src/config/SSSDConfig/sssdoptions.py:486 msgid "Objectclass for services" msgstr "서비스용 오브젝트 클래스" -#: src/config/SSSDConfig/sssdoptions.py:481 +#: src/config/SSSDConfig/sssdoptions.py:487 msgid "Service name attribute" msgstr "서비스 이름 속성" -#: src/config/SSSDConfig/sssdoptions.py:482 +#: src/config/SSSDConfig/sssdoptions.py:488 msgid "Service port attribute" msgstr "서비스 포트 속성" -#: src/config/SSSDConfig/sssdoptions.py:483 +#: src/config/SSSDConfig/sssdoptions.py:489 msgid "Service protocol attribute" msgstr "서비스 프로토콜 속성" -#: src/config/SSSDConfig/sssdoptions.py:485 +#: src/config/SSSDConfig/sssdoptions.py:491 msgid "Lower bound for ID-mapping" msgstr "ID 매핑의 바인딩 하한값" -#: src/config/SSSDConfig/sssdoptions.py:486 +#: src/config/SSSDConfig/sssdoptions.py:492 msgid "Upper bound for ID-mapping" msgstr "ID 매핑의 바인딩 상한값" -#: src/config/SSSDConfig/sssdoptions.py:487 +#: src/config/SSSDConfig/sssdoptions.py:493 msgid "Number of IDs for each slice when ID-mapping" msgstr "ID 매핑 시 각 슬라이스에 대한 ID 수" -#: src/config/SSSDConfig/sssdoptions.py:488 +#: src/config/SSSDConfig/sssdoptions.py:494 msgid "Use autorid-compatible algorithm for ID-mapping" msgstr "ID 매핑을 위한 autorid-compatible 알고리즘 사용" -#: src/config/SSSDConfig/sssdoptions.py:489 +#: src/config/SSSDConfig/sssdoptions.py:495 msgid "Name of the default domain for ID-mapping" msgstr "ID 매핑의 기본 도메인 이름" -#: src/config/SSSDConfig/sssdoptions.py:490 +#: src/config/SSSDConfig/sssdoptions.py:496 msgid "SID of the default domain for ID-mapping" msgstr "ID 매핑을 위한 기본 도메인의 SID" -#: src/config/SSSDConfig/sssdoptions.py:491 +#: src/config/SSSDConfig/sssdoptions.py:497 msgid "Number of secondary slices" msgstr "두 번째 슬라이스 수" -#: src/config/SSSDConfig/sssdoptions.py:493 +#: src/config/SSSDConfig/sssdoptions.py:499 msgid "Whether to use Token-Groups" msgstr "Token-Groups 사용 여부" -#: src/config/SSSDConfig/sssdoptions.py:494 +#: src/config/SSSDConfig/sssdoptions.py:500 msgid "Set lower boundary for allowed IDs from the LDAP server" msgstr "LDAP 서버에서 허용된 ID의 하한 경계 설정" -#: src/config/SSSDConfig/sssdoptions.py:495 +#: src/config/SSSDConfig/sssdoptions.py:501 msgid "Set upper boundary for allowed IDs from the LDAP server" msgstr "LDAP 서버에서 허용된 ID의 상한 경계 설정" -#: src/config/SSSDConfig/sssdoptions.py:496 +#: src/config/SSSDConfig/sssdoptions.py:502 msgid "DN for ppolicy queries" msgstr "ppolicy 쿼리의 DN" -#: src/config/SSSDConfig/sssdoptions.py:497 +#: src/config/SSSDConfig/sssdoptions.py:503 msgid "How many maximum entries to fetch during a wildcard request" msgstr "와일드카드 요청 중 가져올 최대 항목 수" -#: src/config/SSSDConfig/sssdoptions.py:498 +#: src/config/SSSDConfig/sssdoptions.py:504 msgid "Set libldap debug level" msgstr "libldap 디버그 수준 설정" -#: src/config/SSSDConfig/sssdoptions.py:501 +#: src/config/SSSDConfig/sssdoptions.py:507 msgid "Policy to evaluate the password expiration" msgstr "암호 만료 평가 정책" -#: src/config/SSSDConfig/sssdoptions.py:505 +#: src/config/SSSDConfig/sssdoptions.py:511 msgid "Which attributes shall be used to evaluate if an account is expired" msgstr "계정이 만료되었는지 평가하기 위해 사용할 속성" -#: src/config/SSSDConfig/sssdoptions.py:509 +#: src/config/SSSDConfig/sssdoptions.py:515 msgid "URI of an LDAP server where password changes are allowed" msgstr "암호 변경이 허용되는 LDAP 서버의 URI" -#: src/config/SSSDConfig/sssdoptions.py:510 +#: src/config/SSSDConfig/sssdoptions.py:516 msgid "URI of a backup LDAP server where password changes are allowed" msgstr "암호 변경이 허용되는 백업 LDAP 서버의 URI" -#: src/config/SSSDConfig/sssdoptions.py:511 +#: src/config/SSSDConfig/sssdoptions.py:517 msgid "DNS service name for LDAP password change server" msgstr "LDAP 암호 변경 서버의 DNS 서비스 이름" -#: src/config/SSSDConfig/sssdoptions.py:512 +#: src/config/SSSDConfig/sssdoptions.py:518 msgid "" "Whether to update the ldap_user_shadow_last_change attribute after a " "password change" -msgstr "비밀번호 변경 후에 ldap_user_shadow_last_change 속성을 최신화 할지 여부" +msgstr "" +"비밀번호 변경 후에 ldap_user_shadow_last_change 속성을 최신화 할지 여부" -#: src/config/SSSDConfig/sssdoptions.py:516 +#: src/config/SSSDConfig/sssdoptions.py:522 msgid "Base DN for sudo rules lookups" msgstr "sudo 규칙 검색의 기본 DN" -#: src/config/SSSDConfig/sssdoptions.py:517 +#: src/config/SSSDConfig/sssdoptions.py:523 msgid "Automatic full refresh period" msgstr "자동 전체 새로 고침 기간" -#: src/config/SSSDConfig/sssdoptions.py:518 +#: src/config/SSSDConfig/sssdoptions.py:524 msgid "Automatic smart refresh period" msgstr "자동 스마트 새로 고침 기간" -#: src/config/SSSDConfig/sssdoptions.py:519 +#: src/config/SSSDConfig/sssdoptions.py:525 msgid "Smart and full refresh random offset" msgstr "스마트 및 전체 새로 고침 임의 오프셋" -#: src/config/SSSDConfig/sssdoptions.py:520 +#: src/config/SSSDConfig/sssdoptions.py:526 msgid "Whether to filter rules by hostname, IP addresses and network" msgstr "호스트 이름, IP 주소 및 네트워크로 규칙을 필터링할지 여부" -#: src/config/SSSDConfig/sssdoptions.py:521 +#: src/config/SSSDConfig/sssdoptions.py:527 msgid "" "Hostnames and/or fully qualified domain names of this machine to filter sudo " "rules" @@ -1733,189 +1788,190 @@ msgstr "" "sudo 규칙을 필터링하기 위한 이 시스템의 호스트 이름 및/또는 정규화된 도메인 " "이름" -#: src/config/SSSDConfig/sssdoptions.py:522 +#: src/config/SSSDConfig/sssdoptions.py:528 msgid "IPv4 or IPv6 addresses or network of this machine to filter sudo rules" -msgstr "sudo 규칙을 필터링하기 위한 이 시스템의 IPv4 또는 IPv6 주소 또는 네트워크" +msgstr "" +"sudo 규칙을 필터링하기 위한 이 시스템의 IPv4 또는 IPv6 주소 또는 네트워크" -#: src/config/SSSDConfig/sssdoptions.py:523 +#: src/config/SSSDConfig/sssdoptions.py:529 msgid "Whether to include rules that contains netgroup in host attribute" msgstr "호스트 속성에 netgroup을 포함하는 규칙을 포함할지 여부" -#: src/config/SSSDConfig/sssdoptions.py:524 +#: src/config/SSSDConfig/sssdoptions.py:530 msgid "" "Whether to include rules that contains regular expression in host attribute" msgstr "호스트 속성에 정규 표현식을 포함하는 규칙을 포함할지 여부" -#: src/config/SSSDConfig/sssdoptions.py:525 +#: src/config/SSSDConfig/sssdoptions.py:531 msgid "Object class for sudo rules" msgstr "sudo 규칙의 오브젝트 클래스" -#: src/config/SSSDConfig/sssdoptions.py:526 +#: src/config/SSSDConfig/sssdoptions.py:532 msgid "Name of attribute that is used as object class for sudo rules" msgstr "sudo 규칙의 오브젝트 클래스로 사용되는 속성의 이름" -#: src/config/SSSDConfig/sssdoptions.py:527 +#: src/config/SSSDConfig/sssdoptions.py:533 msgid "Sudo rule name" msgstr "sudo 규칙 이름" -#: src/config/SSSDConfig/sssdoptions.py:528 +#: src/config/SSSDConfig/sssdoptions.py:534 msgid "Sudo rule command attribute" msgstr "sudo 규칙 명령 속성" -#: src/config/SSSDConfig/sssdoptions.py:529 +#: src/config/SSSDConfig/sssdoptions.py:535 msgid "Sudo rule host attribute" msgstr "sudo 규칙 호스트 속성" -#: src/config/SSSDConfig/sssdoptions.py:530 +#: src/config/SSSDConfig/sssdoptions.py:536 msgid "Sudo rule user attribute" msgstr "sudo 규칙 사용자 속성" -#: src/config/SSSDConfig/sssdoptions.py:531 +#: src/config/SSSDConfig/sssdoptions.py:537 msgid "Sudo rule option attribute" msgstr "sudo 규칙 옵션 속성" -#: src/config/SSSDConfig/sssdoptions.py:532 +#: src/config/SSSDConfig/sssdoptions.py:538 msgid "Sudo rule runas attribute" msgstr "sudo 규칙 runas 속성" -#: src/config/SSSDConfig/sssdoptions.py:533 +#: src/config/SSSDConfig/sssdoptions.py:539 msgid "Sudo rule runasuser attribute" msgstr "sudo 규칙 runasuser 속성" -#: src/config/SSSDConfig/sssdoptions.py:534 +#: src/config/SSSDConfig/sssdoptions.py:540 msgid "Sudo rule runasgroup attribute" msgstr "sudo 규칙 runasgroup 속성" -#: src/config/SSSDConfig/sssdoptions.py:535 +#: src/config/SSSDConfig/sssdoptions.py:541 msgid "Sudo rule notbefore attribute" msgstr "sudo 규칙 notfore 속성" -#: src/config/SSSDConfig/sssdoptions.py:536 +#: src/config/SSSDConfig/sssdoptions.py:542 msgid "Sudo rule notafter attribute" msgstr "sudo 규칙 notafter 속성" -#: src/config/SSSDConfig/sssdoptions.py:537 +#: src/config/SSSDConfig/sssdoptions.py:543 msgid "Sudo rule order attribute" msgstr "sudo 규칙 순서 속성" -#: src/config/SSSDConfig/sssdoptions.py:540 +#: src/config/SSSDConfig/sssdoptions.py:546 msgid "Object class for automounter maps" msgstr "automounter 맵의 오브젝트 클래스" -#: src/config/SSSDConfig/sssdoptions.py:541 +#: src/config/SSSDConfig/sssdoptions.py:547 msgid "Automounter map name attribute" msgstr "automounter 맵 이름 속성" -#: src/config/SSSDConfig/sssdoptions.py:542 +#: src/config/SSSDConfig/sssdoptions.py:548 msgid "Object class for automounter map entries" msgstr "automounter 맵 항목의 오브젝트 클래스" -#: src/config/SSSDConfig/sssdoptions.py:543 +#: src/config/SSSDConfig/sssdoptions.py:549 msgid "Automounter map entry key attribute" msgstr "automounter 맵 항목 키 속성" -#: src/config/SSSDConfig/sssdoptions.py:544 +#: src/config/SSSDConfig/sssdoptions.py:550 msgid "Automounter map entry value attribute" msgstr "automounter 맵 항목 값 속성" -#: src/config/SSSDConfig/sssdoptions.py:545 +#: src/config/SSSDConfig/sssdoptions.py:551 msgid "Base DN for automounter map lookups" msgstr "automounter 맵 검색의 기본 DN" -#: src/config/SSSDConfig/sssdoptions.py:546 +#: src/config/SSSDConfig/sssdoptions.py:552 msgid "The name of the automount master map in LDAP." msgstr "LDAP의 automounter 마스터 맵의 이름입니다." -#: src/config/SSSDConfig/sssdoptions.py:549 +#: src/config/SSSDConfig/sssdoptions.py:555 msgid "Base DN for IP hosts lookups" msgstr "IP 호스트 검색의 기본 DN" -#: src/config/SSSDConfig/sssdoptions.py:550 +#: src/config/SSSDConfig/sssdoptions.py:556 msgid "Object class for IP hosts" msgstr "IP 호스트용 오브젝트 클래스" -#: src/config/SSSDConfig/sssdoptions.py:551 +#: src/config/SSSDConfig/sssdoptions.py:557 msgid "IP host name attribute" msgstr "IP 호스트 이름 속성" -#: src/config/SSSDConfig/sssdoptions.py:552 +#: src/config/SSSDConfig/sssdoptions.py:558 msgid "IP host number (address) attribute" msgstr "IP 호스트 번호(address) 속성" -#: src/config/SSSDConfig/sssdoptions.py:553 +#: src/config/SSSDConfig/sssdoptions.py:559 msgid "IP host entryUSN attribute" msgstr "IP 호스트 항목USN 속성" -#: src/config/SSSDConfig/sssdoptions.py:554 +#: src/config/SSSDConfig/sssdoptions.py:560 msgid "Base DN for IP networks lookups" msgstr "IP 네트워크 검색의 기본 DN" -#: src/config/SSSDConfig/sssdoptions.py:555 +#: src/config/SSSDConfig/sssdoptions.py:561 msgid "Object class for IP networks" msgstr "IP 네트워크의 오브젝트 클래스" -#: src/config/SSSDConfig/sssdoptions.py:556 +#: src/config/SSSDConfig/sssdoptions.py:562 msgid "IP network name attribute" msgstr "IP 네트워크 이름 속성" -#: src/config/SSSDConfig/sssdoptions.py:557 +#: src/config/SSSDConfig/sssdoptions.py:563 msgid "IP network number (address) attribute" msgstr "IP 네트워크 번호(address) 속성" -#: src/config/SSSDConfig/sssdoptions.py:558 +#: src/config/SSSDConfig/sssdoptions.py:564 msgid "IP network entryUSN attribute" msgstr "IP 네트워크 항목USN 속성" -#: src/config/SSSDConfig/sssdoptions.py:561 +#: src/config/SSSDConfig/sssdoptions.py:567 msgid "Comma separated list of allowed users" msgstr "쉼표로 구분된 허용된 사용자 목록" -#: src/config/SSSDConfig/sssdoptions.py:562 +#: src/config/SSSDConfig/sssdoptions.py:568 msgid "Comma separated list of prohibited users" msgstr "쉼표로 구분된 금지된 사용자 목록" -#: src/config/SSSDConfig/sssdoptions.py:563 +#: src/config/SSSDConfig/sssdoptions.py:569 msgid "" "Comma separated list of groups that are allowed to log in. This applies only " "to groups within this SSSD domain. Local groups are not evaluated." msgstr "" -"로그인할 수 있는 쉼표로 구분된 그룹 목록입니다. 이는 이 SSSD 도메인 내의 " -"그룹에만 적용됩니다. 로컬 그룹은 평가되지 않습니다." +"로그인할 수 있는 쉼표로 구분된 그룹 목록입니다. 이는 이 SSSD 도메인 내의 그룹" +"에만 적용됩니다. 로컬 그룹은 평가되지 않습니다." -#: src/config/SSSDConfig/sssdoptions.py:565 +#: src/config/SSSDConfig/sssdoptions.py:571 msgid "" "Comma separated list of groups that are explicitly denied access. This " "applies only to groups within this SSSD domain. Local groups are not " "evaluated." msgstr "" -"명시적으로 액세스가 거부된 그룹 목록입니다. 이는 이 SSSD 도메인 내의 " -"그룹에만 적용됩니다. 로컬 그룹은 평가되지 않습니다." +"명시적으로 액세스가 거부된 그룹 목록입니다. 이는 이 SSSD 도메인 내의 그룹에" +"만 적용됩니다. 로컬 그룹은 평가되지 않습니다." -#: src/config/SSSDConfig/sssdoptions.py:569 +#: src/config/SSSDConfig/sssdoptions.py:575 msgid "The number of preforked proxy children." msgstr "미리 정렬된 프락시 하위 항목 수입니다." -#: src/config/SSSDConfig/sssdoptions.py:572 +#: src/config/SSSDConfig/sssdoptions.py:578 msgid "The name of the NSS library to use" msgstr "사용할 NSS 라이브러리의 이름" -#: src/config/SSSDConfig/sssdoptions.py:573 +#: src/config/SSSDConfig/sssdoptions.py:579 msgid "The name of the NSS library to use for hosts and networks lookups" msgstr "호스트 및 네트워크 검색에 사용할 NSS 라이브러리의 이름" -#: src/config/SSSDConfig/sssdoptions.py:574 +#: src/config/SSSDConfig/sssdoptions.py:580 msgid "Whether to look up canonical group name from cache if possible" msgstr "가능한 경우 캐쉬에서 정식 그룹 이름을 검색할지 여부" -#: src/config/SSSDConfig/sssdoptions.py:577 +#: src/config/SSSDConfig/sssdoptions.py:583 msgid "PAM stack to use" msgstr "사용할 PAM 스택" -#: src/config/SSSDConfig/sssdoptions.py:580 +#: src/config/SSSDConfig/sssdoptions.py:586 msgid "Path of passwd file sources." msgstr "passwd 파일 소스 경로입니다." -#: src/config/SSSDConfig/sssdoptions.py:581 +#: src/config/SSSDConfig/sssdoptions.py:587 msgid "Path of group file sources." msgstr "그룹 파일 소스의 경로입니다." @@ -1946,169 +2002,174 @@ msgstr "" msgid "Option -i|--interactive is not allowed together with -D|--daemon\n" msgstr "옵션 -i|--interactive는 -D|--daemon과 함께 사용할 수 없습니다.\n" -#: src/monitor/monitor.c:1836 +#: src/monitor/monitor.c:1838 msgid "Failed to get initial capabilities\n" msgstr "초기 기능을 가져오는 데 실패함\n" -#: src/monitor/monitor.c:1847 +#: src/monitor/monitor.c:1849 msgid "Non-root service user support isn't built. Can't run under %" msgstr "" "비-root 사용자 서비스 사용자 지원이 제작되지 않았습니다. % 아래로 실행 할 수 " "없습니다" -#: src/monitor/monitor.c:1864 +#: src/monitor/monitor.c:1866 #, c-format msgid "Can't read config: '%s'\n" msgstr "환경설정을 읽을 수 없습니다: '%s'\n" -#: src/monitor/monitor.c:1876 -#, c-format -msgid "Failed to boostrap SSSD 'monitor' process: %s" +#: src/monitor/monitor.c:1878 +#, fuzzy, c-format +msgid "Failed to bootstrap SSSD 'monitor' process: %s" msgstr "SSSD 'monitor' 부트스트랩에 실패했습니다: %s" -#: src/monitor/monitor.c:1971 +#: src/monitor/monitor.c:1973 msgid "Out of memory\n" msgstr "메모리 부족\n" -#: src/providers/krb5/krb5_child.c:4221 +#: src/providers/krb5/krb5_child.c:4316 msgid "Use anonymous PKINIT to request FAST armor ticket" msgstr "익명의 PKINIT를 사용하여 FAST 강화된 티켓을 요청합니다" -#: src/providers/krb5/krb5_child.c:4223 +#: src/providers/krb5/krb5_child.c:4318 msgid "Kerberos realm to use" msgstr "사용할 Kerberos 영역" -#: src/providers/krb5/krb5_child.c:4225 +#: src/providers/krb5/krb5_child.c:4320 msgid "Requested lifetime of the ticket" msgstr "티켓의 요청된 수명" -#: src/providers/krb5/krb5_child.c:4227 +#: src/providers/krb5/krb5_child.c:4322 msgid "Requested renewable lifetime of the ticket" msgstr "티켓의 요청된 재생 가능 수명" -#: src/providers/krb5/krb5_child.c:4229 +#: src/providers/krb5/krb5_child.c:4324 msgid "FAST options ('never', 'try', 'demand')" msgstr "FAST 옵션 ('never', 'try', 'demand')" -#: src/providers/krb5/krb5_child.c:4232 +#: src/providers/krb5/krb5_child.c:4327 msgid "Specifies the server principal to use for FAST" msgstr "FAST에 사용할 서버 주체를 지정" -#: src/providers/krb5/krb5_child.c:4234 +#: src/providers/krb5/krb5_child.c:4329 msgid "Requests canonicalization of the principal name" msgstr "주체 이름의 정규화 요청" -#: src/providers/krb5/krb5_child.c:4236 +#: src/providers/krb5/krb5_child.c:4331 msgid "Use custom version of krb5_get_init_creds_password" msgstr "krb5_get_init_creds_password의 사용자 지정 버전 사용" -#: src/providers/krb5/krb5_child.c:4238 +#: src/providers/krb5/krb5_child.c:4333 msgid "Check PAC flags" msgstr "PAC 플래그 점검" -#: src/providers/data_provider_be.c:790 +#: src/providers/krb5/krb5_child.c:4335 +msgid "Set environment variable (KEY=VALUE)" +msgstr "" + +#: src/providers/data_provider_be.c:786 msgid "Domain of the information provider (mandatory)" msgstr "정보 공급자의 도메인 (필수)" -#: src/sss_client/common.c:1165 +#: src/sss_client/common.c:1208 msgid "Socket has wrong ownership or permissions." msgstr "소켓이 잘못된 소유권이나 권한을 갖습니다." -#: src/sss_client/common.c:1168 +#: src/sss_client/common.c:1211 msgid "Unexpected format of the server credential message." msgstr "서버 인증 정보 메시지의 예기치 않은 형식입니다." -#: src/sss_client/common.c:1171 +#: src/sss_client/common.c:1214 msgid "SSSD is not run by trusted user." msgstr "SSSD는 신뢰하는 사용자에 의해 동작하지 않습니다." -#: src/sss_client/common.c:1174 +#: src/sss_client/common.c:1217 msgid "SSSD socket does not exist." msgstr "SSSD 소켓이 존재하지 않습니다." -#: src/sss_client/common.c:1177 +#: src/sss_client/common.c:1220 msgid "Cannot get stat of SSSD socket." msgstr "SSSD 소켓 통계를 가져올 수 없습니다." -#: src/sss_client/common.c:1182 +#: src/sss_client/common.c:1225 msgid "An error occurred, but no description can be found." msgstr "오류가 발생했지만 설명을 찾을 수 없습니다." -#: src/sss_client/common.c:1188 +#: src/sss_client/common.c:1231 msgid "Unexpected error while looking for an error description" msgstr "오류 설명을 찾는 동안 예기치 않은 오류 발생" -#: src/sss_client/pam_sss.c:74 +#: src/sss_client/pam_sss.c:135 msgid "Permission denied. " msgstr "권한이 거부되었습니다. " -#: src/sss_client/pam_sss.c:75 src/sss_client/pam_sss.c:843 -#: src/sss_client/pam_sss.c:854 +#: src/sss_client/pam_sss.c:136 src/sss_client/pam_sss.c:921 +#: src/sss_client/pam_sss.c:932 msgid "Server message: " msgstr "서버 메시지: " -#: src/sss_client/pam_sss.c:76 +#: src/sss_client/pam_sss.c:137 msgid "" "Kerberos TGT will not be granted upon login, user experience will be " "affected." -msgstr "커버러스 TGT는 로그인 시 허용되지 않으며, 사용자 환경에 영향을 미칩니다." +msgstr "" +"커버러스 TGT는 로그인 시 허용되지 않으며, 사용자 환경에 영향을 미칩니다." -#: src/sss_client/pam_sss.c:77 +#: src/sss_client/pam_sss.c:138 msgid "Enter PIN:" msgstr "PIN 입력:" -#: src/sss_client/pam_sss.c:320 +#: src/sss_client/pam_sss.c:385 msgid "Passwords do not match" msgstr "암호가 일치하지 않습니다" -#: src/sss_client/pam_sss.c:508 +#: src/sss_client/pam_sss.c:584 msgid "Password reset by root is not supported." msgstr "root로 재설정한 암호는 지원되지 않습니다." -#: src/sss_client/pam_sss.c:549 +#: src/sss_client/pam_sss.c:625 msgid "Authenticated with cached credentials" msgstr "캐쉬된 인증 정보로 인증됨" -#: src/sss_client/pam_sss.c:550 +#: src/sss_client/pam_sss.c:626 msgid ", your cached password will expire at: " msgstr ", 당신의 캐쉬된 비밀번호는 다음에 만료됩니다.: " -#: src/sss_client/pam_sss.c:580 +#: src/sss_client/pam_sss.c:656 #, c-format msgid "Your password has expired. You have %1$d grace login(s) remaining." msgstr "암호가 만료되었습니다. %1$d 유예 로그인이 남아 있습니다." -#: src/sss_client/pam_sss.c:630 +#: src/sss_client/pam_sss.c:706 #, c-format msgid "Your password will expire in %1$d %2$s." msgstr "암호는 %1$d %2$s에 만료됩니다." -#: src/sss_client/pam_sss.c:633 +#: src/sss_client/pam_sss.c:709 #, c-format msgid "Your password has expired." msgstr "당신의 비밀번호가 만료되었습니다." -#: src/sss_client/pam_sss.c:684 +#: src/sss_client/pam_sss.c:760 msgid "Authentication is denied until: " msgstr "인증은 다음 기간까지 거부됩니다. " -#: src/sss_client/pam_sss.c:705 +#: src/sss_client/pam_sss.c:781 msgid "System is offline, password change not possible" msgstr "시스템이 오프라인 상태이며 암호가 변경될 수 없습니다" -#: src/sss_client/pam_sss.c:720 +#: src/sss_client/pam_sss.c:796 msgid "" "After changing the OTP password, you need to log out and back in order to " "acquire a ticket" msgstr "" -"OTP 비밀번호를 변경한 후, 티켓을 받으려면 로그아웃한 후 다시 로그인해야 " -"합니다" +"OTP 비밀번호를 변경한 후, 티켓을 받으려면 로그아웃한 후 다시 로그인해야 합니" +"다" -#: src/sss_client/pam_sss.c:735 +#: src/sss_client/pam_sss.c:813 msgid "PIN locked" msgstr "PIN 잠금" -#: src/sss_client/pam_sss.c:750 +#: src/sss_client/pam_sss.c:828 msgid "" "No Kerberos TGT granted as the server does not support this method. Your " "single-sign on(SSO) experience will be affected." @@ -2116,61 +2177,65 @@ msgstr "" "서버가 이와 같은 방식을 지원하지 않으므로 커버러스 TGT가 허용되지 않습니다. " "통합인증(SSO) 환경이 영향을 받습니다." -#: src/sss_client/pam_sss.c:840 src/sss_client/pam_sss.c:853 +#: src/sss_client/pam_sss.c:918 src/sss_client/pam_sss.c:931 msgid "Password change failed. " msgstr "비밀번호 변경에 실패함. " -#: src/sss_client/pam_sss.c:1859 -#, c-format -msgid "Authenticate at %1$s and press ENTER." +#: src/sss_client/pam_sss.c:2028 +#, fuzzy, c-format +msgid "Authenticate at \"%1$s\"." msgstr "%1$s에 인증하고 ENTER를 누릅니다." -#: src/sss_client/pam_sss.c:1862 -#, c-format -msgid "Authenticate with PIN %1$s at %2$s and press ENTER." +#: src/sss_client/pam_sss.c:2031 +#, fuzzy, c-format +msgid "Authenticate with PIN \"%1$s\" at \"%2$s\"." msgstr "PIN %1$s(%2$s에서)으로 인증하고 ENTER를 누릅니다." -#: src/sss_client/pam_sss.c:2281 +#: src/sss_client/pam_sss.c:2470 msgid "Please (re)insert (different) Smartcard" msgstr "다른 스마트카드를 (다시)입력해 주세요" -#: src/sss_client/pam_sss.c:2482 +#: src/sss_client/pam_sss.c:2700 msgid "New Password: " msgstr "신규 비밀번호: " -#: src/sss_client/pam_sss.c:2483 +#: src/sss_client/pam_sss.c:2701 msgid "Reenter new Password: " msgstr "신규 비밀번호 재입력: " -#: src/sss_client/pam_sss.c:2676 src/sss_client/pam_sss.c:2679 +#: src/sss_client/pam_sss.c:2890 +msgid "Press ENTER to continue." +msgstr "" + +#: src/sss_client/pam_sss.c:2913 src/sss_client/pam_sss.c:2916 msgid "First Factor: " msgstr "첫 번째 요인: " -#: src/sss_client/pam_sss.c:2677 src/sss_client/pam_sss.c:2851 +#: src/sss_client/pam_sss.c:2914 src/sss_client/pam_sss.c:3088 msgid "Second Factor (optional): " msgstr "두 번째 요인(선택 사항): " -#: src/sss_client/pam_sss.c:2680 src/sss_client/pam_sss.c:2855 +#: src/sss_client/pam_sss.c:2917 src/sss_client/pam_sss.c:3092 msgid "Second Factor: " msgstr "두 번째 요인: " -#: src/sss_client/pam_sss.c:2684 +#: src/sss_client/pam_sss.c:2921 msgid "Insert your passkey device, then press ENTER." msgstr "자신의 패스키 장치를 넣고, 그런 후에 Enter를 눌러주세요." -#: src/sss_client/pam_sss.c:2688 src/sss_client/pam_sss.c:2696 +#: src/sss_client/pam_sss.c:2925 src/sss_client/pam_sss.c:2933 msgid "Password: " msgstr "비밀번호: " -#: src/sss_client/pam_sss.c:2850 src/sss_client/pam_sss.c:2854 +#: src/sss_client/pam_sss.c:3087 src/sss_client/pam_sss.c:3091 msgid "First Factor (Current Password): " msgstr "첫 번째 요인 (현재 비밀번호): " -#: src/sss_client/pam_sss.c:2874 +#: src/sss_client/pam_sss.c:3111 msgid "Current Password: " msgstr "현재 비밀번호: " -#: src/sss_client/pam_sss.c:3248 +#: src/sss_client/pam_sss.c:3485 msgid "Password expired. Change your password now." msgstr "비밀번호가 만료되었습니다. 지금 비밀번호를 변경하세요." @@ -2210,8 +2275,8 @@ msgid "" msgstr "" "\n" "******************************************************************************\n" -"자신의 시스템이 더 이상 사용하지 않는 도구sss_ssh_knownhostsproxy를 " -"사용하도록 구성되었습니다.\n" +"자신의 시스템이 더 이상 사용하지 않는 도구sss_ssh_knownhostsproxy를 사용하도" +"록 구성되었습니다.\n" "sss_ssh_knownhosts(1) 설명서 부분을 읽고 해당 교체에 대해 알아보세요.\n" "******************************************************************************\n" "\n" @@ -2613,9 +2678,9 @@ msgstr "객체를 출력하는 데 실패함: %s\n" #: src/tools/sssctl/sssctl_cache.c:835 src/tools/sssctl/sssctl_cache.c:918 #: src/tools/sssctl/sssctl_cache.c:950 src/tools/sssctl/sssctl_cache.c:956 #: src/tools/sssctl/sssctl_cache.c:1010 src/tools/sssctl/sssctl_cache.c:1034 -#: src/tools/sssctl/sssctl_cache.c:1085 src/tools/sssctl/sssctl_cache.c:1194 -#: src/tools/sssctl/sssctl_cache.c:1229 src/tools/sssctl/sssctl_cache.c:1235 -#: src/tools/sssctl/sssctl_cache.c:1244 +#: src/tools/sssctl/sssctl_cache.c:1085 src/tools/sssctl/sssctl_cache.c:1195 +#: src/tools/sssctl/sssctl_cache.c:1230 src/tools/sssctl/sssctl_cache.c:1236 +#: src/tools/sssctl/sssctl_cache.c:1245 msgid "talloc failed\n" msgstr "talloc이 실패함\n" @@ -2673,8 +2738,8 @@ msgid "" "The GPO path was not yet stored in cache. Please remove files manually from " "[%s]\n" msgstr "" -"GPO 경로가 캐쉬에서 아직 저장되지 않았습니다. [%s]에서 수동으로 파일을 " -"제거하세요\n" +"GPO 경로가 캐쉬에서 아직 저장되지 않았습니다. [%s]에서 수동으로 파일을 제거하" +"세요\n" #: src/tools/sssctl/sssctl_cache.c:1062 src/tools/sssctl/sssctl_cache.c:1068 #, c-format @@ -2691,25 +2756,25 @@ msgstr "캐쉬된 GPO 경로 [%s] 는 [%s] 에 없으므로, 무시합니다.\n" msgid "Unable to remove downloaded GPO files: %s\n" msgstr "내려받은 GPO 파일을 제거 할 수 없음: %s\n" -#: src/tools/sssctl/sssctl_cache.c:1165 +#: src/tools/sssctl/sssctl_cache.c:1166 #, c-format msgid "Failed to fetch cache entry: %s\n" msgstr "캐쉬 항목을 가져오는 데 실패함: %s\n" -#: src/tools/sssctl/sssctl_cache.c:1170 +#: src/tools/sssctl/sssctl_cache.c:1171 msgid "Could not determine object domain\n" msgstr "객체 도메인을 결정 할 수 없습니다\n" -#: src/tools/sssctl/sssctl_cache.c:1200 +#: src/tools/sssctl/sssctl_cache.c:1201 msgid "Could not find GUID attribute in GPO entry\n" msgstr "GPO 항목에서 GUID 속성을 찾을 수 없습니다\n" -#: src/tools/sssctl/sssctl_cache.c:1206 +#: src/tools/sssctl/sssctl_cache.c:1207 #, c-format msgid "Failed to delete GPO: %s\n" msgstr "GPO를 삭제하는 데 실패함: %s\n" -#: src/tools/sssctl/sssctl_cache.c:1210 +#: src/tools/sssctl/sssctl_cache.c:1211 #, c-format msgid "%s removed from cache\n" msgstr "캐쉬에서 제거된 %s\n" @@ -2800,43 +2865,44 @@ msgid "" "where the main config file is located. For example if the config is set to " "\"/my/path/sssd.conf\", the snippet dir \"/my/path/conf.d\" is used)" msgstr "" -"기본이 아닌 스니펫 디렉토리를 지정합니다(기본값은 기본 설정 파일이 있는 " -"동일한 위치를 검색하는 것입니다. 예를 들어 구성이 \"/my/path/sssd.conf\"로 " -"설정된 경우 스니펫 디렉토리 \"/my/path/conf.d\"가 사용됨)" +"기본이 아닌 스니펫 디렉토리를 지정합니다(기본값은 기본 설정 파일이 있는 동일" +"한 위치를 검색하는 것입니다. 예를 들어 구성이 \"/my/path/sssd.conf\"로 설정" +"된 경우 스니펫 디렉토리 \"/my/path/conf.d\"가 사용됨)" -#: src/tools/sssctl/sssctl_config.c:114 +#: src/tools/sssctl/sssctl_config.c:126 #, c-format msgid "File %1$s does not exist.\n" msgstr "파일 %1$s이 존재하지 않음.\n" -#: src/tools/sssctl/sssctl_config.c:115 +#: src/tools/sssctl/sssctl_config.c:127 msgid "There is no configuration.\n" msgstr "구성이 없습니다.\n" -#: src/tools/sssctl/sssctl_config.c:120 +#: src/tools/sssctl/sssctl_config.c:132 #, c-format msgid "Configuration validation failed: %s\n" msgstr "구성 검증이 실패함: %s\n" -#: src/tools/sssctl/sssctl_config.c:121 +#: src/tools/sssctl/sssctl_config.c:133 msgid "Run with high debug level to see details.\n" msgstr "높은 디버그 수준으로 실행하여 자세히 보세요.\n" -#: src/tools/sssctl/sssctl_config.c:130 -msgid "Failed to run validators" +#: src/tools/sssctl/sssctl_config.c:142 +#, fuzzy +msgid "Failed to run validators\n" msgstr "검증기를 실행하지 못했습니다" -#: src/tools/sssctl/sssctl_config.c:134 +#: src/tools/sssctl/sssctl_config.c:146 #, c-format msgid "Issues identified by validators: %zu\n" msgstr "검증기로 식별된 문제: %zu\n" -#: src/tools/sssctl/sssctl_config.c:145 +#: src/tools/sssctl/sssctl_config.c:157 #, c-format msgid "Messages generated during configuration merging: %zu\n" msgstr "구성 병합 중에 생성된 메시지: %zu\n" -#: src/tools/sssctl/sssctl_config.c:158 +#: src/tools/sssctl/sssctl_config.c:170 #, c-format msgid "Used configuration snippet files: %zu\n" msgstr "사용된 구성 스니펫 파일: %zu\n" @@ -3135,7 +3201,8 @@ msgstr "설정할 디버그 수준 지정" #: src/tools/sssctl/sssctl_logs.c:593 msgid "ERROR: Tevent chain ID support missing, log analyzer is unsupported.\n" -msgstr "오류: T이벤트 체인 ID 지원이 누락되었으며, 로그 분석이 지원되지 않습니다.\n" +msgstr "" +"오류: T이벤트 체인 ID 지원이 누락되었으며, 로그 분석이 지원되지 않습니다.\n" #: src/tools/sssctl/sssctl_user_checks.c:121 msgid "SSSD InfoPipe user lookup result:\n" diff --git a/po/lv.po b/po/lv.po index 009a997371c..d4e02ea53b9 100644 --- a/po/lv.po +++ b/po/lv.po @@ -6,8 +6,8 @@ msgid "" msgstr "" "Project-Id-Version: PACKAGE VERSION\n" "Report-Msgid-Bugs-To: sssd-devel@lists.fedorahosted.org\n" -"POT-Creation-Date: 2026-01-14 14:57+0000\n" -"PO-Revision-Date: 2026-04-23 16:47+0000\n" +"POT-Creation-Date: 2026-10-02 15:57+0000\n" +"PO-Revision-Date: 2026-10-05 17:18+0000\n" "Last-Translator: Anonymous \n" "Language-Team: Latvian \n" @@ -17,50 +17,50 @@ msgstr "" "Content-Transfer-Encoding: 8bit\n" "Plural-Forms: nplurals=3; plural=(n % 10 == 0 || n % 100 >= 11 && n % 100 <= " "19) ? 0 : ((n % 10 == 1 && n % 100 != 11) ? 1 : 2);\n" -"X-Generator: Weblate 5.17\n" +"X-Generator: Weblate 2026.10\n" -#: src/config/SSSDConfig/sssdoptions.py:20 -#: src/config/SSSDConfig/sssdoptions.py:21 +#: src/config/SSSDConfig/sssdoptions.py:16 +#: src/config/SSSDConfig/sssdoptions.py:17 msgid "Set the verbosity of the debug logging" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:22 +#: src/config/SSSDConfig/sssdoptions.py:18 msgid "Include timestamps in debug logs" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:23 +#: src/config/SSSDConfig/sssdoptions.py:19 msgid "Include microseconds in timestamps in debug logs" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:24 +#: src/config/SSSDConfig/sssdoptions.py:20 msgid "Enable/disable debug backtrace" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:25 +#: src/config/SSSDConfig/sssdoptions.py:21 msgid "Watchdog timeout before restarting service" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:26 +#: src/config/SSSDConfig/sssdoptions.py:22 msgid "Command to start service" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:27 +#: src/config/SSSDConfig/sssdoptions.py:23 msgid "The number of file descriptors that may be opened by this responder" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:28 +#: src/config/SSSDConfig/sssdoptions.py:24 msgid "Idle time before automatic disconnection of a client" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:29 +#: src/config/SSSDConfig/sssdoptions.py:25 msgid "Idle time before automatic shutdown of the responder" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:30 +#: src/config/SSSDConfig/sssdoptions.py:26 msgid "Always query all the caches before querying the Data Providers" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:31 +#: src/config/SSSDConfig/sssdoptions.py:27 msgid "" "When SSSD switches to offline mode the amount of time before it tries to go " "back online will increase based upon the time spent disconnected. This value " @@ -68,63 +68,63 @@ msgid "" "random_offset." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:36 +#: src/config/SSSDConfig/sssdoptions.py:32 msgid "SSSD Services to start" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:37 +#: src/config/SSSDConfig/sssdoptions.py:33 msgid "SSSD Domains to start" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:38 +#: src/config/SSSDConfig/sssdoptions.py:34 msgid "Regex to parse username and domain" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:39 +#: src/config/SSSDConfig/sssdoptions.py:35 msgid "Printf-compatible format for displaying fully-qualified names" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:40 +#: src/config/SSSDConfig/sssdoptions.py:36 msgid "" "Directory on the filesystem where SSSD should store Kerberos replay cache " "files." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:41 +#: src/config/SSSDConfig/sssdoptions.py:37 msgid "Domain to add to names without a domain component." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:42 +#: src/config/SSSDConfig/sssdoptions.py:38 msgid "The user to drop privileges to" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:43 +#: src/config/SSSDConfig/sssdoptions.py:39 msgid "Tune certificate verification" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:44 +#: src/config/SSSDConfig/sssdoptions.py:40 msgid "All spaces in group or user names will be replaced with this character" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:45 +#: src/config/SSSDConfig/sssdoptions.py:41 msgid "Tune sssd to honor or ignore netlink state changes" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:46 +#: src/config/SSSDConfig/sssdoptions.py:42 msgid "Enable or disable the implicit files domain" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:47 +#: src/config/SSSDConfig/sssdoptions.py:43 msgid "A specific order of the domains to be looked up" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:48 +#: src/config/SSSDConfig/sssdoptions.py:44 msgid "" "Controls if SSSD should monitor the state of resolv.conf to identify when it " "needs to update its internal DNS resolver." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:50 +#: src/config/SSSDConfig/sssdoptions.py:46 msgid "" "SSSD monitors the state of resolv.conf to identify when it needs to update " "its internal DNS resolver. By default, we will attempt to use inotify for " @@ -132,393 +132,400 @@ msgid "" "inotify cannot be used." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:53 +#: src/config/SSSDConfig/sssdoptions.py:49 msgid "Run PAC responder automatically for AD and IPA provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:54 +#: src/config/SSSDConfig/sssdoptions.py:50 msgid "Enable or disable core dumps for all SSSD processes." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:55 +#: src/config/SSSDConfig/sssdoptions.py:51 msgid "Tune passkey verification behavior" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:58 +#: src/config/SSSDConfig/sssdoptions.py:54 msgid "Enumeration cache timeout length (seconds)" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:59 +#: src/config/SSSDConfig/sssdoptions.py:55 msgid "Entry cache background update timeout length (seconds)" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:60 -#: src/config/SSSDConfig/sssdoptions.py:125 +#: src/config/SSSDConfig/sssdoptions.py:56 +#: src/config/SSSDConfig/sssdoptions.py:124 msgid "Negative cache timeout length (seconds)" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:61 +#: src/config/SSSDConfig/sssdoptions.py:57 msgid "Users that SSSD should explicitly ignore" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:62 +#: src/config/SSSDConfig/sssdoptions.py:58 msgid "Groups that SSSD should explicitly ignore" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:63 +#: src/config/SSSDConfig/sssdoptions.py:59 msgid "Should filtered users appear in groups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:64 +#: src/config/SSSDConfig/sssdoptions.py:60 msgid "The value of the password field the NSS provider should return" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:65 +#: src/config/SSSDConfig/sssdoptions.py:61 msgid "Override homedir value from the identity provider with this value" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:66 +#: src/config/SSSDConfig/sssdoptions.py:62 msgid "" "Substitute empty homedir value from the identity provider with this value" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:67 +#: src/config/SSSDConfig/sssdoptions.py:63 msgid "Override shell value from the identity provider with this value" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:68 +#: src/config/SSSDConfig/sssdoptions.py:64 msgid "The list of shells users are allowed to log in with" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:69 +#: src/config/SSSDConfig/sssdoptions.py:65 msgid "" "The list of shells that will be vetoed, and replaced with the fallback shell" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:70 +#: src/config/SSSDConfig/sssdoptions.py:66 msgid "" "If a shell stored in central directory is allowed but not available, use " "this fallback" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:71 +#: src/config/SSSDConfig/sssdoptions.py:67 msgid "Shell to use if the provider does not list one" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:72 +#: src/config/SSSDConfig/sssdoptions.py:68 msgid "How long will be in-memory cache records valid" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:74 +#: src/config/SSSDConfig/sssdoptions.py:70 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for passwd requests" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:76 +#: src/config/SSSDConfig/sssdoptions.py:72 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for group requests" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:78 +#: src/config/SSSDConfig/sssdoptions.py:74 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for initgroups requests" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:79 +#: src/config/SSSDConfig/sssdoptions.py:75 msgid "" "The value of this option will be used in the expansion of the " "override_homedir option if the template contains the format string %H." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:81 +#: src/config/SSSDConfig/sssdoptions.py:77 msgid "" "Specifies time in seconds for which the list of subdomains will be " "considered valid." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:83 +#: src/config/SSSDConfig/sssdoptions.py:79 msgid "" "The entry cache can be set to automatically update entries in the background " "if they are requested beyond a percentage of the entry_cache_timeout value " "for the domain." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:88 +#: src/config/SSSDConfig/sssdoptions.py:84 msgid "How long to allow cached logins between online logins (days)" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:89 +#: src/config/SSSDConfig/sssdoptions.py:85 msgid "How many failed logins attempts are allowed when offline" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:91 +#: src/config/SSSDConfig/sssdoptions.py:87 msgid "" "How long (minutes) to deny login after offline_failed_login_attempts has " "been reached" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:92 +#: src/config/SSSDConfig/sssdoptions.py:88 msgid "What kind of messages are displayed to the user during authentication" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:93 +#: src/config/SSSDConfig/sssdoptions.py:89 msgid "Filter PAM responses sent to the pam_sss" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:94 +#: src/config/SSSDConfig/sssdoptions.py:90 msgid "How many seconds to keep identity information cached for PAM requests" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:95 +#: src/config/SSSDConfig/sssdoptions.py:91 msgid "How many days before password expiration a warning should be displayed" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:96 +#: src/config/SSSDConfig/sssdoptions.py:92 msgid "List of trusted uids or user's name" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:97 +#: src/config/SSSDConfig/sssdoptions.py:93 msgid "List of domains accessible even for untrusted users." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:98 +#: src/config/SSSDConfig/sssdoptions.py:94 msgid "Message printed when user account is expired." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:99 +#: src/config/SSSDConfig/sssdoptions.py:95 msgid "Message printed when user account is locked." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:100 +#: src/config/SSSDConfig/sssdoptions.py:96 msgid "Allow certificate based/Smartcard authentication." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:101 +#: src/config/SSSDConfig/sssdoptions.py:97 msgid "Path to certificate database with PKCS#11 modules." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:102 +#: src/config/SSSDConfig/sssdoptions.py:98 msgid "Tune certificate verification for PAM authentication." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:103 +#: src/config/SSSDConfig/sssdoptions.py:99 msgid "How many seconds will pam_sss wait for p11_child to finish" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:104 +#: src/config/SSSDConfig/sssdoptions.py:100 msgid "Which PAM services are permitted to contact application domains" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:105 +#: src/config/SSSDConfig/sssdoptions.py:101 msgid "Allowed services for using smartcards" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:106 +#: src/config/SSSDConfig/sssdoptions.py:102 msgid "Additional timeout to wait for a card if requested" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:107 +#: src/config/SSSDConfig/sssdoptions.py:103 msgid "" "PKCS#11 URI to restrict the selection of devices for Smartcard authentication" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:108 +#: src/config/SSSDConfig/sssdoptions.py:104 msgid "When shall the PAM responder force an initgroups request" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:109 +#: src/config/SSSDConfig/sssdoptions.py:105 msgid "List of PAM services that are allowed to authenticate with GSSAPI." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:110 +#: src/config/SSSDConfig/sssdoptions.py:106 msgid "Whether to match authenticated UPN with target user" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:111 +#: src/config/SSSDConfig/sssdoptions.py:107 msgid "" "List of pairs : that must be enforced " "for PAM access with GSSAPI authentication" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:113 +#: src/config/SSSDConfig/sssdoptions.py:109 +msgid "" +"List of triples :: that assigns " +"additional information from the Kerberos ticket to an authentication " +"indicator." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:112 msgid "Allow passkey device authentication." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:114 +#: src/config/SSSDConfig/sssdoptions.py:113 msgid "How many seconds will pam_sss wait for passkey_child to finish" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:115 +#: src/config/SSSDConfig/sssdoptions.py:114 msgid "Enable debugging in the libfido2 library" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:116 +#: src/config/SSSDConfig/sssdoptions.py:115 msgid "Enable JSON protocol for authentication methods selection." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:119 +#: src/config/SSSDConfig/sssdoptions.py:118 msgid "Whether to evaluate the time-based attributes in sudo rules" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:120 +#: src/config/SSSDConfig/sssdoptions.py:119 msgid "If true, SSSD will switch back to lower-wins ordering logic" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:121 +#: src/config/SSSDConfig/sssdoptions.py:120 msgid "" "Maximum number of rules that can be refreshed at once. If this is exceeded, " "full refresh is performed." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:128 +#: src/config/SSSDConfig/sssdoptions.py:127 msgid "Whether to hash host names and addresses in the known_hosts file" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:129 +#: src/config/SSSDConfig/sssdoptions.py:128 msgid "" "How many seconds to keep a host in the known_hosts file after its host keys " "were requested" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:131 +#: src/config/SSSDConfig/sssdoptions.py:130 msgid "Path to storage of trusted CA certificates" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:132 +#: src/config/SSSDConfig/sssdoptions.py:131 msgid "Allow to generate ssh-keys from certificates" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:133 +#: src/config/SSSDConfig/sssdoptions.py:132 msgid "" "Use the following matching rules to filter the certificates for ssh-key " "generation" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:137 +#: src/config/SSSDConfig/sssdoptions.py:136 msgid "List of UIDs or user names allowed to access the PAC responder" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:138 +#: src/config/SSSDConfig/sssdoptions.py:137 msgid "How long the PAC data is considered valid" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:139 +#: src/config/SSSDConfig/sssdoptions.py:138 msgid "Validate the PAC" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:142 +#: src/config/SSSDConfig/sssdoptions.py:141 msgid "List of user attributes the InfoPipe is allowed to publish" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:145 +#: src/config/SSSDConfig/sssdoptions.py:144 msgid "" "One of the following strings specifying the scope of session recording: none " "- No users are recorded. some - Users/groups specified by users and groups " "options are recorded. all - All users are recorded." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:148 +#: src/config/SSSDConfig/sssdoptions.py:147 msgid "" "A comma-separated list of users which should have session recording enabled. " "Matches user names as returned by NSS. I.e. after the possible space " "replacement, case changes, etc." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:150 +#: src/config/SSSDConfig/sssdoptions.py:149 msgid "" "A comma-separated list of groups, members of which should have session " "recording enabled. Matches group names as returned by NSS. I.e. after the " "possible space replacement, case changes, etc." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:153 +#: src/config/SSSDConfig/sssdoptions.py:152 msgid "" "A comma-separated list of users to be excluded from recording, only when " "scope=all" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:154 +#: src/config/SSSDConfig/sssdoptions.py:153 msgid "" "A comma-separated list of groups, members of which should be excluded from " "recording, only when scope=all. " msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:158 +#: src/config/SSSDConfig/sssdoptions.py:157 msgid "Identity provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:159 +#: src/config/SSSDConfig/sssdoptions.py:158 msgid "Authentication provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:160 +#: src/config/SSSDConfig/sssdoptions.py:159 msgid "Access control provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:161 +#: src/config/SSSDConfig/sssdoptions.py:160 msgid "Password change provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:162 +#: src/config/SSSDConfig/sssdoptions.py:161 msgid "SUDO provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:163 +#: src/config/SSSDConfig/sssdoptions.py:162 msgid "Autofs provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:164 +#: src/config/SSSDConfig/sssdoptions.py:163 msgid "Host identity provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:165 +#: src/config/SSSDConfig/sssdoptions.py:164 msgid "SELinux provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:166 +#: src/config/SSSDConfig/sssdoptions.py:165 msgid "Session management provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:167 +#: src/config/SSSDConfig/sssdoptions.py:166 msgid "Resolver provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:170 +#: src/config/SSSDConfig/sssdoptions.py:169 msgid "Whether the domain is usable by the OS or by applications" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:171 +#: src/config/SSSDConfig/sssdoptions.py:170 msgid "Enable or disable the domain" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:172 +#: src/config/SSSDConfig/sssdoptions.py:171 msgid "Minimum user ID" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:173 +#: src/config/SSSDConfig/sssdoptions.py:172 msgid "Maximum user ID" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:174 +#: src/config/SSSDConfig/sssdoptions.py:173 msgid "Enable enumerating all users/groups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:175 +#: src/config/SSSDConfig/sssdoptions.py:174 msgid "Cache credentials for offline login" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:176 +#: src/config/SSSDConfig/sssdoptions.py:175 msgid "Display users/groups in fully-qualified form" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:177 +#: src/config/SSSDConfig/sssdoptions.py:176 msgid "Don't include group members in group lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:178 +#: src/config/SSSDConfig/sssdoptions.py:177 #: src/config/SSSDConfig/sssdoptions.py:190 #: src/config/SSSDConfig/sssdoptions.py:191 #: src/config/SSSDConfig/sssdoptions.py:192 @@ -529,48 +536,52 @@ msgstr "" msgid "Entry cache timeout length (seconds)" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:179 +#: src/config/SSSDConfig/sssdoptions.py:178 msgid "" "Restrict or prefer a specific address family when performing DNS lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:180 +#: src/config/SSSDConfig/sssdoptions.py:179 msgid "How long to keep cached entries after last successful login (days)" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:181 +#: src/config/SSSDConfig/sssdoptions.py:180 msgid "" "How long should SSSD talk to single DNS server before trying next server " "(miliseconds)" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:183 +#: src/config/SSSDConfig/sssdoptions.py:182 msgid "How long should keep trying to resolve single DNS query (seconds)" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:184 +#: src/config/SSSDConfig/sssdoptions.py:183 msgid "How long to wait for replies from DNS when resolving servers (seconds)" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:185 +#: src/config/SSSDConfig/sssdoptions.py:184 msgid "The domain part of service discovery DNS query" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:186 +#: src/config/SSSDConfig/sssdoptions.py:185 msgid "" "Specifies the interval, in seconds, that SSSD waits before attempting to " "reconnect to the primary server after a successful connection to the backup " "server" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:188 +#: src/config/SSSDConfig/sssdoptions.py:187 msgid "Override GID value from the identity provider with this value" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:189 +#: src/config/SSSDConfig/sssdoptions.py:188 msgid "Treat usernames as case sensitive" msgstr "" +#: src/config/SSSDConfig/sssdoptions.py:189 +msgid "Lookups by ID are expensive or do not work at all" +msgstr "" + #: src/config/SSSDConfig/sssdoptions.py:197 msgid "How often should expired entries be refreshed in background" msgstr "" @@ -790,7 +801,7 @@ msgid "Search base for SUBID ranges" msgstr "" #: src/config/SSSDConfig/sssdoptions.py:259 -#: src/config/SSSDConfig/sssdoptions.py:506 +#: src/config/SSSDConfig/sssdoptions.py:512 msgid "Which rules should be used to evaluate access control" msgstr "" @@ -932,7 +943,7 @@ msgid "Enable DNS sites - location based service discovery" msgstr "" #: src/config/SSSDConfig/sssdoptions.py:301 -#: src/config/SSSDConfig/sssdoptions.py:504 +#: src/config/SSSDConfig/sssdoptions.py:510 msgid "LDAP filter to determine access privileges" msgstr "" @@ -1352,7 +1363,7 @@ msgid "UUID attribute" msgstr "" #: src/config/SSSDConfig/sssdoptions.py:423 -#: src/config/SSSDConfig/sssdoptions.py:464 +#: src/config/SSSDConfig/sssdoptions.py:470 msgid "objectSID attribute" msgstr "" @@ -1476,385 +1487,409 @@ msgstr "" msgid "A list of extra attributes to download along with the user entry" msgstr "" +#: src/config/SSSDConfig/sssdoptions.py:456 +msgid "The object class of an subid entry in LDAP." +msgstr "" + #: src/config/SSSDConfig/sssdoptions.py:457 -msgid "Base DN for group lookups" +msgid "Subordinate user ID count attribute" msgstr "" #: src/config/SSSDConfig/sssdoptions.py:458 -msgid "Objectclass for groups" +msgid "Subordinate group ID count attribute" msgstr "" #: src/config/SSSDConfig/sssdoptions.py:459 -msgid "Group name" +msgid "User ID range start value attribute" msgstr "" #: src/config/SSSDConfig/sssdoptions.py:460 -msgid "Group password" +msgid "Group ID range start value attribute" msgstr "" #: src/config/SSSDConfig/sssdoptions.py:461 +msgid "Owner of an entry" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:463 +msgid "Base DN for group lookups" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:464 +msgid "Objectclass for groups" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:465 +msgid "Group name" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:466 +msgid "Group password" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:467 msgid "GID attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:462 +#: src/config/SSSDConfig/sssdoptions.py:468 msgid "Group member attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:463 +#: src/config/SSSDConfig/sssdoptions.py:469 msgid "Group UUID attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:465 +#: src/config/SSSDConfig/sssdoptions.py:471 msgid "Modification time attribute for groups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:466 +#: src/config/SSSDConfig/sssdoptions.py:472 msgid "Type of the group and other flags" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:467 +#: src/config/SSSDConfig/sssdoptions.py:473 msgid "The LDAP group external member attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:468 +#: src/config/SSSDConfig/sssdoptions.py:474 msgid "Maximum nesting level SSSD will follow" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:469 +#: src/config/SSSDConfig/sssdoptions.py:475 msgid "Filter for group lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:470 +#: src/config/SSSDConfig/sssdoptions.py:476 msgid "Scope of group lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:472 +#: src/config/SSSDConfig/sssdoptions.py:478 msgid "Base DN for netgroup lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:473 +#: src/config/SSSDConfig/sssdoptions.py:479 msgid "Objectclass for netgroups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:474 +#: src/config/SSSDConfig/sssdoptions.py:480 msgid "Netgroup name" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:475 +#: src/config/SSSDConfig/sssdoptions.py:481 msgid "Netgroups members attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:476 +#: src/config/SSSDConfig/sssdoptions.py:482 msgid "Netgroup triple attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:477 +#: src/config/SSSDConfig/sssdoptions.py:483 msgid "Modification time attribute for netgroups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:479 +#: src/config/SSSDConfig/sssdoptions.py:485 msgid "Base DN for service lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:480 +#: src/config/SSSDConfig/sssdoptions.py:486 msgid "Objectclass for services" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:481 +#: src/config/SSSDConfig/sssdoptions.py:487 msgid "Service name attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:482 +#: src/config/SSSDConfig/sssdoptions.py:488 msgid "Service port attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:483 +#: src/config/SSSDConfig/sssdoptions.py:489 msgid "Service protocol attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:485 +#: src/config/SSSDConfig/sssdoptions.py:491 msgid "Lower bound for ID-mapping" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:486 +#: src/config/SSSDConfig/sssdoptions.py:492 msgid "Upper bound for ID-mapping" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:487 +#: src/config/SSSDConfig/sssdoptions.py:493 msgid "Number of IDs for each slice when ID-mapping" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:488 +#: src/config/SSSDConfig/sssdoptions.py:494 msgid "Use autorid-compatible algorithm for ID-mapping" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:489 +#: src/config/SSSDConfig/sssdoptions.py:495 msgid "Name of the default domain for ID-mapping" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:490 +#: src/config/SSSDConfig/sssdoptions.py:496 msgid "SID of the default domain for ID-mapping" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:491 +#: src/config/SSSDConfig/sssdoptions.py:497 msgid "Number of secondary slices" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:493 +#: src/config/SSSDConfig/sssdoptions.py:499 msgid "Whether to use Token-Groups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:494 +#: src/config/SSSDConfig/sssdoptions.py:500 msgid "Set lower boundary for allowed IDs from the LDAP server" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:495 +#: src/config/SSSDConfig/sssdoptions.py:501 msgid "Set upper boundary for allowed IDs from the LDAP server" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:496 +#: src/config/SSSDConfig/sssdoptions.py:502 msgid "DN for ppolicy queries" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:497 +#: src/config/SSSDConfig/sssdoptions.py:503 msgid "How many maximum entries to fetch during a wildcard request" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:498 +#: src/config/SSSDConfig/sssdoptions.py:504 msgid "Set libldap debug level" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:501 +#: src/config/SSSDConfig/sssdoptions.py:507 msgid "Policy to evaluate the password expiration" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:505 +#: src/config/SSSDConfig/sssdoptions.py:511 msgid "Which attributes shall be used to evaluate if an account is expired" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:509 +#: src/config/SSSDConfig/sssdoptions.py:515 msgid "URI of an LDAP server where password changes are allowed" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:510 +#: src/config/SSSDConfig/sssdoptions.py:516 msgid "URI of a backup LDAP server where password changes are allowed" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:511 +#: src/config/SSSDConfig/sssdoptions.py:517 msgid "DNS service name for LDAP password change server" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:512 +#: src/config/SSSDConfig/sssdoptions.py:518 msgid "" "Whether to update the ldap_user_shadow_last_change attribute after a " "password change" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:516 +#: src/config/SSSDConfig/sssdoptions.py:522 msgid "Base DN for sudo rules lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:517 +#: src/config/SSSDConfig/sssdoptions.py:523 msgid "Automatic full refresh period" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:518 +#: src/config/SSSDConfig/sssdoptions.py:524 msgid "Automatic smart refresh period" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:519 +#: src/config/SSSDConfig/sssdoptions.py:525 msgid "Smart and full refresh random offset" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:520 +#: src/config/SSSDConfig/sssdoptions.py:526 msgid "Whether to filter rules by hostname, IP addresses and network" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:521 +#: src/config/SSSDConfig/sssdoptions.py:527 msgid "" "Hostnames and/or fully qualified domain names of this machine to filter sudo " "rules" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:522 +#: src/config/SSSDConfig/sssdoptions.py:528 msgid "IPv4 or IPv6 addresses or network of this machine to filter sudo rules" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:523 +#: src/config/SSSDConfig/sssdoptions.py:529 msgid "Whether to include rules that contains netgroup in host attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:524 +#: src/config/SSSDConfig/sssdoptions.py:530 msgid "" "Whether to include rules that contains regular expression in host attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:525 +#: src/config/SSSDConfig/sssdoptions.py:531 msgid "Object class for sudo rules" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:526 +#: src/config/SSSDConfig/sssdoptions.py:532 msgid "Name of attribute that is used as object class for sudo rules" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:527 +#: src/config/SSSDConfig/sssdoptions.py:533 msgid "Sudo rule name" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:528 +#: src/config/SSSDConfig/sssdoptions.py:534 msgid "Sudo rule command attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:529 +#: src/config/SSSDConfig/sssdoptions.py:535 msgid "Sudo rule host attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:530 +#: src/config/SSSDConfig/sssdoptions.py:536 msgid "Sudo rule user attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:531 +#: src/config/SSSDConfig/sssdoptions.py:537 msgid "Sudo rule option attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:532 +#: src/config/SSSDConfig/sssdoptions.py:538 msgid "Sudo rule runas attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:533 +#: src/config/SSSDConfig/sssdoptions.py:539 msgid "Sudo rule runasuser attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:534 +#: src/config/SSSDConfig/sssdoptions.py:540 msgid "Sudo rule runasgroup attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:535 +#: src/config/SSSDConfig/sssdoptions.py:541 msgid "Sudo rule notbefore attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:536 +#: src/config/SSSDConfig/sssdoptions.py:542 msgid "Sudo rule notafter attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:537 +#: src/config/SSSDConfig/sssdoptions.py:543 msgid "Sudo rule order attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:540 +#: src/config/SSSDConfig/sssdoptions.py:546 msgid "Object class for automounter maps" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:541 +#: src/config/SSSDConfig/sssdoptions.py:547 msgid "Automounter map name attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:542 +#: src/config/SSSDConfig/sssdoptions.py:548 msgid "Object class for automounter map entries" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:543 +#: src/config/SSSDConfig/sssdoptions.py:549 msgid "Automounter map entry key attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:544 +#: src/config/SSSDConfig/sssdoptions.py:550 msgid "Automounter map entry value attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:545 +#: src/config/SSSDConfig/sssdoptions.py:551 msgid "Base DN for automounter map lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:546 +#: src/config/SSSDConfig/sssdoptions.py:552 msgid "The name of the automount master map in LDAP." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:549 +#: src/config/SSSDConfig/sssdoptions.py:555 msgid "Base DN for IP hosts lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:550 +#: src/config/SSSDConfig/sssdoptions.py:556 msgid "Object class for IP hosts" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:551 +#: src/config/SSSDConfig/sssdoptions.py:557 msgid "IP host name attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:552 +#: src/config/SSSDConfig/sssdoptions.py:558 msgid "IP host number (address) attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:553 +#: src/config/SSSDConfig/sssdoptions.py:559 msgid "IP host entryUSN attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:554 +#: src/config/SSSDConfig/sssdoptions.py:560 msgid "Base DN for IP networks lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:555 +#: src/config/SSSDConfig/sssdoptions.py:561 msgid "Object class for IP networks" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:556 +#: src/config/SSSDConfig/sssdoptions.py:562 msgid "IP network name attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:557 +#: src/config/SSSDConfig/sssdoptions.py:563 msgid "IP network number (address) attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:558 +#: src/config/SSSDConfig/sssdoptions.py:564 msgid "IP network entryUSN attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:561 +#: src/config/SSSDConfig/sssdoptions.py:567 msgid "Comma separated list of allowed users" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:562 +#: src/config/SSSDConfig/sssdoptions.py:568 msgid "Comma separated list of prohibited users" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:563 +#: src/config/SSSDConfig/sssdoptions.py:569 msgid "" "Comma separated list of groups that are allowed to log in. This applies only " "to groups within this SSSD domain. Local groups are not evaluated." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:565 +#: src/config/SSSDConfig/sssdoptions.py:571 msgid "" "Comma separated list of groups that are explicitly denied access. This " "applies only to groups within this SSSD domain. Local groups are not " "evaluated." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:569 +#: src/config/SSSDConfig/sssdoptions.py:575 msgid "The number of preforked proxy children." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:572 +#: src/config/SSSDConfig/sssdoptions.py:578 msgid "The name of the NSS library to use" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:573 +#: src/config/SSSDConfig/sssdoptions.py:579 msgid "The name of the NSS library to use for hosts and networks lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:574 +#: src/config/SSSDConfig/sssdoptions.py:580 msgid "Whether to look up canonical group name from cache if possible" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:577 +#: src/config/SSSDConfig/sssdoptions.py:583 msgid "PAM stack to use" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:580 +#: src/config/SSSDConfig/sssdoptions.py:586 msgid "Path of passwd file sources." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:581 +#: src/config/SSSDConfig/sssdoptions.py:587 msgid "Path of group file sources." msgstr "" @@ -1882,225 +1917,233 @@ msgstr "" msgid "Option -i|--interactive is not allowed together with -D|--daemon\n" msgstr "" -#: src/monitor/monitor.c:1836 +#: src/monitor/monitor.c:1838 msgid "Failed to get initial capabilities\n" msgstr "" -#: src/monitor/monitor.c:1847 +#: src/monitor/monitor.c:1849 msgid "Non-root service user support isn't built. Can't run under %" msgstr "" -#: src/monitor/monitor.c:1864 +#: src/monitor/monitor.c:1866 #, c-format msgid "Can't read config: '%s'\n" msgstr "" -#: src/monitor/monitor.c:1876 +#: src/monitor/monitor.c:1878 #, c-format -msgid "Failed to boostrap SSSD 'monitor' process: %s" +msgid "Failed to bootstrap SSSD 'monitor' process: %s" msgstr "" -#: src/monitor/monitor.c:1971 +#: src/monitor/monitor.c:1973 msgid "Out of memory\n" msgstr "" -#: src/providers/krb5/krb5_child.c:4221 +#: src/providers/krb5/krb5_child.c:4316 msgid "Use anonymous PKINIT to request FAST armor ticket" msgstr "" -#: src/providers/krb5/krb5_child.c:4223 +#: src/providers/krb5/krb5_child.c:4318 msgid "Kerberos realm to use" msgstr "" -#: src/providers/krb5/krb5_child.c:4225 +#: src/providers/krb5/krb5_child.c:4320 msgid "Requested lifetime of the ticket" msgstr "" -#: src/providers/krb5/krb5_child.c:4227 +#: src/providers/krb5/krb5_child.c:4322 msgid "Requested renewable lifetime of the ticket" msgstr "" -#: src/providers/krb5/krb5_child.c:4229 +#: src/providers/krb5/krb5_child.c:4324 msgid "FAST options ('never', 'try', 'demand')" msgstr "" -#: src/providers/krb5/krb5_child.c:4232 +#: src/providers/krb5/krb5_child.c:4327 msgid "Specifies the server principal to use for FAST" msgstr "" -#: src/providers/krb5/krb5_child.c:4234 +#: src/providers/krb5/krb5_child.c:4329 msgid "Requests canonicalization of the principal name" msgstr "" -#: src/providers/krb5/krb5_child.c:4236 +#: src/providers/krb5/krb5_child.c:4331 msgid "Use custom version of krb5_get_init_creds_password" msgstr "" -#: src/providers/krb5/krb5_child.c:4238 +#: src/providers/krb5/krb5_child.c:4333 msgid "Check PAC flags" msgstr "" -#: src/providers/data_provider_be.c:790 +#: src/providers/krb5/krb5_child.c:4335 +msgid "Set environment variable (KEY=VALUE)" +msgstr "" + +#: src/providers/data_provider_be.c:786 msgid "Domain of the information provider (mandatory)" msgstr "" -#: src/sss_client/common.c:1165 +#: src/sss_client/common.c:1208 msgid "Socket has wrong ownership or permissions." msgstr "" -#: src/sss_client/common.c:1168 +#: src/sss_client/common.c:1211 msgid "Unexpected format of the server credential message." msgstr "" -#: src/sss_client/common.c:1171 +#: src/sss_client/common.c:1214 msgid "SSSD is not run by trusted user." msgstr "" -#: src/sss_client/common.c:1174 +#: src/sss_client/common.c:1217 msgid "SSSD socket does not exist." msgstr "" -#: src/sss_client/common.c:1177 +#: src/sss_client/common.c:1220 msgid "Cannot get stat of SSSD socket." msgstr "" -#: src/sss_client/common.c:1182 +#: src/sss_client/common.c:1225 msgid "An error occurred, but no description can be found." msgstr "" -#: src/sss_client/common.c:1188 +#: src/sss_client/common.c:1231 msgid "Unexpected error while looking for an error description" msgstr "" -#: src/sss_client/pam_sss.c:74 +#: src/sss_client/pam_sss.c:135 msgid "Permission denied. " msgstr "" -#: src/sss_client/pam_sss.c:75 src/sss_client/pam_sss.c:843 -#: src/sss_client/pam_sss.c:854 +#: src/sss_client/pam_sss.c:136 src/sss_client/pam_sss.c:921 +#: src/sss_client/pam_sss.c:932 msgid "Server message: " msgstr "" -#: src/sss_client/pam_sss.c:76 +#: src/sss_client/pam_sss.c:137 msgid "" "Kerberos TGT will not be granted upon login, user experience will be " "affected." msgstr "" -#: src/sss_client/pam_sss.c:77 +#: src/sss_client/pam_sss.c:138 msgid "Enter PIN:" msgstr "" -#: src/sss_client/pam_sss.c:320 +#: src/sss_client/pam_sss.c:385 msgid "Passwords do not match" msgstr "" -#: src/sss_client/pam_sss.c:508 +#: src/sss_client/pam_sss.c:584 msgid "Password reset by root is not supported." msgstr "" -#: src/sss_client/pam_sss.c:549 +#: src/sss_client/pam_sss.c:625 msgid "Authenticated with cached credentials" msgstr "" -#: src/sss_client/pam_sss.c:550 +#: src/sss_client/pam_sss.c:626 msgid ", your cached password will expire at: " msgstr "" -#: src/sss_client/pam_sss.c:580 +#: src/sss_client/pam_sss.c:656 #, c-format msgid "Your password has expired. You have %1$d grace login(s) remaining." msgstr "" -#: src/sss_client/pam_sss.c:630 +#: src/sss_client/pam_sss.c:706 #, c-format msgid "Your password will expire in %1$d %2$s." msgstr "" -#: src/sss_client/pam_sss.c:633 +#: src/sss_client/pam_sss.c:709 #, c-format msgid "Your password has expired." msgstr "" -#: src/sss_client/pam_sss.c:684 +#: src/sss_client/pam_sss.c:760 msgid "Authentication is denied until: " msgstr "" -#: src/sss_client/pam_sss.c:705 +#: src/sss_client/pam_sss.c:781 msgid "System is offline, password change not possible" msgstr "" -#: src/sss_client/pam_sss.c:720 +#: src/sss_client/pam_sss.c:796 msgid "" "After changing the OTP password, you need to log out and back in order to " "acquire a ticket" msgstr "" -#: src/sss_client/pam_sss.c:735 +#: src/sss_client/pam_sss.c:813 msgid "PIN locked" msgstr "" -#: src/sss_client/pam_sss.c:750 +#: src/sss_client/pam_sss.c:828 msgid "" "No Kerberos TGT granted as the server does not support this method. Your " "single-sign on(SSO) experience will be affected." msgstr "" -#: src/sss_client/pam_sss.c:840 src/sss_client/pam_sss.c:853 +#: src/sss_client/pam_sss.c:918 src/sss_client/pam_sss.c:931 msgid "Password change failed. " msgstr "" -#: src/sss_client/pam_sss.c:1859 +#: src/sss_client/pam_sss.c:2028 #, c-format -msgid "Authenticate at %1$s and press ENTER." +msgid "Authenticate at \"%1$s\"." msgstr "" -#: src/sss_client/pam_sss.c:1862 +#: src/sss_client/pam_sss.c:2031 #, c-format -msgid "Authenticate with PIN %1$s at %2$s and press ENTER." +msgid "Authenticate with PIN \"%1$s\" at \"%2$s\"." msgstr "" -#: src/sss_client/pam_sss.c:2281 +#: src/sss_client/pam_sss.c:2470 msgid "Please (re)insert (different) Smartcard" msgstr "" -#: src/sss_client/pam_sss.c:2482 +#: src/sss_client/pam_sss.c:2700 msgid "New Password: " msgstr "" -#: src/sss_client/pam_sss.c:2483 +#: src/sss_client/pam_sss.c:2701 msgid "Reenter new Password: " msgstr "" -#: src/sss_client/pam_sss.c:2676 src/sss_client/pam_sss.c:2679 +#: src/sss_client/pam_sss.c:2890 +msgid "Press ENTER to continue." +msgstr "" + +#: src/sss_client/pam_sss.c:2913 src/sss_client/pam_sss.c:2916 msgid "First Factor: " msgstr "" -#: src/sss_client/pam_sss.c:2677 src/sss_client/pam_sss.c:2851 +#: src/sss_client/pam_sss.c:2914 src/sss_client/pam_sss.c:3088 msgid "Second Factor (optional): " msgstr "" -#: src/sss_client/pam_sss.c:2680 src/sss_client/pam_sss.c:2855 +#: src/sss_client/pam_sss.c:2917 src/sss_client/pam_sss.c:3092 msgid "Second Factor: " msgstr "" -#: src/sss_client/pam_sss.c:2684 +#: src/sss_client/pam_sss.c:2921 msgid "Insert your passkey device, then press ENTER." msgstr "" -#: src/sss_client/pam_sss.c:2688 src/sss_client/pam_sss.c:2696 +#: src/sss_client/pam_sss.c:2925 src/sss_client/pam_sss.c:2933 msgid "Password: " msgstr "" -#: src/sss_client/pam_sss.c:2850 src/sss_client/pam_sss.c:2854 +#: src/sss_client/pam_sss.c:3087 src/sss_client/pam_sss.c:3091 msgid "First Factor (Current Password): " msgstr "" -#: src/sss_client/pam_sss.c:2874 +#: src/sss_client/pam_sss.c:3111 msgid "Current Password: " msgstr "" -#: src/sss_client/pam_sss.c:3248 +#: src/sss_client/pam_sss.c:3485 msgid "Password expired. Change your password now." msgstr "" @@ -2532,9 +2575,9 @@ msgstr "" #: src/tools/sssctl/sssctl_cache.c:835 src/tools/sssctl/sssctl_cache.c:918 #: src/tools/sssctl/sssctl_cache.c:950 src/tools/sssctl/sssctl_cache.c:956 #: src/tools/sssctl/sssctl_cache.c:1010 src/tools/sssctl/sssctl_cache.c:1034 -#: src/tools/sssctl/sssctl_cache.c:1085 src/tools/sssctl/sssctl_cache.c:1194 -#: src/tools/sssctl/sssctl_cache.c:1229 src/tools/sssctl/sssctl_cache.c:1235 -#: src/tools/sssctl/sssctl_cache.c:1244 +#: src/tools/sssctl/sssctl_cache.c:1085 src/tools/sssctl/sssctl_cache.c:1195 +#: src/tools/sssctl/sssctl_cache.c:1230 src/tools/sssctl/sssctl_cache.c:1236 +#: src/tools/sssctl/sssctl_cache.c:1245 msgid "talloc failed\n" msgstr "" @@ -2608,25 +2651,25 @@ msgstr "" msgid "Unable to remove downloaded GPO files: %s\n" msgstr "" -#: src/tools/sssctl/sssctl_cache.c:1165 +#: src/tools/sssctl/sssctl_cache.c:1166 #, c-format msgid "Failed to fetch cache entry: %s\n" msgstr "" -#: src/tools/sssctl/sssctl_cache.c:1170 +#: src/tools/sssctl/sssctl_cache.c:1171 msgid "Could not determine object domain\n" msgstr "" -#: src/tools/sssctl/sssctl_cache.c:1200 +#: src/tools/sssctl/sssctl_cache.c:1201 msgid "Could not find GUID attribute in GPO entry\n" msgstr "" -#: src/tools/sssctl/sssctl_cache.c:1206 +#: src/tools/sssctl/sssctl_cache.c:1207 #, c-format msgid "Failed to delete GPO: %s\n" msgstr "" -#: src/tools/sssctl/sssctl_cache.c:1210 +#: src/tools/sssctl/sssctl_cache.c:1211 #, c-format msgid "%s removed from cache\n" msgstr "" @@ -2714,39 +2757,39 @@ msgid "" "\"/my/path/sssd.conf\", the snippet dir \"/my/path/conf.d\" is used)" msgstr "" -#: src/tools/sssctl/sssctl_config.c:114 +#: src/tools/sssctl/sssctl_config.c:126 #, c-format msgid "File %1$s does not exist.\n" msgstr "" -#: src/tools/sssctl/sssctl_config.c:115 +#: src/tools/sssctl/sssctl_config.c:127 msgid "There is no configuration.\n" msgstr "" -#: src/tools/sssctl/sssctl_config.c:120 +#: src/tools/sssctl/sssctl_config.c:132 #, c-format msgid "Configuration validation failed: %s\n" msgstr "" -#: src/tools/sssctl/sssctl_config.c:121 +#: src/tools/sssctl/sssctl_config.c:133 msgid "Run with high debug level to see details.\n" msgstr "" -#: src/tools/sssctl/sssctl_config.c:130 -msgid "Failed to run validators" +#: src/tools/sssctl/sssctl_config.c:142 +msgid "Failed to run validators\n" msgstr "" -#: src/tools/sssctl/sssctl_config.c:134 +#: src/tools/sssctl/sssctl_config.c:146 #, c-format msgid "Issues identified by validators: %zu\n" msgstr "" -#: src/tools/sssctl/sssctl_config.c:145 +#: src/tools/sssctl/sssctl_config.c:157 #, c-format msgid "Messages generated during configuration merging: %zu\n" msgstr "" -#: src/tools/sssctl/sssctl_config.c:158 +#: src/tools/sssctl/sssctl_config.c:170 #, c-format msgid "Used configuration snippet files: %zu\n" msgstr "" diff --git a/po/nb.po b/po/nb.po index e833b41ce05..f0262a4486b 100644 --- a/po/nb.po +++ b/po/nb.po @@ -8,60 +8,60 @@ msgid "" msgstr "" "Project-Id-Version: PACKAGE VERSION\n" "Report-Msgid-Bugs-To: sssd-devel@lists.fedorahosted.org\n" -"POT-Creation-Date: 2026-01-14 14:57+0000\n" -"PO-Revision-Date: 2026-04-23 16:26+0000\n" +"POT-Creation-Date: 2026-10-02 15:57+0000\n" +"PO-Revision-Date: 2026-10-05 16:41+0000\n" "Last-Translator: Anonymous \n" "Language-Team: Norwegian Bokmål \n" +"projects/sssd/sssd-master/nb/>\n" "Language: nb\n" "MIME-Version: 1.0\n" "Content-Type: text/plain; charset=UTF-8\n" "Content-Transfer-Encoding: 8bit\n" "Plural-Forms: nplurals=2; plural=n != 1;\n" -"X-Generator: Weblate 5.17\n" +"X-Generator: Weblate 2026.10\n" -#: src/config/SSSDConfig/sssdoptions.py:20 -#: src/config/SSSDConfig/sssdoptions.py:21 +#: src/config/SSSDConfig/sssdoptions.py:16 +#: src/config/SSSDConfig/sssdoptions.py:17 msgid "Set the verbosity of the debug logging" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:22 +#: src/config/SSSDConfig/sssdoptions.py:18 msgid "Include timestamps in debug logs" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:23 +#: src/config/SSSDConfig/sssdoptions.py:19 msgid "Include microseconds in timestamps in debug logs" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:24 +#: src/config/SSSDConfig/sssdoptions.py:20 msgid "Enable/disable debug backtrace" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:25 +#: src/config/SSSDConfig/sssdoptions.py:21 msgid "Watchdog timeout before restarting service" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:26 +#: src/config/SSSDConfig/sssdoptions.py:22 msgid "Command to start service" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:27 +#: src/config/SSSDConfig/sssdoptions.py:23 msgid "The number of file descriptors that may be opened by this responder" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:28 +#: src/config/SSSDConfig/sssdoptions.py:24 msgid "Idle time before automatic disconnection of a client" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:29 +#: src/config/SSSDConfig/sssdoptions.py:25 msgid "Idle time before automatic shutdown of the responder" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:30 +#: src/config/SSSDConfig/sssdoptions.py:26 msgid "Always query all the caches before querying the Data Providers" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:31 +#: src/config/SSSDConfig/sssdoptions.py:27 msgid "" "When SSSD switches to offline mode the amount of time before it tries to go " "back online will increase based upon the time spent disconnected. This value " @@ -69,63 +69,63 @@ msgid "" "random_offset." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:36 +#: src/config/SSSDConfig/sssdoptions.py:32 msgid "SSSD Services to start" msgstr "SSSD-tjenester som skal startes" -#: src/config/SSSDConfig/sssdoptions.py:37 +#: src/config/SSSDConfig/sssdoptions.py:33 msgid "SSSD Domains to start" msgstr "SSSD-domener som skal startes" -#: src/config/SSSDConfig/sssdoptions.py:38 +#: src/config/SSSDConfig/sssdoptions.py:34 msgid "Regex to parse username and domain" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:39 +#: src/config/SSSDConfig/sssdoptions.py:35 msgid "Printf-compatible format for displaying fully-qualified names" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:40 +#: src/config/SSSDConfig/sssdoptions.py:36 msgid "" "Directory on the filesystem where SSSD should store Kerberos replay cache " "files." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:41 +#: src/config/SSSDConfig/sssdoptions.py:37 msgid "Domain to add to names without a domain component." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:42 +#: src/config/SSSDConfig/sssdoptions.py:38 msgid "The user to drop privileges to" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:43 +#: src/config/SSSDConfig/sssdoptions.py:39 msgid "Tune certificate verification" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:44 +#: src/config/SSSDConfig/sssdoptions.py:40 msgid "All spaces in group or user names will be replaced with this character" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:45 +#: src/config/SSSDConfig/sssdoptions.py:41 msgid "Tune sssd to honor or ignore netlink state changes" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:46 +#: src/config/SSSDConfig/sssdoptions.py:42 msgid "Enable or disable the implicit files domain" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:47 +#: src/config/SSSDConfig/sssdoptions.py:43 msgid "A specific order of the domains to be looked up" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:48 +#: src/config/SSSDConfig/sssdoptions.py:44 msgid "" "Controls if SSSD should monitor the state of resolv.conf to identify when it " "needs to update its internal DNS resolver." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:50 +#: src/config/SSSDConfig/sssdoptions.py:46 msgid "" "SSSD monitors the state of resolv.conf to identify when it needs to update " "its internal DNS resolver. By default, we will attempt to use inotify for " @@ -133,393 +133,400 @@ msgid "" "inotify cannot be used." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:53 +#: src/config/SSSDConfig/sssdoptions.py:49 msgid "Run PAC responder automatically for AD and IPA provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:54 +#: src/config/SSSDConfig/sssdoptions.py:50 msgid "Enable or disable core dumps for all SSSD processes." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:55 +#: src/config/SSSDConfig/sssdoptions.py:51 msgid "Tune passkey verification behavior" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:58 +#: src/config/SSSDConfig/sssdoptions.py:54 msgid "Enumeration cache timeout length (seconds)" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:59 +#: src/config/SSSDConfig/sssdoptions.py:55 msgid "Entry cache background update timeout length (seconds)" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:60 -#: src/config/SSSDConfig/sssdoptions.py:125 +#: src/config/SSSDConfig/sssdoptions.py:56 +#: src/config/SSSDConfig/sssdoptions.py:124 msgid "Negative cache timeout length (seconds)" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:61 +#: src/config/SSSDConfig/sssdoptions.py:57 msgid "Users that SSSD should explicitly ignore" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:62 +#: src/config/SSSDConfig/sssdoptions.py:58 msgid "Groups that SSSD should explicitly ignore" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:63 +#: src/config/SSSDConfig/sssdoptions.py:59 msgid "Should filtered users appear in groups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:64 +#: src/config/SSSDConfig/sssdoptions.py:60 msgid "The value of the password field the NSS provider should return" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:65 +#: src/config/SSSDConfig/sssdoptions.py:61 msgid "Override homedir value from the identity provider with this value" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:66 +#: src/config/SSSDConfig/sssdoptions.py:62 msgid "" "Substitute empty homedir value from the identity provider with this value" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:67 +#: src/config/SSSDConfig/sssdoptions.py:63 msgid "Override shell value from the identity provider with this value" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:68 +#: src/config/SSSDConfig/sssdoptions.py:64 msgid "The list of shells users are allowed to log in with" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:69 +#: src/config/SSSDConfig/sssdoptions.py:65 msgid "" "The list of shells that will be vetoed, and replaced with the fallback shell" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:70 +#: src/config/SSSDConfig/sssdoptions.py:66 msgid "" "If a shell stored in central directory is allowed but not available, use " "this fallback" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:71 +#: src/config/SSSDConfig/sssdoptions.py:67 msgid "Shell to use if the provider does not list one" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:72 +#: src/config/SSSDConfig/sssdoptions.py:68 msgid "How long will be in-memory cache records valid" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:74 +#: src/config/SSSDConfig/sssdoptions.py:70 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for passwd requests" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:76 +#: src/config/SSSDConfig/sssdoptions.py:72 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for group requests" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:78 +#: src/config/SSSDConfig/sssdoptions.py:74 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for initgroups requests" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:79 +#: src/config/SSSDConfig/sssdoptions.py:75 msgid "" "The value of this option will be used in the expansion of the " "override_homedir option if the template contains the format string %H." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:81 +#: src/config/SSSDConfig/sssdoptions.py:77 msgid "" "Specifies time in seconds for which the list of subdomains will be " "considered valid." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:83 +#: src/config/SSSDConfig/sssdoptions.py:79 msgid "" "The entry cache can be set to automatically update entries in the background " "if they are requested beyond a percentage of the entry_cache_timeout value " "for the domain." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:88 +#: src/config/SSSDConfig/sssdoptions.py:84 msgid "How long to allow cached logins between online logins (days)" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:89 +#: src/config/SSSDConfig/sssdoptions.py:85 msgid "How many failed logins attempts are allowed when offline" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:91 +#: src/config/SSSDConfig/sssdoptions.py:87 msgid "" "How long (minutes) to deny login after offline_failed_login_attempts has " "been reached" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:92 +#: src/config/SSSDConfig/sssdoptions.py:88 msgid "What kind of messages are displayed to the user during authentication" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:93 +#: src/config/SSSDConfig/sssdoptions.py:89 msgid "Filter PAM responses sent to the pam_sss" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:94 +#: src/config/SSSDConfig/sssdoptions.py:90 msgid "How many seconds to keep identity information cached for PAM requests" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:95 +#: src/config/SSSDConfig/sssdoptions.py:91 msgid "How many days before password expiration a warning should be displayed" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:96 +#: src/config/SSSDConfig/sssdoptions.py:92 msgid "List of trusted uids or user's name" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:97 +#: src/config/SSSDConfig/sssdoptions.py:93 msgid "List of domains accessible even for untrusted users." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:98 +#: src/config/SSSDConfig/sssdoptions.py:94 msgid "Message printed when user account is expired." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:99 +#: src/config/SSSDConfig/sssdoptions.py:95 msgid "Message printed when user account is locked." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:100 +#: src/config/SSSDConfig/sssdoptions.py:96 msgid "Allow certificate based/Smartcard authentication." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:101 +#: src/config/SSSDConfig/sssdoptions.py:97 msgid "Path to certificate database with PKCS#11 modules." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:102 +#: src/config/SSSDConfig/sssdoptions.py:98 msgid "Tune certificate verification for PAM authentication." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:103 +#: src/config/SSSDConfig/sssdoptions.py:99 msgid "How many seconds will pam_sss wait for p11_child to finish" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:104 +#: src/config/SSSDConfig/sssdoptions.py:100 msgid "Which PAM services are permitted to contact application domains" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:105 +#: src/config/SSSDConfig/sssdoptions.py:101 msgid "Allowed services for using smartcards" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:106 +#: src/config/SSSDConfig/sssdoptions.py:102 msgid "Additional timeout to wait for a card if requested" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:107 +#: src/config/SSSDConfig/sssdoptions.py:103 msgid "" "PKCS#11 URI to restrict the selection of devices for Smartcard authentication" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:108 +#: src/config/SSSDConfig/sssdoptions.py:104 msgid "When shall the PAM responder force an initgroups request" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:109 +#: src/config/SSSDConfig/sssdoptions.py:105 msgid "List of PAM services that are allowed to authenticate with GSSAPI." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:110 +#: src/config/SSSDConfig/sssdoptions.py:106 msgid "Whether to match authenticated UPN with target user" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:111 +#: src/config/SSSDConfig/sssdoptions.py:107 msgid "" "List of pairs : that must be enforced " "for PAM access with GSSAPI authentication" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:113 +#: src/config/SSSDConfig/sssdoptions.py:109 +msgid "" +"List of triples :: that assigns " +"additional information from the Kerberos ticket to an authentication " +"indicator." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:112 msgid "Allow passkey device authentication." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:114 +#: src/config/SSSDConfig/sssdoptions.py:113 msgid "How many seconds will pam_sss wait for passkey_child to finish" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:115 +#: src/config/SSSDConfig/sssdoptions.py:114 msgid "Enable debugging in the libfido2 library" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:116 +#: src/config/SSSDConfig/sssdoptions.py:115 msgid "Enable JSON protocol for authentication methods selection." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:119 +#: src/config/SSSDConfig/sssdoptions.py:118 msgid "Whether to evaluate the time-based attributes in sudo rules" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:120 +#: src/config/SSSDConfig/sssdoptions.py:119 msgid "If true, SSSD will switch back to lower-wins ordering logic" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:121 +#: src/config/SSSDConfig/sssdoptions.py:120 msgid "" "Maximum number of rules that can be refreshed at once. If this is exceeded, " "full refresh is performed." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:128 +#: src/config/SSSDConfig/sssdoptions.py:127 msgid "Whether to hash host names and addresses in the known_hosts file" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:129 +#: src/config/SSSDConfig/sssdoptions.py:128 msgid "" "How many seconds to keep a host in the known_hosts file after its host keys " "were requested" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:131 +#: src/config/SSSDConfig/sssdoptions.py:130 msgid "Path to storage of trusted CA certificates" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:132 +#: src/config/SSSDConfig/sssdoptions.py:131 msgid "Allow to generate ssh-keys from certificates" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:133 +#: src/config/SSSDConfig/sssdoptions.py:132 msgid "" "Use the following matching rules to filter the certificates for ssh-key " "generation" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:137 +#: src/config/SSSDConfig/sssdoptions.py:136 msgid "List of UIDs or user names allowed to access the PAC responder" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:138 +#: src/config/SSSDConfig/sssdoptions.py:137 msgid "How long the PAC data is considered valid" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:139 +#: src/config/SSSDConfig/sssdoptions.py:138 msgid "Validate the PAC" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:142 +#: src/config/SSSDConfig/sssdoptions.py:141 msgid "List of user attributes the InfoPipe is allowed to publish" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:145 +#: src/config/SSSDConfig/sssdoptions.py:144 msgid "" "One of the following strings specifying the scope of session recording: none " "- No users are recorded. some - Users/groups specified by users and groups " "options are recorded. all - All users are recorded." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:148 +#: src/config/SSSDConfig/sssdoptions.py:147 msgid "" "A comma-separated list of users which should have session recording enabled. " "Matches user names as returned by NSS. I.e. after the possible space " "replacement, case changes, etc." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:150 +#: src/config/SSSDConfig/sssdoptions.py:149 msgid "" "A comma-separated list of groups, members of which should have session " "recording enabled. Matches group names as returned by NSS. I.e. after the " "possible space replacement, case changes, etc." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:153 +#: src/config/SSSDConfig/sssdoptions.py:152 msgid "" "A comma-separated list of users to be excluded from recording, only when " "scope=all" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:154 +#: src/config/SSSDConfig/sssdoptions.py:153 msgid "" "A comma-separated list of groups, members of which should be excluded from " "recording, only when scope=all. " msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:158 +#: src/config/SSSDConfig/sssdoptions.py:157 msgid "Identity provider" msgstr "Identitetstilbyder" -#: src/config/SSSDConfig/sssdoptions.py:159 +#: src/config/SSSDConfig/sssdoptions.py:158 msgid "Authentication provider" msgstr "Autentiseringstilbyder" -#: src/config/SSSDConfig/sssdoptions.py:160 +#: src/config/SSSDConfig/sssdoptions.py:159 msgid "Access control provider" msgstr "Tilgangskontrolltilbyder" -#: src/config/SSSDConfig/sssdoptions.py:161 +#: src/config/SSSDConfig/sssdoptions.py:160 msgid "Password change provider" msgstr "Passordbyttetilbyder" -#: src/config/SSSDConfig/sssdoptions.py:162 +#: src/config/SSSDConfig/sssdoptions.py:161 msgid "SUDO provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:163 +#: src/config/SSSDConfig/sssdoptions.py:162 msgid "Autofs provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:164 +#: src/config/SSSDConfig/sssdoptions.py:163 msgid "Host identity provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:165 +#: src/config/SSSDConfig/sssdoptions.py:164 msgid "SELinux provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:166 +#: src/config/SSSDConfig/sssdoptions.py:165 msgid "Session management provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:167 +#: src/config/SSSDConfig/sssdoptions.py:166 msgid "Resolver provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:170 +#: src/config/SSSDConfig/sssdoptions.py:169 msgid "Whether the domain is usable by the OS or by applications" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:171 +#: src/config/SSSDConfig/sssdoptions.py:170 msgid "Enable or disable the domain" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:172 +#: src/config/SSSDConfig/sssdoptions.py:171 msgid "Minimum user ID" msgstr "Minste bruker-ID" -#: src/config/SSSDConfig/sssdoptions.py:173 +#: src/config/SSSDConfig/sssdoptions.py:172 msgid "Maximum user ID" msgstr "Største bruker-ID" -#: src/config/SSSDConfig/sssdoptions.py:174 +#: src/config/SSSDConfig/sssdoptions.py:173 msgid "Enable enumerating all users/groups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:175 +#: src/config/SSSDConfig/sssdoptions.py:174 msgid "Cache credentials for offline login" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:176 +#: src/config/SSSDConfig/sssdoptions.py:175 msgid "Display users/groups in fully-qualified form" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:177 +#: src/config/SSSDConfig/sssdoptions.py:176 msgid "Don't include group members in group lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:178 +#: src/config/SSSDConfig/sssdoptions.py:177 #: src/config/SSSDConfig/sssdoptions.py:190 #: src/config/SSSDConfig/sssdoptions.py:191 #: src/config/SSSDConfig/sssdoptions.py:192 @@ -530,48 +537,52 @@ msgstr "" msgid "Entry cache timeout length (seconds)" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:179 +#: src/config/SSSDConfig/sssdoptions.py:178 msgid "" "Restrict or prefer a specific address family when performing DNS lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:180 +#: src/config/SSSDConfig/sssdoptions.py:179 msgid "How long to keep cached entries after last successful login (days)" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:181 +#: src/config/SSSDConfig/sssdoptions.py:180 msgid "" "How long should SSSD talk to single DNS server before trying next server " "(miliseconds)" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:183 +#: src/config/SSSDConfig/sssdoptions.py:182 msgid "How long should keep trying to resolve single DNS query (seconds)" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:184 +#: src/config/SSSDConfig/sssdoptions.py:183 msgid "How long to wait for replies from DNS when resolving servers (seconds)" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:185 +#: src/config/SSSDConfig/sssdoptions.py:184 msgid "The domain part of service discovery DNS query" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:186 +#: src/config/SSSDConfig/sssdoptions.py:185 msgid "" "Specifies the interval, in seconds, that SSSD waits before attempting to " "reconnect to the primary server after a successful connection to the backup " "server" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:188 +#: src/config/SSSDConfig/sssdoptions.py:187 msgid "Override GID value from the identity provider with this value" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:189 +#: src/config/SSSDConfig/sssdoptions.py:188 msgid "Treat usernames as case sensitive" msgstr "" +#: src/config/SSSDConfig/sssdoptions.py:189 +msgid "Lookups by ID are expensive or do not work at all" +msgstr "" + #: src/config/SSSDConfig/sssdoptions.py:197 msgid "How often should expired entries be refreshed in background" msgstr "" @@ -791,7 +802,7 @@ msgid "Search base for SUBID ranges" msgstr "" #: src/config/SSSDConfig/sssdoptions.py:259 -#: src/config/SSSDConfig/sssdoptions.py:506 +#: src/config/SSSDConfig/sssdoptions.py:512 msgid "Which rules should be used to evaluate access control" msgstr "" @@ -933,7 +944,7 @@ msgid "Enable DNS sites - location based service discovery" msgstr "" #: src/config/SSSDConfig/sssdoptions.py:301 -#: src/config/SSSDConfig/sssdoptions.py:504 +#: src/config/SSSDConfig/sssdoptions.py:510 msgid "LDAP filter to determine access privileges" msgstr "" @@ -1353,7 +1364,7 @@ msgid "UUID attribute" msgstr "" #: src/config/SSSDConfig/sssdoptions.py:423 -#: src/config/SSSDConfig/sssdoptions.py:464 +#: src/config/SSSDConfig/sssdoptions.py:470 msgid "objectSID attribute" msgstr "" @@ -1477,385 +1488,409 @@ msgstr "" msgid "A list of extra attributes to download along with the user entry" msgstr "" +#: src/config/SSSDConfig/sssdoptions.py:456 +msgid "The object class of an subid entry in LDAP." +msgstr "" + #: src/config/SSSDConfig/sssdoptions.py:457 -msgid "Base DN for group lookups" +msgid "Subordinate user ID count attribute" msgstr "" #: src/config/SSSDConfig/sssdoptions.py:458 -msgid "Objectclass for groups" +msgid "Subordinate group ID count attribute" msgstr "" #: src/config/SSSDConfig/sssdoptions.py:459 -msgid "Group name" +msgid "User ID range start value attribute" msgstr "" #: src/config/SSSDConfig/sssdoptions.py:460 -msgid "Group password" +msgid "Group ID range start value attribute" msgstr "" #: src/config/SSSDConfig/sssdoptions.py:461 +msgid "Owner of an entry" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:463 +msgid "Base DN for group lookups" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:464 +msgid "Objectclass for groups" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:465 +msgid "Group name" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:466 +msgid "Group password" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:467 msgid "GID attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:462 +#: src/config/SSSDConfig/sssdoptions.py:468 msgid "Group member attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:463 +#: src/config/SSSDConfig/sssdoptions.py:469 msgid "Group UUID attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:465 +#: src/config/SSSDConfig/sssdoptions.py:471 msgid "Modification time attribute for groups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:466 +#: src/config/SSSDConfig/sssdoptions.py:472 msgid "Type of the group and other flags" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:467 +#: src/config/SSSDConfig/sssdoptions.py:473 msgid "The LDAP group external member attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:468 +#: src/config/SSSDConfig/sssdoptions.py:474 msgid "Maximum nesting level SSSD will follow" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:469 +#: src/config/SSSDConfig/sssdoptions.py:475 msgid "Filter for group lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:470 +#: src/config/SSSDConfig/sssdoptions.py:476 msgid "Scope of group lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:472 +#: src/config/SSSDConfig/sssdoptions.py:478 msgid "Base DN for netgroup lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:473 +#: src/config/SSSDConfig/sssdoptions.py:479 msgid "Objectclass for netgroups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:474 +#: src/config/SSSDConfig/sssdoptions.py:480 msgid "Netgroup name" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:475 +#: src/config/SSSDConfig/sssdoptions.py:481 msgid "Netgroups members attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:476 +#: src/config/SSSDConfig/sssdoptions.py:482 msgid "Netgroup triple attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:477 +#: src/config/SSSDConfig/sssdoptions.py:483 msgid "Modification time attribute for netgroups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:479 +#: src/config/SSSDConfig/sssdoptions.py:485 msgid "Base DN for service lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:480 +#: src/config/SSSDConfig/sssdoptions.py:486 msgid "Objectclass for services" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:481 +#: src/config/SSSDConfig/sssdoptions.py:487 msgid "Service name attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:482 +#: src/config/SSSDConfig/sssdoptions.py:488 msgid "Service port attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:483 +#: src/config/SSSDConfig/sssdoptions.py:489 msgid "Service protocol attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:485 +#: src/config/SSSDConfig/sssdoptions.py:491 msgid "Lower bound for ID-mapping" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:486 +#: src/config/SSSDConfig/sssdoptions.py:492 msgid "Upper bound for ID-mapping" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:487 +#: src/config/SSSDConfig/sssdoptions.py:493 msgid "Number of IDs for each slice when ID-mapping" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:488 +#: src/config/SSSDConfig/sssdoptions.py:494 msgid "Use autorid-compatible algorithm for ID-mapping" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:489 +#: src/config/SSSDConfig/sssdoptions.py:495 msgid "Name of the default domain for ID-mapping" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:490 +#: src/config/SSSDConfig/sssdoptions.py:496 msgid "SID of the default domain for ID-mapping" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:491 +#: src/config/SSSDConfig/sssdoptions.py:497 msgid "Number of secondary slices" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:493 +#: src/config/SSSDConfig/sssdoptions.py:499 msgid "Whether to use Token-Groups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:494 +#: src/config/SSSDConfig/sssdoptions.py:500 msgid "Set lower boundary for allowed IDs from the LDAP server" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:495 +#: src/config/SSSDConfig/sssdoptions.py:501 msgid "Set upper boundary for allowed IDs from the LDAP server" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:496 +#: src/config/SSSDConfig/sssdoptions.py:502 msgid "DN for ppolicy queries" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:497 +#: src/config/SSSDConfig/sssdoptions.py:503 msgid "How many maximum entries to fetch during a wildcard request" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:498 +#: src/config/SSSDConfig/sssdoptions.py:504 msgid "Set libldap debug level" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:501 +#: src/config/SSSDConfig/sssdoptions.py:507 msgid "Policy to evaluate the password expiration" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:505 +#: src/config/SSSDConfig/sssdoptions.py:511 msgid "Which attributes shall be used to evaluate if an account is expired" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:509 +#: src/config/SSSDConfig/sssdoptions.py:515 msgid "URI of an LDAP server where password changes are allowed" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:510 +#: src/config/SSSDConfig/sssdoptions.py:516 msgid "URI of a backup LDAP server where password changes are allowed" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:511 +#: src/config/SSSDConfig/sssdoptions.py:517 msgid "DNS service name for LDAP password change server" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:512 +#: src/config/SSSDConfig/sssdoptions.py:518 msgid "" "Whether to update the ldap_user_shadow_last_change attribute after a " "password change" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:516 +#: src/config/SSSDConfig/sssdoptions.py:522 msgid "Base DN for sudo rules lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:517 +#: src/config/SSSDConfig/sssdoptions.py:523 msgid "Automatic full refresh period" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:518 +#: src/config/SSSDConfig/sssdoptions.py:524 msgid "Automatic smart refresh period" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:519 +#: src/config/SSSDConfig/sssdoptions.py:525 msgid "Smart and full refresh random offset" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:520 +#: src/config/SSSDConfig/sssdoptions.py:526 msgid "Whether to filter rules by hostname, IP addresses and network" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:521 +#: src/config/SSSDConfig/sssdoptions.py:527 msgid "" "Hostnames and/or fully qualified domain names of this machine to filter sudo " "rules" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:522 +#: src/config/SSSDConfig/sssdoptions.py:528 msgid "IPv4 or IPv6 addresses or network of this machine to filter sudo rules" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:523 +#: src/config/SSSDConfig/sssdoptions.py:529 msgid "Whether to include rules that contains netgroup in host attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:524 +#: src/config/SSSDConfig/sssdoptions.py:530 msgid "" "Whether to include rules that contains regular expression in host attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:525 +#: src/config/SSSDConfig/sssdoptions.py:531 msgid "Object class for sudo rules" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:526 +#: src/config/SSSDConfig/sssdoptions.py:532 msgid "Name of attribute that is used as object class for sudo rules" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:527 +#: src/config/SSSDConfig/sssdoptions.py:533 msgid "Sudo rule name" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:528 +#: src/config/SSSDConfig/sssdoptions.py:534 msgid "Sudo rule command attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:529 +#: src/config/SSSDConfig/sssdoptions.py:535 msgid "Sudo rule host attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:530 +#: src/config/SSSDConfig/sssdoptions.py:536 msgid "Sudo rule user attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:531 +#: src/config/SSSDConfig/sssdoptions.py:537 msgid "Sudo rule option attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:532 +#: src/config/SSSDConfig/sssdoptions.py:538 msgid "Sudo rule runas attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:533 +#: src/config/SSSDConfig/sssdoptions.py:539 msgid "Sudo rule runasuser attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:534 +#: src/config/SSSDConfig/sssdoptions.py:540 msgid "Sudo rule runasgroup attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:535 +#: src/config/SSSDConfig/sssdoptions.py:541 msgid "Sudo rule notbefore attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:536 +#: src/config/SSSDConfig/sssdoptions.py:542 msgid "Sudo rule notafter attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:537 +#: src/config/SSSDConfig/sssdoptions.py:543 msgid "Sudo rule order attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:540 +#: src/config/SSSDConfig/sssdoptions.py:546 msgid "Object class for automounter maps" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:541 +#: src/config/SSSDConfig/sssdoptions.py:547 msgid "Automounter map name attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:542 +#: src/config/SSSDConfig/sssdoptions.py:548 msgid "Object class for automounter map entries" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:543 +#: src/config/SSSDConfig/sssdoptions.py:549 msgid "Automounter map entry key attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:544 +#: src/config/SSSDConfig/sssdoptions.py:550 msgid "Automounter map entry value attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:545 +#: src/config/SSSDConfig/sssdoptions.py:551 msgid "Base DN for automounter map lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:546 +#: src/config/SSSDConfig/sssdoptions.py:552 msgid "The name of the automount master map in LDAP." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:549 +#: src/config/SSSDConfig/sssdoptions.py:555 msgid "Base DN for IP hosts lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:550 +#: src/config/SSSDConfig/sssdoptions.py:556 msgid "Object class for IP hosts" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:551 +#: src/config/SSSDConfig/sssdoptions.py:557 msgid "IP host name attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:552 +#: src/config/SSSDConfig/sssdoptions.py:558 msgid "IP host number (address) attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:553 +#: src/config/SSSDConfig/sssdoptions.py:559 msgid "IP host entryUSN attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:554 +#: src/config/SSSDConfig/sssdoptions.py:560 msgid "Base DN for IP networks lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:555 +#: src/config/SSSDConfig/sssdoptions.py:561 msgid "Object class for IP networks" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:556 +#: src/config/SSSDConfig/sssdoptions.py:562 msgid "IP network name attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:557 +#: src/config/SSSDConfig/sssdoptions.py:563 msgid "IP network number (address) attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:558 +#: src/config/SSSDConfig/sssdoptions.py:564 msgid "IP network entryUSN attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:561 +#: src/config/SSSDConfig/sssdoptions.py:567 msgid "Comma separated list of allowed users" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:562 +#: src/config/SSSDConfig/sssdoptions.py:568 msgid "Comma separated list of prohibited users" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:563 +#: src/config/SSSDConfig/sssdoptions.py:569 msgid "" "Comma separated list of groups that are allowed to log in. This applies only " "to groups within this SSSD domain. Local groups are not evaluated." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:565 +#: src/config/SSSDConfig/sssdoptions.py:571 msgid "" "Comma separated list of groups that are explicitly denied access. This " "applies only to groups within this SSSD domain. Local groups are not " "evaluated." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:569 +#: src/config/SSSDConfig/sssdoptions.py:575 msgid "The number of preforked proxy children." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:572 +#: src/config/SSSDConfig/sssdoptions.py:578 msgid "The name of the NSS library to use" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:573 +#: src/config/SSSDConfig/sssdoptions.py:579 msgid "The name of the NSS library to use for hosts and networks lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:574 +#: src/config/SSSDConfig/sssdoptions.py:580 msgid "Whether to look up canonical group name from cache if possible" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:577 +#: src/config/SSSDConfig/sssdoptions.py:583 msgid "PAM stack to use" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:580 +#: src/config/SSSDConfig/sssdoptions.py:586 msgid "Path of passwd file sources." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:581 +#: src/config/SSSDConfig/sssdoptions.py:587 msgid "Path of group file sources." msgstr "" @@ -1883,225 +1918,233 @@ msgstr "" msgid "Option -i|--interactive is not allowed together with -D|--daemon\n" msgstr "" -#: src/monitor/monitor.c:1836 +#: src/monitor/monitor.c:1838 msgid "Failed to get initial capabilities\n" msgstr "" -#: src/monitor/monitor.c:1847 +#: src/monitor/monitor.c:1849 msgid "Non-root service user support isn't built. Can't run under %" msgstr "" -#: src/monitor/monitor.c:1864 +#: src/monitor/monitor.c:1866 #, c-format msgid "Can't read config: '%s'\n" msgstr "" -#: src/monitor/monitor.c:1876 +#: src/monitor/monitor.c:1878 #, c-format -msgid "Failed to boostrap SSSD 'monitor' process: %s" +msgid "Failed to bootstrap SSSD 'monitor' process: %s" msgstr "" -#: src/monitor/monitor.c:1971 +#: src/monitor/monitor.c:1973 msgid "Out of memory\n" msgstr "" -#: src/providers/krb5/krb5_child.c:4221 +#: src/providers/krb5/krb5_child.c:4316 msgid "Use anonymous PKINIT to request FAST armor ticket" msgstr "" -#: src/providers/krb5/krb5_child.c:4223 +#: src/providers/krb5/krb5_child.c:4318 msgid "Kerberos realm to use" msgstr "" -#: src/providers/krb5/krb5_child.c:4225 +#: src/providers/krb5/krb5_child.c:4320 msgid "Requested lifetime of the ticket" msgstr "" -#: src/providers/krb5/krb5_child.c:4227 +#: src/providers/krb5/krb5_child.c:4322 msgid "Requested renewable lifetime of the ticket" msgstr "" -#: src/providers/krb5/krb5_child.c:4229 +#: src/providers/krb5/krb5_child.c:4324 msgid "FAST options ('never', 'try', 'demand')" msgstr "" -#: src/providers/krb5/krb5_child.c:4232 +#: src/providers/krb5/krb5_child.c:4327 msgid "Specifies the server principal to use for FAST" msgstr "" -#: src/providers/krb5/krb5_child.c:4234 +#: src/providers/krb5/krb5_child.c:4329 msgid "Requests canonicalization of the principal name" msgstr "" -#: src/providers/krb5/krb5_child.c:4236 +#: src/providers/krb5/krb5_child.c:4331 msgid "Use custom version of krb5_get_init_creds_password" msgstr "" -#: src/providers/krb5/krb5_child.c:4238 +#: src/providers/krb5/krb5_child.c:4333 msgid "Check PAC flags" msgstr "" -#: src/providers/data_provider_be.c:790 +#: src/providers/krb5/krb5_child.c:4335 +msgid "Set environment variable (KEY=VALUE)" +msgstr "" + +#: src/providers/data_provider_be.c:786 msgid "Domain of the information provider (mandatory)" msgstr "" -#: src/sss_client/common.c:1165 +#: src/sss_client/common.c:1208 msgid "Socket has wrong ownership or permissions." msgstr "" -#: src/sss_client/common.c:1168 +#: src/sss_client/common.c:1211 msgid "Unexpected format of the server credential message." msgstr "" -#: src/sss_client/common.c:1171 +#: src/sss_client/common.c:1214 msgid "SSSD is not run by trusted user." msgstr "" -#: src/sss_client/common.c:1174 +#: src/sss_client/common.c:1217 msgid "SSSD socket does not exist." msgstr "" -#: src/sss_client/common.c:1177 +#: src/sss_client/common.c:1220 msgid "Cannot get stat of SSSD socket." msgstr "" -#: src/sss_client/common.c:1182 +#: src/sss_client/common.c:1225 msgid "An error occurred, but no description can be found." msgstr "" -#: src/sss_client/common.c:1188 +#: src/sss_client/common.c:1231 msgid "Unexpected error while looking for an error description" msgstr "" -#: src/sss_client/pam_sss.c:74 +#: src/sss_client/pam_sss.c:135 msgid "Permission denied. " msgstr "" -#: src/sss_client/pam_sss.c:75 src/sss_client/pam_sss.c:843 -#: src/sss_client/pam_sss.c:854 +#: src/sss_client/pam_sss.c:136 src/sss_client/pam_sss.c:921 +#: src/sss_client/pam_sss.c:932 msgid "Server message: " msgstr "" -#: src/sss_client/pam_sss.c:76 +#: src/sss_client/pam_sss.c:137 msgid "" "Kerberos TGT will not be granted upon login, user experience will be " "affected." msgstr "" -#: src/sss_client/pam_sss.c:77 +#: src/sss_client/pam_sss.c:138 msgid "Enter PIN:" msgstr "" -#: src/sss_client/pam_sss.c:320 +#: src/sss_client/pam_sss.c:385 msgid "Passwords do not match" msgstr "" -#: src/sss_client/pam_sss.c:508 +#: src/sss_client/pam_sss.c:584 msgid "Password reset by root is not supported." msgstr "" -#: src/sss_client/pam_sss.c:549 +#: src/sss_client/pam_sss.c:625 msgid "Authenticated with cached credentials" msgstr "" -#: src/sss_client/pam_sss.c:550 +#: src/sss_client/pam_sss.c:626 msgid ", your cached password will expire at: " msgstr "" -#: src/sss_client/pam_sss.c:580 +#: src/sss_client/pam_sss.c:656 #, c-format msgid "Your password has expired. You have %1$d grace login(s) remaining." msgstr "" -#: src/sss_client/pam_sss.c:630 +#: src/sss_client/pam_sss.c:706 #, c-format msgid "Your password will expire in %1$d %2$s." msgstr "" -#: src/sss_client/pam_sss.c:633 +#: src/sss_client/pam_sss.c:709 #, c-format msgid "Your password has expired." msgstr "" -#: src/sss_client/pam_sss.c:684 +#: src/sss_client/pam_sss.c:760 msgid "Authentication is denied until: " msgstr "" -#: src/sss_client/pam_sss.c:705 +#: src/sss_client/pam_sss.c:781 msgid "System is offline, password change not possible" msgstr "" -#: src/sss_client/pam_sss.c:720 +#: src/sss_client/pam_sss.c:796 msgid "" "After changing the OTP password, you need to log out and back in order to " "acquire a ticket" msgstr "" -#: src/sss_client/pam_sss.c:735 +#: src/sss_client/pam_sss.c:813 msgid "PIN locked" msgstr "" -#: src/sss_client/pam_sss.c:750 +#: src/sss_client/pam_sss.c:828 msgid "" "No Kerberos TGT granted as the server does not support this method. Your " "single-sign on(SSO) experience will be affected." msgstr "" -#: src/sss_client/pam_sss.c:840 src/sss_client/pam_sss.c:853 +#: src/sss_client/pam_sss.c:918 src/sss_client/pam_sss.c:931 msgid "Password change failed. " msgstr "" -#: src/sss_client/pam_sss.c:1859 +#: src/sss_client/pam_sss.c:2028 #, c-format -msgid "Authenticate at %1$s and press ENTER." +msgid "Authenticate at \"%1$s\"." msgstr "" -#: src/sss_client/pam_sss.c:1862 +#: src/sss_client/pam_sss.c:2031 #, c-format -msgid "Authenticate with PIN %1$s at %2$s and press ENTER." +msgid "Authenticate with PIN \"%1$s\" at \"%2$s\"." msgstr "" -#: src/sss_client/pam_sss.c:2281 +#: src/sss_client/pam_sss.c:2470 msgid "Please (re)insert (different) Smartcard" msgstr "" -#: src/sss_client/pam_sss.c:2482 +#: src/sss_client/pam_sss.c:2700 msgid "New Password: " msgstr "" -#: src/sss_client/pam_sss.c:2483 +#: src/sss_client/pam_sss.c:2701 msgid "Reenter new Password: " msgstr "" -#: src/sss_client/pam_sss.c:2676 src/sss_client/pam_sss.c:2679 +#: src/sss_client/pam_sss.c:2890 +msgid "Press ENTER to continue." +msgstr "" + +#: src/sss_client/pam_sss.c:2913 src/sss_client/pam_sss.c:2916 msgid "First Factor: " msgstr "" -#: src/sss_client/pam_sss.c:2677 src/sss_client/pam_sss.c:2851 +#: src/sss_client/pam_sss.c:2914 src/sss_client/pam_sss.c:3088 msgid "Second Factor (optional): " msgstr "" -#: src/sss_client/pam_sss.c:2680 src/sss_client/pam_sss.c:2855 +#: src/sss_client/pam_sss.c:2917 src/sss_client/pam_sss.c:3092 msgid "Second Factor: " msgstr "" -#: src/sss_client/pam_sss.c:2684 +#: src/sss_client/pam_sss.c:2921 msgid "Insert your passkey device, then press ENTER." msgstr "" -#: src/sss_client/pam_sss.c:2688 src/sss_client/pam_sss.c:2696 +#: src/sss_client/pam_sss.c:2925 src/sss_client/pam_sss.c:2933 msgid "Password: " msgstr "" -#: src/sss_client/pam_sss.c:2850 src/sss_client/pam_sss.c:2854 +#: src/sss_client/pam_sss.c:3087 src/sss_client/pam_sss.c:3091 msgid "First Factor (Current Password): " msgstr "" -#: src/sss_client/pam_sss.c:2874 +#: src/sss_client/pam_sss.c:3111 msgid "Current Password: " msgstr "" -#: src/sss_client/pam_sss.c:3248 +#: src/sss_client/pam_sss.c:3485 msgid "Password expired. Change your password now." msgstr "" @@ -2533,9 +2576,9 @@ msgstr "" #: src/tools/sssctl/sssctl_cache.c:835 src/tools/sssctl/sssctl_cache.c:918 #: src/tools/sssctl/sssctl_cache.c:950 src/tools/sssctl/sssctl_cache.c:956 #: src/tools/sssctl/sssctl_cache.c:1010 src/tools/sssctl/sssctl_cache.c:1034 -#: src/tools/sssctl/sssctl_cache.c:1085 src/tools/sssctl/sssctl_cache.c:1194 -#: src/tools/sssctl/sssctl_cache.c:1229 src/tools/sssctl/sssctl_cache.c:1235 -#: src/tools/sssctl/sssctl_cache.c:1244 +#: src/tools/sssctl/sssctl_cache.c:1085 src/tools/sssctl/sssctl_cache.c:1195 +#: src/tools/sssctl/sssctl_cache.c:1230 src/tools/sssctl/sssctl_cache.c:1236 +#: src/tools/sssctl/sssctl_cache.c:1245 msgid "talloc failed\n" msgstr "" @@ -2609,25 +2652,25 @@ msgstr "" msgid "Unable to remove downloaded GPO files: %s\n" msgstr "" -#: src/tools/sssctl/sssctl_cache.c:1165 +#: src/tools/sssctl/sssctl_cache.c:1166 #, c-format msgid "Failed to fetch cache entry: %s\n" msgstr "" -#: src/tools/sssctl/sssctl_cache.c:1170 +#: src/tools/sssctl/sssctl_cache.c:1171 msgid "Could not determine object domain\n" msgstr "" -#: src/tools/sssctl/sssctl_cache.c:1200 +#: src/tools/sssctl/sssctl_cache.c:1201 msgid "Could not find GUID attribute in GPO entry\n" msgstr "" -#: src/tools/sssctl/sssctl_cache.c:1206 +#: src/tools/sssctl/sssctl_cache.c:1207 #, c-format msgid "Failed to delete GPO: %s\n" msgstr "" -#: src/tools/sssctl/sssctl_cache.c:1210 +#: src/tools/sssctl/sssctl_cache.c:1211 #, c-format msgid "%s removed from cache\n" msgstr "" @@ -2715,39 +2758,39 @@ msgid "" "\"/my/path/sssd.conf\", the snippet dir \"/my/path/conf.d\" is used)" msgstr "" -#: src/tools/sssctl/sssctl_config.c:114 +#: src/tools/sssctl/sssctl_config.c:126 #, c-format msgid "File %1$s does not exist.\n" msgstr "" -#: src/tools/sssctl/sssctl_config.c:115 +#: src/tools/sssctl/sssctl_config.c:127 msgid "There is no configuration.\n" msgstr "" -#: src/tools/sssctl/sssctl_config.c:120 +#: src/tools/sssctl/sssctl_config.c:132 #, c-format msgid "Configuration validation failed: %s\n" msgstr "" -#: src/tools/sssctl/sssctl_config.c:121 +#: src/tools/sssctl/sssctl_config.c:133 msgid "Run with high debug level to see details.\n" msgstr "" -#: src/tools/sssctl/sssctl_config.c:130 -msgid "Failed to run validators" +#: src/tools/sssctl/sssctl_config.c:142 +msgid "Failed to run validators\n" msgstr "" -#: src/tools/sssctl/sssctl_config.c:134 +#: src/tools/sssctl/sssctl_config.c:146 #, c-format msgid "Issues identified by validators: %zu\n" msgstr "" -#: src/tools/sssctl/sssctl_config.c:145 +#: src/tools/sssctl/sssctl_config.c:157 #, c-format msgid "Messages generated during configuration merging: %zu\n" msgstr "" -#: src/tools/sssctl/sssctl_config.c:158 +#: src/tools/sssctl/sssctl_config.c:170 #, c-format msgid "Used configuration snippet files: %zu\n" msgstr "" diff --git a/po/nl.po b/po/nl.po index a5648c57764..637445e6ab1 100644 --- a/po/nl.po +++ b/po/nl.po @@ -13,8 +13,8 @@ msgid "" msgstr "" "Project-Id-Version: PACKAGE VERSION\n" "Report-Msgid-Bugs-To: sssd-devel@lists.fedorahosted.org\n" -"POT-Creation-Date: 2026-01-14 14:57+0000\n" -"PO-Revision-Date: 2026-04-23 16:43+0000\n" +"POT-Creation-Date: 2026-10-02 15:57+0000\n" +"PO-Revision-Date: 2026-10-05 16:42+0000\n" "Last-Translator: Anonymous \n" "Language-Team: Dutch \n" @@ -23,52 +23,52 @@ msgstr "" "Content-Type: text/plain; charset=UTF-8\n" "Content-Transfer-Encoding: 8bit\n" "Plural-Forms: nplurals=2; plural=n != 1;\n" -"X-Generator: Weblate 5.17\n" +"X-Generator: Weblate 2026.10\n" -#: src/config/SSSDConfig/sssdoptions.py:20 -#: src/config/SSSDConfig/sssdoptions.py:21 +#: src/config/SSSDConfig/sssdoptions.py:16 +#: src/config/SSSDConfig/sssdoptions.py:17 msgid "Set the verbosity of the debug logging" msgstr "Stel de verbositeit van de debug statements in" -#: src/config/SSSDConfig/sssdoptions.py:22 +#: src/config/SSSDConfig/sssdoptions.py:18 msgid "Include timestamps in debug logs" msgstr "Neem tijdstempels op in de debug logs" -#: src/config/SSSDConfig/sssdoptions.py:23 +#: src/config/SSSDConfig/sssdoptions.py:19 msgid "Include microseconds in timestamps in debug logs" msgstr "Voeg microseconden aan tijdstempel is debug log" -#: src/config/SSSDConfig/sssdoptions.py:24 +#: src/config/SSSDConfig/sssdoptions.py:20 msgid "Enable/disable debug backtrace" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:25 +#: src/config/SSSDConfig/sssdoptions.py:21 msgid "Watchdog timeout before restarting service" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:26 +#: src/config/SSSDConfig/sssdoptions.py:22 msgid "Command to start service" msgstr "Commando om service te starten" -#: src/config/SSSDConfig/sssdoptions.py:27 +#: src/config/SSSDConfig/sssdoptions.py:23 msgid "The number of file descriptors that may be opened by this responder" msgstr "" "Het aantal bestand descriptors die door deze beantwoorder geopend mogen " "worden" -#: src/config/SSSDConfig/sssdoptions.py:28 +#: src/config/SSSDConfig/sssdoptions.py:24 msgid "Idle time before automatic disconnection of a client" msgstr "Duur van inactiviteit voor het automatisch loskoppelen van een cliënt" -#: src/config/SSSDConfig/sssdoptions.py:29 +#: src/config/SSSDConfig/sssdoptions.py:25 msgid "Idle time before automatic shutdown of the responder" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:30 +#: src/config/SSSDConfig/sssdoptions.py:26 msgid "Always query all the caches before querying the Data Providers" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:31 +#: src/config/SSSDConfig/sssdoptions.py:27 msgid "" "When SSSD switches to offline mode the amount of time before it tries to go " "back online will increase based upon the time spent disconnected. This value " @@ -76,23 +76,23 @@ msgid "" "random_offset." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:36 +#: src/config/SSSDConfig/sssdoptions.py:32 msgid "SSSD Services to start" msgstr "SSSD Services die gestart moeten worden" -#: src/config/SSSDConfig/sssdoptions.py:37 +#: src/config/SSSDConfig/sssdoptions.py:33 msgid "SSSD Domains to start" msgstr "SSSD Domeinen die gestart moeten worden" -#: src/config/SSSDConfig/sssdoptions.py:38 +#: src/config/SSSDConfig/sssdoptions.py:34 msgid "Regex to parse username and domain" msgstr "Reguliere expressie om gebruikersnamen en domeinen te ontleden" -#: src/config/SSSDConfig/sssdoptions.py:39 +#: src/config/SSSDConfig/sssdoptions.py:35 msgid "Printf-compatible format for displaying fully-qualified names" msgstr "Printf-compatibel formaat voor het tonen van namen in volledige vorm" -#: src/config/SSSDConfig/sssdoptions.py:40 +#: src/config/SSSDConfig/sssdoptions.py:36 msgid "" "Directory on the filesystem where SSSD should store Kerberos replay cache " "files." @@ -100,41 +100,41 @@ msgstr "" "Map in het bestandssysteem waarin SSSD Kerberos replay cache bestanden moet " "opslaan." -#: src/config/SSSDConfig/sssdoptions.py:41 +#: src/config/SSSDConfig/sssdoptions.py:37 msgid "Domain to add to names without a domain component." msgstr "Domein toe te voegen aan namen zonder een domein component." -#: src/config/SSSDConfig/sssdoptions.py:42 +#: src/config/SSSDConfig/sssdoptions.py:38 msgid "The user to drop privileges to" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:43 +#: src/config/SSSDConfig/sssdoptions.py:39 msgid "Tune certificate verification" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:44 +#: src/config/SSSDConfig/sssdoptions.py:40 msgid "All spaces in group or user names will be replaced with this character" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:45 +#: src/config/SSSDConfig/sssdoptions.py:41 msgid "Tune sssd to honor or ignore netlink state changes" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:46 +#: src/config/SSSDConfig/sssdoptions.py:42 msgid "Enable or disable the implicit files domain" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:47 +#: src/config/SSSDConfig/sssdoptions.py:43 msgid "A specific order of the domains to be looked up" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:48 +#: src/config/SSSDConfig/sssdoptions.py:44 msgid "" "Controls if SSSD should monitor the state of resolv.conf to identify when it " "needs to update its internal DNS resolver." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:50 +#: src/config/SSSDConfig/sssdoptions.py:46 msgid "" "SSSD monitors the state of resolv.conf to identify when it needs to update " "its internal DNS resolver. By default, we will attempt to use inotify for " @@ -142,73 +142,74 @@ msgid "" "inotify cannot be used." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:53 +#: src/config/SSSDConfig/sssdoptions.py:49 msgid "Run PAC responder automatically for AD and IPA provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:54 +#: src/config/SSSDConfig/sssdoptions.py:50 msgid "Enable or disable core dumps for all SSSD processes." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:55 +#: src/config/SSSDConfig/sssdoptions.py:51 msgid "Tune passkey verification behavior" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:58 +#: src/config/SSSDConfig/sssdoptions.py:54 msgid "Enumeration cache timeout length (seconds)" msgstr "Enumeratie cache timeout duur (in seconden)" -#: src/config/SSSDConfig/sssdoptions.py:59 +#: src/config/SSSDConfig/sssdoptions.py:55 msgid "Entry cache background update timeout length (seconds)" msgstr "Entry cache achtergrond update timeout duur (in seconden)" -#: src/config/SSSDConfig/sssdoptions.py:60 -#: src/config/SSSDConfig/sssdoptions.py:125 +#: src/config/SSSDConfig/sssdoptions.py:56 +#: src/config/SSSDConfig/sssdoptions.py:124 msgid "Negative cache timeout length (seconds)" msgstr "Negatieve cache timeout duur (in seconden)" -#: src/config/SSSDConfig/sssdoptions.py:61 +#: src/config/SSSDConfig/sssdoptions.py:57 msgid "Users that SSSD should explicitly ignore" msgstr "Gebruikers die SSSD expliciet dient te negeren" -#: src/config/SSSDConfig/sssdoptions.py:62 +#: src/config/SSSDConfig/sssdoptions.py:58 msgid "Groups that SSSD should explicitly ignore" msgstr "Groepen die SSSD expliciet dient te negeren" -#: src/config/SSSDConfig/sssdoptions.py:63 +#: src/config/SSSDConfig/sssdoptions.py:59 msgid "Should filtered users appear in groups" msgstr "Dienen gefilterde gebruikers zichtbaar te zijn in groepen" -#: src/config/SSSDConfig/sssdoptions.py:64 +#: src/config/SSSDConfig/sssdoptions.py:60 msgid "The value of the password field the NSS provider should return" msgstr "De waarde van het wachtwoordveld die de NSS aanbieder terug moet geven" -#: src/config/SSSDConfig/sssdoptions.py:65 +#: src/config/SSSDConfig/sssdoptions.py:61 msgid "Override homedir value from the identity provider with this value" -msgstr "Overschrijf homedir waarde van de identiteit aanbieder met deze waarde " +msgstr "" +"Overschrijf homedir waarde van de identiteit aanbieder met deze waarde " -#: src/config/SSSDConfig/sssdoptions.py:66 +#: src/config/SSSDConfig/sssdoptions.py:62 msgid "" "Substitute empty homedir value from the identity provider with this value" msgstr "" "Vervang lege persoonlijke map waarde van de eindentiteitsaanbieder met deze " "waarde" -#: src/config/SSSDConfig/sssdoptions.py:67 +#: src/config/SSSDConfig/sssdoptions.py:63 msgid "Override shell value from the identity provider with this value" msgstr "Overschrijf shell waarde van identiteit provider met deze waarde" -#: src/config/SSSDConfig/sssdoptions.py:68 +#: src/config/SSSDConfig/sssdoptions.py:64 msgid "The list of shells users are allowed to log in with" msgstr "De lijst van shells waarmee ingelogd kan worden" -#: src/config/SSSDConfig/sssdoptions.py:69 +#: src/config/SSSDConfig/sssdoptions.py:65 msgid "" "The list of shells that will be vetoed, and replaced with the fallback shell" msgstr "" "De lijst van shells die verboden zijn, en vervangen door de fallback shell" -#: src/config/SSSDConfig/sssdoptions.py:70 +#: src/config/SSSDConfig/sssdoptions.py:66 msgid "" "If a shell stored in central directory is allowed but not available, use " "this fallback" @@ -216,60 +217,60 @@ msgstr "" "Als een shell opgeslagen in de centrale map toegestaan is, maar niet " "beschikbaar, gebruik dan deze" -#: src/config/SSSDConfig/sssdoptions.py:71 +#: src/config/SSSDConfig/sssdoptions.py:67 msgid "Shell to use if the provider does not list one" msgstr "Te gebruiken shell als de aanbieder er geen aangeeft " -#: src/config/SSSDConfig/sssdoptions.py:72 +#: src/config/SSSDConfig/sssdoptions.py:68 msgid "How long will be in-memory cache records valid" msgstr "Hoe lang zullen cache records in het geheugen geldig blijven" -#: src/config/SSSDConfig/sssdoptions.py:74 +#: src/config/SSSDConfig/sssdoptions.py:70 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for passwd requests" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:76 +#: src/config/SSSDConfig/sssdoptions.py:72 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for group requests" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:78 +#: src/config/SSSDConfig/sssdoptions.py:74 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for initgroups requests" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:79 +#: src/config/SSSDConfig/sssdoptions.py:75 msgid "" "The value of this option will be used in the expansion of the " "override_homedir option if the template contains the format string %H." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:81 +#: src/config/SSSDConfig/sssdoptions.py:77 msgid "" "Specifies time in seconds for which the list of subdomains will be " "considered valid." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:83 +#: src/config/SSSDConfig/sssdoptions.py:79 msgid "" "The entry cache can be set to automatically update entries in the background " "if they are requested beyond a percentage of the entry_cache_timeout value " "for the domain." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:88 +#: src/config/SSSDConfig/sssdoptions.py:84 msgid "How long to allow cached logins between online logins (days)" msgstr "Hoe lang zijn cached logins toegestaan tussen online logins (in dagen)" -#: src/config/SSSDConfig/sssdoptions.py:89 +#: src/config/SSSDConfig/sssdoptions.py:85 msgid "How many failed logins attempts are allowed when offline" msgstr "Hoe veel mislukte inlogpogingen zijn toegestaan in offline-modus" -#: src/config/SSSDConfig/sssdoptions.py:91 +#: src/config/SSSDConfig/sssdoptions.py:87 msgid "" "How long (minutes) to deny login after offline_failed_login_attempts has " "been reached" @@ -277,131 +278,139 @@ msgstr "" "Hoe lang (in minuten) logins weigeren nadat offline_failed_login_attempts is " "bereikt" -#: src/config/SSSDConfig/sssdoptions.py:92 +#: src/config/SSSDConfig/sssdoptions.py:88 msgid "What kind of messages are displayed to the user during authentication" msgstr "" "Welke boodschappen worden aan de gebruiker getoond tijdens authenticatie" -#: src/config/SSSDConfig/sssdoptions.py:93 +#: src/config/SSSDConfig/sssdoptions.py:89 msgid "Filter PAM responses sent to the pam_sss" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:94 +#: src/config/SSSDConfig/sssdoptions.py:90 msgid "How many seconds to keep identity information cached for PAM requests" msgstr "" "Hoeveel seconden moet de identiteit informatie in cache opgeslagen worden " "voor PAN aanvragen" -#: src/config/SSSDConfig/sssdoptions.py:95 +#: src/config/SSSDConfig/sssdoptions.py:91 msgid "How many days before password expiration a warning should be displayed" msgstr "" "Hoeveel dagen voor het verlopen van het wachtwoord moet een waarschuwing " "getoond worden" -#: src/config/SSSDConfig/sssdoptions.py:96 +#: src/config/SSSDConfig/sssdoptions.py:92 msgid "List of trusted uids or user's name" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:97 +#: src/config/SSSDConfig/sssdoptions.py:93 msgid "List of domains accessible even for untrusted users." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:98 +#: src/config/SSSDConfig/sssdoptions.py:94 msgid "Message printed when user account is expired." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:99 +#: src/config/SSSDConfig/sssdoptions.py:95 msgid "Message printed when user account is locked." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:100 +#: src/config/SSSDConfig/sssdoptions.py:96 msgid "Allow certificate based/Smartcard authentication." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:101 +#: src/config/SSSDConfig/sssdoptions.py:97 msgid "Path to certificate database with PKCS#11 modules." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:102 +#: src/config/SSSDConfig/sssdoptions.py:98 #, fuzzy msgid "Tune certificate verification for PAM authentication." msgstr "Vereis verificatie van het TLS-certificaat" -#: src/config/SSSDConfig/sssdoptions.py:103 +#: src/config/SSSDConfig/sssdoptions.py:99 msgid "How many seconds will pam_sss wait for p11_child to finish" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:104 +#: src/config/SSSDConfig/sssdoptions.py:100 msgid "Which PAM services are permitted to contact application domains" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:105 +#: src/config/SSSDConfig/sssdoptions.py:101 msgid "Allowed services for using smartcards" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:106 +#: src/config/SSSDConfig/sssdoptions.py:102 msgid "Additional timeout to wait for a card if requested" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:107 +#: src/config/SSSDConfig/sssdoptions.py:103 msgid "" "PKCS#11 URI to restrict the selection of devices for Smartcard authentication" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:108 +#: src/config/SSSDConfig/sssdoptions.py:104 msgid "When shall the PAM responder force an initgroups request" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:109 +#: src/config/SSSDConfig/sssdoptions.py:105 msgid "List of PAM services that are allowed to authenticate with GSSAPI." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:110 +#: src/config/SSSDConfig/sssdoptions.py:106 msgid "Whether to match authenticated UPN with target user" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:111 +#: src/config/SSSDConfig/sssdoptions.py:107 msgid "" "List of pairs : that must be enforced " "for PAM access with GSSAPI authentication" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:113 +#: src/config/SSSDConfig/sssdoptions.py:109 +msgid "" +"List of triples :: that assigns " +"additional information from the Kerberos ticket to an authentication " +"indicator." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:112 msgid "Allow passkey device authentication." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:114 +#: src/config/SSSDConfig/sssdoptions.py:113 msgid "How many seconds will pam_sss wait for passkey_child to finish" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:115 +#: src/config/SSSDConfig/sssdoptions.py:114 msgid "Enable debugging in the libfido2 library" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:116 +#: src/config/SSSDConfig/sssdoptions.py:115 msgid "Enable JSON protocol for authentication methods selection." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:119 +#: src/config/SSSDConfig/sssdoptions.py:118 msgid "Whether to evaluate the time-based attributes in sudo rules" msgstr "" "Of de tijd-gebaseerde attributen in sudo regels moeten worden geëvalueerd" -#: src/config/SSSDConfig/sssdoptions.py:120 +#: src/config/SSSDConfig/sssdoptions.py:119 msgid "If true, SSSD will switch back to lower-wins ordering logic" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:121 +#: src/config/SSSDConfig/sssdoptions.py:120 msgid "" "Maximum number of rules that can be refreshed at once. If this is exceeded, " "full refresh is performed." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:128 +#: src/config/SSSDConfig/sssdoptions.py:127 msgid "Whether to hash host names and addresses in the known_hosts file" -msgstr "Moeten host namen en adressen gehashd worden in het known_hosts bestand" +msgstr "" +"Moeten host namen en adressen gehashd worden in het known_hosts bestand" -#: src/config/SSSDConfig/sssdoptions.py:129 +#: src/config/SSSDConfig/sssdoptions.py:128 msgid "" "How many seconds to keep a host in the known_hosts file after its host keys " "were requested" @@ -409,145 +418,145 @@ msgstr "" "Hoeveel seconden moet een host in het known_hosts bestand blijven nadat de " "host sleutels ervan werden aangevraagd" -#: src/config/SSSDConfig/sssdoptions.py:131 +#: src/config/SSSDConfig/sssdoptions.py:130 msgid "Path to storage of trusted CA certificates" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:132 +#: src/config/SSSDConfig/sssdoptions.py:131 msgid "Allow to generate ssh-keys from certificates" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:133 +#: src/config/SSSDConfig/sssdoptions.py:132 msgid "" "Use the following matching rules to filter the certificates for ssh-key " "generation" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:137 +#: src/config/SSSDConfig/sssdoptions.py:136 msgid "List of UIDs or user names allowed to access the PAC responder" msgstr "" "Lijst met UID's of gebruikersnamen waarvoor toegang tot de PAC responder " "toegestaan is" -#: src/config/SSSDConfig/sssdoptions.py:138 +#: src/config/SSSDConfig/sssdoptions.py:137 msgid "How long the PAC data is considered valid" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:139 +#: src/config/SSSDConfig/sssdoptions.py:138 msgid "Validate the PAC" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:142 +#: src/config/SSSDConfig/sssdoptions.py:141 msgid "List of user attributes the InfoPipe is allowed to publish" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:145 +#: src/config/SSSDConfig/sssdoptions.py:144 msgid "" "One of the following strings specifying the scope of session recording: none " "- No users are recorded. some - Users/groups specified by users and groups " "options are recorded. all - All users are recorded." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:148 +#: src/config/SSSDConfig/sssdoptions.py:147 msgid "" "A comma-separated list of users which should have session recording enabled. " "Matches user names as returned by NSS. I.e. after the possible space " "replacement, case changes, etc." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:150 +#: src/config/SSSDConfig/sssdoptions.py:149 msgid "" "A comma-separated list of groups, members of which should have session " "recording enabled. Matches group names as returned by NSS. I.e. after the " "possible space replacement, case changes, etc." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:153 +#: src/config/SSSDConfig/sssdoptions.py:152 msgid "" "A comma-separated list of users to be excluded from recording, only when " "scope=all" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:154 +#: src/config/SSSDConfig/sssdoptions.py:153 msgid "" "A comma-separated list of groups, members of which should be excluded from " "recording, only when scope=all. " msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:158 +#: src/config/SSSDConfig/sssdoptions.py:157 msgid "Identity provider" msgstr "Identiteitaanbieder" -#: src/config/SSSDConfig/sssdoptions.py:159 +#: src/config/SSSDConfig/sssdoptions.py:158 msgid "Authentication provider" msgstr "Authentiecatieaanbieder" -#: src/config/SSSDConfig/sssdoptions.py:160 +#: src/config/SSSDConfig/sssdoptions.py:159 msgid "Access control provider" msgstr "Toegangscontroleaanbieder" -#: src/config/SSSDConfig/sssdoptions.py:161 +#: src/config/SSSDConfig/sssdoptions.py:160 msgid "Password change provider" msgstr "Wachtwoordwijzigingsaanbieder" -#: src/config/SSSDConfig/sssdoptions.py:162 +#: src/config/SSSDConfig/sssdoptions.py:161 msgid "SUDO provider" msgstr "SUDO provider" -#: src/config/SSSDConfig/sssdoptions.py:163 +#: src/config/SSSDConfig/sssdoptions.py:162 msgid "Autofs provider" msgstr "Autofs provider" -#: src/config/SSSDConfig/sssdoptions.py:164 +#: src/config/SSSDConfig/sssdoptions.py:163 msgid "Host identity provider" msgstr "Host identity provider" -#: src/config/SSSDConfig/sssdoptions.py:165 +#: src/config/SSSDConfig/sssdoptions.py:164 msgid "SELinux provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:166 +#: src/config/SSSDConfig/sssdoptions.py:165 msgid "Session management provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:167 +#: src/config/SSSDConfig/sssdoptions.py:166 msgid "Resolver provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:170 +#: src/config/SSSDConfig/sssdoptions.py:169 msgid "Whether the domain is usable by the OS or by applications" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:171 +#: src/config/SSSDConfig/sssdoptions.py:170 #, fuzzy msgid "Enable or disable the domain" msgstr "Schakel authenticatiegegevensvalidatie in" -#: src/config/SSSDConfig/sssdoptions.py:172 +#: src/config/SSSDConfig/sssdoptions.py:171 msgid "Minimum user ID" msgstr "Minimum gebruiker ID" -#: src/config/SSSDConfig/sssdoptions.py:173 +#: src/config/SSSDConfig/sssdoptions.py:172 msgid "Maximum user ID" msgstr "Maximum gebruiker ID" -#: src/config/SSSDConfig/sssdoptions.py:174 +#: src/config/SSSDConfig/sssdoptions.py:173 msgid "Enable enumerating all users/groups" msgstr "Schakel enumeratie van alle gebruikers/groepen" -#: src/config/SSSDConfig/sssdoptions.py:175 +#: src/config/SSSDConfig/sssdoptions.py:174 msgid "Cache credentials for offline login" msgstr "Cache inloggegevens voor offline gebruik" -#: src/config/SSSDConfig/sssdoptions.py:176 +#: src/config/SSSDConfig/sssdoptions.py:175 msgid "Display users/groups in fully-qualified form" msgstr "Laat gebruikers/groepen in volledige vorm zien" -#: src/config/SSSDConfig/sssdoptions.py:177 +#: src/config/SSSDConfig/sssdoptions.py:176 msgid "Don't include group members in group lookups" msgstr "Neem groepsleden niet mee in groep zoekacties" -#: src/config/SSSDConfig/sssdoptions.py:178 +#: src/config/SSSDConfig/sssdoptions.py:177 #: src/config/SSSDConfig/sssdoptions.py:190 #: src/config/SSSDConfig/sssdoptions.py:191 #: src/config/SSSDConfig/sssdoptions.py:192 @@ -558,53 +567,57 @@ msgstr "Neem groepsleden niet mee in groep zoekacties" msgid "Entry cache timeout length (seconds)" msgstr "Entry cache timeout duur (in seconden)" -#: src/config/SSSDConfig/sssdoptions.py:179 +#: src/config/SSSDConfig/sssdoptions.py:178 msgid "" "Restrict or prefer a specific address family when performing DNS lookups" msgstr "" "Beperk of geef de voorkeur aan een specifieke adresfamilie wanneer er DNS-" "lookups uitgevoerd worden" -#: src/config/SSSDConfig/sssdoptions.py:180 +#: src/config/SSSDConfig/sssdoptions.py:179 msgid "How long to keep cached entries after last successful login (days)" msgstr "" "Hoe lang blijven gegevens opgeslagen na een succesvolle login (in dagen)" -#: src/config/SSSDConfig/sssdoptions.py:181 +#: src/config/SSSDConfig/sssdoptions.py:180 msgid "" "How long should SSSD talk to single DNS server before trying next server " "(miliseconds)" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:183 +#: src/config/SSSDConfig/sssdoptions.py:182 msgid "How long should keep trying to resolve single DNS query (seconds)" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:184 +#: src/config/SSSDConfig/sssdoptions.py:183 msgid "How long to wait for replies from DNS when resolving servers (seconds)" msgstr "" "Hoe lang te wachten op antwoord van de DSN bij het opzoeken van servers (in " "seconden)" -#: src/config/SSSDConfig/sssdoptions.py:185 +#: src/config/SSSDConfig/sssdoptions.py:184 msgid "The domain part of service discovery DNS query" msgstr "Het domeingedeelte van DNS queries die service discovery uitvoeren" -#: src/config/SSSDConfig/sssdoptions.py:186 +#: src/config/SSSDConfig/sssdoptions.py:185 msgid "" "Specifies the interval, in seconds, that SSSD waits before attempting to " "reconnect to the primary server after a successful connection to the backup " "server" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:188 +#: src/config/SSSDConfig/sssdoptions.py:187 msgid "Override GID value from the identity provider with this value" msgstr "Overschrijf GID waarde van de identiteit aanbieder met deze waarde" -#: src/config/SSSDConfig/sssdoptions.py:189 +#: src/config/SSSDConfig/sssdoptions.py:188 msgid "Treat usernames as case sensitive" msgstr "Behandel gebruikersnamen als hoofdlettergevoelig" +#: src/config/SSSDConfig/sssdoptions.py:189 +msgid "Lookups by ID are expensive or do not work at all" +msgstr "" + #: src/config/SSSDConfig/sssdoptions.py:197 msgid "How often should expired entries be refreshed in background" msgstr "Hoe vaak moeten verlopen ingangen op de achtergrond ververst worden" @@ -840,7 +853,7 @@ msgid "Search base for SUBID ranges" msgstr "Zoek basis voor HBAC gerelateerde objecten" #: src/config/SSSDConfig/sssdoptions.py:259 -#: src/config/SSSDConfig/sssdoptions.py:506 +#: src/config/SSSDConfig/sssdoptions.py:512 msgid "Which rules should be used to evaluate access control" msgstr "" "Welke regels moeten gebruikt worden voor de evaluatie van toegangscontrole" @@ -983,7 +996,7 @@ msgid "Enable DNS sites - location based service discovery" msgstr "Zet DNS sites aan - locatie gebaseerde service ontdekking" #: src/config/SSSDConfig/sssdoptions.py:301 -#: src/config/SSSDConfig/sssdoptions.py:504 +#: src/config/SSSDConfig/sssdoptions.py:510 msgid "LDAP filter to determine access privileges" msgstr "LDAP-filter om toegangsprivileges mee te bepalen" @@ -1417,7 +1430,7 @@ msgid "UUID attribute" msgstr "" #: src/config/SSSDConfig/sssdoptions.py:423 -#: src/config/SSSDConfig/sssdoptions.py:464 +#: src/config/SSSDConfig/sssdoptions.py:470 msgid "objectSID attribute" msgstr "objectSID attribuut" @@ -1541,177 +1554,206 @@ msgstr "" msgid "A list of extra attributes to download along with the user entry" msgstr "" +#: src/config/SSSDConfig/sssdoptions.py:456 +msgid "The object class of an subid entry in LDAP." +msgstr "" + #: src/config/SSSDConfig/sssdoptions.py:457 +#, fuzzy +msgid "Subordinate user ID count attribute" +msgstr "Sudo regel gebruiker attribuut" + +#: src/config/SSSDConfig/sssdoptions.py:458 +#, fuzzy +msgid "Subordinate group ID count attribute" +msgstr "Sudo regel optie attribuut" + +#: src/config/SSSDConfig/sssdoptions.py:459 +#, fuzzy +msgid "User ID range start value attribute" +msgstr "Username-attribuut" + +#: src/config/SSSDConfig/sssdoptions.py:460 +#, fuzzy +msgid "Group ID range start value attribute" +msgstr "Automounter map ingavewaarde attribuut" + +#: src/config/SSSDConfig/sssdoptions.py:461 +msgid "Owner of an entry" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:463 msgid "Base DN for group lookups" msgstr "Basis DN voor groep opzoeken" -#: src/config/SSSDConfig/sssdoptions.py:458 +#: src/config/SSSDConfig/sssdoptions.py:464 msgid "Objectclass for groups" msgstr "Objectklasse voor groepen" -#: src/config/SSSDConfig/sssdoptions.py:459 +#: src/config/SSSDConfig/sssdoptions.py:465 msgid "Group name" msgstr "Groepsnaam" -#: src/config/SSSDConfig/sssdoptions.py:460 +#: src/config/SSSDConfig/sssdoptions.py:466 msgid "Group password" msgstr "Groep wachtwoord" -#: src/config/SSSDConfig/sssdoptions.py:461 +#: src/config/SSSDConfig/sssdoptions.py:467 msgid "GID attribute" msgstr "GID attribuut" -#: src/config/SSSDConfig/sssdoptions.py:462 +#: src/config/SSSDConfig/sssdoptions.py:468 msgid "Group member attribute" msgstr "Groep deelnemer attribuut" -#: src/config/SSSDConfig/sssdoptions.py:463 +#: src/config/SSSDConfig/sssdoptions.py:469 msgid "Group UUID attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:465 +#: src/config/SSSDConfig/sssdoptions.py:471 msgid "Modification time attribute for groups" msgstr "Verandertijd attribuut voor groepen" -#: src/config/SSSDConfig/sssdoptions.py:466 +#: src/config/SSSDConfig/sssdoptions.py:472 msgid "Type of the group and other flags" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:467 +#: src/config/SSSDConfig/sssdoptions.py:473 msgid "The LDAP group external member attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:468 +#: src/config/SSSDConfig/sssdoptions.py:474 msgid "Maximum nesting level SSSD will follow" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:469 +#: src/config/SSSDConfig/sssdoptions.py:475 msgid "Filter for group lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:470 +#: src/config/SSSDConfig/sssdoptions.py:476 msgid "Scope of group lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:472 +#: src/config/SSSDConfig/sssdoptions.py:478 msgid "Base DN for netgroup lookups" msgstr "Basis DN voor netgroep opzoeken" -#: src/config/SSSDConfig/sssdoptions.py:473 +#: src/config/SSSDConfig/sssdoptions.py:479 msgid "Objectclass for netgroups" msgstr "Objectklasse voor netgroepen" -#: src/config/SSSDConfig/sssdoptions.py:474 +#: src/config/SSSDConfig/sssdoptions.py:480 msgid "Netgroup name" msgstr "Netgroep naam" -#: src/config/SSSDConfig/sssdoptions.py:475 +#: src/config/SSSDConfig/sssdoptions.py:481 msgid "Netgroups members attribute" msgstr "Netgroep leden attribuut" -#: src/config/SSSDConfig/sssdoptions.py:476 +#: src/config/SSSDConfig/sssdoptions.py:482 msgid "Netgroup triple attribute" msgstr "Netgroep triple attibuut" -#: src/config/SSSDConfig/sssdoptions.py:477 +#: src/config/SSSDConfig/sssdoptions.py:483 msgid "Modification time attribute for netgroups" msgstr "Verandertijd attribuut voor netgroepen" -#: src/config/SSSDConfig/sssdoptions.py:479 +#: src/config/SSSDConfig/sssdoptions.py:485 msgid "Base DN for service lookups" msgstr "Basis DN voor service lookups" -#: src/config/SSSDConfig/sssdoptions.py:480 +#: src/config/SSSDConfig/sssdoptions.py:486 msgid "Objectclass for services" msgstr "Objectclass voor services" -#: src/config/SSSDConfig/sssdoptions.py:481 +#: src/config/SSSDConfig/sssdoptions.py:487 msgid "Service name attribute" msgstr "Service naam attribuut" -#: src/config/SSSDConfig/sssdoptions.py:482 +#: src/config/SSSDConfig/sssdoptions.py:488 msgid "Service port attribute" msgstr "Service port attribuut" -#: src/config/SSSDConfig/sssdoptions.py:483 +#: src/config/SSSDConfig/sssdoptions.py:489 msgid "Service protocol attribute" msgstr "Service protocol attribuut" -#: src/config/SSSDConfig/sssdoptions.py:485 +#: src/config/SSSDConfig/sssdoptions.py:491 msgid "Lower bound for ID-mapping" msgstr "Ondergrens voor ID-mapping" -#: src/config/SSSDConfig/sssdoptions.py:486 +#: src/config/SSSDConfig/sssdoptions.py:492 msgid "Upper bound for ID-mapping" msgstr "Bovengrens voor ID-mapping" -#: src/config/SSSDConfig/sssdoptions.py:487 +#: src/config/SSSDConfig/sssdoptions.py:493 msgid "Number of IDs for each slice when ID-mapping" msgstr "Aantal ID's voor elk segment bij ID-mapping" -#: src/config/SSSDConfig/sssdoptions.py:488 +#: src/config/SSSDConfig/sssdoptions.py:494 msgid "Use autorid-compatible algorithm for ID-mapping" msgstr "Gebruik autorid-compatibel algoritme voor ID-mapping" -#: src/config/SSSDConfig/sssdoptions.py:489 +#: src/config/SSSDConfig/sssdoptions.py:495 msgid "Name of the default domain for ID-mapping" msgstr "Naam van het standaard domein voor ID-mapping" -#: src/config/SSSDConfig/sssdoptions.py:490 +#: src/config/SSSDConfig/sssdoptions.py:496 msgid "SID of the default domain for ID-mapping" msgstr "SID van het standaard domein voor ID-mapping" -#: src/config/SSSDConfig/sssdoptions.py:491 +#: src/config/SSSDConfig/sssdoptions.py:497 msgid "Number of secondary slices" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:493 +#: src/config/SSSDConfig/sssdoptions.py:499 msgid "Whether to use Token-Groups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:494 +#: src/config/SSSDConfig/sssdoptions.py:500 msgid "Set lower boundary for allowed IDs from the LDAP server" msgstr "Laagste grens instellen voor toegestane id's van de LDAP-server" -#: src/config/SSSDConfig/sssdoptions.py:495 +#: src/config/SSSDConfig/sssdoptions.py:501 msgid "Set upper boundary for allowed IDs from the LDAP server" msgstr "Hoogste grens instellen voor toegestane id's van de LDAP-server" -#: src/config/SSSDConfig/sssdoptions.py:496 +#: src/config/SSSDConfig/sssdoptions.py:502 msgid "DN for ppolicy queries" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:497 +#: src/config/SSSDConfig/sssdoptions.py:503 msgid "How many maximum entries to fetch during a wildcard request" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:498 +#: src/config/SSSDConfig/sssdoptions.py:504 msgid "Set libldap debug level" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:501 +#: src/config/SSSDConfig/sssdoptions.py:507 msgid "Policy to evaluate the password expiration" msgstr "Policy om wacthwoordverloop mee te evalueren" -#: src/config/SSSDConfig/sssdoptions.py:505 +#: src/config/SSSDConfig/sssdoptions.py:511 msgid "Which attributes shall be used to evaluate if an account is expired" msgstr "" "Welke attributen worden gebruikt voor evaluatie als het account verlopen is" -#: src/config/SSSDConfig/sssdoptions.py:509 +#: src/config/SSSDConfig/sssdoptions.py:515 msgid "URI of an LDAP server where password changes are allowed" -msgstr "URI van een LDAP server waarop wachtwoord veranderingen toegestaan zijn" +msgstr "" +"URI van een LDAP server waarop wachtwoord veranderingen toegestaan zijn" -#: src/config/SSSDConfig/sssdoptions.py:510 +#: src/config/SSSDConfig/sssdoptions.py:516 msgid "URI of a backup LDAP server where password changes are allowed" msgstr "" "URI van een back-up LDAP server waar wachtwoord veranderingen toegestaan zijn" -#: src/config/SSSDConfig/sssdoptions.py:511 +#: src/config/SSSDConfig/sssdoptions.py:517 msgid "DNS service name for LDAP password change server" msgstr "DNS service naam voor LDAP wachtwoord verander server" -#: src/config/SSSDConfig/sssdoptions.py:512 +#: src/config/SSSDConfig/sssdoptions.py:518 msgid "" "Whether to update the ldap_user_shadow_last_change attribute after a " "password change" @@ -1719,27 +1761,27 @@ msgstr "" "Moet het ldap_user_shadow_last_change attribuut vernieuwd worden na een " "wachtwoordwijziging" -#: src/config/SSSDConfig/sssdoptions.py:516 +#: src/config/SSSDConfig/sssdoptions.py:522 msgid "Base DN for sudo rules lookups" msgstr "Basis DN voor sudo regels lookups" -#: src/config/SSSDConfig/sssdoptions.py:517 +#: src/config/SSSDConfig/sssdoptions.py:523 msgid "Automatic full refresh period" msgstr "Automatische volledige ververs periode" -#: src/config/SSSDConfig/sssdoptions.py:518 +#: src/config/SSSDConfig/sssdoptions.py:524 msgid "Automatic smart refresh period" msgstr "Automatische slimme ververs periode" -#: src/config/SSSDConfig/sssdoptions.py:519 +#: src/config/SSSDConfig/sssdoptions.py:525 msgid "Smart and full refresh random offset" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:520 +#: src/config/SSSDConfig/sssdoptions.py:526 msgid "Whether to filter rules by hostname, IP addresses and network" msgstr "Moeten regels gefilterd worden volgens hostnaam, IP adres en netwerk" -#: src/config/SSSDConfig/sssdoptions.py:521 +#: src/config/SSSDConfig/sssdoptions.py:527 msgid "" "Hostnames and/or fully qualified domain names of this machine to filter sudo " "rules" @@ -1747,190 +1789,190 @@ msgstr "" "Hostnamen en/of volledig gekwalificeerde domeinnamen van deze machine voor " "het filteren van sudo regels" -#: src/config/SSSDConfig/sssdoptions.py:522 +#: src/config/SSSDConfig/sssdoptions.py:528 msgid "IPv4 or IPv6 addresses or network of this machine to filter sudo rules" msgstr "" "IPv4 of IPv6 adressen of netwerk van deze machine voor het filteren van sudo " "regels" -#: src/config/SSSDConfig/sssdoptions.py:523 +#: src/config/SSSDConfig/sssdoptions.py:529 msgid "Whether to include rules that contains netgroup in host attribute" msgstr "" "Moeten regels toegevoegd worden die netgroep bevatten in host attribuut " -#: src/config/SSSDConfig/sssdoptions.py:524 +#: src/config/SSSDConfig/sssdoptions.py:530 msgid "" "Whether to include rules that contains regular expression in host attribute" msgstr "" "Moeten regels toegevoegd worden die regulaire expressie bevatten in host " "attribuut " -#: src/config/SSSDConfig/sssdoptions.py:525 +#: src/config/SSSDConfig/sssdoptions.py:531 msgid "Object class for sudo rules" msgstr "Objectklasse voor sudo regels" -#: src/config/SSSDConfig/sssdoptions.py:526 +#: src/config/SSSDConfig/sssdoptions.py:532 msgid "Name of attribute that is used as object class for sudo rules" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:527 +#: src/config/SSSDConfig/sssdoptions.py:533 msgid "Sudo rule name" msgstr "Sudo regelnaam" -#: src/config/SSSDConfig/sssdoptions.py:528 +#: src/config/SSSDConfig/sssdoptions.py:534 msgid "Sudo rule command attribute" msgstr "Sudo regel opdracht attribuut" -#: src/config/SSSDConfig/sssdoptions.py:529 +#: src/config/SSSDConfig/sssdoptions.py:535 msgid "Sudo rule host attribute" msgstr "Sudo regel host attribuut" -#: src/config/SSSDConfig/sssdoptions.py:530 +#: src/config/SSSDConfig/sssdoptions.py:536 msgid "Sudo rule user attribute" msgstr "Sudo regel gebruiker attribuut" -#: src/config/SSSDConfig/sssdoptions.py:531 +#: src/config/SSSDConfig/sssdoptions.py:537 msgid "Sudo rule option attribute" msgstr "Sudo regel optie attribuut" -#: src/config/SSSDConfig/sssdoptions.py:532 +#: src/config/SSSDConfig/sssdoptions.py:538 msgid "Sudo rule runas attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:533 +#: src/config/SSSDConfig/sssdoptions.py:539 msgid "Sudo rule runasuser attribute" msgstr "Sudo regel runasuser attribuut" -#: src/config/SSSDConfig/sssdoptions.py:534 +#: src/config/SSSDConfig/sssdoptions.py:540 msgid "Sudo rule runasgroup attribute" msgstr "Sudo regel runasgroup attribuut" -#: src/config/SSSDConfig/sssdoptions.py:535 +#: src/config/SSSDConfig/sssdoptions.py:541 msgid "Sudo rule notbefore attribute" msgstr "Sudo regel notbefore attribuut" -#: src/config/SSSDConfig/sssdoptions.py:536 +#: src/config/SSSDConfig/sssdoptions.py:542 msgid "Sudo rule notafter attribute" msgstr "Sudo regel notafter attribuut" -#: src/config/SSSDConfig/sssdoptions.py:537 +#: src/config/SSSDConfig/sssdoptions.py:543 msgid "Sudo rule order attribute" msgstr "Sudo regel volgorde attribuut" -#: src/config/SSSDConfig/sssdoptions.py:540 +#: src/config/SSSDConfig/sssdoptions.py:546 msgid "Object class for automounter maps" msgstr "Object class voor automounter maps" -#: src/config/SSSDConfig/sssdoptions.py:541 +#: src/config/SSSDConfig/sssdoptions.py:547 msgid "Automounter map name attribute" msgstr "Automounter map naam attribuut" -#: src/config/SSSDConfig/sssdoptions.py:542 +#: src/config/SSSDConfig/sssdoptions.py:548 msgid "Object class for automounter map entries" msgstr "Objectklasse voor automounter map ingaven" -#: src/config/SSSDConfig/sssdoptions.py:543 +#: src/config/SSSDConfig/sssdoptions.py:549 msgid "Automounter map entry key attribute" msgstr "Automounter map sleutel ingave attribuut" -#: src/config/SSSDConfig/sssdoptions.py:544 +#: src/config/SSSDConfig/sssdoptions.py:550 msgid "Automounter map entry value attribute" msgstr "Automounter map ingavewaarde attribuut" -#: src/config/SSSDConfig/sssdoptions.py:545 +#: src/config/SSSDConfig/sssdoptions.py:551 msgid "Base DN for automounter map lookups" msgstr "Basis DN voor automounter kaart opzoeken" -#: src/config/SSSDConfig/sssdoptions.py:546 +#: src/config/SSSDConfig/sssdoptions.py:552 msgid "The name of the automount master map in LDAP." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:549 +#: src/config/SSSDConfig/sssdoptions.py:555 msgid "Base DN for IP hosts lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:550 +#: src/config/SSSDConfig/sssdoptions.py:556 msgid "Object class for IP hosts" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:551 +#: src/config/SSSDConfig/sssdoptions.py:557 msgid "IP host name attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:552 +#: src/config/SSSDConfig/sssdoptions.py:558 msgid "IP host number (address) attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:553 +#: src/config/SSSDConfig/sssdoptions.py:559 msgid "IP host entryUSN attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:554 +#: src/config/SSSDConfig/sssdoptions.py:560 msgid "Base DN for IP networks lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:555 +#: src/config/SSSDConfig/sssdoptions.py:561 msgid "Object class for IP networks" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:556 +#: src/config/SSSDConfig/sssdoptions.py:562 msgid "IP network name attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:557 +#: src/config/SSSDConfig/sssdoptions.py:563 msgid "IP network number (address) attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:558 +#: src/config/SSSDConfig/sssdoptions.py:564 msgid "IP network entryUSN attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:561 +#: src/config/SSSDConfig/sssdoptions.py:567 msgid "Comma separated list of allowed users" msgstr "Kommagescheiden lijst van toegestane gebruikers" -#: src/config/SSSDConfig/sssdoptions.py:562 +#: src/config/SSSDConfig/sssdoptions.py:568 msgid "Comma separated list of prohibited users" msgstr "Kommagescheiden lijst van geweigerde gebruikers" -#: src/config/SSSDConfig/sssdoptions.py:563 +#: src/config/SSSDConfig/sssdoptions.py:569 msgid "" "Comma separated list of groups that are allowed to log in. This applies only " "to groups within this SSSD domain. Local groups are not evaluated." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:565 +#: src/config/SSSDConfig/sssdoptions.py:571 msgid "" "Comma separated list of groups that are explicitly denied access. This " "applies only to groups within this SSSD domain. Local groups are not " "evaluated." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:569 +#: src/config/SSSDConfig/sssdoptions.py:575 msgid "The number of preforked proxy children." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:572 +#: src/config/SSSDConfig/sssdoptions.py:578 msgid "The name of the NSS library to use" msgstr "De naam van de NSS-bibliotheek die gebruikt wordt" -#: src/config/SSSDConfig/sssdoptions.py:573 +#: src/config/SSSDConfig/sssdoptions.py:579 msgid "The name of the NSS library to use for hosts and networks lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:574 +#: src/config/SSSDConfig/sssdoptions.py:580 msgid "Whether to look up canonical group name from cache if possible" msgstr "Moet indien mogelijk canonieke groepsnaam in cache opgezocht worden " -#: src/config/SSSDConfig/sssdoptions.py:577 +#: src/config/SSSDConfig/sssdoptions.py:583 msgid "PAM stack to use" msgstr "PAM-stack die gebruikt wordt" -#: src/config/SSSDConfig/sssdoptions.py:580 +#: src/config/SSSDConfig/sssdoptions.py:586 msgid "Path of passwd file sources." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:581 +#: src/config/SSSDConfig/sssdoptions.py:587 msgid "Path of group file sources." msgstr "" @@ -1958,229 +2000,237 @@ msgstr "Het post-verwijder commando mislukte: %1$s\n" msgid "Option -i|--interactive is not allowed together with -D|--daemon\n" msgstr "" -#: src/monitor/monitor.c:1836 +#: src/monitor/monitor.c:1838 msgid "Failed to get initial capabilities\n" msgstr "" -#: src/monitor/monitor.c:1847 +#: src/monitor/monitor.c:1849 msgid "Non-root service user support isn't built. Can't run under %" msgstr "" -#: src/monitor/monitor.c:1864 +#: src/monitor/monitor.c:1866 #, c-format msgid "Can't read config: '%s'\n" msgstr "" -#: src/monitor/monitor.c:1876 +#: src/monitor/monitor.c:1878 #, c-format -msgid "Failed to boostrap SSSD 'monitor' process: %s" +msgid "Failed to bootstrap SSSD 'monitor' process: %s" msgstr "" -#: src/monitor/monitor.c:1971 +#: src/monitor/monitor.c:1973 msgid "Out of memory\n" msgstr "Het geheugen zit vol\n" -#: src/providers/krb5/krb5_child.c:4221 +#: src/providers/krb5/krb5_child.c:4316 msgid "Use anonymous PKINIT to request FAST armor ticket" msgstr "" -#: src/providers/krb5/krb5_child.c:4223 +#: src/providers/krb5/krb5_child.c:4318 msgid "Kerberos realm to use" msgstr "" -#: src/providers/krb5/krb5_child.c:4225 +#: src/providers/krb5/krb5_child.c:4320 msgid "Requested lifetime of the ticket" msgstr "" -#: src/providers/krb5/krb5_child.c:4227 +#: src/providers/krb5/krb5_child.c:4322 msgid "Requested renewable lifetime of the ticket" msgstr "" -#: src/providers/krb5/krb5_child.c:4229 +#: src/providers/krb5/krb5_child.c:4324 msgid "FAST options ('never', 'try', 'demand')" msgstr "" -#: src/providers/krb5/krb5_child.c:4232 +#: src/providers/krb5/krb5_child.c:4327 msgid "Specifies the server principal to use for FAST" msgstr "" -#: src/providers/krb5/krb5_child.c:4234 +#: src/providers/krb5/krb5_child.c:4329 msgid "Requests canonicalization of the principal name" msgstr "" -#: src/providers/krb5/krb5_child.c:4236 +#: src/providers/krb5/krb5_child.c:4331 msgid "Use custom version of krb5_get_init_creds_password" msgstr "" -#: src/providers/krb5/krb5_child.c:4238 +#: src/providers/krb5/krb5_child.c:4333 msgid "Check PAC flags" msgstr "" -#: src/providers/data_provider_be.c:790 +#: src/providers/krb5/krb5_child.c:4335 +msgid "Set environment variable (KEY=VALUE)" +msgstr "" + +#: src/providers/data_provider_be.c:786 msgid "Domain of the information provider (mandatory)" msgstr "Domein voor de informatie provider (verplicht)" -#: src/sss_client/common.c:1165 +#: src/sss_client/common.c:1208 #, fuzzy msgid "Socket has wrong ownership or permissions." msgstr "Publiek socket heeft verkeerde rechten of eigendom." -#: src/sss_client/common.c:1168 +#: src/sss_client/common.c:1211 msgid "Unexpected format of the server credential message." msgstr "Onverwacht formaat van het inloggegevensbericht van de server." -#: src/sss_client/common.c:1171 +#: src/sss_client/common.c:1214 #, fuzzy msgid "SSSD is not run by trusted user." msgstr "SSSD wordt niet door root gestart." -#: src/sss_client/common.c:1174 +#: src/sss_client/common.c:1217 msgid "SSSD socket does not exist." msgstr "" -#: src/sss_client/common.c:1177 +#: src/sss_client/common.c:1220 msgid "Cannot get stat of SSSD socket." msgstr "" -#: src/sss_client/common.c:1182 +#: src/sss_client/common.c:1225 msgid "An error occurred, but no description can be found." msgstr "" "Er is een fout opgetreden, maar er kan geen omschrijving gevonden worden." -#: src/sss_client/common.c:1188 +#: src/sss_client/common.c:1231 msgid "Unexpected error while looking for an error description" msgstr "Onverwachtte fout bij het opzoeken van een omschrijving" -#: src/sss_client/pam_sss.c:74 +#: src/sss_client/pam_sss.c:135 msgid "Permission denied. " msgstr "" -#: src/sss_client/pam_sss.c:75 src/sss_client/pam_sss.c:843 -#: src/sss_client/pam_sss.c:854 +#: src/sss_client/pam_sss.c:136 src/sss_client/pam_sss.c:921 +#: src/sss_client/pam_sss.c:932 msgid "Server message: " msgstr "Serverbericht:" -#: src/sss_client/pam_sss.c:76 +#: src/sss_client/pam_sss.c:137 msgid "" "Kerberos TGT will not be granted upon login, user experience will be " "affected." msgstr "" -#: src/sss_client/pam_sss.c:77 +#: src/sss_client/pam_sss.c:138 msgid "Enter PIN:" msgstr "" -#: src/sss_client/pam_sss.c:320 +#: src/sss_client/pam_sss.c:385 msgid "Passwords do not match" msgstr "Wachtwoorden komen niet overeen" -#: src/sss_client/pam_sss.c:508 +#: src/sss_client/pam_sss.c:584 msgid "Password reset by root is not supported." msgstr "Wachtwoorden als root wijzigen wordt niet ondersteund." -#: src/sss_client/pam_sss.c:549 +#: src/sss_client/pam_sss.c:625 msgid "Authenticated with cached credentials" msgstr "Geauthenticeerd met gecachte inloggegevens." -#: src/sss_client/pam_sss.c:550 +#: src/sss_client/pam_sss.c:626 msgid ", your cached password will expire at: " msgstr ", uw wachtwoord verloopt op:" -#: src/sss_client/pam_sss.c:580 +#: src/sss_client/pam_sss.c:656 #, c-format msgid "Your password has expired. You have %1$d grace login(s) remaining." msgstr "" "Je wachtwoord is verlopen. Je hebt nog slechts %1$d login(s) beschikbaar." -#: src/sss_client/pam_sss.c:630 +#: src/sss_client/pam_sss.c:706 #, c-format msgid "Your password will expire in %1$d %2$s." msgstr "Je wachtwoord zal verlopen in %1$d %2$s." -#: src/sss_client/pam_sss.c:633 +#: src/sss_client/pam_sss.c:709 #, fuzzy, c-format msgid "Your password has expired." msgstr "Je wachtwoord zal verlopen in %1$d %2$s." -#: src/sss_client/pam_sss.c:684 +#: src/sss_client/pam_sss.c:760 msgid "Authentication is denied until: " msgstr "Inloggen wordt geweigerd tot:" -#: src/sss_client/pam_sss.c:705 +#: src/sss_client/pam_sss.c:781 msgid "System is offline, password change not possible" msgstr "Systeem is offline, wachtwoord wijzigen niet mogelijk" -#: src/sss_client/pam_sss.c:720 +#: src/sss_client/pam_sss.c:796 msgid "" "After changing the OTP password, you need to log out and back in order to " "acquire a ticket" msgstr "" -#: src/sss_client/pam_sss.c:735 +#: src/sss_client/pam_sss.c:813 msgid "PIN locked" msgstr "" -#: src/sss_client/pam_sss.c:750 +#: src/sss_client/pam_sss.c:828 msgid "" "No Kerberos TGT granted as the server does not support this method. Your " "single-sign on(SSO) experience will be affected." msgstr "" -#: src/sss_client/pam_sss.c:840 src/sss_client/pam_sss.c:853 +#: src/sss_client/pam_sss.c:918 src/sss_client/pam_sss.c:931 msgid "Password change failed. " msgstr "Wijzigen van wachtwoord mislukt." -#: src/sss_client/pam_sss.c:1859 +#: src/sss_client/pam_sss.c:2028 #, c-format -msgid "Authenticate at %1$s and press ENTER." +msgid "Authenticate at \"%1$s\"." msgstr "" -#: src/sss_client/pam_sss.c:1862 +#: src/sss_client/pam_sss.c:2031 #, c-format -msgid "Authenticate with PIN %1$s at %2$s and press ENTER." +msgid "Authenticate with PIN \"%1$s\" at \"%2$s\"." msgstr "" -#: src/sss_client/pam_sss.c:2281 +#: src/sss_client/pam_sss.c:2470 msgid "Please (re)insert (different) Smartcard" msgstr "" -#: src/sss_client/pam_sss.c:2482 +#: src/sss_client/pam_sss.c:2700 msgid "New Password: " msgstr "Nieuw Wachtwoord: " -#: src/sss_client/pam_sss.c:2483 +#: src/sss_client/pam_sss.c:2701 msgid "Reenter new Password: " msgstr "Voer nieuw wachtwoord nogmaals in: " -#: src/sss_client/pam_sss.c:2676 src/sss_client/pam_sss.c:2679 +#: src/sss_client/pam_sss.c:2890 +msgid "Press ENTER to continue." +msgstr "" + +#: src/sss_client/pam_sss.c:2913 src/sss_client/pam_sss.c:2916 msgid "First Factor: " msgstr "" -#: src/sss_client/pam_sss.c:2677 src/sss_client/pam_sss.c:2851 +#: src/sss_client/pam_sss.c:2914 src/sss_client/pam_sss.c:3088 msgid "Second Factor (optional): " msgstr "" -#: src/sss_client/pam_sss.c:2680 src/sss_client/pam_sss.c:2855 +#: src/sss_client/pam_sss.c:2917 src/sss_client/pam_sss.c:3092 msgid "Second Factor: " msgstr "" -#: src/sss_client/pam_sss.c:2684 +#: src/sss_client/pam_sss.c:2921 msgid "Insert your passkey device, then press ENTER." msgstr "" -#: src/sss_client/pam_sss.c:2688 src/sss_client/pam_sss.c:2696 +#: src/sss_client/pam_sss.c:2925 src/sss_client/pam_sss.c:2933 msgid "Password: " msgstr "Wachtwoord: " -#: src/sss_client/pam_sss.c:2850 src/sss_client/pam_sss.c:2854 +#: src/sss_client/pam_sss.c:3087 src/sss_client/pam_sss.c:3091 msgid "First Factor (Current Password): " msgstr "" -#: src/sss_client/pam_sss.c:2874 +#: src/sss_client/pam_sss.c:3111 msgid "Current Password: " msgstr "Huidig wachtwoord:" -#: src/sss_client/pam_sss.c:3248 +#: src/sss_client/pam_sss.c:3485 msgid "Password expired. Change your password now." msgstr "Wachtwoord verlopen. Verander nu uw wachtwoord." @@ -2621,9 +2671,9 @@ msgstr "" #: src/tools/sssctl/sssctl_cache.c:835 src/tools/sssctl/sssctl_cache.c:918 #: src/tools/sssctl/sssctl_cache.c:950 src/tools/sssctl/sssctl_cache.c:956 #: src/tools/sssctl/sssctl_cache.c:1010 src/tools/sssctl/sssctl_cache.c:1034 -#: src/tools/sssctl/sssctl_cache.c:1085 src/tools/sssctl/sssctl_cache.c:1194 -#: src/tools/sssctl/sssctl_cache.c:1229 src/tools/sssctl/sssctl_cache.c:1235 -#: src/tools/sssctl/sssctl_cache.c:1244 +#: src/tools/sssctl/sssctl_cache.c:1085 src/tools/sssctl/sssctl_cache.c:1195 +#: src/tools/sssctl/sssctl_cache.c:1230 src/tools/sssctl/sssctl_cache.c:1236 +#: src/tools/sssctl/sssctl_cache.c:1245 msgid "talloc failed\n" msgstr "" @@ -2697,26 +2747,26 @@ msgstr "" msgid "Unable to remove downloaded GPO files: %s\n" msgstr "" -#: src/tools/sssctl/sssctl_cache.c:1165 +#: src/tools/sssctl/sssctl_cache.c:1166 #, c-format msgid "Failed to fetch cache entry: %s\n" msgstr "" -#: src/tools/sssctl/sssctl_cache.c:1170 +#: src/tools/sssctl/sssctl_cache.c:1171 #, fuzzy msgid "Could not determine object domain\n" msgstr "Kon beschikbare domeinen niet openen\n" -#: src/tools/sssctl/sssctl_cache.c:1200 +#: src/tools/sssctl/sssctl_cache.c:1201 msgid "Could not find GUID attribute in GPO entry\n" msgstr "" -#: src/tools/sssctl/sssctl_cache.c:1206 +#: src/tools/sssctl/sssctl_cache.c:1207 #, c-format msgid "Failed to delete GPO: %s\n" msgstr "" -#: src/tools/sssctl/sssctl_cache.c:1210 +#: src/tools/sssctl/sssctl_cache.c:1211 #, c-format msgid "%s removed from cache\n" msgstr "" @@ -2804,39 +2854,39 @@ msgid "" "\"/my/path/sssd.conf\", the snippet dir \"/my/path/conf.d\" is used)" msgstr "" -#: src/tools/sssctl/sssctl_config.c:114 +#: src/tools/sssctl/sssctl_config.c:126 #, c-format msgid "File %1$s does not exist.\n" msgstr "" -#: src/tools/sssctl/sssctl_config.c:115 +#: src/tools/sssctl/sssctl_config.c:127 msgid "There is no configuration.\n" msgstr "" -#: src/tools/sssctl/sssctl_config.c:120 +#: src/tools/sssctl/sssctl_config.c:132 #, fuzzy, c-format msgid "Configuration validation failed: %s\n" msgstr "Het post-verwijder commando mislukte: %1$s\n" -#: src/tools/sssctl/sssctl_config.c:121 +#: src/tools/sssctl/sssctl_config.c:133 msgid "Run with high debug level to see details.\n" msgstr "" -#: src/tools/sssctl/sssctl_config.c:130 -msgid "Failed to run validators" +#: src/tools/sssctl/sssctl_config.c:142 +msgid "Failed to run validators\n" msgstr "" -#: src/tools/sssctl/sssctl_config.c:134 +#: src/tools/sssctl/sssctl_config.c:146 #, c-format msgid "Issues identified by validators: %zu\n" msgstr "" -#: src/tools/sssctl/sssctl_config.c:145 +#: src/tools/sssctl/sssctl_config.c:157 #, c-format msgid "Messages generated during configuration merging: %zu\n" msgstr "" -#: src/tools/sssctl/sssctl_config.c:158 +#: src/tools/sssctl/sssctl_config.c:170 #, c-format msgid "Used configuration snippet files: %zu\n" msgstr "" diff --git a/po/pl.po b/po/pl.po index 80c1ff09bf5..fc21862c825 100644 --- a/po/pl.po +++ b/po/pl.po @@ -15,8 +15,8 @@ msgid "" msgstr "" "Project-Id-Version: PACKAGE VERSION\n" "Report-Msgid-Bugs-To: sssd-devel@lists.fedorahosted.org\n" -"POT-Creation-Date: 2026-01-14 14:57+0000\n" -"PO-Revision-Date: 2026-04-23 16:22+0000\n" +"POT-Creation-Date: 2026-10-02 15:57+0000\n" +"PO-Revision-Date: 2026-10-05 16:42+0000\n" "Last-Translator: Piotr Drąg \n" "Language-Team: Polish \n" @@ -26,82 +26,82 @@ msgstr "" "Content-Transfer-Encoding: 8bit\n" "Plural-Forms: nplurals=3; plural=n==1 ? 0 : n%10>=2 && n%10<=4 && (n%100<10 " "|| n%100>=20) ? 1 : 2;\n" -"X-Generator: Weblate 5.17\n" +"X-Generator: Weblate 2026.10\n" -#: src/config/SSSDConfig/sssdoptions.py:20 -#: src/config/SSSDConfig/sssdoptions.py:21 +#: src/config/SSSDConfig/sssdoptions.py:16 +#: src/config/SSSDConfig/sssdoptions.py:17 msgid "Set the verbosity of the debug logging" msgstr "Ustawia liczbę komunikatów dziennika debugowania" -#: src/config/SSSDConfig/sssdoptions.py:22 +#: src/config/SSSDConfig/sssdoptions.py:18 msgid "Include timestamps in debug logs" msgstr "Dołącza daty w dziennikach debugowania" -#: src/config/SSSDConfig/sssdoptions.py:23 +#: src/config/SSSDConfig/sssdoptions.py:19 msgid "Include microseconds in timestamps in debug logs" msgstr "Dołączanie mikrosekund w datach w dziennikach debugowania" -#: src/config/SSSDConfig/sssdoptions.py:24 +#: src/config/SSSDConfig/sssdoptions.py:20 msgid "Enable/disable debug backtrace" msgstr "Włącza/wyłącza wyjątek debugowania" -#: src/config/SSSDConfig/sssdoptions.py:25 +#: src/config/SSSDConfig/sssdoptions.py:21 msgid "Watchdog timeout before restarting service" msgstr "Czas oczekiwania watchdoga przed ponownym uruchomieniem usługi" -#: src/config/SSSDConfig/sssdoptions.py:26 +#: src/config/SSSDConfig/sssdoptions.py:22 msgid "Command to start service" msgstr "Polecenie do uruchomienia usługi" -#: src/config/SSSDConfig/sssdoptions.py:27 +#: src/config/SSSDConfig/sssdoptions.py:23 msgid "The number of file descriptors that may be opened by this responder" msgstr "" "Liczba deskryptorów plików, które mogą być otwarte przez ten program " "odpowiadający" -#: src/config/SSSDConfig/sssdoptions.py:28 +#: src/config/SSSDConfig/sssdoptions.py:24 msgid "Idle time before automatic disconnection of a client" msgstr "Czas bezczynności przed automatycznym rozłączeniem klienta" -#: src/config/SSSDConfig/sssdoptions.py:29 +#: src/config/SSSDConfig/sssdoptions.py:25 msgid "Idle time before automatic shutdown of the responder" msgstr "" "Czas bezczynności przed automatycznym wyłączeniem programu odpowiadającego" -#: src/config/SSSDConfig/sssdoptions.py:30 +#: src/config/SSSDConfig/sssdoptions.py:26 msgid "Always query all the caches before querying the Data Providers" msgstr "" "Odpytywanie wszystkich pamięci podręcznych za każdym razem przed " "odpytywaniem dostawców danych" -#: src/config/SSSDConfig/sssdoptions.py:31 +#: src/config/SSSDConfig/sssdoptions.py:27 msgid "" "When SSSD switches to offline mode the amount of time before it tries to go " "back online will increase based upon the time spent disconnected. This value " "is in seconds and calculated by the following: offline_timeout + " "random_offset." msgstr "" -"Kiedy SSSD przechodzi do trybu offline, czas zanim spróbuje przejść z " -"powrotem do trybu online zwiększy się o czas rozłączenia. Ta wartość jest w " -"sekundach i jest obliczana według: offline_timeout + random_offset." +"Kiedy SSSD przechodzi do trybu offline, czas zanim spróbuje przejść " +"z powrotem do trybu online zwiększy się o czas rozłączenia. Ta wartość jest " +"w sekundach i jest obliczana według: offline_timeout + random_offset." -#: src/config/SSSDConfig/sssdoptions.py:36 +#: src/config/SSSDConfig/sssdoptions.py:32 msgid "SSSD Services to start" msgstr "Usługi SSSD do uruchomienia" -#: src/config/SSSDConfig/sssdoptions.py:37 +#: src/config/SSSDConfig/sssdoptions.py:33 msgid "SSSD Domains to start" msgstr "Domeny SSSD do uruchomienia" -#: src/config/SSSDConfig/sssdoptions.py:38 +#: src/config/SSSDConfig/sssdoptions.py:34 msgid "Regex to parse username and domain" msgstr "Wyrażenie regularne do przetworzenia nazwy użytkownika i domeny" -#: src/config/SSSDConfig/sssdoptions.py:39 +#: src/config/SSSDConfig/sssdoptions.py:35 msgid "Printf-compatible format for displaying fully-qualified names" msgstr "Format zgodny z printf do wyświetlania w pełni kwalifikowanych nazw" -#: src/config/SSSDConfig/sssdoptions.py:40 +#: src/config/SSSDConfig/sssdoptions.py:36 msgid "" "Directory on the filesystem where SSSD should store Kerberos replay cache " "files." @@ -109,37 +109,37 @@ msgstr "" "Katalog w systemie plików, w którym SSSD ma przechowywać pliki pamięci " "podręcznej odtwarzania Kerberosa." -#: src/config/SSSDConfig/sssdoptions.py:41 +#: src/config/SSSDConfig/sssdoptions.py:37 msgid "Domain to add to names without a domain component." msgstr "Domeny do dodania do nazw bez składnika domeny." -#: src/config/SSSDConfig/sssdoptions.py:42 +#: src/config/SSSDConfig/sssdoptions.py:38 msgid "The user to drop privileges to" msgstr "Użytkownik, któremu porzucić uprawnienia" -#: src/config/SSSDConfig/sssdoptions.py:43 +#: src/config/SSSDConfig/sssdoptions.py:39 msgid "Tune certificate verification" msgstr "Dostraja sprawdzanie poprawności certyfikatów" -#: src/config/SSSDConfig/sssdoptions.py:44 +#: src/config/SSSDConfig/sssdoptions.py:40 msgid "All spaces in group or user names will be replaced with this character" msgstr "" "Wszystkie spacji w nazwach grup i użytkowników zostaną zastąpione tym znakiem" -#: src/config/SSSDConfig/sssdoptions.py:45 +#: src/config/SSSDConfig/sssdoptions.py:41 msgid "Tune sssd to honor or ignore netlink state changes" msgstr "" "Dostraja usługę SSSD, aby uwzględniała lub ignorowała zmiany stanu netlink" -#: src/config/SSSDConfig/sssdoptions.py:46 +#: src/config/SSSDConfig/sssdoptions.py:42 msgid "Enable or disable the implicit files domain" msgstr "Włącza lub wyłącza bezpośrednią domenę plików" -#: src/config/SSSDConfig/sssdoptions.py:47 +#: src/config/SSSDConfig/sssdoptions.py:43 msgid "A specific order of the domains to be looked up" msgstr "Konkretna kolejność domen do wyszukania" -#: src/config/SSSDConfig/sssdoptions.py:48 +#: src/config/SSSDConfig/sssdoptions.py:44 msgid "" "Controls if SSSD should monitor the state of resolv.conf to identify when it " "needs to update its internal DNS resolver." @@ -147,7 +147,7 @@ msgstr "" "Steruje, czy SSSD ma monitorować stan pliku resolv.conf do identyfikacji, " "kiedy musi zaktualizować swój wewnętrzny program rozwiązujący DNS." -#: src/config/SSSDConfig/sssdoptions.py:50 +#: src/config/SSSDConfig/sssdoptions.py:46 msgid "" "SSSD monitors the state of resolv.conf to identify when it needs to update " "its internal DNS resolver. By default, we will attempt to use inotify for " @@ -159,73 +159,73 @@ msgstr "" "używać do tego inotify, i wróci do odpytywania pliku resolv.conf co pięć " "sekund, jeśli inotify nie może być używane." -#: src/config/SSSDConfig/sssdoptions.py:53 +#: src/config/SSSDConfig/sssdoptions.py:49 msgid "Run PAC responder automatically for AD and IPA provider" msgstr "" -"Automatycznie uruchamia program odpowiadający PAC w przypadku dostawców AD i " -"IPA" +"Automatycznie uruchamia program odpowiadający PAC w przypadku dostawców AD " +"i IPA" -#: src/config/SSSDConfig/sssdoptions.py:54 +#: src/config/SSSDConfig/sssdoptions.py:50 msgid "Enable or disable core dumps for all SSSD processes." msgstr "Włącza lub wyłącza zrzuty core dla wszystkich procesów SSSD." -#: src/config/SSSDConfig/sssdoptions.py:55 +#: src/config/SSSDConfig/sssdoptions.py:51 msgid "Tune passkey verification behavior" msgstr "Dostraja zachowanie sprawdzania poprawności haseł-kluczy" -#: src/config/SSSDConfig/sssdoptions.py:58 +#: src/config/SSSDConfig/sssdoptions.py:54 msgid "Enumeration cache timeout length (seconds)" msgstr "Czas oczekiwania pamięci podręcznej wyliczania (sekundy)" -#: src/config/SSSDConfig/sssdoptions.py:59 +#: src/config/SSSDConfig/sssdoptions.py:55 msgid "Entry cache background update timeout length (seconds)" msgstr "Czas oczekiwania aktualizacji tła pamięci podręcznej wpisów (sekundy)" -#: src/config/SSSDConfig/sssdoptions.py:60 -#: src/config/SSSDConfig/sssdoptions.py:125 +#: src/config/SSSDConfig/sssdoptions.py:56 +#: src/config/SSSDConfig/sssdoptions.py:124 msgid "Negative cache timeout length (seconds)" msgstr "Ujemny czas oczekiwania pamięci podręcznej (sekundy)" -#: src/config/SSSDConfig/sssdoptions.py:61 +#: src/config/SSSDConfig/sssdoptions.py:57 msgid "Users that SSSD should explicitly ignore" msgstr "Użytkownicy, którzy mają być bezpośrednio ignorowani przez SSSD" -#: src/config/SSSDConfig/sssdoptions.py:62 +#: src/config/SSSDConfig/sssdoptions.py:58 msgid "Groups that SSSD should explicitly ignore" msgstr "Grupy, które mają być bezpośrednio ignorowane przez SSSD" -#: src/config/SSSDConfig/sssdoptions.py:63 +#: src/config/SSSDConfig/sssdoptions.py:59 msgid "Should filtered users appear in groups" msgstr "Czy filtrowani użytkownicy mają pojawiać się w grupach" -#: src/config/SSSDConfig/sssdoptions.py:64 +#: src/config/SSSDConfig/sssdoptions.py:60 msgid "The value of the password field the NSS provider should return" msgstr "Wartość pola hasła, jaką dostawca NSS ma zwrócić" -#: src/config/SSSDConfig/sssdoptions.py:65 +#: src/config/SSSDConfig/sssdoptions.py:61 msgid "Override homedir value from the identity provider with this value" msgstr "Zastępuje wartość katalogu domowego z dostawcy tożsamości tą wartością" -#: src/config/SSSDConfig/sssdoptions.py:66 +#: src/config/SSSDConfig/sssdoptions.py:62 msgid "" "Substitute empty homedir value from the identity provider with this value" msgstr "" "Zastępuje pustą wartość katalogu domowego z dostawcy tożsamości tą wartością" -#: src/config/SSSDConfig/sssdoptions.py:67 +#: src/config/SSSDConfig/sssdoptions.py:63 msgid "Override shell value from the identity provider with this value" msgstr "Zastępuje wartość powłoki od dostawcy tożsamości tą wartością" -#: src/config/SSSDConfig/sssdoptions.py:68 +#: src/config/SSSDConfig/sssdoptions.py:64 msgid "The list of shells users are allowed to log in with" msgstr "Lista powłok, za pomocą których użytkownicy mogą się logować" -#: src/config/SSSDConfig/sssdoptions.py:69 +#: src/config/SSSDConfig/sssdoptions.py:65 msgid "" "The list of shells that will be vetoed, and replaced with the fallback shell" msgstr "Lista powłok, które zostaną zawetowane i zastąpione powłoką zastępczą" -#: src/config/SSSDConfig/sssdoptions.py:70 +#: src/config/SSSDConfig/sssdoptions.py:66 msgid "" "If a shell stored in central directory is allowed but not available, use " "this fallback" @@ -233,15 +233,15 @@ msgstr "" "Jeśli powłoka przechowywana w katalogu centralnym jest dozwolona, ale nie " "jest dostępna, to zostanie użyta ta powłoka zastępcza" -#: src/config/SSSDConfig/sssdoptions.py:71 +#: src/config/SSSDConfig/sssdoptions.py:67 msgid "Shell to use if the provider does not list one" msgstr "Powłoka do użycia, jeśli dostawca nie dostarcza żadnej" -#: src/config/SSSDConfig/sssdoptions.py:72 +#: src/config/SSSDConfig/sssdoptions.py:68 msgid "How long will be in-memory cache records valid" msgstr "Jak długo wpisy pamięci podręcznej in-memory są prawidłowe" -#: src/config/SSSDConfig/sssdoptions.py:74 +#: src/config/SSSDConfig/sssdoptions.py:70 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for passwd requests" @@ -249,7 +249,7 @@ msgstr "" "Rozmiar (w megabajtach) tabeli danych przydzielonej w szybkiej pamięci " "podręcznej dla żądań passwd" -#: src/config/SSSDConfig/sssdoptions.py:76 +#: src/config/SSSDConfig/sssdoptions.py:72 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for group requests" @@ -257,7 +257,7 @@ msgstr "" "Rozmiar (w megabajtach) tabeli danych przydzielonej w szybkiej pamięci " "podręcznej dla żądań grup" -#: src/config/SSSDConfig/sssdoptions.py:78 +#: src/config/SSSDConfig/sssdoptions.py:74 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for initgroups requests" @@ -265,7 +265,7 @@ msgstr "" "Rozmiar (w megabajtach) tabeli danych przydzielonej w szybkiej pamięci " "podręcznej dla żądań grup inicjacji" -#: src/config/SSSDConfig/sssdoptions.py:79 +#: src/config/SSSDConfig/sssdoptions.py:75 msgid "" "The value of this option will be used in the expansion of the " "override_homedir option if the template contains the format string %H." @@ -273,7 +273,7 @@ msgstr "" "Wartość tej opcji będzie używana podczas rozwijania opcji override_homedir, " "jeśli szablon zawiera ciąg formatowania %H." -#: src/config/SSSDConfig/sssdoptions.py:81 +#: src/config/SSSDConfig/sssdoptions.py:77 msgid "" "Specifies time in seconds for which the list of subdomains will be " "considered valid." @@ -281,26 +281,27 @@ msgstr "" "Określa czas w sekundach, w którym lista poddomen będzie uważana za " "prawidłową." -#: src/config/SSSDConfig/sssdoptions.py:83 +#: src/config/SSSDConfig/sssdoptions.py:79 msgid "" "The entry cache can be set to automatically update entries in the background " "if they are requested beyond a percentage of the entry_cache_timeout value " "for the domain." msgstr "" -"Pamięć podręczną wpisów można ustawić na automatyczne aktualizowanie wpisów w" -" tle, jeśli są żądane poza procentem wartości entry_cache_timeout dla domeny." +"Pamięć podręczną wpisów można ustawić na automatyczne aktualizowanie wpisów " +"w tle, jeśli są żądane poza procentem wartości entry_cache_timeout dla " +"domeny." -#: src/config/SSSDConfig/sssdoptions.py:88 +#: src/config/SSSDConfig/sssdoptions.py:84 msgid "How long to allow cached logins between online logins (days)" msgstr "" -"Jak długo umożliwiać logowania w pamięci podręcznej między logowaniami w " -"trybie online (dni)" +"Jak długo umożliwiać logowania w pamięci podręcznej między logowaniami " +"w trybie online (dni)" -#: src/config/SSSDConfig/sssdoptions.py:89 +#: src/config/SSSDConfig/sssdoptions.py:85 msgid "How many failed logins attempts are allowed when offline" msgstr "Ile nieudanych prób zalogowania jest dozwolonych w trybie offline" -#: src/config/SSSDConfig/sssdoptions.py:91 +#: src/config/SSSDConfig/sssdoptions.py:87 msgid "" "How long (minutes) to deny login after offline_failed_login_attempts has " "been reached" @@ -308,90 +309,90 @@ msgstr "" "Ile czasu (minut) nie pozwalać na zalogowanie po osiągnięciu " "offline_failed_login_attempts" -#: src/config/SSSDConfig/sssdoptions.py:92 +#: src/config/SSSDConfig/sssdoptions.py:88 msgid "What kind of messages are displayed to the user during authentication" msgstr "" "Jaki rodzaj komunikatów wyświetlać użytkownikowi podczas uwierzytelniania" -#: src/config/SSSDConfig/sssdoptions.py:93 +#: src/config/SSSDConfig/sssdoptions.py:89 msgid "Filter PAM responses sent to the pam_sss" msgstr "Filtruje odpowiedzi PAM wysłane do pam_sss" -#: src/config/SSSDConfig/sssdoptions.py:94 +#: src/config/SSSDConfig/sssdoptions.py:90 msgid "How many seconds to keep identity information cached for PAM requests" msgstr "" "Ile sekund zatrzymać informacje o tożsamości w pamięci podręcznej dla żądań " "PAM" -#: src/config/SSSDConfig/sssdoptions.py:95 +#: src/config/SSSDConfig/sssdoptions.py:91 msgid "How many days before password expiration a warning should be displayed" msgstr "Ile dni przed wygaśnięciem hasła wyświetlić ostrzeżenie" -#: src/config/SSSDConfig/sssdoptions.py:96 +#: src/config/SSSDConfig/sssdoptions.py:92 msgid "List of trusted uids or user's name" msgstr "Lista zaufanych UID lub nazw użytkowników" -#: src/config/SSSDConfig/sssdoptions.py:97 +#: src/config/SSSDConfig/sssdoptions.py:93 msgid "List of domains accessible even for untrusted users." msgstr "Lista domen dostępnych także dla niezaufanych użytkowników." -#: src/config/SSSDConfig/sssdoptions.py:98 +#: src/config/SSSDConfig/sssdoptions.py:94 msgid "Message printed when user account is expired." msgstr "Komunikat wyświetlany po wygaśnięciu konta użytkownika." -#: src/config/SSSDConfig/sssdoptions.py:99 +#: src/config/SSSDConfig/sssdoptions.py:95 msgid "Message printed when user account is locked." msgstr "Komunikat wyświetlany po zablokowaniu konta użytkownika." -#: src/config/SSSDConfig/sssdoptions.py:100 +#: src/config/SSSDConfig/sssdoptions.py:96 msgid "Allow certificate based/Smartcard authentication." msgstr "Zezwala na uwierzytelnianie za pomocą certyfikatów/smartcard." -#: src/config/SSSDConfig/sssdoptions.py:101 +#: src/config/SSSDConfig/sssdoptions.py:97 msgid "Path to certificate database with PKCS#11 modules." msgstr "Ścieżka do bazy danych certyfikatów z modułami PKCS#11." -#: src/config/SSSDConfig/sssdoptions.py:102 +#: src/config/SSSDConfig/sssdoptions.py:98 msgid "Tune certificate verification for PAM authentication." msgstr "" "Dostraja sprawdzanie poprawności certyfikatów przy uwierzytelnianiu PAM." -#: src/config/SSSDConfig/sssdoptions.py:103 +#: src/config/SSSDConfig/sssdoptions.py:99 msgid "How many seconds will pam_sss wait for p11_child to finish" msgstr "Ile sekund pam_sss ma oczekiwać na ukończenie p11_child" -#: src/config/SSSDConfig/sssdoptions.py:104 +#: src/config/SSSDConfig/sssdoptions.py:100 msgid "Which PAM services are permitted to contact application domains" msgstr "Które usługi PAM mają zezwolenie na kontakt z domenami aplikacji" -#: src/config/SSSDConfig/sssdoptions.py:105 +#: src/config/SSSDConfig/sssdoptions.py:101 msgid "Allowed services for using smartcards" msgstr "Usługi mogące używać kart smardcard" -#: src/config/SSSDConfig/sssdoptions.py:106 +#: src/config/SSSDConfig/sssdoptions.py:102 msgid "Additional timeout to wait for a card if requested" msgstr "Dodatkowy czas oczekiwania na kartę, jeśli zażądano" -#: src/config/SSSDConfig/sssdoptions.py:107 +#: src/config/SSSDConfig/sssdoptions.py:103 msgid "" "PKCS#11 URI to restrict the selection of devices for Smartcard authentication" msgstr "" "Adres URI PKCS#11 do ograniczenia wyboru urządzeń dla uwierzytelniania za " "pomocą kart smartcard" -#: src/config/SSSDConfig/sssdoptions.py:108 +#: src/config/SSSDConfig/sssdoptions.py:104 msgid "When shall the PAM responder force an initgroups request" msgstr "Kiedy program odpowiadający PAM ma wymuszać żądanie grup inicjacji" -#: src/config/SSSDConfig/sssdoptions.py:109 +#: src/config/SSSDConfig/sssdoptions.py:105 msgid "List of PAM services that are allowed to authenticate with GSSAPI." msgstr "Lista usług PAM, które mogą się uwierzytelniać za pomocą GSSAPI." -#: src/config/SSSDConfig/sssdoptions.py:110 +#: src/config/SSSDConfig/sssdoptions.py:106 msgid "Whether to match authenticated UPN with target user" msgstr "Czy dopasowywać uwierzytelnione UPN z użytkownikiem docelowym" -#: src/config/SSSDConfig/sssdoptions.py:111 +#: src/config/SSSDConfig/sssdoptions.py:107 msgid "" "List of pairs : that must be enforced " "for PAM access with GSSAPI authentication" @@ -399,33 +400,43 @@ msgstr "" "Lista par :, które muszą być " "wymuszone dla dostępu PAM za pomocą uwierzytelniania GSSAPI" -#: src/config/SSSDConfig/sssdoptions.py:113 +#: src/config/SSSDConfig/sssdoptions.py:109 +#, fuzzy +msgid "" +"List of triples :: that assigns " +"additional information from the Kerberos ticket to an authentication " +"indicator." +msgstr "" +"Lista par :, które muszą być " +"wymuszone dla dostępu PAM za pomocą uwierzytelniania GSSAPI" + +#: src/config/SSSDConfig/sssdoptions.py:112 msgid "Allow passkey device authentication." msgstr "Zezwala na uwierzytelnianie za pomocą urządzenia hasła-klucza." -#: src/config/SSSDConfig/sssdoptions.py:114 +#: src/config/SSSDConfig/sssdoptions.py:113 msgid "How many seconds will pam_sss wait for passkey_child to finish" msgstr "Ile sekund pam_sss ma oczekiwać na ukończenie passkey_child" -#: src/config/SSSDConfig/sssdoptions.py:115 +#: src/config/SSSDConfig/sssdoptions.py:114 msgid "Enable debugging in the libfido2 library" msgstr "Włącza debugowanie w bibliotece libfido2" -#: src/config/SSSDConfig/sssdoptions.py:116 +#: src/config/SSSDConfig/sssdoptions.py:115 msgid "Enable JSON protocol for authentication methods selection." msgstr "Włącza protokół JSON do wyboru metod uwierzytelniania." -#: src/config/SSSDConfig/sssdoptions.py:119 +#: src/config/SSSDConfig/sssdoptions.py:118 msgid "Whether to evaluate the time-based attributes in sudo rules" msgstr "Czy sprawdzać atrybuty oparte na czasie w regułach sudo" -#: src/config/SSSDConfig/sssdoptions.py:120 +#: src/config/SSSDConfig/sssdoptions.py:119 msgid "If true, SSSD will switch back to lower-wins ordering logic" msgstr "" -"Jeśli jest włączone, usługa SSSD przełączy z powrotem do logiki kolejności „" -"niższe wygrywa”" +"Jeśli jest włączone, usługa SSSD przełączy z powrotem do logiki kolejności " +"„niższe wygrywa”" -#: src/config/SSSDConfig/sssdoptions.py:121 +#: src/config/SSSDConfig/sssdoptions.py:120 msgid "" "Maximum number of rules that can be refreshed at once. If this is exceeded, " "full refresh is performed." @@ -433,26 +444,26 @@ msgstr "" "Maksymalna liczba reguł, jaką można odświeżyć jednocześnie. Jeśli zostanie " "przekroczona, wykonywane jest pełne odświeżenie." -#: src/config/SSSDConfig/sssdoptions.py:128 +#: src/config/SSSDConfig/sssdoptions.py:127 msgid "Whether to hash host names and addresses in the known_hosts file" msgstr "Czy mieszać nazwy komputerów i adresy w pliku known_hosts" -#: src/config/SSSDConfig/sssdoptions.py:129 +#: src/config/SSSDConfig/sssdoptions.py:128 msgid "" "How many seconds to keep a host in the known_hosts file after its host keys " "were requested" msgstr "" "Ile sekund przechowywać komputer w pliku known_hosts po zażądaniu jego kluczy" -#: src/config/SSSDConfig/sssdoptions.py:131 +#: src/config/SSSDConfig/sssdoptions.py:130 msgid "Path to storage of trusted CA certificates" msgstr "Ścieżka do miejsca przechowywania zaufanych certyfikatów CA" -#: src/config/SSSDConfig/sssdoptions.py:132 +#: src/config/SSSDConfig/sssdoptions.py:131 msgid "Allow to generate ssh-keys from certificates" msgstr "Zezwala na tworzenie kluczy SSH z certyfikatów" -#: src/config/SSSDConfig/sssdoptions.py:133 +#: src/config/SSSDConfig/sssdoptions.py:132 msgid "" "Use the following matching rules to filter the certificates for ssh-key " "generation" @@ -460,25 +471,25 @@ msgstr "" "Używa poniższych reguł dopasowania do filtrowania certyfikatów do tworzenia " "kluczy SSH" -#: src/config/SSSDConfig/sssdoptions.py:137 +#: src/config/SSSDConfig/sssdoptions.py:136 msgid "List of UIDs or user names allowed to access the PAC responder" msgstr "" "Lista UID lub nazw użytkowników mających dostęp do programu odpowiadającego " "PAC" -#: src/config/SSSDConfig/sssdoptions.py:138 +#: src/config/SSSDConfig/sssdoptions.py:137 msgid "How long the PAC data is considered valid" msgstr "Jak długo dane PAC są uważane za prawidłowe" -#: src/config/SSSDConfig/sssdoptions.py:139 +#: src/config/SSSDConfig/sssdoptions.py:138 msgid "Validate the PAC" msgstr "Sprawdza poprawność PAC" -#: src/config/SSSDConfig/sssdoptions.py:142 +#: src/config/SSSDConfig/sssdoptions.py:141 msgid "List of user attributes the InfoPipe is allowed to publish" msgstr "Lista atrybutów użytkownika, które InfoPipe może publikować" -#: src/config/SSSDConfig/sssdoptions.py:145 +#: src/config/SSSDConfig/sssdoptions.py:144 msgid "" "One of the following strings specifying the scope of session recording: none " "- No users are recorded. some - Users/groups specified by users and groups " @@ -489,7 +500,7 @@ msgstr "" "opcje użytkowników i grup są nagrywane. all — wszyscy użytkownicy są " "nagrywani." -#: src/config/SSSDConfig/sssdoptions.py:148 +#: src/config/SSSDConfig/sssdoptions.py:147 msgid "" "A comma-separated list of users which should have session recording enabled. " "Matches user names as returned by NSS. I.e. after the possible space " @@ -499,7 +510,7 @@ msgstr "" "sesji. Dopasowuje nazwy użytkowników zwracane przez NSS. Tzn. po możliwych " "zastąpieniach spacji, zmianach wielkości znaków itp." -#: src/config/SSSDConfig/sssdoptions.py:150 +#: src/config/SSSDConfig/sssdoptions.py:149 msgid "" "A comma-separated list of groups, members of which should have session " "recording enabled. Matches group names as returned by NSS. I.e. after the " @@ -509,7 +520,7 @@ msgstr "" "sesji. Dopasowuje nazwy grup zwracane przez NSS. Tzn. po możliwych " "zastąpieniach spacji, zmianach wielkości znaków itp." -#: src/config/SSSDConfig/sssdoptions.py:153 +#: src/config/SSSDConfig/sssdoptions.py:152 msgid "" "A comma-separated list of users to be excluded from recording, only when " "scope=all" @@ -517,87 +528,87 @@ msgstr "" "Lista użytkowników oddzielonych przecinkami do wykluczenia z nagrywania, " "tylko kiedy scope=all" -#: src/config/SSSDConfig/sssdoptions.py:154 +#: src/config/SSSDConfig/sssdoptions.py:153 msgid "" "A comma-separated list of groups, members of which should be excluded from " "recording, only when scope=all. " msgstr "" -"Lista grup oddzielonych przecinkami, których członkowie mają być wykluczeni z" -" nagrywania, tylko kiedy scope=all. " +"Lista grup oddzielonych przecinkami, których członkowie mają być wykluczeni " +"z nagrywania, tylko kiedy scope=all. " -#: src/config/SSSDConfig/sssdoptions.py:158 +#: src/config/SSSDConfig/sssdoptions.py:157 msgid "Identity provider" msgstr "Dostawca tożsamości" -#: src/config/SSSDConfig/sssdoptions.py:159 +#: src/config/SSSDConfig/sssdoptions.py:158 msgid "Authentication provider" msgstr "Dostawca uwierzytelniania" -#: src/config/SSSDConfig/sssdoptions.py:160 +#: src/config/SSSDConfig/sssdoptions.py:159 msgid "Access control provider" msgstr "Dostawca kontroli dostępu" -#: src/config/SSSDConfig/sssdoptions.py:161 +#: src/config/SSSDConfig/sssdoptions.py:160 msgid "Password change provider" msgstr "Dostawca zmiany hasła" -#: src/config/SSSDConfig/sssdoptions.py:162 +#: src/config/SSSDConfig/sssdoptions.py:161 msgid "SUDO provider" msgstr "Dostawca SUDO" -#: src/config/SSSDConfig/sssdoptions.py:163 +#: src/config/SSSDConfig/sssdoptions.py:162 msgid "Autofs provider" msgstr "Dostawca Autofs" -#: src/config/SSSDConfig/sssdoptions.py:164 +#: src/config/SSSDConfig/sssdoptions.py:163 msgid "Host identity provider" msgstr "Dostawca tożsamości komputera" -#: src/config/SSSDConfig/sssdoptions.py:165 +#: src/config/SSSDConfig/sssdoptions.py:164 msgid "SELinux provider" msgstr "Dostawca SELinuksa" -#: src/config/SSSDConfig/sssdoptions.py:166 +#: src/config/SSSDConfig/sssdoptions.py:165 msgid "Session management provider" msgstr "Dostawca zarządzania sesją" -#: src/config/SSSDConfig/sssdoptions.py:167 +#: src/config/SSSDConfig/sssdoptions.py:166 msgid "Resolver provider" msgstr "Dostawca programu rozwiązującego" -#: src/config/SSSDConfig/sssdoptions.py:170 +#: src/config/SSSDConfig/sssdoptions.py:169 msgid "Whether the domain is usable by the OS or by applications" msgstr "Czy domena jest używalna przez system operacyjny lub aplikacje" -#: src/config/SSSDConfig/sssdoptions.py:171 +#: src/config/SSSDConfig/sssdoptions.py:170 msgid "Enable or disable the domain" msgstr "Włącza lub wyłącza domenę" -#: src/config/SSSDConfig/sssdoptions.py:172 +#: src/config/SSSDConfig/sssdoptions.py:171 msgid "Minimum user ID" msgstr "Minimalny identyfikator użytkownika" -#: src/config/SSSDConfig/sssdoptions.py:173 +#: src/config/SSSDConfig/sssdoptions.py:172 msgid "Maximum user ID" msgstr "Maksymalny identyfikator użytkownika" -#: src/config/SSSDConfig/sssdoptions.py:174 +#: src/config/SSSDConfig/sssdoptions.py:173 msgid "Enable enumerating all users/groups" msgstr "Włącza wyliczanie wszystkich użytkowników/grup" -#: src/config/SSSDConfig/sssdoptions.py:175 +#: src/config/SSSDConfig/sssdoptions.py:174 msgid "Cache credentials for offline login" msgstr "Dane uwierzytelniające pamięci podręcznej dla logowań w trybie offline" -#: src/config/SSSDConfig/sssdoptions.py:176 +#: src/config/SSSDConfig/sssdoptions.py:175 msgid "Display users/groups in fully-qualified form" msgstr "Wyświetla użytkowników/grupy w pełni kwalifikowanej formie" -#: src/config/SSSDConfig/sssdoptions.py:177 +#: src/config/SSSDConfig/sssdoptions.py:176 msgid "Don't include group members in group lookups" msgstr "Bez dołączania członków grup w wyszukiwaniach grup" -#: src/config/SSSDConfig/sssdoptions.py:178 +#: src/config/SSSDConfig/sssdoptions.py:177 #: src/config/SSSDConfig/sssdoptions.py:190 #: src/config/SSSDConfig/sssdoptions.py:191 #: src/config/SSSDConfig/sssdoptions.py:192 @@ -608,20 +619,20 @@ msgstr "Bez dołączania członków grup w wyszukiwaniach grup" msgid "Entry cache timeout length (seconds)" msgstr "Czas oczekiwania pamięci podręcznej wpisów (sekundy)" -#: src/config/SSSDConfig/sssdoptions.py:179 +#: src/config/SSSDConfig/sssdoptions.py:178 msgid "" "Restrict or prefer a specific address family when performing DNS lookups" msgstr "" "Ogranicza lub preferuje podaną rodzinę adresów podczas wykonywania " "wyszukiwań DNS" -#: src/config/SSSDConfig/sssdoptions.py:180 +#: src/config/SSSDConfig/sssdoptions.py:179 msgid "How long to keep cached entries after last successful login (days)" msgstr "" "Jak długo utrzymywać wpisy logowania w pamięci podręcznej po ostatnim udanym " "zalogowaniu (dni)" -#: src/config/SSSDConfig/sssdoptions.py:181 +#: src/config/SSSDConfig/sssdoptions.py:180 msgid "" "How long should SSSD talk to single DNS server before trying next server " "(miliseconds)" @@ -629,21 +640,21 @@ msgstr "" "Jak długo SSSD ma komunikować się z jednym serwerem DNS przed spróbowaniem " "następnego serwera (milisekundy)" -#: src/config/SSSDConfig/sssdoptions.py:183 +#: src/config/SSSDConfig/sssdoptions.py:182 msgid "How long should keep trying to resolve single DNS query (seconds)" msgstr "Jak długo próbować rozwiązać jedno zapytanie DNS (sekundy)" -#: src/config/SSSDConfig/sssdoptions.py:184 +#: src/config/SSSDConfig/sssdoptions.py:183 msgid "How long to wait for replies from DNS when resolving servers (seconds)" msgstr "" "Jak długo czekać na odpowiedzi od serwera DNS podczas rozwiązywania serwerów " "(sekundy)" -#: src/config/SSSDConfig/sssdoptions.py:185 +#: src/config/SSSDConfig/sssdoptions.py:184 msgid "The domain part of service discovery DNS query" msgstr "Część domeny zapytania DNS wykrywania usługi" -#: src/config/SSSDConfig/sssdoptions.py:186 +#: src/config/SSSDConfig/sssdoptions.py:185 msgid "" "Specifies the interval, in seconds, that SSSD waits before attempting to " "reconnect to the primary server after a successful connection to the backup " @@ -652,14 +663,18 @@ msgstr "" "Określa czas w sekundach, przez jaki SSSD czeka przed próbą ponownego " "połączenia z głównym serwerem po pomyślnym połączeniu z serwerem zapasowym" -#: src/config/SSSDConfig/sssdoptions.py:188 +#: src/config/SSSDConfig/sssdoptions.py:187 msgid "Override GID value from the identity provider with this value" msgstr "Zastępuje wartość GID z dostawcy tożsamości tą wartością" -#: src/config/SSSDConfig/sssdoptions.py:189 +#: src/config/SSSDConfig/sssdoptions.py:188 msgid "Treat usernames as case sensitive" msgstr "Rozróżnianie wielkości liter w nazwach użytkowników" +#: src/config/SSSDConfig/sssdoptions.py:189 +msgid "Lookups by ID are expensive or do not work at all" +msgstr "" + #: src/config/SSSDConfig/sssdoptions.py:197 msgid "How often should expired entries be refreshed in background" msgstr "Jak często odświeżać w tle wygasłe wpisy" @@ -904,7 +919,7 @@ msgid "Search base for SUBID ranges" msgstr "Podstawa wyszukiwania dla zakresów SUBID" #: src/config/SSSDConfig/sssdoptions.py:259 -#: src/config/SSSDConfig/sssdoptions.py:506 +#: src/config/SSSDConfig/sssdoptions.py:512 msgid "Which rules should be used to evaluate access control" msgstr "Które reguły mają być używane do sprawdzania kontroli dostępu" @@ -919,7 +934,8 @@ msgstr "Klasa obiektów wpisu komputera w LDAP." #: src/config/SSSDConfig/sssdoptions.py:262 msgid "Use the given string as search base for host objects." -msgstr "Używa podanego ciągu jako podstawę wyszukiwania dla obiektów komputera." +msgstr "" +"Używa podanego ciągu jako podstawę wyszukiwania dla obiektów komputera." #: src/config/SSSDConfig/sssdoptions.py:263 msgid "The LDAP attribute that contains the host's SSH public keys." @@ -1060,7 +1076,7 @@ msgid "Enable DNS sites - location based service discovery" msgstr "Włącza witryny DNS — wykrywanie usług na podstawie położenia" #: src/config/SSSDConfig/sssdoptions.py:301 -#: src/config/SSSDConfig/sssdoptions.py:504 +#: src/config/SSSDConfig/sssdoptions.py:510 msgid "LDAP filter to determine access privileges" msgstr "Filtr LDAP do określenia uprawnień dostępu" @@ -1090,8 +1106,8 @@ msgid "" "PAM service names that map to the GPO (Deny)RemoteInteractiveLogonRight " "policy settings" msgstr "" -"Nazwy usług PAM mapujących do ustawień zasad GPO (Deny)" -"RemoteInteractiveLogonRight" +"Nazwy usług PAM mapujących do ustawień zasad GPO " +"(Deny)RemoteInteractiveLogonRight" #: src/config/SSSDConfig/sssdoptions.py:309 msgid "" @@ -1112,11 +1128,13 @@ msgstr "" #: src/config/SSSDConfig/sssdoptions.py:312 msgid "PAM service names for which GPO-based access is always granted" -msgstr "Nazwy usług PAM, dla których zawsze udzielany jest dostęp oparty na GPO" +msgstr "" +"Nazwy usług PAM, dla których zawsze udzielany jest dostęp oparty na GPO" #: src/config/SSSDConfig/sssdoptions.py:313 msgid "PAM service names for which GPO-based access is always denied" -msgstr "Nazwy usług PAM, dla których zawsze odmawiany jest dostęp oparty na GPO" +msgstr "" +"Nazwy usług PAM, dla których zawsze odmawiany jest dostęp oparty na GPO" #: src/config/SSSDConfig/sssdoptions.py:314 msgid "" @@ -1192,8 +1210,8 @@ msgstr "Włącza sprawdzanie danych uwierzytelniających" #: src/config/SSSDConfig/sssdoptions.py:337 msgid "Store password if offline for later online authentication" msgstr "" -"Przechowuje hasło, jeśli w trybie offline do późniejszego uwierzytelnienia w " -"trybie online" +"Przechowuje hasło, jeśli w trybie offline do późniejszego uwierzytelnienia " +"w trybie online" #: src/config/SSSDConfig/sssdoptions.py:338 msgid "Renewable lifetime of the TGT" @@ -1501,7 +1519,7 @@ msgid "UUID attribute" msgstr "Atrybut UUID" #: src/config/SSSDConfig/sssdoptions.py:423 -#: src/config/SSSDConfig/sssdoptions.py:464 +#: src/config/SSSDConfig/sssdoptions.py:470 msgid "objectSID attribute" msgstr "Atrybut objectSID" @@ -1626,203 +1644,233 @@ msgstr "atrybut zawierający dane mapowania hasła-klucza użytkownika" msgid "A list of extra attributes to download along with the user entry" msgstr "Lista dodatkowych atrybutów do pobrania razem z wpisem użytkownika" +#: src/config/SSSDConfig/sssdoptions.py:456 +#, fuzzy +msgid "The object class of an subid entry in LDAP." +msgstr "Klasa obiektów wpisu komputera w LDAP." + #: src/config/SSSDConfig/sssdoptions.py:457 +#, fuzzy +msgid "Subordinate user ID count attribute" +msgstr "Atrybut użytkownika reguły sudo" + +#: src/config/SSSDConfig/sssdoptions.py:458 +#, fuzzy +msgid "Subordinate group ID count attribute" +msgstr "Atrybut opcji reguły sudo" + +#: src/config/SSSDConfig/sssdoptions.py:459 +#, fuzzy +msgid "User ID range start value attribute" +msgstr "Atrybut nazwy użytkownika" + +#: src/config/SSSDConfig/sssdoptions.py:460 +#, fuzzy +msgid "Group ID range start value attribute" +msgstr "Atrybut UUID grupy" + +#: src/config/SSSDConfig/sssdoptions.py:461 +msgid "Owner of an entry" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:463 msgid "Base DN for group lookups" msgstr "Podstawowe DN dla wyszukiwania grup" -#: src/config/SSSDConfig/sssdoptions.py:458 +#: src/config/SSSDConfig/sssdoptions.py:464 msgid "Objectclass for groups" msgstr "Klasa obiektów dla grup" -#: src/config/SSSDConfig/sssdoptions.py:459 +#: src/config/SSSDConfig/sssdoptions.py:465 msgid "Group name" msgstr "Nazwa grupy" -#: src/config/SSSDConfig/sssdoptions.py:460 +#: src/config/SSSDConfig/sssdoptions.py:466 msgid "Group password" msgstr "Hasło grupy" -#: src/config/SSSDConfig/sssdoptions.py:461 +#: src/config/SSSDConfig/sssdoptions.py:467 msgid "GID attribute" msgstr "Atrybut GID" -#: src/config/SSSDConfig/sssdoptions.py:462 +#: src/config/SSSDConfig/sssdoptions.py:468 msgid "Group member attribute" msgstr "Atrybut elementu grupy" -#: src/config/SSSDConfig/sssdoptions.py:463 +#: src/config/SSSDConfig/sssdoptions.py:469 msgid "Group UUID attribute" msgstr "Atrybut UUID grupy" -#: src/config/SSSDConfig/sssdoptions.py:465 +#: src/config/SSSDConfig/sssdoptions.py:471 msgid "Modification time attribute for groups" msgstr "Atrybut czasu modyfikacji grup" -#: src/config/SSSDConfig/sssdoptions.py:466 +#: src/config/SSSDConfig/sssdoptions.py:472 msgid "Type of the group and other flags" msgstr "Typ grupy i inne flagi" -#: src/config/SSSDConfig/sssdoptions.py:467 +#: src/config/SSSDConfig/sssdoptions.py:473 msgid "The LDAP group external member attribute" msgstr "Atrybut zewnętrznego członka grupy LDAP" -#: src/config/SSSDConfig/sssdoptions.py:468 +#: src/config/SSSDConfig/sssdoptions.py:474 msgid "Maximum nesting level SSSD will follow" msgstr "Maksymalny poziom zagnieżdżenia, jaki usługa SSSD będzie używała" -#: src/config/SSSDConfig/sssdoptions.py:469 +#: src/config/SSSDConfig/sssdoptions.py:475 msgid "Filter for group lookups" msgstr "Filtruje wyszukiwania grup" -#: src/config/SSSDConfig/sssdoptions.py:470 +#: src/config/SSSDConfig/sssdoptions.py:476 msgid "Scope of group lookups" msgstr "Zakres wyszukiwania grup" -#: src/config/SSSDConfig/sssdoptions.py:472 +#: src/config/SSSDConfig/sssdoptions.py:478 msgid "Base DN for netgroup lookups" msgstr "Podstawowe DN dla wyszukiwania grupy sieciowej" -#: src/config/SSSDConfig/sssdoptions.py:473 +#: src/config/SSSDConfig/sssdoptions.py:479 msgid "Objectclass for netgroups" msgstr "Klasa obiektów dla grup sieciowych" -#: src/config/SSSDConfig/sssdoptions.py:474 +#: src/config/SSSDConfig/sssdoptions.py:480 msgid "Netgroup name" msgstr "Nazwa grupy sieciowej" -#: src/config/SSSDConfig/sssdoptions.py:475 +#: src/config/SSSDConfig/sssdoptions.py:481 msgid "Netgroups members attribute" msgstr "Atrybut elementów grupy sieciowej" -#: src/config/SSSDConfig/sssdoptions.py:476 +#: src/config/SSSDConfig/sssdoptions.py:482 msgid "Netgroup triple attribute" msgstr "Potrójny atrybut grupy sieciowej" -#: src/config/SSSDConfig/sssdoptions.py:477 +#: src/config/SSSDConfig/sssdoptions.py:483 msgid "Modification time attribute for netgroups" msgstr "Atrybut czasu modyfikacji grup sieciowych" -#: src/config/SSSDConfig/sssdoptions.py:479 +#: src/config/SSSDConfig/sssdoptions.py:485 msgid "Base DN for service lookups" msgstr "Podstawowe DN do wyszukiwania usług" -#: src/config/SSSDConfig/sssdoptions.py:480 +#: src/config/SSSDConfig/sssdoptions.py:486 msgid "Objectclass for services" msgstr "Klasa obiektów dla usług" -#: src/config/SSSDConfig/sssdoptions.py:481 +#: src/config/SSSDConfig/sssdoptions.py:487 msgid "Service name attribute" msgstr "Atrybut nazwy usługi" -#: src/config/SSSDConfig/sssdoptions.py:482 +#: src/config/SSSDConfig/sssdoptions.py:488 msgid "Service port attribute" msgstr "Atrybut portu usługi" -#: src/config/SSSDConfig/sssdoptions.py:483 +#: src/config/SSSDConfig/sssdoptions.py:489 msgid "Service protocol attribute" msgstr "Atrybut protokołu usługi" -#: src/config/SSSDConfig/sssdoptions.py:485 +#: src/config/SSSDConfig/sssdoptions.py:491 msgid "Lower bound for ID-mapping" msgstr "Niższa granica dla mapowania identyfikatorów" -#: src/config/SSSDConfig/sssdoptions.py:486 +#: src/config/SSSDConfig/sssdoptions.py:492 msgid "Upper bound for ID-mapping" msgstr "Wyższa granica dla mapowania identyfikatorów" -#: src/config/SSSDConfig/sssdoptions.py:487 +#: src/config/SSSDConfig/sssdoptions.py:493 msgid "Number of IDs for each slice when ID-mapping" msgstr "" "Liczba identyfikatorów dla każdego fragmentu podczas mapowania " "identyfikatorów" -#: src/config/SSSDConfig/sssdoptions.py:488 +#: src/config/SSSDConfig/sssdoptions.py:494 msgid "Use autorid-compatible algorithm for ID-mapping" msgstr "Używa algorytmu zgodnego z autorid do mapowania identyfikatorów" -#: src/config/SSSDConfig/sssdoptions.py:489 +#: src/config/SSSDConfig/sssdoptions.py:495 msgid "Name of the default domain for ID-mapping" msgstr "Nazwa domyślnej domeny dla mapowania identyfikatorów" -#: src/config/SSSDConfig/sssdoptions.py:490 +#: src/config/SSSDConfig/sssdoptions.py:496 msgid "SID of the default domain for ID-mapping" msgstr "SID domyślnej domeny dla mapowania identyfikatorów" -#: src/config/SSSDConfig/sssdoptions.py:491 +#: src/config/SSSDConfig/sssdoptions.py:497 msgid "Number of secondary slices" msgstr "Liczba drugorzędnych fragmentów" -#: src/config/SSSDConfig/sssdoptions.py:493 +#: src/config/SSSDConfig/sssdoptions.py:499 msgid "Whether to use Token-Groups" msgstr "Czy używać Token-Groups" -#: src/config/SSSDConfig/sssdoptions.py:494 +#: src/config/SSSDConfig/sssdoptions.py:500 msgid "Set lower boundary for allowed IDs from the LDAP server" msgstr "Ustawia dolną granicę dla dozwolonych identyfikatorów z serwera LDAP" -#: src/config/SSSDConfig/sssdoptions.py:495 +#: src/config/SSSDConfig/sssdoptions.py:501 msgid "Set upper boundary for allowed IDs from the LDAP server" msgstr "Ustawia górną granicę dla dozwolonych identyfikatorów z serwera LDAP" -#: src/config/SSSDConfig/sssdoptions.py:496 +#: src/config/SSSDConfig/sssdoptions.py:502 msgid "DN for ppolicy queries" msgstr "DN dla zapytań ppolicy" -#: src/config/SSSDConfig/sssdoptions.py:497 +#: src/config/SSSDConfig/sssdoptions.py:503 msgid "How many maximum entries to fetch during a wildcard request" msgstr "Ile maksymalnie wpisów pobierać podczas żądania z wieloznacznikiem" -#: src/config/SSSDConfig/sssdoptions.py:498 +#: src/config/SSSDConfig/sssdoptions.py:504 msgid "Set libldap debug level" msgstr "Ustawia poziom debugowania biblioteki libldap" -#: src/config/SSSDConfig/sssdoptions.py:501 +#: src/config/SSSDConfig/sssdoptions.py:507 msgid "Policy to evaluate the password expiration" msgstr "Zasady do sprawdzania wygaszenia hasła" -#: src/config/SSSDConfig/sssdoptions.py:505 +#: src/config/SSSDConfig/sssdoptions.py:511 msgid "Which attributes shall be used to evaluate if an account is expired" msgstr "Które atrybuty mają być używane do sprawdzenia, czy konto wygasło" -#: src/config/SSSDConfig/sssdoptions.py:509 +#: src/config/SSSDConfig/sssdoptions.py:515 msgid "URI of an LDAP server where password changes are allowed" msgstr "Adres URI serwera LDAP, gdzie zmiany hasła są dozwolone" -#: src/config/SSSDConfig/sssdoptions.py:510 +#: src/config/SSSDConfig/sssdoptions.py:516 msgid "URI of a backup LDAP server where password changes are allowed" msgstr "Adres URI zapasowego serwera LDAP, gdzie zmiany hasła są dozwolone" -#: src/config/SSSDConfig/sssdoptions.py:511 +#: src/config/SSSDConfig/sssdoptions.py:517 msgid "DNS service name for LDAP password change server" msgstr "Nazwa usługi DNS serwera zmiany hasła LDAP" -#: src/config/SSSDConfig/sssdoptions.py:512 +#: src/config/SSSDConfig/sssdoptions.py:518 msgid "" "Whether to update the ldap_user_shadow_last_change attribute after a " "password change" -msgstr "Czy zaktualizować atrybut ldap_user_shadow_last_change po zmianie hasła" +msgstr "" +"Czy zaktualizować atrybut ldap_user_shadow_last_change po zmianie hasła" -#: src/config/SSSDConfig/sssdoptions.py:516 +#: src/config/SSSDConfig/sssdoptions.py:522 msgid "Base DN for sudo rules lookups" msgstr "Podstawowe DN dla wyszukiwań reguł sudo" -#: src/config/SSSDConfig/sssdoptions.py:517 +#: src/config/SSSDConfig/sssdoptions.py:523 msgid "Automatic full refresh period" msgstr "Okres między automatycznymi pełnymi odświeżeniami" -#: src/config/SSSDConfig/sssdoptions.py:518 +#: src/config/SSSDConfig/sssdoptions.py:524 msgid "Automatic smart refresh period" msgstr "Okres między automatycznymi inteligentnymi odświeżeniami" -#: src/config/SSSDConfig/sssdoptions.py:519 +#: src/config/SSSDConfig/sssdoptions.py:525 msgid "Smart and full refresh random offset" msgstr "Losowe przesunięcie inteligentnego i pełnego odświeżenia" -#: src/config/SSSDConfig/sssdoptions.py:520 +#: src/config/SSSDConfig/sssdoptions.py:526 msgid "Whether to filter rules by hostname, IP addresses and network" msgstr "Czy filtrować reguły według nazwy komputera, adresów IP i sieci" -#: src/config/SSSDConfig/sssdoptions.py:521 +#: src/config/SSSDConfig/sssdoptions.py:527 msgid "" "Hostnames and/or fully qualified domain names of this machine to filter sudo " "rules" @@ -1830,149 +1878,150 @@ msgstr "" "Nazwy komputerów lub w pełni kwalifikowane nazwy domen tego komputera do " "filtrowania reguł sudo" -#: src/config/SSSDConfig/sssdoptions.py:522 +#: src/config/SSSDConfig/sssdoptions.py:528 msgid "IPv4 or IPv6 addresses or network of this machine to filter sudo rules" -msgstr "Adresy lub sieci IPv4 lub IPv6 tego komputera do filtrowania reguł sudo" +msgstr "" +"Adresy lub sieci IPv4 lub IPv6 tego komputera do filtrowania reguł sudo" -#: src/config/SSSDConfig/sssdoptions.py:523 +#: src/config/SSSDConfig/sssdoptions.py:529 msgid "Whether to include rules that contains netgroup in host attribute" msgstr "Czy zawierać reguły zawierające grupy sieciowe w atrybucie komputera" -#: src/config/SSSDConfig/sssdoptions.py:524 +#: src/config/SSSDConfig/sssdoptions.py:530 msgid "" "Whether to include rules that contains regular expression in host attribute" msgstr "" "Czy zawierać reguły zawierające wyrażenia regularne w atrybucie komputera" -#: src/config/SSSDConfig/sssdoptions.py:525 +#: src/config/SSSDConfig/sssdoptions.py:531 msgid "Object class for sudo rules" msgstr "Klasa obiektów dla reguł sudo" -#: src/config/SSSDConfig/sssdoptions.py:526 +#: src/config/SSSDConfig/sssdoptions.py:532 msgid "Name of attribute that is used as object class for sudo rules" msgstr "Nazwa atrybutu używanego jako klasa obiektów dla reguł sudo" -#: src/config/SSSDConfig/sssdoptions.py:527 +#: src/config/SSSDConfig/sssdoptions.py:533 msgid "Sudo rule name" msgstr "Nazwa reguły sudo" -#: src/config/SSSDConfig/sssdoptions.py:528 +#: src/config/SSSDConfig/sssdoptions.py:534 msgid "Sudo rule command attribute" msgstr "Atrybut polecenia reguły sudo" -#: src/config/SSSDConfig/sssdoptions.py:529 +#: src/config/SSSDConfig/sssdoptions.py:535 msgid "Sudo rule host attribute" msgstr "Atrybut komputera reguły sudo" -#: src/config/SSSDConfig/sssdoptions.py:530 +#: src/config/SSSDConfig/sssdoptions.py:536 msgid "Sudo rule user attribute" msgstr "Atrybut użytkownika reguły sudo" -#: src/config/SSSDConfig/sssdoptions.py:531 +#: src/config/SSSDConfig/sssdoptions.py:537 msgid "Sudo rule option attribute" msgstr "Atrybut opcji reguły sudo" -#: src/config/SSSDConfig/sssdoptions.py:532 +#: src/config/SSSDConfig/sssdoptions.py:538 msgid "Sudo rule runas attribute" msgstr "Atrybut runas reguły sudo" -#: src/config/SSSDConfig/sssdoptions.py:533 +#: src/config/SSSDConfig/sssdoptions.py:539 msgid "Sudo rule runasuser attribute" msgstr "Atrybut runasuser reguły sudo" -#: src/config/SSSDConfig/sssdoptions.py:534 +#: src/config/SSSDConfig/sssdoptions.py:540 msgid "Sudo rule runasgroup attribute" msgstr "Atrybut runasgroup reguły sudo" -#: src/config/SSSDConfig/sssdoptions.py:535 +#: src/config/SSSDConfig/sssdoptions.py:541 msgid "Sudo rule notbefore attribute" msgstr "Atrybut notbefore reguły sudo" -#: src/config/SSSDConfig/sssdoptions.py:536 +#: src/config/SSSDConfig/sssdoptions.py:542 msgid "Sudo rule notafter attribute" msgstr "Atrybut notafter reguły sudo" -#: src/config/SSSDConfig/sssdoptions.py:537 +#: src/config/SSSDConfig/sssdoptions.py:543 msgid "Sudo rule order attribute" msgstr "Atrybut kolejności reguły sudo" -#: src/config/SSSDConfig/sssdoptions.py:540 +#: src/config/SSSDConfig/sssdoptions.py:546 msgid "Object class for automounter maps" msgstr "Klasa obiektów dla map automountera" -#: src/config/SSSDConfig/sssdoptions.py:541 +#: src/config/SSSDConfig/sssdoptions.py:547 msgid "Automounter map name attribute" msgstr "Atrybut nazwy mapy automountera" -#: src/config/SSSDConfig/sssdoptions.py:542 +#: src/config/SSSDConfig/sssdoptions.py:548 msgid "Object class for automounter map entries" msgstr "Klasa obiektów dla wpisów map automountera" -#: src/config/SSSDConfig/sssdoptions.py:543 +#: src/config/SSSDConfig/sssdoptions.py:549 msgid "Automounter map entry key attribute" msgstr "Atrybut klucza wpisu mapy automountera" -#: src/config/SSSDConfig/sssdoptions.py:544 +#: src/config/SSSDConfig/sssdoptions.py:550 msgid "Automounter map entry value attribute" msgstr "Atrybut wartości wpisu mapy automountera" -#: src/config/SSSDConfig/sssdoptions.py:545 +#: src/config/SSSDConfig/sssdoptions.py:551 msgid "Base DN for automounter map lookups" msgstr "Podstawowe DN dla wyszukiwań map automountera" -#: src/config/SSSDConfig/sssdoptions.py:546 +#: src/config/SSSDConfig/sssdoptions.py:552 msgid "The name of the automount master map in LDAP." msgstr "Nazwa głównej mapy automatycznego montowania w LDAP." -#: src/config/SSSDConfig/sssdoptions.py:549 +#: src/config/SSSDConfig/sssdoptions.py:555 msgid "Base DN for IP hosts lookups" msgstr "Podstawowe DN dla wyszukiwania IP komputerów" -#: src/config/SSSDConfig/sssdoptions.py:550 +#: src/config/SSSDConfig/sssdoptions.py:556 msgid "Object class for IP hosts" msgstr "Klasa obiektów dla IP komputerów" -#: src/config/SSSDConfig/sssdoptions.py:551 +#: src/config/SSSDConfig/sssdoptions.py:557 msgid "IP host name attribute" msgstr "Atrybut nazwy IP komputera" -#: src/config/SSSDConfig/sssdoptions.py:552 +#: src/config/SSSDConfig/sssdoptions.py:558 msgid "IP host number (address) attribute" msgstr "Atrybut numeru (adresu) IP komputera" -#: src/config/SSSDConfig/sssdoptions.py:553 +#: src/config/SSSDConfig/sssdoptions.py:559 msgid "IP host entryUSN attribute" msgstr "Atrybut entryUSN IP komputera" -#: src/config/SSSDConfig/sssdoptions.py:554 +#: src/config/SSSDConfig/sssdoptions.py:560 msgid "Base DN for IP networks lookups" msgstr "Podstawowe DN dla wyszukiwania IP sieci" -#: src/config/SSSDConfig/sssdoptions.py:555 +#: src/config/SSSDConfig/sssdoptions.py:561 msgid "Object class for IP networks" msgstr "Klasa obiektów dla IP sieci" -#: src/config/SSSDConfig/sssdoptions.py:556 +#: src/config/SSSDConfig/sssdoptions.py:562 msgid "IP network name attribute" msgstr "Atrybut nazwy IP sieci" -#: src/config/SSSDConfig/sssdoptions.py:557 +#: src/config/SSSDConfig/sssdoptions.py:563 msgid "IP network number (address) attribute" msgstr "Atrybut numeru (adresu) IP sieci" -#: src/config/SSSDConfig/sssdoptions.py:558 +#: src/config/SSSDConfig/sssdoptions.py:564 msgid "IP network entryUSN attribute" msgstr "Atrybut entryUSN IP sieci" -#: src/config/SSSDConfig/sssdoptions.py:561 +#: src/config/SSSDConfig/sssdoptions.py:567 msgid "Comma separated list of allowed users" msgstr "Lista dozwolonych użytkowników oddzielonych przecinkami" -#: src/config/SSSDConfig/sssdoptions.py:562 +#: src/config/SSSDConfig/sssdoptions.py:568 msgid "Comma separated list of prohibited users" msgstr "Lista zabronionych użytkowników oddzielonych przecinkami" -#: src/config/SSSDConfig/sssdoptions.py:563 +#: src/config/SSSDConfig/sssdoptions.py:569 msgid "" "Comma separated list of groups that are allowed to log in. This applies only " "to groups within this SSSD domain. Local groups are not evaluated." @@ -1981,7 +2030,7 @@ msgstr "" "zastosowanie tylko do grup w tej domenie SSSD. Lokalne grupy nie są " "sprawdzane." -#: src/config/SSSDConfig/sssdoptions.py:565 +#: src/config/SSSDConfig/sssdoptions.py:571 msgid "" "Comma separated list of groups that are explicitly denied access. This " "applies only to groups within this SSSD domain. Local groups are not " @@ -1991,32 +2040,32 @@ msgstr "" "dostęp. Ma to zastosowanie tylko do grup w tej domenie SSSD. Lokalne grupy " "nie są sprawdzane." -#: src/config/SSSDConfig/sssdoptions.py:569 +#: src/config/SSSDConfig/sssdoptions.py:575 msgid "The number of preforked proxy children." msgstr "Liczba elementów potomnych pośrednika przed rozwidleniem." -#: src/config/SSSDConfig/sssdoptions.py:572 +#: src/config/SSSDConfig/sssdoptions.py:578 msgid "The name of the NSS library to use" msgstr "Nazwa używanej biblioteki NSS" -#: src/config/SSSDConfig/sssdoptions.py:573 +#: src/config/SSSDConfig/sssdoptions.py:579 msgid "The name of the NSS library to use for hosts and networks lookups" msgstr "Nazwa biblioteki NSS używanej do wyszukiwania komputerów i sieci" -#: src/config/SSSDConfig/sssdoptions.py:574 +#: src/config/SSSDConfig/sssdoptions.py:580 msgid "Whether to look up canonical group name from cache if possible" msgstr "" "Czy wyszukiwać kanoniczną nazwę grupy w pamięci podręcznej, jeśli to możliwe" -#: src/config/SSSDConfig/sssdoptions.py:577 +#: src/config/SSSDConfig/sssdoptions.py:583 msgid "PAM stack to use" msgstr "Używany stos PAM" -#: src/config/SSSDConfig/sssdoptions.py:580 +#: src/config/SSSDConfig/sssdoptions.py:586 msgid "Path of passwd file sources." msgstr "Ścieżka źródeł pliku „passwd”." -#: src/config/SSSDConfig/sssdoptions.py:581 +#: src/config/SSSDConfig/sssdoptions.py:587 msgid "Path of group file sources." msgstr "Ścieżka źródeł pliku „group”." @@ -2047,159 +2096,163 @@ msgstr "" msgid "Option -i|--interactive is not allowed together with -D|--daemon\n" msgstr "Opcja -i|--interactive nie jest dozwolona z opcją -D|--daemon\n" -#: src/monitor/monitor.c:1836 +#: src/monitor/monitor.c:1838 msgid "Failed to get initial capabilities\n" msgstr "Uzyskanie początkowych możliwości się nie powiodło\n" -#: src/monitor/monitor.c:1847 +#: src/monitor/monitor.c:1849 msgid "Non-root service user support isn't built. Can't run under %" msgstr "" "Obsługa użytkownika usługi nie jako root nie jest zbudowana. Nie można " "uruchomić jako %" -#: src/monitor/monitor.c:1864 +#: src/monitor/monitor.c:1866 #, c-format msgid "Can't read config: '%s'\n" msgstr "Nie można odczytać konfiguracji: „%s”\n" -#: src/monitor/monitor.c:1876 -#, c-format -msgid "Failed to boostrap SSSD 'monitor' process: %s" +#: src/monitor/monitor.c:1878 +#, fuzzy, c-format +msgid "Failed to bootstrap SSSD 'monitor' process: %s" msgstr "" "Pierwsze uruchomienie procesu „monitor” usługi SSSD się nie powiodło: %s" -#: src/monitor/monitor.c:1971 +#: src/monitor/monitor.c:1973 msgid "Out of memory\n" msgstr "Brak pamięci\n" -#: src/providers/krb5/krb5_child.c:4221 +#: src/providers/krb5/krb5_child.c:4316 msgid "Use anonymous PKINIT to request FAST armor ticket" msgstr "Używa anonimowego PKINIT do żądania opakowanego biletu FAST" -#: src/providers/krb5/krb5_child.c:4223 +#: src/providers/krb5/krb5_child.c:4318 msgid "Kerberos realm to use" msgstr "Używany obszar Kerberosa" -#: src/providers/krb5/krb5_child.c:4225 +#: src/providers/krb5/krb5_child.c:4320 msgid "Requested lifetime of the ticket" msgstr "Żądany czas trwania biletu" -#: src/providers/krb5/krb5_child.c:4227 +#: src/providers/krb5/krb5_child.c:4322 msgid "Requested renewable lifetime of the ticket" msgstr "Żądany odnawialny czas trwania biletu" -#: src/providers/krb5/krb5_child.c:4229 +#: src/providers/krb5/krb5_child.c:4324 msgid "FAST options ('never', 'try', 'demand')" msgstr "Opcje FAST („never”, „try”, „demand”)" -#: src/providers/krb5/krb5_child.c:4232 +#: src/providers/krb5/krb5_child.c:4327 msgid "Specifies the server principal to use for FAST" msgstr "Podaje naczelnika serwera używanego dla FAST" -#: src/providers/krb5/krb5_child.c:4234 +#: src/providers/krb5/krb5_child.c:4329 msgid "Requests canonicalization of the principal name" msgstr "Żąda ujednolicenie nazwy naczelnika" -#: src/providers/krb5/krb5_child.c:4236 +#: src/providers/krb5/krb5_child.c:4331 msgid "Use custom version of krb5_get_init_creds_password" msgstr "Użycie niestandardowej wersji krb5_get_init_creds_password" -#: src/providers/krb5/krb5_child.c:4238 +#: src/providers/krb5/krb5_child.c:4333 msgid "Check PAC flags" msgstr "Sprawdza flagi PAC" -#: src/providers/data_provider_be.c:790 +#: src/providers/krb5/krb5_child.c:4335 +msgid "Set environment variable (KEY=VALUE)" +msgstr "" + +#: src/providers/data_provider_be.c:786 msgid "Domain of the information provider (mandatory)" msgstr "Domena dostawcy informacji (wymagane)" -#: src/sss_client/common.c:1165 +#: src/sss_client/common.c:1208 msgid "Socket has wrong ownership or permissions." msgstr "Gniazdo ma błędnego właściciela lub uprawnienia." -#: src/sss_client/common.c:1168 +#: src/sss_client/common.c:1211 msgid "Unexpected format of the server credential message." msgstr "Nieoczekiwany format komunikatu uwierzytelniającego serwera." -#: src/sss_client/common.c:1171 +#: src/sss_client/common.c:1214 msgid "SSSD is not run by trusted user." msgstr "SSSD nie zostało uruchomione przez zaufanego użytkownika." -#: src/sss_client/common.c:1174 +#: src/sss_client/common.c:1217 msgid "SSSD socket does not exist." msgstr "Gniazdo SSSD nie istnieje." -#: src/sss_client/common.c:1177 +#: src/sss_client/common.c:1220 msgid "Cannot get stat of SSSD socket." msgstr "Nie można wykonać „stat” na gnieździe SSSD." -#: src/sss_client/common.c:1182 +#: src/sss_client/common.c:1225 msgid "An error occurred, but no description can be found." msgstr "Wystąpił błąd, ale nie odnaleziono jego opisu." -#: src/sss_client/common.c:1188 +#: src/sss_client/common.c:1231 msgid "Unexpected error while looking for an error description" msgstr "Nieoczekiwany błąd podczas wyszukiwania opisu błędu" -#: src/sss_client/pam_sss.c:74 +#: src/sss_client/pam_sss.c:135 msgid "Permission denied. " msgstr "Odmowa uprawnienia. " -#: src/sss_client/pam_sss.c:75 src/sss_client/pam_sss.c:843 -#: src/sss_client/pam_sss.c:854 +#: src/sss_client/pam_sss.c:136 src/sss_client/pam_sss.c:921 +#: src/sss_client/pam_sss.c:932 msgid "Server message: " msgstr "Komunikat serwera: " -#: src/sss_client/pam_sss.c:76 +#: src/sss_client/pam_sss.c:137 msgid "" "Kerberos TGT will not be granted upon login, user experience will be " "affected." msgstr "" "TGT Kerberosa nie będzie nadawany po zalogowaniu, co wpłynie na użytkownika." -#: src/sss_client/pam_sss.c:77 +#: src/sss_client/pam_sss.c:138 msgid "Enter PIN:" msgstr "Proszę podać kod PIN:" -#: src/sss_client/pam_sss.c:320 +#: src/sss_client/pam_sss.c:385 msgid "Passwords do not match" msgstr "Hasła się nie zgadzają" -#: src/sss_client/pam_sss.c:508 +#: src/sss_client/pam_sss.c:584 msgid "Password reset by root is not supported." msgstr "Przywrócenie hasła przez użytkownika root nie jest obsługiwane." -#: src/sss_client/pam_sss.c:549 +#: src/sss_client/pam_sss.c:625 msgid "Authenticated with cached credentials" msgstr "Uwierzytelniono za pomocą danych z pamięci podręcznej" -#: src/sss_client/pam_sss.c:550 +#: src/sss_client/pam_sss.c:626 msgid ", your cached password will expire at: " msgstr ", hasło w pamięci podręcznej wygaśnie za: " -#: src/sss_client/pam_sss.c:580 +#: src/sss_client/pam_sss.c:656 #, c-format msgid "Your password has expired. You have %1$d grace login(s) remaining." msgstr "Hasło wygasło. Pozostało %1$d możliwych logowań." -#: src/sss_client/pam_sss.c:630 +#: src/sss_client/pam_sss.c:706 #, c-format msgid "Your password will expire in %1$d %2$s." msgstr "Hasło wygaśnie za %1$d %2$s." -#: src/sss_client/pam_sss.c:633 +#: src/sss_client/pam_sss.c:709 #, c-format msgid "Your password has expired." msgstr "Hasło wygasło." -#: src/sss_client/pam_sss.c:684 +#: src/sss_client/pam_sss.c:760 msgid "Authentication is denied until: " msgstr "Uwierzytelnianie jest zabronione do: " -#: src/sss_client/pam_sss.c:705 +#: src/sss_client/pam_sss.c:781 msgid "System is offline, password change not possible" msgstr "System jest w trybie offline, zmiana hasła nie jest możliwa" -#: src/sss_client/pam_sss.c:720 +#: src/sss_client/pam_sss.c:796 msgid "" "After changing the OTP password, you need to log out and back in order to " "acquire a ticket" @@ -2207,11 +2260,11 @@ msgstr "" "Po zmianie hasła OTP należy się wylogować i zalogować ponownie, aby uzyskać " "bilet" -#: src/sss_client/pam_sss.c:735 +#: src/sss_client/pam_sss.c:813 msgid "PIN locked" msgstr "Zablokowano kod PIN" -#: src/sss_client/pam_sss.c:750 +#: src/sss_client/pam_sss.c:828 msgid "" "No Kerberos TGT granted as the server does not support this method. Your " "single-sign on(SSO) experience will be affected." @@ -2219,64 +2272,68 @@ msgstr "" "Nie nadano TGT Kerberosa, jako że serwer nie obsługuje tej metody, co " "wpłynie na pojedyncze logowanie (SSO)." -#: src/sss_client/pam_sss.c:840 src/sss_client/pam_sss.c:853 +#: src/sss_client/pam_sss.c:918 src/sss_client/pam_sss.c:931 msgid "Password change failed. " msgstr "Zmiana hasła się nie powiodła. " -#: src/sss_client/pam_sss.c:1859 -#, c-format -msgid "Authenticate at %1$s and press ENTER." +#: src/sss_client/pam_sss.c:2028 +#, fuzzy, c-format +msgid "Authenticate at \"%1$s\"." msgstr "Proszę uwierzytelnić pod adresem %1$s i nacisnąć klawisz Enter." -#: src/sss_client/pam_sss.c:1862 -#, c-format -msgid "Authenticate with PIN %1$s at %2$s and press ENTER." +#: src/sss_client/pam_sss.c:2031 +#, fuzzy, c-format +msgid "Authenticate with PIN \"%1$s\" at \"%2$s\"." msgstr "" "Proszę uwierzytelnić za pomocą kodu PIN %1$s pod adresem %2$s i nacisnąć " "klawisz Enter." -#: src/sss_client/pam_sss.c:2281 +#: src/sss_client/pam_sss.c:2470 msgid "Please (re)insert (different) Smartcard" msgstr "Proszę (ponownie) włożyć (inną) kartę smartcard" -#: src/sss_client/pam_sss.c:2482 +#: src/sss_client/pam_sss.c:2700 msgid "New Password: " msgstr "Nowe hasło: " -#: src/sss_client/pam_sss.c:2483 +#: src/sss_client/pam_sss.c:2701 msgid "Reenter new Password: " msgstr "Proszę ponownie podać nowe hasło: " -#: src/sss_client/pam_sss.c:2676 src/sss_client/pam_sss.c:2679 +#: src/sss_client/pam_sss.c:2890 +msgid "Press ENTER to continue." +msgstr "" + +#: src/sss_client/pam_sss.c:2913 src/sss_client/pam_sss.c:2916 msgid "First Factor: " msgstr "Pierwszy czynnik: " -#: src/sss_client/pam_sss.c:2677 src/sss_client/pam_sss.c:2851 +#: src/sss_client/pam_sss.c:2914 src/sss_client/pam_sss.c:3088 msgid "Second Factor (optional): " msgstr "Drugi czynnik (opcjonalnie): " -#: src/sss_client/pam_sss.c:2680 src/sss_client/pam_sss.c:2855 +#: src/sss_client/pam_sss.c:2917 src/sss_client/pam_sss.c:3092 msgid "Second Factor: " msgstr "Drugi czynnik: " -#: src/sss_client/pam_sss.c:2684 +#: src/sss_client/pam_sss.c:2921 msgid "Insert your passkey device, then press ENTER." msgstr "" "Proszę włożyć urządzenie hasła-klucza, a następnie nacisnąć klawisz Enter." -#: src/sss_client/pam_sss.c:2688 src/sss_client/pam_sss.c:2696 +#: src/sss_client/pam_sss.c:2925 src/sss_client/pam_sss.c:2933 msgid "Password: " msgstr "Hasło: " -#: src/sss_client/pam_sss.c:2850 src/sss_client/pam_sss.c:2854 +#: src/sss_client/pam_sss.c:3087 src/sss_client/pam_sss.c:3091 msgid "First Factor (Current Password): " msgstr "Pierwszy czynnik (obecne hasło): " -#: src/sss_client/pam_sss.c:2874 +#: src/sss_client/pam_sss.c:3111 msgid "Current Password: " msgstr "Bieżące hasło: " -#: src/sss_client/pam_sss.c:3248 +#: src/sss_client/pam_sss.c:3485 msgid "Password expired. Change your password now." msgstr "Hasło wygasło. Proszę je zmienić teraz." @@ -2425,8 +2482,9 @@ msgid "" "Could not open domain %1$s. If the domain is a subdomain (trusted domain), " "use fully qualified name instead of --domain/-d parameter.\n" msgstr "" -"Nie można otworzyć domeny %1$s. Jeśli domena jest poddomeną (zaufaną domeną)" -", należy użyć w pełni kwalifikowanej nazwy zamiast parametru --domain/-d.\n" +"Nie można otworzyć domeny %1$s. Jeśli domena jest poddomeną (zaufaną " +"domeną), należy użyć w pełni kwalifikowanej nazwy zamiast parametru --" +"domain/-d.\n" #: src/tools/sss_cache.c:897 msgid "Could not open available domains\n" @@ -2723,9 +2781,9 @@ msgstr "Wyświetlenie obiektu się nie powiodło: %s\n" #: src/tools/sssctl/sssctl_cache.c:835 src/tools/sssctl/sssctl_cache.c:918 #: src/tools/sssctl/sssctl_cache.c:950 src/tools/sssctl/sssctl_cache.c:956 #: src/tools/sssctl/sssctl_cache.c:1010 src/tools/sssctl/sssctl_cache.c:1034 -#: src/tools/sssctl/sssctl_cache.c:1085 src/tools/sssctl/sssctl_cache.c:1194 -#: src/tools/sssctl/sssctl_cache.c:1229 src/tools/sssctl/sssctl_cache.c:1235 -#: src/tools/sssctl/sssctl_cache.c:1244 +#: src/tools/sssctl/sssctl_cache.c:1085 src/tools/sssctl/sssctl_cache.c:1195 +#: src/tools/sssctl/sssctl_cache.c:1230 src/tools/sssctl/sssctl_cache.c:1236 +#: src/tools/sssctl/sssctl_cache.c:1245 msgid "talloc failed\n" msgstr "talloc się nie powiodło\n" @@ -2802,25 +2860,25 @@ msgstr "" msgid "Unable to remove downloaded GPO files: %s\n" msgstr "Nie można usunąć pobranych plików GPO: %s\n" -#: src/tools/sssctl/sssctl_cache.c:1165 +#: src/tools/sssctl/sssctl_cache.c:1166 #, c-format msgid "Failed to fetch cache entry: %s\n" msgstr "Pobranie wpisu pamięci podręcznej się nie powiodło: %s\n" -#: src/tools/sssctl/sssctl_cache.c:1170 +#: src/tools/sssctl/sssctl_cache.c:1171 msgid "Could not determine object domain\n" msgstr "Nie można ustalić domeny obiektu\n" -#: src/tools/sssctl/sssctl_cache.c:1200 +#: src/tools/sssctl/sssctl_cache.c:1201 msgid "Could not find GUID attribute in GPO entry\n" msgstr "Nie można odnaleźć atrybutu GUID we wpisie GPO\n" -#: src/tools/sssctl/sssctl_cache.c:1206 +#: src/tools/sssctl/sssctl_cache.c:1207 #, c-format msgid "Failed to delete GPO: %s\n" msgstr "Usunięcie GPO się nie powiodło: %s\n" -#: src/tools/sssctl/sssctl_cache.c:1210 +#: src/tools/sssctl/sssctl_cache.c:1211 #, c-format msgid "%s removed from cache\n" msgstr "Usunięto %s z pamięci podręcznej\n" @@ -2917,40 +2975,41 @@ msgstr "" "„/moja/ścieżka/sssd.conf”, to używany jest katalog wstawek „/moja/ścieżka/" "conf.d”)" -#: src/tools/sssctl/sssctl_config.c:114 +#: src/tools/sssctl/sssctl_config.c:126 #, c-format msgid "File %1$s does not exist.\n" msgstr "Plik %1$s nie istnieje.\n" -#: src/tools/sssctl/sssctl_config.c:115 +#: src/tools/sssctl/sssctl_config.c:127 msgid "There is no configuration.\n" msgstr "Nie ma konfiguracji.\n" -#: src/tools/sssctl/sssctl_config.c:120 +#: src/tools/sssctl/sssctl_config.c:132 #, c-format msgid "Configuration validation failed: %s\n" msgstr "Sprawdzenie poprawności konfiguracji się nie powiodło: %s\n" -#: src/tools/sssctl/sssctl_config.c:121 +#: src/tools/sssctl/sssctl_config.c:133 msgid "Run with high debug level to see details.\n" msgstr "" "Uruchomienie na wysokim poziomie debugowania wyświetli więcej informacji.\n" -#: src/tools/sssctl/sssctl_config.c:130 -msgid "Failed to run validators" +#: src/tools/sssctl/sssctl_config.c:142 +#, fuzzy +msgid "Failed to run validators\n" msgstr "Uruchomienie programów sprawdzających poprawność się nie powiodło" -#: src/tools/sssctl/sssctl_config.c:134 +#: src/tools/sssctl/sssctl_config.c:146 #, c-format msgid "Issues identified by validators: %zu\n" msgstr "Problemy zidentyfikowane przez programy sprawdzające poprawność: %zu\n" -#: src/tools/sssctl/sssctl_config.c:145 +#: src/tools/sssctl/sssctl_config.c:157 #, c-format msgid "Messages generated during configuration merging: %zu\n" msgstr "Komunikaty utworzone podczas łączenia konfiguracji: %zu\n" -#: src/tools/sssctl/sssctl_config.c:158 +#: src/tools/sssctl/sssctl_config.c:170 #, c-format msgid "Used configuration snippet files: %zu\n" msgstr "Użyte pliki wstawek konfiguracji: %zu\n" diff --git a/po/pt.po b/po/pt.po index 339c3f10f97..ab93b174d87 100644 --- a/po/pt.po +++ b/po/pt.po @@ -9,8 +9,8 @@ msgid "" msgstr "" "Project-Id-Version: PACKAGE VERSION\n" "Report-Msgid-Bugs-To: sssd-devel@lists.fedorahosted.org\n" -"POT-Creation-Date: 2026-01-14 14:57+0000\n" -"PO-Revision-Date: 2026-04-23 16:44+0000\n" +"POT-Creation-Date: 2026-10-02 15:57+0000\n" +"PO-Revision-Date: 2026-10-05 21:20+0000\n" "Last-Translator: Weblate Translation Memory \n" "Language-Team: Portuguese : that must be enforced " "for PAM access with GSSAPI authentication" @@ -392,31 +393,40 @@ msgstr "" "Lista de pares : que têm de ser " "impostos para acesso PAM com autenticação GSSAPI" -#: src/config/SSSDConfig/sssdoptions.py:113 +#: src/config/SSSDConfig/sssdoptions.py:109 +msgid "" +"List of triples :: that assigns " +"additional information from the Kerberos ticket to an authentication " +"indicator." +msgstr "" +"Lista de triplos :: que atribui " +"informação adicional do bilhete Kerberos a um indicador de autenticação." + +#: src/config/SSSDConfig/sssdoptions.py:112 msgid "Allow passkey device authentication." msgstr "Permitir autenticação de dispositivo passkey." -#: src/config/SSSDConfig/sssdoptions.py:114 +#: src/config/SSSDConfig/sssdoptions.py:113 msgid "How many seconds will pam_sss wait for passkey_child to finish" msgstr "Quantos segundos irá o pam_sss esperar pelo passkey_child terminar" -#: src/config/SSSDConfig/sssdoptions.py:115 +#: src/config/SSSDConfig/sssdoptions.py:114 msgid "Enable debugging in the libfido2 library" msgstr "Ativa depuração na biblioteca libfido2" -#: src/config/SSSDConfig/sssdoptions.py:116 +#: src/config/SSSDConfig/sssdoptions.py:115 msgid "Enable JSON protocol for authentication methods selection." msgstr "Ativar protocolo JSON para seleção de métodos de autenticação." -#: src/config/SSSDConfig/sssdoptions.py:119 +#: src/config/SSSDConfig/sssdoptions.py:118 msgid "Whether to evaluate the time-based attributes in sudo rules" msgstr "Se deve-se avaliar os atributos baseados em hora nas regras sudo" -#: src/config/SSSDConfig/sssdoptions.py:120 +#: src/config/SSSDConfig/sssdoptions.py:119 msgid "If true, SSSD will switch back to lower-wins ordering logic" msgstr "Se true, SSSD irá comutar para lógica de ordenação lower-wins" -#: src/config/SSSDConfig/sssdoptions.py:121 +#: src/config/SSSDConfig/sssdoptions.py:120 msgid "" "Maximum number of rules that can be refreshed at once. If this is exceeded, " "full refresh is performed." @@ -424,13 +434,13 @@ msgstr "" "Número máximo de regras que podem ser refrescadas de uma vez. Se sito for " "excedido, é executado refrescar total." -#: src/config/SSSDConfig/sssdoptions.py:128 +#: src/config/SSSDConfig/sssdoptions.py:127 msgid "Whether to hash host names and addresses in the known_hosts file" msgstr "" "Se deve-se guarda nomes de máquinas e endereços em cinzas no ficheiro " "known_hosts" -#: src/config/SSSDConfig/sssdoptions.py:129 +#: src/config/SSSDConfig/sssdoptions.py:128 msgid "" "How many seconds to keep a host in the known_hosts file after its host keys " "were requested" @@ -438,15 +448,15 @@ msgstr "" "Durante quantos segundos manter uma máquina no ficheiro known_hosts após as " "chaves dessa máquina serem requisitadas" -#: src/config/SSSDConfig/sssdoptions.py:131 +#: src/config/SSSDConfig/sssdoptions.py:130 msgid "Path to storage of trusted CA certificates" msgstr "Caminho para armazém de certificados CA de confiança" -#: src/config/SSSDConfig/sssdoptions.py:132 +#: src/config/SSSDConfig/sssdoptions.py:131 msgid "Allow to generate ssh-keys from certificates" msgstr "Permite gerar chaves ssh a partir de certificados" -#: src/config/SSSDConfig/sssdoptions.py:133 +#: src/config/SSSDConfig/sssdoptions.py:132 msgid "" "Use the following matching rules to filter the certificates for ssh-key " "generation" @@ -454,26 +464,26 @@ msgstr "" "Usa as seguintes regras de correspondência para filtrar os cerificados para " "a geração de chave ssh" -#: src/config/SSSDConfig/sssdoptions.py:137 +#: src/config/SSSDConfig/sssdoptions.py:136 msgid "List of UIDs or user names allowed to access the PAC responder" msgstr "" "Lista de UIDs ou nomes de utilizador com permissão de acesso ao respondedor " "PAC" -#: src/config/SSSDConfig/sssdoptions.py:138 +#: src/config/SSSDConfig/sssdoptions.py:137 msgid "How long the PAC data is considered valid" msgstr "Durante quanto tempo os dados PAC são considerados válidos" -#: src/config/SSSDConfig/sssdoptions.py:139 +#: src/config/SSSDConfig/sssdoptions.py:138 msgid "Validate the PAC" msgstr "Valida o PAC" -#: src/config/SSSDConfig/sssdoptions.py:142 +#: src/config/SSSDConfig/sssdoptions.py:141 msgid "List of user attributes the InfoPipe is allowed to publish" msgstr "" "Lista de atributos de utilizador que o InfoPipe tem permissão de publicar" -#: src/config/SSSDConfig/sssdoptions.py:145 +#: src/config/SSSDConfig/sssdoptions.py:144 msgid "" "One of the following strings specifying the scope of session recording: none " "- No users are recorded. some - Users/groups specified by users and groups " @@ -484,7 +494,7 @@ msgstr "" "especificados pelas opções users e groups são registados. all - Todos os " "utilizadores são registados." -#: src/config/SSSDConfig/sssdoptions.py:148 +#: src/config/SSSDConfig/sssdoptions.py:147 msgid "" "A comma-separated list of users which should have session recording enabled. " "Matches user names as returned by NSS. I.e. after the possible space " @@ -495,7 +505,7 @@ msgstr "" "isto é, após a possível substituição de espaços, alterações de minúscula/" "maiúscula, etc." -#: src/config/SSSDConfig/sssdoptions.py:150 +#: src/config/SSSDConfig/sssdoptions.py:149 msgid "" "A comma-separated list of groups, members of which should have session " "recording enabled. Matches group names as returned by NSS. I.e. after the " @@ -506,7 +516,7 @@ msgstr "" "isto é, após a possível substituição de espaços, alterações de minúscula/" "maiúscula, etc." -#: src/config/SSSDConfig/sssdoptions.py:153 +#: src/config/SSSDConfig/sssdoptions.py:152 msgid "" "A comma-separated list of users to be excluded from recording, only when " "scope=all" @@ -514,7 +524,7 @@ msgstr "" "Uma lista de utilizadores separados por vírgulas a serem excluídos de " "registo, apenas quando scope=all" -#: src/config/SSSDConfig/sssdoptions.py:154 +#: src/config/SSSDConfig/sssdoptions.py:153 msgid "" "A comma-separated list of groups, members of which should be excluded from " "recording, only when scope=all. " @@ -522,79 +532,79 @@ msgstr "" "Uma lista de grupos separados por vírgulas, cujos membros devem ser " "excluídos de registo, apenas quando scope=all. " -#: src/config/SSSDConfig/sssdoptions.py:158 +#: src/config/SSSDConfig/sssdoptions.py:157 msgid "Identity provider" msgstr "Provedor de identidade" -#: src/config/SSSDConfig/sssdoptions.py:159 +#: src/config/SSSDConfig/sssdoptions.py:158 msgid "Authentication provider" msgstr "Provedor de autenticação" -#: src/config/SSSDConfig/sssdoptions.py:160 +#: src/config/SSSDConfig/sssdoptions.py:159 msgid "Access control provider" msgstr "Provedor de controle de acesso" -#: src/config/SSSDConfig/sssdoptions.py:161 +#: src/config/SSSDConfig/sssdoptions.py:160 msgid "Password change provider" msgstr "Provedor de alteração de palavra passe" -#: src/config/SSSDConfig/sssdoptions.py:162 +#: src/config/SSSDConfig/sssdoptions.py:161 msgid "SUDO provider" msgstr "Provedor do SUDO" -#: src/config/SSSDConfig/sssdoptions.py:163 +#: src/config/SSSDConfig/sssdoptions.py:162 msgid "Autofs provider" msgstr "Provedor Autofs" -#: src/config/SSSDConfig/sssdoptions.py:164 +#: src/config/SSSDConfig/sssdoptions.py:163 msgid "Host identity provider" msgstr "Provedor de identidade de máquina" -#: src/config/SSSDConfig/sssdoptions.py:165 +#: src/config/SSSDConfig/sssdoptions.py:164 msgid "SELinux provider" msgstr "Provedor do SELinux" -#: src/config/SSSDConfig/sssdoptions.py:166 +#: src/config/SSSDConfig/sssdoptions.py:165 msgid "Session management provider" msgstr "Provedor de gestão de sessão" -#: src/config/SSSDConfig/sssdoptions.py:167 +#: src/config/SSSDConfig/sssdoptions.py:166 msgid "Resolver provider" msgstr "Provedor de resolvedor" -#: src/config/SSSDConfig/sssdoptions.py:170 +#: src/config/SSSDConfig/sssdoptions.py:169 msgid "Whether the domain is usable by the OS or by applications" msgstr "Se o domínio é utilizável pelo OS ou pelas aplicações" -#: src/config/SSSDConfig/sssdoptions.py:171 +#: src/config/SSSDConfig/sssdoptions.py:170 msgid "Enable or disable the domain" msgstr "Activar ou desactivar o domínio" -#: src/config/SSSDConfig/sssdoptions.py:172 +#: src/config/SSSDConfig/sssdoptions.py:171 msgid "Minimum user ID" msgstr "ID de utilizador mínimo" -#: src/config/SSSDConfig/sssdoptions.py:173 +#: src/config/SSSDConfig/sssdoptions.py:172 msgid "Maximum user ID" msgstr "ID de utilizador máximo" -#: src/config/SSSDConfig/sssdoptions.py:174 +#: src/config/SSSDConfig/sssdoptions.py:173 msgid "Enable enumerating all users/groups" msgstr "Permitir enumeração de todos os utilizadores/grupos" -#: src/config/SSSDConfig/sssdoptions.py:175 +#: src/config/SSSDConfig/sssdoptions.py:174 msgid "Cache credentials for offline login" msgstr "Usar cache de credenciais para inicio de sessões em modo desligado" -#: src/config/SSSDConfig/sssdoptions.py:176 +#: src/config/SSSDConfig/sssdoptions.py:175 msgid "Display users/groups in fully-qualified form" msgstr "Apresentar utilizadores/grupos no formato totalmente qualificado" -#: src/config/SSSDConfig/sssdoptions.py:177 +#: src/config/SSSDConfig/sssdoptions.py:176 msgid "Don't include group members in group lookups" msgstr "Não inclui membros de grupo em pesquisas de grupo" -#: src/config/SSSDConfig/sssdoptions.py:178 +#: src/config/SSSDConfig/sssdoptions.py:177 #: src/config/SSSDConfig/sssdoptions.py:190 #: src/config/SSSDConfig/sssdoptions.py:191 #: src/config/SSSDConfig/sssdoptions.py:192 @@ -605,20 +615,20 @@ msgstr "Não inclui membros de grupo em pesquisas de grupo" msgid "Entry cache timeout length (seconds)" msgstr "Tempo limite da entrada de cache (segundos)" -#: src/config/SSSDConfig/sssdoptions.py:179 +#: src/config/SSSDConfig/sssdoptions.py:178 msgid "" "Restrict or prefer a specific address family when performing DNS lookups" msgstr "" "Restringir ou preferir uma família de endereços específicos quando efectua " "consultas DNS" -#: src/config/SSSDConfig/sssdoptions.py:180 +#: src/config/SSSDConfig/sssdoptions.py:179 msgid "How long to keep cached entries after last successful login (days)" msgstr "" "Durante quanto tempo manter as entradas em cache após o último login bem " "sucedido (dias)" -#: src/config/SSSDConfig/sssdoptions.py:181 +#: src/config/SSSDConfig/sssdoptions.py:180 msgid "" "How long should SSSD talk to single DNS server before trying next server " "(miliseconds)" @@ -626,23 +636,23 @@ msgstr "" "Durante quanto tempo deve o SSSD falar com um único servidor DNS antes de " "tentar o próximo servidor (milisegundos)" -#: src/config/SSSDConfig/sssdoptions.py:183 +#: src/config/SSSDConfig/sssdoptions.py:182 msgid "How long should keep trying to resolve single DNS query (seconds)" msgstr "" "Durante quanto tempo deve-se continuar a tentar resolver consultas DNS " "únicas (segundos)" -#: src/config/SSSDConfig/sssdoptions.py:184 +#: src/config/SSSDConfig/sssdoptions.py:183 msgid "How long to wait for replies from DNS when resolving servers (seconds)" msgstr "" "Durante quanto tempo esperar por respostas DNS quando se resolve servidores " "(segundos)" -#: src/config/SSSDConfig/sssdoptions.py:185 +#: src/config/SSSDConfig/sssdoptions.py:184 msgid "The domain part of service discovery DNS query" msgstr "A parte domínio da consulta DNS de descoberta de serviço" -#: src/config/SSSDConfig/sssdoptions.py:186 +#: src/config/SSSDConfig/sssdoptions.py:185 msgid "" "Specifies the interval, in seconds, that SSSD waits before attempting to " "reconnect to the primary server after a successful connection to the backup " @@ -652,14 +662,18 @@ msgstr "" "ligar ao servidor principal após uma ligação com sucesso ao servidor de " "salvaguarda" -#: src/config/SSSDConfig/sssdoptions.py:188 +#: src/config/SSSDConfig/sssdoptions.py:187 msgid "Override GID value from the identity provider with this value" msgstr "Sobrepõe o valor GID do provedor de identidade com este valor" -#: src/config/SSSDConfig/sssdoptions.py:189 +#: src/config/SSSDConfig/sssdoptions.py:188 msgid "Treat usernames as case sensitive" msgstr "Trata nomes de utilizador como sensível a maiúsculas/minúsculas" +#: src/config/SSSDConfig/sssdoptions.py:189 +msgid "Lookups by ID are expensive or do not work at all" +msgstr "Pesquisas pelo ID são dispendiosas e não funcionam de todo" + #: src/config/SSSDConfig/sssdoptions.py:197 msgid "How often should expired entries be refreshed in background" msgstr "" @@ -904,7 +918,7 @@ msgid "Search base for SUBID ranges" msgstr "Base de busca para gamas SUBID" #: src/config/SSSDConfig/sssdoptions.py:259 -#: src/config/SSSDConfig/sssdoptions.py:506 +#: src/config/SSSDConfig/sssdoptions.py:512 msgid "Which rules should be used to evaluate access control" msgstr "Quais regras devem ser usadas para avaliar o controle de acesso" @@ -1062,7 +1076,7 @@ msgid "Enable DNS sites - location based service discovery" msgstr "Activa sítios DNS - descoberta de serviços baseada em localização" #: src/config/SSSDConfig/sssdoptions.py:301 -#: src/config/SSSDConfig/sssdoptions.py:504 +#: src/config/SSSDConfig/sssdoptions.py:510 msgid "LDAP filter to determine access privileges" msgstr "Filtro LDAP para determinar privilégios de acesso" @@ -1087,37 +1101,37 @@ msgid "" "PAM service names that map to the GPO (Deny)InteractiveLogonRight policy " "settings" msgstr "" -"Nomes de serviço PAM que mapeiam as definições de política GPO (Deny)" -"InteractiveLogonRight" +"Nomes de serviço PAM que mapeiam as definições de política GPO " +"(Deny)InteractiveLogonRight" #: src/config/SSSDConfig/sssdoptions.py:307 msgid "" "PAM service names that map to the GPO (Deny)RemoteInteractiveLogonRight " "policy settings" msgstr "" -"Nomes de serviço PAM que mapeiam as definições de política GPO (Deny)" -"RemoteInteractiveLogonRight" +"Nomes de serviço PAM que mapeiam as definições de política GPO " +"(Deny)RemoteInteractiveLogonRight" #: src/config/SSSDConfig/sssdoptions.py:309 msgid "" "PAM service names that map to the GPO (Deny)NetworkLogonRight policy settings" msgstr "" -"Nomes de serviço PAM que mapeiam as definições de política GPO (Deny)" -"NetworkLogonRight" +"Nomes de serviço PAM que mapeiam as definições de política GPO " +"(Deny)NetworkLogonRight" #: src/config/SSSDConfig/sssdoptions.py:310 msgid "" "PAM service names that map to the GPO (Deny)BatchLogonRight policy settings" msgstr "" -"Nomes de serviço PAM que mapeiam as definições de política GPO (Deny)" -"BatchLogonRight" +"Nomes de serviço PAM que mapeiam as definições de política GPO " +"(Deny)BatchLogonRight" #: src/config/SSSDConfig/sssdoptions.py:311 msgid "" "PAM service names that map to the GPO (Deny)ServiceLogonRight policy settings" msgstr "" -"Nomes de serviço PAM que mapeiam as definições de política GPO (Deny)" -"ServiceLogonRight" +"Nomes de serviço PAM que mapeiam as definições de política GPO " +"(Deny)ServiceLogonRight" #: src/config/SSSDConfig/sssdoptions.py:312 msgid "PAM service names for which GPO-based access is always granted" @@ -1513,7 +1527,7 @@ msgid "UUID attribute" msgstr "Atributo UUID" #: src/config/SSSDConfig/sssdoptions.py:423 -#: src/config/SSSDConfig/sssdoptions.py:464 +#: src/config/SSSDConfig/sssdoptions.py:470 msgid "objectSID attribute" msgstr "Atributo objectSID" @@ -1642,178 +1656,202 @@ msgstr "" "Uma lista de atributos extra a descarregar juntamente com a entrada do " "utilizador" +#: src/config/SSSDConfig/sssdoptions.py:456 +msgid "The object class of an subid entry in LDAP." +msgstr "A classe de objecto de uma entrada sub-id em LDAP." + #: src/config/SSSDConfig/sssdoptions.py:457 +msgid "Subordinate user ID count attribute" +msgstr "Atributo de contagem de ID de utilizador subordinado" + +#: src/config/SSSDConfig/sssdoptions.py:458 +msgid "Subordinate group ID count attribute" +msgstr "Atributo de contagem de ID de grupo subordinado" + +#: src/config/SSSDConfig/sssdoptions.py:459 +msgid "User ID range start value attribute" +msgstr "Atributo de valor de inicio da gama de ID de utilizador" + +#: src/config/SSSDConfig/sssdoptions.py:460 +msgid "Group ID range start value attribute" +msgstr "Atributo de valor de inicio da gama de ID de grupo" + +#: src/config/SSSDConfig/sssdoptions.py:461 +msgid "Owner of an entry" +msgstr "Dono de uma entrada" + +#: src/config/SSSDConfig/sssdoptions.py:463 msgid "Base DN for group lookups" msgstr "DN base para pesquisa de grupos" -#: src/config/SSSDConfig/sssdoptions.py:458 +#: src/config/SSSDConfig/sssdoptions.py:464 msgid "Objectclass for groups" msgstr "Classe de objeto para grupos" -#: src/config/SSSDConfig/sssdoptions.py:459 +#: src/config/SSSDConfig/sssdoptions.py:465 msgid "Group name" msgstr "Nome do Grupo" -#: src/config/SSSDConfig/sssdoptions.py:460 +#: src/config/SSSDConfig/sssdoptions.py:466 msgid "Group password" msgstr "Palavra-passe do Grupo" -#: src/config/SSSDConfig/sssdoptions.py:461 +#: src/config/SSSDConfig/sssdoptions.py:467 msgid "GID attribute" msgstr "Atributo GID" -#: src/config/SSSDConfig/sssdoptions.py:462 +#: src/config/SSSDConfig/sssdoptions.py:468 msgid "Group member attribute" msgstr "Atributo de membro de grupo" -#: src/config/SSSDConfig/sssdoptions.py:463 +#: src/config/SSSDConfig/sssdoptions.py:469 msgid "Group UUID attribute" msgstr "Atributo UUID de grupo" -#: src/config/SSSDConfig/sssdoptions.py:465 +#: src/config/SSSDConfig/sssdoptions.py:471 msgid "Modification time attribute for groups" msgstr "Atributo de modificação de tempo para grupos" -#: src/config/SSSDConfig/sssdoptions.py:466 +#: src/config/SSSDConfig/sssdoptions.py:472 msgid "Type of the group and other flags" msgstr "Tipo de grupo e outras bandeiras" -#: src/config/SSSDConfig/sssdoptions.py:467 +#: src/config/SSSDConfig/sssdoptions.py:473 msgid "The LDAP group external member attribute" msgstr "O atributo de membro externo do grupo LDAP" -#: src/config/SSSDConfig/sssdoptions.py:468 +#: src/config/SSSDConfig/sssdoptions.py:474 msgid "Maximum nesting level SSSD will follow" msgstr "Nível máximo de aninhamento que o SSSD irá seguir" -#: src/config/SSSDConfig/sssdoptions.py:469 +#: src/config/SSSDConfig/sssdoptions.py:475 msgid "Filter for group lookups" msgstr "Filtro para pesquisas de grupo" -#: src/config/SSSDConfig/sssdoptions.py:470 +#: src/config/SSSDConfig/sssdoptions.py:476 msgid "Scope of group lookups" msgstr "Escopo para pesquisas de grupo" -#: src/config/SSSDConfig/sssdoptions.py:472 +#: src/config/SSSDConfig/sssdoptions.py:478 msgid "Base DN for netgroup lookups" msgstr "DN base para pesquisas de netgroup" -#: src/config/SSSDConfig/sssdoptions.py:473 +#: src/config/SSSDConfig/sssdoptions.py:479 msgid "Objectclass for netgroups" msgstr "Classe de objeto para netgroups" -#: src/config/SSSDConfig/sssdoptions.py:474 +#: src/config/SSSDConfig/sssdoptions.py:480 msgid "Netgroup name" msgstr "Nome do netgroup" -#: src/config/SSSDConfig/sssdoptions.py:475 +#: src/config/SSSDConfig/sssdoptions.py:481 msgid "Netgroups members attribute" msgstr "Atributo de membros de netgroups" -#: src/config/SSSDConfig/sssdoptions.py:476 +#: src/config/SSSDConfig/sssdoptions.py:482 msgid "Netgroup triple attribute" msgstr "Atributo triplo de netgroup" -#: src/config/SSSDConfig/sssdoptions.py:477 +#: src/config/SSSDConfig/sssdoptions.py:483 msgid "Modification time attribute for netgroups" msgstr "Atributo de modificação de tempo para netgroups" -#: src/config/SSSDConfig/sssdoptions.py:479 +#: src/config/SSSDConfig/sssdoptions.py:485 msgid "Base DN for service lookups" msgstr "DN base para pesquisa de serviços" -#: src/config/SSSDConfig/sssdoptions.py:480 +#: src/config/SSSDConfig/sssdoptions.py:486 msgid "Objectclass for services" msgstr "Classe de objeto para serviços" -#: src/config/SSSDConfig/sssdoptions.py:481 +#: src/config/SSSDConfig/sssdoptions.py:487 msgid "Service name attribute" msgstr "Atributo de nome de serviço" -#: src/config/SSSDConfig/sssdoptions.py:482 +#: src/config/SSSDConfig/sssdoptions.py:488 msgid "Service port attribute" msgstr "Atributo de porto de serviço" -#: src/config/SSSDConfig/sssdoptions.py:483 +#: src/config/SSSDConfig/sssdoptions.py:489 msgid "Service protocol attribute" msgstr "Atributo de protocolo de serviço" -#: src/config/SSSDConfig/sssdoptions.py:485 +#: src/config/SSSDConfig/sssdoptions.py:491 msgid "Lower bound for ID-mapping" msgstr "Vínculo inferior para mapeamento de ID" -#: src/config/SSSDConfig/sssdoptions.py:486 +#: src/config/SSSDConfig/sssdoptions.py:492 msgid "Upper bound for ID-mapping" msgstr "Vínculo superior para mapeamento de ID" -#: src/config/SSSDConfig/sssdoptions.py:487 +#: src/config/SSSDConfig/sssdoptions.py:493 msgid "Number of IDs for each slice when ID-mapping" msgstr "Número de IDs para cada fatia ao fazer mapeamento de ID" -#: src/config/SSSDConfig/sssdoptions.py:488 +#: src/config/SSSDConfig/sssdoptions.py:494 msgid "Use autorid-compatible algorithm for ID-mapping" msgstr "Usar algoritmo compatível com autorid para mapeamento de ID" -#: src/config/SSSDConfig/sssdoptions.py:489 +#: src/config/SSSDConfig/sssdoptions.py:495 msgid "Name of the default domain for ID-mapping" msgstr "Nome do domínio predefinido para mapeamento de ID" -#: src/config/SSSDConfig/sssdoptions.py:490 +#: src/config/SSSDConfig/sssdoptions.py:496 msgid "SID of the default domain for ID-mapping" msgstr "SID do domínio predefinido para mapeamento de ID" -#: src/config/SSSDConfig/sssdoptions.py:491 +#: src/config/SSSDConfig/sssdoptions.py:497 msgid "Number of secondary slices" msgstr "Número de fatias secundarias" -#: src/config/SSSDConfig/sssdoptions.py:493 +#: src/config/SSSDConfig/sssdoptions.py:499 msgid "Whether to use Token-Groups" msgstr "Se deve-se usar Token-Groups" -#: src/config/SSSDConfig/sssdoptions.py:494 +#: src/config/SSSDConfig/sssdoptions.py:500 msgid "Set lower boundary for allowed IDs from the LDAP server" msgstr "Define limite inferior para IDS permitidos do servidor LDAP" -#: src/config/SSSDConfig/sssdoptions.py:495 +#: src/config/SSSDConfig/sssdoptions.py:501 msgid "Set upper boundary for allowed IDs from the LDAP server" msgstr "Define limite superior para IDS permitidos do servidor LDAP" -#: src/config/SSSDConfig/sssdoptions.py:496 +#: src/config/SSSDConfig/sssdoptions.py:502 msgid "DN for ppolicy queries" msgstr "DN para consultas ppolicy" -#: src/config/SSSDConfig/sssdoptions.py:497 +#: src/config/SSSDConfig/sssdoptions.py:503 msgid "How many maximum entries to fetch during a wildcard request" msgstr "Qual o máximo de entradas a obter durante um pedido de wildcard" -#: src/config/SSSDConfig/sssdoptions.py:498 +#: src/config/SSSDConfig/sssdoptions.py:504 msgid "Set libldap debug level" msgstr "Define nível de depuração da libldap" -#: src/config/SSSDConfig/sssdoptions.py:501 +#: src/config/SSSDConfig/sssdoptions.py:507 msgid "Policy to evaluate the password expiration" msgstr "Politica para avaliar a expiração da palavra passe" -#: src/config/SSSDConfig/sssdoptions.py:505 +#: src/config/SSSDConfig/sssdoptions.py:511 msgid "Which attributes shall be used to evaluate if an account is expired" msgstr "" "Quais atributos devem ser usados para avaliar se uma conta está expirada" -#: src/config/SSSDConfig/sssdoptions.py:509 +#: src/config/SSSDConfig/sssdoptions.py:515 msgid "URI of an LDAP server where password changes are allowed" msgstr "URI dum servidor LDAP onde as mudanças de palavra passe são permitidas" -#: src/config/SSSDConfig/sssdoptions.py:510 +#: src/config/SSSDConfig/sssdoptions.py:516 msgid "URI of a backup LDAP server where password changes are allowed" msgstr "" "URI dum servidor LDAP de salvaguarda onde alterações de palavra passe são " "permitidas" -#: src/config/SSSDConfig/sssdoptions.py:511 +#: src/config/SSSDConfig/sssdoptions.py:517 msgid "DNS service name for LDAP password change server" msgstr "Nome de serviço DNS para servidor de mudança de palavra passe LDAP" -#: src/config/SSSDConfig/sssdoptions.py:512 +#: src/config/SSSDConfig/sssdoptions.py:518 msgid "" "Whether to update the ldap_user_shadow_last_change attribute after a " "password change" @@ -1821,27 +1859,27 @@ msgstr "" "Se deve-se atualizar o atributo ldap_user_shadow_last_change após mudança da " "palavra passe" -#: src/config/SSSDConfig/sssdoptions.py:516 +#: src/config/SSSDConfig/sssdoptions.py:522 msgid "Base DN for sudo rules lookups" msgstr "DN base para pesquisas de regras sudo" -#: src/config/SSSDConfig/sssdoptions.py:517 +#: src/config/SSSDConfig/sssdoptions.py:523 msgid "Automatic full refresh period" msgstr "Período de refrescamento total automático" -#: src/config/SSSDConfig/sssdoptions.py:518 +#: src/config/SSSDConfig/sssdoptions.py:524 msgid "Automatic smart refresh period" msgstr "Período de refrescamento inteligente automático" -#: src/config/SSSDConfig/sssdoptions.py:519 +#: src/config/SSSDConfig/sssdoptions.py:525 msgid "Smart and full refresh random offset" msgstr "Desvio aleatório do refrescamento inteligente e total" -#: src/config/SSSDConfig/sssdoptions.py:520 +#: src/config/SSSDConfig/sssdoptions.py:526 msgid "Whether to filter rules by hostname, IP addresses and network" msgstr "Se deve-se filtra regras pelo nome de máquina, endereços IP e rede" -#: src/config/SSSDConfig/sssdoptions.py:521 +#: src/config/SSSDConfig/sssdoptions.py:527 msgid "" "Hostnames and/or fully qualified domain names of this machine to filter sudo " "rules" @@ -1849,149 +1887,149 @@ msgstr "" "Nomes de máquina e/ou nomes de domínio totalmente qualificados desta máquina " "para filtrar regras sudo" -#: src/config/SSSDConfig/sssdoptions.py:522 +#: src/config/SSSDConfig/sssdoptions.py:528 msgid "IPv4 or IPv6 addresses or network of this machine to filter sudo rules" msgstr "Endereços IPv4 ou IPv6 ou rede desta máquina para filtrar regras sudo" -#: src/config/SSSDConfig/sssdoptions.py:523 +#: src/config/SSSDConfig/sssdoptions.py:529 msgid "Whether to include rules that contains netgroup in host attribute" msgstr "Se deve-se incluir regras que contêm netgroup no seu atributo host" -#: src/config/SSSDConfig/sssdoptions.py:524 +#: src/config/SSSDConfig/sssdoptions.py:530 msgid "" "Whether to include rules that contains regular expression in host attribute" msgstr "" "Se deve-se incluir regras que contêm expressão regular no seu atributo host" -#: src/config/SSSDConfig/sssdoptions.py:525 +#: src/config/SSSDConfig/sssdoptions.py:531 msgid "Object class for sudo rules" msgstr "Classe objeto para regras sudo" -#: src/config/SSSDConfig/sssdoptions.py:526 +#: src/config/SSSDConfig/sssdoptions.py:532 msgid "Name of attribute that is used as object class for sudo rules" msgstr "Nome do atributo que é usado como classe de objeto para regras sudo" -#: src/config/SSSDConfig/sssdoptions.py:527 +#: src/config/SSSDConfig/sssdoptions.py:533 msgid "Sudo rule name" msgstr "Nome de regra sudo" -#: src/config/SSSDConfig/sssdoptions.py:528 +#: src/config/SSSDConfig/sssdoptions.py:534 msgid "Sudo rule command attribute" msgstr "Atributo de comando de regra sudo" -#: src/config/SSSDConfig/sssdoptions.py:529 +#: src/config/SSSDConfig/sssdoptions.py:535 msgid "Sudo rule host attribute" msgstr "Atributo de máquina de regra sudo" -#: src/config/SSSDConfig/sssdoptions.py:530 +#: src/config/SSSDConfig/sssdoptions.py:536 msgid "Sudo rule user attribute" msgstr "Atributo de utilizador de regra sudo" -#: src/config/SSSDConfig/sssdoptions.py:531 +#: src/config/SSSDConfig/sssdoptions.py:537 msgid "Sudo rule option attribute" msgstr "Atributo de opção de regra sudo" -#: src/config/SSSDConfig/sssdoptions.py:532 +#: src/config/SSSDConfig/sssdoptions.py:538 msgid "Sudo rule runas attribute" msgstr "Atributo de runas de regra sudo" -#: src/config/SSSDConfig/sssdoptions.py:533 +#: src/config/SSSDConfig/sssdoptions.py:539 msgid "Sudo rule runasuser attribute" msgstr "Atributo de runas-utilizador de regra sudo" -#: src/config/SSSDConfig/sssdoptions.py:534 +#: src/config/SSSDConfig/sssdoptions.py:540 msgid "Sudo rule runasgroup attribute" msgstr "Atributo de runas-grupo de regra sudo" -#: src/config/SSSDConfig/sssdoptions.py:535 +#: src/config/SSSDConfig/sssdoptions.py:541 msgid "Sudo rule notbefore attribute" msgstr "Atributo de não-antes de regra sudo" -#: src/config/SSSDConfig/sssdoptions.py:536 +#: src/config/SSSDConfig/sssdoptions.py:542 msgid "Sudo rule notafter attribute" msgstr "Atributo de não-depois de regra sudo" -#: src/config/SSSDConfig/sssdoptions.py:537 +#: src/config/SSSDConfig/sssdoptions.py:543 msgid "Sudo rule order attribute" msgstr "Atributo de ordem de regra sudo" -#: src/config/SSSDConfig/sssdoptions.py:540 +#: src/config/SSSDConfig/sssdoptions.py:546 msgid "Object class for automounter maps" msgstr "Classe de objeto para mapas do automounter" -#: src/config/SSSDConfig/sssdoptions.py:541 +#: src/config/SSSDConfig/sssdoptions.py:547 msgid "Automounter map name attribute" msgstr "Atributo de nome de mapa do automounter" -#: src/config/SSSDConfig/sssdoptions.py:542 +#: src/config/SSSDConfig/sssdoptions.py:548 msgid "Object class for automounter map entries" msgstr "Classe de objeto para entradas de mapa do automounter" -#: src/config/SSSDConfig/sssdoptions.py:543 +#: src/config/SSSDConfig/sssdoptions.py:549 msgid "Automounter map entry key attribute" msgstr "Atributo chave de entrada de mapa do automounter" -#: src/config/SSSDConfig/sssdoptions.py:544 +#: src/config/SSSDConfig/sssdoptions.py:550 msgid "Automounter map entry value attribute" msgstr "Atributo valor de entrada de mapa do automounter" -#: src/config/SSSDConfig/sssdoptions.py:545 +#: src/config/SSSDConfig/sssdoptions.py:551 msgid "Base DN for automounter map lookups" msgstr "DN base para pesquisas de mapa de automounter" -#: src/config/SSSDConfig/sssdoptions.py:546 +#: src/config/SSSDConfig/sssdoptions.py:552 msgid "The name of the automount master map in LDAP." msgstr "O nome do mapa mestre automount no LDAP." -#: src/config/SSSDConfig/sssdoptions.py:549 +#: src/config/SSSDConfig/sssdoptions.py:555 msgid "Base DN for IP hosts lookups" msgstr "DN base para pesquisas de máquinas IP" -#: src/config/SSSDConfig/sssdoptions.py:550 +#: src/config/SSSDConfig/sssdoptions.py:556 msgid "Object class for IP hosts" msgstr "Classe de objeto para máquinas IP" -#: src/config/SSSDConfig/sssdoptions.py:551 +#: src/config/SSSDConfig/sssdoptions.py:557 msgid "IP host name attribute" msgstr "Atributo do nome da máquina IP" -#: src/config/SSSDConfig/sssdoptions.py:552 +#: src/config/SSSDConfig/sssdoptions.py:558 msgid "IP host number (address) attribute" msgstr "Atributo número (endereço) de máquina IP" -#: src/config/SSSDConfig/sssdoptions.py:553 +#: src/config/SSSDConfig/sssdoptions.py:559 msgid "IP host entryUSN attribute" msgstr "Atributo entryUSN de máquina IP" -#: src/config/SSSDConfig/sssdoptions.py:554 +#: src/config/SSSDConfig/sssdoptions.py:560 msgid "Base DN for IP networks lookups" msgstr "DN base para pesquisas de redes IP" -#: src/config/SSSDConfig/sssdoptions.py:555 +#: src/config/SSSDConfig/sssdoptions.py:561 msgid "Object class for IP networks" msgstr "Classe objeto para redes IP" -#: src/config/SSSDConfig/sssdoptions.py:556 +#: src/config/SSSDConfig/sssdoptions.py:562 msgid "IP network name attribute" msgstr "Atributo nome de rede IP" -#: src/config/SSSDConfig/sssdoptions.py:557 +#: src/config/SSSDConfig/sssdoptions.py:563 msgid "IP network number (address) attribute" msgstr "Atributo número (endereço) de rede IP" -#: src/config/SSSDConfig/sssdoptions.py:558 +#: src/config/SSSDConfig/sssdoptions.py:564 msgid "IP network entryUSN attribute" msgstr "Atributo entryUSN de rede IP" -#: src/config/SSSDConfig/sssdoptions.py:561 +#: src/config/SSSDConfig/sssdoptions.py:567 msgid "Comma separated list of allowed users" msgstr "Lista de utilizadores autorizados separados por vírgulas" -#: src/config/SSSDConfig/sssdoptions.py:562 +#: src/config/SSSDConfig/sssdoptions.py:568 msgid "Comma separated list of prohibited users" msgstr "Lista de utilizadores proibidos separados por vírgulas" -#: src/config/SSSDConfig/sssdoptions.py:563 +#: src/config/SSSDConfig/sssdoptions.py:569 msgid "" "Comma separated list of groups that are allowed to log in. This applies only " "to groups within this SSSD domain. Local groups are not evaluated." @@ -2000,7 +2038,7 @@ msgstr "" "aplica-se apenas a grupos dentro do domínio SSSD. Os grupos locais não são " "avaliados." -#: src/config/SSSDConfig/sssdoptions.py:565 +#: src/config/SSSDConfig/sssdoptions.py:571 msgid "" "Comma separated list of groups that are explicitly denied access. This " "applies only to groups within this SSSD domain. Local groups are not " @@ -2010,31 +2048,31 @@ msgstr "" "Isto aplica-se apenas a grupos dentro do domínio SSSD. Os grupos locais não " "são avaliados." -#: src/config/SSSDConfig/sssdoptions.py:569 +#: src/config/SSSDConfig/sssdoptions.py:575 msgid "The number of preforked proxy children." msgstr "O número de filhos de proxy pré-forcados." -#: src/config/SSSDConfig/sssdoptions.py:572 +#: src/config/SSSDConfig/sssdoptions.py:578 msgid "The name of the NSS library to use" msgstr "O nome da biblioteca NSS a utilizar" -#: src/config/SSSDConfig/sssdoptions.py:573 +#: src/config/SSSDConfig/sssdoptions.py:579 msgid "The name of the NSS library to use for hosts and networks lookups" msgstr "O nome a biblioteca NSS a usar para procuras por máquinas e redes" -#: src/config/SSSDConfig/sssdoptions.py:574 +#: src/config/SSSDConfig/sssdoptions.py:580 msgid "Whether to look up canonical group name from cache if possible" msgstr "Se deve-se procurar nome de grupo canônico da cache se possível" -#: src/config/SSSDConfig/sssdoptions.py:577 +#: src/config/SSSDConfig/sssdoptions.py:583 msgid "PAM stack to use" msgstr "Pilha PAM a utilizar" -#: src/config/SSSDConfig/sssdoptions.py:580 +#: src/config/SSSDConfig/sssdoptions.py:586 msgid "Path of passwd file sources." msgstr "Caminho de fontes do ficheiro passwd." -#: src/config/SSSDConfig/sssdoptions.py:581 +#: src/config/SSSDConfig/sssdoptions.py:587 msgid "Path of group file sources." msgstr "Caminho de fontes do ficheiro group." @@ -2065,108 +2103,112 @@ msgstr "" msgid "Option -i|--interactive is not allowed together with -D|--daemon\n" msgstr "A opção -i|--interactive não é permitida juntamente com -D|--daemon\n" -#: src/monitor/monitor.c:1836 +#: src/monitor/monitor.c:1838 msgid "Failed to get initial capabilities\n" msgstr "Falhou ao obter capacidades iniciais\n" -#: src/monitor/monitor.c:1847 +#: src/monitor/monitor.c:1849 msgid "Non-root service user support isn't built. Can't run under %" msgstr "" "O suporte a utilizador de serviço não-root não está compilado. Não pode " "correr sob %" -#: src/monitor/monitor.c:1864 +#: src/monitor/monitor.c:1866 #, c-format msgid "Can't read config: '%s'\n" msgstr "Incapaz de ler configuração: '%s'\n" -#: src/monitor/monitor.c:1876 +#: src/monitor/monitor.c:1878 #, c-format -msgid "Failed to boostrap SSSD 'monitor' process: %s" +msgid "Failed to bootstrap SSSD 'monitor' process: %s" msgstr "Falhou ao impulsionar o processo 'monitor' do SSSD: %s" -#: src/monitor/monitor.c:1971 +#: src/monitor/monitor.c:1973 msgid "Out of memory\n" msgstr "Memória esgotada\n" -#: src/providers/krb5/krb5_child.c:4221 +#: src/providers/krb5/krb5_child.c:4316 msgid "Use anonymous PKINIT to request FAST armor ticket" msgstr "Usa PKINIT anônimo para requisitar bilhete armadura FAST" -#: src/providers/krb5/krb5_child.c:4223 +#: src/providers/krb5/krb5_child.c:4318 msgid "Kerberos realm to use" msgstr "Reino Kerberos a usar" -#: src/providers/krb5/krb5_child.c:4225 +#: src/providers/krb5/krb5_child.c:4320 msgid "Requested lifetime of the ticket" msgstr "Tempo de vida requisitado do bilhete" -#: src/providers/krb5/krb5_child.c:4227 +#: src/providers/krb5/krb5_child.c:4322 msgid "Requested renewable lifetime of the ticket" msgstr "Tempo de vida renovável requisitado do bilhete" -#: src/providers/krb5/krb5_child.c:4229 +#: src/providers/krb5/krb5_child.c:4324 msgid "FAST options ('never', 'try', 'demand')" msgstr "Opções FAST ('never', 'try', 'demand')" -#: src/providers/krb5/krb5_child.c:4232 +#: src/providers/krb5/krb5_child.c:4327 msgid "Specifies the server principal to use for FAST" msgstr "Especifica o principal do servidor a usar para FAST" -#: src/providers/krb5/krb5_child.c:4234 +#: src/providers/krb5/krb5_child.c:4329 msgid "Requests canonicalization of the principal name" msgstr "Requisita canonização do nome do principal" -#: src/providers/krb5/krb5_child.c:4236 +#: src/providers/krb5/krb5_child.c:4331 msgid "Use custom version of krb5_get_init_creds_password" msgstr "Usa versão personalizada do krb5_get_init_creds_password" -#: src/providers/krb5/krb5_child.c:4238 +#: src/providers/krb5/krb5_child.c:4333 msgid "Check PAC flags" msgstr "Verifica bandeiras PAC" -#: src/providers/data_provider_be.c:790 +#: src/providers/krb5/krb5_child.c:4335 +msgid "Set environment variable (KEY=VALUE)" +msgstr "Definir variável de ambiente (CHAVE=VALOR)" + +#: src/providers/data_provider_be.c:786 msgid "Domain of the information provider (mandatory)" msgstr "Domínio do provedor de informação (obrigatório)" -#: src/sss_client/common.c:1165 +#: src/sss_client/common.c:1208 msgid "Socket has wrong ownership or permissions." msgstr "Socket tem posse ou permissões erradas." -#: src/sss_client/common.c:1168 +#: src/sss_client/common.c:1211 msgid "Unexpected format of the server credential message." msgstr "Formato inesperado da mensagem de credenciais do servidor." -#: src/sss_client/common.c:1171 +#: src/sss_client/common.c:1214 msgid "SSSD is not run by trusted user." msgstr "O SSSD não está correr por utilizador de confiança." -#: src/sss_client/common.c:1174 +#: src/sss_client/common.c:1217 msgid "SSSD socket does not exist." msgstr "O socket SSSD não existe." -#: src/sss_client/common.c:1177 +#: src/sss_client/common.c:1220 msgid "Cannot get stat of SSSD socket." msgstr "Incapaz de obter estatuto do socket SSSD." -#: src/sss_client/common.c:1182 +#: src/sss_client/common.c:1225 msgid "An error occurred, but no description can be found." msgstr "Ocorreu um erro, mas nenhuma descrição foi encontrada." -#: src/sss_client/common.c:1188 +#: src/sss_client/common.c:1231 msgid "Unexpected error while looking for an error description" msgstr "Erro inesperado ao procurar por uma descrição de erro" -#: src/sss_client/pam_sss.c:74 +#: src/sss_client/pam_sss.c:135 msgid "Permission denied. " msgstr "Permissão negada. " -#: src/sss_client/pam_sss.c:75 src/sss_client/pam_sss.c:843 -#: src/sss_client/pam_sss.c:854 +#: src/sss_client/pam_sss.c:136 src/sss_client/pam_sss.c:921 +#: src/sss_client/pam_sss.c:932 msgid "Server message: " msgstr "Mensagem do Servidor: " -#: src/sss_client/pam_sss.c:76 +#: src/sss_client/pam_sss.c:137 msgid "" "Kerberos TGT will not be granted upon login, user experience will be " "affected." @@ -2174,50 +2216,51 @@ msgstr "" "TGT de Kerberos não será concedido após login, a experiência do utilizador " "será afetada." -#: src/sss_client/pam_sss.c:77 +#: src/sss_client/pam_sss.c:138 msgid "Enter PIN:" msgstr "Insira PIN:" -#: src/sss_client/pam_sss.c:320 +#: src/sss_client/pam_sss.c:385 msgid "Passwords do not match" msgstr "Palavras passe não coincidem" -#: src/sss_client/pam_sss.c:508 +#: src/sss_client/pam_sss.c:584 msgid "Password reset by root is not supported." msgstr "Não é suportado reiniciar a palavra passe pelo root." -#: src/sss_client/pam_sss.c:549 +#: src/sss_client/pam_sss.c:625 msgid "Authenticated with cached credentials" msgstr "Autenticado com credenciais em cache" -#: src/sss_client/pam_sss.c:550 +#: src/sss_client/pam_sss.c:626 msgid ", your cached password will expire at: " msgstr ", a sua palavra passe guardada em cache irá expirar em: " -#: src/sss_client/pam_sss.c:580 +#: src/sss_client/pam_sss.c:656 #, c-format msgid "Your password has expired. You have %1$d grace login(s) remaining." -msgstr "A sua palavra passe expirou. Você tem %1$d login(s) de graça restantes." +msgstr "" +"A sua palavra passe expirou. Você tem %1$d login(s) de graça restantes." -#: src/sss_client/pam_sss.c:630 +#: src/sss_client/pam_sss.c:706 #, c-format msgid "Your password will expire in %1$d %2$s." msgstr "A sua palavra irá expirar em %1$d %2$s." -#: src/sss_client/pam_sss.c:633 +#: src/sss_client/pam_sss.c:709 #, c-format msgid "Your password has expired." msgstr "A sua palavra passe expirou." -#: src/sss_client/pam_sss.c:684 +#: src/sss_client/pam_sss.c:760 msgid "Authentication is denied until: " msgstr "A autenticação é negada até: " -#: src/sss_client/pam_sss.c:705 +#: src/sss_client/pam_sss.c:781 msgid "System is offline, password change not possible" msgstr "O sistema está offline, a mudança de palavra passe não é possível" -#: src/sss_client/pam_sss.c:720 +#: src/sss_client/pam_sss.c:796 msgid "" "After changing the OTP password, you need to log out and back in order to " "acquire a ticket" @@ -2225,11 +2268,11 @@ msgstr "" "Após mudar a palavra passe OTP, você precisa de terminar sessão e regressar " "de modo a adquirir um bilhete" -#: src/sss_client/pam_sss.c:735 +#: src/sss_client/pam_sss.c:813 msgid "PIN locked" msgstr "PIN trancado" -#: src/sss_client/pam_sss.c:750 +#: src/sss_client/pam_sss.c:828 msgid "" "No Kerberos TGT granted as the server does not support this method. Your " "single-sign on(SSO) experience will be affected." @@ -2237,61 +2280,65 @@ msgstr "" "Nenhum TGT de Kerberos concedido pois o servidor não suporta este método. A " "sua experiência de única-assinatura on (SSO) irá ser afetada." -#: src/sss_client/pam_sss.c:840 src/sss_client/pam_sss.c:853 +#: src/sss_client/pam_sss.c:918 src/sss_client/pam_sss.c:931 msgid "Password change failed. " msgstr "Alteração da palavra passe falhou. " -#: src/sss_client/pam_sss.c:1859 +#: src/sss_client/pam_sss.c:2028 #, c-format -msgid "Authenticate at %1$s and press ENTER." -msgstr "Autentique em %1$s e pressione ENTER." +msgid "Authenticate at \"%1$s\"." +msgstr "Autentique em \"%1$s\"." -#: src/sss_client/pam_sss.c:1862 +#: src/sss_client/pam_sss.c:2031 #, c-format -msgid "Authenticate with PIN %1$s at %2$s and press ENTER." -msgstr "Autentique com PIN %1$s em %2$s e pressione ENTER." +msgid "Authenticate with PIN \"%1$s\" at \"%2$s\"." +msgstr "Autentique com PIN \"%1$s\" em \"%2$s\"." -#: src/sss_client/pam_sss.c:2281 +#: src/sss_client/pam_sss.c:2470 msgid "Please (re)insert (different) Smartcard" msgstr "Por favor (re)insira Smartcard (diferente)" -#: src/sss_client/pam_sss.c:2482 +#: src/sss_client/pam_sss.c:2700 msgid "New Password: " msgstr "Nova Palavra Passe: " -#: src/sss_client/pam_sss.c:2483 +#: src/sss_client/pam_sss.c:2701 msgid "Reenter new Password: " msgstr "Re-insira a nova Palavra Passe: " -#: src/sss_client/pam_sss.c:2676 src/sss_client/pam_sss.c:2679 +#: src/sss_client/pam_sss.c:2890 +msgid "Press ENTER to continue." +msgstr "Pressione ENTER para continuar." + +#: src/sss_client/pam_sss.c:2913 src/sss_client/pam_sss.c:2916 msgid "First Factor: " msgstr "Primeiro Factor: " -#: src/sss_client/pam_sss.c:2677 src/sss_client/pam_sss.c:2851 +#: src/sss_client/pam_sss.c:2914 src/sss_client/pam_sss.c:3088 msgid "Second Factor (optional): " msgstr "Segundo Factor (opcional): " -#: src/sss_client/pam_sss.c:2680 src/sss_client/pam_sss.c:2855 +#: src/sss_client/pam_sss.c:2917 src/sss_client/pam_sss.c:3092 msgid "Second Factor: " msgstr "Segundo Factor: " -#: src/sss_client/pam_sss.c:2684 +#: src/sss_client/pam_sss.c:2921 msgid "Insert your passkey device, then press ENTER." msgstr "Insira o seu dispositivo passkey, depois pressione ENTER." -#: src/sss_client/pam_sss.c:2688 src/sss_client/pam_sss.c:2696 +#: src/sss_client/pam_sss.c:2925 src/sss_client/pam_sss.c:2933 msgid "Password: " msgstr "Palavra Passe: " -#: src/sss_client/pam_sss.c:2850 src/sss_client/pam_sss.c:2854 +#: src/sss_client/pam_sss.c:3087 src/sss_client/pam_sss.c:3091 msgid "First Factor (Current Password): " msgstr "Primeiro Factor (Palavra Passe Atual): " -#: src/sss_client/pam_sss.c:2874 +#: src/sss_client/pam_sss.c:3111 msgid "Current Password: " msgstr "Palavra Passe Actual: " -#: src/sss_client/pam_sss.c:3248 +#: src/sss_client/pam_sss.c:3485 msgid "Password expired. Change your password now." msgstr "A palavra passe expirou. Altere a sua palavra passe agora." @@ -2738,9 +2785,9 @@ msgstr "Falhou ao escrever objeto: %s\n" #: src/tools/sssctl/sssctl_cache.c:835 src/tools/sssctl/sssctl_cache.c:918 #: src/tools/sssctl/sssctl_cache.c:950 src/tools/sssctl/sssctl_cache.c:956 #: src/tools/sssctl/sssctl_cache.c:1010 src/tools/sssctl/sssctl_cache.c:1034 -#: src/tools/sssctl/sssctl_cache.c:1085 src/tools/sssctl/sssctl_cache.c:1194 -#: src/tools/sssctl/sssctl_cache.c:1229 src/tools/sssctl/sssctl_cache.c:1235 -#: src/tools/sssctl/sssctl_cache.c:1244 +#: src/tools/sssctl/sssctl_cache.c:1085 src/tools/sssctl/sssctl_cache.c:1195 +#: src/tools/sssctl/sssctl_cache.c:1230 src/tools/sssctl/sssctl_cache.c:1236 +#: src/tools/sssctl/sssctl_cache.c:1245 msgid "talloc failed\n" msgstr "talloc falhado\n" @@ -2816,25 +2863,25 @@ msgstr "O caminho GPO em cache [%s] não é sob [%s], a ignorar.\n" msgid "Unable to remove downloaded GPO files: %s\n" msgstr "Incapaz de remover ficheiros GPO descarregados: %s\n" -#: src/tools/sssctl/sssctl_cache.c:1165 +#: src/tools/sssctl/sssctl_cache.c:1166 #, c-format msgid "Failed to fetch cache entry: %s\n" msgstr "Falhou ao ir buscar entrada de cache: %s\n" -#: src/tools/sssctl/sssctl_cache.c:1170 +#: src/tools/sssctl/sssctl_cache.c:1171 msgid "Could not determine object domain\n" msgstr "Não pude determinar domínio objeto\n" -#: src/tools/sssctl/sssctl_cache.c:1200 +#: src/tools/sssctl/sssctl_cache.c:1201 msgid "Could not find GUID attribute in GPO entry\n" msgstr "Não pude encontrar atributo GUID em entrada GPO\n" -#: src/tools/sssctl/sssctl_cache.c:1206 +#: src/tools/sssctl/sssctl_cache.c:1207 #, c-format msgid "Failed to delete GPO: %s\n" msgstr "Falhou ao apagar GPO: %s\n" -#: src/tools/sssctl/sssctl_cache.c:1210 +#: src/tools/sssctl/sssctl_cache.c:1211 #, c-format msgid "%s removed from cache\n" msgstr "%s removido da cache\n" @@ -2883,8 +2930,8 @@ msgstr "Falhou ao configurar contexto certmap.\n" #, c-format msgid "Failed to add mapping and matching rules with error [%d][%s].\n" msgstr "" -"Falhou ao adicionar regras de mapeamento e correspondência com erro " -"[%d][%s].\n" +"Falhou ao adicionar regras de mapeamento e correspondência com erro [%d]" +"[%s].\n" #: src/tools/sssctl/sssctl_cert.c:251 msgid "Failed to decode base64 string.\n" @@ -2932,39 +2979,39 @@ msgstr "" "localizado. Por exemplo se a configuração estiver definida para \"/my/path/" "sssd.conf\", é usado o directório de trechos \"/my/path/conf.d\")" -#: src/tools/sssctl/sssctl_config.c:114 +#: src/tools/sssctl/sssctl_config.c:126 #, c-format msgid "File %1$s does not exist.\n" msgstr "O ficheiro %1$s não existe.\n" -#: src/tools/sssctl/sssctl_config.c:115 +#: src/tools/sssctl/sssctl_config.c:127 msgid "There is no configuration.\n" msgstr "Não existe configuração.\n" -#: src/tools/sssctl/sssctl_config.c:120 +#: src/tools/sssctl/sssctl_config.c:132 #, c-format msgid "Configuration validation failed: %s\n" msgstr "Validação de configuração falhada: %s\n" -#: src/tools/sssctl/sssctl_config.c:121 +#: src/tools/sssctl/sssctl_config.c:133 msgid "Run with high debug level to see details.\n" msgstr "Corra com nível de depuração alto para ver detalhes.\n" -#: src/tools/sssctl/sssctl_config.c:130 -msgid "Failed to run validators" -msgstr "Falhou ao correr validadores" +#: src/tools/sssctl/sssctl_config.c:142 +msgid "Failed to run validators\n" +msgstr "Falhou ao correr validadores\n" -#: src/tools/sssctl/sssctl_config.c:134 +#: src/tools/sssctl/sssctl_config.c:146 #, c-format msgid "Issues identified by validators: %zu\n" msgstr "Problemas identificados pelos validadores: %zu\n" -#: src/tools/sssctl/sssctl_config.c:145 +#: src/tools/sssctl/sssctl_config.c:157 #, c-format msgid "Messages generated during configuration merging: %zu\n" msgstr "Mensagens geradas durante a fusão de configuração: %zu\n" -#: src/tools/sssctl/sssctl_config.c:158 +#: src/tools/sssctl/sssctl_config.c:170 #, c-format msgid "Used configuration snippet files: %zu\n" msgstr "Ficheiros de trechos do configuração usados: %zu\n" @@ -3110,7 +3157,8 @@ msgstr "Operação de indexar falhou: %1$s\n" #: src/tools/sssctl/sssctl_data.c:483 msgid "Don't forget to also update the indexes on the remote providers.\n" -msgstr "Não se esqueça de também atualizar os índices nos provedores remotos.\n" +msgstr "" +"Não se esqueça de também atualizar os índices nos provedores remotos.\n" #: src/tools/sssctl/sssctl_domains.c:82 msgid "Show domain list including primary or trusted domain type" diff --git a/po/pt_BR.po b/po/pt_BR.po index 43d5fc1565c..097dd4f177e 100644 --- a/po/pt_BR.po +++ b/po/pt_BR.po @@ -1,11 +1,13 @@ # Marco Aurélio Krause , 2015. #zanata # Nari Ivy , 2025, 2026. +# Rafael Fontenelle , 2026. +# Vanessa Miranda , 2026. msgid "" msgstr "" "Project-Id-Version: PACKAGE VERSION\n" "Report-Msgid-Bugs-To: sssd-devel@lists.fedorahosted.org\n" -"POT-Creation-Date: 2026-01-14 14:57+0000\n" -"PO-Revision-Date: 2026-04-23 16:26+0000\n" +"POT-Creation-Date: 2026-10-02 15:57+0000\n" +"PO-Revision-Date: 2026-10-05 16:43+0000\n" "Last-Translator: Nari Ivy \n" "Language-Team: Portuguese (Brazil) \n" @@ -14,509 +16,587 @@ msgstr "" "Content-Type: text/plain; charset=UTF-8\n" "Content-Transfer-Encoding: 8bit\n" "Plural-Forms: nplurals=2; plural=(n != 1);\n" -"X-Generator: Weblate 5.17\n" +"X-Generator: Weblate 2026.10\n" -#: src/config/SSSDConfig/sssdoptions.py:20 -#: src/config/SSSDConfig/sssdoptions.py:21 +#: src/config/SSSDConfig/sssdoptions.py:16 +#: src/config/SSSDConfig/sssdoptions.py:17 msgid "Set the verbosity of the debug logging" -msgstr "Definir a verbosidade do log de depuração" +msgstr "Define a verbosidade do log de depuração" -#: src/config/SSSDConfig/sssdoptions.py:22 +#: src/config/SSSDConfig/sssdoptions.py:18 msgid "Include timestamps in debug logs" -msgstr "Incluir timestamps em logs de depuração" +msgstr "Inclui timestamps em logs de depuração" -#: src/config/SSSDConfig/sssdoptions.py:23 +#: src/config/SSSDConfig/sssdoptions.py:19 msgid "Include microseconds in timestamps in debug logs" -msgstr "Incluir microssegundos em timestamps em logs de depuração" +msgstr "Inclui microssegundos em timestamps em logs de depuração" -#: src/config/SSSDConfig/sssdoptions.py:24 +#: src/config/SSSDConfig/sssdoptions.py:20 msgid "Enable/disable debug backtrace" -msgstr "Ativar/desativar rastreamento de depuração" +msgstr "Ativa/desativa rastreamento de depuração" -#: src/config/SSSDConfig/sssdoptions.py:25 +#: src/config/SSSDConfig/sssdoptions.py:21 msgid "Watchdog timeout before restarting service" msgstr "Tempo limite do watchdog antes de reiniciar o serviço" -#: src/config/SSSDConfig/sssdoptions.py:26 +#: src/config/SSSDConfig/sssdoptions.py:22 msgid "Command to start service" msgstr "Comando para iniciar o serviço" -#: src/config/SSSDConfig/sssdoptions.py:27 +#: src/config/SSSDConfig/sssdoptions.py:23 msgid "The number of file descriptors that may be opened by this responder" msgstr "" "O número de descritores de arquivo que podem ser abertos por este respondedor" -#: src/config/SSSDConfig/sssdoptions.py:28 +#: src/config/SSSDConfig/sssdoptions.py:24 msgid "Idle time before automatic disconnection of a client" -msgstr "" +msgstr "Tempo de inatividade antes da desconexão automática de um cliente" -#: src/config/SSSDConfig/sssdoptions.py:29 +#: src/config/SSSDConfig/sssdoptions.py:25 msgid "Idle time before automatic shutdown of the responder" -msgstr "" +msgstr "Tempo de inatividade antes do desligamento automático do respondedor" -#: src/config/SSSDConfig/sssdoptions.py:30 +#: src/config/SSSDConfig/sssdoptions.py:26 msgid "Always query all the caches before querying the Data Providers" msgstr "" +"Sempre consulta todos os caches antes de consultar os Provedores de Dados" -#: src/config/SSSDConfig/sssdoptions.py:31 +#: src/config/SSSDConfig/sssdoptions.py:27 msgid "" "When SSSD switches to offline mode the amount of time before it tries to go " "back online will increase based upon the time spent disconnected. This value " "is in seconds and calculated by the following: offline_timeout + " "random_offset." msgstr "" +"Quando o SSSD entra em modo offline, o tempo limite antes de tentar voltar a " +"ficar online aumenta com base no tempo em que esteve desconectado. Esse " +"valor é em segundos e calculado da seguinte forma: tempolimite_offline + " +"deslocamento_aleatório." -#: src/config/SSSDConfig/sssdoptions.py:36 +#: src/config/SSSDConfig/sssdoptions.py:32 msgid "SSSD Services to start" msgstr "Serviços SSSD para iniciar" -#: src/config/SSSDConfig/sssdoptions.py:37 +#: src/config/SSSDConfig/sssdoptions.py:33 msgid "SSSD Domains to start" -msgstr "" +msgstr "Domínios SSSD para iniciar" -#: src/config/SSSDConfig/sssdoptions.py:38 +#: src/config/SSSDConfig/sssdoptions.py:34 msgid "Regex to parse username and domain" -msgstr "" +msgstr "Expressão regular para analisar nome de usuário e domínio" -#: src/config/SSSDConfig/sssdoptions.py:39 +#: src/config/SSSDConfig/sssdoptions.py:35 msgid "Printf-compatible format for displaying fully-qualified names" msgstr "" +"Formato compatível com printf para exibir nomes completamente qualificados" -#: src/config/SSSDConfig/sssdoptions.py:40 +#: src/config/SSSDConfig/sssdoptions.py:36 msgid "" "Directory on the filesystem where SSSD should store Kerberos replay cache " "files." msgstr "" +"Diretório no sistema de arquivos no qual SSSD deve armazenar arquivos cache " +"de reprodução de Kerberos." -#: src/config/SSSDConfig/sssdoptions.py:41 +#: src/config/SSSDConfig/sssdoptions.py:37 msgid "Domain to add to names without a domain component." -msgstr "" +msgstr "Domínio para adicionar a nomes sem um componente de domínio." -#: src/config/SSSDConfig/sssdoptions.py:42 +#: src/config/SSSDConfig/sssdoptions.py:38 msgid "The user to drop privileges to" -msgstr "" +msgstr "O usuário para retirar privilégios" -#: src/config/SSSDConfig/sssdoptions.py:43 +#: src/config/SSSDConfig/sssdoptions.py:39 msgid "Tune certificate verification" -msgstr "" +msgstr "Ajusta a verificação de certificado" -#: src/config/SSSDConfig/sssdoptions.py:44 +#: src/config/SSSDConfig/sssdoptions.py:40 msgid "All spaces in group or user names will be replaced with this character" msgstr "" +"Todos espaços em nomes de usuário e de grupo serão substituídos por este " +"caractere" -#: src/config/SSSDConfig/sssdoptions.py:45 +#: src/config/SSSDConfig/sssdoptions.py:41 msgid "Tune sssd to honor or ignore netlink state changes" -msgstr "" +msgstr "Ajusta sssd para honrar ou ignorar alterações de estado de netlink" -#: src/config/SSSDConfig/sssdoptions.py:46 +#: src/config/SSSDConfig/sssdoptions.py:42 msgid "Enable or disable the implicit files domain" -msgstr "" +msgstr "Habilita ou desabilita o domínio implícito de arquivos" -#: src/config/SSSDConfig/sssdoptions.py:47 +#: src/config/SSSDConfig/sssdoptions.py:43 msgid "A specific order of the domains to be looked up" -msgstr "" +msgstr "Uma ordem específica de domínios para procurar" -#: src/config/SSSDConfig/sssdoptions.py:48 +#: src/config/SSSDConfig/sssdoptions.py:44 msgid "" "Controls if SSSD should monitor the state of resolv.conf to identify when it " "needs to update its internal DNS resolver." msgstr "" +"Controla se SSSD deve monitorar o estado de resolv.conf para identificar " +"quando ele precisa atualizar seu resolvedor interno de DNS." -#: src/config/SSSDConfig/sssdoptions.py:50 +#: src/config/SSSDConfig/sssdoptions.py:46 msgid "" "SSSD monitors the state of resolv.conf to identify when it needs to update " "its internal DNS resolver. By default, we will attempt to use inotify for " "this, and will fall back to polling resolv.conf every five seconds if " "inotify cannot be used." msgstr "" +"SSSD monitora o estado de resolv.conf para identificar quando ele precisa " +"atualizar seu resolvedor interno de DNS. Por padrão, tentaremos usar inotify " +"para isso e, alternativamente, pode recorrer a consultar resolv.conf a cada " +"cinco segundos se inotify não puder ser usado." -#: src/config/SSSDConfig/sssdoptions.py:53 +#: src/config/SSSDConfig/sssdoptions.py:49 msgid "Run PAC responder automatically for AD and IPA provider" -msgstr "" +msgstr "Executa respondedor PAC automaticamente para provedor de AD e IPA" -#: src/config/SSSDConfig/sssdoptions.py:54 +#: src/config/SSSDConfig/sssdoptions.py:50 msgid "Enable or disable core dumps for all SSSD processes." msgstr "" +"Habilita ou desabilita despejos de núcleo para todos os processos de SSSD." -#: src/config/SSSDConfig/sssdoptions.py:55 +#: src/config/SSSDConfig/sssdoptions.py:51 msgid "Tune passkey verification behavior" -msgstr "" +msgstr "Ajusta o comportamento da verificação da chave de acesso" -#: src/config/SSSDConfig/sssdoptions.py:58 +#: src/config/SSSDConfig/sssdoptions.py:54 msgid "Enumeration cache timeout length (seconds)" -msgstr "" +msgstr "Tempo limite (em segundos) do cache de enumeração" -#: src/config/SSSDConfig/sssdoptions.py:59 +#: src/config/SSSDConfig/sssdoptions.py:55 msgid "Entry cache background update timeout length (seconds)" msgstr "" +"Tempo limite (em segundos) da atualização em segundo plano do cacho de " +"entrada" -#: src/config/SSSDConfig/sssdoptions.py:60 -#: src/config/SSSDConfig/sssdoptions.py:125 +#: src/config/SSSDConfig/sssdoptions.py:56 +#: src/config/SSSDConfig/sssdoptions.py:124 msgid "Negative cache timeout length (seconds)" -msgstr "" +msgstr "Tempo limite (em segundos) do cache negativo" -#: src/config/SSSDConfig/sssdoptions.py:61 +#: src/config/SSSDConfig/sssdoptions.py:57 msgid "Users that SSSD should explicitly ignore" -msgstr "" +msgstr "Usuários que SSSD deve explicitamente ignorar" -#: src/config/SSSDConfig/sssdoptions.py:62 +#: src/config/SSSDConfig/sssdoptions.py:58 msgid "Groups that SSSD should explicitly ignore" -msgstr "" +msgstr "Grupos que SSSD deve explicitamente ignorar" -#: src/config/SSSDConfig/sssdoptions.py:63 +#: src/config/SSSDConfig/sssdoptions.py:59 msgid "Should filtered users appear in groups" -msgstr "" +msgstr "Se usuários filtrados devem aparecer nos grupos" -#: src/config/SSSDConfig/sssdoptions.py:64 +#: src/config/SSSDConfig/sssdoptions.py:60 msgid "The value of the password field the NSS provider should return" -msgstr "" +msgstr "O valor do campo de senha que o provedor NSS deve devolver" -#: src/config/SSSDConfig/sssdoptions.py:65 +#: src/config/SSSDConfig/sssdoptions.py:61 msgid "Override homedir value from the identity provider with this value" -msgstr "" +msgstr "Substitui o valor de homedir do provedor de identidade com este valor" -#: src/config/SSSDConfig/sssdoptions.py:66 +#: src/config/SSSDConfig/sssdoptions.py:62 msgid "" "Substitute empty homedir value from the identity provider with this value" msgstr "" +"Substitui um valor vazio de homedir do provedor de identidade com este valor" -#: src/config/SSSDConfig/sssdoptions.py:67 +#: src/config/SSSDConfig/sssdoptions.py:63 msgid "Override shell value from the identity provider with this value" -msgstr "" +msgstr "Substitui o valor shell do provedor de identidade com este valor" -#: src/config/SSSDConfig/sssdoptions.py:68 +#: src/config/SSSDConfig/sssdoptions.py:64 msgid "The list of shells users are allowed to log in with" msgstr "" +"A lista de shells com os quais os usuários são permitidos se autenticar" -#: src/config/SSSDConfig/sssdoptions.py:69 +#: src/config/SSSDConfig/sssdoptions.py:65 msgid "" "The list of shells that will be vetoed, and replaced with the fallback shell" msgstr "" +"A lista de shells que serão vetados e substituídos com este shell como " +"reserva" -#: src/config/SSSDConfig/sssdoptions.py:70 +#: src/config/SSSDConfig/sssdoptions.py:66 msgid "" "If a shell stored in central directory is allowed but not available, use " "this fallback" msgstr "" +"Se um shell armazenado no diretório central é permitido, mas não está " +"disponível, usa este reserva" -#: src/config/SSSDConfig/sssdoptions.py:71 +#: src/config/SSSDConfig/sssdoptions.py:67 msgid "Shell to use if the provider does not list one" -msgstr "" +msgstr "Shell para usar se o provedor não lista um" -#: src/config/SSSDConfig/sssdoptions.py:72 +#: src/config/SSSDConfig/sssdoptions.py:68 msgid "How long will be in-memory cache records valid" -msgstr "" +msgstr "Por quanto tempo os registros de cacho na memória serão válidos" -#: src/config/SSSDConfig/sssdoptions.py:74 +#: src/config/SSSDConfig/sssdoptions.py:70 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for passwd requests" msgstr "" +"Tamanho (em megabytes) da tabela de dados alocada dentro do cache rápido em " +"memória para requisições de passwd" -#: src/config/SSSDConfig/sssdoptions.py:76 +#: src/config/SSSDConfig/sssdoptions.py:72 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for group requests" msgstr "" +"Tamanho (em megabytes) da tabela de dados alocada dentro do cache rápido em " +"memória para requisições de grupo" -#: src/config/SSSDConfig/sssdoptions.py:78 +#: src/config/SSSDConfig/sssdoptions.py:74 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for initgroups requests" msgstr "" +"Tamanho (em megabytes) da tabela de dados alocada dentro do cache rápido em " +"memória para requisições de initgroups" -#: src/config/SSSDConfig/sssdoptions.py:79 +#: src/config/SSSDConfig/sssdoptions.py:75 msgid "" "The value of this option will be used in the expansion of the " "override_homedir option if the template contains the format string %H." msgstr "" +"O valor desta opção será usada na expansão da opção override_homedir se o " +"modelo contiver a string de formato %H." -#: src/config/SSSDConfig/sssdoptions.py:81 +#: src/config/SSSDConfig/sssdoptions.py:77 msgid "" "Specifies time in seconds for which the list of subdomains will be " "considered valid." msgstr "" +"Especifica o tempo em segundos pelo qual a lista de subdomínios será " +"considerada válida." -#: src/config/SSSDConfig/sssdoptions.py:83 +#: src/config/SSSDConfig/sssdoptions.py:79 msgid "" "The entry cache can be set to automatically update entries in the background " "if they are requested beyond a percentage of the entry_cache_timeout value " "for the domain." msgstr "" +"O cache de entrada pode ser definido para atualizar automaticamente entradas " +"em segundo plano se elas forem solicitadas além de uma porcentagem do valor " +"entry_cache_timeout para o domínio." -#: src/config/SSSDConfig/sssdoptions.py:88 +#: src/config/SSSDConfig/sssdoptions.py:84 msgid "How long to allow cached logins between online logins (days)" -msgstr "" +msgstr "Por quanto tempo permitir logins em cache entre logins online (dias)" -#: src/config/SSSDConfig/sssdoptions.py:89 +#: src/config/SSSDConfig/sssdoptions.py:85 msgid "How many failed logins attempts are allowed when offline" msgstr "" +"Quantas tentativas de login com falha são permitidas quando se está offline" -#: src/config/SSSDConfig/sssdoptions.py:91 +#: src/config/SSSDConfig/sssdoptions.py:87 msgid "" "How long (minutes) to deny login after offline_failed_login_attempts has " "been reached" msgstr "" +"Por quantos minutos negar login após offline_failed_login_attempts ter sido " +"atingido" -#: src/config/SSSDConfig/sssdoptions.py:92 +#: src/config/SSSDConfig/sssdoptions.py:88 msgid "What kind of messages are displayed to the user during authentication" -msgstr "" +msgstr "Que tipo de mensagens é exigido ao usuário durante a autenticação" -#: src/config/SSSDConfig/sssdoptions.py:93 +#: src/config/SSSDConfig/sssdoptions.py:89 msgid "Filter PAM responses sent to the pam_sss" -msgstr "" +msgstr "Filtra as respostas PAM enviadas para pam_sss" -#: src/config/SSSDConfig/sssdoptions.py:94 +#: src/config/SSSDConfig/sssdoptions.py:90 msgid "How many seconds to keep identity information cached for PAM requests" msgstr "" +"Por quantos segundos manter informações de identidade em cache para " +"requisições PAM" -#: src/config/SSSDConfig/sssdoptions.py:95 +#: src/config/SSSDConfig/sssdoptions.py:91 msgid "How many days before password expiration a warning should be displayed" -msgstr "" +msgstr "Por quantos dias um aviso deve ser exibido antes de expirar a senha" -#: src/config/SSSDConfig/sssdoptions.py:96 +#: src/config/SSSDConfig/sssdoptions.py:92 msgid "List of trusted uids or user's name" -msgstr "" +msgstr "Lista de uids ou nome do usuário confiados" -#: src/config/SSSDConfig/sssdoptions.py:97 +#: src/config/SSSDConfig/sssdoptions.py:93 msgid "List of domains accessible even for untrusted users." -msgstr "" +msgstr "Lista de domínios acessíveis mesmo para usuário não confiados." -#: src/config/SSSDConfig/sssdoptions.py:98 +#: src/config/SSSDConfig/sssdoptions.py:94 msgid "Message printed when user account is expired." -msgstr "" +msgstr "Mensagem exibida quando a conta do usuário expirou." -#: src/config/SSSDConfig/sssdoptions.py:99 +#: src/config/SSSDConfig/sssdoptions.py:95 msgid "Message printed when user account is locked." -msgstr "" +msgstr "Mensagem exibida quando a conta do usuário está bloqueada." -#: src/config/SSSDConfig/sssdoptions.py:100 +#: src/config/SSSDConfig/sssdoptions.py:96 msgid "Allow certificate based/Smartcard authentication." -msgstr "" +msgstr "Permite autenticação por cartão inteligente / com base em certificado." -#: src/config/SSSDConfig/sssdoptions.py:101 +#: src/config/SSSDConfig/sssdoptions.py:97 msgid "Path to certificate database with PKCS#11 modules." -msgstr "" +msgstr "Caminho do banco de dados de certificado com módulos PKCS#11." -#: src/config/SSSDConfig/sssdoptions.py:102 +#: src/config/SSSDConfig/sssdoptions.py:98 msgid "Tune certificate verification for PAM authentication." -msgstr "" +msgstr "Ajusta a verificação de certificado para autenticação PAM." -#: src/config/SSSDConfig/sssdoptions.py:103 +#: src/config/SSSDConfig/sssdoptions.py:99 msgid "How many seconds will pam_sss wait for p11_child to finish" -msgstr "" +msgstr "Por quanto tempo pam_sss vai esperar até p11_child terminar" -#: src/config/SSSDConfig/sssdoptions.py:104 +#: src/config/SSSDConfig/sssdoptions.py:100 msgid "Which PAM services are permitted to contact application domains" -msgstr "" +msgstr "Quais serviços PAM têm permissão para contatar domínios de aplicativos" -#: src/config/SSSDConfig/sssdoptions.py:105 +#: src/config/SSSDConfig/sssdoptions.py:101 msgid "Allowed services for using smartcards" -msgstr "" +msgstr "Serviços permitidos a usar cartões inteligentes" -#: src/config/SSSDConfig/sssdoptions.py:106 +#: src/config/SSSDConfig/sssdoptions.py:102 msgid "Additional timeout to wait for a card if requested" -msgstr "" +msgstr "Tempo limite adicional para esperar por um cartão se solicitado" -#: src/config/SSSDConfig/sssdoptions.py:107 +#: src/config/SSSDConfig/sssdoptions.py:103 msgid "" "PKCS#11 URI to restrict the selection of devices for Smartcard authentication" msgstr "" +"URI PKCS#11 para restringir a seleção de dispositivos para autenticação por " +"cartão inteligente" -#: src/config/SSSDConfig/sssdoptions.py:108 +#: src/config/SSSDConfig/sssdoptions.py:104 msgid "When shall the PAM responder force an initgroups request" -msgstr "" +msgstr "Quando o respondedor PAM deve forçar uma requisição de initgroups" -#: src/config/SSSDConfig/sssdoptions.py:109 +#: src/config/SSSDConfig/sssdoptions.py:105 msgid "List of PAM services that are allowed to authenticate with GSSAPI." -msgstr "" +msgstr "Lista de serviços PAM que têm permissão para autenticar com GSSAPI." -#: src/config/SSSDConfig/sssdoptions.py:110 +#: src/config/SSSDConfig/sssdoptions.py:106 msgid "Whether to match authenticated UPN with target user" -msgstr "" +msgstr "Se deve corresponder UPN não autenticado com usuário alvo" -#: src/config/SSSDConfig/sssdoptions.py:111 +#: src/config/SSSDConfig/sssdoptions.py:107 msgid "" "List of pairs : that must be enforced " "for PAM access with GSSAPI authentication" msgstr "" +"Lista de pares : que deve ser " +"forçado para acesso PAM com autenticação GSSAPI" -#: src/config/SSSDConfig/sssdoptions.py:113 -msgid "Allow passkey device authentication." +#: src/config/SSSDConfig/sssdoptions.py:109 +msgid "" +"List of triples :: that assigns " +"additional information from the Kerberos ticket to an authentication " +"indicator." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:114 +#: src/config/SSSDConfig/sssdoptions.py:112 +msgid "Allow passkey device authentication." +msgstr "Permite autenticação de dispositivo de chave de acesso." + +#: src/config/SSSDConfig/sssdoptions.py:113 msgid "How many seconds will pam_sss wait for passkey_child to finish" -msgstr "" +msgstr "Por quantos segundos pam_sss vai esperar passkey_child terminar" -#: src/config/SSSDConfig/sssdoptions.py:115 +#: src/config/SSSDConfig/sssdoptions.py:114 msgid "Enable debugging in the libfido2 library" -msgstr "" +msgstr "Habilita depuração na biblioteca de libfido2" -#: src/config/SSSDConfig/sssdoptions.py:116 +#: src/config/SSSDConfig/sssdoptions.py:115 msgid "Enable JSON protocol for authentication methods selection." -msgstr "" +msgstr "Habilita protocolo JSON para seleção de métodos de autenticação." -#: src/config/SSSDConfig/sssdoptions.py:119 +#: src/config/SSSDConfig/sssdoptions.py:118 msgid "Whether to evaluate the time-based attributes in sudo rules" -msgstr "" +msgstr "Se deve avaliar os atributos baseados em tempo em regras do sudo" -#: src/config/SSSDConfig/sssdoptions.py:120 +#: src/config/SSSDConfig/sssdoptions.py:119 msgid "If true, SSSD will switch back to lower-wins ordering logic" msgstr "" +"Se verdadeiro, SSSD voltará a usar a lógica de ordenação \"lower wins\"." -#: src/config/SSSDConfig/sssdoptions.py:121 +#: src/config/SSSDConfig/sssdoptions.py:120 msgid "" "Maximum number of rules that can be refreshed at once. If this is exceeded, " "full refresh is performed." msgstr "" +"Número máximo de regras que podem ser atualizados de uma vez. Se esse número " +"for excedido, atualização total é realizada." -#: src/config/SSSDConfig/sssdoptions.py:128 +#: src/config/SSSDConfig/sssdoptions.py:127 msgid "Whether to hash host names and addresses in the known_hosts file" msgstr "" +"Se deve gerar hashes de nomes de host e endereços no arquivo known_hosts" -#: src/config/SSSDConfig/sssdoptions.py:129 +#: src/config/SSSDConfig/sssdoptions.py:128 msgid "" "How many seconds to keep a host in the known_hosts file after its host keys " "were requested" msgstr "" +"Por quantos segundos manter um host no arquivo known_hosts após suas chaves " +"de host terem sido solicitadas" -#: src/config/SSSDConfig/sssdoptions.py:131 +#: src/config/SSSDConfig/sssdoptions.py:130 msgid "Path to storage of trusted CA certificates" -msgstr "" +msgstr "Caminho para o armazenamento de certificados de AC confiáveis" -#: src/config/SSSDConfig/sssdoptions.py:132 +#: src/config/SSSDConfig/sssdoptions.py:131 msgid "Allow to generate ssh-keys from certificates" -msgstr "" +msgstr "Permite gerar chaves ssh a partir de certificados" -#: src/config/SSSDConfig/sssdoptions.py:133 +#: src/config/SSSDConfig/sssdoptions.py:132 msgid "" "Use the following matching rules to filter the certificates for ssh-key " "generation" msgstr "" +"Usa as seguintes regras de correspondência para filtrar os certificados para " +"geração de chave ssh" -#: src/config/SSSDConfig/sssdoptions.py:137 +#: src/config/SSSDConfig/sssdoptions.py:136 msgid "List of UIDs or user names allowed to access the PAC responder" msgstr "" +"Lista de UIDs ou nomes de usuários permitidos a acessar o respondedor PAC" -#: src/config/SSSDConfig/sssdoptions.py:138 +#: src/config/SSSDConfig/sssdoptions.py:137 msgid "How long the PAC data is considered valid" -msgstr "" +msgstr "Por quanto tempo os dados PAC são considerados válidos" -#: src/config/SSSDConfig/sssdoptions.py:139 +#: src/config/SSSDConfig/sssdoptions.py:138 msgid "Validate the PAC" -msgstr "" +msgstr "Valida o PAC" -#: src/config/SSSDConfig/sssdoptions.py:142 +#: src/config/SSSDConfig/sssdoptions.py:141 msgid "List of user attributes the InfoPipe is allowed to publish" -msgstr "" +msgstr "Lista de atributos de usuário que o InfoPipe é permitido publicar" -#: src/config/SSSDConfig/sssdoptions.py:145 +#: src/config/SSSDConfig/sssdoptions.py:144 msgid "" "One of the following strings specifying the scope of session recording: none " "- No users are recorded. some - Users/groups specified by users and groups " "options are recorded. all - All users are recorded." msgstr "" +"Uma das seguintes strings especifica o escopo da gravação da sessão: none - " +"Nenhum usuário é gravado. some - Usuários/grupos especificados pelas opções " +"users e groups são gravados. all - Todos os usuários são gravados." -#: src/config/SSSDConfig/sssdoptions.py:148 +#: src/config/SSSDConfig/sssdoptions.py:147 msgid "" "A comma-separated list of users which should have session recording enabled. " "Matches user names as returned by NSS. I.e. after the possible space " "replacement, case changes, etc." msgstr "" +"Uma lista de usuários separados por vírgula que devem ter a gravação de " +"sessão ativada. Corresponde aos nomes de usuário retornados pelo NSS, ou " +"seja, após possíveis substituições de espaços, alterações de maiúsculas e " +"minúsculas, etc." -#: src/config/SSSDConfig/sssdoptions.py:150 +#: src/config/SSSDConfig/sssdoptions.py:149 msgid "" "A comma-separated list of groups, members of which should have session " "recording enabled. Matches group names as returned by NSS. I.e. after the " "possible space replacement, case changes, etc." msgstr "" +"Uma lista de grupos separados por vírgulas, cujos membros devem ter a " +"gravação de sessão ativada. Corresponde aos nomes dos grupos conforme " +"retornados pelo NSS, ou seja, após a possível substituição de espaços, " +"alterações de maiúsculas e minúsculas, etc." -#: src/config/SSSDConfig/sssdoptions.py:153 +#: src/config/SSSDConfig/sssdoptions.py:152 msgid "" "A comma-separated list of users to be excluded from recording, only when " "scope=all" msgstr "" +"Uma lista de usuários separados por vírgula a serem excluídos da gravação, " +"somente quando scope=all" -#: src/config/SSSDConfig/sssdoptions.py:154 +#: src/config/SSSDConfig/sssdoptions.py:153 msgid "" "A comma-separated list of groups, members of which should be excluded from " "recording, only when scope=all. " msgstr "" +"Uma lista de grupos separados por vírgulas, cujos membros devem ser " +"excluídos da gravação somente quando scope=all. " -#: src/config/SSSDConfig/sssdoptions.py:158 +#: src/config/SSSDConfig/sssdoptions.py:157 msgid "Identity provider" -msgstr "" +msgstr "Provedor de identidade" -#: src/config/SSSDConfig/sssdoptions.py:159 +#: src/config/SSSDConfig/sssdoptions.py:158 msgid "Authentication provider" -msgstr "" +msgstr "Provedor de autenticação" -#: src/config/SSSDConfig/sssdoptions.py:160 +#: src/config/SSSDConfig/sssdoptions.py:159 msgid "Access control provider" -msgstr "" +msgstr "Provedor de controle de acesso" -#: src/config/SSSDConfig/sssdoptions.py:161 +#: src/config/SSSDConfig/sssdoptions.py:160 msgid "Password change provider" -msgstr "" +msgstr "Provedor de alteração de senha" -#: src/config/SSSDConfig/sssdoptions.py:162 +#: src/config/SSSDConfig/sssdoptions.py:161 msgid "SUDO provider" -msgstr "" +msgstr "Provedor de SUDO" -#: src/config/SSSDConfig/sssdoptions.py:163 +#: src/config/SSSDConfig/sssdoptions.py:162 msgid "Autofs provider" -msgstr "" +msgstr "Provedor de Autofs" -#: src/config/SSSDConfig/sssdoptions.py:164 +#: src/config/SSSDConfig/sssdoptions.py:163 msgid "Host identity provider" -msgstr "" +msgstr "Provedor de identidade de host" -#: src/config/SSSDConfig/sssdoptions.py:165 +#: src/config/SSSDConfig/sssdoptions.py:164 msgid "SELinux provider" -msgstr "" +msgstr "Provedor de SELinux" -#: src/config/SSSDConfig/sssdoptions.py:166 +#: src/config/SSSDConfig/sssdoptions.py:165 msgid "Session management provider" -msgstr "" +msgstr "Provedor de gerenciamento de sessão" -#: src/config/SSSDConfig/sssdoptions.py:167 +#: src/config/SSSDConfig/sssdoptions.py:166 msgid "Resolver provider" -msgstr "" +msgstr "Provedor de resolvedor" -#: src/config/SSSDConfig/sssdoptions.py:170 +#: src/config/SSSDConfig/sssdoptions.py:169 msgid "Whether the domain is usable by the OS or by applications" -msgstr "" +msgstr "Se o domínio é usável pelo sistema operacional ou pelos aplicativos" -#: src/config/SSSDConfig/sssdoptions.py:171 +#: src/config/SSSDConfig/sssdoptions.py:170 msgid "Enable or disable the domain" -msgstr "" +msgstr "Habilita ou desabilita o domínio" -#: src/config/SSSDConfig/sssdoptions.py:172 +#: src/config/SSSDConfig/sssdoptions.py:171 msgid "Minimum user ID" -msgstr "" +msgstr "ID mínimo de usuário" -#: src/config/SSSDConfig/sssdoptions.py:173 +#: src/config/SSSDConfig/sssdoptions.py:172 msgid "Maximum user ID" -msgstr "" +msgstr "ID máximo de usuário" -#: src/config/SSSDConfig/sssdoptions.py:174 +#: src/config/SSSDConfig/sssdoptions.py:173 msgid "Enable enumerating all users/groups" -msgstr "" +msgstr "Habilita enumeração de todos os usuários/grupos" -#: src/config/SSSDConfig/sssdoptions.py:175 +#: src/config/SSSDConfig/sssdoptions.py:174 msgid "Cache credentials for offline login" -msgstr "" +msgstr "Faz cache de credenciais para login offline" -#: src/config/SSSDConfig/sssdoptions.py:176 +#: src/config/SSSDConfig/sssdoptions.py:175 msgid "Display users/groups in fully-qualified form" -msgstr "" +msgstr "Exibe usuários/grupos na forma completamente qualificada" -#: src/config/SSSDConfig/sssdoptions.py:177 +#: src/config/SSSDConfig/sssdoptions.py:176 msgid "Don't include group members in group lookups" -msgstr "" +msgstr "Não inclui membros de grupo ao procurar grupos" -#: src/config/SSSDConfig/sssdoptions.py:178 +#: src/config/SSSDConfig/sssdoptions.py:177 #: src/config/SSSDConfig/sssdoptions.py:190 #: src/config/SSSDConfig/sssdoptions.py:191 #: src/config/SSSDConfig/sssdoptions.py:192 @@ -525,160 +605,192 @@ msgstr "" #: src/config/SSSDConfig/sssdoptions.py:195 #: src/config/SSSDConfig/sssdoptions.py:196 msgid "Entry cache timeout length (seconds)" -msgstr "" +msgstr "Tempo limite (em segundos) de cache de entrada" -#: src/config/SSSDConfig/sssdoptions.py:179 +#: src/config/SSSDConfig/sssdoptions.py:178 msgid "" "Restrict or prefer a specific address family when performing DNS lookups" msgstr "" +"Restringe ou prefere uma família de endereço específica ao realizar " +"pesquisas de DNS" -#: src/config/SSSDConfig/sssdoptions.py:180 +#: src/config/SSSDConfig/sssdoptions.py:179 msgid "How long to keep cached entries after last successful login (days)" msgstr "" +"Por quanto tempo manter entradas em cache após o último login bem-sucedido " +"(dias)" -#: src/config/SSSDConfig/sssdoptions.py:181 +#: src/config/SSSDConfig/sssdoptions.py:180 msgid "" "How long should SSSD talk to single DNS server before trying next server " "(miliseconds)" msgstr "" +"Por quanto tempo SSSD deve falar com um único serviço DNS antes de tentar o " +"próximo servidor (milissegundos)" -#: src/config/SSSDConfig/sssdoptions.py:183 +#: src/config/SSSDConfig/sssdoptions.py:182 msgid "How long should keep trying to resolve single DNS query (seconds)" msgstr "" +"Por quanto tempo deve continuar tentando resolver uma única consulta DNS " +"(segundos)" -#: src/config/SSSDConfig/sssdoptions.py:184 +#: src/config/SSSDConfig/sssdoptions.py:183 msgid "How long to wait for replies from DNS when resolving servers (seconds)" msgstr "" +"Por quanto tempo deve esperar por respostas do DNS ao resolver servidores " +"(segundos)" -#: src/config/SSSDConfig/sssdoptions.py:185 +#: src/config/SSSDConfig/sssdoptions.py:184 msgid "The domain part of service discovery DNS query" -msgstr "" +msgstr "A parte do domínio da consulta DNS de descoberta de serviços" -#: src/config/SSSDConfig/sssdoptions.py:186 +#: src/config/SSSDConfig/sssdoptions.py:185 msgid "" "Specifies the interval, in seconds, that SSSD waits before attempting to " "reconnect to the primary server after a successful connection to the backup " "server" msgstr "" +"Especifica o intervalo, em segundos, que SSSD espera antes de tentar " +"reconectar o servidor principal após uma conexão bem-sucedida ao servidor " +"backup" -#: src/config/SSSDConfig/sssdoptions.py:188 +#: src/config/SSSDConfig/sssdoptions.py:187 msgid "Override GID value from the identity provider with this value" -msgstr "" +msgstr "Substitui o valor de GID do provedor de identidade com este valor" -#: src/config/SSSDConfig/sssdoptions.py:189 +#: src/config/SSSDConfig/sssdoptions.py:188 msgid "Treat usernames as case sensitive" +msgstr "Trata nomes de usuários diferenciando maiúsculo de minúsculo" + +#: src/config/SSSDConfig/sssdoptions.py:189 +msgid "Lookups by ID are expensive or do not work at all" msgstr "" #: src/config/SSSDConfig/sssdoptions.py:197 msgid "How often should expired entries be refreshed in background" msgstr "" +"Com qual frequência entradas expiradas devem ser atualizadas em segundo plano" #: src/config/SSSDConfig/sssdoptions.py:198 msgid "Maximum period deviation when refreshing expired entries in background" msgstr "" +"Desvio máximo do período ao atualizar entradas expiradas em segundo plano" #: src/config/SSSDConfig/sssdoptions.py:199 msgid "Whether to automatically update the client's DNS entry" -msgstr "" +msgstr "Se deve atualizar automaticamente entrada de DNS do cliente" #: src/config/SSSDConfig/sssdoptions.py:200 msgid "" "Whether DNS update of A and AAAA record should be performed in one update or " "in two separate updates" msgstr "" +"Se atualização de DNS dos registros A e AAAA deve ser realizada em uma única " +"atualização ou em duas atualizações separadas" #: src/config/SSSDConfig/sssdoptions.py:202 msgid "The TTL to apply to the client's DNS entry after updating it" -msgstr "" +msgstr "O TTL para aplicar à entrada de DNS do cliente após atualizá-la" #: src/config/SSSDConfig/sssdoptions.py:203 msgid "The interface whose IP should be used for dynamic DNS updates" -msgstr "" +msgstr "A interface cujo IP deve ser usado para atualizações DNS dinâmicas" #: src/config/SSSDConfig/sssdoptions.py:204 msgid "The list of IP addresses that should be used for dynamic DNS updates" msgstr "" +"A lista de endereços IP que deve ser usada para atualizações DNS dinâmicas" #: src/config/SSSDConfig/sssdoptions.py:205 msgid "How often to periodically update the client's DNS entry" msgstr "" +"Com qual frequência atualizar periodicamente a entrada de DNS do cliente" #: src/config/SSSDConfig/sssdoptions.py:206 msgid "Maximum period deviation when updating the client's DNS entry" -msgstr "" +msgstr "Desvio máximo do período ao atualizar a entrada DNS do cliente" #: src/config/SSSDConfig/sssdoptions.py:207 msgid "Whether the provider should explicitly update the PTR record as well" -msgstr "" +msgstr "Se o provedor deve atualizar explicitamente o registro PTR também" #: src/config/SSSDConfig/sssdoptions.py:208 msgid "Whether the nsupdate utility should default to using TCP" -msgstr "" +msgstr "Se o utilitário nsupdate deve usar TCP por padrão" #: src/config/SSSDConfig/sssdoptions.py:209 msgid "What kind of authentication should be used to perform the DNS update" msgstr "" +"Qual tipo de autenticação deve ser usado para realizar a atualização DNS" #: src/config/SSSDConfig/sssdoptions.py:210 msgid "Override the DNS server used to perform the DNS update" -msgstr "" +msgstr "Substitui o servidor DNS usado para realizar a atualização DNS" #: src/config/SSSDConfig/sssdoptions.py:211 msgid "The file of the certificate authorities certificates for DoT" -msgstr "" +msgstr "O arquivo de certificados das autoridades de certificação para DoT" #: src/config/SSSDConfig/sssdoptions.py:212 msgid "The certificate(s) file for authentication for the DoT transport" -msgstr "" +msgstr "O arquivo de certificado(s) para autenticação para o transporte DoT" #: src/config/SSSDConfig/sssdoptions.py:213 msgid "The key file for authenticated encryption for the DoT transport" -msgstr "" +msgstr "O arquivo de chave para criptografia autenticada para o transporte DoT" #: src/config/SSSDConfig/sssdoptions.py:214 msgid "How often should subdomains list be refreshed" -msgstr "" +msgstr "Com que frequência a lista de subdomínios deve ser atualizada" #: src/config/SSSDConfig/sssdoptions.py:215 msgid "Maximum period deviation when refreshing the subdomain list" -msgstr "" +msgstr "Desvio máximo do período ao atualizar a lista de subdomínios" #: src/config/SSSDConfig/sssdoptions.py:216 msgid "List of options that should be inherited into a subdomain" -msgstr "" +msgstr "Lista de opções que devem ser herdadas em um subdomínio" #: src/config/SSSDConfig/sssdoptions.py:217 msgid "Default subdomain homedir value" -msgstr "" +msgstr "Valor padrão de homedir do subdomínio" #: src/config/SSSDConfig/sssdoptions.py:218 msgid "How long can cached credentials be used for cached authentication" msgstr "" +"Por quanto tempo as credenciais em cache podem ser usadas para autenticação " +"em cache" #: src/config/SSSDConfig/sssdoptions.py:219 msgid "Whether to automatically create private groups for users" -msgstr "" +msgstr "Se deve criar automaticamente grupos privados para usuários" #: src/config/SSSDConfig/sssdoptions.py:220 msgid "Display a warning N days before the password expires." -msgstr "" +msgstr "Exibe um aviso N dias antes da expiração da senha." #: src/config/SSSDConfig/sssdoptions.py:221 msgid "" "Various tags stored by the realmd configuration service for this domain." msgstr "" +"Várias tags armazenadas pelo serviço de configuração realmd para este " +"domínio." #: src/config/SSSDConfig/sssdoptions.py:222 msgid "" "The provider which should handle fetching of subdomains. This value should " "be always the same as id_provider." msgstr "" +"O provedor que deve lidar com a busca de subdomínios. Este valor deve ser " +"sempre o mesmo que id_provider." #: src/config/SSSDConfig/sssdoptions.py:224 msgid "" "How many seconds to keep a host ssh key after refresh. IE how long to cache " "the host key for." msgstr "" +"Por quantos segundos manter uma chave SSH do host após a atualização. Ou " +"seja, por quanto tempo armazenar a chave do host em cache." #: src/config/SSSDConfig/sssdoptions.py:226 msgid "" @@ -686,418 +798,465 @@ msgid "" "this value determines the minimal length the first authentication factor " "(long term password) must have to be saved as SHA512 hash into the cache." msgstr "" +"Se a autenticação de dois fatores (2FA) for usada e as credenciais devem ser " +"salvas, este valor determina o comprimento mínimo que o primeiro fator de " +"autenticação (senha de longo prazo) deve ter para ser salvo como hash SHA512 " +"no cache." #: src/config/SSSDConfig/sssdoptions.py:230 msgid "Local authentication methods policy " -msgstr "" +msgstr "Política de métodos de autenticação local " #: src/config/SSSDConfig/sssdoptions.py:233 msgid "IPA domain" -msgstr "" +msgstr "Domínio IPA" #: src/config/SSSDConfig/sssdoptions.py:234 msgid "IPA server address" -msgstr "" +msgstr "Endereço do servidor IPA" #: src/config/SSSDConfig/sssdoptions.py:235 msgid "Address of backup IPA server" -msgstr "" +msgstr "Endereço do servidor IPA de backup" #: src/config/SSSDConfig/sssdoptions.py:236 msgid "IPA client hostname" -msgstr "" +msgstr "Nome do host do cliente IPA" #: src/config/SSSDConfig/sssdoptions.py:237 msgid "Search base for HBAC related objects" -msgstr "" +msgstr "Base de pesquisa para objetos relacionados a HBAC" #: src/config/SSSDConfig/sssdoptions.py:238 msgid "" "The amount of time between lookups of the HBAC rules against the IPA server" -msgstr "" +msgstr "Tempo entre as consultas das regras HBAC no servidor IPA" #: src/config/SSSDConfig/sssdoptions.py:239 msgid "" "The amount of time in seconds between lookups of the SELinux maps against " "the IPA server" -msgstr "" +msgstr "Tempo em segundos entre as consultas dos mapas SELinux no servidor IPA" #: src/config/SSSDConfig/sssdoptions.py:241 msgid "If set to false, host argument given by PAM will be ignored" msgstr "" +"Se definido como falso, o argumento de host fornecido pelo PAM será ignorado" #: src/config/SSSDConfig/sssdoptions.py:242 msgid "The automounter location this IPA client is using" -msgstr "" +msgstr "Local de montagem automática que este cliente IPA está usando" #: src/config/SSSDConfig/sssdoptions.py:243 msgid "Search base for object containing info about IPA domain" -msgstr "" +msgstr "Base de pesquisa para objetos contendo informações sobre o domínio IPA" #: src/config/SSSDConfig/sssdoptions.py:244 msgid "Search base for objects containing info about ID ranges" msgstr "" +"Base de pesquisa para objetos contendo informações sobre intervalos de ID" #: src/config/SSSDConfig/sssdoptions.py:245 msgid "Search base for view containers" -msgstr "" +msgstr "Base de pesquisa para contêineres de visualização" #: src/config/SSSDConfig/sssdoptions.py:246 msgid "Objectclass for view containers" -msgstr "" +msgstr "Objectclass para contêineres de visualização" #: src/config/SSSDConfig/sssdoptions.py:247 msgid "Attribute with the name of the view" -msgstr "" +msgstr "Atributo com o nome da visualização" #: src/config/SSSDConfig/sssdoptions.py:248 msgid "Objectclass for override objects" -msgstr "" +msgstr "Objectclass para objetos de substituição" #: src/config/SSSDConfig/sssdoptions.py:249 msgid "Attribute with the reference to the original object" -msgstr "" +msgstr "Atributo com a referência ao objeto original" #: src/config/SSSDConfig/sssdoptions.py:250 msgid "Objectclass for user override objects" -msgstr "" +msgstr "Objectclass para objetos de substituição de usuário" #: src/config/SSSDConfig/sssdoptions.py:251 msgid "Objectclass for group override objects" -msgstr "" +msgstr "Objectclass para objetos de substituição de grupo" #: src/config/SSSDConfig/sssdoptions.py:252 msgid "Search base for Desktop Profile related objects" -msgstr "" +msgstr "Base de pesquisa para objetos relacionados ao Perfil Desktop" #: src/config/SSSDConfig/sssdoptions.py:253 msgid "" "The amount of time in seconds between lookups of the Desktop Profile rules " "against the IPA server" msgstr "" +"O tempo em segundos entre as pesquisas das regras do Perfil Desktop no " +"servidor IPA" #: src/config/SSSDConfig/sssdoptions.py:255 msgid "" "The amount of time in minutes between lookups of Desktop Profiles rules " "against the IPA server when the last request did not find any rule" msgstr "" +"O tempo em minutos entre as pesquisas das regras do Perfil Desktop no " +"servidor IPA quando a última solicitação não encontrou nenhuma regra" #: src/config/SSSDConfig/sssdoptions.py:258 #: src/config/SSSDConfig/sssdoptions.py:455 msgid "Search base for SUBID ranges" -msgstr "" +msgstr "Base de pesquisa para intervalos de SUBID" #: src/config/SSSDConfig/sssdoptions.py:259 -#: src/config/SSSDConfig/sssdoptions.py:506 +#: src/config/SSSDConfig/sssdoptions.py:512 msgid "Which rules should be used to evaluate access control" -msgstr "" +msgstr "Quais regras devem ser usadas para avaliar o controle de acesso" #: src/config/SSSDConfig/sssdoptions.py:260 msgid "The LDAP attribute that contains FQDN of the host." -msgstr "" +msgstr "O atributo LDAP que contém o FQDN do host." #: src/config/SSSDConfig/sssdoptions.py:261 #: src/config/SSSDConfig/sssdoptions.py:284 msgid "The object class of a host entry in LDAP." -msgstr "" +msgstr "A classe de objeto de uma entrada de host no LDAP." #: src/config/SSSDConfig/sssdoptions.py:262 msgid "Use the given string as search base for host objects." -msgstr "" +msgstr "Usa a string fornecida como base de pesquisa para objetos de host." #: src/config/SSSDConfig/sssdoptions.py:263 msgid "The LDAP attribute that contains the host's SSH public keys." -msgstr "" +msgstr "O atributo LDAP que contém as chaves públicas SSH do host." #: src/config/SSSDConfig/sssdoptions.py:264 msgid "The LDAP attribute that contains NIS domain name of the netgroup." -msgstr "" +msgstr "O atributo LDAP que contém o nome de domínio NIS do grupo de rede." #: src/config/SSSDConfig/sssdoptions.py:265 msgid "The LDAP attribute that contains the names of the netgroup's members." -msgstr "" +msgstr "O atributo LDAP que contém os nomes dos membros do grupo de rede." #: src/config/SSSDConfig/sssdoptions.py:266 msgid "" "The LDAP attribute that lists FQDNs of hosts and host groups that are " "members of the netgroup." msgstr "" +"O atributo LDAP que lista os FQDNs de hosts e grupos de hosts que são " +"membros do grupo de rede." #: src/config/SSSDConfig/sssdoptions.py:268 msgid "" "The LDAP attribute that lists hosts and host groups that are direct members " "of the netgroup." msgstr "" +"O atributo LDAP que lista os hosts e grupos de hosts que são membros diretos " +"do grupo de rede." #: src/config/SSSDConfig/sssdoptions.py:270 msgid "The LDAP attribute that lists netgroup's memberships." -msgstr "" +msgstr "O atributo LDAP que lista as associações do grupo de rede." #: src/config/SSSDConfig/sssdoptions.py:271 msgid "" "The LDAP attribute that lists system users and groups that are direct " "members of the netgroup." msgstr "" +"O atributo LDAP que lista os usuários e grupos do sistema que são membros " +"diretos do grupo de rede." #: src/config/SSSDConfig/sssdoptions.py:273 msgid "The LDAP attribute that corresponds to the netgroup name." -msgstr "" +msgstr "O atributo LDAP que corresponde ao nome do grupo de rede." #: src/config/SSSDConfig/sssdoptions.py:274 msgid "The object class of a netgroup entry in LDAP." -msgstr "" +msgstr "A classe de objeto de uma entrada de grupo de rede no LDAP." #: src/config/SSSDConfig/sssdoptions.py:275 msgid "" "The LDAP attribute that contains the UUID/GUID of an LDAP netgroup object." msgstr "" +"O atributo LDAP que contém o UUID/GUID de um objeto de grupo de rede LDAP." #: src/config/SSSDConfig/sssdoptions.py:276 msgid "" "The LDAP attribute that contains whether or not is user map enabled for " "usage." msgstr "" +"O atributo LDAP que indica se o mapeamento de usuários está habilitado para " +"uso." #: src/config/SSSDConfig/sssdoptions.py:278 msgid "The LDAP attribute that contains host category such as 'all'." -msgstr "" +msgstr "O atributo LDAP que contém a categoria do host, como 'all'." #: src/config/SSSDConfig/sssdoptions.py:279 msgid "" "The LDAP attribute that contains all hosts / hostgroups this rule match " "against." msgstr "" +"O atributo LDAP que contém todos os hosts/grupos de hosts com os quais esta " +"regra corresponde." #: src/config/SSSDConfig/sssdoptions.py:281 msgid "" "The LDAP attribute that contains all users / groups this rule match against." msgstr "" +"O atributo LDAP que contém todos os usuários/grupos com os quais esta regra " +"corresponde." #: src/config/SSSDConfig/sssdoptions.py:283 msgid "The LDAP attribute that contains the name of SELinux usermap." -msgstr "" +msgstr "O atributo LDAP que contém o nome do mapeamento de usuários SELinux." #: src/config/SSSDConfig/sssdoptions.py:285 msgid "" "The LDAP attribute that contains DN of HBAC rule which can be used for " "matching instead of memberUser and memberHost." msgstr "" +"O atributo LDAP que contém o DN da regra HBAC que pode ser usada para " +"correspondência em vez de memberUser e memberHost." #: src/config/SSSDConfig/sssdoptions.py:287 msgid "The LDAP attribute that contains SELinux user string itself." -msgstr "" +msgstr "O atributo LDAP que contém a própria string do usuário SELinux." #: src/config/SSSDConfig/sssdoptions.py:288 msgid "The LDAP attribute that contains user category such as 'all'." -msgstr "" +msgstr "O atributo LDAP que contém a categoria do usuário, como 'all'." #: src/config/SSSDConfig/sssdoptions.py:289 msgid "The LDAP attribute that contains unique ID of the user map." -msgstr "" +msgstr "O atributo LDAP que contém o ID exclusivo do mapeamento de usuários." #: src/config/SSSDConfig/sssdoptions.py:290 msgid "" "The option denotes that the SSSD is running on IPA server and should perform " "lookups of users and groups from trusted domains differently." msgstr "" +"Esta opção indica que o SSSD está sendo executado no servidor IPA e deve " +"realizar pesquisas de usuários e grupos de domínios confiáveis de forma " +"diferente." #: src/config/SSSDConfig/sssdoptions.py:292 msgid "Use the given string as search base for trusted domains." -msgstr "" +msgstr "Use a string fornecida como base de pesquisa para domínios confiáveis." #: src/config/SSSDConfig/sssdoptions.py:295 msgid "Active Directory domain" -msgstr "" +msgstr "Domínio Active Directory" #: src/config/SSSDConfig/sssdoptions.py:296 msgid "Enabled Active Directory domains" -msgstr "" +msgstr "Domínios Active Directory habilitados" #: src/config/SSSDConfig/sssdoptions.py:297 msgid "Active Directory server address" -msgstr "" +msgstr "Endereço do servidor do Active Directory" #: src/config/SSSDConfig/sssdoptions.py:298 msgid "Active Directory backup server address" -msgstr "" +msgstr "Endereço do servidor de backup do Active Directory" #: src/config/SSSDConfig/sssdoptions.py:299 msgid "Active Directory client hostname" -msgstr "" +msgstr "Nome do host do cliente do Active Directory" #: src/config/SSSDConfig/sssdoptions.py:300 msgid "Enable DNS sites - location based service discovery" -msgstr "" +msgstr "Habilita sites DNS - descoberta de serviços baseada em localização" #: src/config/SSSDConfig/sssdoptions.py:301 -#: src/config/SSSDConfig/sssdoptions.py:504 +#: src/config/SSSDConfig/sssdoptions.py:510 msgid "LDAP filter to determine access privileges" -msgstr "" +msgstr "Filtro LDAP para determinar privilégios de acesso" #: src/config/SSSDConfig/sssdoptions.py:302 msgid "Whether to use the Global Catalog for lookups" -msgstr "" +msgstr "Usa o Catálogo Global para pesquisas" #: src/config/SSSDConfig/sssdoptions.py:303 msgid "Operation mode for GPO-based access control" -msgstr "" +msgstr "Modo de operação para controle de acesso baseado em GPO" #: src/config/SSSDConfig/sssdoptions.py:304 msgid "" "The amount of time between lookups of the GPO policy files against the AD " "server" -msgstr "" +msgstr "Tempo entre pesquisas dos arquivos de política de GPO no servidor AD" #: src/config/SSSDConfig/sssdoptions.py:305 msgid "" "PAM service names that map to the GPO (Deny)InteractiveLogonRight policy " "settings" msgstr "" +"Nomes de serviço PAM que mapeiam para as configurações de política " +"(Deny)InteractiveLogonRight do GPO" #: src/config/SSSDConfig/sssdoptions.py:307 msgid "" "PAM service names that map to the GPO (Deny)RemoteInteractiveLogonRight " "policy settings" msgstr "" +"Nomes de serviço PAM que mapeiam para as configurações de política " +"(Deny)RemoteInteractiveLogonRight do GPO" #: src/config/SSSDConfig/sssdoptions.py:309 msgid "" "PAM service names that map to the GPO (Deny)NetworkLogonRight policy settings" msgstr "" +"Nomes de serviço PAM que mapeiam para as configurações de política " +"(Deny)NetworkLogonRight do GPO" #: src/config/SSSDConfig/sssdoptions.py:310 msgid "" "PAM service names that map to the GPO (Deny)BatchLogonRight policy settings" msgstr "" +"Nomes de serviço PAM que mapeiam para as configurações de política " +"(Deny)BatchLogonRight do GPO" #: src/config/SSSDConfig/sssdoptions.py:311 msgid "" "PAM service names that map to the GPO (Deny)ServiceLogonRight policy settings" msgstr "" +"Nomes de serviço PAM que mapeiam para as configurações de política " +"(Deny)ServiceLogonRight do GPO" #: src/config/SSSDConfig/sssdoptions.py:312 msgid "PAM service names for which GPO-based access is always granted" msgstr "" +"Nomes de serviço PAM para os quais o acesso baseado em GPO é sempre concedido" #: src/config/SSSDConfig/sssdoptions.py:313 msgid "PAM service names for which GPO-based access is always denied" msgstr "" +"Nomes de serviço PAM para os quais o acesso baseado em GPO é sempre negado" #: src/config/SSSDConfig/sssdoptions.py:314 msgid "" "Default logon right (or permit/deny) to use for unmapped PAM service names" msgstr "" +"Direito de logon padrão (ou permitir/negar) o uso para nomes de serviço PAM " +"não mapeados" #: src/config/SSSDConfig/sssdoptions.py:315 msgid "a particular site to be used by the client" -msgstr "" +msgstr "um site específico a ser usado pelo cliente" #: src/config/SSSDConfig/sssdoptions.py:316 msgid "" "Maximum age in days before the machine account password should be renewed" -msgstr "" +msgstr "Idade máxima em dias antes da renovação da senha da conta da máquina" #: src/config/SSSDConfig/sssdoptions.py:318 msgid "Option for tuning the machine account renewal task" -msgstr "" +msgstr "Opção para ajustar a tarefa de renovação da conta da máquina" #: src/config/SSSDConfig/sssdoptions.py:319 msgid "Whether to update the machine account password in the Samba database" msgstr "" +"Se a senha da conta da máquina deve ser atualizada no banco de dados Samba" #: src/config/SSSDConfig/sssdoptions.py:321 msgid "Use LDAPS port for LDAP and Global Catalog requests" -msgstr "" +msgstr "Usa a porta LDAPS para solicitações LDAP e Global Catalog" #: src/config/SSSDConfig/sssdoptions.py:324 #: src/config/SSSDConfig/sssdoptions.py:325 msgid "Kerberos server address" -msgstr "" +msgstr "Endereço do servidor Kerberos" #: src/config/SSSDConfig/sssdoptions.py:326 msgid "Kerberos backup server address" -msgstr "" +msgstr "Endereço do servidor de backup Kerberos" #: src/config/SSSDConfig/sssdoptions.py:327 msgid "Kerberos realm" -msgstr "" +msgstr "Reino Kerberos" #: src/config/SSSDConfig/sssdoptions.py:328 msgid "Authentication timeout" -msgstr "" +msgstr "Tempo limite de autenticação" #: src/config/SSSDConfig/sssdoptions.py:329 msgid "Whether to create kdcinfo files" -msgstr "" +msgstr "Se os arquivos kdcinfo devem ser criados" #: src/config/SSSDConfig/sssdoptions.py:330 msgid "Where to drop krb5 config snippets" -msgstr "" +msgstr "Onde colocar os trechos de configuração krb5" #: src/config/SSSDConfig/sssdoptions.py:333 msgid "Directory to store credential caches" -msgstr "" +msgstr "Diretório para armazenar caches de credenciais" #: src/config/SSSDConfig/sssdoptions.py:334 msgid "Location of the user's credential cache" -msgstr "" +msgstr "Local do cache de credenciais do usuário" #: src/config/SSSDConfig/sssdoptions.py:335 msgid "Location of the keytab to validate credentials" -msgstr "" +msgstr "Local da tabela de chaves para validar credenciais" #: src/config/SSSDConfig/sssdoptions.py:336 msgid "Enable credential validation" -msgstr "" +msgstr "Habilita validação de credenciais" #: src/config/SSSDConfig/sssdoptions.py:337 msgid "Store password if offline for later online authentication" -msgstr "" +msgstr "Armazena senha se estiver offline para autenticação online posterior" #: src/config/SSSDConfig/sssdoptions.py:338 msgid "Renewable lifetime of the TGT" -msgstr "" +msgstr "Tempo de vida renovável do TGT" #: src/config/SSSDConfig/sssdoptions.py:339 msgid "Lifetime of the TGT" -msgstr "" +msgstr "Tempo de vida do TGT" #: src/config/SSSDConfig/sssdoptions.py:340 msgid "Time between two checks for renewal" -msgstr "" +msgstr "Tempo entre duas verificações de renovação" #: src/config/SSSDConfig/sssdoptions.py:341 msgid "Enables FAST" -msgstr "" +msgstr "Habilita FAST" #: src/config/SSSDConfig/sssdoptions.py:342 msgid "Selects the principal to use for FAST" -msgstr "" +msgstr "Seleciona a entidade principal a ser usada para FAST" #: src/config/SSSDConfig/sssdoptions.py:343 msgid "Use anonymous PKINIT to request FAST credentials" -msgstr "" +msgstr "Usa PKINIT anônimo para solicitar credenciais FAST" #: src/config/SSSDConfig/sssdoptions.py:344 msgid "Enables principal canonicalization" -msgstr "" +msgstr "Habilita a canonicalização da entidade principal" #: src/config/SSSDConfig/sssdoptions.py:345 msgid "Enables enterprise principals" -msgstr "" +msgstr "Habilita entidades principais corporativas" #: src/config/SSSDConfig/sssdoptions.py:346 msgid "Enables using of subdomains realms for authentication" -msgstr "" +msgstr "Habilita o uso de realms de subdomínios para autenticação" #: src/config/SSSDConfig/sssdoptions.py:347 msgid "A mapping from user names to Kerberos principal names" msgstr "" +"Um mapeamento de nomes de usuário para nomes de entidade principal do " +"Kerberos" #: src/config/SSSDConfig/sssdoptions.py:350 #: src/config/SSSDConfig/sssdoptions.py:351 msgid "Server where the change password service is running if not on the KDC" msgstr "" +"Servidor onde o serviço de alteração de senha está em execução, se não " +"estiver no KDC" #: src/config/SSSDConfig/sssdoptions.py:354 msgid "ldap_uri, The URI of the LDAP server" @@ -1350,7 +1509,7 @@ msgid "UUID attribute" msgstr "" #: src/config/SSSDConfig/sssdoptions.py:423 -#: src/config/SSSDConfig/sssdoptions.py:464 +#: src/config/SSSDConfig/sssdoptions.py:470 msgid "objectSID attribute" msgstr "" @@ -1474,385 +1633,409 @@ msgstr "" msgid "A list of extra attributes to download along with the user entry" msgstr "" +#: src/config/SSSDConfig/sssdoptions.py:456 +msgid "The object class of an subid entry in LDAP." +msgstr "" + #: src/config/SSSDConfig/sssdoptions.py:457 -msgid "Base DN for group lookups" +msgid "Subordinate user ID count attribute" msgstr "" #: src/config/SSSDConfig/sssdoptions.py:458 -msgid "Objectclass for groups" +msgid "Subordinate group ID count attribute" msgstr "" #: src/config/SSSDConfig/sssdoptions.py:459 -msgid "Group name" +msgid "User ID range start value attribute" msgstr "" #: src/config/SSSDConfig/sssdoptions.py:460 -msgid "Group password" +msgid "Group ID range start value attribute" msgstr "" #: src/config/SSSDConfig/sssdoptions.py:461 +msgid "Owner of an entry" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:463 +msgid "Base DN for group lookups" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:464 +msgid "Objectclass for groups" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:465 +msgid "Group name" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:466 +msgid "Group password" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:467 msgid "GID attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:462 +#: src/config/SSSDConfig/sssdoptions.py:468 msgid "Group member attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:463 +#: src/config/SSSDConfig/sssdoptions.py:469 msgid "Group UUID attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:465 +#: src/config/SSSDConfig/sssdoptions.py:471 msgid "Modification time attribute for groups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:466 +#: src/config/SSSDConfig/sssdoptions.py:472 msgid "Type of the group and other flags" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:467 +#: src/config/SSSDConfig/sssdoptions.py:473 msgid "The LDAP group external member attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:468 +#: src/config/SSSDConfig/sssdoptions.py:474 msgid "Maximum nesting level SSSD will follow" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:469 +#: src/config/SSSDConfig/sssdoptions.py:475 msgid "Filter for group lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:470 +#: src/config/SSSDConfig/sssdoptions.py:476 msgid "Scope of group lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:472 +#: src/config/SSSDConfig/sssdoptions.py:478 msgid "Base DN for netgroup lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:473 +#: src/config/SSSDConfig/sssdoptions.py:479 msgid "Objectclass for netgroups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:474 +#: src/config/SSSDConfig/sssdoptions.py:480 msgid "Netgroup name" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:475 +#: src/config/SSSDConfig/sssdoptions.py:481 msgid "Netgroups members attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:476 +#: src/config/SSSDConfig/sssdoptions.py:482 msgid "Netgroup triple attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:477 +#: src/config/SSSDConfig/sssdoptions.py:483 msgid "Modification time attribute for netgroups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:479 +#: src/config/SSSDConfig/sssdoptions.py:485 msgid "Base DN for service lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:480 +#: src/config/SSSDConfig/sssdoptions.py:486 msgid "Objectclass for services" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:481 +#: src/config/SSSDConfig/sssdoptions.py:487 msgid "Service name attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:482 +#: src/config/SSSDConfig/sssdoptions.py:488 msgid "Service port attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:483 +#: src/config/SSSDConfig/sssdoptions.py:489 msgid "Service protocol attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:485 +#: src/config/SSSDConfig/sssdoptions.py:491 msgid "Lower bound for ID-mapping" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:486 +#: src/config/SSSDConfig/sssdoptions.py:492 msgid "Upper bound for ID-mapping" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:487 +#: src/config/SSSDConfig/sssdoptions.py:493 msgid "Number of IDs for each slice when ID-mapping" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:488 +#: src/config/SSSDConfig/sssdoptions.py:494 msgid "Use autorid-compatible algorithm for ID-mapping" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:489 +#: src/config/SSSDConfig/sssdoptions.py:495 msgid "Name of the default domain for ID-mapping" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:490 +#: src/config/SSSDConfig/sssdoptions.py:496 msgid "SID of the default domain for ID-mapping" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:491 +#: src/config/SSSDConfig/sssdoptions.py:497 msgid "Number of secondary slices" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:493 +#: src/config/SSSDConfig/sssdoptions.py:499 msgid "Whether to use Token-Groups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:494 +#: src/config/SSSDConfig/sssdoptions.py:500 msgid "Set lower boundary for allowed IDs from the LDAP server" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:495 +#: src/config/SSSDConfig/sssdoptions.py:501 msgid "Set upper boundary for allowed IDs from the LDAP server" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:496 +#: src/config/SSSDConfig/sssdoptions.py:502 msgid "DN for ppolicy queries" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:497 +#: src/config/SSSDConfig/sssdoptions.py:503 msgid "How many maximum entries to fetch during a wildcard request" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:498 +#: src/config/SSSDConfig/sssdoptions.py:504 msgid "Set libldap debug level" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:501 +#: src/config/SSSDConfig/sssdoptions.py:507 msgid "Policy to evaluate the password expiration" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:505 +#: src/config/SSSDConfig/sssdoptions.py:511 msgid "Which attributes shall be used to evaluate if an account is expired" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:509 +#: src/config/SSSDConfig/sssdoptions.py:515 msgid "URI of an LDAP server where password changes are allowed" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:510 +#: src/config/SSSDConfig/sssdoptions.py:516 msgid "URI of a backup LDAP server where password changes are allowed" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:511 +#: src/config/SSSDConfig/sssdoptions.py:517 msgid "DNS service name for LDAP password change server" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:512 +#: src/config/SSSDConfig/sssdoptions.py:518 msgid "" "Whether to update the ldap_user_shadow_last_change attribute after a " "password change" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:516 +#: src/config/SSSDConfig/sssdoptions.py:522 msgid "Base DN for sudo rules lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:517 +#: src/config/SSSDConfig/sssdoptions.py:523 msgid "Automatic full refresh period" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:518 +#: src/config/SSSDConfig/sssdoptions.py:524 msgid "Automatic smart refresh period" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:519 +#: src/config/SSSDConfig/sssdoptions.py:525 msgid "Smart and full refresh random offset" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:520 +#: src/config/SSSDConfig/sssdoptions.py:526 msgid "Whether to filter rules by hostname, IP addresses and network" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:521 +#: src/config/SSSDConfig/sssdoptions.py:527 msgid "" "Hostnames and/or fully qualified domain names of this machine to filter sudo " "rules" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:522 +#: src/config/SSSDConfig/sssdoptions.py:528 msgid "IPv4 or IPv6 addresses or network of this machine to filter sudo rules" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:523 +#: src/config/SSSDConfig/sssdoptions.py:529 msgid "Whether to include rules that contains netgroup in host attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:524 +#: src/config/SSSDConfig/sssdoptions.py:530 msgid "" "Whether to include rules that contains regular expression in host attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:525 +#: src/config/SSSDConfig/sssdoptions.py:531 msgid "Object class for sudo rules" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:526 +#: src/config/SSSDConfig/sssdoptions.py:532 msgid "Name of attribute that is used as object class for sudo rules" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:527 +#: src/config/SSSDConfig/sssdoptions.py:533 msgid "Sudo rule name" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:528 +#: src/config/SSSDConfig/sssdoptions.py:534 msgid "Sudo rule command attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:529 +#: src/config/SSSDConfig/sssdoptions.py:535 msgid "Sudo rule host attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:530 +#: src/config/SSSDConfig/sssdoptions.py:536 msgid "Sudo rule user attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:531 +#: src/config/SSSDConfig/sssdoptions.py:537 msgid "Sudo rule option attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:532 +#: src/config/SSSDConfig/sssdoptions.py:538 msgid "Sudo rule runas attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:533 +#: src/config/SSSDConfig/sssdoptions.py:539 msgid "Sudo rule runasuser attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:534 +#: src/config/SSSDConfig/sssdoptions.py:540 msgid "Sudo rule runasgroup attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:535 +#: src/config/SSSDConfig/sssdoptions.py:541 msgid "Sudo rule notbefore attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:536 +#: src/config/SSSDConfig/sssdoptions.py:542 msgid "Sudo rule notafter attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:537 +#: src/config/SSSDConfig/sssdoptions.py:543 msgid "Sudo rule order attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:540 +#: src/config/SSSDConfig/sssdoptions.py:546 msgid "Object class for automounter maps" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:541 +#: src/config/SSSDConfig/sssdoptions.py:547 msgid "Automounter map name attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:542 +#: src/config/SSSDConfig/sssdoptions.py:548 msgid "Object class for automounter map entries" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:543 +#: src/config/SSSDConfig/sssdoptions.py:549 msgid "Automounter map entry key attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:544 +#: src/config/SSSDConfig/sssdoptions.py:550 msgid "Automounter map entry value attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:545 +#: src/config/SSSDConfig/sssdoptions.py:551 msgid "Base DN for automounter map lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:546 +#: src/config/SSSDConfig/sssdoptions.py:552 msgid "The name of the automount master map in LDAP." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:549 +#: src/config/SSSDConfig/sssdoptions.py:555 msgid "Base DN for IP hosts lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:550 +#: src/config/SSSDConfig/sssdoptions.py:556 msgid "Object class for IP hosts" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:551 +#: src/config/SSSDConfig/sssdoptions.py:557 msgid "IP host name attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:552 +#: src/config/SSSDConfig/sssdoptions.py:558 msgid "IP host number (address) attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:553 +#: src/config/SSSDConfig/sssdoptions.py:559 msgid "IP host entryUSN attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:554 +#: src/config/SSSDConfig/sssdoptions.py:560 msgid "Base DN for IP networks lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:555 +#: src/config/SSSDConfig/sssdoptions.py:561 msgid "Object class for IP networks" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:556 +#: src/config/SSSDConfig/sssdoptions.py:562 msgid "IP network name attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:557 +#: src/config/SSSDConfig/sssdoptions.py:563 msgid "IP network number (address) attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:558 +#: src/config/SSSDConfig/sssdoptions.py:564 msgid "IP network entryUSN attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:561 +#: src/config/SSSDConfig/sssdoptions.py:567 msgid "Comma separated list of allowed users" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:562 +#: src/config/SSSDConfig/sssdoptions.py:568 msgid "Comma separated list of prohibited users" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:563 +#: src/config/SSSDConfig/sssdoptions.py:569 msgid "" "Comma separated list of groups that are allowed to log in. This applies only " "to groups within this SSSD domain. Local groups are not evaluated." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:565 +#: src/config/SSSDConfig/sssdoptions.py:571 msgid "" "Comma separated list of groups that are explicitly denied access. This " "applies only to groups within this SSSD domain. Local groups are not " "evaluated." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:569 +#: src/config/SSSDConfig/sssdoptions.py:575 msgid "The number of preforked proxy children." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:572 +#: src/config/SSSDConfig/sssdoptions.py:578 msgid "The name of the NSS library to use" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:573 +#: src/config/SSSDConfig/sssdoptions.py:579 msgid "The name of the NSS library to use for hosts and networks lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:574 +#: src/config/SSSDConfig/sssdoptions.py:580 msgid "Whether to look up canonical group name from cache if possible" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:577 +#: src/config/SSSDConfig/sssdoptions.py:583 msgid "PAM stack to use" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:580 +#: src/config/SSSDConfig/sssdoptions.py:586 msgid "Path of passwd file sources." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:581 +#: src/config/SSSDConfig/sssdoptions.py:587 msgid "Path of group file sources." msgstr "" @@ -1880,225 +2063,233 @@ msgstr "" msgid "Option -i|--interactive is not allowed together with -D|--daemon\n" msgstr "" -#: src/monitor/monitor.c:1836 +#: src/monitor/monitor.c:1838 msgid "Failed to get initial capabilities\n" msgstr "" -#: src/monitor/monitor.c:1847 +#: src/monitor/monitor.c:1849 msgid "Non-root service user support isn't built. Can't run under %" msgstr "" -#: src/monitor/monitor.c:1864 +#: src/monitor/monitor.c:1866 #, c-format msgid "Can't read config: '%s'\n" msgstr "" -#: src/monitor/monitor.c:1876 +#: src/monitor/monitor.c:1878 #, c-format -msgid "Failed to boostrap SSSD 'monitor' process: %s" +msgid "Failed to bootstrap SSSD 'monitor' process: %s" msgstr "" -#: src/monitor/monitor.c:1971 +#: src/monitor/monitor.c:1973 msgid "Out of memory\n" msgstr "" -#: src/providers/krb5/krb5_child.c:4221 +#: src/providers/krb5/krb5_child.c:4316 msgid "Use anonymous PKINIT to request FAST armor ticket" msgstr "" -#: src/providers/krb5/krb5_child.c:4223 +#: src/providers/krb5/krb5_child.c:4318 msgid "Kerberos realm to use" msgstr "" -#: src/providers/krb5/krb5_child.c:4225 +#: src/providers/krb5/krb5_child.c:4320 msgid "Requested lifetime of the ticket" msgstr "" -#: src/providers/krb5/krb5_child.c:4227 +#: src/providers/krb5/krb5_child.c:4322 msgid "Requested renewable lifetime of the ticket" msgstr "" -#: src/providers/krb5/krb5_child.c:4229 +#: src/providers/krb5/krb5_child.c:4324 msgid "FAST options ('never', 'try', 'demand')" msgstr "" -#: src/providers/krb5/krb5_child.c:4232 +#: src/providers/krb5/krb5_child.c:4327 msgid "Specifies the server principal to use for FAST" msgstr "" -#: src/providers/krb5/krb5_child.c:4234 +#: src/providers/krb5/krb5_child.c:4329 msgid "Requests canonicalization of the principal name" msgstr "" -#: src/providers/krb5/krb5_child.c:4236 +#: src/providers/krb5/krb5_child.c:4331 msgid "Use custom version of krb5_get_init_creds_password" msgstr "" -#: src/providers/krb5/krb5_child.c:4238 +#: src/providers/krb5/krb5_child.c:4333 msgid "Check PAC flags" msgstr "" -#: src/providers/data_provider_be.c:790 +#: src/providers/krb5/krb5_child.c:4335 +msgid "Set environment variable (KEY=VALUE)" +msgstr "" + +#: src/providers/data_provider_be.c:786 msgid "Domain of the information provider (mandatory)" msgstr "" -#: src/sss_client/common.c:1165 +#: src/sss_client/common.c:1208 msgid "Socket has wrong ownership or permissions." msgstr "" -#: src/sss_client/common.c:1168 +#: src/sss_client/common.c:1211 msgid "Unexpected format of the server credential message." msgstr "" -#: src/sss_client/common.c:1171 +#: src/sss_client/common.c:1214 msgid "SSSD is not run by trusted user." msgstr "" -#: src/sss_client/common.c:1174 +#: src/sss_client/common.c:1217 msgid "SSSD socket does not exist." msgstr "" -#: src/sss_client/common.c:1177 +#: src/sss_client/common.c:1220 msgid "Cannot get stat of SSSD socket." msgstr "" -#: src/sss_client/common.c:1182 +#: src/sss_client/common.c:1225 msgid "An error occurred, but no description can be found." msgstr "" -#: src/sss_client/common.c:1188 +#: src/sss_client/common.c:1231 msgid "Unexpected error while looking for an error description" msgstr "" -#: src/sss_client/pam_sss.c:74 +#: src/sss_client/pam_sss.c:135 msgid "Permission denied. " msgstr "" -#: src/sss_client/pam_sss.c:75 src/sss_client/pam_sss.c:843 -#: src/sss_client/pam_sss.c:854 +#: src/sss_client/pam_sss.c:136 src/sss_client/pam_sss.c:921 +#: src/sss_client/pam_sss.c:932 msgid "Server message: " msgstr "" -#: src/sss_client/pam_sss.c:76 +#: src/sss_client/pam_sss.c:137 msgid "" "Kerberos TGT will not be granted upon login, user experience will be " "affected." msgstr "" -#: src/sss_client/pam_sss.c:77 +#: src/sss_client/pam_sss.c:138 msgid "Enter PIN:" msgstr "" -#: src/sss_client/pam_sss.c:320 +#: src/sss_client/pam_sss.c:385 msgid "Passwords do not match" msgstr "" -#: src/sss_client/pam_sss.c:508 +#: src/sss_client/pam_sss.c:584 msgid "Password reset by root is not supported." msgstr "" -#: src/sss_client/pam_sss.c:549 +#: src/sss_client/pam_sss.c:625 msgid "Authenticated with cached credentials" msgstr "" -#: src/sss_client/pam_sss.c:550 +#: src/sss_client/pam_sss.c:626 msgid ", your cached password will expire at: " msgstr "" -#: src/sss_client/pam_sss.c:580 +#: src/sss_client/pam_sss.c:656 #, c-format msgid "Your password has expired. You have %1$d grace login(s) remaining." msgstr "" -#: src/sss_client/pam_sss.c:630 +#: src/sss_client/pam_sss.c:706 #, c-format msgid "Your password will expire in %1$d %2$s." msgstr "" -#: src/sss_client/pam_sss.c:633 +#: src/sss_client/pam_sss.c:709 #, c-format msgid "Your password has expired." msgstr "" -#: src/sss_client/pam_sss.c:684 +#: src/sss_client/pam_sss.c:760 msgid "Authentication is denied until: " msgstr "" -#: src/sss_client/pam_sss.c:705 +#: src/sss_client/pam_sss.c:781 msgid "System is offline, password change not possible" msgstr "" -#: src/sss_client/pam_sss.c:720 +#: src/sss_client/pam_sss.c:796 msgid "" "After changing the OTP password, you need to log out and back in order to " "acquire a ticket" msgstr "" -#: src/sss_client/pam_sss.c:735 +#: src/sss_client/pam_sss.c:813 msgid "PIN locked" msgstr "" -#: src/sss_client/pam_sss.c:750 +#: src/sss_client/pam_sss.c:828 msgid "" "No Kerberos TGT granted as the server does not support this method. Your " "single-sign on(SSO) experience will be affected." msgstr "" -#: src/sss_client/pam_sss.c:840 src/sss_client/pam_sss.c:853 +#: src/sss_client/pam_sss.c:918 src/sss_client/pam_sss.c:931 msgid "Password change failed. " msgstr "" -#: src/sss_client/pam_sss.c:1859 +#: src/sss_client/pam_sss.c:2028 #, c-format -msgid "Authenticate at %1$s and press ENTER." +msgid "Authenticate at \"%1$s\"." msgstr "" -#: src/sss_client/pam_sss.c:1862 +#: src/sss_client/pam_sss.c:2031 #, c-format -msgid "Authenticate with PIN %1$s at %2$s and press ENTER." +msgid "Authenticate with PIN \"%1$s\" at \"%2$s\"." msgstr "" -#: src/sss_client/pam_sss.c:2281 +#: src/sss_client/pam_sss.c:2470 msgid "Please (re)insert (different) Smartcard" msgstr "" -#: src/sss_client/pam_sss.c:2482 +#: src/sss_client/pam_sss.c:2700 msgid "New Password: " msgstr "" -#: src/sss_client/pam_sss.c:2483 +#: src/sss_client/pam_sss.c:2701 msgid "Reenter new Password: " msgstr "" -#: src/sss_client/pam_sss.c:2676 src/sss_client/pam_sss.c:2679 +#: src/sss_client/pam_sss.c:2890 +msgid "Press ENTER to continue." +msgstr "" + +#: src/sss_client/pam_sss.c:2913 src/sss_client/pam_sss.c:2916 msgid "First Factor: " msgstr "" -#: src/sss_client/pam_sss.c:2677 src/sss_client/pam_sss.c:2851 +#: src/sss_client/pam_sss.c:2914 src/sss_client/pam_sss.c:3088 msgid "Second Factor (optional): " msgstr "" -#: src/sss_client/pam_sss.c:2680 src/sss_client/pam_sss.c:2855 +#: src/sss_client/pam_sss.c:2917 src/sss_client/pam_sss.c:3092 msgid "Second Factor: " msgstr "" -#: src/sss_client/pam_sss.c:2684 +#: src/sss_client/pam_sss.c:2921 msgid "Insert your passkey device, then press ENTER." msgstr "" -#: src/sss_client/pam_sss.c:2688 src/sss_client/pam_sss.c:2696 +#: src/sss_client/pam_sss.c:2925 src/sss_client/pam_sss.c:2933 msgid "Password: " msgstr "" -#: src/sss_client/pam_sss.c:2850 src/sss_client/pam_sss.c:2854 +#: src/sss_client/pam_sss.c:3087 src/sss_client/pam_sss.c:3091 msgid "First Factor (Current Password): " msgstr "" -#: src/sss_client/pam_sss.c:2874 +#: src/sss_client/pam_sss.c:3111 msgid "Current Password: " msgstr "" -#: src/sss_client/pam_sss.c:3248 +#: src/sss_client/pam_sss.c:3485 msgid "Password expired. Change your password now." msgstr "" @@ -2530,9 +2721,9 @@ msgstr "" #: src/tools/sssctl/sssctl_cache.c:835 src/tools/sssctl/sssctl_cache.c:918 #: src/tools/sssctl/sssctl_cache.c:950 src/tools/sssctl/sssctl_cache.c:956 #: src/tools/sssctl/sssctl_cache.c:1010 src/tools/sssctl/sssctl_cache.c:1034 -#: src/tools/sssctl/sssctl_cache.c:1085 src/tools/sssctl/sssctl_cache.c:1194 -#: src/tools/sssctl/sssctl_cache.c:1229 src/tools/sssctl/sssctl_cache.c:1235 -#: src/tools/sssctl/sssctl_cache.c:1244 +#: src/tools/sssctl/sssctl_cache.c:1085 src/tools/sssctl/sssctl_cache.c:1195 +#: src/tools/sssctl/sssctl_cache.c:1230 src/tools/sssctl/sssctl_cache.c:1236 +#: src/tools/sssctl/sssctl_cache.c:1245 msgid "talloc failed\n" msgstr "" @@ -2606,25 +2797,25 @@ msgstr "" msgid "Unable to remove downloaded GPO files: %s\n" msgstr "" -#: src/tools/sssctl/sssctl_cache.c:1165 +#: src/tools/sssctl/sssctl_cache.c:1166 #, c-format msgid "Failed to fetch cache entry: %s\n" msgstr "" -#: src/tools/sssctl/sssctl_cache.c:1170 +#: src/tools/sssctl/sssctl_cache.c:1171 msgid "Could not determine object domain\n" msgstr "" -#: src/tools/sssctl/sssctl_cache.c:1200 +#: src/tools/sssctl/sssctl_cache.c:1201 msgid "Could not find GUID attribute in GPO entry\n" msgstr "" -#: src/tools/sssctl/sssctl_cache.c:1206 +#: src/tools/sssctl/sssctl_cache.c:1207 #, c-format msgid "Failed to delete GPO: %s\n" msgstr "" -#: src/tools/sssctl/sssctl_cache.c:1210 +#: src/tools/sssctl/sssctl_cache.c:1211 #, c-format msgid "%s removed from cache\n" msgstr "" @@ -2712,39 +2903,39 @@ msgid "" "\"/my/path/sssd.conf\", the snippet dir \"/my/path/conf.d\" is used)" msgstr "" -#: src/tools/sssctl/sssctl_config.c:114 +#: src/tools/sssctl/sssctl_config.c:126 #, c-format msgid "File %1$s does not exist.\n" msgstr "" -#: src/tools/sssctl/sssctl_config.c:115 +#: src/tools/sssctl/sssctl_config.c:127 msgid "There is no configuration.\n" msgstr "" -#: src/tools/sssctl/sssctl_config.c:120 +#: src/tools/sssctl/sssctl_config.c:132 #, c-format msgid "Configuration validation failed: %s\n" msgstr "" -#: src/tools/sssctl/sssctl_config.c:121 +#: src/tools/sssctl/sssctl_config.c:133 msgid "Run with high debug level to see details.\n" msgstr "" -#: src/tools/sssctl/sssctl_config.c:130 -msgid "Failed to run validators" +#: src/tools/sssctl/sssctl_config.c:142 +msgid "Failed to run validators\n" msgstr "" -#: src/tools/sssctl/sssctl_config.c:134 +#: src/tools/sssctl/sssctl_config.c:146 #, c-format msgid "Issues identified by validators: %zu\n" msgstr "" -#: src/tools/sssctl/sssctl_config.c:145 +#: src/tools/sssctl/sssctl_config.c:157 #, c-format msgid "Messages generated during configuration merging: %zu\n" msgstr "" -#: src/tools/sssctl/sssctl_config.c:158 +#: src/tools/sssctl/sssctl_config.c:170 #, c-format msgid "Used configuration snippet files: %zu\n" msgstr "" diff --git a/po/ro.po b/po/ro.po new file mode 100644 index 00000000000..cb468417bab --- /dev/null +++ b/po/ro.po @@ -0,0 +1,3287 @@ +# SOME DESCRIPTIVE TITLE. +# Copyright (C) YEAR Red Hat, Inc. +# This file is distributed under the same license as the PACKAGE package. +# Rafael Fontenelle , 2026. +msgid "" +msgstr "" +"Project-Id-Version: PACKAGE VERSION\n" +"Report-Msgid-Bugs-To: sssd-devel@lists.fedorahosted.org\n" +"POT-Creation-Date: 2026-10-02 15:57+0000\n" +"PO-Revision-Date: 2026-10-05 17:26+0000\n" +"Last-Translator: Anonymous \n" +"Language-Team: Romanian \n" +"Language: ro\n" +"MIME-Version: 1.0\n" +"Content-Type: text/plain; charset=UTF-8\n" +"Content-Transfer-Encoding: 8bit\n" +"Plural-Forms: nplurals=3; plural=n==1 ? 0 : (n==0 || (n%100 > 0 && n%100 < " +"20)) ? 1 : 2;\n" +"X-Generator: Weblate 2026.10\n" + +#: src/config/SSSDConfig/sssdoptions.py:16 +#: src/config/SSSDConfig/sssdoptions.py:17 +msgid "Set the verbosity of the debug logging" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:18 +msgid "Include timestamps in debug logs" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:19 +msgid "Include microseconds in timestamps in debug logs" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:20 +msgid "Enable/disable debug backtrace" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:21 +msgid "Watchdog timeout before restarting service" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:22 +msgid "Command to start service" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:23 +msgid "The number of file descriptors that may be opened by this responder" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:24 +msgid "Idle time before automatic disconnection of a client" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:25 +msgid "Idle time before automatic shutdown of the responder" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:26 +msgid "Always query all the caches before querying the Data Providers" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:27 +msgid "" +"When SSSD switches to offline mode the amount of time before it tries to go " +"back online will increase based upon the time spent disconnected. This value " +"is in seconds and calculated by the following: offline_timeout + " +"random_offset." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:32 +msgid "SSSD Services to start" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:33 +msgid "SSSD Domains to start" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:34 +msgid "Regex to parse username and domain" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:35 +msgid "Printf-compatible format for displaying fully-qualified names" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:36 +msgid "" +"Directory on the filesystem where SSSD should store Kerberos replay cache " +"files." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:37 +msgid "Domain to add to names without a domain component." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:38 +msgid "The user to drop privileges to" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:39 +msgid "Tune certificate verification" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:40 +msgid "All spaces in group or user names will be replaced with this character" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:41 +msgid "Tune sssd to honor or ignore netlink state changes" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:42 +msgid "Enable or disable the implicit files domain" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:43 +msgid "A specific order of the domains to be looked up" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:44 +msgid "" +"Controls if SSSD should monitor the state of resolv.conf to identify when it " +"needs to update its internal DNS resolver." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:46 +msgid "" +"SSSD monitors the state of resolv.conf to identify when it needs to update " +"its internal DNS resolver. By default, we will attempt to use inotify for " +"this, and will fall back to polling resolv.conf every five seconds if " +"inotify cannot be used." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:49 +msgid "Run PAC responder automatically for AD and IPA provider" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:50 +msgid "Enable or disable core dumps for all SSSD processes." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:51 +msgid "Tune passkey verification behavior" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:54 +msgid "Enumeration cache timeout length (seconds)" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:55 +msgid "Entry cache background update timeout length (seconds)" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:56 +#: src/config/SSSDConfig/sssdoptions.py:124 +msgid "Negative cache timeout length (seconds)" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:57 +msgid "Users that SSSD should explicitly ignore" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:58 +msgid "Groups that SSSD should explicitly ignore" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:59 +msgid "Should filtered users appear in groups" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:60 +msgid "The value of the password field the NSS provider should return" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:61 +msgid "Override homedir value from the identity provider with this value" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:62 +msgid "" +"Substitute empty homedir value from the identity provider with this value" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:63 +msgid "Override shell value from the identity provider with this value" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:64 +msgid "The list of shells users are allowed to log in with" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:65 +msgid "" +"The list of shells that will be vetoed, and replaced with the fallback shell" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:66 +msgid "" +"If a shell stored in central directory is allowed but not available, use " +"this fallback" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:67 +msgid "Shell to use if the provider does not list one" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:68 +msgid "How long will be in-memory cache records valid" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:70 +msgid "" +"Size (in megabytes) of the data table allocated inside fast in-memory cache " +"for passwd requests" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:72 +msgid "" +"Size (in megabytes) of the data table allocated inside fast in-memory cache " +"for group requests" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:74 +msgid "" +"Size (in megabytes) of the data table allocated inside fast in-memory cache " +"for initgroups requests" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:75 +msgid "" +"The value of this option will be used in the expansion of the " +"override_homedir option if the template contains the format string %H." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:77 +msgid "" +"Specifies time in seconds for which the list of subdomains will be " +"considered valid." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:79 +msgid "" +"The entry cache can be set to automatically update entries in the background " +"if they are requested beyond a percentage of the entry_cache_timeout value " +"for the domain." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:84 +msgid "How long to allow cached logins between online logins (days)" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:85 +msgid "How many failed logins attempts are allowed when offline" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:87 +msgid "" +"How long (minutes) to deny login after offline_failed_login_attempts has " +"been reached" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:88 +msgid "What kind of messages are displayed to the user during authentication" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:89 +msgid "Filter PAM responses sent to the pam_sss" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:90 +msgid "How many seconds to keep identity information cached for PAM requests" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:91 +msgid "How many days before password expiration a warning should be displayed" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:92 +msgid "List of trusted uids or user's name" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:93 +msgid "List of domains accessible even for untrusted users." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:94 +msgid "Message printed when user account is expired." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:95 +msgid "Message printed when user account is locked." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:96 +msgid "Allow certificate based/Smartcard authentication." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:97 +msgid "Path to certificate database with PKCS#11 modules." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:98 +msgid "Tune certificate verification for PAM authentication." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:99 +msgid "How many seconds will pam_sss wait for p11_child to finish" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:100 +msgid "Which PAM services are permitted to contact application domains" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:101 +msgid "Allowed services for using smartcards" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:102 +msgid "Additional timeout to wait for a card if requested" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:103 +msgid "" +"PKCS#11 URI to restrict the selection of devices for Smartcard authentication" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:104 +msgid "When shall the PAM responder force an initgroups request" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:105 +msgid "List of PAM services that are allowed to authenticate with GSSAPI." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:106 +msgid "Whether to match authenticated UPN with target user" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:107 +msgid "" +"List of pairs : that must be enforced " +"for PAM access with GSSAPI authentication" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:109 +msgid "" +"List of triples :: that assigns " +"additional information from the Kerberos ticket to an authentication " +"indicator." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:112 +msgid "Allow passkey device authentication." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:113 +msgid "How many seconds will pam_sss wait for passkey_child to finish" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:114 +msgid "Enable debugging in the libfido2 library" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:115 +msgid "Enable JSON protocol for authentication methods selection." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:118 +msgid "Whether to evaluate the time-based attributes in sudo rules" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:119 +msgid "If true, SSSD will switch back to lower-wins ordering logic" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:120 +msgid "" +"Maximum number of rules that can be refreshed at once. If this is exceeded, " +"full refresh is performed." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:127 +msgid "Whether to hash host names and addresses in the known_hosts file" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:128 +msgid "" +"How many seconds to keep a host in the known_hosts file after its host keys " +"were requested" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:130 +msgid "Path to storage of trusted CA certificates" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:131 +msgid "Allow to generate ssh-keys from certificates" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:132 +msgid "" +"Use the following matching rules to filter the certificates for ssh-key " +"generation" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:136 +msgid "List of UIDs or user names allowed to access the PAC responder" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:137 +msgid "How long the PAC data is considered valid" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:138 +msgid "Validate the PAC" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:141 +msgid "List of user attributes the InfoPipe is allowed to publish" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:144 +msgid "" +"One of the following strings specifying the scope of session recording: none " +"- No users are recorded. some - Users/groups specified by users and groups " +"options are recorded. all - All users are recorded." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:147 +msgid "" +"A comma-separated list of users which should have session recording enabled. " +"Matches user names as returned by NSS. I.e. after the possible space " +"replacement, case changes, etc." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:149 +msgid "" +"A comma-separated list of groups, members of which should have session " +"recording enabled. Matches group names as returned by NSS. I.e. after the " +"possible space replacement, case changes, etc." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:152 +msgid "" +"A comma-separated list of users to be excluded from recording, only when " +"scope=all" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:153 +msgid "" +"A comma-separated list of groups, members of which should be excluded from " +"recording, only when scope=all. " +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:157 +msgid "Identity provider" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:158 +msgid "Authentication provider" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:159 +msgid "Access control provider" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:160 +msgid "Password change provider" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:161 +msgid "SUDO provider" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:162 +msgid "Autofs provider" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:163 +msgid "Host identity provider" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:164 +msgid "SELinux provider" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:165 +msgid "Session management provider" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:166 +msgid "Resolver provider" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:169 +msgid "Whether the domain is usable by the OS or by applications" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:170 +msgid "Enable or disable the domain" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:171 +msgid "Minimum user ID" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:172 +msgid "Maximum user ID" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:173 +msgid "Enable enumerating all users/groups" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:174 +msgid "Cache credentials for offline login" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:175 +msgid "Display users/groups in fully-qualified form" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:176 +msgid "Don't include group members in group lookups" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:177 +#: src/config/SSSDConfig/sssdoptions.py:190 +#: src/config/SSSDConfig/sssdoptions.py:191 +#: src/config/SSSDConfig/sssdoptions.py:192 +#: src/config/SSSDConfig/sssdoptions.py:193 +#: src/config/SSSDConfig/sssdoptions.py:194 +#: src/config/SSSDConfig/sssdoptions.py:195 +#: src/config/SSSDConfig/sssdoptions.py:196 +msgid "Entry cache timeout length (seconds)" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:178 +msgid "" +"Restrict or prefer a specific address family when performing DNS lookups" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:179 +msgid "How long to keep cached entries after last successful login (days)" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:180 +msgid "" +"How long should SSSD talk to single DNS server before trying next server " +"(miliseconds)" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:182 +msgid "How long should keep trying to resolve single DNS query (seconds)" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:183 +msgid "How long to wait for replies from DNS when resolving servers (seconds)" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:184 +msgid "The domain part of service discovery DNS query" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:185 +msgid "" +"Specifies the interval, in seconds, that SSSD waits before attempting to " +"reconnect to the primary server after a successful connection to the backup " +"server" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:187 +msgid "Override GID value from the identity provider with this value" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:188 +msgid "Treat usernames as case sensitive" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:189 +msgid "Lookups by ID are expensive or do not work at all" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:197 +msgid "How often should expired entries be refreshed in background" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:198 +msgid "Maximum period deviation when refreshing expired entries in background" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:199 +msgid "Whether to automatically update the client's DNS entry" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:200 +msgid "" +"Whether DNS update of A and AAAA record should be performed in one update or " +"in two separate updates" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:202 +msgid "The TTL to apply to the client's DNS entry after updating it" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:203 +msgid "The interface whose IP should be used for dynamic DNS updates" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:204 +msgid "The list of IP addresses that should be used for dynamic DNS updates" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:205 +msgid "How often to periodically update the client's DNS entry" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:206 +msgid "Maximum period deviation when updating the client's DNS entry" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:207 +msgid "Whether the provider should explicitly update the PTR record as well" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:208 +msgid "Whether the nsupdate utility should default to using TCP" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:209 +msgid "What kind of authentication should be used to perform the DNS update" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:210 +msgid "Override the DNS server used to perform the DNS update" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:211 +msgid "The file of the certificate authorities certificates for DoT" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:212 +msgid "The certificate(s) file for authentication for the DoT transport" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:213 +msgid "The key file for authenticated encryption for the DoT transport" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:214 +msgid "How often should subdomains list be refreshed" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:215 +msgid "Maximum period deviation when refreshing the subdomain list" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:216 +msgid "List of options that should be inherited into a subdomain" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:217 +msgid "Default subdomain homedir value" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:218 +msgid "How long can cached credentials be used for cached authentication" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:219 +msgid "Whether to automatically create private groups for users" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:220 +msgid "Display a warning N days before the password expires." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:221 +msgid "" +"Various tags stored by the realmd configuration service for this domain." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:222 +msgid "" +"The provider which should handle fetching of subdomains. This value should " +"be always the same as id_provider." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:224 +msgid "" +"How many seconds to keep a host ssh key after refresh. IE how long to cache " +"the host key for." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:226 +msgid "" +"If 2-Factor-Authentication (2FA) is used and credentials should be saved " +"this value determines the minimal length the first authentication factor " +"(long term password) must have to be saved as SHA512 hash into the cache." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:230 +msgid "Local authentication methods policy " +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:233 +msgid "IPA domain" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:234 +msgid "IPA server address" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:235 +msgid "Address of backup IPA server" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:236 +msgid "IPA client hostname" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:237 +msgid "Search base for HBAC related objects" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:238 +msgid "" +"The amount of time between lookups of the HBAC rules against the IPA server" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:239 +msgid "" +"The amount of time in seconds between lookups of the SELinux maps against " +"the IPA server" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:241 +msgid "If set to false, host argument given by PAM will be ignored" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:242 +msgid "The automounter location this IPA client is using" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:243 +msgid "Search base for object containing info about IPA domain" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:244 +msgid "Search base for objects containing info about ID ranges" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:245 +msgid "Search base for view containers" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:246 +msgid "Objectclass for view containers" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:247 +msgid "Attribute with the name of the view" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:248 +msgid "Objectclass for override objects" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:249 +msgid "Attribute with the reference to the original object" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:250 +msgid "Objectclass for user override objects" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:251 +msgid "Objectclass for group override objects" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:252 +msgid "Search base for Desktop Profile related objects" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:253 +msgid "" +"The amount of time in seconds between lookups of the Desktop Profile rules " +"against the IPA server" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:255 +msgid "" +"The amount of time in minutes between lookups of Desktop Profiles rules " +"against the IPA server when the last request did not find any rule" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:258 +#: src/config/SSSDConfig/sssdoptions.py:455 +msgid "Search base for SUBID ranges" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:259 +#: src/config/SSSDConfig/sssdoptions.py:512 +msgid "Which rules should be used to evaluate access control" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:260 +msgid "The LDAP attribute that contains FQDN of the host." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:261 +#: src/config/SSSDConfig/sssdoptions.py:284 +msgid "The object class of a host entry in LDAP." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:262 +msgid "Use the given string as search base for host objects." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:263 +msgid "The LDAP attribute that contains the host's SSH public keys." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:264 +msgid "The LDAP attribute that contains NIS domain name of the netgroup." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:265 +msgid "The LDAP attribute that contains the names of the netgroup's members." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:266 +msgid "" +"The LDAP attribute that lists FQDNs of hosts and host groups that are " +"members of the netgroup." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:268 +msgid "" +"The LDAP attribute that lists hosts and host groups that are direct members " +"of the netgroup." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:270 +msgid "The LDAP attribute that lists netgroup's memberships." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:271 +msgid "" +"The LDAP attribute that lists system users and groups that are direct " +"members of the netgroup." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:273 +msgid "The LDAP attribute that corresponds to the netgroup name." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:274 +msgid "The object class of a netgroup entry in LDAP." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:275 +msgid "" +"The LDAP attribute that contains the UUID/GUID of an LDAP netgroup object." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:276 +msgid "" +"The LDAP attribute that contains whether or not is user map enabled for " +"usage." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:278 +msgid "The LDAP attribute that contains host category such as 'all'." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:279 +msgid "" +"The LDAP attribute that contains all hosts / hostgroups this rule match " +"against." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:281 +msgid "" +"The LDAP attribute that contains all users / groups this rule match against." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:283 +msgid "The LDAP attribute that contains the name of SELinux usermap." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:285 +msgid "" +"The LDAP attribute that contains DN of HBAC rule which can be used for " +"matching instead of memberUser and memberHost." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:287 +msgid "The LDAP attribute that contains SELinux user string itself." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:288 +msgid "The LDAP attribute that contains user category such as 'all'." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:289 +msgid "The LDAP attribute that contains unique ID of the user map." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:290 +msgid "" +"The option denotes that the SSSD is running on IPA server and should perform " +"lookups of users and groups from trusted domains differently." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:292 +msgid "Use the given string as search base for trusted domains." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:295 +msgid "Active Directory domain" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:296 +msgid "Enabled Active Directory domains" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:297 +msgid "Active Directory server address" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:298 +msgid "Active Directory backup server address" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:299 +msgid "Active Directory client hostname" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:300 +msgid "Enable DNS sites - location based service discovery" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:301 +#: src/config/SSSDConfig/sssdoptions.py:510 +msgid "LDAP filter to determine access privileges" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:302 +msgid "Whether to use the Global Catalog for lookups" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:303 +msgid "Operation mode for GPO-based access control" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:304 +msgid "" +"The amount of time between lookups of the GPO policy files against the AD " +"server" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:305 +msgid "" +"PAM service names that map to the GPO (Deny)InteractiveLogonRight policy " +"settings" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:307 +msgid "" +"PAM service names that map to the GPO (Deny)RemoteInteractiveLogonRight " +"policy settings" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:309 +msgid "" +"PAM service names that map to the GPO (Deny)NetworkLogonRight policy settings" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:310 +msgid "" +"PAM service names that map to the GPO (Deny)BatchLogonRight policy settings" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:311 +msgid "" +"PAM service names that map to the GPO (Deny)ServiceLogonRight policy settings" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:312 +msgid "PAM service names for which GPO-based access is always granted" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:313 +msgid "PAM service names for which GPO-based access is always denied" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:314 +msgid "" +"Default logon right (or permit/deny) to use for unmapped PAM service names" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:315 +msgid "a particular site to be used by the client" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:316 +msgid "" +"Maximum age in days before the machine account password should be renewed" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:318 +msgid "Option for tuning the machine account renewal task" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:319 +msgid "Whether to update the machine account password in the Samba database" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:321 +msgid "Use LDAPS port for LDAP and Global Catalog requests" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:324 +#: src/config/SSSDConfig/sssdoptions.py:325 +msgid "Kerberos server address" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:326 +msgid "Kerberos backup server address" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:327 +msgid "Kerberos realm" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:328 +msgid "Authentication timeout" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:329 +msgid "Whether to create kdcinfo files" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:330 +msgid "Where to drop krb5 config snippets" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:333 +msgid "Directory to store credential caches" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:334 +msgid "Location of the user's credential cache" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:335 +msgid "Location of the keytab to validate credentials" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:336 +msgid "Enable credential validation" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:337 +msgid "Store password if offline for later online authentication" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:338 +msgid "Renewable lifetime of the TGT" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:339 +msgid "Lifetime of the TGT" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:340 +msgid "Time between two checks for renewal" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:341 +msgid "Enables FAST" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:342 +msgid "Selects the principal to use for FAST" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:343 +msgid "Use anonymous PKINIT to request FAST credentials" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:344 +msgid "Enables principal canonicalization" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:345 +msgid "Enables enterprise principals" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:346 +msgid "Enables using of subdomains realms for authentication" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:347 +msgid "A mapping from user names to Kerberos principal names" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:350 +#: src/config/SSSDConfig/sssdoptions.py:351 +msgid "Server where the change password service is running if not on the KDC" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:354 +msgid "ldap_uri, The URI of the LDAP server" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:355 +msgid "ldap_backup_uri, The URI of the LDAP server" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:356 +msgid "The default base DN" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:357 +msgid "How to read rootDSE from LDAP server" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:358 +msgid "The Schema Type in use on the LDAP server, rfc2307" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:359 +msgid "Mode used to change user password" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:360 +msgid "The default bind DN" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:361 +msgid "The type of the authentication token of the default bind DN" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:362 +msgid "The authentication token of the default bind DN" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:363 +msgid "Length of time to attempt connection" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:364 +msgid "Length of time to attempt synchronous LDAP operations" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:365 +msgid "Length of time between attempts to reconnect while offline" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:366 +msgid "Use only the upper case for realm names" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:367 +msgid "File that contains CA certificates" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:368 +msgid "Path to CA certificate directory" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:369 +msgid "File that contains the client certificate" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:370 +msgid "File that contains the client key" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:371 +msgid "List of possible ciphers suites" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:372 +msgid "Require TLS certificate verification" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:373 +msgid "Specify the sasl mechanism to use" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:374 +msgid "Specify the sasl authorization id to use" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:375 +msgid "Specify the sasl authorization realm to use" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:376 +msgid "Specify the minimal SSF for LDAP sasl authorization" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:377 +msgid "Specify the maximal SSF for LDAP sasl authorization" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:378 +msgid "Kerberos service keytab" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:379 +msgid "Use Kerberos auth for LDAP connection" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:380 +msgid "Follow LDAP referrals" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:381 +msgid "Lifetime of TGT for LDAP connection" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:382 +msgid "How to dereference aliases" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:383 +msgid "Service name for DNS service lookups" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:384 +msgid "The number of records to retrieve in a single LDAP query" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:385 +msgid "The number of members that must be missing to trigger a full deref" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:386 +msgid "Ignore unreadable LDAP references" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:387 +msgid "" +"Whether the LDAP library should perform a reverse lookup to canonicalize the " +"host name during a SASL bind" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:389 +msgid "" +"Allows to retain local users as members of an LDAP group for servers that " +"use the RFC2307 schema." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:392 +msgid "entryUSN attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:393 +msgid "lastUSN attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:395 +msgid "How long to retain a connection to the LDAP server before disconnecting" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:398 +msgid "Disable the LDAP paging control" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:399 +msgid "Disable Active Directory range retrieval" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:400 +msgid "Use the ppolicy extension" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:401 +msgid "" +"Force a password change when remaining grace logins reach or go below this " +"threshold" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:404 +msgid "Length of time to wait for a search request" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:405 +msgid "Length of time to wait for a enumeration request" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:406 +msgid "Length of time between enumeration updates" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:407 +msgid "Maximum period deviation between enumeration updates" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:408 +msgid "Length of time between cache cleanups" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:409 +msgid "Maximum time deviation between cache cleanups" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:410 +msgid "Require TLS for ID lookups" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:411 +msgid "Use ID-mapping of objectSID instead of pre-set IDs" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:412 +msgid "Base DN for user lookups" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:413 +msgid "Scope of user lookups" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:414 +msgid "Filter for user lookups" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:415 +msgid "Objectclass for users" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:416 +msgid "Username attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:417 +msgid "UID attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:418 +msgid "Primary GID attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:419 +msgid "GECOS attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:420 +msgid "Home directory attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:421 +msgid "Shell attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:422 +msgid "UUID attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:423 +#: src/config/SSSDConfig/sssdoptions.py:470 +msgid "objectSID attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:424 +msgid "Active Directory primary group attribute for ID-mapping" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:425 +msgid "User principal attribute (for Kerberos)" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:426 +msgid "Full Name" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:427 +msgid "memberOf attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:428 +msgid "Modification time attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:429 +msgid "shadowLastChange attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:430 +msgid "shadowMin attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:431 +msgid "shadowMax attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:432 +msgid "shadowWarning attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:433 +msgid "shadowInactive attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:434 +msgid "shadowExpire attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:435 +msgid "shadowFlag attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:436 +msgid "Attribute listing authorized PAM services" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:437 +msgid "Attribute listing authorized server hosts" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:438 +msgid "Attribute listing authorized server rhosts" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:439 +msgid "krbLastPwdChange attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:440 +msgid "krbPasswordExpiration attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:441 +msgid "Attribute indicating that server side password policies are active" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:442 +msgid "accountExpires attribute of AD" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:443 +msgid "userAccountControl attribute of AD" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:444 +msgid "nsAccountLock attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:445 +msgid "loginDisabled attribute of NDS" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:446 +msgid "loginExpirationTime attribute of NDS" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:447 +msgid "loginAllowedTimeMap attribute of NDS" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:448 +msgid "SSH public key attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:449 +msgid "attribute listing allowed authentication types for a user" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:450 +msgid "attribute containing the X509 certificate of the user" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:451 +msgid "attribute containing the email address of the user" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:452 +msgid "attribute containing the passkey mapping data of the user" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:453 +msgid "A list of extra attributes to download along with the user entry" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:456 +msgid "The object class of an subid entry in LDAP." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:457 +msgid "Subordinate user ID count attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:458 +msgid "Subordinate group ID count attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:459 +msgid "User ID range start value attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:460 +msgid "Group ID range start value attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:461 +msgid "Owner of an entry" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:463 +msgid "Base DN for group lookups" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:464 +msgid "Objectclass for groups" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:465 +msgid "Group name" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:466 +msgid "Group password" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:467 +msgid "GID attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:468 +msgid "Group member attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:469 +msgid "Group UUID attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:471 +msgid "Modification time attribute for groups" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:472 +msgid "Type of the group and other flags" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:473 +msgid "The LDAP group external member attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:474 +msgid "Maximum nesting level SSSD will follow" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:475 +msgid "Filter for group lookups" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:476 +msgid "Scope of group lookups" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:478 +msgid "Base DN for netgroup lookups" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:479 +msgid "Objectclass for netgroups" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:480 +msgid "Netgroup name" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:481 +msgid "Netgroups members attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:482 +msgid "Netgroup triple attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:483 +msgid "Modification time attribute for netgroups" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:485 +msgid "Base DN for service lookups" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:486 +msgid "Objectclass for services" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:487 +msgid "Service name attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:488 +msgid "Service port attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:489 +msgid "Service protocol attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:491 +msgid "Lower bound for ID-mapping" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:492 +msgid "Upper bound for ID-mapping" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:493 +msgid "Number of IDs for each slice when ID-mapping" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:494 +msgid "Use autorid-compatible algorithm for ID-mapping" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:495 +msgid "Name of the default domain for ID-mapping" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:496 +msgid "SID of the default domain for ID-mapping" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:497 +msgid "Number of secondary slices" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:499 +msgid "Whether to use Token-Groups" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:500 +msgid "Set lower boundary for allowed IDs from the LDAP server" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:501 +msgid "Set upper boundary for allowed IDs from the LDAP server" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:502 +msgid "DN for ppolicy queries" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:503 +msgid "How many maximum entries to fetch during a wildcard request" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:504 +msgid "Set libldap debug level" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:507 +msgid "Policy to evaluate the password expiration" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:511 +msgid "Which attributes shall be used to evaluate if an account is expired" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:515 +msgid "URI of an LDAP server where password changes are allowed" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:516 +msgid "URI of a backup LDAP server where password changes are allowed" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:517 +msgid "DNS service name for LDAP password change server" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:518 +msgid "" +"Whether to update the ldap_user_shadow_last_change attribute after a " +"password change" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:522 +msgid "Base DN for sudo rules lookups" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:523 +msgid "Automatic full refresh period" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:524 +msgid "Automatic smart refresh period" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:525 +msgid "Smart and full refresh random offset" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:526 +msgid "Whether to filter rules by hostname, IP addresses and network" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:527 +msgid "" +"Hostnames and/or fully qualified domain names of this machine to filter sudo " +"rules" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:528 +msgid "IPv4 or IPv6 addresses or network of this machine to filter sudo rules" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:529 +msgid "Whether to include rules that contains netgroup in host attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:530 +msgid "" +"Whether to include rules that contains regular expression in host attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:531 +msgid "Object class for sudo rules" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:532 +msgid "Name of attribute that is used as object class for sudo rules" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:533 +msgid "Sudo rule name" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:534 +msgid "Sudo rule command attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:535 +msgid "Sudo rule host attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:536 +msgid "Sudo rule user attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:537 +msgid "Sudo rule option attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:538 +msgid "Sudo rule runas attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:539 +msgid "Sudo rule runasuser attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:540 +msgid "Sudo rule runasgroup attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:541 +msgid "Sudo rule notbefore attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:542 +msgid "Sudo rule notafter attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:543 +msgid "Sudo rule order attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:546 +msgid "Object class for automounter maps" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:547 +msgid "Automounter map name attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:548 +msgid "Object class for automounter map entries" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:549 +msgid "Automounter map entry key attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:550 +msgid "Automounter map entry value attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:551 +msgid "Base DN for automounter map lookups" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:552 +msgid "The name of the automount master map in LDAP." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:555 +msgid "Base DN for IP hosts lookups" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:556 +msgid "Object class for IP hosts" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:557 +msgid "IP host name attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:558 +msgid "IP host number (address) attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:559 +msgid "IP host entryUSN attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:560 +msgid "Base DN for IP networks lookups" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:561 +msgid "Object class for IP networks" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:562 +msgid "IP network name attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:563 +msgid "IP network number (address) attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:564 +msgid "IP network entryUSN attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:567 +msgid "Comma separated list of allowed users" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:568 +msgid "Comma separated list of prohibited users" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:569 +msgid "" +"Comma separated list of groups that are allowed to log in. This applies only " +"to groups within this SSSD domain. Local groups are not evaluated." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:571 +msgid "" +"Comma separated list of groups that are explicitly denied access. This " +"applies only to groups within this SSSD domain. Local groups are not " +"evaluated." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:575 +msgid "The number of preforked proxy children." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:578 +msgid "The name of the NSS library to use" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:579 +msgid "The name of the NSS library to use for hosts and networks lookups" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:580 +msgid "Whether to look up canonical group name from cache if possible" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:583 +msgid "PAM stack to use" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:586 +msgid "Path of passwd file sources." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:587 +msgid "Path of group file sources." +msgstr "" + +#: src/monitor/monitor.c:1757 +msgid "Become a daemon (default)" +msgstr "" + +#: src/monitor/monitor.c:1759 +msgid "Run interactive (not a daemon)" +msgstr "" + +#: src/monitor/monitor.c:1761 +msgid "Print version number and exit" +msgstr "" + +#: src/monitor/monitor.c:1772 +#, c-format +msgid "" +"\n" +"Invalid option %s: %s\n" +"\n" +msgstr "" + +#: src/monitor/monitor.c:1794 +msgid "Option -i|--interactive is not allowed together with -D|--daemon\n" +msgstr "" + +#: src/monitor/monitor.c:1838 +msgid "Failed to get initial capabilities\n" +msgstr "" + +#: src/monitor/monitor.c:1849 +msgid "Non-root service user support isn't built. Can't run under %" +msgstr "" + +#: src/monitor/monitor.c:1866 +#, c-format +msgid "Can't read config: '%s'\n" +msgstr "" + +#: src/monitor/monitor.c:1878 +#, c-format +msgid "Failed to bootstrap SSSD 'monitor' process: %s" +msgstr "" + +#: src/monitor/monitor.c:1973 +msgid "Out of memory\n" +msgstr "" + +#: src/providers/krb5/krb5_child.c:4316 +msgid "Use anonymous PKINIT to request FAST armor ticket" +msgstr "" + +#: src/providers/krb5/krb5_child.c:4318 +msgid "Kerberos realm to use" +msgstr "" + +#: src/providers/krb5/krb5_child.c:4320 +msgid "Requested lifetime of the ticket" +msgstr "" + +#: src/providers/krb5/krb5_child.c:4322 +msgid "Requested renewable lifetime of the ticket" +msgstr "" + +#: src/providers/krb5/krb5_child.c:4324 +msgid "FAST options ('never', 'try', 'demand')" +msgstr "" + +#: src/providers/krb5/krb5_child.c:4327 +msgid "Specifies the server principal to use for FAST" +msgstr "" + +#: src/providers/krb5/krb5_child.c:4329 +msgid "Requests canonicalization of the principal name" +msgstr "" + +#: src/providers/krb5/krb5_child.c:4331 +msgid "Use custom version of krb5_get_init_creds_password" +msgstr "" + +#: src/providers/krb5/krb5_child.c:4333 +msgid "Check PAC flags" +msgstr "" + +#: src/providers/krb5/krb5_child.c:4335 +msgid "Set environment variable (KEY=VALUE)" +msgstr "" + +#: src/providers/data_provider_be.c:786 +msgid "Domain of the information provider (mandatory)" +msgstr "" + +#: src/sss_client/common.c:1208 +msgid "Socket has wrong ownership or permissions." +msgstr "" + +#: src/sss_client/common.c:1211 +msgid "Unexpected format of the server credential message." +msgstr "" + +#: src/sss_client/common.c:1214 +msgid "SSSD is not run by trusted user." +msgstr "" + +#: src/sss_client/common.c:1217 +msgid "SSSD socket does not exist." +msgstr "" + +#: src/sss_client/common.c:1220 +msgid "Cannot get stat of SSSD socket." +msgstr "" + +#: src/sss_client/common.c:1225 +msgid "An error occurred, but no description can be found." +msgstr "" + +#: src/sss_client/common.c:1231 +msgid "Unexpected error while looking for an error description" +msgstr "" + +#: src/sss_client/pam_sss.c:135 +msgid "Permission denied. " +msgstr "" + +#: src/sss_client/pam_sss.c:136 src/sss_client/pam_sss.c:921 +#: src/sss_client/pam_sss.c:932 +msgid "Server message: " +msgstr "" + +#: src/sss_client/pam_sss.c:137 +msgid "" +"Kerberos TGT will not be granted upon login, user experience will be " +"affected." +msgstr "" + +#: src/sss_client/pam_sss.c:138 +msgid "Enter PIN:" +msgstr "" + +#: src/sss_client/pam_sss.c:385 +msgid "Passwords do not match" +msgstr "" + +#: src/sss_client/pam_sss.c:584 +msgid "Password reset by root is not supported." +msgstr "" + +#: src/sss_client/pam_sss.c:625 +msgid "Authenticated with cached credentials" +msgstr "" + +#: src/sss_client/pam_sss.c:626 +msgid ", your cached password will expire at: " +msgstr "" + +#: src/sss_client/pam_sss.c:656 +#, c-format +msgid "Your password has expired. You have %1$d grace login(s) remaining." +msgstr "" + +#: src/sss_client/pam_sss.c:706 +#, c-format +msgid "Your password will expire in %1$d %2$s." +msgstr "" + +#: src/sss_client/pam_sss.c:709 +#, c-format +msgid "Your password has expired." +msgstr "" + +#: src/sss_client/pam_sss.c:760 +msgid "Authentication is denied until: " +msgstr "" + +#: src/sss_client/pam_sss.c:781 +msgid "System is offline, password change not possible" +msgstr "" + +#: src/sss_client/pam_sss.c:796 +msgid "" +"After changing the OTP password, you need to log out and back in order to " +"acquire a ticket" +msgstr "" + +#: src/sss_client/pam_sss.c:813 +msgid "PIN locked" +msgstr "" + +#: src/sss_client/pam_sss.c:828 +msgid "" +"No Kerberos TGT granted as the server does not support this method. Your " +"single-sign on(SSO) experience will be affected." +msgstr "" + +#: src/sss_client/pam_sss.c:918 src/sss_client/pam_sss.c:931 +msgid "Password change failed. " +msgstr "" + +#: src/sss_client/pam_sss.c:2028 +#, c-format +msgid "Authenticate at \"%1$s\"." +msgstr "" + +#: src/sss_client/pam_sss.c:2031 +#, c-format +msgid "Authenticate with PIN \"%1$s\" at \"%2$s\"." +msgstr "" + +#: src/sss_client/pam_sss.c:2470 +msgid "Please (re)insert (different) Smartcard" +msgstr "" + +#: src/sss_client/pam_sss.c:2700 +msgid "New Password: " +msgstr "" + +#: src/sss_client/pam_sss.c:2701 +msgid "Reenter new Password: " +msgstr "" + +#: src/sss_client/pam_sss.c:2890 +msgid "Press ENTER to continue." +msgstr "" + +#: src/sss_client/pam_sss.c:2913 src/sss_client/pam_sss.c:2916 +msgid "First Factor: " +msgstr "" + +#: src/sss_client/pam_sss.c:2914 src/sss_client/pam_sss.c:3088 +msgid "Second Factor (optional): " +msgstr "" + +#: src/sss_client/pam_sss.c:2917 src/sss_client/pam_sss.c:3092 +msgid "Second Factor: " +msgstr "" + +#: src/sss_client/pam_sss.c:2921 +msgid "Insert your passkey device, then press ENTER." +msgstr "" + +#: src/sss_client/pam_sss.c:2925 src/sss_client/pam_sss.c:2933 +msgid "Password: " +msgstr "" + +#: src/sss_client/pam_sss.c:3087 src/sss_client/pam_sss.c:3091 +msgid "First Factor (Current Password): " +msgstr "" + +#: src/sss_client/pam_sss.c:3111 +msgid "Current Password: " +msgstr "" + +#: src/sss_client/pam_sss.c:3485 +msgid "Password expired. Change your password now." +msgstr "" + +#: src/sss_client/ssh/sss_ssh_authorizedkeys.c:41 src/tools/sss_cache.c:707 +msgid "The debug level to run with" +msgstr "" + +#: src/sss_client/ssh/sss_ssh_authorizedkeys.c:43 +msgid "The SSSD domain to use" +msgstr "" + +#: src/sss_client/ssh/sss_ssh_authorizedkeys.c:57 src/tools/sss_cache.c:753 +msgid "Error setting the locale\n" +msgstr "" + +#: src/sss_client/ssh/sss_ssh_authorizedkeys.c:64 +msgid "Not enough memory\n" +msgstr "" + +#: src/sss_client/ssh/sss_ssh_authorizedkeys.c:83 +msgid "User not specified\n" +msgstr "" + +#: src/sss_client/ssh/sss_ssh_authorizedkeys.c:97 +msgid "Error looking up public keys\n" +msgstr "" + +#: src/sss_client/ssh/sss_ssh_knownhostsproxy.c:27 +msgid "" +"\n" +"******************************************************************************\n" +"Your system is configured to use the obsolete tool sss_ssh_knownhostsproxy.\n" +"Please read the sss_ssh_knownhosts(1) man page to learn about its " +"replacement.\n" +"******************************************************************************\n" +"\n" +msgstr "" + +#: src/tools/sss_cache.c:229 +msgid "No cache object matched the specified search\n" +msgstr "" + +#: src/tools/sss_cache.c:520 +#, c-format +msgid "Couldn't invalidate %1$s\n" +msgstr "" + +#: src/tools/sss_cache.c:527 +#, c-format +msgid "Couldn't invalidate %1$s %2$s\n" +msgstr "" + +#: src/tools/sss_cache.c:653 +msgid "Can't find configuration db, was SSSD configured and run?\n" +msgstr "" + +#: src/tools/sss_cache.c:709 +msgid "Invalidate all cached entries" +msgstr "" + +#: src/tools/sss_cache.c:711 +msgid "Invalidate particular user" +msgstr "" + +#: src/tools/sss_cache.c:713 +msgid "Invalidate all users" +msgstr "" + +#: src/tools/sss_cache.c:715 +msgid "Invalidate particular group" +msgstr "" + +#: src/tools/sss_cache.c:717 +msgid "Invalidate all groups" +msgstr "" + +#: src/tools/sss_cache.c:719 +msgid "Invalidate particular netgroup" +msgstr "" + +#: src/tools/sss_cache.c:721 +msgid "Invalidate all netgroups" +msgstr "" + +#: src/tools/sss_cache.c:723 +msgid "Invalidate particular service" +msgstr "" + +#: src/tools/sss_cache.c:725 +msgid "Invalidate all services" +msgstr "" + +#: src/tools/sss_cache.c:728 +msgid "Invalidate particular autofs map" +msgstr "" + +#: src/tools/sss_cache.c:730 +msgid "Invalidate all autofs maps" +msgstr "" + +#: src/tools/sss_cache.c:734 +msgid "Invalidate particular SSH host" +msgstr "" + +#: src/tools/sss_cache.c:736 +msgid "Invalidate all SSH hosts" +msgstr "" + +#: src/tools/sss_cache.c:740 +msgid "Invalidate particular sudo rule" +msgstr "" + +#: src/tools/sss_cache.c:742 +msgid "Invalidate all cached sudo rules" +msgstr "" + +#: src/tools/sss_cache.c:745 +msgid "Only invalidate entries from a particular domain" +msgstr "" + +#: src/tools/sss_cache.c:799 +msgid "" +"Unexpected argument(s) provided, options that invalidate a single object " +"only accept a single provided argument.\n" +msgstr "" + +#: src/tools/sss_cache.c:809 +msgid "Please select at least one object to invalidate\n" +msgstr "" + +#: src/tools/sss_cache.c:892 +#, c-format +msgid "" +"Could not open domain %1$s. If the domain is a subdomain (trusted domain), " +"use fully qualified name instead of --domain/-d parameter.\n" +msgstr "" + +#: src/tools/sss_cache.c:897 +msgid "Could not open available domains\n" +msgstr "" + +#: src/tools/tools_util.h:36 +#, c-format +msgid "%1$s must be run as root\n" +msgstr "" + +#: src/tools/sssctl/sssctl.c:35 +msgid "yes" +msgstr "" + +#: src/tools/sssctl/sssctl.c:37 +msgid "no" +msgstr "" + +#: src/tools/sssctl/sssctl.c:39 +msgid "error" +msgstr "" + +#: src/tools/sssctl/sssctl.c:42 +msgid "Invalid result." +msgstr "" + +#: src/tools/sssctl/sssctl.c:78 +msgid "Unable to read user input\n" +msgstr "" + +#: src/tools/sssctl/sssctl.c:91 +#, c-format +msgid "Invalid input, please provide either '%s' or '%s'.\n" +msgstr "" + +#: src/tools/sssctl/sssctl.c:151 src/tools/sssctl/sssctl.c:161 +msgid "Error while executing external command\n" +msgstr "" + +#: src/tools/sssctl/sssctl.c:165 +#, c-format +msgid "Error while executing external command '%s'\n" +msgstr "" + +#: src/tools/sssctl/sssctl.c:168 +#, c-format +msgid "Command '%s' failed with [%d]\n" +msgstr "" + +#: src/tools/sssctl/sssctl.c:215 +msgid "SSSD needs to be running. Start SSSD now?" +msgstr "" + +#: src/tools/sssctl/sssctl.c:254 +msgid "SSSD must not be running. Stop SSSD now?" +msgstr "" + +#: src/tools/sssctl/sssctl.c:290 +msgid "SSSD needs to be restarted. Restart SSSD now?" +msgstr "" + +#: src/tools/sssctl/sssctl.c:322 +msgid "SSSD Status:" +msgstr "" + +#: src/tools/sssctl/sssctl.c:323 +msgid "List available domains" +msgstr "" + +#: src/tools/sssctl/sssctl.c:324 +msgid "Print information about domain" +msgstr "" + +#: src/tools/sssctl/sssctl.c:325 +msgid "Print information about a user and check authentication" +msgstr "" + +#: src/tools/sssctl/sssctl.c:326 +msgid "Generate access report for a domain" +msgstr "" + +#: src/tools/sssctl/sssctl.c:327 +msgid "Information about cached content:" +msgstr "" + +#: src/tools/sssctl/sssctl.c:328 +msgid "Information about cached user" +msgstr "" + +#: src/tools/sssctl/sssctl.c:329 +msgid "Information about cached group" +msgstr "" + +#: src/tools/sssctl/sssctl.c:330 +msgid "Information about cached netgroup" +msgstr "" + +#: src/tools/sssctl/sssctl.c:331 +msgid "Local data tools:" +msgstr "" + +#: src/tools/sssctl/sssctl.c:332 +msgid "Backup local data" +msgstr "" + +#: src/tools/sssctl/sssctl.c:333 +msgid "Restore local data from backup" +msgstr "" + +#: src/tools/sssctl/sssctl.c:334 +msgid "Backup local data and remove cached content" +msgstr "" + +#: src/tools/sssctl/sssctl.c:335 +msgid "Invalidate cached objects" +msgstr "" + +#: src/tools/sssctl/sssctl.c:336 +msgid "Manage cache indexes" +msgstr "" + +#: src/tools/sssctl/sssctl.c:337 +msgid "Log files tools:" +msgstr "" + +#: src/tools/sssctl/sssctl.c:338 +msgid "Remove existing SSSD log files" +msgstr "" + +#: src/tools/sssctl/sssctl.c:339 +msgid "Archive SSSD log files in tarball" +msgstr "" + +#: src/tools/sssctl/sssctl.c:340 +msgid "Change or print information about SSSD debug level" +msgstr "" + +#: src/tools/sssctl/sssctl.c:341 +msgid "Analyze logged data" +msgstr "" + +#: src/tools/sssctl/sssctl.c:342 +msgid "Configuration files tools:" +msgstr "" + +#: src/tools/sssctl/sssctl.c:343 +msgid "Perform static analysis of SSSD configuration" +msgstr "" + +#: src/tools/sssctl/sssctl.c:344 +msgid "Certificate related tools:" +msgstr "" + +#: src/tools/sssctl/sssctl.c:345 +msgid "Print information about the certificate" +msgstr "" + +#: src/tools/sssctl/sssctl.c:346 +msgid "Show users mapped to the certificate" +msgstr "" + +#: src/tools/sssctl/sssctl.c:347 +msgid "Check mapping and matching rule with a certificate" +msgstr "" + +#: src/tools/sssctl/sssctl.c:348 +msgid "GPOs related tools:" +msgstr "" + +#: src/tools/sssctl/sssctl.c:349 +msgid "Information about cached GPO" +msgstr "" + +#: src/tools/sssctl/sssctl.c:350 +msgid "Enumerate cached GPOs" +msgstr "" + +#: src/tools/sssctl/sssctl.c:351 +msgid "Remove cached GPO" +msgstr "" + +#: src/tools/sssctl/sssctl.c:352 +msgid "Remove all cached GPOs" +msgstr "" + +#: src/tools/sssctl/sssctl.c:354 +msgid "Passkey related tools:" +msgstr "" + +#: src/tools/sssctl/sssctl.c:355 +msgid "Perform passkey registration" +msgstr "" + +#: src/tools/sssctl/sssctl_cache.c:31 +#, c-format +msgid " %s is not present in cache.\n" +msgstr "" + +#: src/tools/sssctl/sssctl_cache.c:33 +msgid "Name" +msgstr "" + +#: src/tools/sssctl/sssctl_cache.c:34 +msgid "Cache entry creation date" +msgstr "" + +#: src/tools/sssctl/sssctl_cache.c:35 +msgid "Cache entry last update time" +msgstr "" + +#: src/tools/sssctl/sssctl_cache.c:36 +msgid "Cache entry expiration time" +msgstr "" + +#: src/tools/sssctl/sssctl_cache.c:37 +msgid "Cached in InfoPipe" +msgstr "" + +#: src/tools/sssctl/sssctl_cache.c:38 +msgid "Policy Name" +msgstr "" + +#: src/tools/sssctl/sssctl_cache.c:39 +msgid "Policy GUID" +msgstr "" + +#: src/tools/sssctl/sssctl_cache.c:40 +msgid "Policy Path" +msgstr "" + +#: src/tools/sssctl/sssctl_cache.c:41 +msgid "Policy file timeout" +msgstr "" + +#: src/tools/sssctl/sssctl_cache.c:42 +msgid "Policy version" +msgstr "" + +#: src/tools/sssctl/sssctl_cache.c:556 +#, c-format +msgid "Error: Unable to get object [%d]: %s\n" +msgstr "" + +#: src/tools/sssctl/sssctl_cache.c:572 src/tools/sssctl/sssctl_cache.c:927 +#, c-format +msgid "%s: Unable to read value [%d]: %s\n" +msgstr "" + +#: src/tools/sssctl/sssctl_cache.c:602 +msgid "Specify name." +msgstr "" + +#: src/tools/sssctl/sssctl_cache.c:612 +#, c-format +msgid "Unable to parse name %s.\n" +msgstr "" + +#: src/tools/sssctl/sssctl_cache.c:641 src/tools/sssctl/sssctl_cache.c:688 +msgid "Search by SID" +msgstr "" + +#: src/tools/sssctl/sssctl_cache.c:642 +msgid "Search by user ID" +msgstr "" + +#: src/tools/sssctl/sssctl_cache.c:651 +msgid "Initgroups expiration time" +msgstr "" + +#: src/tools/sssctl/sssctl_cache.c:689 +msgid "Search by group ID" +msgstr "" + +#: src/tools/sssctl/sssctl_cache.c:778 src/tools/sssctl/sssctl_cache.c:1126 +msgid "Search by GPO guid" +msgstr "" + +#: src/tools/sssctl/sssctl_cache.c:785 src/tools/sssctl/sssctl_cache.c:1143 +#, c-format +msgid "Failed to parse command line: %s\n" +msgstr "" + +#: src/tools/sssctl/sssctl_cache.c:790 src/tools/sssctl/sssctl_cache.c:1148 +#, c-format +msgid "%s\n" +msgstr "" + +#: src/tools/sssctl/sssctl_cache.c:803 +#, c-format +msgid "Failed to print object: %s\n" +msgstr "" + +#: src/tools/sssctl/sssctl_cache.c:835 src/tools/sssctl/sssctl_cache.c:918 +#: src/tools/sssctl/sssctl_cache.c:950 src/tools/sssctl/sssctl_cache.c:956 +#: src/tools/sssctl/sssctl_cache.c:1010 src/tools/sssctl/sssctl_cache.c:1034 +#: src/tools/sssctl/sssctl_cache.c:1085 src/tools/sssctl/sssctl_cache.c:1195 +#: src/tools/sssctl/sssctl_cache.c:1230 src/tools/sssctl/sssctl_cache.c:1236 +#: src/tools/sssctl/sssctl_cache.c:1245 +msgid "talloc failed\n" +msgstr "" + +#: src/tools/sssctl/sssctl_cache.c:841 +msgid "Unable to get attribute list!\n" +msgstr "" + +#: src/tools/sssctl/sssctl_cache.c:848 +msgid "Unable to create filter\n" +msgstr "" + +#: src/tools/sssctl/sssctl_cache.c:861 +#, c-format +msgid "%s [%s]:\n" +msgstr "" + +#: src/tools/sssctl/sssctl_cache.c:866 +msgid "Unable to get GPOs base DN\n" +msgstr "" + +#: src/tools/sssctl/sssctl_cache.c:876 +#, c-format +msgid "Unable to search sysdb: %s\n" +msgstr "" + +#: src/tools/sssctl/sssctl_cache.c:882 +#, c-format +msgid "Unable to convert message to sysdb attrs: %s\n" +msgstr "" + +#: src/tools/sssctl/sssctl_cache.c:931 +#, c-format +msgid "\t%s: %s\n" +msgstr "" + +#: src/tools/sssctl/sssctl_cache.c:933 src/tools/sssctl/sssctl_logs.c:50 +msgid "\n" +msgstr "" + +#: src/tools/sssctl/sssctl_cache.c:1016 +msgid "Could not find GUID attribute from GPO entry\n" +msgstr "" + +#: src/tools/sssctl/sssctl_cache.c:1023 +msgid "Could not find description attribute from GPO entry\n" +msgstr "" + +#: src/tools/sssctl/sssctl_cache.c:1047 +msgid "Could not delete GPO entry from cache\n" +msgstr "" + +#: src/tools/sssctl/sssctl_cache.c:1053 +#, c-format +msgid "" +"The GPO path was not yet stored in cache. Please remove files manually from " +"[%s]\n" +msgstr "" + +#: src/tools/sssctl/sssctl_cache.c:1062 src/tools/sssctl/sssctl_cache.c:1068 +#, c-format +msgid "Could not determine real path for [%s]: %s\n" +msgstr "" + +#: src/tools/sssctl/sssctl_cache.c:1073 +#, c-format +msgid "The cached GPO path [%s] is not under [%s], ignoring.\n" +msgstr "" + +#: src/tools/sssctl/sssctl_cache.c:1098 +#, c-format +msgid "Unable to remove downloaded GPO files: %s\n" +msgstr "" + +#: src/tools/sssctl/sssctl_cache.c:1166 +#, c-format +msgid "Failed to fetch cache entry: %s\n" +msgstr "" + +#: src/tools/sssctl/sssctl_cache.c:1171 +msgid "Could not determine object domain\n" +msgstr "" + +#: src/tools/sssctl/sssctl_cache.c:1201 +msgid "Could not find GUID attribute in GPO entry\n" +msgstr "" + +#: src/tools/sssctl/sssctl_cache.c:1207 +#, c-format +msgid "Failed to delete GPO: %s\n" +msgstr "" + +#: src/tools/sssctl/sssctl_cache.c:1211 +#, c-format +msgid "%s removed from cache\n" +msgstr "" + +#: src/tools/sssctl/sssctl_cert.c:50 src/tools/sssctl/sssctl_cert.c:108 +#: src/tools/sssctl/sssctl_cert.c:214 +msgid "Show debug information" +msgstr "" + +#: src/tools/sssctl/sssctl_cert.c:56 src/tools/sssctl/sssctl_cert.c:114 +#: src/tools/sssctl/sssctl_cert.c:220 +msgid "Specify base64 encoded certificate." +msgstr "" + +#: src/tools/sssctl/sssctl_cert.c:138 src/tools/sssctl/sssctl_domains.c:104 +#: src/tools/sssctl/sssctl_domains.c:366 +#: src/tools/sssctl/sssctl_user_checks.c:99 +msgid "Unable to connect to system bus!\n" +msgstr "" + +#: src/tools/sssctl/sssctl_cert.c:164 +msgid " - no mapped users found -" +msgstr "" + +#: src/tools/sssctl/sssctl_cert.c:212 +msgid "Mapping rule" +msgstr "" + +#: src/tools/sssctl/sssctl_cert.c:213 +msgid "Matching rule" +msgstr "" + +#: src/tools/sssctl/sssctl_cert.c:223 +msgid "Unable to parse command arguments\n" +msgstr "" + +#: src/tools/sssctl/sssctl_cert.c:229 src/tools/sssctl/sssctl_domains.c:354 +msgid "Out of memory!\n" +msgstr "" + +#: src/tools/sssctl/sssctl_cert.c:238 +msgid "Failed to setup certmap context.\n" +msgstr "" + +#: src/tools/sssctl/sssctl_cert.c:244 +#, c-format +msgid "Failed to add mapping and matching rules with error [%d][%s].\n" +msgstr "" + +#: src/tools/sssctl/sssctl_cert.c:251 +msgid "Failed to decode base64 string.\n" +msgstr "" + +#: src/tools/sssctl/sssctl_cert.c:259 +msgid "Certificate matches rule.\n" +msgstr "" + +#: src/tools/sssctl/sssctl_cert.c:262 +msgid "Certificate does not match rule.\n" +msgstr "" + +#: src/tools/sssctl/sssctl_cert.c:265 +#, c-format +msgid "Error during certificate matching [%d][%s].\n" +msgstr "" + +#: src/tools/sssctl/sssctl_cert.c:272 +#, c-format +msgid "Failed to generate mapping filter [%d][%s].\n" +msgstr "" + +#: src/tools/sssctl/sssctl_cert.c:276 +#, c-format +msgid "" +"Mapping filter:\n" +"\n" +" %s\n" +"\n" +msgstr "" + +#: src/tools/sssctl/sssctl_config.c:75 +msgid "" +"Specify a non-default snippet dir (The default is to look in the same place " +"where the main config file is located. For example if the config is set to " +"\"/my/path/sssd.conf\", the snippet dir \"/my/path/conf.d\" is used)" +msgstr "" + +#: src/tools/sssctl/sssctl_config.c:126 +#, c-format +msgid "File %1$s does not exist.\n" +msgstr "" + +#: src/tools/sssctl/sssctl_config.c:127 +msgid "There is no configuration.\n" +msgstr "" + +#: src/tools/sssctl/sssctl_config.c:132 +#, c-format +msgid "Configuration validation failed: %s\n" +msgstr "" + +#: src/tools/sssctl/sssctl_config.c:133 +msgid "Run with high debug level to see details.\n" +msgstr "" + +#: src/tools/sssctl/sssctl_config.c:142 +msgid "Failed to run validators\n" +msgstr "" + +#: src/tools/sssctl/sssctl_config.c:146 +#, c-format +msgid "Issues identified by validators: %zu\n" +msgstr "" + +#: src/tools/sssctl/sssctl_config.c:157 +#, c-format +msgid "Messages generated during configuration merging: %zu\n" +msgstr "" + +#: src/tools/sssctl/sssctl_config.c:170 +#, c-format +msgid "Used configuration snippet files: %zu\n" +msgstr "" + +#: src/tools/sssctl/sssctl_data.c:91 +#, c-format +msgid "Unable to create backup directory [%d]: %s" +msgstr "" + +#: src/tools/sssctl/sssctl_data.c:97 +msgid "SSSD backup of local data already exists, override?" +msgstr "" + +#: src/tools/sssctl/sssctl_data.c:113 +msgid "Unable to export user overrides\n" +msgstr "" + +#: src/tools/sssctl/sssctl_data.c:120 +msgid "Unable to export group overrides\n" +msgstr "" + +#: src/tools/sssctl/sssctl_data.c:135 src/tools/sssctl/sssctl_data.c:216 +msgid "Override existing backup" +msgstr "" + +#: src/tools/sssctl/sssctl_data.c:165 +msgid "Unable to import user overrides\n" +msgstr "" + +#: src/tools/sssctl/sssctl_data.c:174 +msgid "Unable to import group overrides\n" +msgstr "" + +#: src/tools/sssctl/sssctl_data.c:194 src/tools/sssctl/sssctl_domains.c:81 +#: src/tools/sssctl/sssctl_domains.c:326 +msgid "Start SSSD if it is not running" +msgstr "" + +#: src/tools/sssctl/sssctl_data.c:195 +msgid "Restart SSSD after data import" +msgstr "" + +#: src/tools/sssctl/sssctl_data.c:217 +msgid "Create clean cache files and import local data" +msgstr "" + +#: src/tools/sssctl/sssctl_data.c:218 +msgid "Stop SSSD before removing the cache" +msgstr "" + +#: src/tools/sssctl/sssctl_data.c:219 +msgid "Start SSSD when the cache is removed" +msgstr "" + +#: src/tools/sssctl/sssctl_data.c:234 +msgid "Creating backup of local data...\n" +msgstr "" + +#: src/tools/sssctl/sssctl_data.c:237 +msgid "Unable to create backup of local data, can not remove the cache.\n" +msgstr "" + +#: src/tools/sssctl/sssctl_data.c:242 +msgid "Removing cache files...\n" +msgstr "" + +#: src/tools/sssctl/sssctl_data.c:245 +msgid "Unable to remove cache files\n" +msgstr "" + +#: src/tools/sssctl/sssctl_data.c:250 +msgid "Restoring local data...\n" +msgstr "" + +#: src/tools/sssctl/sssctl_data.c:377 +#, c-format +msgid "Creating cache index for domain %1$s\n" +msgstr "" + +#: src/tools/sssctl/sssctl_data.c:379 +#, c-format +msgid "Deleting cache index for domain %1$s\n" +msgstr "" + +#: src/tools/sssctl/sssctl_data.c:381 +#, c-format +msgid "Indexes for domain %1$s:\n" +msgstr "" + +#: src/tools/sssctl/sssctl_data.c:401 +#, c-format +msgid " Attribute: %1$s\n" +msgstr "" + +#: src/tools/sssctl/sssctl_data.c:428 src/tools/sssctl/sssctl_logs.c:525 +msgid "Target a specific domain" +msgstr "" + +#: src/tools/sssctl/sssctl_data.c:428 src/tools/sssctl/sssctl_logs.c:525 +msgid "domain" +msgstr "" + +#: src/tools/sssctl/sssctl_data.c:430 +msgid "Attribute to index" +msgstr "" + +#: src/tools/sssctl/sssctl_data.c:430 +msgid "attribute" +msgstr "" + +#: src/tools/sssctl/sssctl_data.c:443 +msgid "Action not provided\n" +msgstr "" + +#: src/tools/sssctl/sssctl_data.c:456 +#, c-format +msgid "" +"Unknown action: %1$s\n" +"Valid actions are \"%2$s\", \"%3$s and \"%4$s\"\n" +msgstr "" + +#: src/tools/sssctl/sssctl_data.c:464 +msgid "Attribute (-a) not provided\n" +msgstr "" + +#: src/tools/sssctl/sssctl_data.c:472 +#, c-format +msgid "Attribute %1$s not indexed.\n" +msgstr "" + +#: src/tools/sssctl/sssctl_data.c:475 +#, c-format +msgid "Attribute %1$s already indexed.\n" +msgstr "" + +#: src/tools/sssctl/sssctl_data.c:478 +#, c-format +msgid "Index operation failed: %1$s\n" +msgstr "" + +#: src/tools/sssctl/sssctl_data.c:483 +msgid "Don't forget to also update the indexes on the remote providers.\n" +msgstr "" + +#: src/tools/sssctl/sssctl_domains.c:82 +msgid "Show domain list including primary or trusted domain type" +msgstr "" + +#: src/tools/sssctl/sssctl_domains.c:166 +msgid "Online" +msgstr "" + +#: src/tools/sssctl/sssctl_domains.c:166 +msgid "Offline" +msgstr "" + +#: src/tools/sssctl/sssctl_domains.c:166 +#, c-format +msgid "Online status: %s\n" +msgstr "" + +#: src/tools/sssctl/sssctl_domains.c:212 +msgid "This domain has no active servers.\n" +msgstr "" + +#: src/tools/sssctl/sssctl_domains.c:217 +msgid "Active servers:\n" +msgstr "" + +#: src/tools/sssctl/sssctl_domains.c:229 +msgid "not connected" +msgstr "" + +#: src/tools/sssctl/sssctl_domains.c:266 +msgid "No servers discovered.\n" +msgstr "" + +#: src/tools/sssctl/sssctl_domains.c:272 +#, c-format +msgid "Discovered %s servers:\n" +msgstr "" + +#: src/tools/sssctl/sssctl_domains.c:284 +msgid "None so far.\n" +msgstr "" + +#: src/tools/sssctl/sssctl_domains.c:323 +msgid "Show online status" +msgstr "" + +#: src/tools/sssctl/sssctl_domains.c:324 +msgid "Show information about active server" +msgstr "" + +#: src/tools/sssctl/sssctl_domains.c:325 +msgid "Show list of discovered servers" +msgstr "" + +#: src/tools/sssctl/sssctl_domains.c:331 +msgid "Specify domain name." +msgstr "" + +#: src/tools/sssctl/sssctl_domains.c:374 src/tools/sssctl/sssctl_domains.c:384 +msgid "Unable to get online status\n" +msgstr "" + +#: src/tools/sssctl/sssctl_domains.c:394 +msgid "Unable to get server list\n" +msgstr "" + +#: src/tools/sssctl/sssctl_logs.c:214 +msgid "SSSD is not running.\n" +msgstr "" + +#: src/tools/sssctl/sssctl_logs.c:231 +#, c-format +msgid "%1$-25s %2$#.4x\n" +msgstr "" + +#: src/tools/sssctl/sssctl_logs.c:235 +#, c-format +msgid "%1$-25s Unknown domain\n" +msgstr "" + +#: src/tools/sssctl/sssctl_logs.c:237 +#, c-format +msgid "%1$-25s Unreachable service\n" +msgstr "" + +#: src/tools/sssctl/sssctl_logs.c:429 +msgid "Delete log files instead of truncating" +msgstr "" + +#: src/tools/sssctl/sssctl_logs.c:440 +msgid "Deleting log files...\n" +msgstr "" + +#: src/tools/sssctl/sssctl_logs.c:443 +msgid "Unable to remove log files\n" +msgstr "" + +#: src/tools/sssctl/sssctl_logs.c:460 +msgid "Truncating log files...\n" +msgstr "" + +#: src/tools/sssctl/sssctl_logs.c:464 +msgid "Unable to truncate log files\n" +msgstr "" + +#: src/tools/sssctl/sssctl_logs.c:498 +#, c-format +msgid "Archiving log files into %s...\n" +msgstr "" + +#: src/tools/sssctl/sssctl_logs.c:502 +msgid "Unable to archive log files\n" +msgstr "" + +#: src/tools/sssctl/sssctl_logs.c:526 +msgid "Target the SSSD service" +msgstr "" + +#: src/tools/sssctl/sssctl_logs.c:527 +msgid "Target the NSS service" +msgstr "" + +#: src/tools/sssctl/sssctl_logs.c:528 +msgid "Target the PAM service" +msgstr "" + +#: src/tools/sssctl/sssctl_logs.c:529 +msgid "Target the SUDO service" +msgstr "" + +#: src/tools/sssctl/sssctl_logs.c:530 +msgid "Target the AUTOFS service" +msgstr "" + +#: src/tools/sssctl/sssctl_logs.c:531 +msgid "Target the SSH service" +msgstr "" + +#: src/tools/sssctl/sssctl_logs.c:532 +msgid "Target the PAC service" +msgstr "" + +#: src/tools/sssctl/sssctl_logs.c:533 +msgid "Target the IFP service" +msgstr "" + +#: src/tools/sssctl/sssctl_logs.c:548 +msgid "Specify debug level you want to set" +msgstr "" + +#: src/tools/sssctl/sssctl_logs.c:593 +msgid "ERROR: Tevent chain ID support missing, log analyzer is unsupported.\n" +msgstr "" + +#: src/tools/sssctl/sssctl_user_checks.c:121 +msgid "SSSD InfoPipe user lookup result:\n" +msgstr "" + +#: src/tools/sssctl/sssctl_user_checks.c:171 +#, c-format +msgid "dlopen failed with [%s].\n" +msgstr "" + +#: src/tools/sssctl/sssctl_user_checks.c:178 +#, c-format +msgid "dlsym failed with [%s].\n" +msgstr "" + +#: src/tools/sssctl/sssctl_user_checks.c:186 +msgid "malloc failed.\n" +msgstr "" + +#: src/tools/sssctl/sssctl_user_checks.c:193 +#, c-format +msgid "sss_getpwnam_r failed with [%d].\n" +msgstr "" + +#: src/tools/sssctl/sssctl_user_checks.c:198 +msgid "SSSD nss user lookup result:\n" +msgstr "" + +#: src/tools/sssctl/sssctl_user_checks.c:199 +#, c-format +msgid " - user name: %s\n" +msgstr "" + +#: src/tools/sssctl/sssctl_user_checks.c:200 +#, c-format +msgid " - user id: %d\n" +msgstr "" + +#: src/tools/sssctl/sssctl_user_checks.c:201 +#, c-format +msgid " - group id: %d\n" +msgstr "" + +#: src/tools/sssctl/sssctl_user_checks.c:202 +#, c-format +msgid " - gecos: %s\n" +msgstr "" + +#: src/tools/sssctl/sssctl_user_checks.c:203 +#, c-format +msgid " - home directory: %s\n" +msgstr "" + +#: src/tools/sssctl/sssctl_user_checks.c:204 +#, c-format +msgid "" +" - shell: %s\n" +"\n" +msgstr "" + +#: src/tools/sssctl/sssctl_user_checks.c:235 +msgid "PAM action [auth|acct|setc|chau|open|clos], default: " +msgstr "" + +#: src/tools/sssctl/sssctl_user_checks.c:238 +msgid "PAM service, default: " +msgstr "" + +#: src/tools/sssctl/sssctl_user_checks.c:243 +msgid "Specify user name." +msgstr "" + +#: src/tools/sssctl/sssctl_user_checks.c:250 +#, c-format +msgid "" +"user: %s\n" +"action: %s\n" +"service: %s\n" +"\n" +msgstr "" + +#: src/tools/sssctl/sssctl_user_checks.c:255 +#, c-format +msgid "User name lookup with [%s] failed.\n" +msgstr "" + +#: src/tools/sssctl/sssctl_user_checks.c:260 +#, c-format +msgid "InfoPipe User lookup with [%s] failed.\n" +msgstr "" + +#: src/tools/sssctl/sssctl_user_checks.c:266 +#, c-format +msgid "pam_start failed: %s\n" +msgstr "" + +#: src/tools/sssctl/sssctl_user_checks.c:272 +msgid "" +"testing pam_authenticate\n" +"\n" +msgstr "" + +#: src/tools/sssctl/sssctl_user_checks.c:276 +#, c-format +msgid "pam_get_item failed: %s\n" +msgstr "" + +#: src/tools/sssctl/sssctl_user_checks.c:279 +#, c-format +msgid "" +"pam_authenticate for user [%s]: %s\n" +"\n" +msgstr "" + +#: src/tools/sssctl/sssctl_user_checks.c:282 +msgid "" +"testing pam_chauthtok\n" +"\n" +msgstr "" + +#: src/tools/sssctl/sssctl_user_checks.c:284 +#, c-format +msgid "" +"pam_chauthtok: %s\n" +"\n" +msgstr "" + +#: src/tools/sssctl/sssctl_user_checks.c:286 +msgid "" +"testing pam_acct_mgmt\n" +"\n" +msgstr "" + +#: src/tools/sssctl/sssctl_user_checks.c:288 +#, c-format +msgid "" +"pam_acct_mgmt: %s\n" +"\n" +msgstr "" + +#: src/tools/sssctl/sssctl_user_checks.c:290 +msgid "" +"testing pam_setcred\n" +"\n" +msgstr "" + +#: src/tools/sssctl/sssctl_user_checks.c:292 +#, c-format +msgid "" +"pam_setcred: [%s]\n" +"\n" +msgstr "" + +#: src/tools/sssctl/sssctl_user_checks.c:294 +msgid "" +"testing pam_open_session\n" +"\n" +msgstr "" + +#: src/tools/sssctl/sssctl_user_checks.c:296 +#, c-format +msgid "" +"pam_open_session: %s\n" +"\n" +msgstr "" + +#: src/tools/sssctl/sssctl_user_checks.c:298 +msgid "" +"testing pam_close_session\n" +"\n" +msgstr "" + +#: src/tools/sssctl/sssctl_user_checks.c:300 +#, c-format +msgid "" +"pam_close_session: %s\n" +"\n" +msgstr "" + +#: src/tools/sssctl/sssctl_user_checks.c:302 +msgid "unknown action\n" +msgstr "" + +#: src/tools/sssctl/sssctl_user_checks.c:305 +msgid "PAM Environment:\n" +msgstr "" + +#: src/tools/sssctl/sssctl_user_checks.c:313 +msgid " - no env -\n" +msgstr "" + +#: src/util/util.h:100 +msgid "Specify a non-default config file" +msgstr "" + +#: src/util/util.h:107 +msgid "Informs that the responder has been socket-activated" +msgstr "" diff --git a/po/ru.po b/po/ru.po index 1eefe7ddf0a..d41fc591d3d 100644 --- a/po/ru.po +++ b/po/ru.po @@ -8,13 +8,14 @@ # Evgeny Sinelnikov , 2021, 2026. # Olesya Gerasimenko , 2021, 2026. # Elena Mishina , 2022, 2023, 2024, 2025, 2026. +# Andrei Stepanov , 2026. msgid "" msgstr "" "Project-Id-Version: PACKAGE VERSION\n" "Report-Msgid-Bugs-To: sssd-devel@lists.fedorahosted.org\n" -"POT-Creation-Date: 2026-01-14 14:57+0000\n" -"PO-Revision-Date: 2026-04-23 16:57+0000\n" -"Last-Translator: Evgeny Sinelnikov \n" +"POT-Creation-Date: 2026-10-02 15:57+0000\n" +"PO-Revision-Date: 2026-10-05 21:20+0000\n" +"Last-Translator: Andrei Stepanov \n" "Language-Team: Russian \n" "Language: ru\n" @@ -23,50 +24,50 @@ msgstr "" "Content-Transfer-Encoding: 8bit\n" "Plural-Forms: nplurals=3; plural=n%10==1 && n%100!=11 ? 0 : n%10>=2 && " "n%10<=4 && (n%100<10 || n%100>=20) ? 1 : 2;\n" -"X-Generator: Weblate 5.17\n" +"X-Generator: Weblate 2026.10\n" -#: src/config/SSSDConfig/sssdoptions.py:20 -#: src/config/SSSDConfig/sssdoptions.py:21 +#: src/config/SSSDConfig/sssdoptions.py:16 +#: src/config/SSSDConfig/sssdoptions.py:17 msgid "Set the verbosity of the debug logging" msgstr "Установить подробность журнала отладки" -#: src/config/SSSDConfig/sssdoptions.py:22 +#: src/config/SSSDConfig/sssdoptions.py:18 msgid "Include timestamps in debug logs" msgstr "Добавить отметки времени в журнал отладки" -#: src/config/SSSDConfig/sssdoptions.py:23 +#: src/config/SSSDConfig/sssdoptions.py:19 msgid "Include microseconds in timestamps in debug logs" msgstr "Указывать микросекунды в отметках времени в журнале отладки" -#: src/config/SSSDConfig/sssdoptions.py:24 +#: src/config/SSSDConfig/sssdoptions.py:20 msgid "Enable/disable debug backtrace" msgstr "Включить или отключить обратную трассировку отладки" -#: src/config/SSSDConfig/sssdoptions.py:25 +#: src/config/SSSDConfig/sssdoptions.py:21 msgid "Watchdog timeout before restarting service" msgstr "Тайм-аут сторожевого таймера перед перезапуском службы" -#: src/config/SSSDConfig/sssdoptions.py:26 +#: src/config/SSSDConfig/sssdoptions.py:22 msgid "Command to start service" msgstr "Команда для запуска службы" -#: src/config/SSSDConfig/sssdoptions.py:27 +#: src/config/SSSDConfig/sssdoptions.py:23 msgid "The number of file descriptors that may be opened by this responder" msgstr "Количество файловых дескрипторов, которые может открыть этот ответчик" -#: src/config/SSSDConfig/sssdoptions.py:28 +#: src/config/SSSDConfig/sssdoptions.py:24 msgid "Idle time before automatic disconnection of a client" msgstr "Время простоя до автоматического отсоединения клиента" -#: src/config/SSSDConfig/sssdoptions.py:29 +#: src/config/SSSDConfig/sssdoptions.py:25 msgid "Idle time before automatic shutdown of the responder" msgstr "Время простоя до автоматического отключения ответчика" -#: src/config/SSSDConfig/sssdoptions.py:30 +#: src/config/SSSDConfig/sssdoptions.py:26 msgid "Always query all the caches before querying the Data Providers" msgstr "Всегда опрашивать все кэши перед опросом поставщиков данных" -#: src/config/SSSDConfig/sssdoptions.py:31 +#: src/config/SSSDConfig/sssdoptions.py:27 msgid "" "When SSSD switches to offline mode the amount of time before it tries to go " "back online will increase based upon the time spent disconnected. This value " @@ -78,23 +79,23 @@ msgstr "" "проведённым без подключения. Это значение измеряется в секундах и " "вычисляется по формуле: offline_timeout + random_offset." -#: src/config/SSSDConfig/sssdoptions.py:36 +#: src/config/SSSDConfig/sssdoptions.py:32 msgid "SSSD Services to start" msgstr "Запускаемые службы SSSD" -#: src/config/SSSDConfig/sssdoptions.py:37 +#: src/config/SSSDConfig/sssdoptions.py:33 msgid "SSSD Domains to start" msgstr "Запускаемые домены SSSD" -#: src/config/SSSDConfig/sssdoptions.py:38 +#: src/config/SSSDConfig/sssdoptions.py:34 msgid "Regex to parse username and domain" msgstr "Регулярное выражение для разбора имени пользователя и домена" -#: src/config/SSSDConfig/sssdoptions.py:39 +#: src/config/SSSDConfig/sssdoptions.py:35 msgid "Printf-compatible format for displaying fully-qualified names" msgstr "Printf-совместимый формат для отображения полностью определённых имён" -#: src/config/SSSDConfig/sssdoptions.py:40 +#: src/config/SSSDConfig/sssdoptions.py:36 msgid "" "Directory on the filesystem where SSSD should store Kerberos replay cache " "files." @@ -102,35 +103,36 @@ msgstr "" "Каталог файловой системы, в котором SSSD следует сохранять файлы кэша " "повтора Kerberos." -#: src/config/SSSDConfig/sssdoptions.py:41 +#: src/config/SSSDConfig/sssdoptions.py:37 msgid "Domain to add to names without a domain component." msgstr "Домен для имён без указанного компонента домена." -#: src/config/SSSDConfig/sssdoptions.py:42 +#: src/config/SSSDConfig/sssdoptions.py:38 msgid "The user to drop privileges to" msgstr "Пользователь, чьи привилегии будут использоваться" -#: src/config/SSSDConfig/sssdoptions.py:43 +#: src/config/SSSDConfig/sssdoptions.py:39 msgid "Tune certificate verification" msgstr "Настроить проверку сертификатов" -#: src/config/SSSDConfig/sssdoptions.py:44 +#: src/config/SSSDConfig/sssdoptions.py:40 msgid "All spaces in group or user names will be replaced with this character" -msgstr "Все пробелы в именах пользователей и групп будут заменены этим символом" +msgstr "" +"Все пробелы в именах пользователей и групп будут заменены этим символом" -#: src/config/SSSDConfig/sssdoptions.py:45 +#: src/config/SSSDConfig/sssdoptions.py:41 msgid "Tune sssd to honor or ignore netlink state changes" msgstr "Настроить sssd на учёт или игнорирование изменений состояния netlink" -#: src/config/SSSDConfig/sssdoptions.py:46 +#: src/config/SSSDConfig/sssdoptions.py:42 msgid "Enable or disable the implicit files domain" msgstr "Включить или отключить домен неявных файлов" -#: src/config/SSSDConfig/sssdoptions.py:47 +#: src/config/SSSDConfig/sssdoptions.py:43 msgid "A specific order of the domains to be looked up" msgstr "Порядок доменов, в котором их следует использовать для поиска" -#: src/config/SSSDConfig/sssdoptions.py:48 +#: src/config/SSSDConfig/sssdoptions.py:44 msgid "" "Controls if SSSD should monitor the state of resolv.conf to identify when it " "needs to update its internal DNS resolver." @@ -139,7 +141,7 @@ msgstr "" "определения момента, когда требуется обновить данные встроенного " "сопоставителя DNS." -#: src/config/SSSDConfig/sssdoptions.py:50 +#: src/config/SSSDConfig/sssdoptions.py:46 msgid "" "SSSD monitors the state of resolv.conf to identify when it needs to update " "its internal DNS resolver. By default, we will attempt to use inotify for " @@ -151,79 +153,79 @@ msgstr "" "этого используется inotify. Если невозможно использовать inotify, опрос " "resolv.conf будет выполняться каждые пять секунд." -#: src/config/SSSDConfig/sssdoptions.py:53 +#: src/config/SSSDConfig/sssdoptions.py:49 msgid "Run PAC responder automatically for AD and IPA provider" msgstr "Автоматически запускать ответчик PAC для поставщиков AD и IPA" -#: src/config/SSSDConfig/sssdoptions.py:54 +#: src/config/SSSDConfig/sssdoptions.py:50 msgid "Enable or disable core dumps for all SSSD processes." msgstr "Включить или отключить дампы памяти для всех процессов SSSD." -#: src/config/SSSDConfig/sssdoptions.py:55 +#: src/config/SSSDConfig/sssdoptions.py:51 msgid "Tune passkey verification behavior" msgstr "Настроить проверку ключа доступа" -#: src/config/SSSDConfig/sssdoptions.py:58 +#: src/config/SSSDConfig/sssdoptions.py:54 msgid "Enumeration cache timeout length (seconds)" msgstr "Тайм-аут кэша перечисления (в секундах)" -#: src/config/SSSDConfig/sssdoptions.py:59 +#: src/config/SSSDConfig/sssdoptions.py:55 msgid "Entry cache background update timeout length (seconds)" msgstr "Тайм-аут фонового обновления кэша записей (в секундах)" -#: src/config/SSSDConfig/sssdoptions.py:60 -#: src/config/SSSDConfig/sssdoptions.py:125 +#: src/config/SSSDConfig/sssdoptions.py:56 +#: src/config/SSSDConfig/sssdoptions.py:124 msgid "Negative cache timeout length (seconds)" msgstr "Отрицательный тайм-аут кэша (в секундах)" -#: src/config/SSSDConfig/sssdoptions.py:61 +#: src/config/SSSDConfig/sssdoptions.py:57 msgid "Users that SSSD should explicitly ignore" msgstr "Пользователи, которых SSSD следует явно игнорировать" -#: src/config/SSSDConfig/sssdoptions.py:62 +#: src/config/SSSDConfig/sssdoptions.py:58 msgid "Groups that SSSD should explicitly ignore" msgstr "Группы, которые SSSD следует явно игнорировать" -#: src/config/SSSDConfig/sssdoptions.py:63 +#: src/config/SSSDConfig/sssdoptions.py:59 msgid "Should filtered users appear in groups" msgstr "Должны ли отфильтрованные пользователи появляться в группах" -#: src/config/SSSDConfig/sssdoptions.py:64 +#: src/config/SSSDConfig/sssdoptions.py:60 msgid "The value of the password field the NSS provider should return" msgstr "Значение поля пароля, которое должен вернуть поставщик NSS" -#: src/config/SSSDConfig/sssdoptions.py:65 +#: src/config/SSSDConfig/sssdoptions.py:61 msgid "Override homedir value from the identity provider with this value" msgstr "" "Переопределять значение домашнего каталога от поставщика учётных данных этим " "значением" -#: src/config/SSSDConfig/sssdoptions.py:66 +#: src/config/SSSDConfig/sssdoptions.py:62 msgid "" "Substitute empty homedir value from the identity provider with this value" msgstr "" "Заменять пустое значение домашнего каталога от поставщика учётных данных " "этим значением" -#: src/config/SSSDConfig/sssdoptions.py:67 +#: src/config/SSSDConfig/sssdoptions.py:63 msgid "Override shell value from the identity provider with this value" msgstr "" "Переопределять значение командной оболочки от поставщика учётных данных этим " "значением" -#: src/config/SSSDConfig/sssdoptions.py:68 +#: src/config/SSSDConfig/sssdoptions.py:64 msgid "The list of shells users are allowed to log in with" msgstr "" "Список командных оболочек, с которыми пользователям разрешён вход в систему" -#: src/config/SSSDConfig/sssdoptions.py:69 +#: src/config/SSSDConfig/sssdoptions.py:65 msgid "" "The list of shells that will be vetoed, and replaced with the fallback shell" msgstr "" "Список командных оболочек, которые будут ветированы и заменены запасной " "оболочкой" -#: src/config/SSSDConfig/sssdoptions.py:70 +#: src/config/SSSDConfig/sssdoptions.py:66 msgid "" "If a shell stored in central directory is allowed but not available, use " "this fallback" @@ -231,16 +233,16 @@ msgstr "" "Если командная оболочка из центрального каталога разрешена, но не доступна, " "использовать эту как запасную" -#: src/config/SSSDConfig/sssdoptions.py:71 +#: src/config/SSSDConfig/sssdoptions.py:67 msgid "Shell to use if the provider does not list one" msgstr "" "Оболочка, которая будет использоваться, если поставщиком оболочка не указана" -#: src/config/SSSDConfig/sssdoptions.py:72 +#: src/config/SSSDConfig/sssdoptions.py:68 msgid "How long will be in-memory cache records valid" msgstr "Насколько долго записи кэша в памяти будут оставаться действительными" -#: src/config/SSSDConfig/sssdoptions.py:74 +#: src/config/SSSDConfig/sssdoptions.py:70 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for passwd requests" @@ -248,7 +250,7 @@ msgstr "" "Размер (в мегабайтах) таблицы данных, которая размещена в быстром кэше в " "памяти для запросов passwd" -#: src/config/SSSDConfig/sssdoptions.py:76 +#: src/config/SSSDConfig/sssdoptions.py:72 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for group requests" @@ -256,7 +258,7 @@ msgstr "" "Размер (в мегабайтах) таблицы данных, которая размещена в быстром кэше в " "памяти для запросов group" -#: src/config/SSSDConfig/sssdoptions.py:78 +#: src/config/SSSDConfig/sssdoptions.py:74 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for initgroups requests" @@ -264,7 +266,7 @@ msgstr "" "Размер (в мегабайтах) таблицы данных, которая размещена в быстром кэше в " "памяти для запросов групп инициализации" -#: src/config/SSSDConfig/sssdoptions.py:79 +#: src/config/SSSDConfig/sssdoptions.py:75 msgid "" "The value of this option will be used in the expansion of the " "override_homedir option if the template contains the format string %H." @@ -272,7 +274,7 @@ msgstr "" "Значение этого параметра будет использоваться в расширении параметра " "override_homedir, если шаблон содержит строку формата %H." -#: src/config/SSSDConfig/sssdoptions.py:81 +#: src/config/SSSDConfig/sssdoptions.py:77 msgid "" "Specifies time in seconds for which the list of subdomains will be " "considered valid." @@ -280,7 +282,7 @@ msgstr "" "Указывает время в секундах, в течение которого список поддоменов считается " "действительным." -#: src/config/SSSDConfig/sssdoptions.py:83 +#: src/config/SSSDConfig/sssdoptions.py:79 msgid "" "The entry cache can be set to automatically update entries in the background " "if they are requested beyond a percentage of the entry_cache_timeout value " @@ -290,17 +292,17 @@ msgstr "" "фоновомрежиме, если запрос о них поступает позже срока, определённого в " "процентах от значенияentry_cache_timeout для домена." -#: src/config/SSSDConfig/sssdoptions.py:88 +#: src/config/SSSDConfig/sssdoptions.py:84 msgid "How long to allow cached logins between online logins (days)" msgstr "" "Разрешённый интервал кэшированных входов между интерактивными входами (в " "днях)" -#: src/config/SSSDConfig/sssdoptions.py:89 +#: src/config/SSSDConfig/sssdoptions.py:85 msgid "How many failed logins attempts are allowed when offline" msgstr "Разрешённое количество неудачных попыток неинтерактивного входа" -#: src/config/SSSDConfig/sssdoptions.py:91 +#: src/config/SSSDConfig/sssdoptions.py:87 msgid "" "How long (minutes) to deny login after offline_failed_login_attempts has " "been reached" @@ -308,103 +310,104 @@ msgstr "" "Временной интервал (в минутах), в течение которого будет запрещён вход после " "достижения offline_failed_login_attempts" -#: src/config/SSSDConfig/sssdoptions.py:92 +#: src/config/SSSDConfig/sssdoptions.py:88 msgid "What kind of messages are displayed to the user during authentication" msgstr "" "Какие сообщения будут показаны пользователю во время проверки подлинности" -#: src/config/SSSDConfig/sssdoptions.py:93 +#: src/config/SSSDConfig/sssdoptions.py:89 msgid "Filter PAM responses sent to the pam_sss" msgstr "Фильтровать ответы PAM, отправленные pam_sss" -#: src/config/SSSDConfig/sssdoptions.py:94 +#: src/config/SSSDConfig/sssdoptions.py:90 msgid "How many seconds to keep identity information cached for PAM requests" msgstr "" "Разрешённое количество секунд, в течение которого данные идентификации " "хранятся в кэше для запросов PAM" -#: src/config/SSSDConfig/sssdoptions.py:95 +#: src/config/SSSDConfig/sssdoptions.py:91 msgid "How many days before password expiration a warning should be displayed" msgstr "" "Разрешённое количество дней до показа предупреждения об истечении срока " "действия пароля" -#: src/config/SSSDConfig/sssdoptions.py:96 +#: src/config/SSSDConfig/sssdoptions.py:92 msgid "List of trusted uids or user's name" msgstr "Список доверенных UID или имён пользователей" -#: src/config/SSSDConfig/sssdoptions.py:97 +#: src/config/SSSDConfig/sssdoptions.py:93 msgid "List of domains accessible even for untrusted users." msgstr "Список доменов, доступных даже для недоверенных пользователей." -#: src/config/SSSDConfig/sssdoptions.py:98 +#: src/config/SSSDConfig/sssdoptions.py:94 msgid "Message printed when user account is expired." msgstr "" "Сообщение, которое выводится при истечении срока действия учётной записи " "пользователя." -#: src/config/SSSDConfig/sssdoptions.py:99 +#: src/config/SSSDConfig/sssdoptions.py:95 msgid "Message printed when user account is locked." msgstr "" "Сообщение, которое выводится при блокировке учётной записи пользователя." -#: src/config/SSSDConfig/sssdoptions.py:100 +#: src/config/SSSDConfig/sssdoptions.py:96 msgid "Allow certificate based/Smartcard authentication." msgstr "Разрешить проверку подлинности на основе сертификата или смарт-карты." -#: src/config/SSSDConfig/sssdoptions.py:101 +#: src/config/SSSDConfig/sssdoptions.py:97 msgid "Path to certificate database with PKCS#11 modules." msgstr "Путь к базе данных сертификатов с модулями PKCS#11." -#: src/config/SSSDConfig/sssdoptions.py:102 +#: src/config/SSSDConfig/sssdoptions.py:98 msgid "Tune certificate verification for PAM authentication." -msgstr "Настроить проверку сертификатов для проверки подлинности с помощью PAM." +msgstr "" +"Настроить проверку сертификатов для проверки подлинности с помощью PAM." -#: src/config/SSSDConfig/sssdoptions.py:103 +#: src/config/SSSDConfig/sssdoptions.py:99 msgid "How many seconds will pam_sss wait for p11_child to finish" msgstr "" "Разрешённое количество секунд, в течение которого pam_sss ожидает завершения " "работы p11_child" -#: src/config/SSSDConfig/sssdoptions.py:104 +#: src/config/SSSDConfig/sssdoptions.py:100 msgid "Which PAM services are permitted to contact application domains" msgstr "" "Указывает, каким службам PAM разрешено устанавливать соединение с доменами " "приложений" -#: src/config/SSSDConfig/sssdoptions.py:105 +#: src/config/SSSDConfig/sssdoptions.py:101 msgid "Allowed services for using smartcards" msgstr "Разрешённые службы для использования смарт-карт" -#: src/config/SSSDConfig/sssdoptions.py:106 +#: src/config/SSSDConfig/sssdoptions.py:102 msgid "Additional timeout to wait for a card if requested" msgstr "Дополнительный тайм-аут для ожидания карты в случае запроса" -#: src/config/SSSDConfig/sssdoptions.py:107 +#: src/config/SSSDConfig/sssdoptions.py:103 msgid "" "PKCS#11 URI to restrict the selection of devices for Smartcard authentication" msgstr "" "URI PKCS#11 для ограничения перечня устройств с проверкой подлинности по " "смарт-карте" -#: src/config/SSSDConfig/sssdoptions.py:108 +#: src/config/SSSDConfig/sssdoptions.py:104 msgid "When shall the PAM responder force an initgroups request" msgstr "" "Когда ответчику PAM следует принудительно выполнять запрос групп " "инициализации" -#: src/config/SSSDConfig/sssdoptions.py:109 +#: src/config/SSSDConfig/sssdoptions.py:105 msgid "List of PAM services that are allowed to authenticate with GSSAPI." msgstr "" "Список служб PAM, которым разрешена проверка подлинности с помощью GSSAPI." -#: src/config/SSSDConfig/sssdoptions.py:110 +#: src/config/SSSDConfig/sssdoptions.py:106 msgid "Whether to match authenticated UPN with target user" msgstr "" "Следует ли устанавливать соответствие имени участника-пользователя (UPN), " "прошедшего проверку подлинности, целевому пользователю" -#: src/config/SSSDConfig/sssdoptions.py:111 +#: src/config/SSSDConfig/sssdoptions.py:107 msgid "" "List of pairs : that must be enforced " "for PAM access with GSSAPI authentication" @@ -413,37 +416,47 @@ msgstr "" "быть принудительно установлен доступ PAM с проверкой подлинности с помощью " "GSSAPI" -#: src/config/SSSDConfig/sssdoptions.py:113 +#: src/config/SSSDConfig/sssdoptions.py:109 +msgid "" +"List of triples :: that assigns " +"additional information from the Kerberos ticket to an authentication " +"indicator." +msgstr "" +"Список троек <тип>:<значение>:<индикатор проверки подлинности>, который " +"назначает дополнительную информацию из билета Kerberos индикатору проверки " +"подлинности." + +#: src/config/SSSDConfig/sssdoptions.py:112 msgid "Allow passkey device authentication." msgstr "Разрешить проверку подлинности на основе ключа доступа." -#: src/config/SSSDConfig/sssdoptions.py:114 +#: src/config/SSSDConfig/sssdoptions.py:113 msgid "How many seconds will pam_sss wait for passkey_child to finish" msgstr "" "Разрешённое количество секунд, в течение которого pam_sss ожидает завершения " "работы passkey_child" -#: src/config/SSSDConfig/sssdoptions.py:115 +#: src/config/SSSDConfig/sssdoptions.py:114 msgid "Enable debugging in the libfido2 library" msgstr "Включить отладку в библиотеке libfido2" -#: src/config/SSSDConfig/sssdoptions.py:116 +#: src/config/SSSDConfig/sssdoptions.py:115 msgid "Enable JSON protocol for authentication methods selection." msgstr "Включить JSON-протокол для выбора методов аутентификации." -#: src/config/SSSDConfig/sssdoptions.py:119 +#: src/config/SSSDConfig/sssdoptions.py:118 msgid "Whether to evaluate the time-based attributes in sudo rules" msgstr "" "Следует ли обрабатывать связанные с временными ограничениями атрибуты правил " "sudo" -#: src/config/SSSDConfig/sssdoptions.py:120 +#: src/config/SSSDConfig/sssdoptions.py:119 msgid "If true, SSSD will switch back to lower-wins ordering logic" msgstr "" "Если значение «true», SSSD вернётся к логике упорядочивания «побеждает самое " "низкое»" -#: src/config/SSSDConfig/sssdoptions.py:121 +#: src/config/SSSDConfig/sssdoptions.py:120 msgid "" "Maximum number of rules that can be refreshed at once. If this is exceeded, " "full refresh is performed." @@ -451,11 +464,11 @@ msgstr "" "Максимальное количество правил, которые можно обновить одновременно. Если " "это количество превышено, будет выполнено полное обновление." -#: src/config/SSSDConfig/sssdoptions.py:128 +#: src/config/SSSDConfig/sssdoptions.py:127 msgid "Whether to hash host names and addresses in the known_hosts file" msgstr "Следует ли хэшировать имена и адреса узлов в файле known_hosts" -#: src/config/SSSDConfig/sssdoptions.py:129 +#: src/config/SSSDConfig/sssdoptions.py:128 msgid "" "How many seconds to keep a host in the known_hosts file after its host keys " "were requested" @@ -463,15 +476,15 @@ msgstr "" "Разрешённое количество секунд, в течение которого узел хранится в файле " "known_hosts после запроса ключей этого узла" -#: src/config/SSSDConfig/sssdoptions.py:131 +#: src/config/SSSDConfig/sssdoptions.py:130 msgid "Path to storage of trusted CA certificates" msgstr "Путь к хранилищу доверенных сертификатов CA" -#: src/config/SSSDConfig/sssdoptions.py:132 +#: src/config/SSSDConfig/sssdoptions.py:131 msgid "Allow to generate ssh-keys from certificates" msgstr "Разрешить генерировать ключи SSH из сертификатов" -#: src/config/SSSDConfig/sssdoptions.py:133 +#: src/config/SSSDConfig/sssdoptions.py:132 msgid "" "Use the following matching rules to filter the certificates for ssh-key " "generation" @@ -479,24 +492,24 @@ msgstr "" "Использовать следующие правила установления соответствия при фильтрации " "сертификатов для создания ключей SSH" -#: src/config/SSSDConfig/sssdoptions.py:137 +#: src/config/SSSDConfig/sssdoptions.py:136 msgid "List of UIDs or user names allowed to access the PAC responder" msgstr "" "Список UID или имён пользователей, которым разрешён доступ к ответчику PAC" -#: src/config/SSSDConfig/sssdoptions.py:138 +#: src/config/SSSDConfig/sssdoptions.py:137 msgid "How long the PAC data is considered valid" msgstr "Как долго данные PAC будут считаться действительными" -#: src/config/SSSDConfig/sssdoptions.py:139 +#: src/config/SSSDConfig/sssdoptions.py:138 msgid "Validate the PAC" msgstr "Проверить PAC" -#: src/config/SSSDConfig/sssdoptions.py:142 +#: src/config/SSSDConfig/sssdoptions.py:141 msgid "List of user attributes the InfoPipe is allowed to publish" msgstr "Список атрибутов пользователя, которые разрешено публиковать InfoPipe" -#: src/config/SSSDConfig/sssdoptions.py:145 +#: src/config/SSSDConfig/sssdoptions.py:144 msgid "" "One of the following strings specifying the scope of session recording: none " "- No users are recorded. some - Users/groups specified by users and groups " @@ -507,7 +520,7 @@ msgstr "" "группы,которые указаны параметрами users и groups; all — записывать всех " "пользователей." -#: src/config/SSSDConfig/sssdoptions.py:148 +#: src/config/SSSDConfig/sssdoptions.py:147 msgid "" "A comma-separated list of users which should have session recording enabled. " "Matches user names as returned by NSS. I.e. after the possible space " @@ -518,7 +531,7 @@ msgstr "" "возвращённым NSS, то есть после возможной замены пробелов, смены регистра и " "так далее." -#: src/config/SSSDConfig/sssdoptions.py:150 +#: src/config/SSSDConfig/sssdoptions.py:149 msgid "" "A comma-separated list of groups, members of which should have session " "recording enabled. Matches group names as returned by NSS. I.e. after the " @@ -528,7 +541,7 @@ msgstr "" "сеансов. Соответствие списку устанавливается по именам групп, возвращённым " "NSS, то есть после возможной замены пробелов, смены регистра и так далее." -#: src/config/SSSDConfig/sssdoptions.py:153 +#: src/config/SSSDConfig/sssdoptions.py:152 msgid "" "A comma-separated list of users to be excluded from recording, only when " "scope=all" @@ -536,7 +549,7 @@ msgstr "" "Разделённый запятыми список пользователей, которые исключаются из записи; " "только если scope=all" -#: src/config/SSSDConfig/sssdoptions.py:154 +#: src/config/SSSDConfig/sssdoptions.py:153 msgid "" "A comma-separated list of groups, members of which should be excluded from " "recording, only when scope=all. " @@ -544,79 +557,79 @@ msgstr "" "Разделённый запятыми список групп, участники которых исключаются из записи; " "только если scope=all. " -#: src/config/SSSDConfig/sssdoptions.py:158 +#: src/config/SSSDConfig/sssdoptions.py:157 msgid "Identity provider" msgstr "Поставщик данных для идентификации" -#: src/config/SSSDConfig/sssdoptions.py:159 +#: src/config/SSSDConfig/sssdoptions.py:158 msgid "Authentication provider" msgstr "Поставщик данных для проверки подлинности" -#: src/config/SSSDConfig/sssdoptions.py:160 +#: src/config/SSSDConfig/sssdoptions.py:159 msgid "Access control provider" msgstr "Поставщик данных для контроля доступа" -#: src/config/SSSDConfig/sssdoptions.py:161 +#: src/config/SSSDConfig/sssdoptions.py:160 msgid "Password change provider" msgstr "Поставщик операции смены пароля" -#: src/config/SSSDConfig/sssdoptions.py:162 +#: src/config/SSSDConfig/sssdoptions.py:161 msgid "SUDO provider" msgstr "Поставщик данных SUDO" -#: src/config/SSSDConfig/sssdoptions.py:163 +#: src/config/SSSDConfig/sssdoptions.py:162 msgid "Autofs provider" msgstr "Поставщик данных Autofs" -#: src/config/SSSDConfig/sssdoptions.py:164 +#: src/config/SSSDConfig/sssdoptions.py:163 msgid "Host identity provider" msgstr "Поставщик данных для идентификации узла" -#: src/config/SSSDConfig/sssdoptions.py:165 +#: src/config/SSSDConfig/sssdoptions.py:164 msgid "SELinux provider" msgstr "Поставщик данных SELinux" -#: src/config/SSSDConfig/sssdoptions.py:166 +#: src/config/SSSDConfig/sssdoptions.py:165 msgid "Session management provider" msgstr "Поставщик данных управления сеансами" -#: src/config/SSSDConfig/sssdoptions.py:167 +#: src/config/SSSDConfig/sssdoptions.py:166 msgid "Resolver provider" msgstr "Поставщик данных сопоставителя" -#: src/config/SSSDConfig/sssdoptions.py:170 +#: src/config/SSSDConfig/sssdoptions.py:169 msgid "Whether the domain is usable by the OS or by applications" msgstr "Определяет, может ли домен использоваться ОС или приложениями" -#: src/config/SSSDConfig/sssdoptions.py:171 +#: src/config/SSSDConfig/sssdoptions.py:170 msgid "Enable or disable the domain" msgstr "Включить или отключить домен" -#: src/config/SSSDConfig/sssdoptions.py:172 +#: src/config/SSSDConfig/sssdoptions.py:171 msgid "Minimum user ID" msgstr "Минимальный ID пользователя" -#: src/config/SSSDConfig/sssdoptions.py:173 +#: src/config/SSSDConfig/sssdoptions.py:172 msgid "Maximum user ID" msgstr "Максимальный ID пользователя" -#: src/config/SSSDConfig/sssdoptions.py:174 +#: src/config/SSSDConfig/sssdoptions.py:173 msgid "Enable enumerating all users/groups" msgstr "Включить перечисление всех пользователей/групп" -#: src/config/SSSDConfig/sssdoptions.py:175 +#: src/config/SSSDConfig/sssdoptions.py:174 msgid "Cache credentials for offline login" msgstr "Кэшировать учётные данные для неинтерактивного входа" -#: src/config/SSSDConfig/sssdoptions.py:176 +#: src/config/SSSDConfig/sssdoptions.py:175 msgid "Display users/groups in fully-qualified form" msgstr "Отображать пользователей/группы в полной форме" -#: src/config/SSSDConfig/sssdoptions.py:177 +#: src/config/SSSDConfig/sssdoptions.py:176 msgid "Don't include group members in group lookups" msgstr "Не включать участников группы при поиске групп" -#: src/config/SSSDConfig/sssdoptions.py:178 +#: src/config/SSSDConfig/sssdoptions.py:177 #: src/config/SSSDConfig/sssdoptions.py:190 #: src/config/SSSDConfig/sssdoptions.py:191 #: src/config/SSSDConfig/sssdoptions.py:192 @@ -627,20 +640,20 @@ msgstr "Не включать участников группы при поис msgid "Entry cache timeout length (seconds)" msgstr "Тайм-аут кэша записей (в секундах)" -#: src/config/SSSDConfig/sssdoptions.py:179 +#: src/config/SSSDConfig/sssdoptions.py:178 msgid "" "Restrict or prefer a specific address family when performing DNS lookups" msgstr "" "Ограничивать или предпочитать определённое семейство адресов при выполнении " "запросов DNS" -#: src/config/SSSDConfig/sssdoptions.py:180 +#: src/config/SSSDConfig/sssdoptions.py:179 msgid "How long to keep cached entries after last successful login (days)" msgstr "" "Как долго хранить кэшированные записи после последнего успешного входа (в " "днях)" -#: src/config/SSSDConfig/sssdoptions.py:181 +#: src/config/SSSDConfig/sssdoptions.py:180 msgid "" "How long should SSSD talk to single DNS server before trying next server " "(miliseconds)" @@ -648,19 +661,20 @@ msgstr "" "Как долго SSSD следует пытаться обменяться данными с одним сервером DNS " "перед переходом к следующему (в миллисекундах)" -#: src/config/SSSDConfig/sssdoptions.py:183 +#: src/config/SSSDConfig/sssdoptions.py:182 msgid "How long should keep trying to resolve single DNS query (seconds)" msgstr "Как долго следует пытаться разрешить один запрос DNS (в секундах)" -#: src/config/SSSDConfig/sssdoptions.py:184 +#: src/config/SSSDConfig/sssdoptions.py:183 msgid "How long to wait for replies from DNS when resolving servers (seconds)" -msgstr "Время ожидания ответа DNS при преобразовании имён серверов (в секундах)" +msgstr "" +"Время ожидания ответа DNS при преобразовании имён серверов (в секундах)" -#: src/config/SSSDConfig/sssdoptions.py:185 +#: src/config/SSSDConfig/sssdoptions.py:184 msgid "The domain part of service discovery DNS query" msgstr "Доменная часть DNS-запроса поиска служб" -#: src/config/SSSDConfig/sssdoptions.py:186 +#: src/config/SSSDConfig/sssdoptions.py:185 msgid "" "Specifies the interval, in seconds, that SSSD waits before attempting to " "reconnect to the primary server after a successful connection to the backup " @@ -670,14 +684,19 @@ msgstr "" "попыткой повторного подключения к основному серверу после успешного " "подключения к резервному серверу" -#: src/config/SSSDConfig/sssdoptions.py:188 +#: src/config/SSSDConfig/sssdoptions.py:187 msgid "Override GID value from the identity provider with this value" -msgstr "Переопределять значение GID от поставщика учётных данных этим значением" +msgstr "" +"Переопределять значение GID от поставщика учётных данных этим значением" -#: src/config/SSSDConfig/sssdoptions.py:189 +#: src/config/SSSDConfig/sssdoptions.py:188 msgid "Treat usernames as case sensitive" msgstr "Обрабатывать имена пользователей с учётом регистра" +#: src/config/SSSDConfig/sssdoptions.py:189 +msgid "Lookups by ID are expensive or do not work at all" +msgstr "Поиск по ID обходится дорого или вообще не работает" + #: src/config/SSSDConfig/sssdoptions.py:197 msgid "How often should expired entries be refreshed in background" msgstr "" @@ -790,7 +809,8 @@ msgstr "Показать предупреждение за N дней до ис #: src/config/SSSDConfig/sssdoptions.py:221 msgid "" "Various tags stored by the realmd configuration service for this domain." -msgstr "Различные метки, сохранённые службой настройки realmd для этого домена." +msgstr "" +"Различные метки, сохранённые службой настройки realmd для этого домена." #: src/config/SSSDConfig/sssdoptions.py:222 msgid "" @@ -931,7 +951,7 @@ msgid "Search base for SUBID ranges" msgstr "База поиска для диапазонов SUBID" #: src/config/SSSDConfig/sssdoptions.py:259 -#: src/config/SSSDConfig/sssdoptions.py:506 +#: src/config/SSSDConfig/sssdoptions.py:512 msgid "Which rules should be used to evaluate access control" msgstr "" "Правила, которые используются, чтобы определить достаточность прав доступа" @@ -1091,7 +1111,7 @@ msgid "Enable DNS sites - location based service discovery" msgstr "Включить сайты DNS — обнаружение служб по расположению" #: src/config/SSSDConfig/sssdoptions.py:301 -#: src/config/SSSDConfig/sssdoptions.py:504 +#: src/config/SSSDConfig/sssdoptions.py:510 msgid "LDAP filter to determine access privileges" msgstr "Фильтр LDAP для определения прав доступа" @@ -1115,37 +1135,37 @@ msgid "" "PAM service names that map to the GPO (Deny)InteractiveLogonRight policy " "settings" msgstr "" -"Имена служб PAM, которые сопоставляются параметрам политики GPO (Deny)" -"InteractiveLogonRight" +"Имена служб PAM, которые сопоставляются параметрам политики GPO " +"(Deny)InteractiveLogonRight" #: src/config/SSSDConfig/sssdoptions.py:307 msgid "" "PAM service names that map to the GPO (Deny)RemoteInteractiveLogonRight " "policy settings" msgstr "" -"Имена служб PAM, которые сопоставляются параметрам политики GPO (Deny)" -"RemoteInteractiveLogonRight" +"Имена служб PAM, которые сопоставляются параметрам политики GPO " +"(Deny)RemoteInteractiveLogonRight" #: src/config/SSSDConfig/sssdoptions.py:309 msgid "" "PAM service names that map to the GPO (Deny)NetworkLogonRight policy settings" msgstr "" -"Имена служб PAM, которые сопоставляются параметрам политики GPO (Deny)" -"NetworkLogonRight" +"Имена служб PAM, которые сопоставляются параметрам политики GPO " +"(Deny)NetworkLogonRight" #: src/config/SSSDConfig/sssdoptions.py:310 msgid "" "PAM service names that map to the GPO (Deny)BatchLogonRight policy settings" msgstr "" -"Имена служб PAM, которые сопоставляются параметрам политики GPO (Deny)" -"BatchLogonRight" +"Имена служб PAM, которые сопоставляются параметрам политики GPO " +"(Deny)BatchLogonRight" #: src/config/SSSDConfig/sssdoptions.py:311 msgid "" "PAM service names that map to the GPO (Deny)ServiceLogonRight policy settings" msgstr "" -"Имена служб PAM, которые сопоставляются параметрам политики GPO (Deny)" -"ServiceLogonRight" +"Имена служб PAM, которые сопоставляются параметрам политики GPO " +"(Deny)ServiceLogonRight" #: src/config/SSSDConfig/sssdoptions.py:312 msgid "PAM service names for which GPO-based access is always granted" @@ -1368,7 +1388,8 @@ msgstr "Укажите область авторизации SASL" #: src/config/SSSDConfig/sssdoptions.py:376 msgid "Specify the minimal SSF for LDAP sasl authorization" -msgstr "Укажите минимальное значение SSF для авторизации на LDAP с помощью SASL" +msgstr "" +"Укажите минимальное значение SSF для авторизации на LDAP с помощью SASL" #: src/config/SSSDConfig/sssdoptions.py:377 msgid "Specify the maximal SSF for LDAP sasl authorization" @@ -1538,7 +1559,7 @@ msgid "UUID attribute" msgstr "Атрибут UUID" #: src/config/SSSDConfig/sssdoptions.py:423 -#: src/config/SSSDConfig/sssdoptions.py:464 +#: src/config/SSSDConfig/sssdoptions.py:470 msgid "objectSID attribute" msgstr "Атрибут objectSID" @@ -1665,206 +1686,230 @@ msgid "A list of extra attributes to download along with the user entry" msgstr "" "Список дополнительных атрибутов для загрузки вместе с записью пользователя" +#: src/config/SSSDConfig/sssdoptions.py:456 +msgid "The object class of an subid entry in LDAP." +msgstr "Класс объектов записи subid в LDAP." + #: src/config/SSSDConfig/sssdoptions.py:457 +msgid "Subordinate user ID count attribute" +msgstr "Атрибут количества подчинённых идентификаторов пользователя" + +#: src/config/SSSDConfig/sssdoptions.py:458 +msgid "Subordinate group ID count attribute" +msgstr "Атрибут количества подчинённых идентификаторов группы" + +#: src/config/SSSDConfig/sssdoptions.py:459 +msgid "User ID range start value attribute" +msgstr "Атрибут начального значения диапазона идентификаторов пользователей" + +#: src/config/SSSDConfig/sssdoptions.py:460 +msgid "Group ID range start value attribute" +msgstr "Атрибут начального значения диапазона идентификаторов групп" + +#: src/config/SSSDConfig/sssdoptions.py:461 +msgid "Owner of an entry" +msgstr "Владелец записи" + +#: src/config/SSSDConfig/sssdoptions.py:463 msgid "Base DN for group lookups" msgstr "Base DN для поиска групп" -#: src/config/SSSDConfig/sssdoptions.py:458 +#: src/config/SSSDConfig/sssdoptions.py:464 msgid "Objectclass for groups" msgstr "Класс объектов для групп" -#: src/config/SSSDConfig/sssdoptions.py:459 +#: src/config/SSSDConfig/sssdoptions.py:465 msgid "Group name" msgstr "Имя группы" -#: src/config/SSSDConfig/sssdoptions.py:460 +#: src/config/SSSDConfig/sssdoptions.py:466 msgid "Group password" msgstr "Пароль группы" -#: src/config/SSSDConfig/sssdoptions.py:461 +#: src/config/SSSDConfig/sssdoptions.py:467 msgid "GID attribute" msgstr "Атрибут GID" -#: src/config/SSSDConfig/sssdoptions.py:462 +#: src/config/SSSDConfig/sssdoptions.py:468 msgid "Group member attribute" msgstr "Атрибут участника группы" -#: src/config/SSSDConfig/sssdoptions.py:463 +#: src/config/SSSDConfig/sssdoptions.py:469 msgid "Group UUID attribute" msgstr "Атрибут UUID группы" -#: src/config/SSSDConfig/sssdoptions.py:465 +#: src/config/SSSDConfig/sssdoptions.py:471 msgid "Modification time attribute for groups" msgstr "Атрибут времени изменения для групп" -#: src/config/SSSDConfig/sssdoptions.py:466 +#: src/config/SSSDConfig/sssdoptions.py:472 msgid "Type of the group and other flags" msgstr "Тип группы и другие флаги" -#: src/config/SSSDConfig/sssdoptions.py:467 +#: src/config/SSSDConfig/sssdoptions.py:473 msgid "The LDAP group external member attribute" msgstr "Атрибут LDAP внешнего участника группы" -#: src/config/SSSDConfig/sssdoptions.py:468 +#: src/config/SSSDConfig/sssdoptions.py:474 msgid "Maximum nesting level SSSD will follow" msgstr "Максимальный уровень вложенности, который используется SSSD" -#: src/config/SSSDConfig/sssdoptions.py:469 +#: src/config/SSSDConfig/sssdoptions.py:475 msgid "Filter for group lookups" msgstr "Фильтр поиска групп" -#: src/config/SSSDConfig/sssdoptions.py:470 +#: src/config/SSSDConfig/sssdoptions.py:476 msgid "Scope of group lookups" msgstr "Область поиска групп" -#: src/config/SSSDConfig/sssdoptions.py:472 +#: src/config/SSSDConfig/sssdoptions.py:478 msgid "Base DN for netgroup lookups" msgstr "Base DN для поиска сетевых групп" -#: src/config/SSSDConfig/sssdoptions.py:473 +#: src/config/SSSDConfig/sssdoptions.py:479 msgid "Objectclass for netgroups" msgstr "Класс объектов для сетевых групп" -#: src/config/SSSDConfig/sssdoptions.py:474 +#: src/config/SSSDConfig/sssdoptions.py:480 msgid "Netgroup name" msgstr "Имя сетевой группы" -#: src/config/SSSDConfig/sssdoptions.py:475 +#: src/config/SSSDConfig/sssdoptions.py:481 msgid "Netgroups members attribute" msgstr "Атрибут участников сетевых групп" -#: src/config/SSSDConfig/sssdoptions.py:476 +#: src/config/SSSDConfig/sssdoptions.py:482 msgid "Netgroup triple attribute" msgstr "Атрибут тройки сетевых групп" -#: src/config/SSSDConfig/sssdoptions.py:477 +#: src/config/SSSDConfig/sssdoptions.py:483 msgid "Modification time attribute for netgroups" msgstr "Атрибут времени изменения для сетевых групп" -#: src/config/SSSDConfig/sssdoptions.py:479 +#: src/config/SSSDConfig/sssdoptions.py:485 msgid "Base DN for service lookups" msgstr "Base DN для поиска служб" -#: src/config/SSSDConfig/sssdoptions.py:480 +#: src/config/SSSDConfig/sssdoptions.py:486 msgid "Objectclass for services" msgstr "Класс объектов для служб" -#: src/config/SSSDConfig/sssdoptions.py:481 +#: src/config/SSSDConfig/sssdoptions.py:487 msgid "Service name attribute" msgstr "Атрибут имени службы" -#: src/config/SSSDConfig/sssdoptions.py:482 +#: src/config/SSSDConfig/sssdoptions.py:488 msgid "Service port attribute" msgstr "Атрибут порта службы" -#: src/config/SSSDConfig/sssdoptions.py:483 +#: src/config/SSSDConfig/sssdoptions.py:489 msgid "Service protocol attribute" msgstr "Атрибут протокола службы" -#: src/config/SSSDConfig/sssdoptions.py:485 +#: src/config/SSSDConfig/sssdoptions.py:491 msgid "Lower bound for ID-mapping" msgstr "Нижняя граница для сопоставления ID" -#: src/config/SSSDConfig/sssdoptions.py:486 +#: src/config/SSSDConfig/sssdoptions.py:492 msgid "Upper bound for ID-mapping" msgstr "Верхняя граница для сопоставления ID" -#: src/config/SSSDConfig/sssdoptions.py:487 +#: src/config/SSSDConfig/sssdoptions.py:493 msgid "Number of IDs for each slice when ID-mapping" msgstr "Количество ID для каждого среза при сопоставлении ID" -#: src/config/SSSDConfig/sssdoptions.py:488 +#: src/config/SSSDConfig/sssdoptions.py:494 msgid "Use autorid-compatible algorithm for ID-mapping" msgstr "Использовать совместимый с autorid алгоритм для сопоставления ID" -#: src/config/SSSDConfig/sssdoptions.py:489 +#: src/config/SSSDConfig/sssdoptions.py:495 msgid "Name of the default domain for ID-mapping" msgstr "Имя домена по умолчанию для сопоставления ID" -#: src/config/SSSDConfig/sssdoptions.py:490 +#: src/config/SSSDConfig/sssdoptions.py:496 msgid "SID of the default domain for ID-mapping" msgstr "SID домена по умолчанию для сопоставления ID" -#: src/config/SSSDConfig/sssdoptions.py:491 +#: src/config/SSSDConfig/sssdoptions.py:497 msgid "Number of secondary slices" msgstr "Количество вторичных срезов" -#: src/config/SSSDConfig/sssdoptions.py:493 +#: src/config/SSSDConfig/sssdoptions.py:499 msgid "Whether to use Token-Groups" msgstr "Следует ли использовать группы маркеров" -#: src/config/SSSDConfig/sssdoptions.py:494 +#: src/config/SSSDConfig/sssdoptions.py:500 msgid "Set lower boundary for allowed IDs from the LDAP server" msgstr "Установить нижнюю границу для разрешённых ID с сервера LDAP" -#: src/config/SSSDConfig/sssdoptions.py:495 +#: src/config/SSSDConfig/sssdoptions.py:501 msgid "Set upper boundary for allowed IDs from the LDAP server" msgstr "Установить верхнюю границу для разрешённых ID с сервера LDAP" -#: src/config/SSSDConfig/sssdoptions.py:496 +#: src/config/SSSDConfig/sssdoptions.py:502 msgid "DN for ppolicy queries" msgstr "DN для запросов ppolicy" -#: src/config/SSSDConfig/sssdoptions.py:497 +#: src/config/SSSDConfig/sssdoptions.py:503 msgid "How many maximum entries to fetch during a wildcard request" msgstr "" "Максимальное количество записей, которое может быть получено при запросе с " "использованием подстановочных знаков" -#: src/config/SSSDConfig/sssdoptions.py:498 +#: src/config/SSSDConfig/sssdoptions.py:504 msgid "Set libldap debug level" msgstr "Установить уровень отладки libldap" -#: src/config/SSSDConfig/sssdoptions.py:501 +#: src/config/SSSDConfig/sssdoptions.py:507 msgid "Policy to evaluate the password expiration" msgstr "Политика вычисления окончания срока действия пароля" -#: src/config/SSSDConfig/sssdoptions.py:505 +#: src/config/SSSDConfig/sssdoptions.py:511 msgid "Which attributes shall be used to evaluate if an account is expired" msgstr "" "Атрибуты, которые используются, чтобы определить, не истёк ли срок действия " "учётной записи" -#: src/config/SSSDConfig/sssdoptions.py:509 +#: src/config/SSSDConfig/sssdoptions.py:515 msgid "URI of an LDAP server where password changes are allowed" msgstr "URI сервера LDAP, на котором разрешена смена паролей" -#: src/config/SSSDConfig/sssdoptions.py:510 +#: src/config/SSSDConfig/sssdoptions.py:516 msgid "URI of a backup LDAP server where password changes are allowed" msgstr "URI резервного сервера LDAP, на котором разрешена смена паролей" -#: src/config/SSSDConfig/sssdoptions.py:511 +#: src/config/SSSDConfig/sssdoptions.py:517 msgid "DNS service name for LDAP password change server" msgstr "Имя сервера смены паролей LDAP в службе DNS" -#: src/config/SSSDConfig/sssdoptions.py:512 +#: src/config/SSSDConfig/sssdoptions.py:518 msgid "" "Whether to update the ldap_user_shadow_last_change attribute after a " "password change" msgstr "" "Следует ли обновлять атрибут ldap_user_shadow_last_change после смены пароля" -#: src/config/SSSDConfig/sssdoptions.py:516 +#: src/config/SSSDConfig/sssdoptions.py:522 msgid "Base DN for sudo rules lookups" msgstr "Base DN для поиска правил sudo" -#: src/config/SSSDConfig/sssdoptions.py:517 +#: src/config/SSSDConfig/sssdoptions.py:523 msgid "Automatic full refresh period" msgstr "Период полного автоматического обновления данных" -#: src/config/SSSDConfig/sssdoptions.py:518 +#: src/config/SSSDConfig/sssdoptions.py:524 msgid "Automatic smart refresh period" msgstr "Период автоматического интеллектуального обновления данных" -#: src/config/SSSDConfig/sssdoptions.py:519 +#: src/config/SSSDConfig/sssdoptions.py:525 msgid "Smart and full refresh random offset" msgstr "Случайная задержка интеллектуального и полного обновления" -#: src/config/SSSDConfig/sssdoptions.py:520 +#: src/config/SSSDConfig/sssdoptions.py:526 msgid "Whether to filter rules by hostname, IP addresses and network" msgstr "Следует ли фильтровать правила по именам узлов, IP-адресам и сетям" -#: src/config/SSSDConfig/sssdoptions.py:521 +#: src/config/SSSDConfig/sssdoptions.py:527 msgid "" "Hostnames and/or fully qualified domain names of this machine to filter sudo " "rules" @@ -1872,156 +1917,156 @@ msgstr "" "Имена узлов и/или полные доменные имена для этого компьютера для фильтрации " "правил sudo" -#: src/config/SSSDConfig/sssdoptions.py:522 +#: src/config/SSSDConfig/sssdoptions.py:528 msgid "IPv4 or IPv6 addresses or network of this machine to filter sudo rules" msgstr "" "Адреса IPv4 или IPv6 или сеть этого компьютера для фильтрации списка правил " "sudo" -#: src/config/SSSDConfig/sssdoptions.py:523 +#: src/config/SSSDConfig/sssdoptions.py:529 msgid "Whether to include rules that contains netgroup in host attribute" msgstr "" "Следует ли включать правила, которые содержат сетевую группу в атрибуте узла" -#: src/config/SSSDConfig/sssdoptions.py:524 +#: src/config/SSSDConfig/sssdoptions.py:530 msgid "" "Whether to include rules that contains regular expression in host attribute" msgstr "" "Следует ли включать правила, которые содержат регулярное выражение в " "атрибуте узла" -#: src/config/SSSDConfig/sssdoptions.py:525 +#: src/config/SSSDConfig/sssdoptions.py:531 msgid "Object class for sudo rules" msgstr "Класс объектов для правил sudo" -#: src/config/SSSDConfig/sssdoptions.py:526 +#: src/config/SSSDConfig/sssdoptions.py:532 msgid "Name of attribute that is used as object class for sudo rules" msgstr "Имя атрибута, который используется как класс объектов для правил sudo" -#: src/config/SSSDConfig/sssdoptions.py:527 +#: src/config/SSSDConfig/sssdoptions.py:533 msgid "Sudo rule name" msgstr "Имя правила sudo" -#: src/config/SSSDConfig/sssdoptions.py:528 +#: src/config/SSSDConfig/sssdoptions.py:534 msgid "Sudo rule command attribute" msgstr "Атрибут command (команда) правила sudo" -#: src/config/SSSDConfig/sssdoptions.py:529 +#: src/config/SSSDConfig/sssdoptions.py:535 msgid "Sudo rule host attribute" msgstr "Атрибут host (узел) правила sudo" -#: src/config/SSSDConfig/sssdoptions.py:530 +#: src/config/SSSDConfig/sssdoptions.py:536 msgid "Sudo rule user attribute" msgstr "Атрибут user (пользователь) правила sudo" -#: src/config/SSSDConfig/sssdoptions.py:531 +#: src/config/SSSDConfig/sssdoptions.py:537 msgid "Sudo rule option attribute" msgstr "Атрибут option (параметр) правила sudo" -#: src/config/SSSDConfig/sssdoptions.py:532 +#: src/config/SSSDConfig/sssdoptions.py:538 msgid "Sudo rule runas attribute" msgstr "Атрибут runas (запуск от имени) правила sudo" -#: src/config/SSSDConfig/sssdoptions.py:533 +#: src/config/SSSDConfig/sssdoptions.py:539 msgid "Sudo rule runasuser attribute" msgstr "" "Атрибут runasuser (пользователь, от имени которого выполняется запуск) " "правила sudo" -#: src/config/SSSDConfig/sssdoptions.py:534 +#: src/config/SSSDConfig/sssdoptions.py:540 msgid "Sudo rule runasgroup attribute" msgstr "" "Атрибут runasgroup (группа, от имени которой выполняется запуск) правила sudo" -#: src/config/SSSDConfig/sssdoptions.py:535 +#: src/config/SSSDConfig/sssdoptions.py:541 msgid "Sudo rule notbefore attribute" msgstr "Атрибут notbefore (предельное время начала действия) правила sudo" -#: src/config/SSSDConfig/sssdoptions.py:536 +#: src/config/SSSDConfig/sssdoptions.py:542 msgid "Sudo rule notafter attribute" msgstr "Атрибут notafter (предельное время окончания действия) правила sudo" -#: src/config/SSSDConfig/sssdoptions.py:537 +#: src/config/SSSDConfig/sssdoptions.py:543 msgid "Sudo rule order attribute" msgstr "Атрибут order (порядок) правила sudo" -#: src/config/SSSDConfig/sssdoptions.py:540 +#: src/config/SSSDConfig/sssdoptions.py:546 msgid "Object class for automounter maps" msgstr "Класс объектов для карт автоматического монтирования" -#: src/config/SSSDConfig/sssdoptions.py:541 +#: src/config/SSSDConfig/sssdoptions.py:547 msgid "Automounter map name attribute" msgstr "Атрибут имени карты автоматического монтирования" -#: src/config/SSSDConfig/sssdoptions.py:542 +#: src/config/SSSDConfig/sssdoptions.py:548 msgid "Object class for automounter map entries" msgstr "Класс объектов для записей карт автоматического монтирования" -#: src/config/SSSDConfig/sssdoptions.py:543 +#: src/config/SSSDConfig/sssdoptions.py:549 msgid "Automounter map entry key attribute" msgstr "Атрибут ключа записи карты автоматического монтирования" -#: src/config/SSSDConfig/sssdoptions.py:544 +#: src/config/SSSDConfig/sssdoptions.py:550 msgid "Automounter map entry value attribute" msgstr "Атрибут значения записи карты автоматического монтирования" -#: src/config/SSSDConfig/sssdoptions.py:545 +#: src/config/SSSDConfig/sssdoptions.py:551 msgid "Base DN for automounter map lookups" msgstr "Base DN для поиска карт автоматического монтирования" -#: src/config/SSSDConfig/sssdoptions.py:546 +#: src/config/SSSDConfig/sssdoptions.py:552 msgid "The name of the automount master map in LDAP." msgstr "Имя основной карты автоматического монтирования в LDAP." -#: src/config/SSSDConfig/sssdoptions.py:549 +#: src/config/SSSDConfig/sssdoptions.py:555 msgid "Base DN for IP hosts lookups" msgstr "Base DN для поиска IP-узлов" -#: src/config/SSSDConfig/sssdoptions.py:550 +#: src/config/SSSDConfig/sssdoptions.py:556 msgid "Object class for IP hosts" msgstr "Класс объектов для IP-узлов" -#: src/config/SSSDConfig/sssdoptions.py:551 +#: src/config/SSSDConfig/sssdoptions.py:557 msgid "IP host name attribute" msgstr "Атрибут имени IP-узла" -#: src/config/SSSDConfig/sssdoptions.py:552 +#: src/config/SSSDConfig/sssdoptions.py:558 msgid "IP host number (address) attribute" msgstr "Атрибут номера (адреса) IP-узла" -#: src/config/SSSDConfig/sssdoptions.py:553 +#: src/config/SSSDConfig/sssdoptions.py:559 msgid "IP host entryUSN attribute" msgstr "Атрибут entryUSN IP-узла" -#: src/config/SSSDConfig/sssdoptions.py:554 +#: src/config/SSSDConfig/sssdoptions.py:560 msgid "Base DN for IP networks lookups" msgstr "Base DN для поиска IP-сетей" -#: src/config/SSSDConfig/sssdoptions.py:555 +#: src/config/SSSDConfig/sssdoptions.py:561 msgid "Object class for IP networks" msgstr "Класс объектов для IP-сетей" -#: src/config/SSSDConfig/sssdoptions.py:556 +#: src/config/SSSDConfig/sssdoptions.py:562 msgid "IP network name attribute" msgstr "Атрибут имени IP-сети" -#: src/config/SSSDConfig/sssdoptions.py:557 +#: src/config/SSSDConfig/sssdoptions.py:563 msgid "IP network number (address) attribute" msgstr "Атрибут номера (адреса) IP-сети" -#: src/config/SSSDConfig/sssdoptions.py:558 +#: src/config/SSSDConfig/sssdoptions.py:564 msgid "IP network entryUSN attribute" msgstr "Атрибут entryUSN IP-сети" -#: src/config/SSSDConfig/sssdoptions.py:561 +#: src/config/SSSDConfig/sssdoptions.py:567 msgid "Comma separated list of allowed users" msgstr "Разделённый запятыми список разрешённых пользователей" -#: src/config/SSSDConfig/sssdoptions.py:562 +#: src/config/SSSDConfig/sssdoptions.py:568 msgid "Comma separated list of prohibited users" msgstr "Разделённый запятыми список запрещённых пользователей" -#: src/config/SSSDConfig/sssdoptions.py:563 +#: src/config/SSSDConfig/sssdoptions.py:569 msgid "" "Comma separated list of groups that are allowed to log in. This applies only " "to groups within this SSSD domain. Local groups are not evaluated." @@ -2030,7 +2075,7 @@ msgstr "" "систему. Применимо только к группам внутри этого домена SSSD. Локальные " "группы не обрабатываются." -#: src/config/SSSDConfig/sssdoptions.py:565 +#: src/config/SSSDConfig/sssdoptions.py:571 msgid "" "Comma separated list of groups that are explicitly denied access. This " "applies only to groups within this SSSD domain. Local groups are not " @@ -2040,32 +2085,32 @@ msgstr "" "доступ. Применимо только к группам внутри этого домена SSSD. Локальные " "группы не обрабатываются." -#: src/config/SSSDConfig/sssdoptions.py:569 +#: src/config/SSSDConfig/sssdoptions.py:575 msgid "The number of preforked proxy children." msgstr "Количество предварительно ответвлённых дочерних прокси." -#: src/config/SSSDConfig/sssdoptions.py:572 +#: src/config/SSSDConfig/sssdoptions.py:578 msgid "The name of the NSS library to use" msgstr "Имя используемой библиотеки NSS" -#: src/config/SSSDConfig/sssdoptions.py:573 +#: src/config/SSSDConfig/sssdoptions.py:579 msgid "The name of the NSS library to use for hosts and networks lookups" msgstr "" "Имя библиотеки NSS, которая будет использоваться для поиска узлов и сетей" -#: src/config/SSSDConfig/sssdoptions.py:574 +#: src/config/SSSDConfig/sssdoptions.py:580 msgid "Whether to look up canonical group name from cache if possible" msgstr "Следует ли искать каноническое имя группы в кэше, когда это возможно" -#: src/config/SSSDConfig/sssdoptions.py:577 +#: src/config/SSSDConfig/sssdoptions.py:583 msgid "PAM stack to use" msgstr "Используемый стек PAM" -#: src/config/SSSDConfig/sssdoptions.py:580 +#: src/config/SSSDConfig/sssdoptions.py:586 msgid "Path of passwd file sources." msgstr "Путь к исходному тексту файла passwd." -#: src/config/SSSDConfig/sssdoptions.py:581 +#: src/config/SSSDConfig/sssdoptions.py:587 msgid "Path of group file sources." msgstr "Путь к исходному тексту файла group." @@ -2096,108 +2141,112 @@ msgstr "" msgid "Option -i|--interactive is not allowed together with -D|--daemon\n" msgstr "Параметр -i|--interactive нельзя использовать вместе с -D|--daemon\n" -#: src/monitor/monitor.c:1836 +#: src/monitor/monitor.c:1838 msgid "Failed to get initial capabilities\n" msgstr "Не удалось получить исходные возможности\n" -#: src/monitor/monitor.c:1847 +#: src/monitor/monitor.c:1849 msgid "Non-root service user support isn't built. Can't run under %" msgstr "" "Поддержка пользователей службы без полномочий root не реализована. " "Невозможно запустить ниже %" -#: src/monitor/monitor.c:1864 +#: src/monitor/monitor.c:1866 #, c-format msgid "Can't read config: '%s'\n" msgstr "Не возможно прочитать конфигурацию: '%s'\n" -#: src/monitor/monitor.c:1876 +#: src/monitor/monitor.c:1878 #, c-format -msgid "Failed to boostrap SSSD 'monitor' process: %s" -msgstr "Не удалось ускорить процесс «мониторинга» SSSD: %s" +msgid "Failed to bootstrap SSSD 'monitor' process: %s" +msgstr "Не удалось запустить процесс «monitor» SSSD: %s" -#: src/monitor/monitor.c:1971 +#: src/monitor/monitor.c:1973 msgid "Out of memory\n" msgstr "Недостаточно памяти\n" -#: src/providers/krb5/krb5_child.c:4221 +#: src/providers/krb5/krb5_child.c:4316 msgid "Use anonymous PKINIT to request FAST armor ticket" msgstr "Использовать анонимный PKINIT для запроса билета защиты FAST" -#: src/providers/krb5/krb5_child.c:4223 +#: src/providers/krb5/krb5_child.c:4318 msgid "Kerberos realm to use" msgstr "Область действия Kerberos" -#: src/providers/krb5/krb5_child.c:4225 +#: src/providers/krb5/krb5_child.c:4320 msgid "Requested lifetime of the ticket" msgstr "Запрашиваемое время жизни билета" -#: src/providers/krb5/krb5_child.c:4227 +#: src/providers/krb5/krb5_child.c:4322 msgid "Requested renewable lifetime of the ticket" msgstr "Запрашиваемое возобновляемое время жизни билета" -#: src/providers/krb5/krb5_child.c:4229 +#: src/providers/krb5/krb5_child.c:4324 msgid "FAST options ('never', 'try', 'demand')" msgstr "Параметры FAST («never», «try», «demand»)" -#: src/providers/krb5/krb5_child.c:4232 +#: src/providers/krb5/krb5_child.c:4327 msgid "Specifies the server principal to use for FAST" msgstr "Указывает участник-сервер, который следует использовать для FAST" -#: src/providers/krb5/krb5_child.c:4234 +#: src/providers/krb5/krb5_child.c:4329 msgid "Requests canonicalization of the principal name" msgstr "Запрашивает преобразование имени участника в каноническую форму" -#: src/providers/krb5/krb5_child.c:4236 +#: src/providers/krb5/krb5_child.c:4331 msgid "Use custom version of krb5_get_init_creds_password" msgstr "Использовать нестандартную версию krb5_get_init_creds_password" -#: src/providers/krb5/krb5_child.c:4238 +#: src/providers/krb5/krb5_child.c:4333 msgid "Check PAC flags" msgstr "Проверить PAC флаги" -#: src/providers/data_provider_be.c:790 +#: src/providers/krb5/krb5_child.c:4335 +msgid "Set environment variable (KEY=VALUE)" +msgstr "Задать переменную окружения (KEY=VALUE)" + +#: src/providers/data_provider_be.c:786 msgid "Domain of the information provider (mandatory)" msgstr "Домен поставщика информации (обязательный)" -#: src/sss_client/common.c:1165 +#: src/sss_client/common.c:1208 msgid "Socket has wrong ownership or permissions." msgstr "Для сокета установлен неверный владелец или права доступа." -#: src/sss_client/common.c:1168 +#: src/sss_client/common.c:1211 msgid "Unexpected format of the server credential message." msgstr "Некорректный формат сообщения об учётных данных сервера." -#: src/sss_client/common.c:1171 +#: src/sss_client/common.c:1214 msgid "SSSD is not run by trusted user." msgstr "Запуск SSSD выполнен не от имени доверенного пользователя." -#: src/sss_client/common.c:1174 +#: src/sss_client/common.c:1217 msgid "SSSD socket does not exist." msgstr "Сокет SSSD не существует." -#: src/sss_client/common.c:1177 +#: src/sss_client/common.c:1220 msgid "Cannot get stat of SSSD socket." msgstr "Не удалось получить статистику сокета SSSD." -#: src/sss_client/common.c:1182 +#: src/sss_client/common.c:1225 msgid "An error occurred, but no description can be found." msgstr "Произошла ошибка, но не удалось найти её описание." -#: src/sss_client/common.c:1188 +#: src/sss_client/common.c:1231 msgid "Unexpected error while looking for an error description" msgstr "Непредвиденная ошибка при поиске описания ошибки" -#: src/sss_client/pam_sss.c:74 +#: src/sss_client/pam_sss.c:135 msgid "Permission denied. " msgstr "Доступ запрещён. " -#: src/sss_client/pam_sss.c:75 src/sss_client/pam_sss.c:843 -#: src/sss_client/pam_sss.c:854 +#: src/sss_client/pam_sss.c:136 src/sss_client/pam_sss.c:921 +#: src/sss_client/pam_sss.c:932 msgid "Server message: " msgstr "Сообщение сервера: " -#: src/sss_client/pam_sss.c:76 +#: src/sss_client/pam_sss.c:137 msgid "" "Kerberos TGT will not be granted upon login, user experience will be " "affected." @@ -2205,50 +2254,50 @@ msgstr "" "После входа в систему не будет предоставлен TGT Kerberos. Это может помешать " "нормальной работе пользователя." -#: src/sss_client/pam_sss.c:77 +#: src/sss_client/pam_sss.c:138 msgid "Enter PIN:" msgstr "Введите PIN:" -#: src/sss_client/pam_sss.c:320 +#: src/sss_client/pam_sss.c:385 msgid "Passwords do not match" msgstr "Пароли не совпадают" -#: src/sss_client/pam_sss.c:508 +#: src/sss_client/pam_sss.c:584 msgid "Password reset by root is not supported." msgstr "Поддержка сброса пароля пользователем root не предусмотрена." -#: src/sss_client/pam_sss.c:549 +#: src/sss_client/pam_sss.c:625 msgid "Authenticated with cached credentials" msgstr "Проверка подлинности с учётными данными из кэша" -#: src/sss_client/pam_sss.c:550 +#: src/sss_client/pam_sss.c:626 msgid ", your cached password will expire at: " msgstr ", срок действия вашего кэшированного пароля истечёт: " -#: src/sss_client/pam_sss.c:580 +#: src/sss_client/pam_sss.c:656 #, c-format msgid "Your password has expired. You have %1$d grace login(s) remaining." msgstr "Срок действия пароля истёк. Осталось попыток входа в систему: %1$d." -#: src/sss_client/pam_sss.c:630 +#: src/sss_client/pam_sss.c:706 #, c-format msgid "Your password will expire in %1$d %2$s." msgstr "Срок действия пароля истекает через %1$d %2$s." -#: src/sss_client/pam_sss.c:633 +#: src/sss_client/pam_sss.c:709 #, c-format msgid "Your password has expired." msgstr "Срок действия пароля истёк." -#: src/sss_client/pam_sss.c:684 +#: src/sss_client/pam_sss.c:760 msgid "Authentication is denied until: " msgstr "Проверка подлинности запрещена до: " -#: src/sss_client/pam_sss.c:705 +#: src/sss_client/pam_sss.c:781 msgid "System is offline, password change not possible" msgstr "Система находится в автономном режиме, невозможно сменить пароль" -#: src/sss_client/pam_sss.c:720 +#: src/sss_client/pam_sss.c:796 msgid "" "After changing the OTP password, you need to log out and back in order to " "acquire a ticket" @@ -2256,11 +2305,11 @@ msgstr "" "После смены одноразового пароля необходимо выйти из системы и снова войти в " "неё, чтобы получить билет" -#: src/sss_client/pam_sss.c:735 +#: src/sss_client/pam_sss.c:813 msgid "PIN locked" msgstr "PIN заблокирован" -#: src/sss_client/pam_sss.c:750 +#: src/sss_client/pam_sss.c:828 msgid "" "No Kerberos TGT granted as the server does not support this method. Your " "single-sign on(SSO) experience will be affected." @@ -2268,62 +2317,65 @@ msgstr "" "TGT Kerberos не предоставлен, поскольку на сервере не предусмотрена " "поддержка этого метода. Это повлияет на работу системы единого входа (SSO)." -#: src/sss_client/pam_sss.c:840 src/sss_client/pam_sss.c:853 +#: src/sss_client/pam_sss.c:918 src/sss_client/pam_sss.c:931 msgid "Password change failed. " msgstr "Не удалось сменить пароль. " -#: src/sss_client/pam_sss.c:1859 +#: src/sss_client/pam_sss.c:2028 #, c-format -msgid "Authenticate at %1$s and press ENTER." -msgstr "Пожалуйста, авторизуйтесь на %1$s и нажмите ENTER." +msgid "Authenticate at \"%1$s\"." +msgstr "Пройдите проверку подлинности на \"%1$s\"." -#: src/sss_client/pam_sss.c:1862 +#: src/sss_client/pam_sss.c:2031 #, c-format -msgid "Authenticate with PIN %1$s at %2$s and press ENTER." -msgstr "" -"Пожалуйста, авторизуйтесь с помощью PIN-кода %1$s на %2$s и нажмите ENTER." +msgid "Authenticate with PIN \"%1$s\" at \"%2$s\"." +msgstr "Пройдите проверку подлинности с помощью PIN \"%1$s\" на \"%2$s\"." -#: src/sss_client/pam_sss.c:2281 +#: src/sss_client/pam_sss.c:2470 msgid "Please (re)insert (different) Smartcard" msgstr "Пожалуйста, вставьте (повторно/другую) смарт-карту" -#: src/sss_client/pam_sss.c:2482 +#: src/sss_client/pam_sss.c:2700 msgid "New Password: " msgstr "Новый пароль: " -#: src/sss_client/pam_sss.c:2483 +#: src/sss_client/pam_sss.c:2701 msgid "Reenter new Password: " msgstr "Введите новый пароль ещё раз: " -#: src/sss_client/pam_sss.c:2676 src/sss_client/pam_sss.c:2679 +#: src/sss_client/pam_sss.c:2890 +msgid "Press ENTER to continue." +msgstr "Нажмите ENTER для продолжения." + +#: src/sss_client/pam_sss.c:2913 src/sss_client/pam_sss.c:2916 msgid "First Factor: " msgstr "Первый фактор: " -#: src/sss_client/pam_sss.c:2677 src/sss_client/pam_sss.c:2851 +#: src/sss_client/pam_sss.c:2914 src/sss_client/pam_sss.c:3088 msgid "Second Factor (optional): " msgstr "Второй фактор (необязательно): " -#: src/sss_client/pam_sss.c:2680 src/sss_client/pam_sss.c:2855 +#: src/sss_client/pam_sss.c:2917 src/sss_client/pam_sss.c:3092 msgid "Second Factor: " msgstr "Второй фактор: " -#: src/sss_client/pam_sss.c:2684 +#: src/sss_client/pam_sss.c:2921 msgid "Insert your passkey device, then press ENTER." msgstr "Вставьте устройство с ключом доступа и нажмите ENTER." -#: src/sss_client/pam_sss.c:2688 src/sss_client/pam_sss.c:2696 +#: src/sss_client/pam_sss.c:2925 src/sss_client/pam_sss.c:2933 msgid "Password: " msgstr "Пароль: " -#: src/sss_client/pam_sss.c:2850 src/sss_client/pam_sss.c:2854 +#: src/sss_client/pam_sss.c:3087 src/sss_client/pam_sss.c:3091 msgid "First Factor (Current Password): " msgstr "Первый фактор (текущий пароль): " -#: src/sss_client/pam_sss.c:2874 +#: src/sss_client/pam_sss.c:3111 msgid "Current Password: " msgstr "Текущий пароль: " -#: src/sss_client/pam_sss.c:3248 +#: src/sss_client/pam_sss.c:3485 msgid "Password expired. Change your password now." msgstr "Срок действия пароля истёк. Необходимо сейчас изменить ваш пароль." @@ -2770,9 +2822,9 @@ msgstr "Не удалось вывести объект: %s\n" #: src/tools/sssctl/sssctl_cache.c:835 src/tools/sssctl/sssctl_cache.c:918 #: src/tools/sssctl/sssctl_cache.c:950 src/tools/sssctl/sssctl_cache.c:956 #: src/tools/sssctl/sssctl_cache.c:1010 src/tools/sssctl/sssctl_cache.c:1034 -#: src/tools/sssctl/sssctl_cache.c:1085 src/tools/sssctl/sssctl_cache.c:1194 -#: src/tools/sssctl/sssctl_cache.c:1229 src/tools/sssctl/sssctl_cache.c:1235 -#: src/tools/sssctl/sssctl_cache.c:1244 +#: src/tools/sssctl/sssctl_cache.c:1085 src/tools/sssctl/sssctl_cache.c:1195 +#: src/tools/sssctl/sssctl_cache.c:1230 src/tools/sssctl/sssctl_cache.c:1236 +#: src/tools/sssctl/sssctl_cache.c:1245 msgid "talloc failed\n" msgstr "ошибка talloc\n" @@ -2852,25 +2904,25 @@ msgstr "" msgid "Unable to remove downloaded GPO files: %s\n" msgstr "Не удалось удалить загруженные файлы объекта групповой политики: %s\n" -#: src/tools/sssctl/sssctl_cache.c:1165 +#: src/tools/sssctl/sssctl_cache.c:1166 #, c-format msgid "Failed to fetch cache entry: %s\n" msgstr "Не удалось получить запись кэша: %s\n" -#: src/tools/sssctl/sssctl_cache.c:1170 +#: src/tools/sssctl/sssctl_cache.c:1171 msgid "Could not determine object domain\n" msgstr "Не удалось определить домен объекта\n" -#: src/tools/sssctl/sssctl_cache.c:1200 +#: src/tools/sssctl/sssctl_cache.c:1201 msgid "Could not find GUID attribute in GPO entry\n" msgstr "Не удалось найти атрибут GUID в записи объекта групповой политики.\n" -#: src/tools/sssctl/sssctl_cache.c:1206 +#: src/tools/sssctl/sssctl_cache.c:1207 #, c-format msgid "Failed to delete GPO: %s\n" msgstr "Не удалось удалить объект групповой политики: %s\n" -#: src/tools/sssctl/sssctl_cache.c:1210 +#: src/tools/sssctl/sssctl_cache.c:1211 #, c-format msgid "%s removed from cache\n" msgstr "%s удален из кеша\n" @@ -2919,8 +2971,8 @@ msgstr "Не удалось настроить контекст привязки #, c-format msgid "Failed to add mapping and matching rules with error [%d][%s].\n" msgstr "" -"Не удалось добавить правила сопоставления и соответствия из-за ошибки " -"[%d][%s].\n" +"Не удалось добавить правила сопоставления и соответствия из-за ошибки [%d]" +"[%s].\n" #: src/tools/sssctl/sssctl_cert.c:251 msgid "Failed to decode base64 string.\n" @@ -2968,39 +3020,40 @@ msgstr "" "находится по пути «/my/path/sssd.conf», расположением каталога фрагментов " "будет «/my/path/conf.d».)" -#: src/tools/sssctl/sssctl_config.c:114 +#: src/tools/sssctl/sssctl_config.c:126 #, c-format msgid "File %1$s does not exist.\n" msgstr "Файл %1$s не существует.\n" -#: src/tools/sssctl/sssctl_config.c:115 +#: src/tools/sssctl/sssctl_config.c:127 msgid "There is no configuration.\n" msgstr "Нет никакой конфигурации.\n" -#: src/tools/sssctl/sssctl_config.c:120 +#: src/tools/sssctl/sssctl_config.c:132 #, c-format msgid "Configuration validation failed: %s\n" msgstr "Ошибка проверки конфигурации: %s\n" -#: src/tools/sssctl/sssctl_config.c:121 +#: src/tools/sssctl/sssctl_config.c:133 msgid "Run with high debug level to see details.\n" -msgstr "Запустите с более высоким уровнем отладки, чтобы увидеть подробности.\n" +msgstr "" +"Запустите с более высоким уровнем отладки, чтобы увидеть подробности.\n" -#: src/tools/sssctl/sssctl_config.c:130 -msgid "Failed to run validators" -msgstr "Не удалось запустить средства проверки" +#: src/tools/sssctl/sssctl_config.c:142 +msgid "Failed to run validators\n" +msgstr "Не удалось запустить средства проверки\n" -#: src/tools/sssctl/sssctl_config.c:134 +#: src/tools/sssctl/sssctl_config.c:146 #, c-format msgid "Issues identified by validators: %zu\n" msgstr "Проблемы, выявленные средствами проверки: %zu\n" -#: src/tools/sssctl/sssctl_config.c:145 +#: src/tools/sssctl/sssctl_config.c:157 #, c-format msgid "Messages generated during configuration merging: %zu\n" msgstr "Сообщения, созданные при объединении конфигурации: %zu\n" -#: src/tools/sssctl/sssctl_config.c:158 +#: src/tools/sssctl/sssctl_config.c:170 #, c-format msgid "Used configuration snippet files: %zu\n" msgstr "Использованных файлов фрагментов конфигурации: %zu\n" diff --git a/po/sssd.pot b/po/sssd.pot index 46ca4cb109c..2354e6d9016 100644 --- a/po/sssd.pot +++ b/po/sssd.pot @@ -8,7 +8,7 @@ msgid "" msgstr "" "Project-Id-Version: PACKAGE VERSION\n" "Report-Msgid-Bugs-To: sssd-devel@lists.fedorahosted.org\n" -"POT-Creation-Date: 2026-01-14 14:57+0000\n" +"POT-Creation-Date: 2026-10-02 15:57+0000\n" "PO-Revision-Date: YEAR-MO-DA HO:MI+ZONE\n" "Last-Translator: FULL NAME \n" "Language-Team: LANGUAGE \n" @@ -17,48 +17,48 @@ msgstr "" "Content-Type: text/plain; charset=CHARSET\n" "Content-Transfer-Encoding: 8bit\n" -#: src/config/SSSDConfig/sssdoptions.py:20 -#: src/config/SSSDConfig/sssdoptions.py:21 +#: src/config/SSSDConfig/sssdoptions.py:16 +#: src/config/SSSDConfig/sssdoptions.py:17 msgid "Set the verbosity of the debug logging" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:22 +#: src/config/SSSDConfig/sssdoptions.py:18 msgid "Include timestamps in debug logs" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:23 +#: src/config/SSSDConfig/sssdoptions.py:19 msgid "Include microseconds in timestamps in debug logs" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:24 +#: src/config/SSSDConfig/sssdoptions.py:20 msgid "Enable/disable debug backtrace" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:25 +#: src/config/SSSDConfig/sssdoptions.py:21 msgid "Watchdog timeout before restarting service" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:26 +#: src/config/SSSDConfig/sssdoptions.py:22 msgid "Command to start service" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:27 +#: src/config/SSSDConfig/sssdoptions.py:23 msgid "The number of file descriptors that may be opened by this responder" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:28 +#: src/config/SSSDConfig/sssdoptions.py:24 msgid "Idle time before automatic disconnection of a client" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:29 +#: src/config/SSSDConfig/sssdoptions.py:25 msgid "Idle time before automatic shutdown of the responder" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:30 +#: src/config/SSSDConfig/sssdoptions.py:26 msgid "Always query all the caches before querying the Data Providers" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:31 +#: src/config/SSSDConfig/sssdoptions.py:27 msgid "" "When SSSD switches to offline mode the amount of time before it tries to go " "back online will increase based upon the time spent disconnected. This value " @@ -66,63 +66,63 @@ msgid "" "random_offset." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:36 +#: src/config/SSSDConfig/sssdoptions.py:32 msgid "SSSD Services to start" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:37 +#: src/config/SSSDConfig/sssdoptions.py:33 msgid "SSSD Domains to start" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:38 +#: src/config/SSSDConfig/sssdoptions.py:34 msgid "Regex to parse username and domain" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:39 +#: src/config/SSSDConfig/sssdoptions.py:35 msgid "Printf-compatible format for displaying fully-qualified names" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:40 +#: src/config/SSSDConfig/sssdoptions.py:36 msgid "" "Directory on the filesystem where SSSD should store Kerberos replay cache " "files." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:41 +#: src/config/SSSDConfig/sssdoptions.py:37 msgid "Domain to add to names without a domain component." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:42 +#: src/config/SSSDConfig/sssdoptions.py:38 msgid "The user to drop privileges to" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:43 +#: src/config/SSSDConfig/sssdoptions.py:39 msgid "Tune certificate verification" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:44 +#: src/config/SSSDConfig/sssdoptions.py:40 msgid "All spaces in group or user names will be replaced with this character" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:45 +#: src/config/SSSDConfig/sssdoptions.py:41 msgid "Tune sssd to honor or ignore netlink state changes" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:46 +#: src/config/SSSDConfig/sssdoptions.py:42 msgid "Enable or disable the implicit files domain" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:47 +#: src/config/SSSDConfig/sssdoptions.py:43 msgid "A specific order of the domains to be looked up" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:48 +#: src/config/SSSDConfig/sssdoptions.py:44 msgid "" "Controls if SSSD should monitor the state of resolv.conf to identify when it " "needs to update its internal DNS resolver." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:50 +#: src/config/SSSDConfig/sssdoptions.py:46 msgid "" "SSSD monitors the state of resolv.conf to identify when it needs to update " "its internal DNS resolver. By default, we will attempt to use inotify for " @@ -130,393 +130,400 @@ msgid "" "inotify cannot be used." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:53 +#: src/config/SSSDConfig/sssdoptions.py:49 msgid "Run PAC responder automatically for AD and IPA provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:54 +#: src/config/SSSDConfig/sssdoptions.py:50 msgid "Enable or disable core dumps for all SSSD processes." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:55 +#: src/config/SSSDConfig/sssdoptions.py:51 msgid "Tune passkey verification behavior" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:58 +#: src/config/SSSDConfig/sssdoptions.py:54 msgid "Enumeration cache timeout length (seconds)" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:59 +#: src/config/SSSDConfig/sssdoptions.py:55 msgid "Entry cache background update timeout length (seconds)" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:60 -#: src/config/SSSDConfig/sssdoptions.py:125 +#: src/config/SSSDConfig/sssdoptions.py:56 +#: src/config/SSSDConfig/sssdoptions.py:124 msgid "Negative cache timeout length (seconds)" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:61 +#: src/config/SSSDConfig/sssdoptions.py:57 msgid "Users that SSSD should explicitly ignore" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:62 +#: src/config/SSSDConfig/sssdoptions.py:58 msgid "Groups that SSSD should explicitly ignore" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:63 +#: src/config/SSSDConfig/sssdoptions.py:59 msgid "Should filtered users appear in groups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:64 +#: src/config/SSSDConfig/sssdoptions.py:60 msgid "The value of the password field the NSS provider should return" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:65 +#: src/config/SSSDConfig/sssdoptions.py:61 msgid "Override homedir value from the identity provider with this value" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:66 +#: src/config/SSSDConfig/sssdoptions.py:62 msgid "" "Substitute empty homedir value from the identity provider with this value" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:67 +#: src/config/SSSDConfig/sssdoptions.py:63 msgid "Override shell value from the identity provider with this value" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:68 +#: src/config/SSSDConfig/sssdoptions.py:64 msgid "The list of shells users are allowed to log in with" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:69 +#: src/config/SSSDConfig/sssdoptions.py:65 msgid "" "The list of shells that will be vetoed, and replaced with the fallback shell" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:70 +#: src/config/SSSDConfig/sssdoptions.py:66 msgid "" "If a shell stored in central directory is allowed but not available, use " "this fallback" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:71 +#: src/config/SSSDConfig/sssdoptions.py:67 msgid "Shell to use if the provider does not list one" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:72 +#: src/config/SSSDConfig/sssdoptions.py:68 msgid "How long will be in-memory cache records valid" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:74 +#: src/config/SSSDConfig/sssdoptions.py:70 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for passwd requests" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:76 +#: src/config/SSSDConfig/sssdoptions.py:72 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for group requests" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:78 +#: src/config/SSSDConfig/sssdoptions.py:74 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for initgroups requests" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:79 +#: src/config/SSSDConfig/sssdoptions.py:75 msgid "" "The value of this option will be used in the expansion of the " "override_homedir option if the template contains the format string %H." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:81 +#: src/config/SSSDConfig/sssdoptions.py:77 msgid "" "Specifies time in seconds for which the list of subdomains will be " "considered valid." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:83 +#: src/config/SSSDConfig/sssdoptions.py:79 msgid "" "The entry cache can be set to automatically update entries in the background " "if they are requested beyond a percentage of the entry_cache_timeout value " "for the domain." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:88 +#: src/config/SSSDConfig/sssdoptions.py:84 msgid "How long to allow cached logins between online logins (days)" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:89 +#: src/config/SSSDConfig/sssdoptions.py:85 msgid "How many failed logins attempts are allowed when offline" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:91 +#: src/config/SSSDConfig/sssdoptions.py:87 msgid "" "How long (minutes) to deny login after offline_failed_login_attempts has " "been reached" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:92 +#: src/config/SSSDConfig/sssdoptions.py:88 msgid "What kind of messages are displayed to the user during authentication" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:93 +#: src/config/SSSDConfig/sssdoptions.py:89 msgid "Filter PAM responses sent to the pam_sss" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:94 +#: src/config/SSSDConfig/sssdoptions.py:90 msgid "How many seconds to keep identity information cached for PAM requests" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:95 +#: src/config/SSSDConfig/sssdoptions.py:91 msgid "How many days before password expiration a warning should be displayed" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:96 +#: src/config/SSSDConfig/sssdoptions.py:92 msgid "List of trusted uids or user's name" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:97 +#: src/config/SSSDConfig/sssdoptions.py:93 msgid "List of domains accessible even for untrusted users." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:98 +#: src/config/SSSDConfig/sssdoptions.py:94 msgid "Message printed when user account is expired." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:99 +#: src/config/SSSDConfig/sssdoptions.py:95 msgid "Message printed when user account is locked." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:100 +#: src/config/SSSDConfig/sssdoptions.py:96 msgid "Allow certificate based/Smartcard authentication." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:101 +#: src/config/SSSDConfig/sssdoptions.py:97 msgid "Path to certificate database with PKCS#11 modules." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:102 +#: src/config/SSSDConfig/sssdoptions.py:98 msgid "Tune certificate verification for PAM authentication." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:103 +#: src/config/SSSDConfig/sssdoptions.py:99 msgid "How many seconds will pam_sss wait for p11_child to finish" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:104 +#: src/config/SSSDConfig/sssdoptions.py:100 msgid "Which PAM services are permitted to contact application domains" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:105 +#: src/config/SSSDConfig/sssdoptions.py:101 msgid "Allowed services for using smartcards" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:106 +#: src/config/SSSDConfig/sssdoptions.py:102 msgid "Additional timeout to wait for a card if requested" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:107 +#: src/config/SSSDConfig/sssdoptions.py:103 msgid "" "PKCS#11 URI to restrict the selection of devices for Smartcard authentication" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:108 +#: src/config/SSSDConfig/sssdoptions.py:104 msgid "When shall the PAM responder force an initgroups request" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:109 +#: src/config/SSSDConfig/sssdoptions.py:105 msgid "List of PAM services that are allowed to authenticate with GSSAPI." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:110 +#: src/config/SSSDConfig/sssdoptions.py:106 msgid "Whether to match authenticated UPN with target user" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:111 +#: src/config/SSSDConfig/sssdoptions.py:107 msgid "" "List of pairs : that must be enforced " "for PAM access with GSSAPI authentication" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:113 +#: src/config/SSSDConfig/sssdoptions.py:109 +msgid "" +"List of triples :: that assigns " +"additional information from the Kerberos ticket to an authentication " +"indicator." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:112 msgid "Allow passkey device authentication." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:114 +#: src/config/SSSDConfig/sssdoptions.py:113 msgid "How many seconds will pam_sss wait for passkey_child to finish" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:115 +#: src/config/SSSDConfig/sssdoptions.py:114 msgid "Enable debugging in the libfido2 library" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:116 +#: src/config/SSSDConfig/sssdoptions.py:115 msgid "Enable JSON protocol for authentication methods selection." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:119 +#: src/config/SSSDConfig/sssdoptions.py:118 msgid "Whether to evaluate the time-based attributes in sudo rules" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:120 +#: src/config/SSSDConfig/sssdoptions.py:119 msgid "If true, SSSD will switch back to lower-wins ordering logic" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:121 +#: src/config/SSSDConfig/sssdoptions.py:120 msgid "" "Maximum number of rules that can be refreshed at once. If this is exceeded, " "full refresh is performed." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:128 +#: src/config/SSSDConfig/sssdoptions.py:127 msgid "Whether to hash host names and addresses in the known_hosts file" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:129 +#: src/config/SSSDConfig/sssdoptions.py:128 msgid "" "How many seconds to keep a host in the known_hosts file after its host keys " "were requested" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:131 +#: src/config/SSSDConfig/sssdoptions.py:130 msgid "Path to storage of trusted CA certificates" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:132 +#: src/config/SSSDConfig/sssdoptions.py:131 msgid "Allow to generate ssh-keys from certificates" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:133 +#: src/config/SSSDConfig/sssdoptions.py:132 msgid "" "Use the following matching rules to filter the certificates for ssh-key " "generation" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:137 +#: src/config/SSSDConfig/sssdoptions.py:136 msgid "List of UIDs or user names allowed to access the PAC responder" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:138 +#: src/config/SSSDConfig/sssdoptions.py:137 msgid "How long the PAC data is considered valid" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:139 +#: src/config/SSSDConfig/sssdoptions.py:138 msgid "Validate the PAC" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:142 +#: src/config/SSSDConfig/sssdoptions.py:141 msgid "List of user attributes the InfoPipe is allowed to publish" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:145 +#: src/config/SSSDConfig/sssdoptions.py:144 msgid "" "One of the following strings specifying the scope of session recording: none " "- No users are recorded. some - Users/groups specified by users and groups " "options are recorded. all - All users are recorded." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:148 +#: src/config/SSSDConfig/sssdoptions.py:147 msgid "" "A comma-separated list of users which should have session recording enabled. " "Matches user names as returned by NSS. I.e. after the possible space " "replacement, case changes, etc." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:150 +#: src/config/SSSDConfig/sssdoptions.py:149 msgid "" "A comma-separated list of groups, members of which should have session " "recording enabled. Matches group names as returned by NSS. I.e. after the " "possible space replacement, case changes, etc." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:153 +#: src/config/SSSDConfig/sssdoptions.py:152 msgid "" "A comma-separated list of users to be excluded from recording, only when " "scope=all" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:154 +#: src/config/SSSDConfig/sssdoptions.py:153 msgid "" "A comma-separated list of groups, members of which should be excluded from " "recording, only when scope=all. " msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:158 +#: src/config/SSSDConfig/sssdoptions.py:157 msgid "Identity provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:159 +#: src/config/SSSDConfig/sssdoptions.py:158 msgid "Authentication provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:160 +#: src/config/SSSDConfig/sssdoptions.py:159 msgid "Access control provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:161 +#: src/config/SSSDConfig/sssdoptions.py:160 msgid "Password change provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:162 +#: src/config/SSSDConfig/sssdoptions.py:161 msgid "SUDO provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:163 +#: src/config/SSSDConfig/sssdoptions.py:162 msgid "Autofs provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:164 +#: src/config/SSSDConfig/sssdoptions.py:163 msgid "Host identity provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:165 +#: src/config/SSSDConfig/sssdoptions.py:164 msgid "SELinux provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:166 +#: src/config/SSSDConfig/sssdoptions.py:165 msgid "Session management provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:167 +#: src/config/SSSDConfig/sssdoptions.py:166 msgid "Resolver provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:170 +#: src/config/SSSDConfig/sssdoptions.py:169 msgid "Whether the domain is usable by the OS or by applications" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:171 +#: src/config/SSSDConfig/sssdoptions.py:170 msgid "Enable or disable the domain" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:172 +#: src/config/SSSDConfig/sssdoptions.py:171 msgid "Minimum user ID" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:173 +#: src/config/SSSDConfig/sssdoptions.py:172 msgid "Maximum user ID" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:174 +#: src/config/SSSDConfig/sssdoptions.py:173 msgid "Enable enumerating all users/groups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:175 +#: src/config/SSSDConfig/sssdoptions.py:174 msgid "Cache credentials for offline login" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:176 +#: src/config/SSSDConfig/sssdoptions.py:175 msgid "Display users/groups in fully-qualified form" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:177 +#: src/config/SSSDConfig/sssdoptions.py:176 msgid "Don't include group members in group lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:178 +#: src/config/SSSDConfig/sssdoptions.py:177 #: src/config/SSSDConfig/sssdoptions.py:190 #: src/config/SSSDConfig/sssdoptions.py:191 #: src/config/SSSDConfig/sssdoptions.py:192 @@ -527,48 +534,52 @@ msgstr "" msgid "Entry cache timeout length (seconds)" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:179 +#: src/config/SSSDConfig/sssdoptions.py:178 msgid "" "Restrict or prefer a specific address family when performing DNS lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:180 +#: src/config/SSSDConfig/sssdoptions.py:179 msgid "How long to keep cached entries after last successful login (days)" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:181 +#: src/config/SSSDConfig/sssdoptions.py:180 msgid "" "How long should SSSD talk to single DNS server before trying next server " "(miliseconds)" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:183 +#: src/config/SSSDConfig/sssdoptions.py:182 msgid "How long should keep trying to resolve single DNS query (seconds)" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:184 +#: src/config/SSSDConfig/sssdoptions.py:183 msgid "How long to wait for replies from DNS when resolving servers (seconds)" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:185 +#: src/config/SSSDConfig/sssdoptions.py:184 msgid "The domain part of service discovery DNS query" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:186 +#: src/config/SSSDConfig/sssdoptions.py:185 msgid "" "Specifies the interval, in seconds, that SSSD waits before attempting to " "reconnect to the primary server after a successful connection to the backup " "server" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:188 +#: src/config/SSSDConfig/sssdoptions.py:187 msgid "Override GID value from the identity provider with this value" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:189 +#: src/config/SSSDConfig/sssdoptions.py:188 msgid "Treat usernames as case sensitive" msgstr "" +#: src/config/SSSDConfig/sssdoptions.py:189 +msgid "Lookups by ID are expensive or do not work at all" +msgstr "" + #: src/config/SSSDConfig/sssdoptions.py:197 msgid "How often should expired entries be refreshed in background" msgstr "" @@ -788,7 +799,7 @@ msgid "Search base for SUBID ranges" msgstr "" #: src/config/SSSDConfig/sssdoptions.py:259 -#: src/config/SSSDConfig/sssdoptions.py:506 +#: src/config/SSSDConfig/sssdoptions.py:512 msgid "Which rules should be used to evaluate access control" msgstr "" @@ -930,7 +941,7 @@ msgid "Enable DNS sites - location based service discovery" msgstr "" #: src/config/SSSDConfig/sssdoptions.py:301 -#: src/config/SSSDConfig/sssdoptions.py:504 +#: src/config/SSSDConfig/sssdoptions.py:510 msgid "LDAP filter to determine access privileges" msgstr "" @@ -1350,7 +1361,7 @@ msgid "UUID attribute" msgstr "" #: src/config/SSSDConfig/sssdoptions.py:423 -#: src/config/SSSDConfig/sssdoptions.py:464 +#: src/config/SSSDConfig/sssdoptions.py:470 msgid "objectSID attribute" msgstr "" @@ -1474,385 +1485,409 @@ msgstr "" msgid "A list of extra attributes to download along with the user entry" msgstr "" +#: src/config/SSSDConfig/sssdoptions.py:456 +msgid "The object class of an subid entry in LDAP." +msgstr "" + #: src/config/SSSDConfig/sssdoptions.py:457 -msgid "Base DN for group lookups" +msgid "Subordinate user ID count attribute" msgstr "" #: src/config/SSSDConfig/sssdoptions.py:458 -msgid "Objectclass for groups" +msgid "Subordinate group ID count attribute" msgstr "" #: src/config/SSSDConfig/sssdoptions.py:459 -msgid "Group name" +msgid "User ID range start value attribute" msgstr "" #: src/config/SSSDConfig/sssdoptions.py:460 -msgid "Group password" +msgid "Group ID range start value attribute" msgstr "" #: src/config/SSSDConfig/sssdoptions.py:461 +msgid "Owner of an entry" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:463 +msgid "Base DN for group lookups" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:464 +msgid "Objectclass for groups" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:465 +msgid "Group name" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:466 +msgid "Group password" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:467 msgid "GID attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:462 +#: src/config/SSSDConfig/sssdoptions.py:468 msgid "Group member attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:463 +#: src/config/SSSDConfig/sssdoptions.py:469 msgid "Group UUID attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:465 +#: src/config/SSSDConfig/sssdoptions.py:471 msgid "Modification time attribute for groups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:466 +#: src/config/SSSDConfig/sssdoptions.py:472 msgid "Type of the group and other flags" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:467 +#: src/config/SSSDConfig/sssdoptions.py:473 msgid "The LDAP group external member attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:468 +#: src/config/SSSDConfig/sssdoptions.py:474 msgid "Maximum nesting level SSSD will follow" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:469 +#: src/config/SSSDConfig/sssdoptions.py:475 msgid "Filter for group lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:470 +#: src/config/SSSDConfig/sssdoptions.py:476 msgid "Scope of group lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:472 +#: src/config/SSSDConfig/sssdoptions.py:478 msgid "Base DN for netgroup lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:473 +#: src/config/SSSDConfig/sssdoptions.py:479 msgid "Objectclass for netgroups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:474 +#: src/config/SSSDConfig/sssdoptions.py:480 msgid "Netgroup name" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:475 +#: src/config/SSSDConfig/sssdoptions.py:481 msgid "Netgroups members attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:476 +#: src/config/SSSDConfig/sssdoptions.py:482 msgid "Netgroup triple attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:477 +#: src/config/SSSDConfig/sssdoptions.py:483 msgid "Modification time attribute for netgroups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:479 +#: src/config/SSSDConfig/sssdoptions.py:485 msgid "Base DN for service lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:480 +#: src/config/SSSDConfig/sssdoptions.py:486 msgid "Objectclass for services" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:481 +#: src/config/SSSDConfig/sssdoptions.py:487 msgid "Service name attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:482 +#: src/config/SSSDConfig/sssdoptions.py:488 msgid "Service port attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:483 +#: src/config/SSSDConfig/sssdoptions.py:489 msgid "Service protocol attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:485 +#: src/config/SSSDConfig/sssdoptions.py:491 msgid "Lower bound for ID-mapping" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:486 +#: src/config/SSSDConfig/sssdoptions.py:492 msgid "Upper bound for ID-mapping" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:487 +#: src/config/SSSDConfig/sssdoptions.py:493 msgid "Number of IDs for each slice when ID-mapping" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:488 +#: src/config/SSSDConfig/sssdoptions.py:494 msgid "Use autorid-compatible algorithm for ID-mapping" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:489 +#: src/config/SSSDConfig/sssdoptions.py:495 msgid "Name of the default domain for ID-mapping" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:490 +#: src/config/SSSDConfig/sssdoptions.py:496 msgid "SID of the default domain for ID-mapping" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:491 +#: src/config/SSSDConfig/sssdoptions.py:497 msgid "Number of secondary slices" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:493 +#: src/config/SSSDConfig/sssdoptions.py:499 msgid "Whether to use Token-Groups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:494 +#: src/config/SSSDConfig/sssdoptions.py:500 msgid "Set lower boundary for allowed IDs from the LDAP server" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:495 +#: src/config/SSSDConfig/sssdoptions.py:501 msgid "Set upper boundary for allowed IDs from the LDAP server" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:496 +#: src/config/SSSDConfig/sssdoptions.py:502 msgid "DN for ppolicy queries" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:497 +#: src/config/SSSDConfig/sssdoptions.py:503 msgid "How many maximum entries to fetch during a wildcard request" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:498 +#: src/config/SSSDConfig/sssdoptions.py:504 msgid "Set libldap debug level" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:501 +#: src/config/SSSDConfig/sssdoptions.py:507 msgid "Policy to evaluate the password expiration" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:505 +#: src/config/SSSDConfig/sssdoptions.py:511 msgid "Which attributes shall be used to evaluate if an account is expired" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:509 +#: src/config/SSSDConfig/sssdoptions.py:515 msgid "URI of an LDAP server where password changes are allowed" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:510 +#: src/config/SSSDConfig/sssdoptions.py:516 msgid "URI of a backup LDAP server where password changes are allowed" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:511 +#: src/config/SSSDConfig/sssdoptions.py:517 msgid "DNS service name for LDAP password change server" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:512 +#: src/config/SSSDConfig/sssdoptions.py:518 msgid "" "Whether to update the ldap_user_shadow_last_change attribute after a " "password change" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:516 +#: src/config/SSSDConfig/sssdoptions.py:522 msgid "Base DN for sudo rules lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:517 +#: src/config/SSSDConfig/sssdoptions.py:523 msgid "Automatic full refresh period" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:518 +#: src/config/SSSDConfig/sssdoptions.py:524 msgid "Automatic smart refresh period" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:519 +#: src/config/SSSDConfig/sssdoptions.py:525 msgid "Smart and full refresh random offset" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:520 +#: src/config/SSSDConfig/sssdoptions.py:526 msgid "Whether to filter rules by hostname, IP addresses and network" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:521 +#: src/config/SSSDConfig/sssdoptions.py:527 msgid "" "Hostnames and/or fully qualified domain names of this machine to filter sudo " "rules" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:522 +#: src/config/SSSDConfig/sssdoptions.py:528 msgid "IPv4 or IPv6 addresses or network of this machine to filter sudo rules" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:523 +#: src/config/SSSDConfig/sssdoptions.py:529 msgid "Whether to include rules that contains netgroup in host attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:524 +#: src/config/SSSDConfig/sssdoptions.py:530 msgid "" "Whether to include rules that contains regular expression in host attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:525 +#: src/config/SSSDConfig/sssdoptions.py:531 msgid "Object class for sudo rules" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:526 +#: src/config/SSSDConfig/sssdoptions.py:532 msgid "Name of attribute that is used as object class for sudo rules" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:527 +#: src/config/SSSDConfig/sssdoptions.py:533 msgid "Sudo rule name" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:528 +#: src/config/SSSDConfig/sssdoptions.py:534 msgid "Sudo rule command attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:529 +#: src/config/SSSDConfig/sssdoptions.py:535 msgid "Sudo rule host attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:530 +#: src/config/SSSDConfig/sssdoptions.py:536 msgid "Sudo rule user attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:531 +#: src/config/SSSDConfig/sssdoptions.py:537 msgid "Sudo rule option attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:532 +#: src/config/SSSDConfig/sssdoptions.py:538 msgid "Sudo rule runas attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:533 +#: src/config/SSSDConfig/sssdoptions.py:539 msgid "Sudo rule runasuser attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:534 +#: src/config/SSSDConfig/sssdoptions.py:540 msgid "Sudo rule runasgroup attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:535 +#: src/config/SSSDConfig/sssdoptions.py:541 msgid "Sudo rule notbefore attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:536 +#: src/config/SSSDConfig/sssdoptions.py:542 msgid "Sudo rule notafter attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:537 +#: src/config/SSSDConfig/sssdoptions.py:543 msgid "Sudo rule order attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:540 +#: src/config/SSSDConfig/sssdoptions.py:546 msgid "Object class for automounter maps" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:541 +#: src/config/SSSDConfig/sssdoptions.py:547 msgid "Automounter map name attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:542 +#: src/config/SSSDConfig/sssdoptions.py:548 msgid "Object class for automounter map entries" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:543 +#: src/config/SSSDConfig/sssdoptions.py:549 msgid "Automounter map entry key attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:544 +#: src/config/SSSDConfig/sssdoptions.py:550 msgid "Automounter map entry value attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:545 +#: src/config/SSSDConfig/sssdoptions.py:551 msgid "Base DN for automounter map lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:546 +#: src/config/SSSDConfig/sssdoptions.py:552 msgid "The name of the automount master map in LDAP." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:549 +#: src/config/SSSDConfig/sssdoptions.py:555 msgid "Base DN for IP hosts lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:550 +#: src/config/SSSDConfig/sssdoptions.py:556 msgid "Object class for IP hosts" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:551 +#: src/config/SSSDConfig/sssdoptions.py:557 msgid "IP host name attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:552 +#: src/config/SSSDConfig/sssdoptions.py:558 msgid "IP host number (address) attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:553 +#: src/config/SSSDConfig/sssdoptions.py:559 msgid "IP host entryUSN attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:554 +#: src/config/SSSDConfig/sssdoptions.py:560 msgid "Base DN for IP networks lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:555 +#: src/config/SSSDConfig/sssdoptions.py:561 msgid "Object class for IP networks" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:556 +#: src/config/SSSDConfig/sssdoptions.py:562 msgid "IP network name attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:557 +#: src/config/SSSDConfig/sssdoptions.py:563 msgid "IP network number (address) attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:558 +#: src/config/SSSDConfig/sssdoptions.py:564 msgid "IP network entryUSN attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:561 +#: src/config/SSSDConfig/sssdoptions.py:567 msgid "Comma separated list of allowed users" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:562 +#: src/config/SSSDConfig/sssdoptions.py:568 msgid "Comma separated list of prohibited users" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:563 +#: src/config/SSSDConfig/sssdoptions.py:569 msgid "" "Comma separated list of groups that are allowed to log in. This applies only " "to groups within this SSSD domain. Local groups are not evaluated." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:565 +#: src/config/SSSDConfig/sssdoptions.py:571 msgid "" "Comma separated list of groups that are explicitly denied access. This " "applies only to groups within this SSSD domain. Local groups are not " "evaluated." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:569 +#: src/config/SSSDConfig/sssdoptions.py:575 msgid "The number of preforked proxy children." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:572 +#: src/config/SSSDConfig/sssdoptions.py:578 msgid "The name of the NSS library to use" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:573 +#: src/config/SSSDConfig/sssdoptions.py:579 msgid "The name of the NSS library to use for hosts and networks lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:574 +#: src/config/SSSDConfig/sssdoptions.py:580 msgid "Whether to look up canonical group name from cache if possible" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:577 +#: src/config/SSSDConfig/sssdoptions.py:583 msgid "PAM stack to use" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:580 +#: src/config/SSSDConfig/sssdoptions.py:586 msgid "Path of passwd file sources." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:581 +#: src/config/SSSDConfig/sssdoptions.py:587 msgid "Path of group file sources." msgstr "" @@ -1880,225 +1915,233 @@ msgstr "" msgid "Option -i|--interactive is not allowed together with -D|--daemon\n" msgstr "" -#: src/monitor/monitor.c:1836 +#: src/monitor/monitor.c:1838 msgid "Failed to get initial capabilities\n" msgstr "" -#: src/monitor/monitor.c:1847 +#: src/monitor/monitor.c:1849 msgid "Non-root service user support isn't built. Can't run under %" msgstr "" -#: src/monitor/monitor.c:1864 +#: src/monitor/monitor.c:1866 #, c-format msgid "Can't read config: '%s'\n" msgstr "" -#: src/monitor/monitor.c:1876 +#: src/monitor/monitor.c:1878 #, c-format -msgid "Failed to boostrap SSSD 'monitor' process: %s" +msgid "Failed to bootstrap SSSD 'monitor' process: %s" msgstr "" -#: src/monitor/monitor.c:1971 +#: src/monitor/monitor.c:1973 msgid "Out of memory\n" msgstr "" -#: src/providers/krb5/krb5_child.c:4221 +#: src/providers/krb5/krb5_child.c:4316 msgid "Use anonymous PKINIT to request FAST armor ticket" msgstr "" -#: src/providers/krb5/krb5_child.c:4223 +#: src/providers/krb5/krb5_child.c:4318 msgid "Kerberos realm to use" msgstr "" -#: src/providers/krb5/krb5_child.c:4225 +#: src/providers/krb5/krb5_child.c:4320 msgid "Requested lifetime of the ticket" msgstr "" -#: src/providers/krb5/krb5_child.c:4227 +#: src/providers/krb5/krb5_child.c:4322 msgid "Requested renewable lifetime of the ticket" msgstr "" -#: src/providers/krb5/krb5_child.c:4229 +#: src/providers/krb5/krb5_child.c:4324 msgid "FAST options ('never', 'try', 'demand')" msgstr "" -#: src/providers/krb5/krb5_child.c:4232 +#: src/providers/krb5/krb5_child.c:4327 msgid "Specifies the server principal to use for FAST" msgstr "" -#: src/providers/krb5/krb5_child.c:4234 +#: src/providers/krb5/krb5_child.c:4329 msgid "Requests canonicalization of the principal name" msgstr "" -#: src/providers/krb5/krb5_child.c:4236 +#: src/providers/krb5/krb5_child.c:4331 msgid "Use custom version of krb5_get_init_creds_password" msgstr "" -#: src/providers/krb5/krb5_child.c:4238 +#: src/providers/krb5/krb5_child.c:4333 msgid "Check PAC flags" msgstr "" -#: src/providers/data_provider_be.c:790 +#: src/providers/krb5/krb5_child.c:4335 +msgid "Set environment variable (KEY=VALUE)" +msgstr "" + +#: src/providers/data_provider_be.c:786 msgid "Domain of the information provider (mandatory)" msgstr "" -#: src/sss_client/common.c:1165 +#: src/sss_client/common.c:1208 msgid "Socket has wrong ownership or permissions." msgstr "" -#: src/sss_client/common.c:1168 +#: src/sss_client/common.c:1211 msgid "Unexpected format of the server credential message." msgstr "" -#: src/sss_client/common.c:1171 +#: src/sss_client/common.c:1214 msgid "SSSD is not run by trusted user." msgstr "" -#: src/sss_client/common.c:1174 +#: src/sss_client/common.c:1217 msgid "SSSD socket does not exist." msgstr "" -#: src/sss_client/common.c:1177 +#: src/sss_client/common.c:1220 msgid "Cannot get stat of SSSD socket." msgstr "" -#: src/sss_client/common.c:1182 +#: src/sss_client/common.c:1225 msgid "An error occurred, but no description can be found." msgstr "" -#: src/sss_client/common.c:1188 +#: src/sss_client/common.c:1231 msgid "Unexpected error while looking for an error description" msgstr "" -#: src/sss_client/pam_sss.c:74 +#: src/sss_client/pam_sss.c:135 msgid "Permission denied. " msgstr "" -#: src/sss_client/pam_sss.c:75 src/sss_client/pam_sss.c:843 -#: src/sss_client/pam_sss.c:854 +#: src/sss_client/pam_sss.c:136 src/sss_client/pam_sss.c:921 +#: src/sss_client/pam_sss.c:932 msgid "Server message: " msgstr "" -#: src/sss_client/pam_sss.c:76 +#: src/sss_client/pam_sss.c:137 msgid "" "Kerberos TGT will not be granted upon login, user experience will be " "affected." msgstr "" -#: src/sss_client/pam_sss.c:77 +#: src/sss_client/pam_sss.c:138 msgid "Enter PIN:" msgstr "" -#: src/sss_client/pam_sss.c:320 +#: src/sss_client/pam_sss.c:385 msgid "Passwords do not match" msgstr "" -#: src/sss_client/pam_sss.c:508 +#: src/sss_client/pam_sss.c:584 msgid "Password reset by root is not supported." msgstr "" -#: src/sss_client/pam_sss.c:549 +#: src/sss_client/pam_sss.c:625 msgid "Authenticated with cached credentials" msgstr "" -#: src/sss_client/pam_sss.c:550 +#: src/sss_client/pam_sss.c:626 msgid ", your cached password will expire at: " msgstr "" -#: src/sss_client/pam_sss.c:580 +#: src/sss_client/pam_sss.c:656 #, c-format msgid "Your password has expired. You have %1$d grace login(s) remaining." msgstr "" -#: src/sss_client/pam_sss.c:630 +#: src/sss_client/pam_sss.c:706 #, c-format msgid "Your password will expire in %1$d %2$s." msgstr "" -#: src/sss_client/pam_sss.c:633 +#: src/sss_client/pam_sss.c:709 #, c-format msgid "Your password has expired." msgstr "" -#: src/sss_client/pam_sss.c:684 +#: src/sss_client/pam_sss.c:760 msgid "Authentication is denied until: " msgstr "" -#: src/sss_client/pam_sss.c:705 +#: src/sss_client/pam_sss.c:781 msgid "System is offline, password change not possible" msgstr "" -#: src/sss_client/pam_sss.c:720 +#: src/sss_client/pam_sss.c:796 msgid "" "After changing the OTP password, you need to log out and back in order to " "acquire a ticket" msgstr "" -#: src/sss_client/pam_sss.c:735 +#: src/sss_client/pam_sss.c:813 msgid "PIN locked" msgstr "" -#: src/sss_client/pam_sss.c:750 +#: src/sss_client/pam_sss.c:828 msgid "" "No Kerberos TGT granted as the server does not support this method. Your " "single-sign on(SSO) experience will be affected." msgstr "" -#: src/sss_client/pam_sss.c:840 src/sss_client/pam_sss.c:853 +#: src/sss_client/pam_sss.c:918 src/sss_client/pam_sss.c:931 msgid "Password change failed. " msgstr "" -#: src/sss_client/pam_sss.c:1859 +#: src/sss_client/pam_sss.c:2028 #, c-format -msgid "Authenticate at %1$s and press ENTER." +msgid "Authenticate at \"%1$s\"." msgstr "" -#: src/sss_client/pam_sss.c:1862 +#: src/sss_client/pam_sss.c:2031 #, c-format -msgid "Authenticate with PIN %1$s at %2$s and press ENTER." +msgid "Authenticate with PIN \"%1$s\" at \"%2$s\"." msgstr "" -#: src/sss_client/pam_sss.c:2281 +#: src/sss_client/pam_sss.c:2470 msgid "Please (re)insert (different) Smartcard" msgstr "" -#: src/sss_client/pam_sss.c:2482 +#: src/sss_client/pam_sss.c:2700 msgid "New Password: " msgstr "" -#: src/sss_client/pam_sss.c:2483 +#: src/sss_client/pam_sss.c:2701 msgid "Reenter new Password: " msgstr "" -#: src/sss_client/pam_sss.c:2676 src/sss_client/pam_sss.c:2679 +#: src/sss_client/pam_sss.c:2890 +msgid "Press ENTER to continue." +msgstr "" + +#: src/sss_client/pam_sss.c:2913 src/sss_client/pam_sss.c:2916 msgid "First Factor: " msgstr "" -#: src/sss_client/pam_sss.c:2677 src/sss_client/pam_sss.c:2851 +#: src/sss_client/pam_sss.c:2914 src/sss_client/pam_sss.c:3088 msgid "Second Factor (optional): " msgstr "" -#: src/sss_client/pam_sss.c:2680 src/sss_client/pam_sss.c:2855 +#: src/sss_client/pam_sss.c:2917 src/sss_client/pam_sss.c:3092 msgid "Second Factor: " msgstr "" -#: src/sss_client/pam_sss.c:2684 +#: src/sss_client/pam_sss.c:2921 msgid "Insert your passkey device, then press ENTER." msgstr "" -#: src/sss_client/pam_sss.c:2688 src/sss_client/pam_sss.c:2696 +#: src/sss_client/pam_sss.c:2925 src/sss_client/pam_sss.c:2933 msgid "Password: " msgstr "" -#: src/sss_client/pam_sss.c:2850 src/sss_client/pam_sss.c:2854 +#: src/sss_client/pam_sss.c:3087 src/sss_client/pam_sss.c:3091 msgid "First Factor (Current Password): " msgstr "" -#: src/sss_client/pam_sss.c:2874 +#: src/sss_client/pam_sss.c:3111 msgid "Current Password: " msgstr "" -#: src/sss_client/pam_sss.c:3248 +#: src/sss_client/pam_sss.c:3485 msgid "Password expired. Change your password now." msgstr "" @@ -2530,9 +2573,9 @@ msgstr "" #: src/tools/sssctl/sssctl_cache.c:835 src/tools/sssctl/sssctl_cache.c:918 #: src/tools/sssctl/sssctl_cache.c:950 src/tools/sssctl/sssctl_cache.c:956 #: src/tools/sssctl/sssctl_cache.c:1010 src/tools/sssctl/sssctl_cache.c:1034 -#: src/tools/sssctl/sssctl_cache.c:1085 src/tools/sssctl/sssctl_cache.c:1194 -#: src/tools/sssctl/sssctl_cache.c:1229 src/tools/sssctl/sssctl_cache.c:1235 -#: src/tools/sssctl/sssctl_cache.c:1244 +#: src/tools/sssctl/sssctl_cache.c:1085 src/tools/sssctl/sssctl_cache.c:1195 +#: src/tools/sssctl/sssctl_cache.c:1230 src/tools/sssctl/sssctl_cache.c:1236 +#: src/tools/sssctl/sssctl_cache.c:1245 msgid "talloc failed\n" msgstr "" @@ -2606,25 +2649,25 @@ msgstr "" msgid "Unable to remove downloaded GPO files: %s\n" msgstr "" -#: src/tools/sssctl/sssctl_cache.c:1165 +#: src/tools/sssctl/sssctl_cache.c:1166 #, c-format msgid "Failed to fetch cache entry: %s\n" msgstr "" -#: src/tools/sssctl/sssctl_cache.c:1170 +#: src/tools/sssctl/sssctl_cache.c:1171 msgid "Could not determine object domain\n" msgstr "" -#: src/tools/sssctl/sssctl_cache.c:1200 +#: src/tools/sssctl/sssctl_cache.c:1201 msgid "Could not find GUID attribute in GPO entry\n" msgstr "" -#: src/tools/sssctl/sssctl_cache.c:1206 +#: src/tools/sssctl/sssctl_cache.c:1207 #, c-format msgid "Failed to delete GPO: %s\n" msgstr "" -#: src/tools/sssctl/sssctl_cache.c:1210 +#: src/tools/sssctl/sssctl_cache.c:1211 #, c-format msgid "%s removed from cache\n" msgstr "" @@ -2712,39 +2755,39 @@ msgid "" "\"/my/path/sssd.conf\", the snippet dir \"/my/path/conf.d\" is used)" msgstr "" -#: src/tools/sssctl/sssctl_config.c:114 +#: src/tools/sssctl/sssctl_config.c:126 #, c-format msgid "File %1$s does not exist.\n" msgstr "" -#: src/tools/sssctl/sssctl_config.c:115 +#: src/tools/sssctl/sssctl_config.c:127 msgid "There is no configuration.\n" msgstr "" -#: src/tools/sssctl/sssctl_config.c:120 +#: src/tools/sssctl/sssctl_config.c:132 #, c-format msgid "Configuration validation failed: %s\n" msgstr "" -#: src/tools/sssctl/sssctl_config.c:121 +#: src/tools/sssctl/sssctl_config.c:133 msgid "Run with high debug level to see details.\n" msgstr "" -#: src/tools/sssctl/sssctl_config.c:130 -msgid "Failed to run validators" +#: src/tools/sssctl/sssctl_config.c:142 +msgid "Failed to run validators\n" msgstr "" -#: src/tools/sssctl/sssctl_config.c:134 +#: src/tools/sssctl/sssctl_config.c:146 #, c-format msgid "Issues identified by validators: %zu\n" msgstr "" -#: src/tools/sssctl/sssctl_config.c:145 +#: src/tools/sssctl/sssctl_config.c:157 #, c-format msgid "Messages generated during configuration merging: %zu\n" msgstr "" -#: src/tools/sssctl/sssctl_config.c:158 +#: src/tools/sssctl/sssctl_config.c:170 #, c-format msgid "Used configuration snippet files: %zu\n" msgstr "" diff --git a/po/sv.po b/po/sv.po index 62f31542753..8f07ecc9e37 100644 --- a/po/sv.po +++ b/po/sv.po @@ -15,8 +15,8 @@ msgid "" msgstr "" "Project-Id-Version: PACKAGE VERSION\n" "Report-Msgid-Bugs-To: sssd-devel@lists.fedorahosted.org\n" -"POT-Creation-Date: 2026-01-14 14:57+0000\n" -"PO-Revision-Date: 2026-04-23 16:47+0000\n" +"POT-Creation-Date: 2026-10-02 15:57+0000\n" +"PO-Revision-Date: 2026-10-05 16:46+0000\n" "Last-Translator: Weblate Translation Memory \n" "Language-Team: Swedish : that must be enforced " "for PAM access with GSSAPI authentication" msgstr "" +"Lista över par : som måste " +"upprätthållas för PAM-åtkomst med GSSAPI-autentisering" + +#: src/config/SSSDConfig/sssdoptions.py:109 +#, fuzzy +msgid "" +"List of triples :: that assigns " +"additional information from the Kerberos ticket to an authentication " +"indicator." +msgstr "" "Lista av par : som måste upprätthållas " "för PAM-åtkomst med GSSAPI-autentisering" -#: src/config/SSSDConfig/sssdoptions.py:113 +#: src/config/SSSDConfig/sssdoptions.py:112 msgid "Allow passkey device authentication." -msgstr "Tillåt autentisering med lösennyckelsenhet." +msgstr "Tillåt autentisering med lösennyckelenheter." -#: src/config/SSSDConfig/sssdoptions.py:114 +#: src/config/SSSDConfig/sssdoptions.py:113 msgid "How many seconds will pam_sss wait for passkey_child to finish" -msgstr "Hur många sekunder kommer pam_sss vänta på passkey_child att avsluta" +msgstr "Hur länge pam_sss ska vänta på att passkey_child avslutas" -#: src/config/SSSDConfig/sssdoptions.py:115 +#: src/config/SSSDConfig/sssdoptions.py:114 msgid "Enable debugging in the libfido2 library" -msgstr "Aktivera felsökning i biblioteket libfido2" +msgstr "Aktivera felsökning i libfido2-biblioteket" -#: src/config/SSSDConfig/sssdoptions.py:116 +#: src/config/SSSDConfig/sssdoptions.py:115 msgid "Enable JSON protocol for authentication methods selection." msgstr "Aktivera JSON-protokoll för val av autentiseringsmetoder." -#: src/config/SSSDConfig/sssdoptions.py:119 +#: src/config/SSSDConfig/sssdoptions.py:118 msgid "Whether to evaluate the time-based attributes in sudo rules" -msgstr "Om tidsbaserade attribut i sudo-regler skall beräknas" +msgstr "Om tidsbaserade attribut i sudo-regler ska utvärderas" -#: src/config/SSSDConfig/sssdoptions.py:120 +#: src/config/SSSDConfig/sssdoptions.py:119 msgid "If true, SSSD will switch back to lower-wins ordering logic" -msgstr "Om sant kommer SSSD byta tillbaka till ordningslogiken att lägre vinner" +msgstr "" +"Om sant växlar SSSD tillbaka till ordningslogiken där lägre värde vinner" -#: src/config/SSSDConfig/sssdoptions.py:121 +#: src/config/SSSDConfig/sssdoptions.py:120 msgid "" "Maximum number of rules that can be refreshed at once. If this is exceeded, " "full refresh is performed." msgstr "" -"Maximalt antal regler som kan som kan uppdateras samtidigt. Om detta " -"överskrids utförs en fullständig uppdatering." +"Maximalt antal regler som kan uppdateras samtidigt. Om antalet överskrids " +"utförs en fullständig uppdatering." -#: src/config/SSSDConfig/sssdoptions.py:128 +#: src/config/SSSDConfig/sssdoptions.py:127 msgid "Whether to hash host names and addresses in the known_hosts file" -msgstr "" -"Om värdnamn och adresser i known_hosts-filen skall göras till kontrollsummor" +msgstr "Om värdnamn och adresser i known_hosts-filen ska hashas" -#: src/config/SSSDConfig/sssdoptions.py:129 +#: src/config/SSSDConfig/sssdoptions.py:128 msgid "" "How many seconds to keep a host in the known_hosts file after its host keys " "were requested" msgstr "" -"Hur många sekunder att behålla en värd i filen known_hosts efter att dess " -"värdnycklar begärdes" +"Hur länge en värd ska behållas i known_hosts-filen efter att dess " +"värdnycklar har begärts" -#: src/config/SSSDConfig/sssdoptions.py:131 +#: src/config/SSSDConfig/sssdoptions.py:130 msgid "Path to storage of trusted CA certificates" msgstr "Sökväg till lagring av betrodda CA-certifikat" -#: src/config/SSSDConfig/sssdoptions.py:132 +#: src/config/SSSDConfig/sssdoptions.py:131 msgid "Allow to generate ssh-keys from certificates" -msgstr "Tillåt att generera ssh-nycklar från certifikat" +msgstr "Tillåt generering av SSH-nycklar från certifikat" -#: src/config/SSSDConfig/sssdoptions.py:133 +#: src/config/SSSDConfig/sssdoptions.py:132 msgid "" "Use the following matching rules to filter the certificates for ssh-key " "generation" msgstr "" -"Använd följande matchningsregler för att filtrera certifikatet för ssh-" -"nyckelgenerering" +"Använd följande matchningsregler för att filtrera certifikaten för " +"generering av SSH-nycklar" -#: src/config/SSSDConfig/sssdoptions.py:137 +#: src/config/SSSDConfig/sssdoptions.py:136 msgid "List of UIDs or user names allowed to access the PAC responder" -msgstr "Lista över UID:er eller användarnamn som tillåts komma åt PAC-svararen" +msgstr "Lista över UID:er eller användarnamn som får åtkomst till PAC-svararen" -#: src/config/SSSDConfig/sssdoptions.py:138 +#: src/config/SSSDConfig/sssdoptions.py:137 msgid "How long the PAC data is considered valid" msgstr "Hur länge PAC-data betraktas som giltiga" -#: src/config/SSSDConfig/sssdoptions.py:139 +#: src/config/SSSDConfig/sssdoptions.py:138 msgid "Validate the PAC" msgstr "Validera PAC:en" -#: src/config/SSSDConfig/sssdoptions.py:142 +#: src/config/SSSDConfig/sssdoptions.py:141 msgid "List of user attributes the InfoPipe is allowed to publish" -msgstr "Lista över användarattribut InfoPipe får publicera" +msgstr "Lista över användarattribut som InfoPipe får publicera" -#: src/config/SSSDConfig/sssdoptions.py:145 +#: src/config/SSSDConfig/sssdoptions.py:144 msgid "" "One of the following strings specifying the scope of session recording: none " "- No users are recorded. some - Users/groups specified by users and groups " @@ -476,115 +482,115 @@ msgstr "" "Inga användare spelas in. some – Användare/grupper uppräknade i användar- " "och gruppalternativen spelas in. all – Alla användare spelas in." -#: src/config/SSSDConfig/sssdoptions.py:148 +#: src/config/SSSDConfig/sssdoptions.py:147 msgid "" "A comma-separated list of users which should have session recording enabled. " "Matches user names as returned by NSS. I.e. after the possible space " "replacement, case changes, etc." msgstr "" -"En kommaseparerad lista över användare vilka skall ha inspelning av " -"sessioner aktiverat. Matchar användarnamn som de returneras av NSS. D.v.s. " -"efter eventuellt utbyte av mellanslag, ändring av skiftläge, etc." +"En kommaseparerad lista med användare som ska ha sessionsinspelning " +"aktiverad. Matchar användarnamn såsom de returneras av NSS, dvs. efter " +"eventuellt mellanslagsbyte, ändring av skiftläge osv." -#: src/config/SSSDConfig/sssdoptions.py:150 +#: src/config/SSSDConfig/sssdoptions.py:149 msgid "" "A comma-separated list of groups, members of which should have session " "recording enabled. Matches group names as returned by NSS. I.e. after the " "possible space replacement, case changes, etc." msgstr "" -"En kommaseparerad lista över gruppmedlemmar vilka skall ha inspelning av " -"sessioner aktiverat. Matchar gruppnamn som de returneras av NSS. D.v.s. " -"efter eventuellt utbyte av mellanslag, ändring av skiftläge, etc." +"En kommaseparerad lista med grupper vars medlemmar ska ha sessionsinspelning " +"aktiverad. Matchar gruppnamn såsom de returneras av NSS, dvs. efter " +"eventuellt mellanslagsbyte, ändring av skiftläge osv." -#: src/config/SSSDConfig/sssdoptions.py:153 +#: src/config/SSSDConfig/sssdoptions.py:152 msgid "" "A comma-separated list of users to be excluded from recording, only when " "scope=all" msgstr "" -"En kommaseparerad lista av användare att undanta från inspelning, endast när " -"scope=all" +"En kommaseparerad lista över användare som ska undantas från inspelning, " +"endast när scope=all" -#: src/config/SSSDConfig/sssdoptions.py:154 +#: src/config/SSSDConfig/sssdoptions.py:153 msgid "" "A comma-separated list of groups, members of which should be excluded from " "recording, only when scope=all. " msgstr "" -"En kommaseparerad lista av grupper vars medlemmar skall undantas från " -"inspelning, endast när scope=all " +"En kommaseparerad lista över grupper vars medlemmar ska undantas från " +"inspelning, endast när scope=all. " -#: src/config/SSSDConfig/sssdoptions.py:158 +#: src/config/SSSDConfig/sssdoptions.py:157 msgid "Identity provider" msgstr "Identitetsleverantör" -#: src/config/SSSDConfig/sssdoptions.py:159 +#: src/config/SSSDConfig/sssdoptions.py:158 msgid "Authentication provider" msgstr "Autentiseringsleverantör" -#: src/config/SSSDConfig/sssdoptions.py:160 +#: src/config/SSSDConfig/sssdoptions.py:159 msgid "Access control provider" msgstr "Leverantör av åtkomstkontroll" -#: src/config/SSSDConfig/sssdoptions.py:161 +#: src/config/SSSDConfig/sssdoptions.py:160 msgid "Password change provider" -msgstr "Leverantör av lösenordsändringar" +msgstr "Leverantör för lösenordsändring" -#: src/config/SSSDConfig/sssdoptions.py:162 +#: src/config/SSSDConfig/sssdoptions.py:161 msgid "SUDO provider" msgstr "SUDO-leverantör" -#: src/config/SSSDConfig/sssdoptions.py:163 +#: src/config/SSSDConfig/sssdoptions.py:162 msgid "Autofs provider" msgstr "Autofs-leverantör" -#: src/config/SSSDConfig/sssdoptions.py:164 +#: src/config/SSSDConfig/sssdoptions.py:163 msgid "Host identity provider" msgstr "Värdidentitetsleverantör" -#: src/config/SSSDConfig/sssdoptions.py:165 +#: src/config/SSSDConfig/sssdoptions.py:164 msgid "SELinux provider" msgstr "SELinux-leverantör" -#: src/config/SSSDConfig/sssdoptions.py:166 +#: src/config/SSSDConfig/sssdoptions.py:165 msgid "Session management provider" msgstr "Sessionshanteringsleverantör" -#: src/config/SSSDConfig/sssdoptions.py:167 +#: src/config/SSSDConfig/sssdoptions.py:166 msgid "Resolver provider" msgstr "Uppslagsleverantör" -#: src/config/SSSDConfig/sssdoptions.py:170 +#: src/config/SSSDConfig/sssdoptions.py:169 msgid "Whether the domain is usable by the OS or by applications" -msgstr "Huruvida domänen är användbar av OS:et eller av program" +msgstr "Om domänen kan användas av operativsystemet eller av program" -#: src/config/SSSDConfig/sssdoptions.py:171 +#: src/config/SSSDConfig/sssdoptions.py:170 msgid "Enable or disable the domain" msgstr "Aktivera eller avaktivera domänen" -#: src/config/SSSDConfig/sssdoptions.py:172 +#: src/config/SSSDConfig/sssdoptions.py:171 msgid "Minimum user ID" msgstr "Minsta användar-ID" -#: src/config/SSSDConfig/sssdoptions.py:173 +#: src/config/SSSDConfig/sssdoptions.py:172 msgid "Maximum user ID" msgstr "Största användar-ID" -#: src/config/SSSDConfig/sssdoptions.py:174 +#: src/config/SSSDConfig/sssdoptions.py:173 msgid "Enable enumerating all users/groups" msgstr "Aktivera uppräkning av alla användare/grupper" -#: src/config/SSSDConfig/sssdoptions.py:175 +#: src/config/SSSDConfig/sssdoptions.py:174 msgid "Cache credentials for offline login" -msgstr "Cache-kreditiv för frånkopplad inloggning" +msgstr "Cachelagra autentiseringsuppgifter för frånkopplad inloggning" -#: src/config/SSSDConfig/sssdoptions.py:176 +#: src/config/SSSDConfig/sssdoptions.py:175 msgid "Display users/groups in fully-qualified form" msgstr "Visa användare/grupper i fullständigt kvalificerat format" -#: src/config/SSSDConfig/sssdoptions.py:177 +#: src/config/SSSDConfig/sssdoptions.py:176 msgid "Don't include group members in group lookups" msgstr "Inkludera inte gruppmedlemmar i gruppuppslagningar" -#: src/config/SSSDConfig/sssdoptions.py:178 +#: src/config/SSSDConfig/sssdoptions.py:177 #: src/config/SSSDConfig/sssdoptions.py:190 #: src/config/SSSDConfig/sssdoptions.py:191 #: src/config/SSSDConfig/sssdoptions.py:192 @@ -593,61 +599,65 @@ msgstr "Inkludera inte gruppmedlemmar i gruppuppslagningar" #: src/config/SSSDConfig/sssdoptions.py:195 #: src/config/SSSDConfig/sssdoptions.py:196 msgid "Entry cache timeout length (seconds)" -msgstr "Tidsgränslängd för postcache (sekunder)" +msgstr "Tidsgräns för postcachen (sekunder)" -#: src/config/SSSDConfig/sssdoptions.py:179 +#: src/config/SSSDConfig/sssdoptions.py:178 msgid "" "Restrict or prefer a specific address family when performing DNS lookups" msgstr "Begränsa eller föredra en specifik adressfamilj vid DNS-uppslagningar" -#: src/config/SSSDConfig/sssdoptions.py:180 +#: src/config/SSSDConfig/sssdoptions.py:179 msgid "How long to keep cached entries after last successful login (days)" msgstr "" -"Hur länge cachade poster skall behållas efter senaste lyckade inloggning " +"Hur länge cachade poster ska behållas efter den senaste lyckade inloggningen " "(dagar)" -#: src/config/SSSDConfig/sssdoptions.py:181 +#: src/config/SSSDConfig/sssdoptions.py:180 msgid "" "How long should SSSD talk to single DNS server before trying next server " "(miliseconds)" msgstr "" -"Hur länge SSSD skall prata med en enskild DNS-server innan den försöker med " -"nästa server (millisekunder)" +"Hur länge SSSD ska använda en enskild DNS-server innan nästa server provas " +"(millisekunder)" -#: src/config/SSSDConfig/sssdoptions.py:183 +#: src/config/SSSDConfig/sssdoptions.py:182 msgid "How long should keep trying to resolve single DNS query (seconds)" msgstr "" -"Hur länge SSSD skall fortsätta försöka slå upp en enskild DNS-fråga " +"Hur länge uppslagning av en enskild DNS-fråga ska fortsätta försökas " "(sekunder)" -#: src/config/SSSDConfig/sssdoptions.py:184 +#: src/config/SSSDConfig/sssdoptions.py:183 msgid "How long to wait for replies from DNS when resolving servers (seconds)" msgstr "Hur länge man väntar på svar från DNS när servrar slås upp (sekunder)" -#: src/config/SSSDConfig/sssdoptions.py:185 +#: src/config/SSSDConfig/sssdoptions.py:184 msgid "The domain part of service discovery DNS query" msgstr "Domändelen av DNS-frågan för tjänstedetektering" -#: src/config/SSSDConfig/sssdoptions.py:186 +#: src/config/SSSDConfig/sssdoptions.py:185 msgid "" "Specifies the interval, in seconds, that SSSD waits before attempting to " "reconnect to the primary server after a successful connection to the backup " "server" msgstr "" -"Anger intervallet, i sekunder, som SSSD väntar före den försöker återansluta " +"Anger intervallet i sekunder som SSSD väntar innan det försöker återansluta " "till primärservern efter en lyckad anslutning till reservservern" -#: src/config/SSSDConfig/sssdoptions.py:188 +#: src/config/SSSDConfig/sssdoptions.py:187 msgid "Override GID value from the identity provider with this value" msgstr "Åsidosätt GID-värdet från identitetsleverantören med detta värde" -#: src/config/SSSDConfig/sssdoptions.py:189 +#: src/config/SSSDConfig/sssdoptions.py:188 msgid "Treat usernames as case sensitive" msgstr "Behandla användarnamn som skiftlägeskänsliga" +#: src/config/SSSDConfig/sssdoptions.py:189 +msgid "Lookups by ID are expensive or do not work at all" +msgstr "" + #: src/config/SSSDConfig/sssdoptions.py:197 msgid "How often should expired entries be refreshed in background" -msgstr "Hur ofta utgångna poster skall förnyas i bakgrunden" +msgstr "Hur ofta utgångna poster ska uppdateras i bakgrunden" #: src/config/SSSDConfig/sssdoptions.py:198 msgid "Maximum period deviation when refreshing expired entries in background" @@ -656,7 +666,7 @@ msgstr "" #: src/config/SSSDConfig/sssdoptions.py:199 msgid "Whether to automatically update the client's DNS entry" -msgstr "Huruvida klienternas DNS-poster uppdateras automatiskt" +msgstr "Om klientens DNS-post ska uppdateras automatiskt" #: src/config/SSSDConfig/sssdoptions.py:200 msgid "" @@ -668,11 +678,12 @@ msgstr "" #: src/config/SSSDConfig/sssdoptions.py:202 msgid "The TTL to apply to the client's DNS entry after updating it" -msgstr "TTL:en att använda för klientens DNS-post efter att ha uppdaterat den" +msgstr "TTL-värdet som ska användas för klientens DNS-post efter uppdateringen" #: src/config/SSSDConfig/sssdoptions.py:203 msgid "The interface whose IP should be used for dynamic DNS updates" -msgstr "Gränssnittet vars IP skall användas för dynamiska DNS-uppdateringar" +msgstr "" +"Gränssnittet vars IP-adress ska användas för dynamiska DNS-uppdateringar" #: src/config/SSSDConfig/sssdoptions.py:204 msgid "The list of IP addresses that should be used for dynamic DNS updates" @@ -681,7 +692,7 @@ msgstr "" #: src/config/SSSDConfig/sssdoptions.py:205 msgid "How often to periodically update the client's DNS entry" -msgstr "Hur ofta klienternas DNS-poster periodiskt skall uppdateras" +msgstr "Hur ofta klientens DNS-post ska uppdateras periodiskt" #: src/config/SSSDConfig/sssdoptions.py:206 msgid "Maximum period deviation when updating the client's DNS entry" @@ -689,17 +700,15 @@ msgstr "Maximal intervallavvikelse vid uppdatering av klientens DNS-post" #: src/config/SSSDConfig/sssdoptions.py:207 msgid "Whether the provider should explicitly update the PTR record as well" -msgstr "Huruvida leverantören explicit skall uppdatera PTR-posten också" +msgstr "Om leverantören också uttryckligen ska uppdatera PTR-posten" #: src/config/SSSDConfig/sssdoptions.py:208 msgid "Whether the nsupdate utility should default to using TCP" -msgstr "Huruvida verktyget nsupdate skall använda TCP som standard" +msgstr "Om verktyget nsupdate ska använda TCP som standard" #: src/config/SSSDConfig/sssdoptions.py:209 msgid "What kind of authentication should be used to perform the DNS update" -msgstr "" -"Vilken sorts autentisering som skall användas för att utföra DNS-" -"uppdateringen" +msgstr "Vilken typ av autentisering som ska användas för DNS-uppdateringen" #: src/config/SSSDConfig/sssdoptions.py:210 msgid "Override the DNS server used to perform the DNS update" @@ -711,7 +720,7 @@ msgstr "Filen med certifikatutfärdarnas certifikat för DoT" #: src/config/SSSDConfig/sssdoptions.py:212 msgid "The certificate(s) file for authentication for the DoT transport" -msgstr "Certifikatfilen för autentisering för DoT-transporten" +msgstr "Certifikatfilen för autentisering med DoT-transporten" #: src/config/SSSDConfig/sssdoptions.py:213 msgid "The key file for authenticated encryption for the DoT transport" @@ -719,15 +728,15 @@ msgstr "Nyckelfilen för autentiserad kryptering för DoT-transporten" #: src/config/SSSDConfig/sssdoptions.py:214 msgid "How often should subdomains list be refreshed" -msgstr "Hur ofta skall listan över underdomäner uppdateras" +msgstr "Hur ofta listan över underdomäner ska uppdateras" #: src/config/SSSDConfig/sssdoptions.py:215 msgid "Maximum period deviation when refreshing the subdomain list" -msgstr "Maximal intervallavvikelse fid uppdatering av subdomänlistan" +msgstr "Maximal intervallavvikelse vid uppdatering av listan över underdomäner" #: src/config/SSSDConfig/sssdoptions.py:216 msgid "List of options that should be inherited into a subdomain" -msgstr "Lista över flaggor som skall ärvas in i en underdomän" +msgstr "Lista över alternativ som ska ärvas till en underdomän" #: src/config/SSSDConfig/sssdoptions.py:217 msgid "Default subdomain homedir value" @@ -735,11 +744,13 @@ msgstr "Standard hemkatalogvärde för underdomäner" #: src/config/SSSDConfig/sssdoptions.py:218 msgid "How long can cached credentials be used for cached authentication" -msgstr "Hur länge cachade kreditiv får användas för cachad autentisering" +msgstr "" +"Hur länge cachade autentiseringsuppgifter får användas för cachad " +"autentisering" #: src/config/SSSDConfig/sssdoptions.py:219 msgid "Whether to automatically create private groups for users" -msgstr "Huruvida privata grupper för användare skall skapas automatiskt" +msgstr "Om privata grupper för användare ska skapas automatiskt" #: src/config/SSSDConfig/sssdoptions.py:220 msgid "Display a warning N days before the password expires." @@ -749,23 +760,23 @@ msgstr "Visa en varning N dagar före lösenordet går ut." msgid "" "Various tags stored by the realmd configuration service for this domain." msgstr "" -"Diverse taggar lagrade av realmd-konfigurationstjänsten för denna domän." +"Olika taggar som lagras av realmd-konfigurationstjänsten för denna domän." #: src/config/SSSDConfig/sssdoptions.py:222 msgid "" "The provider which should handle fetching of subdomains. This value should " "be always the same as id_provider." msgstr "" -"Leverantören som skall hantera hämtandet av underdomäner. Detta värde skall " -"alltid vara samma som id_provider." +"Leverantören som ska hantera hämtning av underdomäner. Värdet ska alltid " +"vara detsamma som id_provider." #: src/config/SSSDConfig/sssdoptions.py:224 msgid "" "How many seconds to keep a host ssh key after refresh. IE how long to cache " "the host key for." msgstr "" -"Hur många sekunder en värds ssh-nyckel behålls efter en uppdatering. D.v.s. " -"hur länge värdnyckeln skall cachas." +"Hur länge en värds SSH-nyckel ska behållas efter uppdatering, dvs. hur länge " +"värdnyckeln ska cachelagras." #: src/config/SSSDConfig/sssdoptions.py:226 msgid "" @@ -773,9 +784,10 @@ msgid "" "this value determines the minimal length the first authentication factor " "(long term password) must have to be saved as SHA512 hash into the cache." msgstr "" -"Om 2-faktorautentisering (2FA) används och kreditiv skall sparas avgör detta " -"värde den minsta längden den första autentiseringsfaktorn (långvarigt " -"lösenord) måste ha för att sparas som en SHA512-kontrollsumma i cachen." +"Om tvåfaktorsautentisering (2FA) används och autentiseringsuppgifter ska " +"sparas anger detta värde den minsta längd som den första " +"autentiseringsfaktorn (långsiktigt lösenord) måste ha för att kunna sparas " +"som ett SHA512-hashvärde i cachen." #: src/config/SSSDConfig/sssdoptions.py:230 msgid "Local authentication methods policy " @@ -791,7 +803,7 @@ msgstr "IPA-serveradress" #: src/config/SSSDConfig/sssdoptions.py:235 msgid "Address of backup IPA server" -msgstr "Adress till reserv-IPA-server" +msgstr "Adress till reserv-IPA-servern" #: src/config/SSSDConfig/sssdoptions.py:236 msgid "IPA client hostname" @@ -804,7 +816,7 @@ msgstr "Sökbas för HBAC-relaterade objekt" #: src/config/SSSDConfig/sssdoptions.py:238 msgid "" "The amount of time between lookups of the HBAC rules against the IPA server" -msgstr "Tidsåtgången mellan uppslagningar av HBAC-reglerna mot IPA-servern" +msgstr "Tidsintervallet mellan uppslagningar av HBAC-regler mot IPA-servern" #: src/config/SSSDConfig/sssdoptions.py:239 msgid "" @@ -815,11 +827,11 @@ msgstr "" #: src/config/SSSDConfig/sssdoptions.py:241 msgid "If set to false, host argument given by PAM will be ignored" -msgstr "Om satt till falskt kommer värdargument givna av PAM ignoreras" +msgstr "Om värdet sätts till falskt ignoreras värdargumentet från PAM" #: src/config/SSSDConfig/sssdoptions.py:242 msgid "The automounter location this IPA client is using" -msgstr "Platsen för automatmonteraren denna IPA-klient använder" +msgstr "Automonterarplatsen som denna IPA-klient använder" #: src/config/SSSDConfig/sssdoptions.py:243 msgid "Search base for object containing info about IPA domain" @@ -843,7 +855,7 @@ msgstr "Attribut med namnet på vyn" #: src/config/SSSDConfig/sssdoptions.py:248 msgid "Objectclass for override objects" -msgstr "Objektklass för åsidosättande objekt" +msgstr "Objektklass för åsidosättningsobjekt" #: src/config/SSSDConfig/sssdoptions.py:249 msgid "Attribute with the reference to the original object" @@ -851,15 +863,15 @@ msgstr "Attribut med referensen till originalobjektet" #: src/config/SSSDConfig/sssdoptions.py:250 msgid "Objectclass for user override objects" -msgstr "Objektklass för användaråsidosättande objekt" +msgstr "Objektklass för användaråsidosättningsobjekt" #: src/config/SSSDConfig/sssdoptions.py:251 msgid "Objectclass for group override objects" -msgstr "Objektklass för gruppåsidosättande objekt" +msgstr "Objektklass för gruppåsidosättningsobjekt" #: src/config/SSSDConfig/sssdoptions.py:252 msgid "Search base for Desktop Profile related objects" -msgstr "Sökväg för objekt relaterade till skrivbordsprofiler" +msgstr "Sökbas för objekt relaterade till skrivbordsprofiler" #: src/config/SSSDConfig/sssdoptions.py:253 msgid "" @@ -880,12 +892,12 @@ msgstr "" #: src/config/SSSDConfig/sssdoptions.py:258 #: src/config/SSSDConfig/sssdoptions.py:455 msgid "Search base for SUBID ranges" -msgstr "Sökbas för SUBAID-intervall" +msgstr "Sökbas för SUBID-intervall" #: src/config/SSSDConfig/sssdoptions.py:259 -#: src/config/SSSDConfig/sssdoptions.py:506 +#: src/config/SSSDConfig/sssdoptions.py:512 msgid "Which rules should be used to evaluate access control" -msgstr "Vilka regler skall användas för att avgöra åtkomstkontroll" +msgstr "Vilka regler ska användas för att utvärdera åtkomstkontrollen" #: src/config/SSSDConfig/sssdoptions.py:260 msgid "The LDAP attribute that contains FQDN of the host." @@ -957,27 +969,25 @@ msgstr "LDAP-attributet som innehåller UUID/GUID för ett LDAP-nätgruppobjekt. msgid "" "The LDAP attribute that contains whether or not is user map enabled for " "usage." -msgstr "" -"LDAP-attributet som innehåller huruvida användaravbildningar är aktiverade " -"för användning eller inte." +msgstr "LDAP-attributet som anger om användaravbildningen är aktiverad." #: src/config/SSSDConfig/sssdoptions.py:278 msgid "The LDAP attribute that contains host category such as 'all'." -msgstr "LDAP-attributet som innehåller värtkategorin såsom ”all”." +msgstr "LDAP-attributet som innehåller en värdkategori, till exempel ”all”." #: src/config/SSSDConfig/sssdoptions.py:279 msgid "" "The LDAP attribute that contains all hosts / hostgroups this rule match " "against." msgstr "" -"LDAP-attributet som innehåller alla värdar / värdgrupper denna regel matchar " -"mot." +"LDAP-attributet som innehåller alla värdar och värdgrupper som regeln " +"matchar mot." #: src/config/SSSDConfig/sssdoptions.py:281 msgid "" "The LDAP attribute that contains all users / groups this rule match against." msgstr "" -"LDAP-attributet som innehåller alla användare / grupper denna regel matchar " +"LDAP-attributet som innehåller alla användare och grupper som regeln matchar " "mot." #: src/config/SSSDConfig/sssdoptions.py:283 @@ -989,8 +999,8 @@ msgid "" "The LDAP attribute that contains DN of HBAC rule which can be used for " "matching instead of memberUser and memberHost." msgstr "" -"LDAP-attributet som innehåller DN för HBAC-regeln som kan användas för att " -"matcha istället för memberUser och memberHost." +"LDAP-attributet som innehåller DN för en HBAC-regel som kan användas för " +"matchning i stället för memberUser och memberHost." #: src/config/SSSDConfig/sssdoptions.py:287 msgid "The LDAP attribute that contains SELinux user string itself." @@ -998,7 +1008,8 @@ msgstr "LDAP-attributet som innehåller själva SELinux-användarsträngen." #: src/config/SSSDConfig/sssdoptions.py:288 msgid "The LDAP attribute that contains user category such as 'all'." -msgstr "LDAP-attributet som innehåller användarkategorin såsom ”all”." +msgstr "" +"LDAP-attributet som innehåller en användarkategori, till exempel ”all”." #: src/config/SSSDConfig/sssdoptions.py:289 msgid "The LDAP attribute that contains unique ID of the user map." @@ -1009,8 +1020,9 @@ msgid "" "The option denotes that the SSSD is running on IPA server and should perform " "lookups of users and groups from trusted domains differently." msgstr "" -"Flaggan anger att SSSD:n kör på en IPA-server och skall utföra uppslagningar " -"av användare och grupper från betrodda domäner på ett annat sätt." +"Alternativet anger att SSSD kör på en IPA-server och ska utföra " +"uppslagningar av användare och grupper från betrodda domäner på ett annat " +"sätt." #: src/config/SSSDConfig/sssdoptions.py:292 msgid "Use the given string as search base for trusted domains." @@ -1022,15 +1034,15 @@ msgstr "Active Directory-domän" #: src/config/SSSDConfig/sssdoptions.py:296 msgid "Enabled Active Directory domains" -msgstr "Aktivera Active Directory-domäner" +msgstr "Aktiverade Active Directory-domäner" #: src/config/SSSDConfig/sssdoptions.py:297 msgid "Active Directory server address" -msgstr "Adress till Active Directory-server" +msgstr "Active Directory-serveradress" #: src/config/SSSDConfig/sssdoptions.py:298 msgid "Active Directory backup server address" -msgstr "Adress till Active Directory-reservserver" +msgstr "Active Directory-reservserveradress" #: src/config/SSSDConfig/sssdoptions.py:299 msgid "Active Directory client hostname" @@ -1038,16 +1050,16 @@ msgstr "Active Directory-klientvärdnamn" #: src/config/SSSDConfig/sssdoptions.py:300 msgid "Enable DNS sites - location based service discovery" -msgstr "Aktivera DNS-sajter - platsbaserad detektering av tjänster" +msgstr "Aktivera DNS-platser – platsbaserad tjänsteidentifiering" #: src/config/SSSDConfig/sssdoptions.py:301 -#: src/config/SSSDConfig/sssdoptions.py:504 +#: src/config/SSSDConfig/sssdoptions.py:510 msgid "LDAP filter to determine access privileges" msgstr "LDAP-filter för att bestämma åtkomstprivilegier" #: src/config/SSSDConfig/sssdoptions.py:302 msgid "Whether to use the Global Catalog for lookups" -msgstr "Huruvida den globala katalogen skall användas för uppslagningar" +msgstr "Om den globala katalogen ska användas för uppslagningar" #: src/config/SSSDConfig/sssdoptions.py:303 msgid "Operation mode for GPO-based access control" @@ -1057,44 +1069,43 @@ msgstr "Arbetsläge för GPO-baserad åtkomstkontroll" msgid "" "The amount of time between lookups of the GPO policy files against the AD " "server" -msgstr "Tidsåtgången mellan uppslagningar av GPO-policyfiler mot AD-servern" +msgstr "Tidsintervallet mellan uppslagningar av GPO-policyfiler mot AD-servern" #: src/config/SSSDConfig/sssdoptions.py:305 msgid "" "PAM service names that map to the GPO (Deny)InteractiveLogonRight policy " "settings" msgstr "" -"PAM-tjänstenamn som översätts till GPO-policyinställningen (Deny)" -"InteractiveLogonRight" +"PAM-tjänstenamn som mappas till GPO-policyinställningen " +"(Deny)InteractiveLogonRight" #: src/config/SSSDConfig/sssdoptions.py:307 msgid "" "PAM service names that map to the GPO (Deny)RemoteInteractiveLogonRight " "policy settings" msgstr "" -"PAM-tjänstenamn som översätts till GPO-policyinställningen (Deny)" -"RemoteInteractiveLogonRight" +"PAM-tjänstenamn som mappas till GPO-policyinställningen " +"(Deny)RemoteInteractiveLogonRight" #: src/config/SSSDConfig/sssdoptions.py:309 msgid "" "PAM service names that map to the GPO (Deny)NetworkLogonRight policy settings" msgstr "" -"PAM-tjänstenamn som översätts till GPO-policyinställningen (Deny)" -"NetworkLogonRight" +"PAM-tjänstenamn som mappas till GPO-policyinställningen " +"(Deny)NetworkLogonRight" #: src/config/SSSDConfig/sssdoptions.py:310 msgid "" "PAM service names that map to the GPO (Deny)BatchLogonRight policy settings" msgstr "" -"PAM-tjänstenamn som översätts till GPO-policyinställningen (Deny)" -"BatchLogonRight" +"PAM-tjänstenamn som mappas till GPO-policyinställningen (Deny)BatchLogonRight" #: src/config/SSSDConfig/sssdoptions.py:311 msgid "" "PAM service names that map to the GPO (Deny)ServiceLogonRight policy settings" msgstr "" -"PAM-tjänstenamn som översätts till GPO-policyinställningen (Deny)" -"ServiceLogonRight" +"PAM-tjänstenamn som mappas till GPO-policyinställningen " +"(Deny)ServiceLogonRight" #: src/config/SSSDConfig/sssdoptions.py:312 msgid "PAM service names for which GPO-based access is always granted" @@ -1108,25 +1119,25 @@ msgstr "PAM-tjänstenamn för vilka GPO-baserad åtkomst alltid nekas" msgid "" "Default logon right (or permit/deny) to use for unmapped PAM service names" msgstr "" -"Standardinloggningsrättigheter (eller permit/deny) att använda för omappade " +"Standardinloggningsrättighet (eller permit/deny) att använda för omappade " "PAM-tjänstenamn" #: src/config/SSSDConfig/sssdoptions.py:315 msgid "a particular site to be used by the client" -msgstr "en viss sajt att användas av klienten" +msgstr "en viss plats som klienten ska använda" #: src/config/SSSDConfig/sssdoptions.py:316 msgid "" "Maximum age in days before the machine account password should be renewed" -msgstr "Maximal ålder i dagar innan maskinkontots lösenord skall förnyas" +msgstr "Maximal ålder i dagar innan maskinkontots lösenord ska förnyas" #: src/config/SSSDConfig/sssdoptions.py:318 msgid "Option for tuning the machine account renewal task" -msgstr "Flagga för att trimma maskinkontots förnyelseuppgift" +msgstr "Alternativ för finjustering av maskinkontots förnyelseuppgift" #: src/config/SSSDConfig/sssdoptions.py:319 msgid "Whether to update the machine account password in the Samba database" -msgstr "Huruvida lösenordet för maskinkontot i Sambadatabasen skall uppdateras" +msgstr "Om maskinkontots lösenord i Samba-databasen ska uppdateras" #: src/config/SSSDConfig/sssdoptions.py:321 msgid "Use LDAPS port for LDAP and Global Catalog requests" @@ -1135,15 +1146,15 @@ msgstr "Använd LDAPS-porten för LDAP och Global Catalog-begäranden" #: src/config/SSSDConfig/sssdoptions.py:324 #: src/config/SSSDConfig/sssdoptions.py:325 msgid "Kerberos server address" -msgstr "Adress till Kerberosserver" +msgstr "Kerberos-serveradress" #: src/config/SSSDConfig/sssdoptions.py:326 msgid "Kerberos backup server address" -msgstr "Adress till reservserver för Kerberos" +msgstr "Kerberos-reservserveradress" #: src/config/SSSDConfig/sssdoptions.py:327 msgid "Kerberos realm" -msgstr "Kerberosrike" +msgstr "Kerberos-domän" #: src/config/SSSDConfig/sssdoptions.py:328 msgid "Authentication timeout" @@ -1151,31 +1162,33 @@ msgstr "Autentiseringstidsgräns" #: src/config/SSSDConfig/sssdoptions.py:329 msgid "Whether to create kdcinfo files" -msgstr "Huruvida kdcinfo-filer skall skapas" +msgstr "Om kdcinfo-filer ska skapas" #: src/config/SSSDConfig/sssdoptions.py:330 msgid "Where to drop krb5 config snippets" -msgstr "Var konfigurationssnuttar för krb5 skall läggas" +msgstr "Var konfigurationssnuttar för krb5 ska placeras" #: src/config/SSSDConfig/sssdoptions.py:333 msgid "Directory to store credential caches" -msgstr "Katalog att lagra kreditiv-cachar i" +msgstr "Katalog för lagring av cacheminnen med autentiseringsuppgifter" #: src/config/SSSDConfig/sssdoptions.py:334 msgid "Location of the user's credential cache" -msgstr "Plats för användarens kreditiv-cache" +msgstr "Plats för användarens cacheminne med autentiseringsuppgifter" #: src/config/SSSDConfig/sssdoptions.py:335 msgid "Location of the keytab to validate credentials" -msgstr "Plats för nyckeltabellen för att validera kreditiv" +msgstr "" +"Plats för nyckeltabellen som används för att validera autentiseringsuppgifter" #: src/config/SSSDConfig/sssdoptions.py:336 msgid "Enable credential validation" -msgstr "Aktivera validering av kreditiv" +msgstr "Aktivera validering av autentiseringsuppgifter" #: src/config/SSSDConfig/sssdoptions.py:337 msgid "Store password if offline for later online authentication" -msgstr "Lagra lösenord när ej ansluten för ansluten autentisering senare" +msgstr "" +"Lagra lösenord i frånkopplat läge för senare autentisering i anslutet läge" #: src/config/SSSDConfig/sssdoptions.py:338 msgid "Renewable lifetime of the TGT" @@ -1195,32 +1208,33 @@ msgstr "Aktiverar FAST" #: src/config/SSSDConfig/sssdoptions.py:342 msgid "Selects the principal to use for FAST" -msgstr "Väljer huvudman att använda för FAST" +msgstr "Väljer den principal som ska användas för FAST" #: src/config/SSSDConfig/sssdoptions.py:343 msgid "Use anonymous PKINIT to request FAST credentials" -msgstr "Använd anonym PKINIT för att begära FAST-kreditiv" +msgstr "Använd anonym PKINIT för att begära FAST-autentiseringsuppgifter" #: src/config/SSSDConfig/sssdoptions.py:344 msgid "Enables principal canonicalization" -msgstr "Aktivera kanonisk form av huvudman" +msgstr "Aktiverar kanonisering av principal" #: src/config/SSSDConfig/sssdoptions.py:345 msgid "Enables enterprise principals" -msgstr "Aktiverar företagshuvudmän" +msgstr "Aktiverar företagsprincipaler" #: src/config/SSSDConfig/sssdoptions.py:346 msgid "Enables using of subdomains realms for authentication" -msgstr "Aktiverar användningen av underdomänriken för autentisering" +msgstr "Aktiverar användning av underdomändomäner för autentisering" #: src/config/SSSDConfig/sssdoptions.py:347 msgid "A mapping from user names to Kerberos principal names" -msgstr "En översättning från användarnamn till Kerberos huvudmansnamn" +msgstr "En mappning från användarnamn till Kerberos-principalnamn" #: src/config/SSSDConfig/sssdoptions.py:350 #: src/config/SSSDConfig/sssdoptions.py:351 msgid "Server where the change password service is running if not on the KDC" -msgstr "Server där ändringstjänsten för lösenord kör om inte på KDC:n" +msgstr "" +"Server där tjänsten för lösenordsändring körs, om den inte körs på KDC:n" #: src/config/SSSDConfig/sssdoptions.py:354 msgid "ldap_uri, The URI of the LDAP server" @@ -1232,7 +1246,7 @@ msgstr "ldap_backup_uri, URI:n för LDAP-servern" #: src/config/SSSDConfig/sssdoptions.py:356 msgid "The default base DN" -msgstr "Standard bas-DN" +msgstr "Standardbas-DN" #: src/config/SSSDConfig/sssdoptions.py:357 msgid "How to read rootDSE from LDAP server" @@ -1244,35 +1258,35 @@ msgstr "Schematypen som används i LDAP-servern, rfc2307" #: src/config/SSSDConfig/sssdoptions.py:359 msgid "Mode used to change user password" -msgstr "Läge som används för att ändra användares lösenord" +msgstr "Läge som används för att ändra användarens lösenord" #: src/config/SSSDConfig/sssdoptions.py:360 msgid "The default bind DN" -msgstr "Standard bindnings-DN" +msgstr "Standardbindnings-DN" #: src/config/SSSDConfig/sssdoptions.py:361 msgid "The type of the authentication token of the default bind DN" -msgstr "Typen på autentiserings-token för standard bindnings-DN" +msgstr "Typen av autentiseringstoken för standardbindnings-DN" #: src/config/SSSDConfig/sssdoptions.py:362 msgid "The authentication token of the default bind DN" -msgstr "Autentiserings-token för standard bindnings-DN" +msgstr "Autentiseringstoken för standardbindnings-DN" #: src/config/SSSDConfig/sssdoptions.py:363 msgid "Length of time to attempt connection" -msgstr "Tidslängd att försöka ansluta" +msgstr "Hur länge anslutning ska försökas" #: src/config/SSSDConfig/sssdoptions.py:364 msgid "Length of time to attempt synchronous LDAP operations" -msgstr "Tidslängd att försöka synkrona LDAP-operationer" +msgstr "Hur länge synkrona LDAP-åtgärder ska försökas" #: src/config/SSSDConfig/sssdoptions.py:365 msgid "Length of time between attempts to reconnect while offline" -msgstr "Tidslängd mellan försök att återansluta vid frånkoppling" +msgstr "Tidsintervallet mellan återanslutningsförsök i frånkopplat läge" #: src/config/SSSDConfig/sssdoptions.py:366 msgid "Use only the upper case for realm names" -msgstr "Använd endast versaler för namn på riken" +msgstr "Använd endast versaler för domännamn" #: src/config/SSSDConfig/sssdoptions.py:367 msgid "File that contains CA certificates" @@ -1300,23 +1314,23 @@ msgstr "Kräv TLS-certifikatverifiering" #: src/config/SSSDConfig/sssdoptions.py:373 msgid "Specify the sasl mechanism to use" -msgstr "Ange sasl-mekanismen att använda" +msgstr "Ange SASL-mekanismen som ska användas" #: src/config/SSSDConfig/sssdoptions.py:374 msgid "Specify the sasl authorization id to use" -msgstr "Ange sasl-auktorisering-id att använda" +msgstr "Ange det SASL-auktoriserings-ID som ska användas" #: src/config/SSSDConfig/sssdoptions.py:375 msgid "Specify the sasl authorization realm to use" -msgstr "Ange sasl-auktoriseringsrike att använda" +msgstr "Ange den SASL-auktoriseringsdomän som ska användas" #: src/config/SSSDConfig/sssdoptions.py:376 msgid "Specify the minimal SSF for LDAP sasl authorization" -msgstr "Ange minsta SSF för LDAP-sasl-auktorisering" +msgstr "Ange lägsta SSF för LDAP-SASL-auktorisering" #: src/config/SSSDConfig/sssdoptions.py:377 msgid "Specify the maximal SSF for LDAP sasl authorization" -msgstr "Ange största SSF för LDAP-sasl-auktorisering" +msgstr "Ange högsta SSF för LDAP-SASL-auktorisering" #: src/config/SSSDConfig/sssdoptions.py:378 msgid "Kerberos service keytab" @@ -1328,7 +1342,7 @@ msgstr "Använd Kerberosautentisering för LDAP-anslutningar" #: src/config/SSSDConfig/sssdoptions.py:380 msgid "Follow LDAP referrals" -msgstr "Följer LDAP-hänvisningar" +msgstr "Följ LDAP-hänvisningar" #: src/config/SSSDConfig/sssdoptions.py:381 msgid "Lifetime of TGT for LDAP connection" @@ -1336,7 +1350,7 @@ msgstr "Livslängd på TGT för LDAP-anslutning" #: src/config/SSSDConfig/sssdoptions.py:382 msgid "How to dereference aliases" -msgstr "Hur alias skall derefereras" +msgstr "Hur alias ska derefereras" #: src/config/SSSDConfig/sssdoptions.py:383 msgid "Service name for DNS service lookups" @@ -1344,7 +1358,7 @@ msgstr "Tjänstenamn för uppslagning av DNS-tjänster" #: src/config/SSSDConfig/sssdoptions.py:384 msgid "The number of records to retrieve in a single LDAP query" -msgstr "Antalet poster som skall hämtas i en enda LDAP-fråga" +msgstr "Antalet poster som ska hämtas i en enda LDAP-fråga" #: src/config/SSSDConfig/sssdoptions.py:385 msgid "The number of members that must be missing to trigger a full deref" @@ -1360,16 +1374,16 @@ msgid "" "Whether the LDAP library should perform a reverse lookup to canonicalize the " "host name during a SASL bind" msgstr "" -"Huruvida LDAP-biblioteket skall utföra en omvänd uppslagning för att ta fram " -"värdnamnets kanoniska form under en SASL-bindning" +"Om LDAP-biblioteket ska utföra en omvänd uppslagning för att kanonisera " +"värdnamnet under en SASL-bindning" #: src/config/SSSDConfig/sssdoptions.py:389 msgid "" "Allows to retain local users as members of an LDAP group for servers that " "use the RFC2307 schema." msgstr "" -"Tillåter att behålla lokala användare som medlemmar i en LDAP-grupp för " -"servrar som använder schemat RFC2307." +"Gör det möjligt att behålla lokala användare som medlemmar i en LDAP-grupp " +"på servrar som använder RFC2307-schemat." #: src/config/SSSDConfig/sssdoptions.py:392 msgid "entryUSN attribute" @@ -1382,15 +1396,15 @@ msgstr "lastUSN-attribut" #: src/config/SSSDConfig/sssdoptions.py:395 msgid "How long to retain a connection to the LDAP server before disconnecting" msgstr "" -"Hur länge en anslutning till LDAP-servern skall behållas före den kopplas ner" +"Hur länge en anslutning till LDAP-servern ska behållas innan den kopplas ned" #: src/config/SSSDConfig/sssdoptions.py:398 msgid "Disable the LDAP paging control" -msgstr "Avaktivera flödesstyrningen (paging) av LDAP" +msgstr "Inaktivera LDAP-sidindelning" #: src/config/SSSDConfig/sssdoptions.py:399 msgid "Disable Active Directory range retrieval" -msgstr "Avaktivera Active Directorys intervallhämtande" +msgstr "Inaktivera intervallhämtning i Active Directory" #: src/config/SSSDConfig/sssdoptions.py:400 msgid "Use the ppolicy extension" @@ -1401,20 +1415,20 @@ msgid "" "Force a password change when remaining grace logins reach or go below this " "threshold" msgstr "" -"Framtvinga ett lösenordsbyte når fristen med återstående inloggningar nås " -"eller går nedanför detta tröskelvärde" +"Framtvinga lösenordsbyte när antalet återstående respitinloggningar når " +"eller understiger detta tröskelvärde" #: src/config/SSSDConfig/sssdoptions.py:404 msgid "Length of time to wait for a search request" -msgstr "Tidslängd att vänta på en sökbegäran" +msgstr "Hur länge en sökbegäran ska vänta" #: src/config/SSSDConfig/sssdoptions.py:405 msgid "Length of time to wait for a enumeration request" -msgstr "Tidslängd att vänta på en uppräkningsbegäran" +msgstr "Hur länge en uppräkningsbegäran ska vänta" #: src/config/SSSDConfig/sssdoptions.py:406 msgid "Length of time between enumeration updates" -msgstr "Tidslängd mellan uppräkningsuppdateringar" +msgstr "Tidsintervallet mellan uppräkningsuppdateringar" #: src/config/SSSDConfig/sssdoptions.py:407 msgid "Maximum period deviation between enumeration updates" @@ -1422,7 +1436,7 @@ msgstr "Maximal intervallavvikelse mellan uppräkningsuppdateringar" #: src/config/SSSDConfig/sssdoptions.py:408 msgid "Length of time between cache cleanups" -msgstr "Tidslängd mellan cache-tömningar" +msgstr "Tidsintervallet mellan cacherensningar" #: src/config/SSSDConfig/sssdoptions.py:409 msgid "Maximum time deviation between cache cleanups" @@ -1434,7 +1448,7 @@ msgstr "Kräv TLS för ID-uppslagningar" #: src/config/SSSDConfig/sssdoptions.py:411 msgid "Use ID-mapping of objectSID instead of pre-set IDs" -msgstr "Använd ID-översättning av objectSID istället för förhandssatta ID:n" +msgstr "Använd ID-mappning av objectSID i stället för förinställda ID:n" #: src/config/SSSDConfig/sssdoptions.py:412 msgid "Base DN for user lookups" @@ -1442,7 +1456,7 @@ msgstr "Bas-DN för användaruppslagningar" #: src/config/SSSDConfig/sssdoptions.py:413 msgid "Scope of user lookups" -msgstr "Omfång av användaruppslagningar" +msgstr "Sökintervall för användaruppslagningar" #: src/config/SSSDConfig/sssdoptions.py:414 msgid "Filter for user lookups" @@ -1470,7 +1484,7 @@ msgstr "GECOS-attribut" #: src/config/SSSDConfig/sssdoptions.py:420 msgid "Home directory attribute" -msgstr "Hemkatalogattribut" +msgstr "Attribut för hemkatalog" #: src/config/SSSDConfig/sssdoptions.py:421 msgid "Shell attribute" @@ -1481,7 +1495,7 @@ msgid "UUID attribute" msgstr "UUID-attribut" #: src/config/SSSDConfig/sssdoptions.py:423 -#: src/config/SSSDConfig/sssdoptions.py:464 +#: src/config/SSSDConfig/sssdoptions.py:470 msgid "objectSID attribute" msgstr "objectSID-attribut" @@ -1491,7 +1505,7 @@ msgstr "Primärt gruppattribut i Active Directory för ID-mappning" #: src/config/SSSDConfig/sssdoptions.py:425 msgid "User principal attribute (for Kerberos)" -msgstr "Användarens huvudmansattribut (för Kerberos)" +msgstr "Attribut för användarprincipal (för Kerberos)" #: src/config/SSSDConfig/sssdoptions.py:426 msgid "Full Name" @@ -1499,15 +1513,15 @@ msgstr "Fullständigt namn" #: src/config/SSSDConfig/sssdoptions.py:427 msgid "memberOf attribute" -msgstr "medlemAv-attribut" +msgstr "memberOf-attribut" #: src/config/SSSDConfig/sssdoptions.py:428 msgid "Modification time attribute" -msgstr "Modifieringstidsattribut" +msgstr "Attribut för ändringstid" #: src/config/SSSDConfig/sssdoptions.py:429 msgid "shadowLastChange attribute" -msgstr "attributet shadowLastChange" +msgstr "shadowLastChange-attribut" #: src/config/SSSDConfig/sssdoptions.py:430 msgid "shadowMin attribute" @@ -1555,7 +1569,7 @@ msgstr "krbPasswordExpiration-attribut" #: src/config/SSSDConfig/sssdoptions.py:441 msgid "Attribute indicating that server side password policies are active" -msgstr "Attribut som indikerar att serversidans lösenordspolicyer är aktiva" +msgstr "Attribut som anger att lösenordspolicyerna på serversidan är aktiva" #: src/config/SSSDConfig/sssdoptions.py:442 msgid "accountExpires attribute of AD" @@ -1571,15 +1585,15 @@ msgstr "attributet nsAccountLock" #: src/config/SSSDConfig/sssdoptions.py:445 msgid "loginDisabled attribute of NDS" -msgstr "NDS attribut loginDisabled" +msgstr "NDS-attributet loginDisabled" #: src/config/SSSDConfig/sssdoptions.py:446 msgid "loginExpirationTime attribute of NDS" -msgstr "NDS attribut loginExpirationTime" +msgstr "NDS-attributet loginExpirationTime" #: src/config/SSSDConfig/sssdoptions.py:447 msgid "loginAllowedTimeMap attribute of NDS" -msgstr "NDS attribut loginAllowedTimeMap" +msgstr "NDS-attributet loginAllowedTimeMap" #: src/config/SSSDConfig/sssdoptions.py:448 msgid "SSH public key attribute" @@ -1587,221 +1601,251 @@ msgstr "Attribut för publik SSH-nyckel" #: src/config/SSSDConfig/sssdoptions.py:449 msgid "attribute listing allowed authentication types for a user" -msgstr "attribut för listning av tillåtna autentiseringstyper för en användare" +msgstr "Attribut som listar tillåtna autentiseringstyper för en användare" #: src/config/SSSDConfig/sssdoptions.py:450 msgid "attribute containing the X509 certificate of the user" -msgstr "attribut som innehåller användarens X509-certifikat" +msgstr "Attribut som innehåller användarens X.509-certifikat" #: src/config/SSSDConfig/sssdoptions.py:451 msgid "attribute containing the email address of the user" -msgstr "attribut som innehåller e-postadresser till användaren" +msgstr "Attribut som innehåller användarens e-postadress" #: src/config/SSSDConfig/sssdoptions.py:452 msgid "attribute containing the passkey mapping data of the user" -msgstr "attribut som innehåller avbildningsdata för lösennyckel för användaren" +msgstr "Attribut som innehåller användarens mappningsdata för lösennyckel" #: src/config/SSSDConfig/sssdoptions.py:453 msgid "A list of extra attributes to download along with the user entry" msgstr "En lista över extra attribut att hämta tillsammans med användarposten" +#: src/config/SSSDConfig/sssdoptions.py:456 +#, fuzzy +msgid "The object class of an subid entry in LDAP." +msgstr "Objektklassen hos en värdpost i LDAP." + #: src/config/SSSDConfig/sssdoptions.py:457 +#, fuzzy +msgid "Subordinate user ID count attribute" +msgstr "Attribut för sudo-regelanvändare" + +#: src/config/SSSDConfig/sssdoptions.py:458 +#, fuzzy +msgid "Subordinate group ID count attribute" +msgstr "Attribut för sudo-regelflaggor" + +#: src/config/SSSDConfig/sssdoptions.py:459 +#, fuzzy +msgid "User ID range start value attribute" +msgstr "Användarnamnsattribut" + +#: src/config/SSSDConfig/sssdoptions.py:460 +#, fuzzy +msgid "Group ID range start value attribute" +msgstr "Grupp-UUID-attribut" + +#: src/config/SSSDConfig/sssdoptions.py:461 +msgid "Owner of an entry" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:463 msgid "Base DN for group lookups" msgstr "Bas-DN för gruppuppslagningar" -#: src/config/SSSDConfig/sssdoptions.py:458 +#: src/config/SSSDConfig/sssdoptions.py:464 msgid "Objectclass for groups" msgstr "Objektklass för grupper" -#: src/config/SSSDConfig/sssdoptions.py:459 +#: src/config/SSSDConfig/sssdoptions.py:465 msgid "Group name" msgstr "Gruppnamn" -#: src/config/SSSDConfig/sssdoptions.py:460 +#: src/config/SSSDConfig/sssdoptions.py:466 msgid "Group password" msgstr "Grupplösenord" -#: src/config/SSSDConfig/sssdoptions.py:461 +#: src/config/SSSDConfig/sssdoptions.py:467 msgid "GID attribute" msgstr "GID-attribut" -#: src/config/SSSDConfig/sssdoptions.py:462 +#: src/config/SSSDConfig/sssdoptions.py:468 msgid "Group member attribute" msgstr "Gruppmedlemsattribut" -#: src/config/SSSDConfig/sssdoptions.py:463 +#: src/config/SSSDConfig/sssdoptions.py:469 msgid "Group UUID attribute" msgstr "Grupp-UUID-attribut" -#: src/config/SSSDConfig/sssdoptions.py:465 +#: src/config/SSSDConfig/sssdoptions.py:471 msgid "Modification time attribute for groups" msgstr "Modifieringstidsattribut för grupper" -#: src/config/SSSDConfig/sssdoptions.py:466 +#: src/config/SSSDConfig/sssdoptions.py:472 msgid "Type of the group and other flags" msgstr "Typen av grupp och andra flaggor" -#: src/config/SSSDConfig/sssdoptions.py:467 +#: src/config/SSSDConfig/sssdoptions.py:473 msgid "The LDAP group external member attribute" msgstr "LDAP-gruppens externa medlemsattribut" -#: src/config/SSSDConfig/sssdoptions.py:468 +#: src/config/SSSDConfig/sssdoptions.py:474 msgid "Maximum nesting level SSSD will follow" -msgstr "Maximal nästlingsnivå SSSD kommer följa" +msgstr "Maximal kapslingsnivå som SSSD ska följa" -#: src/config/SSSDConfig/sssdoptions.py:469 +#: src/config/SSSDConfig/sssdoptions.py:475 msgid "Filter for group lookups" msgstr "Filter för gruppuppslagningar" -#: src/config/SSSDConfig/sssdoptions.py:470 +#: src/config/SSSDConfig/sssdoptions.py:476 msgid "Scope of group lookups" -msgstr "Omfång av gruppuppslagningar" +msgstr "Sökintervall för gruppuppslagningar" -#: src/config/SSSDConfig/sssdoptions.py:472 +#: src/config/SSSDConfig/sssdoptions.py:478 msgid "Base DN for netgroup lookups" msgstr "Bas-DN för nätgruppuppslagningar" -#: src/config/SSSDConfig/sssdoptions.py:473 +#: src/config/SSSDConfig/sssdoptions.py:479 msgid "Objectclass for netgroups" msgstr "Objektklass för nätgrupper" -#: src/config/SSSDConfig/sssdoptions.py:474 +#: src/config/SSSDConfig/sssdoptions.py:480 msgid "Netgroup name" msgstr "Nätgruppnamn" -#: src/config/SSSDConfig/sssdoptions.py:475 +#: src/config/SSSDConfig/sssdoptions.py:481 msgid "Netgroups members attribute" -msgstr "Attribut på nätgruppmedlemmar" +msgstr "Attribut för nätgruppmedlemmar" -#: src/config/SSSDConfig/sssdoptions.py:476 +#: src/config/SSSDConfig/sssdoptions.py:482 msgid "Netgroup triple attribute" -msgstr "Attribut på nätgruppstripplar" +msgstr "Attribut för nätgruppstrippel" -#: src/config/SSSDConfig/sssdoptions.py:477 +#: src/config/SSSDConfig/sssdoptions.py:483 msgid "Modification time attribute for netgroups" -msgstr "Modifieringstidsattribut för nätgrupper" +msgstr "Attribut för ändringstid för nätgrupper" -#: src/config/SSSDConfig/sssdoptions.py:479 +#: src/config/SSSDConfig/sssdoptions.py:485 msgid "Base DN for service lookups" msgstr "Bas-DN för tjänsteuppslagningar" -#: src/config/SSSDConfig/sssdoptions.py:480 +#: src/config/SSSDConfig/sssdoptions.py:486 msgid "Objectclass for services" msgstr "Objektklass för tjänster" -#: src/config/SSSDConfig/sssdoptions.py:481 +#: src/config/SSSDConfig/sssdoptions.py:487 msgid "Service name attribute" msgstr "Tjänstenamnsattribut" -#: src/config/SSSDConfig/sssdoptions.py:482 +#: src/config/SSSDConfig/sssdoptions.py:488 msgid "Service port attribute" msgstr "Tjänsteportsattribut" -#: src/config/SSSDConfig/sssdoptions.py:483 +#: src/config/SSSDConfig/sssdoptions.py:489 msgid "Service protocol attribute" msgstr "Tjänsteprotokollsattribut" -#: src/config/SSSDConfig/sssdoptions.py:485 +#: src/config/SSSDConfig/sssdoptions.py:491 msgid "Lower bound for ID-mapping" msgstr "Undre gräns för ID-mappning" -#: src/config/SSSDConfig/sssdoptions.py:486 +#: src/config/SSSDConfig/sssdoptions.py:492 msgid "Upper bound for ID-mapping" msgstr "Övre gräns för ID-mappning" -#: src/config/SSSDConfig/sssdoptions.py:487 +#: src/config/SSSDConfig/sssdoptions.py:493 msgid "Number of IDs for each slice when ID-mapping" -msgstr "Antal ID:n till varje skiva vid ID-mappning" +msgstr "Antal ID:n för varje intervall vid ID-mappning" -#: src/config/SSSDConfig/sssdoptions.py:488 +#: src/config/SSSDConfig/sssdoptions.py:494 msgid "Use autorid-compatible algorithm for ID-mapping" msgstr "Använd en autorid-kompatibel algoritm för ID-mappning" -#: src/config/SSSDConfig/sssdoptions.py:489 +#: src/config/SSSDConfig/sssdoptions.py:495 msgid "Name of the default domain for ID-mapping" -msgstr "Standarddomänens namn för ID-mappning" +msgstr "Namnet på standarddomänen för ID-mappning" -#: src/config/SSSDConfig/sssdoptions.py:490 +#: src/config/SSSDConfig/sssdoptions.py:496 msgid "SID of the default domain for ID-mapping" -msgstr "Standarddomänens SID för ID-mappning" +msgstr "SID för standarddomänen för ID-mappning" -#: src/config/SSSDConfig/sssdoptions.py:491 +#: src/config/SSSDConfig/sssdoptions.py:497 msgid "Number of secondary slices" -msgstr "Antal sekundära skivor" +msgstr "Antal sekundära intervall" -#: src/config/SSSDConfig/sssdoptions.py:493 +#: src/config/SSSDConfig/sssdoptions.py:499 msgid "Whether to use Token-Groups" -msgstr "Huruvida Token-Groups skall användas" +msgstr "Om Token-Groups ska användas" -#: src/config/SSSDConfig/sssdoptions.py:494 +#: src/config/SSSDConfig/sssdoptions.py:500 msgid "Set lower boundary for allowed IDs from the LDAP server" msgstr "Sätt undre gräns för tillåtna ID:n från LDAP-servern" -#: src/config/SSSDConfig/sssdoptions.py:495 +#: src/config/SSSDConfig/sssdoptions.py:501 msgid "Set upper boundary for allowed IDs from the LDAP server" msgstr "Sätt övre gräns för tillåtna ID:n från LDAP-servern" -#: src/config/SSSDConfig/sssdoptions.py:496 +#: src/config/SSSDConfig/sssdoptions.py:502 msgid "DN for ppolicy queries" msgstr "DN för ppolicy-frågor" -#: src/config/SSSDConfig/sssdoptions.py:497 +#: src/config/SSSDConfig/sssdoptions.py:503 msgid "How many maximum entries to fetch during a wildcard request" -msgstr "Hur många poster att maximalt hämta i en joker-begäran" +msgstr "Maximalt antal poster att hämta vid en jokerteckenbegäran" -#: src/config/SSSDConfig/sssdoptions.py:498 +#: src/config/SSSDConfig/sssdoptions.py:504 msgid "Set libldap debug level" msgstr "Sätt felsökningsnivå för libldap" -#: src/config/SSSDConfig/sssdoptions.py:501 +#: src/config/SSSDConfig/sssdoptions.py:507 msgid "Policy to evaluate the password expiration" -msgstr "Policy för att utvärdera utgång av lösenord" +msgstr "Policy för utvärdering av lösenordets utgång" -#: src/config/SSSDConfig/sssdoptions.py:505 +#: src/config/SSSDConfig/sssdoptions.py:511 msgid "Which attributes shall be used to evaluate if an account is expired" -msgstr "Vilka attribut skall användas för att avgöra om ett konto gått ut" +msgstr "" +"Vilka attribut som ska användas för att avgöra om ett konto har gått ut" -#: src/config/SSSDConfig/sssdoptions.py:509 +#: src/config/SSSDConfig/sssdoptions.py:515 msgid "URI of an LDAP server where password changes are allowed" msgstr "URI till en LDAP-server där lösenordsändringar är tillåtna" -#: src/config/SSSDConfig/sssdoptions.py:510 +#: src/config/SSSDConfig/sssdoptions.py:516 msgid "URI of a backup LDAP server where password changes are allowed" msgstr "URI till en reserv-LDAP-server där lösenordsändringar är tillåtna" -#: src/config/SSSDConfig/sssdoptions.py:511 +#: src/config/SSSDConfig/sssdoptions.py:517 msgid "DNS service name for LDAP password change server" msgstr "DNS-tjänstenamn för LDAP-lösenordsändringsservern" -#: src/config/SSSDConfig/sssdoptions.py:512 +#: src/config/SSSDConfig/sssdoptions.py:518 msgid "" "Whether to update the ldap_user_shadow_last_change attribute after a " "password change" msgstr "" -"Huruvida attributet ldap_user_shadow_last_change skall uppdateras efter en " -"ändring av lösenord" +"Om attributet ldap_user_shadow_last_change ska uppdateras efter ett " +"lösenordsbyte" -#: src/config/SSSDConfig/sssdoptions.py:516 +#: src/config/SSSDConfig/sssdoptions.py:522 msgid "Base DN for sudo rules lookups" -msgstr "Bas-DN för regeluppslagningar" +msgstr "Bas-DN för uppslagning av sudo-regler" -#: src/config/SSSDConfig/sssdoptions.py:517 +#: src/config/SSSDConfig/sssdoptions.py:523 msgid "Automatic full refresh period" -msgstr "Intervall mellan automatisk fullständig omläsning" +msgstr "Intervall för automatisk fullständig uppdatering" -#: src/config/SSSDConfig/sssdoptions.py:518 +#: src/config/SSSDConfig/sssdoptions.py:524 msgid "Automatic smart refresh period" -msgstr "Intervall mellan automatisk smart omläsning" +msgstr "Intervall för automatisk inkrementell uppdatering" -#: src/config/SSSDConfig/sssdoptions.py:519 +#: src/config/SSSDConfig/sssdoptions.py:525 msgid "Smart and full refresh random offset" -msgstr "Förskjutning mellan smart och fullständig omläsning" +msgstr "Slumpmässig förskjutning för inkrementell och fullständig uppdatering" -#: src/config/SSSDConfig/sssdoptions.py:520 +#: src/config/SSSDConfig/sssdoptions.py:526 msgid "Whether to filter rules by hostname, IP addresses and network" -msgstr "Huruvida regler skall filtreras efter värdnamn, IP-adresser och nätverk" +msgstr "Om regler ska filtreras efter värdnamn, IP-adresser och nätverk" -#: src/config/SSSDConfig/sssdoptions.py:521 +#: src/config/SSSDConfig/sssdoptions.py:527 msgid "" "Hostnames and/or fully qualified domain names of this machine to filter sudo " "rules" @@ -1809,201 +1853,199 @@ msgstr "" "Värdnamn och/eller fullständigt kvalificerade domännamn på denna maskin för " "att filtrera sudo-regler" -#: src/config/SSSDConfig/sssdoptions.py:522 +#: src/config/SSSDConfig/sssdoptions.py:528 msgid "IPv4 or IPv6 addresses or network of this machine to filter sudo rules" msgstr "" "IPv4- eller IPv6-adresser eller -nätverk för denna maskin för att filtrera " "sudo-regler" -#: src/config/SSSDConfig/sssdoptions.py:523 +#: src/config/SSSDConfig/sssdoptions.py:529 msgid "Whether to include rules that contains netgroup in host attribute" -msgstr "" -"Huruvida regler som innehåller nätgrupper i värdattribut skall inkluderas" +msgstr "Om regler som innehåller en nätgrupp i värdattributet ska tas med" -#: src/config/SSSDConfig/sssdoptions.py:524 +#: src/config/SSSDConfig/sssdoptions.py:530 msgid "" "Whether to include rules that contains regular expression in host attribute" msgstr "" -"Huruvida regler som innehåller reguljära uttryck i värdattribut skall " -"inkluderas" +"Om regler som innehåller ett reguljärt uttryck i värdattributet ska tas med" -#: src/config/SSSDConfig/sssdoptions.py:525 +#: src/config/SSSDConfig/sssdoptions.py:531 msgid "Object class for sudo rules" msgstr "Objektklass för sudo-regler" -#: src/config/SSSDConfig/sssdoptions.py:526 +#: src/config/SSSDConfig/sssdoptions.py:532 msgid "Name of attribute that is used as object class for sudo rules" msgstr "Namn på attributet som används som objektklass för sudo-regler" -#: src/config/SSSDConfig/sssdoptions.py:527 +#: src/config/SSSDConfig/sssdoptions.py:533 msgid "Sudo rule name" -msgstr "Sudo-regelnamn" +msgstr "Namn på sudo-regel" -#: src/config/SSSDConfig/sssdoptions.py:528 +#: src/config/SSSDConfig/sssdoptions.py:534 msgid "Sudo rule command attribute" -msgstr "Attribut för sudo-regelkommandon" +msgstr "Kommandoattribut för sudo-regel" -#: src/config/SSSDConfig/sssdoptions.py:529 +#: src/config/SSSDConfig/sssdoptions.py:535 msgid "Sudo rule host attribute" -msgstr "Attribut för sudo-regelvärd" +msgstr "Värdattribut för sudo-regel" -#: src/config/SSSDConfig/sssdoptions.py:530 +#: src/config/SSSDConfig/sssdoptions.py:536 msgid "Sudo rule user attribute" -msgstr "Attribut för sudo-regelanvändare" +msgstr "Användarattribut för sudo-regel" -#: src/config/SSSDConfig/sssdoptions.py:531 +#: src/config/SSSDConfig/sssdoptions.py:537 msgid "Sudo rule option attribute" -msgstr "Attribut för sudo-regelflaggor" +msgstr "Alternativattribut för sudo-regel" -#: src/config/SSSDConfig/sssdoptions.py:532 +#: src/config/SSSDConfig/sssdoptions.py:538 msgid "Sudo rule runas attribute" -msgstr "Sudo-regel-runas-attribut" +msgstr "Runas-attribut för sudo-regel" -#: src/config/SSSDConfig/sssdoptions.py:533 +#: src/config/SSSDConfig/sssdoptions.py:539 msgid "Sudo rule runasuser attribute" -msgstr "Attribut för sudo-runasuser" +msgstr "Runasuser-attribut för sudo-regel" -#: src/config/SSSDConfig/sssdoptions.py:534 +#: src/config/SSSDConfig/sssdoptions.py:540 msgid "Sudo rule runasgroup attribute" -msgstr "Attribut på runasgroup i sudo-regel" +msgstr "Runasgroup-attribut för sudo-regel" -#: src/config/SSSDConfig/sssdoptions.py:535 +#: src/config/SSSDConfig/sssdoptions.py:541 msgid "Sudo rule notbefore attribute" -msgstr "Attribut för sudo-notbefore-regler" +msgstr "Notbefore-attribut för sudo-regel" -#: src/config/SSSDConfig/sssdoptions.py:536 +#: src/config/SSSDConfig/sssdoptions.py:542 msgid "Sudo rule notafter attribute" -msgstr "Attribut för sudo-notafter-regler" +msgstr "Notafter-attribut för sudo-regel" -#: src/config/SSSDConfig/sssdoptions.py:537 +#: src/config/SSSDConfig/sssdoptions.py:543 msgid "Sudo rule order attribute" -msgstr "Attribut för sudo-order-regler" +msgstr "Order-attribut för sudo-regel" -#: src/config/SSSDConfig/sssdoptions.py:540 +#: src/config/SSSDConfig/sssdoptions.py:546 msgid "Object class for automounter maps" -msgstr "Objektklass för avbildningar för automatmonterare" +msgstr "Objektklass för automonterarkartor" -#: src/config/SSSDConfig/sssdoptions.py:541 +#: src/config/SSSDConfig/sssdoptions.py:547 msgid "Automounter map name attribute" -msgstr "Attribut för namn i avbildningar för automatmonterare" +msgstr "Namn-attribut för automonterarkarta" -#: src/config/SSSDConfig/sssdoptions.py:542 +#: src/config/SSSDConfig/sssdoptions.py:548 msgid "Object class for automounter map entries" -msgstr "Objektklass för poster i avbildningar för automatmonterare" +msgstr "Objektklass för poster i automonterarkartor" -#: src/config/SSSDConfig/sssdoptions.py:543 +#: src/config/SSSDConfig/sssdoptions.py:549 msgid "Automounter map entry key attribute" -msgstr "Attribut för postnycklar i avbildningar för automatmonterare" +msgstr "Nyckelattribut för post i automonterarkarta" -#: src/config/SSSDConfig/sssdoptions.py:544 +#: src/config/SSSDConfig/sssdoptions.py:550 msgid "Automounter map entry value attribute" -msgstr "Attribut på postvärde i avbildning för automatmonteraren" +msgstr "Värdeattribut för post i automonterarkarta" -#: src/config/SSSDConfig/sssdoptions.py:545 +#: src/config/SSSDConfig/sssdoptions.py:551 msgid "Base DN for automounter map lookups" -msgstr "Bas-DN för uppslagningar i avbildningar för automatmonterare" +msgstr "Bas-DN för uppslagning av automonterarkartor" -#: src/config/SSSDConfig/sssdoptions.py:546 +#: src/config/SSSDConfig/sssdoptions.py:552 msgid "The name of the automount master map in LDAP." -msgstr "Namnet på automount master-kartan i LDAP." +msgstr "Namnet på huvudkartan för automatmontering i LDAP." -#: src/config/SSSDConfig/sssdoptions.py:549 +#: src/config/SSSDConfig/sssdoptions.py:555 msgid "Base DN for IP hosts lookups" -msgstr "Bas-DN för IP-värd-uppslagningar" +msgstr "Bas-DN för uppslagning av IP-värdar" -#: src/config/SSSDConfig/sssdoptions.py:550 +#: src/config/SSSDConfig/sssdoptions.py:556 msgid "Object class for IP hosts" msgstr "Objektklass för IP-värdar" -#: src/config/SSSDConfig/sssdoptions.py:551 +#: src/config/SSSDConfig/sssdoptions.py:557 msgid "IP host name attribute" msgstr "IP-värdnamnsattribut" -#: src/config/SSSDConfig/sssdoptions.py:552 +#: src/config/SSSDConfig/sssdoptions.py:558 msgid "IP host number (address) attribute" -msgstr "IP-värdnummer- (adress-)attribut" +msgstr "Adressattribut för IP-värd" -#: src/config/SSSDConfig/sssdoptions.py:553 +#: src/config/SSSDConfig/sssdoptions.py:559 msgid "IP host entryUSN attribute" msgstr "IP-värd-entryUSN-attribut" -#: src/config/SSSDConfig/sssdoptions.py:554 +#: src/config/SSSDConfig/sssdoptions.py:560 msgid "Base DN for IP networks lookups" -msgstr "Bas-DN för IP-nätverks-uppslagningar" +msgstr "Bas-DN för uppslagning av IP-nätverk" -#: src/config/SSSDConfig/sssdoptions.py:555 +#: src/config/SSSDConfig/sssdoptions.py:561 msgid "Object class for IP networks" msgstr "Objektklass för IP-nätverk" -#: src/config/SSSDConfig/sssdoptions.py:556 +#: src/config/SSSDConfig/sssdoptions.py:562 msgid "IP network name attribute" msgstr "IP-nätverksnamnsattribut" -#: src/config/SSSDConfig/sssdoptions.py:557 +#: src/config/SSSDConfig/sssdoptions.py:563 msgid "IP network number (address) attribute" -msgstr "IP-nätverksnummer- (adress-)attribut" +msgstr "Adressattribut för IP-nätverk" -#: src/config/SSSDConfig/sssdoptions.py:558 +#: src/config/SSSDConfig/sssdoptions.py:564 msgid "IP network entryUSN attribute" msgstr "IP-nätverks-entryUSN-attribut" -#: src/config/SSSDConfig/sssdoptions.py:561 +#: src/config/SSSDConfig/sssdoptions.py:567 msgid "Comma separated list of allowed users" msgstr "Kommaseparerad lista över tillåtna användare" -#: src/config/SSSDConfig/sssdoptions.py:562 +#: src/config/SSSDConfig/sssdoptions.py:568 msgid "Comma separated list of prohibited users" msgstr "Kommaseparerad lista över förbjudna användare" -#: src/config/SSSDConfig/sssdoptions.py:563 +#: src/config/SSSDConfig/sssdoptions.py:569 msgid "" "Comma separated list of groups that are allowed to log in. This applies only " "to groups within this SSSD domain. Local groups are not evaluated." msgstr "" -"Kommaseparerad lista över grupper som tillåts logga in. Detta är endast " -"tillämpligt på grupper i denna SSSD-domän. Lokala grupper utvärderas inte." +"Kommaseparerad lista över grupper som får logga in. Detta gäller endast " +"grupper i denna SSSD-domän. Lokala grupper utvärderas inte." -#: src/config/SSSDConfig/sssdoptions.py:565 +#: src/config/SSSDConfig/sssdoptions.py:571 msgid "" "Comma separated list of groups that are explicitly denied access. This " "applies only to groups within this SSSD domain. Local groups are not " "evaluated." msgstr "" -"Kommaseparerad lista över grupper som nekas åtkomst. Detta är endast " -"tillämpligt på grupper i denna SSSD-domän. Lokala grupper utvärderas inte." +"Kommaseparerad lista över grupper som uttryckligen nekas åtkomst. Detta " +"gäller endast grupper i denna SSSD-domän. Lokala grupper utvärderas inte." -#: src/config/SSSDConfig/sssdoptions.py:569 +#: src/config/SSSDConfig/sssdoptions.py:575 msgid "The number of preforked proxy children." -msgstr "Antal ombudsbarn före grening." +msgstr "Antalet förstartade underprocesser för proxyn." -#: src/config/SSSDConfig/sssdoptions.py:572 +#: src/config/SSSDConfig/sssdoptions.py:578 msgid "The name of the NSS library to use" msgstr "Namnet på NSS-biblioteket att använda" -#: src/config/SSSDConfig/sssdoptions.py:573 +#: src/config/SSSDConfig/sssdoptions.py:579 msgid "The name of the NSS library to use for hosts and networks lookups" msgstr "" "Namnet på NSS-biblioteket som används för värd- och nätverksuppslagningar" -#: src/config/SSSDConfig/sssdoptions.py:574 +#: src/config/SSSDConfig/sssdoptions.py:580 msgid "Whether to look up canonical group name from cache if possible" -msgstr "Huruvida kanoniska gruppnamn skall slås upp från cachen om möjligt" +msgstr "Om kanoniskt gruppnamn ska slås upp från cachen om möjligt" -#: src/config/SSSDConfig/sssdoptions.py:577 +#: src/config/SSSDConfig/sssdoptions.py:583 msgid "PAM stack to use" -msgstr "PAM-stack att använda" +msgstr "PAM-stack som ska användas" -#: src/config/SSSDConfig/sssdoptions.py:580 +#: src/config/SSSDConfig/sssdoptions.py:586 msgid "Path of passwd file sources." msgstr "Sökväg till lösenordsfilkällor." -#: src/config/SSSDConfig/sssdoptions.py:581 +#: src/config/SSSDConfig/sssdoptions.py:587 msgid "Path of group file sources." msgstr "Sökväg till gruppfilkällor." #: src/monitor/monitor.c:1757 msgid "Become a daemon (default)" -msgstr "Bli en demon (standard)" +msgstr "Kör som demon (standard)" #: src/monitor/monitor.c:1759 msgid "Run interactive (not a daemon)" @@ -2026,252 +2068,261 @@ msgstr "" #: src/monitor/monitor.c:1794 msgid "Option -i|--interactive is not allowed together with -D|--daemon\n" -msgstr "Flaggan -i|--interactive är inte tillåten tillsammans med -D|--daemon\n" +msgstr "" +"Flaggan -i|--interactive är inte tillåten tillsammans med -D|--daemon\n" -#: src/monitor/monitor.c:1836 +#: src/monitor/monitor.c:1838 msgid "Failed to get initial capabilities\n" msgstr "Misslyckades att hämta initiala förmågor\n" -#: src/monitor/monitor.c:1847 +#: src/monitor/monitor.c:1849 msgid "Non-root service user support isn't built. Can't run under %" msgstr "" "Stöd för icke-root-tjänsteanvändare är inte byggt. Kan inte köra under %" -#: src/monitor/monitor.c:1864 +#: src/monitor/monitor.c:1866 #, c-format msgid "Can't read config: '%s'\n" msgstr "Kan inte läsa konfigurationen: ”%s”\n" -#: src/monitor/monitor.c:1876 -#, c-format -msgid "Failed to boostrap SSSD 'monitor' process: %s" +#: src/monitor/monitor.c:1878 +#, fuzzy, c-format +msgid "Failed to bootstrap SSSD 'monitor' process: %s" msgstr "Misslyckades att starta upp SSSD:s process ”monitor”: %s" -#: src/monitor/monitor.c:1971 +#: src/monitor/monitor.c:1973 msgid "Out of memory\n" msgstr "Slut på minne\n" -#: src/providers/krb5/krb5_child.c:4221 +#: src/providers/krb5/krb5_child.c:4316 msgid "Use anonymous PKINIT to request FAST armor ticket" msgstr "Använd anonym PKINIT för att begära FAST-skyddad biljett" -#: src/providers/krb5/krb5_child.c:4223 +#: src/providers/krb5/krb5_child.c:4318 msgid "Kerberos realm to use" -msgstr "Kerberosrike att använda" +msgstr "Kerberos-domän att använda" -#: src/providers/krb5/krb5_child.c:4225 +#: src/providers/krb5/krb5_child.c:4320 msgid "Requested lifetime of the ticket" msgstr "Begärd livslängd på biljetten" -#: src/providers/krb5/krb5_child.c:4227 +#: src/providers/krb5/krb5_child.c:4322 msgid "Requested renewable lifetime of the ticket" msgstr "Begärd förnybar livslängd på biljetten" -#: src/providers/krb5/krb5_child.c:4229 +#: src/providers/krb5/krb5_child.c:4324 msgid "FAST options ('never', 'try', 'demand')" -msgstr "FAST-flaggor (”never”, ”try”, ”demand”)" +msgstr "FAST-alternativ (”never”, ”try”, ”demand”)" -#: src/providers/krb5/krb5_child.c:4232 +#: src/providers/krb5/krb5_child.c:4327 msgid "Specifies the server principal to use for FAST" -msgstr "Anger serverhuvudmannen att använda för FAST" +msgstr "Anger den serverprincipal som ska användas för FAST" -#: src/providers/krb5/krb5_child.c:4234 +#: src/providers/krb5/krb5_child.c:4329 msgid "Requests canonicalization of the principal name" -msgstr "Begär kanonisering av huvudmannanamnet" +msgstr "Begär kanonisering av principalnamnet" -#: src/providers/krb5/krb5_child.c:4236 +#: src/providers/krb5/krb5_child.c:4331 msgid "Use custom version of krb5_get_init_creds_password" msgstr "Använd en anpassad version av krb5_get_init_creds_password" -#: src/providers/krb5/krb5_child.c:4238 +#: src/providers/krb5/krb5_child.c:4333 msgid "Check PAC flags" msgstr "Kontrollera PAC-flaggor" -#: src/providers/data_provider_be.c:790 +#: src/providers/krb5/krb5_child.c:4335 +msgid "Set environment variable (KEY=VALUE)" +msgstr "" + +#: src/providers/data_provider_be.c:786 msgid "Domain of the information provider (mandatory)" msgstr "Domän för informationsleverantören (obligatoriskt)" -#: src/sss_client/common.c:1165 +#: src/sss_client/common.c:1208 msgid "Socket has wrong ownership or permissions." -msgstr "Uttaget (socket) har fel ägare eller rättigheter." +msgstr "Socketen har fel ägare eller behörigheter." -#: src/sss_client/common.c:1168 +#: src/sss_client/common.c:1211 msgid "Unexpected format of the server credential message." -msgstr "Oväntat format på serverns kreditivmeddelande." +msgstr "Oväntat format på serverns meddelande om autentiseringsuppgifter." -#: src/sss_client/common.c:1171 +#: src/sss_client/common.c:1214 msgid "SSSD is not run by trusted user." msgstr "SSSD körs inte av en betrodd användare." -#: src/sss_client/common.c:1174 +#: src/sss_client/common.c:1217 msgid "SSSD socket does not exist." -msgstr "SSSD-uttaget finns inte." +msgstr "SSSD-socketen finns inte." -#: src/sss_client/common.c:1177 +#: src/sss_client/common.c:1220 msgid "Cannot get stat of SSSD socket." -msgstr "Kan inte ta status på SSSD-uttaget." +msgstr "Kan inte hämta status för SSSD-socketen." -#: src/sss_client/common.c:1182 +#: src/sss_client/common.c:1225 msgid "An error occurred, but no description can be found." -msgstr "Ett fel uppstod, men ingen beskrivning kan hittas." +msgstr "Ett fel uppstod, men ingen beskrivning hittades." -#: src/sss_client/common.c:1188 +#: src/sss_client/common.c:1231 msgid "Unexpected error while looking for an error description" msgstr "Oväntat fel vid sökning efter ett felmeddelande" -#: src/sss_client/pam_sss.c:74 +#: src/sss_client/pam_sss.c:135 msgid "Permission denied. " msgstr "Åtkomst nekas. " -#: src/sss_client/pam_sss.c:75 src/sss_client/pam_sss.c:843 -#: src/sss_client/pam_sss.c:854 +#: src/sss_client/pam_sss.c:136 src/sss_client/pam_sss.c:921 +#: src/sss_client/pam_sss.c:932 msgid "Server message: " msgstr "Servermeddelande: " -#: src/sss_client/pam_sss.c:76 +#: src/sss_client/pam_sss.c:137 msgid "" "Kerberos TGT will not be granted upon login, user experience will be " "affected." msgstr "" -"Kerberos-TGT kommer inte att ges vid inloggning, användarupplevelsen kommer " -"påverkas." +"Kerberos-TGT kommer inte att tilldelas vid inloggning, vilket påverkar " +"användarupplevelsen." -#: src/sss_client/pam_sss.c:77 +#: src/sss_client/pam_sss.c:138 msgid "Enter PIN:" msgstr "Ange PIN:" -#: src/sss_client/pam_sss.c:320 +#: src/sss_client/pam_sss.c:385 msgid "Passwords do not match" msgstr "Lösenorden stämmer inte överens" -#: src/sss_client/pam_sss.c:508 +#: src/sss_client/pam_sss.c:584 msgid "Password reset by root is not supported." -msgstr "Återställning av lösenord av root stöds inte." +msgstr "Lösenordsåterställning av root stöds inte." -#: src/sss_client/pam_sss.c:549 +#: src/sss_client/pam_sss.c:625 msgid "Authenticated with cached credentials" -msgstr "Autentiserad med cachade kreditiv" +msgstr "Autentiserad med cachade autentiseringsuppgifter" -#: src/sss_client/pam_sss.c:550 +#: src/sss_client/pam_sss.c:626 msgid ", your cached password will expire at: " -msgstr ", ditt cache-lösenord kommer gå ut: " +msgstr ", ditt cachade lösenord går ut: " -#: src/sss_client/pam_sss.c:580 +#: src/sss_client/pam_sss.c:656 #, c-format msgid "Your password has expired. You have %1$d grace login(s) remaining." msgstr "Ditt lösenord har gått ut. Du har en frist på %1$d inloggningar kvar." -#: src/sss_client/pam_sss.c:630 +#: src/sss_client/pam_sss.c:706 #, c-format msgid "Your password will expire in %1$d %2$s." -msgstr "Ditt lösenordet kommer gå ut om %1$d %2$s." +msgstr "Ditt lösenord går ut om %1$d %2$s." -#: src/sss_client/pam_sss.c:633 +#: src/sss_client/pam_sss.c:709 #, c-format msgid "Your password has expired." -msgstr "Ditt lösenordet har gått ut." +msgstr "Ditt lösenord har gått ut." -#: src/sss_client/pam_sss.c:684 +#: src/sss_client/pam_sss.c:760 msgid "Authentication is denied until: " -msgstr "Autentisering nekas till: " +msgstr "Autentisering nekas till och med: " -#: src/sss_client/pam_sss.c:705 +#: src/sss_client/pam_sss.c:781 msgid "System is offline, password change not possible" msgstr "Systemet är frånkopplat, ändring av lösenord är inte möjligt" -#: src/sss_client/pam_sss.c:720 +#: src/sss_client/pam_sss.c:796 msgid "" "After changing the OTP password, you need to log out and back in order to " "acquire a ticket" msgstr "" -"Efter att ha ändrat OTP-lösenordet behöver du logga ut och tillbaka in för " -"att få en biljett" +"Efter att du har ändrat OTP-lösenordet måste du logga ut och sedan logga in " +"igen för att få en biljett" -#: src/sss_client/pam_sss.c:735 +#: src/sss_client/pam_sss.c:813 msgid "PIN locked" msgstr "PIN-låst" -#: src/sss_client/pam_sss.c:750 +#: src/sss_client/pam_sss.c:828 msgid "" "No Kerberos TGT granted as the server does not support this method. Your " "single-sign on(SSO) experience will be affected." msgstr "" -"Ingen Kerberos-TGT gavs eftersom servern inte stödjer denna metod. Din " -"eninloggningsupplevelse (SSO) kommer påverkas." +"Ingen Kerberos-TGT tilldelades eftersom servern inte stöder denna metod. Din " +"upplevelse av enkel inloggning (SSO) påverkas." -#: src/sss_client/pam_sss.c:840 src/sss_client/pam_sss.c:853 +#: src/sss_client/pam_sss.c:918 src/sss_client/pam_sss.c:931 msgid "Password change failed. " msgstr "Lösenordsändringen misslyckades. " -#: src/sss_client/pam_sss.c:1859 -#, c-format -msgid "Authenticate at %1$s and press ENTER." +#: src/sss_client/pam_sss.c:2028 +#, fuzzy, c-format +msgid "Authenticate at \"%1$s\"." msgstr "Autentisera vid %1$s och tryck på ENTER." -#: src/sss_client/pam_sss.c:1862 -#, c-format -msgid "Authenticate with PIN %1$s at %2$s and press ENTER." +#: src/sss_client/pam_sss.c:2031 +#, fuzzy, c-format +msgid "Authenticate with PIN \"%1$s\" at \"%2$s\"." msgstr "Autentisera med PIN %1$s vid %2$s och tryck på ENTER." -#: src/sss_client/pam_sss.c:2281 +#: src/sss_client/pam_sss.c:2470 msgid "Please (re)insert (different) Smartcard" msgstr "Sätt (igen) in ett (annat) smartkort" -#: src/sss_client/pam_sss.c:2482 +#: src/sss_client/pam_sss.c:2700 msgid "New Password: " msgstr "Nytt lösenord: " -#: src/sss_client/pam_sss.c:2483 +#: src/sss_client/pam_sss.c:2701 msgid "Reenter new Password: " msgstr "Skriv det nya lösenordet igen: " -#: src/sss_client/pam_sss.c:2676 src/sss_client/pam_sss.c:2679 +#: src/sss_client/pam_sss.c:2890 +msgid "Press ENTER to continue." +msgstr "" + +#: src/sss_client/pam_sss.c:2913 src/sss_client/pam_sss.c:2916 msgid "First Factor: " msgstr "Första faktorn: " -#: src/sss_client/pam_sss.c:2677 src/sss_client/pam_sss.c:2851 +#: src/sss_client/pam_sss.c:2914 src/sss_client/pam_sss.c:3088 msgid "Second Factor (optional): " msgstr "Andra faktorn (frivillig): " -#: src/sss_client/pam_sss.c:2680 src/sss_client/pam_sss.c:2855 +#: src/sss_client/pam_sss.c:2917 src/sss_client/pam_sss.c:3092 msgid "Second Factor: " msgstr "Andra faktorn: " -#: src/sss_client/pam_sss.c:2684 +#: src/sss_client/pam_sss.c:2921 msgid "Insert your passkey device, then press ENTER." -msgstr "Sätt in en lösennyckelsenhet, tryck sedan ENTER." +msgstr "Sätt in din lösennyckelenhet och tryck sedan på Retur." -#: src/sss_client/pam_sss.c:2688 src/sss_client/pam_sss.c:2696 +#: src/sss_client/pam_sss.c:2925 src/sss_client/pam_sss.c:2933 msgid "Password: " msgstr "Lösenord: " -#: src/sss_client/pam_sss.c:2850 src/sss_client/pam_sss.c:2854 +#: src/sss_client/pam_sss.c:3087 src/sss_client/pam_sss.c:3091 msgid "First Factor (Current Password): " msgstr "Första faktorn (nuvarande lösenord): " -#: src/sss_client/pam_sss.c:2874 +#: src/sss_client/pam_sss.c:3111 msgid "Current Password: " msgstr "Nuvarande lösenord: " -#: src/sss_client/pam_sss.c:3248 +#: src/sss_client/pam_sss.c:3485 msgid "Password expired. Change your password now." msgstr "Lösenordet har gått ut. Ändra ditt lösenord nu." #: src/sss_client/ssh/sss_ssh_authorizedkeys.c:41 src/tools/sss_cache.c:707 msgid "The debug level to run with" -msgstr "Felsökningsnivån att köra med" +msgstr "Felsökningsnivån som ska användas" #: src/sss_client/ssh/sss_ssh_authorizedkeys.c:43 msgid "The SSSD domain to use" -msgstr "SSSD-domäner att använda" +msgstr "SSSD-domänen som ska användas" #: src/sss_client/ssh/sss_ssh_authorizedkeys.c:57 src/tools/sss_cache.c:753 msgid "Error setting the locale\n" -msgstr "Fel när lokalen sattes\n" +msgstr "Fel vid inställning av språkregion\n" #: src/sss_client/ssh/sss_ssh_authorizedkeys.c:64 msgid "Not enough memory\n" -msgstr "Inte tillräckligt med minne\n" +msgstr "Otillräckligt med minne\n" #: src/sss_client/ssh/sss_ssh_authorizedkeys.c:83 msgid "User not specified\n" @@ -2302,7 +2353,7 @@ msgstr "" #: src/tools/sss_cache.c:229 msgid "No cache object matched the specified search\n" -msgstr "Inga cache-objekt matchade den angivna sökningen\n" +msgstr "Inget cacheobjekt matchade den angivna sökningen\n" #: src/tools/sss_cache.c:520 #, c-format @@ -2316,7 +2367,8 @@ msgstr "Kunde inte invalidera %1$s %2$s\n" #: src/tools/sss_cache.c:653 msgid "Can't find configuration db, was SSSD configured and run?\n" -msgstr "Kan inte hitta konfigurations-db:n, konfigurerades och kördes SSSD?\n" +msgstr "" +"Kan inte hitta konfigurationsdatabasen. Har SSSD konfigurerats och körts?\n" #: src/tools/sss_cache.c:709 msgid "Invalidate all cached entries" @@ -2387,8 +2439,8 @@ msgid "" "Unexpected argument(s) provided, options that invalidate a single object " "only accept a single provided argument.\n" msgstr "" -"Oväntat argument angivet, flaggor som invaliderar ett ensamt objekt tar bara " -"ett ensamt angivet argument.\n" +"Oväntade argument angavs. Alternativ som invaliderar ett enskilt objekt tar " +"bara ett argument.\n" #: src/tools/sss_cache.c:809 msgid "Please select at least one object to invalidate\n" @@ -2401,7 +2453,8 @@ msgid "" "use fully qualified name instead of --domain/-d parameter.\n" msgstr "" "Kunde inte öppna domänen %1$s. Om domänen är en underdomän (betrodd domän), " -"använd fullt kvalificerat namn istället för parametrarna --domain/-d.\n" +"använd ett fullständigt kvalificerat namn i stället för parametern --domain/-" +"d.\n" #: src/tools/sss_cache.c:897 msgid "Could not open available domains\n" @@ -2430,7 +2483,7 @@ msgstr "Felaktigt resultat." #: src/tools/sssctl/sssctl.c:78 msgid "Unable to read user input\n" -msgstr "Kan inte läsa användarens indata\n" +msgstr "Kunde inte läsa användarindata\n" #: src/tools/sssctl/sssctl.c:91 #, c-format @@ -2439,25 +2492,25 @@ msgstr "Felaktig indata, ange antingen ”%s” eller ”%s”.\n" #: src/tools/sssctl/sssctl.c:151 src/tools/sssctl/sssctl.c:161 msgid "Error while executing external command\n" -msgstr "Fel när externt kommando kördes\n" +msgstr "Fel vid körning av externt kommando\n" #: src/tools/sssctl/sssctl.c:165 #, c-format msgid "Error while executing external command '%s'\n" -msgstr "Fel när externt kommando kördes ”%s”\n" +msgstr "Fel vid körning av externt kommando ”%s”\n" #: src/tools/sssctl/sssctl.c:168 #, c-format msgid "Command '%s' failed with [%d]\n" -msgstr "Kommandot ”%s” misslyckades med [%d].\n" +msgstr "Kommandot ”%s” misslyckades med [%d]\n" #: src/tools/sssctl/sssctl.c:215 msgid "SSSD needs to be running. Start SSSD now?" -msgstr "SSSD behöver köras. Starta SSSD nu?" +msgstr "SSSD måste köras. Starta SSSD nu?" #: src/tools/sssctl/sssctl.c:254 msgid "SSSD must not be running. Stop SSSD now?" -msgstr "SSSD får inte köra. Stoppa SSSD nu?" +msgstr "SSSD får inte köras. Stoppa SSSD nu?" #: src/tools/sssctl/sssctl.c:290 msgid "SSSD needs to be restarted. Restart SSSD now?" @@ -2465,7 +2518,7 @@ msgstr "SSSD behöver startas om. Starta om SSSD nu?" #: src/tools/sssctl/sssctl.c:322 msgid "SSSD Status:" -msgstr "SSSD status:" +msgstr "SSSD-status:" #: src/tools/sssctl/sssctl.c:323 msgid "List available domains" @@ -2485,7 +2538,7 @@ msgstr "Generera en åtkomstrapport för en domän" #: src/tools/sssctl/sssctl.c:327 msgid "Information about cached content:" -msgstr "Information om cachat innehåll:" +msgstr "Information om cachelagrat innehåll:" #: src/tools/sssctl/sssctl.c:328 msgid "Information about cached user" @@ -2521,7 +2574,7 @@ msgstr "Invalidera cachade objekt" #: src/tools/sssctl/sssctl.c:336 msgid "Manage cache indexes" -msgstr "Hantera cachade index" +msgstr "Hantera cacheindex" #: src/tools/sssctl/sssctl.c:337 msgid "Log files tools:" @@ -2533,11 +2586,11 @@ msgstr "Ta bort befintliga SSSD-loggfiler" #: src/tools/sssctl/sssctl.c:339 msgid "Archive SSSD log files in tarball" -msgstr "Arkivera SSSD-loggfiler in i en tarboll" +msgstr "Arkivera SSSD-loggfiler i ett tar-arkiv" #: src/tools/sssctl/sssctl.c:340 msgid "Change or print information about SSSD debug level" -msgstr "Ändra eller skriv information om SSSD-felsökningsnivå" +msgstr "Ändra eller visa information om SSSD-felsökningsnivån" #: src/tools/sssctl/sssctl.c:341 msgid "Analyze logged data" @@ -2557,15 +2610,15 @@ msgstr "Certifikatrelaterade verktyg:" #: src/tools/sssctl/sssctl.c:345 msgid "Print information about the certificate" -msgstr "Skriv information om certifikatet" +msgstr "Visa information om certifikatet" #: src/tools/sssctl/sssctl.c:346 msgid "Show users mapped to the certificate" -msgstr "Visa användare avbildade till certifikatet" +msgstr "Visa användare som är mappade till certifikatet" #: src/tools/sssctl/sssctl.c:347 msgid "Check mapping and matching rule with a certificate" -msgstr "Kontrollera avbildnings- och matchningsregel för ett certifikat" +msgstr "Kontrollera mappnings- och matchningsregel med ett certifikat" #: src/tools/sssctl/sssctl.c:348 msgid "GPOs related tools:" @@ -2593,7 +2646,7 @@ msgstr "Lösennyckelrelaterade verktyg:" #: src/tools/sssctl/sssctl.c:355 msgid "Perform passkey registration" -msgstr "Utför lösennyckelsregistrering" +msgstr "Utför registrering av lösennyckel" #: src/tools/sssctl/sssctl_cache.c:31 #, c-format @@ -2606,15 +2659,15 @@ msgstr "Namn" #: src/tools/sssctl/sssctl_cache.c:34 msgid "Cache entry creation date" -msgstr "Datum då cache-posten skapades" +msgstr "Skapandedatum för cachepost" #: src/tools/sssctl/sssctl_cache.c:35 msgid "Cache entry last update time" -msgstr "Tidpunkt då cache-posten senast uppdaterades" +msgstr "Tidpunkt för senaste uppdatering av cachepost" #: src/tools/sssctl/sssctl_cache.c:36 msgid "Cache entry expiration time" -msgstr "Tidpunkt då cache-posten går ut" +msgstr "Utgångstid för cachepost" #: src/tools/sssctl/sssctl_cache.c:37 msgid "Cached in InfoPipe" @@ -2634,7 +2687,7 @@ msgstr "Policysökväg" #: src/tools/sssctl/sssctl_cache.c:41 msgid "Policy file timeout" -msgstr "Policyfiltidsgräns" +msgstr "Tidsgräns för policyfil" #: src/tools/sssctl/sssctl_cache.c:42 msgid "Policy version" @@ -2669,7 +2722,7 @@ msgstr "Sök via användar-ID" #: src/tools/sssctl/sssctl_cache.c:651 msgid "Initgroups expiration time" -msgstr "Init-gruppers utgångstid" +msgstr "Utgångstid för initgroups" #: src/tools/sssctl/sssctl_cache.c:689 msgid "Search by group ID" @@ -2677,7 +2730,7 @@ msgstr "Sök via grupp-ID" #: src/tools/sssctl/sssctl_cache.c:778 src/tools/sssctl/sssctl_cache.c:1126 msgid "Search by GPO guid" -msgstr "Sök via GPO-guid" +msgstr "Sök efter GPO-GUID" #: src/tools/sssctl/sssctl_cache.c:785 src/tools/sssctl/sssctl_cache.c:1143 #, c-format @@ -2692,20 +2745,20 @@ msgstr "%s\n" #: src/tools/sssctl/sssctl_cache.c:803 #, c-format msgid "Failed to print object: %s\n" -msgstr "Misslyckades med att skriva objekt: %s\n" +msgstr "Misslyckades med att visa objektet: %s\n" #: src/tools/sssctl/sssctl_cache.c:835 src/tools/sssctl/sssctl_cache.c:918 #: src/tools/sssctl/sssctl_cache.c:950 src/tools/sssctl/sssctl_cache.c:956 #: src/tools/sssctl/sssctl_cache.c:1010 src/tools/sssctl/sssctl_cache.c:1034 -#: src/tools/sssctl/sssctl_cache.c:1085 src/tools/sssctl/sssctl_cache.c:1194 -#: src/tools/sssctl/sssctl_cache.c:1229 src/tools/sssctl/sssctl_cache.c:1235 -#: src/tools/sssctl/sssctl_cache.c:1244 +#: src/tools/sssctl/sssctl_cache.c:1085 src/tools/sssctl/sssctl_cache.c:1195 +#: src/tools/sssctl/sssctl_cache.c:1230 src/tools/sssctl/sssctl_cache.c:1236 +#: src/tools/sssctl/sssctl_cache.c:1245 msgid "talloc failed\n" msgstr "talloc misslyckades\n" #: src/tools/sssctl/sssctl_cache.c:841 msgid "Unable to get attribute list!\n" -msgstr "Kan inte ta reda på attributlistan\n" +msgstr "Kan inte hämta attributlistan!\n" #: src/tools/sssctl/sssctl_cache.c:848 msgid "Unable to create filter\n" @@ -2718,7 +2771,7 @@ msgstr "%s [%s]:\n" #: src/tools/sssctl/sssctl_cache.c:866 msgid "Unable to get GPOs base DN\n" -msgstr "Kan inte ta reda på GPO:ns bas-DN\n" +msgstr "Kan inte hämta bas-DN för GPO:er\n" #: src/tools/sssctl/sssctl_cache.c:876 #, c-format @@ -2741,7 +2794,7 @@ msgstr "\n" #: src/tools/sssctl/sssctl_cache.c:1016 msgid "Could not find GUID attribute from GPO entry\n" -msgstr "Kunde inte hitta GUID-attribut i GPO-posten\n" +msgstr "Kunde inte hitta GUID-attributet i GPO-posten\n" #: src/tools/sssctl/sssctl_cache.c:1023 msgid "Could not find description attribute from GPO entry\n" @@ -2757,7 +2810,8 @@ msgid "" "The GPO path was not yet stored in cache. Please remove files manually from " "[%s]\n" msgstr "" -"GPO-sökvägen lagrades inte ännu i cachen. Ta bort filer manuellt från [%s]\n" +"GPO-sökvägen har ännu inte lagrats i cachen. Ta bort filer manuellt från " +"[%s]\n" #: src/tools/sssctl/sssctl_cache.c:1062 src/tools/sssctl/sssctl_cache.c:1068 #, c-format @@ -2767,32 +2821,32 @@ msgstr "Kunde inte avgöra verklig sökväg för [%s]: %s\n" #: src/tools/sssctl/sssctl_cache.c:1073 #, c-format msgid "The cached GPO path [%s] is not under [%s], ignoring.\n" -msgstr "Den cachade GPO-sökvägen [%s] är inte under [%s], ignorerar.\n" +msgstr "Den cachade GPO-sökvägen [%s] ligger inte under [%s]; ignorerar.\n" #: src/tools/sssctl/sssctl_cache.c:1098 #, c-format msgid "Unable to remove downloaded GPO files: %s\n" msgstr "Kan inte ta bort hämtade GPO-filer: %s\n" -#: src/tools/sssctl/sssctl_cache.c:1165 +#: src/tools/sssctl/sssctl_cache.c:1166 #, c-format msgid "Failed to fetch cache entry: %s\n" msgstr "Misslyckades med att hämta cacheposten: %s\n" -#: src/tools/sssctl/sssctl_cache.c:1170 +#: src/tools/sssctl/sssctl_cache.c:1171 msgid "Could not determine object domain\n" msgstr "Kunde inte avgöra objektdomänen\n" -#: src/tools/sssctl/sssctl_cache.c:1200 +#: src/tools/sssctl/sssctl_cache.c:1201 msgid "Could not find GUID attribute in GPO entry\n" -msgstr "Kunde inte hitta GUID-attribut i GPO-posten\n" +msgstr "Kunde inte hitta GUID-attributet i GPO-posten\n" -#: src/tools/sssctl/sssctl_cache.c:1206 +#: src/tools/sssctl/sssctl_cache.c:1207 #, c-format msgid "Failed to delete GPO: %s\n" msgstr "Misslyckades med att radera GPO: %s\n" -#: src/tools/sssctl/sssctl_cache.c:1210 +#: src/tools/sssctl/sssctl_cache.c:1211 #, c-format msgid "%s removed from cache\n" msgstr "%s borttagen från cachen\n" @@ -2800,12 +2854,12 @@ msgstr "%s borttagen från cachen\n" #: src/tools/sssctl/sssctl_cert.c:50 src/tools/sssctl/sssctl_cert.c:108 #: src/tools/sssctl/sssctl_cert.c:214 msgid "Show debug information" -msgstr "Visa felsökingsinformation" +msgstr "Visa felsökningsinformation" #: src/tools/sssctl/sssctl_cert.c:56 src/tools/sssctl/sssctl_cert.c:114 #: src/tools/sssctl/sssctl_cert.c:220 msgid "Specify base64 encoded certificate." -msgstr "Ange bas64-kodat certifikat." +msgstr "Ange base64-kodat certifikat." #: src/tools/sssctl/sssctl_cert.c:138 src/tools/sssctl/sssctl_domains.c:104 #: src/tools/sssctl/sssctl_domains.c:366 @@ -2815,7 +2869,7 @@ msgstr "Det går inte att ansluta till systembussen!\n" #: src/tools/sssctl/sssctl_cert.c:164 msgid " - no mapped users found -" -msgstr " – inga avbildade användare hittade –" +msgstr " – inga mappade användare hittades –" #: src/tools/sssctl/sssctl_cert.c:212 msgid "Mapping rule" @@ -2835,14 +2889,14 @@ msgstr "Slut på minne!\n" #: src/tools/sssctl/sssctl_cert.c:238 msgid "Failed to setup certmap context.\n" -msgstr "Misslyckades att sätta upp certmap-kontext.\n" +msgstr "Misslyckades med att konfigurera certmap-kontexten.\n" #: src/tools/sssctl/sssctl_cert.c:244 #, c-format msgid "Failed to add mapping and matching rules with error [%d][%s].\n" msgstr "" -"Misslyckades att lägga till avbildnings- och matchningsregler med felet " -"[%d][%s].\n" +"Misslyckades att lägga till avbildnings- och matchningsregler med felet [%d]" +"[%s].\n" #: src/tools/sssctl/sssctl_cert.c:251 msgid "Failed to decode base64 string.\n" @@ -2850,7 +2904,7 @@ msgstr "Misslyckades att avkoda en base64-sträng.\n" #: src/tools/sssctl/sssctl_cert.c:259 msgid "Certificate matches rule.\n" -msgstr "Certifikatet matchar regeln\n" +msgstr "Certifikatet matchar regeln.\n" #: src/tools/sssctl/sssctl_cert.c:262 msgid "Certificate does not match rule.\n" @@ -2885,52 +2939,53 @@ msgid "" "where the main config file is located. For example if the config is set to " "\"/my/path/sssd.conf\", the snippet dir \"/my/path/conf.d\" is used)" msgstr "" -"Ange en icke-standardkatalog för snuttar (Standard är att leta på samma " -"plats som huvudkonfigurationsfilen finns. Till exempel om konfigurationen är " -"satt till ”/min/sökväg/sssd.conf” används snuttkatalogen ”/min/sökväg/" -"conf.d”)" +"Ange en katalog för snuttar som inte är standardkatalogen (som standard söks " +"på samma plats som huvudkonfigurationsfilen. Om konfigurationen till exempel " +"är inställd på \"/my/path/sssd.conf\", används snuttkatalogen \"/my/path/" +"conf.d\")" -#: src/tools/sssctl/sssctl_config.c:114 +#: src/tools/sssctl/sssctl_config.c:126 #, c-format msgid "File %1$s does not exist.\n" msgstr "Filen %1$s finns inte.\n" -#: src/tools/sssctl/sssctl_config.c:115 +#: src/tools/sssctl/sssctl_config.c:127 msgid "There is no configuration.\n" msgstr "Det finns ingen konfiguration.\n" -#: src/tools/sssctl/sssctl_config.c:120 +#: src/tools/sssctl/sssctl_config.c:132 #, c-format msgid "Configuration validation failed: %s\n" msgstr "Konfigurationsvalidering misslyckades: %s\n" -#: src/tools/sssctl/sssctl_config.c:121 +#: src/tools/sssctl/sssctl_config.c:133 msgid "Run with high debug level to see details.\n" msgstr "Kör med hög felsökningsnivå för att se detaljer.\n" -#: src/tools/sssctl/sssctl_config.c:130 -msgid "Failed to run validators" +#: src/tools/sssctl/sssctl_config.c:142 +#, fuzzy +msgid "Failed to run validators\n" msgstr "Misslyckades att köra validerare" -#: src/tools/sssctl/sssctl_config.c:134 +#: src/tools/sssctl/sssctl_config.c:146 #, c-format msgid "Issues identified by validators: %zu\n" -msgstr "Problem identifierade av validerare: %zu\n" +msgstr "Problem som identifierades av validerarna: %zu\n" -#: src/tools/sssctl/sssctl_config.c:145 +#: src/tools/sssctl/sssctl_config.c:157 #, c-format msgid "Messages generated during configuration merging: %zu\n" msgstr "Meddelanden genererade under sammanslagning av konfigurationen: %zu\n" -#: src/tools/sssctl/sssctl_config.c:158 +#: src/tools/sssctl/sssctl_config.c:170 #, c-format msgid "Used configuration snippet files: %zu\n" -msgstr "Använd konfigurationssnuttfiler: %zu\n" +msgstr "Använda konfigurationssnuttfiler: %zu\n" #: src/tools/sssctl/sssctl_data.c:91 #, c-format msgid "Unable to create backup directory [%d]: %s" -msgstr "Kan inte skapa en katalog för säkerhetskopia [%d]: %s" +msgstr "Kan inte skapa säkerhetskopieringskatalogen [%d]: %s" #: src/tools/sssctl/sssctl_data.c:97 msgid "SSSD backup of local data already exists, override?" @@ -2946,7 +3001,7 @@ msgstr "Kan inte exportera gruppåsidosättanden\n" #: src/tools/sssctl/sssctl_data.c:135 src/tools/sssctl/sssctl_data.c:216 msgid "Override existing backup" -msgstr "Åsidosätt befintlig säkerhetskopia" +msgstr "Skriv över befintlig säkerhetskopia" #: src/tools/sssctl/sssctl_data.c:165 msgid "Unable to import user overrides\n" @@ -2959,7 +3014,7 @@ msgstr "Kan inte importera gruppåsidosättanden\n" #: src/tools/sssctl/sssctl_data.c:194 src/tools/sssctl/sssctl_domains.c:81 #: src/tools/sssctl/sssctl_domains.c:326 msgid "Start SSSD if it is not running" -msgstr "Starta SSSD om den inte kör" +msgstr "Starta SSSD om det inte körs" #: src/tools/sssctl/sssctl_data.c:195 msgid "Restart SSSD after data import" @@ -2971,15 +3026,15 @@ msgstr "Skapa rena cachefiler och importera lokala data" #: src/tools/sssctl/sssctl_data.c:218 msgid "Stop SSSD before removing the cache" -msgstr "Stoppa SSSD före cachen tas bort" +msgstr "Stoppa SSSD innan cachen tas bort" #: src/tools/sssctl/sssctl_data.c:219 msgid "Start SSSD when the cache is removed" -msgstr "Starta SSSD när cachen är borttagen" +msgstr "Starta SSSD när cachen har tagits bort" #: src/tools/sssctl/sssctl_data.c:234 msgid "Creating backup of local data...\n" -msgstr "Skapa säkerhetskopia av lokala data …\n" +msgstr "Skapar säkerhetskopia av lokala data …\n" #: src/tools/sssctl/sssctl_data.c:237 msgid "Unable to create backup of local data, can not remove the cache.\n" @@ -2988,11 +3043,11 @@ msgstr "" #: src/tools/sssctl/sssctl_data.c:242 msgid "Removing cache files...\n" -msgstr "Tar bort cache-filer …\n" +msgstr "Tar bort cachefiler …\n" #: src/tools/sssctl/sssctl_data.c:245 msgid "Unable to remove cache files\n" -msgstr "Kan inte ta bort cache-filer\n" +msgstr "Kan inte ta bort cachefiler\n" #: src/tools/sssctl/sssctl_data.c:250 msgid "Restoring local data...\n" @@ -3001,12 +3056,12 @@ msgstr "Återställer lokala data …\n" #: src/tools/sssctl/sssctl_data.c:377 #, c-format msgid "Creating cache index for domain %1$s\n" -msgstr "Skapar cache-index för domänen %1$s\n" +msgstr "Skapar cacheindex för domänen %1$s\n" #: src/tools/sssctl/sssctl_data.c:379 #, c-format msgid "Deleting cache index for domain %1$s\n" -msgstr "Raderar cache-index för domänen %1$s\n" +msgstr "Tar bort cacheindex för domänen %1$s\n" #: src/tools/sssctl/sssctl_data.c:381 #, c-format @@ -3020,7 +3075,7 @@ msgstr " Attribut: %1$s\n" #: src/tools/sssctl/sssctl_data.c:428 src/tools/sssctl/sssctl_logs.c:525 msgid "Target a specific domain" -msgstr "Sikta på en specifik domän" +msgstr "Använd en specifik domän" #: src/tools/sssctl/sssctl_data.c:428 src/tools/sssctl/sssctl_logs.c:525 msgid "domain" @@ -3028,7 +3083,7 @@ msgstr "domän" #: src/tools/sssctl/sssctl_data.c:430 msgid "Attribute to index" -msgstr "Attribut till index" +msgstr "Attribut som ska indexeras" #: src/tools/sssctl/sssctl_data.c:430 msgid "attribute" @@ -3054,7 +3109,7 @@ msgstr "Attribut (-a) angavs inte\n" #: src/tools/sssctl/sssctl_data.c:472 #, c-format msgid "Attribute %1$s not indexed.\n" -msgstr "Attribut %1$s inte indexerat.\n" +msgstr "Attributet %1$s är inte indexerat.\n" #: src/tools/sssctl/sssctl_data.c:475 #, c-format @@ -3072,7 +3127,7 @@ msgstr "Glöm inte att även uppdatera indexen på fjärrleverantörerna.\n" #: src/tools/sssctl/sssctl_domains.c:82 msgid "Show domain list including primary or trusted domain type" -msgstr "Visa domänlistan inklusive primär eller betrodd domäntyp" +msgstr "Visa domänlistan med typ av primär eller betrodd domän" #: src/tools/sssctl/sssctl_domains.c:166 msgid "Online" @@ -3085,7 +3140,7 @@ msgstr "Frånkopplad" #: src/tools/sssctl/sssctl_domains.c:166 #, c-format msgid "Online status: %s\n" -msgstr "Uppkopplingsstatus: %s\n" +msgstr "Anslutningsstatus: %s\n" #: src/tools/sssctl/sssctl_domains.c:212 msgid "This domain has no active servers.\n" @@ -3106,15 +3161,15 @@ msgstr "Inga servrar upptäcktes.\n" #: src/tools/sssctl/sssctl_domains.c:272 #, c-format msgid "Discovered %s servers:\n" -msgstr "Upptäckte %s servrar:\n" +msgstr "%s servrar upptäcktes:\n" #: src/tools/sssctl/sssctl_domains.c:284 msgid "None so far.\n" -msgstr "Ingen än så länge.\n" +msgstr "Inga ännu.\n" #: src/tools/sssctl/sssctl_domains.c:323 msgid "Show online status" -msgstr "Visa uppkopplingsstatus" +msgstr "Visa anslutningsstatus" #: src/tools/sssctl/sssctl_domains.c:324 msgid "Show information about active server" @@ -3130,15 +3185,15 @@ msgstr "Ange domännamn." #: src/tools/sssctl/sssctl_domains.c:374 src/tools/sssctl/sssctl_domains.c:384 msgid "Unable to get online status\n" -msgstr "Kan inte ta reda på uppkopplingsstatus\n" +msgstr "Kan inte hämta anslutningsstatus\n" #: src/tools/sssctl/sssctl_domains.c:394 msgid "Unable to get server list\n" -msgstr "Kan inte ta reda på serverlistan\n" +msgstr "Kan inte hämta serverlistan\n" #: src/tools/sssctl/sssctl_logs.c:214 msgid "SSSD is not running.\n" -msgstr "SSSD kör inte.\n" +msgstr "SSSD körs inte.\n" #: src/tools/sssctl/sssctl_logs.c:231 #, c-format @@ -3157,7 +3212,7 @@ msgstr "%1$-25s Onåbar tjänst\n" #: src/tools/sssctl/sssctl_logs.c:429 msgid "Delete log files instead of truncating" -msgstr "Radera loggfiler istället för att hugga av" +msgstr "Ta bort loggfiler i stället för att trunkera dem" #: src/tools/sssctl/sssctl_logs.c:440 msgid "Deleting log files...\n" @@ -3169,16 +3224,16 @@ msgstr "Kan inte ta bort loggfiler\n" #: src/tools/sssctl/sssctl_logs.c:460 msgid "Truncating log files...\n" -msgstr "Hugger av loggfiler …\n" +msgstr "Trunkerar loggfiler …\n" #: src/tools/sssctl/sssctl_logs.c:464 msgid "Unable to truncate log files\n" -msgstr "Kan inte hugga av loggfiler\n" +msgstr "Kan inte trunkera loggfiler\n" #: src/tools/sssctl/sssctl_logs.c:498 #, c-format msgid "Archiving log files into %s...\n" -msgstr "Arkiverar loggfiler in i %s …\n" +msgstr "Arkiverar loggfiler i %s …\n" #: src/tools/sssctl/sssctl_logs.c:502 msgid "Unable to archive log files\n" @@ -3186,47 +3241,47 @@ msgstr "Kan inte arkivera loggfiler\n" #: src/tools/sssctl/sssctl_logs.c:526 msgid "Target the SSSD service" -msgstr "Sikta på SSSD-tjänsten" +msgstr "Välj SSSD-tjänsten" #: src/tools/sssctl/sssctl_logs.c:527 msgid "Target the NSS service" -msgstr "Sikta på NSS-tjänsten" +msgstr "Välj NSS-tjänsten" #: src/tools/sssctl/sssctl_logs.c:528 msgid "Target the PAM service" -msgstr "Sikta på PAM-tjänsten" +msgstr "Välj PAM-tjänsten" #: src/tools/sssctl/sssctl_logs.c:529 msgid "Target the SUDO service" -msgstr "Sikta på SUDO-tjänsten" +msgstr "Välj SUDO-tjänsten" #: src/tools/sssctl/sssctl_logs.c:530 msgid "Target the AUTOFS service" -msgstr "Sikta på AUTOFS-tjänsten" +msgstr "Välj AUTOFS-tjänsten" #: src/tools/sssctl/sssctl_logs.c:531 msgid "Target the SSH service" -msgstr "Sikta på SSH-tjänsten" +msgstr "Välj SSH-tjänsten" #: src/tools/sssctl/sssctl_logs.c:532 msgid "Target the PAC service" -msgstr "Sikta på PAC-tjänsten" +msgstr "Välj PAC-tjänsten" #: src/tools/sssctl/sssctl_logs.c:533 msgid "Target the IFP service" -msgstr "Sikta på IFP-tjänsten" +msgstr "Välj IFP-tjänsten" #: src/tools/sssctl/sssctl_logs.c:548 msgid "Specify debug level you want to set" -msgstr "Ange felsökningsnivå du vill sätta" +msgstr "Ange felsökningsnivån som ska ställas in" #: src/tools/sssctl/sssctl_logs.c:593 msgid "ERROR: Tevent chain ID support missing, log analyzer is unsupported.\n" -msgstr "FEL: stöd för tevent-kedje-ID saknas, logganalysatorn stödjs inte.\n" +msgstr "FEL: Stöd för Tevent-kedje-ID saknas, logganalysatorn stöds inte.\n" #: src/tools/sssctl/sssctl_user_checks.c:121 msgid "SSSD InfoPipe user lookup result:\n" -msgstr "Resultat av SSSD InfoPipe-användaruppslagning:\n" +msgstr "Resultat från SSSD InfoPipe-användaruppslagning:\n" #: src/tools/sssctl/sssctl_user_checks.c:171 #, c-format @@ -3249,7 +3304,7 @@ msgstr "sss_getpwnam_r misslyckades med [%d].\n" #: src/tools/sssctl/sssctl_user_checks.c:198 msgid "SSSD nss user lookup result:\n" -msgstr "Resultat av SSSD nss-användaruppslagning:\n" +msgstr "Resultat från SSSD NSS-användaruppslagning:\n" #: src/tools/sssctl/sssctl_user_checks.c:199 #, c-format @@ -3259,12 +3314,12 @@ msgstr " - användarnamn: %s\n" #: src/tools/sssctl/sssctl_user_checks.c:200 #, c-format msgid " - user id: %d\n" -msgstr " - användar-id: %d\n" +msgstr " - användar-ID: %d\n" #: src/tools/sssctl/sssctl_user_checks.c:201 #, c-format msgid " - group id: %d\n" -msgstr " - grupp-id: %d\n" +msgstr " - grupp-ID: %d\n" #: src/tools/sssctl/sssctl_user_checks.c:202 #, c-format @@ -3330,7 +3385,7 @@ msgid "" "testing pam_authenticate\n" "\n" msgstr "" -"testar pam_authenticate\n" +"Testar pam_authenticate\n" "\n" #: src/tools/sssctl/sssctl_user_checks.c:276 @@ -3352,7 +3407,7 @@ msgid "" "testing pam_chauthtok\n" "\n" msgstr "" -"testar pam_chauthtok\n" +"Testar pam_chauthtok\n" "\n" #: src/tools/sssctl/sssctl_user_checks.c:284 @@ -3369,7 +3424,7 @@ msgid "" "testing pam_acct_mgmt\n" "\n" msgstr "" -"testar pam_acct_mgmt\n" +"Testar pam_acct_mgmt\n" "\n" #: src/tools/sssctl/sssctl_user_checks.c:288 @@ -3386,7 +3441,7 @@ msgid "" "testing pam_setcred\n" "\n" msgstr "" -"testar pam_setcred\n" +"Testar pam_setcred\n" "\n" #: src/tools/sssctl/sssctl_user_checks.c:292 @@ -3403,7 +3458,7 @@ msgid "" "testing pam_open_session\n" "\n" msgstr "" -"testar pam_open_session\n" +"Testar pam_open_session\n" "\n" #: src/tools/sssctl/sssctl_user_checks.c:296 @@ -3420,7 +3475,7 @@ msgid "" "testing pam_close_session\n" "\n" msgstr "" -"testar pam_close_session\n" +"Testar pam_close_session\n" "\n" #: src/tools/sssctl/sssctl_user_checks.c:300 @@ -3434,7 +3489,7 @@ msgstr "" #: src/tools/sssctl/sssctl_user_checks.c:302 msgid "unknown action\n" -msgstr "okänd åtgärd\n" +msgstr "Okänd åtgärd\n" #: src/tools/sssctl/sssctl_user_checks.c:305 msgid "PAM Environment:\n" @@ -3446,11 +3501,11 @@ msgstr " - ingen miljö -\n" #: src/util/util.h:100 msgid "Specify a non-default config file" -msgstr "Ange en konfigurationsfil annan än standard" +msgstr "Ange en annan konfigurationsfil än standardfilen" #: src/util/util.h:107 msgid "Informs that the responder has been socket-activated" -msgstr "Informerar att respondenten har blivit uttagsaktiverad" +msgstr "Anger att svararen har socketaktiverats" #~ msgid "Control enumeration of trusted domains" #~ msgstr "Styr uppräkning av betrodda domäner" diff --git a/po/tg.po b/po/tg.po index 440ea0e08fc..71ba33df809 100644 --- a/po/tg.po +++ b/po/tg.po @@ -7,8 +7,8 @@ msgid "" msgstr "" "Project-Id-Version: PACKAGE VERSION\n" "Report-Msgid-Bugs-To: sssd-devel@lists.fedorahosted.org\n" -"POT-Creation-Date: 2026-01-14 14:57+0000\n" -"PO-Revision-Date: 2026-04-23 16:50+0000\n" +"POT-Creation-Date: 2026-10-02 15:57+0000\n" +"PO-Revision-Date: 2026-10-05 16:47+0000\n" "Last-Translator: Anonymous \n" "Language-Team: Tajik \n" @@ -17,50 +17,50 @@ msgstr "" "Content-Type: text/plain; charset=UTF-8\n" "Content-Transfer-Encoding: 8bit\n" "Plural-Forms: nplurals=2; plural=(n != 1);\n" -"X-Generator: Weblate 5.17\n" +"X-Generator: Weblate 2026.10\n" -#: src/config/SSSDConfig/sssdoptions.py:20 -#: src/config/SSSDConfig/sssdoptions.py:21 +#: src/config/SSSDConfig/sssdoptions.py:16 +#: src/config/SSSDConfig/sssdoptions.py:17 msgid "Set the verbosity of the debug logging" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:22 +#: src/config/SSSDConfig/sssdoptions.py:18 msgid "Include timestamps in debug logs" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:23 +#: src/config/SSSDConfig/sssdoptions.py:19 msgid "Include microseconds in timestamps in debug logs" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:24 +#: src/config/SSSDConfig/sssdoptions.py:20 msgid "Enable/disable debug backtrace" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:25 +#: src/config/SSSDConfig/sssdoptions.py:21 msgid "Watchdog timeout before restarting service" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:26 +#: src/config/SSSDConfig/sssdoptions.py:22 msgid "Command to start service" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:27 +#: src/config/SSSDConfig/sssdoptions.py:23 msgid "The number of file descriptors that may be opened by this responder" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:28 +#: src/config/SSSDConfig/sssdoptions.py:24 msgid "Idle time before automatic disconnection of a client" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:29 +#: src/config/SSSDConfig/sssdoptions.py:25 msgid "Idle time before automatic shutdown of the responder" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:30 +#: src/config/SSSDConfig/sssdoptions.py:26 msgid "Always query all the caches before querying the Data Providers" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:31 +#: src/config/SSSDConfig/sssdoptions.py:27 msgid "" "When SSSD switches to offline mode the amount of time before it tries to go " "back online will increase based upon the time spent disconnected. This value " @@ -68,63 +68,63 @@ msgid "" "random_offset." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:36 +#: src/config/SSSDConfig/sssdoptions.py:32 msgid "SSSD Services to start" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:37 +#: src/config/SSSDConfig/sssdoptions.py:33 msgid "SSSD Domains to start" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:38 +#: src/config/SSSDConfig/sssdoptions.py:34 msgid "Regex to parse username and domain" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:39 +#: src/config/SSSDConfig/sssdoptions.py:35 msgid "Printf-compatible format for displaying fully-qualified names" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:40 +#: src/config/SSSDConfig/sssdoptions.py:36 msgid "" "Directory on the filesystem where SSSD should store Kerberos replay cache " "files." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:41 +#: src/config/SSSDConfig/sssdoptions.py:37 msgid "Domain to add to names without a domain component." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:42 +#: src/config/SSSDConfig/sssdoptions.py:38 msgid "The user to drop privileges to" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:43 +#: src/config/SSSDConfig/sssdoptions.py:39 msgid "Tune certificate verification" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:44 +#: src/config/SSSDConfig/sssdoptions.py:40 msgid "All spaces in group or user names will be replaced with this character" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:45 +#: src/config/SSSDConfig/sssdoptions.py:41 msgid "Tune sssd to honor or ignore netlink state changes" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:46 +#: src/config/SSSDConfig/sssdoptions.py:42 msgid "Enable or disable the implicit files domain" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:47 +#: src/config/SSSDConfig/sssdoptions.py:43 msgid "A specific order of the domains to be looked up" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:48 +#: src/config/SSSDConfig/sssdoptions.py:44 msgid "" "Controls if SSSD should monitor the state of resolv.conf to identify when it " "needs to update its internal DNS resolver." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:50 +#: src/config/SSSDConfig/sssdoptions.py:46 msgid "" "SSSD monitors the state of resolv.conf to identify when it needs to update " "its internal DNS resolver. By default, we will attempt to use inotify for " @@ -132,393 +132,400 @@ msgid "" "inotify cannot be used." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:53 +#: src/config/SSSDConfig/sssdoptions.py:49 msgid "Run PAC responder automatically for AD and IPA provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:54 +#: src/config/SSSDConfig/sssdoptions.py:50 msgid "Enable or disable core dumps for all SSSD processes." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:55 +#: src/config/SSSDConfig/sssdoptions.py:51 msgid "Tune passkey verification behavior" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:58 +#: src/config/SSSDConfig/sssdoptions.py:54 msgid "Enumeration cache timeout length (seconds)" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:59 +#: src/config/SSSDConfig/sssdoptions.py:55 msgid "Entry cache background update timeout length (seconds)" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:60 -#: src/config/SSSDConfig/sssdoptions.py:125 +#: src/config/SSSDConfig/sssdoptions.py:56 +#: src/config/SSSDConfig/sssdoptions.py:124 msgid "Negative cache timeout length (seconds)" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:61 +#: src/config/SSSDConfig/sssdoptions.py:57 msgid "Users that SSSD should explicitly ignore" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:62 +#: src/config/SSSDConfig/sssdoptions.py:58 msgid "Groups that SSSD should explicitly ignore" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:63 +#: src/config/SSSDConfig/sssdoptions.py:59 msgid "Should filtered users appear in groups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:64 +#: src/config/SSSDConfig/sssdoptions.py:60 msgid "The value of the password field the NSS provider should return" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:65 +#: src/config/SSSDConfig/sssdoptions.py:61 msgid "Override homedir value from the identity provider with this value" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:66 +#: src/config/SSSDConfig/sssdoptions.py:62 msgid "" "Substitute empty homedir value from the identity provider with this value" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:67 +#: src/config/SSSDConfig/sssdoptions.py:63 msgid "Override shell value from the identity provider with this value" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:68 +#: src/config/SSSDConfig/sssdoptions.py:64 msgid "The list of shells users are allowed to log in with" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:69 +#: src/config/SSSDConfig/sssdoptions.py:65 msgid "" "The list of shells that will be vetoed, and replaced with the fallback shell" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:70 +#: src/config/SSSDConfig/sssdoptions.py:66 msgid "" "If a shell stored in central directory is allowed but not available, use " "this fallback" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:71 +#: src/config/SSSDConfig/sssdoptions.py:67 msgid "Shell to use if the provider does not list one" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:72 +#: src/config/SSSDConfig/sssdoptions.py:68 msgid "How long will be in-memory cache records valid" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:74 +#: src/config/SSSDConfig/sssdoptions.py:70 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for passwd requests" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:76 +#: src/config/SSSDConfig/sssdoptions.py:72 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for group requests" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:78 +#: src/config/SSSDConfig/sssdoptions.py:74 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for initgroups requests" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:79 +#: src/config/SSSDConfig/sssdoptions.py:75 msgid "" "The value of this option will be used in the expansion of the " "override_homedir option if the template contains the format string %H." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:81 +#: src/config/SSSDConfig/sssdoptions.py:77 msgid "" "Specifies time in seconds for which the list of subdomains will be " "considered valid." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:83 +#: src/config/SSSDConfig/sssdoptions.py:79 msgid "" "The entry cache can be set to automatically update entries in the background " "if they are requested beyond a percentage of the entry_cache_timeout value " "for the domain." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:88 +#: src/config/SSSDConfig/sssdoptions.py:84 msgid "How long to allow cached logins between online logins (days)" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:89 +#: src/config/SSSDConfig/sssdoptions.py:85 msgid "How many failed logins attempts are allowed when offline" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:91 +#: src/config/SSSDConfig/sssdoptions.py:87 msgid "" "How long (minutes) to deny login after offline_failed_login_attempts has " "been reached" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:92 +#: src/config/SSSDConfig/sssdoptions.py:88 msgid "What kind of messages are displayed to the user during authentication" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:93 +#: src/config/SSSDConfig/sssdoptions.py:89 msgid "Filter PAM responses sent to the pam_sss" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:94 +#: src/config/SSSDConfig/sssdoptions.py:90 msgid "How many seconds to keep identity information cached for PAM requests" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:95 +#: src/config/SSSDConfig/sssdoptions.py:91 msgid "How many days before password expiration a warning should be displayed" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:96 +#: src/config/SSSDConfig/sssdoptions.py:92 msgid "List of trusted uids or user's name" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:97 +#: src/config/SSSDConfig/sssdoptions.py:93 msgid "List of domains accessible even for untrusted users." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:98 +#: src/config/SSSDConfig/sssdoptions.py:94 msgid "Message printed when user account is expired." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:99 +#: src/config/SSSDConfig/sssdoptions.py:95 msgid "Message printed when user account is locked." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:100 +#: src/config/SSSDConfig/sssdoptions.py:96 msgid "Allow certificate based/Smartcard authentication." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:101 +#: src/config/SSSDConfig/sssdoptions.py:97 msgid "Path to certificate database with PKCS#11 modules." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:102 +#: src/config/SSSDConfig/sssdoptions.py:98 msgid "Tune certificate verification for PAM authentication." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:103 +#: src/config/SSSDConfig/sssdoptions.py:99 msgid "How many seconds will pam_sss wait for p11_child to finish" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:104 +#: src/config/SSSDConfig/sssdoptions.py:100 msgid "Which PAM services are permitted to contact application domains" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:105 +#: src/config/SSSDConfig/sssdoptions.py:101 msgid "Allowed services for using smartcards" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:106 +#: src/config/SSSDConfig/sssdoptions.py:102 msgid "Additional timeout to wait for a card if requested" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:107 +#: src/config/SSSDConfig/sssdoptions.py:103 msgid "" "PKCS#11 URI to restrict the selection of devices for Smartcard authentication" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:108 +#: src/config/SSSDConfig/sssdoptions.py:104 msgid "When shall the PAM responder force an initgroups request" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:109 +#: src/config/SSSDConfig/sssdoptions.py:105 msgid "List of PAM services that are allowed to authenticate with GSSAPI." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:110 +#: src/config/SSSDConfig/sssdoptions.py:106 msgid "Whether to match authenticated UPN with target user" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:111 +#: src/config/SSSDConfig/sssdoptions.py:107 msgid "" "List of pairs : that must be enforced " "for PAM access with GSSAPI authentication" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:113 +#: src/config/SSSDConfig/sssdoptions.py:109 +msgid "" +"List of triples :: that assigns " +"additional information from the Kerberos ticket to an authentication " +"indicator." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:112 msgid "Allow passkey device authentication." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:114 +#: src/config/SSSDConfig/sssdoptions.py:113 msgid "How many seconds will pam_sss wait for passkey_child to finish" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:115 +#: src/config/SSSDConfig/sssdoptions.py:114 msgid "Enable debugging in the libfido2 library" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:116 +#: src/config/SSSDConfig/sssdoptions.py:115 msgid "Enable JSON protocol for authentication methods selection." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:119 +#: src/config/SSSDConfig/sssdoptions.py:118 msgid "Whether to evaluate the time-based attributes in sudo rules" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:120 +#: src/config/SSSDConfig/sssdoptions.py:119 msgid "If true, SSSD will switch back to lower-wins ordering logic" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:121 +#: src/config/SSSDConfig/sssdoptions.py:120 msgid "" "Maximum number of rules that can be refreshed at once. If this is exceeded, " "full refresh is performed." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:128 +#: src/config/SSSDConfig/sssdoptions.py:127 msgid "Whether to hash host names and addresses in the known_hosts file" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:129 +#: src/config/SSSDConfig/sssdoptions.py:128 msgid "" "How many seconds to keep a host in the known_hosts file after its host keys " "were requested" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:131 +#: src/config/SSSDConfig/sssdoptions.py:130 msgid "Path to storage of trusted CA certificates" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:132 +#: src/config/SSSDConfig/sssdoptions.py:131 msgid "Allow to generate ssh-keys from certificates" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:133 +#: src/config/SSSDConfig/sssdoptions.py:132 msgid "" "Use the following matching rules to filter the certificates for ssh-key " "generation" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:137 +#: src/config/SSSDConfig/sssdoptions.py:136 msgid "List of UIDs or user names allowed to access the PAC responder" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:138 +#: src/config/SSSDConfig/sssdoptions.py:137 msgid "How long the PAC data is considered valid" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:139 +#: src/config/SSSDConfig/sssdoptions.py:138 msgid "Validate the PAC" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:142 +#: src/config/SSSDConfig/sssdoptions.py:141 msgid "List of user attributes the InfoPipe is allowed to publish" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:145 +#: src/config/SSSDConfig/sssdoptions.py:144 msgid "" "One of the following strings specifying the scope of session recording: none " "- No users are recorded. some - Users/groups specified by users and groups " "options are recorded. all - All users are recorded." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:148 +#: src/config/SSSDConfig/sssdoptions.py:147 msgid "" "A comma-separated list of users which should have session recording enabled. " "Matches user names as returned by NSS. I.e. after the possible space " "replacement, case changes, etc." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:150 +#: src/config/SSSDConfig/sssdoptions.py:149 msgid "" "A comma-separated list of groups, members of which should have session " "recording enabled. Matches group names as returned by NSS. I.e. after the " "possible space replacement, case changes, etc." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:153 +#: src/config/SSSDConfig/sssdoptions.py:152 msgid "" "A comma-separated list of users to be excluded from recording, only when " "scope=all" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:154 +#: src/config/SSSDConfig/sssdoptions.py:153 msgid "" "A comma-separated list of groups, members of which should be excluded from " "recording, only when scope=all. " msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:158 +#: src/config/SSSDConfig/sssdoptions.py:157 msgid "Identity provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:159 +#: src/config/SSSDConfig/sssdoptions.py:158 msgid "Authentication provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:160 +#: src/config/SSSDConfig/sssdoptions.py:159 msgid "Access control provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:161 +#: src/config/SSSDConfig/sssdoptions.py:160 msgid "Password change provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:162 +#: src/config/SSSDConfig/sssdoptions.py:161 msgid "SUDO provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:163 +#: src/config/SSSDConfig/sssdoptions.py:162 msgid "Autofs provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:164 +#: src/config/SSSDConfig/sssdoptions.py:163 msgid "Host identity provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:165 +#: src/config/SSSDConfig/sssdoptions.py:164 msgid "SELinux provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:166 +#: src/config/SSSDConfig/sssdoptions.py:165 msgid "Session management provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:167 +#: src/config/SSSDConfig/sssdoptions.py:166 msgid "Resolver provider" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:170 +#: src/config/SSSDConfig/sssdoptions.py:169 msgid "Whether the domain is usable by the OS or by applications" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:171 +#: src/config/SSSDConfig/sssdoptions.py:170 msgid "Enable or disable the domain" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:172 +#: src/config/SSSDConfig/sssdoptions.py:171 msgid "Minimum user ID" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:173 +#: src/config/SSSDConfig/sssdoptions.py:172 msgid "Maximum user ID" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:174 +#: src/config/SSSDConfig/sssdoptions.py:173 msgid "Enable enumerating all users/groups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:175 +#: src/config/SSSDConfig/sssdoptions.py:174 msgid "Cache credentials for offline login" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:176 +#: src/config/SSSDConfig/sssdoptions.py:175 msgid "Display users/groups in fully-qualified form" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:177 +#: src/config/SSSDConfig/sssdoptions.py:176 msgid "Don't include group members in group lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:178 +#: src/config/SSSDConfig/sssdoptions.py:177 #: src/config/SSSDConfig/sssdoptions.py:190 #: src/config/SSSDConfig/sssdoptions.py:191 #: src/config/SSSDConfig/sssdoptions.py:192 @@ -529,48 +536,52 @@ msgstr "" msgid "Entry cache timeout length (seconds)" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:179 +#: src/config/SSSDConfig/sssdoptions.py:178 msgid "" "Restrict or prefer a specific address family when performing DNS lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:180 +#: src/config/SSSDConfig/sssdoptions.py:179 msgid "How long to keep cached entries after last successful login (days)" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:181 +#: src/config/SSSDConfig/sssdoptions.py:180 msgid "" "How long should SSSD talk to single DNS server before trying next server " "(miliseconds)" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:183 +#: src/config/SSSDConfig/sssdoptions.py:182 msgid "How long should keep trying to resolve single DNS query (seconds)" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:184 +#: src/config/SSSDConfig/sssdoptions.py:183 msgid "How long to wait for replies from DNS when resolving servers (seconds)" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:185 +#: src/config/SSSDConfig/sssdoptions.py:184 msgid "The domain part of service discovery DNS query" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:186 +#: src/config/SSSDConfig/sssdoptions.py:185 msgid "" "Specifies the interval, in seconds, that SSSD waits before attempting to " "reconnect to the primary server after a successful connection to the backup " "server" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:188 +#: src/config/SSSDConfig/sssdoptions.py:187 msgid "Override GID value from the identity provider with this value" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:189 +#: src/config/SSSDConfig/sssdoptions.py:188 msgid "Treat usernames as case sensitive" msgstr "" +#: src/config/SSSDConfig/sssdoptions.py:189 +msgid "Lookups by ID are expensive or do not work at all" +msgstr "" + #: src/config/SSSDConfig/sssdoptions.py:197 msgid "How often should expired entries be refreshed in background" msgstr "" @@ -790,7 +801,7 @@ msgid "Search base for SUBID ranges" msgstr "" #: src/config/SSSDConfig/sssdoptions.py:259 -#: src/config/SSSDConfig/sssdoptions.py:506 +#: src/config/SSSDConfig/sssdoptions.py:512 msgid "Which rules should be used to evaluate access control" msgstr "" @@ -932,7 +943,7 @@ msgid "Enable DNS sites - location based service discovery" msgstr "" #: src/config/SSSDConfig/sssdoptions.py:301 -#: src/config/SSSDConfig/sssdoptions.py:504 +#: src/config/SSSDConfig/sssdoptions.py:510 msgid "LDAP filter to determine access privileges" msgstr "" @@ -1352,7 +1363,7 @@ msgid "UUID attribute" msgstr "" #: src/config/SSSDConfig/sssdoptions.py:423 -#: src/config/SSSDConfig/sssdoptions.py:464 +#: src/config/SSSDConfig/sssdoptions.py:470 msgid "objectSID attribute" msgstr "" @@ -1476,385 +1487,409 @@ msgstr "" msgid "A list of extra attributes to download along with the user entry" msgstr "" +#: src/config/SSSDConfig/sssdoptions.py:456 +msgid "The object class of an subid entry in LDAP." +msgstr "" + #: src/config/SSSDConfig/sssdoptions.py:457 -msgid "Base DN for group lookups" +msgid "Subordinate user ID count attribute" msgstr "" #: src/config/SSSDConfig/sssdoptions.py:458 -msgid "Objectclass for groups" +msgid "Subordinate group ID count attribute" msgstr "" #: src/config/SSSDConfig/sssdoptions.py:459 +msgid "User ID range start value attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:460 +msgid "Group ID range start value attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:461 +msgid "Owner of an entry" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:463 +msgid "Base DN for group lookups" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:464 +msgid "Objectclass for groups" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:465 msgid "Group name" msgstr "Номи гурӯҳ" -#: src/config/SSSDConfig/sssdoptions.py:460 +#: src/config/SSSDConfig/sssdoptions.py:466 msgid "Group password" msgstr "Пароли гурӯҳ" -#: src/config/SSSDConfig/sssdoptions.py:461 +#: src/config/SSSDConfig/sssdoptions.py:467 msgid "GID attribute" msgstr "Аттрибути GID" -#: src/config/SSSDConfig/sssdoptions.py:462 +#: src/config/SSSDConfig/sssdoptions.py:468 msgid "Group member attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:463 +#: src/config/SSSDConfig/sssdoptions.py:469 msgid "Group UUID attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:465 +#: src/config/SSSDConfig/sssdoptions.py:471 msgid "Modification time attribute for groups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:466 +#: src/config/SSSDConfig/sssdoptions.py:472 msgid "Type of the group and other flags" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:467 +#: src/config/SSSDConfig/sssdoptions.py:473 msgid "The LDAP group external member attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:468 +#: src/config/SSSDConfig/sssdoptions.py:474 msgid "Maximum nesting level SSSD will follow" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:469 +#: src/config/SSSDConfig/sssdoptions.py:475 msgid "Filter for group lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:470 +#: src/config/SSSDConfig/sssdoptions.py:476 msgid "Scope of group lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:472 +#: src/config/SSSDConfig/sssdoptions.py:478 msgid "Base DN for netgroup lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:473 +#: src/config/SSSDConfig/sssdoptions.py:479 msgid "Objectclass for netgroups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:474 +#: src/config/SSSDConfig/sssdoptions.py:480 msgid "Netgroup name" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:475 +#: src/config/SSSDConfig/sssdoptions.py:481 msgid "Netgroups members attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:476 +#: src/config/SSSDConfig/sssdoptions.py:482 msgid "Netgroup triple attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:477 +#: src/config/SSSDConfig/sssdoptions.py:483 msgid "Modification time attribute for netgroups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:479 +#: src/config/SSSDConfig/sssdoptions.py:485 msgid "Base DN for service lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:480 +#: src/config/SSSDConfig/sssdoptions.py:486 msgid "Objectclass for services" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:481 +#: src/config/SSSDConfig/sssdoptions.py:487 msgid "Service name attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:482 +#: src/config/SSSDConfig/sssdoptions.py:488 msgid "Service port attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:483 +#: src/config/SSSDConfig/sssdoptions.py:489 msgid "Service protocol attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:485 +#: src/config/SSSDConfig/sssdoptions.py:491 msgid "Lower bound for ID-mapping" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:486 +#: src/config/SSSDConfig/sssdoptions.py:492 msgid "Upper bound for ID-mapping" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:487 +#: src/config/SSSDConfig/sssdoptions.py:493 msgid "Number of IDs for each slice when ID-mapping" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:488 +#: src/config/SSSDConfig/sssdoptions.py:494 msgid "Use autorid-compatible algorithm for ID-mapping" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:489 +#: src/config/SSSDConfig/sssdoptions.py:495 msgid "Name of the default domain for ID-mapping" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:490 +#: src/config/SSSDConfig/sssdoptions.py:496 msgid "SID of the default domain for ID-mapping" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:491 +#: src/config/SSSDConfig/sssdoptions.py:497 msgid "Number of secondary slices" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:493 +#: src/config/SSSDConfig/sssdoptions.py:499 msgid "Whether to use Token-Groups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:494 +#: src/config/SSSDConfig/sssdoptions.py:500 msgid "Set lower boundary for allowed IDs from the LDAP server" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:495 +#: src/config/SSSDConfig/sssdoptions.py:501 msgid "Set upper boundary for allowed IDs from the LDAP server" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:496 +#: src/config/SSSDConfig/sssdoptions.py:502 msgid "DN for ppolicy queries" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:497 +#: src/config/SSSDConfig/sssdoptions.py:503 msgid "How many maximum entries to fetch during a wildcard request" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:498 +#: src/config/SSSDConfig/sssdoptions.py:504 msgid "Set libldap debug level" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:501 +#: src/config/SSSDConfig/sssdoptions.py:507 msgid "Policy to evaluate the password expiration" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:505 +#: src/config/SSSDConfig/sssdoptions.py:511 msgid "Which attributes shall be used to evaluate if an account is expired" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:509 +#: src/config/SSSDConfig/sssdoptions.py:515 msgid "URI of an LDAP server where password changes are allowed" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:510 +#: src/config/SSSDConfig/sssdoptions.py:516 msgid "URI of a backup LDAP server where password changes are allowed" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:511 +#: src/config/SSSDConfig/sssdoptions.py:517 msgid "DNS service name for LDAP password change server" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:512 +#: src/config/SSSDConfig/sssdoptions.py:518 msgid "" "Whether to update the ldap_user_shadow_last_change attribute after a " "password change" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:516 +#: src/config/SSSDConfig/sssdoptions.py:522 msgid "Base DN for sudo rules lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:517 +#: src/config/SSSDConfig/sssdoptions.py:523 msgid "Automatic full refresh period" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:518 +#: src/config/SSSDConfig/sssdoptions.py:524 msgid "Automatic smart refresh period" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:519 +#: src/config/SSSDConfig/sssdoptions.py:525 msgid "Smart and full refresh random offset" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:520 +#: src/config/SSSDConfig/sssdoptions.py:526 msgid "Whether to filter rules by hostname, IP addresses and network" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:521 +#: src/config/SSSDConfig/sssdoptions.py:527 msgid "" "Hostnames and/or fully qualified domain names of this machine to filter sudo " "rules" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:522 +#: src/config/SSSDConfig/sssdoptions.py:528 msgid "IPv4 or IPv6 addresses or network of this machine to filter sudo rules" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:523 +#: src/config/SSSDConfig/sssdoptions.py:529 msgid "Whether to include rules that contains netgroup in host attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:524 +#: src/config/SSSDConfig/sssdoptions.py:530 msgid "" "Whether to include rules that contains regular expression in host attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:525 +#: src/config/SSSDConfig/sssdoptions.py:531 msgid "Object class for sudo rules" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:526 +#: src/config/SSSDConfig/sssdoptions.py:532 msgid "Name of attribute that is used as object class for sudo rules" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:527 +#: src/config/SSSDConfig/sssdoptions.py:533 msgid "Sudo rule name" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:528 +#: src/config/SSSDConfig/sssdoptions.py:534 msgid "Sudo rule command attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:529 +#: src/config/SSSDConfig/sssdoptions.py:535 msgid "Sudo rule host attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:530 +#: src/config/SSSDConfig/sssdoptions.py:536 msgid "Sudo rule user attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:531 +#: src/config/SSSDConfig/sssdoptions.py:537 msgid "Sudo rule option attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:532 +#: src/config/SSSDConfig/sssdoptions.py:538 msgid "Sudo rule runas attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:533 +#: src/config/SSSDConfig/sssdoptions.py:539 msgid "Sudo rule runasuser attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:534 +#: src/config/SSSDConfig/sssdoptions.py:540 msgid "Sudo rule runasgroup attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:535 +#: src/config/SSSDConfig/sssdoptions.py:541 msgid "Sudo rule notbefore attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:536 +#: src/config/SSSDConfig/sssdoptions.py:542 msgid "Sudo rule notafter attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:537 +#: src/config/SSSDConfig/sssdoptions.py:543 msgid "Sudo rule order attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:540 +#: src/config/SSSDConfig/sssdoptions.py:546 msgid "Object class for automounter maps" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:541 +#: src/config/SSSDConfig/sssdoptions.py:547 msgid "Automounter map name attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:542 +#: src/config/SSSDConfig/sssdoptions.py:548 msgid "Object class for automounter map entries" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:543 +#: src/config/SSSDConfig/sssdoptions.py:549 msgid "Automounter map entry key attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:544 +#: src/config/SSSDConfig/sssdoptions.py:550 msgid "Automounter map entry value attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:545 +#: src/config/SSSDConfig/sssdoptions.py:551 msgid "Base DN for automounter map lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:546 +#: src/config/SSSDConfig/sssdoptions.py:552 msgid "The name of the automount master map in LDAP." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:549 +#: src/config/SSSDConfig/sssdoptions.py:555 msgid "Base DN for IP hosts lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:550 +#: src/config/SSSDConfig/sssdoptions.py:556 msgid "Object class for IP hosts" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:551 +#: src/config/SSSDConfig/sssdoptions.py:557 msgid "IP host name attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:552 +#: src/config/SSSDConfig/sssdoptions.py:558 msgid "IP host number (address) attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:553 +#: src/config/SSSDConfig/sssdoptions.py:559 msgid "IP host entryUSN attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:554 +#: src/config/SSSDConfig/sssdoptions.py:560 msgid "Base DN for IP networks lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:555 +#: src/config/SSSDConfig/sssdoptions.py:561 msgid "Object class for IP networks" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:556 +#: src/config/SSSDConfig/sssdoptions.py:562 msgid "IP network name attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:557 +#: src/config/SSSDConfig/sssdoptions.py:563 msgid "IP network number (address) attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:558 +#: src/config/SSSDConfig/sssdoptions.py:564 msgid "IP network entryUSN attribute" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:561 +#: src/config/SSSDConfig/sssdoptions.py:567 msgid "Comma separated list of allowed users" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:562 +#: src/config/SSSDConfig/sssdoptions.py:568 msgid "Comma separated list of prohibited users" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:563 +#: src/config/SSSDConfig/sssdoptions.py:569 msgid "" "Comma separated list of groups that are allowed to log in. This applies only " "to groups within this SSSD domain. Local groups are not evaluated." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:565 +#: src/config/SSSDConfig/sssdoptions.py:571 msgid "" "Comma separated list of groups that are explicitly denied access. This " "applies only to groups within this SSSD domain. Local groups are not " "evaluated." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:569 +#: src/config/SSSDConfig/sssdoptions.py:575 msgid "The number of preforked proxy children." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:572 +#: src/config/SSSDConfig/sssdoptions.py:578 msgid "The name of the NSS library to use" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:573 +#: src/config/SSSDConfig/sssdoptions.py:579 msgid "The name of the NSS library to use for hosts and networks lookups" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:574 +#: src/config/SSSDConfig/sssdoptions.py:580 msgid "Whether to look up canonical group name from cache if possible" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:577 +#: src/config/SSSDConfig/sssdoptions.py:583 msgid "PAM stack to use" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:580 +#: src/config/SSSDConfig/sssdoptions.py:586 msgid "Path of passwd file sources." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:581 +#: src/config/SSSDConfig/sssdoptions.py:587 msgid "Path of group file sources." msgstr "" @@ -1882,225 +1917,233 @@ msgstr "" msgid "Option -i|--interactive is not allowed together with -D|--daemon\n" msgstr "" -#: src/monitor/monitor.c:1836 +#: src/monitor/monitor.c:1838 msgid "Failed to get initial capabilities\n" msgstr "" -#: src/monitor/monitor.c:1847 +#: src/monitor/monitor.c:1849 msgid "Non-root service user support isn't built. Can't run under %" msgstr "" -#: src/monitor/monitor.c:1864 +#: src/monitor/monitor.c:1866 #, c-format msgid "Can't read config: '%s'\n" msgstr "" -#: src/monitor/monitor.c:1876 +#: src/monitor/monitor.c:1878 #, c-format -msgid "Failed to boostrap SSSD 'monitor' process: %s" +msgid "Failed to bootstrap SSSD 'monitor' process: %s" msgstr "" -#: src/monitor/monitor.c:1971 +#: src/monitor/monitor.c:1973 msgid "Out of memory\n" msgstr "Берун аз хотира\n" -#: src/providers/krb5/krb5_child.c:4221 +#: src/providers/krb5/krb5_child.c:4316 msgid "Use anonymous PKINIT to request FAST armor ticket" msgstr "" -#: src/providers/krb5/krb5_child.c:4223 +#: src/providers/krb5/krb5_child.c:4318 msgid "Kerberos realm to use" msgstr "" -#: src/providers/krb5/krb5_child.c:4225 +#: src/providers/krb5/krb5_child.c:4320 msgid "Requested lifetime of the ticket" msgstr "" -#: src/providers/krb5/krb5_child.c:4227 +#: src/providers/krb5/krb5_child.c:4322 msgid "Requested renewable lifetime of the ticket" msgstr "" -#: src/providers/krb5/krb5_child.c:4229 +#: src/providers/krb5/krb5_child.c:4324 msgid "FAST options ('never', 'try', 'demand')" msgstr "" -#: src/providers/krb5/krb5_child.c:4232 +#: src/providers/krb5/krb5_child.c:4327 msgid "Specifies the server principal to use for FAST" msgstr "" -#: src/providers/krb5/krb5_child.c:4234 +#: src/providers/krb5/krb5_child.c:4329 msgid "Requests canonicalization of the principal name" msgstr "" -#: src/providers/krb5/krb5_child.c:4236 +#: src/providers/krb5/krb5_child.c:4331 msgid "Use custom version of krb5_get_init_creds_password" msgstr "" -#: src/providers/krb5/krb5_child.c:4238 +#: src/providers/krb5/krb5_child.c:4333 msgid "Check PAC flags" msgstr "" -#: src/providers/data_provider_be.c:790 +#: src/providers/krb5/krb5_child.c:4335 +msgid "Set environment variable (KEY=VALUE)" +msgstr "" + +#: src/providers/data_provider_be.c:786 msgid "Domain of the information provider (mandatory)" msgstr "" -#: src/sss_client/common.c:1165 +#: src/sss_client/common.c:1208 msgid "Socket has wrong ownership or permissions." msgstr "" -#: src/sss_client/common.c:1168 +#: src/sss_client/common.c:1211 msgid "Unexpected format of the server credential message." msgstr "" -#: src/sss_client/common.c:1171 +#: src/sss_client/common.c:1214 msgid "SSSD is not run by trusted user." msgstr "" -#: src/sss_client/common.c:1174 +#: src/sss_client/common.c:1217 msgid "SSSD socket does not exist." msgstr "" -#: src/sss_client/common.c:1177 +#: src/sss_client/common.c:1220 msgid "Cannot get stat of SSSD socket." msgstr "" -#: src/sss_client/common.c:1182 +#: src/sss_client/common.c:1225 msgid "An error occurred, but no description can be found." msgstr "" -#: src/sss_client/common.c:1188 +#: src/sss_client/common.c:1231 msgid "Unexpected error while looking for an error description" msgstr "" -#: src/sss_client/pam_sss.c:74 +#: src/sss_client/pam_sss.c:135 msgid "Permission denied. " msgstr "" -#: src/sss_client/pam_sss.c:75 src/sss_client/pam_sss.c:843 -#: src/sss_client/pam_sss.c:854 +#: src/sss_client/pam_sss.c:136 src/sss_client/pam_sss.c:921 +#: src/sss_client/pam_sss.c:932 msgid "Server message: " msgstr "" -#: src/sss_client/pam_sss.c:76 +#: src/sss_client/pam_sss.c:137 msgid "" "Kerberos TGT will not be granted upon login, user experience will be " "affected." msgstr "" -#: src/sss_client/pam_sss.c:77 +#: src/sss_client/pam_sss.c:138 msgid "Enter PIN:" msgstr "" -#: src/sss_client/pam_sss.c:320 +#: src/sss_client/pam_sss.c:385 msgid "Passwords do not match" msgstr "Паролҳо номувофиқанд" -#: src/sss_client/pam_sss.c:508 +#: src/sss_client/pam_sss.c:584 msgid "Password reset by root is not supported." msgstr "" -#: src/sss_client/pam_sss.c:549 +#: src/sss_client/pam_sss.c:625 msgid "Authenticated with cached credentials" msgstr "" -#: src/sss_client/pam_sss.c:550 +#: src/sss_client/pam_sss.c:626 msgid ", your cached password will expire at: " msgstr "" -#: src/sss_client/pam_sss.c:580 +#: src/sss_client/pam_sss.c:656 #, c-format msgid "Your password has expired. You have %1$d grace login(s) remaining." msgstr "" -#: src/sss_client/pam_sss.c:630 +#: src/sss_client/pam_sss.c:706 #, c-format msgid "Your password will expire in %1$d %2$s." msgstr "" -#: src/sss_client/pam_sss.c:633 +#: src/sss_client/pam_sss.c:709 #, c-format msgid "Your password has expired." msgstr "" -#: src/sss_client/pam_sss.c:684 +#: src/sss_client/pam_sss.c:760 msgid "Authentication is denied until: " msgstr "" -#: src/sss_client/pam_sss.c:705 +#: src/sss_client/pam_sss.c:781 msgid "System is offline, password change not possible" msgstr "" -#: src/sss_client/pam_sss.c:720 +#: src/sss_client/pam_sss.c:796 msgid "" "After changing the OTP password, you need to log out and back in order to " "acquire a ticket" msgstr "" -#: src/sss_client/pam_sss.c:735 +#: src/sss_client/pam_sss.c:813 msgid "PIN locked" msgstr "" -#: src/sss_client/pam_sss.c:750 +#: src/sss_client/pam_sss.c:828 msgid "" "No Kerberos TGT granted as the server does not support this method. Your " "single-sign on(SSO) experience will be affected." msgstr "" -#: src/sss_client/pam_sss.c:840 src/sss_client/pam_sss.c:853 +#: src/sss_client/pam_sss.c:918 src/sss_client/pam_sss.c:931 msgid "Password change failed. " msgstr "" -#: src/sss_client/pam_sss.c:1859 +#: src/sss_client/pam_sss.c:2028 #, c-format -msgid "Authenticate at %1$s and press ENTER." +msgid "Authenticate at \"%1$s\"." msgstr "" -#: src/sss_client/pam_sss.c:1862 +#: src/sss_client/pam_sss.c:2031 #, c-format -msgid "Authenticate with PIN %1$s at %2$s and press ENTER." +msgid "Authenticate with PIN \"%1$s\" at \"%2$s\"." msgstr "" -#: src/sss_client/pam_sss.c:2281 +#: src/sss_client/pam_sss.c:2470 msgid "Please (re)insert (different) Smartcard" msgstr "" -#: src/sss_client/pam_sss.c:2482 +#: src/sss_client/pam_sss.c:2700 msgid "New Password: " msgstr "Пароли нав:" -#: src/sss_client/pam_sss.c:2483 +#: src/sss_client/pam_sss.c:2701 msgid "Reenter new Password: " msgstr "" -#: src/sss_client/pam_sss.c:2676 src/sss_client/pam_sss.c:2679 +#: src/sss_client/pam_sss.c:2890 +msgid "Press ENTER to continue." +msgstr "" + +#: src/sss_client/pam_sss.c:2913 src/sss_client/pam_sss.c:2916 msgid "First Factor: " msgstr "" -#: src/sss_client/pam_sss.c:2677 src/sss_client/pam_sss.c:2851 +#: src/sss_client/pam_sss.c:2914 src/sss_client/pam_sss.c:3088 msgid "Second Factor (optional): " msgstr "" -#: src/sss_client/pam_sss.c:2680 src/sss_client/pam_sss.c:2855 +#: src/sss_client/pam_sss.c:2917 src/sss_client/pam_sss.c:3092 msgid "Second Factor: " msgstr "" -#: src/sss_client/pam_sss.c:2684 +#: src/sss_client/pam_sss.c:2921 msgid "Insert your passkey device, then press ENTER." msgstr "" -#: src/sss_client/pam_sss.c:2688 src/sss_client/pam_sss.c:2696 +#: src/sss_client/pam_sss.c:2925 src/sss_client/pam_sss.c:2933 msgid "Password: " msgstr "Парол:" -#: src/sss_client/pam_sss.c:2850 src/sss_client/pam_sss.c:2854 +#: src/sss_client/pam_sss.c:3087 src/sss_client/pam_sss.c:3091 msgid "First Factor (Current Password): " msgstr "" -#: src/sss_client/pam_sss.c:2874 +#: src/sss_client/pam_sss.c:3111 msgid "Current Password: " msgstr "" -#: src/sss_client/pam_sss.c:3248 +#: src/sss_client/pam_sss.c:3485 msgid "Password expired. Change your password now." msgstr "" @@ -2532,9 +2575,9 @@ msgstr "" #: src/tools/sssctl/sssctl_cache.c:835 src/tools/sssctl/sssctl_cache.c:918 #: src/tools/sssctl/sssctl_cache.c:950 src/tools/sssctl/sssctl_cache.c:956 #: src/tools/sssctl/sssctl_cache.c:1010 src/tools/sssctl/sssctl_cache.c:1034 -#: src/tools/sssctl/sssctl_cache.c:1085 src/tools/sssctl/sssctl_cache.c:1194 -#: src/tools/sssctl/sssctl_cache.c:1229 src/tools/sssctl/sssctl_cache.c:1235 -#: src/tools/sssctl/sssctl_cache.c:1244 +#: src/tools/sssctl/sssctl_cache.c:1085 src/tools/sssctl/sssctl_cache.c:1195 +#: src/tools/sssctl/sssctl_cache.c:1230 src/tools/sssctl/sssctl_cache.c:1236 +#: src/tools/sssctl/sssctl_cache.c:1245 msgid "talloc failed\n" msgstr "" @@ -2608,25 +2651,25 @@ msgstr "" msgid "Unable to remove downloaded GPO files: %s\n" msgstr "" -#: src/tools/sssctl/sssctl_cache.c:1165 +#: src/tools/sssctl/sssctl_cache.c:1166 #, c-format msgid "Failed to fetch cache entry: %s\n" msgstr "" -#: src/tools/sssctl/sssctl_cache.c:1170 +#: src/tools/sssctl/sssctl_cache.c:1171 msgid "Could not determine object domain\n" msgstr "" -#: src/tools/sssctl/sssctl_cache.c:1200 +#: src/tools/sssctl/sssctl_cache.c:1201 msgid "Could not find GUID attribute in GPO entry\n" msgstr "" -#: src/tools/sssctl/sssctl_cache.c:1206 +#: src/tools/sssctl/sssctl_cache.c:1207 #, c-format msgid "Failed to delete GPO: %s\n" msgstr "" -#: src/tools/sssctl/sssctl_cache.c:1210 +#: src/tools/sssctl/sssctl_cache.c:1211 #, c-format msgid "%s removed from cache\n" msgstr "" @@ -2714,39 +2757,39 @@ msgid "" "\"/my/path/sssd.conf\", the snippet dir \"/my/path/conf.d\" is used)" msgstr "" -#: src/tools/sssctl/sssctl_config.c:114 +#: src/tools/sssctl/sssctl_config.c:126 #, c-format msgid "File %1$s does not exist.\n" msgstr "" -#: src/tools/sssctl/sssctl_config.c:115 +#: src/tools/sssctl/sssctl_config.c:127 msgid "There is no configuration.\n" msgstr "" -#: src/tools/sssctl/sssctl_config.c:120 +#: src/tools/sssctl/sssctl_config.c:132 #, c-format msgid "Configuration validation failed: %s\n" msgstr "" -#: src/tools/sssctl/sssctl_config.c:121 +#: src/tools/sssctl/sssctl_config.c:133 msgid "Run with high debug level to see details.\n" msgstr "" -#: src/tools/sssctl/sssctl_config.c:130 -msgid "Failed to run validators" +#: src/tools/sssctl/sssctl_config.c:142 +msgid "Failed to run validators\n" msgstr "" -#: src/tools/sssctl/sssctl_config.c:134 +#: src/tools/sssctl/sssctl_config.c:146 #, c-format msgid "Issues identified by validators: %zu\n" msgstr "" -#: src/tools/sssctl/sssctl_config.c:145 +#: src/tools/sssctl/sssctl_config.c:157 #, c-format msgid "Messages generated during configuration merging: %zu\n" msgstr "" -#: src/tools/sssctl/sssctl_config.c:158 +#: src/tools/sssctl/sssctl_config.c:170 #, c-format msgid "Used configuration snippet files: %zu\n" msgstr "" diff --git a/po/tr.po b/po/tr.po index 82cbd7c50d6..582555d1922 100644 --- a/po/tr.po +++ b/po/tr.po @@ -11,8 +11,8 @@ msgid "" msgstr "" "Project-Id-Version: PACKAGE VERSION\n" "Report-Msgid-Bugs-To: sssd-devel@lists.fedorahosted.org\n" -"POT-Creation-Date: 2026-01-14 14:57+0000\n" -"PO-Revision-Date: 2026-04-23 16:23+0000\n" +"POT-Creation-Date: 2026-10-02 15:57+0000\n" +"PO-Revision-Date: 2026-10-05 16:47+0000\n" "Last-Translator: Anonymous \n" "Language-Team: Turkish \n" @@ -21,52 +21,53 @@ msgstr "" "Content-Type: text/plain; charset=UTF-8\n" "Content-Transfer-Encoding: 8bit\n" "Plural-Forms: nplurals=2; plural=(n>1);\n" -"X-Generator: Weblate 5.17\n" +"X-Generator: Weblate 2026.10\n" -#: src/config/SSSDConfig/sssdoptions.py:20 -#: src/config/SSSDConfig/sssdoptions.py:21 +#: src/config/SSSDConfig/sssdoptions.py:16 +#: src/config/SSSDConfig/sssdoptions.py:17 msgid "Set the verbosity of the debug logging" msgstr "Hata ayıklama günlüğünün ayrıntı düzeyini ayarla" -#: src/config/SSSDConfig/sssdoptions.py:22 +#: src/config/SSSDConfig/sssdoptions.py:18 msgid "Include timestamps in debug logs" msgstr "Hata ayıklama günlüklerine zaman damgalarını dahil et" -#: src/config/SSSDConfig/sssdoptions.py:23 +#: src/config/SSSDConfig/sssdoptions.py:19 msgid "Include microseconds in timestamps in debug logs" msgstr "" "Hata ayıklama günlüklerindeki zaman damgalarına mikrosaniyeleri dahil et" -#: src/config/SSSDConfig/sssdoptions.py:24 +#: src/config/SSSDConfig/sssdoptions.py:20 msgid "Enable/disable debug backtrace" msgstr "Hata ayıklama geri izlemeyi etkinleştir/devre dışı bırak" -#: src/config/SSSDConfig/sssdoptions.py:25 +#: src/config/SSSDConfig/sssdoptions.py:21 msgid "Watchdog timeout before restarting service" msgstr "Hizmeti yeniden başlatmadan önce watchdog zaman aşımı" -#: src/config/SSSDConfig/sssdoptions.py:26 +#: src/config/SSSDConfig/sssdoptions.py:22 msgid "Command to start service" msgstr "Hizmeti başlatma komutu" -#: src/config/SSSDConfig/sssdoptions.py:27 +#: src/config/SSSDConfig/sssdoptions.py:23 msgid "The number of file descriptors that may be opened by this responder" msgstr "Bu yanıtlayıcı tarafından açılabilecek dosya tanımlayıcılarının sayısı" -#: src/config/SSSDConfig/sssdoptions.py:28 +#: src/config/SSSDConfig/sssdoptions.py:24 msgid "Idle time before automatic disconnection of a client" msgstr "" "İstemci bağlantısının otomatik olarak kesilmesinden önceki boşta geçen süre" -#: src/config/SSSDConfig/sssdoptions.py:29 +#: src/config/SSSDConfig/sssdoptions.py:25 msgid "Idle time before automatic shutdown of the responder" msgstr "Yanıtlayıcının otomatik kapanmasından önceki boşta geçen süre" -#: src/config/SSSDConfig/sssdoptions.py:30 +#: src/config/SSSDConfig/sssdoptions.py:26 msgid "Always query all the caches before querying the Data Providers" -msgstr "Veri sağlayıcıları sorgulamadan önce her zaman tüm önbellekleri sorgula" +msgstr "" +"Veri sağlayıcıları sorgulamadan önce her zaman tüm önbellekleri sorgula" -#: src/config/SSSDConfig/sssdoptions.py:31 +#: src/config/SSSDConfig/sssdoptions.py:27 msgid "" "When SSSD switches to offline mode the amount of time before it tries to go " "back online will increase based upon the time spent disconnected. This value " @@ -78,23 +79,23 @@ msgstr "" "cinsindendir ve şu şekilde hesaplanır: çevrim_dışı_zaman_aşımı + " "rastgele_ofset." -#: src/config/SSSDConfig/sssdoptions.py:36 +#: src/config/SSSDConfig/sssdoptions.py:32 msgid "SSSD Services to start" msgstr "Başlatılacak SSSD hizmetleri" -#: src/config/SSSDConfig/sssdoptions.py:37 +#: src/config/SSSDConfig/sssdoptions.py:33 msgid "SSSD Domains to start" msgstr "Başlatılacak SSSD etki alanları" -#: src/config/SSSDConfig/sssdoptions.py:38 +#: src/config/SSSDConfig/sssdoptions.py:34 msgid "Regex to parse username and domain" msgstr "Kullanıcı adını ve etki alanını ayrıştırmak için düzenli ifade" -#: src/config/SSSDConfig/sssdoptions.py:39 +#: src/config/SSSDConfig/sssdoptions.py:35 msgid "Printf-compatible format for displaying fully-qualified names" msgstr "Tam nitelikli adları görüntülemek için printf uyumlu biçim" -#: src/config/SSSDConfig/sssdoptions.py:40 +#: src/config/SSSDConfig/sssdoptions.py:36 msgid "" "Directory on the filesystem where SSSD should store Kerberos replay cache " "files." @@ -102,38 +103,38 @@ msgstr "" "SSSD'nin Kerberos yeniden oynatma önbellek dosyalarını depolaması gereken " "dosya sistemindeki dizin." -#: src/config/SSSDConfig/sssdoptions.py:41 +#: src/config/SSSDConfig/sssdoptions.py:37 msgid "Domain to add to names without a domain component." msgstr "Etki alanı bileşeni olmayan adlara eklenecek etki alanı." -#: src/config/SSSDConfig/sssdoptions.py:42 +#: src/config/SSSDConfig/sssdoptions.py:38 msgid "The user to drop privileges to" msgstr "Ayrıcalıkların bırakılacağı kullanıcı" -#: src/config/SSSDConfig/sssdoptions.py:43 +#: src/config/SSSDConfig/sssdoptions.py:39 msgid "Tune certificate verification" msgstr "Sertifika doğrulamasını ayarla" -#: src/config/SSSDConfig/sssdoptions.py:44 +#: src/config/SSSDConfig/sssdoptions.py:40 msgid "All spaces in group or user names will be replaced with this character" msgstr "" "Grup veya kullanıcı adlarındaki tüm boşluklar bu karakterle değiştirilecek" -#: src/config/SSSDConfig/sssdoptions.py:45 +#: src/config/SSSDConfig/sssdoptions.py:41 msgid "Tune sssd to honor or ignore netlink state changes" msgstr "" "Netlink durum değişikliklerini dikkate almak veya yok saymak için sssd'yi " "ayarla" -#: src/config/SSSDConfig/sssdoptions.py:46 +#: src/config/SSSDConfig/sssdoptions.py:42 msgid "Enable or disable the implicit files domain" msgstr "Öntanımlı dosyalar etki alanını etkinleştir veya devre dışı bırak" -#: src/config/SSSDConfig/sssdoptions.py:47 +#: src/config/SSSDConfig/sssdoptions.py:43 msgid "A specific order of the domains to be looked up" msgstr "Aranacak etki alanlarının belirli bir sırası" -#: src/config/SSSDConfig/sssdoptions.py:48 +#: src/config/SSSDConfig/sssdoptions.py:44 msgid "" "Controls if SSSD should monitor the state of resolv.conf to identify when it " "needs to update its internal DNS resolver." @@ -141,7 +142,7 @@ msgstr "" "SSSD'nin dahili DNS çözümleyicisini ne zaman güncellemesi gerektiğini " "belirlemek için resolv.conf durumunu izlemesi gerekip gerekmediğini denetler." -#: src/config/SSSDConfig/sssdoptions.py:50 +#: src/config/SSSDConfig/sssdoptions.py:46 msgid "" "SSSD monitors the state of resolv.conf to identify when it needs to update " "its internal DNS resolver. By default, we will attempt to use inotify for " @@ -153,78 +154,78 @@ msgstr "" "inotify kullanmayı deneyeceğiz ve inotify kullanılamıyorsa bunun yerine her " "beş saniyede bir resolv.conf'u sorgulamayı kullanacağız." -#: src/config/SSSDConfig/sssdoptions.py:53 +#: src/config/SSSDConfig/sssdoptions.py:49 msgid "Run PAC responder automatically for AD and IPA provider" msgstr "" "AD ve IPA sağlayıcısı için PAC yanıtlayıcısını otomatik olarak çalıştırın" -#: src/config/SSSDConfig/sssdoptions.py:54 +#: src/config/SSSDConfig/sssdoptions.py:50 msgid "Enable or disable core dumps for all SSSD processes." msgstr "" "Tüm SSSD işlemleri için çekirdek dökümlerini etkinleştirin veya devre dışı " "bırakın." -#: src/config/SSSDConfig/sssdoptions.py:55 +#: src/config/SSSDConfig/sssdoptions.py:51 msgid "Tune passkey verification behavior" msgstr "Geçiş anahtarı doğrulama davranışını ayarlayın" -#: src/config/SSSDConfig/sssdoptions.py:58 +#: src/config/SSSDConfig/sssdoptions.py:54 msgid "Enumeration cache timeout length (seconds)" msgstr "Numaralandırma önbelleği zaman aşımı uzunluğu (saniye)" -#: src/config/SSSDConfig/sssdoptions.py:59 +#: src/config/SSSDConfig/sssdoptions.py:55 msgid "Entry cache background update timeout length (seconds)" msgstr "Girdi önbelleği arka planda güncelleme zaman aşımı uzunluğu (saniye)" -#: src/config/SSSDConfig/sssdoptions.py:60 -#: src/config/SSSDConfig/sssdoptions.py:125 +#: src/config/SSSDConfig/sssdoptions.py:56 +#: src/config/SSSDConfig/sssdoptions.py:124 msgid "Negative cache timeout length (seconds)" msgstr "Negatif önbellek zaman aşımı uzunluğu (saniye)" -#: src/config/SSSDConfig/sssdoptions.py:61 +#: src/config/SSSDConfig/sssdoptions.py:57 msgid "Users that SSSD should explicitly ignore" msgstr "SSSD'nin açıkça yok sayması gereken kullanıcılar" -#: src/config/SSSDConfig/sssdoptions.py:62 +#: src/config/SSSDConfig/sssdoptions.py:58 msgid "Groups that SSSD should explicitly ignore" msgstr "SSSD'nin açıkça yok sayması gereken gruplar" -#: src/config/SSSDConfig/sssdoptions.py:63 +#: src/config/SSSDConfig/sssdoptions.py:59 msgid "Should filtered users appear in groups" msgstr "Filtrelenen kullanıcılar gruplarda görünmeli mi" -#: src/config/SSSDConfig/sssdoptions.py:64 +#: src/config/SSSDConfig/sssdoptions.py:60 msgid "The value of the password field the NSS provider should return" msgstr "NSS sağlayıcısının döndürmesi gereken parola alanının değeri" -#: src/config/SSSDConfig/sssdoptions.py:65 +#: src/config/SSSDConfig/sssdoptions.py:61 msgid "Override homedir value from the identity provider with this value" msgstr "" "Kimlik sağlayıcıdan alınan homedir (ev dizini) değerini bu değerle geçersiz " "kıl" -#: src/config/SSSDConfig/sssdoptions.py:66 +#: src/config/SSSDConfig/sssdoptions.py:62 msgid "" "Substitute empty homedir value from the identity provider with this value" msgstr "" "Kimlik sağlayıcıdan alınan boş homedir (ev dizini) değerini bu değerle " "değiştir" -#: src/config/SSSDConfig/sssdoptions.py:67 +#: src/config/SSSDConfig/sssdoptions.py:63 msgid "Override shell value from the identity provider with this value" msgstr "" "Kimlik sağlayıcıdan alınan shell (kabuk) değerini bu değerle geçersiz kıl" -#: src/config/SSSDConfig/sssdoptions.py:68 +#: src/config/SSSDConfig/sssdoptions.py:64 msgid "The list of shells users are allowed to log in with" msgstr "Kullanıcıların oturum açmasına izin verilen kabukların listesi" -#: src/config/SSSDConfig/sssdoptions.py:69 +#: src/config/SSSDConfig/sssdoptions.py:65 msgid "" "The list of shells that will be vetoed, and replaced with the fallback shell" msgstr "Reddedilecek ve yedek kabuk ile değiştirilecek kabukların listesi" -#: src/config/SSSDConfig/sssdoptions.py:70 +#: src/config/SSSDConfig/sssdoptions.py:66 msgid "" "If a shell stored in central directory is allowed but not available, use " "this fallback" @@ -232,15 +233,15 @@ msgstr "" "Merkezi dizinde depolanan bir kabuğa izin veriliyor ancak kullanılamıyorsa, " "yedek olarak bunu kullan" -#: src/config/SSSDConfig/sssdoptions.py:71 +#: src/config/SSSDConfig/sssdoptions.py:67 msgid "Shell to use if the provider does not list one" msgstr "Sağlayıcı bir tane listelemiyorsa kullanılacak kabuk" -#: src/config/SSSDConfig/sssdoptions.py:72 +#: src/config/SSSDConfig/sssdoptions.py:68 msgid "How long will be in-memory cache records valid" msgstr "Bellek içi önbellek kayıtları ne kadar süreyle geçerli olacak" -#: src/config/SSSDConfig/sssdoptions.py:74 +#: src/config/SSSDConfig/sssdoptions.py:70 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for passwd requests" @@ -248,7 +249,7 @@ msgstr "" "passwd istekleri için hızlı bellek içi önbellek içinde ayrılan veri " "tablosunun boyutu (megabayt olarak)" -#: src/config/SSSDConfig/sssdoptions.py:76 +#: src/config/SSSDConfig/sssdoptions.py:72 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for group requests" @@ -256,7 +257,7 @@ msgstr "" "Grup istekleri için hızlı bellek içi önbellek içinde ayrılan veri tablosunun " "boyutu (megabayt olarak)" -#: src/config/SSSDConfig/sssdoptions.py:78 +#: src/config/SSSDConfig/sssdoptions.py:74 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for initgroups requests" @@ -264,7 +265,7 @@ msgstr "" "initgroups istekleri için hızlı bellek içi önbellek içinde ayrılan veri " "tablosunun boyutu (megabayt olarak)" -#: src/config/SSSDConfig/sssdoptions.py:79 +#: src/config/SSSDConfig/sssdoptions.py:75 msgid "" "The value of this option will be used in the expansion of the " "override_homedir option if the template contains the format string %H." @@ -272,7 +273,7 @@ msgstr "" "Bu seçeneğin değeri, şablon %H biçim dizgesini içeriyorsa override_homedir " "seçeneğinin genişletilmesinde kullanılacaktır." -#: src/config/SSSDConfig/sssdoptions.py:81 +#: src/config/SSSDConfig/sssdoptions.py:77 msgid "" "Specifies time in seconds for which the list of subdomains will be " "considered valid." @@ -280,7 +281,7 @@ msgstr "" "Alt etki alanı adları listesinin geçerli sayılacağı süreyi saniye cinsinden " "belirtir." -#: src/config/SSSDConfig/sssdoptions.py:83 +#: src/config/SSSDConfig/sssdoptions.py:79 msgid "" "The entry cache can be set to automatically update entries in the background " "if they are requested beyond a percentage of the entry_cache_timeout value " @@ -290,18 +291,18 @@ msgstr "" "yüzdesinin ötesinde istenirse girdileri arka planda otomatik olarak " "güncelleyecek şekilde ayarlanabilir." -#: src/config/SSSDConfig/sssdoptions.py:88 +#: src/config/SSSDConfig/sssdoptions.py:84 msgid "How long to allow cached logins between online logins (days)" msgstr "" "Çevrim içi oturum açma işlemleri arasında önbelleğe alınmış oturum açma " "işlemlerine ne kadar süreyle izin verilecek (gün)" -#: src/config/SSSDConfig/sssdoptions.py:89 +#: src/config/SSSDConfig/sssdoptions.py:85 msgid "How many failed logins attempts are allowed when offline" msgstr "" "Çevrim dışıyken kaç tane başarısız oturum açma girişimine izin verilecek" -#: src/config/SSSDConfig/sssdoptions.py:91 +#: src/config/SSSDConfig/sssdoptions.py:87 msgid "" "How long (minutes) to deny login after offline_failed_login_attempts has " "been reached" @@ -309,90 +310,91 @@ msgstr "" "offline_failed_login_attempts değerine ulaşıldıktan sonra oturum açmanın " "reddedileceği süre (dakika)" -#: src/config/SSSDConfig/sssdoptions.py:92 +#: src/config/SSSDConfig/sssdoptions.py:88 msgid "What kind of messages are displayed to the user during authentication" msgstr "Kimlik doğrulama sırasında kullanıcıya ne tür mesajlar gösterilecek" -#: src/config/SSSDConfig/sssdoptions.py:93 +#: src/config/SSSDConfig/sssdoptions.py:89 msgid "Filter PAM responses sent to the pam_sss" msgstr "pam_sss'ye gönderilen PAM yanıtlarını filtrele" -#: src/config/SSSDConfig/sssdoptions.py:94 +#: src/config/SSSDConfig/sssdoptions.py:90 msgid "How many seconds to keep identity information cached for PAM requests" msgstr "PAM istekleri için kimlik bilgileri kaç saniye önbellekte tutulacak" -#: src/config/SSSDConfig/sssdoptions.py:95 +#: src/config/SSSDConfig/sssdoptions.py:91 msgid "How many days before password expiration a warning should be displayed" msgstr "Parola süresinin dolmasına kaç gün kala bir uyarı görüntülenmeli" -#: src/config/SSSDConfig/sssdoptions.py:96 +#: src/config/SSSDConfig/sssdoptions.py:92 msgid "List of trusted uids or user's name" msgstr "Güvenilen kullanıcı kimliklerinin veya adlarının listesi" -#: src/config/SSSDConfig/sssdoptions.py:97 +#: src/config/SSSDConfig/sssdoptions.py:93 msgid "List of domains accessible even for untrusted users." msgstr "" "Güvenilmeyen kullanıcılar için bile erişilebilen etki alanı adlarının " "listesi." -#: src/config/SSSDConfig/sssdoptions.py:98 +#: src/config/SSSDConfig/sssdoptions.py:94 msgid "Message printed when user account is expired." msgstr "Kullanıcı hesabının süresi dolduğunda görüntülenen mesaj." -#: src/config/SSSDConfig/sssdoptions.py:99 +#: src/config/SSSDConfig/sssdoptions.py:95 msgid "Message printed when user account is locked." msgstr "Kullanıcı hesabı kilitlendiğinde görüntülenen mesaj." -#: src/config/SSSDConfig/sssdoptions.py:100 +#: src/config/SSSDConfig/sssdoptions.py:96 msgid "Allow certificate based/Smartcard authentication." msgstr "Sertifika tabanlı/Akıllı kart kimlik doğrulamasına izin ver." -#: src/config/SSSDConfig/sssdoptions.py:101 +#: src/config/SSSDConfig/sssdoptions.py:97 msgid "Path to certificate database with PKCS#11 modules." msgstr "PKCS#11 modüllerine sahip sertifika veri tabanının yolu." -#: src/config/SSSDConfig/sssdoptions.py:102 +#: src/config/SSSDConfig/sssdoptions.py:98 msgid "Tune certificate verification for PAM authentication." msgstr "PAM kimlik doğrulaması için sertifika doğrulamasını ayarla." -#: src/config/SSSDConfig/sssdoptions.py:103 +#: src/config/SSSDConfig/sssdoptions.py:99 msgid "How many seconds will pam_sss wait for p11_child to finish" msgstr "pam_sss, p11_child'in bitmesi için kaç saniye bekleyecek" -#: src/config/SSSDConfig/sssdoptions.py:104 +#: src/config/SSSDConfig/sssdoptions.py:100 msgid "Which PAM services are permitted to contact application domains" msgstr "" "Hangi PAM hizmetlerinin uygulama etki alanlarıyla iletişim kurmasına izin " "verilecek" -#: src/config/SSSDConfig/sssdoptions.py:105 +#: src/config/SSSDConfig/sssdoptions.py:101 msgid "Allowed services for using smartcards" msgstr "Akıllı kartları kullanmak için izin verilen hizmetler" -#: src/config/SSSDConfig/sssdoptions.py:106 +#: src/config/SSSDConfig/sssdoptions.py:102 msgid "Additional timeout to wait for a card if requested" msgstr "İstendiğinde kart beklemek için ek zaman aşımı" -#: src/config/SSSDConfig/sssdoptions.py:107 +#: src/config/SSSDConfig/sssdoptions.py:103 msgid "" "PKCS#11 URI to restrict the selection of devices for Smartcard authentication" msgstr "" "Akıllı kart kimlik doğrulaması için aygıt seçimini kısıtlamak için PKCS#11 " "URI'si" -#: src/config/SSSDConfig/sssdoptions.py:108 +#: src/config/SSSDConfig/sssdoptions.py:104 msgid "When shall the PAM responder force an initgroups request" msgstr "PAM yanıtlayıcısı bir initgroups talebini ne zaman zorlayacak" -#: src/config/SSSDConfig/sssdoptions.py:109 +#: src/config/SSSDConfig/sssdoptions.py:105 msgid "List of PAM services that are allowed to authenticate with GSSAPI." -msgstr "GSSAPI ile kimlik doğrulamasına izin verilen PAM hizmetlerinin listesi." +msgstr "" +"GSSAPI ile kimlik doğrulamasına izin verilen PAM hizmetlerinin listesi." -#: src/config/SSSDConfig/sssdoptions.py:110 +#: src/config/SSSDConfig/sssdoptions.py:106 msgid "Whether to match authenticated UPN with target user" msgstr "Kimliği doğrulanmış UPN'nin hedef kullanıcıyla eşleşip eşleşmeyeceği" -#: src/config/SSSDConfig/sssdoptions.py:111 +#: src/config/SSSDConfig/sssdoptions.py:107 msgid "" "List of pairs : that must be enforced " "for PAM access with GSSAPI authentication" @@ -400,33 +402,43 @@ msgstr "" "GSSAPI kimlik doğrulaması ile PAM erişimi için zorunlu kılınması gereken " ": çiftlerinin listesi" -#: src/config/SSSDConfig/sssdoptions.py:113 +#: src/config/SSSDConfig/sssdoptions.py:109 +#, fuzzy +msgid "" +"List of triples :: that assigns " +"additional information from the Kerberos ticket to an authentication " +"indicator." +msgstr "" +"GSSAPI kimlik doğrulaması ile PAM erişimi için zorunlu kılınması gereken " +": çiftlerinin listesi" + +#: src/config/SSSDConfig/sssdoptions.py:112 msgid "Allow passkey device authentication." msgstr "Geçiş anahtarı cihaz kimlik doğrulamasına izin ver." -#: src/config/SSSDConfig/sssdoptions.py:114 +#: src/config/SSSDConfig/sssdoptions.py:113 msgid "How many seconds will pam_sss wait for passkey_child to finish" msgstr "pam_sss, p11_child'in bitmesi için kaç saniye bekleyecek" -#: src/config/SSSDConfig/sssdoptions.py:115 +#: src/config/SSSDConfig/sssdoptions.py:114 msgid "Enable debugging in the libfido2 library" msgstr "libfido2 kitaplığında hata ayıklamayı etkinleştir" -#: src/config/SSSDConfig/sssdoptions.py:116 +#: src/config/SSSDConfig/sssdoptions.py:115 msgid "Enable JSON protocol for authentication methods selection." msgstr "Kimlik doğrulama yöntemleri seçimi için JSON protokolünü etkinleştir." -#: src/config/SSSDConfig/sssdoptions.py:119 +#: src/config/SSSDConfig/sssdoptions.py:118 msgid "Whether to evaluate the time-based attributes in sudo rules" msgstr "" "Sudo kurallarında zamana dayalı özniteliklerin değerlendirilip " "değerlendirilmeyeceği" -#: src/config/SSSDConfig/sssdoptions.py:120 +#: src/config/SSSDConfig/sssdoptions.py:119 msgid "If true, SSSD will switch back to lower-wins ordering logic" msgstr "Doğruysa, SSSD düşük kazançlı sıralama mantığına geri dönecek" -#: src/config/SSSDConfig/sssdoptions.py:121 +#: src/config/SSSDConfig/sssdoptions.py:120 msgid "" "Maximum number of rules that can be refreshed at once. If this is exceeded, " "full refresh is performed." @@ -434,13 +446,13 @@ msgstr "" "Tek seferde yenilenebilecek azami kural sayısı. Bu aşılırsa, tam yenileme " "gerçekleştirilir." -#: src/config/SSSDConfig/sssdoptions.py:128 +#: src/config/SSSDConfig/sssdoptions.py:127 msgid "Whether to hash host names and addresses in the known_hosts file" msgstr "" "known_hosts dosyasında ana bilgisayar adlarının ve adreslerinin karılıp " "karılmayacağı" -#: src/config/SSSDConfig/sssdoptions.py:129 +#: src/config/SSSDConfig/sssdoptions.py:128 msgid "" "How many seconds to keep a host in the known_hosts file after its host keys " "were requested" @@ -448,15 +460,15 @@ msgstr "" "Ana bilgisayar anahtarları istendikten sonra bir ana bilgisayarın " "known_hosts dosyasında kaç saniye tutulacağı" -#: src/config/SSSDConfig/sssdoptions.py:131 +#: src/config/SSSDConfig/sssdoptions.py:130 msgid "Path to storage of trusted CA certificates" msgstr "Güvenilir CA sertifikalarının depolanmasına giden yol" -#: src/config/SSSDConfig/sssdoptions.py:132 +#: src/config/SSSDConfig/sssdoptions.py:131 msgid "Allow to generate ssh-keys from certificates" msgstr "Sertifikalardan ssh anahtarları oluşturmaya izin ver" -#: src/config/SSSDConfig/sssdoptions.py:133 +#: src/config/SSSDConfig/sssdoptions.py:132 msgid "" "Use the following matching rules to filter the certificates for ssh-key " "generation" @@ -464,26 +476,26 @@ msgstr "" "Ssh anahtarı üretimi için sertifikaları süzmede aşağıdaki eşleştirme " "kurallarını kullanın" -#: src/config/SSSDConfig/sssdoptions.py:137 +#: src/config/SSSDConfig/sssdoptions.py:136 msgid "List of UIDs or user names allowed to access the PAC responder" msgstr "" "PAC yanıtlayıcısına erişmesine izin verilen UID'lerin veya kullanıcı " "adlarının listesi" -#: src/config/SSSDConfig/sssdoptions.py:138 +#: src/config/SSSDConfig/sssdoptions.py:137 msgid "How long the PAC data is considered valid" msgstr "PAC verilerinin ne kadar süreyle geçerli olduğu kabul edilir" -#: src/config/SSSDConfig/sssdoptions.py:139 +#: src/config/SSSDConfig/sssdoptions.py:138 msgid "Validate the PAC" msgstr "PAC'yi doğrulayın" -#: src/config/SSSDConfig/sssdoptions.py:142 +#: src/config/SSSDConfig/sssdoptions.py:141 msgid "List of user attributes the InfoPipe is allowed to publish" msgstr "" "InfoPipe'ın yayınlamasına izin verilen kullanıcı özniteliklerinin listesi" -#: src/config/SSSDConfig/sssdoptions.py:145 +#: src/config/SSSDConfig/sssdoptions.py:144 msgid "" "One of the following strings specifying the scope of session recording: none " "- No users are recorded. some - Users/groups specified by users and groups " @@ -494,7 +506,7 @@ msgstr "" "kullanıcılar/gruplar ve grup seçenekleri kaydedilir. all - Tüm kullanıcılar " "kaydedilir." -#: src/config/SSSDConfig/sssdoptions.py:148 +#: src/config/SSSDConfig/sssdoptions.py:147 msgid "" "A comma-separated list of users which should have session recording enabled. " "Matches user names as returned by NSS. I.e. after the possible space " @@ -504,7 +516,7 @@ msgstr "" "listesi. NSS tarafından döndürülen kullanıcı adlarıyla eşleşir. Yani olası " "alan değişiminden sonra, vaka değişiklikleri vb." -#: src/config/SSSDConfig/sssdoptions.py:150 +#: src/config/SSSDConfig/sssdoptions.py:149 msgid "" "A comma-separated list of groups, members of which should have session " "recording enabled. Matches group names as returned by NSS. I.e. after the " @@ -514,7 +526,7 @@ msgstr "" "grup listesi. NSS tarafından döndürülen grup adlarıyla eşleşir. Yani olası " "alan değişiminden sonra, vaka değişiklikleri vb." -#: src/config/SSSDConfig/sssdoptions.py:153 +#: src/config/SSSDConfig/sssdoptions.py:152 msgid "" "A comma-separated list of users to be excluded from recording, only when " "scope=all" @@ -522,7 +534,7 @@ msgstr "" "Yalnızca scope=all olduğunda kayıttan hariç tutulacak kullanıcıların " "virgülle ayrılmış listesi" -#: src/config/SSSDConfig/sssdoptions.py:154 +#: src/config/SSSDConfig/sssdoptions.py:153 msgid "" "A comma-separated list of groups, members of which should be excluded from " "recording, only when scope=all. " @@ -530,81 +542,81 @@ msgstr "" "Üyeleri yalnızca scope=all olduğunda kayıttan çıkarılması gereken virgülle " "ayrılmış grup listesi. " -#: src/config/SSSDConfig/sssdoptions.py:158 +#: src/config/SSSDConfig/sssdoptions.py:157 msgid "Identity provider" msgstr "Kimlik sağlayıcı" -#: src/config/SSSDConfig/sssdoptions.py:159 +#: src/config/SSSDConfig/sssdoptions.py:158 msgid "Authentication provider" msgstr "Kimlik doğrulama sağlayıcısı" -#: src/config/SSSDConfig/sssdoptions.py:160 +#: src/config/SSSDConfig/sssdoptions.py:159 msgid "Access control provider" msgstr "Erişim denetimi sağlayıcısı" -#: src/config/SSSDConfig/sssdoptions.py:161 +#: src/config/SSSDConfig/sssdoptions.py:160 msgid "Password change provider" msgstr "Parola değiştirme sağlayıcısı" -#: src/config/SSSDConfig/sssdoptions.py:162 +#: src/config/SSSDConfig/sssdoptions.py:161 msgid "SUDO provider" msgstr "SUDO sağlayıcısı" -#: src/config/SSSDConfig/sssdoptions.py:163 +#: src/config/SSSDConfig/sssdoptions.py:162 msgid "Autofs provider" msgstr "Autofs sağlayıcısı" -#: src/config/SSSDConfig/sssdoptions.py:164 +#: src/config/SSSDConfig/sssdoptions.py:163 msgid "Host identity provider" msgstr "Ana bilgisayar kimliği sağlayıcısı" -#: src/config/SSSDConfig/sssdoptions.py:165 +#: src/config/SSSDConfig/sssdoptions.py:164 msgid "SELinux provider" msgstr "SELinux sağlayıcısı" -#: src/config/SSSDConfig/sssdoptions.py:166 +#: src/config/SSSDConfig/sssdoptions.py:165 msgid "Session management provider" msgstr "Oturum yönetimi sağlayıcısı" -#: src/config/SSSDConfig/sssdoptions.py:167 +#: src/config/SSSDConfig/sssdoptions.py:166 msgid "Resolver provider" msgstr "Çözümleyici sağlayıcı" -#: src/config/SSSDConfig/sssdoptions.py:170 +#: src/config/SSSDConfig/sssdoptions.py:169 msgid "Whether the domain is usable by the OS or by applications" msgstr "" "Etki alanının işletim sistemi veya uygulamalar tarafından kullanılabilir " "olup olmadığı" -#: src/config/SSSDConfig/sssdoptions.py:171 +#: src/config/SSSDConfig/sssdoptions.py:170 msgid "Enable or disable the domain" msgstr "Etki alanını etkinleştirin veya devre dışı bırakın" -#: src/config/SSSDConfig/sssdoptions.py:172 +#: src/config/SSSDConfig/sssdoptions.py:171 msgid "Minimum user ID" msgstr "En düşük kullanıcı kimliği" -#: src/config/SSSDConfig/sssdoptions.py:173 +#: src/config/SSSDConfig/sssdoptions.py:172 msgid "Maximum user ID" msgstr "En yüksek kullanıcı kimliği" -#: src/config/SSSDConfig/sssdoptions.py:174 +#: src/config/SSSDConfig/sssdoptions.py:173 msgid "Enable enumerating all users/groups" msgstr "Tüm kullanıcıları/grupları numaralandırmayı etkinleştir" -#: src/config/SSSDConfig/sssdoptions.py:175 +#: src/config/SSSDConfig/sssdoptions.py:174 msgid "Cache credentials for offline login" msgstr "Çevrimdışı oturum açma için önbellek kimlik bilgileri" -#: src/config/SSSDConfig/sssdoptions.py:176 +#: src/config/SSSDConfig/sssdoptions.py:175 msgid "Display users/groups in fully-qualified form" msgstr "Kullanıcıları/grupları tam nitelikli(FQDN) biçimde görüntüleyin" -#: src/config/SSSDConfig/sssdoptions.py:177 +#: src/config/SSSDConfig/sssdoptions.py:176 msgid "Don't include group members in group lookups" msgstr "Grup aramalarına grup üyelerini dahil etme" -#: src/config/SSSDConfig/sssdoptions.py:178 +#: src/config/SSSDConfig/sssdoptions.py:177 #: src/config/SSSDConfig/sssdoptions.py:190 #: src/config/SSSDConfig/sssdoptions.py:191 #: src/config/SSSDConfig/sssdoptions.py:192 @@ -615,20 +627,20 @@ msgstr "Grup aramalarına grup üyelerini dahil etme" msgid "Entry cache timeout length (seconds)" msgstr "Girdi önbelleği zaman aşımı uzunluğu (saniye)" -#: src/config/SSSDConfig/sssdoptions.py:179 +#: src/config/SSSDConfig/sssdoptions.py:178 msgid "" "Restrict or prefer a specific address family when performing DNS lookups" msgstr "" "DNS aramaları gerçekleştirirken belirli bir adres ailesini kısıtlayın veya " "tercih edin" -#: src/config/SSSDConfig/sssdoptions.py:180 +#: src/config/SSSDConfig/sssdoptions.py:179 msgid "How long to keep cached entries after last successful login (days)" msgstr "" "Son başarılı oturum açma işleminden sonra önbelleğe alınmış girişlerin ne " "kadar süreyle saklanacağı (gün)" -#: src/config/SSSDConfig/sssdoptions.py:181 +#: src/config/SSSDConfig/sssdoptions.py:180 msgid "" "How long should SSSD talk to single DNS server before trying next server " "(miliseconds)" @@ -636,20 +648,20 @@ msgstr "" "SSSD, bir sonraki sunucuyu denemeden önce tek DNS sunucusuyla ne kadar " "konuşmalı (milisaniye)" -#: src/config/SSSDConfig/sssdoptions.py:183 +#: src/config/SSSDConfig/sssdoptions.py:182 msgid "How long should keep trying to resolve single DNS query (seconds)" msgstr "Tek bir DNS sorgusunu çözmeye ne kadar süre devam etmeli (saniye)" -#: src/config/SSSDConfig/sssdoptions.py:184 +#: src/config/SSSDConfig/sssdoptions.py:183 msgid "How long to wait for replies from DNS when resolving servers (seconds)" msgstr "" "Sunucuları çözümlerken DNS'den gelen yanıtların ne kadar bekleneceği (saniye)" -#: src/config/SSSDConfig/sssdoptions.py:185 +#: src/config/SSSDConfig/sssdoptions.py:184 msgid "The domain part of service discovery DNS query" msgstr "Hizmet keşfi DNS sorgusunun etki alanı kısmı" -#: src/config/SSSDConfig/sssdoptions.py:186 +#: src/config/SSSDConfig/sssdoptions.py:185 msgid "" "Specifies the interval, in seconds, that SSSD waits before attempting to " "reconnect to the primary server after a successful connection to the backup " @@ -659,14 +671,18 @@ msgstr "" "sunucuya yeniden bağlanmayı denemeden önce bekleyeceği aralığı saniye " "cinsinden belirtir" -#: src/config/SSSDConfig/sssdoptions.py:188 +#: src/config/SSSDConfig/sssdoptions.py:187 msgid "Override GID value from the identity provider with this value" msgstr "Kimlik sağlayıcıdan alınan GID değerini bu değerle geçersiz kıl" -#: src/config/SSSDConfig/sssdoptions.py:189 +#: src/config/SSSDConfig/sssdoptions.py:188 msgid "Treat usernames as case sensitive" msgstr "Kullanıcı adlarını büyük/küçük harfe duyarlı olarak ele alın" +#: src/config/SSSDConfig/sssdoptions.py:189 +msgid "Lookups by ID are expensive or do not work at all" +msgstr "" + #: src/config/SSSDConfig/sssdoptions.py:197 msgid "How often should expired entries be refreshed in background" msgstr "Süresi dolan girişler arka planda ne sıklıkla yenilenmelidir" @@ -916,7 +932,7 @@ msgid "Search base for SUBID ranges" msgstr "SUBID aralıkları için arama tabanı" #: src/config/SSSDConfig/sssdoptions.py:259 -#: src/config/SSSDConfig/sssdoptions.py:506 +#: src/config/SSSDConfig/sssdoptions.py:512 msgid "Which rules should be used to evaluate access control" msgstr "Erişim denetimini değerlendirmek için hangi kurallar kullanılmalıdır" @@ -1010,7 +1026,8 @@ msgstr "" #: src/config/SSSDConfig/sssdoptions.py:281 msgid "" "The LDAP attribute that contains all users / groups this rule match against." -msgstr "Bu kuralın eşleştiği tüm kullanıcıları/grupları içeren LDAP özniteliği." +msgstr "" +"Bu kuralın eşleştiği tüm kullanıcıları/grupları içeren LDAP özniteliği." #: src/config/SSSDConfig/sssdoptions.py:283 msgid "The LDAP attribute that contains the name of SELinux usermap." @@ -1075,7 +1092,7 @@ msgid "Enable DNS sites - location based service discovery" msgstr "DNS sitelerini etkinleştirin - konuma dayalı hizmet keşfi" #: src/config/SSSDConfig/sssdoptions.py:301 -#: src/config/SSSDConfig/sssdoptions.py:504 +#: src/config/SSSDConfig/sssdoptions.py:510 msgid "LDAP filter to determine access privileges" msgstr "Erişim ayrıcalıklarını belirlemek için LDAP süzgeci" @@ -1512,7 +1529,7 @@ msgid "UUID attribute" msgstr "UUID özniteliği" #: src/config/SSSDConfig/sssdoptions.py:423 -#: src/config/SSSDConfig/sssdoptions.py:464 +#: src/config/SSSDConfig/sssdoptions.py:470 msgid "objectSID attribute" msgstr "objectSID özniteliği" @@ -1638,177 +1655,206 @@ msgstr "kullanıcının parola eşleme verilerini içeren öznitelik" msgid "A list of extra attributes to download along with the user entry" msgstr "Kullanıcı girişi ile birlikte indirilecek ek özniteliklerin listesi" +#: src/config/SSSDConfig/sssdoptions.py:456 +#, fuzzy +msgid "The object class of an subid entry in LDAP." +msgstr "LDAP'daki bir ana bilgisayar girdisinin nesne sınıfı." + #: src/config/SSSDConfig/sssdoptions.py:457 +#, fuzzy +msgid "Subordinate user ID count attribute" +msgstr "Sudo kuralı kullanıcı(user) özniteliği" + +#: src/config/SSSDConfig/sssdoptions.py:458 +#, fuzzy +msgid "Subordinate group ID count attribute" +msgstr "Sudo kuralı seçenek(option) özniteliği" + +#: src/config/SSSDConfig/sssdoptions.py:459 +#, fuzzy +msgid "User ID range start value attribute" +msgstr "Kullanıcı adı özniteliği" + +#: src/config/SSSDConfig/sssdoptions.py:460 +#, fuzzy +msgid "Group ID range start value attribute" +msgstr "Grup UUID özniteliği" + +#: src/config/SSSDConfig/sssdoptions.py:461 +msgid "Owner of an entry" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:463 msgid "Base DN for group lookups" msgstr "Grup aramaları için taban DN" -#: src/config/SSSDConfig/sssdoptions.py:458 +#: src/config/SSSDConfig/sssdoptions.py:464 msgid "Objectclass for groups" msgstr "Gruplar için nesne sınıfı" -#: src/config/SSSDConfig/sssdoptions.py:459 +#: src/config/SSSDConfig/sssdoptions.py:465 msgid "Group name" msgstr "Grup adı" -#: src/config/SSSDConfig/sssdoptions.py:460 +#: src/config/SSSDConfig/sssdoptions.py:466 msgid "Group password" msgstr "Grup parolası" -#: src/config/SSSDConfig/sssdoptions.py:461 +#: src/config/SSSDConfig/sssdoptions.py:467 msgid "GID attribute" msgstr "GID özniteliği" -#: src/config/SSSDConfig/sssdoptions.py:462 +#: src/config/SSSDConfig/sssdoptions.py:468 msgid "Group member attribute" msgstr "Grup üyesi özniteliği" -#: src/config/SSSDConfig/sssdoptions.py:463 +#: src/config/SSSDConfig/sssdoptions.py:469 msgid "Group UUID attribute" msgstr "Grup UUID özniteliği" -#: src/config/SSSDConfig/sssdoptions.py:465 +#: src/config/SSSDConfig/sssdoptions.py:471 msgid "Modification time attribute for groups" msgstr "Gruplar için değişiklik zamanı özniteliği" -#: src/config/SSSDConfig/sssdoptions.py:466 +#: src/config/SSSDConfig/sssdoptions.py:472 msgid "Type of the group and other flags" msgstr "Grubun türü ve diğer bayraklar" -#: src/config/SSSDConfig/sssdoptions.py:467 +#: src/config/SSSDConfig/sssdoptions.py:473 msgid "The LDAP group external member attribute" msgstr "LDAP grubu harici üye özniteliği" -#: src/config/SSSDConfig/sssdoptions.py:468 +#: src/config/SSSDConfig/sssdoptions.py:474 msgid "Maximum nesting level SSSD will follow" msgstr "SSSD'nin izleyeceği azami yuvalama seviyesi" -#: src/config/SSSDConfig/sssdoptions.py:469 +#: src/config/SSSDConfig/sssdoptions.py:475 msgid "Filter for group lookups" msgstr "Grup aramaları için süzgeç" -#: src/config/SSSDConfig/sssdoptions.py:470 +#: src/config/SSSDConfig/sssdoptions.py:476 msgid "Scope of group lookups" msgstr "Grup aramalarının kapsamı" -#: src/config/SSSDConfig/sssdoptions.py:472 +#: src/config/SSSDConfig/sssdoptions.py:478 msgid "Base DN for netgroup lookups" msgstr "Ağ grubu aramaları için taban DN" -#: src/config/SSSDConfig/sssdoptions.py:473 +#: src/config/SSSDConfig/sssdoptions.py:479 msgid "Objectclass for netgroups" msgstr "Ağ grupları için nesne sınıfı" -#: src/config/SSSDConfig/sssdoptions.py:474 +#: src/config/SSSDConfig/sssdoptions.py:480 msgid "Netgroup name" msgstr "Ağ grubu adı" -#: src/config/SSSDConfig/sssdoptions.py:475 +#: src/config/SSSDConfig/sssdoptions.py:481 msgid "Netgroups members attribute" msgstr "Ağ grupları üyeleri özniteliği" -#: src/config/SSSDConfig/sssdoptions.py:476 +#: src/config/SSSDConfig/sssdoptions.py:482 msgid "Netgroup triple attribute" msgstr "Ağ grubu üçlü özniteliği" -#: src/config/SSSDConfig/sssdoptions.py:477 +#: src/config/SSSDConfig/sssdoptions.py:483 msgid "Modification time attribute for netgroups" msgstr "Ağ grupları için değişiklik zamanı özniteliği" -#: src/config/SSSDConfig/sssdoptions.py:479 +#: src/config/SSSDConfig/sssdoptions.py:485 msgid "Base DN for service lookups" msgstr "Hizmet aramaları için taban DN" -#: src/config/SSSDConfig/sssdoptions.py:480 +#: src/config/SSSDConfig/sssdoptions.py:486 msgid "Objectclass for services" msgstr "Hizmetler için nesne sınıfı" -#: src/config/SSSDConfig/sssdoptions.py:481 +#: src/config/SSSDConfig/sssdoptions.py:487 msgid "Service name attribute" msgstr "Hizmet adı özniteliği" -#: src/config/SSSDConfig/sssdoptions.py:482 +#: src/config/SSSDConfig/sssdoptions.py:488 msgid "Service port attribute" msgstr "Hizmet bağlantı noktası özniteliği" -#: src/config/SSSDConfig/sssdoptions.py:483 +#: src/config/SSSDConfig/sssdoptions.py:489 msgid "Service protocol attribute" msgstr "Hizmet protokolü özniteliği" -#: src/config/SSSDConfig/sssdoptions.py:485 +#: src/config/SSSDConfig/sssdoptions.py:491 msgid "Lower bound for ID-mapping" msgstr "Kimlik eşleme için alt sınır" -#: src/config/SSSDConfig/sssdoptions.py:486 +#: src/config/SSSDConfig/sssdoptions.py:492 msgid "Upper bound for ID-mapping" msgstr "Kimlik eşleme için üst sınır" -#: src/config/SSSDConfig/sssdoptions.py:487 +#: src/config/SSSDConfig/sssdoptions.py:493 msgid "Number of IDs for each slice when ID-mapping" msgstr "Kimlik eşlemesi yapılırken her dilim için kimlik sayısı" -#: src/config/SSSDConfig/sssdoptions.py:488 +#: src/config/SSSDConfig/sssdoptions.py:494 msgid "Use autorid-compatible algorithm for ID-mapping" msgstr "Kimlik eşleme için otomatik kimlik eşleme uyumlu algoritmayı kullanın" -#: src/config/SSSDConfig/sssdoptions.py:489 +#: src/config/SSSDConfig/sssdoptions.py:495 msgid "Name of the default domain for ID-mapping" msgstr "Kimlik eşlemesi için varsayılan etki alanının adı" -#: src/config/SSSDConfig/sssdoptions.py:490 +#: src/config/SSSDConfig/sssdoptions.py:496 msgid "SID of the default domain for ID-mapping" msgstr "Kimlik eşleme için varsayılan etki alanının SID'si" -#: src/config/SSSDConfig/sssdoptions.py:491 +#: src/config/SSSDConfig/sssdoptions.py:497 msgid "Number of secondary slices" msgstr "İkincil dilim sayısı" -#: src/config/SSSDConfig/sssdoptions.py:493 +#: src/config/SSSDConfig/sssdoptions.py:499 msgid "Whether to use Token-Groups" msgstr "Belirteç Gruplarının(Token-Groups) kullanılıp kullanılmayacağı" -#: src/config/SSSDConfig/sssdoptions.py:494 +#: src/config/SSSDConfig/sssdoptions.py:500 msgid "Set lower boundary for allowed IDs from the LDAP server" msgstr "LDAP sunucusundan izin verilen kimlikler için alt sınır belirleme" -#: src/config/SSSDConfig/sssdoptions.py:495 +#: src/config/SSSDConfig/sssdoptions.py:501 msgid "Set upper boundary for allowed IDs from the LDAP server" msgstr "LDAP sunucusundan izin verilen kimlikler için üst sınır belirleme" -#: src/config/SSSDConfig/sssdoptions.py:496 +#: src/config/SSSDConfig/sssdoptions.py:502 msgid "DN for ppolicy queries" msgstr "Parola ilkesi sorguları için DN" -#: src/config/SSSDConfig/sssdoptions.py:497 +#: src/config/SSSDConfig/sssdoptions.py:503 msgid "How many maximum entries to fetch during a wildcard request" msgstr "Bir joker karakter isteği sırasında alınacak azami girdi sayısı" -#: src/config/SSSDConfig/sssdoptions.py:498 +#: src/config/SSSDConfig/sssdoptions.py:504 msgid "Set libldap debug level" msgstr "libldap hata ayıklama düzeyini ayarla" -#: src/config/SSSDConfig/sssdoptions.py:501 +#: src/config/SSSDConfig/sssdoptions.py:507 msgid "Policy to evaluate the password expiration" msgstr "Parola süresinin dolmasını değerlendirme ilkesi" -#: src/config/SSSDConfig/sssdoptions.py:505 +#: src/config/SSSDConfig/sssdoptions.py:511 msgid "Which attributes shall be used to evaluate if an account is expired" msgstr "" "Bir hesabın süresinin dolup dolmadığını değerlendirmek için hangi " "öznitelikler kullanılır" -#: src/config/SSSDConfig/sssdoptions.py:509 +#: src/config/SSSDConfig/sssdoptions.py:515 msgid "URI of an LDAP server where password changes are allowed" msgstr "Parola değişikliklerine izin verilen bir LDAP sunucusunun URI'si" -#: src/config/SSSDConfig/sssdoptions.py:510 +#: src/config/SSSDConfig/sssdoptions.py:516 msgid "URI of a backup LDAP server where password changes are allowed" msgstr "Parola değişikliklerine izin verilen bir yedek LDAP sunucusunun URI'si" -#: src/config/SSSDConfig/sssdoptions.py:511 +#: src/config/SSSDConfig/sssdoptions.py:517 msgid "DNS service name for LDAP password change server" msgstr "LDAP parola değiştirme sunucusu için DNS hizmet adı" -#: src/config/SSSDConfig/sssdoptions.py:512 +#: src/config/SSSDConfig/sssdoptions.py:518 msgid "" "Whether to update the ldap_user_shadow_last_change attribute after a " "password change" @@ -1816,29 +1862,29 @@ msgstr "" "Parola değişikliğinden sonra ldap_user_shadow_last_change özniteliğinin " "güncelleştirilip güncelleştirilmeyeceği" -#: src/config/SSSDConfig/sssdoptions.py:516 +#: src/config/SSSDConfig/sssdoptions.py:522 msgid "Base DN for sudo rules lookups" msgstr "Sudo kuralları aramaları için taban DN" -#: src/config/SSSDConfig/sssdoptions.py:517 +#: src/config/SSSDConfig/sssdoptions.py:523 msgid "Automatic full refresh period" msgstr "Otomatik tam yenileme süresi" -#: src/config/SSSDConfig/sssdoptions.py:518 +#: src/config/SSSDConfig/sssdoptions.py:524 msgid "Automatic smart refresh period" msgstr "Otomatik akıllı yenileme süresi" -#: src/config/SSSDConfig/sssdoptions.py:519 +#: src/config/SSSDConfig/sssdoptions.py:525 msgid "Smart and full refresh random offset" msgstr "Akıllı ve tam yenileme rastgele aralığı" -#: src/config/SSSDConfig/sssdoptions.py:520 +#: src/config/SSSDConfig/sssdoptions.py:526 msgid "Whether to filter rules by hostname, IP addresses and network" msgstr "" "Kuralların ana bilgisayar adına, IP adreslerine ve ağa göre süzülüp " "süzülmeyeceği" -#: src/config/SSSDConfig/sssdoptions.py:521 +#: src/config/SSSDConfig/sssdoptions.py:527 msgid "" "Hostnames and/or fully qualified domain names of this machine to filter sudo " "rules" @@ -1846,153 +1892,153 @@ msgstr "" "Sudo kurallarını süzmek için bu makinenin ana bilgisayar adları ve/veya tam " "etki alanı adları(FQDN)" -#: src/config/SSSDConfig/sssdoptions.py:522 +#: src/config/SSSDConfig/sssdoptions.py:528 msgid "IPv4 or IPv6 addresses or network of this machine to filter sudo rules" msgstr "" "Sudo kurallarını süzmek için IPv4 veya IPv6 adresleri veya bu makinenin ağı" -#: src/config/SSSDConfig/sssdoptions.py:523 +#: src/config/SSSDConfig/sssdoptions.py:529 msgid "Whether to include rules that contains netgroup in host attribute" msgstr "" "Ana bilgisayar özniteliğine ağ grubu içeren kuralların dahil edilip " "edilmeyeceği" -#: src/config/SSSDConfig/sssdoptions.py:524 +#: src/config/SSSDConfig/sssdoptions.py:530 msgid "" "Whether to include rules that contains regular expression in host attribute" msgstr "" "Ana bilgisayar özniteliğinde düzenli ifade içeren kuralların dahil edilip " "edilmeyeceği" -#: src/config/SSSDConfig/sssdoptions.py:525 +#: src/config/SSSDConfig/sssdoptions.py:531 msgid "Object class for sudo rules" msgstr "Sudo kuralları için nesne sınıfı" -#: src/config/SSSDConfig/sssdoptions.py:526 +#: src/config/SSSDConfig/sssdoptions.py:532 msgid "Name of attribute that is used as object class for sudo rules" msgstr "Sudo kuralları için nesne sınıfı olarak kullanılan özniteliğin adı" -#: src/config/SSSDConfig/sssdoptions.py:527 +#: src/config/SSSDConfig/sssdoptions.py:533 msgid "Sudo rule name" msgstr "Sudo kural adı" -#: src/config/SSSDConfig/sssdoptions.py:528 +#: src/config/SSSDConfig/sssdoptions.py:534 msgid "Sudo rule command attribute" msgstr "Sudo kuralı komut(command) özniteliği" -#: src/config/SSSDConfig/sssdoptions.py:529 +#: src/config/SSSDConfig/sssdoptions.py:535 msgid "Sudo rule host attribute" msgstr "Sudo kuralı ana bilgisayar(host) özniteliği" -#: src/config/SSSDConfig/sssdoptions.py:530 +#: src/config/SSSDConfig/sssdoptions.py:536 msgid "Sudo rule user attribute" msgstr "Sudo kuralı kullanıcı(user) özniteliği" -#: src/config/SSSDConfig/sssdoptions.py:531 +#: src/config/SSSDConfig/sssdoptions.py:537 msgid "Sudo rule option attribute" msgstr "Sudo kuralı seçenek(option) özniteliği" -#: src/config/SSSDConfig/sssdoptions.py:532 +#: src/config/SSSDConfig/sssdoptions.py:538 msgid "Sudo rule runas attribute" msgstr "Sudo kuralı farklı çalıştır(runas) özniteliği" -#: src/config/SSSDConfig/sssdoptions.py:533 +#: src/config/SSSDConfig/sssdoptions.py:539 msgid "Sudo rule runasuser attribute" msgstr "Sudo kuralı farklı kullanıcı ile çalıştır(runasuser) özniteliği" -#: src/config/SSSDConfig/sssdoptions.py:534 +#: src/config/SSSDConfig/sssdoptions.py:540 msgid "Sudo rule runasgroup attribute" msgstr "Sudo kuralı farklı grup ile çalıştır(runasgroup) özniteliği" -#: src/config/SSSDConfig/sssdoptions.py:535 +#: src/config/SSSDConfig/sssdoptions.py:541 msgid "Sudo rule notbefore attribute" msgstr "Sudo kuralı önce değil(notbefore) özniteliği" -#: src/config/SSSDConfig/sssdoptions.py:536 +#: src/config/SSSDConfig/sssdoptions.py:542 msgid "Sudo rule notafter attribute" msgstr "Sudo kuralı sonra değil(notafter) özniteliği" -#: src/config/SSSDConfig/sssdoptions.py:537 +#: src/config/SSSDConfig/sssdoptions.py:543 msgid "Sudo rule order attribute" msgstr "Sudo kuralı sıra(order) özniteliği" -#: src/config/SSSDConfig/sssdoptions.py:540 +#: src/config/SSSDConfig/sssdoptions.py:546 msgid "Object class for automounter maps" msgstr "Otomatik bağlayıcı eşlemeleri için nesne sınıfı" -#: src/config/SSSDConfig/sssdoptions.py:541 +#: src/config/SSSDConfig/sssdoptions.py:547 msgid "Automounter map name attribute" msgstr "Otomatik bağlayıcı eşleme adı özniteliği" -#: src/config/SSSDConfig/sssdoptions.py:542 +#: src/config/SSSDConfig/sssdoptions.py:548 msgid "Object class for automounter map entries" msgstr "Otomatik bağlayıcı eşleme girdileri için nesne sınıfı" -#: src/config/SSSDConfig/sssdoptions.py:543 +#: src/config/SSSDConfig/sssdoptions.py:549 msgid "Automounter map entry key attribute" msgstr "Otomatik bağlayıcı eşleme girdisi anahtar özniteliği" -#: src/config/SSSDConfig/sssdoptions.py:544 +#: src/config/SSSDConfig/sssdoptions.py:550 msgid "Automounter map entry value attribute" msgstr "Otomatik bağlayıcı eşleme girdisi değeri özniteliği" -#: src/config/SSSDConfig/sssdoptions.py:545 +#: src/config/SSSDConfig/sssdoptions.py:551 msgid "Base DN for automounter map lookups" msgstr "Otomatik bağlayıcı eşleme aramaları için taban DN" -#: src/config/SSSDConfig/sssdoptions.py:546 +#: src/config/SSSDConfig/sssdoptions.py:552 msgid "The name of the automount master map in LDAP." msgstr "LDAP'deki otomatik bağlama ana eşlemesinin adı." -#: src/config/SSSDConfig/sssdoptions.py:549 +#: src/config/SSSDConfig/sssdoptions.py:555 msgid "Base DN for IP hosts lookups" msgstr "IP ana bilgisayar aramaları için taban DN" -#: src/config/SSSDConfig/sssdoptions.py:550 +#: src/config/SSSDConfig/sssdoptions.py:556 msgid "Object class for IP hosts" msgstr "IP ana bilgisayarları için nesne sınıfı" -#: src/config/SSSDConfig/sssdoptions.py:551 +#: src/config/SSSDConfig/sssdoptions.py:557 msgid "IP host name attribute" msgstr "IP ana bilgisayar adı özniteliği" -#: src/config/SSSDConfig/sssdoptions.py:552 +#: src/config/SSSDConfig/sssdoptions.py:558 msgid "IP host number (address) attribute" msgstr "IP ana bilgisayar numarası (address) özniteliği" -#: src/config/SSSDConfig/sssdoptions.py:553 +#: src/config/SSSDConfig/sssdoptions.py:559 msgid "IP host entryUSN attribute" msgstr "IP ana bilgisayar entryUSN özniteliği" -#: src/config/SSSDConfig/sssdoptions.py:554 +#: src/config/SSSDConfig/sssdoptions.py:560 msgid "Base DN for IP networks lookups" msgstr "IP ağları aramaları için taban DN" -#: src/config/SSSDConfig/sssdoptions.py:555 +#: src/config/SSSDConfig/sssdoptions.py:561 msgid "Object class for IP networks" msgstr "IP ağları için nesne sınıfı" -#: src/config/SSSDConfig/sssdoptions.py:556 +#: src/config/SSSDConfig/sssdoptions.py:562 msgid "IP network name attribute" msgstr "IP ağ adı özniteliği" -#: src/config/SSSDConfig/sssdoptions.py:557 +#: src/config/SSSDConfig/sssdoptions.py:563 msgid "IP network number (address) attribute" msgstr "IP ağ numarası (address) özelliği" -#: src/config/SSSDConfig/sssdoptions.py:558 +#: src/config/SSSDConfig/sssdoptions.py:564 msgid "IP network entryUSN attribute" msgstr "IP ağ entryUSN özniteliği" -#: src/config/SSSDConfig/sssdoptions.py:561 +#: src/config/SSSDConfig/sssdoptions.py:567 msgid "Comma separated list of allowed users" msgstr "İzin verilen kullanıcıların virgülle ayrılmış listesi" -#: src/config/SSSDConfig/sssdoptions.py:562 +#: src/config/SSSDConfig/sssdoptions.py:568 msgid "Comma separated list of prohibited users" msgstr "Yasaklanmış kullanıcıların virgülle ayrılmış listesi" -#: src/config/SSSDConfig/sssdoptions.py:563 +#: src/config/SSSDConfig/sssdoptions.py:569 msgid "" "Comma separated list of groups that are allowed to log in. This applies only " "to groups within this SSSD domain. Local groups are not evaluated." @@ -2001,7 +2047,7 @@ msgstr "" "yalnızca bu SSSD etki alanındaki gruplar için geçerlidir. Yerel gruplar " "değerlendirilmez." -#: src/config/SSSDConfig/sssdoptions.py:565 +#: src/config/SSSDConfig/sssdoptions.py:571 msgid "" "Comma separated list of groups that are explicitly denied access. This " "applies only to groups within this SSSD domain. Local groups are not " @@ -2011,32 +2057,32 @@ msgstr "" "bu SSSD etki alanındaki gruplar için geçerlidir. Yerel gruplar " "değerlendirilmez." -#: src/config/SSSDConfig/sssdoptions.py:569 +#: src/config/SSSDConfig/sssdoptions.py:575 msgid "The number of preforked proxy children." msgstr "Önceden çatallanmış vekil alt öğelerinin sayısı." -#: src/config/SSSDConfig/sssdoptions.py:572 +#: src/config/SSSDConfig/sssdoptions.py:578 msgid "The name of the NSS library to use" msgstr "Kullanılacak NSS kitaplığının adı" -#: src/config/SSSDConfig/sssdoptions.py:573 +#: src/config/SSSDConfig/sssdoptions.py:579 msgid "The name of the NSS library to use for hosts and networks lookups" msgstr "" "Ana bilgisayarlar ve ağ aramaları için kullanılacak NSS kitaplığının adı" -#: src/config/SSSDConfig/sssdoptions.py:574 +#: src/config/SSSDConfig/sssdoptions.py:580 msgid "Whether to look up canonical group name from cache if possible" msgstr "Mümkünse önbellekten standart grup adının aranıp aranmayacağı" -#: src/config/SSSDConfig/sssdoptions.py:577 +#: src/config/SSSDConfig/sssdoptions.py:583 msgid "PAM stack to use" msgstr "Kullanılacak PAM yığını" -#: src/config/SSSDConfig/sssdoptions.py:580 +#: src/config/SSSDConfig/sssdoptions.py:586 msgid "Path of passwd file sources." msgstr "Parola dosya kaynaklarının yolu." -#: src/config/SSSDConfig/sssdoptions.py:581 +#: src/config/SSSDConfig/sssdoptions.py:587 msgid "Path of group file sources." msgstr "Grup dosya kaynaklarının yolu." @@ -2067,108 +2113,112 @@ msgstr "" msgid "Option -i|--interactive is not allowed together with -D|--daemon\n" msgstr "-i|--interactive seçeneğine -D|--daemon ile birlikte izin verilmez\n" -#: src/monitor/monitor.c:1836 +#: src/monitor/monitor.c:1838 msgid "Failed to get initial capabilities\n" msgstr "Başlangıç yetenekleri alınamadı\n" -#: src/monitor/monitor.c:1847 +#: src/monitor/monitor.c:1849 msgid "Non-root service user support isn't built. Can't run under %" msgstr "" "Yetkili (root) olmayan hizmet kullanıcısı desteği oluşturulmadı. % altında " "çalıştırılamaz" -#: src/monitor/monitor.c:1864 +#: src/monitor/monitor.c:1866 #, c-format msgid "Can't read config: '%s'\n" msgstr "Yapılandırma okunamıyor: '%s'\n" -#: src/monitor/monitor.c:1876 -#, c-format -msgid "Failed to boostrap SSSD 'monitor' process: %s" +#: src/monitor/monitor.c:1878 +#, fuzzy, c-format +msgid "Failed to bootstrap SSSD 'monitor' process: %s" msgstr "SSSD 'monitor' işlemi başlatılamadı: %s" -#: src/monitor/monitor.c:1971 +#: src/monitor/monitor.c:1973 msgid "Out of memory\n" msgstr "Yetersiz bellek!\n" -#: src/providers/krb5/krb5_child.c:4221 +#: src/providers/krb5/krb5_child.c:4316 msgid "Use anonymous PKINIT to request FAST armor ticket" msgstr "FAST kimlik bilgilerini istemek için anonim PKINIT kullanın" -#: src/providers/krb5/krb5_child.c:4223 +#: src/providers/krb5/krb5_child.c:4318 msgid "Kerberos realm to use" msgstr "Kullanılacak Kerberos bölgesi" -#: src/providers/krb5/krb5_child.c:4225 +#: src/providers/krb5/krb5_child.c:4320 msgid "Requested lifetime of the ticket" msgstr "Biletin talep edilen kullanım ömrü" -#: src/providers/krb5/krb5_child.c:4227 +#: src/providers/krb5/krb5_child.c:4322 msgid "Requested renewable lifetime of the ticket" msgstr "Biletin talep edilen yenilenebilir kullanım ömrü" -#: src/providers/krb5/krb5_child.c:4229 +#: src/providers/krb5/krb5_child.c:4324 msgid "FAST options ('never', 'try', 'demand')" msgstr "FAST seçenekleri ('never', 'try', 'demand')" -#: src/providers/krb5/krb5_child.c:4232 +#: src/providers/krb5/krb5_child.c:4327 msgid "Specifies the server principal to use for FAST" msgstr "FAST için kullanılacak sunucu sorumlusunu belirtir" -#: src/providers/krb5/krb5_child.c:4234 +#: src/providers/krb5/krb5_child.c:4329 msgid "Requests canonicalization of the principal name" msgstr "Ana adın standartlaştırılmasını ister" -#: src/providers/krb5/krb5_child.c:4236 +#: src/providers/krb5/krb5_child.c:4331 msgid "Use custom version of krb5_get_init_creds_password" msgstr "krb5_get_init_creds_password'ün özel sürümünü kullanın" -#: src/providers/krb5/krb5_child.c:4238 +#: src/providers/krb5/krb5_child.c:4333 msgid "Check PAC flags" msgstr "PAC bayraklarını denetleyin" -#: src/providers/data_provider_be.c:790 +#: src/providers/krb5/krb5_child.c:4335 +msgid "Set environment variable (KEY=VALUE)" +msgstr "" + +#: src/providers/data_provider_be.c:786 msgid "Domain of the information provider (mandatory)" msgstr "Bilgi sağlayıcısının etki alanı (zorunlu)" -#: src/sss_client/common.c:1165 +#: src/sss_client/common.c:1208 msgid "Socket has wrong ownership or permissions." msgstr "Yuva (soket) yanlış sahiplik veya izinlere sahip." -#: src/sss_client/common.c:1168 +#: src/sss_client/common.c:1211 msgid "Unexpected format of the server credential message." msgstr "Sunucu kimlik bilgisi iletisinin beklenmeyen biçimi." -#: src/sss_client/common.c:1171 +#: src/sss_client/common.c:1214 msgid "SSSD is not run by trusted user." msgstr "SSSD güvenilir kullanıcı tarafından çalıştırılmıyor." -#: src/sss_client/common.c:1174 +#: src/sss_client/common.c:1217 msgid "SSSD socket does not exist." msgstr "SSSD yuvası(socket) mevcut değil." -#: src/sss_client/common.c:1177 +#: src/sss_client/common.c:1220 msgid "Cannot get stat of SSSD socket." msgstr "SSSD yuvasının(socket) istatistiği alınamıyor." -#: src/sss_client/common.c:1182 +#: src/sss_client/common.c:1225 msgid "An error occurred, but no description can be found." msgstr "Bir hata oluştu, ancak açıklama bulunamadı." -#: src/sss_client/common.c:1188 +#: src/sss_client/common.c:1231 msgid "Unexpected error while looking for an error description" msgstr "Hata açıklaması aranırken beklenmeyen hata" -#: src/sss_client/pam_sss.c:74 +#: src/sss_client/pam_sss.c:135 msgid "Permission denied. " msgstr "İzin reddedildi. " -#: src/sss_client/pam_sss.c:75 src/sss_client/pam_sss.c:843 -#: src/sss_client/pam_sss.c:854 +#: src/sss_client/pam_sss.c:136 src/sss_client/pam_sss.c:921 +#: src/sss_client/pam_sss.c:932 msgid "Server message: " msgstr "Sunucu iletisi: " -#: src/sss_client/pam_sss.c:76 +#: src/sss_client/pam_sss.c:137 msgid "" "Kerberos TGT will not be granted upon login, user experience will be " "affected." @@ -2176,50 +2226,50 @@ msgstr "" "Kerberos TGT oturum açma sırasında verilmeyecek, kullanıcı deneyimi " "etkilenecektir." -#: src/sss_client/pam_sss.c:77 +#: src/sss_client/pam_sss.c:138 msgid "Enter PIN:" msgstr "PIN girin:" -#: src/sss_client/pam_sss.c:320 +#: src/sss_client/pam_sss.c:385 msgid "Passwords do not match" msgstr "Parolalar eşleşmiyor" -#: src/sss_client/pam_sss.c:508 +#: src/sss_client/pam_sss.c:584 msgid "Password reset by root is not supported." msgstr "Yönetici tarafından parola sıfırlama desteklenmez." -#: src/sss_client/pam_sss.c:549 +#: src/sss_client/pam_sss.c:625 msgid "Authenticated with cached credentials" msgstr "Önbelleğe alınmış kimlik bilgileriyle doğrulandı" -#: src/sss_client/pam_sss.c:550 +#: src/sss_client/pam_sss.c:626 msgid ", your cached password will expire at: " msgstr ", önbelleğe alınmış parolanızın süresi şu tarihte sona erecek: " -#: src/sss_client/pam_sss.c:580 +#: src/sss_client/pam_sss.c:656 #, c-format msgid "Your password has expired. You have %1$d grace login(s) remaining." msgstr "Parolanızın süresi doldu. %1$d ek oturum açma hakkınız kaldı." -#: src/sss_client/pam_sss.c:630 +#: src/sss_client/pam_sss.c:706 #, c-format msgid "Your password will expire in %1$d %2$s." msgstr "Parolanızın süresi %1$d %2$s içinde dolacak." -#: src/sss_client/pam_sss.c:633 +#: src/sss_client/pam_sss.c:709 #, c-format msgid "Your password has expired." msgstr "Parolanızın süresi doldu." -#: src/sss_client/pam_sss.c:684 +#: src/sss_client/pam_sss.c:760 msgid "Authentication is denied until: " msgstr "Kimlik doğrulama şu ana kadar reddedilir: " -#: src/sss_client/pam_sss.c:705 +#: src/sss_client/pam_sss.c:781 msgid "System is offline, password change not possible" msgstr "Sistem çevrimdışı, şifre değişikliği mümkün değil" -#: src/sss_client/pam_sss.c:720 +#: src/sss_client/pam_sss.c:796 msgid "" "After changing the OTP password, you need to log out and back in order to " "acquire a ticket" @@ -2227,11 +2277,11 @@ msgstr "" "OTP şifresini değiştirdikten sonra bilet almak için oturumu kapatıp tekrar " "açmanız gerekir" -#: src/sss_client/pam_sss.c:735 +#: src/sss_client/pam_sss.c:813 msgid "PIN locked" msgstr "PIN kilitli" -#: src/sss_client/pam_sss.c:750 +#: src/sss_client/pam_sss.c:828 msgid "" "No Kerberos TGT granted as the server does not support this method. Your " "single-sign on(SSO) experience will be affected." @@ -2239,61 +2289,65 @@ msgstr "" "Sunucu bu yöntemi desteklemediği için Kerberos TGT verilmedi. Ortak oturum " "açma (SSO) deneyiminiz etkilenecektir." -#: src/sss_client/pam_sss.c:840 src/sss_client/pam_sss.c:853 +#: src/sss_client/pam_sss.c:918 src/sss_client/pam_sss.c:931 msgid "Password change failed. " msgstr "Parola değişikliği başarısız oldu. " -#: src/sss_client/pam_sss.c:1859 -#, c-format -msgid "Authenticate at %1$s and press ENTER." +#: src/sss_client/pam_sss.c:2028 +#, fuzzy, c-format +msgid "Authenticate at \"%1$s\"." msgstr "%1$s'de kimlik doğrulaması yapın ve ENTER'a basın." -#: src/sss_client/pam_sss.c:1862 -#, c-format -msgid "Authenticate with PIN %1$s at %2$s and press ENTER." +#: src/sss_client/pam_sss.c:2031 +#, fuzzy, c-format +msgid "Authenticate with PIN \"%1$s\" at \"%2$s\"." msgstr "%2$s'de %1$s PIN'i ile kimlik doğrulaması yapın ve ENTER'a basın." -#: src/sss_client/pam_sss.c:2281 +#: src/sss_client/pam_sss.c:2470 msgid "Please (re)insert (different) Smartcard" msgstr "Lütfen (farklı bir) Akıllı Kartı (yeniden) yerleştirin" -#: src/sss_client/pam_sss.c:2482 +#: src/sss_client/pam_sss.c:2700 msgid "New Password: " msgstr "Yeni Parola: " -#: src/sss_client/pam_sss.c:2483 +#: src/sss_client/pam_sss.c:2701 msgid "Reenter new Password: " msgstr "Yeni parolayı tekrar giriniz: " -#: src/sss_client/pam_sss.c:2676 src/sss_client/pam_sss.c:2679 +#: src/sss_client/pam_sss.c:2890 +msgid "Press ENTER to continue." +msgstr "" + +#: src/sss_client/pam_sss.c:2913 src/sss_client/pam_sss.c:2916 msgid "First Factor: " msgstr "Birinci Etken: " -#: src/sss_client/pam_sss.c:2677 src/sss_client/pam_sss.c:2851 +#: src/sss_client/pam_sss.c:2914 src/sss_client/pam_sss.c:3088 msgid "Second Factor (optional): " msgstr "İkinci Etken (isteğe bağlı): " -#: src/sss_client/pam_sss.c:2680 src/sss_client/pam_sss.c:2855 +#: src/sss_client/pam_sss.c:2917 src/sss_client/pam_sss.c:3092 msgid "Second Factor: " msgstr "İkinci Etken: " -#: src/sss_client/pam_sss.c:2684 +#: src/sss_client/pam_sss.c:2921 msgid "Insert your passkey device, then press ENTER." msgstr "Geçiş anahtarı aygıtınızı girin ve ardından ENTER'a basın." -#: src/sss_client/pam_sss.c:2688 src/sss_client/pam_sss.c:2696 +#: src/sss_client/pam_sss.c:2925 src/sss_client/pam_sss.c:2933 msgid "Password: " msgstr "Parola: " -#: src/sss_client/pam_sss.c:2850 src/sss_client/pam_sss.c:2854 +#: src/sss_client/pam_sss.c:3087 src/sss_client/pam_sss.c:3091 msgid "First Factor (Current Password): " msgstr "Birinci Etken (Geçerli Parola): " -#: src/sss_client/pam_sss.c:2874 +#: src/sss_client/pam_sss.c:3111 msgid "Current Password: " msgstr "Geçerli Parola: " -#: src/sss_client/pam_sss.c:3248 +#: src/sss_client/pam_sss.c:3485 msgid "Password expired. Change your password now." msgstr "Parolanızın zamanı doldu. Parolanızı şimdi değiştirin." @@ -2740,9 +2794,9 @@ msgstr "Nesne yazdırılamadı: %s\n" #: src/tools/sssctl/sssctl_cache.c:835 src/tools/sssctl/sssctl_cache.c:918 #: src/tools/sssctl/sssctl_cache.c:950 src/tools/sssctl/sssctl_cache.c:956 #: src/tools/sssctl/sssctl_cache.c:1010 src/tools/sssctl/sssctl_cache.c:1034 -#: src/tools/sssctl/sssctl_cache.c:1085 src/tools/sssctl/sssctl_cache.c:1194 -#: src/tools/sssctl/sssctl_cache.c:1229 src/tools/sssctl/sssctl_cache.c:1235 -#: src/tools/sssctl/sssctl_cache.c:1244 +#: src/tools/sssctl/sssctl_cache.c:1085 src/tools/sssctl/sssctl_cache.c:1195 +#: src/tools/sssctl/sssctl_cache.c:1230 src/tools/sssctl/sssctl_cache.c:1236 +#: src/tools/sssctl/sssctl_cache.c:1245 msgid "talloc failed\n" msgstr "talloc başarısız oldu.\n" @@ -2818,25 +2872,25 @@ msgstr "Önbelleğe alınan GPO yolu [%s], [%s] altında değil, yok sayılıyor msgid "Unable to remove downloaded GPO files: %s\n" msgstr "İndirilen GPO dosyaları kaldırılamıyor: %s\n" -#: src/tools/sssctl/sssctl_cache.c:1165 +#: src/tools/sssctl/sssctl_cache.c:1166 #, c-format msgid "Failed to fetch cache entry: %s\n" msgstr "Önbellek girdisi alınamadı: %s\n" -#: src/tools/sssctl/sssctl_cache.c:1170 +#: src/tools/sssctl/sssctl_cache.c:1171 msgid "Could not determine object domain\n" msgstr "Nesne etki alanı belirlenemedi\n" -#: src/tools/sssctl/sssctl_cache.c:1200 +#: src/tools/sssctl/sssctl_cache.c:1201 msgid "Could not find GUID attribute in GPO entry\n" msgstr "GPO girdisinde GUID özniteliği bulunamadı\n" -#: src/tools/sssctl/sssctl_cache.c:1206 +#: src/tools/sssctl/sssctl_cache.c:1207 #, c-format msgid "Failed to delete GPO: %s\n" msgstr "GPO silinemedi: %s\n" -#: src/tools/sssctl/sssctl_cache.c:1210 +#: src/tools/sssctl/sssctl_cache.c:1211 #, c-format msgid "%s removed from cache\n" msgstr "%s önbellekten kaldırıldı\n" @@ -2932,39 +2986,40 @@ msgstr "" "my/path/sssd.conf\" olarak ayarlanmışsa, parçacık dizini olarak \"/my/path/" "conf.d\" kullanılır)" -#: src/tools/sssctl/sssctl_config.c:114 +#: src/tools/sssctl/sssctl_config.c:126 #, c-format msgid "File %1$s does not exist.\n" msgstr "%1$s dosyası yok.\n" -#: src/tools/sssctl/sssctl_config.c:115 +#: src/tools/sssctl/sssctl_config.c:127 msgid "There is no configuration.\n" msgstr "Yapılandırma yok..\n" -#: src/tools/sssctl/sssctl_config.c:120 +#: src/tools/sssctl/sssctl_config.c:132 #, c-format msgid "Configuration validation failed: %s\n" msgstr "Yapılandırma doğrulaması başarısız oldu: %s\n" -#: src/tools/sssctl/sssctl_config.c:121 +#: src/tools/sssctl/sssctl_config.c:133 msgid "Run with high debug level to see details.\n" msgstr "Ayrıntıları görmek için yüksek hata ayıklama düzeyinde çalıştırın.\n" -#: src/tools/sssctl/sssctl_config.c:130 -msgid "Failed to run validators" +#: src/tools/sssctl/sssctl_config.c:142 +#, fuzzy +msgid "Failed to run validators\n" msgstr "Doğrulayıcılar çalıştırılamadı" -#: src/tools/sssctl/sssctl_config.c:134 +#: src/tools/sssctl/sssctl_config.c:146 #, c-format msgid "Issues identified by validators: %zu\n" msgstr "Doğrulayıcılar tarafından tanımlanan sorunlar: %zu\n" -#: src/tools/sssctl/sssctl_config.c:145 +#: src/tools/sssctl/sssctl_config.c:157 #, c-format msgid "Messages generated during configuration merging: %zu\n" msgstr "Yapılandırma birleştirme sırasında oluşturulan iletiler: %zu\n" -#: src/tools/sssctl/sssctl_config.c:158 +#: src/tools/sssctl/sssctl_config.c:170 #, c-format msgid "Used configuration snippet files: %zu\n" msgstr "Kullanılan yapılandırma parçacığı dosyaları: %zu\n" diff --git a/po/uk.po b/po/uk.po index aed75e46638..29adbc368f7 100644 --- a/po/uk.po +++ b/po/uk.po @@ -17,8 +17,8 @@ msgid "" msgstr "" "Project-Id-Version: PACKAGE VERSION\n" "Report-Msgid-Bugs-To: sssd-devel@lists.fedorahosted.org\n" -"POT-Creation-Date: 2026-01-14 14:57+0000\n" -"PO-Revision-Date: 2026-04-23 16:52+0000\n" +"POT-Creation-Date: 2026-10-02 15:57+0000\n" +"PO-Revision-Date: 2026-10-05 16:49+0000\n" "Last-Translator: Elena Mishina \n" "Language-Team: Ukrainian \n" @@ -28,50 +28,52 @@ msgstr "" "Content-Transfer-Encoding: 8bit\n" "Plural-Forms: nplurals=3; plural=n%10==1 && n%100!=11 ? 0 : n%10>=2 && " "n%10<=4 && (n%100<10 || n%100>=20) ? 1 : 2;\n" -"X-Generator: Weblate 5.17\n" +"X-Generator: Weblate 2026.10\n" -#: src/config/SSSDConfig/sssdoptions.py:20 -#: src/config/SSSDConfig/sssdoptions.py:21 +#: src/config/SSSDConfig/sssdoptions.py:16 +#: src/config/SSSDConfig/sssdoptions.py:17 msgid "Set the verbosity of the debug logging" msgstr "Встановити рівень докладності діагностичних записів журналу" -#: src/config/SSSDConfig/sssdoptions.py:22 +#: src/config/SSSDConfig/sssdoptions.py:18 msgid "Include timestamps in debug logs" msgstr "Додати до діагностичних журналів позначки часу" -#: src/config/SSSDConfig/sssdoptions.py:23 +#: src/config/SSSDConfig/sssdoptions.py:19 msgid "Include microseconds in timestamps in debug logs" msgstr "Включати мілісекунди до часових позначок у журналах" -#: src/config/SSSDConfig/sssdoptions.py:24 +#: src/config/SSSDConfig/sssdoptions.py:20 msgid "Enable/disable debug backtrace" msgstr "Увімкнути або вимкнути діагностичне зворотне трасування" -#: src/config/SSSDConfig/sssdoptions.py:25 +#: src/config/SSSDConfig/sssdoptions.py:21 msgid "Watchdog timeout before restarting service" -msgstr "Час очікування відповіді засобу спостереження перед перезапуском служби" +msgstr "" +"Час очікування відповіді засобу спостереження перед перезапуском служби" -#: src/config/SSSDConfig/sssdoptions.py:26 +#: src/config/SSSDConfig/sssdoptions.py:22 msgid "Command to start service" msgstr "Команда запуску служби" -#: src/config/SSSDConfig/sssdoptions.py:27 +#: src/config/SSSDConfig/sssdoptions.py:23 msgid "The number of file descriptors that may be opened by this responder" msgstr "Кількість дескрипторів файлів, які може бути відкрито цим відповідачем" -#: src/config/SSSDConfig/sssdoptions.py:28 +#: src/config/SSSDConfig/sssdoptions.py:24 msgid "Idle time before automatic disconnection of a client" -msgstr "Проміжок бездіяльності до автоматичного від’єднання клієнтської частини" +msgstr "" +"Проміжок бездіяльності до автоматичного від’єднання клієнтської частини" -#: src/config/SSSDConfig/sssdoptions.py:29 +#: src/config/SSSDConfig/sssdoptions.py:25 msgid "Idle time before automatic shutdown of the responder" msgstr "Проміжок бездіяльності до автоматичного вимикання відповідача" -#: src/config/SSSDConfig/sssdoptions.py:30 +#: src/config/SSSDConfig/sssdoptions.py:26 msgid "Always query all the caches before querying the Data Providers" msgstr "Завжди опитувати усі кеші до опитування засобів надання даних" -#: src/config/SSSDConfig/sssdoptions.py:31 +#: src/config/SSSDConfig/sssdoptions.py:27 msgid "" "When SSSD switches to offline mode the amount of time before it tries to go " "back online will increase based upon the time spent disconnected. This value " @@ -84,23 +86,23 @@ msgstr "" "значення вказується у секундах і обчислюється за такою формулою: " "час_очікування_від'єднання + випадкове_зміщення." -#: src/config/SSSDConfig/sssdoptions.py:36 +#: src/config/SSSDConfig/sssdoptions.py:32 msgid "SSSD Services to start" msgstr "Служби SSSD, які слід запустити" -#: src/config/SSSDConfig/sssdoptions.py:37 +#: src/config/SSSDConfig/sssdoptions.py:33 msgid "SSSD Domains to start" msgstr "Домени SSSD, які слід запустити" -#: src/config/SSSDConfig/sssdoptions.py:38 +#: src/config/SSSDConfig/sssdoptions.py:34 msgid "Regex to parse username and domain" msgstr "Формальний вираз для обробки імені користувача і домену" -#: src/config/SSSDConfig/sssdoptions.py:39 +#: src/config/SSSDConfig/sssdoptions.py:35 msgid "Printf-compatible format for displaying fully-qualified names" msgstr "Сумісний з printf формат показу повних назв" -#: src/config/SSSDConfig/sssdoptions.py:40 +#: src/config/SSSDConfig/sssdoptions.py:36 msgid "" "Directory on the filesystem where SSSD should store Kerberos replay cache " "files." @@ -108,36 +110,36 @@ msgstr "" "Каталог у файловій системі, де SSSD має зберігати файли кешу відтворення " "Kerberos." -#: src/config/SSSDConfig/sssdoptions.py:41 +#: src/config/SSSDConfig/sssdoptions.py:37 msgid "Domain to add to names without a domain component." msgstr "Домен, який слід додати до назв без компонента домену." -#: src/config/SSSDConfig/sssdoptions.py:42 +#: src/config/SSSDConfig/sssdoptions.py:38 msgid "The user to drop privileges to" msgstr "Користувач, привілеї якого слід скинути" -#: src/config/SSSDConfig/sssdoptions.py:43 +#: src/config/SSSDConfig/sssdoptions.py:39 msgid "Tune certificate verification" msgstr "Скоригувати перевірку сертифікатів" -#: src/config/SSSDConfig/sssdoptions.py:44 +#: src/config/SSSDConfig/sssdoptions.py:40 msgid "All spaces in group or user names will be replaced with this character" msgstr "" "Усі пробіли у назвах груп і іменах користувачів буде замінено на цей символ" -#: src/config/SSSDConfig/sssdoptions.py:45 +#: src/config/SSSDConfig/sssdoptions.py:41 msgid "Tune sssd to honor or ignore netlink state changes" msgstr "Налаштувати sssd на врахування або ігнорування змін стану netlink" -#: src/config/SSSDConfig/sssdoptions.py:46 +#: src/config/SSSDConfig/sssdoptions.py:42 msgid "Enable or disable the implicit files domain" msgstr "Увімкнути або вимкнути домен неявних файлів" -#: src/config/SSSDConfig/sssdoptions.py:47 +#: src/config/SSSDConfig/sssdoptions.py:43 msgid "A specific order of the domains to be looked up" msgstr "Певний порядок доменів, у якому їх слід використовувати для пошуку" -#: src/config/SSSDConfig/sssdoptions.py:48 +#: src/config/SSSDConfig/sssdoptions.py:44 msgid "" "Controls if SSSD should monitor the state of resolv.conf to identify when it " "needs to update its internal DNS resolver." @@ -145,7 +147,7 @@ msgstr "" "Керує тим, чи SSSD має спостерігати за станом resolv.conf для визначення " "моменту, коли слід оновити дані вбудованого інструмента визначення DNS." -#: src/config/SSSDConfig/sssdoptions.py:50 +#: src/config/SSSDConfig/sssdoptions.py:46 msgid "" "SSSD monitors the state of resolv.conf to identify when it needs to update " "its internal DNS resolver. By default, we will attempt to use inotify for " @@ -157,74 +159,74 @@ msgstr "" "використовується inotify. У разі неможливості використання inotify, " "виконуватиметься опитування resolv.conf кожні п’ять секунд." -#: src/config/SSSDConfig/sssdoptions.py:53 +#: src/config/SSSDConfig/sssdoptions.py:49 msgid "Run PAC responder automatically for AD and IPA provider" msgstr "Запускати відповідач PAC автоматично для надавачів AD та IPA" -#: src/config/SSSDConfig/sssdoptions.py:54 +#: src/config/SSSDConfig/sssdoptions.py:50 msgid "Enable or disable core dumps for all SSSD processes." msgstr "Увімкнути або вимкнути дампи ядра для усіх процесів SSSD." -#: src/config/SSSDConfig/sssdoptions.py:55 +#: src/config/SSSDConfig/sssdoptions.py:51 msgid "Tune passkey verification behavior" msgstr "Скоригувати поведінку при перевірці пароля" -#: src/config/SSSDConfig/sssdoptions.py:58 +#: src/config/SSSDConfig/sssdoptions.py:54 msgid "Enumeration cache timeout length (seconds)" msgstr "Тривалість часу очікування на дані кешу нумерування (у секундах)" -#: src/config/SSSDConfig/sssdoptions.py:59 +#: src/config/SSSDConfig/sssdoptions.py:55 msgid "Entry cache background update timeout length (seconds)" msgstr "Час очікування на фонове оновлення кешу записів (у секундах)" -#: src/config/SSSDConfig/sssdoptions.py:60 -#: src/config/SSSDConfig/sssdoptions.py:125 +#: src/config/SSSDConfig/sssdoptions.py:56 +#: src/config/SSSDConfig/sssdoptions.py:124 msgid "Negative cache timeout length (seconds)" msgstr "Від’ємний час очікування на дані з кешу (у секундах)" -#: src/config/SSSDConfig/sssdoptions.py:61 +#: src/config/SSSDConfig/sssdoptions.py:57 msgid "Users that SSSD should explicitly ignore" msgstr "Користувачі, яких SSSD має явно ігнорувати" -#: src/config/SSSDConfig/sssdoptions.py:62 +#: src/config/SSSDConfig/sssdoptions.py:58 msgid "Groups that SSSD should explicitly ignore" msgstr "Групи користувачів, які SSSD має явно ігнорувати" -#: src/config/SSSDConfig/sssdoptions.py:63 +#: src/config/SSSDConfig/sssdoptions.py:59 msgid "Should filtered users appear in groups" msgstr "Чи слід показувати відфільтрованих користувачів у групах" -#: src/config/SSSDConfig/sssdoptions.py:64 +#: src/config/SSSDConfig/sssdoptions.py:60 msgid "The value of the password field the NSS provider should return" msgstr "Значення поля пароля, яке має повертати постачальник даних NSS" -#: src/config/SSSDConfig/sssdoptions.py:65 +#: src/config/SSSDConfig/sssdoptions.py:61 msgid "Override homedir value from the identity provider with this value" msgstr "" "Замінити значення назви домашнього каталогу від надавача профілю цим " "значенням" -#: src/config/SSSDConfig/sssdoptions.py:66 +#: src/config/SSSDConfig/sssdoptions.py:62 msgid "" "Substitute empty homedir value from the identity provider with this value" msgstr "" "Замінювати порожні значення домашніх каталогів у засобі надання даних " "профілів цим значенням" -#: src/config/SSSDConfig/sssdoptions.py:67 +#: src/config/SSSDConfig/sssdoptions.py:63 msgid "Override shell value from the identity provider with this value" msgstr "Замінити значення оболонки від надавача профілю цим значенням" -#: src/config/SSSDConfig/sssdoptions.py:68 +#: src/config/SSSDConfig/sssdoptions.py:64 msgid "The list of shells users are allowed to log in with" msgstr "Список оболонок, за допомогою яких можуть входити користувачі" -#: src/config/SSSDConfig/sssdoptions.py:69 +#: src/config/SSSDConfig/sssdoptions.py:65 msgid "" "The list of shells that will be vetoed, and replaced with the fallback shell" msgstr "Список оболонок, які буде заборонено і замінено резервною оболонкою" -#: src/config/SSSDConfig/sssdoptions.py:70 +#: src/config/SSSDConfig/sssdoptions.py:66 msgid "" "If a shell stored in central directory is allowed but not available, use " "this fallback" @@ -232,15 +234,15 @@ msgstr "" "Якщо оболонка, що зберігається у центральному каталозі дозволена, але " "недоступна, використовувати цю резервну" -#: src/config/SSSDConfig/sssdoptions.py:71 +#: src/config/SSSDConfig/sssdoptions.py:67 msgid "Shell to use if the provider does not list one" msgstr "Оболонка, яку слід використовувати, якщо засіб не надає жодної" -#: src/config/SSSDConfig/sssdoptions.py:72 +#: src/config/SSSDConfig/sssdoptions.py:68 msgid "How long will be in-memory cache records valid" msgstr "Строк дії записів кешу у пам’яті" -#: src/config/SSSDConfig/sssdoptions.py:74 +#: src/config/SSSDConfig/sssdoptions.py:70 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for passwd requests" @@ -248,7 +250,7 @@ msgstr "" "Розмір (у мегабайтах) таблиці даних, яку розміщено у швидкому кеші у " "пам'яті, для запитів passwd" -#: src/config/SSSDConfig/sssdoptions.py:76 +#: src/config/SSSDConfig/sssdoptions.py:72 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for group requests" @@ -256,7 +258,7 @@ msgstr "" "Розмір (у мегабайтах) таблиці даних, які розміщено у швидкому кеші у " "пам'яті, для запитів щодо груп" -#: src/config/SSSDConfig/sssdoptions.py:78 +#: src/config/SSSDConfig/sssdoptions.py:74 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for initgroups requests" @@ -264,7 +266,7 @@ msgstr "" "Розмір (у мегабайтах) таблиці даних, які розміщено у швидкому кеші у " "пам'яті, для запитів щодо груп ініціалізації" -#: src/config/SSSDConfig/sssdoptions.py:79 +#: src/config/SSSDConfig/sssdoptions.py:75 msgid "" "The value of this option will be used in the expansion of the " "override_homedir option if the template contains the format string %H." @@ -272,7 +274,7 @@ msgstr "" "Значення цього параметра буде використано у розгортанні параметра " "override_homedir, якщо шаблон містить рядок форматування %H." -#: src/config/SSSDConfig/sssdoptions.py:81 +#: src/config/SSSDConfig/sssdoptions.py:77 msgid "" "Specifies time in seconds for which the list of subdomains will be " "considered valid." @@ -280,7 +282,7 @@ msgstr "" "Визначає час у секундах, протягом якого список піддоменів вважатиметься " "чинним." -#: src/config/SSSDConfig/sssdoptions.py:83 +#: src/config/SSSDConfig/sssdoptions.py:79 msgid "" "The entry cache can be set to automatically update entries in the background " "if they are requested beyond a percentage of the entry_cache_timeout value " @@ -290,17 +292,17 @@ msgstr "" "режимі, якщо запит щодо них надходить у визначений у відсотках від " "entry_cache_timeout для домену період часу." -#: src/config/SSSDConfig/sssdoptions.py:88 +#: src/config/SSSDConfig/sssdoptions.py:84 msgid "How long to allow cached logins between online logins (days)" msgstr "" "Тривалість зберігання кешованих реєстраційних даних між входами до системи " "(у днях)" -#: src/config/SSSDConfig/sssdoptions.py:89 +#: src/config/SSSDConfig/sssdoptions.py:85 msgid "How many failed logins attempts are allowed when offline" msgstr "Макс. дозволена кількість помилкових спроб входу у автономному режимі" -#: src/config/SSSDConfig/sssdoptions.py:91 +#: src/config/SSSDConfig/sssdoptions.py:87 msgid "" "How long (minutes) to deny login after offline_failed_login_attempts has " "been reached" @@ -308,103 +310,103 @@ msgstr "" "Тривалість (у хвилинах) заборони входу після досягнення значення " "offline_failed_login_attempts" -#: src/config/SSSDConfig/sssdoptions.py:92 +#: src/config/SSSDConfig/sssdoptions.py:88 msgid "What kind of messages are displayed to the user during authentication" msgstr "Тип повідомлень, які буде показано користувачеві під час розпізнавання" -#: src/config/SSSDConfig/sssdoptions.py:93 +#: src/config/SSSDConfig/sssdoptions.py:89 msgid "Filter PAM responses sent to the pam_sss" msgstr "Фільтрувати відповіді PAM, які надіслано pam_sss" -#: src/config/SSSDConfig/sssdoptions.py:94 +#: src/config/SSSDConfig/sssdoptions.py:90 msgid "How many seconds to keep identity information cached for PAM requests" msgstr "" "Тривалість (у секундах) зберігання даних щодо розпізнавання у кеші для " "запитів PAM" -#: src/config/SSSDConfig/sssdoptions.py:95 +#: src/config/SSSDConfig/sssdoptions.py:91 msgid "How many days before password expiration a warning should be displayed" msgstr "" "Визначає кількість днів між днем, коли має бути показано попередження, і " "днем, коли завершиться строк дії пароля" -#: src/config/SSSDConfig/sssdoptions.py:96 +#: src/config/SSSDConfig/sssdoptions.py:92 msgid "List of trusted uids or user's name" msgstr "Список надійних UUID або імен користувачів" -#: src/config/SSSDConfig/sssdoptions.py:97 +#: src/config/SSSDConfig/sssdoptions.py:93 msgid "List of domains accessible even for untrusted users." msgstr "" "Список доменів, доступ до яких відкрито навіть для ненадійних користувачів." -#: src/config/SSSDConfig/sssdoptions.py:98 +#: src/config/SSSDConfig/sssdoptions.py:94 msgid "Message printed when user account is expired." msgstr "" "Повідомлення, яке буде виведено, коли строк дії облікового запису " "користувача буде завершено." -#: src/config/SSSDConfig/sssdoptions.py:99 +#: src/config/SSSDConfig/sssdoptions.py:95 msgid "Message printed when user account is locked." msgstr "" "Повідомлення, яке буде виведено, коли обліковий запис користувача буде " "заблоковано." -#: src/config/SSSDConfig/sssdoptions.py:100 +#: src/config/SSSDConfig/sssdoptions.py:96 msgid "Allow certificate based/Smartcard authentication." msgstr "Дозволити розпізнавання за сертифікатом або смарткарткою." -#: src/config/SSSDConfig/sssdoptions.py:101 +#: src/config/SSSDConfig/sssdoptions.py:97 msgid "Path to certificate database with PKCS#11 modules." msgstr "Шлях до бази даних сертифікатів із модулями PKCS#11." -#: src/config/SSSDConfig/sssdoptions.py:102 +#: src/config/SSSDConfig/sssdoptions.py:98 msgid "Tune certificate verification for PAM authentication." msgstr "Скоригувати перевірку сертифікатів для розпізнавання за допомогою PAM." -#: src/config/SSSDConfig/sssdoptions.py:103 +#: src/config/SSSDConfig/sssdoptions.py:99 msgid "How many seconds will pam_sss wait for p11_child to finish" msgstr "" "Час у секундах, протягом якого pam_sss очікуватиме на завершення роботи " "p11_child" -#: src/config/SSSDConfig/sssdoptions.py:104 +#: src/config/SSSDConfig/sssdoptions.py:100 msgid "Which PAM services are permitted to contact application domains" msgstr "" "Визначає, яким службам PAM дозволено встановлювати з'єднання із доменами " "програм" -#: src/config/SSSDConfig/sssdoptions.py:105 +#: src/config/SSSDConfig/sssdoptions.py:101 msgid "Allowed services for using smartcards" msgstr "Дозволені служби для використання смарт-карток" -#: src/config/SSSDConfig/sssdoptions.py:106 +#: src/config/SSSDConfig/sssdoptions.py:102 msgid "Additional timeout to wait for a card if requested" msgstr "Додатковий час очікування на картку, якщо надійде запит" -#: src/config/SSSDConfig/sssdoptions.py:107 +#: src/config/SSSDConfig/sssdoptions.py:103 msgid "" "PKCS#11 URI to restrict the selection of devices for Smartcard authentication" msgstr "" "Адреса PKCS#11 для обмеження переліку пристроїв для розпізнавання за смарт-" "карткою" -#: src/config/SSSDConfig/sssdoptions.py:108 +#: src/config/SSSDConfig/sssdoptions.py:104 msgid "When shall the PAM responder force an initgroups request" msgstr "" "Визначає, коли відповідач PAM має примусово виконувати запит щодо груп " "ініціалізації" -#: src/config/SSSDConfig/sssdoptions.py:109 +#: src/config/SSSDConfig/sssdoptions.py:105 msgid "List of PAM services that are allowed to authenticate with GSSAPI." msgstr "Список служб PAM, яким дозволене розпізнавання за допомогою GSSAPI." -#: src/config/SSSDConfig/sssdoptions.py:110 +#: src/config/SSSDConfig/sssdoptions.py:106 msgid "Whether to match authenticated UPN with target user" msgstr "" "Чи слід встановлювати відповідність розпізнаного UPN із користувачем " "призначення" -#: src/config/SSSDConfig/sssdoptions.py:111 +#: src/config/SSSDConfig/sssdoptions.py:107 msgid "" "List of pairs : that must be enforced " "for PAM access with GSSAPI authentication" @@ -412,38 +414,48 @@ msgstr "" "Список пар <служба PAM>:<індикатор розпізнавання>, для яких має бути " "примусово встановлено доступ PAM із розпізнаванням GSSAPI" -#: src/config/SSSDConfig/sssdoptions.py:113 +#: src/config/SSSDConfig/sssdoptions.py:109 +#, fuzzy +msgid "" +"List of triples :: that assigns " +"additional information from the Kerberos ticket to an authentication " +"indicator." +msgstr "" +"Список пар <служба PAM>:<індикатор розпізнавання>, для яких має бути " +"примусово встановлено доступ PAM із розпізнаванням GSSAPI" + +#: src/config/SSSDConfig/sssdoptions.py:112 msgid "Allow passkey device authentication." msgstr "Дозволити розпізнавання за допомогою пристрою пароля." -#: src/config/SSSDConfig/sssdoptions.py:114 +#: src/config/SSSDConfig/sssdoptions.py:113 msgid "How many seconds will pam_sss wait for passkey_child to finish" msgstr "" "Час у секундах, протягом якого pam_sss очікуватиме на завершення роботи " "passkey_child" -#: src/config/SSSDConfig/sssdoptions.py:115 +#: src/config/SSSDConfig/sssdoptions.py:114 msgid "Enable debugging in the libfido2 library" msgstr "Увімкнути діагностику у бібліотеці libfido2" -#: src/config/SSSDConfig/sssdoptions.py:116 +#: src/config/SSSDConfig/sssdoptions.py:115 #, fuzzy msgid "Enable JSON protocol for authentication methods selection." msgstr "Правила щодо локальних способів розпізнавання " -#: src/config/SSSDConfig/sssdoptions.py:119 +#: src/config/SSSDConfig/sssdoptions.py:118 msgid "Whether to evaluate the time-based attributes in sudo rules" msgstr "" "Визначає, чи слід обробляти атрибути правил sudo, пов’язані з часовими " "обмеженнями" -#: src/config/SSSDConfig/sssdoptions.py:120 +#: src/config/SSSDConfig/sssdoptions.py:119 msgid "If true, SSSD will switch back to lower-wins ordering logic" msgstr "" "Якщо має значення true, SSSD перемикнеться на логіку упорядковування менший-" "кращий" -#: src/config/SSSDConfig/sssdoptions.py:121 +#: src/config/SSSDConfig/sssdoptions.py:120 msgid "" "Maximum number of rules that can be refreshed at once. If this is exceeded, " "full refresh is performed." @@ -451,11 +463,11 @@ msgstr "" "Максимальна кількість правил, які може бути одночасно оновлено. Якщо цю " "кількість буде перевищено, буде виконано повне оновлення." -#: src/config/SSSDConfig/sssdoptions.py:128 +#: src/config/SSSDConfig/sssdoptions.py:127 msgid "Whether to hash host names and addresses in the known_hosts file" msgstr "Чи слід хешувати назви та адреси вузлів у файлі known_hosts" -#: src/config/SSSDConfig/sssdoptions.py:129 +#: src/config/SSSDConfig/sssdoptions.py:128 msgid "" "How many seconds to keep a host in the known_hosts file after its host keys " "were requested" @@ -463,15 +475,15 @@ msgstr "" "Кількість секунд, протягом яких запису вузла зберігатиметься у файлі " "known_hosts після надсилання запиту щодо ключів вузла" -#: src/config/SSSDConfig/sssdoptions.py:131 +#: src/config/SSSDConfig/sssdoptions.py:130 msgid "Path to storage of trusted CA certificates" msgstr "Шлях до сховища надійних сертифікатів служб сертифікації (CA)" -#: src/config/SSSDConfig/sssdoptions.py:132 +#: src/config/SSSDConfig/sssdoptions.py:131 msgid "Allow to generate ssh-keys from certificates" msgstr "Дозволити створення ключів SSH з сертифікатів" -#: src/config/SSSDConfig/sssdoptions.py:133 +#: src/config/SSSDConfig/sssdoptions.py:132 msgid "" "Use the following matching rules to filter the certificates for ssh-key " "generation" @@ -479,25 +491,25 @@ msgstr "" "Використати вказані нижче відповідні правила для фільтрування сертифікатів " "для створення ключів SSH" -#: src/config/SSSDConfig/sssdoptions.py:137 +#: src/config/SSSDConfig/sssdoptions.py:136 msgid "List of UIDs or user names allowed to access the PAC responder" msgstr "" "Список унікальних ідентифікаторів (UID) або імен користувачів, яким надано " "доступ до відповідача PAC" -#: src/config/SSSDConfig/sssdoptions.py:138 +#: src/config/SSSDConfig/sssdoptions.py:137 msgid "How long the PAC data is considered valid" msgstr "Час, протягом якого дані PAC вважатимуться чинними" -#: src/config/SSSDConfig/sssdoptions.py:139 +#: src/config/SSSDConfig/sssdoptions.py:138 msgid "Validate the PAC" msgstr "Перевірити PAC" -#: src/config/SSSDConfig/sssdoptions.py:142 +#: src/config/SSSDConfig/sssdoptions.py:141 msgid "List of user attributes the InfoPipe is allowed to publish" msgstr "Список атрибутів запису користувача, які може оприлюднювати InfoPipe" -#: src/config/SSSDConfig/sssdoptions.py:145 +#: src/config/SSSDConfig/sssdoptions.py:144 msgid "" "One of the following strings specifying the scope of session recording: none " "- No users are recorded. some - Users/groups specified by users and groups " @@ -507,7 +519,7 @@ msgstr "" "записувати жодного користувача.; some — записувати користувачів і групи, які " "вказано параметрами users і groups; all — записувати усіх користувачів." -#: src/config/SSSDConfig/sssdoptions.py:148 +#: src/config/SSSDConfig/sssdoptions.py:147 msgid "" "A comma-separated list of users which should have session recording enabled. " "Matches user names as returned by NSS. I.e. after the possible space " @@ -518,7 +530,7 @@ msgstr "" "повернутими NSS, тобто після можливих замін пробілів, змін регістру символів " "тощо." -#: src/config/SSSDConfig/sssdoptions.py:150 +#: src/config/SSSDConfig/sssdoptions.py:149 msgid "" "A comma-separated list of groups, members of which should have session " "recording enabled. Matches group names as returned by NSS. I.e. after the " @@ -529,7 +541,7 @@ msgstr "" "назвами, повернутими NSS, тобто після можливих замін пробілів, змін регістру " "символів тощо." -#: src/config/SSSDConfig/sssdoptions.py:153 +#: src/config/SSSDConfig/sssdoptions.py:152 msgid "" "A comma-separated list of users to be excluded from recording, only when " "scope=all" @@ -537,7 +549,7 @@ msgstr "" "Список відокремлених комами облікових записів користувачів, яких має бути " "виключено з записування; лише якщо scope=all" -#: src/config/SSSDConfig/sssdoptions.py:154 +#: src/config/SSSDConfig/sssdoptions.py:153 msgid "" "A comma-separated list of groups, members of which should be excluded from " "recording, only when scope=all. " @@ -545,81 +557,81 @@ msgstr "" "Список відокремлених комами записів груп, учасників яких має бути виключено " "з записування; лише якщо scope=all " -#: src/config/SSSDConfig/sssdoptions.py:158 +#: src/config/SSSDConfig/sssdoptions.py:157 msgid "Identity provider" msgstr "Служба профілів" -#: src/config/SSSDConfig/sssdoptions.py:159 +#: src/config/SSSDConfig/sssdoptions.py:158 msgid "Authentication provider" msgstr "Служба розпізнавання" -#: src/config/SSSDConfig/sssdoptions.py:160 +#: src/config/SSSDConfig/sssdoptions.py:159 msgid "Access control provider" msgstr "Служба керування доступом" -#: src/config/SSSDConfig/sssdoptions.py:161 +#: src/config/SSSDConfig/sssdoptions.py:160 msgid "Password change provider" msgstr "Служба зміни паролів" -#: src/config/SSSDConfig/sssdoptions.py:162 +#: src/config/SSSDConfig/sssdoptions.py:161 msgid "SUDO provider" msgstr "Служба SUDO" -#: src/config/SSSDConfig/sssdoptions.py:163 +#: src/config/SSSDConfig/sssdoptions.py:162 msgid "Autofs provider" msgstr "Служба автоматизації файлових систем" -#: src/config/SSSDConfig/sssdoptions.py:164 +#: src/config/SSSDConfig/sssdoptions.py:163 msgid "Host identity provider" msgstr "Служба профілів вузлів" -#: src/config/SSSDConfig/sssdoptions.py:165 +#: src/config/SSSDConfig/sssdoptions.py:164 msgid "SELinux provider" msgstr "Надавач даних SELinux" -#: src/config/SSSDConfig/sssdoptions.py:166 +#: src/config/SSSDConfig/sssdoptions.py:165 msgid "Session management provider" msgstr "Засіб керування сеансами" -#: src/config/SSSDConfig/sssdoptions.py:167 +#: src/config/SSSDConfig/sssdoptions.py:166 msgid "Resolver provider" msgstr "Надавач даних визначення адрес" -#: src/config/SSSDConfig/sssdoptions.py:170 +#: src/config/SSSDConfig/sssdoptions.py:169 msgid "Whether the domain is usable by the OS or by applications" msgstr "" "Визначає, чи можна використовувати домен у операційній системі або у " "програмах" -#: src/config/SSSDConfig/sssdoptions.py:171 +#: src/config/SSSDConfig/sssdoptions.py:170 msgid "Enable or disable the domain" msgstr "Увімкнути або вимкнути домен" -#: src/config/SSSDConfig/sssdoptions.py:172 +#: src/config/SSSDConfig/sssdoptions.py:171 msgid "Minimum user ID" msgstr "Мін. ідентифікатор користувача" -#: src/config/SSSDConfig/sssdoptions.py:173 +#: src/config/SSSDConfig/sssdoptions.py:172 msgid "Maximum user ID" msgstr "Макс. ідентифікатор користувача" -#: src/config/SSSDConfig/sssdoptions.py:174 +#: src/config/SSSDConfig/sssdoptions.py:173 msgid "Enable enumerating all users/groups" msgstr "Увімкнути нумерацію всіх користувачів/груп" -#: src/config/SSSDConfig/sssdoptions.py:175 +#: src/config/SSSDConfig/sssdoptions.py:174 msgid "Cache credentials for offline login" msgstr "Кешувати реєстраційні дані для автономного входу" -#: src/config/SSSDConfig/sssdoptions.py:176 +#: src/config/SSSDConfig/sssdoptions.py:175 msgid "Display users/groups in fully-qualified form" msgstr "Показувати записи користувачів/груп повністю" -#: src/config/SSSDConfig/sssdoptions.py:177 +#: src/config/SSSDConfig/sssdoptions.py:176 msgid "Don't include group members in group lookups" msgstr "Не включати учасників групи у пошуки групи" -#: src/config/SSSDConfig/sssdoptions.py:178 +#: src/config/SSSDConfig/sssdoptions.py:177 #: src/config/SSSDConfig/sssdoptions.py:190 #: src/config/SSSDConfig/sssdoptions.py:191 #: src/config/SSSDConfig/sssdoptions.py:192 @@ -630,20 +642,20 @@ msgstr "Не включати учасників групи у пошуки гр msgid "Entry cache timeout length (seconds)" msgstr "Тривалість кешування записів (у секундах)" -#: src/config/SSSDConfig/sssdoptions.py:179 +#: src/config/SSSDConfig/sssdoptions.py:178 msgid "" "Restrict or prefer a specific address family when performing DNS lookups" msgstr "" "Обмежити або надавати перевагу певному сімейству адрес під час виконання " "пошуків DNS" -#: src/config/SSSDConfig/sssdoptions.py:180 +#: src/config/SSSDConfig/sssdoptions.py:179 msgid "How long to keep cached entries after last successful login (days)" msgstr "" "Тривалість зберігання кешованих записів після останнього успішного входу (у " "днях)" -#: src/config/SSSDConfig/sssdoptions.py:181 +#: src/config/SSSDConfig/sssdoptions.py:180 msgid "" "How long should SSSD talk to single DNS server before trying next server " "(miliseconds)" @@ -651,21 +663,21 @@ msgstr "" "Гранична тривалість спроби обмінятися даними SSSD з окремим сервером DNS, " "перш ніж програма спробує наступний сервер (у мілісекундах)" -#: src/config/SSSDConfig/sssdoptions.py:183 +#: src/config/SSSDConfig/sssdoptions.py:182 msgid "How long should keep trying to resolve single DNS query (seconds)" msgstr "Гранична тривалість спроби обробки окремого запиту DNS (у секундах)" -#: src/config/SSSDConfig/sssdoptions.py:184 +#: src/config/SSSDConfig/sssdoptions.py:183 msgid "How long to wait for replies from DNS when resolving servers (seconds)" msgstr "" "Тривалість очікування на відповідь від DNS під час визначення адрес серверів " "(у секундах)" -#: src/config/SSSDConfig/sssdoptions.py:185 +#: src/config/SSSDConfig/sssdoptions.py:184 msgid "The domain part of service discovery DNS query" msgstr "Частина запиту щодо виявлення служби DNS, пов’язана з доменом" -#: src/config/SSSDConfig/sssdoptions.py:186 +#: src/config/SSSDConfig/sssdoptions.py:185 msgid "" "Specifies the interval, in seconds, that SSSD waits before attempting to " "reconnect to the primary server after a successful connection to the backup " @@ -675,15 +687,19 @@ msgstr "" "повторного з'єднання із основним сервером після успішного встановлення " "з'єднання із резервним сервером" -#: src/config/SSSDConfig/sssdoptions.py:188 +#: src/config/SSSDConfig/sssdoptions.py:187 msgid "Override GID value from the identity provider with this value" msgstr "" "Замінити значення ідентифікатора групи від надавача профілю цим значенням" -#: src/config/SSSDConfig/sssdoptions.py:189 +#: src/config/SSSDConfig/sssdoptions.py:188 msgid "Treat usernames as case sensitive" msgstr "Враховувати регістр у іменах користувачів" +#: src/config/SSSDConfig/sssdoptions.py:189 +msgid "Lookups by ID are expensive or do not work at all" +msgstr "" + #: src/config/SSSDConfig/sssdoptions.py:197 msgid "How often should expired entries be refreshed in background" msgstr "Наскільки часто має виконувати оновлення у тлі застарілих записів" @@ -708,7 +724,8 @@ msgstr "" #: src/config/SSSDConfig/sssdoptions.py:202 msgid "The TTL to apply to the client's DNS entry after updating it" -msgstr "TTL, який слід застосовувати до запису DNS клієнта після його оновлення" +msgstr "" +"TTL, який слід застосовувати до запису DNS клієнта після його оновлення" #: src/config/SSSDConfig/sssdoptions.py:203 msgid "The interface whose IP should be used for dynamic DNS updates" @@ -733,7 +750,8 @@ msgstr "" #: src/config/SSSDConfig/sssdoptions.py:207 msgid "Whether the provider should explicitly update the PTR record as well" -msgstr "Визначає, чи слід надавачу даних також явним чином оновлювати запис PTR" +msgstr "" +"Визначає, чи слід надавачу даних також явним чином оновлювати запис PTR" #: src/config/SSSDConfig/sssdoptions.py:208 msgid "Whether the nsupdate utility should default to using TCP" @@ -937,7 +955,7 @@ msgid "Search base for SUBID ranges" msgstr "Основа пошуку для діапазонів SUBID" #: src/config/SSSDConfig/sssdoptions.py:259 -#: src/config/SSSDConfig/sssdoptions.py:506 +#: src/config/SSSDConfig/sssdoptions.py:512 msgid "Which rules should be used to evaluate access control" msgstr "" "Правила, які має бути використано для визначення достатності прав доступу" @@ -1058,7 +1076,8 @@ msgstr "Атрибут LDAP, який містить категорію кори #: src/config/SSSDConfig/sssdoptions.py:289 msgid "The LDAP attribute that contains unique ID of the user map." -msgstr "Атрибут LDAP, який містить унікальний ідентифікатор карти користувачів." +msgstr "" +"Атрибут LDAP, який містить унікальний ідентифікатор карти користувачів." #: src/config/SSSDConfig/sssdoptions.py:290 msgid "" @@ -1097,7 +1116,7 @@ msgid "Enable DNS sites - location based service discovery" msgstr "Увімкнути сайти DNS — визначення служб на основі адрес" #: src/config/SSSDConfig/sssdoptions.py:301 -#: src/config/SSSDConfig/sssdoptions.py:504 +#: src/config/SSSDConfig/sssdoptions.py:510 msgid "LDAP filter to determine access privileges" msgstr "Фільтр LDAP для визначення прав доступу" @@ -1113,44 +1132,45 @@ msgstr "Режим роботи для керування доступом на msgid "" "The amount of time between lookups of the GPO policy files against the AD " "server" -msgstr "Інтервал часу між послідовними сеансами пошуку правил GPO на сервері AD" +msgstr "" +"Інтервал часу між послідовними сеансами пошуку правил GPO на сервері AD" #: src/config/SSSDConfig/sssdoptions.py:305 msgid "" "PAM service names that map to the GPO (Deny)InteractiveLogonRight policy " "settings" msgstr "" -"Назви служб PAM, які виконують прив’язування до параметрів правил GPO (Deny)" -"InteractiveLogonRight" +"Назви служб PAM, які виконують прив’язування до параметрів правил GPO " +"(Deny)InteractiveLogonRight" #: src/config/SSSDConfig/sssdoptions.py:307 msgid "" "PAM service names that map to the GPO (Deny)RemoteInteractiveLogonRight " "policy settings" msgstr "" -"Назви служб PAM, які виконують прив’язування до параметрів правил GPO (Deny)" -"RemoteInteractiveLogonRight" +"Назви служб PAM, які виконують прив’язування до параметрів правил GPO " +"(Deny)RemoteInteractiveLogonRight" #: src/config/SSSDConfig/sssdoptions.py:309 msgid "" "PAM service names that map to the GPO (Deny)NetworkLogonRight policy settings" msgstr "" -"Назви служб PAM, які виконують прив’язування до параметрів правил GPO (Deny)" -"NetworkLogonRight" +"Назви служб PAM, які виконують прив’язування до параметрів правил GPO " +"(Deny)NetworkLogonRight" #: src/config/SSSDConfig/sssdoptions.py:310 msgid "" "PAM service names that map to the GPO (Deny)BatchLogonRight policy settings" msgstr "" -"Назви служб PAM, які виконують прив’язування до параметрів правил GPO (Deny)" -"BatchLogonRight" +"Назви служб PAM, які виконують прив’язування до параметрів правил GPO " +"(Deny)BatchLogonRight" #: src/config/SSSDConfig/sssdoptions.py:311 msgid "" "PAM service names that map to the GPO (Deny)ServiceLogonRight policy settings" msgstr "" -"Назви служб PAM, які виконують прив’язування до параметрів правил GPO (Deny)" -"ServiceLogonRight" +"Назви служб PAM, які виконують прив’язування до параметрів правил GPO " +"(Deny)ServiceLogonRight" #: src/config/SSSDConfig/sssdoptions.py:312 msgid "PAM service names for which GPO-based access is always granted" @@ -1550,7 +1570,7 @@ msgid "UUID attribute" msgstr "Атрибут UUID" #: src/config/SSSDConfig/sssdoptions.py:423 -#: src/config/SSSDConfig/sssdoptions.py:464 +#: src/config/SSSDConfig/sssdoptions.py:470 msgid "objectSID attribute" msgstr "Атрибут objectSID" @@ -1678,182 +1698,211 @@ msgid "A list of extra attributes to download along with the user entry" msgstr "" "Список додаткових атрибутів, які слід отримувати разом із записом користувача" +#: src/config/SSSDConfig/sssdoptions.py:456 +#, fuzzy +msgid "The object class of an subid entry in LDAP." +msgstr "Клас об’єктів запису вузла у LDAP." + #: src/config/SSSDConfig/sssdoptions.py:457 +#, fuzzy +msgid "Subordinate user ID count attribute" +msgstr "Атрибут користувача правила sudo" + +#: src/config/SSSDConfig/sssdoptions.py:458 +#, fuzzy +msgid "Subordinate group ID count attribute" +msgstr "Атрибут параметрів правила sudo" + +#: src/config/SSSDConfig/sssdoptions.py:459 +#, fuzzy +msgid "User ID range start value attribute" +msgstr "Атрибут імені користувача" + +#: src/config/SSSDConfig/sssdoptions.py:460 +#, fuzzy +msgid "Group ID range start value attribute" +msgstr "Атрибут UUID групи" + +#: src/config/SSSDConfig/sssdoptions.py:461 +msgid "Owner of an entry" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:463 msgid "Base DN for group lookups" msgstr "Базова назва домену для пошуків груп" -#: src/config/SSSDConfig/sssdoptions.py:458 +#: src/config/SSSDConfig/sssdoptions.py:464 msgid "Objectclass for groups" msgstr "Клас об’єктів для груп" -#: src/config/SSSDConfig/sssdoptions.py:459 +#: src/config/SSSDConfig/sssdoptions.py:465 msgid "Group name" msgstr "Назва групи" -#: src/config/SSSDConfig/sssdoptions.py:460 +#: src/config/SSSDConfig/sssdoptions.py:466 msgid "Group password" msgstr "Пароль групи" -#: src/config/SSSDConfig/sssdoptions.py:461 +#: src/config/SSSDConfig/sssdoptions.py:467 msgid "GID attribute" msgstr "Атрибут GID" -#: src/config/SSSDConfig/sssdoptions.py:462 +#: src/config/SSSDConfig/sssdoptions.py:468 msgid "Group member attribute" msgstr "Атрибут членства у групі" -#: src/config/SSSDConfig/sssdoptions.py:463 +#: src/config/SSSDConfig/sssdoptions.py:469 msgid "Group UUID attribute" msgstr "Атрибут UUID групи" -#: src/config/SSSDConfig/sssdoptions.py:465 +#: src/config/SSSDConfig/sssdoptions.py:471 msgid "Modification time attribute for groups" msgstr "Атрибут часу зміни для груп" -#: src/config/SSSDConfig/sssdoptions.py:466 +#: src/config/SSSDConfig/sssdoptions.py:472 msgid "Type of the group and other flags" msgstr "Тип групи та інші прапорці" -#: src/config/SSSDConfig/sssdoptions.py:467 +#: src/config/SSSDConfig/sssdoptions.py:473 msgid "The LDAP group external member attribute" msgstr "Атрибут групи LDAP зовнішнього учасника" -#: src/config/SSSDConfig/sssdoptions.py:468 +#: src/config/SSSDConfig/sssdoptions.py:474 msgid "Maximum nesting level SSSD will follow" msgstr "Максимальний рівень вкладеності, який використовуватиме SSSD" -#: src/config/SSSDConfig/sssdoptions.py:469 +#: src/config/SSSDConfig/sssdoptions.py:475 msgid "Filter for group lookups" msgstr "Фільтр пошуку груп" -#: src/config/SSSDConfig/sssdoptions.py:470 +#: src/config/SSSDConfig/sssdoptions.py:476 msgid "Scope of group lookups" msgstr "Область пошуку груп" -#: src/config/SSSDConfig/sssdoptions.py:472 +#: src/config/SSSDConfig/sssdoptions.py:478 msgid "Base DN for netgroup lookups" msgstr "Базова назва домену для пошуків груп у мережі" -#: src/config/SSSDConfig/sssdoptions.py:473 +#: src/config/SSSDConfig/sssdoptions.py:479 msgid "Objectclass for netgroups" msgstr "Клас об’єктів для груп у мережі" -#: src/config/SSSDConfig/sssdoptions.py:474 +#: src/config/SSSDConfig/sssdoptions.py:480 msgid "Netgroup name" msgstr "Назва мережевої групи" -#: src/config/SSSDConfig/sssdoptions.py:475 +#: src/config/SSSDConfig/sssdoptions.py:481 msgid "Netgroups members attribute" msgstr "Атрибут членства у групах у мережі" -#: src/config/SSSDConfig/sssdoptions.py:476 +#: src/config/SSSDConfig/sssdoptions.py:482 msgid "Netgroup triple attribute" msgstr "Атрибут трійки груп у мережі" -#: src/config/SSSDConfig/sssdoptions.py:477 +#: src/config/SSSDConfig/sssdoptions.py:483 msgid "Modification time attribute for netgroups" msgstr "Атрибут часу зміни для мережевих груп" -#: src/config/SSSDConfig/sssdoptions.py:479 +#: src/config/SSSDConfig/sssdoptions.py:485 msgid "Base DN for service lookups" msgstr "Базова сервер назв домену для пошуку служб" -#: src/config/SSSDConfig/sssdoptions.py:480 +#: src/config/SSSDConfig/sssdoptions.py:486 msgid "Objectclass for services" msgstr "Клас об’єктів для служб" -#: src/config/SSSDConfig/sssdoptions.py:481 +#: src/config/SSSDConfig/sssdoptions.py:487 msgid "Service name attribute" msgstr "Атрибут назви служби" -#: src/config/SSSDConfig/sssdoptions.py:482 +#: src/config/SSSDConfig/sssdoptions.py:488 msgid "Service port attribute" msgstr "Атрибут порту служби" -#: src/config/SSSDConfig/sssdoptions.py:483 +#: src/config/SSSDConfig/sssdoptions.py:489 msgid "Service protocol attribute" msgstr "Атрибут протоколу служби" -#: src/config/SSSDConfig/sssdoptions.py:485 +#: src/config/SSSDConfig/sssdoptions.py:491 msgid "Lower bound for ID-mapping" msgstr "Нижня межа встановлення відповідності ідентифікатора" -#: src/config/SSSDConfig/sssdoptions.py:486 +#: src/config/SSSDConfig/sssdoptions.py:492 msgid "Upper bound for ID-mapping" msgstr "Верхня межа встановлення відповідності ідентифікатора" -#: src/config/SSSDConfig/sssdoptions.py:487 +#: src/config/SSSDConfig/sssdoptions.py:493 msgid "Number of IDs for each slice when ID-mapping" msgstr "" "Кількість ідентифікаторів для кожного зрізу під час встановлення " "відповідності ідентифікаторів" -#: src/config/SSSDConfig/sssdoptions.py:488 +#: src/config/SSSDConfig/sssdoptions.py:494 msgid "Use autorid-compatible algorithm for ID-mapping" msgstr "" "Використовувати для встановлення відповідності ідентифікаторів алгоритм, " "сумісний з autorid" -#: src/config/SSSDConfig/sssdoptions.py:489 +#: src/config/SSSDConfig/sssdoptions.py:495 msgid "Name of the default domain for ID-mapping" msgstr "Назва типового домену для встановлення відповідності ідентифікаторів" -#: src/config/SSSDConfig/sssdoptions.py:490 +#: src/config/SSSDConfig/sssdoptions.py:496 msgid "SID of the default domain for ID-mapping" msgstr "SID типового домену для встановлення відповідності ідентифікаторів" -#: src/config/SSSDConfig/sssdoptions.py:491 +#: src/config/SSSDConfig/sssdoptions.py:497 msgid "Number of secondary slices" msgstr "Кількість вторинних зрізів" -#: src/config/SSSDConfig/sssdoptions.py:493 +#: src/config/SSSDConfig/sssdoptions.py:499 msgid "Whether to use Token-Groups" msgstr "Визначає, чи слід використовувати крупи реєстраційних записів" -#: src/config/SSSDConfig/sssdoptions.py:494 +#: src/config/SSSDConfig/sssdoptions.py:500 msgid "Set lower boundary for allowed IDs from the LDAP server" msgstr "Встановити нижню межу для дозволених ідентифікаторів із сервера LDAP" -#: src/config/SSSDConfig/sssdoptions.py:495 +#: src/config/SSSDConfig/sssdoptions.py:501 msgid "Set upper boundary for allowed IDs from the LDAP server" msgstr "Встановити верхню межу для дозволених ідентифікаторів із сервера LDAP" -#: src/config/SSSDConfig/sssdoptions.py:496 +#: src/config/SSSDConfig/sssdoptions.py:502 msgid "DN for ppolicy queries" msgstr "DN для запитів щодо ppolicy" -#: src/config/SSSDConfig/sssdoptions.py:497 +#: src/config/SSSDConfig/sssdoptions.py:503 msgid "How many maximum entries to fetch during a wildcard request" msgstr "" "Максимальна кількість записів для отримання під час обробки запитів із " "замінниками" -#: src/config/SSSDConfig/sssdoptions.py:498 +#: src/config/SSSDConfig/sssdoptions.py:504 msgid "Set libldap debug level" msgstr "Встановити рівень діагностики для libldap" -#: src/config/SSSDConfig/sssdoptions.py:501 +#: src/config/SSSDConfig/sssdoptions.py:507 msgid "Policy to evaluate the password expiration" msgstr "Правила оцінки завершення строку дії пароля" -#: src/config/SSSDConfig/sssdoptions.py:505 +#: src/config/SSSDConfig/sssdoptions.py:511 msgid "Which attributes shall be used to evaluate if an account is expired" msgstr "" "Атрибути які слід використовувати для визначення чинності облікового запису" -#: src/config/SSSDConfig/sssdoptions.py:509 +#: src/config/SSSDConfig/sssdoptions.py:515 msgid "URI of an LDAP server where password changes are allowed" msgstr "Адреса на сервері LDAP, для якої можливі зміни паролів" -#: src/config/SSSDConfig/sssdoptions.py:510 +#: src/config/SSSDConfig/sssdoptions.py:516 msgid "URI of a backup LDAP server where password changes are allowed" msgstr "Адреса резервного сервера LDAP, для якої можливі зміни паролів" -#: src/config/SSSDConfig/sssdoptions.py:511 +#: src/config/SSSDConfig/sssdoptions.py:517 msgid "DNS service name for LDAP password change server" msgstr "Назва у службі DNS сервера зміни паролів LDAP" -#: src/config/SSSDConfig/sssdoptions.py:512 +#: src/config/SSSDConfig/sssdoptions.py:518 msgid "" "Whether to update the ldap_user_shadow_last_change attribute after a " "password change" @@ -1861,29 +1910,29 @@ msgstr "" "Визначає, чи слід оновлювати атрибут ldap_user_shadow_last_change після " "зміни пароля" -#: src/config/SSSDConfig/sssdoptions.py:516 +#: src/config/SSSDConfig/sssdoptions.py:522 msgid "Base DN for sudo rules lookups" msgstr "Базова назва домену для пошуків правил sudo" -#: src/config/SSSDConfig/sssdoptions.py:517 +#: src/config/SSSDConfig/sssdoptions.py:523 msgid "Automatic full refresh period" msgstr "Період автоматичного повного оновлення даних" -#: src/config/SSSDConfig/sssdoptions.py:518 +#: src/config/SSSDConfig/sssdoptions.py:524 msgid "Automatic smart refresh period" msgstr "Період автоматичного кмітливого оновлення даних" -#: src/config/SSSDConfig/sssdoptions.py:519 +#: src/config/SSSDConfig/sssdoptions.py:525 msgid "Smart and full refresh random offset" msgstr "Випадковий кмітливий відступ і відступ повного оновлення" -#: src/config/SSSDConfig/sssdoptions.py:520 +#: src/config/SSSDConfig/sssdoptions.py:526 msgid "Whether to filter rules by hostname, IP addresses and network" msgstr "" "Визначає, чи слід фільтрувати правила за назвами вузлів, IP-адресами та " "мережами" -#: src/config/SSSDConfig/sssdoptions.py:521 +#: src/config/SSSDConfig/sssdoptions.py:527 msgid "" "Hostnames and/or fully qualified domain names of this machine to filter sudo " "rules" @@ -1891,155 +1940,155 @@ msgstr "" "Назви вузлів і/або повні назви у домені для цього комп’ютера для " "фільтрування списку правил sudo" -#: src/config/SSSDConfig/sssdoptions.py:522 +#: src/config/SSSDConfig/sssdoptions.py:528 msgid "IPv4 or IPv6 addresses or network of this machine to filter sudo rules" msgstr "" "Адреси IPv4 або IPv6 чи мережа цього комп’ютера для фільтрування списку " "правил sudo" -#: src/config/SSSDConfig/sssdoptions.py:523 +#: src/config/SSSDConfig/sssdoptions.py:529 msgid "Whether to include rules that contains netgroup in host attribute" msgstr "" "Визначає, чи слід включати правила, що містять мережеву групу у атрибуті " "вузла" -#: src/config/SSSDConfig/sssdoptions.py:524 +#: src/config/SSSDConfig/sssdoptions.py:530 msgid "" "Whether to include rules that contains regular expression in host attribute" msgstr "" "Визначає, чи слід включати правила, що містять формальний вираз у атрибуті " "вузла" -#: src/config/SSSDConfig/sssdoptions.py:525 +#: src/config/SSSDConfig/sssdoptions.py:531 msgid "Object class for sudo rules" msgstr "Клас об’єктів для правил sudo" -#: src/config/SSSDConfig/sssdoptions.py:526 +#: src/config/SSSDConfig/sssdoptions.py:532 msgid "Name of attribute that is used as object class for sudo rules" msgstr "Назва атрибута, який використано як клас об'єктів для правил sudo" -#: src/config/SSSDConfig/sssdoptions.py:527 +#: src/config/SSSDConfig/sssdoptions.py:533 msgid "Sudo rule name" msgstr "Назва правила sudo" -#: src/config/SSSDConfig/sssdoptions.py:528 +#: src/config/SSSDConfig/sssdoptions.py:534 msgid "Sudo rule command attribute" msgstr "Атрибут команди правила sudo" -#: src/config/SSSDConfig/sssdoptions.py:529 +#: src/config/SSSDConfig/sssdoptions.py:535 msgid "Sudo rule host attribute" msgstr "Атрибут вузла правила sudo" -#: src/config/SSSDConfig/sssdoptions.py:530 +#: src/config/SSSDConfig/sssdoptions.py:536 msgid "Sudo rule user attribute" msgstr "Атрибут користувача правила sudo" -#: src/config/SSSDConfig/sssdoptions.py:531 +#: src/config/SSSDConfig/sssdoptions.py:537 msgid "Sudo rule option attribute" msgstr "Атрибут параметрів правила sudo" -#: src/config/SSSDConfig/sssdoptions.py:532 +#: src/config/SSSDConfig/sssdoptions.py:538 msgid "Sudo rule runas attribute" msgstr "Атрибут runas правила sudo" -#: src/config/SSSDConfig/sssdoptions.py:533 +#: src/config/SSSDConfig/sssdoptions.py:539 msgid "Sudo rule runasuser attribute" msgstr "" "Атрибут користувача, від імені якого виконуватиметься запуск, правила sudo" -#: src/config/SSSDConfig/sssdoptions.py:534 +#: src/config/SSSDConfig/sssdoptions.py:540 msgid "Sudo rule runasgroup attribute" msgstr "Атрибут групи, від імені якої виконуватиметься запуск, правила sudo" -#: src/config/SSSDConfig/sssdoptions.py:535 +#: src/config/SSSDConfig/sssdoptions.py:541 msgid "Sudo rule notbefore attribute" msgstr "Атрибут граничного часу початку дії правила sudo" -#: src/config/SSSDConfig/sssdoptions.py:536 +#: src/config/SSSDConfig/sssdoptions.py:542 msgid "Sudo rule notafter attribute" msgstr "Атрибут граничного часу завершення дії правила sudo" -#: src/config/SSSDConfig/sssdoptions.py:537 +#: src/config/SSSDConfig/sssdoptions.py:543 msgid "Sudo rule order attribute" msgstr "Атрибут порядку правила sudo" -#: src/config/SSSDConfig/sssdoptions.py:540 +#: src/config/SSSDConfig/sssdoptions.py:546 msgid "Object class for automounter maps" msgstr "Клас об’єктів для карт автоматичного монтування" -#: src/config/SSSDConfig/sssdoptions.py:541 +#: src/config/SSSDConfig/sssdoptions.py:547 msgid "Automounter map name attribute" msgstr "Атрибут назви карти автоматичного монтування" -#: src/config/SSSDConfig/sssdoptions.py:542 +#: src/config/SSSDConfig/sssdoptions.py:548 msgid "Object class for automounter map entries" msgstr "Клас об’єктів для записів карт автоматичного монтування" -#: src/config/SSSDConfig/sssdoptions.py:543 +#: src/config/SSSDConfig/sssdoptions.py:549 msgid "Automounter map entry key attribute" msgstr "Атрибут ключа запису карти автоматичного монтування" -#: src/config/SSSDConfig/sssdoptions.py:544 +#: src/config/SSSDConfig/sssdoptions.py:550 msgid "Automounter map entry value attribute" msgstr "Атрибут значення запису карти автоматичного монтування" -#: src/config/SSSDConfig/sssdoptions.py:545 +#: src/config/SSSDConfig/sssdoptions.py:551 msgid "Base DN for automounter map lookups" msgstr "Базовий сервер назв домену для пошуків карти автоматичного монтування" -#: src/config/SSSDConfig/sssdoptions.py:546 +#: src/config/SSSDConfig/sssdoptions.py:552 msgid "The name of the automount master map in LDAP." msgstr "Назва основної карти автоматичного монтування у LDAP." -#: src/config/SSSDConfig/sssdoptions.py:549 +#: src/config/SSSDConfig/sssdoptions.py:555 msgid "Base DN for IP hosts lookups" msgstr "Базова назва домену для пошуків IP-вузлів" -#: src/config/SSSDConfig/sssdoptions.py:550 +#: src/config/SSSDConfig/sssdoptions.py:556 msgid "Object class for IP hosts" msgstr "Клас об'єктів для IP-вузлів" -#: src/config/SSSDConfig/sssdoptions.py:551 +#: src/config/SSSDConfig/sssdoptions.py:557 msgid "IP host name attribute" msgstr "Атрибут назви IP-вузла" -#: src/config/SSSDConfig/sssdoptions.py:552 +#: src/config/SSSDConfig/sssdoptions.py:558 msgid "IP host number (address) attribute" msgstr "Атрибут номер (адреси) IP-вузла" -#: src/config/SSSDConfig/sssdoptions.py:553 +#: src/config/SSSDConfig/sssdoptions.py:559 msgid "IP host entryUSN attribute" msgstr "Атрибут entryUSN IP-вузла" -#: src/config/SSSDConfig/sssdoptions.py:554 +#: src/config/SSSDConfig/sssdoptions.py:560 msgid "Base DN for IP networks lookups" msgstr "Базова назва домену для пошуків IP-мереж" -#: src/config/SSSDConfig/sssdoptions.py:555 +#: src/config/SSSDConfig/sssdoptions.py:561 msgid "Object class for IP networks" msgstr "Клас об'єктів для IP-мереж" -#: src/config/SSSDConfig/sssdoptions.py:556 +#: src/config/SSSDConfig/sssdoptions.py:562 msgid "IP network name attribute" msgstr "Атрибут назви IP-мережі" -#: src/config/SSSDConfig/sssdoptions.py:557 +#: src/config/SSSDConfig/sssdoptions.py:563 msgid "IP network number (address) attribute" msgstr "Атрибут номер (адреси) IP-мережі" -#: src/config/SSSDConfig/sssdoptions.py:558 +#: src/config/SSSDConfig/sssdoptions.py:564 msgid "IP network entryUSN attribute" msgstr "Атрибут entryUSN IP-мережі" -#: src/config/SSSDConfig/sssdoptions.py:561 +#: src/config/SSSDConfig/sssdoptions.py:567 msgid "Comma separated list of allowed users" msgstr "Відокремлений комами список дозволених користувачів" -#: src/config/SSSDConfig/sssdoptions.py:562 +#: src/config/SSSDConfig/sssdoptions.py:568 msgid "Comma separated list of prohibited users" msgstr "Відокремлений комами список заборонених користувачів" -#: src/config/SSSDConfig/sssdoptions.py:563 +#: src/config/SSSDConfig/sssdoptions.py:569 msgid "" "Comma separated list of groups that are allowed to log in. This applies only " "to groups within this SSSD domain. Local groups are not evaluated." @@ -2048,7 +2097,7 @@ msgstr "" "системи. Стосується лише груп у межах цього домену SSSD. Локальні групи не " "обробляються." -#: src/config/SSSDConfig/sssdoptions.py:565 +#: src/config/SSSDConfig/sssdoptions.py:571 msgid "" "Comma separated list of groups that are explicitly denied access. This " "applies only to groups within this SSSD domain. Local groups are not " @@ -2058,34 +2107,34 @@ msgstr "" "Стосується лише груп у межах цього домену SSSD. Локальні групи не " "обробляються." -#: src/config/SSSDConfig/sssdoptions.py:569 +#: src/config/SSSDConfig/sssdoptions.py:575 msgid "The number of preforked proxy children." msgstr "Кількість попередньо відгалужених дочірніх проксі-записів." -#: src/config/SSSDConfig/sssdoptions.py:572 +#: src/config/SSSDConfig/sssdoptions.py:578 msgid "The name of the NSS library to use" msgstr "Назва бібліотеки NSS, яку слід використовувати" -#: src/config/SSSDConfig/sssdoptions.py:573 +#: src/config/SSSDConfig/sssdoptions.py:579 msgid "The name of the NSS library to use for hosts and networks lookups" msgstr "" "Назва бібліотеки NSS, яку слід використовувати для пошуків вузлів і мереж" -#: src/config/SSSDConfig/sssdoptions.py:574 +#: src/config/SSSDConfig/sssdoptions.py:580 msgid "Whether to look up canonical group name from cache if possible" msgstr "" "Визначає, чи слід виконувати пошук канонічної назви групи у кеші, якщо це " "можливо" -#: src/config/SSSDConfig/sssdoptions.py:577 +#: src/config/SSSDConfig/sssdoptions.py:583 msgid "PAM stack to use" msgstr "Стек PAM, який слід використовувати" -#: src/config/SSSDConfig/sssdoptions.py:580 +#: src/config/SSSDConfig/sssdoptions.py:586 msgid "Path of passwd file sources." msgstr "Шлях до початкового тексту файла passwd." -#: src/config/SSSDConfig/sssdoptions.py:581 +#: src/config/SSSDConfig/sssdoptions.py:587 msgid "Path of group file sources." msgstr "Шлях до початкового тексту файла group." @@ -2117,108 +2166,112 @@ msgid "Option -i|--interactive is not allowed together with -D|--daemon\n" msgstr "" "Параметр -i|--interactive не можна поєднувати із параметром -D|--daemon\n" -#: src/monitor/monitor.c:1836 +#: src/monitor/monitor.c:1838 msgid "Failed to get initial capabilities\n" msgstr "Не вдалося отримати початкові можливості\n" -#: src/monitor/monitor.c:1847 +#: src/monitor/monitor.c:1849 msgid "Non-root service user support isn't built. Can't run under %" msgstr "" "Підтримку служб користувача поза root не зібрано. Неможливий запуск від %" -#: src/monitor/monitor.c:1864 +#: src/monitor/monitor.c:1866 #, c-format msgid "Can't read config: '%s'\n" msgstr "Не вдалося прочитати налаштування: '%s'\n" -#: src/monitor/monitor.c:1876 -#, c-format -msgid "Failed to boostrap SSSD 'monitor' process: %s" +#: src/monitor/monitor.c:1878 +#, fuzzy, c-format +msgid "Failed to bootstrap SSSD 'monitor' process: %s" msgstr "Не вдалося виконати початкове завантаження процесу «monitor» SSSD: %s" -#: src/monitor/monitor.c:1971 +#: src/monitor/monitor.c:1973 msgid "Out of memory\n" msgstr "Не вистачає пам'яті\n" -#: src/providers/krb5/krb5_child.c:4221 +#: src/providers/krb5/krb5_child.c:4316 msgid "Use anonymous PKINIT to request FAST armor ticket" msgstr "Анонімний PKINIT для запитів щодо квитка захисту FAST" -#: src/providers/krb5/krb5_child.c:4223 +#: src/providers/krb5/krb5_child.c:4318 msgid "Kerberos realm to use" msgstr "Область Kerberos, якою слід скористатися" -#: src/providers/krb5/krb5_child.c:4225 +#: src/providers/krb5/krb5_child.c:4320 msgid "Requested lifetime of the ticket" msgstr "Запитаний строк дії квитка" -#: src/providers/krb5/krb5_child.c:4227 +#: src/providers/krb5/krb5_child.c:4322 msgid "Requested renewable lifetime of the ticket" msgstr "Запитаний час оновлення строку дії квитка" -#: src/providers/krb5/krb5_child.c:4229 +#: src/providers/krb5/krb5_child.c:4324 msgid "FAST options ('never', 'try', 'demand')" msgstr "Параметри FAST ('never', 'try', 'demand')" -#: src/providers/krb5/krb5_child.c:4232 +#: src/providers/krb5/krb5_child.c:4327 msgid "Specifies the server principal to use for FAST" msgstr "" "Визначає реєстраційний запис сервера, який слід використовувати для FAST" -#: src/providers/krb5/krb5_child.c:4234 +#: src/providers/krb5/krb5_child.c:4329 msgid "Requests canonicalization of the principal name" msgstr "Вимагає перетворення реєстраційного запису у канонічну форму" -#: src/providers/krb5/krb5_child.c:4236 +#: src/providers/krb5/krb5_child.c:4331 msgid "Use custom version of krb5_get_init_creds_password" msgstr "Використовувати нетипову версію krb5_get_init_creds_password" -#: src/providers/krb5/krb5_child.c:4238 +#: src/providers/krb5/krb5_child.c:4333 msgid "Check PAC flags" msgstr "Перевірити прапорці PAC" -#: src/providers/data_provider_be.c:790 +#: src/providers/krb5/krb5_child.c:4335 +msgid "Set environment variable (KEY=VALUE)" +msgstr "" + +#: src/providers/data_provider_be.c:786 msgid "Domain of the information provider (mandatory)" msgstr "Домен надання відомостей (обов’язковий)" -#: src/sss_client/common.c:1165 +#: src/sss_client/common.c:1208 msgid "Socket has wrong ownership or permissions." msgstr "Сокет має помилкового власника або помилкові права доступу." -#: src/sss_client/common.c:1168 +#: src/sss_client/common.c:1211 msgid "Unexpected format of the server credential message." msgstr "Некоректний формат повідомлення щодо реєстраційних даних сервера." -#: src/sss_client/common.c:1171 +#: src/sss_client/common.c:1214 msgid "SSSD is not run by trusted user." msgstr "SSSD запущено не від імені довіреного користувача." -#: src/sss_client/common.c:1174 +#: src/sss_client/common.c:1217 msgid "SSSD socket does not exist." msgstr "Сокета SSSD не існує." -#: src/sss_client/common.c:1177 +#: src/sss_client/common.c:1220 msgid "Cannot get stat of SSSD socket." msgstr "Не вдалося отримати статистику щодо сокета SSSD." -#: src/sss_client/common.c:1182 +#: src/sss_client/common.c:1225 msgid "An error occurred, but no description can be found." msgstr "Сталася помилка, але не вдалося знайти її опису." -#: src/sss_client/common.c:1188 +#: src/sss_client/common.c:1231 msgid "Unexpected error while looking for an error description" msgstr "Неочікувана помилка під час пошуку опису помилки" -#: src/sss_client/pam_sss.c:74 +#: src/sss_client/pam_sss.c:135 msgid "Permission denied. " msgstr "Відмовлено у доступі. " -#: src/sss_client/pam_sss.c:75 src/sss_client/pam_sss.c:843 -#: src/sss_client/pam_sss.c:854 +#: src/sss_client/pam_sss.c:136 src/sss_client/pam_sss.c:921 +#: src/sss_client/pam_sss.c:932 msgid "Server message: " msgstr "Повідомлення сервера: " -#: src/sss_client/pam_sss.c:76 +#: src/sss_client/pam_sss.c:137 msgid "" "Kerberos TGT will not be granted upon login, user experience will be " "affected." @@ -2226,50 +2279,50 @@ msgstr "" "Після входу до системи не буде надано TGT Kerberos. Це може завадити " "нормальній роботі користувача." -#: src/sss_client/pam_sss.c:77 +#: src/sss_client/pam_sss.c:138 msgid "Enter PIN:" msgstr "Введіть PIN:" -#: src/sss_client/pam_sss.c:320 +#: src/sss_client/pam_sss.c:385 msgid "Passwords do not match" msgstr "Паролі не збігаються" -#: src/sss_client/pam_sss.c:508 +#: src/sss_client/pam_sss.c:584 msgid "Password reset by root is not supported." msgstr "Підтримки скидання пароля користувачем root не передбачено." -#: src/sss_client/pam_sss.c:549 +#: src/sss_client/pam_sss.c:625 msgid "Authenticated with cached credentials" msgstr "Розпізнано за реєстраційними даними з кешу" -#: src/sss_client/pam_sss.c:550 +#: src/sss_client/pam_sss.c:626 msgid ", your cached password will expire at: " msgstr ", строк дії вашого кешованого пароля завершиться: " -#: src/sss_client/pam_sss.c:580 +#: src/sss_client/pam_sss.c:656 #, c-format msgid "Your password has expired. You have %1$d grace login(s) remaining." msgstr "Строк дії вашого пароля вичерпано. Залишилося %1$d резервних входи." -#: src/sss_client/pam_sss.c:630 +#: src/sss_client/pam_sss.c:706 #, c-format msgid "Your password will expire in %1$d %2$s." msgstr "Строк дії вашого пароля завершиться за %1$d %2$s." -#: src/sss_client/pam_sss.c:633 +#: src/sss_client/pam_sss.c:709 #, c-format msgid "Your password has expired." msgstr "Строк дії вашого пароля вичерпано." -#: src/sss_client/pam_sss.c:684 +#: src/sss_client/pam_sss.c:760 msgid "Authentication is denied until: " msgstr "Розпізнавання заборонено до: " -#: src/sss_client/pam_sss.c:705 +#: src/sss_client/pam_sss.c:781 msgid "System is offline, password change not possible" msgstr "Система працює у автономному режимі, зміна пароля неможлива" -#: src/sss_client/pam_sss.c:720 +#: src/sss_client/pam_sss.c:796 msgid "" "After changing the OTP password, you need to log out and back in order to " "acquire a ticket" @@ -2277,11 +2330,11 @@ msgstr "" "Після зміни пароля OTP вам слід вийти із системи і увійти до неї знову, щоб " "отримати про квиток" -#: src/sss_client/pam_sss.c:735 +#: src/sss_client/pam_sss.c:813 msgid "PIN locked" msgstr "PIN заблоковано" -#: src/sss_client/pam_sss.c:750 +#: src/sss_client/pam_sss.c:828 msgid "" "No Kerberos TGT granted as the server does not support this method. Your " "single-sign on(SSO) experience will be affected." @@ -2289,61 +2342,66 @@ msgstr "" "Не надано TGT Kerberos, оскільки на сервері не передбачено підтримки цього " "методу. Це завадить використанню single-sign on(SSO)." -#: src/sss_client/pam_sss.c:840 src/sss_client/pam_sss.c:853 +#: src/sss_client/pam_sss.c:918 src/sss_client/pam_sss.c:931 msgid "Password change failed. " msgstr "Спроба зміни пароля зазнала невдачі. " -#: src/sss_client/pam_sss.c:1859 -#, c-format -msgid "Authenticate at %1$s and press ENTER." +#: src/sss_client/pam_sss.c:2028 +#, fuzzy, c-format +msgid "Authenticate at \"%1$s\"." msgstr "Пройдіть розпізнавання на %1$s і натисніть ENTER." -#: src/sss_client/pam_sss.c:1862 -#, c-format -msgid "Authenticate with PIN %1$s at %2$s and press ENTER." -msgstr "Пройдіть розпізнавання за допомогою PIN %1$s на %2$s і натисніть ENTER." +#: src/sss_client/pam_sss.c:2031 +#, fuzzy, c-format +msgid "Authenticate with PIN \"%1$s\" at \"%2$s\"." +msgstr "" +"Пройдіть розпізнавання за допомогою PIN %1$s на %2$s і натисніть ENTER." -#: src/sss_client/pam_sss.c:2281 +#: src/sss_client/pam_sss.c:2470 msgid "Please (re)insert (different) Smartcard" msgstr "Будь ласка, вставте (повторно) (іншу) смарт-картку" -#: src/sss_client/pam_sss.c:2482 +#: src/sss_client/pam_sss.c:2700 msgid "New Password: " msgstr "Новий пароль: " -#: src/sss_client/pam_sss.c:2483 +#: src/sss_client/pam_sss.c:2701 msgid "Reenter new Password: " msgstr "Ще раз введіть новий пароль: " -#: src/sss_client/pam_sss.c:2676 src/sss_client/pam_sss.c:2679 +#: src/sss_client/pam_sss.c:2890 +msgid "Press ENTER to continue." +msgstr "" + +#: src/sss_client/pam_sss.c:2913 src/sss_client/pam_sss.c:2916 msgid "First Factor: " msgstr "Перший фактор: " -#: src/sss_client/pam_sss.c:2677 src/sss_client/pam_sss.c:2851 +#: src/sss_client/pam_sss.c:2914 src/sss_client/pam_sss.c:3088 msgid "Second Factor (optional): " msgstr "Другий фактор (необов'язковий): " -#: src/sss_client/pam_sss.c:2680 src/sss_client/pam_sss.c:2855 +#: src/sss_client/pam_sss.c:2917 src/sss_client/pam_sss.c:3092 msgid "Second Factor: " msgstr "Другий фактор: " -#: src/sss_client/pam_sss.c:2684 +#: src/sss_client/pam_sss.c:2921 msgid "Insert your passkey device, then press ENTER." msgstr "Вставте ваш пристрій ключа і натисніть клавішу ENTER." -#: src/sss_client/pam_sss.c:2688 src/sss_client/pam_sss.c:2696 +#: src/sss_client/pam_sss.c:2925 src/sss_client/pam_sss.c:2933 msgid "Password: " msgstr "Пароль: " -#: src/sss_client/pam_sss.c:2850 src/sss_client/pam_sss.c:2854 +#: src/sss_client/pam_sss.c:3087 src/sss_client/pam_sss.c:3091 msgid "First Factor (Current Password): " msgstr "Перший фактор (поточний пароль): " -#: src/sss_client/pam_sss.c:2874 +#: src/sss_client/pam_sss.c:3111 msgid "Current Password: " msgstr "Поточний пароль: " -#: src/sss_client/pam_sss.c:3248 +#: src/sss_client/pam_sss.c:3485 msgid "Password expired. Change your password now." msgstr "Строк дії пароля вичерпано. Змініть ваш пароль." @@ -2787,9 +2845,9 @@ msgstr "Не вдалося надрукувати об'єкт: %s\n" #: src/tools/sssctl/sssctl_cache.c:835 src/tools/sssctl/sssctl_cache.c:918 #: src/tools/sssctl/sssctl_cache.c:950 src/tools/sssctl/sssctl_cache.c:956 #: src/tools/sssctl/sssctl_cache.c:1010 src/tools/sssctl/sssctl_cache.c:1034 -#: src/tools/sssctl/sssctl_cache.c:1085 src/tools/sssctl/sssctl_cache.c:1194 -#: src/tools/sssctl/sssctl_cache.c:1229 src/tools/sssctl/sssctl_cache.c:1235 -#: src/tools/sssctl/sssctl_cache.c:1244 +#: src/tools/sssctl/sssctl_cache.c:1085 src/tools/sssctl/sssctl_cache.c:1195 +#: src/tools/sssctl/sssctl_cache.c:1230 src/tools/sssctl/sssctl_cache.c:1236 +#: src/tools/sssctl/sssctl_cache.c:1245 msgid "talloc failed\n" msgstr "Помилка talloc\n" @@ -2865,25 +2923,25 @@ msgstr "Кешований шлях GPO [%s] не перебуває у [%s], і msgid "Unable to remove downloaded GPO files: %s\n" msgstr "Не вдалося вилучити отримані файли GPO: %s\n" -#: src/tools/sssctl/sssctl_cache.c:1165 +#: src/tools/sssctl/sssctl_cache.c:1166 #, c-format msgid "Failed to fetch cache entry: %s\n" msgstr "Не вдалося отримати запис кешу: %s\n" -#: src/tools/sssctl/sssctl_cache.c:1170 +#: src/tools/sssctl/sssctl_cache.c:1171 msgid "Could not determine object domain\n" msgstr "Не вдалося визначити домен об'єкта\n" -#: src/tools/sssctl/sssctl_cache.c:1200 +#: src/tools/sssctl/sssctl_cache.c:1201 msgid "Could not find GUID attribute in GPO entry\n" msgstr "Не вдалося знайти атрибут GUID у записі GPO\n" -#: src/tools/sssctl/sssctl_cache.c:1206 +#: src/tools/sssctl/sssctl_cache.c:1207 #, c-format msgid "Failed to delete GPO: %s\n" msgstr "Не вдалося вилучити GPO: %s\n" -#: src/tools/sssctl/sssctl_cache.c:1210 +#: src/tools/sssctl/sssctl_cache.c:1211 #, c-format msgid "%s removed from cache\n" msgstr "%s вилучено з кешу\n" @@ -2950,7 +3008,8 @@ msgstr "Сертифікат не відповідає правилу.\n" #: src/tools/sssctl/sssctl_cert.c:265 #, c-format msgid "Error during certificate matching [%d][%s].\n" -msgstr "Помилка під час спроби встановити відповідність сертифіката [%d][%s].\n" +msgstr "" +"Помилка під час спроби встановити відповідність сертифіката [%d][%s].\n" #: src/tools/sssctl/sssctl_cert.c:272 #, c-format @@ -2981,39 +3040,40 @@ msgstr "" "файлом налаштувань є «/my/path/sssd.conf», буде використано каталог " "фрагментів «/my/path/conf.d»)" -#: src/tools/sssctl/sssctl_config.c:114 +#: src/tools/sssctl/sssctl_config.c:126 #, c-format msgid "File %1$s does not exist.\n" msgstr "Файла %1$s не існує.\n" -#: src/tools/sssctl/sssctl_config.c:115 +#: src/tools/sssctl/sssctl_config.c:127 msgid "There is no configuration.\n" msgstr "Немає налаштувань.\n" -#: src/tools/sssctl/sssctl_config.c:120 +#: src/tools/sssctl/sssctl_config.c:132 #, c-format msgid "Configuration validation failed: %s\n" msgstr "Не пройдено перевірку налаштувань: %s\n" -#: src/tools/sssctl/sssctl_config.c:121 +#: src/tools/sssctl/sssctl_config.c:133 msgid "Run with high debug level to see details.\n" msgstr "Запустіть із вищим рівнем діагностики, щоб переглянути подробиці.\n" -#: src/tools/sssctl/sssctl_config.c:130 -msgid "Failed to run validators" +#: src/tools/sssctl/sssctl_config.c:142 +#, fuzzy +msgid "Failed to run validators\n" msgstr "Не вдалося запустити засоби перевірки" -#: src/tools/sssctl/sssctl_config.c:134 +#: src/tools/sssctl/sssctl_config.c:146 #, c-format msgid "Issues identified by validators: %zu\n" msgstr "Вади, які виявлено засобами перевірки: %zu\n" -#: src/tools/sssctl/sssctl_config.c:145 +#: src/tools/sssctl/sssctl_config.c:157 #, c-format msgid "Messages generated during configuration merging: %zu\n" msgstr "Повідомлення, створені під час об'єднування налаштувань: %zu\n" -#: src/tools/sssctl/sssctl_config.c:158 +#: src/tools/sssctl/sssctl_config.c:170 #, c-format msgid "Used configuration snippet files: %zu\n" msgstr "Використаних файлів фрагментів налаштувань: %zu\n" diff --git a/po/zh_CN.po b/po/zh_CN.po index 3cabf461631..fb7b14e265f 100644 --- a/po/zh_CN.po +++ b/po/zh_CN.po @@ -14,8 +14,8 @@ msgid "" msgstr "" "Project-Id-Version: PACKAGE VERSION\n" "Report-Msgid-Bugs-To: sssd-devel@lists.fedorahosted.org\n" -"POT-Creation-Date: 2026-01-14 14:57+0000\n" -"PO-Revision-Date: 2026-04-23 16:59+0000\n" +"POT-Creation-Date: 2026-10-02 15:57+0000\n" +"PO-Revision-Date: 2026-10-05 16:49+0000\n" "Last-Translator: Charles Lee \n" "Language-Team: Chinese (Simplified) \n" @@ -24,50 +24,50 @@ msgstr "" "Content-Type: text/plain; charset=UTF-8\n" "Content-Transfer-Encoding: 8bit\n" "Plural-Forms: nplurals=1; plural=0;\n" -"X-Generator: Weblate 5.17\n" +"X-Generator: Weblate 2026.10\n" -#: src/config/SSSDConfig/sssdoptions.py:20 -#: src/config/SSSDConfig/sssdoptions.py:21 +#: src/config/SSSDConfig/sssdoptions.py:16 +#: src/config/SSSDConfig/sssdoptions.py:17 msgid "Set the verbosity of the debug logging" msgstr "设定调试日志的详细程度" -#: src/config/SSSDConfig/sssdoptions.py:22 +#: src/config/SSSDConfig/sssdoptions.py:18 msgid "Include timestamps in debug logs" msgstr "在调试日志中包含时间戳" -#: src/config/SSSDConfig/sssdoptions.py:23 +#: src/config/SSSDConfig/sssdoptions.py:19 msgid "Include microseconds in timestamps in debug logs" msgstr "在调试日志中的时间戳中包含微秒" -#: src/config/SSSDConfig/sssdoptions.py:24 +#: src/config/SSSDConfig/sssdoptions.py:20 msgid "Enable/disable debug backtrace" msgstr "启用/禁用 debug backtrace" -#: src/config/SSSDConfig/sssdoptions.py:25 +#: src/config/SSSDConfig/sssdoptions.py:21 msgid "Watchdog timeout before restarting service" msgstr "重新启动服务前 Watchdog 超时" -#: src/config/SSSDConfig/sssdoptions.py:26 +#: src/config/SSSDConfig/sssdoptions.py:22 msgid "Command to start service" msgstr "启动服务命令" -#: src/config/SSSDConfig/sssdoptions.py:27 +#: src/config/SSSDConfig/sssdoptions.py:23 msgid "The number of file descriptors that may be opened by this responder" msgstr "可能会被该响应者打开的文件描述符的数量" -#: src/config/SSSDConfig/sssdoptions.py:28 +#: src/config/SSSDConfig/sssdoptions.py:24 msgid "Idle time before automatic disconnection of a client" msgstr "客户端自动断开连接之前的空闲时间" -#: src/config/SSSDConfig/sssdoptions.py:29 +#: src/config/SSSDConfig/sssdoptions.py:25 msgid "Idle time before automatic shutdown of the responder" msgstr "自动关闭响应者之前的空闲时间" -#: src/config/SSSDConfig/sssdoptions.py:30 +#: src/config/SSSDConfig/sssdoptions.py:26 msgid "Always query all the caches before querying the Data Providers" msgstr "在查询 Data Providers 之前,始终查询所有缓存" -#: src/config/SSSDConfig/sssdoptions.py:31 +#: src/config/SSSDConfig/sssdoptions.py:27 msgid "" "When SSSD switches to offline mode the amount of time before it tries to go " "back online will increase based upon the time spent disconnected. This value " @@ -77,65 +77,65 @@ msgstr "" "当 SSSD 切换到脱机模式时,它尝试重新上线前的时间会根据断开连接的时间而增加。" "这个值以秒为单位,并使用以下公式计算:offline_timeout + random_offset。" -#: src/config/SSSDConfig/sssdoptions.py:36 +#: src/config/SSSDConfig/sssdoptions.py:32 msgid "SSSD Services to start" msgstr "SSSD 服务启动" -#: src/config/SSSDConfig/sssdoptions.py:37 +#: src/config/SSSDConfig/sssdoptions.py:33 msgid "SSSD Domains to start" msgstr "SSSD 域启动" -#: src/config/SSSDConfig/sssdoptions.py:38 +#: src/config/SSSDConfig/sssdoptions.py:34 msgid "Regex to parse username and domain" msgstr "正则表达式解析用户名和域" -#: src/config/SSSDConfig/sssdoptions.py:39 +#: src/config/SSSDConfig/sssdoptions.py:35 msgid "Printf-compatible format for displaying fully-qualified names" msgstr "兼容 Printf 的格式用于显示完全限定名称" -#: src/config/SSSDConfig/sssdoptions.py:40 +#: src/config/SSSDConfig/sssdoptions.py:36 msgid "" "Directory on the filesystem where SSSD should store Kerberos replay cache " "files." msgstr "SSSD 应该在其中存储 Kerberos 重放缓存文件的文件系统上的目录。" -#: src/config/SSSDConfig/sssdoptions.py:41 +#: src/config/SSSDConfig/sssdoptions.py:37 msgid "Domain to add to names without a domain component." msgstr "要添加到名称中的域,没有域组件。" -#: src/config/SSSDConfig/sssdoptions.py:42 +#: src/config/SSSDConfig/sssdoptions.py:38 msgid "The user to drop privileges to" msgstr "放弃特权的用户" -#: src/config/SSSDConfig/sssdoptions.py:43 +#: src/config/SSSDConfig/sssdoptions.py:39 msgid "Tune certificate verification" msgstr "调整证书验证" -#: src/config/SSSDConfig/sssdoptions.py:44 +#: src/config/SSSDConfig/sssdoptions.py:40 msgid "All spaces in group or user names will be replaced with this character" msgstr "组或用户名中的所有空格都将替换为该字符" -#: src/config/SSSDConfig/sssdoptions.py:45 +#: src/config/SSSDConfig/sssdoptions.py:41 msgid "Tune sssd to honor or ignore netlink state changes" msgstr "调整 sssd 来接受或忽略 netlink 状态更改" -#: src/config/SSSDConfig/sssdoptions.py:46 +#: src/config/SSSDConfig/sssdoptions.py:42 msgid "Enable or disable the implicit files domain" msgstr "启用或禁用隐式文件域" -#: src/config/SSSDConfig/sssdoptions.py:47 +#: src/config/SSSDConfig/sssdoptions.py:43 msgid "A specific order of the domains to be looked up" msgstr "要查询的域的特定顺序" -#: src/config/SSSDConfig/sssdoptions.py:48 +#: src/config/SSSDConfig/sssdoptions.py:44 msgid "" "Controls if SSSD should monitor the state of resolv.conf to identify when it " "needs to update its internal DNS resolver." msgstr "" -"控制 SSSD 是否应监控 resolv.conf 的状态,以确定何时需要更新其内部 DNS 解析器" -"。" +"控制 SSSD 是否应监控 resolv.conf 的状态,以确定何时需要更新其内部 DNS 解析" +"器。" -#: src/config/SSSDConfig/sssdoptions.py:50 +#: src/config/SSSDConfig/sssdoptions.py:46 msgid "" "SSSD monitors the state of resolv.conf to identify when it needs to update " "its internal DNS resolver. By default, we will attempt to use inotify for " @@ -146,84 +146,84 @@ msgstr "" "下,我们会尝试使用 inotify 进行。如果不能使用 inotify,则会回到每五秒轮询一" "次 resolv.conf 的状态。" -#: src/config/SSSDConfig/sssdoptions.py:53 +#: src/config/SSSDConfig/sssdoptions.py:49 msgid "Run PAC responder automatically for AD and IPA provider" msgstr "为 AD 和 IPA 提供商自动运行 PAC 响应器" -#: src/config/SSSDConfig/sssdoptions.py:54 +#: src/config/SSSDConfig/sssdoptions.py:50 msgid "Enable or disable core dumps for all SSSD processes." msgstr "为所有 SSSD 进程启用或禁用内核转储。" -#: src/config/SSSDConfig/sssdoptions.py:55 +#: src/config/SSSDConfig/sssdoptions.py:51 msgid "Tune passkey verification behavior" msgstr "调整密码验证行为" -#: src/config/SSSDConfig/sssdoptions.py:58 +#: src/config/SSSDConfig/sssdoptions.py:54 msgid "Enumeration cache timeout length (seconds)" msgstr "枚举缓存超时时间(秒)" -#: src/config/SSSDConfig/sssdoptions.py:59 +#: src/config/SSSDConfig/sssdoptions.py:55 msgid "Entry cache background update timeout length (seconds)" msgstr "条目缓存后台更新超时时间(秒)" -#: src/config/SSSDConfig/sssdoptions.py:60 -#: src/config/SSSDConfig/sssdoptions.py:125 +#: src/config/SSSDConfig/sssdoptions.py:56 +#: src/config/SSSDConfig/sssdoptions.py:124 msgid "Negative cache timeout length (seconds)" msgstr "负缓存超时时间(秒)" -#: src/config/SSSDConfig/sssdoptions.py:61 +#: src/config/SSSDConfig/sssdoptions.py:57 msgid "Users that SSSD should explicitly ignore" msgstr "SSSD 应该明确忽略的用户" -#: src/config/SSSDConfig/sssdoptions.py:62 +#: src/config/SSSDConfig/sssdoptions.py:58 msgid "Groups that SSSD should explicitly ignore" msgstr "SSSD 应该明确忽略的组" -#: src/config/SSSDConfig/sssdoptions.py:63 +#: src/config/SSSDConfig/sssdoptions.py:59 msgid "Should filtered users appear in groups" msgstr "出现在组中的应将过滤的用户" -#: src/config/SSSDConfig/sssdoptions.py:64 +#: src/config/SSSDConfig/sssdoptions.py:60 msgid "The value of the password field the NSS provider should return" msgstr "NSS 提供程序应返回的密码字段的值" -#: src/config/SSSDConfig/sssdoptions.py:65 +#: src/config/SSSDConfig/sssdoptions.py:61 msgid "Override homedir value from the identity provider with this value" msgstr "使用此值覆盖来自身份提供者的 homedir 值" -#: src/config/SSSDConfig/sssdoptions.py:66 +#: src/config/SSSDConfig/sssdoptions.py:62 msgid "" "Substitute empty homedir value from the identity provider with this value" msgstr "使用此值替换来自身份提供者的空的 homedir 值" -#: src/config/SSSDConfig/sssdoptions.py:67 +#: src/config/SSSDConfig/sssdoptions.py:63 msgid "Override shell value from the identity provider with this value" msgstr "使用此值覆盖来自身份提供者的 shell 值" -#: src/config/SSSDConfig/sssdoptions.py:68 +#: src/config/SSSDConfig/sssdoptions.py:64 msgid "The list of shells users are allowed to log in with" msgstr "允许进行登陆的 shell 用户列表" -#: src/config/SSSDConfig/sssdoptions.py:69 +#: src/config/SSSDConfig/sssdoptions.py:65 msgid "" "The list of shells that will be vetoed, and replaced with the fallback shell" msgstr "将被否决并替换为后备 shell 的 shell 列表" -#: src/config/SSSDConfig/sssdoptions.py:70 +#: src/config/SSSDConfig/sssdoptions.py:66 msgid "" "If a shell stored in central directory is allowed but not available, use " "this fallback" msgstr "如果允许使用存储在中央目录中的 shell 但并不存在,使用这个后备" -#: src/config/SSSDConfig/sssdoptions.py:71 +#: src/config/SSSDConfig/sssdoptions.py:67 msgid "Shell to use if the provider does not list one" msgstr "如果提供程序未列出,则使用这个 shell" -#: src/config/SSSDConfig/sssdoptions.py:72 +#: src/config/SSSDConfig/sssdoptions.py:68 msgid "How long will be in-memory cache records valid" msgstr "内存缓存记录有效期的长度" -#: src/config/SSSDConfig/sssdoptions.py:74 +#: src/config/SSSDConfig/sssdoptions.py:70 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for passwd requests" @@ -231,13 +231,14 @@ msgstr "" "为 passwd 请求在快速内存缓存(in-memory cache)中分配的数据表的大小(以 MB 为" "单位)" -#: src/config/SSSDConfig/sssdoptions.py:76 +#: src/config/SSSDConfig/sssdoptions.py:72 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for group requests" -msgstr "为组请求在快速内存缓存(in-memory cache)中分配的数据表的大小(以 MB 为单位)" +msgstr "" +"为组请求在快速内存缓存(in-memory cache)中分配的数据表的大小(以 MB 为单位)" -#: src/config/SSSDConfig/sssdoptions.py:78 +#: src/config/SSSDConfig/sssdoptions.py:74 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for initgroups requests" @@ -245,7 +246,7 @@ msgstr "" "为 initgroups 请求在快速内存缓存(in-memory cache)中分配的数据表的大小(以 " "MB 为单位)" -#: src/config/SSSDConfig/sssdoptions.py:79 +#: src/config/SSSDConfig/sssdoptions.py:75 msgid "" "The value of this option will be used in the expansion of the " "override_homedir option if the template contains the format string %H." @@ -253,13 +254,13 @@ msgstr "" "如果模板中包含格式字符串%H,那么这个选项的值将被用于 override_homedir 选项的" "扩展。" -#: src/config/SSSDConfig/sssdoptions.py:81 +#: src/config/SSSDConfig/sssdoptions.py:77 msgid "" "Specifies time in seconds for which the list of subdomains will be " "considered valid." msgstr "指定子域列表被视为有效的时间,以秒为单位。" -#: src/config/SSSDConfig/sssdoptions.py:83 +#: src/config/SSSDConfig/sssdoptions.py:79 msgid "" "The entry cache can be set to automatically update entries in the background " "if they are requested beyond a percentage of the entry_cache_timeout value " @@ -268,98 +269,99 @@ msgstr "" "条目缓存可以设置为在后台自动更新条目,如果被请求的时间超过域名的 " "entry_cache_timeout 值的一个百分比。" -#: src/config/SSSDConfig/sssdoptions.py:88 +#: src/config/SSSDConfig/sssdoptions.py:84 msgid "How long to allow cached logins between online logins (days)" msgstr "在线登录间隔多长时间内允许使用缓存的登录(以天为单位)" -#: src/config/SSSDConfig/sssdoptions.py:89 +#: src/config/SSSDConfig/sssdoptions.py:85 msgid "How many failed logins attempts are allowed when offline" msgstr "离线时允许多少次失败的登录尝试" -#: src/config/SSSDConfig/sssdoptions.py:91 +#: src/config/SSSDConfig/sssdoptions.py:87 msgid "" "How long (minutes) to deny login after offline_failed_login_attempts has " "been reached" -msgstr "当达到 offline_failed_login_attempts 之后多长时间要拒绝登录(以分钟为单位)" +msgstr "" +"当达到 offline_failed_login_attempts 之后多长时间要拒绝登录(以分钟为单位)" -#: src/config/SSSDConfig/sssdoptions.py:92 +#: src/config/SSSDConfig/sssdoptions.py:88 msgid "What kind of messages are displayed to the user during authentication" msgstr "在身份验证期间向用户显示什么信息" -#: src/config/SSSDConfig/sssdoptions.py:93 +#: src/config/SSSDConfig/sssdoptions.py:89 msgid "Filter PAM responses sent to the pam_sss" msgstr "过滤发送到 pam_sss 的 PAM 响应" -#: src/config/SSSDConfig/sssdoptions.py:94 +#: src/config/SSSDConfig/sssdoptions.py:90 msgid "How many seconds to keep identity information cached for PAM requests" msgstr "为 PAM 请求保留多长时间的身份信息缓存(以秒为单位)" -#: src/config/SSSDConfig/sssdoptions.py:95 +#: src/config/SSSDConfig/sssdoptions.py:91 msgid "How many days before password expiration a warning should be displayed" msgstr "在密码过期前几天应显示警告信息" -#: src/config/SSSDConfig/sssdoptions.py:96 +#: src/config/SSSDConfig/sssdoptions.py:92 msgid "List of trusted uids or user's name" msgstr "受信任的 uid 或用户名列表" -#: src/config/SSSDConfig/sssdoptions.py:97 +#: src/config/SSSDConfig/sssdoptions.py:93 msgid "List of domains accessible even for untrusted users." msgstr "即使不受信任的用户也可以访问的域列表。" -#: src/config/SSSDConfig/sssdoptions.py:98 +#: src/config/SSSDConfig/sssdoptions.py:94 msgid "Message printed when user account is expired." msgstr "当用户账户过期时显示的消息。" -#: src/config/SSSDConfig/sssdoptions.py:99 +#: src/config/SSSDConfig/sssdoptions.py:95 msgid "Message printed when user account is locked." msgstr "当用户账户被锁住时显示的消息。" -#: src/config/SSSDConfig/sssdoptions.py:100 +#: src/config/SSSDConfig/sssdoptions.py:96 msgid "Allow certificate based/Smartcard authentication." msgstr "允许基于证书/智能卡的身份验证。" -#: src/config/SSSDConfig/sssdoptions.py:101 +#: src/config/SSSDConfig/sssdoptions.py:97 msgid "Path to certificate database with PKCS#11 modules." msgstr "带有 PKCS#11 模块的证书数据库的路径。" -#: src/config/SSSDConfig/sssdoptions.py:102 +#: src/config/SSSDConfig/sssdoptions.py:98 msgid "Tune certificate verification for PAM authentication." msgstr "对 PAM 验证调整证书验证。" -#: src/config/SSSDConfig/sssdoptions.py:103 +#: src/config/SSSDConfig/sssdoptions.py:99 msgid "How many seconds will pam_sss wait for p11_child to finish" msgstr "pam_sss 等待 p11_child 完成的时间(以秒为单位)" -#: src/config/SSSDConfig/sssdoptions.py:104 +#: src/config/SSSDConfig/sssdoptions.py:100 msgid "Which PAM services are permitted to contact application domains" msgstr "允许哪些 PAM 服务联系应用程序域" -#: src/config/SSSDConfig/sssdoptions.py:105 +#: src/config/SSSDConfig/sssdoptions.py:101 msgid "Allowed services for using smartcards" msgstr "允许服务使用智能卡" -#: src/config/SSSDConfig/sssdoptions.py:106 +#: src/config/SSSDConfig/sssdoptions.py:102 msgid "Additional timeout to wait for a card if requested" msgstr "等待卡的额外超时,如果请求" -#: src/config/SSSDConfig/sssdoptions.py:107 +#: src/config/SSSDConfig/sssdoptions.py:103 msgid "" "PKCS#11 URI to restrict the selection of devices for Smartcard authentication" msgstr "PKCS#11 URI,用于限制智能卡认证设备的选择" -#: src/config/SSSDConfig/sssdoptions.py:108 +#: src/config/SSSDConfig/sssdoptions.py:104 msgid "When shall the PAM responder force an initgroups request" msgstr "什么时候 PAM 响应者要强制发起 initgroups 请求" -#: src/config/SSSDConfig/sssdoptions.py:109 +#: src/config/SSSDConfig/sssdoptions.py:105 msgid "List of PAM services that are allowed to authenticate with GSSAPI." msgstr "允许使用 GSSAPI 验证的 PAM 服务列表。" -#: src/config/SSSDConfig/sssdoptions.py:110 +#: src/config/SSSDConfig/sssdoptions.py:106 msgid "Whether to match authenticated UPN with target user" msgstr "是否与目标用户匹配认证的 UPN" -#: src/config/SSSDConfig/sssdoptions.py:111 +#: src/config/SSSDConfig/sssdoptions.py:107 msgid "" "List of pairs : that must be enforced " "for PAM access with GSSAPI authentication" @@ -367,77 +369,88 @@ msgstr "" ": 对列表,它们必须强制使用 GSSAPI 身份" "验证进行 PAM 访问" -#: src/config/SSSDConfig/sssdoptions.py:113 +#: src/config/SSSDConfig/sssdoptions.py:109 +#, fuzzy +msgid "" +"List of triples :: that assigns " +"additional information from the Kerberos ticket to an authentication " +"indicator." +msgstr "" +": 对列表,它们必须强制使用 GSSAPI 身份" +"验证进行 PAM 访问" + +#: src/config/SSSDConfig/sssdoptions.py:112 msgid "Allow passkey device authentication." msgstr "允许使用通行密钥设备认证。" -#: src/config/SSSDConfig/sssdoptions.py:114 +#: src/config/SSSDConfig/sssdoptions.py:113 msgid "How many seconds will pam_sss wait for passkey_child to finish" msgstr "pam_sss 等待 passkey_child 完成的时间" -#: src/config/SSSDConfig/sssdoptions.py:115 +#: src/config/SSSDConfig/sssdoptions.py:114 msgid "Enable debugging in the libfido2 library" msgstr "在 libfido2 库中启用调试功能" -#: src/config/SSSDConfig/sssdoptions.py:116 +#: src/config/SSSDConfig/sssdoptions.py:115 msgid "Enable JSON protocol for authentication methods selection." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:119 +#: src/config/SSSDConfig/sssdoptions.py:118 msgid "Whether to evaluate the time-based attributes in sudo rules" msgstr "是否在 sudo 规则中评估基于时间的属性" -#: src/config/SSSDConfig/sssdoptions.py:120 +#: src/config/SSSDConfig/sssdoptions.py:119 msgid "If true, SSSD will switch back to lower-wins ordering logic" msgstr "如果为 true,SSSD 将切换回 lower-wins ordering 逻辑" -#: src/config/SSSDConfig/sssdoptions.py:121 +#: src/config/SSSDConfig/sssdoptions.py:120 msgid "" "Maximum number of rules that can be refreshed at once. If this is exceeded, " "full refresh is performed." msgstr "一次可以刷新的最大规则数。如果超出此范围,则执行完全刷新。" -#: src/config/SSSDConfig/sssdoptions.py:128 +#: src/config/SSSDConfig/sssdoptions.py:127 msgid "Whether to hash host names and addresses in the known_hosts file" msgstr "在 known_hosts 文件中是否对主机名和地址进行哈希处理" -#: src/config/SSSDConfig/sssdoptions.py:129 +#: src/config/SSSDConfig/sssdoptions.py:128 msgid "" "How many seconds to keep a host in the known_hosts file after its host keys " "were requested" -msgstr "当请求了它的主机密钥后,将主机保留在 known_hosts 文件中的时间(以秒为单位)" +msgstr "" +"当请求了它的主机密钥后,将主机保留在 known_hosts 文件中的时间(以秒为单位)" -#: src/config/SSSDConfig/sssdoptions.py:131 +#: src/config/SSSDConfig/sssdoptions.py:130 msgid "Path to storage of trusted CA certificates" msgstr "到可信 CA 证书存储的路径" -#: src/config/SSSDConfig/sssdoptions.py:132 +#: src/config/SSSDConfig/sssdoptions.py:131 msgid "Allow to generate ssh-keys from certificates" msgstr "允许从证书中生成 ssh-keys" -#: src/config/SSSDConfig/sssdoptions.py:133 +#: src/config/SSSDConfig/sssdoptions.py:132 msgid "" "Use the following matching rules to filter the certificates for ssh-key " "generation" msgstr "使用以下匹配规则来过滤生成 ssh-key 的证书" -#: src/config/SSSDConfig/sssdoptions.py:137 +#: src/config/SSSDConfig/sssdoptions.py:136 msgid "List of UIDs or user names allowed to access the PAC responder" msgstr "允许访问 PAC 响应者的 UID 或用户名列表" -#: src/config/SSSDConfig/sssdoptions.py:138 +#: src/config/SSSDConfig/sssdoptions.py:137 msgid "How long the PAC data is considered valid" msgstr "PAC 数据被视为有效的时间长度" -#: src/config/SSSDConfig/sssdoptions.py:139 +#: src/config/SSSDConfig/sssdoptions.py:138 msgid "Validate the PAC" msgstr "验证 PAC" -#: src/config/SSSDConfig/sssdoptions.py:142 +#: src/config/SSSDConfig/sssdoptions.py:141 msgid "List of user attributes the InfoPipe is allowed to publish" msgstr "允许 InfoPipe 发布的用户属性列表" -#: src/config/SSSDConfig/sssdoptions.py:145 +#: src/config/SSSDConfig/sssdoptions.py:144 msgid "" "One of the following strings specifying the scope of session recording: none " "- No users are recorded. some - Users/groups specified by users and groups " @@ -446,7 +459,7 @@ msgstr "" "使用以下字符串之一指定会话记录范围: none - 不记录用户。 some - 记录由用户和" "组选项指定的用户和组。 all - 记录所有用户。" -#: src/config/SSSDConfig/sssdoptions.py:148 +#: src/config/SSSDConfig/sssdoptions.py:147 msgid "" "A comma-separated list of users which should have session recording enabled. " "Matches user names as returned by NSS. I.e. after the possible space " @@ -455,7 +468,7 @@ msgstr "" "以逗号分隔的用户列表,这些用户应该启用会话记录。匹配 NSS 返回的用户名。在可能" "的空格替换、大小写更改等之后。" -#: src/config/SSSDConfig/sssdoptions.py:150 +#: src/config/SSSDConfig/sssdoptions.py:149 msgid "" "A comma-separated list of groups, members of which should have session " "recording enabled. Matches group names as returned by NSS. I.e. after the " @@ -464,91 +477,91 @@ msgstr "" "以逗号分隔的组列表,其成员应已启用会话记录。匹配NSS 返回的组名。在可能的空格" "替换、大小写改变等之后。" -#: src/config/SSSDConfig/sssdoptions.py:153 +#: src/config/SSSDConfig/sssdoptions.py:152 msgid "" "A comma-separated list of users to be excluded from recording, only when " "scope=all" msgstr "要从记录中排除的用逗号分开的用户列表,仅当 scope=all 时" -#: src/config/SSSDConfig/sssdoptions.py:154 +#: src/config/SSSDConfig/sssdoptions.py:153 msgid "" "A comma-separated list of groups, members of which should be excluded from " "recording, only when scope=all. " msgstr "用逗号分隔的组列表,其中的成员应不记录中排除,仅在 scope=all 时。 " -#: src/config/SSSDConfig/sssdoptions.py:158 +#: src/config/SSSDConfig/sssdoptions.py:157 msgid "Identity provider" msgstr "身份提供者" -#: src/config/SSSDConfig/sssdoptions.py:159 +#: src/config/SSSDConfig/sssdoptions.py:158 msgid "Authentication provider" msgstr "身份验证提供者" -#: src/config/SSSDConfig/sssdoptions.py:160 +#: src/config/SSSDConfig/sssdoptions.py:159 msgid "Access control provider" msgstr "访问控制提供者" -#: src/config/SSSDConfig/sssdoptions.py:161 +#: src/config/SSSDConfig/sssdoptions.py:160 msgid "Password change provider" msgstr "密码改变提供者" -#: src/config/SSSDConfig/sssdoptions.py:162 +#: src/config/SSSDConfig/sssdoptions.py:161 msgid "SUDO provider" msgstr "SUDO 提供者" -#: src/config/SSSDConfig/sssdoptions.py:163 +#: src/config/SSSDConfig/sssdoptions.py:162 msgid "Autofs provider" msgstr "Autofs 提供者" -#: src/config/SSSDConfig/sssdoptions.py:164 +#: src/config/SSSDConfig/sssdoptions.py:163 msgid "Host identity provider" msgstr "主机身份提供者" -#: src/config/SSSDConfig/sssdoptions.py:165 +#: src/config/SSSDConfig/sssdoptions.py:164 msgid "SELinux provider" msgstr "SELinux 提供者" -#: src/config/SSSDConfig/sssdoptions.py:166 +#: src/config/SSSDConfig/sssdoptions.py:165 msgid "Session management provider" msgstr "会话管理提供者" -#: src/config/SSSDConfig/sssdoptions.py:167 +#: src/config/SSSDConfig/sssdoptions.py:166 msgid "Resolver provider" msgstr "解析器提供者" -#: src/config/SSSDConfig/sssdoptions.py:170 +#: src/config/SSSDConfig/sssdoptions.py:169 msgid "Whether the domain is usable by the OS or by applications" msgstr "域是否可以被 OS 或应用程序使用" -#: src/config/SSSDConfig/sssdoptions.py:171 +#: src/config/SSSDConfig/sssdoptions.py:170 msgid "Enable or disable the domain" msgstr "启用或禁用域" -#: src/config/SSSDConfig/sssdoptions.py:172 +#: src/config/SSSDConfig/sssdoptions.py:171 msgid "Minimum user ID" msgstr "最小用户 ID" -#: src/config/SSSDConfig/sssdoptions.py:173 +#: src/config/SSSDConfig/sssdoptions.py:172 msgid "Maximum user ID" msgstr "最大用户 ID" -#: src/config/SSSDConfig/sssdoptions.py:174 +#: src/config/SSSDConfig/sssdoptions.py:173 msgid "Enable enumerating all users/groups" msgstr "启用枚举所有用户/组" -#: src/config/SSSDConfig/sssdoptions.py:175 +#: src/config/SSSDConfig/sssdoptions.py:174 msgid "Cache credentials for offline login" msgstr "为脱机登录缓存凭据" -#: src/config/SSSDConfig/sssdoptions.py:176 +#: src/config/SSSDConfig/sssdoptions.py:175 msgid "Display users/groups in fully-qualified form" msgstr "以完全限定的形式显示用户/组" -#: src/config/SSSDConfig/sssdoptions.py:177 +#: src/config/SSSDConfig/sssdoptions.py:176 msgid "Don't include group members in group lookups" msgstr "在组查询中不包括的组成员" -#: src/config/SSSDConfig/sssdoptions.py:178 +#: src/config/SSSDConfig/sssdoptions.py:177 #: src/config/SSSDConfig/sssdoptions.py:190 #: src/config/SSSDConfig/sssdoptions.py:191 #: src/config/SSSDConfig/sssdoptions.py:192 @@ -559,48 +572,52 @@ msgstr "在组查询中不包括的组成员" msgid "Entry cache timeout length (seconds)" msgstr "输入缓存超时时间(秒)" -#: src/config/SSSDConfig/sssdoptions.py:179 +#: src/config/SSSDConfig/sssdoptions.py:178 msgid "" "Restrict or prefer a specific address family when performing DNS lookups" msgstr "执行 DNS 查找时限制或首选使用特定的地址系列" -#: src/config/SSSDConfig/sssdoptions.py:180 +#: src/config/SSSDConfig/sssdoptions.py:179 msgid "How long to keep cached entries after last successful login (days)" msgstr "上次成功登录后保留缓存条目的时间(天)" -#: src/config/SSSDConfig/sssdoptions.py:181 +#: src/config/SSSDConfig/sssdoptions.py:180 msgid "" "How long should SSSD talk to single DNS server before trying next server " "(miliseconds)" msgstr "在尝试下一个服务器之前,SSSD 应该与一个 DNS 服务器联系多久(毫秒)" -#: src/config/SSSDConfig/sssdoptions.py:183 +#: src/config/SSSDConfig/sssdoptions.py:182 msgid "How long should keep trying to resolve single DNS query (seconds)" msgstr "尝试解析单个 DNS 查询需要多长时间(秒)" -#: src/config/SSSDConfig/sssdoptions.py:184 +#: src/config/SSSDConfig/sssdoptions.py:183 msgid "How long to wait for replies from DNS when resolving servers (seconds)" msgstr "解析服务器时等待 DNS 回复的时间(秒)" -#: src/config/SSSDConfig/sssdoptions.py:185 +#: src/config/SSSDConfig/sssdoptions.py:184 msgid "The domain part of service discovery DNS query" msgstr "服务发现 DNS 查询的域部分" -#: src/config/SSSDConfig/sssdoptions.py:186 +#: src/config/SSSDConfig/sssdoptions.py:185 msgid "" "Specifies the interval, in seconds, that SSSD waits before attempting to " "reconnect to the primary server after a successful connection to the backup " "server" msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:188 +#: src/config/SSSDConfig/sssdoptions.py:187 msgid "Override GID value from the identity provider with this value" msgstr "使用此值覆盖来自身份提供者的 GID 值" -#: src/config/SSSDConfig/sssdoptions.py:189 +#: src/config/SSSDConfig/sssdoptions.py:188 msgid "Treat usernames as case sensitive" msgstr "用户名区分大小写" +#: src/config/SSSDConfig/sssdoptions.py:189 +msgid "Lookups by ID are expensive or do not work at all" +msgstr "" + #: src/config/SSSDConfig/sssdoptions.py:197 msgid "How often should expired entries be refreshed in background" msgstr "过期条目应在后台刷新的频率" @@ -827,7 +844,7 @@ msgid "Search base for SUBID ranges" msgstr "搜索 SUBID 范围的基础" #: src/config/SSSDConfig/sssdoptions.py:259 -#: src/config/SSSDConfig/sssdoptions.py:506 +#: src/config/SSSDConfig/sssdoptions.py:512 msgid "Which rules should be used to evaluate access control" msgstr "应该使用哪些规则来评估访问控制" @@ -973,7 +990,7 @@ msgid "Enable DNS sites - location based service discovery" msgstr "启用 DNS 站点 - 基于位置的服务发现" #: src/config/SSSDConfig/sssdoptions.py:301 -#: src/config/SSSDConfig/sssdoptions.py:504 +#: src/config/SSSDConfig/sssdoptions.py:510 msgid "LDAP filter to determine access privileges" msgstr "用于决定访问权限 的 LDAP 过滤器" @@ -1393,7 +1410,7 @@ msgid "UUID attribute" msgstr "UUID 属性" #: src/config/SSSDConfig/sssdoptions.py:423 -#: src/config/SSSDConfig/sssdoptions.py:464 +#: src/config/SSSDConfig/sssdoptions.py:470 msgid "objectSID attribute" msgstr "objectSID 属性" @@ -1517,354 +1534,384 @@ msgstr "包含用户的通行密钥映射数据的属性" msgid "A list of extra attributes to download along with the user entry" msgstr "要与用户条目一起下载的其他属性的列表" +#: src/config/SSSDConfig/sssdoptions.py:456 +#, fuzzy +msgid "The object class of an subid entry in LDAP." +msgstr "LDAP 中主机条目的对象类。" + #: src/config/SSSDConfig/sssdoptions.py:457 +#, fuzzy +msgid "Subordinate user ID count attribute" +msgstr "sudo 规则用户属性" + +#: src/config/SSSDConfig/sssdoptions.py:458 +#, fuzzy +msgid "Subordinate group ID count attribute" +msgstr "sudo 规则选项属性" + +#: src/config/SSSDConfig/sssdoptions.py:459 +#, fuzzy +msgid "User ID range start value attribute" +msgstr "用户名属性" + +#: src/config/SSSDConfig/sssdoptions.py:460 +#, fuzzy +msgid "Group ID range start value attribute" +msgstr "组 UUID 属性" + +#: src/config/SSSDConfig/sssdoptions.py:461 +msgid "Owner of an entry" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:463 msgid "Base DN for group lookups" msgstr "组查找的基本 DN" -#: src/config/SSSDConfig/sssdoptions.py:458 +#: src/config/SSSDConfig/sssdoptions.py:464 msgid "Objectclass for groups" msgstr "组的对象类" -#: src/config/SSSDConfig/sssdoptions.py:459 +#: src/config/SSSDConfig/sssdoptions.py:465 msgid "Group name" msgstr "组名称" -#: src/config/SSSDConfig/sssdoptions.py:460 +#: src/config/SSSDConfig/sssdoptions.py:466 msgid "Group password" msgstr "组密码" -#: src/config/SSSDConfig/sssdoptions.py:461 +#: src/config/SSSDConfig/sssdoptions.py:467 msgid "GID attribute" msgstr "GID 属性" -#: src/config/SSSDConfig/sssdoptions.py:462 +#: src/config/SSSDConfig/sssdoptions.py:468 msgid "Group member attribute" msgstr "组成员属性" -#: src/config/SSSDConfig/sssdoptions.py:463 +#: src/config/SSSDConfig/sssdoptions.py:469 msgid "Group UUID attribute" msgstr "组 UUID 属性" -#: src/config/SSSDConfig/sssdoptions.py:465 +#: src/config/SSSDConfig/sssdoptions.py:471 msgid "Modification time attribute for groups" msgstr "组的修改时间属性" -#: src/config/SSSDConfig/sssdoptions.py:466 +#: src/config/SSSDConfig/sssdoptions.py:472 msgid "Type of the group and other flags" msgstr "组的类型和其他标志" -#: src/config/SSSDConfig/sssdoptions.py:467 +#: src/config/SSSDConfig/sssdoptions.py:473 msgid "The LDAP group external member attribute" msgstr "LDAP 组外部成员属性" -#: src/config/SSSDConfig/sssdoptions.py:468 +#: src/config/SSSDConfig/sssdoptions.py:474 msgid "Maximum nesting level SSSD will follow" msgstr "将遵循的最大嵌套级别 SSSD" -#: src/config/SSSDConfig/sssdoptions.py:469 +#: src/config/SSSDConfig/sssdoptions.py:475 msgid "Filter for group lookups" msgstr "组查询的过滤器" -#: src/config/SSSDConfig/sssdoptions.py:470 +#: src/config/SSSDConfig/sssdoptions.py:476 msgid "Scope of group lookups" msgstr "组查询的范围" -#: src/config/SSSDConfig/sssdoptions.py:472 +#: src/config/SSSDConfig/sssdoptions.py:478 msgid "Base DN for netgroup lookups" msgstr "netgroup 查找的基本 DN" -#: src/config/SSSDConfig/sssdoptions.py:473 +#: src/config/SSSDConfig/sssdoptions.py:479 msgid "Objectclass for netgroups" msgstr "netgroup 的对象类" -#: src/config/SSSDConfig/sssdoptions.py:474 +#: src/config/SSSDConfig/sssdoptions.py:480 msgid "Netgroup name" msgstr "Netgroup 名" -#: src/config/SSSDConfig/sssdoptions.py:475 +#: src/config/SSSDConfig/sssdoptions.py:481 msgid "Netgroups members attribute" msgstr "Netgroups 成员属性" -#: src/config/SSSDConfig/sssdoptions.py:476 +#: src/config/SSSDConfig/sssdoptions.py:482 msgid "Netgroup triple attribute" msgstr "Netgroup triple 属性" -#: src/config/SSSDConfig/sssdoptions.py:477 +#: src/config/SSSDConfig/sssdoptions.py:483 msgid "Modification time attribute for netgroups" msgstr "netgroup 的修改时间属性" -#: src/config/SSSDConfig/sssdoptions.py:479 +#: src/config/SSSDConfig/sssdoptions.py:485 msgid "Base DN for service lookups" msgstr "服务查找的基本 DN" -#: src/config/SSSDConfig/sssdoptions.py:480 +#: src/config/SSSDConfig/sssdoptions.py:486 msgid "Objectclass for services" msgstr "服务的对象类" -#: src/config/SSSDConfig/sssdoptions.py:481 +#: src/config/SSSDConfig/sssdoptions.py:487 msgid "Service name attribute" msgstr "服务名属性" -#: src/config/SSSDConfig/sssdoptions.py:482 +#: src/config/SSSDConfig/sssdoptions.py:488 msgid "Service port attribute" msgstr "服务端口属性" -#: src/config/SSSDConfig/sssdoptions.py:483 +#: src/config/SSSDConfig/sssdoptions.py:489 msgid "Service protocol attribute" msgstr "服务协议属性" -#: src/config/SSSDConfig/sssdoptions.py:485 +#: src/config/SSSDConfig/sssdoptions.py:491 msgid "Lower bound for ID-mapping" msgstr "ID 映射的下限" -#: src/config/SSSDConfig/sssdoptions.py:486 +#: src/config/SSSDConfig/sssdoptions.py:492 msgid "Upper bound for ID-mapping" msgstr "ID 映射的上限" -#: src/config/SSSDConfig/sssdoptions.py:487 +#: src/config/SSSDConfig/sssdoptions.py:493 msgid "Number of IDs for each slice when ID-mapping" msgstr "ID 映射时每个片的 ID 数" -#: src/config/SSSDConfig/sssdoptions.py:488 +#: src/config/SSSDConfig/sssdoptions.py:494 msgid "Use autorid-compatible algorithm for ID-mapping" msgstr "使用与 autorid 兼容的算法进行 ID 映射" -#: src/config/SSSDConfig/sssdoptions.py:489 +#: src/config/SSSDConfig/sssdoptions.py:495 msgid "Name of the default domain for ID-mapping" msgstr "用于 ID 映射的默认域的名称" -#: src/config/SSSDConfig/sssdoptions.py:490 +#: src/config/SSSDConfig/sssdoptions.py:496 msgid "SID of the default domain for ID-mapping" msgstr "用于 ID 映射的默认域的 SID" -#: src/config/SSSDConfig/sssdoptions.py:491 +#: src/config/SSSDConfig/sssdoptions.py:497 msgid "Number of secondary slices" msgstr "次要切片数" -#: src/config/SSSDConfig/sssdoptions.py:493 +#: src/config/SSSDConfig/sssdoptions.py:499 msgid "Whether to use Token-Groups" msgstr "是否使用令牌组" -#: src/config/SSSDConfig/sssdoptions.py:494 +#: src/config/SSSDConfig/sssdoptions.py:500 msgid "Set lower boundary for allowed IDs from the LDAP server" msgstr "设置 LDAP 服务器允许的 ID 的下边界" -#: src/config/SSSDConfig/sssdoptions.py:495 +#: src/config/SSSDConfig/sssdoptions.py:501 msgid "Set upper boundary for allowed IDs from the LDAP server" msgstr "设置 LDAP 服务器允许的 ID 的上边界" -#: src/config/SSSDConfig/sssdoptions.py:496 +#: src/config/SSSDConfig/sssdoptions.py:502 msgid "DN for ppolicy queries" msgstr "ppolicy 查询的 DN" -#: src/config/SSSDConfig/sssdoptions.py:497 +#: src/config/SSSDConfig/sssdoptions.py:503 msgid "How many maximum entries to fetch during a wildcard request" msgstr "在通配符请求期间要提取多少个最大条目" -#: src/config/SSSDConfig/sssdoptions.py:498 +#: src/config/SSSDConfig/sssdoptions.py:504 msgid "Set libldap debug level" msgstr "设置 libldap debug 级别" -#: src/config/SSSDConfig/sssdoptions.py:501 +#: src/config/SSSDConfig/sssdoptions.py:507 msgid "Policy to evaluate the password expiration" msgstr "评估密码有效期的策略" -#: src/config/SSSDConfig/sssdoptions.py:505 +#: src/config/SSSDConfig/sssdoptions.py:511 msgid "Which attributes shall be used to evaluate if an account is expired" msgstr "应使用哪些属性来评估账户是否过期" -#: src/config/SSSDConfig/sssdoptions.py:509 +#: src/config/SSSDConfig/sssdoptions.py:515 msgid "URI of an LDAP server where password changes are allowed" msgstr "允许更改密码的 LDAP 服务器的 URI" -#: src/config/SSSDConfig/sssdoptions.py:510 +#: src/config/SSSDConfig/sssdoptions.py:516 msgid "URI of a backup LDAP server where password changes are allowed" msgstr "允许更改密码的备份 LDAP 服务器的 URI" -#: src/config/SSSDConfig/sssdoptions.py:511 +#: src/config/SSSDConfig/sssdoptions.py:517 msgid "DNS service name for LDAP password change server" msgstr "LDAP 密码更改服务器的 DNS 服务名称" -#: src/config/SSSDConfig/sssdoptions.py:512 +#: src/config/SSSDConfig/sssdoptions.py:518 msgid "" "Whether to update the ldap_user_shadow_last_change attribute after a " "password change" msgstr "更改密码后是否更新 ldap_user_shadow_last_change 属性" -#: src/config/SSSDConfig/sssdoptions.py:516 +#: src/config/SSSDConfig/sssdoptions.py:522 msgid "Base DN for sudo rules lookups" msgstr "sudo 规则查找的基本DN" -#: src/config/SSSDConfig/sssdoptions.py:517 +#: src/config/SSSDConfig/sssdoptions.py:523 msgid "Automatic full refresh period" msgstr "自动完整刷新周期" -#: src/config/SSSDConfig/sssdoptions.py:518 +#: src/config/SSSDConfig/sssdoptions.py:524 msgid "Automatic smart refresh period" msgstr "自动智能刷新周期" -#: src/config/SSSDConfig/sssdoptions.py:519 +#: src/config/SSSDConfig/sssdoptions.py:525 msgid "Smart and full refresh random offset" msgstr "智能和完整刷新随机偏移" -#: src/config/SSSDConfig/sssdoptions.py:520 +#: src/config/SSSDConfig/sssdoptions.py:526 msgid "Whether to filter rules by hostname, IP addresses and network" msgstr "是否按主机名,IP地址和网络过滤规则" -#: src/config/SSSDConfig/sssdoptions.py:521 +#: src/config/SSSDConfig/sssdoptions.py:527 msgid "" "Hostnames and/or fully qualified domain names of this machine to filter sudo " "rules" msgstr "本机的主机名和/或限定域名,用于过滤 sudo 规则" -#: src/config/SSSDConfig/sssdoptions.py:522 +#: src/config/SSSDConfig/sssdoptions.py:528 msgid "IPv4 or IPv6 addresses or network of this machine to filter sudo rules" msgstr "IPv4 或 IPv6 地址或本机器的网络,用于过滤 sudo 规则" -#: src/config/SSSDConfig/sssdoptions.py:523 +#: src/config/SSSDConfig/sssdoptions.py:529 msgid "Whether to include rules that contains netgroup in host attribute" msgstr "是否在主机属性中包含带有 netgroup 的规则" -#: src/config/SSSDConfig/sssdoptions.py:524 +#: src/config/SSSDConfig/sssdoptions.py:530 msgid "" "Whether to include rules that contains regular expression in host attribute" msgstr "是否在主机属性中包含带有正则表达式的规则" -#: src/config/SSSDConfig/sssdoptions.py:525 +#: src/config/SSSDConfig/sssdoptions.py:531 msgid "Object class for sudo rules" msgstr "sudo 规则的对象类" -#: src/config/SSSDConfig/sssdoptions.py:526 +#: src/config/SSSDConfig/sssdoptions.py:532 msgid "Name of attribute that is used as object class for sudo rules" msgstr "用作 sudo 规则的对象类的属性名称" -#: src/config/SSSDConfig/sssdoptions.py:527 +#: src/config/SSSDConfig/sssdoptions.py:533 msgid "Sudo rule name" msgstr "sudo 规则名" -#: src/config/SSSDConfig/sssdoptions.py:528 +#: src/config/SSSDConfig/sssdoptions.py:534 msgid "Sudo rule command attribute" msgstr "sudo 规则命令属性" -#: src/config/SSSDConfig/sssdoptions.py:529 +#: src/config/SSSDConfig/sssdoptions.py:535 msgid "Sudo rule host attribute" msgstr "sudo 规则主机属性" -#: src/config/SSSDConfig/sssdoptions.py:530 +#: src/config/SSSDConfig/sssdoptions.py:536 msgid "Sudo rule user attribute" msgstr "sudo 规则用户属性" -#: src/config/SSSDConfig/sssdoptions.py:531 +#: src/config/SSSDConfig/sssdoptions.py:537 msgid "Sudo rule option attribute" msgstr "sudo 规则选项属性" -#: src/config/SSSDConfig/sssdoptions.py:532 +#: src/config/SSSDConfig/sssdoptions.py:538 msgid "Sudo rule runas attribute" msgstr "sudo 规则 runas 属性" -#: src/config/SSSDConfig/sssdoptions.py:533 +#: src/config/SSSDConfig/sssdoptions.py:539 msgid "Sudo rule runasuser attribute" msgstr "sudo 规则 runasuser 属性" -#: src/config/SSSDConfig/sssdoptions.py:534 +#: src/config/SSSDConfig/sssdoptions.py:540 msgid "Sudo rule runasgroup attribute" msgstr "sudo 规则 runasgroup 属性" -#: src/config/SSSDConfig/sssdoptions.py:535 +#: src/config/SSSDConfig/sssdoptions.py:541 msgid "Sudo rule notbefore attribute" msgstr "sudo 规则 notbefore 属性" -#: src/config/SSSDConfig/sssdoptions.py:536 +#: src/config/SSSDConfig/sssdoptions.py:542 msgid "Sudo rule notafter attribute" msgstr "sudo 规则 notafter 属性" -#: src/config/SSSDConfig/sssdoptions.py:537 +#: src/config/SSSDConfig/sssdoptions.py:543 msgid "Sudo rule order attribute" msgstr "sudo 规则顺序属性" -#: src/config/SSSDConfig/sssdoptions.py:540 +#: src/config/SSSDConfig/sssdoptions.py:546 msgid "Object class for automounter maps" msgstr "自动挂载器映射的对象类" -#: src/config/SSSDConfig/sssdoptions.py:541 +#: src/config/SSSDConfig/sssdoptions.py:547 msgid "Automounter map name attribute" msgstr "自动挂载器映射名称属性" -#: src/config/SSSDConfig/sssdoptions.py:542 +#: src/config/SSSDConfig/sssdoptions.py:548 msgid "Object class for automounter map entries" msgstr "自动挂载器映射条目的对象类" -#: src/config/SSSDConfig/sssdoptions.py:543 +#: src/config/SSSDConfig/sssdoptions.py:549 msgid "Automounter map entry key attribute" msgstr "自动挂载器映射条目键的属性" -#: src/config/SSSDConfig/sssdoptions.py:544 +#: src/config/SSSDConfig/sssdoptions.py:550 msgid "Automounter map entry value attribute" msgstr "自动挂载器映射条目值的属性" -#: src/config/SSSDConfig/sssdoptions.py:545 +#: src/config/SSSDConfig/sssdoptions.py:551 msgid "Base DN for automounter map lookups" msgstr "自动挂载程序映射查找的基本 DN" -#: src/config/SSSDConfig/sssdoptions.py:546 +#: src/config/SSSDConfig/sssdoptions.py:552 msgid "The name of the automount master map in LDAP." msgstr "LDAP 中自动挂载主映射的名称。" -#: src/config/SSSDConfig/sssdoptions.py:549 +#: src/config/SSSDConfig/sssdoptions.py:555 msgid "Base DN for IP hosts lookups" msgstr "IP 主机查询的基础 DN" -#: src/config/SSSDConfig/sssdoptions.py:550 +#: src/config/SSSDConfig/sssdoptions.py:556 msgid "Object class for IP hosts" msgstr "IP 主机的对象类" -#: src/config/SSSDConfig/sssdoptions.py:551 +#: src/config/SSSDConfig/sssdoptions.py:557 msgid "IP host name attribute" msgstr "IP 主机名属性" -#: src/config/SSSDConfig/sssdoptions.py:552 +#: src/config/SSSDConfig/sssdoptions.py:558 msgid "IP host number (address) attribute" msgstr "IP 主机号(地址)属性" -#: src/config/SSSDConfig/sssdoptions.py:553 +#: src/config/SSSDConfig/sssdoptions.py:559 msgid "IP host entryUSN attribute" msgstr "IP 主机 entryUSN 属性" -#: src/config/SSSDConfig/sssdoptions.py:554 +#: src/config/SSSDConfig/sssdoptions.py:560 msgid "Base DN for IP networks lookups" msgstr "IP 网络查询的基础 DN" -#: src/config/SSSDConfig/sssdoptions.py:555 +#: src/config/SSSDConfig/sssdoptions.py:561 msgid "Object class for IP networks" msgstr "IP 网络的对象类" -#: src/config/SSSDConfig/sssdoptions.py:556 +#: src/config/SSSDConfig/sssdoptions.py:562 msgid "IP network name attribute" msgstr "IP 网络名称属性" -#: src/config/SSSDConfig/sssdoptions.py:557 +#: src/config/SSSDConfig/sssdoptions.py:563 msgid "IP network number (address) attribute" msgstr "I P网号(地址)属性" -#: src/config/SSSDConfig/sssdoptions.py:558 +#: src/config/SSSDConfig/sssdoptions.py:564 msgid "IP network entryUSN attribute" msgstr "IP 网络 entryUSN 属性" -#: src/config/SSSDConfig/sssdoptions.py:561 +#: src/config/SSSDConfig/sssdoptions.py:567 msgid "Comma separated list of allowed users" msgstr "以逗号分隔的允许的用户列表" -#: src/config/SSSDConfig/sssdoptions.py:562 +#: src/config/SSSDConfig/sssdoptions.py:568 msgid "Comma separated list of prohibited users" msgstr "以逗号分隔的不允许的用户列表" -#: src/config/SSSDConfig/sssdoptions.py:563 +#: src/config/SSSDConfig/sssdoptions.py:569 msgid "" "Comma separated list of groups that are allowed to log in. This applies only " "to groups within this SSSD domain. Local groups are not evaluated." -msgstr "以逗号分隔的允许登录的组的列表。这只适用于此 SSSD 域内的组。本地组不被评估。" +msgstr "" +"以逗号分隔的允许登录的组的列表。这只适用于此 SSSD 域内的组。本地组不被评估。" -#: src/config/SSSDConfig/sssdoptions.py:565 +#: src/config/SSSDConfig/sssdoptions.py:571 msgid "" "Comma separated list of groups that are explicitly denied access. This " "applies only to groups within this SSSD domain. Local groups are not " @@ -1873,31 +1920,31 @@ msgstr "" "以逗号分隔的明确拒绝访问的组的列表。这只适用于此 SSSD 域内的组。本地组不被评" "估。" -#: src/config/SSSDConfig/sssdoptions.py:569 +#: src/config/SSSDConfig/sssdoptions.py:575 msgid "The number of preforked proxy children." msgstr "预分支代理子代的数量。" -#: src/config/SSSDConfig/sssdoptions.py:572 +#: src/config/SSSDConfig/sssdoptions.py:578 msgid "The name of the NSS library to use" msgstr "使用的 NSS 库的名称" -#: src/config/SSSDConfig/sssdoptions.py:573 +#: src/config/SSSDConfig/sssdoptions.py:579 msgid "The name of the NSS library to use for hosts and networks lookups" msgstr "用于查询主机和网络的 NSS 库名称" -#: src/config/SSSDConfig/sssdoptions.py:574 +#: src/config/SSSDConfig/sssdoptions.py:580 msgid "Whether to look up canonical group name from cache if possible" msgstr "如果可能,是否从缓存中查找规范的组名" -#: src/config/SSSDConfig/sssdoptions.py:577 +#: src/config/SSSDConfig/sssdoptions.py:583 msgid "PAM stack to use" msgstr "使用的 PAM 堆栈" -#: src/config/SSSDConfig/sssdoptions.py:580 +#: src/config/SSSDConfig/sssdoptions.py:586 msgid "Path of passwd file sources." msgstr "passwd 文件源的路径。" -#: src/config/SSSDConfig/sssdoptions.py:581 +#: src/config/SSSDConfig/sssdoptions.py:587 msgid "Path of group file sources." msgstr "group 文件源的路径。" @@ -1925,227 +1972,235 @@ msgstr "索引操作失败:%1$s\n" msgid "Option -i|--interactive is not allowed together with -D|--daemon\n" msgstr "选项 -i|--interactive 不能和 -D|--daemon 一起使用\n" -#: src/monitor/monitor.c:1836 +#: src/monitor/monitor.c:1838 msgid "Failed to get initial capabilities\n" msgstr "" -#: src/monitor/monitor.c:1847 +#: src/monitor/monitor.c:1849 msgid "Non-root service user support isn't built. Can't run under %" msgstr "" -#: src/monitor/monitor.c:1864 +#: src/monitor/monitor.c:1866 #, c-format msgid "Can't read config: '%s'\n" msgstr "" -#: src/monitor/monitor.c:1876 +#: src/monitor/monitor.c:1878 #, c-format -msgid "Failed to boostrap SSSD 'monitor' process: %s" +msgid "Failed to bootstrap SSSD 'monitor' process: %s" msgstr "" -#: src/monitor/monitor.c:1971 +#: src/monitor/monitor.c:1973 msgid "Out of memory\n" msgstr "无可用内存\n" -#: src/providers/krb5/krb5_child.c:4221 +#: src/providers/krb5/krb5_child.c:4316 msgid "Use anonymous PKINIT to request FAST armor ticket" msgstr "使用匿名 PKINIT 请求 FAST armor 票" -#: src/providers/krb5/krb5_child.c:4223 +#: src/providers/krb5/krb5_child.c:4318 msgid "Kerberos realm to use" msgstr "要使用的 kerberos 域" -#: src/providers/krb5/krb5_child.c:4225 +#: src/providers/krb5/krb5_child.c:4320 msgid "Requested lifetime of the ticket" msgstr "要求的票证寿命" -#: src/providers/krb5/krb5_child.c:4227 +#: src/providers/krb5/krb5_child.c:4322 msgid "Requested renewable lifetime of the ticket" msgstr "要求的可续约票证寿命" -#: src/providers/krb5/krb5_child.c:4229 +#: src/providers/krb5/krb5_child.c:4324 msgid "FAST options ('never', 'try', 'demand')" msgstr "FAST 选项('never'、'try'、'demand')" -#: src/providers/krb5/krb5_child.c:4232 +#: src/providers/krb5/krb5_child.c:4327 msgid "Specifies the server principal to use for FAST" msgstr "指定用于 FAST 的服务器主体" -#: src/providers/krb5/krb5_child.c:4234 +#: src/providers/krb5/krb5_child.c:4329 msgid "Requests canonicalization of the principal name" msgstr "要求规范化主体名称" -#: src/providers/krb5/krb5_child.c:4236 +#: src/providers/krb5/krb5_child.c:4331 msgid "Use custom version of krb5_get_init_creds_password" msgstr "使用自定义版本的 krb5_get_init_creds_password" -#: src/providers/krb5/krb5_child.c:4238 +#: src/providers/krb5/krb5_child.c:4333 msgid "Check PAC flags" msgstr "检查 PAC 标志" -#: src/providers/data_provider_be.c:790 +#: src/providers/krb5/krb5_child.c:4335 +msgid "Set environment variable (KEY=VALUE)" +msgstr "" + +#: src/providers/data_provider_be.c:786 msgid "Domain of the information provider (mandatory)" msgstr "信息提供者的域(强制)" -#: src/sss_client/common.c:1165 +#: src/sss_client/common.c:1208 #, fuzzy msgid "Socket has wrong ownership or permissions." msgstr "公共套接字有错误的所有权或权限。" -#: src/sss_client/common.c:1168 +#: src/sss_client/common.c:1211 msgid "Unexpected format of the server credential message." msgstr "服务器凭证消息的格式异常。" -#: src/sss_client/common.c:1171 +#: src/sss_client/common.c:1214 #, fuzzy msgid "SSSD is not run by trusted user." msgstr "SSSD 没有由 root 运行。" -#: src/sss_client/common.c:1174 +#: src/sss_client/common.c:1217 msgid "SSSD socket does not exist." msgstr "SSSD socket 不存在。" -#: src/sss_client/common.c:1177 +#: src/sss_client/common.c:1220 msgid "Cannot get stat of SSSD socket." msgstr "无法获取 SSSD socket 的统计数据。" -#: src/sss_client/common.c:1182 +#: src/sss_client/common.c:1225 msgid "An error occurred, but no description can be found." msgstr "发生错误,但找不到描述信息。" -#: src/sss_client/common.c:1188 +#: src/sss_client/common.c:1231 msgid "Unexpected error while looking for an error description" msgstr "查找错误说明时出现意外错误" -#: src/sss_client/pam_sss.c:74 +#: src/sss_client/pam_sss.c:135 msgid "Permission denied. " msgstr "权限被拒绝。 " -#: src/sss_client/pam_sss.c:75 src/sss_client/pam_sss.c:843 -#: src/sss_client/pam_sss.c:854 +#: src/sss_client/pam_sss.c:136 src/sss_client/pam_sss.c:921 +#: src/sss_client/pam_sss.c:932 msgid "Server message: " msgstr "服务器消息: " -#: src/sss_client/pam_sss.c:76 +#: src/sss_client/pam_sss.c:137 msgid "" "Kerberos TGT will not be granted upon login, user experience will be " "affected." msgstr "" -#: src/sss_client/pam_sss.c:77 +#: src/sss_client/pam_sss.c:138 msgid "Enter PIN:" msgstr "输入 PIN:" -#: src/sss_client/pam_sss.c:320 +#: src/sss_client/pam_sss.c:385 msgid "Passwords do not match" msgstr "密码不匹配" -#: src/sss_client/pam_sss.c:508 +#: src/sss_client/pam_sss.c:584 msgid "Password reset by root is not supported." msgstr "不支持通过 root 重置密码。" -#: src/sss_client/pam_sss.c:549 +#: src/sss_client/pam_sss.c:625 msgid "Authenticated with cached credentials" msgstr "通过缓存的凭据进行身份验证" -#: src/sss_client/pam_sss.c:550 +#: src/sss_client/pam_sss.c:626 msgid ", your cached password will expire at: " msgstr ",您缓存的密码将过期于: " -#: src/sss_client/pam_sss.c:580 +#: src/sss_client/pam_sss.c:656 #, c-format msgid "Your password has expired. You have %1$d grace login(s) remaining." msgstr "您的密码已过期。您有 %1$d 剩余宽限登陆。" -#: src/sss_client/pam_sss.c:630 +#: src/sss_client/pam_sss.c:706 #, c-format msgid "Your password will expire in %1$d %2$s." msgstr "您的密码将于 %1$d %2$s 过期。" -#: src/sss_client/pam_sss.c:633 +#: src/sss_client/pam_sss.c:709 #, c-format msgid "Your password has expired." msgstr "您的密码已经过期。" -#: src/sss_client/pam_sss.c:684 +#: src/sss_client/pam_sss.c:760 msgid "Authentication is denied until: " msgstr "身份验证被拒绝,直到: " -#: src/sss_client/pam_sss.c:705 +#: src/sss_client/pam_sss.c:781 msgid "System is offline, password change not possible" msgstr "系统离线,无法更改密码" -#: src/sss_client/pam_sss.c:720 +#: src/sss_client/pam_sss.c:796 msgid "" "After changing the OTP password, you need to log out and back in order to " "acquire a ticket" msgstr "更改 OTP 密码后,您需要注销并重新登录以获得票证" -#: src/sss_client/pam_sss.c:735 +#: src/sss_client/pam_sss.c:813 msgid "PIN locked" msgstr "PIN 已锁定" -#: src/sss_client/pam_sss.c:750 +#: src/sss_client/pam_sss.c:828 msgid "" "No Kerberos TGT granted as the server does not support this method. Your " "single-sign on(SSO) experience will be affected." msgstr "" -#: src/sss_client/pam_sss.c:840 src/sss_client/pam_sss.c:853 +#: src/sss_client/pam_sss.c:918 src/sss_client/pam_sss.c:931 msgid "Password change failed. " msgstr "更改密码失败。 " -#: src/sss_client/pam_sss.c:1859 -#, c-format -msgid "Authenticate at %1$s and press ENTER." +#: src/sss_client/pam_sss.c:2028 +#, fuzzy, c-format +msgid "Authenticate at \"%1$s\"." msgstr "在 %1$s 处进行身份验证,然后按 ENTER 。" -#: src/sss_client/pam_sss.c:1862 -#, c-format -msgid "Authenticate with PIN %1$s at %2$s and press ENTER." +#: src/sss_client/pam_sss.c:2031 +#, fuzzy, c-format +msgid "Authenticate with PIN \"%1$s\" at \"%2$s\"." msgstr "在 %2$s 处使用 PIN %1$s 进行身份验证,然后按 ENTER 。" -#: src/sss_client/pam_sss.c:2281 +#: src/sss_client/pam_sss.c:2470 msgid "Please (re)insert (different) Smartcard" msgstr "请(重新)插入(不同的)智能卡" -#: src/sss_client/pam_sss.c:2482 +#: src/sss_client/pam_sss.c:2700 msgid "New Password: " msgstr "新密码: " -#: src/sss_client/pam_sss.c:2483 +#: src/sss_client/pam_sss.c:2701 msgid "Reenter new Password: " msgstr "重新输入新密码: " -#: src/sss_client/pam_sss.c:2676 src/sss_client/pam_sss.c:2679 +#: src/sss_client/pam_sss.c:2890 +msgid "Press ENTER to continue." +msgstr "" + +#: src/sss_client/pam_sss.c:2913 src/sss_client/pam_sss.c:2916 msgid "First Factor: " msgstr "第一因素: " -#: src/sss_client/pam_sss.c:2677 src/sss_client/pam_sss.c:2851 +#: src/sss_client/pam_sss.c:2914 src/sss_client/pam_sss.c:3088 msgid "Second Factor (optional): " msgstr "第二因素(可选): " -#: src/sss_client/pam_sss.c:2680 src/sss_client/pam_sss.c:2855 +#: src/sss_client/pam_sss.c:2917 src/sss_client/pam_sss.c:3092 msgid "Second Factor: " msgstr "第二因素: " -#: src/sss_client/pam_sss.c:2684 +#: src/sss_client/pam_sss.c:2921 msgid "Insert your passkey device, then press ENTER." msgstr "插入您的通行密钥设备,然后按回车键。" -#: src/sss_client/pam_sss.c:2688 src/sss_client/pam_sss.c:2696 +#: src/sss_client/pam_sss.c:2925 src/sss_client/pam_sss.c:2933 msgid "Password: " msgstr "密码: " -#: src/sss_client/pam_sss.c:2850 src/sss_client/pam_sss.c:2854 +#: src/sss_client/pam_sss.c:3087 src/sss_client/pam_sss.c:3091 msgid "First Factor (Current Password): " msgstr "第一因素(当前密码): " -#: src/sss_client/pam_sss.c:2874 +#: src/sss_client/pam_sss.c:3111 msgid "Current Password: " msgstr "当前密码: " -#: src/sss_client/pam_sss.c:3248 +#: src/sss_client/pam_sss.c:3485 msgid "Password expired. Change your password now." msgstr "密码已过期。立即更改密码。" @@ -2583,9 +2638,9 @@ msgstr "打开失败: %s\n" #: src/tools/sssctl/sssctl_cache.c:835 src/tools/sssctl/sssctl_cache.c:918 #: src/tools/sssctl/sssctl_cache.c:950 src/tools/sssctl/sssctl_cache.c:956 #: src/tools/sssctl/sssctl_cache.c:1010 src/tools/sssctl/sssctl_cache.c:1034 -#: src/tools/sssctl/sssctl_cache.c:1085 src/tools/sssctl/sssctl_cache.c:1194 -#: src/tools/sssctl/sssctl_cache.c:1229 src/tools/sssctl/sssctl_cache.c:1235 -#: src/tools/sssctl/sssctl_cache.c:1244 +#: src/tools/sssctl/sssctl_cache.c:1085 src/tools/sssctl/sssctl_cache.c:1195 +#: src/tools/sssctl/sssctl_cache.c:1230 src/tools/sssctl/sssctl_cache.c:1236 +#: src/tools/sssctl/sssctl_cache.c:1245 #, fuzzy msgid "talloc failed\n" msgstr "malloc 失败。\n" @@ -2663,26 +2718,26 @@ msgstr "" msgid "Unable to remove downloaded GPO files: %s\n" msgstr "无法删除日志文件\n" -#: src/tools/sssctl/sssctl_cache.c:1165 +#: src/tools/sssctl/sssctl_cache.c:1166 #, fuzzy, c-format msgid "Failed to fetch cache entry: %s\n" msgstr "打开失败: %s\n" -#: src/tools/sssctl/sssctl_cache.c:1170 +#: src/tools/sssctl/sssctl_cache.c:1171 #, fuzzy msgid "Could not determine object domain\n" msgstr "无法打开可用域\n" -#: src/tools/sssctl/sssctl_cache.c:1200 +#: src/tools/sssctl/sssctl_cache.c:1201 msgid "Could not find GUID attribute in GPO entry\n" msgstr "" -#: src/tools/sssctl/sssctl_cache.c:1206 +#: src/tools/sssctl/sssctl_cache.c:1207 #, fuzzy, c-format msgid "Failed to delete GPO: %s\n" msgstr "打开失败: %s\n" -#: src/tools/sssctl/sssctl_cache.c:1210 +#: src/tools/sssctl/sssctl_cache.c:1211 #, c-format msgid "%s removed from cache\n" msgstr "" @@ -2776,39 +2831,40 @@ msgstr "" "指定非默认 snippet dir(默认为在主配置文件所在的相同位置查找)。例如,如果配" "置被设置为 \"/my/path/sssd.conf\", snippet dir 为 \"/my/path/conf.d\" )" -#: src/tools/sssctl/sssctl_config.c:114 +#: src/tools/sssctl/sssctl_config.c:126 #, c-format msgid "File %1$s does not exist.\n" msgstr "文件 %1$s 不存在。\n" -#: src/tools/sssctl/sssctl_config.c:115 +#: src/tools/sssctl/sssctl_config.c:127 msgid "There is no configuration.\n" msgstr "没有任何配置。\n" -#: src/tools/sssctl/sssctl_config.c:120 +#: src/tools/sssctl/sssctl_config.c:132 #, fuzzy, c-format msgid "Configuration validation failed: %s\n" msgstr "索引操作失败:%1$s\n" -#: src/tools/sssctl/sssctl_config.c:121 +#: src/tools/sssctl/sssctl_config.c:133 msgid "Run with high debug level to see details.\n" msgstr "" -#: src/tools/sssctl/sssctl_config.c:130 -msgid "Failed to run validators" +#: src/tools/sssctl/sssctl_config.c:142 +#, fuzzy +msgid "Failed to run validators\n" msgstr "运行验证器失败" -#: src/tools/sssctl/sssctl_config.c:134 +#: src/tools/sssctl/sssctl_config.c:146 #, c-format msgid "Issues identified by validators: %zu\n" msgstr "验证者发现了问题: %zu\n" -#: src/tools/sssctl/sssctl_config.c:145 +#: src/tools/sssctl/sssctl_config.c:157 #, c-format msgid "Messages generated during configuration merging: %zu\n" msgstr "配置合并期间生成的消息: %zu\n" -#: src/tools/sssctl/sssctl_config.c:158 +#: src/tools/sssctl/sssctl_config.c:170 #, c-format msgid "Used configuration snippet files: %zu\n" msgstr "所使用的配置摘要文件: %zu\n" diff --git a/po/zh_TW.po b/po/zh_TW.po index 732d587337c..446081add25 100644 --- a/po/zh_TW.po +++ b/po/zh_TW.po @@ -4,12 +4,13 @@ # # Translators: # hsu zangmen , 2025, 2026. +# Alang Hsu , 2026. msgid "" msgstr "" "Project-Id-Version: PACKAGE VERSION\n" "Report-Msgid-Bugs-To: sssd-devel@lists.fedorahosted.org\n" -"POT-Creation-Date: 2026-01-14 14:57+0000\n" -"PO-Revision-Date: 2026-04-23 16:30+0000\n" +"POT-Creation-Date: 2026-10-02 15:57+0000\n" +"PO-Revision-Date: 2026-10-05 16:50+0000\n" "Last-Translator: hsu zangmen \n" "Language-Team: Chinese (Traditional) \n" @@ -18,510 +19,530 @@ msgstr "" "Content-Type: text/plain; charset=UTF-8\n" "Content-Transfer-Encoding: 8bit\n" "Plural-Forms: nplurals=1; plural=0;\n" -"X-Generator: Weblate 5.17\n" +"X-Generator: Weblate 2026.10\n" -#: src/config/SSSDConfig/sssdoptions.py:20 -#: src/config/SSSDConfig/sssdoptions.py:21 +#: src/config/SSSDConfig/sssdoptions.py:16 +#: src/config/SSSDConfig/sssdoptions.py:17 msgid "Set the verbosity of the debug logging" msgstr "設定除錯紀錄的疏密程度" -#: src/config/SSSDConfig/sssdoptions.py:22 +#: src/config/SSSDConfig/sssdoptions.py:18 msgid "Include timestamps in debug logs" msgstr "在除錯日誌內加入時間戳記" -#: src/config/SSSDConfig/sssdoptions.py:23 +#: src/config/SSSDConfig/sssdoptions.py:19 msgid "Include microseconds in timestamps in debug logs" -msgstr "" +msgstr "在除錯日誌內的時間戳記中加入微秒" -#: src/config/SSSDConfig/sssdoptions.py:24 +#: src/config/SSSDConfig/sssdoptions.py:20 msgid "Enable/disable debug backtrace" -msgstr "" +msgstr "啟用或停用除錯回溯" -#: src/config/SSSDConfig/sssdoptions.py:25 +#: src/config/SSSDConfig/sssdoptions.py:21 msgid "Watchdog timeout before restarting service" -msgstr "" +msgstr "重新啟動服務前的看門狗逾時" -#: src/config/SSSDConfig/sssdoptions.py:26 +#: src/config/SSSDConfig/sssdoptions.py:22 msgid "Command to start service" msgstr "啟動服務的指令" -#: src/config/SSSDConfig/sssdoptions.py:27 +#: src/config/SSSDConfig/sssdoptions.py:23 msgid "The number of file descriptors that may be opened by this responder" -msgstr "" +msgstr "此回應器可開啟的檔案描述符數量" -#: src/config/SSSDConfig/sssdoptions.py:28 +#: src/config/SSSDConfig/sssdoptions.py:24 msgid "Idle time before automatic disconnection of a client" -msgstr "" +msgstr "自動中斷用戶端連線前的閒置時間" -#: src/config/SSSDConfig/sssdoptions.py:29 +#: src/config/SSSDConfig/sssdoptions.py:25 msgid "Idle time before automatic shutdown of the responder" -msgstr "" +msgstr "自動關閉回應器前的閒置時間" -#: src/config/SSSDConfig/sssdoptions.py:30 +#: src/config/SSSDConfig/sssdoptions.py:26 msgid "Always query all the caches before querying the Data Providers" -msgstr "" +msgstr "在查詢資料提供者之前,一律先查詢所有快取" -#: src/config/SSSDConfig/sssdoptions.py:31 +#: src/config/SSSDConfig/sssdoptions.py:27 msgid "" "When SSSD switches to offline mode the amount of time before it tries to go " "back online will increase based upon the time spent disconnected. This value " "is in seconds and calculated by the following: offline_timeout + " "random_offset." msgstr "" +"當 SSSD 切換到離線模式時,嘗試重新上線前等待的時間會依離線時間長度而增加。此" +"值以秒為單位,計算方式如下:offline_timeout + random_offset。" -#: src/config/SSSDConfig/sssdoptions.py:36 +#: src/config/SSSDConfig/sssdoptions.py:32 msgid "SSSD Services to start" msgstr "要啟動的 SSSD 服務" -#: src/config/SSSDConfig/sssdoptions.py:37 +#: src/config/SSSDConfig/sssdoptions.py:33 msgid "SSSD Domains to start" msgstr "要啟動的 SSSD 網域" -#: src/config/SSSDConfig/sssdoptions.py:38 +#: src/config/SSSDConfig/sssdoptions.py:34 msgid "Regex to parse username and domain" msgstr "用來解析使用者名稱與網域的正規表示式" -#: src/config/SSSDConfig/sssdoptions.py:39 +#: src/config/SSSDConfig/sssdoptions.py:35 msgid "Printf-compatible format for displaying fully-qualified names" -msgstr "" +msgstr "顯示完整限定名稱的 printf 相容格式" -#: src/config/SSSDConfig/sssdoptions.py:40 +#: src/config/SSSDConfig/sssdoptions.py:36 msgid "" "Directory on the filesystem where SSSD should store Kerberos replay cache " "files." -msgstr "" +msgstr "SSSD 應在檔案系統上儲存 Kerberos 重播快取檔案的目錄。" -#: src/config/SSSDConfig/sssdoptions.py:41 +#: src/config/SSSDConfig/sssdoptions.py:37 msgid "Domain to add to names without a domain component." -msgstr "" +msgstr "要附加到沒有網域部分之名稱上的網域。" -#: src/config/SSSDConfig/sssdoptions.py:42 +#: src/config/SSSDConfig/sssdoptions.py:38 msgid "The user to drop privileges to" -msgstr "" +msgstr "要降低權限至的使用者" -#: src/config/SSSDConfig/sssdoptions.py:43 +#: src/config/SSSDConfig/sssdoptions.py:39 msgid "Tune certificate verification" -msgstr "" +msgstr "調整憑證驗證" -#: src/config/SSSDConfig/sssdoptions.py:44 +#: src/config/SSSDConfig/sssdoptions.py:40 msgid "All spaces in group or user names will be replaced with this character" -msgstr "" +msgstr "群組或使用者名稱中的所有空格將以這個字元取代" -#: src/config/SSSDConfig/sssdoptions.py:45 +#: src/config/SSSDConfig/sssdoptions.py:41 msgid "Tune sssd to honor or ignore netlink state changes" -msgstr "" +msgstr "調整 sssd 以採用或忽略 netlink 狀態變更" -#: src/config/SSSDConfig/sssdoptions.py:46 +#: src/config/SSSDConfig/sssdoptions.py:42 msgid "Enable or disable the implicit files domain" -msgstr "" +msgstr "啟用或停用隱含的 files 網域" -#: src/config/SSSDConfig/sssdoptions.py:47 +#: src/config/SSSDConfig/sssdoptions.py:43 msgid "A specific order of the domains to be looked up" -msgstr "" +msgstr "要查詢的網域之特定順序" -#: src/config/SSSDConfig/sssdoptions.py:48 +#: src/config/SSSDConfig/sssdoptions.py:44 msgid "" "Controls if SSSD should monitor the state of resolv.conf to identify when it " "needs to update its internal DNS resolver." msgstr "" +"控制 SSSD 是否應監控 resolv.conf 的狀態,以判斷何時需要更新其內部的 DNS 解析" +"器。" -#: src/config/SSSDConfig/sssdoptions.py:50 +#: src/config/SSSDConfig/sssdoptions.py:46 msgid "" "SSSD monitors the state of resolv.conf to identify when it needs to update " "its internal DNS resolver. By default, we will attempt to use inotify for " "this, and will fall back to polling resolv.conf every five seconds if " "inotify cannot be used." msgstr "" +"SSSD 監控 resolv.conf 的狀態,以判斷何時需要更新其內部的 DNS 解析器。預設會嘗" +"試使用 inotify 達成,若無法使用 inotify,則改為每五秒輪詢 resolv.conf。" -#: src/config/SSSDConfig/sssdoptions.py:53 +#: src/config/SSSDConfig/sssdoptions.py:49 msgid "Run PAC responder automatically for AD and IPA provider" -msgstr "" +msgstr "自動為 AD 與 IPA 提供者執行 PAC 回應器" -#: src/config/SSSDConfig/sssdoptions.py:54 +#: src/config/SSSDConfig/sssdoptions.py:50 msgid "Enable or disable core dumps for all SSSD processes." -msgstr "" +msgstr "啟用或停用所有 SSSD 處理程式的核心傾印。" -#: src/config/SSSDConfig/sssdoptions.py:55 +#: src/config/SSSDConfig/sssdoptions.py:51 msgid "Tune passkey verification behavior" -msgstr "" +msgstr "調整金鑰驗證行為" -#: src/config/SSSDConfig/sssdoptions.py:58 +#: src/config/SSSDConfig/sssdoptions.py:54 msgid "Enumeration cache timeout length (seconds)" -msgstr "" +msgstr "列舉快取逾時長度(秒)" -#: src/config/SSSDConfig/sssdoptions.py:59 +#: src/config/SSSDConfig/sssdoptions.py:55 msgid "Entry cache background update timeout length (seconds)" -msgstr "" +msgstr "項目快取背景更新逾時長度(秒)" -#: src/config/SSSDConfig/sssdoptions.py:60 -#: src/config/SSSDConfig/sssdoptions.py:125 +#: src/config/SSSDConfig/sssdoptions.py:56 +#: src/config/SSSDConfig/sssdoptions.py:124 msgid "Negative cache timeout length (seconds)" -msgstr "" +msgstr "負面快取逾時長度(秒)" -#: src/config/SSSDConfig/sssdoptions.py:61 +#: src/config/SSSDConfig/sssdoptions.py:57 msgid "Users that SSSD should explicitly ignore" msgstr "SSSD 應該明確忽略的使用者" -#: src/config/SSSDConfig/sssdoptions.py:62 +#: src/config/SSSDConfig/sssdoptions.py:58 msgid "Groups that SSSD should explicitly ignore" msgstr "SSSD 應該明確忽略的群組" -#: src/config/SSSDConfig/sssdoptions.py:63 +#: src/config/SSSDConfig/sssdoptions.py:59 msgid "Should filtered users appear in groups" msgstr "過濾的使用者是否應該顯現在群組內" -#: src/config/SSSDConfig/sssdoptions.py:64 +#: src/config/SSSDConfig/sssdoptions.py:60 msgid "The value of the password field the NSS provider should return" -msgstr "" +msgstr "NSS 提供者應回傳的密碼欄位值" -#: src/config/SSSDConfig/sssdoptions.py:65 +#: src/config/SSSDConfig/sssdoptions.py:61 msgid "Override homedir value from the identity provider with this value" -msgstr "" +msgstr "使用此值覆寫身分提供者的家目錄值" -#: src/config/SSSDConfig/sssdoptions.py:66 +#: src/config/SSSDConfig/sssdoptions.py:62 msgid "" "Substitute empty homedir value from the identity provider with this value" -msgstr "" +msgstr "使用此值取代身分提供者傳回的空家目錄值" -#: src/config/SSSDConfig/sssdoptions.py:67 +#: src/config/SSSDConfig/sssdoptions.py:63 msgid "Override shell value from the identity provider with this value" -msgstr "" +msgstr "使用此值覆寫身分提供者的 shell 值" -#: src/config/SSSDConfig/sssdoptions.py:68 +#: src/config/SSSDConfig/sssdoptions.py:64 msgid "The list of shells users are allowed to log in with" -msgstr "" +msgstr "允許使用者登入的 shell 清單" -#: src/config/SSSDConfig/sssdoptions.py:69 +#: src/config/SSSDConfig/sssdoptions.py:65 msgid "" "The list of shells that will be vetoed, and replaced with the fallback shell" -msgstr "" +msgstr "將被否決並以後備 shell 取代的 shell 清單" -#: src/config/SSSDConfig/sssdoptions.py:70 +#: src/config/SSSDConfig/sssdoptions.py:66 msgid "" "If a shell stored in central directory is allowed but not available, use " "this fallback" -msgstr "" +msgstr "若中央目錄中儲存的 shell 雖被允許但不可用,則使用此後備" -#: src/config/SSSDConfig/sssdoptions.py:71 +#: src/config/SSSDConfig/sssdoptions.py:67 msgid "Shell to use if the provider does not list one" -msgstr "" +msgstr "提供者未列出 shell 時要使用的 shell" -#: src/config/SSSDConfig/sssdoptions.py:72 +#: src/config/SSSDConfig/sssdoptions.py:68 msgid "How long will be in-memory cache records valid" -msgstr "" +msgstr "記憶體中快取紀錄的有效時間" -#: src/config/SSSDConfig/sssdoptions.py:74 +#: src/config/SSSDConfig/sssdoptions.py:70 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for passwd requests" -msgstr "" +msgstr "為 passwd 請求配置於快速記憶體快取中的資料表大小(百萬位元組)" -#: src/config/SSSDConfig/sssdoptions.py:76 +#: src/config/SSSDConfig/sssdoptions.py:72 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for group requests" -msgstr "" +msgstr "為 group 請求配置於快速記憶體快取中的資料表大小(百萬位元組)" -#: src/config/SSSDConfig/sssdoptions.py:78 +#: src/config/SSSDConfig/sssdoptions.py:74 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for initgroups requests" -msgstr "" +msgstr "為 initgroups 請求配置於快速記憶體快取中的資料表大小(百萬位元組)" -#: src/config/SSSDConfig/sssdoptions.py:79 +#: src/config/SSSDConfig/sssdoptions.py:75 msgid "" "The value of this option will be used in the expansion of the " "override_homedir option if the template contains the format string %H." -msgstr "" +msgstr "若範本包含格式字串 %H,此選項的值將用於展開 override_homedir 選項。" -#: src/config/SSSDConfig/sssdoptions.py:81 +#: src/config/SSSDConfig/sssdoptions.py:77 msgid "" "Specifies time in seconds for which the list of subdomains will be " "considered valid." -msgstr "" +msgstr "指定子網域清單被視為有效的時間(秒)。" -#: src/config/SSSDConfig/sssdoptions.py:83 +#: src/config/SSSDConfig/sssdoptions.py:79 msgid "" "The entry cache can be set to automatically update entries in the background " "if they are requested beyond a percentage of the entry_cache_timeout value " "for the domain." msgstr "" +"若項目在超過網域的 entry_cache_timeout 值一定百分比後仍被請求,可設定項目快取" +"在背景自動更新項目。" -#: src/config/SSSDConfig/sssdoptions.py:88 +#: src/config/SSSDConfig/sssdoptions.py:84 msgid "How long to allow cached logins between online logins (days)" -msgstr "" +msgstr "允許線上登入之間使用快取登入的時間(天)" -#: src/config/SSSDConfig/sssdoptions.py:89 +#: src/config/SSSDConfig/sssdoptions.py:85 msgid "How many failed logins attempts are allowed when offline" -msgstr "" +msgstr "離線時允許的失敗登入嘗試次數" -#: src/config/SSSDConfig/sssdoptions.py:91 +#: src/config/SSSDConfig/sssdoptions.py:87 msgid "" "How long (minutes) to deny login after offline_failed_login_attempts has " "been reached" -msgstr "" +msgstr "達到 offline_failed_login_attempts 之後拒絕登入的時間(分鐘)" -#: src/config/SSSDConfig/sssdoptions.py:92 +#: src/config/SSSDConfig/sssdoptions.py:88 msgid "What kind of messages are displayed to the user during authentication" -msgstr "" +msgstr "認證期間顯示給使用者的訊息類型" -#: src/config/SSSDConfig/sssdoptions.py:93 +#: src/config/SSSDConfig/sssdoptions.py:89 msgid "Filter PAM responses sent to the pam_sss" -msgstr "" +msgstr "過濾傳送給 pam_sss 的 PAM 回應" -#: src/config/SSSDConfig/sssdoptions.py:94 +#: src/config/SSSDConfig/sssdoptions.py:90 msgid "How many seconds to keep identity information cached for PAM requests" -msgstr "" +msgstr "為 PAM 請求快取身分資訊的秒數" -#: src/config/SSSDConfig/sssdoptions.py:95 +#: src/config/SSSDConfig/sssdoptions.py:91 msgid "How many days before password expiration a warning should be displayed" -msgstr "" +msgstr "密碼到期前多少天應顯示警告" -#: src/config/SSSDConfig/sssdoptions.py:96 +#: src/config/SSSDConfig/sssdoptions.py:92 msgid "List of trusted uids or user's name" -msgstr "" +msgstr "受信任的 uid 或使用者名稱的清單" -#: src/config/SSSDConfig/sssdoptions.py:97 +#: src/config/SSSDConfig/sssdoptions.py:93 msgid "List of domains accessible even for untrusted users." -msgstr "" +msgstr "即使未受信任的使用者也能存取的網域清單。" -#: src/config/SSSDConfig/sssdoptions.py:98 +#: src/config/SSSDConfig/sssdoptions.py:94 msgid "Message printed when user account is expired." -msgstr "" +msgstr "使用者帳號到期時顯示的訊息。" -#: src/config/SSSDConfig/sssdoptions.py:99 +#: src/config/SSSDConfig/sssdoptions.py:95 msgid "Message printed when user account is locked." -msgstr "" +msgstr "使用者帳號鎖定時顯示的訊息。" -#: src/config/SSSDConfig/sssdoptions.py:100 +#: src/config/SSSDConfig/sssdoptions.py:96 msgid "Allow certificate based/Smartcard authentication." -msgstr "" +msgstr "允許以憑證/智慧卡進行認證。" -#: src/config/SSSDConfig/sssdoptions.py:101 +#: src/config/SSSDConfig/sssdoptions.py:97 msgid "Path to certificate database with PKCS#11 modules." -msgstr "" +msgstr "含 PKCS#11 模組的憑證資料庫路徑。" -#: src/config/SSSDConfig/sssdoptions.py:102 -#, fuzzy +#: src/config/SSSDConfig/sssdoptions.py:98 msgid "Tune certificate verification for PAM authentication." -msgstr "需要 TLS 憑證驗證" +msgstr "調整 PAM 認證的憑證驗證。" -#: src/config/SSSDConfig/sssdoptions.py:103 +#: src/config/SSSDConfig/sssdoptions.py:99 msgid "How many seconds will pam_sss wait for p11_child to finish" -msgstr "" +msgstr "pam_sss 等待 p11_child 完成的秒數" -#: src/config/SSSDConfig/sssdoptions.py:104 +#: src/config/SSSDConfig/sssdoptions.py:100 msgid "Which PAM services are permitted to contact application domains" -msgstr "" +msgstr "允許哪些 PAM 服務聯絡應用程式網域" -#: src/config/SSSDConfig/sssdoptions.py:105 +#: src/config/SSSDConfig/sssdoptions.py:101 msgid "Allowed services for using smartcards" -msgstr "" +msgstr "允許使用智慧卡的服務" -#: src/config/SSSDConfig/sssdoptions.py:106 +#: src/config/SSSDConfig/sssdoptions.py:102 msgid "Additional timeout to wait for a card if requested" -msgstr "" +msgstr "若有要求,等待卡片就緒的額外逾時" -#: src/config/SSSDConfig/sssdoptions.py:107 +#: src/config/SSSDConfig/sssdoptions.py:103 msgid "" "PKCS#11 URI to restrict the selection of devices for Smartcard authentication" -msgstr "" +msgstr "用於限制智慧卡認證裝置選取的 PKCS#11 URI" -#: src/config/SSSDConfig/sssdoptions.py:108 +#: src/config/SSSDConfig/sssdoptions.py:104 msgid "When shall the PAM responder force an initgroups request" -msgstr "" +msgstr "PAM 回應器應於何時強制發出 initgroups 請求" -#: src/config/SSSDConfig/sssdoptions.py:109 +#: src/config/SSSDConfig/sssdoptions.py:105 msgid "List of PAM services that are allowed to authenticate with GSSAPI." -msgstr "" +msgstr "允許使用 GSSAPI 認證的 PAM 服務清單。" -#: src/config/SSSDConfig/sssdoptions.py:110 +#: src/config/SSSDConfig/sssdoptions.py:106 msgid "Whether to match authenticated UPN with target user" -msgstr "" +msgstr "是否將已認證的 UPN 與目標使用者比對" -#: src/config/SSSDConfig/sssdoptions.py:111 +#: src/config/SSSDConfig/sssdoptions.py:107 msgid "" "List of pairs : that must be enforced " "for PAM access with GSSAPI authentication" msgstr "" +"使用 GSSAPI 認證的 PAM 存取必須強制執行的 :<認證指示器> 配對清單" -#: src/config/SSSDConfig/sssdoptions.py:113 -msgid "Allow passkey device authentication." +#: src/config/SSSDConfig/sssdoptions.py:109 +msgid "" +"List of triples :: that assigns " +"additional information from the Kerberos ticket to an authentication " +"indicator." msgstr "" -#: src/config/SSSDConfig/sssdoptions.py:114 +#: src/config/SSSDConfig/sssdoptions.py:112 +msgid "Allow passkey device authentication." +msgstr "允許金鑰裝置認證。" + +#: src/config/SSSDConfig/sssdoptions.py:113 msgid "How many seconds will pam_sss wait for passkey_child to finish" -msgstr "" +msgstr "pam_sss 等待 passkey_child 完成的秒數" -#: src/config/SSSDConfig/sssdoptions.py:115 +#: src/config/SSSDConfig/sssdoptions.py:114 msgid "Enable debugging in the libfido2 library" -msgstr "" +msgstr "在 libfido2 函式庫中啟用除錯" -#: src/config/SSSDConfig/sssdoptions.py:116 +#: src/config/SSSDConfig/sssdoptions.py:115 msgid "Enable JSON protocol for authentication methods selection." -msgstr "" +msgstr "啟用 JSON 協定以選取認證方法。" -#: src/config/SSSDConfig/sssdoptions.py:119 +#: src/config/SSSDConfig/sssdoptions.py:118 msgid "Whether to evaluate the time-based attributes in sudo rules" -msgstr "" +msgstr "是否評估 sudo 規則中與時間相關的屬性" -#: src/config/SSSDConfig/sssdoptions.py:120 +#: src/config/SSSDConfig/sssdoptions.py:119 msgid "If true, SSSD will switch back to lower-wins ordering logic" -msgstr "" +msgstr "若為 true,SSSD 將切回較低優先順序得勝的排序邏輯" -#: src/config/SSSDConfig/sssdoptions.py:121 +#: src/config/SSSDConfig/sssdoptions.py:120 msgid "" "Maximum number of rules that can be refreshed at once. If this is exceeded, " "full refresh is performed." -msgstr "" +msgstr "一次可重新整理的規則數上限。若超過此數,將執行完整重新整理。" -#: src/config/SSSDConfig/sssdoptions.py:128 +#: src/config/SSSDConfig/sssdoptions.py:127 msgid "Whether to hash host names and addresses in the known_hosts file" -msgstr "" +msgstr "是否對 known_hosts 檔案中的主機名稱與位址進行雜湊" -#: src/config/SSSDConfig/sssdoptions.py:129 +#: src/config/SSSDConfig/sssdoptions.py:128 msgid "" "How many seconds to keep a host in the known_hosts file after its host keys " "were requested" -msgstr "" +msgstr "主機金鑰被請求之後,主機保留在 known_hosts 檔案中的秒數" -#: src/config/SSSDConfig/sssdoptions.py:131 +#: src/config/SSSDConfig/sssdoptions.py:130 msgid "Path to storage of trusted CA certificates" -msgstr "" +msgstr "受信任 CA 憑證儲存的路徑" -#: src/config/SSSDConfig/sssdoptions.py:132 +#: src/config/SSSDConfig/sssdoptions.py:131 msgid "Allow to generate ssh-keys from certificates" -msgstr "" +msgstr "允許從憑證產生 ssh 金鑰" -#: src/config/SSSDConfig/sssdoptions.py:133 +#: src/config/SSSDConfig/sssdoptions.py:132 msgid "" "Use the following matching rules to filter the certificates for ssh-key " "generation" -msgstr "" +msgstr "使用下列比對規則篩選用於產生 ssh 金鑰的憑證" -#: src/config/SSSDConfig/sssdoptions.py:137 +#: src/config/SSSDConfig/sssdoptions.py:136 msgid "List of UIDs or user names allowed to access the PAC responder" -msgstr "" +msgstr "允許存取 PAC 回應器的 UID 或使用者名稱清單" -#: src/config/SSSDConfig/sssdoptions.py:138 +#: src/config/SSSDConfig/sssdoptions.py:137 msgid "How long the PAC data is considered valid" -msgstr "" +msgstr "PAC 資料被視為有效的時間" -#: src/config/SSSDConfig/sssdoptions.py:139 +#: src/config/SSSDConfig/sssdoptions.py:138 msgid "Validate the PAC" -msgstr "" +msgstr "驗證 PAC" -#: src/config/SSSDConfig/sssdoptions.py:142 +#: src/config/SSSDConfig/sssdoptions.py:141 msgid "List of user attributes the InfoPipe is allowed to publish" -msgstr "" +msgstr "允許 InfoPipe 發布的使用者屬性清單" -#: src/config/SSSDConfig/sssdoptions.py:145 +#: src/config/SSSDConfig/sssdoptions.py:144 msgid "" "One of the following strings specifying the scope of session recording: none " "- No users are recorded. some - Users/groups specified by users and groups " "options are recorded. all - All users are recorded." msgstr "" +"下列字串之一,指定工作階段錄製的範圍:none - 不錄製任何使用者。some - 錄製 " +"users 與 groups 選項指定的使用者/群組。all - 錄製所有使用者。" -#: src/config/SSSDConfig/sssdoptions.py:148 +#: src/config/SSSDConfig/sssdoptions.py:147 msgid "" "A comma-separated list of users which should have session recording enabled. " "Matches user names as returned by NSS. I.e. after the possible space " "replacement, case changes, etc." msgstr "" +"應啟用工作階段錄製的使用者清單,以逗號分隔。比對 NSS 回傳的使用者名稱,亦即經" +"過可能的空格取代、大小寫變更等處理之後的名稱。" -#: src/config/SSSDConfig/sssdoptions.py:150 +#: src/config/SSSDConfig/sssdoptions.py:149 msgid "" "A comma-separated list of groups, members of which should have session " "recording enabled. Matches group names as returned by NSS. I.e. after the " "possible space replacement, case changes, etc." msgstr "" +"成員應啟用工作階段錄製的群組清單,以逗號分隔。比對 NSS 回傳的群組名稱,亦即經" +"過可能的空格取代、大小寫變更等處理之後的名稱。" -#: src/config/SSSDConfig/sssdoptions.py:153 +#: src/config/SSSDConfig/sssdoptions.py:152 msgid "" "A comma-separated list of users to be excluded from recording, only when " "scope=all" -msgstr "" +msgstr "要排除於錄製之外的使用者清單,以逗號分隔,僅在 scope=all 時生效" -#: src/config/SSSDConfig/sssdoptions.py:154 +#: src/config/SSSDConfig/sssdoptions.py:153 msgid "" "A comma-separated list of groups, members of which should be excluded from " "recording, only when scope=all. " -msgstr "" +msgstr "成員應排除於錄製之外的群組清單,以逗號分隔,僅在 scope=all 時生效。 " -#: src/config/SSSDConfig/sssdoptions.py:158 +#: src/config/SSSDConfig/sssdoptions.py:157 msgid "Identity provider" msgstr "身分提供者" -#: src/config/SSSDConfig/sssdoptions.py:159 +#: src/config/SSSDConfig/sssdoptions.py:158 msgid "Authentication provider" msgstr "認證提供者" -#: src/config/SSSDConfig/sssdoptions.py:160 +#: src/config/SSSDConfig/sssdoptions.py:159 msgid "Access control provider" msgstr "存取控制提供者" -#: src/config/SSSDConfig/sssdoptions.py:161 +#: src/config/SSSDConfig/sssdoptions.py:160 msgid "Password change provider" msgstr "密碼變更提供者" -#: src/config/SSSDConfig/sssdoptions.py:162 +#: src/config/SSSDConfig/sssdoptions.py:161 msgid "SUDO provider" -msgstr "" +msgstr "SUDO 提供者" -#: src/config/SSSDConfig/sssdoptions.py:163 +#: src/config/SSSDConfig/sssdoptions.py:162 msgid "Autofs provider" -msgstr "" +msgstr "Autofs 提供者" -#: src/config/SSSDConfig/sssdoptions.py:164 +#: src/config/SSSDConfig/sssdoptions.py:163 msgid "Host identity provider" -msgstr "" +msgstr "主機身分提供者" -#: src/config/SSSDConfig/sssdoptions.py:165 +#: src/config/SSSDConfig/sssdoptions.py:164 msgid "SELinux provider" -msgstr "" +msgstr "SELinux 提供者" -#: src/config/SSSDConfig/sssdoptions.py:166 +#: src/config/SSSDConfig/sssdoptions.py:165 msgid "Session management provider" -msgstr "" +msgstr "工作階段管理提供者" -#: src/config/SSSDConfig/sssdoptions.py:167 +#: src/config/SSSDConfig/sssdoptions.py:166 msgid "Resolver provider" -msgstr "" +msgstr "解析器提供者" -#: src/config/SSSDConfig/sssdoptions.py:170 +#: src/config/SSSDConfig/sssdoptions.py:169 msgid "Whether the domain is usable by the OS or by applications" -msgstr "" +msgstr "此網域是否可供作業系統或應用程式使用" -#: src/config/SSSDConfig/sssdoptions.py:171 -#, fuzzy +#: src/config/SSSDConfig/sssdoptions.py:170 msgid "Enable or disable the domain" -msgstr "啟用憑證驗證" +msgstr "啟用或停用此網域" -#: src/config/SSSDConfig/sssdoptions.py:172 +#: src/config/SSSDConfig/sssdoptions.py:171 msgid "Minimum user ID" msgstr "最小的使用者 ID" -#: src/config/SSSDConfig/sssdoptions.py:173 +#: src/config/SSSDConfig/sssdoptions.py:172 msgid "Maximum user ID" msgstr "最大的使用者 ID" -#: src/config/SSSDConfig/sssdoptions.py:174 +#: src/config/SSSDConfig/sssdoptions.py:173 msgid "Enable enumerating all users/groups" msgstr "啟用所有使用者或群組的列舉" -#: src/config/SSSDConfig/sssdoptions.py:175 +#: src/config/SSSDConfig/sssdoptions.py:174 msgid "Cache credentials for offline login" msgstr "供離線登入使用的快取憑證" -#: src/config/SSSDConfig/sssdoptions.py:176 +#: src/config/SSSDConfig/sssdoptions.py:175 msgid "Display users/groups in fully-qualified form" -msgstr "" +msgstr "以完整限定形式顯示使用者/群組" -#: src/config/SSSDConfig/sssdoptions.py:177 +#: src/config/SSSDConfig/sssdoptions.py:176 msgid "Don't include group members in group lookups" -msgstr "" +msgstr "在群組查詢中不包含群組成員" -#: src/config/SSSDConfig/sssdoptions.py:178 +#: src/config/SSSDConfig/sssdoptions.py:177 #: src/config/SSSDConfig/sssdoptions.py:190 #: src/config/SSSDConfig/sssdoptions.py:191 #: src/config/SSSDConfig/sssdoptions.py:192 @@ -530,161 +551,166 @@ msgstr "" #: src/config/SSSDConfig/sssdoptions.py:195 #: src/config/SSSDConfig/sssdoptions.py:196 msgid "Entry cache timeout length (seconds)" -msgstr "" +msgstr "項目快取逾時長度(秒)" -#: src/config/SSSDConfig/sssdoptions.py:179 +#: src/config/SSSDConfig/sssdoptions.py:178 msgid "" "Restrict or prefer a specific address family when performing DNS lookups" -msgstr "" +msgstr "執行 DNS 查詢時限制或偏好特定的位址家族" -#: src/config/SSSDConfig/sssdoptions.py:180 +#: src/config/SSSDConfig/sssdoptions.py:179 msgid "How long to keep cached entries after last successful login (days)" -msgstr "" +msgstr "最後一次成功登入後保留快取項目的時間(天)" -#: src/config/SSSDConfig/sssdoptions.py:181 +#: src/config/SSSDConfig/sssdoptions.py:180 msgid "" "How long should SSSD talk to single DNS server before trying next server " "(miliseconds)" -msgstr "" +msgstr "SSSD 嘗試下一台伺服器前,與單一 DNS 伺服器通訊的時間(毫秒)" -#: src/config/SSSDConfig/sssdoptions.py:183 +#: src/config/SSSDConfig/sssdoptions.py:182 msgid "How long should keep trying to resolve single DNS query (seconds)" -msgstr "" +msgstr "持續嘗試解析單一 DNS 查詢的時間(秒)" -#: src/config/SSSDConfig/sssdoptions.py:184 +#: src/config/SSSDConfig/sssdoptions.py:183 msgid "How long to wait for replies from DNS when resolving servers (seconds)" -msgstr "" +msgstr "解析伺服器時等待 DNS 回覆的時間(秒)" -#: src/config/SSSDConfig/sssdoptions.py:185 +#: src/config/SSSDConfig/sssdoptions.py:184 msgid "The domain part of service discovery DNS query" -msgstr "" +msgstr "服務探索 DNS 查詢的網域部分" -#: src/config/SSSDConfig/sssdoptions.py:186 +#: src/config/SSSDConfig/sssdoptions.py:185 msgid "" "Specifies the interval, in seconds, that SSSD waits before attempting to " "reconnect to the primary server after a successful connection to the backup " "server" msgstr "" +"指定 SSSD 在成功連線到備份伺服器後,嘗試重新連線到主要伺服器前等待的間隔" +"(秒)" -#: src/config/SSSDConfig/sssdoptions.py:188 +#: src/config/SSSDConfig/sssdoptions.py:187 msgid "Override GID value from the identity provider with this value" -msgstr "" +msgstr "使用此值覆寫身分提供者的 GID 值" -#: src/config/SSSDConfig/sssdoptions.py:189 +#: src/config/SSSDConfig/sssdoptions.py:188 msgid "Treat usernames as case sensitive" +msgstr "將使用者名稱視為區分大小寫" + +#: src/config/SSSDConfig/sssdoptions.py:189 +msgid "Lookups by ID are expensive or do not work at all" msgstr "" #: src/config/SSSDConfig/sssdoptions.py:197 msgid "How often should expired entries be refreshed in background" -msgstr "" +msgstr "過期項目在背景重新整理的頻率" #: src/config/SSSDConfig/sssdoptions.py:198 msgid "Maximum period deviation when refreshing expired entries in background" -msgstr "" +msgstr "在背景重新整理過期項目時的最大時間偏差" #: src/config/SSSDConfig/sssdoptions.py:199 msgid "Whether to automatically update the client's DNS entry" -msgstr "" +msgstr "是否自動更新用戶端的 DNS 記錄" #: src/config/SSSDConfig/sssdoptions.py:200 msgid "" "Whether DNS update of A and AAAA record should be performed in one update or " "in two separate updates" -msgstr "" +msgstr "A 與 AAAA 記錄的 DNS 更新應在一次更新中執行,還是分兩次更新執行" #: src/config/SSSDConfig/sssdoptions.py:202 msgid "The TTL to apply to the client's DNS entry after updating it" -msgstr "" +msgstr "更新後套用於用戶端 DNS 記錄的 TTL" #: src/config/SSSDConfig/sssdoptions.py:203 msgid "The interface whose IP should be used for dynamic DNS updates" -msgstr "" +msgstr "動態 DNS 更新應使用其 IP 的網路介面" #: src/config/SSSDConfig/sssdoptions.py:204 msgid "The list of IP addresses that should be used for dynamic DNS updates" -msgstr "" +msgstr "動態 DNS 更新應使用的 IP 位址清單" #: src/config/SSSDConfig/sssdoptions.py:205 msgid "How often to periodically update the client's DNS entry" -msgstr "" +msgstr "定期更新用戶端 DNS 記錄的頻率" #: src/config/SSSDConfig/sssdoptions.py:206 msgid "Maximum period deviation when updating the client's DNS entry" -msgstr "" +msgstr "更新用戶端 DNS 記錄時的最大時間偏差" #: src/config/SSSDConfig/sssdoptions.py:207 msgid "Whether the provider should explicitly update the PTR record as well" -msgstr "" +msgstr "提供者是否也應明確更新 PTR 記錄" #: src/config/SSSDConfig/sssdoptions.py:208 msgid "Whether the nsupdate utility should default to using TCP" -msgstr "" +msgstr "nsupdate 工具是否應預設使用 TCP" #: src/config/SSSDConfig/sssdoptions.py:209 msgid "What kind of authentication should be used to perform the DNS update" -msgstr "" +msgstr "執行 DNS 更新應使用哪種認證" #: src/config/SSSDConfig/sssdoptions.py:210 msgid "Override the DNS server used to perform the DNS update" -msgstr "" +msgstr "覆寫用於執行 DNS 更新的 DNS 伺服器" #: src/config/SSSDConfig/sssdoptions.py:211 msgid "The file of the certificate authorities certificates for DoT" -msgstr "" +msgstr "DoT 的憑證授權機構憑證檔案" #: src/config/SSSDConfig/sssdoptions.py:212 -#, fuzzy msgid "The certificate(s) file for authentication for the DoT transport" -msgstr "需要 TLS 憑證驗證" +msgstr "用於 DoT 傳輸認證的憑證檔案" #: src/config/SSSDConfig/sssdoptions.py:213 msgid "The key file for authenticated encryption for the DoT transport" -msgstr "" +msgstr "用於 DoT 傳輸驗證加密的金鑰檔案" #: src/config/SSSDConfig/sssdoptions.py:214 msgid "How often should subdomains list be refreshed" -msgstr "" +msgstr "子網域清單重新整理的頻率" #: src/config/SSSDConfig/sssdoptions.py:215 msgid "Maximum period deviation when refreshing the subdomain list" -msgstr "" +msgstr "重新整理子網域清單時的最大時間偏差" #: src/config/SSSDConfig/sssdoptions.py:216 msgid "List of options that should be inherited into a subdomain" -msgstr "" +msgstr "應繼承到子網域的選項清單" #: src/config/SSSDConfig/sssdoptions.py:217 msgid "Default subdomain homedir value" -msgstr "" +msgstr "預設的子網域家目錄值" #: src/config/SSSDConfig/sssdoptions.py:218 msgid "How long can cached credentials be used for cached authentication" -msgstr "" +msgstr "快取認證可使用快取憑證的時間" #: src/config/SSSDConfig/sssdoptions.py:219 msgid "Whether to automatically create private groups for users" -msgstr "" +msgstr "是否自動為使用者建立私有群組" #: src/config/SSSDConfig/sssdoptions.py:220 msgid "Display a warning N days before the password expires." -msgstr "" +msgstr "在密碼到期前 N 天顯示警告。" #: src/config/SSSDConfig/sssdoptions.py:221 msgid "" "Various tags stored by the realmd configuration service for this domain." -msgstr "" +msgstr "realmd 設定服務為此網域儲存的各種標籤。" #: src/config/SSSDConfig/sssdoptions.py:222 msgid "" "The provider which should handle fetching of subdomains. This value should " "be always the same as id_provider." -msgstr "" +msgstr "應負責取得子網域的提供者。此值應永遠與 id_provider 相同。" #: src/config/SSSDConfig/sssdoptions.py:224 msgid "" "How many seconds to keep a host ssh key after refresh. IE how long to cache " "the host key for." -msgstr "" +msgstr "重新整理後保留主機 ssh 金鑰的秒數。亦即主機金鑰的快取時間。" #: src/config/SSSDConfig/sssdoptions.py:226 msgid "" @@ -692,10 +718,12 @@ msgid "" "this value determines the minimal length the first authentication factor " "(long term password) must have to be saved as SHA512 hash into the cache." msgstr "" +"若使用雙因素認證 (2FA) 且應儲存憑證,此值決定第一個認證因素(長期密碼)要存入" +"快取作為 SHA512 雜湊所需的最短長度。" #: src/config/SSSDConfig/sssdoptions.py:230 msgid "Local authentication methods policy " -msgstr "" +msgstr "本機認證方法原則 " #: src/config/SSSDConfig/sssdoptions.py:233 msgid "IPA domain" @@ -707,7 +735,7 @@ msgstr "IPA 伺服器位址" #: src/config/SSSDConfig/sssdoptions.py:235 msgid "Address of backup IPA server" -msgstr "" +msgstr "備份 IPA 伺服器的位址" #: src/config/SSSDConfig/sssdoptions.py:236 msgid "IPA client hostname" @@ -715,305 +743,310 @@ msgstr "IPA 客戶端主機名稱" #: src/config/SSSDConfig/sssdoptions.py:237 msgid "Search base for HBAC related objects" -msgstr "" +msgstr "HBAC 相關物件的搜尋基準" #: src/config/SSSDConfig/sssdoptions.py:238 msgid "" "The amount of time between lookups of the HBAC rules against the IPA server" -msgstr "" +msgstr "向 IPA 伺服器查詢 HBAC 規則之間的間隔時間" #: src/config/SSSDConfig/sssdoptions.py:239 msgid "" "The amount of time in seconds between lookups of the SELinux maps against " "the IPA server" -msgstr "" +msgstr "向 IPA 伺服器查詢 SELinux 對應之間的間隔時間(秒)" #: src/config/SSSDConfig/sssdoptions.py:241 msgid "If set to false, host argument given by PAM will be ignored" -msgstr "" +msgstr "若設為 false,將忽略 PAM 提供的主機引數" #: src/config/SSSDConfig/sssdoptions.py:242 msgid "The automounter location this IPA client is using" -msgstr "" +msgstr "此 IPA 用戶端正在使用的自動掛載位置" #: src/config/SSSDConfig/sssdoptions.py:243 msgid "Search base for object containing info about IPA domain" -msgstr "" +msgstr "包含 IPA 網域資訊之物件的搜尋基準" #: src/config/SSSDConfig/sssdoptions.py:244 msgid "Search base for objects containing info about ID ranges" -msgstr "" +msgstr "包含 ID 範圍資訊之物件的搜尋基準" #: src/config/SSSDConfig/sssdoptions.py:245 msgid "Search base for view containers" -msgstr "" +msgstr "檢視容器的搜尋基準" #: src/config/SSSDConfig/sssdoptions.py:246 msgid "Objectclass for view containers" -msgstr "" +msgstr "檢視容器的物件類別" #: src/config/SSSDConfig/sssdoptions.py:247 msgid "Attribute with the name of the view" -msgstr "" +msgstr "包含檢視名稱的屬性" #: src/config/SSSDConfig/sssdoptions.py:248 msgid "Objectclass for override objects" -msgstr "" +msgstr "覆寫物件的物件類別" #: src/config/SSSDConfig/sssdoptions.py:249 msgid "Attribute with the reference to the original object" -msgstr "" +msgstr "包含原始物件參照的屬性" #: src/config/SSSDConfig/sssdoptions.py:250 msgid "Objectclass for user override objects" -msgstr "" +msgstr "使用者覆寫物件的物件類別" #: src/config/SSSDConfig/sssdoptions.py:251 msgid "Objectclass for group override objects" -msgstr "" +msgstr "群組覆寫物件的物件類別" #: src/config/SSSDConfig/sssdoptions.py:252 msgid "Search base for Desktop Profile related objects" -msgstr "" +msgstr "桌面設定檔相關物件的搜尋基準" #: src/config/SSSDConfig/sssdoptions.py:253 msgid "" "The amount of time in seconds between lookups of the Desktop Profile rules " "against the IPA server" -msgstr "" +msgstr "向 IPA 伺服器查詢桌面設定檔規則之間的間隔時間(秒)" #: src/config/SSSDConfig/sssdoptions.py:255 msgid "" "The amount of time in minutes between lookups of Desktop Profiles rules " "against the IPA server when the last request did not find any rule" msgstr "" +"當最後一次請求未找到任何規則時,向 IPA 伺服器查詢桌面設定檔規則之間的間隔時間" +"(分鐘)" #: src/config/SSSDConfig/sssdoptions.py:258 #: src/config/SSSDConfig/sssdoptions.py:455 msgid "Search base for SUBID ranges" -msgstr "" +msgstr "SUBID 範圍的搜尋基準" #: src/config/SSSDConfig/sssdoptions.py:259 -#: src/config/SSSDConfig/sssdoptions.py:506 +#: src/config/SSSDConfig/sssdoptions.py:512 msgid "Which rules should be used to evaluate access control" -msgstr "" +msgstr "應用哪些規則評估存取控制" #: src/config/SSSDConfig/sssdoptions.py:260 msgid "The LDAP attribute that contains FQDN of the host." -msgstr "" +msgstr "包含主機 FQDN 的 LDAP 屬性。" #: src/config/SSSDConfig/sssdoptions.py:261 #: src/config/SSSDConfig/sssdoptions.py:284 msgid "The object class of a host entry in LDAP." -msgstr "" +msgstr "LDAP 中主機項目的物件類別。" #: src/config/SSSDConfig/sssdoptions.py:262 msgid "Use the given string as search base for host objects." -msgstr "" +msgstr "使用給定的字串作為主機物件的搜尋基準。" #: src/config/SSSDConfig/sssdoptions.py:263 msgid "The LDAP attribute that contains the host's SSH public keys." -msgstr "" +msgstr "包含主機 SSH 公開金鑰的 LDAP 屬性。" #: src/config/SSSDConfig/sssdoptions.py:264 msgid "The LDAP attribute that contains NIS domain name of the netgroup." -msgstr "" +msgstr "包含網路群組之 NIS 網域名稱的 LDAP 屬性。" #: src/config/SSSDConfig/sssdoptions.py:265 msgid "The LDAP attribute that contains the names of the netgroup's members." -msgstr "" +msgstr "包含網路群組成員名稱的 LDAP 屬性。" #: src/config/SSSDConfig/sssdoptions.py:266 msgid "" "The LDAP attribute that lists FQDNs of hosts and host groups that are " "members of the netgroup." -msgstr "" +msgstr "列出為網路群組成員之主機與主機群組 FQDN 的 LDAP 屬性。" #: src/config/SSSDConfig/sssdoptions.py:268 msgid "" "The LDAP attribute that lists hosts and host groups that are direct members " "of the netgroup." -msgstr "" +msgstr "列出為網路群組直接成員之主機與主機群組的 LDAP 屬性。" #: src/config/SSSDConfig/sssdoptions.py:270 msgid "The LDAP attribute that lists netgroup's memberships." -msgstr "" +msgstr "列出網路群組成員身分的 LDAP 屬性。" #: src/config/SSSDConfig/sssdoptions.py:271 msgid "" "The LDAP attribute that lists system users and groups that are direct " "members of the netgroup." -msgstr "" +msgstr "列出為網路群組直接成員之系統使用者與群組的 LDAP 屬性。" #: src/config/SSSDConfig/sssdoptions.py:273 msgid "The LDAP attribute that corresponds to the netgroup name." -msgstr "" +msgstr "對應網路群組名稱的 LDAP 屬性。" #: src/config/SSSDConfig/sssdoptions.py:274 msgid "The object class of a netgroup entry in LDAP." -msgstr "" +msgstr "LDAP 中網路群組項目的物件類別。" #: src/config/SSSDConfig/sssdoptions.py:275 msgid "" "The LDAP attribute that contains the UUID/GUID of an LDAP netgroup object." -msgstr "" +msgstr "包含 LDAP 網路群組物件之 UUID/GUID 的 LDAP 屬性。" #: src/config/SSSDConfig/sssdoptions.py:276 msgid "" "The LDAP attribute that contains whether or not is user map enabled for " "usage." -msgstr "" +msgstr "包含使用者對應是否已啟用供使用的 LDAP 屬性。" #: src/config/SSSDConfig/sssdoptions.py:278 msgid "The LDAP attribute that contains host category such as 'all'." -msgstr "" +msgstr "包含主機類別(如 'all')的 LDAP 屬性。" #: src/config/SSSDConfig/sssdoptions.py:279 msgid "" "The LDAP attribute that contains all hosts / hostgroups this rule match " "against." -msgstr "" +msgstr "包含此規則比對之所有主機/主機群組的 LDAP 屬性。" #: src/config/SSSDConfig/sssdoptions.py:281 msgid "" "The LDAP attribute that contains all users / groups this rule match against." -msgstr "" +msgstr "包含此規則比對之所有使用者/群組的 LDAP 屬性。" #: src/config/SSSDConfig/sssdoptions.py:283 msgid "The LDAP attribute that contains the name of SELinux usermap." -msgstr "" +msgstr "包含 SELinux 使用者對應名稱的 LDAP 屬性。" #: src/config/SSSDConfig/sssdoptions.py:285 msgid "" "The LDAP attribute that contains DN of HBAC rule which can be used for " "matching instead of memberUser and memberHost." msgstr "" +"包含 HBAC 規則 DN 的 LDAP 屬性,可代替 memberUser 與 memberHost 用於比對。" #: src/config/SSSDConfig/sssdoptions.py:287 msgid "The LDAP attribute that contains SELinux user string itself." -msgstr "" +msgstr "包含 SELinux 使用者字串本身的 LDAP 屬性。" #: src/config/SSSDConfig/sssdoptions.py:288 msgid "The LDAP attribute that contains user category such as 'all'." -msgstr "" +msgstr "包含使用者類別(如 'all')的 LDAP 屬性。" #: src/config/SSSDConfig/sssdoptions.py:289 msgid "The LDAP attribute that contains unique ID of the user map." -msgstr "" +msgstr "包含使用者對應唯一 ID 的 LDAP 屬性。" #: src/config/SSSDConfig/sssdoptions.py:290 msgid "" "The option denotes that the SSSD is running on IPA server and should perform " "lookups of users and groups from trusted domains differently." msgstr "" +"此選項表示 SSSD 正在 IPA 伺服器上執行,且應以不同方式查詢來自受信任網域的使用" +"者與群組。" #: src/config/SSSDConfig/sssdoptions.py:292 msgid "Use the given string as search base for trusted domains." -msgstr "" +msgstr "使用給定的字串作為受信任網域的搜尋基準。" #: src/config/SSSDConfig/sssdoptions.py:295 msgid "Active Directory domain" -msgstr "" +msgstr "Active Directory 網域" #: src/config/SSSDConfig/sssdoptions.py:296 msgid "Enabled Active Directory domains" -msgstr "" +msgstr "已啟用的 Active Directory 網域" #: src/config/SSSDConfig/sssdoptions.py:297 msgid "Active Directory server address" -msgstr "" +msgstr "Active Directory 伺服器位址" #: src/config/SSSDConfig/sssdoptions.py:298 msgid "Active Directory backup server address" -msgstr "" +msgstr "Active Directory 備份伺服器位址" #: src/config/SSSDConfig/sssdoptions.py:299 msgid "Active Directory client hostname" -msgstr "" +msgstr "Active Directory 用戶端主機名稱" #: src/config/SSSDConfig/sssdoptions.py:300 msgid "Enable DNS sites - location based service discovery" -msgstr "" +msgstr "啟用 DNS 站台 - 以位置為基礎的服務探索" #: src/config/SSSDConfig/sssdoptions.py:301 -#: src/config/SSSDConfig/sssdoptions.py:504 +#: src/config/SSSDConfig/sssdoptions.py:510 msgid "LDAP filter to determine access privileges" -msgstr "" +msgstr "判斷存取權限的 LDAP 篩選器" #: src/config/SSSDConfig/sssdoptions.py:302 msgid "Whether to use the Global Catalog for lookups" -msgstr "" +msgstr "查詢時是否使用全域目錄" #: src/config/SSSDConfig/sssdoptions.py:303 msgid "Operation mode for GPO-based access control" -msgstr "" +msgstr "以 GPO 為基礎之存取控制的作業模式" #: src/config/SSSDConfig/sssdoptions.py:304 msgid "" "The amount of time between lookups of the GPO policy files against the AD " "server" -msgstr "" +msgstr "向 AD 伺服器查詢 GPO 原則檔案之間的間隔時間" #: src/config/SSSDConfig/sssdoptions.py:305 msgid "" "PAM service names that map to the GPO (Deny)InteractiveLogonRight policy " "settings" -msgstr "" +msgstr "對應到 GPO (Deny)InteractiveLogonRight 原則設定的 PAM 服務名稱" #: src/config/SSSDConfig/sssdoptions.py:307 msgid "" "PAM service names that map to the GPO (Deny)RemoteInteractiveLogonRight " "policy settings" -msgstr "" +msgstr "對應到 GPO (Deny)RemoteInteractiveLogonRight 原則設定的 PAM 服務名稱" #: src/config/SSSDConfig/sssdoptions.py:309 msgid "" "PAM service names that map to the GPO (Deny)NetworkLogonRight policy settings" -msgstr "" +msgstr "對應到 GPO (Deny)NetworkLogonRight 原則設定的 PAM 服務名稱" #: src/config/SSSDConfig/sssdoptions.py:310 msgid "" "PAM service names that map to the GPO (Deny)BatchLogonRight policy settings" -msgstr "" +msgstr "對應到 GPO (Deny)BatchLogonRight 原則設定的 PAM 服務名稱" #: src/config/SSSDConfig/sssdoptions.py:311 msgid "" "PAM service names that map to the GPO (Deny)ServiceLogonRight policy settings" -msgstr "" +msgstr "對應到 GPO (Deny)ServiceLogonRight 原則設定的 PAM 服務名稱" #: src/config/SSSDConfig/sssdoptions.py:312 msgid "PAM service names for which GPO-based access is always granted" -msgstr "" +msgstr "一律允許以 GPO 為基礎之存取的 PAM 服務名稱" #: src/config/SSSDConfig/sssdoptions.py:313 msgid "PAM service names for which GPO-based access is always denied" -msgstr "" +msgstr "一律拒絕以 GPO 為基礎之存取的 PAM 服務名稱" #: src/config/SSSDConfig/sssdoptions.py:314 msgid "" "Default logon right (or permit/deny) to use for unmapped PAM service names" -msgstr "" +msgstr "未對應 PAM 服務名稱使用的預設登入權限(或允許/拒絕)" #: src/config/SSSDConfig/sssdoptions.py:315 msgid "a particular site to be used by the client" -msgstr "" +msgstr "用戶端要使用的特定站台" #: src/config/SSSDConfig/sssdoptions.py:316 msgid "" "Maximum age in days before the machine account password should be renewed" -msgstr "" +msgstr "機器帳號密碼應更新前的最大天數" #: src/config/SSSDConfig/sssdoptions.py:318 msgid "Option for tuning the machine account renewal task" -msgstr "" +msgstr "調整機器帳號更新工作的選項" #: src/config/SSSDConfig/sssdoptions.py:319 msgid "Whether to update the machine account password in the Samba database" -msgstr "" +msgstr "是否在 Samba 資料庫中更新機器帳號密碼" #: src/config/SSSDConfig/sssdoptions.py:321 msgid "Use LDAPS port for LDAP and Global Catalog requests" -msgstr "" +msgstr "對 LDAP 與全域目錄請求使用 LDAPS 連接埠" #: src/config/SSSDConfig/sssdoptions.py:324 #: src/config/SSSDConfig/sssdoptions.py:325 @@ -1022,11 +1055,11 @@ msgstr "Kerberos 伺服器位址" #: src/config/SSSDConfig/sssdoptions.py:326 msgid "Kerberos backup server address" -msgstr "" +msgstr "Kerberos 備份伺服器位址" #: src/config/SSSDConfig/sssdoptions.py:327 msgid "Kerberos realm" -msgstr "" +msgstr "Kerberos 領域" #: src/config/SSSDConfig/sssdoptions.py:328 msgid "Authentication timeout" @@ -1034,11 +1067,11 @@ msgstr "認證逾時" #: src/config/SSSDConfig/sssdoptions.py:329 msgid "Whether to create kdcinfo files" -msgstr "" +msgstr "是否建立 kdcinfo 檔案" #: src/config/SSSDConfig/sssdoptions.py:330 msgid "Where to drop krb5 config snippets" -msgstr "" +msgstr "放置 krb5 設定片段的位置" #: src/config/SSSDConfig/sssdoptions.py:333 msgid "Directory to store credential caches" @@ -1058,124 +1091,124 @@ msgstr "啟用憑證驗證" #: src/config/SSSDConfig/sssdoptions.py:337 msgid "Store password if offline for later online authentication" -msgstr "" +msgstr "離線時儲存密碼以供日後線上認證" #: src/config/SSSDConfig/sssdoptions.py:338 msgid "Renewable lifetime of the TGT" -msgstr "" +msgstr "TGT 的可續期存續時間" #: src/config/SSSDConfig/sssdoptions.py:339 msgid "Lifetime of the TGT" -msgstr "" +msgstr "TGT 的存續時間" #: src/config/SSSDConfig/sssdoptions.py:340 msgid "Time between two checks for renewal" -msgstr "" +msgstr "兩次續期檢查之間的間隔時間" #: src/config/SSSDConfig/sssdoptions.py:341 msgid "Enables FAST" -msgstr "" +msgstr "啟用 FAST" #: src/config/SSSDConfig/sssdoptions.py:342 msgid "Selects the principal to use for FAST" -msgstr "" +msgstr "選取 FAST 使用的 principal" #: src/config/SSSDConfig/sssdoptions.py:343 msgid "Use anonymous PKINIT to request FAST credentials" -msgstr "" +msgstr "使用匿名 PKINIT 請求 FAST 憑證" #: src/config/SSSDConfig/sssdoptions.py:344 msgid "Enables principal canonicalization" -msgstr "" +msgstr "啟用 principal 正規化" #: src/config/SSSDConfig/sssdoptions.py:345 msgid "Enables enterprise principals" -msgstr "" +msgstr "啟用企業 principal" #: src/config/SSSDConfig/sssdoptions.py:346 msgid "Enables using of subdomains realms for authentication" -msgstr "" +msgstr "啟用使用子網域領域進行認證" #: src/config/SSSDConfig/sssdoptions.py:347 msgid "A mapping from user names to Kerberos principal names" -msgstr "" +msgstr "從使用者名稱到 Kerberos principal 名稱的對應" #: src/config/SSSDConfig/sssdoptions.py:350 #: src/config/SSSDConfig/sssdoptions.py:351 msgid "Server where the change password service is running if not on the KDC" -msgstr "" +msgstr "變更密碼服務執行所在的伺服器(若非位於 KDC 上)" #: src/config/SSSDConfig/sssdoptions.py:354 msgid "ldap_uri, The URI of the LDAP server" -msgstr "" +msgstr "ldap_uri:LDAP 伺服器的 URI" #: src/config/SSSDConfig/sssdoptions.py:355 msgid "ldap_backup_uri, The URI of the LDAP server" -msgstr "" +msgstr "ldap_backup_uri:LDAP 伺服器的 URI" #: src/config/SSSDConfig/sssdoptions.py:356 msgid "The default base DN" -msgstr "" +msgstr "預設的基準 DN" #: src/config/SSSDConfig/sssdoptions.py:357 msgid "How to read rootDSE from LDAP server" -msgstr "" +msgstr "如何從 LDAP 伺服器讀取 rootDSE" #: src/config/SSSDConfig/sssdoptions.py:358 msgid "The Schema Type in use on the LDAP server, rfc2307" -msgstr "" +msgstr "LDAP 伺服器使用的架構類型 rfc2307" #: src/config/SSSDConfig/sssdoptions.py:359 msgid "Mode used to change user password" -msgstr "" +msgstr "變更使用者密碼使用的模式" #: src/config/SSSDConfig/sssdoptions.py:360 msgid "The default bind DN" -msgstr "" +msgstr "預設的 bind DN" #: src/config/SSSDConfig/sssdoptions.py:361 msgid "The type of the authentication token of the default bind DN" -msgstr "" +msgstr "預設 bind DN 的認證權杖類型" #: src/config/SSSDConfig/sssdoptions.py:362 msgid "The authentication token of the default bind DN" -msgstr "" +msgstr "預設 bind DN 的認證權杖" #: src/config/SSSDConfig/sssdoptions.py:363 msgid "Length of time to attempt connection" -msgstr "" +msgstr "嘗試連線的時間長度" #: src/config/SSSDConfig/sssdoptions.py:364 msgid "Length of time to attempt synchronous LDAP operations" -msgstr "" +msgstr "嘗試同步 LDAP 作業的時間長度" #: src/config/SSSDConfig/sssdoptions.py:365 msgid "Length of time between attempts to reconnect while offline" -msgstr "" +msgstr "離線時嘗試重新連線的間隔時間" #: src/config/SSSDConfig/sssdoptions.py:366 msgid "Use only the upper case for realm names" -msgstr "" +msgstr "領域名稱僅使用大寫" #: src/config/SSSDConfig/sssdoptions.py:367 msgid "File that contains CA certificates" -msgstr "" +msgstr "包含 CA 憑證的檔案" #: src/config/SSSDConfig/sssdoptions.py:368 msgid "Path to CA certificate directory" -msgstr "" +msgstr "CA 憑證目錄的路徑" #: src/config/SSSDConfig/sssdoptions.py:369 msgid "File that contains the client certificate" -msgstr "" +msgstr "包含用戶端憑證的檔案" #: src/config/SSSDConfig/sssdoptions.py:370 msgid "File that contains the client key" -msgstr "" +msgstr "包含用戶端金鑰的檔案" #: src/config/SSSDConfig/sssdoptions.py:371 msgid "List of possible ciphers suites" -msgstr "" +msgstr "可能的加密套件清單" #: src/config/SSSDConfig/sssdoptions.py:372 msgid "Require TLS certificate verification" @@ -1191,93 +1224,93 @@ msgstr "指定要使用的 sasl 認證 id" #: src/config/SSSDConfig/sssdoptions.py:375 msgid "Specify the sasl authorization realm to use" -msgstr "" +msgstr "指定要使用的 sasl 授權領域" #: src/config/SSSDConfig/sssdoptions.py:376 msgid "Specify the minimal SSF for LDAP sasl authorization" -msgstr "" +msgstr "指定 LDAP sasl 授權的最低 SSF" #: src/config/SSSDConfig/sssdoptions.py:377 msgid "Specify the maximal SSF for LDAP sasl authorization" -msgstr "" +msgstr "指定 LDAP sasl 授權的最高 SSF" #: src/config/SSSDConfig/sssdoptions.py:378 msgid "Kerberos service keytab" -msgstr "" +msgstr "Kerberos 服務 keytab" #: src/config/SSSDConfig/sssdoptions.py:379 msgid "Use Kerberos auth for LDAP connection" -msgstr "" +msgstr "LDAP 連線使用 Kerberos 認證" #: src/config/SSSDConfig/sssdoptions.py:380 msgid "Follow LDAP referrals" -msgstr "" +msgstr "追蹤 LDAP 轉介" #: src/config/SSSDConfig/sssdoptions.py:381 msgid "Lifetime of TGT for LDAP connection" -msgstr "" +msgstr "LDAP 連線的 TGT 存續時間" #: src/config/SSSDConfig/sssdoptions.py:382 msgid "How to dereference aliases" -msgstr "" +msgstr "如何解除別名參照" #: src/config/SSSDConfig/sssdoptions.py:383 msgid "Service name for DNS service lookups" -msgstr "" +msgstr "DNS 服務查詢的服務名稱" #: src/config/SSSDConfig/sssdoptions.py:384 msgid "The number of records to retrieve in a single LDAP query" -msgstr "" +msgstr "單次 LDAP 查詢要取回的紀錄數" #: src/config/SSSDConfig/sssdoptions.py:385 msgid "The number of members that must be missing to trigger a full deref" -msgstr "" +msgstr "觸發完整解除參照所需缺失的成員數" #: src/config/SSSDConfig/sssdoptions.py:386 msgid "Ignore unreadable LDAP references" -msgstr "" +msgstr "忽略無法讀取的 LDAP 參照" #: src/config/SSSDConfig/sssdoptions.py:387 msgid "" "Whether the LDAP library should perform a reverse lookup to canonicalize the " "host name during a SASL bind" -msgstr "" +msgstr "LDAP 函式庫在 SASL bind 期間是否應執行反向查詢以正規化主機名稱" #: src/config/SSSDConfig/sssdoptions.py:389 msgid "" "Allows to retain local users as members of an LDAP group for servers that " "use the RFC2307 schema." -msgstr "" +msgstr "允許對使用 RFC2307 架構的伺服器保留本機使用者作為 LDAP 群組的成員。" #: src/config/SSSDConfig/sssdoptions.py:392 msgid "entryUSN attribute" -msgstr "" +msgstr "entryUSN 屬性" #: src/config/SSSDConfig/sssdoptions.py:393 msgid "lastUSN attribute" -msgstr "" +msgstr "lastUSN 屬性" #: src/config/SSSDConfig/sssdoptions.py:395 msgid "How long to retain a connection to the LDAP server before disconnecting" -msgstr "" +msgstr "中斷連線前保留 LDAP 伺服器連線的時間" #: src/config/SSSDConfig/sssdoptions.py:398 msgid "Disable the LDAP paging control" -msgstr "" +msgstr "停用 LDAP 分頁控制" #: src/config/SSSDConfig/sssdoptions.py:399 msgid "Disable Active Directory range retrieval" -msgstr "" +msgstr "停用 Active Directory 範圍取回" #: src/config/SSSDConfig/sssdoptions.py:400 msgid "Use the ppolicy extension" -msgstr "" +msgstr "使用 ppolicy 擴充功能" #: src/config/SSSDConfig/sssdoptions.py:401 msgid "" "Force a password change when remaining grace logins reach or go below this " "threshold" -msgstr "" +msgstr "當剩餘寬限登入次數達到或低於此門檻時強制變更密碼" #: src/config/SSSDConfig/sssdoptions.py:404 msgid "Length of time to wait for a search request" @@ -1285,88 +1318,88 @@ msgstr "搜尋請求的等候時間長度" #: src/config/SSSDConfig/sssdoptions.py:405 msgid "Length of time to wait for a enumeration request" -msgstr "" +msgstr "等待列舉請求的時間長度" #: src/config/SSSDConfig/sssdoptions.py:406 msgid "Length of time between enumeration updates" -msgstr "" +msgstr "列舉更新之間的間隔時間" #: src/config/SSSDConfig/sssdoptions.py:407 msgid "Maximum period deviation between enumeration updates" -msgstr "" +msgstr "列舉更新之間的最大時間偏差" #: src/config/SSSDConfig/sssdoptions.py:408 msgid "Length of time between cache cleanups" -msgstr "" +msgstr "快取清理之間的間隔時間" #: src/config/SSSDConfig/sssdoptions.py:409 msgid "Maximum time deviation between cache cleanups" -msgstr "" +msgstr "快取清理之間的最大時間偏差" #: src/config/SSSDConfig/sssdoptions.py:410 msgid "Require TLS for ID lookups" -msgstr "" +msgstr "ID 查詢需要 TLS" #: src/config/SSSDConfig/sssdoptions.py:411 msgid "Use ID-mapping of objectSID instead of pre-set IDs" -msgstr "" +msgstr "使用 objectSID 的 ID 對應而非預先設定的 ID" #: src/config/SSSDConfig/sssdoptions.py:412 msgid "Base DN for user lookups" -msgstr "" +msgstr "使用者查詢的基準 DN" #: src/config/SSSDConfig/sssdoptions.py:413 msgid "Scope of user lookups" -msgstr "" +msgstr "使用者查詢的範圍" #: src/config/SSSDConfig/sssdoptions.py:414 msgid "Filter for user lookups" -msgstr "" +msgstr "使用者查詢的篩選器" #: src/config/SSSDConfig/sssdoptions.py:415 msgid "Objectclass for users" -msgstr "" +msgstr "使用者的物件類別" #: src/config/SSSDConfig/sssdoptions.py:416 msgid "Username attribute" -msgstr "" +msgstr "使用者名稱屬性" #: src/config/SSSDConfig/sssdoptions.py:417 msgid "UID attribute" -msgstr "" +msgstr "UID 屬性" #: src/config/SSSDConfig/sssdoptions.py:418 msgid "Primary GID attribute" -msgstr "" +msgstr "主要 GID 屬性" #: src/config/SSSDConfig/sssdoptions.py:419 msgid "GECOS attribute" -msgstr "" +msgstr "GECOS 屬性" #: src/config/SSSDConfig/sssdoptions.py:420 msgid "Home directory attribute" -msgstr "" +msgstr "家目錄屬性" #: src/config/SSSDConfig/sssdoptions.py:421 msgid "Shell attribute" -msgstr "" +msgstr "Shell 屬性" #: src/config/SSSDConfig/sssdoptions.py:422 msgid "UUID attribute" -msgstr "" +msgstr "UUID 屬性" #: src/config/SSSDConfig/sssdoptions.py:423 -#: src/config/SSSDConfig/sssdoptions.py:464 +#: src/config/SSSDConfig/sssdoptions.py:470 msgid "objectSID attribute" -msgstr "" +msgstr "objectSID 屬性" #: src/config/SSSDConfig/sssdoptions.py:424 msgid "Active Directory primary group attribute for ID-mapping" -msgstr "" +msgstr "用於 ID 對應的 Active Directory 主要群組屬性" #: src/config/SSSDConfig/sssdoptions.py:425 msgid "User principal attribute (for Kerberos)" -msgstr "" +msgstr "使用者 principal 屬性(用於 Kerberos)" #: src/config/SSSDConfig/sssdoptions.py:426 msgid "Full Name" @@ -1374,493 +1407,521 @@ msgstr "全名" #: src/config/SSSDConfig/sssdoptions.py:427 msgid "memberOf attribute" -msgstr "" +msgstr "memberOf 屬性" #: src/config/SSSDConfig/sssdoptions.py:428 msgid "Modification time attribute" -msgstr "" +msgstr "修改時間屬性" #: src/config/SSSDConfig/sssdoptions.py:429 msgid "shadowLastChange attribute" -msgstr "" +msgstr "shadowLastChange 屬性" #: src/config/SSSDConfig/sssdoptions.py:430 msgid "shadowMin attribute" -msgstr "" +msgstr "shadowMin 屬性" #: src/config/SSSDConfig/sssdoptions.py:431 msgid "shadowMax attribute" -msgstr "" +msgstr "shadowMax 屬性" #: src/config/SSSDConfig/sssdoptions.py:432 msgid "shadowWarning attribute" -msgstr "" +msgstr "shadowWarning 屬性" #: src/config/SSSDConfig/sssdoptions.py:433 msgid "shadowInactive attribute" -msgstr "" +msgstr "shadowInactive 屬性" #: src/config/SSSDConfig/sssdoptions.py:434 msgid "shadowExpire attribute" -msgstr "" +msgstr "shadowExpire 屬性" #: src/config/SSSDConfig/sssdoptions.py:435 msgid "shadowFlag attribute" -msgstr "" +msgstr "shadowFlag 屬性" #: src/config/SSSDConfig/sssdoptions.py:436 msgid "Attribute listing authorized PAM services" -msgstr "" +msgstr "列出已授權 PAM 服務的屬性" #: src/config/SSSDConfig/sssdoptions.py:437 msgid "Attribute listing authorized server hosts" -msgstr "" +msgstr "列出已授權伺服器主機的屬性" #: src/config/SSSDConfig/sssdoptions.py:438 msgid "Attribute listing authorized server rhosts" -msgstr "" +msgstr "列出已授權伺服器 rhosts 的屬性" #: src/config/SSSDConfig/sssdoptions.py:439 msgid "krbLastPwdChange attribute" -msgstr "" +msgstr "krbLastPwdChange 屬性" #: src/config/SSSDConfig/sssdoptions.py:440 msgid "krbPasswordExpiration attribute" -msgstr "" +msgstr "krbPasswordExpiration 屬性" #: src/config/SSSDConfig/sssdoptions.py:441 msgid "Attribute indicating that server side password policies are active" -msgstr "" +msgstr "表示伺服器端密碼原則已生效的屬性" #: src/config/SSSDConfig/sssdoptions.py:442 msgid "accountExpires attribute of AD" -msgstr "" +msgstr "AD 的 accountExpires 屬性" #: src/config/SSSDConfig/sssdoptions.py:443 msgid "userAccountControl attribute of AD" -msgstr "" +msgstr "AD 的 userAccountControl 屬性" #: src/config/SSSDConfig/sssdoptions.py:444 msgid "nsAccountLock attribute" -msgstr "" +msgstr "nsAccountLock 屬性" #: src/config/SSSDConfig/sssdoptions.py:445 msgid "loginDisabled attribute of NDS" -msgstr "" +msgstr "NDS 的 loginDisabled 屬性" #: src/config/SSSDConfig/sssdoptions.py:446 msgid "loginExpirationTime attribute of NDS" -msgstr "" +msgstr "NDS 的 loginExpirationTime 屬性" #: src/config/SSSDConfig/sssdoptions.py:447 msgid "loginAllowedTimeMap attribute of NDS" -msgstr "" +msgstr "NDS 的 loginAllowedTimeMap 屬性" #: src/config/SSSDConfig/sssdoptions.py:448 msgid "SSH public key attribute" -msgstr "" +msgstr "SSH 公開金鑰屬性" #: src/config/SSSDConfig/sssdoptions.py:449 msgid "attribute listing allowed authentication types for a user" -msgstr "" +msgstr "列出使用者允許之認證類型的屬性" #: src/config/SSSDConfig/sssdoptions.py:450 msgid "attribute containing the X509 certificate of the user" -msgstr "" +msgstr "包含使用者 X509 憑證的屬性" #: src/config/SSSDConfig/sssdoptions.py:451 msgid "attribute containing the email address of the user" -msgstr "" +msgstr "包含使用者電子郵件位址的屬性" #: src/config/SSSDConfig/sssdoptions.py:452 msgid "attribute containing the passkey mapping data of the user" -msgstr "" +msgstr "包含使用者金鑰對應資料的屬性" #: src/config/SSSDConfig/sssdoptions.py:453 msgid "A list of extra attributes to download along with the user entry" +msgstr "與使用者項目一起下載的額外屬性清單" + +#: src/config/SSSDConfig/sssdoptions.py:456 +msgid "The object class of an subid entry in LDAP." msgstr "" #: src/config/SSSDConfig/sssdoptions.py:457 -msgid "Base DN for group lookups" +msgid "Subordinate user ID count attribute" msgstr "" #: src/config/SSSDConfig/sssdoptions.py:458 -msgid "Objectclass for groups" +msgid "Subordinate group ID count attribute" msgstr "" #: src/config/SSSDConfig/sssdoptions.py:459 +msgid "User ID range start value attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:460 +msgid "Group ID range start value attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:461 +msgid "Owner of an entry" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:463 +msgid "Base DN for group lookups" +msgstr "群組查詢的基準 DN" + +#: src/config/SSSDConfig/sssdoptions.py:464 +msgid "Objectclass for groups" +msgstr "群組的物件類別" + +#: src/config/SSSDConfig/sssdoptions.py:465 msgid "Group name" -msgstr "" +msgstr "群組名稱" -#: src/config/SSSDConfig/sssdoptions.py:460 +#: src/config/SSSDConfig/sssdoptions.py:466 msgid "Group password" -msgstr "" +msgstr "群組密碼" -#: src/config/SSSDConfig/sssdoptions.py:461 +#: src/config/SSSDConfig/sssdoptions.py:467 msgid "GID attribute" -msgstr "" +msgstr "GID 屬性" -#: src/config/SSSDConfig/sssdoptions.py:462 +#: src/config/SSSDConfig/sssdoptions.py:468 msgid "Group member attribute" -msgstr "" +msgstr "群組成員屬性" -#: src/config/SSSDConfig/sssdoptions.py:463 +#: src/config/SSSDConfig/sssdoptions.py:469 msgid "Group UUID attribute" -msgstr "" +msgstr "群組 UUID 屬性" -#: src/config/SSSDConfig/sssdoptions.py:465 +#: src/config/SSSDConfig/sssdoptions.py:471 msgid "Modification time attribute for groups" -msgstr "" +msgstr "群組的修改時間屬性" -#: src/config/SSSDConfig/sssdoptions.py:466 +#: src/config/SSSDConfig/sssdoptions.py:472 msgid "Type of the group and other flags" -msgstr "" +msgstr "群組類型及其他旗標" -#: src/config/SSSDConfig/sssdoptions.py:467 +#: src/config/SSSDConfig/sssdoptions.py:473 msgid "The LDAP group external member attribute" -msgstr "" +msgstr "LDAP 群組外部成員屬性" -#: src/config/SSSDConfig/sssdoptions.py:468 +#: src/config/SSSDConfig/sssdoptions.py:474 msgid "Maximum nesting level SSSD will follow" -msgstr "" +msgstr "SSSD 會追蹤的最大巢狀層級" -#: src/config/SSSDConfig/sssdoptions.py:469 +#: src/config/SSSDConfig/sssdoptions.py:475 msgid "Filter for group lookups" -msgstr "" +msgstr "群組查詢的篩選器" -#: src/config/SSSDConfig/sssdoptions.py:470 +#: src/config/SSSDConfig/sssdoptions.py:476 msgid "Scope of group lookups" -msgstr "" +msgstr "群組查詢的範圍" -#: src/config/SSSDConfig/sssdoptions.py:472 +#: src/config/SSSDConfig/sssdoptions.py:478 msgid "Base DN for netgroup lookups" -msgstr "" +msgstr "網路群組查詢的基準 DN" -#: src/config/SSSDConfig/sssdoptions.py:473 +#: src/config/SSSDConfig/sssdoptions.py:479 msgid "Objectclass for netgroups" -msgstr "" +msgstr "網路群組的物件類別" -#: src/config/SSSDConfig/sssdoptions.py:474 +#: src/config/SSSDConfig/sssdoptions.py:480 msgid "Netgroup name" -msgstr "" +msgstr "網路群組名稱" -#: src/config/SSSDConfig/sssdoptions.py:475 +#: src/config/SSSDConfig/sssdoptions.py:481 msgid "Netgroups members attribute" -msgstr "" +msgstr "網路群組成員屬性" -#: src/config/SSSDConfig/sssdoptions.py:476 +#: src/config/SSSDConfig/sssdoptions.py:482 msgid "Netgroup triple attribute" -msgstr "" +msgstr "網路群組三元組屬性" -#: src/config/SSSDConfig/sssdoptions.py:477 +#: src/config/SSSDConfig/sssdoptions.py:483 msgid "Modification time attribute for netgroups" -msgstr "" +msgstr "網路群組的修改時間屬性" -#: src/config/SSSDConfig/sssdoptions.py:479 +#: src/config/SSSDConfig/sssdoptions.py:485 msgid "Base DN for service lookups" -msgstr "" +msgstr "服務查詢的基準 DN" -#: src/config/SSSDConfig/sssdoptions.py:480 +#: src/config/SSSDConfig/sssdoptions.py:486 msgid "Objectclass for services" -msgstr "" +msgstr "服務的物件類別" -#: src/config/SSSDConfig/sssdoptions.py:481 +#: src/config/SSSDConfig/sssdoptions.py:487 msgid "Service name attribute" -msgstr "" +msgstr "服務名稱屬性" -#: src/config/SSSDConfig/sssdoptions.py:482 +#: src/config/SSSDConfig/sssdoptions.py:488 msgid "Service port attribute" -msgstr "" +msgstr "服務連接埠屬性" -#: src/config/SSSDConfig/sssdoptions.py:483 +#: src/config/SSSDConfig/sssdoptions.py:489 msgid "Service protocol attribute" -msgstr "" +msgstr "服務協定屬性" -#: src/config/SSSDConfig/sssdoptions.py:485 +#: src/config/SSSDConfig/sssdoptions.py:491 msgid "Lower bound for ID-mapping" -msgstr "" +msgstr "ID 對應的下限" -#: src/config/SSSDConfig/sssdoptions.py:486 +#: src/config/SSSDConfig/sssdoptions.py:492 msgid "Upper bound for ID-mapping" -msgstr "" +msgstr "ID 對應的上限" -#: src/config/SSSDConfig/sssdoptions.py:487 +#: src/config/SSSDConfig/sssdoptions.py:493 msgid "Number of IDs for each slice when ID-mapping" -msgstr "" +msgstr "ID 對應時每個區段的 ID 數量" -#: src/config/SSSDConfig/sssdoptions.py:488 +#: src/config/SSSDConfig/sssdoptions.py:494 msgid "Use autorid-compatible algorithm for ID-mapping" -msgstr "" +msgstr "ID 對應使用與 autorid 相容的演算法" -#: src/config/SSSDConfig/sssdoptions.py:489 +#: src/config/SSSDConfig/sssdoptions.py:495 msgid "Name of the default domain for ID-mapping" -msgstr "" +msgstr "ID 對應的預設網域名稱" -#: src/config/SSSDConfig/sssdoptions.py:490 +#: src/config/SSSDConfig/sssdoptions.py:496 msgid "SID of the default domain for ID-mapping" -msgstr "" +msgstr "ID 對應的預設網域 SID" -#: src/config/SSSDConfig/sssdoptions.py:491 +#: src/config/SSSDConfig/sssdoptions.py:497 msgid "Number of secondary slices" -msgstr "" +msgstr "次要區段數量" -#: src/config/SSSDConfig/sssdoptions.py:493 +#: src/config/SSSDConfig/sssdoptions.py:499 msgid "Whether to use Token-Groups" -msgstr "" +msgstr "是否使用 Token-Groups" -#: src/config/SSSDConfig/sssdoptions.py:494 +#: src/config/SSSDConfig/sssdoptions.py:500 msgid "Set lower boundary for allowed IDs from the LDAP server" -msgstr "" +msgstr "設定 LDAP 伺服器允許 ID 的下限" -#: src/config/SSSDConfig/sssdoptions.py:495 +#: src/config/SSSDConfig/sssdoptions.py:501 msgid "Set upper boundary for allowed IDs from the LDAP server" -msgstr "" +msgstr "設定 LDAP 伺服器允許 ID 的上限" -#: src/config/SSSDConfig/sssdoptions.py:496 +#: src/config/SSSDConfig/sssdoptions.py:502 msgid "DN for ppolicy queries" -msgstr "" +msgstr "ppolicy 查詢的 DN" -#: src/config/SSSDConfig/sssdoptions.py:497 +#: src/config/SSSDConfig/sssdoptions.py:503 msgid "How many maximum entries to fetch during a wildcard request" -msgstr "" +msgstr "萬用字元請求期間最多取回的項目數" -#: src/config/SSSDConfig/sssdoptions.py:498 +#: src/config/SSSDConfig/sssdoptions.py:504 msgid "Set libldap debug level" -msgstr "" +msgstr "設定 libldap 除錯層級" -#: src/config/SSSDConfig/sssdoptions.py:501 +#: src/config/SSSDConfig/sssdoptions.py:507 msgid "Policy to evaluate the password expiration" msgstr "評估密碼過期時效的策略" -#: src/config/SSSDConfig/sssdoptions.py:505 +#: src/config/SSSDConfig/sssdoptions.py:511 msgid "Which attributes shall be used to evaluate if an account is expired" -msgstr "" +msgstr "應用哪些屬性評估帳號是否已到期" -#: src/config/SSSDConfig/sssdoptions.py:509 +#: src/config/SSSDConfig/sssdoptions.py:515 msgid "URI of an LDAP server where password changes are allowed" -msgstr "" +msgstr "允許變更密碼之 LDAP 伺服器的 URI" -#: src/config/SSSDConfig/sssdoptions.py:510 +#: src/config/SSSDConfig/sssdoptions.py:516 msgid "URI of a backup LDAP server where password changes are allowed" -msgstr "" +msgstr "允許變更密碼之備份 LDAP 伺服器的 URI" -#: src/config/SSSDConfig/sssdoptions.py:511 +#: src/config/SSSDConfig/sssdoptions.py:517 msgid "DNS service name for LDAP password change server" -msgstr "" +msgstr "LDAP 密碼變更伺服器的 DNS 服務名稱" -#: src/config/SSSDConfig/sssdoptions.py:512 +#: src/config/SSSDConfig/sssdoptions.py:518 msgid "" "Whether to update the ldap_user_shadow_last_change attribute after a " "password change" -msgstr "" +msgstr "密碼變更後是否更新 ldap_user_shadow_last_change 屬性" -#: src/config/SSSDConfig/sssdoptions.py:516 +#: src/config/SSSDConfig/sssdoptions.py:522 msgid "Base DN for sudo rules lookups" -msgstr "" +msgstr "sudo 規則查詢的基準 DN" -#: src/config/SSSDConfig/sssdoptions.py:517 +#: src/config/SSSDConfig/sssdoptions.py:523 msgid "Automatic full refresh period" -msgstr "" +msgstr "自動完整重新整理週期" -#: src/config/SSSDConfig/sssdoptions.py:518 +#: src/config/SSSDConfig/sssdoptions.py:524 msgid "Automatic smart refresh period" -msgstr "" +msgstr "自動智慧重新整理週期" -#: src/config/SSSDConfig/sssdoptions.py:519 +#: src/config/SSSDConfig/sssdoptions.py:525 msgid "Smart and full refresh random offset" -msgstr "" +msgstr "智慧與完整重新整理的隨機偏移" -#: src/config/SSSDConfig/sssdoptions.py:520 +#: src/config/SSSDConfig/sssdoptions.py:526 msgid "Whether to filter rules by hostname, IP addresses and network" -msgstr "" +msgstr "是否依主機名稱、IP 位址與網路篩選規則" -#: src/config/SSSDConfig/sssdoptions.py:521 +#: src/config/SSSDConfig/sssdoptions.py:527 msgid "" "Hostnames and/or fully qualified domain names of this machine to filter sudo " "rules" -msgstr "" +msgstr "用於篩選 sudo 規則的此機器主機名稱與/或完整限定網域名稱" -#: src/config/SSSDConfig/sssdoptions.py:522 +#: src/config/SSSDConfig/sssdoptions.py:528 msgid "IPv4 or IPv6 addresses or network of this machine to filter sudo rules" -msgstr "" +msgstr "用於篩選 sudo 規則的此機器 IPv4 或 IPv6 位址或網路" -#: src/config/SSSDConfig/sssdoptions.py:523 +#: src/config/SSSDConfig/sssdoptions.py:529 msgid "Whether to include rules that contains netgroup in host attribute" -msgstr "" +msgstr "是否包含主機屬性中含有網路群組的規則" -#: src/config/SSSDConfig/sssdoptions.py:524 +#: src/config/SSSDConfig/sssdoptions.py:530 msgid "" "Whether to include rules that contains regular expression in host attribute" -msgstr "" +msgstr "是否包含主機屬性中含有正規表示式的規則" -#: src/config/SSSDConfig/sssdoptions.py:525 +#: src/config/SSSDConfig/sssdoptions.py:531 msgid "Object class for sudo rules" -msgstr "" +msgstr "sudo 規則的物件類別" -#: src/config/SSSDConfig/sssdoptions.py:526 +#: src/config/SSSDConfig/sssdoptions.py:532 msgid "Name of attribute that is used as object class for sudo rules" -msgstr "" +msgstr "作為 sudo 規則物件類別的屬性名稱" -#: src/config/SSSDConfig/sssdoptions.py:527 +#: src/config/SSSDConfig/sssdoptions.py:533 msgid "Sudo rule name" -msgstr "" +msgstr "sudo 規則名稱" -#: src/config/SSSDConfig/sssdoptions.py:528 +#: src/config/SSSDConfig/sssdoptions.py:534 msgid "Sudo rule command attribute" -msgstr "" +msgstr "sudo 規則指令屬性" -#: src/config/SSSDConfig/sssdoptions.py:529 +#: src/config/SSSDConfig/sssdoptions.py:535 msgid "Sudo rule host attribute" -msgstr "" +msgstr "sudo 規則主機屬性" -#: src/config/SSSDConfig/sssdoptions.py:530 +#: src/config/SSSDConfig/sssdoptions.py:536 msgid "Sudo rule user attribute" -msgstr "" +msgstr "sudo 規則使用者屬性" -#: src/config/SSSDConfig/sssdoptions.py:531 +#: src/config/SSSDConfig/sssdoptions.py:537 msgid "Sudo rule option attribute" -msgstr "" +msgstr "sudo 規則選項屬性" -#: src/config/SSSDConfig/sssdoptions.py:532 +#: src/config/SSSDConfig/sssdoptions.py:538 msgid "Sudo rule runas attribute" -msgstr "" +msgstr "sudo 規則 runas 屬性" -#: src/config/SSSDConfig/sssdoptions.py:533 +#: src/config/SSSDConfig/sssdoptions.py:539 msgid "Sudo rule runasuser attribute" -msgstr "" +msgstr "sudo 規則 runasuser 屬性" -#: src/config/SSSDConfig/sssdoptions.py:534 +#: src/config/SSSDConfig/sssdoptions.py:540 msgid "Sudo rule runasgroup attribute" -msgstr "" +msgstr "sudo 規則 runasgroup 屬性" -#: src/config/SSSDConfig/sssdoptions.py:535 +#: src/config/SSSDConfig/sssdoptions.py:541 msgid "Sudo rule notbefore attribute" -msgstr "" +msgstr "sudo 規則 notbefore 屬性" -#: src/config/SSSDConfig/sssdoptions.py:536 +#: src/config/SSSDConfig/sssdoptions.py:542 msgid "Sudo rule notafter attribute" -msgstr "" +msgstr "sudo 規則 notafter 屬性" -#: src/config/SSSDConfig/sssdoptions.py:537 +#: src/config/SSSDConfig/sssdoptions.py:543 msgid "Sudo rule order attribute" -msgstr "" +msgstr "sudo 規則順序屬性" -#: src/config/SSSDConfig/sssdoptions.py:540 +#: src/config/SSSDConfig/sssdoptions.py:546 msgid "Object class for automounter maps" -msgstr "" +msgstr "自動掛載器對應表的物件類別" -#: src/config/SSSDConfig/sssdoptions.py:541 +#: src/config/SSSDConfig/sssdoptions.py:547 msgid "Automounter map name attribute" -msgstr "" +msgstr "自動掛載器對應表名稱屬性" -#: src/config/SSSDConfig/sssdoptions.py:542 +#: src/config/SSSDConfig/sssdoptions.py:548 msgid "Object class for automounter map entries" -msgstr "" +msgstr "自動掛載器對應表項目的物件類別" -#: src/config/SSSDConfig/sssdoptions.py:543 +#: src/config/SSSDConfig/sssdoptions.py:549 msgid "Automounter map entry key attribute" -msgstr "" +msgstr "自動掛載器對應表項目鍵屬性" -#: src/config/SSSDConfig/sssdoptions.py:544 +#: src/config/SSSDConfig/sssdoptions.py:550 msgid "Automounter map entry value attribute" -msgstr "" +msgstr "自動掛載器對應表項目值屬性" -#: src/config/SSSDConfig/sssdoptions.py:545 +#: src/config/SSSDConfig/sssdoptions.py:551 msgid "Base DN for automounter map lookups" -msgstr "" +msgstr "自動掛載器對應表查詢的基準 DN" -#: src/config/SSSDConfig/sssdoptions.py:546 +#: src/config/SSSDConfig/sssdoptions.py:552 msgid "The name of the automount master map in LDAP." -msgstr "" +msgstr "LDAP 中自動掛載主對應表的名稱。" -#: src/config/SSSDConfig/sssdoptions.py:549 +#: src/config/SSSDConfig/sssdoptions.py:555 msgid "Base DN for IP hosts lookups" -msgstr "" +msgstr "IP 主機查詢的基準 DN" -#: src/config/SSSDConfig/sssdoptions.py:550 +#: src/config/SSSDConfig/sssdoptions.py:556 msgid "Object class for IP hosts" -msgstr "" +msgstr "IP 主機的物件類別" -#: src/config/SSSDConfig/sssdoptions.py:551 +#: src/config/SSSDConfig/sssdoptions.py:557 msgid "IP host name attribute" -msgstr "" +msgstr "IP 主機名稱屬性" -#: src/config/SSSDConfig/sssdoptions.py:552 +#: src/config/SSSDConfig/sssdoptions.py:558 msgid "IP host number (address) attribute" -msgstr "" +msgstr "IP 主機號碼(位址)屬性" -#: src/config/SSSDConfig/sssdoptions.py:553 +#: src/config/SSSDConfig/sssdoptions.py:559 msgid "IP host entryUSN attribute" -msgstr "" +msgstr "IP 主機 entryUSN 屬性" -#: src/config/SSSDConfig/sssdoptions.py:554 +#: src/config/SSSDConfig/sssdoptions.py:560 msgid "Base DN for IP networks lookups" -msgstr "" +msgstr "IP 網路查詢的基準 DN" -#: src/config/SSSDConfig/sssdoptions.py:555 +#: src/config/SSSDConfig/sssdoptions.py:561 msgid "Object class for IP networks" -msgstr "" +msgstr "IP 網路的物件類別" -#: src/config/SSSDConfig/sssdoptions.py:556 +#: src/config/SSSDConfig/sssdoptions.py:562 msgid "IP network name attribute" -msgstr "" +msgstr "IP 網路名稱屬性" -#: src/config/SSSDConfig/sssdoptions.py:557 +#: src/config/SSSDConfig/sssdoptions.py:563 msgid "IP network number (address) attribute" -msgstr "" +msgstr "IP 網路號碼(位址)屬性" -#: src/config/SSSDConfig/sssdoptions.py:558 +#: src/config/SSSDConfig/sssdoptions.py:564 msgid "IP network entryUSN attribute" -msgstr "" +msgstr "IP 網路 entryUSN 屬性" -#: src/config/SSSDConfig/sssdoptions.py:561 +#: src/config/SSSDConfig/sssdoptions.py:567 msgid "Comma separated list of allowed users" msgstr "許可的使用者清單,請使用半形逗號作為分隔" -#: src/config/SSSDConfig/sssdoptions.py:562 +#: src/config/SSSDConfig/sssdoptions.py:568 msgid "Comma separated list of prohibited users" msgstr "被禁止的使用者清單,請使用半形逗號作為分隔" -#: src/config/SSSDConfig/sssdoptions.py:563 +#: src/config/SSSDConfig/sssdoptions.py:569 msgid "" "Comma separated list of groups that are allowed to log in. This applies only " "to groups within this SSSD domain. Local groups are not evaluated." msgstr "" +"允許登入的群組清單,以逗號分隔。此設定僅適用於此 SSSD 網域內的群組。本機群組" +"不予評估。" -#: src/config/SSSDConfig/sssdoptions.py:565 +#: src/config/SSSDConfig/sssdoptions.py:571 msgid "" "Comma separated list of groups that are explicitly denied access. This " "applies only to groups within this SSSD domain. Local groups are not " "evaluated." msgstr "" +"明確拒絕存取的群組清單,以逗號分隔。此設定僅適用於此 SSSD 網域內的群組。本機" +"群組不予評估。" -#: src/config/SSSDConfig/sssdoptions.py:569 +#: src/config/SSSDConfig/sssdoptions.py:575 msgid "The number of preforked proxy children." -msgstr "" +msgstr "預先分派的代理子處理程式數量。" -#: src/config/SSSDConfig/sssdoptions.py:572 +#: src/config/SSSDConfig/sssdoptions.py:578 msgid "The name of the NSS library to use" msgstr "要使用的 NSS 函式庫名稱" -#: src/config/SSSDConfig/sssdoptions.py:573 +#: src/config/SSSDConfig/sssdoptions.py:579 msgid "The name of the NSS library to use for hosts and networks lookups" -msgstr "" +msgstr "用於主機與網路查詢的 NSS 函式庫名稱" -#: src/config/SSSDConfig/sssdoptions.py:574 +#: src/config/SSSDConfig/sssdoptions.py:580 msgid "Whether to look up canonical group name from cache if possible" -msgstr "" +msgstr "是否在可能時從快取查詢正式群組名稱" -#: src/config/SSSDConfig/sssdoptions.py:577 +#: src/config/SSSDConfig/sssdoptions.py:583 msgid "PAM stack to use" msgstr "要使用的 PAM 堆疊" -#: src/config/SSSDConfig/sssdoptions.py:580 +#: src/config/SSSDConfig/sssdoptions.py:586 msgid "Path of passwd file sources." -msgstr "" +msgstr "passwd 檔案來源的路徑。" -#: src/config/SSSDConfig/sssdoptions.py:581 +#: src/config/SSSDConfig/sssdoptions.py:587 msgid "Path of group file sources." -msgstr "" +msgstr "group 檔案來源的路徑。" #: src/monitor/monitor.c:1757 msgid "Become a daemon (default)" @@ -1872,7 +1933,7 @@ msgstr "以互動方式執行 (非幕後程式)" #: src/monitor/monitor.c:1761 msgid "Print version number and exit" -msgstr "" +msgstr "顯示版本號碼後結束" #: src/monitor/monitor.c:1772 #, c-format @@ -1881,240 +1942,253 @@ msgid "" "Invalid option %s: %s\n" "\n" msgstr "" +"\n" +"無效的選項 %s:%s\n" +"\n" #: src/monitor/monitor.c:1794 msgid "Option -i|--interactive is not allowed together with -D|--daemon\n" -msgstr "" +msgstr "選項 -i|--interactive 不能與 -D|--daemon 一起使用\n" -#: src/monitor/monitor.c:1836 +#: src/monitor/monitor.c:1838 msgid "Failed to get initial capabilities\n" -msgstr "" +msgstr "無法取得初始能力\n" -#: src/monitor/monitor.c:1847 +#: src/monitor/monitor.c:1849 msgid "Non-root service user support isn't built. Can't run under %" -msgstr "" +msgstr "未建置非 root 服務使用者支援。無法以 % 執行" -#: src/monitor/monitor.c:1864 +#: src/monitor/monitor.c:1866 #, c-format msgid "Can't read config: '%s'\n" -msgstr "" +msgstr "無法讀取設定:「%s」\n" -#: src/monitor/monitor.c:1876 +#: src/monitor/monitor.c:1878 #, c-format -msgid "Failed to boostrap SSSD 'monitor' process: %s" +msgid "Failed to bootstrap SSSD 'monitor' process: %s" msgstr "" -#: src/monitor/monitor.c:1971 +#: src/monitor/monitor.c:1973 msgid "Out of memory\n" msgstr "記憶體耗盡\n" -#: src/providers/krb5/krb5_child.c:4221 +#: src/providers/krb5/krb5_child.c:4316 msgid "Use anonymous PKINIT to request FAST armor ticket" -msgstr "" +msgstr "使用匿名 PKINIT 請求 FAST armor 票券" -#: src/providers/krb5/krb5_child.c:4223 +#: src/providers/krb5/krb5_child.c:4318 msgid "Kerberos realm to use" -msgstr "" +msgstr "要使用的 Kerberos 領域" -#: src/providers/krb5/krb5_child.c:4225 +#: src/providers/krb5/krb5_child.c:4320 msgid "Requested lifetime of the ticket" -msgstr "" +msgstr "請求的票券存續時間" -#: src/providers/krb5/krb5_child.c:4227 +#: src/providers/krb5/krb5_child.c:4322 msgid "Requested renewable lifetime of the ticket" -msgstr "" +msgstr "請求的票券可續期存續時間" -#: src/providers/krb5/krb5_child.c:4229 +#: src/providers/krb5/krb5_child.c:4324 msgid "FAST options ('never', 'try', 'demand')" -msgstr "" +msgstr "FAST 選項('never'、'try'、'demand')" -#: src/providers/krb5/krb5_child.c:4232 +#: src/providers/krb5/krb5_child.c:4327 msgid "Specifies the server principal to use for FAST" -msgstr "" +msgstr "指定 FAST 使用的伺服器 principal" -#: src/providers/krb5/krb5_child.c:4234 +#: src/providers/krb5/krb5_child.c:4329 msgid "Requests canonicalization of the principal name" -msgstr "" +msgstr "請求 principal 名稱的正規化" -#: src/providers/krb5/krb5_child.c:4236 +#: src/providers/krb5/krb5_child.c:4331 msgid "Use custom version of krb5_get_init_creds_password" -msgstr "" +msgstr "使用自訂版本的 krb5_get_init_creds_password" -#: src/providers/krb5/krb5_child.c:4238 +#: src/providers/krb5/krb5_child.c:4333 msgid "Check PAC flags" +msgstr "檢查 PAC 旗標" + +#: src/providers/krb5/krb5_child.c:4335 +msgid "Set environment variable (KEY=VALUE)" msgstr "" -#: src/providers/data_provider_be.c:790 +#: src/providers/data_provider_be.c:786 msgid "Domain of the information provider (mandatory)" -msgstr "" +msgstr "資訊提供者的網域(必填)" -#: src/sss_client/common.c:1165 +#: src/sss_client/common.c:1208 msgid "Socket has wrong ownership or permissions." -msgstr "" +msgstr "Socket 的擁有者或權限不正確。" -#: src/sss_client/common.c:1168 +#: src/sss_client/common.c:1211 msgid "Unexpected format of the server credential message." -msgstr "" +msgstr "伺服器憑證訊息格式不符合預期。" -#: src/sss_client/common.c:1171 +#: src/sss_client/common.c:1214 msgid "SSSD is not run by trusted user." -msgstr "" +msgstr "SSSD 並非由受信任的使用者執行。" -#: src/sss_client/common.c:1174 +#: src/sss_client/common.c:1217 msgid "SSSD socket does not exist." -msgstr "" +msgstr "SSSD socket 不存在。" -#: src/sss_client/common.c:1177 +#: src/sss_client/common.c:1220 msgid "Cannot get stat of SSSD socket." -msgstr "" +msgstr "無法取得 SSSD socket 的 stat。" -#: src/sss_client/common.c:1182 +#: src/sss_client/common.c:1225 msgid "An error occurred, but no description can be found." -msgstr "" +msgstr "發生錯誤,但找不到任何說明。" -#: src/sss_client/common.c:1188 +#: src/sss_client/common.c:1231 msgid "Unexpected error while looking for an error description" -msgstr "" +msgstr "尋找錯誤說明時發生非預期的錯誤" -#: src/sss_client/pam_sss.c:74 +#: src/sss_client/pam_sss.c:135 msgid "Permission denied. " -msgstr "" +msgstr "權限被拒絕。 " -#: src/sss_client/pam_sss.c:75 src/sss_client/pam_sss.c:843 -#: src/sss_client/pam_sss.c:854 +#: src/sss_client/pam_sss.c:136 src/sss_client/pam_sss.c:921 +#: src/sss_client/pam_sss.c:932 msgid "Server message: " -msgstr "伺服器訊息:" +msgstr "伺服器訊息: " -#: src/sss_client/pam_sss.c:76 +#: src/sss_client/pam_sss.c:137 msgid "" "Kerberos TGT will not be granted upon login, user experience will be " "affected." -msgstr "" +msgstr "登入時不會授予 Kerberos TGT,使用者體驗將受影響。" -#: src/sss_client/pam_sss.c:77 +#: src/sss_client/pam_sss.c:138 msgid "Enter PIN:" -msgstr "" +msgstr "輸入 PIN:" -#: src/sss_client/pam_sss.c:320 +#: src/sss_client/pam_sss.c:385 msgid "Passwords do not match" msgstr "密碼不相符" -#: src/sss_client/pam_sss.c:508 +#: src/sss_client/pam_sss.c:584 msgid "Password reset by root is not supported." -msgstr "" +msgstr "不支援由 root 重設密碼。" -#: src/sss_client/pam_sss.c:549 +#: src/sss_client/pam_sss.c:625 msgid "Authenticated with cached credentials" -msgstr "" +msgstr "已使用快取憑證認證" -#: src/sss_client/pam_sss.c:550 +#: src/sss_client/pam_sss.c:626 msgid ", your cached password will expire at: " -msgstr ",您快取的密碼將在此刻過期:" +msgstr ",您快取的密碼將在此刻過期: " -#: src/sss_client/pam_sss.c:580 +#: src/sss_client/pam_sss.c:656 #, c-format msgid "Your password has expired. You have %1$d grace login(s) remaining." -msgstr "" +msgstr "您的密碼已過期。您剩下 %1$d 次寬限登入。" -#: src/sss_client/pam_sss.c:630 +#: src/sss_client/pam_sss.c:706 #, c-format msgid "Your password will expire in %1$d %2$s." -msgstr "" +msgstr "您的密碼將在 %1$d %2$s 後到期。" -#: src/sss_client/pam_sss.c:633 -#, fuzzy, c-format +#: src/sss_client/pam_sss.c:709 +#, c-format msgid "Your password has expired." -msgstr ",您快取的密碼將在此刻過期:" +msgstr "您的密碼已過期。" -#: src/sss_client/pam_sss.c:684 +#: src/sss_client/pam_sss.c:760 msgid "Authentication is denied until: " -msgstr "" +msgstr "認證將被拒絕直到: " -#: src/sss_client/pam_sss.c:705 +#: src/sss_client/pam_sss.c:781 msgid "System is offline, password change not possible" msgstr "系統已離線,不可能作密碼變更" -#: src/sss_client/pam_sss.c:720 +#: src/sss_client/pam_sss.c:796 msgid "" "After changing the OTP password, you need to log out and back in order to " "acquire a ticket" -msgstr "" +msgstr "變更 OTP 密碼後,您需要登出再登入才能取得票券" -#: src/sss_client/pam_sss.c:735 +#: src/sss_client/pam_sss.c:813 msgid "PIN locked" -msgstr "" +msgstr "PIN 已鎖定" -#: src/sss_client/pam_sss.c:750 +#: src/sss_client/pam_sss.c:828 msgid "" "No Kerberos TGT granted as the server does not support this method. Your " "single-sign on(SSO) experience will be affected." msgstr "" +"由於伺服器不支援此方法,未授予 Kerberos TGT。您的單一登入 (SSO) 體驗將受影" +"響。" -#: src/sss_client/pam_sss.c:840 src/sss_client/pam_sss.c:853 +#: src/sss_client/pam_sss.c:918 src/sss_client/pam_sss.c:931 msgid "Password change failed. " -msgstr "密碼變更失敗。" +msgstr "密碼變更失敗。 " -#: src/sss_client/pam_sss.c:1859 +#: src/sss_client/pam_sss.c:2028 #, c-format -msgid "Authenticate at %1$s and press ENTER." +msgid "Authenticate at \"%1$s\"." msgstr "" -#: src/sss_client/pam_sss.c:1862 +#: src/sss_client/pam_sss.c:2031 #, c-format -msgid "Authenticate with PIN %1$s at %2$s and press ENTER." +msgid "Authenticate with PIN \"%1$s\" at \"%2$s\"." msgstr "" -#: src/sss_client/pam_sss.c:2281 +#: src/sss_client/pam_sss.c:2470 msgid "Please (re)insert (different) Smartcard" -msgstr "" +msgstr "請(重新)插入(不同的)智慧卡" -#: src/sss_client/pam_sss.c:2482 +#: src/sss_client/pam_sss.c:2700 msgid "New Password: " -msgstr "新密碼:" +msgstr "新密碼: " -#: src/sss_client/pam_sss.c:2483 +#: src/sss_client/pam_sss.c:2701 msgid "Reenter new Password: " -msgstr "再次輸入新密碼:" +msgstr "再次輸入新密碼: " -#: src/sss_client/pam_sss.c:2676 src/sss_client/pam_sss.c:2679 -msgid "First Factor: " +#: src/sss_client/pam_sss.c:2890 +msgid "Press ENTER to continue." msgstr "" -#: src/sss_client/pam_sss.c:2677 src/sss_client/pam_sss.c:2851 +#: src/sss_client/pam_sss.c:2913 src/sss_client/pam_sss.c:2916 +msgid "First Factor: " +msgstr "第一因素: " + +#: src/sss_client/pam_sss.c:2914 src/sss_client/pam_sss.c:3088 msgid "Second Factor (optional): " -msgstr "" +msgstr "第二因素(選填): " -#: src/sss_client/pam_sss.c:2680 src/sss_client/pam_sss.c:2855 +#: src/sss_client/pam_sss.c:2917 src/sss_client/pam_sss.c:3092 msgid "Second Factor: " -msgstr "" +msgstr "第二因素: " -#: src/sss_client/pam_sss.c:2684 +#: src/sss_client/pam_sss.c:2921 msgid "Insert your passkey device, then press ENTER." -msgstr "" +msgstr "插入您的金鑰裝置,然後按 ENTER。" -#: src/sss_client/pam_sss.c:2688 src/sss_client/pam_sss.c:2696 +#: src/sss_client/pam_sss.c:2925 src/sss_client/pam_sss.c:2933 msgid "Password: " -msgstr "密碼:" +msgstr "密碼: " -#: src/sss_client/pam_sss.c:2850 src/sss_client/pam_sss.c:2854 +#: src/sss_client/pam_sss.c:3087 src/sss_client/pam_sss.c:3091 msgid "First Factor (Current Password): " -msgstr "" +msgstr "第一因素(目前密碼): " -#: src/sss_client/pam_sss.c:2874 +#: src/sss_client/pam_sss.c:3111 msgid "Current Password: " -msgstr "目前的密碼:" +msgstr "目前的密碼: " -#: src/sss_client/pam_sss.c:3248 +#: src/sss_client/pam_sss.c:3485 msgid "Password expired. Change your password now." msgstr "密碼已過期。請立刻變更您的密碼。" #: src/sss_client/ssh/sss_ssh_authorizedkeys.c:41 src/tools/sss_cache.c:707 msgid "The debug level to run with" -msgstr "" +msgstr "執行的除錯層級" #: src/sss_client/ssh/sss_ssh_authorizedkeys.c:43 msgid "The SSSD domain to use" -msgstr "" +msgstr "要使用的 SSSD 網域" #: src/sss_client/ssh/sss_ssh_authorizedkeys.c:57 src/tools/sss_cache.c:753 msgid "Error setting the locale\n" @@ -2122,15 +2196,15 @@ msgstr "設定區域設置時發生錯誤\n" #: src/sss_client/ssh/sss_ssh_authorizedkeys.c:64 msgid "Not enough memory\n" -msgstr "" +msgstr "記憶體不足\n" #: src/sss_client/ssh/sss_ssh_authorizedkeys.c:83 msgid "User not specified\n" -msgstr "" +msgstr "未指定使用者\n" #: src/sss_client/ssh/sss_ssh_authorizedkeys.c:97 msgid "Error looking up public keys\n" -msgstr "" +msgstr "查詢公開金鑰時發生錯誤\n" #: src/sss_client/ssh/sss_ssh_knownhostsproxy.c:27 msgid "" @@ -2142,98 +2216,104 @@ msgid "" "******************************************************************************\n" "\n" msgstr "" +"\n" +"******************************************************************************\n" +"您的系統設定為使用已淘汰的工具 sss_ssh_knownhostsproxy。\n" +"請閱讀 sss_ssh_knownhosts(1) 的手冊頁以了解取代它的工具。\n" +"******************************************************************************\n" +"\n" #: src/tools/sss_cache.c:229 msgid "No cache object matched the specified search\n" -msgstr "" +msgstr "沒有快取物件符合指定的搜尋\n" #: src/tools/sss_cache.c:520 #, c-format msgid "Couldn't invalidate %1$s\n" -msgstr "" +msgstr "無法讓 %1$s 失效\n" #: src/tools/sss_cache.c:527 #, c-format msgid "Couldn't invalidate %1$s %2$s\n" -msgstr "" +msgstr "無法讓 %1$s %2$s 失效\n" #: src/tools/sss_cache.c:653 msgid "Can't find configuration db, was SSSD configured and run?\n" -msgstr "" +msgstr "找不到設定資料庫,SSSD 是否已設定並執行?\n" #: src/tools/sss_cache.c:709 msgid "Invalidate all cached entries" -msgstr "" +msgstr "讓所有快取項目失效" #: src/tools/sss_cache.c:711 msgid "Invalidate particular user" -msgstr "" +msgstr "讓特定使用者失效" #: src/tools/sss_cache.c:713 msgid "Invalidate all users" -msgstr "" +msgstr "讓所有使用者失效" #: src/tools/sss_cache.c:715 msgid "Invalidate particular group" -msgstr "" +msgstr "讓特定群組失效" #: src/tools/sss_cache.c:717 msgid "Invalidate all groups" -msgstr "" +msgstr "讓所有群組失效" #: src/tools/sss_cache.c:719 msgid "Invalidate particular netgroup" -msgstr "" +msgstr "讓特定網路群組失效" #: src/tools/sss_cache.c:721 msgid "Invalidate all netgroups" -msgstr "" +msgstr "讓所有網路群組失效" #: src/tools/sss_cache.c:723 msgid "Invalidate particular service" -msgstr "" +msgstr "讓特定服務失效" #: src/tools/sss_cache.c:725 msgid "Invalidate all services" -msgstr "" +msgstr "讓所有服務失效" #: src/tools/sss_cache.c:728 msgid "Invalidate particular autofs map" -msgstr "" +msgstr "讓特定 autofs 對應表失效" #: src/tools/sss_cache.c:730 msgid "Invalidate all autofs maps" -msgstr "" +msgstr "讓所有 autofs 對應表失效" #: src/tools/sss_cache.c:734 msgid "Invalidate particular SSH host" -msgstr "" +msgstr "讓特定 SSH 主機失效" #: src/tools/sss_cache.c:736 msgid "Invalidate all SSH hosts" -msgstr "" +msgstr "讓所有 SSH 主機失效" #: src/tools/sss_cache.c:740 msgid "Invalidate particular sudo rule" -msgstr "" +msgstr "讓特定 sudo 規則失效" #: src/tools/sss_cache.c:742 msgid "Invalidate all cached sudo rules" -msgstr "" +msgstr "讓所有快取的 sudo 規則失效" #: src/tools/sss_cache.c:745 msgid "Only invalidate entries from a particular domain" -msgstr "" +msgstr "僅讓特定網域的項目失效" #: src/tools/sss_cache.c:799 msgid "" "Unexpected argument(s) provided, options that invalidate a single object " "only accept a single provided argument.\n" -msgstr "" +msgstr "提供了非預期的引數,讓單一物件失效的選項只接受單一提供的引數。\n" #: src/tools/sss_cache.c:809 msgid "Please select at least one object to invalidate\n" -msgstr "" +msgstr "請至少選取一個要讓其失效的物件\n" #: src/tools/sss_cache.c:892 #, c-format @@ -2241,469 +2321,468 @@ msgid "" "Could not open domain %1$s. If the domain is a subdomain (trusted domain), " "use fully qualified name instead of --domain/-d parameter.\n" msgstr "" +"無法開啟網域 %1$s。若此網域是子網域(受信任網域),請改用完整限定名稱而非 --" +"domain/-d 參數。\n" #: src/tools/sss_cache.c:897 msgid "Could not open available domains\n" -msgstr "" +msgstr "無法開啟可用的網域\n" #: src/tools/tools_util.h:36 #, c-format msgid "%1$s must be run as root\n" -msgstr "" +msgstr "%1$s 必須以 root 身分執行\n" #: src/tools/sssctl/sssctl.c:35 msgid "yes" -msgstr "" +msgstr "是" #: src/tools/sssctl/sssctl.c:37 msgid "no" -msgstr "" +msgstr "否" #: src/tools/sssctl/sssctl.c:39 msgid "error" -msgstr "" +msgstr "錯誤" #: src/tools/sssctl/sssctl.c:42 msgid "Invalid result." -msgstr "" +msgstr "結果無效。" #: src/tools/sssctl/sssctl.c:78 msgid "Unable to read user input\n" -msgstr "" +msgstr "無法讀取使用者輸入\n" #: src/tools/sssctl/sssctl.c:91 #, c-format msgid "Invalid input, please provide either '%s' or '%s'.\n" -msgstr "" +msgstr "輸入無效,請提供「%s」或「%s」。\n" #: src/tools/sssctl/sssctl.c:151 src/tools/sssctl/sssctl.c:161 msgid "Error while executing external command\n" -msgstr "" +msgstr "執行外部指令時發生錯誤\n" #: src/tools/sssctl/sssctl.c:165 #, c-format msgid "Error while executing external command '%s'\n" -msgstr "" +msgstr "執行外部指令「%s」時發生錯誤\n" #: src/tools/sssctl/sssctl.c:168 #, c-format msgid "Command '%s' failed with [%d]\n" -msgstr "" +msgstr "指令「%s」以 [%d] 失敗\n" #: src/tools/sssctl/sssctl.c:215 msgid "SSSD needs to be running. Start SSSD now?" -msgstr "" +msgstr "SSSD 需要執行中。現在啟動 SSSD?" #: src/tools/sssctl/sssctl.c:254 msgid "SSSD must not be running. Stop SSSD now?" -msgstr "" +msgstr "SSSD 不得執行中。現在停止 SSSD?" #: src/tools/sssctl/sssctl.c:290 msgid "SSSD needs to be restarted. Restart SSSD now?" -msgstr "" +msgstr "SSSD 需要重新啟動。現在重新啟動 SSSD?" #: src/tools/sssctl/sssctl.c:322 msgid "SSSD Status:" -msgstr "" +msgstr "SSSD 狀態:" #: src/tools/sssctl/sssctl.c:323 msgid "List available domains" -msgstr "" +msgstr "列出可用的網域" #: src/tools/sssctl/sssctl.c:324 msgid "Print information about domain" -msgstr "" +msgstr "顯示網域的資訊" #: src/tools/sssctl/sssctl.c:325 msgid "Print information about a user and check authentication" -msgstr "" +msgstr "顯示使用者的資訊並檢查認證" #: src/tools/sssctl/sssctl.c:326 msgid "Generate access report for a domain" -msgstr "" +msgstr "為網域產生存取報告" #: src/tools/sssctl/sssctl.c:327 msgid "Information about cached content:" -msgstr "" +msgstr "快取內容的資訊:" #: src/tools/sssctl/sssctl.c:328 -#, fuzzy msgid "Information about cached user" -msgstr "無法取得關於這位使用者的資訊\n" +msgstr "快取使用者的資訊" #: src/tools/sssctl/sssctl.c:329 msgid "Information about cached group" -msgstr "" +msgstr "快取群組的資訊" #: src/tools/sssctl/sssctl.c:330 msgid "Information about cached netgroup" -msgstr "" +msgstr "快取網路群組的資訊" #: src/tools/sssctl/sssctl.c:331 msgid "Local data tools:" -msgstr "" +msgstr "本機資料工具:" #: src/tools/sssctl/sssctl.c:332 msgid "Backup local data" -msgstr "" +msgstr "備份本機資料" #: src/tools/sssctl/sssctl.c:333 msgid "Restore local data from backup" -msgstr "" +msgstr "從備份還原本機資料" #: src/tools/sssctl/sssctl.c:334 msgid "Backup local data and remove cached content" -msgstr "" +msgstr "備份本機資料並移除快取內容" #: src/tools/sssctl/sssctl.c:335 msgid "Invalidate cached objects" -msgstr "" +msgstr "讓快取物件失效" #: src/tools/sssctl/sssctl.c:336 msgid "Manage cache indexes" -msgstr "" +msgstr "管理快取索引" #: src/tools/sssctl/sssctl.c:337 msgid "Log files tools:" -msgstr "" +msgstr "日誌檔工具:" #: src/tools/sssctl/sssctl.c:338 msgid "Remove existing SSSD log files" -msgstr "" +msgstr "移除既有的 SSSD 日誌檔" #: src/tools/sssctl/sssctl.c:339 msgid "Archive SSSD log files in tarball" -msgstr "" +msgstr "將 SSSD 日誌檔封存為 tarball" #: src/tools/sssctl/sssctl.c:340 msgid "Change or print information about SSSD debug level" -msgstr "" +msgstr "變更或顯示 SSSD 除錯層級的資訊" #: src/tools/sssctl/sssctl.c:341 msgid "Analyze logged data" -msgstr "" +msgstr "分析已記錄的資料" #: src/tools/sssctl/sssctl.c:342 msgid "Configuration files tools:" -msgstr "" +msgstr "設定檔工具:" #: src/tools/sssctl/sssctl.c:343 msgid "Perform static analysis of SSSD configuration" -msgstr "" +msgstr "對 SSSD 設定執行靜態分析" #: src/tools/sssctl/sssctl.c:344 msgid "Certificate related tools:" -msgstr "" +msgstr "憑證相關工具:" #: src/tools/sssctl/sssctl.c:345 msgid "Print information about the certificate" -msgstr "" +msgstr "顯示憑證的資訊" #: src/tools/sssctl/sssctl.c:346 msgid "Show users mapped to the certificate" -msgstr "" +msgstr "顯示對應到此憑證的使用者" #: src/tools/sssctl/sssctl.c:347 msgid "Check mapping and matching rule with a certificate" -msgstr "" +msgstr "以憑證檢查對應與比對規則" #: src/tools/sssctl/sssctl.c:348 msgid "GPOs related tools:" -msgstr "" +msgstr "GPO 相關工具:" #: src/tools/sssctl/sssctl.c:349 -#, fuzzy msgid "Information about cached GPO" -msgstr "無法取得關於這位使用者的資訊\n" +msgstr "快取 GPO 的資訊" #: src/tools/sssctl/sssctl.c:350 msgid "Enumerate cached GPOs" -msgstr "" +msgstr "列舉快取的 GPO" #: src/tools/sssctl/sssctl.c:351 msgid "Remove cached GPO" -msgstr "" +msgstr "移除快取的 GPO" #: src/tools/sssctl/sssctl.c:352 msgid "Remove all cached GPOs" -msgstr "" +msgstr "移除所有快取的 GPO" #: src/tools/sssctl/sssctl.c:354 msgid "Passkey related tools:" -msgstr "" +msgstr "金鑰相關工具:" #: src/tools/sssctl/sssctl.c:355 msgid "Perform passkey registration" -msgstr "" +msgstr "執行金鑰註冊" #: src/tools/sssctl/sssctl_cache.c:31 #, c-format msgid " %s is not present in cache.\n" -msgstr "" +msgstr " %s 不在快取中。\n" #: src/tools/sssctl/sssctl_cache.c:33 msgid "Name" -msgstr "" +msgstr "名稱" #: src/tools/sssctl/sssctl_cache.c:34 msgid "Cache entry creation date" -msgstr "" +msgstr "快取項目建立日期" #: src/tools/sssctl/sssctl_cache.c:35 msgid "Cache entry last update time" -msgstr "" +msgstr "快取項目最後更新時間" #: src/tools/sssctl/sssctl_cache.c:36 msgid "Cache entry expiration time" -msgstr "" +msgstr "快取項目到期時間" #: src/tools/sssctl/sssctl_cache.c:37 msgid "Cached in InfoPipe" -msgstr "" +msgstr "已在 InfoPipe 中快取" #: src/tools/sssctl/sssctl_cache.c:38 -#, fuzzy msgid "Policy Name" -msgstr "全名" +msgstr "原則名稱" #: src/tools/sssctl/sssctl_cache.c:39 msgid "Policy GUID" -msgstr "" +msgstr "原則 GUID" #: src/tools/sssctl/sssctl_cache.c:40 msgid "Policy Path" -msgstr "" +msgstr "原則路徑" #: src/tools/sssctl/sssctl_cache.c:41 msgid "Policy file timeout" -msgstr "" +msgstr "原則檔逾時" #: src/tools/sssctl/sssctl_cache.c:42 msgid "Policy version" -msgstr "" +msgstr "原則版本" #: src/tools/sssctl/sssctl_cache.c:556 #, c-format msgid "Error: Unable to get object [%d]: %s\n" -msgstr "" +msgstr "錯誤:無法取得物件 [%d]:%s\n" #: src/tools/sssctl/sssctl_cache.c:572 src/tools/sssctl/sssctl_cache.c:927 #, c-format msgid "%s: Unable to read value [%d]: %s\n" -msgstr "" +msgstr "%s:無法讀取值 [%d]:%s\n" #: src/tools/sssctl/sssctl_cache.c:602 msgid "Specify name." -msgstr "" +msgstr "指定名稱。" #: src/tools/sssctl/sssctl_cache.c:612 #, c-format msgid "Unable to parse name %s.\n" -msgstr "" +msgstr "無法解析名稱 %s。\n" #: src/tools/sssctl/sssctl_cache.c:641 src/tools/sssctl/sssctl_cache.c:688 msgid "Search by SID" -msgstr "" +msgstr "依 SID 搜尋" #: src/tools/sssctl/sssctl_cache.c:642 msgid "Search by user ID" -msgstr "" +msgstr "依使用者 ID 搜尋" #: src/tools/sssctl/sssctl_cache.c:651 msgid "Initgroups expiration time" -msgstr "" +msgstr "initgroups 到期時間" #: src/tools/sssctl/sssctl_cache.c:689 msgid "Search by group ID" -msgstr "" +msgstr "依群組 ID 搜尋" #: src/tools/sssctl/sssctl_cache.c:778 src/tools/sssctl/sssctl_cache.c:1126 msgid "Search by GPO guid" -msgstr "" +msgstr "依 GPO guid 搜尋" #: src/tools/sssctl/sssctl_cache.c:785 src/tools/sssctl/sssctl_cache.c:1143 #, c-format msgid "Failed to parse command line: %s\n" -msgstr "" +msgstr "解析命令列失敗:%s\n" #: src/tools/sssctl/sssctl_cache.c:790 src/tools/sssctl/sssctl_cache.c:1148 #, c-format msgid "%s\n" -msgstr "" +msgstr "%s\n" #: src/tools/sssctl/sssctl_cache.c:803 #, c-format msgid "Failed to print object: %s\n" -msgstr "" +msgstr "顯示物件失敗:%s\n" #: src/tools/sssctl/sssctl_cache.c:835 src/tools/sssctl/sssctl_cache.c:918 #: src/tools/sssctl/sssctl_cache.c:950 src/tools/sssctl/sssctl_cache.c:956 #: src/tools/sssctl/sssctl_cache.c:1010 src/tools/sssctl/sssctl_cache.c:1034 -#: src/tools/sssctl/sssctl_cache.c:1085 src/tools/sssctl/sssctl_cache.c:1194 -#: src/tools/sssctl/sssctl_cache.c:1229 src/tools/sssctl/sssctl_cache.c:1235 -#: src/tools/sssctl/sssctl_cache.c:1244 +#: src/tools/sssctl/sssctl_cache.c:1085 src/tools/sssctl/sssctl_cache.c:1195 +#: src/tools/sssctl/sssctl_cache.c:1230 src/tools/sssctl/sssctl_cache.c:1236 +#: src/tools/sssctl/sssctl_cache.c:1245 msgid "talloc failed\n" -msgstr "" +msgstr "talloc 失敗\n" #: src/tools/sssctl/sssctl_cache.c:841 msgid "Unable to get attribute list!\n" -msgstr "" +msgstr "無法取得屬性清單!\n" #: src/tools/sssctl/sssctl_cache.c:848 msgid "Unable to create filter\n" -msgstr "" +msgstr "無法建立篩選器\n" #: src/tools/sssctl/sssctl_cache.c:861 #, c-format msgid "%s [%s]:\n" -msgstr "" +msgstr "%s [%s]:\n" #: src/tools/sssctl/sssctl_cache.c:866 msgid "Unable to get GPOs base DN\n" -msgstr "" +msgstr "無法取得 GPO 基準 DN\n" #: src/tools/sssctl/sssctl_cache.c:876 #, c-format msgid "Unable to search sysdb: %s\n" -msgstr "" +msgstr "無法搜尋 sysdb:%s\n" #: src/tools/sssctl/sssctl_cache.c:882 #, c-format msgid "Unable to convert message to sysdb attrs: %s\n" -msgstr "" +msgstr "無法將訊息轉換為 sysdb 屬性:%s\n" #: src/tools/sssctl/sssctl_cache.c:931 #, c-format msgid "\t%s: %s\n" -msgstr "" +msgstr "\t%s:%s\n" #: src/tools/sssctl/sssctl_cache.c:933 src/tools/sssctl/sssctl_logs.c:50 msgid "\n" -msgstr "" +msgstr "\n" #: src/tools/sssctl/sssctl_cache.c:1016 msgid "Could not find GUID attribute from GPO entry\n" -msgstr "" +msgstr "無法從 GPO 項目找到 GUID 屬性\n" #: src/tools/sssctl/sssctl_cache.c:1023 msgid "Could not find description attribute from GPO entry\n" -msgstr "" +msgstr "無法從 GPO 項目找到描述屬性\n" #: src/tools/sssctl/sssctl_cache.c:1047 msgid "Could not delete GPO entry from cache\n" -msgstr "" +msgstr "無法從快取刪除 GPO 項目\n" #: src/tools/sssctl/sssctl_cache.c:1053 #, c-format msgid "" "The GPO path was not yet stored in cache. Please remove files manually from " "[%s]\n" -msgstr "" +msgstr "GPO 路徑尚未儲存在快取中。請手動從 [%s] 移除檔案\n" #: src/tools/sssctl/sssctl_cache.c:1062 src/tools/sssctl/sssctl_cache.c:1068 #, c-format msgid "Could not determine real path for [%s]: %s\n" -msgstr "" +msgstr "無法判斷 [%s] 的實際路徑:%s\n" #: src/tools/sssctl/sssctl_cache.c:1073 #, c-format msgid "The cached GPO path [%s] is not under [%s], ignoring.\n" -msgstr "" +msgstr "快取的 GPO 路徑 [%s] 不在 [%s] 之下,已忽略。\n" #: src/tools/sssctl/sssctl_cache.c:1098 #, c-format msgid "Unable to remove downloaded GPO files: %s\n" -msgstr "" +msgstr "無法移除已下載的 GPO 檔案:%s\n" -#: src/tools/sssctl/sssctl_cache.c:1165 +#: src/tools/sssctl/sssctl_cache.c:1166 #, c-format msgid "Failed to fetch cache entry: %s\n" -msgstr "" +msgstr "取得快取項目失敗:%s\n" -#: src/tools/sssctl/sssctl_cache.c:1170 +#: src/tools/sssctl/sssctl_cache.c:1171 msgid "Could not determine object domain\n" -msgstr "" +msgstr "無法判斷物件的網域\n" -#: src/tools/sssctl/sssctl_cache.c:1200 +#: src/tools/sssctl/sssctl_cache.c:1201 msgid "Could not find GUID attribute in GPO entry\n" -msgstr "" +msgstr "無法在 GPO 項目中找到 GUID 屬性\n" -#: src/tools/sssctl/sssctl_cache.c:1206 +#: src/tools/sssctl/sssctl_cache.c:1207 #, c-format msgid "Failed to delete GPO: %s\n" -msgstr "" +msgstr "刪除 GPO 失敗:%s\n" -#: src/tools/sssctl/sssctl_cache.c:1210 +#: src/tools/sssctl/sssctl_cache.c:1211 #, c-format msgid "%s removed from cache\n" -msgstr "" +msgstr "%s 已從快取移除\n" #: src/tools/sssctl/sssctl_cert.c:50 src/tools/sssctl/sssctl_cert.c:108 #: src/tools/sssctl/sssctl_cert.c:214 msgid "Show debug information" -msgstr "" +msgstr "顯示除錯資訊" #: src/tools/sssctl/sssctl_cert.c:56 src/tools/sssctl/sssctl_cert.c:114 #: src/tools/sssctl/sssctl_cert.c:220 msgid "Specify base64 encoded certificate." -msgstr "" +msgstr "指定 base64 編碼的憑證。" #: src/tools/sssctl/sssctl_cert.c:138 src/tools/sssctl/sssctl_domains.c:104 #: src/tools/sssctl/sssctl_domains.c:366 #: src/tools/sssctl/sssctl_user_checks.c:99 msgid "Unable to connect to system bus!\n" -msgstr "" +msgstr "無法連線到系統匯流排!\n" #: src/tools/sssctl/sssctl_cert.c:164 msgid " - no mapped users found -" -msgstr "" +msgstr " - 未找到對應的使用者 -" #: src/tools/sssctl/sssctl_cert.c:212 msgid "Mapping rule" -msgstr "" +msgstr "對應規則" #: src/tools/sssctl/sssctl_cert.c:213 msgid "Matching rule" -msgstr "" +msgstr "比對規則" #: src/tools/sssctl/sssctl_cert.c:223 msgid "Unable to parse command arguments\n" -msgstr "" +msgstr "無法解析指令引數\n" #: src/tools/sssctl/sssctl_cert.c:229 src/tools/sssctl/sssctl_domains.c:354 msgid "Out of memory!\n" -msgstr "" +msgstr "記憶體耗盡!\n" #: src/tools/sssctl/sssctl_cert.c:238 msgid "Failed to setup certmap context.\n" -msgstr "" +msgstr "設定 certmap 環境失敗。\n" #: src/tools/sssctl/sssctl_cert.c:244 #, c-format msgid "Failed to add mapping and matching rules with error [%d][%s].\n" -msgstr "" +msgstr "新增對應與比對規則失敗,錯誤 [%d][%s]。\n" #: src/tools/sssctl/sssctl_cert.c:251 msgid "Failed to decode base64 string.\n" -msgstr "" +msgstr "解碼 base64 字串失敗。\n" #: src/tools/sssctl/sssctl_cert.c:259 msgid "Certificate matches rule.\n" -msgstr "" +msgstr "憑證符合規則。\n" #: src/tools/sssctl/sssctl_cert.c:262 msgid "Certificate does not match rule.\n" -msgstr "" +msgstr "憑證不符合規則。\n" #: src/tools/sssctl/sssctl_cert.c:265 #, c-format msgid "Error during certificate matching [%d][%s].\n" -msgstr "" +msgstr "憑證比對期間發生錯誤 [%d][%s]。\n" #: src/tools/sssctl/sssctl_cert.c:272 #, c-format msgid "Failed to generate mapping filter [%d][%s].\n" -msgstr "" +msgstr "產生對應篩選器失敗 [%d][%s]。\n" #: src/tools/sssctl/sssctl_cert.c:276 #, c-format @@ -2713,6 +2792,10 @@ msgid "" " %s\n" "\n" msgstr "" +"對應篩選器:\n" +"\n" +" %s\n" +"\n" #: src/tools/sssctl/sssctl_config.c:75 msgid "" @@ -2720,155 +2803,155 @@ msgid "" "where the main config file is located. For example if the config is set to " "\"/my/path/sssd.conf\", the snippet dir \"/my/path/conf.d\" is used)" msgstr "" +"指定非預設的片段目錄(預設會在主要設定檔所在的同一位置尋找。例如若設定為 \"/" +"my/path/sssd.conf\",則使用片段目錄 \"/my/path/conf.d\")" -#: src/tools/sssctl/sssctl_config.c:114 +#: src/tools/sssctl/sssctl_config.c:126 #, c-format msgid "File %1$s does not exist.\n" -msgstr "" +msgstr "檔案 %1$s 不存在。\n" -#: src/tools/sssctl/sssctl_config.c:115 +#: src/tools/sssctl/sssctl_config.c:127 msgid "There is no configuration.\n" -msgstr "" +msgstr "沒有任何設定。\n" -#: src/tools/sssctl/sssctl_config.c:120 +#: src/tools/sssctl/sssctl_config.c:132 #, c-format msgid "Configuration validation failed: %s\n" -msgstr "" +msgstr "設定驗證失敗:%s\n" -#: src/tools/sssctl/sssctl_config.c:121 +#: src/tools/sssctl/sssctl_config.c:133 msgid "Run with high debug level to see details.\n" -msgstr "" +msgstr "以高除錯層級執行以檢視詳細資訊。\n" -#: src/tools/sssctl/sssctl_config.c:130 -msgid "Failed to run validators" +#: src/tools/sssctl/sssctl_config.c:142 +msgid "Failed to run validators\n" msgstr "" -#: src/tools/sssctl/sssctl_config.c:134 +#: src/tools/sssctl/sssctl_config.c:146 #, c-format msgid "Issues identified by validators: %zu\n" -msgstr "" +msgstr "驗證器識別出的問題:%zu\n" -#: src/tools/sssctl/sssctl_config.c:145 +#: src/tools/sssctl/sssctl_config.c:157 #, c-format msgid "Messages generated during configuration merging: %zu\n" -msgstr "" +msgstr "設定合併期間產生的訊息:%zu\n" -#: src/tools/sssctl/sssctl_config.c:158 +#: src/tools/sssctl/sssctl_config.c:170 #, c-format msgid "Used configuration snippet files: %zu\n" -msgstr "" +msgstr "使用的設定片段檔:%zu\n" #: src/tools/sssctl/sssctl_data.c:91 #, c-format msgid "Unable to create backup directory [%d]: %s" -msgstr "" +msgstr "無法建立備份目錄 [%d]:%s" #: src/tools/sssctl/sssctl_data.c:97 msgid "SSSD backup of local data already exists, override?" -msgstr "" +msgstr "SSSD 本機資料備份已存在,要覆寫嗎?" #: src/tools/sssctl/sssctl_data.c:113 msgid "Unable to export user overrides\n" -msgstr "" +msgstr "無法匯出使用者覆寫\n" #: src/tools/sssctl/sssctl_data.c:120 msgid "Unable to export group overrides\n" -msgstr "" +msgstr "無法匯出群組覆寫\n" #: src/tools/sssctl/sssctl_data.c:135 src/tools/sssctl/sssctl_data.c:216 msgid "Override existing backup" -msgstr "" +msgstr "覆寫既有的備份" #: src/tools/sssctl/sssctl_data.c:165 msgid "Unable to import user overrides\n" -msgstr "" +msgstr "無法匯入使用者覆寫\n" #: src/tools/sssctl/sssctl_data.c:174 msgid "Unable to import group overrides\n" -msgstr "" +msgstr "無法匯入群組覆寫\n" #: src/tools/sssctl/sssctl_data.c:194 src/tools/sssctl/sssctl_domains.c:81 #: src/tools/sssctl/sssctl_domains.c:326 msgid "Start SSSD if it is not running" -msgstr "" +msgstr "若 SSSD 未執行則啟動它" #: src/tools/sssctl/sssctl_data.c:195 msgid "Restart SSSD after data import" -msgstr "" +msgstr "資料匯入後重新啟動 SSSD" #: src/tools/sssctl/sssctl_data.c:217 msgid "Create clean cache files and import local data" -msgstr "" +msgstr "建立乾淨的快取檔並匯入本機資料" #: src/tools/sssctl/sssctl_data.c:218 msgid "Stop SSSD before removing the cache" -msgstr "" +msgstr "移除快取前停止 SSSD" #: src/tools/sssctl/sssctl_data.c:219 msgid "Start SSSD when the cache is removed" -msgstr "" +msgstr "移除快取後啟動 SSSD" #: src/tools/sssctl/sssctl_data.c:234 msgid "Creating backup of local data...\n" -msgstr "" +msgstr "正在建立本機資料備份...\n" #: src/tools/sssctl/sssctl_data.c:237 msgid "Unable to create backup of local data, can not remove the cache.\n" -msgstr "" +msgstr "無法建立本機資料備份,無法移除快取。\n" #: src/tools/sssctl/sssctl_data.c:242 msgid "Removing cache files...\n" -msgstr "" +msgstr "正在移除快取檔...\n" #: src/tools/sssctl/sssctl_data.c:245 msgid "Unable to remove cache files\n" -msgstr "" +msgstr "無法移除快取檔\n" #: src/tools/sssctl/sssctl_data.c:250 msgid "Restoring local data...\n" -msgstr "" +msgstr "正在還原本機資料...\n" #: src/tools/sssctl/sssctl_data.c:377 #, c-format msgid "Creating cache index for domain %1$s\n" -msgstr "" +msgstr "正在為網域 %1$s 建立快取索引\n" #: src/tools/sssctl/sssctl_data.c:379 #, c-format msgid "Deleting cache index for domain %1$s\n" -msgstr "" +msgstr "正在刪除網域 %1$s 的快取索引\n" #: src/tools/sssctl/sssctl_data.c:381 #, c-format msgid "Indexes for domain %1$s:\n" -msgstr "" +msgstr "網域 %1$s 的索引:\n" #: src/tools/sssctl/sssctl_data.c:401 #, c-format msgid " Attribute: %1$s\n" -msgstr "" +msgstr " 屬性:%1$s\n" #: src/tools/sssctl/sssctl_data.c:428 src/tools/sssctl/sssctl_logs.c:525 msgid "Target a specific domain" -msgstr "" +msgstr "指定目標網域" #: src/tools/sssctl/sssctl_data.c:428 src/tools/sssctl/sssctl_logs.c:525 -#, fuzzy msgid "domain" -msgstr "IPA 網域" +msgstr "網域" #: src/tools/sssctl/sssctl_data.c:430 msgid "Attribute to index" -msgstr "" +msgstr "要建立索引的屬性" #: src/tools/sssctl/sssctl_data.c:430 msgid "attribute" -msgstr "" +msgstr "屬性" #: src/tools/sssctl/sssctl_data.c:443 -#, fuzzy msgid "Action not provided\n" -msgstr "認證提供者" +msgstr "未提供動作\n" #: src/tools/sssctl/sssctl_data.c:456 #, c-format @@ -2876,235 +2959,237 @@ msgid "" "Unknown action: %1$s\n" "Valid actions are \"%2$s\", \"%3$s and \"%4$s\"\n" msgstr "" +"未知的動作:%1$s\n" +"有效的動作有「%2$s」、「%3$s」與「%4$s」\n" #: src/tools/sssctl/sssctl_data.c:464 msgid "Attribute (-a) not provided\n" -msgstr "" +msgstr "未提供屬性 (-a)\n" #: src/tools/sssctl/sssctl_data.c:472 #, c-format msgid "Attribute %1$s not indexed.\n" -msgstr "" +msgstr "屬性 %1$s 未建立索引。\n" #: src/tools/sssctl/sssctl_data.c:475 #, c-format msgid "Attribute %1$s already indexed.\n" -msgstr "" +msgstr "屬性 %1$s 已建立索引。\n" #: src/tools/sssctl/sssctl_data.c:478 #, c-format msgid "Index operation failed: %1$s\n" -msgstr "" +msgstr "索引作業失敗:%1$s\n" #: src/tools/sssctl/sssctl_data.c:483 msgid "Don't forget to also update the indexes on the remote providers.\n" -msgstr "" +msgstr "別忘了也要更新遠端提供者上的索引。\n" #: src/tools/sssctl/sssctl_domains.c:82 msgid "Show domain list including primary or trusted domain type" -msgstr "" +msgstr "顯示網域清單,包括主要或受信任的網域類型" #: src/tools/sssctl/sssctl_domains.c:166 msgid "Online" -msgstr "" +msgstr "線上" #: src/tools/sssctl/sssctl_domains.c:166 msgid "Offline" -msgstr "" +msgstr "離線" #: src/tools/sssctl/sssctl_domains.c:166 #, c-format msgid "Online status: %s\n" -msgstr "" +msgstr "線上狀態:%s\n" #: src/tools/sssctl/sssctl_domains.c:212 msgid "This domain has no active servers.\n" -msgstr "" +msgstr "此網域沒有作用中的伺服器。\n" #: src/tools/sssctl/sssctl_domains.c:217 msgid "Active servers:\n" -msgstr "" +msgstr "作用中的伺服器:\n" #: src/tools/sssctl/sssctl_domains.c:229 msgid "not connected" -msgstr "" +msgstr "未連線" #: src/tools/sssctl/sssctl_domains.c:266 msgid "No servers discovered.\n" -msgstr "" +msgstr "未探索到任何伺服器。\n" #: src/tools/sssctl/sssctl_domains.c:272 #, c-format msgid "Discovered %s servers:\n" -msgstr "" +msgstr "已探索到 %s 台伺服器:\n" #: src/tools/sssctl/sssctl_domains.c:284 msgid "None so far.\n" -msgstr "" +msgstr "目前沒有。\n" #: src/tools/sssctl/sssctl_domains.c:323 msgid "Show online status" -msgstr "" +msgstr "顯示線上狀態" #: src/tools/sssctl/sssctl_domains.c:324 msgid "Show information about active server" -msgstr "" +msgstr "顯示作用中伺服器的資訊" #: src/tools/sssctl/sssctl_domains.c:325 msgid "Show list of discovered servers" -msgstr "" +msgstr "顯示已探索到的伺服器清單" #: src/tools/sssctl/sssctl_domains.c:331 msgid "Specify domain name." -msgstr "" +msgstr "指定網域名稱。" #: src/tools/sssctl/sssctl_domains.c:374 src/tools/sssctl/sssctl_domains.c:384 msgid "Unable to get online status\n" -msgstr "" +msgstr "無法取得線上狀態\n" #: src/tools/sssctl/sssctl_domains.c:394 msgid "Unable to get server list\n" -msgstr "" +msgstr "無法取得伺服器清單\n" #: src/tools/sssctl/sssctl_logs.c:214 msgid "SSSD is not running.\n" -msgstr "" +msgstr "SSSD 未在執行。\n" #: src/tools/sssctl/sssctl_logs.c:231 #, c-format msgid "%1$-25s %2$#.4x\n" -msgstr "" +msgstr "%1$-25s %2$#.4x\n" #: src/tools/sssctl/sssctl_logs.c:235 #, c-format msgid "%1$-25s Unknown domain\n" -msgstr "" +msgstr "%1$-25s 未知的網域\n" #: src/tools/sssctl/sssctl_logs.c:237 #, c-format msgid "%1$-25s Unreachable service\n" -msgstr "" +msgstr "%1$-25s 無法連線的服務\n" #: src/tools/sssctl/sssctl_logs.c:429 msgid "Delete log files instead of truncating" -msgstr "" +msgstr "刪除日誌檔而非截斷" #: src/tools/sssctl/sssctl_logs.c:440 msgid "Deleting log files...\n" -msgstr "" +msgstr "正在刪除日誌檔...\n" #: src/tools/sssctl/sssctl_logs.c:443 msgid "Unable to remove log files\n" -msgstr "" +msgstr "無法移除日誌檔\n" #: src/tools/sssctl/sssctl_logs.c:460 msgid "Truncating log files...\n" -msgstr "" +msgstr "正在截斷日誌檔...\n" #: src/tools/sssctl/sssctl_logs.c:464 msgid "Unable to truncate log files\n" -msgstr "" +msgstr "無法截斷日誌檔\n" #: src/tools/sssctl/sssctl_logs.c:498 #, c-format msgid "Archiving log files into %s...\n" -msgstr "" +msgstr "正在將日誌檔封存到 %s...\n" #: src/tools/sssctl/sssctl_logs.c:502 msgid "Unable to archive log files\n" -msgstr "" +msgstr "無法封存日誌檔\n" #: src/tools/sssctl/sssctl_logs.c:526 msgid "Target the SSSD service" -msgstr "" +msgstr "指定目標為 SSSD 服務" #: src/tools/sssctl/sssctl_logs.c:527 msgid "Target the NSS service" -msgstr "" +msgstr "指定目標為 NSS 服務" #: src/tools/sssctl/sssctl_logs.c:528 msgid "Target the PAM service" -msgstr "" +msgstr "指定目標為 PAM 服務" #: src/tools/sssctl/sssctl_logs.c:529 msgid "Target the SUDO service" -msgstr "" +msgstr "指定目標為 SUDO 服務" #: src/tools/sssctl/sssctl_logs.c:530 msgid "Target the AUTOFS service" -msgstr "" +msgstr "指定目標為 AUTOFS 服務" #: src/tools/sssctl/sssctl_logs.c:531 msgid "Target the SSH service" -msgstr "" +msgstr "指定目標為 SSH 服務" #: src/tools/sssctl/sssctl_logs.c:532 msgid "Target the PAC service" -msgstr "" +msgstr "指定目標為 PAC 服務" #: src/tools/sssctl/sssctl_logs.c:533 msgid "Target the IFP service" -msgstr "" +msgstr "指定目標為 IFP 服務" #: src/tools/sssctl/sssctl_logs.c:548 msgid "Specify debug level you want to set" -msgstr "" +msgstr "指定要設定的除錯層級" #: src/tools/sssctl/sssctl_logs.c:593 msgid "ERROR: Tevent chain ID support missing, log analyzer is unsupported.\n" -msgstr "" +msgstr "錯誤:缺少 Tevent chain ID 支援,不支援日誌分析器。\n" #: src/tools/sssctl/sssctl_user_checks.c:121 msgid "SSSD InfoPipe user lookup result:\n" -msgstr "" +msgstr "SSSD InfoPipe 使用者查詢結果:\n" #: src/tools/sssctl/sssctl_user_checks.c:171 #, c-format msgid "dlopen failed with [%s].\n" -msgstr "" +msgstr "dlopen 以 [%s] 失敗。\n" #: src/tools/sssctl/sssctl_user_checks.c:178 #, c-format msgid "dlsym failed with [%s].\n" -msgstr "" +msgstr "dlsym 以 [%s] 失敗。\n" #: src/tools/sssctl/sssctl_user_checks.c:186 msgid "malloc failed.\n" -msgstr "" +msgstr "malloc 失敗。\n" #: src/tools/sssctl/sssctl_user_checks.c:193 #, c-format msgid "sss_getpwnam_r failed with [%d].\n" -msgstr "" +msgstr "sss_getpwnam_r 以 [%d] 失敗。\n" #: src/tools/sssctl/sssctl_user_checks.c:198 msgid "SSSD nss user lookup result:\n" -msgstr "" +msgstr "SSSD nss 使用者查詢結果:\n" #: src/tools/sssctl/sssctl_user_checks.c:199 #, c-format msgid " - user name: %s\n" -msgstr "" +msgstr " - 使用者名稱:%s\n" #: src/tools/sssctl/sssctl_user_checks.c:200 #, c-format msgid " - user id: %d\n" -msgstr "" +msgstr " - 使用者 id:%d\n" #: src/tools/sssctl/sssctl_user_checks.c:201 #, c-format msgid " - group id: %d\n" -msgstr "" +msgstr " - 群組 id:%d\n" #: src/tools/sssctl/sssctl_user_checks.c:202 #, c-format msgid " - gecos: %s\n" -msgstr "" +msgstr " - gecos:%s\n" #: src/tools/sssctl/sssctl_user_checks.c:203 #, c-format msgid " - home directory: %s\n" -msgstr "" +msgstr " - 家目錄:%s\n" #: src/tools/sssctl/sssctl_user_checks.c:204 #, c-format @@ -3112,18 +3197,20 @@ msgid "" " - shell: %s\n" "\n" msgstr "" +" - shell:%s\n" +"\n" #: src/tools/sssctl/sssctl_user_checks.c:235 msgid "PAM action [auth|acct|setc|chau|open|clos], default: " -msgstr "" +msgstr "PAM 動作 [auth|acct|setc|chau|open|clos],預設: " #: src/tools/sssctl/sssctl_user_checks.c:238 msgid "PAM service, default: " -msgstr "" +msgstr "PAM 服務,預設: " #: src/tools/sssctl/sssctl_user_checks.c:243 msgid "Specify user name." -msgstr "" +msgstr "指定使用者名稱。" #: src/tools/sssctl/sssctl_user_checks.c:250 #, c-format @@ -3133,32 +3220,38 @@ msgid "" "service: %s\n" "\n" msgstr "" +"使用者:%s\n" +"動作:%s\n" +"服務:%s\n" +"\n" #: src/tools/sssctl/sssctl_user_checks.c:255 #, c-format msgid "User name lookup with [%s] failed.\n" -msgstr "" +msgstr "使用 [%s] 查詢使用者名稱失敗。\n" #: src/tools/sssctl/sssctl_user_checks.c:260 #, c-format msgid "InfoPipe User lookup with [%s] failed.\n" -msgstr "" +msgstr "使用 [%s] 查詢 InfoPipe 使用者失敗。\n" #: src/tools/sssctl/sssctl_user_checks.c:266 #, c-format msgid "pam_start failed: %s\n" -msgstr "" +msgstr "pam_start 失敗:%s\n" #: src/tools/sssctl/sssctl_user_checks.c:272 msgid "" "testing pam_authenticate\n" "\n" msgstr "" +"正在測試 pam_authenticate\n" +"\n" #: src/tools/sssctl/sssctl_user_checks.c:276 #, c-format msgid "pam_get_item failed: %s\n" -msgstr "" +msgstr "pam_get_item 失敗:%s\n" #: src/tools/sssctl/sssctl_user_checks.c:279 #, c-format @@ -3166,12 +3259,16 @@ msgid "" "pam_authenticate for user [%s]: %s\n" "\n" msgstr "" +"對使用者 [%s] 執行 pam_authenticate:%s\n" +"\n" #: src/tools/sssctl/sssctl_user_checks.c:282 msgid "" "testing pam_chauthtok\n" "\n" msgstr "" +"正在測試 pam_chauthtok\n" +"\n" #: src/tools/sssctl/sssctl_user_checks.c:284 #, c-format @@ -3179,12 +3276,16 @@ msgid "" "pam_chauthtok: %s\n" "\n" msgstr "" +"pam_chauthtok:%s\n" +"\n" #: src/tools/sssctl/sssctl_user_checks.c:286 msgid "" "testing pam_acct_mgmt\n" "\n" msgstr "" +"正在測試 pam_acct_mgmt\n" +"\n" #: src/tools/sssctl/sssctl_user_checks.c:288 #, c-format @@ -3192,12 +3293,16 @@ msgid "" "pam_acct_mgmt: %s\n" "\n" msgstr "" +"pam_acct_mgmt:%s\n" +"\n" #: src/tools/sssctl/sssctl_user_checks.c:290 msgid "" "testing pam_setcred\n" "\n" msgstr "" +"正在測試 pam_setcred\n" +"\n" #: src/tools/sssctl/sssctl_user_checks.c:292 #, c-format @@ -3205,12 +3310,16 @@ msgid "" "pam_setcred: [%s]\n" "\n" msgstr "" +"pam_setcred:[%s]\n" +"\n" #: src/tools/sssctl/sssctl_user_checks.c:294 msgid "" "testing pam_open_session\n" "\n" msgstr "" +"正在測試 pam_open_session\n" +"\n" #: src/tools/sssctl/sssctl_user_checks.c:296 #, c-format @@ -3218,12 +3327,16 @@ msgid "" "pam_open_session: %s\n" "\n" msgstr "" +"pam_open_session:%s\n" +"\n" #: src/tools/sssctl/sssctl_user_checks.c:298 msgid "" "testing pam_close_session\n" "\n" msgstr "" +"正在測試 pam_close_session\n" +"\n" #: src/tools/sssctl/sssctl_user_checks.c:300 #, c-format @@ -3231,18 +3344,20 @@ msgid "" "pam_close_session: %s\n" "\n" msgstr "" +"pam_close_session:%s\n" +"\n" #: src/tools/sssctl/sssctl_user_checks.c:302 msgid "unknown action\n" -msgstr "" +msgstr "未知的動作\n" #: src/tools/sssctl/sssctl_user_checks.c:305 msgid "PAM Environment:\n" -msgstr "" +msgstr "PAM 環境:\n" #: src/tools/sssctl/sssctl_user_checks.c:313 msgid " - no env -\n" -msgstr "" +msgstr " - 沒有環境 -\n" #: src/util/util.h:100 msgid "Specify a non-default config file" @@ -3250,7 +3365,7 @@ msgstr "指定非預設的配置檔" #: src/util/util.h:107 msgid "Informs that the responder has been socket-activated" -msgstr "" +msgstr "告知回應器已由 socket 啟動" #~ msgid "The UID of the user" #~ msgstr "使用者的 UID" diff --git a/src/man/po/bg.po b/src/man/po/bg.po index 77ec2f28b9e..9be9306cd33 100644 --- a/src/man/po/bg.po +++ b/src/man/po/bg.po @@ -8,7 +8,7 @@ msgstr "" "Project-Id-Version: sssd-docs 2.12.0\n" "Report-Msgid-Bugs-To: sssd-devel@redhat.com\n" "POT-Creation-Date: 2026-01-14 15:00+0000\n" -"PO-Revision-Date: 2026-04-23 16:39+0000\n" +"PO-Revision-Date: 2026-10-05 17:19+0000\n" "Last-Translator: Anonymous \n" "Language-Team: Bulgarian \n" @@ -17,7 +17,7 @@ msgstr "" "Content-Type: text/plain; charset=UTF-8\n" "Content-Transfer-Encoding: 8bit\n" "Plural-Forms: nplurals=2; plural=n != 1;\n" -"X-Generator: Weblate 5.17\n" +"X-Generator: Weblate 2026.10\n" #. type: Content of: #: sssd.conf.5.xml:8 sssd-ldap.5.xml:5 pam_sss.8.xml:5 pam_sss_gss.8.xml:5 diff --git a/src/man/po/br.po b/src/man/po/br.po index d7a129cad99..19c0c90ed9e 100644 --- a/src/man/po/br.po +++ b/src/man/po/br.po @@ -8,8 +8,8 @@ msgid "" msgstr "" "Project-Id-Version: sssd-docs 2.3.0\n" "Report-Msgid-Bugs-To: sssd-devel@redhat.com\n" -"POT-Creation-Date: 2026-01-14 15:00+0000\n" -"PO-Revision-Date: 2026-04-23 16:33+0000\n" +"POT-Creation-Date: 2026-10-05 16:14+0000\n" +"PO-Revision-Date: 2026-10-05 16:39+0000\n" "Last-Translator: Anonymous <noreply@weblate.org>\n" "Language-Team: Breton <https://translate.fedoraproject.org/projects/sssd/" "sssd-manpage-master/br/>\n" @@ -18,10 +18,10 @@ msgstr "" "Content-Type: text/plain; charset=UTF-8\n" "Content-Transfer-Encoding: 8bit\n" "Plural-Forms: nplurals=2; plural=n > 1;\n" -"X-Generator: Weblate 5.17\n" +"X-Generator: Weblate 2026.10\n" #. type: Content of: <reference><title> -#: sssd.conf.5.xml:8 sssd-ldap.5.xml:5 pam_sss.8.xml:5 pam_sss_gss.8.xml:5 +#: sssd.conf.5.xml:10 sssd-ldap.5.xml:5 pam_sss.8.xml:5 pam_sss_gss.8.xml:5 #: sssd_krb5_locator_plugin.8.xml:5 sssd-simple.5.xml:5 sss-certmap.5.xml:5 #: sssd-ipa.5.xml:5 sssd-ad.5.xml:5 sssd-sudo.5.xml:5 sssd-idp.5.xml:5 #: sssd.8.xml:5 sss_obfuscate.8.xml:5 sss_override.8.xml:5 sssd-krb5.5.xml:5 @@ -34,12 +34,12 @@ msgid "SSSD Manual pages" msgstr "Dornlevr SSSD" #. type: Content of: <reference><refentry><refnamediv><refname> -#: sssd.conf.5.xml:13 sssd.conf.5.xml:19 +#: sssd.conf.5.xml:15 sssd.conf.5.xml:21 msgid "sssd.conf" msgstr "sssd.conf" #. type: Content of: <reference><refentry><refmeta><manvolnum> -#: sssd.conf.5.xml:14 sssd-ldap.5.xml:11 sssd-simple.5.xml:11 +#: sssd.conf.5.xml:16 sssd-ldap.5.xml:11 sssd-simple.5.xml:11 #: sss-certmap.5.xml:11 sssd-ipa.5.xml:11 sssd-ad.5.xml:11 sssd-sudo.5.xml:11 #: sssd-idp.5.xml:11 sssd-krb5.5.xml:11 sssd-ifp.5.xml:11 #: sss_rpcidmapd.5.xml:27 sssd-session-recording.5.xml:11 @@ -48,7 +48,7 @@ msgid "5" msgstr "5" #. type: Content of: <reference><refentry><refmeta><refmiscinfo> -#: sssd.conf.5.xml:15 sssd-ldap.5.xml:12 sssd-simple.5.xml:12 +#: sssd.conf.5.xml:17 sssd-ldap.5.xml:12 sssd-simple.5.xml:12 #: sss-certmap.5.xml:12 sssd-ipa.5.xml:12 sssd-ad.5.xml:12 sssd-sudo.5.xml:12 #: sssd-idp.5.xml:12 sssd-krb5.5.xml:12 sssd-ifp.5.xml:12 #: sss_rpcidmapd.5.xml:28 sssd-session-recording.5.xml:12 sssd-kcm.8.xml:12 @@ -57,17 +57,17 @@ msgid "File Formats and Conventions" msgstr "" #. type: Content of: <reference><refentry><refnamediv><refpurpose> -#: sssd.conf.5.xml:20 +#: sssd.conf.5.xml:22 msgid "the configuration file for SSSD" msgstr "Ar restr gefluniañ evit SSSD" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:24 +#: sssd.conf.5.xml:26 msgid "FILE FORMAT" msgstr "FURMAD RESTR" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd.conf.5.xml:32 +#: sssd.conf.5.xml:34 #, no-wrap msgid "" "<replaceable>[section]</replaceable>\n" @@ -77,7 +77,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:27 +#: sssd.conf.5.xml:29 msgid "" "The file has an ini-style syntax and consists of sections and parameters. A " "section begins with the name of the section in square brackets and continues " @@ -86,47 +86,50 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:39 +#: sssd.conf.5.xml:41 msgid "" -"The data types used are string (no quotes needed), integer and bool (with " -"values of <quote>TRUE/FALSE</quote>)." +"The data types used are string (no quotes needed), integer and boolean (with " +"values of <quote>TRUE/FALSE</quote>). Boolean values are case-insensitive; " +"for example, <quote>TRUE</quote>, <quote>True</quote> and <quote>true</" +"quote> are all equivalent and valid; the same applies to <quote>FALSE</" +"quote>." msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:44 +#: sssd.conf.5.xml:49 msgid "" "A comment line starts with a hash sign (<quote>#</quote>) or a semicolon " "(<quote>;</quote>). Inline comments are not supported." msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:50 +#: sssd.conf.5.xml:55 msgid "" "All sections can have an optional <replaceable>description</replaceable> " "parameter. Its function is only as a label for the section." msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:56 +#: sssd.conf.5.xml:61 msgid "" "<filename>sssd.conf</filename> must be a regular file that is owned, " "readable, and writeable only by 'root'." msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:60 +#: sssd.conf.5.xml:65 msgid "" "<filename>sssd.conf</filename> must be a regular file that is accessible " "only by the user used to run SSSD service or root." msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:66 +#: sssd.conf.5.xml:71 msgid "CONFIGURATION SNIPPETS FROM INCLUDE DIRECTORY" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:69 +#: sssd.conf.5.xml:74 msgid "" "The configuration file <filename>sssd.conf</filename> will include " "configuration snippets using the include directory <filename>conf.d</" @@ -134,7 +137,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:75 +#: sssd.conf.5.xml:80 msgid "" "Any file placed in <filename>conf.d</filename> that ends in " "<quote><filename>.conf</filename></quote> and does not begin with a dot " @@ -143,7 +146,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:83 +#: sssd.conf.5.xml:88 msgid "" "The configuration snippets from <filename>conf.d</filename> have higher " "priority than <filename>sssd.conf</filename> and will override " @@ -156,39 +159,88 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:97 +#: sssd.conf.5.xml:102 msgid "" "The snippet files require the same owner and permissions as " "<filename>sssd.conf</filename>." msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:103 +#: sssd.conf.5.xml:108 +msgid "VENDOR PROVIDED CONFIGURATION" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:111 +msgid "" +"The vendor provided configuration file is installed in " +"<filename>&sssd_vendor_dir;/sssd.conf</filename>, but this file must not be " +"directly edited. It can be completely masked by creating the system specific " +"configuration file <filename>&sssd_conf_dir;/sssd.conf</filename>, or partly " +"overriden by creating config snippets in <filename>&sssd_conf_dir;/conf.d</" +"filename> directory." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><title> +#: sssd.conf.5.xml:120 +msgid "CONFIGURATION FILE HIERARCHY" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:122 +msgid "" +"When sssd reads the configuration it first tries to open the system specific " +"configuration file in <filename>&sssd_conf_dir;/sssd.conf</filename>. If it " +"exists, it is loaded and snippets from <filename>&sssd_conf_dir;/conf.d</" +"filename> are applied. The vendor provided configuration file " +"<filename>&sssd_vendor_dir;/sssd.conf</filename> is completely ignored in " +"this case." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:131 +msgid "" +"If the system specific configuration file <filename>&sssd_conf_dir;/" +"sssd.conf</filename> does not exist, then the vendor configuration file " +"<filename>&sssd_vendor_dir;/sssd.conf</filename> is loaded and snippets from " +"<filename>&sssd_conf_dir;/conf.d</filename> are applied." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd.conf.5.xml:141 msgid "GENERAL OPTIONS" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:105 +#: sssd.conf.5.xml:143 msgid "Following options are usable in more than one configuration sections." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:109 +#: sssd.conf.5.xml:147 msgid "Options usable in all sections" msgstr "" +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:149 +msgid "" +"Note: Below options are ignored in <quote>[session_recording]</quote> " +"section, see <quote>Session recording configuration options</quote> section " +"for more details." +msgstr "" + #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:113 +#: sssd.conf.5.xml:156 msgid "debug_level (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:117 +#: sssd.conf.5.xml:160 msgid "debug (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:120 +#: sssd.conf.5.xml:163 msgid "" "SSSD 1.14 and later also includes the <replaceable>debug</replaceable> alias " "for <replaceable>debug_level</replaceable> as a convenience feature. If both " @@ -197,61 +249,61 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:130 -msgid "debug_timestamps (bool)" +#: sssd.conf.5.xml:173 +msgid "debug_timestamps (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:133 +#: sssd.conf.5.xml:176 msgid "" "Add a timestamp to the debug messages. If journald is enabled for SSSD " "debug logging this option is ignored." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:138 sssd.conf.5.xml:175 sssd.conf.5.xml:337 -#: sssd.conf.5.xml:644 sssd.conf.5.xml:668 sssd.conf.5.xml:875 -#: sssd.conf.5.xml:979 sssd.conf.5.xml:2113 sssd-ldap.5.xml:979 -#: sssd-ldap.5.xml:1134 sssd-ldap.5.xml:1237 sssd-ldap.5.xml:1306 -#: sssd-ldap.5.xml:1714 sssd-ldap.5.xml:1848 sssd-ldap.5.xml:1913 -#: sssd-ipa.5.xml:346 sssd-ad.5.xml:252 sssd-ad.5.xml:367 sssd-ad.5.xml:1180 -#: sssd-ad.5.xml:1382 sssd-krb5.5.xml:358 +#: sssd.conf.5.xml:181 sssd.conf.5.xml:218 sssd.conf.5.xml:380 +#: sssd.conf.5.xml:687 sssd.conf.5.xml:711 sssd.conf.5.xml:827 +#: sssd.conf.5.xml:932 sssd.conf.5.xml:2149 sssd.conf.5.xml:4730 +#: sssd-ldap.5.xml:979 sssd-ldap.5.xml:1134 sssd-ldap.5.xml:1237 +#: sssd-ldap.5.xml:1306 sssd-ldap.5.xml:1714 sssd-ldap.5.xml:1848 +#: sssd-ldap.5.xml:1913 sssd-ipa.5.xml:341 sssd-ad.5.xml:252 sssd-ad.5.xml:367 +#: sssd-ad.5.xml:1180 sssd-ad.5.xml:1375 sssd-krb5.5.xml:358 msgid "Default: true" msgstr "Dre ziouer : true" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:143 -msgid "debug_microseconds (bool)" +#: sssd.conf.5.xml:186 +msgid "debug_microseconds (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:146 +#: sssd.conf.5.xml:189 msgid "" "Add microseconds to the timestamp in debug messages. If journald is enabled " "for SSSD debug logging this option is ignored." msgstr "" #. type: Content of: <variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:151 sssd.conf.5.xml:2040 sssd.conf.5.xml:4158 +#: sssd.conf.5.xml:194 sssd.conf.5.xml:2072 sssd.conf.5.xml:4363 #: sssd-ldap.5.xml:363 sssd-ldap.5.xml:998 sssd-ldap.5.xml:1209 -#: sssd-ldap.5.xml:1663 sssd-ldap.5.xml:1937 sssd-ipa.5.xml:146 -#: sssd-ipa.5.xml:706 sssd-ad.5.xml:1135 sssd-krb5.5.xml:268 +#: sssd-ldap.5.xml:1663 sssd-ldap.5.xml:1937 sssd-ipa.5.xml:141 +#: sssd-ipa.5.xml:701 sssd-ad.5.xml:1140 sssd-idp.5.xml:287 sssd-krb5.5.xml:268 #: sssd-krb5.5.xml:330 sssd-krb5.5.xml:432 include/krb5_options.xml:163 msgid "Default: false" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:156 -msgid "debug_backtrace_enabled (bool)" +#: sssd.conf.5.xml:199 +msgid "debug_backtrace_enabled (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:159 +#: sssd.conf.5.xml:202 msgid "Enable debug backtrace." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:162 +#: sssd.conf.5.xml:205 msgid "" "In case SSSD is run with debug_level less than 9, everything is logged to a " "ring buffer in memory and flushed to a log file on any error up to and " @@ -261,14 +313,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:171 +#: sssd.conf.5.xml:214 msgid "" "Feature is only supported for `logger == files` (i.e. setting doesn't have " "effect for other logger types)." msgstr "" #. type: Content of: outside any tag (error?) -#: sssd.conf.5.xml:111 sssd.conf.5.xml:186 sssd-ldap.5.xml:1754 +#: sssd.conf.5.xml:154 sssd.conf.5.xml:229 sssd-ldap.5.xml:1754 #: sssd-ldap.5.xml:1960 sss-certmap.5.xml:645 sssd-systemtap.5.xml:82 #: sssd-systemtap.5.xml:143 sssd-systemtap.5.xml:236 sssd-systemtap.5.xml:274 #: sssd-systemtap.5.xml:330 sssd-ldap-attributes.5.xml:40 @@ -281,17 +333,17 @@ msgid "<placeholder type=\"variablelist\" id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:184 +#: sssd.conf.5.xml:227 msgid "Options usable in SERVICE and DOMAIN sections" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:188 +#: sssd.conf.5.xml:231 msgid "timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:191 +#: sssd.conf.5.xml:234 msgid "" "Timeout in seconds between heartbeats for this service. This is used to " "ensure that the process is alive and capable of answering requests. Note " @@ -299,34 +351,36 @@ msgid "" msgstr "" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:198 sssd.conf.5.xml:1199 sssd.conf.5.xml:1673 -#: sssd.conf.5.xml:4174 sssd-ldap.5.xml:825 sssd-idp.5.xml:192 +#: sssd.conf.5.xml:241 sssd.conf.5.xml:1155 sssd.conf.5.xml:1665 +#: sssd.conf.5.xml:4379 sssd-ldap.5.xml:825 sssd-idp.5.xml:271 #: include/ldap_id_mapping.xml:270 msgid "Default: 10" msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:208 +#: sssd.conf.5.xml:251 msgid "SPECIAL SECTIONS" msgstr "RANNOÙ DIBAR" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:211 +#: sssd.conf.5.xml:254 msgid "The [sssd] section" msgstr "Ar rann [sssd]" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><title> -#: sssd.conf.5.xml:220 +#: sssd.conf.5.xml:263 msgid "Section parameters" msgstr "Arventennoù ar rann" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:222 -msgid "services" -msgstr "" +#: sssd.conf.5.xml:265 +#, fuzzy +#| msgid "re_expression (string)" +msgid "services (string)" +msgstr "re_expression (neudennad)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:225 +#: sssd.conf.5.xml:268 msgid "" "Comma separated list of services that are started when sssd itself starts. " "<phrase condition=\"have_systemd\"> The services' list is optional on " @@ -335,7 +389,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:234 +#: sssd.conf.5.xml:277 msgid "" "Supported services: nss, pam, ifp <phrase condition=\"with_sudo\">, sudo</" "phrase> <phrase condition=\"with_autofs\">, autofs</phrase> <phrase " @@ -344,20 +398,20 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:241 +#: sssd.conf.5.xml:284 msgid "" "<phrase condition=\"have_systemd\"> By default, all services are disabled " "and the administrator must enable the ones allowed to be used by executing: " "\"systemctl enable sssd-@service@.socket\". </phrase>" msgstr "" -#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:250 -msgid "domains" -msgstr "domanioù" +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sssd.conf.5.xml:293 sssd.conf.5.xml:4562 +msgid "domains (string)" +msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:253 +#: sssd.conf.5.xml:296 msgid "" "A domain is a database containing user information. SSSD can use more " "domains at the same time, but at least one must be configured or SSSD won't " @@ -368,19 +422,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:266 sssd.conf.5.xml:3467 +#: sssd.conf.5.xml:309 sssd.conf.5.xml:3598 msgid "re_expression (string)" msgstr "re_expression (neudennad)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:269 +#: sssd.conf.5.xml:312 msgid "" "Default regular expression that describes how to parse the string containing " "user name and domain into these components." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:274 +#: sssd.conf.5.xml:317 msgid "" "Each domain can have an individual regular expression configured. For some " "ID providers there are also default regular expressions. See DOMAIN SECTIONS " @@ -388,12 +442,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:283 sssd.conf.5.xml:3524 +#: sssd.conf.5.xml:326 sssd.conf.5.xml:3655 msgid "full_name_format (string)" msgstr "full_name_format (neudennad)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:286 sssd.conf.5.xml:3527 +#: sssd.conf.5.xml:329 sssd.conf.5.xml:3658 msgid "" "A <citerefentry> <refentrytitle>printf</refentrytitle> <manvolnum>3</" "manvolnum> </citerefentry>-compatible format that describes how to compose a " @@ -401,70 +455,70 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:297 sssd.conf.5.xml:3538 +#: sssd.conf.5.xml:340 sssd.conf.5.xml:3669 msgid "%1$s" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:298 sssd.conf.5.xml:3539 +#: sssd.conf.5.xml:341 sssd.conf.5.xml:3670 msgid "user name" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:301 sssd.conf.5.xml:3542 +#: sssd.conf.5.xml:344 sssd.conf.5.xml:3673 msgid "%2$s" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:304 sssd.conf.5.xml:3545 +#: sssd.conf.5.xml:347 sssd.conf.5.xml:3676 msgid "domain name as specified in the SSSD config file." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:310 sssd.conf.5.xml:3551 +#: sssd.conf.5.xml:353 sssd.conf.5.xml:3682 msgid "%3$s" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:313 sssd.conf.5.xml:3554 +#: sssd.conf.5.xml:356 sssd.conf.5.xml:3685 msgid "" "domain flat name. Mostly usable for Active Directory domains, both directly " "configured or discovered via IPA trusts." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:294 sssd.conf.5.xml:3535 +#: sssd.conf.5.xml:337 sssd.conf.5.xml:3666 msgid "" "The following expansions are supported: <placeholder type=\"variablelist\" " "id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:323 +#: sssd.conf.5.xml:366 msgid "" "Each domain can have an individual format string configured. See DOMAIN " "SECTIONS for more info on this option." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:329 +#: sssd.conf.5.xml:372 msgid "monitor_resolv_conf (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:332 +#: sssd.conf.5.xml:375 msgid "" "Controls if SSSD should monitor the state of resolv.conf to identify when it " "needs to update its internal DNS resolver." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:342 +#: sssd.conf.5.xml:385 msgid "try_inotify (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:345 +#: sssd.conf.5.xml:388 msgid "" "By default, SSSD will attempt to use inotify to monitor configuration files " "changes and will fall back to polling every five seconds if inotify cannot " @@ -472,7 +526,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:351 +#: sssd.conf.5.xml:394 msgid "" "There are some limited situations where it is preferred that we should skip " "even trying to use inotify. In these rare cases, this option should be set " @@ -480,59 +534,59 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:357 +#: sssd.conf.5.xml:400 msgid "" "Default: true on platforms where inotify is supported. False on other " "platforms." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:361 +#: sssd.conf.5.xml:404 msgid "" "Note: this option will have no effect on platforms where inotify is " "unavailable. On these platforms, polling will always be used." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:368 +#: sssd.conf.5.xml:411 msgid "krb5_rcache_dir (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:371 +#: sssd.conf.5.xml:414 msgid "" "Directory on the filesystem where SSSD should store Kerberos replay cache " "files." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:375 +#: sssd.conf.5.xml:418 msgid "" "This option accepts a special value __LIBKRB5_DEFAULTS__ that will instruct " "SSSD to let libkrb5 decide the appropriate location for the replay cache." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:381 +#: sssd.conf.5.xml:424 msgid "" "Default: Distribution-specific and specified at build-time. " "(__LIBKRB5_DEFAULTS__ if not configured)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:388 +#: sssd.conf.5.xml:431 msgid "default_domain_suffix (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:391 +#: sssd.conf.5.xml:434 msgid "" "Please note that this option is deprecated and domain_resolution_order " "should be used." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:395 +#: sssd.conf.5.xml:438 msgid "" "This string will be used as a default domain name for all names without a " "domain name component. The main use case is environments where the primary " @@ -542,7 +596,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:405 +#: sssd.conf.5.xml:448 msgid "" "Please note that if this option is set all users from the primary domain " "have to use their fully qualified name, e.g. user@domain.name, to log in. " @@ -552,21 +606,21 @@ msgid "" msgstr "" #. type: Content of: <variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:414 sssd-ldap.5.xml:937 sssd-ldap.5.xml:949 -#: sssd-ldap.5.xml:1042 sssd-ad.5.xml:921 sssd-ad.5.xml:996 sssd-krb5.5.xml:468 -#: sssd-ldap-attributes.5.xml:470 sssd-ldap-attributes.5.xml:978 -#: include/ldap_id_mapping.xml:211 include/ldap_id_mapping.xml:222 -#: include/krb5_options.xml:148 +#: sssd.conf.5.xml:457 sssd.conf.5.xml:2006 sssd-ldap.5.xml:937 +#: sssd-ldap.5.xml:949 sssd-ldap.5.xml:1042 sssd-ad.5.xml:926 +#: sssd-ad.5.xml:1001 sssd-krb5.5.xml:468 sssd-ldap-attributes.5.xml:470 +#: sssd-ldap-attributes.5.xml:978 include/ldap_id_mapping.xml:211 +#: include/ldap_id_mapping.xml:222 include/krb5_options.xml:148 msgid "Default: not set" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:419 +#: sssd.conf.5.xml:462 msgid "override_space (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:422 +#: sssd.conf.5.xml:465 msgid "" "This parameter will replace spaces (space bar) with the given character for " "user and group names. e.g. (_). User name "john doe" will be " @@ -576,7 +630,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:431 +#: sssd.conf.5.xml:474 msgid "" "Please note it is a configuration error to use a replacement character that " "might be used in user or group names. If a name contains the replacement " @@ -585,22 +639,22 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:439 +#: sssd.conf.5.xml:482 msgid "Default: not set (spaces will not be replaced)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:444 +#: sssd.conf.5.xml:487 msgid "certificate_verification (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:452 +#: sssd.conf.5.xml:495 msgid "no_ocsp" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:454 +#: sssd.conf.5.xml:497 msgid "" "Disables Online Certificate Status Protocol (OCSP) checks. This might be " "needed if the OCSP servers defined in the certificate are not reachable from " @@ -608,12 +662,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:462 +#: sssd.conf.5.xml:505 msgid "soft_ocsp" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:464 +#: sssd.conf.5.xml:507 msgid "" "If a connection cannot be established to an OCSP responder the OCSP check is " "skipped. This option should be used to allow authentication when the system " @@ -621,61 +675,61 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:474 +#: sssd.conf.5.xml:517 msgid "ocsp_dgst" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:476 +#: sssd.conf.5.xml:519 msgid "" "Digest (hash) function used to create the certificate ID for the OCSP " "request. Allowed values are:" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:480 +#: sssd.conf.5.xml:523 msgid "sha1" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:481 +#: sssd.conf.5.xml:524 msgid "sha256" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:482 +#: sssd.conf.5.xml:525 msgid "sha384" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:483 +#: sssd.conf.5.xml:526 msgid "sha512" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:486 +#: sssd.conf.5.xml:529 msgid "Default: sha1 (to allow compatibility with RFC5019-compliant responder)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:492 +#: sssd.conf.5.xml:535 msgid "no_verification" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:494 +#: sssd.conf.5.xml:537 msgid "" "Disables verification completely. This option should only be used for " "testing." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:500 +#: sssd.conf.5.xml:543 msgid "partial_chain" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:502 +#: sssd.conf.5.xml:545 msgid "" "Allow verification to succeed even if a <replaceable>complete</replaceable> " "chain cannot be built to a self-signed trust-anchor, provided it is possible " @@ -683,12 +737,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:511 +#: sssd.conf.5.xml:554 msgid "ocsp_default_responder=URL" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:513 +#: sssd.conf.5.xml:556 msgid "" "Sets the OCSP default responder which should be used instead of the one " "mentioned in the certificate. URL must be replaced with the URL of the OCSP " @@ -696,24 +750,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:523 +#: sssd.conf.5.xml:566 msgid "ocsp_default_responder_signing_cert=NAME" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:525 +#: sssd.conf.5.xml:568 msgid "" "This option is currently ignored. All needed certificates must be available " "in the PEM file given by pam_cert_db_path." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:533 +#: sssd.conf.5.xml:576 msgid "crl_file=/PATH/TO/CRL/FILE" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:535 +#: sssd.conf.5.xml:578 msgid "" "Use the Certificate Revocation List (CRL) from the given file during the " "verification of the certificate. The CRL must be given in PEM format, see " @@ -722,12 +776,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:548 +#: sssd.conf.5.xml:591 msgid "soft_crl" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:551 +#: sssd.conf.5.xml:594 msgid "" "If a Certificate Revocation List (CRL) is expired ignore the expiration " "time of the CRL and check the related certificates with the expired CRL. " @@ -736,7 +790,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:447 +#: sssd.conf.5.xml:490 msgid "" "With this parameter the certificate verification can be tuned with a comma " "separated list of options. Supported options are: <placeholder " @@ -744,46 +798,48 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:564 +#: sssd.conf.5.xml:607 msgid "Unknown options are reported but ignored." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:567 +#: sssd.conf.5.xml:610 msgid "Default: not set, i.e. do not restrict certificate verification" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:573 +#: sssd.conf.5.xml:616 msgid "disable_netlink (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:576 +#: sssd.conf.5.xml:619 msgid "" "SSSD hooks into the netlink interface to monitor changes to routes, " "addresses, links and trigger certain actions." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:581 +#: sssd.conf.5.xml:624 msgid "" "The SSSD state changes caused by netlink events may be undesirable and can " "be disabled by setting this option to 'true'" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:586 +#: sssd.conf.5.xml:629 msgid "Default: false (netlink changes are detected)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:591 -msgid "domain_resolution_order" -msgstr "" +#: sssd.conf.5.xml:634 +#, fuzzy +#| msgid "re_expression (string)" +msgid "domain_resolution_order (string)" +msgstr "re_expression (neudennad)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:594 +#: sssd.conf.5.xml:637 msgid "" "Comma separated list of domains and subdomains representing the lookup order " "that will be followed. The list doesn't have to include all possible " @@ -794,7 +850,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:606 +#: sssd.conf.5.xml:649 msgid "" "Please, note that when this option is set the output format of all commands " "is always fully-qualified even when using short names for input. In case " @@ -810,19 +866,20 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:630 sssd.conf.5.xml:1697 sssd.conf.5.xml:4224 -#: sssd-ad.5.xml:187 sssd-ad.5.xml:328 sssd-ad.5.xml:342 sssd-idp.5.xml:108 -#: sssd-idp.5.xml:132 sssd-idp.5.xml:145 sssd-idp.5.xml:159 sssd-idp.5.xml:180 +#: sssd.conf.5.xml:673 sssd.conf.5.xml:1026 sssd.conf.5.xml:1689 +#: sssd.conf.5.xml:4429 sssd-ad.5.xml:187 sssd-ad.5.xml:328 sssd-ad.5.xml:342 +#: sssd-idp.5.xml:112 sssd-idp.5.xml:136 sssd-idp.5.xml:149 sssd-idp.5.xml:167 +#: sssd-idp.5.xml:188 msgid "Default: Not set" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:635 +#: sssd.conf.5.xml:678 msgid "implicit_pac_responder (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:638 +#: sssd.conf.5.xml:681 msgid "" "The PAC responder is enabled automatically for the IPA and AD provider to " "evaluate and check the PAC. If it has to be disabled set this option to " @@ -830,12 +887,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:649 +#: sssd.conf.5.xml:692 msgid "core_dumpable (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:652 +#: sssd.conf.5.xml:695 msgid "" "This option can be used for general system hardening: setting it to 'false' " "forbids core dumps for all SSSD processes to avoid leaking plain text " @@ -844,7 +901,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:660 +#: sssd.conf.5.xml:703 msgid "" "Take a note that this setting has no effect for 'ldap_child', 'krb5_child' " "and 'sssd_pam' as those privileged binaries can have a copy of a host keytab " @@ -853,28 +910,28 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:673 +#: sssd.conf.5.xml:716 #, fuzzy #| msgid "re_expression (string)" msgid "passkey_verification (string)" msgstr "re_expression (neudennad)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:681 +#: sssd.conf.5.xml:724 #, fuzzy #| msgid "re_expression (string)" msgid "user_verification (boolean)" msgstr "re_expression (neudennad)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:683 +#: sssd.conf.5.xml:726 msgid "" "Enable or disable the user verification (i.e. PIN, fingerprint) during " "authentication. If enabled, the PIN will always be requested." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:689 +#: sssd.conf.5.xml:732 msgid "" "The default is that the key settings decide what to do. In the IPA or " "kerberos pre-authentication case, this value will be overwritten by the " @@ -882,7 +939,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:676 +#: sssd.conf.5.xml:719 msgid "" "With this parameter the passkey verification can be tuned with a comma " "separated list of options. Supported options are: <placeholder " @@ -890,7 +947,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:213 +#: sssd.conf.5.xml:256 msgid "" "Individual pieces of SSSD functionality are provided by special SSSD " "services that are started and stopped together with SSSD. The services are " @@ -901,12 +958,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:708 +#: sssd.conf.5.xml:751 msgid "SERVICES SECTIONS" msgstr "RANNOÙ SERVIJOÙ" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:710 +#: sssd.conf.5.xml:753 msgid "" "Settings that can be used to configure different services are described in " "this section. They should reside in the [<replaceable>$NAME</replaceable>] " @@ -915,42 +972,41 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:717 +#: sssd.conf.5.xml:760 msgid "General service configuration options" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:719 +#: sssd.conf.5.xml:762 msgid "These options can be used to configure any service." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:723 -msgid "fd_limit" +#: sssd.conf.5.xml:766 +msgid "fd_limit (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:726 +#: sssd.conf.5.xml:769 msgid "" "This option specifies the maximum number of file descriptors that may be " -"opened at one time by this SSSD process. On systems where SSSD is granted " -"the CAP_SYS_RESOURCE capability, this will be an absolute setting. On " -"systems without this capability, the resulting value will be the lower value " -"of this or the limits.conf \"hard\" limit." +"opened at one time by this SSSD process. Note this value will be capped by " +"the init system at the startup of SSSD, see e.g. man systemd.exec for " +"details." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:735 +#: sssd.conf.5.xml:776 msgid "Default: 8192 (or limits.conf \"hard\" limit)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:740 -msgid "client_idle_timeout" +#: sssd.conf.5.xml:781 +msgid "client_idle_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:743 +#: sssd.conf.5.xml:784 msgid "" "This option specifies the number of seconds that a client of an SSSD process " "can hold onto a file descriptor without communicating on it. This value is " @@ -960,146 +1016,21 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:752 +#: sssd.conf.5.xml:793 #, fuzzy #| msgid "Default: 3" msgid "Default: 60, KCM: 300" msgstr "Dre ziouer : 3" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:757 -msgid "offline_timeout (integer)" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:760 -msgid "" -"When SSSD switches to offline mode the amount of time before it tries to go " -"back online will increase based upon the time spent disconnected. By " -"default SSSD uses incremental behaviour to calculate delay in between " -"retries. So, the wait time for a given retry will be longer than the wait " -"time for the previous ones. After each unsuccessful attempt to go online, " -"the new interval is recalculated by the following:" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:771 sssd.conf.5.xml:827 -msgid "" -"new_delay = Minimum(old_delay * 2, offline_timeout_max) + " -"random[0...offline_timeout_random_offset]" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:774 -msgid "" -"The offline_timeout default value is 60. The offline_timeout_max default " -"value is 3600. The offline_timeout_random_offset default value is 30. The " -"end result is amount of seconds before next retry." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:780 -msgid "" -"Note that the maximum length of each interval is defined by " -"offline_timeout_max (apart of random part)." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:784 sssd.conf.5.xml:1110 sssd.conf.5.xml:1490 -#: sssd.conf.5.xml:1791 sssd-ldap.5.xml:550 -msgid "Default: 60" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:789 -msgid "offline_timeout_max (integer)" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:792 -msgid "" -"Controls by how much the time between attempts to go online can be " -"incremented following unsuccessful attempts to go online." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:797 -msgid "A value of 0 disables the incrementing behaviour." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:800 -msgid "" -"The value of this parameter should be set in correlation to offline_timeout " -"parameter value." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:804 -msgid "" -"With offline_timeout set to 60 (default value) there is no point in setting " -"offlinet_timeout_max to less than 120 as it will saturate instantly. General " -"rule here should be to set offline_timeout_max to at least 4 times " -"offline_timeout." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:810 -msgid "" -"Although a value between 0 and offline_timeout may be specified, it has the " -"effect of overriding the offline_timeout value so is of little use." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:815 -#, fuzzy -#| msgid "Default: 3" -msgid "Default: 3600" -msgstr "Dre ziouer : 3" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:820 -msgid "offline_timeout_random_offset (integer)" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:823 -msgid "" -"When SSSD is in offline mode it keeps probing backend servers in specified " -"time intervals:" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:830 -msgid "" -"This parameter controls the value of the random offset used for the above " -"equation. Final random_offset value will be random number in range:" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:835 -msgid "[0 - offline_timeout_random_offset]" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:838 -msgid "A value of 0 disables the random offset addition." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:841 +#: sssd.conf.5.xml:798 #, fuzzy -#| msgid "Default: 3" -msgid "Default: 30" -msgstr "Dre ziouer : 3" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:846 -msgid "responder_idle_timeout" -msgstr "" +#| msgid "re_expression (string)" +msgid "responder_idle_timeout (integer)" +msgstr "re_expression (neudennad)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:849 +#: sssd.conf.5.xml:801 msgid "" "This option specifies the number of seconds that an SSSD responder process " "can be up without being used. This value is limited in order to avoid " @@ -1111,58 +1042,61 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:863 sssd.conf.5.xml:1123 sssd.conf.5.xml:2248 +#: sssd.conf.5.xml:815 sssd.conf.5.xml:1079 sssd.conf.5.xml:2285 #: sssd-ldap.5.xml:377 msgid "Default: 300" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:868 -msgid "cache_first" -msgstr "" +#: sssd.conf.5.xml:820 +#, fuzzy +#| msgid "re_expression (string)" +msgid "cache_first (boolean)" +msgstr "re_expression (neudennad)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:871 +#: sssd.conf.5.xml:823 msgid "" "This option specifies whether the responder should query all caches before " "querying the Data Providers." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:883 +#: sssd.conf.5.xml:835 msgid "NSS configuration options" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:885 +#: sssd.conf.5.xml:837 msgid "" -"These options can be used to configure the Name Service Switch (NSS) service." +"These options can be used to configure the Name Service Switch (NSS) service " +"and should be specified under the <quote>[nss]</quote> section." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:890 +#: sssd.conf.5.xml:843 msgid "enum_cache_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:893 +#: sssd.conf.5.xml:846 msgid "" "How many seconds should nss_sss cache enumerations (requests for info about " "all users)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:897 +#: sssd.conf.5.xml:850 msgid "Default: 120" msgstr "Dre ziouer : 120" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:902 +#: sssd.conf.5.xml:855 msgid "entry_cache_nowait_percentage (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:905 +#: sssd.conf.5.xml:858 msgid "" "The entry cache can be set to automatically update entries in the background " "if they are requested beyond a percentage of the entry_cache_timeout value " @@ -1170,7 +1104,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:911 +#: sssd.conf.5.xml:864 msgid "" "For example, if the domain's entry_cache_timeout is set to 30s and " "entry_cache_nowait_percentage is set to 50 (percent), entries that come in " @@ -1180,7 +1114,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:921 +#: sssd.conf.5.xml:874 msgid "" "Valid values for this option are 0-99 and represent a percentage of the " "entry_cache_timeout for each domain. For performance reasons, this " @@ -1189,17 +1123,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:929 sssd.conf.5.xml:2061 +#: sssd.conf.5.xml:882 sssd.conf.5.xml:2093 msgid "Default: 50" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:934 +#: sssd.conf.5.xml:887 msgid "entry_negative_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:937 +#: sssd.conf.5.xml:890 msgid "" "Specifies for how many seconds nss_sss should cache negative cache hits " "(that is, queries for invalid database entries, like nonexistent ones) " @@ -1207,17 +1141,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:943 sssd.conf.5.xml:1685 sssd.conf.5.xml:2085 +#: sssd.conf.5.xml:896 sssd.conf.5.xml:1677 sssd.conf.5.xml:2119 msgid "Default: 15" msgstr "Dre ziouer : 15" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:948 +#: sssd.conf.5.xml:901 msgid "filter_users, filter_groups (string)" msgstr "filter_users, filter_groups (neudennad)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:951 +#: sssd.conf.5.xml:904 msgid "" "Exclude certain users or groups from being fetched from the sss NSS " "database. This is particularly useful for system accounts. This option can " @@ -1226,7 +1160,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:959 +#: sssd.conf.5.xml:912 msgid "" "NOTE: The filter_groups option doesn't affect inheritance of nested group " "members, since filtering happens after they are propagated for returning via " @@ -1235,41 +1169,43 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:967 +#: sssd.conf.5.xml:920 msgid "Default: root" msgstr "Dre zoiuer : root" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:972 -msgid "filter_users_in_groups (bool)" -msgstr "" +#: sssd.conf.5.xml:925 +#, fuzzy +#| msgid "filter_users, filter_groups (string)" +msgid "filter_users_in_groups (boolean)" +msgstr "filter_users, filter_groups (neudennad)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:975 +#: sssd.conf.5.xml:928 msgid "" -"If you want filtered user still be group members set this option to false." +"If you want filtered users to remain group members set this option to false" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:986 +#: sssd.conf.5.xml:939 msgid "fallback_homedir (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:989 +#: sssd.conf.5.xml:942 msgid "" "Set a default template for a user's home directory if one is not specified " "explicitly by the domain's data provider." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:994 +#: sssd.conf.5.xml:947 msgid "" "The available values for this option are the same as for override_homedir." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1000 +#: sssd.conf.5.xml:953 #, no-wrap msgid "" "fallback_homedir = /home/%u\n" @@ -1277,23 +1213,23 @@ msgid "" msgstr "" #. type: Content of: <varlistentry><listitem><para> -#: sssd.conf.5.xml:998 sssd.conf.5.xml:1557 sssd.conf.5.xml:1576 -#: sssd.conf.5.xml:1653 sssd-krb5.5.xml:451 include/override_homedir.xml:78 +#: sssd.conf.5.xml:951 sssd.conf.5.xml:1524 sssd.conf.5.xml:1543 +#: sssd.conf.5.xml:1645 sssd-krb5.5.xml:451 include/override_homedir.xml:78 msgid "example: <placeholder type=\"programlisting\" id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1004 +#: sssd.conf.5.xml:957 msgid "Default: not set (no substitution for unset home directories)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1010 +#: sssd.conf.5.xml:963 msgid "override_shell (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1013 +#: sssd.conf.5.xml:966 msgid "" "Override the login shell for all users. This option supersedes any other " "shell options if it takes effect and can be set either in the [nss] section " @@ -1301,47 +1237,47 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1019 +#: sssd.conf.5.xml:972 msgid "Default: not set (SSSD will use the value retrieved from LDAP)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1025 +#: sssd.conf.5.xml:978 msgid "allowed_shells (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1028 +#: sssd.conf.5.xml:981 msgid "" "Restrict user shell to one of the listed values. The order of evaluation is:" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1031 +#: sssd.conf.5.xml:984 msgid "1. If the shell is present in <quote>/etc/shells</quote>, it is used." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1035 +#: sssd.conf.5.xml:988 msgid "" "2. If the shell is in the allowed_shells list but not in <quote>/etc/shells</" "quote>, use the value of the shell_fallback parameter." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1040 +#: sssd.conf.5.xml:993 msgid "" "3. If the shell is not in the allowed_shells list and not in <quote>/etc/" "shells</quote>, a nologin shell is used." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1045 +#: sssd.conf.5.xml:998 msgid "The wildcard (*) can be used to allow any shell." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1048 +#: sssd.conf.5.xml:1001 msgid "" "The (*) is useful if you want to use shell_fallback in case that user's " "shell is not in <quote>/etc/shells</quote> and maintaining list of all " @@ -1349,113 +1285,121 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1055 +#: sssd.conf.5.xml:1008 msgid "An empty string for shell is passed as-is to libc." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1058 +#: sssd.conf.5.xml:1011 msgid "" "The <quote>/etc/shells</quote> is only read on SSSD start up, which means " "that a restart of the SSSD is required in case a new shell is installed." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1062 +#: sssd.conf.5.xml:1015 msgid "Default: Not set. The user shell is automatically used." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1067 +#: sssd.conf.5.xml:1020 msgid "vetoed_shells (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1070 +#: sssd.conf.5.xml:1023 msgid "Replace any instance of these shells with the shell_fallback" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1075 +#: sssd.conf.5.xml:1031 msgid "shell_fallback (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1078 +#: sssd.conf.5.xml:1034 msgid "" "The default shell to use if an allowed shell is not installed on the machine." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1082 +#: sssd.conf.5.xml:1038 msgid "Default: /bin/sh" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1087 -msgid "default_shell" -msgstr "" +#: sssd.conf.5.xml:1043 +#, fuzzy +#| msgid "re_expression (string)" +msgid "default_shell (string)" +msgstr "re_expression (neudennad)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1090 +#: sssd.conf.5.xml:1046 msgid "" "The default shell to use if the provider does not return one during lookup. " "This option can be specified globally in the [nss] section or per-domain." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1096 +#: sssd.conf.5.xml:1052 msgid "" "Default: not set (Return NULL if no shell is specified and rely on libc to " "substitute something sensible when necessary, usually /bin/sh)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1103 sssd.conf.5.xml:1483 +#: sssd.conf.5.xml:1059 sssd.conf.5.xml:1450 msgid "get_domains_timeout (int)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1106 sssd.conf.5.xml:1486 +#: sssd.conf.5.xml:1062 sssd.conf.5.xml:1453 msgid "" "Specifies time in seconds for which the list of subdomains will be " "considered valid." msgstr "" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1066 sssd.conf.5.xml:1457 sssd.conf.5.xml:1788 +#: sssd.conf.5.xml:2862 sssd-ldap.5.xml:550 +msgid "Default: 60" +msgstr "" + #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1115 +#: sssd.conf.5.xml:1071 msgid "memcache_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1118 +#: sssd.conf.5.xml:1074 msgid "" "Specifies time in seconds for which records in the in-memory cache will be " "valid. Setting this option to zero will disable the in-memory cache." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1126 +#: sssd.conf.5.xml:1082 msgid "" "WARNING: Disabling the in-memory cache will have significant negative impact " "on SSSD's performance and should only be used for testing." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1132 sssd.conf.5.xml:1157 sssd.conf.5.xml:1182 -#: sssd.conf.5.xml:1207 sssd.conf.5.xml:1234 +#: sssd.conf.5.xml:1088 sssd.conf.5.xml:1113 sssd.conf.5.xml:1138 +#: sssd.conf.5.xml:1163 sssd.conf.5.xml:1190 msgid "" "NOTE: If the environment variable SSS_NSS_USE_MEMCACHE is set to \"NO\", " "client applications will not use the fast in-memory cache." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1140 +#: sssd.conf.5.xml:1096 msgid "memcache_size_passwd (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1143 +#: sssd.conf.5.xml:1099 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for passwd requests. Setting the size to 0 will disable the passwd in-" @@ -1463,25 +1407,25 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1149 sssd.conf.5.xml:2888 sssd-ldap.5.xml:604 +#: sssd.conf.5.xml:1105 sssd.conf.5.xml:3013 sssd-ldap.5.xml:604 msgid "Default: 8" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1152 sssd.conf.5.xml:1177 sssd.conf.5.xml:1202 -#: sssd.conf.5.xml:1229 +#: sssd.conf.5.xml:1108 sssd.conf.5.xml:1133 sssd.conf.5.xml:1158 +#: sssd.conf.5.xml:1185 msgid "" "WARNING: Disabled or too small in-memory cache can have significant negative " "impact on SSSD's performance." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1165 +#: sssd.conf.5.xml:1121 msgid "memcache_size_group (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1168 +#: sssd.conf.5.xml:1124 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for group requests. Setting the size to 0 will disable the group in-memory " @@ -1489,19 +1433,19 @@ msgid "" msgstr "" #. type: Content of: <variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1174 sssd.conf.5.xml:1226 sssd.conf.5.xml:3656 +#: sssd.conf.5.xml:1130 sssd.conf.5.xml:1182 sssd.conf.5.xml:3835 #: sssd-ldap.5.xml:534 sssd-ldap.5.xml:581 include/failover.xml:116 #: include/krb5_options.xml:11 msgid "Default: 6" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1190 +#: sssd.conf.5.xml:1146 msgid "memcache_size_initgroups (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1193 +#: sssd.conf.5.xml:1149 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for initgroups requests. Setting the size to 0 will disable the initgroups " @@ -1509,12 +1453,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1215 +#: sssd.conf.5.xml:1171 msgid "memcache_size_sid (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1218 +#: sssd.conf.5.xml:1174 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for SID related requests. Only SID-by-ID and ID-by-SID requests are " @@ -1523,12 +1467,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1242 sssd-ifp.5.xml:90 +#: sssd.conf.5.xml:1198 sssd-ifp.5.xml:90 msgid "user_attributes (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1245 +#: sssd.conf.5.xml:1201 msgid "" "Some of the additional NSS responder requests can return more attributes " "than just the POSIX ones defined by the NSS interface. The list of " @@ -1539,105 +1483,111 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1258 +#: sssd.conf.5.xml:1214 msgid "" "To make configuration more easy the NSS responder will check the InfoPipe " "option if it is not set for the NSS responder." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1263 +#: sssd.conf.5.xml:1219 msgid "Default: not set, fallback to InfoPipe option" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1268 +#: sssd.conf.5.xml:1224 msgid "pwfield (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1271 +#: sssd.conf.5.xml:1227 msgid "" "The value that NSS operations that return users or groups will return for " "the <quote>password</quote> field." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1276 +#: sssd.conf.5.xml:1232 +msgid "" +"This option can also be set per-domain, which overwrites the value in the " +"<quote>[nss]</quote> section for that domain. This is particularly useful " +"when using a proxy domain with <option>proxy_lib_name=files</option> and a " +"<option>proxy_pam_target</option> other than <quote>sssd-shadowutils</" +"quote>. In that case, SSSD returns <quote>*</quote> for the password field " +"by default, which causes <command>pam_unix</command> to treat all accounts " +"as locked. Setting <option>pwfield = x</option> in the domain section " +"restores the expected behavior." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1246 #, fuzzy #| msgid "Default: true" msgid "Default: <quote>*</quote>" msgstr "Dre ziouer : true" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1279 +#: sssd.conf.5.xml:1249 msgid "" -"Note: This option can also be set per-domain which overwrites the value in " -"[nss] section." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1283 -msgid "" -"Default: <quote>not set</quote> (remote domains), <quote>x</quote> (proxy " -"domain with nss_files and sssd-shadowutils target)" +"Default (per-domain): <quote>not set</quote> (remote domains), <quote>x</" +"quote> (proxy domain with nss_files and sssd-shadowutils target)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:1292 +#: sssd.conf.5.xml:1258 msgid "PAM configuration options" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:1294 +#: sssd.conf.5.xml:1260 msgid "" "These options can be used to configure the Pluggable Authentication Module " -"(PAM) service." +"(PAM) service and should be specified under the <quote>[pam]</quote> section." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1299 +#: sssd.conf.5.xml:1266 msgid "offline_credentials_expiration (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1302 +#: sssd.conf.5.xml:1269 msgid "" "If the authentication provider is offline, how long should we allow cached " "logins (in days since the last successful online login)." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1307 sssd.conf.5.xml:1320 +#: sssd.conf.5.xml:1274 sssd.conf.5.xml:1287 msgid "Default: 0 (No limit)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1313 +#: sssd.conf.5.xml:1280 msgid "offline_failed_login_attempts (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1316 +#: sssd.conf.5.xml:1283 msgid "" "If the authentication provider is offline, how many failed login attempts " "are allowed." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1326 +#: sssd.conf.5.xml:1293 msgid "offline_failed_login_delay (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1329 +#: sssd.conf.5.xml:1296 msgid "" "The time in minutes which has to pass after offline_failed_login_attempts " "has been reached before a new login attempt is possible." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1334 +#: sssd.conf.5.xml:1301 msgid "" "If set to 0 the user cannot authenticate offline if " "offline_failed_login_attempts has been reached. Only a successful online " @@ -1645,61 +1595,61 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1340 sssd.conf.5.xml:1450 +#: sssd.conf.5.xml:1307 sssd.conf.5.xml:1417 msgid "Default: 5" msgstr "Dre zoiuer : 5" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1346 +#: sssd.conf.5.xml:1313 msgid "pam_verbosity (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1349 +#: sssd.conf.5.xml:1316 msgid "" "Controls what kind of messages are shown to the user during authentication. " "The higher the number to more messages are displayed." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1354 +#: sssd.conf.5.xml:1321 msgid "Currently sssd supports the following values:" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1357 +#: sssd.conf.5.xml:1324 msgid "<emphasis>0</emphasis>: do not show any message" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1360 +#: sssd.conf.5.xml:1327 msgid "<emphasis>1</emphasis>: show only important messages" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1364 +#: sssd.conf.5.xml:1331 msgid "<emphasis>2</emphasis>: show informational messages" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1367 +#: sssd.conf.5.xml:1334 msgid "<emphasis>3</emphasis>: show all messages and debug information" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1371 sssd.8.xml:63 +#: sssd.conf.5.xml:1338 sssd.8.xml:63 msgid "Default: 1" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1377 +#: sssd.conf.5.xml:1344 #, fuzzy #| msgid "re_expression (string)" msgid "pam_response_filter (string)" msgstr "re_expression (neudennad)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1380 +#: sssd.conf.5.xml:1347 msgid "" "A comma separated list of strings which allows to remove (filter) data sent " "by the PAM responder to pam_sss PAM module. There are different kind of " @@ -1708,51 +1658,51 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1388 +#: sssd.conf.5.xml:1355 msgid "" "While messages already can be controlled with the help of the pam_verbosity " "option this option allows to filter out other kind of responses as well." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1395 +#: sssd.conf.5.xml:1362 msgid "ENV" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1396 +#: sssd.conf.5.xml:1363 msgid "Do not send any environment variables to any service." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1399 +#: sssd.conf.5.xml:1366 msgid "ENV:var_name" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1400 +#: sssd.conf.5.xml:1367 msgid "Do not send environment variable var_name to any service." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1404 +#: sssd.conf.5.xml:1371 msgid "ENV:var_name:service" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1405 +#: sssd.conf.5.xml:1372 msgid "Do not send environment variable var_name to service." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1393 +#: sssd.conf.5.xml:1360 msgid "" "Currently the following filters are supported: <placeholder " "type=\"variablelist\" id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1412 +#: sssd.conf.5.xml:1379 msgid "" "The list of strings can either be the list of filters which would set this " "list of filters and overwrite the defaults. Or each element of the list can " @@ -1763,23 +1713,23 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1423 +#: sssd.conf.5.xml:1390 msgid "Default: ENV:KRB5CCNAME:sudo, ENV:KRB5CCNAME:sudo-i" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1426 +#: sssd.conf.5.xml:1393 msgid "" "Example: -ENV:KRB5CCNAME:sudo-i will remove the filter from the default list" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1433 +#: sssd.conf.5.xml:1400 msgid "pam_id_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1436 +#: sssd.conf.5.xml:1403 msgid "" "For any PAM request while SSSD is online, the SSSD will attempt to " "immediately update the cached identity information for the user in order to " @@ -1787,7 +1737,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1442 +#: sssd.conf.5.xml:1409 msgid "" "A complete PAM conversation may perform multiple PAM requests, such as " "account management and session opening. This option controls (on a per-" @@ -1796,17 +1746,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1456 +#: sssd.conf.5.xml:1423 msgid "pam_pwd_expiration_warning (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1459 sssd.conf.5.xml:2912 +#: sssd.conf.5.xml:1426 sssd.conf.5.xml:3037 msgid "Display a warning N days before the password expires." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1462 +#: sssd.conf.5.xml:1429 msgid "" "Please note that the backend server has to provide information about the " "expiration time of the password. If this information is missing, sssd " @@ -1814,32 +1764,32 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1468 sssd.conf.5.xml:2915 +#: sssd.conf.5.xml:1435 sssd.conf.5.xml:3040 msgid "" "If zero is set, then this filter is not applied, i.e. if the expiration " "warning was received from backend server, it will automatically be displayed." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1473 +#: sssd.conf.5.xml:1440 msgid "" "This setting can be overridden by setting <emphasis>pwd_expiration_warning</" "emphasis> for a particular domain." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1478 sssd.conf.5.xml:3913 sssd-ldap.5.xml:662 +#: sssd.conf.5.xml:1445 sssd.conf.5.xml:4118 sssd-ldap.5.xml:662 #: sssd-ldap.5.xml:1733 sssd.8.xml:79 msgid "Default: 0" msgstr "Dre ziouer : 0" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1495 +#: sssd.conf.5.xml:1462 msgid "pam_trusted_users (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1498 +#: sssd.conf.5.xml:1465 msgid "" "Specifies the comma-separated list of UID values or user names that are " "allowed to run PAM conversations against trusted domains. Users not " @@ -1849,74 +1799,74 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1508 +#: sssd.conf.5.xml:1475 msgid "Default: All users are considered trusted by default" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1512 +#: sssd.conf.5.xml:1479 msgid "" "Please note that UID 0 is always allowed to access the PAM responder even in " "case it is not in the pam_trusted_users list." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1519 +#: sssd.conf.5.xml:1486 msgid "pam_public_domains (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1522 +#: sssd.conf.5.xml:1489 msgid "" "Specifies the comma-separated list of domain names that are accessible even " "to untrusted users." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1526 +#: sssd.conf.5.xml:1493 msgid "Two special values for pam_public_domains option are defined:" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1530 +#: sssd.conf.5.xml:1497 msgid "" "all (Untrusted users are allowed to access all domains in PAM responder.)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1534 +#: sssd.conf.5.xml:1501 msgid "" "none (Untrusted users are not allowed to access any domains PAM in " "responder.)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1538 sssd.conf.5.xml:1563 sssd.conf.5.xml:1582 -#: sssd.conf.5.xml:1824 sssd.conf.5.xml:3842 sssd-ldap.5.xml:1270 +#: sssd.conf.5.xml:1505 sssd.conf.5.xml:1530 sssd.conf.5.xml:1549 +#: sssd.conf.5.xml:1821 sssd.conf.5.xml:4048 sssd-ldap.5.xml:1270 msgid "Default: none" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1543 +#: sssd.conf.5.xml:1510 msgid "pam_account_expired_message (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1546 +#: sssd.conf.5.xml:1513 msgid "" "Allows a custom expiration message to be set, replacing the default " "'Permission denied' message." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1551 +#: sssd.conf.5.xml:1518 msgid "" "Note: Please be aware that message is only printed for the SSH service " "unless pam_verbosity is set to 3 (show all messages and debug information)." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1559 +#: sssd.conf.5.xml:1526 #, no-wrap msgid "" "pam_account_expired_message = Account expired, please contact help desk.\n" @@ -1924,19 +1874,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1568 +#: sssd.conf.5.xml:1535 msgid "pam_account_locked_message (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1571 +#: sssd.conf.5.xml:1538 msgid "" "Allows a custom lockout message to be set, replacing the default 'Permission " "denied' message." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1578 +#: sssd.conf.5.xml:1545 #, no-wrap msgid "" "pam_account_locked_message = Account locked, please contact help desk.\n" @@ -1944,83 +1894,126 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1587 -msgid "pam_passkey_auth (bool)" +#: sssd.conf.5.xml:1554 +msgid "pam_passkey_auth (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1590 +#: sssd.conf.5.xml:1557 msgid "Enable passkey device based authentication." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1593 sssd.conf.5.xml:1910 sssd-ad.5.xml:1286 +#: sssd.conf.5.xml:1560 sssd.conf.5.xml:1907 sssd-ad.5.xml:1279 #: sss_rpcidmapd.5.xml:76 msgid "Default: True" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1598 -msgid "passkey_debug_libfido2 (bool)" -msgstr "" +#: sssd.conf.5.xml:1565 +#, fuzzy +#| msgid "re_expression (string)" +msgid "passkey_debug_libfido2 (boolean)" +msgstr "re_expression (neudennad)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1601 +#: sssd.conf.5.xml:1568 msgid "Enable libfido2 library debug messages." msgstr "" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1604 sssd.conf.5.xml:1618 sssd-ldap.5.xml:727 -#: sssd-ldap.5.xml:752 sssd-ldap.5.xml:848 sssd-ldap.5.xml:1356 -#: sssd-ad.5.xml:506 sssd-ad.5.xml:582 sssd-ad.5.xml:1155 +#: sssd.conf.5.xml:1571 sssd.conf.5.xml:1585 sssd.conf.5.xml:4781 +#: sssd-ldap.5.xml:727 sssd-ldap.5.xml:752 sssd-ldap.5.xml:848 +#: sssd-ldap.5.xml:1356 sssd-ad.5.xml:506 sssd-ad.5.xml:582 sssd-ad.5.xml:1160 #: include/ldap_id_mapping.xml:250 msgid "Default: False" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1609 -msgid "pam_cert_auth (bool)" -msgstr "" +#: sssd.conf.5.xml:1576 +#, fuzzy +#| msgid "re_expression (string)" +msgid "pam_cert_auth (boolean)" +msgstr "re_expression (neudennad)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1612 +#: sssd.conf.5.xml:1579 msgid "" "Enable certificate based Smartcard authentication. Since this requires " "additional communication with the Smartcard which will delay the " "authentication process this option is disabled by default." msgstr "" +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1588 +msgid "" +"Note: In case OpenSC is used for Smartcard access SSSD supports the " +"filesystem caching in OpenSC when enabled in opensc.conf. The cached files " +"are located in a common <quote>opensc</quote> directory in SSSD's state " +"directory. The behaviour can be changed in opensc.conf" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> +#: sssd.conf.5.xml:1597 +#, no-wrap +msgid "" +"app /usr/libexec/sssd/p11_child {\n" +" framework pkcs15 {\n" +" use_file_caching = no;\n" +" }\n" +"}\n" +"app /usr/libexec/sssd/krb5_child {\n" +" framework pkcs15 {\n" +" use_file_caching = no;\n" +" }\n" +"}\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1595 +msgid "" +"Example opensc.conf (*): <placeholder type=\"programlisting\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1610 +msgid "" +"(*) The actual <quote>libexec</quote> directory for p11_child and krb5_child " +"depends on the distribution." +msgstr "" + #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1623 +#: sssd.conf.5.xml:1615 msgid "pam_cert_db_path (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1626 +#: sssd.conf.5.xml:1618 msgid "The path to the certificate database." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1629 sssd.conf.5.xml:2163 sssd.conf.5.xml:4338 +#: sssd.conf.5.xml:1621 sssd.conf.5.xml:2199 sssd.conf.5.xml:4543 msgid "Default:" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1631 sssd.conf.5.xml:2165 +#: sssd.conf.5.xml:1623 sssd.conf.5.xml:2201 msgid "" "/etc/sssd/pki/sssd_auth_ca_db.pem (path to a file with trusted CA " "certificates in PEM format)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1641 +#: sssd.conf.5.xml:1633 #, fuzzy #| msgid "re_expression (string)" msgid "pam_cert_verification (string)" msgstr "re_expression (neudennad)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1644 +#: sssd.conf.5.xml:1636 msgid "" "With this parameter the PAM certificate verification can be tuned with a " "comma separated list of options that override the " @@ -2030,7 +2023,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1655 +#: sssd.conf.5.xml:1647 #, no-wrap msgid "" "pam_cert_verification = partial_chain\n" @@ -2038,61 +2031,61 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1659 +#: sssd.conf.5.xml:1651 msgid "" "Default: not set, i.e. use default <quote>certificate_verification</quote> " "option defined in <quote>[sssd]</quote> section." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1666 +#: sssd.conf.5.xml:1658 msgid "p11_child_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1669 +#: sssd.conf.5.xml:1661 msgid "How many seconds will pam_sss wait for p11_child to finish." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1678 +#: sssd.conf.5.xml:1670 msgid "passkey_child_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1681 +#: sssd.conf.5.xml:1673 msgid "" "How many seconds will the PAM responder wait for passkey_child to finish." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1690 +#: sssd.conf.5.xml:1682 msgid "pam_app_services (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1693 +#: sssd.conf.5.xml:1685 msgid "" "Which PAM services are permitted to contact domains of type " "<quote>application</quote>" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1702 +#: sssd.conf.5.xml:1694 #, fuzzy #| msgid "re_expression (string)" msgid "pam_p11_allowed_services (string)" msgstr "re_expression (neudennad)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1705 +#: sssd.conf.5.xml:1697 msgid "" "A comma-separated list of PAM service names for which it will be allowed to " "use Smartcards." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1720 +#: sssd.conf.5.xml:1712 #, no-wrap msgid "" "pam_p11_allowed_services = +my_pam_service, -login\n" @@ -2100,7 +2093,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1709 +#: sssd.conf.5.xml:1701 msgid "" "It is possible to add another PAM service name to the default set by using " "<quote>+service_name</quote> or to explicitly remove a PAM service name from " @@ -2112,68 +2105,73 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1724 sssd-ad.5.xml:645 sssd-ad.5.xml:754 sssd-ad.5.xml:812 -#: sssd-ad.5.xml:870 sssd-ad.5.xml:948 +#: sssd.conf.5.xml:1716 sssd-ad.5.xml:645 sssd-ad.5.xml:759 sssd-ad.5.xml:817 +#: sssd-ad.5.xml:875 sssd-ad.5.xml:953 msgid "Default: the default set of PAM service names includes:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1729 sssd-ad.5.xml:649 +#: sssd.conf.5.xml:1721 sssd-ad.5.xml:649 msgid "login" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1734 sssd-ad.5.xml:654 +#: sssd.conf.5.xml:1726 sssd-ad.5.xml:654 msgid "su" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1739 sssd-ad.5.xml:659 +#: sssd.conf.5.xml:1731 sssd-ad.5.xml:659 msgid "su-l" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1744 sssd-ad.5.xml:674 +#: sssd.conf.5.xml:1736 sssd-ad.5.xml:674 msgid "gdm-smartcard" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1749 sssd-ad.5.xml:669 +#: sssd.conf.5.xml:1741 sssd-ad.5.xml:669 msgid "gdm-password" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1754 +#: sssd.conf.5.xml:1746 msgid "gdm-switchable-auth" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1759 sssd-ad.5.xml:679 +#: sssd.conf.5.xml:1751 sssd-ad.5.xml:679 msgid "kdm" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1764 sssd-ad.5.xml:957 +#: sssd.conf.5.xml:1756 sssd-ad.5.xml:694 +msgid "plasmalogin" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:1761 sssd-ad.5.xml:962 msgid "sudo" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1769 sssd-ad.5.xml:962 +#: sssd.conf.5.xml:1766 sssd-ad.5.xml:967 msgid "sudo-i" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1774 +#: sssd.conf.5.xml:1771 msgid "gnome-screensaver" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1782 +#: sssd.conf.5.xml:1779 msgid "p11_wait_for_card_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1785 +#: sssd.conf.5.xml:1782 msgid "" "If Smartcard authentication is required how many extra seconds in addition " "to p11_child_timeout should the PAM responder wait until a Smartcard is " @@ -2181,12 +2179,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1796 +#: sssd.conf.5.xml:1793 msgid "p11_uri (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1799 +#: sssd.conf.5.xml:1796 msgid "" "PKCS#11 URI (see RFC-7512 for details) which can be used to restrict the " "selection of devices used for Smartcard authentication. By default SSSD's " @@ -2197,7 +2195,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1812 +#: sssd.conf.5.xml:1809 #, no-wrap msgid "" "p11_uri = pkcs11:slot-description=My%20Smartcard%20Reader\n" @@ -2205,7 +2203,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1816 +#: sssd.conf.5.xml:1813 #, no-wrap msgid "" "p11_uri = pkcs11:library-description=OpenSC%20smartcard%20framework;slot-id=2\n" @@ -2213,7 +2211,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1810 +#: sssd.conf.5.xml:1807 msgid "" "Example: <placeholder type=\"programlisting\" id=\"0\"/> or <placeholder " "type=\"programlisting\" id=\"1\"/> To find suitable URI please check the " @@ -2222,47 +2220,49 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1829 -msgid "pam_initgroups_scheme" -msgstr "" +#: sssd.conf.5.xml:1826 +#, fuzzy +#| msgid "re_expression (string)" +msgid "pam_initgroups_scheme (string)" +msgstr "re_expression (neudennad)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1837 +#: sssd.conf.5.xml:1834 msgid "always" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1838 +#: sssd.conf.5.xml:1835 msgid "" "Always do an online lookup, please note that pam_id_timeout still applies" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1842 +#: sssd.conf.5.xml:1839 msgid "no_session" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1843 +#: sssd.conf.5.xml:1840 msgid "" "Only do an online lookup if there is no active session of the user, i.e. if " "the user is currently not logged in" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1848 sssd-ldap.5.xml:189 +#: sssd.conf.5.xml:1845 sssd-ldap.5.xml:189 msgid "never" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1849 +#: sssd.conf.5.xml:1846 msgid "" "Never force an online lookup, use the data from the cache as long as they " "are not expired" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1832 +#: sssd.conf.5.xml:1829 msgid "" "The PAM responder can force an online lookup to get the current group " "memberships of the user trying to log in. This option controls when this " @@ -2271,30 +2271,32 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1856 +#: sssd.conf.5.xml:1853 msgid "Default: no_session" msgstr "" -#. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:1861 sssd.conf.5.xml:4277 -msgid "pam_gssapi_services" -msgstr "" +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1858 +#, fuzzy +#| msgid "re_expression (string)" +msgid "pam_gssapi_services (string)" +msgstr "re_expression (neudennad)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1864 +#: sssd.conf.5.xml:1861 msgid "" "Comma separated list of PAM services that are allowed to try GSSAPI " "authentication using pam_sss_gss.so module." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1869 +#: sssd.conf.5.xml:1866 msgid "" "To disable GSSAPI authentication, set this option to <quote>-</quote> (dash)." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1873 sssd.conf.5.xml:1904 sssd.conf.5.xml:1942 +#: sssd.conf.5.xml:1870 sssd.conf.5.xml:1901 sssd.conf.5.xml:1939 msgid "" "Note: This option can also be set per-domain which overwrites the value in " "[pam] section. It can also be set for trusted domain which overwrites the " @@ -2302,7 +2304,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1881 +#: sssd.conf.5.xml:1878 #, no-wrap msgid "" "pam_gssapi_services = sudo, sudo-i\n" @@ -2310,22 +2312,22 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1879 sssd.conf.5.xml:1994 sssd.conf.5.xml:3836 +#: sssd.conf.5.xml:1876 sssd.conf.5.xml:2023 sssd.conf.5.xml:4042 msgid "Example: <placeholder type=\"programlisting\" id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1885 +#: sssd.conf.5.xml:1882 msgid "Default: - (GSSAPI authentication is disabled)" msgstr "" -#. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:1890 sssd.conf.5.xml:4278 -msgid "pam_gssapi_check_upn" +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1887 +msgid "pam_gssapi_check_upn (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1893 +#: sssd.conf.5.xml:1890 msgid "" "If True, SSSD will require that the Kerberos user principal that " "successfully authenticated through GSSAPI can be associated with the user " @@ -2333,19 +2335,21 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1900 +#: sssd.conf.5.xml:1897 msgid "" -"If False, every user that is able to obtained required service ticket will " +"If False, every user that is able to obtain a required service ticket will " "be authenticated." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1915 -msgid "pam_gssapi_indicators_map" -msgstr "" +#: sssd.conf.5.xml:1912 +#, fuzzy +#| msgid "re_expression (string)" +msgid "pam_gssapi_indicators_map (string)" +msgstr "re_expression (neudennad)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1918 +#: sssd.conf.5.xml:1915 msgid "" "Comma separated list of authentication indicators required to be present in " "a Kerberos ticket to access a PAM service that is allowed to try GSSAPI " @@ -2353,7 +2357,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1924 +#: sssd.conf.5.xml:1921 msgid "" "Each element of the list can be either an authentication indicator name or a " "pair <quote>service:indicator</quote>. Indicators not prefixed with the PAM " @@ -2368,7 +2372,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1937 +#: sssd.conf.5.xml:1934 msgid "" "To disable GSSAPI authentication indicator check, set this option to <quote>-" "</quote> (dash). To disable the check for a specific PAM service, add " @@ -2376,45 +2380,45 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1948 +#: sssd.conf.5.xml:1945 msgid "" "Following authentication indicators are supported by IPA Kerberos " "deployments:" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1951 +#: sssd.conf.5.xml:1948 msgid "" "pkinit -- pre-authentication using X.509 certificates -- whether stored in " "files or on smart cards." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1954 +#: sssd.conf.5.xml:1951 msgid "" "hardened -- SPAKE pre-authentication or any pre-authentication wrapped in a " "FAST channel." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1957 +#: sssd.conf.5.xml:1954 msgid "radius -- pre-authentication with the help of a RADIUS server." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1960 +#: sssd.conf.5.xml:1957 msgid "" "otp -- pre-authentication using integrated two-factor authentication (2FA or " "one-time password, OTP) in IPA." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1963 +#: sssd.conf.5.xml:1960 msgid "idp -- pre-authentication using external identity provider." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1973 +#: sssd.conf.5.xml:1970 #, no-wrap msgid "" "pam_gssapi_indicators_map = sudo:pkinit, sudo-i:pkinit\n" @@ -2422,7 +2426,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1968 +#: sssd.conf.5.xml:1965 msgid "" "Example: to require access to SUDO services only for users which obtained " "their Kerberos tickets with a X.509 certificate pre-authentication (PKINIT), " @@ -2430,31 +2434,72 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1977 +#: sssd.conf.5.xml:1974 msgid "Default: not set (use of authentication indicators is not required)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1979 +#, fuzzy +#| msgid "re_expression (string)" +msgid "pam_gssapi_indicators_apply (string)" +msgstr "re_expression (neudennad)" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1982 +msgid "" +"Comma separated list of triples to assign additional information from the " +"Kerberos ticket, e.g. a SID from the PAC, to authentication indicators." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1988 +msgid "Currently supported is:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:1991 +msgid "SID:S-1-5-[domain]-[RID]:[authentication indicator]" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> +#: sssd.conf.5.xml:2002 +#, no-wrap +msgid "" +"pam_gssapi_indicators_apply = SID:S-1-5-12345-23456-34567-4321:pkinit\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1996 +msgid "" +"Example: To assign a SID, which is e.g. set by Active Directory's " +"Authentication Mechanism Assurance (AMA) if the AD user used a Smartcard for " +"authentication, to the 'pkinit' authentication indicator use: <placeholder " +"type=\"programlisting\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2011 #, fuzzy #| msgid "re_expression (string)" msgid "pam_json_services (string)" msgstr "re_expression (neudennad)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1985 +#: sssd.conf.5.xml:2014 msgid "" "Comma separated list of PAM services which can handle the JSON protocol for " "selecting authentication mechanisms" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1990 +#: sssd.conf.5.xml:2019 msgid "To disable JSON protocol, set this option to <quote>-</quote> (dash)." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1996 +#: sssd.conf.5.xml:2025 #, no-wrap msgid "" "pam_json_services = gdm-switchable-auth\n" @@ -2462,52 +2507,59 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2000 +#: sssd.conf.5.xml:2029 msgid "Default: - (JSON protocol is disabled)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2003 +#: sssd.conf.5.xml:2032 msgid "" "Note: 2-Factor Authentication (2FA) is not supported. If 2FA is required, do " "not activate the JSON protocol." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:2013 +#: sssd.conf.5.xml:2042 msgid "SUDO configuration options" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2015 +#: sssd.conf.5.xml:2044 msgid "" -"These options can be used to configure the sudo service. The detailed " -"instructions for configuration of <citerefentry> <refentrytitle>sudo</" -"refentrytitle> <manvolnum>8</manvolnum> </citerefentry> to work with " -"<citerefentry> <refentrytitle>sssd</refentrytitle> <manvolnum>8</manvolnum> " -"</citerefentry> are in the manual page <citerefentry> <refentrytitle>sssd-" -"sudo</refentrytitle> <manvolnum>5</manvolnum> </citerefentry>." +"These options can be used to configure the sudo service and should be " +"specified under the <quote>[sudo]</quote> section." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:2048 +msgid "" +"The detailed instructions for configuration of <citerefentry> " +"<refentrytitle>sudo</refentrytitle> <manvolnum>8</manvolnum> </citerefentry> " +"to work with <citerefentry> <refentrytitle>sssd</refentrytitle> " +"<manvolnum>8</manvolnum> </citerefentry> are in the manual page " +"<citerefentry> <refentrytitle>sssd-sudo</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry>." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2032 -msgid "sudo_timed (bool)" +#: sssd.conf.5.xml:2064 +msgid "sudo_timed (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2035 +#: sssd.conf.5.xml:2067 msgid "" "Whether or not to evaluate the sudoNotBefore and sudoNotAfter attributes " "that implement time-dependent sudoers entries." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2047 +#: sssd.conf.5.xml:2079 msgid "sudo_threshold (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2050 +#: sssd.conf.5.xml:2082 msgid "" "Maximum number of expired rules that can be refreshed at once. If number of " "expired rules is below threshold, those rules are refreshed with " @@ -2517,22 +2569,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:2069 +#: sssd.conf.5.xml:2101 msgid "AUTOFS configuration options" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2071 -msgid "These options can be used to configure the autofs service." +#: sssd.conf.5.xml:2103 +msgid "" +"These options can be used to configure the autofs service and should be " +"specified under the <quote>[autofs]</quote> section." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2075 +#: sssd.conf.5.xml:2109 msgid "autofs_negative_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2078 +#: sssd.conf.5.xml:2112 msgid "" "Specifies for how many seconds should the autofs responder negative cache " "hits (that is, queries for invalid map entries, like nonexistent ones) " @@ -2540,22 +2594,26 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:2094 +#: sssd.conf.5.xml:2128 msgid "SSH configuration options" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2096 -msgid "These options can be used to configure the SSH service." +#: sssd.conf.5.xml:2130 +msgid "" +"These options can be used to configure the SSH service and should be " +"specified under the <quote>[ssh]</quote> section." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2100 -msgid "ssh_use_certificate_keys (bool)" -msgstr "" +#: sssd.conf.5.xml:2136 +#, fuzzy +#| msgid "re_expression (string)" +msgid "ssh_use_certificate_keys (boolean)" +msgstr "re_expression (neudennad)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2103 +#: sssd.conf.5.xml:2139 msgid "" "If set to true the <command>sss_ssh_authorizedkeys</command> will return ssh " "keys derived from the public key of X.509 certificates stored in the user " @@ -2564,12 +2622,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2118 +#: sssd.conf.5.xml:2154 msgid "ssh_use_certificate_matching_rules (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2121 +#: sssd.conf.5.xml:2157 msgid "" "By default the ssh responder will use all available certificate matching " "rules to filter the certificates so that ssh keys are only derived from the " @@ -2579,7 +2637,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2130 +#: sssd.conf.5.xml:2166 msgid "" "There are two special key words 'all_rules' and 'no_rules' which will enable " "all or no rules, respectively. The latter means that no certificates will be " @@ -2587,7 +2645,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2137 +#: sssd.conf.5.xml:2173 msgid "" "If no rules are configured using 'all_rules' will enable a default rule " "which enables all certificates suitable for client authentication. This is " @@ -2596,38 +2654,38 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2144 +#: sssd.conf.5.xml:2180 msgid "" "A non-existing rule name is considered an error. If as a result no rule is " "selected all certificates will be ignored." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2149 +#: sssd.conf.5.xml:2185 msgid "" "Default: not set, equivalent to 'all_rules', all found rules or the default " "rule are used" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2155 +#: sssd.conf.5.xml:2191 msgid "ca_db (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2158 +#: sssd.conf.5.xml:2194 msgid "" "Path to a storage of trusted CA certificates. The option is used to validate " "user certificates before deriving public ssh keys from them." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:2178 +#: sssd.conf.5.xml:2214 msgid "PAC responder configuration options" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2180 +#: sssd.conf.5.xml:2216 msgid "" "The PAC responder works together with the authorization data plugin for MIT " "Kerberos sssd_pac_plugin.so and a sub-domain provider. The plugin sends the " @@ -2638,7 +2696,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:2189 +#: sssd.conf.5.xml:2225 msgid "" "If the remote user does not exist in the cache, it is created. The UID is " "determined with the help of the SID, trusted domains will have UPGs and the " @@ -2649,24 +2707,26 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:2197 +#: sssd.conf.5.xml:2233 msgid "" "If there are SIDs of groups from domains sssd knows about, the user will be " "added to those groups." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2203 -msgid "These options can be used to configure the PAC responder." +#: sssd.conf.5.xml:2239 +msgid "" +"These options can be used to configure the PAC responder and should be " +"specified under the <quote>[pac]</quote> section." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2207 sssd-ifp.5.xml:66 +#: sssd.conf.5.xml:2244 sssd-ifp.5.xml:66 msgid "allowed_uids (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2210 +#: sssd.conf.5.xml:2247 msgid "" "Specifies the comma-separated list of UID values or user names that are " "allowed to access the PAC responder. User names are resolved to UIDs at " @@ -2674,19 +2734,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2216 +#: sssd.conf.5.xml:2253 msgid "" "Default: 0, &sssd_user_name; (only root and SSSD service users are allowed " "to access the PAC responder)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2220 +#: sssd.conf.5.xml:2257 msgid "Default: 0 (only the root user is allowed to access the PAC responder)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2224 +#: sssd.conf.5.xml:2261 msgid "" "Please note that defaults will be overwritten with this option. If you still " "want to allow the root and/or '&sssd_user_name;' user to access the PAC " @@ -2695,7 +2755,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2231 +#: sssd.conf.5.xml:2268 msgid "" "Please note that although the UID 0 is used as the default it will be " "overwritten with this option. If you still want to allow the root user to " @@ -2704,26 +2764,26 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2240 +#: sssd.conf.5.xml:2277 msgid "pac_lifetime (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2243 +#: sssd.conf.5.xml:2280 msgid "" "Lifetime of the PAC entry in seconds. As long as the PAC is valid the PAC " "data can be used to determine the group memberships of a user." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2253 +#: sssd.conf.5.xml:2290 #, fuzzy #| msgid "re_expression (string)" msgid "pac_check (string)" msgstr "re_expression (neudennad)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2256 +#: sssd.conf.5.xml:2293 msgid "" "Apply additional checks on the PAC of the Kerberos ticket which is available " "in Active Directory and FreeIPA domains, if configured. Please note that " @@ -2734,7 +2794,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2266 +#: sssd.conf.5.xml:2303 msgid "" "Please note that the checks listed below only apply to PACs issued by Active " "Directory or recent versions of FreeIPA. PACs issued e.g. by a plain MIT " @@ -2742,24 +2802,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2277 +#: sssd.conf.5.xml:2314 msgid "no_check" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2279 +#: sssd.conf.5.xml:2316 msgid "" "The PAC must not be present and even if it is present no additional checks " "will be done." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2285 +#: sssd.conf.5.xml:2322 msgid "pac_present" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2287 +#: sssd.conf.5.xml:2324 msgid "" "The PAC must be present in the service ticket which SSSD will request with " "the help of the user's TGT. If the PAC is not available the authentication " @@ -2767,24 +2827,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2295 +#: sssd.conf.5.xml:2332 msgid "check_upn" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2297 +#: sssd.conf.5.xml:2334 msgid "" "If the PAC is present check if the user principal name (UPN) information is " "consistent." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2303 +#: sssd.conf.5.xml:2340 msgid "check_upn_allow_missing" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2305 +#: sssd.conf.5.xml:2342 msgid "" "This option should be used together with 'check_upn' and handles the case " "where a UPN is set on the server-side but is not read by SSSD. The typical " @@ -2796,7 +2856,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2317 +#: sssd.conf.5.xml:2354 msgid "" "Currently this option is set by default to avoid regressions in such " "environments. A log message will be added to the system log and SSSD's debug " @@ -2807,60 +2867,60 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2331 +#: sssd.conf.5.xml:2368 msgid "upn_dns_info_present" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2333 +#: sssd.conf.5.xml:2370 msgid "The PAC must contain the UPN-DNS-INFO buffer, implies 'check_upn'." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2338 +#: sssd.conf.5.xml:2375 msgid "check_upn_dns_info_ex" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2340 +#: sssd.conf.5.xml:2377 msgid "" "If the PAC is present and the extension to the UPN-DNS-INFO buffer is " "available check if the information in the extension is consistent." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2347 +#: sssd.conf.5.xml:2384 msgid "upn_dns_info_ex_present" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2349 +#: sssd.conf.5.xml:2386 msgid "" "The PAC must contain the extension of the UPN-DNS-INFO buffer, implies " "'check_upn_dns_info_ex', 'upn_dns_info_present' and 'check_upn'." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2273 +#: sssd.conf.5.xml:2310 msgid "" "The following options can be used alone or in a comma-separated list: " "<placeholder type=\"variablelist\" id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2359 +#: sssd.conf.5.xml:2396 msgid "" "Default: no_check (AD and IPA provider 'check_upn, check_upn_allow_missing, " "check_upn_dns_info_ex')" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:2368 +#: sssd.conf.5.xml:2405 msgid "Session recording configuration options" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2370 +#: sssd.conf.5.xml:2407 msgid "" "Session recording works in conjunction with <citerefentry> " "<refentrytitle>tlog-rec-session</refentrytitle> <manvolnum>8</manvolnum> </" @@ -2870,66 +2930,78 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2383 -msgid "These options can be used to configure session recording." +#: sssd.conf.5.xml:2420 +msgid "" +"These options can be used to configure session recording and should be " +"specified under the <quote>[session_recording]</quote> section." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:2425 +msgid "" +"Note: Unlike other sections, the <quote>[session_recording]</quote> section " +"ignores <replaceable>debug*</replaceable> options and suitable " +"<replaceable>debug*</replaceable> options must be set in <quote>[pam]</" +"quote>, <quote>[nss]</quote> and <quote>[domain/<replaceable>NAME</" +"replaceable>]</quote> sections." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2387 sssd-session-recording.5.xml:64 +#: sssd.conf.5.xml:2433 sssd-session-recording.5.xml:64 msgid "scope (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2394 sssd-session-recording.5.xml:71 +#: sssd.conf.5.xml:2440 sssd-session-recording.5.xml:71 msgid "\"none\"" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2397 sssd-session-recording.5.xml:74 +#: sssd.conf.5.xml:2443 sssd-session-recording.5.xml:74 msgid "No users are recorded." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2402 sssd-session-recording.5.xml:79 +#: sssd.conf.5.xml:2448 sssd-session-recording.5.xml:79 msgid "\"some\"" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2405 sssd-session-recording.5.xml:82 +#: sssd.conf.5.xml:2451 sssd-session-recording.5.xml:82 msgid "" "Users/groups specified by <replaceable>users</replaceable> and " "<replaceable>groups</replaceable> options are recorded." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2414 sssd-session-recording.5.xml:91 +#: sssd.conf.5.xml:2460 sssd-session-recording.5.xml:91 msgid "\"all\"" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2417 sssd-session-recording.5.xml:94 +#: sssd.conf.5.xml:2463 sssd-session-recording.5.xml:94 msgid "All users are recorded." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2390 sssd-session-recording.5.xml:67 +#: sssd.conf.5.xml:2436 sssd-session-recording.5.xml:67 msgid "" "One of the following strings specifying the scope of session recording: " "<placeholder type=\"variablelist\" id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2424 sssd-session-recording.5.xml:101 +#: sssd.conf.5.xml:2470 sssd-session-recording.5.xml:101 msgid "Default: \"none\"" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2429 sssd-session-recording.5.xml:106 +#: sssd.conf.5.xml:2475 sssd-session-recording.5.xml:106 msgid "users (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2432 sssd-session-recording.5.xml:109 +#: sssd.conf.5.xml:2478 sssd-session-recording.5.xml:109 msgid "" "A comma-separated list of users which should have session recording enabled. " "Matches user names as returned by NSS. I.e. after the possible space " @@ -2937,17 +3009,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2438 sssd-session-recording.5.xml:115 +#: sssd.conf.5.xml:2484 sssd-session-recording.5.xml:115 msgid "Default: Empty. Matches no users." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2443 sssd-session-recording.5.xml:120 +#: sssd.conf.5.xml:2489 sssd-session-recording.5.xml:120 msgid "groups (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2446 sssd-session-recording.5.xml:123 +#: sssd.conf.5.xml:2492 sssd-session-recording.5.xml:123 msgid "" "A comma-separated list of groups, members of which should have session " "recording enabled. Matches group names as returned by NSS. I.e. after the " @@ -2955,7 +3027,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2452 sssd.conf.5.xml:2484 sssd-session-recording.5.xml:129 +#: sssd.conf.5.xml:2498 sssd.conf.5.xml:2530 sssd-session-recording.5.xml:129 #: sssd-session-recording.5.xml:161 msgid "" "NOTE: using this option (having it set to anything) has a considerable " @@ -2964,61 +3036,60 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2459 sssd-session-recording.5.xml:136 +#: sssd.conf.5.xml:2505 sssd-session-recording.5.xml:136 msgid "Default: Empty. Matches no groups." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2464 sssd-session-recording.5.xml:141 +#: sssd.conf.5.xml:2510 sssd-session-recording.5.xml:141 #, fuzzy #| msgid "re_expression (string)" msgid "exclude_users (string)" msgstr "re_expression (neudennad)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2467 sssd-session-recording.5.xml:144 +#: sssd.conf.5.xml:2513 sssd-session-recording.5.xml:144 msgid "" "A comma-separated list of users to be excluded from recording, only " "applicable with 'scope=all'." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2471 sssd-session-recording.5.xml:148 +#: sssd.conf.5.xml:2517 sssd-session-recording.5.xml:148 msgid "Default: Empty. No users excluded." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2476 sssd-session-recording.5.xml:153 +#: sssd.conf.5.xml:2522 sssd-session-recording.5.xml:153 #, fuzzy #| msgid "filter_users, filter_groups (string)" msgid "exclude_groups (string)" msgstr "filter_users, filter_groups (neudennad)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2479 sssd-session-recording.5.xml:156 +#: sssd.conf.5.xml:2525 sssd-session-recording.5.xml:156 msgid "" "A comma-separated list of groups, members of which should be excluded from " "recording. Only applicable with 'scope=all'." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2491 sssd-session-recording.5.xml:168 +#: sssd.conf.5.xml:2537 sssd-session-recording.5.xml:168 msgid "Default: Empty. No groups excluded." msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:2501 +#: sssd.conf.5.xml:2547 msgid "DOMAIN SECTIONS" msgstr "RANNOÙ DOMANI" -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry><para> -#: sssd.conf.5.xml:2508 sssd.conf.5.xml:3964 sssd.conf.5.xml:3965 -#: sssd.conf.5.xml:3968 -msgid "enabled" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2554 +msgid "enabled (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2511 +#: sssd.conf.5.xml:2557 msgid "" "Explicitly enable or disable the domain. If <quote>true</quote>, the domain " "is always <quote>enabled</quote>. If <quote>false</quote>, the domain is " @@ -3028,12 +3099,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2523 +#: sssd.conf.5.xml:2569 msgid "domain_type (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2526 +#: sssd.conf.5.xml:2572 msgid "" "Specifies whether the domain is meant to be used by POSIX-aware clients such " "as the Name Service Switch or by applications that do not need POSIX data to " @@ -3042,14 +3113,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2534 +#: sssd.conf.5.xml:2580 msgid "" "Allowed values for this option are <quote>posix</quote> and " "<quote>application</quote>." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2538 +#: sssd.conf.5.xml:2584 msgid "" "POSIX domains are reachable by all services. Application domains are only " "reachable from the InfoPipe responder (see <citerefentry> " @@ -3058,38 +3129,38 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2546 +#: sssd.conf.5.xml:2592 msgid "" "NOTE: The application domains are currently well tested with " "<quote>id_provider=ldap</quote> only." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2550 +#: sssd.conf.5.xml:2596 msgid "" "For an easy way to configure a non-POSIX domains, please see the " "<quote>Application domains</quote> section." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2554 +#: sssd.conf.5.xml:2600 msgid "Default: posix" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2560 +#: sssd.conf.5.xml:2606 msgid "min_id,max_id (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2563 +#: sssd.conf.5.xml:2609 msgid "" "UID and GID limits for the domain. If a domain contains an entry that is " "outside these limits, it is ignored." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2568 +#: sssd.conf.5.xml:2614 msgid "" "For users, this affects the primary GID limit. The user will not be returned " "to NSS if either the UID or the primary GID is outside the range. For non-" @@ -3098,24 +3169,26 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2575 +#: sssd.conf.5.xml:2621 msgid "" "These ID limits affect even saving entries to cache, not only returning them " "by name or ID." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2579 +#: sssd.conf.5.xml:2625 msgid "Default: 1 for min_id, 0 (no limit) for max_id" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2585 -msgid "enumerate (bool)" -msgstr "" +#: sssd.conf.5.xml:2631 +#, fuzzy +#| msgid "re_expression (string)" +msgid "enumerate (boolean)" +msgstr "re_expression (neudennad)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2588 +#: sssd.conf.5.xml:2634 msgid "" "Determines if a domain can be enumerated, that is, whether the domain can " "list all the users and group it contains. Note that it is not required to " @@ -3124,36 +3197,36 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2596 +#: sssd.conf.5.xml:2642 msgid "TRUE = Users and groups are enumerated" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2599 +#: sssd.conf.5.xml:2645 msgid "FALSE = No enumerations for this domain" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2602 sssd.conf.5.xml:2867 sssd.conf.5.xml:3044 +#: sssd.conf.5.xml:2648 sssd.conf.5.xml:2992 sssd.conf.5.xml:3174 msgid "Default: FALSE" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2605 +#: sssd.conf.5.xml:2651 msgid "" "Enumerating a domain requires SSSD to download and store ALL user and group " "entries from the remote server." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2610 +#: sssd.conf.5.xml:2656 msgid "" "Feature is only supported for domains with id_provider = ldap or id_provider " "= proxy." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2614 +#: sssd.conf.5.xml:2660 msgid "" "Note: Enabling enumeration has a severe performance impact on SSSD while " "enumeration is running. It may take up to several minutes after SSSD startup " @@ -3167,14 +3240,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2629 +#: sssd.conf.5.xml:2675 msgid "" "While the first enumeration is running, requests for the complete user or " "group lists may return no results until it completes." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2634 +#: sssd.conf.5.xml:2680 msgid "" "Further, enabling enumeration may increase the time necessary to detect " "network disconnection, as longer timeouts are required to ensure that " @@ -3183,14 +3256,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2642 +#: sssd.conf.5.xml:2688 msgid "" "For the reasons cited above, enabling enumeration is not recommended, " "especially in large environments." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2647 +#: sssd.conf.5.xml:2693 msgid "" "Note: the proxy provider is tested with open source modules like " "'libnss_files' and 'libnss_ldap'. 3rd party modules must follow the " @@ -3198,19 +3271,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2656 +#: sssd.conf.5.xml:2702 msgid "entry_cache_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2659 +#: sssd.conf.5.xml:2705 msgid "" "How many seconds should nss_sss consider entries valid before asking the " "backend again" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2663 +#: sssd.conf.5.xml:2709 msgid "" "The cache expiration timestamps are stored as attributes of individual " "objects in the cache. Therefore, changing the cache timeout only has effect " @@ -3221,139 +3294,248 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2676 +#: sssd.conf.5.xml:2722 msgid "Default: 5400" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2682 +#: sssd.conf.5.xml:2728 msgid "entry_cache_user_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2685 +#: sssd.conf.5.xml:2731 msgid "" "How many seconds should nss_sss consider user entries valid before asking " "the backend again" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2689 sssd.conf.5.xml:2702 sssd.conf.5.xml:2715 -#: sssd.conf.5.xml:2728 sssd.conf.5.xml:2742 sssd.conf.5.xml:2755 -#: sssd.conf.5.xml:2769 sssd.conf.5.xml:2783 sssd.conf.5.xml:2796 +#: sssd.conf.5.xml:2735 sssd.conf.5.xml:2748 sssd.conf.5.xml:2761 +#: sssd.conf.5.xml:2774 sssd.conf.5.xml:2788 sssd.conf.5.xml:2801 +#: sssd.conf.5.xml:2815 sssd.conf.5.xml:2829 msgid "Default: entry_cache_timeout" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2695 +#: sssd.conf.5.xml:2741 msgid "entry_cache_group_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2698 +#: sssd.conf.5.xml:2744 msgid "" "How many seconds should nss_sss consider group entries valid before asking " "the backend again" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2708 +#: sssd.conf.5.xml:2754 msgid "entry_cache_netgroup_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2711 +#: sssd.conf.5.xml:2757 msgid "" "How many seconds should nss_sss consider netgroup entries valid before " "asking the backend again" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2721 +#: sssd.conf.5.xml:2767 msgid "entry_cache_service_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2724 +#: sssd.conf.5.xml:2770 msgid "" "How many seconds should nss_sss consider service entries valid before asking " "the backend again" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2734 +#: sssd.conf.5.xml:2780 msgid "entry_cache_resolver_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2737 +#: sssd.conf.5.xml:2783 msgid "" "How many seconds should nss_sss consider hosts and networks entries valid " "before asking the backend again" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2748 +#: sssd.conf.5.xml:2794 msgid "entry_cache_sudo_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2751 +#: sssd.conf.5.xml:2797 msgid "" "How many seconds should sudo consider rules valid before asking the backend " "again" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2761 +#: sssd.conf.5.xml:2807 msgid "entry_cache_autofs_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2764 +#: sssd.conf.5.xml:2810 msgid "" "How many seconds should the autofs service consider automounter maps valid " "before asking the backend again" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2775 +#: sssd.conf.5.xml:2821 msgid "entry_cache_ssh_host_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2778 +#: sssd.conf.5.xml:2824 msgid "" "How many seconds to keep a host ssh key after refresh. IE how long to cache " "the host key for." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2789 -msgid "entry_cache_computer_timeout (integer)" +#: sssd.conf.5.xml:2835 +msgid "offline_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2792 +#: sssd.conf.5.xml:2838 msgid "" -"How many seconds to keep the local computer entry before asking the backend " -"again" +"When SSSD switches to offline mode the amount of time before it tries to go " +"back online will increase based upon the time spent disconnected. By " +"default SSSD uses incremental behaviour to calculate delay in between " +"retries. So, the wait time for a given retry will be longer than the wait " +"time for the previous ones. After each unsuccessful attempt to go online, " +"the new interval is recalculated by the following:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2849 sssd.conf.5.xml:2907 +msgid "" +"new_delay = Minimum(old_delay * 2, offline_timeout_max) + " +"random[0...offline_timeout_random_offset]" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2852 +msgid "" +"The offline_timeout default value is 60. The offline_timeout_max default " +"value is 3600. The offline_timeout_random_offset default value is 30. The " +"end result is the number of seconds before next retry." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2858 +msgid "" +"Note that the maximum length of each interval is defined by " +"offline_timeout_max (apart from the random part)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2868 +msgid "offline_timeout_max (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2871 +msgid "" +"Controls by how much the time between attempts to go online can be " +"incremented following unsuccessful attempts to go online." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2876 +msgid "A value of 0 disables the incrementing behaviour." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2879 +msgid "" +"The value of this parameter should be set in correlation to offline_timeout " +"parameter value." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2883 +msgid "" +"With offline_timeout set to 60 (default value) there is no point in setting " +"offline_timeout_max to less than 120 as it will saturate instantly. General " +"rule here should be to set offline_timeout_max to at least 4 times " +"offline_timeout." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2889 +msgid "" +"Although a value between 0 and offline_timeout may be specified, it has the " +"effect of overriding the offline_timeout value so is of little use." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2894 +#, fuzzy +#| msgid "Default: 3" +msgid "Default: 3600" +msgstr "Dre ziouer : 3" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2900 +msgid "offline_timeout_random_offset (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2903 +msgid "" +"When SSSD is in offline mode it keeps probing backend servers in specified " +"time intervals:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2910 +msgid "" +"This parameter controls the value of the random offset used for the above " +"equation. Final random_offset value will be random number in range:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2915 +msgid "[0 - offline_timeout_random_offset]" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2918 +msgid "A value of 0 disables the random offset addition." msgstr "" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2921 +#, fuzzy +#| msgid "Default: 3" +msgid "Default: 30" +msgstr "Dre ziouer : 3" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2802 +#: sssd.conf.5.xml:2927 msgid "refresh_expired_interval (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2805 +#: sssd.conf.5.xml:2930 msgid "" "Specifies how many seconds SSSD has to wait before triggering a background " "refresh task which will refresh all expired or nearly expired records." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2810 +#: sssd.conf.5.xml:2935 msgid "" "The background refresh will process users, groups and netgroups in the " "cache. For users who have performed the initgroups (get group membership for " @@ -3362,17 +3544,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2818 +#: sssd.conf.5.xml:2943 msgid "This option is automatically inherited for all trusted domains." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2822 +#: sssd.conf.5.xml:2947 msgid "You can consider setting this value to 3/4 * entry_cache_timeout." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2826 +#: sssd.conf.5.xml:2951 msgid "" "Cache entry will be refreshed by background task when 2/3 of cache timeout " "has already passed. If there are existing cached entries, the background " @@ -3384,18 +3566,18 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2839 sssd-ldap.5.xml:406 sssd-ldap.5.xml:1834 -#: sssd-ipa.5.xml:255 +#: sssd.conf.5.xml:2964 sssd-ldap.5.xml:406 sssd-ldap.5.xml:1834 +#: sssd-ipa.5.xml:250 msgid "Default: 0 (disabled)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2845 -msgid "cache_credentials (bool)" +#: sssd.conf.5.xml:2970 +msgid "cache_credentials (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2848 +#: sssd.conf.5.xml:2973 msgid "" "Determines if user credentials are also cached in the local LDB cache. The " "cached credentials refer to passwords, which includes the first (long term) " @@ -3406,7 +3588,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2859 +#: sssd.conf.5.xml:2984 msgid "" "Take a note that while credentials are stored as a salted SHA512 hash, this " "still potentially poses some security risk in case an attacker manages to " @@ -3415,12 +3597,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2873 +#: sssd.conf.5.xml:2998 msgid "cache_credentials_minimal_first_factor_length (int)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2876 +#: sssd.conf.5.xml:3001 msgid "" "If 2-Factor-Authentication (2FA) is used and credentials should be saved " "this value determines the minimal length the first authentication factor " @@ -3428,19 +3610,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2883 +#: sssd.conf.5.xml:3008 msgid "" "This should avoid that the short PINs of a PIN based 2FA scheme are saved in " "the cache which would make them easy targets for brute-force attacks." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2894 +#: sssd.conf.5.xml:3019 msgid "account_cache_expiration (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2897 +#: sssd.conf.5.xml:3022 msgid "" "Number of days entries are left in cache after last successful login before " "being removed during a cleanup of the cache. 0 means keep forever. The " @@ -3449,17 +3631,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2904 +#: sssd.conf.5.xml:3029 msgid "Default: 0 (unlimited)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2909 +#: sssd.conf.5.xml:3034 msgid "pwd_expiration_warning (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2920 +#: sssd.conf.5.xml:3045 msgid "" "Please note that the backend server has to provide information about the " "expiration time of the password. If this information is missing, sssd " @@ -3468,28 +3650,28 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2927 +#: sssd.conf.5.xml:3052 msgid "Default: 7 (Kerberos), 0 (LDAP)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2933 +#: sssd.conf.5.xml:3058 msgid "id_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2936 +#: sssd.conf.5.xml:3061 msgid "" "The identification provider used for the domain. Supported ID providers are:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2940 +#: sssd.conf.5.xml:3065 msgid "<quote>proxy</quote>: Support a legacy NSS provider." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2943 +#: sssd.conf.5.xml:3068 msgid "" "<quote>ldap</quote>: LDAP provider. See <citerefentry> <refentrytitle>sssd-" "ldap</refentrytitle> <manvolnum>5</manvolnum> </citerefentry> for more " @@ -3497,8 +3679,8 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2951 sssd.conf.5.xml:3070 sssd.conf.5.xml:3129 -#: sssd.conf.5.xml:3192 +#: sssd.conf.5.xml:3076 sssd.conf.5.xml:3200 sssd.conf.5.xml:3259 +#: sssd.conf.5.xml:3322 msgid "" "<quote>ipa</quote>: FreeIPA and Red Hat Identity Management provider. See " "<citerefentry> <refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</" @@ -3506,8 +3688,8 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2960 sssd.conf.5.xml:3079 sssd.conf.5.xml:3138 -#: sssd.conf.5.xml:3201 +#: sssd.conf.5.xml:3085 sssd.conf.5.xml:3209 sssd.conf.5.xml:3268 +#: sssd.conf.5.xml:3331 msgid "" "<quote>ad</quote>: Active Directory provider. See <citerefentry> " "<refentrytitle>sssd-ad</refentrytitle> <manvolnum>5</manvolnum> </" @@ -3515,27 +3697,34 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2968 +#: sssd.conf.5.xml:3093 msgid "" "<quote>idp</quote>: Provider for OAuth 2.0/OIDC based Identity Providers " "(IdP). See <citerefentry> <refentrytitle>sssd-idp</refentrytitle> " "<manvolnum>5</manvolnum> </citerefentry> for more information." msgstr "" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3101 +msgid "" +"Default: Not set (This is a mandatory setting that must be explicitly " +"defined for each configured domain)." +msgstr "" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2979 -msgid "use_fully_qualified_names (bool)" +#: sssd.conf.5.xml:3109 +msgid "use_fully_qualified_names (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2982 +#: sssd.conf.5.xml:3112 msgid "" "Use the full name and domain (as formatted by the domain's full_name_format) " "as the user's login name reported to NSS." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2987 +#: sssd.conf.5.xml:3117 msgid "" "If set to TRUE, all requests to this domain must use fully qualified names. " "For example, if used in EXAMPLE domain that contains a \"test\" user, " @@ -3544,7 +3733,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2995 +#: sssd.conf.5.xml:3125 msgid "" "NOTE: This option has no effect on netgroup lookups due to their tendency to " "include nested netgroups without qualified names. For netgroups, all domains " @@ -3552,24 +3741,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3002 +#: sssd.conf.5.xml:3132 msgid "" "Default: FALSE (TRUE for trusted domain/sub-domains or if " "default_domain_suffix is used)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3009 -msgid "ignore_group_members (bool)" +#: sssd.conf.5.xml:3139 +msgid "ignore_group_members (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3012 +#: sssd.conf.5.xml:3142 msgid "Do not return group members for group lookups." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3015 +#: sssd.conf.5.xml:3145 msgid "" "If set to TRUE, the group membership attribute is not requested from the " "ldap server, and group members are not returned when processing group lookup " @@ -3581,7 +3770,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3033 +#: sssd.conf.5.xml:3163 msgid "" "Enabling this option can also make access provider checks for group " "membership significantly faster, especially for groups containing many " @@ -3589,7 +3778,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3039 sssd.conf.5.xml:3767 sssd-ldap.5.xml:401 +#: sssd.conf.5.xml:3169 sssd.conf.5.xml:3951 sssd-ldap.5.xml:401 #: sssd-ldap.5.xml:454 sssd-ldap.5.xml:529 sssd-ldap.5.xml:576 #: sssd-ldap.5.xml:599 sssd-ldap.5.xml:638 sssd-ldap.5.xml:657 #: sssd-ldap.5.xml:681 sssd-ldap.5.xml:1114 sssd-ldap.5.xml:1147 @@ -3599,19 +3788,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3049 +#: sssd.conf.5.xml:3179 msgid "auth_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3052 +#: sssd.conf.5.xml:3182 msgid "" "The authentication provider used for the domain. Supported auth providers " "are:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3056 sssd.conf.5.xml:3122 +#: sssd.conf.5.xml:3186 sssd.conf.5.xml:3252 msgid "" "<quote>ldap</quote> for native LDAP authentication. See <citerefentry> " "<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> </" @@ -3619,7 +3808,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3063 +#: sssd.conf.5.xml:3193 msgid "" "<quote>krb5</quote> for Kerberos authentication. See <citerefentry> " "<refentrytitle>sssd-krb5</refentrytitle> <manvolnum>5</manvolnum> </" @@ -3627,7 +3816,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3087 +#: sssd.conf.5.xml:3217 msgid "" "<quote>idp</quote>: Provider for OAuth 2.0/OIDC based authentication. See " "<citerefentry> <refentrytitle>sssd-idp</refentrytitle> <manvolnum>5</" @@ -3635,30 +3824,30 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3095 +#: sssd.conf.5.xml:3225 msgid "" "<quote>proxy</quote> for relaying authentication to some other PAM target." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3098 +#: sssd.conf.5.xml:3228 msgid "<quote>none</quote> disables authentication explicitly." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3101 +#: sssd.conf.5.xml:3231 msgid "" "Default: <quote>id_provider</quote> is used if it is set and can handle " "authentication requests." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3107 +#: sssd.conf.5.xml:3237 msgid "access_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3110 +#: sssd.conf.5.xml:3240 msgid "" "The access control provider used for the domain. There are two built-in " "access providers (in addition to any included in installed backends) " @@ -3666,17 +3855,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3116 +#: sssd.conf.5.xml:3246 msgid "<quote>permit</quote> always allow access." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3119 +#: sssd.conf.5.xml:3249 msgid "<quote>deny</quote> always deny access." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3146 +#: sssd.conf.5.xml:3276 msgid "" "<quote>simple</quote> access control based on access or deny lists. See " "<citerefentry> <refentrytitle>sssd-simple</refentrytitle> <manvolnum>5</" @@ -3685,7 +3874,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3153 +#: sssd.conf.5.xml:3283 msgid "" "<quote>krb5</quote>: .k5login based access control. See <citerefentry> " "<refentrytitle>sssd-krb5</refentrytitle> <manvolnum>5</manvolnum></" @@ -3693,29 +3882,29 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3160 +#: sssd.conf.5.xml:3290 msgid "<quote>proxy</quote> for relaying access control to another PAM module." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3163 +#: sssd.conf.5.xml:3293 msgid "Default: <quote>permit</quote>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3168 +#: sssd.conf.5.xml:3298 msgid "chpass_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3171 +#: sssd.conf.5.xml:3301 msgid "" "The provider which should handle change password operations for the domain. " "Supported change password providers are:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3176 +#: sssd.conf.5.xml:3306 msgid "" "<quote>ldap</quote> to change a password stored in a LDAP server. See " "<citerefentry> <refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</" @@ -3723,7 +3912,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3184 +#: sssd.conf.5.xml:3314 msgid "" "<quote>krb5</quote> to change the Kerberos password. See <citerefentry> " "<refentrytitle>sssd-krb5</refentrytitle> <manvolnum>5</manvolnum> </" @@ -3731,35 +3920,35 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3209 +#: sssd.conf.5.xml:3339 msgid "" "<quote>proxy</quote> for relaying password changes to some other PAM target." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3213 +#: sssd.conf.5.xml:3343 msgid "<quote>none</quote> disallows password changes explicitly." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3216 +#: sssd.conf.5.xml:3346 msgid "" "Default: <quote>auth_provider</quote> is used if it is set and can handle " "change password requests." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3223 +#: sssd.conf.5.xml:3353 msgid "sudo_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3226 +#: sssd.conf.5.xml:3356 msgid "The SUDO provider used for the domain. Supported SUDO providers are:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3230 +#: sssd.conf.5.xml:3360 msgid "" "<quote>ldap</quote> for rules stored in LDAP. See <citerefentry> " "<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> </" @@ -3767,33 +3956,33 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3238 +#: sssd.conf.5.xml:3368 msgid "" "<quote>ipa</quote> the same as <quote>ldap</quote> but with IPA default " "settings." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3242 +#: sssd.conf.5.xml:3372 msgid "" "<quote>ad</quote> the same as <quote>ldap</quote> but with AD default " "settings." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3246 +#: sssd.conf.5.xml:3376 msgid "<quote>none</quote> disables SUDO explicitly." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3249 +#: sssd.conf.5.xml:3379 msgid "" "Default: The value of <quote>id_provider</quote> is used if it is set and " "can handle sudo requests." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3253 +#: sssd.conf.5.xml:3383 msgid "" "The detailed instructions for configuration of sudo_provider are in the " "manual page <citerefentry> <refentrytitle>sssd-sudo</refentrytitle> " @@ -3804,7 +3993,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3268 +#: sssd.conf.5.xml:3398 msgid "" "<emphasis>NOTE:</emphasis> Sudo rules are periodically downloaded in the " "background unless the sudo provider is explicitly disabled. Set " @@ -3813,12 +4002,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3278 +#: sssd.conf.5.xml:3408 msgid "selinux_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3281 +#: sssd.conf.5.xml:3411 msgid "" "The provider which should handle loading of selinux settings. Note that this " "provider will be called right after access provider ends. Supported selinux " @@ -3826,7 +4015,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3287 +#: sssd.conf.5.xml:3417 msgid "" "<quote>ipa</quote> to load selinux settings from an IPA server. See " "<citerefentry> <refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</" @@ -3834,31 +4023,32 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3295 +#: sssd.conf.5.xml:3425 msgid "<quote>none</quote> disallows fetching selinux settings explicitly." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3298 +#: sssd.conf.5.xml:3428 msgid "" -"Default: <quote>id_provider</quote> is used if it is set and can handle " -"selinux loading requests." +"Default: the value of <quote>id_provider</quote> is used if it is set and " +"can handle selinux loading requests. Otherwise the result is the same as if " +"the selinux_provider is set to none." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3304 +#: sssd.conf.5.xml:3435 msgid "subdomains_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3307 +#: sssd.conf.5.xml:3438 msgid "" "The provider which should handle fetching of subdomains. This value should " "be always the same as id_provider. Supported subdomain providers are:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3313 +#: sssd.conf.5.xml:3444 msgid "" "<quote>ipa</quote> to load a list of subdomains from an IPA server. See " "<citerefentry> <refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</" @@ -3866,7 +4056,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3322 +#: sssd.conf.5.xml:3453 msgid "" "<quote>ad</quote> to load a list of subdomains from an Active Directory " "server. See <citerefentry> <refentrytitle>sssd-ad</refentrytitle> " @@ -3875,24 +4065,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3331 +#: sssd.conf.5.xml:3462 msgid "<quote>none</quote> disallows fetching subdomains explicitly." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3335 +#: sssd.conf.5.xml:3466 msgid "" "Default: The value of <quote>id_provider</quote> is used if it is set and " "can handle subdomain requests." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3341 +#: sssd.conf.5.xml:3472 msgid "session_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3344 +#: sssd.conf.5.xml:3475 msgid "" "The provider which configures and manages user session related tasks. The " "only user session task currently provided is the integration with Fleet " @@ -3900,36 +4090,36 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3351 +#: sssd.conf.5.xml:3482 msgid "<quote>ipa</quote> to allow performing user session related tasks." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3355 +#: sssd.conf.5.xml:3486 msgid "" "<quote>none</quote> does not perform any kind of user session related tasks." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3359 +#: sssd.conf.5.xml:3490 #, fuzzy #| msgid "Default: true" msgid "Default: <quote>none</quote>." msgstr "Dre ziouer : true" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3365 +#: sssd.conf.5.xml:3496 msgid "autofs_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3368 +#: sssd.conf.5.xml:3499 msgid "" "The autofs provider used for the domain. Supported autofs providers are:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3372 +#: sssd.conf.5.xml:3503 msgid "" "<quote>ldap</quote> to load maps stored in LDAP. See <citerefentry> " "<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> </" @@ -3937,7 +4127,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3379 +#: sssd.conf.5.xml:3510 msgid "" "<quote>ipa</quote> to load maps stored in an IPA server. See <citerefentry> " "<refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</manvolnum> </" @@ -3945,7 +4135,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3387 +#: sssd.conf.5.xml:3518 msgid "" "<quote>ad</quote> to load maps stored in an AD server. See <citerefentry> " "<refentrytitle>sssd-ad</refentrytitle> <manvolnum>5</manvolnum> </" @@ -3953,31 +4143,31 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3396 +#: sssd.conf.5.xml:3527 msgid "<quote>none</quote> disables autofs explicitly." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3399 +#: sssd.conf.5.xml:3530 msgid "" "Default: The value of <quote>id_provider</quote> is used if it is set and " "can handle autofs requests." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3406 +#: sssd.conf.5.xml:3537 msgid "hostid_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3409 +#: sssd.conf.5.xml:3540 msgid "" "The provider used for retrieving host identity information. Supported " "hostid providers are:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3413 +#: sssd.conf.5.xml:3544 msgid "" "<quote>ipa</quote> to load host identity stored in an IPA server. See " "<citerefentry> <refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</" @@ -3985,38 +4175,38 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3421 +#: sssd.conf.5.xml:3552 msgid "<quote>none</quote> disables hostid explicitly." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3424 +#: sssd.conf.5.xml:3555 msgid "" "Default: The value of <quote>id_provider</quote> is used if it is set and " "can handle hostid requests." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3431 +#: sssd.conf.5.xml:3562 msgid "resolver_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3434 +#: sssd.conf.5.xml:3565 msgid "" "The provider which should handle hosts and networks lookups. Supported " "resolver providers are:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3438 +#: sssd.conf.5.xml:3569 msgid "" "<quote>proxy</quote> to forward lookups to another NSS library. See " "<quote>proxy_resolver_lib_name</quote>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3442 +#: sssd.conf.5.xml:3573 msgid "" "<quote>ldap</quote> to fetch hosts and networks stored in LDAP. See " "<citerefentry> <refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</" @@ -4024,7 +4214,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3449 +#: sssd.conf.5.xml:3580 msgid "" "<quote>ad</quote> to fetch hosts and networks stored in AD. See " "<citerefentry> <refentrytitle>sssd-ad</refentrytitle> <manvolnum>5</" @@ -4033,19 +4223,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3457 +#: sssd.conf.5.xml:3588 msgid "<quote>none</quote> disallows fetching hosts and networks explicitly." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3460 +#: sssd.conf.5.xml:3591 msgid "" "Default: The value of <quote>id_provider</quote> is used if it is set and " "can handle resolver requests." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3470 +#: sssd.conf.5.xml:3601 msgid "" "Regular expression for this domain that describes how to parse the string " "containing user name and domain into these components. The \"domain\" can " @@ -4055,24 +4245,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3479 +#: sssd.conf.5.xml:3610 msgid "" "Default: <quote>^((?P<name>.+)@(?P<domain>[^@]*)|(?P<name>" "[^@]+))$</quote> which allows two different styles for user names:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:3484 sssd.conf.5.xml:3498 +#: sssd.conf.5.xml:3615 sssd.conf.5.xml:3629 msgid "username" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:3487 sssd.conf.5.xml:3501 +#: sssd.conf.5.xml:3618 sssd.conf.5.xml:3632 msgid "username@domain.name" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3492 +#: sssd.conf.5.xml:3623 msgid "" "Default for the AD and IPA provider: <quote>^(((?P<domain>[^\\\\]+)\\\\" "(?P<name>.+))|((?P<name>.+)@(?P<domain>[^@]+))|((?" @@ -4081,19 +4271,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:3504 +#: sssd.conf.5.xml:3635 msgid "domain\\username" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3507 +#: sssd.conf.5.xml:3638 msgid "" "While the first two correspond to the general default the third one is " "introduced to allow easy integration of users from Windows domains." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3512 +#: sssd.conf.5.xml:3643 msgid "" "The default re_expression uses the <quote>@</quote> character as a separator " "between the name and the domain. As a result of this setting the default " @@ -4103,89 +4293,94 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3564 +#: sssd.conf.5.xml:3695 msgid "Default: <quote>%1$s@%2$s</quote>." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3570 +#: sssd.conf.5.xml:3701 msgid "lookup_family_order (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3573 +#: sssd.conf.5.xml:3704 msgid "" "Provides the ability to select preferred address family to use when " "performing DNS lookups." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3577 +#: sssd.conf.5.xml:3708 msgid "Supported values:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3580 +#: sssd.conf.5.xml:3711 msgid "ipv4_first: Try looking up IPv4 address, if that fails, try IPv6" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3583 +#: sssd.conf.5.xml:3714 msgid "ipv4_only: Only attempt to resolve hostnames to IPv4 addresses." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3586 +#: sssd.conf.5.xml:3717 msgid "ipv6_first: Try looking up IPv6 address, if that fails, try IPv4" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3589 +#: sssd.conf.5.xml:3720 msgid "ipv6_only: Only attempt to resolve hostnames to IPv6 addresses." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3592 +#: sssd.conf.5.xml:3723 msgid "Default: ipv4_first" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3598 +#: sssd.conf.5.xml:3729 msgid "dns_resolver_server_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3601 +#: sssd.conf.5.xml:3732 msgid "" -"Defines the amount of time (in milliseconds) SSSD would try to talk to DNS " -"server before trying next DNS server." +"Defines the timeout duration (in milliseconds) SSSD waits for a DNS server " +"to respond before moving to the next one." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3606 +#: sssd.conf.5.xml:3737 msgid "" "The AD provider will use this option for the CLDAP ping timeouts as well." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3610 sssd.conf.5.xml:3630 sssd.conf.5.xml:3651 +#: sssd.conf.5.xml:3741 sssd.conf.5.xml:3777 sssd.conf.5.xml:3814 msgid "" -"Please see the section <quote>FAILOVER</quote> for more information about " -"the service resolution." +"Please see the section <quote>FAILOVER</quote> in <citerefentry> " +"<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> </" +"citerefentry>, <citerefentry> <refentrytitle>sssd-krb5</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry>, <citerefentry> <refentrytitle>sssd-" +"ipa</refentrytitle> <manvolnum>5</manvolnum> </citerefentry> or " +"<citerefentry> <refentrytitle>sssd-ad</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry> for more information about the service resolution." msgstr "" #. type: Content of: <refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3615 sssd-ldap.5.xml:700 include/failover.xml:84 +#: sssd.conf.5.xml:3762 sssd-ldap.5.xml:700 include/failover.xml:84 msgid "Default: 1000" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3621 +#: sssd.conf.5.xml:3768 msgid "dns_resolver_op_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3624 +#: sssd.conf.5.xml:3771 msgid "" "Defines the amount of time (in seconds) to wait to resolve single DNS query " "(e.g. resolution of a hostname or an SRV record) before trying the next " @@ -4193,17 +4388,17 @@ msgid "" msgstr "" #. type: Content of: <refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3635 include/failover.xml:100 +#: sssd.conf.5.xml:3798 include/failover.xml:100 msgid "Default: 3" msgstr "Dre ziouer : 3" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3641 +#: sssd.conf.5.xml:3804 msgid "dns_resolver_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3644 +#: sssd.conf.5.xml:3807 msgid "" "Defines the amount of time (in seconds) to wait for a reply from the " "internal fail over service before assuming that the service is unreachable. " @@ -4212,12 +4407,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3662 -msgid "dns_resolver_use_search_list (bool)" +#: sssd.conf.5.xml:3841 +msgid "dns_resolver_use_search_list (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3665 +#: sssd.conf.5.xml:3844 msgid "" "Normally, the DNS resolver searches the domain list defined in the " "\"search\" directive from the resolv.conf file. This can lead to delays in " @@ -4225,7 +4420,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3671 +#: sssd.conf.5.xml:3850 msgid "" "If fully qualified domain names (or _srv_) are used in the SSSD " "configuration, setting this option to FALSE can prevent unnecessary DNS " @@ -4233,36 +4428,36 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3677 +#: sssd.conf.5.xml:3856 #, fuzzy #| msgid "Default: 3" msgid "Default: TRUE" msgstr "Dre ziouer : 3" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3683 +#: sssd.conf.5.xml:3862 msgid "dns_discovery_domain (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3686 +#: sssd.conf.5.xml:3865 msgid "" "If service discovery is used in the back end, specifies the domain part of " "the service discovery DNS query." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3690 +#: sssd.conf.5.xml:3869 msgid "Default: Use the domain part of machine's hostname" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3696 +#: sssd.conf.5.xml:3875 msgid "failover_primary_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3699 +#: sssd.conf.5.xml:3878 msgid "" "When no primary server is available, SSSD fails over to a backup server. " "This option defines the number of seconds SSSD waits before attempting to " @@ -4270,59 +4465,68 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3706 +#: sssd.conf.5.xml:3885 msgid "Note: The minimum value is 31." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3709 +#: sssd.conf.5.xml:3888 #, fuzzy #| msgid "Default: 3" msgid "Default: 31" msgstr "Dre ziouer : 3" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3715 +#: sssd.conf.5.xml:3894 msgid "override_gid (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3718 -msgid "Override the primary GID value with the one specified." +#: sssd.conf.5.xml:3897 +msgid "" +"Override the primary GID value for all users in the domain with specified " +"value." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3901 +msgid "" +"Default: not set (Use the primary GID value retrieved from the identity " +"provider)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3724 +#: sssd.conf.5.xml:3908 msgid "case_sensitive (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3731 +#: sssd.conf.5.xml:3915 msgid "True" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3734 +#: sssd.conf.5.xml:3918 msgid "Case sensitive. This value is invalid for AD provider." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3740 +#: sssd.conf.5.xml:3924 msgid "False" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3742 +#: sssd.conf.5.xml:3926 msgid "Case insensitive." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3746 +#: sssd.conf.5.xml:3930 msgid "Preserving" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3749 +#: sssd.conf.5.xml:3933 msgid "" "Same as False (case insensitive), but does not lowercase names in the result " "of NSS operations. Note that name aliases (and in case of services also " @@ -4330,31 +4534,57 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3757 +#: sssd.conf.5.xml:3941 msgid "" "If you want to set this value for trusted domain with IPA provider, you need " "to set it on both the client and SSSD on the server." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3727 +#: sssd.conf.5.xml:3911 msgid "" "Treat user and group names as case sensitive. Possible option values are: " "<placeholder type=\"variablelist\" id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3772 +#: sssd.conf.5.xml:3956 msgid "Default: True (False for AD provider)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3778 +#: sssd.conf.5.xml:3962 +msgid "avoid_by_id_lookups (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3965 +msgid "" +"If this option is set to 'true' SSSD will try to avoid sending lookups by ID " +"to the backend and will switch to a lookup by name if a cached object with a " +"matching ID can be found." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3971 +msgid "" +"This option can e.g. be used in cases where searches by ID are expensive on " +"the server side because of missing indexes or are not even possible, e.g. " +"due to non-reversible POSIX id-mapping." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3978 +msgid "Default: False (True for IdP provider)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:3984 msgid "subdomain_inherit (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3781 +#: sssd.conf.5.xml:3987 msgid "" "Specifies a list of configuration parameters that should be inherited by a " "subdomain. Please note that only selected parameters can be inherited. " @@ -4362,89 +4592,89 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3787 +#: sssd.conf.5.xml:3993 msgid "ldap_search_timeout" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3790 +#: sssd.conf.5.xml:3996 msgid "ldap_network_timeout" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3793 +#: sssd.conf.5.xml:3999 msgid "ldap_opt_timeout" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3796 +#: sssd.conf.5.xml:4002 msgid "ldap_offline_timeout" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3799 +#: sssd.conf.5.xml:4005 msgid "ldap_purge_cache_timeout" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3802 +#: sssd.conf.5.xml:4008 msgid "ldap_purge_cache_offset" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3805 +#: sssd.conf.5.xml:4011 msgid "" "ldap_krb5_keytab (the value of krb5_keytab will be used if ldap_krb5_keytab " "is not set explicitly)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3809 +#: sssd.conf.5.xml:4015 msgid "ldap_krb5_ticket_lifetime" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3812 +#: sssd.conf.5.xml:4018 msgid "ldap_connection_expire_timeout" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3815 +#: sssd.conf.5.xml:4021 msgid "ldap_connection_expire_offset" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3818 +#: sssd.conf.5.xml:4024 msgid "ldap_connection_idle_timeout" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3821 sssd-ldap.5.xml:446 +#: sssd.conf.5.xml:4027 sssd-ldap.5.xml:446 msgid "ldap_use_tokengroups" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3824 +#: sssd.conf.5.xml:4030 msgid "ldap_user_principal" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3827 +#: sssd.conf.5.xml:4033 msgid "ignore_group_members" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3830 +#: sssd.conf.5.xml:4036 msgid "auto_private_groups" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3833 +#: sssd.conf.5.xml:4039 msgid "case_sensitive" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:3838 +#: sssd.conf.5.xml:4044 #, no-wrap msgid "" "subdomain_inherit = ldap_purge_cache_timeout\n" @@ -4452,27 +4682,27 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3845 +#: sssd.conf.5.xml:4051 msgid "Note: This option only works with the IPA and AD provider." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3852 +#: sssd.conf.5.xml:4058 msgid "subdomain_homedir (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3863 +#: sssd.conf.5.xml:4069 msgid "%F" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3864 +#: sssd.conf.5.xml:4070 msgid "flat (NetBIOS) name of a subdomain." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3855 +#: sssd.conf.5.xml:4061 msgid "" "Use this homedir as default value for all subdomains within this domain in " "IPA AD trust. See <emphasis>override_homedir</emphasis> for info about " @@ -4482,55 +4712,55 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3869 +#: sssd.conf.5.xml:4075 msgid "" "The value can be overridden by <emphasis>override_homedir</emphasis> option." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3873 +#: sssd.conf.5.xml:4079 msgid "Default: <filename>/home/%d/%u</filename>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3878 +#: sssd.conf.5.xml:4084 msgid "realmd_tags (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3881 +#: sssd.conf.5.xml:4087 msgid "" "Various tags stored by the realmd configuration service for this domain." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3887 +#: sssd.conf.5.xml:4093 msgid "cached_auth_timeout (int)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3890 +#: sssd.conf.5.xml:4096 msgid "" -"Specifies time in seconds since last successful online authentication for " -"which user will be authenticated using cached credentials while SSSD is in " -"the online mode. If the credentials are incorrect, SSSD falls back to online " -"authentication." +"Specifies the number of seconds since the last successful online " +"authentication during which SSSD will authenticate users via cached " +"credentials, even while online. If the cached authentication fails, SSSD " +"immediately falls back to online authentication." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3898 +#: sssd.conf.5.xml:4103 msgid "" "This option's value is inherited by all trusted domains. At the moment it is " "not possible to set a different value per trusted domain." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3903 +#: sssd.conf.5.xml:4108 msgid "Special value 0 implies that this feature is disabled." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3907 +#: sssd.conf.5.xml:4112 msgid "" "Please note that if <quote>cached_auth_timeout</quote> is longer than " "<quote>pam_id_timeout</quote> then the back end could be called to handle " @@ -4538,14 +4768,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3918 +#: sssd.conf.5.xml:4123 #, fuzzy #| msgid "re_expression (string)" msgid "local_auth_policy (string)" msgstr "re_expression (neudennad)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3921 +#: sssd.conf.5.xml:4126 msgid "" "Local authentication methods policy. Some backends (i.e. LDAP, proxy " "provider) only support a password based authentication, while others can " @@ -4557,7 +4787,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3933 +#: sssd.conf.5.xml:4138 msgid "" "There are three possible values for this option: match, only, enable. " "<quote>match</quote> is used to match offline and online states for Kerberos " @@ -4569,7 +4799,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3946 +#: sssd.conf.5.xml:4151 msgid "" "The following table shows which authentication methods, if configured " "properly, are currently enabled or disabled for each backend, with the " @@ -4577,44 +4807,49 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> -#: sssd.conf.5.xml:3959 +#: sssd.conf.5.xml:4164 #, fuzzy #| msgid "re_expression (string)" msgid "local_auth_policy = match (default)" msgstr "re_expression (neudennad)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> -#: sssd.conf.5.xml:3960 +#: sssd.conf.5.xml:4165 msgid "Passkey" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> -#: sssd.conf.5.xml:3961 +#: sssd.conf.5.xml:4166 msgid "Smartcard" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:3964 sssd-ldap.5.xml:228 +#: sssd.conf.5.xml:4169 sssd-ldap.5.xml:228 msgid "IPA" msgstr "" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry><para> +#: sssd.conf.5.xml:4169 sssd.conf.5.xml:4170 sssd.conf.5.xml:4173 +msgid "enabled" +msgstr "" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:3967 sssd-ldap.5.xml:233 +#: sssd.conf.5.xml:4172 sssd-ldap.5.xml:233 msgid "AD" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry><para> -#: sssd.conf.5.xml:3967 sssd.conf.5.xml:3970 sssd.conf.5.xml:3971 +#: sssd.conf.5.xml:4172 sssd.conf.5.xml:4175 sssd.conf.5.xml:4176 msgid "disabled" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry> -#: sssd.conf.5.xml:3970 +#: sssd.conf.5.xml:4175 msgid "LDAP" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3975 +#: sssd.conf.5.xml:4180 msgid "" "Please note that if local Smartcard authentication is enabled and a " "Smartcard is present, Smartcard authentication will be preferred over the " @@ -4623,7 +4858,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:3987 +#: sssd.conf.5.xml:4192 #, no-wrap msgid "" "[domain/shadowutils]\n" @@ -4634,7 +4869,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3983 +#: sssd.conf.5.xml:4188 msgid "" "The following configuration example allows local users to authenticate " "locally using any enabled method (i.e. smartcard, passkey). <placeholder " @@ -4642,31 +4877,31 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3995 +#: sssd.conf.5.xml:4200 #, fuzzy #| msgid "Default: 3" msgid "Default: match" msgstr "Dre ziouer : 3" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4000 +#: sssd.conf.5.xml:4205 msgid "auto_private_groups (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4006 +#: sssd.conf.5.xml:4211 msgid "true" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4009 +#: sssd.conf.5.xml:4214 msgid "" "Create user's private group unconditionally from user's UID number. The GID " "number is ignored in this case." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4013 +#: sssd.conf.5.xml:4218 msgid "" "NOTE: Because the GID number and the user private group are inferred from " "the UID number, it is not supported to have multiple entries with the same " @@ -4675,24 +4910,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4022 +#: sssd.conf.5.xml:4227 msgid "false" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4025 +#: sssd.conf.5.xml:4230 msgid "" "Always use the user's primary GID number. The GID number must refer to a " "group object in the LDAP database." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4031 +#: sssd.conf.5.xml:4236 msgid "hybrid" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4034 +#: sssd.conf.5.xml:4239 msgid "" "A primary group is autogenerated for user entries whose UID and GID numbers " "have the same value and at the same time the GID number does not correspond " @@ -4702,14 +4937,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4047 +#: sssd.conf.5.xml:4252 msgid "" "If the UID and GID of a user are different, then the GID must correspond to " "a group entry, otherwise the GID is simply not resolvable." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4054 +#: sssd.conf.5.xml:4259 msgid "" "This feature is useful for environments that wish to stop maintaining a " "separate group objects for the user private groups, but also wish to retain " @@ -4717,14 +4952,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4003 +#: sssd.conf.5.xml:4208 msgid "" "This option takes any of three available values: <placeholder " "type=\"variablelist\" id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4066 +#: sssd.conf.5.xml:4271 msgid "" "For the LDAP based id providers (LDAP, IPA and AD) the default for the " "configured domain is typically False because the sources have the concept of " @@ -4734,14 +4969,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4075 +#: sssd.conf.5.xml:4280 msgid "" "For subdomains, the default value is False for subdomains that use assigned " "POSIX IDs and True for subdomains that use automatic ID-mapping." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:4083 +#: sssd.conf.5.xml:4288 #, no-wrap msgid "" "[domain/forest.domain/sub.domain]\n" @@ -4749,7 +4984,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:4089 +#: sssd.conf.5.xml:4294 #, no-wrap msgid "" "[domain/forest.domain]\n" @@ -4758,7 +4993,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4080 +#: sssd.conf.5.xml:4285 msgid "" "The value of auto_private_groups can either be set per subdomains in a " "subsection, for example: <placeholder type=\"programlisting\" id=\"0\"/> or " @@ -4767,7 +5002,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:2503 +#: sssd.conf.5.xml:2549 msgid "" "These configuration options can be present in a domain configuration " "section, that is, in a section called <quote>[domain/<replaceable>NAME</" @@ -4775,17 +5010,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4104 +#: sssd.conf.5.xml:4309 msgid "proxy_pam_target (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4107 +#: sssd.conf.5.xml:4312 msgid "The proxy target PAM proxies to." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4110 +#: sssd.conf.5.xml:4315 msgid "" "Default: not set by default, you have to take an existing pam configuration " "or create a new one and add the service name here. As an alternative you can " @@ -4793,12 +5028,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4120 +#: sssd.conf.5.xml:4325 msgid "proxy_lib_name (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4123 +#: sssd.conf.5.xml:4328 msgid "" "The name of the NSS library to use in proxy domains. The NSS functions " "searched for in the library are in the form of _nss_$(libName)_$(function), " @@ -4806,12 +5041,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4133 +#: sssd.conf.5.xml:4338 msgid "proxy_resolver_lib_name (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4136 +#: sssd.conf.5.xml:4341 msgid "" "The name of the NSS library to use for hosts and networks lookups in proxy " "domains. The NSS functions searched for in the library are in the form of " @@ -4819,12 +5054,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4147 +#: sssd.conf.5.xml:4352 msgid "proxy_fast_alias (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4150 +#: sssd.conf.5.xml:4355 msgid "" "When a user or group is looked up by name in the proxy provider, a second " "lookup by ID is performed to \"canonicalize\" the name in case the requested " @@ -4833,12 +5068,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4164 +#: sssd.conf.5.xml:4369 msgid "proxy_max_children (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4167 +#: sssd.conf.5.xml:4372 msgid "" "This option specifies the number of pre-forked proxy children. It is useful " "for high-load SSSD environments where sssd may run out of available child " @@ -4846,19 +5081,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4100 +#: sssd.conf.5.xml:4305 msgid "" "Options valid for proxy domains. <placeholder type=\"variablelist\" " "id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:4183 +#: sssd.conf.5.xml:4388 msgid "Application domains" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:4185 +#: sssd.conf.5.xml:4390 msgid "" "SSSD, with its D-Bus interface (see <citerefentry> <refentrytitle>sssd-ifp</" "refentrytitle> <manvolnum>5</manvolnum> </citerefentry>) is appealing to " @@ -4875,7 +5110,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:4205 +#: sssd.conf.5.xml:4410 msgid "" "Please note that the application domain must still be explicitly enabled in " "the <quote>domains</quote> parameter so that the lookup order between the " @@ -4883,17 +5118,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><title> -#: sssd.conf.5.xml:4211 +#: sssd.conf.5.xml:4416 msgid "Application domain parameters" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4213 +#: sssd.conf.5.xml:4418 msgid "inherit_from (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4216 +#: sssd.conf.5.xml:4421 msgid "" "The SSSD POSIX-type domain the application domain inherits all settings " "from. The application domain can moreover add its own settings to the " @@ -4902,7 +5137,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:4230 +#: sssd.conf.5.xml:4435 msgid "" "The following example illustrates the use of an application domain. In this " "setup, the POSIX domain is connected to an LDAP server and is used by the OS " @@ -4912,7 +5147,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><programlisting> -#: sssd.conf.5.xml:4238 +#: sssd.conf.5.xml:4443 #, no-wrap msgid "" "[sssd]\n" @@ -4932,12 +5167,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:4258 +#: sssd.conf.5.xml:4463 msgid "TRUSTED DOMAIN SECTION" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4260 +#: sssd.conf.5.xml:4465 msgid "" "Some options used in the domain section can also be used in the trusted " "domain section, that is, in a section called <quote>[domain/" @@ -4948,69 +5183,79 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4267 +#: sssd.conf.5.xml:4472 msgid "ldap_search_base," msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4268 +#: sssd.conf.5.xml:4473 msgid "ldap_user_search_base," msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4269 +#: sssd.conf.5.xml:4474 msgid "ldap_group_search_base," msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4270 +#: sssd.conf.5.xml:4475 msgid "ldap_netgroup_search_base," msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4271 +#: sssd.conf.5.xml:4476 msgid "ldap_service_search_base," msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4272 +#: sssd.conf.5.xml:4477 msgid "ldap_sasl_mech," msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4273 +#: sssd.conf.5.xml:4478 msgid "ad_server," msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4274 +#: sssd.conf.5.xml:4479 msgid "ad_backup_server," msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4275 -msgid "ad_site," +#: sssd.conf.5.xml:4480 +msgid "ad_site," +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:4481 sssd-ipa.5.xml:929 +msgid "use_fully_qualified_names" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:4482 +msgid "pam_gssapi_services" msgstr "" -#. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:4276 sssd-ipa.5.xml:934 -msgid "use_fully_qualified_names" +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:4483 +msgid "pam_gssapi_check_upn" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4280 +#: sssd.conf.5.xml:4485 msgid "" "For more details about these options see their individual description in the " "manual page." msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:4286 +#: sssd.conf.5.xml:4491 msgid "CERTIFICATE MAPPING SECTION" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4288 +#: sssd.conf.5.xml:4493 msgid "" "To allow authentication with Smartcards and certificates SSSD must be able " "to map certificates to users. This can be done by adding the full " @@ -5023,7 +5268,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4302 +#: sssd.conf.5.xml:4507 msgid "" "To make the mapping more flexible mapping and matching rules were added to " "SSSD (see <citerefentry> <refentrytitle>sss-certmap</refentrytitle> " @@ -5031,7 +5276,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4311 +#: sssd.conf.5.xml:4516 msgid "" "A mapping and matching rule can be added to the SSSD configuration in a " "section on its own with a name like <quote>[certmap/" @@ -5040,55 +5285,50 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4318 +#: sssd.conf.5.xml:4523 msgid "matchrule (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4321 +#: sssd.conf.5.xml:4526 msgid "" "Only certificates from the Smartcard which matches this rule will be " "processed, all others are ignored." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4325 +#: sssd.conf.5.xml:4530 msgid "" "Default: KRB5:<EKU>clientAuth, i.e. only certificates which have the " "Extended Key Usage <quote>clientAuth</quote>" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4332 +#: sssd.conf.5.xml:4537 msgid "maprule (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4335 +#: sssd.conf.5.xml:4540 msgid "Defines how the user is found for a given certificate." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:4341 +#: sssd.conf.5.xml:4546 msgid "" "LDAP:(userCertificate;binary={cert!bin}) for LDAP based providers like " "<quote>ldap</quote>, <quote>AD</quote> or <quote>ipa</quote>." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:4347 +#: sssd.conf.5.xml:4552 msgid "" "If maprule is not set and provider is <quote>proxy</quote>, the RULE_NAME " "name is assumed to be the name of the matching user." msgstr "" -#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4357 -msgid "domains (string)" -msgstr "" - #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4360 +#: sssd.conf.5.xml:4565 msgid "" "Comma separated list of domain names the rule should be applied. By default " "a rule is only valid in the domain configured in sssd.conf. If the provider " @@ -5097,17 +5337,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4367 +#: sssd.conf.5.xml:4572 msgid "Default: the configured domain in sssd.conf" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4372 +#: sssd.conf.5.xml:4577 msgid "priority (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4375 +#: sssd.conf.5.xml:4580 msgid "" "Unsigned integer value defining the priority of the rule. The higher the " "number the lower the priority. <quote>0</quote> stands for the highest " @@ -5115,17 +5355,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4381 +#: sssd.conf.5.xml:4586 msgid "Default: the lowest priority" msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:4389 +#: sssd.conf.5.xml:4594 msgid "PROMPTING CONFIGURATION SECTION" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4391 +#: sssd.conf.5.xml:4596 msgid "" "If a special file (<filename>/var/lib/sss/pubconf/pam_preauth_available</" "filename>) exists SSSD's PAM module pam_sss will ask SSSD to figure out " @@ -5135,7 +5375,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4399 +#: sssd.conf.5.xml:4604 msgid "" "With the growing number of authentication methods and the possibility that " "there are multiple ones for a single user the heuristic used by pam_sss to " @@ -5144,59 +5384,59 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4411 +#: sssd.conf.5.xml:4616 msgid "[prompting/password]" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4414 +#: sssd.conf.5.xml:4619 msgid "password_prompt" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4415 +#: sssd.conf.5.xml:4620 msgid "to change the string of the password prompt" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4413 +#: sssd.conf.5.xml:4618 msgid "" "to configure password prompting, allowed options are: <placeholder " "type=\"variablelist\" id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4423 +#: sssd.conf.5.xml:4628 msgid "[prompting/2fa]" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4427 +#: sssd.conf.5.xml:4632 msgid "first_prompt" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4428 +#: sssd.conf.5.xml:4633 msgid "to change the string of the prompt for the first factor" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4431 +#: sssd.conf.5.xml:4636 msgid "second_prompt" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4432 +#: sssd.conf.5.xml:4637 msgid "to change the string of the prompt for the second factor" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4435 +#: sssd.conf.5.xml:4640 msgid "single_prompt" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4436 +#: sssd.conf.5.xml:4641 msgid "" "boolean value, if True there will be only a single prompt using the value of " "first_prompt where it is expected that both factors are entered as a single " @@ -5205,7 +5445,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4425 +#: sssd.conf.5.xml:4630 msgid "" "to configure two-factor authentication prompting, allowed options are: " "<placeholder type=\"variablelist\" id=\"0\"/> If the second factor is " @@ -5214,7 +5454,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4449 +#: sssd.conf.5.xml:4654 msgid "" "Some clients, such as SSH with 'PasswordAuthentication yes', generate their " "own prompts and do not use prompts provided by SSSD or other PAM modules. " @@ -5225,17 +5465,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4464 +#: sssd.conf.5.xml:4669 msgid "[prompting/passkey]" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:4470 sssd-ad.5.xml:1022 +#: sssd.conf.5.xml:4675 sssd.conf.5.xml:4719 sssd-ad.5.xml:1027 msgid "interactive" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4472 +#: sssd.conf.5.xml:4677 msgid "" "boolean value, if True prompt a message and wait before testing the presence " "of a passkey device. Recommended if your device doesn’t have a tactile " @@ -5243,55 +5483,131 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4480 +#: sssd.conf.5.xml:4685 sssd.conf.5.xml:4735 msgid "interactive_prompt" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4482 +#: sssd.conf.5.xml:4687 sssd.conf.5.xml:4737 msgid "to change the message of the interactive prompt." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4487 +#: sssd.conf.5.xml:4692 msgid "touch" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4489 +#: sssd.conf.5.xml:4694 msgid "" "boolean value, if True prompt a message to remind the user to touch the " "device." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4495 +#: sssd.conf.5.xml:4700 msgid "touch_prompt" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4497 +#: sssd.conf.5.xml:4702 msgid "to change the message of the touch prompt." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4466 +#: sssd.conf.5.xml:4671 msgid "" "to configure passkey authentication prompting, allowed options are: " "<placeholder type=\"variablelist\" id=\"0\"/>" msgstr "" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4713 +msgid "[prompting/oauth2]" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4721 +msgid "" +"boolean value, if True prompt a message after asking the user to " +"authenticate, and wait before requesting the access token." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4725 +msgid "" +"If False, make sure to set the <quote>idp_request_timeout</quote> " +"sufficiently high, to give the user time to authenticate." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4715 +msgid "" +"to configure OAuth2 authentication prompting, allowed options are: " +"<placeholder type=\"variablelist\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4748 +msgid "[prompting/cert_auth]" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4754 +msgid "pin_prompt" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4756 +msgid "" +"to change the message which asks the user to enter the PIN at the computer " +"keyboard. At the end of the message the token name is printed." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4764 +msgid "keypad_prompt" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4766 +msgid "" +"to change the message which asks the user to enter the PIN at keypad of the " +"Smartcard reader. At the end of the message the token name is printed." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4774 +msgid "user_name_hint" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4776 +msgid "" +"boolean value, if True ask for a user name if no name was given before and " +"the found certificate can be mapped to more than one user." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4750 +msgid "" +"to configure Smartcard authentication prompting, allowed options are: " +"<placeholder type=\"variablelist\" id=\"0\"/>" +msgstr "" + #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4406 +#: sssd.conf.5.xml:4611 msgid "" "Each supported authentication method has its own configuration subsection " "under <quote>[prompting/...]</quote>. Currently there are: <placeholder " "type=\"variablelist\" id=\"0\"/> <placeholder type=\"variablelist\" id=\"1\"/" -"> <placeholder type=\"variablelist\" id=\"2\"/>" +"> <placeholder type=\"variablelist\" id=\"2\"/> <placeholder " +"type=\"variablelist\" id=\"3\"/> <placeholder type=\"variablelist\" id=\"4\"/" +">" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4508 +#: sssd.conf.5.xml:4792 msgid "" "It is possible to add a subsection for specific PAM services, e.g. " "<quote>[prompting/password/sshd]</quote> to individual change the prompting " @@ -5299,12 +5615,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:4515 pam_sss_gss.8.xml:157 idmap_sss.8.xml:43 +#: sssd.conf.5.xml:4799 pam_sss_gss.8.xml:157 idmap_sss.8.xml:43 msgid "EXAMPLES" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd.conf.5.xml:4521 +#: sssd.conf.5.xml:4805 #, no-wrap msgid "" "[sssd]\n" @@ -5333,7 +5649,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4517 +#: sssd.conf.5.xml:4801 msgid "" "1. The following example shows a typical SSSD config. It does not describe " "configuration of the domains themselves - refer to documentation on " @@ -5342,7 +5658,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd.conf.5.xml:4553 +#: sssd.conf.5.xml:4837 #, no-wrap msgid "" "[domain/ipa.com/child.ad.com]\n" @@ -5350,7 +5666,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4547 +#: sssd.conf.5.xml:4831 msgid "" "2. The following example shows configuration of IPA AD trust where the AD " "forest consists of two domains in a parent-child structure. Suppose IPA " @@ -5361,7 +5677,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd.conf.5.xml:4564 +#: sssd.conf.5.xml:4848 #, no-wrap msgid "" "[certmap/my.domain/rule_name]\n" @@ -5372,7 +5688,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4558 +#: sssd.conf.5.xml:4842 msgid "" "3. The following example shows the configuration of a certificate mapping " "rule. It is valid for the configured domain <quote>my.domain</quote> and " @@ -5569,7 +5885,7 @@ msgid "" "defaultNamingContext does not exist or has an empty value namingContexts is " "used. The namingContexts attribute must have a single value with the DN of " "the search base of the LDAP server to make this work. Multiple values are " -"are not supported." +"not supported." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> @@ -5874,15 +6190,15 @@ msgid "Optional. Use the given string as search base for host objects." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap.5.xml:472 sssd-ipa.5.xml:506 sssd-ipa.5.xml:525 sssd-ipa.5.xml:544 -#: sssd-ipa.5.xml:563 +#: sssd-ldap.5.xml:472 sssd-ipa.5.xml:501 sssd-ipa.5.xml:520 sssd-ipa.5.xml:539 +#: sssd-ipa.5.xml:558 msgid "" "See <quote>ldap_search_base</quote> for information about configuring " "multiple search bases." msgstr "" #. type: Content of: <listitem><para> -#: sssd-ldap.5.xml:477 sssd-ipa.5.xml:511 include/ldap_search_bases.xml:27 +#: sssd-ldap.5.xml:477 sssd-ipa.5.xml:506 include/ldap_search_bases.xml:27 msgid "Default: the value of <emphasis>ldap_search_base</emphasis>" msgstr "" @@ -6008,7 +6324,7 @@ msgid "" "closed early to ensure that a new query cannot require the connection to " "remain open past its expiration. This implies that connections will always " "be closed immediately and will never be reused if " -"<emphasis>ldap_connection_expire_timeout <= ldap_opt_timout</emphasis>" +"<emphasis>ldap_connection_expire_timeout <= ldap_opt_timeout</emphasis>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> @@ -6190,7 +6506,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:831 -msgid "ldap_ignore_unreadable_references (bool)" +msgid "ldap_ignore_unreadable_references (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> @@ -6515,7 +6831,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap.5.xml:1152 sssd-ad.5.xml:1267 +#: sssd-ldap.5.xml:1152 sssd-ad.5.xml:1260 msgid "Default: 86400 (24 hours)" msgstr "" @@ -6553,7 +6869,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ldap.5.xml:1187 sssd-ipa.5.xml:575 sssd-krb5.5.xml:103 +#: sssd-ldap.5.xml:1187 sssd-ipa.5.xml:570 sssd-krb5.5.xml:103 msgid "krb5_realm (string)" msgstr "" @@ -6709,8 +7025,10 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1339 -msgid "ldap_chpass_update_last_change (bool)" -msgstr "" +#, fuzzy +#| msgid "re_expression (string)" +msgid "ldap_chpass_update_last_change (boolean)" +msgstr "re_expression (neudennad)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1342 @@ -6856,7 +7174,7 @@ msgid "ldap_access_order (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap.5.xml:1470 sssd-ipa.5.xml:405 +#: sssd-ldap.5.xml:1470 sssd-ipa.5.xml:400 msgid "Comma separated list of access control options. Allowed values are:" msgstr "" @@ -6901,7 +7219,7 @@ msgid "<emphasis>expire</emphasis>: use ldap_account_expire_policy" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap.5.xml:1515 sssd-ipa.5.xml:413 +#: sssd-ldap.5.xml:1515 sssd-ipa.5.xml:408 msgid "" "<emphasis>pwd_expire_policy_reject, pwd_expire_policy_warn, " "pwd_expire_policy_renew: </emphasis> These options are useful if users are " @@ -6911,24 +7229,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap.5.xml:1525 sssd-ipa.5.xml:423 +#: sssd-ldap.5.xml:1525 sssd-ipa.5.xml:418 msgid "" "The difference between these options is the action taken if user password is " "expired:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ldap.5.xml:1530 sssd-ipa.5.xml:428 +#: sssd-ldap.5.xml:1530 sssd-ipa.5.xml:423 msgid "pwd_expire_policy_reject - user is denied to log in," msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ldap.5.xml:1536 sssd-ipa.5.xml:434 +#: sssd-ldap.5.xml:1536 sssd-ipa.5.xml:429 msgid "pwd_expire_policy_warn - user is still able to log in," msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ldap.5.xml:1542 sssd-ipa.5.xml:440 +#: sssd-ldap.5.xml:1542 sssd-ipa.5.xml:435 msgid "" "pwd_expire_policy_renew - user is prompted to change their password " "immediately." @@ -7465,8 +7783,8 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd-ldap.5.xml:2032 sssd-simple.5.xml:169 sssd-ipa.5.xml:984 -#: sssd-ad.5.xml:1470 sssd-idp.5.xml:248 sssd-krb5.5.xml:483 +#: sssd-ldap.5.xml:2032 sssd-simple.5.xml:169 sssd-ipa.5.xml:979 +#: sssd-ad.5.xml:1463 sssd-idp.5.xml:343 sssd-krb5.5.xml:483 #: sss_rpcidmapd.5.xml:98 sssd-session-recording.5.xml:176 msgid "EXAMPLE" msgstr "" @@ -7494,7 +7812,7 @@ msgstr "" #. type: Content of: <refsect1><refsect2><para> #: sssd-ldap.5.xml:2039 sssd-ldap.5.xml:2057 sssd-simple.5.xml:177 -#: sssd-ipa.5.xml:992 sssd-ad.5.xml:1478 sssd-sudo.5.xml:56 sssd-krb5.5.xml:492 +#: sssd-ipa.5.xml:987 sssd-ad.5.xml:1471 sssd-sudo.5.xml:56 sssd-krb5.5.xml:492 #: sssd-session-recording.5.xml:182 include/ldap_id_mapping.xml:105 msgid "<placeholder type=\"programlisting\" id=\"0\"/>" msgstr "" @@ -7529,7 +7847,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><title> #: sssd-ldap.5.xml:2073 sssd_krb5_locator_plugin.8.xml:83 sssd-simple.5.xml:189 -#: sssd-ad.5.xml:1493 sssd.8.xml:270 sss_seed.8.xml:163 +#: sssd-ad.5.xml:1486 sssd.8.xml:270 sss_seed.8.xml:163 msgid "NOTES" msgstr "" @@ -8036,7 +8354,7 @@ msgstr "" #: pam_sss.8.xml:434 msgid "" "No authentication method was found by Kerberos. This might happen if the " -"user has a Smartcard assigned but the pkint plugin is not available on the " +"user has a Smartcard assigned but the pkinit plugin is not available on the " "client." msgstr "" @@ -8468,6 +8786,23 @@ msgid "" "first DNS resolving failure." msgstr "" +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_locator_plugin.8.xml:106 +msgid "" +"If the environment variable SSSD_KRB5_LOCATOR_KDC_ADDRESS is set to a KDC " +"address the plugin will use this address instead of reading the kdcinfo " +"file. The address format is the same as in the kdcinfo file (see above)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_locator_plugin.8.xml:112 +msgid "" +"If the environment variable SSSD_KRB5_LOCATOR_KPASSWD_ADDRESS is set to a " +"kpasswd server address the plugin will use this address instead of reading " +"the kpasswdinfo file. The address format is the same as in the kpasswdinfo " +"file (see above)." +msgstr "" + #. type: Content of: <reference><refentry><refnamediv><refname> #: sssd-simple.5.xml:10 sssd-simple.5.xml:16 msgid "sssd-simple" @@ -9851,7 +10186,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:129 sssd-ad.5.xml:1161 +#: sssd-ipa.5.xml:129 sssd-ad.5.xml:1166 msgid "dyndns_update (boolean)" msgstr "" @@ -9865,20 +10200,13 @@ msgid "" "quote> option." msgstr "" -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:141 sssd-ad.5.xml:1175 -msgid "" -"NOTE: On older systems (such as RHEL 5), for this behavior to work reliably, " -"the default Kerberos realm must be set properly in /etc/krb5.conf" -msgstr "" - #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:152 sssd-ad.5.xml:1186 +#: sssd-ipa.5.xml:147 sssd-ad.5.xml:1186 msgid "dyndns_ttl (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:155 sssd-ad.5.xml:1189 +#: sssd-ipa.5.xml:150 sssd-ad.5.xml:1189 msgid "" "The TTL to apply to the client DNS record when updating it. If " "dyndns_update is false this has no effect. This will override the TTL " @@ -9886,17 +10214,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:160 +#: sssd-ipa.5.xml:155 msgid "Default: 1200 (seconds)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:166 sssd-ad.5.xml:1200 +#: sssd-ipa.5.xml:161 sssd-ad.5.xml:1200 msgid "dyndns_iface (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:169 sssd-ad.5.xml:1203 +#: sssd-ipa.5.xml:164 sssd-ad.5.xml:1203 msgid "" "Optional. Applicable only when dyndns_update is true. Choose the interface " "or a list of interfaces whose IP addresses should be used for dynamic DNS " @@ -9908,26 +10236,26 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:182 +#: sssd-ipa.5.xml:177 msgid "" "Default: Use the IP addresses of the interface which is used for IPA LDAP " "connection" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:186 sssd-ad.5.xml:1226 +#: sssd-ipa.5.xml:181 sssd-ad.5.xml:1220 msgid "Example: dyndns_iface = em[12], !vnet1, vnet*" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:192 sssd-ad.5.xml:1232 +#: sssd-ipa.5.xml:187 sssd-ad.5.xml:1226 #, fuzzy #| msgid "re_expression (string)" msgid "dyndns_address (string)" msgstr "re_expression (neudennad)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:195 sssd-ad.5.xml:1235 +#: sssd-ipa.5.xml:190 sssd-ad.5.xml:1229 msgid "" "Optional. Applicable only when <emphasis>dyndns_update</emphasis> is true. " "A list of IP addresses or IP networks to be used for dynamic DNS updates. " @@ -9938,22 +10266,22 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:206 sssd-ad.5.xml:1246 +#: sssd-ipa.5.xml:201 sssd-ad.5.xml:1240 msgid "Default: No filtering of IP addresses." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:209 sssd-ad.5.xml:1249 +#: sssd-ipa.5.xml:204 sssd-ad.5.xml:1243 msgid "Example: dyndns_address = 10.0.0.0/16, !10.0.1.0/24" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:215 sssd-ad.5.xml:1305 +#: sssd-ipa.5.xml:210 sssd-ad.5.xml:1298 msgid "dyndns_auth (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:218 sssd-ad.5.xml:1308 +#: sssd-ipa.5.xml:213 sssd-ad.5.xml:1301 msgid "" "Whether the nsupdate utility should use GSS-TSIG authentication for secure " "updates with the DNS server, insecure updates can be sent by setting this " @@ -9961,17 +10289,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:224 sssd-ad.5.xml:1314 +#: sssd-ipa.5.xml:219 sssd-ad.5.xml:1307 msgid "Default: GSS-TSIG" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:230 sssd-ad.5.xml:1320 +#: sssd-ipa.5.xml:225 sssd-ad.5.xml:1313 msgid "dyndns_auth_ptr (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:233 sssd-ad.5.xml:1323 +#: sssd-ipa.5.xml:228 sssd-ad.5.xml:1316 msgid "" "Whether the nsupdate utility should use GSS-TSIG authentication for secure " "PTR updates with the DNS server, insecure updates can be sent by setting " @@ -9979,17 +10307,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:239 sssd-ad.5.xml:1329 +#: sssd-ipa.5.xml:234 sssd-ad.5.xml:1322 msgid "Default: Same as dyndns_auth" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:245 sssd-ad.5.xml:1255 +#: sssd-ipa.5.xml:240 sssd-ad.5.xml:1249 msgid "dyndns_refresh_interval (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:248 +#: sssd-ipa.5.xml:243 msgid "" "How often should the back end perform periodic DNS update in addition to the " "automatic update performed when the back end goes online. This option is " @@ -9997,74 +10325,76 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:261 sssd-ad.5.xml:1273 -msgid "dyndns_update_ptr (bool)" -msgstr "" +#: sssd-ipa.5.xml:256 sssd-ad.5.xml:1266 +#, fuzzy +#| msgid "re_expression (string)" +msgid "dyndns_update_ptr (boolean)" +msgstr "re_expression (neudennad)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:264 sssd-ad.5.xml:1276 +#: sssd-ipa.5.xml:259 sssd-ad.5.xml:1269 msgid "" "Whether the PTR record should also be explicitly updated when updating the " "client's DNS records. Applicable only when dyndns_update is true." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:269 +#: sssd-ipa.5.xml:264 msgid "" "This option should be False in most IPA deployments as the IPA server " "generates the PTR records automatically when forward records are changed." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:275 sssd-ad.5.xml:1281 +#: sssd-ipa.5.xml:270 sssd-ad.5.xml:1274 msgid "" "Note that <emphasis>dyndns_update_per_family</emphasis> parameter does not " "apply for PTR record updates. Those updates are always sent separately." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:280 +#: sssd-ipa.5.xml:275 msgid "Default: False (disabled)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:286 sssd-ad.5.xml:1292 -msgid "dyndns_force_tcp (bool)" +#: sssd-ipa.5.xml:281 sssd-ad.5.xml:1285 +msgid "dyndns_force_tcp (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:289 sssd-ad.5.xml:1295 +#: sssd-ipa.5.xml:284 sssd-ad.5.xml:1288 msgid "" "Whether the nsupdate utility should default to using TCP for communicating " "with the DNS server." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:293 sssd-ad.5.xml:1299 +#: sssd-ipa.5.xml:288 sssd-ad.5.xml:1292 msgid "Default: False (let nsupdate choose the protocol)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:299 sssd-ad.5.xml:1335 +#: sssd-ipa.5.xml:294 sssd-ad.5.xml:1328 msgid "dyndns_server (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:302 sssd-ad.5.xml:1338 +#: sssd-ipa.5.xml:297 sssd-ad.5.xml:1331 msgid "" "The DNS server to use when performing a DNS update. In most setups, it's " "recommended to leave this option unset." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:307 sssd-ad.5.xml:1343 +#: sssd-ipa.5.xml:302 sssd-ad.5.xml:1336 msgid "" "Setting this option makes sense for environments where the DNS server is " "different from the identity server or when we use encrypted DNS." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:312 sssd-ad.5.xml:1348 +#: sssd-ipa.5.xml:307 sssd-ad.5.xml:1341 msgid "" "The parameter can be a simple string containing DNS name or IP address. It " "can also be an URI. The URI can look like <emphasis>dns://servername/</" @@ -10072,7 +10402,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:319 sssd-ad.5.xml:1355 +#: sssd-ipa.5.xml:314 sssd-ad.5.xml:1348 msgid "" "The second example enables DNS-over-TLS protocol for DNS updates. The " "nsupdate utility must support DoT - check the <emphasis>man nsupdate</" @@ -10080,7 +10410,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:325 sssd-ad.5.xml:1361 +#: sssd-ipa.5.xml:320 sssd-ad.5.xml:1354 msgid "" "Please note that this option will be only used in fallback attempt when " "previous attempt using autodetected settings failed or when DNS-over-TLS is " @@ -10088,17 +10418,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:331 sssd-ad.5.xml:1367 +#: sssd-ipa.5.xml:326 sssd-ad.5.xml:1360 msgid "Default: None (let nsupdate choose the server)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:337 sssd-ad.5.xml:1373 +#: sssd-ipa.5.xml:332 sssd-ad.5.xml:1366 msgid "dyndns_update_per_family (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:340 sssd-ad.5.xml:1376 +#: sssd-ipa.5.xml:335 sssd-ad.5.xml:1369 msgid "" "DNS update is by default performed in two steps - IPv4 update and then IPv6 " "update. In some cases it might be desirable to perform IPv4 and IPv6 update " @@ -10106,12 +10436,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:352 sssd-ad.5.xml:1388 +#: sssd-ipa.5.xml:347 sssd-ad.5.xml:1381 msgid "dyndns_dot_cacert (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:355 sssd-ad.5.xml:1391 +#: sssd-ipa.5.xml:350 sssd-ad.5.xml:1384 msgid "" "This option specifies the file of the certificate authorities certificates " "(in PEM format) in order to verify the remote server TLS certificate when " @@ -10119,17 +10449,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:361 sssd-ad.5.xml:1397 +#: sssd-ipa.5.xml:356 sssd-ad.5.xml:1390 msgid "Default: None (use global certificate store)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:367 sssd-ad.5.xml:1403 +#: sssd-ipa.5.xml:362 sssd-ad.5.xml:1396 msgid "dyndns_dot_cert (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:370 sssd-ad.5.xml:1406 +#: sssd-ipa.5.xml:365 sssd-ad.5.xml:1399 msgid "" "This option sets the certificate(s) file for authentication for the DoT " "transport to the remote server. The certificate chain file is expected to be " @@ -10137,26 +10467,26 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:376 sssd-ad.5.xml:1412 +#: sssd-ipa.5.xml:371 sssd-ad.5.xml:1405 msgid "" "The <emphasis>dyndns_dot_cert</emphasis> and <emphasis>dyndns_dot_key</" "emphasis> options must be both set to achieve mutual TLS authentication." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:381 sssd-ipa.5.xml:396 sssd-ad.5.xml:1417 sssd-ad.5.xml:1432 +#: sssd-ipa.5.xml:376 sssd-ipa.5.xml:391 sssd-ad.5.xml:1410 sssd-ad.5.xml:1425 msgid "Default: None (Do not use TLS authentication)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:387 sssd-ad.5.xml:1423 +#: sssd-ipa.5.xml:382 sssd-ad.5.xml:1416 #, fuzzy #| msgid "re_expression (string)" msgid "dyndns_dot_key (string)" msgstr "re_expression (neudennad)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:390 sssd-ad.5.xml:1426 +#: sssd-ipa.5.xml:385 sssd-ad.5.xml:1419 msgid "" "This option sets the key file for authenticated encryption for the DoT " "transport to the remote server. The private key file is expected to be in " @@ -10164,172 +10494,172 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:402 +#: sssd-ipa.5.xml:397 #, fuzzy #| msgid "re_expression (string)" msgid "ipa_access_order (string)" msgstr "re_expression (neudennad)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:409 +#: sssd-ipa.5.xml:404 msgid "<emphasis>expire</emphasis>: use IPA's account expiration policy." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:448 +#: sssd-ipa.5.xml:443 msgid "" "Please note that 'access_provider = ipa' must be set for this feature to " "work." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:455 +#: sssd-ipa.5.xml:450 msgid "ipa_deskprofile_search_base (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:458 +#: sssd-ipa.5.xml:453 msgid "" "Optional. Use the given string as search base for Desktop Profile related " "objects." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:462 sssd-ipa.5.xml:484 +#: sssd-ipa.5.xml:457 sssd-ipa.5.xml:479 msgid "Default: Use base DN" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:468 +#: sssd-ipa.5.xml:463 msgid "ipa_subid_ranges_search_base (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:471 +#: sssd-ipa.5.xml:466 msgid "Deprecated. Use ldap_subid_ranges_search_base instead." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:477 +#: sssd-ipa.5.xml:472 msgid "ipa_hbac_search_base (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:480 +#: sssd-ipa.5.xml:475 msgid "Optional. Use the given string as search base for HBAC related objects." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:490 +#: sssd-ipa.5.xml:485 msgid "ipa_host_search_base (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:493 +#: sssd-ipa.5.xml:488 msgid "Deprecated. Use ldap_host_search_base instead." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:499 +#: sssd-ipa.5.xml:494 msgid "ipa_selinux_search_base (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:502 +#: sssd-ipa.5.xml:497 msgid "Optional. Use the given string as search base for SELinux user maps." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:518 +#: sssd-ipa.5.xml:513 msgid "ipa_subdomains_search_base (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:521 +#: sssd-ipa.5.xml:516 msgid "Optional. Use the given string as search base for trusted domains." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:530 +#: sssd-ipa.5.xml:525 msgid "Default: the value of <emphasis>cn=trusts,%basedn</emphasis>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:537 +#: sssd-ipa.5.xml:532 msgid "ipa_master_domain_search_base (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:540 +#: sssd-ipa.5.xml:535 msgid "Optional. Use the given string as search base for master domain object." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:549 +#: sssd-ipa.5.xml:544 msgid "Default: the value of <emphasis>cn=ad,cn=etc,%basedn</emphasis>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:556 +#: sssd-ipa.5.xml:551 msgid "ipa_views_search_base (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:559 +#: sssd-ipa.5.xml:554 msgid "Optional. Use the given string as search base for views containers." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:568 +#: sssd-ipa.5.xml:563 msgid "Default: the value of <emphasis>cn=views,cn=accounts,%basedn</emphasis>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:578 +#: sssd-ipa.5.xml:573 msgid "" "The name of the Kerberos realm. This is optional and defaults to the value " "of <quote>ipa_domain</quote>." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:582 +#: sssd-ipa.5.xml:577 msgid "" "The name of the Kerberos realm has a special meaning in IPA - it is " "converted into the base DN to use for performing LDAP operations." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:590 sssd-ad.5.xml:1441 +#: sssd-ipa.5.xml:585 sssd-ad.5.xml:1434 msgid "krb5_confd_path (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:593 sssd-ad.5.xml:1444 +#: sssd-ipa.5.xml:588 sssd-ad.5.xml:1437 msgid "" "Absolute path of a directory where SSSD should place Kerberos configuration " "snippets." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:597 sssd-ad.5.xml:1448 +#: sssd-ipa.5.xml:592 sssd-ad.5.xml:1441 msgid "" "To disable the creation of the configuration snippets set the parameter to " "'none'." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:601 sssd-ad.5.xml:1452 +#: sssd-ipa.5.xml:596 sssd-ad.5.xml:1445 msgid "" "Default: not set (krb5.include.d subdirectory of SSSD's pubconf directory)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:608 +#: sssd-ipa.5.xml:603 msgid "ipa_deskprofile_refresh (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:611 +#: sssd-ipa.5.xml:606 msgid "" "The amount of time between lookups of the Desktop Profile rules against the " "IPA server. This will reduce the latency and load on the IPA server if there " @@ -10337,34 +10667,34 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:618 sssd-ipa.5.xml:648 sssd-ipa.5.xml:664 sssd-ad.5.xml:600 +#: sssd-ipa.5.xml:613 sssd-ipa.5.xml:643 sssd-ipa.5.xml:659 sssd-ad.5.xml:600 msgid "Default: 5 (seconds)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:624 +#: sssd-ipa.5.xml:619 msgid "ipa_deskprofile_request_interval (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:627 +#: sssd-ipa.5.xml:622 msgid "" "The amount of time between lookups of the Desktop Profile rules against the " "IPA server in case the last request did not return any rule." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:632 +#: sssd-ipa.5.xml:627 msgid "Default: 60 (minutes)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:638 +#: sssd-ipa.5.xml:633 msgid "ipa_hbac_refresh (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:641 +#: sssd-ipa.5.xml:636 msgid "" "The amount of time between lookups of the HBAC rules against the IPA server. " "This will reduce the latency and load on the IPA server if there are many " @@ -10372,12 +10702,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:654 -msgid "ipa_hbac_selinux (integer)" +#: sssd-ipa.5.xml:649 +msgid "ipa_selinux_refresh (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:657 +#: sssd-ipa.5.xml:652 msgid "" "The amount of time between lookups of the SELinux maps against the IPA " "server. This will reduce the latency and load on the IPA server if there are " @@ -10385,33 +10715,33 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:670 +#: sssd-ipa.5.xml:665 msgid "ipa_server_mode (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:673 +#: sssd-ipa.5.xml:668 msgid "" "This option will be set by the IPA installer (ipa-server-install) " "automatically and denotes if SSSD is running on an IPA server or not." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:678 +#: sssd-ipa.5.xml:673 msgid "" "On an IPA server SSSD will lookup users and groups from trusted domains " "directly while on a client it will ask an IPA server." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:683 +#: sssd-ipa.5.xml:678 msgid "" "NOTE: There are currently some assumptions that must be met when SSSD is " "running on an IPA server." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:688 +#: sssd-ipa.5.xml:683 msgid "" "The <quote>ipa_server</quote> option must be configured to point to the IPA " "server itself. This is already the default set by the IPA installer, so no " @@ -10419,59 +10749,59 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:697 +#: sssd-ipa.5.xml:692 msgid "" "The <quote>full_name_format</quote> option must not be tweaked to only print " "short names for users from trusted domains." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:712 +#: sssd-ipa.5.xml:707 msgid "ipa_automount_location (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:715 +#: sssd-ipa.5.xml:710 msgid "The automounter location this IPA client will be using" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:718 +#: sssd-ipa.5.xml:713 msgid "Default: The location named \"default\"" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd-ipa.5.xml:726 +#: sssd-ipa.5.xml:721 msgid "VIEWS AND OVERRIDES" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:735 +#: sssd-ipa.5.xml:730 msgid "ipa_view_class (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:738 +#: sssd-ipa.5.xml:733 msgid "Objectclass of the view container." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:741 +#: sssd-ipa.5.xml:736 msgid "Default: nsContainer" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:747 +#: sssd-ipa.5.xml:742 msgid "ipa_view_name (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:750 +#: sssd-ipa.5.xml:745 msgid "Name of the attribute holding the name of the view." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:754 sssd-ldap-attributes.5.xml:496 +#: sssd-ipa.5.xml:749 sssd-ldap-attributes.5.xml:496 #: sssd-ldap-attributes.5.xml:832 sssd-ldap-attributes.5.xml:913 #: sssd-ldap-attributes.5.xml:1010 sssd-ldap-attributes.5.xml:1068 #: sssd-ldap-attributes.5.xml:1226 sssd-ldap-attributes.5.xml:1271 @@ -10479,128 +10809,128 @@ msgid "Default: cn" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:760 +#: sssd-ipa.5.xml:755 msgid "ipa_override_object_class (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:763 +#: sssd-ipa.5.xml:758 msgid "Objectclass of the override objects." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:766 +#: sssd-ipa.5.xml:761 msgid "Default: ipaOverrideAnchor" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:772 +#: sssd-ipa.5.xml:767 msgid "ipa_anchor_uuid (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:775 +#: sssd-ipa.5.xml:770 msgid "" "Name of the attribute containing the reference to the original object in a " "remote domain." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:779 +#: sssd-ipa.5.xml:774 msgid "Default: ipaAnchorUUID" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:785 +#: sssd-ipa.5.xml:780 msgid "ipa_user_override_object_class (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:788 +#: sssd-ipa.5.xml:783 msgid "" "Name of the objectclass for user overrides. It is used to determine if the " "found override object is related to a user or a group." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:793 +#: sssd-ipa.5.xml:788 msgid "User overrides can contain attributes given by" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:796 +#: sssd-ipa.5.xml:791 msgid "ldap_user_name" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:799 +#: sssd-ipa.5.xml:794 msgid "ldap_user_uid_number" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:802 +#: sssd-ipa.5.xml:797 msgid "ldap_user_gid_number" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:805 +#: sssd-ipa.5.xml:800 msgid "ldap_user_gecos" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:808 +#: sssd-ipa.5.xml:803 msgid "ldap_user_home_directory" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:811 +#: sssd-ipa.5.xml:806 msgid "ldap_user_shell" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:814 +#: sssd-ipa.5.xml:809 msgid "ldap_user_ssh_public_key" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:819 +#: sssd-ipa.5.xml:814 msgid "Default: ipaUserOverride" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:825 +#: sssd-ipa.5.xml:820 msgid "ipa_group_override_object_class (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:828 +#: sssd-ipa.5.xml:823 msgid "" "Name of the objectclass for group overrides. It is used to determine if the " "found override object is related to a user or a group." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:833 +#: sssd-ipa.5.xml:828 msgid "Group overrides can contain attributes given by" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:836 +#: sssd-ipa.5.xml:831 msgid "ldap_group_name" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:839 +#: sssd-ipa.5.xml:834 msgid "ldap_group_gid_number" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:844 +#: sssd-ipa.5.xml:839 msgid "Default: ipaGroupOverride" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:728 +#: sssd-ipa.5.xml:723 msgid "" "SSSD can handle views and overrides which are offered by FreeIPA 4.1 and " "later version. Since all paths and objectclasses are fixed on the server " @@ -10610,19 +10940,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd-ipa.5.xml:856 +#: sssd-ipa.5.xml:851 msgid "SUBDOMAINS PROVIDER" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:858 +#: sssd-ipa.5.xml:853 msgid "" "The IPA subdomains provider behaves slightly differently if it is configured " "explicitly or implicitly." msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:862 +#: sssd-ipa.5.xml:857 msgid "" "If the option 'subdomains_provider = ipa' is found in the domain section of " "sssd.conf, the IPA subdomains provider is configured explicitly, and all " @@ -10630,7 +10960,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:868 +#: sssd-ipa.5.xml:863 msgid "" "If the option 'subdomains_provider' is not set in the domain section of " "sssd.conf but there is the option 'id_provider = ipa', the IPA subdomains " @@ -10642,12 +10972,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd-ipa.5.xml:879 +#: sssd-ipa.5.xml:874 msgid "TRUSTED DOMAINS CONFIGURATION" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-ipa.5.xml:887 +#: sssd-ipa.5.xml:882 #, no-wrap msgid "" "[domain/ipa.domain.com/ad.domain.com]\n" @@ -10655,7 +10985,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:881 +#: sssd-ipa.5.xml:876 msgid "" "Some configuration options can also be set for a trusted domain. A trusted " "domain configuration can be set using the trusted domain subsection as shown " @@ -10665,97 +10995,97 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:892 +#: sssd-ipa.5.xml:887 msgid "" "For more details, see the <citerefentry> <refentrytitle>sssd.conf</" "refentrytitle> <manvolnum>5</manvolnum> </citerefentry> manual page." msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:899 +#: sssd-ipa.5.xml:894 msgid "" "Different configuration options are tunable for a trusted domain depending " "on whether you are configuring SSSD on an IPA server or an IPA client." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd-ipa.5.xml:904 +#: sssd-ipa.5.xml:899 msgid "OPTIONS TUNABLE ON IPA MASTERS" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:906 +#: sssd-ipa.5.xml:901 msgid "" "The following options can be set in a subdomain section on an IPA master:" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:910 sssd-ipa.5.xml:950 +#: sssd-ipa.5.xml:905 sssd-ipa.5.xml:945 msgid "ad_server" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:913 +#: sssd-ipa.5.xml:908 msgid "ad_backup_server" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:916 sssd-ipa.5.xml:953 +#: sssd-ipa.5.xml:911 sssd-ipa.5.xml:948 msgid "ad_site" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:919 +#: sssd-ipa.5.xml:914 msgid "ipa_server" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:922 +#: sssd-ipa.5.xml:917 msgid "ipa_backup_server" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:925 +#: sssd-ipa.5.xml:920 msgid "ldap_search_base" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:928 +#: sssd-ipa.5.xml:923 msgid "ldap_user_search_base" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:931 +#: sssd-ipa.5.xml:926 msgid "ldap_group_search_base" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:939 +#: sssd-ipa.5.xml:934 msgid "" "Options prefixed with 'ad_' or 'ipa_' only apply to their respective " "subdomain type." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd-ipa.5.xml:944 +#: sssd-ipa.5.xml:939 msgid "OPTIONS TUNABLE ON IPA CLIENTS" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:946 +#: sssd-ipa.5.xml:941 msgid "" "The following options can be set in an AD subdomain section on an IPA client:" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:958 +#: sssd-ipa.5.xml:953 msgid "" "Note that if both options are set, only <quote>ad_server</quote> is " "evaluated." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:962 +#: sssd-ipa.5.xml:957 msgid "" "Since any request for a user or a group identity from a trusted domain " "triggered from an IPA client is resolved by the IPA server, the " @@ -10769,7 +11099,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:986 +#: sssd-ipa.5.xml:981 msgid "" "The following example assumes that SSSD is correctly configured and " "example.com is one of the domains in the <replaceable>[sssd]</replaceable> " @@ -10777,7 +11107,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-ipa.5.xml:993 +#: sssd-ipa.5.xml:988 #, no-wrap msgid "" "[domain/example.com]\n" @@ -11476,27 +11806,27 @@ msgid "lxdm" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:694 +#: sssd-ad.5.xml:699 msgid "sddm" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:699 +#: sssd-ad.5.xml:704 msgid "unity" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:704 +#: sssd-ad.5.xml:709 msgid "xdm" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:713 +#: sssd-ad.5.xml:718 msgid "ad_gpo_map_remote_interactive (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:716 +#: sssd-ad.5.xml:721 msgid "" "A comma-separated list of PAM service names for which GPO-based access " "control is evaluated based on the RemoteInteractiveLogonRight and " @@ -11512,7 +11842,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:735 +#: sssd-ad.5.xml:740 msgid "" "Note: Using the Group Policy Management Editor this value is called \"Allow " "log on through Remote Desktop Services\" and \"Deny log on through Remote " @@ -11520,7 +11850,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:750 +#: sssd-ad.5.xml:755 #, no-wrap msgid "" "ad_gpo_map_remote_interactive = +my_pam_service, -sshd\n" @@ -11528,7 +11858,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:741 +#: sssd-ad.5.xml:746 msgid "" "It is possible to add another PAM service name to the default set by using " "<quote>+service_name</quote> or to explicitly remove a PAM service name from " @@ -11540,22 +11870,22 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:758 +#: sssd-ad.5.xml:763 msgid "sshd" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:763 +#: sssd-ad.5.xml:768 msgid "cockpit" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:772 +#: sssd-ad.5.xml:777 msgid "ad_gpo_map_network (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:775 +#: sssd-ad.5.xml:780 msgid "" "A comma-separated list of PAM service names for which GPO-based access " "control is evaluated based on the NetworkLogonRight and " @@ -11571,7 +11901,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:793 +#: sssd-ad.5.xml:798 msgid "" "Note: Using the Group Policy Management Editor this value is called \"Access " "this computer from the network\" and \"Deny access to this computer from the " @@ -11579,7 +11909,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:808 +#: sssd-ad.5.xml:813 #, no-wrap msgid "" "ad_gpo_map_network = +my_pam_service, -ftp\n" @@ -11587,7 +11917,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:799 +#: sssd-ad.5.xml:804 msgid "" "It is possible to add another PAM service name to the default set by using " "<quote>+service_name</quote> or to explicitly remove a PAM service name from " @@ -11599,22 +11929,22 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:816 +#: sssd-ad.5.xml:821 msgid "ftp" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:821 +#: sssd-ad.5.xml:826 msgid "samba" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:830 +#: sssd-ad.5.xml:835 msgid "ad_gpo_map_batch (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:833 +#: sssd-ad.5.xml:838 msgid "" "A comma-separated list of PAM service names for which GPO-based access " "control is evaluated based on the BatchLogonRight and DenyBatchLogonRight " @@ -11629,14 +11959,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:851 +#: sssd-ad.5.xml:856 msgid "" "Note: Using the Group Policy Management Editor this value is called \"Allow " "log on as a batch job\" and \"Deny log on as a batch job\"." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:865 +#: sssd-ad.5.xml:870 #, no-wrap msgid "" "ad_gpo_map_batch = +my_pam_service, -crond\n" @@ -11644,7 +11974,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:856 +#: sssd-ad.5.xml:861 msgid "" "It is possible to add another PAM service name to the default set by using " "<quote>+service_name</quote> or to explicitly remove a PAM service name from " @@ -11656,23 +11986,23 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:868 +#: sssd-ad.5.xml:873 msgid "" "Note: Cron service name may differ depending on Linux distribution used." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:874 +#: sssd-ad.5.xml:879 msgid "crond" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:883 +#: sssd-ad.5.xml:888 msgid "ad_gpo_map_service (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:886 +#: sssd-ad.5.xml:891 msgid "" "A comma-separated list of PAM service names for which GPO-based access " "control is evaluated based on the ServiceLogonRight and " @@ -11688,14 +12018,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:904 +#: sssd-ad.5.xml:909 msgid "" "Note: Using the Group Policy Management Editor this value is called \"Allow " "log on as a service\" and \"Deny log on as a service\"." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:917 +#: sssd-ad.5.xml:922 #, no-wrap msgid "" "ad_gpo_map_service = +my_pam_service\n" @@ -11703,7 +12033,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:909 sssd-ad.5.xml:984 +#: sssd-ad.5.xml:914 sssd-ad.5.xml:989 msgid "" "It is possible to add a PAM service name to the default set by using " "<quote>+service_name</quote>. Since the default set is empty, it is not " @@ -11714,19 +12044,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:927 +#: sssd-ad.5.xml:932 msgid "ad_gpo_map_permit (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:930 +#: sssd-ad.5.xml:935 msgid "" "A comma-separated list of PAM service names for which GPO-based access is " "always granted, regardless of any GPO Logon Rights." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:944 +#: sssd-ad.5.xml:949 #, no-wrap msgid "" "ad_gpo_map_permit = +my_pam_service, -sudo\n" @@ -11734,7 +12064,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:935 +#: sssd-ad.5.xml:940 msgid "" "It is possible to add another PAM service name to the default set by using " "<quote>+service_name</quote> or to explicitly remove a PAM service name from " @@ -11746,29 +12076,29 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:952 +#: sssd-ad.5.xml:957 msgid "polkit-1" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:967 +#: sssd-ad.5.xml:972 msgid "systemd-user" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:976 +#: sssd-ad.5.xml:981 msgid "ad_gpo_map_deny (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:979 +#: sssd-ad.5.xml:984 msgid "" "A comma-separated list of PAM service names for which GPO-based access is " "always denied, regardless of any GPO Logon Rights." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:992 +#: sssd-ad.5.xml:997 #, no-wrap msgid "" "ad_gpo_map_deny = +my_pam_service\n" @@ -11776,12 +12106,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:1002 +#: sssd-ad.5.xml:1007 msgid "ad_gpo_default_right (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1005 +#: sssd-ad.5.xml:1010 msgid "" "This option defines how access control is evaluated for PAM service names " "that are not explicitly listed in one of the ad_gpo_map_* options. This " @@ -11794,52 +12124,52 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1018 +#: sssd-ad.5.xml:1023 msgid "Supported values for this option include:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1027 +#: sssd-ad.5.xml:1032 msgid "remote_interactive" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1032 +#: sssd-ad.5.xml:1037 msgid "network" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1037 +#: sssd-ad.5.xml:1042 msgid "batch" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1042 +#: sssd-ad.5.xml:1047 msgid "service" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1047 +#: sssd-ad.5.xml:1052 msgid "permit" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1052 +#: sssd-ad.5.xml:1057 msgid "deny" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1058 +#: sssd-ad.5.xml:1063 msgid "Default: deny" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:1064 +#: sssd-ad.5.xml:1069 msgid "ad_maximum_machine_account_password_age (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1067 +#: sssd-ad.5.xml:1072 msgid "" "SSSD will check once a day if the machine account password is older than the " "given age in days and try to renew it. A value of 0 will disable the renewal " @@ -11847,17 +12177,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1073 +#: sssd-ad.5.xml:1078 msgid "Default: 30 days" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:1079 +#: sssd-ad.5.xml:1084 msgid "ad_machine_account_password_renewal_opts (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1082 +#: sssd-ad.5.xml:1087 msgid "" "This option should only be used to test the machine account renewal task. " "The option expects 3 integers and a string separated by a colon (':'). The " @@ -11870,20 +12200,20 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1096 +#: sssd-ad.5.xml:1101 msgid "" "The optional fourth string value identifies the helper binary which should " "be used for the renewal. Currently <command>adcli</command> and " "<command>realm</command> are supported. If this value is missing or empty in " "the value string <command>realm</command> will be used. Since the helper is " "started as the user SSSD is running as there might be the chance that the " -"renewal will fail if this user does not has permissions to modify the keytab " -"file where the machine account credentials are stored. This will typically " -"be the case for <command>adcli</command>." +"renewal will fail if this user does not have permissions to modify the " +"keytab file where the machine account credentials are stored. This will " +"typically be the case for <command>adcli</command>." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1110 +#: sssd-ad.5.xml:1115 msgid "" "<command>realm</command> is not updating the keytab directly but is calling " "the <command>realmd</command> process, which runs as root user, for this " @@ -11893,17 +12223,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1119 +#: sssd-ad.5.xml:1124 msgid "Default: 86400:750:300:realm (24h, 12m30s and 5m)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:1125 +#: sssd-ad.5.xml:1130 msgid "ad_update_samba_machine_account_password (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1128 +#: sssd-ad.5.xml:1133 msgid "" "If enabled, when SSSD renews the machine account password, it will also be " "updated in Samba's database. This prevents Samba's copy of the machine " @@ -11912,23 +12242,25 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:1141 -msgid "ad_use_ldaps (bool)" -msgstr "" +#: sssd-ad.5.xml:1146 +#, fuzzy +#| msgid "re_expression (string)" +msgid "ad_use_ldaps (boolean)" +msgstr "re_expression (neudennad)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1144 +#: sssd-ad.5.xml:1149 msgid "" "By default SSSD uses the plain LDAP port 389 and the Global Catalog port " -"3628. If this option is set to True SSSD will use the LDAPS port 636 and " -"Global Catalog port 3629 with LDAPS protection. Since AD does not allow to " +"3268. If this option is set to True SSSD will use the LDAPS port 636 and " +"Global Catalog port 3269 with LDAPS protection. Since AD does not allow to " "have multiple encryption layers on a single connection and we still want to " "use SASL/GSSAPI or SASL/GSS-SPNEGO for authentication the SASL security " "property maxssf is set to 0 (zero) for those connections." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1164 +#: sssd-ad.5.xml:1169 msgid "" "Optional. This option tells SSSD to automatically update the Active " "Directory DNS server with the IP address of this client. The update is " @@ -11946,30 +12278,21 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:1216 msgid "" -"NOTE: While it is still possible to use the old <emphasis>ipa_dyndns_iface</" -"emphasis> option, users should migrate to using <emphasis>dyndns_iface</" -"emphasis> in their config file." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1222 -msgid "" "Default: Use the IP addresses of the interface which is used for AD LDAP " "connection" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1258 +#: sssd-ad.5.xml:1252 msgid "" "How often should the back end perform periodic DNS update in addition to the " -"automatic update performed when the back end goes online. This option is " -"optional and applicable only when dyndns_update is true. Note that the " -"lowest possible value is 60 seconds in-case if value is provided less than " -"60, parameter will assume lowest value only." +"automatic update performed when the back end goes online. This is optional " +"and applicable only when dyndns_update is true. Note that the minimum value " +"is 60 seconds, any specified value below this threshold will default to 60." msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ad.5.xml:1472 +#: sssd-ad.5.xml:1465 msgid "" "The following example assumes that SSSD is correctly configured and " "example.com is one of the domains in the <replaceable>[sssd]</replaceable> " @@ -11977,7 +12300,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-ad.5.xml:1479 +#: sssd-ad.5.xml:1472 #, no-wrap msgid "" "[domain/EXAMPLE]\n" @@ -11992,7 +12315,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-ad.5.xml:1499 +#: sssd-ad.5.xml:1492 #, no-wrap msgid "" "access_provider = ldap\n" @@ -12001,7 +12324,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ad.5.xml:1495 +#: sssd-ad.5.xml:1488 msgid "" "The AD access control provider checks if the account is expired. It has the " "same effect as the following configuration of the LDAP provider: " @@ -12009,7 +12332,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ad.5.xml:1505 +#: sssd-ad.5.xml:1498 msgid "" "However, unless the <quote>ad</quote> access control provider is explicitly " "configured, the default access provider is <quote>permit</quote>. Please " @@ -12019,7 +12342,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ad.5.xml:1513 +#: sssd-ad.5.xml:1506 msgid "" "When the autofs provider is set to <quote>ad</quote>, the RFC2307 schema " "attribute mapping (nisMap, nisObject, ...) is used, because these attributes " @@ -12173,9 +12496,9 @@ msgstr "" #: sssd-sudo.5.xml:137 msgid "" "The <emphasis>smart refresh</emphasis> periodically downloads rules that are " -"new or were modified after the last update. Its primary goal is to keep the " -"database growing by fetching only small increments that do not generate " -"large amounts of network traffic." +"new or were modified after the last update. Its primary goal is to grow the " +"database incrementally by fetching only small updates, avoiding large " +"amounts of network traffic." msgstr "" #. type: Content of: <reference><refentry><refsect1><para> @@ -12357,26 +12680,29 @@ msgstr "" msgid "" "Depending on the IdP product additional platform specific options might " "follow the name separated by a colon (:). E.g. for Keycloak the base URI for " -"the user and group REST API must be given. For Entra ID this is not needed " -"because there is a generic endpoint for all tenants." +"the user and group REST API must be given. For Entra ID the base URI for the " +"Microsoft Graph API can be given to use sovereign or government cloud " +"endpoints instead of the default (https://graph.microsoft.com/v1.0). E.g. " +"<quote>entra_id:https://graph.microsoft.us/v1.0</quote> for the US " +"government cloud (GCC High)." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:78 sssd-idp.5.xml:94 sssd-idp.5.xml:119 +#: sssd-idp.5.xml:82 sssd-idp.5.xml:98 sssd-idp.5.xml:123 #, fuzzy #| msgid "Default: true" msgid "Default: Not set (Required)" msgstr "Dre ziouer : true" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:83 +#: sssd-idp.5.xml:87 #, fuzzy #| msgid "re_expression (string)" msgid "idp_client_id (string)" msgstr "re_expression (neudennad)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:86 +#: sssd-idp.5.xml:90 msgid "" "ID of the IdP client used by SSSD to authenticate users and as a client to " "lookup user and group attributes. This client must offer device " @@ -12385,14 +12711,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:99 +#: sssd-idp.5.xml:103 #, fuzzy #| msgid "re_expression (string)" msgid "idp_client_secret (string)" msgstr "re_expression (neudennad)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:102 +#: sssd-idp.5.xml:106 msgid "" "Password of the IdP client. The password is required for the id_provider. If " "only used as auth_provider it depends on the server side configuration if it " @@ -12400,76 +12726,83 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:113 +#: sssd-idp.5.xml:117 #, fuzzy #| msgid "re_expression (string)" msgid "idp_token_endpoint (string)" msgstr "re_expression (neudennad)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:116 +#: sssd-idp.5.xml:120 msgid "IdP endpoint for requesting access tokens." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:124 +#: sssd-idp.5.xml:128 #, fuzzy #| msgid "re_expression (string)" msgid "idp_device_auth_endpoint (string)" msgstr "re_expression (neudennad)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:127 +#: sssd-idp.5.xml:131 msgid "" "IdP endpoint for device authorization according to RFC-8628. This is " "required for user authentication." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:137 +#: sssd-idp.5.xml:141 #, fuzzy #| msgid "re_expression (string)" msgid "idp_userinfo_endpoint (string)" msgstr "re_expression (neudennad)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:140 +#: sssd-idp.5.xml:144 msgid "" "IdP userinfo endpoint to request user attributes after a successful " "authentication of the user. Required for authentication." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:150 +#: sssd-idp.5.xml:154 #, fuzzy #| msgid "re_expression (string)" msgid "idp_id_scope (string)" msgstr "re_expression (neudennad)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:153 +#: sssd-idp.5.xml:157 msgid "" "Scope required for looking up user and group attributes with the REST API. " "The scopes are used by the server to determine which attributes/claims are " "returned to the caller." msgstr "" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:163 +msgid "" +"Note: In previous versions of SSSD, this option was expected to already be " +"URL-encoded." +msgstr "" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:164 +#: sssd-idp.5.xml:172 #, fuzzy #| msgid "re_expression (string)" msgid "idp_auth_scope (string)" msgstr "re_expression (neudennad)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:167 +#: sssd-idp.5.xml:175 msgid "" "Scope required during authentication. The scopes are used by the server to " "determine which attributes/claims are returned to the caller." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:172 +#: sssd-idp.5.xml:180 msgid "" "Currently the tokens returned during user authentication are not used for " "other purposes hence the only important claim is the subject identifier " @@ -12478,22 +12811,118 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:185 +#: sssd-idp.5.xml:193 +#, fuzzy +#| msgid "re_expression (string)" +msgid "idp_auth_user_identifier_attr (string)" +msgstr "re_expression (neudennad)" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:196 +msgid "" +"Attribute used to identify the authenticated user in userinfo data or token " +"claims." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:200 +msgid "" +"For hybrid Active Directory and Entra ID deployments where " +"<quote>id_provider = ad</quote> and <quote>auth_provider = idp</quote>, this " +"option must be set explicitly. No value is derived from the identity " +"provider, because more than one attribute can link an Entra ID object to its " +"on-premises counterpart and only the administrator knows which one the " +"directory synchronization is configured to use." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:211 +msgid "" +"Setting this option to <quote>onPremisesImmutableId</quote> is the usual " +"choice for such deployments. Microsoft Entra Connect populates that " +"attribute with the base64-encoded form of the 16-byte Active Directory " +"<quote>objectGUID</quote> when objectGUID is used as the sourceAnchor. SSSD " +"decodes the value and converts the raw bytes with the same conversion used " +"for AD objectGUID attributes, so the result matches the UUID stored in the " +"SSSD cache for the AD user." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:224 +msgid "" +"Note that Microsoft Entra Connect 1.1.524.0 and later use <quote>ms-DS-" +"ConsistencyGuid</quote> as the sourceAnchor for user objects instead of " +"<quote>objectGUID</quote>. The value is normally copied from objectGUID for " +"objects that do not have it set yet, in which case the decoded identifier " +"still matches. It does not match if ms-DS-ConsistencyGuid was populated " +"independently, if users were moved between forests or domains, or if a " +"different attribute such as employeeID was selected as the sourceAnchor. See " +"<ulink url=\"https://learn.microsoft.com/en-us/entra/identity/hybrid/connect/" +"plan-connect-design-concepts\"> Microsoft Entra Connect: Design concepts</" +"ulink> for details on sourceAnchor selection." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:241 +msgid "" +"Microsoft Graph does not return <quote>onPremisesImmutableId</quote> by " +"default. The <quote>idp_userinfo_endpoint</quote> must request it with " +"<quote>$select</quote>, see the example below and <ulink url=\"https://" +"learn.microsoft.com/en-us/graph/api/resources/user\"> the Microsoft Graph " +"user resource type</ulink>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:251 +msgid "" +"If the configured attribute is missing or cannot be decoded (for example " +"cloud-only Entra ID users without <quote>onPremisesImmutableId</quote>), " +"authentication fails. SSSD does not fall back to another attribute when this " +"option is set." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:258 +msgid "" +"Default: not set, <quote>sub</quote> for Keycloak and <quote>id</quote> for " +"other IdP types" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-idp.5.xml:264 msgid "idp_request_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:188 +#: sssd-idp.5.xml:267 msgid "Timeout in seconds for an individual request to the IdP." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:197 +#: sssd-idp.5.xml:276 +msgid "idp_auto_refresh (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:279 +msgid "" +"Refresh tokens automatically, after they have reached about half their " +"lifetime." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:283 +msgid "" +"Note: Scheduled token refreshes are not preserved across restarts of SSSD." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-idp.5.xml:292 msgid "idmap_range_min (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:200 +#: sssd-idp.5.xml:295 msgid "" "Specifies the lower (inclusive) bound of the range of POSIX IDs to use for " "mapping IdP users and group to POSIX IDs. It is the first POSIX ID which can " @@ -12501,7 +12930,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:206 +#: sssd-idp.5.xml:301 msgid "" "The interval between <quote>idmap_range_min</quote> and " "<quote>idmap_range_max</quote> will be split into smaller ranges of size " @@ -12510,18 +12939,18 @@ msgid "" msgstr "" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:213 sssd-idp.5.xml:239 include/ldap_id_mapping.xml:139 +#: sssd-idp.5.xml:308 sssd-idp.5.xml:334 include/ldap_id_mapping.xml:139 #: include/ldap_id_mapping.xml:197 msgid "Default: 200000" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:218 +#: sssd-idp.5.xml:313 msgid "idmap_range_max (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:221 +#: sssd-idp.5.xml:316 msgid "" "Specifies the upper (exclusive) bound of the range of POSIX IDs to use for " "mapping IdP users and groups to POSIX IDs. It is the first POSIX ID which " @@ -12529,45 +12958,68 @@ msgid "" msgstr "" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:227 include/ldap_id_mapping.xml:165 +#: sssd-idp.5.xml:322 include/ldap_id_mapping.xml:165 msgid "Default: 2000200000" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:232 +#: sssd-idp.5.xml:327 msgid "idmap_range_size (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:235 +#: sssd-idp.5.xml:330 msgid "Specifies the number of POSIX IDs available for a single IdP domain." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-idp.5.xml:251 +#: sssd-idp.5.xml:346 #, no-wrap msgid "" "[domain/entra_id]\n" "id_provider = idp\n" "idp_type = entra_id\n" "idp_client_id = 12345678-abcd-0101-efef-ba9876543210\n" -"idp_client_secret = YOUR-CLIENT-SCERET\n" -"idp_token_endpoint = https://login.microsoftonline.com/TENNANT-ID/oauth2/v2.0/token\n" +"idp_client_secret = YOUR-CLIENT-SECRET\n" +"idp_token_endpoint = https://login.microsoftonline.com/TENANT-ID/oauth2/v2.0/token\n" "idp_userinfo_endpoint = https://graph.microsoft.com/v1.0/me\n" -"idp_device_auth_endpoint = https://login.microsoftonline.com/TENNANT-ID/oauth2/v2.0/devicecode\n" -"idp_id_scope = https%3A%2F%2Fgraph.microsoft.com%2F.default\n" +"idp_device_auth_endpoint = https://login.microsoftonline.com/TENANT-ID/oauth2/v2.0/devicecode\n" +"idp_id_scope = https://graph.microsoft.com/.default\n" +"idp_auth_scope = openid profile email\n" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><programlisting> +#: sssd-idp.5.xml:358 +#, no-wrap +msgid "" +"[domain/ad.example.com]\n" +"id_provider = ad\n" +"auth_provider = idp\n" +"access_provider = permit\n" +"\n" +"ad_domain = ad.example.com\n" +"krb5_realm = AD.EXAMPLE.COM\n" +"\n" +"idp_type = entra_id\n" +"idp_client_id = 12345678-abcd-0101-efef-ba9876543210\n" +"idp_client_secret = YOUR-CLIENT-SECRET\n" +"idp_token_endpoint = https://login.microsoftonline.com/TENANT-ID/oauth2/v2.0/token\n" +"idp_userinfo_endpoint = https://graph.microsoft.com/v1.0/me?$select=id,userPrincipalName,onPremisesImmutableId\n" +"idp_device_auth_endpoint = https://login.microsoftonline.com/TENANT-ID/oauth2/v2.0/devicecode\n" +"idp_id_scope = https://graph.microsoft.com/.default\n" "idp_auth_scope = openid profile email\n" +"idp_auth_user_identifier_attr = onPremisesImmutableId\n" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-idp.5.xml:263 +#: sssd-idp.5.xml:377 #, no-wrap msgid "" "[domain/keycloak]\n" "idp_type = keycloak:https://master.keycloak.test:8443/auth/admin/realms/master/\n" "id_provider = idp\n" "idp_client_id = myclient\n" -"idp_client_secret = YOUR-CLIENT-SCERET\n" +"idp_client_secret = YOUR-CLIENT-SECRET\n" "idp_token_endpoint = https://master.keycloak.test:8443/auth/realms/master/protocol/openid-connect/token\n" "idp_userinfo_endpoint = https://master.keycloak.test:8443/auth/realms/master/protocol/openid-connect/userinfo\n" "idp_device_auth_endpoint = https://master.keycloak.test:8443/auth/realms/master/protocol/openid-connect/auth/device\n" @@ -12576,10 +13028,22 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-idp.5.xml:250 +#: sssd-idp.5.xml:345 msgid "" "<placeholder type=\"programlisting\" id=\"0\"/> <placeholder " -"type=\"programlisting\" id=\"1\"/>" +"type=\"programlisting\" id=\"1\"/> <placeholder type=\"programlisting\" " +"id=\"2\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-idp.5.xml:390 +msgid "" +"In the hybrid Active Directory and Entra ID example above, " +"<quote>onPremisesImmutableId</quote> is used during authentication so the " +"IdP result matches the AD objectGUID UUID stored in the SSSD cache. The " +"attribute must be requested via <quote>$select</quote> on the Graph userinfo " +"endpoint and is only populated for users synchronized from Active Directory " +"with objectGUID as the sourceAnchor." msgstr "" #. type: Content of: <reference><refentry><refnamediv><refname> @@ -13545,7 +14009,7 @@ msgstr "" #: sssd-krb5.5.xml:291 msgid "" "<emphasis>demand</emphasis> to use FAST. The authentication fails if the " -"server does not require fast." +"server does not support FAST." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> @@ -14434,7 +14898,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sss_rpcidmapd.5.xml:69 -msgid "memcache (bool)" +msgid "memcache (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> @@ -14488,7 +14952,7 @@ msgid "" msgstr "" #. type: Content of: <refsect1><title> -#: sss_rpcidmapd.5.xml:120 sssd-kcm.8.xml:316 include/seealso.xml:2 +#: sss_rpcidmapd.5.xml:120 sssd-kcm.8.xml:315 include/seealso.xml:2 msgid "SEE ALSO" msgstr "GWELET IVEZ" @@ -14723,8 +15187,8 @@ msgstr "" #: sss_ssh_knownhosts.1.xml:93 msgid "" "The key lines retrieved from the backend are expected to respect the key " -"format as decribed in the <quote>SSH_KNOWN_HOSTS FILE FORMAT</quote> section " -"of <citerefentry><refentrytitle>sshd</refentrytitle> <manvolnum>8</" +"format as described in the <quote>SSH_KNOWN_HOSTS FILE FORMAT</quote> " +"section of <citerefentry><refentrytitle>sshd</refentrytitle> <manvolnum>8</" "manvolnum></citerefentry>. However, returning only the keytype and the key " "itself is tolerated, in which case, the hostname received as parameter will " "be added before the keytype to output a correctly formatted line. The " @@ -15200,14 +15664,13 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-kcm.8.xml:215 msgid "" -"The KCM service is configured in the <quote>kcm</quote> For a detailed " -"syntax reference, refer to the <quote>FILE FORMAT</quote> section of the " -"<citerefentry> <refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</" -"manvolnum> </citerefentry> manual page." +"For a detailed syntax reference, refer to the <quote>FILE FORMAT</quote> " +"section of the <citerefentry> <refentrytitle>sssd.conf</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry> manual page." msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-kcm.8.xml:223 +#: sssd-kcm.8.xml:222 msgid "" "The generic SSSD service options such as <quote>debug_level</quote> or " "<quote>fd_limit</quote> are accepted by the kcm service. Please refer to " @@ -15217,22 +15680,22 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:234 +#: sssd-kcm.8.xml:233 msgid "socket_path (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:237 +#: sssd-kcm.8.xml:236 msgid "The socket the KCM service will listen on." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:240 +#: sssd-kcm.8.xml:239 msgid "Default: <replaceable>/var/run/.heim_org.h5l.kcm-socket</replaceable>" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:243 +#: sssd-kcm.8.xml:242 msgid "" "<phrase condition=\"have_systemd\"> Note: on platforms where systemd is " "supported, the socket path is overwritten by the one defined in the sssd-" @@ -15240,90 +15703,92 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:252 +#: sssd-kcm.8.xml:251 msgid "max_ccaches (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:255 +#: sssd-kcm.8.xml:254 msgid "How many credential caches does the KCM database allow for all users." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:259 +#: sssd-kcm.8.xml:258 msgid "Default: 0 (unlimited, only the per-UID quota is enforced)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:264 +#: sssd-kcm.8.xml:263 msgid "max_uid_ccaches (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:267 +#: sssd-kcm.8.xml:266 msgid "" "How many credential caches does the KCM database allow per UID. This is " "equivalent to <quote>with how many principals you can kinit</quote>." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:272 +#: sssd-kcm.8.xml:271 msgid "Default: 64" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:277 +#: sssd-kcm.8.xml:276 msgid "max_ccache_size (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:280 +#: sssd-kcm.8.xml:279 msgid "" -"How big can a credential cache be per ccache. Each service ticket accounts " -"into this quota." +"How big a credential cache be per ccache. Each service ticket counts toward " +"this quota." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:284 +#: sssd-kcm.8.xml:283 msgid "Default: 65536" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:289 -msgid "tgt_renewal (bool)" -msgstr "" +#: sssd-kcm.8.xml:288 +#, fuzzy +#| msgid "re_expression (string)" +msgid "tgt_renewal (boolean)" +msgstr "re_expression (neudennad)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:292 +#: sssd-kcm.8.xml:291 msgid "Enables TGT renewals functionality." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:295 +#: sssd-kcm.8.xml:294 msgid "Default: False (Automatic renewals disabled)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:300 +#: sssd-kcm.8.xml:299 #, fuzzy #| msgid "re_expression (string)" msgid "tgt_renewal_inherit (string)" msgstr "re_expression (neudennad)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:303 +#: sssd-kcm.8.xml:302 msgid "Domain to inherit krb5_* options from, for use with TGT renewals." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:307 +#: sssd-kcm.8.xml:306 #, fuzzy #| msgid "Default: 3" msgid "Default: NULL" msgstr "Dre ziouer : 3" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-kcm.8.xml:318 +#: sssd-kcm.8.xml:317 msgid "" "<citerefentry> <refentrytitle>sssd</refentrytitle><manvolnum>8</manvolnum> </" "citerefentry>, <citerefentry> <refentrytitle>sssd.conf</" @@ -16227,8 +16692,8 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap-attributes.5.xml:381 sssd-ldap-attributes.5.xml:395 -msgid "Default: loginDisabled" +#: sssd-ldap-attributes.5.xml:381 +msgid "Default: loginDisabled (rfc2307, rfc2307bis and IPA), not set (AD)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> @@ -16243,6 +16708,12 @@ msgid "" "which date access is granted." msgstr "" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:395 +msgid "" +"Default: loginExpirationTime (rfc2307, rfc2307bis and IPA), not set (AD)" +msgstr "" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:401 msgid "ldap_user_nds_login_allowed_time_map (string)" @@ -16257,7 +16728,8 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:409 -msgid "Default: loginAllowedTimeMap" +msgid "" +"Default: loginAllowedTimeMap (rfc2307, rfc2307bis and IPA), not set (AD)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> @@ -16773,8 +17245,8 @@ msgid "The object class of a host entry in LDAP." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap-attributes.5.xml:900 sssd-ldap-attributes.5.xml:997 -msgid "Default: ipService" +#: sssd-ldap-attributes.5.xml:900 sssd-ldap-attributes.5.xml:1213 +msgid "Default: ipHost" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> @@ -16859,6 +17331,11 @@ msgstr "" msgid "The object class of a service entry in LDAP." msgstr "" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:997 +msgid "Default: ipService" +msgstr "" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1003 msgid "ldap_service_name (string)" @@ -17099,11 +17576,6 @@ msgstr "" msgid "The object class of an iphost entry in LDAP." msgstr "" -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap-attributes.5.xml:1213 -msgid "Default: ipHost" -msgstr "" - #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1219 msgid "ldap_iphost_name (string)" @@ -17343,6 +17815,7 @@ msgstr "" msgid "" "[plugins]\n" " localauth = {\n" +" disable = an2ln\n" " module = sssd:/usr/lib64/sssd/modules/sssd_krb5_localauth_plugin.so\n" " }\n" msgstr "" @@ -17359,6 +17832,28 @@ msgid "" "the local Kerberos configuration the plugin will be enabled automatically." msgstr "" +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_localauth_plugin.8.xml:67 +msgid "" +"This configuration snippet also disables the <command>an2ln</command> module " +"provided by MIT Kerberos if SSSD is configured to use the AD or IPA " +"provider. In those environments <command>sssd_krb5_localauth_plugin</" +"command> can reliably map the system user names to Kerberos principals. A " +"fallback to <command>an2ln</command> might cause issues in environments " +"where users have the privilege to create Kerberos principals on their own " +"which might collide with names of other users used in the system. Other " +"modules provided by MIT Kerberos, e.g. <command>k5login</command> are not " +"affected." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_localauth_plugin.8.xml:79 +msgid "" +"Note: If using <quote>auth_provider = krb5</quote> then " +"<command>sssd_krb5_localauth_plugin</command> is not used, therefore the " +"above text is not applicable." +msgstr "" + #. type: Content of: <variablelist><varlistentry><term> #: include/autofs_attributes.xml:3 msgid "ldap_autofs_map_object_class (string)" @@ -18215,30 +18710,6 @@ msgid "" "failures; corresponds to setting 2 in decimal notation)" msgstr "" -#. type: Content of: <refsect1><title> -#: include/local.xml:2 -msgid "THE LOCAL DOMAIN" -msgstr "" - -#. type: Content of: <refsect1><para> -#: include/local.xml:4 -msgid "" -"In order to function correctly, a domain with <quote>id_provider=local</" -"quote> must be created and the SSSD must be running." -msgstr "" - -#. type: Content of: <refsect1><para> -#: include/local.xml:9 -msgid "" -"The administrator might want to use the SSSD local users instead of " -"traditional UNIX users in cases where the group nesting (see <citerefentry> " -"<refentrytitle>sss_groupadd</refentrytitle> <manvolnum>8</manvolnum> </" -"citerefentry>) is needed. The local users are also useful for testing and " -"development of the SSSD without having to deploy a full remote server. The " -"<command>sss_user*</command> and <command>sss_group*</command> tools use a " -"local LDB storage to store users and groups." -msgstr "" - #. type: Content of: <refsect1><para> #: include/seealso.xml:4 msgid "" @@ -18842,6 +19313,9 @@ msgid "" "feature is available with MIT Kerberos 1.7 and later versions." msgstr "" +#~ msgid "domains" +#~ msgstr "domanioù" + #~ msgid "sss_groupmod" #~ msgstr "sss_groupmod" diff --git a/src/man/po/ca.po b/src/man/po/ca.po index 6cb8e92cdce..80daa8c6ba0 100644 --- a/src/man/po/ca.po +++ b/src/man/po/ca.po @@ -14,8 +14,8 @@ msgid "" msgstr "" "Project-Id-Version: sssd-docs 2.3.0\n" "Report-Msgid-Bugs-To: sssd-devel@redhat.com\n" -"POT-Creation-Date: 2026-01-14 15:00+0000\n" -"PO-Revision-Date: 2026-04-23 16:35+0000\n" +"POT-Creation-Date: 2026-10-05 16:14+0000\n" +"PO-Revision-Date: 2026-10-05 16:44+0000\n" "Last-Translator: Anonymous <noreply@weblate.org>\n" "Language-Team: Catalan <https://translate.fedoraproject.org/projects/sssd/" "sssd-manpage-master/ca/>\n" @@ -24,10 +24,10 @@ msgstr "" "Content-Type: text/plain; charset=UTF-8\n" "Content-Transfer-Encoding: 8bit\n" "Plural-Forms: nplurals=2; plural=n != 1;\n" -"X-Generator: Weblate 5.17\n" +"X-Generator: Weblate 2026.10\n" #. type: Content of: <reference><title> -#: sssd.conf.5.xml:8 sssd-ldap.5.xml:5 pam_sss.8.xml:5 pam_sss_gss.8.xml:5 +#: sssd.conf.5.xml:10 sssd-ldap.5.xml:5 pam_sss.8.xml:5 pam_sss_gss.8.xml:5 #: sssd_krb5_locator_plugin.8.xml:5 sssd-simple.5.xml:5 sss-certmap.5.xml:5 #: sssd-ipa.5.xml:5 sssd-ad.5.xml:5 sssd-sudo.5.xml:5 sssd-idp.5.xml:5 #: sssd.8.xml:5 sss_obfuscate.8.xml:5 sss_override.8.xml:5 sssd-krb5.5.xml:5 @@ -40,12 +40,12 @@ msgid "SSSD Manual pages" msgstr "Pàgines del manual de l'SSSD" #. type: Content of: <reference><refentry><refnamediv><refname> -#: sssd.conf.5.xml:13 sssd.conf.5.xml:19 +#: sssd.conf.5.xml:15 sssd.conf.5.xml:21 msgid "sssd.conf" msgstr "sssd.conf" #. type: Content of: <reference><refentry><refmeta><manvolnum> -#: sssd.conf.5.xml:14 sssd-ldap.5.xml:11 sssd-simple.5.xml:11 +#: sssd.conf.5.xml:16 sssd-ldap.5.xml:11 sssd-simple.5.xml:11 #: sss-certmap.5.xml:11 sssd-ipa.5.xml:11 sssd-ad.5.xml:11 sssd-sudo.5.xml:11 #: sssd-idp.5.xml:11 sssd-krb5.5.xml:11 sssd-ifp.5.xml:11 #: sss_rpcidmapd.5.xml:27 sssd-session-recording.5.xml:11 @@ -54,7 +54,7 @@ msgid "5" msgstr "5" #. type: Content of: <reference><refentry><refmeta><refmiscinfo> -#: sssd.conf.5.xml:15 sssd-ldap.5.xml:12 sssd-simple.5.xml:12 +#: sssd.conf.5.xml:17 sssd-ldap.5.xml:12 sssd-simple.5.xml:12 #: sss-certmap.5.xml:12 sssd-ipa.5.xml:12 sssd-ad.5.xml:12 sssd-sudo.5.xml:12 #: sssd-idp.5.xml:12 sssd-krb5.5.xml:12 sssd-ifp.5.xml:12 #: sss_rpcidmapd.5.xml:28 sssd-session-recording.5.xml:12 sssd-kcm.8.xml:12 @@ -63,17 +63,17 @@ msgid "File Formats and Conventions" msgstr "Formats i convencions dels fitxers" #. type: Content of: <reference><refentry><refnamediv><refpurpose> -#: sssd.conf.5.xml:20 +#: sssd.conf.5.xml:22 msgid "the configuration file for SSSD" msgstr "el fitxer de configuració per a l'SSSD" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:24 +#: sssd.conf.5.xml:26 msgid "FILE FORMAT" msgstr "FORMAT DEL FITXER" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd.conf.5.xml:32 +#: sssd.conf.5.xml:34 #, no-wrap msgid "" "<replaceable>[section]</replaceable>\n" @@ -87,7 +87,7 @@ msgstr "" " " #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:27 +#: sssd.conf.5.xml:29 msgid "" "The file has an ini-style syntax and consists of sections and parameters. A " "section begins with the name of the section in square brackets and continues " @@ -101,23 +101,24 @@ msgstr "" "type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:39 +#: sssd.conf.5.xml:41 msgid "" -"The data types used are string (no quotes needed), integer and bool (with " -"values of <quote>TRUE/FALSE</quote>)." +"The data types used are string (no quotes needed), integer and boolean (with " +"values of <quote>TRUE/FALSE</quote>). Boolean values are case-insensitive; " +"for example, <quote>TRUE</quote>, <quote>True</quote> and <quote>true</" +"quote> are all equivalent and valid; the same applies to <quote>FALSE</" +"quote>." msgstr "" -"Els tipus de dades que s'utilitzen són cadenes (no necessiten cometes), " -"enters i booleans (amb valors <quote>TRUE/FALSE</quote>)." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:44 +#: sssd.conf.5.xml:49 msgid "" "A comment line starts with a hash sign (<quote>#</quote>) or a semicolon " "(<quote>;</quote>). Inline comments are not supported." msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:50 +#: sssd.conf.5.xml:55 msgid "" "All sections can have an optional <replaceable>description</replaceable> " "parameter. Its function is only as a label for the section." @@ -127,7 +128,7 @@ msgstr "" "secció." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:56 +#: sssd.conf.5.xml:61 #, fuzzy #| msgid "" #| "<filename>sssd.conf</filename> must be a regular file, owned by root and " @@ -140,7 +141,7 @@ msgstr "" "propietari i només l'usuari root hi pot llegir o escriure." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:60 +#: sssd.conf.5.xml:65 #, fuzzy #| msgid "" #| "<filename>sssd.conf</filename> must be a regular file, owned by root and " @@ -153,12 +154,12 @@ msgstr "" "propietari i només l'usuari root hi pot llegir o escriure." #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:66 +#: sssd.conf.5.xml:71 msgid "CONFIGURATION SNIPPETS FROM INCLUDE DIRECTORY" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:69 +#: sssd.conf.5.xml:74 msgid "" "The configuration file <filename>sssd.conf</filename> will include " "configuration snippets using the include directory <filename>conf.d</" @@ -166,7 +167,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:75 +#: sssd.conf.5.xml:80 msgid "" "Any file placed in <filename>conf.d</filename> that ends in " "<quote><filename>.conf</filename></quote> and does not begin with a dot " @@ -175,7 +176,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:83 +#: sssd.conf.5.xml:88 msgid "" "The configuration snippets from <filename>conf.d</filename> have higher " "priority than <filename>sssd.conf</filename> and will override " @@ -188,40 +189,93 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:97 +#: sssd.conf.5.xml:102 msgid "" "The snippet files require the same owner and permissions as " "<filename>sssd.conf</filename>." msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:103 +#: sssd.conf.5.xml:108 +#, fuzzy +#| msgid "CONFIGURATION FILE" +msgid "VENDOR PROVIDED CONFIGURATION" +msgstr "FITXER DE CONFIGURACIÓ" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:111 +msgid "" +"The vendor provided configuration file is installed in " +"<filename>&sssd_vendor_dir;/sssd.conf</filename>, but this file must not be " +"directly edited. It can be completely masked by creating the system specific " +"configuration file <filename>&sssd_conf_dir;/sssd.conf</filename>, or partly " +"overriden by creating config snippets in <filename>&sssd_conf_dir;/conf.d</" +"filename> directory." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><title> +#: sssd.conf.5.xml:120 +#, fuzzy +#| msgid "CONFIGURATION FILE" +msgid "CONFIGURATION FILE HIERARCHY" +msgstr "FITXER DE CONFIGURACIÓ" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:122 +msgid "" +"When sssd reads the configuration it first tries to open the system specific " +"configuration file in <filename>&sssd_conf_dir;/sssd.conf</filename>. If it " +"exists, it is loaded and snippets from <filename>&sssd_conf_dir;/conf.d</" +"filename> are applied. The vendor provided configuration file " +"<filename>&sssd_vendor_dir;/sssd.conf</filename> is completely ignored in " +"this case." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:131 +msgid "" +"If the system specific configuration file <filename>&sssd_conf_dir;/" +"sssd.conf</filename> does not exist, then the vendor configuration file " +"<filename>&sssd_vendor_dir;/sssd.conf</filename> is loaded and snippets from " +"<filename>&sssd_conf_dir;/conf.d</filename> are applied." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd.conf.5.xml:141 msgid "GENERAL OPTIONS" msgstr "OPCIONS GENERALS" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:105 +#: sssd.conf.5.xml:143 msgid "Following options are usable in more than one configuration sections." msgstr "" "Les següents opcions es poden utilitzar en més d'una secció de configuració." #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:109 +#: sssd.conf.5.xml:147 msgid "Options usable in all sections" msgstr "Opcions que es poden utilitzar en totes les seccions" +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:149 +msgid "" +"Note: Below options are ignored in <quote>[session_recording]</quote> " +"section, see <quote>Session recording configuration options</quote> section " +"for more details." +msgstr "" + #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:113 +#: sssd.conf.5.xml:156 msgid "debug_level (integer)" msgstr "debug_level (enter)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:117 +#: sssd.conf.5.xml:160 msgid "debug (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:120 +#: sssd.conf.5.xml:163 msgid "" "SSSD 1.14 and later also includes the <replaceable>debug</replaceable> alias " "for <replaceable>debug_level</replaceable> as a convenience feature. If both " @@ -230,12 +284,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:130 -msgid "debug_timestamps (bool)" +#: sssd.conf.5.xml:173 +#, fuzzy +#| msgid "debug_timestamps (bool)" +msgid "debug_timestamps (boolean)" msgstr "debug_timestamps (booleà)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:133 +#: sssd.conf.5.xml:176 msgid "" "Add a timestamp to the debug messages. If journald is enabled for SSSD " "debug logging this option is ignored." @@ -245,23 +301,25 @@ msgstr "" "opció." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:138 sssd.conf.5.xml:175 sssd.conf.5.xml:337 -#: sssd.conf.5.xml:644 sssd.conf.5.xml:668 sssd.conf.5.xml:875 -#: sssd.conf.5.xml:979 sssd.conf.5.xml:2113 sssd-ldap.5.xml:979 -#: sssd-ldap.5.xml:1134 sssd-ldap.5.xml:1237 sssd-ldap.5.xml:1306 -#: sssd-ldap.5.xml:1714 sssd-ldap.5.xml:1848 sssd-ldap.5.xml:1913 -#: sssd-ipa.5.xml:346 sssd-ad.5.xml:252 sssd-ad.5.xml:367 sssd-ad.5.xml:1180 -#: sssd-ad.5.xml:1382 sssd-krb5.5.xml:358 +#: sssd.conf.5.xml:181 sssd.conf.5.xml:218 sssd.conf.5.xml:380 +#: sssd.conf.5.xml:687 sssd.conf.5.xml:711 sssd.conf.5.xml:827 +#: sssd.conf.5.xml:932 sssd.conf.5.xml:2149 sssd.conf.5.xml:4730 +#: sssd-ldap.5.xml:979 sssd-ldap.5.xml:1134 sssd-ldap.5.xml:1237 +#: sssd-ldap.5.xml:1306 sssd-ldap.5.xml:1714 sssd-ldap.5.xml:1848 +#: sssd-ldap.5.xml:1913 sssd-ipa.5.xml:341 sssd-ad.5.xml:252 sssd-ad.5.xml:367 +#: sssd-ad.5.xml:1180 sssd-ad.5.xml:1375 sssd-krb5.5.xml:358 msgid "Default: true" msgstr "Per defecte: true" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:143 -msgid "debug_microseconds (bool)" +#: sssd.conf.5.xml:186 +#, fuzzy +#| msgid "debug_microseconds (bool)" +msgid "debug_microseconds (boolean)" msgstr "debug_microseconds (booleà)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:146 +#: sssd.conf.5.xml:189 msgid "" "Add microseconds to the timestamp in debug messages. If journald is enabled " "for SSSD debug logging this option is ignored." @@ -271,28 +329,28 @@ msgstr "" "aleshores s'ignora aquesta opció." #. type: Content of: <variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:151 sssd.conf.5.xml:2040 sssd.conf.5.xml:4158 +#: sssd.conf.5.xml:194 sssd.conf.5.xml:2072 sssd.conf.5.xml:4363 #: sssd-ldap.5.xml:363 sssd-ldap.5.xml:998 sssd-ldap.5.xml:1209 -#: sssd-ldap.5.xml:1663 sssd-ldap.5.xml:1937 sssd-ipa.5.xml:146 -#: sssd-ipa.5.xml:706 sssd-ad.5.xml:1135 sssd-krb5.5.xml:268 +#: sssd-ldap.5.xml:1663 sssd-ldap.5.xml:1937 sssd-ipa.5.xml:141 +#: sssd-ipa.5.xml:701 sssd-ad.5.xml:1140 sssd-idp.5.xml:287 sssd-krb5.5.xml:268 #: sssd-krb5.5.xml:330 sssd-krb5.5.xml:432 include/krb5_options.xml:163 msgid "Default: false" msgstr "Per defecte: false" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:156 +#: sssd.conf.5.xml:199 #, fuzzy #| msgid "debug_microseconds (bool)" -msgid "debug_backtrace_enabled (bool)" +msgid "debug_backtrace_enabled (boolean)" msgstr "debug_microseconds (booleà)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:159 +#: sssd.conf.5.xml:202 msgid "Enable debug backtrace." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:162 +#: sssd.conf.5.xml:205 msgid "" "In case SSSD is run with debug_level less than 9, everything is logged to a " "ring buffer in memory and flushed to a log file on any error up to and " @@ -302,14 +360,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:171 +#: sssd.conf.5.xml:214 msgid "" "Feature is only supported for `logger == files` (i.e. setting doesn't have " "effect for other logger types)." msgstr "" #. type: Content of: outside any tag (error?) -#: sssd.conf.5.xml:111 sssd.conf.5.xml:186 sssd-ldap.5.xml:1754 +#: sssd.conf.5.xml:154 sssd.conf.5.xml:229 sssd-ldap.5.xml:1754 #: sssd-ldap.5.xml:1960 sss-certmap.5.xml:645 sssd-systemtap.5.xml:82 #: sssd-systemtap.5.xml:143 sssd-systemtap.5.xml:236 sssd-systemtap.5.xml:274 #: sssd-systemtap.5.xml:330 sssd-ldap-attributes.5.xml:40 @@ -322,17 +380,17 @@ msgid "<placeholder type=\"variablelist\" id=\"0\"/>" msgstr "<placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:184 +#: sssd.conf.5.xml:227 msgid "Options usable in SERVICE and DOMAIN sections" msgstr "Opcions que es poden utilitzar a les seccions SERVEI i DOMINI" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:188 +#: sssd.conf.5.xml:231 msgid "timeout (integer)" msgstr "timeout (enter)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:191 +#: sssd.conf.5.xml:234 msgid "" "Timeout in seconds between heartbeats for this service. This is used to " "ensure that the process is alive and capable of answering requests. Note " @@ -340,34 +398,36 @@ msgid "" msgstr "" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:198 sssd.conf.5.xml:1199 sssd.conf.5.xml:1673 -#: sssd.conf.5.xml:4174 sssd-ldap.5.xml:825 sssd-idp.5.xml:192 +#: sssd.conf.5.xml:241 sssd.conf.5.xml:1155 sssd.conf.5.xml:1665 +#: sssd.conf.5.xml:4379 sssd-ldap.5.xml:825 sssd-idp.5.xml:271 #: include/ldap_id_mapping.xml:270 msgid "Default: 10" msgstr "Per defecte: 10" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:208 +#: sssd.conf.5.xml:251 msgid "SPECIAL SECTIONS" msgstr "SECCIONS ESPECIALS" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:211 +#: sssd.conf.5.xml:254 msgid "The [sssd] section" msgstr "La secció [sssd]" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><title> -#: sssd.conf.5.xml:220 +#: sssd.conf.5.xml:263 msgid "Section parameters" msgstr "Paràmetres de la secció" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:222 -msgid "services" -msgstr "services" +#: sssd.conf.5.xml:265 +#, fuzzy +#| msgid "user (string)" +msgid "services (string)" +msgstr "user (cadena)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:225 +#: sssd.conf.5.xml:268 msgid "" "Comma separated list of services that are started when sssd itself starts. " "<phrase condition=\"have_systemd\"> The services' list is optional on " @@ -376,7 +436,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:234 +#: sssd.conf.5.xml:277 #, fuzzy #| msgid "" #| "Supported services: nss, pam <phrase condition=\"with_sudo\">, sudo</" @@ -397,20 +457,20 @@ msgstr "" "condition=\"with_ifp\">, ifp</phrase>" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:241 +#: sssd.conf.5.xml:284 msgid "" "<phrase condition=\"have_systemd\"> By default, all services are disabled " "and the administrator must enable the ones allowed to be used by executing: " "\"systemctl enable sssd-@service@.socket\". </phrase>" msgstr "" -#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:250 -msgid "domains" -msgstr "domains" +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sssd.conf.5.xml:293 sssd.conf.5.xml:4562 +msgid "domains (string)" +msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:253 +#: sssd.conf.5.xml:296 msgid "" "A domain is a database containing user information. SSSD can use more " "domains at the same time, but at least one must be configured or SSSD won't " @@ -421,12 +481,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:266 sssd.conf.5.xml:3467 +#: sssd.conf.5.xml:309 sssd.conf.5.xml:3598 msgid "re_expression (string)" msgstr "re_expression (cadena)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:269 +#: sssd.conf.5.xml:312 msgid "" "Default regular expression that describes how to parse the string containing " "user name and domain into these components." @@ -435,7 +495,7 @@ msgstr "" "conté el nom d'usuari i el domini en aquests components." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:274 +#: sssd.conf.5.xml:317 msgid "" "Each domain can have an individual regular expression configured. For some " "ID providers there are also default regular expressions. See DOMAIN SECTIONS " @@ -443,12 +503,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:283 sssd.conf.5.xml:3524 +#: sssd.conf.5.xml:326 sssd.conf.5.xml:3655 msgid "full_name_format (string)" msgstr "full_name_format (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:286 sssd.conf.5.xml:3527 +#: sssd.conf.5.xml:329 sssd.conf.5.xml:3658 msgid "" "A <citerefentry> <refentrytitle>printf</refentrytitle> <manvolnum>3</" "manvolnum> </citerefentry>-compatible format that describes how to compose a " @@ -459,40 +519,40 @@ msgstr "" "compondre un FQN des dels components del nom d'usuari i del nom del domini." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:297 sssd.conf.5.xml:3538 +#: sssd.conf.5.xml:340 sssd.conf.5.xml:3669 msgid "%1$s" msgstr "%1$s" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:298 sssd.conf.5.xml:3539 +#: sssd.conf.5.xml:341 sssd.conf.5.xml:3670 msgid "user name" msgstr "nom d'usuari" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:301 sssd.conf.5.xml:3542 +#: sssd.conf.5.xml:344 sssd.conf.5.xml:3673 msgid "%2$s" msgstr "%2$s" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:304 sssd.conf.5.xml:3545 +#: sssd.conf.5.xml:347 sssd.conf.5.xml:3676 msgid "domain name as specified in the SSSD config file." msgstr "" "el nom del domini tal com s'especifica al fitxer de configuració de l'SSSD." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:310 sssd.conf.5.xml:3551 +#: sssd.conf.5.xml:353 sssd.conf.5.xml:3682 msgid "%3$s" msgstr "%3$s" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:313 sssd.conf.5.xml:3554 +#: sssd.conf.5.xml:356 sssd.conf.5.xml:3685 msgid "" "domain flat name. Mostly usable for Active Directory domains, both directly " "configured or discovered via IPA trusts." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:294 sssd.conf.5.xml:3535 +#: sssd.conf.5.xml:337 sssd.conf.5.xml:3666 msgid "" "The following expansions are supported: <placeholder type=\"variablelist\" " "id=\"0\"/>" @@ -501,31 +561,31 @@ msgstr "" "id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:323 +#: sssd.conf.5.xml:366 msgid "" "Each domain can have an individual format string configured. See DOMAIN " "SECTIONS for more info on this option." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:329 +#: sssd.conf.5.xml:372 msgid "monitor_resolv_conf (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:332 +#: sssd.conf.5.xml:375 msgid "" "Controls if SSSD should monitor the state of resolv.conf to identify when it " "needs to update its internal DNS resolver." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:342 +#: sssd.conf.5.xml:385 msgid "try_inotify (boolean)" msgstr "try_inotify (booleà)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:345 +#: sssd.conf.5.xml:388 msgid "" "By default, SSSD will attempt to use inotify to monitor configuration files " "changes and will fall back to polling every five seconds if inotify cannot " @@ -533,7 +593,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:351 +#: sssd.conf.5.xml:394 msgid "" "There are some limited situations where it is preferred that we should skip " "even trying to use inotify. In these rare cases, this option should be set " @@ -544,7 +604,7 @@ msgstr "" "d'establir aquesta opció a «false»" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:357 +#: sssd.conf.5.xml:400 msgid "" "Default: true on platforms where inotify is supported. False on other " "platforms." @@ -553,7 +613,7 @@ msgstr "" "altres plataformes." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:361 +#: sssd.conf.5.xml:404 msgid "" "Note: this option will have no effect on platforms where inotify is " "unavailable. On these platforms, polling will always be used." @@ -562,12 +622,12 @@ msgstr "" "disponible. En aquestes plataformes, sempre s'utilitzarà el sondeig." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:368 +#: sssd.conf.5.xml:411 msgid "krb5_rcache_dir (string)" msgstr "krb5_rcache_dir (cadena)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:371 +#: sssd.conf.5.xml:414 msgid "" "Directory on the filesystem where SSSD should store Kerberos replay cache " "files." @@ -576,7 +636,7 @@ msgstr "" "cau de repetició del Kerberos." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:375 +#: sssd.conf.5.xml:418 msgid "" "This option accepts a special value __LIBKRB5_DEFAULTS__ that will instruct " "SSSD to let libkrb5 decide the appropriate location for the replay cache." @@ -586,7 +646,7 @@ msgstr "" "auxiliar de reproducció." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:381 +#: sssd.conf.5.xml:424 msgid "" "Default: Distribution-specific and specified at build-time. " "(__LIBKRB5_DEFAULTS__ if not configured)" @@ -595,19 +655,19 @@ msgstr "" "construcció. (__LIBKRB5_DEFAULTS__ si no està configurat)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:388 +#: sssd.conf.5.xml:431 msgid "default_domain_suffix (string)" msgstr "default_domain_suffix (cadena)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:391 +#: sssd.conf.5.xml:434 msgid "" "Please note that this option is deprecated and domain_resolution_order " "should be used." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:395 +#: sssd.conf.5.xml:438 msgid "" "This string will be used as a default domain name for all names without a " "domain name component. The main use case is environments where the primary " @@ -623,7 +683,7 @@ msgstr "" "nom d'usuari sense donar també un nom de domini." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:405 +#: sssd.conf.5.xml:448 msgid "" "Please note that if this option is set all users from the primary domain " "have to use their fully qualified name, e.g. user@domain.name, to log in. " @@ -633,21 +693,21 @@ msgid "" msgstr "" #. type: Content of: <variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:414 sssd-ldap.5.xml:937 sssd-ldap.5.xml:949 -#: sssd-ldap.5.xml:1042 sssd-ad.5.xml:921 sssd-ad.5.xml:996 sssd-krb5.5.xml:468 -#: sssd-ldap-attributes.5.xml:470 sssd-ldap-attributes.5.xml:978 -#: include/ldap_id_mapping.xml:211 include/ldap_id_mapping.xml:222 -#: include/krb5_options.xml:148 +#: sssd.conf.5.xml:457 sssd.conf.5.xml:2006 sssd-ldap.5.xml:937 +#: sssd-ldap.5.xml:949 sssd-ldap.5.xml:1042 sssd-ad.5.xml:926 +#: sssd-ad.5.xml:1001 sssd-krb5.5.xml:468 sssd-ldap-attributes.5.xml:470 +#: sssd-ldap-attributes.5.xml:978 include/ldap_id_mapping.xml:211 +#: include/ldap_id_mapping.xml:222 include/krb5_options.xml:148 msgid "Default: not set" msgstr "Per defecte: sense establir" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:419 +#: sssd.conf.5.xml:462 msgid "override_space (string)" msgstr "override_space (cadena)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:422 +#: sssd.conf.5.xml:465 msgid "" "This parameter will replace spaces (space bar) with the given character for " "user and group names. e.g. (_). User name "john doe" will be " @@ -657,7 +717,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:431 +#: sssd.conf.5.xml:474 msgid "" "Please note it is a configuration error to use a replacement character that " "might be used in user or group names. If a name contains the replacement " @@ -666,22 +726,22 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:439 +#: sssd.conf.5.xml:482 msgid "Default: not set (spaces will not be replaced)" msgstr "Per defecte: sense establir (no se substituiran els espais)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:444 +#: sssd.conf.5.xml:487 msgid "certificate_verification (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:452 +#: sssd.conf.5.xml:495 msgid "no_ocsp" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:454 +#: sssd.conf.5.xml:497 msgid "" "Disables Online Certificate Status Protocol (OCSP) checks. This might be " "needed if the OCSP servers defined in the certificate are not reachable from " @@ -689,12 +749,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:462 +#: sssd.conf.5.xml:505 msgid "soft_ocsp" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:464 +#: sssd.conf.5.xml:507 msgid "" "If a connection cannot be established to an OCSP responder the OCSP check is " "skipped. This option should be used to allow authentication when the system " @@ -702,61 +762,61 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:474 +#: sssd.conf.5.xml:517 msgid "ocsp_dgst" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:476 +#: sssd.conf.5.xml:519 msgid "" "Digest (hash) function used to create the certificate ID for the OCSP " "request. Allowed values are:" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:480 +#: sssd.conf.5.xml:523 msgid "sha1" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:481 +#: sssd.conf.5.xml:524 msgid "sha256" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:482 +#: sssd.conf.5.xml:525 msgid "sha384" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:483 +#: sssd.conf.5.xml:526 msgid "sha512" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:486 +#: sssd.conf.5.xml:529 msgid "Default: sha1 (to allow compatibility with RFC5019-compliant responder)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:492 +#: sssd.conf.5.xml:535 msgid "no_verification" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:494 +#: sssd.conf.5.xml:537 msgid "" "Disables verification completely. This option should only be used for " "testing." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:500 +#: sssd.conf.5.xml:543 msgid "partial_chain" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:502 +#: sssd.conf.5.xml:545 msgid "" "Allow verification to succeed even if a <replaceable>complete</replaceable> " "chain cannot be built to a self-signed trust-anchor, provided it is possible " @@ -764,12 +824,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:511 +#: sssd.conf.5.xml:554 msgid "ocsp_default_responder=URL" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:513 +#: sssd.conf.5.xml:556 msgid "" "Sets the OCSP default responder which should be used instead of the one " "mentioned in the certificate. URL must be replaced with the URL of the OCSP " @@ -777,24 +837,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:523 +#: sssd.conf.5.xml:566 msgid "ocsp_default_responder_signing_cert=NAME" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:525 +#: sssd.conf.5.xml:568 msgid "" "This option is currently ignored. All needed certificates must be available " "in the PEM file given by pam_cert_db_path." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:533 +#: sssd.conf.5.xml:576 msgid "crl_file=/PATH/TO/CRL/FILE" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:535 +#: sssd.conf.5.xml:578 #, fuzzy #| msgid "" #| "The skeleton directory, which contains files and directories to be copied " @@ -813,12 +873,12 @@ msgstr "" "manvolnum></citerefentry>" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:548 +#: sssd.conf.5.xml:591 msgid "soft_crl" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:551 +#: sssd.conf.5.xml:594 msgid "" "If a Certificate Revocation List (CRL) is expired ignore the expiration " "time of the CRL and check the related certificates with the expired CRL. " @@ -827,7 +887,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:447 +#: sssd.conf.5.xml:490 msgid "" "With this parameter the certificate verification can be tuned with a comma " "separated list of options. Supported options are: <placeholder " @@ -835,46 +895,48 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:564 +#: sssd.conf.5.xml:607 msgid "Unknown options are reported but ignored." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:567 +#: sssd.conf.5.xml:610 msgid "Default: not set, i.e. do not restrict certificate verification" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:573 +#: sssd.conf.5.xml:616 msgid "disable_netlink (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:576 +#: sssd.conf.5.xml:619 msgid "" "SSSD hooks into the netlink interface to monitor changes to routes, " "addresses, links and trigger certain actions." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:581 +#: sssd.conf.5.xml:624 msgid "" "The SSSD state changes caused by netlink events may be undesirable and can " "be disabled by setting this option to 'true'" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:586 +#: sssd.conf.5.xml:629 msgid "Default: false (netlink changes are detected)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:591 -msgid "domain_resolution_order" -msgstr "" +#: sssd.conf.5.xml:634 +#, fuzzy +#| msgid "subdomains_provider (string)" +msgid "domain_resolution_order (string)" +msgstr "subdomains_provider (cadena)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:594 +#: sssd.conf.5.xml:637 msgid "" "Comma separated list of domains and subdomains representing the lookup order " "that will be followed. The list doesn't have to include all possible " @@ -885,7 +947,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:606 +#: sssd.conf.5.xml:649 msgid "" "Please, note that when this option is set the output format of all commands " "is always fully-qualified even when using short names for input. In case " @@ -901,21 +963,22 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:630 sssd.conf.5.xml:1697 sssd.conf.5.xml:4224 -#: sssd-ad.5.xml:187 sssd-ad.5.xml:328 sssd-ad.5.xml:342 sssd-idp.5.xml:108 -#: sssd-idp.5.xml:132 sssd-idp.5.xml:145 sssd-idp.5.xml:159 sssd-idp.5.xml:180 +#: sssd.conf.5.xml:673 sssd.conf.5.xml:1026 sssd.conf.5.xml:1689 +#: sssd.conf.5.xml:4429 sssd-ad.5.xml:187 sssd-ad.5.xml:328 sssd-ad.5.xml:342 +#: sssd-idp.5.xml:112 sssd-idp.5.xml:136 sssd-idp.5.xml:149 sssd-idp.5.xml:167 +#: sssd-idp.5.xml:188 msgid "Default: Not set" msgstr "Per defecte: Sense establir" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:635 +#: sssd.conf.5.xml:678 #, fuzzy #| msgid "ipa_server_mode (boolean)" msgid "implicit_pac_responder (boolean)" msgstr "ipa_server_mode (booleà)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:638 +#: sssd.conf.5.xml:681 msgid "" "The PAC responder is enabled automatically for the IPA and AD provider to " "evaluate and check the PAC. If it has to be disabled set this option to " @@ -923,14 +986,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:649 +#: sssd.conf.5.xml:692 #, fuzzy #| msgid "ad_enable_gc (boolean)" msgid "core_dumpable (boolean)" msgstr "ad_enable_gc (booleà)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:652 +#: sssd.conf.5.xml:695 msgid "" "This option can be used for general system hardening: setting it to 'false' " "forbids core dumps for all SSSD processes to avoid leaking plain text " @@ -939,7 +1002,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:660 +#: sssd.conf.5.xml:703 msgid "" "Take a note that this setting has no effect for 'ldap_child', 'krb5_child' " "and 'sssd_pam' as those privileged binaries can have a copy of a host keytab " @@ -948,28 +1011,28 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:673 +#: sssd.conf.5.xml:716 #, fuzzy #| msgid "ldap_user_certificate (string)" msgid "passkey_verification (string)" msgstr "ldap_user_certificate (cadena)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:681 +#: sssd.conf.5.xml:724 #, fuzzy #| msgid "ldap_user_certificate (string)" msgid "user_verification (boolean)" msgstr "ldap_user_certificate (cadena)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:683 +#: sssd.conf.5.xml:726 msgid "" "Enable or disable the user verification (i.e. PIN, fingerprint) during " "authentication. If enabled, the PIN will always be requested." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:689 +#: sssd.conf.5.xml:732 msgid "" "The default is that the key settings decide what to do. In the IPA or " "kerberos pre-authentication case, this value will be overwritten by the " @@ -977,7 +1040,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:676 +#: sssd.conf.5.xml:719 #, fuzzy #| msgid "" #| "The following expansions are supported: <placeholder " @@ -991,7 +1054,7 @@ msgstr "" "id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:213 +#: sssd.conf.5.xml:256 msgid "" "Individual pieces of SSSD functionality are provided by special SSSD " "services that are started and stopped together with SSSD. The services are " @@ -1008,12 +1071,12 @@ msgstr "" "type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:708 +#: sssd.conf.5.xml:751 msgid "SERVICES SECTIONS" msgstr "SECCIONS DELS SERVEIS" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:710 +#: sssd.conf.5.xml:753 msgid "" "Settings that can be used to configure different services are described in " "this section. They should reside in the [<replaceable>$NAME</replaceable>] " @@ -1026,42 +1089,45 @@ msgstr "" "quote>" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:717 +#: sssd.conf.5.xml:760 msgid "General service configuration options" msgstr "Opcions de configuració del servei general" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:719 +#: sssd.conf.5.xml:762 msgid "These options can be used to configure any service." msgstr "Es poden utilitzar aquestes opcions per configurar qualsevol servei." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:723 -msgid "fd_limit" -msgstr "fd_limit" +#: sssd.conf.5.xml:766 +#, fuzzy +#| msgid "timeout (integer)" +msgid "fd_limit (integer)" +msgstr "timeout (enter)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:726 +#: sssd.conf.5.xml:769 msgid "" "This option specifies the maximum number of file descriptors that may be " -"opened at one time by this SSSD process. On systems where SSSD is granted " -"the CAP_SYS_RESOURCE capability, this will be an absolute setting. On " -"systems without this capability, the resulting value will be the lower value " -"of this or the limits.conf \"hard\" limit." +"opened at one time by this SSSD process. Note this value will be capped by " +"the init system at the startup of SSSD, see e.g. man systemd.exec for " +"details." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:735 +#: sssd.conf.5.xml:776 msgid "Default: 8192 (or limits.conf \"hard\" limit)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:740 -msgid "client_idle_timeout" -msgstr "client_idle_timeout" +#: sssd.conf.5.xml:781 +#, fuzzy +#| msgid "offline_timeout (integer)" +msgid "client_idle_timeout (integer)" +msgstr "offline_timeout (enter)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:743 +#: sssd.conf.5.xml:784 msgid "" "This option specifies the number of seconds that a client of an SSSD process " "can hold onto a file descriptor without communicating on it. This value is " @@ -1071,152 +1137,21 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:752 +#: sssd.conf.5.xml:793 #, fuzzy #| msgid "Default: 300" msgid "Default: 60, KCM: 300" msgstr "Per defecte: 300" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:757 -msgid "offline_timeout (integer)" -msgstr "offline_timeout (enter)" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:760 -msgid "" -"When SSSD switches to offline mode the amount of time before it tries to go " -"back online will increase based upon the time spent disconnected. By " -"default SSSD uses incremental behaviour to calculate delay in between " -"retries. So, the wait time for a given retry will be longer than the wait " -"time for the previous ones. After each unsuccessful attempt to go online, " -"the new interval is recalculated by the following:" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:771 sssd.conf.5.xml:827 -msgid "" -"new_delay = Minimum(old_delay * 2, offline_timeout_max) + " -"random[0...offline_timeout_random_offset]" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:774 -msgid "" -"The offline_timeout default value is 60. The offline_timeout_max default " -"value is 3600. The offline_timeout_random_offset default value is 30. The " -"end result is amount of seconds before next retry." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:780 -msgid "" -"Note that the maximum length of each interval is defined by " -"offline_timeout_max (apart of random part)." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:784 sssd.conf.5.xml:1110 sssd.conf.5.xml:1490 -#: sssd.conf.5.xml:1791 sssd-ldap.5.xml:550 -msgid "Default: 60" -msgstr "Per defecte: 60" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:789 -#, fuzzy -#| msgid "offline_timeout (integer)" -msgid "offline_timeout_max (integer)" -msgstr "offline_timeout (enter)" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:792 -msgid "" -"Controls by how much the time between attempts to go online can be " -"incremented following unsuccessful attempts to go online." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:797 -msgid "A value of 0 disables the incrementing behaviour." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:800 -msgid "" -"The value of this parameter should be set in correlation to offline_timeout " -"parameter value." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:804 -msgid "" -"With offline_timeout set to 60 (default value) there is no point in setting " -"offlinet_timeout_max to less than 120 as it will saturate instantly. General " -"rule here should be to set offline_timeout_max to at least 4 times " -"offline_timeout." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:810 -msgid "" -"Although a value between 0 and offline_timeout may be specified, it has the " -"effect of overriding the offline_timeout value so is of little use." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:815 -#, fuzzy -#| msgid "Default: 300" -msgid "Default: 3600" -msgstr "Per defecte: 300" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:820 -#, fuzzy -#| msgid "offline_timeout + random_offset" -msgid "offline_timeout_random_offset (integer)" -msgstr "offline_timeout + random_offset" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:823 -msgid "" -"When SSSD is in offline mode it keeps probing backend servers in specified " -"time intervals:" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:830 -msgid "" -"This parameter controls the value of the random offset used for the above " -"equation. Final random_offset value will be random number in range:" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:835 -#, fuzzy -#| msgid "offline_timeout + random_offset" -msgid "[0 - offline_timeout_random_offset]" -msgstr "offline_timeout + random_offset" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:838 -msgid "A value of 0 disables the random offset addition." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:841 +#: sssd.conf.5.xml:798 #, fuzzy -#| msgid "Default: 300" -msgid "Default: 30" -msgstr "Per defecte: 300" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:846 -msgid "responder_idle_timeout" -msgstr "" +#| msgid "pam_id_timeout (integer)" +msgid "responder_idle_timeout (integer)" +msgstr "pam_id_timeout (enter)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:849 +#: sssd.conf.5.xml:801 msgid "" "This option specifies the number of seconds that an SSSD responder process " "can be up without being used. This value is limited in order to avoid " @@ -1228,43 +1163,50 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:863 sssd.conf.5.xml:1123 sssd.conf.5.xml:2248 +#: sssd.conf.5.xml:815 sssd.conf.5.xml:1079 sssd.conf.5.xml:2285 #: sssd-ldap.5.xml:377 msgid "Default: 300" msgstr "Per defecte: 300" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:868 -msgid "cache_first" -msgstr "" +#: sssd.conf.5.xml:820 +#, fuzzy +#| msgid "ldap_referrals (boolean)" +msgid "cache_first (boolean)" +msgstr "ldap_referrals (booleà)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:871 +#: sssd.conf.5.xml:823 msgid "" "This option specifies whether the responder should query all caches before " "querying the Data Providers." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:883 +#: sssd.conf.5.xml:835 msgid "NSS configuration options" msgstr "Opcions de configuració de l'NSS" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:885 +#: sssd.conf.5.xml:837 +#, fuzzy +#| msgid "" +#| "These options can be used to configure the Name Service Switch (NSS) " +#| "service." msgid "" -"These options can be used to configure the Name Service Switch (NSS) service." +"These options can be used to configure the Name Service Switch (NSS) service " +"and should be specified under the <quote>[nss]</quote> section." msgstr "" "Es poden utilitzar aquestes opcions per configurar el servei del NSS (Name " "Service Switch)." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:890 +#: sssd.conf.5.xml:843 msgid "enum_cache_timeout (integer)" msgstr "enum_cache_timeout (enter)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:893 +#: sssd.conf.5.xml:846 msgid "" "How many seconds should nss_sss cache enumerations (requests for info about " "all users)" @@ -1273,17 +1215,17 @@ msgstr "" "(peticions d'informació sobre tots els usuaris)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:897 +#: sssd.conf.5.xml:850 msgid "Default: 120" msgstr "Per defecte: 120" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:902 +#: sssd.conf.5.xml:855 msgid "entry_cache_nowait_percentage (integer)" msgstr "entry_cache_nowait_percentage (enter)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:905 +#: sssd.conf.5.xml:858 msgid "" "The entry cache can be set to automatically update entries in the background " "if they are requested beyond a percentage of the entry_cache_timeout value " @@ -1294,7 +1236,7 @@ msgstr "" "valor entry_cache_timeout per al domini." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:911 +#: sssd.conf.5.xml:864 msgid "" "For example, if the domain's entry_cache_timeout is set to 30s and " "entry_cache_nowait_percentage is set to 50 (percent), entries that come in " @@ -1310,7 +1252,7 @@ msgstr "" "peticions que esperen per a una actualització de la memòria cau." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:921 +#: sssd.conf.5.xml:874 msgid "" "Valid values for this option are 0-99 and represent a percentage of the " "entry_cache_timeout for each domain. For performance reasons, this " @@ -1323,17 +1265,17 @@ msgstr "" "(0 desactiva aquesta característica)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:929 sssd.conf.5.xml:2061 +#: sssd.conf.5.xml:882 sssd.conf.5.xml:2093 msgid "Default: 50" msgstr "Per defecte: 50" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:934 +#: sssd.conf.5.xml:887 msgid "entry_negative_timeout (integer)" msgstr "entry_negative_timeout (enter)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:937 +#: sssd.conf.5.xml:890 msgid "" "Specifies for how many seconds nss_sss should cache negative cache hits " "(that is, queries for invalid database entries, like nonexistent ones) " @@ -1345,17 +1287,17 @@ msgstr "" "altra vegada." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:943 sssd.conf.5.xml:1685 sssd.conf.5.xml:2085 +#: sssd.conf.5.xml:896 sssd.conf.5.xml:1677 sssd.conf.5.xml:2119 msgid "Default: 15" msgstr "Per defecte: 15" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:948 +#: sssd.conf.5.xml:901 msgid "filter_users, filter_groups (string)" msgstr "filter_users, filter_groups (cadena)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:951 +#: sssd.conf.5.xml:904 msgid "" "Exclude certain users or groups from being fetched from the sss NSS " "database. This is particularly useful for system accounts. This option can " @@ -1364,7 +1306,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:959 +#: sssd.conf.5.xml:912 msgid "" "NOTE: The filter_groups option doesn't affect inheritance of nested group " "members, since filtering happens after they are propagated for returning via " @@ -1373,30 +1315,35 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:967 +#: sssd.conf.5.xml:920 msgid "Default: root" msgstr "Per defecte: root" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:972 -msgid "filter_users_in_groups (bool)" +#: sssd.conf.5.xml:925 +#, fuzzy +#| msgid "filter_users_in_groups (bool)" +msgid "filter_users_in_groups (boolean)" msgstr "filter_users_in_groups (booleà)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:975 +#: sssd.conf.5.xml:928 +#, fuzzy +#| msgid "" +#| "If you want filtered user still be group members set this option to false." msgid "" -"If you want filtered user still be group members set this option to false." +"If you want filtered users to remain group members set this option to false" msgstr "" "Si voleu que els usuaris filtrats encara siguin membres del grup establiu " "aquesta opció a false." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:986 +#: sssd.conf.5.xml:939 msgid "fallback_homedir (string)" msgstr "fallback_homedir (cadena)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:989 +#: sssd.conf.5.xml:942 msgid "" "Set a default template for a user's home directory if one is not specified " "explicitly by the domain's data provider." @@ -1405,7 +1352,7 @@ msgstr "" "si no se n'especifica cap explícitament amb el proveïdor de dades del domini." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:994 +#: sssd.conf.5.xml:947 msgid "" "The available values for this option are the same as for override_homedir." msgstr "" @@ -1413,7 +1360,7 @@ msgstr "" "override_homedir." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1000 +#: sssd.conf.5.xml:953 #, no-wrap msgid "" "fallback_homedir = /home/%u\n" @@ -1423,25 +1370,25 @@ msgstr "" " " #. type: Content of: <varlistentry><listitem><para> -#: sssd.conf.5.xml:998 sssd.conf.5.xml:1557 sssd.conf.5.xml:1576 -#: sssd.conf.5.xml:1653 sssd-krb5.5.xml:451 include/override_homedir.xml:78 +#: sssd.conf.5.xml:951 sssd.conf.5.xml:1524 sssd.conf.5.xml:1543 +#: sssd.conf.5.xml:1645 sssd-krb5.5.xml:451 include/override_homedir.xml:78 msgid "example: <placeholder type=\"programlisting\" id=\"0\"/>" msgstr "exemple: <placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1004 +#: sssd.conf.5.xml:957 msgid "Default: not set (no substitution for unset home directories)" msgstr "" "Per defecte: sense establir (cap substitució per als directoris inicials no " "establerts)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1010 +#: sssd.conf.5.xml:963 msgid "override_shell (string)" msgstr "override_shell (cadena)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1013 +#: sssd.conf.5.xml:966 msgid "" "Override the login shell for all users. This option supersedes any other " "shell options if it takes effect and can be set either in the [nss] section " @@ -1452,18 +1399,18 @@ msgstr "" "pot configurar ja sigui en la secció [nss] o per cada domini." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1019 +#: sssd.conf.5.xml:972 msgid "Default: not set (SSSD will use the value retrieved from LDAP)" msgstr "" "Per defecte: sense establir (SSSD utilitzarà el valor recuperat del LDAP)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1025 +#: sssd.conf.5.xml:978 msgid "allowed_shells (string)" msgstr "allowed_shells (cadena)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1028 +#: sssd.conf.5.xml:981 msgid "" "Restrict user shell to one of the listed values. The order of evaluation is:" msgstr "" @@ -1471,31 +1418,31 @@ msgstr "" "d'avaluació és:" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1031 +#: sssd.conf.5.xml:984 msgid "1. If the shell is present in <quote>/etc/shells</quote>, it is used." msgstr "1. Si el shell està present al <quote>/etc/shells</quote>, s'utilitza." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1035 +#: sssd.conf.5.xml:988 msgid "" "2. If the shell is in the allowed_shells list but not in <quote>/etc/shells</" "quote>, use the value of the shell_fallback parameter." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1040 +#: sssd.conf.5.xml:993 msgid "" "3. If the shell is not in the allowed_shells list and not in <quote>/etc/" "shells</quote>, a nologin shell is used." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1045 +#: sssd.conf.5.xml:998 msgid "The wildcard (*) can be used to allow any shell." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1048 +#: sssd.conf.5.xml:1001 msgid "" "The (*) is useful if you want to use shell_fallback in case that user's " "shell is not in <quote>/etc/shells</quote> and maintaining list of all " @@ -1503,117 +1450,123 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1055 +#: sssd.conf.5.xml:1008 msgid "An empty string for shell is passed as-is to libc." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1058 +#: sssd.conf.5.xml:1011 msgid "" "The <quote>/etc/shells</quote> is only read on SSSD start up, which means " "that a restart of the SSSD is required in case a new shell is installed." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1062 +#: sssd.conf.5.xml:1015 msgid "Default: Not set. The user shell is automatically used." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1067 +#: sssd.conf.5.xml:1020 msgid "vetoed_shells (string)" msgstr "vetoed_shells (cadena)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1070 +#: sssd.conf.5.xml:1023 msgid "Replace any instance of these shells with the shell_fallback" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1075 +#: sssd.conf.5.xml:1031 msgid "shell_fallback (string)" msgstr "shell_fallback (cadena)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1078 +#: sssd.conf.5.xml:1034 msgid "" "The default shell to use if an allowed shell is not installed on the machine." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1082 +#: sssd.conf.5.xml:1038 msgid "Default: /bin/sh" msgstr "Per defecte: /bin/sh" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1087 -msgid "default_shell" -msgstr "default_shell" +#: sssd.conf.5.xml:1043 +msgid "default_shell (string)" +msgstr "default_shell (cadena)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1090 +#: sssd.conf.5.xml:1046 msgid "" "The default shell to use if the provider does not return one during lookup. " "This option can be specified globally in the [nss] section or per-domain." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1096 +#: sssd.conf.5.xml:1052 msgid "" "Default: not set (Return NULL if no shell is specified and rely on libc to " "substitute something sensible when necessary, usually /bin/sh)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1103 sssd.conf.5.xml:1483 +#: sssd.conf.5.xml:1059 sssd.conf.5.xml:1450 msgid "get_domains_timeout (int)" msgstr "get_domains_timeout (enter)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1106 sssd.conf.5.xml:1486 +#: sssd.conf.5.xml:1062 sssd.conf.5.xml:1453 msgid "" "Specifies time in seconds for which the list of subdomains will be " "considered valid." msgstr "" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1066 sssd.conf.5.xml:1457 sssd.conf.5.xml:1788 +#: sssd.conf.5.xml:2862 sssd-ldap.5.xml:550 +msgid "Default: 60" +msgstr "Per defecte: 60" + #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1115 +#: sssd.conf.5.xml:1071 #, fuzzy #| msgid "enum_cache_timeout (integer)" msgid "memcache_timeout (integer)" msgstr "enum_cache_timeout (enter)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1118 +#: sssd.conf.5.xml:1074 msgid "" "Specifies time in seconds for which records in the in-memory cache will be " "valid. Setting this option to zero will disable the in-memory cache." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1126 +#: sssd.conf.5.xml:1082 msgid "" "WARNING: Disabling the in-memory cache will have significant negative impact " "on SSSD's performance and should only be used for testing." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1132 sssd.conf.5.xml:1157 sssd.conf.5.xml:1182 -#: sssd.conf.5.xml:1207 sssd.conf.5.xml:1234 +#: sssd.conf.5.xml:1088 sssd.conf.5.xml:1113 sssd.conf.5.xml:1138 +#: sssd.conf.5.xml:1163 sssd.conf.5.xml:1190 msgid "" "NOTE: If the environment variable SSS_NSS_USE_MEMCACHE is set to \"NO\", " "client applications will not use the fast in-memory cache." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1140 +#: sssd.conf.5.xml:1096 #, fuzzy #| msgid "enum_cache_timeout (integer)" msgid "memcache_size_passwd (integer)" msgstr "enum_cache_timeout (enter)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1143 +#: sssd.conf.5.xml:1099 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for passwd requests. Setting the size to 0 will disable the passwd in-" @@ -1621,27 +1574,27 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1149 sssd.conf.5.xml:2888 sssd-ldap.5.xml:604 +#: sssd.conf.5.xml:1105 sssd.conf.5.xml:3013 sssd-ldap.5.xml:604 msgid "Default: 8" msgstr "Per defecte: 8" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1152 sssd.conf.5.xml:1177 sssd.conf.5.xml:1202 -#: sssd.conf.5.xml:1229 +#: sssd.conf.5.xml:1108 sssd.conf.5.xml:1133 sssd.conf.5.xml:1158 +#: sssd.conf.5.xml:1185 msgid "" "WARNING: Disabled or too small in-memory cache can have significant negative " "impact on SSSD's performance." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1165 +#: sssd.conf.5.xml:1121 #, fuzzy #| msgid "enum_cache_timeout (integer)" msgid "memcache_size_group (integer)" msgstr "enum_cache_timeout (enter)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1168 +#: sssd.conf.5.xml:1124 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for group requests. Setting the size to 0 will disable the group in-memory " @@ -1649,21 +1602,21 @@ msgid "" msgstr "" #. type: Content of: <variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1174 sssd.conf.5.xml:1226 sssd.conf.5.xml:3656 +#: sssd.conf.5.xml:1130 sssd.conf.5.xml:1182 sssd.conf.5.xml:3835 #: sssd-ldap.5.xml:534 sssd-ldap.5.xml:581 include/failover.xml:116 #: include/krb5_options.xml:11 msgid "Default: 6" msgstr "Per defecte: 6" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1190 +#: sssd.conf.5.xml:1146 #, fuzzy #| msgid "enum_cache_timeout (integer)" msgid "memcache_size_initgroups (integer)" msgstr "enum_cache_timeout (enter)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1193 +#: sssd.conf.5.xml:1149 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for initgroups requests. Setting the size to 0 will disable the initgroups " @@ -1671,14 +1624,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1215 +#: sssd.conf.5.xml:1171 #, fuzzy #| msgid "enum_cache_timeout (integer)" msgid "memcache_size_sid (integer)" msgstr "enum_cache_timeout (enter)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1218 +#: sssd.conf.5.xml:1174 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for SID related requests. Only SID-by-ID and ID-by-SID requests are " @@ -1687,12 +1640,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1242 sssd-ifp.5.xml:90 +#: sssd.conf.5.xml:1198 sssd-ifp.5.xml:90 msgid "user_attributes (string)" msgstr "user_attributes (cadena)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1245 +#: sssd.conf.5.xml:1201 msgid "" "Some of the additional NSS responder requests can return more attributes " "than just the POSIX ones defined by the NSS interface. The list of " @@ -1703,71 +1656,81 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1258 +#: sssd.conf.5.xml:1214 msgid "" "To make configuration more easy the NSS responder will check the InfoPipe " "option if it is not set for the NSS responder." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1263 +#: sssd.conf.5.xml:1219 msgid "Default: not set, fallback to InfoPipe option" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1268 +#: sssd.conf.5.xml:1224 msgid "pwfield (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1271 +#: sssd.conf.5.xml:1227 msgid "" "The value that NSS operations that return users or groups will return for " "the <quote>password</quote> field." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1276 +#: sssd.conf.5.xml:1232 +msgid "" +"This option can also be set per-domain, which overwrites the value in the " +"<quote>[nss]</quote> section for that domain. This is particularly useful " +"when using a proxy domain with <option>proxy_lib_name=files</option> and a " +"<option>proxy_pam_target</option> other than <quote>sssd-shadowutils</" +"quote>. In that case, SSSD returns <quote>*</quote> for the password field " +"by default, which causes <command>pam_unix</command> to treat all accounts " +"as locked. Setting <option>pwfield = x</option> in the domain section " +"restores the expected behavior." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1246 #, fuzzy #| msgid "Default: <quote>permit</quote>" msgid "Default: <quote>*</quote>" msgstr "Per defecte: <quote>permit</quote>" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1279 -msgid "" -"Note: This option can also be set per-domain which overwrites the value in " -"[nss] section." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1283 +#: sssd.conf.5.xml:1249 msgid "" -"Default: <quote>not set</quote> (remote domains), <quote>x</quote> (proxy " -"domain with nss_files and sssd-shadowutils target)" +"Default (per-domain): <quote>not set</quote> (remote domains), <quote>x</" +"quote> (proxy domain with nss_files and sssd-shadowutils target)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:1292 +#: sssd.conf.5.xml:1258 msgid "PAM configuration options" msgstr "Opcions de configuració del PAM" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:1294 +#: sssd.conf.5.xml:1260 +#, fuzzy +#| msgid "" +#| "These options can be used to configure the Pluggable Authentication " +#| "Module (PAM) service." msgid "" "These options can be used to configure the Pluggable Authentication Module " -"(PAM) service." +"(PAM) service and should be specified under the <quote>[pam]</quote> section." msgstr "" "Es poden utilitzar aquestes opcions per configurar el servei del PAM " "(Pluggable Authentication Module)." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1299 +#: sssd.conf.5.xml:1266 msgid "offline_credentials_expiration (integer)" msgstr "offline_credentials_expiration (enter)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1302 +#: sssd.conf.5.xml:1269 msgid "" "If the authentication provider is offline, how long should we allow cached " "logins (in days since the last successful online login)." @@ -1777,17 +1740,17 @@ msgstr "" "de sessió)." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1307 sssd.conf.5.xml:1320 +#: sssd.conf.5.xml:1274 sssd.conf.5.xml:1287 msgid "Default: 0 (No limit)" msgstr "Per defecte: 0 (sense límit)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1313 +#: sssd.conf.5.xml:1280 msgid "offline_failed_login_attempts (integer)" msgstr "offline_failed_login_attempts (enter)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1316 +#: sssd.conf.5.xml:1283 msgid "" "If the authentication provider is offline, how many failed login attempts " "are allowed." @@ -1796,12 +1759,12 @@ msgstr "" "fallits es permet." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1326 +#: sssd.conf.5.xml:1293 msgid "offline_failed_login_delay (integer)" msgstr "offline_failed_login_delay (enter)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1329 +#: sssd.conf.5.xml:1296 msgid "" "The time in minutes which has to pass after offline_failed_login_attempts " "has been reached before a new login attempt is possible." @@ -1811,7 +1774,7 @@ msgstr "" "possible." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1334 +#: sssd.conf.5.xml:1301 msgid "" "If set to 0 the user cannot authenticate offline if " "offline_failed_login_attempts has been reached. Only a successful online " @@ -1819,17 +1782,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1340 sssd.conf.5.xml:1450 +#: sssd.conf.5.xml:1307 sssd.conf.5.xml:1417 msgid "Default: 5" msgstr "Per defecte: 5" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1346 +#: sssd.conf.5.xml:1313 msgid "pam_verbosity (integer)" msgstr "pam_verbosity (enter)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1349 +#: sssd.conf.5.xml:1316 msgid "" "Controls what kind of messages are shown to the user during authentication. " "The higher the number to more messages are displayed." @@ -1838,45 +1801,45 @@ msgstr "" "l'autenticació. Com més gran sigui el nombre més missatges es mostren." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1354 +#: sssd.conf.5.xml:1321 msgid "Currently sssd supports the following values:" msgstr "L'sssd actualment admet els següents valors:" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1357 +#: sssd.conf.5.xml:1324 msgid "<emphasis>0</emphasis>: do not show any message" msgstr "<emphasis>0</emphasis>: no mostris cap missatge" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1360 +#: sssd.conf.5.xml:1327 msgid "<emphasis>1</emphasis>: show only important messages" msgstr "<emphasis>1</emphasis>: Mostra només missatges importants" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1364 +#: sssd.conf.5.xml:1331 msgid "<emphasis>2</emphasis>: show informational messages" msgstr "<emphasis>2</emphasis>: Mostra missatges informatius" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1367 +#: sssd.conf.5.xml:1334 msgid "<emphasis>3</emphasis>: show all messages and debug information" msgstr "" "<emphasis>3</emphasis>: Mostra tots els missatges i informació de depuració" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1371 sssd.8.xml:63 +#: sssd.conf.5.xml:1338 sssd.8.xml:63 msgid "Default: 1" msgstr "Per defecte: 1" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1377 +#: sssd.conf.5.xml:1344 #, fuzzy #| msgid "ad_access_filter (string)" msgid "pam_response_filter (string)" msgstr "ad_access_filter (cadena)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1380 +#: sssd.conf.5.xml:1347 msgid "" "A comma separated list of strings which allows to remove (filter) data sent " "by the PAM responder to pam_sss PAM module. There are different kind of " @@ -1885,51 +1848,51 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1388 +#: sssd.conf.5.xml:1355 msgid "" "While messages already can be controlled with the help of the pam_verbosity " "option this option allows to filter out other kind of responses as well." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1395 +#: sssd.conf.5.xml:1362 msgid "ENV" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1396 +#: sssd.conf.5.xml:1363 msgid "Do not send any environment variables to any service." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1399 +#: sssd.conf.5.xml:1366 msgid "ENV:var_name" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1400 +#: sssd.conf.5.xml:1367 msgid "Do not send environment variable var_name to any service." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1404 +#: sssd.conf.5.xml:1371 msgid "ENV:var_name:service" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1405 +#: sssd.conf.5.xml:1372 msgid "Do not send environment variable var_name to service." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1393 +#: sssd.conf.5.xml:1360 msgid "" "Currently the following filters are supported: <placeholder " "type=\"variablelist\" id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1412 +#: sssd.conf.5.xml:1379 msgid "" "The list of strings can either be the list of filters which would set this " "list of filters and overwrite the defaults. Or each element of the list can " @@ -1940,23 +1903,23 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1423 +#: sssd.conf.5.xml:1390 msgid "Default: ENV:KRB5CCNAME:sudo, ENV:KRB5CCNAME:sudo-i" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1426 +#: sssd.conf.5.xml:1393 msgid "" "Example: -ENV:KRB5CCNAME:sudo-i will remove the filter from the default list" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1433 +#: sssd.conf.5.xml:1400 msgid "pam_id_timeout (integer)" msgstr "pam_id_timeout (enter)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1436 +#: sssd.conf.5.xml:1403 msgid "" "For any PAM request while SSSD is online, the SSSD will attempt to " "immediately update the cached identity information for the user in order to " @@ -1968,7 +1931,7 @@ msgstr "" "l'última informació." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1442 +#: sssd.conf.5.xml:1409 msgid "" "A complete PAM conversation may perform multiple PAM requests, such as " "account management and session opening. This option controls (on a per-" @@ -1982,17 +1945,17 @@ msgstr "" "excessives al proveïdor d'identitat." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1456 +#: sssd.conf.5.xml:1423 msgid "pam_pwd_expiration_warning (integer)" msgstr "pam_pwd_expiration_warning (enter)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1459 sssd.conf.5.xml:2912 +#: sssd.conf.5.xml:1426 sssd.conf.5.xml:3037 msgid "Display a warning N days before the password expires." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1462 +#: sssd.conf.5.xml:1429 msgid "" "Please note that the backend server has to provide information about the " "expiration time of the password. If this information is missing, sssd " @@ -2000,32 +1963,32 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1468 sssd.conf.5.xml:2915 +#: sssd.conf.5.xml:1435 sssd.conf.5.xml:3040 msgid "" "If zero is set, then this filter is not applied, i.e. if the expiration " "warning was received from backend server, it will automatically be displayed." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1473 +#: sssd.conf.5.xml:1440 msgid "" "This setting can be overridden by setting <emphasis>pwd_expiration_warning</" "emphasis> for a particular domain." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1478 sssd.conf.5.xml:3913 sssd-ldap.5.xml:662 +#: sssd.conf.5.xml:1445 sssd.conf.5.xml:4118 sssd-ldap.5.xml:662 #: sssd-ldap.5.xml:1733 sssd.8.xml:79 msgid "Default: 0" msgstr "Per defecte: 0" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1495 +#: sssd.conf.5.xml:1462 msgid "pam_trusted_users (string)" msgstr "pam_trusted_users (cadena)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1498 +#: sssd.conf.5.xml:1465 msgid "" "Specifies the comma-separated list of UID values or user names that are " "allowed to run PAM conversations against trusted domains. Users not " @@ -2035,74 +1998,74 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1508 +#: sssd.conf.5.xml:1475 msgid "Default: All users are considered trusted by default" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1512 +#: sssd.conf.5.xml:1479 msgid "" "Please note that UID 0 is always allowed to access the PAM responder even in " "case it is not in the pam_trusted_users list." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1519 +#: sssd.conf.5.xml:1486 msgid "pam_public_domains (string)" msgstr "pam_public_domains (cadena)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1522 +#: sssd.conf.5.xml:1489 msgid "" "Specifies the comma-separated list of domain names that are accessible even " "to untrusted users." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1526 +#: sssd.conf.5.xml:1493 msgid "Two special values for pam_public_domains option are defined:" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1530 +#: sssd.conf.5.xml:1497 msgid "" "all (Untrusted users are allowed to access all domains in PAM responder.)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1534 +#: sssd.conf.5.xml:1501 msgid "" "none (Untrusted users are not allowed to access any domains PAM in " "responder.)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1538 sssd.conf.5.xml:1563 sssd.conf.5.xml:1582 -#: sssd.conf.5.xml:1824 sssd.conf.5.xml:3842 sssd-ldap.5.xml:1270 +#: sssd.conf.5.xml:1505 sssd.conf.5.xml:1530 sssd.conf.5.xml:1549 +#: sssd.conf.5.xml:1821 sssd.conf.5.xml:4048 sssd-ldap.5.xml:1270 msgid "Default: none" msgstr "Per defecte: none" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1543 +#: sssd.conf.5.xml:1510 msgid "pam_account_expired_message (string)" msgstr "pam_account_expired_message (cadena)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1546 +#: sssd.conf.5.xml:1513 msgid "" "Allows a custom expiration message to be set, replacing the default " "'Permission denied' message." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1551 +#: sssd.conf.5.xml:1518 msgid "" "Note: Please be aware that message is only printed for the SSH service " "unless pam_verbosity is set to 3 (show all messages and debug information)." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1559 +#: sssd.conf.5.xml:1526 #, no-wrap msgid "" "pam_account_expired_message = Account expired, please contact help desk.\n" @@ -2110,19 +2073,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1568 +#: sssd.conf.5.xml:1535 msgid "pam_account_locked_message (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1571 +#: sssd.conf.5.xml:1538 msgid "" "Allows a custom lockout message to be set, replacing the default 'Permission " "denied' message." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1578 +#: sssd.conf.5.xml:1545 #, no-wrap msgid "" "pam_account_locked_message = Account locked, please contact help desk.\n" @@ -2130,85 +2093,130 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1587 +#: sssd.conf.5.xml:1554 #, fuzzy #| msgid "ldap_chpass_update_last_change (bool)" -msgid "pam_passkey_auth (bool)" +msgid "pam_passkey_auth (boolean)" msgstr "ldap_chpass_update_last_change (booleà)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1590 +#: sssd.conf.5.xml:1557 msgid "Enable passkey device based authentication." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1593 sssd.conf.5.xml:1910 sssd-ad.5.xml:1286 +#: sssd.conf.5.xml:1560 sssd.conf.5.xml:1907 sssd-ad.5.xml:1279 #: sss_rpcidmapd.5.xml:76 msgid "Default: True" msgstr "Per defecte: True" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1598 -msgid "passkey_debug_libfido2 (bool)" -msgstr "" +#: sssd.conf.5.xml:1565 +#, fuzzy +#| msgid "ldap_user_certificate (string)" +msgid "passkey_debug_libfido2 (boolean)" +msgstr "ldap_user_certificate (cadena)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1601 +#: sssd.conf.5.xml:1568 msgid "Enable libfido2 library debug messages." msgstr "" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1604 sssd.conf.5.xml:1618 sssd-ldap.5.xml:727 -#: sssd-ldap.5.xml:752 sssd-ldap.5.xml:848 sssd-ldap.5.xml:1356 -#: sssd-ad.5.xml:506 sssd-ad.5.xml:582 sssd-ad.5.xml:1155 +#: sssd.conf.5.xml:1571 sssd.conf.5.xml:1585 sssd.conf.5.xml:4781 +#: sssd-ldap.5.xml:727 sssd-ldap.5.xml:752 sssd-ldap.5.xml:848 +#: sssd-ldap.5.xml:1356 sssd-ad.5.xml:506 sssd-ad.5.xml:582 sssd-ad.5.xml:1160 #: include/ldap_id_mapping.xml:250 msgid "Default: False" msgstr "Per defecte: False" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1609 -msgid "pam_cert_auth (bool)" -msgstr "" +#: sssd.conf.5.xml:1576 +#, fuzzy +#| msgid "ldap_chpass_update_last_change (bool)" +msgid "pam_cert_auth (boolean)" +msgstr "ldap_chpass_update_last_change (booleà)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1612 +#: sssd.conf.5.xml:1579 msgid "" "Enable certificate based Smartcard authentication. Since this requires " "additional communication with the Smartcard which will delay the " "authentication process this option is disabled by default." msgstr "" +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1588 +msgid "" +"Note: In case OpenSC is used for Smartcard access SSSD supports the " +"filesystem caching in OpenSC when enabled in opensc.conf. The cached files " +"are located in a common <quote>opensc</quote> directory in SSSD's state " +"directory. The behaviour can be changed in opensc.conf" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> +#: sssd.conf.5.xml:1597 +#, no-wrap +msgid "" +"app /usr/libexec/sssd/p11_child {\n" +" framework pkcs15 {\n" +" use_file_caching = no;\n" +" }\n" +"}\n" +"app /usr/libexec/sssd/krb5_child {\n" +" framework pkcs15 {\n" +" use_file_caching = no;\n" +" }\n" +"}\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1595 +#, fuzzy +#| msgid "Example: <placeholder type=\"programlisting\" id=\"0\"/>" +msgid "" +"Example opensc.conf (*): <placeholder type=\"programlisting\" id=\"0\"/>" +msgstr "Exemple: <placeholder type=\"programlisting\" id=\"0\"/>" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1610 +msgid "" +"(*) The actual <quote>libexec</quote> directory for p11_child and krb5_child " +"depends on the distribution." +msgstr "" + #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1623 +#: sssd.conf.5.xml:1615 msgid "pam_cert_db_path (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1626 +#: sssd.conf.5.xml:1618 msgid "The path to the certificate database." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1629 sssd.conf.5.xml:2163 sssd.conf.5.xml:4338 +#: sssd.conf.5.xml:1621 sssd.conf.5.xml:2199 sssd.conf.5.xml:4543 msgid "Default:" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1631 sssd.conf.5.xml:2165 +#: sssd.conf.5.xml:1623 sssd.conf.5.xml:2201 msgid "" "/etc/sssd/pki/sssd_auth_ca_db.pem (path to a file with trusted CA " "certificates in PEM format)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1641 +#: sssd.conf.5.xml:1633 #, fuzzy #| msgid "ldap_user_certificate (string)" msgid "pam_cert_verification (string)" msgstr "ldap_user_certificate (cadena)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1644 +#: sssd.conf.5.xml:1636 msgid "" "With this parameter the PAM certificate verification can be tuned with a " "comma separated list of options that override the " @@ -2218,7 +2226,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1655 +#: sssd.conf.5.xml:1647 #, fuzzy, no-wrap #| msgid "" #| "ad_gpo_map_service = +my_pam_service\n" @@ -2231,63 +2239,63 @@ msgstr "" " " #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1659 +#: sssd.conf.5.xml:1651 msgid "" "Default: not set, i.e. use default <quote>certificate_verification</quote> " "option defined in <quote>[sssd]</quote> section." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1666 +#: sssd.conf.5.xml:1658 msgid "p11_child_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1669 +#: sssd.conf.5.xml:1661 msgid "How many seconds will pam_sss wait for p11_child to finish." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1678 +#: sssd.conf.5.xml:1670 #, fuzzy #| msgid "pam_id_timeout (integer)" msgid "passkey_child_timeout (integer)" msgstr "pam_id_timeout (enter)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1681 +#: sssd.conf.5.xml:1673 msgid "" "How many seconds will the PAM responder wait for passkey_child to finish." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1690 +#: sssd.conf.5.xml:1682 msgid "pam_app_services (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1693 +#: sssd.conf.5.xml:1685 msgid "" "Which PAM services are permitted to contact domains of type " "<quote>application</quote>" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1702 +#: sssd.conf.5.xml:1694 #, fuzzy #| msgid "ad_gpo_map_service (string)" msgid "pam_p11_allowed_services (string)" msgstr "ad_gpo_map_service (cadena)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1705 +#: sssd.conf.5.xml:1697 msgid "" "A comma-separated list of PAM service names for which it will be allowed to " "use Smartcards." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1720 +#: sssd.conf.5.xml:1712 #, no-wrap msgid "" "pam_p11_allowed_services = +my_pam_service, -login\n" @@ -2295,7 +2303,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1709 +#: sssd.conf.5.xml:1701 msgid "" "It is possible to add another PAM service name to the default set by using " "<quote>+service_name</quote> or to explicitly remove a PAM service name from " @@ -2307,68 +2315,75 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1724 sssd-ad.5.xml:645 sssd-ad.5.xml:754 sssd-ad.5.xml:812 -#: sssd-ad.5.xml:870 sssd-ad.5.xml:948 +#: sssd.conf.5.xml:1716 sssd-ad.5.xml:645 sssd-ad.5.xml:759 sssd-ad.5.xml:817 +#: sssd-ad.5.xml:875 sssd-ad.5.xml:953 msgid "Default: the default set of PAM service names includes:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1729 sssd-ad.5.xml:649 +#: sssd.conf.5.xml:1721 sssd-ad.5.xml:649 msgid "login" msgstr "login" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1734 sssd-ad.5.xml:654 +#: sssd.conf.5.xml:1726 sssd-ad.5.xml:654 msgid "su" msgstr "su" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1739 sssd-ad.5.xml:659 +#: sssd.conf.5.xml:1731 sssd-ad.5.xml:659 msgid "su-l" msgstr "su-l" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1744 sssd-ad.5.xml:674 +#: sssd.conf.5.xml:1736 sssd-ad.5.xml:674 msgid "gdm-smartcard" msgstr "gdm-smartcard" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1749 sssd-ad.5.xml:669 +#: sssd.conf.5.xml:1741 sssd-ad.5.xml:669 msgid "gdm-password" msgstr "gdm-password" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1754 +#: sssd.conf.5.xml:1746 msgid "gdm-switchable-auth" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1759 sssd-ad.5.xml:679 +#: sssd.conf.5.xml:1751 sssd-ad.5.xml:679 msgid "kdm" msgstr "kdm" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1764 sssd-ad.5.xml:957 +#: sssd.conf.5.xml:1756 sssd-ad.5.xml:694 +#, fuzzy +#| msgid "login" +msgid "plasmalogin" +msgstr "login" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:1761 sssd-ad.5.xml:962 msgid "sudo" msgstr "sudo" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1769 sssd-ad.5.xml:962 +#: sssd.conf.5.xml:1766 sssd-ad.5.xml:967 msgid "sudo-i" msgstr "sudo-i" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1774 +#: sssd.conf.5.xml:1771 msgid "gnome-screensaver" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1782 +#: sssd.conf.5.xml:1779 msgid "p11_wait_for_card_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1785 +#: sssd.conf.5.xml:1782 msgid "" "If Smartcard authentication is required how many extra seconds in addition " "to p11_child_timeout should the PAM responder wait until a Smartcard is " @@ -2376,12 +2391,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1796 +#: sssd.conf.5.xml:1793 msgid "p11_uri (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1799 +#: sssd.conf.5.xml:1796 msgid "" "PKCS#11 URI (see RFC-7512 for details) which can be used to restrict the " "selection of devices used for Smartcard authentication. By default SSSD's " @@ -2392,7 +2407,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1812 +#: sssd.conf.5.xml:1809 #, no-wrap msgid "" "p11_uri = pkcs11:slot-description=My%20Smartcard%20Reader\n" @@ -2400,7 +2415,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1816 +#: sssd.conf.5.xml:1813 #, no-wrap msgid "" "p11_uri = pkcs11:library-description=OpenSC%20smartcard%20framework;slot-id=2\n" @@ -2408,7 +2423,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1810 +#: sssd.conf.5.xml:1807 msgid "" "Example: <placeholder type=\"programlisting\" id=\"0\"/> or <placeholder " "type=\"programlisting\" id=\"1\"/> To find suitable URI please check the " @@ -2417,47 +2432,49 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1829 -msgid "pam_initgroups_scheme" -msgstr "" +#: sssd.conf.5.xml:1826 +#, fuzzy +#| msgid "ldap_netgroup_member (string)" +msgid "pam_initgroups_scheme (string)" +msgstr "ldap_netgroup_member (cadena)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1837 +#: sssd.conf.5.xml:1834 msgid "always" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1838 +#: sssd.conf.5.xml:1835 msgid "" "Always do an online lookup, please note that pam_id_timeout still applies" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1842 +#: sssd.conf.5.xml:1839 msgid "no_session" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1843 +#: sssd.conf.5.xml:1840 msgid "" "Only do an online lookup if there is no active session of the user, i.e. if " "the user is currently not logged in" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1848 sssd-ldap.5.xml:189 +#: sssd.conf.5.xml:1845 sssd-ldap.5.xml:189 msgid "never" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1849 +#: sssd.conf.5.xml:1846 msgid "" "Never force an online lookup, use the data from the cache as long as they " "are not expired" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1832 +#: sssd.conf.5.xml:1829 msgid "" "The PAM responder can force an online lookup to get the current group " "memberships of the user trying to log in. This option controls when this " @@ -2466,19 +2483,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1856 +#: sssd.conf.5.xml:1853 msgid "Default: no_session" msgstr "" -#. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:1861 sssd.conf.5.xml:4277 +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1858 #, fuzzy #| msgid "ad_gpo_map_service (string)" -msgid "pam_gssapi_services" +msgid "pam_gssapi_services (string)" msgstr "ad_gpo_map_service (cadena)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1864 +#: sssd.conf.5.xml:1861 #, fuzzy #| msgid "Comma separated list of users who are allowed to log in." msgid "" @@ -2488,13 +2505,13 @@ msgstr "" "Llista separada per comes dels usuaris a qui se'ls permet iniciar la sessió." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1869 +#: sssd.conf.5.xml:1866 msgid "" "To disable GSSAPI authentication, set this option to <quote>-</quote> (dash)." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1873 sssd.conf.5.xml:1904 sssd.conf.5.xml:1942 +#: sssd.conf.5.xml:1870 sssd.conf.5.xml:1901 sssd.conf.5.xml:1939 msgid "" "Note: This option can also be set per-domain which overwrites the value in " "[pam] section. It can also be set for trusted domain which overwrites the " @@ -2502,7 +2519,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1881 +#: sssd.conf.5.xml:1878 #, fuzzy, no-wrap #| msgid "" #| "ad_gpo_map_service = +my_pam_service\n" @@ -2515,22 +2532,24 @@ msgstr "" " " #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1879 sssd.conf.5.xml:1994 sssd.conf.5.xml:3836 +#: sssd.conf.5.xml:1876 sssd.conf.5.xml:2023 sssd.conf.5.xml:4042 msgid "Example: <placeholder type=\"programlisting\" id=\"0\"/>" msgstr "Exemple: <placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1885 +#: sssd.conf.5.xml:1882 msgid "Default: - (GSSAPI authentication is disabled)" msgstr "" -#. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:1890 sssd.conf.5.xml:4278 -msgid "pam_gssapi_check_upn" -msgstr "" +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1887 +#, fuzzy +#| msgid "ldap_disable_paging (boolean)" +msgid "pam_gssapi_check_upn (boolean)" +msgstr "ldap_disable_paging (booleà)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1893 +#: sssd.conf.5.xml:1890 msgid "" "If True, SSSD will require that the Kerberos user principal that " "successfully authenticated through GSSAPI can be associated with the user " @@ -2538,19 +2557,21 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1900 +#: sssd.conf.5.xml:1897 msgid "" -"If False, every user that is able to obtained required service ticket will " +"If False, every user that is able to obtain a required service ticket will " "be authenticated." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1915 -msgid "pam_gssapi_indicators_map" -msgstr "" +#: sssd.conf.5.xml:1912 +#, fuzzy +#| msgid "pam_public_domains (string)" +msgid "pam_gssapi_indicators_map (string)" +msgstr "pam_public_domains (cadena)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1918 +#: sssd.conf.5.xml:1915 msgid "" "Comma separated list of authentication indicators required to be present in " "a Kerberos ticket to access a PAM service that is allowed to try GSSAPI " @@ -2558,7 +2579,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1924 +#: sssd.conf.5.xml:1921 msgid "" "Each element of the list can be either an authentication indicator name or a " "pair <quote>service:indicator</quote>. Indicators not prefixed with the PAM " @@ -2573,7 +2594,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1937 +#: sssd.conf.5.xml:1934 msgid "" "To disable GSSAPI authentication indicator check, set this option to <quote>-" "</quote> (dash). To disable the check for a specific PAM service, add " @@ -2581,45 +2602,45 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1948 +#: sssd.conf.5.xml:1945 msgid "" "Following authentication indicators are supported by IPA Kerberos " "deployments:" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1951 +#: sssd.conf.5.xml:1948 msgid "" "pkinit -- pre-authentication using X.509 certificates -- whether stored in " "files or on smart cards." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1954 +#: sssd.conf.5.xml:1951 msgid "" "hardened -- SPAKE pre-authentication or any pre-authentication wrapped in a " "FAST channel." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1957 +#: sssd.conf.5.xml:1954 msgid "radius -- pre-authentication with the help of a RADIUS server." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1960 +#: sssd.conf.5.xml:1957 msgid "" "otp -- pre-authentication using integrated two-factor authentication (2FA or " "one-time password, OTP) in IPA." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1963 +#: sssd.conf.5.xml:1960 msgid "idp -- pre-authentication using external identity provider." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1973 +#: sssd.conf.5.xml:1970 #, fuzzy, no-wrap #| msgid "" #| "ad_gpo_map_permit = +my_pam_service, -sudo\n" @@ -2632,7 +2653,7 @@ msgstr "" " " #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1968 +#: sssd.conf.5.xml:1965 msgid "" "Example: to require access to SUDO services only for users which obtained " "their Kerberos tickets with a X.509 certificate pre-authentication (PKINIT), " @@ -2640,7 +2661,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1977 +#: sssd.conf.5.xml:1974 #, fuzzy #| msgid "Default: not set (no substitution for unset home directories)" msgid "Default: not set (use of authentication indicators is not required)" @@ -2649,14 +2670,62 @@ msgstr "" "establerts)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1979 +#, fuzzy +#| msgid "base_directory (string)" +msgid "pam_gssapi_indicators_apply (string)" +msgstr "base_directory (cadena)" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1982 +msgid "" +"Comma separated list of triples to assign additional information from the " +"Kerberos ticket, e.g. a SID from the PAC, to authentication indicators." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1988 +#, fuzzy +#| msgid "Currently supported debug levels:" +msgid "Currently supported is:" +msgstr "Els nivells de depuració que s'admeten actualment:" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:1991 +msgid "SID:S-1-5-[domain]-[RID]:[authentication indicator]" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> +#: sssd.conf.5.xml:2002 +#, fuzzy, no-wrap +#| msgid "" +#| "ad_gpo_map_permit = +my_pam_service, -sudo\n" +#| " " +msgid "" +"pam_gssapi_indicators_apply = SID:S-1-5-12345-23456-34567-4321:pkinit\n" +" " +msgstr "" +"ad_gpo_map_permit = +my_pam_service, -sudo\n" +" " + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1996 +msgid "" +"Example: To assign a SID, which is e.g. set by Active Directory's " +"Authentication Mechanism Assurance (AMA) if the AD user used a Smartcard for " +"authentication, to the 'pkinit' authentication indicator use: <placeholder " +"type=\"programlisting\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2011 #, fuzzy #| msgid "ad_gpo_map_service (string)" msgid "pam_json_services (string)" msgstr "ad_gpo_map_service (cadena)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1985 +#: sssd.conf.5.xml:2014 #, fuzzy #| msgid "Comma separated list of users who are allowed to log in." msgid "" @@ -2666,12 +2735,12 @@ msgstr "" "Llista separada per comes dels usuaris a qui se'ls permet iniciar la sessió." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1990 +#: sssd.conf.5.xml:2019 msgid "To disable JSON protocol, set this option to <quote>-</quote> (dash)." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1996 +#: sssd.conf.5.xml:2025 #, fuzzy, no-wrap #| msgid "" #| "ad_gpo_map_service = +my_pam_service\n" @@ -2684,33 +2753,55 @@ msgstr "" " " #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2000 +#: sssd.conf.5.xml:2029 #, fuzzy #| msgid "Default: 0 (disabled)" msgid "Default: - (JSON protocol is disabled)" msgstr "Per defecte: 0 (inhabilitat)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2003 +#: sssd.conf.5.xml:2032 msgid "" "Note: 2-Factor Authentication (2FA) is not supported. If 2FA is required, do " "not activate the JSON protocol." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:2013 +#: sssd.conf.5.xml:2042 msgid "SUDO configuration options" msgstr "Opcions de configuració de SUDO" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2015 +#: sssd.conf.5.xml:2044 +#, fuzzy +#| msgid "" +#| "These options can be used to configure the Name Service Switch (NSS) " +#| "service." msgid "" -"These options can be used to configure the sudo service. The detailed " -"instructions for configuration of <citerefentry> <refentrytitle>sudo</" -"refentrytitle> <manvolnum>8</manvolnum> </citerefentry> to work with " -"<citerefentry> <refentrytitle>sssd</refentrytitle> <manvolnum>8</manvolnum> " -"</citerefentry> are in the manual page <citerefentry> <refentrytitle>sssd-" -"sudo</refentrytitle> <manvolnum>5</manvolnum> </citerefentry>." +"These options can be used to configure the sudo service and should be " +"specified under the <quote>[sudo]</quote> section." +msgstr "" +"Es poden utilitzar aquestes opcions per configurar el servei del NSS (Name " +"Service Switch)." + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:2048 +#, fuzzy +#| msgid "" +#| "These options can be used to configure the sudo service. The detailed " +#| "instructions for configuration of <citerefentry> <refentrytitle>sudo</" +#| "refentrytitle> <manvolnum>8</manvolnum> </citerefentry> to work with " +#| "<citerefentry> <refentrytitle>sssd</refentrytitle> <manvolnum>8</" +#| "manvolnum> </citerefentry> are in the manual page <citerefentry> " +#| "<refentrytitle>sssd-sudo</refentrytitle> <manvolnum>5</manvolnum> </" +#| "citerefentry>." +msgid "" +"The detailed instructions for configuration of <citerefentry> " +"<refentrytitle>sudo</refentrytitle> <manvolnum>8</manvolnum> </citerefentry> " +"to work with <citerefentry> <refentrytitle>sssd</refentrytitle> " +"<manvolnum>8</manvolnum> </citerefentry> are in the manual page " +"<citerefentry> <refentrytitle>sssd-sudo</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry>." msgstr "" "Es poden utilitzar aquestes opcions per configurar el servei del sudo. Les " "instruccions detallades per la configuració del <citerefentry> " @@ -2721,24 +2812,26 @@ msgstr "" "manvolnum> </citerefentry>." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2032 -msgid "sudo_timed (bool)" +#: sssd.conf.5.xml:2064 +#, fuzzy +#| msgid "sudo_timed (bool)" +msgid "sudo_timed (boolean)" msgstr "sudo_timed (booleà)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2035 +#: sssd.conf.5.xml:2067 msgid "" "Whether or not to evaluate the sudoNotBefore and sudoNotAfter attributes " "that implement time-dependent sudoers entries." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2047 +#: sssd.conf.5.xml:2079 msgid "sudo_threshold (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2050 +#: sssd.conf.5.xml:2082 msgid "" "Maximum number of expired rules that can be refreshed at once. If number of " "expired rules is below threshold, those rules are refreshed with " @@ -2748,23 +2841,27 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:2069 +#: sssd.conf.5.xml:2101 msgid "AUTOFS configuration options" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2071 -msgid "These options can be used to configure the autofs service." +#: sssd.conf.5.xml:2103 +#, fuzzy +#| msgid "These options can be used to configure the autofs service." +msgid "" +"These options can be used to configure the autofs service and should be " +"specified under the <quote>[autofs]</quote> section." msgstr "" "Es poden utilitzar aquestes opcions per configurar el servei de l'autofs." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2075 +#: sssd.conf.5.xml:2109 msgid "autofs_negative_timeout (integer)" msgstr "autofs_negative_timeout (enter)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2078 +#: sssd.conf.5.xml:2112 msgid "" "Specifies for how many seconds should the autofs responder negative cache " "hits (that is, queries for invalid map entries, like nonexistent ones) " @@ -2772,22 +2869,28 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:2094 +#: sssd.conf.5.xml:2128 msgid "SSH configuration options" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2096 -msgid "These options can be used to configure the SSH service." +#: sssd.conf.5.xml:2130 +#, fuzzy +#| msgid "These options can be used to configure the SSH service." +msgid "" +"These options can be used to configure the SSH service and should be " +"specified under the <quote>[ssh]</quote> section." msgstr "Es poden utilitzar aquestes opcions per configurar el servei de l'SSH." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2100 -msgid "ssh_use_certificate_keys (bool)" -msgstr "" +#: sssd.conf.5.xml:2136 +#, fuzzy +#| msgid "ldap_user_certificate (string)" +msgid "ssh_use_certificate_keys (boolean)" +msgstr "ldap_user_certificate (cadena)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2103 +#: sssd.conf.5.xml:2139 msgid "" "If set to true the <command>sss_ssh_authorizedkeys</command> will return ssh " "keys derived from the public key of X.509 certificates stored in the user " @@ -2796,12 +2899,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2118 +#: sssd.conf.5.xml:2154 msgid "ssh_use_certificate_matching_rules (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2121 +#: sssd.conf.5.xml:2157 msgid "" "By default the ssh responder will use all available certificate matching " "rules to filter the certificates so that ssh keys are only derived from the " @@ -2811,7 +2914,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2130 +#: sssd.conf.5.xml:2166 msgid "" "There are two special key words 'all_rules' and 'no_rules' which will enable " "all or no rules, respectively. The latter means that no certificates will be " @@ -2819,7 +2922,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2137 +#: sssd.conf.5.xml:2173 msgid "" "If no rules are configured using 'all_rules' will enable a default rule " "which enables all certificates suitable for client authentication. This is " @@ -2828,38 +2931,38 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2144 +#: sssd.conf.5.xml:2180 msgid "" "A non-existing rule name is considered an error. If as a result no rule is " "selected all certificates will be ignored." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2149 +#: sssd.conf.5.xml:2185 msgid "" "Default: not set, equivalent to 'all_rules', all found rules or the default " "rule are used" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2155 +#: sssd.conf.5.xml:2191 msgid "ca_db (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2158 +#: sssd.conf.5.xml:2194 msgid "" "Path to a storage of trusted CA certificates. The option is used to validate " "user certificates before deriving public ssh keys from them." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:2178 +#: sssd.conf.5.xml:2214 msgid "PAC responder configuration options" msgstr "Opcions de configuració del contestador del PAC." #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2180 +#: sssd.conf.5.xml:2216 msgid "" "The PAC responder works together with the authorization data plugin for MIT " "Kerberos sssd_pac_plugin.so and a sub-domain provider. The plugin sends the " @@ -2870,7 +2973,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:2189 +#: sssd.conf.5.xml:2225 msgid "" "If the remote user does not exist in the cache, it is created. The UID is " "determined with the help of the SID, trusted domains will have UPGs and the " @@ -2881,25 +2984,29 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:2197 +#: sssd.conf.5.xml:2233 msgid "" "If there are SIDs of groups from domains sssd knows about, the user will be " "added to those groups." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2203 -msgid "These options can be used to configure the PAC responder." +#: sssd.conf.5.xml:2239 +#, fuzzy +#| msgid "These options can be used to configure the PAC responder." +msgid "" +"These options can be used to configure the PAC responder and should be " +"specified under the <quote>[pac]</quote> section." msgstr "" "Es poden utilitzar aquestes opcions per configurar el contestador del PAC." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2207 sssd-ifp.5.xml:66 +#: sssd.conf.5.xml:2244 sssd-ifp.5.xml:66 msgid "allowed_uids (string)" msgstr "allowed_uids (cadena)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2210 +#: sssd.conf.5.xml:2247 msgid "" "Specifies the comma-separated list of UID values or user names that are " "allowed to access the PAC responder. User names are resolved to UIDs at " @@ -2907,7 +3014,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2216 +#: sssd.conf.5.xml:2253 #, fuzzy #| msgid "" #| "Default: 0 (only the root user is allowed to access the InfoPipe " @@ -2920,12 +3027,12 @@ msgstr "" "contestador de l'InfoPipe)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2220 +#: sssd.conf.5.xml:2257 msgid "Default: 0 (only the root user is allowed to access the PAC responder)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2224 +#: sssd.conf.5.xml:2261 #, fuzzy #| msgid "" #| "Please note that although the UID 0 is used as the default it will be " @@ -2944,7 +3051,7 @@ msgstr "" "també cal afegir 0 a la llista dels UID permesos." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2231 +#: sssd.conf.5.xml:2268 msgid "" "Please note that although the UID 0 is used as the default it will be " "overwritten with this option. If you still want to allow the root user to " @@ -2953,26 +3060,26 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2240 +#: sssd.conf.5.xml:2277 msgid "pac_lifetime (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2243 +#: sssd.conf.5.xml:2280 msgid "" "Lifetime of the PAC entry in seconds. As long as the PAC is valid the PAC " "data can be used to determine the group memberships of a user." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2253 +#: sssd.conf.5.xml:2290 #, fuzzy #| msgid "ldap_schema (string)" msgid "pac_check (string)" msgstr "ldap_schema (cadena)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2256 +#: sssd.conf.5.xml:2293 msgid "" "Apply additional checks on the PAC of the Kerberos ticket which is available " "in Active Directory and FreeIPA domains, if configured. Please note that " @@ -2983,7 +3090,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2266 +#: sssd.conf.5.xml:2303 msgid "" "Please note that the checks listed below only apply to PACs issued by Active " "Directory or recent versions of FreeIPA. PACs issued e.g. by a plain MIT " @@ -2991,24 +3098,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2277 +#: sssd.conf.5.xml:2314 msgid "no_check" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2279 +#: sssd.conf.5.xml:2316 msgid "" "The PAC must not be present and even if it is present no additional checks " "will be done." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2285 +#: sssd.conf.5.xml:2322 msgid "pac_present" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2287 +#: sssd.conf.5.xml:2324 msgid "" "The PAC must be present in the service ticket which SSSD will request with " "the help of the user's TGT. If the PAC is not available the authentication " @@ -3016,24 +3123,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2295 +#: sssd.conf.5.xml:2332 msgid "check_upn" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2297 +#: sssd.conf.5.xml:2334 msgid "" "If the PAC is present check if the user principal name (UPN) information is " "consistent." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2303 +#: sssd.conf.5.xml:2340 msgid "check_upn_allow_missing" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2305 +#: sssd.conf.5.xml:2342 msgid "" "This option should be used together with 'check_upn' and handles the case " "where a UPN is set on the server-side but is not read by SSSD. The typical " @@ -3045,7 +3152,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2317 +#: sssd.conf.5.xml:2354 msgid "" "Currently this option is set by default to avoid regressions in such " "environments. A log message will be added to the system log and SSSD's debug " @@ -3056,41 +3163,41 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2331 +#: sssd.conf.5.xml:2368 msgid "upn_dns_info_present" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2333 +#: sssd.conf.5.xml:2370 msgid "The PAC must contain the UPN-DNS-INFO buffer, implies 'check_upn'." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2338 +#: sssd.conf.5.xml:2375 msgid "check_upn_dns_info_ex" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2340 +#: sssd.conf.5.xml:2377 msgid "" "If the PAC is present and the extension to the UPN-DNS-INFO buffer is " "available check if the information in the extension is consistent." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2347 +#: sssd.conf.5.xml:2384 msgid "upn_dns_info_ex_present" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2349 +#: sssd.conf.5.xml:2386 msgid "" "The PAC must contain the extension of the UPN-DNS-INFO buffer, implies " "'check_upn_dns_info_ex', 'upn_dns_info_present' and 'check_upn'." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2273 +#: sssd.conf.5.xml:2310 #, fuzzy #| msgid "" #| "The following expansions are supported: <placeholder " @@ -3103,19 +3210,19 @@ msgstr "" "id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2359 +#: sssd.conf.5.xml:2396 msgid "" "Default: no_check (AD and IPA provider 'check_upn, check_upn_allow_missing, " "check_upn_dns_info_ex')" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:2368 +#: sssd.conf.5.xml:2405 msgid "Session recording configuration options" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2370 +#: sssd.conf.5.xml:2407 msgid "" "Session recording works in conjunction with <citerefentry> " "<refentrytitle>tlog-rec-session</refentrytitle> <manvolnum>8</manvolnum> </" @@ -3125,66 +3232,78 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2383 -msgid "These options can be used to configure session recording." +#: sssd.conf.5.xml:2420 +msgid "" +"These options can be used to configure session recording and should be " +"specified under the <quote>[session_recording]</quote> section." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:2425 +msgid "" +"Note: Unlike other sections, the <quote>[session_recording]</quote> section " +"ignores <replaceable>debug*</replaceable> options and suitable " +"<replaceable>debug*</replaceable> options must be set in <quote>[pam]</" +"quote>, <quote>[nss]</quote> and <quote>[domain/<replaceable>NAME</" +"replaceable>]</quote> sections." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2387 sssd-session-recording.5.xml:64 +#: sssd.conf.5.xml:2433 sssd-session-recording.5.xml:64 msgid "scope (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2394 sssd-session-recording.5.xml:71 +#: sssd.conf.5.xml:2440 sssd-session-recording.5.xml:71 msgid "\"none\"" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2397 sssd-session-recording.5.xml:74 +#: sssd.conf.5.xml:2443 sssd-session-recording.5.xml:74 msgid "No users are recorded." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2402 sssd-session-recording.5.xml:79 +#: sssd.conf.5.xml:2448 sssd-session-recording.5.xml:79 msgid "\"some\"" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2405 sssd-session-recording.5.xml:82 +#: sssd.conf.5.xml:2451 sssd-session-recording.5.xml:82 msgid "" "Users/groups specified by <replaceable>users</replaceable> and " "<replaceable>groups</replaceable> options are recorded." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2414 sssd-session-recording.5.xml:91 +#: sssd.conf.5.xml:2460 sssd-session-recording.5.xml:91 msgid "\"all\"" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2417 sssd-session-recording.5.xml:94 +#: sssd.conf.5.xml:2463 sssd-session-recording.5.xml:94 msgid "All users are recorded." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2390 sssd-session-recording.5.xml:67 +#: sssd.conf.5.xml:2436 sssd-session-recording.5.xml:67 msgid "" "One of the following strings specifying the scope of session recording: " "<placeholder type=\"variablelist\" id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2424 sssd-session-recording.5.xml:101 +#: sssd.conf.5.xml:2470 sssd-session-recording.5.xml:101 msgid "Default: \"none\"" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2429 sssd-session-recording.5.xml:106 +#: sssd.conf.5.xml:2475 sssd-session-recording.5.xml:106 msgid "users (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2432 sssd-session-recording.5.xml:109 +#: sssd.conf.5.xml:2478 sssd-session-recording.5.xml:109 msgid "" "A comma-separated list of users which should have session recording enabled. " "Matches user names as returned by NSS. I.e. after the possible space " @@ -3192,17 +3311,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2438 sssd-session-recording.5.xml:115 +#: sssd.conf.5.xml:2484 sssd-session-recording.5.xml:115 msgid "Default: Empty. Matches no users." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2443 sssd-session-recording.5.xml:120 +#: sssd.conf.5.xml:2489 sssd-session-recording.5.xml:120 msgid "groups (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2446 sssd-session-recording.5.xml:123 +#: sssd.conf.5.xml:2492 sssd-session-recording.5.xml:123 msgid "" "A comma-separated list of groups, members of which should have session " "recording enabled. Matches group names as returned by NSS. I.e. after the " @@ -3210,7 +3329,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2452 sssd.conf.5.xml:2484 sssd-session-recording.5.xml:129 +#: sssd.conf.5.xml:2498 sssd.conf.5.xml:2530 sssd-session-recording.5.xml:129 #: sssd-session-recording.5.xml:161 msgid "" "NOTE: using this option (having it set to anything) has a considerable " @@ -3219,65 +3338,66 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2459 sssd-session-recording.5.xml:136 +#: sssd.conf.5.xml:2505 sssd-session-recording.5.xml:136 msgid "Default: Empty. Matches no groups." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2464 sssd-session-recording.5.xml:141 +#: sssd.conf.5.xml:2510 sssd-session-recording.5.xml:141 #, fuzzy #| msgid "simple_deny_users (string)" msgid "exclude_users (string)" msgstr "simple_deny_users (cadena)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2467 sssd-session-recording.5.xml:144 +#: sssd.conf.5.xml:2513 sssd-session-recording.5.xml:144 msgid "" "A comma-separated list of users to be excluded from recording, only " "applicable with 'scope=all'." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2471 sssd-session-recording.5.xml:148 +#: sssd.conf.5.xml:2517 sssd-session-recording.5.xml:148 #, fuzzy #| msgid "Default: empty, i.e. ldap_uri is used." msgid "Default: Empty. No users excluded." msgstr "Per defecte: buit, és a dir, s'utilitza ldap_uri." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2476 sssd-session-recording.5.xml:153 +#: sssd.conf.5.xml:2522 sssd-session-recording.5.xml:153 #, fuzzy #| msgid "simple_deny_groups (string)" msgid "exclude_groups (string)" msgstr "simple_deny_groups (cadena)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2479 sssd-session-recording.5.xml:156 +#: sssd.conf.5.xml:2525 sssd-session-recording.5.xml:156 msgid "" "A comma-separated list of groups, members of which should be excluded from " "recording. Only applicable with 'scope=all'." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2491 sssd-session-recording.5.xml:168 +#: sssd.conf.5.xml:2537 sssd-session-recording.5.xml:168 #, fuzzy #| msgid "Default: empty, i.e. ldap_uri is used." msgid "Default: Empty. No groups excluded." msgstr "Per defecte: buit, és a dir, s'utilitza ldap_uri." #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:2501 +#: sssd.conf.5.xml:2547 msgid "DOMAIN SECTIONS" msgstr "SECCIONS DE DOMINI" -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry><para> -#: sssd.conf.5.xml:2508 sssd.conf.5.xml:3964 sssd.conf.5.xml:3965 -#: sssd.conf.5.xml:3968 -msgid "enabled" -msgstr "" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2554 +#, fuzzy +#| msgid "ad_enable_gc (boolean)" +msgid "enabled (boolean)" +msgstr "ad_enable_gc (booleà)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2511 +#: sssd.conf.5.xml:2557 msgid "" "Explicitly enable or disable the domain. If <quote>true</quote>, the domain " "is always <quote>enabled</quote>. If <quote>false</quote>, the domain is " @@ -3287,12 +3407,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2523 +#: sssd.conf.5.xml:2569 msgid "domain_type (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2526 +#: sssd.conf.5.xml:2572 msgid "" "Specifies whether the domain is meant to be used by POSIX-aware clients such " "as the Name Service Switch or by applications that do not need POSIX data to " @@ -3301,14 +3421,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2534 +#: sssd.conf.5.xml:2580 msgid "" "Allowed values for this option are <quote>posix</quote> and " "<quote>application</quote>." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2538 +#: sssd.conf.5.xml:2584 msgid "" "POSIX domains are reachable by all services. Application domains are only " "reachable from the InfoPipe responder (see <citerefentry> " @@ -3317,31 +3437,31 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2546 +#: sssd.conf.5.xml:2592 msgid "" "NOTE: The application domains are currently well tested with " "<quote>id_provider=ldap</quote> only." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2550 +#: sssd.conf.5.xml:2596 msgid "" "For an easy way to configure a non-POSIX domains, please see the " "<quote>Application domains</quote> section." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2554 +#: sssd.conf.5.xml:2600 msgid "Default: posix" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2560 +#: sssd.conf.5.xml:2606 msgid "min_id,max_id (integer)" msgstr "min_id, max_id (enter)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2563 +#: sssd.conf.5.xml:2609 msgid "" "UID and GID limits for the domain. If a domain contains an entry that is " "outside these limits, it is ignored." @@ -3350,7 +3470,7 @@ msgstr "" "fora d'aquests límits, s'ignora." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2568 +#: sssd.conf.5.xml:2614 msgid "" "For users, this affects the primary GID limit. The user will not be returned " "to NSS if either the UID or the primary GID is outside the range. For non-" @@ -3363,24 +3483,26 @@ msgstr "" "com s'esperava." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2575 +#: sssd.conf.5.xml:2621 msgid "" "These ID limits affect even saving entries to cache, not only returning them " "by name or ID." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2579 +#: sssd.conf.5.xml:2625 msgid "Default: 1 for min_id, 0 (no limit) for max_id" msgstr "Per defecte: 1 per a min_id, 0 (sense límit) per a max_id" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2585 -msgid "enumerate (bool)" +#: sssd.conf.5.xml:2631 +#, fuzzy +#| msgid "enumerate (bool)" +msgid "enumerate (boolean)" msgstr "enumerate (booleà)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2588 +#: sssd.conf.5.xml:2634 msgid "" "Determines if a domain can be enumerated, that is, whether the domain can " "list all the users and group it contains. Note that it is not required to " @@ -3389,36 +3511,36 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2596 +#: sssd.conf.5.xml:2642 msgid "TRUE = Users and groups are enumerated" msgstr "TRUE = Els usuaris i grups s'enumeren" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2599 +#: sssd.conf.5.xml:2645 msgid "FALSE = No enumerations for this domain" msgstr "FALSE = Cap enumeració per a aquest domini" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2602 sssd.conf.5.xml:2867 sssd.conf.5.xml:3044 +#: sssd.conf.5.xml:2648 sssd.conf.5.xml:2992 sssd.conf.5.xml:3174 msgid "Default: FALSE" msgstr "Per defecte: FALSE" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2605 +#: sssd.conf.5.xml:2651 msgid "" "Enumerating a domain requires SSSD to download and store ALL user and group " "entries from the remote server." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2610 +#: sssd.conf.5.xml:2656 msgid "" "Feature is only supported for domains with id_provider = ldap or id_provider " "= proxy." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2614 +#: sssd.conf.5.xml:2660 msgid "" "Note: Enabling enumeration has a severe performance impact on SSSD while " "enumeration is running. It may take up to several minutes after SSSD startup " @@ -3432,7 +3554,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2629 +#: sssd.conf.5.xml:2675 msgid "" "While the first enumeration is running, requests for the complete user or " "group lists may return no results until it completes." @@ -3442,7 +3564,7 @@ msgstr "" "finalitzi." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2634 +#: sssd.conf.5.xml:2680 msgid "" "Further, enabling enumeration may increase the time necessary to detect " "network disconnection, as longer timeouts are required to ensure that " @@ -3456,14 +3578,14 @@ msgstr "" "ús." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2642 +#: sssd.conf.5.xml:2688 msgid "" "For the reasons cited above, enabling enumeration is not recommended, " "especially in large environments." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2647 +#: sssd.conf.5.xml:2693 msgid "" "Note: the proxy provider is tested with open source modules like " "'libnss_files' and 'libnss_ldap'. 3rd party modules must follow the " @@ -3471,12 +3593,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2656 +#: sssd.conf.5.xml:2702 msgid "entry_cache_timeout (integer)" msgstr "entry_cache_timeout (enter)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2659 +#: sssd.conf.5.xml:2705 msgid "" "How many seconds should nss_sss consider entries valid before asking the " "backend again" @@ -3485,7 +3607,7 @@ msgstr "" "demanar al rerefons una altra vegada" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2663 +#: sssd.conf.5.xml:2709 msgid "" "The cache expiration timestamps are stored as attributes of individual " "objects in the cache. Therefore, changing the cache timeout only has effect " @@ -3496,139 +3618,254 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2676 +#: sssd.conf.5.xml:2722 msgid "Default: 5400" msgstr "Per defecte: 5400" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2682 +#: sssd.conf.5.xml:2728 msgid "entry_cache_user_timeout (integer)" msgstr "entry_cache_user_timeout (enter)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2685 +#: sssd.conf.5.xml:2731 msgid "" "How many seconds should nss_sss consider user entries valid before asking " "the backend again" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2689 sssd.conf.5.xml:2702 sssd.conf.5.xml:2715 -#: sssd.conf.5.xml:2728 sssd.conf.5.xml:2742 sssd.conf.5.xml:2755 -#: sssd.conf.5.xml:2769 sssd.conf.5.xml:2783 sssd.conf.5.xml:2796 +#: sssd.conf.5.xml:2735 sssd.conf.5.xml:2748 sssd.conf.5.xml:2761 +#: sssd.conf.5.xml:2774 sssd.conf.5.xml:2788 sssd.conf.5.xml:2801 +#: sssd.conf.5.xml:2815 sssd.conf.5.xml:2829 msgid "Default: entry_cache_timeout" msgstr "Per defecte: entry_cache_timeout" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2695 +#: sssd.conf.5.xml:2741 msgid "entry_cache_group_timeout (integer)" msgstr "entry_cache_group_timeout (enter)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2698 +#: sssd.conf.5.xml:2744 msgid "" "How many seconds should nss_sss consider group entries valid before asking " "the backend again" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2708 +#: sssd.conf.5.xml:2754 msgid "entry_cache_netgroup_timeout (integer)" msgstr "entry_cache_netgroup_timeout (enter)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2711 +#: sssd.conf.5.xml:2757 msgid "" "How many seconds should nss_sss consider netgroup entries valid before " "asking the backend again" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2721 +#: sssd.conf.5.xml:2767 msgid "entry_cache_service_timeout (integer)" msgstr "entry_cache_service_timeout (enter)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2724 +#: sssd.conf.5.xml:2770 +msgid "" +"How many seconds should nss_sss consider service entries valid before asking " +"the backend again" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2780 +msgid "entry_cache_resolver_timeout (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2783 +msgid "" +"How many seconds should nss_sss consider hosts and networks entries valid " +"before asking the backend again" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2794 +msgid "entry_cache_sudo_timeout (integer)" +msgstr "entry_cache_sudo_timeout (enter)" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2797 +msgid "" +"How many seconds should sudo consider rules valid before asking the backend " +"again" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2807 +msgid "entry_cache_autofs_timeout (integer)" +msgstr "entry_cache_autofs_timeout (enter)" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2810 +msgid "" +"How many seconds should the autofs service consider automounter maps valid " +"before asking the backend again" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2821 +msgid "entry_cache_ssh_host_timeout (integer)" +msgstr "entry_cache_ssh_host_timeout (enter)" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2824 +msgid "" +"How many seconds to keep a host ssh key after refresh. IE how long to cache " +"the host key for." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2835 +msgid "offline_timeout (integer)" +msgstr "offline_timeout (enter)" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2838 +msgid "" +"When SSSD switches to offline mode the amount of time before it tries to go " +"back online will increase based upon the time spent disconnected. By " +"default SSSD uses incremental behaviour to calculate delay in between " +"retries. So, the wait time for a given retry will be longer than the wait " +"time for the previous ones. After each unsuccessful attempt to go online, " +"the new interval is recalculated by the following:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2849 sssd.conf.5.xml:2907 +msgid "" +"new_delay = Minimum(old_delay * 2, offline_timeout_max) + " +"random[0...offline_timeout_random_offset]" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2852 +msgid "" +"The offline_timeout default value is 60. The offline_timeout_max default " +"value is 3600. The offline_timeout_random_offset default value is 30. The " +"end result is the number of seconds before next retry." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2858 +msgid "" +"Note that the maximum length of each interval is defined by " +"offline_timeout_max (apart from the random part)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2868 +#, fuzzy +#| msgid "offline_timeout (integer)" +msgid "offline_timeout_max (integer)" +msgstr "offline_timeout (enter)" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2871 msgid "" -"How many seconds should nss_sss consider service entries valid before asking " -"the backend again" +"Controls by how much the time between attempts to go online can be " +"incremented following unsuccessful attempts to go online." msgstr "" -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2734 -msgid "entry_cache_resolver_timeout (integer)" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2876 +msgid "A value of 0 disables the incrementing behaviour." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2737 +#: sssd.conf.5.xml:2879 msgid "" -"How many seconds should nss_sss consider hosts and networks entries valid " -"before asking the backend again" +"The value of this parameter should be set in correlation to offline_timeout " +"parameter value." msgstr "" -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2748 -msgid "entry_cache_sudo_timeout (integer)" -msgstr "entry_cache_sudo_timeout (enter)" - #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2751 +#: sssd.conf.5.xml:2883 msgid "" -"How many seconds should sudo consider rules valid before asking the backend " -"again" +"With offline_timeout set to 60 (default value) there is no point in setting " +"offline_timeout_max to less than 120 as it will saturate instantly. General " +"rule here should be to set offline_timeout_max to at least 4 times " +"offline_timeout." msgstr "" -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2761 -msgid "entry_cache_autofs_timeout (integer)" -msgstr "entry_cache_autofs_timeout (enter)" - #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2764 +#: sssd.conf.5.xml:2889 msgid "" -"How many seconds should the autofs service consider automounter maps valid " -"before asking the backend again" +"Although a value between 0 and offline_timeout may be specified, it has the " +"effect of overriding the offline_timeout value so is of little use." msgstr "" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2894 +#, fuzzy +#| msgid "Default: 300" +msgid "Default: 3600" +msgstr "Per defecte: 300" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2775 -msgid "entry_cache_ssh_host_timeout (integer)" -msgstr "entry_cache_ssh_host_timeout (enter)" +#: sssd.conf.5.xml:2900 +#, fuzzy +#| msgid "offline_timeout + random_offset" +msgid "offline_timeout_random_offset (integer)" +msgstr "offline_timeout + random_offset" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2778 +#: sssd.conf.5.xml:2903 msgid "" -"How many seconds to keep a host ssh key after refresh. IE how long to cache " -"the host key for." +"When SSSD is in offline mode it keeps probing backend servers in specified " +"time intervals:" msgstr "" -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2789 -msgid "entry_cache_computer_timeout (integer)" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2910 +msgid "" +"This parameter controls the value of the random offset used for the above " +"equation. Final random_offset value will be random number in range:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2792 -msgid "" -"How many seconds to keep the local computer entry before asking the backend " -"again" +#: sssd.conf.5.xml:2915 +#, fuzzy +#| msgid "offline_timeout + random_offset" +msgid "[0 - offline_timeout_random_offset]" +msgstr "offline_timeout + random_offset" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2918 +msgid "A value of 0 disables the random offset addition." msgstr "" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2921 +#, fuzzy +#| msgid "Default: 300" +msgid "Default: 30" +msgstr "Per defecte: 300" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2802 +#: sssd.conf.5.xml:2927 msgid "refresh_expired_interval (integer)" msgstr "refresh_expired_interval (enter)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2805 +#: sssd.conf.5.xml:2930 msgid "" "Specifies how many seconds SSSD has to wait before triggering a background " "refresh task which will refresh all expired or nearly expired records." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2810 +#: sssd.conf.5.xml:2935 msgid "" "The background refresh will process users, groups and netgroups in the " "cache. For users who have performed the initgroups (get group membership for " @@ -3637,17 +3874,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2818 +#: sssd.conf.5.xml:2943 msgid "This option is automatically inherited for all trusted domains." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2822 +#: sssd.conf.5.xml:2947 msgid "You can consider setting this value to 3/4 * entry_cache_timeout." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2826 +#: sssd.conf.5.xml:2951 msgid "" "Cache entry will be refreshed by background task when 2/3 of cache timeout " "has already passed. If there are existing cached entries, the background " @@ -3659,18 +3896,20 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2839 sssd-ldap.5.xml:406 sssd-ldap.5.xml:1834 -#: sssd-ipa.5.xml:255 +#: sssd.conf.5.xml:2964 sssd-ldap.5.xml:406 sssd-ldap.5.xml:1834 +#: sssd-ipa.5.xml:250 msgid "Default: 0 (disabled)" msgstr "Per defecte: 0 (inhabilitat)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2845 -msgid "cache_credentials (bool)" +#: sssd.conf.5.xml:2970 +#, fuzzy +#| msgid "cache_credentials (bool)" +msgid "cache_credentials (boolean)" msgstr "cache_credentials (booleà)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2848 +#: sssd.conf.5.xml:2973 msgid "" "Determines if user credentials are also cached in the local LDB cache. The " "cached credentials refer to passwords, which includes the first (long term) " @@ -3681,7 +3920,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2859 +#: sssd.conf.5.xml:2984 msgid "" "Take a note that while credentials are stored as a salted SHA512 hash, this " "still potentially poses some security risk in case an attacker manages to " @@ -3690,12 +3929,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2873 +#: sssd.conf.5.xml:2998 msgid "cache_credentials_minimal_first_factor_length (int)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2876 +#: sssd.conf.5.xml:3001 msgid "" "If 2-Factor-Authentication (2FA) is used and credentials should be saved " "this value determines the minimal length the first authentication factor " @@ -3703,19 +3942,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2883 +#: sssd.conf.5.xml:3008 msgid "" "This should avoid that the short PINs of a PIN based 2FA scheme are saved in " "the cache which would make them easy targets for brute-force attacks." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2894 +#: sssd.conf.5.xml:3019 msgid "account_cache_expiration (integer)" msgstr "account_cache_expiration (enter)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2897 +#: sssd.conf.5.xml:3022 msgid "" "Number of days entries are left in cache after last successful login before " "being removed during a cleanup of the cache. 0 means keep forever. The " @@ -3728,17 +3967,17 @@ msgstr "" "ha de ser superior o igual que offline_credentials_expiration." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2904 +#: sssd.conf.5.xml:3029 msgid "Default: 0 (unlimited)" msgstr "Per defecte: 0 (sense límit)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2909 +#: sssd.conf.5.xml:3034 msgid "pwd_expiration_warning (integer)" msgstr "pwd_expiration_warning (enter)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2920 +#: sssd.conf.5.xml:3045 msgid "" "Please note that the backend server has to provide information about the " "expiration time of the password. If this information is missing, sssd " @@ -3747,28 +3986,28 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2927 +#: sssd.conf.5.xml:3052 msgid "Default: 7 (Kerberos), 0 (LDAP)" msgstr "Per defecte: 7 (Kerberos), 0 (LDAP)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2933 +#: sssd.conf.5.xml:3058 msgid "id_provider (string)" msgstr "id_provider (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2936 +#: sssd.conf.5.xml:3061 msgid "" "The identification provider used for the domain. Supported ID providers are:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2940 +#: sssd.conf.5.xml:3065 msgid "<quote>proxy</quote>: Support a legacy NSS provider." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2943 +#: sssd.conf.5.xml:3068 msgid "" "<quote>ldap</quote>: LDAP provider. See <citerefentry> <refentrytitle>sssd-" "ldap</refentrytitle> <manvolnum>5</manvolnum> </citerefentry> for more " @@ -3776,8 +4015,8 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2951 sssd.conf.5.xml:3070 sssd.conf.5.xml:3129 -#: sssd.conf.5.xml:3192 +#: sssd.conf.5.xml:3076 sssd.conf.5.xml:3200 sssd.conf.5.xml:3259 +#: sssd.conf.5.xml:3322 #, fuzzy #| msgid "" #| "<quote>ldap</quote> for native LDAP authentication. See <citerefentry> " @@ -3793,8 +4032,8 @@ msgstr "" "citerefentry> per a més informació sobre configuració d'LDAP." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2960 sssd.conf.5.xml:3079 sssd.conf.5.xml:3138 -#: sssd.conf.5.xml:3201 +#: sssd.conf.5.xml:3085 sssd.conf.5.xml:3209 sssd.conf.5.xml:3268 +#: sssd.conf.5.xml:3331 msgid "" "<quote>ad</quote>: Active Directory provider. See <citerefentry> " "<refentrytitle>sssd-ad</refentrytitle> <manvolnum>5</manvolnum> </" @@ -3802,7 +4041,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2968 +#: sssd.conf.5.xml:3093 #, fuzzy #| msgid "" #| "<quote>ldap</quote> for native LDAP authentication. See <citerefentry> " @@ -3817,20 +4056,29 @@ msgstr "" "<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum></" "citerefentry> per a més informació sobre configuració d'LDAP." +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3101 +msgid "" +"Default: Not set (This is a mandatory setting that must be explicitly " +"defined for each configured domain)." +msgstr "" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2979 -msgid "use_fully_qualified_names (bool)" +#: sssd.conf.5.xml:3109 +#, fuzzy +#| msgid "use_fully_qualified_names (bool)" +msgid "use_fully_qualified_names (boolean)" msgstr "use_fully_qualified_names (booleà)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2982 +#: sssd.conf.5.xml:3112 msgid "" "Use the full name and domain (as formatted by the domain's full_name_format) " "as the user's login name reported to NSS." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2987 +#: sssd.conf.5.xml:3117 #, fuzzy #| msgid "" #| "If set to TRUE, all requests to this domain must use fully qualified " @@ -3849,7 +4097,7 @@ msgstr "" "l'usuari mentre que <command>getent passwd test@LOCAL</command> sí." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2995 +#: sssd.conf.5.xml:3125 msgid "" "NOTE: This option has no effect on netgroup lookups due to their tendency to " "include nested netgroups without qualified names. For netgroups, all domains " @@ -3857,24 +4105,26 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3002 +#: sssd.conf.5.xml:3132 msgid "" "Default: FALSE (TRUE for trusted domain/sub-domains or if " "default_domain_suffix is used)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3009 -msgid "ignore_group_members (bool)" +#: sssd.conf.5.xml:3139 +#, fuzzy +#| msgid "ignore_group_members (bool)" +msgid "ignore_group_members (boolean)" msgstr "ignore_group_members (booleà)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3012 +#: sssd.conf.5.xml:3142 msgid "Do not return group members for group lookups." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3015 +#: sssd.conf.5.xml:3145 msgid "" "If set to TRUE, the group membership attribute is not requested from the " "ldap server, and group members are not returned when processing group lookup " @@ -3886,7 +4136,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3033 +#: sssd.conf.5.xml:3163 msgid "" "Enabling this option can also make access provider checks for group " "membership significantly faster, especially for groups containing many " @@ -3894,7 +4144,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3039 sssd.conf.5.xml:3767 sssd-ldap.5.xml:401 +#: sssd.conf.5.xml:3169 sssd.conf.5.xml:3951 sssd-ldap.5.xml:401 #: sssd-ldap.5.xml:454 sssd-ldap.5.xml:529 sssd-ldap.5.xml:576 #: sssd-ldap.5.xml:599 sssd-ldap.5.xml:638 sssd-ldap.5.xml:657 #: sssd-ldap.5.xml:681 sssd-ldap.5.xml:1114 sssd-ldap.5.xml:1147 @@ -3904,12 +4154,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3049 +#: sssd.conf.5.xml:3179 msgid "auth_provider (string)" msgstr "auth_provider (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3052 +#: sssd.conf.5.xml:3182 msgid "" "The authentication provider used for the domain. Supported auth providers " "are:" @@ -3918,7 +4168,7 @@ msgstr "" "d'autenticació suportats són:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3056 sssd.conf.5.xml:3122 +#: sssd.conf.5.xml:3186 sssd.conf.5.xml:3252 msgid "" "<quote>ldap</quote> for native LDAP authentication. See <citerefentry> " "<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> </" @@ -3929,7 +4179,7 @@ msgstr "" "citerefentry> per a més informació sobre configuració d'LDAP." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3063 +#: sssd.conf.5.xml:3193 msgid "" "<quote>krb5</quote> for Kerberos authentication. See <citerefentry> " "<refentrytitle>sssd-krb5</refentrytitle> <manvolnum>5</manvolnum> </" @@ -3940,7 +4190,7 @@ msgstr "" "citerefentry> per a més informació sobre configurar Kerberos." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3087 +#: sssd.conf.5.xml:3217 #, fuzzy #| msgid "" #| "<quote>ldap</quote> for native LDAP authentication. See <citerefentry> " @@ -3956,7 +4206,7 @@ msgstr "" "citerefentry> per a més informació sobre configuració d'LDAP." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3095 +#: sssd.conf.5.xml:3225 msgid "" "<quote>proxy</quote> for relaying authentication to some other PAM target." msgstr "" @@ -3964,12 +4214,12 @@ msgstr "" "de PAM." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3098 +#: sssd.conf.5.xml:3228 msgid "<quote>none</quote> disables authentication explicitly." msgstr "<quote>none</quote> impossibilita l'autenticació explícitament." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3101 +#: sssd.conf.5.xml:3231 msgid "" "Default: <quote>id_provider</quote> is used if it is set and can handle " "authentication requests." @@ -3978,12 +4228,12 @@ msgstr "" "gestionar les sol·licituds d'autenticació." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3107 +#: sssd.conf.5.xml:3237 msgid "access_provider (string)" msgstr "access_provider (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3110 +#: sssd.conf.5.xml:3240 msgid "" "The access control provider used for the domain. There are two built-in " "access providers (in addition to any included in installed backends) " @@ -3994,19 +4244,19 @@ msgstr "" "instal·lats) Els proveïdors especials interns són:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3116 +#: sssd.conf.5.xml:3246 #, fuzzy #| msgid "<quote>deny</quote> always deny access." msgid "<quote>permit</quote> always allow access." msgstr "<quote>deny</quote> sempre denega l'accés." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3119 +#: sssd.conf.5.xml:3249 msgid "<quote>deny</quote> always deny access." msgstr "<quote>deny</quote> sempre denega l'accés." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3146 +#: sssd.conf.5.xml:3276 msgid "" "<quote>simple</quote> access control based on access or deny lists. See " "<citerefentry> <refentrytitle>sssd-simple</refentrytitle> <manvolnum>5</" @@ -4019,7 +4269,7 @@ msgstr "" "configuració del mòdul d'accés simple." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3153 +#: sssd.conf.5.xml:3283 msgid "" "<quote>krb5</quote>: .k5login based access control. See <citerefentry> " "<refentrytitle>sssd-krb5</refentrytitle> <manvolnum>5</manvolnum></" @@ -4027,22 +4277,22 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3160 +#: sssd.conf.5.xml:3290 msgid "<quote>proxy</quote> for relaying access control to another PAM module." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3163 +#: sssd.conf.5.xml:3293 msgid "Default: <quote>permit</quote>" msgstr "Per defecte: <quote>permit</quote>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3168 +#: sssd.conf.5.xml:3298 msgid "chpass_provider (string)" msgstr "chpass_provider (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3171 +#: sssd.conf.5.xml:3301 msgid "" "The provider which should handle change password operations for the domain. " "Supported change password providers are:" @@ -4051,7 +4301,7 @@ msgstr "" "al domini. Els proveïdors de canvi de contrasenya compatibles són:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3176 +#: sssd.conf.5.xml:3306 msgid "" "<quote>ldap</quote> to change a password stored in a LDAP server. See " "<citerefentry> <refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</" @@ -4059,7 +4309,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3184 +#: sssd.conf.5.xml:3314 msgid "" "<quote>krb5</quote> to change the Kerberos password. See <citerefentry> " "<refentrytitle>sssd-krb5</refentrytitle> <manvolnum>5</manvolnum> </" @@ -4070,7 +4320,7 @@ msgstr "" "citerefentry> per a més informació sobre configurar Kerberos." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3209 +#: sssd.conf.5.xml:3339 msgid "" "<quote>proxy</quote> for relaying password changes to some other PAM target." msgstr "" @@ -4078,12 +4328,12 @@ msgstr "" "objectiu PAM." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3213 +#: sssd.conf.5.xml:3343 msgid "<quote>none</quote> disallows password changes explicitly." msgstr "<quote>none</quote> rebutja els canvis de contrasenya explícitament." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3216 +#: sssd.conf.5.xml:3346 msgid "" "Default: <quote>auth_provider</quote> is used if it is set and can handle " "change password requests." @@ -4092,17 +4342,17 @@ msgstr "" "gestionar peticions de canvi de contrasenya." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3223 +#: sssd.conf.5.xml:3353 msgid "sudo_provider (string)" msgstr "sudo_provider (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3226 +#: sssd.conf.5.xml:3356 msgid "The SUDO provider used for the domain. Supported SUDO providers are:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3230 +#: sssd.conf.5.xml:3360 msgid "" "<quote>ldap</quote> for rules stored in LDAP. See <citerefentry> " "<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> </" @@ -4110,26 +4360,26 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3238 +#: sssd.conf.5.xml:3368 msgid "" "<quote>ipa</quote> the same as <quote>ldap</quote> but with IPA default " "settings." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3242 +#: sssd.conf.5.xml:3372 msgid "" "<quote>ad</quote> the same as <quote>ldap</quote> but with AD default " "settings." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3246 +#: sssd.conf.5.xml:3376 msgid "<quote>none</quote> disables SUDO explicitly." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3249 +#: sssd.conf.5.xml:3379 #, fuzzy #| msgid "" #| "Default: <quote>id_provider</quote> is used if it is set and can handle " @@ -4142,7 +4392,7 @@ msgstr "" "gestionar les sol·licituds d'autenticació." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3253 +#: sssd.conf.5.xml:3383 msgid "" "The detailed instructions for configuration of sudo_provider are in the " "manual page <citerefentry> <refentrytitle>sssd-sudo</refentrytitle> " @@ -4153,7 +4403,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3268 +#: sssd.conf.5.xml:3398 msgid "" "<emphasis>NOTE:</emphasis> Sudo rules are periodically downloaded in the " "background unless the sudo provider is explicitly disabled. Set " @@ -4162,12 +4412,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3278 +#: sssd.conf.5.xml:3408 msgid "selinux_provider (string)" msgstr "selinux_provider (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3281 +#: sssd.conf.5.xml:3411 msgid "" "The provider which should handle loading of selinux settings. Note that this " "provider will be called right after access provider ends. Supported selinux " @@ -4175,7 +4425,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3287 +#: sssd.conf.5.xml:3417 msgid "" "<quote>ipa</quote> to load selinux settings from an IPA server. See " "<citerefentry> <refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</" @@ -4183,31 +4433,38 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3295 +#: sssd.conf.5.xml:3425 msgid "<quote>none</quote> disallows fetching selinux settings explicitly." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3298 +#: sssd.conf.5.xml:3428 +#, fuzzy +#| msgid "" +#| "Default: <quote>id_provider</quote> is used if it is set and can handle " +#| "authentication requests." msgid "" -"Default: <quote>id_provider</quote> is used if it is set and can handle " -"selinux loading requests." +"Default: the value of <quote>id_provider</quote> is used if it is set and " +"can handle selinux loading requests. Otherwise the result is the same as if " +"the selinux_provider is set to none." msgstr "" +"Per defecte: <quote>id_provider</quote> s'utilitza si s'ha establert i pot " +"gestionar les sol·licituds d'autenticació." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3304 +#: sssd.conf.5.xml:3435 msgid "subdomains_provider (string)" msgstr "subdomains_provider (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3307 +#: sssd.conf.5.xml:3438 msgid "" "The provider which should handle fetching of subdomains. This value should " "be always the same as id_provider. Supported subdomain providers are:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3313 +#: sssd.conf.5.xml:3444 msgid "" "<quote>ipa</quote> to load a list of subdomains from an IPA server. See " "<citerefentry> <refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</" @@ -4215,7 +4472,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3322 +#: sssd.conf.5.xml:3453 msgid "" "<quote>ad</quote> to load a list of subdomains from an Active Directory " "server. See <citerefentry> <refentrytitle>sssd-ad</refentrytitle> " @@ -4224,12 +4481,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3331 +#: sssd.conf.5.xml:3462 msgid "<quote>none</quote> disallows fetching subdomains explicitly." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3335 +#: sssd.conf.5.xml:3466 #, fuzzy #| msgid "" #| "Default: <quote>id_provider</quote> is used if it is set and can handle " @@ -4242,12 +4499,12 @@ msgstr "" "gestionar les sol·licituds d'autenticació." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3341 +#: sssd.conf.5.xml:3472 msgid "session_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3344 +#: sssd.conf.5.xml:3475 msgid "" "The provider which configures and manages user session related tasks. The " "only user session task currently provided is the integration with Fleet " @@ -4255,36 +4512,36 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3351 +#: sssd.conf.5.xml:3482 msgid "<quote>ipa</quote> to allow performing user session related tasks." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3355 +#: sssd.conf.5.xml:3486 msgid "" "<quote>none</quote> does not perform any kind of user session related tasks." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3359 +#: sssd.conf.5.xml:3490 #, fuzzy #| msgid "Default: <quote>permit</quote>" msgid "Default: <quote>none</quote>." msgstr "Per defecte: <quote>permit</quote>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3365 +#: sssd.conf.5.xml:3496 msgid "autofs_provider (string)" msgstr "autofs_provider (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3368 +#: sssd.conf.5.xml:3499 msgid "" "The autofs provider used for the domain. Supported autofs providers are:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3372 +#: sssd.conf.5.xml:3503 msgid "" "<quote>ldap</quote> to load maps stored in LDAP. See <citerefentry> " "<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> </" @@ -4292,7 +4549,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3379 +#: sssd.conf.5.xml:3510 msgid "" "<quote>ipa</quote> to load maps stored in an IPA server. See <citerefentry> " "<refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</manvolnum> </" @@ -4300,7 +4557,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3387 +#: sssd.conf.5.xml:3518 msgid "" "<quote>ad</quote> to load maps stored in an AD server. See <citerefentry> " "<refentrytitle>sssd-ad</refentrytitle> <manvolnum>5</manvolnum> </" @@ -4308,12 +4565,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3396 +#: sssd.conf.5.xml:3527 msgid "<quote>none</quote> disables autofs explicitly." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3399 +#: sssd.conf.5.xml:3530 #, fuzzy #| msgid "" #| "Default: <quote>id_provider</quote> is used if it is set and can handle " @@ -4326,19 +4583,19 @@ msgstr "" "gestionar les sol·licituds d'autenticació." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3406 +#: sssd.conf.5.xml:3537 msgid "hostid_provider (string)" msgstr "hostid_provider (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3409 +#: sssd.conf.5.xml:3540 msgid "" "The provider used for retrieving host identity information. Supported " "hostid providers are:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3413 +#: sssd.conf.5.xml:3544 msgid "" "<quote>ipa</quote> to load host identity stored in an IPA server. See " "<citerefentry> <refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</" @@ -4346,12 +4603,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3421 +#: sssd.conf.5.xml:3552 msgid "<quote>none</quote> disables hostid explicitly." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3424 +#: sssd.conf.5.xml:3555 #, fuzzy #| msgid "" #| "Default: <quote>id_provider</quote> is used if it is set and can handle " @@ -4364,26 +4621,26 @@ msgstr "" "gestionar les sol·licituds d'autenticació." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3431 +#: sssd.conf.5.xml:3562 msgid "resolver_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3434 +#: sssd.conf.5.xml:3565 msgid "" "The provider which should handle hosts and networks lookups. Supported " "resolver providers are:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3438 +#: sssd.conf.5.xml:3569 msgid "" "<quote>proxy</quote> to forward lookups to another NSS library. See " "<quote>proxy_resolver_lib_name</quote>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3442 +#: sssd.conf.5.xml:3573 msgid "" "<quote>ldap</quote> to fetch hosts and networks stored in LDAP. See " "<citerefentry> <refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</" @@ -4391,7 +4648,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3449 +#: sssd.conf.5.xml:3580 msgid "" "<quote>ad</quote> to fetch hosts and networks stored in AD. See " "<citerefentry> <refentrytitle>sssd-ad</refentrytitle> <manvolnum>5</" @@ -4400,12 +4657,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3457 +#: sssd.conf.5.xml:3588 msgid "<quote>none</quote> disallows fetching hosts and networks explicitly." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3460 +#: sssd.conf.5.xml:3591 #, fuzzy #| msgid "" #| "Default: <quote>id_provider</quote> is used if it is set and can handle " @@ -4418,7 +4675,7 @@ msgstr "" "gestionar les sol·licituds d'autenticació." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3470 +#: sssd.conf.5.xml:3601 msgid "" "Regular expression for this domain that describes how to parse the string " "containing user name and domain into these components. The \"domain\" can " @@ -4428,24 +4685,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3479 +#: sssd.conf.5.xml:3610 msgid "" "Default: <quote>^((?P<name>.+)@(?P<domain>[^@]*)|(?P<name>" "[^@]+))$</quote> which allows two different styles for user names:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:3484 sssd.conf.5.xml:3498 +#: sssd.conf.5.xml:3615 sssd.conf.5.xml:3629 msgid "username" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:3487 sssd.conf.5.xml:3501 +#: sssd.conf.5.xml:3618 sssd.conf.5.xml:3632 msgid "username@domain.name" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3492 +#: sssd.conf.5.xml:3623 msgid "" "Default for the AD and IPA provider: <quote>^(((?P<domain>[^\\\\]+)\\\\" "(?P<name>.+))|((?P<name>.+)@(?P<domain>[^@]+))|((?" @@ -4454,19 +4711,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:3504 +#: sssd.conf.5.xml:3635 msgid "domain\\username" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3507 +#: sssd.conf.5.xml:3638 msgid "" "While the first two correspond to the general default the third one is " "introduced to allow easy integration of users from Windows domains." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3512 +#: sssd.conf.5.xml:3643 msgid "" "The default re_expression uses the <quote>@</quote> character as a separator " "between the name and the domain. As a result of this setting the default " @@ -4476,17 +4733,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3564 +#: sssd.conf.5.xml:3695 msgid "Default: <quote>%1$s@%2$s</quote>." msgstr "Per defecte: <quote>%1$s@%2$s</quote>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3570 +#: sssd.conf.5.xml:3701 msgid "lookup_family_order (string)" msgstr "lookup_family_order (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3573 +#: sssd.conf.5.xml:3704 msgid "" "Provides the ability to select preferred address family to use when " "performing DNS lookups." @@ -4495,76 +4752,95 @@ msgstr "" "realitzar cerques de DNS." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3577 +#: sssd.conf.5.xml:3708 msgid "Supported values:" msgstr "Valors admesos:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3580 +#: sssd.conf.5.xml:3711 msgid "ipv4_first: Try looking up IPv4 address, if that fails, try IPv6" msgstr "ipv4_first: Intenta resoldre l'adreça IPv4, si falla, intenta IPv6" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3583 +#: sssd.conf.5.xml:3714 msgid "ipv4_only: Only attempt to resolve hostnames to IPv4 addresses." msgstr "ipv4_only: Intenta resoldre només noms màquina a adreces IPv4." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3586 +#: sssd.conf.5.xml:3717 msgid "ipv6_first: Try looking up IPv6 address, if that fails, try IPv4" msgstr "ipv6_first: Intenta resoldre l'adreça IPv6, si falla, intenta IPv4" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3589 +#: sssd.conf.5.xml:3720 msgid "ipv6_only: Only attempt to resolve hostnames to IPv6 addresses." msgstr "ipv6_only: Intenta resoldre només noms màquina a adreces IPv6." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3592 +#: sssd.conf.5.xml:3723 msgid "Default: ipv4_first" msgstr "Per defecte: ipv4_first" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3598 +#: sssd.conf.5.xml:3729 #, fuzzy #| msgid "dns_resolver_timeout (integer)" msgid "dns_resolver_server_timeout (integer)" msgstr "dns_resolver_timeout (enter)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3601 +#: sssd.conf.5.xml:3732 msgid "" -"Defines the amount of time (in milliseconds) SSSD would try to talk to DNS " -"server before trying next DNS server." +"Defines the timeout duration (in milliseconds) SSSD waits for a DNS server " +"to respond before moving to the next one." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3606 +#: sssd.conf.5.xml:3737 msgid "" "The AD provider will use this option for the CLDAP ping timeouts as well." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3610 sssd.conf.5.xml:3630 sssd.conf.5.xml:3651 -msgid "" -"Please see the section <quote>FAILOVER</quote> for more information about " -"the service resolution." +#: sssd.conf.5.xml:3741 sssd.conf.5.xml:3777 sssd.conf.5.xml:3814 +#, fuzzy +#| msgid "" +#| "Specifies the timeout (in seconds) after which the <citerefentry> " +#| "<refentrytitle>poll</refentrytitle> <manvolnum>2</manvolnum> </" +#| "citerefentry>/<citerefentry> <refentrytitle>select</refentrytitle> " +#| "<manvolnum>2</manvolnum> </citerefentry> following a <citerefentry> " +#| "<refentrytitle>connect</refentrytitle> <manvolnum>2</manvolnum> </" +#| "citerefentry> returns in case of no activity." +msgid "" +"Please see the section <quote>FAILOVER</quote> in <citerefentry> " +"<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> </" +"citerefentry>, <citerefentry> <refentrytitle>sssd-krb5</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry>, <citerefentry> <refentrytitle>sssd-" +"ipa</refentrytitle> <manvolnum>5</manvolnum> </citerefentry> or " +"<citerefentry> <refentrytitle>sssd-ad</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry> for more information about the service resolution." msgstr "" +"Especifica el temps d'espera (en segons) després que el " +"<citerefentry><refentrytitle>sondeig</refentrytitle> <manvolnum>2</" +"manvolnum></citerefentry>/<citerefentry><refentrytitle>selecció</" +"refentrytitle> <manvolnum>2</manvolnum></citerefentry> seguit d'una " +"<citerefentry><refentrytitle>connexió</refentrytitle> <manvolnum>2</" +"manvolnum></citerefentry> retorna en cas de cap activitat." #. type: Content of: <refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3615 sssd-ldap.5.xml:700 include/failover.xml:84 +#: sssd.conf.5.xml:3762 sssd-ldap.5.xml:700 include/failover.xml:84 msgid "Default: 1000" msgstr "Per defecte: 1000" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3621 +#: sssd.conf.5.xml:3768 #, fuzzy #| msgid "dns_resolver_timeout (integer)" msgid "dns_resolver_op_timeout (integer)" msgstr "dns_resolver_timeout (enter)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3624 +#: sssd.conf.5.xml:3771 msgid "" "Defines the amount of time (in seconds) to wait to resolve single DNS query " "(e.g. resolution of a hostname or an SRV record) before trying the next " @@ -4572,17 +4848,17 @@ msgid "" msgstr "" #. type: Content of: <refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3635 include/failover.xml:100 +#: sssd.conf.5.xml:3798 include/failover.xml:100 msgid "Default: 3" msgstr "Per defecte: 3" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3641 +#: sssd.conf.5.xml:3804 msgid "dns_resolver_timeout (integer)" msgstr "dns_resolver_timeout (enter)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3644 +#: sssd.conf.5.xml:3807 msgid "" "Defines the amount of time (in seconds) to wait for a reply from the " "internal fail over service before assuming that the service is unreachable. " @@ -4591,14 +4867,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3662 +#: sssd.conf.5.xml:3841 #, fuzzy #| msgid "dns_resolver_timeout (integer)" -msgid "dns_resolver_use_search_list (bool)" +msgid "dns_resolver_use_search_list (boolean)" msgstr "dns_resolver_timeout (enter)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3665 +#: sssd.conf.5.xml:3844 msgid "" "Normally, the DNS resolver searches the domain list defined in the " "\"search\" directive from the resolv.conf file. This can lead to delays in " @@ -4606,7 +4882,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3671 +#: sssd.conf.5.xml:3850 msgid "" "If fully qualified domain names (or _srv_) are used in the SSSD " "configuration, setting this option to FALSE can prevent unnecessary DNS " @@ -4614,17 +4890,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3677 +#: sssd.conf.5.xml:3856 msgid "Default: TRUE" msgstr "Per defecte: TRUE" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3683 +#: sssd.conf.5.xml:3862 msgid "dns_discovery_domain (string)" msgstr "dns_discovery_domain (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3686 +#: sssd.conf.5.xml:3865 msgid "" "If service discovery is used in the back end, specifies the domain part of " "the service discovery DNS query." @@ -4633,19 +4909,19 @@ msgstr "" "del domini de la consulta DNS del servei de descobriment." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3690 +#: sssd.conf.5.xml:3869 msgid "Default: Use the domain part of machine's hostname" msgstr "Per defecte: Utilitza la part del domini del nom de màquina" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3696 +#: sssd.conf.5.xml:3875 #, fuzzy #| msgid "pam_id_timeout (integer)" msgid "failover_primary_timeout (integer)" msgstr "pam_id_timeout (enter)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3699 +#: sssd.conf.5.xml:3878 msgid "" "When no primary server is available, SSSD fails over to a backup server. " "This option defines the number of seconds SSSD waits before attempting to " @@ -4653,59 +4929,71 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3706 +#: sssd.conf.5.xml:3885 msgid "Note: The minimum value is 31." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3709 +#: sssd.conf.5.xml:3888 #, fuzzy #| msgid "Default: 3" msgid "Default: 31" msgstr "Per defecte: 3" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3715 +#: sssd.conf.5.xml:3894 msgid "override_gid (integer)" msgstr "override_gid (enter)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3718 -msgid "Override the primary GID value with the one specified." +#: sssd.conf.5.xml:3897 +msgid "" +"Override the primary GID value for all users in the domain with specified " +"value." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3901 +#, fuzzy +#| msgid "Default: not set (SSSD will use the value retrieved from LDAP)" +msgid "" +"Default: not set (Use the primary GID value retrieved from the identity " +"provider)" msgstr "" +"Per defecte: sense establir (SSSD utilitzarà el valor recuperat del LDAP)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3724 +#: sssd.conf.5.xml:3908 msgid "case_sensitive (string)" msgstr "case_sensitive (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3731 +#: sssd.conf.5.xml:3915 msgid "True" msgstr "True" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3734 +#: sssd.conf.5.xml:3918 msgid "Case sensitive. This value is invalid for AD provider." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3740 +#: sssd.conf.5.xml:3924 msgid "False" msgstr "False" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3742 +#: sssd.conf.5.xml:3926 msgid "Case insensitive." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3746 +#: sssd.conf.5.xml:3930 msgid "Preserving" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3749 +#: sssd.conf.5.xml:3933 msgid "" "Same as False (case insensitive), but does not lowercase names in the result " "of NSS operations. Note that name aliases (and in case of services also " @@ -4713,14 +5001,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3757 +#: sssd.conf.5.xml:3941 msgid "" "If you want to set this value for trusted domain with IPA provider, you need " "to set it on both the client and SSSD on the server." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3727 +#: sssd.conf.5.xml:3911 #, fuzzy #| msgid "" #| "The following expansions are supported: <placeholder " @@ -4733,17 +5021,47 @@ msgstr "" "id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3772 +#: sssd.conf.5.xml:3956 msgid "Default: True (False for AD provider)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3778 +#: sssd.conf.5.xml:3962 +#, fuzzy +#| msgid "ad_enable_dns_sites (boolean)" +msgid "avoid_by_id_lookups (boolean)" +msgstr "ad_enable_dns_sites (booleà)" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3965 +msgid "" +"If this option is set to 'true' SSSD will try to avoid sending lookups by ID " +"to the backend and will switch to a lookup by name if a cached object with a " +"matching ID can be found." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3971 +msgid "" +"This option can e.g. be used in cases where searches by ID are expensive on " +"the server side because of missing indexes or are not even possible, e.g. " +"due to non-reversible POSIX id-mapping." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3978 +#, fuzzy +#| msgid "Default: False (disabled)" +msgid "Default: False (True for IdP provider)" +msgstr "Per defecte: False (inhabilitat)" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:3984 msgid "subdomain_inherit (string)" msgstr "subdomain_inherit (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3781 +#: sssd.conf.5.xml:3987 msgid "" "Specifies a list of configuration parameters that should be inherited by a " "subdomain. Please note that only selected parameters can be inherited. " @@ -4751,109 +5069,109 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3787 +#: sssd.conf.5.xml:3993 #, fuzzy #| msgid "ldap_search_timeout (integer)" msgid "ldap_search_timeout" msgstr "ldap_search_timeout (enter)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3790 +#: sssd.conf.5.xml:3996 #, fuzzy #| msgid "ldap_network_timeout (integer)" msgid "ldap_network_timeout" msgstr "ldap_network_timeout (enter)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3793 +#: sssd.conf.5.xml:3999 #, fuzzy #| msgid "ldap_opt_timeout (integer)" msgid "ldap_opt_timeout" msgstr "ldap_opt_timeout (enter)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3796 +#: sssd.conf.5.xml:4002 #, fuzzy #| msgid "ldap_connection_expire_timeout (integer)" msgid "ldap_offline_timeout" msgstr "ldap_connection_expire_timeout (enter)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3799 +#: sssd.conf.5.xml:4005 msgid "ldap_purge_cache_timeout" msgstr "ldap_purge_cache_timeout" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3802 +#: sssd.conf.5.xml:4008 #, fuzzy #| msgid "ldap_purge_cache_timeout" msgid "ldap_purge_cache_offset" msgstr "ldap_purge_cache_timeout" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3805 +#: sssd.conf.5.xml:4011 msgid "" "ldap_krb5_keytab (the value of krb5_keytab will be used if ldap_krb5_keytab " "is not set explicitly)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3809 +#: sssd.conf.5.xml:4015 #, fuzzy #| msgid "ldap_krb5_ticket_lifetime (integer)" msgid "ldap_krb5_ticket_lifetime" msgstr "ldap_krb5_ticket_lifetime (enter)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3812 +#: sssd.conf.5.xml:4018 #, fuzzy #| msgid "ldap_connection_expire_timeout (integer)" msgid "ldap_connection_expire_timeout" msgstr "ldap_connection_expire_timeout (enter)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3815 +#: sssd.conf.5.xml:4021 #, fuzzy #| msgid "ldap_connection_expire_timeout (integer)" msgid "ldap_connection_expire_offset" msgstr "ldap_connection_expire_timeout (enter)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3818 +#: sssd.conf.5.xml:4024 #, fuzzy #| msgid "ldap_connection_expire_timeout (integer)" msgid "ldap_connection_idle_timeout" msgstr "ldap_connection_expire_timeout (enter)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3821 sssd-ldap.5.xml:446 +#: sssd.conf.5.xml:4027 sssd-ldap.5.xml:446 msgid "ldap_use_tokengroups" msgstr "ldap_use_tokengroups" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3824 +#: sssd.conf.5.xml:4030 msgid "ldap_user_principal" msgstr "ldap_user_principal" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3827 +#: sssd.conf.5.xml:4033 msgid "ignore_group_members" msgstr "ignore_group_members" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3830 +#: sssd.conf.5.xml:4036 msgid "auto_private_groups" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3833 +#: sssd.conf.5.xml:4039 #, fuzzy #| msgid "case_sensitive (string)" msgid "case_sensitive" msgstr "case_sensitive (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:3838 +#: sssd.conf.5.xml:4044 #, no-wrap msgid "" "subdomain_inherit = ldap_purge_cache_timeout\n" @@ -4863,27 +5181,27 @@ msgstr "" " " #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3845 +#: sssd.conf.5.xml:4051 msgid "Note: This option only works with the IPA and AD provider." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3852 +#: sssd.conf.5.xml:4058 msgid "subdomain_homedir (string)" msgstr "subdomain_homedir (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3863 +#: sssd.conf.5.xml:4069 msgid "%F" msgstr "%F" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3864 +#: sssd.conf.5.xml:4070 msgid "flat (NetBIOS) name of a subdomain." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3855 +#: sssd.conf.5.xml:4061 msgid "" "Use this homedir as default value for all subdomains within this domain in " "IPA AD trust. See <emphasis>override_homedir</emphasis> for info about " @@ -4893,55 +5211,55 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3869 +#: sssd.conf.5.xml:4075 msgid "" "The value can be overridden by <emphasis>override_homedir</emphasis> option." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3873 +#: sssd.conf.5.xml:4079 msgid "Default: <filename>/home/%d/%u</filename>" msgstr "Per defecte: <filename>/home/%d/%u</filename>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3878 +#: sssd.conf.5.xml:4084 msgid "realmd_tags (string)" msgstr "realmd_tags (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3881 +#: sssd.conf.5.xml:4087 msgid "" "Various tags stored by the realmd configuration service for this domain." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3887 +#: sssd.conf.5.xml:4093 msgid "cached_auth_timeout (int)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3890 +#: sssd.conf.5.xml:4096 msgid "" -"Specifies time in seconds since last successful online authentication for " -"which user will be authenticated using cached credentials while SSSD is in " -"the online mode. If the credentials are incorrect, SSSD falls back to online " -"authentication." +"Specifies the number of seconds since the last successful online " +"authentication during which SSSD will authenticate users via cached " +"credentials, even while online. If the cached authentication fails, SSSD " +"immediately falls back to online authentication." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3898 +#: sssd.conf.5.xml:4103 msgid "" "This option's value is inherited by all trusted domains. At the moment it is " "not possible to set a different value per trusted domain." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3903 +#: sssd.conf.5.xml:4108 msgid "Special value 0 implies that this feature is disabled." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3907 +#: sssd.conf.5.xml:4112 msgid "" "Please note that if <quote>cached_auth_timeout</quote> is longer than " "<quote>pam_id_timeout</quote> then the back end could be called to handle " @@ -4949,14 +5267,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3918 +#: sssd.conf.5.xml:4123 #, fuzzy #| msgid "ldap_pwd_policy (string)" msgid "local_auth_policy (string)" msgstr "ldap_pwd_policy (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3921 +#: sssd.conf.5.xml:4126 msgid "" "Local authentication methods policy. Some backends (i.e. LDAP, proxy " "provider) only support a password based authentication, while others can " @@ -4968,7 +5286,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3933 +#: sssd.conf.5.xml:4138 msgid "" "There are three possible values for this option: match, only, enable. " "<quote>match</quote> is used to match offline and online states for Kerberos " @@ -4980,7 +5298,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3946 +#: sssd.conf.5.xml:4151 msgid "" "The following table shows which authentication methods, if configured " "properly, are currently enabled or disabled for each backend, with the " @@ -4988,46 +5306,51 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> -#: sssd.conf.5.xml:3959 +#: sssd.conf.5.xml:4164 #, fuzzy #| msgid "ldap_pwd_policy (string)" msgid "local_auth_policy = match (default)" msgstr "ldap_pwd_policy (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> -#: sssd.conf.5.xml:3960 +#: sssd.conf.5.xml:4165 msgid "Passkey" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> -#: sssd.conf.5.xml:3961 +#: sssd.conf.5.xml:4166 #, fuzzy #| msgid "gdm-smartcard" msgid "Smartcard" msgstr "gdm-smartcard" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:3964 sssd-ldap.5.xml:228 +#: sssd.conf.5.xml:4169 sssd-ldap.5.xml:228 msgid "IPA" msgstr "IPA" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry><para> +#: sssd.conf.5.xml:4169 sssd.conf.5.xml:4170 sssd.conf.5.xml:4173 +msgid "enabled" +msgstr "" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:3967 sssd-ldap.5.xml:233 +#: sssd.conf.5.xml:4172 sssd-ldap.5.xml:233 msgid "AD" msgstr "AD" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry><para> -#: sssd.conf.5.xml:3967 sssd.conf.5.xml:3970 sssd.conf.5.xml:3971 +#: sssd.conf.5.xml:4172 sssd.conf.5.xml:4175 sssd.conf.5.xml:4176 msgid "disabled" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry> -#: sssd.conf.5.xml:3970 +#: sssd.conf.5.xml:4175 msgid "LDAP" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3975 +#: sssd.conf.5.xml:4180 msgid "" "Please note that if local Smartcard authentication is enabled and a " "Smartcard is present, Smartcard authentication will be preferred over the " @@ -5036,7 +5359,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:3987 +#: sssd.conf.5.xml:4192 #, no-wrap msgid "" "[domain/shadowutils]\n" @@ -5047,7 +5370,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3983 +#: sssd.conf.5.xml:4188 #, fuzzy #| msgid "" #| "The following example shows a minimal idmapd.conf which makes use of the " @@ -5061,31 +5384,31 @@ msgstr "" "sss. <placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3995 +#: sssd.conf.5.xml:4200 #, fuzzy #| msgid "Default: cn" msgid "Default: match" msgstr "Per defecte: cn" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4000 +#: sssd.conf.5.xml:4205 msgid "auto_private_groups (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4006 +#: sssd.conf.5.xml:4211 msgid "true" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4009 +#: sssd.conf.5.xml:4214 msgid "" "Create user's private group unconditionally from user's UID number. The GID " "number is ignored in this case." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4013 +#: sssd.conf.5.xml:4218 msgid "" "NOTE: Because the GID number and the user private group are inferred from " "the UID number, it is not supported to have multiple entries with the same " @@ -5094,24 +5417,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4022 +#: sssd.conf.5.xml:4227 msgid "false" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4025 +#: sssd.conf.5.xml:4230 msgid "" "Always use the user's primary GID number. The GID number must refer to a " "group object in the LDAP database." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4031 +#: sssd.conf.5.xml:4236 msgid "hybrid" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4034 +#: sssd.conf.5.xml:4239 msgid "" "A primary group is autogenerated for user entries whose UID and GID numbers " "have the same value and at the same time the GID number does not correspond " @@ -5121,14 +5444,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4047 +#: sssd.conf.5.xml:4252 msgid "" "If the UID and GID of a user are different, then the GID must correspond to " "a group entry, otherwise the GID is simply not resolvable." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4054 +#: sssd.conf.5.xml:4259 msgid "" "This feature is useful for environments that wish to stop maintaining a " "separate group objects for the user private groups, but also wish to retain " @@ -5136,14 +5459,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4003 +#: sssd.conf.5.xml:4208 msgid "" "This option takes any of three available values: <placeholder " "type=\"variablelist\" id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4066 +#: sssd.conf.5.xml:4271 msgid "" "For the LDAP based id providers (LDAP, IPA and AD) the default for the " "configured domain is typically False because the sources have the concept of " @@ -5153,14 +5476,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4075 +#: sssd.conf.5.xml:4280 msgid "" "For subdomains, the default value is False for subdomains that use assigned " "POSIX IDs and True for subdomains that use automatic ID-mapping." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:4083 +#: sssd.conf.5.xml:4288 #, no-wrap msgid "" "[domain/forest.domain/sub.domain]\n" @@ -5168,7 +5491,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:4089 +#: sssd.conf.5.xml:4294 #, no-wrap msgid "" "[domain/forest.domain]\n" @@ -5177,7 +5500,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4080 +#: sssd.conf.5.xml:4285 msgid "" "The value of auto_private_groups can either be set per subdomains in a " "subsection, for example: <placeholder type=\"programlisting\" id=\"0\"/> or " @@ -5186,7 +5509,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:2503 +#: sssd.conf.5.xml:2549 msgid "" "These configuration options can be present in a domain configuration " "section, that is, in a section called <quote>[domain/<replaceable>NAME</" @@ -5197,17 +5520,17 @@ msgstr "" "replaceable>]</quote> <placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4104 +#: sssd.conf.5.xml:4309 msgid "proxy_pam_target (string)" msgstr "proxy_pam_target (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4107 +#: sssd.conf.5.xml:4312 msgid "The proxy target PAM proxies to." msgstr "El servidor intermediari on reenvia PAM." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4110 +#: sssd.conf.5.xml:4315 #, fuzzy #| msgid "" #| "Default: not set by default, you have to take an existing pam " @@ -5221,12 +5544,12 @@ msgstr "" "de pam existent o crear-ne una de nova i afegir aquí el nom del servei." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4120 +#: sssd.conf.5.xml:4325 msgid "proxy_lib_name (string)" msgstr "proxy_lib_name (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4123 +#: sssd.conf.5.xml:4328 msgid "" "The name of the NSS library to use in proxy domains. The NSS functions " "searched for in the library are in the form of _nss_$(libName)_$(function), " @@ -5237,12 +5560,12 @@ msgstr "" "format _nss_$(libName)_$(function), per exemple _nss_files_getpwent." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4133 +#: sssd.conf.5.xml:4338 msgid "proxy_resolver_lib_name (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4136 +#: sssd.conf.5.xml:4341 msgid "" "The name of the NSS library to use for hosts and networks lookups in proxy " "domains. The NSS functions searched for in the library are in the form of " @@ -5250,12 +5573,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4147 +#: sssd.conf.5.xml:4352 msgid "proxy_fast_alias (boolean)" msgstr "proxy_fast_alias (booleà)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4150 +#: sssd.conf.5.xml:4355 msgid "" "When a user or group is looked up by name in the proxy provider, a second " "lookup by ID is performed to \"canonicalize\" the name in case the requested " @@ -5264,12 +5587,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4164 +#: sssd.conf.5.xml:4369 msgid "proxy_max_children (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4167 +#: sssd.conf.5.xml:4372 msgid "" "This option specifies the number of pre-forked proxy children. It is useful " "for high-load SSSD environments where sssd may run out of available child " @@ -5277,7 +5600,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4100 +#: sssd.conf.5.xml:4305 msgid "" "Options valid for proxy domains. <placeholder type=\"variablelist\" " "id=\"0\"/>" @@ -5286,12 +5609,12 @@ msgstr "" "type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:4183 +#: sssd.conf.5.xml:4388 msgid "Application domains" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:4185 +#: sssd.conf.5.xml:4390 msgid "" "SSSD, with its D-Bus interface (see <citerefentry> <refentrytitle>sssd-ifp</" "refentrytitle> <manvolnum>5</manvolnum> </citerefentry>) is appealing to " @@ -5308,7 +5631,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:4205 +#: sssd.conf.5.xml:4410 msgid "" "Please note that the application domain must still be explicitly enabled in " "the <quote>domains</quote> parameter so that the lookup order between the " @@ -5316,17 +5639,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><title> -#: sssd.conf.5.xml:4211 +#: sssd.conf.5.xml:4416 msgid "Application domain parameters" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4213 +#: sssd.conf.5.xml:4418 msgid "inherit_from (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4216 +#: sssd.conf.5.xml:4421 msgid "" "The SSSD POSIX-type domain the application domain inherits all settings " "from. The application domain can moreover add its own settings to the " @@ -5335,7 +5658,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:4230 +#: sssd.conf.5.xml:4435 msgid "" "The following example illustrates the use of an application domain. In this " "setup, the POSIX domain is connected to an LDAP server and is used by the OS " @@ -5345,7 +5668,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><programlisting> -#: sssd.conf.5.xml:4238 +#: sssd.conf.5.xml:4443 #, no-wrap msgid "" "[sssd]\n" @@ -5365,12 +5688,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:4258 +#: sssd.conf.5.xml:4463 msgid "TRUSTED DOMAIN SECTION" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4260 +#: sssd.conf.5.xml:4465 msgid "" "Some options used in the domain section can also be used in the trusted " "domain section, that is, in a section called <quote>[domain/" @@ -5381,69 +5704,81 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4267 +#: sssd.conf.5.xml:4472 msgid "ldap_search_base," msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4268 +#: sssd.conf.5.xml:4473 msgid "ldap_user_search_base," msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4269 +#: sssd.conf.5.xml:4474 msgid "ldap_group_search_base," msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4270 +#: sssd.conf.5.xml:4475 msgid "ldap_netgroup_search_base," msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4271 +#: sssd.conf.5.xml:4476 msgid "ldap_service_search_base," msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4272 +#: sssd.conf.5.xml:4477 msgid "ldap_sasl_mech," msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4273 +#: sssd.conf.5.xml:4478 msgid "ad_server," msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4274 +#: sssd.conf.5.xml:4479 msgid "ad_backup_server," msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4275 +#: sssd.conf.5.xml:4480 msgid "ad_site," msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:4276 sssd-ipa.5.xml:934 +#: sssd.conf.5.xml:4481 sssd-ipa.5.xml:929 msgid "use_fully_qualified_names" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4280 +#: sssd.conf.5.xml:4482 +#, fuzzy +#| msgid "ad_gpo_map_service (string)" +msgid "pam_gssapi_services" +msgstr "ad_gpo_map_service (cadena)" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:4483 +msgid "pam_gssapi_check_upn" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:4485 msgid "" "For more details about these options see their individual description in the " "manual page." msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:4286 +#: sssd.conf.5.xml:4491 msgid "CERTIFICATE MAPPING SECTION" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4288 +#: sssd.conf.5.xml:4493 msgid "" "To allow authentication with Smartcards and certificates SSSD must be able " "to map certificates to users. This can be done by adding the full " @@ -5456,7 +5791,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4302 +#: sssd.conf.5.xml:4507 msgid "" "To make the mapping more flexible mapping and matching rules were added to " "SSSD (see <citerefentry> <refentrytitle>sss-certmap</refentrytitle> " @@ -5464,7 +5799,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4311 +#: sssd.conf.5.xml:4516 msgid "" "A mapping and matching rule can be added to the SSSD configuration in a " "section on its own with a name like <quote>[certmap/" @@ -5473,55 +5808,50 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4318 +#: sssd.conf.5.xml:4523 msgid "matchrule (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4321 +#: sssd.conf.5.xml:4526 msgid "" "Only certificates from the Smartcard which matches this rule will be " "processed, all others are ignored." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4325 +#: sssd.conf.5.xml:4530 msgid "" "Default: KRB5:<EKU>clientAuth, i.e. only certificates which have the " "Extended Key Usage <quote>clientAuth</quote>" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4332 +#: sssd.conf.5.xml:4537 msgid "maprule (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4335 +#: sssd.conf.5.xml:4540 msgid "Defines how the user is found for a given certificate." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:4341 +#: sssd.conf.5.xml:4546 msgid "" "LDAP:(userCertificate;binary={cert!bin}) for LDAP based providers like " "<quote>ldap</quote>, <quote>AD</quote> or <quote>ipa</quote>." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:4347 +#: sssd.conf.5.xml:4552 msgid "" "If maprule is not set and provider is <quote>proxy</quote>, the RULE_NAME " "name is assumed to be the name of the matching user." msgstr "" -#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4357 -msgid "domains (string)" -msgstr "" - #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4360 +#: sssd.conf.5.xml:4565 msgid "" "Comma separated list of domain names the rule should be applied. By default " "a rule is only valid in the domain configured in sssd.conf. If the provider " @@ -5530,17 +5860,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4367 +#: sssd.conf.5.xml:4572 msgid "Default: the configured domain in sssd.conf" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4372 +#: sssd.conf.5.xml:4577 msgid "priority (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4375 +#: sssd.conf.5.xml:4580 msgid "" "Unsigned integer value defining the priority of the rule. The higher the " "number the lower the priority. <quote>0</quote> stands for the highest " @@ -5548,17 +5878,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4381 +#: sssd.conf.5.xml:4586 msgid "Default: the lowest priority" msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:4389 +#: sssd.conf.5.xml:4594 msgid "PROMPTING CONFIGURATION SECTION" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4391 +#: sssd.conf.5.xml:4596 msgid "" "If a special file (<filename>/var/lib/sss/pubconf/pam_preauth_available</" "filename>) exists SSSD's PAM module pam_sss will ask SSSD to figure out " @@ -5568,7 +5898,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4399 +#: sssd.conf.5.xml:4604 msgid "" "With the growing number of authentication methods and the possibility that " "there are multiple ones for a single user the heuristic used by pam_sss to " @@ -5577,59 +5907,59 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4411 +#: sssd.conf.5.xml:4616 msgid "[prompting/password]" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4414 +#: sssd.conf.5.xml:4619 msgid "password_prompt" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4415 +#: sssd.conf.5.xml:4620 msgid "to change the string of the password prompt" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4413 +#: sssd.conf.5.xml:4618 msgid "" "to configure password prompting, allowed options are: <placeholder " "type=\"variablelist\" id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4423 +#: sssd.conf.5.xml:4628 msgid "[prompting/2fa]" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4427 +#: sssd.conf.5.xml:4632 msgid "first_prompt" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4428 +#: sssd.conf.5.xml:4633 msgid "to change the string of the prompt for the first factor" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4431 +#: sssd.conf.5.xml:4636 msgid "second_prompt" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4432 +#: sssd.conf.5.xml:4637 msgid "to change the string of the prompt for the second factor" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4435 +#: sssd.conf.5.xml:4640 msgid "single_prompt" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4436 +#: sssd.conf.5.xml:4641 msgid "" "boolean value, if True there will be only a single prompt using the value of " "first_prompt where it is expected that both factors are entered as a single " @@ -5638,7 +5968,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4425 +#: sssd.conf.5.xml:4630 msgid "" "to configure two-factor authentication prompting, allowed options are: " "<placeholder type=\"variablelist\" id=\"0\"/> If the second factor is " @@ -5647,7 +5977,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4449 +#: sssd.conf.5.xml:4654 msgid "" "Some clients, such as SSH with 'PasswordAuthentication yes', generate their " "own prompts and do not use prompts provided by SSSD or other PAM modules. " @@ -5658,79 +5988,169 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4464 -msgid "[prompting/passkey]" +#: sssd.conf.5.xml:4669 +msgid "[prompting/passkey]" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:4675 sssd.conf.5.xml:4719 sssd-ad.5.xml:1027 +msgid "interactive" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4677 +msgid "" +"boolean value, if True prompt a message and wait before testing the presence " +"of a passkey device. Recommended if your device doesn’t have a tactile " +"trigger." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4685 sssd.conf.5.xml:4735 +msgid "interactive_prompt" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4687 sssd.conf.5.xml:4737 +msgid "to change the message of the interactive prompt." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4692 +msgid "touch" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4694 +msgid "" +"boolean value, if True prompt a message to remind the user to touch the " +"device." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4700 +msgid "touch_prompt" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4702 +msgid "to change the message of the touch prompt." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4671 +#, fuzzy +#| msgid "" +#| "The following expansions are supported: <placeholder " +#| "type=\"variablelist\" id=\"0\"/>" +msgid "" +"to configure passkey authentication prompting, allowed options are: " +"<placeholder type=\"variablelist\" id=\"0\"/>" +msgstr "" +"S'admeten les següents ampliacions: <placeholder type=\"variablelist\" " +"id=\"0\"/>" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4713 +msgid "[prompting/oauth2]" msgstr "" -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:4470 sssd-ad.5.xml:1022 -msgid "interactive" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4721 +msgid "" +"boolean value, if True prompt a message after asking the user to " +"authenticate, and wait before requesting the access token." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4472 +#: sssd.conf.5.xml:4725 msgid "" -"boolean value, if True prompt a message and wait before testing the presence " -"of a passkey device. Recommended if your device doesn’t have a tactile " -"trigger." +"If False, make sure to set the <quote>idp_request_timeout</quote> " +"sufficiently high, to give the user time to authenticate." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4715 +#, fuzzy +#| msgid "" +#| "The following expansions are supported: <placeholder " +#| "type=\"variablelist\" id=\"0\"/>" +msgid "" +"to configure OAuth2 authentication prompting, allowed options are: " +"<placeholder type=\"variablelist\" id=\"0\"/>" +msgstr "" +"S'admeten les següents ampliacions: <placeholder type=\"variablelist\" " +"id=\"0\"/>" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4748 +msgid "[prompting/cert_auth]" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4480 -msgid "interactive_prompt" +#: sssd.conf.5.xml:4754 +msgid "pin_prompt" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4482 -msgid "to change the message of the interactive prompt." +#: sssd.conf.5.xml:4756 +msgid "" +"to change the message which asks the user to enter the PIN at the computer " +"keyboard. At the end of the message the token name is printed." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4487 -msgid "touch" +#: sssd.conf.5.xml:4764 +msgid "keypad_prompt" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4489 +#: sssd.conf.5.xml:4766 msgid "" -"boolean value, if True prompt a message to remind the user to touch the " -"device." +"to change the message which asks the user to enter the PIN at keypad of the " +"Smartcard reader. At the end of the message the token name is printed." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4495 -msgid "touch_prompt" -msgstr "" +#: sssd.conf.5.xml:4774 +#, fuzzy +#| msgid "user name" +msgid "user_name_hint" +msgstr "nom d'usuari" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4497 -msgid "to change the message of the touch prompt." +#: sssd.conf.5.xml:4776 +msgid "" +"boolean value, if True ask for a user name if no name was given before and " +"the found certificate can be mapped to more than one user." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4466 +#: sssd.conf.5.xml:4750 #, fuzzy #| msgid "" #| "The following expansions are supported: <placeholder " #| "type=\"variablelist\" id=\"0\"/>" msgid "" -"to configure passkey authentication prompting, allowed options are: " +"to configure Smartcard authentication prompting, allowed options are: " "<placeholder type=\"variablelist\" id=\"0\"/>" msgstr "" "S'admeten les següents ampliacions: <placeholder type=\"variablelist\" " "id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4406 +#: sssd.conf.5.xml:4611 msgid "" "Each supported authentication method has its own configuration subsection " "under <quote>[prompting/...]</quote>. Currently there are: <placeholder " "type=\"variablelist\" id=\"0\"/> <placeholder type=\"variablelist\" id=\"1\"/" -"> <placeholder type=\"variablelist\" id=\"2\"/>" +"> <placeholder type=\"variablelist\" id=\"2\"/> <placeholder " +"type=\"variablelist\" id=\"3\"/> <placeholder type=\"variablelist\" id=\"4\"/" +">" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4508 +#: sssd.conf.5.xml:4792 msgid "" "It is possible to add a subsection for specific PAM services, e.g. " "<quote>[prompting/password/sshd]</quote> to individual change the prompting " @@ -5738,12 +6158,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:4515 pam_sss_gss.8.xml:157 idmap_sss.8.xml:43 +#: sssd.conf.5.xml:4799 pam_sss_gss.8.xml:157 idmap_sss.8.xml:43 msgid "EXAMPLES" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd.conf.5.xml:4521 +#: sssd.conf.5.xml:4805 #, fuzzy, no-wrap #| msgid "" #| "[sssd]\n" @@ -5821,7 +6241,7 @@ msgstr "" "enumerate = False\n" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4517 +#: sssd.conf.5.xml:4801 msgid "" "1. The following example shows a typical SSSD config. It does not describe " "configuration of the domains themselves - refer to documentation on " @@ -5830,7 +6250,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd.conf.5.xml:4553 +#: sssd.conf.5.xml:4837 #, no-wrap msgid "" "[domain/ipa.com/child.ad.com]\n" @@ -5838,7 +6258,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4547 +#: sssd.conf.5.xml:4831 msgid "" "2. The following example shows configuration of IPA AD trust where the AD " "forest consists of two domains in a parent-child structure. Suppose IPA " @@ -5849,7 +6269,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd.conf.5.xml:4564 +#: sssd.conf.5.xml:4848 #, no-wrap msgid "" "[certmap/my.domain/rule_name]\n" @@ -5860,7 +6280,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4558 +#: sssd.conf.5.xml:4842 msgid "" "3. The following example shows the configuration of a certificate mapping " "rule. It is valid for the configured domain <quote>my.domain</quote> and " @@ -6084,7 +6504,7 @@ msgid "" "defaultNamingContext does not exist or has an empty value namingContexts is " "used. The namingContexts attribute must have a single value with the DN of " "the search base of the LDAP server to make this work. Multiple values are " -"are not supported." +"not supported." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> @@ -6403,15 +6823,15 @@ msgid "Optional. Use the given string as search base for host objects." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap.5.xml:472 sssd-ipa.5.xml:506 sssd-ipa.5.xml:525 sssd-ipa.5.xml:544 -#: sssd-ipa.5.xml:563 +#: sssd-ldap.5.xml:472 sssd-ipa.5.xml:501 sssd-ipa.5.xml:520 sssd-ipa.5.xml:539 +#: sssd-ipa.5.xml:558 msgid "" "See <quote>ldap_search_base</quote> for information about configuring " "multiple search bases." msgstr "" #. type: Content of: <listitem><para> -#: sssd-ldap.5.xml:477 sssd-ipa.5.xml:511 include/ldap_search_bases.xml:27 +#: sssd-ldap.5.xml:477 sssd-ipa.5.xml:506 include/ldap_search_bases.xml:27 msgid "Default: the value of <emphasis>ldap_search_base</emphasis>" msgstr "Per defecte: el valor de <emphasis>ldap_search_base</emphasis>" @@ -6545,7 +6965,7 @@ msgid "" "closed early to ensure that a new query cannot require the connection to " "remain open past its expiration. This implies that connections will always " "be closed immediately and will never be reused if " -"<emphasis>ldap_connection_expire_timeout <= ldap_opt_timout</emphasis>" +"<emphasis>ldap_connection_expire_timeout <= ldap_opt_timeout</emphasis>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> @@ -6729,8 +7149,10 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:831 -msgid "ldap_ignore_unreadable_references (bool)" -msgstr "" +#, fuzzy +#| msgid "ldap_force_upper_case_realm (boolean)" +msgid "ldap_ignore_unreadable_references (boolean)" +msgstr "ldap_force_upper_case_realm (booleà)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:834 @@ -7093,7 +7515,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap.5.xml:1152 sssd-ad.5.xml:1267 +#: sssd-ldap.5.xml:1152 sssd-ad.5.xml:1260 msgid "Default: 86400 (24 hours)" msgstr "Per defecte: 86400 (24 hores)" @@ -7138,7 +7560,7 @@ msgstr "" "krb5_server</quote>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ldap.5.xml:1187 sssd-ipa.5.xml:575 sssd-krb5.5.xml:103 +#: sssd-ldap.5.xml:1187 sssd-ipa.5.xml:570 sssd-krb5.5.xml:103 msgid "krb5_realm (string)" msgstr "krb5_realm (cadena)" @@ -7313,7 +7735,9 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1339 -msgid "ldap_chpass_update_last_change (bool)" +#, fuzzy +#| msgid "ldap_chpass_update_last_change (bool)" +msgid "ldap_chpass_update_last_change (boolean)" msgstr "ldap_chpass_update_last_change (booleà)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> @@ -7468,7 +7892,7 @@ msgid "ldap_access_order (string)" msgstr "ldap_access_order (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap.5.xml:1470 sssd-ipa.5.xml:405 +#: sssd-ldap.5.xml:1470 sssd-ipa.5.xml:400 msgid "Comma separated list of access control options. Allowed values are:" msgstr "" "Llista separada per comes d'opcions de control d'accés. Els valors permesos " @@ -7515,7 +7939,7 @@ msgid "<emphasis>expire</emphasis>: use ldap_account_expire_policy" msgstr "<emphasis>expire</emphasis>: utilitza ldap_account_expire_policy" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap.5.xml:1515 sssd-ipa.5.xml:413 +#: sssd-ldap.5.xml:1515 sssd-ipa.5.xml:408 msgid "" "<emphasis>pwd_expire_policy_reject, pwd_expire_policy_warn, " "pwd_expire_policy_renew: </emphasis> These options are useful if users are " @@ -7525,24 +7949,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap.5.xml:1525 sssd-ipa.5.xml:423 +#: sssd-ldap.5.xml:1525 sssd-ipa.5.xml:418 msgid "" "The difference between these options is the action taken if user password is " "expired:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ldap.5.xml:1530 sssd-ipa.5.xml:428 +#: sssd-ldap.5.xml:1530 sssd-ipa.5.xml:423 msgid "pwd_expire_policy_reject - user is denied to log in," msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ldap.5.xml:1536 sssd-ipa.5.xml:434 +#: sssd-ldap.5.xml:1536 sssd-ipa.5.xml:429 msgid "pwd_expire_policy_warn - user is still able to log in," msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ldap.5.xml:1542 sssd-ipa.5.xml:440 +#: sssd-ldap.5.xml:1542 sssd-ipa.5.xml:435 msgid "" "pwd_expire_policy_renew - user is prompted to change their password " "immediately." @@ -8103,8 +8527,8 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd-ldap.5.xml:2032 sssd-simple.5.xml:169 sssd-ipa.5.xml:984 -#: sssd-ad.5.xml:1470 sssd-idp.5.xml:248 sssd-krb5.5.xml:483 +#: sssd-ldap.5.xml:2032 sssd-simple.5.xml:169 sssd-ipa.5.xml:979 +#: sssd-ad.5.xml:1463 sssd-idp.5.xml:343 sssd-krb5.5.xml:483 #: sss_rpcidmapd.5.xml:98 sssd-session-recording.5.xml:176 msgid "EXAMPLE" msgstr "EXEMPLE" @@ -8135,7 +8559,7 @@ msgstr "" #. type: Content of: <refsect1><refsect2><para> #: sssd-ldap.5.xml:2039 sssd-ldap.5.xml:2057 sssd-simple.5.xml:177 -#: sssd-ipa.5.xml:992 sssd-ad.5.xml:1478 sssd-sudo.5.xml:56 sssd-krb5.5.xml:492 +#: sssd-ipa.5.xml:987 sssd-ad.5.xml:1471 sssd-sudo.5.xml:56 sssd-krb5.5.xml:492 #: sssd-session-recording.5.xml:182 include/ldap_id_mapping.xml:105 msgid "<placeholder type=\"programlisting\" id=\"0\"/>" msgstr "<placeholder type=\"programlisting\" id=\"0\"/>" @@ -8170,7 +8594,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><title> #: sssd-ldap.5.xml:2073 sssd_krb5_locator_plugin.8.xml:83 sssd-simple.5.xml:189 -#: sssd-ad.5.xml:1493 sssd.8.xml:270 sss_seed.8.xml:163 +#: sssd-ad.5.xml:1486 sssd.8.xml:270 sss_seed.8.xml:163 msgid "NOTES" msgstr "NOTES" @@ -8721,7 +9145,7 @@ msgstr "" #: pam_sss.8.xml:434 msgid "" "No authentication method was found by Kerberos. This might happen if the " -"user has a Smartcard assigned but the pkint plugin is not available on the " +"user has a Smartcard assigned but the pkinit plugin is not available on the " "client." msgstr "" @@ -9176,6 +9600,23 @@ msgid "" "first DNS resolving failure." msgstr "" +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_locator_plugin.8.xml:106 +msgid "" +"If the environment variable SSSD_KRB5_LOCATOR_KDC_ADDRESS is set to a KDC " +"address the plugin will use this address instead of reading the kdcinfo " +"file. The address format is the same as in the kdcinfo file (see above)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_locator_plugin.8.xml:112 +msgid "" +"If the environment variable SSSD_KRB5_LOCATOR_KPASSWD_ADDRESS is set to a " +"kpasswd server address the plugin will use this address instead of reading " +"the kpasswdinfo file. The address format is the same as in the kpasswdinfo " +"file (see above)." +msgstr "" + #. type: Content of: <reference><refentry><refnamediv><refname> #: sssd-simple.5.xml:10 sssd-simple.5.xml:16 msgid "sssd-simple" @@ -10657,7 +11098,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:129 sssd-ad.5.xml:1161 +#: sssd-ipa.5.xml:129 sssd-ad.5.xml:1166 msgid "dyndns_update (boolean)" msgstr "dyndns_update (booleà)" @@ -10671,20 +11112,13 @@ msgid "" "quote> option." msgstr "" -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:141 sssd-ad.5.xml:1175 -msgid "" -"NOTE: On older systems (such as RHEL 5), for this behavior to work reliably, " -"the default Kerberos realm must be set properly in /etc/krb5.conf" -msgstr "" - #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:152 sssd-ad.5.xml:1186 +#: sssd-ipa.5.xml:147 sssd-ad.5.xml:1186 msgid "dyndns_ttl (integer)" msgstr "dyndns_ttl (enter)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:155 sssd-ad.5.xml:1189 +#: sssd-ipa.5.xml:150 sssd-ad.5.xml:1189 msgid "" "The TTL to apply to the client DNS record when updating it. If " "dyndns_update is false this has no effect. This will override the TTL " @@ -10692,17 +11126,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:160 +#: sssd-ipa.5.xml:155 msgid "Default: 1200 (seconds)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:166 sssd-ad.5.xml:1200 +#: sssd-ipa.5.xml:161 sssd-ad.5.xml:1200 msgid "dyndns_iface (string)" msgstr "dyndns_iface (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:169 sssd-ad.5.xml:1203 +#: sssd-ipa.5.xml:164 sssd-ad.5.xml:1203 msgid "" "Optional. Applicable only when dyndns_update is true. Choose the interface " "or a list of interfaces whose IP addresses should be used for dynamic DNS " @@ -10714,26 +11148,26 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:182 +#: sssd-ipa.5.xml:177 msgid "" "Default: Use the IP addresses of the interface which is used for IPA LDAP " "connection" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:186 sssd-ad.5.xml:1226 +#: sssd-ipa.5.xml:181 sssd-ad.5.xml:1220 msgid "Example: dyndns_iface = em[12], !vnet1, vnet*" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:192 sssd-ad.5.xml:1232 +#: sssd-ipa.5.xml:187 sssd-ad.5.xml:1226 #, fuzzy #| msgid "dyndns_iface (string)" msgid "dyndns_address (string)" msgstr "dyndns_iface (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:195 sssd-ad.5.xml:1235 +#: sssd-ipa.5.xml:190 sssd-ad.5.xml:1229 msgid "" "Optional. Applicable only when <emphasis>dyndns_update</emphasis> is true. " "A list of IP addresses or IP networks to be used for dynamic DNS updates. " @@ -10744,22 +11178,22 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:206 sssd-ad.5.xml:1246 +#: sssd-ipa.5.xml:201 sssd-ad.5.xml:1240 msgid "Default: No filtering of IP addresses." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:209 sssd-ad.5.xml:1249 +#: sssd-ipa.5.xml:204 sssd-ad.5.xml:1243 msgid "Example: dyndns_address = 10.0.0.0/16, !10.0.1.0/24" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:215 sssd-ad.5.xml:1305 +#: sssd-ipa.5.xml:210 sssd-ad.5.xml:1298 msgid "dyndns_auth (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:218 sssd-ad.5.xml:1308 +#: sssd-ipa.5.xml:213 sssd-ad.5.xml:1301 msgid "" "Whether the nsupdate utility should use GSS-TSIG authentication for secure " "updates with the DNS server, insecure updates can be sent by setting this " @@ -10767,19 +11201,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:224 sssd-ad.5.xml:1314 +#: sssd-ipa.5.xml:219 sssd-ad.5.xml:1307 msgid "Default: GSS-TSIG" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:230 sssd-ad.5.xml:1320 +#: sssd-ipa.5.xml:225 sssd-ad.5.xml:1313 #, fuzzy #| msgid "dyndns_iface (string)" msgid "dyndns_auth_ptr (string)" msgstr "dyndns_iface (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:233 sssd-ad.5.xml:1323 +#: sssd-ipa.5.xml:228 sssd-ad.5.xml:1316 msgid "" "Whether the nsupdate utility should use GSS-TSIG authentication for secure " "PTR updates with the DNS server, insecure updates can be sent by setting " @@ -10787,17 +11221,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:239 sssd-ad.5.xml:1329 +#: sssd-ipa.5.xml:234 sssd-ad.5.xml:1322 msgid "Default: Same as dyndns_auth" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:245 sssd-ad.5.xml:1255 +#: sssd-ipa.5.xml:240 sssd-ad.5.xml:1249 msgid "dyndns_refresh_interval (integer)" msgstr "dyndns_refresh_interval (enter)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:248 +#: sssd-ipa.5.xml:243 msgid "" "How often should the back end perform periodic DNS update in addition to the " "automatic update performed when the back end goes online. This option is " @@ -10805,74 +11239,78 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:261 sssd-ad.5.xml:1273 -msgid "dyndns_update_ptr (bool)" +#: sssd-ipa.5.xml:256 sssd-ad.5.xml:1266 +#, fuzzy +#| msgid "dyndns_update_ptr (bool)" +msgid "dyndns_update_ptr (boolean)" msgstr "dyndns_update_ptr (booleà)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:264 sssd-ad.5.xml:1276 +#: sssd-ipa.5.xml:259 sssd-ad.5.xml:1269 msgid "" "Whether the PTR record should also be explicitly updated when updating the " "client's DNS records. Applicable only when dyndns_update is true." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:269 +#: sssd-ipa.5.xml:264 msgid "" "This option should be False in most IPA deployments as the IPA server " "generates the PTR records automatically when forward records are changed." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:275 sssd-ad.5.xml:1281 +#: sssd-ipa.5.xml:270 sssd-ad.5.xml:1274 msgid "" "Note that <emphasis>dyndns_update_per_family</emphasis> parameter does not " "apply for PTR record updates. Those updates are always sent separately." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:280 +#: sssd-ipa.5.xml:275 msgid "Default: False (disabled)" msgstr "Per defecte: False (inhabilitat)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:286 sssd-ad.5.xml:1292 -msgid "dyndns_force_tcp (bool)" +#: sssd-ipa.5.xml:281 sssd-ad.5.xml:1285 +#, fuzzy +#| msgid "dyndns_force_tcp (bool)" +msgid "dyndns_force_tcp (boolean)" msgstr "dyndns_force_tcp (booleà)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:289 sssd-ad.5.xml:1295 +#: sssd-ipa.5.xml:284 sssd-ad.5.xml:1288 msgid "" "Whether the nsupdate utility should default to using TCP for communicating " "with the DNS server." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:293 sssd-ad.5.xml:1299 +#: sssd-ipa.5.xml:288 sssd-ad.5.xml:1292 msgid "Default: False (let nsupdate choose the protocol)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:299 sssd-ad.5.xml:1335 +#: sssd-ipa.5.xml:294 sssd-ad.5.xml:1328 msgid "dyndns_server (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:302 sssd-ad.5.xml:1338 +#: sssd-ipa.5.xml:297 sssd-ad.5.xml:1331 msgid "" "The DNS server to use when performing a DNS update. In most setups, it's " "recommended to leave this option unset." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:307 sssd-ad.5.xml:1343 +#: sssd-ipa.5.xml:302 sssd-ad.5.xml:1336 msgid "" "Setting this option makes sense for environments where the DNS server is " "different from the identity server or when we use encrypted DNS." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:312 sssd-ad.5.xml:1348 +#: sssd-ipa.5.xml:307 sssd-ad.5.xml:1341 msgid "" "The parameter can be a simple string containing DNS name or IP address. It " "can also be an URI. The URI can look like <emphasis>dns://servername/</" @@ -10880,7 +11318,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:319 sssd-ad.5.xml:1355 +#: sssd-ipa.5.xml:314 sssd-ad.5.xml:1348 msgid "" "The second example enables DNS-over-TLS protocol for DNS updates. The " "nsupdate utility must support DoT - check the <emphasis>man nsupdate</" @@ -10888,7 +11326,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:325 sssd-ad.5.xml:1361 +#: sssd-ipa.5.xml:320 sssd-ad.5.xml:1354 msgid "" "Please note that this option will be only used in fallback attempt when " "previous attempt using autodetected settings failed or when DNS-over-TLS is " @@ -10896,17 +11334,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:331 sssd-ad.5.xml:1367 +#: sssd-ipa.5.xml:326 sssd-ad.5.xml:1360 msgid "Default: None (let nsupdate choose the server)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:337 sssd-ad.5.xml:1373 +#: sssd-ipa.5.xml:332 sssd-ad.5.xml:1366 msgid "dyndns_update_per_family (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:340 sssd-ad.5.xml:1376 +#: sssd-ipa.5.xml:335 sssd-ad.5.xml:1369 msgid "" "DNS update is by default performed in two steps - IPv4 update and then IPv6 " "update. In some cases it might be desirable to perform IPv4 and IPv6 update " @@ -10914,14 +11352,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:352 sssd-ad.5.xml:1388 +#: sssd-ipa.5.xml:347 sssd-ad.5.xml:1381 #, fuzzy #| msgid "dyndns_iface (string)" msgid "dyndns_dot_cacert (string)" msgstr "dyndns_iface (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:355 sssd-ad.5.xml:1391 +#: sssd-ipa.5.xml:350 sssd-ad.5.xml:1384 msgid "" "This option specifies the file of the certificate authorities certificates " "(in PEM format) in order to verify the remote server TLS certificate when " @@ -10929,19 +11367,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:361 sssd-ad.5.xml:1397 +#: sssd-ipa.5.xml:356 sssd-ad.5.xml:1390 msgid "Default: None (use global certificate store)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:367 sssd-ad.5.xml:1403 +#: sssd-ipa.5.xml:362 sssd-ad.5.xml:1396 #, fuzzy #| msgid "dyndns_iface (string)" msgid "dyndns_dot_cert (string)" msgstr "dyndns_iface (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:370 sssd-ad.5.xml:1406 +#: sssd-ipa.5.xml:365 sssd-ad.5.xml:1399 msgid "" "This option sets the certificate(s) file for authentication for the DoT " "transport to the remote server. The certificate chain file is expected to be " @@ -10949,14 +11387,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:376 sssd-ad.5.xml:1412 +#: sssd-ipa.5.xml:371 sssd-ad.5.xml:1405 msgid "" "The <emphasis>dyndns_dot_cert</emphasis> and <emphasis>dyndns_dot_key</" "emphasis> options must be both set to achieve mutual TLS authentication." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:381 sssd-ipa.5.xml:396 sssd-ad.5.xml:1417 sssd-ad.5.xml:1432 +#: sssd-ipa.5.xml:376 sssd-ipa.5.xml:391 sssd-ad.5.xml:1410 sssd-ad.5.xml:1425 #, fuzzy #| msgid "Default: not set (no substitution for unset home directories)" msgid "Default: None (Do not use TLS authentication)" @@ -10965,14 +11403,14 @@ msgstr "" "establerts)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:387 sssd-ad.5.xml:1423 +#: sssd-ipa.5.xml:382 sssd-ad.5.xml:1416 #, fuzzy #| msgid "dyndns_iface (string)" msgid "dyndns_dot_key (string)" msgstr "dyndns_iface (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:390 sssd-ad.5.xml:1426 +#: sssd-ipa.5.xml:385 sssd-ad.5.xml:1419 msgid "" "This option sets the key file for authenticated encryption for the DoT " "transport to the remote server. The private key file is expected to be in " @@ -10980,178 +11418,178 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:402 +#: sssd-ipa.5.xml:397 #, fuzzy #| msgid "ldap_access_order (string)" msgid "ipa_access_order (string)" msgstr "ldap_access_order (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:409 +#: sssd-ipa.5.xml:404 #, fuzzy #| msgid "<emphasis>expire</emphasis>: use ldap_account_expire_policy" msgid "<emphasis>expire</emphasis>: use IPA's account expiration policy." msgstr "<emphasis>expire</emphasis>: utilitza ldap_account_expire_policy" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:448 +#: sssd-ipa.5.xml:443 msgid "" "Please note that 'access_provider = ipa' must be set for this feature to " "work." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:455 +#: sssd-ipa.5.xml:450 msgid "ipa_deskprofile_search_base (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:458 +#: sssd-ipa.5.xml:453 msgid "" "Optional. Use the given string as search base for Desktop Profile related " "objects." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:462 sssd-ipa.5.xml:484 +#: sssd-ipa.5.xml:457 sssd-ipa.5.xml:479 msgid "Default: Use base DN" msgstr "Per defecte: Utilitza el DN base" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:468 +#: sssd-ipa.5.xml:463 #, fuzzy #| msgid "ipa_subdomains_search_base (string)" msgid "ipa_subid_ranges_search_base (string)" msgstr "ipa_subdomains_search_base (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:471 +#: sssd-ipa.5.xml:466 #, fuzzy #| msgid "ipa_subdomains_search_base (string)" msgid "Deprecated. Use ldap_subid_ranges_search_base instead." msgstr "ipa_subdomains_search_base (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:477 +#: sssd-ipa.5.xml:472 msgid "ipa_hbac_search_base (string)" msgstr "ipa_hbac_search_base (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:480 +#: sssd-ipa.5.xml:475 msgid "Optional. Use the given string as search base for HBAC related objects." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:490 +#: sssd-ipa.5.xml:485 msgid "ipa_host_search_base (string)" msgstr "ipa_host_search_base (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:493 +#: sssd-ipa.5.xml:488 msgid "Deprecated. Use ldap_host_search_base instead." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:499 +#: sssd-ipa.5.xml:494 msgid "ipa_selinux_search_base (string)" msgstr "ipa_selinux_search_base (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:502 +#: sssd-ipa.5.xml:497 msgid "Optional. Use the given string as search base for SELinux user maps." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:518 +#: sssd-ipa.5.xml:513 msgid "ipa_subdomains_search_base (string)" msgstr "ipa_subdomains_search_base (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:521 +#: sssd-ipa.5.xml:516 msgid "Optional. Use the given string as search base for trusted domains." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:530 +#: sssd-ipa.5.xml:525 msgid "Default: the value of <emphasis>cn=trusts,%basedn</emphasis>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:537 +#: sssd-ipa.5.xml:532 msgid "ipa_master_domain_search_base (string)" msgstr "ipa_master_domain_search_base (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:540 +#: sssd-ipa.5.xml:535 msgid "Optional. Use the given string as search base for master domain object." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:549 +#: sssd-ipa.5.xml:544 msgid "Default: the value of <emphasis>cn=ad,cn=etc,%basedn</emphasis>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:556 +#: sssd-ipa.5.xml:551 msgid "ipa_views_search_base (string)" msgstr "ipa_views_search_base (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:559 +#: sssd-ipa.5.xml:554 msgid "Optional. Use the given string as search base for views containers." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:568 +#: sssd-ipa.5.xml:563 msgid "Default: the value of <emphasis>cn=views,cn=accounts,%basedn</emphasis>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:578 +#: sssd-ipa.5.xml:573 msgid "" "The name of the Kerberos realm. This is optional and defaults to the value " "of <quote>ipa_domain</quote>." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:582 +#: sssd-ipa.5.xml:577 msgid "" "The name of the Kerberos realm has a special meaning in IPA - it is " "converted into the base DN to use for performing LDAP operations." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:590 sssd-ad.5.xml:1441 +#: sssd-ipa.5.xml:585 sssd-ad.5.xml:1434 msgid "krb5_confd_path (string)" msgstr "krb5_confd_path (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:593 sssd-ad.5.xml:1444 +#: sssd-ipa.5.xml:588 sssd-ad.5.xml:1437 msgid "" "Absolute path of a directory where SSSD should place Kerberos configuration " "snippets." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:597 sssd-ad.5.xml:1448 +#: sssd-ipa.5.xml:592 sssd-ad.5.xml:1441 msgid "" "To disable the creation of the configuration snippets set the parameter to " "'none'." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:601 sssd-ad.5.xml:1452 +#: sssd-ipa.5.xml:596 sssd-ad.5.xml:1445 msgid "" "Default: not set (krb5.include.d subdirectory of SSSD's pubconf directory)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:608 +#: sssd-ipa.5.xml:603 msgid "ipa_deskprofile_refresh (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:611 +#: sssd-ipa.5.xml:606 msgid "" "The amount of time between lookups of the Desktop Profile rules against the " "IPA server. This will reduce the latency and load on the IPA server if there " @@ -11159,34 +11597,34 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:618 sssd-ipa.5.xml:648 sssd-ipa.5.xml:664 sssd-ad.5.xml:600 +#: sssd-ipa.5.xml:613 sssd-ipa.5.xml:643 sssd-ipa.5.xml:659 sssd-ad.5.xml:600 msgid "Default: 5 (seconds)" msgstr "Per defecte: 5 (segons)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:624 +#: sssd-ipa.5.xml:619 msgid "ipa_deskprofile_request_interval (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:627 +#: sssd-ipa.5.xml:622 msgid "" "The amount of time between lookups of the Desktop Profile rules against the " "IPA server in case the last request did not return any rule." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:632 +#: sssd-ipa.5.xml:627 msgid "Default: 60 (minutes)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:638 +#: sssd-ipa.5.xml:633 msgid "ipa_hbac_refresh (integer)" msgstr "ipa_hbac_refresh (enter)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:641 +#: sssd-ipa.5.xml:636 msgid "" "The amount of time between lookups of the HBAC rules against the IPA server. " "This will reduce the latency and load on the IPA server if there are many " @@ -11194,12 +11632,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:654 -msgid "ipa_hbac_selinux (integer)" -msgstr "ipa_hbac_selinux (enter)" +#: sssd-ipa.5.xml:649 +#, fuzzy +#| msgid "ipa_hbac_refresh (integer)" +msgid "ipa_selinux_refresh (integer)" +msgstr "ipa_hbac_refresh (enter)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:657 +#: sssd-ipa.5.xml:652 msgid "" "The amount of time between lookups of the SELinux maps against the IPA " "server. This will reduce the latency and load on the IPA server if there are " @@ -11207,33 +11647,33 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:670 +#: sssd-ipa.5.xml:665 msgid "ipa_server_mode (boolean)" msgstr "ipa_server_mode (booleà)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:673 +#: sssd-ipa.5.xml:668 msgid "" "This option will be set by the IPA installer (ipa-server-install) " "automatically and denotes if SSSD is running on an IPA server or not." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:678 +#: sssd-ipa.5.xml:673 msgid "" "On an IPA server SSSD will lookup users and groups from trusted domains " "directly while on a client it will ask an IPA server." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:683 +#: sssd-ipa.5.xml:678 msgid "" "NOTE: There are currently some assumptions that must be met when SSSD is " "running on an IPA server." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:688 +#: sssd-ipa.5.xml:683 msgid "" "The <quote>ipa_server</quote> option must be configured to point to the IPA " "server itself. This is already the default set by the IPA installer, so no " @@ -11241,59 +11681,59 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:697 +#: sssd-ipa.5.xml:692 msgid "" "The <quote>full_name_format</quote> option must not be tweaked to only print " "short names for users from trusted domains." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:712 +#: sssd-ipa.5.xml:707 msgid "ipa_automount_location (string)" msgstr "ipa_automount_location (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:715 +#: sssd-ipa.5.xml:710 msgid "The automounter location this IPA client will be using" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:718 +#: sssd-ipa.5.xml:713 msgid "Default: The location named \"default\"" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd-ipa.5.xml:726 +#: sssd-ipa.5.xml:721 msgid "VIEWS AND OVERRIDES" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:735 +#: sssd-ipa.5.xml:730 msgid "ipa_view_class (string)" msgstr "ipa_view_class (cadena)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:738 +#: sssd-ipa.5.xml:733 msgid "Objectclass of the view container." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:741 +#: sssd-ipa.5.xml:736 msgid "Default: nsContainer" msgstr "Per defecte: nsContainer" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:747 +#: sssd-ipa.5.xml:742 msgid "ipa_view_name (string)" msgstr "ipa_view_name (cadena)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:750 +#: sssd-ipa.5.xml:745 msgid "Name of the attribute holding the name of the view." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:754 sssd-ldap-attributes.5.xml:496 +#: sssd-ipa.5.xml:749 sssd-ldap-attributes.5.xml:496 #: sssd-ldap-attributes.5.xml:832 sssd-ldap-attributes.5.xml:913 #: sssd-ldap-attributes.5.xml:1010 sssd-ldap-attributes.5.xml:1068 #: sssd-ldap-attributes.5.xml:1226 sssd-ldap-attributes.5.xml:1271 @@ -11301,128 +11741,128 @@ msgid "Default: cn" msgstr "Per defecte: cn" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:760 +#: sssd-ipa.5.xml:755 msgid "ipa_override_object_class (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:763 +#: sssd-ipa.5.xml:758 msgid "Objectclass of the override objects." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:766 +#: sssd-ipa.5.xml:761 msgid "Default: ipaOverrideAnchor" msgstr "Per defecte: ipaOverrideAnchor" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:772 +#: sssd-ipa.5.xml:767 msgid "ipa_anchor_uuid (string)" msgstr "ipa_anchor_uuid (cadena)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:775 +#: sssd-ipa.5.xml:770 msgid "" "Name of the attribute containing the reference to the original object in a " "remote domain." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:779 +#: sssd-ipa.5.xml:774 msgid "Default: ipaAnchorUUID" msgstr "Per defecte: ipaAnchorUUID" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:785 +#: sssd-ipa.5.xml:780 msgid "ipa_user_override_object_class (string)" msgstr "ipa_user_override_object_class (cadena)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:788 +#: sssd-ipa.5.xml:783 msgid "" "Name of the objectclass for user overrides. It is used to determine if the " "found override object is related to a user or a group." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:793 +#: sssd-ipa.5.xml:788 msgid "User overrides can contain attributes given by" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:796 +#: sssd-ipa.5.xml:791 msgid "ldap_user_name" msgstr "ldap_user_name" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:799 +#: sssd-ipa.5.xml:794 msgid "ldap_user_uid_number" msgstr "ldap_user_uid_number" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:802 +#: sssd-ipa.5.xml:797 msgid "ldap_user_gid_number" msgstr "ldap_user_gid_number" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:805 +#: sssd-ipa.5.xml:800 msgid "ldap_user_gecos" msgstr "ldap_user_gecos" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:808 +#: sssd-ipa.5.xml:803 msgid "ldap_user_home_directory" msgstr "ldap_user_home_directory" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:811 +#: sssd-ipa.5.xml:806 msgid "ldap_user_shell" msgstr "ldap_user_shell" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:814 +#: sssd-ipa.5.xml:809 msgid "ldap_user_ssh_public_key" msgstr "ldap_user_ssh_public_key" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:819 +#: sssd-ipa.5.xml:814 msgid "Default: ipaUserOverride" msgstr "Per defecte: ipaUserOverride" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:825 +#: sssd-ipa.5.xml:820 msgid "ipa_group_override_object_class (string)" msgstr "ipa_group_override_object_class (cadena)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:828 +#: sssd-ipa.5.xml:823 msgid "" "Name of the objectclass for group overrides. It is used to determine if the " "found override object is related to a user or a group." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:833 +#: sssd-ipa.5.xml:828 msgid "Group overrides can contain attributes given by" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:836 +#: sssd-ipa.5.xml:831 msgid "ldap_group_name" msgstr "ldap_group_name" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:839 +#: sssd-ipa.5.xml:834 msgid "ldap_group_gid_number" msgstr "ldap_group_gid_number" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:844 +#: sssd-ipa.5.xml:839 msgid "Default: ipaGroupOverride" msgstr "Per defecte: ipaGroupOverride" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:728 +#: sssd-ipa.5.xml:723 msgid "" "SSSD can handle views and overrides which are offered by FreeIPA 4.1 and " "later version. Since all paths and objectclasses are fixed on the server " @@ -11432,19 +11872,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd-ipa.5.xml:856 +#: sssd-ipa.5.xml:851 msgid "SUBDOMAINS PROVIDER" msgstr "PROVEÏDOR DELS SUBDOMINIS" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:858 +#: sssd-ipa.5.xml:853 msgid "" "The IPA subdomains provider behaves slightly differently if it is configured " "explicitly or implicitly." msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:862 +#: sssd-ipa.5.xml:857 msgid "" "If the option 'subdomains_provider = ipa' is found in the domain section of " "sssd.conf, the IPA subdomains provider is configured explicitly, and all " @@ -11452,7 +11892,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:868 +#: sssd-ipa.5.xml:863 msgid "" "If the option 'subdomains_provider' is not set in the domain section of " "sssd.conf but there is the option 'id_provider = ipa', the IPA subdomains " @@ -11464,12 +11904,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd-ipa.5.xml:879 +#: sssd-ipa.5.xml:874 msgid "TRUSTED DOMAINS CONFIGURATION" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-ipa.5.xml:887 +#: sssd-ipa.5.xml:882 #, no-wrap msgid "" "[domain/ipa.domain.com/ad.domain.com]\n" @@ -11477,7 +11917,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:881 +#: sssd-ipa.5.xml:876 msgid "" "Some configuration options can also be set for a trusted domain. A trusted " "domain configuration can be set using the trusted domain subsection as shown " @@ -11487,99 +11927,99 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:892 +#: sssd-ipa.5.xml:887 msgid "" "For more details, see the <citerefentry> <refentrytitle>sssd.conf</" "refentrytitle> <manvolnum>5</manvolnum> </citerefentry> manual page." msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:899 +#: sssd-ipa.5.xml:894 msgid "" "Different configuration options are tunable for a trusted domain depending " "on whether you are configuring SSSD on an IPA server or an IPA client." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd-ipa.5.xml:904 +#: sssd-ipa.5.xml:899 msgid "OPTIONS TUNABLE ON IPA MASTERS" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:906 +#: sssd-ipa.5.xml:901 msgid "" "The following options can be set in a subdomain section on an IPA master:" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:910 sssd-ipa.5.xml:950 +#: sssd-ipa.5.xml:905 sssd-ipa.5.xml:945 msgid "ad_server" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:913 +#: sssd-ipa.5.xml:908 msgid "ad_backup_server" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:916 sssd-ipa.5.xml:953 +#: sssd-ipa.5.xml:911 sssd-ipa.5.xml:948 msgid "ad_site" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:919 +#: sssd-ipa.5.xml:914 msgid "ipa_server" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:922 +#: sssd-ipa.5.xml:917 #, fuzzy #| msgid "ipa_server, ipa_backup_server (string)" msgid "ipa_backup_server" msgstr "ipa_server, ipa_backup_server (cadena)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:925 +#: sssd-ipa.5.xml:920 msgid "ldap_search_base" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:928 +#: sssd-ipa.5.xml:923 msgid "ldap_user_search_base" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:931 +#: sssd-ipa.5.xml:926 msgid "ldap_group_search_base" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:939 +#: sssd-ipa.5.xml:934 msgid "" "Options prefixed with 'ad_' or 'ipa_' only apply to their respective " "subdomain type." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd-ipa.5.xml:944 +#: sssd-ipa.5.xml:939 msgid "OPTIONS TUNABLE ON IPA CLIENTS" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:946 +#: sssd-ipa.5.xml:941 msgid "" "The following options can be set in an AD subdomain section on an IPA client:" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:958 +#: sssd-ipa.5.xml:953 msgid "" "Note that if both options are set, only <quote>ad_server</quote> is " "evaluated." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:962 +#: sssd-ipa.5.xml:957 msgid "" "Since any request for a user or a group identity from a trusted domain " "triggered from an IPA client is resolved by the IPA server, the " @@ -11593,7 +12033,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:986 +#: sssd-ipa.5.xml:981 msgid "" "The following example assumes that SSSD is correctly configured and " "example.com is one of the domains in the <replaceable>[sssd]</replaceable> " @@ -11605,7 +12045,7 @@ msgstr "" "específiques del proveïdor IPA." #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-ipa.5.xml:993 +#: sssd-ipa.5.xml:988 #, no-wrap msgid "" "[domain/example.com]\n" @@ -12320,27 +12760,27 @@ msgid "lxdm" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:694 +#: sssd-ad.5.xml:699 msgid "sddm" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:699 +#: sssd-ad.5.xml:704 msgid "unity" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:704 +#: sssd-ad.5.xml:709 msgid "xdm" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:713 +#: sssd-ad.5.xml:718 msgid "ad_gpo_map_remote_interactive (string)" msgstr "ad_gpo_map_remote_interactive (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:716 +#: sssd-ad.5.xml:721 msgid "" "A comma-separated list of PAM service names for which GPO-based access " "control is evaluated based on the RemoteInteractiveLogonRight and " @@ -12356,7 +12796,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:735 +#: sssd-ad.5.xml:740 msgid "" "Note: Using the Group Policy Management Editor this value is called \"Allow " "log on through Remote Desktop Services\" and \"Deny log on through Remote " @@ -12364,7 +12804,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:750 +#: sssd-ad.5.xml:755 #, no-wrap msgid "" "ad_gpo_map_remote_interactive = +my_pam_service, -sshd\n" @@ -12374,7 +12814,7 @@ msgstr "" " " #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:741 +#: sssd-ad.5.xml:746 msgid "" "It is possible to add another PAM service name to the default set by using " "<quote>+service_name</quote> or to explicitly remove a PAM service name from " @@ -12386,22 +12826,22 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:758 +#: sssd-ad.5.xml:763 msgid "sshd" msgstr "sshd" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:763 +#: sssd-ad.5.xml:768 msgid "cockpit" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:772 +#: sssd-ad.5.xml:777 msgid "ad_gpo_map_network (string)" msgstr "ad_gpo_map_network (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:775 +#: sssd-ad.5.xml:780 msgid "" "A comma-separated list of PAM service names for which GPO-based access " "control is evaluated based on the NetworkLogonRight and " @@ -12417,7 +12857,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:793 +#: sssd-ad.5.xml:798 msgid "" "Note: Using the Group Policy Management Editor this value is called \"Access " "this computer from the network\" and \"Deny access to this computer from the " @@ -12425,7 +12865,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:808 +#: sssd-ad.5.xml:813 #, no-wrap msgid "" "ad_gpo_map_network = +my_pam_service, -ftp\n" @@ -12435,7 +12875,7 @@ msgstr "" " " #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:799 +#: sssd-ad.5.xml:804 msgid "" "It is possible to add another PAM service name to the default set by using " "<quote>+service_name</quote> or to explicitly remove a PAM service name from " @@ -12447,22 +12887,22 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:816 +#: sssd-ad.5.xml:821 msgid "ftp" msgstr "ftp" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:821 +#: sssd-ad.5.xml:826 msgid "samba" msgstr "samba" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:830 +#: sssd-ad.5.xml:835 msgid "ad_gpo_map_batch (string)" msgstr "ad_gpo_map_batch (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:833 +#: sssd-ad.5.xml:838 msgid "" "A comma-separated list of PAM service names for which GPO-based access " "control is evaluated based on the BatchLogonRight and DenyBatchLogonRight " @@ -12477,14 +12917,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:851 +#: sssd-ad.5.xml:856 msgid "" "Note: Using the Group Policy Management Editor this value is called \"Allow " "log on as a batch job\" and \"Deny log on as a batch job\"." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:865 +#: sssd-ad.5.xml:870 #, no-wrap msgid "" "ad_gpo_map_batch = +my_pam_service, -crond\n" @@ -12494,7 +12934,7 @@ msgstr "" " " #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:856 +#: sssd-ad.5.xml:861 msgid "" "It is possible to add another PAM service name to the default set by using " "<quote>+service_name</quote> or to explicitly remove a PAM service name from " @@ -12506,23 +12946,23 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:868 +#: sssd-ad.5.xml:873 msgid "" "Note: Cron service name may differ depending on Linux distribution used." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:874 +#: sssd-ad.5.xml:879 msgid "crond" msgstr "crond" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:883 +#: sssd-ad.5.xml:888 msgid "ad_gpo_map_service (string)" msgstr "ad_gpo_map_service (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:886 +#: sssd-ad.5.xml:891 msgid "" "A comma-separated list of PAM service names for which GPO-based access " "control is evaluated based on the ServiceLogonRight and " @@ -12538,14 +12978,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:904 +#: sssd-ad.5.xml:909 msgid "" "Note: Using the Group Policy Management Editor this value is called \"Allow " "log on as a service\" and \"Deny log on as a service\"." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:917 +#: sssd-ad.5.xml:922 #, no-wrap msgid "" "ad_gpo_map_service = +my_pam_service\n" @@ -12555,7 +12995,7 @@ msgstr "" " " #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:909 sssd-ad.5.xml:984 +#: sssd-ad.5.xml:914 sssd-ad.5.xml:989 msgid "" "It is possible to add a PAM service name to the default set by using " "<quote>+service_name</quote>. Since the default set is empty, it is not " @@ -12566,19 +13006,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:927 +#: sssd-ad.5.xml:932 msgid "ad_gpo_map_permit (string)" msgstr "ad_gpo_map_permit (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:930 +#: sssd-ad.5.xml:935 msgid "" "A comma-separated list of PAM service names for which GPO-based access is " "always granted, regardless of any GPO Logon Rights." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:944 +#: sssd-ad.5.xml:949 #, no-wrap msgid "" "ad_gpo_map_permit = +my_pam_service, -sudo\n" @@ -12588,7 +13028,7 @@ msgstr "" " " #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:935 +#: sssd-ad.5.xml:940 msgid "" "It is possible to add another PAM service name to the default set by using " "<quote>+service_name</quote> or to explicitly remove a PAM service name from " @@ -12600,29 +13040,29 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:952 +#: sssd-ad.5.xml:957 msgid "polkit-1" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:967 +#: sssd-ad.5.xml:972 msgid "systemd-user" msgstr "systemd-user" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:976 +#: sssd-ad.5.xml:981 msgid "ad_gpo_map_deny (string)" msgstr "ad_gpo_map_deny (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:979 +#: sssd-ad.5.xml:984 msgid "" "A comma-separated list of PAM service names for which GPO-based access is " "always denied, regardless of any GPO Logon Rights." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:992 +#: sssd-ad.5.xml:997 #, no-wrap msgid "" "ad_gpo_map_deny = +my_pam_service\n" @@ -12632,12 +13072,12 @@ msgstr "" " " #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:1002 +#: sssd-ad.5.xml:1007 msgid "ad_gpo_default_right (string)" msgstr "ad_gpo_default_right (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1005 +#: sssd-ad.5.xml:1010 msgid "" "This option defines how access control is evaluated for PAM service names " "that are not explicitly listed in one of the ad_gpo_map_* options. This " @@ -12650,52 +13090,52 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1018 +#: sssd-ad.5.xml:1023 msgid "Supported values for this option include:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1027 +#: sssd-ad.5.xml:1032 msgid "remote_interactive" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1032 +#: sssd-ad.5.xml:1037 msgid "network" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1037 +#: sssd-ad.5.xml:1042 msgid "batch" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1042 +#: sssd-ad.5.xml:1047 msgid "service" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1047 +#: sssd-ad.5.xml:1052 msgid "permit" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1052 +#: sssd-ad.5.xml:1057 msgid "deny" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1058 +#: sssd-ad.5.xml:1063 msgid "Default: deny" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:1064 +#: sssd-ad.5.xml:1069 msgid "ad_maximum_machine_account_password_age (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1067 +#: sssd-ad.5.xml:1072 msgid "" "SSSD will check once a day if the machine account password is older than the " "given age in days and try to renew it. A value of 0 will disable the renewal " @@ -12703,17 +13143,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1073 +#: sssd-ad.5.xml:1078 msgid "Default: 30 days" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:1079 +#: sssd-ad.5.xml:1084 msgid "ad_machine_account_password_renewal_opts (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1082 +#: sssd-ad.5.xml:1087 msgid "" "This option should only be used to test the machine account renewal task. " "The option expects 3 integers and a string separated by a colon (':'). The " @@ -12726,20 +13166,20 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1096 +#: sssd-ad.5.xml:1101 msgid "" "The optional fourth string value identifies the helper binary which should " "be used for the renewal. Currently <command>adcli</command> and " "<command>realm</command> are supported. If this value is missing or empty in " "the value string <command>realm</command> will be used. Since the helper is " "started as the user SSSD is running as there might be the chance that the " -"renewal will fail if this user does not has permissions to modify the keytab " -"file where the machine account credentials are stored. This will typically " -"be the case for <command>adcli</command>." +"renewal will fail if this user does not have permissions to modify the " +"keytab file where the machine account credentials are stored. This will " +"typically be the case for <command>adcli</command>." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1110 +#: sssd-ad.5.xml:1115 msgid "" "<command>realm</command> is not updating the keytab directly but is calling " "the <command>realmd</command> process, which runs as root user, for this " @@ -12749,17 +13189,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1119 +#: sssd-ad.5.xml:1124 msgid "Default: 86400:750:300:realm (24h, 12m30s and 5m)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:1125 +#: sssd-ad.5.xml:1130 msgid "ad_update_samba_machine_account_password (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1128 +#: sssd-ad.5.xml:1133 msgid "" "If enabled, when SSSD renews the machine account password, it will also be " "updated in Samba's database. This prevents Samba's copy of the machine " @@ -12768,23 +13208,25 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:1141 -msgid "ad_use_ldaps (bool)" -msgstr "" +#: sssd-ad.5.xml:1146 +#, fuzzy +#| msgid "ldap_id_use_start_tls (boolean)" +msgid "ad_use_ldaps (boolean)" +msgstr "ldap_id_use_start_tls (booleà)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1144 +#: sssd-ad.5.xml:1149 msgid "" "By default SSSD uses the plain LDAP port 389 and the Global Catalog port " -"3628. If this option is set to True SSSD will use the LDAPS port 636 and " -"Global Catalog port 3629 with LDAPS protection. Since AD does not allow to " +"3268. If this option is set to True SSSD will use the LDAPS port 636 and " +"Global Catalog port 3269 with LDAPS protection. Since AD does not allow to " "have multiple encryption layers on a single connection and we still want to " "use SASL/GSSAPI or SASL/GSS-SPNEGO for authentication the SASL security " "property maxssf is set to 0 (zero) for those connections." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1164 +#: sssd-ad.5.xml:1169 msgid "" "Optional. This option tells SSSD to automatically update the Active " "Directory DNS server with the IP address of this client. The update is " @@ -12802,30 +13244,21 @@ msgstr "Per defecte: 3600 (segons)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:1216 msgid "" -"NOTE: While it is still possible to use the old <emphasis>ipa_dyndns_iface</" -"emphasis> option, users should migrate to using <emphasis>dyndns_iface</" -"emphasis> in their config file." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1222 -msgid "" "Default: Use the IP addresses of the interface which is used for AD LDAP " "connection" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1258 +#: sssd-ad.5.xml:1252 msgid "" "How often should the back end perform periodic DNS update in addition to the " -"automatic update performed when the back end goes online. This option is " -"optional and applicable only when dyndns_update is true. Note that the " -"lowest possible value is 60 seconds in-case if value is provided less than " -"60, parameter will assume lowest value only." +"automatic update performed when the back end goes online. This is optional " +"and applicable only when dyndns_update is true. Note that the minimum value " +"is 60 seconds, any specified value below this threshold will default to 60." msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ad.5.xml:1472 +#: sssd-ad.5.xml:1465 msgid "" "The following example assumes that SSSD is correctly configured and " "example.com is one of the domains in the <replaceable>[sssd]</replaceable> " @@ -12833,7 +13266,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-ad.5.xml:1479 +#: sssd-ad.5.xml:1472 #, no-wrap msgid "" "[domain/EXAMPLE]\n" @@ -12857,7 +13290,7 @@ msgstr "" "ad_domain = exemple.com\n" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-ad.5.xml:1499 +#: sssd-ad.5.xml:1492 #, no-wrap msgid "" "access_provider = ldap\n" @@ -12869,7 +13302,7 @@ msgstr "" "ldap_account_expire_policy = ad\n" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ad.5.xml:1495 +#: sssd-ad.5.xml:1488 msgid "" "The AD access control provider checks if the account is expired. It has the " "same effect as the following configuration of the LDAP provider: " @@ -12877,7 +13310,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ad.5.xml:1505 +#: sssd-ad.5.xml:1498 msgid "" "However, unless the <quote>ad</quote> access control provider is explicitly " "configured, the default access provider is <quote>permit</quote>. Please " @@ -12887,7 +13320,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ad.5.xml:1513 +#: sssd-ad.5.xml:1506 msgid "" "When the autofs provider is set to <quote>ad</quote>, the RFC2307 schema " "attribute mapping (nisMap, nisObject, ...) is used, because these attributes " @@ -13062,9 +13495,9 @@ msgstr "" #: sssd-sudo.5.xml:137 msgid "" "The <emphasis>smart refresh</emphasis> periodically downloads rules that are " -"new or were modified after the last update. Its primary goal is to keep the " -"database growing by fetching only small increments that do not generate " -"large amounts of network traffic." +"new or were modified after the last update. Its primary goal is to grow the " +"database incrementally by fetching only small updates, avoiding large " +"amounts of network traffic." msgstr "" #. type: Content of: <reference><refentry><refsect1><para> @@ -13264,26 +13697,29 @@ msgstr "" msgid "" "Depending on the IdP product additional platform specific options might " "follow the name separated by a colon (:). E.g. for Keycloak the base URI for " -"the user and group REST API must be given. For Entra ID this is not needed " -"because there is a generic endpoint for all tenants." +"the user and group REST API must be given. For Entra ID the base URI for the " +"Microsoft Graph API can be given to use sovereign or government cloud " +"endpoints instead of the default (https://graph.microsoft.com/v1.0). E.g. " +"<quote>entra_id:https://graph.microsoft.us/v1.0</quote> for the US " +"government cloud (GCC High)." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:78 sssd-idp.5.xml:94 sssd-idp.5.xml:119 +#: sssd-idp.5.xml:82 sssd-idp.5.xml:98 sssd-idp.5.xml:123 #, fuzzy #| msgid "Default: Not set" msgid "Default: Not set (Required)" msgstr "Per defecte: Sense establir" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:83 +#: sssd-idp.5.xml:87 #, fuzzy #| msgid "ldap_user_uuid (string)" msgid "idp_client_id (string)" msgstr "ldap_user_uuid (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:86 +#: sssd-idp.5.xml:90 msgid "" "ID of the IdP client used by SSSD to authenticate users and as a client to " "lookup user and group attributes. This client must offer device " @@ -13292,14 +13728,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:99 +#: sssd-idp.5.xml:103 #, fuzzy #| msgid "ldap_tls_cert (string)" msgid "idp_client_secret (string)" msgstr "ldap_tls_cert (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:102 +#: sssd-idp.5.xml:106 msgid "" "Password of the IdP client. The password is required for the id_provider. If " "only used as auth_provider it depends on the server side configuration if it " @@ -13307,76 +13743,83 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:113 +#: sssd-idp.5.xml:117 #, fuzzy #| msgid "ipa_domain (string)" msgid "idp_token_endpoint (string)" msgstr "ipa_domain (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:116 +#: sssd-idp.5.xml:120 msgid "IdP endpoint for requesting access tokens." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:124 +#: sssd-idp.5.xml:128 #, fuzzy #| msgid "ldap_service_port (string)" msgid "idp_device_auth_endpoint (string)" msgstr "ldap_service_port (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:127 +#: sssd-idp.5.xml:131 msgid "" "IdP endpoint for device authorization according to RFC-8628. This is " "required for user authentication." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:137 +#: sssd-idp.5.xml:141 #, fuzzy #| msgid "ldap_service_port (string)" msgid "idp_userinfo_endpoint (string)" msgstr "ldap_service_port (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:140 +#: sssd-idp.5.xml:144 msgid "" "IdP userinfo endpoint to request user attributes after a successful " "authentication of the user. Required for authentication." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:150 +#: sssd-idp.5.xml:154 #, fuzzy #| msgid "id_provider (string)" msgid "idp_id_scope (string)" msgstr "id_provider (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:153 +#: sssd-idp.5.xml:157 msgid "" "Scope required for looking up user and group attributes with the REST API. " "The scopes are used by the server to determine which attributes/claims are " "returned to the caller." msgstr "" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:163 +msgid "" +"Note: In previous versions of SSSD, this option was expected to already be " +"URL-encoded." +msgstr "" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:164 +#: sssd-idp.5.xml:172 #, fuzzy #| msgid "dyndns_iface (string)" msgid "idp_auth_scope (string)" msgstr "dyndns_iface (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:167 +#: sssd-idp.5.xml:175 msgid "" "Scope required during authentication. The scopes are used by the server to " "determine which attributes/claims are returned to the caller." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:172 +#: sssd-idp.5.xml:180 msgid "" "Currently the tokens returned during user authentication are not used for " "other purposes hence the only important claim is the subject identifier " @@ -13385,26 +13828,124 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:185 +#: sssd-idp.5.xml:193 +#, fuzzy +#| msgid "ldap_user_extra_attrs (string)" +msgid "idp_auth_user_identifier_attr (string)" +msgstr "ldap_user_extra_attrs (cadena)" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:196 +msgid "" +"Attribute used to identify the authenticated user in userinfo data or token " +"claims." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:200 +msgid "" +"For hybrid Active Directory and Entra ID deployments where " +"<quote>id_provider = ad</quote> and <quote>auth_provider = idp</quote>, this " +"option must be set explicitly. No value is derived from the identity " +"provider, because more than one attribute can link an Entra ID object to its " +"on-premises counterpart and only the administrator knows which one the " +"directory synchronization is configured to use." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:211 +msgid "" +"Setting this option to <quote>onPremisesImmutableId</quote> is the usual " +"choice for such deployments. Microsoft Entra Connect populates that " +"attribute with the base64-encoded form of the 16-byte Active Directory " +"<quote>objectGUID</quote> when objectGUID is used as the sourceAnchor. SSSD " +"decodes the value and converts the raw bytes with the same conversion used " +"for AD objectGUID attributes, so the result matches the UUID stored in the " +"SSSD cache for the AD user." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:224 +msgid "" +"Note that Microsoft Entra Connect 1.1.524.0 and later use <quote>ms-DS-" +"ConsistencyGuid</quote> as the sourceAnchor for user objects instead of " +"<quote>objectGUID</quote>. The value is normally copied from objectGUID for " +"objects that do not have it set yet, in which case the decoded identifier " +"still matches. It does not match if ms-DS-ConsistencyGuid was populated " +"independently, if users were moved between forests or domains, or if a " +"different attribute such as employeeID was selected as the sourceAnchor. See " +"<ulink url=\"https://learn.microsoft.com/en-us/entra/identity/hybrid/connect/" +"plan-connect-design-concepts\"> Microsoft Entra Connect: Design concepts</" +"ulink> for details on sourceAnchor selection." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:241 +msgid "" +"Microsoft Graph does not return <quote>onPremisesImmutableId</quote> by " +"default. The <quote>idp_userinfo_endpoint</quote> must request it with " +"<quote>$select</quote>, see the example below and <ulink url=\"https://" +"learn.microsoft.com/en-us/graph/api/resources/user\"> the Microsoft Graph " +"user resource type</ulink>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:251 +msgid "" +"If the configured attribute is missing or cannot be decoded (for example " +"cloud-only Entra ID users without <quote>onPremisesImmutableId</quote>), " +"authentication fails. SSSD does not fall back to another attribute when this " +"option is set." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:258 +msgid "" +"Default: not set, <quote>sub</quote> for Keycloak and <quote>id</quote> for " +"other IdP types" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-idp.5.xml:264 #, fuzzy #| msgid "ldap_opt_timeout (integer)" msgid "idp_request_timeout (integer)" msgstr "ldap_opt_timeout (enter)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:188 +#: sssd-idp.5.xml:267 msgid "Timeout in seconds for an individual request to the IdP." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:197 +#: sssd-idp.5.xml:276 +#, fuzzy +#| msgid "ldap_referrals (boolean)" +msgid "idp_auto_refresh (boolean)" +msgstr "ldap_referrals (booleà)" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:279 +msgid "" +"Refresh tokens automatically, after they have reached about half their " +"lifetime." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:283 +msgid "" +"Note: Scheduled token refreshes are not preserved across restarts of SSSD." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-idp.5.xml:292 #, fuzzy #| msgid "ldap_idmap_range_min (integer)" msgid "idmap_range_min (integer)" msgstr "ldap_idmap_range_min (enter)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:200 +#: sssd-idp.5.xml:295 msgid "" "Specifies the lower (inclusive) bound of the range of POSIX IDs to use for " "mapping IdP users and group to POSIX IDs. It is the first POSIX ID which can " @@ -13412,7 +13953,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:206 +#: sssd-idp.5.xml:301 msgid "" "The interval between <quote>idmap_range_min</quote> and " "<quote>idmap_range_max</quote> will be split into smaller ranges of size " @@ -13421,20 +13962,20 @@ msgid "" msgstr "" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:213 sssd-idp.5.xml:239 include/ldap_id_mapping.xml:139 +#: sssd-idp.5.xml:308 sssd-idp.5.xml:334 include/ldap_id_mapping.xml:139 #: include/ldap_id_mapping.xml:197 msgid "Default: 200000" msgstr "Per defecte: 200000" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:218 +#: sssd-idp.5.xml:313 #, fuzzy #| msgid "ldap_idmap_range_max (integer)" msgid "idmap_range_max (integer)" msgstr "ldap_idmap_range_max (enter)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:221 +#: sssd-idp.5.xml:316 msgid "" "Specifies the upper (exclusive) bound of the range of POSIX IDs to use for " "mapping IdP users and groups to POSIX IDs. It is the first POSIX ID which " @@ -13442,47 +13983,70 @@ msgid "" msgstr "" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:227 include/ldap_id_mapping.xml:165 +#: sssd-idp.5.xml:322 include/ldap_id_mapping.xml:165 msgid "Default: 2000200000" msgstr "Per defecte: 2000200000" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:232 +#: sssd-idp.5.xml:327 #, fuzzy #| msgid "ldap_idmap_range_size (integer)" msgid "idmap_range_size (integer)" msgstr "ldap_idmap_range_size (enter)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:235 +#: sssd-idp.5.xml:330 msgid "Specifies the number of POSIX IDs available for a single IdP domain." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-idp.5.xml:251 +#: sssd-idp.5.xml:346 #, no-wrap msgid "" "[domain/entra_id]\n" "id_provider = idp\n" "idp_type = entra_id\n" "idp_client_id = 12345678-abcd-0101-efef-ba9876543210\n" -"idp_client_secret = YOUR-CLIENT-SCERET\n" -"idp_token_endpoint = https://login.microsoftonline.com/TENNANT-ID/oauth2/v2.0/token\n" +"idp_client_secret = YOUR-CLIENT-SECRET\n" +"idp_token_endpoint = https://login.microsoftonline.com/TENANT-ID/oauth2/v2.0/token\n" "idp_userinfo_endpoint = https://graph.microsoft.com/v1.0/me\n" -"idp_device_auth_endpoint = https://login.microsoftonline.com/TENNANT-ID/oauth2/v2.0/devicecode\n" -"idp_id_scope = https%3A%2F%2Fgraph.microsoft.com%2F.default\n" +"idp_device_auth_endpoint = https://login.microsoftonline.com/TENANT-ID/oauth2/v2.0/devicecode\n" +"idp_id_scope = https://graph.microsoft.com/.default\n" +"idp_auth_scope = openid profile email\n" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><programlisting> +#: sssd-idp.5.xml:358 +#, no-wrap +msgid "" +"[domain/ad.example.com]\n" +"id_provider = ad\n" +"auth_provider = idp\n" +"access_provider = permit\n" +"\n" +"ad_domain = ad.example.com\n" +"krb5_realm = AD.EXAMPLE.COM\n" +"\n" +"idp_type = entra_id\n" +"idp_client_id = 12345678-abcd-0101-efef-ba9876543210\n" +"idp_client_secret = YOUR-CLIENT-SECRET\n" +"idp_token_endpoint = https://login.microsoftonline.com/TENANT-ID/oauth2/v2.0/token\n" +"idp_userinfo_endpoint = https://graph.microsoft.com/v1.0/me?$select=id,userPrincipalName,onPremisesImmutableId\n" +"idp_device_auth_endpoint = https://login.microsoftonline.com/TENANT-ID/oauth2/v2.0/devicecode\n" +"idp_id_scope = https://graph.microsoft.com/.default\n" "idp_auth_scope = openid profile email\n" +"idp_auth_user_identifier_attr = onPremisesImmutableId\n" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-idp.5.xml:263 +#: sssd-idp.5.xml:377 #, no-wrap msgid "" "[domain/keycloak]\n" "idp_type = keycloak:https://master.keycloak.test:8443/auth/admin/realms/master/\n" "id_provider = idp\n" "idp_client_id = myclient\n" -"idp_client_secret = YOUR-CLIENT-SCERET\n" +"idp_client_secret = YOUR-CLIENT-SECRET\n" "idp_token_endpoint = https://master.keycloak.test:8443/auth/realms/master/protocol/openid-connect/token\n" "idp_userinfo_endpoint = https://master.keycloak.test:8443/auth/realms/master/protocol/openid-connect/userinfo\n" "idp_device_auth_endpoint = https://master.keycloak.test:8443/auth/realms/master/protocol/openid-connect/auth/device\n" @@ -13491,14 +14055,26 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-idp.5.xml:250 +#: sssd-idp.5.xml:345 #, fuzzy #| msgid "example: <placeholder type=\"programlisting\" id=\"0\"/>" msgid "" "<placeholder type=\"programlisting\" id=\"0\"/> <placeholder " -"type=\"programlisting\" id=\"1\"/>" +"type=\"programlisting\" id=\"1\"/> <placeholder type=\"programlisting\" " +"id=\"2\"/>" msgstr "exemple: <placeholder type=\"programlisting\" id=\"0\"/>" +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-idp.5.xml:390 +msgid "" +"In the hybrid Active Directory and Entra ID example above, " +"<quote>onPremisesImmutableId</quote> is used during authentication so the " +"IdP result matches the AD objectGUID UUID stored in the SSSD cache. The " +"attribute must be requested via <quote>$select</quote> on the Graph userinfo " +"endpoint and is only populated for users synchronized from Active Directory " +"with objectGUID as the sourceAnchor." +msgstr "" + #. type: Content of: <reference><refentry><refnamediv><refname> #: sssd.8.xml:10 sssd.8.xml:15 msgid "sssd" @@ -14524,7 +15100,7 @@ msgstr "" #: sssd-krb5.5.xml:291 msgid "" "<emphasis>demand</emphasis> to use FAST. The authentication fails if the " -"server does not require fast." +"server does not support FAST." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> @@ -15566,7 +16142,9 @@ msgstr "Atributs de configuració" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sss_rpcidmapd.5.xml:69 -msgid "memcache (bool)" +#, fuzzy +#| msgid "memcache (bool)" +msgid "memcache (boolean)" msgstr "memcache (booleà)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> @@ -15639,7 +16217,7 @@ msgstr "" "sss. <placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <refsect1><title> -#: sss_rpcidmapd.5.xml:120 sssd-kcm.8.xml:316 include/seealso.xml:2 +#: sss_rpcidmapd.5.xml:120 sssd-kcm.8.xml:315 include/seealso.xml:2 msgid "SEE ALSO" msgstr "VEGEU TAMBÉ" @@ -15901,8 +16479,8 @@ msgstr "" #: sss_ssh_knownhosts.1.xml:93 msgid "" "The key lines retrieved from the backend are expected to respect the key " -"format as decribed in the <quote>SSH_KNOWN_HOSTS FILE FORMAT</quote> section " -"of <citerefentry><refentrytitle>sshd</refentrytitle> <manvolnum>8</" +"format as described in the <quote>SSH_KNOWN_HOSTS FILE FORMAT</quote> " +"section of <citerefentry><refentrytitle>sshd</refentrytitle> <manvolnum>8</" "manvolnum></citerefentry>. However, returning only the keytype and the key " "itself is tolerated, in which case, the hostname received as parameter will " "be added before the keytype to output a correctly formatted line. The " @@ -16377,15 +16955,22 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-kcm.8.xml:215 +#, fuzzy +#| msgid "" +#| "<quote>krb5</quote> for Kerberos authentication. See <citerefentry> " +#| "<refentrytitle>sssd-krb5</refentrytitle> <manvolnum>5</manvolnum> </" +#| "citerefentry> for more information on configuring Kerberos." msgid "" -"The KCM service is configured in the <quote>kcm</quote> For a detailed " -"syntax reference, refer to the <quote>FILE FORMAT</quote> section of the " -"<citerefentry> <refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</" -"manvolnum> </citerefentry> manual page." +"For a detailed syntax reference, refer to the <quote>FILE FORMAT</quote> " +"section of the <citerefentry> <refentrytitle>sssd.conf</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry> manual page." msgstr "" +"<quote>krb5</quote> per a l'autenticació Kerberos. Vegeu " +"<citerefentry><refentrytitle>sssd-krb5</refentrytitle> <manvolnum>5</" +"manvolnum></citerefentry> per a més informació sobre configurar Kerberos." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-kcm.8.xml:223 +#: sssd-kcm.8.xml:222 msgid "" "The generic SSSD service options such as <quote>debug_level</quote> or " "<quote>fd_limit</quote> are accepted by the kcm service. Please refer to " @@ -16395,22 +16980,22 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:234 +#: sssd-kcm.8.xml:233 msgid "socket_path (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:237 +#: sssd-kcm.8.xml:236 msgid "The socket the KCM service will listen on." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:240 +#: sssd-kcm.8.xml:239 msgid "Default: <replaceable>/var/run/.heim_org.h5l.kcm-socket</replaceable>" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:243 +#: sssd-kcm.8.xml:242 msgid "" "<phrase condition=\"have_systemd\"> Note: on platforms where systemd is " "supported, the socket path is overwritten by the one defined in the sssd-" @@ -16418,94 +17003,94 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:252 +#: sssd-kcm.8.xml:251 msgid "max_ccaches (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:255 +#: sssd-kcm.8.xml:254 msgid "How many credential caches does the KCM database allow for all users." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:259 +#: sssd-kcm.8.xml:258 msgid "Default: 0 (unlimited, only the per-UID quota is enforced)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:264 +#: sssd-kcm.8.xml:263 msgid "max_uid_ccaches (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:267 +#: sssd-kcm.8.xml:266 msgid "" "How many credential caches does the KCM database allow per UID. This is " "equivalent to <quote>with how many principals you can kinit</quote>." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:272 +#: sssd-kcm.8.xml:271 msgid "Default: 64" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:277 +#: sssd-kcm.8.xml:276 msgid "max_ccache_size (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:280 +#: sssd-kcm.8.xml:279 msgid "" -"How big can a credential cache be per ccache. Each service ticket accounts " -"into this quota." +"How big a credential cache be per ccache. Each service ticket counts toward " +"this quota." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:284 +#: sssd-kcm.8.xml:283 msgid "Default: 65536" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:289 +#: sssd-kcm.8.xml:288 #, fuzzy #| msgid "enumerate (bool)" -msgid "tgt_renewal (bool)" +msgid "tgt_renewal (boolean)" msgstr "enumerate (booleà)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:292 +#: sssd-kcm.8.xml:291 msgid "Enables TGT renewals functionality." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:295 +#: sssd-kcm.8.xml:294 #, fuzzy #| msgid "Default: False (disabled)" msgid "Default: False (Automatic renewals disabled)" msgstr "Per defecte: False (inhabilitat)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:300 +#: sssd-kcm.8.xml:299 #, fuzzy #| msgid "krb5_renew_interval (string)" msgid "tgt_renewal_inherit (string)" msgstr "krb5_renew_interval (cadena)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:303 +#: sssd-kcm.8.xml:302 msgid "Domain to inherit krb5_* options from, for use with TGT renewals." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:307 +#: sssd-kcm.8.xml:306 #, fuzzy #| msgid "Default: 3" msgid "Default: NULL" msgstr "Per defecte: 3" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-kcm.8.xml:318 +#: sssd-kcm.8.xml:317 msgid "" "<citerefentry> <refentrytitle>sssd</refentrytitle><manvolnum>8</manvolnum> </" "citerefentry>, <citerefentry> <refentrytitle>sssd.conf</" @@ -17442,9 +18027,9 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap-attributes.5.xml:381 sssd-ldap-attributes.5.xml:395 -msgid "Default: loginDisabled" -msgstr "Per defecte: loginDisabled" +#: sssd-ldap-attributes.5.xml:381 +msgid "Default: loginDisabled (rfc2307, rfc2307bis and IPA), not set (AD)" +msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:387 @@ -17458,6 +18043,12 @@ msgid "" "which date access is granted." msgstr "" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:395 +msgid "" +"Default: loginExpirationTime (rfc2307, rfc2307bis and IPA), not set (AD)" +msgstr "" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:401 msgid "ldap_user_nds_login_allowed_time_map (string)" @@ -17472,8 +18063,9 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:409 -msgid "Default: loginAllowedTimeMap" -msgstr "Per defecte: loginAllowedTimeMap" +msgid "" +"Default: loginAllowedTimeMap (rfc2307, rfc2307bis and IPA), not set (AD)" +msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:415 @@ -17998,9 +18590,9 @@ msgid "The object class of a host entry in LDAP." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap-attributes.5.xml:900 sssd-ldap-attributes.5.xml:997 -msgid "Default: ipService" -msgstr "Per defecte: ipService" +#: sssd-ldap-attributes.5.xml:900 sssd-ldap-attributes.5.xml:1213 +msgid "Default: ipHost" +msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:906 @@ -18084,6 +18676,11 @@ msgstr "ldap_service_object_class (cadena)" msgid "The object class of a service entry in LDAP." msgstr "" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:997 +msgid "Default: ipService" +msgstr "Per defecte: ipService" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1003 msgid "ldap_service_name (string)" @@ -18324,11 +18921,6 @@ msgstr "" msgid "The object class of an iphost entry in LDAP." msgstr "" -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap-attributes.5.xml:1213 -msgid "Default: ipHost" -msgstr "" - #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1219 msgid "ldap_iphost_name (string)" @@ -18578,6 +19170,7 @@ msgstr "FITXER DE CONFIGURACIÓ" msgid "" "[plugins]\n" " localauth = {\n" +" disable = an2ln\n" " module = sssd:/usr/lib64/sssd/modules/sssd_krb5_localauth_plugin.so\n" " }\n" msgstr "" @@ -18594,6 +19187,28 @@ msgid "" "the local Kerberos configuration the plugin will be enabled automatically." msgstr "" +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_localauth_plugin.8.xml:67 +msgid "" +"This configuration snippet also disables the <command>an2ln</command> module " +"provided by MIT Kerberos if SSSD is configured to use the AD or IPA " +"provider. In those environments <command>sssd_krb5_localauth_plugin</" +"command> can reliably map the system user names to Kerberos principals. A " +"fallback to <command>an2ln</command> might cause issues in environments " +"where users have the privilege to create Kerberos principals on their own " +"which might collide with names of other users used in the system. Other " +"modules provided by MIT Kerberos, e.g. <command>k5login</command> are not " +"affected." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_localauth_plugin.8.xml:79 +msgid "" +"Note: If using <quote>auth_provider = krb5</quote> then " +"<command>sssd_krb5_localauth_plugin</command> is not used, therefore the " +"above text is not applicable." +msgstr "" + #. type: Content of: <variablelist><varlistentry><term> #: include/autofs_attributes.xml:3 msgid "ldap_autofs_map_object_class (string)" @@ -19497,40 +20112,6 @@ msgid "" "failures; corresponds to setting 2 in decimal notation)" msgstr "" -#. type: Content of: <refsect1><title> -#: include/local.xml:2 -msgid "THE LOCAL DOMAIN" -msgstr "EL DOMINI LOCAL" - -#. type: Content of: <refsect1><para> -#: include/local.xml:4 -msgid "" -"In order to function correctly, a domain with <quote>id_provider=local</" -"quote> must be created and the SSSD must be running." -msgstr "" -"Per a un funcionament correcte, s'ha de crear un domini amb <quote>" -"id_provider=local</quote> i l'SSSD ha d'estar en execució." - -#. type: Content of: <refsect1><para> -#: include/local.xml:9 -msgid "" -"The administrator might want to use the SSSD local users instead of " -"traditional UNIX users in cases where the group nesting (see <citerefentry> " -"<refentrytitle>sss_groupadd</refentrytitle> <manvolnum>8</manvolnum> </" -"citerefentry>) is needed. The local users are also useful for testing and " -"development of the SSSD without having to deploy a full remote server. The " -"<command>sss_user*</command> and <command>sss_group*</command> tools use a " -"local LDB storage to store users and groups." -msgstr "" -"L'administrador pot ser que vulgui utilitzar els usuaris locals de l'SSSD en " -"lloc dels usuaris tradicionals d'UNIX en els casos en què es requereixi la " -"imbricació dels grups (vegeu <citerefentry> <refentrytitle>sss_groupadd</" -"refentrytitle> <manvolnum>8</manvolnum> </citerefentry>). Els usuaris locals " -"també són útils per provar i desplegar l'SSSD sense haver de desplegar tot " -"un servidor remot. Les eines <command>sss_user*</command> i <command>" -"sss_group*</command> utilitzen l'emmagatzematge LDB local per emmagatzemar " -"els usuaris i els grups." - #. type: Content of: <refsect1><para> #: include/seealso.xml:4 msgid "" @@ -20144,6 +20725,65 @@ msgid "" "feature is available with MIT Kerberos 1.7 and later versions." msgstr "" +#~ msgid "" +#~ "The data types used are string (no quotes needed), integer and bool (with " +#~ "values of <quote>TRUE/FALSE</quote>)." +#~ msgstr "" +#~ "Els tipus de dades que s'utilitzen són cadenes (no necessiten cometes), " +#~ "enters i booleans (amb valors <quote>TRUE/FALSE</quote>)." + +#~ msgid "services" +#~ msgstr "services" + +#~ msgid "domains" +#~ msgstr "domains" + +#~ msgid "fd_limit" +#~ msgstr "fd_limit" + +#~ msgid "client_idle_timeout" +#~ msgstr "client_idle_timeout" + +#~ msgid "default_shell" +#~ msgstr "default_shell" + +#~ msgid "ipa_hbac_selinux (integer)" +#~ msgstr "ipa_hbac_selinux (enter)" + +#~ msgid "Default: loginDisabled" +#~ msgstr "Per defecte: loginDisabled" + +#~ msgid "Default: loginAllowedTimeMap" +#~ msgstr "Per defecte: loginAllowedTimeMap" + +#~ msgid "THE LOCAL DOMAIN" +#~ msgstr "EL DOMINI LOCAL" + +#~ msgid "" +#~ "In order to function correctly, a domain with <quote>id_provider=local</" +#~ "quote> must be created and the SSSD must be running." +#~ msgstr "" +#~ "Per a un funcionament correcte, s'ha de crear un domini amb " +#~ "<quote>id_provider=local</quote> i l'SSSD ha d'estar en execució." + +#~ msgid "" +#~ "The administrator might want to use the SSSD local users instead of " +#~ "traditional UNIX users in cases where the group nesting (see " +#~ "<citerefentry> <refentrytitle>sss_groupadd</refentrytitle> <manvolnum>8</" +#~ "manvolnum> </citerefentry>) is needed. The local users are also useful " +#~ "for testing and development of the SSSD without having to deploy a full " +#~ "remote server. The <command>sss_user*</command> and <command>sss_group*</" +#~ "command> tools use a local LDB storage to store users and groups." +#~ msgstr "" +#~ "L'administrador pot ser que vulgui utilitzar els usuaris locals de l'SSSD " +#~ "en lloc dels usuaris tradicionals d'UNIX en els casos en què es " +#~ "requereixi la imbricació dels grups (vegeu <citerefentry> " +#~ "<refentrytitle>sss_groupadd</refentrytitle> <manvolnum>8</manvolnum> </" +#~ "citerefentry>). Els usuaris locals també són útils per provar i desplegar " +#~ "l'SSSD sense haver de desplegar tot un servidor remot. Les eines " +#~ "<command>sss_user*</command> i <command>sss_group*</command> utilitzen " +#~ "l'emmagatzematge LDB local per emmagatzemar els usuaris i els grups." + #~ msgid "subdomain_enumerate (string)" #~ msgstr "subdomain_enumerate (cadena)" @@ -20182,9 +20822,6 @@ msgstr "" #~ "Especifica una llista separada per comes dels atributs de la llista negra " #~ "o blanca." -#~ msgid "user (string)" -#~ msgstr "user (cadena)" - #~ msgid "Default: not set, process will run as root" #~ msgstr "Per defecte: sense establir, els processos s'executaran com a root" @@ -20363,9 +21000,6 @@ msgstr "" #~ "usuaris i grups a la base de dades SSSD nadiu de, és a dir, un domini que " #~ "utilitza <replaceable>id_provider = local</replaceable>." -#~ msgid "default_shell (string)" -#~ msgstr "default_shell (cadena)" - #~ msgid "The default shell for users created with SSSD userspace tools." #~ msgstr "" #~ "El shell predeterminat per als usuaris que es creen amb eines de l'espai " @@ -20374,9 +21008,6 @@ msgstr "" #~ msgid "Default: <filename>/bin/bash</filename>" #~ msgstr "Per defecte: <filename>/bin/bash</filename>" -#~ msgid "base_directory (string)" -#~ msgstr "base_directory (cadena)" - #~ msgid "" #~ "The tools append the login name to <replaceable>base_directory</" #~ "replaceable> and use that as the home directory." diff --git a/src/man/po/cs.po b/src/man/po/cs.po index 2d7ddc7ebd6..5925f9aeff0 100644 --- a/src/man/po/cs.po +++ b/src/man/po/cs.po @@ -10,8 +10,8 @@ msgid "" msgstr "" "Project-Id-Version: sssd-docs 2.3.0\n" "Report-Msgid-Bugs-To: sssd-devel@redhat.com\n" -"POT-Creation-Date: 2026-01-14 15:00+0000\n" -"PO-Revision-Date: 2026-04-23 16:43+0000\n" +"POT-Creation-Date: 2026-10-05 16:14+0000\n" +"PO-Revision-Date: 2026-10-05 16:46+0000\n" "Last-Translator: Weblate Translation Memory <noreply-mt-weblate-translation-" "memory@weblate.org>\n" "Language-Team: Czech <https://translate.fedoraproject.org/projects/sssd/sssd-" @@ -21,10 +21,10 @@ msgstr "" "Content-Type: text/plain; charset=UTF-8\n" "Content-Transfer-Encoding: 8bit\n" "Plural-Forms: nplurals=3; plural=(n==1) ? 0 : (n>=2 && n<=4) ? 1 : 2;\n" -"X-Generator: Weblate 5.17\n" +"X-Generator: Weblate 2026.10\n" #. type: Content of: <reference><title> -#: sssd.conf.5.xml:8 sssd-ldap.5.xml:5 pam_sss.8.xml:5 pam_sss_gss.8.xml:5 +#: sssd.conf.5.xml:10 sssd-ldap.5.xml:5 pam_sss.8.xml:5 pam_sss_gss.8.xml:5 #: sssd_krb5_locator_plugin.8.xml:5 sssd-simple.5.xml:5 sss-certmap.5.xml:5 #: sssd-ipa.5.xml:5 sssd-ad.5.xml:5 sssd-sudo.5.xml:5 sssd-idp.5.xml:5 #: sssd.8.xml:5 sss_obfuscate.8.xml:5 sss_override.8.xml:5 sssd-krb5.5.xml:5 @@ -37,14 +37,14 @@ msgid "SSSD Manual pages" msgstr "Manuálové stránky SSSD" #. type: Content of: <reference><refentry><refnamediv><refname> -#: sssd.conf.5.xml:13 sssd.conf.5.xml:19 +#: sssd.conf.5.xml:15 sssd.conf.5.xml:21 msgid "sssd.conf" msgstr "sssd.conf" # auto translated by TM merge from project: Fedora Elections Guide, version: # master, DocId: Methods #. type: Content of: <reference><refentry><refmeta><manvolnum> -#: sssd.conf.5.xml:14 sssd-ldap.5.xml:11 sssd-simple.5.xml:11 +#: sssd.conf.5.xml:16 sssd-ldap.5.xml:11 sssd-simple.5.xml:11 #: sss-certmap.5.xml:11 sssd-ipa.5.xml:11 sssd-ad.5.xml:11 sssd-sudo.5.xml:11 #: sssd-idp.5.xml:11 sssd-krb5.5.xml:11 sssd-ifp.5.xml:11 #: sss_rpcidmapd.5.xml:27 sssd-session-recording.5.xml:11 @@ -53,7 +53,7 @@ msgid "5" msgstr "5" #. type: Content of: <reference><refentry><refmeta><refmiscinfo> -#: sssd.conf.5.xml:15 sssd-ldap.5.xml:12 sssd-simple.5.xml:12 +#: sssd.conf.5.xml:17 sssd-ldap.5.xml:12 sssd-simple.5.xml:12 #: sss-certmap.5.xml:12 sssd-ipa.5.xml:12 sssd-ad.5.xml:12 sssd-sudo.5.xml:12 #: sssd-idp.5.xml:12 sssd-krb5.5.xml:12 sssd-ifp.5.xml:12 #: sss_rpcidmapd.5.xml:28 sssd-session-recording.5.xml:12 sssd-kcm.8.xml:12 @@ -62,17 +62,17 @@ msgid "File Formats and Conventions" msgstr "Formáty souborů a konvence" #. type: Content of: <reference><refentry><refnamediv><refpurpose> -#: sssd.conf.5.xml:20 +#: sssd.conf.5.xml:22 msgid "the configuration file for SSSD" msgstr "soubor s nastaveními pro SSSD" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:24 +#: sssd.conf.5.xml:26 msgid "FILE FORMAT" msgstr "FORMÁT SOUBORU" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd.conf.5.xml:32 +#: sssd.conf.5.xml:34 #, no-wrap msgid "" "<replaceable>[section]</replaceable>\n" @@ -87,7 +87,7 @@ msgstr "" " " #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:27 +#: sssd.conf.5.xml:29 msgid "" "The file has an ini-style syntax and consists of sections and parameters. A " "section begins with the name of the section in square brackets and continues " @@ -100,16 +100,17 @@ msgstr "" "<placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:39 +#: sssd.conf.5.xml:41 msgid "" -"The data types used are string (no quotes needed), integer and bool (with " -"values of <quote>TRUE/FALSE</quote>)." +"The data types used are string (no quotes needed), integer and boolean (with " +"values of <quote>TRUE/FALSE</quote>). Boolean values are case-insensitive; " +"for example, <quote>TRUE</quote>, <quote>True</quote> and <quote>true</" +"quote> are all equivalent and valid; the same applies to <quote>FALSE</" +"quote>." msgstr "" -"Používané datové typy jsou řetězce (není třeba obklopovat uvozovkami), celá " -"čísla bolean (s hodnotami <quote>TRUE/FALSE</quote>)." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:44 +#: sssd.conf.5.xml:49 msgid "" "A comment line starts with a hash sign (<quote>#</quote>) or a semicolon " "(<quote>;</quote>). Inline comments are not supported." @@ -118,7 +119,7 @@ msgstr "" "středník (<quote>;</quote>). Komentáře v rámci řádku nejsou podporovány." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:50 +#: sssd.conf.5.xml:55 msgid "" "All sections can have an optional <replaceable>description</replaceable> " "parameter. Its function is only as a label for the section." @@ -127,7 +128,7 @@ msgstr "" "parametry. Jeho funkcí je pouze oštítkování sekce." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:56 +#: sssd.conf.5.xml:61 msgid "" "<filename>sssd.conf</filename> must be a regular file that is owned, " "readable, and writeable only by 'root'." @@ -136,7 +137,7 @@ msgstr "" "zapisuje pouze 'root'." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:60 +#: sssd.conf.5.xml:65 #, fuzzy #| msgid "" #| "<filename>sssd.conf</filename> must be a regular file that is owned, " @@ -151,12 +152,12 @@ msgstr "" "služby SSSD." #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:66 +#: sssd.conf.5.xml:71 msgid "CONFIGURATION SNIPPETS FROM INCLUDE DIRECTORY" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:69 +#: sssd.conf.5.xml:74 msgid "" "The configuration file <filename>sssd.conf</filename> will include " "configuration snippets using the include directory <filename>conf.d</" @@ -166,7 +167,7 @@ msgstr "" "konfigurace pomocí adresáře include <filename>conf.d </filename>." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:75 +#: sssd.conf.5.xml:80 msgid "" "Any file placed in <filename>conf.d</filename> that ends in " "<quote><filename>.conf</filename></quote> and does not begin with a dot " @@ -175,7 +176,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:83 +#: sssd.conf.5.xml:88 msgid "" "The configuration snippets from <filename>conf.d</filename> have higher " "priority than <filename>sssd.conf</filename> and will override " @@ -188,39 +189,88 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:97 +#: sssd.conf.5.xml:102 msgid "" "The snippet files require the same owner and permissions as " "<filename>sssd.conf</filename>." msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:103 +#: sssd.conf.5.xml:108 +msgid "VENDOR PROVIDED CONFIGURATION" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:111 +msgid "" +"The vendor provided configuration file is installed in " +"<filename>&sssd_vendor_dir;/sssd.conf</filename>, but this file must not be " +"directly edited. It can be completely masked by creating the system specific " +"configuration file <filename>&sssd_conf_dir;/sssd.conf</filename>, or partly " +"overriden by creating config snippets in <filename>&sssd_conf_dir;/conf.d</" +"filename> directory." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><title> +#: sssd.conf.5.xml:120 +msgid "CONFIGURATION FILE HIERARCHY" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:122 +msgid "" +"When sssd reads the configuration it first tries to open the system specific " +"configuration file in <filename>&sssd_conf_dir;/sssd.conf</filename>. If it " +"exists, it is loaded and snippets from <filename>&sssd_conf_dir;/conf.d</" +"filename> are applied. The vendor provided configuration file " +"<filename>&sssd_vendor_dir;/sssd.conf</filename> is completely ignored in " +"this case." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:131 +msgid "" +"If the system specific configuration file <filename>&sssd_conf_dir;/" +"sssd.conf</filename> does not exist, then the vendor configuration file " +"<filename>&sssd_vendor_dir;/sssd.conf</filename> is loaded and snippets from " +"<filename>&sssd_conf_dir;/conf.d</filename> are applied." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd.conf.5.xml:141 msgid "GENERAL OPTIONS" msgstr "OBECNÉ VOLBY" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:105 +#: sssd.conf.5.xml:143 msgid "Following options are usable in more than one configuration sections." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:109 +#: sssd.conf.5.xml:147 msgid "Options usable in all sections" msgstr "Volby použitelné ve všech sekcích" +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:149 +msgid "" +"Note: Below options are ignored in <quote>[session_recording]</quote> " +"section, see <quote>Session recording configuration options</quote> section " +"for more details." +msgstr "" + #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:113 +#: sssd.conf.5.xml:156 msgid "debug_level (integer)" msgstr "debug_level (celé kladné číslo)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:117 +#: sssd.conf.5.xml:160 msgid "debug (integer)" msgstr "debug (celé kladné číslo)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:120 +#: sssd.conf.5.xml:163 msgid "" "SSSD 1.14 and later also includes the <replaceable>debug</replaceable> alias " "for <replaceable>debug_level</replaceable> as a convenience feature. If both " @@ -229,61 +279,61 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:130 -msgid "debug_timestamps (bool)" +#: sssd.conf.5.xml:173 +msgid "debug_timestamps (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:133 +#: sssd.conf.5.xml:176 msgid "" "Add a timestamp to the debug messages. If journald is enabled for SSSD " "debug logging this option is ignored." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:138 sssd.conf.5.xml:175 sssd.conf.5.xml:337 -#: sssd.conf.5.xml:644 sssd.conf.5.xml:668 sssd.conf.5.xml:875 -#: sssd.conf.5.xml:979 sssd.conf.5.xml:2113 sssd-ldap.5.xml:979 -#: sssd-ldap.5.xml:1134 sssd-ldap.5.xml:1237 sssd-ldap.5.xml:1306 -#: sssd-ldap.5.xml:1714 sssd-ldap.5.xml:1848 sssd-ldap.5.xml:1913 -#: sssd-ipa.5.xml:346 sssd-ad.5.xml:252 sssd-ad.5.xml:367 sssd-ad.5.xml:1180 -#: sssd-ad.5.xml:1382 sssd-krb5.5.xml:358 +#: sssd.conf.5.xml:181 sssd.conf.5.xml:218 sssd.conf.5.xml:380 +#: sssd.conf.5.xml:687 sssd.conf.5.xml:711 sssd.conf.5.xml:827 +#: sssd.conf.5.xml:932 sssd.conf.5.xml:2149 sssd.conf.5.xml:4730 +#: sssd-ldap.5.xml:979 sssd-ldap.5.xml:1134 sssd-ldap.5.xml:1237 +#: sssd-ldap.5.xml:1306 sssd-ldap.5.xml:1714 sssd-ldap.5.xml:1848 +#: sssd-ldap.5.xml:1913 sssd-ipa.5.xml:341 sssd-ad.5.xml:252 sssd-ad.5.xml:367 +#: sssd-ad.5.xml:1180 sssd-ad.5.xml:1375 sssd-krb5.5.xml:358 msgid "Default: true" msgstr "Výchozí: pravda" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:143 -msgid "debug_microseconds (bool)" +#: sssd.conf.5.xml:186 +msgid "debug_microseconds (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:146 +#: sssd.conf.5.xml:189 msgid "" "Add microseconds to the timestamp in debug messages. If journald is enabled " "for SSSD debug logging this option is ignored." msgstr "" #. type: Content of: <variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:151 sssd.conf.5.xml:2040 sssd.conf.5.xml:4158 +#: sssd.conf.5.xml:194 sssd.conf.5.xml:2072 sssd.conf.5.xml:4363 #: sssd-ldap.5.xml:363 sssd-ldap.5.xml:998 sssd-ldap.5.xml:1209 -#: sssd-ldap.5.xml:1663 sssd-ldap.5.xml:1937 sssd-ipa.5.xml:146 -#: sssd-ipa.5.xml:706 sssd-ad.5.xml:1135 sssd-krb5.5.xml:268 +#: sssd-ldap.5.xml:1663 sssd-ldap.5.xml:1937 sssd-ipa.5.xml:141 +#: sssd-ipa.5.xml:701 sssd-ad.5.xml:1140 sssd-idp.5.xml:287 sssd-krb5.5.xml:268 #: sssd-krb5.5.xml:330 sssd-krb5.5.xml:432 include/krb5_options.xml:163 msgid "Default: false" msgstr "Výchozí: false (nepravda)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:156 -msgid "debug_backtrace_enabled (bool)" +#: sssd.conf.5.xml:199 +msgid "debug_backtrace_enabled (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:159 +#: sssd.conf.5.xml:202 msgid "Enable debug backtrace." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:162 +#: sssd.conf.5.xml:205 msgid "" "In case SSSD is run with debug_level less than 9, everything is logged to a " "ring buffer in memory and flushed to a log file on any error up to and " @@ -293,14 +343,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:171 +#: sssd.conf.5.xml:214 msgid "" "Feature is only supported for `logger == files` (i.e. setting doesn't have " "effect for other logger types)." msgstr "" #. type: Content of: outside any tag (error?) -#: sssd.conf.5.xml:111 sssd.conf.5.xml:186 sssd-ldap.5.xml:1754 +#: sssd.conf.5.xml:154 sssd.conf.5.xml:229 sssd-ldap.5.xml:1754 #: sssd-ldap.5.xml:1960 sss-certmap.5.xml:645 sssd-systemtap.5.xml:82 #: sssd-systemtap.5.xml:143 sssd-systemtap.5.xml:236 sssd-systemtap.5.xml:274 #: sssd-systemtap.5.xml:330 sssd-ldap-attributes.5.xml:40 @@ -313,17 +363,17 @@ msgid "<placeholder type=\"variablelist\" id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:184 +#: sssd.conf.5.xml:227 msgid "Options usable in SERVICE and DOMAIN sections" msgstr "Volby použitelné v sekcích SERVICE a DOMAIN" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:188 +#: sssd.conf.5.xml:231 msgid "timeout (integer)" msgstr "timeout (celé kladné číslo)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:191 +#: sssd.conf.5.xml:234 msgid "" "Timeout in seconds between heartbeats for this service. This is used to " "ensure that the process is alive and capable of answering requests. Note " @@ -331,34 +381,36 @@ msgid "" msgstr "" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:198 sssd.conf.5.xml:1199 sssd.conf.5.xml:1673 -#: sssd.conf.5.xml:4174 sssd-ldap.5.xml:825 sssd-idp.5.xml:192 +#: sssd.conf.5.xml:241 sssd.conf.5.xml:1155 sssd.conf.5.xml:1665 +#: sssd.conf.5.xml:4379 sssd-ldap.5.xml:825 sssd-idp.5.xml:271 #: include/ldap_id_mapping.xml:270 msgid "Default: 10" msgstr "Výchozí: 10" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:208 +#: sssd.conf.5.xml:251 msgid "SPECIAL SECTIONS" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:211 +#: sssd.conf.5.xml:254 msgid "The [sssd] section" msgstr "Sekce [sssd]" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><title> -#: sssd.conf.5.xml:220 +#: sssd.conf.5.xml:263 msgid "Section parameters" msgstr "Parametry sekce" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:222 -msgid "services" -msgstr "služby" +#: sssd.conf.5.xml:265 +#, fuzzy +#| msgid "pam_p11_allowed_services (string)" +msgid "services (string)" +msgstr "pam_p11_allowed_services (řetězec)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:225 +#: sssd.conf.5.xml:268 msgid "" "Comma separated list of services that are started when sssd itself starts. " "<phrase condition=\"have_systemd\"> The services' list is optional on " @@ -367,7 +419,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:234 +#: sssd.conf.5.xml:277 msgid "" "Supported services: nss, pam, ifp <phrase condition=\"with_sudo\">, sudo</" "phrase> <phrase condition=\"with_autofs\">, autofs</phrase> <phrase " @@ -376,20 +428,20 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:241 +#: sssd.conf.5.xml:284 msgid "" "<phrase condition=\"have_systemd\"> By default, all services are disabled " "and the administrator must enable the ones allowed to be used by executing: " "\"systemctl enable sssd-@service@.socket\". </phrase>" msgstr "" -#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:250 -msgid "domains" -msgstr "domény" +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sssd.conf.5.xml:293 sssd.conf.5.xml:4562 +msgid "domains (string)" +msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:253 +#: sssd.conf.5.xml:296 msgid "" "A domain is a database containing user information. SSSD can use more " "domains at the same time, but at least one must be configured or SSSD won't " @@ -400,19 +452,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:266 sssd.conf.5.xml:3467 +#: sssd.conf.5.xml:309 sssd.conf.5.xml:3598 msgid "re_expression (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:269 +#: sssd.conf.5.xml:312 msgid "" "Default regular expression that describes how to parse the string containing " "user name and domain into these components." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:274 +#: sssd.conf.5.xml:317 msgid "" "Each domain can have an individual regular expression configured. For some " "ID providers there are also default regular expressions. See DOMAIN SECTIONS " @@ -420,12 +472,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:283 sssd.conf.5.xml:3524 +#: sssd.conf.5.xml:326 sssd.conf.5.xml:3655 msgid "full_name_format (string)" msgstr "full_name_format (řetězec)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:286 sssd.conf.5.xml:3527 +#: sssd.conf.5.xml:329 sssd.conf.5.xml:3658 msgid "" "A <citerefentry> <refentrytitle>printf</refentrytitle> <manvolnum>3</" "manvolnum> </citerefentry>-compatible format that describes how to compose a " @@ -433,58 +485,58 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:297 sssd.conf.5.xml:3538 +#: sssd.conf.5.xml:340 sssd.conf.5.xml:3669 msgid "%1$s" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:298 sssd.conf.5.xml:3539 +#: sssd.conf.5.xml:341 sssd.conf.5.xml:3670 msgid "user name" msgstr "uživatelské jméno" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:301 sssd.conf.5.xml:3542 +#: sssd.conf.5.xml:344 sssd.conf.5.xml:3673 msgid "%2$s" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:304 sssd.conf.5.xml:3545 +#: sssd.conf.5.xml:347 sssd.conf.5.xml:3676 msgid "domain name as specified in the SSSD config file." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:310 sssd.conf.5.xml:3551 +#: sssd.conf.5.xml:353 sssd.conf.5.xml:3682 msgid "%3$s" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:313 sssd.conf.5.xml:3554 +#: sssd.conf.5.xml:356 sssd.conf.5.xml:3685 msgid "" "domain flat name. Mostly usable for Active Directory domains, both directly " "configured or discovered via IPA trusts." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:294 sssd.conf.5.xml:3535 +#: sssd.conf.5.xml:337 sssd.conf.5.xml:3666 msgid "" "The following expansions are supported: <placeholder type=\"variablelist\" " "id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:323 +#: sssd.conf.5.xml:366 msgid "" "Each domain can have an individual format string configured. See DOMAIN " "SECTIONS for more info on this option." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:329 +#: sssd.conf.5.xml:372 msgid "monitor_resolv_conf (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:332 +#: sssd.conf.5.xml:375 msgid "" "Controls if SSSD should monitor the state of resolv.conf to identify when it " "needs to update its internal DNS resolver." @@ -493,12 +545,12 @@ msgstr "" "zapotřebí aktualizovat svůj vestavěný překlad DNS názvů." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:342 +#: sssd.conf.5.xml:385 msgid "try_inotify (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:345 +#: sssd.conf.5.xml:388 msgid "" "By default, SSSD will attempt to use inotify to monitor configuration files " "changes and will fall back to polling every five seconds if inotify cannot " @@ -506,7 +558,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:351 +#: sssd.conf.5.xml:394 msgid "" "There are some limited situations where it is preferred that we should skip " "even trying to use inotify. In these rare cases, this option should be set " @@ -514,26 +566,26 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:357 +#: sssd.conf.5.xml:400 msgid "" "Default: true on platforms where inotify is supported. False on other " "platforms." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:361 +#: sssd.conf.5.xml:404 msgid "" "Note: this option will have no effect on platforms where inotify is " "unavailable. On these platforms, polling will always be used." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:368 +#: sssd.conf.5.xml:411 msgid "krb5_rcache_dir (string)" msgstr "krb5_rcache_dir (řetězec)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:371 +#: sssd.conf.5.xml:414 msgid "" "Directory on the filesystem where SSSD should store Kerberos replay cache " "files." @@ -542,33 +594,33 @@ msgstr "" "replay." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:375 +#: sssd.conf.5.xml:418 msgid "" "This option accepts a special value __LIBKRB5_DEFAULTS__ that will instruct " "SSSD to let libkrb5 decide the appropriate location for the replay cache." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:381 +#: sssd.conf.5.xml:424 msgid "" "Default: Distribution-specific and specified at build-time. " "(__LIBKRB5_DEFAULTS__ if not configured)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:388 +#: sssd.conf.5.xml:431 msgid "default_domain_suffix (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:391 +#: sssd.conf.5.xml:434 msgid "" "Please note that this option is deprecated and domain_resolution_order " "should be used." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:395 +#: sssd.conf.5.xml:438 msgid "" "This string will be used as a default domain name for all names without a " "domain name component. The main use case is environments where the primary " @@ -578,7 +630,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:405 +#: sssd.conf.5.xml:448 msgid "" "Please note that if this option is set all users from the primary domain " "have to use their fully qualified name, e.g. user@domain.name, to log in. " @@ -588,21 +640,21 @@ msgid "" msgstr "" #. type: Content of: <variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:414 sssd-ldap.5.xml:937 sssd-ldap.5.xml:949 -#: sssd-ldap.5.xml:1042 sssd-ad.5.xml:921 sssd-ad.5.xml:996 sssd-krb5.5.xml:468 -#: sssd-ldap-attributes.5.xml:470 sssd-ldap-attributes.5.xml:978 -#: include/ldap_id_mapping.xml:211 include/ldap_id_mapping.xml:222 -#: include/krb5_options.xml:148 +#: sssd.conf.5.xml:457 sssd.conf.5.xml:2006 sssd-ldap.5.xml:937 +#: sssd-ldap.5.xml:949 sssd-ldap.5.xml:1042 sssd-ad.5.xml:926 +#: sssd-ad.5.xml:1001 sssd-krb5.5.xml:468 sssd-ldap-attributes.5.xml:470 +#: sssd-ldap-attributes.5.xml:978 include/ldap_id_mapping.xml:211 +#: include/ldap_id_mapping.xml:222 include/krb5_options.xml:148 msgid "Default: not set" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:419 +#: sssd.conf.5.xml:462 msgid "override_space (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:422 +#: sssd.conf.5.xml:465 msgid "" "This parameter will replace spaces (space bar) with the given character for " "user and group names. e.g. (_). User name "john doe" will be " @@ -612,7 +664,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:431 +#: sssd.conf.5.xml:474 msgid "" "Please note it is a configuration error to use a replacement character that " "might be used in user or group names. If a name contains the replacement " @@ -621,22 +673,22 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:439 +#: sssd.conf.5.xml:482 msgid "Default: not set (spaces will not be replaced)" msgstr "Výchozí: nenastaveno (mezery nebudou nahrazovány)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:444 +#: sssd.conf.5.xml:487 msgid "certificate_verification (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:452 +#: sssd.conf.5.xml:495 msgid "no_ocsp" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:454 +#: sssd.conf.5.xml:497 msgid "" "Disables Online Certificate Status Protocol (OCSP) checks. This might be " "needed if the OCSP servers defined in the certificate are not reachable from " @@ -644,12 +696,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:462 +#: sssd.conf.5.xml:505 msgid "soft_ocsp" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:464 +#: sssd.conf.5.xml:507 msgid "" "If a connection cannot be established to an OCSP responder the OCSP check is " "skipped. This option should be used to allow authentication when the system " @@ -657,61 +709,61 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:474 +#: sssd.conf.5.xml:517 msgid "ocsp_dgst" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:476 +#: sssd.conf.5.xml:519 msgid "" "Digest (hash) function used to create the certificate ID for the OCSP " "request. Allowed values are:" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:480 +#: sssd.conf.5.xml:523 msgid "sha1" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:481 +#: sssd.conf.5.xml:524 msgid "sha256" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:482 +#: sssd.conf.5.xml:525 msgid "sha384" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:483 +#: sssd.conf.5.xml:526 msgid "sha512" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:486 +#: sssd.conf.5.xml:529 msgid "Default: sha1 (to allow compatibility with RFC5019-compliant responder)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:492 +#: sssd.conf.5.xml:535 msgid "no_verification" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:494 +#: sssd.conf.5.xml:537 msgid "" "Disables verification completely. This option should only be used for " "testing." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:500 +#: sssd.conf.5.xml:543 msgid "partial_chain" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:502 +#: sssd.conf.5.xml:545 msgid "" "Allow verification to succeed even if a <replaceable>complete</replaceable> " "chain cannot be built to a self-signed trust-anchor, provided it is possible " @@ -719,12 +771,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:511 +#: sssd.conf.5.xml:554 msgid "ocsp_default_responder=URL" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:513 +#: sssd.conf.5.xml:556 msgid "" "Sets the OCSP default responder which should be used instead of the one " "mentioned in the certificate. URL must be replaced with the URL of the OCSP " @@ -732,24 +784,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:523 +#: sssd.conf.5.xml:566 msgid "ocsp_default_responder_signing_cert=NAME" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:525 +#: sssd.conf.5.xml:568 msgid "" "This option is currently ignored. All needed certificates must be available " "in the PEM file given by pam_cert_db_path." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:533 +#: sssd.conf.5.xml:576 msgid "crl_file=/PATH/TO/CRL/FILE" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:535 +#: sssd.conf.5.xml:578 msgid "" "Use the Certificate Revocation List (CRL) from the given file during the " "verification of the certificate. The CRL must be given in PEM format, see " @@ -758,12 +810,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:548 +#: sssd.conf.5.xml:591 msgid "soft_crl" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:551 +#: sssd.conf.5.xml:594 msgid "" "If a Certificate Revocation List (CRL) is expired ignore the expiration " "time of the CRL and check the related certificates with the expired CRL. " @@ -772,7 +824,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:447 +#: sssd.conf.5.xml:490 msgid "" "With this parameter the certificate verification can be tuned with a comma " "separated list of options. Supported options are: <placeholder " @@ -780,46 +832,48 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:564 +#: sssd.conf.5.xml:607 msgid "Unknown options are reported but ignored." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:567 +#: sssd.conf.5.xml:610 msgid "Default: not set, i.e. do not restrict certificate verification" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:573 +#: sssd.conf.5.xml:616 msgid "disable_netlink (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:576 +#: sssd.conf.5.xml:619 msgid "" "SSSD hooks into the netlink interface to monitor changes to routes, " "addresses, links and trigger certain actions." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:581 +#: sssd.conf.5.xml:624 msgid "" "The SSSD state changes caused by netlink events may be undesirable and can " "be disabled by setting this option to 'true'" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:586 +#: sssd.conf.5.xml:629 msgid "Default: false (netlink changes are detected)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:591 -msgid "domain_resolution_order" -msgstr "" +#: sssd.conf.5.xml:634 +#, fuzzy +#| msgid "ipa_access_order (string)" +msgid "domain_resolution_order (string)" +msgstr "ipa_access_order (řetězec)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:594 +#: sssd.conf.5.xml:637 msgid "" "Comma separated list of domains and subdomains representing the lookup order " "that will be followed. The list doesn't have to include all possible " @@ -830,7 +884,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:606 +#: sssd.conf.5.xml:649 msgid "" "Please, note that when this option is set the output format of all commands " "is always fully-qualified even when using short names for input. In case " @@ -846,19 +900,20 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:630 sssd.conf.5.xml:1697 sssd.conf.5.xml:4224 -#: sssd-ad.5.xml:187 sssd-ad.5.xml:328 sssd-ad.5.xml:342 sssd-idp.5.xml:108 -#: sssd-idp.5.xml:132 sssd-idp.5.xml:145 sssd-idp.5.xml:159 sssd-idp.5.xml:180 +#: sssd.conf.5.xml:673 sssd.conf.5.xml:1026 sssd.conf.5.xml:1689 +#: sssd.conf.5.xml:4429 sssd-ad.5.xml:187 sssd-ad.5.xml:328 sssd-ad.5.xml:342 +#: sssd-idp.5.xml:112 sssd-idp.5.xml:136 sssd-idp.5.xml:149 sssd-idp.5.xml:167 +#: sssd-idp.5.xml:188 msgid "Default: Not set" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:635 +#: sssd.conf.5.xml:678 msgid "implicit_pac_responder (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:638 +#: sssd.conf.5.xml:681 msgid "" "The PAC responder is enabled automatically for the IPA and AD provider to " "evaluate and check the PAC. If it has to be disabled set this option to " @@ -866,12 +921,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:649 +#: sssd.conf.5.xml:692 msgid "core_dumpable (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:652 +#: sssd.conf.5.xml:695 msgid "" "This option can be used for general system hardening: setting it to 'false' " "forbids core dumps for all SSSD processes to avoid leaking plain text " @@ -880,7 +935,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:660 +#: sssd.conf.5.xml:703 msgid "" "Take a note that this setting has no effect for 'ldap_child', 'krb5_child' " "and 'sssd_pam' as those privileged binaries can have a copy of a host keytab " @@ -889,24 +944,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:673 +#: sssd.conf.5.xml:716 msgid "passkey_verification (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:681 +#: sssd.conf.5.xml:724 msgid "user_verification (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:683 +#: sssd.conf.5.xml:726 msgid "" "Enable or disable the user verification (i.e. PIN, fingerprint) during " "authentication. If enabled, the PIN will always be requested." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:689 +#: sssd.conf.5.xml:732 msgid "" "The default is that the key settings decide what to do. In the IPA or " "kerberos pre-authentication case, this value will be overwritten by the " @@ -914,7 +969,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:676 +#: sssd.conf.5.xml:719 msgid "" "With this parameter the passkey verification can be tuned with a comma " "separated list of options. Supported options are: <placeholder " @@ -922,7 +977,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:213 +#: sssd.conf.5.xml:256 msgid "" "Individual pieces of SSSD functionality are provided by special SSSD " "services that are started and stopped together with SSSD. The services are " @@ -933,12 +988,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:708 +#: sssd.conf.5.xml:751 msgid "SERVICES SECTIONS" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:710 +#: sssd.conf.5.xml:753 msgid "" "Settings that can be used to configure different services are described in " "this section. They should reside in the [<replaceable>$NAME</replaceable>] " @@ -947,42 +1002,45 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:717 +#: sssd.conf.5.xml:760 msgid "General service configuration options" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:719 +#: sssd.conf.5.xml:762 msgid "These options can be used to configure any service." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:723 -msgid "fd_limit" -msgstr "" +#: sssd.conf.5.xml:766 +#, fuzzy +#| msgid "timeout (integer)" +msgid "fd_limit (integer)" +msgstr "timeout (celé kladné číslo)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:726 +#: sssd.conf.5.xml:769 msgid "" "This option specifies the maximum number of file descriptors that may be " -"opened at one time by this SSSD process. On systems where SSSD is granted " -"the CAP_SYS_RESOURCE capability, this will be an absolute setting. On " -"systems without this capability, the resulting value will be the lower value " -"of this or the limits.conf \"hard\" limit." +"opened at one time by this SSSD process. Note this value will be capped by " +"the init system at the startup of SSSD, see e.g. man systemd.exec for " +"details." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:735 +#: sssd.conf.5.xml:776 msgid "Default: 8192 (or limits.conf \"hard\" limit)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:740 -msgid "client_idle_timeout" -msgstr "" +#: sssd.conf.5.xml:781 +#, fuzzy +#| msgid "ldap_connection_idle_timeout (integer)" +msgid "client_idle_timeout (integer)" +msgstr "ldap_connection_idle_timeout (celé číslo)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:743 +#: sssd.conf.5.xml:784 msgid "" "This option specifies the number of seconds that a client of an SSSD process " "can hold onto a file descriptor without communicating on it. This value is " @@ -992,140 +1050,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:752 +#: sssd.conf.5.xml:793 msgid "Default: 60, KCM: 300" msgstr "Výchozí: 60, KCM: 300" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:757 -msgid "offline_timeout (integer)" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:760 -msgid "" -"When SSSD switches to offline mode the amount of time before it tries to go " -"back online will increase based upon the time spent disconnected. By " -"default SSSD uses incremental behaviour to calculate delay in between " -"retries. So, the wait time for a given retry will be longer than the wait " -"time for the previous ones. After each unsuccessful attempt to go online, " -"the new interval is recalculated by the following:" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:771 sssd.conf.5.xml:827 -msgid "" -"new_delay = Minimum(old_delay * 2, offline_timeout_max) + " -"random[0...offline_timeout_random_offset]" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:774 -msgid "" -"The offline_timeout default value is 60. The offline_timeout_max default " -"value is 3600. The offline_timeout_random_offset default value is 30. The " -"end result is amount of seconds before next retry." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:780 -msgid "" -"Note that the maximum length of each interval is defined by " -"offline_timeout_max (apart of random part)." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:784 sssd.conf.5.xml:1110 sssd.conf.5.xml:1490 -#: sssd.conf.5.xml:1791 sssd-ldap.5.xml:550 -msgid "Default: 60" -msgstr "Výchozí: 60" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:789 -msgid "offline_timeout_max (integer)" -msgstr "offline_timeout_max (celé číslo)" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:792 -msgid "" -"Controls by how much the time between attempts to go online can be " -"incremented following unsuccessful attempts to go online." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:797 -msgid "A value of 0 disables the incrementing behaviour." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:800 -msgid "" -"The value of this parameter should be set in correlation to offline_timeout " -"parameter value." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:804 -msgid "" -"With offline_timeout set to 60 (default value) there is no point in setting " -"offlinet_timeout_max to less than 120 as it will saturate instantly. General " -"rule here should be to set offline_timeout_max to at least 4 times " -"offline_timeout." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:810 -msgid "" -"Although a value between 0 and offline_timeout may be specified, it has the " -"effect of overriding the offline_timeout value so is of little use." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:815 -msgid "Default: 3600" -msgstr "Výchozí: 3600" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:820 -msgid "offline_timeout_random_offset (integer)" -msgstr "offline_timeout_random_offset (celé číslo)" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:823 -msgid "" -"When SSSD is in offline mode it keeps probing backend servers in specified " -"time intervals:" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:830 -msgid "" -"This parameter controls the value of the random offset used for the above " -"equation. Final random_offset value will be random number in range:" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:835 -msgid "[0 - offline_timeout_random_offset]" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:838 -msgid "A value of 0 disables the random offset addition." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:841 -msgid "Default: 30" -msgstr "Výchozí: 30" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:846 -msgid "responder_idle_timeout" -msgstr "" +#: sssd.conf.5.xml:798 +#, fuzzy +#| msgid "ldap_connection_idle_timeout (integer)" +msgid "responder_idle_timeout (integer)" +msgstr "ldap_connection_idle_timeout (celé číslo)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:849 +#: sssd.conf.5.xml:801 msgid "" "This option specifies the number of seconds that an SSSD responder process " "can be up without being used. This value is limited in order to avoid " @@ -1137,58 +1074,59 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:863 sssd.conf.5.xml:1123 sssd.conf.5.xml:2248 +#: sssd.conf.5.xml:815 sssd.conf.5.xml:1079 sssd.conf.5.xml:2285 #: sssd-ldap.5.xml:377 msgid "Default: 300" msgstr "Výchozí: 300" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:868 -msgid "cache_first" +#: sssd.conf.5.xml:820 +msgid "cache_first (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:871 +#: sssd.conf.5.xml:823 msgid "" "This option specifies whether the responder should query all caches before " "querying the Data Providers." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:883 +#: sssd.conf.5.xml:835 msgid "NSS configuration options" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:885 +#: sssd.conf.5.xml:837 msgid "" -"These options can be used to configure the Name Service Switch (NSS) service." +"These options can be used to configure the Name Service Switch (NSS) service " +"and should be specified under the <quote>[nss]</quote> section." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:890 +#: sssd.conf.5.xml:843 msgid "enum_cache_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:893 +#: sssd.conf.5.xml:846 msgid "" "How many seconds should nss_sss cache enumerations (requests for info about " "all users)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:897 +#: sssd.conf.5.xml:850 msgid "Default: 120" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:902 +#: sssd.conf.5.xml:855 msgid "entry_cache_nowait_percentage (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:905 +#: sssd.conf.5.xml:858 msgid "" "The entry cache can be set to automatically update entries in the background " "if they are requested beyond a percentage of the entry_cache_timeout value " @@ -1199,7 +1137,7 @@ msgstr "" "doménu." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:911 +#: sssd.conf.5.xml:864 msgid "" "For example, if the domain's entry_cache_timeout is set to 30s and " "entry_cache_nowait_percentage is set to 50 (percent), entries that come in " @@ -1209,7 +1147,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:921 +#: sssd.conf.5.xml:874 msgid "" "Valid values for this option are 0-99 and represent a percentage of the " "entry_cache_timeout for each domain. For performance reasons, this " @@ -1218,17 +1156,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:929 sssd.conf.5.xml:2061 +#: sssd.conf.5.xml:882 sssd.conf.5.xml:2093 msgid "Default: 50" msgstr "Výchozí: 50" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:934 +#: sssd.conf.5.xml:887 msgid "entry_negative_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:937 +#: sssd.conf.5.xml:890 msgid "" "Specifies for how many seconds nss_sss should cache negative cache hits " "(that is, queries for invalid database entries, like nonexistent ones) " @@ -1236,17 +1174,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:943 sssd.conf.5.xml:1685 sssd.conf.5.xml:2085 +#: sssd.conf.5.xml:896 sssd.conf.5.xml:1677 sssd.conf.5.xml:2119 msgid "Default: 15" msgstr "Výchozí: 15" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:948 +#: sssd.conf.5.xml:901 msgid "filter_users, filter_groups (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:951 +#: sssd.conf.5.xml:904 msgid "" "Exclude certain users or groups from being fetched from the sss NSS " "database. This is particularly useful for system accounts. This option can " @@ -1255,7 +1193,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:959 +#: sssd.conf.5.xml:912 msgid "" "NOTE: The filter_groups option doesn't affect inheritance of nested group " "members, since filtering happens after they are propagated for returning via " @@ -1264,41 +1202,41 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:967 +#: sssd.conf.5.xml:920 msgid "Default: root" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:972 -msgid "filter_users_in_groups (bool)" +#: sssd.conf.5.xml:925 +msgid "filter_users_in_groups (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:975 +#: sssd.conf.5.xml:928 msgid "" -"If you want filtered user still be group members set this option to false." +"If you want filtered users to remain group members set this option to false" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:986 +#: sssd.conf.5.xml:939 msgid "fallback_homedir (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:989 +#: sssd.conf.5.xml:942 msgid "" "Set a default template for a user's home directory if one is not specified " "explicitly by the domain's data provider." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:994 +#: sssd.conf.5.xml:947 msgid "" "The available values for this option are the same as for override_homedir." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1000 +#: sssd.conf.5.xml:953 #, no-wrap msgid "" "fallback_homedir = /home/%u\n" @@ -1306,23 +1244,23 @@ msgid "" msgstr "" #. type: Content of: <varlistentry><listitem><para> -#: sssd.conf.5.xml:998 sssd.conf.5.xml:1557 sssd.conf.5.xml:1576 -#: sssd.conf.5.xml:1653 sssd-krb5.5.xml:451 include/override_homedir.xml:78 +#: sssd.conf.5.xml:951 sssd.conf.5.xml:1524 sssd.conf.5.xml:1543 +#: sssd.conf.5.xml:1645 sssd-krb5.5.xml:451 include/override_homedir.xml:78 msgid "example: <placeholder type=\"programlisting\" id=\"0\"/>" msgstr "příklad: <placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1004 +#: sssd.conf.5.xml:957 msgid "Default: not set (no substitution for unset home directories)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1010 +#: sssd.conf.5.xml:963 msgid "override_shell (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1013 +#: sssd.conf.5.xml:966 msgid "" "Override the login shell for all users. This option supersedes any other " "shell options if it takes effect and can be set either in the [nss] section " @@ -1330,47 +1268,47 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1019 +#: sssd.conf.5.xml:972 msgid "Default: not set (SSSD will use the value retrieved from LDAP)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1025 +#: sssd.conf.5.xml:978 msgid "allowed_shells (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1028 +#: sssd.conf.5.xml:981 msgid "" "Restrict user shell to one of the listed values. The order of evaluation is:" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1031 +#: sssd.conf.5.xml:984 msgid "1. If the shell is present in <quote>/etc/shells</quote>, it is used." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1035 +#: sssd.conf.5.xml:988 msgid "" "2. If the shell is in the allowed_shells list but not in <quote>/etc/shells</" "quote>, use the value of the shell_fallback parameter." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1040 +#: sssd.conf.5.xml:993 msgid "" "3. If the shell is not in the allowed_shells list and not in <quote>/etc/" "shells</quote>, a nologin shell is used." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1045 +#: sssd.conf.5.xml:998 msgid "The wildcard (*) can be used to allow any shell." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1048 +#: sssd.conf.5.xml:1001 msgid "" "The (*) is useful if you want to use shell_fallback in case that user's " "shell is not in <quote>/etc/shells</quote> and maintaining list of all " @@ -1378,74 +1316,76 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1055 +#: sssd.conf.5.xml:1008 msgid "An empty string for shell is passed as-is to libc." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1058 +#: sssd.conf.5.xml:1011 msgid "" "The <quote>/etc/shells</quote> is only read on SSSD start up, which means " "that a restart of the SSSD is required in case a new shell is installed." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1062 +#: sssd.conf.5.xml:1015 msgid "Default: Not set. The user shell is automatically used." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1067 +#: sssd.conf.5.xml:1020 msgid "vetoed_shells (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1070 +#: sssd.conf.5.xml:1023 msgid "Replace any instance of these shells with the shell_fallback" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1075 +#: sssd.conf.5.xml:1031 msgid "shell_fallback (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1078 +#: sssd.conf.5.xml:1034 msgid "" "The default shell to use if an allowed shell is not installed on the machine." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1082 +#: sssd.conf.5.xml:1038 msgid "Default: /bin/sh" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1087 -msgid "default_shell" -msgstr "" +#: sssd.conf.5.xml:1043 +#, fuzzy +#| msgid "pac_check (string)" +msgid "default_shell (string)" +msgstr "pac_check (řetězec)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1090 +#: sssd.conf.5.xml:1046 msgid "" "The default shell to use if the provider does not return one during lookup. " "This option can be specified globally in the [nss] section or per-domain." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1096 +#: sssd.conf.5.xml:1052 msgid "" "Default: not set (Return NULL if no shell is specified and rely on libc to " "substitute something sensible when necessary, usually /bin/sh)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1103 sssd.conf.5.xml:1483 +#: sssd.conf.5.xml:1059 sssd.conf.5.xml:1450 msgid "get_domains_timeout (int)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1106 sssd.conf.5.xml:1486 +#: sssd.conf.5.xml:1062 sssd.conf.5.xml:1453 msgid "" "Specifies time in seconds for which the list of subdomains will be " "considered valid." @@ -1453,40 +1393,46 @@ msgstr "" "Určuje dobu (v sekundách) po které bude seznam dílčích domén považován za " "platný." +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1066 sssd.conf.5.xml:1457 sssd.conf.5.xml:1788 +#: sssd.conf.5.xml:2862 sssd-ldap.5.xml:550 +msgid "Default: 60" +msgstr "Výchozí: 60" + #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1115 +#: sssd.conf.5.xml:1071 msgid "memcache_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1118 +#: sssd.conf.5.xml:1074 msgid "" "Specifies time in seconds for which records in the in-memory cache will be " "valid. Setting this option to zero will disable the in-memory cache." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1126 +#: sssd.conf.5.xml:1082 msgid "" "WARNING: Disabling the in-memory cache will have significant negative impact " "on SSSD's performance and should only be used for testing." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1132 sssd.conf.5.xml:1157 sssd.conf.5.xml:1182 -#: sssd.conf.5.xml:1207 sssd.conf.5.xml:1234 +#: sssd.conf.5.xml:1088 sssd.conf.5.xml:1113 sssd.conf.5.xml:1138 +#: sssd.conf.5.xml:1163 sssd.conf.5.xml:1190 msgid "" "NOTE: If the environment variable SSS_NSS_USE_MEMCACHE is set to \"NO\", " "client applications will not use the fast in-memory cache." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1140 +#: sssd.conf.5.xml:1096 msgid "memcache_size_passwd (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1143 +#: sssd.conf.5.xml:1099 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for passwd requests. Setting the size to 0 will disable the passwd in-" @@ -1494,25 +1440,25 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1149 sssd.conf.5.xml:2888 sssd-ldap.5.xml:604 +#: sssd.conf.5.xml:1105 sssd.conf.5.xml:3013 sssd-ldap.5.xml:604 msgid "Default: 8" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1152 sssd.conf.5.xml:1177 sssd.conf.5.xml:1202 -#: sssd.conf.5.xml:1229 +#: sssd.conf.5.xml:1108 sssd.conf.5.xml:1133 sssd.conf.5.xml:1158 +#: sssd.conf.5.xml:1185 msgid "" "WARNING: Disabled or too small in-memory cache can have significant negative " "impact on SSSD's performance." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1165 +#: sssd.conf.5.xml:1121 msgid "memcache_size_group (integer)" msgstr "memcache_size_group (celé číslo)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1168 +#: sssd.conf.5.xml:1124 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for group requests. Setting the size to 0 will disable the group in-memory " @@ -1520,19 +1466,19 @@ msgid "" msgstr "" #. type: Content of: <variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1174 sssd.conf.5.xml:1226 sssd.conf.5.xml:3656 +#: sssd.conf.5.xml:1130 sssd.conf.5.xml:1182 sssd.conf.5.xml:3835 #: sssd-ldap.5.xml:534 sssd-ldap.5.xml:581 include/failover.xml:116 #: include/krb5_options.xml:11 msgid "Default: 6" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1190 +#: sssd.conf.5.xml:1146 msgid "memcache_size_initgroups (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1193 +#: sssd.conf.5.xml:1149 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for initgroups requests. Setting the size to 0 will disable the initgroups " @@ -1540,12 +1486,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1215 +#: sssd.conf.5.xml:1171 msgid "memcache_size_sid (integer)" msgstr "memcache_size_sid (celé číslo)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1218 +#: sssd.conf.5.xml:1174 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for SID related requests. Only SID-by-ID and ID-by-SID requests are " @@ -1554,12 +1500,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1242 sssd-ifp.5.xml:90 +#: sssd.conf.5.xml:1198 sssd-ifp.5.xml:90 msgid "user_attributes (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1245 +#: sssd.conf.5.xml:1201 msgid "" "Some of the additional NSS responder requests can return more attributes " "than just the POSIX ones defined by the NSS interface. The list of " @@ -1570,103 +1516,109 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1258 +#: sssd.conf.5.xml:1214 msgid "" "To make configuration more easy the NSS responder will check the InfoPipe " "option if it is not set for the NSS responder." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1263 +#: sssd.conf.5.xml:1219 msgid "Default: not set, fallback to InfoPipe option" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1268 +#: sssd.conf.5.xml:1224 msgid "pwfield (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1271 +#: sssd.conf.5.xml:1227 msgid "" "The value that NSS operations that return users or groups will return for " "the <quote>password</quote> field." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1276 -msgid "Default: <quote>*</quote>" +#: sssd.conf.5.xml:1232 +msgid "" +"This option can also be set per-domain, which overwrites the value in the " +"<quote>[nss]</quote> section for that domain. This is particularly useful " +"when using a proxy domain with <option>proxy_lib_name=files</option> and a " +"<option>proxy_pam_target</option> other than <quote>sssd-shadowutils</" +"quote>. In that case, SSSD returns <quote>*</quote> for the password field " +"by default, which causes <command>pam_unix</command> to treat all accounts " +"as locked. Setting <option>pwfield = x</option> in the domain section " +"restores the expected behavior." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1279 -msgid "" -"Note: This option can also be set per-domain which overwrites the value in " -"[nss] section." +#: sssd.conf.5.xml:1246 +msgid "Default: <quote>*</quote>" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1283 +#: sssd.conf.5.xml:1249 msgid "" -"Default: <quote>not set</quote> (remote domains), <quote>x</quote> (proxy " -"domain with nss_files and sssd-shadowutils target)" +"Default (per-domain): <quote>not set</quote> (remote domains), <quote>x</" +"quote> (proxy domain with nss_files and sssd-shadowutils target)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:1292 +#: sssd.conf.5.xml:1258 msgid "PAM configuration options" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:1294 +#: sssd.conf.5.xml:1260 msgid "" "These options can be used to configure the Pluggable Authentication Module " -"(PAM) service." +"(PAM) service and should be specified under the <quote>[pam]</quote> section." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1299 +#: sssd.conf.5.xml:1266 msgid "offline_credentials_expiration (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1302 +#: sssd.conf.5.xml:1269 msgid "" "If the authentication provider is offline, how long should we allow cached " "logins (in days since the last successful online login)." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1307 sssd.conf.5.xml:1320 +#: sssd.conf.5.xml:1274 sssd.conf.5.xml:1287 msgid "Default: 0 (No limit)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1313 +#: sssd.conf.5.xml:1280 msgid "offline_failed_login_attempts (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1316 +#: sssd.conf.5.xml:1283 msgid "" "If the authentication provider is offline, how many failed login attempts " "are allowed." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1326 +#: sssd.conf.5.xml:1293 msgid "offline_failed_login_delay (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1329 +#: sssd.conf.5.xml:1296 msgid "" "The time in minutes which has to pass after offline_failed_login_attempts " "has been reached before a new login attempt is possible." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1334 +#: sssd.conf.5.xml:1301 msgid "" "If set to 0 the user cannot authenticate offline if " "offline_failed_login_attempts has been reached. Only a successful online " @@ -1674,59 +1626,59 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1340 sssd.conf.5.xml:1450 +#: sssd.conf.5.xml:1307 sssd.conf.5.xml:1417 msgid "Default: 5" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1346 +#: sssd.conf.5.xml:1313 msgid "pam_verbosity (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1349 +#: sssd.conf.5.xml:1316 msgid "" "Controls what kind of messages are shown to the user during authentication. " "The higher the number to more messages are displayed." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1354 +#: sssd.conf.5.xml:1321 msgid "Currently sssd supports the following values:" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1357 +#: sssd.conf.5.xml:1324 msgid "<emphasis>0</emphasis>: do not show any message" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1360 +#: sssd.conf.5.xml:1327 msgid "<emphasis>1</emphasis>: show only important messages" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1364 +#: sssd.conf.5.xml:1331 msgid "<emphasis>2</emphasis>: show informational messages" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1367 +#: sssd.conf.5.xml:1334 msgid "<emphasis>3</emphasis>: show all messages and debug information" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1371 sssd.8.xml:63 +#: sssd.conf.5.xml:1338 sssd.8.xml:63 msgid "Default: 1" msgstr "Výchozí: 1" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1377 +#: sssd.conf.5.xml:1344 msgid "pam_response_filter (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1380 +#: sssd.conf.5.xml:1347 msgid "" "A comma separated list of strings which allows to remove (filter) data sent " "by the PAM responder to pam_sss PAM module. There are different kind of " @@ -1735,51 +1687,51 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1388 +#: sssd.conf.5.xml:1355 msgid "" "While messages already can be controlled with the help of the pam_verbosity " "option this option allows to filter out other kind of responses as well." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1395 +#: sssd.conf.5.xml:1362 msgid "ENV" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1396 +#: sssd.conf.5.xml:1363 msgid "Do not send any environment variables to any service." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1399 +#: sssd.conf.5.xml:1366 msgid "ENV:var_name" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1400 +#: sssd.conf.5.xml:1367 msgid "Do not send environment variable var_name to any service." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1404 +#: sssd.conf.5.xml:1371 msgid "ENV:var_name:service" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1405 +#: sssd.conf.5.xml:1372 msgid "Do not send environment variable var_name to service." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1393 +#: sssd.conf.5.xml:1360 msgid "" "Currently the following filters are supported: <placeholder " "type=\"variablelist\" id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1412 +#: sssd.conf.5.xml:1379 msgid "" "The list of strings can either be the list of filters which would set this " "list of filters and overwrite the defaults. Or each element of the list can " @@ -1790,23 +1742,23 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1423 +#: sssd.conf.5.xml:1390 msgid "Default: ENV:KRB5CCNAME:sudo, ENV:KRB5CCNAME:sudo-i" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1426 +#: sssd.conf.5.xml:1393 msgid "" "Example: -ENV:KRB5CCNAME:sudo-i will remove the filter from the default list" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1433 +#: sssd.conf.5.xml:1400 msgid "pam_id_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1436 +#: sssd.conf.5.xml:1403 msgid "" "For any PAM request while SSSD is online, the SSSD will attempt to " "immediately update the cached identity information for the user in order to " @@ -1814,7 +1766,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1442 +#: sssd.conf.5.xml:1409 msgid "" "A complete PAM conversation may perform multiple PAM requests, such as " "account management and session opening. This option controls (on a per-" @@ -1823,17 +1775,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1456 +#: sssd.conf.5.xml:1423 msgid "pam_pwd_expiration_warning (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1459 sssd.conf.5.xml:2912 +#: sssd.conf.5.xml:1426 sssd.conf.5.xml:3037 msgid "Display a warning N days before the password expires." msgstr "Zobrazit varování N dnů před skončením platnosti hesla." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1462 +#: sssd.conf.5.xml:1429 msgid "" "Please note that the backend server has to provide information about the " "expiration time of the password. If this information is missing, sssd " @@ -1841,32 +1793,32 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1468 sssd.conf.5.xml:2915 +#: sssd.conf.5.xml:1435 sssd.conf.5.xml:3040 msgid "" "If zero is set, then this filter is not applied, i.e. if the expiration " "warning was received from backend server, it will automatically be displayed." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1473 +#: sssd.conf.5.xml:1440 msgid "" "This setting can be overridden by setting <emphasis>pwd_expiration_warning</" "emphasis> for a particular domain." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1478 sssd.conf.5.xml:3913 sssd-ldap.5.xml:662 +#: sssd.conf.5.xml:1445 sssd.conf.5.xml:4118 sssd-ldap.5.xml:662 #: sssd-ldap.5.xml:1733 sssd.8.xml:79 msgid "Default: 0" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1495 +#: sssd.conf.5.xml:1462 msgid "pam_trusted_users (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1498 +#: sssd.conf.5.xml:1465 msgid "" "Specifies the comma-separated list of UID values or user names that are " "allowed to run PAM conversations against trusted domains. Users not " @@ -1876,74 +1828,74 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1508 +#: sssd.conf.5.xml:1475 msgid "Default: All users are considered trusted by default" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1512 +#: sssd.conf.5.xml:1479 msgid "" "Please note that UID 0 is always allowed to access the PAM responder even in " "case it is not in the pam_trusted_users list." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1519 +#: sssd.conf.5.xml:1486 msgid "pam_public_domains (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1522 +#: sssd.conf.5.xml:1489 msgid "" "Specifies the comma-separated list of domain names that are accessible even " "to untrusted users." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1526 +#: sssd.conf.5.xml:1493 msgid "Two special values for pam_public_domains option are defined:" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1530 +#: sssd.conf.5.xml:1497 msgid "" "all (Untrusted users are allowed to access all domains in PAM responder.)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1534 +#: sssd.conf.5.xml:1501 msgid "" "none (Untrusted users are not allowed to access any domains PAM in " "responder.)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1538 sssd.conf.5.xml:1563 sssd.conf.5.xml:1582 -#: sssd.conf.5.xml:1824 sssd.conf.5.xml:3842 sssd-ldap.5.xml:1270 +#: sssd.conf.5.xml:1505 sssd.conf.5.xml:1530 sssd.conf.5.xml:1549 +#: sssd.conf.5.xml:1821 sssd.conf.5.xml:4048 sssd-ldap.5.xml:1270 msgid "Default: none" msgstr "Výchozí: nic" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1543 +#: sssd.conf.5.xml:1510 msgid "pam_account_expired_message (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1546 +#: sssd.conf.5.xml:1513 msgid "" "Allows a custom expiration message to be set, replacing the default " "'Permission denied' message." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1551 +#: sssd.conf.5.xml:1518 msgid "" "Note: Please be aware that message is only printed for the SSH service " "unless pam_verbosity is set to 3 (show all messages and debug information)." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1559 +#: sssd.conf.5.xml:1526 #, no-wrap msgid "" "pam_account_expired_message = Account expired, please contact help desk.\n" @@ -1951,19 +1903,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1568 +#: sssd.conf.5.xml:1535 msgid "pam_account_locked_message (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1571 +#: sssd.conf.5.xml:1538 msgid "" "Allows a custom lockout message to be set, replacing the default 'Permission " "denied' message." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1578 +#: sssd.conf.5.xml:1545 #, no-wrap msgid "" "pam_account_locked_message = Account locked, please contact help desk.\n" @@ -1971,81 +1923,122 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1587 -msgid "pam_passkey_auth (bool)" +#: sssd.conf.5.xml:1554 +msgid "pam_passkey_auth (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1590 +#: sssd.conf.5.xml:1557 msgid "Enable passkey device based authentication." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1593 sssd.conf.5.xml:1910 sssd-ad.5.xml:1286 +#: sssd.conf.5.xml:1560 sssd.conf.5.xml:1907 sssd-ad.5.xml:1279 #: sss_rpcidmapd.5.xml:76 msgid "Default: True" msgstr "Výchozí: true (pravda)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1598 -msgid "passkey_debug_libfido2 (bool)" +#: sssd.conf.5.xml:1565 +msgid "passkey_debug_libfido2 (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1601 +#: sssd.conf.5.xml:1568 msgid "Enable libfido2 library debug messages." msgstr "" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1604 sssd.conf.5.xml:1618 sssd-ldap.5.xml:727 -#: sssd-ldap.5.xml:752 sssd-ldap.5.xml:848 sssd-ldap.5.xml:1356 -#: sssd-ad.5.xml:506 sssd-ad.5.xml:582 sssd-ad.5.xml:1155 +#: sssd.conf.5.xml:1571 sssd.conf.5.xml:1585 sssd.conf.5.xml:4781 +#: sssd-ldap.5.xml:727 sssd-ldap.5.xml:752 sssd-ldap.5.xml:848 +#: sssd-ldap.5.xml:1356 sssd-ad.5.xml:506 sssd-ad.5.xml:582 sssd-ad.5.xml:1160 #: include/ldap_id_mapping.xml:250 msgid "Default: False" msgstr "Výchozí: false (nepravda)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1609 -msgid "pam_cert_auth (bool)" +#: sssd.conf.5.xml:1576 +msgid "pam_cert_auth (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1612 +#: sssd.conf.5.xml:1579 msgid "" "Enable certificate based Smartcard authentication. Since this requires " "additional communication with the Smartcard which will delay the " "authentication process this option is disabled by default." msgstr "" +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1588 +msgid "" +"Note: In case OpenSC is used for Smartcard access SSSD supports the " +"filesystem caching in OpenSC when enabled in opensc.conf. The cached files " +"are located in a common <quote>opensc</quote> directory in SSSD's state " +"directory. The behaviour can be changed in opensc.conf" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> +#: sssd.conf.5.xml:1597 +#, no-wrap +msgid "" +"app /usr/libexec/sssd/p11_child {\n" +" framework pkcs15 {\n" +" use_file_caching = no;\n" +" }\n" +"}\n" +"app /usr/libexec/sssd/krb5_child {\n" +" framework pkcs15 {\n" +" use_file_caching = no;\n" +" }\n" +"}\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1595 +#, fuzzy +#| msgid "Example: <placeholder type=\"programlisting\" id=\"0\"/>" +msgid "" +"Example opensc.conf (*): <placeholder type=\"programlisting\" id=\"0\"/>" +msgstr "Příklad: <placeholder type=\"programlisting\" id=\"0\"/>" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1610 +msgid "" +"(*) The actual <quote>libexec</quote> directory for p11_child and krb5_child " +"depends on the distribution." +msgstr "" + #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1623 +#: sssd.conf.5.xml:1615 msgid "pam_cert_db_path (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1626 +#: sssd.conf.5.xml:1618 msgid "The path to the certificate database." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1629 sssd.conf.5.xml:2163 sssd.conf.5.xml:4338 +#: sssd.conf.5.xml:1621 sssd.conf.5.xml:2199 sssd.conf.5.xml:4543 msgid "Default:" msgstr "Výchozí:" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1631 sssd.conf.5.xml:2165 +#: sssd.conf.5.xml:1623 sssd.conf.5.xml:2201 msgid "" "/etc/sssd/pki/sssd_auth_ca_db.pem (path to a file with trusted CA " "certificates in PEM format)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1641 +#: sssd.conf.5.xml:1633 msgid "pam_cert_verification (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1644 +#: sssd.conf.5.xml:1636 msgid "" "With this parameter the PAM certificate verification can be tuned with a " "comma separated list of options that override the " @@ -2055,7 +2048,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1655 +#: sssd.conf.5.xml:1647 #, no-wrap msgid "" "pam_cert_verification = partial_chain\n" @@ -2063,59 +2056,59 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1659 +#: sssd.conf.5.xml:1651 msgid "" "Default: not set, i.e. use default <quote>certificate_verification</quote> " "option defined in <quote>[sssd]</quote> section." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1666 +#: sssd.conf.5.xml:1658 msgid "p11_child_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1669 +#: sssd.conf.5.xml:1661 msgid "How many seconds will pam_sss wait for p11_child to finish." msgstr "Kolik sekund bude pam_sss čekat na dokončení p11_child." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1678 +#: sssd.conf.5.xml:1670 msgid "passkey_child_timeout (integer)" msgstr "passkey_child_timeout (celé číslo)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1681 +#: sssd.conf.5.xml:1673 msgid "" "How many seconds will the PAM responder wait for passkey_child to finish." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1690 +#: sssd.conf.5.xml:1682 msgid "pam_app_services (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1693 +#: sssd.conf.5.xml:1685 msgid "" "Which PAM services are permitted to contact domains of type " "<quote>application</quote>" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1702 +#: sssd.conf.5.xml:1694 msgid "pam_p11_allowed_services (string)" msgstr "pam_p11_allowed_services (řetězec)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1705 +#: sssd.conf.5.xml:1697 msgid "" "A comma-separated list of PAM service names for which it will be allowed to " "use Smartcards." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1720 +#: sssd.conf.5.xml:1712 #, no-wrap msgid "" "pam_p11_allowed_services = +my_pam_service, -login\n" @@ -2123,7 +2116,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1709 +#: sssd.conf.5.xml:1701 msgid "" "It is possible to add another PAM service name to the default set by using " "<quote>+service_name</quote> or to explicitly remove a PAM service name from " @@ -2135,68 +2128,75 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1724 sssd-ad.5.xml:645 sssd-ad.5.xml:754 sssd-ad.5.xml:812 -#: sssd-ad.5.xml:870 sssd-ad.5.xml:948 +#: sssd.conf.5.xml:1716 sssd-ad.5.xml:645 sssd-ad.5.xml:759 sssd-ad.5.xml:817 +#: sssd-ad.5.xml:875 sssd-ad.5.xml:953 msgid "Default: the default set of PAM service names includes:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1729 sssd-ad.5.xml:649 +#: sssd.conf.5.xml:1721 sssd-ad.5.xml:649 msgid "login" msgstr "přihlášení" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1734 sssd-ad.5.xml:654 +#: sssd.conf.5.xml:1726 sssd-ad.5.xml:654 msgid "su" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1739 sssd-ad.5.xml:659 +#: sssd.conf.5.xml:1731 sssd-ad.5.xml:659 msgid "su-l" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1744 sssd-ad.5.xml:674 +#: sssd.conf.5.xml:1736 sssd-ad.5.xml:674 msgid "gdm-smartcard" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1749 sssd-ad.5.xml:669 +#: sssd.conf.5.xml:1741 sssd-ad.5.xml:669 msgid "gdm-password" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1754 +#: sssd.conf.5.xml:1746 msgid "gdm-switchable-auth" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1759 sssd-ad.5.xml:679 +#: sssd.conf.5.xml:1751 sssd-ad.5.xml:679 msgid "kdm" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1764 sssd-ad.5.xml:957 +#: sssd.conf.5.xml:1756 sssd-ad.5.xml:694 +#, fuzzy +#| msgid "login" +msgid "plasmalogin" +msgstr "přihlášení" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:1761 sssd-ad.5.xml:962 msgid "sudo" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1769 sssd-ad.5.xml:962 +#: sssd.conf.5.xml:1766 sssd-ad.5.xml:967 msgid "sudo-i" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1774 +#: sssd.conf.5.xml:1771 msgid "gnome-screensaver" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1782 +#: sssd.conf.5.xml:1779 msgid "p11_wait_for_card_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1785 +#: sssd.conf.5.xml:1782 msgid "" "If Smartcard authentication is required how many extra seconds in addition " "to p11_child_timeout should the PAM responder wait until a Smartcard is " @@ -2204,12 +2204,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1796 +#: sssd.conf.5.xml:1793 msgid "p11_uri (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1799 +#: sssd.conf.5.xml:1796 msgid "" "PKCS#11 URI (see RFC-7512 for details) which can be used to restrict the " "selection of devices used for Smartcard authentication. By default SSSD's " @@ -2220,7 +2220,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1812 +#: sssd.conf.5.xml:1809 #, no-wrap msgid "" "p11_uri = pkcs11:slot-description=My%20Smartcard%20Reader\n" @@ -2228,7 +2228,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1816 +#: sssd.conf.5.xml:1813 #, no-wrap msgid "" "p11_uri = pkcs11:library-description=OpenSC%20smartcard%20framework;slot-id=2\n" @@ -2236,7 +2236,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1810 +#: sssd.conf.5.xml:1807 msgid "" "Example: <placeholder type=\"programlisting\" id=\"0\"/> or <placeholder " "type=\"programlisting\" id=\"1\"/> To find suitable URI please check the " @@ -2245,47 +2245,49 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1829 -msgid "pam_initgroups_scheme" -msgstr "" +#: sssd.conf.5.xml:1826 +#, fuzzy +#| msgid "pam_p11_allowed_services (string)" +msgid "pam_initgroups_scheme (string)" +msgstr "pam_p11_allowed_services (řetězec)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1837 +#: sssd.conf.5.xml:1834 msgid "always" msgstr "vždy" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1838 +#: sssd.conf.5.xml:1835 msgid "" "Always do an online lookup, please note that pam_id_timeout still applies" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1842 +#: sssd.conf.5.xml:1839 msgid "no_session" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1843 +#: sssd.conf.5.xml:1840 msgid "" "Only do an online lookup if there is no active session of the user, i.e. if " "the user is currently not logged in" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1848 sssd-ldap.5.xml:189 +#: sssd.conf.5.xml:1845 sssd-ldap.5.xml:189 msgid "never" msgstr "nikdy" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1849 +#: sssd.conf.5.xml:1846 msgid "" "Never force an online lookup, use the data from the cache as long as they " "are not expired" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1832 +#: sssd.conf.5.xml:1829 msgid "" "The PAM responder can force an online lookup to get the current group " "memberships of the user trying to log in. This option controls when this " @@ -2294,30 +2296,32 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1856 +#: sssd.conf.5.xml:1853 msgid "Default: no_session" msgstr "" -#. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:1861 sssd.conf.5.xml:4277 -msgid "pam_gssapi_services" -msgstr "" +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1858 +#, fuzzy +#| msgid "pam_p11_allowed_services (string)" +msgid "pam_gssapi_services (string)" +msgstr "pam_p11_allowed_services (řetězec)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1864 +#: sssd.conf.5.xml:1861 msgid "" "Comma separated list of PAM services that are allowed to try GSSAPI " "authentication using pam_sss_gss.so module." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1869 +#: sssd.conf.5.xml:1866 msgid "" "To disable GSSAPI authentication, set this option to <quote>-</quote> (dash)." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1873 sssd.conf.5.xml:1904 sssd.conf.5.xml:1942 +#: sssd.conf.5.xml:1870 sssd.conf.5.xml:1901 sssd.conf.5.xml:1939 msgid "" "Note: This option can also be set per-domain which overwrites the value in " "[pam] section. It can also be set for trusted domain which overwrites the " @@ -2325,7 +2329,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1881 +#: sssd.conf.5.xml:1878 #, no-wrap msgid "" "pam_gssapi_services = sudo, sudo-i\n" @@ -2333,22 +2337,22 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1879 sssd.conf.5.xml:1994 sssd.conf.5.xml:3836 +#: sssd.conf.5.xml:1876 sssd.conf.5.xml:2023 sssd.conf.5.xml:4042 msgid "Example: <placeholder type=\"programlisting\" id=\"0\"/>" msgstr "Příklad: <placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1885 +#: sssd.conf.5.xml:1882 msgid "Default: - (GSSAPI authentication is disabled)" msgstr "" -#. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:1890 sssd.conf.5.xml:4278 -msgid "pam_gssapi_check_upn" +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1887 +msgid "pam_gssapi_check_upn (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1893 +#: sssd.conf.5.xml:1890 msgid "" "If True, SSSD will require that the Kerberos user principal that " "successfully authenticated through GSSAPI can be associated with the user " @@ -2356,19 +2360,21 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1900 +#: sssd.conf.5.xml:1897 msgid "" -"If False, every user that is able to obtained required service ticket will " +"If False, every user that is able to obtain a required service ticket will " "be authenticated." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1915 -msgid "pam_gssapi_indicators_map" -msgstr "" +#: sssd.conf.5.xml:1912 +#, fuzzy +#| msgid "pam_p11_allowed_services (string)" +msgid "pam_gssapi_indicators_map (string)" +msgstr "pam_p11_allowed_services (řetězec)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1918 +#: sssd.conf.5.xml:1915 msgid "" "Comma separated list of authentication indicators required to be present in " "a Kerberos ticket to access a PAM service that is allowed to try GSSAPI " @@ -2376,7 +2382,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1924 +#: sssd.conf.5.xml:1921 msgid "" "Each element of the list can be either an authentication indicator name or a " "pair <quote>service:indicator</quote>. Indicators not prefixed with the PAM " @@ -2391,7 +2397,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1937 +#: sssd.conf.5.xml:1934 msgid "" "To disable GSSAPI authentication indicator check, set this option to <quote>-" "</quote> (dash). To disable the check for a specific PAM service, add " @@ -2399,45 +2405,45 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1948 +#: sssd.conf.5.xml:1945 msgid "" "Following authentication indicators are supported by IPA Kerberos " "deployments:" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1951 +#: sssd.conf.5.xml:1948 msgid "" "pkinit -- pre-authentication using X.509 certificates -- whether stored in " "files or on smart cards." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1954 +#: sssd.conf.5.xml:1951 msgid "" "hardened -- SPAKE pre-authentication or any pre-authentication wrapped in a " "FAST channel." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1957 +#: sssd.conf.5.xml:1954 msgid "radius -- pre-authentication with the help of a RADIUS server." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1960 +#: sssd.conf.5.xml:1957 msgid "" "otp -- pre-authentication using integrated two-factor authentication (2FA or " "one-time password, OTP) in IPA." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1963 +#: sssd.conf.5.xml:1960 msgid "idp -- pre-authentication using external identity provider." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1973 +#: sssd.conf.5.xml:1970 #, no-wrap msgid "" "pam_gssapi_indicators_map = sudo:pkinit, sudo-i:pkinit\n" @@ -2445,7 +2451,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1968 +#: sssd.conf.5.xml:1965 msgid "" "Example: to require access to SUDO services only for users which obtained " "their Kerberos tickets with a X.509 certificate pre-authentication (PKINIT), " @@ -2453,31 +2459,70 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1977 +#: sssd.conf.5.xml:1974 msgid "Default: not set (use of authentication indicators is not required)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1979 +msgid "pam_gssapi_indicators_apply (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1982 +msgid "" +"Comma separated list of triples to assign additional information from the " +"Kerberos ticket, e.g. a SID from the PAC, to authentication indicators." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1988 +msgid "Currently supported is:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:1991 +msgid "SID:S-1-5-[domain]-[RID]:[authentication indicator]" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> +#: sssd.conf.5.xml:2002 +#, no-wrap +msgid "" +"pam_gssapi_indicators_apply = SID:S-1-5-12345-23456-34567-4321:pkinit\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1996 +msgid "" +"Example: To assign a SID, which is e.g. set by Active Directory's " +"Authentication Mechanism Assurance (AMA) if the AD user used a Smartcard for " +"authentication, to the 'pkinit' authentication indicator use: <placeholder " +"type=\"programlisting\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2011 #, fuzzy #| msgid "pam_p11_allowed_services (string)" msgid "pam_json_services (string)" msgstr "pam_p11_allowed_services (řetězec)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1985 +#: sssd.conf.5.xml:2014 msgid "" "Comma separated list of PAM services which can handle the JSON protocol for " "selecting authentication mechanisms" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1990 +#: sssd.conf.5.xml:2019 msgid "To disable JSON protocol, set this option to <quote>-</quote> (dash)." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1996 +#: sssd.conf.5.xml:2025 #, no-wrap msgid "" "pam_json_services = gdm-switchable-auth\n" @@ -2485,52 +2530,59 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2000 +#: sssd.conf.5.xml:2029 msgid "Default: - (JSON protocol is disabled)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2003 +#: sssd.conf.5.xml:2032 msgid "" "Note: 2-Factor Authentication (2FA) is not supported. If 2FA is required, do " "not activate the JSON protocol." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:2013 +#: sssd.conf.5.xml:2042 msgid "SUDO configuration options" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2015 +#: sssd.conf.5.xml:2044 +msgid "" +"These options can be used to configure the sudo service and should be " +"specified under the <quote>[sudo]</quote> section." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:2048 msgid "" -"These options can be used to configure the sudo service. The detailed " -"instructions for configuration of <citerefentry> <refentrytitle>sudo</" -"refentrytitle> <manvolnum>8</manvolnum> </citerefentry> to work with " -"<citerefentry> <refentrytitle>sssd</refentrytitle> <manvolnum>8</manvolnum> " -"</citerefentry> are in the manual page <citerefentry> <refentrytitle>sssd-" -"sudo</refentrytitle> <manvolnum>5</manvolnum> </citerefentry>." +"The detailed instructions for configuration of <citerefentry> " +"<refentrytitle>sudo</refentrytitle> <manvolnum>8</manvolnum> </citerefentry> " +"to work with <citerefentry> <refentrytitle>sssd</refentrytitle> " +"<manvolnum>8</manvolnum> </citerefentry> are in the manual page " +"<citerefentry> <refentrytitle>sssd-sudo</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry>." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2032 -msgid "sudo_timed (bool)" +#: sssd.conf.5.xml:2064 +msgid "sudo_timed (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2035 +#: sssd.conf.5.xml:2067 msgid "" "Whether or not to evaluate the sudoNotBefore and sudoNotAfter attributes " "that implement time-dependent sudoers entries." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2047 +#: sssd.conf.5.xml:2079 msgid "sudo_threshold (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2050 +#: sssd.conf.5.xml:2082 msgid "" "Maximum number of expired rules that can be refreshed at once. If number of " "expired rules is below threshold, those rules are refreshed with " @@ -2540,22 +2592,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:2069 +#: sssd.conf.5.xml:2101 msgid "AUTOFS configuration options" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2071 -msgid "These options can be used to configure the autofs service." +#: sssd.conf.5.xml:2103 +msgid "" +"These options can be used to configure the autofs service and should be " +"specified under the <quote>[autofs]</quote> section." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2075 +#: sssd.conf.5.xml:2109 msgid "autofs_negative_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2078 +#: sssd.conf.5.xml:2112 msgid "" "Specifies for how many seconds should the autofs responder negative cache " "hits (that is, queries for invalid map entries, like nonexistent ones) " @@ -2563,22 +2617,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:2094 +#: sssd.conf.5.xml:2128 msgid "SSH configuration options" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2096 -msgid "These options can be used to configure the SSH service." +#: sssd.conf.5.xml:2130 +msgid "" +"These options can be used to configure the SSH service and should be " +"specified under the <quote>[ssh]</quote> section." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2100 -msgid "ssh_use_certificate_keys (bool)" +#: sssd.conf.5.xml:2136 +msgid "ssh_use_certificate_keys (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2103 +#: sssd.conf.5.xml:2139 msgid "" "If set to true the <command>sss_ssh_authorizedkeys</command> will return ssh " "keys derived from the public key of X.509 certificates stored in the user " @@ -2587,12 +2643,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2118 +#: sssd.conf.5.xml:2154 msgid "ssh_use_certificate_matching_rules (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2121 +#: sssd.conf.5.xml:2157 msgid "" "By default the ssh responder will use all available certificate matching " "rules to filter the certificates so that ssh keys are only derived from the " @@ -2602,7 +2658,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2130 +#: sssd.conf.5.xml:2166 msgid "" "There are two special key words 'all_rules' and 'no_rules' which will enable " "all or no rules, respectively. The latter means that no certificates will be " @@ -2610,7 +2666,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2137 +#: sssd.conf.5.xml:2173 msgid "" "If no rules are configured using 'all_rules' will enable a default rule " "which enables all certificates suitable for client authentication. This is " @@ -2619,38 +2675,38 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2144 +#: sssd.conf.5.xml:2180 msgid "" "A non-existing rule name is considered an error. If as a result no rule is " "selected all certificates will be ignored." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2149 +#: sssd.conf.5.xml:2185 msgid "" "Default: not set, equivalent to 'all_rules', all found rules or the default " "rule are used" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2155 +#: sssd.conf.5.xml:2191 msgid "ca_db (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2158 +#: sssd.conf.5.xml:2194 msgid "" "Path to a storage of trusted CA certificates. The option is used to validate " "user certificates before deriving public ssh keys from them." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:2178 +#: sssd.conf.5.xml:2214 msgid "PAC responder configuration options" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2180 +#: sssd.conf.5.xml:2216 msgid "" "The PAC responder works together with the authorization data plugin for MIT " "Kerberos sssd_pac_plugin.so and a sub-domain provider. The plugin sends the " @@ -2661,7 +2717,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:2189 +#: sssd.conf.5.xml:2225 msgid "" "If the remote user does not exist in the cache, it is created. The UID is " "determined with the help of the SID, trusted domains will have UPGs and the " @@ -2672,24 +2728,26 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:2197 +#: sssd.conf.5.xml:2233 msgid "" "If there are SIDs of groups from domains sssd knows about, the user will be " "added to those groups." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2203 -msgid "These options can be used to configure the PAC responder." +#: sssd.conf.5.xml:2239 +msgid "" +"These options can be used to configure the PAC responder and should be " +"specified under the <quote>[pac]</quote> section." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2207 sssd-ifp.5.xml:66 +#: sssd.conf.5.xml:2244 sssd-ifp.5.xml:66 msgid "allowed_uids (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2210 +#: sssd.conf.5.xml:2247 msgid "" "Specifies the comma-separated list of UID values or user names that are " "allowed to access the PAC responder. User names are resolved to UIDs at " @@ -2697,19 +2755,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2216 +#: sssd.conf.5.xml:2253 msgid "" "Default: 0, &sssd_user_name; (only root and SSSD service users are allowed " "to access the PAC responder)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2220 +#: sssd.conf.5.xml:2257 msgid "Default: 0 (only the root user is allowed to access the PAC responder)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2224 +#: sssd.conf.5.xml:2261 msgid "" "Please note that defaults will be overwritten with this option. If you still " "want to allow the root and/or '&sssd_user_name;' user to access the PAC " @@ -2718,7 +2776,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2231 +#: sssd.conf.5.xml:2268 msgid "" "Please note that although the UID 0 is used as the default it will be " "overwritten with this option. If you still want to allow the root user to " @@ -2727,24 +2785,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2240 +#: sssd.conf.5.xml:2277 msgid "pac_lifetime (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2243 +#: sssd.conf.5.xml:2280 msgid "" "Lifetime of the PAC entry in seconds. As long as the PAC is valid the PAC " "data can be used to determine the group memberships of a user." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2253 +#: sssd.conf.5.xml:2290 msgid "pac_check (string)" msgstr "pac_check (řetězec)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2256 +#: sssd.conf.5.xml:2293 msgid "" "Apply additional checks on the PAC of the Kerberos ticket which is available " "in Active Directory and FreeIPA domains, if configured. Please note that " @@ -2755,7 +2813,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2266 +#: sssd.conf.5.xml:2303 msgid "" "Please note that the checks listed below only apply to PACs issued by Active " "Directory or recent versions of FreeIPA. PACs issued e.g. by a plain MIT " @@ -2763,24 +2821,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2277 +#: sssd.conf.5.xml:2314 msgid "no_check" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2279 +#: sssd.conf.5.xml:2316 msgid "" "The PAC must not be present and even if it is present no additional checks " "will be done." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2285 +#: sssd.conf.5.xml:2322 msgid "pac_present" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2287 +#: sssd.conf.5.xml:2324 msgid "" "The PAC must be present in the service ticket which SSSD will request with " "the help of the user's TGT. If the PAC is not available the authentication " @@ -2788,24 +2846,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2295 +#: sssd.conf.5.xml:2332 msgid "check_upn" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2297 +#: sssd.conf.5.xml:2334 msgid "" "If the PAC is present check if the user principal name (UPN) information is " "consistent." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2303 +#: sssd.conf.5.xml:2340 msgid "check_upn_allow_missing" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2305 +#: sssd.conf.5.xml:2342 msgid "" "This option should be used together with 'check_upn' and handles the case " "where a UPN is set on the server-side but is not read by SSSD. The typical " @@ -2817,7 +2875,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2317 +#: sssd.conf.5.xml:2354 msgid "" "Currently this option is set by default to avoid regressions in such " "environments. A log message will be added to the system log and SSSD's debug " @@ -2828,60 +2886,60 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2331 +#: sssd.conf.5.xml:2368 msgid "upn_dns_info_present" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2333 +#: sssd.conf.5.xml:2370 msgid "The PAC must contain the UPN-DNS-INFO buffer, implies 'check_upn'." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2338 +#: sssd.conf.5.xml:2375 msgid "check_upn_dns_info_ex" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2340 +#: sssd.conf.5.xml:2377 msgid "" "If the PAC is present and the extension to the UPN-DNS-INFO buffer is " "available check if the information in the extension is consistent." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2347 +#: sssd.conf.5.xml:2384 msgid "upn_dns_info_ex_present" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2349 +#: sssd.conf.5.xml:2386 msgid "" "The PAC must contain the extension of the UPN-DNS-INFO buffer, implies " "'check_upn_dns_info_ex', 'upn_dns_info_present' and 'check_upn'." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2273 +#: sssd.conf.5.xml:2310 msgid "" "The following options can be used alone or in a comma-separated list: " "<placeholder type=\"variablelist\" id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2359 +#: sssd.conf.5.xml:2396 msgid "" "Default: no_check (AD and IPA provider 'check_upn, check_upn_allow_missing, " "check_upn_dns_info_ex')" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:2368 +#: sssd.conf.5.xml:2405 msgid "Session recording configuration options" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2370 +#: sssd.conf.5.xml:2407 msgid "" "Session recording works in conjunction with <citerefentry> " "<refentrytitle>tlog-rec-session</refentrytitle> <manvolnum>8</manvolnum> </" @@ -2891,49 +2949,61 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2383 -msgid "These options can be used to configure session recording." +#: sssd.conf.5.xml:2420 +msgid "" +"These options can be used to configure session recording and should be " +"specified under the <quote>[session_recording]</quote> section." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:2425 +msgid "" +"Note: Unlike other sections, the <quote>[session_recording]</quote> section " +"ignores <replaceable>debug*</replaceable> options and suitable " +"<replaceable>debug*</replaceable> options must be set in <quote>[pam]</" +"quote>, <quote>[nss]</quote> and <quote>[domain/<replaceable>NAME</" +"replaceable>]</quote> sections." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2387 sssd-session-recording.5.xml:64 +#: sssd.conf.5.xml:2433 sssd-session-recording.5.xml:64 msgid "scope (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2394 sssd-session-recording.5.xml:71 +#: sssd.conf.5.xml:2440 sssd-session-recording.5.xml:71 msgid "\"none\"" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2397 sssd-session-recording.5.xml:74 +#: sssd.conf.5.xml:2443 sssd-session-recording.5.xml:74 msgid "No users are recorded." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2402 sssd-session-recording.5.xml:79 +#: sssd.conf.5.xml:2448 sssd-session-recording.5.xml:79 msgid "\"some\"" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2405 sssd-session-recording.5.xml:82 +#: sssd.conf.5.xml:2451 sssd-session-recording.5.xml:82 msgid "" "Users/groups specified by <replaceable>users</replaceable> and " "<replaceable>groups</replaceable> options are recorded." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2414 sssd-session-recording.5.xml:91 +#: sssd.conf.5.xml:2460 sssd-session-recording.5.xml:91 msgid "\"all\"" msgstr "\"vše\"" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2417 sssd-session-recording.5.xml:94 +#: sssd.conf.5.xml:2463 sssd-session-recording.5.xml:94 msgid "All users are recorded." msgstr "Všichni uživatelé jsou zaznamenáni." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2390 sssd-session-recording.5.xml:67 +#: sssd.conf.5.xml:2436 sssd-session-recording.5.xml:67 msgid "" "One of the following strings specifying the scope of session recording: " "<placeholder type=\"variablelist\" id=\"0\"/>" @@ -2942,17 +3012,17 @@ msgstr "" "type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2424 sssd-session-recording.5.xml:101 +#: sssd.conf.5.xml:2470 sssd-session-recording.5.xml:101 msgid "Default: \"none\"" msgstr "Výchozí: nic" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2429 sssd-session-recording.5.xml:106 +#: sssd.conf.5.xml:2475 sssd-session-recording.5.xml:106 msgid "users (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2432 sssd-session-recording.5.xml:109 +#: sssd.conf.5.xml:2478 sssd-session-recording.5.xml:109 msgid "" "A comma-separated list of users which should have session recording enabled. " "Matches user names as returned by NSS. I.e. after the possible space " @@ -2963,17 +3033,17 @@ msgstr "" "mezer, změně velikosti písmen, atd." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2438 sssd-session-recording.5.xml:115 +#: sssd.conf.5.xml:2484 sssd-session-recording.5.xml:115 msgid "Default: Empty. Matches no users." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2443 sssd-session-recording.5.xml:120 +#: sssd.conf.5.xml:2489 sssd-session-recording.5.xml:120 msgid "groups (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2446 sssd-session-recording.5.xml:123 +#: sssd.conf.5.xml:2492 sssd-session-recording.5.xml:123 msgid "" "A comma-separated list of groups, members of which should have session " "recording enabled. Matches group names as returned by NSS. I.e. after the " @@ -2984,7 +3054,7 @@ msgstr "" "nahrazení mezer, změn velikosti písmen, atd." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2452 sssd.conf.5.xml:2484 sssd-session-recording.5.xml:129 +#: sssd.conf.5.xml:2498 sssd.conf.5.xml:2530 sssd-session-recording.5.xml:129 #: sssd-session-recording.5.xml:161 msgid "" "NOTE: using this option (having it set to anything) has a considerable " @@ -2993,17 +3063,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2459 sssd-session-recording.5.xml:136 +#: sssd.conf.5.xml:2505 sssd-session-recording.5.xml:136 msgid "Default: Empty. Matches no groups." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2464 sssd-session-recording.5.xml:141 +#: sssd.conf.5.xml:2510 sssd-session-recording.5.xml:141 msgid "exclude_users (string)" msgstr "exclude_users (řetězec)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2467 sssd-session-recording.5.xml:144 +#: sssd.conf.5.xml:2513 sssd-session-recording.5.xml:144 msgid "" "A comma-separated list of users to be excluded from recording, only " "applicable with 'scope=all'." @@ -3012,17 +3082,17 @@ msgstr "" "použitelný pouze s 'scope=all'." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2471 sssd-session-recording.5.xml:148 +#: sssd.conf.5.xml:2517 sssd-session-recording.5.xml:148 msgid "Default: Empty. No users excluded." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2476 sssd-session-recording.5.xml:153 +#: sssd.conf.5.xml:2522 sssd-session-recording.5.xml:153 msgid "exclude_groups (string)" msgstr "exclude_groups (řetězec)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2479 sssd-session-recording.5.xml:156 +#: sssd.conf.5.xml:2525 sssd-session-recording.5.xml:156 msgid "" "A comma-separated list of groups, members of which should be excluded from " "recording. Only applicable with 'scope=all'." @@ -3031,23 +3101,22 @@ msgstr "" "záznamu. Použitelné pouze s 'scope=all'." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2491 sssd-session-recording.5.xml:168 +#: sssd.conf.5.xml:2537 sssd-session-recording.5.xml:168 msgid "Default: Empty. No groups excluded." msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:2501 +#: sssd.conf.5.xml:2547 msgid "DOMAIN SECTIONS" msgstr "" -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry><para> -#: sssd.conf.5.xml:2508 sssd.conf.5.xml:3964 sssd.conf.5.xml:3965 -#: sssd.conf.5.xml:3968 -msgid "enabled" -msgstr "povoleno" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2554 +msgid "enabled (boolean)" +msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2511 +#: sssd.conf.5.xml:2557 msgid "" "Explicitly enable or disable the domain. If <quote>true</quote>, the domain " "is always <quote>enabled</quote>. If <quote>false</quote>, the domain is " @@ -3057,12 +3126,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2523 +#: sssd.conf.5.xml:2569 msgid "domain_type (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2526 +#: sssd.conf.5.xml:2572 msgid "" "Specifies whether the domain is meant to be used by POSIX-aware clients such " "as the Name Service Switch or by applications that do not need POSIX data to " @@ -3071,14 +3140,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2534 +#: sssd.conf.5.xml:2580 msgid "" "Allowed values for this option are <quote>posix</quote> and " "<quote>application</quote>." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2538 +#: sssd.conf.5.xml:2584 msgid "" "POSIX domains are reachable by all services. Application domains are only " "reachable from the InfoPipe responder (see <citerefentry> " @@ -3087,38 +3156,38 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2546 +#: sssd.conf.5.xml:2592 msgid "" "NOTE: The application domains are currently well tested with " "<quote>id_provider=ldap</quote> only." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2550 +#: sssd.conf.5.xml:2596 msgid "" "For an easy way to configure a non-POSIX domains, please see the " "<quote>Application domains</quote> section." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2554 +#: sssd.conf.5.xml:2600 msgid "Default: posix" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2560 +#: sssd.conf.5.xml:2606 msgid "min_id,max_id (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2563 +#: sssd.conf.5.xml:2609 msgid "" "UID and GID limits for the domain. If a domain contains an entry that is " "outside these limits, it is ignored." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2568 +#: sssd.conf.5.xml:2614 msgid "" "For users, this affects the primary GID limit. The user will not be returned " "to NSS if either the UID or the primary GID is outside the range. For non-" @@ -3127,24 +3196,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2575 +#: sssd.conf.5.xml:2621 msgid "" "These ID limits affect even saving entries to cache, not only returning them " "by name or ID." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2579 +#: sssd.conf.5.xml:2625 msgid "Default: 1 for min_id, 0 (no limit) for max_id" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2585 -msgid "enumerate (bool)" +#: sssd.conf.5.xml:2631 +msgid "enumerate (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2588 +#: sssd.conf.5.xml:2634 msgid "" "Determines if a domain can be enumerated, that is, whether the domain can " "list all the users and group it contains. Note that it is not required to " @@ -3153,36 +3222,36 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2596 +#: sssd.conf.5.xml:2642 msgid "TRUE = Users and groups are enumerated" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2599 +#: sssd.conf.5.xml:2645 msgid "FALSE = No enumerations for this domain" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2602 sssd.conf.5.xml:2867 sssd.conf.5.xml:3044 +#: sssd.conf.5.xml:2648 sssd.conf.5.xml:2992 sssd.conf.5.xml:3174 msgid "Default: FALSE" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2605 +#: sssd.conf.5.xml:2651 msgid "" "Enumerating a domain requires SSSD to download and store ALL user and group " "entries from the remote server." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2610 +#: sssd.conf.5.xml:2656 msgid "" "Feature is only supported for domains with id_provider = ldap or id_provider " "= proxy." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2614 +#: sssd.conf.5.xml:2660 msgid "" "Note: Enabling enumeration has a severe performance impact on SSSD while " "enumeration is running. It may take up to several minutes after SSSD startup " @@ -3196,14 +3265,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2629 +#: sssd.conf.5.xml:2675 msgid "" "While the first enumeration is running, requests for the complete user or " "group lists may return no results until it completes." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2634 +#: sssd.conf.5.xml:2680 msgid "" "Further, enabling enumeration may increase the time necessary to detect " "network disconnection, as longer timeouts are required to ensure that " @@ -3212,14 +3281,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2642 +#: sssd.conf.5.xml:2688 msgid "" "For the reasons cited above, enabling enumeration is not recommended, " "especially in large environments." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2647 +#: sssd.conf.5.xml:2693 msgid "" "Note: the proxy provider is tested with open source modules like " "'libnss_files' and 'libnss_ldap'. 3rd party modules must follow the " @@ -3227,19 +3296,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2656 +#: sssd.conf.5.xml:2702 msgid "entry_cache_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2659 +#: sssd.conf.5.xml:2705 msgid "" "How many seconds should nss_sss consider entries valid before asking the " "backend again" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2663 +#: sssd.conf.5.xml:2709 msgid "" "The cache expiration timestamps are stored as attributes of individual " "objects in the cache. Therefore, changing the cache timeout only has effect " @@ -3250,108 +3319,108 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2676 +#: sssd.conf.5.xml:2722 msgid "Default: 5400" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2682 +#: sssd.conf.5.xml:2728 msgid "entry_cache_user_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2685 +#: sssd.conf.5.xml:2731 msgid "" "How many seconds should nss_sss consider user entries valid before asking " "the backend again" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2689 sssd.conf.5.xml:2702 sssd.conf.5.xml:2715 -#: sssd.conf.5.xml:2728 sssd.conf.5.xml:2742 sssd.conf.5.xml:2755 -#: sssd.conf.5.xml:2769 sssd.conf.5.xml:2783 sssd.conf.5.xml:2796 +#: sssd.conf.5.xml:2735 sssd.conf.5.xml:2748 sssd.conf.5.xml:2761 +#: sssd.conf.5.xml:2774 sssd.conf.5.xml:2788 sssd.conf.5.xml:2801 +#: sssd.conf.5.xml:2815 sssd.conf.5.xml:2829 msgid "Default: entry_cache_timeout" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2695 +#: sssd.conf.5.xml:2741 msgid "entry_cache_group_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2698 +#: sssd.conf.5.xml:2744 msgid "" "How many seconds should nss_sss consider group entries valid before asking " "the backend again" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2708 +#: sssd.conf.5.xml:2754 msgid "entry_cache_netgroup_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2711 +#: sssd.conf.5.xml:2757 msgid "" "How many seconds should nss_sss consider netgroup entries valid before " "asking the backend again" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2721 +#: sssd.conf.5.xml:2767 msgid "entry_cache_service_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2724 +#: sssd.conf.5.xml:2770 msgid "" "How many seconds should nss_sss consider service entries valid before asking " "the backend again" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2734 +#: sssd.conf.5.xml:2780 msgid "entry_cache_resolver_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2737 +#: sssd.conf.5.xml:2783 msgid "" "How many seconds should nss_sss consider hosts and networks entries valid " "before asking the backend again" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2748 +#: sssd.conf.5.xml:2794 msgid "entry_cache_sudo_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2751 +#: sssd.conf.5.xml:2797 msgid "" "How many seconds should sudo consider rules valid before asking the backend " "again" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2761 +#: sssd.conf.5.xml:2807 msgid "entry_cache_autofs_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2764 +#: sssd.conf.5.xml:2810 msgid "" "How many seconds should the autofs service consider automounter maps valid " "before asking the backend again" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2775 +#: sssd.conf.5.xml:2821 msgid "entry_cache_ssh_host_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2778 +#: sssd.conf.5.xml:2824 msgid "" "How many seconds to keep a host ssh key after refresh. IE how long to cache " "the host key for." @@ -3360,31 +3429,136 @@ msgstr "" "dlouhou dobu ponechávat klíč hostitel v mezipaměti." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2789 -msgid "entry_cache_computer_timeout (integer)" +#: sssd.conf.5.xml:2835 +msgid "offline_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2792 +#: sssd.conf.5.xml:2838 msgid "" -"How many seconds to keep the local computer entry before asking the backend " -"again" +"When SSSD switches to offline mode the amount of time before it tries to go " +"back online will increase based upon the time spent disconnected. By " +"default SSSD uses incremental behaviour to calculate delay in between " +"retries. So, the wait time for a given retry will be longer than the wait " +"time for the previous ones. After each unsuccessful attempt to go online, " +"the new interval is recalculated by the following:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2849 sssd.conf.5.xml:2907 +msgid "" +"new_delay = Minimum(old_delay * 2, offline_timeout_max) + " +"random[0...offline_timeout_random_offset]" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2852 +msgid "" +"The offline_timeout default value is 60. The offline_timeout_max default " +"value is 3600. The offline_timeout_random_offset default value is 30. The " +"end result is the number of seconds before next retry." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2858 +msgid "" +"Note that the maximum length of each interval is defined by " +"offline_timeout_max (apart from the random part)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2868 +msgid "offline_timeout_max (integer)" +msgstr "offline_timeout_max (celé číslo)" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2871 +msgid "" +"Controls by how much the time between attempts to go online can be " +"incremented following unsuccessful attempts to go online." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2876 +msgid "A value of 0 disables the incrementing behaviour." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2879 +msgid "" +"The value of this parameter should be set in correlation to offline_timeout " +"parameter value." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2883 +msgid "" +"With offline_timeout set to 60 (default value) there is no point in setting " +"offline_timeout_max to less than 120 as it will saturate instantly. General " +"rule here should be to set offline_timeout_max to at least 4 times " +"offline_timeout." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2889 +msgid "" +"Although a value between 0 and offline_timeout may be specified, it has the " +"effect of overriding the offline_timeout value so is of little use." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2894 +msgid "Default: 3600" +msgstr "Výchozí: 3600" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2900 +msgid "offline_timeout_random_offset (integer)" +msgstr "offline_timeout_random_offset (celé číslo)" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2903 +msgid "" +"When SSSD is in offline mode it keeps probing backend servers in specified " +"time intervals:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2910 +msgid "" +"This parameter controls the value of the random offset used for the above " +"equation. Final random_offset value will be random number in range:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2915 +msgid "[0 - offline_timeout_random_offset]" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2918 +msgid "A value of 0 disables the random offset addition." msgstr "" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2921 +msgid "Default: 30" +msgstr "Výchozí: 30" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2802 +#: sssd.conf.5.xml:2927 msgid "refresh_expired_interval (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2805 +#: sssd.conf.5.xml:2930 msgid "" "Specifies how many seconds SSSD has to wait before triggering a background " "refresh task which will refresh all expired or nearly expired records." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2810 +#: sssd.conf.5.xml:2935 msgid "" "The background refresh will process users, groups and netgroups in the " "cache. For users who have performed the initgroups (get group membership for " @@ -3393,17 +3567,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2818 +#: sssd.conf.5.xml:2943 msgid "This option is automatically inherited for all trusted domains." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2822 +#: sssd.conf.5.xml:2947 msgid "You can consider setting this value to 3/4 * entry_cache_timeout." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2826 +#: sssd.conf.5.xml:2951 msgid "" "Cache entry will be refreshed by background task when 2/3 of cache timeout " "has already passed. If there are existing cached entries, the background " @@ -3415,18 +3589,18 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2839 sssd-ldap.5.xml:406 sssd-ldap.5.xml:1834 -#: sssd-ipa.5.xml:255 +#: sssd.conf.5.xml:2964 sssd-ldap.5.xml:406 sssd-ldap.5.xml:1834 +#: sssd-ipa.5.xml:250 msgid "Default: 0 (disabled)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2845 -msgid "cache_credentials (bool)" +#: sssd.conf.5.xml:2970 +msgid "cache_credentials (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2848 +#: sssd.conf.5.xml:2973 msgid "" "Determines if user credentials are also cached in the local LDB cache. The " "cached credentials refer to passwords, which includes the first (long term) " @@ -3437,7 +3611,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2859 +#: sssd.conf.5.xml:2984 msgid "" "Take a note that while credentials are stored as a salted SHA512 hash, this " "still potentially poses some security risk in case an attacker manages to " @@ -3446,12 +3620,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2873 +#: sssd.conf.5.xml:2998 msgid "cache_credentials_minimal_first_factor_length (int)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2876 +#: sssd.conf.5.xml:3001 msgid "" "If 2-Factor-Authentication (2FA) is used and credentials should be saved " "this value determines the minimal length the first authentication factor " @@ -3463,19 +3637,19 @@ msgstr "" "otisk do mezipaměti." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2883 +#: sssd.conf.5.xml:3008 msgid "" "This should avoid that the short PINs of a PIN based 2FA scheme are saved in " "the cache which would make them easy targets for brute-force attacks." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2894 +#: sssd.conf.5.xml:3019 msgid "account_cache_expiration (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2897 +#: sssd.conf.5.xml:3022 msgid "" "Number of days entries are left in cache after last successful login before " "being removed during a cleanup of the cache. 0 means keep forever. The " @@ -3484,17 +3658,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2904 +#: sssd.conf.5.xml:3029 msgid "Default: 0 (unlimited)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2909 +#: sssd.conf.5.xml:3034 msgid "pwd_expiration_warning (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2920 +#: sssd.conf.5.xml:3045 msgid "" "Please note that the backend server has to provide information about the " "expiration time of the password. If this information is missing, sssd " @@ -3503,28 +3677,28 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2927 +#: sssd.conf.5.xml:3052 msgid "Default: 7 (Kerberos), 0 (LDAP)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2933 +#: sssd.conf.5.xml:3058 msgid "id_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2936 +#: sssd.conf.5.xml:3061 msgid "" "The identification provider used for the domain. Supported ID providers are:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2940 +#: sssd.conf.5.xml:3065 msgid "<quote>proxy</quote>: Support a legacy NSS provider." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2943 +#: sssd.conf.5.xml:3068 msgid "" "<quote>ldap</quote>: LDAP provider. See <citerefentry> <refentrytitle>sssd-" "ldap</refentrytitle> <manvolnum>5</manvolnum> </citerefentry> for more " @@ -3532,8 +3706,8 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2951 sssd.conf.5.xml:3070 sssd.conf.5.xml:3129 -#: sssd.conf.5.xml:3192 +#: sssd.conf.5.xml:3076 sssd.conf.5.xml:3200 sssd.conf.5.xml:3259 +#: sssd.conf.5.xml:3322 msgid "" "<quote>ipa</quote>: FreeIPA and Red Hat Identity Management provider. See " "<citerefentry> <refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</" @@ -3541,8 +3715,8 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2960 sssd.conf.5.xml:3079 sssd.conf.5.xml:3138 -#: sssd.conf.5.xml:3201 +#: sssd.conf.5.xml:3085 sssd.conf.5.xml:3209 sssd.conf.5.xml:3268 +#: sssd.conf.5.xml:3331 msgid "" "<quote>ad</quote>: Active Directory provider. See <citerefentry> " "<refentrytitle>sssd-ad</refentrytitle> <manvolnum>5</manvolnum> </" @@ -3550,27 +3724,34 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2968 +#: sssd.conf.5.xml:3093 msgid "" "<quote>idp</quote>: Provider for OAuth 2.0/OIDC based Identity Providers " "(IdP). See <citerefentry> <refentrytitle>sssd-idp</refentrytitle> " "<manvolnum>5</manvolnum> </citerefentry> for more information." msgstr "" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3101 +msgid "" +"Default: Not set (This is a mandatory setting that must be explicitly " +"defined for each configured domain)." +msgstr "" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2979 -msgid "use_fully_qualified_names (bool)" +#: sssd.conf.5.xml:3109 +msgid "use_fully_qualified_names (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2982 +#: sssd.conf.5.xml:3112 msgid "" "Use the full name and domain (as formatted by the domain's full_name_format) " "as the user's login name reported to NSS." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2987 +#: sssd.conf.5.xml:3117 msgid "" "If set to TRUE, all requests to this domain must use fully qualified names. " "For example, if used in EXAMPLE domain that contains a \"test\" user, " @@ -3579,7 +3760,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2995 +#: sssd.conf.5.xml:3125 msgid "" "NOTE: This option has no effect on netgroup lookups due to their tendency to " "include nested netgroups without qualified names. For netgroups, all domains " @@ -3587,24 +3768,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3002 +#: sssd.conf.5.xml:3132 msgid "" "Default: FALSE (TRUE for trusted domain/sub-domains or if " "default_domain_suffix is used)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3009 -msgid "ignore_group_members (bool)" +#: sssd.conf.5.xml:3139 +msgid "ignore_group_members (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3012 +#: sssd.conf.5.xml:3142 msgid "Do not return group members for group lookups." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3015 +#: sssd.conf.5.xml:3145 msgid "" "If set to TRUE, the group membership attribute is not requested from the " "ldap server, and group members are not returned when processing group lookup " @@ -3616,7 +3797,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3033 +#: sssd.conf.5.xml:3163 msgid "" "Enabling this option can also make access provider checks for group " "membership significantly faster, especially for groups containing many " @@ -3624,7 +3805,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3039 sssd.conf.5.xml:3767 sssd-ldap.5.xml:401 +#: sssd.conf.5.xml:3169 sssd.conf.5.xml:3951 sssd-ldap.5.xml:401 #: sssd-ldap.5.xml:454 sssd-ldap.5.xml:529 sssd-ldap.5.xml:576 #: sssd-ldap.5.xml:599 sssd-ldap.5.xml:638 sssd-ldap.5.xml:657 #: sssd-ldap.5.xml:681 sssd-ldap.5.xml:1114 sssd-ldap.5.xml:1147 @@ -3634,19 +3815,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3049 +#: sssd.conf.5.xml:3179 msgid "auth_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3052 +#: sssd.conf.5.xml:3182 msgid "" "The authentication provider used for the domain. Supported auth providers " "are:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3056 sssd.conf.5.xml:3122 +#: sssd.conf.5.xml:3186 sssd.conf.5.xml:3252 msgid "" "<quote>ldap</quote> for native LDAP authentication. See <citerefentry> " "<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> </" @@ -3654,7 +3835,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3063 +#: sssd.conf.5.xml:3193 msgid "" "<quote>krb5</quote> for Kerberos authentication. See <citerefentry> " "<refentrytitle>sssd-krb5</refentrytitle> <manvolnum>5</manvolnum> </" @@ -3662,7 +3843,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3087 +#: sssd.conf.5.xml:3217 msgid "" "<quote>idp</quote>: Provider for OAuth 2.0/OIDC based authentication. See " "<citerefentry> <refentrytitle>sssd-idp</refentrytitle> <manvolnum>5</" @@ -3670,30 +3851,30 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3095 +#: sssd.conf.5.xml:3225 msgid "" "<quote>proxy</quote> for relaying authentication to some other PAM target." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3098 +#: sssd.conf.5.xml:3228 msgid "<quote>none</quote> disables authentication explicitly." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3101 +#: sssd.conf.5.xml:3231 msgid "" "Default: <quote>id_provider</quote> is used if it is set and can handle " "authentication requests." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3107 +#: sssd.conf.5.xml:3237 msgid "access_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3110 +#: sssd.conf.5.xml:3240 msgid "" "The access control provider used for the domain. There are two built-in " "access providers (in addition to any included in installed backends) " @@ -3701,17 +3882,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3116 +#: sssd.conf.5.xml:3246 msgid "<quote>permit</quote> always allow access." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3119 +#: sssd.conf.5.xml:3249 msgid "<quote>deny</quote> always deny access." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3146 +#: sssd.conf.5.xml:3276 msgid "" "<quote>simple</quote> access control based on access or deny lists. See " "<citerefentry> <refentrytitle>sssd-simple</refentrytitle> <manvolnum>5</" @@ -3720,7 +3901,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3153 +#: sssd.conf.5.xml:3283 msgid "" "<quote>krb5</quote>: .k5login based access control. See <citerefentry> " "<refentrytitle>sssd-krb5</refentrytitle> <manvolnum>5</manvolnum></" @@ -3728,29 +3909,29 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3160 +#: sssd.conf.5.xml:3290 msgid "<quote>proxy</quote> for relaying access control to another PAM module." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3163 +#: sssd.conf.5.xml:3293 msgid "Default: <quote>permit</quote>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3168 +#: sssd.conf.5.xml:3298 msgid "chpass_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3171 +#: sssd.conf.5.xml:3301 msgid "" "The provider which should handle change password operations for the domain. " "Supported change password providers are:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3176 +#: sssd.conf.5.xml:3306 msgid "" "<quote>ldap</quote> to change a password stored in a LDAP server. See " "<citerefentry> <refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</" @@ -3758,7 +3939,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3184 +#: sssd.conf.5.xml:3314 msgid "" "<quote>krb5</quote> to change the Kerberos password. See <citerefentry> " "<refentrytitle>sssd-krb5</refentrytitle> <manvolnum>5</manvolnum> </" @@ -3766,35 +3947,35 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3209 +#: sssd.conf.5.xml:3339 msgid "" "<quote>proxy</quote> for relaying password changes to some other PAM target." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3213 +#: sssd.conf.5.xml:3343 msgid "<quote>none</quote> disallows password changes explicitly." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3216 +#: sssd.conf.5.xml:3346 msgid "" "Default: <quote>auth_provider</quote> is used if it is set and can handle " "change password requests." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3223 +#: sssd.conf.5.xml:3353 msgid "sudo_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3226 +#: sssd.conf.5.xml:3356 msgid "The SUDO provider used for the domain. Supported SUDO providers are:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3230 +#: sssd.conf.5.xml:3360 msgid "" "<quote>ldap</quote> for rules stored in LDAP. See <citerefentry> " "<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> </" @@ -3802,33 +3983,33 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3238 +#: sssd.conf.5.xml:3368 msgid "" "<quote>ipa</quote> the same as <quote>ldap</quote> but with IPA default " "settings." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3242 +#: sssd.conf.5.xml:3372 msgid "" "<quote>ad</quote> the same as <quote>ldap</quote> but with AD default " "settings." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3246 +#: sssd.conf.5.xml:3376 msgid "<quote>none</quote> disables SUDO explicitly." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3249 +#: sssd.conf.5.xml:3379 msgid "" "Default: The value of <quote>id_provider</quote> is used if it is set and " "can handle sudo requests." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3253 +#: sssd.conf.5.xml:3383 msgid "" "The detailed instructions for configuration of sudo_provider are in the " "manual page <citerefentry> <refentrytitle>sssd-sudo</refentrytitle> " @@ -3839,7 +4020,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3268 +#: sssd.conf.5.xml:3398 msgid "" "<emphasis>NOTE:</emphasis> Sudo rules are periodically downloaded in the " "background unless the sudo provider is explicitly disabled. Set " @@ -3848,12 +4029,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3278 +#: sssd.conf.5.xml:3408 msgid "selinux_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3281 +#: sssd.conf.5.xml:3411 msgid "" "The provider which should handle loading of selinux settings. Note that this " "provider will be called right after access provider ends. Supported selinux " @@ -3861,7 +4042,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3287 +#: sssd.conf.5.xml:3417 msgid "" "<quote>ipa</quote> to load selinux settings from an IPA server. See " "<citerefentry> <refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</" @@ -3869,31 +4050,32 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3295 +#: sssd.conf.5.xml:3425 msgid "<quote>none</quote> disallows fetching selinux settings explicitly." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3298 +#: sssd.conf.5.xml:3428 msgid "" -"Default: <quote>id_provider</quote> is used if it is set and can handle " -"selinux loading requests." +"Default: the value of <quote>id_provider</quote> is used if it is set and " +"can handle selinux loading requests. Otherwise the result is the same as if " +"the selinux_provider is set to none." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3304 +#: sssd.conf.5.xml:3435 msgid "subdomains_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3307 +#: sssd.conf.5.xml:3438 msgid "" "The provider which should handle fetching of subdomains. This value should " "be always the same as id_provider. Supported subdomain providers are:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3313 +#: sssd.conf.5.xml:3444 msgid "" "<quote>ipa</quote> to load a list of subdomains from an IPA server. See " "<citerefentry> <refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</" @@ -3901,7 +4083,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3322 +#: sssd.conf.5.xml:3453 msgid "" "<quote>ad</quote> to load a list of subdomains from an Active Directory " "server. See <citerefentry> <refentrytitle>sssd-ad</refentrytitle> " @@ -3910,24 +4092,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3331 +#: sssd.conf.5.xml:3462 msgid "<quote>none</quote> disallows fetching subdomains explicitly." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3335 +#: sssd.conf.5.xml:3466 msgid "" "Default: The value of <quote>id_provider</quote> is used if it is set and " "can handle subdomain requests." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3341 +#: sssd.conf.5.xml:3472 msgid "session_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3344 +#: sssd.conf.5.xml:3475 msgid "" "The provider which configures and manages user session related tasks. The " "only user session task currently provided is the integration with Fleet " @@ -3935,36 +4117,36 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3351 +#: sssd.conf.5.xml:3482 msgid "<quote>ipa</quote> to allow performing user session related tasks." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3355 +#: sssd.conf.5.xml:3486 msgid "" "<quote>none</quote> does not perform any kind of user session related tasks." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3359 +#: sssd.conf.5.xml:3490 #, fuzzy #| msgid "Default: none" msgid "Default: <quote>none</quote>." msgstr "Výchozí: nic" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3365 +#: sssd.conf.5.xml:3496 msgid "autofs_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3368 +#: sssd.conf.5.xml:3499 msgid "" "The autofs provider used for the domain. Supported autofs providers are:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3372 +#: sssd.conf.5.xml:3503 msgid "" "<quote>ldap</quote> to load maps stored in LDAP. See <citerefentry> " "<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> </" @@ -3972,7 +4154,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3379 +#: sssd.conf.5.xml:3510 msgid "" "<quote>ipa</quote> to load maps stored in an IPA server. See <citerefentry> " "<refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</manvolnum> </" @@ -3980,7 +4162,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3387 +#: sssd.conf.5.xml:3518 msgid "" "<quote>ad</quote> to load maps stored in an AD server. See <citerefentry> " "<refentrytitle>sssd-ad</refentrytitle> <manvolnum>5</manvolnum> </" @@ -3988,31 +4170,31 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3396 +#: sssd.conf.5.xml:3527 msgid "<quote>none</quote> disables autofs explicitly." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3399 +#: sssd.conf.5.xml:3530 msgid "" "Default: The value of <quote>id_provider</quote> is used if it is set and " "can handle autofs requests." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3406 +#: sssd.conf.5.xml:3537 msgid "hostid_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3409 +#: sssd.conf.5.xml:3540 msgid "" "The provider used for retrieving host identity information. Supported " "hostid providers are:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3413 +#: sssd.conf.5.xml:3544 msgid "" "<quote>ipa</quote> to load host identity stored in an IPA server. See " "<citerefentry> <refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</" @@ -4020,38 +4202,38 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3421 +#: sssd.conf.5.xml:3552 msgid "<quote>none</quote> disables hostid explicitly." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3424 +#: sssd.conf.5.xml:3555 msgid "" "Default: The value of <quote>id_provider</quote> is used if it is set and " "can handle hostid requests." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3431 +#: sssd.conf.5.xml:3562 msgid "resolver_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3434 +#: sssd.conf.5.xml:3565 msgid "" "The provider which should handle hosts and networks lookups. Supported " "resolver providers are:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3438 +#: sssd.conf.5.xml:3569 msgid "" "<quote>proxy</quote> to forward lookups to another NSS library. See " "<quote>proxy_resolver_lib_name</quote>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3442 +#: sssd.conf.5.xml:3573 msgid "" "<quote>ldap</quote> to fetch hosts and networks stored in LDAP. See " "<citerefentry> <refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</" @@ -4059,7 +4241,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3449 +#: sssd.conf.5.xml:3580 msgid "" "<quote>ad</quote> to fetch hosts and networks stored in AD. See " "<citerefentry> <refentrytitle>sssd-ad</refentrytitle> <manvolnum>5</" @@ -4068,19 +4250,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3457 +#: sssd.conf.5.xml:3588 msgid "<quote>none</quote> disallows fetching hosts and networks explicitly." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3460 +#: sssd.conf.5.xml:3591 msgid "" "Default: The value of <quote>id_provider</quote> is used if it is set and " "can handle resolver requests." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3470 +#: sssd.conf.5.xml:3601 msgid "" "Regular expression for this domain that describes how to parse the string " "containing user name and domain into these components. The \"domain\" can " @@ -4090,7 +4272,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3479 +#: sssd.conf.5.xml:3610 msgid "" "Default: <quote>^((?P<name>.+)@(?P<domain>[^@]*)|(?P<name>" "[^@]+))$</quote> which allows two different styles for user names:" @@ -4099,17 +4281,17 @@ msgstr "" # auto translated by TM merge from project: Fedora Websites, version: # fedorahosted.org, DocId: po/fedorahosted #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:3484 sssd.conf.5.xml:3498 +#: sssd.conf.5.xml:3615 sssd.conf.5.xml:3629 msgid "username" msgstr "username" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:3487 sssd.conf.5.xml:3501 +#: sssd.conf.5.xml:3618 sssd.conf.5.xml:3632 msgid "username@domain.name" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3492 +#: sssd.conf.5.xml:3623 msgid "" "Default for the AD and IPA provider: <quote>^(((?P<domain>[^\\\\]+)\\\\" "(?P<name>.+))|((?P<name>.+)@(?P<domain>[^@]+))|((?" @@ -4118,19 +4300,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:3504 +#: sssd.conf.5.xml:3635 msgid "domain\\username" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3507 +#: sssd.conf.5.xml:3638 msgid "" "While the first two correspond to the general default the third one is " "introduced to allow easy integration of users from Windows domains." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3512 +#: sssd.conf.5.xml:3643 msgid "" "The default re_expression uses the <quote>@</quote> character as a separator " "between the name and the domain. As a result of this setting the default " @@ -4140,89 +4322,94 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3564 +#: sssd.conf.5.xml:3695 msgid "Default: <quote>%1$s@%2$s</quote>." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3570 +#: sssd.conf.5.xml:3701 msgid "lookup_family_order (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3573 +#: sssd.conf.5.xml:3704 msgid "" "Provides the ability to select preferred address family to use when " "performing DNS lookups." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3577 +#: sssd.conf.5.xml:3708 msgid "Supported values:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3580 +#: sssd.conf.5.xml:3711 msgid "ipv4_first: Try looking up IPv4 address, if that fails, try IPv6" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3583 +#: sssd.conf.5.xml:3714 msgid "ipv4_only: Only attempt to resolve hostnames to IPv4 addresses." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3586 +#: sssd.conf.5.xml:3717 msgid "ipv6_first: Try looking up IPv6 address, if that fails, try IPv4" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3589 +#: sssd.conf.5.xml:3720 msgid "ipv6_only: Only attempt to resolve hostnames to IPv6 addresses." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3592 +#: sssd.conf.5.xml:3723 msgid "Default: ipv4_first" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3598 +#: sssd.conf.5.xml:3729 msgid "dns_resolver_server_timeout (integer)" msgstr "dns_resolver_server_timeout (celé číslo)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3601 +#: sssd.conf.5.xml:3732 msgid "" -"Defines the amount of time (in milliseconds) SSSD would try to talk to DNS " -"server before trying next DNS server." +"Defines the timeout duration (in milliseconds) SSSD waits for a DNS server " +"to respond before moving to the next one." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3606 +#: sssd.conf.5.xml:3737 msgid "" "The AD provider will use this option for the CLDAP ping timeouts as well." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3610 sssd.conf.5.xml:3630 sssd.conf.5.xml:3651 +#: sssd.conf.5.xml:3741 sssd.conf.5.xml:3777 sssd.conf.5.xml:3814 msgid "" -"Please see the section <quote>FAILOVER</quote> for more information about " -"the service resolution." +"Please see the section <quote>FAILOVER</quote> in <citerefentry> " +"<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> </" +"citerefentry>, <citerefentry> <refentrytitle>sssd-krb5</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry>, <citerefentry> <refentrytitle>sssd-" +"ipa</refentrytitle> <manvolnum>5</manvolnum> </citerefentry> or " +"<citerefentry> <refentrytitle>sssd-ad</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry> for more information about the service resolution." msgstr "" #. type: Content of: <refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3615 sssd-ldap.5.xml:700 include/failover.xml:84 +#: sssd.conf.5.xml:3762 sssd-ldap.5.xml:700 include/failover.xml:84 msgid "Default: 1000" msgstr "Výchozí: 1000" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3621 +#: sssd.conf.5.xml:3768 msgid "dns_resolver_op_timeout (integer)" msgstr "dns_resolver_op_timeout (celé číslo)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3624 +#: sssd.conf.5.xml:3771 msgid "" "Defines the amount of time (in seconds) to wait to resolve single DNS query " "(e.g. resolution of a hostname or an SRV record) before trying the next " @@ -4230,17 +4417,17 @@ msgid "" msgstr "" #. type: Content of: <refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3635 include/failover.xml:100 +#: sssd.conf.5.xml:3798 include/failover.xml:100 msgid "Default: 3" msgstr "Výchozí: 3" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3641 +#: sssd.conf.5.xml:3804 msgid "dns_resolver_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3644 +#: sssd.conf.5.xml:3807 msgid "" "Defines the amount of time (in seconds) to wait for a reply from the " "internal fail over service before assuming that the service is unreachable. " @@ -4249,12 +4436,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3662 -msgid "dns_resolver_use_search_list (bool)" +#: sssd.conf.5.xml:3841 +#, fuzzy +#| msgid "dns_resolver_use_search_list (bool)" +msgid "dns_resolver_use_search_list (boolean)" msgstr "dns_resolver_use_search_list (logická hodnota)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3665 +#: sssd.conf.5.xml:3844 msgid "" "Normally, the DNS resolver searches the domain list defined in the " "\"search\" directive from the resolv.conf file. This can lead to delays in " @@ -4262,7 +4451,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3671 +#: sssd.conf.5.xml:3850 msgid "" "If fully qualified domain names (or _srv_) are used in the SSSD " "configuration, setting this option to FALSE can prevent unnecessary DNS " @@ -4270,34 +4459,34 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3677 +#: sssd.conf.5.xml:3856 msgid "Default: TRUE" msgstr "Výchozí: PRAVDA" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3683 +#: sssd.conf.5.xml:3862 msgid "dns_discovery_domain (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3686 +#: sssd.conf.5.xml:3865 msgid "" "If service discovery is used in the back end, specifies the domain part of " "the service discovery DNS query." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3690 +#: sssd.conf.5.xml:3869 msgid "Default: Use the domain part of machine's hostname" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3696 +#: sssd.conf.5.xml:3875 msgid "failover_primary_timeout (integer)" msgstr "failover_primary_timeout (celé číslo)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3699 +#: sssd.conf.5.xml:3878 msgid "" "When no primary server is available, SSSD fails over to a backup server. " "This option defines the number of seconds SSSD waits before attempting to " @@ -4305,57 +4494,66 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3706 +#: sssd.conf.5.xml:3885 msgid "Note: The minimum value is 31." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3709 +#: sssd.conf.5.xml:3888 msgid "Default: 31" msgstr "Výchozí: 31" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3715 +#: sssd.conf.5.xml:3894 msgid "override_gid (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3718 -msgid "Override the primary GID value with the one specified." +#: sssd.conf.5.xml:3897 +msgid "" +"Override the primary GID value for all users in the domain with specified " +"value." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3901 +msgid "" +"Default: not set (Use the primary GID value retrieved from the identity " +"provider)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3724 +#: sssd.conf.5.xml:3908 msgid "case_sensitive (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3731 +#: sssd.conf.5.xml:3915 msgid "True" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3734 +#: sssd.conf.5.xml:3918 msgid "Case sensitive. This value is invalid for AD provider." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3740 +#: sssd.conf.5.xml:3924 msgid "False" msgstr "Nepravda" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3742 +#: sssd.conf.5.xml:3926 msgid "Case insensitive." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3746 +#: sssd.conf.5.xml:3930 msgid "Preserving" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3749 +#: sssd.conf.5.xml:3933 msgid "" "Same as False (case insensitive), but does not lowercase names in the result " "of NSS operations. Note that name aliases (and in case of services also " @@ -4363,31 +4561,57 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3757 +#: sssd.conf.5.xml:3941 msgid "" "If you want to set this value for trusted domain with IPA provider, you need " "to set it on both the client and SSSD on the server." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3727 +#: sssd.conf.5.xml:3911 msgid "" "Treat user and group names as case sensitive. Possible option values are: " "<placeholder type=\"variablelist\" id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3772 +#: sssd.conf.5.xml:3956 msgid "Default: True (False for AD provider)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3778 +#: sssd.conf.5.xml:3962 +msgid "avoid_by_id_lookups (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3965 +msgid "" +"If this option is set to 'true' SSSD will try to avoid sending lookups by ID " +"to the backend and will switch to a lookup by name if a cached object with a " +"matching ID can be found." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3971 +msgid "" +"This option can e.g. be used in cases where searches by ID are expensive on " +"the server side because of missing indexes or are not even possible, e.g. " +"due to non-reversible POSIX id-mapping." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3978 +msgid "Default: False (True for IdP provider)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:3984 msgid "subdomain_inherit (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3781 +#: sssd.conf.5.xml:3987 msgid "" "Specifies a list of configuration parameters that should be inherited by a " "subdomain. Please note that only selected parameters can be inherited. " @@ -4395,89 +4619,89 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3787 +#: sssd.conf.5.xml:3993 msgid "ldap_search_timeout" msgstr "ldap_search_timeout" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3790 +#: sssd.conf.5.xml:3996 msgid "ldap_network_timeout" msgstr "ldap_network_timeout" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3793 +#: sssd.conf.5.xml:3999 msgid "ldap_opt_timeout" msgstr "ldap_opt_timeout" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3796 +#: sssd.conf.5.xml:4002 msgid "ldap_offline_timeout" msgstr "ldap_offline_timeout" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3799 +#: sssd.conf.5.xml:4005 msgid "ldap_purge_cache_timeout" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3802 +#: sssd.conf.5.xml:4008 msgid "ldap_purge_cache_offset" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3805 +#: sssd.conf.5.xml:4011 msgid "" "ldap_krb5_keytab (the value of krb5_keytab will be used if ldap_krb5_keytab " "is not set explicitly)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3809 +#: sssd.conf.5.xml:4015 msgid "ldap_krb5_ticket_lifetime" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3812 +#: sssd.conf.5.xml:4018 msgid "ldap_connection_expire_timeout" msgstr "ldap_connection_expire_timeout" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3815 +#: sssd.conf.5.xml:4021 msgid "ldap_connection_expire_offset" msgstr "ldap_connection_expire_offset" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3818 +#: sssd.conf.5.xml:4024 msgid "ldap_connection_idle_timeout" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3821 sssd-ldap.5.xml:446 +#: sssd.conf.5.xml:4027 sssd-ldap.5.xml:446 msgid "ldap_use_tokengroups" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3824 +#: sssd.conf.5.xml:4030 msgid "ldap_user_principal" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3827 +#: sssd.conf.5.xml:4033 msgid "ignore_group_members" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3830 +#: sssd.conf.5.xml:4036 msgid "auto_private_groups" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3833 +#: sssd.conf.5.xml:4039 msgid "case_sensitive" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:3838 +#: sssd.conf.5.xml:4044 #, no-wrap msgid "" "subdomain_inherit = ldap_purge_cache_timeout\n" @@ -4485,27 +4709,27 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3845 +#: sssd.conf.5.xml:4051 msgid "Note: This option only works with the IPA and AD provider." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3852 +#: sssd.conf.5.xml:4058 msgid "subdomain_homedir (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3863 +#: sssd.conf.5.xml:4069 msgid "%F" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3864 +#: sssd.conf.5.xml:4070 msgid "flat (NetBIOS) name of a subdomain." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3855 +#: sssd.conf.5.xml:4061 msgid "" "Use this homedir as default value for all subdomains within this domain in " "IPA AD trust. See <emphasis>override_homedir</emphasis> for info about " @@ -4515,55 +4739,55 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3869 +#: sssd.conf.5.xml:4075 msgid "" "The value can be overridden by <emphasis>override_homedir</emphasis> option." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3873 +#: sssd.conf.5.xml:4079 msgid "Default: <filename>/home/%d/%u</filename>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3878 +#: sssd.conf.5.xml:4084 msgid "realmd_tags (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3881 +#: sssd.conf.5.xml:4087 msgid "" "Various tags stored by the realmd configuration service for this domain." msgstr "Různé štítky uložené službou nastavování realmd pro tuto doménu." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3887 +#: sssd.conf.5.xml:4093 msgid "cached_auth_timeout (int)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3890 +#: sssd.conf.5.xml:4096 msgid "" -"Specifies time in seconds since last successful online authentication for " -"which user will be authenticated using cached credentials while SSSD is in " -"the online mode. If the credentials are incorrect, SSSD falls back to online " -"authentication." +"Specifies the number of seconds since the last successful online " +"authentication during which SSSD will authenticate users via cached " +"credentials, even while online. If the cached authentication fails, SSSD " +"immediately falls back to online authentication." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3898 +#: sssd.conf.5.xml:4103 msgid "" "This option's value is inherited by all trusted domains. At the moment it is " "not possible to set a different value per trusted domain." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3903 +#: sssd.conf.5.xml:4108 msgid "Special value 0 implies that this feature is disabled." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3907 +#: sssd.conf.5.xml:4112 msgid "" "Please note that if <quote>cached_auth_timeout</quote> is longer than " "<quote>pam_id_timeout</quote> then the back end could be called to handle " @@ -4571,12 +4795,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3918 +#: sssd.conf.5.xml:4123 msgid "local_auth_policy (string)" msgstr "local_auth_policy (řetězec)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3921 +#: sssd.conf.5.xml:4126 msgid "" "Local authentication methods policy. Some backends (i.e. LDAP, proxy " "provider) only support a password based authentication, while others can " @@ -4588,7 +4812,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3933 +#: sssd.conf.5.xml:4138 msgid "" "There are three possible values for this option: match, only, enable. " "<quote>match</quote> is used to match offline and online states for Kerberos " @@ -4600,7 +4824,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3946 +#: sssd.conf.5.xml:4151 msgid "" "The following table shows which authentication methods, if configured " "properly, are currently enabled or disabled for each backend, with the " @@ -4608,42 +4832,47 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> -#: sssd.conf.5.xml:3959 +#: sssd.conf.5.xml:4164 msgid "local_auth_policy = match (default)" msgstr "local_auth_policy = shoda (výchozí)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> -#: sssd.conf.5.xml:3960 +#: sssd.conf.5.xml:4165 msgid "Passkey" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> -#: sssd.conf.5.xml:3961 +#: sssd.conf.5.xml:4166 msgid "Smartcard" msgstr "Čipová karta" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:3964 sssd-ldap.5.xml:228 +#: sssd.conf.5.xml:4169 sssd-ldap.5.xml:228 msgid "IPA" msgstr "" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry><para> +#: sssd.conf.5.xml:4169 sssd.conf.5.xml:4170 sssd.conf.5.xml:4173 +msgid "enabled" +msgstr "povoleno" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:3967 sssd-ldap.5.xml:233 +#: sssd.conf.5.xml:4172 sssd-ldap.5.xml:233 msgid "AD" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry><para> -#: sssd.conf.5.xml:3967 sssd.conf.5.xml:3970 sssd.conf.5.xml:3971 +#: sssd.conf.5.xml:4172 sssd.conf.5.xml:4175 sssd.conf.5.xml:4176 msgid "disabled" msgstr "zakázáno" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry> -#: sssd.conf.5.xml:3970 +#: sssd.conf.5.xml:4175 msgid "LDAP" msgstr "LDAP" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3975 +#: sssd.conf.5.xml:4180 msgid "" "Please note that if local Smartcard authentication is enabled and a " "Smartcard is present, Smartcard authentication will be preferred over the " @@ -4652,7 +4881,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:3987 +#: sssd.conf.5.xml:4192 #, no-wrap msgid "" "[domain/shadowutils]\n" @@ -4663,7 +4892,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3983 +#: sssd.conf.5.xml:4188 msgid "" "The following configuration example allows local users to authenticate " "locally using any enabled method (i.e. smartcard, passkey). <placeholder " @@ -4671,29 +4900,29 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3995 +#: sssd.conf.5.xml:4200 msgid "Default: match" msgstr "Výchozí: shoda" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4000 +#: sssd.conf.5.xml:4205 msgid "auto_private_groups (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4006 +#: sssd.conf.5.xml:4211 msgid "true" msgstr "pravda" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4009 +#: sssd.conf.5.xml:4214 msgid "" "Create user's private group unconditionally from user's UID number. The GID " "number is ignored in this case." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4013 +#: sssd.conf.5.xml:4218 msgid "" "NOTE: Because the GID number and the user private group are inferred from " "the UID number, it is not supported to have multiple entries with the same " @@ -4702,24 +4931,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4022 +#: sssd.conf.5.xml:4227 msgid "false" msgstr "nepravda" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4025 +#: sssd.conf.5.xml:4230 msgid "" "Always use the user's primary GID number. The GID number must refer to a " "group object in the LDAP database." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4031 +#: sssd.conf.5.xml:4236 msgid "hybrid" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4034 +#: sssd.conf.5.xml:4239 msgid "" "A primary group is autogenerated for user entries whose UID and GID numbers " "have the same value and at the same time the GID number does not correspond " @@ -4729,14 +4958,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4047 +#: sssd.conf.5.xml:4252 msgid "" "If the UID and GID of a user are different, then the GID must correspond to " "a group entry, otherwise the GID is simply not resolvable." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4054 +#: sssd.conf.5.xml:4259 msgid "" "This feature is useful for environments that wish to stop maintaining a " "separate group objects for the user private groups, but also wish to retain " @@ -4744,14 +4973,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4003 +#: sssd.conf.5.xml:4208 msgid "" "This option takes any of three available values: <placeholder " "type=\"variablelist\" id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4066 +#: sssd.conf.5.xml:4271 msgid "" "For the LDAP based id providers (LDAP, IPA and AD) the default for the " "configured domain is typically False because the sources have the concept of " @@ -4761,14 +4990,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4075 +#: sssd.conf.5.xml:4280 msgid "" "For subdomains, the default value is False for subdomains that use assigned " "POSIX IDs and True for subdomains that use automatic ID-mapping." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:4083 +#: sssd.conf.5.xml:4288 #, no-wrap msgid "" "[domain/forest.domain/sub.domain]\n" @@ -4776,7 +5005,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:4089 +#: sssd.conf.5.xml:4294 #, no-wrap msgid "" "[domain/forest.domain]\n" @@ -4785,7 +5014,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4080 +#: sssd.conf.5.xml:4285 msgid "" "The value of auto_private_groups can either be set per subdomains in a " "subsection, for example: <placeholder type=\"programlisting\" id=\"0\"/> or " @@ -4794,7 +5023,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:2503 +#: sssd.conf.5.xml:2549 msgid "" "These configuration options can be present in a domain configuration " "section, that is, in a section called <quote>[domain/<replaceable>NAME</" @@ -4802,17 +5031,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4104 +#: sssd.conf.5.xml:4309 msgid "proxy_pam_target (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4107 +#: sssd.conf.5.xml:4312 msgid "The proxy target PAM proxies to." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4110 +#: sssd.conf.5.xml:4315 msgid "" "Default: not set by default, you have to take an existing pam configuration " "or create a new one and add the service name here. As an alternative you can " @@ -4820,12 +5049,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4120 +#: sssd.conf.5.xml:4325 msgid "proxy_lib_name (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4123 +#: sssd.conf.5.xml:4328 msgid "" "The name of the NSS library to use in proxy domains. The NSS functions " "searched for in the library are in the form of _nss_$(libName)_$(function), " @@ -4833,12 +5062,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4133 +#: sssd.conf.5.xml:4338 msgid "proxy_resolver_lib_name (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4136 +#: sssd.conf.5.xml:4341 msgid "" "The name of the NSS library to use for hosts and networks lookups in proxy " "domains. The NSS functions searched for in the library are in the form of " @@ -4846,12 +5075,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4147 +#: sssd.conf.5.xml:4352 msgid "proxy_fast_alias (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4150 +#: sssd.conf.5.xml:4355 msgid "" "When a user or group is looked up by name in the proxy provider, a second " "lookup by ID is performed to \"canonicalize\" the name in case the requested " @@ -4860,12 +5089,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4164 +#: sssd.conf.5.xml:4369 msgid "proxy_max_children (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4167 +#: sssd.conf.5.xml:4372 msgid "" "This option specifies the number of pre-forked proxy children. It is useful " "for high-load SSSD environments where sssd may run out of available child " @@ -4873,19 +5102,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4100 +#: sssd.conf.5.xml:4305 msgid "" "Options valid for proxy domains. <placeholder type=\"variablelist\" " "id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:4183 +#: sssd.conf.5.xml:4388 msgid "Application domains" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:4185 +#: sssd.conf.5.xml:4390 msgid "" "SSSD, with its D-Bus interface (see <citerefentry> <refentrytitle>sssd-ifp</" "refentrytitle> <manvolnum>5</manvolnum> </citerefentry>) is appealing to " @@ -4902,7 +5131,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:4205 +#: sssd.conf.5.xml:4410 msgid "" "Please note that the application domain must still be explicitly enabled in " "the <quote>domains</quote> parameter so that the lookup order between the " @@ -4910,17 +5139,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><title> -#: sssd.conf.5.xml:4211 +#: sssd.conf.5.xml:4416 msgid "Application domain parameters" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4213 +#: sssd.conf.5.xml:4418 msgid "inherit_from (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4216 +#: sssd.conf.5.xml:4421 msgid "" "The SSSD POSIX-type domain the application domain inherits all settings " "from. The application domain can moreover add its own settings to the " @@ -4929,7 +5158,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:4230 +#: sssd.conf.5.xml:4435 msgid "" "The following example illustrates the use of an application domain. In this " "setup, the POSIX domain is connected to an LDAP server and is used by the OS " @@ -4939,7 +5168,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><programlisting> -#: sssd.conf.5.xml:4238 +#: sssd.conf.5.xml:4443 #, no-wrap msgid "" "[sssd]\n" @@ -4959,12 +5188,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:4258 +#: sssd.conf.5.xml:4463 msgid "TRUSTED DOMAIN SECTION" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4260 +#: sssd.conf.5.xml:4465 msgid "" "Some options used in the domain section can also be used in the trusted " "domain section, that is, in a section called <quote>[domain/" @@ -4975,69 +5204,79 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4267 +#: sssd.conf.5.xml:4472 msgid "ldap_search_base," msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4268 +#: sssd.conf.5.xml:4473 msgid "ldap_user_search_base," msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4269 +#: sssd.conf.5.xml:4474 msgid "ldap_group_search_base," msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4270 +#: sssd.conf.5.xml:4475 msgid "ldap_netgroup_search_base," msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4271 +#: sssd.conf.5.xml:4476 msgid "ldap_service_search_base," msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4272 +#: sssd.conf.5.xml:4477 msgid "ldap_sasl_mech," msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4273 +#: sssd.conf.5.xml:4478 msgid "ad_server," msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4274 +#: sssd.conf.5.xml:4479 msgid "ad_backup_server," msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4275 +#: sssd.conf.5.xml:4480 msgid "ad_site," msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:4276 sssd-ipa.5.xml:934 +#: sssd.conf.5.xml:4481 sssd-ipa.5.xml:929 msgid "use_fully_qualified_names" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4280 +#: sssd.conf.5.xml:4482 +msgid "pam_gssapi_services" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:4483 +msgid "pam_gssapi_check_upn" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:4485 msgid "" "For more details about these options see their individual description in the " "manual page." msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:4286 +#: sssd.conf.5.xml:4491 msgid "CERTIFICATE MAPPING SECTION" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4288 +#: sssd.conf.5.xml:4493 msgid "" "To allow authentication with Smartcards and certificates SSSD must be able " "to map certificates to users. This can be done by adding the full " @@ -5050,7 +5289,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4302 +#: sssd.conf.5.xml:4507 msgid "" "To make the mapping more flexible mapping and matching rules were added to " "SSSD (see <citerefentry> <refentrytitle>sss-certmap</refentrytitle> " @@ -5058,7 +5297,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4311 +#: sssd.conf.5.xml:4516 msgid "" "A mapping and matching rule can be added to the SSSD configuration in a " "section on its own with a name like <quote>[certmap/" @@ -5067,55 +5306,50 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4318 +#: sssd.conf.5.xml:4523 msgid "matchrule (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4321 +#: sssd.conf.5.xml:4526 msgid "" "Only certificates from the Smartcard which matches this rule will be " "processed, all others are ignored." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4325 +#: sssd.conf.5.xml:4530 msgid "" "Default: KRB5:<EKU>clientAuth, i.e. only certificates which have the " "Extended Key Usage <quote>clientAuth</quote>" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4332 +#: sssd.conf.5.xml:4537 msgid "maprule (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4335 +#: sssd.conf.5.xml:4540 msgid "Defines how the user is found for a given certificate." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:4341 +#: sssd.conf.5.xml:4546 msgid "" "LDAP:(userCertificate;binary={cert!bin}) for LDAP based providers like " "<quote>ldap</quote>, <quote>AD</quote> or <quote>ipa</quote>." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:4347 +#: sssd.conf.5.xml:4552 msgid "" "If maprule is not set and provider is <quote>proxy</quote>, the RULE_NAME " "name is assumed to be the name of the matching user." msgstr "" -#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4357 -msgid "domains (string)" -msgstr "" - #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4360 +#: sssd.conf.5.xml:4565 msgid "" "Comma separated list of domain names the rule should be applied. By default " "a rule is only valid in the domain configured in sssd.conf. If the provider " @@ -5124,17 +5358,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4367 +#: sssd.conf.5.xml:4572 msgid "Default: the configured domain in sssd.conf" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4372 +#: sssd.conf.5.xml:4577 msgid "priority (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4375 +#: sssd.conf.5.xml:4580 msgid "" "Unsigned integer value defining the priority of the rule. The higher the " "number the lower the priority. <quote>0</quote> stands for the highest " @@ -5142,17 +5376,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4381 +#: sssd.conf.5.xml:4586 msgid "Default: the lowest priority" msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:4389 +#: sssd.conf.5.xml:4594 msgid "PROMPTING CONFIGURATION SECTION" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4391 +#: sssd.conf.5.xml:4596 msgid "" "If a special file (<filename>/var/lib/sss/pubconf/pam_preauth_available</" "filename>) exists SSSD's PAM module pam_sss will ask SSSD to figure out " @@ -5162,7 +5396,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4399 +#: sssd.conf.5.xml:4604 msgid "" "With the growing number of authentication methods and the possibility that " "there are multiple ones for a single user the heuristic used by pam_sss to " @@ -5171,59 +5405,59 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4411 +#: sssd.conf.5.xml:4616 msgid "[prompting/password]" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4414 +#: sssd.conf.5.xml:4619 msgid "password_prompt" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4415 +#: sssd.conf.5.xml:4620 msgid "to change the string of the password prompt" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4413 +#: sssd.conf.5.xml:4618 msgid "" "to configure password prompting, allowed options are: <placeholder " "type=\"variablelist\" id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4423 +#: sssd.conf.5.xml:4628 msgid "[prompting/2fa]" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4427 +#: sssd.conf.5.xml:4632 msgid "first_prompt" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4428 +#: sssd.conf.5.xml:4633 msgid "to change the string of the prompt for the first factor" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4431 +#: sssd.conf.5.xml:4636 msgid "second_prompt" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4432 +#: sssd.conf.5.xml:4637 msgid "to change the string of the prompt for the second factor" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4435 +#: sssd.conf.5.xml:4640 msgid "single_prompt" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4436 +#: sssd.conf.5.xml:4641 msgid "" "boolean value, if True there will be only a single prompt using the value of " "first_prompt where it is expected that both factors are entered as a single " @@ -5232,7 +5466,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4425 +#: sssd.conf.5.xml:4630 msgid "" "to configure two-factor authentication prompting, allowed options are: " "<placeholder type=\"variablelist\" id=\"0\"/> If the second factor is " @@ -5241,7 +5475,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4449 +#: sssd.conf.5.xml:4654 msgid "" "Some clients, such as SSH with 'PasswordAuthentication yes', generate their " "own prompts and do not use prompts provided by SSSD or other PAM modules. " @@ -5252,17 +5486,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4464 +#: sssd.conf.5.xml:4669 msgid "[prompting/passkey]" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:4470 sssd-ad.5.xml:1022 +#: sssd.conf.5.xml:4675 sssd.conf.5.xml:4719 sssd-ad.5.xml:1027 msgid "interactive" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4472 +#: sssd.conf.5.xml:4677 msgid "" "boolean value, if True prompt a message and wait before testing the presence " "of a passkey device. Recommended if your device doesn’t have a tactile " @@ -5270,55 +5504,147 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4480 +#: sssd.conf.5.xml:4685 sssd.conf.5.xml:4735 msgid "interactive_prompt" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4482 +#: sssd.conf.5.xml:4687 sssd.conf.5.xml:4737 msgid "to change the message of the interactive prompt." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4487 +#: sssd.conf.5.xml:4692 msgid "touch" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4489 +#: sssd.conf.5.xml:4694 msgid "" "boolean value, if True prompt a message to remind the user to touch the " "device." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4495 +#: sssd.conf.5.xml:4700 msgid "touch_prompt" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4497 +#: sssd.conf.5.xml:4702 msgid "to change the message of the touch prompt." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4466 +#: sssd.conf.5.xml:4671 msgid "" "to configure passkey authentication prompting, allowed options are: " "<placeholder type=\"variablelist\" id=\"0\"/>" msgstr "" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4713 +msgid "[prompting/oauth2]" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4721 +msgid "" +"boolean value, if True prompt a message after asking the user to " +"authenticate, and wait before requesting the access token." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4725 +msgid "" +"If False, make sure to set the <quote>idp_request_timeout</quote> " +"sufficiently high, to give the user time to authenticate." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4715 +#, fuzzy +#| msgid "" +#| "One of the following strings specifying the scope of session recording: " +#| "<placeholder type=\"variablelist\" id=\"0\"/>" +msgid "" +"to configure OAuth2 authentication prompting, allowed options are: " +"<placeholder type=\"variablelist\" id=\"0\"/>" +msgstr "" +"Jeden z následujících řetězců určujících rozsah záznamu relace: <placeholder " +"type=\"variablelist\" id=\"0\"/>" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4748 +msgid "[prompting/cert_auth]" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4754 +msgid "pin_prompt" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4756 +msgid "" +"to change the message which asks the user to enter the PIN at the computer " +"keyboard. At the end of the message the token name is printed." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4764 +msgid "keypad_prompt" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4766 +msgid "" +"to change the message which asks the user to enter the PIN at keypad of the " +"Smartcard reader. At the end of the message the token name is printed." +msgstr "" + +# auto translated by TM merge from project: Fedora Websites, version: +# fedorahosted.org, DocId: po/fedorahosted +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4774 +#, fuzzy +#| msgid "username" +msgid "user_name_hint" +msgstr "username" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4776 +msgid "" +"boolean value, if True ask for a user name if no name was given before and " +"the found certificate can be mapped to more than one user." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4750 +#, fuzzy +#| msgid "" +#| "One of the following strings specifying the scope of session recording: " +#| "<placeholder type=\"variablelist\" id=\"0\"/>" +msgid "" +"to configure Smartcard authentication prompting, allowed options are: " +"<placeholder type=\"variablelist\" id=\"0\"/>" +msgstr "" +"Jeden z následujících řetězců určujících rozsah záznamu relace: <placeholder " +"type=\"variablelist\" id=\"0\"/>" + #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4406 +#: sssd.conf.5.xml:4611 msgid "" "Each supported authentication method has its own configuration subsection " "under <quote>[prompting/...]</quote>. Currently there are: <placeholder " "type=\"variablelist\" id=\"0\"/> <placeholder type=\"variablelist\" id=\"1\"/" -"> <placeholder type=\"variablelist\" id=\"2\"/>" +"> <placeholder type=\"variablelist\" id=\"2\"/> <placeholder " +"type=\"variablelist\" id=\"3\"/> <placeholder type=\"variablelist\" id=\"4\"/" +">" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4508 +#: sssd.conf.5.xml:4792 msgid "" "It is possible to add a subsection for specific PAM services, e.g. " "<quote>[prompting/password/sshd]</quote> to individual change the prompting " @@ -5326,12 +5652,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:4515 pam_sss_gss.8.xml:157 idmap_sss.8.xml:43 +#: sssd.conf.5.xml:4799 pam_sss_gss.8.xml:157 idmap_sss.8.xml:43 msgid "EXAMPLES" msgstr "PŘÍKLADY" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd.conf.5.xml:4521 +#: sssd.conf.5.xml:4805 #, no-wrap msgid "" "[sssd]\n" @@ -5360,7 +5686,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4517 +#: sssd.conf.5.xml:4801 msgid "" "1. The following example shows a typical SSSD config. It does not describe " "configuration of the domains themselves - refer to documentation on " @@ -5369,7 +5695,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd.conf.5.xml:4553 +#: sssd.conf.5.xml:4837 #, no-wrap msgid "" "[domain/ipa.com/child.ad.com]\n" @@ -5377,7 +5703,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4547 +#: sssd.conf.5.xml:4831 msgid "" "2. The following example shows configuration of IPA AD trust where the AD " "forest consists of two domains in a parent-child structure. Suppose IPA " @@ -5388,7 +5714,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd.conf.5.xml:4564 +#: sssd.conf.5.xml:4848 #, no-wrap msgid "" "[certmap/my.domain/rule_name]\n" @@ -5399,7 +5725,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4558 +#: sssd.conf.5.xml:4842 msgid "" "3. The following example shows the configuration of a certificate mapping " "rule. It is valid for the configured domain <quote>my.domain</quote> and " @@ -5596,7 +5922,7 @@ msgid "" "defaultNamingContext does not exist or has an empty value namingContexts is " "used. The namingContexts attribute must have a single value with the DN of " "the search base of the LDAP server to make this work. Multiple values are " -"are not supported." +"not supported." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> @@ -5907,15 +6233,15 @@ msgstr "" "hostitelských objektů." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap.5.xml:472 sssd-ipa.5.xml:506 sssd-ipa.5.xml:525 sssd-ipa.5.xml:544 -#: sssd-ipa.5.xml:563 +#: sssd-ldap.5.xml:472 sssd-ipa.5.xml:501 sssd-ipa.5.xml:520 sssd-ipa.5.xml:539 +#: sssd-ipa.5.xml:558 msgid "" "See <quote>ldap_search_base</quote> for information about configuring " "multiple search bases." msgstr "" #. type: Content of: <listitem><para> -#: sssd-ldap.5.xml:477 sssd-ipa.5.xml:511 include/ldap_search_bases.xml:27 +#: sssd-ldap.5.xml:477 sssd-ipa.5.xml:506 include/ldap_search_bases.xml:27 msgid "Default: the value of <emphasis>ldap_search_base</emphasis>" msgstr "" @@ -6041,7 +6367,7 @@ msgid "" "closed early to ensure that a new query cannot require the connection to " "remain open past its expiration. This implies that connections will always " "be closed immediately and will never be reused if " -"<emphasis>ldap_connection_expire_timeout <= ldap_opt_timout</emphasis>" +"<emphasis>ldap_connection_expire_timeout <= ldap_opt_timeout</emphasis>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> @@ -6223,7 +6549,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:831 -msgid "ldap_ignore_unreadable_references (bool)" +msgid "ldap_ignore_unreadable_references (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> @@ -6550,7 +6876,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap.5.xml:1152 sssd-ad.5.xml:1267 +#: sssd-ldap.5.xml:1152 sssd-ad.5.xml:1260 msgid "Default: 86400 (24 hours)" msgstr "" @@ -6588,7 +6914,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ldap.5.xml:1187 sssd-ipa.5.xml:575 sssd-krb5.5.xml:103 +#: sssd-ldap.5.xml:1187 sssd-ipa.5.xml:570 sssd-krb5.5.xml:103 msgid "krb5_realm (string)" msgstr "" @@ -6744,7 +7070,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1339 -msgid "ldap_chpass_update_last_change (bool)" +msgid "ldap_chpass_update_last_change (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> @@ -6891,7 +7217,7 @@ msgid "ldap_access_order (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap.5.xml:1470 sssd-ipa.5.xml:405 +#: sssd-ldap.5.xml:1470 sssd-ipa.5.xml:400 msgid "Comma separated list of access control options. Allowed values are:" msgstr "" @@ -6936,7 +7262,7 @@ msgid "<emphasis>expire</emphasis>: use ldap_account_expire_policy" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap.5.xml:1515 sssd-ipa.5.xml:413 +#: sssd-ldap.5.xml:1515 sssd-ipa.5.xml:408 msgid "" "<emphasis>pwd_expire_policy_reject, pwd_expire_policy_warn, " "pwd_expire_policy_renew: </emphasis> These options are useful if users are " @@ -6946,24 +7272,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap.5.xml:1525 sssd-ipa.5.xml:423 +#: sssd-ldap.5.xml:1525 sssd-ipa.5.xml:418 msgid "" "The difference between these options is the action taken if user password is " "expired:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ldap.5.xml:1530 sssd-ipa.5.xml:428 +#: sssd-ldap.5.xml:1530 sssd-ipa.5.xml:423 msgid "pwd_expire_policy_reject - user is denied to log in," msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ldap.5.xml:1536 sssd-ipa.5.xml:434 +#: sssd-ldap.5.xml:1536 sssd-ipa.5.xml:429 msgid "pwd_expire_policy_warn - user is still able to log in," msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ldap.5.xml:1542 sssd-ipa.5.xml:440 +#: sssd-ldap.5.xml:1542 sssd-ipa.5.xml:435 msgid "" "pwd_expire_policy_renew - user is prompted to change their password " "immediately." @@ -7500,8 +7826,8 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd-ldap.5.xml:2032 sssd-simple.5.xml:169 sssd-ipa.5.xml:984 -#: sssd-ad.5.xml:1470 sssd-idp.5.xml:248 sssd-krb5.5.xml:483 +#: sssd-ldap.5.xml:2032 sssd-simple.5.xml:169 sssd-ipa.5.xml:979 +#: sssd-ad.5.xml:1463 sssd-idp.5.xml:343 sssd-krb5.5.xml:483 #: sss_rpcidmapd.5.xml:98 sssd-session-recording.5.xml:176 msgid "EXAMPLE" msgstr "PŘÍKLAD" @@ -7529,7 +7855,7 @@ msgstr "" #. type: Content of: <refsect1><refsect2><para> #: sssd-ldap.5.xml:2039 sssd-ldap.5.xml:2057 sssd-simple.5.xml:177 -#: sssd-ipa.5.xml:992 sssd-ad.5.xml:1478 sssd-sudo.5.xml:56 sssd-krb5.5.xml:492 +#: sssd-ipa.5.xml:987 sssd-ad.5.xml:1471 sssd-sudo.5.xml:56 sssd-krb5.5.xml:492 #: sssd-session-recording.5.xml:182 include/ldap_id_mapping.xml:105 msgid "<placeholder type=\"programlisting\" id=\"0\"/>" msgstr "syntaxe: <placeholder type=\"programlisting\" id=\"0\"/>" @@ -7564,7 +7890,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><title> #: sssd-ldap.5.xml:2073 sssd_krb5_locator_plugin.8.xml:83 sssd-simple.5.xml:189 -#: sssd-ad.5.xml:1493 sssd.8.xml:270 sss_seed.8.xml:163 +#: sssd-ad.5.xml:1486 sssd.8.xml:270 sss_seed.8.xml:163 msgid "NOTES" msgstr "POZNÁMKY" @@ -8071,7 +8397,7 @@ msgstr "" #: pam_sss.8.xml:434 msgid "" "No authentication method was found by Kerberos. This might happen if the " -"user has a Smartcard assigned but the pkint plugin is not available on the " +"user has a Smartcard assigned but the pkinit plugin is not available on the " "client." msgstr "" @@ -8497,6 +8823,23 @@ msgid "" "first DNS resolving failure." msgstr "" +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_locator_plugin.8.xml:106 +msgid "" +"If the environment variable SSSD_KRB5_LOCATOR_KDC_ADDRESS is set to a KDC " +"address the plugin will use this address instead of reading the kdcinfo " +"file. The address format is the same as in the kdcinfo file (see above)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_locator_plugin.8.xml:112 +msgid "" +"If the environment variable SSSD_KRB5_LOCATOR_KPASSWD_ADDRESS is set to a " +"kpasswd server address the plugin will use this address instead of reading " +"the kpasswdinfo file. The address format is the same as in the kpasswdinfo " +"file (see above)." +msgstr "" + #. type: Content of: <reference><refentry><refnamediv><refname> #: sssd-simple.5.xml:10 sssd-simple.5.xml:16 msgid "sssd-simple" @@ -9909,7 +10252,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:129 sssd-ad.5.xml:1161 +#: sssd-ipa.5.xml:129 sssd-ad.5.xml:1166 msgid "dyndns_update (boolean)" msgstr "" @@ -9923,20 +10266,13 @@ msgid "" "quote> option." msgstr "" -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:141 sssd-ad.5.xml:1175 -msgid "" -"NOTE: On older systems (such as RHEL 5), for this behavior to work reliably, " -"the default Kerberos realm must be set properly in /etc/krb5.conf" -msgstr "" - #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:152 sssd-ad.5.xml:1186 +#: sssd-ipa.5.xml:147 sssd-ad.5.xml:1186 msgid "dyndns_ttl (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:155 sssd-ad.5.xml:1189 +#: sssd-ipa.5.xml:150 sssd-ad.5.xml:1189 msgid "" "The TTL to apply to the client DNS record when updating it. If " "dyndns_update is false this has no effect. This will override the TTL " @@ -9944,17 +10280,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:160 +#: sssd-ipa.5.xml:155 msgid "Default: 1200 (seconds)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:166 sssd-ad.5.xml:1200 +#: sssd-ipa.5.xml:161 sssd-ad.5.xml:1200 msgid "dyndns_iface (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:169 sssd-ad.5.xml:1203 +#: sssd-ipa.5.xml:164 sssd-ad.5.xml:1203 msgid "" "Optional. Applicable only when dyndns_update is true. Choose the interface " "or a list of interfaces whose IP addresses should be used for dynamic DNS " @@ -9966,26 +10302,26 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:182 +#: sssd-ipa.5.xml:177 msgid "" "Default: Use the IP addresses of the interface which is used for IPA LDAP " "connection" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:186 sssd-ad.5.xml:1226 +#: sssd-ipa.5.xml:181 sssd-ad.5.xml:1220 msgid "Example: dyndns_iface = em[12], !vnet1, vnet*" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:192 sssd-ad.5.xml:1232 +#: sssd-ipa.5.xml:187 sssd-ad.5.xml:1226 #, fuzzy #| msgid "ldap_user_passkey (string)" msgid "dyndns_address (string)" msgstr "ldap_user_passkey (řetězec)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:195 sssd-ad.5.xml:1235 +#: sssd-ipa.5.xml:190 sssd-ad.5.xml:1229 msgid "" "Optional. Applicable only when <emphasis>dyndns_update</emphasis> is true. " "A list of IP addresses or IP networks to be used for dynamic DNS updates. " @@ -9996,22 +10332,22 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:206 sssd-ad.5.xml:1246 +#: sssd-ipa.5.xml:201 sssd-ad.5.xml:1240 msgid "Default: No filtering of IP addresses." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:209 sssd-ad.5.xml:1249 +#: sssd-ipa.5.xml:204 sssd-ad.5.xml:1243 msgid "Example: dyndns_address = 10.0.0.0/16, !10.0.1.0/24" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:215 sssd-ad.5.xml:1305 +#: sssd-ipa.5.xml:210 sssd-ad.5.xml:1298 msgid "dyndns_auth (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:218 sssd-ad.5.xml:1308 +#: sssd-ipa.5.xml:213 sssd-ad.5.xml:1301 msgid "" "Whether the nsupdate utility should use GSS-TSIG authentication for secure " "updates with the DNS server, insecure updates can be sent by setting this " @@ -10019,17 +10355,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:224 sssd-ad.5.xml:1314 +#: sssd-ipa.5.xml:219 sssd-ad.5.xml:1307 msgid "Default: GSS-TSIG" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:230 sssd-ad.5.xml:1320 +#: sssd-ipa.5.xml:225 sssd-ad.5.xml:1313 msgid "dyndns_auth_ptr (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:233 sssd-ad.5.xml:1323 +#: sssd-ipa.5.xml:228 sssd-ad.5.xml:1316 msgid "" "Whether the nsupdate utility should use GSS-TSIG authentication for secure " "PTR updates with the DNS server, insecure updates can be sent by setting " @@ -10037,17 +10373,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:239 sssd-ad.5.xml:1329 +#: sssd-ipa.5.xml:234 sssd-ad.5.xml:1322 msgid "Default: Same as dyndns_auth" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:245 sssd-ad.5.xml:1255 +#: sssd-ipa.5.xml:240 sssd-ad.5.xml:1249 msgid "dyndns_refresh_interval (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:248 +#: sssd-ipa.5.xml:243 msgid "" "How often should the back end perform periodic DNS update in addition to the " "automatic update performed when the back end goes online. This option is " @@ -10055,74 +10391,76 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:261 sssd-ad.5.xml:1273 -msgid "dyndns_update_ptr (bool)" +#: sssd-ipa.5.xml:256 sssd-ad.5.xml:1266 +msgid "dyndns_update_ptr (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:264 sssd-ad.5.xml:1276 +#: sssd-ipa.5.xml:259 sssd-ad.5.xml:1269 msgid "" "Whether the PTR record should also be explicitly updated when updating the " "client's DNS records. Applicable only when dyndns_update is true." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:269 +#: sssd-ipa.5.xml:264 msgid "" "This option should be False in most IPA deployments as the IPA server " "generates the PTR records automatically when forward records are changed." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:275 sssd-ad.5.xml:1281 +#: sssd-ipa.5.xml:270 sssd-ad.5.xml:1274 msgid "" "Note that <emphasis>dyndns_update_per_family</emphasis> parameter does not " "apply for PTR record updates. Those updates are always sent separately." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:280 +#: sssd-ipa.5.xml:275 msgid "Default: False (disabled)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:286 sssd-ad.5.xml:1292 -msgid "dyndns_force_tcp (bool)" -msgstr "" +#: sssd-ipa.5.xml:281 sssd-ad.5.xml:1285 +#, fuzzy +#| msgid "simple_deny_users (string)" +msgid "dyndns_force_tcp (boolean)" +msgstr "simple_deny_users (řetězec)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:289 sssd-ad.5.xml:1295 +#: sssd-ipa.5.xml:284 sssd-ad.5.xml:1288 msgid "" "Whether the nsupdate utility should default to using TCP for communicating " "with the DNS server." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:293 sssd-ad.5.xml:1299 +#: sssd-ipa.5.xml:288 sssd-ad.5.xml:1292 msgid "Default: False (let nsupdate choose the protocol)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:299 sssd-ad.5.xml:1335 +#: sssd-ipa.5.xml:294 sssd-ad.5.xml:1328 msgid "dyndns_server (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:302 sssd-ad.5.xml:1338 +#: sssd-ipa.5.xml:297 sssd-ad.5.xml:1331 msgid "" "The DNS server to use when performing a DNS update. In most setups, it's " "recommended to leave this option unset." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:307 sssd-ad.5.xml:1343 +#: sssd-ipa.5.xml:302 sssd-ad.5.xml:1336 msgid "" "Setting this option makes sense for environments where the DNS server is " "different from the identity server or when we use encrypted DNS." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:312 sssd-ad.5.xml:1348 +#: sssd-ipa.5.xml:307 sssd-ad.5.xml:1341 msgid "" "The parameter can be a simple string containing DNS name or IP address. It " "can also be an URI. The URI can look like <emphasis>dns://servername/</" @@ -10130,7 +10468,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:319 sssd-ad.5.xml:1355 +#: sssd-ipa.5.xml:314 sssd-ad.5.xml:1348 msgid "" "The second example enables DNS-over-TLS protocol for DNS updates. The " "nsupdate utility must support DoT - check the <emphasis>man nsupdate</" @@ -10138,7 +10476,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:325 sssd-ad.5.xml:1361 +#: sssd-ipa.5.xml:320 sssd-ad.5.xml:1354 msgid "" "Please note that this option will be only used in fallback attempt when " "previous attempt using autodetected settings failed or when DNS-over-TLS is " @@ -10146,17 +10484,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:331 sssd-ad.5.xml:1367 +#: sssd-ipa.5.xml:326 sssd-ad.5.xml:1360 msgid "Default: None (let nsupdate choose the server)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:337 sssd-ad.5.xml:1373 +#: sssd-ipa.5.xml:332 sssd-ad.5.xml:1366 msgid "dyndns_update_per_family (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:340 sssd-ad.5.xml:1376 +#: sssd-ipa.5.xml:335 sssd-ad.5.xml:1369 msgid "" "DNS update is by default performed in two steps - IPv4 update and then IPv6 " "update. In some cases it might be desirable to perform IPv4 and IPv6 update " @@ -10164,14 +10502,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:352 sssd-ad.5.xml:1388 +#: sssd-ipa.5.xml:347 sssd-ad.5.xml:1381 #, fuzzy #| msgid "krb5_rcache_dir (string)" msgid "dyndns_dot_cacert (string)" msgstr "krb5_rcache_dir (řetězec)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:355 sssd-ad.5.xml:1391 +#: sssd-ipa.5.xml:350 sssd-ad.5.xml:1384 msgid "" "This option specifies the file of the certificate authorities certificates " "(in PEM format) in order to verify the remote server TLS certificate when " @@ -10179,19 +10517,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:361 sssd-ad.5.xml:1397 +#: sssd-ipa.5.xml:356 sssd-ad.5.xml:1390 msgid "Default: None (use global certificate store)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:367 sssd-ad.5.xml:1403 +#: sssd-ipa.5.xml:362 sssd-ad.5.xml:1396 #, fuzzy #| msgid "simple_deny_users (string)" msgid "dyndns_dot_cert (string)" msgstr "simple_deny_users (řetězec)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:370 sssd-ad.5.xml:1406 +#: sssd-ipa.5.xml:365 sssd-ad.5.xml:1399 msgid "" "This option sets the certificate(s) file for authentication for the DoT " "transport to the remote server. The certificate chain file is expected to be " @@ -10199,26 +10537,26 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:376 sssd-ad.5.xml:1412 +#: sssd-ipa.5.xml:371 sssd-ad.5.xml:1405 msgid "" "The <emphasis>dyndns_dot_cert</emphasis> and <emphasis>dyndns_dot_key</" "emphasis> options must be both set to achieve mutual TLS authentication." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:381 sssd-ipa.5.xml:396 sssd-ad.5.xml:1417 sssd-ad.5.xml:1432 +#: sssd-ipa.5.xml:376 sssd-ipa.5.xml:391 sssd-ad.5.xml:1410 sssd-ad.5.xml:1425 msgid "Default: None (Do not use TLS authentication)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:387 sssd-ad.5.xml:1423 +#: sssd-ipa.5.xml:382 sssd-ad.5.xml:1416 #, fuzzy #| msgid "ldap_user_passkey (string)" msgid "dyndns_dot_key (string)" msgstr "ldap_user_passkey (řetězec)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:390 sssd-ad.5.xml:1426 +#: sssd-ipa.5.xml:385 sssd-ad.5.xml:1419 msgid "" "This option sets the key file for authenticated encryption for the DoT " "transport to the remote server. The private key file is expected to be in " @@ -10226,172 +10564,172 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:402 +#: sssd-ipa.5.xml:397 msgid "ipa_access_order (string)" msgstr "ipa_access_order (řetězec)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:409 +#: sssd-ipa.5.xml:404 msgid "<emphasis>expire</emphasis>: use IPA's account expiration policy." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:448 +#: sssd-ipa.5.xml:443 msgid "" "Please note that 'access_provider = ipa' must be set for this feature to " "work." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:455 +#: sssd-ipa.5.xml:450 msgid "ipa_deskprofile_search_base (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:458 +#: sssd-ipa.5.xml:453 msgid "" "Optional. Use the given string as search base for Desktop Profile related " "objects." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:462 sssd-ipa.5.xml:484 +#: sssd-ipa.5.xml:457 sssd-ipa.5.xml:479 msgid "Default: Use base DN" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:468 +#: sssd-ipa.5.xml:463 msgid "ipa_subid_ranges_search_base (string)" msgstr "ipa_subid_ranges_search_base (řetězec)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:471 +#: sssd-ipa.5.xml:466 #, fuzzy #| msgid "ipa_subid_ranges_search_base (string)" msgid "Deprecated. Use ldap_subid_ranges_search_base instead." msgstr "ipa_subid_ranges_search_base (řetězec)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:477 +#: sssd-ipa.5.xml:472 msgid "ipa_hbac_search_base (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:480 +#: sssd-ipa.5.xml:475 msgid "Optional. Use the given string as search base for HBAC related objects." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:490 +#: sssd-ipa.5.xml:485 msgid "ipa_host_search_base (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:493 +#: sssd-ipa.5.xml:488 msgid "Deprecated. Use ldap_host_search_base instead." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:499 +#: sssd-ipa.5.xml:494 msgid "ipa_selinux_search_base (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:502 +#: sssd-ipa.5.xml:497 msgid "Optional. Use the given string as search base for SELinux user maps." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:518 +#: sssd-ipa.5.xml:513 msgid "ipa_subdomains_search_base (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:521 +#: sssd-ipa.5.xml:516 msgid "Optional. Use the given string as search base for trusted domains." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:530 +#: sssd-ipa.5.xml:525 msgid "Default: the value of <emphasis>cn=trusts,%basedn</emphasis>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:537 +#: sssd-ipa.5.xml:532 msgid "ipa_master_domain_search_base (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:540 +#: sssd-ipa.5.xml:535 msgid "Optional. Use the given string as search base for master domain object." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:549 +#: sssd-ipa.5.xml:544 msgid "Default: the value of <emphasis>cn=ad,cn=etc,%basedn</emphasis>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:556 +#: sssd-ipa.5.xml:551 msgid "ipa_views_search_base (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:559 +#: sssd-ipa.5.xml:554 msgid "Optional. Use the given string as search base for views containers." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:568 +#: sssd-ipa.5.xml:563 msgid "Default: the value of <emphasis>cn=views,cn=accounts,%basedn</emphasis>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:578 +#: sssd-ipa.5.xml:573 msgid "" "The name of the Kerberos realm. This is optional and defaults to the value " "of <quote>ipa_domain</quote>." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:582 +#: sssd-ipa.5.xml:577 msgid "" "The name of the Kerberos realm has a special meaning in IPA - it is " "converted into the base DN to use for performing LDAP operations." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:590 sssd-ad.5.xml:1441 +#: sssd-ipa.5.xml:585 sssd-ad.5.xml:1434 msgid "krb5_confd_path (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:593 sssd-ad.5.xml:1444 +#: sssd-ipa.5.xml:588 sssd-ad.5.xml:1437 msgid "" "Absolute path of a directory where SSSD should place Kerberos configuration " "snippets." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:597 sssd-ad.5.xml:1448 +#: sssd-ipa.5.xml:592 sssd-ad.5.xml:1441 msgid "" "To disable the creation of the configuration snippets set the parameter to " "'none'." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:601 sssd-ad.5.xml:1452 +#: sssd-ipa.5.xml:596 sssd-ad.5.xml:1445 msgid "" "Default: not set (krb5.include.d subdirectory of SSSD's pubconf directory)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:608 +#: sssd-ipa.5.xml:603 msgid "ipa_deskprofile_refresh (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:611 +#: sssd-ipa.5.xml:606 msgid "" "The amount of time between lookups of the Desktop Profile rules against the " "IPA server. This will reduce the latency and load on the IPA server if there " @@ -10399,34 +10737,34 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:618 sssd-ipa.5.xml:648 sssd-ipa.5.xml:664 sssd-ad.5.xml:600 +#: sssd-ipa.5.xml:613 sssd-ipa.5.xml:643 sssd-ipa.5.xml:659 sssd-ad.5.xml:600 msgid "Default: 5 (seconds)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:624 +#: sssd-ipa.5.xml:619 msgid "ipa_deskprofile_request_interval (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:627 +#: sssd-ipa.5.xml:622 msgid "" "The amount of time between lookups of the Desktop Profile rules against the " "IPA server in case the last request did not return any rule." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:632 +#: sssd-ipa.5.xml:627 msgid "Default: 60 (minutes)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:638 +#: sssd-ipa.5.xml:633 msgid "ipa_hbac_refresh (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:641 +#: sssd-ipa.5.xml:636 msgid "" "The amount of time between lookups of the HBAC rules against the IPA server. " "This will reduce the latency and load on the IPA server if there are many " @@ -10434,12 +10772,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:654 -msgid "ipa_hbac_selinux (integer)" -msgstr "" +#: sssd-ipa.5.xml:649 +#, fuzzy +#| msgid "ldap_idmap_range_size (integer)" +msgid "ipa_selinux_refresh (integer)" +msgstr "ldap_idmap_range_size (celé číslo)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:657 +#: sssd-ipa.5.xml:652 msgid "" "The amount of time between lookups of the SELinux maps against the IPA " "server. This will reduce the latency and load on the IPA server if there are " @@ -10447,33 +10787,33 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:670 +#: sssd-ipa.5.xml:665 msgid "ipa_server_mode (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:673 +#: sssd-ipa.5.xml:668 msgid "" "This option will be set by the IPA installer (ipa-server-install) " "automatically and denotes if SSSD is running on an IPA server or not." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:678 +#: sssd-ipa.5.xml:673 msgid "" "On an IPA server SSSD will lookup users and groups from trusted domains " "directly while on a client it will ask an IPA server." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:683 +#: sssd-ipa.5.xml:678 msgid "" "NOTE: There are currently some assumptions that must be met when SSSD is " "running on an IPA server." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:688 +#: sssd-ipa.5.xml:683 msgid "" "The <quote>ipa_server</quote> option must be configured to point to the IPA " "server itself. This is already the default set by the IPA installer, so no " @@ -10481,59 +10821,59 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:697 +#: sssd-ipa.5.xml:692 msgid "" "The <quote>full_name_format</quote> option must not be tweaked to only print " "short names for users from trusted domains." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:712 +#: sssd-ipa.5.xml:707 msgid "ipa_automount_location (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:715 +#: sssd-ipa.5.xml:710 msgid "The automounter location this IPA client will be using" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:718 +#: sssd-ipa.5.xml:713 msgid "Default: The location named \"default\"" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd-ipa.5.xml:726 +#: sssd-ipa.5.xml:721 msgid "VIEWS AND OVERRIDES" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:735 +#: sssd-ipa.5.xml:730 msgid "ipa_view_class (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:738 +#: sssd-ipa.5.xml:733 msgid "Objectclass of the view container." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:741 +#: sssd-ipa.5.xml:736 msgid "Default: nsContainer" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:747 +#: sssd-ipa.5.xml:742 msgid "ipa_view_name (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:750 +#: sssd-ipa.5.xml:745 msgid "Name of the attribute holding the name of the view." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:754 sssd-ldap-attributes.5.xml:496 +#: sssd-ipa.5.xml:749 sssd-ldap-attributes.5.xml:496 #: sssd-ldap-attributes.5.xml:832 sssd-ldap-attributes.5.xml:913 #: sssd-ldap-attributes.5.xml:1010 sssd-ldap-attributes.5.xml:1068 #: sssd-ldap-attributes.5.xml:1226 sssd-ldap-attributes.5.xml:1271 @@ -10541,128 +10881,128 @@ msgid "Default: cn" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:760 +#: sssd-ipa.5.xml:755 msgid "ipa_override_object_class (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:763 +#: sssd-ipa.5.xml:758 msgid "Objectclass of the override objects." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:766 +#: sssd-ipa.5.xml:761 msgid "Default: ipaOverrideAnchor" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:772 +#: sssd-ipa.5.xml:767 msgid "ipa_anchor_uuid (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:775 +#: sssd-ipa.5.xml:770 msgid "" "Name of the attribute containing the reference to the original object in a " "remote domain." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:779 +#: sssd-ipa.5.xml:774 msgid "Default: ipaAnchorUUID" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:785 +#: sssd-ipa.5.xml:780 msgid "ipa_user_override_object_class (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:788 +#: sssd-ipa.5.xml:783 msgid "" "Name of the objectclass for user overrides. It is used to determine if the " "found override object is related to a user or a group." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:793 +#: sssd-ipa.5.xml:788 msgid "User overrides can contain attributes given by" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:796 +#: sssd-ipa.5.xml:791 msgid "ldap_user_name" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:799 +#: sssd-ipa.5.xml:794 msgid "ldap_user_uid_number" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:802 +#: sssd-ipa.5.xml:797 msgid "ldap_user_gid_number" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:805 +#: sssd-ipa.5.xml:800 msgid "ldap_user_gecos" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:808 +#: sssd-ipa.5.xml:803 msgid "ldap_user_home_directory" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:811 +#: sssd-ipa.5.xml:806 msgid "ldap_user_shell" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:814 +#: sssd-ipa.5.xml:809 msgid "ldap_user_ssh_public_key" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:819 +#: sssd-ipa.5.xml:814 msgid "Default: ipaUserOverride" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:825 +#: sssd-ipa.5.xml:820 msgid "ipa_group_override_object_class (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:828 +#: sssd-ipa.5.xml:823 msgid "" "Name of the objectclass for group overrides. It is used to determine if the " "found override object is related to a user or a group." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:833 +#: sssd-ipa.5.xml:828 msgid "Group overrides can contain attributes given by" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:836 +#: sssd-ipa.5.xml:831 msgid "ldap_group_name" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:839 +#: sssd-ipa.5.xml:834 msgid "ldap_group_gid_number" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:844 +#: sssd-ipa.5.xml:839 msgid "Default: ipaGroupOverride" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:728 +#: sssd-ipa.5.xml:723 msgid "" "SSSD can handle views and overrides which are offered by FreeIPA 4.1 and " "later version. Since all paths and objectclasses are fixed on the server " @@ -10672,19 +11012,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd-ipa.5.xml:856 +#: sssd-ipa.5.xml:851 msgid "SUBDOMAINS PROVIDER" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:858 +#: sssd-ipa.5.xml:853 msgid "" "The IPA subdomains provider behaves slightly differently if it is configured " "explicitly or implicitly." msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:862 +#: sssd-ipa.5.xml:857 msgid "" "If the option 'subdomains_provider = ipa' is found in the domain section of " "sssd.conf, the IPA subdomains provider is configured explicitly, and all " @@ -10692,7 +11032,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:868 +#: sssd-ipa.5.xml:863 msgid "" "If the option 'subdomains_provider' is not set in the domain section of " "sssd.conf but there is the option 'id_provider = ipa', the IPA subdomains " @@ -10704,12 +11044,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd-ipa.5.xml:879 +#: sssd-ipa.5.xml:874 msgid "TRUSTED DOMAINS CONFIGURATION" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-ipa.5.xml:887 +#: sssd-ipa.5.xml:882 #, no-wrap msgid "" "[domain/ipa.domain.com/ad.domain.com]\n" @@ -10717,7 +11057,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:881 +#: sssd-ipa.5.xml:876 msgid "" "Some configuration options can also be set for a trusted domain. A trusted " "domain configuration can be set using the trusted domain subsection as shown " @@ -10727,99 +11067,99 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:892 +#: sssd-ipa.5.xml:887 msgid "" "For more details, see the <citerefentry> <refentrytitle>sssd.conf</" "refentrytitle> <manvolnum>5</manvolnum> </citerefentry> manual page." msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:899 +#: sssd-ipa.5.xml:894 msgid "" "Different configuration options are tunable for a trusted domain depending " "on whether you are configuring SSSD on an IPA server or an IPA client." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd-ipa.5.xml:904 +#: sssd-ipa.5.xml:899 msgid "OPTIONS TUNABLE ON IPA MASTERS" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:906 +#: sssd-ipa.5.xml:901 msgid "" "The following options can be set in a subdomain section on an IPA master:" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:910 sssd-ipa.5.xml:950 +#: sssd-ipa.5.xml:905 sssd-ipa.5.xml:945 msgid "ad_server" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:913 +#: sssd-ipa.5.xml:908 msgid "ad_backup_server" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:916 sssd-ipa.5.xml:953 +#: sssd-ipa.5.xml:911 sssd-ipa.5.xml:948 msgid "ad_site" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:919 +#: sssd-ipa.5.xml:914 #, fuzzy #| msgid "serverAuth" msgid "ipa_server" msgstr "serverAuth" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:922 +#: sssd-ipa.5.xml:917 msgid "ipa_backup_server" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:925 +#: sssd-ipa.5.xml:920 msgid "ldap_search_base" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:928 +#: sssd-ipa.5.xml:923 msgid "ldap_user_search_base" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:931 +#: sssd-ipa.5.xml:926 msgid "ldap_group_search_base" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:939 +#: sssd-ipa.5.xml:934 msgid "" "Options prefixed with 'ad_' or 'ipa_' only apply to their respective " "subdomain type." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd-ipa.5.xml:944 +#: sssd-ipa.5.xml:939 msgid "OPTIONS TUNABLE ON IPA CLIENTS" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:946 +#: sssd-ipa.5.xml:941 msgid "" "The following options can be set in an AD subdomain section on an IPA client:" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:958 +#: sssd-ipa.5.xml:953 msgid "" "Note that if both options are set, only <quote>ad_server</quote> is " "evaluated." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:962 +#: sssd-ipa.5.xml:957 msgid "" "Since any request for a user or a group identity from a trusted domain " "triggered from an IPA client is resolved by the IPA server, the " @@ -10833,7 +11173,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:986 +#: sssd-ipa.5.xml:981 msgid "" "The following example assumes that SSSD is correctly configured and " "example.com is one of the domains in the <replaceable>[sssd]</replaceable> " @@ -10841,7 +11181,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-ipa.5.xml:993 +#: sssd-ipa.5.xml:988 #, no-wrap msgid "" "[domain/example.com]\n" @@ -11540,27 +11880,27 @@ msgid "lxdm" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:694 +#: sssd-ad.5.xml:699 msgid "sddm" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:699 +#: sssd-ad.5.xml:704 msgid "unity" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:704 +#: sssd-ad.5.xml:709 msgid "xdm" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:713 +#: sssd-ad.5.xml:718 msgid "ad_gpo_map_remote_interactive (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:716 +#: sssd-ad.5.xml:721 msgid "" "A comma-separated list of PAM service names for which GPO-based access " "control is evaluated based on the RemoteInteractiveLogonRight and " @@ -11576,7 +11916,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:735 +#: sssd-ad.5.xml:740 msgid "" "Note: Using the Group Policy Management Editor this value is called \"Allow " "log on through Remote Desktop Services\" and \"Deny log on through Remote " @@ -11584,7 +11924,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:750 +#: sssd-ad.5.xml:755 #, no-wrap msgid "" "ad_gpo_map_remote_interactive = +my_pam_service, -sshd\n" @@ -11592,7 +11932,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:741 +#: sssd-ad.5.xml:746 msgid "" "It is possible to add another PAM service name to the default set by using " "<quote>+service_name</quote> or to explicitly remove a PAM service name from " @@ -11604,22 +11944,22 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:758 +#: sssd-ad.5.xml:763 msgid "sshd" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:763 +#: sssd-ad.5.xml:768 msgid "cockpit" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:772 +#: sssd-ad.5.xml:777 msgid "ad_gpo_map_network (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:775 +#: sssd-ad.5.xml:780 msgid "" "A comma-separated list of PAM service names for which GPO-based access " "control is evaluated based on the NetworkLogonRight and " @@ -11635,7 +11975,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:793 +#: sssd-ad.5.xml:798 msgid "" "Note: Using the Group Policy Management Editor this value is called \"Access " "this computer from the network\" and \"Deny access to this computer from the " @@ -11643,7 +11983,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:808 +#: sssd-ad.5.xml:813 #, no-wrap msgid "" "ad_gpo_map_network = +my_pam_service, -ftp\n" @@ -11651,7 +11991,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:799 +#: sssd-ad.5.xml:804 msgid "" "It is possible to add another PAM service name to the default set by using " "<quote>+service_name</quote> or to explicitly remove a PAM service name from " @@ -11663,22 +12003,22 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:816 +#: sssd-ad.5.xml:821 msgid "ftp" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:821 +#: sssd-ad.5.xml:826 msgid "samba" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:830 +#: sssd-ad.5.xml:835 msgid "ad_gpo_map_batch (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:833 +#: sssd-ad.5.xml:838 msgid "" "A comma-separated list of PAM service names for which GPO-based access " "control is evaluated based on the BatchLogonRight and DenyBatchLogonRight " @@ -11693,14 +12033,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:851 +#: sssd-ad.5.xml:856 msgid "" "Note: Using the Group Policy Management Editor this value is called \"Allow " "log on as a batch job\" and \"Deny log on as a batch job\"." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:865 +#: sssd-ad.5.xml:870 #, no-wrap msgid "" "ad_gpo_map_batch = +my_pam_service, -crond\n" @@ -11708,7 +12048,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:856 +#: sssd-ad.5.xml:861 msgid "" "It is possible to add another PAM service name to the default set by using " "<quote>+service_name</quote> or to explicitly remove a PAM service name from " @@ -11720,23 +12060,23 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:868 +#: sssd-ad.5.xml:873 msgid "" "Note: Cron service name may differ depending on Linux distribution used." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:874 +#: sssd-ad.5.xml:879 msgid "crond" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:883 +#: sssd-ad.5.xml:888 msgid "ad_gpo_map_service (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:886 +#: sssd-ad.5.xml:891 msgid "" "A comma-separated list of PAM service names for which GPO-based access " "control is evaluated based on the ServiceLogonRight and " @@ -11752,14 +12092,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:904 +#: sssd-ad.5.xml:909 msgid "" "Note: Using the Group Policy Management Editor this value is called \"Allow " "log on as a service\" and \"Deny log on as a service\"." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:917 +#: sssd-ad.5.xml:922 #, no-wrap msgid "" "ad_gpo_map_service = +my_pam_service\n" @@ -11767,7 +12107,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:909 sssd-ad.5.xml:984 +#: sssd-ad.5.xml:914 sssd-ad.5.xml:989 msgid "" "It is possible to add a PAM service name to the default set by using " "<quote>+service_name</quote>. Since the default set is empty, it is not " @@ -11778,19 +12118,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:927 +#: sssd-ad.5.xml:932 msgid "ad_gpo_map_permit (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:930 +#: sssd-ad.5.xml:935 msgid "" "A comma-separated list of PAM service names for which GPO-based access is " "always granted, regardless of any GPO Logon Rights." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:944 +#: sssd-ad.5.xml:949 #, no-wrap msgid "" "ad_gpo_map_permit = +my_pam_service, -sudo\n" @@ -11798,7 +12138,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:935 +#: sssd-ad.5.xml:940 msgid "" "It is possible to add another PAM service name to the default set by using " "<quote>+service_name</quote> or to explicitly remove a PAM service name from " @@ -11810,29 +12150,29 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:952 +#: sssd-ad.5.xml:957 msgid "polkit-1" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:967 +#: sssd-ad.5.xml:972 msgid "systemd-user" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:976 +#: sssd-ad.5.xml:981 msgid "ad_gpo_map_deny (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:979 +#: sssd-ad.5.xml:984 msgid "" "A comma-separated list of PAM service names for which GPO-based access is " "always denied, regardless of any GPO Logon Rights." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:992 +#: sssd-ad.5.xml:997 #, no-wrap msgid "" "ad_gpo_map_deny = +my_pam_service\n" @@ -11840,12 +12180,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:1002 +#: sssd-ad.5.xml:1007 msgid "ad_gpo_default_right (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1005 +#: sssd-ad.5.xml:1010 msgid "" "This option defines how access control is evaluated for PAM service names " "that are not explicitly listed in one of the ad_gpo_map_* options. This " @@ -11858,52 +12198,52 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1018 +#: sssd-ad.5.xml:1023 msgid "Supported values for this option include:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1027 +#: sssd-ad.5.xml:1032 msgid "remote_interactive" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1032 +#: sssd-ad.5.xml:1037 msgid "network" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1037 +#: sssd-ad.5.xml:1042 msgid "batch" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1042 +#: sssd-ad.5.xml:1047 msgid "service" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1047 +#: sssd-ad.5.xml:1052 msgid "permit" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1052 +#: sssd-ad.5.xml:1057 msgid "deny" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1058 +#: sssd-ad.5.xml:1063 msgid "Default: deny" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:1064 +#: sssd-ad.5.xml:1069 msgid "ad_maximum_machine_account_password_age (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1067 +#: sssd-ad.5.xml:1072 msgid "" "SSSD will check once a day if the machine account password is older than the " "given age in days and try to renew it. A value of 0 will disable the renewal " @@ -11911,17 +12251,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1073 +#: sssd-ad.5.xml:1078 msgid "Default: 30 days" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:1079 +#: sssd-ad.5.xml:1084 msgid "ad_machine_account_password_renewal_opts (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1082 +#: sssd-ad.5.xml:1087 msgid "" "This option should only be used to test the machine account renewal task. " "The option expects 3 integers and a string separated by a colon (':'). The " @@ -11934,20 +12274,20 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1096 +#: sssd-ad.5.xml:1101 msgid "" "The optional fourth string value identifies the helper binary which should " "be used for the renewal. Currently <command>adcli</command> and " "<command>realm</command> are supported. If this value is missing or empty in " "the value string <command>realm</command> will be used. Since the helper is " "started as the user SSSD is running as there might be the chance that the " -"renewal will fail if this user does not has permissions to modify the keytab " -"file where the machine account credentials are stored. This will typically " -"be the case for <command>adcli</command>." +"renewal will fail if this user does not have permissions to modify the " +"keytab file where the machine account credentials are stored. This will " +"typically be the case for <command>adcli</command>." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1110 +#: sssd-ad.5.xml:1115 msgid "" "<command>realm</command> is not updating the keytab directly but is calling " "the <command>realmd</command> process, which runs as root user, for this " @@ -11957,17 +12297,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1119 +#: sssd-ad.5.xml:1124 msgid "Default: 86400:750:300:realm (24h, 12m30s and 5m)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:1125 +#: sssd-ad.5.xml:1130 msgid "ad_update_samba_machine_account_password (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1128 +#: sssd-ad.5.xml:1133 msgid "" "If enabled, when SSSD renews the machine account password, it will also be " "updated in Samba's database. This prevents Samba's copy of the machine " @@ -11976,23 +12316,23 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:1141 -msgid "ad_use_ldaps (bool)" +#: sssd-ad.5.xml:1146 +msgid "ad_use_ldaps (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1144 +#: sssd-ad.5.xml:1149 msgid "" "By default SSSD uses the plain LDAP port 389 and the Global Catalog port " -"3628. If this option is set to True SSSD will use the LDAPS port 636 and " -"Global Catalog port 3629 with LDAPS protection. Since AD does not allow to " +"3268. If this option is set to True SSSD will use the LDAPS port 636 and " +"Global Catalog port 3269 with LDAPS protection. Since AD does not allow to " "have multiple encryption layers on a single connection and we still want to " "use SASL/GSSAPI or SASL/GSS-SPNEGO for authentication the SASL security " "property maxssf is set to 0 (zero) for those connections." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1164 +#: sssd-ad.5.xml:1169 msgid "" "Optional. This option tells SSSD to automatically update the Active " "Directory DNS server with the IP address of this client. The update is " @@ -12010,30 +12350,21 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:1216 msgid "" -"NOTE: While it is still possible to use the old <emphasis>ipa_dyndns_iface</" -"emphasis> option, users should migrate to using <emphasis>dyndns_iface</" -"emphasis> in their config file." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1222 -msgid "" "Default: Use the IP addresses of the interface which is used for AD LDAP " "connection" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1258 +#: sssd-ad.5.xml:1252 msgid "" "How often should the back end perform periodic DNS update in addition to the " -"automatic update performed when the back end goes online. This option is " -"optional and applicable only when dyndns_update is true. Note that the " -"lowest possible value is 60 seconds in-case if value is provided less than " -"60, parameter will assume lowest value only." +"automatic update performed when the back end goes online. This is optional " +"and applicable only when dyndns_update is true. Note that the minimum value " +"is 60 seconds, any specified value below this threshold will default to 60." msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ad.5.xml:1472 +#: sssd-ad.5.xml:1465 msgid "" "The following example assumes that SSSD is correctly configured and " "example.com is one of the domains in the <replaceable>[sssd]</replaceable> " @@ -12041,7 +12372,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-ad.5.xml:1479 +#: sssd-ad.5.xml:1472 #, no-wrap msgid "" "[domain/EXAMPLE]\n" @@ -12056,7 +12387,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-ad.5.xml:1499 +#: sssd-ad.5.xml:1492 #, no-wrap msgid "" "access_provider = ldap\n" @@ -12065,7 +12396,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ad.5.xml:1495 +#: sssd-ad.5.xml:1488 msgid "" "The AD access control provider checks if the account is expired. It has the " "same effect as the following configuration of the LDAP provider: " @@ -12073,7 +12404,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ad.5.xml:1505 +#: sssd-ad.5.xml:1498 msgid "" "However, unless the <quote>ad</quote> access control provider is explicitly " "configured, the default access provider is <quote>permit</quote>. Please " @@ -12083,7 +12414,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ad.5.xml:1513 +#: sssd-ad.5.xml:1506 msgid "" "When the autofs provider is set to <quote>ad</quote>, the RFC2307 schema " "attribute mapping (nisMap, nisObject, ...) is used, because these attributes " @@ -12237,9 +12568,9 @@ msgstr "" #: sssd-sudo.5.xml:137 msgid "" "The <emphasis>smart refresh</emphasis> periodically downloads rules that are " -"new or were modified after the last update. Its primary goal is to keep the " -"database growing by fetching only small increments that do not generate " -"large amounts of network traffic." +"new or were modified after the last update. Its primary goal is to grow the " +"database incrementally by fetching only small updates, avoiding large " +"amounts of network traffic." msgstr "" #. type: Content of: <reference><refentry><refsect1><para> @@ -12423,26 +12754,29 @@ msgstr "" msgid "" "Depending on the IdP product additional platform specific options might " "follow the name separated by a colon (:). E.g. for Keycloak the base URI for " -"the user and group REST API must be given. For Entra ID this is not needed " -"because there is a generic endpoint for all tenants." +"the user and group REST API must be given. For Entra ID the base URI for the " +"Microsoft Graph API can be given to use sovereign or government cloud " +"endpoints instead of the default (https://graph.microsoft.com/v1.0). E.g. " +"<quote>entra_id:https://graph.microsoft.us/v1.0</quote> for the US " +"government cloud (GCC High)." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:78 sssd-idp.5.xml:94 sssd-idp.5.xml:119 +#: sssd-idp.5.xml:82 sssd-idp.5.xml:98 sssd-idp.5.xml:123 #, fuzzy #| msgid "Default: not set (spaces will not be replaced)" msgid "Default: Not set (Required)" msgstr "Výchozí: nenastaveno (mezery nebudou nahrazovány)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:83 +#: sssd-idp.5.xml:87 #, fuzzy #| msgid "ipa_access_order (string)" msgid "idp_client_id (string)" msgstr "ipa_access_order (řetězec)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:86 +#: sssd-idp.5.xml:90 msgid "" "ID of the IdP client used by SSSD to authenticate users and as a client to " "lookup user and group attributes. This client must offer device " @@ -12451,14 +12785,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:99 +#: sssd-idp.5.xml:103 #, fuzzy #| msgid "simple_deny_users (string)" msgid "idp_client_secret (string)" msgstr "simple_deny_users (řetězec)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:102 +#: sssd-idp.5.xml:106 msgid "" "Password of the IdP client. The password is required for the id_provider. If " "only used as auth_provider it depends on the server side configuration if it " @@ -12466,76 +12800,83 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:113 +#: sssd-idp.5.xml:117 #, fuzzy #| msgid "ldap_idmap_default_domain (string)" msgid "idp_token_endpoint (string)" msgstr "ldap_idmap_default_domain (řetězec)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:116 +#: sssd-idp.5.xml:120 msgid "IdP endpoint for requesting access tokens." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:124 +#: sssd-idp.5.xml:128 #, fuzzy #| msgid "ldap_idmap_default_domain (string)" msgid "idp_device_auth_endpoint (string)" msgstr "ldap_idmap_default_domain (řetězec)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:127 +#: sssd-idp.5.xml:131 msgid "" "IdP endpoint for device authorization according to RFC-8628. This is " "required for user authentication." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:137 +#: sssd-idp.5.xml:141 #, fuzzy #| msgid "ldap_user_passkey (string)" msgid "idp_userinfo_endpoint (string)" msgstr "ldap_user_passkey (řetězec)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:140 +#: sssd-idp.5.xml:144 msgid "" "IdP userinfo endpoint to request user attributes after a successful " "authentication of the user. Required for authentication." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:150 +#: sssd-idp.5.xml:154 #, fuzzy #| msgid "simple_deny_users (string)" msgid "idp_id_scope (string)" msgstr "simple_deny_users (řetězec)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:153 +#: sssd-idp.5.xml:157 msgid "" "Scope required for looking up user and group attributes with the REST API. " "The scopes are used by the server to determine which attributes/claims are " "returned to the caller." msgstr "" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:163 +msgid "" +"Note: In previous versions of SSSD, this option was expected to already be " +"URL-encoded." +msgstr "" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:164 +#: sssd-idp.5.xml:172 #, fuzzy #| msgid "pac_check (string)" msgid "idp_auth_scope (string)" msgstr "pac_check (řetězec)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:167 +#: sssd-idp.5.xml:175 msgid "" "Scope required during authentication. The scopes are used by the server to " "determine which attributes/claims are returned to the caller." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:172 +#: sssd-idp.5.xml:180 msgid "" "Currently the tokens returned during user authentication are not used for " "other purposes hence the only important claim is the subject identifier " @@ -12544,26 +12885,122 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:185 +#: sssd-idp.5.xml:193 +#, fuzzy +#| msgid "pac_check (string)" +msgid "idp_auth_user_identifier_attr (string)" +msgstr "pac_check (řetězec)" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:196 +msgid "" +"Attribute used to identify the authenticated user in userinfo data or token " +"claims." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:200 +msgid "" +"For hybrid Active Directory and Entra ID deployments where " +"<quote>id_provider = ad</quote> and <quote>auth_provider = idp</quote>, this " +"option must be set explicitly. No value is derived from the identity " +"provider, because more than one attribute can link an Entra ID object to its " +"on-premises counterpart and only the administrator knows which one the " +"directory synchronization is configured to use." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:211 +msgid "" +"Setting this option to <quote>onPremisesImmutableId</quote> is the usual " +"choice for such deployments. Microsoft Entra Connect populates that " +"attribute with the base64-encoded form of the 16-byte Active Directory " +"<quote>objectGUID</quote> when objectGUID is used as the sourceAnchor. SSSD " +"decodes the value and converts the raw bytes with the same conversion used " +"for AD objectGUID attributes, so the result matches the UUID stored in the " +"SSSD cache for the AD user." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:224 +msgid "" +"Note that Microsoft Entra Connect 1.1.524.0 and later use <quote>ms-DS-" +"ConsistencyGuid</quote> as the sourceAnchor for user objects instead of " +"<quote>objectGUID</quote>. The value is normally copied from objectGUID for " +"objects that do not have it set yet, in which case the decoded identifier " +"still matches. It does not match if ms-DS-ConsistencyGuid was populated " +"independently, if users were moved between forests or domains, or if a " +"different attribute such as employeeID was selected as the sourceAnchor. See " +"<ulink url=\"https://learn.microsoft.com/en-us/entra/identity/hybrid/connect/" +"plan-connect-design-concepts\"> Microsoft Entra Connect: Design concepts</" +"ulink> for details on sourceAnchor selection." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:241 +msgid "" +"Microsoft Graph does not return <quote>onPremisesImmutableId</quote> by " +"default. The <quote>idp_userinfo_endpoint</quote> must request it with " +"<quote>$select</quote>, see the example below and <ulink url=\"https://" +"learn.microsoft.com/en-us/graph/api/resources/user\"> the Microsoft Graph " +"user resource type</ulink>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:251 +msgid "" +"If the configured attribute is missing or cannot be decoded (for example " +"cloud-only Entra ID users without <quote>onPremisesImmutableId</quote>), " +"authentication fails. SSSD does not fall back to another attribute when this " +"option is set." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:258 +msgid "" +"Default: not set, <quote>sub</quote> for Keycloak and <quote>id</quote> for " +"other IdP types" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-idp.5.xml:264 #, fuzzy #| msgid "dns_resolver_op_timeout (integer)" msgid "idp_request_timeout (integer)" msgstr "dns_resolver_op_timeout (celé číslo)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:188 +#: sssd-idp.5.xml:267 msgid "Timeout in seconds for an individual request to the IdP." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:197 +#: sssd-idp.5.xml:276 +msgid "idp_auto_refresh (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:279 +msgid "" +"Refresh tokens automatically, after they have reached about half their " +"lifetime." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:283 +msgid "" +"Note: Scheduled token refreshes are not preserved across restarts of SSSD." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-idp.5.xml:292 #, fuzzy #| msgid "ldap_idmap_range_min (integer)" msgid "idmap_range_min (integer)" msgstr "ldap_idmap_range_min (celé číslo)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:200 +#: sssd-idp.5.xml:295 msgid "" "Specifies the lower (inclusive) bound of the range of POSIX IDs to use for " "mapping IdP users and group to POSIX IDs. It is the first POSIX ID which can " @@ -12571,7 +13008,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:206 +#: sssd-idp.5.xml:301 msgid "" "The interval between <quote>idmap_range_min</quote> and " "<quote>idmap_range_max</quote> will be split into smaller ranges of size " @@ -12580,20 +13017,20 @@ msgid "" msgstr "" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:213 sssd-idp.5.xml:239 include/ldap_id_mapping.xml:139 +#: sssd-idp.5.xml:308 sssd-idp.5.xml:334 include/ldap_id_mapping.xml:139 #: include/ldap_id_mapping.xml:197 msgid "Default: 200000" msgstr "Výchozí: 200000" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:218 +#: sssd-idp.5.xml:313 #, fuzzy #| msgid "ldap_idmap_range_max (integer)" msgid "idmap_range_max (integer)" msgstr "ldap_idmap_range_max (celé číslo)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:221 +#: sssd-idp.5.xml:316 msgid "" "Specifies the upper (exclusive) bound of the range of POSIX IDs to use for " "mapping IdP users and groups to POSIX IDs. It is the first POSIX ID which " @@ -12601,47 +13038,70 @@ msgid "" msgstr "" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:227 include/ldap_id_mapping.xml:165 +#: sssd-idp.5.xml:322 include/ldap_id_mapping.xml:165 msgid "Default: 2000200000" msgstr "Výchozí: 2000200000" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:232 +#: sssd-idp.5.xml:327 #, fuzzy #| msgid "ldap_idmap_range_size (integer)" msgid "idmap_range_size (integer)" msgstr "ldap_idmap_range_size (celé číslo)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:235 +#: sssd-idp.5.xml:330 msgid "Specifies the number of POSIX IDs available for a single IdP domain." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-idp.5.xml:251 +#: sssd-idp.5.xml:346 #, no-wrap msgid "" "[domain/entra_id]\n" "id_provider = idp\n" "idp_type = entra_id\n" "idp_client_id = 12345678-abcd-0101-efef-ba9876543210\n" -"idp_client_secret = YOUR-CLIENT-SCERET\n" -"idp_token_endpoint = https://login.microsoftonline.com/TENNANT-ID/oauth2/v2.0/token\n" +"idp_client_secret = YOUR-CLIENT-SECRET\n" +"idp_token_endpoint = https://login.microsoftonline.com/TENANT-ID/oauth2/v2.0/token\n" "idp_userinfo_endpoint = https://graph.microsoft.com/v1.0/me\n" -"idp_device_auth_endpoint = https://login.microsoftonline.com/TENNANT-ID/oauth2/v2.0/devicecode\n" -"idp_id_scope = https%3A%2F%2Fgraph.microsoft.com%2F.default\n" +"idp_device_auth_endpoint = https://login.microsoftonline.com/TENANT-ID/oauth2/v2.0/devicecode\n" +"idp_id_scope = https://graph.microsoft.com/.default\n" +"idp_auth_scope = openid profile email\n" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><programlisting> +#: sssd-idp.5.xml:358 +#, no-wrap +msgid "" +"[domain/ad.example.com]\n" +"id_provider = ad\n" +"auth_provider = idp\n" +"access_provider = permit\n" +"\n" +"ad_domain = ad.example.com\n" +"krb5_realm = AD.EXAMPLE.COM\n" +"\n" +"idp_type = entra_id\n" +"idp_client_id = 12345678-abcd-0101-efef-ba9876543210\n" +"idp_client_secret = YOUR-CLIENT-SECRET\n" +"idp_token_endpoint = https://login.microsoftonline.com/TENANT-ID/oauth2/v2.0/token\n" +"idp_userinfo_endpoint = https://graph.microsoft.com/v1.0/me?$select=id,userPrincipalName,onPremisesImmutableId\n" +"idp_device_auth_endpoint = https://login.microsoftonline.com/TENANT-ID/oauth2/v2.0/devicecode\n" +"idp_id_scope = https://graph.microsoft.com/.default\n" "idp_auth_scope = openid profile email\n" +"idp_auth_user_identifier_attr = onPremisesImmutableId\n" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-idp.5.xml:263 +#: sssd-idp.5.xml:377 #, no-wrap msgid "" "[domain/keycloak]\n" "idp_type = keycloak:https://master.keycloak.test:8443/auth/admin/realms/master/\n" "id_provider = idp\n" "idp_client_id = myclient\n" -"idp_client_secret = YOUR-CLIENT-SCERET\n" +"idp_client_secret = YOUR-CLIENT-SECRET\n" "idp_token_endpoint = https://master.keycloak.test:8443/auth/realms/master/protocol/openid-connect/token\n" "idp_userinfo_endpoint = https://master.keycloak.test:8443/auth/realms/master/protocol/openid-connect/userinfo\n" "idp_device_auth_endpoint = https://master.keycloak.test:8443/auth/realms/master/protocol/openid-connect/auth/device\n" @@ -12650,14 +13110,26 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-idp.5.xml:250 +#: sssd-idp.5.xml:345 #, fuzzy #| msgid "example: <placeholder type=\"programlisting\" id=\"0\"/>" msgid "" "<placeholder type=\"programlisting\" id=\"0\"/> <placeholder " -"type=\"programlisting\" id=\"1\"/>" +"type=\"programlisting\" id=\"1\"/> <placeholder type=\"programlisting\" " +"id=\"2\"/>" msgstr "příklad: <placeholder type=\"programlisting\" id=\"0\"/>" +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-idp.5.xml:390 +msgid "" +"In the hybrid Active Directory and Entra ID example above, " +"<quote>onPremisesImmutableId</quote> is used during authentication so the " +"IdP result matches the AD objectGUID UUID stored in the SSSD cache. The " +"attribute must be requested via <quote>$select</quote> on the Graph userinfo " +"endpoint and is only populated for users synchronized from Active Directory " +"with objectGUID as the sourceAnchor." +msgstr "" + #. type: Content of: <reference><refentry><refnamediv><refname> #: sssd.8.xml:10 sssd.8.xml:15 msgid "sssd" @@ -13621,7 +14093,7 @@ msgstr "" #: sssd-krb5.5.xml:291 msgid "" "<emphasis>demand</emphasis> to use FAST. The authentication fails if the " -"server does not require fast." +"server does not support FAST." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> @@ -14510,7 +14982,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sss_rpcidmapd.5.xml:69 -msgid "memcache (bool)" +msgid "memcache (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> @@ -14564,7 +15036,7 @@ msgid "" msgstr "" #. type: Content of: <refsect1><title> -#: sss_rpcidmapd.5.xml:120 sssd-kcm.8.xml:316 include/seealso.xml:2 +#: sss_rpcidmapd.5.xml:120 sssd-kcm.8.xml:315 include/seealso.xml:2 msgid "SEE ALSO" msgstr "VIZ TAKÉ" @@ -14793,8 +15265,8 @@ msgstr "" #: sss_ssh_knownhosts.1.xml:93 msgid "" "The key lines retrieved from the backend are expected to respect the key " -"format as decribed in the <quote>SSH_KNOWN_HOSTS FILE FORMAT</quote> section " -"of <citerefentry><refentrytitle>sshd</refentrytitle> <manvolnum>8</" +"format as described in the <quote>SSH_KNOWN_HOSTS FILE FORMAT</quote> " +"section of <citerefentry><refentrytitle>sshd</refentrytitle> <manvolnum>8</" "manvolnum></citerefentry>. However, returning only the keytype and the key " "itself is tolerated, in which case, the hostname received as parameter will " "be added before the keytype to output a correctly formatted line. The " @@ -15270,14 +15742,13 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-kcm.8.xml:215 msgid "" -"The KCM service is configured in the <quote>kcm</quote> For a detailed " -"syntax reference, refer to the <quote>FILE FORMAT</quote> section of the " -"<citerefentry> <refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</" -"manvolnum> </citerefentry> manual page." +"For a detailed syntax reference, refer to the <quote>FILE FORMAT</quote> " +"section of the <citerefentry> <refentrytitle>sssd.conf</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry> manual page." msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-kcm.8.xml:223 +#: sssd-kcm.8.xml:222 msgid "" "The generic SSSD service options such as <quote>debug_level</quote> or " "<quote>fd_limit</quote> are accepted by the kcm service. Please refer to " @@ -15287,22 +15758,22 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:234 +#: sssd-kcm.8.xml:233 msgid "socket_path (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:237 +#: sssd-kcm.8.xml:236 msgid "The socket the KCM service will listen on." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:240 +#: sssd-kcm.8.xml:239 msgid "Default: <replaceable>/var/run/.heim_org.h5l.kcm-socket</replaceable>" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:243 +#: sssd-kcm.8.xml:242 msgid "" "<phrase condition=\"have_systemd\"> Note: on platforms where systemd is " "supported, the socket path is overwritten by the one defined in the sssd-" @@ -15310,86 +15781,86 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:252 +#: sssd-kcm.8.xml:251 msgid "max_ccaches (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:255 +#: sssd-kcm.8.xml:254 msgid "How many credential caches does the KCM database allow for all users." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:259 +#: sssd-kcm.8.xml:258 msgid "Default: 0 (unlimited, only the per-UID quota is enforced)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:264 +#: sssd-kcm.8.xml:263 msgid "max_uid_ccaches (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:267 +#: sssd-kcm.8.xml:266 msgid "" "How many credential caches does the KCM database allow per UID. This is " "equivalent to <quote>with how many principals you can kinit</quote>." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:272 +#: sssd-kcm.8.xml:271 msgid "Default: 64" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:277 +#: sssd-kcm.8.xml:276 msgid "max_ccache_size (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:280 +#: sssd-kcm.8.xml:279 msgid "" -"How big can a credential cache be per ccache. Each service ticket accounts " -"into this quota." +"How big a credential cache be per ccache. Each service ticket counts toward " +"this quota." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:284 +#: sssd-kcm.8.xml:283 msgid "Default: 65536" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:289 -msgid "tgt_renewal (bool)" +#: sssd-kcm.8.xml:288 +msgid "tgt_renewal (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:292 +#: sssd-kcm.8.xml:291 msgid "Enables TGT renewals functionality." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:295 +#: sssd-kcm.8.xml:294 msgid "Default: False (Automatic renewals disabled)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:300 +#: sssd-kcm.8.xml:299 msgid "tgt_renewal_inherit (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:303 +#: sssd-kcm.8.xml:302 msgid "Domain to inherit krb5_* options from, for use with TGT renewals." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:307 +#: sssd-kcm.8.xml:306 msgid "Default: NULL" msgstr "Výchozí: NULL" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-kcm.8.xml:318 +#: sssd-kcm.8.xml:317 msgid "" "<citerefentry> <refentrytitle>sssd</refentrytitle><manvolnum>8</manvolnum> </" "citerefentry>, <citerefentry> <refentrytitle>sssd.conf</" @@ -16295,8 +16766,8 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap-attributes.5.xml:381 sssd-ldap-attributes.5.xml:395 -msgid "Default: loginDisabled" +#: sssd-ldap-attributes.5.xml:381 +msgid "Default: loginDisabled (rfc2307, rfc2307bis and IPA), not set (AD)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> @@ -16311,6 +16782,12 @@ msgid "" "which date access is granted." msgstr "" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:395 +msgid "" +"Default: loginExpirationTime (rfc2307, rfc2307bis and IPA), not set (AD)" +msgstr "" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:401 msgid "ldap_user_nds_login_allowed_time_map (string)" @@ -16325,7 +16802,8 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:409 -msgid "Default: loginAllowedTimeMap" +msgid "" +"Default: loginAllowedTimeMap (rfc2307, rfc2307bis and IPA), not set (AD)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> @@ -16841,8 +17319,8 @@ msgid "The object class of a host entry in LDAP." msgstr "Třída objektu položky hostitele v LDAP." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap-attributes.5.xml:900 sssd-ldap-attributes.5.xml:997 -msgid "Default: ipService" +#: sssd-ldap-attributes.5.xml:900 sssd-ldap-attributes.5.xml:1213 +msgid "Default: ipHost" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> @@ -16927,6 +17405,11 @@ msgstr "" msgid "The object class of a service entry in LDAP." msgstr "" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:997 +msgid "Default: ipService" +msgstr "" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1003 msgid "ldap_service_name (string)" @@ -17167,11 +17650,6 @@ msgstr "" msgid "The object class of an iphost entry in LDAP." msgstr "" -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap-attributes.5.xml:1213 -msgid "Default: ipHost" -msgstr "" - #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1219 msgid "ldap_iphost_name (string)" @@ -17417,6 +17895,7 @@ msgstr "" msgid "" "[plugins]\n" " localauth = {\n" +" disable = an2ln\n" " module = sssd:/usr/lib64/sssd/modules/sssd_krb5_localauth_plugin.so\n" " }\n" msgstr "" @@ -17433,6 +17912,28 @@ msgid "" "the local Kerberos configuration the plugin will be enabled automatically." msgstr "" +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_localauth_plugin.8.xml:67 +msgid "" +"This configuration snippet also disables the <command>an2ln</command> module " +"provided by MIT Kerberos if SSSD is configured to use the AD or IPA " +"provider. In those environments <command>sssd_krb5_localauth_plugin</" +"command> can reliably map the system user names to Kerberos principals. A " +"fallback to <command>an2ln</command> might cause issues in environments " +"where users have the privilege to create Kerberos principals on their own " +"which might collide with names of other users used in the system. Other " +"modules provided by MIT Kerberos, e.g. <command>k5login</command> are not " +"affected." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_localauth_plugin.8.xml:79 +msgid "" +"Note: If using <quote>auth_provider = krb5</quote> then " +"<command>sssd_krb5_localauth_plugin</command> is not used, therefore the " +"above text is not applicable." +msgstr "" + #. type: Content of: <variablelist><varlistentry><term> #: include/autofs_attributes.xml:3 msgid "ldap_autofs_map_object_class (string)" @@ -18291,30 +18792,6 @@ msgid "" "failures; corresponds to setting 2 in decimal notation)" msgstr "" -#. type: Content of: <refsect1><title> -#: include/local.xml:2 -msgid "THE LOCAL DOMAIN" -msgstr "" - -#. type: Content of: <refsect1><para> -#: include/local.xml:4 -msgid "" -"In order to function correctly, a domain with <quote>id_provider=local</" -"quote> must be created and the SSSD must be running." -msgstr "" - -#. type: Content of: <refsect1><para> -#: include/local.xml:9 -msgid "" -"The administrator might want to use the SSSD local users instead of " -"traditional UNIX users in cases where the group nesting (see <citerefentry> " -"<refentrytitle>sss_groupadd</refentrytitle> <manvolnum>8</manvolnum> </" -"citerefentry>) is needed. The local users are also useful for testing and " -"development of the SSSD without having to deploy a full remote server. The " -"<command>sss_user*</command> and <command>sss_group*</command> tools use a " -"local LDB storage to store users and groups." -msgstr "" - #. type: Content of: <refsect1><para> #: include/seealso.xml:4 msgid "" @@ -18918,6 +19395,19 @@ msgid "" "feature is available with MIT Kerberos 1.7 and later versions." msgstr "" +#~ msgid "" +#~ "The data types used are string (no quotes needed), integer and bool (with " +#~ "values of <quote>TRUE/FALSE</quote>)." +#~ msgstr "" +#~ "Používané datové typy jsou řetězce (není třeba obklopovat uvozovkami), " +#~ "celá čísla bolean (s hodnotami <quote>TRUE/FALSE</quote>)." + +#~ msgid "services" +#~ msgstr "služby" + +#~ msgid "domains" +#~ msgstr "domény" + #~ msgid "all" #~ msgstr "vše" diff --git a/src/man/po/de.po b/src/man/po/de.po index 5db53c17a2a..b8d0ec8243c 100644 --- a/src/man/po/de.po +++ b/src/man/po/de.po @@ -10,8 +10,8 @@ msgid "" msgstr "" "Project-Id-Version: sssd-docs 2.3.0\n" "Report-Msgid-Bugs-To: sssd-devel@redhat.com\n" -"POT-Creation-Date: 2026-01-14 15:00+0000\n" -"PO-Revision-Date: 2026-04-23 16:21+0000\n" +"POT-Creation-Date: 2026-10-05 16:14+0000\n" +"PO-Revision-Date: 2026-10-05 16:49+0000\n" "Last-Translator: Sumit Bose <sbose@redhat.com>\n" "Language-Team: German <https://translate.fedoraproject.org/projects/sssd/" "sssd-manpage-master/de/>\n" @@ -20,10 +20,10 @@ msgstr "" "Content-Type: text/plain; charset=UTF-8\n" "Content-Transfer-Encoding: 8bit\n" "Plural-Forms: nplurals=2; plural=n != 1;\n" -"X-Generator: Weblate 5.17\n" +"X-Generator: Weblate 2026.10\n" #. type: Content of: <reference><title> -#: sssd.conf.5.xml:8 sssd-ldap.5.xml:5 pam_sss.8.xml:5 pam_sss_gss.8.xml:5 +#: sssd.conf.5.xml:10 sssd-ldap.5.xml:5 pam_sss.8.xml:5 pam_sss_gss.8.xml:5 #: sssd_krb5_locator_plugin.8.xml:5 sssd-simple.5.xml:5 sss-certmap.5.xml:5 #: sssd-ipa.5.xml:5 sssd-ad.5.xml:5 sssd-sudo.5.xml:5 sssd-idp.5.xml:5 #: sssd.8.xml:5 sss_obfuscate.8.xml:5 sss_override.8.xml:5 sssd-krb5.5.xml:5 @@ -36,12 +36,12 @@ msgid "SSSD Manual pages" msgstr "SSSD-Handbuchseiten" #. type: Content of: <reference><refentry><refnamediv><refname> -#: sssd.conf.5.xml:13 sssd.conf.5.xml:19 +#: sssd.conf.5.xml:15 sssd.conf.5.xml:21 msgid "sssd.conf" msgstr "sssd.conf" #. type: Content of: <reference><refentry><refmeta><manvolnum> -#: sssd.conf.5.xml:14 sssd-ldap.5.xml:11 sssd-simple.5.xml:11 +#: sssd.conf.5.xml:16 sssd-ldap.5.xml:11 sssd-simple.5.xml:11 #: sss-certmap.5.xml:11 sssd-ipa.5.xml:11 sssd-ad.5.xml:11 sssd-sudo.5.xml:11 #: sssd-idp.5.xml:11 sssd-krb5.5.xml:11 sssd-ifp.5.xml:11 #: sss_rpcidmapd.5.xml:27 sssd-session-recording.5.xml:11 @@ -50,7 +50,7 @@ msgid "5" msgstr "5" #. type: Content of: <reference><refentry><refmeta><refmiscinfo> -#: sssd.conf.5.xml:15 sssd-ldap.5.xml:12 sssd-simple.5.xml:12 +#: sssd.conf.5.xml:17 sssd-ldap.5.xml:12 sssd-simple.5.xml:12 #: sss-certmap.5.xml:12 sssd-ipa.5.xml:12 sssd-ad.5.xml:12 sssd-sudo.5.xml:12 #: sssd-idp.5.xml:12 sssd-krb5.5.xml:12 sssd-ifp.5.xml:12 #: sss_rpcidmapd.5.xml:28 sssd-session-recording.5.xml:12 sssd-kcm.8.xml:12 @@ -59,17 +59,17 @@ msgid "File Formats and Conventions" msgstr "Dateiformate und Konventionen" #. type: Content of: <reference><refentry><refnamediv><refpurpose> -#: sssd.conf.5.xml:20 +#: sssd.conf.5.xml:22 msgid "the configuration file for SSSD" msgstr "die Konfigurationsdatei für SSSD" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:24 +#: sssd.conf.5.xml:26 msgid "FILE FORMAT" msgstr "DATEIFORMAT" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd.conf.5.xml:32 +#: sssd.conf.5.xml:34 #, no-wrap msgid "" "<replaceable>[section]</replaceable>\n" @@ -79,7 +79,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:27 +#: sssd.conf.5.xml:29 msgid "" "The file has an ini-style syntax and consists of sections and parameters. A " "section begins with the name of the section in square brackets and continues " @@ -93,23 +93,24 @@ msgstr "" "<placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:39 +#: sssd.conf.5.xml:41 msgid "" -"The data types used are string (no quotes needed), integer and bool (with " -"values of <quote>TRUE/FALSE</quote>)." +"The data types used are string (no quotes needed), integer and boolean (with " +"values of <quote>TRUE/FALSE</quote>). Boolean values are case-insensitive; " +"for example, <quote>TRUE</quote>, <quote>True</quote> and <quote>true</" +"quote> are all equivalent and valid; the same applies to <quote>FALSE</" +"quote>." msgstr "" -"Die benutzten Datentypen sind Zeichenkette (keine Anführungszeichen nötig), " -"Ganzzahl und Boolesch (mit den Werten »TRUE« und »FALSE«)." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:44 +#: sssd.conf.5.xml:49 msgid "" "A comment line starts with a hash sign (<quote>#</quote>) or a semicolon " "(<quote>;</quote>). Inline comments are not supported." msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:50 +#: sssd.conf.5.xml:55 msgid "" "All sections can have an optional <replaceable>description</replaceable> " "parameter. Its function is only as a label for the section." @@ -118,7 +119,7 @@ msgstr "" "replaceable> haben. Er dient nur als Beschriftung eines Abschnitts." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:56 +#: sssd.conf.5.xml:61 #, fuzzy #| msgid "" #| "<filename>sssd.conf</filename> must be a regular file, owned by root and " @@ -131,7 +132,7 @@ msgstr "" "und die nur von Root gelesen oder geschrieben werden darf." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:60 +#: sssd.conf.5.xml:65 #, fuzzy #| msgid "" #| "<filename>sssd.conf</filename> must be a regular file, owned by root and " @@ -144,12 +145,12 @@ msgstr "" "und die nur von Root gelesen oder geschrieben werden darf." #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:66 +#: sssd.conf.5.xml:71 msgid "CONFIGURATION SNIPPETS FROM INCLUDE DIRECTORY" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:69 +#: sssd.conf.5.xml:74 msgid "" "The configuration file <filename>sssd.conf</filename> will include " "configuration snippets using the include directory <filename>conf.d</" @@ -157,7 +158,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:75 +#: sssd.conf.5.xml:80 msgid "" "Any file placed in <filename>conf.d</filename> that ends in " "<quote><filename>.conf</filename></quote> and does not begin with a dot " @@ -166,7 +167,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:83 +#: sssd.conf.5.xml:88 msgid "" "The configuration snippets from <filename>conf.d</filename> have higher " "priority than <filename>sssd.conf</filename> and will override " @@ -179,40 +180,93 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:97 +#: sssd.conf.5.xml:102 msgid "" "The snippet files require the same owner and permissions as " "<filename>sssd.conf</filename>." msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:103 +#: sssd.conf.5.xml:108 +#, fuzzy +#| msgid "CONFIGURATION OPTIONS" +msgid "VENDOR PROVIDED CONFIGURATION" +msgstr "KONFIGURATIONSOPTIONEN" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:111 +msgid "" +"The vendor provided configuration file is installed in " +"<filename>&sssd_vendor_dir;/sssd.conf</filename>, but this file must not be " +"directly edited. It can be completely masked by creating the system specific " +"configuration file <filename>&sssd_conf_dir;/sssd.conf</filename>, or partly " +"overriden by creating config snippets in <filename>&sssd_conf_dir;/conf.d</" +"filename> directory." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><title> +#: sssd.conf.5.xml:120 +#, fuzzy +#| msgid "CONFIGURATION OPTIONS" +msgid "CONFIGURATION FILE HIERARCHY" +msgstr "KONFIGURATIONSOPTIONEN" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:122 +msgid "" +"When sssd reads the configuration it first tries to open the system specific " +"configuration file in <filename>&sssd_conf_dir;/sssd.conf</filename>. If it " +"exists, it is loaded and snippets from <filename>&sssd_conf_dir;/conf.d</" +"filename> are applied. The vendor provided configuration file " +"<filename>&sssd_vendor_dir;/sssd.conf</filename> is completely ignored in " +"this case." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:131 +msgid "" +"If the system specific configuration file <filename>&sssd_conf_dir;/" +"sssd.conf</filename> does not exist, then the vendor configuration file " +"<filename>&sssd_vendor_dir;/sssd.conf</filename> is loaded and snippets from " +"<filename>&sssd_conf_dir;/conf.d</filename> are applied." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd.conf.5.xml:141 msgid "GENERAL OPTIONS" msgstr "ALLGEMEINE OPTIONEN" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:105 +#: sssd.conf.5.xml:143 msgid "Following options are usable in more than one configuration sections." msgstr "" "Die folgenden Optionen sind in mehreren Konfigurationsabschnitten verfügbar." #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:109 +#: sssd.conf.5.xml:147 msgid "Options usable in all sections" msgstr "In allen Abschnitten verfügbare Optionen" +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:149 +msgid "" +"Note: Below options are ignored in <quote>[session_recording]</quote> " +"section, see <quote>Session recording configuration options</quote> section " +"for more details." +msgstr "" + #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:113 +#: sssd.conf.5.xml:156 msgid "debug_level (integer)" msgstr "debug_level (Ganzzahl)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:117 +#: sssd.conf.5.xml:160 msgid "debug (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:120 +#: sssd.conf.5.xml:163 msgid "" "SSSD 1.14 and later also includes the <replaceable>debug</replaceable> alias " "for <replaceable>debug_level</replaceable> as a convenience feature. If both " @@ -221,63 +275,67 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:130 -msgid "debug_timestamps (bool)" +#: sssd.conf.5.xml:173 +#, fuzzy +#| msgid "debug_timestamps (bool)" +msgid "debug_timestamps (boolean)" msgstr "debug_timestamps (Boolesch)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:133 +#: sssd.conf.5.xml:176 msgid "" "Add a timestamp to the debug messages. If journald is enabled for SSSD " "debug logging this option is ignored." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:138 sssd.conf.5.xml:175 sssd.conf.5.xml:337 -#: sssd.conf.5.xml:644 sssd.conf.5.xml:668 sssd.conf.5.xml:875 -#: sssd.conf.5.xml:979 sssd.conf.5.xml:2113 sssd-ldap.5.xml:979 -#: sssd-ldap.5.xml:1134 sssd-ldap.5.xml:1237 sssd-ldap.5.xml:1306 -#: sssd-ldap.5.xml:1714 sssd-ldap.5.xml:1848 sssd-ldap.5.xml:1913 -#: sssd-ipa.5.xml:346 sssd-ad.5.xml:252 sssd-ad.5.xml:367 sssd-ad.5.xml:1180 -#: sssd-ad.5.xml:1382 sssd-krb5.5.xml:358 +#: sssd.conf.5.xml:181 sssd.conf.5.xml:218 sssd.conf.5.xml:380 +#: sssd.conf.5.xml:687 sssd.conf.5.xml:711 sssd.conf.5.xml:827 +#: sssd.conf.5.xml:932 sssd.conf.5.xml:2149 sssd.conf.5.xml:4730 +#: sssd-ldap.5.xml:979 sssd-ldap.5.xml:1134 sssd-ldap.5.xml:1237 +#: sssd-ldap.5.xml:1306 sssd-ldap.5.xml:1714 sssd-ldap.5.xml:1848 +#: sssd-ldap.5.xml:1913 sssd-ipa.5.xml:341 sssd-ad.5.xml:252 sssd-ad.5.xml:367 +#: sssd-ad.5.xml:1180 sssd-ad.5.xml:1375 sssd-krb5.5.xml:358 msgid "Default: true" msgstr "Voreinstellung: »true«" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:143 -msgid "debug_microseconds (bool)" +#: sssd.conf.5.xml:186 +#, fuzzy +#| msgid "debug_microseconds (bool)" +msgid "debug_microseconds (boolean)" msgstr "debug_microseconds (Boolesch)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:146 +#: sssd.conf.5.xml:189 msgid "" "Add microseconds to the timestamp in debug messages. If journald is enabled " "for SSSD debug logging this option is ignored." msgstr "" #. type: Content of: <variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:151 sssd.conf.5.xml:2040 sssd.conf.5.xml:4158 +#: sssd.conf.5.xml:194 sssd.conf.5.xml:2072 sssd.conf.5.xml:4363 #: sssd-ldap.5.xml:363 sssd-ldap.5.xml:998 sssd-ldap.5.xml:1209 -#: sssd-ldap.5.xml:1663 sssd-ldap.5.xml:1937 sssd-ipa.5.xml:146 -#: sssd-ipa.5.xml:706 sssd-ad.5.xml:1135 sssd-krb5.5.xml:268 +#: sssd-ldap.5.xml:1663 sssd-ldap.5.xml:1937 sssd-ipa.5.xml:141 +#: sssd-ipa.5.xml:701 sssd-ad.5.xml:1140 sssd-idp.5.xml:287 sssd-krb5.5.xml:268 #: sssd-krb5.5.xml:330 sssd-krb5.5.xml:432 include/krb5_options.xml:163 msgid "Default: false" msgstr "Voreinstellung: »false«" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:156 +#: sssd.conf.5.xml:199 #, fuzzy #| msgid "debug_microseconds (bool)" -msgid "debug_backtrace_enabled (bool)" +msgid "debug_backtrace_enabled (boolean)" msgstr "debug_microseconds (Boolesch)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:159 +#: sssd.conf.5.xml:202 msgid "Enable debug backtrace." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:162 +#: sssd.conf.5.xml:205 msgid "" "In case SSSD is run with debug_level less than 9, everything is logged to a " "ring buffer in memory and flushed to a log file on any error up to and " @@ -287,14 +345,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:171 +#: sssd.conf.5.xml:214 msgid "" "Feature is only supported for `logger == files` (i.e. setting doesn't have " "effect for other logger types)." msgstr "" #. type: Content of: outside any tag (error?) -#: sssd.conf.5.xml:111 sssd.conf.5.xml:186 sssd-ldap.5.xml:1754 +#: sssd.conf.5.xml:154 sssd.conf.5.xml:229 sssd-ldap.5.xml:1754 #: sssd-ldap.5.xml:1960 sss-certmap.5.xml:645 sssd-systemtap.5.xml:82 #: sssd-systemtap.5.xml:143 sssd-systemtap.5.xml:236 sssd-systemtap.5.xml:274 #: sssd-systemtap.5.xml:330 sssd-ldap-attributes.5.xml:40 @@ -307,17 +365,17 @@ msgid "<placeholder type=\"variablelist\" id=\"0\"/>" msgstr "<placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:184 +#: sssd.conf.5.xml:227 msgid "Options usable in SERVICE and DOMAIN sections" msgstr "In den Abschnitten SERVICE und DOMAIN verwendbare Optionen" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:188 +#: sssd.conf.5.xml:231 msgid "timeout (integer)" msgstr "timeout (Ganzzahl)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:191 +#: sssd.conf.5.xml:234 msgid "" "Timeout in seconds between heartbeats for this service. This is used to " "ensure that the process is alive and capable of answering requests. Note " @@ -325,34 +383,36 @@ msgid "" msgstr "" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:198 sssd.conf.5.xml:1199 sssd.conf.5.xml:1673 -#: sssd.conf.5.xml:4174 sssd-ldap.5.xml:825 sssd-idp.5.xml:192 +#: sssd.conf.5.xml:241 sssd.conf.5.xml:1155 sssd.conf.5.xml:1665 +#: sssd.conf.5.xml:4379 sssd-ldap.5.xml:825 sssd-idp.5.xml:271 #: include/ldap_id_mapping.xml:270 msgid "Default: 10" msgstr "Voreinstellung: 10" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:208 +#: sssd.conf.5.xml:251 msgid "SPECIAL SECTIONS" msgstr "BESONDERE ABSCHNITTE" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:211 +#: sssd.conf.5.xml:254 msgid "The [sssd] section" msgstr "Der Abschnitt [sssd]" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><title> -#: sssd.conf.5.xml:220 +#: sssd.conf.5.xml:263 msgid "Section parameters" msgstr "Abschnittsparameter" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:222 -msgid "services" -msgstr "Dienste" +#: sssd.conf.5.xml:265 +#, fuzzy +#| msgid "simple_allow_users (string)" +msgid "services (string)" +msgstr "simple_allow_users (Zeichenkette)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:225 +#: sssd.conf.5.xml:268 msgid "" "Comma separated list of services that are started when sssd itself starts. " "<phrase condition=\"have_systemd\"> The services' list is optional on " @@ -361,7 +421,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:234 +#: sssd.conf.5.xml:277 #, fuzzy #| msgid "" #| "Supported services: nss, pam <phrase condition=\"with_sudo\">, sudo</" @@ -382,20 +442,20 @@ msgstr "" "condition=\"with_ifp\">, ifp</phrase>" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:241 +#: sssd.conf.5.xml:284 msgid "" "<phrase condition=\"have_systemd\"> By default, all services are disabled " "and the administrator must enable the ones allowed to be used by executing: " "\"systemctl enable sssd-@service@.socket\". </phrase>" msgstr "" -#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:250 -msgid "domains" -msgstr "Domains" +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sssd.conf.5.xml:293 sssd.conf.5.xml:4562 +msgid "domains (string)" +msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:253 +#: sssd.conf.5.xml:296 msgid "" "A domain is a database containing user information. SSSD can use more " "domains at the same time, but at least one must be configured or SSSD won't " @@ -406,12 +466,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:266 sssd.conf.5.xml:3467 +#: sssd.conf.5.xml:309 sssd.conf.5.xml:3598 msgid "re_expression (string)" msgstr "re_expression (Zeichenkette)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:269 +#: sssd.conf.5.xml:312 msgid "" "Default regular expression that describes how to parse the string containing " "user name and domain into these components." @@ -421,7 +481,7 @@ msgstr "" "werden sollen." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:274 +#: sssd.conf.5.xml:317 msgid "" "Each domain can have an individual regular expression configured. For some " "ID providers there are also default regular expressions. See DOMAIN SECTIONS " @@ -429,12 +489,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:283 sssd.conf.5.xml:3524 +#: sssd.conf.5.xml:326 sssd.conf.5.xml:3655 msgid "full_name_format (string)" msgstr "full_name_format (Zeichenkette)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:286 sssd.conf.5.xml:3527 +#: sssd.conf.5.xml:329 sssd.conf.5.xml:3658 msgid "" "A <citerefentry> <refentrytitle>printf</refentrytitle> <manvolnum>3</" "manvolnum> </citerefentry>-compatible format that describes how to compose a " @@ -446,32 +506,32 @@ msgstr "" "zusammengestellt wird." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:297 sssd.conf.5.xml:3538 +#: sssd.conf.5.xml:340 sssd.conf.5.xml:3669 msgid "%1$s" msgstr "%1$s" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:298 sssd.conf.5.xml:3539 +#: sssd.conf.5.xml:341 sssd.conf.5.xml:3670 msgid "user name" msgstr "Benutzername" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:301 sssd.conf.5.xml:3542 +#: sssd.conf.5.xml:344 sssd.conf.5.xml:3673 msgid "%2$s" msgstr "%2$s" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:304 sssd.conf.5.xml:3545 +#: sssd.conf.5.xml:347 sssd.conf.5.xml:3676 msgid "domain name as specified in the SSSD config file." msgstr "Domain-Name, wie er durch die SSSD-Konfigurationsdatei angegeben wird" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:310 sssd.conf.5.xml:3551 +#: sssd.conf.5.xml:353 sssd.conf.5.xml:3682 msgid "%3$s" msgstr "%3$s" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:313 sssd.conf.5.xml:3554 +#: sssd.conf.5.xml:356 sssd.conf.5.xml:3685 msgid "" "domain flat name. Mostly usable for Active Directory domains, both directly " "configured or discovered via IPA trusts." @@ -480,7 +540,7 @@ msgstr "" "direkt konfiguriert als auch über IPA-Trust" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:294 sssd.conf.5.xml:3535 +#: sssd.conf.5.xml:337 sssd.conf.5.xml:3666 msgid "" "The following expansions are supported: <placeholder type=\"variablelist\" " "id=\"0\"/>" @@ -489,31 +549,31 @@ msgstr "" "type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:323 +#: sssd.conf.5.xml:366 msgid "" "Each domain can have an individual format string configured. See DOMAIN " "SECTIONS for more info on this option." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:329 +#: sssd.conf.5.xml:372 msgid "monitor_resolv_conf (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:332 +#: sssd.conf.5.xml:375 msgid "" "Controls if SSSD should monitor the state of resolv.conf to identify when it " "needs to update its internal DNS resolver." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:342 +#: sssd.conf.5.xml:385 msgid "try_inotify (boolean)" msgstr "try_inotify (Boolesch)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:345 +#: sssd.conf.5.xml:388 msgid "" "By default, SSSD will attempt to use inotify to monitor configuration files " "changes and will fall back to polling every five seconds if inotify cannot " @@ -521,7 +581,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:351 +#: sssd.conf.5.xml:394 msgid "" "There are some limited situations where it is preferred that we should skip " "even trying to use inotify. In these rare cases, this option should be set " @@ -532,7 +592,7 @@ msgstr "" "sollte diese Option auf »false« gesetzt werden." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:357 +#: sssd.conf.5.xml:400 msgid "" "Default: true on platforms where inotify is supported. False on other " "platforms." @@ -541,7 +601,7 @@ msgstr "" "false« auf anderen Plattformen." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:361 +#: sssd.conf.5.xml:404 msgid "" "Note: this option will have no effect on platforms where inotify is " "unavailable. On these platforms, polling will always be used." @@ -550,12 +610,12 @@ msgstr "" "verfügbar ist, keine Auswirkungen haben." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:368 +#: sssd.conf.5.xml:411 msgid "krb5_rcache_dir (string)" msgstr "krb5_rcache_dir (Zeichenkette)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:371 +#: sssd.conf.5.xml:414 msgid "" "Directory on the filesystem where SSSD should store Kerberos replay cache " "files." @@ -563,7 +623,7 @@ msgstr "" "Verzeichnis im Dateisystem, in welchem SSSD den Kerberos Replay-Cache ablegt." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:375 +#: sssd.conf.5.xml:418 msgid "" "This option accepts a special value __LIBKRB5_DEFAULTS__ that will instruct " "SSSD to let libkrb5 decide the appropriate location for the replay cache." @@ -573,7 +633,7 @@ msgstr "" "Ort für den Replay-Zwischenspeicher ist." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:381 +#: sssd.conf.5.xml:424 msgid "" "Default: Distribution-specific and specified at build-time. " "(__LIBKRB5_DEFAULTS__ if not configured)" @@ -582,19 +642,19 @@ msgstr "" "(__LIBKRB5_DEFAULTS__, falls nicht konfiguriert)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:388 +#: sssd.conf.5.xml:431 msgid "default_domain_suffix (string)" msgstr "default_domain_suffix (Zeichenkette)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:391 +#: sssd.conf.5.xml:434 msgid "" "Please note that this option is deprecated and domain_resolution_order " "should be used." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:395 +#: sssd.conf.5.xml:438 msgid "" "This string will be used as a default domain name for all names without a " "domain name component. The main use case is environments where the primary " @@ -610,7 +670,7 @@ msgstr "" "ihrem Benutzernamen ohne auch eine Domain anzugeben." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:405 +#: sssd.conf.5.xml:448 msgid "" "Please note that if this option is set all users from the primary domain " "have to use their fully qualified name, e.g. user@domain.name, to log in. " @@ -620,21 +680,21 @@ msgid "" msgstr "" #. type: Content of: <variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:414 sssd-ldap.5.xml:937 sssd-ldap.5.xml:949 -#: sssd-ldap.5.xml:1042 sssd-ad.5.xml:921 sssd-ad.5.xml:996 sssd-krb5.5.xml:468 -#: sssd-ldap-attributes.5.xml:470 sssd-ldap-attributes.5.xml:978 -#: include/ldap_id_mapping.xml:211 include/ldap_id_mapping.xml:222 -#: include/krb5_options.xml:148 +#: sssd.conf.5.xml:457 sssd.conf.5.xml:2006 sssd-ldap.5.xml:937 +#: sssd-ldap.5.xml:949 sssd-ldap.5.xml:1042 sssd-ad.5.xml:926 +#: sssd-ad.5.xml:1001 sssd-krb5.5.xml:468 sssd-ldap-attributes.5.xml:470 +#: sssd-ldap-attributes.5.xml:978 include/ldap_id_mapping.xml:211 +#: include/ldap_id_mapping.xml:222 include/krb5_options.xml:148 msgid "Default: not set" msgstr "Voreinstellung: nicht gesetzt" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:419 +#: sssd.conf.5.xml:462 msgid "override_space (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:422 +#: sssd.conf.5.xml:465 msgid "" "This parameter will replace spaces (space bar) with the given character for " "user and group names. e.g. (_). User name "john doe" will be " @@ -644,7 +704,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:431 +#: sssd.conf.5.xml:474 msgid "" "Please note it is a configuration error to use a replacement character that " "might be used in user or group names. If a name contains the replacement " @@ -653,22 +713,22 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:439 +#: sssd.conf.5.xml:482 msgid "Default: not set (spaces will not be replaced)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:444 +#: sssd.conf.5.xml:487 msgid "certificate_verification (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:452 +#: sssd.conf.5.xml:495 msgid "no_ocsp" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:454 +#: sssd.conf.5.xml:497 msgid "" "Disables Online Certificate Status Protocol (OCSP) checks. This might be " "needed if the OCSP servers defined in the certificate are not reachable from " @@ -676,12 +736,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:462 +#: sssd.conf.5.xml:505 msgid "soft_ocsp" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:464 +#: sssd.conf.5.xml:507 msgid "" "If a connection cannot be established to an OCSP responder the OCSP check is " "skipped. This option should be used to allow authentication when the system " @@ -689,61 +749,61 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:474 +#: sssd.conf.5.xml:517 msgid "ocsp_dgst" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:476 +#: sssd.conf.5.xml:519 msgid "" "Digest (hash) function used to create the certificate ID for the OCSP " "request. Allowed values are:" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:480 +#: sssd.conf.5.xml:523 msgid "sha1" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:481 +#: sssd.conf.5.xml:524 msgid "sha256" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:482 +#: sssd.conf.5.xml:525 msgid "sha384" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:483 +#: sssd.conf.5.xml:526 msgid "sha512" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:486 +#: sssd.conf.5.xml:529 msgid "Default: sha1 (to allow compatibility with RFC5019-compliant responder)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:492 +#: sssd.conf.5.xml:535 msgid "no_verification" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:494 +#: sssd.conf.5.xml:537 msgid "" "Disables verification completely. This option should only be used for " "testing." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:500 +#: sssd.conf.5.xml:543 msgid "partial_chain" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:502 +#: sssd.conf.5.xml:545 msgid "" "Allow verification to succeed even if a <replaceable>complete</replaceable> " "chain cannot be built to a self-signed trust-anchor, provided it is possible " @@ -751,12 +811,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:511 +#: sssd.conf.5.xml:554 msgid "ocsp_default_responder=URL" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:513 +#: sssd.conf.5.xml:556 msgid "" "Sets the OCSP default responder which should be used instead of the one " "mentioned in the certificate. URL must be replaced with the URL of the OCSP " @@ -764,24 +824,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:523 +#: sssd.conf.5.xml:566 msgid "ocsp_default_responder_signing_cert=NAME" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:525 +#: sssd.conf.5.xml:568 msgid "" "This option is currently ignored. All needed certificates must be available " "in the PEM file given by pam_cert_db_path." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:533 +#: sssd.conf.5.xml:576 msgid "crl_file=/PATH/TO/CRL/FILE" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:535 +#: sssd.conf.5.xml:578 #, fuzzy #| msgid "" #| "Please refer to the <quote>dns_discovery_domain</quote> parameter in the " @@ -798,12 +858,12 @@ msgstr "" "citerefentry> beim Parameter »dns_discovery_domain«." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:548 +#: sssd.conf.5.xml:591 msgid "soft_crl" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:551 +#: sssd.conf.5.xml:594 msgid "" "If a Certificate Revocation List (CRL) is expired ignore the expiration " "time of the CRL and check the related certificates with the expired CRL. " @@ -812,7 +872,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:447 +#: sssd.conf.5.xml:490 msgid "" "With this parameter the certificate verification can be tuned with a comma " "separated list of options. Supported options are: <placeholder " @@ -820,46 +880,48 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:564 +#: sssd.conf.5.xml:607 msgid "Unknown options are reported but ignored." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:567 +#: sssd.conf.5.xml:610 msgid "Default: not set, i.e. do not restrict certificate verification" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:573 +#: sssd.conf.5.xml:616 msgid "disable_netlink (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:576 +#: sssd.conf.5.xml:619 msgid "" "SSSD hooks into the netlink interface to monitor changes to routes, " "addresses, links and trigger certain actions." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:581 +#: sssd.conf.5.xml:624 msgid "" "The SSSD state changes caused by netlink events may be undesirable and can " "be disabled by setting this option to 'true'" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:586 +#: sssd.conf.5.xml:629 msgid "Default: false (netlink changes are detected)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:591 -msgid "domain_resolution_order" -msgstr "" +#: sssd.conf.5.xml:634 +#, fuzzy +#| msgid "subdomains_provider (string)" +msgid "domain_resolution_order (string)" +msgstr "subdomains_provider (Zeichenkette)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:594 +#: sssd.conf.5.xml:637 msgid "" "Comma separated list of domains and subdomains representing the lookup order " "that will be followed. The list doesn't have to include all possible " @@ -870,7 +932,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:606 +#: sssd.conf.5.xml:649 msgid "" "Please, note that when this option is set the output format of all commands " "is always fully-qualified even when using short names for input. In case " @@ -886,21 +948,22 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:630 sssd.conf.5.xml:1697 sssd.conf.5.xml:4224 -#: sssd-ad.5.xml:187 sssd-ad.5.xml:328 sssd-ad.5.xml:342 sssd-idp.5.xml:108 -#: sssd-idp.5.xml:132 sssd-idp.5.xml:145 sssd-idp.5.xml:159 sssd-idp.5.xml:180 +#: sssd.conf.5.xml:673 sssd.conf.5.xml:1026 sssd.conf.5.xml:1689 +#: sssd.conf.5.xml:4429 sssd-ad.5.xml:187 sssd-ad.5.xml:328 sssd-ad.5.xml:342 +#: sssd-idp.5.xml:112 sssd-idp.5.xml:136 sssd-idp.5.xml:149 sssd-idp.5.xml:167 +#: sssd-idp.5.xml:188 msgid "Default: Not set" msgstr "Voreinstellung: Nicht gesetzt" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:635 +#: sssd.conf.5.xml:678 #, fuzzy #| msgid "ipa_server_mode (boolean)" msgid "implicit_pac_responder (boolean)" msgstr "ipa_server_mode (Boolesch)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:638 +#: sssd.conf.5.xml:681 msgid "" "The PAC responder is enabled automatically for the IPA and AD provider to " "evaluate and check the PAC. If it has to be disabled set this option to " @@ -908,14 +971,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:649 +#: sssd.conf.5.xml:692 #, fuzzy #| msgid "ad_enable_gc (boolean)" msgid "core_dumpable (boolean)" msgstr "ad_enable_gc (Boolesch)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:652 +#: sssd.conf.5.xml:695 msgid "" "This option can be used for general system hardening: setting it to 'false' " "forbids core dumps for all SSSD processes to avoid leaking plain text " @@ -924,7 +987,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:660 +#: sssd.conf.5.xml:703 msgid "" "Take a note that this setting has no effect for 'ldap_child', 'krb5_child' " "and 'sssd_pam' as those privileged binaries can have a copy of a host keytab " @@ -933,28 +996,28 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:673 +#: sssd.conf.5.xml:716 #, fuzzy #| msgid "ipa_automount_location (string)" msgid "passkey_verification (string)" msgstr "ipa_automount_location (Zeichenkette)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:681 +#: sssd.conf.5.xml:724 #, fuzzy #| msgid "ipa_automount_location (string)" msgid "user_verification (boolean)" msgstr "ipa_automount_location (Zeichenkette)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:683 +#: sssd.conf.5.xml:726 msgid "" "Enable or disable the user verification (i.e. PIN, fingerprint) during " "authentication. If enabled, the PIN will always be requested." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:689 +#: sssd.conf.5.xml:732 msgid "" "The default is that the key settings decide what to do. In the IPA or " "kerberos pre-authentication case, this value will be overwritten by the " @@ -962,7 +1025,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:676 +#: sssd.conf.5.xml:719 #, fuzzy #| msgid "" #| "The following expansions are supported: <placeholder " @@ -976,7 +1039,7 @@ msgstr "" "type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:213 +#: sssd.conf.5.xml:256 msgid "" "Individual pieces of SSSD functionality are provided by special SSSD " "services that are started and stopped together with SSSD. The services are " @@ -993,12 +1056,12 @@ msgstr "" "verwendet. <placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:708 +#: sssd.conf.5.xml:751 msgid "SERVICES SECTIONS" msgstr "DIENSTABSCHNITTE" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:710 +#: sssd.conf.5.xml:753 msgid "" "Settings that can be used to configure different services are described in " "this section. They should reside in the [<replaceable>$NAME</replaceable>] " @@ -1011,28 +1074,36 @@ msgstr "" "Abschnitt zum Beispiel <quote>[nss]</quote>." #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:717 +#: sssd.conf.5.xml:760 msgid "General service configuration options" msgstr "Allgemeine Optionen zum Konfigurieren von Diensten" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:719 +#: sssd.conf.5.xml:762 msgid "These options can be used to configure any service." msgstr "Diese Optionen können zur Konfiguration jedes Dienstes benutzt werden." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:723 -msgid "fd_limit" -msgstr "fd_limit" +#: sssd.conf.5.xml:766 +#, fuzzy +#| msgid "timeout (integer)" +msgid "fd_limit (integer)" +msgstr "timeout (Ganzzahl)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:726 +#: sssd.conf.5.xml:769 +#, fuzzy +#| msgid "" +#| "This option specifies the maximum number of file descriptors that may be " +#| "opened at one time by this SSSD process. On systems where SSSD is granted " +#| "the CAP_SYS_RESOURCE capability, this will be an absolute setting. On " +#| "systems without this capability, the resulting value will be the lower " +#| "value of this or the limits.conf \"hard\" limit." msgid "" "This option specifies the maximum number of file descriptors that may be " -"opened at one time by this SSSD process. On systems where SSSD is granted " -"the CAP_SYS_RESOURCE capability, this will be an absolute setting. On " -"systems without this capability, the resulting value will be the lower value " -"of this or the limits.conf \"hard\" limit." +"opened at one time by this SSSD process. Note this value will be capped by " +"the init system at the startup of SSSD, see e.g. man systemd.exec for " +"details." msgstr "" "Diese Option gibt die maximale Anzahl von Dateideskriptoren an, die " "gleichzeitig durch diesen SSSD-Prozess geöffnet sein können. Auf Systemen, " @@ -1042,17 +1113,19 @@ msgstr "" "Begrenzung in der »limit.conf« sein." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:735 +#: sssd.conf.5.xml:776 msgid "Default: 8192 (or limits.conf \"hard\" limit)" msgstr "Voreinstellung: 8192 (oder die »harte« Begrenzung der »limit.conf«)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:740 -msgid "client_idle_timeout" -msgstr "client_idle_timeout" +#: sssd.conf.5.xml:781 +#, fuzzy +#| msgid "offline_timeout (integer)" +msgid "client_idle_timeout (integer)" +msgstr "offline_timeout (Ganzzahl)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:743 +#: sssd.conf.5.xml:784 msgid "" "This option specifies the number of seconds that a client of an SSSD process " "can hold onto a file descriptor without communicating on it. This value is " @@ -1062,150 +1135,21 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:752 +#: sssd.conf.5.xml:793 #, fuzzy #| msgid "Default: 300" msgid "Default: 60, KCM: 300" msgstr "Voreinstellung: 300" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:757 -msgid "offline_timeout (integer)" -msgstr "offline_timeout (Ganzzahl)" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:760 -msgid "" -"When SSSD switches to offline mode the amount of time before it tries to go " -"back online will increase based upon the time spent disconnected. By " -"default SSSD uses incremental behaviour to calculate delay in between " -"retries. So, the wait time for a given retry will be longer than the wait " -"time for the previous ones. After each unsuccessful attempt to go online, " -"the new interval is recalculated by the following:" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:771 sssd.conf.5.xml:827 -msgid "" -"new_delay = Minimum(old_delay * 2, offline_timeout_max) + " -"random[0...offline_timeout_random_offset]" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:774 -msgid "" -"The offline_timeout default value is 60. The offline_timeout_max default " -"value is 3600. The offline_timeout_random_offset default value is 30. The " -"end result is amount of seconds before next retry." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:780 -msgid "" -"Note that the maximum length of each interval is defined by " -"offline_timeout_max (apart of random part)." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:784 sssd.conf.5.xml:1110 sssd.conf.5.xml:1490 -#: sssd.conf.5.xml:1791 sssd-ldap.5.xml:550 -msgid "Default: 60" -msgstr "Voreinstellung: 60" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:789 -#, fuzzy -#| msgid "offline_timeout (integer)" -msgid "offline_timeout_max (integer)" -msgstr "offline_timeout (Ganzzahl)" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:792 -msgid "" -"Controls by how much the time between attempts to go online can be " -"incremented following unsuccessful attempts to go online." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:797 -msgid "A value of 0 disables the incrementing behaviour." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:800 -msgid "" -"The value of this parameter should be set in correlation to offline_timeout " -"parameter value." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:804 -msgid "" -"With offline_timeout set to 60 (default value) there is no point in setting " -"offlinet_timeout_max to less than 120 as it will saturate instantly. General " -"rule here should be to set offline_timeout_max to at least 4 times " -"offline_timeout." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:810 -msgid "" -"Although a value between 0 and offline_timeout may be specified, it has the " -"effect of overriding the offline_timeout value so is of little use." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:815 -#, fuzzy -#| msgid "Default: 300" -msgid "Default: 3600" -msgstr "Voreinstellung: 300" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:820 -#, fuzzy -#| msgid "offline_timeout (integer)" -msgid "offline_timeout_random_offset (integer)" -msgstr "offline_timeout (Ganzzahl)" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:823 -msgid "" -"When SSSD is in offline mode it keeps probing backend servers in specified " -"time intervals:" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:830 -msgid "" -"This parameter controls the value of the random offset used for the above " -"equation. Final random_offset value will be random number in range:" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:835 -msgid "[0 - offline_timeout_random_offset]" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:838 -msgid "A value of 0 disables the random offset addition." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:841 +#: sssd.conf.5.xml:798 #, fuzzy -#| msgid "Default: 300" -msgid "Default: 30" -msgstr "Voreinstellung: 300" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:846 -msgid "responder_idle_timeout" -msgstr "" +#| msgid "pam_id_timeout (integer)" +msgid "responder_idle_timeout (integer)" +msgstr "pam_id_timeout (Ganzzahl)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:849 +#: sssd.conf.5.xml:801 msgid "" "This option specifies the number of seconds that an SSSD responder process " "can be up without being used. This value is limited in order to avoid " @@ -1217,43 +1161,50 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:863 sssd.conf.5.xml:1123 sssd.conf.5.xml:2248 +#: sssd.conf.5.xml:815 sssd.conf.5.xml:1079 sssd.conf.5.xml:2285 #: sssd-ldap.5.xml:377 msgid "Default: 300" msgstr "Voreinstellung: 300" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:868 -msgid "cache_first" -msgstr "" +#: sssd.conf.5.xml:820 +#, fuzzy +#| msgid "ldap_referrals (boolean)" +msgid "cache_first (boolean)" +msgstr "ldap_referrals (Boolesch)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:871 +#: sssd.conf.5.xml:823 msgid "" "This option specifies whether the responder should query all caches before " "querying the Data Providers." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:883 +#: sssd.conf.5.xml:835 msgid "NSS configuration options" msgstr "NSS-Konfigurationsoptionen" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:885 +#: sssd.conf.5.xml:837 +#, fuzzy +#| msgid "" +#| "These options can be used to configure the Name Service Switch (NSS) " +#| "service." msgid "" -"These options can be used to configure the Name Service Switch (NSS) service." +"These options can be used to configure the Name Service Switch (NSS) service " +"and should be specified under the <quote>[nss]</quote> section." msgstr "" "Diese Optionen können zum Konfigurieren des »Name Service Switch« (NSS) " "benutzt werden" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:890 +#: sssd.conf.5.xml:843 msgid "enum_cache_timeout (integer)" msgstr "enum_cache_timeout (Ganzzahl)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:893 +#: sssd.conf.5.xml:846 msgid "" "How many seconds should nss_sss cache enumerations (requests for info about " "all users)" @@ -1262,17 +1213,17 @@ msgstr "" "über alle Nutzer) zwischenspeichern?" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:897 +#: sssd.conf.5.xml:850 msgid "Default: 120" msgstr "Voreinstellung: 120" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:902 +#: sssd.conf.5.xml:855 msgid "entry_cache_nowait_percentage (integer)" msgstr "entry_cache_nowait_percentage (Ganzzahl)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:905 +#: sssd.conf.5.xml:858 msgid "" "The entry cache can be set to automatically update entries in the background " "if they are requested beyond a percentage of the entry_cache_timeout value " @@ -1284,7 +1235,7 @@ msgstr "" "werden." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:911 +#: sssd.conf.5.xml:864 msgid "" "For example, if the domain's entry_cache_timeout is set to 30s and " "entry_cache_nowait_percentage is set to 50 (percent), entries that come in " @@ -1301,7 +1252,7 @@ msgstr "" "Zwischenspeicheraktualisierung zu warten." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:921 +#: sssd.conf.5.xml:874 msgid "" "Valid values for this option are 0-99 and represent a percentage of the " "entry_cache_timeout for each domain. For performance reasons, this " @@ -1314,17 +1265,17 @@ msgstr "" "Sekunden senken. (0 schaltet diese Funktionalität aus.)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:929 sssd.conf.5.xml:2061 +#: sssd.conf.5.xml:882 sssd.conf.5.xml:2093 msgid "Default: 50" msgstr "Voreinstellung: 50" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:934 +#: sssd.conf.5.xml:887 msgid "entry_negative_timeout (integer)" msgstr "entry_negative_timeout (Ganzzahl)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:937 +#: sssd.conf.5.xml:890 msgid "" "Specifies for how many seconds nss_sss should cache negative cache hits " "(that is, queries for invalid database entries, like nonexistent ones) " @@ -1336,17 +1287,17 @@ msgstr "" "Backend erneut gefragt wird)." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:943 sssd.conf.5.xml:1685 sssd.conf.5.xml:2085 +#: sssd.conf.5.xml:896 sssd.conf.5.xml:1677 sssd.conf.5.xml:2119 msgid "Default: 15" msgstr "Voreinstellung: 15" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:948 +#: sssd.conf.5.xml:901 msgid "filter_users, filter_groups (string)" msgstr "filter_users, filter_groups (Zeichenkette)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:951 +#: sssd.conf.5.xml:904 msgid "" "Exclude certain users or groups from being fetched from the sss NSS " "database. This is particularly useful for system accounts. This option can " @@ -1355,7 +1306,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:959 +#: sssd.conf.5.xml:912 msgid "" "NOTE: The filter_groups option doesn't affect inheritance of nested group " "members, since filtering happens after they are propagated for returning via " @@ -1364,30 +1315,35 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:967 +#: sssd.conf.5.xml:920 msgid "Default: root" msgstr "Voreinstellung: root" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:972 -msgid "filter_users_in_groups (bool)" +#: sssd.conf.5.xml:925 +#, fuzzy +#| msgid "filter_users_in_groups (bool)" +msgid "filter_users_in_groups (boolean)" msgstr "filter_users_in_groups (Boolesch)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:975 +#: sssd.conf.5.xml:928 +#, fuzzy +#| msgid "" +#| "If you want filtered user still be group members set this option to false." msgid "" -"If you want filtered user still be group members set this option to false." +"If you want filtered users to remain group members set this option to false" msgstr "" "Falls Sie möchten, dass gefilterte Nutzer weiterhin Gruppenmitglieder sind, " "setzen Sie diese Option auf »false«." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:986 +#: sssd.conf.5.xml:939 msgid "fallback_homedir (string)" msgstr "fallback_homedir (Zeichenkette)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:989 +#: sssd.conf.5.xml:942 msgid "" "Set a default template for a user's home directory if one is not specified " "explicitly by the domain's data provider." @@ -1396,7 +1352,7 @@ msgstr "" "es nicht explizit durch den Datenanbieter der Domain angegeben wurde." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:994 +#: sssd.conf.5.xml:947 msgid "" "The available values for this option are the same as for override_homedir." msgstr "" @@ -1404,7 +1360,7 @@ msgstr "" "override_homedir«." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1000 +#: sssd.conf.5.xml:953 #, no-wrap msgid "" "fallback_homedir = /home/%u\n" @@ -1414,25 +1370,25 @@ msgstr "" " " #. type: Content of: <varlistentry><listitem><para> -#: sssd.conf.5.xml:998 sssd.conf.5.xml:1557 sssd.conf.5.xml:1576 -#: sssd.conf.5.xml:1653 sssd-krb5.5.xml:451 include/override_homedir.xml:78 +#: sssd.conf.5.xml:951 sssd.conf.5.xml:1524 sssd.conf.5.xml:1543 +#: sssd.conf.5.xml:1645 sssd-krb5.5.xml:451 include/override_homedir.xml:78 msgid "example: <placeholder type=\"programlisting\" id=\"0\"/>" msgstr "Beispiel: <placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1004 +#: sssd.conf.5.xml:957 msgid "Default: not set (no substitution for unset home directories)" msgstr "" "Voreinstellung: nicht gesetzt (kein Ersetzen nicht gesetzter Home-" "Verzeichnisse)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1010 +#: sssd.conf.5.xml:963 msgid "override_shell (string)" msgstr "override_shell (Zeichenkette)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1013 +#: sssd.conf.5.xml:966 msgid "" "Override the login shell for all users. This option supersedes any other " "shell options if it takes effect and can be set either in the [nss] section " @@ -1443,19 +1399,19 @@ msgstr "" "entweder im Abschnitt [nss] oder für jede Domain gesetzt werden." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1019 +#: sssd.conf.5.xml:972 msgid "Default: not set (SSSD will use the value retrieved from LDAP)" msgstr "" "Voreinstellung: nicht gesetzt (SSSD wird den von LDAP erhaltenen Wert " "benutzen)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1025 +#: sssd.conf.5.xml:978 msgid "allowed_shells (string)" msgstr "allowed_shells (Zeichenkette)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1028 +#: sssd.conf.5.xml:981 msgid "" "Restrict user shell to one of the listed values. The order of evaluation is:" msgstr "" @@ -1463,12 +1419,12 @@ msgstr "" "Reihenfolge der Auswertung ist:" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1031 +#: sssd.conf.5.xml:984 msgid "1. If the shell is present in <quote>/etc/shells</quote>, it is used." msgstr "1. Falls die Shell in »/etc/shells« vorhanden ist, wird sie benutzt." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1035 +#: sssd.conf.5.xml:988 msgid "" "2. If the shell is in the allowed_shells list but not in <quote>/etc/shells</" "quote>, use the value of the shell_fallback parameter." @@ -1477,7 +1433,7 @@ msgstr "" "« steht, wird der Wert des Parameters »shell_fallback« verwendet." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1040 +#: sssd.conf.5.xml:993 msgid "" "3. If the shell is not in the allowed_shells list and not in <quote>/etc/" "shells</quote>, a nologin shell is used." @@ -1486,12 +1442,12 @@ msgstr "" "steht, wird eine Nicht-Login-Shell benutzt." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1045 +#: sssd.conf.5.xml:998 msgid "The wildcard (*) can be used to allow any shell." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1048 +#: sssd.conf.5.xml:1001 msgid "" "The (*) is useful if you want to use shell_fallback in case that user's " "shell is not in <quote>/etc/shells</quote> and maintaining list of all " @@ -1499,13 +1455,13 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1055 +#: sssd.conf.5.xml:1008 msgid "An empty string for shell is passed as-is to libc." msgstr "" "Eine leere Zeichenkette als Shell wird, so wie sie ist, an Libc übergeben." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1058 +#: sssd.conf.5.xml:1011 msgid "" "The <quote>/etc/shells</quote> is only read on SSSD start up, which means " "that a restart of the SSSD is required in case a new shell is installed." @@ -1514,28 +1470,28 @@ msgstr "" "Fall einer neu installierten Shell ein Neustart von SSSD nötig ist." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1062 +#: sssd.conf.5.xml:1015 msgid "Default: Not set. The user shell is automatically used." msgstr "" "Voreinstellung: nicht gesetzt. Die Benutzer-Shell wird automatisch verwendet." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1067 +#: sssd.conf.5.xml:1020 msgid "vetoed_shells (string)" msgstr "vetoed_shells (Zeichenkette)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1070 +#: sssd.conf.5.xml:1023 msgid "Replace any instance of these shells with the shell_fallback" msgstr "ersetzt jedwede Instanz dieser Shells durch die aus »shell_fallback«." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1075 +#: sssd.conf.5.xml:1031 msgid "shell_fallback (string)" msgstr "shell_fallback (Zeichenkette)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1078 +#: sssd.conf.5.xml:1034 msgid "" "The default shell to use if an allowed shell is not installed on the machine." msgstr "" @@ -1543,17 +1499,17 @@ msgstr "" "auf dem Rechner installiert ist." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1082 +#: sssd.conf.5.xml:1038 msgid "Default: /bin/sh" msgstr "Voreinstellung: /bin/sh" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1087 -msgid "default_shell" -msgstr "default_shell" +#: sssd.conf.5.xml:1043 +msgid "default_shell (string)" +msgstr "default_shell (Zeichenkette)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1090 +#: sssd.conf.5.xml:1046 msgid "" "The default shell to use if the provider does not return one during lookup. " "This option can be specified globally in the [nss] section or per-domain." @@ -1563,7 +1519,7 @@ msgstr "" "jede Domain gesetzt werden." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1096 +#: sssd.conf.5.xml:1052 msgid "" "Default: not set (Return NULL if no shell is specified and rely on libc to " "substitute something sensible when necessary, usually /bin/sh)" @@ -1573,12 +1529,12 @@ msgstr "" "Vernünftiges, üblicherweise /bin/sh, ersetzt.)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1103 sssd.conf.5.xml:1483 +#: sssd.conf.5.xml:1059 sssd.conf.5.xml:1450 msgid "get_domains_timeout (int)" msgstr "get_domains_timeout (Ganzzahl)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1106 sssd.conf.5.xml:1486 +#: sssd.conf.5.xml:1062 sssd.conf.5.xml:1453 msgid "" "Specifies time in seconds for which the list of subdomains will be " "considered valid." @@ -1586,44 +1542,50 @@ msgstr "" "gibt die Zeit in Sekunden an, während der die Liste der Subdomains als " "gültig erachtet wird." +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1066 sssd.conf.5.xml:1457 sssd.conf.5.xml:1788 +#: sssd.conf.5.xml:2862 sssd-ldap.5.xml:550 +msgid "Default: 60" +msgstr "Voreinstellung: 60" + #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1115 +#: sssd.conf.5.xml:1071 #, fuzzy #| msgid "enum_cache_timeout (integer)" msgid "memcache_timeout (integer)" msgstr "enum_cache_timeout (Ganzzahl)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1118 +#: sssd.conf.5.xml:1074 msgid "" "Specifies time in seconds for which records in the in-memory cache will be " "valid. Setting this option to zero will disable the in-memory cache." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1126 +#: sssd.conf.5.xml:1082 msgid "" "WARNING: Disabling the in-memory cache will have significant negative impact " "on SSSD's performance and should only be used for testing." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1132 sssd.conf.5.xml:1157 sssd.conf.5.xml:1182 -#: sssd.conf.5.xml:1207 sssd.conf.5.xml:1234 +#: sssd.conf.5.xml:1088 sssd.conf.5.xml:1113 sssd.conf.5.xml:1138 +#: sssd.conf.5.xml:1163 sssd.conf.5.xml:1190 msgid "" "NOTE: If the environment variable SSS_NSS_USE_MEMCACHE is set to \"NO\", " "client applications will not use the fast in-memory cache." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1140 +#: sssd.conf.5.xml:1096 #, fuzzy #| msgid "enum_cache_timeout (integer)" msgid "memcache_size_passwd (integer)" msgstr "enum_cache_timeout (Ganzzahl)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1143 +#: sssd.conf.5.xml:1099 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for passwd requests. Setting the size to 0 will disable the passwd in-" @@ -1631,27 +1593,27 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1149 sssd.conf.5.xml:2888 sssd-ldap.5.xml:604 +#: sssd.conf.5.xml:1105 sssd.conf.5.xml:3013 sssd-ldap.5.xml:604 msgid "Default: 8" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1152 sssd.conf.5.xml:1177 sssd.conf.5.xml:1202 -#: sssd.conf.5.xml:1229 +#: sssd.conf.5.xml:1108 sssd.conf.5.xml:1133 sssd.conf.5.xml:1158 +#: sssd.conf.5.xml:1185 msgid "" "WARNING: Disabled or too small in-memory cache can have significant negative " "impact on SSSD's performance." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1165 +#: sssd.conf.5.xml:1121 #, fuzzy #| msgid "enum_cache_timeout (integer)" msgid "memcache_size_group (integer)" msgstr "enum_cache_timeout (Ganzzahl)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1168 +#: sssd.conf.5.xml:1124 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for group requests. Setting the size to 0 will disable the group in-memory " @@ -1659,21 +1621,21 @@ msgid "" msgstr "" #. type: Content of: <variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1174 sssd.conf.5.xml:1226 sssd.conf.5.xml:3656 +#: sssd.conf.5.xml:1130 sssd.conf.5.xml:1182 sssd.conf.5.xml:3835 #: sssd-ldap.5.xml:534 sssd-ldap.5.xml:581 include/failover.xml:116 #: include/krb5_options.xml:11 msgid "Default: 6" msgstr "Voreinstellung: 6" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1190 +#: sssd.conf.5.xml:1146 #, fuzzy #| msgid "enum_cache_timeout (integer)" msgid "memcache_size_initgroups (integer)" msgstr "enum_cache_timeout (Ganzzahl)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1193 +#: sssd.conf.5.xml:1149 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for initgroups requests. Setting the size to 0 will disable the initgroups " @@ -1681,14 +1643,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1215 +#: sssd.conf.5.xml:1171 #, fuzzy #| msgid "enum_cache_timeout (integer)" msgid "memcache_size_sid (integer)" msgstr "enum_cache_timeout (Ganzzahl)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1218 +#: sssd.conf.5.xml:1174 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for SID related requests. Only SID-by-ID and ID-by-SID requests are " @@ -1697,12 +1659,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1242 sssd-ifp.5.xml:90 +#: sssd.conf.5.xml:1198 sssd-ifp.5.xml:90 msgid "user_attributes (string)" msgstr "user_attributes (Zeichenkette)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1245 +#: sssd.conf.5.xml:1201 msgid "" "Some of the additional NSS responder requests can return more attributes " "than just the POSIX ones defined by the NSS interface. The list of " @@ -1713,73 +1675,81 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1258 +#: sssd.conf.5.xml:1214 msgid "" "To make configuration more easy the NSS responder will check the InfoPipe " "option if it is not set for the NSS responder." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1263 +#: sssd.conf.5.xml:1219 msgid "Default: not set, fallback to InfoPipe option" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1268 +#: sssd.conf.5.xml:1224 msgid "pwfield (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1271 +#: sssd.conf.5.xml:1227 msgid "" "The value that NSS operations that return users or groups will return for " "the <quote>password</quote> field." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1276 +#: sssd.conf.5.xml:1232 +msgid "" +"This option can also be set per-domain, which overwrites the value in the " +"<quote>[nss]</quote> section for that domain. This is particularly useful " +"when using a proxy domain with <option>proxy_lib_name=files</option> and a " +"<option>proxy_pam_target</option> other than <quote>sssd-shadowutils</" +"quote>. In that case, SSSD returns <quote>*</quote> for the password field " +"by default, which causes <command>pam_unix</command> to treat all accounts " +"as locked. Setting <option>pwfield = x</option> in the domain section " +"restores the expected behavior." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1246 #, fuzzy #| msgid "Default: <quote>permit</quote>" msgid "Default: <quote>*</quote>" msgstr "Voreinstellung: »permit«" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1279 -#, fuzzy -#| msgid "This option can also be set per-domain." -msgid "" -"Note: This option can also be set per-domain which overwrites the value in " -"[nss] section." -msgstr "Diese Option kann auch pro Domain gesetzt werden." - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1283 +#: sssd.conf.5.xml:1249 msgid "" -"Default: <quote>not set</quote> (remote domains), <quote>x</quote> (proxy " -"domain with nss_files and sssd-shadowutils target)" +"Default (per-domain): <quote>not set</quote> (remote domains), <quote>x</" +"quote> (proxy domain with nss_files and sssd-shadowutils target)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:1292 +#: sssd.conf.5.xml:1258 msgid "PAM configuration options" msgstr "PAM-Konfigurationsoptionen" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:1294 +#: sssd.conf.5.xml:1260 +#, fuzzy +#| msgid "" +#| "These options can be used to configure the Pluggable Authentication " +#| "Module (PAM) service." msgid "" "These options can be used to configure the Pluggable Authentication Module " -"(PAM) service." +"(PAM) service and should be specified under the <quote>[pam]</quote> section." msgstr "" "Diese Optionen können benutzt werden, um den Dienst »Pluggable " "Authentication Module« (PAM) einzurichten." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1299 +#: sssd.conf.5.xml:1266 msgid "offline_credentials_expiration (integer)" msgstr "offline_credentials_expiration (Ganzzahl)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1302 +#: sssd.conf.5.xml:1269 msgid "" "If the authentication provider is offline, how long should we allow cached " "logins (in days since the last successful online login)." @@ -1789,17 +1759,17 @@ msgstr "" "erfolgreichen Anmeldung)?" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1307 sssd.conf.5.xml:1320 +#: sssd.conf.5.xml:1274 sssd.conf.5.xml:1287 msgid "Default: 0 (No limit)" msgstr "Voreinstellung: 0 (unbegrenzt)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1313 +#: sssd.conf.5.xml:1280 msgid "offline_failed_login_attempts (integer)" msgstr "offline_failed_login_attempts (Ganzzahl)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1316 +#: sssd.conf.5.xml:1283 msgid "" "If the authentication provider is offline, how many failed login attempts " "are allowed." @@ -1808,12 +1778,12 @@ msgstr "" "Authentifizierungsanbieter offline ist?" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1326 +#: sssd.conf.5.xml:1293 msgid "offline_failed_login_delay (integer)" msgstr "offline_failed_login_delay (Ganzzahl)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1329 +#: sssd.conf.5.xml:1296 msgid "" "The time in minutes which has to pass after offline_failed_login_attempts " "has been reached before a new login attempt is possible." @@ -1823,7 +1793,7 @@ msgstr "" "möglich ist." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1334 +#: sssd.conf.5.xml:1301 msgid "" "If set to 0 the user cannot authenticate offline if " "offline_failed_login_attempts has been reached. Only a successful online " @@ -1835,17 +1805,17 @@ msgstr "" "Authentifizierung reaktivieren." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1340 sssd.conf.5.xml:1450 +#: sssd.conf.5.xml:1307 sssd.conf.5.xml:1417 msgid "Default: 5" msgstr "Voreinstellung: 5" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1346 +#: sssd.conf.5.xml:1313 msgid "pam_verbosity (integer)" msgstr "pam_verbosity (Ganzzahl)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1349 +#: sssd.conf.5.xml:1316 msgid "" "Controls what kind of messages are shown to the user during authentication. " "The higher the number to more messages are displayed." @@ -1854,45 +1824,45 @@ msgstr "" "angezeigt werden. Je höher die Zahl, desto mehr Nachrichten werden angezeigt." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1354 +#: sssd.conf.5.xml:1321 msgid "Currently sssd supports the following values:" msgstr "Derzeit unterstützt SSSD folgende Werte:" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1357 +#: sssd.conf.5.xml:1324 msgid "<emphasis>0</emphasis>: do not show any message" msgstr "<emphasis>0</emphasis>: keine Nachricht anzeigen" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1360 +#: sssd.conf.5.xml:1327 msgid "<emphasis>1</emphasis>: show only important messages" msgstr "<emphasis>1</emphasis>: nur wichtige Nachrichten anzeigen" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1364 +#: sssd.conf.5.xml:1331 msgid "<emphasis>2</emphasis>: show informational messages" msgstr "<emphasis>2</emphasis>: nur informative Nachrichten anzeigen" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1367 +#: sssd.conf.5.xml:1334 msgid "<emphasis>3</emphasis>: show all messages and debug information" msgstr "" "<emphasis>3</emphasis>: alle Nachrichten und Debug-Informationen anzeigen" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1371 sssd.8.xml:63 +#: sssd.conf.5.xml:1338 sssd.8.xml:63 msgid "Default: 1" msgstr "Voreinstellung: 1" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1377 +#: sssd.conf.5.xml:1344 #, fuzzy #| msgid "ad_access_filter (string)" msgid "pam_response_filter (string)" msgstr "ad_access_filter (Zeichenkette)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1380 +#: sssd.conf.5.xml:1347 msgid "" "A comma separated list of strings which allows to remove (filter) data sent " "by the PAM responder to pam_sss PAM module. There are different kind of " @@ -1901,51 +1871,51 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1388 +#: sssd.conf.5.xml:1355 msgid "" "While messages already can be controlled with the help of the pam_verbosity " "option this option allows to filter out other kind of responses as well." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1395 +#: sssd.conf.5.xml:1362 msgid "ENV" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1396 +#: sssd.conf.5.xml:1363 msgid "Do not send any environment variables to any service." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1399 +#: sssd.conf.5.xml:1366 msgid "ENV:var_name" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1400 +#: sssd.conf.5.xml:1367 msgid "Do not send environment variable var_name to any service." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1404 +#: sssd.conf.5.xml:1371 msgid "ENV:var_name:service" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1405 +#: sssd.conf.5.xml:1372 msgid "Do not send environment variable var_name to service." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1393 +#: sssd.conf.5.xml:1360 msgid "" "Currently the following filters are supported: <placeholder " "type=\"variablelist\" id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1412 +#: sssd.conf.5.xml:1379 msgid "" "The list of strings can either be the list of filters which would set this " "list of filters and overwrite the defaults. Or each element of the list can " @@ -1956,23 +1926,23 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1423 +#: sssd.conf.5.xml:1390 msgid "Default: ENV:KRB5CCNAME:sudo, ENV:KRB5CCNAME:sudo-i" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1426 +#: sssd.conf.5.xml:1393 msgid "" "Example: -ENV:KRB5CCNAME:sudo-i will remove the filter from the default list" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1433 +#: sssd.conf.5.xml:1400 msgid "pam_id_timeout (integer)" msgstr "pam_id_timeout (Ganzzahl)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1436 +#: sssd.conf.5.xml:1403 msgid "" "For any PAM request while SSSD is online, the SSSD will attempt to " "immediately update the cached identity information for the user in order to " @@ -1984,7 +1954,7 @@ msgstr "" "den neusten Informationen erfolgt." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1442 +#: sssd.conf.5.xml:1409 msgid "" "A complete PAM conversation may perform multiple PAM requests, such as " "account management and session opening. This option controls (on a per-" @@ -1998,17 +1968,17 @@ msgstr "" "viele Abfragen der Identitätsanbieter zu vermeiden." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1456 +#: sssd.conf.5.xml:1423 msgid "pam_pwd_expiration_warning (integer)" msgstr "pam_pwd_expiration_warning (Ganzzahl)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1459 sssd.conf.5.xml:2912 +#: sssd.conf.5.xml:1426 sssd.conf.5.xml:3037 msgid "Display a warning N days before the password expires." msgstr "zeigt N Tage vor Ablauf des Passworts eine Warnung an." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1462 +#: sssd.conf.5.xml:1429 msgid "" "Please note that the backend server has to provide information about the " "expiration time of the password. If this information is missing, sssd " @@ -2019,7 +1989,7 @@ msgstr "" "SSSD keine Warnung anzeigen." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1468 sssd.conf.5.xml:2915 +#: sssd.conf.5.xml:1435 sssd.conf.5.xml:3040 msgid "" "If zero is set, then this filter is not applied, i.e. if the expiration " "warning was received from backend server, it will automatically be displayed." @@ -2029,7 +1999,7 @@ msgstr "" "automatisch angezeigt." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1473 +#: sssd.conf.5.xml:1440 msgid "" "This setting can be overridden by setting <emphasis>pwd_expiration_warning</" "emphasis> for a particular domain." @@ -2038,18 +2008,18 @@ msgstr "" "emphasis> für eine bestimmte Domain außer Kraft gesetzt werden." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1478 sssd.conf.5.xml:3913 sssd-ldap.5.xml:662 +#: sssd.conf.5.xml:1445 sssd.conf.5.xml:4118 sssd-ldap.5.xml:662 #: sssd-ldap.5.xml:1733 sssd.8.xml:79 msgid "Default: 0" msgstr "Voreinstellung: 0" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1495 +#: sssd.conf.5.xml:1462 msgid "pam_trusted_users (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1498 +#: sssd.conf.5.xml:1465 msgid "" "Specifies the comma-separated list of UID values or user names that are " "allowed to run PAM conversations against trusted domains. Users not " @@ -2059,74 +2029,74 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1508 +#: sssd.conf.5.xml:1475 msgid "Default: All users are considered trusted by default" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1512 +#: sssd.conf.5.xml:1479 msgid "" "Please note that UID 0 is always allowed to access the PAM responder even in " "case it is not in the pam_trusted_users list." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1519 +#: sssd.conf.5.xml:1486 msgid "pam_public_domains (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1522 +#: sssd.conf.5.xml:1489 msgid "" "Specifies the comma-separated list of domain names that are accessible even " "to untrusted users." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1526 +#: sssd.conf.5.xml:1493 msgid "Two special values for pam_public_domains option are defined:" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1530 +#: sssd.conf.5.xml:1497 msgid "" "all (Untrusted users are allowed to access all domains in PAM responder.)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1534 +#: sssd.conf.5.xml:1501 msgid "" "none (Untrusted users are not allowed to access any domains PAM in " "responder.)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1538 sssd.conf.5.xml:1563 sssd.conf.5.xml:1582 -#: sssd.conf.5.xml:1824 sssd.conf.5.xml:3842 sssd-ldap.5.xml:1270 +#: sssd.conf.5.xml:1505 sssd.conf.5.xml:1530 sssd.conf.5.xml:1549 +#: sssd.conf.5.xml:1821 sssd.conf.5.xml:4048 sssd-ldap.5.xml:1270 msgid "Default: none" msgstr "Voreinstellung: none" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1543 +#: sssd.conf.5.xml:1510 msgid "pam_account_expired_message (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1546 +#: sssd.conf.5.xml:1513 msgid "" "Allows a custom expiration message to be set, replacing the default " "'Permission denied' message." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1551 +#: sssd.conf.5.xml:1518 msgid "" "Note: Please be aware that message is only printed for the SSH service " "unless pam_verbosity is set to 3 (show all messages and debug information)." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1559 +#: sssd.conf.5.xml:1526 #, no-wrap msgid "" "pam_account_expired_message = Account expired, please contact help desk.\n" @@ -2134,19 +2104,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1568 +#: sssd.conf.5.xml:1535 msgid "pam_account_locked_message (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1571 +#: sssd.conf.5.xml:1538 msgid "" "Allows a custom lockout message to be set, replacing the default 'Permission " "denied' message." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1578 +#: sssd.conf.5.xml:1545 #, no-wrap msgid "" "pam_account_locked_message = Account locked, please contact help desk.\n" @@ -2154,85 +2124,130 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1587 +#: sssd.conf.5.xml:1554 #, fuzzy #| msgid "ldap_chpass_update_last_change (bool)" -msgid "pam_passkey_auth (bool)" +msgid "pam_passkey_auth (boolean)" msgstr "ldap_chpass_update_last_change (Boolesch)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1590 +#: sssd.conf.5.xml:1557 msgid "Enable passkey device based authentication." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1593 sssd.conf.5.xml:1910 sssd-ad.5.xml:1286 +#: sssd.conf.5.xml:1560 sssd.conf.5.xml:1907 sssd-ad.5.xml:1279 #: sss_rpcidmapd.5.xml:76 msgid "Default: True" msgstr "Voreinstellung: True" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1598 -msgid "passkey_debug_libfido2 (bool)" -msgstr "" +#: sssd.conf.5.xml:1565 +#, fuzzy +#| msgid "ipa_automount_location (string)" +msgid "passkey_debug_libfido2 (boolean)" +msgstr "ipa_automount_location (Zeichenkette)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1601 +#: sssd.conf.5.xml:1568 msgid "Enable libfido2 library debug messages." msgstr "" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1604 sssd.conf.5.xml:1618 sssd-ldap.5.xml:727 -#: sssd-ldap.5.xml:752 sssd-ldap.5.xml:848 sssd-ldap.5.xml:1356 -#: sssd-ad.5.xml:506 sssd-ad.5.xml:582 sssd-ad.5.xml:1155 +#: sssd.conf.5.xml:1571 sssd.conf.5.xml:1585 sssd.conf.5.xml:4781 +#: sssd-ldap.5.xml:727 sssd-ldap.5.xml:752 sssd-ldap.5.xml:848 +#: sssd-ldap.5.xml:1356 sssd-ad.5.xml:506 sssd-ad.5.xml:582 sssd-ad.5.xml:1160 #: include/ldap_id_mapping.xml:250 msgid "Default: False" msgstr "Voreinstellung: False" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1609 -msgid "pam_cert_auth (bool)" -msgstr "" +#: sssd.conf.5.xml:1576 +#, fuzzy +#| msgid "ldap_chpass_update_last_change (bool)" +msgid "pam_cert_auth (boolean)" +msgstr "ldap_chpass_update_last_change (Boolesch)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1612 +#: sssd.conf.5.xml:1579 msgid "" "Enable certificate based Smartcard authentication. Since this requires " "additional communication with the Smartcard which will delay the " "authentication process this option is disabled by default." msgstr "" +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1588 +msgid "" +"Note: In case OpenSC is used for Smartcard access SSSD supports the " +"filesystem caching in OpenSC when enabled in opensc.conf. The cached files " +"are located in a common <quote>opensc</quote> directory in SSSD's state " +"directory. The behaviour can be changed in opensc.conf" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> +#: sssd.conf.5.xml:1597 +#, no-wrap +msgid "" +"app /usr/libexec/sssd/p11_child {\n" +" framework pkcs15 {\n" +" use_file_caching = no;\n" +" }\n" +"}\n" +"app /usr/libexec/sssd/krb5_child {\n" +" framework pkcs15 {\n" +" use_file_caching = no;\n" +" }\n" +"}\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1595 +#, fuzzy +#| msgid "example: <placeholder type=\"programlisting\" id=\"0\"/>" +msgid "" +"Example opensc.conf (*): <placeholder type=\"programlisting\" id=\"0\"/>" +msgstr "Beispiel: <placeholder type=\"programlisting\" id=\"0\"/>" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1610 +msgid "" +"(*) The actual <quote>libexec</quote> directory for p11_child and krb5_child " +"depends on the distribution." +msgstr "" + #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1623 +#: sssd.conf.5.xml:1615 msgid "pam_cert_db_path (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1626 +#: sssd.conf.5.xml:1618 msgid "The path to the certificate database." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1629 sssd.conf.5.xml:2163 sssd.conf.5.xml:4338 +#: sssd.conf.5.xml:1621 sssd.conf.5.xml:2199 sssd.conf.5.xml:4543 msgid "Default:" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1631 sssd.conf.5.xml:2165 +#: sssd.conf.5.xml:1623 sssd.conf.5.xml:2201 msgid "" "/etc/sssd/pki/sssd_auth_ca_db.pem (path to a file with trusted CA " "certificates in PEM format)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1641 +#: sssd.conf.5.xml:1633 #, fuzzy #| msgid "ipa_automount_location (string)" msgid "pam_cert_verification (string)" msgstr "ipa_automount_location (Zeichenkette)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1644 +#: sssd.conf.5.xml:1636 msgid "" "With this parameter the PAM certificate verification can be tuned with a " "comma separated list of options that override the " @@ -2242,7 +2257,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1655 +#: sssd.conf.5.xml:1647 #, fuzzy, no-wrap #| msgid "" #| "fallback_homedir = /home/%u\n" @@ -2255,63 +2270,63 @@ msgstr "" " " #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1659 +#: sssd.conf.5.xml:1651 msgid "" "Default: not set, i.e. use default <quote>certificate_verification</quote> " "option defined in <quote>[sssd]</quote> section." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1666 +#: sssd.conf.5.xml:1658 msgid "p11_child_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1669 +#: sssd.conf.5.xml:1661 msgid "How many seconds will pam_sss wait for p11_child to finish." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1678 +#: sssd.conf.5.xml:1670 #, fuzzy #| msgid "pam_id_timeout (integer)" msgid "passkey_child_timeout (integer)" msgstr "pam_id_timeout (Ganzzahl)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1681 +#: sssd.conf.5.xml:1673 msgid "" "How many seconds will the PAM responder wait for passkey_child to finish." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1690 +#: sssd.conf.5.xml:1682 msgid "pam_app_services (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1693 +#: sssd.conf.5.xml:1685 msgid "" "Which PAM services are permitted to contact domains of type " "<quote>application</quote>" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1702 +#: sssd.conf.5.xml:1694 #, fuzzy #| msgid "simple_allow_users (string)" msgid "pam_p11_allowed_services (string)" msgstr "simple_allow_users (Zeichenkette)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1705 +#: sssd.conf.5.xml:1697 msgid "" "A comma-separated list of PAM service names for which it will be allowed to " "use Smartcards." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1720 +#: sssd.conf.5.xml:1712 #, no-wrap msgid "" "pam_p11_allowed_services = +my_pam_service, -login\n" @@ -2319,7 +2334,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1709 +#: sssd.conf.5.xml:1701 msgid "" "It is possible to add another PAM service name to the default set by using " "<quote>+service_name</quote> or to explicitly remove a PAM service name from " @@ -2331,68 +2346,73 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1724 sssd-ad.5.xml:645 sssd-ad.5.xml:754 sssd-ad.5.xml:812 -#: sssd-ad.5.xml:870 sssd-ad.5.xml:948 +#: sssd.conf.5.xml:1716 sssd-ad.5.xml:645 sssd-ad.5.xml:759 sssd-ad.5.xml:817 +#: sssd-ad.5.xml:875 sssd-ad.5.xml:953 msgid "Default: the default set of PAM service names includes:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1729 sssd-ad.5.xml:649 +#: sssd.conf.5.xml:1721 sssd-ad.5.xml:649 msgid "login" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1734 sssd-ad.5.xml:654 +#: sssd.conf.5.xml:1726 sssd-ad.5.xml:654 msgid "su" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1739 sssd-ad.5.xml:659 +#: sssd.conf.5.xml:1731 sssd-ad.5.xml:659 msgid "su-l" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1744 sssd-ad.5.xml:674 +#: sssd.conf.5.xml:1736 sssd-ad.5.xml:674 msgid "gdm-smartcard" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1749 sssd-ad.5.xml:669 +#: sssd.conf.5.xml:1741 sssd-ad.5.xml:669 msgid "gdm-password" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1754 +#: sssd.conf.5.xml:1746 msgid "gdm-switchable-auth" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1759 sssd-ad.5.xml:679 +#: sssd.conf.5.xml:1751 sssd-ad.5.xml:679 msgid "kdm" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1764 sssd-ad.5.xml:957 +#: sssd.conf.5.xml:1756 sssd-ad.5.xml:694 +msgid "plasmalogin" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:1761 sssd-ad.5.xml:962 msgid "sudo" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1769 sssd-ad.5.xml:962 +#: sssd.conf.5.xml:1766 sssd-ad.5.xml:967 msgid "sudo-i" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1774 +#: sssd.conf.5.xml:1771 msgid "gnome-screensaver" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1782 +#: sssd.conf.5.xml:1779 msgid "p11_wait_for_card_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1785 +#: sssd.conf.5.xml:1782 msgid "" "If Smartcard authentication is required how many extra seconds in addition " "to p11_child_timeout should the PAM responder wait until a Smartcard is " @@ -2400,12 +2420,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1796 +#: sssd.conf.5.xml:1793 msgid "p11_uri (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1799 +#: sssd.conf.5.xml:1796 msgid "" "PKCS#11 URI (see RFC-7512 for details) which can be used to restrict the " "selection of devices used for Smartcard authentication. By default SSSD's " @@ -2416,7 +2436,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1812 +#: sssd.conf.5.xml:1809 #, no-wrap msgid "" "p11_uri = pkcs11:slot-description=My%20Smartcard%20Reader\n" @@ -2424,7 +2444,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1816 +#: sssd.conf.5.xml:1813 #, no-wrap msgid "" "p11_uri = pkcs11:library-description=OpenSC%20smartcard%20framework;slot-id=2\n" @@ -2432,7 +2452,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1810 +#: sssd.conf.5.xml:1807 msgid "" "Example: <placeholder type=\"programlisting\" id=\"0\"/> or <placeholder " "type=\"programlisting\" id=\"1\"/> To find suitable URI please check the " @@ -2441,47 +2461,49 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1829 -msgid "pam_initgroups_scheme" -msgstr "" +#: sssd.conf.5.xml:1826 +#, fuzzy +#| msgid "ldap_netgroup_member (string)" +msgid "pam_initgroups_scheme (string)" +msgstr "ldap_netgroup_member (Zeichenkette)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1837 +#: sssd.conf.5.xml:1834 msgid "always" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1838 +#: sssd.conf.5.xml:1835 msgid "" "Always do an online lookup, please note that pam_id_timeout still applies" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1842 +#: sssd.conf.5.xml:1839 msgid "no_session" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1843 +#: sssd.conf.5.xml:1840 msgid "" "Only do an online lookup if there is no active session of the user, i.e. if " "the user is currently not logged in" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1848 sssd-ldap.5.xml:189 +#: sssd.conf.5.xml:1845 sssd-ldap.5.xml:189 msgid "never" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1849 +#: sssd.conf.5.xml:1846 msgid "" "Never force an online lookup, use the data from the cache as long as they " "are not expired" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1832 +#: sssd.conf.5.xml:1829 msgid "" "The PAM responder can force an online lookup to get the current group " "memberships of the user trying to log in. This option controls when this " @@ -2490,17 +2512,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1856 +#: sssd.conf.5.xml:1853 msgid "Default: no_session" msgstr "" -#. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:1861 sssd.conf.5.xml:4277 -msgid "pam_gssapi_services" -msgstr "" +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1858 +#, fuzzy +#| msgid "simple_allow_users (string)" +msgid "pam_gssapi_services (string)" +msgstr "simple_allow_users (Zeichenkette)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1864 +#: sssd.conf.5.xml:1861 #, fuzzy #| msgid "Comma separated list of users who are allowed to log in." msgid "" @@ -2509,13 +2533,13 @@ msgid "" msgstr "Durch Kommata getrennte Liste von Benutzern, die sich anmelden dürfen." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1869 +#: sssd.conf.5.xml:1866 msgid "" "To disable GSSAPI authentication, set this option to <quote>-</quote> (dash)." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1873 sssd.conf.5.xml:1904 sssd.conf.5.xml:1942 +#: sssd.conf.5.xml:1870 sssd.conf.5.xml:1901 sssd.conf.5.xml:1939 msgid "" "Note: This option can also be set per-domain which overwrites the value in " "[pam] section. It can also be set for trusted domain which overwrites the " @@ -2523,7 +2547,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1881 +#: sssd.conf.5.xml:1878 #, fuzzy, no-wrap #| msgid "" #| "fallback_homedir = /home/%u\n" @@ -2536,22 +2560,24 @@ msgstr "" " " #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1879 sssd.conf.5.xml:1994 sssd.conf.5.xml:3836 +#: sssd.conf.5.xml:1876 sssd.conf.5.xml:2023 sssd.conf.5.xml:4042 msgid "Example: <placeholder type=\"programlisting\" id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1885 +#: sssd.conf.5.xml:1882 msgid "Default: - (GSSAPI authentication is disabled)" msgstr "" -#. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:1890 sssd.conf.5.xml:4278 -msgid "pam_gssapi_check_upn" -msgstr "" +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1887 +#, fuzzy +#| msgid "ldap_disable_paging (boolean)" +msgid "pam_gssapi_check_upn (boolean)" +msgstr "ldap_disable_paging (Boolesch)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1893 +#: sssd.conf.5.xml:1890 msgid "" "If True, SSSD will require that the Kerberos user principal that " "successfully authenticated through GSSAPI can be associated with the user " @@ -2559,19 +2585,21 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1900 +#: sssd.conf.5.xml:1897 msgid "" -"If False, every user that is able to obtained required service ticket will " +"If False, every user that is able to obtain a required service ticket will " "be authenticated." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1915 -msgid "pam_gssapi_indicators_map" -msgstr "" +#: sssd.conf.5.xml:1912 +#, fuzzy +#| msgid "ldap_autofs_map_name (string)" +msgid "pam_gssapi_indicators_map (string)" +msgstr "ldap_autofs_map_name (Zeichenkette)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1918 +#: sssd.conf.5.xml:1915 msgid "" "Comma separated list of authentication indicators required to be present in " "a Kerberos ticket to access a PAM service that is allowed to try GSSAPI " @@ -2579,7 +2607,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1924 +#: sssd.conf.5.xml:1921 msgid "" "Each element of the list can be either an authentication indicator name or a " "pair <quote>service:indicator</quote>. Indicators not prefixed with the PAM " @@ -2594,7 +2622,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1937 +#: sssd.conf.5.xml:1934 msgid "" "To disable GSSAPI authentication indicator check, set this option to <quote>-" "</quote> (dash). To disable the check for a specific PAM service, add " @@ -2602,45 +2630,45 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1948 +#: sssd.conf.5.xml:1945 msgid "" "Following authentication indicators are supported by IPA Kerberos " "deployments:" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1951 +#: sssd.conf.5.xml:1948 msgid "" "pkinit -- pre-authentication using X.509 certificates -- whether stored in " "files or on smart cards." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1954 +#: sssd.conf.5.xml:1951 msgid "" "hardened -- SPAKE pre-authentication or any pre-authentication wrapped in a " "FAST channel." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1957 +#: sssd.conf.5.xml:1954 msgid "radius -- pre-authentication with the help of a RADIUS server." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1960 +#: sssd.conf.5.xml:1957 msgid "" "otp -- pre-authentication using integrated two-factor authentication (2FA or " "one-time password, OTP) in IPA." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1963 +#: sssd.conf.5.xml:1960 msgid "idp -- pre-authentication using external identity provider." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1973 +#: sssd.conf.5.xml:1970 #, no-wrap msgid "" "pam_gssapi_indicators_map = sudo:pkinit, sudo-i:pkinit\n" @@ -2648,7 +2676,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1968 +#: sssd.conf.5.xml:1965 msgid "" "Example: to require access to SUDO services only for users which obtained " "their Kerberos tickets with a X.509 certificate pre-authentication (PKINIT), " @@ -2656,7 +2684,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1977 +#: sssd.conf.5.xml:1974 #, fuzzy #| msgid "Default: not set (no substitution for unset home directories)" msgid "Default: not set (use of authentication indicators is not required)" @@ -2665,14 +2693,57 @@ msgstr "" "Verzeichnisse)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1979 +#, fuzzy +#| msgid "base_directory (string)" +msgid "pam_gssapi_indicators_apply (string)" +msgstr "base_directory (Zeichenkette)" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1982 +msgid "" +"Comma separated list of triples to assign additional information from the " +"Kerberos ticket, e.g. a SID from the PAC, to authentication indicators." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1988 +#, fuzzy +#| msgid "Currently supported debug levels:" +msgid "Currently supported is:" +msgstr "derzeit unterstützte Debug-Stufen:" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:1991 +msgid "SID:S-1-5-[domain]-[RID]:[authentication indicator]" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> +#: sssd.conf.5.xml:2002 +#, no-wrap +msgid "" +"pam_gssapi_indicators_apply = SID:S-1-5-12345-23456-34567-4321:pkinit\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1996 +msgid "" +"Example: To assign a SID, which is e.g. set by Active Directory's " +"Authentication Mechanism Assurance (AMA) if the AD user used a Smartcard for " +"authentication, to the 'pkinit' authentication indicator use: <placeholder " +"type=\"programlisting\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2011 #, fuzzy #| msgid "simple_allow_users (string)" msgid "pam_json_services (string)" msgstr "simple_allow_users (Zeichenkette)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1985 +#: sssd.conf.5.xml:2014 #, fuzzy #| msgid "Comma separated list of users who are allowed to log in." msgid "" @@ -2681,12 +2752,12 @@ msgid "" msgstr "Durch Kommata getrennte Liste von Benutzern, die sich anmelden dürfen." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1990 +#: sssd.conf.5.xml:2019 msgid "To disable JSON protocol, set this option to <quote>-</quote> (dash)." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1996 +#: sssd.conf.5.xml:2025 #, fuzzy, no-wrap #| msgid "" #| "fallback_homedir = /home/%u\n" @@ -2699,33 +2770,55 @@ msgstr "" " " #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2000 +#: sssd.conf.5.xml:2029 #, fuzzy #| msgid "Default: 0 (disabled)" msgid "Default: - (JSON protocol is disabled)" msgstr "Voreinstellung: 0 (deaktiviert)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2003 +#: sssd.conf.5.xml:2032 msgid "" "Note: 2-Factor Authentication (2FA) is not supported. If 2FA is required, do " "not activate the JSON protocol." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:2013 +#: sssd.conf.5.xml:2042 msgid "SUDO configuration options" msgstr "Sudo-Konfigurationsoptionen" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2015 +#: sssd.conf.5.xml:2044 +#, fuzzy +#| msgid "" +#| "These options can be used to configure the Name Service Switch (NSS) " +#| "service." msgid "" -"These options can be used to configure the sudo service. The detailed " -"instructions for configuration of <citerefentry> <refentrytitle>sudo</" -"refentrytitle> <manvolnum>8</manvolnum> </citerefentry> to work with " -"<citerefentry> <refentrytitle>sssd</refentrytitle> <manvolnum>8</manvolnum> " -"</citerefentry> are in the manual page <citerefentry> <refentrytitle>sssd-" -"sudo</refentrytitle> <manvolnum>5</manvolnum> </citerefentry>." +"These options can be used to configure the sudo service and should be " +"specified under the <quote>[sudo]</quote> section." +msgstr "" +"Diese Optionen können zum Konfigurieren des »Name Service Switch« (NSS) " +"benutzt werden" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:2048 +#, fuzzy +#| msgid "" +#| "These options can be used to configure the sudo service. The detailed " +#| "instructions for configuration of <citerefentry> <refentrytitle>sudo</" +#| "refentrytitle> <manvolnum>8</manvolnum> </citerefentry> to work with " +#| "<citerefentry> <refentrytitle>sssd</refentrytitle> <manvolnum>8</" +#| "manvolnum> </citerefentry> are in the manual page <citerefentry> " +#| "<refentrytitle>sssd-sudo</refentrytitle> <manvolnum>5</manvolnum> </" +#| "citerefentry>." +msgid "" +"The detailed instructions for configuration of <citerefentry> " +"<refentrytitle>sudo</refentrytitle> <manvolnum>8</manvolnum> </citerefentry> " +"to work with <citerefentry> <refentrytitle>sssd</refentrytitle> " +"<manvolnum>8</manvolnum> </citerefentry> are in the manual page " +"<citerefentry> <refentrytitle>sssd-sudo</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry>." msgstr "" "Diese Optionen können zur Konfiguration des Sudo-Dienstes verwendet werden. " "Detaillierte Informationen zur Konfiguration von <citerefentry> " @@ -2736,12 +2829,14 @@ msgstr "" "manvolnum> </citerefentry>." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2032 -msgid "sudo_timed (bool)" +#: sssd.conf.5.xml:2064 +#, fuzzy +#| msgid "sudo_timed (bool)" +msgid "sudo_timed (boolean)" msgstr "sudo_timed (Boolesch)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2035 +#: sssd.conf.5.xml:2067 msgid "" "Whether or not to evaluate the sudoNotBefore and sudoNotAfter attributes " "that implement time-dependent sudoers entries." @@ -2751,12 +2846,12 @@ msgstr "" "nicht." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2047 +#: sssd.conf.5.xml:2079 msgid "sudo_threshold (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2050 +#: sssd.conf.5.xml:2082 msgid "" "Maximum number of expired rules that can be refreshed at once. If number of " "expired rules is below threshold, those rules are refreshed with " @@ -2766,23 +2861,27 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:2069 +#: sssd.conf.5.xml:2101 msgid "AUTOFS configuration options" msgstr "AUTOFS-Konfigurationsoptionen" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2071 -msgid "These options can be used to configure the autofs service." +#: sssd.conf.5.xml:2103 +#, fuzzy +#| msgid "These options can be used to configure the autofs service." +msgid "" +"These options can be used to configure the autofs service and should be " +"specified under the <quote>[autofs]</quote> section." msgstr "" "Diese Optionen können zum Konfigurieren des Dienstes »autofs« benutzt werden." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2075 +#: sssd.conf.5.xml:2109 msgid "autofs_negative_timeout (integer)" msgstr "autofs_negative_timeout (Ganzzahl)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2078 +#: sssd.conf.5.xml:2112 msgid "" "Specifies for how many seconds should the autofs responder negative cache " "hits (that is, queries for invalid map entries, like nonexistent ones) " @@ -2793,23 +2892,29 @@ msgstr "" "nicht existierende), bevor das Backend erneut befragt wird." #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:2094 +#: sssd.conf.5.xml:2128 msgid "SSH configuration options" msgstr "SSH-Konfigurationsoptionen" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2096 -msgid "These options can be used to configure the SSH service." +#: sssd.conf.5.xml:2130 +#, fuzzy +#| msgid "These options can be used to configure the SSH service." +msgid "" +"These options can be used to configure the SSH service and should be " +"specified under the <quote>[ssh]</quote> section." msgstr "" "Diese Optionen können zum Konfigurieren des SSH-Dienstes benutzt werden." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2100 -msgid "ssh_use_certificate_keys (bool)" -msgstr "" +#: sssd.conf.5.xml:2136 +#, fuzzy +#| msgid "ipa_automount_location (string)" +msgid "ssh_use_certificate_keys (boolean)" +msgstr "ipa_automount_location (Zeichenkette)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2103 +#: sssd.conf.5.xml:2139 msgid "" "If set to true the <command>sss_ssh_authorizedkeys</command> will return ssh " "keys derived from the public key of X.509 certificates stored in the user " @@ -2818,12 +2923,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2118 +#: sssd.conf.5.xml:2154 msgid "ssh_use_certificate_matching_rules (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2121 +#: sssd.conf.5.xml:2157 msgid "" "By default the ssh responder will use all available certificate matching " "rules to filter the certificates so that ssh keys are only derived from the " @@ -2833,7 +2938,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2130 +#: sssd.conf.5.xml:2166 msgid "" "There are two special key words 'all_rules' and 'no_rules' which will enable " "all or no rules, respectively. The latter means that no certificates will be " @@ -2841,7 +2946,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2137 +#: sssd.conf.5.xml:2173 msgid "" "If no rules are configured using 'all_rules' will enable a default rule " "which enables all certificates suitable for client authentication. This is " @@ -2850,38 +2955,38 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2144 +#: sssd.conf.5.xml:2180 msgid "" "A non-existing rule name is considered an error. If as a result no rule is " "selected all certificates will be ignored." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2149 +#: sssd.conf.5.xml:2185 msgid "" "Default: not set, equivalent to 'all_rules', all found rules or the default " "rule are used" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2155 +#: sssd.conf.5.xml:2191 msgid "ca_db (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2158 +#: sssd.conf.5.xml:2194 msgid "" "Path to a storage of trusted CA certificates. The option is used to validate " "user certificates before deriving public ssh keys from them." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:2178 +#: sssd.conf.5.xml:2214 msgid "PAC responder configuration options" msgstr "PAC-Responder-Konfigurationsoptionen" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2180 +#: sssd.conf.5.xml:2216 msgid "" "The PAC responder works together with the authorization data plugin for MIT " "Kerberos sssd_pac_plugin.so and a sub-domain provider. The plugin sends the " @@ -2892,7 +2997,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:2189 +#: sssd.conf.5.xml:2225 msgid "" "If the remote user does not exist in the cache, it is created. The UID is " "determined with the help of the SID, trusted domains will have UPGs and the " @@ -2903,7 +3008,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:2197 +#: sssd.conf.5.xml:2233 msgid "" "If there are SIDs of groups from domains sssd knows about, the user will be " "added to those groups." @@ -2912,18 +3017,22 @@ msgstr "" "diesen Gruppen hinzugefügt." #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2203 -msgid "These options can be used to configure the PAC responder." +#: sssd.conf.5.xml:2239 +#, fuzzy +#| msgid "These options can be used to configure the PAC responder." +msgid "" +"These options can be used to configure the PAC responder and should be " +"specified under the <quote>[pac]</quote> section." msgstr "" "Diese Optionen können zur Konfiguration des PAC-Responders verwendet werden." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2207 sssd-ifp.5.xml:66 +#: sssd.conf.5.xml:2244 sssd-ifp.5.xml:66 msgid "allowed_uids (string)" msgstr "allowed_uids (Zeichenkette)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2210 +#: sssd.conf.5.xml:2247 msgid "" "Specifies the comma-separated list of UID values or user names that are " "allowed to access the PAC responder. User names are resolved to UIDs at " @@ -2934,7 +3043,7 @@ msgstr "" "beim Starten zu UIDs aufgelöst." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2216 +#: sssd.conf.5.xml:2253 #, fuzzy #| msgid "" #| "Default: 0 (only the root user is allowed to access the PAC responder)" @@ -2946,14 +3055,14 @@ msgstr "" "Responder gestattet.)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2220 +#: sssd.conf.5.xml:2257 msgid "Default: 0 (only the root user is allowed to access the PAC responder)" msgstr "" "Voreinstellung: 0 (Nur dem Benutzer Root ist der Zugriff auf den PAC-" "Responder gestattet.)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2224 +#: sssd.conf.5.xml:2261 #, fuzzy #| msgid "" #| "Please note that although the UID 0 is used as the default it will be " @@ -2972,7 +3081,7 @@ msgstr "" "der Liste der erlaubten UIDs auch die 0 hinzufügen." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2231 +#: sssd.conf.5.xml:2268 msgid "" "Please note that although the UID 0 is used as the default it will be " "overwritten with this option. If you still want to allow the root user to " @@ -2985,26 +3094,26 @@ msgstr "" "der Liste der erlaubten UIDs auch die 0 hinzufügen." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2240 +#: sssd.conf.5.xml:2277 msgid "pac_lifetime (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2243 +#: sssd.conf.5.xml:2280 msgid "" "Lifetime of the PAC entry in seconds. As long as the PAC is valid the PAC " "data can be used to determine the group memberships of a user." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2253 +#: sssd.conf.5.xml:2290 #, fuzzy #| msgid "ldap_schema (string)" msgid "pac_check (string)" msgstr "ldap_schema (Zeichenkette)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2256 +#: sssd.conf.5.xml:2293 msgid "" "Apply additional checks on the PAC of the Kerberos ticket which is available " "in Active Directory and FreeIPA domains, if configured. Please note that " @@ -3015,7 +3124,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2266 +#: sssd.conf.5.xml:2303 msgid "" "Please note that the checks listed below only apply to PACs issued by Active " "Directory or recent versions of FreeIPA. PACs issued e.g. by a plain MIT " @@ -3023,24 +3132,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2277 +#: sssd.conf.5.xml:2314 msgid "no_check" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2279 +#: sssd.conf.5.xml:2316 msgid "" "The PAC must not be present and even if it is present no additional checks " "will be done." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2285 +#: sssd.conf.5.xml:2322 msgid "pac_present" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2287 +#: sssd.conf.5.xml:2324 msgid "" "The PAC must be present in the service ticket which SSSD will request with " "the help of the user's TGT. If the PAC is not available the authentication " @@ -3048,24 +3157,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2295 +#: sssd.conf.5.xml:2332 msgid "check_upn" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2297 +#: sssd.conf.5.xml:2334 msgid "" "If the PAC is present check if the user principal name (UPN) information is " "consistent." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2303 +#: sssd.conf.5.xml:2340 msgid "check_upn_allow_missing" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2305 +#: sssd.conf.5.xml:2342 msgid "" "This option should be used together with 'check_upn' and handles the case " "where a UPN is set on the server-side but is not read by SSSD. The typical " @@ -3077,7 +3186,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2317 +#: sssd.conf.5.xml:2354 msgid "" "Currently this option is set by default to avoid regressions in such " "environments. A log message will be added to the system log and SSSD's debug " @@ -3088,41 +3197,41 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2331 +#: sssd.conf.5.xml:2368 msgid "upn_dns_info_present" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2333 +#: sssd.conf.5.xml:2370 msgid "The PAC must contain the UPN-DNS-INFO buffer, implies 'check_upn'." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2338 +#: sssd.conf.5.xml:2375 msgid "check_upn_dns_info_ex" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2340 +#: sssd.conf.5.xml:2377 msgid "" "If the PAC is present and the extension to the UPN-DNS-INFO buffer is " "available check if the information in the extension is consistent." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2347 +#: sssd.conf.5.xml:2384 msgid "upn_dns_info_ex_present" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2349 +#: sssd.conf.5.xml:2386 msgid "" "The PAC must contain the extension of the UPN-DNS-INFO buffer, implies " "'check_upn_dns_info_ex', 'upn_dns_info_present' and 'check_upn'." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2273 +#: sssd.conf.5.xml:2310 #, fuzzy #| msgid "" #| "The following expansions are supported: <placeholder " @@ -3135,19 +3244,19 @@ msgstr "" "type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2359 +#: sssd.conf.5.xml:2396 msgid "" "Default: no_check (AD and IPA provider 'check_upn, check_upn_allow_missing, " "check_upn_dns_info_ex')" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:2368 +#: sssd.conf.5.xml:2405 msgid "Session recording configuration options" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2370 +#: sssd.conf.5.xml:2407 msgid "" "Session recording works in conjunction with <citerefentry> " "<refentrytitle>tlog-rec-session</refentrytitle> <manvolnum>8</manvolnum> </" @@ -3157,66 +3266,78 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2383 -msgid "These options can be used to configure session recording." +#: sssd.conf.5.xml:2420 +msgid "" +"These options can be used to configure session recording and should be " +"specified under the <quote>[session_recording]</quote> section." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:2425 +msgid "" +"Note: Unlike other sections, the <quote>[session_recording]</quote> section " +"ignores <replaceable>debug*</replaceable> options and suitable " +"<replaceable>debug*</replaceable> options must be set in <quote>[pam]</" +"quote>, <quote>[nss]</quote> and <quote>[domain/<replaceable>NAME</" +"replaceable>]</quote> sections." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2387 sssd-session-recording.5.xml:64 +#: sssd.conf.5.xml:2433 sssd-session-recording.5.xml:64 msgid "scope (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2394 sssd-session-recording.5.xml:71 +#: sssd.conf.5.xml:2440 sssd-session-recording.5.xml:71 msgid "\"none\"" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2397 sssd-session-recording.5.xml:74 +#: sssd.conf.5.xml:2443 sssd-session-recording.5.xml:74 msgid "No users are recorded." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2402 sssd-session-recording.5.xml:79 +#: sssd.conf.5.xml:2448 sssd-session-recording.5.xml:79 msgid "\"some\"" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2405 sssd-session-recording.5.xml:82 +#: sssd.conf.5.xml:2451 sssd-session-recording.5.xml:82 msgid "" "Users/groups specified by <replaceable>users</replaceable> and " "<replaceable>groups</replaceable> options are recorded." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2414 sssd-session-recording.5.xml:91 +#: sssd.conf.5.xml:2460 sssd-session-recording.5.xml:91 msgid "\"all\"" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2417 sssd-session-recording.5.xml:94 +#: sssd.conf.5.xml:2463 sssd-session-recording.5.xml:94 msgid "All users are recorded." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2390 sssd-session-recording.5.xml:67 +#: sssd.conf.5.xml:2436 sssd-session-recording.5.xml:67 msgid "" "One of the following strings specifying the scope of session recording: " "<placeholder type=\"variablelist\" id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2424 sssd-session-recording.5.xml:101 +#: sssd.conf.5.xml:2470 sssd-session-recording.5.xml:101 msgid "Default: \"none\"" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2429 sssd-session-recording.5.xml:106 +#: sssd.conf.5.xml:2475 sssd-session-recording.5.xml:106 msgid "users (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2432 sssd-session-recording.5.xml:109 +#: sssd.conf.5.xml:2478 sssd-session-recording.5.xml:109 msgid "" "A comma-separated list of users which should have session recording enabled. " "Matches user names as returned by NSS. I.e. after the possible space " @@ -3224,17 +3345,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2438 sssd-session-recording.5.xml:115 +#: sssd.conf.5.xml:2484 sssd-session-recording.5.xml:115 msgid "Default: Empty. Matches no users." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2443 sssd-session-recording.5.xml:120 +#: sssd.conf.5.xml:2489 sssd-session-recording.5.xml:120 msgid "groups (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2446 sssd-session-recording.5.xml:123 +#: sssd.conf.5.xml:2492 sssd-session-recording.5.xml:123 msgid "" "A comma-separated list of groups, members of which should have session " "recording enabled. Matches group names as returned by NSS. I.e. after the " @@ -3242,7 +3363,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2452 sssd.conf.5.xml:2484 sssd-session-recording.5.xml:129 +#: sssd.conf.5.xml:2498 sssd.conf.5.xml:2530 sssd-session-recording.5.xml:129 #: sssd-session-recording.5.xml:161 msgid "" "NOTE: using this option (having it set to anything) has a considerable " @@ -3251,65 +3372,66 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2459 sssd-session-recording.5.xml:136 +#: sssd.conf.5.xml:2505 sssd-session-recording.5.xml:136 msgid "Default: Empty. Matches no groups." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2464 sssd-session-recording.5.xml:141 +#: sssd.conf.5.xml:2510 sssd-session-recording.5.xml:141 #, fuzzy #| msgid "simple_deny_users (string)" msgid "exclude_users (string)" msgstr "simple_deny_users (Zeichenkette)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2467 sssd-session-recording.5.xml:144 +#: sssd.conf.5.xml:2513 sssd-session-recording.5.xml:144 msgid "" "A comma-separated list of users to be excluded from recording, only " "applicable with 'scope=all'." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2471 sssd-session-recording.5.xml:148 +#: sssd.conf.5.xml:2517 sssd-session-recording.5.xml:148 #, fuzzy #| msgid "Default: empty, i.e. ldap_uri is used." msgid "Default: Empty. No users excluded." msgstr "Voreinstellung: leer, d.h., dass »ldap_uri« benutzt wird" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2476 sssd-session-recording.5.xml:153 +#: sssd.conf.5.xml:2522 sssd-session-recording.5.xml:153 #, fuzzy #| msgid "simple_deny_groups (string)" msgid "exclude_groups (string)" msgstr "simple_deny_groups (Zeichenkette)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2479 sssd-session-recording.5.xml:156 +#: sssd.conf.5.xml:2525 sssd-session-recording.5.xml:156 msgid "" "A comma-separated list of groups, members of which should be excluded from " "recording. Only applicable with 'scope=all'." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2491 sssd-session-recording.5.xml:168 +#: sssd.conf.5.xml:2537 sssd-session-recording.5.xml:168 #, fuzzy #| msgid "Default: empty, i.e. ldap_uri is used." msgid "Default: Empty. No groups excluded." msgstr "Voreinstellung: leer, d.h., dass »ldap_uri« benutzt wird" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:2501 +#: sssd.conf.5.xml:2547 msgid "DOMAIN SECTIONS" msgstr "DOMAIN-ABSCHNITTE" -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry><para> -#: sssd.conf.5.xml:2508 sssd.conf.5.xml:3964 sssd.conf.5.xml:3965 -#: sssd.conf.5.xml:3968 -msgid "enabled" -msgstr "" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2554 +#, fuzzy +#| msgid "ad_enable_gc (boolean)" +msgid "enabled (boolean)" +msgstr "ad_enable_gc (Boolesch)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2511 +#: sssd.conf.5.xml:2557 msgid "" "Explicitly enable or disable the domain. If <quote>true</quote>, the domain " "is always <quote>enabled</quote>. If <quote>false</quote>, the domain is " @@ -3319,12 +3441,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2523 +#: sssd.conf.5.xml:2569 msgid "domain_type (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2526 +#: sssd.conf.5.xml:2572 msgid "" "Specifies whether the domain is meant to be used by POSIX-aware clients such " "as the Name Service Switch or by applications that do not need POSIX data to " @@ -3333,14 +3455,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2534 +#: sssd.conf.5.xml:2580 msgid "" "Allowed values for this option are <quote>posix</quote> and " "<quote>application</quote>." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2538 +#: sssd.conf.5.xml:2584 msgid "" "POSIX domains are reachable by all services. Application domains are only " "reachable from the InfoPipe responder (see <citerefentry> " @@ -3349,31 +3471,31 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2546 +#: sssd.conf.5.xml:2592 msgid "" "NOTE: The application domains are currently well tested with " "<quote>id_provider=ldap</quote> only." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2550 +#: sssd.conf.5.xml:2596 msgid "" "For an easy way to configure a non-POSIX domains, please see the " "<quote>Application domains</quote> section." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2554 +#: sssd.conf.5.xml:2600 msgid "Default: posix" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2560 +#: sssd.conf.5.xml:2606 msgid "min_id,max_id (integer)" msgstr "min_id,max_id (Ganzzahl)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2563 +#: sssd.conf.5.xml:2609 msgid "" "UID and GID limits for the domain. If a domain contains an entry that is " "outside these limits, it is ignored." @@ -3382,7 +3504,7 @@ msgstr "" "enthält, der jenseits dieser Beschränkungen liegt, wird er ignoriert." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2568 +#: sssd.conf.5.xml:2614 msgid "" "For users, this affects the primary GID limit. The user will not be returned " "to NSS if either the UID or the primary GID is outside the range. For non-" @@ -3395,7 +3517,7 @@ msgstr "" "werden jene, die im Bereich liegen, wie erwartet gemeldet." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2575 +#: sssd.conf.5.xml:2621 msgid "" "These ID limits affect even saving entries to cache, not only returning them " "by name or ID." @@ -3404,17 +3526,19 @@ msgstr "" "den Zwischenspeicher und nicht nur ihre Rückgabe über Name oder ID." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2579 +#: sssd.conf.5.xml:2625 msgid "Default: 1 for min_id, 0 (no limit) for max_id" msgstr "Voreinstellung: 1 für »min_id«, 0 (keine Beschränkung) für »max_id«" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2585 -msgid "enumerate (bool)" +#: sssd.conf.5.xml:2631 +#, fuzzy +#| msgid "enumerate (bool)" +msgid "enumerate (boolean)" msgstr "enumerate (Boolesch)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2588 +#: sssd.conf.5.xml:2634 msgid "" "Determines if a domain can be enumerated, that is, whether the domain can " "list all the users and group it contains. Note that it is not required to " @@ -3423,36 +3547,36 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2596 +#: sssd.conf.5.xml:2642 msgid "TRUE = Users and groups are enumerated" msgstr "TRUE = Benutzer und Gruppen werden aufgezählt." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2599 +#: sssd.conf.5.xml:2645 msgid "FALSE = No enumerations for this domain" msgstr "FALSE = keine Aufzählungen für diese Domain" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2602 sssd.conf.5.xml:2867 sssd.conf.5.xml:3044 +#: sssd.conf.5.xml:2648 sssd.conf.5.xml:2992 sssd.conf.5.xml:3174 msgid "Default: FALSE" msgstr "Voreinstellung: FALSE" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2605 +#: sssd.conf.5.xml:2651 msgid "" "Enumerating a domain requires SSSD to download and store ALL user and group " "entries from the remote server." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2610 +#: sssd.conf.5.xml:2656 msgid "" "Feature is only supported for domains with id_provider = ldap or id_provider " "= proxy." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2614 +#: sssd.conf.5.xml:2660 msgid "" "Note: Enabling enumeration has a severe performance impact on SSSD while " "enumeration is running. It may take up to several minutes after SSSD startup " @@ -3466,7 +3590,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2629 +#: sssd.conf.5.xml:2675 msgid "" "While the first enumeration is running, requests for the complete user or " "group lists may return no results until it completes." @@ -3476,7 +3600,7 @@ msgstr "" "Ergebnisse zurück." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2634 +#: sssd.conf.5.xml:2680 msgid "" "Further, enabling enumeration may increase the time necessary to detect " "network disconnection, as longer timeouts are required to ensure that " @@ -3491,7 +3615,7 @@ msgstr "" "benutzten »id_provider«." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2642 +#: sssd.conf.5.xml:2688 msgid "" "For the reasons cited above, enabling enumeration is not recommended, " "especially in large environments." @@ -3500,7 +3624,7 @@ msgstr "" "insbesondere in großen Umgebungen, nicht empfohlen." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2647 +#: sssd.conf.5.xml:2693 msgid "" "Note: the proxy provider is tested with open source modules like " "'libnss_files' and 'libnss_ldap'. 3rd party modules must follow the " @@ -3508,12 +3632,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2656 +#: sssd.conf.5.xml:2702 msgid "entry_cache_timeout (integer)" msgstr "entry_cache_timeout (Ganzzahl)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2659 +#: sssd.conf.5.xml:2705 msgid "" "How many seconds should nss_sss consider entries valid before asking the " "backend again" @@ -3522,7 +3646,7 @@ msgstr "" "soll, bevor das Backend erneut abgefragt wird." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2663 +#: sssd.conf.5.xml:2709 msgid "" "The cache expiration timestamps are stored as attributes of individual " "objects in the cache. Therefore, changing the cache timeout only has effect " @@ -3540,17 +3664,17 @@ msgstr "" "wurden." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2676 +#: sssd.conf.5.xml:2722 msgid "Default: 5400" msgstr "Voreinstellung: 5400" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2682 +#: sssd.conf.5.xml:2728 msgid "entry_cache_user_timeout (integer)" msgstr "entry_cache_user_timeout (Ganzzahl)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2685 +#: sssd.conf.5.xml:2731 msgid "" "How many seconds should nss_sss consider user entries valid before asking " "the backend again" @@ -3559,19 +3683,19 @@ msgstr "" "betrachten soll, bevor das Backend erneut abgefragt wird." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2689 sssd.conf.5.xml:2702 sssd.conf.5.xml:2715 -#: sssd.conf.5.xml:2728 sssd.conf.5.xml:2742 sssd.conf.5.xml:2755 -#: sssd.conf.5.xml:2769 sssd.conf.5.xml:2783 sssd.conf.5.xml:2796 +#: sssd.conf.5.xml:2735 sssd.conf.5.xml:2748 sssd.conf.5.xml:2761 +#: sssd.conf.5.xml:2774 sssd.conf.5.xml:2788 sssd.conf.5.xml:2801 +#: sssd.conf.5.xml:2815 sssd.conf.5.xml:2829 msgid "Default: entry_cache_timeout" msgstr "Voreinstellung: entry_cache_timeout" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2695 +#: sssd.conf.5.xml:2741 msgid "entry_cache_group_timeout (integer)" msgstr "entry_cache_group_timeout (Ganzzahl)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2698 +#: sssd.conf.5.xml:2744 msgid "" "How many seconds should nss_sss consider group entries valid before asking " "the backend again" @@ -3580,12 +3704,12 @@ msgstr "" "betrachten soll, bevor das Backend erneut abgefragt wird." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2708 +#: sssd.conf.5.xml:2754 msgid "entry_cache_netgroup_timeout (integer)" msgstr "entry_cache_netgroup_timeout (Ganzzahl)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2711 +#: sssd.conf.5.xml:2757 msgid "" "How many seconds should nss_sss consider netgroup entries valid before " "asking the backend again" @@ -3594,12 +3718,12 @@ msgstr "" "betrachten soll, bevor das Backend erneut abgefragt wird." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2721 +#: sssd.conf.5.xml:2767 msgid "entry_cache_service_timeout (integer)" msgstr "entry_cache_service_timeout (Ganzzahl)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2724 +#: sssd.conf.5.xml:2770 msgid "" "How many seconds should nss_sss consider service entries valid before asking " "the backend again" @@ -3608,77 +3732,190 @@ msgstr "" "betrachten soll, bevor das Backend erneut abgefragt wird." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2734 +#: sssd.conf.5.xml:2780 msgid "entry_cache_resolver_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2737 +#: sssd.conf.5.xml:2783 msgid "" "How many seconds should nss_sss consider hosts and networks entries valid " "before asking the backend again" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2748 +#: sssd.conf.5.xml:2794 msgid "entry_cache_sudo_timeout (integer)" msgstr "entry_cache_sudo_timeout (Ganzzahl)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2751 +#: sssd.conf.5.xml:2797 +msgid "" +"How many seconds should sudo consider rules valid before asking the backend " +"again" +msgstr "" +"bestimmt, wie viele Sekunden lang Sudo Regeln als gültig betrachten soll, " +"bevor das Backend erneut abgefragt wird." + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2807 +msgid "entry_cache_autofs_timeout (integer)" +msgstr "entry_cache_autofs_timeout (Ganzzahl)" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2810 +msgid "" +"How many seconds should the autofs service consider automounter maps valid " +"before asking the backend again" +msgstr "" +"bestimmt, wie viele Sekunden lang der Dienst »autofs« Abbilder des " +"Automounters als gültig betrachten soll, bevor das Backend erneut abgefragt " +"wird." + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2821 +msgid "entry_cache_ssh_host_timeout (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2824 +msgid "" +"How many seconds to keep a host ssh key after refresh. IE how long to cache " +"the host key for." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2835 +msgid "offline_timeout (integer)" +msgstr "offline_timeout (Ganzzahl)" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2838 +msgid "" +"When SSSD switches to offline mode the amount of time before it tries to go " +"back online will increase based upon the time spent disconnected. By " +"default SSSD uses incremental behaviour to calculate delay in between " +"retries. So, the wait time for a given retry will be longer than the wait " +"time for the previous ones. After each unsuccessful attempt to go online, " +"the new interval is recalculated by the following:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2849 sssd.conf.5.xml:2907 +msgid "" +"new_delay = Minimum(old_delay * 2, offline_timeout_max) + " +"random[0...offline_timeout_random_offset]" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2852 +msgid "" +"The offline_timeout default value is 60. The offline_timeout_max default " +"value is 3600. The offline_timeout_random_offset default value is 30. The " +"end result is the number of seconds before next retry." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2858 +msgid "" +"Note that the maximum length of each interval is defined by " +"offline_timeout_max (apart from the random part)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2868 +#, fuzzy +#| msgid "offline_timeout (integer)" +msgid "offline_timeout_max (integer)" +msgstr "offline_timeout (Ganzzahl)" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2871 +msgid "" +"Controls by how much the time between attempts to go online can be " +"incremented following unsuccessful attempts to go online." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2876 +msgid "A value of 0 disables the incrementing behaviour." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2879 +msgid "" +"The value of this parameter should be set in correlation to offline_timeout " +"parameter value." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2883 +msgid "" +"With offline_timeout set to 60 (default value) there is no point in setting " +"offline_timeout_max to less than 120 as it will saturate instantly. General " +"rule here should be to set offline_timeout_max to at least 4 times " +"offline_timeout." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2889 msgid "" -"How many seconds should sudo consider rules valid before asking the backend " -"again" +"Although a value between 0 and offline_timeout may be specified, it has the " +"effect of overriding the offline_timeout value so is of little use." msgstr "" -"bestimmt, wie viele Sekunden lang Sudo Regeln als gültig betrachten soll, " -"bevor das Backend erneut abgefragt wird." + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2894 +#, fuzzy +#| msgid "Default: 300" +msgid "Default: 3600" +msgstr "Voreinstellung: 300" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2761 -msgid "entry_cache_autofs_timeout (integer)" -msgstr "entry_cache_autofs_timeout (Ganzzahl)" +#: sssd.conf.5.xml:2900 +#, fuzzy +#| msgid "offline_timeout (integer)" +msgid "offline_timeout_random_offset (integer)" +msgstr "offline_timeout (Ganzzahl)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2764 +#: sssd.conf.5.xml:2903 msgid "" -"How many seconds should the autofs service consider automounter maps valid " -"before asking the backend again" -msgstr "" -"bestimmt, wie viele Sekunden lang der Dienst »autofs« Abbilder des " -"Automounters als gültig betrachten soll, bevor das Backend erneut abgefragt " -"wird." - -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2775 -msgid "entry_cache_ssh_host_timeout (integer)" +"When SSSD is in offline mode it keeps probing backend servers in specified " +"time intervals:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2778 +#: sssd.conf.5.xml:2910 msgid "" -"How many seconds to keep a host ssh key after refresh. IE how long to cache " -"the host key for." +"This parameter controls the value of the random offset used for the above " +"equation. Final random_offset value will be random number in range:" msgstr "" -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2789 -msgid "entry_cache_computer_timeout (integer)" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2915 +msgid "[0 - offline_timeout_random_offset]" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2792 -msgid "" -"How many seconds to keep the local computer entry before asking the backend " -"again" +#: sssd.conf.5.xml:2918 +msgid "A value of 0 disables the random offset addition." msgstr "" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2921 +#, fuzzy +#| msgid "Default: 300" +msgid "Default: 30" +msgstr "Voreinstellung: 300" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2802 +#: sssd.conf.5.xml:2927 msgid "refresh_expired_interval (integer)" msgstr "refresh_expired_interval (Ganzzahl)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2805 +#: sssd.conf.5.xml:2930 msgid "" "Specifies how many seconds SSSD has to wait before triggering a background " "refresh task which will refresh all expired or nearly expired records." @@ -3688,7 +3925,7 @@ msgstr "" "abgelaufenen oder beinahe abgelaufenen Daten aktualisiert werden." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2810 +#: sssd.conf.5.xml:2935 msgid "" "The background refresh will process users, groups and netgroups in the " "cache. For users who have performed the initgroups (get group membership for " @@ -3697,19 +3934,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2818 +#: sssd.conf.5.xml:2943 msgid "This option is automatically inherited for all trusted domains." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2822 +#: sssd.conf.5.xml:2947 msgid "You can consider setting this value to 3/4 * entry_cache_timeout." msgstr "" "Sie können in Betracht ziehen, diesen Wert auf 3/4 * entry_cache_timeout zu " "setzen." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2826 +#: sssd.conf.5.xml:2951 msgid "" "Cache entry will be refreshed by background task when 2/3 of cache timeout " "has already passed. If there are existing cached entries, the background " @@ -3721,18 +3958,20 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2839 sssd-ldap.5.xml:406 sssd-ldap.5.xml:1834 -#: sssd-ipa.5.xml:255 +#: sssd.conf.5.xml:2964 sssd-ldap.5.xml:406 sssd-ldap.5.xml:1834 +#: sssd-ipa.5.xml:250 msgid "Default: 0 (disabled)" msgstr "Voreinstellung: 0 (deaktiviert)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2845 -msgid "cache_credentials (bool)" +#: sssd.conf.5.xml:2970 +#, fuzzy +#| msgid "cache_credentials (bool)" +msgid "cache_credentials (boolean)" msgstr "cache_credentials (Boolesch)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2848 +#: sssd.conf.5.xml:2973 msgid "" "Determines if user credentials are also cached in the local LDB cache. The " "cached credentials refer to passwords, which includes the first (long term) " @@ -3743,7 +3982,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2859 +#: sssd.conf.5.xml:2984 msgid "" "Take a note that while credentials are stored as a salted SHA512 hash, this " "still potentially poses some security risk in case an attacker manages to " @@ -3752,12 +3991,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2873 +#: sssd.conf.5.xml:2998 msgid "cache_credentials_minimal_first_factor_length (int)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2876 +#: sssd.conf.5.xml:3001 msgid "" "If 2-Factor-Authentication (2FA) is used and credentials should be saved " "this value determines the minimal length the first authentication factor " @@ -3769,19 +4008,19 @@ msgstr "" "gespeichert zu werden." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2883 +#: sssd.conf.5.xml:3008 msgid "" "This should avoid that the short PINs of a PIN based 2FA scheme are saved in " "the cache which would make them easy targets for brute-force attacks." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2894 +#: sssd.conf.5.xml:3019 msgid "account_cache_expiration (integer)" msgstr "account_cache_expiration (Ganzzahl)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2897 +#: sssd.conf.5.xml:3022 msgid "" "Number of days entries are left in cache after last successful login before " "being removed during a cleanup of the cache. 0 means keep forever. The " @@ -3794,17 +4033,17 @@ msgstr "" "Parameters muss größer oder gleich »offline_credentials_expiration« sein." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2904 +#: sssd.conf.5.xml:3029 msgid "Default: 0 (unlimited)" msgstr "Voreinstellung: 0 (unbegrenzt)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2909 +#: sssd.conf.5.xml:3034 msgid "pwd_expiration_warning (integer)" msgstr "pwd_expiration_warning (Ganzzahl)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2920 +#: sssd.conf.5.xml:3045 msgid "" "Please note that the backend server has to provide information about the " "expiration time of the password. If this information is missing, sssd " @@ -3817,17 +4056,17 @@ msgstr "" "Authentifizierungsanbieter konfiguriert werden." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2927 +#: sssd.conf.5.xml:3052 msgid "Default: 7 (Kerberos), 0 (LDAP)" msgstr "Voreinstellung: 7 (Kerberos), 0 (LDAP)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2933 +#: sssd.conf.5.xml:3058 msgid "id_provider (string)" msgstr "id_provider (Zeichenkette)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2936 +#: sssd.conf.5.xml:3061 msgid "" "The identification provider used for the domain. Supported ID providers are:" msgstr "" @@ -3835,12 +4074,12 @@ msgstr "" "werden unterstützt:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2940 +#: sssd.conf.5.xml:3065 msgid "<quote>proxy</quote>: Support a legacy NSS provider." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2943 +#: sssd.conf.5.xml:3068 msgid "" "<quote>ldap</quote>: LDAP provider. See <citerefentry> <refentrytitle>sssd-" "ldap</refentrytitle> <manvolnum>5</manvolnum> </citerefentry> for more " @@ -3851,8 +4090,8 @@ msgstr "" "<manvolnum>5</manvolnum> </citerefentry>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2951 sssd.conf.5.xml:3070 sssd.conf.5.xml:3129 -#: sssd.conf.5.xml:3192 +#: sssd.conf.5.xml:3076 sssd.conf.5.xml:3200 sssd.conf.5.xml:3259 +#: sssd.conf.5.xml:3322 #, fuzzy #| msgid "" #| "<quote>ipa</quote>: FreeIPA and Red Hat Enterprise Identity Management " @@ -3870,8 +4109,8 @@ msgstr "" "manvolnum> </citerefentry>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2960 sssd.conf.5.xml:3079 sssd.conf.5.xml:3138 -#: sssd.conf.5.xml:3201 +#: sssd.conf.5.xml:3085 sssd.conf.5.xml:3209 sssd.conf.5.xml:3268 +#: sssd.conf.5.xml:3331 msgid "" "<quote>ad</quote>: Active Directory provider. See <citerefentry> " "<refentrytitle>sssd-ad</refentrytitle> <manvolnum>5</manvolnum> </" @@ -3883,7 +4122,7 @@ msgstr "" "citerefentry>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2968 +#: sssd.conf.5.xml:3093 #, fuzzy #| msgid "" #| "<quote>ipa</quote>: FreeIPA and Red Hat Enterprise Identity Management " @@ -3900,13 +4139,22 @@ msgstr "" "<citerefentry> <refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</" "manvolnum> </citerefentry>." +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3101 +msgid "" +"Default: Not set (This is a mandatory setting that must be explicitly " +"defined for each configured domain)." +msgstr "" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2979 -msgid "use_fully_qualified_names (bool)" +#: sssd.conf.5.xml:3109 +#, fuzzy +#| msgid "use_fully_qualified_names (bool)" +msgid "use_fully_qualified_names (boolean)" msgstr "use_fully_qualified_names (Boolesch)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2982 +#: sssd.conf.5.xml:3112 msgid "" "Use the full name and domain (as formatted by the domain's full_name_format) " "as the user's login name reported to NSS." @@ -3916,7 +4164,7 @@ msgstr "" "Benutzers, der an NSS gemeldet wird." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2987 +#: sssd.conf.5.xml:3117 #, fuzzy #| msgid "" #| "If set to TRUE, all requests to this domain must use fully qualified " @@ -3936,7 +4184,7 @@ msgstr "" "test@LOCAL</command> würde ihn hingegen finden." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2995 +#: sssd.conf.5.xml:3125 msgid "" "NOTE: This option has no effect on netgroup lookups due to their tendency to " "include nested netgroups without qualified names. For netgroups, all domains " @@ -3948,24 +4196,26 @@ msgstr "" "nicht voll qualifizierter Name angefragt wird." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3002 +#: sssd.conf.5.xml:3132 msgid "" "Default: FALSE (TRUE for trusted domain/sub-domains or if " "default_domain_suffix is used)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3009 -msgid "ignore_group_members (bool)" +#: sssd.conf.5.xml:3139 +#, fuzzy +#| msgid "ignore_group_members (bool)" +msgid "ignore_group_members (boolean)" msgstr "ignore_group_members (Boolesch)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3012 +#: sssd.conf.5.xml:3142 msgid "Do not return group members for group lookups." msgstr "gibt beim Nachschlagen der Gruppe nicht die Gruppenmitglieder zurück." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3015 +#: sssd.conf.5.xml:3145 msgid "" "If set to TRUE, the group membership attribute is not requested from the " "ldap server, and group members are not returned when processing group lookup " @@ -3977,7 +4227,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3033 +#: sssd.conf.5.xml:3163 msgid "" "Enabling this option can also make access provider checks for group " "membership significantly faster, especially for groups containing many " @@ -3985,7 +4235,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3039 sssd.conf.5.xml:3767 sssd-ldap.5.xml:401 +#: sssd.conf.5.xml:3169 sssd.conf.5.xml:3951 sssd-ldap.5.xml:401 #: sssd-ldap.5.xml:454 sssd-ldap.5.xml:529 sssd-ldap.5.xml:576 #: sssd-ldap.5.xml:599 sssd-ldap.5.xml:638 sssd-ldap.5.xml:657 #: sssd-ldap.5.xml:681 sssd-ldap.5.xml:1114 sssd-ldap.5.xml:1147 @@ -3995,12 +4245,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3049 +#: sssd.conf.5.xml:3179 msgid "auth_provider (string)" msgstr "auth_provider (Zeichenkette)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3052 +#: sssd.conf.5.xml:3182 msgid "" "The authentication provider used for the domain. Supported auth providers " "are:" @@ -4009,7 +4259,7 @@ msgstr "" "Authentifizierungsanbieter werden unterstützt:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3056 sssd.conf.5.xml:3122 +#: sssd.conf.5.xml:3186 sssd.conf.5.xml:3252 msgid "" "<quote>ldap</quote> for native LDAP authentication. See <citerefentry> " "<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> </" @@ -4020,7 +4270,7 @@ msgstr "" "ldap</refentrytitle> <manvolnum>5</manvolnum> </citerefentry>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3063 +#: sssd.conf.5.xml:3193 msgid "" "<quote>krb5</quote> for Kerberos authentication. See <citerefentry> " "<refentrytitle>sssd-krb5</refentrytitle> <manvolnum>5</manvolnum> </" @@ -4031,7 +4281,7 @@ msgstr "" "sssd-krb5</refentrytitle> <manvolnum>5</manvolnum> </citerefentry>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3087 +#: sssd.conf.5.xml:3217 #, fuzzy #| msgid "" #| "<quote>ldap</quote> for native LDAP authentication. See <citerefentry> " @@ -4047,19 +4297,19 @@ msgstr "" "ldap</refentrytitle> <manvolnum>5</manvolnum> </citerefentry>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3095 +#: sssd.conf.5.xml:3225 msgid "" "<quote>proxy</quote> for relaying authentication to some other PAM target." msgstr "" "»proxy« zur Weitergabe der Authentifizierung an irgendein anderes PAM-Ziel" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3098 +#: sssd.conf.5.xml:3228 msgid "<quote>none</quote> disables authentication explicitly." msgstr "»none« deaktiviert explizit die Authentifizierung." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3101 +#: sssd.conf.5.xml:3231 msgid "" "Default: <quote>id_provider</quote> is used if it is set and can handle " "authentication requests." @@ -4068,12 +4318,12 @@ msgstr "" "mit Authentifizierungsanfragen umgehen." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3107 +#: sssd.conf.5.xml:3237 msgid "access_provider (string)" msgstr "access_provider (Zeichenkette)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3110 +#: sssd.conf.5.xml:3240 msgid "" "The access control provider used for the domain. There are two built-in " "access providers (in addition to any included in installed backends) " @@ -4084,19 +4334,19 @@ msgstr "" "Backends enthalten sind). Interne Spezialanbieter sind:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3116 +#: sssd.conf.5.xml:3246 #, fuzzy #| msgid "<quote>deny</quote> always deny access." msgid "<quote>permit</quote> always allow access." msgstr "»deny« verweigert dem Zugriff immer." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3119 +#: sssd.conf.5.xml:3249 msgid "<quote>deny</quote> always deny access." msgstr "»deny« verweigert dem Zugriff immer." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3146 +#: sssd.conf.5.xml:3276 msgid "" "<quote>simple</quote> access control based on access or deny lists. See " "<citerefentry> <refentrytitle>sssd-simple</refentrytitle> <manvolnum>5</" @@ -4109,7 +4359,7 @@ msgstr "" "simple</refentrytitle> <manvolnum>5</manvolnum></citerefentry>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3153 +#: sssd.conf.5.xml:3283 msgid "" "<quote>krb5</quote>: .k5login based access control. See <citerefentry> " "<refentrytitle>sssd-krb5</refentrytitle> <manvolnum>5</manvolnum></" @@ -4117,22 +4367,22 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3160 +#: sssd.conf.5.xml:3290 msgid "<quote>proxy</quote> for relaying access control to another PAM module." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3163 +#: sssd.conf.5.xml:3293 msgid "Default: <quote>permit</quote>" msgstr "Voreinstellung: »permit«" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3168 +#: sssd.conf.5.xml:3298 msgid "chpass_provider (string)" msgstr "chpass_provider (Zeichenkette)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3171 +#: sssd.conf.5.xml:3301 msgid "" "The provider which should handle change password operations for the domain. " "Supported change password providers are:" @@ -4141,7 +4391,7 @@ msgstr "" "Folgende Anbieter von Passwortänderungen werden unterstützt:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3176 +#: sssd.conf.5.xml:3306 msgid "" "<quote>ldap</quote> to change a password stored in a LDAP server. See " "<citerefentry> <refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</" @@ -4149,7 +4399,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3184 +#: sssd.conf.5.xml:3314 msgid "" "<quote>krb5</quote> to change the Kerberos password. See <citerefentry> " "<refentrytitle>sssd-krb5</refentrytitle> <manvolnum>5</manvolnum> </" @@ -4160,19 +4410,19 @@ msgstr "" "sssd-krb5</refentrytitle> <manvolnum>5</manvolnum> </citerefentry>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3209 +#: sssd.conf.5.xml:3339 msgid "" "<quote>proxy</quote> for relaying password changes to some other PAM target." msgstr "" "»proxy« zur Weitergabe der Passwortänderung an irgendein anderes PAM-Ziel" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3213 +#: sssd.conf.5.xml:3343 msgid "<quote>none</quote> disallows password changes explicitly." msgstr "»none« verbietet explizit Passwortänderungen." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3216 +#: sssd.conf.5.xml:3346 msgid "" "Default: <quote>auth_provider</quote> is used if it is set and can handle " "change password requests." @@ -4181,19 +4431,19 @@ msgstr "" "kann mit Passwortänderungsanfragen umgehen." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3223 +#: sssd.conf.5.xml:3353 msgid "sudo_provider (string)" msgstr "sudo_provider (Zeichenkette)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3226 +#: sssd.conf.5.xml:3356 msgid "The SUDO provider used for the domain. Supported SUDO providers are:" msgstr "" "der für diese Domain benutzte Sudo-Anbieter. Folgende Sudo-Anbieter werden " "unterstützt:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3230 +#: sssd.conf.5.xml:3360 msgid "" "<quote>ldap</quote> for rules stored in LDAP. See <citerefentry> " "<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> </" @@ -4204,7 +4454,7 @@ msgstr "" "ldap</refentrytitle> <manvolnum>5</manvolnum> </citerefentry>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3238 +#: sssd.conf.5.xml:3368 msgid "" "<quote>ipa</quote> the same as <quote>ldap</quote> but with IPA default " "settings." @@ -4213,7 +4463,7 @@ msgstr "" "Vorgabeeinstellungen für IPA." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3242 +#: sssd.conf.5.xml:3372 msgid "" "<quote>ad</quote> the same as <quote>ldap</quote> but with AD default " "settings." @@ -4222,12 +4472,12 @@ msgstr "" "Vorgabeeinstellungen für AD." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3246 +#: sssd.conf.5.xml:3376 msgid "<quote>none</quote> disables SUDO explicitly." msgstr "»none« deaktiviert explizit Sudo." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3249 +#: sssd.conf.5.xml:3379 #, fuzzy #| msgid "" #| "Default: <quote>id_provider</quote> is used if it is set and can handle " @@ -4240,7 +4490,7 @@ msgstr "" "kann SELinux-Ladeanfragen handhaben." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3253 +#: sssd.conf.5.xml:3383 msgid "" "The detailed instructions for configuration of sudo_provider are in the " "manual page <citerefentry> <refentrytitle>sssd-sudo</refentrytitle> " @@ -4257,7 +4507,7 @@ msgstr "" "<manvolnum>5</manvolnum> </citerefentry>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3268 +#: sssd.conf.5.xml:3398 msgid "" "<emphasis>NOTE:</emphasis> Sudo rules are periodically downloaded in the " "background unless the sudo provider is explicitly disabled. Set " @@ -4266,12 +4516,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3278 +#: sssd.conf.5.xml:3408 msgid "selinux_provider (string)" msgstr "selinux_provider (Zeichenkette)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3281 +#: sssd.conf.5.xml:3411 msgid "" "The provider which should handle loading of selinux settings. Note that this " "provider will be called right after access provider ends. Supported selinux " @@ -4282,7 +4532,7 @@ msgstr "" "Zugriffsanbieter beendet hat. Folgende SELinux-Anbieter werden unterstützt:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3287 +#: sssd.conf.5.xml:3417 msgid "" "<quote>ipa</quote> to load selinux settings from an IPA server. See " "<citerefentry> <refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</" @@ -4294,26 +4544,31 @@ msgstr "" "manvolnum> </citerefentry>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3295 +#: sssd.conf.5.xml:3425 msgid "<quote>none</quote> disallows fetching selinux settings explicitly." msgstr "»none« verbietet explizit das Abholen von SELinux-Einstellungen." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3298 +#: sssd.conf.5.xml:3428 +#, fuzzy +#| msgid "" +#| "Default: <quote>id_provider</quote> is used if it is set and can handle " +#| "selinux loading requests." msgid "" -"Default: <quote>id_provider</quote> is used if it is set and can handle " -"selinux loading requests." +"Default: the value of <quote>id_provider</quote> is used if it is set and " +"can handle selinux loading requests. Otherwise the result is the same as if " +"the selinux_provider is set to none." msgstr "" "Voreinstellung: Falls gesetzt, wird der Wert von »id_provider« benutzt. Er " "kann SELinux-Ladeanfragen handhaben." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3304 +#: sssd.conf.5.xml:3435 msgid "subdomains_provider (string)" msgstr "subdomains_provider (Zeichenkette)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3307 +#: sssd.conf.5.xml:3438 msgid "" "The provider which should handle fetching of subdomains. This value should " "be always the same as id_provider. Supported subdomain providers are:" @@ -4323,7 +4578,7 @@ msgstr "" "werden unterstützt:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3313 +#: sssd.conf.5.xml:3444 msgid "" "<quote>ipa</quote> to load a list of subdomains from an IPA server. See " "<citerefentry> <refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</" @@ -4335,7 +4590,7 @@ msgstr "" "citerefentry>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3322 +#: sssd.conf.5.xml:3453 msgid "" "<quote>ad</quote> to load a list of subdomains from an Active Directory " "server. See <citerefentry> <refentrytitle>sssd-ad</refentrytitle> " @@ -4344,12 +4599,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3331 +#: sssd.conf.5.xml:3462 msgid "<quote>none</quote> disallows fetching subdomains explicitly." msgstr "»none« deaktiviert explizit das Abholen von Subdomains." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3335 +#: sssd.conf.5.xml:3466 #, fuzzy #| msgid "" #| "Default: <quote>id_provider</quote> is used if it is set and can handle " @@ -4362,12 +4617,12 @@ msgstr "" "kann SELinux-Ladeanfragen handhaben." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3341 +#: sssd.conf.5.xml:3472 msgid "session_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3344 +#: sssd.conf.5.xml:3475 msgid "" "The provider which configures and manages user session related tasks. The " "only user session task currently provided is the integration with Fleet " @@ -4375,30 +4630,30 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3351 +#: sssd.conf.5.xml:3482 msgid "<quote>ipa</quote> to allow performing user session related tasks." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3355 +#: sssd.conf.5.xml:3486 msgid "" "<quote>none</quote> does not perform any kind of user session related tasks." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3359 +#: sssd.conf.5.xml:3490 #, fuzzy #| msgid "Default: <quote>permit</quote>" msgid "Default: <quote>none</quote>." msgstr "Voreinstellung: »permit«" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3365 +#: sssd.conf.5.xml:3496 msgid "autofs_provider (string)" msgstr "autofs_provider (Zeichenkette)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3368 +#: sssd.conf.5.xml:3499 msgid "" "The autofs provider used for the domain. Supported autofs providers are:" msgstr "" @@ -4406,7 +4661,7 @@ msgstr "" "autofs« werden unterstützt:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3372 +#: sssd.conf.5.xml:3503 msgid "" "<quote>ldap</quote> to load maps stored in LDAP. See <citerefentry> " "<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> </" @@ -4418,7 +4673,7 @@ msgstr "" "citerefentry>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3379 +#: sssd.conf.5.xml:3510 msgid "" "<quote>ipa</quote> to load maps stored in an IPA server. See <citerefentry> " "<refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</manvolnum> </" @@ -4430,7 +4685,7 @@ msgstr "" "citerefentry>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3387 +#: sssd.conf.5.xml:3518 msgid "" "<quote>ad</quote> to load maps stored in an AD server. See <citerefentry> " "<refentrytitle>sssd-ad</refentrytitle> <manvolnum>5</manvolnum> </" @@ -4438,12 +4693,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3396 +#: sssd.conf.5.xml:3527 msgid "<quote>none</quote> disables autofs explicitly." msgstr "»none« deaktiviert explizit »autofs«." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3399 +#: sssd.conf.5.xml:3530 #, fuzzy #| msgid "" #| "Default: <quote>id_provider</quote> is used if it is set and can handle " @@ -4456,12 +4711,12 @@ msgstr "" "mit Authentifizierungsanfragen umgehen." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3406 +#: sssd.conf.5.xml:3537 msgid "hostid_provider (string)" msgstr "hostid_provider (Zeichenkette)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3409 +#: sssd.conf.5.xml:3540 msgid "" "The provider used for retrieving host identity information. Supported " "hostid providers are:" @@ -4470,7 +4725,7 @@ msgstr "" "wird. Folgende Anbieter von »hostid« werden unterstützt:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3413 +#: sssd.conf.5.xml:3544 msgid "" "<quote>ipa</quote> to load host identity stored in an IPA server. See " "<citerefentry> <refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</" @@ -4482,12 +4737,12 @@ msgstr "" "manvolnum> </citerefentry>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3421 +#: sssd.conf.5.xml:3552 msgid "<quote>none</quote> disables hostid explicitly." msgstr "»none« deaktiviert explizit »hostid«." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3424 +#: sssd.conf.5.xml:3555 #, fuzzy #| msgid "" #| "Default: <quote>id_provider</quote> is used if it is set and can handle " @@ -4500,26 +4755,26 @@ msgstr "" "mit Authentifizierungsanfragen umgehen." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3431 +#: sssd.conf.5.xml:3562 msgid "resolver_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3434 +#: sssd.conf.5.xml:3565 msgid "" "The provider which should handle hosts and networks lookups. Supported " "resolver providers are:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3438 +#: sssd.conf.5.xml:3569 msgid "" "<quote>proxy</quote> to forward lookups to another NSS library. See " "<quote>proxy_resolver_lib_name</quote>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3442 +#: sssd.conf.5.xml:3573 msgid "" "<quote>ldap</quote> to fetch hosts and networks stored in LDAP. See " "<citerefentry> <refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</" @@ -4527,7 +4782,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3449 +#: sssd.conf.5.xml:3580 msgid "" "<quote>ad</quote> to fetch hosts and networks stored in AD. See " "<citerefentry> <refentrytitle>sssd-ad</refentrytitle> <manvolnum>5</" @@ -4536,12 +4791,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3457 +#: sssd.conf.5.xml:3588 msgid "<quote>none</quote> disallows fetching hosts and networks explicitly." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3460 +#: sssd.conf.5.xml:3591 #, fuzzy #| msgid "" #| "Default: <quote>id_provider</quote> is used if it is set and can handle " @@ -4554,7 +4809,7 @@ msgstr "" "mit Authentifizierungsanfragen umgehen." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3470 +#: sssd.conf.5.xml:3601 msgid "" "Regular expression for this domain that describes how to parse the string " "containing user name and domain into these components. The \"domain\" can " @@ -4569,7 +4824,7 @@ msgstr "" "(NetBIOS-) Namen der Domain entsprechen." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3479 +#: sssd.conf.5.xml:3610 #, fuzzy #| msgid "" #| "Default for the AD and IPA provider: <quote>(((?P<domain>[^\\\\]+)\\" @@ -4585,17 +4840,17 @@ msgstr "" "(?P<Name>[^@\\\\]+)$))« " #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:3484 sssd.conf.5.xml:3498 +#: sssd.conf.5.xml:3615 sssd.conf.5.xml:3629 msgid "username" msgstr "Benutzername" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:3487 sssd.conf.5.xml:3501 +#: sssd.conf.5.xml:3618 sssd.conf.5.xml:3632 msgid "username@domain.name" msgstr "Benutzername@Domain.Name" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3492 +#: sssd.conf.5.xml:3623 #, fuzzy #| msgid "" #| "Default for the AD and IPA provider: <quote>(((?P<domain>[^\\\\]+)\\" @@ -4613,12 +4868,12 @@ msgstr "" "(?P<Name>[^@\\\\]+)$))« " #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:3504 +#: sssd.conf.5.xml:3635 msgid "domain\\username" msgstr "Domain\\Benutzername" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3507 +#: sssd.conf.5.xml:3638 msgid "" "While the first two correspond to the general default the third one is " "introduced to allow easy integration of users from Windows domains." @@ -4628,7 +4883,7 @@ msgstr "" "Windows-Domains zu ermöglichen." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3512 +#: sssd.conf.5.xml:3643 msgid "" "The default re_expression uses the <quote>@</quote> character as a separator " "between the name and the domain. As a result of this setting the default " @@ -4638,17 +4893,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3564 +#: sssd.conf.5.xml:3695 msgid "Default: <quote>%1$s@%2$s</quote>." msgstr "Voreinstellung: »%1$s@%2$s«" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3570 +#: sssd.conf.5.xml:3701 msgid "lookup_family_order (string)" msgstr "lookup_family_order (Zeichenkette)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3573 +#: sssd.conf.5.xml:3704 msgid "" "Provides the ability to select preferred address family to use when " "performing DNS lookups." @@ -4656,80 +4911,99 @@ msgstr "" "ermöglicht es, die bei DNS-Abfragen zu bevorzugende Adressfamilie zu wählen." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3577 +#: sssd.conf.5.xml:3708 msgid "Supported values:" msgstr "unterstützte Werte:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3580 +#: sssd.conf.5.xml:3711 msgid "ipv4_first: Try looking up IPv4 address, if that fails, try IPv6" msgstr "" "ipv4_first: versucht die IPv4- und, falls dies fehlschlägt, die IPv6-Adresse " "nachzuschlagen" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3583 +#: sssd.conf.5.xml:3714 msgid "ipv4_only: Only attempt to resolve hostnames to IPv4 addresses." msgstr "ipv4_only: versucht, nur Rechnernamen zu IPv4-Adressen aufzulösen" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3586 +#: sssd.conf.5.xml:3717 msgid "ipv6_first: Try looking up IPv6 address, if that fails, try IPv4" msgstr "" "ipv6_first: versucht die IPv6- und, falls dies fehlschlägt, die IPv4-Adresse " "nachzuschlagen" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3589 +#: sssd.conf.5.xml:3720 msgid "ipv6_only: Only attempt to resolve hostnames to IPv6 addresses." msgstr "ipv6_only: versucht, nur Rechnernamen zu IPv6-Adressen aufzulösen" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3592 +#: sssd.conf.5.xml:3723 msgid "Default: ipv4_first" msgstr "Voreinstellung: ipv4_first" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3598 +#: sssd.conf.5.xml:3729 #, fuzzy #| msgid "dns_resolver_timeout (integer)" msgid "dns_resolver_server_timeout (integer)" msgstr "dns_resolver_timeout (Ganzzahl)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3601 +#: sssd.conf.5.xml:3732 msgid "" -"Defines the amount of time (in milliseconds) SSSD would try to talk to DNS " -"server before trying next DNS server." +"Defines the timeout duration (in milliseconds) SSSD waits for a DNS server " +"to respond before moving to the next one." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3606 +#: sssd.conf.5.xml:3737 msgid "" "The AD provider will use this option for the CLDAP ping timeouts as well." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3610 sssd.conf.5.xml:3630 sssd.conf.5.xml:3651 -msgid "" -"Please see the section <quote>FAILOVER</quote> for more information about " -"the service resolution." +#: sssd.conf.5.xml:3741 sssd.conf.5.xml:3777 sssd.conf.5.xml:3814 +#, fuzzy +#| msgid "" +#| "Specifies the timeout (in seconds) after which the <citerefentry> " +#| "<refentrytitle>poll</refentrytitle> <manvolnum>2</manvolnum> </" +#| "citerefentry>/<citerefentry> <refentrytitle>select</refentrytitle> " +#| "<manvolnum>2</manvolnum> </citerefentry> following a <citerefentry> " +#| "<refentrytitle>connect</refentrytitle> <manvolnum>2</manvolnum> </" +#| "citerefentry> returns in case of no activity." +msgid "" +"Please see the section <quote>FAILOVER</quote> in <citerefentry> " +"<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> </" +"citerefentry>, <citerefentry> <refentrytitle>sssd-krb5</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry>, <citerefentry> <refentrytitle>sssd-" +"ipa</refentrytitle> <manvolnum>5</manvolnum> </citerefentry> or " +"<citerefentry> <refentrytitle>sssd-ad</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry> for more information about the service resolution." msgstr "" +"gibt den Zeitpunkt der Zeitüberschreitung (in Sekunden) an, nach dem " +"<citerefentry> <refentrytitle>poll</refentrytitle> <manvolnum>2</manvolnum> " +"</citerefentry>/<citerefentry> <refentrytitle>select</refentrytitle> " +"<manvolnum>2</manvolnum> </citerefentry> gefolgt von einem <citerefentry> " +"<refentrytitle>connect</refentrytitle> <manvolnum>2</manvolnum> </" +"citerefentry> zurückkehrt, falls keine Aktivität stattfindet." #. type: Content of: <refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3615 sssd-ldap.5.xml:700 include/failover.xml:84 +#: sssd.conf.5.xml:3762 sssd-ldap.5.xml:700 include/failover.xml:84 msgid "Default: 1000" msgstr "Voreinstellung: 1000" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3621 +#: sssd.conf.5.xml:3768 #, fuzzy #| msgid "dns_resolver_timeout (integer)" msgid "dns_resolver_op_timeout (integer)" msgstr "dns_resolver_timeout (Ganzzahl)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3624 +#: sssd.conf.5.xml:3771 msgid "" "Defines the amount of time (in seconds) to wait to resolve single DNS query " "(e.g. resolution of a hostname or an SRV record) before trying the next " @@ -4737,17 +5011,17 @@ msgid "" msgstr "" #. type: Content of: <refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3635 include/failover.xml:100 +#: sssd.conf.5.xml:3798 include/failover.xml:100 msgid "Default: 3" msgstr "Voreinstellung: 3" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3641 +#: sssd.conf.5.xml:3804 msgid "dns_resolver_timeout (integer)" msgstr "dns_resolver_timeout (Ganzzahl)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3644 +#: sssd.conf.5.xml:3807 msgid "" "Defines the amount of time (in seconds) to wait for a reply from the " "internal fail over service before assuming that the service is unreachable. " @@ -4756,14 +5030,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3662 +#: sssd.conf.5.xml:3841 #, fuzzy #| msgid "dns_resolver_timeout (integer)" -msgid "dns_resolver_use_search_list (bool)" +msgid "dns_resolver_use_search_list (boolean)" msgstr "dns_resolver_timeout (Ganzzahl)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3665 +#: sssd.conf.5.xml:3844 msgid "" "Normally, the DNS resolver searches the domain list defined in the " "\"search\" directive from the resolv.conf file. This can lead to delays in " @@ -4771,7 +5045,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3671 +#: sssd.conf.5.xml:3850 msgid "" "If fully qualified domain names (or _srv_) are used in the SSSD " "configuration, setting this option to FALSE can prevent unnecessary DNS " @@ -4779,17 +5053,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3677 +#: sssd.conf.5.xml:3856 msgid "Default: TRUE" msgstr "Voreinstellung: TRUE" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3683 +#: sssd.conf.5.xml:3862 msgid "dns_discovery_domain (string)" msgstr "dns_discovery_domain (Zeichenkette)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3686 +#: sssd.conf.5.xml:3865 msgid "" "If service discovery is used in the back end, specifies the domain part of " "the service discovery DNS query." @@ -4798,19 +5072,19 @@ msgstr "" "DNS-Dienstabfrage an." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3690 +#: sssd.conf.5.xml:3869 msgid "Default: Use the domain part of machine's hostname" msgstr "Voreinstellung: Der Domain-Teil des Rechnernamens wird benutzt." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3696 +#: sssd.conf.5.xml:3875 #, fuzzy #| msgid "pam_id_timeout (integer)" msgid "failover_primary_timeout (integer)" msgstr "pam_id_timeout (Ganzzahl)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3699 +#: sssd.conf.5.xml:3878 msgid "" "When no primary server is available, SSSD fails over to a backup server. " "This option defines the number of seconds SSSD waits before attempting to " @@ -4818,59 +5092,74 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3706 +#: sssd.conf.5.xml:3885 msgid "Note: The minimum value is 31." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3709 +#: sssd.conf.5.xml:3888 #, fuzzy #| msgid "Default: 3" msgid "Default: 31" msgstr "Voreinstellung: 3" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3715 +#: sssd.conf.5.xml:3894 msgid "override_gid (integer)" msgstr "override_gid (Ganzzahl)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3718 -msgid "Override the primary GID value with the one specified." +#: sssd.conf.5.xml:3897 +#, fuzzy +#| msgid "Override the primary GID value with the one specified." +msgid "" +"Override the primary GID value for all users in the domain with specified " +"value." msgstr "überschreibt die Haupt-GID mit der angegebenen." +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3901 +#, fuzzy +#| msgid "Default: not set (SSSD will use the value retrieved from LDAP)" +msgid "" +"Default: not set (Use the primary GID value retrieved from the identity " +"provider)" +msgstr "" +"Voreinstellung: nicht gesetzt (SSSD wird den von LDAP erhaltenen Wert " +"benutzen)" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3724 +#: sssd.conf.5.xml:3908 msgid "case_sensitive (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3731 +#: sssd.conf.5.xml:3915 msgid "True" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3734 +#: sssd.conf.5.xml:3918 msgid "Case sensitive. This value is invalid for AD provider." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3740 +#: sssd.conf.5.xml:3924 msgid "False" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3742 +#: sssd.conf.5.xml:3926 msgid "Case insensitive." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3746 +#: sssd.conf.5.xml:3930 msgid "Preserving" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3749 +#: sssd.conf.5.xml:3933 msgid "" "Same as False (case insensitive), but does not lowercase names in the result " "of NSS operations. Note that name aliases (and in case of services also " @@ -4878,14 +5167,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3757 +#: sssd.conf.5.xml:3941 msgid "" "If you want to set this value for trusted domain with IPA provider, you need " "to set it on both the client and SSSD on the server." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3727 +#: sssd.conf.5.xml:3911 #, fuzzy #| msgid "" #| "The following expansions are supported: <placeholder " @@ -4898,17 +5187,47 @@ msgstr "" "type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3772 +#: sssd.conf.5.xml:3956 msgid "Default: True (False for AD provider)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3778 +#: sssd.conf.5.xml:3962 +#, fuzzy +#| msgid "ad_enable_dns_sites (boolean)" +msgid "avoid_by_id_lookups (boolean)" +msgstr "ad_enable_dns_sites (Boolesch)" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3965 +msgid "" +"If this option is set to 'true' SSSD will try to avoid sending lookups by ID " +"to the backend and will switch to a lookup by name if a cached object with a " +"matching ID can be found." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3971 +msgid "" +"This option can e.g. be used in cases where searches by ID are expensive on " +"the server side because of missing indexes or are not even possible, e.g. " +"due to non-reversible POSIX id-mapping." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3978 +#, fuzzy +#| msgid "Default: false (AD provider: true)" +msgid "Default: False (True for IdP provider)" +msgstr "Voreinstellung: falsch (AD-Anbieter: wahr)" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:3984 msgid "subdomain_inherit (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3781 +#: sssd.conf.5.xml:3987 msgid "" "Specifies a list of configuration parameters that should be inherited by a " "subdomain. Please note that only selected parameters can be inherited. " @@ -4916,107 +5235,107 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3787 +#: sssd.conf.5.xml:3993 #, fuzzy #| msgid "ldap_search_timeout (integer)" msgid "ldap_search_timeout" msgstr "ldap_search_timeout (Ganzzahl)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3790 +#: sssd.conf.5.xml:3996 #, fuzzy #| msgid "ldap_network_timeout (integer)" msgid "ldap_network_timeout" msgstr "ldap_network_timeout (Ganzzahl)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3793 +#: sssd.conf.5.xml:3999 #, fuzzy #| msgid "ldap_opt_timeout (integer)" msgid "ldap_opt_timeout" msgstr "ldap_opt_timeout (Ganzzahl)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3796 +#: sssd.conf.5.xml:4002 #, fuzzy #| msgid "ldap_connection_expire_timeout (integer)" msgid "ldap_offline_timeout" msgstr "ldap_connection_expire_timeout (Ganzzahl)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3799 +#: sssd.conf.5.xml:4005 msgid "ldap_purge_cache_timeout" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3802 +#: sssd.conf.5.xml:4008 #, fuzzy #| msgid "ldap_purge_cache_timeout (integer)" msgid "ldap_purge_cache_offset" msgstr "ldap_purge_cache_timeout (Ganzzahl)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3805 +#: sssd.conf.5.xml:4011 msgid "" "ldap_krb5_keytab (the value of krb5_keytab will be used if ldap_krb5_keytab " "is not set explicitly)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3809 +#: sssd.conf.5.xml:4015 #, fuzzy #| msgid "ldap_krb5_ticket_lifetime (integer)" msgid "ldap_krb5_ticket_lifetime" msgstr "ldap_krb5_ticket_lifetime (Ganzzahl)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3812 +#: sssd.conf.5.xml:4018 #, fuzzy #| msgid "ldap_connection_expire_timeout (integer)" msgid "ldap_connection_expire_timeout" msgstr "ldap_connection_expire_timeout (Ganzzahl)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3815 +#: sssd.conf.5.xml:4021 #, fuzzy #| msgid "ldap_connection_expire_timeout (integer)" msgid "ldap_connection_expire_offset" msgstr "ldap_connection_expire_timeout (Ganzzahl)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3818 +#: sssd.conf.5.xml:4024 #, fuzzy #| msgid "ldap_connection_expire_timeout (integer)" msgid "ldap_connection_idle_timeout" msgstr "ldap_connection_expire_timeout (Ganzzahl)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3821 sssd-ldap.5.xml:446 +#: sssd.conf.5.xml:4027 sssd-ldap.5.xml:446 msgid "ldap_use_tokengroups" msgstr "ldap_use_tokengroups" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3824 +#: sssd.conf.5.xml:4030 msgid "ldap_user_principal" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3827 +#: sssd.conf.5.xml:4033 msgid "ignore_group_members" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3830 +#: sssd.conf.5.xml:4036 msgid "auto_private_groups" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3833 +#: sssd.conf.5.xml:4039 msgid "case_sensitive" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:3838 +#: sssd.conf.5.xml:4044 #, no-wrap msgid "" "subdomain_inherit = ldap_purge_cache_timeout\n" @@ -5024,27 +5343,27 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3845 +#: sssd.conf.5.xml:4051 msgid "Note: This option only works with the IPA and AD provider." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3852 +#: sssd.conf.5.xml:4058 msgid "subdomain_homedir (string)" msgstr "subdomain_homedir (Zeichenkette)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3863 +#: sssd.conf.5.xml:4069 msgid "%F" msgstr "%F" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3864 +#: sssd.conf.5.xml:4070 msgid "flat (NetBIOS) name of a subdomain." msgstr "flacher (NetBIOS-) Name einer Subdomain" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3855 +#: sssd.conf.5.xml:4061 msgid "" "Use this homedir as default value for all subdomains within this domain in " "IPA AD trust. See <emphasis>override_homedir</emphasis> for info about " @@ -5059,7 +5378,7 @@ msgstr "" "verwendet werden. <placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3869 +#: sssd.conf.5.xml:4075 msgid "" "The value can be overridden by <emphasis>override_homedir</emphasis> option." msgstr "" @@ -5067,17 +5386,17 @@ msgstr "" "überschrieben werden." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3873 +#: sssd.conf.5.xml:4079 msgid "Default: <filename>/home/%d/%u</filename>" msgstr "Voreinstellung: <filename>/home/%d/%u</filename>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3878 +#: sssd.conf.5.xml:4084 msgid "realmd_tags (string)" msgstr "realmd_tags (Zeichenkette)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3881 +#: sssd.conf.5.xml:4087 msgid "" "Various tags stored by the realmd configuration service for this domain." msgstr "" @@ -5085,33 +5404,33 @@ msgstr "" "Kennzeichnungen." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3887 +#: sssd.conf.5.xml:4093 msgid "cached_auth_timeout (int)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3890 +#: sssd.conf.5.xml:4096 msgid "" -"Specifies time in seconds since last successful online authentication for " -"which user will be authenticated using cached credentials while SSSD is in " -"the online mode. If the credentials are incorrect, SSSD falls back to online " -"authentication." +"Specifies the number of seconds since the last successful online " +"authentication during which SSSD will authenticate users via cached " +"credentials, even while online. If the cached authentication fails, SSSD " +"immediately falls back to online authentication." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3898 +#: sssd.conf.5.xml:4103 msgid "" "This option's value is inherited by all trusted domains. At the moment it is " "not possible to set a different value per trusted domain." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3903 +#: sssd.conf.5.xml:4108 msgid "Special value 0 implies that this feature is disabled." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3907 +#: sssd.conf.5.xml:4112 msgid "" "Please note that if <quote>cached_auth_timeout</quote> is longer than " "<quote>pam_id_timeout</quote> then the back end could be called to handle " @@ -5119,14 +5438,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3918 +#: sssd.conf.5.xml:4123 #, fuzzy #| msgid "ldap_pwd_policy (string)" msgid "local_auth_policy (string)" msgstr "ldap_pwd_policy (Zeichenkette)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3921 +#: sssd.conf.5.xml:4126 msgid "" "Local authentication methods policy. Some backends (i.e. LDAP, proxy " "provider) only support a password based authentication, while others can " @@ -5138,7 +5457,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3933 +#: sssd.conf.5.xml:4138 msgid "" "There are three possible values for this option: match, only, enable. " "<quote>match</quote> is used to match offline and online states for Kerberos " @@ -5150,7 +5469,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3946 +#: sssd.conf.5.xml:4151 msgid "" "The following table shows which authentication methods, if configured " "properly, are currently enabled or disabled for each backend, with the " @@ -5158,44 +5477,49 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> -#: sssd.conf.5.xml:3959 +#: sssd.conf.5.xml:4164 #, fuzzy #| msgid "ldap_pwd_policy (string)" msgid "local_auth_policy = match (default)" msgstr "ldap_pwd_policy (Zeichenkette)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> -#: sssd.conf.5.xml:3960 +#: sssd.conf.5.xml:4165 msgid "Passkey" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> -#: sssd.conf.5.xml:3961 +#: sssd.conf.5.xml:4166 msgid "Smartcard" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:3964 sssd-ldap.5.xml:228 +#: sssd.conf.5.xml:4169 sssd-ldap.5.xml:228 msgid "IPA" msgstr "IPA" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry><para> +#: sssd.conf.5.xml:4169 sssd.conf.5.xml:4170 sssd.conf.5.xml:4173 +msgid "enabled" +msgstr "" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:3967 sssd-ldap.5.xml:233 +#: sssd.conf.5.xml:4172 sssd-ldap.5.xml:233 msgid "AD" msgstr "AD" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry><para> -#: sssd.conf.5.xml:3967 sssd.conf.5.xml:3970 sssd.conf.5.xml:3971 +#: sssd.conf.5.xml:4172 sssd.conf.5.xml:4175 sssd.conf.5.xml:4176 msgid "disabled" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry> -#: sssd.conf.5.xml:3970 +#: sssd.conf.5.xml:4175 msgid "LDAP" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3975 +#: sssd.conf.5.xml:4180 msgid "" "Please note that if local Smartcard authentication is enabled and a " "Smartcard is present, Smartcard authentication will be preferred over the " @@ -5204,7 +5528,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:3987 +#: sssd.conf.5.xml:4192 #, no-wrap msgid "" "[domain/shadowutils]\n" @@ -5215,7 +5539,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3983 +#: sssd.conf.5.xml:4188 msgid "" "The following configuration example allows local users to authenticate " "locally using any enabled method (i.e. smartcard, passkey). <placeholder " @@ -5223,31 +5547,31 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3995 +#: sssd.conf.5.xml:4200 #, fuzzy #| msgid "Default: cn" msgid "Default: match" msgstr "Voreinstellung: cn" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4000 +#: sssd.conf.5.xml:4205 msgid "auto_private_groups (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4006 +#: sssd.conf.5.xml:4211 msgid "true" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4009 +#: sssd.conf.5.xml:4214 msgid "" "Create user's private group unconditionally from user's UID number. The GID " "number is ignored in this case." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4013 +#: sssd.conf.5.xml:4218 msgid "" "NOTE: Because the GID number and the user private group are inferred from " "the UID number, it is not supported to have multiple entries with the same " @@ -5256,24 +5580,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4022 +#: sssd.conf.5.xml:4227 msgid "false" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4025 +#: sssd.conf.5.xml:4230 msgid "" "Always use the user's primary GID number. The GID number must refer to a " "group object in the LDAP database." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4031 +#: sssd.conf.5.xml:4236 msgid "hybrid" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4034 +#: sssd.conf.5.xml:4239 msgid "" "A primary group is autogenerated for user entries whose UID and GID numbers " "have the same value and at the same time the GID number does not correspond " @@ -5283,14 +5607,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4047 +#: sssd.conf.5.xml:4252 msgid "" "If the UID and GID of a user are different, then the GID must correspond to " "a group entry, otherwise the GID is simply not resolvable." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4054 +#: sssd.conf.5.xml:4259 msgid "" "This feature is useful for environments that wish to stop maintaining a " "separate group objects for the user private groups, but also wish to retain " @@ -5298,14 +5622,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4003 +#: sssd.conf.5.xml:4208 msgid "" "This option takes any of three available values: <placeholder " "type=\"variablelist\" id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4066 +#: sssd.conf.5.xml:4271 msgid "" "For the LDAP based id providers (LDAP, IPA and AD) the default for the " "configured domain is typically False because the sources have the concept of " @@ -5315,14 +5639,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4075 +#: sssd.conf.5.xml:4280 msgid "" "For subdomains, the default value is False for subdomains that use assigned " "POSIX IDs and True for subdomains that use automatic ID-mapping." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:4083 +#: sssd.conf.5.xml:4288 #, no-wrap msgid "" "[domain/forest.domain/sub.domain]\n" @@ -5330,7 +5654,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:4089 +#: sssd.conf.5.xml:4294 #, no-wrap msgid "" "[domain/forest.domain]\n" @@ -5339,7 +5663,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4080 +#: sssd.conf.5.xml:4285 msgid "" "The value of auto_private_groups can either be set per subdomains in a " "subsection, for example: <placeholder type=\"programlisting\" id=\"0\"/> or " @@ -5348,7 +5672,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:2503 +#: sssd.conf.5.xml:2549 msgid "" "These configuration options can be present in a domain configuration " "section, that is, in a section called <quote>[domain/<replaceable>NAME</" @@ -5360,17 +5684,17 @@ msgstr "" "type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4104 +#: sssd.conf.5.xml:4309 msgid "proxy_pam_target (string)" msgstr "proxy_pam_target (Zeichenkette)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4107 +#: sssd.conf.5.xml:4312 msgid "The proxy target PAM proxies to." msgstr "das Proxy-Ziel, an das PAM weiterleitet" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4110 +#: sssd.conf.5.xml:4315 #, fuzzy #| msgid "" #| "Default: not set by default, you have to take an existing pam " @@ -5385,12 +5709,12 @@ msgstr "" "hinzufügen." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4120 +#: sssd.conf.5.xml:4325 msgid "proxy_lib_name (string)" msgstr "proxy_lib_name (Zeichenkette)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4123 +#: sssd.conf.5.xml:4328 msgid "" "The name of the NSS library to use in proxy domains. The NSS functions " "searched for in the library are in the form of _nss_$(libName)_$(function), " @@ -5401,12 +5725,12 @@ msgstr "" "(libName)_$(function)«, zum Beispiel »_nss_files_getpwent«." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4133 +#: sssd.conf.5.xml:4338 msgid "proxy_resolver_lib_name (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4136 +#: sssd.conf.5.xml:4341 msgid "" "The name of the NSS library to use for hosts and networks lookups in proxy " "domains. The NSS functions searched for in the library are in the form of " @@ -5414,12 +5738,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4147 +#: sssd.conf.5.xml:4352 msgid "proxy_fast_alias (boolean)" msgstr "proxy_fast_alias (Boolesch)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4150 +#: sssd.conf.5.xml:4355 msgid "" "When a user or group is looked up by name in the proxy provider, a second " "lookup by ID is performed to \"canonicalize\" the name in case the requested " @@ -5433,12 +5757,12 @@ msgstr "" "veranlassen, die ID im Zwischenspeicher nachzuschlagen." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4164 +#: sssd.conf.5.xml:4369 msgid "proxy_max_children (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4167 +#: sssd.conf.5.xml:4372 msgid "" "This option specifies the number of pre-forked proxy children. It is useful " "for high-load SSSD environments where sssd may run out of available child " @@ -5446,7 +5770,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4100 +#: sssd.conf.5.xml:4305 msgid "" "Options valid for proxy domains. <placeholder type=\"variablelist\" " "id=\"0\"/>" @@ -5455,12 +5779,12 @@ msgstr "" "id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:4183 +#: sssd.conf.5.xml:4388 msgid "Application domains" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:4185 +#: sssd.conf.5.xml:4390 msgid "" "SSSD, with its D-Bus interface (see <citerefentry> <refentrytitle>sssd-ifp</" "refentrytitle> <manvolnum>5</manvolnum> </citerefentry>) is appealing to " @@ -5477,7 +5801,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:4205 +#: sssd.conf.5.xml:4410 msgid "" "Please note that the application domain must still be explicitly enabled in " "the <quote>domains</quote> parameter so that the lookup order between the " @@ -5485,17 +5809,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><title> -#: sssd.conf.5.xml:4211 +#: sssd.conf.5.xml:4416 msgid "Application domain parameters" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4213 +#: sssd.conf.5.xml:4418 msgid "inherit_from (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4216 +#: sssd.conf.5.xml:4421 msgid "" "The SSSD POSIX-type domain the application domain inherits all settings " "from. The application domain can moreover add its own settings to the " @@ -5504,7 +5828,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:4230 +#: sssd.conf.5.xml:4435 msgid "" "The following example illustrates the use of an application domain. In this " "setup, the POSIX domain is connected to an LDAP server and is used by the OS " @@ -5514,7 +5838,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><programlisting> -#: sssd.conf.5.xml:4238 +#: sssd.conf.5.xml:4443 #, no-wrap msgid "" "[sssd]\n" @@ -5534,12 +5858,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:4258 +#: sssd.conf.5.xml:4463 msgid "TRUSTED DOMAIN SECTION" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4260 +#: sssd.conf.5.xml:4465 msgid "" "Some options used in the domain section can also be used in the trusted " "domain section, that is, in a section called <quote>[domain/" @@ -5550,69 +5874,79 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4267 +#: sssd.conf.5.xml:4472 msgid "ldap_search_base," msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4268 +#: sssd.conf.5.xml:4473 msgid "ldap_user_search_base," msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4269 +#: sssd.conf.5.xml:4474 msgid "ldap_group_search_base," msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4270 +#: sssd.conf.5.xml:4475 msgid "ldap_netgroup_search_base," msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4271 +#: sssd.conf.5.xml:4476 msgid "ldap_service_search_base," msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4272 +#: sssd.conf.5.xml:4477 msgid "ldap_sasl_mech," msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4273 +#: sssd.conf.5.xml:4478 msgid "ad_server," msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4274 +#: sssd.conf.5.xml:4479 msgid "ad_backup_server," msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4275 +#: sssd.conf.5.xml:4480 msgid "ad_site," msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:4276 sssd-ipa.5.xml:934 +#: sssd.conf.5.xml:4481 sssd-ipa.5.xml:929 msgid "use_fully_qualified_names" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4280 +#: sssd.conf.5.xml:4482 +msgid "pam_gssapi_services" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:4483 +msgid "pam_gssapi_check_upn" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:4485 msgid "" "For more details about these options see their individual description in the " "manual page." msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:4286 +#: sssd.conf.5.xml:4491 msgid "CERTIFICATE MAPPING SECTION" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4288 +#: sssd.conf.5.xml:4493 msgid "" "To allow authentication with Smartcards and certificates SSSD must be able " "to map certificates to users. This can be done by adding the full " @@ -5625,7 +5959,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4302 +#: sssd.conf.5.xml:4507 msgid "" "To make the mapping more flexible mapping and matching rules were added to " "SSSD (see <citerefentry> <refentrytitle>sss-certmap</refentrytitle> " @@ -5633,7 +5967,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4311 +#: sssd.conf.5.xml:4516 msgid "" "A mapping and matching rule can be added to the SSSD configuration in a " "section on its own with a name like <quote>[certmap/" @@ -5642,55 +5976,50 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4318 +#: sssd.conf.5.xml:4523 msgid "matchrule (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4321 +#: sssd.conf.5.xml:4526 msgid "" "Only certificates from the Smartcard which matches this rule will be " "processed, all others are ignored." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4325 +#: sssd.conf.5.xml:4530 msgid "" "Default: KRB5:<EKU>clientAuth, i.e. only certificates which have the " "Extended Key Usage <quote>clientAuth</quote>" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4332 +#: sssd.conf.5.xml:4537 msgid "maprule (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4335 +#: sssd.conf.5.xml:4540 msgid "Defines how the user is found for a given certificate." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:4341 +#: sssd.conf.5.xml:4546 msgid "" "LDAP:(userCertificate;binary={cert!bin}) for LDAP based providers like " "<quote>ldap</quote>, <quote>AD</quote> or <quote>ipa</quote>." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:4347 +#: sssd.conf.5.xml:4552 msgid "" "If maprule is not set and provider is <quote>proxy</quote>, the RULE_NAME " "name is assumed to be the name of the matching user." msgstr "" -#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4357 -msgid "domains (string)" -msgstr "" - #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4360 +#: sssd.conf.5.xml:4565 msgid "" "Comma separated list of domain names the rule should be applied. By default " "a rule is only valid in the domain configured in sssd.conf. If the provider " @@ -5699,17 +6028,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4367 +#: sssd.conf.5.xml:4572 msgid "Default: the configured domain in sssd.conf" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4372 +#: sssd.conf.5.xml:4577 msgid "priority (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4375 +#: sssd.conf.5.xml:4580 msgid "" "Unsigned integer value defining the priority of the rule. The higher the " "number the lower the priority. <quote>0</quote> stands for the highest " @@ -5717,17 +6046,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4381 +#: sssd.conf.5.xml:4586 msgid "Default: the lowest priority" msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:4389 +#: sssd.conf.5.xml:4594 msgid "PROMPTING CONFIGURATION SECTION" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4391 +#: sssd.conf.5.xml:4596 msgid "" "If a special file (<filename>/var/lib/sss/pubconf/pam_preauth_available</" "filename>) exists SSSD's PAM module pam_sss will ask SSSD to figure out " @@ -5737,7 +6066,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4399 +#: sssd.conf.5.xml:4604 msgid "" "With the growing number of authentication methods and the possibility that " "there are multiple ones for a single user the heuristic used by pam_sss to " @@ -5746,59 +6075,59 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4411 +#: sssd.conf.5.xml:4616 msgid "[prompting/password]" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4414 +#: sssd.conf.5.xml:4619 msgid "password_prompt" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4415 +#: sssd.conf.5.xml:4620 msgid "to change the string of the password prompt" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4413 +#: sssd.conf.5.xml:4618 msgid "" "to configure password prompting, allowed options are: <placeholder " "type=\"variablelist\" id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4423 +#: sssd.conf.5.xml:4628 msgid "[prompting/2fa]" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4427 +#: sssd.conf.5.xml:4632 msgid "first_prompt" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4428 +#: sssd.conf.5.xml:4633 msgid "to change the string of the prompt for the first factor" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4431 +#: sssd.conf.5.xml:4636 msgid "second_prompt" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4432 +#: sssd.conf.5.xml:4637 msgid "to change the string of the prompt for the second factor" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4435 +#: sssd.conf.5.xml:4640 msgid "single_prompt" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4436 +#: sssd.conf.5.xml:4641 msgid "" "boolean value, if True there will be only a single prompt using the value of " "first_prompt where it is expected that both factors are entered as a single " @@ -5807,7 +6136,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4425 +#: sssd.conf.5.xml:4630 msgid "" "to configure two-factor authentication prompting, allowed options are: " "<placeholder type=\"variablelist\" id=\"0\"/> If the second factor is " @@ -5816,7 +6145,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4449 +#: sssd.conf.5.xml:4654 msgid "" "Some clients, such as SSH with 'PasswordAuthentication yes', generate their " "own prompts and do not use prompts provided by SSSD or other PAM modules. " @@ -5827,17 +6156,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4464 +#: sssd.conf.5.xml:4669 msgid "[prompting/passkey]" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:4470 sssd-ad.5.xml:1022 +#: sssd.conf.5.xml:4675 sssd.conf.5.xml:4719 sssd-ad.5.xml:1027 msgid "interactive" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4472 +#: sssd.conf.5.xml:4677 msgid "" "boolean value, if True prompt a message and wait before testing the presence " "of a passkey device. Recommended if your device doesn’t have a tactile " @@ -5845,61 +6174,151 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4480 +#: sssd.conf.5.xml:4685 sssd.conf.5.xml:4735 msgid "interactive_prompt" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4482 +#: sssd.conf.5.xml:4687 sssd.conf.5.xml:4737 msgid "to change the message of the interactive prompt." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4487 +#: sssd.conf.5.xml:4692 msgid "touch" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4489 +#: sssd.conf.5.xml:4694 +msgid "" +"boolean value, if True prompt a message to remind the user to touch the " +"device." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4700 +msgid "touch_prompt" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4702 +msgid "to change the message of the touch prompt." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4671 +#, fuzzy +#| msgid "" +#| "The following expansions are supported: <placeholder " +#| "type=\"variablelist\" id=\"0\"/>" +msgid "" +"to configure passkey authentication prompting, allowed options are: " +"<placeholder type=\"variablelist\" id=\"0\"/>" +msgstr "" +"Die folgenden Erweiterungen werden unterstützt: <placeholder " +"type=\"variablelist\" id=\"0\"/>" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4713 +msgid "[prompting/oauth2]" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4721 +msgid "" +"boolean value, if True prompt a message after asking the user to " +"authenticate, and wait before requesting the access token." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4725 +msgid "" +"If False, make sure to set the <quote>idp_request_timeout</quote> " +"sufficiently high, to give the user time to authenticate." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4715 +#, fuzzy +#| msgid "" +#| "The following expansions are supported: <placeholder " +#| "type=\"variablelist\" id=\"0\"/>" +msgid "" +"to configure OAuth2 authentication prompting, allowed options are: " +"<placeholder type=\"variablelist\" id=\"0\"/>" +msgstr "" +"Die folgenden Erweiterungen werden unterstützt: <placeholder " +"type=\"variablelist\" id=\"0\"/>" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4748 +msgid "[prompting/cert_auth]" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4754 +msgid "pin_prompt" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4756 +msgid "" +"to change the message which asks the user to enter the PIN at the computer " +"keyboard. At the end of the message the token name is printed." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4764 +msgid "keypad_prompt" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4766 msgid "" -"boolean value, if True prompt a message to remind the user to touch the " -"device." +"to change the message which asks the user to enter the PIN at keypad of the " +"Smartcard reader. At the end of the message the token name is printed." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4495 -msgid "touch_prompt" -msgstr "" +#: sssd.conf.5.xml:4774 +#, fuzzy +#| msgid "username" +msgid "user_name_hint" +msgstr "Benutzername" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4497 -msgid "to change the message of the touch prompt." +#: sssd.conf.5.xml:4776 +msgid "" +"boolean value, if True ask for a user name if no name was given before and " +"the found certificate can be mapped to more than one user." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4466 +#: sssd.conf.5.xml:4750 #, fuzzy #| msgid "" #| "The following expansions are supported: <placeholder " #| "type=\"variablelist\" id=\"0\"/>" msgid "" -"to configure passkey authentication prompting, allowed options are: " +"to configure Smartcard authentication prompting, allowed options are: " "<placeholder type=\"variablelist\" id=\"0\"/>" msgstr "" "Die folgenden Erweiterungen werden unterstützt: <placeholder " "type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4406 +#: sssd.conf.5.xml:4611 msgid "" "Each supported authentication method has its own configuration subsection " "under <quote>[prompting/...]</quote>. Currently there are: <placeholder " "type=\"variablelist\" id=\"0\"/> <placeholder type=\"variablelist\" id=\"1\"/" -"> <placeholder type=\"variablelist\" id=\"2\"/>" +"> <placeholder type=\"variablelist\" id=\"2\"/> <placeholder " +"type=\"variablelist\" id=\"3\"/> <placeholder type=\"variablelist\" id=\"4\"/" +">" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4508 +#: sssd.conf.5.xml:4792 msgid "" "It is possible to add a subsection for specific PAM services, e.g. " "<quote>[prompting/password/sshd]</quote> to individual change the prompting " @@ -5907,12 +6326,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:4515 pam_sss_gss.8.xml:157 idmap_sss.8.xml:43 +#: sssd.conf.5.xml:4799 pam_sss_gss.8.xml:157 idmap_sss.8.xml:43 msgid "EXAMPLES" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd.conf.5.xml:4521 +#: sssd.conf.5.xml:4805 #, fuzzy, no-wrap #| msgid "" #| "[sssd]\n" @@ -5990,7 +6409,7 @@ msgstr "" "enumerate = False\n" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4517 +#: sssd.conf.5.xml:4801 msgid "" "1. The following example shows a typical SSSD config. It does not describe " "configuration of the domains themselves - refer to documentation on " @@ -5999,7 +6418,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd.conf.5.xml:4553 +#: sssd.conf.5.xml:4837 #, no-wrap msgid "" "[domain/ipa.com/child.ad.com]\n" @@ -6007,7 +6426,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4547 +#: sssd.conf.5.xml:4831 msgid "" "2. The following example shows configuration of IPA AD trust where the AD " "forest consists of two domains in a parent-child structure. Suppose IPA " @@ -6018,7 +6437,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd.conf.5.xml:4564 +#: sssd.conf.5.xml:4848 #, no-wrap msgid "" "[certmap/my.domain/rule_name]\n" @@ -6029,7 +6448,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4558 +#: sssd.conf.5.xml:4842 msgid "" "3. The following example shows the configuration of a certificate mapping " "rule. It is valid for the configured domain <quote>my.domain</quote> and " @@ -6272,16 +6691,24 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:151 +#, fuzzy +#| msgid "" +#| "Default: If not set, the value of the defaultNamingContext or " +#| "namingContexts attribute from the RootDSE of the LDAP server is used. If " +#| "defaultNamingContext does not exist or has an empty value namingContexts " +#| "is used. The namingContexts attribute must have a single value with the " +#| "DN of the search base of the LDAP server to make this work. Multiple " +#| "values are are not supported." msgid "" "Default: If not set, the value of the defaultNamingContext or namingContexts " "attribute from the RootDSE of the LDAP server is used. If " "defaultNamingContext does not exist or has an empty value namingContexts is " "used. The namingContexts attribute must have a single value with the DN of " "the search base of the LDAP server to make this work. Multiple values are " -"are not supported." +"not supported." msgstr "" -"Voreinstellung: Falls nicht gesetzt, wird der Wert der Attribute »" -"defaultNamingContext« oder »namingContexts« vom RootDSE des LDAP-Servers " +"Voreinstellung: Falls nicht gesetzt, wird der Wert der Attribute " +"»defaultNamingContext« oder »namingContexts« vom RootDSE des LDAP-Servers " "benutzt. Falls »defaultNamingContext« nicht existiert oder ihr Wert leer " "ist, wird »namingContexts« verwendet. Das Attribut »namingContexts« muss " "einen einzelnen Wert mit dem Domain-Namen der Suchgrundlage des LDAP-Servers " @@ -6629,8 +7056,8 @@ msgstr "" "Rechnerobjekte" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap.5.xml:472 sssd-ipa.5.xml:506 sssd-ipa.5.xml:525 sssd-ipa.5.xml:544 -#: sssd-ipa.5.xml:563 +#: sssd-ldap.5.xml:472 sssd-ipa.5.xml:501 sssd-ipa.5.xml:520 sssd-ipa.5.xml:539 +#: sssd-ipa.5.xml:558 msgid "" "See <quote>ldap_search_base</quote> for information about configuring " "multiple search bases." @@ -6639,7 +7066,7 @@ msgstr "" "unter »ldap_search_base«." #. type: Content of: <listitem><para> -#: sssd-ldap.5.xml:477 sssd-ipa.5.xml:511 include/ldap_search_bases.xml:27 +#: sssd-ldap.5.xml:477 sssd-ipa.5.xml:506 include/ldap_search_bases.xml:27 msgid "Default: the value of <emphasis>ldap_search_base</emphasis>" msgstr "Voreinstellung: der Wert von <emphasis>ldap_search_base</emphasis>" @@ -6793,7 +7220,7 @@ msgid "" "closed early to ensure that a new query cannot require the connection to " "remain open past its expiration. This implies that connections will always " "be closed immediately and will never be reused if " -"<emphasis>ldap_connection_expire_timeout <= ldap_opt_timout</emphasis>" +"<emphasis>ldap_connection_expire_timeout <= ldap_opt_timeout</emphasis>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> @@ -7031,8 +7458,10 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:831 -msgid "ldap_ignore_unreadable_references (bool)" -msgstr "" +#, fuzzy +#| msgid "ldap_force_upper_case_realm (boolean)" +msgid "ldap_ignore_unreadable_references (boolean)" +msgstr "ldap_force_upper_case_realm (Boolesch)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:834 @@ -7416,7 +7845,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap.5.xml:1152 sssd-ad.5.xml:1267 +#: sssd-ldap.5.xml:1152 sssd-ad.5.xml:1260 msgid "Default: 86400 (24 hours)" msgstr "Voreinstellung: 86400 (24 Stunden)" @@ -7468,7 +7897,7 @@ msgstr "" "migrieren." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ldap.5.xml:1187 sssd-ipa.5.xml:575 sssd-krb5.5.xml:103 +#: sssd-ldap.5.xml:1187 sssd-ipa.5.xml:570 sssd-krb5.5.xml:103 msgid "krb5_realm (string)" msgstr "krb5_realm (Zeichenkette)" @@ -7673,7 +8102,9 @@ msgstr "Voreinstellung: nicht gesetzt, d.h. Dienstsuche ist deaktiviert" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1339 -msgid "ldap_chpass_update_last_change (bool)" +#, fuzzy +#| msgid "ldap_chpass_update_last_change (bool)" +msgid "ldap_chpass_update_last_change (boolean)" msgstr "ldap_chpass_update_last_change (Boolesch)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> @@ -7862,7 +8293,7 @@ msgid "ldap_access_order (string)" msgstr "ldap_access_order (Zeichenkette)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap.5.xml:1470 sssd-ipa.5.xml:405 +#: sssd-ldap.5.xml:1470 sssd-ipa.5.xml:400 msgid "Comma separated list of access control options. Allowed values are:" msgstr "" "durch Kommata getrennte Liste von Zugriffssteuerungsoptionen. Folgende Werte " @@ -7909,7 +8340,7 @@ msgid "<emphasis>expire</emphasis>: use ldap_account_expire_policy" msgstr "<emphasis>expire</emphasis>: verwendet »ldap_account_expire_policy«." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap.5.xml:1515 sssd-ipa.5.xml:413 +#: sssd-ldap.5.xml:1515 sssd-ipa.5.xml:408 msgid "" "<emphasis>pwd_expire_policy_reject, pwd_expire_policy_warn, " "pwd_expire_policy_renew: </emphasis> These options are useful if users are " @@ -7919,24 +8350,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap.5.xml:1525 sssd-ipa.5.xml:423 +#: sssd-ldap.5.xml:1525 sssd-ipa.5.xml:418 msgid "" "The difference between these options is the action taken if user password is " "expired:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ldap.5.xml:1530 sssd-ipa.5.xml:428 +#: sssd-ldap.5.xml:1530 sssd-ipa.5.xml:423 msgid "pwd_expire_policy_reject - user is denied to log in," msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ldap.5.xml:1536 sssd-ipa.5.xml:434 +#: sssd-ldap.5.xml:1536 sssd-ipa.5.xml:429 msgid "pwd_expire_policy_warn - user is still able to log in," msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ldap.5.xml:1542 sssd-ipa.5.xml:440 +#: sssd-ldap.5.xml:1542 sssd-ipa.5.xml:435 msgid "" "pwd_expire_policy_renew - user is prompted to change their password " "immediately." @@ -8541,8 +8972,8 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd-ldap.5.xml:2032 sssd-simple.5.xml:169 sssd-ipa.5.xml:984 -#: sssd-ad.5.xml:1470 sssd-idp.5.xml:248 sssd-krb5.5.xml:483 +#: sssd-ldap.5.xml:2032 sssd-simple.5.xml:169 sssd-ipa.5.xml:979 +#: sssd-ad.5.xml:1463 sssd-idp.5.xml:343 sssd-krb5.5.xml:483 #: sss_rpcidmapd.5.xml:98 sssd-session-recording.5.xml:176 msgid "EXAMPLE" msgstr "BEISPIEL" @@ -8573,7 +9004,7 @@ msgstr "" #. type: Content of: <refsect1><refsect2><para> #: sssd-ldap.5.xml:2039 sssd-ldap.5.xml:2057 sssd-simple.5.xml:177 -#: sssd-ipa.5.xml:992 sssd-ad.5.xml:1478 sssd-sudo.5.xml:56 sssd-krb5.5.xml:492 +#: sssd-ipa.5.xml:987 sssd-ad.5.xml:1471 sssd-sudo.5.xml:56 sssd-krb5.5.xml:492 #: sssd-session-recording.5.xml:182 include/ldap_id_mapping.xml:105 msgid "<placeholder type=\"programlisting\" id=\"0\"/>" msgstr "<placeholder type=\"programlisting\" id=\"0\"/>" @@ -8608,7 +9039,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><title> #: sssd-ldap.5.xml:2073 sssd_krb5_locator_plugin.8.xml:83 sssd-simple.5.xml:189 -#: sssd-ad.5.xml:1493 sssd.8.xml:270 sss_seed.8.xml:163 +#: sssd-ad.5.xml:1486 sssd.8.xml:270 sss_seed.8.xml:163 msgid "NOTES" msgstr "ANMERKUNGEN" @@ -9157,7 +9588,7 @@ msgstr "" #: pam_sss.8.xml:434 msgid "" "No authentication method was found by Kerberos. This might happen if the " -"user has a Smartcard assigned but the pkint plugin is not available on the " +"user has a Smartcard assigned but the pkinit plugin is not available on the " "client." msgstr "" @@ -9614,6 +10045,23 @@ msgid "" "first DNS resolving failure." msgstr "" +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_locator_plugin.8.xml:106 +msgid "" +"If the environment variable SSSD_KRB5_LOCATOR_KDC_ADDRESS is set to a KDC " +"address the plugin will use this address instead of reading the kdcinfo " +"file. The address format is the same as in the kdcinfo file (see above)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_locator_plugin.8.xml:112 +msgid "" +"If the environment variable SSSD_KRB5_LOCATOR_KPASSWD_ADDRESS is set to a " +"kpasswd server address the plugin will use this address instead of reading " +"the kpasswdinfo file. The address format is the same as in the kpasswdinfo " +"file (see above)." +msgstr "" + #. type: Content of: <reference><refentry><refnamediv><refname> #: sssd-simple.5.xml:10 sssd-simple.5.xml:16 msgid "sssd-simple" @@ -11101,7 +11549,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:129 sssd-ad.5.xml:1161 +#: sssd-ipa.5.xml:129 sssd-ad.5.xml:1166 msgid "dyndns_update (boolean)" msgstr "dyndns_update (Boolesch)" @@ -11115,23 +11563,13 @@ msgid "" "quote> option." msgstr "" -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:141 sssd-ad.5.xml:1175 -msgid "" -"NOTE: On older systems (such as RHEL 5), for this behavior to work reliably, " -"the default Kerberos realm must be set properly in /etc/krb5.conf" -msgstr "" -"HINWEIS: Auf älteren Systemen (wie RHEL 5) muss der Standard-Kerberos-Realm " -"ordentlich in /etc/krb5.conf gesetzt sein, damit dies zuverlässig " -"funktioniert." - #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:152 sssd-ad.5.xml:1186 +#: sssd-ipa.5.xml:147 sssd-ad.5.xml:1186 msgid "dyndns_ttl (integer)" msgstr "dyndns_ttl (Ganzzahl)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:155 sssd-ad.5.xml:1189 +#: sssd-ipa.5.xml:150 sssd-ad.5.xml:1189 msgid "" "The TTL to apply to the client DNS record when updating it. If " "dyndns_update is false this has no effect. This will override the TTL " @@ -11143,17 +11581,17 @@ msgstr "" "Administrator gesetzt wurde." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:160 +#: sssd-ipa.5.xml:155 msgid "Default: 1200 (seconds)" msgstr "Voreinstellung: 1200 (Sekunden)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:166 sssd-ad.5.xml:1200 +#: sssd-ipa.5.xml:161 sssd-ad.5.xml:1200 msgid "dyndns_iface (string)" msgstr "dyndns_iface (Zeichenkette)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:169 sssd-ad.5.xml:1203 +#: sssd-ipa.5.xml:164 sssd-ad.5.xml:1203 msgid "" "Optional. Applicable only when dyndns_update is true. Choose the interface " "or a list of interfaces whose IP addresses should be used for dynamic DNS " @@ -11165,26 +11603,26 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:182 +#: sssd-ipa.5.xml:177 msgid "" "Default: Use the IP addresses of the interface which is used for IPA LDAP " "connection" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:186 sssd-ad.5.xml:1226 +#: sssd-ipa.5.xml:181 sssd-ad.5.xml:1220 msgid "Example: dyndns_iface = em[12], !vnet1, vnet*" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:192 sssd-ad.5.xml:1232 +#: sssd-ipa.5.xml:187 sssd-ad.5.xml:1226 #, fuzzy #| msgid "dyndns_iface (string)" msgid "dyndns_address (string)" msgstr "dyndns_iface (Zeichenkette)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:195 sssd-ad.5.xml:1235 +#: sssd-ipa.5.xml:190 sssd-ad.5.xml:1229 msgid "" "Optional. Applicable only when <emphasis>dyndns_update</emphasis> is true. " "A list of IP addresses or IP networks to be used for dynamic DNS updates. " @@ -11195,22 +11633,22 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:206 sssd-ad.5.xml:1246 +#: sssd-ipa.5.xml:201 sssd-ad.5.xml:1240 msgid "Default: No filtering of IP addresses." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:209 sssd-ad.5.xml:1249 +#: sssd-ipa.5.xml:204 sssd-ad.5.xml:1243 msgid "Example: dyndns_address = 10.0.0.0/16, !10.0.1.0/24" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:215 sssd-ad.5.xml:1305 +#: sssd-ipa.5.xml:210 sssd-ad.5.xml:1298 msgid "dyndns_auth (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:218 sssd-ad.5.xml:1308 +#: sssd-ipa.5.xml:213 sssd-ad.5.xml:1301 msgid "" "Whether the nsupdate utility should use GSS-TSIG authentication for secure " "updates with the DNS server, insecure updates can be sent by setting this " @@ -11218,19 +11656,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:224 sssd-ad.5.xml:1314 +#: sssd-ipa.5.xml:219 sssd-ad.5.xml:1307 msgid "Default: GSS-TSIG" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:230 sssd-ad.5.xml:1320 +#: sssd-ipa.5.xml:225 sssd-ad.5.xml:1313 #, fuzzy #| msgid "dyndns_iface (string)" msgid "dyndns_auth_ptr (string)" msgstr "dyndns_iface (Zeichenkette)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:233 sssd-ad.5.xml:1323 +#: sssd-ipa.5.xml:228 sssd-ad.5.xml:1316 msgid "" "Whether the nsupdate utility should use GSS-TSIG authentication for secure " "PTR updates with the DNS server, insecure updates can be sent by setting " @@ -11238,17 +11676,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:239 sssd-ad.5.xml:1329 +#: sssd-ipa.5.xml:234 sssd-ad.5.xml:1322 msgid "Default: Same as dyndns_auth" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:245 sssd-ad.5.xml:1255 +#: sssd-ipa.5.xml:240 sssd-ad.5.xml:1249 msgid "dyndns_refresh_interval (integer)" msgstr "dyndns_refresh_interval (Ganzzahl)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:248 +#: sssd-ipa.5.xml:243 msgid "" "How often should the back end perform periodic DNS update in addition to the " "automatic update performed when the back end goes online. This option is " @@ -11259,12 +11697,14 @@ msgstr "" "Diese Option ist optional und nur anwendbar, wenn »dyndns_update« »true« ist." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:261 sssd-ad.5.xml:1273 -msgid "dyndns_update_ptr (bool)" +#: sssd-ipa.5.xml:256 sssd-ad.5.xml:1266 +#, fuzzy +#| msgid "dyndns_update_ptr (bool)" +msgid "dyndns_update_ptr (boolean)" msgstr "dyndns_update_ptr (Boolesch)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:264 sssd-ad.5.xml:1276 +#: sssd-ipa.5.xml:259 sssd-ad.5.xml:1269 msgid "" "Whether the PTR record should also be explicitly updated when updating the " "client's DNS records. Applicable only when dyndns_update is true." @@ -11274,7 +11714,7 @@ msgstr "" "dyndns_update« »true« ist" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:269 +#: sssd-ipa.5.xml:264 msgid "" "This option should be False in most IPA deployments as the IPA server " "generates the PTR records automatically when forward records are changed." @@ -11284,24 +11724,26 @@ msgstr "" "Weiterleitungsdatensätze ändern." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:275 sssd-ad.5.xml:1281 +#: sssd-ipa.5.xml:270 sssd-ad.5.xml:1274 msgid "" "Note that <emphasis>dyndns_update_per_family</emphasis> parameter does not " "apply for PTR record updates. Those updates are always sent separately." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:280 +#: sssd-ipa.5.xml:275 msgid "Default: False (disabled)" msgstr "Voreinstellung: False (deaktiviert)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:286 sssd-ad.5.xml:1292 -msgid "dyndns_force_tcp (bool)" +#: sssd-ipa.5.xml:281 sssd-ad.5.xml:1285 +#, fuzzy +#| msgid "dyndns_force_tcp (bool)" +msgid "dyndns_force_tcp (boolean)" msgstr "dyndns_force_tcp (Boolesch)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:289 sssd-ad.5.xml:1295 +#: sssd-ipa.5.xml:284 sssd-ad.5.xml:1288 msgid "" "Whether the nsupdate utility should default to using TCP for communicating " "with the DNS server." @@ -11310,31 +11752,31 @@ msgstr "" "DNS-Server verwenden soll" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:293 sssd-ad.5.xml:1299 +#: sssd-ipa.5.xml:288 sssd-ad.5.xml:1292 msgid "Default: False (let nsupdate choose the protocol)" msgstr "Voreinstellung: False (lässt Nsupdate das Protokoll auswählen)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:299 sssd-ad.5.xml:1335 +#: sssd-ipa.5.xml:294 sssd-ad.5.xml:1328 msgid "dyndns_server (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:302 sssd-ad.5.xml:1338 +#: sssd-ipa.5.xml:297 sssd-ad.5.xml:1331 msgid "" "The DNS server to use when performing a DNS update. In most setups, it's " "recommended to leave this option unset." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:307 sssd-ad.5.xml:1343 +#: sssd-ipa.5.xml:302 sssd-ad.5.xml:1336 msgid "" "Setting this option makes sense for environments where the DNS server is " "different from the identity server or when we use encrypted DNS." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:312 sssd-ad.5.xml:1348 +#: sssd-ipa.5.xml:307 sssd-ad.5.xml:1341 msgid "" "The parameter can be a simple string containing DNS name or IP address. It " "can also be an URI. The URI can look like <emphasis>dns://servername/</" @@ -11342,7 +11784,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:319 sssd-ad.5.xml:1355 +#: sssd-ipa.5.xml:314 sssd-ad.5.xml:1348 msgid "" "The second example enables DNS-over-TLS protocol for DNS updates. The " "nsupdate utility must support DoT - check the <emphasis>man nsupdate</" @@ -11350,7 +11792,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:325 sssd-ad.5.xml:1361 +#: sssd-ipa.5.xml:320 sssd-ad.5.xml:1354 msgid "" "Please note that this option will be only used in fallback attempt when " "previous attempt using autodetected settings failed or when DNS-over-TLS is " @@ -11358,17 +11800,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:331 sssd-ad.5.xml:1367 +#: sssd-ipa.5.xml:326 sssd-ad.5.xml:1360 msgid "Default: None (let nsupdate choose the server)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:337 sssd-ad.5.xml:1373 +#: sssd-ipa.5.xml:332 sssd-ad.5.xml:1366 msgid "dyndns_update_per_family (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:340 sssd-ad.5.xml:1376 +#: sssd-ipa.5.xml:335 sssd-ad.5.xml:1369 msgid "" "DNS update is by default performed in two steps - IPv4 update and then IPv6 " "update. In some cases it might be desirable to perform IPv4 and IPv6 update " @@ -11376,14 +11818,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:352 sssd-ad.5.xml:1388 +#: sssd-ipa.5.xml:347 sssd-ad.5.xml:1381 #, fuzzy #| msgid "dyndns_iface (string)" msgid "dyndns_dot_cacert (string)" msgstr "dyndns_iface (Zeichenkette)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:355 sssd-ad.5.xml:1391 +#: sssd-ipa.5.xml:350 sssd-ad.5.xml:1384 msgid "" "This option specifies the file of the certificate authorities certificates " "(in PEM format) in order to verify the remote server TLS certificate when " @@ -11391,19 +11833,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:361 sssd-ad.5.xml:1397 +#: sssd-ipa.5.xml:356 sssd-ad.5.xml:1390 msgid "Default: None (use global certificate store)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:367 sssd-ad.5.xml:1403 +#: sssd-ipa.5.xml:362 sssd-ad.5.xml:1396 #, fuzzy #| msgid "dyndns_iface (string)" msgid "dyndns_dot_cert (string)" msgstr "dyndns_iface (Zeichenkette)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:370 sssd-ad.5.xml:1406 +#: sssd-ipa.5.xml:365 sssd-ad.5.xml:1399 msgid "" "This option sets the certificate(s) file for authentication for the DoT " "transport to the remote server. The certificate chain file is expected to be " @@ -11411,14 +11853,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:376 sssd-ad.5.xml:1412 +#: sssd-ipa.5.xml:371 sssd-ad.5.xml:1405 msgid "" "The <emphasis>dyndns_dot_cert</emphasis> and <emphasis>dyndns_dot_key</" "emphasis> options must be both set to achieve mutual TLS authentication." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:381 sssd-ipa.5.xml:396 sssd-ad.5.xml:1417 sssd-ad.5.xml:1432 +#: sssd-ipa.5.xml:376 sssd-ipa.5.xml:391 sssd-ad.5.xml:1410 sssd-ad.5.xml:1425 #, fuzzy #| msgid "Default: not set (no substitution for unset home directories)" msgid "Default: None (Do not use TLS authentication)" @@ -11427,14 +11869,14 @@ msgstr "" "Verzeichnisse)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:387 sssd-ad.5.xml:1423 +#: sssd-ipa.5.xml:382 sssd-ad.5.xml:1416 #, fuzzy #| msgid "dyndns_iface (string)" msgid "dyndns_dot_key (string)" msgstr "dyndns_iface (Zeichenkette)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:390 sssd-ad.5.xml:1426 +#: sssd-ipa.5.xml:385 sssd-ad.5.xml:1419 msgid "" "This option sets the key file for authenticated encryption for the DoT " "transport to the remote server. The private key file is expected to be in " @@ -11442,142 +11884,142 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:402 +#: sssd-ipa.5.xml:397 #, fuzzy #| msgid "ldap_access_order (string)" msgid "ipa_access_order (string)" msgstr "ldap_access_order (Zeichenkette)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:409 +#: sssd-ipa.5.xml:404 #, fuzzy #| msgid "<emphasis>expire</emphasis>: use ldap_account_expire_policy" msgid "<emphasis>expire</emphasis>: use IPA's account expiration policy." msgstr "<emphasis>expire</emphasis>: verwendet »ldap_account_expire_policy«." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:448 +#: sssd-ipa.5.xml:443 msgid "" "Please note that 'access_provider = ipa' must be set for this feature to " "work." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:455 +#: sssd-ipa.5.xml:450 msgid "ipa_deskprofile_search_base (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:458 +#: sssd-ipa.5.xml:453 msgid "" "Optional. Use the given string as search base for Desktop Profile related " "objects." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:462 sssd-ipa.5.xml:484 +#: sssd-ipa.5.xml:457 sssd-ipa.5.xml:479 msgid "Default: Use base DN" msgstr "Voreinstellung: verwendet Basis-DN" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:468 +#: sssd-ipa.5.xml:463 #, fuzzy #| msgid "ipa_subdomains_search_base (string)" msgid "ipa_subid_ranges_search_base (string)" msgstr "ipa_subdomains_search_base (Zeichenkette)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:471 +#: sssd-ipa.5.xml:466 #, fuzzy #| msgid "ipa_subdomains_search_base (string)" msgid "Deprecated. Use ldap_subid_ranges_search_base instead." msgstr "ipa_subdomains_search_base (Zeichenkette)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:477 +#: sssd-ipa.5.xml:472 msgid "ipa_hbac_search_base (string)" msgstr "ipa_hbac_search_base (Zeichenkette)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:480 +#: sssd-ipa.5.xml:475 msgid "Optional. Use the given string as search base for HBAC related objects." msgstr "" "optional, verwendet die angegebene Zeichenkette als Suchgrundlage für HBAC-" "bezogene Objekte" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:490 +#: sssd-ipa.5.xml:485 msgid "ipa_host_search_base (string)" msgstr "ipa_host_search_base (Zeichenkette)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:493 +#: sssd-ipa.5.xml:488 msgid "Deprecated. Use ldap_host_search_base instead." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:499 +#: sssd-ipa.5.xml:494 msgid "ipa_selinux_search_base (string)" msgstr "ipa_selinux_search_base (Zeichenkette)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:502 +#: sssd-ipa.5.xml:497 msgid "Optional. Use the given string as search base for SELinux user maps." msgstr "" "optional, verwendet die angegebene Zeichenkette als Suchgrundlage für " "SELinux-Benutzerabbildungen" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:518 +#: sssd-ipa.5.xml:513 msgid "ipa_subdomains_search_base (string)" msgstr "ipa_subdomains_search_base (Zeichenkette)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:521 +#: sssd-ipa.5.xml:516 msgid "Optional. Use the given string as search base for trusted domains." msgstr "" "optional, verwendet die angegebene Zeichenkette als Suchgrundlage für " "vertrauenswürdige Domains" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:530 +#: sssd-ipa.5.xml:525 msgid "Default: the value of <emphasis>cn=trusts,%basedn</emphasis>" msgstr "Voreinstellung: der Wert von <emphasis>cn=trusts,%basedn</emphasis>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:537 +#: sssd-ipa.5.xml:532 msgid "ipa_master_domain_search_base (string)" msgstr "ipa_master_domain_search_base (Zeichenkette)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:540 +#: sssd-ipa.5.xml:535 msgid "Optional. Use the given string as search base for master domain object." msgstr "" "optional, verwendet die angegebene Zeichenkette als Suchgrundlage für das " "Master-Domain-Objekt." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:549 +#: sssd-ipa.5.xml:544 msgid "Default: the value of <emphasis>cn=ad,cn=etc,%basedn</emphasis>" msgstr "Voreinstellung: der Wert von <emphasis>cn=ad,cn=etc,%basedn</emphasis>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:556 +#: sssd-ipa.5.xml:551 msgid "ipa_views_search_base (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:559 +#: sssd-ipa.5.xml:554 msgid "Optional. Use the given string as search base for views containers." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:568 +#: sssd-ipa.5.xml:563 msgid "Default: the value of <emphasis>cn=views,cn=accounts,%basedn</emphasis>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:578 +#: sssd-ipa.5.xml:573 msgid "" "The name of the Kerberos realm. This is optional and defaults to the value " "of <quote>ipa_domain</quote>." @@ -11586,7 +12028,7 @@ msgstr "" "Wert von »ipa_domain«." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:582 +#: sssd-ipa.5.xml:577 msgid "" "The name of the Kerberos realm has a special meaning in IPA - it is " "converted into the base DN to use for performing LDAP operations." @@ -11596,37 +12038,37 @@ msgstr "" "zu verwenden." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:590 sssd-ad.5.xml:1441 +#: sssd-ipa.5.xml:585 sssd-ad.5.xml:1434 msgid "krb5_confd_path (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:593 sssd-ad.5.xml:1444 +#: sssd-ipa.5.xml:588 sssd-ad.5.xml:1437 msgid "" "Absolute path of a directory where SSSD should place Kerberos configuration " "snippets." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:597 sssd-ad.5.xml:1448 +#: sssd-ipa.5.xml:592 sssd-ad.5.xml:1441 msgid "" "To disable the creation of the configuration snippets set the parameter to " "'none'." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:601 sssd-ad.5.xml:1452 +#: sssd-ipa.5.xml:596 sssd-ad.5.xml:1445 msgid "" "Default: not set (krb5.include.d subdirectory of SSSD's pubconf directory)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:608 +#: sssd-ipa.5.xml:603 msgid "ipa_deskprofile_refresh (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:611 +#: sssd-ipa.5.xml:606 msgid "" "The amount of time between lookups of the Desktop Profile rules against the " "IPA server. This will reduce the latency and load on the IPA server if there " @@ -11634,34 +12076,34 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:618 sssd-ipa.5.xml:648 sssd-ipa.5.xml:664 sssd-ad.5.xml:600 +#: sssd-ipa.5.xml:613 sssd-ipa.5.xml:643 sssd-ipa.5.xml:659 sssd-ad.5.xml:600 msgid "Default: 5 (seconds)" msgstr "Voreinstellung: 5 (Sekunden)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:624 +#: sssd-ipa.5.xml:619 msgid "ipa_deskprofile_request_interval (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:627 +#: sssd-ipa.5.xml:622 msgid "" "The amount of time between lookups of the Desktop Profile rules against the " "IPA server in case the last request did not return any rule." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:632 +#: sssd-ipa.5.xml:627 msgid "Default: 60 (minutes)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:638 +#: sssd-ipa.5.xml:633 msgid "ipa_hbac_refresh (integer)" msgstr "ipa_hbac_refresh (Ganzzahl)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:641 +#: sssd-ipa.5.xml:636 msgid "" "The amount of time between lookups of the HBAC rules against the IPA server. " "This will reduce the latency and load on the IPA server if there are many " @@ -11672,12 +12114,14 @@ msgstr "" "Zugriffssteuerungsanfragen in einer kurzen Zeitspanne ankommen." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:654 -msgid "ipa_hbac_selinux (integer)" -msgstr "ipa_hbac_selinux (Ganzzahl)" +#: sssd-ipa.5.xml:649 +#, fuzzy +#| msgid "ipa_hbac_refresh (integer)" +msgid "ipa_selinux_refresh (integer)" +msgstr "ipa_hbac_refresh (Ganzzahl)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:657 +#: sssd-ipa.5.xml:652 msgid "" "The amount of time between lookups of the SELinux maps against the IPA " "server. This will reduce the latency and load on the IPA server if there are " @@ -11688,33 +12132,33 @@ msgstr "" "viele Benutzeranmeldeanfragen in einer kurzen Zeitspanne ankommen." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:670 +#: sssd-ipa.5.xml:665 msgid "ipa_server_mode (boolean)" msgstr "ipa_server_mode (Boolesch)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:673 +#: sssd-ipa.5.xml:668 msgid "" "This option will be set by the IPA installer (ipa-server-install) " "automatically and denotes if SSSD is running on an IPA server or not." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:678 +#: sssd-ipa.5.xml:673 msgid "" "On an IPA server SSSD will lookup users and groups from trusted domains " "directly while on a client it will ask an IPA server." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:683 +#: sssd-ipa.5.xml:678 msgid "" "NOTE: There are currently some assumptions that must be met when SSSD is " "running on an IPA server." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:688 +#: sssd-ipa.5.xml:683 msgid "" "The <quote>ipa_server</quote> option must be configured to point to the IPA " "server itself. This is already the default set by the IPA installer, so no " @@ -11722,59 +12166,59 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:697 +#: sssd-ipa.5.xml:692 msgid "" "The <quote>full_name_format</quote> option must not be tweaked to only print " "short names for users from trusted domains." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:712 +#: sssd-ipa.5.xml:707 msgid "ipa_automount_location (string)" msgstr "ipa_automount_location (Zeichenkette)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:715 +#: sssd-ipa.5.xml:710 msgid "The automounter location this IPA client will be using" msgstr "der Ort des Automounters, den dieser IPA-Client benutzen wird" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:718 +#: sssd-ipa.5.xml:713 msgid "Default: The location named \"default\"" msgstr "Voreinstellung: der Ort namens »default«" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd-ipa.5.xml:726 +#: sssd-ipa.5.xml:721 msgid "VIEWS AND OVERRIDES" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:735 +#: sssd-ipa.5.xml:730 msgid "ipa_view_class (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:738 +#: sssd-ipa.5.xml:733 msgid "Objectclass of the view container." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:741 +#: sssd-ipa.5.xml:736 msgid "Default: nsContainer" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:747 +#: sssd-ipa.5.xml:742 msgid "ipa_view_name (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:750 +#: sssd-ipa.5.xml:745 msgid "Name of the attribute holding the name of the view." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:754 sssd-ldap-attributes.5.xml:496 +#: sssd-ipa.5.xml:749 sssd-ldap-attributes.5.xml:496 #: sssd-ldap-attributes.5.xml:832 sssd-ldap-attributes.5.xml:913 #: sssd-ldap-attributes.5.xml:1010 sssd-ldap-attributes.5.xml:1068 #: sssd-ldap-attributes.5.xml:1226 sssd-ldap-attributes.5.xml:1271 @@ -11782,128 +12226,128 @@ msgid "Default: cn" msgstr "Voreinstellung: cn" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:760 +#: sssd-ipa.5.xml:755 msgid "ipa_override_object_class (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:763 +#: sssd-ipa.5.xml:758 msgid "Objectclass of the override objects." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:766 +#: sssd-ipa.5.xml:761 msgid "Default: ipaOverrideAnchor" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:772 +#: sssd-ipa.5.xml:767 msgid "ipa_anchor_uuid (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:775 +#: sssd-ipa.5.xml:770 msgid "" "Name of the attribute containing the reference to the original object in a " "remote domain." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:779 +#: sssd-ipa.5.xml:774 msgid "Default: ipaAnchorUUID" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:785 +#: sssd-ipa.5.xml:780 msgid "ipa_user_override_object_class (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:788 +#: sssd-ipa.5.xml:783 msgid "" "Name of the objectclass for user overrides. It is used to determine if the " "found override object is related to a user or a group." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:793 +#: sssd-ipa.5.xml:788 msgid "User overrides can contain attributes given by" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:796 +#: sssd-ipa.5.xml:791 msgid "ldap_user_name" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:799 +#: sssd-ipa.5.xml:794 msgid "ldap_user_uid_number" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:802 +#: sssd-ipa.5.xml:797 msgid "ldap_user_gid_number" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:805 +#: sssd-ipa.5.xml:800 msgid "ldap_user_gecos" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:808 +#: sssd-ipa.5.xml:803 msgid "ldap_user_home_directory" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:811 +#: sssd-ipa.5.xml:806 msgid "ldap_user_shell" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:814 +#: sssd-ipa.5.xml:809 msgid "ldap_user_ssh_public_key" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:819 +#: sssd-ipa.5.xml:814 msgid "Default: ipaUserOverride" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:825 +#: sssd-ipa.5.xml:820 msgid "ipa_group_override_object_class (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:828 +#: sssd-ipa.5.xml:823 msgid "" "Name of the objectclass for group overrides. It is used to determine if the " "found override object is related to a user or a group." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:833 +#: sssd-ipa.5.xml:828 msgid "Group overrides can contain attributes given by" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:836 +#: sssd-ipa.5.xml:831 msgid "ldap_group_name" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:839 +#: sssd-ipa.5.xml:834 msgid "ldap_group_gid_number" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:844 +#: sssd-ipa.5.xml:839 msgid "Default: ipaGroupOverride" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:728 +#: sssd-ipa.5.xml:723 msgid "" "SSSD can handle views and overrides which are offered by FreeIPA 4.1 and " "later version. Since all paths and objectclasses are fixed on the server " @@ -11913,12 +12357,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd-ipa.5.xml:856 +#: sssd-ipa.5.xml:851 msgid "SUBDOMAINS PROVIDER" msgstr "ANBIETER VON UNTER-DOMAINS" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:858 +#: sssd-ipa.5.xml:853 msgid "" "The IPA subdomains provider behaves slightly differently if it is configured " "explicitly or implicitly." @@ -11927,7 +12371,7 @@ msgstr "" "ob er explizit oder implizit konfiguriert wurde." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:862 +#: sssd-ipa.5.xml:857 msgid "" "If the option 'subdomains_provider = ipa' is found in the domain section of " "sssd.conf, the IPA subdomains provider is configured explicitly, and all " @@ -11939,7 +12383,7 @@ msgstr "" "Server gesandt." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:868 +#: sssd-ipa.5.xml:863 msgid "" "If the option 'subdomains_provider' is not set in the domain section of " "sssd.conf but there is the option 'id_provider = ipa', the IPA subdomains " @@ -11958,12 +12402,12 @@ msgstr "" "online gegangen ist, wird der Subdomain-Anbieter erneut aktiviert." #. type: Content of: <reference><refentry><refsect1><title> -#: sssd-ipa.5.xml:879 +#: sssd-ipa.5.xml:874 msgid "TRUSTED DOMAINS CONFIGURATION" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-ipa.5.xml:887 +#: sssd-ipa.5.xml:882 #, no-wrap msgid "" "[domain/ipa.domain.com/ad.domain.com]\n" @@ -11971,7 +12415,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:881 +#: sssd-ipa.5.xml:876 msgid "" "Some configuration options can also be set for a trusted domain. A trusted " "domain configuration can be set using the trusted domain subsection as shown " @@ -11981,99 +12425,99 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:892 +#: sssd-ipa.5.xml:887 msgid "" "For more details, see the <citerefentry> <refentrytitle>sssd.conf</" "refentrytitle> <manvolnum>5</manvolnum> </citerefentry> manual page." msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:899 +#: sssd-ipa.5.xml:894 msgid "" "Different configuration options are tunable for a trusted domain depending " "on whether you are configuring SSSD on an IPA server or an IPA client." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd-ipa.5.xml:904 +#: sssd-ipa.5.xml:899 msgid "OPTIONS TUNABLE ON IPA MASTERS" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:906 +#: sssd-ipa.5.xml:901 msgid "" "The following options can be set in a subdomain section on an IPA master:" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:910 sssd-ipa.5.xml:950 +#: sssd-ipa.5.xml:905 sssd-ipa.5.xml:945 msgid "ad_server" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:913 +#: sssd-ipa.5.xml:908 msgid "ad_backup_server" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:916 sssd-ipa.5.xml:953 +#: sssd-ipa.5.xml:911 sssd-ipa.5.xml:948 msgid "ad_site" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:919 +#: sssd-ipa.5.xml:914 msgid "ipa_server" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:922 +#: sssd-ipa.5.xml:917 #, fuzzy #| msgid "ipa_server, ipa_backup_server (string)" msgid "ipa_backup_server" msgstr "ipa_server, ipa_backup_server (Zeichenkette)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:925 +#: sssd-ipa.5.xml:920 msgid "ldap_search_base" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:928 +#: sssd-ipa.5.xml:923 msgid "ldap_user_search_base" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:931 +#: sssd-ipa.5.xml:926 msgid "ldap_group_search_base" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:939 +#: sssd-ipa.5.xml:934 msgid "" "Options prefixed with 'ad_' or 'ipa_' only apply to their respective " "subdomain type." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd-ipa.5.xml:944 +#: sssd-ipa.5.xml:939 msgid "OPTIONS TUNABLE ON IPA CLIENTS" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:946 +#: sssd-ipa.5.xml:941 msgid "" "The following options can be set in an AD subdomain section on an IPA client:" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:958 +#: sssd-ipa.5.xml:953 msgid "" "Note that if both options are set, only <quote>ad_server</quote> is " "evaluated." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:962 +#: sssd-ipa.5.xml:957 msgid "" "Since any request for a user or a group identity from a trusted domain " "triggered from an IPA client is resolved by the IPA server, the " @@ -12087,7 +12531,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:986 +#: sssd-ipa.5.xml:981 msgid "" "The following example assumes that SSSD is correctly configured and " "example.com is one of the domains in the <replaceable>[sssd]</replaceable> " @@ -12099,7 +12543,7 @@ msgstr "" "Optionen von IPA." #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-ipa.5.xml:993 +#: sssd-ipa.5.xml:988 #, no-wrap msgid "" "[domain/example.com]\n" @@ -12870,27 +13314,27 @@ msgid "lxdm" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:694 +#: sssd-ad.5.xml:699 msgid "sddm" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:699 +#: sssd-ad.5.xml:704 msgid "unity" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:704 +#: sssd-ad.5.xml:709 msgid "xdm" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:713 +#: sssd-ad.5.xml:718 msgid "ad_gpo_map_remote_interactive (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:716 +#: sssd-ad.5.xml:721 msgid "" "A comma-separated list of PAM service names for which GPO-based access " "control is evaluated based on the RemoteInteractiveLogonRight and " @@ -12906,7 +13350,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:735 +#: sssd-ad.5.xml:740 msgid "" "Note: Using the Group Policy Management Editor this value is called \"Allow " "log on through Remote Desktop Services\" and \"Deny log on through Remote " @@ -12914,7 +13358,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:750 +#: sssd-ad.5.xml:755 #, no-wrap msgid "" "ad_gpo_map_remote_interactive = +my_pam_service, -sshd\n" @@ -12922,7 +13366,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:741 +#: sssd-ad.5.xml:746 msgid "" "It is possible to add another PAM service name to the default set by using " "<quote>+service_name</quote> or to explicitly remove a PAM service name from " @@ -12934,22 +13378,22 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:758 +#: sssd-ad.5.xml:763 msgid "sshd" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:763 +#: sssd-ad.5.xml:768 msgid "cockpit" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:772 +#: sssd-ad.5.xml:777 msgid "ad_gpo_map_network (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:775 +#: sssd-ad.5.xml:780 msgid "" "A comma-separated list of PAM service names for which GPO-based access " "control is evaluated based on the NetworkLogonRight and " @@ -12965,7 +13409,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:793 +#: sssd-ad.5.xml:798 msgid "" "Note: Using the Group Policy Management Editor this value is called \"Access " "this computer from the network\" and \"Deny access to this computer from the " @@ -12973,7 +13417,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:808 +#: sssd-ad.5.xml:813 #, no-wrap msgid "" "ad_gpo_map_network = +my_pam_service, -ftp\n" @@ -12981,7 +13425,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:799 +#: sssd-ad.5.xml:804 msgid "" "It is possible to add another PAM service name to the default set by using " "<quote>+service_name</quote> or to explicitly remove a PAM service name from " @@ -12993,22 +13437,22 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:816 +#: sssd-ad.5.xml:821 msgid "ftp" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:821 +#: sssd-ad.5.xml:826 msgid "samba" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:830 +#: sssd-ad.5.xml:835 msgid "ad_gpo_map_batch (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:833 +#: sssd-ad.5.xml:838 msgid "" "A comma-separated list of PAM service names for which GPO-based access " "control is evaluated based on the BatchLogonRight and DenyBatchLogonRight " @@ -13023,14 +13467,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:851 +#: sssd-ad.5.xml:856 msgid "" "Note: Using the Group Policy Management Editor this value is called \"Allow " "log on as a batch job\" and \"Deny log on as a batch job\"." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:865 +#: sssd-ad.5.xml:870 #, no-wrap msgid "" "ad_gpo_map_batch = +my_pam_service, -crond\n" @@ -13038,7 +13482,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:856 +#: sssd-ad.5.xml:861 msgid "" "It is possible to add another PAM service name to the default set by using " "<quote>+service_name</quote> or to explicitly remove a PAM service name from " @@ -13050,23 +13494,23 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:868 +#: sssd-ad.5.xml:873 msgid "" "Note: Cron service name may differ depending on Linux distribution used." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:874 +#: sssd-ad.5.xml:879 msgid "crond" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:883 +#: sssd-ad.5.xml:888 msgid "ad_gpo_map_service (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:886 +#: sssd-ad.5.xml:891 msgid "" "A comma-separated list of PAM service names for which GPO-based access " "control is evaluated based on the ServiceLogonRight and " @@ -13082,14 +13526,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:904 +#: sssd-ad.5.xml:909 msgid "" "Note: Using the Group Policy Management Editor this value is called \"Allow " "log on as a service\" and \"Deny log on as a service\"." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:917 +#: sssd-ad.5.xml:922 #, no-wrap msgid "" "ad_gpo_map_service = +my_pam_service\n" @@ -13097,7 +13541,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:909 sssd-ad.5.xml:984 +#: sssd-ad.5.xml:914 sssd-ad.5.xml:989 msgid "" "It is possible to add a PAM service name to the default set by using " "<quote>+service_name</quote>. Since the default set is empty, it is not " @@ -13108,19 +13552,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:927 +#: sssd-ad.5.xml:932 msgid "ad_gpo_map_permit (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:930 +#: sssd-ad.5.xml:935 msgid "" "A comma-separated list of PAM service names for which GPO-based access is " "always granted, regardless of any GPO Logon Rights." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:944 +#: sssd-ad.5.xml:949 #, no-wrap msgid "" "ad_gpo_map_permit = +my_pam_service, -sudo\n" @@ -13128,7 +13572,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:935 +#: sssd-ad.5.xml:940 msgid "" "It is possible to add another PAM service name to the default set by using " "<quote>+service_name</quote> or to explicitly remove a PAM service name from " @@ -13140,29 +13584,29 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:952 +#: sssd-ad.5.xml:957 msgid "polkit-1" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:967 +#: sssd-ad.5.xml:972 msgid "systemd-user" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:976 +#: sssd-ad.5.xml:981 msgid "ad_gpo_map_deny (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:979 +#: sssd-ad.5.xml:984 msgid "" "A comma-separated list of PAM service names for which GPO-based access is " "always denied, regardless of any GPO Logon Rights." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:992 +#: sssd-ad.5.xml:997 #, no-wrap msgid "" "ad_gpo_map_deny = +my_pam_service\n" @@ -13170,12 +13614,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:1002 +#: sssd-ad.5.xml:1007 msgid "ad_gpo_default_right (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1005 +#: sssd-ad.5.xml:1010 msgid "" "This option defines how access control is evaluated for PAM service names " "that are not explicitly listed in one of the ad_gpo_map_* options. This " @@ -13188,52 +13632,52 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1018 +#: sssd-ad.5.xml:1023 msgid "Supported values for this option include:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1027 +#: sssd-ad.5.xml:1032 msgid "remote_interactive" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1032 +#: sssd-ad.5.xml:1037 msgid "network" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1037 +#: sssd-ad.5.xml:1042 msgid "batch" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1042 +#: sssd-ad.5.xml:1047 msgid "service" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1047 +#: sssd-ad.5.xml:1052 msgid "permit" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1052 +#: sssd-ad.5.xml:1057 msgid "deny" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1058 +#: sssd-ad.5.xml:1063 msgid "Default: deny" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:1064 +#: sssd-ad.5.xml:1069 msgid "ad_maximum_machine_account_password_age (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1067 +#: sssd-ad.5.xml:1072 msgid "" "SSSD will check once a day if the machine account password is older than the " "given age in days and try to renew it. A value of 0 will disable the renewal " @@ -13241,17 +13685,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1073 +#: sssd-ad.5.xml:1078 msgid "Default: 30 days" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:1079 +#: sssd-ad.5.xml:1084 msgid "ad_machine_account_password_renewal_opts (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1082 +#: sssd-ad.5.xml:1087 msgid "" "This option should only be used to test the machine account renewal task. " "The option expects 3 integers and a string separated by a colon (':'). The " @@ -13264,20 +13708,20 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1096 +#: sssd-ad.5.xml:1101 msgid "" "The optional fourth string value identifies the helper binary which should " "be used for the renewal. Currently <command>adcli</command> and " "<command>realm</command> are supported. If this value is missing or empty in " "the value string <command>realm</command> will be used. Since the helper is " "started as the user SSSD is running as there might be the chance that the " -"renewal will fail if this user does not has permissions to modify the keytab " -"file where the machine account credentials are stored. This will typically " -"be the case for <command>adcli</command>." +"renewal will fail if this user does not have permissions to modify the " +"keytab file where the machine account credentials are stored. This will " +"typically be the case for <command>adcli</command>." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1110 +#: sssd-ad.5.xml:1115 msgid "" "<command>realm</command> is not updating the keytab directly but is calling " "the <command>realmd</command> process, which runs as root user, for this " @@ -13287,17 +13731,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1119 +#: sssd-ad.5.xml:1124 msgid "Default: 86400:750:300:realm (24h, 12m30s and 5m)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:1125 +#: sssd-ad.5.xml:1130 msgid "ad_update_samba_machine_account_password (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1128 +#: sssd-ad.5.xml:1133 msgid "" "If enabled, when SSSD renews the machine account password, it will also be " "updated in Samba's database. This prevents Samba's copy of the machine " @@ -13306,23 +13750,25 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:1141 -msgid "ad_use_ldaps (bool)" -msgstr "" +#: sssd-ad.5.xml:1146 +#, fuzzy +#| msgid "ldap_id_use_start_tls (boolean)" +msgid "ad_use_ldaps (boolean)" +msgstr "ldap_id_use_start_tls (Boolesch)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1144 +#: sssd-ad.5.xml:1149 msgid "" "By default SSSD uses the plain LDAP port 389 and the Global Catalog port " -"3628. If this option is set to True SSSD will use the LDAPS port 636 and " -"Global Catalog port 3629 with LDAPS protection. Since AD does not allow to " +"3268. If this option is set to True SSSD will use the LDAPS port 636 and " +"Global Catalog port 3269 with LDAPS protection. Since AD does not allow to " "have multiple encryption layers on a single connection and we still want to " "use SASL/GSSAPI or SASL/GSS-SPNEGO for authentication the SASL security " "property maxssf is set to 0 (zero) for those connections." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1164 +#: sssd-ad.5.xml:1169 msgid "" "Optional. This option tells SSSD to automatically update the Active " "Directory DNS server with the IP address of this client. The update is " @@ -13347,33 +13793,29 @@ msgstr "Voreinstellung: 3600 (Sekunden)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:1216 msgid "" -"NOTE: While it is still possible to use the old <emphasis>ipa_dyndns_iface</" -"emphasis> option, users should migrate to using <emphasis>dyndns_iface</" -"emphasis> in their config file." -msgstr "" -"HINWEIS: Obwohl es immer noch möglich ist, die alte Option <emphasis>" -"ipa_dyndns_iface</emphasis> zu benutzen, sollten Anwender auf die Verwendung " -"von <emphasis>dyndns_iface</emphasis> in ihrer Konfigurationsdatei migrieren." - -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1222 -msgid "" "Default: Use the IP addresses of the interface which is used for AD LDAP " "connection" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1258 +#: sssd-ad.5.xml:1252 +#, fuzzy +#| msgid "" +#| "How often should the back end perform periodic DNS update in addition to " +#| "the automatic update performed when the back end goes online. This " +#| "option is optional and applicable only when dyndns_update is true." msgid "" "How often should the back end perform periodic DNS update in addition to the " -"automatic update performed when the back end goes online. This option is " -"optional and applicable only when dyndns_update is true. Note that the " -"lowest possible value is 60 seconds in-case if value is provided less than " -"60, parameter will assume lowest value only." +"automatic update performed when the back end goes online. This is optional " +"and applicable only when dyndns_update is true. Note that the minimum value " +"is 60 seconds, any specified value below this threshold will default to 60." msgstr "" +"wie oft das Backend periodische DNS-Aktualisierungen zusätzlich zur " +"automatisch beim Online-Gehen durchgeführten Aktualisierung vornehmen soll. " +"Diese Option ist optional und nur anwendbar, wenn »dyndns_update« »true« ist." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ad.5.xml:1472 +#: sssd-ad.5.xml:1465 msgid "" "The following example assumes that SSSD is correctly configured and " "example.com is one of the domains in the <replaceable>[sssd]</replaceable> " @@ -13385,7 +13827,7 @@ msgstr "" "Optionen von AD." #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-ad.5.xml:1479 +#: sssd-ad.5.xml:1472 #, no-wrap msgid "" "[domain/EXAMPLE]\n" @@ -13409,7 +13851,7 @@ msgstr "" "ad_domain = example.com\n" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-ad.5.xml:1499 +#: sssd-ad.5.xml:1492 #, no-wrap msgid "" "access_provider = ldap\n" @@ -13421,7 +13863,7 @@ msgstr "" "ldap_account_expire_policy = ad\n" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ad.5.xml:1495 +#: sssd-ad.5.xml:1488 msgid "" "The AD access control provider checks if the account is expired. It has the " "same effect as the following configuration of the LDAP provider: " @@ -13432,7 +13874,7 @@ msgstr "" "<placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ad.5.xml:1505 +#: sssd-ad.5.xml:1498 msgid "" "However, unless the <quote>ad</quote> access control provider is explicitly " "configured, the default access provider is <quote>permit</quote>. Please " @@ -13442,7 +13884,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ad.5.xml:1513 +#: sssd-ad.5.xml:1506 msgid "" "When the autofs provider is set to <quote>ad</quote>, the RFC2307 schema " "attribute mapping (nisMap, nisObject, ...) is used, because these attributes " @@ -13654,11 +14096,17 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-sudo.5.xml:137 +#, fuzzy +#| msgid "" +#| "The <emphasis>smart refresh</emphasis> periodically downloads rules that " +#| "are new or were modified after the last update. Its primary goal is to " +#| "keep the database growing by fetching only small increments that do not " +#| "generate large amounts of network traffic." msgid "" "The <emphasis>smart refresh</emphasis> periodically downloads rules that are " -"new or were modified after the last update. Its primary goal is to keep the " -"database growing by fetching only small increments that do not generate " -"large amounts of network traffic." +"new or were modified after the last update. Its primary goal is to grow the " +"database incrementally by fetching only small updates, avoiding large " +"amounts of network traffic." msgstr "" "Das <emphasis>kluge Aktualisieren</emphasis> lädt periodisch Regeln " "herunter, die neu sind oder seit der letzten Aktualisierung geändert wurden. " @@ -13885,26 +14333,29 @@ msgstr "" msgid "" "Depending on the IdP product additional platform specific options might " "follow the name separated by a colon (:). E.g. for Keycloak the base URI for " -"the user and group REST API must be given. For Entra ID this is not needed " -"because there is a generic endpoint for all tenants." +"the user and group REST API must be given. For Entra ID the base URI for the " +"Microsoft Graph API can be given to use sovereign or government cloud " +"endpoints instead of the default (https://graph.microsoft.com/v1.0). E.g. " +"<quote>entra_id:https://graph.microsoft.us/v1.0</quote> for the US " +"government cloud (GCC High)." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:78 sssd-idp.5.xml:94 sssd-idp.5.xml:119 +#: sssd-idp.5.xml:82 sssd-idp.5.xml:98 sssd-idp.5.xml:123 #, fuzzy #| msgid "Default: Not set" msgid "Default: Not set (Required)" msgstr "Voreinstellung: Nicht gesetzt" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:83 +#: sssd-idp.5.xml:87 #, fuzzy #| msgid "ipa_domain (string)" msgid "idp_client_id (string)" msgstr "ipa_domain (Zeichenkette)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:86 +#: sssd-idp.5.xml:90 msgid "" "ID of the IdP client used by SSSD to authenticate users and as a client to " "lookup user and group attributes. This client must offer device " @@ -13913,14 +14364,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:99 +#: sssd-idp.5.xml:103 #, fuzzy #| msgid "ldap_tls_cert (string)" msgid "idp_client_secret (string)" msgstr "ldap_tls_cert (Zeichenkette)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:102 +#: sssd-idp.5.xml:106 msgid "" "Password of the IdP client. The password is required for the id_provider. If " "only used as auth_provider it depends on the server side configuration if it " @@ -13928,76 +14379,83 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:113 +#: sssd-idp.5.xml:117 #, fuzzy #| msgid "ipa_domain (string)" msgid "idp_token_endpoint (string)" msgstr "ipa_domain (Zeichenkette)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:116 +#: sssd-idp.5.xml:120 msgid "IdP endpoint for requesting access tokens." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:124 +#: sssd-idp.5.xml:128 #, fuzzy #| msgid "ldap_service_port (string)" msgid "idp_device_auth_endpoint (string)" msgstr "ldap_service_port (Zeichenkette)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:127 +#: sssd-idp.5.xml:131 msgid "" "IdP endpoint for device authorization according to RFC-8628. This is " "required for user authentication." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:137 +#: sssd-idp.5.xml:141 #, fuzzy #| msgid "ldap_service_port (string)" msgid "idp_userinfo_endpoint (string)" msgstr "ldap_service_port (Zeichenkette)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:140 +#: sssd-idp.5.xml:144 msgid "" "IdP userinfo endpoint to request user attributes after a successful " "authentication of the user. Required for authentication." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:150 +#: sssd-idp.5.xml:154 #, fuzzy #| msgid "id_provider (string)" msgid "idp_id_scope (string)" msgstr "id_provider (Zeichenkette)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:153 +#: sssd-idp.5.xml:157 msgid "" "Scope required for looking up user and group attributes with the REST API. " "The scopes are used by the server to determine which attributes/claims are " "returned to the caller." msgstr "" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:163 +msgid "" +"Note: In previous versions of SSSD, this option was expected to already be " +"URL-encoded." +msgstr "" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:164 +#: sssd-idp.5.xml:172 #, fuzzy #| msgid "dyndns_iface (string)" msgid "idp_auth_scope (string)" msgstr "dyndns_iface (Zeichenkette)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:167 +#: sssd-idp.5.xml:175 msgid "" "Scope required during authentication. The scopes are used by the server to " "determine which attributes/claims are returned to the caller." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:172 +#: sssd-idp.5.xml:180 msgid "" "Currently the tokens returned during user authentication are not used for " "other purposes hence the only important claim is the subject identifier " @@ -14006,26 +14464,124 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:185 +#: sssd-idp.5.xml:193 +#, fuzzy +#| msgid "ldap_user_extra_attrs (string)" +msgid "idp_auth_user_identifier_attr (string)" +msgstr "ldap_user_extra_attrs (Zeichenkette)" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:196 +msgid "" +"Attribute used to identify the authenticated user in userinfo data or token " +"claims." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:200 +msgid "" +"For hybrid Active Directory and Entra ID deployments where " +"<quote>id_provider = ad</quote> and <quote>auth_provider = idp</quote>, this " +"option must be set explicitly. No value is derived from the identity " +"provider, because more than one attribute can link an Entra ID object to its " +"on-premises counterpart and only the administrator knows which one the " +"directory synchronization is configured to use." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:211 +msgid "" +"Setting this option to <quote>onPremisesImmutableId</quote> is the usual " +"choice for such deployments. Microsoft Entra Connect populates that " +"attribute with the base64-encoded form of the 16-byte Active Directory " +"<quote>objectGUID</quote> when objectGUID is used as the sourceAnchor. SSSD " +"decodes the value and converts the raw bytes with the same conversion used " +"for AD objectGUID attributes, so the result matches the UUID stored in the " +"SSSD cache for the AD user." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:224 +msgid "" +"Note that Microsoft Entra Connect 1.1.524.0 and later use <quote>ms-DS-" +"ConsistencyGuid</quote> as the sourceAnchor for user objects instead of " +"<quote>objectGUID</quote>. The value is normally copied from objectGUID for " +"objects that do not have it set yet, in which case the decoded identifier " +"still matches. It does not match if ms-DS-ConsistencyGuid was populated " +"independently, if users were moved between forests or domains, or if a " +"different attribute such as employeeID was selected as the sourceAnchor. See " +"<ulink url=\"https://learn.microsoft.com/en-us/entra/identity/hybrid/connect/" +"plan-connect-design-concepts\"> Microsoft Entra Connect: Design concepts</" +"ulink> for details on sourceAnchor selection." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:241 +msgid "" +"Microsoft Graph does not return <quote>onPremisesImmutableId</quote> by " +"default. The <quote>idp_userinfo_endpoint</quote> must request it with " +"<quote>$select</quote>, see the example below and <ulink url=\"https://" +"learn.microsoft.com/en-us/graph/api/resources/user\"> the Microsoft Graph " +"user resource type</ulink>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:251 +msgid "" +"If the configured attribute is missing or cannot be decoded (for example " +"cloud-only Entra ID users without <quote>onPremisesImmutableId</quote>), " +"authentication fails. SSSD does not fall back to another attribute when this " +"option is set." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:258 +msgid "" +"Default: not set, <quote>sub</quote> for Keycloak and <quote>id</quote> for " +"other IdP types" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-idp.5.xml:264 #, fuzzy #| msgid "ldap_opt_timeout (integer)" msgid "idp_request_timeout (integer)" msgstr "ldap_opt_timeout (Ganzzahl)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:188 +#: sssd-idp.5.xml:267 msgid "Timeout in seconds for an individual request to the IdP." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:197 +#: sssd-idp.5.xml:276 +#, fuzzy +#| msgid "ldap_referrals (boolean)" +msgid "idp_auto_refresh (boolean)" +msgstr "ldap_referrals (Boolesch)" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:279 +msgid "" +"Refresh tokens automatically, after they have reached about half their " +"lifetime." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:283 +msgid "" +"Note: Scheduled token refreshes are not preserved across restarts of SSSD." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-idp.5.xml:292 #, fuzzy #| msgid "ldap_idmap_range_min (integer)" msgid "idmap_range_min (integer)" msgstr "ldap_idmap_range_min (Ganzzahl)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:200 +#: sssd-idp.5.xml:295 #, fuzzy #| msgid "" #| "Specifies the lower bound of the range of POSIX IDs to use for mapping " @@ -14039,7 +14595,7 @@ msgstr "" "Active-Directory-Benutzern und Gruppen-SIDs benutzt wird." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:206 +#: sssd-idp.5.xml:301 msgid "" "The interval between <quote>idmap_range_min</quote> and " "<quote>idmap_range_max</quote> will be split into smaller ranges of size " @@ -14048,20 +14604,20 @@ msgid "" msgstr "" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:213 sssd-idp.5.xml:239 include/ldap_id_mapping.xml:139 +#: sssd-idp.5.xml:308 sssd-idp.5.xml:334 include/ldap_id_mapping.xml:139 #: include/ldap_id_mapping.xml:197 msgid "Default: 200000" msgstr "Voreinstellung: 200000" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:218 +#: sssd-idp.5.xml:313 #, fuzzy #| msgid "ldap_idmap_range_max (integer)" msgid "idmap_range_max (integer)" msgstr "ldap_idmap_range_max (Ganzzahl)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:221 +#: sssd-idp.5.xml:316 #, fuzzy #| msgid "" #| "Specifies the lower bound of the range of POSIX IDs to use for mapping " @@ -14075,47 +14631,70 @@ msgstr "" "Active-Directory-Benutzern und Gruppen-SIDs benutzt wird." #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:227 include/ldap_id_mapping.xml:165 +#: sssd-idp.5.xml:322 include/ldap_id_mapping.xml:165 msgid "Default: 2000200000" msgstr "Voreinstellung: 2000200000" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:232 +#: sssd-idp.5.xml:327 #, fuzzy #| msgid "ldap_idmap_range_size (integer)" msgid "idmap_range_size (integer)" msgstr "ldap_idmap_range_size (Ganzzahl)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:235 +#: sssd-idp.5.xml:330 msgid "Specifies the number of POSIX IDs available for a single IdP domain." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-idp.5.xml:251 +#: sssd-idp.5.xml:346 #, no-wrap msgid "" "[domain/entra_id]\n" "id_provider = idp\n" "idp_type = entra_id\n" "idp_client_id = 12345678-abcd-0101-efef-ba9876543210\n" -"idp_client_secret = YOUR-CLIENT-SCERET\n" -"idp_token_endpoint = https://login.microsoftonline.com/TENNANT-ID/oauth2/v2.0/token\n" +"idp_client_secret = YOUR-CLIENT-SECRET\n" +"idp_token_endpoint = https://login.microsoftonline.com/TENANT-ID/oauth2/v2.0/token\n" "idp_userinfo_endpoint = https://graph.microsoft.com/v1.0/me\n" -"idp_device_auth_endpoint = https://login.microsoftonline.com/TENNANT-ID/oauth2/v2.0/devicecode\n" -"idp_id_scope = https%3A%2F%2Fgraph.microsoft.com%2F.default\n" +"idp_device_auth_endpoint = https://login.microsoftonline.com/TENANT-ID/oauth2/v2.0/devicecode\n" +"idp_id_scope = https://graph.microsoft.com/.default\n" +"idp_auth_scope = openid profile email\n" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><programlisting> +#: sssd-idp.5.xml:358 +#, no-wrap +msgid "" +"[domain/ad.example.com]\n" +"id_provider = ad\n" +"auth_provider = idp\n" +"access_provider = permit\n" +"\n" +"ad_domain = ad.example.com\n" +"krb5_realm = AD.EXAMPLE.COM\n" +"\n" +"idp_type = entra_id\n" +"idp_client_id = 12345678-abcd-0101-efef-ba9876543210\n" +"idp_client_secret = YOUR-CLIENT-SECRET\n" +"idp_token_endpoint = https://login.microsoftonline.com/TENANT-ID/oauth2/v2.0/token\n" +"idp_userinfo_endpoint = https://graph.microsoft.com/v1.0/me?$select=id,userPrincipalName,onPremisesImmutableId\n" +"idp_device_auth_endpoint = https://login.microsoftonline.com/TENANT-ID/oauth2/v2.0/devicecode\n" +"idp_id_scope = https://graph.microsoft.com/.default\n" "idp_auth_scope = openid profile email\n" +"idp_auth_user_identifier_attr = onPremisesImmutableId\n" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-idp.5.xml:263 +#: sssd-idp.5.xml:377 #, no-wrap msgid "" "[domain/keycloak]\n" "idp_type = keycloak:https://master.keycloak.test:8443/auth/admin/realms/master/\n" "id_provider = idp\n" "idp_client_id = myclient\n" -"idp_client_secret = YOUR-CLIENT-SCERET\n" +"idp_client_secret = YOUR-CLIENT-SECRET\n" "idp_token_endpoint = https://master.keycloak.test:8443/auth/realms/master/protocol/openid-connect/token\n" "idp_userinfo_endpoint = https://master.keycloak.test:8443/auth/realms/master/protocol/openid-connect/userinfo\n" "idp_device_auth_endpoint = https://master.keycloak.test:8443/auth/realms/master/protocol/openid-connect/auth/device\n" @@ -14124,14 +14703,26 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-idp.5.xml:250 +#: sssd-idp.5.xml:345 #, fuzzy #| msgid "example: <placeholder type=\"programlisting\" id=\"0\"/>" msgid "" "<placeholder type=\"programlisting\" id=\"0\"/> <placeholder " -"type=\"programlisting\" id=\"1\"/>" +"type=\"programlisting\" id=\"1\"/> <placeholder type=\"programlisting\" " +"id=\"2\"/>" msgstr "Beispiel: <placeholder type=\"programlisting\" id=\"0\"/>" +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-idp.5.xml:390 +msgid "" +"In the hybrid Active Directory and Entra ID example above, " +"<quote>onPremisesImmutableId</quote> is used during authentication so the " +"IdP result matches the AD objectGUID UUID stored in the SSSD cache. The " +"attribute must be requested via <quote>$select</quote> on the Graph userinfo " +"endpoint and is only populated for users synchronized from Active Directory " +"with objectGUID as the sourceAnchor." +msgstr "" + #. type: Content of: <reference><refentry><refnamediv><refname> #: sssd.8.xml:10 sssd.8.xml:15 msgid "sssd" @@ -15226,9 +15817,13 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:291 +#, fuzzy +#| msgid "" +#| "<emphasis>demand</emphasis> to use FAST. The authentication fails if the " +#| "server does not require fast." msgid "" "<emphasis>demand</emphasis> to use FAST. The authentication fails if the " -"server does not require fast." +"server does not support FAST." msgstr "" "<emphasis>demand</emphasis>: Fragt nach, ob FAST benutzt werden soll. Die " "Authentifizierung schlägt fehl, falls der Server kein FAST erfordert." @@ -16269,8 +16864,10 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sss_rpcidmapd.5.xml:69 -msgid "memcache (bool)" -msgstr "" +#, fuzzy +#| msgid "ad_enable_gc (boolean)" +msgid "memcache (boolean)" +msgstr "ad_enable_gc (Boolesch)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sss_rpcidmapd.5.xml:72 @@ -16323,7 +16920,7 @@ msgid "" msgstr "" #. type: Content of: <refsect1><title> -#: sss_rpcidmapd.5.xml:120 sssd-kcm.8.xml:316 include/seealso.xml:2 +#: sss_rpcidmapd.5.xml:120 sssd-kcm.8.xml:315 include/seealso.xml:2 msgid "SEE ALSO" msgstr "SIEHE AUCH" @@ -16603,8 +17200,8 @@ msgstr "" #: sss_ssh_knownhosts.1.xml:93 msgid "" "The key lines retrieved from the backend are expected to respect the key " -"format as decribed in the <quote>SSH_KNOWN_HOSTS FILE FORMAT</quote> section " -"of <citerefentry><refentrytitle>sshd</refentrytitle> <manvolnum>8</" +"format as described in the <quote>SSH_KNOWN_HOSTS FILE FORMAT</quote> " +"section of <citerefentry><refentrytitle>sshd</refentrytitle> <manvolnum>8</" "manvolnum></citerefentry>. However, returning only the keytype and the key " "itself is tolerated, in which case, the hostname received as parameter will " "be added before the keytype to output a correctly formatted line. The " @@ -17084,15 +17681,22 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-kcm.8.xml:215 +#, fuzzy +#| msgid "" +#| "Please refer to the <quote>dns_discovery_domain</quote> parameter in the " +#| "<citerefentry> <refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</" +#| "manvolnum> </citerefentry> manual page for more details." msgid "" -"The KCM service is configured in the <quote>kcm</quote> For a detailed " -"syntax reference, refer to the <quote>FILE FORMAT</quote> section of the " -"<citerefentry> <refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</" -"manvolnum> </citerefentry> manual page." +"For a detailed syntax reference, refer to the <quote>FILE FORMAT</quote> " +"section of the <citerefentry> <refentrytitle>sssd.conf</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry> manual page." msgstr "" +"Weitere Einzelheiten finden Sie in der Handbuchseite <citerefentry> " +"<refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</manvolnum> </" +"citerefentry> beim Parameter »dns_discovery_domain«." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-kcm.8.xml:223 +#: sssd-kcm.8.xml:222 msgid "" "The generic SSSD service options such as <quote>debug_level</quote> or " "<quote>fd_limit</quote> are accepted by the kcm service. Please refer to " @@ -17102,22 +17706,22 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:234 +#: sssd-kcm.8.xml:233 msgid "socket_path (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:237 +#: sssd-kcm.8.xml:236 msgid "The socket the KCM service will listen on." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:240 +#: sssd-kcm.8.xml:239 msgid "Default: <replaceable>/var/run/.heim_org.h5l.kcm-socket</replaceable>" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:243 +#: sssd-kcm.8.xml:242 msgid "" "<phrase condition=\"have_systemd\"> Note: on platforms where systemd is " "supported, the socket path is overwritten by the one defined in the sssd-" @@ -17125,94 +17729,94 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:252 +#: sssd-kcm.8.xml:251 msgid "max_ccaches (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:255 +#: sssd-kcm.8.xml:254 msgid "How many credential caches does the KCM database allow for all users." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:259 +#: sssd-kcm.8.xml:258 msgid "Default: 0 (unlimited, only the per-UID quota is enforced)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:264 +#: sssd-kcm.8.xml:263 msgid "max_uid_ccaches (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:267 +#: sssd-kcm.8.xml:266 msgid "" "How many credential caches does the KCM database allow per UID. This is " "equivalent to <quote>with how many principals you can kinit</quote>." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:272 +#: sssd-kcm.8.xml:271 msgid "Default: 64" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:277 +#: sssd-kcm.8.xml:276 msgid "max_ccache_size (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:280 +#: sssd-kcm.8.xml:279 msgid "" -"How big can a credential cache be per ccache. Each service ticket accounts " -"into this quota." +"How big a credential cache be per ccache. Each service ticket counts toward " +"this quota." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:284 +#: sssd-kcm.8.xml:283 msgid "Default: 65536" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:289 +#: sssd-kcm.8.xml:288 #, fuzzy #| msgid "enumerate (bool)" -msgid "tgt_renewal (bool)" +msgid "tgt_renewal (boolean)" msgstr "enumerate (Boolesch)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:292 +#: sssd-kcm.8.xml:291 msgid "Enables TGT renewals functionality." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:295 +#: sssd-kcm.8.xml:294 #, fuzzy #| msgid "Default: False (disabled)" msgid "Default: False (Automatic renewals disabled)" msgstr "Voreinstellung: False (deaktiviert)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:300 +#: sssd-kcm.8.xml:299 #, fuzzy #| msgid "krb5_renew_interval (string)" msgid "tgt_renewal_inherit (string)" msgstr "krb5_renew_interval (Zeichenkette)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:303 +#: sssd-kcm.8.xml:302 msgid "Domain to inherit krb5_* options from, for use with TGT renewals." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:307 +#: sssd-kcm.8.xml:306 #, fuzzy #| msgid "Default: 3" msgid "Default: NULL" msgstr "Voreinstellung: 3" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-kcm.8.xml:318 +#: sssd-kcm.8.xml:317 msgid "" "<citerefentry> <refentrytitle>sssd</refentrytitle><manvolnum>8</manvolnum> </" "citerefentry>, <citerefentry> <refentrytitle>sssd.conf</" @@ -18163,9 +18767,9 @@ msgstr "" "fest, ob Zugriff gewährt wird oder nicht." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap-attributes.5.xml:381 sssd-ldap-attributes.5.xml:395 -msgid "Default: loginDisabled" -msgstr "Voreinstellung: loginDisabled" +#: sssd-ldap-attributes.5.xml:381 +msgid "Default: loginDisabled (rfc2307, rfc2307bis and IPA), not set (AD)" +msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:387 @@ -18181,6 +18785,12 @@ msgstr "" "Wenn »ldap_account_expire_policy=nds« benutzt wird, legt dieser Parameter " "fest, bis zu welchem Datum Zugriff gewährt wird." +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:395 +msgid "" +"Default: loginExpirationTime (rfc2307, rfc2307bis and IPA), not set (AD)" +msgstr "" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:401 msgid "ldap_user_nds_login_allowed_time_map (string)" @@ -18197,8 +18807,9 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:409 -msgid "Default: loginAllowedTimeMap" -msgstr "Voreinstellung: loginAllowedTimeMap" +msgid "" +"Default: loginAllowedTimeMap (rfc2307, rfc2307bis and IPA), not set (AD)" +msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:415 @@ -18765,9 +19376,9 @@ msgid "The object class of a host entry in LDAP." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap-attributes.5.xml:900 sssd-ldap-attributes.5.xml:997 -msgid "Default: ipService" -msgstr "Voreinstellung: ipService" +#: sssd-ldap-attributes.5.xml:900 sssd-ldap-attributes.5.xml:1213 +msgid "Default: ipHost" +msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:906 @@ -18851,6 +19462,11 @@ msgstr "ldap_service_object_class (Zeichenkette)" msgid "The object class of a service entry in LDAP." msgstr "die Objektklasse eines Diensteintrags in LDAP" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:997 +msgid "Default: ipService" +msgstr "Voreinstellung: ipService" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1003 msgid "ldap_service_name (string)" @@ -19105,11 +19721,6 @@ msgstr "" msgid "The object class of an iphost entry in LDAP." msgstr "" -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap-attributes.5.xml:1213 -msgid "Default: ipHost" -msgstr "" - #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1219 msgid "ldap_iphost_name (string)" @@ -19361,6 +19972,7 @@ msgstr "KONFIGURATIONSOPTIONEN" msgid "" "[plugins]\n" " localauth = {\n" +" disable = an2ln\n" " module = sssd:/usr/lib64/sssd/modules/sssd_krb5_localauth_plugin.so\n" " }\n" msgstr "" @@ -19377,6 +19989,28 @@ msgid "" "the local Kerberos configuration the plugin will be enabled automatically." msgstr "" +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_localauth_plugin.8.xml:67 +msgid "" +"This configuration snippet also disables the <command>an2ln</command> module " +"provided by MIT Kerberos if SSSD is configured to use the AD or IPA " +"provider. In those environments <command>sssd_krb5_localauth_plugin</" +"command> can reliably map the system user names to Kerberos principals. A " +"fallback to <command>an2ln</command> might cause issues in environments " +"where users have the privilege to create Kerberos principals on their own " +"which might collide with names of other users used in the system. Other " +"modules provided by MIT Kerberos, e.g. <command>k5login</command> are not " +"affected." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_localauth_plugin.8.xml:79 +msgid "" +"Note: If using <quote>auth_provider = krb5</quote> then " +"<command>sssd_krb5_localauth_plugin</command> is not used, therefore the " +"above text is not applicable." +msgstr "" + #. type: Content of: <variablelist><varlistentry><term> #: include/autofs_attributes.xml:3 msgid "ldap_autofs_map_object_class (string)" @@ -20448,40 +21082,6 @@ msgid "" "failures; corresponds to setting 2 in decimal notation)" msgstr "" -#. type: Content of: <refsect1><title> -#: include/local.xml:2 -msgid "THE LOCAL DOMAIN" -msgstr "DIE LOKALE DOMAIN" - -#. type: Content of: <refsect1><para> -#: include/local.xml:4 -msgid "" -"In order to function correctly, a domain with <quote>id_provider=local</" -"quote> must be created and the SSSD must be running." -msgstr "" -"Für korrektes Funktionieren muss eine Domain mit »id_provider=local« " -"erstellt sein und SSSD muss laufen." - -#. type: Content of: <refsect1><para> -#: include/local.xml:9 -msgid "" -"The administrator might want to use the SSSD local users instead of " -"traditional UNIX users in cases where the group nesting (see <citerefentry> " -"<refentrytitle>sss_groupadd</refentrytitle> <manvolnum>8</manvolnum> </" -"citerefentry>) is needed. The local users are also useful for testing and " -"development of the SSSD without having to deploy a full remote server. The " -"<command>sss_user*</command> and <command>sss_group*</command> tools use a " -"local LDB storage to store users and groups." -msgstr "" -"Möglicherweise möchte der Administrator in Fällen, in denen " -"Gruppenverschachtelung (siehe <citerefentry> <refentrytitle>sss_groupadd</" -"refentrytitle> <manvolnum>8</manvolnum> </citerefentry>) benötigt wird, " -"lokale Benutzer anstelle traditioneller UNIX-Benutzer verwenden. Die lokalen " -"Benutzer sind auch für das Testen und Entwickeln von SSSD nützlich, ohne " -"dass ein vollständiger ferner Server bereitgestellt werden muss. Die " -"<command>sss_user*</command>- und <command>sss_group*</command>-Werkzeuge " -"benutzen einen lokalen LDB-Speicher, um Benutzer und Gruppen abzulegen." - #. type: Content of: <refsect1><para> #: include/seealso.xml:4 msgid "" @@ -21163,6 +21763,99 @@ msgstr "" "werden sollen. Diese Funktionalität ist mit MIT-Kerberos 1.7 und neueren " "Versionen verfügbar." +#~ msgid "" +#~ "The data types used are string (no quotes needed), integer and bool (with " +#~ "values of <quote>TRUE/FALSE</quote>)." +#~ msgstr "" +#~ "Die benutzten Datentypen sind Zeichenkette (keine Anführungszeichen " +#~ "nötig), Ganzzahl und Boolesch (mit den Werten »TRUE« und »FALSE«)." + +#~ msgid "services" +#~ msgstr "Dienste" + +#~ msgid "domains" +#~ msgstr "Domains" + +#~ msgid "fd_limit" +#~ msgstr "fd_limit" + +#~ msgid "client_idle_timeout" +#~ msgstr "client_idle_timeout" + +#~ msgid "default_shell" +#~ msgstr "default_shell" + +#, fuzzy +#~| msgid "This option can also be set per-domain." +#~ msgid "" +#~ "Note: This option can also be set per-domain which overwrites the value " +#~ "in [nss] section." +#~ msgstr "Diese Option kann auch pro Domain gesetzt werden." + +#~ msgid "" +#~ "Default: <quote>id_provider</quote> is used if it is set and can handle " +#~ "selinux loading requests." +#~ msgstr "" +#~ "Voreinstellung: Falls gesetzt, wird der Wert von »id_provider« benutzt. " +#~ "Er kann SELinux-Ladeanfragen handhaben." + +#~ msgid "" +#~ "NOTE: On older systems (such as RHEL 5), for this behavior to work " +#~ "reliably, the default Kerberos realm must be set properly in /etc/" +#~ "krb5.conf" +#~ msgstr "" +#~ "HINWEIS: Auf älteren Systemen (wie RHEL 5) muss der Standard-Kerberos-" +#~ "Realm ordentlich in /etc/krb5.conf gesetzt sein, damit dies zuverlässig " +#~ "funktioniert." + +#~ msgid "ipa_hbac_selinux (integer)" +#~ msgstr "ipa_hbac_selinux (Ganzzahl)" + +#~ msgid "" +#~ "NOTE: While it is still possible to use the old " +#~ "<emphasis>ipa_dyndns_iface</emphasis> option, users should migrate to " +#~ "using <emphasis>dyndns_iface</emphasis> in their config file." +#~ msgstr "" +#~ "HINWEIS: Obwohl es immer noch möglich ist, die alte Option " +#~ "<emphasis>ipa_dyndns_iface</emphasis> zu benutzen, sollten Anwender auf " +#~ "die Verwendung von <emphasis>dyndns_iface</emphasis> in ihrer " +#~ "Konfigurationsdatei migrieren." + +#~ msgid "Default: loginDisabled" +#~ msgstr "Voreinstellung: loginDisabled" + +#~ msgid "Default: loginAllowedTimeMap" +#~ msgstr "Voreinstellung: loginAllowedTimeMap" + +#~ msgid "THE LOCAL DOMAIN" +#~ msgstr "DIE LOKALE DOMAIN" + +#~ msgid "" +#~ "In order to function correctly, a domain with <quote>id_provider=local</" +#~ "quote> must be created and the SSSD must be running." +#~ msgstr "" +#~ "Für korrektes Funktionieren muss eine Domain mit »id_provider=local« " +#~ "erstellt sein und SSSD muss laufen." + +#~ msgid "" +#~ "The administrator might want to use the SSSD local users instead of " +#~ "traditional UNIX users in cases where the group nesting (see " +#~ "<citerefentry> <refentrytitle>sss_groupadd</refentrytitle> <manvolnum>8</" +#~ "manvolnum> </citerefentry>) is needed. The local users are also useful " +#~ "for testing and development of the SSSD without having to deploy a full " +#~ "remote server. The <command>sss_user*</command> and <command>sss_group*</" +#~ "command> tools use a local LDB storage to store users and groups." +#~ msgstr "" +#~ "Möglicherweise möchte der Administrator in Fällen, in denen " +#~ "Gruppenverschachtelung (siehe <citerefentry> <refentrytitle>sss_groupadd</" +#~ "refentrytitle> <manvolnum>8</manvolnum> </citerefentry>) benötigt wird, " +#~ "lokale Benutzer anstelle traditioneller UNIX-Benutzer verwenden. Die " +#~ "lokalen Benutzer sind auch für das Testen und Entwickeln von SSSD " +#~ "nützlich, ohne dass ein vollständiger ferner Server bereitgestellt werden " +#~ "muss. Die <command>sss_user*</command>- und <command>sss_group*</command>-" +#~ "Werkzeuge benutzen einen lokalen LDB-Speicher, um Benutzer und Gruppen " +#~ "abzulegen." + #~ msgid "subdomain_enumerate (string)" #~ msgstr "subdomain_enumerate (Zeichenkette)" @@ -21538,9 +22231,6 @@ msgstr "" #~ "Gruppen ein einer nativen SSSD-Datenbank speichern, das heißt eine " #~ "Domain, die <replaceable>ID_Anbieter=lokal</replaceable> benutzt." -#~ msgid "default_shell (string)" -#~ msgstr "default_shell (Zeichenkette)" - #~ msgid "The default shell for users created with SSSD userspace tools." #~ msgstr "" #~ "die Standard-Shell für Anwender, die mit den SSSD-Werkzeugen für den " @@ -21549,9 +22239,6 @@ msgstr "" #~ msgid "Default: <filename>/bin/bash</filename>" #~ msgstr "Voreinstellung: <filename>/bin/bash</filename>" -#~ msgid "base_directory (string)" -#~ msgstr "base_directory (Zeichenkette)" - #~ msgid "" #~ "The tools append the login name to <replaceable>base_directory</" #~ "replaceable> and use that as the home directory." diff --git a/src/man/po/es.po b/src/man/po/es.po index 5f2fbf033c9..c587e9610f4 100644 --- a/src/man/po/es.po +++ b/src/man/po/es.po @@ -18,8 +18,8 @@ msgid "" msgstr "" "Project-Id-Version: sssd-docs 2.3.0\n" "Report-Msgid-Bugs-To: sssd-devel@redhat.com\n" -"POT-Creation-Date: 2026-01-14 15:00+0000\n" -"PO-Revision-Date: 2026-04-23 16:38+0000\n" +"POT-Creation-Date: 2026-10-05 16:14+0000\n" +"PO-Revision-Date: 2026-10-05 16:51+0000\n" "Last-Translator: Weblate Translation Memory <noreply-mt-weblate-translation-" "memory@weblate.org>\n" "Language-Team: Spanish <https://translate.fedoraproject.org/projects/sssd/" @@ -29,10 +29,10 @@ msgstr "" "Content-Type: text/plain; charset=UTF-8\n" "Content-Transfer-Encoding: 8bit\n" "Plural-Forms: nplurals=2; plural=n != 1;\n" -"X-Generator: Weblate 5.17\n" +"X-Generator: Weblate 2026.10\n" #. type: Content of: <reference><title> -#: sssd.conf.5.xml:8 sssd-ldap.5.xml:5 pam_sss.8.xml:5 pam_sss_gss.8.xml:5 +#: sssd.conf.5.xml:10 sssd-ldap.5.xml:5 pam_sss.8.xml:5 pam_sss_gss.8.xml:5 #: sssd_krb5_locator_plugin.8.xml:5 sssd-simple.5.xml:5 sss-certmap.5.xml:5 #: sssd-ipa.5.xml:5 sssd-ad.5.xml:5 sssd-sudo.5.xml:5 sssd-idp.5.xml:5 #: sssd.8.xml:5 sss_obfuscate.8.xml:5 sss_override.8.xml:5 sssd-krb5.5.xml:5 @@ -45,12 +45,12 @@ msgid "SSSD Manual pages" msgstr "Páginas del manual de SSSD" #. type: Content of: <reference><refentry><refnamediv><refname> -#: sssd.conf.5.xml:13 sssd.conf.5.xml:19 +#: sssd.conf.5.xml:15 sssd.conf.5.xml:21 msgid "sssd.conf" msgstr "sssd.conf" #. type: Content of: <reference><refentry><refmeta><manvolnum> -#: sssd.conf.5.xml:14 sssd-ldap.5.xml:11 sssd-simple.5.xml:11 +#: sssd.conf.5.xml:16 sssd-ldap.5.xml:11 sssd-simple.5.xml:11 #: sss-certmap.5.xml:11 sssd-ipa.5.xml:11 sssd-ad.5.xml:11 sssd-sudo.5.xml:11 #: sssd-idp.5.xml:11 sssd-krb5.5.xml:11 sssd-ifp.5.xml:11 #: sss_rpcidmapd.5.xml:27 sssd-session-recording.5.xml:11 @@ -59,26 +59,26 @@ msgid "5" msgstr "5" #. type: Content of: <reference><refentry><refmeta><refmiscinfo> -#: sssd.conf.5.xml:15 sssd-ldap.5.xml:12 sssd-simple.5.xml:12 +#: sssd.conf.5.xml:17 sssd-ldap.5.xml:12 sssd-simple.5.xml:12 #: sss-certmap.5.xml:12 sssd-ipa.5.xml:12 sssd-ad.5.xml:12 sssd-sudo.5.xml:12 #: sssd-idp.5.xml:12 sssd-krb5.5.xml:12 sssd-ifp.5.xml:12 #: sss_rpcidmapd.5.xml:28 sssd-session-recording.5.xml:12 sssd-kcm.8.xml:12 #: sssd-systemtap.5.xml:12 sssd-ldap-attributes.5.xml:12 msgid "File Formats and Conventions" -msgstr "Formatos de archivo y convenciones" +msgstr "Formatos de Archivo y Convenciones" #. type: Content of: <reference><refentry><refnamediv><refpurpose> -#: sssd.conf.5.xml:20 +#: sssd.conf.5.xml:22 msgid "the configuration file for SSSD" -msgstr "El archivo de configuración de SSSD" +msgstr "el archivo de configuración para SSSD" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:24 +#: sssd.conf.5.xml:26 msgid "FILE FORMAT" -msgstr "Formato de archivo" +msgstr "FORMATO DE ARCHIVO" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd.conf.5.xml:32 +#: sssd.conf.5.xml:34 #, no-wrap msgid "" "<replaceable>[section]</replaceable>\n" @@ -93,30 +93,31 @@ msgstr "" " " #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:27 +#: sssd.conf.5.xml:29 msgid "" "The file has an ini-style syntax and consists of sections and parameters. A " "section begins with the name of the section in square brackets and continues " "until the next section begins. An example of section with single and multi-" "valued parameters: <placeholder type=\"programlisting\" id=\"0\"/>" msgstr "" -"El archivo tiene una sintaxis de estilo-ini consistente de secciones y " +"El archivo tiene una sintaxis de estilo‐ini consistente de secciones y " "parámetros. Una sección comienza con el nombre de dicha sección colocado " "entre corchetes, y continua hasta que comienza la siguiente sección. Este es " "un ejemplo de una sección con parámetros de valores simples y múltiples: " "<placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:39 +#: sssd.conf.5.xml:41 msgid "" -"The data types used are string (no quotes needed), integer and bool (with " -"values of <quote>TRUE/FALSE</quote>)." +"The data types used are string (no quotes needed), integer and boolean (with " +"values of <quote>TRUE/FALSE</quote>). Boolean values are case-insensitive; " +"for example, <quote>TRUE</quote>, <quote>True</quote> and <quote>true</" +"quote> are all equivalent and valid; the same applies to <quote>FALSE</" +"quote>." msgstr "" -"Los tipos de datos utilizados son cadenas (no es necesario entrecomillado), " -"enteros o booleanos (cuyos valores son <quote>TRUE/FALSE</quote>)." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:44 +#: sssd.conf.5.xml:49 msgid "" "A comment line starts with a hash sign (<quote>#</quote>) or a semicolon " "(<quote>;</quote>). Inline comments are not supported." @@ -126,7 +127,7 @@ msgstr "" "admitidos." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:50 +#: sssd.conf.5.xml:55 msgid "" "All sections can have an optional <replaceable>description</replaceable> " "parameter. Its function is only as a label for the section." @@ -136,7 +137,7 @@ msgstr "" "para la sección." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:56 +#: sssd.conf.5.xml:61 msgid "" "<filename>sssd.conf</filename> must be a regular file that is owned, " "readable, and writeable only by 'root'." @@ -145,7 +146,7 @@ msgstr "" "legible, y escribible solo por 'root'." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:60 +#: sssd.conf.5.xml:65 msgid "" "<filename>sssd.conf</filename> must be a regular file that is accessible " "only by the user used to run SSSD service or root." @@ -154,12 +155,12 @@ msgstr "" "solo por el usuario utilizado para ejecutar el servicio SSSD o root." #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:66 +#: sssd.conf.5.xml:71 msgid "CONFIGURATION SNIPPETS FROM INCLUDE DIRECTORY" msgstr "FRAGMENTOS DE CONFIGURACIÓN DESDE EL DIRECTORIO INCLUDE" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:69 +#: sssd.conf.5.xml:74 msgid "" "The configuration file <filename>sssd.conf</filename> will include " "configuration snippets using the include directory <filename>conf.d</" @@ -170,7 +171,7 @@ msgstr "" "filename>." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:75 +#: sssd.conf.5.xml:80 msgid "" "Any file placed in <filename>conf.d</filename> that ends in " "<quote><filename>.conf</filename></quote> and does not begin with a dot " @@ -183,7 +184,7 @@ msgstr "" "configurar SSSD." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:83 +#: sssd.conf.5.xml:88 msgid "" "The configuration snippets from <filename>conf.d</filename> have higher " "priority than <filename>sssd.conf</filename> and will override " @@ -204,7 +205,7 @@ msgstr "" "prioridad (números mas altos significan prioridad más alta)." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:97 +#: sssd.conf.5.xml:102 msgid "" "The snippet files require the same owner and permissions as " "<filename>sssd.conf</filename>." @@ -213,34 +214,87 @@ msgstr "" "<filename>sssd.conf</filename>." #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:103 +#: sssd.conf.5.xml:108 +#, fuzzy +#| msgid "TRUSTED DOMAINS CONFIGURATION" +msgid "VENDOR PROVIDED CONFIGURATION" +msgstr "CONFIGURACIÓN DE DOMINIOS DE CONFIANZA" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:111 +msgid "" +"The vendor provided configuration file is installed in " +"<filename>&sssd_vendor_dir;/sssd.conf</filename>, but this file must not be " +"directly edited. It can be completely masked by creating the system specific " +"configuration file <filename>&sssd_conf_dir;/sssd.conf</filename>, or partly " +"overriden by creating config snippets in <filename>&sssd_conf_dir;/conf.d</" +"filename> directory." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><title> +#: sssd.conf.5.xml:120 +#, fuzzy +#| msgid "CONFIGURATION FILE" +msgid "CONFIGURATION FILE HIERARCHY" +msgstr "ARCHIVO DE CONFIGURACIÓN" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:122 +msgid "" +"When sssd reads the configuration it first tries to open the system specific " +"configuration file in <filename>&sssd_conf_dir;/sssd.conf</filename>. If it " +"exists, it is loaded and snippets from <filename>&sssd_conf_dir;/conf.d</" +"filename> are applied. The vendor provided configuration file " +"<filename>&sssd_vendor_dir;/sssd.conf</filename> is completely ignored in " +"this case." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:131 +msgid "" +"If the system specific configuration file <filename>&sssd_conf_dir;/" +"sssd.conf</filename> does not exist, then the vendor configuration file " +"<filename>&sssd_vendor_dir;/sssd.conf</filename> is loaded and snippets from " +"<filename>&sssd_conf_dir;/conf.d</filename> are applied." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd.conf.5.xml:141 msgid "GENERAL OPTIONS" msgstr "OPCIONES GENERALES" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:105 +#: sssd.conf.5.xml:143 msgid "Following options are usable in more than one configuration sections." msgstr "" "Las siguientes opciones son útiles en más de una de las secciones de " "configuración." #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:109 +#: sssd.conf.5.xml:147 msgid "Options usable in all sections" msgstr "Opciones utilizables en todas las secciones" +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:149 +msgid "" +"Note: Below options are ignored in <quote>[session_recording]</quote> " +"section, see <quote>Session recording configuration options</quote> section " +"for more details." +msgstr "" + #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:113 +#: sssd.conf.5.xml:156 msgid "debug_level (integer)" msgstr "debug_level (entero)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:117 +#: sssd.conf.5.xml:160 msgid "debug (integer)" msgstr "debug (entero)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:120 +#: sssd.conf.5.xml:163 msgid "" "SSSD 1.14 and later also includes the <replaceable>debug</replaceable> alias " "for <replaceable>debug_level</replaceable> as a convenience feature. If both " @@ -253,12 +307,14 @@ msgstr "" "<replaceable>debug_level</replaceable>." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:130 -msgid "debug_timestamps (bool)" +#: sssd.conf.5.xml:173 +#, fuzzy +#| msgid "debug_timestamps (bool)" +msgid "debug_timestamps (boolean)" msgstr "debug_timestamps (bool)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:133 +#: sssd.conf.5.xml:176 msgid "" "Add a timestamp to the debug messages. If journald is enabled for SSSD " "debug logging this option is ignored." @@ -268,23 +324,25 @@ msgstr "" "omiso." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:138 sssd.conf.5.xml:175 sssd.conf.5.xml:337 -#: sssd.conf.5.xml:644 sssd.conf.5.xml:668 sssd.conf.5.xml:875 -#: sssd.conf.5.xml:979 sssd.conf.5.xml:2113 sssd-ldap.5.xml:979 -#: sssd-ldap.5.xml:1134 sssd-ldap.5.xml:1237 sssd-ldap.5.xml:1306 -#: sssd-ldap.5.xml:1714 sssd-ldap.5.xml:1848 sssd-ldap.5.xml:1913 -#: sssd-ipa.5.xml:346 sssd-ad.5.xml:252 sssd-ad.5.xml:367 sssd-ad.5.xml:1180 -#: sssd-ad.5.xml:1382 sssd-krb5.5.xml:358 +#: sssd.conf.5.xml:181 sssd.conf.5.xml:218 sssd.conf.5.xml:380 +#: sssd.conf.5.xml:687 sssd.conf.5.xml:711 sssd.conf.5.xml:827 +#: sssd.conf.5.xml:932 sssd.conf.5.xml:2149 sssd.conf.5.xml:4730 +#: sssd-ldap.5.xml:979 sssd-ldap.5.xml:1134 sssd-ldap.5.xml:1237 +#: sssd-ldap.5.xml:1306 sssd-ldap.5.xml:1714 sssd-ldap.5.xml:1848 +#: sssd-ldap.5.xml:1913 sssd-ipa.5.xml:341 sssd-ad.5.xml:252 sssd-ad.5.xml:367 +#: sssd-ad.5.xml:1180 sssd-ad.5.xml:1375 sssd-krb5.5.xml:358 msgid "Default: true" msgstr "Predeterminado: true" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:143 -msgid "debug_microseconds (bool)" +#: sssd.conf.5.xml:186 +#, fuzzy +#| msgid "debug_microseconds (bool)" +msgid "debug_microseconds (boolean)" msgstr "debug_microseconds (bool)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:146 +#: sssd.conf.5.xml:189 msgid "" "Add microseconds to the timestamp in debug messages. If journald is enabled " "for SSSD debug logging this option is ignored." @@ -294,26 +352,28 @@ msgstr "" "se hace caso omiso." #. type: Content of: <variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:151 sssd.conf.5.xml:2040 sssd.conf.5.xml:4158 +#: sssd.conf.5.xml:194 sssd.conf.5.xml:2072 sssd.conf.5.xml:4363 #: sssd-ldap.5.xml:363 sssd-ldap.5.xml:998 sssd-ldap.5.xml:1209 -#: sssd-ldap.5.xml:1663 sssd-ldap.5.xml:1937 sssd-ipa.5.xml:146 -#: sssd-ipa.5.xml:706 sssd-ad.5.xml:1135 sssd-krb5.5.xml:268 +#: sssd-ldap.5.xml:1663 sssd-ldap.5.xml:1937 sssd-ipa.5.xml:141 +#: sssd-ipa.5.xml:701 sssd-ad.5.xml:1140 sssd-idp.5.xml:287 sssd-krb5.5.xml:268 #: sssd-krb5.5.xml:330 sssd-krb5.5.xml:432 include/krb5_options.xml:163 msgid "Default: false" msgstr "Predeterminado: false" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:156 -msgid "debug_backtrace_enabled (bool)" +#: sssd.conf.5.xml:199 +#, fuzzy +#| msgid "debug_backtrace_enabled (bool)" +msgid "debug_backtrace_enabled (boolean)" msgstr "debug_backtrace_enabled (bool)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:159 +#: sssd.conf.5.xml:202 msgid "Enable debug backtrace." msgstr "Habilita el seguimiento de depuración." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:162 +#: sssd.conf.5.xml:205 msgid "" "In case SSSD is run with debug_level less than 9, everything is logged to a " "ring buffer in memory and flushed to a log file on any error up to and " @@ -328,7 +388,7 @@ msgstr "" "una traza, de lo contrario hasta 2)." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:171 +#: sssd.conf.5.xml:214 msgid "" "Feature is only supported for `logger == files` (i.e. setting doesn't have " "effect for other logger types)." @@ -337,7 +397,7 @@ msgstr "" "configuración no tiene efecto para otro tipo de bitácora)." #. type: Content of: outside any tag (error?) -#: sssd.conf.5.xml:111 sssd.conf.5.xml:186 sssd-ldap.5.xml:1754 +#: sssd.conf.5.xml:154 sssd.conf.5.xml:229 sssd-ldap.5.xml:1754 #: sssd-ldap.5.xml:1960 sss-certmap.5.xml:645 sssd-systemtap.5.xml:82 #: sssd-systemtap.5.xml:143 sssd-systemtap.5.xml:236 sssd-systemtap.5.xml:274 #: sssd-systemtap.5.xml:330 sssd-ldap-attributes.5.xml:40 @@ -350,17 +410,17 @@ msgid "<placeholder type=\"variablelist\" id=\"0\"/>" msgstr "<placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:184 +#: sssd.conf.5.xml:227 msgid "Options usable in SERVICE and DOMAIN sections" msgstr "Opciones utilizables en las secciones SERVICIO y DOMINIO" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:188 +#: sssd.conf.5.xml:231 msgid "timeout (integer)" msgstr "timeout (entero)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:191 +#: sssd.conf.5.xml:234 msgid "" "Timeout in seconds between heartbeats for this service. This is used to " "ensure that the process is alive and capable of answering requests. Note " @@ -371,34 +431,36 @@ msgstr "" "que después de tres pulsaciones ausentes el servicio se terminará." #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:198 sssd.conf.5.xml:1199 sssd.conf.5.xml:1673 -#: sssd.conf.5.xml:4174 sssd-ldap.5.xml:825 sssd-idp.5.xml:192 +#: sssd.conf.5.xml:241 sssd.conf.5.xml:1155 sssd.conf.5.xml:1665 +#: sssd.conf.5.xml:4379 sssd-ldap.5.xml:825 sssd-idp.5.xml:271 #: include/ldap_id_mapping.xml:270 msgid "Default: 10" msgstr "Predeterminado: 10" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:208 +#: sssd.conf.5.xml:251 msgid "SPECIAL SECTIONS" msgstr "SECCIONES ESPECIALES" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:211 +#: sssd.conf.5.xml:254 msgid "The [sssd] section" msgstr "La sección [sssd]" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><title> -#: sssd.conf.5.xml:220 +#: sssd.conf.5.xml:263 msgid "Section parameters" msgstr "Parámetros de sección" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:222 -msgid "services" -msgstr "servicios" +#: sssd.conf.5.xml:265 +#, fuzzy +#| msgid "users (string)" +msgid "services (string)" +msgstr "users (cadena)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:225 +#: sssd.conf.5.xml:268 msgid "" "Comma separated list of services that are started when sssd itself starts. " "<phrase condition=\"have_systemd\"> The services' list is optional on " @@ -411,7 +473,7 @@ msgstr "" "serán enchufados o activado D-Bus cuando sea necesario. </phrase>" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:234 +#: sssd.conf.5.xml:277 msgid "" "Supported services: nss, pam, ifp <phrase condition=\"with_sudo\">, sudo</" "phrase> <phrase condition=\"with_autofs\">, autofs</phrase> <phrase " @@ -424,7 +486,7 @@ msgstr "" "condition=\"with_pac_responder\">, pac</phrase>" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:241 +#: sssd.conf.5.xml:284 msgid "" "<phrase condition=\"have_systemd\"> By default, all services are disabled " "and the administrator must enable the ones allowed to be used by executing: " @@ -434,13 +496,13 @@ msgstr "" "deshabilitados y el administrador debe habilitar aquellos que permita que se " "usen para ejecución: \"systemctl enable sssd-@service@.socket\". </phrase>" -#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:250 -msgid "domains" -msgstr "dominios" +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sssd.conf.5.xml:293 sssd.conf.5.xml:4562 +msgid "domains (string)" +msgstr "domains (cadena)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:253 +#: sssd.conf.5.xml:296 msgid "" "A domain is a database containing user information. SSSD can use more " "domains at the same time, but at least one must be configured or SSSD won't " @@ -457,12 +519,12 @@ msgstr "" "bajos. El carácter '/' está prohibido." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:266 sssd.conf.5.xml:3467 +#: sssd.conf.5.xml:309 sssd.conf.5.xml:3598 msgid "re_expression (string)" msgstr "re_expression (cadena)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:269 +#: sssd.conf.5.xml:312 msgid "" "Default regular expression that describes how to parse the string containing " "user name and domain into these components." @@ -471,7 +533,7 @@ msgstr "" "contiene el nombre de usuario y el dominio en estos componentes." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:274 +#: sssd.conf.5.xml:317 msgid "" "Each domain can have an individual regular expression configured. For some " "ID providers there are also default regular expressions. See DOMAIN SECTIONS " @@ -483,12 +545,12 @@ msgstr "" "regulares." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:283 sssd.conf.5.xml:3524 +#: sssd.conf.5.xml:326 sssd.conf.5.xml:3655 msgid "full_name_format (string)" msgstr "full_name_format (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:286 sssd.conf.5.xml:3527 +#: sssd.conf.5.xml:329 sssd.conf.5.xml:3658 msgid "" "A <citerefentry> <refentrytitle>printf</refentrytitle> <manvolnum>3</" "manvolnum> </citerefentry>-compatible format that describes how to compose a " @@ -500,32 +562,32 @@ msgstr "" "dominio." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:297 sssd.conf.5.xml:3538 +#: sssd.conf.5.xml:340 sssd.conf.5.xml:3669 msgid "%1$s" msgstr "%1$s" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:298 sssd.conf.5.xml:3539 +#: sssd.conf.5.xml:341 sssd.conf.5.xml:3670 msgid "user name" msgstr "nombre de usuario" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:301 sssd.conf.5.xml:3542 +#: sssd.conf.5.xml:344 sssd.conf.5.xml:3673 msgid "%2$s" msgstr "%2$s" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:304 sssd.conf.5.xml:3545 +#: sssd.conf.5.xml:347 sssd.conf.5.xml:3676 msgid "domain name as specified in the SSSD config file." msgstr "nombre de dominio como especificó en el archivo de configuración SSSD." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:310 sssd.conf.5.xml:3551 +#: sssd.conf.5.xml:353 sssd.conf.5.xml:3682 msgid "%3$s" msgstr "%3$s" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:313 sssd.conf.5.xml:3554 +#: sssd.conf.5.xml:356 sssd.conf.5.xml:3685 msgid "" "domain flat name. Mostly usable for Active Directory domains, both directly " "configured or discovered via IPA trusts." @@ -535,7 +597,7 @@ msgstr "" "de confianza." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:294 sssd.conf.5.xml:3535 +#: sssd.conf.5.xml:337 sssd.conf.5.xml:3666 msgid "" "The following expansions are supported: <placeholder type=\"variablelist\" " "id=\"0\"/>" @@ -544,7 +606,7 @@ msgstr "" "id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:323 +#: sssd.conf.5.xml:366 msgid "" "Each domain can have an individual format string configured. See DOMAIN " "SECTIONS for more info on this option." @@ -553,12 +615,12 @@ msgstr "" "Consulte SECCIONES DE DOMINIO para más información sobre esta opción." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:329 +#: sssd.conf.5.xml:372 msgid "monitor_resolv_conf (boolean)" msgstr "monitor_resolv_conf (booleano)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:332 +#: sssd.conf.5.xml:375 msgid "" "Controls if SSSD should monitor the state of resolv.conf to identify when it " "needs to update its internal DNS resolver." @@ -567,12 +629,12 @@ msgstr "" "cuando necesita actualizar su interfaz de resolución DNS interno." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:342 +#: sssd.conf.5.xml:385 msgid "try_inotify (boolean)" msgstr "try_inotify (boolean)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:345 +#: sssd.conf.5.xml:388 msgid "" "By default, SSSD will attempt to use inotify to monitor configuration files " "changes and will fall back to polling every five seconds if inotify cannot " @@ -583,7 +645,7 @@ msgstr "" "no puede ser usado." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:351 +#: sssd.conf.5.xml:394 msgid "" "There are some limited situations where it is preferred that we should skip " "even trying to use inotify. In these rare cases, this option should be set " @@ -593,7 +655,7 @@ msgstr "" "inotify. En estos casos raros, esta opción sería establecida a 'false'" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:357 +#: sssd.conf.5.xml:400 msgid "" "Default: true on platforms where inotify is supported. False on other " "platforms." @@ -602,7 +664,7 @@ msgstr "" "en el resto de las plataformas." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:361 +#: sssd.conf.5.xml:404 msgid "" "Note: this option will have no effect on platforms where inotify is " "unavailable. On these platforms, polling will always be used." @@ -611,12 +673,12 @@ msgstr "" "encuentre disponible. En estas plataformas, el sondeo será utilizada siempre." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:368 +#: sssd.conf.5.xml:411 msgid "krb5_rcache_dir (string)" msgstr "krb5_rcache_dir (cadena)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:371 +#: sssd.conf.5.xml:414 msgid "" "Directory on the filesystem where SSSD should store Kerberos replay cache " "files." @@ -625,7 +687,7 @@ msgstr "" "reproducción de cache de Kerberos." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:375 +#: sssd.conf.5.xml:418 msgid "" "This option accepts a special value __LIBKRB5_DEFAULTS__ that will instruct " "SSSD to let libkrb5 decide the appropriate location for the replay cache." @@ -634,7 +696,7 @@ msgstr "" "SSSD para dejar a libkrb5 decidir el lugar apropiado del caché de respuesta." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:381 +#: sssd.conf.5.xml:424 msgid "" "Default: Distribution-specific and specified at build-time. " "(__LIBKRB5_DEFAULTS__ if not configured)" @@ -643,12 +705,12 @@ msgstr "" "compilación. (__LIBKRB5_DEFAULTS__ si no se configura)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:388 +#: sssd.conf.5.xml:431 msgid "default_domain_suffix (string)" msgstr "default_domain_suffix (cadena)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:391 +#: sssd.conf.5.xml:434 msgid "" "Please note that this option is deprecated and domain_resolution_order " "should be used." @@ -657,7 +719,7 @@ msgstr "" "utilizada." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:395 +#: sssd.conf.5.xml:438 msgid "" "This string will be used as a default domain name for all names without a " "domain name component. The main use case is environments where the primary " @@ -673,7 +735,7 @@ msgstr "" "usuario sin dar también un nombre de dominio." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:405 +#: sssd.conf.5.xml:448 msgid "" "Please note that if this option is set all users from the primary domain " "have to use their fully qualified name, e.g. user@domain.name, to log in. " @@ -689,21 +751,21 @@ msgstr "" "establecido a False." #. type: Content of: <variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:414 sssd-ldap.5.xml:937 sssd-ldap.5.xml:949 -#: sssd-ldap.5.xml:1042 sssd-ad.5.xml:921 sssd-ad.5.xml:996 sssd-krb5.5.xml:468 -#: sssd-ldap-attributes.5.xml:470 sssd-ldap-attributes.5.xml:978 -#: include/ldap_id_mapping.xml:211 include/ldap_id_mapping.xml:222 -#: include/krb5_options.xml:148 +#: sssd.conf.5.xml:457 sssd.conf.5.xml:2006 sssd-ldap.5.xml:937 +#: sssd-ldap.5.xml:949 sssd-ldap.5.xml:1042 sssd-ad.5.xml:926 +#: sssd-ad.5.xml:1001 sssd-krb5.5.xml:468 sssd-ldap-attributes.5.xml:470 +#: sssd-ldap-attributes.5.xml:978 include/ldap_id_mapping.xml:211 +#: include/ldap_id_mapping.xml:222 include/krb5_options.xml:148 msgid "Default: not set" msgstr "Predeterminado: no definido" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:419 +#: sssd.conf.5.xml:462 msgid "override_space (string)" msgstr "override_space (cadena)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:422 +#: sssd.conf.5.xml:465 msgid "" "This parameter will replace spaces (space bar) with the given character for " "user and group names. e.g. (_). User name "john doe" will be " @@ -719,7 +781,7 @@ msgstr "" "predeterminado en el intérprete." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:431 +#: sssd.conf.5.xml:474 msgid "" "Please note it is a configuration error to use a replacement character that " "might be used in user or group names. If a name contains the replacement " @@ -732,22 +794,22 @@ msgstr "" "no modificado pero en general el resultado de la búsqueda es indefinido." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:439 +#: sssd.conf.5.xml:482 msgid "Default: not set (spaces will not be replaced)" msgstr "Por defecto: no ajustado (los espacios no serán reemplazados)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:444 +#: sssd.conf.5.xml:487 msgid "certificate_verification (string)" msgstr "certificate_verification (cadena)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:452 +#: sssd.conf.5.xml:495 msgid "no_ocsp" msgstr "no_ocsp" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:454 +#: sssd.conf.5.xml:497 msgid "" "Disables Online Certificate Status Protocol (OCSP) checks. This might be " "needed if the OCSP servers defined in the certificate are not reachable from " @@ -758,12 +820,12 @@ msgstr "" "certificado no son alcanzables por el cliente." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:462 +#: sssd.conf.5.xml:505 msgid "soft_ocsp" msgstr "soft_ocsp" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:464 +#: sssd.conf.5.xml:507 msgid "" "If a connection cannot be established to an OCSP responder the OCSP check is " "skipped. This option should be used to allow authentication when the system " @@ -775,12 +837,12 @@ msgstr "" "puede ser alcanzado." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:474 +#: sssd.conf.5.xml:517 msgid "ocsp_dgst" msgstr "ocsp_dgst" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:476 +#: sssd.conf.5.xml:519 msgid "" "Digest (hash) function used to create the certificate ID for the OCSP " "request. Allowed values are:" @@ -789,39 +851,39 @@ msgstr "" "petición OCSP. Los valores permitidos son:" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:480 +#: sssd.conf.5.xml:523 msgid "sha1" msgstr "sha1" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:481 +#: sssd.conf.5.xml:524 msgid "sha256" msgstr "sha256" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:482 +#: sssd.conf.5.xml:525 msgid "sha384" msgstr "sha384" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:483 +#: sssd.conf.5.xml:526 msgid "sha512" msgstr "sha512" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:486 +#: sssd.conf.5.xml:529 msgid "Default: sha1 (to allow compatibility with RFC5019-compliant responder)" msgstr "" "Predeterminado: sha1 (para permitir la compatibilidad con el contestador que " "cumple el RFC50190)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:492 +#: sssd.conf.5.xml:535 msgid "no_verification" msgstr "no_verification" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:494 +#: sssd.conf.5.xml:537 msgid "" "Disables verification completely. This option should only be used for " "testing." @@ -830,12 +892,12 @@ msgstr "" "para pruebas." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:500 +#: sssd.conf.5.xml:543 msgid "partial_chain" msgstr "partial_chain" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:502 +#: sssd.conf.5.xml:545 msgid "" "Allow verification to succeed even if a <replaceable>complete</replaceable> " "chain cannot be built to a self-signed trust-anchor, provided it is possible " @@ -847,12 +909,12 @@ msgstr "" "que puede no estar auto-firmado." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:511 +#: sssd.conf.5.xml:554 msgid "ocsp_default_responder=URL" msgstr "ocsp_default_responder=URL" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:513 +#: sssd.conf.5.xml:556 msgid "" "Sets the OCSP default responder which should be used instead of the one " "mentioned in the certificate. URL must be replaced with the URL of the OCSP " @@ -863,12 +925,12 @@ msgstr "" "OCSP por defecto e.g. http://ejemplo.com:80/ocsp." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:523 +#: sssd.conf.5.xml:566 msgid "ocsp_default_responder_signing_cert=NAME" msgstr "ocsp_default_responder_signing_cert=NOMBRE" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:525 +#: sssd.conf.5.xml:568 msgid "" "This option is currently ignored. All needed certificates must be available " "in the PEM file given by pam_cert_db_path." @@ -877,12 +939,12 @@ msgstr "" "estar disponibles en el archivo PEM indicado por pam_cert_db_path." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:533 +#: sssd.conf.5.xml:576 msgid "crl_file=/PATH/TO/CRL/FILE" msgstr "crl_file=/RUTA/AL/ARCHIVO/CRL" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:535 +#: sssd.conf.5.xml:578 msgid "" "Use the Certificate Revocation List (CRL) from the given file during the " "verification of the certificate. The CRL must be given in PEM format, see " @@ -895,12 +957,12 @@ msgstr "" "1ssl</manvolnum> </citerefentry>." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:548 +#: sssd.conf.5.xml:591 msgid "soft_crl" msgstr "soft_crl" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:551 +#: sssd.conf.5.xml:594 msgid "" "If a Certificate Revocation List (CRL) is expired ignore the expiration " "time of the CRL and check the related certificates with the expired CRL. " @@ -914,7 +976,7 @@ msgstr "" "renovado." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:447 +#: sssd.conf.5.xml:490 msgid "" "With this parameter the certificate verification can be tuned with a comma " "separated list of options. Supported options are: <placeholder " @@ -925,23 +987,23 @@ msgstr "" "<placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:564 +#: sssd.conf.5.xml:607 msgid "Unknown options are reported but ignored." msgstr "Se informa de las opciones desconocidas pero son ignoradas." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:567 +#: sssd.conf.5.xml:610 msgid "Default: not set, i.e. do not restrict certificate verification" msgstr "" "Por defecto: no fijado, i.e. no restringe la verificación de certificado" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:573 +#: sssd.conf.5.xml:616 msgid "disable_netlink (boolean)" msgstr "disable_netlink (boolean)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:576 +#: sssd.conf.5.xml:619 msgid "" "SSSD hooks into the netlink interface to monitor changes to routes, " "addresses, links and trigger certain actions." @@ -950,7 +1012,7 @@ msgstr "" "rutas, direcciones, enlaces y disparar ciertas acciones." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:581 +#: sssd.conf.5.xml:624 msgid "" "The SSSD state changes caused by netlink events may be undesirable and can " "be disabled by setting this option to 'true'" @@ -960,17 +1022,19 @@ msgstr "" "'true'" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:586 +#: sssd.conf.5.xml:629 msgid "Default: false (netlink changes are detected)" msgstr "Predeterminado: false (se detectan los cambio de enlace de red)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:591 -msgid "domain_resolution_order" +#: sssd.conf.5.xml:634 +#, fuzzy +#| msgid "domain_resolution_order" +msgid "domain_resolution_order (string)" msgstr "domain_resolution_order" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:594 +#: sssd.conf.5.xml:637 msgid "" "Comma separated list of domains and subdomains representing the lookup order " "that will be followed. The list doesn't have to include all possible " @@ -987,7 +1051,7 @@ msgstr "" "serán buscados en un orden aleatorio por cada dominio padre." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:606 +#: sssd.conf.5.xml:649 msgid "" "Please, note that when this option is set the output format of all commands " "is always fully-qualified even when using short names for input. In case " @@ -1016,19 +1080,20 @@ msgstr "" "casos donde los nombres de usuarios se deben compartir entre dominios." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:630 sssd.conf.5.xml:1697 sssd.conf.5.xml:4224 -#: sssd-ad.5.xml:187 sssd-ad.5.xml:328 sssd-ad.5.xml:342 sssd-idp.5.xml:108 -#: sssd-idp.5.xml:132 sssd-idp.5.xml:145 sssd-idp.5.xml:159 sssd-idp.5.xml:180 +#: sssd.conf.5.xml:673 sssd.conf.5.xml:1026 sssd.conf.5.xml:1689 +#: sssd.conf.5.xml:4429 sssd-ad.5.xml:187 sssd-ad.5.xml:328 sssd-ad.5.xml:342 +#: sssd-idp.5.xml:112 sssd-idp.5.xml:136 sssd-idp.5.xml:149 sssd-idp.5.xml:167 +#: sssd-idp.5.xml:188 msgid "Default: Not set" msgstr "Por defecto: No definido" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:635 +#: sssd.conf.5.xml:678 msgid "implicit_pac_responder (boolean)" msgstr "implicit_pac_responder (boolean)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:638 +#: sssd.conf.5.xml:681 msgid "" "The PAC responder is enabled automatically for the IPA and AD provider to " "evaluate and check the PAC. If it has to be disabled set this option to " @@ -1039,12 +1104,12 @@ msgstr "" "opción a 'false'." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:649 +#: sssd.conf.5.xml:692 msgid "core_dumpable (boolean)" msgstr "core_dumpable (boolean)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:652 +#: sssd.conf.5.xml:695 msgid "" "This option can be used for general system hardening: setting it to 'false' " "forbids core dumps for all SSSD processes to avoid leaking plain text " @@ -1058,7 +1123,7 @@ msgstr "" "detalles." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:660 +#: sssd.conf.5.xml:703 msgid "" "Take a note that this setting has no effect for 'ldap_child', 'krb5_child' " "and 'sssd_pam' as those privileged binaries can have a copy of a host keytab " @@ -1072,17 +1137,17 @@ msgstr "" "sistema." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:673 +#: sssd.conf.5.xml:716 msgid "passkey_verification (string)" msgstr "passkey_verification (cadena)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:681 +#: sssd.conf.5.xml:724 msgid "user_verification (boolean)" msgstr "user_verification (booleano)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:683 +#: sssd.conf.5.xml:726 msgid "" "Enable or disable the user verification (i.e. PIN, fingerprint) during " "authentication. If enabled, the PIN will always be requested." @@ -1091,7 +1156,7 @@ msgstr "" "durante autenticación. Si activado, el PIN siempre será solicitado." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:689 +#: sssd.conf.5.xml:732 msgid "" "The default is that the key settings decide what to do. In the IPA or " "kerberos pre-authentication case, this value will be overwritten by the " @@ -1102,7 +1167,7 @@ msgstr "" "el servidor." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:676 +#: sssd.conf.5.xml:719 msgid "" "With this parameter the passkey verification can be tuned with a comma " "separated list of options. Supported options are: <placeholder " @@ -1113,7 +1178,7 @@ msgstr "" "soportadas son: <placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:213 +#: sssd.conf.5.xml:256 msgid "" "Individual pieces of SSSD functionality are provided by special SSSD " "services that are started and stopped together with SSSD. The services are " @@ -1130,12 +1195,12 @@ msgstr "" "<placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:708 +#: sssd.conf.5.xml:751 msgid "SERVICES SECTIONS" msgstr "SECCIONES DE SERVICIOS" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:710 +#: sssd.conf.5.xml:753 msgid "" "Settings that can be used to configure different services are described in " "this section. They should reside in the [<replaceable>$NAME</replaceable>] " @@ -1148,28 +1213,36 @@ msgstr "" "<quote>[nss]</quote>" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:717 +#: sssd.conf.5.xml:760 msgid "General service configuration options" msgstr "Opciones de configuración de servicios generales" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:719 +#: sssd.conf.5.xml:762 msgid "These options can be used to configure any service." msgstr "Estas opciones pueden usarse para configurar cualquier servicio." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:723 -msgid "fd_limit" -msgstr "fd_limit" +#: sssd.conf.5.xml:766 +#, fuzzy +#| msgid "wildcard_limit (integer)" +msgid "fd_limit (integer)" +msgstr "wildcard_limit (entero)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:726 +#: sssd.conf.5.xml:769 +#, fuzzy +#| msgid "" +#| "This option specifies the maximum number of file descriptors that may be " +#| "opened at one time by this SSSD process. On systems where SSSD is granted " +#| "the CAP_SYS_RESOURCE capability, this will be an absolute setting. On " +#| "systems without this capability, the resulting value will be the lower " +#| "value of this or the limits.conf \"hard\" limit." msgid "" "This option specifies the maximum number of file descriptors that may be " -"opened at one time by this SSSD process. On systems where SSSD is granted " -"the CAP_SYS_RESOURCE capability, this will be an absolute setting. On " -"systems without this capability, the resulting value will be the lower value " -"of this or the limits.conf \"hard\" limit." +"opened at one time by this SSSD process. Note this value will be capped by " +"the init system at the startup of SSSD, see e.g. man systemd.exec for " +"details." msgstr "" "Esta opción especifica el número máximo de descriptores de ficheros que " "pueden ser abiertos a la vez por este proceso SSSD. Sobre sistemas donde " @@ -1178,17 +1251,19 @@ msgstr "" "valor más bajo de este o de limite “hard” en limits.conf." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:735 +#: sssd.conf.5.xml:776 msgid "Default: 8192 (or limits.conf \"hard\" limit)" msgstr "Por defecto: 8192 (o limite “hard” en limits.conf)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:740 -msgid "client_idle_timeout" -msgstr "client_idle_timeout" +#: sssd.conf.5.xml:781 +#, fuzzy +#| msgid "offline_timeout (integer)" +msgid "client_idle_timeout (integer)" +msgstr "offline_timeout (entero)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:743 +#: sssd.conf.5.xml:784 msgid "" "This option specifies the number of seconds that a client of an SSSD process " "can hold onto a file descriptor without communicating on it. This value is " @@ -1203,170 +1278,19 @@ msgstr "" "configura un valor más bajo será ajustado a 10 segundos." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:752 +#: sssd.conf.5.xml:793 msgid "Default: 60, KCM: 300" msgstr "Predeterminado: 60, KCM: 300" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:757 -msgid "offline_timeout (integer)" -msgstr "offline_timeout (entero)" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:760 -msgid "" -"When SSSD switches to offline mode the amount of time before it tries to go " -"back online will increase based upon the time spent disconnected. By " -"default SSSD uses incremental behaviour to calculate delay in between " -"retries. So, the wait time for a given retry will be longer than the wait " -"time for the previous ones. After each unsuccessful attempt to go online, " -"the new interval is recalculated by the following:" -msgstr "" -"Cuando SSSD conmuta al modo fuera de línea la cantidad tiempo antes de que " -"intente volver a estar en línea se incrementará en base al tiempo que ha " -"estado desconectado. De modo predeterminado SSSD utiliza un comportamiento " -"incremental para calcular el retraso entre reintentos. De este modo, el " -"tiempo de espera para un reintento dado no será más largo que el tiempo de " -"los anteriores. Después de cada intento fracasado para estar en línea, el " -"nuevo intervalo se calcula mediante lo siguiente:" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:771 sssd.conf.5.xml:827 -msgid "" -"new_delay = Minimum(old_delay * 2, offline_timeout_max) + " -"random[0...offline_timeout_random_offset]" -msgstr "" -"new_delay = Minimum(old_delay * 2, offline_timeout_max) + " -"random[0...offline_timeout_random_offset]" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:774 -msgid "" -"The offline_timeout default value is 60. The offline_timeout_max default " -"value is 3600. The offline_timeout_random_offset default value is 30. The " -"end result is amount of seconds before next retry." -msgstr "" -"El valor predeterminado de offline_timeout es 60. El valor predeterminado de " -"offline_timeout_max es 3600. El valor predeterminado de " -"offline_timeout_random_offset es 30. El resultado final es la cantidad de " -"segundos antes del próximo reintento." - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:780 -msgid "" -"Note that the maximum length of each interval is defined by " -"offline_timeout_max (apart of random part)." -msgstr "" -"Note que la longitud máxima de cada intervalo está definido por " -"offline_timeout_max (a parte de parte aleatoria)." - -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:784 sssd.conf.5.xml:1110 sssd.conf.5.xml:1490 -#: sssd.conf.5.xml:1791 sssd-ldap.5.xml:550 -msgid "Default: 60" -msgstr "Predeterminado: 60" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:789 -msgid "offline_timeout_max (integer)" -msgstr "offline_timeout_max (entero)" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:792 -msgid "" -"Controls by how much the time between attempts to go online can be " -"incremented following unsuccessful attempts to go online." -msgstr "" -"Controla cuanto tiempo entre intentos para conectar puede ser incrementado " -"seguido de intentos incorrectos para ir a en línea." - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:797 -msgid "A value of 0 disables the incrementing behaviour." -msgstr "Un valor de 0 deshabilita el comportamiento de incremento." - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:800 -msgid "" -"The value of this parameter should be set in correlation to offline_timeout " -"parameter value." -msgstr "" -"el valor de este parámetro sería puesto en correlación al valor del " -"parámetro online_timeout." - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:804 -msgid "" -"With offline_timeout set to 60 (default value) there is no point in setting " -"offlinet_timeout_max to less than 120 as it will saturate instantly. General " -"rule here should be to set offline_timeout_max to at least 4 times " -"offline_timeout." -msgstr "" -"Con establecer offline_timeout a 60 (valor por defecto) no hay ningún punto " -"en establecer offline_timeout_max a menor que 120 como saturará " -"intantemente. La regla general aquí sería establecer offline-timeout_max a " -"al menos 4 veces offline_timeout." - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:810 -msgid "" -"Although a value between 0 and offline_timeout may be specified, it has the " -"effect of overriding the offline_timeout value so is of little use." -msgstr "" -"Aunque un valor entre 0 y offline_timeout puede ser especificado, tiene el " -"efecto de sobrescribir el valor offline_timeout tal que es de poco uso." - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:815 -msgid "Default: 3600" -msgstr "Predeterminado: 3600" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:820 -msgid "offline_timeout_random_offset (integer)" -msgstr "offline_timeout_random_offset (entero)" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:823 -msgid "" -"When SSSD is in offline mode it keeps probing backend servers in specified " -"time intervals:" -msgstr "" -"Cuando SSSD está en modo desconectado mantiene probar servidores de backend " -"internos a intervalos de tiempo especificados:" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:830 -msgid "" -"This parameter controls the value of the random offset used for the above " -"equation. Final random_offset value will be random number in range:" -msgstr "" -"Este parámetro controla el valor de desplazamiento aleatorio utilizado para " -"la ecuación de arriba. El valor final de random_offset será número aleatorio " -"dentro del intervalo:" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:835 -msgid "[0 - offline_timeout_random_offset]" -msgstr "[0 - offline_timeout_random_offset]" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:838 -msgid "A value of 0 disables the random offset addition." -msgstr "Un valor de 0 desactiva la adición del desplazamiento aleatorio." - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:841 -msgid "Default: 30" -msgstr "Predeterminado: 30" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:846 -msgid "responder_idle_timeout" +#: sssd.conf.5.xml:798 +#, fuzzy +#| msgid "responder_idle_timeout" +msgid "responder_idle_timeout (integer)" msgstr "responder_idle_timeout" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:849 +#: sssd.conf.5.xml:801 msgid "" "This option specifies the number of seconds that an SSSD responder process " "can be up without being used. This value is limited in order to avoid " @@ -1385,18 +1309,20 @@ msgstr "" "los servicios activados son socket o D-Bus." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:863 sssd.conf.5.xml:1123 sssd.conf.5.xml:2248 +#: sssd.conf.5.xml:815 sssd.conf.5.xml:1079 sssd.conf.5.xml:2285 #: sssd-ldap.5.xml:377 msgid "Default: 300" msgstr "Predeterminado: 300" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:868 -msgid "cache_first" +#: sssd.conf.5.xml:820 +#, fuzzy +#| msgid "cache_first" +msgid "cache_first (boolean)" msgstr "cache_first" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:871 +#: sssd.conf.5.xml:823 msgid "" "This option specifies whether the responder should query all caches before " "querying the Data Providers." @@ -1405,25 +1331,30 @@ msgstr "" "de consultar a los Proveedores de Datos." #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:883 +#: sssd.conf.5.xml:835 msgid "NSS configuration options" msgstr "Opciones de configuración de NSS" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:885 +#: sssd.conf.5.xml:837 +#, fuzzy +#| msgid "" +#| "These options can be used to configure the Name Service Switch (NSS) " +#| "service." msgid "" -"These options can be used to configure the Name Service Switch (NSS) service." +"These options can be used to configure the Name Service Switch (NSS) service " +"and should be specified under the <quote>[nss]</quote> section." msgstr "" "Estas opciones pueden ser usadas para configurar el servicio Name Service " "Switch (NSS)." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:890 +#: sssd.conf.5.xml:843 msgid "enum_cache_timeout (integer)" msgstr "enum_cache_timeout (entero)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:893 +#: sssd.conf.5.xml:846 msgid "" "How many seconds should nss_sss cache enumerations (requests for info about " "all users)" @@ -1432,17 +1363,17 @@ msgstr "" "sobre todos los usuarios)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:897 +#: sssd.conf.5.xml:850 msgid "Default: 120" msgstr "Predeterminado: 120" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:902 +#: sssd.conf.5.xml:855 msgid "entry_cache_nowait_percentage (integer)" msgstr "entry_cache_nowait_percentage (entero)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:905 +#: sssd.conf.5.xml:858 msgid "" "The entry cache can be set to automatically update entries in the background " "if they are requested beyond a percentage of the entry_cache_timeout value " @@ -1453,7 +1384,7 @@ msgstr "" "valor de entry_cache_timeout para el dominio." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:911 +#: sssd.conf.5.xml:864 msgid "" "For example, if the domain's entry_cache_timeout is set to 30s and " "entry_cache_nowait_percentage is set to 50 (percent), entries that come in " @@ -1469,7 +1400,7 @@ msgstr "" "actualización del cache." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:921 +#: sssd.conf.5.xml:874 msgid "" "Valid values for this option are 0-99 and represent a percentage of the " "entry_cache_timeout for each domain. For performance reasons, this " @@ -1482,17 +1413,17 @@ msgstr "" "segundos. (0 deshabilita esta función)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:929 sssd.conf.5.xml:2061 +#: sssd.conf.5.xml:882 sssd.conf.5.xml:2093 msgid "Default: 50" msgstr "Predeterminado: 50" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:934 +#: sssd.conf.5.xml:887 msgid "entry_negative_timeout (integer)" msgstr "entry_negative_timeout (entero)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:937 +#: sssd.conf.5.xml:890 msgid "" "Specifies for how many seconds nss_sss should cache negative cache hits " "(that is, queries for invalid database entries, like nonexistent ones) " @@ -1503,17 +1434,17 @@ msgstr "" "entradas no existentes) antes de preguntar al punto final otra vez." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:943 sssd.conf.5.xml:1685 sssd.conf.5.xml:2085 +#: sssd.conf.5.xml:896 sssd.conf.5.xml:1677 sssd.conf.5.xml:2119 msgid "Default: 15" msgstr "Predeterminado: 15" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:948 +#: sssd.conf.5.xml:901 msgid "filter_users, filter_groups (string)" msgstr "filter_users, filter_groups (cadena)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:951 +#: sssd.conf.5.xml:904 msgid "" "Exclude certain users or groups from being fetched from the sss NSS " "database. This is particularly useful for system accounts. This option can " @@ -1527,7 +1458,7 @@ msgstr "" "usuario (UPN)." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:959 +#: sssd.conf.5.xml:912 msgid "" "NOTE: The filter_groups option doesn't affect inheritance of nested group " "members, since filtering happens after they are propagated for returning via " @@ -1540,30 +1471,35 @@ msgstr "" "filtrado mantendrá los usuarios miembros del listado posterior." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:967 +#: sssd.conf.5.xml:920 msgid "Default: root" msgstr "Predeterminado: root" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:972 -msgid "filter_users_in_groups (bool)" +#: sssd.conf.5.xml:925 +#, fuzzy +#| msgid "filter_users_in_groups (bool)" +msgid "filter_users_in_groups (boolean)" msgstr "filter_users_in_groups (bool)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:975 +#: sssd.conf.5.xml:928 +#, fuzzy +#| msgid "" +#| "If you want filtered user still be group members set this option to false." msgid "" -"If you want filtered user still be group members set this option to false." +"If you want filtered users to remain group members set this option to false" msgstr "" "Si usted desea filtrar usuarios aunque sean miembros del grupo, fije esta " "opción a false." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:986 +#: sssd.conf.5.xml:939 msgid "fallback_homedir (string)" msgstr "fallback_homedir (cadena)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:989 +#: sssd.conf.5.xml:942 msgid "" "Set a default template for a user's home directory if one is not specified " "explicitly by the domain's data provider." @@ -1572,7 +1508,7 @@ msgstr "" "especificado una explícitamente por el proveedor de datos del dominio." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:994 +#: sssd.conf.5.xml:947 msgid "" "The available values for this option are the same as for override_homedir." msgstr "" @@ -1580,7 +1516,7 @@ msgstr "" "override_homedir." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1000 +#: sssd.conf.5.xml:953 #, no-wrap msgid "" "fallback_homedir = /home/%u\n" @@ -1590,24 +1526,24 @@ msgstr "" " " #. type: Content of: <varlistentry><listitem><para> -#: sssd.conf.5.xml:998 sssd.conf.5.xml:1557 sssd.conf.5.xml:1576 -#: sssd.conf.5.xml:1653 sssd-krb5.5.xml:451 include/override_homedir.xml:78 +#: sssd.conf.5.xml:951 sssd.conf.5.xml:1524 sssd.conf.5.xml:1543 +#: sssd.conf.5.xml:1645 sssd-krb5.5.xml:451 include/override_homedir.xml:78 msgid "example: <placeholder type=\"programlisting\" id=\"0\"/>" msgstr "ejemplo: <placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1004 +#: sssd.conf.5.xml:957 msgid "Default: not set (no substitution for unset home directories)" msgstr "" "Por defecto: no fijado (sin sustitución para los directorios home no fijados)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1010 +#: sssd.conf.5.xml:963 msgid "override_shell (string)" msgstr "override_shell (cadena)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1013 +#: sssd.conf.5.xml:966 msgid "" "Override the login shell for all users. This option supersedes any other " "shell options if it takes effect and can be set either in the [nss] section " @@ -1618,17 +1554,17 @@ msgstr "" "la sección [nss] o por dominio." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1019 +#: sssd.conf.5.xml:972 msgid "Default: not set (SSSD will use the value retrieved from LDAP)" msgstr "Por defecto: no fijado (SSSD usará el valor recuperado desde LDAP)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1025 +#: sssd.conf.5.xml:978 msgid "allowed_shells (string)" msgstr "allowed_shells (cadena)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1028 +#: sssd.conf.5.xml:981 msgid "" "Restrict user shell to one of the listed values. The order of evaluation is:" msgstr "" @@ -1636,12 +1572,12 @@ msgstr "" "evaluación es:" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1031 +#: sssd.conf.5.xml:984 msgid "1. If the shell is present in <quote>/etc/shells</quote>, it is used." msgstr "1. Si el shell está presente en <quote>/etc/shells</quote>, se usa." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1035 +#: sssd.conf.5.xml:988 msgid "" "2. If the shell is in the allowed_shells list but not in <quote>/etc/shells</" "quote>, use the value of the shell_fallback parameter." @@ -1650,7 +1586,7 @@ msgstr "" "shells</quote>, usa el valor del parámetro shell_fallback." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1040 +#: sssd.conf.5.xml:993 msgid "" "3. If the shell is not in the allowed_shells list and not in <quote>/etc/" "shells</quote>, a nologin shell is used." @@ -1659,12 +1595,12 @@ msgstr "" "shells</quote>, se usará un shell de no acceso." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1045 +#: sssd.conf.5.xml:998 msgid "The wildcard (*) can be used to allow any shell." msgstr "Se puede usar el comodín (*) para permitir cualquier shell." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1048 +#: sssd.conf.5.xml:1001 msgid "" "The (*) is useful if you want to use shell_fallback in case that user's " "shell is not in <quote>/etc/shells</quote> and maintaining list of all " @@ -1675,12 +1611,12 @@ msgstr "" "los shells permitidos en allowed_shells estuviera llena." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1055 +#: sssd.conf.5.xml:1008 msgid "An empty string for shell is passed as-is to libc." msgstr "Una cadena vacía para el shell se pasa como-es a libc." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1058 +#: sssd.conf.5.xml:1011 msgid "" "The <quote>/etc/shells</quote> is only read on SSSD start up, which means " "that a restart of the SSSD is required in case a new shell is installed." @@ -1690,27 +1626,27 @@ msgstr "" "una nueva shell." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1062 +#: sssd.conf.5.xml:1015 msgid "Default: Not set. The user shell is automatically used." msgstr "Por defecto: No fijado. La shell del usuario se usa automáticamente." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1067 +#: sssd.conf.5.xml:1020 msgid "vetoed_shells (string)" msgstr "vetoed_shells (cadena)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1070 +#: sssd.conf.5.xml:1023 msgid "Replace any instance of these shells with the shell_fallback" msgstr "Reemplaza cualquier instancia de estos shells con shell_fallback" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1075 +#: sssd.conf.5.xml:1031 msgid "shell_fallback (string)" msgstr "shell_fallback (cadena)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1078 +#: sssd.conf.5.xml:1034 msgid "" "The default shell to use if an allowed shell is not installed on the machine." msgstr "" @@ -1718,17 +1654,17 @@ msgstr "" "instalada en la máquina." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1082 +#: sssd.conf.5.xml:1038 msgid "Default: /bin/sh" msgstr "Predeterminado: /bin/sh" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1087 -msgid "default_shell" -msgstr "default_shell" +#: sssd.conf.5.xml:1043 +msgid "default_shell (string)" +msgstr "default_shell (cadena)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1090 +#: sssd.conf.5.xml:1046 msgid "" "The default shell to use if the provider does not return one during lookup. " "This option can be specified globally in the [nss] section or per-domain." @@ -1738,7 +1674,7 @@ msgstr "" "o por dominio." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1096 +#: sssd.conf.5.xml:1052 msgid "" "Default: not set (Return NULL if no shell is specified and rely on libc to " "substitute something sensible when necessary, usually /bin/sh)" @@ -1748,12 +1684,12 @@ msgstr "" "normalmente /bin/sh)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1103 sssd.conf.5.xml:1483 +#: sssd.conf.5.xml:1059 sssd.conf.5.xml:1450 msgid "get_domains_timeout (int)" msgstr "get_domains_timeout (entero)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1106 sssd.conf.5.xml:1486 +#: sssd.conf.5.xml:1062 sssd.conf.5.xml:1453 msgid "" "Specifies time in seconds for which the list of subdomains will be " "considered valid." @@ -1761,13 +1697,19 @@ msgstr "" "Especifica el tiempo en segundos por los cuales la lista de subdominios será " "considerada válida." +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1066 sssd.conf.5.xml:1457 sssd.conf.5.xml:1788 +#: sssd.conf.5.xml:2862 sssd-ldap.5.xml:550 +msgid "Default: 60" +msgstr "Predeterminado: 60" + #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1115 +#: sssd.conf.5.xml:1071 msgid "memcache_timeout (integer)" msgstr "memcache_timeout (entero)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1118 +#: sssd.conf.5.xml:1074 msgid "" "Specifies time in seconds for which records in the in-memory cache will be " "valid. Setting this option to zero will disable the in-memory cache." @@ -1776,7 +1718,7 @@ msgstr "" "cache serán validos. Fijando esta opción o cero deshabilita la memoria cache." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1126 +#: sssd.conf.5.xml:1082 msgid "" "WARNING: Disabling the in-memory cache will have significant negative impact " "on SSSD's performance and should only be used for testing." @@ -1786,8 +1728,8 @@ msgstr "" "pruebas." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1132 sssd.conf.5.xml:1157 sssd.conf.5.xml:1182 -#: sssd.conf.5.xml:1207 sssd.conf.5.xml:1234 +#: sssd.conf.5.xml:1088 sssd.conf.5.xml:1113 sssd.conf.5.xml:1138 +#: sssd.conf.5.xml:1163 sssd.conf.5.xml:1190 msgid "" "NOTE: If the environment variable SSS_NSS_USE_MEMCACHE is set to \"NO\", " "client applications will not use the fast in-memory cache." @@ -1796,12 +1738,12 @@ msgstr "" "las aplicaciones clientes no usaran la memoria cache rápida." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1140 +#: sssd.conf.5.xml:1096 msgid "memcache_size_passwd (integer)" msgstr "memcache_size_passwd (entero)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1143 +#: sssd.conf.5.xml:1099 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for passwd requests. Setting the size to 0 will disable the passwd in-" @@ -1812,13 +1754,13 @@ msgstr "" "deshabilita la memoria cache de passwd." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1149 sssd.conf.5.xml:2888 sssd-ldap.5.xml:604 +#: sssd.conf.5.xml:1105 sssd.conf.5.xml:3013 sssd-ldap.5.xml:604 msgid "Default: 8" msgstr "Predeterminado: 8" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1152 sssd.conf.5.xml:1177 sssd.conf.5.xml:1202 -#: sssd.conf.5.xml:1229 +#: sssd.conf.5.xml:1108 sssd.conf.5.xml:1133 sssd.conf.5.xml:1158 +#: sssd.conf.5.xml:1185 msgid "" "WARNING: Disabled or too small in-memory cache can have significant negative " "impact on SSSD's performance." @@ -1827,12 +1769,12 @@ msgstr "" "impacto negativo significativo sobre el rendimiento de SSSD." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1165 +#: sssd.conf.5.xml:1121 msgid "memcache_size_group (integer)" msgstr "memcache_size_group (entero)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1168 +#: sssd.conf.5.xml:1124 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for group requests. Setting the size to 0 will disable the group in-memory " @@ -1843,19 +1785,19 @@ msgstr "" "deshabilitará el grupo cache en memoria." #. type: Content of: <variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1174 sssd.conf.5.xml:1226 sssd.conf.5.xml:3656 +#: sssd.conf.5.xml:1130 sssd.conf.5.xml:1182 sssd.conf.5.xml:3835 #: sssd-ldap.5.xml:534 sssd-ldap.5.xml:581 include/failover.xml:116 #: include/krb5_options.xml:11 msgid "Default: 6" msgstr "Predeterminado: 6" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1190 +#: sssd.conf.5.xml:1146 msgid "memcache_size_initgroups (integer)" msgstr "memcache_size_initgroups (entero)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1193 +#: sssd.conf.5.xml:1149 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for initgroups requests. Setting the size to 0 will disable the initgroups " @@ -1866,12 +1808,12 @@ msgstr "" "deshabilita la memoria caché dentro de grupos de inicio." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1215 +#: sssd.conf.5.xml:1171 msgid "memcache_size_sid (integer)" msgstr "memcache_size_sid (entero)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1218 +#: sssd.conf.5.xml:1174 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for SID related requests. Only SID-by-ID and ID-by-SID requests are " @@ -1884,12 +1826,12 @@ msgstr "" "tamaño a cero deshabilitará la caché SID de memoria." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1242 sssd-ifp.5.xml:90 +#: sssd.conf.5.xml:1198 sssd-ifp.5.xml:90 msgid "user_attributes (string)" msgstr "user_attributes (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1245 +#: sssd.conf.5.xml:1201 msgid "" "Some of the additional NSS responder requests can return more attributes " "than just the POSIX ones defined by the NSS interface. The list of " @@ -1907,7 +1849,7 @@ msgstr "" "predeterminados." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1258 +#: sssd.conf.5.xml:1214 msgid "" "To make configuration more easy the NSS responder will check the InfoPipe " "option if it is not set for the NSS responder." @@ -1916,17 +1858,17 @@ msgstr "" "opción InfoPipe si no está fijada para el contestador NSS." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1263 +#: sssd.conf.5.xml:1219 msgid "Default: not set, fallback to InfoPipe option" msgstr "Por defecto: no ajustada, retroceder a opción InfoPipe" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1268 +#: sssd.conf.5.xml:1224 msgid "pwfield (string)" msgstr "pwfield (cadena)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1271 +#: sssd.conf.5.xml:1227 msgid "" "The value that NSS operations that return users or groups will return for " "the <quote>password</quote> field." @@ -1935,49 +1877,61 @@ msgstr "" "para el campo <quote>password</quote>." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1276 -msgid "Default: <quote>*</quote>" -msgstr "Predeterminado: <quote>*</quote>" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1279 +#: sssd.conf.5.xml:1232 msgid "" -"Note: This option can also be set per-domain which overwrites the value in " -"[nss] section." +"This option can also be set per-domain, which overwrites the value in the " +"<quote>[nss]</quote> section for that domain. This is particularly useful " +"when using a proxy domain with <option>proxy_lib_name=files</option> and a " +"<option>proxy_pam_target</option> other than <quote>sssd-shadowutils</" +"quote>. In that case, SSSD returns <quote>*</quote> for the password field " +"by default, which causes <command>pam_unix</command> to treat all accounts " +"as locked. Setting <option>pwfield = x</option> in the domain section " +"restores the expected behavior." msgstr "" -"Nota: esta opción puede ser también fijada por dominio lo cual sobrescribe " -"el valor en la sección [nss]." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1283 +#: sssd.conf.5.xml:1246 +msgid "Default: <quote>*</quote>" +msgstr "Predeterminado: <quote>*</quote>" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1249 +#, fuzzy +#| msgid "" +#| "Default: <quote>not set</quote> (remote domains), <quote>x</quote> (proxy " +#| "domain with nss_files and sssd-shadowutils target)" msgid "" -"Default: <quote>not set</quote> (remote domains), <quote>x</quote> (proxy " -"domain with nss_files and sssd-shadowutils target)" +"Default (per-domain): <quote>not set</quote> (remote domains), <quote>x</" +"quote> (proxy domain with nss_files and sssd-shadowutils target)" msgstr "" "Por defecto: <quote>no establecida</quote> (dominios remotos), <quote>x</" "quote> (proxy dominio con nss_files y destino ssd-shadowutils)" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:1292 +#: sssd.conf.5.xml:1258 msgid "PAM configuration options" msgstr "Opciones de configuración PAM" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:1294 +#: sssd.conf.5.xml:1260 +#, fuzzy +#| msgid "" +#| "These options can be used to configure the Pluggable Authentication " +#| "Module (PAM) service." msgid "" "These options can be used to configure the Pluggable Authentication Module " -"(PAM) service." +"(PAM) service and should be specified under the <quote>[pam]</quote> section." msgstr "" "Estas opciones pueden ser usadas para configurar el servicio Pluggable " "Authentication Module (PAM)." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1299 +#: sssd.conf.5.xml:1266 msgid "offline_credentials_expiration (integer)" msgstr "offline_credentials_expiration (entero)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1302 +#: sssd.conf.5.xml:1269 msgid "" "If the authentication provider is offline, how long should we allow cached " "logins (in days since the last successful online login)." @@ -1986,17 +1940,17 @@ msgstr "" "los accesos escondidos (en días desde el último login en línea con éxito)." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1307 sssd.conf.5.xml:1320 +#: sssd.conf.5.xml:1274 sssd.conf.5.xml:1287 msgid "Default: 0 (No limit)" msgstr "Predeterminado: 0 (Sin límite)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1313 +#: sssd.conf.5.xml:1280 msgid "offline_failed_login_attempts (integer)" msgstr "offline_failed_login_attempts (entero)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1316 +#: sssd.conf.5.xml:1283 msgid "" "If the authentication provider is offline, how many failed login attempts " "are allowed." @@ -2005,12 +1959,12 @@ msgstr "" "login fallados están permitidos." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1326 +#: sssd.conf.5.xml:1293 msgid "offline_failed_login_delay (integer)" msgstr "offline_failed_login_delay (entero)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1329 +#: sssd.conf.5.xml:1296 msgid "" "The time in minutes which has to pass after offline_failed_login_attempts " "has been reached before a new login attempt is possible." @@ -2020,7 +1974,7 @@ msgstr "" "intento de login sea posible." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1334 +#: sssd.conf.5.xml:1301 msgid "" "If set to 0 the user cannot authenticate offline if " "offline_failed_login_attempts has been reached. Only a successful online " @@ -2031,17 +1985,17 @@ msgstr "" "éxito puede habilitar otra vez la autenticación fuera de línea." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1340 sssd.conf.5.xml:1450 +#: sssd.conf.5.xml:1307 sssd.conf.5.xml:1417 msgid "Default: 5" msgstr "Predeterminado: 5" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1346 +#: sssd.conf.5.xml:1313 msgid "pam_verbosity (integer)" msgstr "pam_verbosity (entero)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1349 +#: sssd.conf.5.xml:1316 msgid "" "Controls what kind of messages are shown to the user during authentication. " "The higher the number to more messages are displayed." @@ -2050,44 +2004,44 @@ msgstr "" "autenticación. Cuanto mayor sea el número de mensajes más aparecen." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1354 +#: sssd.conf.5.xml:1321 msgid "Currently sssd supports the following values:" msgstr "Actualmente sssd soporta los siguientes valores:" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1357 +#: sssd.conf.5.xml:1324 msgid "<emphasis>0</emphasis>: do not show any message" msgstr "<emphasis>0</emphasis>: no mostrar ningún mensaje" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1360 +#: sssd.conf.5.xml:1327 msgid "<emphasis>1</emphasis>: show only important messages" msgstr "<emphasis>1</emphasis>: mostrar sólo mensajes importantes" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1364 +#: sssd.conf.5.xml:1331 msgid "<emphasis>2</emphasis>: show informational messages" msgstr "<emphasis>2</emphasis>: mostrar mensajes informativos" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1367 +#: sssd.conf.5.xml:1334 msgid "<emphasis>3</emphasis>: show all messages and debug information" msgstr "" "<emphasis>3</emphasis>: mostrar todos los mensajes e información de " "depuración" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1371 sssd.8.xml:63 +#: sssd.conf.5.xml:1338 sssd.8.xml:63 msgid "Default: 1" msgstr "Predeterminado: 1" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1377 +#: sssd.conf.5.xml:1344 msgid "pam_response_filter (string)" msgstr "pam_response_filter (cadena)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1380 +#: sssd.conf.5.xml:1347 msgid "" "A comma separated list of strings which allows to remove (filter) data sent " "by the PAM responder to pam_sss PAM module. There are different kind of " @@ -2100,7 +2054,7 @@ msgstr "" "variables de entorno que deberían ser fijadas por pam_sss." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1388 +#: sssd.conf.5.xml:1355 msgid "" "While messages already can be controlled with the help of the pam_verbosity " "option this option allows to filter out other kind of responses as well." @@ -2109,37 +2063,37 @@ msgstr "" "pam_verbosity esta opción permite filtrar otra clase de respuestas también." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1395 +#: sssd.conf.5.xml:1362 msgid "ENV" msgstr "ENV" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1396 +#: sssd.conf.5.xml:1363 msgid "Do not send any environment variables to any service." msgstr "No envía ninguna variable de entorno a ningún servicio." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1399 +#: sssd.conf.5.xml:1366 msgid "ENV:var_name" msgstr "ENV:var_name" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1400 +#: sssd.conf.5.xml:1367 msgid "Do not send environment variable var_name to any service." msgstr "No envía la variable de entorno var_name a ningún servicio." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1404 +#: sssd.conf.5.xml:1371 msgid "ENV:var_name:service" msgstr "ENV:var_name:service" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1405 +#: sssd.conf.5.xml:1372 msgid "Do not send environment variable var_name to service." msgstr "No envía la variable de entorno var_name al servicio." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1393 +#: sssd.conf.5.xml:1360 msgid "" "Currently the following filters are supported: <placeholder " "type=\"variablelist\" id=\"0\"/>" @@ -2148,7 +2102,7 @@ msgstr "" "type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1412 +#: sssd.conf.5.xml:1379 msgid "" "The list of strings can either be the list of filters which would set this " "list of filters and overwrite the defaults. Or each element of the list can " @@ -2166,12 +2120,12 @@ msgstr "" "estilos." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1423 +#: sssd.conf.5.xml:1390 msgid "Default: ENV:KRB5CCNAME:sudo, ENV:KRB5CCNAME:sudo-i" msgstr "Por defecto: ENV:KRB5CCNAME:sudo, ENV:KRB5CCNAME:sudo-i" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1426 +#: sssd.conf.5.xml:1393 msgid "" "Example: -ENV:KRB5CCNAME:sudo-i will remove the filter from the default list" msgstr "" @@ -2179,12 +2133,12 @@ msgstr "" "predeterminado" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1433 +#: sssd.conf.5.xml:1400 msgid "pam_id_timeout (integer)" msgstr "pam_id_timeout (entero)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1436 +#: sssd.conf.5.xml:1403 msgid "" "For any PAM request while SSSD is online, the SSSD will attempt to " "immediately update the cached identity information for the user in order to " @@ -2196,7 +2150,7 @@ msgstr "" "información más actual." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1442 +#: sssd.conf.5.xml:1409 msgid "" "A complete PAM conversation may perform multiple PAM requests, such as " "account management and session opening. This option controls (on a per-" @@ -2210,17 +2164,17 @@ msgstr "" "proveedor de identidad." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1456 +#: sssd.conf.5.xml:1423 msgid "pam_pwd_expiration_warning (integer)" msgstr "pam_pwd_expiration_warning (entero)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1459 sssd.conf.5.xml:2912 +#: sssd.conf.5.xml:1426 sssd.conf.5.xml:3037 msgid "Display a warning N days before the password expires." msgstr "Mostrar una advertencia N días antes que la contraseña caduque." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1462 +#: sssd.conf.5.xml:1429 msgid "" "Please note that the backend server has to provide information about the " "expiration time of the password. If this information is missing, sssd " @@ -2231,7 +2185,7 @@ msgstr "" "información desaparece, sssd no podrá mostrar un aviso." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1468 sssd.conf.5.xml:2915 +#: sssd.conf.5.xml:1435 sssd.conf.5.xml:3040 msgid "" "If zero is set, then this filter is not applied, i.e. if the expiration " "warning was received from backend server, it will automatically be displayed." @@ -2241,7 +2195,7 @@ msgstr "" "automáticamente." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1473 +#: sssd.conf.5.xml:1440 msgid "" "This setting can be overridden by setting <emphasis>pwd_expiration_warning</" "emphasis> for a particular domain." @@ -2250,18 +2204,18 @@ msgstr "" "pwd_expiration_warning</emphasis> para un dominio concreto." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1478 sssd.conf.5.xml:3913 sssd-ldap.5.xml:662 +#: sssd.conf.5.xml:1445 sssd.conf.5.xml:4118 sssd-ldap.5.xml:662 #: sssd-ldap.5.xml:1733 sssd.8.xml:79 msgid "Default: 0" msgstr "Predeterminado: 0" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1495 +#: sssd.conf.5.xml:1462 msgid "pam_trusted_users (string)" msgstr "pam_trusted_users (cadena)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1498 +#: sssd.conf.5.xml:1465 msgid "" "Specifies the comma-separated list of UID values or user names that are " "allowed to run PAM conversations against trusted domains. Users not " @@ -2276,12 +2230,12 @@ msgstr "" "nombres de usuarios se resuelven a UIDs en el arranque." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1508 +#: sssd.conf.5.xml:1475 msgid "Default: All users are considered trusted by default" msgstr "Por defecto: Todos los usuarios se consideran de confianza por defecto" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1512 +#: sssd.conf.5.xml:1479 msgid "" "Please note that UID 0 is always allowed to access the PAM responder even in " "case it is not in the pam_trusted_users list." @@ -2290,12 +2244,12 @@ msgstr "" "aunque no está en la lista pam_trusted_users." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1519 +#: sssd.conf.5.xml:1486 msgid "pam_public_domains (string)" msgstr "pam_public_domains (cadena)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1522 +#: sssd.conf.5.xml:1489 msgid "" "Specifies the comma-separated list of domain names that are accessible even " "to untrusted users." @@ -2304,12 +2258,12 @@ msgstr "" "accesibles hasta para los usuarios en los que no se confíe." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1526 +#: sssd.conf.5.xml:1493 msgid "Two special values for pam_public_domains option are defined:" msgstr "Hay definidos dos valores especiales para la opción pam_public_domains:" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1530 +#: sssd.conf.5.xml:1497 msgid "" "all (Untrusted users are allowed to access all domains in PAM responder.)" msgstr "" @@ -2317,7 +2271,7 @@ msgstr "" "dominios en el contestador PAM.)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1534 +#: sssd.conf.5.xml:1501 msgid "" "none (Untrusted users are not allowed to access any domains PAM in " "responder.)" @@ -2326,18 +2280,18 @@ msgstr "" "dominios PAM en el contestador.)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1538 sssd.conf.5.xml:1563 sssd.conf.5.xml:1582 -#: sssd.conf.5.xml:1824 sssd.conf.5.xml:3842 sssd-ldap.5.xml:1270 +#: sssd.conf.5.xml:1505 sssd.conf.5.xml:1530 sssd.conf.5.xml:1549 +#: sssd.conf.5.xml:1821 sssd.conf.5.xml:4048 sssd-ldap.5.xml:1270 msgid "Default: none" msgstr "Predeterminado: none" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1543 +#: sssd.conf.5.xml:1510 msgid "pam_account_expired_message (string)" msgstr "pam_account_expired_message (cadena)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1546 +#: sssd.conf.5.xml:1513 msgid "" "Allows a custom expiration message to be set, replacing the default " "'Permission denied' message." @@ -2346,7 +2300,7 @@ msgstr "" "mensaje predeterminado 'Permiso denegado'." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1551 +#: sssd.conf.5.xml:1518 msgid "" "Note: Please be aware that message is only printed for the SSH service " "unless pam_verbosity is set to 3 (show all messages and debug information)." @@ -2356,7 +2310,7 @@ msgstr "" "mensajes e información de depuración)." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1559 +#: sssd.conf.5.xml:1526 #, no-wrap msgid "" "pam_account_expired_message = Account expired, please contact help desk.\n" @@ -2367,12 +2321,12 @@ msgstr "" " " #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1568 +#: sssd.conf.5.xml:1535 msgid "pam_account_locked_message (string)" msgstr "pam_account_locked_message (cadena)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1571 +#: sssd.conf.5.xml:1538 msgid "" "Allows a custom lockout message to be set, replacing the default 'Permission " "denied' message." @@ -2381,7 +2335,7 @@ msgstr "" "por defecto 'Permiso denegado'." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1578 +#: sssd.conf.5.xml:1545 #, no-wrap msgid "" "pam_account_locked_message = Account locked, please contact help desk.\n" @@ -2392,46 +2346,52 @@ msgstr "" " " #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1587 -msgid "pam_passkey_auth (bool)" +#: sssd.conf.5.xml:1554 +#, fuzzy +#| msgid "pam_passkey_auth (bool)" +msgid "pam_passkey_auth (boolean)" msgstr "pam_passkey_auth (booleano)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1590 +#: sssd.conf.5.xml:1557 msgid "Enable passkey device based authentication." msgstr "Activa dispositivo con clave de paso basada en autenticación." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1593 sssd.conf.5.xml:1910 sssd-ad.5.xml:1286 +#: sssd.conf.5.xml:1560 sssd.conf.5.xml:1907 sssd-ad.5.xml:1279 #: sss_rpcidmapd.5.xml:76 msgid "Default: True" msgstr "Predeterminado: True" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1598 -msgid "passkey_debug_libfido2 (bool)" +#: sssd.conf.5.xml:1565 +#, fuzzy +#| msgid "passkey_debug_libfido2 (bool)" +msgid "passkey_debug_libfido2 (boolean)" msgstr "passkey_debug_libfido2 (booleano)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1601 +#: sssd.conf.5.xml:1568 msgid "Enable libfido2 library debug messages." msgstr "Activa la biblioteca libfido2 de mensajes de depuración." #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1604 sssd.conf.5.xml:1618 sssd-ldap.5.xml:727 -#: sssd-ldap.5.xml:752 sssd-ldap.5.xml:848 sssd-ldap.5.xml:1356 -#: sssd-ad.5.xml:506 sssd-ad.5.xml:582 sssd-ad.5.xml:1155 +#: sssd.conf.5.xml:1571 sssd.conf.5.xml:1585 sssd.conf.5.xml:4781 +#: sssd-ldap.5.xml:727 sssd-ldap.5.xml:752 sssd-ldap.5.xml:848 +#: sssd-ldap.5.xml:1356 sssd-ad.5.xml:506 sssd-ad.5.xml:582 sssd-ad.5.xml:1160 #: include/ldap_id_mapping.xml:250 msgid "Default: False" msgstr "Por defecto: False" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1609 -msgid "pam_cert_auth (bool)" +#: sssd.conf.5.xml:1576 +#, fuzzy +#| msgid "pam_cert_auth (bool)" +msgid "pam_cert_auth (boolean)" msgstr "pam_cert_auth (booleano)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1612 +#: sssd.conf.5.xml:1579 msgid "" "Enable certificate based Smartcard authentication. Since this requires " "additional communication with the Smartcard which will delay the " @@ -2441,23 +2401,64 @@ msgstr "" "requiere comunicación adicional con la Smartcard lo que dilatará el proceso " "de autenticación esta opción está deshabilitada por defecto." +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1588 +msgid "" +"Note: In case OpenSC is used for Smartcard access SSSD supports the " +"filesystem caching in OpenSC when enabled in opensc.conf. The cached files " +"are located in a common <quote>opensc</quote> directory in SSSD's state " +"directory. The behaviour can be changed in opensc.conf" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> +#: sssd.conf.5.xml:1597 +#, no-wrap +msgid "" +"app /usr/libexec/sssd/p11_child {\n" +" framework pkcs15 {\n" +" use_file_caching = no;\n" +" }\n" +"}\n" +"app /usr/libexec/sssd/krb5_child {\n" +" framework pkcs15 {\n" +" use_file_caching = no;\n" +" }\n" +"}\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1595 +#, fuzzy +#| msgid "Example: <placeholder type=\"programlisting\" id=\"0\"/>" +msgid "" +"Example opensc.conf (*): <placeholder type=\"programlisting\" id=\"0\"/>" +msgstr "Ejemplo: <placeholder type=\"programlisting\" id=\"0\"/>" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1610 +msgid "" +"(*) The actual <quote>libexec</quote> directory for p11_child and krb5_child " +"depends on the distribution." +msgstr "" + #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1623 +#: sssd.conf.5.xml:1615 msgid "pam_cert_db_path (string)" msgstr "pam_cert_db_path (cadena)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1626 +#: sssd.conf.5.xml:1618 msgid "The path to the certificate database." msgstr "La ruta a la base de datos del certificado." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1629 sssd.conf.5.xml:2163 sssd.conf.5.xml:4338 +#: sssd.conf.5.xml:1621 sssd.conf.5.xml:2199 sssd.conf.5.xml:4543 msgid "Default:" msgstr "Predeterminado:" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1631 sssd.conf.5.xml:2165 +#: sssd.conf.5.xml:1623 sssd.conf.5.xml:2201 msgid "" "/etc/sssd/pki/sssd_auth_ca_db.pem (path to a file with trusted CA " "certificates in PEM format)" @@ -2466,12 +2467,12 @@ msgstr "" "confiado en formato PEM)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1641 +#: sssd.conf.5.xml:1633 msgid "pam_cert_verification (string)" msgstr "pam_certificate_verification (cadena)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1644 +#: sssd.conf.5.xml:1636 msgid "" "With this parameter the PAM certificate verification can be tuned with a " "comma separated list of options that override the " @@ -2486,7 +2487,7 @@ msgstr "" "quote>." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1655 +#: sssd.conf.5.xml:1647 #, no-wrap msgid "" "pam_cert_verification = partial_chain\n" @@ -2496,7 +2497,7 @@ msgstr "" " " #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1659 +#: sssd.conf.5.xml:1651 msgid "" "Default: not set, i.e. use default <quote>certificate_verification</quote> " "option defined in <quote>[sssd]</quote> section." @@ -2506,34 +2507,34 @@ msgstr "" "." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1666 +#: sssd.conf.5.xml:1658 msgid "p11_child_timeout (integer)" msgstr "p11_child_timeout (entero)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1669 +#: sssd.conf.5.xml:1661 msgid "How many seconds will pam_sss wait for p11_child to finish." msgstr "Cuantos segundos esperará pam_sss wait para que p11_child finalice." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1678 +#: sssd.conf.5.xml:1670 msgid "passkey_child_timeout (integer)" msgstr "passkey_child_timeout (entero)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1681 +#: sssd.conf.5.xml:1673 msgid "" "How many seconds will the PAM responder wait for passkey_child to finish." msgstr "" "Cuantos segundos el PAM esperará responder para que finalice passkey_child." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1690 +#: sssd.conf.5.xml:1682 msgid "pam_app_services (string)" msgstr "pam_app_services (cadena)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1693 +#: sssd.conf.5.xml:1685 msgid "" "Which PAM services are permitted to contact domains of type " "<quote>application</quote>" @@ -2542,12 +2543,12 @@ msgstr "" "tipo <quote>application</quote>" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1702 +#: sssd.conf.5.xml:1694 msgid "pam_p11_allowed_services (string)" msgstr "pam_p11_allowed_services (cadena)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1705 +#: sssd.conf.5.xml:1697 msgid "" "A comma-separated list of PAM service names for which it will be allowed to " "use Smartcards." @@ -2556,7 +2557,7 @@ msgstr "" "permitidos usar Smartcards." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1720 +#: sssd.conf.5.xml:1712 #, no-wrap msgid "" "pam_p11_allowed_services = +my_pam_service, -login\n" @@ -2566,7 +2567,7 @@ msgstr "" " " #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1709 +#: sssd.conf.5.xml:1701 msgid "" "It is possible to add another PAM service name to the default set by using " "<quote>+service_name</quote> or to explicitly remove a PAM service name from " @@ -2586,70 +2587,77 @@ msgstr "" "id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1724 sssd-ad.5.xml:645 sssd-ad.5.xml:754 sssd-ad.5.xml:812 -#: sssd-ad.5.xml:870 sssd-ad.5.xml:948 +#: sssd.conf.5.xml:1716 sssd-ad.5.xml:645 sssd-ad.5.xml:759 sssd-ad.5.xml:817 +#: sssd-ad.5.xml:875 sssd-ad.5.xml:953 msgid "Default: the default set of PAM service names includes:" msgstr "" "Predeterminado: el conjunto predeterminado de nombres de servicio PAM " "incluye:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1729 sssd-ad.5.xml:649 +#: sssd.conf.5.xml:1721 sssd-ad.5.xml:649 msgid "login" msgstr "login" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1734 sssd-ad.5.xml:654 +#: sssd.conf.5.xml:1726 sssd-ad.5.xml:654 msgid "su" msgstr "su" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1739 sssd-ad.5.xml:659 +#: sssd.conf.5.xml:1731 sssd-ad.5.xml:659 msgid "su-l" msgstr "su-l" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1744 sssd-ad.5.xml:674 +#: sssd.conf.5.xml:1736 sssd-ad.5.xml:674 msgid "gdm-smartcard" msgstr "gdm-smartcard" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1749 sssd-ad.5.xml:669 +#: sssd.conf.5.xml:1741 sssd-ad.5.xml:669 msgid "gdm-password" msgstr "gdm-password" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1754 +#: sssd.conf.5.xml:1746 msgid "gdm-switchable-auth" msgstr "gdm-switchable-auth" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1759 sssd-ad.5.xml:679 +#: sssd.conf.5.xml:1751 sssd-ad.5.xml:679 msgid "kdm" msgstr "kdm" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1764 sssd-ad.5.xml:957 +#: sssd.conf.5.xml:1756 sssd-ad.5.xml:694 +#, fuzzy +#| msgid "login" +msgid "plasmalogin" +msgstr "login" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:1761 sssd-ad.5.xml:962 msgid "sudo" msgstr "sudo" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1769 sssd-ad.5.xml:962 +#: sssd.conf.5.xml:1766 sssd-ad.5.xml:967 msgid "sudo-i" msgstr "sudo-i" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1774 +#: sssd.conf.5.xml:1771 msgid "gnome-screensaver" msgstr "gnome-screensaver" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1782 +#: sssd.conf.5.xml:1779 msgid "p11_wait_for_card_timeout (integer)" msgstr "p11_wait_for_card_timeout (entero)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1785 +#: sssd.conf.5.xml:1782 msgid "" "If Smartcard authentication is required how many extra seconds in addition " "to p11_child_timeout should the PAM responder wait until a Smartcard is " @@ -2660,12 +2668,12 @@ msgstr "" "inserte la Smartcard." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1796 +#: sssd.conf.5.xml:1793 msgid "p11_uri (string)" msgstr "p11_uri (cadena)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1799 +#: sssd.conf.5.xml:1796 msgid "" "PKCS#11 URI (see RFC-7512 for details) which can be used to restrict the " "selection of devices used for Smartcard authentication. By default SSSD's " @@ -2683,7 +2691,7 @@ msgstr "" "específico." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1812 +#: sssd.conf.5.xml:1809 #, no-wrap msgid "" "p11_uri = pkcs11:slot-description=My%20Smartcard%20Reader\n" @@ -2693,7 +2701,7 @@ msgstr "" " " #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1816 +#: sssd.conf.5.xml:1813 #, no-wrap msgid "" "p11_uri = pkcs11:library-description=OpenSC%20smartcard%20framework;slot-id=2\n" @@ -2704,7 +2712,7 @@ msgstr "" " " #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1810 +#: sssd.conf.5.xml:1807 msgid "" "Example: <placeholder type=\"programlisting\" id=\"0\"/> or <placeholder " "type=\"programlisting\" id=\"1\"/> To find suitable URI please check the " @@ -2717,29 +2725,31 @@ msgstr "" "GnuTLS 'p11tool' con p.e. '--list-all' también mostrará PKCS#11 de las URI." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1829 -msgid "pam_initgroups_scheme" +#: sssd.conf.5.xml:1826 +#, fuzzy +#| msgid "pam_initgroups_scheme" +msgid "pam_initgroups_scheme (string)" msgstr "pam_initgroups_scheme" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1837 +#: sssd.conf.5.xml:1834 msgid "always" msgstr "siempre" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1838 +#: sssd.conf.5.xml:1835 msgid "" "Always do an online lookup, please note that pam_id_timeout still applies" msgstr "" "Haga siempre una búsqueda en línea, note que todavía se aplica pam_id_timeout" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1842 +#: sssd.conf.5.xml:1839 msgid "no_session" msgstr "no_session" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1843 +#: sssd.conf.5.xml:1840 msgid "" "Only do an online lookup if there is no active session of the user, i.e. if " "the user is currently not logged in" @@ -2748,12 +2758,12 @@ msgstr "" "p.ej. si el usuario actualmente no ha accedido" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1848 sssd-ldap.5.xml:189 +#: sssd.conf.5.xml:1845 sssd-ldap.5.xml:189 msgid "never" msgstr "never" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1849 +#: sssd.conf.5.xml:1846 msgid "" "Never force an online lookup, use the data from the cache as long as they " "are not expired" @@ -2762,7 +2772,7 @@ msgstr "" "largo como no son caducados" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1832 +#: sssd.conf.5.xml:1829 msgid "" "The PAM responder can force an online lookup to get the current group " "memberships of the user trying to log in. This option controls when this " @@ -2775,17 +2785,19 @@ msgstr "" "<placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1856 +#: sssd.conf.5.xml:1853 msgid "Default: no_session" msgstr "Predeterminado: no_session" -#. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:1861 sssd.conf.5.xml:4277 -msgid "pam_gssapi_services" -msgstr "pam_gssapi_services" +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1858 +#, fuzzy +#| msgid "pam_app_services (string)" +msgid "pam_gssapi_services (string)" +msgstr "pam_app_services (cadena)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1864 +#: sssd.conf.5.xml:1861 msgid "" "Comma separated list of PAM services that are allowed to try GSSAPI " "authentication using pam_sss_gss.so module." @@ -2794,7 +2806,7 @@ msgstr "" "autenticación GSSAPI utilizando el módulo pam_sss_gss.so." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1869 +#: sssd.conf.5.xml:1866 msgid "" "To disable GSSAPI authentication, set this option to <quote>-</quote> (dash)." msgstr "" @@ -2802,7 +2814,7 @@ msgstr "" "(guion)." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1873 sssd.conf.5.xml:1904 sssd.conf.5.xml:1942 +#: sssd.conf.5.xml:1870 sssd.conf.5.xml:1901 sssd.conf.5.xml:1939 msgid "" "Note: This option can also be set per-domain which overwrites the value in " "[pam] section. It can also be set for trusted domain which overwrites the " @@ -2814,7 +2826,7 @@ msgstr "" "dominio." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1881 +#: sssd.conf.5.xml:1878 #, no-wrap msgid "" "pam_gssapi_services = sudo, sudo-i\n" @@ -2824,22 +2836,24 @@ msgstr "" " " #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1879 sssd.conf.5.xml:1994 sssd.conf.5.xml:3836 +#: sssd.conf.5.xml:1876 sssd.conf.5.xml:2023 sssd.conf.5.xml:4042 msgid "Example: <placeholder type=\"programlisting\" id=\"0\"/>" msgstr "Ejemplo: <placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1885 +#: sssd.conf.5.xml:1882 msgid "Default: - (GSSAPI authentication is disabled)" msgstr "Predeterminado: - (Autenticación GSSAPI está deshabilitada)" -#. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:1890 sssd.conf.5.xml:4278 -msgid "pam_gssapi_check_upn" +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1887 +#, fuzzy +#| msgid "pam_gssapi_check_upn" +msgid "pam_gssapi_check_upn (boolean)" msgstr "pam_gssapi_check_upn" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1893 +#: sssd.conf.5.xml:1890 msgid "" "If True, SSSD will require that the Kerberos user principal that " "successfully authenticated through GSSAPI can be associated with the user " @@ -2851,21 +2865,27 @@ msgstr "" "comprobación falla." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1900 +#: sssd.conf.5.xml:1897 +#, fuzzy +#| msgid "" +#| "If False, every user that is able to obtained required service ticket " +#| "will be authenticated." msgid "" -"If False, every user that is able to obtained required service ticket will " +"If False, every user that is able to obtain a required service ticket will " "be authenticated." msgstr "" "Si es falso, cada usuario que es capaz de obtener ticket de servicio " "requerido estará autenticado." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1915 -msgid "pam_gssapi_indicators_map" +#: sssd.conf.5.xml:1912 +#, fuzzy +#| msgid "pam_gssapi_indicators_map" +msgid "pam_gssapi_indicators_map (string)" msgstr "pam_gssapi_indicators_map" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1918 +#: sssd.conf.5.xml:1915 msgid "" "Comma separated list of authentication indicators required to be present in " "a Kerberos ticket to access a PAM service that is allowed to try GSSAPI " @@ -2876,7 +2896,7 @@ msgstr "" "intentar la autenticación GSSAPI mediante el módulo pam_sss_gss.so." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1924 +#: sssd.conf.5.xml:1921 msgid "" "Each element of the list can be either an authentication indicator name or a " "pair <quote>service:indicator</quote>. Indicators not prefixed with the PAM " @@ -2902,7 +2922,7 @@ msgstr "" "acceso." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1937 +#: sssd.conf.5.xml:1934 msgid "" "To disable GSSAPI authentication indicator check, set this option to <quote>-" "</quote> (dash). To disable the check for a specific PAM service, add " @@ -2913,7 +2933,7 @@ msgstr "" "comprobación de un servicio PAM, añada <quote>service:-</quote>." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1948 +#: sssd.conf.5.xml:1945 msgid "" "Following authentication indicators are supported by IPA Kerberos " "deployments:" @@ -2922,7 +2942,7 @@ msgstr "" "Kerberos IPA:" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1951 +#: sssd.conf.5.xml:1948 msgid "" "pkinit -- pre-authentication using X.509 certificates -- whether stored in " "files or on smart cards." @@ -2931,7 +2951,7 @@ msgstr "" "en archivos o en tarjetas inteligentes." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1954 +#: sssd.conf.5.xml:1951 msgid "" "hardened -- SPAKE pre-authentication or any pre-authentication wrapped in a " "FAST channel." @@ -2940,12 +2960,12 @@ msgstr "" "en un canal FAST." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1957 +#: sssd.conf.5.xml:1954 msgid "radius -- pre-authentication with the help of a RADIUS server." msgstr "radius -- pre-autenticación con la ayuda de un servidor RADIUS." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1960 +#: sssd.conf.5.xml:1957 msgid "" "otp -- pre-authentication using integrated two-factor authentication (2FA or " "one-time password, OTP) in IPA." @@ -2954,12 +2974,12 @@ msgstr "" "(2FA o contraseña de una vez, OTP) en IPA." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1963 +#: sssd.conf.5.xml:1960 msgid "idp -- pre-authentication using external identity provider." msgstr "idp -- pre-autenticación utilizando proveedor de identidad externa." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1973 +#: sssd.conf.5.xml:1970 #, no-wrap msgid "" "pam_gssapi_indicators_map = sudo:pkinit, sudo-i:pkinit\n" @@ -2969,7 +2989,7 @@ msgstr "" " " #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1968 +#: sssd.conf.5.xml:1965 msgid "" "Example: to require access to SUDO services only for users which obtained " "their Kerberos tickets with a X.509 certificate pre-authentication (PKINIT), " @@ -2980,19 +3000,67 @@ msgstr "" "(PKINIT), establezca <placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1977 +#: sssd.conf.5.xml:1974 msgid "Default: not set (use of authentication indicators is not required)" msgstr "" "Por defecto: no fijado (la utilización de indicadores de autenticación no " "está requerida)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1979 +#, fuzzy +#| msgid "pam_gssapi_indicators_map" +msgid "pam_gssapi_indicators_apply (string)" +msgstr "pam_gssapi_indicators_map" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1982 +msgid "" +"Comma separated list of triples to assign additional information from the " +"Kerberos ticket, e.g. a SID from the PAC, to authentication indicators." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1988 +#, fuzzy +#| msgid "Currently supported debug levels:" +msgid "Currently supported is:" +msgstr "Niveles de depuración actualmente soportados:" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:1991 +msgid "SID:S-1-5-[domain]-[RID]:[authentication indicator]" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> +#: sssd.conf.5.xml:2002 +#, fuzzy, no-wrap +#| msgid "" +#| "pam_gssapi_indicators_map = sudo:pkinit, sudo-i:pkinit\n" +#| " " +msgid "" +"pam_gssapi_indicators_apply = SID:S-1-5-12345-23456-34567-4321:pkinit\n" +" " +msgstr "" +"pam_gssapi_indicators_map = sudo:pkinit, sudo-i:pkinit\n" +" " + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1996 +msgid "" +"Example: To assign a SID, which is e.g. set by Active Directory's " +"Authentication Mechanism Assurance (AMA) if the AD user used a Smartcard for " +"authentication, to the 'pkinit' authentication indicator use: <placeholder " +"type=\"programlisting\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2011 msgid "pam_json_services (string)" msgstr "pam_json_services (cadena)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1985 +#: sssd.conf.5.xml:2014 msgid "" "Comma separated list of PAM services which can handle the JSON protocol for " "selecting authentication mechanisms" @@ -3001,14 +3069,14 @@ msgstr "" "protocolo JSON para seleccionar los mecanismos de autenticación" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1990 +#: sssd.conf.5.xml:2019 msgid "To disable JSON protocol, set this option to <quote>-</quote> (dash)." msgstr "" "Para inhabilitar el protocolo JSON, ponga esta opción a <quote>-</quote> " "(guion)." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1996 +#: sssd.conf.5.xml:2025 #, no-wrap msgid "" "pam_json_services = gdm-switchable-auth\n" @@ -3018,12 +3086,12 @@ msgstr "" " " #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2000 +#: sssd.conf.5.xml:2029 msgid "Default: - (JSON protocol is disabled)" msgstr "Predeterminado: - (Protocolo JSON está inhabilitado)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2003 +#: sssd.conf.5.xml:2032 msgid "" "Note: 2-Factor Authentication (2FA) is not supported. If 2FA is required, do " "not activate the JSON protocol." @@ -3032,19 +3100,38 @@ msgstr "" "2FA, no activa el protocolo JSON." #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:2013 +#: sssd.conf.5.xml:2042 msgid "SUDO configuration options" msgstr "Opciones de configuración de SUDO" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2015 +#: sssd.conf.5.xml:2044 +#, fuzzy +#| msgid "These options can be used to configure the session recording." msgid "" -"These options can be used to configure the sudo service. The detailed " -"instructions for configuration of <citerefentry> <refentrytitle>sudo</" -"refentrytitle> <manvolnum>8</manvolnum> </citerefentry> to work with " -"<citerefentry> <refentrytitle>sssd</refentrytitle> <manvolnum>8</manvolnum> " -"</citerefentry> are in the manual page <citerefentry> <refentrytitle>sssd-" -"sudo</refentrytitle> <manvolnum>5</manvolnum> </citerefentry>." +"These options can be used to configure the sudo service and should be " +"specified under the <quote>[sudo]</quote> section." +msgstr "" +"Se pueden utilizar estas opciones para configurar la grabación de sesión." + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:2048 +#, fuzzy +#| msgid "" +#| "These options can be used to configure the sudo service. The detailed " +#| "instructions for configuration of <citerefentry> <refentrytitle>sudo</" +#| "refentrytitle> <manvolnum>8</manvolnum> </citerefentry> to work with " +#| "<citerefentry> <refentrytitle>sssd</refentrytitle> <manvolnum>8</" +#| "manvolnum> </citerefentry> are in the manual page <citerefentry> " +#| "<refentrytitle>sssd-sudo</refentrytitle> <manvolnum>5</manvolnum> </" +#| "citerefentry>." +msgid "" +"The detailed instructions for configuration of <citerefentry> " +"<refentrytitle>sudo</refentrytitle> <manvolnum>8</manvolnum> </citerefentry> " +"to work with <citerefentry> <refentrytitle>sssd</refentrytitle> " +"<manvolnum>8</manvolnum> </citerefentry> are in the manual page " +"<citerefentry> <refentrytitle>sssd-sudo</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry>." msgstr "" "Se pueden usar estas opciones para configurar el servicio sudo. Las " "instrucciones detalladas para la configuración de <citerefentry> " @@ -3055,12 +3142,14 @@ msgstr "" "manvolnum> </citerefentry>." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2032 -msgid "sudo_timed (bool)" +#: sssd.conf.5.xml:2064 +#, fuzzy +#| msgid "sudo_timed (bool)" +msgid "sudo_timed (boolean)" msgstr "sudo_timed (booleano)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2035 +#: sssd.conf.5.xml:2067 msgid "" "Whether or not to evaluate the sudoNotBefore and sudoNotAfter attributes " "that implement time-dependent sudoers entries." @@ -3069,12 +3158,12 @@ msgstr "" "entradas de sudoers dependientes del tiempo." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2047 +#: sssd.conf.5.xml:2079 msgid "sudo_threshold (integer)" msgstr "sudo_threshold (entero)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2050 +#: sssd.conf.5.xml:2082 msgid "" "Maximum number of expired rules that can be refreshed at once. If number of " "expired rules is below threshold, those rules are refreshed with " @@ -3090,22 +3179,26 @@ msgstr "" "comando." #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:2069 +#: sssd.conf.5.xml:2101 msgid "AUTOFS configuration options" msgstr "Opciones de configuración AUTOFS" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2071 -msgid "These options can be used to configure the autofs service." +#: sssd.conf.5.xml:2103 +#, fuzzy +#| msgid "These options can be used to configure the autofs service." +msgid "" +"These options can be used to configure the autofs service and should be " +"specified under the <quote>[autofs]</quote> section." msgstr "Estas opciones pueden ser usadas para configurar el servicio autofs." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2075 +#: sssd.conf.5.xml:2109 msgid "autofs_negative_timeout (integer)" msgstr "autofs_negative_timeout (entero)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2078 +#: sssd.conf.5.xml:2112 msgid "" "Specifies for how many seconds should the autofs responder negative cache " "hits (that is, queries for invalid map entries, like nonexistent ones) " @@ -3116,22 +3209,28 @@ msgstr "" "validado, como las no existentes) antes de preguntar al punto final otra vez." #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:2094 +#: sssd.conf.5.xml:2128 msgid "SSH configuration options" msgstr "Opciones de configuración SSH" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2096 -msgid "These options can be used to configure the SSH service." +#: sssd.conf.5.xml:2130 +#, fuzzy +#| msgid "These options can be used to configure the SSH service." +msgid "" +"These options can be used to configure the SSH service and should be " +"specified under the <quote>[ssh]</quote> section." msgstr "Estas opciones se pueden usar para configurar el servicio SSH." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2100 -msgid "ssh_use_certificate_keys (bool)" +#: sssd.conf.5.xml:2136 +#, fuzzy +#| msgid "ssh_use_certificate_keys (bool)" +msgid "ssh_use_certificate_keys (boolean)" msgstr "ssh_use_certificate_keys (booleano)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2103 +#: sssd.conf.5.xml:2139 msgid "" "If set to true the <command>sss_ssh_authorizedkeys</command> will return ssh " "keys derived from the public key of X.509 certificates stored in the user " @@ -3145,12 +3244,12 @@ msgstr "" "manvolnum> </citerefentry> for details." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2118 +#: sssd.conf.5.xml:2154 msgid "ssh_use_certificate_matching_rules (string)" msgstr "ssh_use_certificate_matching_rules (cadena)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2121 +#: sssd.conf.5.xml:2157 msgid "" "By default the ssh responder will use all available certificate matching " "rules to filter the certificates so that ssh keys are only derived from the " @@ -3165,7 +3264,7 @@ msgstr "" "de reglas que coincidan y mapeen. Todas las demás reglas serán ignoradas." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2130 +#: sssd.conf.5.xml:2166 msgid "" "There are two special key words 'all_rules' and 'no_rules' which will enable " "all or no rules, respectively. The latter means that no certificates will be " @@ -3177,7 +3276,7 @@ msgstr "" "serán generadas desde todos los certificados válidos." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2137 +#: sssd.conf.5.xml:2173 msgid "" "If no rules are configured using 'all_rules' will enable a default rule " "which enables all certificates suitable for client authentication. This is " @@ -3190,7 +3289,7 @@ msgstr "" "respuesta PAM si la autenticación del certificado está habilitada." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2144 +#: sssd.conf.5.xml:2180 msgid "" "A non-existing rule name is considered an error. If as a result no rule is " "selected all certificates will be ignored." @@ -3200,7 +3299,7 @@ msgstr "" "ignorados." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2149 +#: sssd.conf.5.xml:2185 msgid "" "Default: not set, equivalent to 'all_rules', all found rules or the default " "rule are used" @@ -3209,12 +3308,12 @@ msgstr "" "o se utiliza la regla predeterminada" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2155 +#: sssd.conf.5.xml:2191 msgid "ca_db (string)" msgstr "ca_db (cadena)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2158 +#: sssd.conf.5.xml:2194 msgid "" "Path to a storage of trusted CA certificates. The option is used to validate " "user certificates before deriving public ssh keys from them." @@ -3224,12 +3323,12 @@ msgstr "" "públicas ssh de ellos." #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:2178 +#: sssd.conf.5.xml:2214 msgid "PAC responder configuration options" msgstr "Opciones de configuración del contestador PAC" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2180 +#: sssd.conf.5.xml:2216 msgid "" "The PAC responder works together with the authorization data plugin for MIT " "Kerberos sssd_pac_plugin.so and a sub-domain provider. The plugin sends the " @@ -3247,7 +3346,7 @@ msgstr "" "se hacen algunas de las siguientes operaciones:" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:2189 +#: sssd.conf.5.xml:2225 msgid "" "If the remote user does not exist in the cache, it is created. The UID is " "determined with the help of the SID, trusted domains will have UPGs and the " @@ -3263,7 +3362,7 @@ msgstr "" "predeterminado, pero se puede sustituir con el parámetro default_shell." #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:2197 +#: sssd.conf.5.xml:2233 msgid "" "If there are SIDs of groups from domains sssd knows about, the user will be " "added to those groups." @@ -3272,17 +3371,21 @@ msgstr "" "a esos grupos." #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2203 -msgid "These options can be used to configure the PAC responder." +#: sssd.conf.5.xml:2239 +#, fuzzy +#| msgid "These options can be used to configure the PAC responder." +msgid "" +"These options can be used to configure the PAC responder and should be " +"specified under the <quote>[pac]</quote> section." msgstr "Estas opciones pueden ser usadas para configurar el contestador PAC." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2207 sssd-ifp.5.xml:66 +#: sssd.conf.5.xml:2244 sssd-ifp.5.xml:66 msgid "allowed_uids (string)" msgstr "allowed_uids (cadena)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2210 +#: sssd.conf.5.xml:2247 msgid "" "Specifies the comma-separated list of UID values or user names that are " "allowed to access the PAC responder. User names are resolved to UIDs at " @@ -3292,7 +3395,7 @@ msgstr "" "usuario que tiene el acceso permitido al contestador PAC." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2216 +#: sssd.conf.5.xml:2253 msgid "" "Default: 0, &sssd_user_name; (only root and SSSD service users are allowed " "to access the PAC responder)" @@ -3301,14 +3404,14 @@ msgstr "" "tiene permitido el acceso al contestador PAC)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2220 +#: sssd.conf.5.xml:2257 msgid "Default: 0 (only the root user is allowed to access the PAC responder)" msgstr "" "Por defecto: 0 (sólo el usuario root tiene permitido el acceso al " "contestador PAC)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2224 +#: sssd.conf.5.xml:2261 msgid "" "Please note that defaults will be overwritten with this option. If you still " "want to allow the root and/or '&sssd_user_name;' user to access the PAC " @@ -3321,7 +3424,7 @@ msgstr "" "concedidos explícitamente." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2231 +#: sssd.conf.5.xml:2268 msgid "" "Please note that although the UID 0 is used as the default it will be " "overwritten with this option. If you still want to allow the root user to " @@ -3334,12 +3437,12 @@ msgstr "" "lista de los UID permitidos también." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2240 +#: sssd.conf.5.xml:2277 msgid "pac_lifetime (integer)" msgstr "pac_lifetime (entero)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2243 +#: sssd.conf.5.xml:2280 msgid "" "Lifetime of the PAC entry in seconds. As long as the PAC is valid the PAC " "data can be used to determine the group memberships of a user." @@ -3349,12 +3452,12 @@ msgstr "" "usuario." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2253 +#: sssd.conf.5.xml:2290 msgid "pac_check (string)" msgstr "pac_check (cadena)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2256 +#: sssd.conf.5.xml:2293 msgid "" "Apply additional checks on the PAC of the Kerberos ticket which is available " "in Active Directory and FreeIPA domains, if configured. Please note that " @@ -3372,7 +3475,7 @@ msgstr "" "omitirán las comprobaciones del PAC." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2266 +#: sssd.conf.5.xml:2303 msgid "" "Please note that the checks listed below only apply to PACs issued by Active " "Directory or recent versions of FreeIPA. PACs issued e.g. by a plain MIT " @@ -3384,12 +3487,12 @@ msgstr "" "datos PAC necesarios para ejecutar los comprobantes." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2277 +#: sssd.conf.5.xml:2314 msgid "no_check" msgstr "no_check" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2279 +#: sssd.conf.5.xml:2316 msgid "" "The PAC must not be present and even if it is present no additional checks " "will be done." @@ -3398,12 +3501,12 @@ msgstr "" "comprobaciones adicionales." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2285 +#: sssd.conf.5.xml:2322 msgid "pac_present" msgstr "pac_present" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2287 +#: sssd.conf.5.xml:2324 msgid "" "The PAC must be present in the service ticket which SSSD will request with " "the help of the user's TGT. If the PAC is not available the authentication " @@ -3414,12 +3517,12 @@ msgstr "" "autenticación fallará." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2295 +#: sssd.conf.5.xml:2332 msgid "check_upn" msgstr "check_upn" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2297 +#: sssd.conf.5.xml:2334 msgid "" "If the PAC is present check if the user principal name (UPN) information is " "consistent." @@ -3428,12 +3531,12 @@ msgstr "" "nombre principal del usuario (UPN)." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2303 +#: sssd.conf.5.xml:2340 msgid "check_upn_allow_missing" msgstr "check_upn_allow_missing" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2305 +#: sssd.conf.5.xml:2342 msgid "" "This option should be used together with 'check_upn' and handles the case " "where a UPN is set on the server-side but is not read by SSSD. The typical " @@ -3452,7 +3555,7 @@ msgstr "" "por lo que ya no es necesario configurar 'ldap_user_principal'." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2317 +#: sssd.conf.5.xml:2354 msgid "" "Currently this option is set by default to avoid regressions in such " "environments. A log message will be added to the system log and SSSD's debug " @@ -3470,22 +3573,22 @@ msgstr "" "registro." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2331 +#: sssd.conf.5.xml:2368 msgid "upn_dns_info_present" msgstr "upn_dns_info_present" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2333 +#: sssd.conf.5.xml:2370 msgid "The PAC must contain the UPN-DNS-INFO buffer, implies 'check_upn'." msgstr "El PAC debe contener el tampón UPN-DNS-INFO, implica 'check_upn'." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2338 +#: sssd.conf.5.xml:2375 msgid "check_upn_dns_info_ex" msgstr "check_upn_dns_info_ex" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2340 +#: sssd.conf.5.xml:2377 msgid "" "If the PAC is present and the extension to the UPN-DNS-INFO buffer is " "available check if the information in the extension is consistent." @@ -3494,12 +3597,12 @@ msgstr "" "disponible compruebe si es consistente la información en la extensión." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2347 +#: sssd.conf.5.xml:2384 msgid "upn_dns_info_ex_present" msgstr "upn_dns_info_ex_present" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2349 +#: sssd.conf.5.xml:2386 msgid "" "The PAC must contain the extension of the UPN-DNS-INFO buffer, implies " "'check_upn_dns_info_ex', 'upn_dns_info_present' and 'check_upn'." @@ -3508,7 +3611,7 @@ msgstr "" "'check_upn_dns_info_ex', 'upn_dns_info_present' y 'check_upn'." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2273 +#: sssd.conf.5.xml:2310 msgid "" "The following options can be used alone or in a comma-separated list: " "<placeholder type=\"variablelist\" id=\"0\"/>" @@ -3517,7 +3620,7 @@ msgstr "" "por comas: <placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2359 +#: sssd.conf.5.xml:2396 msgid "" "Default: no_check (AD and IPA provider 'check_upn, check_upn_allow_missing, " "check_upn_dns_info_ex')" @@ -3526,12 +3629,12 @@ msgstr "" "check_upn_allow_missing, check_upn_dns_info_ex')" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:2368 +#: sssd.conf.5.xml:2405 msgid "Session recording configuration options" msgstr "Opciones de configuración de la grabación de sesión" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2370 +#: sssd.conf.5.xml:2407 msgid "" "Session recording works in conjunction with <citerefentry> " "<refentrytitle>tlog-rec-session</refentrytitle> <manvolnum>8</manvolnum> </" @@ -3547,51 +3650,66 @@ msgstr "" "refentrytitle> <manvolnum>5</manvolnum> </citerefentry>." #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2383 -msgid "These options can be used to configure session recording." -msgstr "Se pueden usar estas opciones para configurar la grabación de sesión." +#: sssd.conf.5.xml:2420 +#, fuzzy +#| msgid "These options can be used to configure the session recording." +msgid "" +"These options can be used to configure session recording and should be " +"specified under the <quote>[session_recording]</quote> section." +msgstr "" +"Se pueden utilizar estas opciones para configurar la grabación de sesión." + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:2425 +msgid "" +"Note: Unlike other sections, the <quote>[session_recording]</quote> section " +"ignores <replaceable>debug*</replaceable> options and suitable " +"<replaceable>debug*</replaceable> options must be set in <quote>[pam]</" +"quote>, <quote>[nss]</quote> and <quote>[domain/<replaceable>NAME</" +"replaceable>]</quote> sections." +msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2387 sssd-session-recording.5.xml:64 +#: sssd.conf.5.xml:2433 sssd-session-recording.5.xml:64 msgid "scope (string)" msgstr "scope (cadena)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2394 sssd-session-recording.5.xml:71 +#: sssd.conf.5.xml:2440 sssd-session-recording.5.xml:71 msgid "\"none\"" msgstr "\"none\"" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2397 sssd-session-recording.5.xml:74 +#: sssd.conf.5.xml:2443 sssd-session-recording.5.xml:74 msgid "No users are recorded." msgstr "Ningún usuario está registrado." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2402 sssd-session-recording.5.xml:79 +#: sssd.conf.5.xml:2448 sssd-session-recording.5.xml:79 msgid "\"some\"" msgstr "\"some\"" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2405 sssd-session-recording.5.xml:82 +#: sssd.conf.5.xml:2451 sssd-session-recording.5.xml:82 msgid "" "Users/groups specified by <replaceable>users</replaceable> and " "<replaceable>groups</replaceable> options are recorded." msgstr "" "Usuarios/grupos especificados por las opciones <replaceable>users</" -"replaceable> y<replaceable>groups</replaceable> están registrados." +"replaceable> y <replaceable>groups</replaceable> están registrados." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2414 sssd-session-recording.5.xml:91 +#: sssd.conf.5.xml:2460 sssd-session-recording.5.xml:91 msgid "\"all\"" msgstr "\"all\"" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2417 sssd-session-recording.5.xml:94 +#: sssd.conf.5.xml:2463 sssd-session-recording.5.xml:94 msgid "All users are recorded." msgstr "Todos los usuarios están registrados." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2390 sssd-session-recording.5.xml:67 +#: sssd.conf.5.xml:2436 sssd-session-recording.5.xml:67 msgid "" "One of the following strings specifying the scope of session recording: " "<placeholder type=\"variablelist\" id=\"0\"/>" @@ -3600,17 +3718,17 @@ msgstr "" "grabación: <placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2424 sssd-session-recording.5.xml:101 +#: sssd.conf.5.xml:2470 sssd-session-recording.5.xml:101 msgid "Default: \"none\"" msgstr "Predeterminado: \"none\"" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2429 sssd-session-recording.5.xml:106 +#: sssd.conf.5.xml:2475 sssd-session-recording.5.xml:106 msgid "users (string)" msgstr "users (cadena)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2432 sssd-session-recording.5.xml:109 +#: sssd.conf.5.xml:2478 sssd-session-recording.5.xml:109 msgid "" "A comma-separated list of users which should have session recording enabled. " "Matches user names as returned by NSS. I.e. after the possible space " @@ -3622,17 +3740,17 @@ msgstr "" "mayúsculas/minúsculas, etc." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2438 sssd-session-recording.5.xml:115 +#: sssd.conf.5.xml:2484 sssd-session-recording.5.xml:115 msgid "Default: Empty. Matches no users." msgstr "Predeterminado: Vacío. No hay usuarios coincidentes." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2443 sssd-session-recording.5.xml:120 +#: sssd.conf.5.xml:2489 sssd-session-recording.5.xml:120 msgid "groups (string)" msgstr "groups (cadena)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2446 sssd-session-recording.5.xml:123 +#: sssd.conf.5.xml:2492 sssd-session-recording.5.xml:123 msgid "" "A comma-separated list of groups, members of which should have session " "recording enabled. Matches group names as returned by NSS. I.e. after the " @@ -3644,7 +3762,7 @@ msgstr "" "minúsculas, etc." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2452 sssd.conf.5.xml:2484 sssd-session-recording.5.xml:129 +#: sssd.conf.5.xml:2498 sssd.conf.5.xml:2530 sssd-session-recording.5.xml:129 #: sssd-session-recording.5.xml:161 msgid "" "NOTE: using this option (having it set to anything) has a considerable " @@ -3657,17 +3775,17 @@ msgstr "" "pertenece el usuario." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2459 sssd-session-recording.5.xml:136 +#: sssd.conf.5.xml:2505 sssd-session-recording.5.xml:136 msgid "Default: Empty. Matches no groups." msgstr "Predeterminado: Vacío. No empareja grupos." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2464 sssd-session-recording.5.xml:141 +#: sssd.conf.5.xml:2510 sssd-session-recording.5.xml:141 msgid "exclude_users (string)" msgstr "exclude_users (cadena)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2467 sssd-session-recording.5.xml:144 +#: sssd.conf.5.xml:2513 sssd-session-recording.5.xml:144 msgid "" "A comma-separated list of users to be excluded from recording, only " "applicable with 'scope=all'." @@ -3676,17 +3794,17 @@ msgstr "" "registro, solo aplicable a todos los ámbitos con 'scope=all'." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2471 sssd-session-recording.5.xml:148 +#: sssd.conf.5.xml:2517 sssd-session-recording.5.xml:148 msgid "Default: Empty. No users excluded." msgstr "Predeterminado: Vacío. No hay usuarios excluidos." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2476 sssd-session-recording.5.xml:153 +#: sssd.conf.5.xml:2522 sssd-session-recording.5.xml:153 msgid "exclude_groups (string)" msgstr "exclude_groups (cadena)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2479 sssd-session-recording.5.xml:156 +#: sssd.conf.5.xml:2525 sssd-session-recording.5.xml:156 msgid "" "A comma-separated list of groups, members of which should be excluded from " "recording. Only applicable with 'scope=all'." @@ -3695,23 +3813,24 @@ msgstr "" "excluidos desde registro. Solo aplicable con 'scope=all'." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2491 sssd-session-recording.5.xml:168 +#: sssd.conf.5.xml:2537 sssd-session-recording.5.xml:168 msgid "Default: Empty. No groups excluded." msgstr "Predeterminado: Vacío. Sin grupos excluidos." #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:2501 +#: sssd.conf.5.xml:2547 msgid "DOMAIN SECTIONS" msgstr "SECCIONES DE DOMINIO" -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry><para> -#: sssd.conf.5.xml:2508 sssd.conf.5.xml:3964 sssd.conf.5.xml:3965 -#: sssd.conf.5.xml:3968 -msgid "enabled" -msgstr "habilitado" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2554 +#, fuzzy +#| msgid "ad_enable_gc (boolean)" +msgid "enabled (boolean)" +msgstr "ad_enable_gc (booleano)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2511 +#: sssd.conf.5.xml:2557 msgid "" "Explicitly enable or disable the domain. If <quote>true</quote>, the domain " "is always <quote>enabled</quote>. If <quote>false</quote>, the domain is " @@ -3726,12 +3845,12 @@ msgstr "" "opción «Dominios» de la sección <quote>[sssd]</quote>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2523 +#: sssd.conf.5.xml:2569 msgid "domain_type (string)" msgstr "domain_type (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2526 +#: sssd.conf.5.xml:2572 msgid "" "Specifies whether the domain is meant to be used by POSIX-aware clients such " "as the Name Service Switch or by applications that do not need POSIX data to " @@ -3744,7 +3863,7 @@ msgstr "" "disponibles para las interfaces y utilidades de sistema operativo." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2534 +#: sssd.conf.5.xml:2580 msgid "" "Allowed values for this option are <quote>posix</quote> and " "<quote>application</quote>." @@ -3753,7 +3872,7 @@ msgstr "" "application</quote>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2538 +#: sssd.conf.5.xml:2584 msgid "" "POSIX domains are reachable by all services. Application domains are only " "reachable from the InfoPipe responder (see <citerefentry> " @@ -3766,7 +3885,7 @@ msgstr "" "manvolnum> </citerefentry>) y el contestador PAM." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2546 +#: sssd.conf.5.xml:2592 msgid "" "NOTE: The application domains are currently well tested with " "<quote>id_provider=ldap</quote> only." @@ -3775,7 +3894,7 @@ msgstr "" "<quote>id_provider=ldap</quote>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2550 +#: sssd.conf.5.xml:2596 msgid "" "For an easy way to configure a non-POSIX domains, please see the " "<quote>Application domains</quote> section." @@ -3784,17 +3903,17 @@ msgstr "" "Dominios aplicación</quote>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2554 +#: sssd.conf.5.xml:2600 msgid "Default: posix" msgstr "Predeterminado: posix" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2560 +#: sssd.conf.5.xml:2606 msgid "min_id,max_id (integer)" msgstr "min_id, max_id (entero)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2563 +#: sssd.conf.5.xml:2609 msgid "" "UID and GID limits for the domain. If a domain contains an entry that is " "outside these limits, it is ignored." @@ -3803,7 +3922,7 @@ msgstr "" "está fuera de estos límites, ésta es ignorada." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2568 +#: sssd.conf.5.xml:2614 msgid "" "For users, this affects the primary GID limit. The user will not be returned " "to NSS if either the UID or the primary GID is outside the range. For non-" @@ -3816,7 +3935,7 @@ msgstr "" "reportados como en espera." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2575 +#: sssd.conf.5.xml:2621 msgid "" "These ID limits affect even saving entries to cache, not only returning them " "by name or ID." @@ -3825,17 +3944,19 @@ msgstr "" "devolviéndolas por nombre o ID." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2579 +#: sssd.conf.5.xml:2625 msgid "Default: 1 for min_id, 0 (no limit) for max_id" msgstr "Predeterminado: 1 para min_id, 0 (sin límite) para max_id" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2585 -msgid "enumerate (bool)" +#: sssd.conf.5.xml:2631 +#, fuzzy +#| msgid "enumerate (bool)" +msgid "enumerate (boolean)" msgstr "enumerar (bool)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2588 +#: sssd.conf.5.xml:2634 msgid "" "Determines if a domain can be enumerated, that is, whether the domain can " "list all the users and group it contains. Note that it is not required to " @@ -3848,22 +3969,22 @@ msgstr "" "Este parámetros puede tener uno de los siguientes valores:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2596 +#: sssd.conf.5.xml:2642 msgid "TRUE = Users and groups are enumerated" msgstr "TRUE = Usuarios y grupos son enumerados" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2599 +#: sssd.conf.5.xml:2645 msgid "FALSE = No enumerations for this domain" msgstr "FALSE = Sin enumeraciones para este dominio" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2602 sssd.conf.5.xml:2867 sssd.conf.5.xml:3044 +#: sssd.conf.5.xml:2648 sssd.conf.5.xml:2992 sssd.conf.5.xml:3174 msgid "Default: FALSE" msgstr "Predeterminado: FALSE" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2605 +#: sssd.conf.5.xml:2651 msgid "" "Enumerating a domain requires SSSD to download and store ALL user and group " "entries from the remote server." @@ -3872,7 +3993,7 @@ msgstr "" "entradas de usuario y grupo del servidor remoto." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2610 +#: sssd.conf.5.xml:2656 msgid "" "Feature is only supported for domains with id_provider = ldap or id_provider " "= proxy." @@ -3881,7 +4002,7 @@ msgstr "" "id_provider = proxy." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2614 +#: sssd.conf.5.xml:2660 msgid "" "Note: Enabling enumeration has a severe performance impact on SSSD while " "enumeration is running. It may take up to several minutes after SSSD startup " @@ -3905,7 +4026,7 @@ msgstr "" "guardián interno." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2629 +#: sssd.conf.5.xml:2675 msgid "" "While the first enumeration is running, requests for the complete user or " "group lists may return no results until it completes." @@ -3915,7 +4036,7 @@ msgstr "" "completen." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2634 +#: sssd.conf.5.xml:2680 msgid "" "Further, enabling enumeration may increase the time necessary to detect " "network disconnection, as longer timeouts are required to ensure that " @@ -3929,7 +4050,7 @@ msgstr "" "específico id_provider en uso." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2642 +#: sssd.conf.5.xml:2688 msgid "" "For the reasons cited above, enabling enumeration is not recommended, " "especially in large environments." @@ -3938,7 +4059,7 @@ msgstr "" "especialmente en entornos grandes." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2647 +#: sssd.conf.5.xml:2693 msgid "" "Note: the proxy provider is tested with open source modules like " "'libnss_files' and 'libnss_ldap'. 3rd party modules must follow the " @@ -3950,12 +4071,12 @@ msgstr "" "configuración." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2656 +#: sssd.conf.5.xml:2702 msgid "entry_cache_timeout (integer)" msgstr "entry_cache_timeout (entero)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2659 +#: sssd.conf.5.xml:2705 msgid "" "How many seconds should nss_sss consider entries valid before asking the " "backend again" @@ -3964,7 +4085,7 @@ msgstr "" "consultar al backend" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2663 +#: sssd.conf.5.xml:2709 msgid "" "The cache expiration timestamps are stored as attributes of individual " "objects in the cache. Therefore, changing the cache timeout only has effect " @@ -3981,17 +4102,17 @@ msgstr "" "objetivo de forzar el refresco de los apuntes que ya están en la caché." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2676 +#: sssd.conf.5.xml:2722 msgid "Default: 5400" msgstr "Predeterminado: 5400" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2682 +#: sssd.conf.5.xml:2728 msgid "entry_cache_user_timeout (integer)" msgstr "entry_cache_user_timeout (entero)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2685 +#: sssd.conf.5.xml:2731 msgid "" "How many seconds should nss_sss consider user entries valid before asking " "the backend again" @@ -4000,19 +4121,19 @@ msgstr "" "antes de preguntar al punto final otra vez" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2689 sssd.conf.5.xml:2702 sssd.conf.5.xml:2715 -#: sssd.conf.5.xml:2728 sssd.conf.5.xml:2742 sssd.conf.5.xml:2755 -#: sssd.conf.5.xml:2769 sssd.conf.5.xml:2783 sssd.conf.5.xml:2796 +#: sssd.conf.5.xml:2735 sssd.conf.5.xml:2748 sssd.conf.5.xml:2761 +#: sssd.conf.5.xml:2774 sssd.conf.5.xml:2788 sssd.conf.5.xml:2801 +#: sssd.conf.5.xml:2815 sssd.conf.5.xml:2829 msgid "Default: entry_cache_timeout" msgstr "Por defecto: entry_cache_timeout" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2695 +#: sssd.conf.5.xml:2741 msgid "entry_cache_group_timeout (integer)" msgstr "entry_cache_group_timeout (entero)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2698 +#: sssd.conf.5.xml:2744 msgid "" "How many seconds should nss_sss consider group entries valid before asking " "the backend again" @@ -4021,12 +4142,12 @@ msgstr "" "de preguntar al backend otra vez" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2708 +#: sssd.conf.5.xml:2754 msgid "entry_cache_netgroup_timeout (integer)" msgstr "entry_cache_netgroup_timeout (entero)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2711 +#: sssd.conf.5.xml:2757 msgid "" "How many seconds should nss_sss consider netgroup entries valid before " "asking the backend again" @@ -4035,12 +4156,12 @@ msgstr "" "válidas antes de preguntar al backend otra vez" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2721 +#: sssd.conf.5.xml:2767 msgid "entry_cache_service_timeout (integer)" msgstr "entry_cache_service_timeout (entero)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2724 +#: sssd.conf.5.xml:2770 msgid "" "How many seconds should nss_sss consider service entries valid before asking " "the backend again" @@ -4049,12 +4170,12 @@ msgstr "" "antes de preguntar al segundo plano otra vez" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2734 +#: sssd.conf.5.xml:2780 msgid "entry_cache_resolver_timeout (integer)" msgstr "entry_cache_resolver_timeout (entero)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2737 +#: sssd.conf.5.xml:2783 msgid "" "How many seconds should nss_sss consider hosts and networks entries valid " "before asking the backend again" @@ -4063,68 +4184,216 @@ msgstr "" "asignar el segundo plano de nuevo" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2748 +#: sssd.conf.5.xml:2794 msgid "entry_cache_sudo_timeout (integer)" msgstr "entry_cache_sudo_timeout (entero)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2751 -msgid "" -"How many seconds should sudo consider rules valid before asking the backend " -"again" -msgstr "" -"Cuantos segundos debería considerar las regulas sudo válidas antes de " -"preguntar al segundo plano otra vez" +#: sssd.conf.5.xml:2797 +msgid "" +"How many seconds should sudo consider rules valid before asking the backend " +"again" +msgstr "" +"Cuantos segundos debería considerar las regulas sudo válidas antes de " +"preguntar al segundo plano otra vez" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2807 +msgid "entry_cache_autofs_timeout (integer)" +msgstr "entry_cache_autofs_timeout (entero)" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2810 +msgid "" +"How many seconds should the autofs service consider automounter maps valid " +"before asking the backend again" +msgstr "" +"Cuantos segundos deberá considerar el servicio autofs los mapas de auto-" +"montaje válidos antes de preguntar al punto final otra vez" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2821 +msgid "entry_cache_ssh_host_timeout (integer)" +msgstr "entry_cache_ssh_host_timeout (entero)" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2824 +msgid "" +"How many seconds to keep a host ssh key after refresh. IE how long to cache " +"the host key for." +msgstr "" +"Cuantos segundos mantener una clave ssh de host tras refrescar. IE cuanto " +"guardar en caché la clave de host." + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2835 +msgid "offline_timeout (integer)" +msgstr "offline_timeout (entero)" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2838 +msgid "" +"When SSSD switches to offline mode the amount of time before it tries to go " +"back online will increase based upon the time spent disconnected. By " +"default SSSD uses incremental behaviour to calculate delay in between " +"retries. So, the wait time for a given retry will be longer than the wait " +"time for the previous ones. After each unsuccessful attempt to go online, " +"the new interval is recalculated by the following:" +msgstr "" +"Cuando SSSD conmuta al modo fuera de línea la cantidad tiempo antes de que " +"intente volver a estar en línea se incrementará en base al tiempo que ha " +"estado desconectado. De modo predeterminado SSSD utiliza un comportamiento " +"incremental para calcular el retraso entre reintentos. De este modo, el " +"tiempo de espera para un reintento dado no será más largo que el tiempo de " +"los anteriores. Después de cada intento fracasado para estar en línea, el " +"nuevo intervalo se calcula mediante lo siguiente:" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2849 sssd.conf.5.xml:2907 +msgid "" +"new_delay = Minimum(old_delay * 2, offline_timeout_max) + " +"random[0...offline_timeout_random_offset]" +msgstr "" +"new_delay = Minimum(old_delay * 2, offline_timeout_max) + " +"random[0...offline_timeout_random_offset]" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2852 +#, fuzzy +#| msgid "" +#| "The offline_timeout default value is 60. The offline_timeout_max default " +#| "value is 3600. The offline_timeout_random_offset default value is 30. " +#| "The end result is amount of seconds before next retry." +msgid "" +"The offline_timeout default value is 60. The offline_timeout_max default " +"value is 3600. The offline_timeout_random_offset default value is 30. The " +"end result is the number of seconds before next retry." +msgstr "" +"El valor predeterminado de offline_timeout es 60. El valor predeterminado de " +"offline_timeout_max es 3600. El valor predeterminado de " +"offline_timeout_random_offset es 30. El resultado final es la cantidad de " +"segundos antes del próximo reintento." + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2858 +#, fuzzy +#| msgid "" +#| "Note that the maximum length of each interval is defined by " +#| "offline_timeout_max (apart of random part)." +msgid "" +"Note that the maximum length of each interval is defined by " +"offline_timeout_max (apart from the random part)." +msgstr "" +"Note que la longitud máxima de cada intervalo está definido por " +"offline_timeout_max (a parte de parte aleatoria)." + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2868 +msgid "offline_timeout_max (integer)" +msgstr "offline_timeout_max (entero)" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2871 +msgid "" +"Controls by how much the time between attempts to go online can be " +"incremented following unsuccessful attempts to go online." +msgstr "" +"Controla cuanto tiempo entre intentos para conectar puede ser incrementado " +"seguido de intentos incorrectos para ir a en línea." + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2876 +msgid "A value of 0 disables the incrementing behaviour." +msgstr "Un valor de 0 deshabilita el comportamiento de incremento." + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2879 +msgid "" +"The value of this parameter should be set in correlation to offline_timeout " +"parameter value." +msgstr "" +"el valor de este parámetro sería puesto en correlación al valor del " +"parámetro online_timeout." + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2883 +#, fuzzy +#| msgid "" +#| "With offline_timeout set to 60 (default value) there is no point in " +#| "setting offlinet_timeout_max to less than 120 as it will saturate " +#| "instantly. General rule here should be to set offline_timeout_max to at " +#| "least 4 times offline_timeout." +msgid "" +"With offline_timeout set to 60 (default value) there is no point in setting " +"offline_timeout_max to less than 120 as it will saturate instantly. General " +"rule here should be to set offline_timeout_max to at least 4 times " +"offline_timeout." +msgstr "" +"Con establecer offline_timeout a 60 (valor por defecto) no hay ningún punto " +"en establecer offline_timeout_max a menor que 120 como saturará " +"intantemente. La regla general aquí sería establecer offline-timeout_max a " +"al menos 4 veces offline_timeout." + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2889 +msgid "" +"Although a value between 0 and offline_timeout may be specified, it has the " +"effect of overriding the offline_timeout value so is of little use." +msgstr "" +"Aunque un valor entre 0 y offline_timeout puede ser especificado, tiene el " +"efecto de sobrescribir el valor offline_timeout tal que es de poco uso." + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2894 +msgid "Default: 3600" +msgstr "Predeterminado: 3600" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2761 -msgid "entry_cache_autofs_timeout (integer)" -msgstr "entry_cache_autofs_timeout (entero)" +#: sssd.conf.5.xml:2900 +msgid "offline_timeout_random_offset (integer)" +msgstr "offline_timeout_random_offset (entero)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2764 +#: sssd.conf.5.xml:2903 msgid "" -"How many seconds should the autofs service consider automounter maps valid " -"before asking the backend again" +"When SSSD is in offline mode it keeps probing backend servers in specified " +"time intervals:" msgstr "" -"Cuantos segundos deberá considerar el servicio autofs los mapas de auto-" -"montaje válidos antes de preguntar al punto final otra vez" - -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2775 -msgid "entry_cache_ssh_host_timeout (integer)" -msgstr "entry_cache_ssh_host_timeout (entero)" +"Cuando SSSD está en modo desconectado mantiene probar servidores de backend " +"internos a intervalos de tiempo especificados:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2778 +#: sssd.conf.5.xml:2910 msgid "" -"How many seconds to keep a host ssh key after refresh. IE how long to cache " -"the host key for." +"This parameter controls the value of the random offset used for the above " +"equation. Final random_offset value will be random number in range:" msgstr "" -"Cuantos segundos mantener una clave ssh de host tras refrescar. IE cuanto " -"guardar en caché la clave de host." +"Este parámetro controla el valor de desplazamiento aleatorio utilizado para " +"la ecuación de arriba. El valor final de random_offset será número aleatorio " +"dentro del intervalo:" -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2789 -msgid "entry_cache_computer_timeout (integer)" -msgstr "entry_cache_computer_timeout (entero)" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2915 +msgid "[0 - offline_timeout_random_offset]" +msgstr "[0 - offline_timeout_random_offset]" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2792 -msgid "" -"How many seconds to keep the local computer entry before asking the backend " -"again" -msgstr "" -"Cuantos segundos mantener el apunte de computador local antes que el segundo " -"plano de nuevo" +#: sssd.conf.5.xml:2918 +msgid "A value of 0 disables the random offset addition." +msgstr "Un valor de 0 desactiva la adición del desplazamiento aleatorio." + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2921 +msgid "Default: 30" +msgstr "Predeterminado: 30" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2802 +#: sssd.conf.5.xml:2927 msgid "refresh_expired_interval (integer)" msgstr "refresh_expired_interval (entero)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2805 +#: sssd.conf.5.xml:2930 msgid "" "Specifies how many seconds SSSD has to wait before triggering a background " "refresh task which will refresh all expired or nearly expired records." @@ -4134,7 +4403,7 @@ msgstr "" "caducados o a punto de hacerlo." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2810 +#: sssd.conf.5.xml:2935 msgid "" "The background refresh will process users, groups and netgroups in the " "cache. For users who have performed the initgroups (get group membership for " @@ -4147,18 +4416,18 @@ msgstr "" ", tanto la entrada usuario y la membresía de grupo son actualizados." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2818 +#: sssd.conf.5.xml:2943 msgid "This option is automatically inherited for all trusted domains." msgstr "" "Esta opción se hereda automáticamente para todos los dominios de confianza." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2822 +#: sssd.conf.5.xml:2947 msgid "You can consider setting this value to 3/4 * entry_cache_timeout." msgstr "Usted puede considerar ajustar este valor a 3/4 * entry_cache_timeout." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2826 +#: sssd.conf.5.xml:2951 msgid "" "Cache entry will be refreshed by background task when 2/3 of cache timeout " "has already passed. If there are existing cached entries, the background " @@ -4179,18 +4448,20 @@ msgstr "" "la caché existente." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2839 sssd-ldap.5.xml:406 sssd-ldap.5.xml:1834 -#: sssd-ipa.5.xml:255 +#: sssd.conf.5.xml:2964 sssd-ldap.5.xml:406 sssd-ldap.5.xml:1834 +#: sssd-ipa.5.xml:250 msgid "Default: 0 (disabled)" msgstr "Predeterminado: 0 (inhabilitado)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2845 -msgid "cache_credentials (bool)" +#: sssd.conf.5.xml:2970 +#, fuzzy +#| msgid "cache_credentials (bool)" +msgid "cache_credentials (boolean)" msgstr "cache_credentials (bool)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2848 +#: sssd.conf.5.xml:2973 msgid "" "Determines if user credentials are also cached in the local LDB cache. The " "cached credentials refer to passwords, which includes the first (long term) " @@ -4208,7 +4479,7 @@ msgstr "" "correcta sin configuración adicional." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2859 +#: sssd.conf.5.xml:2984 msgid "" "Take a note that while credentials are stored as a salted SHA512 hash, this " "still potentially poses some security risk in case an attacker manages to " @@ -4222,12 +4493,12 @@ msgstr "" "mediante un ataque por fuerza bruta." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2873 +#: sssd.conf.5.xml:2998 msgid "cache_credentials_minimal_first_factor_length (int)" msgstr "cache_credentials_minimal_first_factor_length (entero)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2876 +#: sssd.conf.5.xml:3001 msgid "" "If 2-Factor-Authentication (2FA) is used and credentials should be saved " "this value determines the minimal length the first authentication factor " @@ -4239,7 +4510,7 @@ msgstr "" "SHA512 en el caché." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2883 +#: sssd.conf.5.xml:3008 msgid "" "This should avoid that the short PINs of a PIN based 2FA scheme are saved in " "the cache which would make them easy targets for brute-force attacks." @@ -4249,12 +4520,12 @@ msgstr "" "bruta." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2894 +#: sssd.conf.5.xml:3019 msgid "account_cache_expiration (integer)" msgstr "account_cache_expiration (entero)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2897 +#: sssd.conf.5.xml:3022 msgid "" "Number of days entries are left in cache after last successful login before " "being removed during a cleanup of the cache. 0 means keep forever. The " @@ -4267,17 +4538,17 @@ msgstr "" "grande o igual que offline_credentials_expiration." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2904 +#: sssd.conf.5.xml:3029 msgid "Default: 0 (unlimited)" msgstr "Predeterminado: 0 (ilimitado)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2909 +#: sssd.conf.5.xml:3034 msgid "pwd_expiration_warning (integer)" msgstr "pwd_expiration_warning (entero)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2920 +#: sssd.conf.5.xml:3045 msgid "" "Please note that the backend server has to provide information about the " "expiration time of the password. If this information is missing, sssd " @@ -4290,17 +4561,17 @@ msgstr "" "configurar un proveedor de autorización para el segundo plano." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2927 +#: sssd.conf.5.xml:3052 msgid "Default: 7 (Kerberos), 0 (LDAP)" msgstr "Por defecto: 7 (Kerberos), 0 (LDAP)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2933 +#: sssd.conf.5.xml:3058 msgid "id_provider (string)" msgstr "id_provider (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2936 +#: sssd.conf.5.xml:3061 msgid "" "The identification provider used for the domain. Supported ID providers are:" msgstr "" @@ -4308,12 +4579,12 @@ msgstr "" "admitidos son:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2940 +#: sssd.conf.5.xml:3065 msgid "<quote>proxy</quote>: Support a legacy NSS provider." msgstr "<quote>proxy</quote>: Soporta un proveedor NSS heredado." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2943 +#: sssd.conf.5.xml:3068 msgid "" "<quote>ldap</quote>: LDAP provider. See <citerefentry> <refentrytitle>sssd-" "ldap</refentrytitle> <manvolnum>5</manvolnum> </citerefentry> for more " @@ -4324,8 +4595,8 @@ msgstr "" "información sobre la configuración de LDAP." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2951 sssd.conf.5.xml:3070 sssd.conf.5.xml:3129 -#: sssd.conf.5.xml:3192 +#: sssd.conf.5.xml:3076 sssd.conf.5.xml:3200 sssd.conf.5.xml:3259 +#: sssd.conf.5.xml:3322 msgid "" "<quote>ipa</quote>: FreeIPA and Red Hat Identity Management provider. See " "<citerefentry> <refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</" @@ -4337,8 +4608,8 @@ msgstr "" "FreeIPA." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2960 sssd.conf.5.xml:3079 sssd.conf.5.xml:3138 -#: sssd.conf.5.xml:3201 +#: sssd.conf.5.xml:3085 sssd.conf.5.xml:3209 sssd.conf.5.xml:3268 +#: sssd.conf.5.xml:3331 msgid "" "<quote>ad</quote>: Active Directory provider. See <citerefentry> " "<refentrytitle>sssd-ad</refentrytitle> <manvolnum>5</manvolnum> </" @@ -4350,7 +4621,7 @@ msgstr "" "Directory." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2968 +#: sssd.conf.5.xml:3093 msgid "" "<quote>idp</quote>: Provider for OAuth 2.0/OIDC based Identity Providers " "(IdP). See <citerefentry> <refentrytitle>sssd-idp</refentrytitle> " @@ -4360,13 +4631,22 @@ msgstr "" "Identidad (IdP). Consulte <citerefentry> <refentrytitle>sssd-idp</" "refentrytitle> <manvolnum>5</manvolnum> </citerefentry> para más información." +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3101 +msgid "" +"Default: Not set (This is a mandatory setting that must be explicitly " +"defined for each configured domain)." +msgstr "" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2979 -msgid "use_fully_qualified_names (bool)" +#: sssd.conf.5.xml:3109 +#, fuzzy +#| msgid "use_fully_qualified_names (bool)" +msgid "use_fully_qualified_names (boolean)" msgstr "use_fully_qualified_names (bool)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2982 +#: sssd.conf.5.xml:3112 msgid "" "Use the full name and domain (as formatted by the domain's full_name_format) " "as the user's login name reported to NSS." @@ -4376,7 +4656,7 @@ msgstr "" "NSS." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2987 +#: sssd.conf.5.xml:3117 msgid "" "If set to TRUE, all requests to this domain must use fully qualified names. " "For example, if used in EXAMPLE domain that contains a \"test\" user, " @@ -4390,7 +4670,7 @@ msgstr "" "command> lo haría." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2995 +#: sssd.conf.5.xml:3125 msgid "" "NOTE: This option has no effect on netgroup lookups due to their tendency to " "include nested netgroups without qualified names. For netgroups, all domains " @@ -4402,7 +4682,7 @@ msgstr "" "cualificado." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3002 +#: sssd.conf.5.xml:3132 msgid "" "Default: FALSE (TRUE for trusted domain/sub-domains or if " "default_domain_suffix is used)" @@ -4411,17 +4691,19 @@ msgstr "" "utilizado default_domain_suffix)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3009 -msgid "ignore_group_members (bool)" +#: sssd.conf.5.xml:3139 +#, fuzzy +#| msgid "ignore_group_members (bool)" +msgid "ignore_group_members (boolean)" msgstr "ignore_group_members (bool)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3012 +#: sssd.conf.5.xml:3142 msgid "Do not return group members for group lookups." msgstr "No devuelve miembros de grupo para búsquedas de grupo." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3015 +#: sssd.conf.5.xml:3145 msgid "" "If set to TRUE, the group membership attribute is not requested from the " "ldap server, and group members are not returned when processing group lookup " @@ -4440,7 +4722,7 @@ msgstr "" "pedido como si estuviera vacío." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3033 +#: sssd.conf.5.xml:3163 msgid "" "Enabling this option can also make access provider checks for group " "membership significantly faster, especially for groups containing many " @@ -4451,7 +4733,7 @@ msgstr "" "especialmente para grupos que contienen muchos miembros." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3039 sssd.conf.5.xml:3767 sssd-ldap.5.xml:401 +#: sssd.conf.5.xml:3169 sssd.conf.5.xml:3951 sssd-ldap.5.xml:401 #: sssd-ldap.5.xml:454 sssd-ldap.5.xml:529 sssd-ldap.5.xml:576 #: sssd-ldap.5.xml:599 sssd-ldap.5.xml:638 sssd-ldap.5.xml:657 #: sssd-ldap.5.xml:681 sssd-ldap.5.xml:1114 sssd-ldap.5.xml:1147 @@ -4463,12 +4745,12 @@ msgstr "" "<emphasis>subdomain_inherit</emphasis>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3049 +#: sssd.conf.5.xml:3179 msgid "auth_provider (string)" msgstr "auth_provider (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3052 +#: sssd.conf.5.xml:3182 msgid "" "The authentication provider used for the domain. Supported auth providers " "are:" @@ -4477,7 +4759,7 @@ msgstr "" "autenticación soportados son:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3056 sssd.conf.5.xml:3122 +#: sssd.conf.5.xml:3186 sssd.conf.5.xml:3252 msgid "" "<quote>ldap</quote> for native LDAP authentication. See <citerefentry> " "<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> </" @@ -4488,7 +4770,7 @@ msgstr "" "citerefentry> para más información sobre la configuración LDAP." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3063 +#: sssd.conf.5.xml:3193 msgid "" "<quote>krb5</quote> for Kerberos authentication. See <citerefentry> " "<refentrytitle>sssd-krb5</refentrytitle> <manvolnum>5</manvolnum> </" @@ -4499,7 +4781,7 @@ msgstr "" "citerefentry> para más información sobre la configuración de Kerberos." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3087 +#: sssd.conf.5.xml:3217 msgid "" "<quote>idp</quote>: Provider for OAuth 2.0/OIDC based authentication. See " "<citerefentry> <refentrytitle>sssd-idp</refentrytitle> <manvolnum>5</" @@ -4510,7 +4792,7 @@ msgstr "" "5</manvolnum> </citerefentry> para más información." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3095 +#: sssd.conf.5.xml:3225 msgid "" "<quote>proxy</quote> for relaying authentication to some other PAM target." msgstr "" @@ -4518,12 +4800,12 @@ msgstr "" "destino PAM." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3098 +#: sssd.conf.5.xml:3228 msgid "<quote>none</quote> disables authentication explicitly." msgstr "<quote>none</quote> deshabilita la autenticación explícitamente." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3101 +#: sssd.conf.5.xml:3231 msgid "" "Default: <quote>id_provider</quote> is used if it is set and can handle " "authentication requests." @@ -4532,12 +4814,12 @@ msgstr "" "manejar las peticiones de autenticación." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3107 +#: sssd.conf.5.xml:3237 msgid "access_provider (string)" msgstr "access_provider (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3110 +#: sssd.conf.5.xml:3240 msgid "" "The access control provider used for the domain. There are two built-in " "access providers (in addition to any included in installed backends) " @@ -4548,17 +4830,17 @@ msgstr "" "proveedores especiales internos son:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3116 +#: sssd.conf.5.xml:3246 msgid "<quote>permit</quote> always allow access." msgstr "<quote>permit</quote> siempre permite acceder." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3119 +#: sssd.conf.5.xml:3249 msgid "<quote>deny</quote> always deny access." msgstr "<quote>deny</quote> siempre niega acceder." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3146 +#: sssd.conf.5.xml:3276 msgid "" "<quote>simple</quote> access control based on access or deny lists. See " "<citerefentry> <refentrytitle>sssd-simple</refentrytitle> <manvolnum>5</" @@ -4571,7 +4853,7 @@ msgstr "" "sobre la configuración del módulo de acceso sencillo." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3153 +#: sssd.conf.5.xml:3283 msgid "" "<quote>krb5</quote>: .k5login based access control. See <citerefentry> " "<refentrytitle>sssd-krb5</refentrytitle> <manvolnum>5</manvolnum></" @@ -4583,23 +4865,23 @@ msgstr "" "Kerberos." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3160 +#: sssd.conf.5.xml:3290 msgid "<quote>proxy</quote> for relaying access control to another PAM module." msgstr "" "<quote>proxy</quote> para transmitir control de acceso a otro módulo PAM." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3163 +#: sssd.conf.5.xml:3293 msgid "Default: <quote>permit</quote>" msgstr "Predeterminado: <quote>permit</quote>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3168 +#: sssd.conf.5.xml:3298 msgid "chpass_provider (string)" msgstr "chpass_provider (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3171 +#: sssd.conf.5.xml:3301 msgid "" "The provider which should handle change password operations for the domain. " "Supported change password providers are:" @@ -4608,7 +4890,7 @@ msgstr "" "para el dominio. Los proveedores de cambio de contraseña soportados son:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3176 +#: sssd.conf.5.xml:3306 msgid "" "<quote>ldap</quote> to change a password stored in a LDAP server. See " "<citerefentry> <refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</" @@ -4620,7 +4902,7 @@ msgstr "" "configuración de LDAP." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3184 +#: sssd.conf.5.xml:3314 msgid "" "<quote>krb5</quote> to change the Kerberos password. See <citerefentry> " "<refentrytitle>sssd-krb5</refentrytitle> <manvolnum>5</manvolnum> </" @@ -4631,7 +4913,7 @@ msgstr "" "manvolnum> </citerefentry> para más información sobre configurar Kerberos." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3209 +#: sssd.conf.5.xml:3339 msgid "" "<quote>proxy</quote> for relaying password changes to some other PAM target." msgstr "" @@ -4639,13 +4921,13 @@ msgstr "" "algunos otros destinos de PAM." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3213 +#: sssd.conf.5.xml:3343 msgid "<quote>none</quote> disallows password changes explicitly." msgstr "" "<quote>none</quote> deniega explícitamente los cambios en la contraseña." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3216 +#: sssd.conf.5.xml:3346 msgid "" "Default: <quote>auth_provider</quote> is used if it is set and can handle " "change password requests." @@ -4654,18 +4936,18 @@ msgstr "" "puede manejar las peticiones de cambio de contraseña." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3223 +#: sssd.conf.5.xml:3353 msgid "sudo_provider (string)" msgstr "sudo_provider (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3226 +#: sssd.conf.5.xml:3356 msgid "The SUDO provider used for the domain. Supported SUDO providers are:" msgstr "" "El proveedor SUDO usado por el dominio. Los proveedores SUDO soportados son:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3230 +#: sssd.conf.5.xml:3360 msgid "" "<quote>ldap</quote> for rules stored in LDAP. See <citerefentry> " "<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> </" @@ -4676,7 +4958,7 @@ msgstr "" "citerefentry> para más información sobre la configuración LDAP." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3238 +#: sssd.conf.5.xml:3368 msgid "" "<quote>ipa</quote> the same as <quote>ldap</quote> but with IPA default " "settings." @@ -4685,7 +4967,7 @@ msgstr "" "predeterminados IPA." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3242 +#: sssd.conf.5.xml:3372 msgid "" "<quote>ad</quote> the same as <quote>ldap</quote> but with AD default " "settings." @@ -4694,12 +4976,12 @@ msgstr "" "predeterminados AD." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3246 +#: sssd.conf.5.xml:3376 msgid "<quote>none</quote> disables SUDO explicitly." -msgstr "<quote>none</quote>deshabilita SUDO explícitamente." +msgstr "<quote>none</quote> inhabilita SUDO explícitamente." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3249 +#: sssd.conf.5.xml:3379 msgid "" "Default: The value of <quote>id_provider</quote> is used if it is set and " "can handle sudo requests." @@ -4708,7 +4990,7 @@ msgstr "" "puede manejar las peticiones sudo." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3253 +#: sssd.conf.5.xml:3383 msgid "" "The detailed instructions for configuration of sudo_provider are in the " "manual page <citerefentry> <refentrytitle>sssd-sudo</refentrytitle> " @@ -4725,7 +5007,7 @@ msgstr "" "refentrytitle> <manvolnum>5</manvolnum> </citerefentry>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3268 +#: sssd.conf.5.xml:3398 msgid "" "<emphasis>NOTE:</emphasis> Sudo rules are periodically downloaded in the " "background unless the sudo provider is explicitly disabled. Set " @@ -4739,12 +5021,12 @@ msgstr "" "más." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3278 +#: sssd.conf.5.xml:3408 msgid "selinux_provider (string)" msgstr "selinux_provider (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3281 +#: sssd.conf.5.xml:3411 msgid "" "The provider which should handle loading of selinux settings. Note that this " "provider will be called right after access provider ends. Supported selinux " @@ -4755,7 +5037,7 @@ msgstr "" "finalice. Los proveedores selinux soportados son:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3287 +#: sssd.conf.5.xml:3417 msgid "" "<quote>ipa</quote> to load selinux settings from an IPA server. See " "<citerefentry> <refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</" @@ -4767,28 +5049,33 @@ msgstr "" "IPA." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3295 +#: sssd.conf.5.xml:3425 msgid "<quote>none</quote> disallows fetching selinux settings explicitly." msgstr "" "<quote>none</quote> deshabilita ir a buscar los ajustes selinux " "explícitamente." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3298 +#: sssd.conf.5.xml:3428 +#, fuzzy +#| msgid "" +#| "Default: The value of <quote>id_provider</quote> is used if it is set and " +#| "can handle subdomain requests." msgid "" -"Default: <quote>id_provider</quote> is used if it is set and can handle " -"selinux loading requests." +"Default: the value of <quote>id_provider</quote> is used if it is set and " +"can handle selinux loading requests. Otherwise the result is the same as if " +"the selinux_provider is set to none." msgstr "" -"Por defecto: <quote>id_provider</quote> se usa si está fijado y puede " -"manejar las peticiones de carga selinux." +"Por defecto: El valor de <quote>id_provider</quote> es utilizado si está " +"fijado y puede manipular solicitudes de subdominio." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3304 +#: sssd.conf.5.xml:3435 msgid "subdomains_provider (string)" msgstr "subdomains_provider (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3307 +#: sssd.conf.5.xml:3438 msgid "" "The provider which should handle fetching of subdomains. This value should " "be always the same as id_provider. Supported subdomain providers are:" @@ -4798,7 +5085,7 @@ msgstr "" "soportados son:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3313 +#: sssd.conf.5.xml:3444 msgid "" "<quote>ipa</quote> to load a list of subdomains from an IPA server. See " "<citerefentry> <refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</" @@ -4810,7 +5097,7 @@ msgstr "" "IPA." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3322 +#: sssd.conf.5.xml:3453 msgid "" "<quote>ad</quote> to load a list of subdomains from an Active Directory " "server. See <citerefentry> <refentrytitle>sssd-ad</refentrytitle> " @@ -4823,13 +5110,13 @@ msgstr "" "configuración del proveedor AD." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3331 +#: sssd.conf.5.xml:3462 msgid "<quote>none</quote> disallows fetching subdomains explicitly." msgstr "" "<quote>none</quote> deshabilita el buscador de subdominios explícitamente." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3335 +#: sssd.conf.5.xml:3466 msgid "" "Default: The value of <quote>id_provider</quote> is used if it is set and " "can handle subdomain requests." @@ -4838,12 +5125,12 @@ msgstr "" "fijado y puede manipular solicitudes de subdominio." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3341 +#: sssd.conf.5.xml:3472 msgid "session_provider (string)" msgstr "session_provider (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3344 +#: sssd.conf.5.xml:3475 msgid "" "The provider which configures and manages user session related tasks. The " "only user session task currently provided is the integration with Fleet " @@ -4855,14 +5142,14 @@ msgstr "" "de sesiones soportados son:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3351 +#: sssd.conf.5.xml:3482 msgid "<quote>ipa</quote> to allow performing user session related tasks." msgstr "" "<quote>ipa</quote> para permitir llevar a cabo tareas relacionadas con la " "sesión de usuario." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3355 +#: sssd.conf.5.xml:3486 msgid "" "<quote>none</quote> does not perform any kind of user session related tasks." msgstr "" @@ -4870,17 +5157,17 @@ msgstr "" "de usuario." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3359 +#: sssd.conf.5.xml:3490 msgid "Default: <quote>none</quote>." msgstr "Predeterminado: <quote>none</quote>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3365 +#: sssd.conf.5.xml:3496 msgid "autofs_provider (string)" msgstr "autofs_provider (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3368 +#: sssd.conf.5.xml:3499 msgid "" "The autofs provider used for the domain. Supported autofs providers are:" msgstr "" @@ -4888,7 +5175,7 @@ msgstr "" "son:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3372 +#: sssd.conf.5.xml:3503 msgid "" "<quote>ldap</quote> to load maps stored in LDAP. See <citerefentry> " "<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> </" @@ -4900,7 +5187,7 @@ msgstr "" "LDAP." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3379 +#: sssd.conf.5.xml:3510 msgid "" "<quote>ipa</quote> to load maps stored in an IPA server. See <citerefentry> " "<refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</manvolnum> </" @@ -4912,7 +5199,7 @@ msgstr "" "IPA." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3387 +#: sssd.conf.5.xml:3518 msgid "" "<quote>ad</quote> to load maps stored in an AD server. See <citerefentry> " "<refentrytitle>sssd-ad</refentrytitle> <manvolnum>5</manvolnum> </" @@ -4924,12 +5211,12 @@ msgstr "" "proveedor AD." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3396 +#: sssd.conf.5.xml:3527 msgid "<quote>none</quote> disables autofs explicitly." msgstr "<quote>none</quote> deshabilita autofs explícitamente." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3399 +#: sssd.conf.5.xml:3530 msgid "" "Default: The value of <quote>id_provider</quote> is used if it is set and " "can handle autofs requests." @@ -4938,12 +5225,12 @@ msgstr "" "fijado y puede manipular solicitudes de autofs." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3406 +#: sssd.conf.5.xml:3537 msgid "hostid_provider (string)" msgstr "hostid_provider (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3409 +#: sssd.conf.5.xml:3540 msgid "" "The provider used for retrieving host identity information. Supported " "hostid providers are:" @@ -4952,7 +5239,7 @@ msgstr "" "proveedores de hostid soportados son:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3413 +#: sssd.conf.5.xml:3544 msgid "" "<quote>ipa</quote> to load host identity stored in an IPA server. See " "<citerefentry> <refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</" @@ -4964,12 +5251,12 @@ msgstr "" "configuración de IPA." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3421 +#: sssd.conf.5.xml:3552 msgid "<quote>none</quote> disables hostid explicitly." msgstr "<quote>none</quote> deshabilita hostid explícitamente." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3424 +#: sssd.conf.5.xml:3555 msgid "" "Default: The value of <quote>id_provider</quote> is used if it is set and " "can handle hostid requests." @@ -4978,12 +5265,12 @@ msgstr "" "fijado y puede manipular solicitudes de hostid." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3431 +#: sssd.conf.5.xml:3562 msgid "resolver_provider (string)" msgstr "resolver_provider (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3434 +#: sssd.conf.5.xml:3565 msgid "" "The provider which should handle hosts and networks lookups. Supported " "resolver providers are:" @@ -4992,7 +5279,7 @@ msgstr "" "proveedores de resolución compatibles son:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3438 +#: sssd.conf.5.xml:3569 msgid "" "<quote>proxy</quote> to forward lookups to another NSS library. See " "<quote>proxy_resolver_lib_name</quote>" @@ -5001,7 +5288,7 @@ msgstr "" "<quote>proxy_resolver_lib_name</quote>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3442 +#: sssd.conf.5.xml:3573 msgid "" "<quote>ldap</quote> to fetch hosts and networks stored in LDAP. See " "<citerefentry> <refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</" @@ -5013,7 +5300,7 @@ msgstr "" "configuración de LDAP." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3449 +#: sssd.conf.5.xml:3580 msgid "" "<quote>ad</quote> to fetch hosts and networks stored in AD. See " "<citerefentry> <refentrytitle>sssd-ad</refentrytitle> <manvolnum>5</" @@ -5026,12 +5313,12 @@ msgstr "" "configuración del proveedor de AD." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3457 +#: sssd.conf.5.xml:3588 msgid "<quote>none</quote> disallows fetching hosts and networks explicitly." msgstr "<quote>none</quote> inhabilita obtener hosts y redes explícitamente." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3460 +#: sssd.conf.5.xml:3591 msgid "" "Default: The value of <quote>id_provider</quote> is used if it is set and " "can handle resolver requests." @@ -5040,7 +5327,7 @@ msgstr "" "puede manejar las peticiones de resolutor." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3470 +#: sssd.conf.5.xml:3601 msgid "" "Regular expression for this domain that describes how to parse the string " "containing user name and domain into these components. The \"domain\" can " @@ -5055,7 +5342,7 @@ msgstr "" "dominios Active Directory, el nombre plano (NetBIOS) del dominio." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3479 +#: sssd.conf.5.xml:3610 msgid "" "Default: <quote>^((?P<name>.+)@(?P<domain>[^@]*)|(?P<name>" "[^@]+))$</quote> which allows two different styles for user names:" @@ -5065,17 +5352,17 @@ msgstr "" "nombres de usuario:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:3484 sssd.conf.5.xml:3498 +#: sssd.conf.5.xml:3615 sssd.conf.5.xml:3629 msgid "username" msgstr "nombre de usuario" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:3487 sssd.conf.5.xml:3501 +#: sssd.conf.5.xml:3618 sssd.conf.5.xml:3632 msgid "username@domain.name" msgstr "username@domain.name" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3492 +#: sssd.conf.5.xml:3623 msgid "" "Default for the AD and IPA provider: <quote>^(((?P<domain>[^\\\\]+)\\\\" "(?P<name>.+))|((?P<name>.+)@(?P<domain>[^@]+))|((?" @@ -5088,12 +5375,12 @@ msgstr "" "nombres de usuario:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:3504 +#: sssd.conf.5.xml:3635 msgid "domain\\username" msgstr "dominio/nombre_de_usuario" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3507 +#: sssd.conf.5.xml:3638 msgid "" "While the first two correspond to the general default the third one is " "introduced to allow easy integration of users from Windows domains." @@ -5103,7 +5390,7 @@ msgstr "" "dominios Windows." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3512 +#: sssd.conf.5.xml:3643 msgid "" "The default re_expression uses the <quote>@</quote> character as a separator " "between the name and the domain. As a result of this setting the default " @@ -5118,17 +5405,17 @@ msgstr "" "con <quote>@</quote>, debe crear su propia re_expresión." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3564 +#: sssd.conf.5.xml:3695 msgid "Default: <quote>%1$s@%2$s</quote>." msgstr "Predeterminado: <quote>%1$s@%2$s</quote>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3570 +#: sssd.conf.5.xml:3701 msgid "lookup_family_order (string)" msgstr "lookup_family_order (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3573 +#: sssd.conf.5.xml:3704 msgid "" "Provides the ability to select preferred address family to use when " "performing DNS lookups." @@ -5137,51 +5424,55 @@ msgstr "" "a usar cuando se lleven a cabo búsquedas DNS." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3577 +#: sssd.conf.5.xml:3708 msgid "Supported values:" msgstr "Valores soportados:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3580 +#: sssd.conf.5.xml:3711 msgid "ipv4_first: Try looking up IPv4 address, if that fails, try IPv6" msgstr "ipv4_first: Intenta buscar dirección IPv4, si falla, intenta IPv6" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3583 +#: sssd.conf.5.xml:3714 msgid "ipv4_only: Only attempt to resolve hostnames to IPv4 addresses." msgstr "ipv4_only: Sólo intenta resolver nombres de host a direcciones IPv4." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3586 +#: sssd.conf.5.xml:3717 msgid "ipv6_first: Try looking up IPv6 address, if that fails, try IPv4" msgstr "ipv6_first: Intenta buscar dirección IPv6, si falla, intenta IPv4" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3589 +#: sssd.conf.5.xml:3720 msgid "ipv6_only: Only attempt to resolve hostnames to IPv6 addresses." msgstr "ipv6_only: Sólo intenta resolver nombres de host a direcciones IPv6." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3592 +#: sssd.conf.5.xml:3723 msgid "Default: ipv4_first" msgstr "Predeterminado: ipv4_first" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3598 +#: sssd.conf.5.xml:3729 msgid "dns_resolver_server_timeout (integer)" msgstr "dns_resolver_server_timeout (entero)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3601 +#: sssd.conf.5.xml:3732 +#, fuzzy +#| msgid "" +#| "Defines the amount of time (in milliseconds) SSSD would try to talk to " +#| "DNS server before trying next DNS server." msgid "" -"Defines the amount of time (in milliseconds) SSSD would try to talk to DNS " -"server before trying next DNS server." +"Defines the timeout duration (in milliseconds) SSSD waits for a DNS server " +"to respond before moving to the next one." msgstr "" "Defina la cantidad de tiempo (en milisegundos) SSSD intentaría hablar con " "el servidor DNS antes de intentar con el siguiente DNS." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3606 +#: sssd.conf.5.xml:3737 msgid "" "The AD provider will use this option for the CLDAP ping timeouts as well." msgstr "" @@ -5189,26 +5480,43 @@ msgstr "" "CLDAP también." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3610 sssd.conf.5.xml:3630 sssd.conf.5.xml:3651 -msgid "" -"Please see the section <quote>FAILOVER</quote> for more information about " -"the service resolution." +#: sssd.conf.5.xml:3741 sssd.conf.5.xml:3777 sssd.conf.5.xml:3814 +#, fuzzy +#| msgid "" +#| "Specifies the timeout (in seconds) after which the <citerefentry> " +#| "<refentrytitle>poll</refentrytitle> <manvolnum>2</manvolnum> </" +#| "citerefentry>/<citerefentry> <refentrytitle>select</refentrytitle> " +#| "<manvolnum>2</manvolnum> </citerefentry> following a <citerefentry> " +#| "<refentrytitle>connect</refentrytitle> <manvolnum>2</manvolnum> </" +#| "citerefentry> returns in case of no activity." +msgid "" +"Please see the section <quote>FAILOVER</quote> in <citerefentry> " +"<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> </" +"citerefentry>, <citerefentry> <refentrytitle>sssd-krb5</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry>, <citerefentry> <refentrytitle>sssd-" +"ipa</refentrytitle> <manvolnum>5</manvolnum> </citerefentry> or " +"<citerefentry> <refentrytitle>sssd-ad</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry> for more information about the service resolution." msgstr "" -"Por favor vea la sección <quote>RECUPERACIÓN DE FALLOS</quote> para más " -"información sobre la resolución del servicio." +"Especifica el tiempo de salida (en segudos) después del cual <citerefentry> " +"<refentrytitle>poll</refentrytitle> <manvolnum>2</manvolnum> </citerefentry>/" +"<citerefentry> <refentrytitle>select</refentrytitle> <manvolnum>2</" +"manvolnum> </citerefentry> siguiendo un <citerefentry> " +"<refentrytitle>connect</refentrytitle> <manvolnum>2</manvolnum> </" +"citerefentry> vuelve en caso de no actividad." #. type: Content of: <refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3615 sssd-ldap.5.xml:700 include/failover.xml:84 +#: sssd.conf.5.xml:3762 sssd-ldap.5.xml:700 include/failover.xml:84 msgid "Default: 1000" msgstr "Predeterminado: 1000" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3621 +#: sssd.conf.5.xml:3768 msgid "dns_resolver_op_timeout (integer)" msgstr "dns_resolver_op_timeout (entero)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3624 +#: sssd.conf.5.xml:3771 msgid "" "Defines the amount of time (in seconds) to wait to resolve single DNS query " "(e.g. resolution of a hostname or an SRV record) before trying the next " @@ -5219,17 +5527,17 @@ msgstr "" "SRV) antes de intentar con el siguiente nombre de host o descubrir por DNS." #. type: Content of: <refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3635 include/failover.xml:100 +#: sssd.conf.5.xml:3798 include/failover.xml:100 msgid "Default: 3" msgstr "Predeterminado: 3" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3641 +#: sssd.conf.5.xml:3804 msgid "dns_resolver_timeout (integer)" msgstr "dns_resolver_timeout (entero)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3644 +#: sssd.conf.5.xml:3807 msgid "" "Defines the amount of time (in seconds) to wait for a reply from the " "internal fail over service before assuming that the service is unreachable. " @@ -5242,12 +5550,14 @@ msgstr "" "para operar en modo desconectado." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3662 -msgid "dns_resolver_use_search_list (bool)" +#: sssd.conf.5.xml:3841 +#, fuzzy +#| msgid "dns_resolver_use_search_list (bool)" +msgid "dns_resolver_use_search_list (boolean)" msgstr "dns_resolver_use_search_list (bool)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3665 +#: sssd.conf.5.xml:3844 msgid "" "Normally, the DNS resolver searches the domain list defined in the " "\"search\" directive from the resolv.conf file. This can lead to delays in " @@ -5258,7 +5568,7 @@ msgstr "" "en entornos con DNS impropiamente configurado." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3671 +#: sssd.conf.5.xml:3850 msgid "" "If fully qualified domain names (or _srv_) are used in the SSSD " "configuration, setting this option to FALSE can prevent unnecessary DNS " @@ -5269,17 +5579,17 @@ msgstr "" "prevenir búsqueda de DNS dentro de tales entornos." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3677 +#: sssd.conf.5.xml:3856 msgid "Default: TRUE" msgstr "Predeterminado: TRUE" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3683 +#: sssd.conf.5.xml:3862 msgid "dns_discovery_domain (string)" msgstr "dns_discovery_domain (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3686 +#: sssd.conf.5.xml:3865 msgid "" "If service discovery is used in the back end, specifies the domain part of " "the service discovery DNS query." @@ -5288,18 +5598,18 @@ msgstr "" "de dominio de la pregunta al descubridor de servicio DNS." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3690 +#: sssd.conf.5.xml:3869 msgid "Default: Use the domain part of machine's hostname" msgstr "" "Predeterminado: Utilizar la parte del dominio del nombre de host del equipo" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3696 +#: sssd.conf.5.xml:3875 msgid "failover_primary_timeout (integer)" msgstr "failover_primary_timeout (entero)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3699 +#: sssd.conf.5.xml:3878 msgid "" "When no primary server is available, SSSD fails over to a backup server. " "This option defines the number of seconds SSSD waits before attempting to " @@ -5310,59 +5620,72 @@ msgstr "" "para SSSD intentando a reconectar al servidor primario." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3706 +#: sssd.conf.5.xml:3885 msgid "Note: The minimum value is 31." msgstr "Nota: el valor mínimo es 31." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3709 +#: sssd.conf.5.xml:3888 msgid "Default: 31" msgstr "Predeterminado: 31" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3715 +#: sssd.conf.5.xml:3894 msgid "override_gid (integer)" msgstr "override_gid (entero)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3718 -msgid "Override the primary GID value with the one specified." +#: sssd.conf.5.xml:3897 +#, fuzzy +#| msgid "Override the primary GID value with the one specified." +msgid "" +"Override the primary GID value for all users in the domain with specified " +"value." msgstr "Anula el valor primario GID con el uno especificado." +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3901 +#, fuzzy +#| msgid "Default: not set (SSSD will use the value retrieved from LDAP)" +msgid "" +"Default: not set (Use the primary GID value retrieved from the identity " +"provider)" +msgstr "Por defecto: no fijado (SSSD usará el valor recuperado desde LDAP)" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3724 +#: sssd.conf.5.xml:3908 msgid "case_sensitive (string)" msgstr "case_sensitive (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3731 +#: sssd.conf.5.xml:3915 msgid "True" msgstr "True" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3734 +#: sssd.conf.5.xml:3918 msgid "Case sensitive. This value is invalid for AD provider." msgstr "" "Distingue mayúsculas y minúsculas. Este valor es invalido para el proveedor " "AD." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3740 +#: sssd.conf.5.xml:3924 msgid "False" msgstr "False" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3742 +#: sssd.conf.5.xml:3926 msgid "Case insensitive." msgstr "No sensible a mayúsculas/minúsculas." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3746 +#: sssd.conf.5.xml:3930 msgid "Preserving" msgstr "Preservir" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3749 +#: sssd.conf.5.xml:3933 msgid "" "Same as False (case insensitive), but does not lowercase names in the result " "of NSS operations. Note that name aliases (and in case of services also " @@ -5374,7 +5697,7 @@ msgstr "" "protocolo) están en minúsculas en la salida." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3757 +#: sssd.conf.5.xml:3941 msgid "" "If you want to set this value for trusted domain with IPA provider, you need " "to set it on both the client and SSSD on the server." @@ -5383,7 +5706,7 @@ msgstr "" "necesita establecerlo en ambos el cliente y SSSD en el servidor." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3727 +#: sssd.conf.5.xml:3911 msgid "" "Treat user and group names as case sensitive. Possible option values are: " "<placeholder type=\"variablelist\" id=\"0\"/>" @@ -5393,17 +5716,47 @@ msgstr "" "type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3772 +#: sssd.conf.5.xml:3956 msgid "Default: True (False for AD provider)" msgstr "Predeterminado: True (False para proveedor AD)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3778 +#: sssd.conf.5.xml:3962 +#, fuzzy +#| msgid "ad_enable_dns_sites (boolean)" +msgid "avoid_by_id_lookups (boolean)" +msgstr "ad_enable_dns_sites (booleano)" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3965 +msgid "" +"If this option is set to 'true' SSSD will try to avoid sending lookups by ID " +"to the backend and will switch to a lookup by name if a cached object with a " +"matching ID can be found." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3971 +msgid "" +"This option can e.g. be used in cases where searches by ID are expensive on " +"the server side because of missing indexes or are not even possible, e.g. " +"due to non-reversible POSIX id-mapping." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3978 +#, fuzzy +#| msgid "Default: True (False for AD provider)" +msgid "Default: False (True for IdP provider)" +msgstr "Predeterminado: True (False para proveedor AD)" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:3984 msgid "subdomain_inherit (string)" msgstr "subdomain_inherit (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3781 +#: sssd.conf.5.xml:3987 msgid "" "Specifies a list of configuration parameters that should be inherited by a " "subdomain. Please note that only selected parameters can be inherited. " @@ -5415,37 +5768,37 @@ msgstr "" "siguientes opciones:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3787 +#: sssd.conf.5.xml:3993 msgid "ldap_search_timeout" msgstr "ldap_search_timeout" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3790 +#: sssd.conf.5.xml:3996 msgid "ldap_network_timeout" msgstr "ldap_network_timeout" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3793 +#: sssd.conf.5.xml:3999 msgid "ldap_opt_timeout" msgstr "ldap_opt_timeout" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3796 +#: sssd.conf.5.xml:4002 msgid "ldap_offline_timeout" msgstr "ldap_offline_timeout" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3799 +#: sssd.conf.5.xml:4005 msgid "ldap_purge_cache_timeout" msgstr "ldap_purge_cache_timeout" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3802 +#: sssd.conf.5.xml:4008 msgid "ldap_purge_cache_offset" msgstr "ldap_purge_cache_offset" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3805 +#: sssd.conf.5.xml:4011 msgid "" "ldap_krb5_keytab (the value of krb5_keytab will be used if ldap_krb5_keytab " "is not set explicitly)" @@ -5454,52 +5807,52 @@ msgstr "" "explícitamente ldap_krb5_keytab)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3809 +#: sssd.conf.5.xml:4015 msgid "ldap_krb5_ticket_lifetime" msgstr "ldap_krb5_ticket_lifetime" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3812 +#: sssd.conf.5.xml:4018 msgid "ldap_connection_expire_timeout" msgstr "ldap_connection_expire_timeout" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3815 +#: sssd.conf.5.xml:4021 msgid "ldap_connection_expire_offset" msgstr "ldap_connection_expire_offset" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3818 +#: sssd.conf.5.xml:4024 msgid "ldap_connection_idle_timeout" msgstr "ldap_connection_idle_timeout" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3821 sssd-ldap.5.xml:446 +#: sssd.conf.5.xml:4027 sssd-ldap.5.xml:446 msgid "ldap_use_tokengroups" msgstr "ldap_use_tokengroups" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3824 +#: sssd.conf.5.xml:4030 msgid "ldap_user_principal" msgstr "ldap_user_principal" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3827 +#: sssd.conf.5.xml:4033 msgid "ignore_group_members" msgstr "ignore_group_members" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3830 +#: sssd.conf.5.xml:4036 msgid "auto_private_groups" msgstr "auto_private_groups" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3833 +#: sssd.conf.5.xml:4039 msgid "case_sensitive" msgstr "case_sensitive" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:3838 +#: sssd.conf.5.xml:4044 #, no-wrap msgid "" "subdomain_inherit = ldap_purge_cache_timeout\n" @@ -5509,27 +5862,27 @@ msgstr "" " " #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3845 +#: sssd.conf.5.xml:4051 msgid "Note: This option only works with the IPA and AD provider." msgstr "Nota: esta opción solo funciona con los proveedores IPA y AD." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3852 +#: sssd.conf.5.xml:4058 msgid "subdomain_homedir (string)" msgstr "subdomain_homedir (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3863 +#: sssd.conf.5.xml:4069 msgid "%F" msgstr "%F" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3864 +#: sssd.conf.5.xml:4070 msgid "flat (NetBIOS) name of a subdomain." msgstr "flat (NetBIOS) nombre de un subdominio." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3855 +#: sssd.conf.5.xml:4061 msgid "" "Use this homedir as default value for all subdomains within this domain in " "IPA AD trust. See <emphasis>override_homedir</emphasis> for info about " @@ -5544,7 +5897,7 @@ msgstr "" "subdomain_homedir</emphasis>. <placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3869 +#: sssd.conf.5.xml:4075 msgid "" "The value can be overridden by <emphasis>override_homedir</emphasis> option." msgstr "" @@ -5552,17 +5905,17 @@ msgstr "" "emphasis>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3873 +#: sssd.conf.5.xml:4079 msgid "Default: <filename>/home/%d/%u</filename>" msgstr "Por defecto: <filename>/home/%d/%u</filename>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3878 +#: sssd.conf.5.xml:4084 msgid "realmd_tags (string)" msgstr "realmd_tags (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3881 +#: sssd.conf.5.xml:4087 msgid "" "Various tags stored by the realmd configuration service for this domain." msgstr "" @@ -5570,17 +5923,23 @@ msgstr "" "este dominio." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3887 +#: sssd.conf.5.xml:4093 msgid "cached_auth_timeout (int)" msgstr "cached_auth_timeout (int)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3890 +#: sssd.conf.5.xml:4096 +#, fuzzy +#| msgid "" +#| "Specifies time in seconds since last successful online authentication for " +#| "which user will be authenticated using cached credentials while SSSD is " +#| "in the online mode. If the credentials are incorrect, SSSD falls back to " +#| "online authentication." msgid "" -"Specifies time in seconds since last successful online authentication for " -"which user will be authenticated using cached credentials while SSSD is in " -"the online mode. If the credentials are incorrect, SSSD falls back to online " -"authentication." +"Specifies the number of seconds since the last successful online " +"authentication during which SSSD will authenticate users via cached " +"credentials, even while online. If the cached authentication fails, SSSD " +"immediately falls back to online authentication." msgstr "" "Especifica el tiempo en segundos desde la última autenticación conectada por " "las cuales el usuario serán autenticado usando las credenciales en cache " @@ -5588,7 +5947,7 @@ msgstr "" "SSSD retorna a la conexión de autenticación." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3898 +#: sssd.conf.5.xml:4103 msgid "" "This option's value is inherited by all trusted domains. At the moment it is " "not possible to set a different value per trusted domain." @@ -5598,12 +5957,12 @@ msgstr "" "confianza." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3903 +#: sssd.conf.5.xml:4108 msgid "Special value 0 implies that this feature is disabled." msgstr "El valor especial 0 implica que esta función está inhabilitada." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3907 +#: sssd.conf.5.xml:4112 msgid "" "Please note that if <quote>cached_auth_timeout</quote> is longer than " "<quote>pam_id_timeout</quote> then the back end could be called to handle " @@ -5614,12 +5973,12 @@ msgstr "" "gestionar <quote>initgroups.</quote>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3918 +#: sssd.conf.5.xml:4123 msgid "local_auth_policy (string)" msgstr "local_auth_policy (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3921 +#: sssd.conf.5.xml:4126 msgid "" "Local authentication methods policy. Some backends (i.e. LDAP, proxy " "provider) only support a password based authentication, while others can " @@ -5639,7 +5998,7 @@ msgstr "" "comprueban localmente." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3933 +#: sssd.conf.5.xml:4138 msgid "" "There are three possible values for this option: match, only, enable. " "<quote>match</quote> is used to match offline and online states for Kerberos " @@ -5659,7 +6018,7 @@ msgstr "" "separados por coma, como <quote>enable:passkey,enable:smartcard</quote>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3946 +#: sssd.conf.5.xml:4151 msgid "" "The following table shows which authentication methods, if configured " "properly, are currently enabled or disabled for each backend, with the " @@ -5671,42 +6030,47 @@ msgstr "" "coincide</quote>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> -#: sssd.conf.5.xml:3959 +#: sssd.conf.5.xml:4164 msgid "local_auth_policy = match (default)" msgstr "local_auth_policy = match (default)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> -#: sssd.conf.5.xml:3960 +#: sssd.conf.5.xml:4165 msgid "Passkey" msgstr "Llave de paso" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> -#: sssd.conf.5.xml:3961 +#: sssd.conf.5.xml:4166 msgid "Smartcard" msgstr "Tarjeta inteligente" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:3964 sssd-ldap.5.xml:228 +#: sssd.conf.5.xml:4169 sssd-ldap.5.xml:228 msgid "IPA" msgstr "IPA" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry><para> +#: sssd.conf.5.xml:4169 sssd.conf.5.xml:4170 sssd.conf.5.xml:4173 +msgid "enabled" +msgstr "habilitado" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:3967 sssd-ldap.5.xml:233 +#: sssd.conf.5.xml:4172 sssd-ldap.5.xml:233 msgid "AD" msgstr "AD" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry><para> -#: sssd.conf.5.xml:3967 sssd.conf.5.xml:3970 sssd.conf.5.xml:3971 +#: sssd.conf.5.xml:4172 sssd.conf.5.xml:4175 sssd.conf.5.xml:4176 msgid "disabled" msgstr "inhabilitado" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry> -#: sssd.conf.5.xml:3970 +#: sssd.conf.5.xml:4175 msgid "LDAP" msgstr "LDAP" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3975 +#: sssd.conf.5.xml:4180 msgid "" "Please note that if local Smartcard authentication is enabled and a " "Smartcard is present, Smartcard authentication will be preferred over the " @@ -5719,7 +6083,7 @@ msgstr "" "solicitud de PIN en lugar de p.ej. una petición de contraseña." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:3987 +#: sssd.conf.5.xml:4192 #, no-wrap msgid "" "[domain/shadowutils]\n" @@ -5735,7 +6099,7 @@ msgstr "" "local_auth_policy = only\n" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3983 +#: sssd.conf.5.xml:4188 msgid "" "The following configuration example allows local users to authenticate " "locally using any enabled method (i.e. smartcard, passkey). <placeholder " @@ -5747,22 +6111,22 @@ msgstr "" "id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3995 +#: sssd.conf.5.xml:4200 msgid "Default: match" msgstr "Predeterminado: coincide" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4000 +#: sssd.conf.5.xml:4205 msgid "auto_private_groups (string)" msgstr "auto_private_groups (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4006 +#: sssd.conf.5.xml:4211 msgid "true" msgstr "true" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4009 +#: sssd.conf.5.xml:4214 msgid "" "Create user's private group unconditionally from user's UID number. The GID " "number is ignored in this case." @@ -5771,7 +6135,7 @@ msgstr "" "usuario. El número GID se ignora en este caso." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4013 +#: sssd.conf.5.xml:4218 msgid "" "NOTE: Because the GID number and the user private group are inferred from " "the UID number, it is not supported to have multiple entries with the same " @@ -5784,12 +6148,12 @@ msgstr "" "unicidad den el espacio de ID." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4022 +#: sssd.conf.5.xml:4227 msgid "false" msgstr "false" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4025 +#: sssd.conf.5.xml:4230 msgid "" "Always use the user's primary GID number. The GID number must refer to a " "group object in the LDAP database." @@ -5798,12 +6162,12 @@ msgstr "" "referirse a un objeto grupo en la base de datos LDAP." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4031 +#: sssd.conf.5.xml:4236 msgid "hybrid" msgstr "hybrid" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4034 +#: sssd.conf.5.xml:4239 msgid "" "A primary group is autogenerated for user entries whose UID and GID numbers " "have the same value and at the same time the GID number does not correspond " @@ -5818,7 +6182,7 @@ msgstr "" "grupo, el GID primario del usuario se resuelve al de ese objeto grupo." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4047 +#: sssd.conf.5.xml:4252 msgid "" "If the UID and GID of a user are different, then the GID must correspond to " "a group entry, otherwise the GID is simply not resolvable." @@ -5827,7 +6191,7 @@ msgstr "" "una entrada de grupo, de otro modo el GID simplemente no se puede resolver." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4054 +#: sssd.conf.5.xml:4259 msgid "" "This feature is useful for environments that wish to stop maintaining a " "separate group objects for the user private groups, but also wish to retain " @@ -5838,7 +6202,7 @@ msgstr "" "también desea retener los grupos privados existentes del usuario." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4003 +#: sssd.conf.5.xml:4208 msgid "" "This option takes any of three available values: <placeholder " "type=\"variablelist\" id=\"0\"/>" @@ -5847,7 +6211,7 @@ msgstr "" "type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4066 +#: sssd.conf.5.xml:4271 msgid "" "For the LDAP based id providers (LDAP, IPA and AD) the default for the " "configured domain is typically False because the sources have the concept of " @@ -5862,7 +6226,7 @@ msgstr "" "grupos primarios.</phrase>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4075 +#: sssd.conf.5.xml:4280 msgid "" "For subdomains, the default value is False for subdomains that use assigned " "POSIX IDs and True for subdomains that use automatic ID-mapping." @@ -5872,7 +6236,7 @@ msgstr "" "automático." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:4083 +#: sssd.conf.5.xml:4288 #, no-wrap msgid "" "[domain/forest.domain/sub.domain]\n" @@ -5882,7 +6246,7 @@ msgstr "" "auto_private_groups = false\n" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:4089 +#: sssd.conf.5.xml:4294 #, no-wrap msgid "" "[domain/forest.domain]\n" @@ -5894,7 +6258,7 @@ msgstr "" "auto_private_groups = false\n" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4080 +#: sssd.conf.5.xml:4285 msgid "" "The value of auto_private_groups can either be set per subdomains in a " "subsection, for example: <placeholder type=\"programlisting\" id=\"0\"/> or " @@ -5908,7 +6272,7 @@ msgstr "" "type=\"programlisting\" id=\"1\"/>" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:2503 +#: sssd.conf.5.xml:2549 msgid "" "These configuration options can be present in a domain configuration " "section, that is, in a section called <quote>[domain/<replaceable>NAME</" @@ -5920,17 +6284,17 @@ msgstr "" "id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4104 +#: sssd.conf.5.xml:4309 msgid "proxy_pam_target (string)" msgstr "proxy_pam_target (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4107 +#: sssd.conf.5.xml:4312 msgid "The proxy target PAM proxies to." msgstr "El proxy de destino PAM próximo a." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4110 +#: sssd.conf.5.xml:4315 msgid "" "Default: not set by default, you have to take an existing pam configuration " "or create a new one and add the service name here. As an alternative you can " @@ -5942,12 +6306,12 @@ msgstr "" "local_auth_policy." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4120 +#: sssd.conf.5.xml:4325 msgid "proxy_lib_name (string)" msgstr "proxy_lib_name (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4123 +#: sssd.conf.5.xml:4328 msgid "" "The name of the NSS library to use in proxy domains. The NSS functions " "searched for in the library are in the form of _nss_$(libName)_$(function), " @@ -5958,12 +6322,12 @@ msgstr "" "(function), por ejemplo _nss_files_getpwent." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4133 +#: sssd.conf.5.xml:4338 msgid "proxy_resolver_lib_name (string)" msgstr "proxy_resolver_lib_name (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4136 +#: sssd.conf.5.xml:4341 msgid "" "The name of the NSS library to use for hosts and networks lookups in proxy " "domains. The NSS functions searched for in the library are in the form of " @@ -5975,12 +6339,12 @@ msgstr "" "_nss_dns_gethostbyname2_r." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4147 +#: sssd.conf.5.xml:4352 msgid "proxy_fast_alias (boolean)" msgstr "proxy_fast_alias (booleano)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4150 +#: sssd.conf.5.xml:4355 msgid "" "When a user or group is looked up by name in the proxy provider, a second " "lookup by ID is performed to \"canonicalize\" the name in case the requested " @@ -5994,12 +6358,12 @@ msgstr "" "razones de rendimiento." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4164 +#: sssd.conf.5.xml:4369 msgid "proxy_max_children (integer)" msgstr "proxy_max_children (entero)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4167 +#: sssd.conf.5.xml:4372 msgid "" "This option specifies the number of pre-forked proxy children. It is useful " "for high-load SSSD environments where sssd may run out of available child " @@ -6011,7 +6375,7 @@ msgstr "" "son encoladas." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4100 +#: sssd.conf.5.xml:4305 msgid "" "Options valid for proxy domains. <placeholder type=\"variablelist\" " "id=\"0\"/>" @@ -6020,12 +6384,12 @@ msgstr "" "id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:4183 +#: sssd.conf.5.xml:4388 msgid "Application domains" msgstr "Dominios de aplicaciones" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:4185 +#: sssd.conf.5.xml:4390 msgid "" "SSSD, with its D-Bus interface (see <citerefentry> <refentrytitle>sssd-ifp</" "refentrytitle> <manvolnum>5</manvolnum> </citerefentry>) is appealing to " @@ -6054,7 +6418,7 @@ msgstr "" "que opcionalmente herede ajustes de un dominio SSSD tradicional." #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:4205 +#: sssd.conf.5.xml:4410 msgid "" "Please note that the application domain must still be explicitly enabled in " "the <quote>domains</quote> parameter so that the lookup order between the " @@ -6066,17 +6430,17 @@ msgstr "" "establecido correctamente." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><title> -#: sssd.conf.5.xml:4211 +#: sssd.conf.5.xml:4416 msgid "Application domain parameters" msgstr "Parámetros de dominio de aplicación" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4213 +#: sssd.conf.5.xml:4418 msgid "inherit_from (string)" msgstr "inherit_from (cadena)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4216 +#: sssd.conf.5.xml:4421 msgid "" "The SSSD POSIX-type domain the application domain inherits all settings " "from. The application domain can moreover add its own settings to the " @@ -6089,7 +6453,7 @@ msgstr "" "<quote>hermano</quote>." #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:4230 +#: sssd.conf.5.xml:4435 msgid "" "The following example illustrates the use of an application domain. In this " "setup, the POSIX domain is connected to an LDAP server and is used by the OS " @@ -6104,7 +6468,7 @@ msgstr "" "cache y hace al atributo phone alcanzable a través del interfaz D-Bus." #. type: Content of: <reference><refentry><refsect1><refsect2><programlisting> -#: sssd.conf.5.xml:4238 +#: sssd.conf.5.xml:4443 #, no-wrap msgid "" "[sssd]\n" @@ -6138,12 +6502,12 @@ msgstr "" "ldap_user_extra_attrs = phone:telephoneNumber\n" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:4258 +#: sssd.conf.5.xml:4463 msgid "TRUSTED DOMAIN SECTION" msgstr "SECCIÓN DE DOMINIO DE CONFIANZA" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4260 +#: sssd.conf.5.xml:4465 msgid "" "Some options used in the domain section can also be used in the trusted " "domain section, that is, in a section called <quote>[domain/" @@ -6153,64 +6517,74 @@ msgid "" "options in the trusted domain section are:" msgstr "" "Algunas opciones usadas en la sección dominio puede ser usadas también en la " -"sección dominio de confianza, esto es, en una sección llamada<quote>[domain/" +"sección dominio de confianza, esto es, en una sección llamada <quote>[domain/" "<replaceable>DOMAIN_NAME</replaceable>/<replaceable>TRUSTED_DOMAIN_NAME</" "replaceable>]</quote>. Donde DOMAIN_NAME es el dominio base real. Por favor " "vea los ejemplos de abajo para una explicación. Actualmente las opciones " "soportadas en la sección de dominio de confianza son:" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4267 +#: sssd.conf.5.xml:4472 msgid "ldap_search_base," msgstr "ldap_search_base," #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4268 +#: sssd.conf.5.xml:4473 msgid "ldap_user_search_base," msgstr "ldap_user_search_base," #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4269 +#: sssd.conf.5.xml:4474 msgid "ldap_group_search_base," msgstr "ldap_group_search_base," #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4270 +#: sssd.conf.5.xml:4475 msgid "ldap_netgroup_search_base," msgstr "ldap_netgroup_search_base," #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4271 +#: sssd.conf.5.xml:4476 msgid "ldap_service_search_base," msgstr "ldap_service_search_base," #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4272 +#: sssd.conf.5.xml:4477 msgid "ldap_sasl_mech," msgstr "ldap_sasl_mech," #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4273 +#: sssd.conf.5.xml:4478 msgid "ad_server," msgstr "ad_server," #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4274 +#: sssd.conf.5.xml:4479 msgid "ad_backup_server," msgstr "ad_backup_server," #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4275 +#: sssd.conf.5.xml:4480 msgid "ad_site," msgstr "ad_site," #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:4276 sssd-ipa.5.xml:934 +#: sssd.conf.5.xml:4481 sssd-ipa.5.xml:929 msgid "use_fully_qualified_names" msgstr "use_fully_qualified_names" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4280 +#: sssd.conf.5.xml:4482 +msgid "pam_gssapi_services" +msgstr "pam_gssapi_services" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:4483 +msgid "pam_gssapi_check_upn" +msgstr "pam_gssapi_check_upn" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:4485 msgid "" "For more details about these options see their individual description in the " "manual page." @@ -6219,12 +6593,12 @@ msgstr "" "página de manual." #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:4286 +#: sssd.conf.5.xml:4491 msgid "CERTIFICATE MAPPING SECTION" msgstr "SECCIÓN DE MAPEO DEL CERTIFICADO" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4288 +#: sssd.conf.5.xml:4493 msgid "" "To allow authentication with Smartcards and certificates SSSD must be able " "to map certificates to users. This can be done by adding the full " @@ -6246,7 +6620,7 @@ msgstr "" "usan autenticación PAM." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4302 +#: sssd.conf.5.xml:4507 msgid "" "To make the mapping more flexible mapping and matching rules were added to " "SSSD (see <citerefentry> <refentrytitle>sss-certmap</refentrytitle> " @@ -6258,7 +6632,7 @@ msgstr "" "citerefentry>)." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4311 +#: sssd.conf.5.xml:4516 msgid "" "A mapping and matching rule can be added to the SSSD configuration in a " "section on its own with a name like <quote>[certmap/" @@ -6271,12 +6645,12 @@ msgstr "" "esta sección están permitidas las siguientes opciones:" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4318 +#: sssd.conf.5.xml:4523 msgid "matchrule (string)" msgstr "matchrule (cadena)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4321 +#: sssd.conf.5.xml:4526 msgid "" "Only certificates from the Smartcard which matches this rule will be " "processed, all others are ignored." @@ -6285,7 +6659,7 @@ msgstr "" "procesados, los demás son ignorados." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4325 +#: sssd.conf.5.xml:4530 msgid "" "Default: KRB5:<EKU>clientAuth, i.e. only certificates which have the " "Extended Key Usage <quote>clientAuth</quote>" @@ -6294,17 +6668,17 @@ msgstr "" "tengan Extended Key Usage <quote>clientAuth</quote>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4332 +#: sssd.conf.5.xml:4537 msgid "maprule (string)" msgstr "maprule (cadena)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4335 +#: sssd.conf.5.xml:4540 msgid "Defines how the user is found for a given certificate." msgstr "Define como se encuentra un usuario desde un certificado dado." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:4341 +#: sssd.conf.5.xml:4546 msgid "" "LDAP:(userCertificate;binary={cert!bin}) for LDAP based providers like " "<quote>ldap</quote>, <quote>AD</quote> or <quote>ipa</quote>." @@ -6313,7 +6687,7 @@ msgstr "" "como <quote>ldap</quote>, <quote>AD</quote> o <quote>ipa</quote>." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:4347 +#: sssd.conf.5.xml:4552 msgid "" "If maprule is not set and provider is <quote>proxy</quote>, the RULE_NAME " "name is assumed to be the name of the matching user." @@ -6321,13 +6695,8 @@ msgstr "" "Si maprule no está establecido y el proveedor es <quote>proxy</quote>, el " "nombre RULE_NAME se asume como ser el nombre del usuario coincidente." -#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4357 -msgid "domains (string)" -msgstr "domains (cadena)" - #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4360 +#: sssd.conf.5.xml:4565 msgid "" "Comma separated list of domain names the rule should be applied. By default " "a rule is only valid in the domain configured in sssd.conf. If the provider " @@ -6340,17 +6709,17 @@ msgstr "" "usada para añadir la regla a los subdominios también." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4367 +#: sssd.conf.5.xml:4572 msgid "Default: the configured domain in sssd.conf" msgstr "Predetermiado: el dominio configurado en sssd.conf" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4372 +#: sssd.conf.5.xml:4577 msgid "priority (integer)" msgstr "priority (entero)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4375 +#: sssd.conf.5.xml:4580 msgid "" "Unsigned integer value defining the priority of the rule. The higher the " "number the lower the priority. <quote>0</quote> stands for the highest " @@ -6361,17 +6730,17 @@ msgstr "" "más alte mientras que <quote>4294967295</quote> es la más baja." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4381 +#: sssd.conf.5.xml:4586 msgid "Default: the lowest priority" msgstr "Predeterminado: la prioridad más baja" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:4389 +#: sssd.conf.5.xml:4594 msgid "PROMPTING CONFIGURATION SECTION" msgstr "SECCIÓN DE CONFIGURACIÓN INICIAL" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4391 +#: sssd.conf.5.xml:4596 msgid "" "If a special file (<filename>/var/lib/sss/pubconf/pam_preauth_available</" "filename>) exists SSSD's PAM module pam_sss will ask SSSD to figure out " @@ -6386,7 +6755,7 @@ msgstr "" "al usuario las credenciales apropiadas." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4399 +#: sssd.conf.5.xml:4604 msgid "" "With the growing number of authentication methods and the possibility that " "there are multiple ones for a single user the heuristic used by pam_sss to " @@ -6399,22 +6768,22 @@ msgstr "" "Las siguientes opciones deberían suministrar una mejor flexibilidad aquí." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4411 +#: sssd.conf.5.xml:4616 msgid "[prompting/password]" msgstr "[prompting/password]" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4414 +#: sssd.conf.5.xml:4619 msgid "password_prompt" msgstr "password_prompt" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4415 +#: sssd.conf.5.xml:4620 msgid "to change the string of the password prompt" msgstr "para cambiar la cadena de solicitud de contraseña" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4413 +#: sssd.conf.5.xml:4618 msgid "" "to configure password prompting, allowed options are: <placeholder " "type=\"variablelist\" id=\"0\"/>" @@ -6423,37 +6792,37 @@ msgstr "" "<placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4423 +#: sssd.conf.5.xml:4628 msgid "[prompting/2fa]" msgstr "[prompting/2fa]" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4427 +#: sssd.conf.5.xml:4632 msgid "first_prompt" msgstr "first_prompt" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4428 +#: sssd.conf.5.xml:4633 msgid "to change the string of the prompt for the first factor" msgstr "para cambiar la cadena de la solicitud del primer factor" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4431 +#: sssd.conf.5.xml:4636 msgid "second_prompt" msgstr "second_prompt" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4432 +#: sssd.conf.5.xml:4637 msgid "to change the string of the prompt for the second factor" msgstr "para cambiar la cadena de la solicitud para el segundo factor" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4435 +#: sssd.conf.5.xml:4640 msgid "single_prompt" msgstr "single_prompt" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4436 +#: sssd.conf.5.xml:4641 msgid "" "boolean value, if True there will be only a single prompt using the value of " "first_prompt where it is expected that both factors are entered as a single " @@ -6466,7 +6835,7 @@ msgstr "" "incluso si el segundo factor es opcional." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4425 +#: sssd.conf.5.xml:4630 msgid "" "to configure two-factor authentication prompting, allowed options are: " "<placeholder type=\"variablelist\" id=\"0\"/> If the second factor is " @@ -6479,7 +6848,7 @@ msgstr "" "con ambos factores de dos-pasos solicitados tiene que ser utilizado." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4449 +#: sssd.conf.5.xml:4654 msgid "" "Some clients, such as SSH with 'PasswordAuthentication yes', generate their " "own prompts and do not use prompts provided by SSSD or other PAM modules. " @@ -6496,17 +6865,17 @@ msgstr "" "serie sola, incluso si autenticación de dos factores es opcional." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4464 +#: sssd.conf.5.xml:4669 msgid "[prompting/passkey]" msgstr "[prompting/passkey]" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:4470 sssd-ad.5.xml:1022 +#: sssd.conf.5.xml:4675 sssd.conf.5.xml:4719 sssd-ad.5.xml:1027 msgid "interactive" msgstr "interactivo" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4472 +#: sssd.conf.5.xml:4677 msgid "" "boolean value, if True prompt a message and wait before testing the presence " "of a passkey device. Recommended if your device doesn’t have a tactile " @@ -6517,22 +6886,22 @@ msgstr "" "un disparador táctil." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4480 +#: sssd.conf.5.xml:4685 sssd.conf.5.xml:4735 msgid "interactive_prompt" msgstr "interactive_prompt" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4482 +#: sssd.conf.5.xml:4687 sssd.conf.5.xml:4737 msgid "to change the message of the interactive prompt." msgstr "para cambiar el mensaje de la solicitud interactiva." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4487 +#: sssd.conf.5.xml:4692 msgid "touch" msgstr "tocar" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4489 +#: sssd.conf.5.xml:4694 msgid "" "boolean value, if True prompt a message to remind the user to touch the " "device." @@ -6541,17 +6910,17 @@ msgstr "" "tocar el dispositivo." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4495 +#: sssd.conf.5.xml:4700 msgid "touch_prompt" msgstr "touch_prompt" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4497 +#: sssd.conf.5.xml:4702 msgid "to change the message of the touch prompt." msgstr "para cambiar el mensaje de la solicitud del toque." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4466 +#: sssd.conf.5.xml:4671 msgid "" "to configure passkey authentication prompting, allowed options are: " "<placeholder type=\"variablelist\" id=\"0\"/>" @@ -6559,13 +6928,123 @@ msgstr "" "para configurar la consulta de autenticación toque de paso, las opciones " "permitidas son: <placeholder type=\"variablelist\" id=\"0\"/>" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4713 +#, fuzzy +#| msgid "[prompting/2fa]" +msgid "[prompting/oauth2]" +msgstr "[prompting/2fa]" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4721 +#, fuzzy +#| msgid "" +#| "boolean value, if True prompt a message to remind the user to touch the " +#| "device." +msgid "" +"boolean value, if True prompt a message after asking the user to " +"authenticate, and wait before requesting the access token." +msgstr "" +"valor booleano, si la solicitud True de un mensaje para recordar al usuario " +"tocar el dispositivo." + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4725 +msgid "" +"If False, make sure to set the <quote>idp_request_timeout</quote> " +"sufficiently high, to give the user time to authenticate." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4715 +#, fuzzy +#| msgid "" +#| "to configure passkey authentication prompting, allowed options are: " +#| "<placeholder type=\"variablelist\" id=\"0\"/>" +msgid "" +"to configure OAuth2 authentication prompting, allowed options are: " +"<placeholder type=\"variablelist\" id=\"0\"/>" +msgstr "" +"para configurar la consulta de autenticación toque de paso, las opciones " +"permitidas son: <placeholder type=\"variablelist\" id=\"0\"/>" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4748 +#, fuzzy +#| msgid "[prompting/2fa]" +msgid "[prompting/cert_auth]" +msgstr "[prompting/2fa]" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4754 +#, fuzzy +#| msgid "single_prompt" +msgid "pin_prompt" +msgstr "single_prompt" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4756 +msgid "" +"to change the message which asks the user to enter the PIN at the computer " +"keyboard. At the end of the message the token name is printed." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4764 +#, fuzzy +#| msgid "password_prompt" +msgid "keypad_prompt" +msgstr "password_prompt" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4766 +msgid "" +"to change the message which asks the user to enter the PIN at keypad of the " +"Smartcard reader. At the end of the message the token name is printed." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4774 +#, fuzzy +#| msgid "username" +msgid "user_name_hint" +msgstr "nombre de usuario" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4776 +msgid "" +"boolean value, if True ask for a user name if no name was given before and " +"the found certificate can be mapped to more than one user." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4750 +#, fuzzy +#| msgid "" +#| "to configure passkey authentication prompting, allowed options are: " +#| "<placeholder type=\"variablelist\" id=\"0\"/>" +msgid "" +"to configure Smartcard authentication prompting, allowed options are: " +"<placeholder type=\"variablelist\" id=\"0\"/>" +msgstr "" +"para configurar la consulta de autenticación toque de paso, las opciones " +"permitidas son: <placeholder type=\"variablelist\" id=\"0\"/>" + #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4406 +#: sssd.conf.5.xml:4611 +#, fuzzy +#| msgid "" +#| "Each supported authentication method has its own configuration subsection " +#| "under <quote>[prompting/...]</quote>. Currently there are: <placeholder " +#| "type=\"variablelist\" id=\"0\"/> <placeholder type=\"variablelist\" " +#| "id=\"1\"/> <placeholder type=\"variablelist\" id=\"2\"/>" msgid "" "Each supported authentication method has its own configuration subsection " "under <quote>[prompting/...]</quote>. Currently there are: <placeholder " "type=\"variablelist\" id=\"0\"/> <placeholder type=\"variablelist\" id=\"1\"/" -"> <placeholder type=\"variablelist\" id=\"2\"/>" +"> <placeholder type=\"variablelist\" id=\"2\"/> <placeholder " +"type=\"variablelist\" id=\"3\"/> <placeholder type=\"variablelist\" id=\"4\"/" +">" msgstr "" "Cada método de autenticación admitido tiene su propia subsección de " "configuración bajo <quote>[prompting/...]</quote>. Actualmente hay: " @@ -6573,7 +7052,7 @@ msgstr "" "type=\"variablelist\" id=\"1\"/><placeholder type=\"variablelist\" id=\"2\"/>" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4508 +#: sssd.conf.5.xml:4792 msgid "" "It is possible to add a subsection for specific PAM services, e.g. " "<quote>[prompting/password/sshd]</quote> to individual change the prompting " @@ -6584,12 +7063,12 @@ msgstr "" "pregunta para este servicio." #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:4515 pam_sss_gss.8.xml:157 idmap_sss.8.xml:43 +#: sssd.conf.5.xml:4799 pam_sss_gss.8.xml:157 idmap_sss.8.xml:43 msgid "EXAMPLES" msgstr "EJEMPLOS" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd.conf.5.xml:4521 +#: sssd.conf.5.xml:4805 #, no-wrap msgid "" "[sssd]\n" @@ -6641,7 +7120,7 @@ msgstr "" "enumerate = False\n" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4517 +#: sssd.conf.5.xml:4801 msgid "" "1. The following example shows a typical SSSD config. It does not describe " "configuration of the domains themselves - refer to documentation on " @@ -6654,7 +7133,7 @@ msgstr "" "type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd.conf.5.xml:4553 +#: sssd.conf.5.xml:4837 #, no-wrap msgid "" "[domain/ipa.com/child.ad.com]\n" @@ -6664,7 +7143,7 @@ msgstr "" "use_fully_qualified_names = false\n" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4547 +#: sssd.conf.5.xml:4831 msgid "" "2. The following example shows configuration of IPA AD trust where the AD " "forest consists of two domains in a parent-child structure. Suppose IPA " @@ -6681,7 +7160,7 @@ msgstr "" "type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd.conf.5.xml:4564 +#: sssd.conf.5.xml:4848 #, no-wrap msgid "" "[certmap/my.domain/rule_name]\n" @@ -6697,7 +7176,7 @@ msgstr "" "priority = 10\n" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4558 +#: sssd.conf.5.xml:4842 msgid "" "3. The following example shows the configuration of a certificate mapping " "rule. It is valid for the configured domain <quote>my.domain</quote> and " @@ -6934,13 +7413,21 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:151 +#, fuzzy +#| msgid "" +#| "Default: If not set, the value of the defaultNamingContext or " +#| "namingContexts attribute from the RootDSE of the LDAP server is used. If " +#| "defaultNamingContext does not exist or has an empty value namingContexts " +#| "is used. The namingContexts attribute must have a single value with the " +#| "DN of the search base of the LDAP server to make this work. Multiple " +#| "values are are not supported." msgid "" "Default: If not set, the value of the defaultNamingContext or namingContexts " "attribute from the RootDSE of the LDAP server is used. If " "defaultNamingContext does not exist or has an empty value namingContexts is " "used. The namingContexts attribute must have a single value with the DN of " "the search base of the LDAP server to make this work. Multiple values are " -"are not supported." +"not supported." msgstr "" "Por defecto: no se fija, se usa el valor de los atributos " "defaultNamingContext o namingContexts de RootDSE del servidor LDAP usado. Si " @@ -7309,8 +7796,8 @@ msgid "Optional. Use the given string as search base for host objects." msgstr "Opcional. Usa la cadena dada como base de búsqueda para objetos host." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap.5.xml:472 sssd-ipa.5.xml:506 sssd-ipa.5.xml:525 sssd-ipa.5.xml:544 -#: sssd-ipa.5.xml:563 +#: sssd-ldap.5.xml:472 sssd-ipa.5.xml:501 sssd-ipa.5.xml:520 sssd-ipa.5.xml:539 +#: sssd-ipa.5.xml:558 msgid "" "See <quote>ldap_search_base</quote> for information about configuring " "multiple search bases." @@ -7319,7 +7806,7 @@ msgstr "" "de múltiples bases de búsqueda." #. type: Content of: <listitem><para> -#: sssd-ldap.5.xml:477 sssd-ipa.5.xml:511 include/ldap_search_bases.xml:27 +#: sssd-ldap.5.xml:477 sssd-ipa.5.xml:506 include/ldap_search_bases.xml:27 msgid "Default: the value of <emphasis>ldap_search_base</emphasis>" msgstr "Predeterminado: el valor de <emphasis>ldap_search_base</emphasis>" @@ -7466,13 +7953,21 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:621 +#, fuzzy +#| msgid "" +#| "If the connection is idle (not actively running an operation) within " +#| "<emphasis>ldap_opt_timeout</emphasis> seconds of expiration, then it will " +#| "be closed early to ensure that a new query cannot require the connection " +#| "to remain open past its expiration. This implies that connections will " +#| "always be closed immediately and will never be reused if " +#| "<emphasis>ldap_connection_expire_timeout <= ldap_opt_timout</emphasis>" msgid "" "If the connection is idle (not actively running an operation) within " "<emphasis>ldap_opt_timeout</emphasis> seconds of expiration, then it will be " "closed early to ensure that a new query cannot require the connection to " "remain open past its expiration. This implies that connections will always " "be closed immediately and will never be reused if " -"<emphasis>ldap_connection_expire_timeout <= ldap_opt_timout</emphasis>" +"<emphasis>ldap_connection_expire_timeout <= ldap_opt_timeout</emphasis>" msgstr "" "Si la conexión está inactiva (sin ejecutar ninguna operación) dentro de " "<emphasis>ldap_opt_timeout</emphasis> segundos tras su caducidad, se cerrará " @@ -7708,7 +8203,9 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:831 -msgid "ldap_ignore_unreadable_references (bool)" +#, fuzzy +#| msgid "ldap_ignore_unreadable_references (bool)" +msgid "ldap_ignore_unreadable_references (boolean)" msgstr "ldap_ignore_unreadable_references (bool)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> @@ -8117,7 +8614,7 @@ msgstr "" "SPNEGO." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap.5.xml:1152 sssd-ad.5.xml:1267 +#: sssd-ldap.5.xml:1152 sssd-ad.5.xml:1260 msgid "Default: 86400 (24 hours)" msgstr "Predeterminado: 86400 (24 horas)" @@ -8169,7 +8666,7 @@ msgstr "" "configuración para usar <quote>krb5_server</quote> en su lugar." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ldap.5.xml:1187 sssd-ipa.5.xml:575 sssd-krb5.5.xml:103 +#: sssd-ldap.5.xml:1187 sssd-ipa.5.xml:570 sssd-krb5.5.xml:103 msgid "krb5_realm (string)" msgstr "krb5_realm (cadena)" @@ -8370,7 +8867,9 @@ msgstr "Por defecto: no fijado, esto es servicio descubridor inhabilitado" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1339 -msgid "ldap_chpass_update_last_change (bool)" +#, fuzzy +#| msgid "ldap_chpass_update_last_change (bool)" +msgid "ldap_chpass_update_last_change (boolean)" msgstr "ldap_chpass_update_last_change (booleano)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> @@ -8565,7 +9064,7 @@ msgid "ldap_access_order (string)" msgstr "ldap_access_order (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap.5.xml:1470 sssd-ipa.5.xml:405 +#: sssd-ldap.5.xml:1470 sssd-ipa.5.xml:400 msgid "Comma separated list of access control options. Allowed values are:" msgstr "" "Lista separada por coma de opciones de control de acceso. Los valores " @@ -8630,7 +9129,7 @@ msgid "<emphasis>expire</emphasis>: use ldap_account_expire_policy" msgstr "<emphasis>caducar</emphasis>: utilizar ldap_account_expire_policy" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap.5.xml:1515 sssd-ipa.5.xml:413 +#: sssd-ldap.5.xml:1515 sssd-ipa.5.xml:408 msgid "" "<emphasis>pwd_expire_policy_reject, pwd_expire_policy_warn, " "pwd_expire_policy_renew: </emphasis> These options are useful if users are " @@ -8639,13 +9138,13 @@ msgid "" "example SSH keys." msgstr "" "<emphasis>pwd_expire_policy_reject, pwd_expire_policy_warn, " -"pwd_expire_policy_renew: </emphasis>Estas opciones son útiles si los " +"pwd_expire_policy_renew: </emphasis> Estas opciones son útiles si los " "usuarios están interesados en que se les avise de que la contraseña está " "próxima a expirar y la autenticación está basada en la utilización de un " "método distinto a las contraseñas; por ejemplo claves SSH." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap.5.xml:1525 sssd-ipa.5.xml:423 +#: sssd-ldap.5.xml:1525 sssd-ipa.5.xml:418 msgid "" "The difference between these options is the action taken if user password is " "expired:" @@ -8654,17 +9153,17 @@ msgstr "" "usuario está caducada:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ldap.5.xml:1530 sssd-ipa.5.xml:428 +#: sssd-ldap.5.xml:1530 sssd-ipa.5.xml:423 msgid "pwd_expire_policy_reject - user is denied to log in," msgstr "pwd_expire_policy_reject: el usuario está denegado para acceder," #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ldap.5.xml:1536 sssd-ipa.5.xml:434 +#: sssd-ldap.5.xml:1536 sssd-ipa.5.xml:429 msgid "pwd_expire_policy_warn - user is still able to log in," msgstr "pwd_expire_policy_warn: usuario aún es capaz de acceder," #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ldap.5.xml:1542 sssd-ipa.5.xml:440 +#: sssd-ldap.5.xml:1542 sssd-ipa.5.xml:435 msgid "" "pwd_expire_policy_renew - user is prompted to change their password " "immediately." @@ -9332,8 +9831,8 @@ msgstr "" "<placeholder type=\"variablelist\" id=\"1\"/>" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd-ldap.5.xml:2032 sssd-simple.5.xml:169 sssd-ipa.5.xml:984 -#: sssd-ad.5.xml:1470 sssd-idp.5.xml:248 sssd-krb5.5.xml:483 +#: sssd-ldap.5.xml:2032 sssd-simple.5.xml:169 sssd-ipa.5.xml:979 +#: sssd-ad.5.xml:1463 sssd-idp.5.xml:343 sssd-krb5.5.xml:483 #: sss_rpcidmapd.5.xml:98 sssd-session-recording.5.xml:176 msgid "EXAMPLE" msgstr "EJEMPLO" @@ -9371,7 +9870,7 @@ msgstr "" #. type: Content of: <refsect1><refsect2><para> #: sssd-ldap.5.xml:2039 sssd-ldap.5.xml:2057 sssd-simple.5.xml:177 -#: sssd-ipa.5.xml:992 sssd-ad.5.xml:1478 sssd-sudo.5.xml:56 sssd-krb5.5.xml:492 +#: sssd-ipa.5.xml:987 sssd-ad.5.xml:1471 sssd-sudo.5.xml:56 sssd-krb5.5.xml:492 #: sssd-session-recording.5.xml:182 include/ldap_id_mapping.xml:105 msgid "<placeholder type=\"programlisting\" id=\"0\"/>" msgstr "<placeholder type=\"programlisting\" id=\"0\"/>" @@ -9418,7 +9917,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><title> #: sssd-ldap.5.xml:2073 sssd_krb5_locator_plugin.8.xml:83 sssd-simple.5.xml:189 -#: sssd-ad.5.xml:1493 sssd.8.xml:270 sss_seed.8.xml:163 +#: sssd-ad.5.xml:1486 sssd.8.xml:270 sss_seed.8.xml:163 msgid "NOTES" msgstr "NOTAS" @@ -10037,9 +10536,14 @@ msgstr "PAM_NO_MODULE_DATA" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:434 +#, fuzzy +#| msgid "" +#| "No authentication method was found by Kerberos. This might happen if the " +#| "user has a Smartcard assigned but the pkint plugin is not available on " +#| "the client." msgid "" "No authentication method was found by Kerberos. This might happen if the " -"user has a Smartcard assigned but the pkint plugin is not available on the " +"user has a Smartcard assigned but the pkinit plugin is not available on the " "client." msgstr "" "No fue encontrado ningún método de autenticación por Kerberos. Esto " @@ -10613,6 +11117,23 @@ msgstr "" "KRB5_PLUGIN_NO_HANDLE al llamante inmediatamente en el primer fallo " "resolviendo DNS." +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_locator_plugin.8.xml:106 +msgid "" +"If the environment variable SSSD_KRB5_LOCATOR_KDC_ADDRESS is set to a KDC " +"address the plugin will use this address instead of reading the kdcinfo " +"file. The address format is the same as in the kdcinfo file (see above)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_locator_plugin.8.xml:112 +msgid "" +"If the environment variable SSSD_KRB5_LOCATOR_KPASSWD_ADDRESS is set to a " +"kpasswd server address the plugin will use this address instead of reading " +"the kpasswdinfo file. The address format is the same as in the kpasswdinfo " +"file (see above)." +msgstr "" + #. type: Content of: <reference><refentry><refnamediv><refname> #: sssd-simple.5.xml:10 sssd-simple.5.xml:16 msgid "sssd-simple" @@ -12342,7 +12863,7 @@ msgstr "" "este host. El nombre de host debe ser totalmente cualificado." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:129 sssd-ad.5.xml:1161 +#: sssd-ipa.5.xml:129 sssd-ad.5.xml:1166 msgid "dyndns_update (boolean)" msgstr "dyndns_update (booleano)" @@ -12361,23 +12882,13 @@ msgstr "" "conexión IPA LDAP se usa para las actualizaciones, si no se especifica de " "otra manera utilizando la opción <quote>dyndns_iface</quote>." -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:141 sssd-ad.5.xml:1175 -msgid "" -"NOTE: On older systems (such as RHEL 5), for this behavior to work reliably, " -"the default Kerberos realm must be set properly in /etc/krb5.conf" -msgstr "" -"NOTA: en sistemas más antiguos (como RHEL 5), para que este comportamiento " -"trabaje fiablemente, el reino por defecto Kerberos debe ser fijado " -"apropiadamente en /etc/krb5.conf" - #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:152 sssd-ad.5.xml:1186 +#: sssd-ipa.5.xml:147 sssd-ad.5.xml:1186 msgid "dyndns_ttl (integer)" msgstr "dyndns_ttl (entero)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:155 sssd-ad.5.xml:1189 +#: sssd-ipa.5.xml:150 sssd-ad.5.xml:1189 msgid "" "The TTL to apply to the client DNS record when updating it. If " "dyndns_update is false this has no effect. This will override the TTL " @@ -12388,17 +12899,17 @@ msgstr "" "servidor si se establece por un administrador." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:160 +#: sssd-ipa.5.xml:155 msgid "Default: 1200 (seconds)" msgstr "Por defecto: 1.200 (segundos)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:166 sssd-ad.5.xml:1200 +#: sssd-ipa.5.xml:161 sssd-ad.5.xml:1200 msgid "dyndns_iface (string)" msgstr "dyndns_iface (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:169 sssd-ad.5.xml:1203 +#: sssd-ipa.5.xml:164 sssd-ad.5.xml:1203 msgid "" "Optional. Applicable only when dyndns_update is true. Choose the interface " "or a list of interfaces whose IP addresses should be used for dynamic DNS " @@ -12418,7 +12929,7 @@ msgstr "" "glob</emphasis> para detalles sobre patrones." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:182 +#: sssd-ipa.5.xml:177 msgid "" "Default: Use the IP addresses of the interface which is used for IPA LDAP " "connection" @@ -12427,17 +12938,17 @@ msgstr "" "la conexión IPA LDAP" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:186 sssd-ad.5.xml:1226 +#: sssd-ipa.5.xml:181 sssd-ad.5.xml:1220 msgid "Example: dyndns_iface = em[12], !vnet1, vnet*" msgstr "Ejemplo: dyndns_iface = em[12], !vnet1, vnet*" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:192 sssd-ad.5.xml:1232 +#: sssd-ipa.5.xml:187 sssd-ad.5.xml:1226 msgid "dyndns_address (string)" msgstr "dyndns_address (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:195 sssd-ad.5.xml:1235 +#: sssd-ipa.5.xml:190 sssd-ad.5.xml:1229 msgid "" "Optional. Applicable only when <emphasis>dyndns_update</emphasis> is true. " "A list of IP addresses or IP networks to be used for dynamic DNS updates. " @@ -12455,22 +12966,22 @@ msgstr "" "más largo toma preferencia)." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:206 sssd-ad.5.xml:1246 +#: sssd-ipa.5.xml:201 sssd-ad.5.xml:1240 msgid "Default: No filtering of IP addresses." msgstr "Por defecto: ningún filtrado de direcciones IP." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:209 sssd-ad.5.xml:1249 +#: sssd-ipa.5.xml:204 sssd-ad.5.xml:1243 msgid "Example: dyndns_address = 10.0.0.0/16, !10.0.1.0/24" msgstr "Ejemplo: dyndns_address = 10.0.0.0/16, !10.0.1.0/24" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:215 sssd-ad.5.xml:1305 +#: sssd-ipa.5.xml:210 sssd-ad.5.xml:1298 msgid "dyndns_auth (string)" msgstr "dyndns_auth (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:218 sssd-ad.5.xml:1308 +#: sssd-ipa.5.xml:213 sssd-ad.5.xml:1301 msgid "" "Whether the nsupdate utility should use GSS-TSIG authentication for secure " "updates with the DNS server, insecure updates can be sent by setting this " @@ -12481,17 +12992,17 @@ msgstr "" "se pueden enviar fijando esta opción a 'none'." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:224 sssd-ad.5.xml:1314 +#: sssd-ipa.5.xml:219 sssd-ad.5.xml:1307 msgid "Default: GSS-TSIG" msgstr "Predeterminado: GSS-TSIG" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:230 sssd-ad.5.xml:1320 +#: sssd-ipa.5.xml:225 sssd-ad.5.xml:1313 msgid "dyndns_auth_ptr (string)" msgstr "dyndns_auth_ptr (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:233 sssd-ad.5.xml:1323 +#: sssd-ipa.5.xml:228 sssd-ad.5.xml:1316 msgid "" "Whether the nsupdate utility should use GSS-TSIG authentication for secure " "PTR updates with the DNS server, insecure updates can be sent by setting " @@ -12502,17 +13013,17 @@ msgstr "" "inseguras se pueden enviar fijando esta opción a 'none'." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:239 sssd-ad.5.xml:1329 +#: sssd-ipa.5.xml:234 sssd-ad.5.xml:1322 msgid "Default: Same as dyndns_auth" msgstr "Por defecto: lo mismo que dyndns_auth" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:245 sssd-ad.5.xml:1255 +#: sssd-ipa.5.xml:240 sssd-ad.5.xml:1249 msgid "dyndns_refresh_interval (integer)" msgstr "dyndns_refresh_interval (entero)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:248 +#: sssd-ipa.5.xml:243 msgid "" "How often should the back end perform periodic DNS update in addition to the " "automatic update performed when the back end goes online. This option is " @@ -12524,12 +13035,14 @@ msgstr "" "dyndns_update está a true." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:261 sssd-ad.5.xml:1273 -msgid "dyndns_update_ptr (bool)" +#: sssd-ipa.5.xml:256 sssd-ad.5.xml:1266 +#, fuzzy +#| msgid "dyndns_update_ptr (bool)" +msgid "dyndns_update_ptr (boolean)" msgstr "dyndns_update_ptr (booleano)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:264 sssd-ad.5.xml:1276 +#: sssd-ipa.5.xml:259 sssd-ad.5.xml:1269 msgid "" "Whether the PTR record should also be explicitly updated when updating the " "client's DNS records. Applicable only when dyndns_update is true." @@ -12539,7 +13052,7 @@ msgstr "" "dyndns_update está a true." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:269 +#: sssd-ipa.5.xml:264 msgid "" "This option should be False in most IPA deployments as the IPA server " "generates the PTR records automatically when forward records are changed." @@ -12549,7 +13062,7 @@ msgstr "" "se cambian los registros que envía." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:275 sssd-ad.5.xml:1281 +#: sssd-ipa.5.xml:270 sssd-ad.5.xml:1274 msgid "" "Note that <emphasis>dyndns_update_per_family</emphasis> parameter does not " "apply for PTR record updates. Those updates are always sent separately." @@ -12559,17 +13072,19 @@ msgstr "" "actualizaciones siempre se envían por separado." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:280 +#: sssd-ipa.5.xml:275 msgid "Default: False (disabled)" msgstr "Predeterminado: False (deshabilitado)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:286 sssd-ad.5.xml:1292 -msgid "dyndns_force_tcp (bool)" +#: sssd-ipa.5.xml:281 sssd-ad.5.xml:1285 +#, fuzzy +#| msgid "dyndns_force_tcp (bool)" +msgid "dyndns_force_tcp (boolean)" msgstr "dyndns_force_tcp (booleano)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:289 sssd-ad.5.xml:1295 +#: sssd-ipa.5.xml:284 sssd-ad.5.xml:1288 msgid "" "Whether the nsupdate utility should default to using TCP for communicating " "with the DNS server." @@ -12578,17 +13093,17 @@ msgstr "" "comunica con el servidor DNS." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:293 sssd-ad.5.xml:1299 +#: sssd-ipa.5.xml:288 sssd-ad.5.xml:1292 msgid "Default: False (let nsupdate choose the protocol)" msgstr "Predeterminado: False (permitir a nsupdate elegir el protocolol)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:299 sssd-ad.5.xml:1335 +#: sssd-ipa.5.xml:294 sssd-ad.5.xml:1328 msgid "dyndns_server (string)" msgstr "dyndns_server (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:302 sssd-ad.5.xml:1338 +#: sssd-ipa.5.xml:297 sssd-ad.5.xml:1331 msgid "" "The DNS server to use when performing a DNS update. In most setups, it's " "recommended to leave this option unset." @@ -12598,7 +13113,7 @@ msgstr "" "establecer." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:307 sssd-ad.5.xml:1343 +#: sssd-ipa.5.xml:302 sssd-ad.5.xml:1336 msgid "" "Setting this option makes sense for environments where the DNS server is " "different from the identity server or when we use encrypted DNS." @@ -12608,7 +13123,7 @@ msgstr "" "cifrado." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:312 sssd-ad.5.xml:1348 +#: sssd-ipa.5.xml:307 sssd-ad.5.xml:1341 msgid "" "The parameter can be a simple string containing DNS name or IP address. It " "can also be an URI. The URI can look like <emphasis>dns://servername/</" @@ -12620,7 +13135,7 @@ msgstr "" "1.2.3.4:853#servername/</emphasis>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:319 sssd-ad.5.xml:1355 +#: sssd-ipa.5.xml:314 sssd-ad.5.xml:1348 msgid "" "The second example enables DNS-over-TLS protocol for DNS updates. The " "nsupdate utility must support DoT - check the <emphasis>man nsupdate</" @@ -12631,7 +13146,7 @@ msgstr "" "instrucción <emphasis>man nsupdate</emphasis> antes de habilitarla en SSSD." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:325 sssd-ad.5.xml:1361 +#: sssd-ipa.5.xml:320 sssd-ad.5.xml:1354 msgid "" "Please note that this option will be only used in fallback attempt when " "previous attempt using autodetected settings failed or when DNS-over-TLS is " @@ -12642,17 +13157,17 @@ msgstr "" "cuando está habilitado DNS-over-TLS." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:331 sssd-ad.5.xml:1367 +#: sssd-ipa.5.xml:326 sssd-ad.5.xml:1360 msgid "Default: None (let nsupdate choose the server)" msgstr "Predeterminado: None (permitir a nsupdate elegir el servidor)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:337 sssd-ad.5.xml:1373 +#: sssd-ipa.5.xml:332 sssd-ad.5.xml:1366 msgid "dyndns_update_per_family (boolean)" msgstr "dyndns_update_per_family (booleano)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:340 sssd-ad.5.xml:1376 +#: sssd-ipa.5.xml:335 sssd-ad.5.xml:1369 msgid "" "DNS update is by default performed in two steps - IPv4 update and then IPv6 " "update. In some cases it might be desirable to perform IPv4 and IPv6 update " @@ -12664,12 +13179,12 @@ msgstr "" "paso." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:352 sssd-ad.5.xml:1388 +#: sssd-ipa.5.xml:347 sssd-ad.5.xml:1381 msgid "dyndns_dot_cacert (string)" msgstr "dyndns_dot_cacert (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:355 sssd-ad.5.xml:1391 +#: sssd-ipa.5.xml:350 sssd-ad.5.xml:1384 msgid "" "This option specifies the file of the certificate authorities certificates " "(in PEM format) in order to verify the remote server TLS certificate when " @@ -12680,17 +13195,17 @@ msgstr "" "servidor remoto cuando se utiliza DoT." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:361 sssd-ad.5.xml:1397 +#: sssd-ipa.5.xml:356 sssd-ad.5.xml:1390 msgid "Default: None (use global certificate store)" msgstr "Predeterminado: None (utiliza almacén de certificado global)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:367 sssd-ad.5.xml:1403 +#: sssd-ipa.5.xml:362 sssd-ad.5.xml:1396 msgid "dyndns_dot_cert (string)" msgstr "dyndns_dot_cert (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:370 sssd-ad.5.xml:1406 +#: sssd-ipa.5.xml:365 sssd-ad.5.xml:1399 msgid "" "This option sets the certificate(s) file for authentication for the DoT " "transport to the remote server. The certificate chain file is expected to be " @@ -12701,7 +13216,7 @@ msgstr "" "certificados esté en formato PEM." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:376 sssd-ad.5.xml:1412 +#: sssd-ipa.5.xml:371 sssd-ad.5.xml:1405 msgid "" "The <emphasis>dyndns_dot_cert</emphasis> and <emphasis>dyndns_dot_key</" "emphasis> options must be both set to achieve mutual TLS authentication." @@ -12711,17 +13226,17 @@ msgstr "" "autenticación TLS mutua." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:381 sssd-ipa.5.xml:396 sssd-ad.5.xml:1417 sssd-ad.5.xml:1432 +#: sssd-ipa.5.xml:376 sssd-ipa.5.xml:391 sssd-ad.5.xml:1410 sssd-ad.5.xml:1425 msgid "Default: None (Do not use TLS authentication)" msgstr "Por defecto: None (No utilice autenticación TLS)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:387 sssd-ad.5.xml:1423 +#: sssd-ipa.5.xml:382 sssd-ad.5.xml:1416 msgid "dyndns_dot_key (string)" msgstr "dyndns_dot_key (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:390 sssd-ad.5.xml:1426 +#: sssd-ipa.5.xml:385 sssd-ad.5.xml:1419 msgid "" "This option sets the key file for authenticated encryption for the DoT " "transport to the remote server. The private key file is expected to be in " @@ -12732,19 +13247,19 @@ msgstr "" "esté en formato PEM." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:402 +#: sssd-ipa.5.xml:397 msgid "ipa_access_order (string)" msgstr "ipa_access_order (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:409 +#: sssd-ipa.5.xml:404 msgid "<emphasis>expire</emphasis>: use IPA's account expiration policy." msgstr "" "<emphasis>caducar</emphasis>: Utilice la directiva de caducidad de cuenta " "IPA." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:448 +#: sssd-ipa.5.xml:443 msgid "" "Please note that 'access_provider = ipa' must be set for this feature to " "work." @@ -12753,12 +13268,12 @@ msgstr "" "que esta característica funcione." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:455 +#: sssd-ipa.5.xml:450 msgid "ipa_deskprofile_search_base (string)" msgstr "ipa_deskprofile_search_base (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:458 +#: sssd-ipa.5.xml:453 msgid "" "Optional. Use the given string as search base for Desktop Profile related " "objects." @@ -12767,106 +13282,106 @@ msgstr "" "relacionados con Desktop Profile." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:462 sssd-ipa.5.xml:484 +#: sssd-ipa.5.xml:457 sssd-ipa.5.xml:479 msgid "Default: Use base DN" msgstr "Predeterminado: Utilizar DN base" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:468 +#: sssd-ipa.5.xml:463 msgid "ipa_subid_ranges_search_base (string)" msgstr "ipa_subid_ranges_search_base (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:471 +#: sssd-ipa.5.xml:466 msgid "Deprecated. Use ldap_subid_ranges_search_base instead." msgstr "Obsoleto. En su lugar utilice ldap_subid_ranges_search_base." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:477 +#: sssd-ipa.5.xml:472 msgid "ipa_hbac_search_base (string)" msgstr "ipa_hbac_search_base (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:480 +#: sssd-ipa.5.xml:475 msgid "Optional. Use the given string as search base for HBAC related objects." msgstr "" "Opcional. Usa la cadena dada como base de búsqueda para los objetos HBAC " "relacionados." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:490 +#: sssd-ipa.5.xml:485 msgid "ipa_host_search_base (string)" msgstr "ipa_host_search_base (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:493 +#: sssd-ipa.5.xml:488 msgid "Deprecated. Use ldap_host_search_base instead." msgstr "Obsoleto. Usa en su lugar ldap_host_search_base." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:499 +#: sssd-ipa.5.xml:494 msgid "ipa_selinux_search_base (string)" msgstr "ipa_selinux_search_base (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:502 +#: sssd-ipa.5.xml:497 msgid "Optional. Use the given string as search base for SELinux user maps." msgstr "" "Opcional. Usa la cadena dada como base de búsqueda para los mapas de usuario " "SELinux." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:518 +#: sssd-ipa.5.xml:513 msgid "ipa_subdomains_search_base (string)" msgstr "ipa_subdomains_search_base (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:521 +#: sssd-ipa.5.xml:516 msgid "Optional. Use the given string as search base for trusted domains." msgstr "" "Opcional: Usa la cadena dada como base de búsqueda de dominios de confianza." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:530 +#: sssd-ipa.5.xml:525 msgid "Default: the value of <emphasis>cn=trusts,%basedn</emphasis>" msgstr "Por defecto: el valor de <emphasis>cn=trusts,%basedn</emphasis>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:537 +#: sssd-ipa.5.xml:532 msgid "ipa_master_domain_search_base (string)" msgstr "ipa_master_domain_search_base (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:540 +#: sssd-ipa.5.xml:535 msgid "Optional. Use the given string as search base for master domain object." msgstr "" "Opcional: Usa la cadena dada como base de búsqueda para el objeto maestro de " "dominio." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:549 +#: sssd-ipa.5.xml:544 msgid "Default: the value of <emphasis>cn=ad,cn=etc,%basedn</emphasis>" msgstr "Por defecto: el valor de <emphasis>cn=ad,cn=etc,%basedn</emphasis>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:556 +#: sssd-ipa.5.xml:551 msgid "ipa_views_search_base (string)" msgstr "ipa_views_search_base (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:559 +#: sssd-ipa.5.xml:554 msgid "Optional. Use the given string as search base for views containers." msgstr "" "Opcional. Usa la cadena dada como base de búsqueda de contenedores de vista." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:568 +#: sssd-ipa.5.xml:563 msgid "Default: the value of <emphasis>cn=views,cn=accounts,%basedn</emphasis>" msgstr "" "Predeterminado: el valor de <emphasis>cn=views,cn=accounts,%basedn</emphasis>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:578 +#: sssd-ipa.5.xml:573 msgid "" "The name of the Kerberos realm. This is optional and defaults to the value " "of <quote>ipa_domain</quote>." @@ -12875,7 +13390,7 @@ msgstr "" "de <quote>ipa_domain</quote>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:582 +#: sssd-ipa.5.xml:577 msgid "" "The name of the Kerberos realm has a special meaning in IPA - it is " "converted into the base DN to use for performing LDAP operations." @@ -12884,12 +13399,12 @@ msgstr "" "convertido hacia la base DN para usarlo para llevar a cabo operaciones LDAP." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:590 sssd-ad.5.xml:1441 +#: sssd-ipa.5.xml:585 sssd-ad.5.xml:1434 msgid "krb5_confd_path (string)" msgstr "krb5_confd_path (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:593 sssd-ad.5.xml:1444 +#: sssd-ipa.5.xml:588 sssd-ad.5.xml:1437 msgid "" "Absolute path of a directory where SSSD should place Kerberos configuration " "snippets." @@ -12898,7 +13413,7 @@ msgstr "" "configuración de Kerberos." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:597 sssd-ad.5.xml:1448 +#: sssd-ipa.5.xml:592 sssd-ad.5.xml:1441 msgid "" "To disable the creation of the configuration snippets set the parameter to " "'none'." @@ -12907,7 +13422,7 @@ msgstr "" "parámetro a 'none'." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:601 sssd-ad.5.xml:1452 +#: sssd-ipa.5.xml:596 sssd-ad.5.xml:1445 msgid "" "Default: not set (krb5.include.d subdirectory of SSSD's pubconf directory)" msgstr "" @@ -12915,12 +13430,12 @@ msgstr "" "pubconf de SSSD)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:608 +#: sssd-ipa.5.xml:603 msgid "ipa_deskprofile_refresh (integer)" msgstr "ipa_deskprofile_refresh (entero)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:611 +#: sssd-ipa.5.xml:606 msgid "" "The amount of time between lookups of the Desktop Profile rules against the " "IPA server. This will reduce the latency and load on the IPA server if there " @@ -12931,17 +13446,17 @@ msgstr "" "hay muchas solicitudes de perfiles de escritorio en un período breve." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:618 sssd-ipa.5.xml:648 sssd-ipa.5.xml:664 sssd-ad.5.xml:600 +#: sssd-ipa.5.xml:613 sssd-ipa.5.xml:643 sssd-ipa.5.xml:659 sssd-ad.5.xml:600 msgid "Default: 5 (seconds)" msgstr "Predeterminado: 5 (segundos)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:624 +#: sssd-ipa.5.xml:619 msgid "ipa_deskprofile_request_interval (integer)" msgstr "ipa_deskprofile_request_interval (entero)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:627 +#: sssd-ipa.5.xml:622 msgid "" "The amount of time between lookups of the Desktop Profile rules against the " "IPA server in case the last request did not return any rule." @@ -12951,17 +13466,17 @@ msgstr "" "regla." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:632 +#: sssd-ipa.5.xml:627 msgid "Default: 60 (minutes)" msgstr "Predeterminado: 60 (minutos)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:638 +#: sssd-ipa.5.xml:633 msgid "ipa_hbac_refresh (integer)" msgstr "ipa_hbac_refresh (entero)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:641 +#: sssd-ipa.5.xml:636 msgid "" "The amount of time between lookups of the HBAC rules against the IPA server. " "This will reduce the latency and load on the IPA server if there are many " @@ -12972,12 +13487,14 @@ msgstr "" "muchas peticiones de control de acceso hechas en un corto período." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:654 -msgid "ipa_hbac_selinux (integer)" -msgstr "ipa_hbac_selinux (entero)" +#: sssd-ipa.5.xml:649 +#, fuzzy +#| msgid "ipa_hbac_refresh (integer)" +msgid "ipa_selinux_refresh (integer)" +msgstr "ipa_hbac_refresh (entero)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:657 +#: sssd-ipa.5.xml:652 msgid "" "The amount of time between lookups of the SELinux maps against the IPA " "server. This will reduce the latency and load on the IPA server if there are " @@ -12988,12 +13505,12 @@ msgstr "" "hay muchas peticiones de acceso de usuario hechas en un corto período." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:670 +#: sssd-ipa.5.xml:665 msgid "ipa_server_mode (boolean)" msgstr "ipa_server_mode (booleano)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:673 +#: sssd-ipa.5.xml:668 msgid "" "This option will be set by the IPA installer (ipa-server-install) " "automatically and denotes if SSSD is running on an IPA server or not." @@ -13002,7 +13519,7 @@ msgstr "" "automáticamente y denota si SSSD está corriendo sobre un servidor IPA o no." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:678 +#: sssd-ipa.5.xml:673 msgid "" "On an IPA server SSSD will lookup users and groups from trusted domains " "directly while on a client it will ask an IPA server." @@ -13012,7 +13529,7 @@ msgstr "" "servidor IPA." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:683 +#: sssd-ipa.5.xml:678 msgid "" "NOTE: There are currently some assumptions that must be met when SSSD is " "running on an IPA server." @@ -13021,7 +13538,7 @@ msgstr "" "se ejecuta en un servidor IPA." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:688 +#: sssd-ipa.5.xml:683 msgid "" "The <quote>ipa_server</quote> option must be configured to point to the IPA " "server itself. This is already the default set by the IPA installer, so no " @@ -13032,7 +13549,7 @@ msgstr "" "instalador IPA de modo que no se necesitan cambios manuales." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:697 +#: sssd-ipa.5.xml:692 msgid "" "The <quote>full_name_format</quote> option must not be tweaked to only print " "short names for users from trusted domains." @@ -13041,52 +13558,52 @@ msgstr "" "solo nombres cortos de los usuarios de los dominios de confianza." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:712 +#: sssd-ipa.5.xml:707 msgid "ipa_automount_location (string)" msgstr "ipa_automount_location (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:715 +#: sssd-ipa.5.xml:710 msgid "The automounter location this IPA client will be using" msgstr "La localización del automontador de este cliente IPA que será usada" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:718 +#: sssd-ipa.5.xml:713 msgid "Default: The location named \"default\"" msgstr "Por defecto: La localización llamada “default”" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd-ipa.5.xml:726 +#: sssd-ipa.5.xml:721 msgid "VIEWS AND OVERRIDES" msgstr "VISTAS Y ANULACIONES" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:735 +#: sssd-ipa.5.xml:730 msgid "ipa_view_class (string)" msgstr "ipa_view_class (cadena)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:738 +#: sssd-ipa.5.xml:733 msgid "Objectclass of the view container." msgstr "Objectclass del contenedorde vistas." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:741 +#: sssd-ipa.5.xml:736 msgid "Default: nsContainer" msgstr "Predeterminado: nsContainer" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:747 +#: sssd-ipa.5.xml:742 msgid "ipa_view_name (string)" msgstr "ipa_view_name (cadena)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:750 +#: sssd-ipa.5.xml:745 msgid "Name of the attribute holding the name of the view." msgstr "Nombre del atributo que contiene el nombre de la vista." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:754 sssd-ldap-attributes.5.xml:496 +#: sssd-ipa.5.xml:749 sssd-ldap-attributes.5.xml:496 #: sssd-ldap-attributes.5.xml:832 sssd-ldap-attributes.5.xml:913 #: sssd-ldap-attributes.5.xml:1010 sssd-ldap-attributes.5.xml:1068 #: sssd-ldap-attributes.5.xml:1226 sssd-ldap-attributes.5.xml:1271 @@ -13094,27 +13611,27 @@ msgid "Default: cn" msgstr "Predeterminado: cn" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:760 +#: sssd-ipa.5.xml:755 msgid "ipa_override_object_class (string)" msgstr "ipa_override_object_class (cadena)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:763 +#: sssd-ipa.5.xml:758 msgid "Objectclass of the override objects." msgstr "Objectclass de los objetos anulados." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:766 +#: sssd-ipa.5.xml:761 msgid "Default: ipaOverrideAnchor" msgstr "Predeterminado: ipaOverrideAnchor" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:772 +#: sssd-ipa.5.xml:767 msgid "ipa_anchor_uuid (string)" msgstr "ipa_anchor_uuid (cadena)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:775 +#: sssd-ipa.5.xml:770 msgid "" "Name of the attribute containing the reference to the original object in a " "remote domain." @@ -13123,17 +13640,17 @@ msgstr "" "dominio remoto." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:779 +#: sssd-ipa.5.xml:774 msgid "Default: ipaAnchorUUID" msgstr "Predeterminado: ipaAnchorUUID" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:785 +#: sssd-ipa.5.xml:780 msgid "ipa_user_override_object_class (string)" msgstr "ipa_user_override_object_class (cadena)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:788 +#: sssd-ipa.5.xml:783 msgid "" "Name of the objectclass for user overrides. It is used to determine if the " "found override object is related to a user or a group." @@ -13142,57 +13659,57 @@ msgstr "" "si el objeto anulado encontrado está relacionado con un usuario o un grupo." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:793 +#: sssd-ipa.5.xml:788 msgid "User overrides can contain attributes given by" msgstr "Las anulaciones de usuario pueden contener atributos dados por" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:796 +#: sssd-ipa.5.xml:791 msgid "ldap_user_name" msgstr "ldap_user_name" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:799 +#: sssd-ipa.5.xml:794 msgid "ldap_user_uid_number" msgstr "ldap_user_uid_number" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:802 +#: sssd-ipa.5.xml:797 msgid "ldap_user_gid_number" msgstr "ldap_user_gid_number" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:805 +#: sssd-ipa.5.xml:800 msgid "ldap_user_gecos" msgstr "ldap_user_gecos" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:808 +#: sssd-ipa.5.xml:803 msgid "ldap_user_home_directory" msgstr "ldap_user_home_directory" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:811 +#: sssd-ipa.5.xml:806 msgid "ldap_user_shell" msgstr "ldap_user_shell" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:814 +#: sssd-ipa.5.xml:809 msgid "ldap_user_ssh_public_key" msgstr "ldap_user_ssh_public_key" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:819 +#: sssd-ipa.5.xml:814 msgid "Default: ipaUserOverride" msgstr "Predeterminado: ipaUserOverride" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:825 +#: sssd-ipa.5.xml:820 msgid "ipa_group_override_object_class (string)" msgstr "ipa_group_override_object_class (cadena)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:828 +#: sssd-ipa.5.xml:823 msgid "" "Name of the objectclass for group overrides. It is used to determine if the " "found override object is related to a user or a group." @@ -13201,27 +13718,27 @@ msgstr "" "objeto anulado encontrado está relacionado con un usuario o un grupo." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:833 +#: sssd-ipa.5.xml:828 msgid "Group overrides can contain attributes given by" msgstr "Las anulaciones de grupo pueden contener atributos dados por" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:836 +#: sssd-ipa.5.xml:831 msgid "ldap_group_name" msgstr "ldap_group_name" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:839 +#: sssd-ipa.5.xml:834 msgid "ldap_group_gid_number" msgstr "ldap_group_gid_number" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:844 +#: sssd-ipa.5.xml:839 msgid "Default: ipaGroupOverride" msgstr "Predeterminado: ipaGroupOverride" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:728 +#: sssd-ipa.5.xml:723 msgid "" "SSSD can handle views and overrides which are offered by FreeIPA 4.1 and " "later version. Since all paths and objectclasses are fixed on the server " @@ -13236,12 +13753,12 @@ msgstr "" "<placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd-ipa.5.xml:856 +#: sssd-ipa.5.xml:851 msgid "SUBDOMAINS PROVIDER" msgstr "PROVEEDOR DE SUBDOMINIOS" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:858 +#: sssd-ipa.5.xml:853 msgid "" "The IPA subdomains provider behaves slightly differently if it is configured " "explicitly or implicitly." @@ -13250,7 +13767,7 @@ msgstr "" "si está configurado explícitamente o implícitamente." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:862 +#: sssd-ipa.5.xml:857 msgid "" "If the option 'subdomains_provider = ipa' is found in the domain section of " "sssd.conf, the IPA subdomains provider is configured explicitly, and all " @@ -13262,7 +13779,7 @@ msgstr "" "de IPA si es necesario." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:868 +#: sssd-ipa.5.xml:863 msgid "" "If the option 'subdomains_provider' is not set in the domain section of " "sssd.conf but there is the option 'id_provider = ipa', the IPA subdomains " @@ -13282,12 +13799,12 @@ msgstr "" "otra vez." #. type: Content of: <reference><refentry><refsect1><title> -#: sssd-ipa.5.xml:879 +#: sssd-ipa.5.xml:874 msgid "TRUSTED DOMAINS CONFIGURATION" msgstr "CONFIGURACIÓN DE DOMINIOS DE CONFIANZA" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-ipa.5.xml:887 +#: sssd-ipa.5.xml:882 #, no-wrap msgid "" "[domain/ipa.domain.com/ad.domain.com]\n" @@ -13297,7 +13814,7 @@ msgstr "" "ad_server = dc.ad.dominio.com\n" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:881 +#: sssd-ipa.5.xml:876 msgid "" "Some configuration options can also be set for a trusted domain. A trusted " "domain configuration can be set using the trusted domain subsection as shown " @@ -13312,7 +13829,7 @@ msgstr "" "dominio principal. <placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:892 +#: sssd-ipa.5.xml:887 msgid "" "For more details, see the <citerefentry> <refentrytitle>sssd.conf</" "refentrytitle> <manvolnum>5</manvolnum> </citerefentry> manual page." @@ -13322,7 +13839,7 @@ msgstr "" "citerefentry>." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:899 +#: sssd-ipa.5.xml:894 msgid "" "Different configuration options are tunable for a trusted domain depending " "on whether you are configuring SSSD on an IPA server or an IPA client." @@ -13332,12 +13849,12 @@ msgstr "" "IPA o un cliente IPA." #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd-ipa.5.xml:904 +#: sssd-ipa.5.xml:899 msgid "OPTIONS TUNABLE ON IPA MASTERS" msgstr "OPCIONES AJUSTABLES EN IPA MAESTROS" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:906 +#: sssd-ipa.5.xml:901 msgid "" "The following options can be set in a subdomain section on an IPA master:" msgstr "" @@ -13345,47 +13862,47 @@ msgstr "" "un IPA maestro:" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:910 sssd-ipa.5.xml:950 +#: sssd-ipa.5.xml:905 sssd-ipa.5.xml:945 msgid "ad_server" msgstr "ad_server" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:913 +#: sssd-ipa.5.xml:908 msgid "ad_backup_server" msgstr "ad_backup_server" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:916 sssd-ipa.5.xml:953 +#: sssd-ipa.5.xml:911 sssd-ipa.5.xml:948 msgid "ad_site" msgstr "ad_site" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:919 +#: sssd-ipa.5.xml:914 msgid "ipa_server" msgstr "ipa_server" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:922 +#: sssd-ipa.5.xml:917 msgid "ipa_backup_server" msgstr "ipa_backup_server" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:925 +#: sssd-ipa.5.xml:920 msgid "ldap_search_base" msgstr "ldap_search_base" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:928 +#: sssd-ipa.5.xml:923 msgid "ldap_user_search_base" msgstr "ldap_user_search_base" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:931 +#: sssd-ipa.5.xml:926 msgid "ldap_group_search_base" msgstr "ldap_group_search_base" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:939 +#: sssd-ipa.5.xml:934 msgid "" "Options prefixed with 'ad_' or 'ipa_' only apply to their respective " "subdomain type." @@ -13394,12 +13911,12 @@ msgstr "" "tipo de subdominio." #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd-ipa.5.xml:944 +#: sssd-ipa.5.xml:939 msgid "OPTIONS TUNABLE ON IPA CLIENTS" msgstr "OPCIONES AJUSTABLES SOBRE CLIENTES IPA" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:946 +#: sssd-ipa.5.xml:941 msgid "" "The following options can be set in an AD subdomain section on an IPA client:" msgstr "" @@ -13407,7 +13924,7 @@ msgstr "" "sobre un cliente IPA:" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:958 +#: sssd-ipa.5.xml:953 msgid "" "Note that if both options are set, only <quote>ad_server</quote> is " "evaluated." @@ -13416,7 +13933,7 @@ msgstr "" "ad_server</quote>." #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:962 +#: sssd-ipa.5.xml:957 msgid "" "Since any request for a user or a group identity from a trusted domain " "triggered from an IPA client is resolved by the IPA server, the " @@ -13439,7 +13956,7 @@ msgstr "" "citerefentry> para mas detalles sobre el complemento localizador Kerberos." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:986 +#: sssd-ipa.5.xml:981 msgid "" "The following example assumes that SSSD is correctly configured and " "example.com is one of the domains in the <replaceable>[sssd]</replaceable> " @@ -13451,7 +13968,7 @@ msgstr "" "proveedor ipa." #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-ipa.5.xml:993 +#: sssd-ipa.5.xml:988 #, no-wrap msgid "" "[domain/example.com]\n" @@ -13651,7 +14168,7 @@ msgstr "" "SSSD solo resuelve grupos de seguridad de Active Directory. Para obtener más " "información sobre los tipos de grupos de AD, consulte: <ulink url=\"https://" "docs.microsoft.com/en-us/windows-server/identity/ad-ds/manage/understand-" -"security-groups\">Grupos de seguridad de Active Directory</ulink>" +"security-groups\"> Grupos de seguridad de Active Directory</ulink>" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ad.5.xml:120 @@ -14411,27 +14928,27 @@ msgid "lxdm" msgstr "lxdm" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:694 +#: sssd-ad.5.xml:699 msgid "sddm" msgstr "sddm" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:699 +#: sssd-ad.5.xml:704 msgid "unity" msgstr "unity" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:704 +#: sssd-ad.5.xml:709 msgid "xdm" msgstr "xdm" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:713 +#: sssd-ad.5.xml:718 msgid "ad_gpo_map_remote_interactive (string)" msgstr "ad_gpo_map_remote_interactive (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:716 +#: sssd-ad.5.xml:721 msgid "" "A comma-separated list of PAM service names for which GPO-based access " "control is evaluated based on the RemoteInteractiveLogonRight and " @@ -14460,7 +14977,7 @@ msgstr "" "parte de la configuración de directiva." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:735 +#: sssd-ad.5.xml:740 msgid "" "Note: Using the Group Policy Management Editor this value is called \"Allow " "log on through Remote Desktop Services\" and \"Deny log on through Remote " @@ -14472,7 +14989,7 @@ msgstr "" "Remoto»." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:750 +#: sssd-ad.5.xml:755 #, no-wrap msgid "" "ad_gpo_map_remote_interactive = +my_pam_service, -sshd\n" @@ -14482,7 +14999,7 @@ msgstr "" " " #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:741 +#: sssd-ad.5.xml:746 msgid "" "It is possible to add another PAM service name to the default set by using " "<quote>+service_name</quote> or to explicitly remove a PAM service name from " @@ -14502,22 +15019,22 @@ msgstr "" "id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:758 +#: sssd-ad.5.xml:763 msgid "sshd" msgstr "sshd" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:763 +#: sssd-ad.5.xml:768 msgid "cockpit" msgstr "cockpit" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:772 +#: sssd-ad.5.xml:777 msgid "ad_gpo_map_network (string)" msgstr "ad_gpo_map_network (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:775 +#: sssd-ad.5.xml:780 msgid "" "A comma-separated list of PAM service names for which GPO-based access " "control is evaluated based on the NetworkLogonRight and " @@ -14546,7 +15063,7 @@ msgstr "" "configuración de directiva." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:793 +#: sssd-ad.5.xml:798 msgid "" "Note: Using the Group Policy Management Editor this value is called \"Access " "this computer from the network\" and \"Deny access to this computer from the " @@ -14557,7 +15074,7 @@ msgstr "" "equipo desde la red»." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:808 +#: sssd-ad.5.xml:813 #, no-wrap msgid "" "ad_gpo_map_network = +my_pam_service, -ftp\n" @@ -14567,7 +15084,7 @@ msgstr "" " " #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:799 +#: sssd-ad.5.xml:804 msgid "" "It is possible to add another PAM service name to the default set by using " "<quote>+service_name</quote> or to explicitly remove a PAM service name from " @@ -14586,22 +15103,22 @@ msgstr "" "la configuración siguiente: <placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:816 +#: sssd-ad.5.xml:821 msgid "ftp" msgstr "ftp" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:821 +#: sssd-ad.5.xml:826 msgid "samba" msgstr "samba" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:830 +#: sssd-ad.5.xml:835 msgid "ad_gpo_map_batch (string)" msgstr "ad_gpo_map_batch (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:833 +#: sssd-ad.5.xml:838 msgid "" "A comma-separated list of PAM service names for which GPO-based access " "control is evaluated based on the BatchLogonRight and DenyBatchLogonRight " @@ -14628,7 +15145,7 @@ msgstr "" "de directivas." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:851 +#: sssd-ad.5.xml:856 msgid "" "Note: Using the Group Policy Management Editor this value is called \"Allow " "log on as a batch job\" and \"Deny log on as a batch job\"." @@ -14638,7 +15155,7 @@ msgstr "" "tarea de lote»." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:865 +#: sssd-ad.5.xml:870 #, no-wrap msgid "" "ad_gpo_map_batch = +my_pam_service, -crond\n" @@ -14648,7 +15165,7 @@ msgstr "" " " #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:856 +#: sssd-ad.5.xml:861 msgid "" "It is possible to add another PAM service name to the default set by using " "<quote>+service_name</quote> or to explicitly remove a PAM service name from " @@ -14668,7 +15185,7 @@ msgstr "" "id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:868 +#: sssd-ad.5.xml:873 msgid "" "Note: Cron service name may differ depending on Linux distribution used." msgstr "" @@ -14676,17 +15193,17 @@ msgstr "" "utilizada." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:874 +#: sssd-ad.5.xml:879 msgid "crond" msgstr "crond" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:883 +#: sssd-ad.5.xml:888 msgid "ad_gpo_map_service (string)" msgstr "ad_gpo_map_service (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:886 +#: sssd-ad.5.xml:891 msgid "" "A comma-separated list of PAM service names for which GPO-based access " "control is evaluated based on the ServiceLogonRight and " @@ -14712,7 +15229,7 @@ msgstr "" "esto o al menos uno de sus grupos es parte de las opciones de directiva." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:904 +#: sssd-ad.5.xml:909 msgid "" "Note: Using the Group Policy Management Editor this value is called \"Allow " "log on as a service\" and \"Deny log on as a service\"." @@ -14722,7 +15239,7 @@ msgstr "" "servicio»." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:917 +#: sssd-ad.5.xml:922 #, no-wrap msgid "" "ad_gpo_map_service = +my_pam_service\n" @@ -14732,7 +15249,7 @@ msgstr "" " " #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:909 sssd-ad.5.xml:984 +#: sssd-ad.5.xml:914 sssd-ad.5.xml:989 msgid "" "It is possible to add a PAM service name to the default set by using " "<quote>+service_name</quote>. Since the default set is empty, it is not " @@ -14749,12 +15266,12 @@ msgstr "" "siguiente: <placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:927 +#: sssd-ad.5.xml:932 msgid "ad_gpo_map_permit (string)" msgstr "ad_gpo_map_permit (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:930 +#: sssd-ad.5.xml:935 msgid "" "A comma-separated list of PAM service names for which GPO-based access is " "always granted, regardless of any GPO Logon Rights." @@ -14764,7 +15281,7 @@ msgstr "" "Acceso GPO." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:944 +#: sssd-ad.5.xml:949 #, no-wrap msgid "" "ad_gpo_map_permit = +my_pam_service, -sudo\n" @@ -14774,7 +15291,7 @@ msgstr "" " " #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:935 +#: sssd-ad.5.xml:940 msgid "" "It is possible to add another PAM service name to the default set by using " "<quote>+service_name</quote> or to explicitly remove a PAM service name from " @@ -14794,22 +15311,22 @@ msgstr "" "id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:952 +#: sssd-ad.5.xml:957 msgid "polkit-1" msgstr "polkit-1" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:967 +#: sssd-ad.5.xml:972 msgid "systemd-user" msgstr "systemd-user" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:976 +#: sssd-ad.5.xml:981 msgid "ad_gpo_map_deny (string)" msgstr "ad_gpo_map_deny (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:979 +#: sssd-ad.5.xml:984 msgid "" "A comma-separated list of PAM service names for which GPO-based access is " "always denied, regardless of any GPO Logon Rights." @@ -14819,7 +15336,7 @@ msgstr "" "Derechos de Acceso de GPO." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:992 +#: sssd-ad.5.xml:997 #, no-wrap msgid "" "ad_gpo_map_deny = +my_pam_service\n" @@ -14829,12 +15346,12 @@ msgstr "" " " #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:1002 +#: sssd-ad.5.xml:1007 msgid "ad_gpo_default_right (string)" msgstr "ad_gpo_default_right (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1005 +#: sssd-ad.5.xml:1010 msgid "" "This option defines how access control is evaluated for PAM service names " "that are not explicitly listed in one of the ad_gpo_map_* options. This " @@ -14858,52 +15375,52 @@ msgstr "" "relacionados." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1018 +#: sssd-ad.5.xml:1023 msgid "Supported values for this option include:" msgstr "Los valores admitidos para esta opción incluyen:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1027 +#: sssd-ad.5.xml:1032 msgid "remote_interactive" msgstr "remote_interactive" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1032 +#: sssd-ad.5.xml:1037 msgid "network" msgstr "network" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1037 +#: sssd-ad.5.xml:1042 msgid "batch" msgstr "batch" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1042 +#: sssd-ad.5.xml:1047 msgid "service" msgstr "service" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1047 +#: sssd-ad.5.xml:1052 msgid "permit" msgstr "permit" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1052 +#: sssd-ad.5.xml:1057 msgid "deny" msgstr "deny" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1058 +#: sssd-ad.5.xml:1063 msgid "Default: deny" msgstr "Predeterminado: deny (deniega)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:1064 +#: sssd-ad.5.xml:1069 msgid "ad_maximum_machine_account_password_age (integer)" msgstr "ad_maximum_machine_account_password_age (entero)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1067 +#: sssd-ad.5.xml:1072 msgid "" "SSSD will check once a day if the machine account password is older than the " "given age in days and try to renew it. A value of 0 will disable the renewal " @@ -14914,17 +15431,17 @@ msgstr "" "inhabilita el intento de renovación." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1073 +#: sssd-ad.5.xml:1078 msgid "Default: 30 days" msgstr "Predeterminado: 30 días" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:1079 +#: sssd-ad.5.xml:1084 msgid "ad_machine_account_password_renewal_opts (string)" msgstr "ad_machine_account_password_renewal_opts (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1082 +#: sssd-ad.5.xml:1087 msgid "" "This option should only be used to test the machine account renewal task. " "The option expects 3 integers and a string separated by a colon (':'). The " @@ -14946,16 +15463,26 @@ msgstr "" "o está vacío este valor en la cadena del valor será utilizado el '0'." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1096 +#: sssd-ad.5.xml:1101 +#, fuzzy +#| msgid "" +#| "The optional fourth string value identifies the helper binary which " +#| "should be used for the renewal. Currently <command>adcli</command> and " +#| "<command>realm</command> are supported. If this value is missing or empty " +#| "in the value string <command>realm</command> will be used. Since the " +#| "helper is started as the user SSSD is running as there might be the " +#| "chance that the renewal will fail if this user does not has permissions " +#| "to modify the keytab file where the machine account credentials are " +#| "stored. This will typically be the case for <command>adcli</command>." msgid "" "The optional fourth string value identifies the helper binary which should " "be used for the renewal. Currently <command>adcli</command> and " "<command>realm</command> are supported. If this value is missing or empty in " "the value string <command>realm</command> will be used. Since the helper is " "started as the user SSSD is running as there might be the chance that the " -"renewal will fail if this user does not has permissions to modify the keytab " -"file where the machine account credentials are stored. This will typically " -"be the case for <command>adcli</command>." +"renewal will fail if this user does not have permissions to modify the " +"keytab file where the machine account credentials are stored. This will " +"typically be the case for <command>adcli</command>." msgstr "" "El valor de cadena cuarta opcional identifica el ayudante binario el cuál " "sería utilizado para la renovación. Actualmente <command>adcli</command> y " @@ -14968,7 +15495,7 @@ msgstr "" "<command>adcli</command>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1110 +#: sssd-ad.5.xml:1115 msgid "" "<command>realm</command> is not updating the keytab directly but is calling " "the <command>realmd</command> process, which runs as root user, for this " @@ -14983,17 +15510,17 @@ msgstr "" "SSSD proporciona reglas adecuadas para como el usuario SSSD está ejecutando." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1119 +#: sssd-ad.5.xml:1124 msgid "Default: 86400:750:300:realm (24h, 12m30s and 5m)" msgstr "Predeterminado: 86400:750:300:realm (24h, 12m30s y 5m)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:1125 +#: sssd-ad.5.xml:1130 msgid "ad_update_samba_machine_account_password (boolean)" msgstr "ad_update_samba_machine_account_password (booleano)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1128 +#: sssd-ad.5.xml:1133 msgid "" "If enabled, when SSSD renews the machine account password, it will also be " "updated in Samba's database. This prevents Samba's copy of the machine " @@ -15006,16 +15533,26 @@ msgstr "" "cuando la configuración a utilizar AD para autenticación." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:1141 -msgid "ad_use_ldaps (bool)" +#: sssd-ad.5.xml:1146 +#, fuzzy +#| msgid "ad_use_ldaps (bool)" +msgid "ad_use_ldaps (boolean)" msgstr "ad_use_ldaps (bool)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1144 +#: sssd-ad.5.xml:1149 +#, fuzzy +#| msgid "" +#| "By default SSSD uses the plain LDAP port 389 and the Global Catalog port " +#| "3628. If this option is set to True SSSD will use the LDAPS port 636 and " +#| "Global Catalog port 3629 with LDAPS protection. Since AD does not allow " +#| "to have multiple encryption layers on a single connection and we still " +#| "want to use SASL/GSSAPI or SASL/GSS-SPNEGO for authentication the SASL " +#| "security property maxssf is set to 0 (zero) for those connections." msgid "" "By default SSSD uses the plain LDAP port 389 and the Global Catalog port " -"3628. If this option is set to True SSSD will use the LDAPS port 636 and " -"Global Catalog port 3629 with LDAPS protection. Since AD does not allow to " +"3268. If this option is set to True SSSD will use the LDAPS port 636 and " +"Global Catalog port 3269 with LDAPS protection. Since AD does not allow to " "have multiple encryption layers on a single connection and we still want to " "use SASL/GSSAPI or SASL/GSS-SPNEGO for authentication the SASL security " "property maxssf is set to 0 (zero) for those connections." @@ -15029,7 +15566,7 @@ msgstr "" "conexiones." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1164 +#: sssd-ad.5.xml:1169 msgid "" "Optional. This option tells SSSD to automatically update the Active " "Directory DNS server with the IP address of this client. The update is " @@ -15054,17 +15591,6 @@ msgstr "Por defecto: 3.600 (segundos)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:1216 msgid "" -"NOTE: While it is still possible to use the old <emphasis>ipa_dyndns_iface</" -"emphasis> option, users should migrate to using <emphasis>dyndns_iface</" -"emphasis> in their config file." -msgstr "" -"NOTA: aunque todavía es posible usar la opción anterior <emphasis>" -"ipa_dyndns_iface</emphasis>, los usuarios deberían migrar usando <emphasis>" -"dyndns_iface</emphasis> en su archivo de configuración." - -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1222 -msgid "" "Default: Use the IP addresses of the interface which is used for AD LDAP " "connection" msgstr "" @@ -15072,13 +15598,19 @@ msgstr "" "utilizadas para la conexión IPA LDAP" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1258 +#: sssd-ad.5.xml:1252 +#, fuzzy +#| msgid "" +#| "How often should the back end perform periodic DNS update in addition to " +#| "the automatic update performed when the back end goes online. This " +#| "option is optional and applicable only when dyndns_update is true. Note " +#| "that the lowest possible value is 60 seconds in-case if value is provided " +#| "less than 60, parameter will assume lowest value only." msgid "" "How often should the back end perform periodic DNS update in addition to the " -"automatic update performed when the back end goes online. This option is " -"optional and applicable only when dyndns_update is true. Note that the " -"lowest possible value is 60 seconds in-case if value is provided less than " -"60, parameter will assume lowest value only." +"automatic update performed when the back end goes online. This is optional " +"and applicable only when dyndns_update is true. Note that the minimum value " +"is 60 seconds, any specified value below this threshold will default to 60." msgstr "" "Qué a menudo tener que el fin posterior actúa periódico DNS actualización " "además de la actualización automática actuada cuándo el fin posterior va on-" @@ -15088,7 +15620,7 @@ msgstr "" "sólo." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ad.5.xml:1472 +#: sssd-ad.5.xml:1465 msgid "" "The following example assumes that SSSD is correctly configured and " "example.com is one of the domains in the <replaceable>[sssd]</replaceable> " @@ -15100,7 +15632,7 @@ msgstr "" "proveedor AD." #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-ad.5.xml:1479 +#: sssd-ad.5.xml:1472 #, no-wrap msgid "" "[domain/EXAMPLE]\n" @@ -15124,7 +15656,7 @@ msgstr "" "ad_domain = ejemplo.com\n" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-ad.5.xml:1499 +#: sssd-ad.5.xml:1492 #, no-wrap msgid "" "access_provider = ldap\n" @@ -15136,7 +15668,7 @@ msgstr "" "ldap_account_expire_policy = ad\n" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ad.5.xml:1495 +#: sssd-ad.5.xml:1488 msgid "" "The AD access control provider checks if the account is expired. It has the " "same effect as the following configuration of the LDAP provider: " @@ -15147,7 +15679,7 @@ msgstr "" "<placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ad.5.xml:1505 +#: sssd-ad.5.xml:1498 msgid "" "However, unless the <quote>ad</quote> access control provider is explicitly " "configured, the default access provider is <quote>permit</quote>. Please " @@ -15162,7 +15694,7 @@ msgstr "" "de conexión (como las URL de LDAP y detalles de cifrado manualmente." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ad.5.xml:1513 +#: sssd-ad.5.xml:1506 msgid "" "When the autofs provider is set to <quote>ad</quote>, the RFC2307 schema " "attribute mapping (nisMap, nisObject, ...) is used, because these attributes " @@ -15376,11 +15908,17 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-sudo.5.xml:137 +#, fuzzy +#| msgid "" +#| "The <emphasis>smart refresh</emphasis> periodically downloads rules that " +#| "are new or were modified after the last update. Its primary goal is to " +#| "keep the database growing by fetching only small increments that do not " +#| "generate large amounts of network traffic." msgid "" "The <emphasis>smart refresh</emphasis> periodically downloads rules that are " -"new or were modified after the last update. Its primary goal is to keep the " -"database growing by fetching only small increments that do not generate " -"large amounts of network traffic." +"new or were modified after the last update. Its primary goal is to grow the " +"database incrementally by fetching only small updates, avoiding large " +"amounts of network traffic." msgstr "" "El <emphasis>refresco inteligente</emphasis> periódicamente descarga reglas " "que son nuevas o fueron modificadas desde la última actualización. Su " @@ -15626,11 +16164,20 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-idp.5.xml:70 +#, fuzzy +#| msgid "" +#| "Depending on the IdP product additional platform specific options might " +#| "follow the name separated by a colon (:). E.g. for Keycloak the base URI " +#| "for the user and group REST API must be given. For Entra ID this is not " +#| "needed because there is a generic endpoint for all tenants." msgid "" "Depending on the IdP product additional platform specific options might " "follow the name separated by a colon (:). E.g. for Keycloak the base URI for " -"the user and group REST API must be given. For Entra ID this is not needed " -"because there is a generic endpoint for all tenants." +"the user and group REST API must be given. For Entra ID the base URI for the " +"Microsoft Graph API can be given to use sovereign or government cloud " +"endpoints instead of the default (https://graph.microsoft.com/v1.0). E.g. " +"<quote>entra_id:https://graph.microsoft.us/v1.0</quote> for the US " +"government cloud (GCC High)." msgstr "" "Dependiendo de las opciones específicas de la plataforma del producto IdP " "tal vez siga el nombre separado por un dos puntos (:). P.ej. para KeyCloak " @@ -15639,17 +16186,17 @@ msgstr "" "rentistas." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:78 sssd-idp.5.xml:94 sssd-idp.5.xml:119 +#: sssd-idp.5.xml:82 sssd-idp.5.xml:98 sssd-idp.5.xml:123 msgid "Default: Not set (Required)" msgstr "Por defecto: No definido (Requerido)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:83 +#: sssd-idp.5.xml:87 msgid "idp_client_id (string)" msgstr "idp_client_id (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:86 +#: sssd-idp.5.xml:90 msgid "" "ID of the IdP client used by SSSD to authenticate users and as a client to " "lookup user and group attributes. This client must offer device " @@ -15662,12 +16209,12 @@ msgstr "" "leer atributos de usuario y grupo." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:99 +#: sssd-idp.5.xml:103 msgid "idp_client_secret (string)" msgstr "idp_client_secret (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:102 +#: sssd-idp.5.xml:106 msgid "" "Password of the IdP client. The password is required for the id_provider. If " "only used as auth_provider it depends on the server side configuration if it " @@ -15678,22 +16225,22 @@ msgstr "" "configuración del servidor si está requerido o no." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:113 +#: sssd-idp.5.xml:117 msgid "idp_token_endpoint (string)" msgstr "idp_token_endpoint (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:116 +#: sssd-idp.5.xml:120 msgid "IdP endpoint for requesting access tokens." msgstr "Punto final de IdP para solicitar tokens de acceso." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:124 +#: sssd-idp.5.xml:128 msgid "idp_device_auth_endpoint (string)" msgstr "idp_device_auth_endpoint (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:127 +#: sssd-idp.5.xml:131 msgid "" "IdP endpoint for device authorization according to RFC-8628. This is " "required for user authentication." @@ -15702,12 +16249,12 @@ msgstr "" "requerido para autentificación de usuario." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:137 +#: sssd-idp.5.xml:141 msgid "idp_userinfo_endpoint (string)" msgstr "idp_userinfo_endpoint (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:140 +#: sssd-idp.5.xml:144 msgid "" "IdP userinfo endpoint to request user attributes after a successful " "authentication of the user. Required for authentication." @@ -15717,12 +16264,12 @@ msgstr "" "autenticación." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:150 +#: sssd-idp.5.xml:154 msgid "idp_id_scope (string)" msgstr "idp_id_scope (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:153 +#: sssd-idp.5.xml:157 msgid "" "Scope required for looking up user and group attributes with the REST API. " "The scopes are used by the server to determine which attributes/claims are " @@ -15732,13 +16279,20 @@ msgstr "" "REST. Los ámbitos son utilizados por el servidor para determinar cuales " "atributos/requerimientos son devueltos al invocante." +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:163 +msgid "" +"Note: In previous versions of SSSD, this option was expected to already be " +"URL-encoded." +msgstr "" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:164 +#: sssd-idp.5.xml:172 msgid "idp_auth_scope (string)" msgstr "idp_auth_scope (cadena)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:167 +#: sssd-idp.5.xml:175 msgid "" "Scope required during authentication. The scopes are used by the server to " "determine which attributes/claims are returned to the caller." @@ -15748,7 +16302,7 @@ msgstr "" "invocador." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:172 +#: sssd-idp.5.xml:180 msgid "" "Currently the tokens returned during user authentication are not used for " "other purposes hence the only important claim is the subject identifier " @@ -15762,22 +16316,120 @@ msgstr "" "el futuro." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:185 +#: sssd-idp.5.xml:193 +#, fuzzy +#| msgid "ldap_user_extra_attrs (string)" +msgid "idp_auth_user_identifier_attr (string)" +msgstr "ldap_user_extra_attrs (cadena)" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:196 +msgid "" +"Attribute used to identify the authenticated user in userinfo data or token " +"claims." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:200 +msgid "" +"For hybrid Active Directory and Entra ID deployments where " +"<quote>id_provider = ad</quote> and <quote>auth_provider = idp</quote>, this " +"option must be set explicitly. No value is derived from the identity " +"provider, because more than one attribute can link an Entra ID object to its " +"on-premises counterpart and only the administrator knows which one the " +"directory synchronization is configured to use." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:211 +msgid "" +"Setting this option to <quote>onPremisesImmutableId</quote> is the usual " +"choice for such deployments. Microsoft Entra Connect populates that " +"attribute with the base64-encoded form of the 16-byte Active Directory " +"<quote>objectGUID</quote> when objectGUID is used as the sourceAnchor. SSSD " +"decodes the value and converts the raw bytes with the same conversion used " +"for AD objectGUID attributes, so the result matches the UUID stored in the " +"SSSD cache for the AD user." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:224 +msgid "" +"Note that Microsoft Entra Connect 1.1.524.0 and later use <quote>ms-DS-" +"ConsistencyGuid</quote> as the sourceAnchor for user objects instead of " +"<quote>objectGUID</quote>. The value is normally copied from objectGUID for " +"objects that do not have it set yet, in which case the decoded identifier " +"still matches. It does not match if ms-DS-ConsistencyGuid was populated " +"independently, if users were moved between forests or domains, or if a " +"different attribute such as employeeID was selected as the sourceAnchor. See " +"<ulink url=\"https://learn.microsoft.com/en-us/entra/identity/hybrid/connect/" +"plan-connect-design-concepts\"> Microsoft Entra Connect: Design concepts</" +"ulink> for details on sourceAnchor selection." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:241 +msgid "" +"Microsoft Graph does not return <quote>onPremisesImmutableId</quote> by " +"default. The <quote>idp_userinfo_endpoint</quote> must request it with " +"<quote>$select</quote>, see the example below and <ulink url=\"https://" +"learn.microsoft.com/en-us/graph/api/resources/user\"> the Microsoft Graph " +"user resource type</ulink>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:251 +msgid "" +"If the configured attribute is missing or cannot be decoded (for example " +"cloud-only Entra ID users without <quote>onPremisesImmutableId</quote>), " +"authentication fails. SSSD does not fall back to another attribute when this " +"option is set." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:258 +msgid "" +"Default: not set, <quote>sub</quote> for Keycloak and <quote>id</quote> for " +"other IdP types" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-idp.5.xml:264 msgid "idp_request_timeout (integer)" msgstr "idp_request_timeout (entero)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:188 +#: sssd-idp.5.xml:267 msgid "Timeout in seconds for an individual request to the IdP." msgstr "Tiempo de espera en segundo para una solicitud individual para el IdP." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:197 +#: sssd-idp.5.xml:276 +#, fuzzy +#| msgid "ldap_referrals (boolean)" +msgid "idp_auto_refresh (boolean)" +msgstr "ldap_referrals (boolean)" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:279 +msgid "" +"Refresh tokens automatically, after they have reached about half their " +"lifetime." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:283 +msgid "" +"Note: Scheduled token refreshes are not preserved across restarts of SSSD." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-idp.5.xml:292 msgid "idmap_range_min (integer)" msgstr "idmap_range_min (entero)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:200 +#: sssd-idp.5.xml:295 msgid "" "Specifies the lower (inclusive) bound of the range of POSIX IDs to use for " "mapping IdP users and group to POSIX IDs. It is the first POSIX ID which can " @@ -15788,7 +16440,7 @@ msgstr "" "Esto es el primer ID de POSIX el cual puede ser utilizado para la relación." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:206 +#: sssd-idp.5.xml:301 msgid "" "The interval between <quote>idmap_range_min</quote> and " "<quote>idmap_range_max</quote> will be split into smaller ranges of size " @@ -15801,18 +16453,18 @@ msgstr "" "individual." #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:213 sssd-idp.5.xml:239 include/ldap_id_mapping.xml:139 +#: sssd-idp.5.xml:308 sssd-idp.5.xml:334 include/ldap_id_mapping.xml:139 #: include/ldap_id_mapping.xml:197 msgid "Default: 200000" msgstr "Por defecto: 200000" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:218 +#: sssd-idp.5.xml:313 msgid "idmap_range_max (integer)" msgstr "idmap_range_max (entero)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:221 +#: sssd-idp.5.xml:316 msgid "" "Specifies the upper (exclusive) bound of the range of POSIX IDs to use for " "mapping IdP users and groups to POSIX IDs. It is the first POSIX ID which " @@ -15824,58 +16476,122 @@ msgstr "" "relacionado de POSIX." #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:227 include/ldap_id_mapping.xml:165 +#: sssd-idp.5.xml:322 include/ldap_id_mapping.xml:165 msgid "Default: 2000200000" msgstr "Por defecto: 2000200000" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:232 +#: sssd-idp.5.xml:327 msgid "idmap_range_size (integer)" msgstr "idmap_range_size (entero)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:235 +#: sssd-idp.5.xml:330 msgid "Specifies the number of POSIX IDs available for a single IdP domain." msgstr "" "Especifica el número de los ID POSIX disponibles para un único dominio IdP." #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-idp.5.xml:251 -#, no-wrap +#: sssd-idp.5.xml:346 +#, fuzzy, no-wrap +#| msgid "" +#| "[domain/entra_id]\n" +#| "id_provider = idp\n" +#| "idp_type = entra_id\n" +#| "idp_client_id = 12345678-abcd-0101-efef-ba9876543210\n" +#| "idp_client_secret = YOUR-CLIENT-SCERET\n" +#| "idp_token_endpoint = https://login.microsoftonline.com/TENNANT-ID/oauth2/v2.0/token\n" +#| "idp_userinfo_endpoint = https://graph.microsoft.com/v1.0/me\n" +#| "idp_device_auth_endpoint = https://login.microsoftonline.com/TENNANT-ID/oauth2/v2.0/devicecode\n" +#| "idp_id_scope = https%3A%2F%2Fgraph.microsoft.com%2F.default\n" +#| "idp_auth_scope = openid profile email\n" msgid "" "[domain/entra_id]\n" "id_provider = idp\n" "idp_type = entra_id\n" "idp_client_id = 12345678-abcd-0101-efef-ba9876543210\n" -"idp_client_secret = YOUR-CLIENT-SCERET\n" +"idp_client_secret = YOUR-CLIENT-SECRET\n" +"idp_token_endpoint = https://login.microsoftonline.com/TENANT-ID/oauth2/v2.0/token\n" +"idp_userinfo_endpoint = https://graph.microsoft.com/v1.0/me\n" +"idp_device_auth_endpoint = https://login.microsoftonline.com/TENANT-ID/oauth2/v2.0/devicecode\n" +"idp_id_scope = https://graph.microsoft.com/.default\n" +"idp_auth_scope = openid profile email\n" +msgstr "" +"[domain/entra_id]\n" +"id_provider = idp\n" +"idp_type = entra_id\n" +"idp_client_id = 12345678-abcd-0101-efef-ba9876543210\n" +"idp_client_secret = SU_CLIENTE_SECRETO\n" "idp_token_endpoint = https://login.microsoftonline.com/TENNANT-ID/oauth2/v2.0/token\n" "idp_userinfo_endpoint = https://graph.microsoft.com/v1.0/me\n" "idp_device_auth_endpoint = https://login.microsoftonline.com/TENNANT-ID/oauth2/v2.0/devicecode\n" "idp_id_scope = https%3A%2F%2Fgraph.microsoft.com%2F.default\n" +"idp_auth_scope = perfil de correo electrónico openid\n" + +#. type: Content of: <reference><refentry><refsect1><para><programlisting> +#: sssd-idp.5.xml:358 +#, fuzzy, no-wrap +#| msgid "" +#| "[domain/entra_id]\n" +#| "id_provider = idp\n" +#| "idp_type = entra_id\n" +#| "idp_client_id = 12345678-abcd-0101-efef-ba9876543210\n" +#| "idp_client_secret = YOUR-CLIENT-SCERET\n" +#| "idp_token_endpoint = https://login.microsoftonline.com/TENNANT-ID/oauth2/v2.0/token\n" +#| "idp_userinfo_endpoint = https://graph.microsoft.com/v1.0/me\n" +#| "idp_device_auth_endpoint = https://login.microsoftonline.com/TENNANT-ID/oauth2/v2.0/devicecode\n" +#| "idp_id_scope = https%3A%2F%2Fgraph.microsoft.com%2F.default\n" +#| "idp_auth_scope = openid profile email\n" +msgid "" +"[domain/ad.example.com]\n" +"id_provider = ad\n" +"auth_provider = idp\n" +"access_provider = permit\n" +"\n" +"ad_domain = ad.example.com\n" +"krb5_realm = AD.EXAMPLE.COM\n" +"\n" +"idp_type = entra_id\n" +"idp_client_id = 12345678-abcd-0101-efef-ba9876543210\n" +"idp_client_secret = YOUR-CLIENT-SECRET\n" +"idp_token_endpoint = https://login.microsoftonline.com/TENANT-ID/oauth2/v2.0/token\n" +"idp_userinfo_endpoint = https://graph.microsoft.com/v1.0/me?$select=id,userPrincipalName,onPremisesImmutableId\n" +"idp_device_auth_endpoint = https://login.microsoftonline.com/TENANT-ID/oauth2/v2.0/devicecode\n" +"idp_id_scope = https://graph.microsoft.com/.default\n" "idp_auth_scope = openid profile email\n" +"idp_auth_user_identifier_attr = onPremisesImmutableId\n" msgstr "" "[domain/entra_id]\n" "id_provider = idp\n" "idp_type = entra_id\n" "idp_client_id = 12345678-abcd-0101-efef-ba9876543210\n" "idp_client_secret = SU_CLIENTE_SECRETO\n" -"idp_token_endpoint = https://login.microsoftonline.com/TENNANT-ID/oauth2/" -"v2.0/token\n" +"idp_token_endpoint = https://login.microsoftonline.com/TENNANT-ID/oauth2/v2.0/token\n" "idp_userinfo_endpoint = https://graph.microsoft.com/v1.0/me\n" -"idp_device_auth_endpoint = https://login.microsoftonline.com/TENNANT-ID/" -"oauth2/v2.0/devicecode\n" +"idp_device_auth_endpoint = https://login.microsoftonline.com/TENNANT-ID/oauth2/v2.0/devicecode\n" "idp_id_scope = https%3A%2F%2Fgraph.microsoft.com%2F.default\n" "idp_auth_scope = perfil de correo electrónico openid\n" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-idp.5.xml:263 -#, no-wrap +#: sssd-idp.5.xml:377 +#, fuzzy, no-wrap +#| msgid "" +#| "[domain/keycloak]\n" +#| "idp_type = keycloak:https://master.keycloak.test:8443/auth/admin/realms/master/\n" +#| "id_provider = idp\n" +#| "idp_client_id = myclient\n" +#| "idp_client_secret = YOUR-CLIENT-SCERET\n" +#| "idp_token_endpoint = https://master.keycloak.test:8443/auth/realms/master/protocol/openid-connect/token\n" +#| "idp_userinfo_endpoint = https://master.keycloak.test:8443/auth/realms/master/protocol/openid-connect/userinfo\n" +#| "idp_device_auth_endpoint = https://master.keycloak.test:8443/auth/realms/master/protocol/openid-connect/auth/device\n" +#| "idp_id_scope = profile\n" +#| "idp_auth_scope = openid profile email\n" msgid "" "[domain/keycloak]\n" "idp_type = keycloak:https://master.keycloak.test:8443/auth/admin/realms/master/\n" "id_provider = idp\n" "idp_client_id = myclient\n" -"idp_client_secret = YOUR-CLIENT-SCERET\n" +"idp_client_secret = YOUR-CLIENT-SECRET\n" "idp_token_endpoint = https://master.keycloak.test:8443/auth/realms/master/protocol/openid-connect/token\n" "idp_userinfo_endpoint = https://master.keycloak.test:8443/auth/realms/master/protocol/openid-connect/userinfo\n" "idp_device_auth_endpoint = https://master.keycloak.test:8443/auth/realms/master/protocol/openid-connect/auth/device\n" @@ -15883,29 +16599,41 @@ msgid "" "idp_auth_scope = openid profile email\n" msgstr "" "[domain/keycloak]\n" -"idp_type = keycloak:https://master.keycloak.test:8443/auth/admin/realms/" -"master/\n" +"idp_type = keycloak:https://master.keycloak.test:8443/auth/admin/realms/master/\n" "id_provider = idp\n" "idp_client_id = myclient\n" "idp_client_secret = SU-CLIENTE-SECRETO\n" -"idp_token_endpoint = https://master.keycloak.test:8443/auth/realms/master/" -"protocol/openid-connect/token\n" -"idp_userinfo_endpoint = https://master.keycloak.test:8443/auth/realms/master/" -"protocol/openid-connect/userinfo\n" -"idp_device_auth_endpoint = https://master.keycloak.test:8443/auth/realms/" -"master/protocol/openid-connect/auth/device\n" +"idp_token_endpoint = https://master.keycloak.test:8443/auth/realms/master/protocol/openid-connect/token\n" +"idp_userinfo_endpoint = https://master.keycloak.test:8443/auth/realms/master/protocol/openid-connect/userinfo\n" +"idp_device_auth_endpoint = https://master.keycloak.test:8443/auth/realms/master/protocol/openid-connect/auth/device\n" "idp_id_scope = perfil\n" "idp_auth_scope = perfil correo-e openid\n" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-idp.5.xml:250 +#: sssd-idp.5.xml:345 +#, fuzzy +#| msgid "" +#| "<placeholder type=\"programlisting\" id=\"0\"/> <placeholder " +#| "type=\"programlisting\" id=\"1\"/>" msgid "" "<placeholder type=\"programlisting\" id=\"0\"/> <placeholder " -"type=\"programlisting\" id=\"1\"/>" +"type=\"programlisting\" id=\"1\"/> <placeholder type=\"programlisting\" " +"id=\"2\"/>" msgstr "" "<placeholder type=\"programlisting\" id=\"0\"/> <placeholder " "type=\"programlisting\" id=\"1\"/>" +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-idp.5.xml:390 +msgid "" +"In the hybrid Active Directory and Entra ID example above, " +"<quote>onPremisesImmutableId</quote> is used during authentication so the " +"IdP result matches the AD objectGUID UUID stored in the SSSD cache. The " +"attribute must be requested via <quote>$select</quote> on the Graph userinfo " +"endpoint and is only populated for users synchronized from Active Directory " +"with objectGUID as the sourceAnchor." +msgstr "" + #. type: Content of: <reference><refentry><refnamediv><refname> #: sssd.8.xml:10 sssd.8.xml:15 msgid "sssd" @@ -15914,7 +16642,7 @@ msgstr "sssd" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sssd.8.xml:16 msgid "System Security Services Daemon" -msgstr "Dæmon de Servicios de Seguridad del Sistema (SSSD)" +msgstr "Dæmon de Servicios de Seguridad del Sistema" #. type: Content of: <reference><refentry><refsynopsisdiv><cmdsynopsis> #: sssd.8.xml:21 @@ -17096,9 +17824,13 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:291 +#, fuzzy +#| msgid "" +#| "<emphasis>demand</emphasis> to use FAST. The authentication fails if the " +#| "server does not require fast." msgid "" "<emphasis>demand</emphasis> to use FAST. The authentication fails if the " -"server does not require fast." +"server does not support FAST." msgstr "" "<emphasis>demanda</emphasis> para utilizar FAST. La autenticación falla si " "el servidor no requiere rapidez." @@ -18072,7 +18804,7 @@ msgid "" "<manvolnum>3</manvolnum> </citerefentry> and includes: <placeholder " "type=\"variablelist\" id=\"0\"/>" msgstr "" -"De forma predeterminada, el contestador de InfoPipe del interfaz `/User` " +"De forma predeterminada, el contestador de InfoPipe del interfaz `/Users` " "solo concede el conjunto predeterminado de atributos POSIX. Este conjunto es " "el mismo que devuelve <citerefentry> <refentrytitle>getpwnam</refentrytitle> " "<manvolnum>3</manvolnum> </citerefentry> e incluye: <placeholder " @@ -18215,7 +18947,9 @@ msgstr "Atributos de configuración" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sss_rpcidmapd.5.xml:69 -msgid "memcache (bool)" +#, fuzzy +#| msgid "memcache (bool)" +msgid "memcache (boolean)" msgstr "memcache (bool)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> @@ -18288,7 +19022,7 @@ msgstr "" "complemento sss. <placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <refsect1><title> -#: sss_rpcidmapd.5.xml:120 sssd-kcm.8.xml:316 include/seealso.xml:2 +#: sss_rpcidmapd.5.xml:120 sssd-kcm.8.xml:315 include/seealso.xml:2 msgid "SEE ALSO" msgstr "CONSULTE ADEMÁS" @@ -18554,8 +19288,8 @@ msgstr "" "<citerefentry><refentrytitle>ssh</refentrytitle> <manvolnum>1</manvolnum></" "citerefentry> puede ser configurado para usar <command>sss_ssh_knownhosts</" "command> para autenticación de la clave del host usando la opción <quote>" -"KnownHostsCommand</quote>: <placeholder type=\"programlisting\" id=\"0\"/>" -"Refuera a la página man <citerefentry><refentrytitle>ssh_config</" +"KnownHostsCommand</quote>: <placeholder type=\"programlisting\" id=\"0\"/> " +"Refiérase a la página man <citerefentry><refentrytitle>ssh_config</" "refentrytitle><manvolnum>5</manvolnum></citerefentry> para más detalles " "sobre esta opción." @@ -18598,10 +19332,21 @@ msgstr "OBTENCIÓN DE CLAVE" #. type: Content of: <reference><refentry><refsect1><para> #: sss_ssh_knownhosts.1.xml:93 +#, fuzzy +#| msgid "" +#| "The key lines retrieved from the backend are expected to respect the key " +#| "format as decribed in the <quote>SSH_KNOWN_HOSTS FILE FORMAT</quote> " +#| "section of <citerefentry><refentrytitle>sshd</refentrytitle> " +#| "<manvolnum>8</manvolnum></citerefentry>. However, returning only the " +#| "keytype and the key itself is tolerated, in which case, the hostname " +#| "received as parameter will be added before the keytype to output a " +#| "correctly formatted line. The hostname will be added unmodified or just " +#| "the hostname (no port number), depending on whether the <option>-o</" +#| "option>,<option>--only-host-name</option> option was provided." msgid "" "The key lines retrieved from the backend are expected to respect the key " -"format as decribed in the <quote>SSH_KNOWN_HOSTS FILE FORMAT</quote> section " -"of <citerefentry><refentrytitle>sshd</refentrytitle> <manvolnum>8</" +"format as described in the <quote>SSH_KNOWN_HOSTS FILE FORMAT</quote> " +"section of <citerefentry><refentrytitle>sshd</refentrytitle> <manvolnum>8</" "manvolnum></citerefentry>. However, returning only the keytype and the key " "itself is tolerated, in which case, the hostname received as parameter will " "be added before the keytype to output a correctly formatted line. The " @@ -19267,19 +20012,25 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-kcm.8.xml:215 +#, fuzzy +#| msgid "" +#| "The KCM service is configured in the <quote>kcm</quote> For a detailed " +#| "syntax reference, refer to the <quote>FILE FORMAT</quote> section of the " +#| "<citerefentry> <refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</" +#| "manvolnum> </citerefentry> manual page." msgid "" -"The KCM service is configured in the <quote>kcm</quote> For a detailed " -"syntax reference, refer to the <quote>FILE FORMAT</quote> section of the " -"<citerefentry> <refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</" -"manvolnum> </citerefentry> manual page." +"For a detailed syntax reference, refer to the <quote>FILE FORMAT</quote> " +"section of the <citerefentry> <refentrytitle>sssd.conf</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry> manual page." msgstr "" "El servicio KCM se configura en <quote>kcm</quote>. Para obtener una " "referencia de sintaxis detallada, consulte la sección <quote>FORMATO DE " -"ARCHIVO</quote> de la página del manual <citerefentry> <refentrytitle>" -"sssd.conf</refentrytitle> <manvolnum>5</manvolnum> </citerefentry>." +"ARCHIVO</quote> de la página del manual <citerefentry> " +"<refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</manvolnum> </" +"citerefentry>." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-kcm.8.xml:223 +#: sssd-kcm.8.xml:222 msgid "" "The generic SSSD service options such as <quote>debug_level</quote> or " "<quote>fd_limit</quote> are accepted by the kcm service. Please refer to " @@ -19294,23 +20045,23 @@ msgstr "" "algunas opciones específicas de KCM." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:234 +#: sssd-kcm.8.xml:233 msgid "socket_path (string)" msgstr "socket_path (string)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:237 +#: sssd-kcm.8.xml:236 msgid "The socket the KCM service will listen on." msgstr "El zócalo en el que escuchará el servicio KCM." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:240 +#: sssd-kcm.8.xml:239 msgid "Default: <replaceable>/var/run/.heim_org.h5l.kcm-socket</replaceable>" msgstr "" "Por defecto: <replaceable>/var/run/.heim_org.h5l.kcm-socket</replaceable>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:243 +#: sssd-kcm.8.xml:242 msgid "" "<phrase condition=\"have_systemd\"> Note: on platforms where systemd is " "supported, the socket path is overwritten by the one defined in the sssd-" @@ -19321,29 +20072,29 @@ msgstr "" "unidad sssd-kcm.socket. </phrase>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:252 +#: sssd-kcm.8.xml:251 msgid "max_ccaches (integer)" msgstr "max_ccaches (integer)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:255 +#: sssd-kcm.8.xml:254 msgid "How many credential caches does the KCM database allow for all users." msgstr "" "Cuantas credenciales de caché permite la base de datos de KCM para todos los " "usuarios." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:259 +#: sssd-kcm.8.xml:258 msgid "Default: 0 (unlimited, only the per-UID quota is enforced)" msgstr "Predeterminado: 0 (ilimitado, solo se aplica la cuota por UID)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:264 +#: sssd-kcm.8.xml:263 msgid "max_uid_ccaches (integer)" msgstr "max_uid_ccaches (integer)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:267 +#: sssd-kcm.8.xml:266 msgid "" "How many credential caches does the KCM database allow per UID. This is " "equivalent to <quote>with how many principals you can kinit</quote>." @@ -19352,62 +20103,68 @@ msgstr "" "Esto equivale a <quote>con cuántos principales se puede kinit</quote>." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:272 +#: sssd-kcm.8.xml:271 msgid "Default: 64" msgstr "Predeterminado: 64" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:277 +#: sssd-kcm.8.xml:276 msgid "max_ccache_size (integer)" msgstr "max_ccache_size (integer)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:280 +#: sssd-kcm.8.xml:279 +#, fuzzy +#| msgid "" +#| "How big can a credential cache be per ccache. Each service ticket " +#| "accounts into this quota." msgid "" -"How big can a credential cache be per ccache. Each service ticket accounts " -"into this quota." +"How big a credential cache be per ccache. Each service ticket counts toward " +"this quota." msgstr "" "Qué tamaño puede tener una caché de credenciales por caché. Cada ticket de " "servicio se incluye en esta cuota." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:284 +#: sssd-kcm.8.xml:283 msgid "Default: 65536" msgstr "Predeterminado: 65.536" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:289 -msgid "tgt_renewal (bool)" +#: sssd-kcm.8.xml:288 +#, fuzzy +#| msgid "tgt_renewal (bool)" +msgid "tgt_renewal (boolean)" msgstr "tgt_renewal (bool)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:292 +#: sssd-kcm.8.xml:291 msgid "Enables TGT renewals functionality." msgstr "Habilita la funcionalidad de renovaciones de TGT." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:295 +#: sssd-kcm.8.xml:294 msgid "Default: False (Automatic renewals disabled)" msgstr "Predeterminado: False (Renovaciones automáticas deshabilitadas)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:300 +#: sssd-kcm.8.xml:299 msgid "tgt_renewal_inherit (string)" msgstr "tgt_renewal_inherit (string)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:303 +#: sssd-kcm.8.xml:302 msgid "Domain to inherit krb5_* options from, for use with TGT renewals." msgstr "" "Dominio del cual heredar las opciones krb5_*, para usar con renovaciones TGT." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:307 +#: sssd-kcm.8.xml:306 msgid "Default: NULL" msgstr "Predeterminado: NULL" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-kcm.8.xml:318 +#: sssd-kcm.8.xml:317 msgid "" "<citerefentry> <refentrytitle>sssd</refentrytitle><manvolnum>8</manvolnum> </" "citerefentry>, <citerefentry> <refentrytitle>sssd.conf</" @@ -20445,9 +21202,11 @@ msgstr "" "acceso está permitido o no." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap-attributes.5.xml:381 sssd-ldap-attributes.5.xml:395 -msgid "Default: loginDisabled" -msgstr "Predeterminado: loginDisabled" +#: sssd-ldap-attributes.5.xml:381 +#, fuzzy +#| msgid "Default: uid (rfc2307, rfc2307bis and IPA), sAMAccountName (AD)" +msgid "Default: loginDisabled (rfc2307, rfc2307bis and IPA), not set (AD)" +msgstr "Predeterminado: uid (rfc2307, rfc2307bis e IPA), sAMAccountName (AD)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:387 @@ -20463,6 +21222,14 @@ msgstr "" "Cuando se usa ldap_account_expire_policy=nds, este atributo determina hasta " "que fecha se concede el acceso." +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:395 +#, fuzzy +#| msgid "Default: cn (rfc2307, rfc2307bis and IPA), sAMAccountName (AD)" +msgid "" +"Default: loginExpirationTime (rfc2307, rfc2307bis and IPA), not set (AD)" +msgstr "Predeterminado: cn (rfc2307, rfc2307bis and IPA), sAMAccountName (AD)" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:401 msgid "ldap_user_nds_login_allowed_time_map (string)" @@ -20479,8 +21246,11 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:409 -msgid "Default: loginAllowedTimeMap" -msgstr "Predeterminado: loginAllowedTimeMap" +#, fuzzy +#| msgid "Default: uid (rfc2307, rfc2307bis and IPA), sAMAccountName (AD)" +msgid "" +"Default: loginAllowedTimeMap (rfc2307, rfc2307bis and IPA), not set (AD)" +msgstr "Predeterminado: uid (rfc2307, rfc2307bis e IPA), sAMAccountName (AD)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:415 @@ -21073,9 +21843,9 @@ msgid "The object class of a host entry in LDAP." msgstr "La clase de objeto de una entrada de host en LDAP." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap-attributes.5.xml:900 sssd-ldap-attributes.5.xml:997 -msgid "Default: ipService" -msgstr "Por defecto: ipService" +#: sssd-ldap-attributes.5.xml:900 sssd-ldap-attributes.5.xml:1213 +msgid "Default: ipHost" +msgstr "Predeterminado: ipHost" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:906 @@ -21161,6 +21931,11 @@ msgstr "ldap_service_object_class (cadena)" msgid "The object class of a service entry in LDAP." msgstr "La clase objeto de una entrada de servicio en LDAP." +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:997 +msgid "Default: ipService" +msgstr "Por defecto: ipService" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1003 msgid "ldap_service_name (string)" @@ -21415,11 +22190,6 @@ msgstr "ldap_iphost_object_class (cadena)" msgid "The object class of an iphost entry in LDAP." msgstr "La clase del objeto de un apunte iphost en LDAP." -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap-attributes.5.xml:1213 -msgid "Default: ipHost" -msgstr "Predeterminado: ipHost" - #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1219 msgid "ldap_iphost_name (string)" @@ -21654,10 +22424,16 @@ msgstr "CONFIGURACIÓN" #. type: Content of: <reference><refentry><refsect1><para><programlisting> #: sssd_krb5_localauth_plugin.8.xml:56 -#, no-wrap +#, fuzzy, no-wrap +#| msgid "" +#| "[plugins]\n" +#| " localauth = {\n" +#| " module = sssd:/usr/lib64/sssd/modules/sssd_krb5_localauth_plugin.so\n" +#| " }\n" msgid "" "[plugins]\n" " localauth = {\n" +" disable = an2ln\n" " module = sssd:/usr/lib64/sssd/modules/sssd_krb5_localauth_plugin.so\n" " }\n" msgstr "" @@ -21686,6 +22462,28 @@ msgstr "" "este directorio está incluido en la configuración local de Kerberos, el " "complemento se habilitará automáticamente." +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_localauth_plugin.8.xml:67 +msgid "" +"This configuration snippet also disables the <command>an2ln</command> module " +"provided by MIT Kerberos if SSSD is configured to use the AD or IPA " +"provider. In those environments <command>sssd_krb5_localauth_plugin</" +"command> can reliably map the system user names to Kerberos principals. A " +"fallback to <command>an2ln</command> might cause issues in environments " +"where users have the privilege to create Kerberos principals on their own " +"which might collide with names of other users used in the system. Other " +"modules provided by MIT Kerberos, e.g. <command>k5login</command> are not " +"affected." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_localauth_plugin.8.xml:79 +msgid "" +"Note: If using <quote>auth_provider = krb5</quote> then " +"<command>sssd_krb5_localauth_plugin</command> is not used, therefore the " +"above text is not applicable." +msgstr "" + #. type: Content of: <variablelist><varlistentry><term> #: include/autofs_attributes.xml:3 msgid "ldap_autofs_map_object_class (string)" @@ -22817,40 +23615,6 @@ msgstr "" "<emphasis>Predeterminado</emphasis>: 0x0070 (es decir, fallas fatales, " "críticas y graves; corresponde a la configuración 2 en notación decimal)" -#. type: Content of: <refsect1><title> -#: include/local.xml:2 -msgid "THE LOCAL DOMAIN" -msgstr "EL DOMINIO LOCAL" - -#. type: Content of: <refsect1><para> -#: include/local.xml:4 -msgid "" -"In order to function correctly, a domain with <quote>id_provider=local</" -"quote> must be created and the SSSD must be running." -msgstr "" -"Con el objetivo de que funcione correctamente, se debe crear un dominio con " -"<quote>id_provider=local</quote> y el SSSD debe estar corriendo." - -#. type: Content of: <refsect1><para> -#: include/local.xml:9 -msgid "" -"The administrator might want to use the SSSD local users instead of " -"traditional UNIX users in cases where the group nesting (see <citerefentry> " -"<refentrytitle>sss_groupadd</refentrytitle> <manvolnum>8</manvolnum> </" -"citerefentry>) is needed. The local users are also useful for testing and " -"development of the SSSD without having to deploy a full remote server. The " -"<command>sss_user*</command> and <command>sss_group*</command> tools use a " -"local LDB storage to store users and groups." -msgstr "" -"El administrador puede desear usar los usuarios locales SSSD en lugar de los " -"usuarios tradicionales UNIX en los casos donde los grupos anidados (vea " -"<citerefentry> <refentrytitle>sss_groupadd</refentrytitle> <manvolnum>8</" -"manvolnum> </citerefentry>) sean necesarios. Los usuarios locales son " -"también útiles para la prueba y el desarrollo del SSSD sin tener que " -"desplegar un servidor remoto completo. Las herramientas <command>sss_user*</" -"command> y <command>sss_group*</command> usan un almacenamiento LDB local " -"para almacenar usuarios y grupos." - #. type: Content of: <refsect1><para> #: include/seealso.xml:4 msgid "" @@ -23590,6 +24354,119 @@ msgstr "" "Especifique si el host y el usuario principal estarían canonicados. Esta " "característica está disponible con MIT Kerberos 1.7 y versiones posteriores." +#~ msgid "" +#~ "The data types used are string (no quotes needed), integer and bool (with " +#~ "values of <quote>TRUE/FALSE</quote>)." +#~ msgstr "" +#~ "Los tipos de datos utilizados son cadenas (no es necesario " +#~ "entrecomillado), enteros o booleanos (cuyos valores son <quote>TRUE/" +#~ "FALSE</quote>)." + +#~ msgid "services" +#~ msgstr "servicios" + +#~ msgid "domains" +#~ msgstr "dominios" + +#~ msgid "fd_limit" +#~ msgstr "fd_limit" + +#~ msgid "client_idle_timeout" +#~ msgstr "client_idle_timeout" + +#~ msgid "default_shell" +#~ msgstr "default_shell" + +#~ msgid "" +#~ "Note: This option can also be set per-domain which overwrites the value " +#~ "in [nss] section." +#~ msgstr "" +#~ "Nota: esta opción puede ser también fijada por dominio lo cual " +#~ "sobrescribe el valor en la sección [nss]." + +#~ msgid "These options can be used to configure session recording." +#~ msgstr "" +#~ "Se pueden usar estas opciones para configurar la grabación de sesión." + +#~ msgid "entry_cache_computer_timeout (integer)" +#~ msgstr "entry_cache_computer_timeout (entero)" + +#~ msgid "" +#~ "How many seconds to keep the local computer entry before asking the " +#~ "backend again" +#~ msgstr "" +#~ "Cuantos segundos mantener el apunte de computador local antes que el " +#~ "segundo plano de nuevo" + +#~ msgid "" +#~ "Default: <quote>id_provider</quote> is used if it is set and can handle " +#~ "selinux loading requests." +#~ msgstr "" +#~ "Por defecto: <quote>id_provider</quote> se usa si está fijado y puede " +#~ "manejar las peticiones de carga selinux." + +#~ msgid "" +#~ "Please see the section <quote>FAILOVER</quote> for more information about " +#~ "the service resolution." +#~ msgstr "" +#~ "Por favor vea la sección <quote>RECUPERACIÓN DE FALLOS</quote> para más " +#~ "información sobre la resolución del servicio." + +#~ msgid "" +#~ "NOTE: On older systems (such as RHEL 5), for this behavior to work " +#~ "reliably, the default Kerberos realm must be set properly in /etc/" +#~ "krb5.conf" +#~ msgstr "" +#~ "NOTA: en sistemas más antiguos (como RHEL 5), para que este " +#~ "comportamiento trabaje fiablemente, el reino por defecto Kerberos debe " +#~ "ser fijado apropiadamente en /etc/krb5.conf" + +#~ msgid "ipa_hbac_selinux (integer)" +#~ msgstr "ipa_hbac_selinux (entero)" + +#~ msgid "" +#~ "NOTE: While it is still possible to use the old " +#~ "<emphasis>ipa_dyndns_iface</emphasis> option, users should migrate to " +#~ "using <emphasis>dyndns_iface</emphasis> in their config file." +#~ msgstr "" +#~ "NOTA: aunque todavía es posible usar la opción anterior " +#~ "<emphasis>ipa_dyndns_iface</emphasis>, los usuarios deberían migrar " +#~ "usando <emphasis>dyndns_iface</emphasis> en su archivo de configuración." + +#~ msgid "Default: loginDisabled" +#~ msgstr "Predeterminado: loginDisabled" + +#~ msgid "Default: loginAllowedTimeMap" +#~ msgstr "Predeterminado: loginAllowedTimeMap" + +#~ msgid "THE LOCAL DOMAIN" +#~ msgstr "EL DOMINIO LOCAL" + +#~ msgid "" +#~ "In order to function correctly, a domain with <quote>id_provider=local</" +#~ "quote> must be created and the SSSD must be running." +#~ msgstr "" +#~ "Con el objetivo de que funcione correctamente, se debe crear un dominio " +#~ "con <quote>id_provider=local</quote> y el SSSD debe estar corriendo." + +#~ msgid "" +#~ "The administrator might want to use the SSSD local users instead of " +#~ "traditional UNIX users in cases where the group nesting (see " +#~ "<citerefentry> <refentrytitle>sss_groupadd</refentrytitle> <manvolnum>8</" +#~ "manvolnum> </citerefentry>) is needed. The local users are also useful " +#~ "for testing and development of the SSSD without having to deploy a full " +#~ "remote server. The <command>sss_user*</command> and <command>sss_group*</" +#~ "command> tools use a local LDB storage to store users and groups." +#~ msgstr "" +#~ "El administrador puede desear usar los usuarios locales SSSD en lugar de " +#~ "los usuarios tradicionales UNIX en los casos donde los grupos anidados " +#~ "(vea <citerefentry> <refentrytitle>sss_groupadd</refentrytitle> " +#~ "<manvolnum>8</manvolnum> </citerefentry>) sean necesarios. Los usuarios " +#~ "locales son también útiles para la prueba y el desarrollo del SSSD sin " +#~ "tener que desplegar un servidor remoto completo. Las herramientas " +#~ "<command>sss_user*</command> y <command>sss_group*</command> usan un " +#~ "almacenamiento LDB local para almacenar usuarios y grupos." + #~ msgid "subdomain_enumerate (string)" #~ msgstr "subdomain_enumerate (cadena)" @@ -24212,9 +25089,6 @@ msgstr "" #~ "usuarios y grupos en la base de datos SSSD nativa, es decir, un dominio " #~ "que utiliza <replaceable>id_provider=local</replaceable>." -#~ msgid "default_shell (string)" -#~ msgstr "default_shell (cadena)" - #~ msgid "The default shell for users created with SSSD userspace tools." #~ msgstr "" #~ "El shell predeterminado para los usuarios creados con herramientas de " diff --git a/src/man/po/eu.po b/src/man/po/eu.po index fb5cf0c294d..745a011c9b4 100644 --- a/src/man/po/eu.po +++ b/src/man/po/eu.po @@ -7,8 +7,8 @@ msgid "" msgstr "" "Project-Id-Version: sssd-docs 2.3.0\n" "Report-Msgid-Bugs-To: sssd-devel@redhat.com\n" -"POT-Creation-Date: 2026-01-14 15:00+0000\n" -"PO-Revision-Date: 2026-04-23 16:46+0000\n" +"POT-Creation-Date: 2026-10-05 16:14+0000\n" +"PO-Revision-Date: 2026-10-05 16:53+0000\n" "Last-Translator: Anonymous <noreply@weblate.org>\n" "Language-Team: Basque <https://translate.fedoraproject.org/projects/sssd/" "sssd-manpage-master/eu/>\n" @@ -17,10 +17,10 @@ msgstr "" "Content-Type: text/plain; charset=UTF-8\n" "Content-Transfer-Encoding: 8bit\n" "Plural-Forms: nplurals=2; plural=n != 1;\n" -"X-Generator: Weblate 5.17\n" +"X-Generator: Weblate 2026.10\n" #. type: Content of: <reference><title> -#: sssd.conf.5.xml:8 sssd-ldap.5.xml:5 pam_sss.8.xml:5 pam_sss_gss.8.xml:5 +#: sssd.conf.5.xml:10 sssd-ldap.5.xml:5 pam_sss.8.xml:5 pam_sss_gss.8.xml:5 #: sssd_krb5_locator_plugin.8.xml:5 sssd-simple.5.xml:5 sss-certmap.5.xml:5 #: sssd-ipa.5.xml:5 sssd-ad.5.xml:5 sssd-sudo.5.xml:5 sssd-idp.5.xml:5 #: sssd.8.xml:5 sss_obfuscate.8.xml:5 sss_override.8.xml:5 sssd-krb5.5.xml:5 @@ -33,12 +33,12 @@ msgid "SSSD Manual pages" msgstr "" #. type: Content of: <reference><refentry><refnamediv><refname> -#: sssd.conf.5.xml:13 sssd.conf.5.xml:19 +#: sssd.conf.5.xml:15 sssd.conf.5.xml:21 msgid "sssd.conf" msgstr "" #. type: Content of: <reference><refentry><refmeta><manvolnum> -#: sssd.conf.5.xml:14 sssd-ldap.5.xml:11 sssd-simple.5.xml:11 +#: sssd.conf.5.xml:16 sssd-ldap.5.xml:11 sssd-simple.5.xml:11 #: sss-certmap.5.xml:11 sssd-ipa.5.xml:11 sssd-ad.5.xml:11 sssd-sudo.5.xml:11 #: sssd-idp.5.xml:11 sssd-krb5.5.xml:11 sssd-ifp.5.xml:11 #: sss_rpcidmapd.5.xml:27 sssd-session-recording.5.xml:11 @@ -47,7 +47,7 @@ msgid "5" msgstr "" #. type: Content of: <reference><refentry><refmeta><refmiscinfo> -#: sssd.conf.5.xml:15 sssd-ldap.5.xml:12 sssd-simple.5.xml:12 +#: sssd.conf.5.xml:17 sssd-ldap.5.xml:12 sssd-simple.5.xml:12 #: sss-certmap.5.xml:12 sssd-ipa.5.xml:12 sssd-ad.5.xml:12 sssd-sudo.5.xml:12 #: sssd-idp.5.xml:12 sssd-krb5.5.xml:12 sssd-ifp.5.xml:12 #: sss_rpcidmapd.5.xml:28 sssd-session-recording.5.xml:12 sssd-kcm.8.xml:12 @@ -56,17 +56,17 @@ msgid "File Formats and Conventions" msgstr "" #. type: Content of: <reference><refentry><refnamediv><refpurpose> -#: sssd.conf.5.xml:20 +#: sssd.conf.5.xml:22 msgid "the configuration file for SSSD" msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:24 +#: sssd.conf.5.xml:26 msgid "FILE FORMAT" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd.conf.5.xml:32 +#: sssd.conf.5.xml:34 #, no-wrap msgid "" "<replaceable>[section]</replaceable>\n" @@ -76,7 +76,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:27 +#: sssd.conf.5.xml:29 msgid "" "The file has an ini-style syntax and consists of sections and parameters. A " "section begins with the name of the section in square brackets and continues " @@ -85,47 +85,50 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:39 +#: sssd.conf.5.xml:41 msgid "" -"The data types used are string (no quotes needed), integer and bool (with " -"values of <quote>TRUE/FALSE</quote>)." +"The data types used are string (no quotes needed), integer and boolean (with " +"values of <quote>TRUE/FALSE</quote>). Boolean values are case-insensitive; " +"for example, <quote>TRUE</quote>, <quote>True</quote> and <quote>true</" +"quote> are all equivalent and valid; the same applies to <quote>FALSE</" +"quote>." msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:44 +#: sssd.conf.5.xml:49 msgid "" "A comment line starts with a hash sign (<quote>#</quote>) or a semicolon " "(<quote>;</quote>). Inline comments are not supported." msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:50 +#: sssd.conf.5.xml:55 msgid "" "All sections can have an optional <replaceable>description</replaceable> " "parameter. Its function is only as a label for the section." msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:56 +#: sssd.conf.5.xml:61 msgid "" "<filename>sssd.conf</filename> must be a regular file that is owned, " "readable, and writeable only by 'root'." msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:60 +#: sssd.conf.5.xml:65 msgid "" "<filename>sssd.conf</filename> must be a regular file that is accessible " "only by the user used to run SSSD service or root." msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:66 +#: sssd.conf.5.xml:71 msgid "CONFIGURATION SNIPPETS FROM INCLUDE DIRECTORY" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:69 +#: sssd.conf.5.xml:74 msgid "" "The configuration file <filename>sssd.conf</filename> will include " "configuration snippets using the include directory <filename>conf.d</" @@ -133,7 +136,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:75 +#: sssd.conf.5.xml:80 msgid "" "Any file placed in <filename>conf.d</filename> that ends in " "<quote><filename>.conf</filename></quote> and does not begin with a dot " @@ -142,7 +145,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:83 +#: sssd.conf.5.xml:88 msgid "" "The configuration snippets from <filename>conf.d</filename> have higher " "priority than <filename>sssd.conf</filename> and will override " @@ -155,39 +158,88 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:97 +#: sssd.conf.5.xml:102 msgid "" "The snippet files require the same owner and permissions as " "<filename>sssd.conf</filename>." msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:103 +#: sssd.conf.5.xml:108 +msgid "VENDOR PROVIDED CONFIGURATION" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:111 +msgid "" +"The vendor provided configuration file is installed in " +"<filename>&sssd_vendor_dir;/sssd.conf</filename>, but this file must not be " +"directly edited. It can be completely masked by creating the system specific " +"configuration file <filename>&sssd_conf_dir;/sssd.conf</filename>, or partly " +"overriden by creating config snippets in <filename>&sssd_conf_dir;/conf.d</" +"filename> directory." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><title> +#: sssd.conf.5.xml:120 +msgid "CONFIGURATION FILE HIERARCHY" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:122 +msgid "" +"When sssd reads the configuration it first tries to open the system specific " +"configuration file in <filename>&sssd_conf_dir;/sssd.conf</filename>. If it " +"exists, it is loaded and snippets from <filename>&sssd_conf_dir;/conf.d</" +"filename> are applied. The vendor provided configuration file " +"<filename>&sssd_vendor_dir;/sssd.conf</filename> is completely ignored in " +"this case." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:131 +msgid "" +"If the system specific configuration file <filename>&sssd_conf_dir;/" +"sssd.conf</filename> does not exist, then the vendor configuration file " +"<filename>&sssd_vendor_dir;/sssd.conf</filename> is loaded and snippets from " +"<filename>&sssd_conf_dir;/conf.d</filename> are applied." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd.conf.5.xml:141 msgid "GENERAL OPTIONS" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:105 +#: sssd.conf.5.xml:143 msgid "Following options are usable in more than one configuration sections." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:109 +#: sssd.conf.5.xml:147 msgid "Options usable in all sections" msgstr "" +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:149 +msgid "" +"Note: Below options are ignored in <quote>[session_recording]</quote> " +"section, see <quote>Session recording configuration options</quote> section " +"for more details." +msgstr "" + #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:113 +#: sssd.conf.5.xml:156 msgid "debug_level (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:117 +#: sssd.conf.5.xml:160 msgid "debug (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:120 +#: sssd.conf.5.xml:163 msgid "" "SSSD 1.14 and later also includes the <replaceable>debug</replaceable> alias " "for <replaceable>debug_level</replaceable> as a convenience feature. If both " @@ -196,61 +248,61 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:130 -msgid "debug_timestamps (bool)" +#: sssd.conf.5.xml:173 +msgid "debug_timestamps (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:133 +#: sssd.conf.5.xml:176 msgid "" "Add a timestamp to the debug messages. If journald is enabled for SSSD " "debug logging this option is ignored." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:138 sssd.conf.5.xml:175 sssd.conf.5.xml:337 -#: sssd.conf.5.xml:644 sssd.conf.5.xml:668 sssd.conf.5.xml:875 -#: sssd.conf.5.xml:979 sssd.conf.5.xml:2113 sssd-ldap.5.xml:979 -#: sssd-ldap.5.xml:1134 sssd-ldap.5.xml:1237 sssd-ldap.5.xml:1306 -#: sssd-ldap.5.xml:1714 sssd-ldap.5.xml:1848 sssd-ldap.5.xml:1913 -#: sssd-ipa.5.xml:346 sssd-ad.5.xml:252 sssd-ad.5.xml:367 sssd-ad.5.xml:1180 -#: sssd-ad.5.xml:1382 sssd-krb5.5.xml:358 +#: sssd.conf.5.xml:181 sssd.conf.5.xml:218 sssd.conf.5.xml:380 +#: sssd.conf.5.xml:687 sssd.conf.5.xml:711 sssd.conf.5.xml:827 +#: sssd.conf.5.xml:932 sssd.conf.5.xml:2149 sssd.conf.5.xml:4730 +#: sssd-ldap.5.xml:979 sssd-ldap.5.xml:1134 sssd-ldap.5.xml:1237 +#: sssd-ldap.5.xml:1306 sssd-ldap.5.xml:1714 sssd-ldap.5.xml:1848 +#: sssd-ldap.5.xml:1913 sssd-ipa.5.xml:341 sssd-ad.5.xml:252 sssd-ad.5.xml:367 +#: sssd-ad.5.xml:1180 sssd-ad.5.xml:1375 sssd-krb5.5.xml:358 msgid "Default: true" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:143 -msgid "debug_microseconds (bool)" +#: sssd.conf.5.xml:186 +msgid "debug_microseconds (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:146 +#: sssd.conf.5.xml:189 msgid "" "Add microseconds to the timestamp in debug messages. If journald is enabled " "for SSSD debug logging this option is ignored." msgstr "" #. type: Content of: <variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:151 sssd.conf.5.xml:2040 sssd.conf.5.xml:4158 +#: sssd.conf.5.xml:194 sssd.conf.5.xml:2072 sssd.conf.5.xml:4363 #: sssd-ldap.5.xml:363 sssd-ldap.5.xml:998 sssd-ldap.5.xml:1209 -#: sssd-ldap.5.xml:1663 sssd-ldap.5.xml:1937 sssd-ipa.5.xml:146 -#: sssd-ipa.5.xml:706 sssd-ad.5.xml:1135 sssd-krb5.5.xml:268 +#: sssd-ldap.5.xml:1663 sssd-ldap.5.xml:1937 sssd-ipa.5.xml:141 +#: sssd-ipa.5.xml:701 sssd-ad.5.xml:1140 sssd-idp.5.xml:287 sssd-krb5.5.xml:268 #: sssd-krb5.5.xml:330 sssd-krb5.5.xml:432 include/krb5_options.xml:163 msgid "Default: false" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:156 -msgid "debug_backtrace_enabled (bool)" +#: sssd.conf.5.xml:199 +msgid "debug_backtrace_enabled (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:159 +#: sssd.conf.5.xml:202 msgid "Enable debug backtrace." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:162 +#: sssd.conf.5.xml:205 msgid "" "In case SSSD is run with debug_level less than 9, everything is logged to a " "ring buffer in memory and flushed to a log file on any error up to and " @@ -260,14 +312,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:171 +#: sssd.conf.5.xml:214 msgid "" "Feature is only supported for `logger == files` (i.e. setting doesn't have " "effect for other logger types)." msgstr "" #. type: Content of: outside any tag (error?) -#: sssd.conf.5.xml:111 sssd.conf.5.xml:186 sssd-ldap.5.xml:1754 +#: sssd.conf.5.xml:154 sssd.conf.5.xml:229 sssd-ldap.5.xml:1754 #: sssd-ldap.5.xml:1960 sss-certmap.5.xml:645 sssd-systemtap.5.xml:82 #: sssd-systemtap.5.xml:143 sssd-systemtap.5.xml:236 sssd-systemtap.5.xml:274 #: sssd-systemtap.5.xml:330 sssd-ldap-attributes.5.xml:40 @@ -280,17 +332,17 @@ msgid "<placeholder type=\"variablelist\" id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:184 +#: sssd.conf.5.xml:227 msgid "Options usable in SERVICE and DOMAIN sections" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:188 +#: sssd.conf.5.xml:231 msgid "timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:191 +#: sssd.conf.5.xml:234 msgid "" "Timeout in seconds between heartbeats for this service. This is used to " "ensure that the process is alive and capable of answering requests. Note " @@ -298,34 +350,34 @@ msgid "" msgstr "" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:198 sssd.conf.5.xml:1199 sssd.conf.5.xml:1673 -#: sssd.conf.5.xml:4174 sssd-ldap.5.xml:825 sssd-idp.5.xml:192 +#: sssd.conf.5.xml:241 sssd.conf.5.xml:1155 sssd.conf.5.xml:1665 +#: sssd.conf.5.xml:4379 sssd-ldap.5.xml:825 sssd-idp.5.xml:271 #: include/ldap_id_mapping.xml:270 msgid "Default: 10" msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:208 +#: sssd.conf.5.xml:251 msgid "SPECIAL SECTIONS" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:211 +#: sssd.conf.5.xml:254 msgid "The [sssd] section" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><title> -#: sssd.conf.5.xml:220 +#: sssd.conf.5.xml:263 msgid "Section parameters" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:222 -msgid "services" +#: sssd.conf.5.xml:265 +msgid "services (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:225 +#: sssd.conf.5.xml:268 msgid "" "Comma separated list of services that are started when sssd itself starts. " "<phrase condition=\"have_systemd\"> The services' list is optional on " @@ -334,7 +386,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:234 +#: sssd.conf.5.xml:277 msgid "" "Supported services: nss, pam, ifp <phrase condition=\"with_sudo\">, sudo</" "phrase> <phrase condition=\"with_autofs\">, autofs</phrase> <phrase " @@ -343,20 +395,20 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:241 +#: sssd.conf.5.xml:284 msgid "" "<phrase condition=\"have_systemd\"> By default, all services are disabled " "and the administrator must enable the ones allowed to be used by executing: " "\"systemctl enable sssd-@service@.socket\". </phrase>" msgstr "" -#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:250 -msgid "domains" +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sssd.conf.5.xml:293 sssd.conf.5.xml:4562 +msgid "domains (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:253 +#: sssd.conf.5.xml:296 msgid "" "A domain is a database containing user information. SSSD can use more " "domains at the same time, but at least one must be configured or SSSD won't " @@ -367,19 +419,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:266 sssd.conf.5.xml:3467 +#: sssd.conf.5.xml:309 sssd.conf.5.xml:3598 msgid "re_expression (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:269 +#: sssd.conf.5.xml:312 msgid "" "Default regular expression that describes how to parse the string containing " "user name and domain into these components." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:274 +#: sssd.conf.5.xml:317 msgid "" "Each domain can have an individual regular expression configured. For some " "ID providers there are also default regular expressions. See DOMAIN SECTIONS " @@ -387,12 +439,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:283 sssd.conf.5.xml:3524 +#: sssd.conf.5.xml:326 sssd.conf.5.xml:3655 msgid "full_name_format (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:286 sssd.conf.5.xml:3527 +#: sssd.conf.5.xml:329 sssd.conf.5.xml:3658 msgid "" "A <citerefentry> <refentrytitle>printf</refentrytitle> <manvolnum>3</" "manvolnum> </citerefentry>-compatible format that describes how to compose a " @@ -400,70 +452,70 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:297 sssd.conf.5.xml:3538 +#: sssd.conf.5.xml:340 sssd.conf.5.xml:3669 msgid "%1$s" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:298 sssd.conf.5.xml:3539 +#: sssd.conf.5.xml:341 sssd.conf.5.xml:3670 msgid "user name" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:301 sssd.conf.5.xml:3542 +#: sssd.conf.5.xml:344 sssd.conf.5.xml:3673 msgid "%2$s" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:304 sssd.conf.5.xml:3545 +#: sssd.conf.5.xml:347 sssd.conf.5.xml:3676 msgid "domain name as specified in the SSSD config file." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:310 sssd.conf.5.xml:3551 +#: sssd.conf.5.xml:353 sssd.conf.5.xml:3682 msgid "%3$s" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:313 sssd.conf.5.xml:3554 +#: sssd.conf.5.xml:356 sssd.conf.5.xml:3685 msgid "" "domain flat name. Mostly usable for Active Directory domains, both directly " "configured or discovered via IPA trusts." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:294 sssd.conf.5.xml:3535 +#: sssd.conf.5.xml:337 sssd.conf.5.xml:3666 msgid "" "The following expansions are supported: <placeholder type=\"variablelist\" " "id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:323 +#: sssd.conf.5.xml:366 msgid "" "Each domain can have an individual format string configured. See DOMAIN " "SECTIONS for more info on this option." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:329 +#: sssd.conf.5.xml:372 msgid "monitor_resolv_conf (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:332 +#: sssd.conf.5.xml:375 msgid "" "Controls if SSSD should monitor the state of resolv.conf to identify when it " "needs to update its internal DNS resolver." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:342 +#: sssd.conf.5.xml:385 msgid "try_inotify (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:345 +#: sssd.conf.5.xml:388 msgid "" "By default, SSSD will attempt to use inotify to monitor configuration files " "changes and will fall back to polling every five seconds if inotify cannot " @@ -471,7 +523,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:351 +#: sssd.conf.5.xml:394 msgid "" "There are some limited situations where it is preferred that we should skip " "even trying to use inotify. In these rare cases, this option should be set " @@ -479,59 +531,59 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:357 +#: sssd.conf.5.xml:400 msgid "" "Default: true on platforms where inotify is supported. False on other " "platforms." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:361 +#: sssd.conf.5.xml:404 msgid "" "Note: this option will have no effect on platforms where inotify is " "unavailable. On these platforms, polling will always be used." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:368 +#: sssd.conf.5.xml:411 msgid "krb5_rcache_dir (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:371 +#: sssd.conf.5.xml:414 msgid "" "Directory on the filesystem where SSSD should store Kerberos replay cache " "files." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:375 +#: sssd.conf.5.xml:418 msgid "" "This option accepts a special value __LIBKRB5_DEFAULTS__ that will instruct " "SSSD to let libkrb5 decide the appropriate location for the replay cache." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:381 +#: sssd.conf.5.xml:424 msgid "" "Default: Distribution-specific and specified at build-time. " "(__LIBKRB5_DEFAULTS__ if not configured)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:388 +#: sssd.conf.5.xml:431 msgid "default_domain_suffix (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:391 +#: sssd.conf.5.xml:434 msgid "" "Please note that this option is deprecated and domain_resolution_order " "should be used." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:395 +#: sssd.conf.5.xml:438 msgid "" "This string will be used as a default domain name for all names without a " "domain name component. The main use case is environments where the primary " @@ -541,7 +593,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:405 +#: sssd.conf.5.xml:448 msgid "" "Please note that if this option is set all users from the primary domain " "have to use their fully qualified name, e.g. user@domain.name, to log in. " @@ -551,21 +603,21 @@ msgid "" msgstr "" #. type: Content of: <variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:414 sssd-ldap.5.xml:937 sssd-ldap.5.xml:949 -#: sssd-ldap.5.xml:1042 sssd-ad.5.xml:921 sssd-ad.5.xml:996 sssd-krb5.5.xml:468 -#: sssd-ldap-attributes.5.xml:470 sssd-ldap-attributes.5.xml:978 -#: include/ldap_id_mapping.xml:211 include/ldap_id_mapping.xml:222 -#: include/krb5_options.xml:148 +#: sssd.conf.5.xml:457 sssd.conf.5.xml:2006 sssd-ldap.5.xml:937 +#: sssd-ldap.5.xml:949 sssd-ldap.5.xml:1042 sssd-ad.5.xml:926 +#: sssd-ad.5.xml:1001 sssd-krb5.5.xml:468 sssd-ldap-attributes.5.xml:470 +#: sssd-ldap-attributes.5.xml:978 include/ldap_id_mapping.xml:211 +#: include/ldap_id_mapping.xml:222 include/krb5_options.xml:148 msgid "Default: not set" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:419 +#: sssd.conf.5.xml:462 msgid "override_space (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:422 +#: sssd.conf.5.xml:465 msgid "" "This parameter will replace spaces (space bar) with the given character for " "user and group names. e.g. (_). User name "john doe" will be " @@ -575,7 +627,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:431 +#: sssd.conf.5.xml:474 msgid "" "Please note it is a configuration error to use a replacement character that " "might be used in user or group names. If a name contains the replacement " @@ -584,22 +636,22 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:439 +#: sssd.conf.5.xml:482 msgid "Default: not set (spaces will not be replaced)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:444 +#: sssd.conf.5.xml:487 msgid "certificate_verification (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:452 +#: sssd.conf.5.xml:495 msgid "no_ocsp" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:454 +#: sssd.conf.5.xml:497 msgid "" "Disables Online Certificate Status Protocol (OCSP) checks. This might be " "needed if the OCSP servers defined in the certificate are not reachable from " @@ -607,12 +659,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:462 +#: sssd.conf.5.xml:505 msgid "soft_ocsp" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:464 +#: sssd.conf.5.xml:507 msgid "" "If a connection cannot be established to an OCSP responder the OCSP check is " "skipped. This option should be used to allow authentication when the system " @@ -620,61 +672,61 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:474 +#: sssd.conf.5.xml:517 msgid "ocsp_dgst" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:476 +#: sssd.conf.5.xml:519 msgid "" "Digest (hash) function used to create the certificate ID for the OCSP " "request. Allowed values are:" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:480 +#: sssd.conf.5.xml:523 msgid "sha1" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:481 +#: sssd.conf.5.xml:524 msgid "sha256" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:482 +#: sssd.conf.5.xml:525 msgid "sha384" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:483 +#: sssd.conf.5.xml:526 msgid "sha512" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:486 +#: sssd.conf.5.xml:529 msgid "Default: sha1 (to allow compatibility with RFC5019-compliant responder)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:492 +#: sssd.conf.5.xml:535 msgid "no_verification" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:494 +#: sssd.conf.5.xml:537 msgid "" "Disables verification completely. This option should only be used for " "testing." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:500 +#: sssd.conf.5.xml:543 msgid "partial_chain" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:502 +#: sssd.conf.5.xml:545 msgid "" "Allow verification to succeed even if a <replaceable>complete</replaceable> " "chain cannot be built to a self-signed trust-anchor, provided it is possible " @@ -682,12 +734,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:511 +#: sssd.conf.5.xml:554 msgid "ocsp_default_responder=URL" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:513 +#: sssd.conf.5.xml:556 msgid "" "Sets the OCSP default responder which should be used instead of the one " "mentioned in the certificate. URL must be replaced with the URL of the OCSP " @@ -695,24 +747,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:523 +#: sssd.conf.5.xml:566 msgid "ocsp_default_responder_signing_cert=NAME" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:525 +#: sssd.conf.5.xml:568 msgid "" "This option is currently ignored. All needed certificates must be available " "in the PEM file given by pam_cert_db_path." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:533 +#: sssd.conf.5.xml:576 msgid "crl_file=/PATH/TO/CRL/FILE" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:535 +#: sssd.conf.5.xml:578 msgid "" "Use the Certificate Revocation List (CRL) from the given file during the " "verification of the certificate. The CRL must be given in PEM format, see " @@ -721,12 +773,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:548 +#: sssd.conf.5.xml:591 msgid "soft_crl" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:551 +#: sssd.conf.5.xml:594 msgid "" "If a Certificate Revocation List (CRL) is expired ignore the expiration " "time of the CRL and check the related certificates with the expired CRL. " @@ -735,7 +787,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:447 +#: sssd.conf.5.xml:490 msgid "" "With this parameter the certificate verification can be tuned with a comma " "separated list of options. Supported options are: <placeholder " @@ -743,46 +795,46 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:564 +#: sssd.conf.5.xml:607 msgid "Unknown options are reported but ignored." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:567 +#: sssd.conf.5.xml:610 msgid "Default: not set, i.e. do not restrict certificate verification" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:573 +#: sssd.conf.5.xml:616 msgid "disable_netlink (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:576 +#: sssd.conf.5.xml:619 msgid "" "SSSD hooks into the netlink interface to monitor changes to routes, " "addresses, links and trigger certain actions." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:581 +#: sssd.conf.5.xml:624 msgid "" "The SSSD state changes caused by netlink events may be undesirable and can " "be disabled by setting this option to 'true'" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:586 +#: sssd.conf.5.xml:629 msgid "Default: false (netlink changes are detected)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:591 -msgid "domain_resolution_order" +#: sssd.conf.5.xml:634 +msgid "domain_resolution_order (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:594 +#: sssd.conf.5.xml:637 msgid "" "Comma separated list of domains and subdomains representing the lookup order " "that will be followed. The list doesn't have to include all possible " @@ -793,7 +845,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:606 +#: sssd.conf.5.xml:649 msgid "" "Please, note that when this option is set the output format of all commands " "is always fully-qualified even when using short names for input. In case " @@ -809,19 +861,20 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:630 sssd.conf.5.xml:1697 sssd.conf.5.xml:4224 -#: sssd-ad.5.xml:187 sssd-ad.5.xml:328 sssd-ad.5.xml:342 sssd-idp.5.xml:108 -#: sssd-idp.5.xml:132 sssd-idp.5.xml:145 sssd-idp.5.xml:159 sssd-idp.5.xml:180 +#: sssd.conf.5.xml:673 sssd.conf.5.xml:1026 sssd.conf.5.xml:1689 +#: sssd.conf.5.xml:4429 sssd-ad.5.xml:187 sssd-ad.5.xml:328 sssd-ad.5.xml:342 +#: sssd-idp.5.xml:112 sssd-idp.5.xml:136 sssd-idp.5.xml:149 sssd-idp.5.xml:167 +#: sssd-idp.5.xml:188 msgid "Default: Not set" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:635 +#: sssd.conf.5.xml:678 msgid "implicit_pac_responder (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:638 +#: sssd.conf.5.xml:681 msgid "" "The PAC responder is enabled automatically for the IPA and AD provider to " "evaluate and check the PAC. If it has to be disabled set this option to " @@ -829,12 +882,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:649 +#: sssd.conf.5.xml:692 msgid "core_dumpable (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:652 +#: sssd.conf.5.xml:695 msgid "" "This option can be used for general system hardening: setting it to 'false' " "forbids core dumps for all SSSD processes to avoid leaking plain text " @@ -843,7 +896,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:660 +#: sssd.conf.5.xml:703 msgid "" "Take a note that this setting has no effect for 'ldap_child', 'krb5_child' " "and 'sssd_pam' as those privileged binaries can have a copy of a host keytab " @@ -852,24 +905,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:673 +#: sssd.conf.5.xml:716 msgid "passkey_verification (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:681 +#: sssd.conf.5.xml:724 msgid "user_verification (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:683 +#: sssd.conf.5.xml:726 msgid "" "Enable or disable the user verification (i.e. PIN, fingerprint) during " "authentication. If enabled, the PIN will always be requested." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:689 +#: sssd.conf.5.xml:732 msgid "" "The default is that the key settings decide what to do. In the IPA or " "kerberos pre-authentication case, this value will be overwritten by the " @@ -877,7 +930,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:676 +#: sssd.conf.5.xml:719 msgid "" "With this parameter the passkey verification can be tuned with a comma " "separated list of options. Supported options are: <placeholder " @@ -885,7 +938,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:213 +#: sssd.conf.5.xml:256 msgid "" "Individual pieces of SSSD functionality are provided by special SSSD " "services that are started and stopped together with SSSD. The services are " @@ -896,12 +949,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:708 +#: sssd.conf.5.xml:751 msgid "SERVICES SECTIONS" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:710 +#: sssd.conf.5.xml:753 msgid "" "Settings that can be used to configure different services are described in " "this section. They should reside in the [<replaceable>$NAME</replaceable>] " @@ -910,42 +963,41 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:717 +#: sssd.conf.5.xml:760 msgid "General service configuration options" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:719 +#: sssd.conf.5.xml:762 msgid "These options can be used to configure any service." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:723 -msgid "fd_limit" +#: sssd.conf.5.xml:766 +msgid "fd_limit (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:726 +#: sssd.conf.5.xml:769 msgid "" "This option specifies the maximum number of file descriptors that may be " -"opened at one time by this SSSD process. On systems where SSSD is granted " -"the CAP_SYS_RESOURCE capability, this will be an absolute setting. On " -"systems without this capability, the resulting value will be the lower value " -"of this or the limits.conf \"hard\" limit." +"opened at one time by this SSSD process. Note this value will be capped by " +"the init system at the startup of SSSD, see e.g. man systemd.exec for " +"details." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:735 +#: sssd.conf.5.xml:776 msgid "Default: 8192 (or limits.conf \"hard\" limit)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:740 -msgid "client_idle_timeout" +#: sssd.conf.5.xml:781 +msgid "client_idle_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:743 +#: sssd.conf.5.xml:784 msgid "" "This option specifies the number of seconds that a client of an SSSD process " "can hold onto a file descriptor without communicating on it. This value is " @@ -955,140 +1007,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:752 +#: sssd.conf.5.xml:793 msgid "Default: 60, KCM: 300" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:757 -msgid "offline_timeout (integer)" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:760 -msgid "" -"When SSSD switches to offline mode the amount of time before it tries to go " -"back online will increase based upon the time spent disconnected. By " -"default SSSD uses incremental behaviour to calculate delay in between " -"retries. So, the wait time for a given retry will be longer than the wait " -"time for the previous ones. After each unsuccessful attempt to go online, " -"the new interval is recalculated by the following:" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:771 sssd.conf.5.xml:827 -msgid "" -"new_delay = Minimum(old_delay * 2, offline_timeout_max) + " -"random[0...offline_timeout_random_offset]" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:774 -msgid "" -"The offline_timeout default value is 60. The offline_timeout_max default " -"value is 3600. The offline_timeout_random_offset default value is 30. The " -"end result is amount of seconds before next retry." +#: sssd.conf.5.xml:798 +msgid "responder_idle_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:780 -msgid "" -"Note that the maximum length of each interval is defined by " -"offline_timeout_max (apart of random part)." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:784 sssd.conf.5.xml:1110 sssd.conf.5.xml:1490 -#: sssd.conf.5.xml:1791 sssd-ldap.5.xml:550 -msgid "Default: 60" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:789 -msgid "offline_timeout_max (integer)" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:792 -msgid "" -"Controls by how much the time between attempts to go online can be " -"incremented following unsuccessful attempts to go online." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:797 -msgid "A value of 0 disables the incrementing behaviour." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:800 -msgid "" -"The value of this parameter should be set in correlation to offline_timeout " -"parameter value." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:804 -msgid "" -"With offline_timeout set to 60 (default value) there is no point in setting " -"offlinet_timeout_max to less than 120 as it will saturate instantly. General " -"rule here should be to set offline_timeout_max to at least 4 times " -"offline_timeout." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:810 -msgid "" -"Although a value between 0 and offline_timeout may be specified, it has the " -"effect of overriding the offline_timeout value so is of little use." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:815 -msgid "Default: 3600" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:820 -msgid "offline_timeout_random_offset (integer)" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:823 -msgid "" -"When SSSD is in offline mode it keeps probing backend servers in specified " -"time intervals:" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:830 -msgid "" -"This parameter controls the value of the random offset used for the above " -"equation. Final random_offset value will be random number in range:" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:835 -msgid "[0 - offline_timeout_random_offset]" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:838 -msgid "A value of 0 disables the random offset addition." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:841 -msgid "Default: 30" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:846 -msgid "responder_idle_timeout" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:849 +#: sssd.conf.5.xml:801 msgid "" "This option specifies the number of seconds that an SSSD responder process " "can be up without being used. This value is limited in order to avoid " @@ -1100,58 +1029,59 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:863 sssd.conf.5.xml:1123 sssd.conf.5.xml:2248 +#: sssd.conf.5.xml:815 sssd.conf.5.xml:1079 sssd.conf.5.xml:2285 #: sssd-ldap.5.xml:377 msgid "Default: 300" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:868 -msgid "cache_first" +#: sssd.conf.5.xml:820 +msgid "cache_first (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:871 +#: sssd.conf.5.xml:823 msgid "" "This option specifies whether the responder should query all caches before " "querying the Data Providers." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:883 +#: sssd.conf.5.xml:835 msgid "NSS configuration options" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:885 +#: sssd.conf.5.xml:837 msgid "" -"These options can be used to configure the Name Service Switch (NSS) service." +"These options can be used to configure the Name Service Switch (NSS) service " +"and should be specified under the <quote>[nss]</quote> section." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:890 +#: sssd.conf.5.xml:843 msgid "enum_cache_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:893 +#: sssd.conf.5.xml:846 msgid "" "How many seconds should nss_sss cache enumerations (requests for info about " "all users)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:897 +#: sssd.conf.5.xml:850 msgid "Default: 120" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:902 +#: sssd.conf.5.xml:855 msgid "entry_cache_nowait_percentage (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:905 +#: sssd.conf.5.xml:858 msgid "" "The entry cache can be set to automatically update entries in the background " "if they are requested beyond a percentage of the entry_cache_timeout value " @@ -1159,7 +1089,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:911 +#: sssd.conf.5.xml:864 msgid "" "For example, if the domain's entry_cache_timeout is set to 30s and " "entry_cache_nowait_percentage is set to 50 (percent), entries that come in " @@ -1169,7 +1099,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:921 +#: sssd.conf.5.xml:874 msgid "" "Valid values for this option are 0-99 and represent a percentage of the " "entry_cache_timeout for each domain. For performance reasons, this " @@ -1178,17 +1108,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:929 sssd.conf.5.xml:2061 +#: sssd.conf.5.xml:882 sssd.conf.5.xml:2093 msgid "Default: 50" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:934 +#: sssd.conf.5.xml:887 msgid "entry_negative_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:937 +#: sssd.conf.5.xml:890 msgid "" "Specifies for how many seconds nss_sss should cache negative cache hits " "(that is, queries for invalid database entries, like nonexistent ones) " @@ -1196,17 +1126,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:943 sssd.conf.5.xml:1685 sssd.conf.5.xml:2085 +#: sssd.conf.5.xml:896 sssd.conf.5.xml:1677 sssd.conf.5.xml:2119 msgid "Default: 15" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:948 +#: sssd.conf.5.xml:901 msgid "filter_users, filter_groups (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:951 +#: sssd.conf.5.xml:904 msgid "" "Exclude certain users or groups from being fetched from the sss NSS " "database. This is particularly useful for system accounts. This option can " @@ -1215,7 +1145,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:959 +#: sssd.conf.5.xml:912 msgid "" "NOTE: The filter_groups option doesn't affect inheritance of nested group " "members, since filtering happens after they are propagated for returning via " @@ -1224,41 +1154,41 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:967 +#: sssd.conf.5.xml:920 msgid "Default: root" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:972 -msgid "filter_users_in_groups (bool)" +#: sssd.conf.5.xml:925 +msgid "filter_users_in_groups (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:975 +#: sssd.conf.5.xml:928 msgid "" -"If you want filtered user still be group members set this option to false." +"If you want filtered users to remain group members set this option to false" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:986 +#: sssd.conf.5.xml:939 msgid "fallback_homedir (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:989 +#: sssd.conf.5.xml:942 msgid "" "Set a default template for a user's home directory if one is not specified " "explicitly by the domain's data provider." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:994 +#: sssd.conf.5.xml:947 msgid "" "The available values for this option are the same as for override_homedir." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1000 +#: sssd.conf.5.xml:953 #, no-wrap msgid "" "fallback_homedir = /home/%u\n" @@ -1266,23 +1196,23 @@ msgid "" msgstr "" #. type: Content of: <varlistentry><listitem><para> -#: sssd.conf.5.xml:998 sssd.conf.5.xml:1557 sssd.conf.5.xml:1576 -#: sssd.conf.5.xml:1653 sssd-krb5.5.xml:451 include/override_homedir.xml:78 +#: sssd.conf.5.xml:951 sssd.conf.5.xml:1524 sssd.conf.5.xml:1543 +#: sssd.conf.5.xml:1645 sssd-krb5.5.xml:451 include/override_homedir.xml:78 msgid "example: <placeholder type=\"programlisting\" id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1004 +#: sssd.conf.5.xml:957 msgid "Default: not set (no substitution for unset home directories)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1010 +#: sssd.conf.5.xml:963 msgid "override_shell (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1013 +#: sssd.conf.5.xml:966 msgid "" "Override the login shell for all users. This option supersedes any other " "shell options if it takes effect and can be set either in the [nss] section " @@ -1290,47 +1220,47 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1019 +#: sssd.conf.5.xml:972 msgid "Default: not set (SSSD will use the value retrieved from LDAP)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1025 +#: sssd.conf.5.xml:978 msgid "allowed_shells (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1028 +#: sssd.conf.5.xml:981 msgid "" "Restrict user shell to one of the listed values. The order of evaluation is:" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1031 +#: sssd.conf.5.xml:984 msgid "1. If the shell is present in <quote>/etc/shells</quote>, it is used." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1035 +#: sssd.conf.5.xml:988 msgid "" "2. If the shell is in the allowed_shells list but not in <quote>/etc/shells</" "quote>, use the value of the shell_fallback parameter." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1040 +#: sssd.conf.5.xml:993 msgid "" "3. If the shell is not in the allowed_shells list and not in <quote>/etc/" "shells</quote>, a nologin shell is used." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1045 +#: sssd.conf.5.xml:998 msgid "The wildcard (*) can be used to allow any shell." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1048 +#: sssd.conf.5.xml:1001 msgid "" "The (*) is useful if you want to use shell_fallback in case that user's " "shell is not in <quote>/etc/shells</quote> and maintaining list of all " @@ -1338,113 +1268,119 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1055 +#: sssd.conf.5.xml:1008 msgid "An empty string for shell is passed as-is to libc." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1058 +#: sssd.conf.5.xml:1011 msgid "" "The <quote>/etc/shells</quote> is only read on SSSD start up, which means " "that a restart of the SSSD is required in case a new shell is installed." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1062 +#: sssd.conf.5.xml:1015 msgid "Default: Not set. The user shell is automatically used." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1067 +#: sssd.conf.5.xml:1020 msgid "vetoed_shells (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1070 +#: sssd.conf.5.xml:1023 msgid "Replace any instance of these shells with the shell_fallback" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1075 +#: sssd.conf.5.xml:1031 msgid "shell_fallback (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1078 +#: sssd.conf.5.xml:1034 msgid "" "The default shell to use if an allowed shell is not installed on the machine." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1082 +#: sssd.conf.5.xml:1038 msgid "Default: /bin/sh" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1087 -msgid "default_shell" +#: sssd.conf.5.xml:1043 +msgid "default_shell (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1090 +#: sssd.conf.5.xml:1046 msgid "" "The default shell to use if the provider does not return one during lookup. " "This option can be specified globally in the [nss] section or per-domain." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1096 +#: sssd.conf.5.xml:1052 msgid "" "Default: not set (Return NULL if no shell is specified and rely on libc to " "substitute something sensible when necessary, usually /bin/sh)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1103 sssd.conf.5.xml:1483 +#: sssd.conf.5.xml:1059 sssd.conf.5.xml:1450 msgid "get_domains_timeout (int)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1106 sssd.conf.5.xml:1486 +#: sssd.conf.5.xml:1062 sssd.conf.5.xml:1453 msgid "" "Specifies time in seconds for which the list of subdomains will be " "considered valid." msgstr "" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1066 sssd.conf.5.xml:1457 sssd.conf.5.xml:1788 +#: sssd.conf.5.xml:2862 sssd-ldap.5.xml:550 +msgid "Default: 60" +msgstr "" + #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1115 +#: sssd.conf.5.xml:1071 msgid "memcache_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1118 +#: sssd.conf.5.xml:1074 msgid "" "Specifies time in seconds for which records in the in-memory cache will be " "valid. Setting this option to zero will disable the in-memory cache." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1126 +#: sssd.conf.5.xml:1082 msgid "" "WARNING: Disabling the in-memory cache will have significant negative impact " "on SSSD's performance and should only be used for testing." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1132 sssd.conf.5.xml:1157 sssd.conf.5.xml:1182 -#: sssd.conf.5.xml:1207 sssd.conf.5.xml:1234 +#: sssd.conf.5.xml:1088 sssd.conf.5.xml:1113 sssd.conf.5.xml:1138 +#: sssd.conf.5.xml:1163 sssd.conf.5.xml:1190 msgid "" "NOTE: If the environment variable SSS_NSS_USE_MEMCACHE is set to \"NO\", " "client applications will not use the fast in-memory cache." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1140 +#: sssd.conf.5.xml:1096 msgid "memcache_size_passwd (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1143 +#: sssd.conf.5.xml:1099 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for passwd requests. Setting the size to 0 will disable the passwd in-" @@ -1452,25 +1388,25 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1149 sssd.conf.5.xml:2888 sssd-ldap.5.xml:604 +#: sssd.conf.5.xml:1105 sssd.conf.5.xml:3013 sssd-ldap.5.xml:604 msgid "Default: 8" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1152 sssd.conf.5.xml:1177 sssd.conf.5.xml:1202 -#: sssd.conf.5.xml:1229 +#: sssd.conf.5.xml:1108 sssd.conf.5.xml:1133 sssd.conf.5.xml:1158 +#: sssd.conf.5.xml:1185 msgid "" "WARNING: Disabled or too small in-memory cache can have significant negative " "impact on SSSD's performance." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1165 +#: sssd.conf.5.xml:1121 msgid "memcache_size_group (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1168 +#: sssd.conf.5.xml:1124 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for group requests. Setting the size to 0 will disable the group in-memory " @@ -1478,19 +1414,19 @@ msgid "" msgstr "" #. type: Content of: <variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1174 sssd.conf.5.xml:1226 sssd.conf.5.xml:3656 +#: sssd.conf.5.xml:1130 sssd.conf.5.xml:1182 sssd.conf.5.xml:3835 #: sssd-ldap.5.xml:534 sssd-ldap.5.xml:581 include/failover.xml:116 #: include/krb5_options.xml:11 msgid "Default: 6" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1190 +#: sssd.conf.5.xml:1146 msgid "memcache_size_initgroups (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1193 +#: sssd.conf.5.xml:1149 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for initgroups requests. Setting the size to 0 will disable the initgroups " @@ -1498,12 +1434,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1215 +#: sssd.conf.5.xml:1171 msgid "memcache_size_sid (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1218 +#: sssd.conf.5.xml:1174 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for SID related requests. Only SID-by-ID and ID-by-SID requests are " @@ -1512,12 +1448,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1242 sssd-ifp.5.xml:90 +#: sssd.conf.5.xml:1198 sssd-ifp.5.xml:90 msgid "user_attributes (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1245 +#: sssd.conf.5.xml:1201 msgid "" "Some of the additional NSS responder requests can return more attributes " "than just the POSIX ones defined by the NSS interface. The list of " @@ -1528,103 +1464,109 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1258 +#: sssd.conf.5.xml:1214 msgid "" "To make configuration more easy the NSS responder will check the InfoPipe " "option if it is not set for the NSS responder." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1263 +#: sssd.conf.5.xml:1219 msgid "Default: not set, fallback to InfoPipe option" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1268 +#: sssd.conf.5.xml:1224 msgid "pwfield (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1271 +#: sssd.conf.5.xml:1227 msgid "" "The value that NSS operations that return users or groups will return for " "the <quote>password</quote> field." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1276 -msgid "Default: <quote>*</quote>" +#: sssd.conf.5.xml:1232 +msgid "" +"This option can also be set per-domain, which overwrites the value in the " +"<quote>[nss]</quote> section for that domain. This is particularly useful " +"when using a proxy domain with <option>proxy_lib_name=files</option> and a " +"<option>proxy_pam_target</option> other than <quote>sssd-shadowutils</" +"quote>. In that case, SSSD returns <quote>*</quote> for the password field " +"by default, which causes <command>pam_unix</command> to treat all accounts " +"as locked. Setting <option>pwfield = x</option> in the domain section " +"restores the expected behavior." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1279 -msgid "" -"Note: This option can also be set per-domain which overwrites the value in " -"[nss] section." +#: sssd.conf.5.xml:1246 +msgid "Default: <quote>*</quote>" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1283 +#: sssd.conf.5.xml:1249 msgid "" -"Default: <quote>not set</quote> (remote domains), <quote>x</quote> (proxy " -"domain with nss_files and sssd-shadowutils target)" +"Default (per-domain): <quote>not set</quote> (remote domains), <quote>x</" +"quote> (proxy domain with nss_files and sssd-shadowutils target)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:1292 +#: sssd.conf.5.xml:1258 msgid "PAM configuration options" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:1294 +#: sssd.conf.5.xml:1260 msgid "" "These options can be used to configure the Pluggable Authentication Module " -"(PAM) service." +"(PAM) service and should be specified under the <quote>[pam]</quote> section." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1299 +#: sssd.conf.5.xml:1266 msgid "offline_credentials_expiration (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1302 +#: sssd.conf.5.xml:1269 msgid "" "If the authentication provider is offline, how long should we allow cached " "logins (in days since the last successful online login)." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1307 sssd.conf.5.xml:1320 +#: sssd.conf.5.xml:1274 sssd.conf.5.xml:1287 msgid "Default: 0 (No limit)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1313 +#: sssd.conf.5.xml:1280 msgid "offline_failed_login_attempts (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1316 +#: sssd.conf.5.xml:1283 msgid "" "If the authentication provider is offline, how many failed login attempts " "are allowed." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1326 +#: sssd.conf.5.xml:1293 msgid "offline_failed_login_delay (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1329 +#: sssd.conf.5.xml:1296 msgid "" "The time in minutes which has to pass after offline_failed_login_attempts " "has been reached before a new login attempt is possible." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1334 +#: sssd.conf.5.xml:1301 msgid "" "If set to 0 the user cannot authenticate offline if " "offline_failed_login_attempts has been reached. Only a successful online " @@ -1632,59 +1574,59 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1340 sssd.conf.5.xml:1450 +#: sssd.conf.5.xml:1307 sssd.conf.5.xml:1417 msgid "Default: 5" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1346 +#: sssd.conf.5.xml:1313 msgid "pam_verbosity (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1349 +#: sssd.conf.5.xml:1316 msgid "" "Controls what kind of messages are shown to the user during authentication. " "The higher the number to more messages are displayed." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1354 +#: sssd.conf.5.xml:1321 msgid "Currently sssd supports the following values:" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1357 +#: sssd.conf.5.xml:1324 msgid "<emphasis>0</emphasis>: do not show any message" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1360 +#: sssd.conf.5.xml:1327 msgid "<emphasis>1</emphasis>: show only important messages" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1364 +#: sssd.conf.5.xml:1331 msgid "<emphasis>2</emphasis>: show informational messages" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1367 +#: sssd.conf.5.xml:1334 msgid "<emphasis>3</emphasis>: show all messages and debug information" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1371 sssd.8.xml:63 +#: sssd.conf.5.xml:1338 sssd.8.xml:63 msgid "Default: 1" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1377 +#: sssd.conf.5.xml:1344 msgid "pam_response_filter (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1380 +#: sssd.conf.5.xml:1347 msgid "" "A comma separated list of strings which allows to remove (filter) data sent " "by the PAM responder to pam_sss PAM module. There are different kind of " @@ -1693,51 +1635,51 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1388 +#: sssd.conf.5.xml:1355 msgid "" "While messages already can be controlled with the help of the pam_verbosity " "option this option allows to filter out other kind of responses as well." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1395 +#: sssd.conf.5.xml:1362 msgid "ENV" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1396 +#: sssd.conf.5.xml:1363 msgid "Do not send any environment variables to any service." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1399 +#: sssd.conf.5.xml:1366 msgid "ENV:var_name" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1400 +#: sssd.conf.5.xml:1367 msgid "Do not send environment variable var_name to any service." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1404 +#: sssd.conf.5.xml:1371 msgid "ENV:var_name:service" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1405 +#: sssd.conf.5.xml:1372 msgid "Do not send environment variable var_name to service." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1393 +#: sssd.conf.5.xml:1360 msgid "" "Currently the following filters are supported: <placeholder " "type=\"variablelist\" id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1412 +#: sssd.conf.5.xml:1379 msgid "" "The list of strings can either be the list of filters which would set this " "list of filters and overwrite the defaults. Or each element of the list can " @@ -1748,23 +1690,23 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1423 +#: sssd.conf.5.xml:1390 msgid "Default: ENV:KRB5CCNAME:sudo, ENV:KRB5CCNAME:sudo-i" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1426 +#: sssd.conf.5.xml:1393 msgid "" "Example: -ENV:KRB5CCNAME:sudo-i will remove the filter from the default list" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1433 +#: sssd.conf.5.xml:1400 msgid "pam_id_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1436 +#: sssd.conf.5.xml:1403 msgid "" "For any PAM request while SSSD is online, the SSSD will attempt to " "immediately update the cached identity information for the user in order to " @@ -1772,7 +1714,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1442 +#: sssd.conf.5.xml:1409 msgid "" "A complete PAM conversation may perform multiple PAM requests, such as " "account management and session opening. This option controls (on a per-" @@ -1781,17 +1723,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1456 +#: sssd.conf.5.xml:1423 msgid "pam_pwd_expiration_warning (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1459 sssd.conf.5.xml:2912 +#: sssd.conf.5.xml:1426 sssd.conf.5.xml:3037 msgid "Display a warning N days before the password expires." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1462 +#: sssd.conf.5.xml:1429 msgid "" "Please note that the backend server has to provide information about the " "expiration time of the password. If this information is missing, sssd " @@ -1799,32 +1741,32 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1468 sssd.conf.5.xml:2915 +#: sssd.conf.5.xml:1435 sssd.conf.5.xml:3040 msgid "" "If zero is set, then this filter is not applied, i.e. if the expiration " "warning was received from backend server, it will automatically be displayed." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1473 +#: sssd.conf.5.xml:1440 msgid "" "This setting can be overridden by setting <emphasis>pwd_expiration_warning</" "emphasis> for a particular domain." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1478 sssd.conf.5.xml:3913 sssd-ldap.5.xml:662 +#: sssd.conf.5.xml:1445 sssd.conf.5.xml:4118 sssd-ldap.5.xml:662 #: sssd-ldap.5.xml:1733 sssd.8.xml:79 msgid "Default: 0" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1495 +#: sssd.conf.5.xml:1462 msgid "pam_trusted_users (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1498 +#: sssd.conf.5.xml:1465 msgid "" "Specifies the comma-separated list of UID values or user names that are " "allowed to run PAM conversations against trusted domains. Users not " @@ -1834,74 +1776,74 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1508 +#: sssd.conf.5.xml:1475 msgid "Default: All users are considered trusted by default" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1512 +#: sssd.conf.5.xml:1479 msgid "" "Please note that UID 0 is always allowed to access the PAM responder even in " "case it is not in the pam_trusted_users list." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1519 +#: sssd.conf.5.xml:1486 msgid "pam_public_domains (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1522 +#: sssd.conf.5.xml:1489 msgid "" "Specifies the comma-separated list of domain names that are accessible even " "to untrusted users." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1526 +#: sssd.conf.5.xml:1493 msgid "Two special values for pam_public_domains option are defined:" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1530 +#: sssd.conf.5.xml:1497 msgid "" "all (Untrusted users are allowed to access all domains in PAM responder.)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1534 +#: sssd.conf.5.xml:1501 msgid "" "none (Untrusted users are not allowed to access any domains PAM in " "responder.)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1538 sssd.conf.5.xml:1563 sssd.conf.5.xml:1582 -#: sssd.conf.5.xml:1824 sssd.conf.5.xml:3842 sssd-ldap.5.xml:1270 +#: sssd.conf.5.xml:1505 sssd.conf.5.xml:1530 sssd.conf.5.xml:1549 +#: sssd.conf.5.xml:1821 sssd.conf.5.xml:4048 sssd-ldap.5.xml:1270 msgid "Default: none" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1543 +#: sssd.conf.5.xml:1510 msgid "pam_account_expired_message (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1546 +#: sssd.conf.5.xml:1513 msgid "" "Allows a custom expiration message to be set, replacing the default " "'Permission denied' message." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1551 +#: sssd.conf.5.xml:1518 msgid "" "Note: Please be aware that message is only printed for the SSH service " "unless pam_verbosity is set to 3 (show all messages and debug information)." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1559 +#: sssd.conf.5.xml:1526 #, no-wrap msgid "" "pam_account_expired_message = Account expired, please contact help desk.\n" @@ -1909,19 +1851,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1568 +#: sssd.conf.5.xml:1535 msgid "pam_account_locked_message (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1571 +#: sssd.conf.5.xml:1538 msgid "" "Allows a custom lockout message to be set, replacing the default 'Permission " "denied' message." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1578 +#: sssd.conf.5.xml:1545 #, no-wrap msgid "" "pam_account_locked_message = Account locked, please contact help desk.\n" @@ -1929,81 +1871,120 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1587 -msgid "pam_passkey_auth (bool)" +#: sssd.conf.5.xml:1554 +msgid "pam_passkey_auth (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1590 +#: sssd.conf.5.xml:1557 msgid "Enable passkey device based authentication." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1593 sssd.conf.5.xml:1910 sssd-ad.5.xml:1286 +#: sssd.conf.5.xml:1560 sssd.conf.5.xml:1907 sssd-ad.5.xml:1279 #: sss_rpcidmapd.5.xml:76 msgid "Default: True" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1598 -msgid "passkey_debug_libfido2 (bool)" +#: sssd.conf.5.xml:1565 +msgid "passkey_debug_libfido2 (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1601 +#: sssd.conf.5.xml:1568 msgid "Enable libfido2 library debug messages." msgstr "" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1604 sssd.conf.5.xml:1618 sssd-ldap.5.xml:727 -#: sssd-ldap.5.xml:752 sssd-ldap.5.xml:848 sssd-ldap.5.xml:1356 -#: sssd-ad.5.xml:506 sssd-ad.5.xml:582 sssd-ad.5.xml:1155 +#: sssd.conf.5.xml:1571 sssd.conf.5.xml:1585 sssd.conf.5.xml:4781 +#: sssd-ldap.5.xml:727 sssd-ldap.5.xml:752 sssd-ldap.5.xml:848 +#: sssd-ldap.5.xml:1356 sssd-ad.5.xml:506 sssd-ad.5.xml:582 sssd-ad.5.xml:1160 #: include/ldap_id_mapping.xml:250 msgid "Default: False" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1609 -msgid "pam_cert_auth (bool)" +#: sssd.conf.5.xml:1576 +msgid "pam_cert_auth (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1612 +#: sssd.conf.5.xml:1579 msgid "" "Enable certificate based Smartcard authentication. Since this requires " "additional communication with the Smartcard which will delay the " "authentication process this option is disabled by default." msgstr "" +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1588 +msgid "" +"Note: In case OpenSC is used for Smartcard access SSSD supports the " +"filesystem caching in OpenSC when enabled in opensc.conf. The cached files " +"are located in a common <quote>opensc</quote> directory in SSSD's state " +"directory. The behaviour can be changed in opensc.conf" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> +#: sssd.conf.5.xml:1597 +#, no-wrap +msgid "" +"app /usr/libexec/sssd/p11_child {\n" +" framework pkcs15 {\n" +" use_file_caching = no;\n" +" }\n" +"}\n" +"app /usr/libexec/sssd/krb5_child {\n" +" framework pkcs15 {\n" +" use_file_caching = no;\n" +" }\n" +"}\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1595 +msgid "" +"Example opensc.conf (*): <placeholder type=\"programlisting\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1610 +msgid "" +"(*) The actual <quote>libexec</quote> directory for p11_child and krb5_child " +"depends on the distribution." +msgstr "" + #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1623 +#: sssd.conf.5.xml:1615 msgid "pam_cert_db_path (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1626 +#: sssd.conf.5.xml:1618 msgid "The path to the certificate database." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1629 sssd.conf.5.xml:2163 sssd.conf.5.xml:4338 +#: sssd.conf.5.xml:1621 sssd.conf.5.xml:2199 sssd.conf.5.xml:4543 msgid "Default:" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1631 sssd.conf.5.xml:2165 +#: sssd.conf.5.xml:1623 sssd.conf.5.xml:2201 msgid "" "/etc/sssd/pki/sssd_auth_ca_db.pem (path to a file with trusted CA " "certificates in PEM format)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1641 +#: sssd.conf.5.xml:1633 msgid "pam_cert_verification (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1644 +#: sssd.conf.5.xml:1636 msgid "" "With this parameter the PAM certificate verification can be tuned with a " "comma separated list of options that override the " @@ -2013,7 +1994,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1655 +#: sssd.conf.5.xml:1647 #, no-wrap msgid "" "pam_cert_verification = partial_chain\n" @@ -2021,59 +2002,59 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1659 +#: sssd.conf.5.xml:1651 msgid "" "Default: not set, i.e. use default <quote>certificate_verification</quote> " "option defined in <quote>[sssd]</quote> section." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1666 +#: sssd.conf.5.xml:1658 msgid "p11_child_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1669 +#: sssd.conf.5.xml:1661 msgid "How many seconds will pam_sss wait for p11_child to finish." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1678 +#: sssd.conf.5.xml:1670 msgid "passkey_child_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1681 +#: sssd.conf.5.xml:1673 msgid "" "How many seconds will the PAM responder wait for passkey_child to finish." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1690 +#: sssd.conf.5.xml:1682 msgid "pam_app_services (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1693 +#: sssd.conf.5.xml:1685 msgid "" "Which PAM services are permitted to contact domains of type " "<quote>application</quote>" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1702 +#: sssd.conf.5.xml:1694 msgid "pam_p11_allowed_services (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1705 +#: sssd.conf.5.xml:1697 msgid "" "A comma-separated list of PAM service names for which it will be allowed to " "use Smartcards." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1720 +#: sssd.conf.5.xml:1712 #, no-wrap msgid "" "pam_p11_allowed_services = +my_pam_service, -login\n" @@ -2081,7 +2062,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1709 +#: sssd.conf.5.xml:1701 msgid "" "It is possible to add another PAM service name to the default set by using " "<quote>+service_name</quote> or to explicitly remove a PAM service name from " @@ -2093,68 +2074,73 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1724 sssd-ad.5.xml:645 sssd-ad.5.xml:754 sssd-ad.5.xml:812 -#: sssd-ad.5.xml:870 sssd-ad.5.xml:948 +#: sssd.conf.5.xml:1716 sssd-ad.5.xml:645 sssd-ad.5.xml:759 sssd-ad.5.xml:817 +#: sssd-ad.5.xml:875 sssd-ad.5.xml:953 msgid "Default: the default set of PAM service names includes:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1729 sssd-ad.5.xml:649 +#: sssd.conf.5.xml:1721 sssd-ad.5.xml:649 msgid "login" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1734 sssd-ad.5.xml:654 +#: sssd.conf.5.xml:1726 sssd-ad.5.xml:654 msgid "su" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1739 sssd-ad.5.xml:659 +#: sssd.conf.5.xml:1731 sssd-ad.5.xml:659 msgid "su-l" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1744 sssd-ad.5.xml:674 +#: sssd.conf.5.xml:1736 sssd-ad.5.xml:674 msgid "gdm-smartcard" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1749 sssd-ad.5.xml:669 +#: sssd.conf.5.xml:1741 sssd-ad.5.xml:669 msgid "gdm-password" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1754 +#: sssd.conf.5.xml:1746 msgid "gdm-switchable-auth" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1759 sssd-ad.5.xml:679 +#: sssd.conf.5.xml:1751 sssd-ad.5.xml:679 msgid "kdm" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1764 sssd-ad.5.xml:957 +#: sssd.conf.5.xml:1756 sssd-ad.5.xml:694 +msgid "plasmalogin" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:1761 sssd-ad.5.xml:962 msgid "sudo" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1769 sssd-ad.5.xml:962 +#: sssd.conf.5.xml:1766 sssd-ad.5.xml:967 msgid "sudo-i" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1774 +#: sssd.conf.5.xml:1771 msgid "gnome-screensaver" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1782 +#: sssd.conf.5.xml:1779 msgid "p11_wait_for_card_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1785 +#: sssd.conf.5.xml:1782 msgid "" "If Smartcard authentication is required how many extra seconds in addition " "to p11_child_timeout should the PAM responder wait until a Smartcard is " @@ -2162,12 +2148,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1796 +#: sssd.conf.5.xml:1793 msgid "p11_uri (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1799 +#: sssd.conf.5.xml:1796 msgid "" "PKCS#11 URI (see RFC-7512 for details) which can be used to restrict the " "selection of devices used for Smartcard authentication. By default SSSD's " @@ -2178,7 +2164,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1812 +#: sssd.conf.5.xml:1809 #, no-wrap msgid "" "p11_uri = pkcs11:slot-description=My%20Smartcard%20Reader\n" @@ -2186,7 +2172,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1816 +#: sssd.conf.5.xml:1813 #, no-wrap msgid "" "p11_uri = pkcs11:library-description=OpenSC%20smartcard%20framework;slot-id=2\n" @@ -2194,7 +2180,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1810 +#: sssd.conf.5.xml:1807 msgid "" "Example: <placeholder type=\"programlisting\" id=\"0\"/> or <placeholder " "type=\"programlisting\" id=\"1\"/> To find suitable URI please check the " @@ -2203,47 +2189,47 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1829 -msgid "pam_initgroups_scheme" +#: sssd.conf.5.xml:1826 +msgid "pam_initgroups_scheme (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1837 +#: sssd.conf.5.xml:1834 msgid "always" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1838 +#: sssd.conf.5.xml:1835 msgid "" "Always do an online lookup, please note that pam_id_timeout still applies" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1842 +#: sssd.conf.5.xml:1839 msgid "no_session" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1843 +#: sssd.conf.5.xml:1840 msgid "" "Only do an online lookup if there is no active session of the user, i.e. if " "the user is currently not logged in" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1848 sssd-ldap.5.xml:189 +#: sssd.conf.5.xml:1845 sssd-ldap.5.xml:189 msgid "never" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1849 +#: sssd.conf.5.xml:1846 msgid "" "Never force an online lookup, use the data from the cache as long as they " "are not expired" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1832 +#: sssd.conf.5.xml:1829 msgid "" "The PAM responder can force an online lookup to get the current group " "memberships of the user trying to log in. This option controls when this " @@ -2252,30 +2238,30 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1856 +#: sssd.conf.5.xml:1853 msgid "Default: no_session" msgstr "" -#. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:1861 sssd.conf.5.xml:4277 -msgid "pam_gssapi_services" +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1858 +msgid "pam_gssapi_services (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1864 +#: sssd.conf.5.xml:1861 msgid "" "Comma separated list of PAM services that are allowed to try GSSAPI " "authentication using pam_sss_gss.so module." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1869 +#: sssd.conf.5.xml:1866 msgid "" "To disable GSSAPI authentication, set this option to <quote>-</quote> (dash)." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1873 sssd.conf.5.xml:1904 sssd.conf.5.xml:1942 +#: sssd.conf.5.xml:1870 sssd.conf.5.xml:1901 sssd.conf.5.xml:1939 msgid "" "Note: This option can also be set per-domain which overwrites the value in " "[pam] section. It can also be set for trusted domain which overwrites the " @@ -2283,7 +2269,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1881 +#: sssd.conf.5.xml:1878 #, no-wrap msgid "" "pam_gssapi_services = sudo, sudo-i\n" @@ -2291,22 +2277,22 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1879 sssd.conf.5.xml:1994 sssd.conf.5.xml:3836 +#: sssd.conf.5.xml:1876 sssd.conf.5.xml:2023 sssd.conf.5.xml:4042 msgid "Example: <placeholder type=\"programlisting\" id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1885 +#: sssd.conf.5.xml:1882 msgid "Default: - (GSSAPI authentication is disabled)" msgstr "" -#. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:1890 sssd.conf.5.xml:4278 -msgid "pam_gssapi_check_upn" +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1887 +msgid "pam_gssapi_check_upn (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1893 +#: sssd.conf.5.xml:1890 msgid "" "If True, SSSD will require that the Kerberos user principal that " "successfully authenticated through GSSAPI can be associated with the user " @@ -2314,19 +2300,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1900 +#: sssd.conf.5.xml:1897 msgid "" -"If False, every user that is able to obtained required service ticket will " +"If False, every user that is able to obtain a required service ticket will " "be authenticated." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1915 -msgid "pam_gssapi_indicators_map" +#: sssd.conf.5.xml:1912 +msgid "pam_gssapi_indicators_map (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1918 +#: sssd.conf.5.xml:1915 msgid "" "Comma separated list of authentication indicators required to be present in " "a Kerberos ticket to access a PAM service that is allowed to try GSSAPI " @@ -2334,7 +2320,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1924 +#: sssd.conf.5.xml:1921 msgid "" "Each element of the list can be either an authentication indicator name or a " "pair <quote>service:indicator</quote>. Indicators not prefixed with the PAM " @@ -2349,7 +2335,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1937 +#: sssd.conf.5.xml:1934 msgid "" "To disable GSSAPI authentication indicator check, set this option to <quote>-" "</quote> (dash). To disable the check for a specific PAM service, add " @@ -2357,45 +2343,45 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1948 +#: sssd.conf.5.xml:1945 msgid "" "Following authentication indicators are supported by IPA Kerberos " "deployments:" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1951 +#: sssd.conf.5.xml:1948 msgid "" "pkinit -- pre-authentication using X.509 certificates -- whether stored in " "files or on smart cards." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1954 +#: sssd.conf.5.xml:1951 msgid "" "hardened -- SPAKE pre-authentication or any pre-authentication wrapped in a " "FAST channel." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1957 +#: sssd.conf.5.xml:1954 msgid "radius -- pre-authentication with the help of a RADIUS server." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1960 +#: sssd.conf.5.xml:1957 msgid "" "otp -- pre-authentication using integrated two-factor authentication (2FA or " "one-time password, OTP) in IPA." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1963 +#: sssd.conf.5.xml:1960 msgid "idp -- pre-authentication using external identity provider." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1973 +#: sssd.conf.5.xml:1970 #, no-wrap msgid "" "pam_gssapi_indicators_map = sudo:pkinit, sudo-i:pkinit\n" @@ -2403,7 +2389,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1968 +#: sssd.conf.5.xml:1965 msgid "" "Example: to require access to SUDO services only for users which obtained " "their Kerberos tickets with a X.509 certificate pre-authentication (PKINIT), " @@ -2411,29 +2397,68 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1977 +#: sssd.conf.5.xml:1974 msgid "Default: not set (use of authentication indicators is not required)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1979 +msgid "pam_gssapi_indicators_apply (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1982 +msgid "" +"Comma separated list of triples to assign additional information from the " +"Kerberos ticket, e.g. a SID from the PAC, to authentication indicators." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1988 +msgid "Currently supported is:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:1991 +msgid "SID:S-1-5-[domain]-[RID]:[authentication indicator]" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> +#: sssd.conf.5.xml:2002 +#, no-wrap +msgid "" +"pam_gssapi_indicators_apply = SID:S-1-5-12345-23456-34567-4321:pkinit\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1996 +msgid "" +"Example: To assign a SID, which is e.g. set by Active Directory's " +"Authentication Mechanism Assurance (AMA) if the AD user used a Smartcard for " +"authentication, to the 'pkinit' authentication indicator use: <placeholder " +"type=\"programlisting\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2011 msgid "pam_json_services (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1985 +#: sssd.conf.5.xml:2014 msgid "" "Comma separated list of PAM services which can handle the JSON protocol for " "selecting authentication mechanisms" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1990 +#: sssd.conf.5.xml:2019 msgid "To disable JSON protocol, set this option to <quote>-</quote> (dash)." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1996 +#: sssd.conf.5.xml:2025 #, no-wrap msgid "" "pam_json_services = gdm-switchable-auth\n" @@ -2441,52 +2466,59 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2000 +#: sssd.conf.5.xml:2029 msgid "Default: - (JSON protocol is disabled)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2003 +#: sssd.conf.5.xml:2032 msgid "" "Note: 2-Factor Authentication (2FA) is not supported. If 2FA is required, do " "not activate the JSON protocol." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:2013 +#: sssd.conf.5.xml:2042 msgid "SUDO configuration options" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2015 +#: sssd.conf.5.xml:2044 msgid "" -"These options can be used to configure the sudo service. The detailed " -"instructions for configuration of <citerefentry> <refentrytitle>sudo</" -"refentrytitle> <manvolnum>8</manvolnum> </citerefentry> to work with " -"<citerefentry> <refentrytitle>sssd</refentrytitle> <manvolnum>8</manvolnum> " -"</citerefentry> are in the manual page <citerefentry> <refentrytitle>sssd-" -"sudo</refentrytitle> <manvolnum>5</manvolnum> </citerefentry>." +"These options can be used to configure the sudo service and should be " +"specified under the <quote>[sudo]</quote> section." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:2048 +msgid "" +"The detailed instructions for configuration of <citerefentry> " +"<refentrytitle>sudo</refentrytitle> <manvolnum>8</manvolnum> </citerefentry> " +"to work with <citerefentry> <refentrytitle>sssd</refentrytitle> " +"<manvolnum>8</manvolnum> </citerefentry> are in the manual page " +"<citerefentry> <refentrytitle>sssd-sudo</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry>." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2032 -msgid "sudo_timed (bool)" +#: sssd.conf.5.xml:2064 +msgid "sudo_timed (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2035 +#: sssd.conf.5.xml:2067 msgid "" "Whether or not to evaluate the sudoNotBefore and sudoNotAfter attributes " "that implement time-dependent sudoers entries." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2047 +#: sssd.conf.5.xml:2079 msgid "sudo_threshold (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2050 +#: sssd.conf.5.xml:2082 msgid "" "Maximum number of expired rules that can be refreshed at once. If number of " "expired rules is below threshold, those rules are refreshed with " @@ -2496,22 +2528,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:2069 +#: sssd.conf.5.xml:2101 msgid "AUTOFS configuration options" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2071 -msgid "These options can be used to configure the autofs service." +#: sssd.conf.5.xml:2103 +msgid "" +"These options can be used to configure the autofs service and should be " +"specified under the <quote>[autofs]</quote> section." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2075 +#: sssd.conf.5.xml:2109 msgid "autofs_negative_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2078 +#: sssd.conf.5.xml:2112 msgid "" "Specifies for how many seconds should the autofs responder negative cache " "hits (that is, queries for invalid map entries, like nonexistent ones) " @@ -2519,22 +2553,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:2094 +#: sssd.conf.5.xml:2128 msgid "SSH configuration options" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2096 -msgid "These options can be used to configure the SSH service." +#: sssd.conf.5.xml:2130 +msgid "" +"These options can be used to configure the SSH service and should be " +"specified under the <quote>[ssh]</quote> section." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2100 -msgid "ssh_use_certificate_keys (bool)" +#: sssd.conf.5.xml:2136 +msgid "ssh_use_certificate_keys (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2103 +#: sssd.conf.5.xml:2139 msgid "" "If set to true the <command>sss_ssh_authorizedkeys</command> will return ssh " "keys derived from the public key of X.509 certificates stored in the user " @@ -2543,12 +2579,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2118 +#: sssd.conf.5.xml:2154 msgid "ssh_use_certificate_matching_rules (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2121 +#: sssd.conf.5.xml:2157 msgid "" "By default the ssh responder will use all available certificate matching " "rules to filter the certificates so that ssh keys are only derived from the " @@ -2558,7 +2594,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2130 +#: sssd.conf.5.xml:2166 msgid "" "There are two special key words 'all_rules' and 'no_rules' which will enable " "all or no rules, respectively. The latter means that no certificates will be " @@ -2566,7 +2602,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2137 +#: sssd.conf.5.xml:2173 msgid "" "If no rules are configured using 'all_rules' will enable a default rule " "which enables all certificates suitable for client authentication. This is " @@ -2575,38 +2611,38 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2144 +#: sssd.conf.5.xml:2180 msgid "" "A non-existing rule name is considered an error. If as a result no rule is " "selected all certificates will be ignored." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2149 +#: sssd.conf.5.xml:2185 msgid "" "Default: not set, equivalent to 'all_rules', all found rules or the default " "rule are used" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2155 +#: sssd.conf.5.xml:2191 msgid "ca_db (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2158 +#: sssd.conf.5.xml:2194 msgid "" "Path to a storage of trusted CA certificates. The option is used to validate " "user certificates before deriving public ssh keys from them." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:2178 +#: sssd.conf.5.xml:2214 msgid "PAC responder configuration options" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2180 +#: sssd.conf.5.xml:2216 msgid "" "The PAC responder works together with the authorization data plugin for MIT " "Kerberos sssd_pac_plugin.so and a sub-domain provider. The plugin sends the " @@ -2617,7 +2653,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:2189 +#: sssd.conf.5.xml:2225 msgid "" "If the remote user does not exist in the cache, it is created. The UID is " "determined with the help of the SID, trusted domains will have UPGs and the " @@ -2628,24 +2664,26 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:2197 +#: sssd.conf.5.xml:2233 msgid "" "If there are SIDs of groups from domains sssd knows about, the user will be " "added to those groups." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2203 -msgid "These options can be used to configure the PAC responder." +#: sssd.conf.5.xml:2239 +msgid "" +"These options can be used to configure the PAC responder and should be " +"specified under the <quote>[pac]</quote> section." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2207 sssd-ifp.5.xml:66 +#: sssd.conf.5.xml:2244 sssd-ifp.5.xml:66 msgid "allowed_uids (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2210 +#: sssd.conf.5.xml:2247 msgid "" "Specifies the comma-separated list of UID values or user names that are " "allowed to access the PAC responder. User names are resolved to UIDs at " @@ -2653,19 +2691,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2216 +#: sssd.conf.5.xml:2253 msgid "" "Default: 0, &sssd_user_name; (only root and SSSD service users are allowed " "to access the PAC responder)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2220 +#: sssd.conf.5.xml:2257 msgid "Default: 0 (only the root user is allowed to access the PAC responder)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2224 +#: sssd.conf.5.xml:2261 msgid "" "Please note that defaults will be overwritten with this option. If you still " "want to allow the root and/or '&sssd_user_name;' user to access the PAC " @@ -2674,7 +2712,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2231 +#: sssd.conf.5.xml:2268 msgid "" "Please note that although the UID 0 is used as the default it will be " "overwritten with this option. If you still want to allow the root user to " @@ -2683,24 +2721,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2240 +#: sssd.conf.5.xml:2277 msgid "pac_lifetime (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2243 +#: sssd.conf.5.xml:2280 msgid "" "Lifetime of the PAC entry in seconds. As long as the PAC is valid the PAC " "data can be used to determine the group memberships of a user." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2253 +#: sssd.conf.5.xml:2290 msgid "pac_check (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2256 +#: sssd.conf.5.xml:2293 msgid "" "Apply additional checks on the PAC of the Kerberos ticket which is available " "in Active Directory and FreeIPA domains, if configured. Please note that " @@ -2711,7 +2749,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2266 +#: sssd.conf.5.xml:2303 msgid "" "Please note that the checks listed below only apply to PACs issued by Active " "Directory or recent versions of FreeIPA. PACs issued e.g. by a plain MIT " @@ -2719,24 +2757,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2277 +#: sssd.conf.5.xml:2314 msgid "no_check" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2279 +#: sssd.conf.5.xml:2316 msgid "" "The PAC must not be present and even if it is present no additional checks " "will be done." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2285 +#: sssd.conf.5.xml:2322 msgid "pac_present" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2287 +#: sssd.conf.5.xml:2324 msgid "" "The PAC must be present in the service ticket which SSSD will request with " "the help of the user's TGT. If the PAC is not available the authentication " @@ -2744,24 +2782,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2295 +#: sssd.conf.5.xml:2332 msgid "check_upn" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2297 +#: sssd.conf.5.xml:2334 msgid "" "If the PAC is present check if the user principal name (UPN) information is " "consistent." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2303 +#: sssd.conf.5.xml:2340 msgid "check_upn_allow_missing" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2305 +#: sssd.conf.5.xml:2342 msgid "" "This option should be used together with 'check_upn' and handles the case " "where a UPN is set on the server-side but is not read by SSSD. The typical " @@ -2773,7 +2811,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2317 +#: sssd.conf.5.xml:2354 msgid "" "Currently this option is set by default to avoid regressions in such " "environments. A log message will be added to the system log and SSSD's debug " @@ -2784,60 +2822,60 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2331 +#: sssd.conf.5.xml:2368 msgid "upn_dns_info_present" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2333 +#: sssd.conf.5.xml:2370 msgid "The PAC must contain the UPN-DNS-INFO buffer, implies 'check_upn'." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2338 +#: sssd.conf.5.xml:2375 msgid "check_upn_dns_info_ex" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2340 +#: sssd.conf.5.xml:2377 msgid "" "If the PAC is present and the extension to the UPN-DNS-INFO buffer is " "available check if the information in the extension is consistent." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2347 +#: sssd.conf.5.xml:2384 msgid "upn_dns_info_ex_present" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2349 +#: sssd.conf.5.xml:2386 msgid "" "The PAC must contain the extension of the UPN-DNS-INFO buffer, implies " "'check_upn_dns_info_ex', 'upn_dns_info_present' and 'check_upn'." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2273 +#: sssd.conf.5.xml:2310 msgid "" "The following options can be used alone or in a comma-separated list: " "<placeholder type=\"variablelist\" id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2359 +#: sssd.conf.5.xml:2396 msgid "" "Default: no_check (AD and IPA provider 'check_upn, check_upn_allow_missing, " "check_upn_dns_info_ex')" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:2368 +#: sssd.conf.5.xml:2405 msgid "Session recording configuration options" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2370 +#: sssd.conf.5.xml:2407 msgid "" "Session recording works in conjunction with <citerefentry> " "<refentrytitle>tlog-rec-session</refentrytitle> <manvolnum>8</manvolnum> </" @@ -2847,66 +2885,78 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2383 -msgid "These options can be used to configure session recording." +#: sssd.conf.5.xml:2420 +msgid "" +"These options can be used to configure session recording and should be " +"specified under the <quote>[session_recording]</quote> section." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:2425 +msgid "" +"Note: Unlike other sections, the <quote>[session_recording]</quote> section " +"ignores <replaceable>debug*</replaceable> options and suitable " +"<replaceable>debug*</replaceable> options must be set in <quote>[pam]</" +"quote>, <quote>[nss]</quote> and <quote>[domain/<replaceable>NAME</" +"replaceable>]</quote> sections." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2387 sssd-session-recording.5.xml:64 +#: sssd.conf.5.xml:2433 sssd-session-recording.5.xml:64 msgid "scope (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2394 sssd-session-recording.5.xml:71 +#: sssd.conf.5.xml:2440 sssd-session-recording.5.xml:71 msgid "\"none\"" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2397 sssd-session-recording.5.xml:74 +#: sssd.conf.5.xml:2443 sssd-session-recording.5.xml:74 msgid "No users are recorded." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2402 sssd-session-recording.5.xml:79 +#: sssd.conf.5.xml:2448 sssd-session-recording.5.xml:79 msgid "\"some\"" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2405 sssd-session-recording.5.xml:82 +#: sssd.conf.5.xml:2451 sssd-session-recording.5.xml:82 msgid "" "Users/groups specified by <replaceable>users</replaceable> and " "<replaceable>groups</replaceable> options are recorded." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2414 sssd-session-recording.5.xml:91 +#: sssd.conf.5.xml:2460 sssd-session-recording.5.xml:91 msgid "\"all\"" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2417 sssd-session-recording.5.xml:94 +#: sssd.conf.5.xml:2463 sssd-session-recording.5.xml:94 msgid "All users are recorded." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2390 sssd-session-recording.5.xml:67 +#: sssd.conf.5.xml:2436 sssd-session-recording.5.xml:67 msgid "" "One of the following strings specifying the scope of session recording: " "<placeholder type=\"variablelist\" id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2424 sssd-session-recording.5.xml:101 +#: sssd.conf.5.xml:2470 sssd-session-recording.5.xml:101 msgid "Default: \"none\"" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2429 sssd-session-recording.5.xml:106 +#: sssd.conf.5.xml:2475 sssd-session-recording.5.xml:106 msgid "users (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2432 sssd-session-recording.5.xml:109 +#: sssd.conf.5.xml:2478 sssd-session-recording.5.xml:109 msgid "" "A comma-separated list of users which should have session recording enabled. " "Matches user names as returned by NSS. I.e. after the possible space " @@ -2914,17 +2964,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2438 sssd-session-recording.5.xml:115 +#: sssd.conf.5.xml:2484 sssd-session-recording.5.xml:115 msgid "Default: Empty. Matches no users." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2443 sssd-session-recording.5.xml:120 +#: sssd.conf.5.xml:2489 sssd-session-recording.5.xml:120 msgid "groups (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2446 sssd-session-recording.5.xml:123 +#: sssd.conf.5.xml:2492 sssd-session-recording.5.xml:123 msgid "" "A comma-separated list of groups, members of which should have session " "recording enabled. Matches group names as returned by NSS. I.e. after the " @@ -2932,7 +2982,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2452 sssd.conf.5.xml:2484 sssd-session-recording.5.xml:129 +#: sssd.conf.5.xml:2498 sssd.conf.5.xml:2530 sssd-session-recording.5.xml:129 #: sssd-session-recording.5.xml:161 msgid "" "NOTE: using this option (having it set to anything) has a considerable " @@ -2941,57 +2991,56 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2459 sssd-session-recording.5.xml:136 +#: sssd.conf.5.xml:2505 sssd-session-recording.5.xml:136 msgid "Default: Empty. Matches no groups." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2464 sssd-session-recording.5.xml:141 +#: sssd.conf.5.xml:2510 sssd-session-recording.5.xml:141 msgid "exclude_users (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2467 sssd-session-recording.5.xml:144 +#: sssd.conf.5.xml:2513 sssd-session-recording.5.xml:144 msgid "" "A comma-separated list of users to be excluded from recording, only " "applicable with 'scope=all'." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2471 sssd-session-recording.5.xml:148 +#: sssd.conf.5.xml:2517 sssd-session-recording.5.xml:148 msgid "Default: Empty. No users excluded." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2476 sssd-session-recording.5.xml:153 +#: sssd.conf.5.xml:2522 sssd-session-recording.5.xml:153 msgid "exclude_groups (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2479 sssd-session-recording.5.xml:156 +#: sssd.conf.5.xml:2525 sssd-session-recording.5.xml:156 msgid "" "A comma-separated list of groups, members of which should be excluded from " "recording. Only applicable with 'scope=all'." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2491 sssd-session-recording.5.xml:168 +#: sssd.conf.5.xml:2537 sssd-session-recording.5.xml:168 msgid "Default: Empty. No groups excluded." msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:2501 +#: sssd.conf.5.xml:2547 msgid "DOMAIN SECTIONS" msgstr "" -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry><para> -#: sssd.conf.5.xml:2508 sssd.conf.5.xml:3964 sssd.conf.5.xml:3965 -#: sssd.conf.5.xml:3968 -msgid "enabled" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2554 +msgid "enabled (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2511 +#: sssd.conf.5.xml:2557 msgid "" "Explicitly enable or disable the domain. If <quote>true</quote>, the domain " "is always <quote>enabled</quote>. If <quote>false</quote>, the domain is " @@ -3001,12 +3050,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2523 +#: sssd.conf.5.xml:2569 msgid "domain_type (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2526 +#: sssd.conf.5.xml:2572 msgid "" "Specifies whether the domain is meant to be used by POSIX-aware clients such " "as the Name Service Switch or by applications that do not need POSIX data to " @@ -3015,14 +3064,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2534 +#: sssd.conf.5.xml:2580 msgid "" "Allowed values for this option are <quote>posix</quote> and " "<quote>application</quote>." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2538 +#: sssd.conf.5.xml:2584 msgid "" "POSIX domains are reachable by all services. Application domains are only " "reachable from the InfoPipe responder (see <citerefentry> " @@ -3031,38 +3080,38 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2546 +#: sssd.conf.5.xml:2592 msgid "" "NOTE: The application domains are currently well tested with " "<quote>id_provider=ldap</quote> only." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2550 +#: sssd.conf.5.xml:2596 msgid "" "For an easy way to configure a non-POSIX domains, please see the " "<quote>Application domains</quote> section." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2554 +#: sssd.conf.5.xml:2600 msgid "Default: posix" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2560 +#: sssd.conf.5.xml:2606 msgid "min_id,max_id (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2563 +#: sssd.conf.5.xml:2609 msgid "" "UID and GID limits for the domain. If a domain contains an entry that is " "outside these limits, it is ignored." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2568 +#: sssd.conf.5.xml:2614 msgid "" "For users, this affects the primary GID limit. The user will not be returned " "to NSS if either the UID or the primary GID is outside the range. For non-" @@ -3071,24 +3120,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2575 +#: sssd.conf.5.xml:2621 msgid "" "These ID limits affect even saving entries to cache, not only returning them " "by name or ID." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2579 +#: sssd.conf.5.xml:2625 msgid "Default: 1 for min_id, 0 (no limit) for max_id" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2585 -msgid "enumerate (bool)" +#: sssd.conf.5.xml:2631 +msgid "enumerate (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2588 +#: sssd.conf.5.xml:2634 msgid "" "Determines if a domain can be enumerated, that is, whether the domain can " "list all the users and group it contains. Note that it is not required to " @@ -3097,36 +3146,36 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2596 +#: sssd.conf.5.xml:2642 msgid "TRUE = Users and groups are enumerated" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2599 +#: sssd.conf.5.xml:2645 msgid "FALSE = No enumerations for this domain" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2602 sssd.conf.5.xml:2867 sssd.conf.5.xml:3044 +#: sssd.conf.5.xml:2648 sssd.conf.5.xml:2992 sssd.conf.5.xml:3174 msgid "Default: FALSE" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2605 +#: sssd.conf.5.xml:2651 msgid "" "Enumerating a domain requires SSSD to download and store ALL user and group " "entries from the remote server." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2610 +#: sssd.conf.5.xml:2656 msgid "" "Feature is only supported for domains with id_provider = ldap or id_provider " "= proxy." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2614 +#: sssd.conf.5.xml:2660 msgid "" "Note: Enabling enumeration has a severe performance impact on SSSD while " "enumeration is running. It may take up to several minutes after SSSD startup " @@ -3140,14 +3189,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2629 +#: sssd.conf.5.xml:2675 msgid "" "While the first enumeration is running, requests for the complete user or " "group lists may return no results until it completes." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2634 +#: sssd.conf.5.xml:2680 msgid "" "Further, enabling enumeration may increase the time necessary to detect " "network disconnection, as longer timeouts are required to ensure that " @@ -3156,14 +3205,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2642 +#: sssd.conf.5.xml:2688 msgid "" "For the reasons cited above, enabling enumeration is not recommended, " "especially in large environments." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2647 +#: sssd.conf.5.xml:2693 msgid "" "Note: the proxy provider is tested with open source modules like " "'libnss_files' and 'libnss_ldap'. 3rd party modules must follow the " @@ -3171,19 +3220,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2656 +#: sssd.conf.5.xml:2702 msgid "entry_cache_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2659 +#: sssd.conf.5.xml:2705 msgid "" "How many seconds should nss_sss consider entries valid before asking the " "backend again" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2663 +#: sssd.conf.5.xml:2709 msgid "" "The cache expiration timestamps are stored as attributes of individual " "objects in the cache. Therefore, changing the cache timeout only has effect " @@ -3194,139 +3243,244 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2676 +#: sssd.conf.5.xml:2722 msgid "Default: 5400" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2682 +#: sssd.conf.5.xml:2728 msgid "entry_cache_user_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2685 +#: sssd.conf.5.xml:2731 msgid "" "How many seconds should nss_sss consider user entries valid before asking " "the backend again" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2689 sssd.conf.5.xml:2702 sssd.conf.5.xml:2715 -#: sssd.conf.5.xml:2728 sssd.conf.5.xml:2742 sssd.conf.5.xml:2755 -#: sssd.conf.5.xml:2769 sssd.conf.5.xml:2783 sssd.conf.5.xml:2796 +#: sssd.conf.5.xml:2735 sssd.conf.5.xml:2748 sssd.conf.5.xml:2761 +#: sssd.conf.5.xml:2774 sssd.conf.5.xml:2788 sssd.conf.5.xml:2801 +#: sssd.conf.5.xml:2815 sssd.conf.5.xml:2829 msgid "Default: entry_cache_timeout" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2695 +#: sssd.conf.5.xml:2741 msgid "entry_cache_group_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2698 +#: sssd.conf.5.xml:2744 msgid "" "How many seconds should nss_sss consider group entries valid before asking " "the backend again" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2708 +#: sssd.conf.5.xml:2754 msgid "entry_cache_netgroup_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2711 +#: sssd.conf.5.xml:2757 msgid "" "How many seconds should nss_sss consider netgroup entries valid before " "asking the backend again" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2721 +#: sssd.conf.5.xml:2767 msgid "entry_cache_service_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2724 +#: sssd.conf.5.xml:2770 msgid "" "How many seconds should nss_sss consider service entries valid before asking " "the backend again" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2734 +#: sssd.conf.5.xml:2780 msgid "entry_cache_resolver_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2737 +#: sssd.conf.5.xml:2783 msgid "" "How many seconds should nss_sss consider hosts and networks entries valid " "before asking the backend again" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2748 +#: sssd.conf.5.xml:2794 msgid "entry_cache_sudo_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2751 +#: sssd.conf.5.xml:2797 msgid "" "How many seconds should sudo consider rules valid before asking the backend " "again" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2761 +#: sssd.conf.5.xml:2807 msgid "entry_cache_autofs_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2764 +#: sssd.conf.5.xml:2810 msgid "" "How many seconds should the autofs service consider automounter maps valid " "before asking the backend again" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2775 +#: sssd.conf.5.xml:2821 msgid "entry_cache_ssh_host_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2778 +#: sssd.conf.5.xml:2824 msgid "" "How many seconds to keep a host ssh key after refresh. IE how long to cache " "the host key for." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2789 -msgid "entry_cache_computer_timeout (integer)" +#: sssd.conf.5.xml:2835 +msgid "offline_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2792 +#: sssd.conf.5.xml:2838 msgid "" -"How many seconds to keep the local computer entry before asking the backend " -"again" +"When SSSD switches to offline mode the amount of time before it tries to go " +"back online will increase based upon the time spent disconnected. By " +"default SSSD uses incremental behaviour to calculate delay in between " +"retries. So, the wait time for a given retry will be longer than the wait " +"time for the previous ones. After each unsuccessful attempt to go online, " +"the new interval is recalculated by the following:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2849 sssd.conf.5.xml:2907 +msgid "" +"new_delay = Minimum(old_delay * 2, offline_timeout_max) + " +"random[0...offline_timeout_random_offset]" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2852 +msgid "" +"The offline_timeout default value is 60. The offline_timeout_max default " +"value is 3600. The offline_timeout_random_offset default value is 30. The " +"end result is the number of seconds before next retry." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2858 +msgid "" +"Note that the maximum length of each interval is defined by " +"offline_timeout_max (apart from the random part)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2868 +msgid "offline_timeout_max (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2871 +msgid "" +"Controls by how much the time between attempts to go online can be " +"incremented following unsuccessful attempts to go online." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2876 +msgid "A value of 0 disables the incrementing behaviour." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2879 +msgid "" +"The value of this parameter should be set in correlation to offline_timeout " +"parameter value." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2883 +msgid "" +"With offline_timeout set to 60 (default value) there is no point in setting " +"offline_timeout_max to less than 120 as it will saturate instantly. General " +"rule here should be to set offline_timeout_max to at least 4 times " +"offline_timeout." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2889 +msgid "" +"Although a value between 0 and offline_timeout may be specified, it has the " +"effect of overriding the offline_timeout value so is of little use." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2894 +msgid "Default: 3600" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2900 +msgid "offline_timeout_random_offset (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2903 +msgid "" +"When SSSD is in offline mode it keeps probing backend servers in specified " +"time intervals:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2910 +msgid "" +"This parameter controls the value of the random offset used for the above " +"equation. Final random_offset value will be random number in range:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2915 +msgid "[0 - offline_timeout_random_offset]" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2918 +msgid "A value of 0 disables the random offset addition." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2921 +msgid "Default: 30" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2802 +#: sssd.conf.5.xml:2927 msgid "refresh_expired_interval (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2805 +#: sssd.conf.5.xml:2930 msgid "" "Specifies how many seconds SSSD has to wait before triggering a background " "refresh task which will refresh all expired or nearly expired records." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2810 +#: sssd.conf.5.xml:2935 msgid "" "The background refresh will process users, groups and netgroups in the " "cache. For users who have performed the initgroups (get group membership for " @@ -3335,17 +3489,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2818 +#: sssd.conf.5.xml:2943 msgid "This option is automatically inherited for all trusted domains." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2822 +#: sssd.conf.5.xml:2947 msgid "You can consider setting this value to 3/4 * entry_cache_timeout." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2826 +#: sssd.conf.5.xml:2951 msgid "" "Cache entry will be refreshed by background task when 2/3 of cache timeout " "has already passed. If there are existing cached entries, the background " @@ -3357,18 +3511,18 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2839 sssd-ldap.5.xml:406 sssd-ldap.5.xml:1834 -#: sssd-ipa.5.xml:255 +#: sssd.conf.5.xml:2964 sssd-ldap.5.xml:406 sssd-ldap.5.xml:1834 +#: sssd-ipa.5.xml:250 msgid "Default: 0 (disabled)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2845 -msgid "cache_credentials (bool)" +#: sssd.conf.5.xml:2970 +msgid "cache_credentials (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2848 +#: sssd.conf.5.xml:2973 msgid "" "Determines if user credentials are also cached in the local LDB cache. The " "cached credentials refer to passwords, which includes the first (long term) " @@ -3379,7 +3533,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2859 +#: sssd.conf.5.xml:2984 msgid "" "Take a note that while credentials are stored as a salted SHA512 hash, this " "still potentially poses some security risk in case an attacker manages to " @@ -3388,12 +3542,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2873 +#: sssd.conf.5.xml:2998 msgid "cache_credentials_minimal_first_factor_length (int)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2876 +#: sssd.conf.5.xml:3001 msgid "" "If 2-Factor-Authentication (2FA) is used and credentials should be saved " "this value determines the minimal length the first authentication factor " @@ -3401,19 +3555,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2883 +#: sssd.conf.5.xml:3008 msgid "" "This should avoid that the short PINs of a PIN based 2FA scheme are saved in " "the cache which would make them easy targets for brute-force attacks." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2894 +#: sssd.conf.5.xml:3019 msgid "account_cache_expiration (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2897 +#: sssd.conf.5.xml:3022 msgid "" "Number of days entries are left in cache after last successful login before " "being removed during a cleanup of the cache. 0 means keep forever. The " @@ -3422,17 +3576,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2904 +#: sssd.conf.5.xml:3029 msgid "Default: 0 (unlimited)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2909 +#: sssd.conf.5.xml:3034 msgid "pwd_expiration_warning (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2920 +#: sssd.conf.5.xml:3045 msgid "" "Please note that the backend server has to provide information about the " "expiration time of the password. If this information is missing, sssd " @@ -3441,28 +3595,28 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2927 +#: sssd.conf.5.xml:3052 msgid "Default: 7 (Kerberos), 0 (LDAP)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2933 +#: sssd.conf.5.xml:3058 msgid "id_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2936 +#: sssd.conf.5.xml:3061 msgid "" "The identification provider used for the domain. Supported ID providers are:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2940 +#: sssd.conf.5.xml:3065 msgid "<quote>proxy</quote>: Support a legacy NSS provider." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2943 +#: sssd.conf.5.xml:3068 msgid "" "<quote>ldap</quote>: LDAP provider. See <citerefentry> <refentrytitle>sssd-" "ldap</refentrytitle> <manvolnum>5</manvolnum> </citerefentry> for more " @@ -3470,8 +3624,8 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2951 sssd.conf.5.xml:3070 sssd.conf.5.xml:3129 -#: sssd.conf.5.xml:3192 +#: sssd.conf.5.xml:3076 sssd.conf.5.xml:3200 sssd.conf.5.xml:3259 +#: sssd.conf.5.xml:3322 msgid "" "<quote>ipa</quote>: FreeIPA and Red Hat Identity Management provider. See " "<citerefentry> <refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</" @@ -3479,8 +3633,8 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2960 sssd.conf.5.xml:3079 sssd.conf.5.xml:3138 -#: sssd.conf.5.xml:3201 +#: sssd.conf.5.xml:3085 sssd.conf.5.xml:3209 sssd.conf.5.xml:3268 +#: sssd.conf.5.xml:3331 msgid "" "<quote>ad</quote>: Active Directory provider. See <citerefentry> " "<refentrytitle>sssd-ad</refentrytitle> <manvolnum>5</manvolnum> </" @@ -3488,27 +3642,34 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2968 +#: sssd.conf.5.xml:3093 msgid "" "<quote>idp</quote>: Provider for OAuth 2.0/OIDC based Identity Providers " "(IdP). See <citerefentry> <refentrytitle>sssd-idp</refentrytitle> " "<manvolnum>5</manvolnum> </citerefentry> for more information." msgstr "" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3101 +msgid "" +"Default: Not set (This is a mandatory setting that must be explicitly " +"defined for each configured domain)." +msgstr "" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2979 -msgid "use_fully_qualified_names (bool)" +#: sssd.conf.5.xml:3109 +msgid "use_fully_qualified_names (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2982 +#: sssd.conf.5.xml:3112 msgid "" "Use the full name and domain (as formatted by the domain's full_name_format) " "as the user's login name reported to NSS." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2987 +#: sssd.conf.5.xml:3117 msgid "" "If set to TRUE, all requests to this domain must use fully qualified names. " "For example, if used in EXAMPLE domain that contains a \"test\" user, " @@ -3517,7 +3678,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2995 +#: sssd.conf.5.xml:3125 msgid "" "NOTE: This option has no effect on netgroup lookups due to their tendency to " "include nested netgroups without qualified names. For netgroups, all domains " @@ -3525,24 +3686,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3002 +#: sssd.conf.5.xml:3132 msgid "" "Default: FALSE (TRUE for trusted domain/sub-domains or if " "default_domain_suffix is used)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3009 -msgid "ignore_group_members (bool)" +#: sssd.conf.5.xml:3139 +msgid "ignore_group_members (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3012 +#: sssd.conf.5.xml:3142 msgid "Do not return group members for group lookups." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3015 +#: sssd.conf.5.xml:3145 msgid "" "If set to TRUE, the group membership attribute is not requested from the " "ldap server, and group members are not returned when processing group lookup " @@ -3554,7 +3715,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3033 +#: sssd.conf.5.xml:3163 msgid "" "Enabling this option can also make access provider checks for group " "membership significantly faster, especially for groups containing many " @@ -3562,7 +3723,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3039 sssd.conf.5.xml:3767 sssd-ldap.5.xml:401 +#: sssd.conf.5.xml:3169 sssd.conf.5.xml:3951 sssd-ldap.5.xml:401 #: sssd-ldap.5.xml:454 sssd-ldap.5.xml:529 sssd-ldap.5.xml:576 #: sssd-ldap.5.xml:599 sssd-ldap.5.xml:638 sssd-ldap.5.xml:657 #: sssd-ldap.5.xml:681 sssd-ldap.5.xml:1114 sssd-ldap.5.xml:1147 @@ -3572,19 +3733,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3049 +#: sssd.conf.5.xml:3179 msgid "auth_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3052 +#: sssd.conf.5.xml:3182 msgid "" "The authentication provider used for the domain. Supported auth providers " "are:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3056 sssd.conf.5.xml:3122 +#: sssd.conf.5.xml:3186 sssd.conf.5.xml:3252 msgid "" "<quote>ldap</quote> for native LDAP authentication. See <citerefentry> " "<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> </" @@ -3592,7 +3753,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3063 +#: sssd.conf.5.xml:3193 msgid "" "<quote>krb5</quote> for Kerberos authentication. See <citerefentry> " "<refentrytitle>sssd-krb5</refentrytitle> <manvolnum>5</manvolnum> </" @@ -3600,7 +3761,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3087 +#: sssd.conf.5.xml:3217 msgid "" "<quote>idp</quote>: Provider for OAuth 2.0/OIDC based authentication. See " "<citerefentry> <refentrytitle>sssd-idp</refentrytitle> <manvolnum>5</" @@ -3608,30 +3769,30 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3095 +#: sssd.conf.5.xml:3225 msgid "" "<quote>proxy</quote> for relaying authentication to some other PAM target." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3098 +#: sssd.conf.5.xml:3228 msgid "<quote>none</quote> disables authentication explicitly." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3101 +#: sssd.conf.5.xml:3231 msgid "" "Default: <quote>id_provider</quote> is used if it is set and can handle " "authentication requests." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3107 +#: sssd.conf.5.xml:3237 msgid "access_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3110 +#: sssd.conf.5.xml:3240 msgid "" "The access control provider used for the domain. There are two built-in " "access providers (in addition to any included in installed backends) " @@ -3639,17 +3800,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3116 +#: sssd.conf.5.xml:3246 msgid "<quote>permit</quote> always allow access." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3119 +#: sssd.conf.5.xml:3249 msgid "<quote>deny</quote> always deny access." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3146 +#: sssd.conf.5.xml:3276 msgid "" "<quote>simple</quote> access control based on access or deny lists. See " "<citerefentry> <refentrytitle>sssd-simple</refentrytitle> <manvolnum>5</" @@ -3658,7 +3819,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3153 +#: sssd.conf.5.xml:3283 msgid "" "<quote>krb5</quote>: .k5login based access control. See <citerefentry> " "<refentrytitle>sssd-krb5</refentrytitle> <manvolnum>5</manvolnum></" @@ -3666,29 +3827,29 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3160 +#: sssd.conf.5.xml:3290 msgid "<quote>proxy</quote> for relaying access control to another PAM module." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3163 +#: sssd.conf.5.xml:3293 msgid "Default: <quote>permit</quote>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3168 +#: sssd.conf.5.xml:3298 msgid "chpass_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3171 +#: sssd.conf.5.xml:3301 msgid "" "The provider which should handle change password operations for the domain. " "Supported change password providers are:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3176 +#: sssd.conf.5.xml:3306 msgid "" "<quote>ldap</quote> to change a password stored in a LDAP server. See " "<citerefentry> <refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</" @@ -3696,7 +3857,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3184 +#: sssd.conf.5.xml:3314 msgid "" "<quote>krb5</quote> to change the Kerberos password. See <citerefentry> " "<refentrytitle>sssd-krb5</refentrytitle> <manvolnum>5</manvolnum> </" @@ -3704,35 +3865,35 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3209 +#: sssd.conf.5.xml:3339 msgid "" "<quote>proxy</quote> for relaying password changes to some other PAM target." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3213 +#: sssd.conf.5.xml:3343 msgid "<quote>none</quote> disallows password changes explicitly." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3216 +#: sssd.conf.5.xml:3346 msgid "" "Default: <quote>auth_provider</quote> is used if it is set and can handle " "change password requests." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3223 +#: sssd.conf.5.xml:3353 msgid "sudo_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3226 +#: sssd.conf.5.xml:3356 msgid "The SUDO provider used for the domain. Supported SUDO providers are:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3230 +#: sssd.conf.5.xml:3360 msgid "" "<quote>ldap</quote> for rules stored in LDAP. See <citerefentry> " "<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> </" @@ -3740,33 +3901,33 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3238 +#: sssd.conf.5.xml:3368 msgid "" "<quote>ipa</quote> the same as <quote>ldap</quote> but with IPA default " "settings." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3242 +#: sssd.conf.5.xml:3372 msgid "" "<quote>ad</quote> the same as <quote>ldap</quote> but with AD default " "settings." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3246 +#: sssd.conf.5.xml:3376 msgid "<quote>none</quote> disables SUDO explicitly." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3249 +#: sssd.conf.5.xml:3379 msgid "" "Default: The value of <quote>id_provider</quote> is used if it is set and " "can handle sudo requests." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3253 +#: sssd.conf.5.xml:3383 msgid "" "The detailed instructions for configuration of sudo_provider are in the " "manual page <citerefentry> <refentrytitle>sssd-sudo</refentrytitle> " @@ -3777,7 +3938,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3268 +#: sssd.conf.5.xml:3398 msgid "" "<emphasis>NOTE:</emphasis> Sudo rules are periodically downloaded in the " "background unless the sudo provider is explicitly disabled. Set " @@ -3786,12 +3947,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3278 +#: sssd.conf.5.xml:3408 msgid "selinux_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3281 +#: sssd.conf.5.xml:3411 msgid "" "The provider which should handle loading of selinux settings. Note that this " "provider will be called right after access provider ends. Supported selinux " @@ -3799,7 +3960,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3287 +#: sssd.conf.5.xml:3417 msgid "" "<quote>ipa</quote> to load selinux settings from an IPA server. See " "<citerefentry> <refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</" @@ -3807,31 +3968,32 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3295 +#: sssd.conf.5.xml:3425 msgid "<quote>none</quote> disallows fetching selinux settings explicitly." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3298 +#: sssd.conf.5.xml:3428 msgid "" -"Default: <quote>id_provider</quote> is used if it is set and can handle " -"selinux loading requests." +"Default: the value of <quote>id_provider</quote> is used if it is set and " +"can handle selinux loading requests. Otherwise the result is the same as if " +"the selinux_provider is set to none." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3304 +#: sssd.conf.5.xml:3435 msgid "subdomains_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3307 +#: sssd.conf.5.xml:3438 msgid "" "The provider which should handle fetching of subdomains. This value should " "be always the same as id_provider. Supported subdomain providers are:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3313 +#: sssd.conf.5.xml:3444 msgid "" "<quote>ipa</quote> to load a list of subdomains from an IPA server. See " "<citerefentry> <refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</" @@ -3839,7 +4001,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3322 +#: sssd.conf.5.xml:3453 msgid "" "<quote>ad</quote> to load a list of subdomains from an Active Directory " "server. See <citerefentry> <refentrytitle>sssd-ad</refentrytitle> " @@ -3848,24 +4010,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3331 +#: sssd.conf.5.xml:3462 msgid "<quote>none</quote> disallows fetching subdomains explicitly." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3335 +#: sssd.conf.5.xml:3466 msgid "" "Default: The value of <quote>id_provider</quote> is used if it is set and " "can handle subdomain requests." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3341 +#: sssd.conf.5.xml:3472 msgid "session_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3344 +#: sssd.conf.5.xml:3475 msgid "" "The provider which configures and manages user session related tasks. The " "only user session task currently provided is the integration with Fleet " @@ -3873,34 +4035,34 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3351 +#: sssd.conf.5.xml:3482 msgid "<quote>ipa</quote> to allow performing user session related tasks." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3355 +#: sssd.conf.5.xml:3486 msgid "" "<quote>none</quote> does not perform any kind of user session related tasks." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3359 +#: sssd.conf.5.xml:3490 msgid "Default: <quote>none</quote>." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3365 +#: sssd.conf.5.xml:3496 msgid "autofs_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3368 +#: sssd.conf.5.xml:3499 msgid "" "The autofs provider used for the domain. Supported autofs providers are:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3372 +#: sssd.conf.5.xml:3503 msgid "" "<quote>ldap</quote> to load maps stored in LDAP. See <citerefentry> " "<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> </" @@ -3908,7 +4070,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3379 +#: sssd.conf.5.xml:3510 msgid "" "<quote>ipa</quote> to load maps stored in an IPA server. See <citerefentry> " "<refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</manvolnum> </" @@ -3916,7 +4078,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3387 +#: sssd.conf.5.xml:3518 msgid "" "<quote>ad</quote> to load maps stored in an AD server. See <citerefentry> " "<refentrytitle>sssd-ad</refentrytitle> <manvolnum>5</manvolnum> </" @@ -3924,31 +4086,31 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3396 +#: sssd.conf.5.xml:3527 msgid "<quote>none</quote> disables autofs explicitly." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3399 +#: sssd.conf.5.xml:3530 msgid "" "Default: The value of <quote>id_provider</quote> is used if it is set and " "can handle autofs requests." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3406 +#: sssd.conf.5.xml:3537 msgid "hostid_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3409 +#: sssd.conf.5.xml:3540 msgid "" "The provider used for retrieving host identity information. Supported " "hostid providers are:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3413 +#: sssd.conf.5.xml:3544 msgid "" "<quote>ipa</quote> to load host identity stored in an IPA server. See " "<citerefentry> <refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</" @@ -3956,38 +4118,38 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3421 +#: sssd.conf.5.xml:3552 msgid "<quote>none</quote> disables hostid explicitly." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3424 +#: sssd.conf.5.xml:3555 msgid "" "Default: The value of <quote>id_provider</quote> is used if it is set and " "can handle hostid requests." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3431 +#: sssd.conf.5.xml:3562 msgid "resolver_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3434 +#: sssd.conf.5.xml:3565 msgid "" "The provider which should handle hosts and networks lookups. Supported " "resolver providers are:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3438 +#: sssd.conf.5.xml:3569 msgid "" "<quote>proxy</quote> to forward lookups to another NSS library. See " "<quote>proxy_resolver_lib_name</quote>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3442 +#: sssd.conf.5.xml:3573 msgid "" "<quote>ldap</quote> to fetch hosts and networks stored in LDAP. See " "<citerefentry> <refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</" @@ -3995,7 +4157,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3449 +#: sssd.conf.5.xml:3580 msgid "" "<quote>ad</quote> to fetch hosts and networks stored in AD. See " "<citerefentry> <refentrytitle>sssd-ad</refentrytitle> <manvolnum>5</" @@ -4004,19 +4166,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3457 +#: sssd.conf.5.xml:3588 msgid "<quote>none</quote> disallows fetching hosts and networks explicitly." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3460 +#: sssd.conf.5.xml:3591 msgid "" "Default: The value of <quote>id_provider</quote> is used if it is set and " "can handle resolver requests." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3470 +#: sssd.conf.5.xml:3601 msgid "" "Regular expression for this domain that describes how to parse the string " "containing user name and domain into these components. The \"domain\" can " @@ -4026,24 +4188,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3479 +#: sssd.conf.5.xml:3610 msgid "" "Default: <quote>^((?P<name>.+)@(?P<domain>[^@]*)|(?P<name>" "[^@]+))$</quote> which allows two different styles for user names:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:3484 sssd.conf.5.xml:3498 +#: sssd.conf.5.xml:3615 sssd.conf.5.xml:3629 msgid "username" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:3487 sssd.conf.5.xml:3501 +#: sssd.conf.5.xml:3618 sssd.conf.5.xml:3632 msgid "username@domain.name" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3492 +#: sssd.conf.5.xml:3623 msgid "" "Default for the AD and IPA provider: <quote>^(((?P<domain>[^\\\\]+)\\\\" "(?P<name>.+))|((?P<name>.+)@(?P<domain>[^@]+))|((?" @@ -4052,19 +4214,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:3504 +#: sssd.conf.5.xml:3635 msgid "domain\\username" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3507 +#: sssd.conf.5.xml:3638 msgid "" "While the first two correspond to the general default the third one is " "introduced to allow easy integration of users from Windows domains." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3512 +#: sssd.conf.5.xml:3643 msgid "" "The default re_expression uses the <quote>@</quote> character as a separator " "between the name and the domain. As a result of this setting the default " @@ -4074,89 +4236,94 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3564 +#: sssd.conf.5.xml:3695 msgid "Default: <quote>%1$s@%2$s</quote>." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3570 +#: sssd.conf.5.xml:3701 msgid "lookup_family_order (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3573 +#: sssd.conf.5.xml:3704 msgid "" "Provides the ability to select preferred address family to use when " "performing DNS lookups." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3577 +#: sssd.conf.5.xml:3708 msgid "Supported values:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3580 +#: sssd.conf.5.xml:3711 msgid "ipv4_first: Try looking up IPv4 address, if that fails, try IPv6" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3583 +#: sssd.conf.5.xml:3714 msgid "ipv4_only: Only attempt to resolve hostnames to IPv4 addresses." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3586 +#: sssd.conf.5.xml:3717 msgid "ipv6_first: Try looking up IPv6 address, if that fails, try IPv4" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3589 +#: sssd.conf.5.xml:3720 msgid "ipv6_only: Only attempt to resolve hostnames to IPv6 addresses." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3592 +#: sssd.conf.5.xml:3723 msgid "Default: ipv4_first" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3598 +#: sssd.conf.5.xml:3729 msgid "dns_resolver_server_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3601 +#: sssd.conf.5.xml:3732 msgid "" -"Defines the amount of time (in milliseconds) SSSD would try to talk to DNS " -"server before trying next DNS server." +"Defines the timeout duration (in milliseconds) SSSD waits for a DNS server " +"to respond before moving to the next one." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3606 +#: sssd.conf.5.xml:3737 msgid "" "The AD provider will use this option for the CLDAP ping timeouts as well." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3610 sssd.conf.5.xml:3630 sssd.conf.5.xml:3651 +#: sssd.conf.5.xml:3741 sssd.conf.5.xml:3777 sssd.conf.5.xml:3814 msgid "" -"Please see the section <quote>FAILOVER</quote> for more information about " -"the service resolution." +"Please see the section <quote>FAILOVER</quote> in <citerefentry> " +"<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> </" +"citerefentry>, <citerefentry> <refentrytitle>sssd-krb5</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry>, <citerefentry> <refentrytitle>sssd-" +"ipa</refentrytitle> <manvolnum>5</manvolnum> </citerefentry> or " +"<citerefentry> <refentrytitle>sssd-ad</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry> for more information about the service resolution." msgstr "" #. type: Content of: <refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3615 sssd-ldap.5.xml:700 include/failover.xml:84 +#: sssd.conf.5.xml:3762 sssd-ldap.5.xml:700 include/failover.xml:84 msgid "Default: 1000" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3621 +#: sssd.conf.5.xml:3768 msgid "dns_resolver_op_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3624 +#: sssd.conf.5.xml:3771 msgid "" "Defines the amount of time (in seconds) to wait to resolve single DNS query " "(e.g. resolution of a hostname or an SRV record) before trying the next " @@ -4164,17 +4331,17 @@ msgid "" msgstr "" #. type: Content of: <refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3635 include/failover.xml:100 +#: sssd.conf.5.xml:3798 include/failover.xml:100 msgid "Default: 3" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3641 +#: sssd.conf.5.xml:3804 msgid "dns_resolver_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3644 +#: sssd.conf.5.xml:3807 msgid "" "Defines the amount of time (in seconds) to wait for a reply from the " "internal fail over service before assuming that the service is unreachable. " @@ -4183,12 +4350,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3662 -msgid "dns_resolver_use_search_list (bool)" +#: sssd.conf.5.xml:3841 +msgid "dns_resolver_use_search_list (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3665 +#: sssd.conf.5.xml:3844 msgid "" "Normally, the DNS resolver searches the domain list defined in the " "\"search\" directive from the resolv.conf file. This can lead to delays in " @@ -4196,7 +4363,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3671 +#: sssd.conf.5.xml:3850 msgid "" "If fully qualified domain names (or _srv_) are used in the SSSD " "configuration, setting this option to FALSE can prevent unnecessary DNS " @@ -4204,34 +4371,34 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3677 +#: sssd.conf.5.xml:3856 msgid "Default: TRUE" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3683 +#: sssd.conf.5.xml:3862 msgid "dns_discovery_domain (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3686 +#: sssd.conf.5.xml:3865 msgid "" "If service discovery is used in the back end, specifies the domain part of " "the service discovery DNS query." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3690 +#: sssd.conf.5.xml:3869 msgid "Default: Use the domain part of machine's hostname" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3696 +#: sssd.conf.5.xml:3875 msgid "failover_primary_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3699 +#: sssd.conf.5.xml:3878 msgid "" "When no primary server is available, SSSD fails over to a backup server. " "This option defines the number of seconds SSSD waits before attempting to " @@ -4239,57 +4406,66 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3706 +#: sssd.conf.5.xml:3885 msgid "Note: The minimum value is 31." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3709 +#: sssd.conf.5.xml:3888 msgid "Default: 31" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3715 +#: sssd.conf.5.xml:3894 msgid "override_gid (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3718 -msgid "Override the primary GID value with the one specified." +#: sssd.conf.5.xml:3897 +msgid "" +"Override the primary GID value for all users in the domain with specified " +"value." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3901 +msgid "" +"Default: not set (Use the primary GID value retrieved from the identity " +"provider)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3724 +#: sssd.conf.5.xml:3908 msgid "case_sensitive (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3731 +#: sssd.conf.5.xml:3915 msgid "True" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3734 +#: sssd.conf.5.xml:3918 msgid "Case sensitive. This value is invalid for AD provider." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3740 +#: sssd.conf.5.xml:3924 msgid "False" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3742 +#: sssd.conf.5.xml:3926 msgid "Case insensitive." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3746 +#: sssd.conf.5.xml:3930 msgid "Preserving" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3749 +#: sssd.conf.5.xml:3933 msgid "" "Same as False (case insensitive), but does not lowercase names in the result " "of NSS operations. Note that name aliases (and in case of services also " @@ -4297,31 +4473,57 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3757 +#: sssd.conf.5.xml:3941 msgid "" "If you want to set this value for trusted domain with IPA provider, you need " "to set it on both the client and SSSD on the server." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3727 +#: sssd.conf.5.xml:3911 msgid "" "Treat user and group names as case sensitive. Possible option values are: " "<placeholder type=\"variablelist\" id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3772 +#: sssd.conf.5.xml:3956 msgid "Default: True (False for AD provider)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3778 +#: sssd.conf.5.xml:3962 +msgid "avoid_by_id_lookups (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3965 +msgid "" +"If this option is set to 'true' SSSD will try to avoid sending lookups by ID " +"to the backend and will switch to a lookup by name if a cached object with a " +"matching ID can be found." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3971 +msgid "" +"This option can e.g. be used in cases where searches by ID are expensive on " +"the server side because of missing indexes or are not even possible, e.g. " +"due to non-reversible POSIX id-mapping." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3978 +msgid "Default: False (True for IdP provider)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:3984 msgid "subdomain_inherit (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3781 +#: sssd.conf.5.xml:3987 msgid "" "Specifies a list of configuration parameters that should be inherited by a " "subdomain. Please note that only selected parameters can be inherited. " @@ -4329,89 +4531,89 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3787 +#: sssd.conf.5.xml:3993 msgid "ldap_search_timeout" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3790 +#: sssd.conf.5.xml:3996 msgid "ldap_network_timeout" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3793 +#: sssd.conf.5.xml:3999 msgid "ldap_opt_timeout" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3796 +#: sssd.conf.5.xml:4002 msgid "ldap_offline_timeout" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3799 +#: sssd.conf.5.xml:4005 msgid "ldap_purge_cache_timeout" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3802 +#: sssd.conf.5.xml:4008 msgid "ldap_purge_cache_offset" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3805 +#: sssd.conf.5.xml:4011 msgid "" "ldap_krb5_keytab (the value of krb5_keytab will be used if ldap_krb5_keytab " "is not set explicitly)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3809 +#: sssd.conf.5.xml:4015 msgid "ldap_krb5_ticket_lifetime" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3812 +#: sssd.conf.5.xml:4018 msgid "ldap_connection_expire_timeout" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3815 +#: sssd.conf.5.xml:4021 msgid "ldap_connection_expire_offset" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3818 +#: sssd.conf.5.xml:4024 msgid "ldap_connection_idle_timeout" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3821 sssd-ldap.5.xml:446 +#: sssd.conf.5.xml:4027 sssd-ldap.5.xml:446 msgid "ldap_use_tokengroups" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3824 +#: sssd.conf.5.xml:4030 msgid "ldap_user_principal" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3827 +#: sssd.conf.5.xml:4033 msgid "ignore_group_members" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3830 +#: sssd.conf.5.xml:4036 msgid "auto_private_groups" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3833 +#: sssd.conf.5.xml:4039 msgid "case_sensitive" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:3838 +#: sssd.conf.5.xml:4044 #, no-wrap msgid "" "subdomain_inherit = ldap_purge_cache_timeout\n" @@ -4419,27 +4621,27 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3845 +#: sssd.conf.5.xml:4051 msgid "Note: This option only works with the IPA and AD provider." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3852 +#: sssd.conf.5.xml:4058 msgid "subdomain_homedir (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3863 +#: sssd.conf.5.xml:4069 msgid "%F" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3864 +#: sssd.conf.5.xml:4070 msgid "flat (NetBIOS) name of a subdomain." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3855 +#: sssd.conf.5.xml:4061 msgid "" "Use this homedir as default value for all subdomains within this domain in " "IPA AD trust. See <emphasis>override_homedir</emphasis> for info about " @@ -4449,55 +4651,55 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3869 +#: sssd.conf.5.xml:4075 msgid "" "The value can be overridden by <emphasis>override_homedir</emphasis> option." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3873 +#: sssd.conf.5.xml:4079 msgid "Default: <filename>/home/%d/%u</filename>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3878 +#: sssd.conf.5.xml:4084 msgid "realmd_tags (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3881 +#: sssd.conf.5.xml:4087 msgid "" "Various tags stored by the realmd configuration service for this domain." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3887 +#: sssd.conf.5.xml:4093 msgid "cached_auth_timeout (int)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3890 +#: sssd.conf.5.xml:4096 msgid "" -"Specifies time in seconds since last successful online authentication for " -"which user will be authenticated using cached credentials while SSSD is in " -"the online mode. If the credentials are incorrect, SSSD falls back to online " -"authentication." +"Specifies the number of seconds since the last successful online " +"authentication during which SSSD will authenticate users via cached " +"credentials, even while online. If the cached authentication fails, SSSD " +"immediately falls back to online authentication." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3898 +#: sssd.conf.5.xml:4103 msgid "" "This option's value is inherited by all trusted domains. At the moment it is " "not possible to set a different value per trusted domain." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3903 +#: sssd.conf.5.xml:4108 msgid "Special value 0 implies that this feature is disabled." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3907 +#: sssd.conf.5.xml:4112 msgid "" "Please note that if <quote>cached_auth_timeout</quote> is longer than " "<quote>pam_id_timeout</quote> then the back end could be called to handle " @@ -4505,12 +4707,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3918 +#: sssd.conf.5.xml:4123 msgid "local_auth_policy (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3921 +#: sssd.conf.5.xml:4126 msgid "" "Local authentication methods policy. Some backends (i.e. LDAP, proxy " "provider) only support a password based authentication, while others can " @@ -4522,7 +4724,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3933 +#: sssd.conf.5.xml:4138 msgid "" "There are three possible values for this option: match, only, enable. " "<quote>match</quote> is used to match offline and online states for Kerberos " @@ -4534,7 +4736,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3946 +#: sssd.conf.5.xml:4151 msgid "" "The following table shows which authentication methods, if configured " "properly, are currently enabled or disabled for each backend, with the " @@ -4542,42 +4744,47 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> -#: sssd.conf.5.xml:3959 +#: sssd.conf.5.xml:4164 msgid "local_auth_policy = match (default)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> -#: sssd.conf.5.xml:3960 +#: sssd.conf.5.xml:4165 msgid "Passkey" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> -#: sssd.conf.5.xml:3961 +#: sssd.conf.5.xml:4166 msgid "Smartcard" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:3964 sssd-ldap.5.xml:228 +#: sssd.conf.5.xml:4169 sssd-ldap.5.xml:228 msgid "IPA" msgstr "" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry><para> +#: sssd.conf.5.xml:4169 sssd.conf.5.xml:4170 sssd.conf.5.xml:4173 +msgid "enabled" +msgstr "" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:3967 sssd-ldap.5.xml:233 +#: sssd.conf.5.xml:4172 sssd-ldap.5.xml:233 msgid "AD" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry><para> -#: sssd.conf.5.xml:3967 sssd.conf.5.xml:3970 sssd.conf.5.xml:3971 +#: sssd.conf.5.xml:4172 sssd.conf.5.xml:4175 sssd.conf.5.xml:4176 msgid "disabled" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry> -#: sssd.conf.5.xml:3970 +#: sssd.conf.5.xml:4175 msgid "LDAP" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3975 +#: sssd.conf.5.xml:4180 msgid "" "Please note that if local Smartcard authentication is enabled and a " "Smartcard is present, Smartcard authentication will be preferred over the " @@ -4586,7 +4793,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:3987 +#: sssd.conf.5.xml:4192 #, no-wrap msgid "" "[domain/shadowutils]\n" @@ -4597,7 +4804,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3983 +#: sssd.conf.5.xml:4188 msgid "" "The following configuration example allows local users to authenticate " "locally using any enabled method (i.e. smartcard, passkey). <placeholder " @@ -4605,29 +4812,29 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3995 +#: sssd.conf.5.xml:4200 msgid "Default: match" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4000 +#: sssd.conf.5.xml:4205 msgid "auto_private_groups (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4006 +#: sssd.conf.5.xml:4211 msgid "true" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4009 +#: sssd.conf.5.xml:4214 msgid "" "Create user's private group unconditionally from user's UID number. The GID " "number is ignored in this case." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4013 +#: sssd.conf.5.xml:4218 msgid "" "NOTE: Because the GID number and the user private group are inferred from " "the UID number, it is not supported to have multiple entries with the same " @@ -4636,24 +4843,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4022 +#: sssd.conf.5.xml:4227 msgid "false" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4025 +#: sssd.conf.5.xml:4230 msgid "" "Always use the user's primary GID number. The GID number must refer to a " "group object in the LDAP database." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4031 +#: sssd.conf.5.xml:4236 msgid "hybrid" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4034 +#: sssd.conf.5.xml:4239 msgid "" "A primary group is autogenerated for user entries whose UID and GID numbers " "have the same value and at the same time the GID number does not correspond " @@ -4663,14 +4870,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4047 +#: sssd.conf.5.xml:4252 msgid "" "If the UID and GID of a user are different, then the GID must correspond to " "a group entry, otherwise the GID is simply not resolvable." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4054 +#: sssd.conf.5.xml:4259 msgid "" "This feature is useful for environments that wish to stop maintaining a " "separate group objects for the user private groups, but also wish to retain " @@ -4678,14 +4885,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4003 +#: sssd.conf.5.xml:4208 msgid "" "This option takes any of three available values: <placeholder " "type=\"variablelist\" id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4066 +#: sssd.conf.5.xml:4271 msgid "" "For the LDAP based id providers (LDAP, IPA and AD) the default for the " "configured domain is typically False because the sources have the concept of " @@ -4695,14 +4902,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4075 +#: sssd.conf.5.xml:4280 msgid "" "For subdomains, the default value is False for subdomains that use assigned " "POSIX IDs and True for subdomains that use automatic ID-mapping." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:4083 +#: sssd.conf.5.xml:4288 #, no-wrap msgid "" "[domain/forest.domain/sub.domain]\n" @@ -4710,7 +4917,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:4089 +#: sssd.conf.5.xml:4294 #, no-wrap msgid "" "[domain/forest.domain]\n" @@ -4719,7 +4926,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4080 +#: sssd.conf.5.xml:4285 msgid "" "The value of auto_private_groups can either be set per subdomains in a " "subsection, for example: <placeholder type=\"programlisting\" id=\"0\"/> or " @@ -4728,7 +4935,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:2503 +#: sssd.conf.5.xml:2549 msgid "" "These configuration options can be present in a domain configuration " "section, that is, in a section called <quote>[domain/<replaceable>NAME</" @@ -4736,17 +4943,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4104 +#: sssd.conf.5.xml:4309 msgid "proxy_pam_target (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4107 +#: sssd.conf.5.xml:4312 msgid "The proxy target PAM proxies to." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4110 +#: sssd.conf.5.xml:4315 msgid "" "Default: not set by default, you have to take an existing pam configuration " "or create a new one and add the service name here. As an alternative you can " @@ -4754,12 +4961,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4120 +#: sssd.conf.5.xml:4325 msgid "proxy_lib_name (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4123 +#: sssd.conf.5.xml:4328 msgid "" "The name of the NSS library to use in proxy domains. The NSS functions " "searched for in the library are in the form of _nss_$(libName)_$(function), " @@ -4767,12 +4974,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4133 +#: sssd.conf.5.xml:4338 msgid "proxy_resolver_lib_name (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4136 +#: sssd.conf.5.xml:4341 msgid "" "The name of the NSS library to use for hosts and networks lookups in proxy " "domains. The NSS functions searched for in the library are in the form of " @@ -4780,12 +4987,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4147 +#: sssd.conf.5.xml:4352 msgid "proxy_fast_alias (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4150 +#: sssd.conf.5.xml:4355 msgid "" "When a user or group is looked up by name in the proxy provider, a second " "lookup by ID is performed to \"canonicalize\" the name in case the requested " @@ -4794,12 +5001,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4164 +#: sssd.conf.5.xml:4369 msgid "proxy_max_children (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4167 +#: sssd.conf.5.xml:4372 msgid "" "This option specifies the number of pre-forked proxy children. It is useful " "for high-load SSSD environments where sssd may run out of available child " @@ -4807,19 +5014,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4100 +#: sssd.conf.5.xml:4305 msgid "" "Options valid for proxy domains. <placeholder type=\"variablelist\" " "id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:4183 +#: sssd.conf.5.xml:4388 msgid "Application domains" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:4185 +#: sssd.conf.5.xml:4390 msgid "" "SSSD, with its D-Bus interface (see <citerefentry> <refentrytitle>sssd-ifp</" "refentrytitle> <manvolnum>5</manvolnum> </citerefentry>) is appealing to " @@ -4836,7 +5043,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:4205 +#: sssd.conf.5.xml:4410 msgid "" "Please note that the application domain must still be explicitly enabled in " "the <quote>domains</quote> parameter so that the lookup order between the " @@ -4844,17 +5051,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><title> -#: sssd.conf.5.xml:4211 +#: sssd.conf.5.xml:4416 msgid "Application domain parameters" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4213 +#: sssd.conf.5.xml:4418 msgid "inherit_from (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4216 +#: sssd.conf.5.xml:4421 msgid "" "The SSSD POSIX-type domain the application domain inherits all settings " "from. The application domain can moreover add its own settings to the " @@ -4863,7 +5070,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:4230 +#: sssd.conf.5.xml:4435 msgid "" "The following example illustrates the use of an application domain. In this " "setup, the POSIX domain is connected to an LDAP server and is used by the OS " @@ -4873,7 +5080,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><programlisting> -#: sssd.conf.5.xml:4238 +#: sssd.conf.5.xml:4443 #, no-wrap msgid "" "[sssd]\n" @@ -4893,12 +5100,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:4258 +#: sssd.conf.5.xml:4463 msgid "TRUSTED DOMAIN SECTION" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4260 +#: sssd.conf.5.xml:4465 msgid "" "Some options used in the domain section can also be used in the trusted " "domain section, that is, in a section called <quote>[domain/" @@ -4909,69 +5116,79 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4267 +#: sssd.conf.5.xml:4472 msgid "ldap_search_base," msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4268 +#: sssd.conf.5.xml:4473 msgid "ldap_user_search_base," msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4269 +#: sssd.conf.5.xml:4474 msgid "ldap_group_search_base," msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4270 +#: sssd.conf.5.xml:4475 msgid "ldap_netgroup_search_base," msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4271 +#: sssd.conf.5.xml:4476 msgid "ldap_service_search_base," msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4272 +#: sssd.conf.5.xml:4477 msgid "ldap_sasl_mech," msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4273 +#: sssd.conf.5.xml:4478 msgid "ad_server," msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4274 +#: sssd.conf.5.xml:4479 msgid "ad_backup_server," msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4275 +#: sssd.conf.5.xml:4480 msgid "ad_site," msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:4276 sssd-ipa.5.xml:934 +#: sssd.conf.5.xml:4481 sssd-ipa.5.xml:929 msgid "use_fully_qualified_names" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4280 +#: sssd.conf.5.xml:4482 +msgid "pam_gssapi_services" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:4483 +msgid "pam_gssapi_check_upn" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:4485 msgid "" "For more details about these options see their individual description in the " "manual page." msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:4286 +#: sssd.conf.5.xml:4491 msgid "CERTIFICATE MAPPING SECTION" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4288 +#: sssd.conf.5.xml:4493 msgid "" "To allow authentication with Smartcards and certificates SSSD must be able " "to map certificates to users. This can be done by adding the full " @@ -4984,7 +5201,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4302 +#: sssd.conf.5.xml:4507 msgid "" "To make the mapping more flexible mapping and matching rules were added to " "SSSD (see <citerefentry> <refentrytitle>sss-certmap</refentrytitle> " @@ -4992,7 +5209,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4311 +#: sssd.conf.5.xml:4516 msgid "" "A mapping and matching rule can be added to the SSSD configuration in a " "section on its own with a name like <quote>[certmap/" @@ -5001,55 +5218,50 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4318 +#: sssd.conf.5.xml:4523 msgid "matchrule (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4321 +#: sssd.conf.5.xml:4526 msgid "" "Only certificates from the Smartcard which matches this rule will be " "processed, all others are ignored." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4325 +#: sssd.conf.5.xml:4530 msgid "" "Default: KRB5:<EKU>clientAuth, i.e. only certificates which have the " "Extended Key Usage <quote>clientAuth</quote>" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4332 +#: sssd.conf.5.xml:4537 msgid "maprule (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4335 +#: sssd.conf.5.xml:4540 msgid "Defines how the user is found for a given certificate." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:4341 +#: sssd.conf.5.xml:4546 msgid "" "LDAP:(userCertificate;binary={cert!bin}) for LDAP based providers like " "<quote>ldap</quote>, <quote>AD</quote> or <quote>ipa</quote>." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:4347 +#: sssd.conf.5.xml:4552 msgid "" "If maprule is not set and provider is <quote>proxy</quote>, the RULE_NAME " "name is assumed to be the name of the matching user." msgstr "" -#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4357 -msgid "domains (string)" -msgstr "" - #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4360 +#: sssd.conf.5.xml:4565 msgid "" "Comma separated list of domain names the rule should be applied. By default " "a rule is only valid in the domain configured in sssd.conf. If the provider " @@ -5058,17 +5270,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4367 +#: sssd.conf.5.xml:4572 msgid "Default: the configured domain in sssd.conf" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4372 +#: sssd.conf.5.xml:4577 msgid "priority (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4375 +#: sssd.conf.5.xml:4580 msgid "" "Unsigned integer value defining the priority of the rule. The higher the " "number the lower the priority. <quote>0</quote> stands for the highest " @@ -5076,17 +5288,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4381 +#: sssd.conf.5.xml:4586 msgid "Default: the lowest priority" msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:4389 +#: sssd.conf.5.xml:4594 msgid "PROMPTING CONFIGURATION SECTION" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4391 +#: sssd.conf.5.xml:4596 msgid "" "If a special file (<filename>/var/lib/sss/pubconf/pam_preauth_available</" "filename>) exists SSSD's PAM module pam_sss will ask SSSD to figure out " @@ -5096,7 +5308,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4399 +#: sssd.conf.5.xml:4604 msgid "" "With the growing number of authentication methods and the possibility that " "there are multiple ones for a single user the heuristic used by pam_sss to " @@ -5105,59 +5317,59 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4411 +#: sssd.conf.5.xml:4616 msgid "[prompting/password]" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4414 +#: sssd.conf.5.xml:4619 msgid "password_prompt" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4415 +#: sssd.conf.5.xml:4620 msgid "to change the string of the password prompt" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4413 +#: sssd.conf.5.xml:4618 msgid "" "to configure password prompting, allowed options are: <placeholder " "type=\"variablelist\" id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4423 +#: sssd.conf.5.xml:4628 msgid "[prompting/2fa]" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4427 +#: sssd.conf.5.xml:4632 msgid "first_prompt" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4428 +#: sssd.conf.5.xml:4633 msgid "to change the string of the prompt for the first factor" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4431 +#: sssd.conf.5.xml:4636 msgid "second_prompt" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4432 +#: sssd.conf.5.xml:4637 msgid "to change the string of the prompt for the second factor" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4435 +#: sssd.conf.5.xml:4640 msgid "single_prompt" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4436 +#: sssd.conf.5.xml:4641 msgid "" "boolean value, if True there will be only a single prompt using the value of " "first_prompt where it is expected that both factors are entered as a single " @@ -5166,7 +5378,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4425 +#: sssd.conf.5.xml:4630 msgid "" "to configure two-factor authentication prompting, allowed options are: " "<placeholder type=\"variablelist\" id=\"0\"/> If the second factor is " @@ -5175,7 +5387,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4449 +#: sssd.conf.5.xml:4654 msgid "" "Some clients, such as SSH with 'PasswordAuthentication yes', generate their " "own prompts and do not use prompts provided by SSSD or other PAM modules. " @@ -5186,17 +5398,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4464 +#: sssd.conf.5.xml:4669 msgid "[prompting/passkey]" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:4470 sssd-ad.5.xml:1022 +#: sssd.conf.5.xml:4675 sssd.conf.5.xml:4719 sssd-ad.5.xml:1027 msgid "interactive" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4472 +#: sssd.conf.5.xml:4677 msgid "" "boolean value, if True prompt a message and wait before testing the presence " "of a passkey device. Recommended if your device doesn’t have a tactile " @@ -5204,55 +5416,131 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4480 +#: sssd.conf.5.xml:4685 sssd.conf.5.xml:4735 msgid "interactive_prompt" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4482 +#: sssd.conf.5.xml:4687 sssd.conf.5.xml:4737 msgid "to change the message of the interactive prompt." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4487 +#: sssd.conf.5.xml:4692 msgid "touch" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4489 +#: sssd.conf.5.xml:4694 msgid "" "boolean value, if True prompt a message to remind the user to touch the " "device." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4495 +#: sssd.conf.5.xml:4700 msgid "touch_prompt" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4497 +#: sssd.conf.5.xml:4702 msgid "to change the message of the touch prompt." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4466 +#: sssd.conf.5.xml:4671 msgid "" "to configure passkey authentication prompting, allowed options are: " "<placeholder type=\"variablelist\" id=\"0\"/>" msgstr "" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4713 +msgid "[prompting/oauth2]" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4721 +msgid "" +"boolean value, if True prompt a message after asking the user to " +"authenticate, and wait before requesting the access token." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4725 +msgid "" +"If False, make sure to set the <quote>idp_request_timeout</quote> " +"sufficiently high, to give the user time to authenticate." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4715 +msgid "" +"to configure OAuth2 authentication prompting, allowed options are: " +"<placeholder type=\"variablelist\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4748 +msgid "[prompting/cert_auth]" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4754 +msgid "pin_prompt" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4756 +msgid "" +"to change the message which asks the user to enter the PIN at the computer " +"keyboard. At the end of the message the token name is printed." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4764 +msgid "keypad_prompt" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4766 +msgid "" +"to change the message which asks the user to enter the PIN at keypad of the " +"Smartcard reader. At the end of the message the token name is printed." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4774 +msgid "user_name_hint" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4776 +msgid "" +"boolean value, if True ask for a user name if no name was given before and " +"the found certificate can be mapped to more than one user." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4750 +msgid "" +"to configure Smartcard authentication prompting, allowed options are: " +"<placeholder type=\"variablelist\" id=\"0\"/>" +msgstr "" + #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4406 +#: sssd.conf.5.xml:4611 msgid "" "Each supported authentication method has its own configuration subsection " "under <quote>[prompting/...]</quote>. Currently there are: <placeholder " "type=\"variablelist\" id=\"0\"/> <placeholder type=\"variablelist\" id=\"1\"/" -"> <placeholder type=\"variablelist\" id=\"2\"/>" +"> <placeholder type=\"variablelist\" id=\"2\"/> <placeholder " +"type=\"variablelist\" id=\"3\"/> <placeholder type=\"variablelist\" id=\"4\"/" +">" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4508 +#: sssd.conf.5.xml:4792 msgid "" "It is possible to add a subsection for specific PAM services, e.g. " "<quote>[prompting/password/sshd]</quote> to individual change the prompting " @@ -5260,12 +5548,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:4515 pam_sss_gss.8.xml:157 idmap_sss.8.xml:43 +#: sssd.conf.5.xml:4799 pam_sss_gss.8.xml:157 idmap_sss.8.xml:43 msgid "EXAMPLES" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd.conf.5.xml:4521 +#: sssd.conf.5.xml:4805 #, no-wrap msgid "" "[sssd]\n" @@ -5294,7 +5582,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4517 +#: sssd.conf.5.xml:4801 msgid "" "1. The following example shows a typical SSSD config. It does not describe " "configuration of the domains themselves - refer to documentation on " @@ -5303,7 +5591,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd.conf.5.xml:4553 +#: sssd.conf.5.xml:4837 #, no-wrap msgid "" "[domain/ipa.com/child.ad.com]\n" @@ -5311,7 +5599,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4547 +#: sssd.conf.5.xml:4831 msgid "" "2. The following example shows configuration of IPA AD trust where the AD " "forest consists of two domains in a parent-child structure. Suppose IPA " @@ -5322,7 +5610,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd.conf.5.xml:4564 +#: sssd.conf.5.xml:4848 #, no-wrap msgid "" "[certmap/my.domain/rule_name]\n" @@ -5333,7 +5621,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4558 +#: sssd.conf.5.xml:4842 msgid "" "3. The following example shows the configuration of a certificate mapping " "rule. It is valid for the configured domain <quote>my.domain</quote> and " @@ -5530,7 +5818,7 @@ msgid "" "defaultNamingContext does not exist or has an empty value namingContexts is " "used. The namingContexts attribute must have a single value with the DN of " "the search base of the LDAP server to make this work. Multiple values are " -"are not supported." +"not supported." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> @@ -5831,15 +6119,15 @@ msgid "Optional. Use the given string as search base for host objects." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap.5.xml:472 sssd-ipa.5.xml:506 sssd-ipa.5.xml:525 sssd-ipa.5.xml:544 -#: sssd-ipa.5.xml:563 +#: sssd-ldap.5.xml:472 sssd-ipa.5.xml:501 sssd-ipa.5.xml:520 sssd-ipa.5.xml:539 +#: sssd-ipa.5.xml:558 msgid "" "See <quote>ldap_search_base</quote> for information about configuring " "multiple search bases." msgstr "" #. type: Content of: <listitem><para> -#: sssd-ldap.5.xml:477 sssd-ipa.5.xml:511 include/ldap_search_bases.xml:27 +#: sssd-ldap.5.xml:477 sssd-ipa.5.xml:506 include/ldap_search_bases.xml:27 msgid "Default: the value of <emphasis>ldap_search_base</emphasis>" msgstr "" @@ -5963,7 +6251,7 @@ msgid "" "closed early to ensure that a new query cannot require the connection to " "remain open past its expiration. This implies that connections will always " "be closed immediately and will never be reused if " -"<emphasis>ldap_connection_expire_timeout <= ldap_opt_timout</emphasis>" +"<emphasis>ldap_connection_expire_timeout <= ldap_opt_timeout</emphasis>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> @@ -6145,7 +6433,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:831 -msgid "ldap_ignore_unreadable_references (bool)" +msgid "ldap_ignore_unreadable_references (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> @@ -6470,7 +6758,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap.5.xml:1152 sssd-ad.5.xml:1267 +#: sssd-ldap.5.xml:1152 sssd-ad.5.xml:1260 msgid "Default: 86400 (24 hours)" msgstr "" @@ -6508,7 +6796,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ldap.5.xml:1187 sssd-ipa.5.xml:575 sssd-krb5.5.xml:103 +#: sssd-ldap.5.xml:1187 sssd-ipa.5.xml:570 sssd-krb5.5.xml:103 msgid "krb5_realm (string)" msgstr "" @@ -6664,7 +6952,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1339 -msgid "ldap_chpass_update_last_change (bool)" +msgid "ldap_chpass_update_last_change (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> @@ -6811,7 +7099,7 @@ msgid "ldap_access_order (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap.5.xml:1470 sssd-ipa.5.xml:405 +#: sssd-ldap.5.xml:1470 sssd-ipa.5.xml:400 msgid "Comma separated list of access control options. Allowed values are:" msgstr "" @@ -6856,7 +7144,7 @@ msgid "<emphasis>expire</emphasis>: use ldap_account_expire_policy" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap.5.xml:1515 sssd-ipa.5.xml:413 +#: sssd-ldap.5.xml:1515 sssd-ipa.5.xml:408 msgid "" "<emphasis>pwd_expire_policy_reject, pwd_expire_policy_warn, " "pwd_expire_policy_renew: </emphasis> These options are useful if users are " @@ -6866,24 +7154,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap.5.xml:1525 sssd-ipa.5.xml:423 +#: sssd-ldap.5.xml:1525 sssd-ipa.5.xml:418 msgid "" "The difference between these options is the action taken if user password is " "expired:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ldap.5.xml:1530 sssd-ipa.5.xml:428 +#: sssd-ldap.5.xml:1530 sssd-ipa.5.xml:423 msgid "pwd_expire_policy_reject - user is denied to log in," msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ldap.5.xml:1536 sssd-ipa.5.xml:434 +#: sssd-ldap.5.xml:1536 sssd-ipa.5.xml:429 msgid "pwd_expire_policy_warn - user is still able to log in," msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ldap.5.xml:1542 sssd-ipa.5.xml:440 +#: sssd-ldap.5.xml:1542 sssd-ipa.5.xml:435 msgid "" "pwd_expire_policy_renew - user is prompted to change their password " "immediately." @@ -7418,8 +7706,8 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd-ldap.5.xml:2032 sssd-simple.5.xml:169 sssd-ipa.5.xml:984 -#: sssd-ad.5.xml:1470 sssd-idp.5.xml:248 sssd-krb5.5.xml:483 +#: sssd-ldap.5.xml:2032 sssd-simple.5.xml:169 sssd-ipa.5.xml:979 +#: sssd-ad.5.xml:1463 sssd-idp.5.xml:343 sssd-krb5.5.xml:483 #: sss_rpcidmapd.5.xml:98 sssd-session-recording.5.xml:176 msgid "EXAMPLE" msgstr "" @@ -7447,7 +7735,7 @@ msgstr "" #. type: Content of: <refsect1><refsect2><para> #: sssd-ldap.5.xml:2039 sssd-ldap.5.xml:2057 sssd-simple.5.xml:177 -#: sssd-ipa.5.xml:992 sssd-ad.5.xml:1478 sssd-sudo.5.xml:56 sssd-krb5.5.xml:492 +#: sssd-ipa.5.xml:987 sssd-ad.5.xml:1471 sssd-sudo.5.xml:56 sssd-krb5.5.xml:492 #: sssd-session-recording.5.xml:182 include/ldap_id_mapping.xml:105 msgid "<placeholder type=\"programlisting\" id=\"0\"/>" msgstr "" @@ -7482,7 +7770,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><title> #: sssd-ldap.5.xml:2073 sssd_krb5_locator_plugin.8.xml:83 sssd-simple.5.xml:189 -#: sssd-ad.5.xml:1493 sssd.8.xml:270 sss_seed.8.xml:163 +#: sssd-ad.5.xml:1486 sssd.8.xml:270 sss_seed.8.xml:163 msgid "NOTES" msgstr "" @@ -7989,7 +8277,7 @@ msgstr "" #: pam_sss.8.xml:434 msgid "" "No authentication method was found by Kerberos. This might happen if the " -"user has a Smartcard assigned but the pkint plugin is not available on the " +"user has a Smartcard assigned but the pkinit plugin is not available on the " "client." msgstr "" @@ -8413,6 +8701,23 @@ msgid "" "first DNS resolving failure." msgstr "" +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_locator_plugin.8.xml:106 +msgid "" +"If the environment variable SSSD_KRB5_LOCATOR_KDC_ADDRESS is set to a KDC " +"address the plugin will use this address instead of reading the kdcinfo " +"file. The address format is the same as in the kdcinfo file (see above)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_locator_plugin.8.xml:112 +msgid "" +"If the environment variable SSSD_KRB5_LOCATOR_KPASSWD_ADDRESS is set to a " +"kpasswd server address the plugin will use this address instead of reading " +"the kpasswdinfo file. The address format is the same as in the kpasswdinfo " +"file (see above)." +msgstr "" + #. type: Content of: <reference><refentry><refnamediv><refname> #: sssd-simple.5.xml:10 sssd-simple.5.xml:16 msgid "sssd-simple" @@ -9796,7 +10101,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:129 sssd-ad.5.xml:1161 +#: sssd-ipa.5.xml:129 sssd-ad.5.xml:1166 msgid "dyndns_update (boolean)" msgstr "" @@ -9810,20 +10115,13 @@ msgid "" "quote> option." msgstr "" -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:141 sssd-ad.5.xml:1175 -msgid "" -"NOTE: On older systems (such as RHEL 5), for this behavior to work reliably, " -"the default Kerberos realm must be set properly in /etc/krb5.conf" -msgstr "" - #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:152 sssd-ad.5.xml:1186 +#: sssd-ipa.5.xml:147 sssd-ad.5.xml:1186 msgid "dyndns_ttl (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:155 sssd-ad.5.xml:1189 +#: sssd-ipa.5.xml:150 sssd-ad.5.xml:1189 msgid "" "The TTL to apply to the client DNS record when updating it. If " "dyndns_update is false this has no effect. This will override the TTL " @@ -9831,17 +10129,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:160 +#: sssd-ipa.5.xml:155 msgid "Default: 1200 (seconds)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:166 sssd-ad.5.xml:1200 +#: sssd-ipa.5.xml:161 sssd-ad.5.xml:1200 msgid "dyndns_iface (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:169 sssd-ad.5.xml:1203 +#: sssd-ipa.5.xml:164 sssd-ad.5.xml:1203 msgid "" "Optional. Applicable only when dyndns_update is true. Choose the interface " "or a list of interfaces whose IP addresses should be used for dynamic DNS " @@ -9853,24 +10151,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:182 +#: sssd-ipa.5.xml:177 msgid "" "Default: Use the IP addresses of the interface which is used for IPA LDAP " "connection" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:186 sssd-ad.5.xml:1226 +#: sssd-ipa.5.xml:181 sssd-ad.5.xml:1220 msgid "Example: dyndns_iface = em[12], !vnet1, vnet*" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:192 sssd-ad.5.xml:1232 +#: sssd-ipa.5.xml:187 sssd-ad.5.xml:1226 msgid "dyndns_address (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:195 sssd-ad.5.xml:1235 +#: sssd-ipa.5.xml:190 sssd-ad.5.xml:1229 msgid "" "Optional. Applicable only when <emphasis>dyndns_update</emphasis> is true. " "A list of IP addresses or IP networks to be used for dynamic DNS updates. " @@ -9881,22 +10179,22 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:206 sssd-ad.5.xml:1246 +#: sssd-ipa.5.xml:201 sssd-ad.5.xml:1240 msgid "Default: No filtering of IP addresses." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:209 sssd-ad.5.xml:1249 +#: sssd-ipa.5.xml:204 sssd-ad.5.xml:1243 msgid "Example: dyndns_address = 10.0.0.0/16, !10.0.1.0/24" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:215 sssd-ad.5.xml:1305 +#: sssd-ipa.5.xml:210 sssd-ad.5.xml:1298 msgid "dyndns_auth (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:218 sssd-ad.5.xml:1308 +#: sssd-ipa.5.xml:213 sssd-ad.5.xml:1301 msgid "" "Whether the nsupdate utility should use GSS-TSIG authentication for secure " "updates with the DNS server, insecure updates can be sent by setting this " @@ -9904,17 +10202,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:224 sssd-ad.5.xml:1314 +#: sssd-ipa.5.xml:219 sssd-ad.5.xml:1307 msgid "Default: GSS-TSIG" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:230 sssd-ad.5.xml:1320 +#: sssd-ipa.5.xml:225 sssd-ad.5.xml:1313 msgid "dyndns_auth_ptr (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:233 sssd-ad.5.xml:1323 +#: sssd-ipa.5.xml:228 sssd-ad.5.xml:1316 msgid "" "Whether the nsupdate utility should use GSS-TSIG authentication for secure " "PTR updates with the DNS server, insecure updates can be sent by setting " @@ -9922,17 +10220,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:239 sssd-ad.5.xml:1329 +#: sssd-ipa.5.xml:234 sssd-ad.5.xml:1322 msgid "Default: Same as dyndns_auth" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:245 sssd-ad.5.xml:1255 +#: sssd-ipa.5.xml:240 sssd-ad.5.xml:1249 msgid "dyndns_refresh_interval (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:248 +#: sssd-ipa.5.xml:243 msgid "" "How often should the back end perform periodic DNS update in addition to the " "automatic update performed when the back end goes online. This option is " @@ -9940,74 +10238,74 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:261 sssd-ad.5.xml:1273 -msgid "dyndns_update_ptr (bool)" +#: sssd-ipa.5.xml:256 sssd-ad.5.xml:1266 +msgid "dyndns_update_ptr (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:264 sssd-ad.5.xml:1276 +#: sssd-ipa.5.xml:259 sssd-ad.5.xml:1269 msgid "" "Whether the PTR record should also be explicitly updated when updating the " "client's DNS records. Applicable only when dyndns_update is true." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:269 +#: sssd-ipa.5.xml:264 msgid "" "This option should be False in most IPA deployments as the IPA server " "generates the PTR records automatically when forward records are changed." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:275 sssd-ad.5.xml:1281 +#: sssd-ipa.5.xml:270 sssd-ad.5.xml:1274 msgid "" "Note that <emphasis>dyndns_update_per_family</emphasis> parameter does not " "apply for PTR record updates. Those updates are always sent separately." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:280 +#: sssd-ipa.5.xml:275 msgid "Default: False (disabled)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:286 sssd-ad.5.xml:1292 -msgid "dyndns_force_tcp (bool)" +#: sssd-ipa.5.xml:281 sssd-ad.5.xml:1285 +msgid "dyndns_force_tcp (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:289 sssd-ad.5.xml:1295 +#: sssd-ipa.5.xml:284 sssd-ad.5.xml:1288 msgid "" "Whether the nsupdate utility should default to using TCP for communicating " "with the DNS server." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:293 sssd-ad.5.xml:1299 +#: sssd-ipa.5.xml:288 sssd-ad.5.xml:1292 msgid "Default: False (let nsupdate choose the protocol)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:299 sssd-ad.5.xml:1335 +#: sssd-ipa.5.xml:294 sssd-ad.5.xml:1328 msgid "dyndns_server (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:302 sssd-ad.5.xml:1338 +#: sssd-ipa.5.xml:297 sssd-ad.5.xml:1331 msgid "" "The DNS server to use when performing a DNS update. In most setups, it's " "recommended to leave this option unset." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:307 sssd-ad.5.xml:1343 +#: sssd-ipa.5.xml:302 sssd-ad.5.xml:1336 msgid "" "Setting this option makes sense for environments where the DNS server is " "different from the identity server or when we use encrypted DNS." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:312 sssd-ad.5.xml:1348 +#: sssd-ipa.5.xml:307 sssd-ad.5.xml:1341 msgid "" "The parameter can be a simple string containing DNS name or IP address. It " "can also be an URI. The URI can look like <emphasis>dns://servername/</" @@ -10015,7 +10313,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:319 sssd-ad.5.xml:1355 +#: sssd-ipa.5.xml:314 sssd-ad.5.xml:1348 msgid "" "The second example enables DNS-over-TLS protocol for DNS updates. The " "nsupdate utility must support DoT - check the <emphasis>man nsupdate</" @@ -10023,7 +10321,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:325 sssd-ad.5.xml:1361 +#: sssd-ipa.5.xml:320 sssd-ad.5.xml:1354 msgid "" "Please note that this option will be only used in fallback attempt when " "previous attempt using autodetected settings failed or when DNS-over-TLS is " @@ -10031,17 +10329,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:331 sssd-ad.5.xml:1367 +#: sssd-ipa.5.xml:326 sssd-ad.5.xml:1360 msgid "Default: None (let nsupdate choose the server)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:337 sssd-ad.5.xml:1373 +#: sssd-ipa.5.xml:332 sssd-ad.5.xml:1366 msgid "dyndns_update_per_family (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:340 sssd-ad.5.xml:1376 +#: sssd-ipa.5.xml:335 sssd-ad.5.xml:1369 msgid "" "DNS update is by default performed in two steps - IPv4 update and then IPv6 " "update. In some cases it might be desirable to perform IPv4 and IPv6 update " @@ -10049,12 +10347,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:352 sssd-ad.5.xml:1388 +#: sssd-ipa.5.xml:347 sssd-ad.5.xml:1381 msgid "dyndns_dot_cacert (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:355 sssd-ad.5.xml:1391 +#: sssd-ipa.5.xml:350 sssd-ad.5.xml:1384 msgid "" "This option specifies the file of the certificate authorities certificates " "(in PEM format) in order to verify the remote server TLS certificate when " @@ -10062,17 +10360,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:361 sssd-ad.5.xml:1397 +#: sssd-ipa.5.xml:356 sssd-ad.5.xml:1390 msgid "Default: None (use global certificate store)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:367 sssd-ad.5.xml:1403 +#: sssd-ipa.5.xml:362 sssd-ad.5.xml:1396 msgid "dyndns_dot_cert (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:370 sssd-ad.5.xml:1406 +#: sssd-ipa.5.xml:365 sssd-ad.5.xml:1399 msgid "" "This option sets the certificate(s) file for authentication for the DoT " "transport to the remote server. The certificate chain file is expected to be " @@ -10080,24 +10378,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:376 sssd-ad.5.xml:1412 +#: sssd-ipa.5.xml:371 sssd-ad.5.xml:1405 msgid "" "The <emphasis>dyndns_dot_cert</emphasis> and <emphasis>dyndns_dot_key</" "emphasis> options must be both set to achieve mutual TLS authentication." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:381 sssd-ipa.5.xml:396 sssd-ad.5.xml:1417 sssd-ad.5.xml:1432 +#: sssd-ipa.5.xml:376 sssd-ipa.5.xml:391 sssd-ad.5.xml:1410 sssd-ad.5.xml:1425 msgid "Default: None (Do not use TLS authentication)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:387 sssd-ad.5.xml:1423 +#: sssd-ipa.5.xml:382 sssd-ad.5.xml:1416 msgid "dyndns_dot_key (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:390 sssd-ad.5.xml:1426 +#: sssd-ipa.5.xml:385 sssd-ad.5.xml:1419 msgid "" "This option sets the key file for authenticated encryption for the DoT " "transport to the remote server. The private key file is expected to be in " @@ -10105,170 +10403,170 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:402 +#: sssd-ipa.5.xml:397 msgid "ipa_access_order (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:409 +#: sssd-ipa.5.xml:404 msgid "<emphasis>expire</emphasis>: use IPA's account expiration policy." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:448 +#: sssd-ipa.5.xml:443 msgid "" "Please note that 'access_provider = ipa' must be set for this feature to " "work." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:455 +#: sssd-ipa.5.xml:450 msgid "ipa_deskprofile_search_base (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:458 +#: sssd-ipa.5.xml:453 msgid "" "Optional. Use the given string as search base for Desktop Profile related " "objects." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:462 sssd-ipa.5.xml:484 +#: sssd-ipa.5.xml:457 sssd-ipa.5.xml:479 msgid "Default: Use base DN" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:468 +#: sssd-ipa.5.xml:463 msgid "ipa_subid_ranges_search_base (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:471 +#: sssd-ipa.5.xml:466 msgid "Deprecated. Use ldap_subid_ranges_search_base instead." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:477 +#: sssd-ipa.5.xml:472 msgid "ipa_hbac_search_base (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:480 +#: sssd-ipa.5.xml:475 msgid "Optional. Use the given string as search base for HBAC related objects." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:490 +#: sssd-ipa.5.xml:485 msgid "ipa_host_search_base (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:493 +#: sssd-ipa.5.xml:488 msgid "Deprecated. Use ldap_host_search_base instead." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:499 +#: sssd-ipa.5.xml:494 msgid "ipa_selinux_search_base (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:502 +#: sssd-ipa.5.xml:497 msgid "Optional. Use the given string as search base for SELinux user maps." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:518 +#: sssd-ipa.5.xml:513 msgid "ipa_subdomains_search_base (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:521 +#: sssd-ipa.5.xml:516 msgid "Optional. Use the given string as search base for trusted domains." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:530 +#: sssd-ipa.5.xml:525 msgid "Default: the value of <emphasis>cn=trusts,%basedn</emphasis>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:537 +#: sssd-ipa.5.xml:532 msgid "ipa_master_domain_search_base (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:540 +#: sssd-ipa.5.xml:535 msgid "Optional. Use the given string as search base for master domain object." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:549 +#: sssd-ipa.5.xml:544 msgid "Default: the value of <emphasis>cn=ad,cn=etc,%basedn</emphasis>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:556 +#: sssd-ipa.5.xml:551 msgid "ipa_views_search_base (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:559 +#: sssd-ipa.5.xml:554 msgid "Optional. Use the given string as search base for views containers." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:568 +#: sssd-ipa.5.xml:563 msgid "Default: the value of <emphasis>cn=views,cn=accounts,%basedn</emphasis>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:578 +#: sssd-ipa.5.xml:573 msgid "" "The name of the Kerberos realm. This is optional and defaults to the value " "of <quote>ipa_domain</quote>." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:582 +#: sssd-ipa.5.xml:577 msgid "" "The name of the Kerberos realm has a special meaning in IPA - it is " "converted into the base DN to use for performing LDAP operations." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:590 sssd-ad.5.xml:1441 +#: sssd-ipa.5.xml:585 sssd-ad.5.xml:1434 msgid "krb5_confd_path (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:593 sssd-ad.5.xml:1444 +#: sssd-ipa.5.xml:588 sssd-ad.5.xml:1437 msgid "" "Absolute path of a directory where SSSD should place Kerberos configuration " "snippets." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:597 sssd-ad.5.xml:1448 +#: sssd-ipa.5.xml:592 sssd-ad.5.xml:1441 msgid "" "To disable the creation of the configuration snippets set the parameter to " "'none'." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:601 sssd-ad.5.xml:1452 +#: sssd-ipa.5.xml:596 sssd-ad.5.xml:1445 msgid "" "Default: not set (krb5.include.d subdirectory of SSSD's pubconf directory)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:608 +#: sssd-ipa.5.xml:603 msgid "ipa_deskprofile_refresh (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:611 +#: sssd-ipa.5.xml:606 msgid "" "The amount of time between lookups of the Desktop Profile rules against the " "IPA server. This will reduce the latency and load on the IPA server if there " @@ -10276,34 +10574,34 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:618 sssd-ipa.5.xml:648 sssd-ipa.5.xml:664 sssd-ad.5.xml:600 +#: sssd-ipa.5.xml:613 sssd-ipa.5.xml:643 sssd-ipa.5.xml:659 sssd-ad.5.xml:600 msgid "Default: 5 (seconds)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:624 +#: sssd-ipa.5.xml:619 msgid "ipa_deskprofile_request_interval (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:627 +#: sssd-ipa.5.xml:622 msgid "" "The amount of time between lookups of the Desktop Profile rules against the " "IPA server in case the last request did not return any rule." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:632 +#: sssd-ipa.5.xml:627 msgid "Default: 60 (minutes)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:638 +#: sssd-ipa.5.xml:633 msgid "ipa_hbac_refresh (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:641 +#: sssd-ipa.5.xml:636 msgid "" "The amount of time between lookups of the HBAC rules against the IPA server. " "This will reduce the latency and load on the IPA server if there are many " @@ -10311,12 +10609,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:654 -msgid "ipa_hbac_selinux (integer)" +#: sssd-ipa.5.xml:649 +msgid "ipa_selinux_refresh (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:657 +#: sssd-ipa.5.xml:652 msgid "" "The amount of time between lookups of the SELinux maps against the IPA " "server. This will reduce the latency and load on the IPA server if there are " @@ -10324,33 +10622,33 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:670 +#: sssd-ipa.5.xml:665 msgid "ipa_server_mode (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:673 +#: sssd-ipa.5.xml:668 msgid "" "This option will be set by the IPA installer (ipa-server-install) " "automatically and denotes if SSSD is running on an IPA server or not." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:678 +#: sssd-ipa.5.xml:673 msgid "" "On an IPA server SSSD will lookup users and groups from trusted domains " "directly while on a client it will ask an IPA server." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:683 +#: sssd-ipa.5.xml:678 msgid "" "NOTE: There are currently some assumptions that must be met when SSSD is " "running on an IPA server." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:688 +#: sssd-ipa.5.xml:683 msgid "" "The <quote>ipa_server</quote> option must be configured to point to the IPA " "server itself. This is already the default set by the IPA installer, so no " @@ -10358,59 +10656,59 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:697 +#: sssd-ipa.5.xml:692 msgid "" "The <quote>full_name_format</quote> option must not be tweaked to only print " "short names for users from trusted domains." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:712 +#: sssd-ipa.5.xml:707 msgid "ipa_automount_location (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:715 +#: sssd-ipa.5.xml:710 msgid "The automounter location this IPA client will be using" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:718 +#: sssd-ipa.5.xml:713 msgid "Default: The location named \"default\"" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd-ipa.5.xml:726 +#: sssd-ipa.5.xml:721 msgid "VIEWS AND OVERRIDES" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:735 +#: sssd-ipa.5.xml:730 msgid "ipa_view_class (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:738 +#: sssd-ipa.5.xml:733 msgid "Objectclass of the view container." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:741 +#: sssd-ipa.5.xml:736 msgid "Default: nsContainer" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:747 +#: sssd-ipa.5.xml:742 msgid "ipa_view_name (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:750 +#: sssd-ipa.5.xml:745 msgid "Name of the attribute holding the name of the view." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:754 sssd-ldap-attributes.5.xml:496 +#: sssd-ipa.5.xml:749 sssd-ldap-attributes.5.xml:496 #: sssd-ldap-attributes.5.xml:832 sssd-ldap-attributes.5.xml:913 #: sssd-ldap-attributes.5.xml:1010 sssd-ldap-attributes.5.xml:1068 #: sssd-ldap-attributes.5.xml:1226 sssd-ldap-attributes.5.xml:1271 @@ -10418,128 +10716,128 @@ msgid "Default: cn" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:760 +#: sssd-ipa.5.xml:755 msgid "ipa_override_object_class (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:763 +#: sssd-ipa.5.xml:758 msgid "Objectclass of the override objects." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:766 +#: sssd-ipa.5.xml:761 msgid "Default: ipaOverrideAnchor" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:772 +#: sssd-ipa.5.xml:767 msgid "ipa_anchor_uuid (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:775 +#: sssd-ipa.5.xml:770 msgid "" "Name of the attribute containing the reference to the original object in a " "remote domain." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:779 +#: sssd-ipa.5.xml:774 msgid "Default: ipaAnchorUUID" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:785 +#: sssd-ipa.5.xml:780 msgid "ipa_user_override_object_class (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:788 +#: sssd-ipa.5.xml:783 msgid "" "Name of the objectclass for user overrides. It is used to determine if the " "found override object is related to a user or a group." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:793 +#: sssd-ipa.5.xml:788 msgid "User overrides can contain attributes given by" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:796 +#: sssd-ipa.5.xml:791 msgid "ldap_user_name" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:799 +#: sssd-ipa.5.xml:794 msgid "ldap_user_uid_number" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:802 +#: sssd-ipa.5.xml:797 msgid "ldap_user_gid_number" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:805 +#: sssd-ipa.5.xml:800 msgid "ldap_user_gecos" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:808 +#: sssd-ipa.5.xml:803 msgid "ldap_user_home_directory" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:811 +#: sssd-ipa.5.xml:806 msgid "ldap_user_shell" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:814 +#: sssd-ipa.5.xml:809 msgid "ldap_user_ssh_public_key" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:819 +#: sssd-ipa.5.xml:814 msgid "Default: ipaUserOverride" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:825 +#: sssd-ipa.5.xml:820 msgid "ipa_group_override_object_class (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:828 +#: sssd-ipa.5.xml:823 msgid "" "Name of the objectclass for group overrides. It is used to determine if the " "found override object is related to a user or a group." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:833 +#: sssd-ipa.5.xml:828 msgid "Group overrides can contain attributes given by" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:836 +#: sssd-ipa.5.xml:831 msgid "ldap_group_name" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:839 +#: sssd-ipa.5.xml:834 msgid "ldap_group_gid_number" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:844 +#: sssd-ipa.5.xml:839 msgid "Default: ipaGroupOverride" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:728 +#: sssd-ipa.5.xml:723 msgid "" "SSSD can handle views and overrides which are offered by FreeIPA 4.1 and " "later version. Since all paths and objectclasses are fixed on the server " @@ -10549,19 +10847,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd-ipa.5.xml:856 +#: sssd-ipa.5.xml:851 msgid "SUBDOMAINS PROVIDER" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:858 +#: sssd-ipa.5.xml:853 msgid "" "The IPA subdomains provider behaves slightly differently if it is configured " "explicitly or implicitly." msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:862 +#: sssd-ipa.5.xml:857 msgid "" "If the option 'subdomains_provider = ipa' is found in the domain section of " "sssd.conf, the IPA subdomains provider is configured explicitly, and all " @@ -10569,7 +10867,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:868 +#: sssd-ipa.5.xml:863 msgid "" "If the option 'subdomains_provider' is not set in the domain section of " "sssd.conf but there is the option 'id_provider = ipa', the IPA subdomains " @@ -10581,12 +10879,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd-ipa.5.xml:879 +#: sssd-ipa.5.xml:874 msgid "TRUSTED DOMAINS CONFIGURATION" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-ipa.5.xml:887 +#: sssd-ipa.5.xml:882 #, no-wrap msgid "" "[domain/ipa.domain.com/ad.domain.com]\n" @@ -10594,7 +10892,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:881 +#: sssd-ipa.5.xml:876 msgid "" "Some configuration options can also be set for a trusted domain. A trusted " "domain configuration can be set using the trusted domain subsection as shown " @@ -10604,97 +10902,97 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:892 +#: sssd-ipa.5.xml:887 msgid "" "For more details, see the <citerefentry> <refentrytitle>sssd.conf</" "refentrytitle> <manvolnum>5</manvolnum> </citerefentry> manual page." msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:899 +#: sssd-ipa.5.xml:894 msgid "" "Different configuration options are tunable for a trusted domain depending " "on whether you are configuring SSSD on an IPA server or an IPA client." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd-ipa.5.xml:904 +#: sssd-ipa.5.xml:899 msgid "OPTIONS TUNABLE ON IPA MASTERS" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:906 +#: sssd-ipa.5.xml:901 msgid "" "The following options can be set in a subdomain section on an IPA master:" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:910 sssd-ipa.5.xml:950 +#: sssd-ipa.5.xml:905 sssd-ipa.5.xml:945 msgid "ad_server" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:913 +#: sssd-ipa.5.xml:908 msgid "ad_backup_server" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:916 sssd-ipa.5.xml:953 +#: sssd-ipa.5.xml:911 sssd-ipa.5.xml:948 msgid "ad_site" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:919 +#: sssd-ipa.5.xml:914 msgid "ipa_server" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:922 +#: sssd-ipa.5.xml:917 msgid "ipa_backup_server" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:925 +#: sssd-ipa.5.xml:920 msgid "ldap_search_base" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:928 +#: sssd-ipa.5.xml:923 msgid "ldap_user_search_base" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:931 +#: sssd-ipa.5.xml:926 msgid "ldap_group_search_base" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:939 +#: sssd-ipa.5.xml:934 msgid "" "Options prefixed with 'ad_' or 'ipa_' only apply to their respective " "subdomain type." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd-ipa.5.xml:944 +#: sssd-ipa.5.xml:939 msgid "OPTIONS TUNABLE ON IPA CLIENTS" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:946 +#: sssd-ipa.5.xml:941 msgid "" "The following options can be set in an AD subdomain section on an IPA client:" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:958 +#: sssd-ipa.5.xml:953 msgid "" "Note that if both options are set, only <quote>ad_server</quote> is " "evaluated." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:962 +#: sssd-ipa.5.xml:957 msgid "" "Since any request for a user or a group identity from a trusted domain " "triggered from an IPA client is resolved by the IPA server, the " @@ -10708,7 +11006,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:986 +#: sssd-ipa.5.xml:981 msgid "" "The following example assumes that SSSD is correctly configured and " "example.com is one of the domains in the <replaceable>[sssd]</replaceable> " @@ -10716,7 +11014,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-ipa.5.xml:993 +#: sssd-ipa.5.xml:988 #, no-wrap msgid "" "[domain/example.com]\n" @@ -11415,27 +11713,27 @@ msgid "lxdm" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:694 +#: sssd-ad.5.xml:699 msgid "sddm" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:699 +#: sssd-ad.5.xml:704 msgid "unity" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:704 +#: sssd-ad.5.xml:709 msgid "xdm" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:713 +#: sssd-ad.5.xml:718 msgid "ad_gpo_map_remote_interactive (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:716 +#: sssd-ad.5.xml:721 msgid "" "A comma-separated list of PAM service names for which GPO-based access " "control is evaluated based on the RemoteInteractiveLogonRight and " @@ -11451,7 +11749,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:735 +#: sssd-ad.5.xml:740 msgid "" "Note: Using the Group Policy Management Editor this value is called \"Allow " "log on through Remote Desktop Services\" and \"Deny log on through Remote " @@ -11459,7 +11757,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:750 +#: sssd-ad.5.xml:755 #, no-wrap msgid "" "ad_gpo_map_remote_interactive = +my_pam_service, -sshd\n" @@ -11467,7 +11765,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:741 +#: sssd-ad.5.xml:746 msgid "" "It is possible to add another PAM service name to the default set by using " "<quote>+service_name</quote> or to explicitly remove a PAM service name from " @@ -11479,22 +11777,22 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:758 +#: sssd-ad.5.xml:763 msgid "sshd" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:763 +#: sssd-ad.5.xml:768 msgid "cockpit" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:772 +#: sssd-ad.5.xml:777 msgid "ad_gpo_map_network (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:775 +#: sssd-ad.5.xml:780 msgid "" "A comma-separated list of PAM service names for which GPO-based access " "control is evaluated based on the NetworkLogonRight and " @@ -11510,7 +11808,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:793 +#: sssd-ad.5.xml:798 msgid "" "Note: Using the Group Policy Management Editor this value is called \"Access " "this computer from the network\" and \"Deny access to this computer from the " @@ -11518,7 +11816,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:808 +#: sssd-ad.5.xml:813 #, no-wrap msgid "" "ad_gpo_map_network = +my_pam_service, -ftp\n" @@ -11526,7 +11824,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:799 +#: sssd-ad.5.xml:804 msgid "" "It is possible to add another PAM service name to the default set by using " "<quote>+service_name</quote> or to explicitly remove a PAM service name from " @@ -11538,22 +11836,22 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:816 +#: sssd-ad.5.xml:821 msgid "ftp" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:821 +#: sssd-ad.5.xml:826 msgid "samba" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:830 +#: sssd-ad.5.xml:835 msgid "ad_gpo_map_batch (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:833 +#: sssd-ad.5.xml:838 msgid "" "A comma-separated list of PAM service names for which GPO-based access " "control is evaluated based on the BatchLogonRight and DenyBatchLogonRight " @@ -11568,14 +11866,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:851 +#: sssd-ad.5.xml:856 msgid "" "Note: Using the Group Policy Management Editor this value is called \"Allow " "log on as a batch job\" and \"Deny log on as a batch job\"." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:865 +#: sssd-ad.5.xml:870 #, no-wrap msgid "" "ad_gpo_map_batch = +my_pam_service, -crond\n" @@ -11583,7 +11881,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:856 +#: sssd-ad.5.xml:861 msgid "" "It is possible to add another PAM service name to the default set by using " "<quote>+service_name</quote> or to explicitly remove a PAM service name from " @@ -11595,23 +11893,23 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:868 +#: sssd-ad.5.xml:873 msgid "" "Note: Cron service name may differ depending on Linux distribution used." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:874 +#: sssd-ad.5.xml:879 msgid "crond" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:883 +#: sssd-ad.5.xml:888 msgid "ad_gpo_map_service (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:886 +#: sssd-ad.5.xml:891 msgid "" "A comma-separated list of PAM service names for which GPO-based access " "control is evaluated based on the ServiceLogonRight and " @@ -11627,14 +11925,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:904 +#: sssd-ad.5.xml:909 msgid "" "Note: Using the Group Policy Management Editor this value is called \"Allow " "log on as a service\" and \"Deny log on as a service\"." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:917 +#: sssd-ad.5.xml:922 #, no-wrap msgid "" "ad_gpo_map_service = +my_pam_service\n" @@ -11642,7 +11940,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:909 sssd-ad.5.xml:984 +#: sssd-ad.5.xml:914 sssd-ad.5.xml:989 msgid "" "It is possible to add a PAM service name to the default set by using " "<quote>+service_name</quote>. Since the default set is empty, it is not " @@ -11653,19 +11951,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:927 +#: sssd-ad.5.xml:932 msgid "ad_gpo_map_permit (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:930 +#: sssd-ad.5.xml:935 msgid "" "A comma-separated list of PAM service names for which GPO-based access is " "always granted, regardless of any GPO Logon Rights." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:944 +#: sssd-ad.5.xml:949 #, no-wrap msgid "" "ad_gpo_map_permit = +my_pam_service, -sudo\n" @@ -11673,7 +11971,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:935 +#: sssd-ad.5.xml:940 msgid "" "It is possible to add another PAM service name to the default set by using " "<quote>+service_name</quote> or to explicitly remove a PAM service name from " @@ -11685,29 +11983,29 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:952 +#: sssd-ad.5.xml:957 msgid "polkit-1" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:967 +#: sssd-ad.5.xml:972 msgid "systemd-user" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:976 +#: sssd-ad.5.xml:981 msgid "ad_gpo_map_deny (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:979 +#: sssd-ad.5.xml:984 msgid "" "A comma-separated list of PAM service names for which GPO-based access is " "always denied, regardless of any GPO Logon Rights." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:992 +#: sssd-ad.5.xml:997 #, no-wrap msgid "" "ad_gpo_map_deny = +my_pam_service\n" @@ -11715,12 +12013,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:1002 +#: sssd-ad.5.xml:1007 msgid "ad_gpo_default_right (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1005 +#: sssd-ad.5.xml:1010 msgid "" "This option defines how access control is evaluated for PAM service names " "that are not explicitly listed in one of the ad_gpo_map_* options. This " @@ -11733,52 +12031,52 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1018 +#: sssd-ad.5.xml:1023 msgid "Supported values for this option include:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1027 +#: sssd-ad.5.xml:1032 msgid "remote_interactive" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1032 +#: sssd-ad.5.xml:1037 msgid "network" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1037 +#: sssd-ad.5.xml:1042 msgid "batch" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1042 +#: sssd-ad.5.xml:1047 msgid "service" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1047 +#: sssd-ad.5.xml:1052 msgid "permit" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1052 +#: sssd-ad.5.xml:1057 msgid "deny" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1058 +#: sssd-ad.5.xml:1063 msgid "Default: deny" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:1064 +#: sssd-ad.5.xml:1069 msgid "ad_maximum_machine_account_password_age (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1067 +#: sssd-ad.5.xml:1072 msgid "" "SSSD will check once a day if the machine account password is older than the " "given age in days and try to renew it. A value of 0 will disable the renewal " @@ -11786,17 +12084,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1073 +#: sssd-ad.5.xml:1078 msgid "Default: 30 days" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:1079 +#: sssd-ad.5.xml:1084 msgid "ad_machine_account_password_renewal_opts (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1082 +#: sssd-ad.5.xml:1087 msgid "" "This option should only be used to test the machine account renewal task. " "The option expects 3 integers and a string separated by a colon (':'). The " @@ -11809,20 +12107,20 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1096 +#: sssd-ad.5.xml:1101 msgid "" "The optional fourth string value identifies the helper binary which should " "be used for the renewal. Currently <command>adcli</command> and " "<command>realm</command> are supported. If this value is missing or empty in " "the value string <command>realm</command> will be used. Since the helper is " "started as the user SSSD is running as there might be the chance that the " -"renewal will fail if this user does not has permissions to modify the keytab " -"file where the machine account credentials are stored. This will typically " -"be the case for <command>adcli</command>." +"renewal will fail if this user does not have permissions to modify the " +"keytab file where the machine account credentials are stored. This will " +"typically be the case for <command>adcli</command>." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1110 +#: sssd-ad.5.xml:1115 msgid "" "<command>realm</command> is not updating the keytab directly but is calling " "the <command>realmd</command> process, which runs as root user, for this " @@ -11832,17 +12130,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1119 +#: sssd-ad.5.xml:1124 msgid "Default: 86400:750:300:realm (24h, 12m30s and 5m)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:1125 +#: sssd-ad.5.xml:1130 msgid "ad_update_samba_machine_account_password (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1128 +#: sssd-ad.5.xml:1133 msgid "" "If enabled, when SSSD renews the machine account password, it will also be " "updated in Samba's database. This prevents Samba's copy of the machine " @@ -11851,23 +12149,23 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:1141 -msgid "ad_use_ldaps (bool)" +#: sssd-ad.5.xml:1146 +msgid "ad_use_ldaps (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1144 +#: sssd-ad.5.xml:1149 msgid "" "By default SSSD uses the plain LDAP port 389 and the Global Catalog port " -"3628. If this option is set to True SSSD will use the LDAPS port 636 and " -"Global Catalog port 3629 with LDAPS protection. Since AD does not allow to " +"3268. If this option is set to True SSSD will use the LDAPS port 636 and " +"Global Catalog port 3269 with LDAPS protection. Since AD does not allow to " "have multiple encryption layers on a single connection and we still want to " "use SASL/GSSAPI or SASL/GSS-SPNEGO for authentication the SASL security " "property maxssf is set to 0 (zero) for those connections." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1164 +#: sssd-ad.5.xml:1169 msgid "" "Optional. This option tells SSSD to automatically update the Active " "Directory DNS server with the IP address of this client. The update is " @@ -11885,30 +12183,21 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:1216 msgid "" -"NOTE: While it is still possible to use the old <emphasis>ipa_dyndns_iface</" -"emphasis> option, users should migrate to using <emphasis>dyndns_iface</" -"emphasis> in their config file." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1222 -msgid "" "Default: Use the IP addresses of the interface which is used for AD LDAP " "connection" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1258 +#: sssd-ad.5.xml:1252 msgid "" "How often should the back end perform periodic DNS update in addition to the " -"automatic update performed when the back end goes online. This option is " -"optional and applicable only when dyndns_update is true. Note that the " -"lowest possible value is 60 seconds in-case if value is provided less than " -"60, parameter will assume lowest value only." +"automatic update performed when the back end goes online. This is optional " +"and applicable only when dyndns_update is true. Note that the minimum value " +"is 60 seconds, any specified value below this threshold will default to 60." msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ad.5.xml:1472 +#: sssd-ad.5.xml:1465 msgid "" "The following example assumes that SSSD is correctly configured and " "example.com is one of the domains in the <replaceable>[sssd]</replaceable> " @@ -11916,7 +12205,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-ad.5.xml:1479 +#: sssd-ad.5.xml:1472 #, no-wrap msgid "" "[domain/EXAMPLE]\n" @@ -11931,7 +12220,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-ad.5.xml:1499 +#: sssd-ad.5.xml:1492 #, no-wrap msgid "" "access_provider = ldap\n" @@ -11940,7 +12229,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ad.5.xml:1495 +#: sssd-ad.5.xml:1488 msgid "" "The AD access control provider checks if the account is expired. It has the " "same effect as the following configuration of the LDAP provider: " @@ -11948,7 +12237,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ad.5.xml:1505 +#: sssd-ad.5.xml:1498 msgid "" "However, unless the <quote>ad</quote> access control provider is explicitly " "configured, the default access provider is <quote>permit</quote>. Please " @@ -11958,7 +12247,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ad.5.xml:1513 +#: sssd-ad.5.xml:1506 msgid "" "When the autofs provider is set to <quote>ad</quote>, the RFC2307 schema " "attribute mapping (nisMap, nisObject, ...) is used, because these attributes " @@ -12112,9 +12401,9 @@ msgstr "" #: sssd-sudo.5.xml:137 msgid "" "The <emphasis>smart refresh</emphasis> periodically downloads rules that are " -"new or were modified after the last update. Its primary goal is to keep the " -"database growing by fetching only small increments that do not generate " -"large amounts of network traffic." +"new or were modified after the last update. Its primary goal is to grow the " +"database incrementally by fetching only small updates, avoiding large " +"amounts of network traffic." msgstr "" #. type: Content of: <reference><refentry><refsect1><para> @@ -12294,22 +12583,25 @@ msgstr "" msgid "" "Depending on the IdP product additional platform specific options might " "follow the name separated by a colon (:). E.g. for Keycloak the base URI for " -"the user and group REST API must be given. For Entra ID this is not needed " -"because there is a generic endpoint for all tenants." +"the user and group REST API must be given. For Entra ID the base URI for the " +"Microsoft Graph API can be given to use sovereign or government cloud " +"endpoints instead of the default (https://graph.microsoft.com/v1.0). E.g. " +"<quote>entra_id:https://graph.microsoft.us/v1.0</quote> for the US " +"government cloud (GCC High)." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:78 sssd-idp.5.xml:94 sssd-idp.5.xml:119 +#: sssd-idp.5.xml:82 sssd-idp.5.xml:98 sssd-idp.5.xml:123 msgid "Default: Not set (Required)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:83 +#: sssd-idp.5.xml:87 msgid "idp_client_id (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:86 +#: sssd-idp.5.xml:90 msgid "" "ID of the IdP client used by SSSD to authenticate users and as a client to " "lookup user and group attributes. This client must offer device " @@ -12318,12 +12610,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:99 +#: sssd-idp.5.xml:103 msgid "idp_client_secret (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:102 +#: sssd-idp.5.xml:106 msgid "" "Password of the IdP client. The password is required for the id_provider. If " "only used as auth_provider it depends on the server side configuration if it " @@ -12331,66 +12623,73 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:113 +#: sssd-idp.5.xml:117 msgid "idp_token_endpoint (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:116 +#: sssd-idp.5.xml:120 msgid "IdP endpoint for requesting access tokens." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:124 +#: sssd-idp.5.xml:128 msgid "idp_device_auth_endpoint (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:127 +#: sssd-idp.5.xml:131 msgid "" "IdP endpoint for device authorization according to RFC-8628. This is " "required for user authentication." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:137 +#: sssd-idp.5.xml:141 msgid "idp_userinfo_endpoint (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:140 +#: sssd-idp.5.xml:144 msgid "" "IdP userinfo endpoint to request user attributes after a successful " "authentication of the user. Required for authentication." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:150 +#: sssd-idp.5.xml:154 msgid "idp_id_scope (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:153 +#: sssd-idp.5.xml:157 msgid "" "Scope required for looking up user and group attributes with the REST API. " "The scopes are used by the server to determine which attributes/claims are " "returned to the caller." msgstr "" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:163 +msgid "" +"Note: In previous versions of SSSD, this option was expected to already be " +"URL-encoded." +msgstr "" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:164 +#: sssd-idp.5.xml:172 msgid "idp_auth_scope (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:167 +#: sssd-idp.5.xml:175 msgid "" "Scope required during authentication. The scopes are used by the server to " "determine which attributes/claims are returned to the caller." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:172 +#: sssd-idp.5.xml:180 msgid "" "Currently the tokens returned during user authentication are not used for " "other purposes hence the only important claim is the subject identifier " @@ -12399,22 +12698,116 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:185 +#: sssd-idp.5.xml:193 +msgid "idp_auth_user_identifier_attr (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:196 +msgid "" +"Attribute used to identify the authenticated user in userinfo data or token " +"claims." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:200 +msgid "" +"For hybrid Active Directory and Entra ID deployments where " +"<quote>id_provider = ad</quote> and <quote>auth_provider = idp</quote>, this " +"option must be set explicitly. No value is derived from the identity " +"provider, because more than one attribute can link an Entra ID object to its " +"on-premises counterpart and only the administrator knows which one the " +"directory synchronization is configured to use." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:211 +msgid "" +"Setting this option to <quote>onPremisesImmutableId</quote> is the usual " +"choice for such deployments. Microsoft Entra Connect populates that " +"attribute with the base64-encoded form of the 16-byte Active Directory " +"<quote>objectGUID</quote> when objectGUID is used as the sourceAnchor. SSSD " +"decodes the value and converts the raw bytes with the same conversion used " +"for AD objectGUID attributes, so the result matches the UUID stored in the " +"SSSD cache for the AD user." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:224 +msgid "" +"Note that Microsoft Entra Connect 1.1.524.0 and later use <quote>ms-DS-" +"ConsistencyGuid</quote> as the sourceAnchor for user objects instead of " +"<quote>objectGUID</quote>. The value is normally copied from objectGUID for " +"objects that do not have it set yet, in which case the decoded identifier " +"still matches. It does not match if ms-DS-ConsistencyGuid was populated " +"independently, if users were moved between forests or domains, or if a " +"different attribute such as employeeID was selected as the sourceAnchor. See " +"<ulink url=\"https://learn.microsoft.com/en-us/entra/identity/hybrid/connect/" +"plan-connect-design-concepts\"> Microsoft Entra Connect: Design concepts</" +"ulink> for details on sourceAnchor selection." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:241 +msgid "" +"Microsoft Graph does not return <quote>onPremisesImmutableId</quote> by " +"default. The <quote>idp_userinfo_endpoint</quote> must request it with " +"<quote>$select</quote>, see the example below and <ulink url=\"https://" +"learn.microsoft.com/en-us/graph/api/resources/user\"> the Microsoft Graph " +"user resource type</ulink>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:251 +msgid "" +"If the configured attribute is missing or cannot be decoded (for example " +"cloud-only Entra ID users without <quote>onPremisesImmutableId</quote>), " +"authentication fails. SSSD does not fall back to another attribute when this " +"option is set." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:258 +msgid "" +"Default: not set, <quote>sub</quote> for Keycloak and <quote>id</quote> for " +"other IdP types" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-idp.5.xml:264 msgid "idp_request_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:188 +#: sssd-idp.5.xml:267 msgid "Timeout in seconds for an individual request to the IdP." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:197 +#: sssd-idp.5.xml:276 +msgid "idp_auto_refresh (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:279 +msgid "" +"Refresh tokens automatically, after they have reached about half their " +"lifetime." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:283 +msgid "" +"Note: Scheduled token refreshes are not preserved across restarts of SSSD." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-idp.5.xml:292 msgid "idmap_range_min (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:200 +#: sssd-idp.5.xml:295 msgid "" "Specifies the lower (inclusive) bound of the range of POSIX IDs to use for " "mapping IdP users and group to POSIX IDs. It is the first POSIX ID which can " @@ -12422,7 +12815,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:206 +#: sssd-idp.5.xml:301 msgid "" "The interval between <quote>idmap_range_min</quote> and " "<quote>idmap_range_max</quote> will be split into smaller ranges of size " @@ -12431,18 +12824,18 @@ msgid "" msgstr "" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:213 sssd-idp.5.xml:239 include/ldap_id_mapping.xml:139 +#: sssd-idp.5.xml:308 sssd-idp.5.xml:334 include/ldap_id_mapping.xml:139 #: include/ldap_id_mapping.xml:197 msgid "Default: 200000" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:218 +#: sssd-idp.5.xml:313 msgid "idmap_range_max (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:221 +#: sssd-idp.5.xml:316 msgid "" "Specifies the upper (exclusive) bound of the range of POSIX IDs to use for " "mapping IdP users and groups to POSIX IDs. It is the first POSIX ID which " @@ -12450,45 +12843,68 @@ msgid "" msgstr "" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:227 include/ldap_id_mapping.xml:165 +#: sssd-idp.5.xml:322 include/ldap_id_mapping.xml:165 msgid "Default: 2000200000" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:232 +#: sssd-idp.5.xml:327 msgid "idmap_range_size (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:235 +#: sssd-idp.5.xml:330 msgid "Specifies the number of POSIX IDs available for a single IdP domain." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-idp.5.xml:251 +#: sssd-idp.5.xml:346 #, no-wrap msgid "" "[domain/entra_id]\n" "id_provider = idp\n" "idp_type = entra_id\n" "idp_client_id = 12345678-abcd-0101-efef-ba9876543210\n" -"idp_client_secret = YOUR-CLIENT-SCERET\n" -"idp_token_endpoint = https://login.microsoftonline.com/TENNANT-ID/oauth2/v2.0/token\n" +"idp_client_secret = YOUR-CLIENT-SECRET\n" +"idp_token_endpoint = https://login.microsoftonline.com/TENANT-ID/oauth2/v2.0/token\n" "idp_userinfo_endpoint = https://graph.microsoft.com/v1.0/me\n" -"idp_device_auth_endpoint = https://login.microsoftonline.com/TENNANT-ID/oauth2/v2.0/devicecode\n" -"idp_id_scope = https%3A%2F%2Fgraph.microsoft.com%2F.default\n" +"idp_device_auth_endpoint = https://login.microsoftonline.com/TENANT-ID/oauth2/v2.0/devicecode\n" +"idp_id_scope = https://graph.microsoft.com/.default\n" +"idp_auth_scope = openid profile email\n" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><programlisting> +#: sssd-idp.5.xml:358 +#, no-wrap +msgid "" +"[domain/ad.example.com]\n" +"id_provider = ad\n" +"auth_provider = idp\n" +"access_provider = permit\n" +"\n" +"ad_domain = ad.example.com\n" +"krb5_realm = AD.EXAMPLE.COM\n" +"\n" +"idp_type = entra_id\n" +"idp_client_id = 12345678-abcd-0101-efef-ba9876543210\n" +"idp_client_secret = YOUR-CLIENT-SECRET\n" +"idp_token_endpoint = https://login.microsoftonline.com/TENANT-ID/oauth2/v2.0/token\n" +"idp_userinfo_endpoint = https://graph.microsoft.com/v1.0/me?$select=id,userPrincipalName,onPremisesImmutableId\n" +"idp_device_auth_endpoint = https://login.microsoftonline.com/TENANT-ID/oauth2/v2.0/devicecode\n" +"idp_id_scope = https://graph.microsoft.com/.default\n" "idp_auth_scope = openid profile email\n" +"idp_auth_user_identifier_attr = onPremisesImmutableId\n" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-idp.5.xml:263 +#: sssd-idp.5.xml:377 #, no-wrap msgid "" "[domain/keycloak]\n" "idp_type = keycloak:https://master.keycloak.test:8443/auth/admin/realms/master/\n" "id_provider = idp\n" "idp_client_id = myclient\n" -"idp_client_secret = YOUR-CLIENT-SCERET\n" +"idp_client_secret = YOUR-CLIENT-SECRET\n" "idp_token_endpoint = https://master.keycloak.test:8443/auth/realms/master/protocol/openid-connect/token\n" "idp_userinfo_endpoint = https://master.keycloak.test:8443/auth/realms/master/protocol/openid-connect/userinfo\n" "idp_device_auth_endpoint = https://master.keycloak.test:8443/auth/realms/master/protocol/openid-connect/auth/device\n" @@ -12497,10 +12913,22 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-idp.5.xml:250 +#: sssd-idp.5.xml:345 msgid "" "<placeholder type=\"programlisting\" id=\"0\"/> <placeholder " -"type=\"programlisting\" id=\"1\"/>" +"type=\"programlisting\" id=\"1\"/> <placeholder type=\"programlisting\" " +"id=\"2\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-idp.5.xml:390 +msgid "" +"In the hybrid Active Directory and Entra ID example above, " +"<quote>onPremisesImmutableId</quote> is used during authentication so the " +"IdP result matches the AD objectGUID UUID stored in the SSSD cache. The " +"attribute must be requested via <quote>$select</quote> on the Graph userinfo " +"endpoint and is only populated for users synchronized from Active Directory " +"with objectGUID as the sourceAnchor." msgstr "" #. type: Content of: <reference><refentry><refnamediv><refname> @@ -13466,7 +13894,7 @@ msgstr "" #: sssd-krb5.5.xml:291 msgid "" "<emphasis>demand</emphasis> to use FAST. The authentication fails if the " -"server does not require fast." +"server does not support FAST." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> @@ -14355,7 +14783,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sss_rpcidmapd.5.xml:69 -msgid "memcache (bool)" +msgid "memcache (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> @@ -14409,7 +14837,7 @@ msgid "" msgstr "" #. type: Content of: <refsect1><title> -#: sss_rpcidmapd.5.xml:120 sssd-kcm.8.xml:316 include/seealso.xml:2 +#: sss_rpcidmapd.5.xml:120 sssd-kcm.8.xml:315 include/seealso.xml:2 msgid "SEE ALSO" msgstr "" @@ -14636,8 +15064,8 @@ msgstr "" #: sss_ssh_knownhosts.1.xml:93 msgid "" "The key lines retrieved from the backend are expected to respect the key " -"format as decribed in the <quote>SSH_KNOWN_HOSTS FILE FORMAT</quote> section " -"of <citerefentry><refentrytitle>sshd</refentrytitle> <manvolnum>8</" +"format as described in the <quote>SSH_KNOWN_HOSTS FILE FORMAT</quote> " +"section of <citerefentry><refentrytitle>sshd</refentrytitle> <manvolnum>8</" "manvolnum></citerefentry>. However, returning only the keytype and the key " "itself is tolerated, in which case, the hostname received as parameter will " "be added before the keytype to output a correctly formatted line. The " @@ -15113,14 +15541,13 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-kcm.8.xml:215 msgid "" -"The KCM service is configured in the <quote>kcm</quote> For a detailed " -"syntax reference, refer to the <quote>FILE FORMAT</quote> section of the " -"<citerefentry> <refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</" -"manvolnum> </citerefentry> manual page." +"For a detailed syntax reference, refer to the <quote>FILE FORMAT</quote> " +"section of the <citerefentry> <refentrytitle>sssd.conf</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry> manual page." msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-kcm.8.xml:223 +#: sssd-kcm.8.xml:222 msgid "" "The generic SSSD service options such as <quote>debug_level</quote> or " "<quote>fd_limit</quote> are accepted by the kcm service. Please refer to " @@ -15130,22 +15557,22 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:234 +#: sssd-kcm.8.xml:233 msgid "socket_path (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:237 +#: sssd-kcm.8.xml:236 msgid "The socket the KCM service will listen on." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:240 +#: sssd-kcm.8.xml:239 msgid "Default: <replaceable>/var/run/.heim_org.h5l.kcm-socket</replaceable>" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:243 +#: sssd-kcm.8.xml:242 msgid "" "<phrase condition=\"have_systemd\"> Note: on platforms where systemd is " "supported, the socket path is overwritten by the one defined in the sssd-" @@ -15153,86 +15580,86 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:252 +#: sssd-kcm.8.xml:251 msgid "max_ccaches (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:255 +#: sssd-kcm.8.xml:254 msgid "How many credential caches does the KCM database allow for all users." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:259 +#: sssd-kcm.8.xml:258 msgid "Default: 0 (unlimited, only the per-UID quota is enforced)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:264 +#: sssd-kcm.8.xml:263 msgid "max_uid_ccaches (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:267 +#: sssd-kcm.8.xml:266 msgid "" "How many credential caches does the KCM database allow per UID. This is " "equivalent to <quote>with how many principals you can kinit</quote>." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:272 +#: sssd-kcm.8.xml:271 msgid "Default: 64" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:277 +#: sssd-kcm.8.xml:276 msgid "max_ccache_size (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:280 +#: sssd-kcm.8.xml:279 msgid "" -"How big can a credential cache be per ccache. Each service ticket accounts " -"into this quota." +"How big a credential cache be per ccache. Each service ticket counts toward " +"this quota." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:284 +#: sssd-kcm.8.xml:283 msgid "Default: 65536" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:289 -msgid "tgt_renewal (bool)" +#: sssd-kcm.8.xml:288 +msgid "tgt_renewal (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:292 +#: sssd-kcm.8.xml:291 msgid "Enables TGT renewals functionality." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:295 +#: sssd-kcm.8.xml:294 msgid "Default: False (Automatic renewals disabled)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:300 +#: sssd-kcm.8.xml:299 msgid "tgt_renewal_inherit (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:303 +#: sssd-kcm.8.xml:302 msgid "Domain to inherit krb5_* options from, for use with TGT renewals." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:307 +#: sssd-kcm.8.xml:306 msgid "Default: NULL" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-kcm.8.xml:318 +#: sssd-kcm.8.xml:317 msgid "" "<citerefentry> <refentrytitle>sssd</refentrytitle><manvolnum>8</manvolnum> </" "citerefentry>, <citerefentry> <refentrytitle>sssd.conf</" @@ -16136,8 +16563,8 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap-attributes.5.xml:381 sssd-ldap-attributes.5.xml:395 -msgid "Default: loginDisabled" +#: sssd-ldap-attributes.5.xml:381 +msgid "Default: loginDisabled (rfc2307, rfc2307bis and IPA), not set (AD)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> @@ -16152,6 +16579,12 @@ msgid "" "which date access is granted." msgstr "" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:395 +msgid "" +"Default: loginExpirationTime (rfc2307, rfc2307bis and IPA), not set (AD)" +msgstr "" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:401 msgid "ldap_user_nds_login_allowed_time_map (string)" @@ -16166,7 +16599,8 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:409 -msgid "Default: loginAllowedTimeMap" +msgid "" +"Default: loginAllowedTimeMap (rfc2307, rfc2307bis and IPA), not set (AD)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> @@ -16680,8 +17114,8 @@ msgid "The object class of a host entry in LDAP." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap-attributes.5.xml:900 sssd-ldap-attributes.5.xml:997 -msgid "Default: ipService" +#: sssd-ldap-attributes.5.xml:900 sssd-ldap-attributes.5.xml:1213 +msgid "Default: ipHost" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> @@ -16766,6 +17200,11 @@ msgstr "" msgid "The object class of a service entry in LDAP." msgstr "" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:997 +msgid "Default: ipService" +msgstr "" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1003 msgid "ldap_service_name (string)" @@ -17006,11 +17445,6 @@ msgstr "" msgid "The object class of an iphost entry in LDAP." msgstr "" -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap-attributes.5.xml:1213 -msgid "Default: ipHost" -msgstr "" - #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1219 msgid "ldap_iphost_name (string)" @@ -17230,6 +17664,7 @@ msgstr "" msgid "" "[plugins]\n" " localauth = {\n" +" disable = an2ln\n" " module = sssd:/usr/lib64/sssd/modules/sssd_krb5_localauth_plugin.so\n" " }\n" msgstr "" @@ -17246,6 +17681,28 @@ msgid "" "the local Kerberos configuration the plugin will be enabled automatically." msgstr "" +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_localauth_plugin.8.xml:67 +msgid "" +"This configuration snippet also disables the <command>an2ln</command> module " +"provided by MIT Kerberos if SSSD is configured to use the AD or IPA " +"provider. In those environments <command>sssd_krb5_localauth_plugin</" +"command> can reliably map the system user names to Kerberos principals. A " +"fallback to <command>an2ln</command> might cause issues in environments " +"where users have the privilege to create Kerberos principals on their own " +"which might collide with names of other users used in the system. Other " +"modules provided by MIT Kerberos, e.g. <command>k5login</command> are not " +"affected." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_localauth_plugin.8.xml:79 +msgid "" +"Note: If using <quote>auth_provider = krb5</quote> then " +"<command>sssd_krb5_localauth_plugin</command> is not used, therefore the " +"above text is not applicable." +msgstr "" + #. type: Content of: <variablelist><varlistentry><term> #: include/autofs_attributes.xml:3 msgid "ldap_autofs_map_object_class (string)" @@ -18102,30 +18559,6 @@ msgid "" "failures; corresponds to setting 2 in decimal notation)" msgstr "" -#. type: Content of: <refsect1><title> -#: include/local.xml:2 -msgid "THE LOCAL DOMAIN" -msgstr "" - -#. type: Content of: <refsect1><para> -#: include/local.xml:4 -msgid "" -"In order to function correctly, a domain with <quote>id_provider=local</" -"quote> must be created and the SSSD must be running." -msgstr "" - -#. type: Content of: <refsect1><para> -#: include/local.xml:9 -msgid "" -"The administrator might want to use the SSSD local users instead of " -"traditional UNIX users in cases where the group nesting (see <citerefentry> " -"<refentrytitle>sss_groupadd</refentrytitle> <manvolnum>8</manvolnum> </" -"citerefentry>) is needed. The local users are also useful for testing and " -"development of the SSSD without having to deploy a full remote server. The " -"<command>sss_user*</command> and <command>sss_group*</command> tools use a " -"local LDB storage to store users and groups." -msgstr "" - #. type: Content of: <refsect1><para> #: include/seealso.xml:4 msgid "" diff --git a/src/man/po/fi.po b/src/man/po/fi.po index 75d91710b2e..c789c2b90fb 100644 --- a/src/man/po/fi.po +++ b/src/man/po/fi.po @@ -3,8 +3,8 @@ msgid "" msgstr "" "Project-Id-Version: sssd-docs 2.3.0\n" "Report-Msgid-Bugs-To: sssd-devel@redhat.com\n" -"POT-Creation-Date: 2026-01-14 15:00+0000\n" -"PO-Revision-Date: 2026-04-23 16:42+0000\n" +"POT-Creation-Date: 2026-10-05 16:14+0000\n" +"PO-Revision-Date: 2026-10-05 16:54+0000\n" "Last-Translator: Ricky Tigg <ricky.tigg@gmail.com>\n" "Language-Team: Finnish <https://translate.fedoraproject.org/projects/sssd/" "sssd-manpage-master/fi/>\n" @@ -13,10 +13,10 @@ msgstr "" "Content-Type: text/plain; charset=UTF-8\n" "Content-Transfer-Encoding: 8bit\n" "Plural-Forms: nplurals=2; plural=n != 1;\n" -"X-Generator: Weblate 5.17\n" +"X-Generator: Weblate 2026.10\n" #. type: Content of: <reference><title> -#: sssd.conf.5.xml:8 sssd-ldap.5.xml:5 pam_sss.8.xml:5 pam_sss_gss.8.xml:5 +#: sssd.conf.5.xml:10 sssd-ldap.5.xml:5 pam_sss.8.xml:5 pam_sss_gss.8.xml:5 #: sssd_krb5_locator_plugin.8.xml:5 sssd-simple.5.xml:5 sss-certmap.5.xml:5 #: sssd-ipa.5.xml:5 sssd-ad.5.xml:5 sssd-sudo.5.xml:5 sssd-idp.5.xml:5 #: sssd.8.xml:5 sss_obfuscate.8.xml:5 sss_override.8.xml:5 sssd-krb5.5.xml:5 @@ -29,12 +29,12 @@ msgid "SSSD Manual pages" msgstr "SSSD ohjesivut" #. type: Content of: <reference><refentry><refnamediv><refname> -#: sssd.conf.5.xml:13 sssd.conf.5.xml:19 +#: sssd.conf.5.xml:15 sssd.conf.5.xml:21 msgid "sssd.conf" msgstr "sssd.conf" #. type: Content of: <reference><refentry><refmeta><manvolnum> -#: sssd.conf.5.xml:14 sssd-ldap.5.xml:11 sssd-simple.5.xml:11 +#: sssd.conf.5.xml:16 sssd-ldap.5.xml:11 sssd-simple.5.xml:11 #: sss-certmap.5.xml:11 sssd-ipa.5.xml:11 sssd-ad.5.xml:11 sssd-sudo.5.xml:11 #: sssd-idp.5.xml:11 sssd-krb5.5.xml:11 sssd-ifp.5.xml:11 #: sss_rpcidmapd.5.xml:27 sssd-session-recording.5.xml:11 @@ -43,7 +43,7 @@ msgid "5" msgstr "5" #. type: Content of: <reference><refentry><refmeta><refmiscinfo> -#: sssd.conf.5.xml:15 sssd-ldap.5.xml:12 sssd-simple.5.xml:12 +#: sssd.conf.5.xml:17 sssd-ldap.5.xml:12 sssd-simple.5.xml:12 #: sss-certmap.5.xml:12 sssd-ipa.5.xml:12 sssd-ad.5.xml:12 sssd-sudo.5.xml:12 #: sssd-idp.5.xml:12 sssd-krb5.5.xml:12 sssd-ifp.5.xml:12 #: sss_rpcidmapd.5.xml:28 sssd-session-recording.5.xml:12 sssd-kcm.8.xml:12 @@ -52,17 +52,17 @@ msgid "File Formats and Conventions" msgstr "" #. type: Content of: <reference><refentry><refnamediv><refpurpose> -#: sssd.conf.5.xml:20 +#: sssd.conf.5.xml:22 msgid "the configuration file for SSSD" msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:24 +#: sssd.conf.5.xml:26 msgid "FILE FORMAT" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd.conf.5.xml:32 +#: sssd.conf.5.xml:34 #, no-wrap msgid "" "<replaceable>[section]</replaceable>\n" @@ -72,7 +72,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:27 +#: sssd.conf.5.xml:29 msgid "" "The file has an ini-style syntax and consists of sections and parameters. A " "section begins with the name of the section in square brackets and continues " @@ -81,47 +81,50 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:39 +#: sssd.conf.5.xml:41 msgid "" -"The data types used are string (no quotes needed), integer and bool (with " -"values of <quote>TRUE/FALSE</quote>)." +"The data types used are string (no quotes needed), integer and boolean (with " +"values of <quote>TRUE/FALSE</quote>). Boolean values are case-insensitive; " +"for example, <quote>TRUE</quote>, <quote>True</quote> and <quote>true</" +"quote> are all equivalent and valid; the same applies to <quote>FALSE</" +"quote>." msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:44 +#: sssd.conf.5.xml:49 msgid "" "A comment line starts with a hash sign (<quote>#</quote>) or a semicolon " "(<quote>;</quote>). Inline comments are not supported." msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:50 +#: sssd.conf.5.xml:55 msgid "" "All sections can have an optional <replaceable>description</replaceable> " "parameter. Its function is only as a label for the section." msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:56 +#: sssd.conf.5.xml:61 msgid "" "<filename>sssd.conf</filename> must be a regular file that is owned, " "readable, and writeable only by 'root'." msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:60 +#: sssd.conf.5.xml:65 msgid "" "<filename>sssd.conf</filename> must be a regular file that is accessible " "only by the user used to run SSSD service or root." msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:66 +#: sssd.conf.5.xml:71 msgid "CONFIGURATION SNIPPETS FROM INCLUDE DIRECTORY" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:69 +#: sssd.conf.5.xml:74 msgid "" "The configuration file <filename>sssd.conf</filename> will include " "configuration snippets using the include directory <filename>conf.d</" @@ -129,7 +132,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:75 +#: sssd.conf.5.xml:80 msgid "" "Any file placed in <filename>conf.d</filename> that ends in " "<quote><filename>.conf</filename></quote> and does not begin with a dot " @@ -138,7 +141,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:83 +#: sssd.conf.5.xml:88 msgid "" "The configuration snippets from <filename>conf.d</filename> have higher " "priority than <filename>sssd.conf</filename> and will override " @@ -151,39 +154,88 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:97 +#: sssd.conf.5.xml:102 msgid "" "The snippet files require the same owner and permissions as " "<filename>sssd.conf</filename>." msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:103 +#: sssd.conf.5.xml:108 +msgid "VENDOR PROVIDED CONFIGURATION" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:111 +msgid "" +"The vendor provided configuration file is installed in " +"<filename>&sssd_vendor_dir;/sssd.conf</filename>, but this file must not be " +"directly edited. It can be completely masked by creating the system specific " +"configuration file <filename>&sssd_conf_dir;/sssd.conf</filename>, or partly " +"overriden by creating config snippets in <filename>&sssd_conf_dir;/conf.d</" +"filename> directory." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><title> +#: sssd.conf.5.xml:120 +msgid "CONFIGURATION FILE HIERARCHY" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:122 +msgid "" +"When sssd reads the configuration it first tries to open the system specific " +"configuration file in <filename>&sssd_conf_dir;/sssd.conf</filename>. If it " +"exists, it is loaded and snippets from <filename>&sssd_conf_dir;/conf.d</" +"filename> are applied. The vendor provided configuration file " +"<filename>&sssd_vendor_dir;/sssd.conf</filename> is completely ignored in " +"this case." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:131 +msgid "" +"If the system specific configuration file <filename>&sssd_conf_dir;/" +"sssd.conf</filename> does not exist, then the vendor configuration file " +"<filename>&sssd_vendor_dir;/sssd.conf</filename> is loaded and snippets from " +"<filename>&sssd_conf_dir;/conf.d</filename> are applied." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd.conf.5.xml:141 msgid "GENERAL OPTIONS" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:105 +#: sssd.conf.5.xml:143 msgid "Following options are usable in more than one configuration sections." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:109 +#: sssd.conf.5.xml:147 msgid "Options usable in all sections" msgstr "" +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:149 +msgid "" +"Note: Below options are ignored in <quote>[session_recording]</quote> " +"section, see <quote>Session recording configuration options</quote> section " +"for more details." +msgstr "" + #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:113 +#: sssd.conf.5.xml:156 msgid "debug_level (integer)" msgstr "debug_level (integer)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:117 +#: sssd.conf.5.xml:160 msgid "debug (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:120 +#: sssd.conf.5.xml:163 msgid "" "SSSD 1.14 and later also includes the <replaceable>debug</replaceable> alias " "for <replaceable>debug_level</replaceable> as a convenience feature. If both " @@ -192,61 +244,67 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:130 -msgid "debug_timestamps (bool)" +#: sssd.conf.5.xml:173 +#, fuzzy +#| msgid "debug_timestamps (bool)" +msgid "debug_timestamps (boolean)" msgstr "debug_timestamps (bool)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:133 +#: sssd.conf.5.xml:176 msgid "" "Add a timestamp to the debug messages. If journald is enabled for SSSD " "debug logging this option is ignored." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:138 sssd.conf.5.xml:175 sssd.conf.5.xml:337 -#: sssd.conf.5.xml:644 sssd.conf.5.xml:668 sssd.conf.5.xml:875 -#: sssd.conf.5.xml:979 sssd.conf.5.xml:2113 sssd-ldap.5.xml:979 -#: sssd-ldap.5.xml:1134 sssd-ldap.5.xml:1237 sssd-ldap.5.xml:1306 -#: sssd-ldap.5.xml:1714 sssd-ldap.5.xml:1848 sssd-ldap.5.xml:1913 -#: sssd-ipa.5.xml:346 sssd-ad.5.xml:252 sssd-ad.5.xml:367 sssd-ad.5.xml:1180 -#: sssd-ad.5.xml:1382 sssd-krb5.5.xml:358 +#: sssd.conf.5.xml:181 sssd.conf.5.xml:218 sssd.conf.5.xml:380 +#: sssd.conf.5.xml:687 sssd.conf.5.xml:711 sssd.conf.5.xml:827 +#: sssd.conf.5.xml:932 sssd.conf.5.xml:2149 sssd.conf.5.xml:4730 +#: sssd-ldap.5.xml:979 sssd-ldap.5.xml:1134 sssd-ldap.5.xml:1237 +#: sssd-ldap.5.xml:1306 sssd-ldap.5.xml:1714 sssd-ldap.5.xml:1848 +#: sssd-ldap.5.xml:1913 sssd-ipa.5.xml:341 sssd-ad.5.xml:252 sssd-ad.5.xml:367 +#: sssd-ad.5.xml:1180 sssd-ad.5.xml:1375 sssd-krb5.5.xml:358 msgid "Default: true" msgstr "Oletus:tosi" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:143 -msgid "debug_microseconds (bool)" -msgstr "" +#: sssd.conf.5.xml:186 +#, fuzzy +#| msgid "debug_timestamps (bool)" +msgid "debug_microseconds (boolean)" +msgstr "debug_timestamps (bool)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:146 +#: sssd.conf.5.xml:189 msgid "" "Add microseconds to the timestamp in debug messages. If journald is enabled " "for SSSD debug logging this option is ignored." msgstr "" #. type: Content of: <variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:151 sssd.conf.5.xml:2040 sssd.conf.5.xml:4158 +#: sssd.conf.5.xml:194 sssd.conf.5.xml:2072 sssd.conf.5.xml:4363 #: sssd-ldap.5.xml:363 sssd-ldap.5.xml:998 sssd-ldap.5.xml:1209 -#: sssd-ldap.5.xml:1663 sssd-ldap.5.xml:1937 sssd-ipa.5.xml:146 -#: sssd-ipa.5.xml:706 sssd-ad.5.xml:1135 sssd-krb5.5.xml:268 +#: sssd-ldap.5.xml:1663 sssd-ldap.5.xml:1937 sssd-ipa.5.xml:141 +#: sssd-ipa.5.xml:701 sssd-ad.5.xml:1140 sssd-idp.5.xml:287 sssd-krb5.5.xml:268 #: sssd-krb5.5.xml:330 sssd-krb5.5.xml:432 include/krb5_options.xml:163 msgid "Default: false" msgstr "Oletus:epätosi" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:156 -msgid "debug_backtrace_enabled (bool)" +#: sssd.conf.5.xml:199 +#, fuzzy +#| msgid "debug_backtrace_enabled (bool)" +msgid "debug_backtrace_enabled (boolean)" msgstr "debug_backtrace_enabled (boolean)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:159 +#: sssd.conf.5.xml:202 msgid "Enable debug backtrace." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:162 +#: sssd.conf.5.xml:205 msgid "" "In case SSSD is run with debug_level less than 9, everything is logged to a " "ring buffer in memory and flushed to a log file on any error up to and " @@ -256,14 +314,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:171 +#: sssd.conf.5.xml:214 msgid "" "Feature is only supported for `logger == files` (i.e. setting doesn't have " "effect for other logger types)." msgstr "" #. type: Content of: outside any tag (error?) -#: sssd.conf.5.xml:111 sssd.conf.5.xml:186 sssd-ldap.5.xml:1754 +#: sssd.conf.5.xml:154 sssd.conf.5.xml:229 sssd-ldap.5.xml:1754 #: sssd-ldap.5.xml:1960 sss-certmap.5.xml:645 sssd-systemtap.5.xml:82 #: sssd-systemtap.5.xml:143 sssd-systemtap.5.xml:236 sssd-systemtap.5.xml:274 #: sssd-systemtap.5.xml:330 sssd-ldap-attributes.5.xml:40 @@ -276,17 +334,17 @@ msgid "<placeholder type=\"variablelist\" id=\"0\"/>" msgstr "<placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:184 +#: sssd.conf.5.xml:227 msgid "Options usable in SERVICE and DOMAIN sections" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:188 +#: sssd.conf.5.xml:231 msgid "timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:191 +#: sssd.conf.5.xml:234 msgid "" "Timeout in seconds between heartbeats for this service. This is used to " "ensure that the process is alive and capable of answering requests. Note " @@ -294,34 +352,36 @@ msgid "" msgstr "" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:198 sssd.conf.5.xml:1199 sssd.conf.5.xml:1673 -#: sssd.conf.5.xml:4174 sssd-ldap.5.xml:825 sssd-idp.5.xml:192 +#: sssd.conf.5.xml:241 sssd.conf.5.xml:1155 sssd.conf.5.xml:1665 +#: sssd.conf.5.xml:4379 sssd-ldap.5.xml:825 sssd-idp.5.xml:271 #: include/ldap_id_mapping.xml:270 msgid "Default: 10" msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:208 +#: sssd.conf.5.xml:251 msgid "SPECIAL SECTIONS" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:211 +#: sssd.conf.5.xml:254 msgid "The [sssd] section" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><title> -#: sssd.conf.5.xml:220 +#: sssd.conf.5.xml:263 msgid "Section parameters" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:222 -msgid "services" -msgstr "palvelut" +#: sssd.conf.5.xml:265 +#, fuzzy +#| msgid "ldap_user_principal" +msgid "services (string)" +msgstr "ldap_user_principal" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:225 +#: sssd.conf.5.xml:268 msgid "" "Comma separated list of services that are started when sssd itself starts. " "<phrase condition=\"have_systemd\"> The services' list is optional on " @@ -330,7 +390,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:234 +#: sssd.conf.5.xml:277 msgid "" "Supported services: nss, pam, ifp <phrase condition=\"with_sudo\">, sudo</" "phrase> <phrase condition=\"with_autofs\">, autofs</phrase> <phrase " @@ -339,20 +399,20 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:241 +#: sssd.conf.5.xml:284 msgid "" "<phrase condition=\"have_systemd\"> By default, all services are disabled " "and the administrator must enable the ones allowed to be used by executing: " "\"systemctl enable sssd-@service@.socket\". </phrase>" msgstr "" -#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:250 -msgid "domains" -msgstr "toimialueet" +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sssd.conf.5.xml:293 sssd.conf.5.xml:4562 +msgid "domains (string)" +msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:253 +#: sssd.conf.5.xml:296 msgid "" "A domain is a database containing user information. SSSD can use more " "domains at the same time, but at least one must be configured or SSSD won't " @@ -363,19 +423,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:266 sssd.conf.5.xml:3467 +#: sssd.conf.5.xml:309 sssd.conf.5.xml:3598 msgid "re_expression (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:269 +#: sssd.conf.5.xml:312 msgid "" "Default regular expression that describes how to parse the string containing " "user name and domain into these components." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:274 +#: sssd.conf.5.xml:317 msgid "" "Each domain can have an individual regular expression configured. For some " "ID providers there are also default regular expressions. See DOMAIN SECTIONS " @@ -383,12 +443,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:283 sssd.conf.5.xml:3524 +#: sssd.conf.5.xml:326 sssd.conf.5.xml:3655 msgid "full_name_format (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:286 sssd.conf.5.xml:3527 +#: sssd.conf.5.xml:329 sssd.conf.5.xml:3658 msgid "" "A <citerefentry> <refentrytitle>printf</refentrytitle> <manvolnum>3</" "manvolnum> </citerefentry>-compatible format that describes how to compose a " @@ -396,58 +456,58 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:297 sssd.conf.5.xml:3538 +#: sssd.conf.5.xml:340 sssd.conf.5.xml:3669 msgid "%1$s" msgstr "%1$s" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:298 sssd.conf.5.xml:3539 +#: sssd.conf.5.xml:341 sssd.conf.5.xml:3670 msgid "user name" msgstr "käyttäjänimi" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:301 sssd.conf.5.xml:3542 +#: sssd.conf.5.xml:344 sssd.conf.5.xml:3673 msgid "%2$s" msgstr "%2$s" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:304 sssd.conf.5.xml:3545 +#: sssd.conf.5.xml:347 sssd.conf.5.xml:3676 msgid "domain name as specified in the SSSD config file." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:310 sssd.conf.5.xml:3551 +#: sssd.conf.5.xml:353 sssd.conf.5.xml:3682 msgid "%3$s" msgstr "%3$s" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:313 sssd.conf.5.xml:3554 +#: sssd.conf.5.xml:356 sssd.conf.5.xml:3685 msgid "" "domain flat name. Mostly usable for Active Directory domains, both directly " "configured or discovered via IPA trusts." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:294 sssd.conf.5.xml:3535 +#: sssd.conf.5.xml:337 sssd.conf.5.xml:3666 msgid "" "The following expansions are supported: <placeholder type=\"variablelist\" " "id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:323 +#: sssd.conf.5.xml:366 msgid "" "Each domain can have an individual format string configured. See DOMAIN " "SECTIONS for more info on this option." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:329 +#: sssd.conf.5.xml:372 msgid "monitor_resolv_conf (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:332 +#: sssd.conf.5.xml:375 msgid "" "Controls if SSSD should monitor the state of resolv.conf to identify when it " "needs to update its internal DNS resolver." @@ -456,12 +516,12 @@ msgstr "" "tunnistaakseen, milloin sen on päivitettävä sisäinen DNS-selvittäjä." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:342 +#: sssd.conf.5.xml:385 msgid "try_inotify (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:345 +#: sssd.conf.5.xml:388 msgid "" "By default, SSSD will attempt to use inotify to monitor configuration files " "changes and will fall back to polling every five seconds if inotify cannot " @@ -469,7 +529,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:351 +#: sssd.conf.5.xml:394 msgid "" "There are some limited situations where it is preferred that we should skip " "even trying to use inotify. In these rare cases, this option should be set " @@ -477,26 +537,26 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:357 +#: sssd.conf.5.xml:400 msgid "" "Default: true on platforms where inotify is supported. False on other " "platforms." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:361 +#: sssd.conf.5.xml:404 msgid "" "Note: this option will have no effect on platforms where inotify is " "unavailable. On these platforms, polling will always be used." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:368 +#: sssd.conf.5.xml:411 msgid "krb5_rcache_dir (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:371 +#: sssd.conf.5.xml:414 msgid "" "Directory on the filesystem where SSSD should store Kerberos replay cache " "files." @@ -505,33 +565,33 @@ msgstr "" "toiston välimuistitiedostot." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:375 +#: sssd.conf.5.xml:418 msgid "" "This option accepts a special value __LIBKRB5_DEFAULTS__ that will instruct " "SSSD to let libkrb5 decide the appropriate location for the replay cache." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:381 +#: sssd.conf.5.xml:424 msgid "" "Default: Distribution-specific and specified at build-time. " "(__LIBKRB5_DEFAULTS__ if not configured)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:388 +#: sssd.conf.5.xml:431 msgid "default_domain_suffix (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:391 +#: sssd.conf.5.xml:434 msgid "" "Please note that this option is deprecated and domain_resolution_order " "should be used." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:395 +#: sssd.conf.5.xml:438 msgid "" "This string will be used as a default domain name for all names without a " "domain name component. The main use case is environments where the primary " @@ -541,7 +601,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:405 +#: sssd.conf.5.xml:448 msgid "" "Please note that if this option is set all users from the primary domain " "have to use their fully qualified name, e.g. user@domain.name, to log in. " @@ -551,21 +611,21 @@ msgid "" msgstr "" #. type: Content of: <variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:414 sssd-ldap.5.xml:937 sssd-ldap.5.xml:949 -#: sssd-ldap.5.xml:1042 sssd-ad.5.xml:921 sssd-ad.5.xml:996 sssd-krb5.5.xml:468 -#: sssd-ldap-attributes.5.xml:470 sssd-ldap-attributes.5.xml:978 -#: include/ldap_id_mapping.xml:211 include/ldap_id_mapping.xml:222 -#: include/krb5_options.xml:148 +#: sssd.conf.5.xml:457 sssd.conf.5.xml:2006 sssd-ldap.5.xml:937 +#: sssd-ldap.5.xml:949 sssd-ldap.5.xml:1042 sssd-ad.5.xml:926 +#: sssd-ad.5.xml:1001 sssd-krb5.5.xml:468 sssd-ldap-attributes.5.xml:470 +#: sssd-ldap-attributes.5.xml:978 include/ldap_id_mapping.xml:211 +#: include/ldap_id_mapping.xml:222 include/krb5_options.xml:148 msgid "Default: not set" msgstr "Oletus: ei asetettu" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:419 +#: sssd.conf.5.xml:462 msgid "override_space (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:422 +#: sssd.conf.5.xml:465 msgid "" "This parameter will replace spaces (space bar) with the given character for " "user and group names. e.g. (_). User name "john doe" will be " @@ -575,7 +635,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:431 +#: sssd.conf.5.xml:474 msgid "" "Please note it is a configuration error to use a replacement character that " "might be used in user or group names. If a name contains the replacement " @@ -584,22 +644,22 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:439 +#: sssd.conf.5.xml:482 msgid "Default: not set (spaces will not be replaced)" msgstr "Oletus: ei asetettu(välilyöntejä ei korvata)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:444 +#: sssd.conf.5.xml:487 msgid "certificate_verification (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:452 +#: sssd.conf.5.xml:495 msgid "no_ocsp" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:454 +#: sssd.conf.5.xml:497 msgid "" "Disables Online Certificate Status Protocol (OCSP) checks. This might be " "needed if the OCSP servers defined in the certificate are not reachable from " @@ -607,12 +667,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:462 +#: sssd.conf.5.xml:505 msgid "soft_ocsp" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:464 +#: sssd.conf.5.xml:507 msgid "" "If a connection cannot be established to an OCSP responder the OCSP check is " "skipped. This option should be used to allow authentication when the system " @@ -620,61 +680,61 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:474 +#: sssd.conf.5.xml:517 msgid "ocsp_dgst" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:476 +#: sssd.conf.5.xml:519 msgid "" "Digest (hash) function used to create the certificate ID for the OCSP " "request. Allowed values are:" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:480 +#: sssd.conf.5.xml:523 msgid "sha1" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:481 +#: sssd.conf.5.xml:524 msgid "sha256" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:482 +#: sssd.conf.5.xml:525 msgid "sha384" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:483 +#: sssd.conf.5.xml:526 msgid "sha512" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:486 +#: sssd.conf.5.xml:529 msgid "Default: sha1 (to allow compatibility with RFC5019-compliant responder)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:492 +#: sssd.conf.5.xml:535 msgid "no_verification" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:494 +#: sssd.conf.5.xml:537 msgid "" "Disables verification completely. This option should only be used for " "testing." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:500 +#: sssd.conf.5.xml:543 msgid "partial_chain" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:502 +#: sssd.conf.5.xml:545 msgid "" "Allow verification to succeed even if a <replaceable>complete</replaceable> " "chain cannot be built to a self-signed trust-anchor, provided it is possible " @@ -682,12 +742,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:511 +#: sssd.conf.5.xml:554 msgid "ocsp_default_responder=URL" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:513 +#: sssd.conf.5.xml:556 msgid "" "Sets the OCSP default responder which should be used instead of the one " "mentioned in the certificate. URL must be replaced with the URL of the OCSP " @@ -695,24 +755,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:523 +#: sssd.conf.5.xml:566 msgid "ocsp_default_responder_signing_cert=NAME" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:525 +#: sssd.conf.5.xml:568 msgid "" "This option is currently ignored. All needed certificates must be available " "in the PEM file given by pam_cert_db_path." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:533 +#: sssd.conf.5.xml:576 msgid "crl_file=/PATH/TO/CRL/FILE" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:535 +#: sssd.conf.5.xml:578 msgid "" "Use the Certificate Revocation List (CRL) from the given file during the " "verification of the certificate. The CRL must be given in PEM format, see " @@ -721,12 +781,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:548 +#: sssd.conf.5.xml:591 msgid "soft_crl" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:551 +#: sssd.conf.5.xml:594 msgid "" "If a Certificate Revocation List (CRL) is expired ignore the expiration " "time of the CRL and check the related certificates with the expired CRL. " @@ -735,7 +795,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:447 +#: sssd.conf.5.xml:490 msgid "" "With this parameter the certificate verification can be tuned with a comma " "separated list of options. Supported options are: <placeholder " @@ -743,46 +803,48 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:564 +#: sssd.conf.5.xml:607 msgid "Unknown options are reported but ignored." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:567 +#: sssd.conf.5.xml:610 msgid "Default: not set, i.e. do not restrict certificate verification" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:573 +#: sssd.conf.5.xml:616 msgid "disable_netlink (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:576 +#: sssd.conf.5.xml:619 msgid "" "SSSD hooks into the netlink interface to monitor changes to routes, " "addresses, links and trigger certain actions." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:581 +#: sssd.conf.5.xml:624 msgid "" "The SSSD state changes caused by netlink events may be undesirable and can " "be disabled by setting this option to 'true'" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:586 +#: sssd.conf.5.xml:629 msgid "Default: false (netlink changes are detected)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:591 -msgid "domain_resolution_order" -msgstr "" +#: sssd.conf.5.xml:634 +#, fuzzy +#| msgid "ldap_user_principal" +msgid "domain_resolution_order (string)" +msgstr "ldap_user_principal" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:594 +#: sssd.conf.5.xml:637 msgid "" "Comma separated list of domains and subdomains representing the lookup order " "that will be followed. The list doesn't have to include all possible " @@ -793,22 +855,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:606 -#, fuzzy -#| msgid "" -#| "Please, note that when this option is set the output format of all " -#| "commands is always fully-qualified even when using short names for input " -#| "<phrase condition=\"with_files_provider\"> , for all users but the ones " -#| "managed by the files provider </phrase>. In case the administrator wants " -#| "the output not fully-qualified, the full_name_format option can be used " -#| "as shown below: <quote>full_name_format=%1$s</quote> However, keep in " -#| "mind that during login, login applications often canonicalize the " -#| "username by calling <citerefentry> <refentrytitle>getpwnam</" -#| "refentrytitle> <manvolnum>3</manvolnum> </citerefentry> which, if a " -#| "shortname is returned for a qualified input (while trying to reach a user " -#| "which exists in multiple domains) might re-route the login attempt into " -#| "the domain which uses shortnames, making this workaround totally not " -#| "recommended in cases where usernames may overlap between domains." +#: sssd.conf.5.xml:649 msgid "" "Please, note that when this option is set the output format of all commands " "is always fully-qualified even when using short names for input. In case " @@ -822,36 +869,35 @@ msgid "" "domain which uses shortnames, making this workaround totally not recommended " "in cases where usernames may overlap between domains." msgstr "" -"Huomaa, että kun tämä vaihtoehto on asetettu, kaikkien komentojen tulosteen " -"muoto on aina täysin määritelty, vaikka syötteelle käytettäisiin lyhyitä " -"nimiä <phrase condition=\"with_files_provider\"> kaikille käyttäjille paitsi " -"niille, joita tiedostotoimittaja hallitsee </phrase >. Jos " -"järjestelmänvalvoja haluaa, että tuloste ei ole täysin määritelty, " -"full_name_format -vaihtoehtoa voidaan käyttää alla olevan kuvan mukaisesti: " -"<quote>full_name_format=%1$s</quote> Muista kuitenkin, että " -"sisäänkirjautumisen aikana sisäänkirjautumissovellukset usein kanonisoivat " -"käyttäjänimen. kutsumalla <citerefentry> <refentrytitle>getpwnam</" -"refentrytitle> <manvolnum>3</manvolnum> </citerefentry> joka, jos lyhyt nimi " -"palautetaan pätevälle syötteelle (yritettäessä tavoittaa useissa " -"verkkotunnuksissa olevaa käyttäjää), saattaa ohjata kirjautumisyrityksen " -"uudelleen lyhyitä nimiä käyttävään verkkotunnukseen, joten tämä kiertotapa " -"ei ole suositeltavaa tapauksissa jossa käyttäjänimet voivat mennä " -"päällekkäin verkkotunnusten välillä." - -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:630 sssd.conf.5.xml:1697 sssd.conf.5.xml:4224 -#: sssd-ad.5.xml:187 sssd-ad.5.xml:328 sssd-ad.5.xml:342 sssd-idp.5.xml:108 -#: sssd-idp.5.xml:132 sssd-idp.5.xml:145 sssd-idp.5.xml:159 sssd-idp.5.xml:180 +"Huomaa, että kun tämä asetus on asetettu, kaikkien komentojen tulostusmuoto " +"on aina täysin määritelty, vaikka syötteenä käytettäisiin lyhyitä nimiä. Jos " +"ylläpitäjä ei halua tulosteen olevan täysin määritelty, full_name_format-" +"asetusta voidaan käyttää alla olevan mukaisesti: <quote>" +"full_name_format=%1$s</quote> Muista kuitenkin, että kirjautumisen aikana " +"kirjautumissovellukset usein kanonisoivat käyttäjätunnuksen kutsumalla " +"funktiota <citerefentry> <refentrytitle>getpwnam</refentrytitle> <manvolnum>" +"3</manvolnum> </citerefentry>. Jos pätevälle syötteelle palautetaan " +"lyhytnimi (yritettäessä tavoittaa käyttäjää, joka on useilla " +"verkkotunnuksilla), kirjautumisyritys saattaa reitittää uudelleen " +"verkkotunnukseen, joka käyttää lyhyitä nimiä. Tämä tekee tästä kiertotavasta " +"täysin epäsuositeltavaa tapauksissa, joissa käyttäjätunnukset voivat olla " +"päällekkäisiä eri verkkotunnusten välillä." + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:673 sssd.conf.5.xml:1026 sssd.conf.5.xml:1689 +#: sssd.conf.5.xml:4429 sssd-ad.5.xml:187 sssd-ad.5.xml:328 sssd-ad.5.xml:342 +#: sssd-idp.5.xml:112 sssd-idp.5.xml:136 sssd-idp.5.xml:149 sssd-idp.5.xml:167 +#: sssd-idp.5.xml:188 msgid "Default: Not set" msgstr "Oletus: ei asetettu" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:635 +#: sssd.conf.5.xml:678 msgid "implicit_pac_responder (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:638 +#: sssd.conf.5.xml:681 msgid "" "The PAC responder is enabled automatically for the IPA and AD provider to " "evaluate and check the PAC. If it has to be disabled set this option to " @@ -859,12 +905,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:649 +#: sssd.conf.5.xml:692 msgid "core_dumpable (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:652 +#: sssd.conf.5.xml:695 msgid "" "This option can be used for general system hardening: setting it to 'false' " "forbids core dumps for all SSSD processes to avoid leaking plain text " @@ -873,7 +919,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:660 +#: sssd.conf.5.xml:703 msgid "" "Take a note that this setting has no effect for 'ldap_child', 'krb5_child' " "and 'sssd_pam' as those privileged binaries can have a copy of a host keytab " @@ -882,24 +928,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:673 +#: sssd.conf.5.xml:716 msgid "passkey_verification (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:681 +#: sssd.conf.5.xml:724 msgid "user_verification (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:683 +#: sssd.conf.5.xml:726 msgid "" "Enable or disable the user verification (i.e. PIN, fingerprint) during " "authentication. If enabled, the PIN will always be requested." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:689 +#: sssd.conf.5.xml:732 msgid "" "The default is that the key settings decide what to do. In the IPA or " "kerberos pre-authentication case, this value will be overwritten by the " @@ -907,7 +953,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:676 +#: sssd.conf.5.xml:719 msgid "" "With this parameter the passkey verification can be tuned with a comma " "separated list of options. Supported options are: <placeholder " @@ -915,7 +961,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:213 +#: sssd.conf.5.xml:256 msgid "" "Individual pieces of SSSD functionality are provided by special SSSD " "services that are started and stopped together with SSSD. The services are " @@ -926,12 +972,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:708 +#: sssd.conf.5.xml:751 msgid "SERVICES SECTIONS" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:710 +#: sssd.conf.5.xml:753 msgid "" "Settings that can be used to configure different services are described in " "this section. They should reside in the [<replaceable>$NAME</replaceable>] " @@ -940,42 +986,45 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:717 +#: sssd.conf.5.xml:760 msgid "General service configuration options" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:719 +#: sssd.conf.5.xml:762 msgid "These options can be used to configure any service." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:723 -msgid "fd_limit" -msgstr "fd_limit" +#: sssd.conf.5.xml:766 +#, fuzzy +#| msgid "offline_timeout (integer)" +msgid "fd_limit (integer)" +msgstr "offline_timeout (integeri)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:726 +#: sssd.conf.5.xml:769 msgid "" "This option specifies the maximum number of file descriptors that may be " -"opened at one time by this SSSD process. On systems where SSSD is granted " -"the CAP_SYS_RESOURCE capability, this will be an absolute setting. On " -"systems without this capability, the resulting value will be the lower value " -"of this or the limits.conf \"hard\" limit." +"opened at one time by this SSSD process. Note this value will be capped by " +"the init system at the startup of SSSD, see e.g. man systemd.exec for " +"details." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:735 +#: sssd.conf.5.xml:776 msgid "Default: 8192 (or limits.conf \"hard\" limit)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:740 -msgid "client_idle_timeout" -msgstr "client_idle_timeout" +#: sssd.conf.5.xml:781 +#, fuzzy +#| msgid "offline_timeout (integer)" +msgid "client_idle_timeout (integer)" +msgstr "offline_timeout (integeri)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:743 +#: sssd.conf.5.xml:784 msgid "" "This option specifies the number of seconds that a client of an SSSD process " "can hold onto a file descriptor without communicating on it. This value is " @@ -985,140 +1034,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:752 +#: sssd.conf.5.xml:793 msgid "Default: 60, KCM: 300" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:757 -msgid "offline_timeout (integer)" -msgstr "offline_timeout (integeri)" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:760 -msgid "" -"When SSSD switches to offline mode the amount of time before it tries to go " -"back online will increase based upon the time spent disconnected. By " -"default SSSD uses incremental behaviour to calculate delay in between " -"retries. So, the wait time for a given retry will be longer than the wait " -"time for the previous ones. After each unsuccessful attempt to go online, " -"the new interval is recalculated by the following:" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:771 sssd.conf.5.xml:827 -msgid "" -"new_delay = Minimum(old_delay * 2, offline_timeout_max) + " -"random[0...offline_timeout_random_offset]" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:774 -msgid "" -"The offline_timeout default value is 60. The offline_timeout_max default " -"value is 3600. The offline_timeout_random_offset default value is 30. The " -"end result is amount of seconds before next retry." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:780 -msgid "" -"Note that the maximum length of each interval is defined by " -"offline_timeout_max (apart of random part)." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:784 sssd.conf.5.xml:1110 sssd.conf.5.xml:1490 -#: sssd.conf.5.xml:1791 sssd-ldap.5.xml:550 -msgid "Default: 60" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:789 -msgid "offline_timeout_max (integer)" -msgstr "offline_timeout_max (integeri)" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:792 -msgid "" -"Controls by how much the time between attempts to go online can be " -"incremented following unsuccessful attempts to go online." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:797 -msgid "A value of 0 disables the incrementing behaviour." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:800 -msgid "" -"The value of this parameter should be set in correlation to offline_timeout " -"parameter value." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:804 -msgid "" -"With offline_timeout set to 60 (default value) there is no point in setting " -"offlinet_timeout_max to less than 120 as it will saturate instantly. General " -"rule here should be to set offline_timeout_max to at least 4 times " -"offline_timeout." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:810 -msgid "" -"Although a value between 0 and offline_timeout may be specified, it has the " -"effect of overriding the offline_timeout value so is of little use." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:815 -msgid "Default: 3600" -msgstr "Oletus: 3600" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:820 -msgid "offline_timeout_random_offset (integer)" -msgstr "offline_timeout_random_offset (integeri)" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:823 -msgid "" -"When SSSD is in offline mode it keeps probing backend servers in specified " -"time intervals:" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:830 -msgid "" -"This parameter controls the value of the random offset used for the above " -"equation. Final random_offset value will be random number in range:" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:835 -msgid "[0 - offline_timeout_random_offset]" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:838 -msgid "A value of 0 disables the random offset addition." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:841 -msgid "Default: 30" -msgstr "Oletus: 30" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:846 -msgid "responder_idle_timeout" -msgstr "" +#: sssd.conf.5.xml:798 +#, fuzzy +#| msgid "ad_gpo_cache_timeout (integer)" +msgid "responder_idle_timeout (integer)" +msgstr "ad_gpo_cache_timeout (integeri)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:849 +#: sssd.conf.5.xml:801 msgid "" "This option specifies the number of seconds that an SSSD responder process " "can be up without being used. This value is limited in order to avoid " @@ -1130,58 +1058,59 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:863 sssd.conf.5.xml:1123 sssd.conf.5.xml:2248 +#: sssd.conf.5.xml:815 sssd.conf.5.xml:1079 sssd.conf.5.xml:2285 #: sssd-ldap.5.xml:377 msgid "Default: 300" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:868 -msgid "cache_first" +#: sssd.conf.5.xml:820 +msgid "cache_first (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:871 +#: sssd.conf.5.xml:823 msgid "" "This option specifies whether the responder should query all caches before " "querying the Data Providers." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:883 +#: sssd.conf.5.xml:835 msgid "NSS configuration options" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:885 +#: sssd.conf.5.xml:837 msgid "" -"These options can be used to configure the Name Service Switch (NSS) service." +"These options can be used to configure the Name Service Switch (NSS) service " +"and should be specified under the <quote>[nss]</quote> section." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:890 +#: sssd.conf.5.xml:843 msgid "enum_cache_timeout (integer)" msgstr "enum_cache_timeout (integeri)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:893 +#: sssd.conf.5.xml:846 msgid "" "How many seconds should nss_sss cache enumerations (requests for info about " "all users)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:897 +#: sssd.conf.5.xml:850 msgid "Default: 120" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:902 +#: sssd.conf.5.xml:855 msgid "entry_cache_nowait_percentage (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:905 +#: sssd.conf.5.xml:858 msgid "" "The entry cache can be set to automatically update entries in the background " "if they are requested beyond a percentage of the entry_cache_timeout value " @@ -1189,7 +1118,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:911 +#: sssd.conf.5.xml:864 msgid "" "For example, if the domain's entry_cache_timeout is set to 30s and " "entry_cache_nowait_percentage is set to 50 (percent), entries that come in " @@ -1199,7 +1128,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:921 +#: sssd.conf.5.xml:874 msgid "" "Valid values for this option are 0-99 and represent a percentage of the " "entry_cache_timeout for each domain. For performance reasons, this " @@ -1208,17 +1137,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:929 sssd.conf.5.xml:2061 +#: sssd.conf.5.xml:882 sssd.conf.5.xml:2093 msgid "Default: 50" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:934 +#: sssd.conf.5.xml:887 msgid "entry_negative_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:937 +#: sssd.conf.5.xml:890 msgid "" "Specifies for how many seconds nss_sss should cache negative cache hits " "(that is, queries for invalid database entries, like nonexistent ones) " @@ -1226,17 +1155,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:943 sssd.conf.5.xml:1685 sssd.conf.5.xml:2085 +#: sssd.conf.5.xml:896 sssd.conf.5.xml:1677 sssd.conf.5.xml:2119 msgid "Default: 15" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:948 +#: sssd.conf.5.xml:901 msgid "filter_users, filter_groups (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:951 +#: sssd.conf.5.xml:904 msgid "" "Exclude certain users or groups from being fetched from the sss NSS " "database. This is particularly useful for system accounts. This option can " @@ -1245,7 +1174,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:959 +#: sssd.conf.5.xml:912 msgid "" "NOTE: The filter_groups option doesn't affect inheritance of nested group " "members, since filtering happens after they are propagated for returning via " @@ -1254,41 +1183,41 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:967 +#: sssd.conf.5.xml:920 msgid "Default: root" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:972 -msgid "filter_users_in_groups (bool)" +#: sssd.conf.5.xml:925 +msgid "filter_users_in_groups (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:975 +#: sssd.conf.5.xml:928 msgid "" -"If you want filtered user still be group members set this option to false." +"If you want filtered users to remain group members set this option to false" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:986 +#: sssd.conf.5.xml:939 msgid "fallback_homedir (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:989 +#: sssd.conf.5.xml:942 msgid "" "Set a default template for a user's home directory if one is not specified " "explicitly by the domain's data provider." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:994 +#: sssd.conf.5.xml:947 msgid "" "The available values for this option are the same as for override_homedir." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1000 +#: sssd.conf.5.xml:953 #, no-wrap msgid "" "fallback_homedir = /home/%u\n" @@ -1296,23 +1225,23 @@ msgid "" msgstr "" #. type: Content of: <varlistentry><listitem><para> -#: sssd.conf.5.xml:998 sssd.conf.5.xml:1557 sssd.conf.5.xml:1576 -#: sssd.conf.5.xml:1653 sssd-krb5.5.xml:451 include/override_homedir.xml:78 +#: sssd.conf.5.xml:951 sssd.conf.5.xml:1524 sssd.conf.5.xml:1543 +#: sssd.conf.5.xml:1645 sssd-krb5.5.xml:451 include/override_homedir.xml:78 msgid "example: <placeholder type=\"programlisting\" id=\"0\"/>" msgstr "Esimerkki: <placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1004 +#: sssd.conf.5.xml:957 msgid "Default: not set (no substitution for unset home directories)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1010 +#: sssd.conf.5.xml:963 msgid "override_shell (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1013 +#: sssd.conf.5.xml:966 msgid "" "Override the login shell for all users. This option supersedes any other " "shell options if it takes effect and can be set either in the [nss] section " @@ -1320,47 +1249,47 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1019 +#: sssd.conf.5.xml:972 msgid "Default: not set (SSSD will use the value retrieved from LDAP)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1025 +#: sssd.conf.5.xml:978 msgid "allowed_shells (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1028 +#: sssd.conf.5.xml:981 msgid "" "Restrict user shell to one of the listed values. The order of evaluation is:" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1031 +#: sssd.conf.5.xml:984 msgid "1. If the shell is present in <quote>/etc/shells</quote>, it is used." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1035 +#: sssd.conf.5.xml:988 msgid "" "2. If the shell is in the allowed_shells list but not in <quote>/etc/shells</" "quote>, use the value of the shell_fallback parameter." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1040 +#: sssd.conf.5.xml:993 msgid "" "3. If the shell is not in the allowed_shells list and not in <quote>/etc/" "shells</quote>, a nologin shell is used." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1045 +#: sssd.conf.5.xml:998 msgid "The wildcard (*) can be used to allow any shell." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1048 +#: sssd.conf.5.xml:1001 msgid "" "The (*) is useful if you want to use shell_fallback in case that user's " "shell is not in <quote>/etc/shells</quote> and maintaining list of all " @@ -1368,113 +1297,121 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1055 +#: sssd.conf.5.xml:1008 msgid "An empty string for shell is passed as-is to libc." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1058 +#: sssd.conf.5.xml:1011 msgid "" "The <quote>/etc/shells</quote> is only read on SSSD start up, which means " "that a restart of the SSSD is required in case a new shell is installed." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1062 +#: sssd.conf.5.xml:1015 msgid "Default: Not set. The user shell is automatically used." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1067 +#: sssd.conf.5.xml:1020 msgid "vetoed_shells (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1070 +#: sssd.conf.5.xml:1023 msgid "Replace any instance of these shells with the shell_fallback" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1075 +#: sssd.conf.5.xml:1031 msgid "shell_fallback (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1078 +#: sssd.conf.5.xml:1034 msgid "" "The default shell to use if an allowed shell is not installed on the machine." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1082 +#: sssd.conf.5.xml:1038 msgid "Default: /bin/sh" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1087 -msgid "default_shell" +#: sssd.conf.5.xml:1043 +#, fuzzy +#| msgid "default_shell" +msgid "default_shell (string)" msgstr "Oletuskomentorivitulkki" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1090 +#: sssd.conf.5.xml:1046 msgid "" "The default shell to use if the provider does not return one during lookup. " "This option can be specified globally in the [nss] section or per-domain." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1096 +#: sssd.conf.5.xml:1052 msgid "" "Default: not set (Return NULL if no shell is specified and rely on libc to " "substitute something sensible when necessary, usually /bin/sh)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1103 sssd.conf.5.xml:1483 +#: sssd.conf.5.xml:1059 sssd.conf.5.xml:1450 msgid "get_domains_timeout (int)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1106 sssd.conf.5.xml:1486 +#: sssd.conf.5.xml:1062 sssd.conf.5.xml:1453 msgid "" "Specifies time in seconds for which the list of subdomains will be " "considered valid." msgstr "" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1066 sssd.conf.5.xml:1457 sssd.conf.5.xml:1788 +#: sssd.conf.5.xml:2862 sssd-ldap.5.xml:550 +msgid "Default: 60" +msgstr "" + #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1115 +#: sssd.conf.5.xml:1071 msgid "memcache_timeout (integer)" msgstr "memcache_timeout (integeri)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1118 +#: sssd.conf.5.xml:1074 msgid "" "Specifies time in seconds for which records in the in-memory cache will be " "valid. Setting this option to zero will disable the in-memory cache." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1126 +#: sssd.conf.5.xml:1082 msgid "" "WARNING: Disabling the in-memory cache will have significant negative impact " "on SSSD's performance and should only be used for testing." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1132 sssd.conf.5.xml:1157 sssd.conf.5.xml:1182 -#: sssd.conf.5.xml:1207 sssd.conf.5.xml:1234 +#: sssd.conf.5.xml:1088 sssd.conf.5.xml:1113 sssd.conf.5.xml:1138 +#: sssd.conf.5.xml:1163 sssd.conf.5.xml:1190 msgid "" "NOTE: If the environment variable SSS_NSS_USE_MEMCACHE is set to \"NO\", " "client applications will not use the fast in-memory cache." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1140 +#: sssd.conf.5.xml:1096 msgid "memcache_size_passwd (integer)" msgstr "memcache_size_passwd (integeri)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1143 +#: sssd.conf.5.xml:1099 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for passwd requests. Setting the size to 0 will disable the passwd in-" @@ -1482,25 +1419,25 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1149 sssd.conf.5.xml:2888 sssd-ldap.5.xml:604 +#: sssd.conf.5.xml:1105 sssd.conf.5.xml:3013 sssd-ldap.5.xml:604 msgid "Default: 8" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1152 sssd.conf.5.xml:1177 sssd.conf.5.xml:1202 -#: sssd.conf.5.xml:1229 +#: sssd.conf.5.xml:1108 sssd.conf.5.xml:1133 sssd.conf.5.xml:1158 +#: sssd.conf.5.xml:1185 msgid "" "WARNING: Disabled or too small in-memory cache can have significant negative " "impact on SSSD's performance." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1165 +#: sssd.conf.5.xml:1121 msgid "memcache_size_group (integer)" msgstr "memcache_size_group (integeri)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1168 +#: sssd.conf.5.xml:1124 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for group requests. Setting the size to 0 will disable the group in-memory " @@ -1508,19 +1445,19 @@ msgid "" msgstr "" #. type: Content of: <variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1174 sssd.conf.5.xml:1226 sssd.conf.5.xml:3656 +#: sssd.conf.5.xml:1130 sssd.conf.5.xml:1182 sssd.conf.5.xml:3835 #: sssd-ldap.5.xml:534 sssd-ldap.5.xml:581 include/failover.xml:116 #: include/krb5_options.xml:11 msgid "Default: 6" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1190 +#: sssd.conf.5.xml:1146 msgid "memcache_size_initgroups (integer)" msgstr "memcache_size_initgroups (integeri)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1193 +#: sssd.conf.5.xml:1149 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for initgroups requests. Setting the size to 0 will disable the initgroups " @@ -1528,14 +1465,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1215 +#: sssd.conf.5.xml:1171 #, fuzzy #| msgid "memcache_size_passwd (integer)" msgid "memcache_size_sid (integer)" msgstr "memcache_size_passwd (integeri)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1218 +#: sssd.conf.5.xml:1174 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for SID related requests. Only SID-by-ID and ID-by-SID requests are " @@ -1544,12 +1481,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1242 sssd-ifp.5.xml:90 +#: sssd.conf.5.xml:1198 sssd-ifp.5.xml:90 msgid "user_attributes (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1245 +#: sssd.conf.5.xml:1201 msgid "" "Some of the additional NSS responder requests can return more attributes " "than just the POSIX ones defined by the NSS interface. The list of " @@ -1560,103 +1497,109 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1258 +#: sssd.conf.5.xml:1214 msgid "" "To make configuration more easy the NSS responder will check the InfoPipe " "option if it is not set for the NSS responder." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1263 +#: sssd.conf.5.xml:1219 msgid "Default: not set, fallback to InfoPipe option" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1268 +#: sssd.conf.5.xml:1224 msgid "pwfield (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1271 +#: sssd.conf.5.xml:1227 msgid "" "The value that NSS operations that return users or groups will return for " "the <quote>password</quote> field." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1276 -msgid "Default: <quote>*</quote>" -msgstr "Oletus: <quote>*</quote>" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1279 +#: sssd.conf.5.xml:1232 msgid "" -"Note: This option can also be set per-domain which overwrites the value in " -"[nss] section." +"This option can also be set per-domain, which overwrites the value in the " +"<quote>[nss]</quote> section for that domain. This is particularly useful " +"when using a proxy domain with <option>proxy_lib_name=files</option> and a " +"<option>proxy_pam_target</option> other than <quote>sssd-shadowutils</" +"quote>. In that case, SSSD returns <quote>*</quote> for the password field " +"by default, which causes <command>pam_unix</command> to treat all accounts " +"as locked. Setting <option>pwfield = x</option> in the domain section " +"restores the expected behavior." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1283 +#: sssd.conf.5.xml:1246 +msgid "Default: <quote>*</quote>" +msgstr "Oletus: <quote>*</quote>" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1249 msgid "" -"Default: <quote>not set</quote> (remote domains), <quote>x</quote> (proxy " -"domain with nss_files and sssd-shadowutils target)" +"Default (per-domain): <quote>not set</quote> (remote domains), <quote>x</" +"quote> (proxy domain with nss_files and sssd-shadowutils target)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:1292 +#: sssd.conf.5.xml:1258 msgid "PAM configuration options" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:1294 +#: sssd.conf.5.xml:1260 msgid "" "These options can be used to configure the Pluggable Authentication Module " -"(PAM) service." +"(PAM) service and should be specified under the <quote>[pam]</quote> section." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1299 +#: sssd.conf.5.xml:1266 msgid "offline_credentials_expiration (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1302 +#: sssd.conf.5.xml:1269 msgid "" "If the authentication provider is offline, how long should we allow cached " "logins (in days since the last successful online login)." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1307 sssd.conf.5.xml:1320 +#: sssd.conf.5.xml:1274 sssd.conf.5.xml:1287 msgid "Default: 0 (No limit)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1313 +#: sssd.conf.5.xml:1280 msgid "offline_failed_login_attempts (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1316 +#: sssd.conf.5.xml:1283 msgid "" "If the authentication provider is offline, how many failed login attempts " "are allowed." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1326 +#: sssd.conf.5.xml:1293 msgid "offline_failed_login_delay (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1329 +#: sssd.conf.5.xml:1296 msgid "" "The time in minutes which has to pass after offline_failed_login_attempts " "has been reached before a new login attempt is possible." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1334 +#: sssd.conf.5.xml:1301 msgid "" "If set to 0 the user cannot authenticate offline if " "offline_failed_login_attempts has been reached. Only a successful online " @@ -1664,59 +1607,59 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1340 sssd.conf.5.xml:1450 +#: sssd.conf.5.xml:1307 sssd.conf.5.xml:1417 msgid "Default: 5" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1346 +#: sssd.conf.5.xml:1313 msgid "pam_verbosity (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1349 +#: sssd.conf.5.xml:1316 msgid "" "Controls what kind of messages are shown to the user during authentication. " "The higher the number to more messages are displayed." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1354 +#: sssd.conf.5.xml:1321 msgid "Currently sssd supports the following values:" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1357 +#: sssd.conf.5.xml:1324 msgid "<emphasis>0</emphasis>: do not show any message" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1360 +#: sssd.conf.5.xml:1327 msgid "<emphasis>1</emphasis>: show only important messages" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1364 +#: sssd.conf.5.xml:1331 msgid "<emphasis>2</emphasis>: show informational messages" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1367 +#: sssd.conf.5.xml:1334 msgid "<emphasis>3</emphasis>: show all messages and debug information" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1371 sssd.8.xml:63 +#: sssd.conf.5.xml:1338 sssd.8.xml:63 msgid "Default: 1" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1377 +#: sssd.conf.5.xml:1344 msgid "pam_response_filter (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1380 +#: sssd.conf.5.xml:1347 msgid "" "A comma separated list of strings which allows to remove (filter) data sent " "by the PAM responder to pam_sss PAM module. There are different kind of " @@ -1725,51 +1668,51 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1388 +#: sssd.conf.5.xml:1355 msgid "" "While messages already can be controlled with the help of the pam_verbosity " "option this option allows to filter out other kind of responses as well." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1395 +#: sssd.conf.5.xml:1362 msgid "ENV" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1396 +#: sssd.conf.5.xml:1363 msgid "Do not send any environment variables to any service." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1399 +#: sssd.conf.5.xml:1366 msgid "ENV:var_name" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1400 +#: sssd.conf.5.xml:1367 msgid "Do not send environment variable var_name to any service." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1404 +#: sssd.conf.5.xml:1371 msgid "ENV:var_name:service" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1405 +#: sssd.conf.5.xml:1372 msgid "Do not send environment variable var_name to service." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1393 +#: sssd.conf.5.xml:1360 msgid "" "Currently the following filters are supported: <placeholder " "type=\"variablelist\" id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1412 +#: sssd.conf.5.xml:1379 msgid "" "The list of strings can either be the list of filters which would set this " "list of filters and overwrite the defaults. Or each element of the list can " @@ -1780,23 +1723,23 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1423 +#: sssd.conf.5.xml:1390 msgid "Default: ENV:KRB5CCNAME:sudo, ENV:KRB5CCNAME:sudo-i" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1426 +#: sssd.conf.5.xml:1393 msgid "" "Example: -ENV:KRB5CCNAME:sudo-i will remove the filter from the default list" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1433 +#: sssd.conf.5.xml:1400 msgid "pam_id_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1436 +#: sssd.conf.5.xml:1403 msgid "" "For any PAM request while SSSD is online, the SSSD will attempt to " "immediately update the cached identity information for the user in order to " @@ -1804,7 +1747,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1442 +#: sssd.conf.5.xml:1409 msgid "" "A complete PAM conversation may perform multiple PAM requests, such as " "account management and session opening. This option controls (on a per-" @@ -1813,17 +1756,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1456 +#: sssd.conf.5.xml:1423 msgid "pam_pwd_expiration_warning (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1459 sssd.conf.5.xml:2912 +#: sssd.conf.5.xml:1426 sssd.conf.5.xml:3037 msgid "Display a warning N days before the password expires." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1462 +#: sssd.conf.5.xml:1429 msgid "" "Please note that the backend server has to provide information about the " "expiration time of the password. If this information is missing, sssd " @@ -1831,32 +1774,32 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1468 sssd.conf.5.xml:2915 +#: sssd.conf.5.xml:1435 sssd.conf.5.xml:3040 msgid "" "If zero is set, then this filter is not applied, i.e. if the expiration " "warning was received from backend server, it will automatically be displayed." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1473 +#: sssd.conf.5.xml:1440 msgid "" "This setting can be overridden by setting <emphasis>pwd_expiration_warning</" "emphasis> for a particular domain." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1478 sssd.conf.5.xml:3913 sssd-ldap.5.xml:662 +#: sssd.conf.5.xml:1445 sssd.conf.5.xml:4118 sssd-ldap.5.xml:662 #: sssd-ldap.5.xml:1733 sssd.8.xml:79 msgid "Default: 0" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1495 +#: sssd.conf.5.xml:1462 msgid "pam_trusted_users (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1498 +#: sssd.conf.5.xml:1465 msgid "" "Specifies the comma-separated list of UID values or user names that are " "allowed to run PAM conversations against trusted domains. Users not " @@ -1866,74 +1809,74 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1508 +#: sssd.conf.5.xml:1475 msgid "Default: All users are considered trusted by default" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1512 +#: sssd.conf.5.xml:1479 msgid "" "Please note that UID 0 is always allowed to access the PAM responder even in " "case it is not in the pam_trusted_users list." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1519 +#: sssd.conf.5.xml:1486 msgid "pam_public_domains (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1522 +#: sssd.conf.5.xml:1489 msgid "" "Specifies the comma-separated list of domain names that are accessible even " "to untrusted users." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1526 +#: sssd.conf.5.xml:1493 msgid "Two special values for pam_public_domains option are defined:" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1530 +#: sssd.conf.5.xml:1497 msgid "" "all (Untrusted users are allowed to access all domains in PAM responder.)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1534 +#: sssd.conf.5.xml:1501 msgid "" "none (Untrusted users are not allowed to access any domains PAM in " "responder.)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1538 sssd.conf.5.xml:1563 sssd.conf.5.xml:1582 -#: sssd.conf.5.xml:1824 sssd.conf.5.xml:3842 sssd-ldap.5.xml:1270 +#: sssd.conf.5.xml:1505 sssd.conf.5.xml:1530 sssd.conf.5.xml:1549 +#: sssd.conf.5.xml:1821 sssd.conf.5.xml:4048 sssd-ldap.5.xml:1270 msgid "Default: none" msgstr "Oletus: ei mitään" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1543 +#: sssd.conf.5.xml:1510 msgid "pam_account_expired_message (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1546 +#: sssd.conf.5.xml:1513 msgid "" "Allows a custom expiration message to be set, replacing the default " "'Permission denied' message." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1551 +#: sssd.conf.5.xml:1518 msgid "" "Note: Please be aware that message is only printed for the SSH service " "unless pam_verbosity is set to 3 (show all messages and debug information)." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1559 +#: sssd.conf.5.xml:1526 #, no-wrap msgid "" "pam_account_expired_message = Account expired, please contact help desk.\n" @@ -1941,19 +1884,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1568 +#: sssd.conf.5.xml:1535 msgid "pam_account_locked_message (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1571 +#: sssd.conf.5.xml:1538 msgid "" "Allows a custom lockout message to be set, replacing the default 'Permission " "denied' message." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1578 +#: sssd.conf.5.xml:1545 #, no-wrap msgid "" "pam_account_locked_message = Account locked, please contact help desk.\n" @@ -1961,81 +1904,122 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1587 -msgid "pam_passkey_auth (bool)" +#: sssd.conf.5.xml:1554 +msgid "pam_passkey_auth (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1590 +#: sssd.conf.5.xml:1557 msgid "Enable passkey device based authentication." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1593 sssd.conf.5.xml:1910 sssd-ad.5.xml:1286 +#: sssd.conf.5.xml:1560 sssd.conf.5.xml:1907 sssd-ad.5.xml:1279 #: sss_rpcidmapd.5.xml:76 msgid "Default: True" msgstr "Oletus:tosi" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1598 -msgid "passkey_debug_libfido2 (bool)" +#: sssd.conf.5.xml:1565 +msgid "passkey_debug_libfido2 (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1601 +#: sssd.conf.5.xml:1568 msgid "Enable libfido2 library debug messages." msgstr "" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1604 sssd.conf.5.xml:1618 sssd-ldap.5.xml:727 -#: sssd-ldap.5.xml:752 sssd-ldap.5.xml:848 sssd-ldap.5.xml:1356 -#: sssd-ad.5.xml:506 sssd-ad.5.xml:582 sssd-ad.5.xml:1155 +#: sssd.conf.5.xml:1571 sssd.conf.5.xml:1585 sssd.conf.5.xml:4781 +#: sssd-ldap.5.xml:727 sssd-ldap.5.xml:752 sssd-ldap.5.xml:848 +#: sssd-ldap.5.xml:1356 sssd-ad.5.xml:506 sssd-ad.5.xml:582 sssd-ad.5.xml:1160 #: include/ldap_id_mapping.xml:250 msgid "Default: False" msgstr "Oletus:epätosi" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1609 -msgid "pam_cert_auth (bool)" +#: sssd.conf.5.xml:1576 +msgid "pam_cert_auth (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1612 +#: sssd.conf.5.xml:1579 msgid "" "Enable certificate based Smartcard authentication. Since this requires " "additional communication with the Smartcard which will delay the " "authentication process this option is disabled by default." msgstr "" +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1588 +msgid "" +"Note: In case OpenSC is used for Smartcard access SSSD supports the " +"filesystem caching in OpenSC when enabled in opensc.conf. The cached files " +"are located in a common <quote>opensc</quote> directory in SSSD's state " +"directory. The behaviour can be changed in opensc.conf" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> +#: sssd.conf.5.xml:1597 +#, no-wrap +msgid "" +"app /usr/libexec/sssd/p11_child {\n" +" framework pkcs15 {\n" +" use_file_caching = no;\n" +" }\n" +"}\n" +"app /usr/libexec/sssd/krb5_child {\n" +" framework pkcs15 {\n" +" use_file_caching = no;\n" +" }\n" +"}\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1595 +#, fuzzy +#| msgid "Example: <placeholder type=\"programlisting\" id=\"0\"/>" +msgid "" +"Example opensc.conf (*): <placeholder type=\"programlisting\" id=\"0\"/>" +msgstr "Esimerkki: <placeholder type=\"programlisting\" id=\"0\"/>" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1610 +msgid "" +"(*) The actual <quote>libexec</quote> directory for p11_child and krb5_child " +"depends on the distribution." +msgstr "" + #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1623 +#: sssd.conf.5.xml:1615 msgid "pam_cert_db_path (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1626 +#: sssd.conf.5.xml:1618 msgid "The path to the certificate database." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1629 sssd.conf.5.xml:2163 sssd.conf.5.xml:4338 +#: sssd.conf.5.xml:1621 sssd.conf.5.xml:2199 sssd.conf.5.xml:4543 msgid "Default:" msgstr "Oletus:" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1631 sssd.conf.5.xml:2165 +#: sssd.conf.5.xml:1623 sssd.conf.5.xml:2201 msgid "" "/etc/sssd/pki/sssd_auth_ca_db.pem (path to a file with trusted CA " "certificates in PEM format)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1641 +#: sssd.conf.5.xml:1633 msgid "pam_cert_verification (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1644 +#: sssd.conf.5.xml:1636 msgid "" "With this parameter the PAM certificate verification can be tuned with a " "comma separated list of options that override the " @@ -2045,7 +2029,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1655 +#: sssd.conf.5.xml:1647 #, no-wrap msgid "" "pam_cert_verification = partial_chain\n" @@ -2055,61 +2039,61 @@ msgstr "" " " #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1659 +#: sssd.conf.5.xml:1651 msgid "" "Default: not set, i.e. use default <quote>certificate_verification</quote> " "option defined in <quote>[sssd]</quote> section." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1666 +#: sssd.conf.5.xml:1658 msgid "p11_child_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1669 +#: sssd.conf.5.xml:1661 msgid "How many seconds will pam_sss wait for p11_child to finish." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1678 +#: sssd.conf.5.xml:1670 #, fuzzy #| msgid "entry_cache_timeout (integer)" msgid "passkey_child_timeout (integer)" msgstr "entry_cache_timeout (integeri)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1681 +#: sssd.conf.5.xml:1673 msgid "" "How many seconds will the PAM responder wait for passkey_child to finish." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1690 +#: sssd.conf.5.xml:1682 msgid "pam_app_services (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1693 +#: sssd.conf.5.xml:1685 msgid "" "Which PAM services are permitted to contact domains of type " "<quote>application</quote>" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1702 +#: sssd.conf.5.xml:1694 msgid "pam_p11_allowed_services (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1705 +#: sssd.conf.5.xml:1697 msgid "" "A comma-separated list of PAM service names for which it will be allowed to " "use Smartcards." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1720 +#: sssd.conf.5.xml:1712 #, no-wrap msgid "" "pam_p11_allowed_services = +my_pam_service, -login\n" @@ -2117,7 +2101,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1709 +#: sssd.conf.5.xml:1701 msgid "" "It is possible to add another PAM service name to the default set by using " "<quote>+service_name</quote> or to explicitly remove a PAM service name from " @@ -2129,68 +2113,75 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1724 sssd-ad.5.xml:645 sssd-ad.5.xml:754 sssd-ad.5.xml:812 -#: sssd-ad.5.xml:870 sssd-ad.5.xml:948 +#: sssd.conf.5.xml:1716 sssd-ad.5.xml:645 sssd-ad.5.xml:759 sssd-ad.5.xml:817 +#: sssd-ad.5.xml:875 sssd-ad.5.xml:953 msgid "Default: the default set of PAM service names includes:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1729 sssd-ad.5.xml:649 +#: sssd.conf.5.xml:1721 sssd-ad.5.xml:649 msgid "login" msgstr "kirjautuminen" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1734 sssd-ad.5.xml:654 +#: sssd.conf.5.xml:1726 sssd-ad.5.xml:654 msgid "su" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1739 sssd-ad.5.xml:659 +#: sssd.conf.5.xml:1731 sssd-ad.5.xml:659 msgid "su-l" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1744 sssd-ad.5.xml:674 +#: sssd.conf.5.xml:1736 sssd-ad.5.xml:674 msgid "gdm-smartcard" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1749 sssd-ad.5.xml:669 +#: sssd.conf.5.xml:1741 sssd-ad.5.xml:669 msgid "gdm-password" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1754 +#: sssd.conf.5.xml:1746 msgid "gdm-switchable-auth" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1759 sssd-ad.5.xml:679 +#: sssd.conf.5.xml:1751 sssd-ad.5.xml:679 msgid "kdm" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1764 sssd-ad.5.xml:957 +#: sssd.conf.5.xml:1756 sssd-ad.5.xml:694 +#, fuzzy +#| msgid "login" +msgid "plasmalogin" +msgstr "kirjautuminen" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:1761 sssd-ad.5.xml:962 msgid "sudo" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1769 sssd-ad.5.xml:962 +#: sssd.conf.5.xml:1766 sssd-ad.5.xml:967 msgid "sudo-i" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1774 +#: sssd.conf.5.xml:1771 msgid "gnome-screensaver" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1782 +#: sssd.conf.5.xml:1779 msgid "p11_wait_for_card_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1785 +#: sssd.conf.5.xml:1782 msgid "" "If Smartcard authentication is required how many extra seconds in addition " "to p11_child_timeout should the PAM responder wait until a Smartcard is " @@ -2198,12 +2189,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1796 +#: sssd.conf.5.xml:1793 msgid "p11_uri (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1799 +#: sssd.conf.5.xml:1796 msgid "" "PKCS#11 URI (see RFC-7512 for details) which can be used to restrict the " "selection of devices used for Smartcard authentication. By default SSSD's " @@ -2214,7 +2205,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1812 +#: sssd.conf.5.xml:1809 #, no-wrap msgid "" "p11_uri = pkcs11:slot-description=My%20Smartcard%20Reader\n" @@ -2222,7 +2213,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1816 +#: sssd.conf.5.xml:1813 #, no-wrap msgid "" "p11_uri = pkcs11:library-description=OpenSC%20smartcard%20framework;slot-id=2\n" @@ -2230,7 +2221,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1810 +#: sssd.conf.5.xml:1807 msgid "" "Example: <placeholder type=\"programlisting\" id=\"0\"/> or <placeholder " "type=\"programlisting\" id=\"1\"/> To find suitable URI please check the " @@ -2239,47 +2230,49 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1829 -msgid "pam_initgroups_scheme" -msgstr "" +#: sssd.conf.5.xml:1826 +#, fuzzy +#| msgid "ldap_user_principal" +msgid "pam_initgroups_scheme (string)" +msgstr "ldap_user_principal" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1837 +#: sssd.conf.5.xml:1834 msgid "always" msgstr "aina" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1838 +#: sssd.conf.5.xml:1835 msgid "" "Always do an online lookup, please note that pam_id_timeout still applies" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1842 +#: sssd.conf.5.xml:1839 msgid "no_session" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1843 +#: sssd.conf.5.xml:1840 msgid "" "Only do an online lookup if there is no active session of the user, i.e. if " "the user is currently not logged in" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1848 sssd-ldap.5.xml:189 +#: sssd.conf.5.xml:1845 sssd-ldap.5.xml:189 msgid "never" msgstr "Ei koskaan" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1849 +#: sssd.conf.5.xml:1846 msgid "" "Never force an online lookup, use the data from the cache as long as they " "are not expired" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1832 +#: sssd.conf.5.xml:1829 msgid "" "The PAM responder can force an online lookup to get the current group " "memberships of the user trying to log in. This option controls when this " @@ -2288,30 +2281,32 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1856 +#: sssd.conf.5.xml:1853 msgid "Default: no_session" msgstr "" -#. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:1861 sssd.conf.5.xml:4277 -msgid "pam_gssapi_services" -msgstr "" +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1858 +#, fuzzy +#| msgid "ldap_user_principal" +msgid "pam_gssapi_services (string)" +msgstr "ldap_user_principal" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1864 +#: sssd.conf.5.xml:1861 msgid "" "Comma separated list of PAM services that are allowed to try GSSAPI " "authentication using pam_sss_gss.so module." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1869 +#: sssd.conf.5.xml:1866 msgid "" "To disable GSSAPI authentication, set this option to <quote>-</quote> (dash)." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1873 sssd.conf.5.xml:1904 sssd.conf.5.xml:1942 +#: sssd.conf.5.xml:1870 sssd.conf.5.xml:1901 sssd.conf.5.xml:1939 msgid "" "Note: This option can also be set per-domain which overwrites the value in " "[pam] section. It can also be set for trusted domain which overwrites the " @@ -2319,7 +2314,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1881 +#: sssd.conf.5.xml:1878 #, no-wrap msgid "" "pam_gssapi_services = sudo, sudo-i\n" @@ -2329,22 +2324,22 @@ msgstr "" " " #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1879 sssd.conf.5.xml:1994 sssd.conf.5.xml:3836 +#: sssd.conf.5.xml:1876 sssd.conf.5.xml:2023 sssd.conf.5.xml:4042 msgid "Example: <placeholder type=\"programlisting\" id=\"0\"/>" msgstr "Esimerkki: <placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1885 +#: sssd.conf.5.xml:1882 msgid "Default: - (GSSAPI authentication is disabled)" msgstr "" -#. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:1890 sssd.conf.5.xml:4278 -msgid "pam_gssapi_check_upn" +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1887 +msgid "pam_gssapi_check_upn (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1893 +#: sssd.conf.5.xml:1890 msgid "" "If True, SSSD will require that the Kerberos user principal that " "successfully authenticated through GSSAPI can be associated with the user " @@ -2352,19 +2347,21 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1900 +#: sssd.conf.5.xml:1897 msgid "" -"If False, every user that is able to obtained required service ticket will " +"If False, every user that is able to obtain a required service ticket will " "be authenticated." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1915 -msgid "pam_gssapi_indicators_map" -msgstr "" +#: sssd.conf.5.xml:1912 +#, fuzzy +#| msgid "ldap_user_principal" +msgid "pam_gssapi_indicators_map (string)" +msgstr "ldap_user_principal" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1918 +#: sssd.conf.5.xml:1915 msgid "" "Comma separated list of authentication indicators required to be present in " "a Kerberos ticket to access a PAM service that is allowed to try GSSAPI " @@ -2372,7 +2369,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1924 +#: sssd.conf.5.xml:1921 msgid "" "Each element of the list can be either an authentication indicator name or a " "pair <quote>service:indicator</quote>. Indicators not prefixed with the PAM " @@ -2387,7 +2384,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1937 +#: sssd.conf.5.xml:1934 msgid "" "To disable GSSAPI authentication indicator check, set this option to <quote>-" "</quote> (dash). To disable the check for a specific PAM service, add " @@ -2395,45 +2392,45 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1948 +#: sssd.conf.5.xml:1945 msgid "" "Following authentication indicators are supported by IPA Kerberos " "deployments:" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1951 +#: sssd.conf.5.xml:1948 msgid "" "pkinit -- pre-authentication using X.509 certificates -- whether stored in " "files or on smart cards." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1954 +#: sssd.conf.5.xml:1951 msgid "" "hardened -- SPAKE pre-authentication or any pre-authentication wrapped in a " "FAST channel." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1957 +#: sssd.conf.5.xml:1954 msgid "radius -- pre-authentication with the help of a RADIUS server." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1960 +#: sssd.conf.5.xml:1957 msgid "" "otp -- pre-authentication using integrated two-factor authentication (2FA or " "one-time password, OTP) in IPA." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1963 +#: sssd.conf.5.xml:1960 msgid "idp -- pre-authentication using external identity provider." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1973 +#: sssd.conf.5.xml:1970 #, no-wrap msgid "" "pam_gssapi_indicators_map = sudo:pkinit, sudo-i:pkinit\n" @@ -2441,7 +2438,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1968 +#: sssd.conf.5.xml:1965 msgid "" "Example: to require access to SUDO services only for users which obtained " "their Kerberos tickets with a X.509 certificate pre-authentication (PKINIT), " @@ -2449,31 +2446,70 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1977 +#: sssd.conf.5.xml:1974 msgid "Default: not set (use of authentication indicators is not required)" msgstr "Oletus: ei asetettu(todennusindikaattoreiden käyttöä ei vaadita)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1982 +#: sssd.conf.5.xml:1979 +msgid "pam_gssapi_indicators_apply (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1982 +msgid "" +"Comma separated list of triples to assign additional information from the " +"Kerberos ticket, e.g. a SID from the PAC, to authentication indicators." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1988 +msgid "Currently supported is:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:1991 +msgid "SID:S-1-5-[domain]-[RID]:[authentication indicator]" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> +#: sssd.conf.5.xml:2002 +#, no-wrap +msgid "" +"pam_gssapi_indicators_apply = SID:S-1-5-12345-23456-34567-4321:pkinit\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1996 +msgid "" +"Example: To assign a SID, which is e.g. set by Active Directory's " +"Authentication Mechanism Assurance (AMA) if the AD user used a Smartcard for " +"authentication, to the 'pkinit' authentication indicator use: <placeholder " +"type=\"programlisting\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2011 #, fuzzy #| msgid "ldap_user_principal" msgid "pam_json_services (string)" msgstr "ldap_user_principal" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1985 +#: sssd.conf.5.xml:2014 msgid "" "Comma separated list of PAM services which can handle the JSON protocol for " "selecting authentication mechanisms" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1990 +#: sssd.conf.5.xml:2019 msgid "To disable JSON protocol, set this option to <quote>-</quote> (dash)." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1996 +#: sssd.conf.5.xml:2025 #, fuzzy, no-wrap #| msgid "" #| "pam_gssapi_services = sudo, sudo-i\n" @@ -2486,52 +2522,61 @@ msgstr "" " " #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2000 +#: sssd.conf.5.xml:2029 msgid "Default: - (JSON protocol is disabled)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2003 +#: sssd.conf.5.xml:2032 msgid "" "Note: 2-Factor Authentication (2FA) is not supported. If 2FA is required, do " "not activate the JSON protocol." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:2013 +#: sssd.conf.5.xml:2042 msgid "SUDO configuration options" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2015 +#: sssd.conf.5.xml:2044 msgid "" -"These options can be used to configure the sudo service. The detailed " -"instructions for configuration of <citerefentry> <refentrytitle>sudo</" -"refentrytitle> <manvolnum>8</manvolnum> </citerefentry> to work with " -"<citerefentry> <refentrytitle>sssd</refentrytitle> <manvolnum>8</manvolnum> " -"</citerefentry> are in the manual page <citerefentry> <refentrytitle>sssd-" -"sudo</refentrytitle> <manvolnum>5</manvolnum> </citerefentry>." +"These options can be used to configure the sudo service and should be " +"specified under the <quote>[sudo]</quote> section." msgstr "" -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2032 -msgid "sudo_timed (bool)" +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:2048 +msgid "" +"The detailed instructions for configuration of <citerefentry> " +"<refentrytitle>sudo</refentrytitle> <manvolnum>8</manvolnum> </citerefentry> " +"to work with <citerefentry> <refentrytitle>sssd</refentrytitle> " +"<manvolnum>8</manvolnum> </citerefentry> are in the manual page " +"<citerefentry> <refentrytitle>sssd-sudo</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry>." msgstr "" +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2064 +#, fuzzy +#| msgid "debug_timestamps (bool)" +msgid "sudo_timed (boolean)" +msgstr "debug_timestamps (bool)" + #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2035 +#: sssd.conf.5.xml:2067 msgid "" "Whether or not to evaluate the sudoNotBefore and sudoNotAfter attributes " "that implement time-dependent sudoers entries." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2047 +#: sssd.conf.5.xml:2079 msgid "sudo_threshold (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2050 +#: sssd.conf.5.xml:2082 msgid "" "Maximum number of expired rules that can be refreshed at once. If number of " "expired rules is below threshold, those rules are refreshed with " @@ -2541,22 +2586,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:2069 +#: sssd.conf.5.xml:2101 msgid "AUTOFS configuration options" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2071 -msgid "These options can be used to configure the autofs service." +#: sssd.conf.5.xml:2103 +msgid "" +"These options can be used to configure the autofs service and should be " +"specified under the <quote>[autofs]</quote> section." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2075 +#: sssd.conf.5.xml:2109 msgid "autofs_negative_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2078 +#: sssd.conf.5.xml:2112 msgid "" "Specifies for how many seconds should the autofs responder negative cache " "hits (that is, queries for invalid map entries, like nonexistent ones) " @@ -2564,22 +2611,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:2094 +#: sssd.conf.5.xml:2128 msgid "SSH configuration options" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2096 -msgid "These options can be used to configure the SSH service." +#: sssd.conf.5.xml:2130 +msgid "" +"These options can be used to configure the SSH service and should be " +"specified under the <quote>[ssh]</quote> section." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2100 -msgid "ssh_use_certificate_keys (bool)" +#: sssd.conf.5.xml:2136 +msgid "ssh_use_certificate_keys (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2103 +#: sssd.conf.5.xml:2139 msgid "" "If set to true the <command>sss_ssh_authorizedkeys</command> will return ssh " "keys derived from the public key of X.509 certificates stored in the user " @@ -2588,12 +2637,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2118 +#: sssd.conf.5.xml:2154 msgid "ssh_use_certificate_matching_rules (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2121 +#: sssd.conf.5.xml:2157 msgid "" "By default the ssh responder will use all available certificate matching " "rules to filter the certificates so that ssh keys are only derived from the " @@ -2603,7 +2652,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2130 +#: sssd.conf.5.xml:2166 msgid "" "There are two special key words 'all_rules' and 'no_rules' which will enable " "all or no rules, respectively. The latter means that no certificates will be " @@ -2611,7 +2660,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2137 +#: sssd.conf.5.xml:2173 msgid "" "If no rules are configured using 'all_rules' will enable a default rule " "which enables all certificates suitable for client authentication. This is " @@ -2620,38 +2669,38 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2144 +#: sssd.conf.5.xml:2180 msgid "" "A non-existing rule name is considered an error. If as a result no rule is " "selected all certificates will be ignored." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2149 +#: sssd.conf.5.xml:2185 msgid "" "Default: not set, equivalent to 'all_rules', all found rules or the default " "rule are used" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2155 +#: sssd.conf.5.xml:2191 msgid "ca_db (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2158 +#: sssd.conf.5.xml:2194 msgid "" "Path to a storage of trusted CA certificates. The option is used to validate " "user certificates before deriving public ssh keys from them." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:2178 +#: sssd.conf.5.xml:2214 msgid "PAC responder configuration options" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2180 +#: sssd.conf.5.xml:2216 msgid "" "The PAC responder works together with the authorization data plugin for MIT " "Kerberos sssd_pac_plugin.so and a sub-domain provider. The plugin sends the " @@ -2662,7 +2711,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:2189 +#: sssd.conf.5.xml:2225 msgid "" "If the remote user does not exist in the cache, it is created. The UID is " "determined with the help of the SID, trusted domains will have UPGs and the " @@ -2673,24 +2722,26 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:2197 +#: sssd.conf.5.xml:2233 msgid "" "If there are SIDs of groups from domains sssd knows about, the user will be " "added to those groups." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2203 -msgid "These options can be used to configure the PAC responder." +#: sssd.conf.5.xml:2239 +msgid "" +"These options can be used to configure the PAC responder and should be " +"specified under the <quote>[pac]</quote> section." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2207 sssd-ifp.5.xml:66 +#: sssd.conf.5.xml:2244 sssd-ifp.5.xml:66 msgid "allowed_uids (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2210 +#: sssd.conf.5.xml:2247 msgid "" "Specifies the comma-separated list of UID values or user names that are " "allowed to access the PAC responder. User names are resolved to UIDs at " @@ -2698,19 +2749,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2216 +#: sssd.conf.5.xml:2253 msgid "" "Default: 0, &sssd_user_name; (only root and SSSD service users are allowed " "to access the PAC responder)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2220 +#: sssd.conf.5.xml:2257 msgid "Default: 0 (only the root user is allowed to access the PAC responder)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2224 +#: sssd.conf.5.xml:2261 msgid "" "Please note that defaults will be overwritten with this option. If you still " "want to allow the root and/or '&sssd_user_name;' user to access the PAC " @@ -2719,7 +2770,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2231 +#: sssd.conf.5.xml:2268 msgid "" "Please note that although the UID 0 is used as the default it will be " "overwritten with this option. If you still want to allow the root user to " @@ -2728,24 +2779,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2240 +#: sssd.conf.5.xml:2277 msgid "pac_lifetime (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2243 +#: sssd.conf.5.xml:2280 msgid "" "Lifetime of the PAC entry in seconds. As long as the PAC is valid the PAC " "data can be used to determine the group memberships of a user." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2253 +#: sssd.conf.5.xml:2290 msgid "pac_check (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2256 +#: sssd.conf.5.xml:2293 msgid "" "Apply additional checks on the PAC of the Kerberos ticket which is available " "in Active Directory and FreeIPA domains, if configured. Please note that " @@ -2756,7 +2807,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2266 +#: sssd.conf.5.xml:2303 msgid "" "Please note that the checks listed below only apply to PACs issued by Active " "Directory or recent versions of FreeIPA. PACs issued e.g. by a plain MIT " @@ -2764,26 +2815,26 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2277 +#: sssd.conf.5.xml:2314 msgid "no_check" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2279 +#: sssd.conf.5.xml:2316 msgid "" "The PAC must not be present and even if it is present no additional checks " "will be done." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2285 +#: sssd.conf.5.xml:2322 #, fuzzy #| msgid "present" msgid "pac_present" msgstr "nykyinen" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2287 +#: sssd.conf.5.xml:2324 msgid "" "The PAC must be present in the service ticket which SSSD will request with " "the help of the user's TGT. If the PAC is not available the authentication " @@ -2791,24 +2842,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2295 +#: sssd.conf.5.xml:2332 msgid "check_upn" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2297 +#: sssd.conf.5.xml:2334 msgid "" "If the PAC is present check if the user principal name (UPN) information is " "consistent." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2303 +#: sssd.conf.5.xml:2340 msgid "check_upn_allow_missing" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2305 +#: sssd.conf.5.xml:2342 msgid "" "This option should be used together with 'check_upn' and handles the case " "where a UPN is set on the server-side but is not read by SSSD. The typical " @@ -2820,7 +2871,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2317 +#: sssd.conf.5.xml:2354 msgid "" "Currently this option is set by default to avoid regressions in such " "environments. A log message will be added to the system log and SSSD's debug " @@ -2831,60 +2882,60 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2331 +#: sssd.conf.5.xml:2368 msgid "upn_dns_info_present" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2333 +#: sssd.conf.5.xml:2370 msgid "The PAC must contain the UPN-DNS-INFO buffer, implies 'check_upn'." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2338 +#: sssd.conf.5.xml:2375 msgid "check_upn_dns_info_ex" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2340 +#: sssd.conf.5.xml:2377 msgid "" "If the PAC is present and the extension to the UPN-DNS-INFO buffer is " "available check if the information in the extension is consistent." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2347 +#: sssd.conf.5.xml:2384 msgid "upn_dns_info_ex_present" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2349 +#: sssd.conf.5.xml:2386 msgid "" "The PAC must contain the extension of the UPN-DNS-INFO buffer, implies " "'check_upn_dns_info_ex', 'upn_dns_info_present' and 'check_upn'." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2273 +#: sssd.conf.5.xml:2310 msgid "" "The following options can be used alone or in a comma-separated list: " "<placeholder type=\"variablelist\" id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2359 +#: sssd.conf.5.xml:2396 msgid "" "Default: no_check (AD and IPA provider 'check_upn, check_upn_allow_missing, " "check_upn_dns_info_ex')" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:2368 +#: sssd.conf.5.xml:2405 msgid "Session recording configuration options" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2370 +#: sssd.conf.5.xml:2407 msgid "" "Session recording works in conjunction with <citerefentry> " "<refentrytitle>tlog-rec-session</refentrytitle> <manvolnum>8</manvolnum> </" @@ -2894,66 +2945,78 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2383 -msgid "These options can be used to configure session recording." +#: sssd.conf.5.xml:2420 +msgid "" +"These options can be used to configure session recording and should be " +"specified under the <quote>[session_recording]</quote> section." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:2425 +msgid "" +"Note: Unlike other sections, the <quote>[session_recording]</quote> section " +"ignores <replaceable>debug*</replaceable> options and suitable " +"<replaceable>debug*</replaceable> options must be set in <quote>[pam]</" +"quote>, <quote>[nss]</quote> and <quote>[domain/<replaceable>NAME</" +"replaceable>]</quote> sections." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2387 sssd-session-recording.5.xml:64 +#: sssd.conf.5.xml:2433 sssd-session-recording.5.xml:64 msgid "scope (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2394 sssd-session-recording.5.xml:71 +#: sssd.conf.5.xml:2440 sssd-session-recording.5.xml:71 msgid "\"none\"" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2397 sssd-session-recording.5.xml:74 +#: sssd.conf.5.xml:2443 sssd-session-recording.5.xml:74 msgid "No users are recorded." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2402 sssd-session-recording.5.xml:79 +#: sssd.conf.5.xml:2448 sssd-session-recording.5.xml:79 msgid "\"some\"" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2405 sssd-session-recording.5.xml:82 +#: sssd.conf.5.xml:2451 sssd-session-recording.5.xml:82 msgid "" "Users/groups specified by <replaceable>users</replaceable> and " "<replaceable>groups</replaceable> options are recorded." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2414 sssd-session-recording.5.xml:91 +#: sssd.conf.5.xml:2460 sssd-session-recording.5.xml:91 msgid "\"all\"" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2417 sssd-session-recording.5.xml:94 +#: sssd.conf.5.xml:2463 sssd-session-recording.5.xml:94 msgid "All users are recorded." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2390 sssd-session-recording.5.xml:67 +#: sssd.conf.5.xml:2436 sssd-session-recording.5.xml:67 msgid "" "One of the following strings specifying the scope of session recording: " "<placeholder type=\"variablelist\" id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2424 sssd-session-recording.5.xml:101 +#: sssd.conf.5.xml:2470 sssd-session-recording.5.xml:101 msgid "Default: \"none\"" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2429 sssd-session-recording.5.xml:106 +#: sssd.conf.5.xml:2475 sssd-session-recording.5.xml:106 msgid "users (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2432 sssd-session-recording.5.xml:109 +#: sssd.conf.5.xml:2478 sssd-session-recording.5.xml:109 msgid "" "A comma-separated list of users which should have session recording enabled. " "Matches user names as returned by NSS. I.e. after the possible space " @@ -2961,17 +3024,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2438 sssd-session-recording.5.xml:115 +#: sssd.conf.5.xml:2484 sssd-session-recording.5.xml:115 msgid "Default: Empty. Matches no users." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2443 sssd-session-recording.5.xml:120 +#: sssd.conf.5.xml:2489 sssd-session-recording.5.xml:120 msgid "groups (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2446 sssd-session-recording.5.xml:123 +#: sssd.conf.5.xml:2492 sssd-session-recording.5.xml:123 msgid "" "A comma-separated list of groups, members of which should have session " "recording enabled. Matches group names as returned by NSS. I.e. after the " @@ -2979,7 +3042,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2452 sssd.conf.5.xml:2484 sssd-session-recording.5.xml:129 +#: sssd.conf.5.xml:2498 sssd.conf.5.xml:2530 sssd-session-recording.5.xml:129 #: sssd-session-recording.5.xml:161 msgid "" "NOTE: using this option (having it set to anything) has a considerable " @@ -2988,57 +3051,56 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2459 sssd-session-recording.5.xml:136 +#: sssd.conf.5.xml:2505 sssd-session-recording.5.xml:136 msgid "Default: Empty. Matches no groups." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2464 sssd-session-recording.5.xml:141 +#: sssd.conf.5.xml:2510 sssd-session-recording.5.xml:141 msgid "exclude_users (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2467 sssd-session-recording.5.xml:144 +#: sssd.conf.5.xml:2513 sssd-session-recording.5.xml:144 msgid "" "A comma-separated list of users to be excluded from recording, only " "applicable with 'scope=all'." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2471 sssd-session-recording.5.xml:148 +#: sssd.conf.5.xml:2517 sssd-session-recording.5.xml:148 msgid "Default: Empty. No users excluded." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2476 sssd-session-recording.5.xml:153 +#: sssd.conf.5.xml:2522 sssd-session-recording.5.xml:153 msgid "exclude_groups (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2479 sssd-session-recording.5.xml:156 +#: sssd.conf.5.xml:2525 sssd-session-recording.5.xml:156 msgid "" "A comma-separated list of groups, members of which should be excluded from " "recording. Only applicable with 'scope=all'." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2491 sssd-session-recording.5.xml:168 +#: sssd.conf.5.xml:2537 sssd-session-recording.5.xml:168 msgid "Default: Empty. No groups excluded." msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:2501 +#: sssd.conf.5.xml:2547 msgid "DOMAIN SECTIONS" msgstr "" -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry><para> -#: sssd.conf.5.xml:2508 sssd.conf.5.xml:3964 sssd.conf.5.xml:3965 -#: sssd.conf.5.xml:3968 -msgid "enabled" -msgstr "käytössä" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2554 +msgid "enabled (boolean)" +msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2511 +#: sssd.conf.5.xml:2557 msgid "" "Explicitly enable or disable the domain. If <quote>true</quote>, the domain " "is always <quote>enabled</quote>. If <quote>false</quote>, the domain is " @@ -3048,12 +3110,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2523 +#: sssd.conf.5.xml:2569 msgid "domain_type (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2526 +#: sssd.conf.5.xml:2572 msgid "" "Specifies whether the domain is meant to be used by POSIX-aware clients such " "as the Name Service Switch or by applications that do not need POSIX data to " @@ -3062,14 +3124,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2534 +#: sssd.conf.5.xml:2580 msgid "" "Allowed values for this option are <quote>posix</quote> and " "<quote>application</quote>." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2538 +#: sssd.conf.5.xml:2584 msgid "" "POSIX domains are reachable by all services. Application domains are only " "reachable from the InfoPipe responder (see <citerefentry> " @@ -3078,38 +3140,38 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2546 +#: sssd.conf.5.xml:2592 msgid "" "NOTE: The application domains are currently well tested with " "<quote>id_provider=ldap</quote> only." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2550 +#: sssd.conf.5.xml:2596 msgid "" "For an easy way to configure a non-POSIX domains, please see the " "<quote>Application domains</quote> section." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2554 +#: sssd.conf.5.xml:2600 msgid "Default: posix" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2560 +#: sssd.conf.5.xml:2606 msgid "min_id,max_id (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2563 +#: sssd.conf.5.xml:2609 msgid "" "UID and GID limits for the domain. If a domain contains an entry that is " "outside these limits, it is ignored." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2568 +#: sssd.conf.5.xml:2614 msgid "" "For users, this affects the primary GID limit. The user will not be returned " "to NSS if either the UID or the primary GID is outside the range. For non-" @@ -3118,24 +3180,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2575 +#: sssd.conf.5.xml:2621 msgid "" "These ID limits affect even saving entries to cache, not only returning them " "by name or ID." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2579 +#: sssd.conf.5.xml:2625 msgid "Default: 1 for min_id, 0 (no limit) for max_id" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2585 -msgid "enumerate (bool)" +#: sssd.conf.5.xml:2631 +msgid "enumerate (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2588 +#: sssd.conf.5.xml:2634 msgid "" "Determines if a domain can be enumerated, that is, whether the domain can " "list all the users and group it contains. Note that it is not required to " @@ -3144,36 +3206,36 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2596 +#: sssd.conf.5.xml:2642 msgid "TRUE = Users and groups are enumerated" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2599 +#: sssd.conf.5.xml:2645 msgid "FALSE = No enumerations for this domain" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2602 sssd.conf.5.xml:2867 sssd.conf.5.xml:3044 +#: sssd.conf.5.xml:2648 sssd.conf.5.xml:2992 sssd.conf.5.xml:3174 msgid "Default: FALSE" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2605 +#: sssd.conf.5.xml:2651 msgid "" "Enumerating a domain requires SSSD to download and store ALL user and group " "entries from the remote server." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2610 +#: sssd.conf.5.xml:2656 msgid "" "Feature is only supported for domains with id_provider = ldap or id_provider " "= proxy." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2614 +#: sssd.conf.5.xml:2660 msgid "" "Note: Enabling enumeration has a severe performance impact on SSSD while " "enumeration is running. It may take up to several minutes after SSSD startup " @@ -3187,14 +3249,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2629 +#: sssd.conf.5.xml:2675 msgid "" "While the first enumeration is running, requests for the complete user or " "group lists may return no results until it completes." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2634 +#: sssd.conf.5.xml:2680 msgid "" "Further, enabling enumeration may increase the time necessary to detect " "network disconnection, as longer timeouts are required to ensure that " @@ -3203,14 +3265,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2642 +#: sssd.conf.5.xml:2688 msgid "" "For the reasons cited above, enabling enumeration is not recommended, " "especially in large environments." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2647 +#: sssd.conf.5.xml:2693 msgid "" "Note: the proxy provider is tested with open source modules like " "'libnss_files' and 'libnss_ldap'. 3rd party modules must follow the " @@ -3218,19 +3280,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2656 +#: sssd.conf.5.xml:2702 msgid "entry_cache_timeout (integer)" msgstr "entry_cache_timeout (integeri)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2659 +#: sssd.conf.5.xml:2705 msgid "" "How many seconds should nss_sss consider entries valid before asking the " "backend again" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2663 +#: sssd.conf.5.xml:2709 msgid "" "The cache expiration timestamps are stored as attributes of individual " "objects in the cache. Therefore, changing the cache timeout only has effect " @@ -3241,139 +3303,244 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2676 +#: sssd.conf.5.xml:2722 msgid "Default: 5400" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2682 +#: sssd.conf.5.xml:2728 msgid "entry_cache_user_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2685 +#: sssd.conf.5.xml:2731 msgid "" "How many seconds should nss_sss consider user entries valid before asking " "the backend again" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2689 sssd.conf.5.xml:2702 sssd.conf.5.xml:2715 -#: sssd.conf.5.xml:2728 sssd.conf.5.xml:2742 sssd.conf.5.xml:2755 -#: sssd.conf.5.xml:2769 sssd.conf.5.xml:2783 sssd.conf.5.xml:2796 +#: sssd.conf.5.xml:2735 sssd.conf.5.xml:2748 sssd.conf.5.xml:2761 +#: sssd.conf.5.xml:2774 sssd.conf.5.xml:2788 sssd.conf.5.xml:2801 +#: sssd.conf.5.xml:2815 sssd.conf.5.xml:2829 msgid "Default: entry_cache_timeout" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2695 +#: sssd.conf.5.xml:2741 msgid "entry_cache_group_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2698 +#: sssd.conf.5.xml:2744 msgid "" "How many seconds should nss_sss consider group entries valid before asking " "the backend again" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2708 +#: sssd.conf.5.xml:2754 msgid "entry_cache_netgroup_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2711 +#: sssd.conf.5.xml:2757 msgid "" "How many seconds should nss_sss consider netgroup entries valid before " "asking the backend again" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2721 +#: sssd.conf.5.xml:2767 msgid "entry_cache_service_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2724 +#: sssd.conf.5.xml:2770 msgid "" "How many seconds should nss_sss consider service entries valid before asking " "the backend again" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2734 +#: sssd.conf.5.xml:2780 msgid "entry_cache_resolver_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2737 +#: sssd.conf.5.xml:2783 msgid "" "How many seconds should nss_sss consider hosts and networks entries valid " "before asking the backend again" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2748 +#: sssd.conf.5.xml:2794 msgid "entry_cache_sudo_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2751 +#: sssd.conf.5.xml:2797 msgid "" "How many seconds should sudo consider rules valid before asking the backend " "again" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2761 +#: sssd.conf.5.xml:2807 msgid "entry_cache_autofs_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2764 +#: sssd.conf.5.xml:2810 msgid "" "How many seconds should the autofs service consider automounter maps valid " "before asking the backend again" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2775 +#: sssd.conf.5.xml:2821 msgid "entry_cache_ssh_host_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2778 +#: sssd.conf.5.xml:2824 msgid "" "How many seconds to keep a host ssh key after refresh. IE how long to cache " "the host key for." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2789 -msgid "entry_cache_computer_timeout (integer)" +#: sssd.conf.5.xml:2835 +msgid "offline_timeout (integer)" +msgstr "offline_timeout (integeri)" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2838 +msgid "" +"When SSSD switches to offline mode the amount of time before it tries to go " +"back online will increase based upon the time spent disconnected. By " +"default SSSD uses incremental behaviour to calculate delay in between " +"retries. So, the wait time for a given retry will be longer than the wait " +"time for the previous ones. After each unsuccessful attempt to go online, " +"the new interval is recalculated by the following:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2792 +#: sssd.conf.5.xml:2849 sssd.conf.5.xml:2907 msgid "" -"How many seconds to keep the local computer entry before asking the backend " -"again" +"new_delay = Minimum(old_delay * 2, offline_timeout_max) + " +"random[0...offline_timeout_random_offset]" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2852 +msgid "" +"The offline_timeout default value is 60. The offline_timeout_max default " +"value is 3600. The offline_timeout_random_offset default value is 30. The " +"end result is the number of seconds before next retry." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2858 +msgid "" +"Note that the maximum length of each interval is defined by " +"offline_timeout_max (apart from the random part)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2868 +msgid "offline_timeout_max (integer)" +msgstr "offline_timeout_max (integeri)" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2871 +msgid "" +"Controls by how much the time between attempts to go online can be " +"incremented following unsuccessful attempts to go online." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2876 +msgid "A value of 0 disables the incrementing behaviour." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2879 +msgid "" +"The value of this parameter should be set in correlation to offline_timeout " +"parameter value." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2883 +msgid "" +"With offline_timeout set to 60 (default value) there is no point in setting " +"offline_timeout_max to less than 120 as it will saturate instantly. General " +"rule here should be to set offline_timeout_max to at least 4 times " +"offline_timeout." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2889 +msgid "" +"Although a value between 0 and offline_timeout may be specified, it has the " +"effect of overriding the offline_timeout value so is of little use." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2894 +msgid "Default: 3600" +msgstr "Oletus: 3600" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2900 +msgid "offline_timeout_random_offset (integer)" +msgstr "offline_timeout_random_offset (integeri)" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2903 +msgid "" +"When SSSD is in offline mode it keeps probing backend servers in specified " +"time intervals:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2910 +msgid "" +"This parameter controls the value of the random offset used for the above " +"equation. Final random_offset value will be random number in range:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2915 +msgid "[0 - offline_timeout_random_offset]" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2918 +msgid "A value of 0 disables the random offset addition." msgstr "" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2921 +msgid "Default: 30" +msgstr "Oletus: 30" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2802 +#: sssd.conf.5.xml:2927 msgid "refresh_expired_interval (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2805 +#: sssd.conf.5.xml:2930 msgid "" "Specifies how many seconds SSSD has to wait before triggering a background " "refresh task which will refresh all expired or nearly expired records." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2810 +#: sssd.conf.5.xml:2935 msgid "" "The background refresh will process users, groups and netgroups in the " "cache. For users who have performed the initgroups (get group membership for " @@ -3382,17 +3549,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2818 +#: sssd.conf.5.xml:2943 msgid "This option is automatically inherited for all trusted domains." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2822 +#: sssd.conf.5.xml:2947 msgid "You can consider setting this value to 3/4 * entry_cache_timeout." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2826 +#: sssd.conf.5.xml:2951 msgid "" "Cache entry will be refreshed by background task when 2/3 of cache timeout " "has already passed. If there are existing cached entries, the background " @@ -3404,18 +3571,18 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2839 sssd-ldap.5.xml:406 sssd-ldap.5.xml:1834 -#: sssd-ipa.5.xml:255 +#: sssd.conf.5.xml:2964 sssd-ldap.5.xml:406 sssd-ldap.5.xml:1834 +#: sssd-ipa.5.xml:250 msgid "Default: 0 (disabled)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2845 -msgid "cache_credentials (bool)" +#: sssd.conf.5.xml:2970 +msgid "cache_credentials (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2848 +#: sssd.conf.5.xml:2973 msgid "" "Determines if user credentials are also cached in the local LDB cache. The " "cached credentials refer to passwords, which includes the first (long term) " @@ -3426,7 +3593,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2859 +#: sssd.conf.5.xml:2984 msgid "" "Take a note that while credentials are stored as a salted SHA512 hash, this " "still potentially poses some security risk in case an attacker manages to " @@ -3435,12 +3602,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2873 +#: sssd.conf.5.xml:2998 msgid "cache_credentials_minimal_first_factor_length (int)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2876 +#: sssd.conf.5.xml:3001 msgid "" "If 2-Factor-Authentication (2FA) is used and credentials should be saved " "this value determines the minimal length the first authentication factor " @@ -3448,19 +3615,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2883 +#: sssd.conf.5.xml:3008 msgid "" "This should avoid that the short PINs of a PIN based 2FA scheme are saved in " "the cache which would make them easy targets for brute-force attacks." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2894 +#: sssd.conf.5.xml:3019 msgid "account_cache_expiration (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2897 +#: sssd.conf.5.xml:3022 msgid "" "Number of days entries are left in cache after last successful login before " "being removed during a cleanup of the cache. 0 means keep forever. The " @@ -3469,17 +3636,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2904 +#: sssd.conf.5.xml:3029 msgid "Default: 0 (unlimited)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2909 +#: sssd.conf.5.xml:3034 msgid "pwd_expiration_warning (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2920 +#: sssd.conf.5.xml:3045 msgid "" "Please note that the backend server has to provide information about the " "expiration time of the password. If this information is missing, sssd " @@ -3488,28 +3655,28 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2927 +#: sssd.conf.5.xml:3052 msgid "Default: 7 (Kerberos), 0 (LDAP)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2933 +#: sssd.conf.5.xml:3058 msgid "id_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2936 +#: sssd.conf.5.xml:3061 msgid "" "The identification provider used for the domain. Supported ID providers are:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2940 +#: sssd.conf.5.xml:3065 msgid "<quote>proxy</quote>: Support a legacy NSS provider." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2943 +#: sssd.conf.5.xml:3068 msgid "" "<quote>ldap</quote>: LDAP provider. See <citerefentry> <refentrytitle>sssd-" "ldap</refentrytitle> <manvolnum>5</manvolnum> </citerefentry> for more " @@ -3517,8 +3684,8 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2951 sssd.conf.5.xml:3070 sssd.conf.5.xml:3129 -#: sssd.conf.5.xml:3192 +#: sssd.conf.5.xml:3076 sssd.conf.5.xml:3200 sssd.conf.5.xml:3259 +#: sssd.conf.5.xml:3322 msgid "" "<quote>ipa</quote>: FreeIPA and Red Hat Identity Management provider. See " "<citerefentry> <refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</" @@ -3526,8 +3693,8 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2960 sssd.conf.5.xml:3079 sssd.conf.5.xml:3138 -#: sssd.conf.5.xml:3201 +#: sssd.conf.5.xml:3085 sssd.conf.5.xml:3209 sssd.conf.5.xml:3268 +#: sssd.conf.5.xml:3331 msgid "" "<quote>ad</quote>: Active Directory provider. See <citerefentry> " "<refentrytitle>sssd-ad</refentrytitle> <manvolnum>5</manvolnum> </" @@ -3535,27 +3702,34 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2968 +#: sssd.conf.5.xml:3093 msgid "" "<quote>idp</quote>: Provider for OAuth 2.0/OIDC based Identity Providers " "(IdP). See <citerefentry> <refentrytitle>sssd-idp</refentrytitle> " "<manvolnum>5</manvolnum> </citerefentry> for more information." msgstr "" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3101 +msgid "" +"Default: Not set (This is a mandatory setting that must be explicitly " +"defined for each configured domain)." +msgstr "" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2979 -msgid "use_fully_qualified_names (bool)" +#: sssd.conf.5.xml:3109 +msgid "use_fully_qualified_names (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2982 +#: sssd.conf.5.xml:3112 msgid "" "Use the full name and domain (as formatted by the domain's full_name_format) " "as the user's login name reported to NSS." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2987 +#: sssd.conf.5.xml:3117 msgid "" "If set to TRUE, all requests to this domain must use fully qualified names. " "For example, if used in EXAMPLE domain that contains a \"test\" user, " @@ -3564,7 +3738,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2995 +#: sssd.conf.5.xml:3125 msgid "" "NOTE: This option has no effect on netgroup lookups due to their tendency to " "include nested netgroups without qualified names. For netgroups, all domains " @@ -3572,24 +3746,26 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3002 +#: sssd.conf.5.xml:3132 msgid "" "Default: FALSE (TRUE for trusted domain/sub-domains or if " "default_domain_suffix is used)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3009 -msgid "ignore_group_members (bool)" -msgstr "" +#: sssd.conf.5.xml:3139 +#, fuzzy +#| msgid "ignore_group_members" +msgid "ignore_group_members (boolean)" +msgstr "ignore_group_members" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3012 +#: sssd.conf.5.xml:3142 msgid "Do not return group members for group lookups." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3015 +#: sssd.conf.5.xml:3145 msgid "" "If set to TRUE, the group membership attribute is not requested from the " "ldap server, and group members are not returned when processing group lookup " @@ -3601,7 +3777,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3033 +#: sssd.conf.5.xml:3163 msgid "" "Enabling this option can also make access provider checks for group " "membership significantly faster, especially for groups containing many " @@ -3609,7 +3785,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3039 sssd.conf.5.xml:3767 sssd-ldap.5.xml:401 +#: sssd.conf.5.xml:3169 sssd.conf.5.xml:3951 sssd-ldap.5.xml:401 #: sssd-ldap.5.xml:454 sssd-ldap.5.xml:529 sssd-ldap.5.xml:576 #: sssd-ldap.5.xml:599 sssd-ldap.5.xml:638 sssd-ldap.5.xml:657 #: sssd-ldap.5.xml:681 sssd-ldap.5.xml:1114 sssd-ldap.5.xml:1147 @@ -3619,19 +3795,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3049 +#: sssd.conf.5.xml:3179 msgid "auth_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3052 +#: sssd.conf.5.xml:3182 msgid "" "The authentication provider used for the domain. Supported auth providers " "are:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3056 sssd.conf.5.xml:3122 +#: sssd.conf.5.xml:3186 sssd.conf.5.xml:3252 msgid "" "<quote>ldap</quote> for native LDAP authentication. See <citerefentry> " "<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> </" @@ -3639,7 +3815,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3063 +#: sssd.conf.5.xml:3193 msgid "" "<quote>krb5</quote> for Kerberos authentication. See <citerefentry> " "<refentrytitle>sssd-krb5</refentrytitle> <manvolnum>5</manvolnum> </" @@ -3647,7 +3823,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3087 +#: sssd.conf.5.xml:3217 msgid "" "<quote>idp</quote>: Provider for OAuth 2.0/OIDC based authentication. See " "<citerefentry> <refentrytitle>sssd-idp</refentrytitle> <manvolnum>5</" @@ -3655,30 +3831,30 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3095 +#: sssd.conf.5.xml:3225 msgid "" "<quote>proxy</quote> for relaying authentication to some other PAM target." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3098 +#: sssd.conf.5.xml:3228 msgid "<quote>none</quote> disables authentication explicitly." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3101 +#: sssd.conf.5.xml:3231 msgid "" "Default: <quote>id_provider</quote> is used if it is set and can handle " "authentication requests." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3107 +#: sssd.conf.5.xml:3237 msgid "access_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3110 +#: sssd.conf.5.xml:3240 msgid "" "The access control provider used for the domain. There are two built-in " "access providers (in addition to any included in installed backends) " @@ -3686,17 +3862,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3116 +#: sssd.conf.5.xml:3246 msgid "<quote>permit</quote> always allow access." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3119 +#: sssd.conf.5.xml:3249 msgid "<quote>deny</quote> always deny access." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3146 +#: sssd.conf.5.xml:3276 msgid "" "<quote>simple</quote> access control based on access or deny lists. See " "<citerefentry> <refentrytitle>sssd-simple</refentrytitle> <manvolnum>5</" @@ -3705,7 +3881,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3153 +#: sssd.conf.5.xml:3283 msgid "" "<quote>krb5</quote>: .k5login based access control. See <citerefentry> " "<refentrytitle>sssd-krb5</refentrytitle> <manvolnum>5</manvolnum></" @@ -3713,29 +3889,29 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3160 +#: sssd.conf.5.xml:3290 msgid "<quote>proxy</quote> for relaying access control to another PAM module." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3163 +#: sssd.conf.5.xml:3293 msgid "Default: <quote>permit</quote>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3168 +#: sssd.conf.5.xml:3298 msgid "chpass_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3171 +#: sssd.conf.5.xml:3301 msgid "" "The provider which should handle change password operations for the domain. " "Supported change password providers are:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3176 +#: sssd.conf.5.xml:3306 msgid "" "<quote>ldap</quote> to change a password stored in a LDAP server. See " "<citerefentry> <refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</" @@ -3743,7 +3919,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3184 +#: sssd.conf.5.xml:3314 msgid "" "<quote>krb5</quote> to change the Kerberos password. See <citerefentry> " "<refentrytitle>sssd-krb5</refentrytitle> <manvolnum>5</manvolnum> </" @@ -3751,35 +3927,35 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3209 +#: sssd.conf.5.xml:3339 msgid "" "<quote>proxy</quote> for relaying password changes to some other PAM target." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3213 +#: sssd.conf.5.xml:3343 msgid "<quote>none</quote> disallows password changes explicitly." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3216 +#: sssd.conf.5.xml:3346 msgid "" "Default: <quote>auth_provider</quote> is used if it is set and can handle " "change password requests." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3223 +#: sssd.conf.5.xml:3353 msgid "sudo_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3226 +#: sssd.conf.5.xml:3356 msgid "The SUDO provider used for the domain. Supported SUDO providers are:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3230 +#: sssd.conf.5.xml:3360 msgid "" "<quote>ldap</quote> for rules stored in LDAP. See <citerefentry> " "<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> </" @@ -3787,33 +3963,33 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3238 +#: sssd.conf.5.xml:3368 msgid "" "<quote>ipa</quote> the same as <quote>ldap</quote> but with IPA default " "settings." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3242 +#: sssd.conf.5.xml:3372 msgid "" "<quote>ad</quote> the same as <quote>ldap</quote> but with AD default " "settings." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3246 +#: sssd.conf.5.xml:3376 msgid "<quote>none</quote> disables SUDO explicitly." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3249 +#: sssd.conf.5.xml:3379 msgid "" "Default: The value of <quote>id_provider</quote> is used if it is set and " "can handle sudo requests." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3253 +#: sssd.conf.5.xml:3383 msgid "" "The detailed instructions for configuration of sudo_provider are in the " "manual page <citerefentry> <refentrytitle>sssd-sudo</refentrytitle> " @@ -3824,7 +4000,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3268 +#: sssd.conf.5.xml:3398 msgid "" "<emphasis>NOTE:</emphasis> Sudo rules are periodically downloaded in the " "background unless the sudo provider is explicitly disabled. Set " @@ -3833,12 +4009,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3278 +#: sssd.conf.5.xml:3408 msgid "selinux_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3281 +#: sssd.conf.5.xml:3411 msgid "" "The provider which should handle loading of selinux settings. Note that this " "provider will be called right after access provider ends. Supported selinux " @@ -3846,7 +4022,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3287 +#: sssd.conf.5.xml:3417 msgid "" "<quote>ipa</quote> to load selinux settings from an IPA server. See " "<citerefentry> <refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</" @@ -3854,31 +4030,32 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3295 +#: sssd.conf.5.xml:3425 msgid "<quote>none</quote> disallows fetching selinux settings explicitly." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3298 +#: sssd.conf.5.xml:3428 msgid "" -"Default: <quote>id_provider</quote> is used if it is set and can handle " -"selinux loading requests." +"Default: the value of <quote>id_provider</quote> is used if it is set and " +"can handle selinux loading requests. Otherwise the result is the same as if " +"the selinux_provider is set to none." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3304 +#: sssd.conf.5.xml:3435 msgid "subdomains_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3307 +#: sssd.conf.5.xml:3438 msgid "" "The provider which should handle fetching of subdomains. This value should " "be always the same as id_provider. Supported subdomain providers are:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3313 +#: sssd.conf.5.xml:3444 msgid "" "<quote>ipa</quote> to load a list of subdomains from an IPA server. See " "<citerefentry> <refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</" @@ -3886,7 +4063,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3322 +#: sssd.conf.5.xml:3453 msgid "" "<quote>ad</quote> to load a list of subdomains from an Active Directory " "server. See <citerefentry> <refentrytitle>sssd-ad</refentrytitle> " @@ -3895,24 +4072,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3331 +#: sssd.conf.5.xml:3462 msgid "<quote>none</quote> disallows fetching subdomains explicitly." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3335 +#: sssd.conf.5.xml:3466 msgid "" "Default: The value of <quote>id_provider</quote> is used if it is set and " "can handle subdomain requests." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3341 +#: sssd.conf.5.xml:3472 msgid "session_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3344 +#: sssd.conf.5.xml:3475 msgid "" "The provider which configures and manages user session related tasks. The " "only user session task currently provided is the integration with Fleet " @@ -3920,36 +4097,36 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3351 +#: sssd.conf.5.xml:3482 msgid "<quote>ipa</quote> to allow performing user session related tasks." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3355 +#: sssd.conf.5.xml:3486 msgid "" "<quote>none</quote> does not perform any kind of user session related tasks." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3359 +#: sssd.conf.5.xml:3490 #, fuzzy #| msgid "Default: <quote>*</quote>" msgid "Default: <quote>none</quote>." msgstr "Oletus: <quote>*</quote>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3365 +#: sssd.conf.5.xml:3496 msgid "autofs_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3368 +#: sssd.conf.5.xml:3499 msgid "" "The autofs provider used for the domain. Supported autofs providers are:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3372 +#: sssd.conf.5.xml:3503 msgid "" "<quote>ldap</quote> to load maps stored in LDAP. See <citerefentry> " "<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> </" @@ -3957,7 +4134,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3379 +#: sssd.conf.5.xml:3510 msgid "" "<quote>ipa</quote> to load maps stored in an IPA server. See <citerefentry> " "<refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</manvolnum> </" @@ -3965,7 +4142,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3387 +#: sssd.conf.5.xml:3518 msgid "" "<quote>ad</quote> to load maps stored in an AD server. See <citerefentry> " "<refentrytitle>sssd-ad</refentrytitle> <manvolnum>5</manvolnum> </" @@ -3973,31 +4150,31 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3396 +#: sssd.conf.5.xml:3527 msgid "<quote>none</quote> disables autofs explicitly." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3399 +#: sssd.conf.5.xml:3530 msgid "" "Default: The value of <quote>id_provider</quote> is used if it is set and " "can handle autofs requests." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3406 +#: sssd.conf.5.xml:3537 msgid "hostid_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3409 +#: sssd.conf.5.xml:3540 msgid "" "The provider used for retrieving host identity information. Supported " "hostid providers are:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3413 +#: sssd.conf.5.xml:3544 msgid "" "<quote>ipa</quote> to load host identity stored in an IPA server. See " "<citerefentry> <refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</" @@ -4005,38 +4182,38 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3421 +#: sssd.conf.5.xml:3552 msgid "<quote>none</quote> disables hostid explicitly." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3424 +#: sssd.conf.5.xml:3555 msgid "" "Default: The value of <quote>id_provider</quote> is used if it is set and " "can handle hostid requests." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3431 +#: sssd.conf.5.xml:3562 msgid "resolver_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3434 +#: sssd.conf.5.xml:3565 msgid "" "The provider which should handle hosts and networks lookups. Supported " "resolver providers are:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3438 +#: sssd.conf.5.xml:3569 msgid "" "<quote>proxy</quote> to forward lookups to another NSS library. See " "<quote>proxy_resolver_lib_name</quote>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3442 +#: sssd.conf.5.xml:3573 msgid "" "<quote>ldap</quote> to fetch hosts and networks stored in LDAP. See " "<citerefentry> <refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</" @@ -4044,7 +4221,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3449 +#: sssd.conf.5.xml:3580 msgid "" "<quote>ad</quote> to fetch hosts and networks stored in AD. See " "<citerefentry> <refentrytitle>sssd-ad</refentrytitle> <manvolnum>5</" @@ -4053,19 +4230,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3457 +#: sssd.conf.5.xml:3588 msgid "<quote>none</quote> disallows fetching hosts and networks explicitly." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3460 +#: sssd.conf.5.xml:3591 msgid "" "Default: The value of <quote>id_provider</quote> is used if it is set and " "can handle resolver requests." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3470 +#: sssd.conf.5.xml:3601 msgid "" "Regular expression for this domain that describes how to parse the string " "containing user name and domain into these components. The \"domain\" can " @@ -4075,24 +4252,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3479 +#: sssd.conf.5.xml:3610 msgid "" "Default: <quote>^((?P<name>.+)@(?P<domain>[^@]*)|(?P<name>" "[^@]+))$</quote> which allows two different styles for user names:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:3484 sssd.conf.5.xml:3498 +#: sssd.conf.5.xml:3615 sssd.conf.5.xml:3629 msgid "username" msgstr "käyttäjänimi" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:3487 sssd.conf.5.xml:3501 +#: sssd.conf.5.xml:3618 sssd.conf.5.xml:3632 msgid "username@domain.name" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3492 +#: sssd.conf.5.xml:3623 msgid "" "Default for the AD and IPA provider: <quote>^(((?P<domain>[^\\\\]+)\\\\" "(?P<name>.+))|((?P<name>.+)@(?P<domain>[^@]+))|((?" @@ -4101,19 +4278,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:3504 +#: sssd.conf.5.xml:3635 msgid "domain\\username" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3507 +#: sssd.conf.5.xml:3638 msgid "" "While the first two correspond to the general default the third one is " "introduced to allow easy integration of users from Windows domains." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3512 +#: sssd.conf.5.xml:3643 msgid "" "The default re_expression uses the <quote>@</quote> character as a separator " "between the name and the domain. As a result of this setting the default " @@ -4123,89 +4300,94 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3564 +#: sssd.conf.5.xml:3695 msgid "Default: <quote>%1$s@%2$s</quote>." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3570 +#: sssd.conf.5.xml:3701 msgid "lookup_family_order (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3573 +#: sssd.conf.5.xml:3704 msgid "" "Provides the ability to select preferred address family to use when " "performing DNS lookups." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3577 +#: sssd.conf.5.xml:3708 msgid "Supported values:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3580 +#: sssd.conf.5.xml:3711 msgid "ipv4_first: Try looking up IPv4 address, if that fails, try IPv6" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3583 +#: sssd.conf.5.xml:3714 msgid "ipv4_only: Only attempt to resolve hostnames to IPv4 addresses." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3586 +#: sssd.conf.5.xml:3717 msgid "ipv6_first: Try looking up IPv6 address, if that fails, try IPv4" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3589 +#: sssd.conf.5.xml:3720 msgid "ipv6_only: Only attempt to resolve hostnames to IPv6 addresses." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3592 +#: sssd.conf.5.xml:3723 msgid "Default: ipv4_first" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3598 +#: sssd.conf.5.xml:3729 msgid "dns_resolver_server_timeout (integer)" msgstr "dns_resolver_server_timeout (integeri)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3601 +#: sssd.conf.5.xml:3732 msgid "" -"Defines the amount of time (in milliseconds) SSSD would try to talk to DNS " -"server before trying next DNS server." +"Defines the timeout duration (in milliseconds) SSSD waits for a DNS server " +"to respond before moving to the next one." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3606 +#: sssd.conf.5.xml:3737 msgid "" "The AD provider will use this option for the CLDAP ping timeouts as well." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3610 sssd.conf.5.xml:3630 sssd.conf.5.xml:3651 +#: sssd.conf.5.xml:3741 sssd.conf.5.xml:3777 sssd.conf.5.xml:3814 msgid "" -"Please see the section <quote>FAILOVER</quote> for more information about " -"the service resolution." +"Please see the section <quote>FAILOVER</quote> in <citerefentry> " +"<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> </" +"citerefentry>, <citerefentry> <refentrytitle>sssd-krb5</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry>, <citerefentry> <refentrytitle>sssd-" +"ipa</refentrytitle> <manvolnum>5</manvolnum> </citerefentry> or " +"<citerefentry> <refentrytitle>sssd-ad</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry> for more information about the service resolution." msgstr "" #. type: Content of: <refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3615 sssd-ldap.5.xml:700 include/failover.xml:84 +#: sssd.conf.5.xml:3762 sssd-ldap.5.xml:700 include/failover.xml:84 msgid "Default: 1000" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3621 +#: sssd.conf.5.xml:3768 msgid "dns_resolver_op_timeout (integer)" msgstr "dns_resolver_op_timeout (integeri)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3624 +#: sssd.conf.5.xml:3771 msgid "" "Defines the amount of time (in seconds) to wait to resolve single DNS query " "(e.g. resolution of a hostname or an SRV record) before trying the next " @@ -4213,17 +4395,17 @@ msgid "" msgstr "" #. type: Content of: <refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3635 include/failover.xml:100 +#: sssd.conf.5.xml:3798 include/failover.xml:100 msgid "Default: 3" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3641 +#: sssd.conf.5.xml:3804 msgid "dns_resolver_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3644 +#: sssd.conf.5.xml:3807 msgid "" "Defines the amount of time (in seconds) to wait for a reply from the " "internal fail over service before assuming that the service is unreachable. " @@ -4232,14 +4414,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3662 +#: sssd.conf.5.xml:3841 #, fuzzy #| msgid "dns_resolver_server_timeout (integer)" -msgid "dns_resolver_use_search_list (bool)" +msgid "dns_resolver_use_search_list (boolean)" msgstr "dns_resolver_server_timeout (integeri)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3665 +#: sssd.conf.5.xml:3844 msgid "" "Normally, the DNS resolver searches the domain list defined in the " "\"search\" directive from the resolv.conf file. This can lead to delays in " @@ -4247,7 +4429,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3671 +#: sssd.conf.5.xml:3850 msgid "" "If fully qualified domain names (or _srv_) are used in the SSSD " "configuration, setting this option to FALSE can prevent unnecessary DNS " @@ -4255,38 +4437,38 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3677 +#: sssd.conf.5.xml:3856 #, fuzzy #| msgid "Default: True" msgid "Default: TRUE" msgstr "Oletus:tosi" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3683 +#: sssd.conf.5.xml:3862 msgid "dns_discovery_domain (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3686 +#: sssd.conf.5.xml:3865 msgid "" "If service discovery is used in the back end, specifies the domain part of " "the service discovery DNS query." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3690 +#: sssd.conf.5.xml:3869 msgid "Default: Use the domain part of machine's hostname" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3696 +#: sssd.conf.5.xml:3875 #, fuzzy #| msgid "dns_resolver_op_timeout (integer)" msgid "failover_primary_timeout (integer)" msgstr "dns_resolver_op_timeout (integeri)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3699 +#: sssd.conf.5.xml:3878 msgid "" "When no primary server is available, SSSD fails over to a backup server. " "This option defines the number of seconds SSSD waits before attempting to " @@ -4294,59 +4476,68 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3706 +#: sssd.conf.5.xml:3885 msgid "Note: The minimum value is 31." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3709 +#: sssd.conf.5.xml:3888 #, fuzzy #| msgid "Default: 30" msgid "Default: 31" msgstr "Oletus: 30" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3715 +#: sssd.conf.5.xml:3894 msgid "override_gid (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3718 -msgid "Override the primary GID value with the one specified." +#: sssd.conf.5.xml:3897 +msgid "" +"Override the primary GID value for all users in the domain with specified " +"value." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3901 +msgid "" +"Default: not set (Use the primary GID value retrieved from the identity " +"provider)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3724 +#: sssd.conf.5.xml:3908 msgid "case_sensitive (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3731 +#: sssd.conf.5.xml:3915 msgid "True" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3734 +#: sssd.conf.5.xml:3918 msgid "Case sensitive. This value is invalid for AD provider." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3740 +#: sssd.conf.5.xml:3924 msgid "False" msgstr "epätosi" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3742 +#: sssd.conf.5.xml:3926 msgid "Case insensitive." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3746 +#: sssd.conf.5.xml:3930 msgid "Preserving" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3749 +#: sssd.conf.5.xml:3933 msgid "" "Same as False (case insensitive), but does not lowercase names in the result " "of NSS operations. Note that name aliases (and in case of services also " @@ -4354,31 +4545,57 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3757 +#: sssd.conf.5.xml:3941 msgid "" "If you want to set this value for trusted domain with IPA provider, you need " "to set it on both the client and SSSD on the server." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3727 +#: sssd.conf.5.xml:3911 msgid "" "Treat user and group names as case sensitive. Possible option values are: " "<placeholder type=\"variablelist\" id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3772 +#: sssd.conf.5.xml:3956 msgid "Default: True (False for AD provider)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3778 +#: sssd.conf.5.xml:3962 +msgid "avoid_by_id_lookups (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3965 +msgid "" +"If this option is set to 'true' SSSD will try to avoid sending lookups by ID " +"to the backend and will switch to a lookup by name if a cached object with a " +"matching ID can be found." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3971 +msgid "" +"This option can e.g. be used in cases where searches by ID are expensive on " +"the server side because of missing indexes or are not even possible, e.g. " +"due to non-reversible POSIX id-mapping." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3978 +msgid "Default: False (True for IdP provider)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:3984 msgid "subdomain_inherit (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3781 +#: sssd.conf.5.xml:3987 msgid "" "Specifies a list of configuration parameters that should be inherited by a " "subdomain. Please note that only selected parameters can be inherited. " @@ -4386,105 +4603,105 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3787 +#: sssd.conf.5.xml:3993 #, fuzzy #| msgid "ldap_purge_cache_timeout" msgid "ldap_search_timeout" msgstr "ldap_purge_cache_timeout" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3790 +#: sssd.conf.5.xml:3996 #, fuzzy #| msgid "client_idle_timeout" msgid "ldap_network_timeout" msgstr "client_idle_timeout" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3793 +#: sssd.conf.5.xml:3999 #, fuzzy #| msgid "ldap_purge_cache_timeout" msgid "ldap_opt_timeout" msgstr "ldap_purge_cache_timeout" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3796 +#: sssd.conf.5.xml:4002 #, fuzzy #| msgid "client_idle_timeout" msgid "ldap_offline_timeout" msgstr "client_idle_timeout" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3799 +#: sssd.conf.5.xml:4005 msgid "ldap_purge_cache_timeout" msgstr "ldap_purge_cache_timeout" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3802 +#: sssd.conf.5.xml:4008 #, fuzzy #| msgid "ldap_purge_cache_timeout" msgid "ldap_purge_cache_offset" msgstr "ldap_purge_cache_timeout" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3805 +#: sssd.conf.5.xml:4011 msgid "" "ldap_krb5_keytab (the value of krb5_keytab will be used if ldap_krb5_keytab " "is not set explicitly)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3809 +#: sssd.conf.5.xml:4015 msgid "ldap_krb5_ticket_lifetime" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3812 +#: sssd.conf.5.xml:4018 #, fuzzy #| msgid "client_idle_timeout" msgid "ldap_connection_expire_timeout" msgstr "client_idle_timeout" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3815 +#: sssd.conf.5.xml:4021 #, fuzzy #| msgid "client_idle_timeout" msgid "ldap_connection_expire_offset" msgstr "client_idle_timeout" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3818 +#: sssd.conf.5.xml:4024 #, fuzzy #| msgid "client_idle_timeout" msgid "ldap_connection_idle_timeout" msgstr "client_idle_timeout" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3821 sssd-ldap.5.xml:446 +#: sssd.conf.5.xml:4027 sssd-ldap.5.xml:446 msgid "ldap_use_tokengroups" msgstr "ldap_use_tokengroups" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3824 +#: sssd.conf.5.xml:4030 msgid "ldap_user_principal" msgstr "ldap_user_principal" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3827 +#: sssd.conf.5.xml:4033 msgid "ignore_group_members" msgstr "ignore_group_members" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3830 +#: sssd.conf.5.xml:4036 msgid "auto_private_groups" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3833 +#: sssd.conf.5.xml:4039 msgid "case_sensitive" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:3838 +#: sssd.conf.5.xml:4044 #, no-wrap msgid "" "subdomain_inherit = ldap_purge_cache_timeout\n" @@ -4494,27 +4711,27 @@ msgstr "" " " #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3845 +#: sssd.conf.5.xml:4051 msgid "Note: This option only works with the IPA and AD provider." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3852 +#: sssd.conf.5.xml:4058 msgid "subdomain_homedir (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3863 +#: sssd.conf.5.xml:4069 msgid "%F" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3864 +#: sssd.conf.5.xml:4070 msgid "flat (NetBIOS) name of a subdomain." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3855 +#: sssd.conf.5.xml:4061 msgid "" "Use this homedir as default value for all subdomains within this domain in " "IPA AD trust. See <emphasis>override_homedir</emphasis> for info about " @@ -4524,55 +4741,55 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3869 +#: sssd.conf.5.xml:4075 msgid "" "The value can be overridden by <emphasis>override_homedir</emphasis> option." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3873 +#: sssd.conf.5.xml:4079 msgid "Default: <filename>/home/%d/%u</filename>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3878 +#: sssd.conf.5.xml:4084 msgid "realmd_tags (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3881 +#: sssd.conf.5.xml:4087 msgid "" "Various tags stored by the realmd configuration service for this domain." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3887 +#: sssd.conf.5.xml:4093 msgid "cached_auth_timeout (int)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3890 +#: sssd.conf.5.xml:4096 msgid "" -"Specifies time in seconds since last successful online authentication for " -"which user will be authenticated using cached credentials while SSSD is in " -"the online mode. If the credentials are incorrect, SSSD falls back to online " -"authentication." +"Specifies the number of seconds since the last successful online " +"authentication during which SSSD will authenticate users via cached " +"credentials, even while online. If the cached authentication fails, SSSD " +"immediately falls back to online authentication." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3898 +#: sssd.conf.5.xml:4103 msgid "" "This option's value is inherited by all trusted domains. At the moment it is " "not possible to set a different value per trusted domain." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3903 +#: sssd.conf.5.xml:4108 msgid "Special value 0 implies that this feature is disabled." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3907 +#: sssd.conf.5.xml:4112 msgid "" "Please note that if <quote>cached_auth_timeout</quote> is longer than " "<quote>pam_id_timeout</quote> then the back end could be called to handle " @@ -4580,14 +4797,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3918 +#: sssd.conf.5.xml:4123 #, fuzzy #| msgid "ldap_user_principal" msgid "local_auth_policy (string)" msgstr "ldap_user_principal" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3921 +#: sssd.conf.5.xml:4126 msgid "" "Local authentication methods policy. Some backends (i.e. LDAP, proxy " "provider) only support a password based authentication, while others can " @@ -4599,7 +4816,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3933 +#: sssd.conf.5.xml:4138 msgid "" "There are three possible values for this option: match, only, enable. " "<quote>match</quote> is used to match offline and online states for Kerberos " @@ -4611,7 +4828,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3946 +#: sssd.conf.5.xml:4151 msgid "" "The following table shows which authentication methods, if configured " "properly, are currently enabled or disabled for each backend, with the " @@ -4619,46 +4836,51 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> -#: sssd.conf.5.xml:3959 +#: sssd.conf.5.xml:4164 #, fuzzy #| msgid "ldap_user_principal" msgid "local_auth_policy = match (default)" msgstr "ldap_user_principal" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> -#: sssd.conf.5.xml:3960 +#: sssd.conf.5.xml:4165 msgid "Passkey" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> -#: sssd.conf.5.xml:3961 +#: sssd.conf.5.xml:4166 msgid "Smartcard" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:3964 sssd-ldap.5.xml:228 +#: sssd.conf.5.xml:4169 sssd-ldap.5.xml:228 msgid "IPA" msgstr "" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry><para> +#: sssd.conf.5.xml:4169 sssd.conf.5.xml:4170 sssd.conf.5.xml:4173 +msgid "enabled" +msgstr "käytössä" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:3967 sssd-ldap.5.xml:233 +#: sssd.conf.5.xml:4172 sssd-ldap.5.xml:233 msgid "AD" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry><para> -#: sssd.conf.5.xml:3967 sssd.conf.5.xml:3970 sssd.conf.5.xml:3971 +#: sssd.conf.5.xml:4172 sssd.conf.5.xml:4175 sssd.conf.5.xml:4176 #, fuzzy #| msgid "enabled" msgid "disabled" msgstr "käytössä" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry> -#: sssd.conf.5.xml:3970 +#: sssd.conf.5.xml:4175 msgid "LDAP" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3975 +#: sssd.conf.5.xml:4180 msgid "" "Please note that if local Smartcard authentication is enabled and a " "Smartcard is present, Smartcard authentication will be preferred over the " @@ -4667,7 +4889,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:3987 +#: sssd.conf.5.xml:4192 #, no-wrap msgid "" "[domain/shadowutils]\n" @@ -4678,7 +4900,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3983 +#: sssd.conf.5.xml:4188 msgid "" "The following configuration example allows local users to authenticate " "locally using any enabled method (i.e. smartcard, passkey). <placeholder " @@ -4686,31 +4908,31 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3995 +#: sssd.conf.5.xml:4200 #, fuzzy #| msgid "Default: true" msgid "Default: match" msgstr "Oletus:tosi" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4000 +#: sssd.conf.5.xml:4205 msgid "auto_private_groups (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4006 +#: sssd.conf.5.xml:4211 msgid "true" msgstr "tosi" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4009 +#: sssd.conf.5.xml:4214 msgid "" "Create user's private group unconditionally from user's UID number. The GID " "number is ignored in this case." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4013 +#: sssd.conf.5.xml:4218 msgid "" "NOTE: Because the GID number and the user private group are inferred from " "the UID number, it is not supported to have multiple entries with the same " @@ -4719,24 +4941,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4022 +#: sssd.conf.5.xml:4227 msgid "false" msgstr "epätosi" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4025 +#: sssd.conf.5.xml:4230 msgid "" "Always use the user's primary GID number. The GID number must refer to a " "group object in the LDAP database." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4031 +#: sssd.conf.5.xml:4236 msgid "hybrid" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4034 +#: sssd.conf.5.xml:4239 msgid "" "A primary group is autogenerated for user entries whose UID and GID numbers " "have the same value and at the same time the GID number does not correspond " @@ -4746,14 +4968,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4047 +#: sssd.conf.5.xml:4252 msgid "" "If the UID and GID of a user are different, then the GID must correspond to " "a group entry, otherwise the GID is simply not resolvable." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4054 +#: sssd.conf.5.xml:4259 msgid "" "This feature is useful for environments that wish to stop maintaining a " "separate group objects for the user private groups, but also wish to retain " @@ -4761,14 +4983,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4003 +#: sssd.conf.5.xml:4208 msgid "" "This option takes any of three available values: <placeholder " "type=\"variablelist\" id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4066 +#: sssd.conf.5.xml:4271 msgid "" "For the LDAP based id providers (LDAP, IPA and AD) the default for the " "configured domain is typically False because the sources have the concept of " @@ -4778,14 +5000,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4075 +#: sssd.conf.5.xml:4280 msgid "" "For subdomains, the default value is False for subdomains that use assigned " "POSIX IDs and True for subdomains that use automatic ID-mapping." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:4083 +#: sssd.conf.5.xml:4288 #, no-wrap msgid "" "[domain/forest.domain/sub.domain]\n" @@ -4793,7 +5015,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:4089 +#: sssd.conf.5.xml:4294 #, no-wrap msgid "" "[domain/forest.domain]\n" @@ -4802,7 +5024,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4080 +#: sssd.conf.5.xml:4285 msgid "" "The value of auto_private_groups can either be set per subdomains in a " "subsection, for example: <placeholder type=\"programlisting\" id=\"0\"/> or " @@ -4811,7 +5033,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:2503 +#: sssd.conf.5.xml:2549 msgid "" "These configuration options can be present in a domain configuration " "section, that is, in a section called <quote>[domain/<replaceable>NAME</" @@ -4819,17 +5041,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4104 +#: sssd.conf.5.xml:4309 msgid "proxy_pam_target (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4107 +#: sssd.conf.5.xml:4312 msgid "The proxy target PAM proxies to." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4110 +#: sssd.conf.5.xml:4315 msgid "" "Default: not set by default, you have to take an existing pam configuration " "or create a new one and add the service name here. As an alternative you can " @@ -4837,12 +5059,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4120 +#: sssd.conf.5.xml:4325 msgid "proxy_lib_name (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4123 +#: sssd.conf.5.xml:4328 msgid "" "The name of the NSS library to use in proxy domains. The NSS functions " "searched for in the library are in the form of _nss_$(libName)_$(function), " @@ -4850,12 +5072,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4133 +#: sssd.conf.5.xml:4338 msgid "proxy_resolver_lib_name (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4136 +#: sssd.conf.5.xml:4341 msgid "" "The name of the NSS library to use for hosts and networks lookups in proxy " "domains. The NSS functions searched for in the library are in the form of " @@ -4863,12 +5085,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4147 +#: sssd.conf.5.xml:4352 msgid "proxy_fast_alias (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4150 +#: sssd.conf.5.xml:4355 msgid "" "When a user or group is looked up by name in the proxy provider, a second " "lookup by ID is performed to \"canonicalize\" the name in case the requested " @@ -4877,12 +5099,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4164 +#: sssd.conf.5.xml:4369 msgid "proxy_max_children (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4167 +#: sssd.conf.5.xml:4372 msgid "" "This option specifies the number of pre-forked proxy children. It is useful " "for high-load SSSD environments where sssd may run out of available child " @@ -4890,19 +5112,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4100 +#: sssd.conf.5.xml:4305 msgid "" "Options valid for proxy domains. <placeholder type=\"variablelist\" " "id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:4183 +#: sssd.conf.5.xml:4388 msgid "Application domains" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:4185 +#: sssd.conf.5.xml:4390 msgid "" "SSSD, with its D-Bus interface (see <citerefentry> <refentrytitle>sssd-ifp</" "refentrytitle> <manvolnum>5</manvolnum> </citerefentry>) is appealing to " @@ -4919,7 +5141,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:4205 +#: sssd.conf.5.xml:4410 msgid "" "Please note that the application domain must still be explicitly enabled in " "the <quote>domains</quote> parameter so that the lookup order between the " @@ -4927,17 +5149,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><title> -#: sssd.conf.5.xml:4211 +#: sssd.conf.5.xml:4416 msgid "Application domain parameters" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4213 +#: sssd.conf.5.xml:4418 msgid "inherit_from (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4216 +#: sssd.conf.5.xml:4421 msgid "" "The SSSD POSIX-type domain the application domain inherits all settings " "from. The application domain can moreover add its own settings to the " @@ -4946,7 +5168,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:4230 +#: sssd.conf.5.xml:4435 msgid "" "The following example illustrates the use of an application domain. In this " "setup, the POSIX domain is connected to an LDAP server and is used by the OS " @@ -4956,7 +5178,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><programlisting> -#: sssd.conf.5.xml:4238 +#: sssd.conf.5.xml:4443 #, no-wrap msgid "" "[sssd]\n" @@ -4976,12 +5198,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:4258 +#: sssd.conf.5.xml:4463 msgid "TRUSTED DOMAIN SECTION" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4260 +#: sssd.conf.5.xml:4465 msgid "" "Some options used in the domain section can also be used in the trusted " "domain section, that is, in a section called <quote>[domain/" @@ -4992,69 +5214,79 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4267 +#: sssd.conf.5.xml:4472 msgid "ldap_search_base," msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4268 +#: sssd.conf.5.xml:4473 msgid "ldap_user_search_base," msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4269 +#: sssd.conf.5.xml:4474 msgid "ldap_group_search_base," msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4270 +#: sssd.conf.5.xml:4475 msgid "ldap_netgroup_search_base," msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4271 +#: sssd.conf.5.xml:4476 msgid "ldap_service_search_base," msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4272 +#: sssd.conf.5.xml:4477 msgid "ldap_sasl_mech," msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4273 +#: sssd.conf.5.xml:4478 msgid "ad_server," msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4274 +#: sssd.conf.5.xml:4479 msgid "ad_backup_server," msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4275 +#: sssd.conf.5.xml:4480 msgid "ad_site," msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:4276 sssd-ipa.5.xml:934 +#: sssd.conf.5.xml:4481 sssd-ipa.5.xml:929 msgid "use_fully_qualified_names" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4280 +#: sssd.conf.5.xml:4482 +msgid "pam_gssapi_services" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:4483 +msgid "pam_gssapi_check_upn" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:4485 msgid "" "For more details about these options see their individual description in the " "manual page." msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:4286 +#: sssd.conf.5.xml:4491 msgid "CERTIFICATE MAPPING SECTION" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4288 +#: sssd.conf.5.xml:4493 msgid "" "To allow authentication with Smartcards and certificates SSSD must be able " "to map certificates to users. This can be done by adding the full " @@ -5067,7 +5299,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4302 +#: sssd.conf.5.xml:4507 msgid "" "To make the mapping more flexible mapping and matching rules were added to " "SSSD (see <citerefentry> <refentrytitle>sss-certmap</refentrytitle> " @@ -5075,7 +5307,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4311 +#: sssd.conf.5.xml:4516 msgid "" "A mapping and matching rule can be added to the SSSD configuration in a " "section on its own with a name like <quote>[certmap/" @@ -5084,55 +5316,50 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4318 +#: sssd.conf.5.xml:4523 msgid "matchrule (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4321 +#: sssd.conf.5.xml:4526 msgid "" "Only certificates from the Smartcard which matches this rule will be " "processed, all others are ignored." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4325 +#: sssd.conf.5.xml:4530 msgid "" "Default: KRB5:<EKU>clientAuth, i.e. only certificates which have the " "Extended Key Usage <quote>clientAuth</quote>" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4332 +#: sssd.conf.5.xml:4537 msgid "maprule (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4335 +#: sssd.conf.5.xml:4540 msgid "Defines how the user is found for a given certificate." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:4341 +#: sssd.conf.5.xml:4546 msgid "" "LDAP:(userCertificate;binary={cert!bin}) for LDAP based providers like " "<quote>ldap</quote>, <quote>AD</quote> or <quote>ipa</quote>." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:4347 +#: sssd.conf.5.xml:4552 msgid "" "If maprule is not set and provider is <quote>proxy</quote>, the RULE_NAME " "name is assumed to be the name of the matching user." msgstr "" -#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4357 -msgid "domains (string)" -msgstr "" - #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4360 +#: sssd.conf.5.xml:4565 msgid "" "Comma separated list of domain names the rule should be applied. By default " "a rule is only valid in the domain configured in sssd.conf. If the provider " @@ -5141,17 +5368,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4367 +#: sssd.conf.5.xml:4572 msgid "Default: the configured domain in sssd.conf" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4372 +#: sssd.conf.5.xml:4577 msgid "priority (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4375 +#: sssd.conf.5.xml:4580 msgid "" "Unsigned integer value defining the priority of the rule. The higher the " "number the lower the priority. <quote>0</quote> stands for the highest " @@ -5159,17 +5386,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4381 +#: sssd.conf.5.xml:4586 msgid "Default: the lowest priority" msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:4389 +#: sssd.conf.5.xml:4594 msgid "PROMPTING CONFIGURATION SECTION" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4391 +#: sssd.conf.5.xml:4596 msgid "" "If a special file (<filename>/var/lib/sss/pubconf/pam_preauth_available</" "filename>) exists SSSD's PAM module pam_sss will ask SSSD to figure out " @@ -5179,7 +5406,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4399 +#: sssd.conf.5.xml:4604 msgid "" "With the growing number of authentication methods and the possibility that " "there are multiple ones for a single user the heuristic used by pam_sss to " @@ -5188,59 +5415,59 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4411 +#: sssd.conf.5.xml:4616 msgid "[prompting/password]" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4414 +#: sssd.conf.5.xml:4619 msgid "password_prompt" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4415 +#: sssd.conf.5.xml:4620 msgid "to change the string of the password prompt" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4413 +#: sssd.conf.5.xml:4618 msgid "" "to configure password prompting, allowed options are: <placeholder " "type=\"variablelist\" id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4423 +#: sssd.conf.5.xml:4628 msgid "[prompting/2fa]" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4427 +#: sssd.conf.5.xml:4632 msgid "first_prompt" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4428 +#: sssd.conf.5.xml:4633 msgid "to change the string of the prompt for the first factor" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4431 +#: sssd.conf.5.xml:4636 msgid "second_prompt" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4432 +#: sssd.conf.5.xml:4637 msgid "to change the string of the prompt for the second factor" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4435 +#: sssd.conf.5.xml:4640 msgid "single_prompt" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4436 +#: sssd.conf.5.xml:4641 msgid "" "boolean value, if True there will be only a single prompt using the value of " "first_prompt where it is expected that both factors are entered as a single " @@ -5249,7 +5476,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4425 +#: sssd.conf.5.xml:4630 msgid "" "to configure two-factor authentication prompting, allowed options are: " "<placeholder type=\"variablelist\" id=\"0\"/> If the second factor is " @@ -5258,7 +5485,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4449 +#: sssd.conf.5.xml:4654 msgid "" "Some clients, such as SSH with 'PasswordAuthentication yes', generate their " "own prompts and do not use prompts provided by SSSD or other PAM modules. " @@ -5269,17 +5496,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4464 +#: sssd.conf.5.xml:4669 msgid "[prompting/passkey]" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:4470 sssd-ad.5.xml:1022 +#: sssd.conf.5.xml:4675 sssd.conf.5.xml:4719 sssd-ad.5.xml:1027 msgid "interactive" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4472 +#: sssd.conf.5.xml:4677 msgid "" "boolean value, if True prompt a message and wait before testing the presence " "of a passkey device. Recommended if your device doesn’t have a tactile " @@ -5287,55 +5514,133 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4480 +#: sssd.conf.5.xml:4685 sssd.conf.5.xml:4735 msgid "interactive_prompt" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4482 +#: sssd.conf.5.xml:4687 sssd.conf.5.xml:4737 msgid "to change the message of the interactive prompt." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4487 +#: sssd.conf.5.xml:4692 msgid "touch" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4489 +#: sssd.conf.5.xml:4694 msgid "" "boolean value, if True prompt a message to remind the user to touch the " "device." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4495 +#: sssd.conf.5.xml:4700 msgid "touch_prompt" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4497 +#: sssd.conf.5.xml:4702 msgid "to change the message of the touch prompt." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4466 +#: sssd.conf.5.xml:4671 msgid "" "to configure passkey authentication prompting, allowed options are: " "<placeholder type=\"variablelist\" id=\"0\"/>" msgstr "" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4713 +msgid "[prompting/oauth2]" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4721 +msgid "" +"boolean value, if True prompt a message after asking the user to " +"authenticate, and wait before requesting the access token." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4725 +msgid "" +"If False, make sure to set the <quote>idp_request_timeout</quote> " +"sufficiently high, to give the user time to authenticate." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4715 +msgid "" +"to configure OAuth2 authentication prompting, allowed options are: " +"<placeholder type=\"variablelist\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4748 +msgid "[prompting/cert_auth]" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4754 +msgid "pin_prompt" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4756 +msgid "" +"to change the message which asks the user to enter the PIN at the computer " +"keyboard. At the end of the message the token name is printed." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4764 +msgid "keypad_prompt" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4766 +msgid "" +"to change the message which asks the user to enter the PIN at keypad of the " +"Smartcard reader. At the end of the message the token name is printed." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4774 +#, fuzzy +#| msgid "username" +msgid "user_name_hint" +msgstr "käyttäjänimi" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4776 +msgid "" +"boolean value, if True ask for a user name if no name was given before and " +"the found certificate can be mapped to more than one user." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4750 +msgid "" +"to configure Smartcard authentication prompting, allowed options are: " +"<placeholder type=\"variablelist\" id=\"0\"/>" +msgstr "" + #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4406 +#: sssd.conf.5.xml:4611 msgid "" "Each supported authentication method has its own configuration subsection " "under <quote>[prompting/...]</quote>. Currently there are: <placeholder " "type=\"variablelist\" id=\"0\"/> <placeholder type=\"variablelist\" id=\"1\"/" -"> <placeholder type=\"variablelist\" id=\"2\"/>" +"> <placeholder type=\"variablelist\" id=\"2\"/> <placeholder " +"type=\"variablelist\" id=\"3\"/> <placeholder type=\"variablelist\" id=\"4\"/" +">" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4508 +#: sssd.conf.5.xml:4792 msgid "" "It is possible to add a subsection for specific PAM services, e.g. " "<quote>[prompting/password/sshd]</quote> to individual change the prompting " @@ -5343,12 +5648,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:4515 pam_sss_gss.8.xml:157 idmap_sss.8.xml:43 +#: sssd.conf.5.xml:4799 pam_sss_gss.8.xml:157 idmap_sss.8.xml:43 msgid "EXAMPLES" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd.conf.5.xml:4521 +#: sssd.conf.5.xml:4805 #, no-wrap msgid "" "[sssd]\n" @@ -5377,7 +5682,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4517 +#: sssd.conf.5.xml:4801 msgid "" "1. The following example shows a typical SSSD config. It does not describe " "configuration of the domains themselves - refer to documentation on " @@ -5386,7 +5691,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd.conf.5.xml:4553 +#: sssd.conf.5.xml:4837 #, no-wrap msgid "" "[domain/ipa.com/child.ad.com]\n" @@ -5394,7 +5699,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4547 +#: sssd.conf.5.xml:4831 msgid "" "2. The following example shows configuration of IPA AD trust where the AD " "forest consists of two domains in a parent-child structure. Suppose IPA " @@ -5405,7 +5710,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd.conf.5.xml:4564 +#: sssd.conf.5.xml:4848 #, no-wrap msgid "" "[certmap/my.domain/rule_name]\n" @@ -5416,7 +5721,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4558 +#: sssd.conf.5.xml:4842 msgid "" "3. The following example shows the configuration of a certificate mapping " "rule. It is valid for the configured domain <quote>my.domain</quote> and " @@ -5613,7 +5918,7 @@ msgid "" "defaultNamingContext does not exist or has an empty value namingContexts is " "used. The namingContexts attribute must have a single value with the DN of " "the search base of the LDAP server to make this work. Multiple values are " -"are not supported." +"not supported." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> @@ -5920,15 +6225,15 @@ msgid "Optional. Use the given string as search base for host objects." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap.5.xml:472 sssd-ipa.5.xml:506 sssd-ipa.5.xml:525 sssd-ipa.5.xml:544 -#: sssd-ipa.5.xml:563 +#: sssd-ldap.5.xml:472 sssd-ipa.5.xml:501 sssd-ipa.5.xml:520 sssd-ipa.5.xml:539 +#: sssd-ipa.5.xml:558 msgid "" "See <quote>ldap_search_base</quote> for information about configuring " "multiple search bases." msgstr "" #. type: Content of: <listitem><para> -#: sssd-ldap.5.xml:477 sssd-ipa.5.xml:511 include/ldap_search_bases.xml:27 +#: sssd-ldap.5.xml:477 sssd-ipa.5.xml:506 include/ldap_search_bases.xml:27 msgid "Default: the value of <emphasis>ldap_search_base</emphasis>" msgstr "" @@ -6054,7 +6359,7 @@ msgid "" "closed early to ensure that a new query cannot require the connection to " "remain open past its expiration. This implies that connections will always " "be closed immediately and will never be reused if " -"<emphasis>ldap_connection_expire_timeout <= ldap_opt_timout</emphasis>" +"<emphasis>ldap_connection_expire_timeout <= ldap_opt_timeout</emphasis>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> @@ -6238,7 +6543,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:831 -msgid "ldap_ignore_unreadable_references (bool)" +msgid "ldap_ignore_unreadable_references (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> @@ -6563,7 +6868,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap.5.xml:1152 sssd-ad.5.xml:1267 +#: sssd-ldap.5.xml:1152 sssd-ad.5.xml:1260 msgid "Default: 86400 (24 hours)" msgstr "" @@ -6601,7 +6906,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ldap.5.xml:1187 sssd-ipa.5.xml:575 sssd-krb5.5.xml:103 +#: sssd-ldap.5.xml:1187 sssd-ipa.5.xml:570 sssd-krb5.5.xml:103 msgid "krb5_realm (string)" msgstr "" @@ -6757,7 +7062,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1339 -msgid "ldap_chpass_update_last_change (bool)" +msgid "ldap_chpass_update_last_change (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> @@ -6904,7 +7209,7 @@ msgid "ldap_access_order (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap.5.xml:1470 sssd-ipa.5.xml:405 +#: sssd-ldap.5.xml:1470 sssd-ipa.5.xml:400 msgid "Comma separated list of access control options. Allowed values are:" msgstr "" @@ -6949,7 +7254,7 @@ msgid "<emphasis>expire</emphasis>: use ldap_account_expire_policy" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap.5.xml:1515 sssd-ipa.5.xml:413 +#: sssd-ldap.5.xml:1515 sssd-ipa.5.xml:408 msgid "" "<emphasis>pwd_expire_policy_reject, pwd_expire_policy_warn, " "pwd_expire_policy_renew: </emphasis> These options are useful if users are " @@ -6959,24 +7264,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap.5.xml:1525 sssd-ipa.5.xml:423 +#: sssd-ldap.5.xml:1525 sssd-ipa.5.xml:418 msgid "" "The difference between these options is the action taken if user password is " "expired:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ldap.5.xml:1530 sssd-ipa.5.xml:428 +#: sssd-ldap.5.xml:1530 sssd-ipa.5.xml:423 msgid "pwd_expire_policy_reject - user is denied to log in," msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ldap.5.xml:1536 sssd-ipa.5.xml:434 +#: sssd-ldap.5.xml:1536 sssd-ipa.5.xml:429 msgid "pwd_expire_policy_warn - user is still able to log in," msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ldap.5.xml:1542 sssd-ipa.5.xml:440 +#: sssd-ldap.5.xml:1542 sssd-ipa.5.xml:435 msgid "" "pwd_expire_policy_renew - user is prompted to change their password " "immediately." @@ -7513,8 +7818,8 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd-ldap.5.xml:2032 sssd-simple.5.xml:169 sssd-ipa.5.xml:984 -#: sssd-ad.5.xml:1470 sssd-idp.5.xml:248 sssd-krb5.5.xml:483 +#: sssd-ldap.5.xml:2032 sssd-simple.5.xml:169 sssd-ipa.5.xml:979 +#: sssd-ad.5.xml:1463 sssd-idp.5.xml:343 sssd-krb5.5.xml:483 #: sss_rpcidmapd.5.xml:98 sssd-session-recording.5.xml:176 msgid "EXAMPLE" msgstr "" @@ -7542,7 +7847,7 @@ msgstr "" #. type: Content of: <refsect1><refsect2><para> #: sssd-ldap.5.xml:2039 sssd-ldap.5.xml:2057 sssd-simple.5.xml:177 -#: sssd-ipa.5.xml:992 sssd-ad.5.xml:1478 sssd-sudo.5.xml:56 sssd-krb5.5.xml:492 +#: sssd-ipa.5.xml:987 sssd-ad.5.xml:1471 sssd-sudo.5.xml:56 sssd-krb5.5.xml:492 #: sssd-session-recording.5.xml:182 include/ldap_id_mapping.xml:105 msgid "<placeholder type=\"programlisting\" id=\"0\"/>" msgstr "<placeholder type=\"programlisting\" id=\"0\"/>" @@ -7577,7 +7882,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><title> #: sssd-ldap.5.xml:2073 sssd_krb5_locator_plugin.8.xml:83 sssd-simple.5.xml:189 -#: sssd-ad.5.xml:1493 sssd.8.xml:270 sss_seed.8.xml:163 +#: sssd-ad.5.xml:1486 sssd.8.xml:270 sss_seed.8.xml:163 msgid "NOTES" msgstr "" @@ -8084,7 +8389,7 @@ msgstr "" #: pam_sss.8.xml:434 msgid "" "No authentication method was found by Kerberos. This might happen if the " -"user has a Smartcard assigned but the pkint plugin is not available on the " +"user has a Smartcard assigned but the pkinit plugin is not available on the " "client." msgstr "" @@ -8508,6 +8813,23 @@ msgid "" "first DNS resolving failure." msgstr "" +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_locator_plugin.8.xml:106 +msgid "" +"If the environment variable SSSD_KRB5_LOCATOR_KDC_ADDRESS is set to a KDC " +"address the plugin will use this address instead of reading the kdcinfo " +"file. The address format is the same as in the kdcinfo file (see above)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_locator_plugin.8.xml:112 +msgid "" +"If the environment variable SSSD_KRB5_LOCATOR_KPASSWD_ADDRESS is set to a " +"kpasswd server address the plugin will use this address instead of reading " +"the kpasswdinfo file. The address format is the same as in the kpasswdinfo " +"file (see above)." +msgstr "" + #. type: Content of: <reference><refentry><refnamediv><refname> #: sssd-simple.5.xml:10 sssd-simple.5.xml:16 msgid "sssd-simple" @@ -9891,7 +10213,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:129 sssd-ad.5.xml:1161 +#: sssd-ipa.5.xml:129 sssd-ad.5.xml:1166 msgid "dyndns_update (boolean)" msgstr "" @@ -9905,20 +10227,13 @@ msgid "" "quote> option." msgstr "" -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:141 sssd-ad.5.xml:1175 -msgid "" -"NOTE: On older systems (such as RHEL 5), for this behavior to work reliably, " -"the default Kerberos realm must be set properly in /etc/krb5.conf" -msgstr "" - #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:152 sssd-ad.5.xml:1186 +#: sssd-ipa.5.xml:147 sssd-ad.5.xml:1186 msgid "dyndns_ttl (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:155 sssd-ad.5.xml:1189 +#: sssd-ipa.5.xml:150 sssd-ad.5.xml:1189 msgid "" "The TTL to apply to the client DNS record when updating it. If " "dyndns_update is false this has no effect. This will override the TTL " @@ -9926,17 +10241,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:160 +#: sssd-ipa.5.xml:155 msgid "Default: 1200 (seconds)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:166 sssd-ad.5.xml:1200 +#: sssd-ipa.5.xml:161 sssd-ad.5.xml:1200 msgid "dyndns_iface (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:169 sssd-ad.5.xml:1203 +#: sssd-ipa.5.xml:164 sssd-ad.5.xml:1203 msgid "" "Optional. Applicable only when dyndns_update is true. Choose the interface " "or a list of interfaces whose IP addresses should be used for dynamic DNS " @@ -9948,26 +10263,26 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:182 +#: sssd-ipa.5.xml:177 msgid "" "Default: Use the IP addresses of the interface which is used for IPA LDAP " "connection" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:186 sssd-ad.5.xml:1226 +#: sssd-ipa.5.xml:181 sssd-ad.5.xml:1220 msgid "Example: dyndns_iface = em[12], !vnet1, vnet*" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:192 sssd-ad.5.xml:1232 +#: sssd-ipa.5.xml:187 sssd-ad.5.xml:1226 #, fuzzy #| msgid "ldap_user_principal" msgid "dyndns_address (string)" msgstr "ldap_user_principal" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:195 sssd-ad.5.xml:1235 +#: sssd-ipa.5.xml:190 sssd-ad.5.xml:1229 msgid "" "Optional. Applicable only when <emphasis>dyndns_update</emphasis> is true. " "A list of IP addresses or IP networks to be used for dynamic DNS updates. " @@ -9978,22 +10293,22 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:206 sssd-ad.5.xml:1246 +#: sssd-ipa.5.xml:201 sssd-ad.5.xml:1240 msgid "Default: No filtering of IP addresses." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:209 sssd-ad.5.xml:1249 +#: sssd-ipa.5.xml:204 sssd-ad.5.xml:1243 msgid "Example: dyndns_address = 10.0.0.0/16, !10.0.1.0/24" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:215 sssd-ad.5.xml:1305 +#: sssd-ipa.5.xml:210 sssd-ad.5.xml:1298 msgid "dyndns_auth (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:218 sssd-ad.5.xml:1308 +#: sssd-ipa.5.xml:213 sssd-ad.5.xml:1301 msgid "" "Whether the nsupdate utility should use GSS-TSIG authentication for secure " "updates with the DNS server, insecure updates can be sent by setting this " @@ -10001,17 +10316,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:224 sssd-ad.5.xml:1314 +#: sssd-ipa.5.xml:219 sssd-ad.5.xml:1307 msgid "Default: GSS-TSIG" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:230 sssd-ad.5.xml:1320 +#: sssd-ipa.5.xml:225 sssd-ad.5.xml:1313 msgid "dyndns_auth_ptr (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:233 sssd-ad.5.xml:1323 +#: sssd-ipa.5.xml:228 sssd-ad.5.xml:1316 msgid "" "Whether the nsupdate utility should use GSS-TSIG authentication for secure " "PTR updates with the DNS server, insecure updates can be sent by setting " @@ -10019,17 +10334,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:239 sssd-ad.5.xml:1329 +#: sssd-ipa.5.xml:234 sssd-ad.5.xml:1322 msgid "Default: Same as dyndns_auth" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:245 sssd-ad.5.xml:1255 +#: sssd-ipa.5.xml:240 sssd-ad.5.xml:1249 msgid "dyndns_refresh_interval (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:248 +#: sssd-ipa.5.xml:243 msgid "" "How often should the back end perform periodic DNS update in addition to the " "automatic update performed when the back end goes online. This option is " @@ -10037,74 +10352,74 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:261 sssd-ad.5.xml:1273 -msgid "dyndns_update_ptr (bool)" +#: sssd-ipa.5.xml:256 sssd-ad.5.xml:1266 +msgid "dyndns_update_ptr (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:264 sssd-ad.5.xml:1276 +#: sssd-ipa.5.xml:259 sssd-ad.5.xml:1269 msgid "" "Whether the PTR record should also be explicitly updated when updating the " "client's DNS records. Applicable only when dyndns_update is true." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:269 +#: sssd-ipa.5.xml:264 msgid "" "This option should be False in most IPA deployments as the IPA server " "generates the PTR records automatically when forward records are changed." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:275 sssd-ad.5.xml:1281 +#: sssd-ipa.5.xml:270 sssd-ad.5.xml:1274 msgid "" "Note that <emphasis>dyndns_update_per_family</emphasis> parameter does not " "apply for PTR record updates. Those updates are always sent separately." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:280 +#: sssd-ipa.5.xml:275 msgid "Default: False (disabled)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:286 sssd-ad.5.xml:1292 -msgid "dyndns_force_tcp (bool)" +#: sssd-ipa.5.xml:281 sssd-ad.5.xml:1285 +msgid "dyndns_force_tcp (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:289 sssd-ad.5.xml:1295 +#: sssd-ipa.5.xml:284 sssd-ad.5.xml:1288 msgid "" "Whether the nsupdate utility should default to using TCP for communicating " "with the DNS server." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:293 sssd-ad.5.xml:1299 +#: sssd-ipa.5.xml:288 sssd-ad.5.xml:1292 msgid "Default: False (let nsupdate choose the protocol)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:299 sssd-ad.5.xml:1335 +#: sssd-ipa.5.xml:294 sssd-ad.5.xml:1328 msgid "dyndns_server (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:302 sssd-ad.5.xml:1338 +#: sssd-ipa.5.xml:297 sssd-ad.5.xml:1331 msgid "" "The DNS server to use when performing a DNS update. In most setups, it's " "recommended to leave this option unset." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:307 sssd-ad.5.xml:1343 +#: sssd-ipa.5.xml:302 sssd-ad.5.xml:1336 msgid "" "Setting this option makes sense for environments where the DNS server is " "different from the identity server or when we use encrypted DNS." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:312 sssd-ad.5.xml:1348 +#: sssd-ipa.5.xml:307 sssd-ad.5.xml:1341 msgid "" "The parameter can be a simple string containing DNS name or IP address. It " "can also be an URI. The URI can look like <emphasis>dns://servername/</" @@ -10112,7 +10427,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:319 sssd-ad.5.xml:1355 +#: sssd-ipa.5.xml:314 sssd-ad.5.xml:1348 msgid "" "The second example enables DNS-over-TLS protocol for DNS updates. The " "nsupdate utility must support DoT - check the <emphasis>man nsupdate</" @@ -10120,7 +10435,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:325 sssd-ad.5.xml:1361 +#: sssd-ipa.5.xml:320 sssd-ad.5.xml:1354 msgid "" "Please note that this option will be only used in fallback attempt when " "previous attempt using autodetected settings failed or when DNS-over-TLS is " @@ -10128,17 +10443,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:331 sssd-ad.5.xml:1367 +#: sssd-ipa.5.xml:326 sssd-ad.5.xml:1360 msgid "Default: None (let nsupdate choose the server)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:337 sssd-ad.5.xml:1373 +#: sssd-ipa.5.xml:332 sssd-ad.5.xml:1366 msgid "dyndns_update_per_family (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:340 sssd-ad.5.xml:1376 +#: sssd-ipa.5.xml:335 sssd-ad.5.xml:1369 msgid "" "DNS update is by default performed in two steps - IPv4 update and then IPv6 " "update. In some cases it might be desirable to perform IPv4 and IPv6 update " @@ -10146,12 +10461,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:352 sssd-ad.5.xml:1388 +#: sssd-ipa.5.xml:347 sssd-ad.5.xml:1381 msgid "dyndns_dot_cacert (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:355 sssd-ad.5.xml:1391 +#: sssd-ipa.5.xml:350 sssd-ad.5.xml:1384 msgid "" "This option specifies the file of the certificate authorities certificates " "(in PEM format) in order to verify the remote server TLS certificate when " @@ -10159,17 +10474,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:361 sssd-ad.5.xml:1397 +#: sssd-ipa.5.xml:356 sssd-ad.5.xml:1390 msgid "Default: None (use global certificate store)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:367 sssd-ad.5.xml:1403 +#: sssd-ipa.5.xml:362 sssd-ad.5.xml:1396 msgid "dyndns_dot_cert (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:370 sssd-ad.5.xml:1406 +#: sssd-ipa.5.xml:365 sssd-ad.5.xml:1399 msgid "" "This option sets the certificate(s) file for authentication for the DoT " "transport to the remote server. The certificate chain file is expected to be " @@ -10177,28 +10492,28 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:376 sssd-ad.5.xml:1412 +#: sssd-ipa.5.xml:371 sssd-ad.5.xml:1405 msgid "" "The <emphasis>dyndns_dot_cert</emphasis> and <emphasis>dyndns_dot_key</" "emphasis> options must be both set to achieve mutual TLS authentication." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:381 sssd-ipa.5.xml:396 sssd-ad.5.xml:1417 sssd-ad.5.xml:1432 +#: sssd-ipa.5.xml:376 sssd-ipa.5.xml:391 sssd-ad.5.xml:1410 sssd-ad.5.xml:1425 #, fuzzy #| msgid "Default: not set (use of authentication indicators is not required)" msgid "Default: None (Do not use TLS authentication)" msgstr "Oletus: ei asetettu(todennusindikaattoreiden käyttöä ei vaadita)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:387 sssd-ad.5.xml:1423 +#: sssd-ipa.5.xml:382 sssd-ad.5.xml:1416 #, fuzzy #| msgid "ldap_user_principal" msgid "dyndns_dot_key (string)" msgstr "ldap_user_principal" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:390 sssd-ad.5.xml:1426 +#: sssd-ipa.5.xml:385 sssd-ad.5.xml:1419 msgid "" "This option sets the key file for authenticated encryption for the DoT " "transport to the remote server. The private key file is expected to be in " @@ -10206,170 +10521,170 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:402 +#: sssd-ipa.5.xml:397 msgid "ipa_access_order (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:409 +#: sssd-ipa.5.xml:404 msgid "<emphasis>expire</emphasis>: use IPA's account expiration policy." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:448 +#: sssd-ipa.5.xml:443 msgid "" "Please note that 'access_provider = ipa' must be set for this feature to " "work." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:455 +#: sssd-ipa.5.xml:450 msgid "ipa_deskprofile_search_base (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:458 +#: sssd-ipa.5.xml:453 msgid "" "Optional. Use the given string as search base for Desktop Profile related " "objects." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:462 sssd-ipa.5.xml:484 +#: sssd-ipa.5.xml:457 sssd-ipa.5.xml:479 msgid "Default: Use base DN" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:468 +#: sssd-ipa.5.xml:463 msgid "ipa_subid_ranges_search_base (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:471 +#: sssd-ipa.5.xml:466 msgid "Deprecated. Use ldap_subid_ranges_search_base instead." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:477 +#: sssd-ipa.5.xml:472 msgid "ipa_hbac_search_base (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:480 +#: sssd-ipa.5.xml:475 msgid "Optional. Use the given string as search base for HBAC related objects." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:490 +#: sssd-ipa.5.xml:485 msgid "ipa_host_search_base (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:493 +#: sssd-ipa.5.xml:488 msgid "Deprecated. Use ldap_host_search_base instead." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:499 +#: sssd-ipa.5.xml:494 msgid "ipa_selinux_search_base (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:502 +#: sssd-ipa.5.xml:497 msgid "Optional. Use the given string as search base for SELinux user maps." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:518 +#: sssd-ipa.5.xml:513 msgid "ipa_subdomains_search_base (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:521 +#: sssd-ipa.5.xml:516 msgid "Optional. Use the given string as search base for trusted domains." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:530 +#: sssd-ipa.5.xml:525 msgid "Default: the value of <emphasis>cn=trusts,%basedn</emphasis>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:537 +#: sssd-ipa.5.xml:532 msgid "ipa_master_domain_search_base (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:540 +#: sssd-ipa.5.xml:535 msgid "Optional. Use the given string as search base for master domain object." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:549 +#: sssd-ipa.5.xml:544 msgid "Default: the value of <emphasis>cn=ad,cn=etc,%basedn</emphasis>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:556 +#: sssd-ipa.5.xml:551 msgid "ipa_views_search_base (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:559 +#: sssd-ipa.5.xml:554 msgid "Optional. Use the given string as search base for views containers." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:568 +#: sssd-ipa.5.xml:563 msgid "Default: the value of <emphasis>cn=views,cn=accounts,%basedn</emphasis>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:578 +#: sssd-ipa.5.xml:573 msgid "" "The name of the Kerberos realm. This is optional and defaults to the value " "of <quote>ipa_domain</quote>." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:582 +#: sssd-ipa.5.xml:577 msgid "" "The name of the Kerberos realm has a special meaning in IPA - it is " "converted into the base DN to use for performing LDAP operations." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:590 sssd-ad.5.xml:1441 +#: sssd-ipa.5.xml:585 sssd-ad.5.xml:1434 msgid "krb5_confd_path (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:593 sssd-ad.5.xml:1444 +#: sssd-ipa.5.xml:588 sssd-ad.5.xml:1437 msgid "" "Absolute path of a directory where SSSD should place Kerberos configuration " "snippets." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:597 sssd-ad.5.xml:1448 +#: sssd-ipa.5.xml:592 sssd-ad.5.xml:1441 msgid "" "To disable the creation of the configuration snippets set the parameter to " "'none'." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:601 sssd-ad.5.xml:1452 +#: sssd-ipa.5.xml:596 sssd-ad.5.xml:1445 msgid "" "Default: not set (krb5.include.d subdirectory of SSSD's pubconf directory)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:608 +#: sssd-ipa.5.xml:603 msgid "ipa_deskprofile_refresh (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:611 +#: sssd-ipa.5.xml:606 msgid "" "The amount of time between lookups of the Desktop Profile rules against the " "IPA server. This will reduce the latency and load on the IPA server if there " @@ -10377,34 +10692,34 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:618 sssd-ipa.5.xml:648 sssd-ipa.5.xml:664 sssd-ad.5.xml:600 +#: sssd-ipa.5.xml:613 sssd-ipa.5.xml:643 sssd-ipa.5.xml:659 sssd-ad.5.xml:600 msgid "Default: 5 (seconds)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:624 +#: sssd-ipa.5.xml:619 msgid "ipa_deskprofile_request_interval (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:627 +#: sssd-ipa.5.xml:622 msgid "" "The amount of time between lookups of the Desktop Profile rules against the " "IPA server in case the last request did not return any rule." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:632 +#: sssd-ipa.5.xml:627 msgid "Default: 60 (minutes)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:638 +#: sssd-ipa.5.xml:633 msgid "ipa_hbac_refresh (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:641 +#: sssd-ipa.5.xml:636 msgid "" "The amount of time between lookups of the HBAC rules against the IPA server. " "This will reduce the latency and load on the IPA server if there are many " @@ -10412,12 +10727,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:654 -msgid "ipa_hbac_selinux (integer)" -msgstr "" +#: sssd-ipa.5.xml:649 +#, fuzzy +#| msgid "memcache_size_passwd (integer)" +msgid "ipa_selinux_refresh (integer)" +msgstr "memcache_size_passwd (integeri)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:657 +#: sssd-ipa.5.xml:652 msgid "" "The amount of time between lookups of the SELinux maps against the IPA " "server. This will reduce the latency and load on the IPA server if there are " @@ -10425,33 +10742,33 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:670 +#: sssd-ipa.5.xml:665 msgid "ipa_server_mode (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:673 +#: sssd-ipa.5.xml:668 msgid "" "This option will be set by the IPA installer (ipa-server-install) " "automatically and denotes if SSSD is running on an IPA server or not." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:678 +#: sssd-ipa.5.xml:673 msgid "" "On an IPA server SSSD will lookup users and groups from trusted domains " "directly while on a client it will ask an IPA server." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:683 +#: sssd-ipa.5.xml:678 msgid "" "NOTE: There are currently some assumptions that must be met when SSSD is " "running on an IPA server." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:688 +#: sssd-ipa.5.xml:683 msgid "" "The <quote>ipa_server</quote> option must be configured to point to the IPA " "server itself. This is already the default set by the IPA installer, so no " @@ -10459,59 +10776,59 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:697 +#: sssd-ipa.5.xml:692 msgid "" "The <quote>full_name_format</quote> option must not be tweaked to only print " "short names for users from trusted domains." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:712 +#: sssd-ipa.5.xml:707 msgid "ipa_automount_location (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:715 +#: sssd-ipa.5.xml:710 msgid "The automounter location this IPA client will be using" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:718 +#: sssd-ipa.5.xml:713 msgid "Default: The location named \"default\"" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd-ipa.5.xml:726 +#: sssd-ipa.5.xml:721 msgid "VIEWS AND OVERRIDES" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:735 +#: sssd-ipa.5.xml:730 msgid "ipa_view_class (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:738 +#: sssd-ipa.5.xml:733 msgid "Objectclass of the view container." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:741 +#: sssd-ipa.5.xml:736 msgid "Default: nsContainer" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:747 +#: sssd-ipa.5.xml:742 msgid "ipa_view_name (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:750 +#: sssd-ipa.5.xml:745 msgid "Name of the attribute holding the name of the view." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:754 sssd-ldap-attributes.5.xml:496 +#: sssd-ipa.5.xml:749 sssd-ldap-attributes.5.xml:496 #: sssd-ldap-attributes.5.xml:832 sssd-ldap-attributes.5.xml:913 #: sssd-ldap-attributes.5.xml:1010 sssd-ldap-attributes.5.xml:1068 #: sssd-ldap-attributes.5.xml:1226 sssd-ldap-attributes.5.xml:1271 @@ -10519,128 +10836,128 @@ msgid "Default: cn" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:760 +#: sssd-ipa.5.xml:755 msgid "ipa_override_object_class (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:763 +#: sssd-ipa.5.xml:758 msgid "Objectclass of the override objects." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:766 +#: sssd-ipa.5.xml:761 msgid "Default: ipaOverrideAnchor" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:772 +#: sssd-ipa.5.xml:767 msgid "ipa_anchor_uuid (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:775 +#: sssd-ipa.5.xml:770 msgid "" "Name of the attribute containing the reference to the original object in a " "remote domain." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:779 +#: sssd-ipa.5.xml:774 msgid "Default: ipaAnchorUUID" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:785 +#: sssd-ipa.5.xml:780 msgid "ipa_user_override_object_class (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:788 +#: sssd-ipa.5.xml:783 msgid "" "Name of the objectclass for user overrides. It is used to determine if the " "found override object is related to a user or a group." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:793 +#: sssd-ipa.5.xml:788 msgid "User overrides can contain attributes given by" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:796 +#: sssd-ipa.5.xml:791 msgid "ldap_user_name" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:799 +#: sssd-ipa.5.xml:794 msgid "ldap_user_uid_number" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:802 +#: sssd-ipa.5.xml:797 msgid "ldap_user_gid_number" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:805 +#: sssd-ipa.5.xml:800 msgid "ldap_user_gecos" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:808 +#: sssd-ipa.5.xml:803 msgid "ldap_user_home_directory" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:811 +#: sssd-ipa.5.xml:806 msgid "ldap_user_shell" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:814 +#: sssd-ipa.5.xml:809 msgid "ldap_user_ssh_public_key" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:819 +#: sssd-ipa.5.xml:814 msgid "Default: ipaUserOverride" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:825 +#: sssd-ipa.5.xml:820 msgid "ipa_group_override_object_class (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:828 +#: sssd-ipa.5.xml:823 msgid "" "Name of the objectclass for group overrides. It is used to determine if the " "found override object is related to a user or a group." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:833 +#: sssd-ipa.5.xml:828 msgid "Group overrides can contain attributes given by" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:836 +#: sssd-ipa.5.xml:831 msgid "ldap_group_name" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:839 +#: sssd-ipa.5.xml:834 msgid "ldap_group_gid_number" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:844 +#: sssd-ipa.5.xml:839 msgid "Default: ipaGroupOverride" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:728 +#: sssd-ipa.5.xml:723 msgid "" "SSSD can handle views and overrides which are offered by FreeIPA 4.1 and " "later version. Since all paths and objectclasses are fixed on the server " @@ -10650,19 +10967,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd-ipa.5.xml:856 +#: sssd-ipa.5.xml:851 msgid "SUBDOMAINS PROVIDER" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:858 +#: sssd-ipa.5.xml:853 msgid "" "The IPA subdomains provider behaves slightly differently if it is configured " "explicitly or implicitly." msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:862 +#: sssd-ipa.5.xml:857 msgid "" "If the option 'subdomains_provider = ipa' is found in the domain section of " "sssd.conf, the IPA subdomains provider is configured explicitly, and all " @@ -10670,7 +10987,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:868 +#: sssd-ipa.5.xml:863 msgid "" "If the option 'subdomains_provider' is not set in the domain section of " "sssd.conf but there is the option 'id_provider = ipa', the IPA subdomains " @@ -10682,12 +10999,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd-ipa.5.xml:879 +#: sssd-ipa.5.xml:874 msgid "TRUSTED DOMAINS CONFIGURATION" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-ipa.5.xml:887 +#: sssd-ipa.5.xml:882 #, no-wrap msgid "" "[domain/ipa.domain.com/ad.domain.com]\n" @@ -10695,7 +11012,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:881 +#: sssd-ipa.5.xml:876 msgid "" "Some configuration options can also be set for a trusted domain. A trusted " "domain configuration can be set using the trusted domain subsection as shown " @@ -10705,97 +11022,97 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:892 +#: sssd-ipa.5.xml:887 msgid "" "For more details, see the <citerefentry> <refentrytitle>sssd.conf</" "refentrytitle> <manvolnum>5</manvolnum> </citerefentry> manual page." msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:899 +#: sssd-ipa.5.xml:894 msgid "" "Different configuration options are tunable for a trusted domain depending " "on whether you are configuring SSSD on an IPA server or an IPA client." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd-ipa.5.xml:904 +#: sssd-ipa.5.xml:899 msgid "OPTIONS TUNABLE ON IPA MASTERS" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:906 +#: sssd-ipa.5.xml:901 msgid "" "The following options can be set in a subdomain section on an IPA master:" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:910 sssd-ipa.5.xml:950 +#: sssd-ipa.5.xml:905 sssd-ipa.5.xml:945 msgid "ad_server" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:913 +#: sssd-ipa.5.xml:908 msgid "ad_backup_server" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:916 sssd-ipa.5.xml:953 +#: sssd-ipa.5.xml:911 sssd-ipa.5.xml:948 msgid "ad_site" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:919 +#: sssd-ipa.5.xml:914 msgid "ipa_server" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:922 +#: sssd-ipa.5.xml:917 msgid "ipa_backup_server" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:925 +#: sssd-ipa.5.xml:920 msgid "ldap_search_base" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:928 +#: sssd-ipa.5.xml:923 msgid "ldap_user_search_base" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:931 +#: sssd-ipa.5.xml:926 msgid "ldap_group_search_base" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:939 +#: sssd-ipa.5.xml:934 msgid "" "Options prefixed with 'ad_' or 'ipa_' only apply to their respective " "subdomain type." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd-ipa.5.xml:944 +#: sssd-ipa.5.xml:939 msgid "OPTIONS TUNABLE ON IPA CLIENTS" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:946 +#: sssd-ipa.5.xml:941 msgid "" "The following options can be set in an AD subdomain section on an IPA client:" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:958 +#: sssd-ipa.5.xml:953 msgid "" "Note that if both options are set, only <quote>ad_server</quote> is " "evaluated." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:962 +#: sssd-ipa.5.xml:957 msgid "" "Since any request for a user or a group identity from a trusted domain " "triggered from an IPA client is resolved by the IPA server, the " @@ -10809,7 +11126,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:986 +#: sssd-ipa.5.xml:981 msgid "" "The following example assumes that SSSD is correctly configured and " "example.com is one of the domains in the <replaceable>[sssd]</replaceable> " @@ -10817,7 +11134,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-ipa.5.xml:993 +#: sssd-ipa.5.xml:988 #, no-wrap msgid "" "[domain/example.com]\n" @@ -11516,27 +11833,27 @@ msgid "lxdm" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:694 +#: sssd-ad.5.xml:699 msgid "sddm" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:699 +#: sssd-ad.5.xml:704 msgid "unity" msgstr "yhtenäisyys" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:704 +#: sssd-ad.5.xml:709 msgid "xdm" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:713 +#: sssd-ad.5.xml:718 msgid "ad_gpo_map_remote_interactive (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:716 +#: sssd-ad.5.xml:721 msgid "" "A comma-separated list of PAM service names for which GPO-based access " "control is evaluated based on the RemoteInteractiveLogonRight and " @@ -11552,7 +11869,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:735 +#: sssd-ad.5.xml:740 msgid "" "Note: Using the Group Policy Management Editor this value is called \"Allow " "log on through Remote Desktop Services\" and \"Deny log on through Remote " @@ -11560,7 +11877,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:750 +#: sssd-ad.5.xml:755 #, no-wrap msgid "" "ad_gpo_map_remote_interactive = +my_pam_service, -sshd\n" @@ -11568,7 +11885,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:741 +#: sssd-ad.5.xml:746 msgid "" "It is possible to add another PAM service name to the default set by using " "<quote>+service_name</quote> or to explicitly remove a PAM service name from " @@ -11580,22 +11897,22 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:758 +#: sssd-ad.5.xml:763 msgid "sshd" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:763 +#: sssd-ad.5.xml:768 msgid "cockpit" msgstr "cockpit" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:772 +#: sssd-ad.5.xml:777 msgid "ad_gpo_map_network (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:775 +#: sssd-ad.5.xml:780 msgid "" "A comma-separated list of PAM service names for which GPO-based access " "control is evaluated based on the NetworkLogonRight and " @@ -11611,7 +11928,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:793 +#: sssd-ad.5.xml:798 msgid "" "Note: Using the Group Policy Management Editor this value is called \"Access " "this computer from the network\" and \"Deny access to this computer from the " @@ -11619,7 +11936,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:808 +#: sssd-ad.5.xml:813 #, no-wrap msgid "" "ad_gpo_map_network = +my_pam_service, -ftp\n" @@ -11627,7 +11944,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:799 +#: sssd-ad.5.xml:804 msgid "" "It is possible to add another PAM service name to the default set by using " "<quote>+service_name</quote> or to explicitly remove a PAM service name from " @@ -11639,22 +11956,22 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:816 +#: sssd-ad.5.xml:821 msgid "ftp" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:821 +#: sssd-ad.5.xml:826 msgid "samba" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:830 +#: sssd-ad.5.xml:835 msgid "ad_gpo_map_batch (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:833 +#: sssd-ad.5.xml:838 msgid "" "A comma-separated list of PAM service names for which GPO-based access " "control is evaluated based on the BatchLogonRight and DenyBatchLogonRight " @@ -11669,14 +11986,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:851 +#: sssd-ad.5.xml:856 msgid "" "Note: Using the Group Policy Management Editor this value is called \"Allow " "log on as a batch job\" and \"Deny log on as a batch job\"." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:865 +#: sssd-ad.5.xml:870 #, no-wrap msgid "" "ad_gpo_map_batch = +my_pam_service, -crond\n" @@ -11684,7 +12001,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:856 +#: sssd-ad.5.xml:861 msgid "" "It is possible to add another PAM service name to the default set by using " "<quote>+service_name</quote> or to explicitly remove a PAM service name from " @@ -11696,23 +12013,23 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:868 +#: sssd-ad.5.xml:873 msgid "" "Note: Cron service name may differ depending on Linux distribution used." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:874 +#: sssd-ad.5.xml:879 msgid "crond" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:883 +#: sssd-ad.5.xml:888 msgid "ad_gpo_map_service (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:886 +#: sssd-ad.5.xml:891 msgid "" "A comma-separated list of PAM service names for which GPO-based access " "control is evaluated based on the ServiceLogonRight and " @@ -11728,14 +12045,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:904 +#: sssd-ad.5.xml:909 msgid "" "Note: Using the Group Policy Management Editor this value is called \"Allow " "log on as a service\" and \"Deny log on as a service\"." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:917 +#: sssd-ad.5.xml:922 #, no-wrap msgid "" "ad_gpo_map_service = +my_pam_service\n" @@ -11743,7 +12060,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:909 sssd-ad.5.xml:984 +#: sssd-ad.5.xml:914 sssd-ad.5.xml:989 msgid "" "It is possible to add a PAM service name to the default set by using " "<quote>+service_name</quote>. Since the default set is empty, it is not " @@ -11754,19 +12071,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:927 +#: sssd-ad.5.xml:932 msgid "ad_gpo_map_permit (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:930 +#: sssd-ad.5.xml:935 msgid "" "A comma-separated list of PAM service names for which GPO-based access is " "always granted, regardless of any GPO Logon Rights." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:944 +#: sssd-ad.5.xml:949 #, no-wrap msgid "" "ad_gpo_map_permit = +my_pam_service, -sudo\n" @@ -11774,7 +12091,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:935 +#: sssd-ad.5.xml:940 msgid "" "It is possible to add another PAM service name to the default set by using " "<quote>+service_name</quote> or to explicitly remove a PAM service name from " @@ -11786,29 +12103,29 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:952 +#: sssd-ad.5.xml:957 msgid "polkit-1" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:967 +#: sssd-ad.5.xml:972 msgid "systemd-user" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:976 +#: sssd-ad.5.xml:981 msgid "ad_gpo_map_deny (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:979 +#: sssd-ad.5.xml:984 msgid "" "A comma-separated list of PAM service names for which GPO-based access is " "always denied, regardless of any GPO Logon Rights." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:992 +#: sssd-ad.5.xml:997 #, no-wrap msgid "" "ad_gpo_map_deny = +my_pam_service\n" @@ -11816,12 +12133,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:1002 +#: sssd-ad.5.xml:1007 msgid "ad_gpo_default_right (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1005 +#: sssd-ad.5.xml:1010 msgid "" "This option defines how access control is evaluated for PAM service names " "that are not explicitly listed in one of the ad_gpo_map_* options. This " @@ -11834,52 +12151,52 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1018 +#: sssd-ad.5.xml:1023 msgid "Supported values for this option include:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1027 +#: sssd-ad.5.xml:1032 msgid "remote_interactive" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1032 +#: sssd-ad.5.xml:1037 msgid "network" msgstr "verkko" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1037 +#: sssd-ad.5.xml:1042 msgid "batch" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1042 +#: sssd-ad.5.xml:1047 msgid "service" msgstr "palvelu" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1047 +#: sssd-ad.5.xml:1052 msgid "permit" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1052 +#: sssd-ad.5.xml:1057 msgid "deny" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1058 +#: sssd-ad.5.xml:1063 msgid "Default: deny" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:1064 +#: sssd-ad.5.xml:1069 msgid "ad_maximum_machine_account_password_age (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1067 +#: sssd-ad.5.xml:1072 msgid "" "SSSD will check once a day if the machine account password is older than the " "given age in days and try to renew it. A value of 0 will disable the renewal " @@ -11887,17 +12204,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1073 +#: sssd-ad.5.xml:1078 msgid "Default: 30 days" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:1079 +#: sssd-ad.5.xml:1084 msgid "ad_machine_account_password_renewal_opts (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1082 +#: sssd-ad.5.xml:1087 msgid "" "This option should only be used to test the machine account renewal task. " "The option expects 3 integers and a string separated by a colon (':'). The " @@ -11910,20 +12227,20 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1096 +#: sssd-ad.5.xml:1101 msgid "" "The optional fourth string value identifies the helper binary which should " "be used for the renewal. Currently <command>adcli</command> and " "<command>realm</command> are supported. If this value is missing or empty in " "the value string <command>realm</command> will be used. Since the helper is " "started as the user SSSD is running as there might be the chance that the " -"renewal will fail if this user does not has permissions to modify the keytab " -"file where the machine account credentials are stored. This will typically " -"be the case for <command>adcli</command>." +"renewal will fail if this user does not have permissions to modify the " +"keytab file where the machine account credentials are stored. This will " +"typically be the case for <command>adcli</command>." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1110 +#: sssd-ad.5.xml:1115 msgid "" "<command>realm</command> is not updating the keytab directly but is calling " "the <command>realmd</command> process, which runs as root user, for this " @@ -11933,17 +12250,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1119 +#: sssd-ad.5.xml:1124 msgid "Default: 86400:750:300:realm (24h, 12m30s and 5m)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:1125 +#: sssd-ad.5.xml:1130 msgid "ad_update_samba_machine_account_password (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1128 +#: sssd-ad.5.xml:1133 msgid "" "If enabled, when SSSD renews the machine account password, it will also be " "updated in Samba's database. This prevents Samba's copy of the machine " @@ -11952,23 +12269,23 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:1141 -msgid "ad_use_ldaps (bool)" +#: sssd-ad.5.xml:1146 +msgid "ad_use_ldaps (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1144 +#: sssd-ad.5.xml:1149 msgid "" "By default SSSD uses the plain LDAP port 389 and the Global Catalog port " -"3628. If this option is set to True SSSD will use the LDAPS port 636 and " -"Global Catalog port 3629 with LDAPS protection. Since AD does not allow to " +"3268. If this option is set to True SSSD will use the LDAPS port 636 and " +"Global Catalog port 3269 with LDAPS protection. Since AD does not allow to " "have multiple encryption layers on a single connection and we still want to " "use SASL/GSSAPI or SASL/GSS-SPNEGO for authentication the SASL security " "property maxssf is set to 0 (zero) for those connections." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1164 +#: sssd-ad.5.xml:1169 msgid "" "Optional. This option tells SSSD to automatically update the Active " "Directory DNS server with the IP address of this client. The update is " @@ -11986,30 +12303,21 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:1216 msgid "" -"NOTE: While it is still possible to use the old <emphasis>ipa_dyndns_iface</" -"emphasis> option, users should migrate to using <emphasis>dyndns_iface</" -"emphasis> in their config file." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1222 -msgid "" "Default: Use the IP addresses of the interface which is used for AD LDAP " "connection" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1258 +#: sssd-ad.5.xml:1252 msgid "" "How often should the back end perform periodic DNS update in addition to the " -"automatic update performed when the back end goes online. This option is " -"optional and applicable only when dyndns_update is true. Note that the " -"lowest possible value is 60 seconds in-case if value is provided less than " -"60, parameter will assume lowest value only." +"automatic update performed when the back end goes online. This is optional " +"and applicable only when dyndns_update is true. Note that the minimum value " +"is 60 seconds, any specified value below this threshold will default to 60." msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ad.5.xml:1472 +#: sssd-ad.5.xml:1465 msgid "" "The following example assumes that SSSD is correctly configured and " "example.com is one of the domains in the <replaceable>[sssd]</replaceable> " @@ -12017,7 +12325,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-ad.5.xml:1479 +#: sssd-ad.5.xml:1472 #, no-wrap msgid "" "[domain/EXAMPLE]\n" @@ -12032,7 +12340,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-ad.5.xml:1499 +#: sssd-ad.5.xml:1492 #, no-wrap msgid "" "access_provider = ldap\n" @@ -12041,7 +12349,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ad.5.xml:1495 +#: sssd-ad.5.xml:1488 msgid "" "The AD access control provider checks if the account is expired. It has the " "same effect as the following configuration of the LDAP provider: " @@ -12049,7 +12357,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ad.5.xml:1505 +#: sssd-ad.5.xml:1498 msgid "" "However, unless the <quote>ad</quote> access control provider is explicitly " "configured, the default access provider is <quote>permit</quote>. Please " @@ -12059,7 +12367,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ad.5.xml:1513 +#: sssd-ad.5.xml:1506 msgid "" "When the autofs provider is set to <quote>ad</quote>, the RFC2307 schema " "attribute mapping (nisMap, nisObject, ...) is used, because these attributes " @@ -12213,9 +12521,9 @@ msgstr "" #: sssd-sudo.5.xml:137 msgid "" "The <emphasis>smart refresh</emphasis> periodically downloads rules that are " -"new or were modified after the last update. Its primary goal is to keep the " -"database growing by fetching only small increments that do not generate " -"large amounts of network traffic." +"new or were modified after the last update. Its primary goal is to grow the " +"database incrementally by fetching only small updates, avoiding large " +"amounts of network traffic." msgstr "" #. type: Content of: <reference><refentry><refsect1><para> @@ -12397,24 +12705,27 @@ msgstr "" msgid "" "Depending on the IdP product additional platform specific options might " "follow the name separated by a colon (:). E.g. for Keycloak the base URI for " -"the user and group REST API must be given. For Entra ID this is not needed " -"because there is a generic endpoint for all tenants." +"the user and group REST API must be given. For Entra ID the base URI for the " +"Microsoft Graph API can be given to use sovereign or government cloud " +"endpoints instead of the default (https://graph.microsoft.com/v1.0). E.g. " +"<quote>entra_id:https://graph.microsoft.us/v1.0</quote> for the US " +"government cloud (GCC High)." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:78 sssd-idp.5.xml:94 sssd-idp.5.xml:119 +#: sssd-idp.5.xml:82 sssd-idp.5.xml:98 sssd-idp.5.xml:123 #, fuzzy #| msgid "Default: Not set" msgid "Default: Not set (Required)" msgstr "Oletus: ei asetettu" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:83 +#: sssd-idp.5.xml:87 msgid "idp_client_id (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:86 +#: sssd-idp.5.xml:90 msgid "" "ID of the IdP client used by SSSD to authenticate users and as a client to " "lookup user and group attributes. This client must offer device " @@ -12423,14 +12734,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:99 +#: sssd-idp.5.xml:103 #, fuzzy #| msgid "ldap_user_principal" msgid "idp_client_secret (string)" msgstr "ldap_user_principal" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:102 +#: sssd-idp.5.xml:106 msgid "" "Password of the IdP client. The password is required for the id_provider. If " "only used as auth_provider it depends on the server side configuration if it " @@ -12438,74 +12749,81 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:113 +#: sssd-idp.5.xml:117 msgid "idp_token_endpoint (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:116 +#: sssd-idp.5.xml:120 msgid "IdP endpoint for requesting access tokens." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:124 +#: sssd-idp.5.xml:128 #, fuzzy #| msgid "ldap_user_principal" msgid "idp_device_auth_endpoint (string)" msgstr "ldap_user_principal" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:127 +#: sssd-idp.5.xml:131 msgid "" "IdP endpoint for device authorization according to RFC-8628. This is " "required for user authentication." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:137 +#: sssd-idp.5.xml:141 #, fuzzy #| msgid "ldap_user_principal" msgid "idp_userinfo_endpoint (string)" msgstr "ldap_user_principal" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:140 +#: sssd-idp.5.xml:144 msgid "" "IdP userinfo endpoint to request user attributes after a successful " "authentication of the user. Required for authentication." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:150 +#: sssd-idp.5.xml:154 #, fuzzy #| msgid "ldap_user_principal" msgid "idp_id_scope (string)" msgstr "ldap_user_principal" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:153 +#: sssd-idp.5.xml:157 msgid "" "Scope required for looking up user and group attributes with the REST API. " "The scopes are used by the server to determine which attributes/claims are " "returned to the caller." msgstr "" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:163 +msgid "" +"Note: In previous versions of SSSD, this option was expected to already be " +"URL-encoded." +msgstr "" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:164 +#: sssd-idp.5.xml:172 #, fuzzy #| msgid "ldap_user_principal" msgid "idp_auth_scope (string)" msgstr "ldap_user_principal" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:167 +#: sssd-idp.5.xml:175 msgid "" "Scope required during authentication. The scopes are used by the server to " "determine which attributes/claims are returned to the caller." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:172 +#: sssd-idp.5.xml:180 msgid "" "Currently the tokens returned during user authentication are not used for " "other purposes hence the only important claim is the subject identifier " @@ -12514,26 +12832,122 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:185 +#: sssd-idp.5.xml:193 +#, fuzzy +#| msgid "ldap_user_principal" +msgid "idp_auth_user_identifier_attr (string)" +msgstr "ldap_user_principal" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:196 +msgid "" +"Attribute used to identify the authenticated user in userinfo data or token " +"claims." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:200 +msgid "" +"For hybrid Active Directory and Entra ID deployments where " +"<quote>id_provider = ad</quote> and <quote>auth_provider = idp</quote>, this " +"option must be set explicitly. No value is derived from the identity " +"provider, because more than one attribute can link an Entra ID object to its " +"on-premises counterpart and only the administrator knows which one the " +"directory synchronization is configured to use." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:211 +msgid "" +"Setting this option to <quote>onPremisesImmutableId</quote> is the usual " +"choice for such deployments. Microsoft Entra Connect populates that " +"attribute with the base64-encoded form of the 16-byte Active Directory " +"<quote>objectGUID</quote> when objectGUID is used as the sourceAnchor. SSSD " +"decodes the value and converts the raw bytes with the same conversion used " +"for AD objectGUID attributes, so the result matches the UUID stored in the " +"SSSD cache for the AD user." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:224 +msgid "" +"Note that Microsoft Entra Connect 1.1.524.0 and later use <quote>ms-DS-" +"ConsistencyGuid</quote> as the sourceAnchor for user objects instead of " +"<quote>objectGUID</quote>. The value is normally copied from objectGUID for " +"objects that do not have it set yet, in which case the decoded identifier " +"still matches. It does not match if ms-DS-ConsistencyGuid was populated " +"independently, if users were moved between forests or domains, or if a " +"different attribute such as employeeID was selected as the sourceAnchor. See " +"<ulink url=\"https://learn.microsoft.com/en-us/entra/identity/hybrid/connect/" +"plan-connect-design-concepts\"> Microsoft Entra Connect: Design concepts</" +"ulink> for details on sourceAnchor selection." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:241 +msgid "" +"Microsoft Graph does not return <quote>onPremisesImmutableId</quote> by " +"default. The <quote>idp_userinfo_endpoint</quote> must request it with " +"<quote>$select</quote>, see the example below and <ulink url=\"https://" +"learn.microsoft.com/en-us/graph/api/resources/user\"> the Microsoft Graph " +"user resource type</ulink>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:251 +msgid "" +"If the configured attribute is missing or cannot be decoded (for example " +"cloud-only Entra ID users without <quote>onPremisesImmutableId</quote>), " +"authentication fails. SSSD does not fall back to another attribute when this " +"option is set." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:258 +msgid "" +"Default: not set, <quote>sub</quote> for Keycloak and <quote>id</quote> for " +"other IdP types" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-idp.5.xml:264 #, fuzzy #| msgid "ad_gpo_cache_timeout (integer)" msgid "idp_request_timeout (integer)" msgstr "ad_gpo_cache_timeout (integeri)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:188 +#: sssd-idp.5.xml:267 msgid "Timeout in seconds for an individual request to the IdP." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:197 +#: sssd-idp.5.xml:276 +msgid "idp_auto_refresh (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:279 +msgid "" +"Refresh tokens automatically, after they have reached about half their " +"lifetime." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:283 +msgid "" +"Note: Scheduled token refreshes are not preserved across restarts of SSSD." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-idp.5.xml:292 #, fuzzy #| msgid "ad_gpo_cache_timeout (integer)" msgid "idmap_range_min (integer)" msgstr "ad_gpo_cache_timeout (integeri)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:200 +#: sssd-idp.5.xml:295 msgid "" "Specifies the lower (inclusive) bound of the range of POSIX IDs to use for " "mapping IdP users and group to POSIX IDs. It is the first POSIX ID which can " @@ -12541,7 +12955,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:206 +#: sssd-idp.5.xml:301 msgid "" "The interval between <quote>idmap_range_min</quote> and " "<quote>idmap_range_max</quote> will be split into smaller ranges of size " @@ -12550,20 +12964,20 @@ msgid "" msgstr "" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:213 sssd-idp.5.xml:239 include/ldap_id_mapping.xml:139 +#: sssd-idp.5.xml:308 sssd-idp.5.xml:334 include/ldap_id_mapping.xml:139 #: include/ldap_id_mapping.xml:197 msgid "Default: 200000" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:218 +#: sssd-idp.5.xml:313 #, fuzzy #| msgid "offline_timeout_max (integer)" msgid "idmap_range_max (integer)" msgstr "offline_timeout_max (integeri)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:221 +#: sssd-idp.5.xml:316 msgid "" "Specifies the upper (exclusive) bound of the range of POSIX IDs to use for " "mapping IdP users and groups to POSIX IDs. It is the first POSIX ID which " @@ -12571,47 +12985,70 @@ msgid "" msgstr "" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:227 include/ldap_id_mapping.xml:165 +#: sssd-idp.5.xml:322 include/ldap_id_mapping.xml:165 msgid "Default: 2000200000" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:232 +#: sssd-idp.5.xml:327 #, fuzzy #| msgid "memcache_size_passwd (integer)" msgid "idmap_range_size (integer)" msgstr "memcache_size_passwd (integeri)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:235 +#: sssd-idp.5.xml:330 msgid "Specifies the number of POSIX IDs available for a single IdP domain." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-idp.5.xml:251 +#: sssd-idp.5.xml:346 #, no-wrap msgid "" "[domain/entra_id]\n" "id_provider = idp\n" "idp_type = entra_id\n" "idp_client_id = 12345678-abcd-0101-efef-ba9876543210\n" -"idp_client_secret = YOUR-CLIENT-SCERET\n" -"idp_token_endpoint = https://login.microsoftonline.com/TENNANT-ID/oauth2/v2.0/token\n" +"idp_client_secret = YOUR-CLIENT-SECRET\n" +"idp_token_endpoint = https://login.microsoftonline.com/TENANT-ID/oauth2/v2.0/token\n" "idp_userinfo_endpoint = https://graph.microsoft.com/v1.0/me\n" -"idp_device_auth_endpoint = https://login.microsoftonline.com/TENNANT-ID/oauth2/v2.0/devicecode\n" -"idp_id_scope = https%3A%2F%2Fgraph.microsoft.com%2F.default\n" +"idp_device_auth_endpoint = https://login.microsoftonline.com/TENANT-ID/oauth2/v2.0/devicecode\n" +"idp_id_scope = https://graph.microsoft.com/.default\n" +"idp_auth_scope = openid profile email\n" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><programlisting> +#: sssd-idp.5.xml:358 +#, no-wrap +msgid "" +"[domain/ad.example.com]\n" +"id_provider = ad\n" +"auth_provider = idp\n" +"access_provider = permit\n" +"\n" +"ad_domain = ad.example.com\n" +"krb5_realm = AD.EXAMPLE.COM\n" +"\n" +"idp_type = entra_id\n" +"idp_client_id = 12345678-abcd-0101-efef-ba9876543210\n" +"idp_client_secret = YOUR-CLIENT-SECRET\n" +"idp_token_endpoint = https://login.microsoftonline.com/TENANT-ID/oauth2/v2.0/token\n" +"idp_userinfo_endpoint = https://graph.microsoft.com/v1.0/me?$select=id,userPrincipalName,onPremisesImmutableId\n" +"idp_device_auth_endpoint = https://login.microsoftonline.com/TENANT-ID/oauth2/v2.0/devicecode\n" +"idp_id_scope = https://graph.microsoft.com/.default\n" "idp_auth_scope = openid profile email\n" +"idp_auth_user_identifier_attr = onPremisesImmutableId\n" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-idp.5.xml:263 +#: sssd-idp.5.xml:377 #, no-wrap msgid "" "[domain/keycloak]\n" "idp_type = keycloak:https://master.keycloak.test:8443/auth/admin/realms/master/\n" "id_provider = idp\n" "idp_client_id = myclient\n" -"idp_client_secret = YOUR-CLIENT-SCERET\n" +"idp_client_secret = YOUR-CLIENT-SECRET\n" "idp_token_endpoint = https://master.keycloak.test:8443/auth/realms/master/protocol/openid-connect/token\n" "idp_userinfo_endpoint = https://master.keycloak.test:8443/auth/realms/master/protocol/openid-connect/userinfo\n" "idp_device_auth_endpoint = https://master.keycloak.test:8443/auth/realms/master/protocol/openid-connect/auth/device\n" @@ -12620,14 +13057,26 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-idp.5.xml:250 +#: sssd-idp.5.xml:345 #, fuzzy #| msgid "example: <placeholder type=\"programlisting\" id=\"0\"/>" msgid "" "<placeholder type=\"programlisting\" id=\"0\"/> <placeholder " -"type=\"programlisting\" id=\"1\"/>" +"type=\"programlisting\" id=\"1\"/> <placeholder type=\"programlisting\" " +"id=\"2\"/>" msgstr "Esimerkki: <placeholder type=\"programlisting\" id=\"0\"/>" +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-idp.5.xml:390 +msgid "" +"In the hybrid Active Directory and Entra ID example above, " +"<quote>onPremisesImmutableId</quote> is used during authentication so the " +"IdP result matches the AD objectGUID UUID stored in the SSSD cache. The " +"attribute must be requested via <quote>$select</quote> on the Graph userinfo " +"endpoint and is only populated for users synchronized from Active Directory " +"with objectGUID as the sourceAnchor." +msgstr "" + #. type: Content of: <reference><refentry><refnamediv><refname> #: sssd.8.xml:10 sssd.8.xml:15 msgid "sssd" @@ -13591,7 +14040,7 @@ msgstr "" #: sssd-krb5.5.xml:291 msgid "" "<emphasis>demand</emphasis> to use FAST. The authentication fails if the " -"server does not require fast." +"server does not support FAST." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> @@ -14480,7 +14929,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sss_rpcidmapd.5.xml:69 -msgid "memcache (bool)" +msgid "memcache (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> @@ -14534,7 +14983,7 @@ msgid "" msgstr "" #. type: Content of: <refsect1><title> -#: sss_rpcidmapd.5.xml:120 sssd-kcm.8.xml:316 include/seealso.xml:2 +#: sss_rpcidmapd.5.xml:120 sssd-kcm.8.xml:315 include/seealso.xml:2 msgid "SEE ALSO" msgstr "" @@ -14761,8 +15210,8 @@ msgstr "" #: sss_ssh_knownhosts.1.xml:93 msgid "" "The key lines retrieved from the backend are expected to respect the key " -"format as decribed in the <quote>SSH_KNOWN_HOSTS FILE FORMAT</quote> section " -"of <citerefentry><refentrytitle>sshd</refentrytitle> <manvolnum>8</" +"format as described in the <quote>SSH_KNOWN_HOSTS FILE FORMAT</quote> " +"section of <citerefentry><refentrytitle>sshd</refentrytitle> <manvolnum>8</" "manvolnum></citerefentry>. However, returning only the keytype and the key " "itself is tolerated, in which case, the hostname received as parameter will " "be added before the keytype to output a correctly formatted line. The " @@ -15238,14 +15687,13 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-kcm.8.xml:215 msgid "" -"The KCM service is configured in the <quote>kcm</quote> For a detailed " -"syntax reference, refer to the <quote>FILE FORMAT</quote> section of the " -"<citerefentry> <refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</" -"manvolnum> </citerefentry> manual page." +"For a detailed syntax reference, refer to the <quote>FILE FORMAT</quote> " +"section of the <citerefentry> <refentrytitle>sssd.conf</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry> manual page." msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-kcm.8.xml:223 +#: sssd-kcm.8.xml:222 msgid "" "The generic SSSD service options such as <quote>debug_level</quote> or " "<quote>fd_limit</quote> are accepted by the kcm service. Please refer to " @@ -15255,22 +15703,22 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:234 +#: sssd-kcm.8.xml:233 msgid "socket_path (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:237 +#: sssd-kcm.8.xml:236 msgid "The socket the KCM service will listen on." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:240 +#: sssd-kcm.8.xml:239 msgid "Default: <replaceable>/var/run/.heim_org.h5l.kcm-socket</replaceable>" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:243 +#: sssd-kcm.8.xml:242 msgid "" "<phrase condition=\"have_systemd\"> Note: on platforms where systemd is " "supported, the socket path is overwritten by the one defined in the sssd-" @@ -15278,86 +15726,86 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:252 +#: sssd-kcm.8.xml:251 msgid "max_ccaches (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:255 +#: sssd-kcm.8.xml:254 msgid "How many credential caches does the KCM database allow for all users." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:259 +#: sssd-kcm.8.xml:258 msgid "Default: 0 (unlimited, only the per-UID quota is enforced)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:264 +#: sssd-kcm.8.xml:263 msgid "max_uid_ccaches (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:267 +#: sssd-kcm.8.xml:266 msgid "" "How many credential caches does the KCM database allow per UID. This is " "equivalent to <quote>with how many principals you can kinit</quote>." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:272 +#: sssd-kcm.8.xml:271 msgid "Default: 64" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:277 +#: sssd-kcm.8.xml:276 msgid "max_ccache_size (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:280 +#: sssd-kcm.8.xml:279 msgid "" -"How big can a credential cache be per ccache. Each service ticket accounts " -"into this quota." +"How big a credential cache be per ccache. Each service ticket counts toward " +"this quota." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:284 +#: sssd-kcm.8.xml:283 msgid "Default: 65536" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:289 -msgid "tgt_renewal (bool)" +#: sssd-kcm.8.xml:288 +msgid "tgt_renewal (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:292 +#: sssd-kcm.8.xml:291 msgid "Enables TGT renewals functionality." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:295 +#: sssd-kcm.8.xml:294 msgid "Default: False (Automatic renewals disabled)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:300 +#: sssd-kcm.8.xml:299 msgid "tgt_renewal_inherit (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:303 +#: sssd-kcm.8.xml:302 msgid "Domain to inherit krb5_* options from, for use with TGT renewals." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:307 +#: sssd-kcm.8.xml:306 msgid "Default: NULL" msgstr "Oletus: NULL" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-kcm.8.xml:318 +#: sssd-kcm.8.xml:317 msgid "" "<citerefentry> <refentrytitle>sssd</refentrytitle><manvolnum>8</manvolnum> </" "citerefentry>, <citerefentry> <refentrytitle>sssd.conf</" @@ -16261,8 +16709,8 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap-attributes.5.xml:381 sssd-ldap-attributes.5.xml:395 -msgid "Default: loginDisabled" +#: sssd-ldap-attributes.5.xml:381 +msgid "Default: loginDisabled (rfc2307, rfc2307bis and IPA), not set (AD)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> @@ -16277,6 +16725,12 @@ msgid "" "which date access is granted." msgstr "" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:395 +msgid "" +"Default: loginExpirationTime (rfc2307, rfc2307bis and IPA), not set (AD)" +msgstr "" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:401 msgid "ldap_user_nds_login_allowed_time_map (string)" @@ -16291,7 +16745,8 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:409 -msgid "Default: loginAllowedTimeMap" +msgid "" +"Default: loginAllowedTimeMap (rfc2307, rfc2307bis and IPA), not set (AD)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> @@ -16807,8 +17262,8 @@ msgid "The object class of a host entry in LDAP." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap-attributes.5.xml:900 sssd-ldap-attributes.5.xml:997 -msgid "Default: ipService" +#: sssd-ldap-attributes.5.xml:900 sssd-ldap-attributes.5.xml:1213 +msgid "Default: ipHost" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> @@ -16893,6 +17348,11 @@ msgstr "" msgid "The object class of a service entry in LDAP." msgstr "" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:997 +msgid "Default: ipService" +msgstr "" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1003 msgid "ldap_service_name (string)" @@ -17133,11 +17593,6 @@ msgstr "" msgid "The object class of an iphost entry in LDAP." msgstr "" -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap-attributes.5.xml:1213 -msgid "Default: ipHost" -msgstr "" - #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1219 msgid "ldap_iphost_name (string)" @@ -17381,6 +17836,7 @@ msgstr "" msgid "" "[plugins]\n" " localauth = {\n" +" disable = an2ln\n" " module = sssd:/usr/lib64/sssd/modules/sssd_krb5_localauth_plugin.so\n" " }\n" msgstr "" @@ -17397,6 +17853,28 @@ msgid "" "the local Kerberos configuration the plugin will be enabled automatically." msgstr "" +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_localauth_plugin.8.xml:67 +msgid "" +"This configuration snippet also disables the <command>an2ln</command> module " +"provided by MIT Kerberos if SSSD is configured to use the AD or IPA " +"provider. In those environments <command>sssd_krb5_localauth_plugin</" +"command> can reliably map the system user names to Kerberos principals. A " +"fallback to <command>an2ln</command> might cause issues in environments " +"where users have the privilege to create Kerberos principals on their own " +"which might collide with names of other users used in the system. Other " +"modules provided by MIT Kerberos, e.g. <command>k5login</command> are not " +"affected." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_localauth_plugin.8.xml:79 +msgid "" +"Note: If using <quote>auth_provider = krb5</quote> then " +"<command>sssd_krb5_localauth_plugin</command> is not used, therefore the " +"above text is not applicable." +msgstr "" + #. type: Content of: <variablelist><varlistentry><term> #: include/autofs_attributes.xml:3 msgid "ldap_autofs_map_object_class (string)" @@ -18256,30 +18734,6 @@ msgid "" "failures; corresponds to setting 2 in decimal notation)" msgstr "" -#. type: Content of: <refsect1><title> -#: include/local.xml:2 -msgid "THE LOCAL DOMAIN" -msgstr "" - -#. type: Content of: <refsect1><para> -#: include/local.xml:4 -msgid "" -"In order to function correctly, a domain with <quote>id_provider=local</" -"quote> must be created and the SSSD must be running." -msgstr "" - -#. type: Content of: <refsect1><para> -#: include/local.xml:9 -msgid "" -"The administrator might want to use the SSSD local users instead of " -"traditional UNIX users in cases where the group nesting (see <citerefentry> " -"<refentrytitle>sss_groupadd</refentrytitle> <manvolnum>8</manvolnum> </" -"citerefentry>) is needed. The local users are also useful for testing and " -"development of the SSSD without having to deploy a full remote server. The " -"<command>sss_user*</command> and <command>sss_group*</command> tools use a " -"local LDB storage to store users and groups." -msgstr "" - #. type: Content of: <refsect1><para> #: include/seealso.xml:4 msgid "" @@ -18885,6 +19339,18 @@ msgid "" "feature is available with MIT Kerberos 1.7 and later versions." msgstr "" +#~ msgid "services" +#~ msgstr "palvelut" + +#~ msgid "domains" +#~ msgstr "toimialueet" + +#~ msgid "fd_limit" +#~ msgstr "fd_limit" + +#~ msgid "client_idle_timeout" +#~ msgstr "client_idle_timeout" + #~ msgid "all" #~ msgstr "kaikki" diff --git a/src/man/po/fr.po b/src/man/po/fr.po index 9f2b52f3d3e..e86b33a5dc7 100644 --- a/src/man/po/fr.po +++ b/src/man/po/fr.po @@ -17,9 +17,9 @@ msgid "" msgstr "" "Project-Id-Version: sssd-docs 2.3.0\n" "Report-Msgid-Bugs-To: sssd-devel@redhat.com\n" -"POT-Creation-Date: 2026-01-14 15:00+0000\n" -"PO-Revision-Date: 2026-04-23 16:29+0000\n" -"Last-Translator: Anonymous <noreply@weblate.org>\n" +"POT-Creation-Date: 2026-10-05 16:14+0000\n" +"PO-Revision-Date: 2026-10-05 16:55+0000\n" +"Last-Translator: red max <redmax761@gmail.com>\n" "Language-Team: French <https://translate.fedoraproject.org/projects/sssd/" "sssd-manpage-master/fr/>\n" "Language: fr\n" @@ -27,10 +27,10 @@ msgstr "" "Content-Type: text/plain; charset=UTF-8\n" "Content-Transfer-Encoding: 8bit\n" "Plural-Forms: nplurals=2; plural=n > 1;\n" -"X-Generator: Weblate 5.17\n" +"X-Generator: Weblate 2026.10\n" #. type: Content of: <reference><title> -#: sssd.conf.5.xml:8 sssd-ldap.5.xml:5 pam_sss.8.xml:5 pam_sss_gss.8.xml:5 +#: sssd.conf.5.xml:10 sssd-ldap.5.xml:5 pam_sss.8.xml:5 pam_sss_gss.8.xml:5 #: sssd_krb5_locator_plugin.8.xml:5 sssd-simple.5.xml:5 sss-certmap.5.xml:5 #: sssd-ipa.5.xml:5 sssd-ad.5.xml:5 sssd-sudo.5.xml:5 sssd-idp.5.xml:5 #: sssd.8.xml:5 sss_obfuscate.8.xml:5 sss_override.8.xml:5 sssd-krb5.5.xml:5 @@ -43,12 +43,12 @@ msgid "SSSD Manual pages" msgstr "Pages de manuel de SSSD" #. type: Content of: <reference><refentry><refnamediv><refname> -#: sssd.conf.5.xml:13 sssd.conf.5.xml:19 +#: sssd.conf.5.xml:15 sssd.conf.5.xml:21 msgid "sssd.conf" msgstr "sssd.conf" #. type: Content of: <reference><refentry><refmeta><manvolnum> -#: sssd.conf.5.xml:14 sssd-ldap.5.xml:11 sssd-simple.5.xml:11 +#: sssd.conf.5.xml:16 sssd-ldap.5.xml:11 sssd-simple.5.xml:11 #: sss-certmap.5.xml:11 sssd-ipa.5.xml:11 sssd-ad.5.xml:11 sssd-sudo.5.xml:11 #: sssd-idp.5.xml:11 sssd-krb5.5.xml:11 sssd-ifp.5.xml:11 #: sss_rpcidmapd.5.xml:27 sssd-session-recording.5.xml:11 @@ -57,7 +57,7 @@ msgid "5" msgstr "5" #. type: Content of: <reference><refentry><refmeta><refmiscinfo> -#: sssd.conf.5.xml:15 sssd-ldap.5.xml:12 sssd-simple.5.xml:12 +#: sssd.conf.5.xml:17 sssd-ldap.5.xml:12 sssd-simple.5.xml:12 #: sss-certmap.5.xml:12 sssd-ipa.5.xml:12 sssd-ad.5.xml:12 sssd-sudo.5.xml:12 #: sssd-idp.5.xml:12 sssd-krb5.5.xml:12 sssd-ifp.5.xml:12 #: sss_rpcidmapd.5.xml:28 sssd-session-recording.5.xml:12 sssd-kcm.8.xml:12 @@ -66,17 +66,17 @@ msgid "File Formats and Conventions" msgstr "Formats de fichier et conventions" #. type: Content of: <reference><refentry><refnamediv><refpurpose> -#: sssd.conf.5.xml:20 +#: sssd.conf.5.xml:22 msgid "the configuration file for SSSD" msgstr "Le fichier de configuration pour SSSD" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:24 +#: sssd.conf.5.xml:26 msgid "FILE FORMAT" msgstr "FORMAT DE FICHIER" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd.conf.5.xml:32 +#: sssd.conf.5.xml:34 #, no-wrap msgid "" "<replaceable>[section]</replaceable>\n" @@ -90,7 +90,7 @@ msgstr "" " " #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:27 +#: sssd.conf.5.xml:29 msgid "" "The file has an ini-style syntax and consists of sections and parameters. A " "section begins with the name of the section in square brackets and continues " @@ -104,24 +104,26 @@ msgstr "" "type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:39 +#: sssd.conf.5.xml:41 msgid "" -"The data types used are string (no quotes needed), integer and bool (with " -"values of <quote>TRUE/FALSE</quote>)." +"The data types used are string (no quotes needed), integer and boolean (with " +"values of <quote>TRUE/FALSE</quote>). Boolean values are case-insensitive; " +"for example, <quote>TRUE</quote>, <quote>True</quote> and <quote>true</" +"quote> are all equivalent and valid; the same applies to <quote>FALSE</" +"quote>." msgstr "" -"Les types de données utilisées sont des chaînes (pas de guillemets " -"nécessaires), des entiers et des booléens (ayant pour valeur <quote>TRUE/" -"FALSE</quote>)." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:44 +#: sssd.conf.5.xml:49 msgid "" "A comment line starts with a hash sign (<quote>#</quote>) or a semicolon " "(<quote>;</quote>). Inline comments are not supported." msgstr "" +"Une ligne de commentaire commence par un dièse (#) ou un point-virgule (;). " +"Les commentaires en ligne ne sont pas pris en charge." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:50 +#: sssd.conf.5.xml:55 msgid "" "All sections can have an optional <replaceable>description</replaceable> " "parameter. Its function is only as a label for the section." @@ -130,7 +132,7 @@ msgstr "" "description</replaceable>. Sa fonction ne sert qu'à nommer la section." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:56 +#: sssd.conf.5.xml:61 #, fuzzy #| msgid "" #| "<filename>sssd.conf</filename> must be a regular file, owned by root and " @@ -143,7 +145,7 @@ msgstr "" "root, et seul root doit pouvoir écrire et lire ce fichier." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:60 +#: sssd.conf.5.xml:65 #, fuzzy #| msgid "" #| "<filename>sssd.conf</filename> must be a regular file, owned by root and " @@ -156,29 +158,36 @@ msgstr "" "root, et seul root doit pouvoir écrire et lire ce fichier." #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:66 +#: sssd.conf.5.xml:71 msgid "CONFIGURATION SNIPPETS FROM INCLUDE DIRECTORY" -msgstr "" +msgstr "EXTRAITS DE CONFIGURATION DU RÉPERTOIRE INCLUDE" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:69 +#: sssd.conf.5.xml:74 msgid "" "The configuration file <filename>sssd.conf</filename> will include " "configuration snippets using the include directory <filename>conf.d</" "filename>." msgstr "" +"Le fichier de configuration <filename>sssd.conf</filename> inclura des " +"extraits de configuration utilisant le répertoire d'inclusion <filename>" +"conf.d</filename>." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:75 +#: sssd.conf.5.xml:80 msgid "" "Any file placed in <filename>conf.d</filename> that ends in " "<quote><filename>.conf</filename></quote> and does not begin with a dot " "(<quote>.</quote>) will be used together with <filename>sssd.conf</filename> " "to configure SSSD." msgstr "" +"Tout fichier placé dans <filename>conf.d</filename> qui se termine par " +"<quote><filename>.conf</filename></quote> et ne commence pas par un point " +"(<quote>.</quote>) sera utilisé avec <filename>sssd.conf</filename> pour " +"configurer SSSD." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:83 +#: sssd.conf.5.xml:88 msgid "" "The configuration snippets from <filename>conf.d</filename> have higher " "priority than <filename>sssd.conf</filename> and will override " @@ -189,57 +198,125 @@ msgid "" "<filename>02_snippet.conf</filename> etc.) can help visualize the priority " "(higher number means higher priority)." msgstr "" +"Les extraits de configuration du fichier `conf.d` sont prioritaires sur ceux " +"du fichier `sssd.conf` et prévalent sur ce dernier en cas de conflit. Si " +"plusieurs extraits sont présents dans `conf.d`, ils sont inclus par ordre " +"alphabétique (selon les paramètres régionaux). Les fichiers inclus en " +"dernier sont prioritaires. Les préfixes numériques (par exemple, " +"`01_snippet.conf`, `02_snippet.conf`, etc.) permettent de visualiser la " +"priorité (un nombre plus élevé indique une priorité plus importante)." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:97 +#: sssd.conf.5.xml:102 msgid "" "The snippet files require the same owner and permissions as " "<filename>sssd.conf</filename>." msgstr "" +"Les fichiers d'extrait nécessitent le même propriétaire et les mêmes " +"permissions que <filename>sssd.conf</filename>." #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:103 +#: sssd.conf.5.xml:108 +#, fuzzy +#| msgid "CONFIGURATION FILE" +msgid "VENDOR PROVIDED CONFIGURATION" +msgstr "FICHIER DE CONFIGURATION" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:111 +msgid "" +"The vendor provided configuration file is installed in " +"<filename>&sssd_vendor_dir;/sssd.conf</filename>, but this file must not be " +"directly edited. It can be completely masked by creating the system specific " +"configuration file <filename>&sssd_conf_dir;/sssd.conf</filename>, or partly " +"overriden by creating config snippets in <filename>&sssd_conf_dir;/conf.d</" +"filename> directory." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><title> +#: sssd.conf.5.xml:120 +#, fuzzy +#| msgid "CONFIGURATION FILE" +msgid "CONFIGURATION FILE HIERARCHY" +msgstr "FICHIER DE CONFIGURATION" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:122 +msgid "" +"When sssd reads the configuration it first tries to open the system specific " +"configuration file in <filename>&sssd_conf_dir;/sssd.conf</filename>. If it " +"exists, it is loaded and snippets from <filename>&sssd_conf_dir;/conf.d</" +"filename> are applied. The vendor provided configuration file " +"<filename>&sssd_vendor_dir;/sssd.conf</filename> is completely ignored in " +"this case." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:131 +msgid "" +"If the system specific configuration file <filename>&sssd_conf_dir;/" +"sssd.conf</filename> does not exist, then the vendor configuration file " +"<filename>&sssd_vendor_dir;/sssd.conf</filename> is loaded and snippets from " +"<filename>&sssd_conf_dir;/conf.d</filename> are applied." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd.conf.5.xml:141 msgid "GENERAL OPTIONS" msgstr "OPTIONS GÉNÉRALES" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:105 +#: sssd.conf.5.xml:143 msgid "Following options are usable in more than one configuration sections." msgstr "" "Les options qui suivent peuvent être utilisées dans plus d'une section de " "configuration." #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:109 +#: sssd.conf.5.xml:147 msgid "Options usable in all sections" msgstr "Options utilisables dans toutes les sections" +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:149 +msgid "" +"Note: Below options are ignored in <quote>[session_recording]</quote> " +"section, see <quote>Session recording configuration options</quote> section " +"for more details." +msgstr "" + #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:113 +#: sssd.conf.5.xml:156 msgid "debug_level (integer)" msgstr "debug_level (entier)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:117 +#: sssd.conf.5.xml:160 msgid "debug (integer)" -msgstr "" +msgstr "débogage (entier)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:120 +#: sssd.conf.5.xml:163 msgid "" "SSSD 1.14 and later also includes the <replaceable>debug</replaceable> alias " "for <replaceable>debug_level</replaceable> as a convenience feature. If both " "are specified, the value of <replaceable>debug_level</replaceable> will be " "used." msgstr "" +"SSSD 1.14 et versions ultérieures incluent également l'alias `<replaceable>" +"debug</replaceable>` pour `<replaceable>debug_level</replaceable>`, par " +"commodité. Si les deux sont spécifiés, la valeur de `<replaceable>" +"debug_level</replaceable>` sera utilisée." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:130 -msgid "debug_timestamps (bool)" +#: sssd.conf.5.xml:173 +#, fuzzy +#| msgid "debug_timestamps (bool)" +msgid "debug_timestamps (boolean)" msgstr "debug_timestamps (booléen)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:133 +#: sssd.conf.5.xml:176 msgid "" "Add a timestamp to the debug messages. If journald is enabled for SSSD " "debug logging this option is ignored." @@ -248,23 +325,25 @@ msgstr "" "la journalisation de débogage de SSSD, cette option sera ignorée." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:138 sssd.conf.5.xml:175 sssd.conf.5.xml:337 -#: sssd.conf.5.xml:644 sssd.conf.5.xml:668 sssd.conf.5.xml:875 -#: sssd.conf.5.xml:979 sssd.conf.5.xml:2113 sssd-ldap.5.xml:979 -#: sssd-ldap.5.xml:1134 sssd-ldap.5.xml:1237 sssd-ldap.5.xml:1306 -#: sssd-ldap.5.xml:1714 sssd-ldap.5.xml:1848 sssd-ldap.5.xml:1913 -#: sssd-ipa.5.xml:346 sssd-ad.5.xml:252 sssd-ad.5.xml:367 sssd-ad.5.xml:1180 -#: sssd-ad.5.xml:1382 sssd-krb5.5.xml:358 +#: sssd.conf.5.xml:181 sssd.conf.5.xml:218 sssd.conf.5.xml:380 +#: sssd.conf.5.xml:687 sssd.conf.5.xml:711 sssd.conf.5.xml:827 +#: sssd.conf.5.xml:932 sssd.conf.5.xml:2149 sssd.conf.5.xml:4730 +#: sssd-ldap.5.xml:979 sssd-ldap.5.xml:1134 sssd-ldap.5.xml:1237 +#: sssd-ldap.5.xml:1306 sssd-ldap.5.xml:1714 sssd-ldap.5.xml:1848 +#: sssd-ldap.5.xml:1913 sssd-ipa.5.xml:341 sssd-ad.5.xml:252 sssd-ad.5.xml:367 +#: sssd-ad.5.xml:1180 sssd-ad.5.xml:1375 sssd-krb5.5.xml:358 msgid "Default: true" msgstr "Par défaut : true" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:143 -msgid "debug_microseconds (bool)" +#: sssd.conf.5.xml:186 +#, fuzzy +#| msgid "debug_microseconds (bool)" +msgid "debug_microseconds (boolean)" msgstr "debug_microseconds (booléen)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:146 +#: sssd.conf.5.xml:189 msgid "" "Add microseconds to the timestamp in debug messages. If journald is enabled " "for SSSD debug logging this option is ignored." @@ -274,28 +353,28 @@ msgstr "" "sera ignorée." #. type: Content of: <variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:151 sssd.conf.5.xml:2040 sssd.conf.5.xml:4158 +#: sssd.conf.5.xml:194 sssd.conf.5.xml:2072 sssd.conf.5.xml:4363 #: sssd-ldap.5.xml:363 sssd-ldap.5.xml:998 sssd-ldap.5.xml:1209 -#: sssd-ldap.5.xml:1663 sssd-ldap.5.xml:1937 sssd-ipa.5.xml:146 -#: sssd-ipa.5.xml:706 sssd-ad.5.xml:1135 sssd-krb5.5.xml:268 +#: sssd-ldap.5.xml:1663 sssd-ldap.5.xml:1937 sssd-ipa.5.xml:141 +#: sssd-ipa.5.xml:701 sssd-ad.5.xml:1140 sssd-idp.5.xml:287 sssd-krb5.5.xml:268 #: sssd-krb5.5.xml:330 sssd-krb5.5.xml:432 include/krb5_options.xml:163 msgid "Default: false" msgstr "Par défaut : false" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:156 +#: sssd.conf.5.xml:199 #, fuzzy #| msgid "debug_microseconds (bool)" -msgid "debug_backtrace_enabled (bool)" +msgid "debug_backtrace_enabled (boolean)" msgstr "debug_microseconds (booléen)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:159 +#: sssd.conf.5.xml:202 msgid "Enable debug backtrace." -msgstr "" +msgstr "Activer le débogage par trace d'exécution." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:162 +#: sssd.conf.5.xml:205 msgid "" "In case SSSD is run with debug_level less than 9, everything is logged to a " "ring buffer in memory and flushed to a log file on any error up to and " @@ -303,16 +382,24 @@ msgid "" "to 0 or 1 then only those error levels will trigger backtrace, otherwise up " "to 2)." msgstr "" +"Dans le cas où SSSD est exécuté avec debug_level inférieur à 9, tout est " +"enregistré dans un tampon circulaire en mémoire et vidé dans un fichier " +"journal sur toute erreur jusqu'à et y compris `min(0x0040, debug_level)` " +"(c'est-à-dire que si debug_level est explicitement défini sur 0 ou 1, seuls " +"ces niveaux d'erreur déclencheront une trace d'exécution, sinon jusqu'à 2)." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:171 +#: sssd.conf.5.xml:214 msgid "" "Feature is only supported for `logger == files` (i.e. setting doesn't have " "effect for other logger types)." msgstr "" +"Cette fonctionnalité est uniquement prise en charge pour `logger == files` " +"(c'est-à-dire que ce paramètre n'a aucun effet pour les autres types de " +"journalisation)." #. type: Content of: outside any tag (error?) -#: sssd.conf.5.xml:111 sssd.conf.5.xml:186 sssd-ldap.5.xml:1754 +#: sssd.conf.5.xml:154 sssd.conf.5.xml:229 sssd-ldap.5.xml:1754 #: sssd-ldap.5.xml:1960 sss-certmap.5.xml:645 sssd-systemtap.5.xml:82 #: sssd-systemtap.5.xml:143 sssd-systemtap.5.xml:236 sssd-systemtap.5.xml:274 #: sssd-systemtap.5.xml:330 sssd-ldap-attributes.5.xml:40 @@ -325,61 +412,71 @@ msgid "<placeholder type=\"variablelist\" id=\"0\"/>" msgstr "<placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:184 +#: sssd.conf.5.xml:227 msgid "Options usable in SERVICE and DOMAIN sections" msgstr "Options utilisables dans les sections SERVICE et DOMAIN" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:188 +#: sssd.conf.5.xml:231 msgid "timeout (integer)" msgstr "timeout (entier)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:191 +#: sssd.conf.5.xml:234 msgid "" "Timeout in seconds between heartbeats for this service. This is used to " "ensure that the process is alive and capable of answering requests. Note " "that after three missed heartbeats the process will terminate itself." msgstr "" +"Délai d'attente en secondes entre les pulsations de ce service. Ce délai " +"permet de s'assurer que le processus est actif et capable de répondre aux " +"requêtes. Veuillez noter qu'après trois pulsations manquées, le processus " +"s'arrêtera automatiquement." #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:198 sssd.conf.5.xml:1199 sssd.conf.5.xml:1673 -#: sssd.conf.5.xml:4174 sssd-ldap.5.xml:825 sssd-idp.5.xml:192 +#: sssd.conf.5.xml:241 sssd.conf.5.xml:1155 sssd.conf.5.xml:1665 +#: sssd.conf.5.xml:4379 sssd-ldap.5.xml:825 sssd-idp.5.xml:271 #: include/ldap_id_mapping.xml:270 msgid "Default: 10" msgstr "Par défaut : 10" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:208 +#: sssd.conf.5.xml:251 msgid "SPECIAL SECTIONS" msgstr "SECTIONS SPÉCIALES" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:211 +#: sssd.conf.5.xml:254 msgid "The [sssd] section" msgstr "La section [sssd]" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><title> -#: sssd.conf.5.xml:220 +#: sssd.conf.5.xml:263 msgid "Section parameters" msgstr "Paramètres de sections" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:222 -msgid "services" -msgstr "services" +#: sssd.conf.5.xml:265 +#, fuzzy +#| msgid "user (string)" +msgid "services (string)" +msgstr "user (chaîne)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:225 +#: sssd.conf.5.xml:268 msgid "" "Comma separated list of services that are started when sssd itself starts. " "<phrase condition=\"have_systemd\"> The services' list is optional on " "platforms where systemd is supported, as they will either be socket or D-Bus " "activated when needed. </phrase>" msgstr "" +"Liste, séparée par des virgules, des services qui démarrent au lancement de " +"sssd. <phrase condition=\"have_systemd\"> Cette liste de services est " +"facultative sur les plateformes prenant en charge systemd, car ils seront " +"activés par socket ou D-Bus selon les besoins. </phrase>" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:234 +#: sssd.conf.5.xml:277 #, fuzzy #| msgid "" #| "Supported services: nss, pam <phrase condition=\"with_sudo\">, sudo</" @@ -400,20 +497,23 @@ msgstr "" "condition=\"with_ifp\">, ifp</phrase>" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:241 +#: sssd.conf.5.xml:284 msgid "" "<phrase condition=\"have_systemd\"> By default, all services are disabled " "and the administrator must enable the ones allowed to be used by executing: " "\"systemctl enable sssd-@service@.socket\". </phrase>" msgstr "" +"Par défaut, tous les services sont désactivés et l'administrateur doit " +"activer ceux qui sont autorisés en exécutant la commande : « systemctl " +"enable sssd-@service@.socket »." -#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:250 -msgid "domains" -msgstr "domaines" +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sssd.conf.5.xml:293 sssd.conf.5.xml:4562 +msgid "domains (string)" +msgstr "domaines (chaîne de caractères)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:253 +#: sssd.conf.5.xml:296 msgid "" "A domain is a database containing user information. SSSD can use more " "domains at the same time, but at least one must be configured or SSSD won't " @@ -422,14 +522,21 @@ msgid "" "alphanumeric ASCII characters, dashes, dots and underscores. '/' character " "is forbidden." msgstr "" +"Un domaine est une base de données contenant des informations utilisateur. " +"SSSD peut utiliser plusieurs domaines simultanément, mais au moins un doit " +"être configuré pour que SSSD puisse démarrer. Ce paramètre décrit la liste " +"des domaines dans l'ordre de leur interrogation. Il est recommandé qu'un nom " +"de domaine contienne uniquement des caractères alphanumériques ASCII, des " +"tirets, des points et des traits de soulignement. Le caractère « / » est " +"interdit." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:266 sssd.conf.5.xml:3467 +#: sssd.conf.5.xml:309 sssd.conf.5.xml:3598 msgid "re_expression (string)" msgstr "re_expression (chaîne)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:269 +#: sssd.conf.5.xml:312 msgid "" "Default regular expression that describes how to parse the string containing " "user name and domain into these components." @@ -438,20 +545,24 @@ msgstr "" "contenant le nom d'utilisateur et de domaine dans ces composants." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:274 +#: sssd.conf.5.xml:317 msgid "" "Each domain can have an individual regular expression configured. For some " "ID providers there are also default regular expressions. See DOMAIN SECTIONS " "for more info on these regular expressions." msgstr "" +"Chaque domaine peut avoir sa propre expression régulière configurée. " +"Certains fournisseurs d'identité proposent également des expressions " +"régulières par défaut. Consultez la section DOMAINE pour plus d'informations " +"sur ces expressions régulières." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:283 sssd.conf.5.xml:3524 +#: sssd.conf.5.xml:326 sssd.conf.5.xml:3655 msgid "full_name_format (string)" msgstr "full_name_format (chaîne)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:286 sssd.conf.5.xml:3527 +#: sssd.conf.5.xml:329 sssd.conf.5.xml:3658 msgid "" "A <citerefentry> <refentrytitle>printf</refentrytitle> <manvolnum>3</" "manvolnum> </citerefentry>-compatible format that describes how to compose a " @@ -463,32 +574,32 @@ msgstr "" "domaine." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:297 sssd.conf.5.xml:3538 +#: sssd.conf.5.xml:340 sssd.conf.5.xml:3669 msgid "%1$s" msgstr "%1$s" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:298 sssd.conf.5.xml:3539 +#: sssd.conf.5.xml:341 sssd.conf.5.xml:3670 msgid "user name" msgstr "nom d'utilisateur" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:301 sssd.conf.5.xml:3542 +#: sssd.conf.5.xml:344 sssd.conf.5.xml:3673 msgid "%2$s" msgstr "%2$s" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:304 sssd.conf.5.xml:3545 +#: sssd.conf.5.xml:347 sssd.conf.5.xml:3676 msgid "domain name as specified in the SSSD config file." msgstr "nom de domaine tel qu'indiqué dans le fichier de configuration de SSSD." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:310 sssd.conf.5.xml:3551 +#: sssd.conf.5.xml:353 sssd.conf.5.xml:3682 msgid "%3$s" msgstr "%3$s" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:313 sssd.conf.5.xml:3554 +#: sssd.conf.5.xml:356 sssd.conf.5.xml:3685 msgid "" "domain flat name. Mostly usable for Active Directory domains, both directly " "configured or discovered via IPA trusts." @@ -498,7 +609,7 @@ msgstr "" "d'approbation IPA." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:294 sssd.conf.5.xml:3535 +#: sssd.conf.5.xml:337 sssd.conf.5.xml:3666 msgid "" "The following expansions are supported: <placeholder type=\"variablelist\" " "id=\"0\"/>" @@ -507,39 +618,46 @@ msgstr "" "type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:323 +#: sssd.conf.5.xml:366 msgid "" "Each domain can have an individual format string configured. See DOMAIN " "SECTIONS for more info on this option." msgstr "" +"Chaque domaine peut avoir une chaîne de format personnalisée. Consultez la " +"section SECTIONS DE DOMAINE pour plus d'informations sur cette option." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:329 +#: sssd.conf.5.xml:372 msgid "monitor_resolv_conf (boolean)" -msgstr "" +msgstr "monitor_resolv_conf (booléen)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:332 +#: sssd.conf.5.xml:375 msgid "" "Controls if SSSD should monitor the state of resolv.conf to identify when it " "needs to update its internal DNS resolver." msgstr "" +"Contrôle si SSSD doit surveiller l'état de resolv.conf pour identifier quand " +"il doit mettre à jour son résolveur DNS interne." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:342 +#: sssd.conf.5.xml:385 msgid "try_inotify (boolean)" msgstr "try_inotify (booléen)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:345 +#: sssd.conf.5.xml:388 msgid "" "By default, SSSD will attempt to use inotify to monitor configuration files " "changes and will fall back to polling every five seconds if inotify cannot " "be used." msgstr "" +"Par défaut, SSSD tentera d'utiliser inotify pour surveiller les " +"modifications des fichiers de configuration et se rabattra sur un " +"interrogation toutes les cinq secondes si inotify ne peut pas être utilisé." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:351 +#: sssd.conf.5.xml:394 msgid "" "There are some limited situations where it is preferred that we should skip " "even trying to use inotify. In these rare cases, this option should be set " @@ -549,7 +667,7 @@ msgstr "" "conseillée. Dans ces rares cas, cette option devrait être définie à « false »" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:357 +#: sssd.conf.5.xml:400 msgid "" "Default: true on platforms where inotify is supported. False on other " "platforms." @@ -558,7 +676,7 @@ msgstr "" "sur les autres plates-formes." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:361 +#: sssd.conf.5.xml:404 msgid "" "Note: this option will have no effect on platforms where inotify is " "unavailable. On these platforms, polling will always be used." @@ -568,12 +686,12 @@ msgstr "" "utilisée." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:368 +#: sssd.conf.5.xml:411 msgid "krb5_rcache_dir (string)" msgstr "krb5_rcache_dir (chaîne)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:371 +#: sssd.conf.5.xml:414 msgid "" "Directory on the filesystem where SSSD should store Kerberos replay cache " "files." @@ -582,7 +700,7 @@ msgstr "" "de rejeu Kerberos." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:375 +#: sssd.conf.5.xml:418 msgid "" "This option accepts a special value __LIBKRB5_DEFAULTS__ that will instruct " "SSSD to let libkrb5 decide the appropriate location for the replay cache." @@ -592,7 +710,7 @@ msgstr "" "relecture." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:381 +#: sssd.conf.5.xml:424 msgid "" "Default: Distribution-specific and specified at build-time. " "(__LIBKRB5_DEFAULTS__ if not configured)" @@ -601,19 +719,21 @@ msgstr "" "la construction du logiciel. (__LIBKRB5_DEFAULTS__ si non configuré)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:388 +#: sssd.conf.5.xml:431 msgid "default_domain_suffix (string)" msgstr "default_domain_suffix (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:391 +#: sssd.conf.5.xml:434 msgid "" "Please note that this option is deprecated and domain_resolution_order " "should be used." msgstr "" +"Veuillez noter que cette option est obsolète et qu'il convient d'utiliser " +"domain_resolution_order." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:395 +#: sssd.conf.5.xml:438 msgid "" "This string will be used as a default domain name for all names without a " "domain name component. The main use case is environments where the primary " @@ -629,7 +749,7 @@ msgstr "" "domaine." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:405 +#: sssd.conf.5.xml:448 msgid "" "Please note that if this option is set all users from the primary domain " "have to use their fully qualified name, e.g. user@domain.name, to log in. " @@ -637,23 +757,29 @@ msgid "" "is not allowed to use this option together with use_fully_qualified_names " "set to False." msgstr "" +"Veuillez noter que si cette option est activée, tous les utilisateurs du " +"domaine principal devront utiliser leur nom complet (par exemple, " +"utilisateur@nom.domaine) pour se connecter. L'activation de cette option " +"modifie la valeur par défaut de `use_fully_qualified_names` et la définit " +"sur `True`. Il est impossible d'utiliser cette option simultanément avec " +"`use_fully_qualified_names` défini sur `False`." #. type: Content of: <variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:414 sssd-ldap.5.xml:937 sssd-ldap.5.xml:949 -#: sssd-ldap.5.xml:1042 sssd-ad.5.xml:921 sssd-ad.5.xml:996 sssd-krb5.5.xml:468 -#: sssd-ldap-attributes.5.xml:470 sssd-ldap-attributes.5.xml:978 -#: include/ldap_id_mapping.xml:211 include/ldap_id_mapping.xml:222 -#: include/krb5_options.xml:148 +#: sssd.conf.5.xml:457 sssd.conf.5.xml:2006 sssd-ldap.5.xml:937 +#: sssd-ldap.5.xml:949 sssd-ldap.5.xml:1042 sssd-ad.5.xml:926 +#: sssd-ad.5.xml:1001 sssd-krb5.5.xml:468 sssd-ldap-attributes.5.xml:470 +#: sssd-ldap-attributes.5.xml:978 include/ldap_id_mapping.xml:211 +#: include/ldap_id_mapping.xml:222 include/krb5_options.xml:148 msgid "Default: not set" msgstr "Par défaut : non défini" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:419 +#: sssd.conf.5.xml:462 msgid "override_space (string)" msgstr "override_space (chaîne)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:422 +#: sssd.conf.5.xml:465 msgid "" "This parameter will replace spaces (space bar) with the given character for " "user and group names. e.g. (_). User name "john doe" will be " @@ -669,144 +795,171 @@ msgstr "" "défaut de l'interpréteur de commande." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:431 +#: sssd.conf.5.xml:474 msgid "" "Please note it is a configuration error to use a replacement character that " "might be used in user or group names. If a name contains the replacement " "character SSSD tries to return the unmodified name but in general the result " "of a lookup is undefined." msgstr "" +"Veuillez noter que l'utilisation d'un caractère de remplacement susceptible " +"d'être utilisé dans les noms d'utilisateurs ou de groupes constitue une " +"erreur de configuration. Si un nom contient ce caractère, SSSD tente de " +"renvoyer le nom non modifié, mais le résultat de la recherche est " +"généralement indéfini." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:439 +#: sssd.conf.5.xml:482 msgid "Default: not set (spaces will not be replaced)" msgstr "Par défaut : non défini (les espaces ne seront pas remplacées)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:444 +#: sssd.conf.5.xml:487 msgid "certificate_verification (string)" -msgstr "" +msgstr "vérification_certificat (chaîne)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:452 +#: sssd.conf.5.xml:495 msgid "no_ocsp" -msgstr "" +msgstr "no_ocsp" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:454 +#: sssd.conf.5.xml:497 msgid "" "Disables Online Certificate Status Protocol (OCSP) checks. This might be " "needed if the OCSP servers defined in the certificate are not reachable from " "the client." msgstr "" +"Désactive les vérifications OCSP (Online Certificate Status Protocol). Cela " +"peut s'avérer nécessaire si les serveurs OCSP définis dans le certificat ne " +"sont pas accessibles depuis le client." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:462 +#: sssd.conf.5.xml:505 msgid "soft_ocsp" -msgstr "" +msgstr "soft_ocsp" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:464 +#: sssd.conf.5.xml:507 msgid "" "If a connection cannot be established to an OCSP responder the OCSP check is " "skipped. This option should be used to allow authentication when the system " "is offline and the OCSP responder cannot be reached." msgstr "" +"Si aucune connexion ne peut être établie avec un serveur OCSP, la " +"vérification OCSP est ignorée. Cette option permet l'authentification " +"lorsque le système est hors ligne et que le serveur OCSP est inaccessible." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:474 +#: sssd.conf.5.xml:517 msgid "ocsp_dgst" -msgstr "" +msgstr "ocsp_dgst" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:476 +#: sssd.conf.5.xml:519 msgid "" "Digest (hash) function used to create the certificate ID for the OCSP " "request. Allowed values are:" msgstr "" +"Fonction de hachage utilisée pour créer l'identifiant du certificat pour la " +"requête OCSP. Les valeurs autorisées sont :" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:480 +#: sssd.conf.5.xml:523 msgid "sha1" -msgstr "" +msgstr "sha1" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:481 +#: sssd.conf.5.xml:524 msgid "sha256" -msgstr "" +msgstr "sha256" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:482 +#: sssd.conf.5.xml:525 msgid "sha384" -msgstr "" +msgstr "Sha348" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:483 +#: sssd.conf.5.xml:526 msgid "sha512" -msgstr "" +msgstr "Sha12" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:486 +#: sssd.conf.5.xml:529 msgid "Default: sha1 (to allow compatibility with RFC5019-compliant responder)" msgstr "" +"Par défaut : sha1 (pour assurer la compatibilité avec les répondeurs " +"conformes à la norme RFC5019)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:492 +#: sssd.conf.5.xml:535 msgid "no_verification" -msgstr "" +msgstr "aucune_vérification" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:494 +#: sssd.conf.5.xml:537 msgid "" "Disables verification completely. This option should only be used for " "testing." msgstr "" +"Désactive complètement la vérification. Cette option ne doit être utilisée " +"qu'à des fins de test." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:500 +#: sssd.conf.5.xml:543 msgid "partial_chain" -msgstr "" +msgstr "chaîne partielle" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:502 +#: sssd.conf.5.xml:545 msgid "" "Allow verification to succeed even if a <replaceable>complete</replaceable> " "chain cannot be built to a self-signed trust-anchor, provided it is possible " "to construct a chain to a trusted certificate that might not be self-signed." msgstr "" +"Autoriser la vérification à réussir même si une chaîne <replaceable>" +"complète</replaceable> ne peut pas être construite jusqu'à une ancre de " +"confiance auto-signée, à condition qu'il soit possible de construire une " +"chaîne jusqu'à un certificat de confiance qui pourrait ne pas être auto-" +"signé." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:511 +#: sssd.conf.5.xml:554 msgid "ocsp_default_responder=URL" -msgstr "" +msgstr "ocsp_default_responder=URL" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:513 +#: sssd.conf.5.xml:556 msgid "" "Sets the OCSP default responder which should be used instead of the one " "mentioned in the certificate. URL must be replaced with the URL of the OCSP " "default responder e.g. http://example.com:80/ocsp." msgstr "" +"Définit le répondeur OCSP par défaut à utiliser à la place de celui " +"mentionné dans le certificat. L'URL doit être remplacée par celle du " +"répondeur OCSP par défaut, par exemple : http://example.com:80/ocsp." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:523 +#: sssd.conf.5.xml:566 msgid "ocsp_default_responder_signing_cert=NAME" -msgstr "" +msgstr "ocsp_default_responder_signing_cert=NOM" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:525 +#: sssd.conf.5.xml:568 msgid "" "This option is currently ignored. All needed certificates must be available " "in the PEM file given by pam_cert_db_path." msgstr "" +"Cette option est actuellement ignorée. Tous les certificats nécessaires " +"doivent être disponibles dans le fichier PEM indiqué par pam_cert_db_path." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:533 +#: sssd.conf.5.xml:576 msgid "crl_file=/PATH/TO/CRL/FILE" -msgstr "" +msgstr "crl_file=/CHEMIN/VERS/CRL/FICHIER" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:535 +#: sssd.conf.5.xml:578 #, fuzzy #| msgid "" #| "Please refer to the <quote>dns_discovery_domain</quote> parameter in the " @@ -823,68 +976,85 @@ msgstr "" "manvolnum></citerefentry> pour plus de détails." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:548 +#: sssd.conf.5.xml:591 msgid "soft_crl" -msgstr "" +msgstr "soft_crl" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:551 +#: sssd.conf.5.xml:594 msgid "" "If a Certificate Revocation List (CRL) is expired ignore the expiration " "time of the CRL and check the related certificates with the expired CRL. " "This option should be used to allow authentication when the system is " "offline and the CRL cannot be renewed." msgstr "" +"Si une liste de révocation de certificats (CRL) a expiré, ignorez sa date " +"d'expiration et vérifiez les certificats associés à cette CRL expirée. Cette " +"option permet l'authentification lorsque le système est hors ligne et que la " +"CRL ne peut être renouvelée." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:447 +#: sssd.conf.5.xml:490 msgid "" "With this parameter the certificate verification can be tuned with a comma " "separated list of options. Supported options are: <placeholder " "type=\"variablelist\" id=\"0\"/>" msgstr "" +"Ce paramètre permet de personnaliser la vérification du certificat à l'aide " +"d'une liste d'options séparées par des virgules. Les options prises en " +"charge sont : <placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:564 +#: sssd.conf.5.xml:607 msgid "Unknown options are reported but ignored." -msgstr "" +msgstr "Les options inconnues sont signalées mais ignorées." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:567 +#: sssd.conf.5.xml:610 msgid "Default: not set, i.e. do not restrict certificate verification" msgstr "" +"Par défaut : non défini, c’est-à-dire que la vérification des certificats " +"n’est pas restreinte." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:573 +#: sssd.conf.5.xml:616 msgid "disable_netlink (boolean)" -msgstr "" +msgstr "désactiver_netlink (booléen)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:576 +#: sssd.conf.5.xml:619 msgid "" "SSSD hooks into the netlink interface to monitor changes to routes, " "addresses, links and trigger certain actions." msgstr "" +"SSSD s'intègre à l'interface netlink pour surveiller les modifications " +"apportées aux routes, aux adresses et aux liens, et déclencher certaines " +"actions." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:581 +#: sssd.conf.5.xml:624 msgid "" "The SSSD state changes caused by netlink events may be undesirable and can " "be disabled by setting this option to 'true'" msgstr "" +"Les modifications d'état SSSD provoquées par les événements netlink peuvent " +"être indésirables et peuvent être désactivées en définissant cette option " +"sur « true »." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:586 +#: sssd.conf.5.xml:629 msgid "Default: false (netlink changes are detected)" -msgstr "" +msgstr "Par défaut : faux (les modifications du réseau sont détectées)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:591 -msgid "domain_resolution_order" -msgstr "" +#: sssd.conf.5.xml:634 +#, fuzzy +#| msgid "subdomains_provider (string)" +msgid "domain_resolution_order (string)" +msgstr "subdomains_provider (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:594 +#: sssd.conf.5.xml:637 msgid "" "Comma separated list of domains and subdomains representing the lookup order " "that will be followed. The list doesn't have to include all possible " @@ -893,9 +1063,15 @@ msgid "" "subdomains which are not listed as part of <quote>lookup_order</quote> will " "be looked up in a random order for each parent domain." msgstr "" +"Liste de domaines et sous-domaines séparés par des virgules, indiquant " +"l'ordre de recherche à suivre. Cette liste n'a pas besoin d'être exhaustive, " +"car les domaines manquants seront recherchés selon l'ordre défini dans " +"l'option de configuration `<quote>domains</quote>`. Les sous-domaines non " +"listés dans `<quote>lookup_order</quote>` seront recherchés de manière " +"aléatoire pour chaque domaine parent." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:606 +#: sssd.conf.5.xml:649 msgid "" "Please, note that when this option is set the output format of all commands " "is always fully-qualified even when using short names for input. In case " @@ -909,99 +1085,128 @@ msgid "" "domain which uses shortnames, making this workaround totally not recommended " "in cases where usernames may overlap between domains." msgstr "" - -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:630 sssd.conf.5.xml:1697 sssd.conf.5.xml:4224 -#: sssd-ad.5.xml:187 sssd-ad.5.xml:328 sssd-ad.5.xml:342 sssd-idp.5.xml:108 -#: sssd-idp.5.xml:132 sssd-idp.5.xml:145 sssd-idp.5.xml:159 sssd-idp.5.xml:180 +"Veuillez noter que lorsque cette option est activée, le format de sortie de " +"toutes les commandes est toujours complet, même avec des noms courts en " +"entrée. Si l'administrateur souhaite une sortie non complète, l'option " +"`full_name_format` peut être utilisée comme suit : `<quote>" +"full_name_format=%1$s</quote>`. Cependant, lors de la connexion, les " +"applications normalisent souvent le nom d'utilisateur en appelant " +"`<citerefentry> <refentrytitle>getpwnam</refentrytitle> <manvolnum>3</" +"manvolnum> </citerefentry>`. Si un nom court est renvoyé pour une entrée " +"qualifiée (lors de la tentative de connexion à un utilisateur présent sur " +"plusieurs domaines), la tentative de connexion peut être redirigée vers le " +"domaine utilisant les noms courts. Cette solution est donc fortement " +"déconseillée lorsque des noms d'utilisateur peuvent se chevaucher entre " +"plusieurs domaines." + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:673 sssd.conf.5.xml:1026 sssd.conf.5.xml:1689 +#: sssd.conf.5.xml:4429 sssd-ad.5.xml:187 sssd-ad.5.xml:328 sssd-ad.5.xml:342 +#: sssd-idp.5.xml:112 sssd-idp.5.xml:136 sssd-idp.5.xml:149 sssd-idp.5.xml:167 +#: sssd-idp.5.xml:188 msgid "Default: Not set" msgstr "Par défaut : non défini" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:635 +#: sssd.conf.5.xml:678 #, fuzzy #| msgid "ipa_server_mode (boolean)" msgid "implicit_pac_responder (boolean)" msgstr "ipa_server_mode (booléen)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:638 +#: sssd.conf.5.xml:681 msgid "" "The PAC responder is enabled automatically for the IPA and AD provider to " "evaluate and check the PAC. If it has to be disabled set this option to " "'false'." msgstr "" +"Le répondeur PAC est activé automatiquement pour permettre au fournisseur " +"IPA et AD d'évaluer et de vérifier le PAC. Si vous devez le désactiver, " +"définissez cette option sur « false »." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:649 +#: sssd.conf.5.xml:692 #, fuzzy #| msgid "ad_enable_gc (boolean)" msgid "core_dumpable (boolean)" msgstr "ad_enable_gc (booléen)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:652 +#: sssd.conf.5.xml:695 msgid "" "This option can be used for general system hardening: setting it to 'false' " "forbids core dumps for all SSSD processes to avoid leaking plain text " "passwords. See man page prctl:PR_SET_DUMPABLE on Linux or " "procctl:PROC_TRACE_CTL on FreeBSD for details." msgstr "" +"Cette option permet de renforcer la sécurité du système : la désactiver " +"empêche la création de fichiers core pour tous les processus SSSD afin " +"d'éviter la divulgation des mots de passe en clair. Consultez la page de " +"manuel de `prctl:PR_SET_DUMPABLE` sous Linux ou de `procctl:PROC_TRACE_CTL` " +"sous FreeBSD pour plus de détails." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:660 +#: sssd.conf.5.xml:703 msgid "" "Take a note that this setting has no effect for 'ldap_child', 'krb5_child' " "and 'sssd_pam' as those privileged binaries can have a copy of a host keytab " "data in a memory and their behavior in this regards is governed by /proc/sys/" "fs/suid_dumpable system setting." msgstr "" +"Veuillez noter que ce paramètre n'a aucun effet sur 'ldap_child', " +"'krb5_child' et 'sssd_pam', car ces binaires privilégiés peuvent avoir une " +"copie des données keytab de l'hôte en mémoire et leur comportement à cet " +"égard est régi par le paramètre système /proc/sys/fs/suid_dumpable." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:673 +#: sssd.conf.5.xml:716 #, fuzzy #| msgid "ldap_user_certificate (string)" msgid "passkey_verification (string)" msgstr "ldap_user_certificate (chaîne)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:681 +#: sssd.conf.5.xml:724 #, fuzzy #| msgid "ldap_user_certificate (string)" msgid "user_verification (boolean)" msgstr "ldap_user_certificate (chaîne)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:683 +#: sssd.conf.5.xml:726 msgid "" "Enable or disable the user verification (i.e. PIN, fingerprint) during " "authentication. If enabled, the PIN will always be requested." msgstr "" +"Activez ou désactivez la vérification de l'utilisateur (code PIN, empreinte " +"digitale, etc.) lors de l'authentification. Si elle est activée, le code PIN " +"sera systématiquement demandé." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:689 +#: sssd.conf.5.xml:732 msgid "" "The default is that the key settings decide what to do. In the IPA or " "kerberos pre-authentication case, this value will be overwritten by the " "server." msgstr "" +"Par défaut, ce sont les paramètres clés qui déterminent le comportement à " +"adopter. Dans le cas d'une pré-authentification IPA ou Kerberos, cette " +"valeur sera remplacée par celle du serveur." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:676 -#, fuzzy -#| msgid "" -#| "The following expansions are supported: <placeholder " -#| "type=\"variablelist\" id=\"0\"/>" +#: sssd.conf.5.xml:719 msgid "" "With this parameter the passkey verification can be tuned with a comma " "separated list of options. Supported options are: <placeholder " "type=\"variablelist\" id=\"0\"/>" msgstr "" -"Les expansions suivantes sont prises en charge : <placeholder " -"type=\"variablelist\" id=\"0\"/>" +"Ce paramètre permet de personnaliser la vérification du code d'accès à " +"l'aide d'une liste d'options séparées par des virgules. Les options prises " +"en charge sont : <placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:213 +#: sssd.conf.5.xml:256 msgid "" "Individual pieces of SSSD functionality are provided by special SSSD " "services that are started and stopped together with SSSD. The services are " @@ -1018,12 +1223,12 @@ msgstr "" "l'identité des domaines. <placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:708 +#: sssd.conf.5.xml:751 msgid "SERVICES SECTIONS" msgstr "SECTIONS DE SERVICES" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:710 +#: sssd.conf.5.xml:753 msgid "" "Settings that can be used to configure different services are described in " "this section. They should reside in the [<replaceable>$NAME</replaceable>] " @@ -1036,28 +1241,36 @@ msgstr "" "section doit être <quote>[nss]</quote>" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:717 +#: sssd.conf.5.xml:760 msgid "General service configuration options" msgstr "Options générales de configuration de service" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:719 +#: sssd.conf.5.xml:762 msgid "These options can be used to configure any service." msgstr "Ces options peuvent être utilisées pour configurer les services." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:723 -msgid "fd_limit" -msgstr "fd_limit" +#: sssd.conf.5.xml:766 +#, fuzzy +#| msgid "timeout (integer)" +msgid "fd_limit (integer)" +msgstr "timeout (entier)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:726 +#: sssd.conf.5.xml:769 +#, fuzzy +#| msgid "" +#| "This option specifies the maximum number of file descriptors that may be " +#| "opened at one time by this SSSD process. On systems where SSSD is granted " +#| "the CAP_SYS_RESOURCE capability, this will be an absolute setting. On " +#| "systems without this capability, the resulting value will be the lower " +#| "value of this or the limits.conf \"hard\" limit." msgid "" "This option specifies the maximum number of file descriptors that may be " -"opened at one time by this SSSD process. On systems where SSSD is granted " -"the CAP_SYS_RESOURCE capability, this will be an absolute setting. On " -"systems without this capability, the resulting value will be the lower value " -"of this or the limits.conf \"hard\" limit." +"opened at one time by this SSSD process. Note this value will be capped by " +"the init system at the startup of SSSD, see e.g. man systemd.exec for " +"details." msgstr "" "Cette option spécifie le nombre maximal de descripteurs de fichiers qui " "peuvent être ouverts en même temps par ce processus SSSD. Sur les systèmes " @@ -1066,17 +1279,19 @@ msgstr "" "valeur inférieure ou la limite « hard » de limits.conf." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:735 +#: sssd.conf.5.xml:776 msgid "Default: 8192 (or limits.conf \"hard\" limit)" msgstr "Par défault : 8192 (ou la limite « hard » de limits.conf)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:740 -msgid "client_idle_timeout" -msgstr "client_idle_timeout" +#: sssd.conf.5.xml:781 +#, fuzzy +#| msgid "offline_timeout (integer)" +msgid "client_idle_timeout (integer)" +msgstr "offline_timeout (entier)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:743 +#: sssd.conf.5.xml:784 msgid "" "This option specifies the number of seconds that a client of an SSSD process " "can hold onto a file descriptor without communicating on it. This value is " @@ -1084,154 +1299,26 @@ msgid "" "can't be shorter than 10 seconds. If a lower value is configured, it will be " "adjusted to 10 seconds." msgstr "" +"Cette option spécifie la durée pendant laquelle un client d'un processus " +"SSSD peut conserver un descripteur de fichier sans communiquer avec celui-" +"ci. Cette valeur est limitée afin d'éviter la saturation des ressources " +"système. Le délai d'expiration ne peut être inférieur à 10 secondes. Si une " +"valeur inférieure est configurée, elle sera ramenée à 10 secondes." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:752 -#, fuzzy -#| msgid "Default: 300" +#: sssd.conf.5.xml:793 msgid "Default: 60, KCM: 300" -msgstr "Par défaut : 300" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:757 -msgid "offline_timeout (integer)" -msgstr "offline_timeout (entier)" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:760 -msgid "" -"When SSSD switches to offline mode the amount of time before it tries to go " -"back online will increase based upon the time spent disconnected. By " -"default SSSD uses incremental behaviour to calculate delay in between " -"retries. So, the wait time for a given retry will be longer than the wait " -"time for the previous ones. After each unsuccessful attempt to go online, " -"the new interval is recalculated by the following:" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:771 sssd.conf.5.xml:827 -msgid "" -"new_delay = Minimum(old_delay * 2, offline_timeout_max) + " -"random[0...offline_timeout_random_offset]" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:774 -msgid "" -"The offline_timeout default value is 60. The offline_timeout_max default " -"value is 3600. The offline_timeout_random_offset default value is 30. The " -"end result is amount of seconds before next retry." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:780 -msgid "" -"Note that the maximum length of each interval is defined by " -"offline_timeout_max (apart of random part)." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:784 sssd.conf.5.xml:1110 sssd.conf.5.xml:1490 -#: sssd.conf.5.xml:1791 sssd-ldap.5.xml:550 -msgid "Default: 60" -msgstr "Par défaut : 60" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:789 -#, fuzzy -#| msgid "offline_timeout (integer)" -msgid "offline_timeout_max (integer)" -msgstr "offline_timeout (entier)" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:792 -msgid "" -"Controls by how much the time between attempts to go online can be " -"incremented following unsuccessful attempts to go online." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:797 -msgid "A value of 0 disables the incrementing behaviour." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:800 -msgid "" -"The value of this parameter should be set in correlation to offline_timeout " -"parameter value." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:804 -msgid "" -"With offline_timeout set to 60 (default value) there is no point in setting " -"offlinet_timeout_max to less than 120 as it will saturate instantly. General " -"rule here should be to set offline_timeout_max to at least 4 times " -"offline_timeout." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:810 -msgid "" -"Although a value between 0 and offline_timeout may be specified, it has the " -"effect of overriding the offline_timeout value so is of little use." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:815 -#, fuzzy -#| msgid "Default: 300" -msgid "Default: 3600" -msgstr "Par défaut : 300" +msgstr "Valeur par défaut : 60, KCM : 300" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:820 -#, fuzzy -#| msgid "offline_timeout + random_offset" -msgid "offline_timeout_random_offset (integer)" -msgstr "offline_timeout + random_offset" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:823 -msgid "" -"When SSSD is in offline mode it keeps probing backend servers in specified " -"time intervals:" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:830 -msgid "" -"This parameter controls the value of the random offset used for the above " -"equation. Final random_offset value will be random number in range:" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:835 +#: sssd.conf.5.xml:798 #, fuzzy -#| msgid "offline_timeout + random_offset" -msgid "[0 - offline_timeout_random_offset]" -msgstr "offline_timeout + random_offset" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:838 -msgid "A value of 0 disables the random offset addition." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:841 -#, fuzzy -#| msgid "Default: 300" -msgid "Default: 30" -msgstr "Par défaut : 300" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:846 -msgid "responder_idle_timeout" -msgstr "" +#| msgid "pam_id_timeout (integer)" +msgid "responder_idle_timeout (integer)" +msgstr "pam_id_timeout (entier)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:849 +#: sssd.conf.5.xml:801 msgid "" "This option specifies the number of seconds that an SSSD responder process " "can be up without being used. This value is limited in order to avoid " @@ -1241,45 +1328,60 @@ msgid "" "built with systemd support and when services are either socket or D-Bus " "activated." msgstr "" +"Cette option spécifie la durée maximale d'inactivité (en secondes) d'un " +"processus répondeur SSSD. Cette limite est imposée afin d'éviter la " +"saturation des ressources système. La valeur minimale acceptable est de 60 " +"secondes. Définir cette option sur 0 (zéro) désactive le délai d'expiration " +"du répondeur. Cette option n'est effective que si SSSD est compilé avec le " +"support de systemd et si les services sont activés via socket ou D-Bus." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:863 sssd.conf.5.xml:1123 sssd.conf.5.xml:2248 +#: sssd.conf.5.xml:815 sssd.conf.5.xml:1079 sssd.conf.5.xml:2285 #: sssd-ldap.5.xml:377 msgid "Default: 300" msgstr "Par défaut : 300" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:868 -msgid "cache_first" -msgstr "" +#: sssd.conf.5.xml:820 +#, fuzzy +#| msgid "ldap_referrals (boolean)" +msgid "cache_first (boolean)" +msgstr "ldap_referrals (booléen)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:871 +#: sssd.conf.5.xml:823 msgid "" "This option specifies whether the responder should query all caches before " "querying the Data Providers." msgstr "" +"Cette option indique si le répondeur doit interroger tous les caches avant " +"d'interroger les fournisseurs de données." #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:883 +#: sssd.conf.5.xml:835 msgid "NSS configuration options" msgstr "Options de configuration NSS" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:885 +#: sssd.conf.5.xml:837 +#, fuzzy +#| msgid "" +#| "These options can be used to configure the Name Service Switch (NSS) " +#| "service." msgid "" -"These options can be used to configure the Name Service Switch (NSS) service." +"These options can be used to configure the Name Service Switch (NSS) service " +"and should be specified under the <quote>[nss]</quote> section." msgstr "" "Ces options peuvent être utilisées pour configurer le service Name Service " "Switch (NSS)." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:890 +#: sssd.conf.5.xml:843 msgid "enum_cache_timeout (integer)" msgstr "enum_cache_timeout (entier)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:893 +#: sssd.conf.5.xml:846 msgid "" "How many seconds should nss_sss cache enumerations (requests for info about " "all users)" @@ -1288,17 +1390,17 @@ msgstr "" "énumérations (requêtes sur les informations de tous les utilisateurs)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:897 +#: sssd.conf.5.xml:850 msgid "Default: 120" msgstr "Par défaut : 120" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:902 +#: sssd.conf.5.xml:855 msgid "entry_cache_nowait_percentage (integer)" msgstr "entry_cache_nowait_percentage (entier)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:905 +#: sssd.conf.5.xml:858 msgid "" "The entry cache can be set to automatically update entries in the background " "if they are requested beyond a percentage of the entry_cache_timeout value " @@ -1309,7 +1411,7 @@ msgstr "" "valeur de entry_cache_timeout pour le domaine." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:911 +#: sssd.conf.5.xml:864 msgid "" "For example, if the domain's entry_cache_timeout is set to 30s and " "entry_cache_nowait_percentage is set to 50 (percent), entries that come in " @@ -1325,7 +1427,7 @@ msgstr "" "cache." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:921 +#: sssd.conf.5.xml:874 msgid "" "Valid values for this option are 0-99 and represent a percentage of the " "entry_cache_timeout for each domain. For performance reasons, this " @@ -1338,17 +1440,17 @@ msgstr "" "de non réponse à moins de 10 secondes (0 pour désactiver l'option)." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:929 sssd.conf.5.xml:2061 +#: sssd.conf.5.xml:882 sssd.conf.5.xml:2093 msgid "Default: 50" msgstr "Par défaut : 50" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:934 +#: sssd.conf.5.xml:887 msgid "entry_negative_timeout (integer)" msgstr "entry_negative_timeout (entier)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:937 +#: sssd.conf.5.xml:890 msgid "" "Specifies for how many seconds nss_sss should cache negative cache hits " "(that is, queries for invalid database entries, like nonexistent ones) " @@ -1360,58 +1462,72 @@ msgstr "" "appel au moteur." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:943 sssd.conf.5.xml:1685 sssd.conf.5.xml:2085 +#: sssd.conf.5.xml:896 sssd.conf.5.xml:1677 sssd.conf.5.xml:2119 msgid "Default: 15" msgstr "Par défaut : 15" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:948 +#: sssd.conf.5.xml:901 msgid "filter_users, filter_groups (string)" msgstr "filter_users, filter_groups (chaîne)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:951 +#: sssd.conf.5.xml:904 msgid "" "Exclude certain users or groups from being fetched from the sss NSS " "database. This is particularly useful for system accounts. This option can " "also be set per-domain or include fully-qualified names to filter only users " "from the particular domain or by a user principal name (UPN)." msgstr "" +"Excluez certains utilisateurs ou groupes de la base de données NSS. Cette " +"option est particulièrement utile pour les comptes système. Elle peut être " +"configurée par domaine ou inclure les noms de domaine complets pour filtrer " +"uniquement les utilisateurs d'un domaine spécifique ou par nom d'utilisateur " +"principal (UPN)." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:959 +#: sssd.conf.5.xml:912 msgid "" "NOTE: The filter_groups option doesn't affect inheritance of nested group " "members, since filtering happens after they are propagated for returning via " "NSS. E.g. a group having a member group filtered out will still have the " "member users of the latter listed." msgstr "" +"REMARQUE : L’option filter_groups n’affecte pas l’héritage des membres de " +"groupes imbriqués, car le filtrage intervient après leur propagation pour le " +"retour via NSS. Par exemple, un groupe dont un sous-groupe est exclu " +"affichera toujours les utilisateurs membres de ce dernier." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:967 +#: sssd.conf.5.xml:920 msgid "Default: root" msgstr "Par défaut : root" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:972 -msgid "filter_users_in_groups (bool)" +#: sssd.conf.5.xml:925 +#, fuzzy +#| msgid "filter_users_in_groups (bool)" +msgid "filter_users_in_groups (boolean)" msgstr "filter_users_in_groups (booléen)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:975 +#: sssd.conf.5.xml:928 +#, fuzzy +#| msgid "" +#| "If you want filtered user still be group members set this option to false." msgid "" -"If you want filtered user still be group members set this option to false." +"If you want filtered users to remain group members set this option to false" msgstr "" "Mettre cette option à « false » si les utilisateurs filtrés doivent rester " "membres de groupes." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:986 +#: sssd.conf.5.xml:939 msgid "fallback_homedir (string)" msgstr "fallback_homedir (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:989 +#: sssd.conf.5.xml:942 msgid "" "Set a default template for a user's home directory if one is not specified " "explicitly by the domain's data provider." @@ -1420,7 +1536,7 @@ msgstr "" "explicitement spécifié par le fournisseur de données du domaine." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:994 +#: sssd.conf.5.xml:947 msgid "" "The available values for this option are the same as for override_homedir." msgstr "" @@ -1428,7 +1544,7 @@ msgstr "" "override_homedir." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1000 +#: sssd.conf.5.xml:953 #, no-wrap msgid "" "fallback_homedir = /home/%u\n" @@ -1438,25 +1554,25 @@ msgstr "" " " #. type: Content of: <varlistentry><listitem><para> -#: sssd.conf.5.xml:998 sssd.conf.5.xml:1557 sssd.conf.5.xml:1576 -#: sssd.conf.5.xml:1653 sssd-krb5.5.xml:451 include/override_homedir.xml:78 +#: sssd.conf.5.xml:951 sssd.conf.5.xml:1524 sssd.conf.5.xml:1543 +#: sssd.conf.5.xml:1645 sssd-krb5.5.xml:451 include/override_homedir.xml:78 msgid "example: <placeholder type=\"programlisting\" id=\"0\"/>" msgstr "exemple : <placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1004 +#: sssd.conf.5.xml:957 msgid "Default: not set (no substitution for unset home directories)" msgstr "" "Par défaut : non défini (aucune substitution pour les répertoires d'accueil " "non définis)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1010 +#: sssd.conf.5.xml:963 msgid "override_shell (string)" msgstr "override_shell (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1013 +#: sssd.conf.5.xml:966 msgid "" "Override the login shell for all users. This option supersedes any other " "shell options if it takes effect and can be set either in the [nss] section " @@ -1468,17 +1584,17 @@ msgstr "" "section [nss], soit par domaine." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1019 +#: sssd.conf.5.xml:972 msgid "Default: not set (SSSD will use the value retrieved from LDAP)" msgstr "Par défaut : indéfini (SSSD utilisera la valeur récupérée de LDAP)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1025 +#: sssd.conf.5.xml:978 msgid "allowed_shells (string)" msgstr "allowed_shells (chaîne)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1028 +#: sssd.conf.5.xml:981 msgid "" "Restrict user shell to one of the listed values. The order of evaluation is:" msgstr "" @@ -1486,14 +1602,14 @@ msgstr "" "indiquées. L'ordre d'évaluation est :" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1031 +#: sssd.conf.5.xml:984 msgid "1. If the shell is present in <quote>/etc/shells</quote>, it is used." msgstr "" "1. Si l'interpréteur de commandes est présent dans <quote>/etc/shells</quote>" ", il est utilisé." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1035 +#: sssd.conf.5.xml:988 msgid "" "2. If the shell is in the allowed_shells list but not in <quote>/etc/shells</" "quote>, use the value of the shell_fallback parameter." @@ -1503,7 +1619,7 @@ msgstr "" "shell_fallback » sera utilisée." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1040 +#: sssd.conf.5.xml:993 msgid "" "3. If the shell is not in the allowed_shells list and not in <quote>/etc/" "shells</quote>, a nologin shell is used." @@ -1512,27 +1628,33 @@ msgstr "" "ni dans <quote>/etc/shells</quote>, une connexion sans shell est utilisée." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1045 +#: sssd.conf.5.xml:998 msgid "The wildcard (*) can be used to allow any shell." msgstr "" +"Le caractère générique (*) peut être utilisé pour autoriser n'importe quel " +"shell." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1048 +#: sssd.conf.5.xml:1001 msgid "" "The (*) is useful if you want to use shell_fallback in case that user's " "shell is not in <quote>/etc/shells</quote> and maintaining list of all " "allowed shells in allowed_shells would be to much overhead." msgstr "" +"L'astérisque (*) est utile si vous souhaitez utiliser shell_fallback au cas " +"où le shell de cet utilisateur ne se trouverait pas dans <quote>/etc/shells</" +"quote> et que la maintenance d'une liste de tous les shells autorisés dans " +"allowed_shells représenterait une surcharge trop importante." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1055 +#: sssd.conf.5.xml:1008 msgid "An empty string for shell is passed as-is to libc." msgstr "" "Une chaîne vide pour l'interpréteur de commandes est passée telle quelle est " "à la libc." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1058 +#: sssd.conf.5.xml:1011 msgid "" "The <quote>/etc/shells</quote> is only read on SSSD start up, which means " "that a restart of the SSSD is required in case a new shell is installed." @@ -1542,31 +1664,31 @@ msgstr "" "est installé." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1062 +#: sssd.conf.5.xml:1015 msgid "Default: Not set. The user shell is automatically used." msgstr "" "Par défaut : non défini. L'interpréteur de commandes de l'utilisateur est " "utilisé automatiquement." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1067 +#: sssd.conf.5.xml:1020 msgid "vetoed_shells (string)" msgstr "vetoed_shells (chaîne)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1070 +#: sssd.conf.5.xml:1023 msgid "Replace any instance of these shells with the shell_fallback" msgstr "" "Remplace toutes les occurences de ces interpréteurs de commandes par " "l'interpréteur de commandes par défaut" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1075 +#: sssd.conf.5.xml:1031 msgid "shell_fallback (string)" msgstr "shell_fallback (chaîne)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1078 +#: sssd.conf.5.xml:1034 msgid "" "The default shell to use if an allowed shell is not installed on the machine." msgstr "" @@ -1574,17 +1696,17 @@ msgstr "" "commandes autorisé n'est pas installé sur la machine." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1082 +#: sssd.conf.5.xml:1038 msgid "Default: /bin/sh" msgstr "Par défaut : /bin/sh" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1087 -msgid "default_shell" -msgstr "default_shell" +#: sssd.conf.5.xml:1043 +msgid "default_shell (string)" +msgstr "default_shell (chaîne)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1090 +#: sssd.conf.5.xml:1046 msgid "" "The default shell to use if the provider does not return one during lookup. " "This option can be specified globally in the [nss] section or per-domain." @@ -1594,7 +1716,7 @@ msgstr "" "choix soit dans la section [nss], soit par domaine." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1096 +#: sssd.conf.5.xml:1052 msgid "" "Default: not set (Return NULL if no shell is specified and rely on libc to " "substitute something sensible when necessary, usually /bin/sh)" @@ -1604,12 +1726,12 @@ msgstr "" "nécessaire, habituellement /bin/sh)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1103 sssd.conf.5.xml:1483 +#: sssd.conf.5.xml:1059 sssd.conf.5.xml:1450 msgid "get_domains_timeout (int)" msgstr "get_domains_timeout (int)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1106 sssd.conf.5.xml:1486 +#: sssd.conf.5.xml:1062 sssd.conf.5.xml:1453 msgid "" "Specifies time in seconds for which the list of subdomains will be " "considered valid." @@ -1617,123 +1739,150 @@ msgstr "" "Spécifie la durée en secondes pendant laquelle la liste de sous-domaines est " "jugée valide." +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1066 sssd.conf.5.xml:1457 sssd.conf.5.xml:1788 +#: sssd.conf.5.xml:2862 sssd-ldap.5.xml:550 +msgid "Default: 60" +msgstr "Par défaut : 60" + #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1115 -#, fuzzy -#| msgid "enum_cache_timeout (integer)" +#: sssd.conf.5.xml:1071 msgid "memcache_timeout (integer)" -msgstr "enum_cache_timeout (entier)" +msgstr "memcache_timeout (entier)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1118 +#: sssd.conf.5.xml:1074 msgid "" "Specifies time in seconds for which records in the in-memory cache will be " "valid. Setting this option to zero will disable the in-memory cache." msgstr "" +"Spécifie la durée, en secondes, de validité des enregistrements dans le " +"cache en mémoire. Définir cette option à zéro désactive le cache en mémoire." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1126 +#: sssd.conf.5.xml:1082 msgid "" "WARNING: Disabling the in-memory cache will have significant negative impact " "on SSSD's performance and should only be used for testing." msgstr "" +"AVERTISSEMENT : La désactivation du cache en mémoire aura un impact négatif " +"important sur les performances de SSSD et ne doit être utilisée qu’à des " +"fins de test." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1132 sssd.conf.5.xml:1157 sssd.conf.5.xml:1182 -#: sssd.conf.5.xml:1207 sssd.conf.5.xml:1234 +#: sssd.conf.5.xml:1088 sssd.conf.5.xml:1113 sssd.conf.5.xml:1138 +#: sssd.conf.5.xml:1163 sssd.conf.5.xml:1190 msgid "" "NOTE: If the environment variable SSS_NSS_USE_MEMCACHE is set to \"NO\", " "client applications will not use the fast in-memory cache." msgstr "" +"REMARQUE : Si la variable d'environnement SSS_NSS_USE_MEMCACHE est définie " +"sur « NO », les applications clientes n'utiliseront pas le cache en mémoire " +"rapide." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1140 +#: sssd.conf.5.xml:1096 #, fuzzy #| msgid "enum_cache_timeout (integer)" msgid "memcache_size_passwd (integer)" msgstr "enum_cache_timeout (entier)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1143 +#: sssd.conf.5.xml:1099 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for passwd requests. Setting the size to 0 will disable the passwd in-" "memory cache." msgstr "" +"Taille (en mégaoctets) de la table de données allouée dans le cache mémoire " +"rapide pour les requêtes passwd. Définir cette taille à 0 désactive le cache " +"mémoire passwd." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1149 sssd.conf.5.xml:2888 sssd-ldap.5.xml:604 +#: sssd.conf.5.xml:1105 sssd.conf.5.xml:3013 sssd-ldap.5.xml:604 msgid "Default: 8" msgstr "Par défaut : 8" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1152 sssd.conf.5.xml:1177 sssd.conf.5.xml:1202 -#: sssd.conf.5.xml:1229 +#: sssd.conf.5.xml:1108 sssd.conf.5.xml:1133 sssd.conf.5.xml:1158 +#: sssd.conf.5.xml:1185 msgid "" "WARNING: Disabled or too small in-memory cache can have significant negative " "impact on SSSD's performance." msgstr "" +"AVERTISSEMENT : Un cache en mémoire désactivé ou trop petit peut avoir un " +"impact négatif important sur les performances de SSSD." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1165 +#: sssd.conf.5.xml:1121 #, fuzzy #| msgid "enum_cache_timeout (integer)" msgid "memcache_size_group (integer)" msgstr "enum_cache_timeout (entier)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1168 +#: sssd.conf.5.xml:1124 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for group requests. Setting the size to 0 will disable the group in-memory " "cache." msgstr "" +"Taille (en mégaoctets) de la table de données allouée dans le cache mémoire " +"rapide pour les requêtes groupées. Définir cette taille à 0 désactive le " +"cache mémoire groupé." #. type: Content of: <variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1174 sssd.conf.5.xml:1226 sssd.conf.5.xml:3656 +#: sssd.conf.5.xml:1130 sssd.conf.5.xml:1182 sssd.conf.5.xml:3835 #: sssd-ldap.5.xml:534 sssd-ldap.5.xml:581 include/failover.xml:116 #: include/krb5_options.xml:11 msgid "Default: 6" msgstr "Par défaut : 6" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1190 +#: sssd.conf.5.xml:1146 #, fuzzy #| msgid "enum_cache_timeout (integer)" msgid "memcache_size_initgroups (integer)" msgstr "enum_cache_timeout (entier)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1193 +#: sssd.conf.5.xml:1149 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for initgroups requests. Setting the size to 0 will disable the initgroups " "in-memory cache." msgstr "" +"Taille (en mégaoctets) de la table de données allouée dans le cache mémoire " +"rapide pour les requêtes initgroups. Définir cette taille à 0 désactive le " +"cache mémoire des initgroups." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1215 +#: sssd.conf.5.xml:1171 #, fuzzy #| msgid "enum_cache_timeout (integer)" msgid "memcache_size_sid (integer)" msgstr "enum_cache_timeout (entier)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1218 +#: sssd.conf.5.xml:1174 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for SID related requests. Only SID-by-ID and ID-by-SID requests are " "currently cached in fast in-memory cache. Setting the size to 0 will " "disable the SID in-memory cache." msgstr "" +"Taille (en mégaoctets) de la table de données allouée dans le cache mémoire " +"rapide pour les requêtes liées au SID. Seules les requêtes SID-by-ID et ID-" +"by-SID sont actuellement mises en cache. Définir la taille à 0 désactivera " +"le cache mémoire des SID." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1242 sssd-ifp.5.xml:90 +#: sssd.conf.5.xml:1198 sssd-ifp.5.xml:90 msgid "user_attributes (string)" msgstr "user_attributes (chaîne)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1245 +#: sssd.conf.5.xml:1201 msgid "" "Some of the additional NSS responder requests can return more attributes " "than just the POSIX ones defined by the NSS interface. The list of " @@ -1742,75 +1891,92 @@ msgid "" "<citerefentry> <refentrytitle>sssd-ifp</refentrytitle> <manvolnum>5</" "manvolnum> </citerefentry> for details) but with no default values." msgstr "" +"Certaines requêtes supplémentaires du répondeur NSS peuvent renvoyer plus " +"d'attributs que ceux définis par l'interface NSS au format POSIX. La liste " +"des attributs est contrôlée par cette option. Elle est gérée de la même " +"manière que l'option `user_attributes` du répondeur InfoPipe (voir `sssd-" +"ifp` pour plus de détails), mais sans valeurs par défaut." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1258 +#: sssd.conf.5.xml:1214 msgid "" "To make configuration more easy the NSS responder will check the InfoPipe " "option if it is not set for the NSS responder." msgstr "" +"Pour simplifier la configuration, le répondeur NSS vérifiera l'option " +"InfoPipe si elle n'est pas définie pour le répondeur NSS." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1263 +#: sssd.conf.5.xml:1219 msgid "Default: not set, fallback to InfoPipe option" msgstr "Par défaut : non défini, repli sur l'option InfoPipe" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1268 +#: sssd.conf.5.xml:1224 msgid "pwfield (string)" -msgstr "" +msgstr "pwfield (chaîne)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1271 +#: sssd.conf.5.xml:1227 msgid "" "The value that NSS operations that return users or groups will return for " "the <quote>password</quote> field." msgstr "" +"La valeur que les opérations NSS qui renvoient des utilisateurs ou des " +"groupes renverront pour le champ <quote>mot de passe</quote>." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1276 -#, fuzzy -#| msgid "Default: <quote>permit</quote>" -msgid "Default: <quote>*</quote>" -msgstr "Par défaut : <quote>permit</quote>" +#: sssd.conf.5.xml:1232 +msgid "" +"This option can also be set per-domain, which overwrites the value in the " +"<quote>[nss]</quote> section for that domain. This is particularly useful " +"when using a proxy domain with <option>proxy_lib_name=files</option> and a " +"<option>proxy_pam_target</option> other than <quote>sssd-shadowutils</" +"quote>. In that case, SSSD returns <quote>*</quote> for the password field " +"by default, which causes <command>pam_unix</command> to treat all accounts " +"as locked. Setting <option>pwfield = x</option> in the domain section " +"restores the expected behavior." +msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1279 +#: sssd.conf.5.xml:1246 #, fuzzy -#| msgid "This option can also be set per-domain." -msgid "" -"Note: This option can also be set per-domain which overwrites the value in " -"[nss] section." -msgstr "Cette option peut aussi être définie pour chaque domaine." +#| msgid "Default: <quote>permit</quote>" +msgid "Default: <quote>*</quote>" +msgstr "Par défaut : <quote>permit</quote>" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1283 +#: sssd.conf.5.xml:1249 msgid "" -"Default: <quote>not set</quote> (remote domains), <quote>x</quote> (proxy " -"domain with nss_files and sssd-shadowutils target)" +"Default (per-domain): <quote>not set</quote> (remote domains), <quote>x</" +"quote> (proxy domain with nss_files and sssd-shadowutils target)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:1292 +#: sssd.conf.5.xml:1258 msgid "PAM configuration options" msgstr "Options de configuration de PAM" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:1294 +#: sssd.conf.5.xml:1260 +#, fuzzy +#| msgid "" +#| "These options can be used to configure the Pluggable Authentication " +#| "Module (PAM) service." msgid "" "These options can be used to configure the Pluggable Authentication Module " -"(PAM) service." +"(PAM) service and should be specified under the <quote>[pam]</quote> section." msgstr "" "Ces options permettent de configurer le service Pluggable Authentication " "Module (PAM)." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1299 +#: sssd.conf.5.xml:1266 msgid "offline_credentials_expiration (integer)" msgstr "offline_credentials_expiration (entier)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1302 +#: sssd.conf.5.xml:1269 msgid "" "If the authentication provider is offline, how long should we allow cached " "logins (in days since the last successful online login)." @@ -1820,17 +1986,17 @@ msgstr "" "connexion réussie)." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1307 sssd.conf.5.xml:1320 +#: sssd.conf.5.xml:1274 sssd.conf.5.xml:1287 msgid "Default: 0 (No limit)" msgstr "Par défaut : 0 (pas de limite)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1313 +#: sssd.conf.5.xml:1280 msgid "offline_failed_login_attempts (integer)" msgstr "offline_failed_login_attempts (entier)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1316 +#: sssd.conf.5.xml:1283 msgid "" "If the authentication provider is offline, how many failed login attempts " "are allowed." @@ -1839,12 +2005,12 @@ msgstr "" "échouées sont autorisées." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1326 +#: sssd.conf.5.xml:1293 msgid "offline_failed_login_delay (integer)" msgstr "offline_failed_login_delay (entier)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1329 +#: sssd.conf.5.xml:1296 msgid "" "The time in minutes which has to pass after offline_failed_login_attempts " "has been reached before a new login attempt is possible." @@ -1854,7 +2020,7 @@ msgstr "" "soit possible." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1334 +#: sssd.conf.5.xml:1301 msgid "" "If set to 0 the user cannot authenticate offline if " "offline_failed_login_attempts has been reached. Only a successful online " @@ -1865,17 +2031,17 @@ msgstr "" "connexion réussie en ligne peut réactiver l'authentification." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1340 sssd.conf.5.xml:1450 +#: sssd.conf.5.xml:1307 sssd.conf.5.xml:1417 msgid "Default: 5" msgstr "Par défaut : 5" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1346 +#: sssd.conf.5.xml:1313 msgid "pam_verbosity (integer)" msgstr "pam_verbosity (entier)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1349 +#: sssd.conf.5.xml:1316 msgid "" "Controls what kind of messages are shown to the user during authentication. " "The higher the number to more messages are displayed." @@ -1885,99 +2051,109 @@ msgstr "" "affichés sera important." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1354 +#: sssd.conf.5.xml:1321 msgid "Currently sssd supports the following values:" msgstr "Actuellement sssd supporte les valeurs suivantes :" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1357 +#: sssd.conf.5.xml:1324 msgid "<emphasis>0</emphasis>: do not show any message" msgstr "<emphasis>0</emphasis> : ne pas afficher de message" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1360 +#: sssd.conf.5.xml:1327 msgid "<emphasis>1</emphasis>: show only important messages" msgstr "<emphasis>1</emphasis> : afficher seulement les messages importants" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1364 +#: sssd.conf.5.xml:1331 msgid "<emphasis>2</emphasis>: show informational messages" msgstr "<emphasis>2</emphasis> : afficher les messages d'information" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1367 +#: sssd.conf.5.xml:1334 msgid "<emphasis>3</emphasis>: show all messages and debug information" msgstr "" "<emphasis>3</emphasis> : afficher tous les messages et informations de " "débogage" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1371 sssd.8.xml:63 +#: sssd.conf.5.xml:1338 sssd.8.xml:63 msgid "Default: 1" msgstr "Par défaut : 1" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1377 +#: sssd.conf.5.xml:1344 #, fuzzy #| msgid "ad_access_filter (string)" msgid "pam_response_filter (string)" msgstr "ad_access_filter (chaîne)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1380 +#: sssd.conf.5.xml:1347 msgid "" "A comma separated list of strings which allows to remove (filter) data sent " "by the PAM responder to pam_sss PAM module. There are different kind of " "responses sent to pam_sss e.g. messages displayed to the user or environment " "variables which should be set by pam_sss." msgstr "" +"Une liste de chaînes de caractères séparées par des virgules permettant de " +"supprimer (filtrer) les données envoyées par le répondeur PAM au module PAM " +"pam_sss. Différents types de réponses sont envoyés à pam_sss, par exemple " +"des messages affichés à l'utilisateur ou des variables d'environnement que " +"pam_sss doit définir." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1388 +#: sssd.conf.5.xml:1355 msgid "" "While messages already can be controlled with the help of the pam_verbosity " "option this option allows to filter out other kind of responses as well." msgstr "" +"Bien que les messages puissent déjà être contrôlés grâce à l'option " +"pam_verbosity, cette option permet également de filtrer d'autres types de " +"réponses." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1395 +#: sssd.conf.5.xml:1362 msgid "ENV" -msgstr "" +msgstr "ENV" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1396 +#: sssd.conf.5.xml:1363 msgid "Do not send any environment variables to any service." -msgstr "" +msgstr "N'envoyez aucune variable d'environnement à aucun service." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1399 +#: sssd.conf.5.xml:1366 msgid "ENV:var_name" -msgstr "" +msgstr "ENV:var_name" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1400 +#: sssd.conf.5.xml:1367 msgid "Do not send environment variable var_name to any service." -msgstr "" +msgstr "Ne transmettez la variable d'environnement var_name à aucun service." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1404 +#: sssd.conf.5.xml:1371 msgid "ENV:var_name:service" -msgstr "" +msgstr "ENV:var_name:service" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1405 +#: sssd.conf.5.xml:1372 msgid "Do not send environment variable var_name to service." -msgstr "" +msgstr "Ne transmettez pas la variable d'environnement var_name au service." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1393 +#: sssd.conf.5.xml:1360 msgid "" "Currently the following filters are supported: <placeholder " "type=\"variablelist\" id=\"0\"/>" msgstr "" +"Les filtres suivants sont actuellement pris en charge : <placeholder " +"type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1412 +#: sssd.conf.5.xml:1379 msgid "" "The list of strings can either be the list of filters which would set this " "list of filters and overwrite the defaults. Or each element of the list can " @@ -1986,25 +2162,32 @@ msgid "" "that either all list elements must have a '+' or '-' prefix or none. It is " "considered as an error to mix both styles." msgstr "" +"La liste de chaînes de caractères peut soit constituer la liste des filtres, " +"qui définira cette liste et remplacera les valeurs par défaut, soit être " +"précédée d'un caractère « + » ou « - » pour ajouter ou supprimer le filtre " +"des valeurs par défaut existantes. Veuillez noter que tous les éléments de " +"la liste doivent être précédés d'un « + » ou d'un « - », ou aucun. Mélanger " +"les deux styles est considéré comme une erreur." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1423 +#: sssd.conf.5.xml:1390 msgid "Default: ENV:KRB5CCNAME:sudo, ENV:KRB5CCNAME:sudo-i" -msgstr "" +msgstr "Valeur par défaut : ENV:KRB5CCNAME:sudo, ENV:KRB5CCNAME:sudo-i" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1426 +#: sssd.conf.5.xml:1393 msgid "" "Example: -ENV:KRB5CCNAME:sudo-i will remove the filter from the default list" msgstr "" +"Exemple : -ENV:KRB5CCNAME:sudo-i supprimera le filtre de la liste par défaut" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1433 +#: sssd.conf.5.xml:1400 msgid "pam_id_timeout (integer)" msgstr "pam_id_timeout (entier)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1436 +#: sssd.conf.5.xml:1403 msgid "" "For any PAM request while SSSD is online, the SSSD will attempt to " "immediately update the cached identity information for the user in order to " @@ -2016,7 +2199,7 @@ msgstr "" "les dernières informations." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1442 +#: sssd.conf.5.xml:1409 msgid "" "A complete PAM conversation may perform multiple PAM requests, such as " "account management and session opening. This option controls (on a per-" @@ -2030,17 +2213,17 @@ msgstr "" "fournisseur d'identité." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1456 +#: sssd.conf.5.xml:1423 msgid "pam_pwd_expiration_warning (integer)" msgstr "pam_pwd_expiration_warning (entier)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1459 sssd.conf.5.xml:2912 +#: sssd.conf.5.xml:1426 sssd.conf.5.xml:3037 msgid "Display a warning N days before the password expires." msgstr "Afficher une alerte N jours avant l'expiration du mot de passe." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1462 +#: sssd.conf.5.xml:1429 msgid "" "Please note that the backend server has to provide information about the " "expiration time of the password. If this information is missing, sssd " @@ -2051,7 +2234,7 @@ msgstr "" "ne peut afficher de message d'alerte." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1468 sssd.conf.5.xml:2915 +#: sssd.conf.5.xml:1435 sssd.conf.5.xml:3040 msgid "" "If zero is set, then this filter is not applied, i.e. if the expiration " "warning was received from backend server, it will automatically be displayed." @@ -2061,7 +2244,7 @@ msgstr "" "sera automatiquement affiché." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1473 +#: sssd.conf.5.xml:1440 msgid "" "This setting can be overridden by setting <emphasis>pwd_expiration_warning</" "emphasis> for a particular domain." @@ -2070,18 +2253,18 @@ msgstr "" "pwd_expiration_warning</emphasis> pour un domaine particulier." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1478 sssd.conf.5.xml:3913 sssd-ldap.5.xml:662 +#: sssd.conf.5.xml:1445 sssd.conf.5.xml:4118 sssd-ldap.5.xml:662 #: sssd-ldap.5.xml:1733 sssd.8.xml:79 msgid "Default: 0" msgstr "Par défaut : 0" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1495 +#: sssd.conf.5.xml:1462 msgid "pam_trusted_users (string)" msgstr "pam_trusted_users (chaîne)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1498 +#: sssd.conf.5.xml:1465 msgid "" "Specifies the comma-separated list of UID values or user names that are " "allowed to run PAM conversations against trusted domains. Users not " @@ -2089,38 +2272,48 @@ msgid "" "<quote>pam_public_domains</quote>. User names are resolved to UIDs at " "startup." msgstr "" +"Spécifie la liste, séparée par des virgules, des UID ou des noms " +"d'utilisateur autorisés à effectuer des conversations PAM sur les domaines " +"de confiance. Les utilisateurs non inclus dans cette liste peuvent " +"uniquement accéder aux domaines marqués comme publics avec " +"`pam_public_domains`. Les noms d'utilisateur sont résolus en UID au " +"démarrage." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1508 +#: sssd.conf.5.xml:1475 msgid "Default: All users are considered trusted by default" -msgstr "" +msgstr "Par défaut : Tous les utilisateurs sont considérés comme fiables." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1512 +#: sssd.conf.5.xml:1479 msgid "" "Please note that UID 0 is always allowed to access the PAM responder even in " "case it is not in the pam_trusted_users list." msgstr "" +"Veuillez noter que l'UID 0 est toujours autorisé à accéder au répondeur PAM " +"même s'il ne figure pas dans la liste pam_trusted_users." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1519 +#: sssd.conf.5.xml:1486 msgid "pam_public_domains (string)" msgstr "pam_public_domains (chaîne)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1522 +#: sssd.conf.5.xml:1489 msgid "" "Specifies the comma-separated list of domain names that are accessible even " "to untrusted users." msgstr "" +"Spécifie la liste, séparée par des virgules, des noms de domaine accessibles " +"même aux utilisateurs non fiables." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1526 +#: sssd.conf.5.xml:1493 msgid "Two special values for pam_public_domains option are defined:" msgstr "Deux valeurs spéciales pour l'option pam_public_domains sont définies :" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1530 +#: sssd.conf.5.xml:1497 msgid "" "all (Untrusted users are allowed to access all domains in PAM responder.)" msgstr "" @@ -2128,7 +2321,7 @@ msgstr "" "à tous les domaines PAM dans le répondeur.)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1534 +#: sssd.conf.5.xml:1501 msgid "" "none (Untrusted users are not allowed to access any domains PAM in " "responder.)" @@ -2137,138 +2330,201 @@ msgstr "" "autorisés à accéder à un des domaines PAM dans le répondeur.)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1538 sssd.conf.5.xml:1563 sssd.conf.5.xml:1582 -#: sssd.conf.5.xml:1824 sssd.conf.5.xml:3842 sssd-ldap.5.xml:1270 +#: sssd.conf.5.xml:1505 sssd.conf.5.xml:1530 sssd.conf.5.xml:1549 +#: sssd.conf.5.xml:1821 sssd.conf.5.xml:4048 sssd-ldap.5.xml:1270 msgid "Default: none" msgstr "Par défaut : aucun" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1543 +#: sssd.conf.5.xml:1510 msgid "pam_account_expired_message (string)" msgstr "pam_account_expired_message (chaîne)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1546 +#: sssd.conf.5.xml:1513 msgid "" "Allows a custom expiration message to be set, replacing the default " "'Permission denied' message." msgstr "" +"Permet de définir un message d'expiration personnalisé, remplaçant le " +"message par défaut « Permission refusée »." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1551 +#: sssd.conf.5.xml:1518 msgid "" "Note: Please be aware that message is only printed for the SSH service " "unless pam_verbosity is set to 3 (show all messages and debug information)." msgstr "" +"Remarque : Veuillez noter que ce message n'est imprimé que pour le service " +"SSH, sauf si pam_verbosity est défini sur 3 (afficher tous les messages et " +"les informations de débogage)." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1559 +#: sssd.conf.5.xml:1526 #, no-wrap msgid "" "pam_account_expired_message = Account expired, please contact help desk.\n" " " msgstr "" +"pam_account_expired_message = Compte expiré, veuillez contacter le service " +"d'assistance.\n" +" " #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1568 +#: sssd.conf.5.xml:1535 msgid "pam_account_locked_message (string)" -msgstr "" +msgstr "pam_account_locked_message (chaîne)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1571 +#: sssd.conf.5.xml:1538 msgid "" "Allows a custom lockout message to be set, replacing the default 'Permission " "denied' message." msgstr "" +"Permet de définir un message de verrouillage personnalisé, remplaçant le " +"message par défaut « Permission refusée »." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1578 +#: sssd.conf.5.xml:1545 #, no-wrap msgid "" "pam_account_locked_message = Account locked, please contact help desk.\n" " " msgstr "" +"pam_account_locked_message = Compte verrouillé, veuillez contacter le " +"service d'assistance.\n" +" " #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1587 +#: sssd.conf.5.xml:1554 #, fuzzy #| msgid "ldap_chpass_update_last_change (bool)" -msgid "pam_passkey_auth (bool)" +msgid "pam_passkey_auth (boolean)" msgstr "ldap_chpass_update_last_change (bool)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1590 +#: sssd.conf.5.xml:1557 msgid "Enable passkey device based authentication." -msgstr "" +msgstr "Activer l'authentification par clé d'accès." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1593 sssd.conf.5.xml:1910 sssd-ad.5.xml:1286 +#: sssd.conf.5.xml:1560 sssd.conf.5.xml:1907 sssd-ad.5.xml:1279 #: sss_rpcidmapd.5.xml:76 msgid "Default: True" msgstr "Par défaut : True" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1598 -msgid "passkey_debug_libfido2 (bool)" -msgstr "" +#: sssd.conf.5.xml:1565 +#, fuzzy +#| msgid "ldap_user_certificate (string)" +msgid "passkey_debug_libfido2 (boolean)" +msgstr "ldap_user_certificate (chaîne)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1601 +#: sssd.conf.5.xml:1568 msgid "Enable libfido2 library debug messages." -msgstr "" +msgstr "Activer les messages de débogage de la bibliothèque libfido2." #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1604 sssd.conf.5.xml:1618 sssd-ldap.5.xml:727 -#: sssd-ldap.5.xml:752 sssd-ldap.5.xml:848 sssd-ldap.5.xml:1356 -#: sssd-ad.5.xml:506 sssd-ad.5.xml:582 sssd-ad.5.xml:1155 +#: sssd.conf.5.xml:1571 sssd.conf.5.xml:1585 sssd.conf.5.xml:4781 +#: sssd-ldap.5.xml:727 sssd-ldap.5.xml:752 sssd-ldap.5.xml:848 +#: sssd-ldap.5.xml:1356 sssd-ad.5.xml:506 sssd-ad.5.xml:582 sssd-ad.5.xml:1160 #: include/ldap_id_mapping.xml:250 msgid "Default: False" msgstr "Par défaut : False" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1609 -msgid "pam_cert_auth (bool)" -msgstr "" +#: sssd.conf.5.xml:1576 +#, fuzzy +#| msgid "ldap_chpass_update_last_change (bool)" +msgid "pam_cert_auth (boolean)" +msgstr "ldap_chpass_update_last_change (bool)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1612 +#: sssd.conf.5.xml:1579 msgid "" "Enable certificate based Smartcard authentication. Since this requires " "additional communication with the Smartcard which will delay the " "authentication process this option is disabled by default." msgstr "" +"Activer l'authentification par carte à puce basée sur un certificat. Cette " +"option, qui nécessite une communication supplémentaire avec la carte à puce " +"et ralentit le processus d'authentification, est désactivée par défaut." + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1588 +msgid "" +"Note: In case OpenSC is used for Smartcard access SSSD supports the " +"filesystem caching in OpenSC when enabled in opensc.conf. The cached files " +"are located in a common <quote>opensc</quote> directory in SSSD's state " +"directory. The behaviour can be changed in opensc.conf" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> +#: sssd.conf.5.xml:1597 +#, no-wrap +msgid "" +"app /usr/libexec/sssd/p11_child {\n" +" framework pkcs15 {\n" +" use_file_caching = no;\n" +" }\n" +"}\n" +"app /usr/libexec/sssd/krb5_child {\n" +" framework pkcs15 {\n" +" use_file_caching = no;\n" +" }\n" +"}\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1595 +#, fuzzy +#| msgid "Example: <placeholder type=\"programlisting\" id=\"0\"/>" +msgid "" +"Example opensc.conf (*): <placeholder type=\"programlisting\" id=\"0\"/>" +msgstr "Exemple : <placeholder type=\"programlisting\" id=\"0\"/>" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1610 +msgid "" +"(*) The actual <quote>libexec</quote> directory for p11_child and krb5_child " +"depends on the distribution." +msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1623 +#: sssd.conf.5.xml:1615 msgid "pam_cert_db_path (string)" -msgstr "" +msgstr "pam_cert_db_path (chaîne)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1626 +#: sssd.conf.5.xml:1618 msgid "The path to the certificate database." -msgstr "" +msgstr "Le chemin d'accès à la base de données des certificats." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1629 sssd.conf.5.xml:2163 sssd.conf.5.xml:4338 +#: sssd.conf.5.xml:1621 sssd.conf.5.xml:2199 sssd.conf.5.xml:4543 msgid "Default:" -msgstr "" +msgstr "Défaut:" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1631 sssd.conf.5.xml:2165 +#: sssd.conf.5.xml:1623 sssd.conf.5.xml:2201 msgid "" "/etc/sssd/pki/sssd_auth_ca_db.pem (path to a file with trusted CA " "certificates in PEM format)" msgstr "" +"/etc/sssd/pki/sssd_auth_ca_db.pem (chemin d'accès à un fichier contenant les " +"certificats d'autorité de certification de confiance au format PEM)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1641 +#: sssd.conf.5.xml:1633 #, fuzzy #| msgid "ldap_user_certificate (string)" msgid "pam_cert_verification (string)" msgstr "ldap_user_certificate (chaîne)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1644 +#: sssd.conf.5.xml:1636 msgid "" "With this parameter the PAM certificate verification can be tuned with a " "comma separated list of options that override the " @@ -2276,13 +2532,14 @@ msgid "" "section. Supported options are the same of <quote>certificate_verification</" "quote>." msgstr "" +"Ce paramètre permet de configurer la vérification du certificat PAM à l'aide " +"d'une liste d'options séparées par des virgules, qui remplacent la valeur de " +"`certificate_verification` dans la section `[sssd]`. Les options prises en " +"charge sont les mêmes que celles de `certificate_verification`." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1655 -#, fuzzy, no-wrap -#| msgid "" -#| "subdomain_inherit = ldap_purge_cache_timeout\n" -#| " " +#: sssd.conf.5.xml:1647 +#, no-wrap msgid "" "pam_cert_verification = partial_chain\n" " " @@ -2291,71 +2548,79 @@ msgstr "" " " #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1659 +#: sssd.conf.5.xml:1651 msgid "" "Default: not set, i.e. use default <quote>certificate_verification</quote> " "option defined in <quote>[sssd]</quote> section." msgstr "" +"Ce paramètre permet de configurer la vérification du certificat PAM à l'aide " +"d'une liste d'options séparées par des virgules, qui remplacent la valeur de " +"`certificate_verification` dans la section `[sssd]`. Les options prises en " +"charge sont les mêmes que celles de `certificate_verification`." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1666 +#: sssd.conf.5.xml:1658 msgid "p11_child_timeout (integer)" -msgstr "" +msgstr "p11_child_timeout (integer)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1669 +#: sssd.conf.5.xml:1661 msgid "How many seconds will pam_sss wait for p11_child to finish." msgstr "" +"Combien de secondes pam_sss attendra-t-elle pour que p11_child ait terminé ?" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1678 +#: sssd.conf.5.xml:1670 #, fuzzy #| msgid "pam_id_timeout (integer)" msgid "passkey_child_timeout (integer)" msgstr "pam_id_timeout (entier)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1681 +#: sssd.conf.5.xml:1673 msgid "" "How many seconds will the PAM responder wait for passkey_child to finish." msgstr "" +"Combien de secondes pam_sss attendra-t-elle pour que p11_child ait terminé ?" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1690 +#: sssd.conf.5.xml:1682 msgid "pam_app_services (string)" -msgstr "" +msgstr "pam_app_services (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1693 +#: sssd.conf.5.xml:1685 msgid "" "Which PAM services are permitted to contact domains of type " "<quote>application</quote>" -msgstr "" +msgstr "pam_app_services (chaîne de caractères)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1702 -#, fuzzy -#| msgid "ad_gpo_map_service (string)" +#: sssd.conf.5.xml:1694 msgid "pam_p11_allowed_services (string)" -msgstr "ad_gpo_map_service (chaîne)" +msgstr "pam_p11_allowed_services (chaîne)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1705 +#: sssd.conf.5.xml:1697 msgid "" "A comma-separated list of PAM service names for which it will be allowed to " "use Smartcards." msgstr "" +"Liste, séparée par des virgules, des noms de services PAM pour lesquels " +"l'utilisation de cartes à puce sera autorisée." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1720 +#: sssd.conf.5.xml:1712 #, no-wrap msgid "" "pam_p11_allowed_services = +my_pam_service, -login\n" " " msgstr "" +"pam_p11_allowed_services = +my_pam_service, -login\n" +" " #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1709 +#: sssd.conf.5.xml:1701 msgid "" "It is possible to add another PAM service name to the default set by using " "<quote>+service_name</quote> or to explicitly remove a PAM service name from " @@ -2365,83 +2630,99 @@ msgid "" "<quote>my_pam_service</quote>), you would use the following configuration: " "<placeholder type=\"programlisting\" id=\"0\"/>" msgstr "" +"Il est possible d'ajouter un autre nom de service PAM à l'ensemble par " +"défaut en utilisant `<quote>+nom_du_service</quote>` ou de supprimer " +"explicitement un nom de service PAM de l'ensemble par défaut en utilisant " +"`<quote>-nom_du_service</quote>`. Par exemple, pour remplacer le nom de " +"service PAM par défaut pour l'authentification par carte à puce (par " +"exemple, `<quote>login</quote>`) par un nom de service PAM personnalisé (par " +"exemple, `<quote>mon_service_PAM</quote>`), vous utiliserez la configuration " +"suivante : `<placeholder type=\"programlisting\" id=\"0\"/>`" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1724 sssd-ad.5.xml:645 sssd-ad.5.xml:754 sssd-ad.5.xml:812 -#: sssd-ad.5.xml:870 sssd-ad.5.xml:948 +#: sssd.conf.5.xml:1716 sssd-ad.5.xml:645 sssd-ad.5.xml:759 sssd-ad.5.xml:817 +#: sssd-ad.5.xml:875 sssd-ad.5.xml:953 msgid "Default: the default set of PAM service names includes:" -msgstr "" +msgstr "Default: the default set of PAM service names includes:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1729 sssd-ad.5.xml:649 +#: sssd.conf.5.xml:1721 sssd-ad.5.xml:649 msgid "login" -msgstr "" +msgstr "se connecter" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1734 sssd-ad.5.xml:654 +#: sssd.conf.5.xml:1726 sssd-ad.5.xml:654 msgid "su" -msgstr "" +msgstr "sur" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1739 sssd-ad.5.xml:659 +#: sssd.conf.5.xml:1731 sssd-ad.5.xml:659 msgid "su-l" -msgstr "" +msgstr "sur le" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1744 sssd-ad.5.xml:674 +#: sssd.conf.5.xml:1736 sssd-ad.5.xml:674 msgid "gdm-smartcard" -msgstr "" +msgstr "carte à puce gdm" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1749 sssd-ad.5.xml:669 +#: sssd.conf.5.xml:1741 sssd-ad.5.xml:669 msgid "gdm-password" -msgstr "" +msgstr "carte à puce gdm" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1754 +#: sssd.conf.5.xml:1746 msgid "gdm-switchable-auth" -msgstr "" +msgstr "Authentification commutable gdm" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1759 sssd-ad.5.xml:679 +#: sssd.conf.5.xml:1751 sssd-ad.5.xml:679 msgid "kdm" +msgstr "kdm" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:1756 sssd-ad.5.xml:694 +msgid "plasmalogin" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1764 sssd-ad.5.xml:957 +#: sssd.conf.5.xml:1761 sssd-ad.5.xml:962 msgid "sudo" -msgstr "" +msgstr "sudo" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1769 sssd-ad.5.xml:962 +#: sssd.conf.5.xml:1766 sssd-ad.5.xml:967 msgid "sudo-i" -msgstr "" +msgstr "sudo-i" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1774 +#: sssd.conf.5.xml:1771 msgid "gnome-screensaver" -msgstr "" +msgstr "économiseur d'écran gnome" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1782 +#: sssd.conf.5.xml:1779 msgid "p11_wait_for_card_timeout (integer)" -msgstr "" +msgstr "p11_wait_for_card_timeout (entier)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1785 +#: sssd.conf.5.xml:1782 msgid "" "If Smartcard authentication is required how many extra seconds in addition " "to p11_child_timeout should the PAM responder wait until a Smartcard is " "inserted." msgstr "" +"Si l'authentification par carte à puce est requise, combien de secondes " +"supplémentaires, en plus de p11_child_timeout, le répondeur PAM doit-il " +"attendre avant qu'une carte à puce soit insérée ?" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1796 +#: sssd.conf.5.xml:1793 msgid "p11_uri (string)" -msgstr "" +msgstr "p11_uri (chaîne)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1799 +#: sssd.conf.5.xml:1796 msgid "" "PKCS#11 URI (see RFC-7512 for details) which can be used to restrict the " "selection of devices used for Smartcard authentication. By default SSSD's " @@ -2450,118 +2731,153 @@ msgid "" "first slot found. If multiple readers are connected p11_uri can be used to " "tell p11_child to use a specific reader." msgstr "" +"L'URI PKCS#11 (voir RFC-7512 pour plus de détails) permet de limiter la " +"sélection des périphériques utilisés pour l'authentification par carte à " +"puce. Par défaut, le composant p11_child de SSSD recherche un emplacement " +"PKCS#11 (lecteur) où l'indicateur « amovible » est activé et lit les " +"certificats du jeton inséré à partir du premier emplacement trouvé. Si " +"plusieurs lecteurs sont connectés, l'URI PKCS#11 peut être utilisée pour " +"indiquer à p11_child d'utiliser un lecteur spécifique." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1812 +#: sssd.conf.5.xml:1809 #, no-wrap msgid "" "p11_uri = pkcs11:slot-description=My%20Smartcard%20Reader\n" " " msgstr "" +"p11_uri = pkcs11:slot-description=Mon%20lecteur%20de%20cartes%20à%puce\n" +" " #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1816 +#: sssd.conf.5.xml:1813 #, no-wrap msgid "" "p11_uri = pkcs11:library-description=OpenSC%20smartcard%20framework;slot-id=2\n" " " msgstr "" +"p11_uri = pkcs11:library-description=OpenSC%20smartcard%20framework;slot-" +"id=2\n" +" " #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1810 +#: sssd.conf.5.xml:1807 msgid "" "Example: <placeholder type=\"programlisting\" id=\"0\"/> or <placeholder " "type=\"programlisting\" id=\"1\"/> To find suitable URI please check the " "debug output of p11_child. As an alternative the GnuTLS utility 'p11tool' " "with e.g. the '--list-all' will show PKCS#11 URIs as well." msgstr "" +"Exemple : `<placeholder type=\"programlisting\" id=\"0\"/>` ou `<placeholder " +"type=\"programlisting\" id=\"1\"/>`. Pour trouver l'URI appropriée, veuillez " +"consulter la sortie de débogage de `p11_child`. Vous pouvez également " +"utiliser l'utilitaire GnuTLS `p11tool` avec l'option `--list-all`, par " +"exemple, pour afficher les URI PKCS#11." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1829 -msgid "pam_initgroups_scheme" -msgstr "" +#: sssd.conf.5.xml:1826 +#, fuzzy +#| msgid "ldap_netgroup_member (string)" +msgid "pam_initgroups_scheme (string)" +msgstr "ldap_netgroup_member (chaîne)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1837 +#: sssd.conf.5.xml:1834 msgid "always" -msgstr "" +msgstr "toujours" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1838 +#: sssd.conf.5.xml:1835 msgid "" "Always do an online lookup, please note that pam_id_timeout still applies" msgstr "" +"Veuillez toujours effectuer une recherche en ligne. Notez que le délai " +"d'expiration de l'identifiant PAM (pam_id_timeout) reste applicable." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1842 +#: sssd.conf.5.xml:1839 msgid "no_session" -msgstr "" +msgstr "aucune session" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1843 +#: sssd.conf.5.xml:1840 msgid "" "Only do an online lookup if there is no active session of the user, i.e. if " "the user is currently not logged in" msgstr "" +"N’effectuez une recherche en ligne que si l’utilisateur n’a pas de session " +"active, c’est-à-dire s’il n’est pas connecté." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1848 sssd-ldap.5.xml:189 +#: sssd.conf.5.xml:1845 sssd-ldap.5.xml:189 msgid "never" -msgstr "" +msgstr "jamais" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1849 +#: sssd.conf.5.xml:1846 msgid "" "Never force an online lookup, use the data from the cache as long as they " "are not expired" msgstr "" +"Ne jamais forcer une recherche en ligne, utiliser les données du cache tant " +"qu'elles ne sont pas expirées." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1832 +#: sssd.conf.5.xml:1829 msgid "" "The PAM responder can force an online lookup to get the current group " "memberships of the user trying to log in. This option controls when this " "should be done and the following values are allowed: <placeholder " "type=\"variablelist\" id=\"0\"/>" msgstr "" +"Le répondeur PAM peut forcer une recherche en ligne pour obtenir les " +"appartenances aux groupes actuelles de l'utilisateur qui tente de se " +"connecter. Cette option détermine quand cette recherche doit être effectuée " +"et les valeurs suivantes sont autorisées : <placeholder " +"type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1856 +#: sssd.conf.5.xml:1853 msgid "Default: no_session" -msgstr "" +msgstr "Par défaut : aucune session" -#. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:1861 sssd.conf.5.xml:4277 +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1858 #, fuzzy #| msgid "ad_gpo_map_service (string)" -msgid "pam_gssapi_services" +msgid "pam_gssapi_services (string)" msgstr "ad_gpo_map_service (chaîne)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1864 -#, fuzzy -#| msgid "Comma separated list of users who are allowed to log in." +#: sssd.conf.5.xml:1861 msgid "" "Comma separated list of PAM services that are allowed to try GSSAPI " "authentication using pam_sss_gss.so module." -msgstr "Liste séparée par des virgules d'utilisateurs autorisés à se connecter." +msgstr "" +"Liste, séparée par des virgules, des services PAM autorisés à tenter " +"l'authentification GSSAPI à l'aide du module pam_sss_gss.so." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1869 +#: sssd.conf.5.xml:1866 msgid "" "To disable GSSAPI authentication, set this option to <quote>-</quote> (dash)." msgstr "" +"Pour désactiver l'authentification GSSAPI, définissez cette option sur " +"<quote>-</quote> (tiret)." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1873 sssd.conf.5.xml:1904 sssd.conf.5.xml:1942 +#: sssd.conf.5.xml:1870 sssd.conf.5.xml:1901 sssd.conf.5.xml:1939 msgid "" "Note: This option can also be set per-domain which overwrites the value in " "[pam] section. It can also be set for trusted domain which overwrites the " "value in the domain section." msgstr "" +"Remarque : Cette option peut également être définie par domaine, remplaçant " +"ainsi la valeur de la section [pam]. Elle peut aussi être définie pour un " +"domaine de confiance, remplaçant alors la valeur de la section « domaine »." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1881 +#: sssd.conf.5.xml:1878 #, fuzzy, no-wrap #| msgid "" #| "fallback_homedir = /home/%u\n" @@ -2574,50 +2890,61 @@ msgstr "" " " #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1879 sssd.conf.5.xml:1994 sssd.conf.5.xml:3836 +#: sssd.conf.5.xml:1876 sssd.conf.5.xml:2023 sssd.conf.5.xml:4042 msgid "Example: <placeholder type=\"programlisting\" id=\"0\"/>" msgstr "Exemple : <placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1885 +#: sssd.conf.5.xml:1882 msgid "Default: - (GSSAPI authentication is disabled)" -msgstr "" +msgstr "Par défaut : - (l’authentification GSSAPI est désactivée)" -#. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:1890 sssd.conf.5.xml:4278 -msgid "pam_gssapi_check_upn" -msgstr "" +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1887 +#, fuzzy +#| msgid "ldap_disable_paging (boolean)" +msgid "pam_gssapi_check_upn (boolean)" +msgstr "ldap_disable_paging (boolean)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1893 +#: sssd.conf.5.xml:1890 msgid "" "If True, SSSD will require that the Kerberos user principal that " "successfully authenticated through GSSAPI can be associated with the user " "who is being authenticated. Authentication will fail if the check fails." msgstr "" +"Si cette option est activée, SSSD exigera que le principal utilisateur " +"Kerberos ayant réussi l'authentification via GSSAPI soit associé à " +"l'utilisateur en cours d'authentification. L'authentification échouera en " +"cas d'échec de cette vérification." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1900 +#: sssd.conf.5.xml:1897 msgid "" -"If False, every user that is able to obtained required service ticket will " +"If False, every user that is able to obtain a required service ticket will " "be authenticated." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1915 -msgid "pam_gssapi_indicators_map" -msgstr "" +#: sssd.conf.5.xml:1912 +#, fuzzy +#| msgid "pam_public_domains (string)" +msgid "pam_gssapi_indicators_map (string)" +msgstr "pam_public_domains (chaîne)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1918 +#: sssd.conf.5.xml:1915 msgid "" "Comma separated list of authentication indicators required to be present in " "a Kerberos ticket to access a PAM service that is allowed to try GSSAPI " "authentication using pam_sss_gss.so module." msgstr "" +"Liste séparée par des virgules des indicateurs d'authentification requis " +"dans un ticket Kerberos pour accéder à un service PAM autorisé à tenter une " +"authentification GSSAPI à l'aide du module pam_sss_gss.so." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1924 +#: sssd.conf.5.xml:1921 msgid "" "Each element of the list can be either an authentication indicator name or a " "pair <quote>service:indicator</quote>. Indicators not prefixed with the PAM " @@ -2630,101 +2957,177 @@ msgid "" "be denied. If the resulting list of indicators for the PAM service is empty, " "the check will not prevent the access." msgstr "" +"Chaque élément de la liste peut être soit le nom d'un indicateur " +"d'authentification, soit une paire <quote>service:indicateur</quote>. Les " +"indicateurs non préfixés par le nom du service PAM sont requis pour accéder " +"à tout service PAM configuré pour être utilisé avec <option>" +"pam_gssapi_services</option>. La liste d'indicateurs résultante pour chaque " +"service PAM est ensuite comparée aux indicateurs du ticket Kerberos lors de " +"l'authentification par pam_sss_gss.so. Tout indicateur du ticket " +"correspondant à la liste d'indicateurs résultante pour le service PAM " +"autorise l'accès. Si aucun indicateur de la liste ne correspond, l'accès est " +"refusé. Si la liste d'indicateurs résultante pour le service PAM est vide, " +"la vérification n'empêche pas l'accès." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1937 +#: sssd.conf.5.xml:1934 msgid "" "To disable GSSAPI authentication indicator check, set this option to <quote>-" "</quote> (dash). To disable the check for a specific PAM service, add " "<quote>service:-</quote>." msgstr "" +"Pour désactiver la vérification de l'indicateur d'authentification GSSAPI, " +"définissez cette option sur <quote>-</quote> (tiret). Pour désactiver la " +"vérification pour un service PAM spécifique, ajoutez <quote>service:-</quote>" +"." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1948 +#: sssd.conf.5.xml:1945 msgid "" "Following authentication indicators are supported by IPA Kerberos " "deployments:" msgstr "" +"Les indicateurs d'authentification suivants sont pris en charge par les " +"déploiements IPA Kerberos :" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1951 +#: sssd.conf.5.xml:1948 msgid "" "pkinit -- pre-authentication using X.509 certificates -- whether stored in " "files or on smart cards." msgstr "" +"pkinit -- pré-authentification utilisant des certificats X.509 -- qu'ils " +"soient stockés dans des fichiers ou sur des cartes à puce." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1954 +#: sssd.conf.5.xml:1951 msgid "" "hardened -- SPAKE pre-authentication or any pre-authentication wrapped in a " "FAST channel." msgstr "" +"durci -- pré-authentification SPAKE ou toute pré-authentification enveloppée " +"dans un canal FAST." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1957 +#: sssd.conf.5.xml:1954 msgid "radius -- pre-authentication with the help of a RADIUS server." msgstr "" +"durci -- pré-authentification SPAKE ou toute pré-authentification enveloppée " +"dans un canal FAST." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1960 +#: sssd.conf.5.xml:1957 msgid "" "otp -- pre-authentication using integrated two-factor authentication (2FA or " "one-time password, OTP) in IPA." msgstr "" +"otp -- pré-authentification utilisant l'authentification à deux facteurs " +"intégrée (2FA ou mot de passe à usage unique, OTP) dans IPA." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1963 +#: sssd.conf.5.xml:1960 msgid "idp -- pre-authentication using external identity provider." -msgstr "" +msgstr "idp -- pré-authentification via un fournisseur d'identité externe." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1973 +#: sssd.conf.5.xml:1970 #, no-wrap msgid "" "pam_gssapi_indicators_map = sudo:pkinit, sudo-i:pkinit\n" " " msgstr "" +"pam_gssapi_indicators_map = sudo:pkinit, sudo-i:pkinit\n" +" " #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1968 +#: sssd.conf.5.xml:1965 msgid "" "Example: to require access to SUDO services only for users which obtained " "their Kerberos tickets with a X.509 certificate pre-authentication (PKINIT), " "set <placeholder type=\"programlisting\" id=\"0\"/>" msgstr "" +"Exemple : pour limiter l’accès aux services SUDO aux seuls utilisateurs " +"ayant obtenu leur ticket Kerberos avec une pré-authentification par " +"certificat X.509 (PKINIT), définissez <placeholder type=\"programlisting\" " +"id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1977 +#: sssd.conf.5.xml:1974 #, fuzzy #| msgid "Default: not set (no substitution for unset home directories)" msgid "Default: not set (use of authentication indicators is not required)" msgstr "" -"Par défaut : non défini (aucune substitution pour les répertoires d'accueil " +"Par défaut : non défini (aucune substitution pour les répertoires d'accueil " "non définis)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1979 +#, fuzzy +#| msgid "base_directory (string)" +msgid "pam_gssapi_indicators_apply (string)" +msgstr "base_directory (chaîne)" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1982 +msgid "" +"Comma separated list of triples to assign additional information from the " +"Kerberos ticket, e.g. a SID from the PAC, to authentication indicators." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1988 +#, fuzzy +#| msgid "Currently supported debug levels:" +msgid "Currently supported is:" +msgstr "Niveaux de débogage actuellement pris en charge :" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:1991 +msgid "SID:S-1-5-[domain]-[RID]:[authentication indicator]" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> +#: sssd.conf.5.xml:2002 +#, no-wrap +msgid "" +"pam_gssapi_indicators_apply = SID:S-1-5-12345-23456-34567-4321:pkinit\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1996 +msgid "" +"Example: To assign a SID, which is e.g. set by Active Directory's " +"Authentication Mechanism Assurance (AMA) if the AD user used a Smartcard for " +"authentication, to the 'pkinit' authentication indicator use: <placeholder " +"type=\"programlisting\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2011 #, fuzzy #| msgid "ad_gpo_map_service (string)" msgid "pam_json_services (string)" msgstr "ad_gpo_map_service (chaîne)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1985 -#, fuzzy -#| msgid "Comma separated list of users who are allowed to log in." +#: sssd.conf.5.xml:2014 msgid "" "Comma separated list of PAM services which can handle the JSON protocol for " "selecting authentication mechanisms" -msgstr "Liste séparée par des virgules d'utilisateurs autorisés à se connecter." +msgstr "" +"Liste, séparée par des virgules, des services PAM capables de gérer le " +"protocole JSON pour la sélection des mécanismes d'authentification." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1990 +#: sssd.conf.5.xml:2019 msgid "To disable JSON protocol, set this option to <quote>-</quote> (dash)." msgstr "" +"Pour désactiver le protocole JSON, définissez cette option sur <quote>-</" +"quote> (tiret)." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1996 +#: sssd.conf.5.xml:2025 #, fuzzy, no-wrap #| msgid "" #| "fallback_homedir = /home/%u\n" @@ -2737,33 +3140,57 @@ msgstr "" " " #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2000 +#: sssd.conf.5.xml:2029 #, fuzzy #| msgid "Default: 0 (disabled)" msgid "Default: - (JSON protocol is disabled)" msgstr "Par défaut : 0 (désactivé)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2003 +#: sssd.conf.5.xml:2032 msgid "" "Note: 2-Factor Authentication (2FA) is not supported. If 2FA is required, do " "not activate the JSON protocol." msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:2013 -msgid "SUDO configuration options" -msgstr "Options de configuration de SUDO" +"Remarque : L’authentification à deux facteurs (2FA) n’est pas prise en " +"charge. Si la 2FA est requise, n’activez pas le protocole JSON." + +#. type: Content of: <reference><refentry><refsect1><refsect2><title> +#: sssd.conf.5.xml:2042 +msgid "SUDO configuration options" +msgstr "Options de configuration de SUDO" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:2044 +#, fuzzy +#| msgid "" +#| "These options can be used to configure the Name Service Switch (NSS) " +#| "service." +msgid "" +"These options can be used to configure the sudo service and should be " +"specified under the <quote>[sudo]</quote> section." +msgstr "" +"Ces options peuvent être utilisées pour configurer le service Name Service " +"Switch (NSS)." #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2015 +#: sssd.conf.5.xml:2048 +#, fuzzy +#| msgid "" +#| "These options can be used to configure the sudo service. The detailed " +#| "instructions for configuration of <citerefentry> <refentrytitle>sudo</" +#| "refentrytitle> <manvolnum>8</manvolnum> </citerefentry> to work with " +#| "<citerefentry> <refentrytitle>sssd</refentrytitle> <manvolnum>8</" +#| "manvolnum> </citerefentry> are in the manual page <citerefentry> " +#| "<refentrytitle>sssd-sudo</refentrytitle> <manvolnum>5</manvolnum> </" +#| "citerefentry>." msgid "" -"These options can be used to configure the sudo service. The detailed " -"instructions for configuration of <citerefentry> <refentrytitle>sudo</" -"refentrytitle> <manvolnum>8</manvolnum> </citerefentry> to work with " -"<citerefentry> <refentrytitle>sssd</refentrytitle> <manvolnum>8</manvolnum> " -"</citerefentry> are in the manual page <citerefentry> <refentrytitle>sssd-" -"sudo</refentrytitle> <manvolnum>5</manvolnum> </citerefentry>." +"The detailed instructions for configuration of <citerefentry> " +"<refentrytitle>sudo</refentrytitle> <manvolnum>8</manvolnum> </citerefentry> " +"to work with <citerefentry> <refentrytitle>sssd</refentrytitle> " +"<manvolnum>8</manvolnum> </citerefentry> are in the manual page " +"<citerefentry> <refentrytitle>sssd-sudo</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry>." msgstr "" "Ces options peuvent être utilisées pour configurer le service sudo. Les " "directives de configuration de <citerefentry> <refentrytitle>sudo</" @@ -2773,26 +3200,28 @@ msgstr "" "sudo</refentrytitle> <manvolnum>5</manvolnum> </citerefentry>." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2032 -msgid "sudo_timed (bool)" +#: sssd.conf.5.xml:2064 +#, fuzzy +#| msgid "sudo_timed (bool)" +msgid "sudo_timed (boolean)" msgstr "sudo_timed (booléen)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2035 +#: sssd.conf.5.xml:2067 msgid "" "Whether or not to evaluate the sudoNotBefore and sudoNotAfter attributes " "that implement time-dependent sudoers entries." msgstr "" -"Évaluation ou non des attributs sudoNotBefore et sudoNotAfter qui utilisent " +"Évaluation ou non des attributs sudoNotBefore et sudoNotAfter qui utilisent " "les entrées sudoers sensibles au temps." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2047 +#: sssd.conf.5.xml:2079 msgid "sudo_threshold (integer)" -msgstr "" +msgstr "sudo_threshold (entier)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2050 +#: sssd.conf.5.xml:2082 msgid "" "Maximum number of expired rules that can be refreshed at once. If number of " "expired rules is below threshold, those rules are refreshed with " @@ -2800,24 +3229,34 @@ msgid "" "<quote>full refresh</quote> of sudo rules is triggered instead. This " "threshold number also applies to IPA sudo command and command group searches." msgstr "" +"Nombre maximal de règles expirées pouvant être actualisées simultanément. Si " +"ce nombre est inférieur au seuil, les règles sont actualisées via le " +"mécanisme d'actualisation des règles. Si le seuil est dépassé, une " +"actualisation complète des règles sudo est déclenchée. Ce seuil s'applique " +"également aux recherches de commandes et de groupes de commandes sudo dans " +"l'API IPA." #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:2069 +#: sssd.conf.5.xml:2101 msgid "AUTOFS configuration options" msgstr "Options de configuration AUTOFS" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2071 -msgid "These options can be used to configure the autofs service." +#: sssd.conf.5.xml:2103 +#, fuzzy +#| msgid "These options can be used to configure the autofs service." +msgid "" +"These options can be used to configure the autofs service and should be " +"specified under the <quote>[autofs]</quote> section." msgstr "Ces options peuvent être utilisées pour configurer le service autofs." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2075 +#: sssd.conf.5.xml:2109 msgid "autofs_negative_timeout (integer)" msgstr "autofs_negative_timeout (entier)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2078 +#: sssd.conf.5.xml:2112 msgid "" "Specifies for how many seconds should the autofs responder negative cache " "hits (that is, queries for invalid map entries, like nonexistent ones) " @@ -2829,37 +3268,48 @@ msgstr "" "moteur." #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:2094 +#: sssd.conf.5.xml:2128 msgid "SSH configuration options" msgstr "Options de configuration SSH" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2096 -msgid "These options can be used to configure the SSH service." +#: sssd.conf.5.xml:2130 +#, fuzzy +#| msgid "These options can be used to configure the SSH service." +msgid "" +"These options can be used to configure the SSH service and should be " +"specified under the <quote>[ssh]</quote> section." msgstr "" "Les options suivantes peuvent être utilisées pour configurer le service SSH." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2100 -msgid "ssh_use_certificate_keys (bool)" -msgstr "" +#: sssd.conf.5.xml:2136 +#, fuzzy +#| msgid "ldap_user_certificate (string)" +msgid "ssh_use_certificate_keys (boolean)" +msgstr "ldap_user_certificate (chaîne)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2103 +#: sssd.conf.5.xml:2139 msgid "" "If set to true the <command>sss_ssh_authorizedkeys</command> will return ssh " "keys derived from the public key of X.509 certificates stored in the user " "entry as well. See <citerefentry> <refentrytitle>sss_ssh_authorizedkeys</" "refentrytitle> <manvolnum>1</manvolnum> </citerefentry> for details." msgstr "" +"Si la valeur est définie sur « true », la commande `sss_ssh_authorizedkeys` " +"renverra également les clés SSH dérivées de la clé publique des certificats " +"X.509 stockés dans l'entrée utilisateur. Voir `<citerefentry><refentrytitle>" +"sss_ssh_authorizedkeys</refentrytitle><manvolnum>1</manvolnum></citerefentry>" +"` pour plus de détails." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2118 +#: sssd.conf.5.xml:2154 msgid "ssh_use_certificate_matching_rules (string)" -msgstr "" +msgstr "ssh_use_certificate_matching_rules (chaîne)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2121 +#: sssd.conf.5.xml:2157 msgid "" "By default the ssh responder will use all available certificate matching " "rules to filter the certificates so that ssh keys are only derived from the " @@ -2867,57 +3317,78 @@ msgid "" "comma separated list of mapping and matching rule names. All other rules " "will be ignored." msgstr "" +"Par défaut, le serveur SSH utilise toutes les règles de correspondance de " +"certificats disponibles pour filtrer les certificats et ne dériver que des " +"certificats correspondants. Cette option permet de limiter les règles " +"utilisées à l'aide d'une liste de noms de règles de correspondance séparés " +"par des virgules. Toutes les autres règles seront ignorées." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2130 +#: sssd.conf.5.xml:2166 msgid "" "There are two special key words 'all_rules' and 'no_rules' which will enable " "all or no rules, respectively. The latter means that no certificates will be " "filtered out and ssh keys will be generated from all valid certificates." msgstr "" +"Deux mots clés spéciaux, « all_rules » et « no_rules », permettent " +"respectivement d'activer toutes les règles ou de les désactiver. L'option « " +"no_rules » signifie qu'aucun certificat ne sera filtré et que les clés SSH " +"seront générées à partir de tous les certificats valides." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2137 +#: sssd.conf.5.xml:2173 msgid "" "If no rules are configured using 'all_rules' will enable a default rule " "which enables all certificates suitable for client authentication. This is " "the same behavior as for the PAM responder if certificate authentication is " "enabled." msgstr "" +"Si aucune règle n'est configurée, l'option « all_rules » active une règle " +"par défaut autorisant tous les certificats compatibles avec " +"l'authentification du client. Ce comportement est identique à celui du " +"répondeur PAM lorsque l'authentification par certificat est activée." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2144 +#: sssd.conf.5.xml:2180 msgid "" "A non-existing rule name is considered an error. If as a result no rule is " "selected all certificates will be ignored." msgstr "" +"Un nom de règle inexistant est considéré comme une erreur. Si, par " +"conséquent, aucune règle n'est sélectionnée, tous les certificats seront " +"ignorés." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2149 +#: sssd.conf.5.xml:2185 msgid "" "Default: not set, equivalent to 'all_rules', all found rules or the default " "rule are used" msgstr "" +"Valeur par défaut : non définie, équivalent à « all_rules », toutes les " +"règles trouvées ou la règle par défaut sont utilisées" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2155 +#: sssd.conf.5.xml:2191 msgid "ca_db (string)" -msgstr "" +msgstr "ca_db (chaîne)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2158 +#: sssd.conf.5.xml:2194 msgid "" "Path to a storage of trusted CA certificates. The option is used to validate " "user certificates before deriving public ssh keys from them." msgstr "" +"Chemin d'accès à un répertoire de certificats d'autorité de certification de " +"confiance. Cette option permet de valider les certificats utilisateur avant " +"d'en dériver les clés SSH publiques." #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:2178 +#: sssd.conf.5.xml:2214 msgid "PAC responder configuration options" msgstr "Options de configuration du répondeur PAC" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2180 +#: sssd.conf.5.xml:2216 msgid "" "The PAC responder works together with the authorization data plugin for MIT " "Kerberos sssd_pac_plugin.so and a sub-domain provider. The plugin sends the " @@ -2926,9 +3397,16 @@ msgid "" "joined to and of remote trusted domains from the local domain controller. If " "the PAC is decoded and evaluated some of the following operations are done:" msgstr "" +"Le répondeur PAC fonctionne conjointement avec le plugin de données " +"d'autorisation pour MIT Kerberos sssd_pac_plugin.so et un fournisseur de " +"sous-domaine. Le plugin envoie les données PAC au répondeur PAC lors d'une " +"authentification GSSAPI. Le fournisseur de sous-domaine collecte les plages " +"SID et ID du domaine auquel le client est rattaché, ainsi que celles des " +"domaines distants de confiance, auprès du contrôleur de domaine local. Si le " +"PAC est décodé et évalué, les opérations suivantes sont effectuées :" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:2189 +#: sssd.conf.5.xml:2225 msgid "" "If the remote user does not exist in the cache, it is created. The UID is " "determined with the help of the SID, trusted domains will have UPGs and the " @@ -2937,9 +3415,15 @@ msgid "" "the system defaults are used, but can be overwritten with the default_shell " "parameter." msgstr "" +"Si l'utilisateur distant n'est pas présent dans le cache, il est créé. L'UID " +"est déterminé à l'aide du SID ; les domaines de confiance possèdent un UPG " +"et le GID a la même valeur que l'UID. Le répertoire personnel est défini en " +"fonction du paramètre `subdomain_homedir`. Par défaut, l'interpréteur de " +"commandes est vide (les commandes système par défaut sont utilisées), mais " +"il est possible de le remplacer avec le paramètre `default_shell`." #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:2197 +#: sssd.conf.5.xml:2233 msgid "" "If there are SIDs of groups from domains sssd knows about, the user will be " "added to those groups." @@ -2948,19 +3432,23 @@ msgstr "" "ajouté à ces groupes." #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2203 -msgid "These options can be used to configure the PAC responder." +#: sssd.conf.5.xml:2239 +#, fuzzy +#| msgid "These options can be used to configure the PAC responder." +msgid "" +"These options can be used to configure the PAC responder and should be " +"specified under the <quote>[pac]</quote> section." msgstr "" "Les options suivantes peuvent être utilisées pour configurer le répondeur " "PAC." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2207 sssd-ifp.5.xml:66 +#: sssd.conf.5.xml:2244 sssd-ifp.5.xml:66 msgid "allowed_uids (string)" msgstr "allowed_uids (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2210 +#: sssd.conf.5.xml:2247 msgid "" "Specifies the comma-separated list of UID values or user names that are " "allowed to access the PAC responder. User names are resolved to UIDs at " @@ -2971,7 +3459,7 @@ msgstr "" "seront résolus en UID au démarrage." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2216 +#: sssd.conf.5.xml:2253 #, fuzzy #| msgid "" #| "Default: 0 (only the root user is allowed to access the PAC responder)" @@ -2983,14 +3471,14 @@ msgstr "" "PAC)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2220 +#: sssd.conf.5.xml:2257 msgid "Default: 0 (only the root user is allowed to access the PAC responder)" msgstr "" "Par défaut : 0 (seul l'utilisateur root est autorisé à accéder au répondeur " "PAC)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2224 +#: sssd.conf.5.xml:2261 #, fuzzy #| msgid "" #| "Please note that although the UID 0 is used as the default it will be " @@ -3009,7 +3497,7 @@ msgstr "" "0 à la liste des UID d'utilisateurs autorisés." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2231 +#: sssd.conf.5.xml:2268 msgid "" "Please note that although the UID 0 is used as the default it will be " "overwritten with this option. If you still want to allow the root user to " @@ -3022,26 +3510,29 @@ msgstr "" "0 à la liste des UID d'utilisateurs autorisés." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2240 +#: sssd.conf.5.xml:2277 msgid "pac_lifetime (integer)" -msgstr "" +msgstr "pac_lifetime (entier)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2243 +#: sssd.conf.5.xml:2280 msgid "" "Lifetime of the PAC entry in seconds. As long as the PAC is valid the PAC " "data can be used to determine the group memberships of a user." msgstr "" +"Durée de vie de l'entrée PAC en secondes. Tant que le PAC est valide, ses " +"données peuvent être utilisées pour déterminer les groupes auxquels " +"appartient un utilisateur." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2253 +#: sssd.conf.5.xml:2290 #, fuzzy #| msgid "ldap_schema (string)" msgid "pac_check (string)" msgstr "ldap_schema (chaîne)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2256 +#: sssd.conf.5.xml:2293 msgid "" "Apply additional checks on the PAC of the Kerberos ticket which is available " "in Active Directory and FreeIPA domains, if configured. Please note that " @@ -3050,59 +3541,77 @@ msgid "" "IPA and AD provider. If krb5_validate is set to 'False' the PAC checks will " "be skipped." msgstr "" +"Effectuez des vérifications supplémentaires sur le PAC du ticket Kerberos, " +"disponible dans les domaines Active Directory et FreeIPA, le cas échéant. " +"Veuillez noter que la validation du ticket Kerberos doit être activée pour " +"pouvoir vérifier le PAC ; autrement dit, l’option `krb5_validate` doit être " +"définie sur « True », valeur par défaut pour les fournisseurs IPA et AD. Si " +"`krb5_validate` est définie sur « False », les vérifications du PAC seront " +"ignorées." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2266 +#: sssd.conf.5.xml:2303 msgid "" "Please note that the checks listed below only apply to PACs issued by Active " "Directory or recent versions of FreeIPA. PACs issued e.g. by a plain MIT " "Kerberos KDC will not contain the needed PAC data buffers to run the checks." msgstr "" +"Veuillez noter que les vérifications ci-dessous ne s'appliquent qu'aux " +"fichiers PAC émis par Active Directory ou les versions récentes de FreeIPA. " +"Les fichiers PAC émis, par exemple, par un contrôleur de domaine Kerberos " +"MIT standard ne contiennent pas les tampons de données nécessaires à " +"l'exécution de ces vérifications." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2277 +#: sssd.conf.5.xml:2314 msgid "no_check" -msgstr "" +msgstr "pas de vérification" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2279 +#: sssd.conf.5.xml:2316 msgid "" "The PAC must not be present and even if it is present no additional checks " "will be done." msgstr "" +"Le PAC ne doit pas être présent et, même s'il est présent, aucun contrôle " +"supplémentaire ne sera effectué." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2285 +#: sssd.conf.5.xml:2322 msgid "pac_present" -msgstr "" +msgstr "pac_présent" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2287 +#: sssd.conf.5.xml:2324 msgid "" "The PAC must be present in the service ticket which SSSD will request with " "the help of the user's TGT. If the PAC is not available the authentication " "will fail." msgstr "" +"Le PAC doit figurer dans le ticket de service que SSSD demandera à l'aide du " +"TGT de l'utilisateur. Si le PAC est absent, l'authentification échouera." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2295 +#: sssd.conf.5.xml:2332 msgid "check_upn" -msgstr "" +msgstr "check_upn" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2297 +#: sssd.conf.5.xml:2334 msgid "" "If the PAC is present check if the user principal name (UPN) information is " "consistent." msgstr "" +"Si le PAC est présent, vérifiez si les informations du nom principal de " +"l'utilisateur (UPN) sont cohérentes." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2303 +#: sssd.conf.5.xml:2340 msgid "check_upn_allow_missing" -msgstr "" +msgstr "check_upn_autoriser_manquant" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2305 +#: sssd.conf.5.xml:2342 msgid "" "This option should be used together with 'check_upn' and handles the case " "where a UPN is set on the server-side but is not read by SSSD. The typical " @@ -3112,9 +3621,17 @@ msgid "" "time and FreeIPA can handle enterprise principals just fine and there is no " "need anymore to set 'ldap_user_principal'." msgstr "" +"Cette option doit être utilisée conjointement avec « check_upn » et gère le " +"cas où un UPN est défini côté serveur mais n'est pas lu par SSSD. L'exemple " +"typique est celui d'un domaine FreeIPA où « ldap_user_principal » est défini " +"sur un nom d'attribut inexistant. Cette pratique était courante pour " +"contourner les problèmes de gestion des principaux d'entreprise. Cependant, " +"ce problème est résolu depuis longtemps et FreeIPA gère parfaitement les " +"principaux d'entreprise ; il n'est donc plus nécessaire de définir « " +"ldap_user_principal »." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2317 +#: sssd.conf.5.xml:2354 msgid "" "Currently this option is set by default to avoid regressions in such " "environments. A log message will be added to the system log and SSSD's debug " @@ -3123,43 +3640,56 @@ msgid "" "can be removed. If this is not possible, removing 'check_upn' will skip the " "test and avoid the log message." msgstr "" +"Actuellement, cette option est activée par défaut afin d'éviter les " +"régressions dans ces environnements. Un message sera ajouté au journal " +"système et au journal de débogage de SSSD si un UPN est trouvé dans le PAC " +"mais pas dans le cache de SSSD. Pour éviter ce message, il serait préférable " +"d'évaluer si l'option « ldap_user_principal » peut être supprimée. Si cela " +"n'est pas possible, la suppression de « check_upn » permettra d'ignorer le " +"test et d'éviter l'affichage du message." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2331 +#: sssd.conf.5.xml:2368 msgid "upn_dns_info_present" -msgstr "" +msgstr "upn_dns_info_présent" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2333 +#: sssd.conf.5.xml:2370 msgid "The PAC must contain the UPN-DNS-INFO buffer, implies 'check_upn'." msgstr "" +"Le PAC doit contenir le tampon UPN-DNS-INFO, ce qui implique 'check_upn'." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2338 +#: sssd.conf.5.xml:2375 msgid "check_upn_dns_info_ex" -msgstr "" +msgstr "check_upn_dns_info_ex" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2340 +#: sssd.conf.5.xml:2377 msgid "" "If the PAC is present and the extension to the UPN-DNS-INFO buffer is " "available check if the information in the extension is consistent." msgstr "" +"Si le PAC est présent et que l'extension du tampon UPN-DNS-INFO est " +"disponible, vérifiez si les informations contenues dans l'extension sont " +"cohérentes." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2347 +#: sssd.conf.5.xml:2384 msgid "upn_dns_info_ex_present" -msgstr "" +msgstr "upn_dns_info_ex_présent" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2349 +#: sssd.conf.5.xml:2386 msgid "" "The PAC must contain the extension of the UPN-DNS-INFO buffer, implies " "'check_upn_dns_info_ex', 'upn_dns_info_present' and 'check_upn'." msgstr "" +"Le PAC doit contenir l'extension du tampon UPN-DNS-INFO, ce qui implique " +"'check_upn_dns_info_ex', 'upn_dns_info_present' et 'check_upn'." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2273 +#: sssd.conf.5.xml:2310 #, fuzzy #| msgid "" #| "The following expansions are supported: <placeholder " @@ -3172,19 +3702,21 @@ msgstr "" "type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2359 +#: sssd.conf.5.xml:2396 msgid "" "Default: no_check (AD and IPA provider 'check_upn, check_upn_allow_missing, " "check_upn_dns_info_ex')" msgstr "" +"Par défaut : no_check (fournisseur AD et IPA : « check_upn, " +"check_upn_allow_missing, check_upn_dns_info_ex »)" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:2368 +#: sssd.conf.5.xml:2405 msgid "Session recording configuration options" -msgstr "" +msgstr "options de configuration de l'enregistrement de session" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2370 +#: sssd.conf.5.xml:2407 msgid "" "Session recording works in conjunction with <citerefentry> " "<refentrytitle>tlog-rec-session</refentrytitle> <manvolnum>8</manvolnum> </" @@ -3192,161 +3724,198 @@ msgid "" "they log in on a text terminal. See also <citerefentry> <refentrytitle>sssd-" "session-recording</refentrytitle> <manvolnum>5</manvolnum> </citerefentry>." msgstr "" +"L'enregistrement de session fonctionne conjointement avec `tlog-rec-" +"session`, un composant du paquet `tlog`, pour enregistrer ce que les " +"utilisateurs voient et saisissent lorsqu'ils se connectent à un terminal " +"texte. Voir aussi `sssd-session-recording`." + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:2420 +msgid "" +"These options can be used to configure session recording and should be " +"specified under the <quote>[session_recording]</quote> section." +msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2383 -msgid "These options can be used to configure session recording." +#: sssd.conf.5.xml:2425 +msgid "" +"Note: Unlike other sections, the <quote>[session_recording]</quote> section " +"ignores <replaceable>debug*</replaceable> options and suitable " +"<replaceable>debug*</replaceable> options must be set in <quote>[pam]</" +"quote>, <quote>[nss]</quote> and <quote>[domain/<replaceable>NAME</" +"replaceable>]</quote> sections." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2387 sssd-session-recording.5.xml:64 +#: sssd.conf.5.xml:2433 sssd-session-recording.5.xml:64 msgid "scope (string)" -msgstr "" +msgstr "portée (chaîne)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2394 sssd-session-recording.5.xml:71 +#: sssd.conf.5.xml:2440 sssd-session-recording.5.xml:71 msgid "\"none\"" -msgstr "" +msgstr "\"aucun\"" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2397 sssd-session-recording.5.xml:74 +#: sssd.conf.5.xml:2443 sssd-session-recording.5.xml:74 msgid "No users are recorded." -msgstr "" +msgstr "Aucun utilisateur n'est enregistré." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2402 sssd-session-recording.5.xml:79 +#: sssd.conf.5.xml:2448 sssd-session-recording.5.xml:79 msgid "\"some\"" -msgstr "" +msgstr "\"quelques\"" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2405 sssd-session-recording.5.xml:82 +#: sssd.conf.5.xml:2451 sssd-session-recording.5.xml:82 msgid "" "Users/groups specified by <replaceable>users</replaceable> and " "<replaceable>groups</replaceable> options are recorded." msgstr "" +"Les utilisateurs/groupes spécifiés par les options <replaceable>users</" +"replaceable> et <replaceable>groups</replaceable> sont enregistrés." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2414 sssd-session-recording.5.xml:91 +#: sssd.conf.5.xml:2460 sssd-session-recording.5.xml:91 msgid "\"all\"" -msgstr "" +msgstr "\"tout\"" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2417 sssd-session-recording.5.xml:94 +#: sssd.conf.5.xml:2463 sssd-session-recording.5.xml:94 msgid "All users are recorded." -msgstr "" +msgstr "Tous les utilisateurs sont enregistrés." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2390 sssd-session-recording.5.xml:67 +#: sssd.conf.5.xml:2436 sssd-session-recording.5.xml:67 msgid "" "One of the following strings specifying the scope of session recording: " "<placeholder type=\"variablelist\" id=\"0\"/>" msgstr "" +"L'une des chaînes suivantes spécifiant la portée de l'enregistrement de " +"session : <placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2424 sssd-session-recording.5.xml:101 +#: sssd.conf.5.xml:2470 sssd-session-recording.5.xml:101 msgid "Default: \"none\"" -msgstr "" +msgstr "Valeur par défaut : « aucune »" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2429 sssd-session-recording.5.xml:106 +#: sssd.conf.5.xml:2475 sssd-session-recording.5.xml:106 msgid "users (string)" -msgstr "" +msgstr "utilisateurs (chaîne de caractères)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2432 sssd-session-recording.5.xml:109 +#: sssd.conf.5.xml:2478 sssd-session-recording.5.xml:109 msgid "" "A comma-separated list of users which should have session recording enabled. " "Matches user names as returned by NSS. I.e. after the possible space " "replacement, case changes, etc." msgstr "" +"Liste d'utilisateurs, séparés par des virgules, pour lesquels " +"l'enregistrement de session doit être activé. Les noms d'utilisateur doivent " +"correspondre à ceux renvoyés par NSS, c'est-à-dire après les éventuelles " +"modifications d'espaces, de casse, etc." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2438 sssd-session-recording.5.xml:115 +#: sssd.conf.5.xml:2484 sssd-session-recording.5.xml:115 msgid "Default: Empty. Matches no users." -msgstr "" +msgstr "Valeur par défaut : vide. Ne correspond à aucun utilisateur." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2443 sssd-session-recording.5.xml:120 +#: sssd.conf.5.xml:2489 sssd-session-recording.5.xml:120 msgid "groups (string)" -msgstr "" +msgstr "groupes (chaîne)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2446 sssd-session-recording.5.xml:123 +#: sssd.conf.5.xml:2492 sssd-session-recording.5.xml:123 msgid "" "A comma-separated list of groups, members of which should have session " "recording enabled. Matches group names as returned by NSS. I.e. after the " "possible space replacement, case changes, etc." msgstr "" +"Liste de groupes, séparés par des virgules, dont les membres doivent avoir " +"l'enregistrement de session activé. Les noms de groupes doivent correspondre " +"à ceux renvoyés par NSS, c'est-à-dire après les éventuelles modifications " +"d'espaces, de casse, etc." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2452 sssd.conf.5.xml:2484 sssd-session-recording.5.xml:129 +#: sssd.conf.5.xml:2498 sssd.conf.5.xml:2530 sssd-session-recording.5.xml:129 #: sssd-session-recording.5.xml:161 msgid "" "NOTE: using this option (having it set to anything) has a considerable " "performance cost, because each uncached request for a user requires " "retrieving and matching the groups the user is member of." msgstr "" +"REMARQUE : l'utilisation de cette option (quelle que soit sa valeur) a un " +"coût considérable en termes de performances, car chaque requête non mise en " +"cache pour un utilisateur nécessite de récupérer et de faire correspondre " +"les groupes auxquels l'utilisateur appartient." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2459 sssd-session-recording.5.xml:136 +#: sssd.conf.5.xml:2505 sssd-session-recording.5.xml:136 msgid "Default: Empty. Matches no groups." -msgstr "" +msgstr "Valeur par défaut : vide. Ne correspond à aucun groupe." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2464 sssd-session-recording.5.xml:141 +#: sssd.conf.5.xml:2510 sssd-session-recording.5.xml:141 #, fuzzy #| msgid "simple_deny_users (string)" msgid "exclude_users (string)" msgstr "simple_deny_users (chaîne)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2467 sssd-session-recording.5.xml:144 +#: sssd.conf.5.xml:2513 sssd-session-recording.5.xml:144 msgid "" "A comma-separated list of users to be excluded from recording, only " "applicable with 'scope=all'." msgstr "" +"Liste d'utilisateurs séparés par des virgules à exclure de l'enregistrement, " +"applicable uniquement avec 'scope=all'." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2471 sssd-session-recording.5.xml:148 +#: sssd.conf.5.xml:2517 sssd-session-recording.5.xml:148 #, fuzzy #| msgid "Default: empty, i.e. ldap_uri is used." msgid "Default: Empty. No users excluded." -msgstr "Par défaut : vide, ldap_uri est donc utilisé." +msgstr "Par défaut : vide, ldap_uri est donc utilisé." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2476 sssd-session-recording.5.xml:153 +#: sssd.conf.5.xml:2522 sssd-session-recording.5.xml:153 #, fuzzy #| msgid "simple_deny_groups (string)" msgid "exclude_groups (string)" msgstr "simple_deny_groups (chaîne)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2479 sssd-session-recording.5.xml:156 +#: sssd.conf.5.xml:2525 sssd-session-recording.5.xml:156 msgid "" "A comma-separated list of groups, members of which should be excluded from " "recording. Only applicable with 'scope=all'." msgstr "" +"Liste de groupes, séparés par des virgules, dont les membres doivent être " +"exclus de l'enregistrement. Applicable uniquement avec « scope=all »." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2491 sssd-session-recording.5.xml:168 +#: sssd.conf.5.xml:2537 sssd-session-recording.5.xml:168 #, fuzzy #| msgid "Default: empty, i.e. ldap_uri is used." msgid "Default: Empty. No groups excluded." -msgstr "Par défaut : vide, ldap_uri est donc utilisé." +msgstr "Par défaut : vide, ldap_uri est donc utilisé." #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:2501 +#: sssd.conf.5.xml:2547 msgid "DOMAIN SECTIONS" msgstr "SECTIONS DOMAINES" -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry><para> -#: sssd.conf.5.xml:2508 sssd.conf.5.xml:3964 sssd.conf.5.xml:3965 -#: sssd.conf.5.xml:3968 -msgid "enabled" -msgstr "" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2554 +#, fuzzy +#| msgid "ad_enable_gc (boolean)" +msgid "enabled (boolean)" +msgstr "ad_enable_gc (booléen)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2511 +#: sssd.conf.5.xml:2557 msgid "" "Explicitly enable or disable the domain. If <quote>true</quote>, the domain " "is always <quote>enabled</quote>. If <quote>false</quote>, the domain is " @@ -3354,63 +3923,81 @@ msgid "" "enabled only if it is listed in the domains option in the <quote>[sssd]</" "quote> section." msgstr "" +"Activez ou désactivez explicitement le domaine. Si la valeur est « true », " +"le domaine est toujours activé. Si la valeur est « false », le domaine est " +"toujours désactivé. Si cette option n'est pas définie, le domaine est activé " +"uniquement s'il figure dans l'option « domains » de la section « [sssd] »." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2523 +#: sssd.conf.5.xml:2569 msgid "domain_type (string)" -msgstr "" +msgstr "type_domaine (chaîne)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2526 +#: sssd.conf.5.xml:2572 msgid "" "Specifies whether the domain is meant to be used by POSIX-aware clients such " "as the Name Service Switch or by applications that do not need POSIX data to " "be present or generated. Only objects from POSIX domains are available to " "the operating system interfaces and utilities." msgstr "" +"Indique si le domaine est destiné à être utilisé par des clients compatibles " +"POSIX, tels que le commutateur de service de noms, ou par des applications " +"qui n'ont pas besoin de données POSIX. Seuls les objets des domaines POSIX " +"sont accessibles aux interfaces et utilitaires du système d'exploitation." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2534 +#: sssd.conf.5.xml:2580 msgid "" "Allowed values for this option are <quote>posix</quote> and " "<quote>application</quote>." msgstr "" +"Les valeurs autorisées pour cette option sont <quote>posix</quote> et <quote>" +"application</quote>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2538 +#: sssd.conf.5.xml:2584 msgid "" "POSIX domains are reachable by all services. Application domains are only " "reachable from the InfoPipe responder (see <citerefentry> " "<refentrytitle>sssd-ifp</refentrytitle> <manvolnum>5</manvolnum> </" "citerefentry>) and the PAM responder." msgstr "" +"Les domaines POSIX sont accessibles par tous les services. Les domaines " +"d'application ne sont accessibles que depuis le répondeur InfoPipe (voir " +"<citerefentry> <refentrytitle>sssd-ifp</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry>) et le répondeur PAM." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2546 +#: sssd.conf.5.xml:2592 msgid "" "NOTE: The application domains are currently well tested with " "<quote>id_provider=ldap</quote> only." msgstr "" +"REMARQUE : Les domaines d'application sont actuellement bien testés avec " +"<quote>id_provider=ldap</quote> uniquement." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2550 +#: sssd.conf.5.xml:2596 msgid "" "For an easy way to configure a non-POSIX domains, please see the " "<quote>Application domains</quote> section." msgstr "" +"Pour configurer facilement un domaine non-POSIX, veuillez consulter la " +"section <quote>Domaines d'application</quote>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2554 +#: sssd.conf.5.xml:2600 msgid "Default: posix" -msgstr "" +msgstr "Par défaut : posix" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2560 +#: sssd.conf.5.xml:2606 msgid "min_id,max_id (integer)" msgstr "min_id,max_id (entier)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2563 +#: sssd.conf.5.xml:2609 msgid "" "UID and GID limits for the domain. If a domain contains an entry that is " "outside these limits, it is ignored." @@ -3419,7 +4006,7 @@ msgstr "" "dehors de ces limites, elle est ignorée." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2568 +#: sssd.conf.5.xml:2614 msgid "" "For users, this affects the primary GID limit. The user will not be returned " "to NSS if either the UID or the primary GID is outside the range. For non-" @@ -3432,7 +4019,7 @@ msgstr "" "qui sont dans la plage seront rapportés comme prévu." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2575 +#: sssd.conf.5.xml:2621 msgid "" "These ID limits affect even saving entries to cache, not only returning them " "by name or ID." @@ -3441,55 +4028,65 @@ msgstr "" "pas seulement leur recherche par nom ou identifiant." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2579 +#: sssd.conf.5.xml:2625 msgid "Default: 1 for min_id, 0 (no limit) for max_id" msgstr "Default: 1 for min_id, 0 (no limit) for max_id" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2585 -msgid "enumerate (bool)" +#: sssd.conf.5.xml:2631 +#, fuzzy +#| msgid "enumerate (bool)" +msgid "enumerate (boolean)" msgstr "enumerate (booléen)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2588 +#: sssd.conf.5.xml:2634 msgid "" "Determines if a domain can be enumerated, that is, whether the domain can " "list all the users and group it contains. Note that it is not required to " "enable enumeration in order for secondary groups to be displayed. This " "parameter can have one of the following values:" msgstr "" +"Détermine si un domaine peut être énuméré, c'est-à-dire s'il peut lister " +"tous les utilisateurs et groupes qu'il contient. Notez que l'activation de " +"l'énumération n'est pas nécessaire pour que les groupes secondaires " +"s'affichent. Ce paramètre peut prendre l'une des valeurs suivantes :" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2596 +#: sssd.conf.5.xml:2642 msgid "TRUE = Users and groups are enumerated" msgstr "TRUE = utilisateurs et groupes sont énumérés" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2599 +#: sssd.conf.5.xml:2645 msgid "FALSE = No enumerations for this domain" msgstr "FALSE = aucune énumération pour ce domaine" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2602 sssd.conf.5.xml:2867 sssd.conf.5.xml:3044 +#: sssd.conf.5.xml:2648 sssd.conf.5.xml:2992 sssd.conf.5.xml:3174 msgid "Default: FALSE" msgstr "Par défaut : FALSE" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2605 +#: sssd.conf.5.xml:2651 msgid "" "Enumerating a domain requires SSSD to download and store ALL user and group " "entries from the remote server." msgstr "" +"L'énumération d'un domaine nécessite que SSSD télécharge et stocke TOUTES " +"les entrées d'utilisateurs et de groupes depuis le serveur distant." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2610 +#: sssd.conf.5.xml:2656 msgid "" "Feature is only supported for domains with id_provider = ldap or id_provider " "= proxy." msgstr "" +"Cette fonctionnalité est uniquement prise en charge pour les domaines avec " +"id_provider = ldap ou id_provider = proxy." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2614 +#: sssd.conf.5.xml:2660 msgid "" "Note: Enabling enumeration has a severe performance impact on SSSD while " "enumeration is running. It may take up to several minutes after SSSD startup " @@ -3501,9 +4098,19 @@ msgid "" "quote> process becoming unresponsive or even restarted by the internal " "watchdog." msgstr "" +"Remarque : L’activation de l’énumération a un impact important sur les " +"performances de SSSD pendant son exécution. L’énumération complète peut " +"prendre jusqu’à plusieurs minutes après le démarrage de SSSD. Pendant ce " +"temps, les requêtes d’information individuelles seront directement envoyées " +"à LDAP, mais le traitement peut être lent en raison de l’important volume de " +"données nécessaires à l’énumération. L’enregistrement d’un grand nombre " +"d’entrées dans le cache après l’énumération peut également solliciter " +"fortement le processeur, car les appartenances doivent être recalculées. " +"Cela peut entraîner le blocage du processus `sssd_be` ou même son " +"redémarrage par le système de surveillance interne." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2629 +#: sssd.conf.5.xml:2675 msgid "" "While the first enumeration is running, requests for the complete user or " "group lists may return no results until it completes." @@ -3513,7 +4120,7 @@ msgstr "" "l'énumération ne se termine." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2634 +#: sssd.conf.5.xml:2680 msgid "" "Further, enabling enumeration may increase the time necessary to detect " "network disconnection, as longer timeouts are required to ensure that " @@ -3527,7 +4134,7 @@ msgstr "" "fournisseur d'identité spécifique utilisé." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2642 +#: sssd.conf.5.xml:2688 msgid "" "For the reasons cited above, enabling enumeration is not recommended, " "especially in large environments." @@ -3536,20 +4143,24 @@ msgstr "" "déconseillée, surtout dans les environnements de grande taille." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2647 +#: sssd.conf.5.xml:2693 msgid "" "Note: the proxy provider is tested with open source modules like " "'libnss_files' and 'libnss_ldap'. 3rd party modules must follow the " "documented behavior of nss modules to be used in this configuration." msgstr "" +"Remarque : le fournisseur de proxy est testé avec des modules open source " +"tels que « libnss_files » et « libnss_ldap ». Les modules tiers doivent " +"respecter le comportement documenté des modules nss pour être utilisés dans " +"cette configuration." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2656 +#: sssd.conf.5.xml:2702 msgid "entry_cache_timeout (integer)" msgstr "entry_cache_timeout (entier)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2659 +#: sssd.conf.5.xml:2705 msgid "" "How many seconds should nss_sss consider entries valid before asking the " "backend again" @@ -3558,7 +4169,7 @@ msgstr "" "comme valides avant de les redemander au moteur" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2663 +#: sssd.conf.5.xml:2709 msgid "" "The cache expiration timestamps are stored as attributes of individual " "objects in the cache. Therefore, changing the cache timeout only has effect " @@ -3576,17 +4187,17 @@ msgstr "" "entrées qui sont déjà en cache." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2676 +#: sssd.conf.5.xml:2722 msgid "Default: 5400" msgstr "Par défaut : 5400" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2682 +#: sssd.conf.5.xml:2728 msgid "entry_cache_user_timeout (integer)" msgstr "entry_cache_user_timeout (entier)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2685 +#: sssd.conf.5.xml:2731 msgid "" "How many seconds should nss_sss consider user entries valid before asking " "the backend again" @@ -3595,19 +4206,19 @@ msgstr "" "d'utilisateurs comme valides avant de les redemander au moteur." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2689 sssd.conf.5.xml:2702 sssd.conf.5.xml:2715 -#: sssd.conf.5.xml:2728 sssd.conf.5.xml:2742 sssd.conf.5.xml:2755 -#: sssd.conf.5.xml:2769 sssd.conf.5.xml:2783 sssd.conf.5.xml:2796 +#: sssd.conf.5.xml:2735 sssd.conf.5.xml:2748 sssd.conf.5.xml:2761 +#: sssd.conf.5.xml:2774 sssd.conf.5.xml:2788 sssd.conf.5.xml:2801 +#: sssd.conf.5.xml:2815 sssd.conf.5.xml:2829 msgid "Default: entry_cache_timeout" msgstr "Par défaut : entry_cache_timeout" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2695 +#: sssd.conf.5.xml:2741 msgid "entry_cache_group_timeout (integer)" msgstr "entry_cache_group_timeout (entier)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2698 +#: sssd.conf.5.xml:2744 msgid "" "How many seconds should nss_sss consider group entries valid before asking " "the backend again" @@ -3616,12 +4227,12 @@ msgstr "" "groupes comme valides avant de les redemander au moteur." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2708 +#: sssd.conf.5.xml:2754 msgid "entry_cache_netgroup_timeout (integer)" msgstr "entry_cache_netgroup_timeout (entier)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2711 +#: sssd.conf.5.xml:2757 msgid "" "How many seconds should nss_sss consider netgroup entries valid before " "asking the backend again" @@ -3630,12 +4241,12 @@ msgstr "" "netgroup comme valides avant de les redemander au moteur." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2721 +#: sssd.conf.5.xml:2767 msgid "entry_cache_service_timeout (integer)" msgstr "entry_cache_service_timeout (entier)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2724 +#: sssd.conf.5.xml:2770 msgid "" "How many seconds should nss_sss consider service entries valid before asking " "the backend again" @@ -3644,24 +4255,26 @@ msgstr "" "service valides avant de les redemander au moteur" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2734 +#: sssd.conf.5.xml:2780 msgid "entry_cache_resolver_timeout (integer)" -msgstr "" +msgstr "délai_d'expiration_du_résolveur_cache_d'entrée (entier)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2737 +#: sssd.conf.5.xml:2783 msgid "" "How many seconds should nss_sss consider hosts and networks entries valid " "before asking the backend again" msgstr "" +"Combien de secondes nss_sss doit-il considérer les entrées hôtes et réseaux " +"comme valides avant d'interroger à nouveau le serveur ?" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2748 +#: sssd.conf.5.xml:2794 msgid "entry_cache_sudo_timeout (integer)" msgstr "entry_cache_sudo_timeout (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2751 +#: sssd.conf.5.xml:2797 msgid "" "How many seconds should sudo consider rules valid before asking the backend " "again" @@ -3670,12 +4283,12 @@ msgstr "" "valides avant de les redemander au moteur" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2761 +#: sssd.conf.5.xml:2807 msgid "entry_cache_autofs_timeout (integer)" msgstr "entry_cache_autofs_timeout (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2764 +#: sssd.conf.5.xml:2810 msgid "" "How many seconds should the autofs service consider automounter maps valid " "before asking the backend again" @@ -3684,12 +4297,12 @@ msgstr "" "cartes d'automontage comme valides avant de les redemander au moteur" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2775 +#: sssd.conf.5.xml:2821 msgid "entry_cache_ssh_host_timeout (integer)" msgstr "entry_cache_ssh_host_timeout (entier)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2778 +#: sssd.conf.5.xml:2824 msgid "" "How many seconds to keep a host ssh key after refresh. IE how long to cache " "the host key for." @@ -3698,24 +4311,153 @@ msgstr "" "rafraichissement. I.e. combien de temps mettre la clé en cache." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2789 -msgid "entry_cache_computer_timeout (integer)" +#: sssd.conf.5.xml:2835 +msgid "offline_timeout (integer)" +msgstr "offline_timeout (entier)" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2838 +msgid "" +"When SSSD switches to offline mode the amount of time before it tries to go " +"back online will increase based upon the time spent disconnected. By " +"default SSSD uses incremental behaviour to calculate delay in between " +"retries. So, the wait time for a given retry will be longer than the wait " +"time for the previous ones. After each unsuccessful attempt to go online, " +"the new interval is recalculated by the following:" msgstr "" +"Lorsque SSSD passe en mode hors ligne, le délai avant la prochaine tentative " +"de connexion augmente en fonction de la durée de la déconnexion. Par défaut, " +"SSSD utilise un calcul incrémentiel pour allonger ce délai. Ainsi, le temps " +"d'attente pour une nouvelle tentative est plus long que pour les " +"précédentes. Après chaque tentative infructueuse de connexion, le nouvel " +"intervalle est recalculé comme suit :" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2792 +#: sssd.conf.5.xml:2849 sssd.conf.5.xml:2907 msgid "" -"How many seconds to keep the local computer entry before asking the backend " -"again" +"new_delay = Minimum(old_delay * 2, offline_timeout_max) + " +"random[0...offline_timeout_random_offset]" +msgstr "" +"nouveau_délai = Minimum(ancien_délai * 2, délai_d'inactivité_max) + " +"aléatoire[0...décalage_aléatoire_d'inactivité]" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2852 +msgid "" +"The offline_timeout default value is 60. The offline_timeout_max default " +"value is 3600. The offline_timeout_random_offset default value is 30. The " +"end result is the number of seconds before next retry." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2858 +msgid "" +"Note that the maximum length of each interval is defined by " +"offline_timeout_max (apart from the random part)." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2802 +#: sssd.conf.5.xml:2868 +msgid "offline_timeout_max (integer)" +msgstr "délai_d'inactivité_max (entier)" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2871 +msgid "" +"Controls by how much the time between attempts to go online can be " +"incremented following unsuccessful attempts to go online." +msgstr "" +"Contrôle la façon dont le délai entre les tentatives de connexion peut être " +"incrémenté après des tentatives infructueuses." + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2876 +msgid "A value of 0 disables the incrementing behaviour." +msgstr "La valeur 0 désactive l'incrémentation." + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2879 +msgid "" +"The value of this parameter should be set in correlation to offline_timeout " +"parameter value." +msgstr "" +"La valeur de ce paramètre doit être définie en corrélation avec la valeur du " +"paramètre offline_timeout." + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2883 +msgid "" +"With offline_timeout set to 60 (default value) there is no point in setting " +"offline_timeout_max to less than 120 as it will saturate instantly. General " +"rule here should be to set offline_timeout_max to at least 4 times " +"offline_timeout." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2889 +msgid "" +"Although a value between 0 and offline_timeout may be specified, it has the " +"effect of overriding the offline_timeout value so is of little use." +msgstr "" +"Bien qu'une valeur comprise entre 0 et offline_timeout puisse être " +"spécifiée, elle a pour effet de remplacer la valeur offline_timeout et " +"s'avère donc peu utile." + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2894 +msgid "Default: 3600" +msgstr "Default: 3600" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2900 +msgid "offline_timeout_random_offset (integer)" +msgstr "délai_d'inactivité_aléatoire (entier)" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2903 +msgid "" +"When SSSD is in offline mode it keeps probing backend servers in specified " +"time intervals:" +msgstr "" +"Lorsque SSSD est en mode hors ligne, il continue d'interroger les serveurs " +"backend à intervalles de temps spécifiés :" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2910 +msgid "" +"This parameter controls the value of the random offset used for the above " +"equation. Final random_offset value will be random number in range:" +msgstr "" +"Ce paramètre contrôle la valeur du décalage aléatoire utilisé pour " +"l'équation ci-dessus. La valeur finale de random_offset sera un nombre " +"aléatoire compris dans la plage :" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2915 +#, fuzzy +#| msgid "offline_timeout + random_offset" +msgid "[0 - offline_timeout_random_offset]" +msgstr "offline_timeout + random_offset" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2918 +msgid "A value of 0 disables the random offset addition." +msgstr "La valeur 0 désactive l'ajout de décalage aléatoire." + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2921 +#, fuzzy +#| msgid "Default: 300" +msgid "Default: 30" +msgstr "Par défaut : 300" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2927 msgid "refresh_expired_interval (integer)" msgstr "refresh_expired_interval (entier)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2805 +#: sssd.conf.5.xml:2930 msgid "" "Specifies how many seconds SSSD has to wait before triggering a background " "refresh task which will refresh all expired or nearly expired records." @@ -3725,27 +4467,33 @@ msgstr "" "enregistrements expirés ou sur le point de l'être." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2810 +#: sssd.conf.5.xml:2935 msgid "" "The background refresh will process users, groups and netgroups in the " "cache. For users who have performed the initgroups (get group membership for " "user, typically ran at login) operation in the past, both the user entry " "and the group membership are updated." msgstr "" +"L'actualisation en arrière-plan traitera les utilisateurs, les groupes et " +"les groupes réseau présents dans le cache. Pour les utilisateurs ayant déjà " +"effectué l'opération initgroups (obtention de l'appartenance à un groupe, " +"généralement exécutée lors de la connexion), leur fiche utilisateur et leur " +"appartenance à un groupe seront mises à jour." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2818 +#: sssd.conf.5.xml:2943 msgid "This option is automatically inherited for all trusted domains." msgstr "" +"Cette option est automatiquement héritée pour tous les domaines de confiance." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2822 +#: sssd.conf.5.xml:2947 msgid "You can consider setting this value to 3/4 * entry_cache_timeout." msgstr "" "Il est envisageable de configurer cette valeur à 3/4 * entry_cache_timeout." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2826 +#: sssd.conf.5.xml:2951 msgid "" "Cache entry will be refreshed by background task when 2/3 of cache timeout " "has already passed. If there are existing cached entries, the background " @@ -3755,20 +4503,31 @@ msgid "" "offline mode operation and reuse of existing valid cache entries. To make " "this change instant the user may want to manually invalidate existing cache." msgstr "" +"L'entrée du cache sera actualisée par une tâche en arrière-plan lorsque les " +"deux tiers du délai d'expiration du cache seront écoulés. Si des entrées " +"sont déjà en cache, la tâche en arrière-plan utilisera leurs valeurs de " +"délai d'expiration d'origine plutôt que la valeur de configuration actuelle. " +"Il est possible que l'actualisation en arrière-plan semble alors ne pas " +"fonctionner. Ce comportement est intentionnel afin d'optimiser le " +"fonctionnement hors ligne et la réutilisation des entrées de cache valides. " +"Pour une mise à jour instantanée, l'utilisateur peut invalider manuellement " +"le cache existant." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2839 sssd-ldap.5.xml:406 sssd-ldap.5.xml:1834 -#: sssd-ipa.5.xml:255 +#: sssd.conf.5.xml:2964 sssd-ldap.5.xml:406 sssd-ldap.5.xml:1834 +#: sssd-ipa.5.xml:250 msgid "Default: 0 (disabled)" msgstr "Par défaut : 0 (désactivé)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2845 -msgid "cache_credentials (bool)" +#: sssd.conf.5.xml:2970 +#, fuzzy +#| msgid "cache_credentials (bool)" +msgid "cache_credentials (boolean)" msgstr "cache_credentials (booléen)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2848 +#: sssd.conf.5.xml:2973 msgid "" "Determines if user credentials are also cached in the local LDB cache. The " "cached credentials refer to passwords, which includes the first (long term) " @@ -3777,43 +4536,64 @@ msgid "" "as a successful online authentication is recorded in the cache without " "additional configuration." msgstr "" +"Détermine si les informations d'identification de l'utilisateur sont " +"également mises en cache dans le cache LDB local. Les informations " +"d'identification mises en cache concernent les mots de passe, y compris le " +"premier facteur (à long terme) de l'authentification à deux facteurs, et non " +"les autres mécanismes d'authentification. L'authentification par mot de " +"passe et par carte à puce devrait fonctionner hors ligne dès lors qu'une " +"authentification en ligne réussie est enregistrée dans le cache sans " +"configuration supplémentaire." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2859 +#: sssd.conf.5.xml:2984 msgid "" "Take a note that while credentials are stored as a salted SHA512 hash, this " "still potentially poses some security risk in case an attacker manages to " "get access to a cache file (normally requires privileged access) and to " "break a password using brute force attack." msgstr "" +"Notez que même si les identifiants sont stockés sous forme de hachage SHA512 " +"salé, cela présente toujours un risque potentiel pour la sécurité si un " +"attaquant parvient à accéder à un fichier cache (ce qui nécessite " +"normalement un accès privilégié) et à casser un mot de passe à l'aide d'une " +"attaque par force brute." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2873 +#: sssd.conf.5.xml:2998 msgid "cache_credentials_minimal_first_factor_length (int)" -msgstr "" +msgstr "cache_credentials_minimal_first_factor_length (int)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2876 +#: sssd.conf.5.xml:3001 msgid "" "If 2-Factor-Authentication (2FA) is used and credentials should be saved " "this value determines the minimal length the first authentication factor " "(long term password) must have to be saved as SHA512 hash into the cache." msgstr "" +"Si l'authentification à deux facteurs (2FA) est utilisée et que les " +"informations d'identification doivent être enregistrées, cette valeur " +"détermine la longueur minimale que le premier facteur d'authentification " +"(mot de passe à long terme) doit avoir pour être enregistré sous forme de " +"hachage SHA512 dans le cache." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2883 +#: sssd.conf.5.xml:3008 msgid "" "This should avoid that the short PINs of a PIN based 2FA scheme are saved in " "the cache which would make them easy targets for brute-force attacks." msgstr "" +"Cela devrait éviter que les codes PIN courts d'un système d'authentification " +"à deux facteurs basé sur un code PIN ne soient enregistrés dans le cache, ce " +"qui en ferait des cibles faciles pour les attaques par force brute." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2894 +#: sssd.conf.5.xml:3019 msgid "account_cache_expiration (integer)" msgstr "account_cache_expiration (entier)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2897 +#: sssd.conf.5.xml:3022 msgid "" "Number of days entries are left in cache after last successful login before " "being removed during a cleanup of the cache. 0 means keep forever. The " @@ -3826,17 +4606,17 @@ msgstr "" "paramètre doit être supérieur ou égal à offline_credentials_expiration." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2904 +#: sssd.conf.5.xml:3029 msgid "Default: 0 (unlimited)" msgstr "Par défaut : 0 (illimité)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2909 +#: sssd.conf.5.xml:3034 msgid "pwd_expiration_warning (integer)" msgstr "pwd_expiration_warning (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2920 +#: sssd.conf.5.xml:3045 msgid "" "Please note that the backend server has to provide information about the " "expiration time of the password. If this information is missing, sssd " @@ -3849,17 +4629,17 @@ msgstr "" "fournisseur oauth doit être configuré pour le moteur." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2927 +#: sssd.conf.5.xml:3052 msgid "Default: 7 (Kerberos), 0 (LDAP)" msgstr "Par défaut : 7 (Kerberos), 0 (LDAP)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2933 +#: sssd.conf.5.xml:3058 msgid "id_provider (string)" msgstr "id_provider (chaîne)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2936 +#: sssd.conf.5.xml:3061 msgid "" "The identification provider used for the domain. Supported ID providers are:" msgstr "" @@ -3867,12 +4647,12 @@ msgstr "" "d'identification pris en charge sont :" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2940 +#: sssd.conf.5.xml:3065 msgid "<quote>proxy</quote>: Support a legacy NSS provider." -msgstr "" +msgstr "<quote>proxy</quote> : Prise en charge d’un fournisseur NSS hérité." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2943 +#: sssd.conf.5.xml:3068 msgid "" "<quote>ldap</quote>: LDAP provider. See <citerefentry> <refentrytitle>sssd-" "ldap</refentrytitle> <manvolnum>5</manvolnum> </citerefentry> for more " @@ -3883,8 +4663,8 @@ msgstr "" "d'informations sur la configuration de LDAP." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2951 sssd.conf.5.xml:3070 sssd.conf.5.xml:3129 -#: sssd.conf.5.xml:3192 +#: sssd.conf.5.xml:3076 sssd.conf.5.xml:3200 sssd.conf.5.xml:3259 +#: sssd.conf.5.xml:3322 #, fuzzy #| msgid "" #| "<quote>ipa</quote>: FreeIPA and Red Hat Enterprise Identity Management " @@ -3902,8 +4682,8 @@ msgstr "" "configuration de FreeIPA." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2960 sssd.conf.5.xml:3079 sssd.conf.5.xml:3138 -#: sssd.conf.5.xml:3201 +#: sssd.conf.5.xml:3085 sssd.conf.5.xml:3209 sssd.conf.5.xml:3268 +#: sssd.conf.5.xml:3331 msgid "" "<quote>ad</quote>: Active Directory provider. See <citerefentry> " "<refentrytitle>sssd-ad</refentrytitle> <manvolnum>5</manvolnum> </" @@ -3915,7 +4695,7 @@ msgstr "" "Directory." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2968 +#: sssd.conf.5.xml:3093 #, fuzzy #| msgid "" #| "<quote>ipa</quote>: FreeIPA and Red Hat Enterprise Identity Management " @@ -3932,13 +4712,22 @@ msgstr "" "<manvolnum>5</manvolnum></citerefentry> pour plus d'informations sur la " "configuration de FreeIPA." +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3101 +msgid "" +"Default: Not set (This is a mandatory setting that must be explicitly " +"defined for each configured domain)." +msgstr "" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2979 -msgid "use_fully_qualified_names (bool)" +#: sssd.conf.5.xml:3109 +#, fuzzy +#| msgid "use_fully_qualified_names (bool)" +msgid "use_fully_qualified_names (boolean)" msgstr "use_fully_qualified_names (booléen)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2982 +#: sssd.conf.5.xml:3112 msgid "" "Use the full name and domain (as formatted by the domain's full_name_format) " "as the user's login name reported to NSS." @@ -3948,7 +4737,7 @@ msgstr "" "communiqué à NSS." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2987 +#: sssd.conf.5.xml:3117 #, fuzzy #| msgid "" #| "If set to TRUE, all requests to this domain must use fully qualified " @@ -3968,7 +4757,7 @@ msgstr "" "trouve." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2995 +#: sssd.conf.5.xml:3125 msgid "" "NOTE: This option has no effect on netgroup lookups due to their tendency to " "include nested netgroups without qualified names. For netgroups, all domains " @@ -3980,24 +4769,28 @@ msgstr "" "qualifié sera demandé." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3002 +#: sssd.conf.5.xml:3132 msgid "" "Default: FALSE (TRUE for trusted domain/sub-domains or if " "default_domain_suffix is used)" msgstr "" +"Valeur par défaut : FAUX (VRAI pour les domaines/sous-domaines de confiance " +"ou si default_domain_suffix est utilisé)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3009 -msgid "ignore_group_members (bool)" +#: sssd.conf.5.xml:3139 +#, fuzzy +#| msgid "ignore_group_members (bool)" +msgid "ignore_group_members (boolean)" msgstr "ignore_group_members (booléen)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3012 +#: sssd.conf.5.xml:3142 msgid "Do not return group members for group lookups." msgstr "Ne pas envoyer les membres des groupes sur les recherches de groupes." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3015 +#: sssd.conf.5.xml:3145 msgid "" "If set to TRUE, the group membership attribute is not requested from the " "ldap server, and group members are not returned when processing group lookup " @@ -4007,17 +4800,27 @@ msgid "" "citerefentry>. As an effect, <quote>getent group $groupname</quote> would " "return the requested group as if it was empty." msgstr "" +"Si la valeur est TRUE, l'attribut d'appartenance au groupe n'est pas demandé " +"au serveur LDAP et les membres du groupe ne sont pas renvoyés lors du " +"traitement des appels de recherche de groupe, tels que `<citerefentry> " +"<refentrytitle>getgrnam</refentrytitle> <manvolnum>3</manvolnum> </" +"citerefentry>` ou `<citerefentry> <refentrytitle>getgrgid</refentrytitle> " +"<manvolnum>3</manvolnum> </citerefentry>`. Par conséquent, `<quote>getent " +"group $groupname</quote>` renverra le groupe demandé comme s'il était vide." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3033 +#: sssd.conf.5.xml:3163 msgid "" "Enabling this option can also make access provider checks for group " "membership significantly faster, especially for groups containing many " "members." msgstr "" +"L'activation de cette option peut également accélérer considérablement les " +"vérifications d'appartenance au groupe effectuées par les fournisseurs " +"d'accès, notamment pour les groupes comportant de nombreux membres." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3039 sssd.conf.5.xml:3767 sssd-ldap.5.xml:401 +#: sssd.conf.5.xml:3169 sssd.conf.5.xml:3951 sssd-ldap.5.xml:401 #: sssd-ldap.5.xml:454 sssd-ldap.5.xml:529 sssd-ldap.5.xml:576 #: sssd-ldap.5.xml:599 sssd-ldap.5.xml:638 sssd-ldap.5.xml:657 #: sssd-ldap.5.xml:681 sssd-ldap.5.xml:1114 sssd-ldap.5.xml:1147 @@ -4025,14 +4828,16 @@ msgid "" "This option can be also set per subdomain or inherited via " "<emphasis>subdomain_inherit</emphasis>." msgstr "" +"Cette option peut également être définie par sous-domaine ou héritée via " +"<emphasis>subdomain_inherit</emphasis>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3049 +#: sssd.conf.5.xml:3179 msgid "auth_provider (string)" msgstr "auth_provider (chaîne)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3052 +#: sssd.conf.5.xml:3182 msgid "" "The authentication provider used for the domain. Supported auth providers " "are:" @@ -4041,7 +4846,7 @@ msgstr "" "pris en charge sont :" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3056 sssd.conf.5.xml:3122 +#: sssd.conf.5.xml:3186 sssd.conf.5.xml:3252 msgid "" "<quote>ldap</quote> for native LDAP authentication. See <citerefentry> " "<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> </" @@ -4049,11 +4854,11 @@ msgid "" msgstr "" "<quote>ldap</quote> pour une authentification LDAP native. Cf. " "<citerefentry> <refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</" -"manvolnum> </citerefentry> pour plus d'informations sur la configuration de " +"manvolnum> </citerefentry> pour plus d'informations sur la configuration de " "LDAP." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3063 +#: sssd.conf.5.xml:3193 msgid "" "<quote>krb5</quote> for Kerberos authentication. See <citerefentry> " "<refentrytitle>sssd-krb5</refentrytitle> <manvolnum>5</manvolnum> </" @@ -4064,7 +4869,7 @@ msgstr "" "citerefentry> pour plus d'informations sur la configuration de Kerberos." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3087 +#: sssd.conf.5.xml:3217 #, fuzzy #| msgid "" #| "<quote>ldap</quote> for native LDAP authentication. See <citerefentry> " @@ -4081,7 +4886,7 @@ msgstr "" "LDAP." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3095 +#: sssd.conf.5.xml:3225 msgid "" "<quote>proxy</quote> for relaying authentication to some other PAM target." msgstr "" @@ -4089,12 +4894,12 @@ msgstr "" "PAM." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3098 +#: sssd.conf.5.xml:3228 msgid "<quote>none</quote> disables authentication explicitly." msgstr "<quote>none</quote> désactive l'authentification explicitement." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3101 +#: sssd.conf.5.xml:3231 msgid "" "Default: <quote>id_provider</quote> is used if it is set and can handle " "authentication requests." @@ -4103,12 +4908,12 @@ msgstr "" "gérer les requêtes d'authentification." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3107 +#: sssd.conf.5.xml:3237 msgid "access_provider (string)" msgstr "access_provider (chaîne)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3110 +#: sssd.conf.5.xml:3240 msgid "" "The access control provider used for the domain. There are two built-in " "access providers (in addition to any included in installed backends) " @@ -4119,19 +4924,19 @@ msgstr "" "installés). Les fournisseurs internes spécifiques sont :" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3116 +#: sssd.conf.5.xml:3246 #, fuzzy #| msgid "<quote>deny</quote> always deny access." msgid "<quote>permit</quote> always allow access." msgstr "<quote>deny</quote> toujours refuser les accès." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3119 +#: sssd.conf.5.xml:3249 msgid "<quote>deny</quote> always deny access." msgstr "<quote>deny</quote> toujours refuser les accès." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3146 +#: sssd.conf.5.xml:3276 msgid "" "<quote>simple</quote> access control based on access or deny lists. See " "<citerefentry> <refentrytitle>sssd-simple</refentrytitle> <manvolnum>5</" @@ -4144,30 +4949,35 @@ msgstr "" "d'informations sur la configuration du module d'accès simple." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3153 +#: sssd.conf.5.xml:3283 msgid "" "<quote>krb5</quote>: .k5login based access control. See <citerefentry> " "<refentrytitle>sssd-krb5</refentrytitle> <manvolnum>5</manvolnum></" "citerefentry> for more information on configuring Kerberos." msgstr "" +"<quote>krb5</quote> : Contrôle d'accès basé sur .k5login. Voir " +"<citerefentry> <refentrytitle>sssd-krb5</refentrytitle> <manvolnum>5</" +"manvolnum></citerefentry> pour plus d'informations sur la configuration de " +"Kerberos." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3160 +#: sssd.conf.5.xml:3290 msgid "<quote>proxy</quote> for relaying access control to another PAM module." msgstr "" +"<quote>proxy</quote> pour relayer le contrôle d'accès à un autre module PAM." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3163 +#: sssd.conf.5.xml:3293 msgid "Default: <quote>permit</quote>" msgstr "Par défaut : <quote>permit</quote>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3168 +#: sssd.conf.5.xml:3298 msgid "chpass_provider (string)" msgstr "chpass_provider (chaîne)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3171 +#: sssd.conf.5.xml:3301 msgid "" "The provider which should handle change password operations for the domain. " "Supported change password providers are:" @@ -4176,15 +4986,17 @@ msgstr "" "domaine. Les fournisseurs pris en charge sont :" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3176 +#: sssd.conf.5.xml:3306 msgid "" "<quote>ldap</quote> to change a password stored in a LDAP server. See " "<citerefentry> <refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</" "manvolnum> </citerefentry> for more information on configuring LDAP." msgstr "" +"Utilisez LDAP pour modifier un mot de passe stocké sur un serveur LDAP. " +"Consultez sssd-ldap pour plus d'informations sur la configuration de LDAP." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3184 +#: sssd.conf.5.xml:3314 msgid "" "<quote>krb5</quote> to change the Kerberos password. See <citerefentry> " "<refentrytitle>sssd-krb5</refentrytitle> <manvolnum>5</manvolnum> </" @@ -4196,7 +5008,7 @@ msgstr "" "Kerberos." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3209 +#: sssd.conf.5.xml:3339 msgid "" "<quote>proxy</quote> for relaying password changes to some other PAM target." msgstr "" @@ -4204,14 +5016,14 @@ msgstr "" "autre cible PAM." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3213 +#: sssd.conf.5.xml:3343 msgid "<quote>none</quote> disallows password changes explicitly." msgstr "" "<quote>none</quote> pour désactiver explicitement le changement de mot de " "passe." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3216 +#: sssd.conf.5.xml:3346 msgid "" "Default: <quote>auth_provider</quote> is used if it is set and can handle " "change password requests." @@ -4220,19 +5032,19 @@ msgstr "" "peut gérer les changements de mot de passe." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3223 +#: sssd.conf.5.xml:3353 msgid "sudo_provider (string)" msgstr "sudo_provider (chaîne)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3226 +#: sssd.conf.5.xml:3356 msgid "The SUDO provider used for the domain. Supported SUDO providers are:" msgstr "" "Le fournisseur SUDO, utilisé pour le domaine. Les fournisseurs SUDO pris en " "charge sont :" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3230 +#: sssd.conf.5.xml:3360 msgid "" "<quote>ldap</quote> for rules stored in LDAP. See <citerefentry> " "<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> </" @@ -4243,7 +5055,7 @@ msgstr "" "citerefentry> pour plus d'informations sur la configuration de LDAP." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3238 +#: sssd.conf.5.xml:3368 msgid "" "<quote>ipa</quote> the same as <quote>ldap</quote> but with IPA default " "settings." @@ -4252,7 +5064,7 @@ msgstr "" "par défaut pour IPA." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3242 +#: sssd.conf.5.xml:3372 msgid "" "<quote>ad</quote> the same as <quote>ldap</quote> but with AD default " "settings." @@ -4261,12 +5073,12 @@ msgstr "" "par défaut pour AD." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3246 +#: sssd.conf.5.xml:3376 msgid "<quote>none</quote> disables SUDO explicitly." msgstr "<quote>none</quote> désactive explicitement SUDO." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3249 +#: sssd.conf.5.xml:3379 #, fuzzy #| msgid "" #| "Default: <quote>id_provider</quote> is used if it is set and can handle " @@ -4275,11 +5087,11 @@ msgid "" "Default: The value of <quote>id_provider</quote> is used if it is set and " "can handle sudo requests." msgstr "" -"Par défaut : <quote>id_provider</quote> est utilisé s'il est défini et peut " +"Par défaut : <quote>id_provider</quote> est utilisé s'il est défini et peut " "gérer le chargement selinux" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3253 +#: sssd.conf.5.xml:3383 msgid "" "The detailed instructions for configuration of sudo_provider are in the " "manual page <citerefentry> <refentrytitle>sssd-sudo</refentrytitle> " @@ -4288,23 +5100,33 @@ msgid "" "\"ldap_sudo_*\" in <citerefentry> <refentrytitle>sssd-ldap</refentrytitle> " "<manvolnum>5</manvolnum> </citerefentry>." msgstr "" +"Les instructions détaillées pour la configuration de sudo_provider se " +"trouvent dans la page de manuel <citerefentry> <refentrytitle>sssd-sudo</" +"refentrytitle> <manvolnum>5</manvolnum> </citerefentry>. De nombreuses " +"options de configuration permettent d'ajuster son comportement. Veuillez " +"vous référer à « ldap_sudo_* » dans <citerefentry> <refentrytitle>sssd-ldap</" +"refentrytitle> <manvolnum>5</manvolnum> </citerefentry>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3268 +#: sssd.conf.5.xml:3398 msgid "" "<emphasis>NOTE:</emphasis> Sudo rules are periodically downloaded in the " "background unless the sudo provider is explicitly disabled. Set " "<emphasis>sudo_provider = None</emphasis> to disable all sudo-related " "activity in SSSD if you do not want to use sudo with SSSD at all." msgstr "" +"Remarque : les règles sudo sont téléchargées périodiquement en arrière-plan, " +"sauf si le fournisseur sudo est explicitement désactivé. Définissez " +"`sudo_provider = None` pour désactiver toute activité liée à sudo dans SSSD " +"si vous ne souhaitez pas utiliser sudo avec SSSD." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3278 +#: sssd.conf.5.xml:3408 msgid "selinux_provider (string)" msgstr "selinux_provider (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3281 +#: sssd.conf.5.xml:3411 msgid "" "The provider which should handle loading of selinux settings. Note that this " "provider will be called right after access provider ends. Supported selinux " @@ -4315,7 +5137,7 @@ msgstr "" "fournisseur d'accès. Les fournisseurs selinux pris en charge sont :" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3287 +#: sssd.conf.5.xml:3417 msgid "" "<quote>ipa</quote> to load selinux settings from an IPA server. See " "<citerefentry> <refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</" @@ -4327,28 +5149,33 @@ msgstr "" "IPA." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3295 +#: sssd.conf.5.xml:3425 msgid "<quote>none</quote> disallows fetching selinux settings explicitly." msgstr "" "<quote>none</quote> n'autorise pas la récupération explicite des paramètres " "selinux." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3298 +#: sssd.conf.5.xml:3428 +#, fuzzy +#| msgid "" +#| "Default: <quote>id_provider</quote> is used if it is set and can handle " +#| "selinux loading requests." msgid "" -"Default: <quote>id_provider</quote> is used if it is set and can handle " -"selinux loading requests." +"Default: the value of <quote>id_provider</quote> is used if it is set and " +"can handle selinux loading requests. Otherwise the result is the same as if " +"the selinux_provider is set to none." msgstr "" "Par défaut : <quote>id_provider</quote> est utilisé s'il est défini et peut " "gérer le chargement selinux" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3304 +#: sssd.conf.5.xml:3435 msgid "subdomains_provider (string)" msgstr "subdomains_provider (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3307 +#: sssd.conf.5.xml:3438 msgid "" "The provider which should handle fetching of subdomains. This value should " "be always the same as id_provider. Supported subdomain providers are:" @@ -4358,7 +5185,7 @@ msgstr "" "fournisseurs de sous-domaine pris en charge sont :" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3313 +#: sssd.conf.5.xml:3444 msgid "" "<quote>ipa</quote> to load a list of subdomains from an IPA server. See " "<citerefentry> <refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</" @@ -4370,22 +5197,26 @@ msgstr "" "IPA." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3322 +#: sssd.conf.5.xml:3453 msgid "" "<quote>ad</quote> to load a list of subdomains from an Active Directory " "server. See <citerefentry> <refentrytitle>sssd-ad</refentrytitle> " "<manvolnum>5</manvolnum> </citerefentry> for more information on configuring " "the AD provider." msgstr "" +"Utilisez la commande `<quote>ad</quote>` pour charger une liste de sous-" +"domaines à partir d'un serveur Active Directory. Consultez `<citerefentry>" +"<refentrytitle>sssd-ad</refentrytitle><manvolnum>5</manvolnum></citerefentry>" +"` pour plus d'informations sur la configuration du fournisseur AD." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3331 +#: sssd.conf.5.xml:3462 msgid "<quote>none</quote> disallows fetching subdomains explicitly." msgstr "" "<quote>none</quote> désactive la récupération explicite des sous-domaines." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3335 +#: sssd.conf.5.xml:3466 #, fuzzy #| msgid "" #| "Default: <quote>id_provider</quote> is used if it is set and can handle " @@ -4394,47 +5225,54 @@ msgid "" "Default: The value of <quote>id_provider</quote> is used if it is set and " "can handle subdomain requests." msgstr "" -"Par défaut : <quote>id_provider</quote> est utilisé s'il est défini et peut " +"Par défaut : <quote>id_provider</quote> est utilisé s'il est défini et peut " "gérer le chargement selinux" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3341 +#: sssd.conf.5.xml:3472 msgid "session_provider (string)" -msgstr "" +msgstr "fournisseur_de_session (chaîne)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3344 +#: sssd.conf.5.xml:3475 msgid "" "The provider which configures and manages user session related tasks. The " "only user session task currently provided is the integration with Fleet " "Commander, which works only with IPA. Supported session providers are:" msgstr "" +"Le fournisseur qui configure et gère les tâches liées aux sessions " +"utilisateur. La seule tâche de session utilisateur actuellement disponible " +"est l'intégration avec Fleet Commander, qui fonctionne uniquement avec IPA. " +"Les fournisseurs de session pris en charge sont :" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3351 +#: sssd.conf.5.xml:3482 msgid "<quote>ipa</quote> to allow performing user session related tasks." msgstr "" +"<quote>ipa</quote> pour permettre l'exécution de tâches liées à la session " +"utilisateur." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3355 +#: sssd.conf.5.xml:3486 msgid "" "<quote>none</quote> does not perform any kind of user session related tasks." msgstr "" +"<quote>none</quote> n'effectue aucune tâche liée à la session utilisateur." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3359 +#: sssd.conf.5.xml:3490 #, fuzzy #| msgid "Default: <quote>permit</quote>" msgid "Default: <quote>none</quote>." -msgstr "Par défaut : <quote>permit</quote>" +msgstr "Par défaut : <quote>permit</quote>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3365 +#: sssd.conf.5.xml:3496 msgid "autofs_provider (string)" msgstr "autofs_provider (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3368 +#: sssd.conf.5.xml:3499 msgid "" "The autofs provider used for the domain. Supported autofs providers are:" msgstr "" @@ -4442,7 +5280,7 @@ msgstr "" "en charge sont :" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3372 +#: sssd.conf.5.xml:3503 msgid "" "<quote>ldap</quote> to load maps stored in LDAP. See <citerefentry> " "<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> </" @@ -4454,7 +5292,7 @@ msgstr "" "LDAP." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3379 +#: sssd.conf.5.xml:3510 msgid "" "<quote>ipa</quote> to load maps stored in an IPA server. See <citerefentry> " "<refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</manvolnum> </" @@ -4466,20 +5304,24 @@ msgstr "" "IPA." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3387 +#: sssd.conf.5.xml:3518 msgid "" "<quote>ad</quote> to load maps stored in an AD server. See <citerefentry> " "<refentrytitle>sssd-ad</refentrytitle> <manvolnum>5</manvolnum> </" "citerefentry> for more information on configuring the AD provider." msgstr "" +"Utilisez la commande `<quote>ad</quote>` pour charger les cartes stockées " +"sur un serveur AD. Consultez `<citerefentry><refentrytitle>sssd-ad</" +"refentrytitle><manvolnum>5</manvolnum></citerefentry>` pour plus " +"d'informations sur la configuration du fournisseur AD." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3396 +#: sssd.conf.5.xml:3527 msgid "<quote>none</quote> disables autofs explicitly." msgstr "<quote>none</quote> désactive explicitement autofs." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3399 +#: sssd.conf.5.xml:3530 #, fuzzy #| msgid "" #| "Default: <quote>id_provider</quote> is used if it is set and can handle " @@ -4488,16 +5330,16 @@ msgid "" "Default: The value of <quote>id_provider</quote> is used if it is set and " "can handle autofs requests." msgstr "" -"Par défaut : <quote>id_provider</quote> est utilisé s'il est défini et peut " +"Par défaut : <quote>id_provider</quote> est utilisé s'il est défini et peut " "gérer les requêtes d'authentification." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3406 +#: sssd.conf.5.xml:3537 msgid "hostid_provider (string)" msgstr "hostid_provider (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3409 +#: sssd.conf.5.xml:3540 msgid "" "The provider used for retrieving host identity information. Supported " "hostid providers are:" @@ -4506,7 +5348,7 @@ msgstr "" "systèmes. Les fournisseurs de hostid pris en charge sont :" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3413 +#: sssd.conf.5.xml:3544 msgid "" "<quote>ipa</quote> to load host identity stored in an IPA server. See " "<citerefentry> <refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</" @@ -4518,12 +5360,12 @@ msgstr "" "de IPA." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3421 +#: sssd.conf.5.xml:3552 msgid "<quote>none</quote> disables hostid explicitly." msgstr "<quote>none</quote> désactive explicitement hostid." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3424 +#: sssd.conf.5.xml:3555 #, fuzzy #| msgid "" #| "Default: <quote>id_provider</quote> is used if it is set and can handle " @@ -4532,52 +5374,64 @@ msgid "" "Default: The value of <quote>id_provider</quote> is used if it is set and " "can handle hostid requests." msgstr "" -"Par défaut : <quote>id_provider</quote> est utilisé s'il est défini et peut " +"Par défaut : <quote>id_provider</quote> est utilisé s'il est défini et peut " "gérer les requêtes d'authentification." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3431 +#: sssd.conf.5.xml:3562 msgid "resolver_provider (string)" -msgstr "" +msgstr "fournisseur_de_résolution (chaîne)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3434 +#: sssd.conf.5.xml:3565 msgid "" "The provider which should handle hosts and networks lookups. Supported " "resolver providers are:" msgstr "" +"Le fournisseur qui doit gérer les recherches d'hôtes et de réseaux. Les " +"fournisseurs de résolution pris en charge sont :" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3438 +#: sssd.conf.5.xml:3569 msgid "" "<quote>proxy</quote> to forward lookups to another NSS library. See " "<quote>proxy_resolver_lib_name</quote>" msgstr "" +"Utilisez un proxy pour rediriger les recherches vers une autre bibliothèque " +"NSS. Voir <quote>proxy_resolver_lib_name</quote>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3442 +#: sssd.conf.5.xml:3573 msgid "" "<quote>ldap</quote> to fetch hosts and networks stored in LDAP. See " "<citerefentry> <refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</" "manvolnum> </citerefentry> for more information on configuring LDAP." msgstr "" +"Utilisez LDAP pour récupérer les hôtes et les réseaux stockés dans LDAP. " +"Consultez sssd-ldap pour plus d'informations sur la configuration de LDAP." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3449 +#: sssd.conf.5.xml:3580 msgid "" "<quote>ad</quote> to fetch hosts and networks stored in AD. See " "<citerefentry> <refentrytitle>sssd-ad</refentrytitle> <manvolnum>5</" "manvolnum> </citerefentry> for more information on configuring the AD " "provider." msgstr "" +"Utilisez `<quote>ad</quote>` pour récupérer les hôtes et les réseaux stockés " +"dans Active Directory. Consultez `<citerefentry> <refentrytitle>sssd-ad</" +"refentrytitle> <manvolnum>5</manvolnum> </citerefentry>` pour plus " +"d'informations sur la configuration du fournisseur Active Directory." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3457 +#: sssd.conf.5.xml:3588 msgid "<quote>none</quote> disallows fetching hosts and networks explicitly." msgstr "" +"<quote>none</quote> interdit la récupération explicite des hôtes et des " +"réseaux." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3460 +#: sssd.conf.5.xml:3591 #, fuzzy #| msgid "" #| "Default: <quote>id_provider</quote> is used if it is set and can handle " @@ -4586,11 +5440,11 @@ msgid "" "Default: The value of <quote>id_provider</quote> is used if it is set and " "can handle resolver requests." msgstr "" -"Par défaut : <quote>id_provider</quote> est utilisé s'il est défini et peut " +"Par défaut : <quote>id_provider</quote> est utilisé s'il est défini et peut " "gérer les requêtes d'authentification." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3470 +#: sssd.conf.5.xml:3601 msgid "" "Regular expression for this domain that describes how to parse the string " "containing user name and domain into these components. The \"domain\" can " @@ -4606,7 +5460,7 @@ msgstr "" "domaine." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3479 +#: sssd.conf.5.xml:3610 #, fuzzy #| msgid "" #| "Default for the AD and IPA provider: <quote>(((?P<domain>[^\\\\]+)\\" @@ -4617,23 +5471,23 @@ msgid "" "Default: <quote>^((?P<name>.+)@(?P<domain>[^@]*)|(?P<name>" "[^@]+))$</quote> which allows two different styles for user names:" msgstr "" -"Valeur par défaut pour les fournisseurs AD et IPA : <quote>((" +"Valeur par défaut pour les fournisseurs AD et IPA : <quote>((" "(?P<domain>[^\\\\]+)\\\\(?P<name>.+$))|((?P<name>[^@]+)@" "(?P<domain>.+$))|(^(?P<name>[^@\\\\]+)$))</quote> qui utilisent " -"trois styles différents pour les noms d'utilisateurs :" +"trois styles différents pour les noms d'utilisateurs :" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:3484 sssd.conf.5.xml:3498 +#: sssd.conf.5.xml:3615 sssd.conf.5.xml:3629 msgid "username" msgstr "username" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:3487 sssd.conf.5.xml:3501 +#: sssd.conf.5.xml:3618 sssd.conf.5.xml:3632 msgid "username@domain.name" msgstr "username@domain.name" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3492 +#: sssd.conf.5.xml:3623 #, fuzzy #| msgid "" #| "Default for the AD and IPA provider: <quote>(((?P<domain>[^\\\\]+)\\" @@ -4646,18 +5500,18 @@ msgid "" "P<name>[^@\\\\]+)))$</quote> which allows three different styles for " "user names:" msgstr "" -"Valeur par défaut pour les fournisseurs AD et IPA : <quote>((" +"Valeur par défaut pour les fournisseurs AD et IPA : <quote>((" "(?P<domain>[^\\\\]+)\\\\(?P<name>.+$))|((?P<name>[^@]+)@" "(?P<domain>.+$))|(^(?P<name>[^@\\\\]+)$))</quote> qui utilisent " -"trois styles différents pour les noms d'utilisateurs :" +"trois styles différents pour les noms d'utilisateurs :" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:3504 +#: sssd.conf.5.xml:3635 msgid "domain\\username" msgstr "domain\\username" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3507 +#: sssd.conf.5.xml:3638 msgid "" "While the first two correspond to the general default the third one is " "introduced to allow easy integration of users from Windows domains." @@ -4667,7 +5521,7 @@ msgstr "" "utilisateurs de domaines Windows." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3512 +#: sssd.conf.5.xml:3643 msgid "" "The default re_expression uses the <quote>@</quote> character as a separator " "between the name and the domain. As a result of this setting the default " @@ -4675,19 +5529,24 @@ msgid "" "allowed in Windows group names). If a user wishes to use short names with " "<quote>@</quote> they must create their own re_expression." msgstr "" +"The default re_expression uses the <quote>@</quote> character as a separator " +"between the name and the domain. As a result of this setting the default " +"does not accept the <quote>@</quote> character in short names (as it is " +"allowed in Windows group names). If a user wishes to use short names with " +"<quote>@</quote> they must create their own re_expression." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3564 +#: sssd.conf.5.xml:3695 msgid "Default: <quote>%1$s@%2$s</quote>." msgstr "Par défaut : <quote>%1$s@%2$s</quote>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3570 +#: sssd.conf.5.xml:3701 msgid "lookup_family_order (string)" msgstr "lookup_family_order (chaîne)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3573 +#: sssd.conf.5.xml:3704 msgid "" "Provides the ability to select preferred address family to use when " "performing DNS lookups." @@ -4696,142 +5555,175 @@ msgstr "" "utiliser pour effectuer les requêtes DNS." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3577 +#: sssd.conf.5.xml:3708 msgid "Supported values:" msgstr "Valeurs prises en charge :" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3580 +#: sssd.conf.5.xml:3711 msgid "ipv4_first: Try looking up IPv4 address, if that fails, try IPv6" msgstr "" "ipv4_first : essayer de chercher une adresse IPv4, et en cas d'échec, " "essayer IPv6." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3583 +#: sssd.conf.5.xml:3714 msgid "ipv4_only: Only attempt to resolve hostnames to IPv4 addresses." msgstr "" "ipv4_only : ne tenter de résoudre les noms de systèmes qu'en adresses IPv4." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3586 +#: sssd.conf.5.xml:3717 msgid "ipv6_first: Try looking up IPv6 address, if that fails, try IPv4" msgstr "" "ipv6_first : essayer de chercher une adresse IPv6, et en cas d'échec, tenter " "IPv4." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3589 +#: sssd.conf.5.xml:3720 msgid "ipv6_only: Only attempt to resolve hostnames to IPv6 addresses." msgstr "" "ipv6_only : ne tenter de résoudre les noms de systèmes qu'en adresses IPv6." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3592 +#: sssd.conf.5.xml:3723 msgid "Default: ipv4_first" msgstr "Par défaut : ipv4_first" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3598 +#: sssd.conf.5.xml:3729 #, fuzzy #| msgid "dns_resolver_timeout (integer)" msgid "dns_resolver_server_timeout (integer)" msgstr "dns_resolver_timeout (entier)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3601 +#: sssd.conf.5.xml:3732 msgid "" -"Defines the amount of time (in milliseconds) SSSD would try to talk to DNS " -"server before trying next DNS server." +"Defines the timeout duration (in milliseconds) SSSD waits for a DNS server " +"to respond before moving to the next one." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3606 +#: sssd.conf.5.xml:3737 msgid "" "The AD provider will use this option for the CLDAP ping timeouts as well." msgstr "" +"Le fournisseur AD utilisera également cette option pour les délais d'attente " +"de ping CLDAP." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3610 sssd.conf.5.xml:3630 sssd.conf.5.xml:3651 -msgid "" -"Please see the section <quote>FAILOVER</quote> for more information about " -"the service resolution." +#: sssd.conf.5.xml:3741 sssd.conf.5.xml:3777 sssd.conf.5.xml:3814 +#, fuzzy +#| msgid "" +#| "Specifies the timeout (in seconds) after which the <citerefentry> " +#| "<refentrytitle>poll</refentrytitle> <manvolnum>2</manvolnum> </" +#| "citerefentry>/<citerefentry> <refentrytitle>select</refentrytitle> " +#| "<manvolnum>2</manvolnum> </citerefentry> following a <citerefentry> " +#| "<refentrytitle>connect</refentrytitle> <manvolnum>2</manvolnum> </" +#| "citerefentry> returns in case of no activity." +msgid "" +"Please see the section <quote>FAILOVER</quote> in <citerefentry> " +"<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> </" +"citerefentry>, <citerefentry> <refentrytitle>sssd-krb5</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry>, <citerefentry> <refentrytitle>sssd-" +"ipa</refentrytitle> <manvolnum>5</manvolnum> </citerefentry> or " +"<citerefentry> <refentrytitle>sssd-ad</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry> for more information about the service resolution." msgstr "" +"Définit le délai d'attente (en secondes) après lequel les fonctions " +"<citerefentry> <refentrytitle>poll</refentrytitle> <manvolnum>2</manvolnum> " +"</citerefentry>/<citerefentry> <refentrytitle>select</refentrytitle> " +"<manvolnum>2</manvolnum> </citerefentry> suivant un <citerefentry> " +"<refentrytitle>connect</refentrytitle> <manvolnum>2</manvolnum> </" +"citerefentry> rendent la main en cas d'inactivité." #. type: Content of: <refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3615 sssd-ldap.5.xml:700 include/failover.xml:84 +#: sssd.conf.5.xml:3762 sssd-ldap.5.xml:700 include/failover.xml:84 msgid "Default: 1000" msgstr "Par défaut : 1000" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3621 +#: sssd.conf.5.xml:3768 #, fuzzy #| msgid "dns_resolver_timeout (integer)" msgid "dns_resolver_op_timeout (integer)" msgstr "dns_resolver_timeout (entier)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3624 +#: sssd.conf.5.xml:3771 msgid "" "Defines the amount of time (in seconds) to wait to resolve single DNS query " "(e.g. resolution of a hostname or an SRV record) before trying the next " "hostname or DNS discovery." msgstr "" +"Définit le temps (en secondes) à attendre pour résoudre une seule requête " +"DNS (par exemple, la résolution d'un nom d'hôte ou d'un enregistrement SRV) " +"avant de tenter la découverte du nom d'hôte ou du DNS suivant." #. type: Content of: <refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3635 include/failover.xml:100 +#: sssd.conf.5.xml:3798 include/failover.xml:100 msgid "Default: 3" msgstr "Par défaut : 3" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3641 +#: sssd.conf.5.xml:3804 msgid "dns_resolver_timeout (integer)" msgstr "dns_resolver_timeout (entier)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3644 +#: sssd.conf.5.xml:3807 msgid "" "Defines the amount of time (in seconds) to wait for a reply from the " "internal fail over service before assuming that the service is unreachable. " "If this timeout is reached, the domain will continue to operate in offline " "mode." msgstr "" +"Définit le délai (en secondes) d'attente d'une réponse du service de " +"basculement interne avant de considérer le service comme injoignable. Si ce " +"délai est atteint, le domaine continuera de fonctionner en mode hors ligne." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3662 +#: sssd.conf.5.xml:3841 #, fuzzy #| msgid "dns_resolver_timeout (integer)" -msgid "dns_resolver_use_search_list (bool)" +msgid "dns_resolver_use_search_list (boolean)" msgstr "dns_resolver_timeout (entier)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3665 +#: sssd.conf.5.xml:3844 msgid "" "Normally, the DNS resolver searches the domain list defined in the " "\"search\" directive from the resolv.conf file. This can lead to delays in " "environments with improperly configured DNS." msgstr "" +"Normalement, le résolveur DNS interroge la liste de domaines définie dans la " +"directive « search » du fichier resolv.conf. Cela peut entraîner des délais " +"dans les environnements où le DNS est mal configuré." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3671 +#: sssd.conf.5.xml:3850 msgid "" "If fully qualified domain names (or _srv_) are used in the SSSD " "configuration, setting this option to FALSE can prevent unnecessary DNS " "lookups in such environments." msgstr "" +"Si des noms de domaine pleinement qualifiés (ou _srv_) sont utilisés dans la " +"configuration SSSD, le fait de définir cette option sur FALSE peut éviter " +"des recherches DNS inutiles dans de tels environnements." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3677 +#: sssd.conf.5.xml:3856 msgid "Default: TRUE" msgstr "Par défaut : TRUE" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3683 +#: sssd.conf.5.xml:3862 msgid "dns_discovery_domain (string)" msgstr "dns_discovery_domain (chaîne)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3686 +#: sssd.conf.5.xml:3865 msgid "" "If service discovery is used in the back end, specifies the domain part of " "the service discovery DNS query." @@ -4840,81 +5732,98 @@ msgstr "" "du domaine faisant partie de la requête DNS de découverte de services." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3690 +#: sssd.conf.5.xml:3869 msgid "Default: Use the domain part of machine's hostname" msgstr "" "Par défaut : utiliser la partie du domaine qui est dans le nom de système de " "la machine." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3696 +#: sssd.conf.5.xml:3875 #, fuzzy #| msgid "pam_id_timeout (integer)" msgid "failover_primary_timeout (integer)" msgstr "pam_id_timeout (entier)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3699 +#: sssd.conf.5.xml:3878 msgid "" "When no primary server is available, SSSD fails over to a backup server. " "This option defines the number of seconds SSSD waits before attempting to " "reconnect to the primary server." msgstr "" +"En l'absence de serveur principal, SSSD bascule vers un serveur de secours. " +"Cette option définit le nombre de secondes pendant lesquelles SSSD attend " +"avant de tenter de se reconnecter au serveur principal." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3706 +#: sssd.conf.5.xml:3885 msgid "Note: The minimum value is 31." -msgstr "" +msgstr "Remarque : La valeur minimale est 31." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3709 +#: sssd.conf.5.xml:3888 #, fuzzy #| msgid "Default: 3" msgid "Default: 31" -msgstr "Par défaut : 3" +msgstr "Par défaut : 3" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3715 +#: sssd.conf.5.xml:3894 msgid "override_gid (integer)" msgstr "override_gid (entier)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3718 -msgid "Override the primary GID value with the one specified." +#: sssd.conf.5.xml:3897 +#, fuzzy +#| msgid "Override the primary GID value with the one specified." +msgid "" +"Override the primary GID value for all users in the domain with specified " +"value." msgstr "Redéfinit le GID primaire avec la valeur spécifiée." +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3901 +#, fuzzy +#| msgid "Default: not set (SSSD will use the value retrieved from LDAP)" +msgid "" +"Default: not set (Use the primary GID value retrieved from the identity " +"provider)" +msgstr "Par défaut : indéfini (SSSD utilisera la valeur récupérée de LDAP)" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3724 +#: sssd.conf.5.xml:3908 msgid "case_sensitive (string)" msgstr "case_sensitive (chaîne)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3731 +#: sssd.conf.5.xml:3915 msgid "True" msgstr "True" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3734 +#: sssd.conf.5.xml:3918 msgid "Case sensitive. This value is invalid for AD provider." msgstr "" +"Respectez la casse. Cette valeur n'est pas valide pour le fournisseur AD." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3740 +#: sssd.conf.5.xml:3924 msgid "False" msgstr "False" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3742 +#: sssd.conf.5.xml:3926 msgid "Case insensitive." msgstr "Insensible à la casse." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3746 +#: sssd.conf.5.xml:3930 msgid "Preserving" msgstr "Preserving" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3749 +#: sssd.conf.5.xml:3933 msgid "" "Same as False (case insensitive), but does not lowercase names in the result " "of NSS operations. Note that name aliases (and in case of services also " @@ -4926,147 +5835,182 @@ msgstr "" "sortie." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3757 +#: sssd.conf.5.xml:3941 msgid "" "If you want to set this value for trusted domain with IPA provider, you need " "to set it on both the client and SSSD on the server." msgstr "" +"Respectez la casse. Cette valeur n'est pas valide pour le fournisseur AD." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3727 -#, fuzzy -#| msgid "" -#| "The following expansions are supported: <placeholder " -#| "type=\"variablelist\" id=\"0\"/>" +#: sssd.conf.5.xml:3911 msgid "" "Treat user and group names as case sensitive. Possible option values are: " "<placeholder type=\"variablelist\" id=\"0\"/>" msgstr "" -"Les expansions suivantes sont prises en charge : <placeholder " -"type=\"variablelist\" id=\"0\"/>" +"Les noms d'utilisateurs et de groupes sont sensibles à la casse. Les valeurs " +"possibles sont : <placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3772 +#: sssd.conf.5.xml:3956 msgid "Default: True (False for AD provider)" msgstr "Par défaut : true (false pour le fournisseur AD)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3778 +#: sssd.conf.5.xml:3962 +#, fuzzy +#| msgid "ad_enable_dns_sites (boolean)" +msgid "avoid_by_id_lookups (boolean)" +msgstr "ad_enable_dns_sites (booléen)" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3965 +msgid "" +"If this option is set to 'true' SSSD will try to avoid sending lookups by ID " +"to the backend and will switch to a lookup by name if a cached object with a " +"matching ID can be found." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3971 +msgid "" +"This option can e.g. be used in cases where searches by ID are expensive on " +"the server side because of missing indexes or are not even possible, e.g. " +"due to non-reversible POSIX id-mapping." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3978 +#, fuzzy +#| msgid "Default: True (False for AD provider)" +msgid "Default: False (True for IdP provider)" +msgstr "Par défaut : true (false pour le fournisseur AD)" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:3984 msgid "subdomain_inherit (string)" msgstr "subdomain_inherit (chaîne)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3781 +#: sssd.conf.5.xml:3987 msgid "" "Specifies a list of configuration parameters that should be inherited by a " "subdomain. Please note that only selected parameters can be inherited. " "Currently the following options can be inherited:" msgstr "" +"Spécifie une liste de paramètres de configuration qui doivent être hérités " +"par un sous-domaine. Veuillez noter que seuls les paramètres sélectionnés " +"peuvent être hérités. Actuellement, les options suivantes peuvent être " +"héritées :" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3787 +#: sssd.conf.5.xml:3993 #, fuzzy #| msgid "ldap_search_timeout (integer)" msgid "ldap_search_timeout" msgstr "ldap_search_timeout (entier)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3790 +#: sssd.conf.5.xml:3996 #, fuzzy #| msgid "ldap_network_timeout (integer)" msgid "ldap_network_timeout" msgstr "ldap_network_timeout (entier)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3793 +#: sssd.conf.5.xml:3999 #, fuzzy #| msgid "ldap_opt_timeout (integer)" msgid "ldap_opt_timeout" msgstr "ldap_opt_timeout (entier)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3796 +#: sssd.conf.5.xml:4002 #, fuzzy #| msgid "ldap_connection_expire_timeout (integer)" msgid "ldap_offline_timeout" msgstr "ldap_connection_expire_timeout (entier)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3799 +#: sssd.conf.5.xml:4005 msgid "ldap_purge_cache_timeout" msgstr "ldap_purge_cache_timeout" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3802 +#: sssd.conf.5.xml:4008 #, fuzzy #| msgid "ldap_purge_cache_timeout" msgid "ldap_purge_cache_offset" msgstr "ldap_purge_cache_timeout" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3805 +#: sssd.conf.5.xml:4011 msgid "" "ldap_krb5_keytab (the value of krb5_keytab will be used if ldap_krb5_keytab " "is not set explicitly)" msgstr "" +"ldap_krb5_keytab (la valeur de krb5_keytab sera utilisée si ldap_krb5_keytab " +"n'est pas défini explicitement)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3809 +#: sssd.conf.5.xml:4015 #, fuzzy #| msgid "ldap_krb5_ticket_lifetime (integer)" msgid "ldap_krb5_ticket_lifetime" msgstr "ldap_krb5_ticket_lifetime (entier)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3812 +#: sssd.conf.5.xml:4018 #, fuzzy #| msgid "ldap_connection_expire_timeout (integer)" msgid "ldap_connection_expire_timeout" msgstr "ldap_connection_expire_timeout (entier)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3815 +#: sssd.conf.5.xml:4021 #, fuzzy #| msgid "ldap_connection_expire_timeout (integer)" msgid "ldap_connection_expire_offset" msgstr "ldap_connection_expire_timeout (entier)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3818 +#: sssd.conf.5.xml:4024 #, fuzzy #| msgid "ldap_connection_expire_timeout (integer)" msgid "ldap_connection_idle_timeout" msgstr "ldap_connection_expire_timeout (entier)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3821 sssd-ldap.5.xml:446 +#: sssd.conf.5.xml:4027 sssd-ldap.5.xml:446 msgid "ldap_use_tokengroups" msgstr "ldap_use_tokengroups" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3824 +#: sssd.conf.5.xml:4030 msgid "ldap_user_principal" msgstr "ldap_user_principal" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3827 +#: sssd.conf.5.xml:4033 msgid "ignore_group_members" msgstr "ignore_group_members" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3830 +#: sssd.conf.5.xml:4036 msgid "auto_private_groups" msgstr "" +"ldap_krb5_keytab (la valeur de krb5_keytab sera utilisée si ldap_krb5_keytab " +"n'est pas défini explicitement)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3833 +#: sssd.conf.5.xml:4039 #, fuzzy #| msgid "Case insensitive." msgid "case_sensitive" msgstr "Insensible à la casse." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:3838 +#: sssd.conf.5.xml:4044 #, no-wrap msgid "" "subdomain_inherit = ldap_purge_cache_timeout\n" @@ -5076,27 +6020,28 @@ msgstr "" " " #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3845 +#: sssd.conf.5.xml:4051 msgid "Note: This option only works with the IPA and AD provider." msgstr "" +"Remarque : cette option fonctionne uniquement avec le fournisseur IPA et AD." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3852 +#: sssd.conf.5.xml:4058 msgid "subdomain_homedir (string)" msgstr "subdomain_homedir (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3863 +#: sssd.conf.5.xml:4069 msgid "%F" msgstr "%F" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3864 +#: sssd.conf.5.xml:4070 msgid "flat (NetBIOS) name of a subdomain." msgstr "nom plat (NetBIOS) d'un sous-domaine." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3855 +#: sssd.conf.5.xml:4061 msgid "" "Use this homedir as default value for all subdomains within this domain in " "IPA AD trust. See <emphasis>override_homedir</emphasis> for info about " @@ -5112,7 +6057,7 @@ msgstr "" "type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3869 +#: sssd.conf.5.xml:4075 msgid "" "The value can be overridden by <emphasis>override_homedir</emphasis> option." msgstr "" @@ -5120,17 +6065,17 @@ msgstr "" "emphasis>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3873 +#: sssd.conf.5.xml:4079 msgid "Default: <filename>/home/%d/%u</filename>" msgstr "Par défaut : <filename>/home/%d/%u</filename>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3878 +#: sssd.conf.5.xml:4084 msgid "realmd_tags (string)" msgstr "realmd_tags (chaîne)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3881 +#: sssd.conf.5.xml:4087 msgid "" "Various tags stored by the realmd configuration service for this domain." msgstr "" @@ -5138,48 +6083,55 @@ msgstr "" "ce domaine." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3887 +#: sssd.conf.5.xml:4093 msgid "cached_auth_timeout (int)" -msgstr "" +msgstr "délai_d'expiration_authentification_en_caché (int)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3890 +#: sssd.conf.5.xml:4096 msgid "" -"Specifies time in seconds since last successful online authentication for " -"which user will be authenticated using cached credentials while SSSD is in " -"the online mode. If the credentials are incorrect, SSSD falls back to online " -"authentication." +"Specifies the number of seconds since the last successful online " +"authentication during which SSSD will authenticate users via cached " +"credentials, even while online. If the cached authentication fails, SSSD " +"immediately falls back to online authentication." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3898 +#: sssd.conf.5.xml:4103 msgid "" "This option's value is inherited by all trusted domains. At the moment it is " "not possible to set a different value per trusted domain." msgstr "" +"La valeur de cette option est héritée par tous les domaines de confiance. Il " +"n'est actuellement pas possible de définir une valeur différente pour chaque " +"domaine de confiance." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3903 +#: sssd.conf.5.xml:4108 msgid "Special value 0 implies that this feature is disabled." -msgstr "" +msgstr "La valeur spéciale 0 indique que cette fonctionnalité est désactivée." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3907 +#: sssd.conf.5.xml:4112 +#, fuzzy msgid "" "Please note that if <quote>cached_auth_timeout</quote> is longer than " "<quote>pam_id_timeout</quote> then the back end could be called to handle " "<quote>initgroups.</quote>" msgstr "" +"Veuillez noter que si <quote>cached_auth_timeout</quote> est supérieur à " +"<quote>pam_id_timeout</quote>, le serveur pourrait être sollicité pour gérer " +"<quote>initgroups</quote>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3918 +#: sssd.conf.5.xml:4123 #, fuzzy #| msgid "ldap_pwd_policy (string)" msgid "local_auth_policy (string)" msgstr "ldap_pwd_policy (chaîne)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3921 +#: sssd.conf.5.xml:4126 msgid "" "Local authentication methods policy. Some backends (i.e. LDAP, proxy " "provider) only support a password based authentication, while others can " @@ -5189,9 +6141,18 @@ msgid "" "supported by the backend. With this option additional methods can be enabled " "which are evaluated and checked locally." msgstr "" +"Politique relative aux méthodes d'authentification locales. Certains " +"systèmes d'authentification (par exemple, LDAP, fournisseur proxy) ne " +"prennent en charge que l'authentification par mot de passe, tandis que " +"d'autres peuvent gérer l'authentification par carte à puce basée sur PKINIT " +"(AD, IPA), l'authentification à deux facteurs (IPA) ou d'autres méthodes " +"auprès d'une instance centrale. Par défaut, dans ces cas, l'authentification " +"est effectuée uniquement avec les méthodes prises en charge par le système " +"d'authentification. Cette option permet d'activer des méthodes " +"supplémentaires qui sont évaluées et vérifiées localement." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3933 +#: sssd.conf.5.xml:4138 msgid "" "There are three possible values for this option: match, only, enable. " "<quote>match</quote> is used to match offline and online states for Kerberos " @@ -5201,63 +6162,84 @@ msgid "" "passkey for local authentication. Multiple enable values should be comma-" "separated, such as <quote>enable:passkey, enable:smartcard</quote>" msgstr "" +"Cette option peut prendre trois valeurs : `match`, `only` et `enable`. " +"`match` permet de faire correspondre les états hors ligne et en ligne pour " +"les méthodes Kerberos. `only` ignore les méthodes en ligne et ne propose que " +"les méthodes locales. `enable` permet de définir explicitement les méthodes " +"d'authentification locale. Par exemple, `enable:passkey` active uniquement " +"l'authentification par clé d'accès pour l'authentification locale. Plusieurs " +"valeurs pour `enable` doivent être séparées par des virgules, comme ceci : " +"`enable:passkey, enable:smartcard`." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3946 +#: sssd.conf.5.xml:4151 msgid "" "The following table shows which authentication methods, if configured " "properly, are currently enabled or disabled for each backend, with the " "default local_auth_policy: <quote>match</quote>" msgstr "" +"Le tableau suivant indique quelles méthodes d'authentification, si elles " +"sont correctement configurées, sont actuellement activées ou désactivées " +"pour chaque serveur, avec la politique d'authentification locale par défaut " +": <quote>match</quote>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> -#: sssd.conf.5.xml:3959 +#: sssd.conf.5.xml:4164 #, fuzzy #| msgid "ldap_pwd_policy (string)" msgid "local_auth_policy = match (default)" msgstr "ldap_pwd_policy (chaîne)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> -#: sssd.conf.5.xml:3960 +#: sssd.conf.5.xml:4165 msgid "Passkey" -msgstr "" +msgstr "Clé d'accès" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> -#: sssd.conf.5.xml:3961 +#: sssd.conf.5.xml:4166 msgid "Smartcard" -msgstr "" +msgstr "carte à puce" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:3964 sssd-ldap.5.xml:228 +#: sssd.conf.5.xml:4169 sssd-ldap.5.xml:228 msgid "IPA" msgstr "IPA" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry><para> +#: sssd.conf.5.xml:4169 sssd.conf.5.xml:4170 sssd.conf.5.xml:4173 +msgid "enabled" +msgstr "activé" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:3967 sssd-ldap.5.xml:233 +#: sssd.conf.5.xml:4172 sssd-ldap.5.xml:233 msgid "AD" msgstr "AD" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry><para> -#: sssd.conf.5.xml:3967 sssd.conf.5.xml:3970 sssd.conf.5.xml:3971 +#: sssd.conf.5.xml:4172 sssd.conf.5.xml:4175 sssd.conf.5.xml:4176 msgid "disabled" -msgstr "" +msgstr "désactivé" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry> -#: sssd.conf.5.xml:3970 +#: sssd.conf.5.xml:4175 msgid "LDAP" -msgstr "" +msgstr "LDAP" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3975 +#: sssd.conf.5.xml:4180 msgid "" "Please note that if local Smartcard authentication is enabled and a " "Smartcard is present, Smartcard authentication will be preferred over the " "authentication methods supported by the backend. I.e. there will be a PIN " "prompt instead of e.g. a password prompt." msgstr "" +"Veuillez noter que si l'authentification par carte à puce locale est activée " +"et qu'une carte à puce est présente, elle sera privilégiée par rapport aux " +"méthodes d'authentification prises en charge par le système. Autrement dit, " +"un code PIN vous sera demandé à la place d'un mot de passe." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:3987 +#: sssd.conf.5.xml:4192 #, no-wrap msgid "" "[domain/shadowutils]\n" @@ -5266,67 +6248,84 @@ msgid "" "auth_provider = none\n" "local_auth_policy = only\n" msgstr "" +"[domain/shadowutils]\n" +"id_provider = proxy\n" +"proxy_lib_name = files\n" +"auth_provider = none\n" +"local_auth_policy = only\n" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3983 +#: sssd.conf.5.xml:4188 msgid "" "The following configuration example allows local users to authenticate " "locally using any enabled method (i.e. smartcard, passkey). <placeholder " "type=\"programlisting\" id=\"0\"/>" msgstr "" +"L'exemple de configuration suivant permet aux utilisateurs locaux de " +"s'authentifier localement à l'aide de n'importe quelle méthode activée (par " +"exemple, carte à puce, clé d'accès). <placeholder type=\"programlisting\" " +"id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3995 +#: sssd.conf.5.xml:4200 #, fuzzy #| msgid "Default: cn" msgid "Default: match" -msgstr "Par défaut : cn" +msgstr "Par défaut : cn" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4000 +#: sssd.conf.5.xml:4205 msgid "auto_private_groups (string)" -msgstr "" +msgstr "auto_private_groups (chaîne)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4006 +#: sssd.conf.5.xml:4211 msgid "true" -msgstr "" +msgstr "vraie" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4009 +#: sssd.conf.5.xml:4214 msgid "" "Create user's private group unconditionally from user's UID number. The GID " "number is ignored in this case." msgstr "" +"Créez systématiquement le groupe privé de l'utilisateur à partir de son UID. " +"Le GID est ignoré dans ce cas." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4013 +#: sssd.conf.5.xml:4218 msgid "" "NOTE: Because the GID number and the user private group are inferred from " "the UID number, it is not supported to have multiple entries with the same " "UID or GID number with this option. In other words, enabling this option " "enforces uniqueness across the ID space." msgstr "" +"REMARQUE : Étant donné que le numéro GID et le groupe privé de l’utilisateur " +"sont déduits du numéro UID, il est impossible d’avoir plusieurs entrées avec " +"le même numéro UID ou GID avec cette option. En d’autres termes, " +"l’activation de cette option garantit l’unicité de chaque identifiant." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4022 +#: sssd.conf.5.xml:4227 msgid "false" -msgstr "" +msgstr "FAUX" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4025 +#: sssd.conf.5.xml:4230 msgid "" "Always use the user's primary GID number. The GID number must refer to a " "group object in the LDAP database." msgstr "" +"Utilisez toujours le numéro GID principal de l'utilisateur. Ce numéro GID " +"doit faire référence à un objet groupe dans la base de données LDAP." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4031 +#: sssd.conf.5.xml:4236 msgid "hybrid" -msgstr "" +msgstr "hybride" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4034 +#: sssd.conf.5.xml:4239 msgid "" "A primary group is autogenerated for user entries whose UID and GID numbers " "have the same value and at the same time the GID number does not correspond " @@ -5334,31 +6333,45 @@ msgid "" "GID in the user entry is also used by a group object, the primary GID of the " "user resolves to that group object." msgstr "" +"Un groupe principal est généré automatiquement pour les entrées utilisateur " +"dont les numéros UID et GID sont identiques, mais dont le numéro GID ne " +"correspond à aucun objet de groupe existant dans LDAP. Si les valeurs sont " +"identiques, mais que le GID principal de l'entrée utilisateur est également " +"utilisé par un objet de groupe, le GID principal de l'utilisateur est alors " +"associé à ce groupe." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4047 +#: sssd.conf.5.xml:4252 msgid "" "If the UID and GID of a user are different, then the GID must correspond to " "a group entry, otherwise the GID is simply not resolvable." msgstr "" +"Si l'UID et le GID d'un utilisateur sont différents, alors le GID doit " +"correspondre à une entrée de groupe, sinon le GID est tout simplement " +"insoluble." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4054 +#: sssd.conf.5.xml:4259 msgid "" "This feature is useful for environments that wish to stop maintaining a " "separate group objects for the user private groups, but also wish to retain " "the existing user private groups." msgstr "" +"Si l'UID et le GID d'un utilisateur sont différents, alors le GID doit " +"correspondre à une entrée de groupe, sinon le GID est tout simplement " +"insoluble." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4003 +#: sssd.conf.5.xml:4208 msgid "" "This option takes any of three available values: <placeholder " "type=\"variablelist\" id=\"0\"/>" msgstr "" +"Cette option accepte l'une des trois valeurs disponibles : <placeholder " +"type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4066 +#: sssd.conf.5.xml:4271 msgid "" "For the LDAP based id providers (LDAP, IPA and AD) the default for the " "configured domain is typically False because the sources have the concept of " @@ -5366,42 +6379,60 @@ msgid "" "provider is using True because IdPs typically do not have primary groups.</" "phrase>" msgstr "" +"Pour les fournisseurs d'identité basés sur LDAP (LDAP, IPA et AD), la valeur " +"par défaut pour le domaine configuré est généralement False, car les sources " +"utilisent la notion de groupe principal. <phrase " +"condition=\"with_idp_provider\">Le fournisseur d'identité utilise True, car " +"les fournisseurs d'identité n'ont généralement pas de groupes principaux.</" +"phrase>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4075 +#: sssd.conf.5.xml:4280 msgid "" "For subdomains, the default value is False for subdomains that use assigned " "POSIX IDs and True for subdomains that use automatic ID-mapping." msgstr "" +"For subdomains, the default value is False for subdomains that use assigned " +"POSIX IDs and True for subdomains that use automatic ID-mapping." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:4083 +#: sssd.conf.5.xml:4288 #, no-wrap msgid "" "[domain/forest.domain/sub.domain]\n" "auto_private_groups = false\n" msgstr "" +"[domaine/forêt.domaine/sous-domaine]\n" +"auto_private_groups = false\n" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:4089 +#: sssd.conf.5.xml:4294 #, no-wrap msgid "" "[domain/forest.domain]\n" "subdomain_inherit = auto_private_groups\n" "auto_private_groups = false\n" msgstr "" +"[domaine/forêt.domaine]\n" +"sous-domaine_hériter = groupes_privés_auto\n" +"groupes_privés_auto = faux\n" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4080 +#: sssd.conf.5.xml:4285 msgid "" "The value of auto_private_groups can either be set per subdomains in a " "subsection, for example: <placeholder type=\"programlisting\" id=\"0\"/> or " "globally for all subdomains in the main domain section using the " "subdomain_inherit option: <placeholder type=\"programlisting\" id=\"1\"/>" msgstr "" +"La valeur de auto_private_groups peut être définie soit par sous-domaine " +"dans une sous-section, par exemple : <placeholder type=\"programlisting\" " +"id=\"0\"/>, soit globalement pour tous les sous-domaines de la section du " +"domaine principal à l'aide de l'option subdomain_inherit : <placeholder " +"type=\"programlisting\" id=\"1\"/>" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:2503 +#: sssd.conf.5.xml:2549 msgid "" "These configuration options can be present in a domain configuration " "section, that is, in a section called <quote>[domain/<replaceable>NAME</" @@ -5413,17 +6444,17 @@ msgstr "" "id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4104 +#: sssd.conf.5.xml:4309 msgid "proxy_pam_target (string)" msgstr "proxy_pam_target (chaîne)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4107 +#: sssd.conf.5.xml:4312 msgid "The proxy target PAM proxies to." msgstr "Le proxy cible duquel PAM devient mandataire." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4110 +#: sssd.conf.5.xml:4315 #, fuzzy #| msgid "" #| "Default: not set by default, you have to take an existing pam " @@ -5433,16 +6464,16 @@ msgid "" "or create a new one and add the service name here. As an alternative you can " "enable local authentication with the local_auth_policy option." msgstr "" -"Par défaut : non défini, il faut utiliser une configuration de pam existante " +"Par défaut : non défini, il faut utiliser une configuration de pam existante " "ou en créer une nouvelle et ajouter le nom de service ici." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4120 +#: sssd.conf.5.xml:4325 msgid "proxy_lib_name (string)" msgstr "proxy_lib_name (chaîne)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4123 +#: sssd.conf.5.xml:4328 msgid "" "The name of the NSS library to use in proxy domains. The NSS functions " "searched for in the library are in the form of _nss_$(libName)_$(function), " @@ -5453,25 +6484,29 @@ msgstr "" "(libName)_$(function), par exemple _nss_files_getpwent." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4133 +#: sssd.conf.5.xml:4338 msgid "proxy_resolver_lib_name (string)" -msgstr "" +msgstr "nom_bibliothèque_résolveur_proxy (chaîne)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4136 +#: sssd.conf.5.xml:4341 msgid "" "The name of the NSS library to use for hosts and networks lookups in proxy " "domains. The NSS functions searched for in the library are in the form of " "_nss_$(libName)_$(function), for example _nss_dns_gethostbyname2_r." msgstr "" +"Nom de la bibliothèque NSS à utiliser pour la recherche d'hôtes et de " +"réseaux dans les domaines proxy. Les fonctions NSS recherchées dans la " +"bibliothèque sont au format _nss_$(nom_bibliothèque)_$(fonction), par " +"exemple _nss_dns_gethostbyname2_r." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4147 +#: sssd.conf.5.xml:4352 msgid "proxy_fast_alias (boolean)" msgstr "proxy_fast_alias (boolean)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4150 +#: sssd.conf.5.xml:4355 msgid "" "When a user or group is looked up by name in the proxy provider, a second " "lookup by ID is performed to \"canonicalize\" the name in case the requested " @@ -5485,20 +6520,24 @@ msgstr "" "afin d'améliorer les performances." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4164 +#: sssd.conf.5.xml:4369 msgid "proxy_max_children (integer)" -msgstr "" +msgstr "proxy_max_children (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4167 +#: sssd.conf.5.xml:4372 msgid "" "This option specifies the number of pre-forked proxy children. It is useful " "for high-load SSSD environments where sssd may run out of available child " "slots, which would cause some issues due to the requests being queued." msgstr "" +"Cette option spécifie le nombre de processus enfants proxy pré-forkés. Elle " +"est utile dans les environnements SSSD à forte charge où SSSD peut manquer " +"d'emplacements enfants disponibles, ce qui entraînerait des problèmes dus à " +"la mise en file d'attente des requêtes." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4100 +#: sssd.conf.5.xml:4305 msgid "" "Options valid for proxy domains. <placeholder type=\"variablelist\" " "id=\"0\"/>" @@ -5507,12 +6546,12 @@ msgstr "" "id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:4183 +#: sssd.conf.5.xml:4388 msgid "Application domains" -msgstr "" +msgstr "Domaines d'application" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:4185 +#: sssd.conf.5.xml:4390 msgid "" "SSSD, with its D-Bus interface (see <citerefentry> <refentrytitle>sssd-ifp</" "refentrytitle> <manvolnum>5</manvolnum> </citerefentry>) is appealing to " @@ -5527,36 +6566,57 @@ msgid "" "<quote>application</quote> optionally inherits settings from a tradition " "SSSD domain." msgstr "" +"SSSD, avec son interface D-Bus (voir <citerefentry> <refentrytitle>sssd-ifp</" +"refentrytitle> <manvolnum>5</manvolnum> </citerefentry>), est un outil " +"précieux pour les applications, servant de passerelle vers un annuaire LDAP " +"où sont stockés les utilisateurs et les groupes. Cependant, contrairement au " +"déploiement SSSD traditionnel où tous les utilisateurs et groupes possèdent " +"des attributs POSIX ou où ces attributs peuvent être déduits des SID " +"Windows, dans de nombreux cas, les utilisateurs et les groupes pris en " +"charge par les applications ne possèdent pas d'attributs POSIX. Au lieu de " +"définir une section <quote>[domain/<replaceable>NAME</replaceable>]</quote>, " +"l'administrateur peut configurer une section <quote>[application/" +"<replaceable>NAME</replaceable>]</quote> qui représente en interne un " +"domaine de type <quote>application</quote> et qui peut hériter des " +"paramètres d'un domaine SSSD traditionnel." #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:4205 +#: sssd.conf.5.xml:4410 msgid "" "Please note that the application domain must still be explicitly enabled in " "the <quote>domains</quote> parameter so that the lookup order between the " "application domain and its POSIX sibling domain is set correctly." msgstr "" +"Veuillez noter que le domaine d'application doit toujours être explicitement " +"activé dans le paramètre <quote>domains</quote> afin que l'ordre de " +"recherche entre le domaine d'application et son domaine frère POSIX soit " +"correctement défini." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><title> -#: sssd.conf.5.xml:4211 +#: sssd.conf.5.xml:4416 msgid "Application domain parameters" -msgstr "" +msgstr "Paramètres du domaine d'application" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4213 +#: sssd.conf.5.xml:4418 msgid "inherit_from (string)" -msgstr "" +msgstr "hériter_de (chaîne)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4216 +#: sssd.conf.5.xml:4421 msgid "" "The SSSD POSIX-type domain the application domain inherits all settings " "from. The application domain can moreover add its own settings to the " "application settings that augment or override the <quote>sibling</quote> " "domain settings." msgstr "" +"The SSSD POSIX-type domain the application domain inherits all settings " +"from. The application domain can moreover add its own settings to the " +"application settings that augment or override the <quote>sibling</quote> " +"domain settings." #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:4230 +#: sssd.conf.5.xml:4435 msgid "" "The following example illustrates the use of an application domain. In this " "setup, the POSIX domain is connected to an LDAP server and is used by the OS " @@ -5564,9 +6624,14 @@ msgid "" "the telephoneNumber attribute, stores it as the phone attribute in the cache " "and makes the phone attribute reachable through the D-Bus interface." msgstr "" +"L'exemple suivant illustre l'utilisation d'un domaine d'application. Dans " +"cette configuration, le domaine POSIX est connecté à un serveur LDAP et " +"utilisé par le système d'exploitation via le répondeur NSS. De plus, le " +"domaine d'application récupère l'attribut telephoneNumber, le stocke comme " +"attribut phone dans le cache et le rend accessible via l'interface D-Bus." #. type: Content of: <reference><refentry><refsect1><refsect2><programlisting> -#: sssd.conf.5.xml:4238 +#: sssd.conf.5.xml:4443 #, no-wrap msgid "" "[sssd]\n" @@ -5584,14 +6649,28 @@ msgid "" "inherit_from = posixdom\n" "ldap_user_extra_attrs = phone:telephoneNumber\n" msgstr "" +"[sssd]\n" +"domaines = appdom, posixdom\n" +"\n" +"[ifp]\n" +"attributs_utilisateur = +téléphone\n" +"\n" +"[domaine/posixdom]\n" +"fournisseur_id = ldap\n" +"uri_ldap = ldap://ldap.example.com\n" +"base_recherche_ldap = dc=example,dc=com\n" +"\n" +"[application/appdom]\n" +"hériter_de = posixdom\n" +"attributs_utilisateur_supplémentaires_ldap = téléphone:numéro_de_téléphone\n" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:4258 +#: sssd.conf.5.xml:4463 msgid "TRUSTED DOMAIN SECTION" -msgstr "" +msgstr "SECTION DOMAINE DE CONFIANCE" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4260 +#: sssd.conf.5.xml:4465 msgid "" "Some options used in the domain section can also be used in the trusted " "domain section, that is, in a section called <quote>[domain/" @@ -5600,71 +6679,92 @@ msgid "" "domain. Please refer to examples below for explanation. Currently supported " "options in the trusted domain section are:" msgstr "" +"Certaines options utilisées dans la section « Domaine » peuvent également " +"être utilisées dans la section « Domaine de confiance », c’est-à-dire dans " +"une section nommée <quote>[domaine/<replaceable>NOM_DOMAIN</replaceable>/" +"<replaceable>NOM_DOMAIN_DE_CONFIANCE</replaceable>]</quote>. Où NOM_DOMAIN " +"correspond au domaine de base auquel la jonction est effectuée. Veuillez " +"consulter les exemples ci-dessous pour plus d’explications. Les options " +"actuellement prises en charge dans la section « Domaine de confiance » sont :" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4267 +#: sssd.conf.5.xml:4472 msgid "ldap_search_base," -msgstr "" +msgstr "base de recherche LDAP," #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4268 +#: sssd.conf.5.xml:4473 msgid "ldap_user_search_base," -msgstr "" +msgstr "ldap_user_search_base," #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4269 +#: sssd.conf.5.xml:4474 msgid "ldap_group_search_base," -msgstr "" +msgstr "base de recherche de groupe LDAP," #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4270 +#: sssd.conf.5.xml:4475 msgid "ldap_netgroup_search_base," -msgstr "" +msgstr "ldap_netgroup_search_base," #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4271 +#: sssd.conf.5.xml:4476 msgid "ldap_service_search_base," -msgstr "" +msgstr "base de recherche du service LDAP," #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4272 +#: sssd.conf.5.xml:4477 msgid "ldap_sasl_mech," -msgstr "" +msgstr "ldap_sasl_mech," #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4273 +#: sssd.conf.5.xml:4478 msgid "ad_server," -msgstr "" +msgstr "serveur_publicitaire," #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4274 +#: sssd.conf.5.xml:4479 msgid "ad_backup_server," -msgstr "" +msgstr "serveur_de_sauvegarde_publicitaire," #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4275 +#: sssd.conf.5.xml:4480 msgid "ad_site," -msgstr "" +msgstr "site_publicitaire," #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:4276 sssd-ipa.5.xml:934 +#: sssd.conf.5.xml:4481 sssd-ipa.5.xml:929 msgid "use_fully_qualified_names" -msgstr "" +msgstr "use_fully_qualified_names" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4280 +#: sssd.conf.5.xml:4482 +#, fuzzy +#| msgid "ad_gpo_map_service (string)" +msgid "pam_gssapi_services" +msgstr "ad_gpo_map_service (chaîne)" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:4483 +msgid "pam_gssapi_check_upn" +msgstr "Vérification de Pam_Gaspi" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:4485 msgid "" "For more details about these options see their individual description in the " "manual page." msgstr "" +"Pour plus de détails sur ces options, consultez leur description " +"individuelle dans la page du manuel." #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:4286 +#: sssd.conf.5.xml:4491 msgid "CERTIFICATE MAPPING SECTION" -msgstr "" +msgstr "SECTION DE CARTOGRAPHIE DES CERTIFICATS" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4288 +#: sssd.conf.5.xml:4493 msgid "" "To allow authentication with Smartcards and certificates SSSD must be able " "to map certificates to users. This can be done by adding the full " @@ -5675,111 +6775,140 @@ msgid "" "might be cumbersome or not even possible to do this for the general case " "where local services use PAM for authentication." msgstr "" +"Pour permettre l'authentification par carte à puce et certificat, SSSD doit " +"pouvoir associer les certificats aux utilisateurs. Cela peut se faire en " +"ajoutant le certificat complet à l'objet LDAP de l'utilisateur ou en " +"utilisant une substitution locale. Bien que l'utilisation du certificat " +"complet soit requise pour l'authentification par carte à puce SSH (voir " +"<citerefentry> <refentrytitle>sss_ssh_authorizedkeys</refentrytitle> " +"<manvolnum>8</manvolnum> </citerefentry> pour plus de détails), cela peut " +"s'avérer complexe, voire impossible, dans le cas général où les services " +"locaux utilisent PAM pour l'authentification." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4302 +#: sssd.conf.5.xml:4507 msgid "" "To make the mapping more flexible mapping and matching rules were added to " "SSSD (see <citerefentry> <refentrytitle>sss-certmap</refentrytitle> " "<manvolnum>5</manvolnum> </citerefentry> for details)." msgstr "" +"Pour rendre le mappage plus flexible, des règles de mappage et de " +"correspondance ont été ajoutées à SSSD (voir <citerefentry> <refentrytitle>" +"sss-certmap</refentrytitle> <manvolnum>5</manvolnum> </citerefentry> pour " +"plus de détails)." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4311 +#: sssd.conf.5.xml:4516 msgid "" "A mapping and matching rule can be added to the SSSD configuration in a " "section on its own with a name like <quote>[certmap/" "<replaceable>DOMAIN_NAME</replaceable>/<replaceable>RULE_NAME</" "replaceable>]</quote>. In this section the following options are allowed:" msgstr "" +"Une règle de mappage et de correspondance peut être ajoutée à la " +"configuration SSSD dans une section dédiée, nommée par exemple : <quote>" +"[certmap/<replaceable>NOM_DOMAIN</replaceable>/<replaceable>NOM_RÈGLE</" +"replaceable>]</quote>. Dans cette section, les options suivantes sont " +"autorisées :" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4318 +#: sssd.conf.5.xml:4523 msgid "matchrule (string)" -msgstr "" +msgstr "règle de correspondance (chaîne)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4321 +#: sssd.conf.5.xml:4526 msgid "" "Only certificates from the Smartcard which matches this rule will be " "processed, all others are ignored." msgstr "" +"Only certificates from the Smartcard which matches this rule will be " +"processed, all others are ignored." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4325 +#: sssd.conf.5.xml:4530 msgid "" "Default: KRB5:<EKU>clientAuth, i.e. only certificates which have the " "Extended Key Usage <quote>clientAuth</quote>" msgstr "" +"Par défaut : KRB5 : &EKU > clientAuth, c’est-à-dire uniquement les " +"certificats disposant de l’utilisation étendue de la clé <quote>clientAuth</" +"quote>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4332 +#: sssd.conf.5.xml:4537 msgid "maprule (string)" -msgstr "" +msgstr "règle de carte (chaîne)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4335 +#: sssd.conf.5.xml:4540 msgid "Defines how the user is found for a given certificate." -msgstr "" +msgstr "Définit comment l'utilisateur est trouvé pour un certificat donné." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:4341 +#: sssd.conf.5.xml:4546 msgid "" "LDAP:(userCertificate;binary={cert!bin}) for LDAP based providers like " "<quote>ldap</quote>, <quote>AD</quote> or <quote>ipa</quote>." msgstr "" +"LDAP:(userCertificate;binary={cert!bin}) pour les fournisseurs basés sur " +"LDAP comme <quote>ldap</quote>, <quote>AD</quote> ou <quote>ipa</quote>." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:4347 +#: sssd.conf.5.xml:4552 msgid "" "If maprule is not set and provider is <quote>proxy</quote>, the RULE_NAME " "name is assumed to be the name of the matching user." msgstr "" - -#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4357 -msgid "domains (string)" -msgstr "" +"Si maprule n'est pas défini et que provider est <quote>proxy</quote>, le nom " +"RULE_NAME est supposé être le nom de l'utilisateur correspondant." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4360 +#: sssd.conf.5.xml:4565 msgid "" "Comma separated list of domain names the rule should be applied. By default " "a rule is only valid in the domain configured in sssd.conf. If the provider " "supports subdomains this option can be used to add the rule to subdomains as " "well." msgstr "" +"Liste de noms de domaine, séparés par des virgules, auxquels la règle doit " +"s'appliquer. Par défaut, une règle n'est valable que pour le domaine " +"configuré dans sssd.conf. Si le fournisseur prend en charge les sous-" +"domaines, cette option permet d'ajouter la règle à ces derniers." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4367 +#: sssd.conf.5.xml:4572 msgid "Default: the configured domain in sssd.conf" -msgstr "" +msgstr "Par défaut : le domaine configuré dans sssd.conf" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4372 +#: sssd.conf.5.xml:4577 msgid "priority (integer)" -msgstr "" +msgstr "priorité (entier)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4375 +#: sssd.conf.5.xml:4580 msgid "" "Unsigned integer value defining the priority of the rule. The higher the " "number the lower the priority. <quote>0</quote> stands for the highest " "priority while <quote>4294967295</quote> is the lowest." msgstr "" +"Valeur entière non signée définissant la priorité de la règle. Plus le " +"nombre est élevé, plus la priorité est faible. 0 représente la priorité la " +"plus élevée, tandis que 4294967295 représente la plus faible." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4381 +#: sssd.conf.5.xml:4586 msgid "Default: the lowest priority" -msgstr "" +msgstr "Par défaut : priorité la plus basse" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:4389 +#: sssd.conf.5.xml:4594 msgid "PROMPTING CONFIGURATION SECTION" -msgstr "" +msgstr "SECTION DE CONFIGURATION DES INVITATIONS" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4391 +#: sssd.conf.5.xml:4596 msgid "" "If a special file (<filename>/var/lib/sss/pubconf/pam_preauth_available</" "filename>) exists SSSD's PAM module pam_sss will ask SSSD to figure out " @@ -5787,88 +6916,109 @@ msgid "" "Based on the results pam_sss will prompt the user for appropriate " "credentials." msgstr "" +"Si un fichier spécifique (<filename>/var/lib/sss/pubconf/" +"pam_preauth_available</filename>) existe, le module PAM de SSSD, pam_sss, " +"interrogera SSSD pour déterminer les méthodes d'authentification disponibles " +"pour l'utilisateur qui tente de se connecter. En fonction des résultats, " +"pam_sss invitera l'utilisateur à saisir les informations d'identification " +"appropriées." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4399 +#: sssd.conf.5.xml:4604 msgid "" "With the growing number of authentication methods and the possibility that " "there are multiple ones for a single user the heuristic used by pam_sss to " "select the prompting might not be suitable for all use cases. The following " "options should provide a better flexibility here." msgstr "" +"Face à la multiplication des méthodes d'authentification et à la possibilité " +"qu'un même utilisateur en utilise plusieurs, l'heuristique employée par " +"pam_sss pour sélectionner le message d'invite peut ne pas convenir à tous " +"les cas de figure. Les options suivantes offrent une plus grande flexibilité." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4411 +#: sssd.conf.5.xml:4616 msgid "[prompting/password]" -msgstr "" +msgstr "[invite/mot de passe]" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4414 +#: sssd.conf.5.xml:4619 msgid "password_prompt" -msgstr "" +msgstr "invite_mot_de_passe" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4415 +#: sssd.conf.5.xml:4620 msgid "to change the string of the password prompt" -msgstr "" +msgstr "modifier le texte de l'invite de mot de passe" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4413 +#: sssd.conf.5.xml:4618 msgid "" "to configure password prompting, allowed options are: <placeholder " "type=\"variablelist\" id=\"0\"/>" msgstr "" +"Pour configurer l'invite de mot de passe, les options autorisées sont : " +"<placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4423 +#: sssd.conf.5.xml:4628 msgid "[prompting/2fa]" -msgstr "" +msgstr "[invite/2fa]" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4427 +#: sssd.conf.5.xml:4632 msgid "first_prompt" -msgstr "" +msgstr "première_invite" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4428 +#: sssd.conf.5.xml:4633 msgid "to change the string of the prompt for the first factor" -msgstr "" +msgstr "modifier la chaîne de l'invite pour le premier facteur" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4431 +#: sssd.conf.5.xml:4636 msgid "second_prompt" -msgstr "" +msgstr "modifier la chaîne de l'invite pour le premier facteur" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4432 +#: sssd.conf.5.xml:4637 msgid "to change the string of the prompt for the second factor" -msgstr "" +msgstr "modifier le texte de l'invite pour le deuxième facteur" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4435 +#: sssd.conf.5.xml:4640 msgid "single_prompt" -msgstr "" +msgstr "invite unique" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4436 +#: sssd.conf.5.xml:4641 msgid "" "boolean value, if True there will be only a single prompt using the value of " "first_prompt where it is expected that both factors are entered as a single " "string. Please note that both factors have to be entered here, even if the " "second factor is optional." msgstr "" +"Valeur booléenne : si la valeur est Vrai, une seule invite s’affichera, " +"utilisant la valeur de `first_prompt`, où les deux facteurs doivent être " +"saisis sous forme d’une seule chaîne de caractères. Veuillez noter que les " +"deux facteurs doivent être saisis, même si le second est facultatif." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4425 +#: sssd.conf.5.xml:4630 msgid "" "to configure two-factor authentication prompting, allowed options are: " "<placeholder type=\"variablelist\" id=\"0\"/> If the second factor is " "optional and it should be possible to log in either only with the password " "or with both factors two-step prompting has to be used." msgstr "" +"Pour configurer l'invite d'authentification à deux facteurs, les options " +"autorisées sont : <placeholder type=\"variablelist\" id=\"0\"/> Si le " +"deuxième facteur est facultatif et qu'il doit être possible de se connecter " +"soit uniquement avec le mot de passe, soit avec les deux facteurs, l'invite " +"en deux étapes doit être utilisée." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4449 +#: sssd.conf.5.xml:4654 msgid "" "Some clients, such as SSH with 'PasswordAuthentication yes', generate their " "own prompts and do not use prompts provided by SSSD or other PAM modules. " @@ -5877,59 +7027,71 @@ msgid "" "the user at the SSH password prompt will always be the two factors in a " "single string, even if two-factor authentication is optional." msgstr "" +"Certains clients, comme SSH avec l'option « PasswordAuthentication yes », " +"génèrent leurs propres invites et n'utilisent pas celles fournies par SSSD " +"ou d'autres modules PAM. De plus, pour SSH avec PasswordAuthentication, si " +"l'authentification à deux facteurs est disponible, SSSD exige que les " +"identifiants saisis par l'utilisateur lors de l'invite de mot de passe SSH " +"correspondent toujours aux deux facteurs dans une seule chaîne de " +"caractères, même si l'authentification à deux facteurs est optionnelle." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4464 +#: sssd.conf.5.xml:4669 msgid "[prompting/passkey]" -msgstr "" +msgstr "[invite/clé d'accès]" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:4470 sssd-ad.5.xml:1022 +#: sssd.conf.5.xml:4675 sssd.conf.5.xml:4719 sssd-ad.5.xml:1027 msgid "interactive" -msgstr "" +msgstr "interactif" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4472 +#: sssd.conf.5.xml:4677 msgid "" "boolean value, if True prompt a message and wait before testing the presence " "of a passkey device. Recommended if your device doesn’t have a tactile " "trigger." msgstr "" +"Valeur booléenne : si la valeur est Vrai, afficher un message et attendre " +"avant de tester la présence d’un périphérique à code d’accès. Recommandé si " +"votre appareil ne possède pas de déclencheur tactile." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4480 +#: sssd.conf.5.xml:4685 sssd.conf.5.xml:4735 msgid "interactive_prompt" -msgstr "" +msgstr "invite interactive" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4482 +#: sssd.conf.5.xml:4687 sssd.conf.5.xml:4737 msgid "to change the message of the interactive prompt." -msgstr "" +msgstr "modifier le message de l'invite interactive." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4487 +#: sssd.conf.5.xml:4692 msgid "touch" -msgstr "" +msgstr "touch" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4489 +#: sssd.conf.5.xml:4694 msgid "" "boolean value, if True prompt a message to remind the user to touch the " "device." msgstr "" +"Valeur booléenne ; si la valeur est True, afficher un message invitant " +"l’utilisateur à toucher l’appareil." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4495 +#: sssd.conf.5.xml:4700 msgid "touch_prompt" -msgstr "" +msgstr "invite tactile" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4497 +#: sssd.conf.5.xml:4702 msgid "to change the message of the touch prompt." -msgstr "" +msgstr "modifier le message de l'invite tactile." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4466 +#: sssd.conf.5.xml:4671 #, fuzzy #| msgid "" #| "The following expansions are supported: <placeholder " @@ -5941,30 +7103,123 @@ msgstr "" "Les expansions suivantes sont prises en charge : <placeholder " "type=\"variablelist\" id=\"0\"/>" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4713 +msgid "[prompting/oauth2]" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4721 +msgid "" +"boolean value, if True prompt a message after asking the user to " +"authenticate, and wait before requesting the access token." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4725 +msgid "" +"If False, make sure to set the <quote>idp_request_timeout</quote> " +"sufficiently high, to give the user time to authenticate." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4715 +#, fuzzy +#| msgid "" +#| "The following expansions are supported: <placeholder " +#| "type=\"variablelist\" id=\"0\"/>" +msgid "" +"to configure OAuth2 authentication prompting, allowed options are: " +"<placeholder type=\"variablelist\" id=\"0\"/>" +msgstr "" +"Les expansions suivantes sont prises en charge : <placeholder " +"type=\"variablelist\" id=\"0\"/>" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4748 +msgid "[prompting/cert_auth]" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4754 +msgid "pin_prompt" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4756 +msgid "" +"to change the message which asks the user to enter the PIN at the computer " +"keyboard. At the end of the message the token name is printed." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4764 +msgid "keypad_prompt" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4766 +msgid "" +"to change the message which asks the user to enter the PIN at keypad of the " +"Smartcard reader. At the end of the message the token name is printed." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4774 +#, fuzzy +#| msgid "username" +msgid "user_name_hint" +msgstr "username" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4776 +msgid "" +"boolean value, if True ask for a user name if no name was given before and " +"the found certificate can be mapped to more than one user." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4750 +#, fuzzy +#| msgid "" +#| "The following expansions are supported: <placeholder " +#| "type=\"variablelist\" id=\"0\"/>" +msgid "" +"to configure Smartcard authentication prompting, allowed options are: " +"<placeholder type=\"variablelist\" id=\"0\"/>" +msgstr "" +"Les expansions suivantes sont prises en charge : <placeholder " +"type=\"variablelist\" id=\"0\"/>" + #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4406 +#: sssd.conf.5.xml:4611 msgid "" "Each supported authentication method has its own configuration subsection " "under <quote>[prompting/...]</quote>. Currently there are: <placeholder " "type=\"variablelist\" id=\"0\"/> <placeholder type=\"variablelist\" id=\"1\"/" -"> <placeholder type=\"variablelist\" id=\"2\"/>" +"> <placeholder type=\"variablelist\" id=\"2\"/> <placeholder " +"type=\"variablelist\" id=\"3\"/> <placeholder type=\"variablelist\" id=\"4\"/" +">" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4508 +#: sssd.conf.5.xml:4792 msgid "" "It is possible to add a subsection for specific PAM services, e.g. " "<quote>[prompting/password/sshd]</quote> to individual change the prompting " "for this service." msgstr "" +"Il est possible d'ajouter une sous-section pour des services PAM " +"spécifiques, par exemple <quote>[prompting/password/sshd]</quote> pour " +"modifier individuellement l'invite pour ce service." #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:4515 pam_sss_gss.8.xml:157 idmap_sss.8.xml:43 +#: sssd.conf.5.xml:4799 pam_sss_gss.8.xml:157 idmap_sss.8.xml:43 msgid "EXAMPLES" -msgstr "" +msgstr "EXEMPLES" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd.conf.5.xml:4521 +#: sssd.conf.5.xml:4805 #, fuzzy, no-wrap #| msgid "" #| "[sssd]\n" @@ -6042,24 +7297,30 @@ msgstr "" "enumerate = False\n" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4517 +#: sssd.conf.5.xml:4801 msgid "" "1. The following example shows a typical SSSD config. It does not describe " "configuration of the domains themselves - refer to documentation on " "configuring domains for more details. <placeholder type=\"programlisting\" " "id=\"0\"/>" msgstr "" +"1. L'exemple suivant illustre une configuration SSSD typique. Il ne décrit " +"pas la configuration des domaines eux-mêmes ; reportez-vous à la " +"documentation relative à la configuration des domaines pour plus de détails. " +"<placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd.conf.5.xml:4553 +#: sssd.conf.5.xml:4837 #, no-wrap msgid "" "[domain/ipa.com/child.ad.com]\n" "use_fully_qualified_names = false\n" msgstr "" +"[domain/ipa.com/child.ad.com]\n" +"use_fully_qualified_names = false\n" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4547 +#: sssd.conf.5.xml:4831 msgid "" "2. The following example shows configuration of IPA AD trust where the AD " "forest consists of two domains in a parent-child structure. Suppose IPA " @@ -6068,9 +7329,15 @@ msgid "" "configuration should be used. <placeholder type=\"programlisting\" id=\"0\"/" ">" msgstr "" +"2. L'exemple suivant illustre la configuration d'une approbation IPA AD " +"lorsque la forêt AD est composée de deux domaines dans une structure parent-" +"enfant. Supposons que le domaine IPA (ipa.com) ait une approbation avec le " +"domaine AD (ad.com). ad.com possède un domaine enfant (child.ad.com). Pour " +"activer les noms courts dans le domaine enfant, la configuration suivante " +"doit être utilisée. <placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd.conf.5.xml:4564 +#: sssd.conf.5.xml:4848 #, no-wrap msgid "" "[certmap/my.domain/rule_name]\n" @@ -6078,10 +7345,15 @@ msgid "" "maprule = (userCertificate;binary={cert!bin})\n" "domains = my.domain, your.domain\n" "priority = 10\n" -msgstr "" +msgstr "" +"[certmap/my.domain/rule_name]\n" +"matchrule = <ISSUER>^CN=My-CA,DC=MY,DC=DOMAIN$\n" +"maprule = (userCertificate;binary={cert!bin})\n" +"domains = my.domain, your.domain\n" +"priority = 10\n" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4558 +#: sssd.conf.5.xml:4842 msgid "" "3. The following example shows the configuration of a certificate mapping " "rule. It is valid for the configured domain <quote>my.domain</quote> and " @@ -6089,6 +7361,11 @@ msgid "" "certificate in the search filter. <placeholder type=\"programlisting\" " "id=\"0\"/>" msgstr "" +"3. L'exemple suivant illustre la configuration d'une règle de mappage de " +"certificat. Elle est valable pour le domaine configuré <quote>my.domain</" +"quote> et également pour les sous-domaines <quote>your.domain</quote>, et " +"utilise le certificat complet dans le filtre de recherche. <placeholder " +"type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refnamediv><refname> #: sssd-ldap.5.xml:10 sssd-ldap.5.xml:16 @@ -6324,13 +7601,21 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:151 +#, fuzzy +#| msgid "" +#| "Default: If not set, the value of the defaultNamingContext or " +#| "namingContexts attribute from the RootDSE of the LDAP server is used. If " +#| "defaultNamingContext does not exist or has an empty value namingContexts " +#| "is used. The namingContexts attribute must have a single value with the " +#| "DN of the search base of the LDAP server to make this work. Multiple " +#| "values are are not supported." msgid "" "Default: If not set, the value of the defaultNamingContext or namingContexts " "attribute from the RootDSE of the LDAP server is used. If " "defaultNamingContext does not exist or has an empty value namingContexts is " "used. The namingContexts attribute must have a single value with the DN of " "the search base of the LDAP server to make this work. Multiple values are " -"are not supported." +"not supported." msgstr "" "Par défaut : si non définie, les valeurs des attributs defaultNamingContext " "ou namingContexts du RootDSE du serveur LDAP sont utilisées. Si " @@ -6353,18 +7638,22 @@ msgid "" "default, this is done anonymously. However, this may not be permitted by the " "LDAP server. In such cases we can use this option to influence SSSD behavior." msgstr "" +"SSSD consulte RootDSE pour obtenir des informations sur LDAP et ses " +"fonctionnalités. Par défaut, cette opération est anonyme. Toutefois, il est " +"possible que le serveur LDAP l'interdise. Dans ce cas, cette option permet " +"d'influencer le comportement de SSSD." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:175 #, fuzzy #| msgid "The following values are allowed:" msgid "Allowed values are:" -msgstr "Les valeurs suivantes sont autorisées :" +msgstr "Les valeurs suivantes sont autorisées :" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ldap.5.xml:179 msgid "anonymous" -msgstr "" +msgstr "anonyme" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ldap.5.xml:184 @@ -6673,8 +7962,8 @@ msgstr "" "des objets." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap.5.xml:472 sssd-ipa.5.xml:506 sssd-ipa.5.xml:525 sssd-ipa.5.xml:544 -#: sssd-ipa.5.xml:563 +#: sssd-ldap.5.xml:472 sssd-ipa.5.xml:501 sssd-ipa.5.xml:520 sssd-ipa.5.xml:539 +#: sssd-ipa.5.xml:558 msgid "" "See <quote>ldap_search_base</quote> for information about configuring " "multiple search bases." @@ -6683,7 +7972,7 @@ msgstr "" "configuration des bases de recherche multiples." #. type: Content of: <listitem><para> -#: sssd-ldap.5.xml:477 sssd-ipa.5.xml:511 include/ldap_search_bases.xml:27 +#: sssd-ldap.5.xml:477 sssd-ipa.5.xml:506 include/ldap_search_bases.xml:27 msgid "Default: the value of <emphasis>ldap_search_base</emphasis>" msgstr "Par défaut : la valeur de <emphasis>ldap_search_base</emphasis>" @@ -6835,7 +8124,7 @@ msgid "" "closed early to ensure that a new query cannot require the connection to " "remain open past its expiration. This implies that connections will always " "be closed immediately and will never be reused if " -"<emphasis>ldap_connection_expire_timeout <= ldap_opt_timout</emphasis>" +"<emphasis>ldap_connection_expire_timeout <= ldap_opt_timeout</emphasis>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> @@ -7069,8 +8358,10 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:831 -msgid "ldap_ignore_unreadable_references (bool)" -msgstr "" +#, fuzzy +#| msgid "ldap_force_upper_case_realm (boolean)" +msgid "ldap_ignore_unreadable_references (boolean)" +msgstr "ldap_force_upper_case_realm (booléen)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:834 @@ -7452,7 +8743,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap.5.xml:1152 sssd-ad.5.xml:1267 +#: sssd-ldap.5.xml:1152 sssd-ad.5.xml:1260 msgid "Default: 86400 (24 hours)" msgstr "Par défaut : 86400 (24 heures)" @@ -7505,7 +8796,7 @@ msgstr "" "l'utilisation de <quote>krb5_server</quote>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ldap.5.xml:1187 sssd-ipa.5.xml:575 sssd-krb5.5.xml:103 +#: sssd-ldap.5.xml:1187 sssd-ipa.5.xml:570 sssd-krb5.5.xml:103 msgid "krb5_realm (string)" msgstr "krb5_realm (chaîne)" @@ -7711,7 +9002,9 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1339 -msgid "ldap_chpass_update_last_change (bool)" +#, fuzzy +#| msgid "ldap_chpass_update_last_change (bool)" +msgid "ldap_chpass_update_last_change (boolean)" msgstr "ldap_chpass_update_last_change (bool)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> @@ -7888,7 +9181,7 @@ msgid "ldap_access_order (string)" msgstr "ldap_access_order (chaîne)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap.5.xml:1470 sssd-ipa.5.xml:405 +#: sssd-ldap.5.xml:1470 sssd-ipa.5.xml:400 msgid "Comma separated list of access control options. Allowed values are:" msgstr "" "Liste séparées par des virgules des options de contrôles d'accès. Les " @@ -7935,7 +9228,7 @@ msgid "<emphasis>expire</emphasis>: use ldap_account_expire_policy" msgstr "<emphasis>expire</emphasis>: utiliser ldap_account_expire_policy" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap.5.xml:1515 sssd-ipa.5.xml:413 +#: sssd-ldap.5.xml:1515 sssd-ipa.5.xml:408 msgid "" "<emphasis>pwd_expire_policy_reject, pwd_expire_policy_warn, " "pwd_expire_policy_renew: </emphasis> These options are useful if users are " @@ -7945,24 +9238,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap.5.xml:1525 sssd-ipa.5.xml:423 +#: sssd-ldap.5.xml:1525 sssd-ipa.5.xml:418 msgid "" "The difference between these options is the action taken if user password is " "expired:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ldap.5.xml:1530 sssd-ipa.5.xml:428 +#: sssd-ldap.5.xml:1530 sssd-ipa.5.xml:423 msgid "pwd_expire_policy_reject - user is denied to log in," msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ldap.5.xml:1536 sssd-ipa.5.xml:434 +#: sssd-ldap.5.xml:1536 sssd-ipa.5.xml:429 msgid "pwd_expire_policy_warn - user is still able to log in," msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ldap.5.xml:1542 sssd-ipa.5.xml:440 +#: sssd-ldap.5.xml:1542 sssd-ipa.5.xml:435 msgid "" "pwd_expire_policy_renew - user is prompted to change their password " "immediately." @@ -8563,8 +9856,8 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd-ldap.5.xml:2032 sssd-simple.5.xml:169 sssd-ipa.5.xml:984 -#: sssd-ad.5.xml:1470 sssd-idp.5.xml:248 sssd-krb5.5.xml:483 +#: sssd-ldap.5.xml:2032 sssd-simple.5.xml:169 sssd-ipa.5.xml:979 +#: sssd-ad.5.xml:1463 sssd-idp.5.xml:343 sssd-krb5.5.xml:483 #: sss_rpcidmapd.5.xml:98 sssd-session-recording.5.xml:176 msgid "EXAMPLE" msgstr "EXEMPLE" @@ -8602,7 +9895,7 @@ msgstr "" #. type: Content of: <refsect1><refsect2><para> #: sssd-ldap.5.xml:2039 sssd-ldap.5.xml:2057 sssd-simple.5.xml:177 -#: sssd-ipa.5.xml:992 sssd-ad.5.xml:1478 sssd-sudo.5.xml:56 sssd-krb5.5.xml:492 +#: sssd-ipa.5.xml:987 sssd-ad.5.xml:1471 sssd-sudo.5.xml:56 sssd-krb5.5.xml:492 #: sssd-session-recording.5.xml:182 include/ldap_id_mapping.xml:105 msgid "<placeholder type=\"programlisting\" id=\"0\"/>" msgstr "<placeholder type=\"programlisting\" id=\"0\"/>" @@ -8647,7 +9940,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><title> #: sssd-ldap.5.xml:2073 sssd_krb5_locator_plugin.8.xml:83 sssd-simple.5.xml:189 -#: sssd-ad.5.xml:1493 sssd.8.xml:270 sss_seed.8.xml:163 +#: sssd-ad.5.xml:1486 sssd.8.xml:270 sss_seed.8.xml:163 msgid "NOTES" msgstr "NOTES" @@ -9187,7 +10480,7 @@ msgstr "" #: pam_sss.8.xml:434 msgid "" "No authentication method was found by Kerberos. This might happen if the " -"user has a Smartcard assigned but the pkint plugin is not available on the " +"user has a Smartcard assigned but the pkinit plugin is not available on the " "client." msgstr "" @@ -9645,6 +10938,23 @@ msgid "" "first DNS resolving failure." msgstr "" +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_locator_plugin.8.xml:106 +msgid "" +"If the environment variable SSSD_KRB5_LOCATOR_KDC_ADDRESS is set to a KDC " +"address the plugin will use this address instead of reading the kdcinfo " +"file. The address format is the same as in the kdcinfo file (see above)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_locator_plugin.8.xml:112 +msgid "" +"If the environment variable SSSD_KRB5_LOCATOR_KPASSWD_ADDRESS is set to a " +"kpasswd server address the plugin will use this address instead of reading " +"the kpasswdinfo file. The address format is the same as in the kpasswdinfo " +"file (see above)." +msgstr "" + #. type: Content of: <reference><refentry><refnamediv><refname> #: sssd-simple.5.xml:10 sssd-simple.5.xml:16 msgid "sssd-simple" @@ -11126,7 +12436,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:129 sssd-ad.5.xml:1161 +#: sssd-ipa.5.xml:129 sssd-ad.5.xml:1166 msgid "dyndns_update (boolean)" msgstr "dyndns_update (booléen)" @@ -11140,23 +12450,13 @@ msgid "" "quote> option." msgstr "" -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:141 sssd-ad.5.xml:1175 -msgid "" -"NOTE: On older systems (such as RHEL 5), for this behavior to work reliably, " -"the default Kerberos realm must be set properly in /etc/krb5.conf" -msgstr "" -"NOTE : Sur les systèmes plus anciens (tels que RHEL 5), afin que ce " -"comportement fonctionne de façon fiable, le domaine Kerberos par défaut doit " -"être défini correctement dans /etc/krb5.conf" - #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:152 sssd-ad.5.xml:1186 +#: sssd-ipa.5.xml:147 sssd-ad.5.xml:1186 msgid "dyndns_ttl (integer)" msgstr "dyndns_ttl (entier)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:155 sssd-ad.5.xml:1189 +#: sssd-ipa.5.xml:150 sssd-ad.5.xml:1189 msgid "" "The TTL to apply to the client DNS record when updating it. If " "dyndns_update is false this has no effect. This will override the TTL " @@ -11167,17 +12467,17 @@ msgstr "" "TTL côté serveur s'il est défini par un administrateur." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:160 +#: sssd-ipa.5.xml:155 msgid "Default: 1200 (seconds)" msgstr "Par défaut : 1200 (secondes)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:166 sssd-ad.5.xml:1200 +#: sssd-ipa.5.xml:161 sssd-ad.5.xml:1200 msgid "dyndns_iface (string)" msgstr "dyndns_iface (chaîne)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:169 sssd-ad.5.xml:1203 +#: sssd-ipa.5.xml:164 sssd-ad.5.xml:1203 msgid "" "Optional. Applicable only when dyndns_update is true. Choose the interface " "or a list of interfaces whose IP addresses should be used for dynamic DNS " @@ -11189,26 +12489,26 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:182 +#: sssd-ipa.5.xml:177 msgid "" "Default: Use the IP addresses of the interface which is used for IPA LDAP " "connection" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:186 sssd-ad.5.xml:1226 +#: sssd-ipa.5.xml:181 sssd-ad.5.xml:1220 msgid "Example: dyndns_iface = em[12], !vnet1, vnet*" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:192 sssd-ad.5.xml:1232 +#: sssd-ipa.5.xml:187 sssd-ad.5.xml:1226 #, fuzzy #| msgid "dyndns_iface (string)" msgid "dyndns_address (string)" msgstr "dyndns_iface (chaîne)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:195 sssd-ad.5.xml:1235 +#: sssd-ipa.5.xml:190 sssd-ad.5.xml:1229 msgid "" "Optional. Applicable only when <emphasis>dyndns_update</emphasis> is true. " "A list of IP addresses or IP networks to be used for dynamic DNS updates. " @@ -11219,22 +12519,22 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:206 sssd-ad.5.xml:1246 +#: sssd-ipa.5.xml:201 sssd-ad.5.xml:1240 msgid "Default: No filtering of IP addresses." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:209 sssd-ad.5.xml:1249 +#: sssd-ipa.5.xml:204 sssd-ad.5.xml:1243 msgid "Example: dyndns_address = 10.0.0.0/16, !10.0.1.0/24" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:215 sssd-ad.5.xml:1305 +#: sssd-ipa.5.xml:210 sssd-ad.5.xml:1298 msgid "dyndns_auth (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:218 sssd-ad.5.xml:1308 +#: sssd-ipa.5.xml:213 sssd-ad.5.xml:1301 msgid "" "Whether the nsupdate utility should use GSS-TSIG authentication for secure " "updates with the DNS server, insecure updates can be sent by setting this " @@ -11242,19 +12542,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:224 sssd-ad.5.xml:1314 +#: sssd-ipa.5.xml:219 sssd-ad.5.xml:1307 msgid "Default: GSS-TSIG" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:230 sssd-ad.5.xml:1320 +#: sssd-ipa.5.xml:225 sssd-ad.5.xml:1313 #, fuzzy #| msgid "dyndns_iface (string)" msgid "dyndns_auth_ptr (string)" msgstr "dyndns_iface (chaîne)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:233 sssd-ad.5.xml:1323 +#: sssd-ipa.5.xml:228 sssd-ad.5.xml:1316 msgid "" "Whether the nsupdate utility should use GSS-TSIG authentication for secure " "PTR updates with the DNS server, insecure updates can be sent by setting " @@ -11262,17 +12562,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:239 sssd-ad.5.xml:1329 +#: sssd-ipa.5.xml:234 sssd-ad.5.xml:1322 msgid "Default: Same as dyndns_auth" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:245 sssd-ad.5.xml:1255 +#: sssd-ipa.5.xml:240 sssd-ad.5.xml:1249 msgid "dyndns_refresh_interval (integer)" msgstr "dyndns_refresh_interval (entier)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:248 +#: sssd-ipa.5.xml:243 msgid "" "How often should the back end perform periodic DNS update in addition to the " "automatic update performed when the back end goes online. This option is " @@ -11284,12 +12584,14 @@ msgstr "" "configurée à true." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:261 sssd-ad.5.xml:1273 -msgid "dyndns_update_ptr (bool)" +#: sssd-ipa.5.xml:256 sssd-ad.5.xml:1266 +#, fuzzy +#| msgid "dyndns_update_ptr (bool)" +msgid "dyndns_update_ptr (boolean)" msgstr "dyndns_update_ptr (booléen)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:264 sssd-ad.5.xml:1276 +#: sssd-ipa.5.xml:259 sssd-ad.5.xml:1269 msgid "" "Whether the PTR record should also be explicitly updated when updating the " "client's DNS records. Applicable only when dyndns_update is true." @@ -11299,7 +12601,7 @@ msgstr "" "l'option dyndns_update est configurée à true." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:269 +#: sssd-ipa.5.xml:264 msgid "" "This option should be False in most IPA deployments as the IPA server " "generates the PTR records automatically when forward records are changed." @@ -11309,24 +12611,26 @@ msgstr "" "quand les enregistrements directs sont modifiés." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:275 sssd-ad.5.xml:1281 +#: sssd-ipa.5.xml:270 sssd-ad.5.xml:1274 msgid "" "Note that <emphasis>dyndns_update_per_family</emphasis> parameter does not " "apply for PTR record updates. Those updates are always sent separately." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:280 +#: sssd-ipa.5.xml:275 msgid "Default: False (disabled)" msgstr "Par défaut : False (désactivé)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:286 sssd-ad.5.xml:1292 -msgid "dyndns_force_tcp (bool)" +#: sssd-ipa.5.xml:281 sssd-ad.5.xml:1285 +#, fuzzy +#| msgid "dyndns_force_tcp (bool)" +msgid "dyndns_force_tcp (boolean)" msgstr "dyndns_force_tcp (booléen)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:289 sssd-ad.5.xml:1295 +#: sssd-ipa.5.xml:284 sssd-ad.5.xml:1288 msgid "" "Whether the nsupdate utility should default to using TCP for communicating " "with the DNS server." @@ -11335,31 +12639,31 @@ msgstr "" "communication avec le serveur DNS." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:293 sssd-ad.5.xml:1299 +#: sssd-ipa.5.xml:288 sssd-ad.5.xml:1292 msgid "Default: False (let nsupdate choose the protocol)" msgstr "Par défaut : False (laisser nsupdate choisir le protocole)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:299 sssd-ad.5.xml:1335 +#: sssd-ipa.5.xml:294 sssd-ad.5.xml:1328 msgid "dyndns_server (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:302 sssd-ad.5.xml:1338 +#: sssd-ipa.5.xml:297 sssd-ad.5.xml:1331 msgid "" "The DNS server to use when performing a DNS update. In most setups, it's " "recommended to leave this option unset." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:307 sssd-ad.5.xml:1343 +#: sssd-ipa.5.xml:302 sssd-ad.5.xml:1336 msgid "" "Setting this option makes sense for environments where the DNS server is " "different from the identity server or when we use encrypted DNS." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:312 sssd-ad.5.xml:1348 +#: sssd-ipa.5.xml:307 sssd-ad.5.xml:1341 msgid "" "The parameter can be a simple string containing DNS name or IP address. It " "can also be an URI. The URI can look like <emphasis>dns://servername/</" @@ -11367,7 +12671,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:319 sssd-ad.5.xml:1355 +#: sssd-ipa.5.xml:314 sssd-ad.5.xml:1348 msgid "" "The second example enables DNS-over-TLS protocol for DNS updates. The " "nsupdate utility must support DoT - check the <emphasis>man nsupdate</" @@ -11375,7 +12679,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:325 sssd-ad.5.xml:1361 +#: sssd-ipa.5.xml:320 sssd-ad.5.xml:1354 msgid "" "Please note that this option will be only used in fallback attempt when " "previous attempt using autodetected settings failed or when DNS-over-TLS is " @@ -11383,17 +12687,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:331 sssd-ad.5.xml:1367 +#: sssd-ipa.5.xml:326 sssd-ad.5.xml:1360 msgid "Default: None (let nsupdate choose the server)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:337 sssd-ad.5.xml:1373 +#: sssd-ipa.5.xml:332 sssd-ad.5.xml:1366 msgid "dyndns_update_per_family (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:340 sssd-ad.5.xml:1376 +#: sssd-ipa.5.xml:335 sssd-ad.5.xml:1369 msgid "" "DNS update is by default performed in two steps - IPv4 update and then IPv6 " "update. In some cases it might be desirable to perform IPv4 and IPv6 update " @@ -11401,14 +12705,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:352 sssd-ad.5.xml:1388 +#: sssd-ipa.5.xml:347 sssd-ad.5.xml:1381 #, fuzzy #| msgid "dyndns_iface (string)" msgid "dyndns_dot_cacert (string)" msgstr "dyndns_iface (chaîne)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:355 sssd-ad.5.xml:1391 +#: sssd-ipa.5.xml:350 sssd-ad.5.xml:1384 msgid "" "This option specifies the file of the certificate authorities certificates " "(in PEM format) in order to verify the remote server TLS certificate when " @@ -11416,19 +12720,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:361 sssd-ad.5.xml:1397 +#: sssd-ipa.5.xml:356 sssd-ad.5.xml:1390 msgid "Default: None (use global certificate store)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:367 sssd-ad.5.xml:1403 +#: sssd-ipa.5.xml:362 sssd-ad.5.xml:1396 #, fuzzy #| msgid "dyndns_iface (string)" msgid "dyndns_dot_cert (string)" msgstr "dyndns_iface (chaîne)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:370 sssd-ad.5.xml:1406 +#: sssd-ipa.5.xml:365 sssd-ad.5.xml:1399 msgid "" "This option sets the certificate(s) file for authentication for the DoT " "transport to the remote server. The certificate chain file is expected to be " @@ -11436,14 +12740,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:376 sssd-ad.5.xml:1412 +#: sssd-ipa.5.xml:371 sssd-ad.5.xml:1405 msgid "" "The <emphasis>dyndns_dot_cert</emphasis> and <emphasis>dyndns_dot_key</" "emphasis> options must be both set to achieve mutual TLS authentication." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:381 sssd-ipa.5.xml:396 sssd-ad.5.xml:1417 sssd-ad.5.xml:1432 +#: sssd-ipa.5.xml:376 sssd-ipa.5.xml:391 sssd-ad.5.xml:1410 sssd-ad.5.xml:1425 #, fuzzy #| msgid "Default: not set (no substitution for unset home directories)" msgid "Default: None (Do not use TLS authentication)" @@ -11452,14 +12756,14 @@ msgstr "" "non définis)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:387 sssd-ad.5.xml:1423 +#: sssd-ipa.5.xml:382 sssd-ad.5.xml:1416 #, fuzzy #| msgid "dyndns_iface (string)" msgid "dyndns_dot_key (string)" msgstr "dyndns_iface (chaîne)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:390 sssd-ad.5.xml:1426 +#: sssd-ipa.5.xml:385 sssd-ad.5.xml:1419 msgid "" "This option sets the key file for authenticated encryption for the DoT " "transport to the remote server. The private key file is expected to be in " @@ -11467,142 +12771,142 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:402 +#: sssd-ipa.5.xml:397 #, fuzzy #| msgid "ldap_access_order (string)" msgid "ipa_access_order (string)" msgstr "ldap_access_order (chaîne)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:409 +#: sssd-ipa.5.xml:404 #, fuzzy #| msgid "<emphasis>expire</emphasis>: use ldap_account_expire_policy" msgid "<emphasis>expire</emphasis>: use IPA's account expiration policy." msgstr "<emphasis>expire</emphasis>: utiliser ldap_account_expire_policy" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:448 +#: sssd-ipa.5.xml:443 msgid "" "Please note that 'access_provider = ipa' must be set for this feature to " "work." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:455 +#: sssd-ipa.5.xml:450 msgid "ipa_deskprofile_search_base (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:458 +#: sssd-ipa.5.xml:453 msgid "" "Optional. Use the given string as search base for Desktop Profile related " "objects." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:462 sssd-ipa.5.xml:484 +#: sssd-ipa.5.xml:457 sssd-ipa.5.xml:479 msgid "Default: Use base DN" msgstr "Par défaut : utilise le DN de base" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:468 +#: sssd-ipa.5.xml:463 #, fuzzy #| msgid "ipa_subdomains_search_base (string)" msgid "ipa_subid_ranges_search_base (string)" msgstr "ipa_subdomains_search_base (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:471 +#: sssd-ipa.5.xml:466 #, fuzzy #| msgid "ipa_subdomains_search_base (string)" msgid "Deprecated. Use ldap_subid_ranges_search_base instead." msgstr "ipa_subdomains_search_base (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:477 +#: sssd-ipa.5.xml:472 msgid "ipa_hbac_search_base (string)" msgstr "ipa_hbac_search_base (chaîne)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:480 +#: sssd-ipa.5.xml:475 msgid "Optional. Use the given string as search base for HBAC related objects." msgstr "" "Facultatif. Utilise la chaîne donnée comme base de recherche pour les objets " "HBAC associés." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:490 +#: sssd-ipa.5.xml:485 msgid "ipa_host_search_base (string)" msgstr "ipa_host_search_base (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:493 +#: sssd-ipa.5.xml:488 msgid "Deprecated. Use ldap_host_search_base instead." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:499 +#: sssd-ipa.5.xml:494 msgid "ipa_selinux_search_base (string)" msgstr "ipa_selinux_search_base (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:502 +#: sssd-ipa.5.xml:497 msgid "Optional. Use the given string as search base for SELinux user maps." msgstr "" "Facultatif. Utiliser la chaîne donnée comme base de recherche pour les " "mappages utilisateur SELinux." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:518 +#: sssd-ipa.5.xml:513 msgid "ipa_subdomains_search_base (string)" msgstr "ipa_subdomains_search_base (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:521 +#: sssd-ipa.5.xml:516 msgid "Optional. Use the given string as search base for trusted domains." msgstr "" "Facultatif. Utiliser la chaîne donnée comme base de recherche pour les " "domaines approuvés." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:530 +#: sssd-ipa.5.xml:525 msgid "Default: the value of <emphasis>cn=trusts,%basedn</emphasis>" msgstr "Par défaut : la valeur de <emphasis>cn=trusts,%basedn</emphasis>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:537 +#: sssd-ipa.5.xml:532 msgid "ipa_master_domain_search_base (string)" msgstr "ipa_master_domain_search_base (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:540 +#: sssd-ipa.5.xml:535 msgid "Optional. Use the given string as search base for master domain object." msgstr "" "Facultatif. Utiliser la chaîne donnée comme base de recherche objet de " "domaine maître." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:549 +#: sssd-ipa.5.xml:544 msgid "Default: the value of <emphasis>cn=ad,cn=etc,%basedn</emphasis>" msgstr "Par défaut : la valeur de <emphasis>cn=ad,cn=etc,%basedn</emphasis>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:556 +#: sssd-ipa.5.xml:551 msgid "ipa_views_search_base (string)" msgstr "ipa_views_search_base (chaîne)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:559 +#: sssd-ipa.5.xml:554 msgid "Optional. Use the given string as search base for views containers." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:568 +#: sssd-ipa.5.xml:563 msgid "Default: the value of <emphasis>cn=views,cn=accounts,%basedn</emphasis>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:578 +#: sssd-ipa.5.xml:573 msgid "" "The name of the Kerberos realm. This is optional and defaults to the value " "of <quote>ipa_domain</quote>." @@ -11611,7 +12915,7 @@ msgstr "" "valeur de <quote>ipa_domain</quote>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:582 +#: sssd-ipa.5.xml:577 msgid "" "The name of the Kerberos realm has a special meaning in IPA - it is " "converted into the base DN to use for performing LDAP operations." @@ -11620,37 +12924,37 @@ msgstr "" "convertit en DN de base pour effectuer les opérations LDAP." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:590 sssd-ad.5.xml:1441 +#: sssd-ipa.5.xml:585 sssd-ad.5.xml:1434 msgid "krb5_confd_path (string)" msgstr "krb5_confd_path (chaîne)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:593 sssd-ad.5.xml:1444 +#: sssd-ipa.5.xml:588 sssd-ad.5.xml:1437 msgid "" "Absolute path of a directory where SSSD should place Kerberos configuration " "snippets." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:597 sssd-ad.5.xml:1448 +#: sssd-ipa.5.xml:592 sssd-ad.5.xml:1441 msgid "" "To disable the creation of the configuration snippets set the parameter to " "'none'." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:601 sssd-ad.5.xml:1452 +#: sssd-ipa.5.xml:596 sssd-ad.5.xml:1445 msgid "" "Default: not set (krb5.include.d subdirectory of SSSD's pubconf directory)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:608 +#: sssd-ipa.5.xml:603 msgid "ipa_deskprofile_refresh (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:611 +#: sssd-ipa.5.xml:606 msgid "" "The amount of time between lookups of the Desktop Profile rules against the " "IPA server. This will reduce the latency and load on the IPA server if there " @@ -11658,34 +12962,34 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:618 sssd-ipa.5.xml:648 sssd-ipa.5.xml:664 sssd-ad.5.xml:600 +#: sssd-ipa.5.xml:613 sssd-ipa.5.xml:643 sssd-ipa.5.xml:659 sssd-ad.5.xml:600 msgid "Default: 5 (seconds)" msgstr "Par défaut : 5 (secondes)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:624 +#: sssd-ipa.5.xml:619 msgid "ipa_deskprofile_request_interval (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:627 +#: sssd-ipa.5.xml:622 msgid "" "The amount of time between lookups of the Desktop Profile rules against the " "IPA server in case the last request did not return any rule." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:632 +#: sssd-ipa.5.xml:627 msgid "Default: 60 (minutes)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:638 +#: sssd-ipa.5.xml:633 msgid "ipa_hbac_refresh (integer)" msgstr "ipa_hbac_refresh (entier)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:641 +#: sssd-ipa.5.xml:636 msgid "" "The amount of time between lookups of the HBAC rules against the IPA server. " "This will reduce the latency and load on the IPA server if there are many " @@ -11696,12 +13000,14 @@ msgstr "" "beaucoup de requêtes de contrôle d'accès sur une courte période." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:654 -msgid "ipa_hbac_selinux (integer)" -msgstr "ipa_hbac_selinux (entier)" +#: sssd-ipa.5.xml:649 +#, fuzzy +#| msgid "ipa_hbac_refresh (integer)" +msgid "ipa_selinux_refresh (integer)" +msgstr "ipa_hbac_refresh (entier)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:657 +#: sssd-ipa.5.xml:652 msgid "" "The amount of time between lookups of the SELinux maps against the IPA " "server. This will reduce the latency and load on the IPA server if there are " @@ -11712,33 +13018,33 @@ msgstr "" "requêtes de connexions utilisateurs sur une courte période." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:670 +#: sssd-ipa.5.xml:665 msgid "ipa_server_mode (boolean)" msgstr "ipa_server_mode (booléen)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:673 +#: sssd-ipa.5.xml:668 msgid "" "This option will be set by the IPA installer (ipa-server-install) " "automatically and denotes if SSSD is running on an IPA server or not." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:678 +#: sssd-ipa.5.xml:673 msgid "" "On an IPA server SSSD will lookup users and groups from trusted domains " "directly while on a client it will ask an IPA server." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:683 +#: sssd-ipa.5.xml:678 msgid "" "NOTE: There are currently some assumptions that must be met when SSSD is " "running on an IPA server." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:688 +#: sssd-ipa.5.xml:683 msgid "" "The <quote>ipa_server</quote> option must be configured to point to the IPA " "server itself. This is already the default set by the IPA installer, so no " @@ -11746,59 +13052,59 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:697 +#: sssd-ipa.5.xml:692 msgid "" "The <quote>full_name_format</quote> option must not be tweaked to only print " "short names for users from trusted domains." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:712 +#: sssd-ipa.5.xml:707 msgid "ipa_automount_location (string)" msgstr "ipa_automount_location (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:715 +#: sssd-ipa.5.xml:710 msgid "The automounter location this IPA client will be using" msgstr "L'emplacement à automonter qu'utilisera ce client IPA" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:718 +#: sssd-ipa.5.xml:713 msgid "Default: The location named \"default\"" msgstr "Par défaut : Le lieu nommé « default »" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd-ipa.5.xml:726 +#: sssd-ipa.5.xml:721 msgid "VIEWS AND OVERRIDES" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:735 +#: sssd-ipa.5.xml:730 msgid "ipa_view_class (string)" msgstr "ipa_view_class (chaîne)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:738 +#: sssd-ipa.5.xml:733 msgid "Objectclass of the view container." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:741 +#: sssd-ipa.5.xml:736 msgid "Default: nsContainer" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:747 +#: sssd-ipa.5.xml:742 msgid "ipa_view_name (string)" msgstr "ipa_view_name (chaîne)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:750 +#: sssd-ipa.5.xml:745 msgid "Name of the attribute holding the name of the view." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:754 sssd-ldap-attributes.5.xml:496 +#: sssd-ipa.5.xml:749 sssd-ldap-attributes.5.xml:496 #: sssd-ldap-attributes.5.xml:832 sssd-ldap-attributes.5.xml:913 #: sssd-ldap-attributes.5.xml:1010 sssd-ldap-attributes.5.xml:1068 #: sssd-ldap-attributes.5.xml:1226 sssd-ldap-attributes.5.xml:1271 @@ -11806,128 +13112,128 @@ msgid "Default: cn" msgstr "Par défaut : cn" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:760 +#: sssd-ipa.5.xml:755 msgid "ipa_override_object_class (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:763 +#: sssd-ipa.5.xml:758 msgid "Objectclass of the override objects." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:766 +#: sssd-ipa.5.xml:761 msgid "Default: ipaOverrideAnchor" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:772 +#: sssd-ipa.5.xml:767 msgid "ipa_anchor_uuid (string)" msgstr "ipa_anchor_uuid (chaîne)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:775 +#: sssd-ipa.5.xml:770 msgid "" "Name of the attribute containing the reference to the original object in a " "remote domain." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:779 +#: sssd-ipa.5.xml:774 msgid "Default: ipaAnchorUUID" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:785 +#: sssd-ipa.5.xml:780 msgid "ipa_user_override_object_class (string)" msgstr "ipa_user_override_object_class (chaîne)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:788 +#: sssd-ipa.5.xml:783 msgid "" "Name of the objectclass for user overrides. It is used to determine if the " "found override object is related to a user or a group." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:793 +#: sssd-ipa.5.xml:788 msgid "User overrides can contain attributes given by" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:796 +#: sssd-ipa.5.xml:791 msgid "ldap_user_name" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:799 +#: sssd-ipa.5.xml:794 msgid "ldap_user_uid_number" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:802 +#: sssd-ipa.5.xml:797 msgid "ldap_user_gid_number" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:805 +#: sssd-ipa.5.xml:800 msgid "ldap_user_gecos" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:808 +#: sssd-ipa.5.xml:803 msgid "ldap_user_home_directory" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:811 +#: sssd-ipa.5.xml:806 msgid "ldap_user_shell" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:814 +#: sssd-ipa.5.xml:809 msgid "ldap_user_ssh_public_key" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:819 +#: sssd-ipa.5.xml:814 msgid "Default: ipaUserOverride" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:825 +#: sssd-ipa.5.xml:820 msgid "ipa_group_override_object_class (string)" msgstr "ipa_group_override_object_class (chaîne)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:828 +#: sssd-ipa.5.xml:823 msgid "" "Name of the objectclass for group overrides. It is used to determine if the " "found override object is related to a user or a group." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:833 +#: sssd-ipa.5.xml:828 msgid "Group overrides can contain attributes given by" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:836 +#: sssd-ipa.5.xml:831 msgid "ldap_group_name" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:839 +#: sssd-ipa.5.xml:834 msgid "ldap_group_gid_number" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:844 +#: sssd-ipa.5.xml:839 msgid "Default: ipaGroupOverride" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:728 +#: sssd-ipa.5.xml:723 msgid "" "SSSD can handle views and overrides which are offered by FreeIPA 4.1 and " "later version. Since all paths and objectclasses are fixed on the server " @@ -11937,12 +13243,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd-ipa.5.xml:856 +#: sssd-ipa.5.xml:851 msgid "SUBDOMAINS PROVIDER" msgstr "FOURNISSEURS DE SOUS-DOMAINES" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:858 +#: sssd-ipa.5.xml:853 msgid "" "The IPA subdomains provider behaves slightly differently if it is configured " "explicitly or implicitly." @@ -11951,7 +13257,7 @@ msgstr "" "configuré explicitement ou implicitement." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:862 +#: sssd-ipa.5.xml:857 msgid "" "If the option 'subdomains_provider = ipa' is found in the domain section of " "sssd.conf, the IPA subdomains provider is configured explicitly, and all " @@ -11963,7 +13269,7 @@ msgstr "" "serveur IPA si nécessaire." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:868 +#: sssd-ipa.5.xml:863 msgid "" "If the option 'subdomains_provider' is not set in the domain section of " "sssd.conf but there is the option 'id_provider = ipa', the IPA subdomains " @@ -11983,12 +13289,12 @@ msgstr "" "fournisseur de sous-domaines est à nouveau activé." #. type: Content of: <reference><refentry><refsect1><title> -#: sssd-ipa.5.xml:879 +#: sssd-ipa.5.xml:874 msgid "TRUSTED DOMAINS CONFIGURATION" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-ipa.5.xml:887 +#: sssd-ipa.5.xml:882 #, no-wrap msgid "" "[domain/ipa.domain.com/ad.domain.com]\n" @@ -11996,7 +13302,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:881 +#: sssd-ipa.5.xml:876 msgid "" "Some configuration options can also be set for a trusted domain. A trusted " "domain configuration can be set using the trusted domain subsection as shown " @@ -12006,99 +13312,99 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:892 +#: sssd-ipa.5.xml:887 msgid "" "For more details, see the <citerefentry> <refentrytitle>sssd.conf</" "refentrytitle> <manvolnum>5</manvolnum> </citerefentry> manual page." msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:899 +#: sssd-ipa.5.xml:894 msgid "" "Different configuration options are tunable for a trusted domain depending " "on whether you are configuring SSSD on an IPA server or an IPA client." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd-ipa.5.xml:904 +#: sssd-ipa.5.xml:899 msgid "OPTIONS TUNABLE ON IPA MASTERS" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:906 +#: sssd-ipa.5.xml:901 msgid "" "The following options can be set in a subdomain section on an IPA master:" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:910 sssd-ipa.5.xml:950 +#: sssd-ipa.5.xml:905 sssd-ipa.5.xml:945 msgid "ad_server" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:913 +#: sssd-ipa.5.xml:908 msgid "ad_backup_server" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:916 sssd-ipa.5.xml:953 +#: sssd-ipa.5.xml:911 sssd-ipa.5.xml:948 msgid "ad_site" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:919 +#: sssd-ipa.5.xml:914 msgid "ipa_server" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:922 +#: sssd-ipa.5.xml:917 #, fuzzy #| msgid "ipa_server, ipa_backup_server (string)" msgid "ipa_backup_server" msgstr "ipa_server, ipa_backup_server (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:925 +#: sssd-ipa.5.xml:920 msgid "ldap_search_base" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:928 +#: sssd-ipa.5.xml:923 msgid "ldap_user_search_base" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:931 +#: sssd-ipa.5.xml:926 msgid "ldap_group_search_base" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:939 +#: sssd-ipa.5.xml:934 msgid "" "Options prefixed with 'ad_' or 'ipa_' only apply to their respective " "subdomain type." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd-ipa.5.xml:944 +#: sssd-ipa.5.xml:939 msgid "OPTIONS TUNABLE ON IPA CLIENTS" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:946 +#: sssd-ipa.5.xml:941 msgid "" "The following options can be set in an AD subdomain section on an IPA client:" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:958 +#: sssd-ipa.5.xml:953 msgid "" "Note that if both options are set, only <quote>ad_server</quote> is " "evaluated." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:962 +#: sssd-ipa.5.xml:957 msgid "" "Since any request for a user or a group identity from a trusted domain " "triggered from an IPA client is resolved by the IPA server, the " @@ -12112,7 +13418,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:986 +#: sssd-ipa.5.xml:981 msgid "" "The following example assumes that SSSD is correctly configured and " "example.com is one of the domains in the <replaceable>[sssd]</replaceable> " @@ -12123,7 +13429,7 @@ msgstr "" "exemples montrent seulement les options spécifiques au fournisseur IPA." #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-ipa.5.xml:993 +#: sssd-ipa.5.xml:988 #, no-wrap msgid "" "[domain/example.com]\n" @@ -12854,27 +14160,27 @@ msgid "lxdm" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:694 +#: sssd-ad.5.xml:699 msgid "sddm" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:699 +#: sssd-ad.5.xml:704 msgid "unity" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:704 +#: sssd-ad.5.xml:709 msgid "xdm" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:713 +#: sssd-ad.5.xml:718 msgid "ad_gpo_map_remote_interactive (string)" msgstr "ad_gpo_map_remote_interactive (chaîne)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:716 +#: sssd-ad.5.xml:721 msgid "" "A comma-separated list of PAM service names for which GPO-based access " "control is evaluated based on the RemoteInteractiveLogonRight and " @@ -12890,7 +14196,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:735 +#: sssd-ad.5.xml:740 msgid "" "Note: Using the Group Policy Management Editor this value is called \"Allow " "log on through Remote Desktop Services\" and \"Deny log on through Remote " @@ -12898,7 +14204,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:750 +#: sssd-ad.5.xml:755 #, no-wrap msgid "" "ad_gpo_map_remote_interactive = +my_pam_service, -sshd\n" @@ -12906,7 +14212,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:741 +#: sssd-ad.5.xml:746 msgid "" "It is possible to add another PAM service name to the default set by using " "<quote>+service_name</quote> or to explicitly remove a PAM service name from " @@ -12918,22 +14224,22 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:758 +#: sssd-ad.5.xml:763 msgid "sshd" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:763 +#: sssd-ad.5.xml:768 msgid "cockpit" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:772 +#: sssd-ad.5.xml:777 msgid "ad_gpo_map_network (string)" msgstr "ad_gpo_map_network (chaîne)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:775 +#: sssd-ad.5.xml:780 msgid "" "A comma-separated list of PAM service names for which GPO-based access " "control is evaluated based on the NetworkLogonRight and " @@ -12949,7 +14255,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:793 +#: sssd-ad.5.xml:798 msgid "" "Note: Using the Group Policy Management Editor this value is called \"Access " "this computer from the network\" and \"Deny access to this computer from the " @@ -12957,7 +14263,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:808 +#: sssd-ad.5.xml:813 #, no-wrap msgid "" "ad_gpo_map_network = +my_pam_service, -ftp\n" @@ -12965,7 +14271,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:799 +#: sssd-ad.5.xml:804 msgid "" "It is possible to add another PAM service name to the default set by using " "<quote>+service_name</quote> or to explicitly remove a PAM service name from " @@ -12977,22 +14283,22 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:816 +#: sssd-ad.5.xml:821 msgid "ftp" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:821 +#: sssd-ad.5.xml:826 msgid "samba" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:830 +#: sssd-ad.5.xml:835 msgid "ad_gpo_map_batch (string)" msgstr "ad_gpo_map_batch (chaîne)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:833 +#: sssd-ad.5.xml:838 msgid "" "A comma-separated list of PAM service names for which GPO-based access " "control is evaluated based on the BatchLogonRight and DenyBatchLogonRight " @@ -13007,14 +14313,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:851 +#: sssd-ad.5.xml:856 msgid "" "Note: Using the Group Policy Management Editor this value is called \"Allow " "log on as a batch job\" and \"Deny log on as a batch job\"." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:865 +#: sssd-ad.5.xml:870 #, no-wrap msgid "" "ad_gpo_map_batch = +my_pam_service, -crond\n" @@ -13022,7 +14328,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:856 +#: sssd-ad.5.xml:861 msgid "" "It is possible to add another PAM service name to the default set by using " "<quote>+service_name</quote> or to explicitly remove a PAM service name from " @@ -13034,23 +14340,23 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:868 +#: sssd-ad.5.xml:873 msgid "" "Note: Cron service name may differ depending on Linux distribution used." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:874 +#: sssd-ad.5.xml:879 msgid "crond" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:883 +#: sssd-ad.5.xml:888 msgid "ad_gpo_map_service (string)" msgstr "ad_gpo_map_service (chaîne)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:886 +#: sssd-ad.5.xml:891 msgid "" "A comma-separated list of PAM service names for which GPO-based access " "control is evaluated based on the ServiceLogonRight and " @@ -13066,14 +14372,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:904 +#: sssd-ad.5.xml:909 msgid "" "Note: Using the Group Policy Management Editor this value is called \"Allow " "log on as a service\" and \"Deny log on as a service\"." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:917 +#: sssd-ad.5.xml:922 #, no-wrap msgid "" "ad_gpo_map_service = +my_pam_service\n" @@ -13081,7 +14387,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:909 sssd-ad.5.xml:984 +#: sssd-ad.5.xml:914 sssd-ad.5.xml:989 msgid "" "It is possible to add a PAM service name to the default set by using " "<quote>+service_name</quote>. Since the default set is empty, it is not " @@ -13092,19 +14398,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:927 +#: sssd-ad.5.xml:932 msgid "ad_gpo_map_permit (string)" msgstr "ad_gpo_map_permit (chaîne)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:930 +#: sssd-ad.5.xml:935 msgid "" "A comma-separated list of PAM service names for which GPO-based access is " "always granted, regardless of any GPO Logon Rights." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:944 +#: sssd-ad.5.xml:949 #, no-wrap msgid "" "ad_gpo_map_permit = +my_pam_service, -sudo\n" @@ -13112,7 +14418,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:935 +#: sssd-ad.5.xml:940 msgid "" "It is possible to add another PAM service name to the default set by using " "<quote>+service_name</quote> or to explicitly remove a PAM service name from " @@ -13124,29 +14430,29 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:952 +#: sssd-ad.5.xml:957 msgid "polkit-1" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:967 +#: sssd-ad.5.xml:972 msgid "systemd-user" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:976 +#: sssd-ad.5.xml:981 msgid "ad_gpo_map_deny (string)" msgstr "ad_gpo_map_deny (chaîne)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:979 +#: sssd-ad.5.xml:984 msgid "" "A comma-separated list of PAM service names for which GPO-based access is " "always denied, regardless of any GPO Logon Rights." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:992 +#: sssd-ad.5.xml:997 #, no-wrap msgid "" "ad_gpo_map_deny = +my_pam_service\n" @@ -13154,12 +14460,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:1002 +#: sssd-ad.5.xml:1007 msgid "ad_gpo_default_right (string)" msgstr "ad_gpo_default_right (chaîne)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1005 +#: sssd-ad.5.xml:1010 msgid "" "This option defines how access control is evaluated for PAM service names " "that are not explicitly listed in one of the ad_gpo_map_* options. This " @@ -13172,52 +14478,52 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1018 +#: sssd-ad.5.xml:1023 msgid "Supported values for this option include:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1027 +#: sssd-ad.5.xml:1032 msgid "remote_interactive" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1032 +#: sssd-ad.5.xml:1037 msgid "network" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1037 +#: sssd-ad.5.xml:1042 msgid "batch" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1042 +#: sssd-ad.5.xml:1047 msgid "service" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1047 +#: sssd-ad.5.xml:1052 msgid "permit" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1052 +#: sssd-ad.5.xml:1057 msgid "deny" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1058 +#: sssd-ad.5.xml:1063 msgid "Default: deny" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:1064 +#: sssd-ad.5.xml:1069 msgid "ad_maximum_machine_account_password_age (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1067 +#: sssd-ad.5.xml:1072 msgid "" "SSSD will check once a day if the machine account password is older than the " "given age in days and try to renew it. A value of 0 will disable the renewal " @@ -13225,17 +14531,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1073 +#: sssd-ad.5.xml:1078 msgid "Default: 30 days" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:1079 +#: sssd-ad.5.xml:1084 msgid "ad_machine_account_password_renewal_opts (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1082 +#: sssd-ad.5.xml:1087 msgid "" "This option should only be used to test the machine account renewal task. " "The option expects 3 integers and a string separated by a colon (':'). The " @@ -13248,20 +14554,20 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1096 +#: sssd-ad.5.xml:1101 msgid "" "The optional fourth string value identifies the helper binary which should " "be used for the renewal. Currently <command>adcli</command> and " "<command>realm</command> are supported. If this value is missing or empty in " "the value string <command>realm</command> will be used. Since the helper is " "started as the user SSSD is running as there might be the chance that the " -"renewal will fail if this user does not has permissions to modify the keytab " -"file where the machine account credentials are stored. This will typically " -"be the case for <command>adcli</command>." +"renewal will fail if this user does not have permissions to modify the " +"keytab file where the machine account credentials are stored. This will " +"typically be the case for <command>adcli</command>." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1110 +#: sssd-ad.5.xml:1115 msgid "" "<command>realm</command> is not updating the keytab directly but is calling " "the <command>realmd</command> process, which runs as root user, for this " @@ -13271,17 +14577,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1119 +#: sssd-ad.5.xml:1124 msgid "Default: 86400:750:300:realm (24h, 12m30s and 5m)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:1125 +#: sssd-ad.5.xml:1130 msgid "ad_update_samba_machine_account_password (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1128 +#: sssd-ad.5.xml:1133 msgid "" "If enabled, when SSSD renews the machine account password, it will also be " "updated in Samba's database. This prevents Samba's copy of the machine " @@ -13290,23 +14596,25 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:1141 -msgid "ad_use_ldaps (bool)" -msgstr "" +#: sssd-ad.5.xml:1146 +#, fuzzy +#| msgid "ldap_id_use_start_tls (boolean)" +msgid "ad_use_ldaps (boolean)" +msgstr "ldap_id_use_start_tls (booléen)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1144 +#: sssd-ad.5.xml:1149 msgid "" "By default SSSD uses the plain LDAP port 389 and the Global Catalog port " -"3628. If this option is set to True SSSD will use the LDAPS port 636 and " -"Global Catalog port 3629 with LDAPS protection. Since AD does not allow to " +"3268. If this option is set to True SSSD will use the LDAPS port 636 and " +"Global Catalog port 3269 with LDAPS protection. Since AD does not allow to " "have multiple encryption layers on a single connection and we still want to " "use SASL/GSSAPI or SASL/GSS-SPNEGO for authentication the SASL security " "property maxssf is set to 0 (zero) for those connections." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1164 +#: sssd-ad.5.xml:1169 msgid "" "Optional. This option tells SSSD to automatically update the Active " "Directory DNS server with the IP address of this client. The update is " @@ -13331,34 +14639,30 @@ msgstr "Par défaut : 3600 (secondes)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:1216 msgid "" -"NOTE: While it is still possible to use the old <emphasis>ipa_dyndns_iface</" -"emphasis> option, users should migrate to using <emphasis>dyndns_iface</" -"emphasis> in their config file." -msgstr "" -"REMARQUE : Bien qu'il soit toujours possible d'utiliser l'ancienne option " -"<emphasis>ipa_dyndns_iface</emphasis>, les utilisateurs doivent maintenant " -"utiliser <emphasis>dyndns_iface</emphasis> dans leur fichier de " -"configuration." - -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1222 -msgid "" "Default: Use the IP addresses of the interface which is used for AD LDAP " "connection" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1258 +#: sssd-ad.5.xml:1252 +#, fuzzy +#| msgid "" +#| "How often should the back end perform periodic DNS update in addition to " +#| "the automatic update performed when the back end goes online. This " +#| "option is optional and applicable only when dyndns_update is true." msgid "" "How often should the back end perform periodic DNS update in addition to the " -"automatic update performed when the back end goes online. This option is " -"optional and applicable only when dyndns_update is true. Note that the " -"lowest possible value is 60 seconds in-case if value is provided less than " -"60, parameter will assume lowest value only." +"automatic update performed when the back end goes online. This is optional " +"and applicable only when dyndns_update is true. Note that the minimum value " +"is 60 seconds, any specified value below this threshold will default to 60." msgstr "" +"Fréquence de mise à jour des DNS par le moteur en plus des mises à jour " +"automatiques effectuées lorsque le moteur arrive en ligne. Cette option est " +"facultative, et n'est applicable que lorsque l'option dyndns_update est " +"configurée à true." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ad.5.xml:1472 +#: sssd-ad.5.xml:1465 msgid "" "The following example assumes that SSSD is correctly configured and " "example.com is one of the domains in the <replaceable>[sssd]</replaceable> " @@ -13369,7 +14673,7 @@ msgstr "" "exemples montrent seulement les options spécifiques au fournisseur AD." #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-ad.5.xml:1479 +#: sssd-ad.5.xml:1472 #, no-wrap msgid "" "[domain/EXAMPLE]\n" @@ -13393,7 +14697,7 @@ msgstr "" "ad_domain = example.com\n" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-ad.5.xml:1499 +#: sssd-ad.5.xml:1492 #, no-wrap msgid "" "access_provider = ldap\n" @@ -13405,7 +14709,7 @@ msgstr "" "ldap_account_expire_policy = ad\n" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ad.5.xml:1495 +#: sssd-ad.5.xml:1488 msgid "" "The AD access control provider checks if the account is expired. It has the " "same effect as the following configuration of the LDAP provider: " @@ -13416,7 +14720,7 @@ msgstr "" "<placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ad.5.xml:1505 +#: sssd-ad.5.xml:1498 msgid "" "However, unless the <quote>ad</quote> access control provider is explicitly " "configured, the default access provider is <quote>permit</quote>. Please " @@ -13426,7 +14730,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ad.5.xml:1513 +#: sssd-ad.5.xml:1506 msgid "" "When the autofs provider is set to <quote>ad</quote>, the RFC2307 schema " "attribute mapping (nisMap, nisObject, ...) is used, because these attributes " @@ -13626,11 +14930,17 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-sudo.5.xml:137 +#, fuzzy +#| msgid "" +#| "The <emphasis>smart refresh</emphasis> periodically downloads rules that " +#| "are new or were modified after the last update. Its primary goal is to " +#| "keep the database growing by fetching only small increments that do not " +#| "generate large amounts of network traffic." msgid "" "The <emphasis>smart refresh</emphasis> periodically downloads rules that are " -"new or were modified after the last update. Its primary goal is to keep the " -"database growing by fetching only small increments that do not generate " -"large amounts of network traffic." +"new or were modified after the last update. Its primary goal is to grow the " +"database incrementally by fetching only small updates, avoiding large " +"amounts of network traffic." msgstr "" "Le <emphasis>rafraîchissement intelligent</emphasis> télécharge " "périodiquement les règles qui sont nouvelles ou qui ont été modifiées après " @@ -13859,26 +15169,29 @@ msgstr "" msgid "" "Depending on the IdP product additional platform specific options might " "follow the name separated by a colon (:). E.g. for Keycloak the base URI for " -"the user and group REST API must be given. For Entra ID this is not needed " -"because there is a generic endpoint for all tenants." +"the user and group REST API must be given. For Entra ID the base URI for the " +"Microsoft Graph API can be given to use sovereign or government cloud " +"endpoints instead of the default (https://graph.microsoft.com/v1.0). E.g. " +"<quote>entra_id:https://graph.microsoft.us/v1.0</quote> for the US " +"government cloud (GCC High)." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:78 sssd-idp.5.xml:94 sssd-idp.5.xml:119 +#: sssd-idp.5.xml:82 sssd-idp.5.xml:98 sssd-idp.5.xml:123 #, fuzzy #| msgid "Default: Not set" msgid "Default: Not set (Required)" msgstr "Par défaut : non défini" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:83 +#: sssd-idp.5.xml:87 #, fuzzy #| msgid "ldap_user_uuid (string)" msgid "idp_client_id (string)" msgstr "ldap_user_uuid (chaîne)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:86 +#: sssd-idp.5.xml:90 msgid "" "ID of the IdP client used by SSSD to authenticate users and as a client to " "lookup user and group attributes. This client must offer device " @@ -13887,14 +15200,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:99 +#: sssd-idp.5.xml:103 #, fuzzy #| msgid "ldap_tls_cert (string)" msgid "idp_client_secret (string)" msgstr "ldap_tls_cert (chaîne)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:102 +#: sssd-idp.5.xml:106 msgid "" "Password of the IdP client. The password is required for the id_provider. If " "only used as auth_provider it depends on the server side configuration if it " @@ -13902,76 +15215,83 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:113 +#: sssd-idp.5.xml:117 #, fuzzy #| msgid "ipa_domain (string)" msgid "idp_token_endpoint (string)" msgstr "ipa_domain (chaîne)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:116 +#: sssd-idp.5.xml:120 msgid "IdP endpoint for requesting access tokens." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:124 +#: sssd-idp.5.xml:128 #, fuzzy #| msgid "ldap_service_port (string)" msgid "idp_device_auth_endpoint (string)" msgstr "ldap_service_port (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:127 +#: sssd-idp.5.xml:131 msgid "" "IdP endpoint for device authorization according to RFC-8628. This is " "required for user authentication." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:137 +#: sssd-idp.5.xml:141 #, fuzzy #| msgid "ldap_service_port (string)" msgid "idp_userinfo_endpoint (string)" msgstr "ldap_service_port (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:140 +#: sssd-idp.5.xml:144 msgid "" "IdP userinfo endpoint to request user attributes after a successful " "authentication of the user. Required for authentication." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:150 +#: sssd-idp.5.xml:154 #, fuzzy #| msgid "id_provider (string)" msgid "idp_id_scope (string)" msgstr "id_provider (chaîne)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:153 +#: sssd-idp.5.xml:157 msgid "" "Scope required for looking up user and group attributes with the REST API. " "The scopes are used by the server to determine which attributes/claims are " "returned to the caller." msgstr "" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:163 +msgid "" +"Note: In previous versions of SSSD, this option was expected to already be " +"URL-encoded." +msgstr "" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:164 +#: sssd-idp.5.xml:172 #, fuzzy #| msgid "dyndns_iface (string)" msgid "idp_auth_scope (string)" msgstr "dyndns_iface (chaîne)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:167 +#: sssd-idp.5.xml:175 msgid "" "Scope required during authentication. The scopes are used by the server to " "determine which attributes/claims are returned to the caller." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:172 +#: sssd-idp.5.xml:180 msgid "" "Currently the tokens returned during user authentication are not used for " "other purposes hence the only important claim is the subject identifier " @@ -13980,26 +15300,124 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:185 +#: sssd-idp.5.xml:193 +#, fuzzy +#| msgid "ldap_user_extra_attrs (string)" +msgid "idp_auth_user_identifier_attr (string)" +msgstr "ldap_user_extra_attrs (chaîne)" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:196 +msgid "" +"Attribute used to identify the authenticated user in userinfo data or token " +"claims." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:200 +msgid "" +"For hybrid Active Directory and Entra ID deployments where " +"<quote>id_provider = ad</quote> and <quote>auth_provider = idp</quote>, this " +"option must be set explicitly. No value is derived from the identity " +"provider, because more than one attribute can link an Entra ID object to its " +"on-premises counterpart and only the administrator knows which one the " +"directory synchronization is configured to use." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:211 +msgid "" +"Setting this option to <quote>onPremisesImmutableId</quote> is the usual " +"choice for such deployments. Microsoft Entra Connect populates that " +"attribute with the base64-encoded form of the 16-byte Active Directory " +"<quote>objectGUID</quote> when objectGUID is used as the sourceAnchor. SSSD " +"decodes the value and converts the raw bytes with the same conversion used " +"for AD objectGUID attributes, so the result matches the UUID stored in the " +"SSSD cache for the AD user." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:224 +msgid "" +"Note that Microsoft Entra Connect 1.1.524.0 and later use <quote>ms-DS-" +"ConsistencyGuid</quote> as the sourceAnchor for user objects instead of " +"<quote>objectGUID</quote>. The value is normally copied from objectGUID for " +"objects that do not have it set yet, in which case the decoded identifier " +"still matches. It does not match if ms-DS-ConsistencyGuid was populated " +"independently, if users were moved between forests or domains, or if a " +"different attribute such as employeeID was selected as the sourceAnchor. See " +"<ulink url=\"https://learn.microsoft.com/en-us/entra/identity/hybrid/connect/" +"plan-connect-design-concepts\"> Microsoft Entra Connect: Design concepts</" +"ulink> for details on sourceAnchor selection." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:241 +msgid "" +"Microsoft Graph does not return <quote>onPremisesImmutableId</quote> by " +"default. The <quote>idp_userinfo_endpoint</quote> must request it with " +"<quote>$select</quote>, see the example below and <ulink url=\"https://" +"learn.microsoft.com/en-us/graph/api/resources/user\"> the Microsoft Graph " +"user resource type</ulink>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:251 +msgid "" +"If the configured attribute is missing or cannot be decoded (for example " +"cloud-only Entra ID users without <quote>onPremisesImmutableId</quote>), " +"authentication fails. SSSD does not fall back to another attribute when this " +"option is set." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:258 +msgid "" +"Default: not set, <quote>sub</quote> for Keycloak and <quote>id</quote> for " +"other IdP types" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-idp.5.xml:264 #, fuzzy #| msgid "ldap_opt_timeout (integer)" msgid "idp_request_timeout (integer)" msgstr "ldap_opt_timeout (entier)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:188 +#: sssd-idp.5.xml:267 msgid "Timeout in seconds for an individual request to the IdP." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:197 +#: sssd-idp.5.xml:276 +#, fuzzy +#| msgid "ldap_referrals (boolean)" +msgid "idp_auto_refresh (boolean)" +msgstr "ldap_referrals (booléen)" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:279 +msgid "" +"Refresh tokens automatically, after they have reached about half their " +"lifetime." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:283 +msgid "" +"Note: Scheduled token refreshes are not preserved across restarts of SSSD." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-idp.5.xml:292 #, fuzzy #| msgid "ldap_idmap_range_min (integer)" msgid "idmap_range_min (integer)" msgstr "ldap_idmap_range_min (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:200 +#: sssd-idp.5.xml:295 #, fuzzy #| msgid "" #| "Specifies the lower bound of the range of POSIX IDs to use for mapping " @@ -14013,7 +15431,7 @@ msgstr "" "en correspondance d'identifiants utilisateurs et groupes Active Directory." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:206 +#: sssd-idp.5.xml:301 msgid "" "The interval between <quote>idmap_range_min</quote> and " "<quote>idmap_range_max</quote> will be split into smaller ranges of size " @@ -14022,20 +15440,20 @@ msgid "" msgstr "" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:213 sssd-idp.5.xml:239 include/ldap_id_mapping.xml:139 +#: sssd-idp.5.xml:308 sssd-idp.5.xml:334 include/ldap_id_mapping.xml:139 #: include/ldap_id_mapping.xml:197 msgid "Default: 200000" msgstr "Par défaut : 200000" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:218 +#: sssd-idp.5.xml:313 #, fuzzy #| msgid "ldap_idmap_range_max (integer)" msgid "idmap_range_max (integer)" msgstr "ldap_idmap_range_max (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:221 +#: sssd-idp.5.xml:316 #, fuzzy #| msgid "" #| "Specifies the lower bound of the range of POSIX IDs to use for mapping " @@ -14049,47 +15467,70 @@ msgstr "" "en correspondance d'identifiants utilisateurs et groupes Active Directory." #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:227 include/ldap_id_mapping.xml:165 +#: sssd-idp.5.xml:322 include/ldap_id_mapping.xml:165 msgid "Default: 2000200000" msgstr "Par défaut : 2000200000" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:232 +#: sssd-idp.5.xml:327 #, fuzzy #| msgid "ldap_idmap_range_size (integer)" msgid "idmap_range_size (integer)" msgstr "ldap_idmap_range_size (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:235 +#: sssd-idp.5.xml:330 msgid "Specifies the number of POSIX IDs available for a single IdP domain." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-idp.5.xml:251 +#: sssd-idp.5.xml:346 #, no-wrap msgid "" "[domain/entra_id]\n" "id_provider = idp\n" "idp_type = entra_id\n" "idp_client_id = 12345678-abcd-0101-efef-ba9876543210\n" -"idp_client_secret = YOUR-CLIENT-SCERET\n" -"idp_token_endpoint = https://login.microsoftonline.com/TENNANT-ID/oauth2/v2.0/token\n" +"idp_client_secret = YOUR-CLIENT-SECRET\n" +"idp_token_endpoint = https://login.microsoftonline.com/TENANT-ID/oauth2/v2.0/token\n" "idp_userinfo_endpoint = https://graph.microsoft.com/v1.0/me\n" -"idp_device_auth_endpoint = https://login.microsoftonline.com/TENNANT-ID/oauth2/v2.0/devicecode\n" -"idp_id_scope = https%3A%2F%2Fgraph.microsoft.com%2F.default\n" +"idp_device_auth_endpoint = https://login.microsoftonline.com/TENANT-ID/oauth2/v2.0/devicecode\n" +"idp_id_scope = https://graph.microsoft.com/.default\n" +"idp_auth_scope = openid profile email\n" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><programlisting> +#: sssd-idp.5.xml:358 +#, no-wrap +msgid "" +"[domain/ad.example.com]\n" +"id_provider = ad\n" +"auth_provider = idp\n" +"access_provider = permit\n" +"\n" +"ad_domain = ad.example.com\n" +"krb5_realm = AD.EXAMPLE.COM\n" +"\n" +"idp_type = entra_id\n" +"idp_client_id = 12345678-abcd-0101-efef-ba9876543210\n" +"idp_client_secret = YOUR-CLIENT-SECRET\n" +"idp_token_endpoint = https://login.microsoftonline.com/TENANT-ID/oauth2/v2.0/token\n" +"idp_userinfo_endpoint = https://graph.microsoft.com/v1.0/me?$select=id,userPrincipalName,onPremisesImmutableId\n" +"idp_device_auth_endpoint = https://login.microsoftonline.com/TENANT-ID/oauth2/v2.0/devicecode\n" +"idp_id_scope = https://graph.microsoft.com/.default\n" "idp_auth_scope = openid profile email\n" +"idp_auth_user_identifier_attr = onPremisesImmutableId\n" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-idp.5.xml:263 +#: sssd-idp.5.xml:377 #, no-wrap msgid "" "[domain/keycloak]\n" "idp_type = keycloak:https://master.keycloak.test:8443/auth/admin/realms/master/\n" "id_provider = idp\n" "idp_client_id = myclient\n" -"idp_client_secret = YOUR-CLIENT-SCERET\n" +"idp_client_secret = YOUR-CLIENT-SECRET\n" "idp_token_endpoint = https://master.keycloak.test:8443/auth/realms/master/protocol/openid-connect/token\n" "idp_userinfo_endpoint = https://master.keycloak.test:8443/auth/realms/master/protocol/openid-connect/userinfo\n" "idp_device_auth_endpoint = https://master.keycloak.test:8443/auth/realms/master/protocol/openid-connect/auth/device\n" @@ -14098,14 +15539,26 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-idp.5.xml:250 +#: sssd-idp.5.xml:345 #, fuzzy #| msgid "example: <placeholder type=\"programlisting\" id=\"0\"/>" msgid "" "<placeholder type=\"programlisting\" id=\"0\"/> <placeholder " -"type=\"programlisting\" id=\"1\"/>" +"type=\"programlisting\" id=\"1\"/> <placeholder type=\"programlisting\" " +"id=\"2\"/>" msgstr "exemple : <placeholder type=\"programlisting\" id=\"0\"/>" +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-idp.5.xml:390 +msgid "" +"In the hybrid Active Directory and Entra ID example above, " +"<quote>onPremisesImmutableId</quote> is used during authentication so the " +"IdP result matches the AD objectGUID UUID stored in the SSSD cache. The " +"attribute must be requested via <quote>$select</quote> on the Graph userinfo " +"endpoint and is only populated for users synchronized from Active Directory " +"with objectGUID as the sourceAnchor." +msgstr "" + #. type: Content of: <reference><refentry><refnamediv><refname> #: sssd.8.xml:10 sssd.8.xml:15 msgid "sssd" @@ -15172,9 +16625,13 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:291 +#, fuzzy +#| msgid "" +#| "<emphasis>demand</emphasis> to use FAST. The authentication fails if the " +#| "server does not require fast." msgid "" "<emphasis>demand</emphasis> to use FAST. The authentication fails if the " -"server does not require fast." +"server does not support FAST." msgstr "" "<emphasis>demander</emphasis>  : imposer d'utiliser FAST. L'authentification " "échoue si le serveur ne requiert pas FAST." @@ -16172,8 +17629,10 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sss_rpcidmapd.5.xml:69 -msgid "memcache (bool)" -msgstr "" +#, fuzzy +#| msgid "ad_enable_gc (boolean)" +msgid "memcache (boolean)" +msgstr "ad_enable_gc (booléen)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sss_rpcidmapd.5.xml:72 @@ -16238,7 +17697,7 @@ msgid "" msgstr "" #. type: Content of: <refsect1><title> -#: sss_rpcidmapd.5.xml:120 sssd-kcm.8.xml:316 include/seealso.xml:2 +#: sss_rpcidmapd.5.xml:120 sssd-kcm.8.xml:315 include/seealso.xml:2 msgid "SEE ALSO" msgstr "VOIR AUSSI" @@ -16524,8 +17983,8 @@ msgstr "" #: sss_ssh_knownhosts.1.xml:93 msgid "" "The key lines retrieved from the backend are expected to respect the key " -"format as decribed in the <quote>SSH_KNOWN_HOSTS FILE FORMAT</quote> section " -"of <citerefentry><refentrytitle>sshd</refentrytitle> <manvolnum>8</" +"format as described in the <quote>SSH_KNOWN_HOSTS FILE FORMAT</quote> " +"section of <citerefentry><refentrytitle>sshd</refentrytitle> <manvolnum>8</" "manvolnum></citerefentry>. However, returning only the keytype and the key " "itself is tolerated, in which case, the hostname received as parameter will " "be added before the keytype to output a correctly formatted line. The " @@ -17006,15 +18465,22 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-kcm.8.xml:215 +#, fuzzy +#| msgid "" +#| "Please refer to the <quote>dns_discovery_domain</quote> parameter in the " +#| "<citerefentry> <refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</" +#| "manvolnum> </citerefentry> manual page for more details." msgid "" -"The KCM service is configured in the <quote>kcm</quote> For a detailed " -"syntax reference, refer to the <quote>FILE FORMAT</quote> section of the " -"<citerefentry> <refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</" -"manvolnum> </citerefentry> manual page." +"For a detailed syntax reference, refer to the <quote>FILE FORMAT</quote> " +"section of the <citerefentry> <refentrytitle>sssd.conf</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry> manual page." msgstr "" +"Se reporter au paramètre <quote>dns_discovery_domain</quote> dans la page de " +"manuel <citerefentry><refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</" +"manvolnum></citerefentry> pour plus de détails." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-kcm.8.xml:223 +#: sssd-kcm.8.xml:222 msgid "" "The generic SSSD service options such as <quote>debug_level</quote> or " "<quote>fd_limit</quote> are accepted by the kcm service. Please refer to " @@ -17024,22 +18490,22 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:234 +#: sssd-kcm.8.xml:233 msgid "socket_path (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:237 +#: sssd-kcm.8.xml:236 msgid "The socket the KCM service will listen on." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:240 +#: sssd-kcm.8.xml:239 msgid "Default: <replaceable>/var/run/.heim_org.h5l.kcm-socket</replaceable>" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:243 +#: sssd-kcm.8.xml:242 msgid "" "<phrase condition=\"have_systemd\"> Note: on platforms where systemd is " "supported, the socket path is overwritten by the one defined in the sssd-" @@ -17047,94 +18513,94 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:252 +#: sssd-kcm.8.xml:251 msgid "max_ccaches (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:255 +#: sssd-kcm.8.xml:254 msgid "How many credential caches does the KCM database allow for all users." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:259 +#: sssd-kcm.8.xml:258 msgid "Default: 0 (unlimited, only the per-UID quota is enforced)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:264 +#: sssd-kcm.8.xml:263 msgid "max_uid_ccaches (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:267 +#: sssd-kcm.8.xml:266 msgid "" "How many credential caches does the KCM database allow per UID. This is " "equivalent to <quote>with how many principals you can kinit</quote>." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:272 +#: sssd-kcm.8.xml:271 msgid "Default: 64" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:277 +#: sssd-kcm.8.xml:276 msgid "max_ccache_size (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:280 +#: sssd-kcm.8.xml:279 msgid "" -"How big can a credential cache be per ccache. Each service ticket accounts " -"into this quota." +"How big a credential cache be per ccache. Each service ticket counts toward " +"this quota." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:284 +#: sssd-kcm.8.xml:283 msgid "Default: 65536" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:289 +#: sssd-kcm.8.xml:288 #, fuzzy #| msgid "enumerate (bool)" -msgid "tgt_renewal (bool)" +msgid "tgt_renewal (boolean)" msgstr "enumerate (booléen)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:292 +#: sssd-kcm.8.xml:291 msgid "Enables TGT renewals functionality." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:295 +#: sssd-kcm.8.xml:294 #, fuzzy #| msgid "Default: False (disabled)" msgid "Default: False (Automatic renewals disabled)" msgstr "Par défaut : False (désactivé)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:300 +#: sssd-kcm.8.xml:299 #, fuzzy #| msgid "krb5_renew_interval (string)" msgid "tgt_renewal_inherit (string)" msgstr "krb5_renew_interval (chaîne)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:303 +#: sssd-kcm.8.xml:302 msgid "Domain to inherit krb5_* options from, for use with TGT renewals." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:307 +#: sssd-kcm.8.xml:306 #, fuzzy #| msgid "Default: 3" msgid "Default: NULL" msgstr "Par défaut : 3" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-kcm.8.xml:318 +#: sssd-kcm.8.xml:317 msgid "" "<citerefentry> <refentrytitle>sssd</refentrytitle><manvolnum>8</manvolnum> </" "citerefentry>, <citerefentry> <refentrytitle>sssd.conf</" @@ -18089,9 +19555,9 @@ msgstr "" "détermine si l'accès est autorisé ou non." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap-attributes.5.xml:381 sssd-ldap-attributes.5.xml:395 -msgid "Default: loginDisabled" -msgstr "Par défaut : loginDisabled" +#: sssd-ldap-attributes.5.xml:381 +msgid "Default: loginDisabled (rfc2307, rfc2307bis and IPA), not set (AD)" +msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:387 @@ -18107,6 +19573,12 @@ msgstr "" "Lors de l'utilisation de ldap_account_expire_policy=nds, cet attribut " "détermine jusqu'à quand l'accès est autorisé." +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:395 +msgid "" +"Default: loginExpirationTime (rfc2307, rfc2307bis and IPA), not set (AD)" +msgstr "" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:401 msgid "ldap_user_nds_login_allowed_time_map (string)" @@ -18124,8 +19596,9 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:409 -msgid "Default: loginAllowedTimeMap" -msgstr "Par défaut : loginAllowedTimeMap" +msgid "" +"Default: loginAllowedTimeMap (rfc2307, rfc2307bis and IPA), not set (AD)" +msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:415 @@ -18688,9 +20161,9 @@ msgid "The object class of a host entry in LDAP." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap-attributes.5.xml:900 sssd-ldap-attributes.5.xml:997 -msgid "Default: ipService" -msgstr "Par défaut : ipService" +#: sssd-ldap-attributes.5.xml:900 sssd-ldap-attributes.5.xml:1213 +msgid "Default: ipHost" +msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:906 @@ -18774,6 +20247,11 @@ msgstr "ldap_service_object_class (chaîne)" msgid "The object class of a service entry in LDAP." msgstr "La classe d'objet d'une entrée de service LDAP." +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:997 +msgid "Default: ipService" +msgstr "Par défaut : ipService" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1003 msgid "ldap_service_name (string)" @@ -19028,11 +20506,6 @@ msgstr "" msgid "The object class of an iphost entry in LDAP." msgstr "" -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap-attributes.5.xml:1213 -msgid "Default: ipHost" -msgstr "" - #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1219 msgid "ldap_iphost_name (string)" @@ -19284,6 +20757,7 @@ msgstr "FICHIER DE CONFIGURATION" msgid "" "[plugins]\n" " localauth = {\n" +" disable = an2ln\n" " module = sssd:/usr/lib64/sssd/modules/sssd_krb5_localauth_plugin.so\n" " }\n" msgstr "" @@ -19300,6 +20774,28 @@ msgid "" "the local Kerberos configuration the plugin will be enabled automatically." msgstr "" +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_localauth_plugin.8.xml:67 +msgid "" +"This configuration snippet also disables the <command>an2ln</command> module " +"provided by MIT Kerberos if SSSD is configured to use the AD or IPA " +"provider. In those environments <command>sssd_krb5_localauth_plugin</" +"command> can reliably map the system user names to Kerberos principals. A " +"fallback to <command>an2ln</command> might cause issues in environments " +"where users have the privilege to create Kerberos principals on their own " +"which might collide with names of other users used in the system. Other " +"modules provided by MIT Kerberos, e.g. <command>k5login</command> are not " +"affected." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_localauth_plugin.8.xml:79 +msgid "" +"Note: If using <quote>auth_provider = krb5</quote> then " +"<command>sssd_krb5_localauth_plugin</command> is not used, therefore the " +"above text is not applicable." +msgstr "" + #. type: Content of: <variablelist><varlistentry><term> #: include/autofs_attributes.xml:3 msgid "ldap_autofs_map_object_class (string)" @@ -20323,40 +21819,6 @@ msgid "" "failures; corresponds to setting 2 in decimal notation)" msgstr "" -#. type: Content of: <refsect1><title> -#: include/local.xml:2 -msgid "THE LOCAL DOMAIN" -msgstr "LE DOMAINE LOCAL" - -#. type: Content of: <refsect1><para> -#: include/local.xml:4 -msgid "" -"In order to function correctly, a domain with <quote>id_provider=local</" -"quote> must be created and the SSSD must be running." -msgstr "" -"Pour fonctionner correctement, un domaine avec <quote>id_provider = local</" -"quote> doit être créé et SSSD doit s'exécuter." - -#. type: Content of: <refsect1><para> -#: include/local.xml:9 -msgid "" -"The administrator might want to use the SSSD local users instead of " -"traditional UNIX users in cases where the group nesting (see <citerefentry> " -"<refentrytitle>sss_groupadd</refentrytitle> <manvolnum>8</manvolnum> </" -"citerefentry>) is needed. The local users are also useful for testing and " -"development of the SSSD without having to deploy a full remote server. The " -"<command>sss_user*</command> and <command>sss_group*</command> tools use a " -"local LDB storage to store users and groups." -msgstr "" -"L'administrateur peut vouloir utiliser les utilisateurs locaux SSSD au lieu " -"des utilisateurs UNIX traditionnels dans les cas où l'imbrication de groupes " -"(cf. <citerefentry><refentrytitle>sss_groupadd</refentrytitle> <manvolnum>8</" -"manvolnum></citerefentry>) est nécessaire. Les utilisateurs locaux sont " -"également utiles pour les tests et le développement de SSSD sans avoir à " -"déployer un serveur distant complet. Les outils <command>sss_user *</" -"command> et <command>sss_group *</command> utilisent alors un stockage local " -"de type LDB pour les utilisateurs et les groupes." - #. type: Content of: <refsect1><para> #: include/seealso.xml:4 msgid "" @@ -21027,6 +22489,99 @@ msgstr "" "rendus canoniques. Cette fonctionnalité est disponible avec MIT Kerberos 1.7 " "et versions suivantes." +#~ msgid "" +#~ "The data types used are string (no quotes needed), integer and bool (with " +#~ "values of <quote>TRUE/FALSE</quote>)." +#~ msgstr "" +#~ "Les types de données utilisées sont des chaînes (pas de guillemets " +#~ "nécessaires), des entiers et des booléens (ayant pour valeur <quote>TRUE/" +#~ "FALSE</quote>)." + +#~ msgid "services" +#~ msgstr "services" + +#~ msgid "domains" +#~ msgstr "domaines" + +#~ msgid "fd_limit" +#~ msgstr "fd_limit" + +#~ msgid "client_idle_timeout" +#~ msgstr "client_idle_timeout" + +#~ msgid "default_shell" +#~ msgstr "default_shell" + +#, fuzzy +#~| msgid "This option can also be set per-domain." +#~ msgid "" +#~ "Note: This option can also be set per-domain which overwrites the value " +#~ "in [nss] section." +#~ msgstr "Cette option peut aussi être définie pour chaque domaine." + +#~ msgid "" +#~ "Default: <quote>id_provider</quote> is used if it is set and can handle " +#~ "selinux loading requests." +#~ msgstr "" +#~ "Par défaut : <quote>id_provider</quote> est utilisé s'il est défini et " +#~ "peut gérer le chargement selinux" + +#~ msgid "" +#~ "NOTE: On older systems (such as RHEL 5), for this behavior to work " +#~ "reliably, the default Kerberos realm must be set properly in /etc/" +#~ "krb5.conf" +#~ msgstr "" +#~ "NOTE : Sur les systèmes plus anciens (tels que RHEL 5), afin que ce " +#~ "comportement fonctionne de façon fiable, le domaine Kerberos par défaut " +#~ "doit être défini correctement dans /etc/krb5.conf" + +#~ msgid "ipa_hbac_selinux (integer)" +#~ msgstr "ipa_hbac_selinux (entier)" + +#~ msgid "" +#~ "NOTE: While it is still possible to use the old " +#~ "<emphasis>ipa_dyndns_iface</emphasis> option, users should migrate to " +#~ "using <emphasis>dyndns_iface</emphasis> in their config file." +#~ msgstr "" +#~ "REMARQUE : Bien qu'il soit toujours possible d'utiliser l'ancienne option " +#~ "<emphasis>ipa_dyndns_iface</emphasis>, les utilisateurs doivent " +#~ "maintenant utiliser <emphasis>dyndns_iface</emphasis> dans leur fichier " +#~ "de configuration." + +#~ msgid "Default: loginDisabled" +#~ msgstr "Par défaut : loginDisabled" + +#~ msgid "Default: loginAllowedTimeMap" +#~ msgstr "Par défaut : loginAllowedTimeMap" + +#~ msgid "THE LOCAL DOMAIN" +#~ msgstr "LE DOMAINE LOCAL" + +#~ msgid "" +#~ "In order to function correctly, a domain with <quote>id_provider=local</" +#~ "quote> must be created and the SSSD must be running." +#~ msgstr "" +#~ "Pour fonctionner correctement, un domaine avec <quote>id_provider = " +#~ "local</quote> doit être créé et SSSD doit s'exécuter." + +#~ msgid "" +#~ "The administrator might want to use the SSSD local users instead of " +#~ "traditional UNIX users in cases where the group nesting (see " +#~ "<citerefentry> <refentrytitle>sss_groupadd</refentrytitle> <manvolnum>8</" +#~ "manvolnum> </citerefentry>) is needed. The local users are also useful " +#~ "for testing and development of the SSSD without having to deploy a full " +#~ "remote server. The <command>sss_user*</command> and <command>sss_group*</" +#~ "command> tools use a local LDB storage to store users and groups." +#~ msgstr "" +#~ "L'administrateur peut vouloir utiliser les utilisateurs locaux SSSD au " +#~ "lieu des utilisateurs UNIX traditionnels dans les cas où l'imbrication de " +#~ "groupes (cf. <citerefentry><refentrytitle>sss_groupadd</refentrytitle> " +#~ "<manvolnum>8</manvolnum></citerefentry>) est nécessaire. Les utilisateurs " +#~ "locaux sont également utiles pour les tests et le développement de SSSD " +#~ "sans avoir à déployer un serveur distant complet. Les outils " +#~ "<command>sss_user *</command> et <command>sss_group *</command> utilisent " +#~ "alors un stockage local de type LDB pour les utilisateurs et les groupes." + #~ msgid "subdomain_enumerate (string)" #~ msgstr "subdomain_enumerate (chaîne)" @@ -21121,9 +22676,6 @@ msgstr "" #~ msgid "This option is deprecated." #~ msgstr "Cette option peut aussi être définie pour chaque domaine." -#~ msgid "user (string)" -#~ msgstr "user (chaîne)" - #~ msgid "Default: not set, process will run as root" #~ msgstr "Par défaut : non défini, le processus tourne en tant que root" @@ -21392,9 +22944,6 @@ msgstr "" #~ "utilisateurs et les groupes dans la base de données native SSSD, c'est-à-" #~ "dire un domaine qui utilise <replaceable>id_provider=local</replaceable>." -#~ msgid "default_shell (string)" -#~ msgstr "default_shell (chaîne)" - #~ msgid "The default shell for users created with SSSD userspace tools." #~ msgstr "" #~ "L'interpréteur de commandes par défaut pour les utilisateurs créés avec " @@ -21403,9 +22952,6 @@ msgstr "" #~ msgid "Default: <filename>/bin/bash</filename>" #~ msgstr "Par défaut : <filename>/bin/bash</filename>" -#~ msgid "base_directory (string)" -#~ msgstr "base_directory (chaîne)" - #~ msgid "" #~ "The tools append the login name to <replaceable>base_directory</" #~ "replaceable> and use that as the home directory." diff --git a/src/man/po/hu.po b/src/man/po/hu.po index aeeb5024a5e..917c49028f7 100644 --- a/src/man/po/hu.po +++ b/src/man/po/hu.po @@ -8,7 +8,7 @@ msgstr "" "Project-Id-Version: sssd-docs 2.12.0\n" "Report-Msgid-Bugs-To: sssd-devel@redhat.com\n" "POT-Creation-Date: 2026-01-14 15:00+0000\n" -"PO-Revision-Date: 2026-04-23 16:54+0000\n" +"PO-Revision-Date: 2026-10-05 17:20+0000\n" "Last-Translator: Anonymous <noreply@weblate.org>\n" "Language-Team: Hungarian <https://translate.fedoraproject.org/projects/sssd/" "sssd-manpage-master/hu/>\n" @@ -17,7 +17,7 @@ msgstr "" "Content-Type: text/plain; charset=UTF-8\n" "Content-Transfer-Encoding: 8bit\n" "Plural-Forms: nplurals=2; plural=n != 1;\n" -"X-Generator: Weblate 5.17\n" +"X-Generator: Weblate 2026.10\n" #. type: Content of: <reference><title> #: sssd.conf.5.xml:8 sssd-ldap.5.xml:5 pam_sss.8.xml:5 pam_sss_gss.8.xml:5 diff --git a/src/man/po/id.po b/src/man/po/id.po index ccf55f9090f..b2151875136 100644 --- a/src/man/po/id.po +++ b/src/man/po/id.po @@ -8,7 +8,7 @@ msgstr "" "Project-Id-Version: sssd-docs 2.12.0\n" "Report-Msgid-Bugs-To: sssd-devel@redhat.com\n" "POT-Creation-Date: 2026-01-14 15:00+0000\n" -"PO-Revision-Date: 2026-04-23 17:03+0000\n" +"PO-Revision-Date: 2026-10-05 17:22+0000\n" "Last-Translator: Anonymous <noreply@weblate.org>\n" "Language-Team: Indonesian <https://translate.fedoraproject.org/projects/sssd/" "sssd-manpage-master/id/>\n" @@ -17,7 +17,7 @@ msgstr "" "Content-Type: text/plain; charset=UTF-8\n" "Content-Transfer-Encoding: 8bit\n" "Plural-Forms: nplurals=1; plural=0;\n" -"X-Generator: Weblate 5.17\n" +"X-Generator: Weblate 2026.10\n" #. type: Content of: <reference><title> #: sssd.conf.5.xml:8 sssd-ldap.5.xml:5 pam_sss.8.xml:5 pam_sss_gss.8.xml:5 diff --git a/src/man/po/it.po b/src/man/po/it.po index aa7c4f301f0..ee864e99d31 100644 --- a/src/man/po/it.po +++ b/src/man/po/it.po @@ -8,7 +8,7 @@ msgstr "" "Project-Id-Version: sssd-docs 2.12.0\n" "Report-Msgid-Bugs-To: sssd-devel@redhat.com\n" "POT-Creation-Date: 2026-01-14 15:00+0000\n" -"PO-Revision-Date: 2026-04-23 16:24+0000\n" +"PO-Revision-Date: 2026-10-05 17:23+0000\n" "Last-Translator: Weblate Translation Memory <noreply-mt-weblate-translation-" "memory@weblate.org>\n" "Language-Team: Italian <https://translate.fedoraproject.org/projects/sssd/" @@ -18,7 +18,7 @@ msgstr "" "Content-Type: text/plain; charset=UTF-8\n" "Content-Transfer-Encoding: 8bit\n" "Plural-Forms: nplurals=2; plural=n != 1;\n" -"X-Generator: Weblate 5.17\n" +"X-Generator: Weblate 2026.10\n" #. type: Content of: <reference><title> #: sssd.conf.5.xml:8 sssd-ldap.5.xml:5 pam_sss.8.xml:5 pam_sss_gss.8.xml:5 diff --git a/src/man/po/ja.po b/src/man/po/ja.po index 3c7f225dae0..def34c89eed 100644 --- a/src/man/po/ja.po +++ b/src/man/po/ja.po @@ -12,8 +12,8 @@ msgid "" msgstr "" "Project-Id-Version: sssd-docs 2.3.0\n" "Report-Msgid-Bugs-To: sssd-devel@redhat.com\n" -"POT-Creation-Date: 2026-01-14 15:00+0000\n" -"PO-Revision-Date: 2026-04-23 16:26+0000\n" +"POT-Creation-Date: 2026-10-05 16:14+0000\n" +"PO-Revision-Date: 2026-10-05 16:57+0000\n" "Last-Translator: Ludek Janda <ljanda@redhat.com>\n" "Language-Team: Japanese <https://translate.fedoraproject.org/projects/sssd/" "sssd-manpage-master/ja/>\n" @@ -22,10 +22,10 @@ msgstr "" "Content-Type: text/plain; charset=UTF-8\n" "Content-Transfer-Encoding: 8bit\n" "Plural-Forms: nplurals=1; plural=0;\n" -"X-Generator: Weblate 5.17\n" +"X-Generator: Weblate 2026.10\n" #. type: Content of: <reference><title> -#: sssd.conf.5.xml:8 sssd-ldap.5.xml:5 pam_sss.8.xml:5 pam_sss_gss.8.xml:5 +#: sssd.conf.5.xml:10 sssd-ldap.5.xml:5 pam_sss.8.xml:5 pam_sss_gss.8.xml:5 #: sssd_krb5_locator_plugin.8.xml:5 sssd-simple.5.xml:5 sss-certmap.5.xml:5 #: sssd-ipa.5.xml:5 sssd-ad.5.xml:5 sssd-sudo.5.xml:5 sssd-idp.5.xml:5 #: sssd.8.xml:5 sss_obfuscate.8.xml:5 sss_override.8.xml:5 sssd-krb5.5.xml:5 @@ -38,12 +38,12 @@ msgid "SSSD Manual pages" msgstr "SSSD マニュアル ページ" #. type: Content of: <reference><refentry><refnamediv><refname> -#: sssd.conf.5.xml:13 sssd.conf.5.xml:19 +#: sssd.conf.5.xml:15 sssd.conf.5.xml:21 msgid "sssd.conf" msgstr "sssd.conf" #. type: Content of: <reference><refentry><refmeta><manvolnum> -#: sssd.conf.5.xml:14 sssd-ldap.5.xml:11 sssd-simple.5.xml:11 +#: sssd.conf.5.xml:16 sssd-ldap.5.xml:11 sssd-simple.5.xml:11 #: sss-certmap.5.xml:11 sssd-ipa.5.xml:11 sssd-ad.5.xml:11 sssd-sudo.5.xml:11 #: sssd-idp.5.xml:11 sssd-krb5.5.xml:11 sssd-ifp.5.xml:11 #: sss_rpcidmapd.5.xml:27 sssd-session-recording.5.xml:11 @@ -52,7 +52,7 @@ msgid "5" msgstr "5" #. type: Content of: <reference><refentry><refmeta><refmiscinfo> -#: sssd.conf.5.xml:15 sssd-ldap.5.xml:12 sssd-simple.5.xml:12 +#: sssd.conf.5.xml:17 sssd-ldap.5.xml:12 sssd-simple.5.xml:12 #: sss-certmap.5.xml:12 sssd-ipa.5.xml:12 sssd-ad.5.xml:12 sssd-sudo.5.xml:12 #: sssd-idp.5.xml:12 sssd-krb5.5.xml:12 sssd-ifp.5.xml:12 #: sss_rpcidmapd.5.xml:28 sssd-session-recording.5.xml:12 sssd-kcm.8.xml:12 @@ -61,17 +61,17 @@ msgid "File Formats and Conventions" msgstr "ファイル形式および変換" #. type: Content of: <reference><refentry><refnamediv><refpurpose> -#: sssd.conf.5.xml:20 +#: sssd.conf.5.xml:22 msgid "the configuration file for SSSD" msgstr "SSSD の設定ファイル" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:24 +#: sssd.conf.5.xml:26 msgid "FILE FORMAT" msgstr "ファイルフォーマット" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd.conf.5.xml:32 +#: sssd.conf.5.xml:34 #, no-wrap msgid "" "<replaceable>[section]</replaceable>\n" @@ -81,7 +81,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:27 +#: sssd.conf.5.xml:29 msgid "" "The file has an ini-style syntax and consists of sections and parameters. A " "section begins with the name of the section in square brackets and continues " @@ -94,23 +94,24 @@ msgstr "" "type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:39 +#: sssd.conf.5.xml:41 msgid "" -"The data types used are string (no quotes needed), integer and bool (with " -"values of <quote>TRUE/FALSE</quote>)." +"The data types used are string (no quotes needed), integer and boolean (with " +"values of <quote>TRUE/FALSE</quote>). Boolean values are case-insensitive; " +"for example, <quote>TRUE</quote>, <quote>True</quote> and <quote>true</" +"quote> are all equivalent and valid; the same applies to <quote>FALSE</" +"quote>." msgstr "" -"使用されるデータ形式は、文字列(引用符は不要)、整数および論理値(<quote>" -"TRUE/FALSE</quote> の値)です。" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:44 +#: sssd.conf.5.xml:49 msgid "" "A comment line starts with a hash sign (<quote>#</quote>) or a semicolon " "(<quote>;</quote>). Inline comments are not supported." msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:50 +#: sssd.conf.5.xml:55 msgid "" "All sections can have an optional <replaceable>description</replaceable> " "parameter. Its function is only as a label for the section." @@ -119,7 +120,7 @@ msgstr "" "パラメーターを持てます。その機能はセクションのラベルとしてのみです。" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:56 +#: sssd.conf.5.xml:61 #, fuzzy #| msgid "" #| "<filename>sssd.conf</filename> must be a regular file, owned by root and " @@ -132,7 +133,7 @@ msgstr "" "きる、通常のファイルである必要があります。" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:60 +#: sssd.conf.5.xml:65 #, fuzzy #| msgid "" #| "<filename>sssd.conf</filename> must be a regular file, owned by root and " @@ -145,12 +146,12 @@ msgstr "" "きる、通常のファイルである必要があります。" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:66 +#: sssd.conf.5.xml:71 msgid "CONFIGURATION SNIPPETS FROM INCLUDE DIRECTORY" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:69 +#: sssd.conf.5.xml:74 msgid "" "The configuration file <filename>sssd.conf</filename> will include " "configuration snippets using the include directory <filename>conf.d</" @@ -158,7 +159,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:75 +#: sssd.conf.5.xml:80 msgid "" "Any file placed in <filename>conf.d</filename> that ends in " "<quote><filename>.conf</filename></quote> and does not begin with a dot " @@ -167,7 +168,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:83 +#: sssd.conf.5.xml:88 msgid "" "The configuration snippets from <filename>conf.d</filename> have higher " "priority than <filename>sssd.conf</filename> and will override " @@ -180,39 +181,92 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:97 +#: sssd.conf.5.xml:102 msgid "" "The snippet files require the same owner and permissions as " "<filename>sssd.conf</filename>." msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:103 +#: sssd.conf.5.xml:108 +#, fuzzy +#| msgid "CONFIGURATION OPTIONS" +msgid "VENDOR PROVIDED CONFIGURATION" +msgstr "設定オプション" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:111 +msgid "" +"The vendor provided configuration file is installed in " +"<filename>&sssd_vendor_dir;/sssd.conf</filename>, but this file must not be " +"directly edited. It can be completely masked by creating the system specific " +"configuration file <filename>&sssd_conf_dir;/sssd.conf</filename>, or partly " +"overriden by creating config snippets in <filename>&sssd_conf_dir;/conf.d</" +"filename> directory." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><title> +#: sssd.conf.5.xml:120 +#, fuzzy +#| msgid "CONFIGURATION OPTIONS" +msgid "CONFIGURATION FILE HIERARCHY" +msgstr "設定オプション" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:122 +msgid "" +"When sssd reads the configuration it first tries to open the system specific " +"configuration file in <filename>&sssd_conf_dir;/sssd.conf</filename>. If it " +"exists, it is loaded and snippets from <filename>&sssd_conf_dir;/conf.d</" +"filename> are applied. The vendor provided configuration file " +"<filename>&sssd_vendor_dir;/sssd.conf</filename> is completely ignored in " +"this case." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:131 +msgid "" +"If the system specific configuration file <filename>&sssd_conf_dir;/" +"sssd.conf</filename> does not exist, then the vendor configuration file " +"<filename>&sssd_vendor_dir;/sssd.conf</filename> is loaded and snippets from " +"<filename>&sssd_conf_dir;/conf.d</filename> are applied." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd.conf.5.xml:141 msgid "GENERAL OPTIONS" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:105 +#: sssd.conf.5.xml:143 msgid "Following options are usable in more than one configuration sections." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:109 +#: sssd.conf.5.xml:147 msgid "Options usable in all sections" msgstr "" +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:149 +msgid "" +"Note: Below options are ignored in <quote>[session_recording]</quote> " +"section, see <quote>Session recording configuration options</quote> section " +"for more details." +msgstr "" + #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:113 +#: sssd.conf.5.xml:156 msgid "debug_level (integer)" msgstr "debug_level (整数)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:117 +#: sssd.conf.5.xml:160 msgid "debug (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:120 +#: sssd.conf.5.xml:163 msgid "" "SSSD 1.14 and later also includes the <replaceable>debug</replaceable> alias " "for <replaceable>debug_level</replaceable> as a convenience feature. If both " @@ -221,63 +275,67 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:130 -msgid "debug_timestamps (bool)" +#: sssd.conf.5.xml:173 +#, fuzzy +#| msgid "debug_timestamps (bool)" +msgid "debug_timestamps (boolean)" msgstr "debug_timestamps (論理値)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:133 +#: sssd.conf.5.xml:176 msgid "" "Add a timestamp to the debug messages. If journald is enabled for SSSD " "debug logging this option is ignored." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:138 sssd.conf.5.xml:175 sssd.conf.5.xml:337 -#: sssd.conf.5.xml:644 sssd.conf.5.xml:668 sssd.conf.5.xml:875 -#: sssd.conf.5.xml:979 sssd.conf.5.xml:2113 sssd-ldap.5.xml:979 -#: sssd-ldap.5.xml:1134 sssd-ldap.5.xml:1237 sssd-ldap.5.xml:1306 -#: sssd-ldap.5.xml:1714 sssd-ldap.5.xml:1848 sssd-ldap.5.xml:1913 -#: sssd-ipa.5.xml:346 sssd-ad.5.xml:252 sssd-ad.5.xml:367 sssd-ad.5.xml:1180 -#: sssd-ad.5.xml:1382 sssd-krb5.5.xml:358 +#: sssd.conf.5.xml:181 sssd.conf.5.xml:218 sssd.conf.5.xml:380 +#: sssd.conf.5.xml:687 sssd.conf.5.xml:711 sssd.conf.5.xml:827 +#: sssd.conf.5.xml:932 sssd.conf.5.xml:2149 sssd.conf.5.xml:4730 +#: sssd-ldap.5.xml:979 sssd-ldap.5.xml:1134 sssd-ldap.5.xml:1237 +#: sssd-ldap.5.xml:1306 sssd-ldap.5.xml:1714 sssd-ldap.5.xml:1848 +#: sssd-ldap.5.xml:1913 sssd-ipa.5.xml:341 sssd-ad.5.xml:252 sssd-ad.5.xml:367 +#: sssd-ad.5.xml:1180 sssd-ad.5.xml:1375 sssd-krb5.5.xml:358 msgid "Default: true" msgstr "初期値: true" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:143 -msgid "debug_microseconds (bool)" +#: sssd.conf.5.xml:186 +#, fuzzy +#| msgid "debug_microseconds (bool)" +msgid "debug_microseconds (boolean)" msgstr "debug_microseconds (論理値)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:146 +#: sssd.conf.5.xml:189 msgid "" "Add microseconds to the timestamp in debug messages. If journald is enabled " "for SSSD debug logging this option is ignored." msgstr "" #. type: Content of: <variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:151 sssd.conf.5.xml:2040 sssd.conf.5.xml:4158 +#: sssd.conf.5.xml:194 sssd.conf.5.xml:2072 sssd.conf.5.xml:4363 #: sssd-ldap.5.xml:363 sssd-ldap.5.xml:998 sssd-ldap.5.xml:1209 -#: sssd-ldap.5.xml:1663 sssd-ldap.5.xml:1937 sssd-ipa.5.xml:146 -#: sssd-ipa.5.xml:706 sssd-ad.5.xml:1135 sssd-krb5.5.xml:268 +#: sssd-ldap.5.xml:1663 sssd-ldap.5.xml:1937 sssd-ipa.5.xml:141 +#: sssd-ipa.5.xml:701 sssd-ad.5.xml:1140 sssd-idp.5.xml:287 sssd-krb5.5.xml:268 #: sssd-krb5.5.xml:330 sssd-krb5.5.xml:432 include/krb5_options.xml:163 msgid "Default: false" msgstr "初期値: false" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:156 +#: sssd.conf.5.xml:199 #, fuzzy #| msgid "debug_microseconds (bool)" -msgid "debug_backtrace_enabled (bool)" +msgid "debug_backtrace_enabled (boolean)" msgstr "debug_microseconds (論理値)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:159 +#: sssd.conf.5.xml:202 msgid "Enable debug backtrace." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:162 +#: sssd.conf.5.xml:205 msgid "" "In case SSSD is run with debug_level less than 9, everything is logged to a " "ring buffer in memory and flushed to a log file on any error up to and " @@ -287,14 +345,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:171 +#: sssd.conf.5.xml:214 msgid "" "Feature is only supported for `logger == files` (i.e. setting doesn't have " "effect for other logger types)." msgstr "" #. type: Content of: outside any tag (error?) -#: sssd.conf.5.xml:111 sssd.conf.5.xml:186 sssd-ldap.5.xml:1754 +#: sssd.conf.5.xml:154 sssd.conf.5.xml:229 sssd-ldap.5.xml:1754 #: sssd-ldap.5.xml:1960 sss-certmap.5.xml:645 sssd-systemtap.5.xml:82 #: sssd-systemtap.5.xml:143 sssd-systemtap.5.xml:236 sssd-systemtap.5.xml:274 #: sssd-systemtap.5.xml:330 sssd-ldap-attributes.5.xml:40 @@ -307,17 +365,17 @@ msgid "<placeholder type=\"variablelist\" id=\"0\"/>" msgstr "<placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:184 +#: sssd.conf.5.xml:227 msgid "Options usable in SERVICE and DOMAIN sections" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:188 +#: sssd.conf.5.xml:231 msgid "timeout (integer)" msgstr "timeout (整数)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:191 +#: sssd.conf.5.xml:234 msgid "" "Timeout in seconds between heartbeats for this service. This is used to " "ensure that the process is alive and capable of answering requests. Note " @@ -325,34 +383,36 @@ msgid "" msgstr "" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:198 sssd.conf.5.xml:1199 sssd.conf.5.xml:1673 -#: sssd.conf.5.xml:4174 sssd-ldap.5.xml:825 sssd-idp.5.xml:192 +#: sssd.conf.5.xml:241 sssd.conf.5.xml:1155 sssd.conf.5.xml:1665 +#: sssd.conf.5.xml:4379 sssd-ldap.5.xml:825 sssd-idp.5.xml:271 #: include/ldap_id_mapping.xml:270 msgid "Default: 10" msgstr "初期値: 10" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:208 +#: sssd.conf.5.xml:251 msgid "SPECIAL SECTIONS" msgstr "特別セクション" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:211 +#: sssd.conf.5.xml:254 msgid "The [sssd] section" msgstr "[sssd] セクション" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><title> -#: sssd.conf.5.xml:220 +#: sssd.conf.5.xml:263 msgid "Section parameters" msgstr "セクションのパラメーター" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:222 -msgid "services" -msgstr "services" +#: sssd.conf.5.xml:265 +#, fuzzy +#| msgid "simple_allow_users (string)" +msgid "services (string)" +msgstr "simple_allow_users (文字列)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:225 +#: sssd.conf.5.xml:268 msgid "" "Comma separated list of services that are started when sssd itself starts. " "<phrase condition=\"have_systemd\"> The services' list is optional on " @@ -361,7 +421,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:234 +#: sssd.conf.5.xml:277 msgid "" "Supported services: nss, pam, ifp <phrase condition=\"with_sudo\">, sudo</" "phrase> <phrase condition=\"with_autofs\">, autofs</phrase> <phrase " @@ -370,20 +430,20 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:241 +#: sssd.conf.5.xml:284 msgid "" "<phrase condition=\"have_systemd\"> By default, all services are disabled " "and the administrator must enable the ones allowed to be used by executing: " "\"systemctl enable sssd-@service@.socket\". </phrase>" msgstr "" -#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:250 -msgid "domains" -msgstr "domains" +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sssd.conf.5.xml:293 sssd.conf.5.xml:4562 +msgid "domains (string)" +msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:253 +#: sssd.conf.5.xml:296 msgid "" "A domain is a database containing user information. SSSD can use more " "domains at the same time, but at least one must be configured or SSSD won't " @@ -394,19 +454,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:266 sssd.conf.5.xml:3467 +#: sssd.conf.5.xml:309 sssd.conf.5.xml:3598 msgid "re_expression (string)" msgstr "re_expression (文字列)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:269 +#: sssd.conf.5.xml:312 msgid "" "Default regular expression that describes how to parse the string containing " "user name and domain into these components." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:274 +#: sssd.conf.5.xml:317 msgid "" "Each domain can have an individual regular expression configured. For some " "ID providers there are also default regular expressions. See DOMAIN SECTIONS " @@ -414,12 +474,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:283 sssd.conf.5.xml:3524 +#: sssd.conf.5.xml:326 sssd.conf.5.xml:3655 msgid "full_name_format (string)" msgstr "full_name_format (文字列)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:286 sssd.conf.5.xml:3527 +#: sssd.conf.5.xml:329 sssd.conf.5.xml:3658 msgid "" "A <citerefentry> <refentrytitle>printf</refentrytitle> <manvolnum>3</" "manvolnum> </citerefentry>-compatible format that describes how to compose a " @@ -430,39 +490,39 @@ msgstr "" "manvolnum> </citerefentry> 互換形式。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:297 sssd.conf.5.xml:3538 +#: sssd.conf.5.xml:340 sssd.conf.5.xml:3669 msgid "%1$s" msgstr "%1$s" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:298 sssd.conf.5.xml:3539 +#: sssd.conf.5.xml:341 sssd.conf.5.xml:3670 msgid "user name" msgstr "ユーザー名" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:301 sssd.conf.5.xml:3542 +#: sssd.conf.5.xml:344 sssd.conf.5.xml:3673 msgid "%2$s" msgstr "%2$s" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:304 sssd.conf.5.xml:3545 +#: sssd.conf.5.xml:347 sssd.conf.5.xml:3676 msgid "domain name as specified in the SSSD config file." msgstr "SSSD 設定ファイルにおいて指定されるドメイン名。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:310 sssd.conf.5.xml:3551 +#: sssd.conf.5.xml:353 sssd.conf.5.xml:3682 msgid "%3$s" msgstr "%3$s" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:313 sssd.conf.5.xml:3554 +#: sssd.conf.5.xml:356 sssd.conf.5.xml:3685 msgid "" "domain flat name. Mostly usable for Active Directory domains, both directly " "configured or discovered via IPA trusts." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:294 sssd.conf.5.xml:3535 +#: sssd.conf.5.xml:337 sssd.conf.5.xml:3666 msgid "" "The following expansions are supported: <placeholder type=\"variablelist\" " "id=\"0\"/>" @@ -471,19 +531,19 @@ msgstr "" "id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:323 +#: sssd.conf.5.xml:366 msgid "" "Each domain can have an individual format string configured. See DOMAIN " "SECTIONS for more info on this option." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:329 +#: sssd.conf.5.xml:372 msgid "monitor_resolv_conf (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:332 +#: sssd.conf.5.xml:375 msgid "" "Controls if SSSD should monitor the state of resolv.conf to identify when it " "needs to update its internal DNS resolver." @@ -492,12 +552,12 @@ msgstr "" "resolv.conf の状態を監視するかどうかを制御します。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:342 +#: sssd.conf.5.xml:385 msgid "try_inotify (boolean)" msgstr "try_inotify (論理値)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:345 +#: sssd.conf.5.xml:388 msgid "" "By default, SSSD will attempt to use inotify to monitor configuration files " "changes and will fall back to polling every five seconds if inotify cannot " @@ -505,7 +565,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:351 +#: sssd.conf.5.xml:394 msgid "" "There are some limited situations where it is preferred that we should skip " "even trying to use inotify. In these rare cases, this option should be set " @@ -516,7 +576,7 @@ msgstr "" "です" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:357 +#: sssd.conf.5.xml:400 msgid "" "Default: true on platforms where inotify is supported. False on other " "platforms." @@ -525,7 +585,7 @@ msgstr "" "プラットフォームにおいては偽です。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:361 +#: sssd.conf.5.xml:404 msgid "" "Note: this option will have no effect on platforms where inotify is " "unavailable. On these platforms, polling will always be used." @@ -534,12 +594,12 @@ msgstr "" "ません。これらのプラットフォームにおいては、ポーリングが常に使用されます。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:368 +#: sssd.conf.5.xml:411 msgid "krb5_rcache_dir (string)" msgstr "krb5_rcache_dir (文字列)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:371 +#: sssd.conf.5.xml:414 msgid "" "Directory on the filesystem where SSSD should store Kerberos replay cache " "files." @@ -548,7 +608,7 @@ msgstr "" "ディレクトリーです。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:375 +#: sssd.conf.5.xml:418 msgid "" "This option accepts a special value __LIBKRB5_DEFAULTS__ that will instruct " "SSSD to let libkrb5 decide the appropriate location for the replay cache." @@ -557,7 +617,7 @@ msgstr "" "よう SSSD に指示する、特別な値 __LIBKRB5_DEFAULTS__ を受け付けます。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:381 +#: sssd.conf.5.xml:424 msgid "" "Default: Distribution-specific and specified at build-time. " "(__LIBKRB5_DEFAULTS__ if not configured)" @@ -566,19 +626,19 @@ msgstr "" "ければ __LIBKRB5_DEFAULTS__ です)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:388 +#: sssd.conf.5.xml:431 msgid "default_domain_suffix (string)" msgstr "default_domain_suffix (文字列)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:391 +#: sssd.conf.5.xml:434 msgid "" "Please note that this option is deprecated and domain_resolution_order " "should be used." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:395 +#: sssd.conf.5.xml:438 msgid "" "This string will be used as a default domain name for all names without a " "domain name component. The main use case is environments where the primary " @@ -588,7 +648,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:405 +#: sssd.conf.5.xml:448 msgid "" "Please note that if this option is set all users from the primary domain " "have to use their fully qualified name, e.g. user@domain.name, to log in. " @@ -598,21 +658,21 @@ msgid "" msgstr "" #. type: Content of: <variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:414 sssd-ldap.5.xml:937 sssd-ldap.5.xml:949 -#: sssd-ldap.5.xml:1042 sssd-ad.5.xml:921 sssd-ad.5.xml:996 sssd-krb5.5.xml:468 -#: sssd-ldap-attributes.5.xml:470 sssd-ldap-attributes.5.xml:978 -#: include/ldap_id_mapping.xml:211 include/ldap_id_mapping.xml:222 -#: include/krb5_options.xml:148 +#: sssd.conf.5.xml:457 sssd.conf.5.xml:2006 sssd-ldap.5.xml:937 +#: sssd-ldap.5.xml:949 sssd-ldap.5.xml:1042 sssd-ad.5.xml:926 +#: sssd-ad.5.xml:1001 sssd-krb5.5.xml:468 sssd-ldap-attributes.5.xml:470 +#: sssd-ldap-attributes.5.xml:978 include/ldap_id_mapping.xml:211 +#: include/ldap_id_mapping.xml:222 include/krb5_options.xml:148 msgid "Default: not set" msgstr "初期値: 設定されません" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:419 +#: sssd.conf.5.xml:462 msgid "override_space (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:422 +#: sssd.conf.5.xml:465 msgid "" "This parameter will replace spaces (space bar) with the given character for " "user and group names. e.g. (_). User name "john doe" will be " @@ -622,7 +682,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:431 +#: sssd.conf.5.xml:474 msgid "" "Please note it is a configuration error to use a replacement character that " "might be used in user or group names. If a name contains the replacement " @@ -631,22 +691,22 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:439 +#: sssd.conf.5.xml:482 msgid "Default: not set (spaces will not be replaced)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:444 +#: sssd.conf.5.xml:487 msgid "certificate_verification (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:452 +#: sssd.conf.5.xml:495 msgid "no_ocsp" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:454 +#: sssd.conf.5.xml:497 msgid "" "Disables Online Certificate Status Protocol (OCSP) checks. This might be " "needed if the OCSP servers defined in the certificate are not reachable from " @@ -654,12 +714,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:462 +#: sssd.conf.5.xml:505 msgid "soft_ocsp" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:464 +#: sssd.conf.5.xml:507 msgid "" "If a connection cannot be established to an OCSP responder the OCSP check is " "skipped. This option should be used to allow authentication when the system " @@ -667,61 +727,61 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:474 +#: sssd.conf.5.xml:517 msgid "ocsp_dgst" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:476 +#: sssd.conf.5.xml:519 msgid "" "Digest (hash) function used to create the certificate ID for the OCSP " "request. Allowed values are:" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:480 +#: sssd.conf.5.xml:523 msgid "sha1" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:481 +#: sssd.conf.5.xml:524 msgid "sha256" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:482 +#: sssd.conf.5.xml:525 msgid "sha384" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:483 +#: sssd.conf.5.xml:526 msgid "sha512" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:486 +#: sssd.conf.5.xml:529 msgid "Default: sha1 (to allow compatibility with RFC5019-compliant responder)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:492 +#: sssd.conf.5.xml:535 msgid "no_verification" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:494 +#: sssd.conf.5.xml:537 msgid "" "Disables verification completely. This option should only be used for " "testing." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:500 +#: sssd.conf.5.xml:543 msgid "partial_chain" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:502 +#: sssd.conf.5.xml:545 msgid "" "Allow verification to succeed even if a <replaceable>complete</replaceable> " "chain cannot be built to a self-signed trust-anchor, provided it is possible " @@ -729,12 +789,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:511 +#: sssd.conf.5.xml:554 msgid "ocsp_default_responder=URL" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:513 +#: sssd.conf.5.xml:556 msgid "" "Sets the OCSP default responder which should be used instead of the one " "mentioned in the certificate. URL must be replaced with the URL of the OCSP " @@ -742,24 +802,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:523 +#: sssd.conf.5.xml:566 msgid "ocsp_default_responder_signing_cert=NAME" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:525 +#: sssd.conf.5.xml:568 msgid "" "This option is currently ignored. All needed certificates must be available " "in the PEM file given by pam_cert_db_path." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:533 +#: sssd.conf.5.xml:576 msgid "crl_file=/PATH/TO/CRL/FILE" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:535 +#: sssd.conf.5.xml:578 #, fuzzy #| msgid "" #| "Please refer to the <quote>dns_discovery_domain</quote> parameter in the " @@ -776,12 +836,12 @@ msgstr "" "dns_discovery_domain</quote> パラメーターを参照してください。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:548 +#: sssd.conf.5.xml:591 msgid "soft_crl" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:551 +#: sssd.conf.5.xml:594 msgid "" "If a Certificate Revocation List (CRL) is expired ignore the expiration " "time of the CRL and check the related certificates with the expired CRL. " @@ -790,7 +850,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:447 +#: sssd.conf.5.xml:490 msgid "" "With this parameter the certificate verification can be tuned with a comma " "separated list of options. Supported options are: <placeholder " @@ -798,46 +858,48 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:564 +#: sssd.conf.5.xml:607 msgid "Unknown options are reported but ignored." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:567 +#: sssd.conf.5.xml:610 msgid "Default: not set, i.e. do not restrict certificate verification" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:573 +#: sssd.conf.5.xml:616 msgid "disable_netlink (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:576 +#: sssd.conf.5.xml:619 msgid "" "SSSD hooks into the netlink interface to monitor changes to routes, " "addresses, links and trigger certain actions." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:581 +#: sssd.conf.5.xml:624 msgid "" "The SSSD state changes caused by netlink events may be undesirable and can " "be disabled by setting this option to 'true'" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:586 +#: sssd.conf.5.xml:629 msgid "Default: false (netlink changes are detected)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:591 -msgid "domain_resolution_order" -msgstr "" +#: sssd.conf.5.xml:634 +#, fuzzy +#| msgid "subdomains_provider (string)" +msgid "domain_resolution_order (string)" +msgstr "subdomains_provider (文字列)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:594 +#: sssd.conf.5.xml:637 msgid "" "Comma separated list of domains and subdomains representing the lookup order " "that will be followed. The list doesn't have to include all possible " @@ -848,7 +910,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:606 +#: sssd.conf.5.xml:649 msgid "" "Please, note that when this option is set the output format of all commands " "is always fully-qualified even when using short names for input. In case " @@ -864,21 +926,22 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:630 sssd.conf.5.xml:1697 sssd.conf.5.xml:4224 -#: sssd-ad.5.xml:187 sssd-ad.5.xml:328 sssd-ad.5.xml:342 sssd-idp.5.xml:108 -#: sssd-idp.5.xml:132 sssd-idp.5.xml:145 sssd-idp.5.xml:159 sssd-idp.5.xml:180 +#: sssd.conf.5.xml:673 sssd.conf.5.xml:1026 sssd.conf.5.xml:1689 +#: sssd.conf.5.xml:4429 sssd-ad.5.xml:187 sssd-ad.5.xml:328 sssd-ad.5.xml:342 +#: sssd-idp.5.xml:112 sssd-idp.5.xml:136 sssd-idp.5.xml:149 sssd-idp.5.xml:167 +#: sssd-idp.5.xml:188 msgid "Default: Not set" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:635 +#: sssd.conf.5.xml:678 #, fuzzy #| msgid "ipa_server_mode (boolean)" msgid "implicit_pac_responder (boolean)" msgstr "ipa_server_mode (論理値)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:638 +#: sssd.conf.5.xml:681 msgid "" "The PAC responder is enabled automatically for the IPA and AD provider to " "evaluate and check the PAC. If it has to be disabled set this option to " @@ -886,14 +949,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:649 +#: sssd.conf.5.xml:692 #, fuzzy #| msgid "dyndns_update (boolean)" msgid "core_dumpable (boolean)" msgstr "dyndns_update (論理値)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:652 +#: sssd.conf.5.xml:695 msgid "" "This option can be used for general system hardening: setting it to 'false' " "forbids core dumps for all SSSD processes to avoid leaking plain text " @@ -902,7 +965,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:660 +#: sssd.conf.5.xml:703 msgid "" "Take a note that this setting has no effect for 'ldap_child', 'krb5_child' " "and 'sssd_pam' as those privileged binaries can have a copy of a host keytab " @@ -911,28 +974,28 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:673 +#: sssd.conf.5.xml:716 #, fuzzy #| msgid "ipa_automount_location (string)" msgid "passkey_verification (string)" msgstr "ipa_automount_location (文字列)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:681 +#: sssd.conf.5.xml:724 #, fuzzy #| msgid "ipa_automount_location (string)" msgid "user_verification (boolean)" msgstr "ipa_automount_location (文字列)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:683 +#: sssd.conf.5.xml:726 msgid "" "Enable or disable the user verification (i.e. PIN, fingerprint) during " "authentication. If enabled, the PIN will always be requested." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:689 +#: sssd.conf.5.xml:732 msgid "" "The default is that the key settings decide what to do. In the IPA or " "kerberos pre-authentication case, this value will be overwritten by the " @@ -940,7 +1003,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:676 +#: sssd.conf.5.xml:719 #, fuzzy #| msgid "" #| "The following expansions are supported: <placeholder " @@ -954,7 +1017,7 @@ msgstr "" "id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:213 +#: sssd.conf.5.xml:256 msgid "" "Individual pieces of SSSD functionality are provided by special SSSD " "services that are started and stopped together with SSSD. The services are " @@ -970,12 +1033,12 @@ msgstr "" "す。 <placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:708 +#: sssd.conf.5.xml:751 msgid "SERVICES SECTIONS" msgstr "サービスセクション" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:710 +#: sssd.conf.5.xml:753 msgid "" "Settings that can be used to configure different services are described in " "this section. They should reside in the [<replaceable>$NAME</replaceable>] " @@ -987,42 +1050,45 @@ msgstr "" "、NSS サービスは <quote>[nss]</quote> セクションです" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:717 +#: sssd.conf.5.xml:760 msgid "General service configuration options" msgstr "サービス設定の全体オプション" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:719 +#: sssd.conf.5.xml:762 msgid "These options can be used to configure any service." msgstr "これらのオプションはすべてのサービスを設定するために使用できます。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:723 -msgid "fd_limit" -msgstr "fd_limit" +#: sssd.conf.5.xml:766 +#, fuzzy +#| msgid "timeout (integer)" +msgid "fd_limit (integer)" +msgstr "timeout (整数)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:726 +#: sssd.conf.5.xml:769 msgid "" "This option specifies the maximum number of file descriptors that may be " -"opened at one time by this SSSD process. On systems where SSSD is granted " -"the CAP_SYS_RESOURCE capability, this will be an absolute setting. On " -"systems without this capability, the resulting value will be the lower value " -"of this or the limits.conf \"hard\" limit." +"opened at one time by this SSSD process. Note this value will be capped by " +"the init system at the startup of SSSD, see e.g. man systemd.exec for " +"details." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:735 +#: sssd.conf.5.xml:776 msgid "Default: 8192 (or limits.conf \"hard\" limit)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:740 -msgid "client_idle_timeout" -msgstr "client_idle_timeout" +#: sssd.conf.5.xml:781 +#, fuzzy +#| msgid "entry_cache_timeout (integer)" +msgid "client_idle_timeout (integer)" +msgstr "entry_cache_timeout (整数)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:743 +#: sssd.conf.5.xml:784 msgid "" "This option specifies the number of seconds that a client of an SSSD process " "can hold onto a file descriptor without communicating on it. This value is " @@ -1032,150 +1098,21 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:752 +#: sssd.conf.5.xml:793 #, fuzzy #| msgid "Default: 300" msgid "Default: 60, KCM: 300" msgstr "初期値: 300" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:757 -msgid "offline_timeout (integer)" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:760 -msgid "" -"When SSSD switches to offline mode the amount of time before it tries to go " -"back online will increase based upon the time spent disconnected. By " -"default SSSD uses incremental behaviour to calculate delay in between " -"retries. So, the wait time for a given retry will be longer than the wait " -"time for the previous ones. After each unsuccessful attempt to go online, " -"the new interval is recalculated by the following:" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:771 sssd.conf.5.xml:827 -msgid "" -"new_delay = Minimum(old_delay * 2, offline_timeout_max) + " -"random[0...offline_timeout_random_offset]" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:774 -msgid "" -"The offline_timeout default value is 60. The offline_timeout_max default " -"value is 3600. The offline_timeout_random_offset default value is 30. The " -"end result is amount of seconds before next retry." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:780 -msgid "" -"Note that the maximum length of each interval is defined by " -"offline_timeout_max (apart of random part)." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:784 sssd.conf.5.xml:1110 sssd.conf.5.xml:1490 -#: sssd.conf.5.xml:1791 sssd-ldap.5.xml:550 -msgid "Default: 60" -msgstr "初期値: 60" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:789 -#, fuzzy -#| msgid "timeout (integer)" -msgid "offline_timeout_max (integer)" -msgstr "timeout (整数)" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:792 -msgid "" -"Controls by how much the time between attempts to go online can be " -"incremented following unsuccessful attempts to go online." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:797 -msgid "A value of 0 disables the incrementing behaviour." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:800 -msgid "" -"The value of this parameter should be set in correlation to offline_timeout " -"parameter value." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:804 -msgid "" -"With offline_timeout set to 60 (default value) there is no point in setting " -"offlinet_timeout_max to less than 120 as it will saturate instantly. General " -"rule here should be to set offline_timeout_max to at least 4 times " -"offline_timeout." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:810 -msgid "" -"Although a value between 0 and offline_timeout may be specified, it has the " -"effect of overriding the offline_timeout value so is of little use." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:815 -#, fuzzy -#| msgid "Default: 300" -msgid "Default: 3600" -msgstr "初期値: 300" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:820 -#, fuzzy -#| msgid "offline_failed_login_attempts (integer)" -msgid "offline_timeout_random_offset (integer)" -msgstr "offline_failed_login_attempts (整数)" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:823 -msgid "" -"When SSSD is in offline mode it keeps probing backend servers in specified " -"time intervals:" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:830 -msgid "" -"This parameter controls the value of the random offset used for the above " -"equation. Final random_offset value will be random number in range:" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:835 -msgid "[0 - offline_timeout_random_offset]" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:838 -msgid "A value of 0 disables the random offset addition." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:841 +#: sssd.conf.5.xml:798 #, fuzzy -#| msgid "Default: 300" -msgid "Default: 30" -msgstr "初期値: 300" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:846 -msgid "responder_idle_timeout" -msgstr "" +#| msgid "pam_id_timeout (integer)" +msgid "responder_idle_timeout (integer)" +msgstr "pam_id_timeout (整数)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:849 +#: sssd.conf.5.xml:801 msgid "" "This option specifies the number of seconds that an SSSD responder process " "can be up without being used. This value is limited in order to avoid " @@ -1187,43 +1124,50 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:863 sssd.conf.5.xml:1123 sssd.conf.5.xml:2248 +#: sssd.conf.5.xml:815 sssd.conf.5.xml:1079 sssd.conf.5.xml:2285 #: sssd-ldap.5.xml:377 msgid "Default: 300" msgstr "初期値: 300" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:868 -msgid "cache_first" -msgstr "" +#: sssd.conf.5.xml:820 +#, fuzzy +#| msgid "ldap_referrals (boolean)" +msgid "cache_first (boolean)" +msgstr "ldap_referrals (論理値)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:871 +#: sssd.conf.5.xml:823 msgid "" "This option specifies whether the responder should query all caches before " "querying the Data Providers." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:883 +#: sssd.conf.5.xml:835 msgid "NSS configuration options" msgstr "NSS 設定オプション" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:885 +#: sssd.conf.5.xml:837 +#, fuzzy +#| msgid "" +#| "These options can be used to configure the Name Service Switch (NSS) " +#| "service." msgid "" -"These options can be used to configure the Name Service Switch (NSS) service." +"These options can be used to configure the Name Service Switch (NSS) service " +"and should be specified under the <quote>[nss]</quote> section." msgstr "" "これらのオプションは Name Service Switch (NSS) サービスを設定するために使用で" "きます。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:890 +#: sssd.conf.5.xml:843 msgid "enum_cache_timeout (integer)" msgstr "enum_cache_timeout (整数)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:893 +#: sssd.conf.5.xml:846 msgid "" "How many seconds should nss_sss cache enumerations (requests for info about " "all users)" @@ -1232,17 +1176,17 @@ msgstr "" "要求)。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:897 +#: sssd.conf.5.xml:850 msgid "Default: 120" msgstr "初期値: 120" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:902 +#: sssd.conf.5.xml:855 msgid "entry_cache_nowait_percentage (integer)" msgstr "entry_cache_nowait_percentage (整数)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:905 +#: sssd.conf.5.xml:858 msgid "" "The entry cache can be set to automatically update entries in the background " "if they are requested beyond a percentage of the entry_cache_timeout value " @@ -1253,7 +1197,7 @@ msgstr "" "。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:911 +#: sssd.conf.5.xml:864 msgid "" "For example, if the domain's entry_cache_timeout is set to 30s and " "entry_cache_nowait_percentage is set to 50 (percent), entries that come in " @@ -1268,7 +1212,7 @@ msgstr "" "とをブロックする必要がありません。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:921 +#: sssd.conf.5.xml:874 msgid "" "Valid values for this option are 0-99 and represent a percentage of the " "entry_cache_timeout for each domain. For performance reasons, this " @@ -1281,17 +1225,17 @@ msgstr "" "せん。(0 はこの機能を無効にします)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:929 sssd.conf.5.xml:2061 +#: sssd.conf.5.xml:882 sssd.conf.5.xml:2093 msgid "Default: 50" msgstr "初期値: 50" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:934 +#: sssd.conf.5.xml:887 msgid "entry_negative_timeout (integer)" msgstr "entry_negative_timeout (整数)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:937 +#: sssd.conf.5.xml:890 msgid "" "Specifies for how many seconds nss_sss should cache negative cache hits " "(that is, queries for invalid database entries, like nonexistent ones) " @@ -1302,17 +1246,17 @@ msgstr "" "せ)をキャッシュする秒数を指定します。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:943 sssd.conf.5.xml:1685 sssd.conf.5.xml:2085 +#: sssd.conf.5.xml:896 sssd.conf.5.xml:1677 sssd.conf.5.xml:2119 msgid "Default: 15" msgstr "初期値: 15" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:948 +#: sssd.conf.5.xml:901 msgid "filter_users, filter_groups (string)" msgstr "filter_users, filter_groups (文字列)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:951 +#: sssd.conf.5.xml:904 msgid "" "Exclude certain users or groups from being fetched from the sss NSS " "database. This is particularly useful for system accounts. This option can " @@ -1321,7 +1265,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:959 +#: sssd.conf.5.xml:912 msgid "" "NOTE: The filter_groups option doesn't affect inheritance of nested group " "members, since filtering happens after they are propagated for returning via " @@ -1330,30 +1274,35 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:967 +#: sssd.conf.5.xml:920 msgid "Default: root" msgstr "初期値: root" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:972 -msgid "filter_users_in_groups (bool)" +#: sssd.conf.5.xml:925 +#, fuzzy +#| msgid "filter_users_in_groups (bool)" +msgid "filter_users_in_groups (boolean)" msgstr "filter_users_in_groups (論理値)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:975 +#: sssd.conf.5.xml:928 +#, fuzzy +#| msgid "" +#| "If you want filtered user still be group members set this option to false." msgid "" -"If you want filtered user still be group members set this option to false." +"If you want filtered users to remain group members set this option to false" msgstr "" -"フィルターされたユーザーがまだグループメンバーのままにしたいならば、この" -"オプションを偽に設定します。" +"フィルターされたユーザーがまだグループメンバーのままにしたいならば、このオプ" +"ションを偽に設定します。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:986 +#: sssd.conf.5.xml:939 msgid "fallback_homedir (string)" msgstr "fallback_homedir (文字列)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:989 +#: sssd.conf.5.xml:942 msgid "" "Set a default template for a user's home directory if one is not specified " "explicitly by the domain's data provider." @@ -1362,7 +1311,7 @@ msgstr "" "ホームディレクトリーの標準テンプレートを設定します。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:994 +#: sssd.conf.5.xml:947 msgid "" "The available values for this option are the same as for override_homedir." msgstr "" @@ -1370,7 +1319,7 @@ msgstr "" "同じです。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1000 +#: sssd.conf.5.xml:953 #, no-wrap msgid "" "fallback_homedir = /home/%u\n" @@ -1380,23 +1329,23 @@ msgstr "" " " #. type: Content of: <varlistentry><listitem><para> -#: sssd.conf.5.xml:998 sssd.conf.5.xml:1557 sssd.conf.5.xml:1576 -#: sssd.conf.5.xml:1653 sssd-krb5.5.xml:451 include/override_homedir.xml:78 +#: sssd.conf.5.xml:951 sssd.conf.5.xml:1524 sssd.conf.5.xml:1543 +#: sssd.conf.5.xml:1645 sssd-krb5.5.xml:451 include/override_homedir.xml:78 msgid "example: <placeholder type=\"programlisting\" id=\"0\"/>" msgstr "例: <placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1004 +#: sssd.conf.5.xml:957 msgid "Default: not set (no substitution for unset home directories)" msgstr "初期値: 設定なし (ホームディレクトリーの設定がない場合は代替なし)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1010 +#: sssd.conf.5.xml:963 msgid "override_shell (string)" msgstr "override_shell (文字列)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1013 +#: sssd.conf.5.xml:966 msgid "" "Override the login shell for all users. This option supersedes any other " "shell options if it takes effect and can be set either in the [nss] section " @@ -1404,17 +1353,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1019 +#: sssd.conf.5.xml:972 msgid "Default: not set (SSSD will use the value retrieved from LDAP)" msgstr "初期値: 設定なし (SSSD は LDAP から取得された値を使用します)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1025 +#: sssd.conf.5.xml:978 msgid "allowed_shells (string)" msgstr "allowed_shells (文字列)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1028 +#: sssd.conf.5.xml:981 msgid "" "Restrict user shell to one of the listed values. The order of evaluation is:" msgstr "" @@ -1422,12 +1371,12 @@ msgstr "" "す:" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1031 +#: sssd.conf.5.xml:984 msgid "1. If the shell is present in <quote>/etc/shells</quote>, it is used." msgstr "1. シェルが <quote>/etc/shells</quote> に存在すると、それが使用されます。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1035 +#: sssd.conf.5.xml:988 msgid "" "2. If the shell is in the allowed_shells list but not in <quote>/etc/shells</" "quote>, use the value of the shell_fallback parameter." @@ -1436,7 +1385,7 @@ msgstr "" "ば、shell_fallback パラメーターの値を使用します。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1040 +#: sssd.conf.5.xml:993 msgid "" "3. If the shell is not in the allowed_shells list and not in <quote>/etc/" "shells</quote>, a nologin shell is used." @@ -1445,12 +1394,12 @@ msgstr "" "ば、nologin シェルが使用されます。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1045 +#: sssd.conf.5.xml:998 msgid "The wildcard (*) can be used to allow any shell." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1048 +#: sssd.conf.5.xml:1001 msgid "" "The (*) is useful if you want to use shell_fallback in case that user's " "shell is not in <quote>/etc/shells</quote> and maintaining list of all " @@ -1458,12 +1407,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1055 +#: sssd.conf.5.xml:1008 msgid "An empty string for shell is passed as-is to libc." msgstr "シェルの空文字列は libc にそのまま渡されます。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1058 +#: sssd.conf.5.xml:1011 msgid "" "The <quote>/etc/shells</quote> is only read on SSSD start up, which means " "that a restart of the SSSD is required in case a new shell is installed." @@ -1473,27 +1422,27 @@ msgstr "" "ます。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1062 +#: sssd.conf.5.xml:1015 msgid "Default: Not set. The user shell is automatically used." msgstr "初期値: 設定されません。ユーザーシェルが自動的に使用されます。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1067 +#: sssd.conf.5.xml:1020 msgid "vetoed_shells (string)" msgstr "vetoed_shells (文字列)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1070 +#: sssd.conf.5.xml:1023 msgid "Replace any instance of these shells with the shell_fallback" msgstr "これらのシェルのインスタンスをすべて shell_fallback に置き換えます" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1075 +#: sssd.conf.5.xml:1031 msgid "shell_fallback (string)" msgstr "shell_fallback (文字列)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1078 +#: sssd.conf.5.xml:1034 msgid "" "The default shell to use if an allowed shell is not installed on the machine." msgstr "" @@ -1501,79 +1450,85 @@ msgstr "" "す。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1082 +#: sssd.conf.5.xml:1038 msgid "Default: /bin/sh" msgstr "初期値: /bin/sh" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1087 -msgid "default_shell" -msgstr "default_shell" +#: sssd.conf.5.xml:1043 +msgid "default_shell (string)" +msgstr "default_shell (文字列)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1090 +#: sssd.conf.5.xml:1046 msgid "" "The default shell to use if the provider does not return one during lookup. " "This option can be specified globally in the [nss] section or per-domain." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1096 +#: sssd.conf.5.xml:1052 msgid "" "Default: not set (Return NULL if no shell is specified and rely on libc to " "substitute something sensible when necessary, usually /bin/sh)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1103 sssd.conf.5.xml:1483 +#: sssd.conf.5.xml:1059 sssd.conf.5.xml:1450 msgid "get_domains_timeout (int)" msgstr "get_domains_timeout (整数)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1106 sssd.conf.5.xml:1486 +#: sssd.conf.5.xml:1062 sssd.conf.5.xml:1453 msgid "" "Specifies time in seconds for which the list of subdomains will be " "considered valid." msgstr "サブドメインのリストが有効とみなされる時間を秒単位で指定します。" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1066 sssd.conf.5.xml:1457 sssd.conf.5.xml:1788 +#: sssd.conf.5.xml:2862 sssd-ldap.5.xml:550 +msgid "Default: 60" +msgstr "初期値: 60" + #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1115 +#: sssd.conf.5.xml:1071 #, fuzzy #| msgid "enum_cache_timeout (integer)" msgid "memcache_timeout (integer)" msgstr "enum_cache_timeout (整数)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1118 +#: sssd.conf.5.xml:1074 msgid "" "Specifies time in seconds for which records in the in-memory cache will be " "valid. Setting this option to zero will disable the in-memory cache." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1126 +#: sssd.conf.5.xml:1082 msgid "" "WARNING: Disabling the in-memory cache will have significant negative impact " "on SSSD's performance and should only be used for testing." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1132 sssd.conf.5.xml:1157 sssd.conf.5.xml:1182 -#: sssd.conf.5.xml:1207 sssd.conf.5.xml:1234 +#: sssd.conf.5.xml:1088 sssd.conf.5.xml:1113 sssd.conf.5.xml:1138 +#: sssd.conf.5.xml:1163 sssd.conf.5.xml:1190 msgid "" "NOTE: If the environment variable SSS_NSS_USE_MEMCACHE is set to \"NO\", " "client applications will not use the fast in-memory cache." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1140 +#: sssd.conf.5.xml:1096 #, fuzzy #| msgid "enum_cache_timeout (integer)" msgid "memcache_size_passwd (integer)" msgstr "enum_cache_timeout (整数)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1143 +#: sssd.conf.5.xml:1099 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for passwd requests. Setting the size to 0 will disable the passwd in-" @@ -1581,27 +1536,27 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1149 sssd.conf.5.xml:2888 sssd-ldap.5.xml:604 +#: sssd.conf.5.xml:1105 sssd.conf.5.xml:3013 sssd-ldap.5.xml:604 msgid "Default: 8" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1152 sssd.conf.5.xml:1177 sssd.conf.5.xml:1202 -#: sssd.conf.5.xml:1229 +#: sssd.conf.5.xml:1108 sssd.conf.5.xml:1133 sssd.conf.5.xml:1158 +#: sssd.conf.5.xml:1185 msgid "" "WARNING: Disabled or too small in-memory cache can have significant negative " "impact on SSSD's performance." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1165 +#: sssd.conf.5.xml:1121 #, fuzzy #| msgid "enum_cache_timeout (integer)" msgid "memcache_size_group (integer)" msgstr "enum_cache_timeout (整数)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1168 +#: sssd.conf.5.xml:1124 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for group requests. Setting the size to 0 will disable the group in-memory " @@ -1609,21 +1564,21 @@ msgid "" msgstr "" #. type: Content of: <variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1174 sssd.conf.5.xml:1226 sssd.conf.5.xml:3656 +#: sssd.conf.5.xml:1130 sssd.conf.5.xml:1182 sssd.conf.5.xml:3835 #: sssd-ldap.5.xml:534 sssd-ldap.5.xml:581 include/failover.xml:116 #: include/krb5_options.xml:11 msgid "Default: 6" msgstr "初期値: 6" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1190 +#: sssd.conf.5.xml:1146 #, fuzzy #| msgid "enum_cache_timeout (integer)" msgid "memcache_size_initgroups (integer)" msgstr "enum_cache_timeout (整数)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1193 +#: sssd.conf.5.xml:1149 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for initgroups requests. Setting the size to 0 will disable the initgroups " @@ -1631,14 +1586,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1215 +#: sssd.conf.5.xml:1171 #, fuzzy #| msgid "enum_cache_timeout (integer)" msgid "memcache_size_sid (integer)" msgstr "enum_cache_timeout (整数)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1218 +#: sssd.conf.5.xml:1174 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for SID related requests. Only SID-by-ID and ID-by-SID requests are " @@ -1647,12 +1602,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1242 sssd-ifp.5.xml:90 +#: sssd.conf.5.xml:1198 sssd-ifp.5.xml:90 msgid "user_attributes (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1245 +#: sssd.conf.5.xml:1201 msgid "" "Some of the additional NSS responder requests can return more attributes " "than just the POSIX ones defined by the NSS interface. The list of " @@ -1663,73 +1618,81 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1258 +#: sssd.conf.5.xml:1214 msgid "" "To make configuration more easy the NSS responder will check the InfoPipe " "option if it is not set for the NSS responder." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1263 +#: sssd.conf.5.xml:1219 msgid "Default: not set, fallback to InfoPipe option" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1268 +#: sssd.conf.5.xml:1224 msgid "pwfield (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1271 +#: sssd.conf.5.xml:1227 msgid "" "The value that NSS operations that return users or groups will return for " "the <quote>password</quote> field." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1276 +#: sssd.conf.5.xml:1232 +msgid "" +"This option can also be set per-domain, which overwrites the value in the " +"<quote>[nss]</quote> section for that domain. This is particularly useful " +"when using a proxy domain with <option>proxy_lib_name=files</option> and a " +"<option>proxy_pam_target</option> other than <quote>sssd-shadowutils</" +"quote>. In that case, SSSD returns <quote>*</quote> for the password field " +"by default, which causes <command>pam_unix</command> to treat all accounts " +"as locked. Setting <option>pwfield = x</option> in the domain section " +"restores the expected behavior." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1246 #, fuzzy #| msgid "Default: <quote>permit</quote>" msgid "Default: <quote>*</quote>" msgstr "初期値: <quote>permit</quote>" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1279 -#, fuzzy -#| msgid "This option can also be set per-domain." -msgid "" -"Note: This option can also be set per-domain which overwrites the value in " -"[nss] section." -msgstr "このオプションはドメインごとに設定できます。" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1283 +#: sssd.conf.5.xml:1249 msgid "" -"Default: <quote>not set</quote> (remote domains), <quote>x</quote> (proxy " -"domain with nss_files and sssd-shadowutils target)" +"Default (per-domain): <quote>not set</quote> (remote domains), <quote>x</" +"quote> (proxy domain with nss_files and sssd-shadowutils target)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:1292 +#: sssd.conf.5.xml:1258 msgid "PAM configuration options" msgstr "PAM 設定オプション" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:1294 +#: sssd.conf.5.xml:1260 +#, fuzzy +#| msgid "" +#| "These options can be used to configure the Pluggable Authentication " +#| "Module (PAM) service." msgid "" "These options can be used to configure the Pluggable Authentication Module " -"(PAM) service." +"(PAM) service and should be specified under the <quote>[pam]</quote> section." msgstr "" "これらのオプションは Pluggable Authentication Module (PAM) サービスを設定する" "ために使用できます。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1299 +#: sssd.conf.5.xml:1266 msgid "offline_credentials_expiration (integer)" msgstr "offline_credentials_expiration (整数)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1302 +#: sssd.conf.5.xml:1269 msgid "" "If the authentication provider is offline, how long should we allow cached " "logins (in days since the last successful online login)." @@ -1738,29 +1701,29 @@ msgstr "" "オンラインログインの最終成功からの日数)です。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1307 sssd.conf.5.xml:1320 +#: sssd.conf.5.xml:1274 sssd.conf.5.xml:1287 msgid "Default: 0 (No limit)" msgstr "初期値: 0 (無制限)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1313 +#: sssd.conf.5.xml:1280 msgid "offline_failed_login_attempts (integer)" msgstr "offline_failed_login_attempts (整数)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1316 +#: sssd.conf.5.xml:1283 msgid "" "If the authentication provider is offline, how many failed login attempts " "are allowed." msgstr "認証プロバイダーがオフラインの場合、ログイン試行の失敗が許容される回数です。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1326 +#: sssd.conf.5.xml:1293 msgid "offline_failed_login_delay (integer)" msgstr "offline_failed_login_delay (整数)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1329 +#: sssd.conf.5.xml:1296 msgid "" "The time in minutes which has to pass after offline_failed_login_attempts " "has been reached before a new login attempt is possible." @@ -1769,7 +1732,7 @@ msgstr "" "渡される分単位の時間です。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1334 +#: sssd.conf.5.xml:1301 msgid "" "If set to 0 the user cannot authenticate offline if " "offline_failed_login_attempts has been reached. Only a successful online " @@ -1780,17 +1743,17 @@ msgstr "" "効にできます。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1340 sssd.conf.5.xml:1450 +#: sssd.conf.5.xml:1307 sssd.conf.5.xml:1417 msgid "Default: 5" msgstr "初期値: 5" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1346 +#: sssd.conf.5.xml:1313 msgid "pam_verbosity (integer)" msgstr "pam_verbosity (整数)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1349 +#: sssd.conf.5.xml:1316 msgid "" "Controls what kind of messages are shown to the user during authentication. " "The higher the number to more messages are displayed." @@ -1799,44 +1762,44 @@ msgstr "" "きいほどメッセージが表示されます。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1354 +#: sssd.conf.5.xml:1321 msgid "Currently sssd supports the following values:" msgstr "現在 sssd は以下の値をサポートします:" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1357 +#: sssd.conf.5.xml:1324 msgid "<emphasis>0</emphasis>: do not show any message" msgstr "<emphasis>0</emphasis>: 何もメッセージを表示しない" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1360 +#: sssd.conf.5.xml:1327 msgid "<emphasis>1</emphasis>: show only important messages" msgstr "<emphasis>1</emphasis>: 重要なメッセージのみを表示する" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1364 +#: sssd.conf.5.xml:1331 msgid "<emphasis>2</emphasis>: show informational messages" msgstr "<emphasis>2</emphasis>: 情報レベルのメッセージを表示する" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1367 +#: sssd.conf.5.xml:1334 msgid "<emphasis>3</emphasis>: show all messages and debug information" msgstr "<emphasis>3</emphasis>: すべてのメッセージとデバッグ情報を表示する" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1371 sssd.8.xml:63 +#: sssd.conf.5.xml:1338 sssd.8.xml:63 msgid "Default: 1" msgstr "初期値: 1" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1377 +#: sssd.conf.5.xml:1344 #, fuzzy #| msgid "ldap_access_filter (string)" msgid "pam_response_filter (string)" msgstr "ldap_access_filter (文字列)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1380 +#: sssd.conf.5.xml:1347 msgid "" "A comma separated list of strings which allows to remove (filter) data sent " "by the PAM responder to pam_sss PAM module. There are different kind of " @@ -1845,51 +1808,51 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1388 +#: sssd.conf.5.xml:1355 msgid "" "While messages already can be controlled with the help of the pam_verbosity " "option this option allows to filter out other kind of responses as well." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1395 +#: sssd.conf.5.xml:1362 msgid "ENV" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1396 +#: sssd.conf.5.xml:1363 msgid "Do not send any environment variables to any service." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1399 +#: sssd.conf.5.xml:1366 msgid "ENV:var_name" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1400 +#: sssd.conf.5.xml:1367 msgid "Do not send environment variable var_name to any service." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1404 +#: sssd.conf.5.xml:1371 msgid "ENV:var_name:service" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1405 +#: sssd.conf.5.xml:1372 msgid "Do not send environment variable var_name to service." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1393 +#: sssd.conf.5.xml:1360 msgid "" "Currently the following filters are supported: <placeholder " "type=\"variablelist\" id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1412 +#: sssd.conf.5.xml:1379 msgid "" "The list of strings can either be the list of filters which would set this " "list of filters and overwrite the defaults. Or each element of the list can " @@ -1900,23 +1863,23 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1423 +#: sssd.conf.5.xml:1390 msgid "Default: ENV:KRB5CCNAME:sudo, ENV:KRB5CCNAME:sudo-i" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1426 +#: sssd.conf.5.xml:1393 msgid "" "Example: -ENV:KRB5CCNAME:sudo-i will remove the filter from the default list" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1433 +#: sssd.conf.5.xml:1400 msgid "pam_id_timeout (integer)" msgstr "pam_id_timeout (整数)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1436 +#: sssd.conf.5.xml:1403 msgid "" "For any PAM request while SSSD is online, the SSSD will attempt to " "immediately update the cached identity information for the user in order to " @@ -1926,7 +1889,7 @@ msgstr "" "されるよう、SSSD は直ちにキャッシュされた識別情報を更新しようとします。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1442 +#: sssd.conf.5.xml:1409 msgid "" "A complete PAM conversation may perform multiple PAM requests, such as " "account management and session opening. This option controls (on a per-" @@ -1939,17 +1902,17 @@ msgstr "" "クライアントアプリケーションごとに)制御します。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1456 +#: sssd.conf.5.xml:1423 msgid "pam_pwd_expiration_warning (integer)" msgstr "pam_pwd_expiration_warning (整数)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1459 sssd.conf.5.xml:2912 +#: sssd.conf.5.xml:1426 sssd.conf.5.xml:3037 msgid "Display a warning N days before the password expires." msgstr "パスワードの期限が切れる前に N 日間警告を表示します。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1462 +#: sssd.conf.5.xml:1429 msgid "" "Please note that the backend server has to provide information about the " "expiration time of the password. If this information is missing, sssd " @@ -1959,32 +1922,32 @@ msgstr "" "ことに注意してください。この情報がなければ、sssd は警告を表示します。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1468 sssd.conf.5.xml:2915 +#: sssd.conf.5.xml:1435 sssd.conf.5.xml:3040 msgid "" "If zero is set, then this filter is not applied, i.e. if the expiration " "warning was received from backend server, it will automatically be displayed." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1473 +#: sssd.conf.5.xml:1440 msgid "" "This setting can be overridden by setting <emphasis>pwd_expiration_warning</" "emphasis> for a particular domain." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1478 sssd.conf.5.xml:3913 sssd-ldap.5.xml:662 +#: sssd.conf.5.xml:1445 sssd.conf.5.xml:4118 sssd-ldap.5.xml:662 #: sssd-ldap.5.xml:1733 sssd.8.xml:79 msgid "Default: 0" msgstr "初期値: 0" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1495 +#: sssd.conf.5.xml:1462 msgid "pam_trusted_users (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1498 +#: sssd.conf.5.xml:1465 msgid "" "Specifies the comma-separated list of UID values or user names that are " "allowed to run PAM conversations against trusted domains. Users not " @@ -1994,74 +1957,74 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1508 +#: sssd.conf.5.xml:1475 msgid "Default: All users are considered trusted by default" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1512 +#: sssd.conf.5.xml:1479 msgid "" "Please note that UID 0 is always allowed to access the PAM responder even in " "case it is not in the pam_trusted_users list." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1519 +#: sssd.conf.5.xml:1486 msgid "pam_public_domains (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1522 +#: sssd.conf.5.xml:1489 msgid "" "Specifies the comma-separated list of domain names that are accessible even " "to untrusted users." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1526 +#: sssd.conf.5.xml:1493 msgid "Two special values for pam_public_domains option are defined:" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1530 +#: sssd.conf.5.xml:1497 msgid "" "all (Untrusted users are allowed to access all domains in PAM responder.)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1534 +#: sssd.conf.5.xml:1501 msgid "" "none (Untrusted users are not allowed to access any domains PAM in " "responder.)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1538 sssd.conf.5.xml:1563 sssd.conf.5.xml:1582 -#: sssd.conf.5.xml:1824 sssd.conf.5.xml:3842 sssd-ldap.5.xml:1270 +#: sssd.conf.5.xml:1505 sssd.conf.5.xml:1530 sssd.conf.5.xml:1549 +#: sssd.conf.5.xml:1821 sssd.conf.5.xml:4048 sssd-ldap.5.xml:1270 msgid "Default: none" msgstr "初期値: none" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1543 +#: sssd.conf.5.xml:1510 msgid "pam_account_expired_message (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1546 +#: sssd.conf.5.xml:1513 msgid "" "Allows a custom expiration message to be set, replacing the default " "'Permission denied' message." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1551 +#: sssd.conf.5.xml:1518 msgid "" "Note: Please be aware that message is only printed for the SSH service " "unless pam_verbosity is set to 3 (show all messages and debug information)." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1559 +#: sssd.conf.5.xml:1526 #, no-wrap msgid "" "pam_account_expired_message = Account expired, please contact help desk.\n" @@ -2069,19 +2032,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1568 +#: sssd.conf.5.xml:1535 msgid "pam_account_locked_message (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1571 +#: sssd.conf.5.xml:1538 msgid "" "Allows a custom lockout message to be set, replacing the default 'Permission " "denied' message." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1578 +#: sssd.conf.5.xml:1545 #, no-wrap msgid "" "pam_account_locked_message = Account locked, please contact help desk.\n" @@ -2089,85 +2052,130 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1587 +#: sssd.conf.5.xml:1554 #, fuzzy #| msgid "ldap_chpass_update_last_change (bool)" -msgid "pam_passkey_auth (bool)" +msgid "pam_passkey_auth (boolean)" msgstr "ldap_chpass_update_last_change (論理値)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1590 +#: sssd.conf.5.xml:1557 msgid "Enable passkey device based authentication." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1593 sssd.conf.5.xml:1910 sssd-ad.5.xml:1286 +#: sssd.conf.5.xml:1560 sssd.conf.5.xml:1907 sssd-ad.5.xml:1279 #: sss_rpcidmapd.5.xml:76 msgid "Default: True" msgstr "初期値: True" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1598 -msgid "passkey_debug_libfido2 (bool)" -msgstr "" +#: sssd.conf.5.xml:1565 +#, fuzzy +#| msgid "ipa_automount_location (string)" +msgid "passkey_debug_libfido2 (boolean)" +msgstr "ipa_automount_location (文字列)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1601 +#: sssd.conf.5.xml:1568 msgid "Enable libfido2 library debug messages." msgstr "" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1604 sssd.conf.5.xml:1618 sssd-ldap.5.xml:727 -#: sssd-ldap.5.xml:752 sssd-ldap.5.xml:848 sssd-ldap.5.xml:1356 -#: sssd-ad.5.xml:506 sssd-ad.5.xml:582 sssd-ad.5.xml:1155 +#: sssd.conf.5.xml:1571 sssd.conf.5.xml:1585 sssd.conf.5.xml:4781 +#: sssd-ldap.5.xml:727 sssd-ldap.5.xml:752 sssd-ldap.5.xml:848 +#: sssd-ldap.5.xml:1356 sssd-ad.5.xml:506 sssd-ad.5.xml:582 sssd-ad.5.xml:1160 #: include/ldap_id_mapping.xml:250 msgid "Default: False" msgstr "初期値: 偽" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1609 -msgid "pam_cert_auth (bool)" -msgstr "" +#: sssd.conf.5.xml:1576 +#, fuzzy +#| msgid "ldap_chpass_update_last_change (bool)" +msgid "pam_cert_auth (boolean)" +msgstr "ldap_chpass_update_last_change (論理値)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1612 +#: sssd.conf.5.xml:1579 msgid "" "Enable certificate based Smartcard authentication. Since this requires " "additional communication with the Smartcard which will delay the " "authentication process this option is disabled by default." msgstr "" +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1588 +msgid "" +"Note: In case OpenSC is used for Smartcard access SSSD supports the " +"filesystem caching in OpenSC when enabled in opensc.conf. The cached files " +"are located in a common <quote>opensc</quote> directory in SSSD's state " +"directory. The behaviour can be changed in opensc.conf" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> +#: sssd.conf.5.xml:1597 +#, no-wrap +msgid "" +"app /usr/libexec/sssd/p11_child {\n" +" framework pkcs15 {\n" +" use_file_caching = no;\n" +" }\n" +"}\n" +"app /usr/libexec/sssd/krb5_child {\n" +" framework pkcs15 {\n" +" use_file_caching = no;\n" +" }\n" +"}\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1595 +#, fuzzy +#| msgid "example: <placeholder type=\"programlisting\" id=\"0\"/>" +msgid "" +"Example opensc.conf (*): <placeholder type=\"programlisting\" id=\"0\"/>" +msgstr "例: <placeholder type=\"programlisting\" id=\"0\"/>" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1610 +msgid "" +"(*) The actual <quote>libexec</quote> directory for p11_child and krb5_child " +"depends on the distribution." +msgstr "" + #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1623 +#: sssd.conf.5.xml:1615 msgid "pam_cert_db_path (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1626 +#: sssd.conf.5.xml:1618 msgid "The path to the certificate database." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1629 sssd.conf.5.xml:2163 sssd.conf.5.xml:4338 +#: sssd.conf.5.xml:1621 sssd.conf.5.xml:2199 sssd.conf.5.xml:4543 msgid "Default:" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1631 sssd.conf.5.xml:2165 +#: sssd.conf.5.xml:1623 sssd.conf.5.xml:2201 msgid "" "/etc/sssd/pki/sssd_auth_ca_db.pem (path to a file with trusted CA " "certificates in PEM format)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1641 +#: sssd.conf.5.xml:1633 #, fuzzy #| msgid "ipa_automount_location (string)" msgid "pam_cert_verification (string)" msgstr "ipa_automount_location (文字列)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1644 +#: sssd.conf.5.xml:1636 msgid "" "With this parameter the PAM certificate verification can be tuned with a " "comma separated list of options that override the " @@ -2177,7 +2185,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1655 +#: sssd.conf.5.xml:1647 #, fuzzy, no-wrap #| msgid "" #| "fallback_homedir = /home/%u\n" @@ -2190,63 +2198,63 @@ msgstr "" " " #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1659 +#: sssd.conf.5.xml:1651 msgid "" "Default: not set, i.e. use default <quote>certificate_verification</quote> " "option defined in <quote>[sssd]</quote> section." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1666 +#: sssd.conf.5.xml:1658 msgid "p11_child_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1669 +#: sssd.conf.5.xml:1661 msgid "How many seconds will pam_sss wait for p11_child to finish." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1678 +#: sssd.conf.5.xml:1670 #, fuzzy #| msgid "pam_id_timeout (integer)" msgid "passkey_child_timeout (integer)" msgstr "pam_id_timeout (整数)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1681 +#: sssd.conf.5.xml:1673 msgid "" "How many seconds will the PAM responder wait for passkey_child to finish." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1690 +#: sssd.conf.5.xml:1682 msgid "pam_app_services (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1693 +#: sssd.conf.5.xml:1685 msgid "" "Which PAM services are permitted to contact domains of type " "<quote>application</quote>" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1702 +#: sssd.conf.5.xml:1694 #, fuzzy #| msgid "simple_allow_users (string)" msgid "pam_p11_allowed_services (string)" msgstr "simple_allow_users (文字列)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1705 +#: sssd.conf.5.xml:1697 msgid "" "A comma-separated list of PAM service names for which it will be allowed to " "use Smartcards." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1720 +#: sssd.conf.5.xml:1712 #, no-wrap msgid "" "pam_p11_allowed_services = +my_pam_service, -login\n" @@ -2254,7 +2262,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1709 +#: sssd.conf.5.xml:1701 msgid "" "It is possible to add another PAM service name to the default set by using " "<quote>+service_name</quote> or to explicitly remove a PAM service name from " @@ -2266,68 +2274,73 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1724 sssd-ad.5.xml:645 sssd-ad.5.xml:754 sssd-ad.5.xml:812 -#: sssd-ad.5.xml:870 sssd-ad.5.xml:948 +#: sssd.conf.5.xml:1716 sssd-ad.5.xml:645 sssd-ad.5.xml:759 sssd-ad.5.xml:817 +#: sssd-ad.5.xml:875 sssd-ad.5.xml:953 msgid "Default: the default set of PAM service names includes:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1729 sssd-ad.5.xml:649 +#: sssd.conf.5.xml:1721 sssd-ad.5.xml:649 msgid "login" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1734 sssd-ad.5.xml:654 +#: sssd.conf.5.xml:1726 sssd-ad.5.xml:654 msgid "su" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1739 sssd-ad.5.xml:659 +#: sssd.conf.5.xml:1731 sssd-ad.5.xml:659 msgid "su-l" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1744 sssd-ad.5.xml:674 +#: sssd.conf.5.xml:1736 sssd-ad.5.xml:674 msgid "gdm-smartcard" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1749 sssd-ad.5.xml:669 +#: sssd.conf.5.xml:1741 sssd-ad.5.xml:669 msgid "gdm-password" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1754 +#: sssd.conf.5.xml:1746 msgid "gdm-switchable-auth" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1759 sssd-ad.5.xml:679 +#: sssd.conf.5.xml:1751 sssd-ad.5.xml:679 msgid "kdm" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1764 sssd-ad.5.xml:957 +#: sssd.conf.5.xml:1756 sssd-ad.5.xml:694 +msgid "plasmalogin" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:1761 sssd-ad.5.xml:962 msgid "sudo" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1769 sssd-ad.5.xml:962 +#: sssd.conf.5.xml:1766 sssd-ad.5.xml:967 msgid "sudo-i" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1774 +#: sssd.conf.5.xml:1771 msgid "gnome-screensaver" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1782 +#: sssd.conf.5.xml:1779 msgid "p11_wait_for_card_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1785 +#: sssd.conf.5.xml:1782 msgid "" "If Smartcard authentication is required how many extra seconds in addition " "to p11_child_timeout should the PAM responder wait until a Smartcard is " @@ -2335,12 +2348,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1796 +#: sssd.conf.5.xml:1793 msgid "p11_uri (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1799 +#: sssd.conf.5.xml:1796 msgid "" "PKCS#11 URI (see RFC-7512 for details) which can be used to restrict the " "selection of devices used for Smartcard authentication. By default SSSD's " @@ -2351,7 +2364,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1812 +#: sssd.conf.5.xml:1809 #, no-wrap msgid "" "p11_uri = pkcs11:slot-description=My%20Smartcard%20Reader\n" @@ -2359,7 +2372,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1816 +#: sssd.conf.5.xml:1813 #, no-wrap msgid "" "p11_uri = pkcs11:library-description=OpenSC%20smartcard%20framework;slot-id=2\n" @@ -2367,7 +2380,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1810 +#: sssd.conf.5.xml:1807 msgid "" "Example: <placeholder type=\"programlisting\" id=\"0\"/> or <placeholder " "type=\"programlisting\" id=\"1\"/> To find suitable URI please check the " @@ -2376,47 +2389,49 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1829 -msgid "pam_initgroups_scheme" -msgstr "" +#: sssd.conf.5.xml:1826 +#, fuzzy +#| msgid "ldap_netgroup_member (string)" +msgid "pam_initgroups_scheme (string)" +msgstr "ldap_netgroup_member (文字列)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1837 +#: sssd.conf.5.xml:1834 msgid "always" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1838 +#: sssd.conf.5.xml:1835 msgid "" "Always do an online lookup, please note that pam_id_timeout still applies" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1842 +#: sssd.conf.5.xml:1839 msgid "no_session" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1843 +#: sssd.conf.5.xml:1840 msgid "" "Only do an online lookup if there is no active session of the user, i.e. if " "the user is currently not logged in" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1848 sssd-ldap.5.xml:189 +#: sssd.conf.5.xml:1845 sssd-ldap.5.xml:189 msgid "never" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1849 +#: sssd.conf.5.xml:1846 msgid "" "Never force an online lookup, use the data from the cache as long as they " "are not expired" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1832 +#: sssd.conf.5.xml:1829 msgid "" "The PAM responder can force an online lookup to get the current group " "memberships of the user trying to log in. This option controls when this " @@ -2425,17 +2440,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1856 +#: sssd.conf.5.xml:1853 msgid "Default: no_session" msgstr "" -#. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:1861 sssd.conf.5.xml:4277 -msgid "pam_gssapi_services" -msgstr "" +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1858 +#, fuzzy +#| msgid "simple_allow_users (string)" +msgid "pam_gssapi_services (string)" +msgstr "simple_allow_users (文字列)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1864 +#: sssd.conf.5.xml:1861 #, fuzzy #| msgid "Comma separated list of users who are allowed to log in." msgid "" @@ -2444,13 +2461,13 @@ msgid "" msgstr "ログインが許可されたユーザーのカンマ区切り一覧です。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1869 +#: sssd.conf.5.xml:1866 msgid "" "To disable GSSAPI authentication, set this option to <quote>-</quote> (dash)." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1873 sssd.conf.5.xml:1904 sssd.conf.5.xml:1942 +#: sssd.conf.5.xml:1870 sssd.conf.5.xml:1901 sssd.conf.5.xml:1939 msgid "" "Note: This option can also be set per-domain which overwrites the value in " "[pam] section. It can also be set for trusted domain which overwrites the " @@ -2458,7 +2475,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1881 +#: sssd.conf.5.xml:1878 #, fuzzy, no-wrap #| msgid "" #| "fallback_homedir = /home/%u\n" @@ -2471,22 +2488,24 @@ msgstr "" " " #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1879 sssd.conf.5.xml:1994 sssd.conf.5.xml:3836 +#: sssd.conf.5.xml:1876 sssd.conf.5.xml:2023 sssd.conf.5.xml:4042 msgid "Example: <placeholder type=\"programlisting\" id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1885 +#: sssd.conf.5.xml:1882 msgid "Default: - (GSSAPI authentication is disabled)" msgstr "" -#. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:1890 sssd.conf.5.xml:4278 -msgid "pam_gssapi_check_upn" -msgstr "" +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1887 +#, fuzzy +#| msgid "ldap_disable_paging (boolean)" +msgid "pam_gssapi_check_upn (boolean)" +msgstr "ldap_disable_paging (論理値)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1893 +#: sssd.conf.5.xml:1890 msgid "" "If True, SSSD will require that the Kerberos user principal that " "successfully authenticated through GSSAPI can be associated with the user " @@ -2494,19 +2513,21 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1900 +#: sssd.conf.5.xml:1897 msgid "" -"If False, every user that is able to obtained required service ticket will " +"If False, every user that is able to obtain a required service ticket will " "be authenticated." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1915 -msgid "pam_gssapi_indicators_map" -msgstr "" +#: sssd.conf.5.xml:1912 +#, fuzzy +#| msgid "ldap_autofs_map_name (string)" +msgid "pam_gssapi_indicators_map (string)" +msgstr "ldap_autofs_map_name (文字列)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1918 +#: sssd.conf.5.xml:1915 msgid "" "Comma separated list of authentication indicators required to be present in " "a Kerberos ticket to access a PAM service that is allowed to try GSSAPI " @@ -2514,7 +2535,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1924 +#: sssd.conf.5.xml:1921 msgid "" "Each element of the list can be either an authentication indicator name or a " "pair <quote>service:indicator</quote>. Indicators not prefixed with the PAM " @@ -2529,7 +2550,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1937 +#: sssd.conf.5.xml:1934 msgid "" "To disable GSSAPI authentication indicator check, set this option to <quote>-" "</quote> (dash). To disable the check for a specific PAM service, add " @@ -2537,45 +2558,45 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1948 +#: sssd.conf.5.xml:1945 msgid "" "Following authentication indicators are supported by IPA Kerberos " "deployments:" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1951 +#: sssd.conf.5.xml:1948 msgid "" "pkinit -- pre-authentication using X.509 certificates -- whether stored in " "files or on smart cards." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1954 +#: sssd.conf.5.xml:1951 msgid "" "hardened -- SPAKE pre-authentication or any pre-authentication wrapped in a " "FAST channel." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1957 +#: sssd.conf.5.xml:1954 msgid "radius -- pre-authentication with the help of a RADIUS server." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1960 +#: sssd.conf.5.xml:1957 msgid "" "otp -- pre-authentication using integrated two-factor authentication (2FA or " "one-time password, OTP) in IPA." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1963 +#: sssd.conf.5.xml:1960 msgid "idp -- pre-authentication using external identity provider." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1973 +#: sssd.conf.5.xml:1970 #, no-wrap msgid "" "pam_gssapi_indicators_map = sudo:pkinit, sudo-i:pkinit\n" @@ -2583,7 +2604,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1968 +#: sssd.conf.5.xml:1965 msgid "" "Example: to require access to SUDO services only for users which obtained " "their Kerberos tickets with a X.509 certificate pre-authentication (PKINIT), " @@ -2591,21 +2612,64 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1977 +#: sssd.conf.5.xml:1974 #, fuzzy #| msgid "Default: not set (no substitution for unset home directories)" msgid "Default: not set (use of authentication indicators is not required)" msgstr "初期値: 設定なし (ホームディレクトリーの設定がない場合は代替なし)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1979 +#, fuzzy +#| msgid "base_directory (string)" +msgid "pam_gssapi_indicators_apply (string)" +msgstr "base_directory (文字列)" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1982 +msgid "" +"Comma separated list of triples to assign additional information from the " +"Kerberos ticket, e.g. a SID from the PAC, to authentication indicators." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1988 +#, fuzzy +#| msgid "Currently supported debug levels:" +msgid "Currently supported is:" +msgstr "現在サポートされるデバッグレベル:" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:1991 +msgid "SID:S-1-5-[domain]-[RID]:[authentication indicator]" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> +#: sssd.conf.5.xml:2002 +#, no-wrap +msgid "" +"pam_gssapi_indicators_apply = SID:S-1-5-12345-23456-34567-4321:pkinit\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1996 +msgid "" +"Example: To assign a SID, which is e.g. set by Active Directory's " +"Authentication Mechanism Assurance (AMA) if the AD user used a Smartcard for " +"authentication, to the 'pkinit' authentication indicator use: <placeholder " +"type=\"programlisting\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2011 #, fuzzy #| msgid "simple_allow_users (string)" msgid "pam_json_services (string)" msgstr "simple_allow_users (文字列)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1985 +#: sssd.conf.5.xml:2014 #, fuzzy #| msgid "Comma separated list of users who are allowed to log in." msgid "" @@ -2614,12 +2678,12 @@ msgid "" msgstr "ログインが許可されたユーザーのカンマ区切り一覧です。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1990 +#: sssd.conf.5.xml:2019 msgid "To disable JSON protocol, set this option to <quote>-</quote> (dash)." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1996 +#: sssd.conf.5.xml:2025 #, fuzzy, no-wrap #| msgid "" #| "fallback_homedir = /home/%u\n" @@ -2632,42 +2696,70 @@ msgstr "" " " #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2000 +#: sssd.conf.5.xml:2029 #, fuzzy #| msgid "Default: 0 (disabled)" msgid "Default: - (JSON protocol is disabled)" msgstr "初期値: 0 (無効)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2003 +#: sssd.conf.5.xml:2032 msgid "" "Note: 2-Factor Authentication (2FA) is not supported. If 2FA is required, do " "not activate the JSON protocol." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:2013 +#: sssd.conf.5.xml:2042 msgid "SUDO configuration options" msgstr "SUDO 設定オプション" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2015 +#: sssd.conf.5.xml:2044 +#, fuzzy +#| msgid "" +#| "These options can be used to configure the Name Service Switch (NSS) " +#| "service." msgid "" -"These options can be used to configure the sudo service. The detailed " -"instructions for configuration of <citerefentry> <refentrytitle>sudo</" -"refentrytitle> <manvolnum>8</manvolnum> </citerefentry> to work with " -"<citerefentry> <refentrytitle>sssd</refentrytitle> <manvolnum>8</manvolnum> " -"</citerefentry> are in the manual page <citerefentry> <refentrytitle>sssd-" -"sudo</refentrytitle> <manvolnum>5</manvolnum> </citerefentry>." +"These options can be used to configure the sudo service and should be " +"specified under the <quote>[sudo]</quote> section." msgstr "" +"これらのオプションは Name Service Switch (NSS) サービスを設定するために使用で" +"きます。" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:2048 +#, fuzzy +#| msgid "" +#| "Specifies the timeout (in seconds) after which the <citerefentry> " +#| "<refentrytitle>poll</refentrytitle> <manvolnum>2</manvolnum> </" +#| "citerefentry>/<citerefentry> <refentrytitle>select</refentrytitle> " +#| "<manvolnum>2</manvolnum> </citerefentry> following a <citerefentry> " +#| "<refentrytitle>connect</refentrytitle> <manvolnum>2</manvolnum> </" +#| "citerefentry> returns in case of no activity." +msgid "" +"The detailed instructions for configuration of <citerefentry> " +"<refentrytitle>sudo</refentrytitle> <manvolnum>8</manvolnum> </citerefentry> " +"to work with <citerefentry> <refentrytitle>sssd</refentrytitle> " +"<manvolnum>8</manvolnum> </citerefentry> are in the manual page " +"<citerefentry> <refentrytitle>sssd-sudo</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry>." +msgstr "" +"<citerefentry> <refentrytitle>connect</refentrytitle> <manvolnum>2</" +"manvolnum> </citerefentry> に続けて <citerefentry> <refentrytitle>poll</" +"refentrytitle> <manvolnum>2</manvolnum> </citerefentry>/<citerefentry> " +"<refentrytitle>select</refentrytitle> <manvolnum>2</manvolnum> </" +"citerefentry> が未使用を返した後のタイムアウト(秒単位)を指定します。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2032 -msgid "sudo_timed (bool)" +#: sssd.conf.5.xml:2064 +#, fuzzy +#| msgid "sudo_timed (bool)" +msgid "sudo_timed (boolean)" msgstr "sudo_timed (論理値)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2035 +#: sssd.conf.5.xml:2067 msgid "" "Whether or not to evaluate the sudoNotBefore and sudoNotAfter attributes " "that implement time-dependent sudoers entries." @@ -2676,12 +2768,12 @@ msgstr "" "を評価するかしないかです。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2047 +#: sssd.conf.5.xml:2079 msgid "sudo_threshold (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2050 +#: sssd.conf.5.xml:2082 msgid "" "Maximum number of expired rules that can be refreshed at once. If number of " "expired rules is below threshold, those rules are refreshed with " @@ -2691,22 +2783,26 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:2069 +#: sssd.conf.5.xml:2101 msgid "AUTOFS configuration options" msgstr "Autofs 設定オプション" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2071 -msgid "These options can be used to configure the autofs service." +#: sssd.conf.5.xml:2103 +#, fuzzy +#| msgid "These options can be used to configure the autofs service." +msgid "" +"These options can be used to configure the autofs service and should be " +"specified under the <quote>[autofs]</quote> section." msgstr "これらのオプションが autofs サービスを設定するために使用されます。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2075 +#: sssd.conf.5.xml:2109 msgid "autofs_negative_timeout (integer)" msgstr "autofs_negative_timeout (整数)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2078 +#: sssd.conf.5.xml:2112 msgid "" "Specifies for how many seconds should the autofs responder negative cache " "hits (that is, queries for invalid map entries, like nonexistent ones) " @@ -2717,22 +2813,28 @@ msgstr "" "ヒットする秒数を指定します。" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:2094 +#: sssd.conf.5.xml:2128 msgid "SSH configuration options" msgstr "SSH 設定オプション" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2096 -msgid "These options can be used to configure the SSH service." +#: sssd.conf.5.xml:2130 +#, fuzzy +#| msgid "These options can be used to configure the SSH service." +msgid "" +"These options can be used to configure the SSH service and should be " +"specified under the <quote>[ssh]</quote> section." msgstr "これらのオプションは SSH サービスを設定するために使用されます。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2100 -msgid "ssh_use_certificate_keys (bool)" -msgstr "" +#: sssd.conf.5.xml:2136 +#, fuzzy +#| msgid "ipa_automount_location (string)" +msgid "ssh_use_certificate_keys (boolean)" +msgstr "ipa_automount_location (文字列)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2103 +#: sssd.conf.5.xml:2139 msgid "" "If set to true the <command>sss_ssh_authorizedkeys</command> will return ssh " "keys derived from the public key of X.509 certificates stored in the user " @@ -2741,12 +2843,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2118 +#: sssd.conf.5.xml:2154 msgid "ssh_use_certificate_matching_rules (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2121 +#: sssd.conf.5.xml:2157 msgid "" "By default the ssh responder will use all available certificate matching " "rules to filter the certificates so that ssh keys are only derived from the " @@ -2756,7 +2858,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2130 +#: sssd.conf.5.xml:2166 msgid "" "There are two special key words 'all_rules' and 'no_rules' which will enable " "all or no rules, respectively. The latter means that no certificates will be " @@ -2764,7 +2866,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2137 +#: sssd.conf.5.xml:2173 msgid "" "If no rules are configured using 'all_rules' will enable a default rule " "which enables all certificates suitable for client authentication. This is " @@ -2773,38 +2875,38 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2144 +#: sssd.conf.5.xml:2180 msgid "" "A non-existing rule name is considered an error. If as a result no rule is " "selected all certificates will be ignored." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2149 +#: sssd.conf.5.xml:2185 msgid "" "Default: not set, equivalent to 'all_rules', all found rules or the default " "rule are used" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2155 +#: sssd.conf.5.xml:2191 msgid "ca_db (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2158 +#: sssd.conf.5.xml:2194 msgid "" "Path to a storage of trusted CA certificates. The option is used to validate " "user certificates before deriving public ssh keys from them." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:2178 +#: sssd.conf.5.xml:2214 msgid "PAC responder configuration options" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2180 +#: sssd.conf.5.xml:2216 msgid "" "The PAC responder works together with the authorization data plugin for MIT " "Kerberos sssd_pac_plugin.so and a sub-domain provider. The plugin sends the " @@ -2815,7 +2917,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:2189 +#: sssd.conf.5.xml:2225 msgid "" "If the remote user does not exist in the cache, it is created. The UID is " "determined with the help of the SID, trusted domains will have UPGs and the " @@ -2826,24 +2928,26 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:2197 +#: sssd.conf.5.xml:2233 msgid "" "If there are SIDs of groups from domains sssd knows about, the user will be " "added to those groups." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2203 -msgid "These options can be used to configure the PAC responder." +#: sssd.conf.5.xml:2239 +msgid "" +"These options can be used to configure the PAC responder and should be " +"specified under the <quote>[pac]</quote> section." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2207 sssd-ifp.5.xml:66 +#: sssd.conf.5.xml:2244 sssd-ifp.5.xml:66 msgid "allowed_uids (string)" msgstr "allowed_uids (文字列)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2210 +#: sssd.conf.5.xml:2247 msgid "" "Specifies the comma-separated list of UID values or user names that are " "allowed to access the PAC responder. User names are resolved to UIDs at " @@ -2851,19 +2955,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2216 +#: sssd.conf.5.xml:2253 msgid "" "Default: 0, &sssd_user_name; (only root and SSSD service users are allowed " "to access the PAC responder)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2220 +#: sssd.conf.5.xml:2257 msgid "Default: 0 (only the root user is allowed to access the PAC responder)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2224 +#: sssd.conf.5.xml:2261 msgid "" "Please note that defaults will be overwritten with this option. If you still " "want to allow the root and/or '&sssd_user_name;' user to access the PAC " @@ -2872,7 +2976,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2231 +#: sssd.conf.5.xml:2268 msgid "" "Please note that although the UID 0 is used as the default it will be " "overwritten with this option. If you still want to allow the root user to " @@ -2881,26 +2985,26 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2240 +#: sssd.conf.5.xml:2277 msgid "pac_lifetime (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2243 +#: sssd.conf.5.xml:2280 msgid "" "Lifetime of the PAC entry in seconds. As long as the PAC is valid the PAC " "data can be used to determine the group memberships of a user." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2253 +#: sssd.conf.5.xml:2290 #, fuzzy #| msgid "ldap_schema (string)" msgid "pac_check (string)" msgstr "ldap_schema (文字列)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2256 +#: sssd.conf.5.xml:2293 msgid "" "Apply additional checks on the PAC of the Kerberos ticket which is available " "in Active Directory and FreeIPA domains, if configured. Please note that " @@ -2911,7 +3015,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2266 +#: sssd.conf.5.xml:2303 msgid "" "Please note that the checks listed below only apply to PACs issued by Active " "Directory or recent versions of FreeIPA. PACs issued e.g. by a plain MIT " @@ -2919,24 +3023,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2277 +#: sssd.conf.5.xml:2314 msgid "no_check" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2279 +#: sssd.conf.5.xml:2316 msgid "" "The PAC must not be present and even if it is present no additional checks " "will be done." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2285 +#: sssd.conf.5.xml:2322 msgid "pac_present" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2287 +#: sssd.conf.5.xml:2324 msgid "" "The PAC must be present in the service ticket which SSSD will request with " "the help of the user's TGT. If the PAC is not available the authentication " @@ -2944,24 +3048,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2295 +#: sssd.conf.5.xml:2332 msgid "check_upn" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2297 +#: sssd.conf.5.xml:2334 msgid "" "If the PAC is present check if the user principal name (UPN) information is " "consistent." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2303 +#: sssd.conf.5.xml:2340 msgid "check_upn_allow_missing" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2305 +#: sssd.conf.5.xml:2342 msgid "" "This option should be used together with 'check_upn' and handles the case " "where a UPN is set on the server-side but is not read by SSSD. The typical " @@ -2973,7 +3077,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2317 +#: sssd.conf.5.xml:2354 msgid "" "Currently this option is set by default to avoid regressions in such " "environments. A log message will be added to the system log and SSSD's debug " @@ -2984,41 +3088,41 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2331 +#: sssd.conf.5.xml:2368 msgid "upn_dns_info_present" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2333 +#: sssd.conf.5.xml:2370 msgid "The PAC must contain the UPN-DNS-INFO buffer, implies 'check_upn'." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2338 +#: sssd.conf.5.xml:2375 msgid "check_upn_dns_info_ex" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2340 +#: sssd.conf.5.xml:2377 msgid "" "If the PAC is present and the extension to the UPN-DNS-INFO buffer is " "available check if the information in the extension is consistent." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2347 +#: sssd.conf.5.xml:2384 msgid "upn_dns_info_ex_present" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2349 +#: sssd.conf.5.xml:2386 msgid "" "The PAC must contain the extension of the UPN-DNS-INFO buffer, implies " "'check_upn_dns_info_ex', 'upn_dns_info_present' and 'check_upn'." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2273 +#: sssd.conf.5.xml:2310 #, fuzzy #| msgid "" #| "The following expansions are supported: <placeholder " @@ -3031,19 +3135,19 @@ msgstr "" "id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2359 +#: sssd.conf.5.xml:2396 msgid "" "Default: no_check (AD and IPA provider 'check_upn, check_upn_allow_missing, " "check_upn_dns_info_ex')" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:2368 +#: sssd.conf.5.xml:2405 msgid "Session recording configuration options" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2370 +#: sssd.conf.5.xml:2407 msgid "" "Session recording works in conjunction with <citerefentry> " "<refentrytitle>tlog-rec-session</refentrytitle> <manvolnum>8</manvolnum> </" @@ -3053,66 +3157,78 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2383 -msgid "These options can be used to configure session recording." +#: sssd.conf.5.xml:2420 +msgid "" +"These options can be used to configure session recording and should be " +"specified under the <quote>[session_recording]</quote> section." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:2425 +msgid "" +"Note: Unlike other sections, the <quote>[session_recording]</quote> section " +"ignores <replaceable>debug*</replaceable> options and suitable " +"<replaceable>debug*</replaceable> options must be set in <quote>[pam]</" +"quote>, <quote>[nss]</quote> and <quote>[domain/<replaceable>NAME</" +"replaceable>]</quote> sections." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2387 sssd-session-recording.5.xml:64 +#: sssd.conf.5.xml:2433 sssd-session-recording.5.xml:64 msgid "scope (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2394 sssd-session-recording.5.xml:71 +#: sssd.conf.5.xml:2440 sssd-session-recording.5.xml:71 msgid "\"none\"" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2397 sssd-session-recording.5.xml:74 +#: sssd.conf.5.xml:2443 sssd-session-recording.5.xml:74 msgid "No users are recorded." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2402 sssd-session-recording.5.xml:79 +#: sssd.conf.5.xml:2448 sssd-session-recording.5.xml:79 msgid "\"some\"" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2405 sssd-session-recording.5.xml:82 +#: sssd.conf.5.xml:2451 sssd-session-recording.5.xml:82 msgid "" "Users/groups specified by <replaceable>users</replaceable> and " "<replaceable>groups</replaceable> options are recorded." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2414 sssd-session-recording.5.xml:91 +#: sssd.conf.5.xml:2460 sssd-session-recording.5.xml:91 msgid "\"all\"" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2417 sssd-session-recording.5.xml:94 +#: sssd.conf.5.xml:2463 sssd-session-recording.5.xml:94 msgid "All users are recorded." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2390 sssd-session-recording.5.xml:67 +#: sssd.conf.5.xml:2436 sssd-session-recording.5.xml:67 msgid "" "One of the following strings specifying the scope of session recording: " "<placeholder type=\"variablelist\" id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2424 sssd-session-recording.5.xml:101 +#: sssd.conf.5.xml:2470 sssd-session-recording.5.xml:101 msgid "Default: \"none\"" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2429 sssd-session-recording.5.xml:106 +#: sssd.conf.5.xml:2475 sssd-session-recording.5.xml:106 msgid "users (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2432 sssd-session-recording.5.xml:109 +#: sssd.conf.5.xml:2478 sssd-session-recording.5.xml:109 msgid "" "A comma-separated list of users which should have session recording enabled. " "Matches user names as returned by NSS. I.e. after the possible space " @@ -3123,17 +3239,17 @@ msgstr "" "の可能性がある場合には、その後になります。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2438 sssd-session-recording.5.xml:115 +#: sssd.conf.5.xml:2484 sssd-session-recording.5.xml:115 msgid "Default: Empty. Matches no users." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2443 sssd-session-recording.5.xml:120 +#: sssd.conf.5.xml:2489 sssd-session-recording.5.xml:120 msgid "groups (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2446 sssd-session-recording.5.xml:123 +#: sssd.conf.5.xml:2492 sssd-session-recording.5.xml:123 msgid "" "A comma-separated list of groups, members of which should have session " "recording enabled. Matches group names as returned by NSS. I.e. after the " @@ -3144,7 +3260,7 @@ msgstr "" "字小文字の変更などの可能性がある場合には、その後になります。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2452 sssd.conf.5.xml:2484 sssd-session-recording.5.xml:129 +#: sssd.conf.5.xml:2498 sssd.conf.5.xml:2530 sssd-session-recording.5.xml:129 #: sssd-session-recording.5.xml:161 msgid "" "NOTE: using this option (having it set to anything) has a considerable " @@ -3153,65 +3269,66 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2459 sssd-session-recording.5.xml:136 +#: sssd.conf.5.xml:2505 sssd-session-recording.5.xml:136 msgid "Default: Empty. Matches no groups." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2464 sssd-session-recording.5.xml:141 +#: sssd.conf.5.xml:2510 sssd-session-recording.5.xml:141 #, fuzzy #| msgid "simple_deny_users (string)" msgid "exclude_users (string)" msgstr "simple_deny_users (文字列)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2467 sssd-session-recording.5.xml:144 +#: sssd.conf.5.xml:2513 sssd-session-recording.5.xml:144 msgid "" "A comma-separated list of users to be excluded from recording, only " "applicable with 'scope=all'." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2471 sssd-session-recording.5.xml:148 +#: sssd.conf.5.xml:2517 sssd-session-recording.5.xml:148 #, fuzzy #| msgid "Default: empty, i.e. ldap_uri is used." msgid "Default: Empty. No users excluded." msgstr "初期値: 空、つまり ldap_uri が使用されます。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2476 sssd-session-recording.5.xml:153 +#: sssd.conf.5.xml:2522 sssd-session-recording.5.xml:153 #, fuzzy #| msgid "simple_deny_groups (string)" msgid "exclude_groups (string)" msgstr "simple_deny_groups (文字列)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2479 sssd-session-recording.5.xml:156 +#: sssd.conf.5.xml:2525 sssd-session-recording.5.xml:156 msgid "" "A comma-separated list of groups, members of which should be excluded from " "recording. Only applicable with 'scope=all'." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2491 sssd-session-recording.5.xml:168 +#: sssd.conf.5.xml:2537 sssd-session-recording.5.xml:168 #, fuzzy #| msgid "Default: empty, i.e. ldap_uri is used." msgid "Default: Empty. No groups excluded." msgstr "初期値: 空、つまり ldap_uri が使用されます。" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:2501 +#: sssd.conf.5.xml:2547 msgid "DOMAIN SECTIONS" msgstr "ドメインセクション" -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry><para> -#: sssd.conf.5.xml:2508 sssd.conf.5.xml:3964 sssd.conf.5.xml:3965 -#: sssd.conf.5.xml:3968 -msgid "enabled" -msgstr "" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2554 +#, fuzzy +#| msgid "dyndns_update (boolean)" +msgid "enabled (boolean)" +msgstr "dyndns_update (論理値)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2511 +#: sssd.conf.5.xml:2557 msgid "" "Explicitly enable or disable the domain. If <quote>true</quote>, the domain " "is always <quote>enabled</quote>. If <quote>false</quote>, the domain is " @@ -3221,12 +3338,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2523 +#: sssd.conf.5.xml:2569 msgid "domain_type (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2526 +#: sssd.conf.5.xml:2572 msgid "" "Specifies whether the domain is meant to be used by POSIX-aware clients such " "as the Name Service Switch or by applications that do not need POSIX data to " @@ -3235,14 +3352,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2534 +#: sssd.conf.5.xml:2580 msgid "" "Allowed values for this option are <quote>posix</quote> and " "<quote>application</quote>." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2538 +#: sssd.conf.5.xml:2584 msgid "" "POSIX domains are reachable by all services. Application domains are only " "reachable from the InfoPipe responder (see <citerefentry> " @@ -3251,31 +3368,31 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2546 +#: sssd.conf.5.xml:2592 msgid "" "NOTE: The application domains are currently well tested with " "<quote>id_provider=ldap</quote> only." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2550 +#: sssd.conf.5.xml:2596 msgid "" "For an easy way to configure a non-POSIX domains, please see the " "<quote>Application domains</quote> section." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2554 +#: sssd.conf.5.xml:2600 msgid "Default: posix" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2560 +#: sssd.conf.5.xml:2606 msgid "min_id,max_id (integer)" msgstr "min_id,max_id (整数)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2563 +#: sssd.conf.5.xml:2609 msgid "" "UID and GID limits for the domain. If a domain contains an entry that is " "outside these limits, it is ignored." @@ -3284,7 +3401,7 @@ msgstr "" "エントリーを含む場合、それは無視されます。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2568 +#: sssd.conf.5.xml:2614 msgid "" "For users, this affects the primary GID limit. The user will not be returned " "to NSS if either the UID or the primary GID is outside the range. For non-" @@ -3297,24 +3414,26 @@ msgstr "" "ます。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2575 +#: sssd.conf.5.xml:2621 msgid "" "These ID limits affect even saving entries to cache, not only returning them " "by name or ID." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2579 +#: sssd.conf.5.xml:2625 msgid "Default: 1 for min_id, 0 (no limit) for max_id" msgstr "初期値: min_id は 1, max_id は 0 (無制限)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2585 -msgid "enumerate (bool)" +#: sssd.conf.5.xml:2631 +#, fuzzy +#| msgid "enumerate (bool)" +msgid "enumerate (boolean)" msgstr "enumerate (論理値)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2588 +#: sssd.conf.5.xml:2634 msgid "" "Determines if a domain can be enumerated, that is, whether the domain can " "list all the users and group it contains. Note that it is not required to " @@ -3323,36 +3442,36 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2596 +#: sssd.conf.5.xml:2642 msgid "TRUE = Users and groups are enumerated" msgstr "TRUE = ユーザーとグループが列挙されます" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2599 +#: sssd.conf.5.xml:2645 msgid "FALSE = No enumerations for this domain" msgstr "FALSE = このドメインに対して列挙しません" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2602 sssd.conf.5.xml:2867 sssd.conf.5.xml:3044 +#: sssd.conf.5.xml:2648 sssd.conf.5.xml:2992 sssd.conf.5.xml:3174 msgid "Default: FALSE" msgstr "初期値: FALSE" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2605 +#: sssd.conf.5.xml:2651 msgid "" "Enumerating a domain requires SSSD to download and store ALL user and group " "entries from the remote server." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2610 +#: sssd.conf.5.xml:2656 msgid "" "Feature is only supported for domains with id_provider = ldap or id_provider " "= proxy." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2614 +#: sssd.conf.5.xml:2660 msgid "" "Note: Enabling enumeration has a severe performance impact on SSSD while " "enumeration is running. It may take up to several minutes after SSSD startup " @@ -3366,7 +3485,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2629 +#: sssd.conf.5.xml:2675 msgid "" "While the first enumeration is running, requests for the complete user or " "group lists may return no results until it completes." @@ -3375,7 +3494,7 @@ msgstr "" "れが完了するまで結果を返しません。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2634 +#: sssd.conf.5.xml:2680 msgid "" "Further, enabling enumeration may increase the time necessary to detect " "network disconnection, as longer timeouts are required to ensure that " @@ -3388,14 +3507,14 @@ msgstr "" "てください。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2642 +#: sssd.conf.5.xml:2688 msgid "" "For the reasons cited above, enabling enumeration is not recommended, " "especially in large environments." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2647 +#: sssd.conf.5.xml:2693 msgid "" "Note: the proxy provider is tested with open source modules like " "'libnss_files' and 'libnss_ldap'. 3rd party modules must follow the " @@ -3403,12 +3522,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2656 +#: sssd.conf.5.xml:2702 msgid "entry_cache_timeout (integer)" msgstr "entry_cache_timeout (整数)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2659 +#: sssd.conf.5.xml:2705 msgid "" "How many seconds should nss_sss consider entries valid before asking the " "backend again" @@ -3417,7 +3536,7 @@ msgstr "" "数です。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2663 +#: sssd.conf.5.xml:2709 msgid "" "The cache expiration timestamps are stored as attributes of individual " "objects in the cache. Therefore, changing the cache timeout only has effect " @@ -3428,17 +3547,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2676 +#: sssd.conf.5.xml:2722 msgid "Default: 5400" msgstr "初期値: 5400" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2682 +#: sssd.conf.5.xml:2728 msgid "entry_cache_user_timeout (integer)" msgstr "entry_cache_user_timeout (整数)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2685 +#: sssd.conf.5.xml:2731 msgid "" "How many seconds should nss_sss consider user entries valid before asking " "the backend again" @@ -3447,19 +3566,19 @@ msgstr "" "考える秒数です。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2689 sssd.conf.5.xml:2702 sssd.conf.5.xml:2715 -#: sssd.conf.5.xml:2728 sssd.conf.5.xml:2742 sssd.conf.5.xml:2755 -#: sssd.conf.5.xml:2769 sssd.conf.5.xml:2783 sssd.conf.5.xml:2796 +#: sssd.conf.5.xml:2735 sssd.conf.5.xml:2748 sssd.conf.5.xml:2761 +#: sssd.conf.5.xml:2774 sssd.conf.5.xml:2788 sssd.conf.5.xml:2801 +#: sssd.conf.5.xml:2815 sssd.conf.5.xml:2829 msgid "Default: entry_cache_timeout" msgstr "初期値: entry_cache_timeout" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2695 +#: sssd.conf.5.xml:2741 msgid "entry_cache_group_timeout (integer)" msgstr "entry_cache_group_timeout (整数)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2698 +#: sssd.conf.5.xml:2744 msgid "" "How many seconds should nss_sss consider group entries valid before asking " "the backend again" @@ -3468,12 +3587,12 @@ msgstr "" "考える秒数です。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2708 +#: sssd.conf.5.xml:2754 msgid "entry_cache_netgroup_timeout (integer)" msgstr "entry_cache_netgroup_timeout (整数)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2711 +#: sssd.conf.5.xml:2757 msgid "" "How many seconds should nss_sss consider netgroup entries valid before " "asking the backend again" @@ -3482,12 +3601,12 @@ msgstr "" "有効であると考える秒数です。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2721 +#: sssd.conf.5.xml:2767 msgid "entry_cache_service_timeout (integer)" msgstr "entry_cache_service_timeout (整数)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2724 +#: sssd.conf.5.xml:2770 msgid "" "How many seconds should nss_sss consider service entries valid before asking " "the backend again" @@ -3495,82 +3614,195 @@ msgstr "" "nss_sss が再びバックエンドに問い合わせる前にサービスエントリーを有効であると" "考える秒数です。" -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2734 -msgid "entry_cache_resolver_timeout (integer)" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2780 +msgid "entry_cache_resolver_timeout (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2783 +msgid "" +"How many seconds should nss_sss consider hosts and networks entries valid " +"before asking the backend again" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2794 +msgid "entry_cache_sudo_timeout (integer)" +msgstr "entry_cache_sudo_timeout (integer)" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2797 +msgid "" +"How many seconds should sudo consider rules valid before asking the backend " +"again" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2807 +msgid "entry_cache_autofs_timeout (integer)" +msgstr "entry_cache_autofs_timeout (整数)" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2810 +msgid "" +"How many seconds should the autofs service consider automounter maps valid " +"before asking the backend again" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2821 +msgid "entry_cache_ssh_host_timeout (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2824 +msgid "" +"How many seconds to keep a host ssh key after refresh. IE how long to cache " +"the host key for." +msgstr "" +"リフレッシュ後にホストの ssh 鍵を保持するには何秒かかるか。IE ホストキーを何" +"秒キャッシュするか。" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2835 +msgid "offline_timeout (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2838 +msgid "" +"When SSSD switches to offline mode the amount of time before it tries to go " +"back online will increase based upon the time spent disconnected. By " +"default SSSD uses incremental behaviour to calculate delay in between " +"retries. So, the wait time for a given retry will be longer than the wait " +"time for the previous ones. After each unsuccessful attempt to go online, " +"the new interval is recalculated by the following:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2849 sssd.conf.5.xml:2907 +msgid "" +"new_delay = Minimum(old_delay * 2, offline_timeout_max) + " +"random[0...offline_timeout_random_offset]" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2852 +msgid "" +"The offline_timeout default value is 60. The offline_timeout_max default " +"value is 3600. The offline_timeout_random_offset default value is 30. The " +"end result is the number of seconds before next retry." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2858 +msgid "" +"Note that the maximum length of each interval is defined by " +"offline_timeout_max (apart from the random part)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2868 +#, fuzzy +#| msgid "timeout (integer)" +msgid "offline_timeout_max (integer)" +msgstr "timeout (整数)" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2871 +msgid "" +"Controls by how much the time between attempts to go online can be " +"incremented following unsuccessful attempts to go online." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2876 +msgid "A value of 0 disables the incrementing behaviour." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2737 +#: sssd.conf.5.xml:2879 msgid "" -"How many seconds should nss_sss consider hosts and networks entries valid " -"before asking the backend again" +"The value of this parameter should be set in correlation to offline_timeout " +"parameter value." msgstr "" -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2748 -msgid "entry_cache_sudo_timeout (integer)" -msgstr "entry_cache_sudo_timeout (integer)" - #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2751 +#: sssd.conf.5.xml:2883 msgid "" -"How many seconds should sudo consider rules valid before asking the backend " -"again" +"With offline_timeout set to 60 (default value) there is no point in setting " +"offline_timeout_max to less than 120 as it will saturate instantly. General " +"rule here should be to set offline_timeout_max to at least 4 times " +"offline_timeout." msgstr "" -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2761 -msgid "entry_cache_autofs_timeout (integer)" -msgstr "entry_cache_autofs_timeout (整数)" - #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2764 +#: sssd.conf.5.xml:2889 msgid "" -"How many seconds should the autofs service consider automounter maps valid " -"before asking the backend again" +"Although a value between 0 and offline_timeout may be specified, it has the " +"effect of overriding the offline_timeout value so is of little use." msgstr "" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2894 +#, fuzzy +#| msgid "Default: 300" +msgid "Default: 3600" +msgstr "初期値: 300" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2775 -msgid "entry_cache_ssh_host_timeout (integer)" +#: sssd.conf.5.xml:2900 +#, fuzzy +#| msgid "offline_failed_login_attempts (integer)" +msgid "offline_timeout_random_offset (integer)" +msgstr "offline_failed_login_attempts (整数)" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2903 +msgid "" +"When SSSD is in offline mode it keeps probing backend servers in specified " +"time intervals:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2778 +#: sssd.conf.5.xml:2910 msgid "" -"How many seconds to keep a host ssh key after refresh. IE how long to cache " -"the host key for." +"This parameter controls the value of the random offset used for the above " +"equation. Final random_offset value will be random number in range:" msgstr "" -"リフレッシュ後にホストの ssh 鍵を保持するには何秒かかるか。IE ホストキーを何" -"秒キャッシュするか。" -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2789 -msgid "entry_cache_computer_timeout (integer)" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2915 +msgid "[0 - offline_timeout_random_offset]" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2792 -msgid "" -"How many seconds to keep the local computer entry before asking the backend " -"again" +#: sssd.conf.5.xml:2918 +msgid "A value of 0 disables the random offset addition." msgstr "" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2921 +#, fuzzy +#| msgid "Default: 300" +msgid "Default: 30" +msgstr "初期値: 300" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2802 +#: sssd.conf.5.xml:2927 msgid "refresh_expired_interval (integer)" msgstr "refresh_expired_interval (整数)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2805 +#: sssd.conf.5.xml:2930 msgid "" "Specifies how many seconds SSSD has to wait before triggering a background " "refresh task which will refresh all expired or nearly expired records." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2810 +#: sssd.conf.5.xml:2935 msgid "" "The background refresh will process users, groups and netgroups in the " "cache. For users who have performed the initgroups (get group membership for " @@ -3579,17 +3811,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2818 +#: sssd.conf.5.xml:2943 msgid "This option is automatically inherited for all trusted domains." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2822 +#: sssd.conf.5.xml:2947 msgid "You can consider setting this value to 3/4 * entry_cache_timeout." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2826 +#: sssd.conf.5.xml:2951 msgid "" "Cache entry will be refreshed by background task when 2/3 of cache timeout " "has already passed. If there are existing cached entries, the background " @@ -3601,18 +3833,20 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2839 sssd-ldap.5.xml:406 sssd-ldap.5.xml:1834 -#: sssd-ipa.5.xml:255 +#: sssd.conf.5.xml:2964 sssd-ldap.5.xml:406 sssd-ldap.5.xml:1834 +#: sssd-ipa.5.xml:250 msgid "Default: 0 (disabled)" msgstr "初期値: 0 (無効)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2845 -msgid "cache_credentials (bool)" +#: sssd.conf.5.xml:2970 +#, fuzzy +#| msgid "cache_credentials (bool)" +msgid "cache_credentials (boolean)" msgstr "cache_credentials (論理値)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2848 +#: sssd.conf.5.xml:2973 msgid "" "Determines if user credentials are also cached in the local LDB cache. The " "cached credentials refer to passwords, which includes the first (long term) " @@ -3623,7 +3857,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2859 +#: sssd.conf.5.xml:2984 msgid "" "Take a note that while credentials are stored as a salted SHA512 hash, this " "still potentially poses some security risk in case an attacker manages to " @@ -3632,12 +3866,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2873 +#: sssd.conf.5.xml:2998 msgid "cache_credentials_minimal_first_factor_length (int)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2876 +#: sssd.conf.5.xml:3001 msgid "" "If 2-Factor-Authentication (2FA) is used and credentials should be saved " "this value determines the minimal length the first authentication factor " @@ -3648,19 +3882,19 @@ msgstr "" "に保存する必要がある最小の長さを決定します。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2883 +#: sssd.conf.5.xml:3008 msgid "" "This should avoid that the short PINs of a PIN based 2FA scheme are saved in " "the cache which would make them easy targets for brute-force attacks." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2894 +#: sssd.conf.5.xml:3019 msgid "account_cache_expiration (integer)" msgstr "account_cache_expiration (整数)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2897 +#: sssd.conf.5.xml:3022 msgid "" "Number of days entries are left in cache after last successful login before " "being removed during a cleanup of the cache. 0 means keep forever. The " @@ -3672,17 +3906,17 @@ msgstr "" "offline_credentials_expiration と同等以上でなければいけません。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2904 +#: sssd.conf.5.xml:3029 msgid "Default: 0 (unlimited)" msgstr "初期値: 0 (無制限)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2909 +#: sssd.conf.5.xml:3034 msgid "pwd_expiration_warning (integer)" msgstr "pwd_expiration_warning (整数)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2920 +#: sssd.conf.5.xml:3045 msgid "" "Please note that the backend server has to provide information about the " "expiration time of the password. If this information is missing, sssd " @@ -3691,17 +3925,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2927 +#: sssd.conf.5.xml:3052 msgid "Default: 7 (Kerberos), 0 (LDAP)" msgstr "初期値: 7 (Kerberos), 0 (LDAP)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2933 +#: sssd.conf.5.xml:3058 msgid "id_provider (string)" msgstr "id_provider (文字列)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2936 +#: sssd.conf.5.xml:3061 msgid "" "The identification provider used for the domain. Supported ID providers are:" msgstr "" @@ -3709,12 +3943,12 @@ msgstr "" "プロバイダーは次のとおりです:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2940 +#: sssd.conf.5.xml:3065 msgid "<quote>proxy</quote>: Support a legacy NSS provider." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2943 +#: sssd.conf.5.xml:3068 msgid "" "<quote>ldap</quote>: LDAP provider. See <citerefentry> <refentrytitle>sssd-" "ldap</refentrytitle> <manvolnum>5</manvolnum> </citerefentry> for more " @@ -3725,8 +3959,8 @@ msgstr "" "manvolnum> </citerefentry> を参照してください。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2951 sssd.conf.5.xml:3070 sssd.conf.5.xml:3129 -#: sssd.conf.5.xml:3192 +#: sssd.conf.5.xml:3076 sssd.conf.5.xml:3200 sssd.conf.5.xml:3259 +#: sssd.conf.5.xml:3322 #, fuzzy #| msgid "" #| "<quote>ipa</quote>: FreeIPA and Red Hat Enterprise Identity Management " @@ -3744,8 +3978,8 @@ msgstr "" "ください。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2960 sssd.conf.5.xml:3079 sssd.conf.5.xml:3138 -#: sssd.conf.5.xml:3201 +#: sssd.conf.5.xml:3085 sssd.conf.5.xml:3209 sssd.conf.5.xml:3268 +#: sssd.conf.5.xml:3331 msgid "" "<quote>ad</quote>: Active Directory provider. See <citerefentry> " "<refentrytitle>sssd-ad</refentrytitle> <manvolnum>5</manvolnum> </" @@ -3756,7 +3990,7 @@ msgstr "" "5</manvolnum> </citerefentry> を参照してください。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2968 +#: sssd.conf.5.xml:3093 #, fuzzy #| msgid "" #| "<quote>ipa</quote>: FreeIPA and Red Hat Enterprise Identity Management " @@ -3773,13 +4007,22 @@ msgstr "" "sssd-ipa</refentrytitle> <manvolnum>5</manvolnum> </citerefentry> を参照して" "ください。" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3101 +msgid "" +"Default: Not set (This is a mandatory setting that must be explicitly " +"defined for each configured domain)." +msgstr "" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2979 -msgid "use_fully_qualified_names (bool)" +#: sssd.conf.5.xml:3109 +#, fuzzy +#| msgid "use_fully_qualified_names (bool)" +msgid "use_fully_qualified_names (boolean)" msgstr "use_fully_qualified_names (論理値)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2982 +#: sssd.conf.5.xml:3112 msgid "" "Use the full name and domain (as formatted by the domain's full_name_format) " "as the user's login name reported to NSS." @@ -3788,7 +4031,7 @@ msgstr "" "名形式により整形されたように) を使用します。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2987 +#: sssd.conf.5.xml:3117 #, fuzzy #| msgid "" #| "If set to TRUE, all requests to this domain must use fully qualified " @@ -3807,7 +4050,7 @@ msgstr "" "んが、<command>getent passwd test@LOCAL</command> は見つけられます。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2995 +#: sssd.conf.5.xml:3125 msgid "" "NOTE: This option has no effect on netgroup lookups due to their tendency to " "include nested netgroups without qualified names. For netgroups, all domains " @@ -3815,24 +4058,26 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3002 +#: sssd.conf.5.xml:3132 msgid "" "Default: FALSE (TRUE for trusted domain/sub-domains or if " "default_domain_suffix is used)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3009 -msgid "ignore_group_members (bool)" +#: sssd.conf.5.xml:3139 +#, fuzzy +#| msgid "ignore_group_members (bool)" +msgid "ignore_group_members (boolean)" msgstr "ignore_group_members (論理値)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3012 +#: sssd.conf.5.xml:3142 msgid "Do not return group members for group lookups." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3015 +#: sssd.conf.5.xml:3145 msgid "" "If set to TRUE, the group membership attribute is not requested from the " "ldap server, and group members are not returned when processing group lookup " @@ -3844,7 +4089,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3033 +#: sssd.conf.5.xml:3163 msgid "" "Enabling this option can also make access provider checks for group " "membership significantly faster, especially for groups containing many " @@ -3852,7 +4097,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3039 sssd.conf.5.xml:3767 sssd-ldap.5.xml:401 +#: sssd.conf.5.xml:3169 sssd.conf.5.xml:3951 sssd-ldap.5.xml:401 #: sssd-ldap.5.xml:454 sssd-ldap.5.xml:529 sssd-ldap.5.xml:576 #: sssd-ldap.5.xml:599 sssd-ldap.5.xml:638 sssd-ldap.5.xml:657 #: sssd-ldap.5.xml:681 sssd-ldap.5.xml:1114 sssd-ldap.5.xml:1147 @@ -3862,12 +4107,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3049 +#: sssd.conf.5.xml:3179 msgid "auth_provider (string)" msgstr "auth_provider (文字列)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3052 +#: sssd.conf.5.xml:3182 msgid "" "The authentication provider used for the domain. Supported auth providers " "are:" @@ -3876,7 +4121,7 @@ msgstr "" "プロバイダーは次のとおりです:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3056 sssd.conf.5.xml:3122 +#: sssd.conf.5.xml:3186 sssd.conf.5.xml:3252 msgid "" "<quote>ldap</quote> for native LDAP authentication. See <citerefentry> " "<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> </" @@ -3887,7 +4132,7 @@ msgstr "" "manvolnum> </citerefentry> を参照してください。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3063 +#: sssd.conf.5.xml:3193 msgid "" "<quote>krb5</quote> for Kerberos authentication. See <citerefentry> " "<refentrytitle>sssd-krb5</refentrytitle> <manvolnum>5</manvolnum> </" @@ -3898,7 +4143,7 @@ msgstr "" "manvolnum> </citerefentry> を参照してください。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3087 +#: sssd.conf.5.xml:3217 #, fuzzy #| msgid "" #| "<quote>ldap</quote> for native LDAP authentication. See <citerefentry> " @@ -3914,18 +4159,18 @@ msgstr "" "manvolnum> </citerefentry> を参照してください。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3095 +#: sssd.conf.5.xml:3225 msgid "" "<quote>proxy</quote> for relaying authentication to some other PAM target." msgstr "<quote>proxy</quote> はいくつかの他の PAM ターゲットに認証を中継します。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3098 +#: sssd.conf.5.xml:3228 msgid "<quote>none</quote> disables authentication explicitly." msgstr "<quote>none</quote> は明示的に認証を無効化します。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3101 +#: sssd.conf.5.xml:3231 msgid "" "Default: <quote>id_provider</quote> is used if it is set and can handle " "authentication requests." @@ -3934,12 +4179,12 @@ msgstr "" "ならば、それが使用されます。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3107 +#: sssd.conf.5.xml:3237 msgid "access_provider (string)" msgstr "access_provider (文字列)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3110 +#: sssd.conf.5.xml:3240 msgid "" "The access control provider used for the domain. There are two built-in " "access providers (in addition to any included in installed backends) " @@ -3950,19 +4195,19 @@ msgstr "" "てを加えます)。内部の特別プロバイダーは次のとおりです:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3116 +#: sssd.conf.5.xml:3246 #, fuzzy #| msgid "<quote>deny</quote> always deny access." msgid "<quote>permit</quote> always allow access." msgstr "<quote>deny</quote> は常にアクセスを拒否します。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3119 +#: sssd.conf.5.xml:3249 msgid "<quote>deny</quote> always deny access." msgstr "<quote>deny</quote> は常にアクセスを拒否します。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3146 +#: sssd.conf.5.xml:3276 msgid "" "<quote>simple</quote> access control based on access or deny lists. See " "<citerefentry> <refentrytitle>sssd-simple</refentrytitle> <manvolnum>5</" @@ -3975,7 +4220,7 @@ msgstr "" "てください。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3153 +#: sssd.conf.5.xml:3283 msgid "" "<quote>krb5</quote>: .k5login based access control. See <citerefentry> " "<refentrytitle>sssd-krb5</refentrytitle> <manvolnum>5</manvolnum></" @@ -3983,22 +4228,22 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3160 +#: sssd.conf.5.xml:3290 msgid "<quote>proxy</quote> for relaying access control to another PAM module." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3163 +#: sssd.conf.5.xml:3293 msgid "Default: <quote>permit</quote>" msgstr "初期値: <quote>permit</quote>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3168 +#: sssd.conf.5.xml:3298 msgid "chpass_provider (string)" msgstr "chpass_provider (文字列)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3171 +#: sssd.conf.5.xml:3301 msgid "" "The provider which should handle change password operations for the domain. " "Supported change password providers are:" @@ -4007,7 +4252,7 @@ msgstr "" "パスワード変更プロバイダーは次のとおりです:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3176 +#: sssd.conf.5.xml:3306 msgid "" "<quote>ldap</quote> to change a password stored in a LDAP server. See " "<citerefentry> <refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</" @@ -4015,7 +4260,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3184 +#: sssd.conf.5.xml:3314 msgid "" "<quote>krb5</quote> to change the Kerberos password. See <citerefentry> " "<refentrytitle>sssd-krb5</refentrytitle> <manvolnum>5</manvolnum> </" @@ -4026,7 +4271,7 @@ msgstr "" "<manvolnum>5</manvolnum> </citerefentry> を参照してください。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3209 +#: sssd.conf.5.xml:3339 msgid "" "<quote>proxy</quote> for relaying password changes to some other PAM target." msgstr "" @@ -4034,12 +4279,12 @@ msgstr "" "します。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3213 +#: sssd.conf.5.xml:3343 msgid "<quote>none</quote> disallows password changes explicitly." msgstr "<quote>none</quote> は明示的にパスワードの変更を無効化します。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3216 +#: sssd.conf.5.xml:3346 msgid "" "Default: <quote>auth_provider</quote> is used if it is set and can handle " "change password requests." @@ -4048,19 +4293,19 @@ msgstr "" "うことができるならば、それが使用されます。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3223 +#: sssd.conf.5.xml:3353 msgid "sudo_provider (string)" msgstr "sudo_provider (文字列)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3226 +#: sssd.conf.5.xml:3356 msgid "The SUDO provider used for the domain. Supported SUDO providers are:" msgstr "" "ドメインに使用される SUDO プロバイダーです。サポートされる SUDO プロバイダー" "は次のとおりです:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3230 +#: sssd.conf.5.xml:3360 msgid "" "<quote>ldap</quote> for rules stored in LDAP. See <citerefentry> " "<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> </" @@ -4071,26 +4316,26 @@ msgstr "" "<manvolnum>5</manvolnum> </citerefentry> を参照します。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3238 +#: sssd.conf.5.xml:3368 msgid "" "<quote>ipa</quote> the same as <quote>ldap</quote> but with IPA default " "settings." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3242 +#: sssd.conf.5.xml:3372 msgid "" "<quote>ad</quote> the same as <quote>ldap</quote> but with AD default " "settings." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3246 +#: sssd.conf.5.xml:3376 msgid "<quote>none</quote> disables SUDO explicitly." msgstr "<quote>none</quote> は SUDO を明示的に無効化します。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3249 +#: sssd.conf.5.xml:3379 #, fuzzy #| msgid "" #| "Default: <quote>id_provider</quote> is used if it is set and can handle " @@ -4103,7 +4348,7 @@ msgstr "" "ならば、それが使用されます。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3253 +#: sssd.conf.5.xml:3383 msgid "" "The detailed instructions for configuration of sudo_provider are in the " "manual page <citerefentry> <refentrytitle>sssd-sudo</refentrytitle> " @@ -4114,7 +4359,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3268 +#: sssd.conf.5.xml:3398 msgid "" "<emphasis>NOTE:</emphasis> Sudo rules are periodically downloaded in the " "background unless the sudo provider is explicitly disabled. Set " @@ -4123,12 +4368,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3278 +#: sssd.conf.5.xml:3408 msgid "selinux_provider (string)" msgstr "selinux_provider (文字列)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3281 +#: sssd.conf.5.xml:3411 msgid "" "The provider which should handle loading of selinux settings. Note that this " "provider will be called right after access provider ends. Supported selinux " @@ -4136,7 +4381,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3287 +#: sssd.conf.5.xml:3417 msgid "" "<quote>ipa</quote> to load selinux settings from an IPA server. See " "<citerefentry> <refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</" @@ -4144,31 +4389,38 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3295 +#: sssd.conf.5.xml:3425 msgid "<quote>none</quote> disallows fetching selinux settings explicitly." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3298 +#: sssd.conf.5.xml:3428 +#, fuzzy +#| msgid "" +#| "Default: <quote>id_provider</quote> is used if it is set and can handle " +#| "authentication requests." msgid "" -"Default: <quote>id_provider</quote> is used if it is set and can handle " -"selinux loading requests." +"Default: the value of <quote>id_provider</quote> is used if it is set and " +"can handle selinux loading requests. Otherwise the result is the same as if " +"the selinux_provider is set to none." msgstr "" +"初期値: <quote>id_provider</quote> が設定され、認証要求を取り扱うことができる" +"ならば、それが使用されます。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3304 +#: sssd.conf.5.xml:3435 msgid "subdomains_provider (string)" msgstr "subdomains_provider (文字列)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3307 +#: sssd.conf.5.xml:3438 msgid "" "The provider which should handle fetching of subdomains. This value should " "be always the same as id_provider. Supported subdomain providers are:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3313 +#: sssd.conf.5.xml:3444 msgid "" "<quote>ipa</quote> to load a list of subdomains from an IPA server. See " "<citerefentry> <refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</" @@ -4176,7 +4428,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3322 +#: sssd.conf.5.xml:3453 msgid "" "<quote>ad</quote> to load a list of subdomains from an Active Directory " "server. See <citerefentry> <refentrytitle>sssd-ad</refentrytitle> " @@ -4185,12 +4437,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3331 +#: sssd.conf.5.xml:3462 msgid "<quote>none</quote> disallows fetching subdomains explicitly." msgstr "<quote>none</quote> はサブドメインの取り出しを明示的に無効化します。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3335 +#: sssd.conf.5.xml:3466 #, fuzzy #| msgid "" #| "Default: <quote>id_provider</quote> is used if it is set and can handle " @@ -4203,12 +4455,12 @@ msgstr "" "ならば、それが使用されます。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3341 +#: sssd.conf.5.xml:3472 msgid "session_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3344 +#: sssd.conf.5.xml:3475 msgid "" "The provider which configures and manages user session related tasks. The " "only user session task currently provided is the integration with Fleet " @@ -4216,30 +4468,30 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3351 +#: sssd.conf.5.xml:3482 msgid "<quote>ipa</quote> to allow performing user session related tasks." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3355 +#: sssd.conf.5.xml:3486 msgid "" "<quote>none</quote> does not perform any kind of user session related tasks." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3359 +#: sssd.conf.5.xml:3490 #, fuzzy #| msgid "Default: <quote>permit</quote>" msgid "Default: <quote>none</quote>." msgstr "初期値: <quote>permit</quote>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3365 +#: sssd.conf.5.xml:3496 msgid "autofs_provider (string)" msgstr "autofs_provider (文字列)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3368 +#: sssd.conf.5.xml:3499 msgid "" "The autofs provider used for the domain. Supported autofs providers are:" msgstr "" @@ -4247,7 +4499,7 @@ msgstr "" "プロバイダーは次のとおりです:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3372 +#: sssd.conf.5.xml:3503 msgid "" "<quote>ldap</quote> to load maps stored in LDAP. See <citerefentry> " "<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> </" @@ -4258,7 +4510,7 @@ msgstr "" "<manvolnum>5</manvolnum> </citerefentry> を参照してください。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3379 +#: sssd.conf.5.xml:3510 msgid "" "<quote>ipa</quote> to load maps stored in an IPA server. See <citerefentry> " "<refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</manvolnum> </" @@ -4269,7 +4521,7 @@ msgstr "" "<manvolnum>5</manvolnum> </citerefentry> を参照してください。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3387 +#: sssd.conf.5.xml:3518 msgid "" "<quote>ad</quote> to load maps stored in an AD server. See <citerefentry> " "<refentrytitle>sssd-ad</refentrytitle> <manvolnum>5</manvolnum> </" @@ -4277,12 +4529,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3396 +#: sssd.conf.5.xml:3527 msgid "<quote>none</quote> disables autofs explicitly." msgstr "<quote>none</quote> は明示的に autofs を無効にします。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3399 +#: sssd.conf.5.xml:3530 #, fuzzy #| msgid "" #| "Default: <quote>id_provider</quote> is used if it is set and can handle " @@ -4295,12 +4547,12 @@ msgstr "" "ならば、それが使用されます。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3406 +#: sssd.conf.5.xml:3537 msgid "hostid_provider (string)" msgstr "hostid_provider (文字列)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3409 +#: sssd.conf.5.xml:3540 msgid "" "The provider used for retrieving host identity information. Supported " "hostid providers are:" @@ -4309,7 +4561,7 @@ msgstr "" "hostid プロバイダーは次のとおりです:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3413 +#: sssd.conf.5.xml:3544 msgid "" "<quote>ipa</quote> to load host identity stored in an IPA server. See " "<citerefentry> <refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</" @@ -4320,12 +4572,12 @@ msgstr "" "refentrytitle> <manvolnum>5</manvolnum> </citerefentry> を参照してください。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3421 +#: sssd.conf.5.xml:3552 msgid "<quote>none</quote> disables hostid explicitly." msgstr "<quote>none</quote> は明示的に hostid を無効にします。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3424 +#: sssd.conf.5.xml:3555 #, fuzzy #| msgid "" #| "Default: <quote>id_provider</quote> is used if it is set and can handle " @@ -4338,26 +4590,26 @@ msgstr "" "ならば、それが使用されます。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3431 +#: sssd.conf.5.xml:3562 msgid "resolver_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3434 +#: sssd.conf.5.xml:3565 msgid "" "The provider which should handle hosts and networks lookups. Supported " "resolver providers are:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3438 +#: sssd.conf.5.xml:3569 msgid "" "<quote>proxy</quote> to forward lookups to another NSS library. See " "<quote>proxy_resolver_lib_name</quote>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3442 +#: sssd.conf.5.xml:3573 msgid "" "<quote>ldap</quote> to fetch hosts and networks stored in LDAP. See " "<citerefentry> <refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</" @@ -4365,7 +4617,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3449 +#: sssd.conf.5.xml:3580 msgid "" "<quote>ad</quote> to fetch hosts and networks stored in AD. See " "<citerefentry> <refentrytitle>sssd-ad</refentrytitle> <manvolnum>5</" @@ -4374,12 +4626,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3457 +#: sssd.conf.5.xml:3588 msgid "<quote>none</quote> disallows fetching hosts and networks explicitly." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3460 +#: sssd.conf.5.xml:3591 #, fuzzy #| msgid "" #| "Default: <quote>id_provider</quote> is used if it is set and can handle " @@ -4392,7 +4644,7 @@ msgstr "" "ならば、それが使用されます。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3470 +#: sssd.conf.5.xml:3601 msgid "" "Regular expression for this domain that describes how to parse the string " "containing user name and domain into these components. The \"domain\" can " @@ -4402,24 +4654,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3479 +#: sssd.conf.5.xml:3610 msgid "" "Default: <quote>^((?P<name>.+)@(?P<domain>[^@]*)|(?P<name>" "[^@]+))$</quote> which allows two different styles for user names:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:3484 sssd.conf.5.xml:3498 +#: sssd.conf.5.xml:3615 sssd.conf.5.xml:3629 msgid "username" msgstr "username" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:3487 sssd.conf.5.xml:3501 +#: sssd.conf.5.xml:3618 sssd.conf.5.xml:3632 msgid "username@domain.name" msgstr "username@domain.name" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3492 +#: sssd.conf.5.xml:3623 msgid "" "Default for the AD and IPA provider: <quote>^(((?P<domain>[^\\\\]+)\\\\" "(?P<name>.+))|((?P<name>.+)@(?P<domain>[^@]+))|((?" @@ -4428,19 +4680,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:3504 +#: sssd.conf.5.xml:3635 msgid "domain\\username" msgstr "domain\\username" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3507 +#: sssd.conf.5.xml:3638 msgid "" "While the first two correspond to the general default the third one is " "introduced to allow easy integration of users from Windows domains." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3512 +#: sssd.conf.5.xml:3643 msgid "" "The default re_expression uses the <quote>@</quote> character as a separator " "between the name and the domain. As a result of this setting the default " @@ -4450,17 +4702,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3564 +#: sssd.conf.5.xml:3695 msgid "Default: <quote>%1$s@%2$s</quote>." msgstr "初期値: <quote>%1$s@%2$s</quote>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3570 +#: sssd.conf.5.xml:3701 msgid "lookup_family_order (string)" msgstr "lookup_family_order (文字列)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3573 +#: sssd.conf.5.xml:3704 msgid "" "Provides the ability to select preferred address family to use when " "performing DNS lookups." @@ -4469,76 +4721,94 @@ msgstr "" "します。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3577 +#: sssd.conf.5.xml:3708 msgid "Supported values:" msgstr "サポートする値:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3580 +#: sssd.conf.5.xml:3711 msgid "ipv4_first: Try looking up IPv4 address, if that fails, try IPv6" msgstr "ipv4_first: IPv4 アドレスの検索を試行します。失敗すると IPv6 を試行します。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3583 +#: sssd.conf.5.xml:3714 msgid "ipv4_only: Only attempt to resolve hostnames to IPv4 addresses." msgstr "ipv4_only: ホスト名を IPv4 アドレスに名前解決することのみを試行します。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3586 +#: sssd.conf.5.xml:3717 msgid "ipv6_first: Try looking up IPv6 address, if that fails, try IPv4" msgstr "ipv6_first: IPv6 アドレスの検索を試行します。失敗すると IPv4 を試行します。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3589 +#: sssd.conf.5.xml:3720 msgid "ipv6_only: Only attempt to resolve hostnames to IPv6 addresses." msgstr "ipv6_only: ホスト名を IPv6 アドレスに名前解決することのみを試行します。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3592 +#: sssd.conf.5.xml:3723 msgid "Default: ipv4_first" msgstr "初期値: ipv4_first" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3598 +#: sssd.conf.5.xml:3729 #, fuzzy #| msgid "dns_resolver_timeout (integer)" msgid "dns_resolver_server_timeout (integer)" msgstr "dns_resolver_timeout (整数)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3601 +#: sssd.conf.5.xml:3732 msgid "" -"Defines the amount of time (in milliseconds) SSSD would try to talk to DNS " -"server before trying next DNS server." +"Defines the timeout duration (in milliseconds) SSSD waits for a DNS server " +"to respond before moving to the next one." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3606 +#: sssd.conf.5.xml:3737 msgid "" "The AD provider will use this option for the CLDAP ping timeouts as well." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3610 sssd.conf.5.xml:3630 sssd.conf.5.xml:3651 -msgid "" -"Please see the section <quote>FAILOVER</quote> for more information about " -"the service resolution." +#: sssd.conf.5.xml:3741 sssd.conf.5.xml:3777 sssd.conf.5.xml:3814 +#, fuzzy +#| msgid "" +#| "Specifies the timeout (in seconds) after which the <citerefentry> " +#| "<refentrytitle>poll</refentrytitle> <manvolnum>2</manvolnum> </" +#| "citerefentry>/<citerefentry> <refentrytitle>select</refentrytitle> " +#| "<manvolnum>2</manvolnum> </citerefentry> following a <citerefentry> " +#| "<refentrytitle>connect</refentrytitle> <manvolnum>2</manvolnum> </" +#| "citerefentry> returns in case of no activity." +msgid "" +"Please see the section <quote>FAILOVER</quote> in <citerefentry> " +"<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> </" +"citerefentry>, <citerefentry> <refentrytitle>sssd-krb5</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry>, <citerefentry> <refentrytitle>sssd-" +"ipa</refentrytitle> <manvolnum>5</manvolnum> </citerefentry> or " +"<citerefentry> <refentrytitle>sssd-ad</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry> for more information about the service resolution." msgstr "" +"<citerefentry> <refentrytitle>connect</refentrytitle> <manvolnum>2</" +"manvolnum> </citerefentry> に続けて <citerefentry> <refentrytitle>poll</" +"refentrytitle> <manvolnum>2</manvolnum> </citerefentry>/<citerefentry> " +"<refentrytitle>select</refentrytitle> <manvolnum>2</manvolnum> </" +"citerefentry> が未使用を返した後のタイムアウト(秒単位)を指定します。" #. type: Content of: <refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3615 sssd-ldap.5.xml:700 include/failover.xml:84 +#: sssd.conf.5.xml:3762 sssd-ldap.5.xml:700 include/failover.xml:84 msgid "Default: 1000" msgstr "初期値: 1000" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3621 +#: sssd.conf.5.xml:3768 #, fuzzy #| msgid "dns_resolver_timeout (integer)" msgid "dns_resolver_op_timeout (integer)" msgstr "dns_resolver_timeout (整数)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3624 +#: sssd.conf.5.xml:3771 msgid "" "Defines the amount of time (in seconds) to wait to resolve single DNS query " "(e.g. resolution of a hostname or an SRV record) before trying the next " @@ -4546,17 +4816,17 @@ msgid "" msgstr "" #. type: Content of: <refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3635 include/failover.xml:100 +#: sssd.conf.5.xml:3798 include/failover.xml:100 msgid "Default: 3" msgstr "初期値: 3" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3641 +#: sssd.conf.5.xml:3804 msgid "dns_resolver_timeout (integer)" msgstr "dns_resolver_timeout (整数)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3644 +#: sssd.conf.5.xml:3807 msgid "" "Defines the amount of time (in seconds) to wait for a reply from the " "internal fail over service before assuming that the service is unreachable. " @@ -4565,14 +4835,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3662 +#: sssd.conf.5.xml:3841 #, fuzzy #| msgid "dns_resolver_timeout (integer)" -msgid "dns_resolver_use_search_list (bool)" +msgid "dns_resolver_use_search_list (boolean)" msgstr "dns_resolver_timeout (整数)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3665 +#: sssd.conf.5.xml:3844 msgid "" "Normally, the DNS resolver searches the domain list defined in the " "\"search\" directive from the resolv.conf file. This can lead to delays in " @@ -4580,7 +4850,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3671 +#: sssd.conf.5.xml:3850 msgid "" "If fully qualified domain names (or _srv_) are used in the SSSD " "configuration, setting this option to FALSE can prevent unnecessary DNS " @@ -4588,17 +4858,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3677 +#: sssd.conf.5.xml:3856 msgid "Default: TRUE" msgstr "初期値: TRUE" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3683 +#: sssd.conf.5.xml:3862 msgid "dns_discovery_domain (string)" msgstr "dns_discovery_domain (文字列)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3686 +#: sssd.conf.5.xml:3865 msgid "" "If service discovery is used in the back end, specifies the domain part of " "the service discovery DNS query." @@ -4607,19 +4877,19 @@ msgstr "" "ドメイン部分を指定します。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3690 +#: sssd.conf.5.xml:3869 msgid "Default: Use the domain part of machine's hostname" msgstr "初期値: マシンのホスト名のドメイン部分を使用します" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3696 +#: sssd.conf.5.xml:3875 #, fuzzy #| msgid "pam_id_timeout (integer)" msgid "failover_primary_timeout (integer)" msgstr "pam_id_timeout (整数)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3699 +#: sssd.conf.5.xml:3878 msgid "" "When no primary server is available, SSSD fails over to a backup server. " "This option defines the number of seconds SSSD waits before attempting to " @@ -4627,59 +4897,72 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3706 +#: sssd.conf.5.xml:3885 msgid "Note: The minimum value is 31." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3709 +#: sssd.conf.5.xml:3888 #, fuzzy #| msgid "Default: 3" msgid "Default: 31" msgstr "初期値: 3" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3715 +#: sssd.conf.5.xml:3894 msgid "override_gid (integer)" msgstr "override_gid (整数)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3718 -msgid "Override the primary GID value with the one specified." +#: sssd.conf.5.xml:3897 +#, fuzzy +#| msgid "Override the primary GID value with the one specified." +msgid "" +"Override the primary GID value for all users in the domain with specified " +"value." msgstr "プライマリー GID の値を指定されたもので上書きします。" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3901 +#, fuzzy +#| msgid "Default: not set (SSSD will use the value retrieved from LDAP)" +msgid "" +"Default: not set (Use the primary GID value retrieved from the identity " +"provider)" +msgstr "初期値: 設定なし (SSSD は LDAP から取得された値を使用します)" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3724 +#: sssd.conf.5.xml:3908 msgid "case_sensitive (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3731 +#: sssd.conf.5.xml:3915 msgid "True" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3734 +#: sssd.conf.5.xml:3918 msgid "Case sensitive. This value is invalid for AD provider." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3740 +#: sssd.conf.5.xml:3924 msgid "False" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3742 +#: sssd.conf.5.xml:3926 msgid "Case insensitive." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3746 +#: sssd.conf.5.xml:3930 msgid "Preserving" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3749 +#: sssd.conf.5.xml:3933 msgid "" "Same as False (case insensitive), but does not lowercase names in the result " "of NSS operations. Note that name aliases (and in case of services also " @@ -4687,14 +4970,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3757 +#: sssd.conf.5.xml:3941 msgid "" "If you want to set this value for trusted domain with IPA provider, you need " "to set it on both the client and SSSD on the server." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3727 +#: sssd.conf.5.xml:3911 #, fuzzy #| msgid "" #| "The following expansions are supported: <placeholder " @@ -4707,17 +4990,47 @@ msgstr "" "id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3772 +#: sssd.conf.5.xml:3956 msgid "Default: True (False for AD provider)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3778 +#: sssd.conf.5.xml:3962 +#, fuzzy +#| msgid "ad_enable_dns_sites (boolean)" +msgid "avoid_by_id_lookups (boolean)" +msgstr "ad_enable_dns_sites (論理値)" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3965 +msgid "" +"If this option is set to 'true' SSSD will try to avoid sending lookups by ID " +"to the backend and will switch to a lookup by name if a cached object with a " +"matching ID can be found." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3971 +msgid "" +"This option can e.g. be used in cases where searches by ID are expensive on " +"the server side because of missing indexes or are not even possible, e.g. " +"due to non-reversible POSIX id-mapping." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3978 +#, fuzzy +#| msgid "Default: False (disabled)" +msgid "Default: False (True for IdP provider)" +msgstr "初期値: False (無効)" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:3984 msgid "subdomain_inherit (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3781 +#: sssd.conf.5.xml:3987 msgid "" "Specifies a list of configuration parameters that should be inherited by a " "subdomain. Please note that only selected parameters can be inherited. " @@ -4725,107 +5038,107 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3787 +#: sssd.conf.5.xml:3993 #, fuzzy #| msgid "ldap_search_timeout (integer)" msgid "ldap_search_timeout" msgstr "ldap_search_timeout (整数)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3790 +#: sssd.conf.5.xml:3996 #, fuzzy #| msgid "ldap_network_timeout (integer)" msgid "ldap_network_timeout" msgstr "ldap_network_timeout (整数)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3793 +#: sssd.conf.5.xml:3999 #, fuzzy #| msgid "ldap_opt_timeout (integer)" msgid "ldap_opt_timeout" msgstr "ldap_opt_timeout (整数)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3796 +#: sssd.conf.5.xml:4002 #, fuzzy #| msgid "ldap_connection_expire_timeout (integer)" msgid "ldap_offline_timeout" msgstr "ldap_connection_expire_timeout (整数)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3799 +#: sssd.conf.5.xml:4005 msgid "ldap_purge_cache_timeout" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3802 +#: sssd.conf.5.xml:4008 #, fuzzy #| msgid "ldap_purge_cache_timeout (integer)" msgid "ldap_purge_cache_offset" msgstr "ldap_purge_cache_timeout (整数)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3805 +#: sssd.conf.5.xml:4011 msgid "" "ldap_krb5_keytab (the value of krb5_keytab will be used if ldap_krb5_keytab " "is not set explicitly)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3809 +#: sssd.conf.5.xml:4015 #, fuzzy #| msgid "ldap_krb5_ticket_lifetime (integer)" msgid "ldap_krb5_ticket_lifetime" msgstr "ldap_krb5_ticket_lifetime (整数)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3812 +#: sssd.conf.5.xml:4018 #, fuzzy #| msgid "ldap_connection_expire_timeout (integer)" msgid "ldap_connection_expire_timeout" msgstr "ldap_connection_expire_timeout (整数)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3815 +#: sssd.conf.5.xml:4021 #, fuzzy #| msgid "ldap_connection_expire_timeout (integer)" msgid "ldap_connection_expire_offset" msgstr "ldap_connection_expire_timeout (整数)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3818 +#: sssd.conf.5.xml:4024 #, fuzzy #| msgid "ldap_connection_expire_timeout (integer)" msgid "ldap_connection_idle_timeout" msgstr "ldap_connection_expire_timeout (整数)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3821 sssd-ldap.5.xml:446 +#: sssd.conf.5.xml:4027 sssd-ldap.5.xml:446 msgid "ldap_use_tokengroups" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3824 +#: sssd.conf.5.xml:4030 msgid "ldap_user_principal" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3827 +#: sssd.conf.5.xml:4033 msgid "ignore_group_members" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3830 +#: sssd.conf.5.xml:4036 msgid "auto_private_groups" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3833 +#: sssd.conf.5.xml:4039 msgid "case_sensitive" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:3838 +#: sssd.conf.5.xml:4044 #, no-wrap msgid "" "subdomain_inherit = ldap_purge_cache_timeout\n" @@ -4833,27 +5146,27 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3845 +#: sssd.conf.5.xml:4051 msgid "Note: This option only works with the IPA and AD provider." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3852 +#: sssd.conf.5.xml:4058 msgid "subdomain_homedir (string)" msgstr "subdomain_homedir (文字列)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3863 +#: sssd.conf.5.xml:4069 msgid "%F" msgstr "%F" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3864 +#: sssd.conf.5.xml:4070 msgid "flat (NetBIOS) name of a subdomain." msgstr "サブドメインのフラット (NetBIOS) 名。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3855 +#: sssd.conf.5.xml:4061 msgid "" "Use this homedir as default value for all subdomains within this domain in " "IPA AD trust. See <emphasis>override_homedir</emphasis> for info about " @@ -4863,55 +5176,55 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3869 +#: sssd.conf.5.xml:4075 msgid "" "The value can be overridden by <emphasis>override_homedir</emphasis> option." msgstr "値は <emphasis>override_homedir</emphasis> オプションにより上書きできます。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3873 +#: sssd.conf.5.xml:4079 msgid "Default: <filename>/home/%d/%u</filename>" msgstr "初期値: <filename>/home/%d/%u</filename>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3878 +#: sssd.conf.5.xml:4084 msgid "realmd_tags (string)" msgstr "realmd_tags (文字列)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3881 +#: sssd.conf.5.xml:4087 msgid "" "Various tags stored by the realmd configuration service for this domain." msgstr "このドメインのための realmd 設定サービスによって格納された様々なタグ。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3887 +#: sssd.conf.5.xml:4093 msgid "cached_auth_timeout (int)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3890 +#: sssd.conf.5.xml:4096 msgid "" -"Specifies time in seconds since last successful online authentication for " -"which user will be authenticated using cached credentials while SSSD is in " -"the online mode. If the credentials are incorrect, SSSD falls back to online " -"authentication." +"Specifies the number of seconds since the last successful online " +"authentication during which SSSD will authenticate users via cached " +"credentials, even while online. If the cached authentication fails, SSSD " +"immediately falls back to online authentication." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3898 +#: sssd.conf.5.xml:4103 msgid "" "This option's value is inherited by all trusted domains. At the moment it is " "not possible to set a different value per trusted domain." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3903 +#: sssd.conf.5.xml:4108 msgid "Special value 0 implies that this feature is disabled." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3907 +#: sssd.conf.5.xml:4112 msgid "" "Please note that if <quote>cached_auth_timeout</quote> is longer than " "<quote>pam_id_timeout</quote> then the back end could be called to handle " @@ -4919,14 +5232,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3918 +#: sssd.conf.5.xml:4123 #, fuzzy #| msgid "ldap_pwd_policy (string)" msgid "local_auth_policy (string)" msgstr "ldap_pwd_policy (文字列)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3921 +#: sssd.conf.5.xml:4126 msgid "" "Local authentication methods policy. Some backends (i.e. LDAP, proxy " "provider) only support a password based authentication, while others can " @@ -4938,7 +5251,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3933 +#: sssd.conf.5.xml:4138 msgid "" "There are three possible values for this option: match, only, enable. " "<quote>match</quote> is used to match offline and online states for Kerberos " @@ -4950,7 +5263,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3946 +#: sssd.conf.5.xml:4151 msgid "" "The following table shows which authentication methods, if configured " "properly, are currently enabled or disabled for each backend, with the " @@ -4958,44 +5271,49 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> -#: sssd.conf.5.xml:3959 +#: sssd.conf.5.xml:4164 #, fuzzy #| msgid "ldap_pwd_policy (string)" msgid "local_auth_policy = match (default)" msgstr "ldap_pwd_policy (文字列)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> -#: sssd.conf.5.xml:3960 +#: sssd.conf.5.xml:4165 msgid "Passkey" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> -#: sssd.conf.5.xml:3961 +#: sssd.conf.5.xml:4166 msgid "Smartcard" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:3964 sssd-ldap.5.xml:228 +#: sssd.conf.5.xml:4169 sssd-ldap.5.xml:228 msgid "IPA" msgstr "IPA" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry><para> +#: sssd.conf.5.xml:4169 sssd.conf.5.xml:4170 sssd.conf.5.xml:4173 +msgid "enabled" +msgstr "" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:3967 sssd-ldap.5.xml:233 +#: sssd.conf.5.xml:4172 sssd-ldap.5.xml:233 msgid "AD" msgstr "AD" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry><para> -#: sssd.conf.5.xml:3967 sssd.conf.5.xml:3970 sssd.conf.5.xml:3971 +#: sssd.conf.5.xml:4172 sssd.conf.5.xml:4175 sssd.conf.5.xml:4176 msgid "disabled" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry> -#: sssd.conf.5.xml:3970 +#: sssd.conf.5.xml:4175 msgid "LDAP" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3975 +#: sssd.conf.5.xml:4180 msgid "" "Please note that if local Smartcard authentication is enabled and a " "Smartcard is present, Smartcard authentication will be preferred over the " @@ -5004,7 +5322,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:3987 +#: sssd.conf.5.xml:4192 #, no-wrap msgid "" "[domain/shadowutils]\n" @@ -5015,7 +5333,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3983 +#: sssd.conf.5.xml:4188 msgid "" "The following configuration example allows local users to authenticate " "locally using any enabled method (i.e. smartcard, passkey). <placeholder " @@ -5023,31 +5341,31 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3995 +#: sssd.conf.5.xml:4200 #, fuzzy #| msgid "Default: cn" msgid "Default: match" msgstr "初期値: cn" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4000 +#: sssd.conf.5.xml:4205 msgid "auto_private_groups (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4006 +#: sssd.conf.5.xml:4211 msgid "true" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4009 +#: sssd.conf.5.xml:4214 msgid "" "Create user's private group unconditionally from user's UID number. The GID " "number is ignored in this case." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4013 +#: sssd.conf.5.xml:4218 msgid "" "NOTE: Because the GID number and the user private group are inferred from " "the UID number, it is not supported to have multiple entries with the same " @@ -5056,24 +5374,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4022 +#: sssd.conf.5.xml:4227 msgid "false" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4025 +#: sssd.conf.5.xml:4230 msgid "" "Always use the user's primary GID number. The GID number must refer to a " "group object in the LDAP database." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4031 +#: sssd.conf.5.xml:4236 msgid "hybrid" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4034 +#: sssd.conf.5.xml:4239 msgid "" "A primary group is autogenerated for user entries whose UID and GID numbers " "have the same value and at the same time the GID number does not correspond " @@ -5083,14 +5401,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4047 +#: sssd.conf.5.xml:4252 msgid "" "If the UID and GID of a user are different, then the GID must correspond to " "a group entry, otherwise the GID is simply not resolvable." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4054 +#: sssd.conf.5.xml:4259 msgid "" "This feature is useful for environments that wish to stop maintaining a " "separate group objects for the user private groups, but also wish to retain " @@ -5098,14 +5416,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4003 +#: sssd.conf.5.xml:4208 msgid "" "This option takes any of three available values: <placeholder " "type=\"variablelist\" id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4066 +#: sssd.conf.5.xml:4271 msgid "" "For the LDAP based id providers (LDAP, IPA and AD) the default for the " "configured domain is typically False because the sources have the concept of " @@ -5115,14 +5433,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4075 +#: sssd.conf.5.xml:4280 msgid "" "For subdomains, the default value is False for subdomains that use assigned " "POSIX IDs and True for subdomains that use automatic ID-mapping." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:4083 +#: sssd.conf.5.xml:4288 #, no-wrap msgid "" "[domain/forest.domain/sub.domain]\n" @@ -5130,7 +5448,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:4089 +#: sssd.conf.5.xml:4294 #, no-wrap msgid "" "[domain/forest.domain]\n" @@ -5139,7 +5457,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4080 +#: sssd.conf.5.xml:4285 msgid "" "The value of auto_private_groups can either be set per subdomains in a " "subsection, for example: <placeholder type=\"programlisting\" id=\"0\"/> or " @@ -5148,7 +5466,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:2503 +#: sssd.conf.5.xml:2549 msgid "" "These configuration options can be present in a domain configuration " "section, that is, in a section called <quote>[domain/<replaceable>NAME</" @@ -5159,17 +5477,17 @@ msgstr "" "type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4104 +#: sssd.conf.5.xml:4309 msgid "proxy_pam_target (string)" msgstr "proxy_pam_target (文字列)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4107 +#: sssd.conf.5.xml:4312 msgid "The proxy target PAM proxies to." msgstr "中継するプロキシターゲット PAM です。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4110 +#: sssd.conf.5.xml:4315 #, fuzzy #| msgid "" #| "Default: not set by default, you have to take an existing pam " @@ -5183,12 +5501,12 @@ msgstr "" "をここに追加する必要があります。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4120 +#: sssd.conf.5.xml:4325 msgid "proxy_lib_name (string)" msgstr "proxy_lib_name (文字列)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4123 +#: sssd.conf.5.xml:4328 msgid "" "The name of the NSS library to use in proxy domains. The NSS functions " "searched for in the library are in the form of _nss_$(libName)_$(function), " @@ -5199,12 +5517,12 @@ msgstr "" "_nss_files_getpwent です。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4133 +#: sssd.conf.5.xml:4338 msgid "proxy_resolver_lib_name (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4136 +#: sssd.conf.5.xml:4341 msgid "" "The name of the NSS library to use for hosts and networks lookups in proxy " "domains. The NSS functions searched for in the library are in the form of " @@ -5212,12 +5530,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4147 +#: sssd.conf.5.xml:4352 msgid "proxy_fast_alias (boolean)" msgstr "proxy_fast_alias (論理値)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4150 +#: sssd.conf.5.xml:4355 msgid "" "When a user or group is looked up by name in the proxy provider, a second " "lookup by ID is performed to \"canonicalize\" the name in case the requested " @@ -5226,12 +5544,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4164 +#: sssd.conf.5.xml:4369 msgid "proxy_max_children (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4167 +#: sssd.conf.5.xml:4372 msgid "" "This option specifies the number of pre-forked proxy children. It is useful " "for high-load SSSD environments where sssd may run out of available child " @@ -5239,7 +5557,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4100 +#: sssd.conf.5.xml:4305 msgid "" "Options valid for proxy domains. <placeholder type=\"variablelist\" " "id=\"0\"/>" @@ -5248,12 +5566,12 @@ msgstr "" "type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:4183 +#: sssd.conf.5.xml:4388 msgid "Application domains" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:4185 +#: sssd.conf.5.xml:4390 msgid "" "SSSD, with its D-Bus interface (see <citerefentry> <refentrytitle>sssd-ifp</" "refentrytitle> <manvolnum>5</manvolnum> </citerefentry>) is appealing to " @@ -5270,7 +5588,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:4205 +#: sssd.conf.5.xml:4410 msgid "" "Please note that the application domain must still be explicitly enabled in " "the <quote>domains</quote> parameter so that the lookup order between the " @@ -5278,17 +5596,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><title> -#: sssd.conf.5.xml:4211 +#: sssd.conf.5.xml:4416 msgid "Application domain parameters" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4213 +#: sssd.conf.5.xml:4418 msgid "inherit_from (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4216 +#: sssd.conf.5.xml:4421 msgid "" "The SSSD POSIX-type domain the application domain inherits all settings " "from. The application domain can moreover add its own settings to the " @@ -5297,7 +5615,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:4230 +#: sssd.conf.5.xml:4435 msgid "" "The following example illustrates the use of an application domain. In this " "setup, the POSIX domain is connected to an LDAP server and is used by the OS " @@ -5307,7 +5625,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><programlisting> -#: sssd.conf.5.xml:4238 +#: sssd.conf.5.xml:4443 #, no-wrap msgid "" "[sssd]\n" @@ -5327,12 +5645,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:4258 +#: sssd.conf.5.xml:4463 msgid "TRUSTED DOMAIN SECTION" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4260 +#: sssd.conf.5.xml:4465 msgid "" "Some options used in the domain section can also be used in the trusted " "domain section, that is, in a section called <quote>[domain/" @@ -5343,69 +5661,79 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4267 +#: sssd.conf.5.xml:4472 msgid "ldap_search_base," msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4268 +#: sssd.conf.5.xml:4473 msgid "ldap_user_search_base," msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4269 +#: sssd.conf.5.xml:4474 msgid "ldap_group_search_base," msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4270 +#: sssd.conf.5.xml:4475 msgid "ldap_netgroup_search_base," msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4271 +#: sssd.conf.5.xml:4476 msgid "ldap_service_search_base," msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4272 +#: sssd.conf.5.xml:4477 msgid "ldap_sasl_mech," msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4273 +#: sssd.conf.5.xml:4478 msgid "ad_server," msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4274 +#: sssd.conf.5.xml:4479 msgid "ad_backup_server," msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4275 +#: sssd.conf.5.xml:4480 msgid "ad_site," msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:4276 sssd-ipa.5.xml:934 +#: sssd.conf.5.xml:4481 sssd-ipa.5.xml:929 msgid "use_fully_qualified_names" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4280 +#: sssd.conf.5.xml:4482 +msgid "pam_gssapi_services" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:4483 +msgid "pam_gssapi_check_upn" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:4485 msgid "" "For more details about these options see their individual description in the " "manual page." msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:4286 +#: sssd.conf.5.xml:4491 msgid "CERTIFICATE MAPPING SECTION" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4288 +#: sssd.conf.5.xml:4493 msgid "" "To allow authentication with Smartcards and certificates SSSD must be able " "to map certificates to users. This can be done by adding the full " @@ -5418,7 +5746,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4302 +#: sssd.conf.5.xml:4507 msgid "" "To make the mapping more flexible mapping and matching rules were added to " "SSSD (see <citerefentry> <refentrytitle>sss-certmap</refentrytitle> " @@ -5426,7 +5754,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4311 +#: sssd.conf.5.xml:4516 msgid "" "A mapping and matching rule can be added to the SSSD configuration in a " "section on its own with a name like <quote>[certmap/" @@ -5435,55 +5763,50 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4318 +#: sssd.conf.5.xml:4523 msgid "matchrule (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4321 +#: sssd.conf.5.xml:4526 msgid "" "Only certificates from the Smartcard which matches this rule will be " "processed, all others are ignored." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4325 +#: sssd.conf.5.xml:4530 msgid "" "Default: KRB5:<EKU>clientAuth, i.e. only certificates which have the " "Extended Key Usage <quote>clientAuth</quote>" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4332 +#: sssd.conf.5.xml:4537 msgid "maprule (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4335 +#: sssd.conf.5.xml:4540 msgid "Defines how the user is found for a given certificate." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:4341 +#: sssd.conf.5.xml:4546 msgid "" "LDAP:(userCertificate;binary={cert!bin}) for LDAP based providers like " "<quote>ldap</quote>, <quote>AD</quote> or <quote>ipa</quote>." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:4347 +#: sssd.conf.5.xml:4552 msgid "" "If maprule is not set and provider is <quote>proxy</quote>, the RULE_NAME " "name is assumed to be the name of the matching user." msgstr "" -#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4357 -msgid "domains (string)" -msgstr "" - #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4360 +#: sssd.conf.5.xml:4565 msgid "" "Comma separated list of domain names the rule should be applied. By default " "a rule is only valid in the domain configured in sssd.conf. If the provider " @@ -5492,17 +5815,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4367 +#: sssd.conf.5.xml:4572 msgid "Default: the configured domain in sssd.conf" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4372 +#: sssd.conf.5.xml:4577 msgid "priority (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4375 +#: sssd.conf.5.xml:4580 msgid "" "Unsigned integer value defining the priority of the rule. The higher the " "number the lower the priority. <quote>0</quote> stands for the highest " @@ -5510,17 +5833,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4381 +#: sssd.conf.5.xml:4586 msgid "Default: the lowest priority" msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:4389 +#: sssd.conf.5.xml:4594 msgid "PROMPTING CONFIGURATION SECTION" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4391 +#: sssd.conf.5.xml:4596 msgid "" "If a special file (<filename>/var/lib/sss/pubconf/pam_preauth_available</" "filename>) exists SSSD's PAM module pam_sss will ask SSSD to figure out " @@ -5530,7 +5853,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4399 +#: sssd.conf.5.xml:4604 msgid "" "With the growing number of authentication methods and the possibility that " "there are multiple ones for a single user the heuristic used by pam_sss to " @@ -5539,59 +5862,59 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4411 +#: sssd.conf.5.xml:4616 msgid "[prompting/password]" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4414 +#: sssd.conf.5.xml:4619 msgid "password_prompt" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4415 +#: sssd.conf.5.xml:4620 msgid "to change the string of the password prompt" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4413 +#: sssd.conf.5.xml:4618 msgid "" "to configure password prompting, allowed options are: <placeholder " "type=\"variablelist\" id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4423 +#: sssd.conf.5.xml:4628 msgid "[prompting/2fa]" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4427 +#: sssd.conf.5.xml:4632 msgid "first_prompt" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4428 +#: sssd.conf.5.xml:4633 msgid "to change the string of the prompt for the first factor" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4431 +#: sssd.conf.5.xml:4636 msgid "second_prompt" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4432 +#: sssd.conf.5.xml:4637 msgid "to change the string of the prompt for the second factor" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4435 +#: sssd.conf.5.xml:4640 msgid "single_prompt" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4436 +#: sssd.conf.5.xml:4641 msgid "" "boolean value, if True there will be only a single prompt using the value of " "first_prompt where it is expected that both factors are entered as a single " @@ -5600,7 +5923,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4425 +#: sssd.conf.5.xml:4630 msgid "" "to configure two-factor authentication prompting, allowed options are: " "<placeholder type=\"variablelist\" id=\"0\"/> If the second factor is " @@ -5609,7 +5932,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4449 +#: sssd.conf.5.xml:4654 msgid "" "Some clients, such as SSH with 'PasswordAuthentication yes', generate their " "own prompts and do not use prompts provided by SSSD or other PAM modules. " @@ -5620,79 +5943,169 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4464 +#: sssd.conf.5.xml:4669 msgid "[prompting/passkey]" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:4470 sssd-ad.5.xml:1022 +#: sssd.conf.5.xml:4675 sssd.conf.5.xml:4719 sssd-ad.5.xml:1027 msgid "interactive" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4472 +#: sssd.conf.5.xml:4677 +msgid "" +"boolean value, if True prompt a message and wait before testing the presence " +"of a passkey device. Recommended if your device doesn’t have a tactile " +"trigger." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4685 sssd.conf.5.xml:4735 +msgid "interactive_prompt" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4687 sssd.conf.5.xml:4737 +msgid "to change the message of the interactive prompt." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4692 +msgid "touch" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4694 +msgid "" +"boolean value, if True prompt a message to remind the user to touch the " +"device." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4700 +msgid "touch_prompt" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4702 +msgid "to change the message of the touch prompt." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4671 +#, fuzzy +#| msgid "" +#| "The following expansions are supported: <placeholder " +#| "type=\"variablelist\" id=\"0\"/>" +msgid "" +"to configure passkey authentication prompting, allowed options are: " +"<placeholder type=\"variablelist\" id=\"0\"/>" +msgstr "" +"以下の拡張モジュールがサポートされます: <placeholder type=\"variablelist\" " +"id=\"0\"/>" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4713 +msgid "[prompting/oauth2]" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4721 +msgid "" +"boolean value, if True prompt a message after asking the user to " +"authenticate, and wait before requesting the access token." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4725 msgid "" -"boolean value, if True prompt a message and wait before testing the presence " -"of a passkey device. Recommended if your device doesn’t have a tactile " -"trigger." +"If False, make sure to set the <quote>idp_request_timeout</quote> " +"sufficiently high, to give the user time to authenticate." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4715 +#, fuzzy +#| msgid "" +#| "The following expansions are supported: <placeholder " +#| "type=\"variablelist\" id=\"0\"/>" +msgid "" +"to configure OAuth2 authentication prompting, allowed options are: " +"<placeholder type=\"variablelist\" id=\"0\"/>" +msgstr "" +"以下の拡張モジュールがサポートされます: <placeholder type=\"variablelist\" " +"id=\"0\"/>" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4748 +msgid "[prompting/cert_auth]" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4480 -msgid "interactive_prompt" +#: sssd.conf.5.xml:4754 +msgid "pin_prompt" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4482 -msgid "to change the message of the interactive prompt." +#: sssd.conf.5.xml:4756 +msgid "" +"to change the message which asks the user to enter the PIN at the computer " +"keyboard. At the end of the message the token name is printed." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4487 -msgid "touch" +#: sssd.conf.5.xml:4764 +msgid "keypad_prompt" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4489 +#: sssd.conf.5.xml:4766 msgid "" -"boolean value, if True prompt a message to remind the user to touch the " -"device." +"to change the message which asks the user to enter the PIN at keypad of the " +"Smartcard reader. At the end of the message the token name is printed." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4495 -msgid "touch_prompt" -msgstr "" +#: sssd.conf.5.xml:4774 +#, fuzzy +#| msgid "username" +msgid "user_name_hint" +msgstr "username" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4497 -msgid "to change the message of the touch prompt." +#: sssd.conf.5.xml:4776 +msgid "" +"boolean value, if True ask for a user name if no name was given before and " +"the found certificate can be mapped to more than one user." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4466 +#: sssd.conf.5.xml:4750 #, fuzzy #| msgid "" #| "The following expansions are supported: <placeholder " #| "type=\"variablelist\" id=\"0\"/>" msgid "" -"to configure passkey authentication prompting, allowed options are: " +"to configure Smartcard authentication prompting, allowed options are: " "<placeholder type=\"variablelist\" id=\"0\"/>" msgstr "" "以下の拡張モジュールがサポートされます: <placeholder type=\"variablelist\" " "id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4406 +#: sssd.conf.5.xml:4611 msgid "" "Each supported authentication method has its own configuration subsection " "under <quote>[prompting/...]</quote>. Currently there are: <placeholder " "type=\"variablelist\" id=\"0\"/> <placeholder type=\"variablelist\" id=\"1\"/" -"> <placeholder type=\"variablelist\" id=\"2\"/>" +"> <placeholder type=\"variablelist\" id=\"2\"/> <placeholder " +"type=\"variablelist\" id=\"3\"/> <placeholder type=\"variablelist\" id=\"4\"/" +">" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4508 +#: sssd.conf.5.xml:4792 msgid "" "It is possible to add a subsection for specific PAM services, e.g. " "<quote>[prompting/password/sshd]</quote> to individual change the prompting " @@ -5700,12 +6113,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:4515 pam_sss_gss.8.xml:157 idmap_sss.8.xml:43 +#: sssd.conf.5.xml:4799 pam_sss_gss.8.xml:157 idmap_sss.8.xml:43 msgid "EXAMPLES" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd.conf.5.xml:4521 +#: sssd.conf.5.xml:4805 #, fuzzy, no-wrap #| msgid "" #| "[sssd]\n" @@ -5783,7 +6196,7 @@ msgstr "" "enumerate = False\n" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4517 +#: sssd.conf.5.xml:4801 msgid "" "1. The following example shows a typical SSSD config. It does not describe " "configuration of the domains themselves - refer to documentation on " @@ -5792,7 +6205,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd.conf.5.xml:4553 +#: sssd.conf.5.xml:4837 #, no-wrap msgid "" "[domain/ipa.com/child.ad.com]\n" @@ -5800,7 +6213,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4547 +#: sssd.conf.5.xml:4831 msgid "" "2. The following example shows configuration of IPA AD trust where the AD " "forest consists of two domains in a parent-child structure. Suppose IPA " @@ -5811,7 +6224,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd.conf.5.xml:4564 +#: sssd.conf.5.xml:4848 #, no-wrap msgid "" "[certmap/my.domain/rule_name]\n" @@ -5822,7 +6235,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4558 +#: sssd.conf.5.xml:4842 msgid "" "3. The following example shows the configuration of a certificate mapping " "rule. It is valid for the configured domain <quote>my.domain</quote> and " @@ -6050,7 +6463,7 @@ msgid "" "defaultNamingContext does not exist or has an empty value namingContexts is " "used. The namingContexts attribute must have a single value with the DN of " "the search base of the LDAP server to make this work. Multiple values are " -"are not supported." +"not supported." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> @@ -6368,8 +6781,8 @@ msgstr "" "ます。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap.5.xml:472 sssd-ipa.5.xml:506 sssd-ipa.5.xml:525 sssd-ipa.5.xml:544 -#: sssd-ipa.5.xml:563 +#: sssd-ldap.5.xml:472 sssd-ipa.5.xml:501 sssd-ipa.5.xml:520 sssd-ipa.5.xml:539 +#: sssd-ipa.5.xml:558 msgid "" "See <quote>ldap_search_base</quote> for information about configuring " "multiple search bases." @@ -6378,7 +6791,7 @@ msgstr "" "してください。" #. type: Content of: <listitem><para> -#: sssd-ldap.5.xml:477 sssd-ipa.5.xml:511 include/ldap_search_bases.xml:27 +#: sssd-ldap.5.xml:477 sssd-ipa.5.xml:506 include/ldap_search_bases.xml:27 msgid "Default: the value of <emphasis>ldap_search_base</emphasis>" msgstr "初期値: <emphasis>ldap_search_base</emphasis> の値" @@ -6519,7 +6932,7 @@ msgid "" "closed early to ensure that a new query cannot require the connection to " "remain open past its expiration. This implies that connections will always " "be closed immediately and will never be reused if " -"<emphasis>ldap_connection_expire_timeout <= ldap_opt_timout</emphasis>" +"<emphasis>ldap_connection_expire_timeout <= ldap_opt_timeout</emphasis>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> @@ -6714,8 +7127,10 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:831 -msgid "ldap_ignore_unreadable_references (bool)" -msgstr "" +#, fuzzy +#| msgid "ldap_force_upper_case_realm (boolean)" +msgid "ldap_ignore_unreadable_references (boolean)" +msgstr "ldap_force_upper_case_realm (論理値)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:834 @@ -7075,7 +7490,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap.5.xml:1152 sssd-ad.5.xml:1267 +#: sssd-ldap.5.xml:1152 sssd-ad.5.xml:1260 msgid "Default: 86400 (24 hours)" msgstr "初期値: 86400 (24 時間)" @@ -7119,7 +7534,7 @@ msgstr "" "quote> を使用するよう設定ファイルを移行することが推奨されます。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ldap.5.xml:1187 sssd-ipa.5.xml:575 sssd-krb5.5.xml:103 +#: sssd-ldap.5.xml:1187 sssd-ipa.5.xml:570 sssd-krb5.5.xml:103 msgid "krb5_realm (string)" msgstr "krb5_realm (文字列)" @@ -7299,7 +7714,9 @@ msgstr "初期値: 設定されていません、つまりサービス検索が #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1339 -msgid "ldap_chpass_update_last_change (bool)" +#, fuzzy +#| msgid "ldap_chpass_update_last_change (bool)" +msgid "ldap_chpass_update_last_change (boolean)" msgstr "ldap_chpass_update_last_change (論理値)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> @@ -7460,7 +7877,7 @@ msgid "ldap_access_order (string)" msgstr "ldap_access_order (文字列)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap.5.xml:1470 sssd-ipa.5.xml:405 +#: sssd-ldap.5.xml:1470 sssd-ipa.5.xml:400 msgid "Comma separated list of access control options. Allowed values are:" msgstr "アクセス制御オプションのカンマ区切り一覧です。許可される値は次のとおりです:" @@ -7505,7 +7922,7 @@ msgid "<emphasis>expire</emphasis>: use ldap_account_expire_policy" msgstr "<emphasis>expire</emphasis>: ldap_account_expire_policy を使用します" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap.5.xml:1515 sssd-ipa.5.xml:413 +#: sssd-ldap.5.xml:1515 sssd-ipa.5.xml:408 msgid "" "<emphasis>pwd_expire_policy_reject, pwd_expire_policy_warn, " "pwd_expire_policy_renew: </emphasis> These options are useful if users are " @@ -7515,24 +7932,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap.5.xml:1525 sssd-ipa.5.xml:423 +#: sssd-ldap.5.xml:1525 sssd-ipa.5.xml:418 msgid "" "The difference between these options is the action taken if user password is " "expired:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ldap.5.xml:1530 sssd-ipa.5.xml:428 +#: sssd-ldap.5.xml:1530 sssd-ipa.5.xml:423 msgid "pwd_expire_policy_reject - user is denied to log in," msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ldap.5.xml:1536 sssd-ipa.5.xml:434 +#: sssd-ldap.5.xml:1536 sssd-ipa.5.xml:429 msgid "pwd_expire_policy_warn - user is still able to log in," msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ldap.5.xml:1542 sssd-ipa.5.xml:440 +#: sssd-ldap.5.xml:1542 sssd-ipa.5.xml:435 msgid "" "pwd_expire_policy_renew - user is prompted to change their password " "immediately." @@ -8102,8 +8519,8 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd-ldap.5.xml:2032 sssd-simple.5.xml:169 sssd-ipa.5.xml:984 -#: sssd-ad.5.xml:1470 sssd-idp.5.xml:248 sssd-krb5.5.xml:483 +#: sssd-ldap.5.xml:2032 sssd-simple.5.xml:169 sssd-ipa.5.xml:979 +#: sssd-ad.5.xml:1463 sssd-idp.5.xml:343 sssd-krb5.5.xml:483 #: sss_rpcidmapd.5.xml:98 sssd-session-recording.5.xml:176 msgid "EXAMPLE" msgstr "例" @@ -8134,7 +8551,7 @@ msgstr "" #. type: Content of: <refsect1><refsect2><para> #: sssd-ldap.5.xml:2039 sssd-ldap.5.xml:2057 sssd-simple.5.xml:177 -#: sssd-ipa.5.xml:992 sssd-ad.5.xml:1478 sssd-sudo.5.xml:56 sssd-krb5.5.xml:492 +#: sssd-ipa.5.xml:987 sssd-ad.5.xml:1471 sssd-sudo.5.xml:56 sssd-krb5.5.xml:492 #: sssd-session-recording.5.xml:182 include/ldap_id_mapping.xml:105 msgid "<placeholder type=\"programlisting\" id=\"0\"/>" msgstr "<placeholder type=\"programlisting\" id=\"0\"/>" @@ -8169,7 +8586,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><title> #: sssd-ldap.5.xml:2073 sssd_krb5_locator_plugin.8.xml:83 sssd-simple.5.xml:189 -#: sssd-ad.5.xml:1493 sssd.8.xml:270 sss_seed.8.xml:163 +#: sssd-ad.5.xml:1486 sssd.8.xml:270 sss_seed.8.xml:163 msgid "NOTES" msgstr "注記" @@ -8707,7 +9124,7 @@ msgstr "" #: pam_sss.8.xml:434 msgid "" "No authentication method was found by Kerberos. This might happen if the " -"user has a Smartcard assigned but the pkint plugin is not available on the " +"user has a Smartcard assigned but the pkinit plugin is not available on the " "client." msgstr "" @@ -9155,6 +9572,23 @@ msgid "" "first DNS resolving failure." msgstr "" +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_locator_plugin.8.xml:106 +msgid "" +"If the environment variable SSSD_KRB5_LOCATOR_KDC_ADDRESS is set to a KDC " +"address the plugin will use this address instead of reading the kdcinfo " +"file. The address format is the same as in the kdcinfo file (see above)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_locator_plugin.8.xml:112 +msgid "" +"If the environment variable SSSD_KRB5_LOCATOR_KPASSWD_ADDRESS is set to a " +"kpasswd server address the plugin will use this address instead of reading " +"the kpasswdinfo file. The address format is the same as in the kpasswdinfo " +"file (see above)." +msgstr "" + #. type: Content of: <reference><refentry><refnamediv><refname> #: sssd-simple.5.xml:10 sssd-simple.5.xml:16 msgid "sssd-simple" @@ -10613,7 +11047,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:129 sssd-ad.5.xml:1161 +#: sssd-ipa.5.xml:129 sssd-ad.5.xml:1166 msgid "dyndns_update (boolean)" msgstr "dyndns_update (論理値)" @@ -10627,23 +11061,13 @@ msgid "" "quote> option." msgstr "" -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:141 sssd-ad.5.xml:1175 -msgid "" -"NOTE: On older systems (such as RHEL 5), for this behavior to work reliably, " -"the default Kerberos realm must be set properly in /etc/krb5.conf" -msgstr "" -"注: (RHEL5 のような) 古いシステムにおいて、この動作が正しく機能するためには、" -"デフォルトの Kerberos レルムが /etc/krb5.conf において正しく設定されている必" -"要があります" - #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:152 sssd-ad.5.xml:1186 +#: sssd-ipa.5.xml:147 sssd-ad.5.xml:1186 msgid "dyndns_ttl (integer)" msgstr "dyndns_ttl (整数)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:155 sssd-ad.5.xml:1189 +#: sssd-ipa.5.xml:150 sssd-ad.5.xml:1189 msgid "" "The TTL to apply to the client DNS record when updating it. If " "dyndns_update is false this has no effect. This will override the TTL " @@ -10651,17 +11075,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:160 +#: sssd-ipa.5.xml:155 msgid "Default: 1200 (seconds)" msgstr "初期値: 1200 (秒)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:166 sssd-ad.5.xml:1200 +#: sssd-ipa.5.xml:161 sssd-ad.5.xml:1200 msgid "dyndns_iface (string)" msgstr "dyndns_iface (文字列)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:169 sssd-ad.5.xml:1203 +#: sssd-ipa.5.xml:164 sssd-ad.5.xml:1203 msgid "" "Optional. Applicable only when dyndns_update is true. Choose the interface " "or a list of interfaces whose IP addresses should be used for dynamic DNS " @@ -10673,26 +11097,26 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:182 +#: sssd-ipa.5.xml:177 msgid "" "Default: Use the IP addresses of the interface which is used for IPA LDAP " "connection" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:186 sssd-ad.5.xml:1226 +#: sssd-ipa.5.xml:181 sssd-ad.5.xml:1220 msgid "Example: dyndns_iface = em[12], !vnet1, vnet*" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:192 sssd-ad.5.xml:1232 +#: sssd-ipa.5.xml:187 sssd-ad.5.xml:1226 #, fuzzy #| msgid "dyndns_iface (string)" msgid "dyndns_address (string)" msgstr "dyndns_iface (文字列)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:195 sssd-ad.5.xml:1235 +#: sssd-ipa.5.xml:190 sssd-ad.5.xml:1229 msgid "" "Optional. Applicable only when <emphasis>dyndns_update</emphasis> is true. " "A list of IP addresses or IP networks to be used for dynamic DNS updates. " @@ -10703,22 +11127,22 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:206 sssd-ad.5.xml:1246 +#: sssd-ipa.5.xml:201 sssd-ad.5.xml:1240 msgid "Default: No filtering of IP addresses." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:209 sssd-ad.5.xml:1249 +#: sssd-ipa.5.xml:204 sssd-ad.5.xml:1243 msgid "Example: dyndns_address = 10.0.0.0/16, !10.0.1.0/24" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:215 sssd-ad.5.xml:1305 +#: sssd-ipa.5.xml:210 sssd-ad.5.xml:1298 msgid "dyndns_auth (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:218 sssd-ad.5.xml:1308 +#: sssd-ipa.5.xml:213 sssd-ad.5.xml:1301 msgid "" "Whether the nsupdate utility should use GSS-TSIG authentication for secure " "updates with the DNS server, insecure updates can be sent by setting this " @@ -10726,19 +11150,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:224 sssd-ad.5.xml:1314 +#: sssd-ipa.5.xml:219 sssd-ad.5.xml:1307 msgid "Default: GSS-TSIG" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:230 sssd-ad.5.xml:1320 +#: sssd-ipa.5.xml:225 sssd-ad.5.xml:1313 #, fuzzy #| msgid "dyndns_iface (string)" msgid "dyndns_auth_ptr (string)" msgstr "dyndns_iface (文字列)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:233 sssd-ad.5.xml:1323 +#: sssd-ipa.5.xml:228 sssd-ad.5.xml:1316 msgid "" "Whether the nsupdate utility should use GSS-TSIG authentication for secure " "PTR updates with the DNS server, insecure updates can be sent by setting " @@ -10746,17 +11170,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:239 sssd-ad.5.xml:1329 +#: sssd-ipa.5.xml:234 sssd-ad.5.xml:1322 msgid "Default: Same as dyndns_auth" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:245 sssd-ad.5.xml:1255 +#: sssd-ipa.5.xml:240 sssd-ad.5.xml:1249 msgid "dyndns_refresh_interval (integer)" msgstr "dyndns_refresh_interval (整数)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:248 +#: sssd-ipa.5.xml:243 msgid "" "How often should the back end perform periodic DNS update in addition to the " "automatic update performed when the back end goes online. This option is " @@ -10764,43 +11188,47 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:261 sssd-ad.5.xml:1273 -msgid "dyndns_update_ptr (bool)" +#: sssd-ipa.5.xml:256 sssd-ad.5.xml:1266 +#, fuzzy +#| msgid "dyndns_update_ptr (bool)" +msgid "dyndns_update_ptr (boolean)" msgstr "dyndns_update_ptr (論理値)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:264 sssd-ad.5.xml:1276 +#: sssd-ipa.5.xml:259 sssd-ad.5.xml:1269 msgid "" "Whether the PTR record should also be explicitly updated when updating the " "client's DNS records. Applicable only when dyndns_update is true." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:269 +#: sssd-ipa.5.xml:264 msgid "" "This option should be False in most IPA deployments as the IPA server " "generates the PTR records automatically when forward records are changed." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:275 sssd-ad.5.xml:1281 +#: sssd-ipa.5.xml:270 sssd-ad.5.xml:1274 msgid "" "Note that <emphasis>dyndns_update_per_family</emphasis> parameter does not " "apply for PTR record updates. Those updates are always sent separately." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:280 +#: sssd-ipa.5.xml:275 msgid "Default: False (disabled)" msgstr "初期値: False (無効)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:286 sssd-ad.5.xml:1292 -msgid "dyndns_force_tcp (bool)" +#: sssd-ipa.5.xml:281 sssd-ad.5.xml:1285 +#, fuzzy +#| msgid "dyndns_force_tcp (bool)" +msgid "dyndns_force_tcp (boolean)" msgstr "dyndns_force_tcp (論理値)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:289 sssd-ad.5.xml:1295 +#: sssd-ipa.5.xml:284 sssd-ad.5.xml:1288 msgid "" "Whether the nsupdate utility should default to using TCP for communicating " "with the DNS server." @@ -10809,31 +11237,31 @@ msgstr "" "どうか。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:293 sssd-ad.5.xml:1299 +#: sssd-ipa.5.xml:288 sssd-ad.5.xml:1292 msgid "Default: False (let nsupdate choose the protocol)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:299 sssd-ad.5.xml:1335 +#: sssd-ipa.5.xml:294 sssd-ad.5.xml:1328 msgid "dyndns_server (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:302 sssd-ad.5.xml:1338 +#: sssd-ipa.5.xml:297 sssd-ad.5.xml:1331 msgid "" "The DNS server to use when performing a DNS update. In most setups, it's " "recommended to leave this option unset." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:307 sssd-ad.5.xml:1343 +#: sssd-ipa.5.xml:302 sssd-ad.5.xml:1336 msgid "" "Setting this option makes sense for environments where the DNS server is " "different from the identity server or when we use encrypted DNS." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:312 sssd-ad.5.xml:1348 +#: sssd-ipa.5.xml:307 sssd-ad.5.xml:1341 msgid "" "The parameter can be a simple string containing DNS name or IP address. It " "can also be an URI. The URI can look like <emphasis>dns://servername/</" @@ -10841,7 +11269,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:319 sssd-ad.5.xml:1355 +#: sssd-ipa.5.xml:314 sssd-ad.5.xml:1348 msgid "" "The second example enables DNS-over-TLS protocol for DNS updates. The " "nsupdate utility must support DoT - check the <emphasis>man nsupdate</" @@ -10849,7 +11277,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:325 sssd-ad.5.xml:1361 +#: sssd-ipa.5.xml:320 sssd-ad.5.xml:1354 msgid "" "Please note that this option will be only used in fallback attempt when " "previous attempt using autodetected settings failed or when DNS-over-TLS is " @@ -10857,17 +11285,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:331 sssd-ad.5.xml:1367 +#: sssd-ipa.5.xml:326 sssd-ad.5.xml:1360 msgid "Default: None (let nsupdate choose the server)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:337 sssd-ad.5.xml:1373 +#: sssd-ipa.5.xml:332 sssd-ad.5.xml:1366 msgid "dyndns_update_per_family (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:340 sssd-ad.5.xml:1376 +#: sssd-ipa.5.xml:335 sssd-ad.5.xml:1369 msgid "" "DNS update is by default performed in two steps - IPv4 update and then IPv6 " "update. In some cases it might be desirable to perform IPv4 and IPv6 update " @@ -10875,14 +11303,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:352 sssd-ad.5.xml:1388 +#: sssd-ipa.5.xml:347 sssd-ad.5.xml:1381 #, fuzzy #| msgid "dyndns_iface (string)" msgid "dyndns_dot_cacert (string)" msgstr "dyndns_iface (文字列)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:355 sssd-ad.5.xml:1391 +#: sssd-ipa.5.xml:350 sssd-ad.5.xml:1384 msgid "" "This option specifies the file of the certificate authorities certificates " "(in PEM format) in order to verify the remote server TLS certificate when " @@ -10890,19 +11318,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:361 sssd-ad.5.xml:1397 +#: sssd-ipa.5.xml:356 sssd-ad.5.xml:1390 msgid "Default: None (use global certificate store)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:367 sssd-ad.5.xml:1403 +#: sssd-ipa.5.xml:362 sssd-ad.5.xml:1396 #, fuzzy #| msgid "dyndns_iface (string)" msgid "dyndns_dot_cert (string)" msgstr "dyndns_iface (文字列)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:370 sssd-ad.5.xml:1406 +#: sssd-ipa.5.xml:365 sssd-ad.5.xml:1399 msgid "" "This option sets the certificate(s) file for authentication for the DoT " "transport to the remote server. The certificate chain file is expected to be " @@ -10910,28 +11338,28 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:376 sssd-ad.5.xml:1412 +#: sssd-ipa.5.xml:371 sssd-ad.5.xml:1405 msgid "" "The <emphasis>dyndns_dot_cert</emphasis> and <emphasis>dyndns_dot_key</" "emphasis> options must be both set to achieve mutual TLS authentication." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:381 sssd-ipa.5.xml:396 sssd-ad.5.xml:1417 sssd-ad.5.xml:1432 +#: sssd-ipa.5.xml:376 sssd-ipa.5.xml:391 sssd-ad.5.xml:1410 sssd-ad.5.xml:1425 #, fuzzy #| msgid "Default: not set (no substitution for unset home directories)" msgid "Default: None (Do not use TLS authentication)" msgstr "初期値: 設定なし (ホームディレクトリーの設定がない場合は代替なし)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:387 sssd-ad.5.xml:1423 +#: sssd-ipa.5.xml:382 sssd-ad.5.xml:1416 #, fuzzy #| msgid "dyndns_iface (string)" msgid "dyndns_dot_key (string)" msgstr "dyndns_iface (文字列)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:390 sssd-ad.5.xml:1426 +#: sssd-ipa.5.xml:385 sssd-ad.5.xml:1419 msgid "" "This option sets the key file for authenticated encryption for the DoT " "transport to the remote server. The private key file is expected to be in " @@ -10939,140 +11367,140 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:402 +#: sssd-ipa.5.xml:397 #, fuzzy #| msgid "ldap_access_order (string)" msgid "ipa_access_order (string)" msgstr "ldap_access_order (文字列)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:409 +#: sssd-ipa.5.xml:404 #, fuzzy #| msgid "<emphasis>expire</emphasis>: use ldap_account_expire_policy" msgid "<emphasis>expire</emphasis>: use IPA's account expiration policy." msgstr "<emphasis>expire</emphasis>: ldap_account_expire_policy を使用します" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:448 +#: sssd-ipa.5.xml:443 msgid "" "Please note that 'access_provider = ipa' must be set for this feature to " "work." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:455 +#: sssd-ipa.5.xml:450 msgid "ipa_deskprofile_search_base (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:458 +#: sssd-ipa.5.xml:453 msgid "" "Optional. Use the given string as search base for Desktop Profile related " "objects." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:462 sssd-ipa.5.xml:484 +#: sssd-ipa.5.xml:457 sssd-ipa.5.xml:479 msgid "Default: Use base DN" msgstr "初期値: ベース DN を使用します" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:468 +#: sssd-ipa.5.xml:463 #, fuzzy #| msgid "ipa_subdomains_search_base (string)" msgid "ipa_subid_ranges_search_base (string)" msgstr "ipa_subdomains_search_base (文字列)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:471 +#: sssd-ipa.5.xml:466 #, fuzzy #| msgid "ipa_subdomains_search_base (string)" msgid "Deprecated. Use ldap_subid_ranges_search_base instead." msgstr "ipa_subdomains_search_base (文字列)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:477 +#: sssd-ipa.5.xml:472 msgid "ipa_hbac_search_base (string)" msgstr "ipa_hbac_search_base (文字列)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:480 +#: sssd-ipa.5.xml:475 msgid "Optional. Use the given string as search base for HBAC related objects." msgstr "" "オプションです。与えられた文字列を HBAC 関連オブジェクトに対する検索ベースと" "して使用します。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:490 +#: sssd-ipa.5.xml:485 msgid "ipa_host_search_base (string)" msgstr "ipa_host_search_base (文字列)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:493 +#: sssd-ipa.5.xml:488 msgid "Deprecated. Use ldap_host_search_base instead." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:499 +#: sssd-ipa.5.xml:494 msgid "ipa_selinux_search_base (string)" msgstr "ipa_selinux_search_base (文字列)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:502 +#: sssd-ipa.5.xml:497 msgid "Optional. Use the given string as search base for SELinux user maps." msgstr "" "オプションです。与えられた文字列を SELinux ユーザーマップに対する検索ベースと" "して使用します。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:518 +#: sssd-ipa.5.xml:513 msgid "ipa_subdomains_search_base (string)" msgstr "ipa_subdomains_search_base (文字列)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:521 +#: sssd-ipa.5.xml:516 msgid "Optional. Use the given string as search base for trusted domains." msgstr "" "オプションです。信頼されたドメインに対する検索ベースとして、与えられた文字列" "を使用します。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:530 +#: sssd-ipa.5.xml:525 msgid "Default: the value of <emphasis>cn=trusts,%basedn</emphasis>" msgstr "初期値: <emphasis>cn=trusts,%basedn</emphasis> の値" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:537 +#: sssd-ipa.5.xml:532 msgid "ipa_master_domain_search_base (string)" msgstr "ipa_master_domain_search_base (文字列)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:540 +#: sssd-ipa.5.xml:535 msgid "Optional. Use the given string as search base for master domain object." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:549 +#: sssd-ipa.5.xml:544 msgid "Default: the value of <emphasis>cn=ad,cn=etc,%basedn</emphasis>" msgstr "初期値: <emphasis>cn=ad,cn=etc,%basedn</emphasis> の値" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:556 +#: sssd-ipa.5.xml:551 msgid "ipa_views_search_base (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:559 +#: sssd-ipa.5.xml:554 msgid "Optional. Use the given string as search base for views containers." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:568 +#: sssd-ipa.5.xml:563 msgid "Default: the value of <emphasis>cn=views,cn=accounts,%basedn</emphasis>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:578 +#: sssd-ipa.5.xml:573 msgid "" "The name of the Kerberos realm. This is optional and defaults to the value " "of <quote>ipa_domain</quote>." @@ -11081,7 +11509,7 @@ msgstr "" "quote> の値です。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:582 +#: sssd-ipa.5.xml:577 msgid "" "The name of the Kerberos realm has a special meaning in IPA - it is " "converted into the base DN to use for performing LDAP operations." @@ -11090,37 +11518,37 @@ msgstr "" "めに使用するベース DN に変換されます。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:590 sssd-ad.5.xml:1441 +#: sssd-ipa.5.xml:585 sssd-ad.5.xml:1434 msgid "krb5_confd_path (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:593 sssd-ad.5.xml:1444 +#: sssd-ipa.5.xml:588 sssd-ad.5.xml:1437 msgid "" "Absolute path of a directory where SSSD should place Kerberos configuration " "snippets." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:597 sssd-ad.5.xml:1448 +#: sssd-ipa.5.xml:592 sssd-ad.5.xml:1441 msgid "" "To disable the creation of the configuration snippets set the parameter to " "'none'." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:601 sssd-ad.5.xml:1452 +#: sssd-ipa.5.xml:596 sssd-ad.5.xml:1445 msgid "" "Default: not set (krb5.include.d subdirectory of SSSD's pubconf directory)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:608 +#: sssd-ipa.5.xml:603 msgid "ipa_deskprofile_refresh (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:611 +#: sssd-ipa.5.xml:606 msgid "" "The amount of time between lookups of the Desktop Profile rules against the " "IPA server. This will reduce the latency and load on the IPA server if there " @@ -11128,34 +11556,34 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:618 sssd-ipa.5.xml:648 sssd-ipa.5.xml:664 sssd-ad.5.xml:600 +#: sssd-ipa.5.xml:613 sssd-ipa.5.xml:643 sssd-ipa.5.xml:659 sssd-ad.5.xml:600 msgid "Default: 5 (seconds)" msgstr "初期値: 5 (秒)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:624 +#: sssd-ipa.5.xml:619 msgid "ipa_deskprofile_request_interval (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:627 +#: sssd-ipa.5.xml:622 msgid "" "The amount of time between lookups of the Desktop Profile rules against the " "IPA server in case the last request did not return any rule." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:632 +#: sssd-ipa.5.xml:627 msgid "Default: 60 (minutes)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:638 +#: sssd-ipa.5.xml:633 msgid "ipa_hbac_refresh (integer)" msgstr "ipa_hbac_refresh (整数)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:641 +#: sssd-ipa.5.xml:636 msgid "" "The amount of time between lookups of the HBAC rules against the IPA server. " "This will reduce the latency and load on the IPA server if there are many " @@ -11163,12 +11591,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:654 -msgid "ipa_hbac_selinux (integer)" -msgstr "ipa_hbac_selinux (整数)" +#: sssd-ipa.5.xml:649 +#, fuzzy +#| msgid "ipa_hbac_refresh (integer)" +msgid "ipa_selinux_refresh (integer)" +msgstr "ipa_hbac_refresh (整数)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:657 +#: sssd-ipa.5.xml:652 msgid "" "The amount of time between lookups of the SELinux maps against the IPA " "server. This will reduce the latency and load on the IPA server if there are " @@ -11176,33 +11606,33 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:670 +#: sssd-ipa.5.xml:665 msgid "ipa_server_mode (boolean)" msgstr "ipa_server_mode (論理値)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:673 +#: sssd-ipa.5.xml:668 msgid "" "This option will be set by the IPA installer (ipa-server-install) " "automatically and denotes if SSSD is running on an IPA server or not." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:678 +#: sssd-ipa.5.xml:673 msgid "" "On an IPA server SSSD will lookup users and groups from trusted domains " "directly while on a client it will ask an IPA server." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:683 +#: sssd-ipa.5.xml:678 msgid "" "NOTE: There are currently some assumptions that must be met when SSSD is " "running on an IPA server." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:688 +#: sssd-ipa.5.xml:683 msgid "" "The <quote>ipa_server</quote> option must be configured to point to the IPA " "server itself. This is already the default set by the IPA installer, so no " @@ -11210,59 +11640,59 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:697 +#: sssd-ipa.5.xml:692 msgid "" "The <quote>full_name_format</quote> option must not be tweaked to only print " "short names for users from trusted domains." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:712 +#: sssd-ipa.5.xml:707 msgid "ipa_automount_location (string)" msgstr "ipa_automount_location (文字列)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:715 +#: sssd-ipa.5.xml:710 msgid "The automounter location this IPA client will be using" msgstr "この IPA クライアントが使用する automounter の場所です" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:718 +#: sssd-ipa.5.xml:713 msgid "Default: The location named \"default\"" msgstr "初期値: \"default\" という名前の場所" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd-ipa.5.xml:726 +#: sssd-ipa.5.xml:721 msgid "VIEWS AND OVERRIDES" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:735 +#: sssd-ipa.5.xml:730 msgid "ipa_view_class (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:738 +#: sssd-ipa.5.xml:733 msgid "Objectclass of the view container." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:741 +#: sssd-ipa.5.xml:736 msgid "Default: nsContainer" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:747 +#: sssd-ipa.5.xml:742 msgid "ipa_view_name (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:750 +#: sssd-ipa.5.xml:745 msgid "Name of the attribute holding the name of the view." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:754 sssd-ldap-attributes.5.xml:496 +#: sssd-ipa.5.xml:749 sssd-ldap-attributes.5.xml:496 #: sssd-ldap-attributes.5.xml:832 sssd-ldap-attributes.5.xml:913 #: sssd-ldap-attributes.5.xml:1010 sssd-ldap-attributes.5.xml:1068 #: sssd-ldap-attributes.5.xml:1226 sssd-ldap-attributes.5.xml:1271 @@ -11270,128 +11700,128 @@ msgid "Default: cn" msgstr "初期値: cn" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:760 +#: sssd-ipa.5.xml:755 msgid "ipa_override_object_class (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:763 +#: sssd-ipa.5.xml:758 msgid "Objectclass of the override objects." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:766 +#: sssd-ipa.5.xml:761 msgid "Default: ipaOverrideAnchor" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:772 +#: sssd-ipa.5.xml:767 msgid "ipa_anchor_uuid (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:775 +#: sssd-ipa.5.xml:770 msgid "" "Name of the attribute containing the reference to the original object in a " "remote domain." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:779 +#: sssd-ipa.5.xml:774 msgid "Default: ipaAnchorUUID" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:785 +#: sssd-ipa.5.xml:780 msgid "ipa_user_override_object_class (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:788 +#: sssd-ipa.5.xml:783 msgid "" "Name of the objectclass for user overrides. It is used to determine if the " "found override object is related to a user or a group." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:793 +#: sssd-ipa.5.xml:788 msgid "User overrides can contain attributes given by" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:796 +#: sssd-ipa.5.xml:791 msgid "ldap_user_name" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:799 +#: sssd-ipa.5.xml:794 msgid "ldap_user_uid_number" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:802 +#: sssd-ipa.5.xml:797 msgid "ldap_user_gid_number" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:805 +#: sssd-ipa.5.xml:800 msgid "ldap_user_gecos" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:808 +#: sssd-ipa.5.xml:803 msgid "ldap_user_home_directory" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:811 +#: sssd-ipa.5.xml:806 msgid "ldap_user_shell" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:814 +#: sssd-ipa.5.xml:809 msgid "ldap_user_ssh_public_key" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:819 +#: sssd-ipa.5.xml:814 msgid "Default: ipaUserOverride" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:825 +#: sssd-ipa.5.xml:820 msgid "ipa_group_override_object_class (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:828 +#: sssd-ipa.5.xml:823 msgid "" "Name of the objectclass for group overrides. It is used to determine if the " "found override object is related to a user or a group." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:833 +#: sssd-ipa.5.xml:828 msgid "Group overrides can contain attributes given by" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:836 +#: sssd-ipa.5.xml:831 msgid "ldap_group_name" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:839 +#: sssd-ipa.5.xml:834 msgid "ldap_group_gid_number" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:844 +#: sssd-ipa.5.xml:839 msgid "Default: ipaGroupOverride" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:728 +#: sssd-ipa.5.xml:723 msgid "" "SSSD can handle views and overrides which are offered by FreeIPA 4.1 and " "later version. Since all paths and objectclasses are fixed on the server " @@ -11401,19 +11831,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd-ipa.5.xml:856 +#: sssd-ipa.5.xml:851 msgid "SUBDOMAINS PROVIDER" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:858 +#: sssd-ipa.5.xml:853 msgid "" "The IPA subdomains provider behaves slightly differently if it is configured " "explicitly or implicitly." msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:862 +#: sssd-ipa.5.xml:857 msgid "" "If the option 'subdomains_provider = ipa' is found in the domain section of " "sssd.conf, the IPA subdomains provider is configured explicitly, and all " @@ -11424,7 +11854,7 @@ msgstr "" "サブドメインのリクエストが必要に応じて IPA サーバーに送られます。" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:868 +#: sssd-ipa.5.xml:863 msgid "" "If the option 'subdomains_provider' is not set in the domain section of " "sssd.conf but there is the option 'id_provider = ipa', the IPA subdomains " @@ -11436,12 +11866,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd-ipa.5.xml:879 +#: sssd-ipa.5.xml:874 msgid "TRUSTED DOMAINS CONFIGURATION" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-ipa.5.xml:887 +#: sssd-ipa.5.xml:882 #, no-wrap msgid "" "[domain/ipa.domain.com/ad.domain.com]\n" @@ -11449,7 +11879,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:881 +#: sssd-ipa.5.xml:876 msgid "" "Some configuration options can also be set for a trusted domain. A trusted " "domain configuration can be set using the trusted domain subsection as shown " @@ -11459,99 +11889,99 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:892 +#: sssd-ipa.5.xml:887 msgid "" "For more details, see the <citerefentry> <refentrytitle>sssd.conf</" "refentrytitle> <manvolnum>5</manvolnum> </citerefentry> manual page." msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:899 +#: sssd-ipa.5.xml:894 msgid "" "Different configuration options are tunable for a trusted domain depending " "on whether you are configuring SSSD on an IPA server or an IPA client." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd-ipa.5.xml:904 +#: sssd-ipa.5.xml:899 msgid "OPTIONS TUNABLE ON IPA MASTERS" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:906 +#: sssd-ipa.5.xml:901 msgid "" "The following options can be set in a subdomain section on an IPA master:" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:910 sssd-ipa.5.xml:950 +#: sssd-ipa.5.xml:905 sssd-ipa.5.xml:945 msgid "ad_server" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:913 +#: sssd-ipa.5.xml:908 msgid "ad_backup_server" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:916 sssd-ipa.5.xml:953 +#: sssd-ipa.5.xml:911 sssd-ipa.5.xml:948 msgid "ad_site" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:919 +#: sssd-ipa.5.xml:914 msgid "ipa_server" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:922 +#: sssd-ipa.5.xml:917 #, fuzzy #| msgid "ipa_server, ipa_backup_server (string)" msgid "ipa_backup_server" msgstr "ipa_server, ipa_backup_server (文字列)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:925 +#: sssd-ipa.5.xml:920 msgid "ldap_search_base" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:928 +#: sssd-ipa.5.xml:923 msgid "ldap_user_search_base" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:931 +#: sssd-ipa.5.xml:926 msgid "ldap_group_search_base" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:939 +#: sssd-ipa.5.xml:934 msgid "" "Options prefixed with 'ad_' or 'ipa_' only apply to their respective " "subdomain type." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd-ipa.5.xml:944 +#: sssd-ipa.5.xml:939 msgid "OPTIONS TUNABLE ON IPA CLIENTS" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:946 +#: sssd-ipa.5.xml:941 msgid "" "The following options can be set in an AD subdomain section on an IPA client:" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:958 +#: sssd-ipa.5.xml:953 msgid "" "Note that if both options are set, only <quote>ad_server</quote> is " "evaluated." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:962 +#: sssd-ipa.5.xml:957 msgid "" "Since any request for a user or a group identity from a trusted domain " "triggered from an IPA client is resolved by the IPA server, the " @@ -11565,7 +11995,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:986 +#: sssd-ipa.5.xml:981 msgid "" "The following example assumes that SSSD is correctly configured and " "example.com is one of the domains in the <replaceable>[sssd]</replaceable> " @@ -11576,7 +12006,7 @@ msgstr "" "例は IPA プロバイダー固有のオプションのみを示しています。" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-ipa.5.xml:993 +#: sssd-ipa.5.xml:988 #, no-wrap msgid "" "[domain/example.com]\n" @@ -12287,27 +12717,27 @@ msgid "lxdm" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:694 +#: sssd-ad.5.xml:699 msgid "sddm" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:699 +#: sssd-ad.5.xml:704 msgid "unity" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:704 +#: sssd-ad.5.xml:709 msgid "xdm" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:713 +#: sssd-ad.5.xml:718 msgid "ad_gpo_map_remote_interactive (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:716 +#: sssd-ad.5.xml:721 msgid "" "A comma-separated list of PAM service names for which GPO-based access " "control is evaluated based on the RemoteInteractiveLogonRight and " @@ -12323,7 +12753,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:735 +#: sssd-ad.5.xml:740 msgid "" "Note: Using the Group Policy Management Editor this value is called \"Allow " "log on through Remote Desktop Services\" and \"Deny log on through Remote " @@ -12331,7 +12761,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:750 +#: sssd-ad.5.xml:755 #, no-wrap msgid "" "ad_gpo_map_remote_interactive = +my_pam_service, -sshd\n" @@ -12339,7 +12769,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:741 +#: sssd-ad.5.xml:746 msgid "" "It is possible to add another PAM service name to the default set by using " "<quote>+service_name</quote> or to explicitly remove a PAM service name from " @@ -12351,22 +12781,22 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:758 +#: sssd-ad.5.xml:763 msgid "sshd" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:763 +#: sssd-ad.5.xml:768 msgid "cockpit" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:772 +#: sssd-ad.5.xml:777 msgid "ad_gpo_map_network (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:775 +#: sssd-ad.5.xml:780 msgid "" "A comma-separated list of PAM service names for which GPO-based access " "control is evaluated based on the NetworkLogonRight and " @@ -12382,7 +12812,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:793 +#: sssd-ad.5.xml:798 msgid "" "Note: Using the Group Policy Management Editor this value is called \"Access " "this computer from the network\" and \"Deny access to this computer from the " @@ -12390,7 +12820,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:808 +#: sssd-ad.5.xml:813 #, no-wrap msgid "" "ad_gpo_map_network = +my_pam_service, -ftp\n" @@ -12398,7 +12828,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:799 +#: sssd-ad.5.xml:804 msgid "" "It is possible to add another PAM service name to the default set by using " "<quote>+service_name</quote> or to explicitly remove a PAM service name from " @@ -12410,22 +12840,22 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:816 +#: sssd-ad.5.xml:821 msgid "ftp" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:821 +#: sssd-ad.5.xml:826 msgid "samba" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:830 +#: sssd-ad.5.xml:835 msgid "ad_gpo_map_batch (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:833 +#: sssd-ad.5.xml:838 msgid "" "A comma-separated list of PAM service names for which GPO-based access " "control is evaluated based on the BatchLogonRight and DenyBatchLogonRight " @@ -12440,14 +12870,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:851 +#: sssd-ad.5.xml:856 msgid "" "Note: Using the Group Policy Management Editor this value is called \"Allow " "log on as a batch job\" and \"Deny log on as a batch job\"." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:865 +#: sssd-ad.5.xml:870 #, no-wrap msgid "" "ad_gpo_map_batch = +my_pam_service, -crond\n" @@ -12455,7 +12885,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:856 +#: sssd-ad.5.xml:861 msgid "" "It is possible to add another PAM service name to the default set by using " "<quote>+service_name</quote> or to explicitly remove a PAM service name from " @@ -12467,23 +12897,23 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:868 +#: sssd-ad.5.xml:873 msgid "" "Note: Cron service name may differ depending on Linux distribution used." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:874 +#: sssd-ad.5.xml:879 msgid "crond" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:883 +#: sssd-ad.5.xml:888 msgid "ad_gpo_map_service (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:886 +#: sssd-ad.5.xml:891 msgid "" "A comma-separated list of PAM service names for which GPO-based access " "control is evaluated based on the ServiceLogonRight and " @@ -12499,14 +12929,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:904 +#: sssd-ad.5.xml:909 msgid "" "Note: Using the Group Policy Management Editor this value is called \"Allow " "log on as a service\" and \"Deny log on as a service\"." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:917 +#: sssd-ad.5.xml:922 #, no-wrap msgid "" "ad_gpo_map_service = +my_pam_service\n" @@ -12514,7 +12944,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:909 sssd-ad.5.xml:984 +#: sssd-ad.5.xml:914 sssd-ad.5.xml:989 msgid "" "It is possible to add a PAM service name to the default set by using " "<quote>+service_name</quote>. Since the default set is empty, it is not " @@ -12525,19 +12955,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:927 +#: sssd-ad.5.xml:932 msgid "ad_gpo_map_permit (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:930 +#: sssd-ad.5.xml:935 msgid "" "A comma-separated list of PAM service names for which GPO-based access is " "always granted, regardless of any GPO Logon Rights." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:944 +#: sssd-ad.5.xml:949 #, no-wrap msgid "" "ad_gpo_map_permit = +my_pam_service, -sudo\n" @@ -12545,7 +12975,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:935 +#: sssd-ad.5.xml:940 msgid "" "It is possible to add another PAM service name to the default set by using " "<quote>+service_name</quote> or to explicitly remove a PAM service name from " @@ -12557,29 +12987,29 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:952 +#: sssd-ad.5.xml:957 msgid "polkit-1" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:967 +#: sssd-ad.5.xml:972 msgid "systemd-user" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:976 +#: sssd-ad.5.xml:981 msgid "ad_gpo_map_deny (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:979 +#: sssd-ad.5.xml:984 msgid "" "A comma-separated list of PAM service names for which GPO-based access is " "always denied, regardless of any GPO Logon Rights." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:992 +#: sssd-ad.5.xml:997 #, no-wrap msgid "" "ad_gpo_map_deny = +my_pam_service\n" @@ -12587,12 +13017,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:1002 +#: sssd-ad.5.xml:1007 msgid "ad_gpo_default_right (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1005 +#: sssd-ad.5.xml:1010 msgid "" "This option defines how access control is evaluated for PAM service names " "that are not explicitly listed in one of the ad_gpo_map_* options. This " @@ -12605,52 +13035,52 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1018 +#: sssd-ad.5.xml:1023 msgid "Supported values for this option include:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1027 +#: sssd-ad.5.xml:1032 msgid "remote_interactive" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1032 +#: sssd-ad.5.xml:1037 msgid "network" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1037 +#: sssd-ad.5.xml:1042 msgid "batch" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1042 +#: sssd-ad.5.xml:1047 msgid "service" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1047 +#: sssd-ad.5.xml:1052 msgid "permit" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1052 +#: sssd-ad.5.xml:1057 msgid "deny" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1058 +#: sssd-ad.5.xml:1063 msgid "Default: deny" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:1064 +#: sssd-ad.5.xml:1069 msgid "ad_maximum_machine_account_password_age (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1067 +#: sssd-ad.5.xml:1072 msgid "" "SSSD will check once a day if the machine account password is older than the " "given age in days and try to renew it. A value of 0 will disable the renewal " @@ -12658,17 +13088,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1073 +#: sssd-ad.5.xml:1078 msgid "Default: 30 days" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:1079 +#: sssd-ad.5.xml:1084 msgid "ad_machine_account_password_renewal_opts (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1082 +#: sssd-ad.5.xml:1087 msgid "" "This option should only be used to test the machine account renewal task. " "The option expects 3 integers and a string separated by a colon (':'). The " @@ -12681,20 +13111,20 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1096 +#: sssd-ad.5.xml:1101 msgid "" "The optional fourth string value identifies the helper binary which should " "be used for the renewal. Currently <command>adcli</command> and " "<command>realm</command> are supported. If this value is missing or empty in " "the value string <command>realm</command> will be used. Since the helper is " "started as the user SSSD is running as there might be the chance that the " -"renewal will fail if this user does not has permissions to modify the keytab " -"file where the machine account credentials are stored. This will typically " -"be the case for <command>adcli</command>." +"renewal will fail if this user does not have permissions to modify the " +"keytab file where the machine account credentials are stored. This will " +"typically be the case for <command>adcli</command>." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1110 +#: sssd-ad.5.xml:1115 msgid "" "<command>realm</command> is not updating the keytab directly but is calling " "the <command>realmd</command> process, which runs as root user, for this " @@ -12704,17 +13134,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1119 +#: sssd-ad.5.xml:1124 msgid "Default: 86400:750:300:realm (24h, 12m30s and 5m)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:1125 +#: sssd-ad.5.xml:1130 msgid "ad_update_samba_machine_account_password (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1128 +#: sssd-ad.5.xml:1133 msgid "" "If enabled, when SSSD renews the machine account password, it will also be " "updated in Samba's database. This prevents Samba's copy of the machine " @@ -12723,23 +13153,25 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:1141 -msgid "ad_use_ldaps (bool)" -msgstr "" +#: sssd-ad.5.xml:1146 +#, fuzzy +#| msgid "ldap_id_use_start_tls (boolean)" +msgid "ad_use_ldaps (boolean)" +msgstr "ldap_id_use_start_tls (論理値)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1144 +#: sssd-ad.5.xml:1149 msgid "" "By default SSSD uses the plain LDAP port 389 and the Global Catalog port " -"3628. If this option is set to True SSSD will use the LDAPS port 636 and " -"Global Catalog port 3629 with LDAPS protection. Since AD does not allow to " +"3268. If this option is set to True SSSD will use the LDAPS port 636 and " +"Global Catalog port 3269 with LDAPS protection. Since AD does not allow to " "have multiple encryption layers on a single connection and we still want to " "use SASL/GSSAPI or SASL/GSS-SPNEGO for authentication the SASL security " "property maxssf is set to 0 (zero) for those connections." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1164 +#: sssd-ad.5.xml:1169 msgid "" "Optional. This option tells SSSD to automatically update the Active " "Directory DNS server with the IP address of this client. The update is " @@ -12757,30 +13189,21 @@ msgstr "初期値: 3600 (秒)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:1216 msgid "" -"NOTE: While it is still possible to use the old <emphasis>ipa_dyndns_iface</" -"emphasis> option, users should migrate to using <emphasis>dyndns_iface</" -"emphasis> in their config file." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1222 -msgid "" "Default: Use the IP addresses of the interface which is used for AD LDAP " "connection" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1258 +#: sssd-ad.5.xml:1252 msgid "" "How often should the back end perform periodic DNS update in addition to the " -"automatic update performed when the back end goes online. This option is " -"optional and applicable only when dyndns_update is true. Note that the " -"lowest possible value is 60 seconds in-case if value is provided less than " -"60, parameter will assume lowest value only." +"automatic update performed when the back end goes online. This is optional " +"and applicable only when dyndns_update is true. Note that the minimum value " +"is 60 seconds, any specified value below this threshold will default to 60." msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ad.5.xml:1472 +#: sssd-ad.5.xml:1465 msgid "" "The following example assumes that SSSD is correctly configured and " "example.com is one of the domains in the <replaceable>[sssd]</replaceable> " @@ -12791,7 +13214,7 @@ msgstr "" "AD プロバイダー固有のオプションのみ示してします。" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-ad.5.xml:1479 +#: sssd-ad.5.xml:1472 #, no-wrap msgid "" "[domain/EXAMPLE]\n" @@ -12815,7 +13238,7 @@ msgstr "" "ad_domain = example.com\n" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-ad.5.xml:1499 +#: sssd-ad.5.xml:1492 #, no-wrap msgid "" "access_provider = ldap\n" @@ -12827,7 +13250,7 @@ msgstr "" "ldap_account_expire_policy = ad\n" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ad.5.xml:1495 +#: sssd-ad.5.xml:1488 msgid "" "The AD access control provider checks if the account is expired. It has the " "same effect as the following configuration of the LDAP provider: " @@ -12835,7 +13258,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ad.5.xml:1505 +#: sssd-ad.5.xml:1498 msgid "" "However, unless the <quote>ad</quote> access control provider is explicitly " "configured, the default access provider is <quote>permit</quote>. Please " @@ -12845,7 +13268,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ad.5.xml:1513 +#: sssd-ad.5.xml:1506 msgid "" "When the autofs provider is set to <quote>ad</quote>, the RFC2307 schema " "attribute mapping (nisMap, nisObject, ...) is used, because these attributes " @@ -13020,9 +13443,9 @@ msgstr "" #: sssd-sudo.5.xml:137 msgid "" "The <emphasis>smart refresh</emphasis> periodically downloads rules that are " -"new or were modified after the last update. Its primary goal is to keep the " -"database growing by fetching only small increments that do not generate " -"large amounts of network traffic." +"new or were modified after the last update. Its primary goal is to grow the " +"database incrementally by fetching only small updates, avoiding large " +"amounts of network traffic." msgstr "" #. type: Content of: <reference><refentry><refsect1><para> @@ -13219,26 +13642,29 @@ msgstr "" msgid "" "Depending on the IdP product additional platform specific options might " "follow the name separated by a colon (:). E.g. for Keycloak the base URI for " -"the user and group REST API must be given. For Entra ID this is not needed " -"because there is a generic endpoint for all tenants." +"the user and group REST API must be given. For Entra ID the base URI for the " +"Microsoft Graph API can be given to use sovereign or government cloud " +"endpoints instead of the default (https://graph.microsoft.com/v1.0). E.g. " +"<quote>entra_id:https://graph.microsoft.us/v1.0</quote> for the US " +"government cloud (GCC High)." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:78 sssd-idp.5.xml:94 sssd-idp.5.xml:119 +#: sssd-idp.5.xml:82 sssd-idp.5.xml:98 sssd-idp.5.xml:123 #, fuzzy #| msgid "Default: not set" msgid "Default: Not set (Required)" msgstr "初期値: 設定されません" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:83 +#: sssd-idp.5.xml:87 #, fuzzy #| msgid "ipa_domain (string)" msgid "idp_client_id (string)" msgstr "ipa_domain (文字列)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:86 +#: sssd-idp.5.xml:90 msgid "" "ID of the IdP client used by SSSD to authenticate users and as a client to " "lookup user and group attributes. This client must offer device " @@ -13247,14 +13673,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:99 +#: sssd-idp.5.xml:103 #, fuzzy #| msgid "ldap_tls_cert (string)" msgid "idp_client_secret (string)" msgstr "ldap_tls_cert (文字列)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:102 +#: sssd-idp.5.xml:106 msgid "" "Password of the IdP client. The password is required for the id_provider. If " "only used as auth_provider it depends on the server side configuration if it " @@ -13262,76 +13688,83 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:113 +#: sssd-idp.5.xml:117 #, fuzzy #| msgid "ipa_domain (string)" msgid "idp_token_endpoint (string)" msgstr "ipa_domain (文字列)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:116 +#: sssd-idp.5.xml:120 msgid "IdP endpoint for requesting access tokens." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:124 +#: sssd-idp.5.xml:128 #, fuzzy #| msgid "ldap_service_port (string)" msgid "idp_device_auth_endpoint (string)" msgstr "ldap_service_port (文字列)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:127 +#: sssd-idp.5.xml:131 msgid "" "IdP endpoint for device authorization according to RFC-8628. This is " "required for user authentication." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:137 +#: sssd-idp.5.xml:141 #, fuzzy #| msgid "ldap_service_port (string)" msgid "idp_userinfo_endpoint (string)" msgstr "ldap_service_port (文字列)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:140 +#: sssd-idp.5.xml:144 msgid "" "IdP userinfo endpoint to request user attributes after a successful " "authentication of the user. Required for authentication." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:150 +#: sssd-idp.5.xml:154 #, fuzzy #| msgid "id_provider (string)" msgid "idp_id_scope (string)" msgstr "id_provider (文字列)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:153 +#: sssd-idp.5.xml:157 msgid "" "Scope required for looking up user and group attributes with the REST API. " "The scopes are used by the server to determine which attributes/claims are " "returned to the caller." msgstr "" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:163 +msgid "" +"Note: In previous versions of SSSD, this option was expected to already be " +"URL-encoded." +msgstr "" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:164 +#: sssd-idp.5.xml:172 #, fuzzy #| msgid "dyndns_iface (string)" msgid "idp_auth_scope (string)" msgstr "dyndns_iface (文字列)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:167 +#: sssd-idp.5.xml:175 msgid "" "Scope required during authentication. The scopes are used by the server to " "determine which attributes/claims are returned to the caller." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:172 +#: sssd-idp.5.xml:180 msgid "" "Currently the tokens returned during user authentication are not used for " "other purposes hence the only important claim is the subject identifier " @@ -13340,26 +13773,124 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:185 +#: sssd-idp.5.xml:193 +#, fuzzy +#| msgid "ldap_autofs_entry_value (string)" +msgid "idp_auth_user_identifier_attr (string)" +msgstr "ldap_autofs_entry_value (文字列)" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:196 +msgid "" +"Attribute used to identify the authenticated user in userinfo data or token " +"claims." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:200 +msgid "" +"For hybrid Active Directory and Entra ID deployments where " +"<quote>id_provider = ad</quote> and <quote>auth_provider = idp</quote>, this " +"option must be set explicitly. No value is derived from the identity " +"provider, because more than one attribute can link an Entra ID object to its " +"on-premises counterpart and only the administrator knows which one the " +"directory synchronization is configured to use." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:211 +msgid "" +"Setting this option to <quote>onPremisesImmutableId</quote> is the usual " +"choice for such deployments. Microsoft Entra Connect populates that " +"attribute with the base64-encoded form of the 16-byte Active Directory " +"<quote>objectGUID</quote> when objectGUID is used as the sourceAnchor. SSSD " +"decodes the value and converts the raw bytes with the same conversion used " +"for AD objectGUID attributes, so the result matches the UUID stored in the " +"SSSD cache for the AD user." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:224 +msgid "" +"Note that Microsoft Entra Connect 1.1.524.0 and later use <quote>ms-DS-" +"ConsistencyGuid</quote> as the sourceAnchor for user objects instead of " +"<quote>objectGUID</quote>. The value is normally copied from objectGUID for " +"objects that do not have it set yet, in which case the decoded identifier " +"still matches. It does not match if ms-DS-ConsistencyGuid was populated " +"independently, if users were moved between forests or domains, or if a " +"different attribute such as employeeID was selected as the sourceAnchor. See " +"<ulink url=\"https://learn.microsoft.com/en-us/entra/identity/hybrid/connect/" +"plan-connect-design-concepts\"> Microsoft Entra Connect: Design concepts</" +"ulink> for details on sourceAnchor selection." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:241 +msgid "" +"Microsoft Graph does not return <quote>onPremisesImmutableId</quote> by " +"default. The <quote>idp_userinfo_endpoint</quote> must request it with " +"<quote>$select</quote>, see the example below and <ulink url=\"https://" +"learn.microsoft.com/en-us/graph/api/resources/user\"> the Microsoft Graph " +"user resource type</ulink>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:251 +msgid "" +"If the configured attribute is missing or cannot be decoded (for example " +"cloud-only Entra ID users without <quote>onPremisesImmutableId</quote>), " +"authentication fails. SSSD does not fall back to another attribute when this " +"option is set." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:258 +msgid "" +"Default: not set, <quote>sub</quote> for Keycloak and <quote>id</quote> for " +"other IdP types" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-idp.5.xml:264 #, fuzzy #| msgid "ldap_opt_timeout (integer)" msgid "idp_request_timeout (integer)" msgstr "ldap_opt_timeout (整数)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:188 +#: sssd-idp.5.xml:267 msgid "Timeout in seconds for an individual request to the IdP." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:197 +#: sssd-idp.5.xml:276 +#, fuzzy +#| msgid "ldap_referrals (boolean)" +msgid "idp_auto_refresh (boolean)" +msgstr "ldap_referrals (論理値)" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:279 +msgid "" +"Refresh tokens automatically, after they have reached about half their " +"lifetime." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:283 +msgid "" +"Note: Scheduled token refreshes are not preserved across restarts of SSSD." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-idp.5.xml:292 #, fuzzy #| msgid "ldap_idmap_range_min (integer)" msgid "idmap_range_min (integer)" msgstr "ldap_idmap_range_min (整数)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:200 +#: sssd-idp.5.xml:295 #, fuzzy #| msgid "" #| "Specifies the lower bound of the range of POSIX IDs to use for mapping " @@ -13373,7 +13904,7 @@ msgstr "" "POSIX ID の範囲の下限を指定します。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:206 +#: sssd-idp.5.xml:301 msgid "" "The interval between <quote>idmap_range_min</quote> and " "<quote>idmap_range_max</quote> will be split into smaller ranges of size " @@ -13382,20 +13913,20 @@ msgid "" msgstr "" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:213 sssd-idp.5.xml:239 include/ldap_id_mapping.xml:139 +#: sssd-idp.5.xml:308 sssd-idp.5.xml:334 include/ldap_id_mapping.xml:139 #: include/ldap_id_mapping.xml:197 msgid "Default: 200000" msgstr "初期値: 200000" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:218 +#: sssd-idp.5.xml:313 #, fuzzy #| msgid "ldap_idmap_range_max (integer)" msgid "idmap_range_max (integer)" msgstr "ldap_idmap_range_max (整数)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:221 +#: sssd-idp.5.xml:316 #, fuzzy #| msgid "" #| "Specifies the lower bound of the range of POSIX IDs to use for mapping " @@ -13409,47 +13940,70 @@ msgstr "" "POSIX ID の範囲の下限を指定します。" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:227 include/ldap_id_mapping.xml:165 +#: sssd-idp.5.xml:322 include/ldap_id_mapping.xml:165 msgid "Default: 2000200000" msgstr "初期値: 2000200000" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:232 +#: sssd-idp.5.xml:327 #, fuzzy #| msgid "ldap_idmap_range_size (integer)" msgid "idmap_range_size (integer)" msgstr "ldap_idmap_range_size (整数)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:235 +#: sssd-idp.5.xml:330 msgid "Specifies the number of POSIX IDs available for a single IdP domain." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-idp.5.xml:251 +#: sssd-idp.5.xml:346 #, no-wrap msgid "" "[domain/entra_id]\n" "id_provider = idp\n" "idp_type = entra_id\n" "idp_client_id = 12345678-abcd-0101-efef-ba9876543210\n" -"idp_client_secret = YOUR-CLIENT-SCERET\n" -"idp_token_endpoint = https://login.microsoftonline.com/TENNANT-ID/oauth2/v2.0/token\n" +"idp_client_secret = YOUR-CLIENT-SECRET\n" +"idp_token_endpoint = https://login.microsoftonline.com/TENANT-ID/oauth2/v2.0/token\n" "idp_userinfo_endpoint = https://graph.microsoft.com/v1.0/me\n" -"idp_device_auth_endpoint = https://login.microsoftonline.com/TENNANT-ID/oauth2/v2.0/devicecode\n" -"idp_id_scope = https%3A%2F%2Fgraph.microsoft.com%2F.default\n" +"idp_device_auth_endpoint = https://login.microsoftonline.com/TENANT-ID/oauth2/v2.0/devicecode\n" +"idp_id_scope = https://graph.microsoft.com/.default\n" +"idp_auth_scope = openid profile email\n" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><programlisting> +#: sssd-idp.5.xml:358 +#, no-wrap +msgid "" +"[domain/ad.example.com]\n" +"id_provider = ad\n" +"auth_provider = idp\n" +"access_provider = permit\n" +"\n" +"ad_domain = ad.example.com\n" +"krb5_realm = AD.EXAMPLE.COM\n" +"\n" +"idp_type = entra_id\n" +"idp_client_id = 12345678-abcd-0101-efef-ba9876543210\n" +"idp_client_secret = YOUR-CLIENT-SECRET\n" +"idp_token_endpoint = https://login.microsoftonline.com/TENANT-ID/oauth2/v2.0/token\n" +"idp_userinfo_endpoint = https://graph.microsoft.com/v1.0/me?$select=id,userPrincipalName,onPremisesImmutableId\n" +"idp_device_auth_endpoint = https://login.microsoftonline.com/TENANT-ID/oauth2/v2.0/devicecode\n" +"idp_id_scope = https://graph.microsoft.com/.default\n" "idp_auth_scope = openid profile email\n" +"idp_auth_user_identifier_attr = onPremisesImmutableId\n" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-idp.5.xml:263 +#: sssd-idp.5.xml:377 #, no-wrap msgid "" "[domain/keycloak]\n" "idp_type = keycloak:https://master.keycloak.test:8443/auth/admin/realms/master/\n" "id_provider = idp\n" "idp_client_id = myclient\n" -"idp_client_secret = YOUR-CLIENT-SCERET\n" +"idp_client_secret = YOUR-CLIENT-SECRET\n" "idp_token_endpoint = https://master.keycloak.test:8443/auth/realms/master/protocol/openid-connect/token\n" "idp_userinfo_endpoint = https://master.keycloak.test:8443/auth/realms/master/protocol/openid-connect/userinfo\n" "idp_device_auth_endpoint = https://master.keycloak.test:8443/auth/realms/master/protocol/openid-connect/auth/device\n" @@ -13458,14 +14012,26 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-idp.5.xml:250 +#: sssd-idp.5.xml:345 #, fuzzy #| msgid "example: <placeholder type=\"programlisting\" id=\"0\"/>" msgid "" "<placeholder type=\"programlisting\" id=\"0\"/> <placeholder " -"type=\"programlisting\" id=\"1\"/>" +"type=\"programlisting\" id=\"1\"/> <placeholder type=\"programlisting\" " +"id=\"2\"/>" msgstr "例: <placeholder type=\"programlisting\" id=\"0\"/>" +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-idp.5.xml:390 +msgid "" +"In the hybrid Active Directory and Entra ID example above, " +"<quote>onPremisesImmutableId</quote> is used during authentication so the " +"IdP result matches the AD objectGUID UUID stored in the SSSD cache. The " +"attribute must be requested via <quote>$select</quote> on the Graph userinfo " +"endpoint and is only populated for users synchronized from Active Directory " +"with objectGUID as the sourceAnchor." +msgstr "" + #. type: Content of: <reference><refentry><refnamediv><refname> #: sssd.8.xml:10 sssd.8.xml:15 msgid "sssd" @@ -14509,9 +15075,13 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:291 +#, fuzzy +#| msgid "" +#| "<emphasis>demand</emphasis> to use FAST. The authentication fails if the " +#| "server does not require fast." msgid "" "<emphasis>demand</emphasis> to use FAST. The authentication fails if the " -"server does not require fast." +"server does not support FAST." msgstr "" "<emphasis>demand</emphasis> は FAST を使用します。サーバーが FAST を要求しな" "ければ、認証が失敗します。" @@ -15475,8 +16045,10 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sss_rpcidmapd.5.xml:69 -msgid "memcache (bool)" -msgstr "" +#, fuzzy +#| msgid "dyndns_update (boolean)" +msgid "memcache (boolean)" +msgstr "dyndns_update (論理値)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sss_rpcidmapd.5.xml:72 @@ -15529,7 +16101,7 @@ msgid "" msgstr "" #. type: Content of: <refsect1><title> -#: sss_rpcidmapd.5.xml:120 sssd-kcm.8.xml:316 include/seealso.xml:2 +#: sss_rpcidmapd.5.xml:120 sssd-kcm.8.xml:315 include/seealso.xml:2 msgid "SEE ALSO" msgstr "関連項目" @@ -15807,8 +16379,8 @@ msgstr "" #: sss_ssh_knownhosts.1.xml:93 msgid "" "The key lines retrieved from the backend are expected to respect the key " -"format as decribed in the <quote>SSH_KNOWN_HOSTS FILE FORMAT</quote> section " -"of <citerefentry><refentrytitle>sshd</refentrytitle> <manvolnum>8</" +"format as described in the <quote>SSH_KNOWN_HOSTS FILE FORMAT</quote> " +"section of <citerefentry><refentrytitle>sshd</refentrytitle> <manvolnum>8</" "manvolnum></citerefentry>. However, returning only the keytype and the key " "itself is tolerated, in which case, the hostname received as parameter will " "be added before the keytype to output a correctly formatted line. The " @@ -16283,15 +16855,22 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-kcm.8.xml:215 +#, fuzzy +#| msgid "" +#| "Please refer to the <quote>dns_discovery_domain</quote> parameter in the " +#| "<citerefentry> <refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</" +#| "manvolnum> </citerefentry> manual page for more details." msgid "" -"The KCM service is configured in the <quote>kcm</quote> For a detailed " -"syntax reference, refer to the <quote>FILE FORMAT</quote> section of the " -"<citerefentry> <refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</" -"manvolnum> </citerefentry> manual page." +"For a detailed syntax reference, refer to the <quote>FILE FORMAT</quote> " +"section of the <citerefentry> <refentrytitle>sssd.conf</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry> manual page." msgstr "" +"詳細は <citerefentry> <refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry> マニュアルページにある " +"<quote>dns_discovery_domain</quote> パラメーターを参照してください。" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-kcm.8.xml:223 +#: sssd-kcm.8.xml:222 msgid "" "The generic SSSD service options such as <quote>debug_level</quote> or " "<quote>fd_limit</quote> are accepted by the kcm service. Please refer to " @@ -16301,22 +16880,22 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:234 +#: sssd-kcm.8.xml:233 msgid "socket_path (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:237 +#: sssd-kcm.8.xml:236 msgid "The socket the KCM service will listen on." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:240 +#: sssd-kcm.8.xml:239 msgid "Default: <replaceable>/var/run/.heim_org.h5l.kcm-socket</replaceable>" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:243 +#: sssd-kcm.8.xml:242 msgid "" "<phrase condition=\"have_systemd\"> Note: on platforms where systemd is " "supported, the socket path is overwritten by the one defined in the sssd-" @@ -16324,94 +16903,94 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:252 +#: sssd-kcm.8.xml:251 msgid "max_ccaches (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:255 +#: sssd-kcm.8.xml:254 msgid "How many credential caches does the KCM database allow for all users." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:259 +#: sssd-kcm.8.xml:258 msgid "Default: 0 (unlimited, only the per-UID quota is enforced)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:264 +#: sssd-kcm.8.xml:263 msgid "max_uid_ccaches (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:267 +#: sssd-kcm.8.xml:266 msgid "" "How many credential caches does the KCM database allow per UID. This is " "equivalent to <quote>with how many principals you can kinit</quote>." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:272 +#: sssd-kcm.8.xml:271 msgid "Default: 64" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:277 +#: sssd-kcm.8.xml:276 msgid "max_ccache_size (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:280 +#: sssd-kcm.8.xml:279 msgid "" -"How big can a credential cache be per ccache. Each service ticket accounts " -"into this quota." +"How big a credential cache be per ccache. Each service ticket counts toward " +"this quota." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:284 +#: sssd-kcm.8.xml:283 msgid "Default: 65536" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:289 +#: sssd-kcm.8.xml:288 #, fuzzy #| msgid "enumerate (bool)" -msgid "tgt_renewal (bool)" +msgid "tgt_renewal (boolean)" msgstr "enumerate (論理値)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:292 +#: sssd-kcm.8.xml:291 msgid "Enables TGT renewals functionality." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:295 +#: sssd-kcm.8.xml:294 #, fuzzy #| msgid "Default: False (disabled)" msgid "Default: False (Automatic renewals disabled)" msgstr "初期値: False (無効)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:300 +#: sssd-kcm.8.xml:299 #, fuzzy #| msgid "krb5_renew_interval (string)" msgid "tgt_renewal_inherit (string)" msgstr "krb5_renew_interval (文字列)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:303 +#: sssd-kcm.8.xml:302 msgid "Domain to inherit krb5_* options from, for use with TGT renewals." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:307 +#: sssd-kcm.8.xml:306 #, fuzzy #| msgid "Default: 3" msgid "Default: NULL" msgstr "初期値: 3" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-kcm.8.xml:318 +#: sssd-kcm.8.xml:317 msgid "" "<citerefentry> <refentrytitle>sssd</refentrytitle><manvolnum>8</manvolnum> </" "citerefentry>, <citerefentry> <refentrytitle>sssd.conf</" @@ -17353,9 +17932,9 @@ msgstr "" "かをこの属性が決定します。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap-attributes.5.xml:381 sssd-ldap-attributes.5.xml:395 -msgid "Default: loginDisabled" -msgstr "初期値: loginDisabled" +#: sssd-ldap-attributes.5.xml:381 +msgid "Default: loginDisabled (rfc2307, rfc2307bis and IPA), not set (AD)" +msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:387 @@ -17371,6 +17950,12 @@ msgstr "" "ldap_account_expire_policy=nds を使用しているとき、この属性はデータアクセスが" "いつまで許可されるのかを決定します。" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:395 +msgid "" +"Default: loginExpirationTime (rfc2307, rfc2307bis and IPA), not set (AD)" +msgstr "" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:401 msgid "ldap_user_nds_login_allowed_time_map (string)" @@ -17387,8 +17972,9 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:409 -msgid "Default: loginAllowedTimeMap" -msgstr "初期値: loginAllowedTimeMap" +msgid "" +"Default: loginAllowedTimeMap (rfc2307, rfc2307bis and IPA), not set (AD)" +msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:415 @@ -17919,9 +18505,9 @@ msgid "The object class of a host entry in LDAP." msgstr "LDAP にあるホストエントリーのオブジェクトクラスです。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap-attributes.5.xml:900 sssd-ldap-attributes.5.xml:997 -msgid "Default: ipService" -msgstr "初期値: ipService" +#: sssd-ldap-attributes.5.xml:900 sssd-ldap-attributes.5.xml:1213 +msgid "Default: ipHost" +msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:906 @@ -18005,6 +18591,11 @@ msgstr "ldap_service_object_class (文字列)" msgid "The object class of a service entry in LDAP." msgstr "LDAP にあるサービスエントリーのオブジェクトクラスです。" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:997 +msgid "Default: ipService" +msgstr "初期値: ipService" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1003 msgid "ldap_service_name (string)" @@ -18251,11 +18842,6 @@ msgstr "" msgid "The object class of an iphost entry in LDAP." msgstr "" -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap-attributes.5.xml:1213 -msgid "Default: ipHost" -msgstr "" - #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1219 msgid "ldap_iphost_name (string)" @@ -18505,6 +19091,7 @@ msgstr "設定オプション" msgid "" "[plugins]\n" " localauth = {\n" +" disable = an2ln\n" " module = sssd:/usr/lib64/sssd/modules/sssd_krb5_localauth_plugin.so\n" " }\n" msgstr "" @@ -18521,6 +19108,28 @@ msgid "" "the local Kerberos configuration the plugin will be enabled automatically." msgstr "" +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_localauth_plugin.8.xml:67 +msgid "" +"This configuration snippet also disables the <command>an2ln</command> module " +"provided by MIT Kerberos if SSSD is configured to use the AD or IPA " +"provider. In those environments <command>sssd_krb5_localauth_plugin</" +"command> can reliably map the system user names to Kerberos principals. A " +"fallback to <command>an2ln</command> might cause issues in environments " +"where users have the privilege to create Kerberos principals on their own " +"which might collide with names of other users used in the system. Other " +"modules provided by MIT Kerberos, e.g. <command>k5login</command> are not " +"affected." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_localauth_plugin.8.xml:79 +msgid "" +"Note: If using <quote>auth_provider = krb5</quote> then " +"<command>sssd_krb5_localauth_plugin</command> is not used, therefore the " +"above text is not applicable." +msgstr "" + #. type: Content of: <variablelist><varlistentry><term> #: include/autofs_attributes.xml:3 msgid "ldap_autofs_map_object_class (string)" @@ -19421,30 +20030,6 @@ msgid "" "failures; corresponds to setting 2 in decimal notation)" msgstr "" -#. type: Content of: <refsect1><title> -#: include/local.xml:2 -msgid "THE LOCAL DOMAIN" -msgstr "ローカルドメイン" - -#. type: Content of: <refsect1><para> -#: include/local.xml:4 -msgid "" -"In order to function correctly, a domain with <quote>id_provider=local</" -"quote> must be created and the SSSD must be running." -msgstr "" - -#. type: Content of: <refsect1><para> -#: include/local.xml:9 -msgid "" -"The administrator might want to use the SSSD local users instead of " -"traditional UNIX users in cases where the group nesting (see <citerefentry> " -"<refentrytitle>sss_groupadd</refentrytitle> <manvolnum>8</manvolnum> </" -"citerefentry>) is needed. The local users are also useful for testing and " -"development of the SSSD without having to deploy a full remote server. The " -"<command>sss_user*</command> and <command>sss_group*</command> tools use a " -"local LDB storage to store users and groups." -msgstr "" - #. type: Content of: <refsect1><para> #: include/seealso.xml:4 msgid "" @@ -20075,6 +20660,56 @@ msgstr "" "ホストとユーザーのプリンシパルが正規化されるかどうかを指定します。この機能は " "MIT Kerberos 1.7 およびそれ以降で利用可能です。" +#~ msgid "" +#~ "The data types used are string (no quotes needed), integer and bool (with " +#~ "values of <quote>TRUE/FALSE</quote>)." +#~ msgstr "" +#~ "使用されるデータ形式は、文字列(引用符は不要)、整数および論理値" +#~ "(<quote>TRUE/FALSE</quote> の値)です。" + +#~ msgid "services" +#~ msgstr "services" + +#~ msgid "domains" +#~ msgstr "domains" + +#~ msgid "fd_limit" +#~ msgstr "fd_limit" + +#~ msgid "client_idle_timeout" +#~ msgstr "client_idle_timeout" + +#~ msgid "default_shell" +#~ msgstr "default_shell" + +#, fuzzy +#~| msgid "This option can also be set per-domain." +#~ msgid "" +#~ "Note: This option can also be set per-domain which overwrites the value " +#~ "in [nss] section." +#~ msgstr "このオプションはドメインごとに設定できます。" + +#~ msgid "" +#~ "NOTE: On older systems (such as RHEL 5), for this behavior to work " +#~ "reliably, the default Kerberos realm must be set properly in /etc/" +#~ "krb5.conf" +#~ msgstr "" +#~ "注: (RHEL5 のような) 古いシステムにおいて、この動作が正しく機能するために" +#~ "は、デフォルトの Kerberos レルムが /etc/krb5.conf において正しく設定されて" +#~ "いる必要があります" + +#~ msgid "ipa_hbac_selinux (integer)" +#~ msgstr "ipa_hbac_selinux (整数)" + +#~ msgid "Default: loginDisabled" +#~ msgstr "初期値: loginDisabled" + +#~ msgid "Default: loginAllowedTimeMap" +#~ msgstr "初期値: loginAllowedTimeMap" + +#~ msgid "THE LOCAL DOMAIN" +#~ msgstr "ローカルドメイン" + #, fuzzy #~| msgid "ldap_enumeration_refresh_timeout (integer)" #~ msgid "ldap_enumeration_refresh_timeout" @@ -20345,18 +20980,12 @@ msgstr "" #~ "るドメイン、つまり、 <replaceable>id_provider=local</replaceable> を使用す" #~ "るドメインに対する設定を含みます。" -#~ msgid "default_shell (string)" -#~ msgstr "default_shell (文字列)" - #~ msgid "The default shell for users created with SSSD userspace tools." #~ msgstr "SSSD ユーザー空間ツールを用いて作成されたユーザーの初期シェルです。" #~ msgid "Default: <filename>/bin/bash</filename>" #~ msgstr "初期値: <filename>/bin/bash</filename>" -#~ msgid "base_directory (string)" -#~ msgstr "base_directory (文字列)" - #~ msgid "" #~ "The tools append the login name to <replaceable>base_directory</" #~ "replaceable> and use that as the home directory." diff --git a/src/man/po/ka.po b/src/man/po/ka.po index e7bbd26bb43..38a406c1148 100644 --- a/src/man/po/ka.po +++ b/src/man/po/ka.po @@ -8,8 +8,9 @@ msgstr "" "Project-Id-Version: sssd-docs 2.11.0\n" "Report-Msgid-Bugs-To: sssd-devel@redhat.com\n" "POT-Creation-Date: 2025-06-04 14:28+0000\n" -"PO-Revision-Date: 2026-04-23 16:20+0000\n" -"Last-Translator: Temuri Doghonadze <temuri.doghonadze@gmail.com>\n" +"PO-Revision-Date: 2026-10-05 17:17+0000\n" +"Last-Translator: Weblate Translation Memory <noreply-mt-weblate-translation-" +"memory@weblate.org>\n" "Language-Team: Georgian <https://translate.fedoraproject.org/projects/sssd/" "sssd-manpage-master/ka/>\n" "Language: ka\n" @@ -17,7 +18,7 @@ msgstr "" "Content-Type: text/plain; charset=UTF-8\n" "Content-Transfer-Encoding: 8bit\n" "Plural-Forms: nplurals=2; plural=n != 1;\n" -"X-Generator: Weblate 5.17\n" +"X-Generator: Weblate 2026.10\n" #. type: Content of: <reference><title> #: sssd.conf.5.xml:8 sssd-ldap.5.xml:5 pam_sss.8.xml:5 pam_sss_gss.8.xml:5 @@ -63,7 +64,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><title> #: sssd.conf.5.xml:24 msgid "FILE FORMAT" -msgstr "" +msgstr "ფაილის ფორმატი" #. type: Content of: <reference><refentry><refsect1><para><programlisting> #: sssd.conf.5.xml:32 @@ -164,7 +165,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><title> #: sssd.conf.5.xml:103 msgid "GENERAL OPTIONS" -msgstr "" +msgstr "ზოგადი პარამეტრები" #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:105 @@ -179,12 +180,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:113 msgid "debug_level (integer)" -msgstr "" +msgstr "debug_level (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:117 msgid "debug (integer)" -msgstr "" +msgstr "debug (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:120 @@ -198,7 +199,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:130 msgid "debug_timestamps (bool)" -msgstr "" +msgstr "debug_timestamps (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:133 @@ -216,12 +217,12 @@ msgstr "" #: sssd-ipa.5.xml:362 sssd-ad.5.xml:252 sssd-ad.5.xml:367 sssd-ad.5.xml:1232 #: sssd-ad.5.xml:1400 sssd-krb5.5.xml:358 msgid "Default: true" -msgstr "" +msgstr "ნაგულისხმევი: ჭეშმარიტი" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:143 msgid "debug_microseconds (bool)" -msgstr "" +msgstr "debug_microseconds (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:146 @@ -237,12 +238,12 @@ msgstr "" #: sssd-ipa.5.xml:255 sssd-ipa.5.xml:727 sssd-ad.5.xml:1135 sssd-krb5.5.xml:268 #: sssd-krb5.5.xml:330 sssd-krb5.5.xml:432 include/krb5_options.xml:163 msgid "Default: false" -msgstr "" +msgstr "ნაგულისხმევი: ცრუ" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:156 msgid "debug_backtrace_enabled (bool)" -msgstr "" +msgstr "debug_backtrace_enabled (bool)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:159 @@ -277,7 +278,7 @@ msgstr "" #: sssd-ldap-attributes.5.xml:1250 include/autofs_attributes.xml:1 #: include/krb5_options.xml:1 msgid "<placeholder type=\"variablelist\" id=\"0\"/>" -msgstr "" +msgstr "<placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><title> #: sssd.conf.5.xml:184 @@ -287,7 +288,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:188 msgid "timeout (integer)" -msgstr "" +msgstr "timeout (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:191 @@ -302,22 +303,22 @@ msgstr "" #: sssd.conf.5.xml:4170 sssd-ldap.5.xml:820 sssd-idp.5.xml:192 #: include/ldap_id_mapping.xml:270 msgid "Default: 10" -msgstr "" +msgstr "ნაგულისხმევი: 10" #. type: Content of: <reference><refentry><refsect1><title> #: sssd.conf.5.xml:208 msgid "SPECIAL SECTIONS" -msgstr "" +msgstr "სპეციალური განყოფილებები" #. type: Content of: <reference><refentry><refsect1><refsect2><title> #: sssd.conf.5.xml:211 msgid "The [sssd] section" -msgstr "" +msgstr "სექცია [sssd]" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><title> #: sssd.conf.5.xml:220 msgid "Section parameters" -msgstr "" +msgstr "განყოფილების პარამეტრები" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:222 @@ -369,7 +370,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:266 sssd.conf.5.xml:3454 msgid "re_expression (string)" -msgstr "" +msgstr "re_expression (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:269 @@ -389,7 +390,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:283 sssd.conf.5.xml:3511 msgid "full_name_format (string)" -msgstr "" +msgstr "full_name_format (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:286 sssd.conf.5.xml:3514 @@ -408,7 +409,7 @@ msgstr "%1$s" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:298 sssd.conf.5.xml:3526 msgid "user name" -msgstr "" +msgstr "მომხმარებლის სახელი" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:301 sssd.conf.5.xml:3529 @@ -449,7 +450,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:329 msgid "monitor_resolv_conf (boolean)" -msgstr "" +msgstr "monitor_resolv_conf (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:332 @@ -461,7 +462,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:342 msgid "try_inotify (boolean)" -msgstr "" +msgstr "try_inotify (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:345 @@ -496,7 +497,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:368 msgid "krb5_rcache_dir (string)" -msgstr "" +msgstr "krb5_rcache_dir (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:371 @@ -522,7 +523,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:388 msgid "default_domain_suffix (string)" -msgstr "" +msgstr "default_domain_suffix (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:391 @@ -558,12 +559,12 @@ msgstr "" #: include/ldap_id_mapping.xml:211 include/ldap_id_mapping.xml:222 #: include/krb5_options.xml:148 msgid "Default: not set" -msgstr "" +msgstr "ნაგულისხმევი: დაყენებული არაა" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:419 msgid "override_space (string)" -msgstr "" +msgstr "override_space (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:422 @@ -592,7 +593,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:444 msgid "certificate_verification (string)" -msgstr "" +msgstr "certificate_verification (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:452 @@ -672,7 +673,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:500 msgid "partial_chain" -msgstr "" +msgstr "partial_chain" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:502 @@ -685,7 +686,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:511 msgid "ocsp_default_responder=URL" -msgstr "" +msgstr "ocsp_default_responder=URL" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:513 @@ -698,7 +699,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:523 msgid "ocsp_default_responder_signing_cert=NAME" -msgstr "" +msgstr "ocsp_default_responder_signing_cert=NAME" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:525 @@ -710,7 +711,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:533 msgid "crl_file=/PATH/TO/CRL/FILE" -msgstr "" +msgstr "crl_file=/PATH/TO/CRL/FILE" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:535 @@ -724,7 +725,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:548 msgid "soft_crl" -msgstr "" +msgstr "soft_crl" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:551 @@ -756,7 +757,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:573 msgid "disable_netlink (boolean)" -msgstr "" +msgstr "disable_netlink (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:576 @@ -780,7 +781,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:591 msgid "domain_resolution_order" -msgstr "" +msgstr "domain_resolution_order" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:594 @@ -815,12 +816,12 @@ msgstr "" #: sssd-ad.5.xml:187 sssd-ad.5.xml:328 sssd-ad.5.xml:342 sssd-idp.5.xml:108 #: sssd-idp.5.xml:132 sssd-idp.5.xml:145 sssd-idp.5.xml:159 sssd-idp.5.xml:180 msgid "Default: Not set" -msgstr "" +msgstr "ნაგულისხმევი: დაყენებული არაა" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:635 msgid "implicit_pac_responder (boolean)" -msgstr "" +msgstr "implicit_pac_responder (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:638 @@ -833,7 +834,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:649 msgid "core_dumpable (boolean)" -msgstr "" +msgstr "core_dumpable (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:652 @@ -856,12 +857,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:673 msgid "passkey_verification (string)" -msgstr "" +msgstr "passkey_verification (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:681 msgid "user_verification (boolean)" -msgstr "" +msgstr "user_verification (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:683 @@ -924,7 +925,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:723 msgid "fd_limit" -msgstr "" +msgstr "fd_limit" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:726 @@ -944,7 +945,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:740 msgid "client_idle_timeout" -msgstr "" +msgstr "client_idle_timeout" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:743 @@ -959,12 +960,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:752 msgid "Default: 60, KCM: 300" -msgstr "" +msgstr "ნაგულისხმევი: 60, KCM: 300" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:757 msgid "offline_timeout (integer)" -msgstr "" +msgstr "offline_timeout (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:760 @@ -1003,12 +1004,12 @@ msgstr "" #: sssd.conf.5.xml:784 sssd.conf.5.xml:1110 sssd.conf.5.xml:1490 #: sssd.conf.5.xml:1786 sssd-ldap.5.xml:545 msgid "Default: 60" -msgstr "" +msgstr "ნაგულისხმევი: 60" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:789 msgid "offline_timeout_max (integer)" -msgstr "" +msgstr "offline_timeout_max (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:792 @@ -1048,12 +1049,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:815 msgid "Default: 3600" -msgstr "" +msgstr "ნაგულისხმევი: 3600" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:820 msgid "offline_timeout_random_offset (integer)" -msgstr "" +msgstr "offline_timeout_random_offset (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:823 @@ -1072,7 +1073,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:835 msgid "[0 - offline_timeout_random_offset]" -msgstr "" +msgstr "[0 - offline_timeout_random_offset]" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:838 @@ -1082,12 +1083,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:841 msgid "Default: 30" -msgstr "" +msgstr "ნაგულისხმევი: 30" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:846 msgid "responder_idle_timeout" -msgstr "" +msgstr "responder_idle_timeout" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:849 @@ -1105,12 +1106,12 @@ msgstr "" #: sssd.conf.5.xml:863 sssd.conf.5.xml:1123 sssd.conf.5.xml:2215 #: sssd-ldap.5.xml:382 msgid "Default: 300" -msgstr "" +msgstr "ნაგულისხმევი: 300" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:868 msgid "cache_first" -msgstr "" +msgstr "cache_first" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:871 @@ -1134,7 +1135,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:890 msgid "enum_cache_timeout (integer)" -msgstr "" +msgstr "enum_cache_timeout (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:893 @@ -1146,12 +1147,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:897 msgid "Default: 120" -msgstr "" +msgstr "ნაგულისხმევი: 120" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:902 msgid "entry_cache_nowait_percentage (integer)" -msgstr "" +msgstr "entry_cache_nowait_percentage (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:905 @@ -1183,12 +1184,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:929 sssd.conf.5.xml:2028 msgid "Default: 50" -msgstr "" +msgstr "ნაგულისხმევი: 50" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:934 msgid "entry_negative_timeout (integer)" -msgstr "" +msgstr "entry_negative_timeout (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:937 @@ -1201,12 +1202,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:943 sssd.conf.5.xml:1685 sssd.conf.5.xml:2052 msgid "Default: 15" -msgstr "" +msgstr "ნაგულისხმევი: 15" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:948 msgid "filter_users, filter_groups (string)" -msgstr "" +msgstr "filter_users, filter_groups (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:951 @@ -1229,12 +1230,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:967 msgid "Default: root" -msgstr "" +msgstr "ნაგულისხმევი: root" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:972 msgid "filter_users_in_groups (bool)" -msgstr "" +msgstr "filter_users_in_groups (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:975 @@ -1244,7 +1245,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:986 msgid "fallback_homedir (string)" -msgstr "" +msgstr "fallback_homedir (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:989 @@ -1265,6 +1266,8 @@ msgid "" "fallback_homedir = /home/%u\n" " " msgstr "" +"fallback_homedir = /home/%u\n" +" " #. type: Content of: <varlistentry><listitem><para> #: sssd.conf.5.xml:998 sssd.conf.5.xml:1557 sssd.conf.5.xml:1576 @@ -1280,7 +1283,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1010 msgid "override_shell (string)" -msgstr "" +msgstr "override_shell (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1013 @@ -1298,7 +1301,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1025 msgid "allowed_shells (string)" -msgstr "" +msgstr "allowed_shells (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1028 @@ -1357,7 +1360,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1067 msgid "vetoed_shells (string)" -msgstr "" +msgstr "vetoed_shells (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1070 @@ -1367,7 +1370,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1075 msgid "shell_fallback (string)" -msgstr "" +msgstr "shell_fallback (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1078 @@ -1379,12 +1382,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1082 msgid "Default: /bin/sh" -msgstr "" +msgstr "ნაგულისხმევი: /bin/sh" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1087 msgid "default_shell" -msgstr "" +msgstr "default_shell" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1090 @@ -1404,7 +1407,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1103 sssd.conf.5.xml:1483 msgid "get_domains_timeout (int)" -msgstr "" +msgstr "get_domains_timeout (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1106 sssd.conf.5.xml:1486 @@ -1416,7 +1419,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1115 msgid "memcache_timeout (integer)" -msgstr "" +msgstr "memcache_timeout (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1118 @@ -1443,7 +1446,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1140 msgid "memcache_size_passwd (integer)" -msgstr "" +msgstr "memcache_size_passwd (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1143 @@ -1456,7 +1459,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1149 sssd.conf.5.xml:2874 sssd-ldap.5.xml:599 msgid "Default: 8" -msgstr "" +msgstr "ნაგულისხმევი: 8" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1152 sssd.conf.5.xml:1177 sssd.conf.5.xml:1202 @@ -1469,7 +1472,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1165 msgid "memcache_size_group (integer)" -msgstr "" +msgstr "memcache_size_group (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1168 @@ -1484,12 +1487,12 @@ msgstr "" #: sssd-ldap.5.xml:524 sssd-ldap.5.xml:576 include/failover.xml:116 #: include/krb5_options.xml:11 msgid "Default: 6" -msgstr "" +msgstr "ნაგულისხმევი: 6" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1190 msgid "memcache_size_initgroups (integer)" -msgstr "" +msgstr "memcache_size_initgroups (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1193 @@ -1502,7 +1505,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1215 msgid "memcache_size_sid (integer)" -msgstr "" +msgstr "memcache_size_sid (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1218 @@ -1516,7 +1519,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.conf.5.xml:1242 sssd-ifp.5.xml:90 msgid "user_attributes (string)" -msgstr "" +msgstr "user_attributes (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1245 @@ -1545,7 +1548,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1268 msgid "pwfield (string)" -msgstr "" +msgstr "pwfield (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1271 @@ -1557,7 +1560,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1276 msgid "Default: <quote>*</quote>" -msgstr "" +msgstr "ნაგულისხმევი: <quote>*</quote>" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1279 @@ -1588,7 +1591,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1299 msgid "offline_credentials_expiration (integer)" -msgstr "" +msgstr "offline_credentials_expiration (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1302 @@ -1600,12 +1603,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1307 sssd.conf.5.xml:1320 msgid "Default: 0 (No limit)" -msgstr "" +msgstr "ნაგულისხმევი: 0 (შეზღუდვის გარეშე)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1313 msgid "offline_failed_login_attempts (integer)" -msgstr "" +msgstr "offline_failed_login_attempts (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1316 @@ -1617,7 +1620,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1326 msgid "offline_failed_login_delay (integer)" -msgstr "" +msgstr "offline_failed_login_delay (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1329 @@ -1637,12 +1640,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1340 sssd.conf.5.xml:1450 msgid "Default: 5" -msgstr "" +msgstr "ნაგულისხმევი: 5" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1346 msgid "pam_verbosity (integer)" -msgstr "" +msgstr "pam_verbosity (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1349 @@ -1679,12 +1682,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1371 sssd.8.xml:63 msgid "Default: 1" -msgstr "" +msgstr "ნაგულისხმევი: 1" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1377 msgid "pam_response_filter (string)" -msgstr "" +msgstr "pam_response_filter (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1380 @@ -1705,7 +1708,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:1395 msgid "ENV" -msgstr "" +msgstr "ENV" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1396 @@ -1715,7 +1718,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:1399 msgid "ENV:var_name" -msgstr "" +msgstr "ENV:var_name" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1400 @@ -1725,7 +1728,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:1404 msgid "ENV:var_name:service" -msgstr "" +msgstr "ENV:var_name:service" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1405 @@ -1753,7 +1756,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1423 msgid "Default: ENV:KRB5CCNAME:sudo, ENV:KRB5CCNAME:sudo-i" -msgstr "" +msgstr "ნაგულისხმევი: ENV:KRB5CCNAME:sudo, ENV:KRB5CCNAME:sudo-i" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1426 @@ -1763,7 +1766,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1433 msgid "pam_id_timeout (integer)" -msgstr "" +msgstr "pam_id_timeout (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1436 @@ -1786,7 +1789,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1456 msgid "pam_pwd_expiration_warning (integer)" -msgstr "" +msgstr "pam_pwd_expiration_warning (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1459 sssd.conf.5.xml:2898 @@ -1820,12 +1823,12 @@ msgstr "" #: sssd.conf.5.xml:1478 sssd.conf.5.xml:3909 sssd-ldap.5.xml:657 #: sssd-ldap.5.xml:1727 sssd.8.xml:79 msgid "Default: 0" -msgstr "" +msgstr "ნაგულისხმევი: 0" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1495 msgid "pam_trusted_users (string)" -msgstr "" +msgstr "pam_trusted_users (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1498 @@ -1852,7 +1855,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1519 msgid "pam_public_domains (string)" -msgstr "" +msgstr "pam_public_domains (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1522 @@ -1883,12 +1886,12 @@ msgstr "" #: sssd.conf.5.xml:1819 sssd.conf.5.xml:2636 sssd.conf.5.xml:3838 #: sssd-ldap.5.xml:1264 msgid "Default: none" -msgstr "" +msgstr "ნაგულისხმევი: არცერთი" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1543 msgid "pam_account_expired_message (string)" -msgstr "" +msgstr "pam_account_expired_message (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1546 @@ -1915,7 +1918,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1568 msgid "pam_account_locked_message (string)" -msgstr "" +msgstr "pam_account_locked_message (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1571 @@ -1935,7 +1938,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1587 msgid "pam_passkey_auth (bool)" -msgstr "" +msgstr "pam_passkey_auth (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1590 @@ -1946,12 +1949,12 @@ msgstr "" #: sssd.conf.5.xml:1593 sssd.conf.5.xml:1905 sssd-ad.5.xml:1304 #: sss_rpcidmapd.5.xml:76 msgid "Default: True" -msgstr "" +msgstr "ნაგულისხმევი: ჭეშმარიტი" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1598 msgid "passkey_debug_libfido2 (bool)" -msgstr "" +msgstr "passkey_debug_libfido2 (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1601 @@ -1964,12 +1967,12 @@ msgstr "" #: sssd-ad.5.xml:506 sssd-ad.5.xml:582 sssd-ad.5.xml:1155 sssd-ad.5.xml:1207 #: include/ldap_id_mapping.xml:250 msgid "Default: False" -msgstr "" +msgstr "ნაგულისხმევი: ცრუ" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1609 msgid "pam_cert_auth (bool)" -msgstr "" +msgstr "pam_cert_auth (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1612 @@ -1982,7 +1985,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1623 msgid "pam_cert_db_path (string)" -msgstr "" +msgstr "pam_cert_db_path (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1626 @@ -1992,7 +1995,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1629 sssd.conf.5.xml:2130 sssd.conf.5.xml:4334 msgid "Default:" -msgstr "" +msgstr "ნაგულისხმევი:" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:1631 sssd.conf.5.xml:2132 @@ -2004,7 +2007,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1641 msgid "pam_cert_verification (string)" -msgstr "" +msgstr "pam_cert_verification (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1644 @@ -2034,7 +2037,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1666 msgid "p11_child_timeout (integer)" -msgstr "" +msgstr "p11_child_timeout (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1669 @@ -2044,7 +2047,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1678 msgid "passkey_child_timeout (integer)" -msgstr "" +msgstr "passkey_child_timeout (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1681 @@ -2054,7 +2057,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1690 msgid "pam_app_services (string)" -msgstr "" +msgstr "pam_app_services (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1693 @@ -2066,7 +2069,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1702 msgid "pam_p11_allowed_services (string)" -msgstr "" +msgstr "pam_p11_allowed_services (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1705 @@ -2104,52 +2107,52 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:1729 sssd-ad.5.xml:649 msgid "login" -msgstr "" +msgstr "login" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:1734 sssd-ad.5.xml:654 msgid "su" -msgstr "" +msgstr "su" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:1739 sssd-ad.5.xml:659 msgid "su-l" -msgstr "" +msgstr "su-l" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:1744 sssd-ad.5.xml:674 msgid "gdm-smartcard" -msgstr "" +msgstr "gdm-smartcard" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:1749 sssd-ad.5.xml:669 msgid "gdm-password" -msgstr "" +msgstr "gdm-password" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:1754 sssd-ad.5.xml:679 msgid "kdm" -msgstr "" +msgstr "kdm" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:1759 sssd-ad.5.xml:957 msgid "sudo" -msgstr "" +msgstr "sudo" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:1764 sssd-ad.5.xml:962 msgid "sudo-i" -msgstr "" +msgstr "sudo-i" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:1769 msgid "gnome-screensaver" -msgstr "" +msgstr "gnome-screensaver" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1777 msgid "p11_wait_for_card_timeout (integer)" -msgstr "" +msgstr "p11_wait_for_card_timeout (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1780 @@ -2162,7 +2165,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1791 msgid "p11_uri (string)" -msgstr "" +msgstr "p11_uri (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1794 @@ -2204,12 +2207,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1824 msgid "pam_initgroups_scheme" -msgstr "" +msgstr "pam_initgroups_scheme" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:1832 msgid "always" -msgstr "" +msgstr "ყოველთვის" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1833 @@ -2219,7 +2222,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:1837 msgid "no_session" -msgstr "" +msgstr "no_session" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1838 @@ -2231,7 +2234,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:1843 sssd-ldap.5.xml:189 msgid "never" -msgstr "" +msgstr "არასოდეს" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1844 @@ -2252,12 +2255,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1851 msgid "Default: no_session" -msgstr "" +msgstr "ნაგულისხმევი: no_session" #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:1856 sssd.conf.5.xml:4273 msgid "pam_gssapi_services" -msgstr "" +msgstr "pam_gssapi_services" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1859 @@ -2288,11 +2291,13 @@ msgid "" "pam_gssapi_services = sudo, sudo-i\n" " " msgstr "" +"pam_gssapi_services = sudo, sudo-i\n" +" " #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1874 sssd.conf.5.xml:3832 msgid "Example: <placeholder type=\"programlisting\" id=\"0\"/>" -msgstr "" +msgstr "მაგალითი: <placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1880 @@ -2302,7 +2307,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:1885 sssd.conf.5.xml:4274 msgid "pam_gssapi_check_upn" -msgstr "" +msgstr "pam_gssapi_check_upn" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1888 @@ -2322,7 +2327,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1910 msgid "pam_gssapi_indicators_map" -msgstr "" +msgstr "pam_gssapi_indicators_map" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1913 @@ -2400,6 +2405,8 @@ msgid "" "pam_gssapi_indicators_map = sudo:pkinit, sudo-i:pkinit\n" " " msgstr "" +"pam_gssapi_indicators_map = sudo:pkinit, sudo-i:pkinit\n" +" " #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1963 @@ -2417,7 +2424,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> #: sssd.conf.5.xml:1980 msgid "SUDO configuration options" -msgstr "" +msgstr "SUDO-ის კონფიგურაციის პარამეტრები" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sssd.conf.5.xml:1982 @@ -2434,7 +2441,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1999 msgid "sudo_timed (bool)" -msgstr "" +msgstr "sudo_timed (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2002 @@ -2446,7 +2453,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:2014 msgid "sudo_threshold (integer)" -msgstr "" +msgstr "sudo_threshold (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2017 @@ -2462,7 +2469,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> #: sssd.conf.5.xml:2036 msgid "AUTOFS configuration options" -msgstr "" +msgstr "AUTOFS-ის კონფიგურაციის პარამეტრები" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sssd.conf.5.xml:2038 @@ -2472,7 +2479,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:2042 msgid "autofs_negative_timeout (integer)" -msgstr "" +msgstr "autofs_negative_timeout (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2045 @@ -2485,7 +2492,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> #: sssd.conf.5.xml:2061 msgid "SSH configuration options" -msgstr "" +msgstr "SSH-ის კონფიგურაციის პარამეტრები" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sssd.conf.5.xml:2063 @@ -2495,7 +2502,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:2067 msgid "ssh_use_certificate_keys (bool)" -msgstr "" +msgstr "ssh_use_certificate_keys (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2070 @@ -2510,7 +2517,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:2085 msgid "ssh_use_certificate_matching_rules (string)" -msgstr "" +msgstr "ssh_use_certificate_matching_rules (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2088 @@ -2556,7 +2563,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:2122 msgid "ca_db (string)" -msgstr "" +msgstr "ca_db (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2125 @@ -2607,7 +2614,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.conf.5.xml:2174 sssd-ifp.5.xml:66 msgid "allowed_uids (string)" -msgstr "" +msgstr "allowed_uids (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2177 @@ -2650,7 +2657,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:2207 msgid "pac_lifetime (integer)" -msgstr "" +msgstr "pac_lifetime (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2210 @@ -2662,7 +2669,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:2220 msgid "pac_check (string)" -msgstr "" +msgstr "pac_check (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2223 @@ -2678,7 +2685,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2237 msgid "no_check" -msgstr "" +msgstr "no_check" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2239 @@ -2690,7 +2697,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2245 msgid "pac_present" -msgstr "" +msgstr "pac_present" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2247 @@ -2703,7 +2710,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2255 msgid "check_upn" -msgstr "" +msgstr "check_upn" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2257 @@ -2715,7 +2722,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2263 msgid "check_upn_allow_missing" -msgstr "" +msgstr "check_upn_allow_missing" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2265 @@ -2743,7 +2750,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2291 msgid "upn_dns_info_present" -msgstr "" +msgstr "upn_dns_info_present" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2293 @@ -2753,7 +2760,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2298 msgid "check_upn_dns_info_ex" -msgstr "" +msgstr "check_upn_dns_info_ex" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2300 @@ -2765,7 +2772,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2307 msgid "upn_dns_info_ex_present" -msgstr "" +msgstr "upn_dns_info_ex_present" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2309 @@ -2812,12 +2819,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.conf.5.xml:2347 sssd-session-recording.5.xml:64 msgid "scope (string)" -msgstr "" +msgstr "scope (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2354 sssd-session-recording.5.xml:71 msgid "\"none\"" -msgstr "" +msgstr "„none“" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2357 sssd-session-recording.5.xml:74 @@ -2827,7 +2834,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2362 sssd-session-recording.5.xml:79 msgid "\"some\"" -msgstr "" +msgstr "\"some\"" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2365 sssd-session-recording.5.xml:82 @@ -2839,7 +2846,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2374 sssd-session-recording.5.xml:91 msgid "\"all\"" -msgstr "" +msgstr "\"all\"" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2377 sssd-session-recording.5.xml:94 @@ -2856,12 +2863,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2384 sssd-session-recording.5.xml:101 msgid "Default: \"none\"" -msgstr "" +msgstr "ნაგულისხმევი: \"none\"" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.conf.5.xml:2389 sssd-session-recording.5.xml:106 msgid "users (string)" -msgstr "" +msgstr "users (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2392 sssd-session-recording.5.xml:109 @@ -2879,7 +2886,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.conf.5.xml:2403 sssd-session-recording.5.xml:120 msgid "groups (string)" -msgstr "" +msgstr "groups (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2406 sssd-session-recording.5.xml:123 @@ -2906,7 +2913,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.conf.5.xml:2424 sssd-session-recording.5.xml:141 msgid "exclude_users (string)" -msgstr "" +msgstr "exclude_users (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2427 sssd-session-recording.5.xml:144 @@ -2923,7 +2930,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.conf.5.xml:2436 sssd-session-recording.5.xml:153 msgid "exclude_groups (string)" -msgstr "" +msgstr "exclude_groups (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2439 sssd-session-recording.5.xml:156 @@ -2946,7 +2953,7 @@ msgstr "" #: sssd.conf.5.xml:2468 sssd.conf.5.xml:3960 sssd.conf.5.xml:3961 #: sssd.conf.5.xml:3964 msgid "enabled" -msgstr "" +msgstr "enabled" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2471 @@ -2961,7 +2968,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2483 msgid "domain_type (string)" -msgstr "" +msgstr "domain_type (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2486 @@ -3005,12 +3012,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2514 msgid "Default: posix" -msgstr "" +msgstr "ნაგულისხმევი: posix" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2520 msgid "min_id,max_id (integer)" -msgstr "" +msgstr "min_id,max_id (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2523 @@ -3043,7 +3050,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2545 msgid "enumerate (bool)" -msgstr "" +msgstr "enumerate (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2548 @@ -3067,7 +3074,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2562 sssd.conf.5.xml:2853 sssd.conf.5.xml:3030 msgid "Default: FALSE" -msgstr "" +msgstr "ნაგულისხმევი: ცრუ" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2565 @@ -3131,12 +3138,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2616 msgid "subdomain_enumerate (string)" -msgstr "" +msgstr "subdomain_enumerate (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2623 msgid "all" -msgstr "" +msgstr "ყველა" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2624 @@ -3146,7 +3153,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2627 msgid "none" -msgstr "" +msgstr "არცერთი" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2628 @@ -3165,7 +3172,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2642 msgid "entry_cache_timeout (integer)" -msgstr "" +msgstr "entry_cache_timeout (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2645 @@ -3188,12 +3195,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2662 msgid "Default: 5400" -msgstr "" +msgstr "ნაგულისხმევი: 5400" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2668 msgid "entry_cache_user_timeout (integer)" -msgstr "" +msgstr "entry_cache_user_timeout (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2671 @@ -3207,12 +3214,12 @@ msgstr "" #: sssd.conf.5.xml:2714 sssd.conf.5.xml:2728 sssd.conf.5.xml:2741 #: sssd.conf.5.xml:2755 sssd.conf.5.xml:2769 sssd.conf.5.xml:2782 msgid "Default: entry_cache_timeout" -msgstr "" +msgstr "ნაგულისხმევი: entry_cache_timeout" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2681 msgid "entry_cache_group_timeout (integer)" -msgstr "" +msgstr "entry_cache_group_timeout (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2684 @@ -3224,7 +3231,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2694 msgid "entry_cache_netgroup_timeout (integer)" -msgstr "" +msgstr "entry_cache_netgroup_timeout (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2697 @@ -3236,7 +3243,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2707 msgid "entry_cache_service_timeout (integer)" -msgstr "" +msgstr "entry_cache_service_timeout (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2710 @@ -3248,7 +3255,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2720 msgid "entry_cache_resolver_timeout (integer)" -msgstr "" +msgstr "entry_cache_resolver_timeout (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2723 @@ -3260,7 +3267,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2734 msgid "entry_cache_sudo_timeout (integer)" -msgstr "" +msgstr "entry_cache_sudo_timeout (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2737 @@ -3272,7 +3279,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2747 msgid "entry_cache_autofs_timeout (integer)" -msgstr "" +msgstr "entry_cache_autofs_timeout (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2750 @@ -3284,7 +3291,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2761 msgid "entry_cache_ssh_host_timeout (integer)" -msgstr "" +msgstr "entry_cache_ssh_host_timeout (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2764 @@ -3296,7 +3303,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2775 msgid "entry_cache_computer_timeout (integer)" -msgstr "" +msgstr "entry_cache_computer_timeout (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2778 @@ -3308,7 +3315,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2788 msgid "refresh_expired_interval (integer)" -msgstr "" +msgstr "refresh_expired_interval (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2791 @@ -3352,12 +3359,12 @@ msgstr "" #: sssd.conf.5.xml:2825 sssd-ldap.5.xml:411 sssd-ldap.5.xml:1828 #: sssd-ipa.5.xml:271 msgid "Default: 0 (disabled)" -msgstr "" +msgstr "ნაგულისხმევი: 0 (გათიშულია)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2831 msgid "cache_credentials (bool)" -msgstr "" +msgstr "cache_credentials (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2834 @@ -3382,7 +3389,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2859 msgid "cache_credentials_minimal_first_factor_length (int)" -msgstr "" +msgstr "cache_credentials_minimal_first_factor_length (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2862 @@ -3402,7 +3409,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2880 msgid "account_cache_expiration (integer)" -msgstr "" +msgstr "account_cache_expiration (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2883 @@ -3416,12 +3423,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2890 msgid "Default: 0 (unlimited)" -msgstr "" +msgstr "ნაგულისხმევი: 0 (შეუზღუდავი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2895 msgid "pwd_expiration_warning (integer)" -msgstr "" +msgstr "pwd_expiration_warning (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2906 @@ -3435,12 +3442,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2913 msgid "Default: 7 (Kerberos), 0 (LDAP)" -msgstr "" +msgstr "ნაგულისხმევი: 7 (Kerberos), 0 (LDAP)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2919 msgid "id_provider (string)" -msgstr "" +msgstr "id_provider (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2922 @@ -3492,7 +3499,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2965 msgid "use_fully_qualified_names (bool)" -msgstr "" +msgstr "use_fully_qualified_names (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2968 @@ -3528,7 +3535,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2995 msgid "ignore_group_members (bool)" -msgstr "" +msgstr "ignore_group_members (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2998 @@ -3569,7 +3576,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3035 msgid "auth_provider (string)" -msgstr "" +msgstr "auth_provider (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3038 @@ -3622,7 +3629,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3093 msgid "access_provider (string)" -msgstr "" +msgstr "access_provider (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3096 @@ -3668,12 +3675,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3149 msgid "Default: <quote>permit</quote>" -msgstr "" +msgstr "ნაგულისხმევი: <quote>permit</quote>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3154 msgid "chpass_provider (string)" -msgstr "" +msgstr "chpass_provider (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3157 @@ -3719,7 +3726,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3209 msgid "sudo_provider (string)" -msgstr "" +msgstr "sudo_provider (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3212 @@ -3783,7 +3790,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3264 msgid "selinux_provider (string)" -msgstr "" +msgstr "selinux_provider (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3267 @@ -3817,7 +3824,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3290 msgid "subdomains_provider (string)" -msgstr "" +msgstr "subdomains_provider (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3293 @@ -3859,7 +3866,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3327 msgid "session_provider (string)" -msgstr "" +msgstr "session_provider (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3330 @@ -3889,7 +3896,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3352 msgid "autofs_provider (string)" -msgstr "" +msgstr "autofs_provider (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3355 @@ -3935,7 +3942,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3393 msgid "hostid_provider (string)" -msgstr "" +msgstr "hostid_provider (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3396 @@ -3968,7 +3975,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3418 msgid "resolver_provider (string)" -msgstr "" +msgstr "resolver_provider (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3421 @@ -4035,12 +4042,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:3471 sssd.conf.5.xml:3485 msgid "username" -msgstr "" +msgstr "მომხმარებლის სახელი" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:3474 sssd.conf.5.xml:3488 msgid "username@domain.name" -msgstr "" +msgstr "username@domain.name" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3479 @@ -4053,7 +4060,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:3491 msgid "domain\\username" -msgstr "" +msgstr "domain\\username" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3494 @@ -4080,7 +4087,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3557 msgid "lookup_family_order (string)" -msgstr "" +msgstr "lookup_family_order (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3560 @@ -4092,7 +4099,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3564 msgid "Supported values:" -msgstr "" +msgstr "მხარდაჭერილი მნიშვნელობები:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3567 @@ -4117,12 +4124,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3579 msgid "Default: ipv4_first" -msgstr "" +msgstr "ნაგულისხმევი: ipv4_first" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3585 msgid "dns_resolver_server_timeout (integer)" -msgstr "" +msgstr "dns_resolver_server_timeout (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3588 @@ -4146,12 +4153,12 @@ msgstr "" #. type: Content of: <refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3602 sssd-ldap.5.xml:695 include/failover.xml:84 msgid "Default: 1000" -msgstr "" +msgstr "ნაგულისხმევი: 1000" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3608 msgid "dns_resolver_op_timeout (integer)" -msgstr "" +msgstr "dns_resolver_op_timeout (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3611 @@ -4164,12 +4171,12 @@ msgstr "" #. type: Content of: <refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3622 include/failover.xml:100 msgid "Default: 3" -msgstr "" +msgstr "ნაგულისხმევი: 3" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3628 msgid "dns_resolver_timeout (integer)" -msgstr "" +msgstr "dns_resolver_timeout (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3631 @@ -4183,7 +4190,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3649 msgid "dns_resolver_use_search_list (bool)" -msgstr "" +msgstr "dns_resolver_use_search_list (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3652 @@ -4204,12 +4211,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3664 msgid "Default: TRUE" -msgstr "" +msgstr "ნაგულისხმევი: ჭეშმარიტი" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3670 msgid "dns_discovery_domain (string)" -msgstr "" +msgstr "dns_discovery_domain (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3673 @@ -4226,7 +4233,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3683 msgid "failover_primary_timeout (integer)" -msgstr "" +msgstr "failover_primary_timeout (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3686 @@ -4244,12 +4251,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3696 msgid "Default: 31" -msgstr "" +msgstr "ნაგულისხმევი: 31" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3702 msgid "override_gid (integer)" -msgstr "" +msgstr "override_gid (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3705 @@ -4259,12 +4266,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3711 msgid "case_sensitive (string)" -msgstr "" +msgstr "case_sensitive (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3718 msgid "True" -msgstr "" +msgstr "ჭეშმარიტი" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3721 @@ -4274,7 +4281,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3727 msgid "False" -msgstr "" +msgstr "მცდარი" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3729 @@ -4284,7 +4291,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3733 msgid "Preserving" -msgstr "" +msgstr "შენარჩუნება" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3736 @@ -4316,7 +4323,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3765 msgid "subdomain_inherit (string)" -msgstr "" +msgstr "subdomain_inherit (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3768 @@ -4329,42 +4336,42 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3774 msgid "ldap_search_timeout" -msgstr "" +msgstr "ldap_search_timeout" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3777 msgid "ldap_network_timeout" -msgstr "" +msgstr "ldap_network_timeout" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3780 msgid "ldap_opt_timeout" -msgstr "" +msgstr "ldap_opt_timeout" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3783 msgid "ldap_offline_timeout" -msgstr "" +msgstr "ldap_offline_timeout" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3786 msgid "ldap_enumeration_refresh_timeout" -msgstr "" +msgstr "ldap_enumeration_refresh_timeout" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3789 msgid "ldap_enumeration_refresh_offset" -msgstr "" +msgstr "ldap_enumeration_refresh_offset" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3792 msgid "ldap_purge_cache_timeout" -msgstr "" +msgstr "ldap_purge_cache_timeout" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3795 msgid "ldap_purge_cache_offset" -msgstr "" +msgstr "ldap_purge_cache_offset" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3798 @@ -4376,52 +4383,52 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3802 msgid "ldap_krb5_ticket_lifetime" -msgstr "" +msgstr "ldap_krb5_ticket_lifetime" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3805 msgid "ldap_enumeration_search_timeout" -msgstr "" +msgstr "ldap_enumeration_search_timeout" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3808 msgid "ldap_connection_expire_timeout" -msgstr "" +msgstr "ldap_connection_expire_timeout" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3811 msgid "ldap_connection_expire_offset" -msgstr "" +msgstr "ldap_connection_expire_offset" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3814 msgid "ldap_connection_idle_timeout" -msgstr "" +msgstr "ldap_connection_idle_timeout" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3817 sssd-ldap.5.xml:451 msgid "ldap_use_tokengroups" -msgstr "" +msgstr "ldap_use_tokengroups" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3820 msgid "ldap_user_principal" -msgstr "" +msgstr "ldap_user_principal" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3823 msgid "ignore_group_members" -msgstr "" +msgstr "ignore_group_members" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3826 msgid "auto_private_groups" -msgstr "" +msgstr "auto_private_groups" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3829 msgid "case_sensitive" -msgstr "" +msgstr "case_sensitive" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> #: sssd.conf.5.xml:3834 @@ -4439,12 +4446,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3848 msgid "subdomain_homedir (string)" -msgstr "" +msgstr "subdomain_homedir (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3859 msgid "%F" -msgstr "" +msgstr "%F" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3860 @@ -4474,7 +4481,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3874 msgid "realmd_tags (string)" -msgstr "" +msgstr "realmd_tags (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3877 @@ -4484,7 +4491,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3883 msgid "cached_auth_timeout (int)" -msgstr "" +msgstr "cached_auth_timeout (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3886 @@ -4518,7 +4525,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3914 msgid "local_auth_policy (string)" -msgstr "" +msgstr "local_auth_policy (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3917 @@ -4560,32 +4567,32 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> #: sssd.conf.5.xml:3956 msgid "Passkey" -msgstr "" +msgstr "საკვანძო გასაღები" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> #: sssd.conf.5.xml:3957 msgid "Smartcard" -msgstr "" +msgstr "Smart ბარათი" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:3960 sssd-ldap.5.xml:228 msgid "IPA" -msgstr "" +msgstr "IPA" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:3963 sssd-ldap.5.xml:233 msgid "AD" -msgstr "" +msgstr "AD" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry><para> #: sssd.conf.5.xml:3963 sssd.conf.5.xml:3966 sssd.conf.5.xml:3967 msgid "disabled" -msgstr "" +msgstr "გამორთულია" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry> #: sssd.conf.5.xml:3966 msgid "LDAP" -msgstr "" +msgstr "LDAP" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3971 @@ -4618,17 +4625,17 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3991 msgid "Default: match" -msgstr "" +msgstr "ნაგულისხმევი: დამთხვევა" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3996 msgid "auto_private_groups (string)" -msgstr "" +msgstr "auto_private_groups (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:4002 msgid "true" -msgstr "" +msgstr "ჭეშმარიტი" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4005 @@ -4649,7 +4656,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:4018 msgid "false" -msgstr "" +msgstr "მცდარი" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4021 @@ -4661,7 +4668,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:4027 msgid "hybrid" -msgstr "" +msgstr "ჰიბრიდი" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4030 @@ -4750,7 +4757,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:4100 msgid "proxy_pam_target (string)" -msgstr "" +msgstr "proxy_pam_target (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4103 @@ -4768,7 +4775,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:4116 msgid "proxy_lib_name (string)" -msgstr "" +msgstr "proxy_lib_name (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4119 @@ -4781,7 +4788,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:4129 msgid "proxy_resolver_lib_name (string)" -msgstr "" +msgstr "proxy_resolver_lib_name (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4132 @@ -4794,7 +4801,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:4143 msgid "proxy_fast_alias (boolean)" -msgstr "" +msgstr "proxy_fast_alias (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4146 @@ -4808,7 +4815,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:4160 msgid "proxy_max_children (integer)" -msgstr "" +msgstr "proxy_max_children (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4163 @@ -4828,7 +4835,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> #: sssd.conf.5.xml:4179 msgid "Application domains" -msgstr "" +msgstr "აპლიკაციის დომენები" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sssd.conf.5.xml:4181 @@ -4864,7 +4871,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:4209 msgid "inherit_from (string)" -msgstr "" +msgstr "inherit_from (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4212 @@ -4924,52 +4931,52 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:4263 msgid "ldap_search_base," -msgstr "" +msgstr "ldap_search_base," #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:4264 msgid "ldap_user_search_base," -msgstr "" +msgstr "ldap_user_search_base," #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:4265 msgid "ldap_group_search_base," -msgstr "" +msgstr "ldap_group_search_base," #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:4266 msgid "ldap_netgroup_search_base," -msgstr "" +msgstr "ldap_netgroup_search_base," #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:4267 msgid "ldap_service_search_base," -msgstr "" +msgstr "ldap_service_search_base," #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:4268 msgid "ldap_sasl_mech," -msgstr "" +msgstr "ldap_sasl_mech," #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:4269 msgid "ad_server," -msgstr "" +msgstr "ad_server," #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:4270 msgid "ad_backup_server," -msgstr "" +msgstr "ad_backup_server," #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:4271 msgid "ad_site," -msgstr "" +msgstr "ad_site," #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:4272 sssd-ipa.5.xml:955 msgid "use_fully_qualified_names" -msgstr "" +msgstr "use_fully_qualified_names" #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:4276 @@ -5017,7 +5024,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.conf.5.xml:4314 msgid "matchrule (string)" -msgstr "" +msgstr "matchrule (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4317 @@ -5036,7 +5043,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.conf.5.xml:4328 msgid "maprule (string)" -msgstr "" +msgstr "maprule (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4331 @@ -5060,7 +5067,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.conf.5.xml:4353 msgid "domains (string)" -msgstr "" +msgstr "domains (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4356 @@ -5079,7 +5086,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.conf.5.xml:4368 msgid "priority (integer)" -msgstr "" +msgstr "priority (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4371 @@ -5121,12 +5128,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:4407 msgid "[prompting/password]" -msgstr "" +msgstr "[prompting/password]" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:4410 msgid "password_prompt" -msgstr "" +msgstr "password_prompt" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4411 @@ -5143,12 +5150,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:4419 msgid "[prompting/2fa]" -msgstr "" +msgstr "[prompting/2fa]" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:4423 msgid "first_prompt" -msgstr "" +msgstr "first_prompt" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4424 @@ -5158,7 +5165,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:4427 msgid "second_prompt" -msgstr "" +msgstr "second_prompt" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4428 @@ -5168,7 +5175,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:4431 msgid "single_prompt" -msgstr "" +msgstr "single_prompt" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4432 @@ -5202,12 +5209,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:4460 msgid "[prompting/passkey]" -msgstr "" +msgstr "[prompting/passkey]" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:4466 sssd-ad.5.xml:1022 msgid "interactive" -msgstr "" +msgstr "ინტერაქტიური" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4468 @@ -5220,7 +5227,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:4476 msgid "interactive_prompt" -msgstr "" +msgstr "interactive_prompt" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4478 @@ -5230,7 +5237,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:4483 msgid "touch" -msgstr "" +msgstr "touch" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4485 @@ -5242,7 +5249,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:4491 msgid "touch_prompt" -msgstr "" +msgstr "touch_prompt" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4493 @@ -5276,7 +5283,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><title> #: sssd.conf.5.xml:4511 pam_sss_gss.8.xml:157 idmap_sss.8.xml:43 msgid "EXAMPLES" -msgstr "" +msgstr "მაგალითები" #. type: Content of: <reference><refentry><refsect1><para><programlisting> #: sssd.conf.5.xml:4517 @@ -5359,7 +5366,7 @@ msgstr "" #. type: Content of: <reference><refentry><refnamediv><refname> #: sssd-ldap.5.xml:10 sssd-ldap.5.xml:16 msgid "sssd-ldap" -msgstr "" +msgstr "sssd-ldap" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sssd-ldap.5.xml:17 @@ -5377,7 +5384,7 @@ msgstr "" #: sssd-session-recording.5.xml:21 sssd-kcm.8.xml:21 sssd-systemtap.5.xml:21 #: sssd-ldap-attributes.5.xml:21 sssd_krb5_localauth_plugin.8.xml:20 msgid "DESCRIPTION" -msgstr "" +msgstr "აღწერა" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ldap.5.xml:23 @@ -5417,7 +5424,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:67 msgid "ldap_uri, ldap_backup_uri (string)" -msgstr "" +msgstr "ldap_uri, ldap_backup_uri (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:70 @@ -5438,7 +5445,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:80 msgid "ldap[s]://<host>[:port]" -msgstr "" +msgstr "ldap[s]://<host>[:port]" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:83 @@ -5448,12 +5455,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:86 msgid "example: ldap://[fc00::126:25]:389" -msgstr "" +msgstr "მაგალითი: ldap://[fc00::126:25]:389" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:92 msgid "ldap_chpass_uri, ldap_chpass_backup_uri (string)" -msgstr "" +msgstr "ldap_chpass_uri, ldap_chpass_backup_uri (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:95 @@ -5477,7 +5484,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:112 msgid "ldap_search_base (string)" -msgstr "" +msgstr "ldap_search_base (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:115 @@ -5494,7 +5501,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:123 msgid "search_base[?scope?[filter][?search_base?scope?[filter]]*]" -msgstr "" +msgstr "search_base[?scope?[filter][?search_base?scope?[filter]]*]" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:126 @@ -5512,7 +5519,7 @@ msgstr "" #: sssd-ldap.5.xml:133 sssd-ad.5.xml:312 sss_override.8.xml:143 #: sss_override.8.xml:240 sssd-ldap-attributes.5.xml:453 msgid "Examples:" -msgstr "" +msgstr "მაგალითები:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:136 @@ -5551,7 +5558,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:165 msgid "ldap_read_rootdse (string)" -msgstr "" +msgstr "ldap_read_rootdse (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:168 @@ -5565,17 +5572,17 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:175 msgid "Allowed values are:" -msgstr "" +msgstr "დაშვებული მნიშვნელობებია:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ldap.5.xml:179 msgid "anonymous" -msgstr "" +msgstr "anonymous" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ldap.5.xml:184 msgid "authenticated" -msgstr "" +msgstr "authenticated" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:193 @@ -5587,12 +5594,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:198 msgid "Default: anonymous" -msgstr "" +msgstr "ნაგულისხმევი: anonymous" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:204 msgid "ldap_schema (string)" -msgstr "" +msgstr "ldap_schema (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:207 @@ -5610,12 +5617,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ldap.5.xml:218 msgid "rfc2307" -msgstr "" +msgstr "rfc2307" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ldap.5.xml:223 msgid "rfc2307bis" -msgstr "" +msgstr "rfc2307bis" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:239 @@ -5631,12 +5638,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:249 msgid "Default: rfc2307" -msgstr "" +msgstr "ნაგულისხმევი: rfc2307" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:255 msgid "ldap_pwmodify_mode (string)" -msgstr "" +msgstr "ldap_pwmodify_mode (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:258 @@ -5646,7 +5653,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:262 msgid "Two modes are currently supported:" -msgstr "" +msgstr "ამჟამად მხარდაჭერილია ორი რეჟიმი:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ldap.5.xml:266 @@ -5679,12 +5686,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:298 msgid "Default: exop" -msgstr "" +msgstr "ნაგულისხმევი: exop" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:304 msgid "ldap_default_bind_dn (string)" -msgstr "" +msgstr "ldap_default_bind_dn (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:307 @@ -5694,7 +5701,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:314 msgid "ldap_default_authtok_type (string)" -msgstr "" +msgstr "ldap_default_authtok_type (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:317 @@ -5709,17 +5716,17 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:324 msgid "password" -msgstr "" +msgstr "password" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:327 msgid "obfuscated_password" -msgstr "" +msgstr "obfuscated_password" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:330 msgid "Default: password" -msgstr "" +msgstr "ნაგულისხმევი: password" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:333 @@ -5731,7 +5738,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:344 msgid "ldap_default_authtok (string)" -msgstr "" +msgstr "ldap_default_authtok (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:347 @@ -5741,7 +5748,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:353 msgid "ldap_force_upper_case_realm (boolean)" -msgstr "" +msgstr "ldap_force_upper_case_realm (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:356 @@ -5755,7 +5762,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:369 msgid "ldap_enumeration_refresh_timeout (integer)" -msgstr "" +msgstr "ldap_enumeration_refresh_timeout (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:372 @@ -5767,7 +5774,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:388 msgid "ldap_purge_cache_timeout (integer)" -msgstr "" +msgstr "ldap_purge_cache_timeout (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:391 @@ -5789,7 +5796,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:417 msgid "ldap_group_nesting_level (integer)" -msgstr "" +msgstr "ldap_group_nesting_level (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:420 @@ -5822,7 +5829,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:445 msgid "Default: 2" -msgstr "" +msgstr "ნაგულისხმევი: 2" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:454 @@ -5839,7 +5846,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:470 msgid "ldap_host_search_base (string)" -msgstr "" +msgstr "ldap_host_search_base (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:473 @@ -5862,22 +5869,22 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:489 msgid "ldap_service_search_base (string)" -msgstr "" +msgstr "ldap_service_search_base (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:494 msgid "ldap_iphost_search_base (string)" -msgstr "" +msgstr "ldap_iphost_search_base (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:499 msgid "ldap_ipnetwork_search_base (string)" -msgstr "" +msgstr "ldap_ipnetwork_search_base (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:504 msgid "ldap_search_timeout (integer)" -msgstr "" +msgstr "ldap_search_timeout (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:507 @@ -5898,7 +5905,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:530 msgid "ldap_enumeration_search_timeout (integer)" -msgstr "" +msgstr "ldap_enumeration_search_timeout (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:533 @@ -5911,7 +5918,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:551 msgid "ldap_network_timeout (integer)" -msgstr "" +msgstr "ldap_network_timeout (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:554 @@ -5927,7 +5934,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:582 msgid "ldap_opt_timeout (integer)" -msgstr "" +msgstr "ldap_opt_timeout (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:585 @@ -5941,7 +5948,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:605 msgid "ldap_connection_expire_timeout (integer)" -msgstr "" +msgstr "ldap_connection_expire_timeout (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:608 @@ -5973,12 +5980,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:638 sssd-ldap.5.xml:681 sssd-ldap.5.xml:1803 msgid "Default: 900 (15 minutes)" -msgstr "" +msgstr "ნაგულისხმევი: 900 (15 წთ)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:644 msgid "ldap_connection_expire_offset (integer)" -msgstr "" +msgstr "ldap_connection_expire_offset (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:647 @@ -5990,7 +5997,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:663 msgid "ldap_connection_idle_timeout (integer)" -msgstr "" +msgstr "ldap_connection_idle_timeout (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:666 @@ -6008,7 +6015,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:687 msgid "ldap_page_size (integer)" -msgstr "" +msgstr "ldap_page_size (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:690 @@ -6020,7 +6027,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:701 msgid "ldap_disable_paging (boolean)" -msgstr "" +msgstr "ldap_disable_paging (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:704 @@ -6049,7 +6056,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:728 msgid "ldap_disable_range_retrieval (boolean)" -msgstr "" +msgstr "ldap_disable_range_retrieval (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:731 @@ -6072,7 +6079,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:753 msgid "ldap_sasl_minssf (integer)" -msgstr "" +msgstr "ldap_sasl_minssf (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:756 @@ -6090,7 +6097,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:769 msgid "ldap_sasl_maxssf (integer)" -msgstr "" +msgstr "ldap_sasl_maxssf (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:772 @@ -6103,7 +6110,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:785 msgid "ldap_deref_threshold (integer)" -msgstr "" +msgstr "ldap_deref_threshold (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:788 @@ -6144,7 +6151,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:826 msgid "ldap_ignore_unreadable_references (bool)" -msgstr "" +msgstr "ldap_ignore_unreadable_references (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:829 @@ -6165,7 +6172,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:849 msgid "ldap_tls_reqcert (string)" -msgstr "" +msgstr "ldap_tls_reqcert (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:852 @@ -6213,12 +6220,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:885 msgid "Default: hard" -msgstr "" +msgstr "ნაგულისხმევი: hard" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:891 msgid "ldap_tls_cacert (string)" -msgstr "" +msgstr "ldap_tls_cacert (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:894 @@ -6237,7 +6244,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:906 msgid "ldap_tls_cacertdir (string)" -msgstr "" +msgstr "ldap_tls_cacertdir (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:909 @@ -6252,7 +6259,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:925 msgid "ldap_tls_cert (string)" -msgstr "" +msgstr "ldap_tls_cert (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:928 @@ -6262,7 +6269,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:938 msgid "ldap_tls_key (string)" -msgstr "" +msgstr "ldap_tls_key (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:941 @@ -6272,7 +6279,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:950 msgid "ldap_tls_cipher_suite (string)" -msgstr "" +msgstr "ldap_tls_cipher_suite (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:953 @@ -6285,7 +6292,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:966 msgid "ldap_id_use_start_tls (boolean)" -msgstr "" +msgstr "ldap_id_use_start_tls (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:969 @@ -6298,7 +6305,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:980 msgid "ldap_id_mapping (boolean)" -msgstr "" +msgstr "ldap_id_mapping (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:983 @@ -6316,7 +6323,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:999 msgid "ldap_min_id, ldap_max_id (integer)" -msgstr "" +msgstr "ldap_min_id, ldap_max_id (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1002 @@ -6337,7 +6344,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1020 msgid "ldap_sasl_mech (string)" -msgstr "" +msgstr "ldap_sasl_mech (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1023 @@ -6360,7 +6367,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1043 msgid "ldap_sasl_authid (string)" -msgstr "" +msgstr "ldap_sasl_authid (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> #: sssd-ldap.5.xml:1055 @@ -6395,7 +6402,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1072 msgid "ldap_sasl_realm (string)" -msgstr "" +msgstr "ldap_sasl_realm (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1075 @@ -6413,7 +6420,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1087 msgid "ldap_sasl_canonicalize (boolean)" -msgstr "" +msgstr "ldap_sasl_canonicalize (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1090 @@ -6425,12 +6432,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1095 msgid "Default: false;" -msgstr "" +msgstr "ნაგულისხმევი: ცრუ;" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1101 msgid "ldap_krb5_keytab (string)" -msgstr "" +msgstr "ldap_krb5_keytab (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1104 @@ -6445,7 +6452,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1119 msgid "ldap_krb5_init_creds (boolean)" -msgstr "" +msgstr "ldap_krb5_init_creds (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1122 @@ -6458,7 +6465,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1134 msgid "ldap_krb5_ticket_lifetime (integer)" -msgstr "" +msgstr "ldap_krb5_ticket_lifetime (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1137 @@ -6470,12 +6477,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1146 sssd-ad.5.xml:1285 msgid "Default: 86400 (24 hours)" -msgstr "" +msgstr "ნაგულისხმევი: 86400 (24 სთ)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1152 sssd-krb5.5.xml:74 msgid "krb5_server, krb5_backup_server (string)" -msgstr "" +msgstr "krb5_server, krb5_backup_server (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1155 @@ -6509,7 +6516,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1181 sssd-ipa.5.xml:596 sssd-krb5.5.xml:103 msgid "krb5_realm (string)" -msgstr "" +msgstr "krb5_realm (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1184 @@ -6524,7 +6531,7 @@ msgstr "" #. type: Content of: <variablelist><varlistentry><term> #: sssd-ldap.5.xml:1194 include/krb5_options.xml:154 msgid "krb5_canonicalize (boolean)" -msgstr "" +msgstr "krb5_canonicalize (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1197 @@ -6536,7 +6543,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1209 sssd-krb5.5.xml:336 msgid "krb5_use_kdcinfo (boolean)" -msgstr "" +msgstr "krb5_use_kdcinfo (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1212 sssd-krb5.5.xml:339 @@ -6560,7 +6567,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1237 msgid "ldap_pwd_policy (string)" -msgstr "" +msgstr "ldap_pwd_policy (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1240 @@ -6604,7 +6611,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1275 msgid "ldap_referrals (boolean)" -msgstr "" +msgstr "ldap_referrals (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1278 @@ -6634,7 +6641,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1306 msgid "ldap_dns_service_name (string)" -msgstr "" +msgstr "ldap_dns_service_name (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1309 @@ -6644,12 +6651,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1313 msgid "Default: ldap" -msgstr "" +msgstr "ნაგულისხმევი: ldap" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1319 msgid "ldap_chpass_dns_service_name (string)" -msgstr "" +msgstr "ldap_chpass_dns_service_name (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1322 @@ -6666,7 +6673,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1333 msgid "ldap_chpass_update_last_change (bool)" -msgstr "" +msgstr "ldap_chpass_update_last_change (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1336 @@ -6687,7 +6694,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1356 msgid "ldap_access_filter (string)" -msgstr "" +msgstr "ldap_access_filter (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1359 @@ -6709,7 +6716,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1379 msgid "Example:" -msgstr "" +msgstr "მაგალითი:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><programlisting> #: sssd-ldap.5.xml:1382 @@ -6739,12 +6746,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1399 sssd-ldap.5.xml:1455 msgid "Default: Empty" -msgstr "" +msgstr "ნაგულისხმევი: ცარიელი" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1405 msgid "ldap_account_expire_policy (string)" -msgstr "" +msgstr "ldap_account_expire_policy (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1408 @@ -6810,7 +6817,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1461 msgid "ldap_access_order (string)" -msgstr "" +msgstr "ldap_access_order (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1464 sssd-ipa.5.xml:421 @@ -6930,7 +6937,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1568 msgid "Default: filter" -msgstr "" +msgstr "ნაგულისხმევი: filter" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1571 @@ -6942,7 +6949,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1578 msgid "ldap_pwdlockout_dn (string)" -msgstr "" +msgstr "ldap_pwdlockout_dn (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1581 @@ -6961,12 +6968,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1592 msgid "Default: cn=ppolicy,ou=policies,$ldap_search_base" -msgstr "" +msgstr "ნაგულისხმევი: cn=ppolicy,ou=policies,$ldap_search_base" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1598 msgid "ldap_deref (string)" -msgstr "" +msgstr "ldap_deref (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1601 @@ -7011,7 +7018,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1633 msgid "ldap_rfc2307_fallback_to_local_users (boolean)" -msgstr "" +msgstr "ldap_rfc2307_fallback_to_local_users (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1636 @@ -7042,7 +7049,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1663 sssd-ifp.5.xml:152 msgid "wildcard_limit (integer)" -msgstr "" +msgstr "wildcard_limit (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1666 @@ -7064,7 +7071,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1680 msgid "ldap_library_debug_level (integer)" -msgstr "" +msgstr "ldap_library_debug_level (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1683 @@ -7088,7 +7095,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1699 msgid "ldap_use_ppolicy (boolean)" -msgstr "" +msgstr "ldap_use_ppolicy (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1702 @@ -7101,7 +7108,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1714 msgid "ldap_ppolicy_pwd_change_threshold (integer)" -msgstr "" +msgstr "ldap_ppolicy_pwd_change_threshold (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1717 @@ -7129,7 +7136,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><title> #: sssd-ldap.5.xml:1737 msgid "SUDO OPTIONS" -msgstr "" +msgstr "SUDO-ის პარამეტრები" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ldap.5.xml:1739 @@ -7142,7 +7149,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1750 msgid "ldap_sudo_full_refresh_interval (integer)" -msgstr "" +msgstr "ldap_sudo_full_refresh_interval (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1753 @@ -7168,12 +7175,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1768 msgid "Default: 21600 (6 hours)" -msgstr "" +msgstr "ნაგულისხმევი: 21600 (6 სთ)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1774 msgid "ldap_sudo_smart_refresh_interval (integer)" -msgstr "" +msgstr "ldap_sudo_smart_refresh_interval (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1777 @@ -7210,7 +7217,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1809 msgid "ldap_sudo_random_offset (integer)" -msgstr "" +msgstr "ldap_sudo_random_offset (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1812 @@ -7236,7 +7243,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1834 msgid "ldap_sudo_use_host_filter (boolean)" -msgstr "" +msgstr "ldap_sudo_use_host_filter (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1837 @@ -7248,7 +7255,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1848 msgid "ldap_sudo_hostnames (string)" -msgstr "" +msgstr "ldap_sudo_hostnames (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1851 @@ -7275,12 +7282,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1866 sssd-ldap.5.xml:1889 msgid "Default: not specified" -msgstr "" +msgstr "ნაგულისხმევი: მითითებული არაა" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1872 msgid "ldap_sudo_ip (string)" -msgstr "" +msgstr "ldap_sudo_ip (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1875 @@ -7299,7 +7306,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1895 msgid "ldap_sudo_include_netgroups (boolean)" -msgstr "" +msgstr "ldap_sudo_include_netgroups (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1898 @@ -7311,7 +7318,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1913 msgid "ldap_sudo_include_regexp (boolean)" -msgstr "" +msgstr "ldap_sudo_include_regexp (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1916 @@ -7339,7 +7346,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><title> #: sssd-ldap.5.xml:1948 msgid "AUTOFS OPTIONS" -msgstr "" +msgstr "AUTOFS-ის კონფიგურაცია" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ldap.5.xml:1950 @@ -7351,7 +7358,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1956 msgid "ldap_autofs_map_master_name (string)" -msgstr "" +msgstr "ldap_autofs_map_master_name (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1959 @@ -7361,32 +7368,32 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1962 msgid "Default: auto.master" -msgstr "" +msgstr "ნაგულისხმევი: auto.master" #. type: Content of: <reference><refentry><refsect1><title> #: sssd-ldap.5.xml:1973 msgid "ADVANCED OPTIONS" -msgstr "" +msgstr "დამატებითი პარამეტრები" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1980 msgid "ldap_netgroup_search_base (string)" -msgstr "" +msgstr "ldap_netgroup_search_base (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1985 msgid "ldap_user_search_base (string)" -msgstr "" +msgstr "ldap_user_search_base (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1990 msgid "ldap_group_search_base (string)" -msgstr "" +msgstr "ldap_group_search_base (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><note> #: sssd-ldap.5.xml:1995 msgid "<note>" -msgstr "" +msgstr "<note>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><note><para> #: sssd-ldap.5.xml:1997 @@ -7400,17 +7407,17 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist> #: sssd-ldap.5.xml:2004 msgid "</note>" -msgstr "" +msgstr "</note>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:2006 msgid "ldap_sudo_search_base (string)" -msgstr "" +msgstr "ldap_sudo_search_base (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:2011 msgid "ldap_autofs_search_base (string)" -msgstr "" +msgstr "ldap_autofs_search_base (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ldap.5.xml:1975 @@ -7426,7 +7433,7 @@ msgstr "" #: sssd-ad.5.xml:1488 sssd-idp.5.xml:248 sssd-krb5.5.xml:483 #: sss_rpcidmapd.5.xml:98 sssd-session-recording.5.xml:176 msgid "EXAMPLE" -msgstr "" +msgstr "მაგალითი" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ldap.5.xml:2028 @@ -7489,7 +7496,7 @@ msgstr "" #: sssd-ldap.5.xml:2067 sssd_krb5_locator_plugin.8.xml:83 sssd-simple.5.xml:189 #: sssd-ad.5.xml:1511 sssd.8.xml:270 sss_seed.8.xml:163 msgid "NOTES" -msgstr "" +msgstr "შენიშვნები" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ldap.5.xml:2069 @@ -7503,7 +7510,7 @@ msgstr "" #. type: Content of: <reference><refentry><refnamediv><refname> #: pam_sss.8.xml:11 pam_sss.8.xml:16 msgid "pam_sss" -msgstr "" +msgstr "pam_sss" #. type: Content of: <reference><refentry><refmeta><manvolnum> #: pam_sss.8.xml:12 pam_sss_gss.8.xml:12 sssd_krb5_locator_plugin.8.xml:11 @@ -7512,7 +7519,7 @@ msgstr "" #: idmap_sss.8.xml:11 sssctl.8.xml:11 sssd-kcm.8.xml:11 #: sssd_krb5_localauth_plugin.8.xml:11 msgid "8" -msgstr "" +msgstr "8" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: pam_sss.8.xml:17 @@ -7551,12 +7558,12 @@ msgstr "" #: sss_cache.8.xml:39 sss_seed.8.xml:42 sss_ssh_authorizedkeys.1.xml:123 #: sss_ssh_knownhosts.1.xml:59 msgid "OPTIONS" -msgstr "" +msgstr "პარამეტრები" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:77 msgid "<option>quiet</option>" -msgstr "" +msgstr "<option>quiet</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:80 @@ -7566,7 +7573,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:85 msgid "<option>forward_pass</option>" -msgstr "" +msgstr "<option>forward_pass</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:88 @@ -7578,7 +7585,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:95 msgid "<option>use_first_pass</option>" -msgstr "" +msgstr "<option>use_first_pass</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:98 @@ -7592,7 +7599,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:106 msgid "<option>use_authtok</option>" -msgstr "" +msgstr "<option>use_authtok</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:109 @@ -7604,7 +7611,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:116 msgid "<option>retry=N</option>" -msgstr "" +msgstr "<option>retry=N</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:119 @@ -7624,7 +7631,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:130 msgid "<option>ignore_unknown_user</option>" -msgstr "" +msgstr "<option>ignore_unknown_user</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:133 @@ -7636,7 +7643,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:140 msgid "<option>ignore_authinfo_unavail</option>" -msgstr "" +msgstr "<option>ignore_authinfo_unavail</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:144 @@ -7648,7 +7655,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:151 msgid "<option>domains</option>" -msgstr "" +msgstr "<option>domains</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:155 @@ -7673,7 +7680,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:176 msgid "<option>allow_missing_name</option>" -msgstr "" +msgstr "<option>allow_missing_name</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:180 @@ -7689,6 +7696,8 @@ msgid "" "auth sufficient pam_sss.so allow_missing_name\n" " " msgstr "" +"auth sufficient pam_sss.so allow_missing_name\n" +" " #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:185 @@ -7704,7 +7713,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:200 msgid "<option>prompt_always</option>" -msgstr "" +msgstr "<option>prompt_always</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:204 @@ -7719,7 +7728,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:215 msgid "<option>try_cert_auth</option>" -msgstr "" +msgstr "<option>try_cert_auth</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:219 @@ -7740,7 +7749,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:235 msgid "<option>require_cert_auth</option>" -msgstr "" +msgstr "<option>require_cert_auth</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:239 @@ -7764,7 +7773,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:257 msgid "<option>allow_chauthtok_by_root</option>" -msgstr "" +msgstr "<option>allow_chauthtok_by_root</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:261 @@ -7804,12 +7813,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><title> #: pam_sss.8.xml:286 pam_sss_gss.8.xml:108 msgid "RETURN VALUES" -msgstr "" +msgstr "RETURN VALUES" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:289 pam_sss_gss.8.xml:111 msgid "PAM_SUCCESS" -msgstr "" +msgstr "PAM_SUCCESS" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:292 pam_sss_gss.8.xml:114 @@ -7819,7 +7828,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:297 pam_sss_gss.8.xml:119 msgid "PAM_USER_UNKNOWN" -msgstr "" +msgstr "PAM_USER_UNKNOWN" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:300 @@ -7831,7 +7840,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:306 pam_sss_gss.8.xml:128 msgid "PAM_AUTH_ERR" -msgstr "" +msgstr "PAM_AUTH_ERR" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:309 @@ -7843,7 +7852,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:315 msgid "PAM_PERM_DENIED" -msgstr "" +msgstr "PAM_PERM_DENIED" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:318 @@ -7855,7 +7864,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:324 msgid "PAM_IGNORE" -msgstr "" +msgstr "PAM_IGNORE" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:327 @@ -7867,7 +7876,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:333 msgid "PAM_AUTHTOK_ERR" -msgstr "" +msgstr "PAM_AUTHTOK_ERR" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:336 @@ -7881,7 +7890,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:344 pam_sss_gss.8.xml:136 msgid "PAM_AUTHINFO_UNAVAIL" -msgstr "" +msgstr "PAM_AUTHINFO_UNAVAIL" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:347 pam_sss_gss.8.xml:139 @@ -7893,7 +7902,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:353 msgid "PAM_BUF_ERR" -msgstr "" +msgstr "PAM_BUF_ERR" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:356 @@ -7906,7 +7915,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:363 pam_sss_gss.8.xml:145 msgid "PAM_SYSTEM_ERR" -msgstr "" +msgstr "PAM_SYSTEM_ERR" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:366 pam_sss_gss.8.xml:148 @@ -7918,7 +7927,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:372 msgid "PAM_CRED_ERR" -msgstr "" +msgstr "PAM_CRED_ERR" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:375 @@ -7928,7 +7937,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:380 msgid "PAM_CRED_INSUFFICIENT" -msgstr "" +msgstr "PAM_CRED_INSUFFICIENT" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:383 @@ -7941,17 +7950,17 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:391 msgid "PAM_SERVICE_ERR" -msgstr "" +msgstr "PAM_SERVICE_ERR" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:394 msgid "Error in service module." -msgstr "" +msgstr "შეცდომა სერვისის მოდულში." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:399 msgid "PAM_NEW_AUTHTOK_REQD" -msgstr "" +msgstr "PAM_NEW_AUTHTOK_REQD" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:402 @@ -7961,17 +7970,17 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:407 msgid "PAM_ACCT_EXPIRED" -msgstr "" +msgstr "PAM_ACCT_EXPIRED" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:410 msgid "The user account has expired." -msgstr "" +msgstr "მომხმარებლის ანგარიშის ვადა ამოიწურა." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:415 msgid "PAM_SESSION_ERR" -msgstr "" +msgstr "PAM_SESSION_ERR" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:418 @@ -7981,7 +7990,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:423 msgid "PAM_CRED_UNAVAIL" -msgstr "" +msgstr "PAM_CRED_UNAVAIL" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:426 @@ -7991,7 +8000,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:431 msgid "PAM_NO_MODULE_DATA" -msgstr "" +msgstr "PAM_NO_MODULE_DATA" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:434 @@ -8004,7 +8013,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:441 msgid "PAM_CONV_ERR" -msgstr "" +msgstr "PAM_CONV_ERR" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:444 @@ -8014,7 +8023,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:449 msgid "PAM_AUTHTOK_LOCK_BUSY" -msgstr "" +msgstr "PAM_AUTHTOK_LOCK_BUSY" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:452 @@ -8024,7 +8033,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:457 msgid "PAM_ABORT" -msgstr "" +msgstr "PAM_ABORT" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:460 @@ -8034,7 +8043,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:465 msgid "PAM_MODULE_UNKNOWN" -msgstr "" +msgstr "PAM_MODULE_UNKNOWN" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:468 @@ -8044,7 +8053,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:473 msgid "PAM_BAD_ITEM" -msgstr "" +msgstr "PAM_BAD_ITEM" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:476 @@ -8054,7 +8063,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><title> #: pam_sss.8.xml:484 msgid "FILES" -msgstr "" +msgstr "ფაილები" #. type: Content of: <reference><refentry><refsect1><para> #: pam_sss.8.xml:485 @@ -8089,7 +8098,7 @@ msgstr "" #. type: Content of: <reference><refentry><refnamediv><refname> #: pam_sss_gss.8.xml:11 pam_sss_gss.8.xml:16 msgid "pam_sss_gss" -msgstr "" +msgstr "pam_sss_gss" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: pam_sss_gss.8.xml:17 @@ -8173,12 +8182,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss_gss.8.xml:93 msgid "<option>debug</option>" -msgstr "" +msgstr "<option>debug</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss_gss.8.xml:96 msgid "Print debugging information." -msgstr "" +msgstr "გამართვის ინფორმაციის გამოტანა." #. type: Content of: <reference><refentry><refsect1><para> #: pam_sss_gss.8.xml:104 @@ -8195,7 +8204,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss_gss.8.xml:131 msgid "Authentication failure." -msgstr "" +msgstr "ავთენტიკაციის ჩავარდნა." #. type: Content of: <reference><refentry><refsect1><para> #: pam_sss_gss.8.xml:159 @@ -8230,11 +8239,15 @@ msgid "" "...\n" " " msgstr "" +"...\n" +"auth sufficient pam_sss_gss.so\n" +"...\n" +" " #. type: Content of: <reference><refentry><refsect1><title> #: pam_sss_gss.8.xml:180 msgid "TROUBLESHOOTING" -msgstr "" +msgstr "პრობლემების გადაჭრა" #. type: Content of: <reference><refentry><refsect1><para> #: pam_sss_gss.8.xml:182 @@ -8290,11 +8303,14 @@ msgid "" ".myhostname = MYREALM\n" " " msgstr "" +"[domain_realm]\n" +".myhostname = MYREALM\n" +" " #. type: Content of: <reference><refentry><refnamediv><refname> #: sssd_krb5_locator_plugin.8.xml:10 sssd_krb5_locator_plugin.8.xml:15 msgid "sssd_krb5_locator_plugin" -msgstr "" +msgstr "sssd_krb5_locator_plugin" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sssd_krb5_locator_plugin.8.xml:16 @@ -8343,32 +8359,32 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><itemizedlist><listitem><para> #: sssd_krb5_locator_plugin.8.xml:58 msgid "kdc.example.com" -msgstr "" +msgstr "kdc.example.com" #. type: Content of: <reference><refentry><refsect1><para><itemizedlist><listitem><para> #: sssd_krb5_locator_plugin.8.xml:59 msgid "kdc.example.com:321" -msgstr "" +msgstr "kdc.example.com:321" #. type: Content of: <reference><refentry><refsect1><para><itemizedlist><listitem><para> #: sssd_krb5_locator_plugin.8.xml:60 msgid "1.2.3.4" -msgstr "" +msgstr "1.2.3.4" #. type: Content of: <reference><refentry><refsect1><para><itemizedlist><listitem><para> #: sssd_krb5_locator_plugin.8.xml:61 msgid "5.6.7.8:99" -msgstr "" +msgstr "5.6.7.8:99" #. type: Content of: <reference><refentry><refsect1><para><itemizedlist><listitem><para> #: sssd_krb5_locator_plugin.8.xml:62 msgid "2001:db8:85a3::8a2e:370:7334" -msgstr "" +msgstr "2001:db8:85a3::8a2e:370:7334" #. type: Content of: <reference><refentry><refsect1><para><itemizedlist><listitem><para> #: sssd_krb5_locator_plugin.8.xml:63 msgid "[2001:db8:85a3::8a2e:370:7334]:321" -msgstr "" +msgstr "[2001:db8:85a3::8a2e:370:7334]:321" #. type: Content of: <reference><refentry><refsect1><para> #: sssd_krb5_locator_plugin.8.xml:65 @@ -8426,7 +8442,7 @@ msgstr "" #. type: Content of: <reference><refentry><refnamediv><refname> #: sssd-simple.5.xml:10 sssd-simple.5.xml:16 msgid "sssd-simple" -msgstr "" +msgstr "sssd-simple" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sssd-simple.5.xml:17 @@ -8496,7 +8512,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-simple.5.xml:91 msgid "simple_allow_users (string)" -msgstr "" +msgstr "simple_allow_users (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-simple.5.xml:94 @@ -8509,7 +8525,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-simple.5.xml:103 msgid "simple_deny_users (string)" -msgstr "" +msgstr "simple_deny_users (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-simple.5.xml:106 @@ -8530,7 +8546,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-simple.5.xml:120 msgid "simple_allow_groups (string)" -msgstr "" +msgstr "simple_allow_groups (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-simple.5.xml:123 @@ -8557,7 +8573,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-simple.5.xml:141 msgid "simple_deny_groups (string)" -msgstr "" +msgstr "simple_deny_groups (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-simple.5.xml:144 @@ -8627,7 +8643,7 @@ msgstr "" #. type: Content of: <reference><refentry><refnamediv><refname> #: sss-certmap.5.xml:10 sss-certmap.5.xml:16 msgid "sss-certmap" -msgstr "" +msgstr "sss-certmap" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sss-certmap.5.xml:17 @@ -8682,7 +8698,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> #: sss-certmap.5.xml:57 msgid "PRIORITY" -msgstr "" +msgstr "პრიორიტეტი" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sss-certmap.5.xml:59 @@ -8740,7 +8756,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:99 msgid "<SUBJECT>regular-expression" -msgstr "" +msgstr "<SUBJECT>რეგულარული-გამოსახულება" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:102 @@ -8784,7 +8800,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:135 msgid "<ISSUER>regular-expression" -msgstr "" +msgstr "<ISSUER>რეგულარული-გამოსახულება" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:138 @@ -8801,7 +8817,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:148 msgid "<KU>key-usage" -msgstr "" +msgstr "<KU>გასაღების-გამოყენება" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:151 @@ -8813,47 +8829,47 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sss-certmap.5.xml:155 msgid "digitalSignature" -msgstr "" +msgstr "digitalSignature" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sss-certmap.5.xml:156 msgid "nonRepudiation" -msgstr "" +msgstr "nonRepudiation" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sss-certmap.5.xml:157 msgid "keyEncipherment" -msgstr "" +msgstr "keyEncipherment" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sss-certmap.5.xml:158 msgid "dataEncipherment" -msgstr "" +msgstr "dataEncipherment" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sss-certmap.5.xml:159 msgid "keyAgreement" -msgstr "" +msgstr "keyAgreement" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sss-certmap.5.xml:160 msgid "keyCertSign" -msgstr "" +msgstr "keyCertSign" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sss-certmap.5.xml:161 msgid "cRLSign" -msgstr "" +msgstr "cRLSign" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sss-certmap.5.xml:162 msgid "encipherOnly" -msgstr "" +msgstr "encipherOnly" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sss-certmap.5.xml:163 msgid "decipherOnly" -msgstr "" +msgstr "decipherOnly" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:167 @@ -8870,7 +8886,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:176 msgid "<EKU>extended-key-usage" -msgstr "" +msgstr "<EKU>გასაღების-გაფართოებული-გამოყენება" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:179 @@ -8882,47 +8898,47 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sss-certmap.5.xml:183 msgid "serverAuth" -msgstr "" +msgstr "serverAuth" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sss-certmap.5.xml:184 msgid "clientAuth" -msgstr "" +msgstr "clientAuth" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sss-certmap.5.xml:185 msgid "codeSigning" -msgstr "" +msgstr "codeSigning" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sss-certmap.5.xml:186 msgid "emailProtection" -msgstr "" +msgstr "emailProtection" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sss-certmap.5.xml:187 msgid "timeStamping" -msgstr "" +msgstr "timeStamping" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sss-certmap.5.xml:188 msgid "OCSPSigning" -msgstr "" +msgstr "OCSPSigning" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sss-certmap.5.xml:189 msgid "KPClientAuth" -msgstr "" +msgstr "KPClientAuth" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sss-certmap.5.xml:190 msgid "pkinit" -msgstr "" +msgstr "pkinit" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sss-certmap.5.xml:191 msgid "msScLogin" -msgstr "" +msgstr "msScLogin" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:195 @@ -8939,7 +8955,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:204 msgid "<SAN>regular-expression" -msgstr "" +msgstr "<SAN>რეგულარულ-გამოსახულება" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:207 @@ -8957,7 +8973,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:217 msgid "<SAN:Principal>regular-expression" -msgstr "" +msgstr "<SAN:Principal>რეგულარული-გამოსახულება" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:220 @@ -8967,12 +8983,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:224 msgid "Example: <SAN:Principal>.*@MY\\.REALM" -msgstr "" +msgstr "მაგალითი: <SAN:Principal>.*@MY\\.REALM" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:229 msgid "<SAN:ntPrincipalName>regular-expression" -msgstr "" +msgstr "<SAN:ntPrincipalName>რეგულარული-გამოსახულება" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:232 @@ -8982,12 +8998,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:236 msgid "Example: <SAN:ntPrincipalName>.*@MY.AD.REALM" -msgstr "" +msgstr "მაგალითი: <SAN:ntPrincipalName>.*@MY.AD.REALM" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:241 msgid "<SAN:pkinit>regular-expression" -msgstr "" +msgstr "<SAN:pkinit>რეგულარული-გამოსახულება" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:244 @@ -8997,12 +9013,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:247 msgid "Example: <SAN:ntPrincipalName>.*@MY\\.PKINIT\\.REALM" -msgstr "" +msgstr "მაგალითი: <SAN:ntPrincipalName>.*@MY\\.PKINIT\\.REALM" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:252 msgid "<SAN:dotted-decimal-oid>regular-expression" -msgstr "" +msgstr "<SAN:dotted-decimal-oid>რეგულარული-გამოსახულება" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:255 @@ -9015,12 +9031,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:261 msgid "Example: <SAN:1.2.3.4>test" -msgstr "" +msgstr "მაგალითი: <SAN:1.2.3.4>test" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:266 msgid "<SAN:otherName>base64-string" -msgstr "" +msgstr "<SAN:otherName>base64-სტრიქონი" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:269 @@ -9034,12 +9050,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:276 msgid "Example: <SAN:otherName>MTIz" -msgstr "" +msgstr "მაგალითი: <SAN:otherName>MTIz" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:281 msgid "<SAN:rfc822Name>regular-expression" -msgstr "" +msgstr "<SAN:rfc822Name>რეგულარული-გამოსახულება" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:284 @@ -9049,12 +9065,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:287 msgid "Example: <SAN:rfc822Name>.*@email\\.domain" -msgstr "" +msgstr "მაგალითი: <SAN:rfc822Name>.*@email\\.domain" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:292 msgid "<SAN:dNSName>regular-expression" -msgstr "" +msgstr "<SAN:dNSName>რეგულარული-გამოსახულება" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:295 @@ -9064,12 +9080,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:298 msgid "Example: <SAN:dNSName>.*\\.my\\.dns\\.domain" -msgstr "" +msgstr "მაგალითი: <SAN:dNSName>.*\\.my\\.dns\\.domain" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:303 msgid "<SAN:x400Address>base64-string" -msgstr "" +msgstr "<SAN:x400Address>base64-სტრიქონი" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:306 @@ -9079,12 +9095,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:309 msgid "Example: <SAN:x400Address>MTIz" -msgstr "" +msgstr "მაგალითი: <SAN:x400Address>MTIz" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:314 msgid "<SAN:directoryName>regular-expression" -msgstr "" +msgstr "<SAN:directoryName>რეგულარული-გამოსახულება" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:317 @@ -9096,12 +9112,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:322 msgid "Example: <SAN:directoryName>.*,DC=com" -msgstr "" +msgstr "მაგალითი: <SAN:directoryName>.*,DC=com" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:327 msgid "<SAN:ediPartyName>base64-string" -msgstr "" +msgstr "<SAN:ediPartyName>base64-სტრიქონი" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:330 @@ -9111,12 +9127,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:333 msgid "Example: <SAN:ediPartyName>MTIz" -msgstr "" +msgstr "მაგალითი: <SAN:ediPartyName>MTIz" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:338 msgid "<SAN:uniformResourceIdentifier>regular-expression" -msgstr "" +msgstr "<SAN:uniformResourceIdentifier>რეგულარული-გამოსახულება" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:341 @@ -9126,12 +9142,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:344 msgid "Example: <SAN:uniformResourceIdentifier>URN:.*" -msgstr "" +msgstr "მაგალითი: <SAN:uniformResourceIdentifier>URN:.*" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:349 msgid "<SAN:iPAddress>regular-expression" -msgstr "" +msgstr "<SAN:iPAddress>რეგულარული-გამოსახულება" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:352 @@ -9141,12 +9157,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:355 msgid "Example: <SAN:iPAddress>192\\.168\\..*" -msgstr "" +msgstr "მაგალითი: <SAN:iPAddress>192\\.168\\..*" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:360 msgid "<SAN:registeredID>regular-expression" -msgstr "" +msgstr "<SAN:registeredID>რეგულარული-გამოსახულება" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:363 @@ -9156,7 +9172,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:367 msgid "Example: <SAN:registeredID>1\\.2\\.3\\..*" -msgstr "" +msgstr "მაგალითი: <SAN:registeredID>1\\.2\\.3\\..*" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sss-certmap.5.xml:96 @@ -9223,7 +9239,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:424 msgid "{issuer_dn[!((ad|ad_x500)|ad_ldap|nss_x500|(nss|nss_ldap))]}" -msgstr "" +msgstr "{issuer_dn[!((ad|ad_x500)|ad_ldap|nss_x500|(nss|nss_ldap))]}" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:427 @@ -9260,11 +9276,13 @@ msgid "" "Example: " "(ipacertmapdata=X509:<I>{issuer_dn!ad}<S>{subject_dn!ad})" msgstr "" +"მაგალითი: (ipacertmapdata=X509:<I>{issuer_dn!ad}<S>" +"{subject_dn!ad})" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:450 msgid "{subject_dn[!((ad|ad_x500)|ad_ldap|nss_x500|(nss|nss_ldap))]}" -msgstr "" +msgstr "{subject_dn[!((ad|ad_x500)|ad_ldap|nss_x500|(nss|nss_ldap))]}" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:453 @@ -9280,11 +9298,13 @@ msgid "" "Example: " "(ipacertmapdata=X509:<I>{issuer_dn!nss_x500}<S>{subject_dn!nss_x500})" msgstr "" +"მაგალითი: (ipacertmapdata=X509:<I>{issuer_dn!nss_x500}<S>" +"{subject_dn!nss_x500})" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:476 msgid "{cert[!(bin|base64)]}" -msgstr "" +msgstr "{cert[!(bin|base64)]}" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:479 @@ -9299,12 +9319,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:487 msgid "Example: (userCertificate;binary={cert!bin})" -msgstr "" +msgstr "მაგალითი: (userCertificate;binary={cert!bin})" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:492 msgid "{subject_principal[.short_name]}" -msgstr "" +msgstr "{subject_principal[.short_name]}" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:495 @@ -9320,11 +9340,13 @@ msgid "" "Example: " "(|(userPrincipal={subject_principal})(samAccountName={subject_principal.short_name}))" msgstr "" +"მაგალითი: (|(userPrincipal={subject_principal})(samAccountName=" +"{subject_principal.short_name}))" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:506 msgid "{subject_pkinit_principal[.short_name]}" -msgstr "" +msgstr "{subject_pkinit_principal[.short_name]}" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:509 @@ -9340,11 +9362,13 @@ msgid "" "Example: " "(|(userPrincipal={subject_pkinit_principal})(uid={subject_pkinit_principal.short_name}))" msgstr "" +"მაგალითი: (|(userPrincipal={subject_pkinit_principal})(uid=" +"{subject_pkinit_principal.short_name}))" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:520 msgid "{subject_nt_principal[.short_name]}" -msgstr "" +msgstr "{subject_nt_principal[.short_name]}" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:523 @@ -9360,11 +9384,13 @@ msgid "" "Example: " "(|(userPrincipalName={subject_nt_principal})(samAccountName={subject_nt_principal.short_name}))" msgstr "" +"მაგალითი: (|(userPrincipalName={subject_nt_principal})(samAccountName=" +"{subject_nt_principal.short_name}))" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:534 msgid "{subject_rfc822_name[.short_name]}" -msgstr "" +msgstr "{subject_rfc822_name[.short_name]}" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:537 @@ -9380,11 +9406,13 @@ msgid "" "Example: " "(|(mail={subject_rfc822_name})(uid={subject_rfc822_name.short_name}))" msgstr "" +"მაგალითი: (|(mail={subject_rfc822_name})(uid=" +"{subject_rfc822_name.short_name}))" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:548 msgid "{subject_dns_name[.short_name]}" -msgstr "" +msgstr "{subject_dns_name[.short_name]}" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:551 @@ -9398,11 +9426,12 @@ msgstr "" #: sss-certmap.5.xml:557 msgid "Example: (|(fqdn={subject_dns_name})(host={subject_dns_name.short_name}))" msgstr "" +"მაგალითი: (|(fqdn={subject_dns_name})(host={subject_dns_name.short_name}))" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:562 msgid "{subject_uri}" -msgstr "" +msgstr "{subject_uri}" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:565 @@ -9414,12 +9443,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:569 msgid "Example: (uri={subject_uri})" -msgstr "" +msgstr "მაგალითი: (uri={subject_uri})" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:574 msgid "{subject_ip_address}" -msgstr "" +msgstr "{subject_ip_address}" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:577 @@ -9431,12 +9460,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:581 msgid "Example: (ip={subject_ip_address})" -msgstr "" +msgstr "მაგალითი: (ip={subject_ip_address})" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:586 msgid "{subject_x400_address}" -msgstr "" +msgstr "{subject_x400_address}" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:589 @@ -9448,12 +9477,13 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:594 msgid "Example: (attr:binary={subject_x400_address})" -msgstr "" +msgstr "მაგალითი: (attr:binary={subject_x400_address})" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:599 msgid "{subject_directory_name[!((ad|ad_x500)|ad_ldap|nss_x500|(nss|nss_ldap))]}" msgstr "" +"{subject_directory_name[!((ad|ad_x500)|ad_ldap|nss_x500|(nss|nss_ldap))]}" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:602 @@ -9465,12 +9495,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:606 msgid "Example: (orig_dn={subject_directory_name})" -msgstr "" +msgstr "მაგალითი: (orig_dn={subject_directory_name})" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:611 msgid "{subject_ediparty_name}" -msgstr "" +msgstr "{subject_ediparty_name}" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:614 @@ -9482,12 +9512,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:619 msgid "Example: (attr:binary={subject_ediparty_name})" -msgstr "" +msgstr "მაგალითი: (attr:binary={subject_ediparty_name})" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:624 msgid "{subject_registered_id}" -msgstr "" +msgstr "{subject_registered_id}" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:627 @@ -9499,7 +9529,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:632 msgid "Example: (oid={subject_registered_id})" -msgstr "" +msgstr "მაგალითი: (oid={subject_registered_id})" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sss-certmap.5.xml:417 @@ -9514,7 +9544,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><title> #: sss-certmap.5.xml:639 msgid "LDAPU1 extension" -msgstr "" +msgstr "LDAPU1 გაფართოება" #. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para> #: sss-certmap.5.xml:641 @@ -9524,7 +9554,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:647 msgid "{serial_number[!(dec|hex[_ucr])]}" -msgstr "" +msgstr "{serial_number[!(dec|hex[_ucr])]}" #. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:650 @@ -9552,7 +9582,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:671 msgid "{subject_key_id[!hex[_ucr]]}" -msgstr "" +msgstr "{subject_key_id[!hex[_ucr]]}" #. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:674 @@ -9579,7 +9609,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:694 msgid "{cert[!DIGEST[_ucr]]}" -msgstr "" +msgstr "{cert[!DIGEST[_ucr]]}" #. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:697 @@ -9602,12 +9632,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:712 msgid "Example: LDAPU1:(dgst={cert!sha256})" -msgstr "" +msgstr "მაგალითი: LDAPU1:(dgst={cert!sha256})" #. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:718 msgid "{subject_dn_component[(.attr_name|[number]]}" -msgstr "" +msgstr "{subject_dn_component[(.attr_name|[number]]}" #. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:721 @@ -9636,7 +9666,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:743 msgid "{issuer_dn_component[(.attr_name|[number]]}" -msgstr "" +msgstr "{issuer_dn_component[(.attr_name|[number]]}" #. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:746 @@ -9662,7 +9692,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:760 msgid "{sid[.rid]}" -msgstr "" +msgstr "{sid[.rid]}" #. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:763 @@ -9675,7 +9705,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:770 msgid "Example: LDAPU1:(objectsid={sid})" -msgstr "" +msgstr "მაგალითი: LDAPU1:(objectsid={sid})" #. type: Content of: <reference><refentry><refsect1><refsect2><title> #: sss-certmap.5.xml:779 @@ -9693,7 +9723,7 @@ msgstr "" #. type: Content of: <reference><refentry><refnamediv><refname> #: sssd-ipa.5.xml:10 sssd-ipa.5.xml:16 msgid "sssd-ipa" -msgstr "" +msgstr "sssd-ipa" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sssd-ipa.5.xml:17 @@ -9768,7 +9798,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:90 msgid "ipa_domain (string)" -msgstr "" +msgstr "ipa_domain (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:93 @@ -9780,7 +9810,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:101 msgid "ipa_server, ipa_backup_server (string)" -msgstr "" +msgstr "ipa_server, ipa_backup_server (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:104 @@ -9795,7 +9825,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:117 msgid "ipa_hostname (string)" -msgstr "" +msgstr "ipa_hostname (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:120 @@ -9808,7 +9838,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:129 sssd-ad.5.xml:1213 msgid "dyndns_update (boolean)" -msgstr "" +msgstr "dyndns_update (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:132 @@ -9838,7 +9868,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:158 sssd-ad.5.xml:1238 msgid "dyndns_ttl (integer)" -msgstr "" +msgstr "dyndns_ttl (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:161 sssd-ad.5.xml:1241 @@ -9859,12 +9889,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:172 msgid "Default: 1200 (seconds)" -msgstr "" +msgstr "ნაგულისხმევი: 1200 (წმ)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:178 sssd-ad.5.xml:1252 msgid "dyndns_iface (string)" -msgstr "" +msgstr "dyndns_iface (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:181 sssd-ad.5.xml:1255 @@ -9898,7 +9928,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:205 sssd-ad.5.xml:1323 msgid "dyndns_auth (string)" -msgstr "" +msgstr "dyndns_auth (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:208 sssd-ad.5.xml:1326 @@ -9911,12 +9941,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:214 sssd-ad.5.xml:1332 msgid "Default: GSS-TSIG" -msgstr "" +msgstr "ნაგულისხმევი: GSS-TSIG" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:220 sssd-ad.5.xml:1338 msgid "dyndns_auth_ptr (string)" -msgstr "" +msgstr "dyndns_auth_ptr (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:223 sssd-ad.5.xml:1341 @@ -9934,7 +9964,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:235 msgid "ipa_enable_dns_sites (boolean)" -msgstr "" +msgstr "ipa_enable_dns_sites (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:238 sssd-ad.5.xml:238 @@ -9957,7 +9987,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:261 sssd-ad.5.xml:1273 msgid "dyndns_refresh_interval (integer)" -msgstr "" +msgstr "dyndns_refresh_interval (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:264 @@ -9970,7 +10000,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:277 sssd-ad.5.xml:1291 msgid "dyndns_update_ptr (bool)" -msgstr "" +msgstr "dyndns_update_ptr (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:280 sssd-ad.5.xml:1294 @@ -10001,7 +10031,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:302 sssd-ad.5.xml:1310 msgid "dyndns_force_tcp (bool)" -msgstr "" +msgstr "dyndns_force_tcp (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:305 sssd-ad.5.xml:1313 @@ -10018,7 +10048,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:315 sssd-ad.5.xml:1353 msgid "dyndns_server (string)" -msgstr "" +msgstr "dyndns_server (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:318 sssd-ad.5.xml:1356 @@ -10067,7 +10097,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:353 sssd-ad.5.xml:1391 msgid "dyndns_update_per_family (boolean)" -msgstr "" +msgstr "dyndns_update_per_family (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:356 sssd-ad.5.xml:1394 @@ -10080,7 +10110,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:368 sssd-ad.5.xml:1406 msgid "dyndns_dot_cacert (string)" -msgstr "" +msgstr "dyndns_dot_cacert (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:371 sssd-ad.5.xml:1409 @@ -10098,7 +10128,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:383 sssd-ad.5.xml:1421 msgid "dyndns_dot_cert (string)" -msgstr "" +msgstr "dyndns_dot_cert (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:386 sssd-ad.5.xml:1424 @@ -10124,7 +10154,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:403 sssd-ad.5.xml:1441 msgid "dyndns_dot_key (string)" -msgstr "" +msgstr "dyndns_dot_key (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:406 sssd-ad.5.xml:1444 @@ -10137,7 +10167,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:418 msgid "ipa_access_order (string)" -msgstr "" +msgstr "ipa_access_order (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:425 @@ -10154,7 +10184,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:471 msgid "ipa_deskprofile_search_base (string)" -msgstr "" +msgstr "ipa_deskprofile_search_base (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:474 @@ -10171,7 +10201,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:484 msgid "ipa_subid_ranges_search_base (string)" -msgstr "" +msgstr "ipa_subid_ranges_search_base (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:487 @@ -10188,7 +10218,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:498 msgid "ipa_hbac_search_base (string)" -msgstr "" +msgstr "ipa_hbac_search_base (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:501 @@ -10198,7 +10228,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:511 msgid "ipa_host_search_base (string)" -msgstr "" +msgstr "ipa_host_search_base (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:514 @@ -10208,7 +10238,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:520 msgid "ipa_selinux_search_base (string)" -msgstr "" +msgstr "ipa_selinux_search_base (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:523 @@ -10218,7 +10248,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:539 msgid "ipa_subdomains_search_base (string)" -msgstr "" +msgstr "ipa_subdomains_search_base (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:542 @@ -10233,7 +10263,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:558 msgid "ipa_master_domain_search_base (string)" -msgstr "" +msgstr "ipa_master_domain_search_base (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:561 @@ -10248,7 +10278,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:577 msgid "ipa_views_search_base (string)" -msgstr "" +msgstr "ipa_views_search_base (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:580 @@ -10277,7 +10307,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:611 sssd-ad.5.xml:1459 msgid "krb5_confd_path (string)" -msgstr "" +msgstr "krb5_confd_path (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:614 sssd-ad.5.xml:1462 @@ -10301,7 +10331,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:629 msgid "ipa_deskprofile_refresh (integer)" -msgstr "" +msgstr "ipa_deskprofile_refresh (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:632 @@ -10314,12 +10344,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:639 sssd-ipa.5.xml:669 sssd-ipa.5.xml:685 sssd-ad.5.xml:600 msgid "Default: 5 (seconds)" -msgstr "" +msgstr "ნაგულისხმევი: 5 (წმ)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:645 msgid "ipa_deskprofile_request_interval (integer)" -msgstr "" +msgstr "ipa_deskprofile_request_interval (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:648 @@ -10331,12 +10361,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:653 msgid "Default: 60 (minutes)" -msgstr "" +msgstr "ნაგულისხმევი: 60 (წთ)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:659 msgid "ipa_hbac_refresh (integer)" -msgstr "" +msgstr "ipa_hbac_refresh (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:662 @@ -10349,7 +10379,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:675 msgid "ipa_hbac_selinux (integer)" -msgstr "" +msgstr "ipa_hbac_selinux (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:678 @@ -10362,7 +10392,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:691 msgid "ipa_server_mode (boolean)" -msgstr "" +msgstr "ipa_server_mode (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:694 @@ -10403,7 +10433,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:733 msgid "ipa_automount_location (string)" -msgstr "" +msgstr "ipa_automount_location (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:736 @@ -10423,7 +10453,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:756 msgid "ipa_view_class (string)" -msgstr "" +msgstr "ipa_view_class (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:759 @@ -10433,12 +10463,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:762 msgid "Default: nsContainer" -msgstr "" +msgstr "ნაგულისხმევი: nsContainer" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:768 msgid "ipa_view_name (string)" -msgstr "" +msgstr "ipa_view_name (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:771 @@ -10451,12 +10481,12 @@ msgstr "" #: sssd-ldap-attributes.5.xml:1010 sssd-ldap-attributes.5.xml:1068 #: sssd-ldap-attributes.5.xml:1226 sssd-ldap-attributes.5.xml:1271 msgid "Default: cn" -msgstr "" +msgstr "ნაგულისხმევი: cn" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:781 msgid "ipa_override_object_class (string)" -msgstr "" +msgstr "ipa_override_object_class (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:784 @@ -10466,12 +10496,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:787 msgid "Default: ipaOverrideAnchor" -msgstr "" +msgstr "ნაგულისხმევი: ipaOverrideAnchor" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:793 msgid "ipa_anchor_uuid (string)" -msgstr "" +msgstr "ipa_anchor_uuid (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:796 @@ -10483,12 +10513,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:800 msgid "Default: ipaAnchorUUID" -msgstr "" +msgstr "ნაგულისხმევი: ipaAnchorUUID" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:806 msgid "ipa_user_override_object_class (string)" -msgstr "" +msgstr "ipa_user_override_object_class (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:809 @@ -10505,47 +10535,47 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ipa.5.xml:817 msgid "ldap_user_name" -msgstr "" +msgstr "ldap_user_name" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ipa.5.xml:820 msgid "ldap_user_uid_number" -msgstr "" +msgstr "ldap_user_uid_number" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ipa.5.xml:823 msgid "ldap_user_gid_number" -msgstr "" +msgstr "ldap_user_gid_number" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ipa.5.xml:826 msgid "ldap_user_gecos" -msgstr "" +msgstr "ldap_user_gecos" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ipa.5.xml:829 msgid "ldap_user_home_directory" -msgstr "" +msgstr "ldap_user_home_directory" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ipa.5.xml:832 msgid "ldap_user_shell" -msgstr "" +msgstr "ldap_user_shell" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ipa.5.xml:835 msgid "ldap_user_ssh_public_key" -msgstr "" +msgstr "ldap_user_ssh_public_key" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:840 msgid "Default: ipaUserOverride" -msgstr "" +msgstr "ნაგულისხმევი: ipaUserOverride" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:846 msgid "ipa_group_override_object_class (string)" -msgstr "" +msgstr "ipa_group_override_object_class (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:849 @@ -10562,17 +10592,17 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ipa.5.xml:857 msgid "ldap_group_name" -msgstr "" +msgstr "ldap_group_name" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ipa.5.xml:860 msgid "ldap_group_gid_number" -msgstr "" +msgstr "ldap_group_gid_number" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:865 msgid "Default: ipaGroupOverride" -msgstr "" +msgstr "ნაგულისხმევი: ipaGroupOverride" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sssd-ipa.5.xml:749 @@ -10667,42 +10697,42 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> #: sssd-ipa.5.xml:931 sssd-ipa.5.xml:971 msgid "ad_server" -msgstr "" +msgstr "ad_server" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> #: sssd-ipa.5.xml:934 msgid "ad_backup_server" -msgstr "" +msgstr "ad_backup_server" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> #: sssd-ipa.5.xml:937 sssd-ipa.5.xml:974 msgid "ad_site" -msgstr "" +msgstr "ad_site" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> #: sssd-ipa.5.xml:940 msgid "ipa_server" -msgstr "" +msgstr "ipa_server" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> #: sssd-ipa.5.xml:943 msgid "ipa_backup_server" -msgstr "" +msgstr "ipa_backup_server" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> #: sssd-ipa.5.xml:946 msgid "ldap_search_base" -msgstr "" +msgstr "ldap_search_base" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> #: sssd-ipa.5.xml:949 msgid "ldap_user_search_base" -msgstr "" +msgstr "ldap_user_search_base" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> #: sssd-ipa.5.xml:952 msgid "ldap_group_search_base" -msgstr "" +msgstr "ldap_group_search_base" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sssd-ipa.5.xml:960 @@ -10766,7 +10796,7 @@ msgstr "" #. type: Content of: <reference><refentry><refnamediv><refname> #: sssd-ad.5.xml:10 sssd-ad.5.xml:16 msgid "sssd-ad" -msgstr "" +msgstr "sssd-ad" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sssd-ad.5.xml:17 @@ -10854,6 +10884,8 @@ msgid "" "ldap_id_mapping = False\n" " " msgstr "" +"ldap_id_mapping = False\n" +" " #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ad.5.xml:85 @@ -10906,7 +10938,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:138 msgid "ad_domain (string)" -msgstr "" +msgstr "ad_domain (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:141 @@ -10932,7 +10964,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:158 msgid "ad_enabled_domains (string)" -msgstr "" +msgstr "ad_enabled_domains (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:161 @@ -10977,7 +11009,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:193 msgid "ad_server, ad_backup_server (string)" -msgstr "" +msgstr "ad_server, ad_backup_server (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:196 @@ -11004,7 +11036,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:216 msgid "ad_hostname (string)" -msgstr "" +msgstr "ad_hostname (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:219 @@ -11026,7 +11058,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:235 msgid "ad_enable_dns_sites (boolean)" -msgstr "" +msgstr "ad_enable_dns_sites (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:242 @@ -11042,7 +11074,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:258 msgid "ad_access_filter (string)" -msgstr "" +msgstr "ad_access_filter (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:261 @@ -11123,7 +11155,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:334 msgid "ad_site (string)" -msgstr "" +msgstr "ad_site (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:337 @@ -11135,7 +11167,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:348 msgid "ad_enable_gc (boolean)" -msgstr "" +msgstr "ad_enable_gc (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:351 @@ -11158,7 +11190,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:373 msgid "ad_gpo_access_control (string)" -msgstr "" +msgstr "ad_gpo_access_control (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:376 @@ -11264,17 +11296,17 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:482 msgid "Default: permissive" -msgstr "" +msgstr "ნაგულისხმევი: permissive" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:485 msgid "Default: enforcing" -msgstr "" +msgstr "ნაგულისხმევი: enforcing" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:491 msgid "ad_gpo_implicit_deny (boolean)" -msgstr "" +msgstr "ad_gpo_implicit_deny (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:494 @@ -11303,23 +11335,23 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> #: sssd-ad.5.xml:523 sssd-ad.5.xml:549 msgid "allow-rules" -msgstr "" +msgstr "allow-rules" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> #: sssd-ad.5.xml:523 sssd-ad.5.xml:549 msgid "deny-rules" -msgstr "" +msgstr "deny-rules" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> #: sssd-ad.5.xml:524 sssd-ad.5.xml:550 msgid "results" -msgstr "" +msgstr "results" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry> #: sssd-ad.5.xml:527 sssd-ad.5.xml:530 sssd-ad.5.xml:533 sssd-ad.5.xml:553 #: sssd-ad.5.xml:556 sssd-ad.5.xml:559 msgid "missing" -msgstr "" +msgstr "missing" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry><para> #: sssd-ad.5.xml:528 @@ -11330,7 +11362,7 @@ msgstr "" #: sssd-ad.5.xml:530 sssd-ad.5.xml:533 sssd-ad.5.xml:536 sssd-ad.5.xml:556 #: sssd-ad.5.xml:559 sssd-ad.5.xml:562 msgid "present" -msgstr "" +msgstr "present" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry><para> #: sssd-ad.5.xml:531 @@ -11350,7 +11382,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> #: sssd-ad.5.xml:548 msgid "ad_gpo_implicit_deny = True" -msgstr "" +msgstr "ad_gpo_implicit_deny = True" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry><para> #: sssd-ad.5.xml:554 sssd-ad.5.xml:557 @@ -11360,7 +11392,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:570 msgid "ad_gpo_ignore_unreadable (boolean)" -msgstr "" +msgstr "ad_gpo_ignore_unreadable (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:573 @@ -11375,7 +11407,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:590 msgid "ad_gpo_cache_timeout (integer)" -msgstr "" +msgstr "ad_gpo_cache_timeout (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:593 @@ -11388,7 +11420,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:606 msgid "ad_gpo_map_interactive (string)" -msgstr "" +msgstr "ad_gpo_map_interactive (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:609 @@ -11436,37 +11468,37 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ad.5.xml:664 msgid "gdm-fingerprint" -msgstr "" +msgstr "gdm-fingerprint" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ad.5.xml:684 msgid "lightdm" -msgstr "" +msgstr "lightdm" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ad.5.xml:689 msgid "lxdm" -msgstr "" +msgstr "lxdm" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ad.5.xml:694 msgid "sddm" -msgstr "" +msgstr "sddm" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ad.5.xml:699 msgid "unity" -msgstr "" +msgstr "unity" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ad.5.xml:704 msgid "xdm" -msgstr "" +msgstr "xdm" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:713 msgid "ad_gpo_map_remote_interactive (string)" -msgstr "" +msgstr "ad_gpo_map_remote_interactive (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:716 @@ -11515,17 +11547,17 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ad.5.xml:758 msgid "sshd" -msgstr "" +msgstr "sshd" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ad.5.xml:763 msgid "cockpit" -msgstr "" +msgstr "cockpit" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:772 msgid "ad_gpo_map_network (string)" -msgstr "" +msgstr "ad_gpo_map_network (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:775 @@ -11574,17 +11606,17 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ad.5.xml:816 msgid "ftp" -msgstr "" +msgstr "ftp" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ad.5.xml:821 msgid "samba" -msgstr "" +msgstr "samba" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:830 msgid "ad_gpo_map_batch (string)" -msgstr "" +msgstr "ad_gpo_map_batch (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:833 @@ -11636,12 +11668,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ad.5.xml:874 msgid "crond" -msgstr "" +msgstr "crond" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:883 msgid "ad_gpo_map_service (string)" -msgstr "" +msgstr "ad_gpo_map_service (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:886 @@ -11673,6 +11705,8 @@ msgid "" "ad_gpo_map_service = +my_pam_service\n" " " msgstr "" +"ad_gpo_map_service = +my_pam_service\n" +" " #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:909 sssd-ad.5.xml:984 @@ -11688,7 +11722,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:927 msgid "ad_gpo_map_permit (string)" -msgstr "" +msgstr "ad_gpo_map_permit (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:930 @@ -11704,6 +11738,8 @@ msgid "" "ad_gpo_map_permit = +my_pam_service, -sudo\n" " " msgstr "" +"ad_gpo_map_permit = +my_pam_service, -sudo\n" +" " #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:935 @@ -11720,17 +11756,17 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ad.5.xml:952 msgid "polkit-1" -msgstr "" +msgstr "polkit-1" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ad.5.xml:967 msgid "systemd-user" -msgstr "" +msgstr "systemd-user" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:976 msgid "ad_gpo_map_deny (string)" -msgstr "" +msgstr "ad_gpo_map_deny (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:979 @@ -11746,11 +11782,13 @@ msgid "" "ad_gpo_map_deny = +my_pam_service\n" " " msgstr "" +"ad_gpo_map_deny = +my_pam_service\n" +" " #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:1002 msgid "ad_gpo_default_right (string)" -msgstr "" +msgstr "ad_gpo_default_right (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:1005 @@ -11773,42 +11811,42 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ad.5.xml:1027 msgid "remote_interactive" -msgstr "" +msgstr "remote_interactive" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ad.5.xml:1032 msgid "network" -msgstr "" +msgstr "network" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ad.5.xml:1037 msgid "batch" -msgstr "" +msgstr "batch" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ad.5.xml:1042 msgid "service" -msgstr "" +msgstr "service" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ad.5.xml:1047 msgid "permit" -msgstr "" +msgstr "permit" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ad.5.xml:1052 msgid "deny" -msgstr "" +msgstr "deny" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:1058 msgid "Default: deny" -msgstr "" +msgstr "ნაგულისხმევი: deny" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:1064 msgid "ad_maximum_machine_account_password_age (integer)" -msgstr "" +msgstr "ad_maximum_machine_account_password_age (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:1067 @@ -11821,12 +11859,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:1073 msgid "Default: 30 days" -msgstr "" +msgstr "ნაგულისხმევი: 30 დღე" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:1079 msgid "ad_machine_account_password_renewal_opts (string)" -msgstr "" +msgstr "ad_machine_account_password_renewal_opts (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:1082 @@ -11872,7 +11910,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:1125 msgid "ad_update_samba_machine_account_password (boolean)" -msgstr "" +msgstr "ad_update_samba_machine_account_password (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:1128 @@ -11886,7 +11924,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:1141 msgid "ad_use_ldaps (bool)" -msgstr "" +msgstr "ad_use_ldaps (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:1144 @@ -11902,7 +11940,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:1161 msgid "ad_allow_remote_domain_local_groups (boolean)" -msgstr "" +msgstr "ad_allow_remote_domain_local_groups (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:1164 @@ -11962,7 +12000,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:1246 msgid "Default: 3600 (seconds)" -msgstr "" +msgstr "ნაგულისხმევი: 3600 (წმ)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:1263 @@ -12047,7 +12085,7 @@ msgstr "" #. type: Content of: <reference><refentry><refnamediv><refname> #: sssd-sudo.5.xml:10 sssd-sudo.5.xml:16 msgid "sssd-sudo" -msgstr "" +msgstr "sssd-sudo" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sssd-sudo.5.xml:17 @@ -12091,7 +12129,7 @@ msgstr "" #: sssd-sudo.5.xml:57 #, no-wrap msgid "sudoers: files sss\n" -msgstr "" +msgstr "sudoers: files sss\n" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-sudo.5.xml:61 @@ -12230,12 +12268,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><itemizedlist><listitem><para> #: sssd-sudo.5.xml:167 msgid "keyword ALL" -msgstr "" +msgstr "keyword ALL" #. type: Content of: <reference><refentry><refsect1><itemizedlist><listitem><para> #: sssd-sudo.5.xml:172 msgid "wildcard" -msgstr "" +msgstr "wildcard" #. type: Content of: <reference><refentry><refsect1><itemizedlist><listitem><para> #: sssd-sudo.5.xml:177 @@ -12320,7 +12358,7 @@ msgstr "" #. type: Content of: <reference><refentry><refnamediv><refname> #: sssd-idp.5.xml:10 sssd-idp.5.xml:16 msgid "sssd-idp" -msgstr "" +msgstr "sssd-idp" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sssd-idp.5.xml:17 @@ -12362,7 +12400,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-idp.5.xml:62 msgid "idp_type (string)" -msgstr "" +msgstr "idp_type (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-idp.5.xml:65 @@ -12383,12 +12421,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-idp.5.xml:78 sssd-idp.5.xml:94 sssd-idp.5.xml:119 msgid "Default: Not set (Required)" -msgstr "" +msgstr "ნაგულისხმევი: დაყენებული არაა (აუცილებელია)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-idp.5.xml:83 msgid "idp_client_id (string)" -msgstr "" +msgstr "idp_client_id (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-idp.5.xml:86 @@ -12402,7 +12440,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-idp.5.xml:99 msgid "idp_client_secret (string)" -msgstr "" +msgstr "idp_client_secret (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-idp.5.xml:102 @@ -12415,7 +12453,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-idp.5.xml:113 msgid "idp_token_endpoint (string)" -msgstr "" +msgstr "idp_token_endpoint (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-idp.5.xml:116 @@ -12425,7 +12463,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-idp.5.xml:124 msgid "idp_device_auth_endpoint (string)" -msgstr "" +msgstr "idp_device_auth_endpoint (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-idp.5.xml:127 @@ -12437,7 +12475,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-idp.5.xml:137 msgid "idp_userinfo_endpoint (string)" -msgstr "" +msgstr "idp_userinfo_endpoint (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-idp.5.xml:140 @@ -12449,7 +12487,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-idp.5.xml:150 msgid "idp_id_scope (string)" -msgstr "" +msgstr "idp_id_scope (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-idp.5.xml:153 @@ -12462,7 +12500,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-idp.5.xml:164 msgid "idp_auth_scope (string)" -msgstr "" +msgstr "idp_auth_scope (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-idp.5.xml:167 @@ -12483,7 +12521,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-idp.5.xml:185 msgid "idp_request_timeout (integer)" -msgstr "" +msgstr "idp_request_timeout (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-idp.5.xml:188 @@ -12493,7 +12531,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-idp.5.xml:197 msgid "idmap_range_min (integer)" -msgstr "" +msgstr "idmap_range_min (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-idp.5.xml:200 @@ -12516,12 +12554,12 @@ msgstr "" #: sssd-idp.5.xml:213 sssd-idp.5.xml:239 include/ldap_id_mapping.xml:139 #: include/ldap_id_mapping.xml:197 msgid "Default: 200000" -msgstr "" +msgstr "ნაგულისხმევი: 200000" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-idp.5.xml:218 msgid "idmap_range_max (integer)" -msgstr "" +msgstr "idmap_range_max (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-idp.5.xml:221 @@ -12534,12 +12572,12 @@ msgstr "" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> #: sssd-idp.5.xml:227 include/ldap_id_mapping.xml:165 msgid "Default: 2000200000" -msgstr "" +msgstr "ნაგულისხმევი: 2000200000" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-idp.5.xml:232 msgid "idmap_range_size (integer)" -msgstr "" +msgstr "idmap_range_size (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-idp.5.xml:235 @@ -12594,7 +12632,7 @@ msgstr "" #. type: Content of: <reference><refentry><refnamediv><refname> #: sssd.8.xml:10 sssd.8.xml:15 msgid "sssd" -msgstr "" +msgstr "sssd" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sssd.8.xml:16 @@ -12630,7 +12668,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.8.xml:53 msgid "<option>--debug-timestamps=</option><replaceable>mode</replaceable>" -msgstr "" +msgstr "<option>--debug-timestamps=</option><replaceable>რეჟიმი</replaceable>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.8.xml:57 @@ -12645,7 +12683,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.8.xml:69 msgid "<option>--debug-microseconds=</option><replaceable>mode</replaceable>" -msgstr "" +msgstr "<option>--debug-microseconds=</option><replaceable>რეჟიმი</replaceable>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.8.xml:73 @@ -12660,7 +12698,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.8.xml:85 msgid "<option>--logger=</option><replaceable>value</replaceable>" -msgstr "" +msgstr "<option>--logger=</option><replaceable>მნიშვნელობა</replaceable>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.8.xml:89 @@ -12695,7 +12733,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.8.xml:113 msgid "<option>-D</option>,<option>--daemon</option>" -msgstr "" +msgstr "<option>-D</option>,<option>--daemon</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.8.xml:117 @@ -12705,7 +12743,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.8.xml:123 sss_seed.8.xml:136 msgid "<option>-i</option>,<option>--interactive</option>" -msgstr "" +msgstr "<option>-i</option>,<option>--interactive</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.8.xml:127 @@ -12715,7 +12753,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.8.xml:133 msgid "<option>-c</option>,<option>--config</option>" -msgstr "" +msgstr "<option>-c</option>,<option>--config</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.8.xml:137 @@ -12730,22 +12768,22 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.8.xml:151 msgid "<option>--version</option>" -msgstr "" +msgstr "<option>--version</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.8.xml:155 msgid "Print version number and exit." -msgstr "" +msgstr "ვერსიის ინფორმაციის გამოტანა და გასვლა." #. type: Content of: <reference><refentry><refsect1><title> #: sssd.8.xml:163 msgid "Signals" -msgstr "" +msgstr "სიგნალები" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.8.xml:166 msgid "SIGTERM/SIGINT" -msgstr "" +msgstr "SIGTERM/SIGINT" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.8.xml:169 @@ -12757,7 +12795,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.8.xml:175 msgid "SIGHUP" -msgstr "" +msgstr "SIGHUP" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.8.xml:178 @@ -12770,7 +12808,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.8.xml:186 msgid "SIGUSR1" -msgstr "" +msgstr "SIGUSR1" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.8.xml:189 @@ -12784,7 +12822,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.8.xml:198 msgid "SIGUSR2" -msgstr "" +msgstr "SIGUSR2" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.8.xml:201 @@ -12797,7 +12835,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.8.xml:208 msgid "SIGRTMIN+1" -msgstr "" +msgstr "SIGRTMIN+1" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.8.xml:211 @@ -12810,12 +12848,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><title> #: sssd.8.xml:223 sss_ssh_authorizedkeys.1.xml:141 sss_ssh_knownhosts.1.xml:116 msgid "EXIT STATUS" -msgstr "" +msgstr "გასვლის სტატუსი" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.8.xml:226 msgid "0" -msgstr "" +msgstr "0" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.8.xml:229 @@ -12825,7 +12863,7 @@ msgstr "" #. type: Content of: <reference><refentry><refmeta><manvolnum> #: sssd.8.xml:234 sss_ssh_authorizedkeys.1.xml:11 sss_ssh_knownhosts.1.xml:11 msgid "1" -msgstr "" +msgstr "1" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.8.xml:237 @@ -12835,17 +12873,17 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.8.xml:242 msgid "2" -msgstr "" +msgstr "2" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.8.xml:245 msgid "Memory allocation error." -msgstr "" +msgstr "მეხსიერების გამოყოფის შეცდომა." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.8.xml:250 msgid "6" -msgstr "" +msgstr "6" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.8.xml:253 @@ -12855,7 +12893,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.8.xml:258 msgid "Other codes" -msgstr "" +msgstr "სხვა კოდები" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.8.xml:261 @@ -12881,7 +12919,7 @@ msgstr "" #. type: Content of: <reference><refentry><refnamediv><refname> #: sss_obfuscate.8.xml:10 sss_obfuscate.8.xml:15 msgid "sss_obfuscate" -msgstr "" +msgstr "sss_obfuscate" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sss_obfuscate.8.xml:16 @@ -12929,7 +12967,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_obfuscate.8.xml:63 msgid "<option>-s</option>,<option>--stdin</option>" -msgstr "" +msgstr "<option>-s</option>,<option>--stdin</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_obfuscate.8.xml:67 @@ -12943,6 +12981,8 @@ msgid "" "<option>-d</option>,<option>--domain</option> " "<replaceable>DOMAIN</replaceable>" msgstr "" +"<option>-d</option>,<option>--domain</option> <replaceable>დომენი</" +"replaceable>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_obfuscate.8.xml:79 @@ -12955,6 +12995,7 @@ msgstr "" #: sss_obfuscate.8.xml:86 msgid "<option>-f</option>,<option>--file</option> <replaceable>FILE</replaceable>" msgstr "" +"<option>-f</option>,<option>--file</option> <replaceable>ფაილი</replaceable>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_obfuscate.8.xml:91 @@ -12964,12 +13005,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_obfuscate.8.xml:95 msgid "Default: <filename>/etc/sssd/sssd.conf</filename>" -msgstr "" +msgstr "ნაგულისხმევი: <filename>/etc/sssd/sssd.conf</filename>" #. type: Content of: <reference><refentry><refnamediv><refname> #: sss_override.8.xml:10 sss_override.8.xml:15 msgid "sss_override" -msgstr "" +msgstr "sss_override" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sss_override.8.xml:16 @@ -13050,7 +13091,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_override.8.xml:86 msgid "<option>user-del</option> <emphasis>NAME</emphasis>" -msgstr "" +msgstr "<option>user-del</option> <emphasis>სახელი</emphasis>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_override.8.xml:91 @@ -13066,6 +13107,8 @@ msgid "" "<option>user-find</option> <optional><option>-d,--domain</option> " "DOMAIN</optional>" msgstr "" +"<option>user-find</option> <optional><option>-d,--domain</option> დომენი</" +"optional>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_override.8.xml:105 @@ -13087,7 +13130,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_override.8.xml:124 msgid "<option>user-import</option> <emphasis>FILE</emphasis>" -msgstr "" +msgstr "<option>user-import</option> <emphasis>ფაილი</emphasis>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_override.8.xml:129 @@ -13099,7 +13142,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_override.8.xml:134 msgid "original_name:name:uid:gid:gecos:home:shell:base64_encoded_certificate" -msgstr "" +msgstr "original_name:name:uid:gid:gecos:home:shell:base64_encoded_certificate" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_override.8.xml:137 @@ -13112,17 +13155,17 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_override.8.xml:146 msgid "ckent:superman::::::" -msgstr "" +msgstr "ckent:superman::::::" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_override.8.xml:149 msgid "ckent@krypton.com::501:501:Superman:/home/earth:/bin/bash:" -msgstr "" +msgstr "ckent@krypton.com::501:501:Superman:/home/earth:/bin/bash:" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_override.8.xml:155 msgid "<option>user-export</option> <emphasis>FILE</emphasis>" -msgstr "" +msgstr "<option>user-export</option> <emphasis>ფაილი</emphasis>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_override.8.xml:160 @@ -13150,7 +13193,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_override.8.xml:183 msgid "<option>group-del</option> <emphasis>NAME</emphasis>" -msgstr "" +msgstr "<option>group-del</option> <emphasis>სახელი</emphasis>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_override.8.xml:188 @@ -13166,6 +13209,8 @@ msgid "" "<option>group-find</option> <optional><option>-d,--domain</option> " "DOMAIN</optional>" msgstr "" +"<option>group-find</option> <optional><option>-d,--domain</option> დომენი</" +"optional>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_override.8.xml:202 @@ -13177,7 +13222,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_override.8.xml:210 msgid "<option>group-show</option> <emphasis>NAME</emphasis>" -msgstr "" +msgstr "<option>group-show</option> <emphasis>სახელი</emphasis>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_override.8.xml:215 @@ -13187,7 +13232,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_override.8.xml:221 msgid "<option>group-import</option> <emphasis>FILE</emphasis>" -msgstr "" +msgstr "<option>group-import</option> <emphasis>ფაილი</emphasis>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_override.8.xml:226 @@ -13199,7 +13244,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_override.8.xml:231 msgid "original_name:name:gid" -msgstr "" +msgstr "original_name:name:gid" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_override.8.xml:234 @@ -13212,17 +13257,17 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_override.8.xml:243 msgid "admins:administrators:" -msgstr "" +msgstr "admins:administrators:" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_override.8.xml:246 msgid "Domain Users:Users:501" -msgstr "" +msgstr "Domain Users:Users:501" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_override.8.xml:252 msgid "<option>group-export</option> <emphasis>FILE</emphasis>" -msgstr "" +msgstr "<option>group-export</option> <emphasis>ფაილი</emphasis>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_override.8.xml:257 @@ -13240,17 +13285,17 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para> #: sss_override.8.xml:269 sssctl.8.xml:52 msgid "Those options are available with all commands." -msgstr "" +msgstr "ეს პარამეტრები ხელმისაწვდომია ყველა ბრძანებისთვის." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_override.8.xml:274 sssctl.8.xml:57 msgid "<option>--debug</option> <replaceable>LEVEL</replaceable>" -msgstr "" +msgstr "<option>--debug</option> <replaceable>დონე</replaceable>" #. type: Content of: <reference><refentry><refnamediv><refname> #: sssd-krb5.5.xml:10 sssd-krb5.5.xml:16 msgid "sssd-krb5" -msgstr "" +msgstr "sssd-krb5" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sssd-krb5.5.xml:17 @@ -13323,7 +13368,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-krb5.5.xml:113 msgid "krb5_kpasswd, krb5_backup_kpasswd (string)" -msgstr "" +msgstr "krb5_kpasswd, krb5_backup_kpasswd (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:116 @@ -13350,7 +13395,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-krb5.5.xml:135 msgid "krb5_ccachedir (string)" -msgstr "" +msgstr "krb5_ccachedir (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:138 @@ -13363,17 +13408,17 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:145 msgid "Default: /tmp" -msgstr "" +msgstr "ნაგულისხმევი: /tmp" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-krb5.5.xml:151 msgid "krb5_ccname_template (string)" -msgstr "" +msgstr "krb5_ccname_template (სტრიქონი)" #. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd-krb5.5.xml:165 include/override_homedir.xml:11 msgid "%u" -msgstr "" +msgstr "%u" #. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:166 include/override_homedir.xml:12 @@ -13383,7 +13428,7 @@ msgstr "" #. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd-krb5.5.xml:169 include/override_homedir.xml:15 msgid "%U" -msgstr "" +msgstr "%U" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:170 @@ -13393,37 +13438,37 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd-krb5.5.xml:173 msgid "%p" -msgstr "" +msgstr "%p" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:174 msgid "principal name" -msgstr "" +msgstr "პრინციპალის სახელი" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd-krb5.5.xml:178 msgid "%r" -msgstr "" +msgstr "%r" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:179 msgid "realm name" -msgstr "" +msgstr "რეალმის სახელი" #. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd-krb5.5.xml:182 include/override_homedir.xml:53 msgid "%h" -msgstr "" +msgstr "%h" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:183 sssd-ifp.5.xml:124 msgid "home directory" -msgstr "" +msgstr "საწყისი საქაღალდე" #. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd-krb5.5.xml:187 include/override_homedir.xml:19 msgid "%d" -msgstr "" +msgstr "%d" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:188 @@ -13433,7 +13478,7 @@ msgstr "" #. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd-krb5.5.xml:193 include/override_homedir.xml:31 msgid "%P" -msgstr "" +msgstr "%P" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:194 @@ -13443,7 +13488,7 @@ msgstr "" #. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd-krb5.5.xml:199 include/override_homedir.xml:68 msgid "%%" -msgstr "" +msgstr "%%" #. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:200 include/override_homedir.xml:69 @@ -13494,12 +13539,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:234 msgid "Default: (from libkrb5)" -msgstr "" +msgstr "ნაგულისხმევი: (libkrb5-დან)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-krb5.5.xml:240 msgid "krb5_keytab (string)" -msgstr "" +msgstr "krb5_keytab (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:243 @@ -13511,7 +13556,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-krb5.5.xml:253 msgid "krb5_store_password_if_offline (boolean)" -msgstr "" +msgstr "krb5_store_password_if_offline (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:256 @@ -13531,7 +13576,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-krb5.5.xml:274 msgid "krb5_use_fast (string)" -msgstr "" +msgstr "krb5_use_fast (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:277 @@ -13582,7 +13627,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-krb5.5.xml:312 msgid "krb5_fast_principal (string)" -msgstr "" +msgstr "krb5_fast_principal (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:315 @@ -13592,7 +13637,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-krb5.5.xml:321 msgid "krb5_fast_use_anonymous_pkinit (boolean)" -msgstr "" +msgstr "krb5_fast_use_anonymous_pkinit (ლოდიკური)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:324 @@ -13605,7 +13650,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-krb5.5.xml:364 msgid "krb5_kdcinfo_lookahead (string)" -msgstr "" +msgstr "krb5_kdcinfo_lookahead (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:367 @@ -13637,12 +13682,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:392 msgid "Default: 3:1" -msgstr "" +msgstr "ნაგულისხმევი: 3:1" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-krb5.5.xml:398 msgid "krb5_use_enterprise_principal (boolean)" -msgstr "" +msgstr "krb5_use_enterprise_principal (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:401 @@ -13668,7 +13713,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-krb5.5.xml:419 msgid "krb5_use_subdomain_realm (boolean)" -msgstr "" +msgstr "krb5_use_subdomain_realm (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:422 @@ -13683,7 +13728,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-krb5.5.xml:438 msgid "krb5_map_user (string)" -msgstr "" +msgstr "krb5_map_user (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:441 @@ -13746,7 +13791,7 @@ msgstr "" #. type: Content of: <reference><refentry><refnamediv><refname> #: sss_cache.8.xml:10 sss_cache.8.xml:15 msgid "sss_cache" -msgstr "" +msgstr "sss_cache" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sss_cache.8.xml:16 @@ -13759,6 +13804,8 @@ msgid "" "<command>sss_cache</command> <arg choice='opt'> " "<replaceable>options</replaceable> </arg>" msgstr "" +"<command>sss_cache</command> <arg choice='opt'> <replaceable>პარამეტრები</" +"replaceable> </arg>" #. type: Content of: <reference><refentry><refsect1><para> #: sss_cache.8.xml:31 @@ -13772,7 +13819,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_cache.8.xml:43 msgid "<option>-E</option>,<option>--everything</option>" -msgstr "" +msgstr "<option>-E</option>,<option>--everything</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_cache.8.xml:47 @@ -13783,6 +13830,8 @@ msgstr "" #: sss_cache.8.xml:53 msgid "<option>-u</option>,<option>--user</option> <replaceable>login</replaceable>" msgstr "" +"<option>-u</option>,<option>--user</option> <replaceable>მომხმარებლისსახელი</" +"replaceable>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_cache.8.xml:58 @@ -13792,7 +13841,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_cache.8.xml:64 msgid "<option>-U</option>,<option>--users</option>" -msgstr "" +msgstr "<option>-U</option>,<option>--users</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_cache.8.xml:68 @@ -13807,6 +13856,7 @@ msgid "" "<option>-g</option>,<option>--group</option> " "<replaceable>group</replaceable>" msgstr "" +"<option>-g</option>,<option>--group</option> <replaceable>ჯგუფი</replaceable>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_cache.8.xml:80 @@ -13816,7 +13866,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_cache.8.xml:86 msgid "<option>-G</option>,<option>--groups</option>" -msgstr "" +msgstr "<option>-G</option>,<option>--groups</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_cache.8.xml:90 @@ -13831,6 +13881,8 @@ msgid "" "<option>-n</option>,<option>--netgroup</option> " "<replaceable>netgroup</replaceable>" msgstr "" +"<option>-n</option>,<option>--netgroup</option> <replaceable>ქსელურჯგუფი</" +"replaceable>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_cache.8.xml:102 @@ -13840,7 +13892,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_cache.8.xml:108 msgid "<option>-N</option>,<option>--netgroups</option>" -msgstr "" +msgstr "<option>-N</option>,<option>--netgroups</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_cache.8.xml:112 @@ -13855,6 +13907,8 @@ msgid "" "<option>-s</option>,<option>--service</option> " "<replaceable>service</replaceable>" msgstr "" +"<option>-s</option>,<option>--service</option> <replaceable>სერვისი</" +"replaceable>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_cache.8.xml:124 @@ -13864,7 +13918,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_cache.8.xml:130 msgid "<option>-S</option>,<option>--services</option>" -msgstr "" +msgstr "<option>-S</option>,<option>--services</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_cache.8.xml:134 @@ -13888,7 +13942,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_cache.8.xml:152 msgid "<option>-A</option>,<option>--autofs-maps</option>" -msgstr "" +msgstr "<option>-A</option>,<option>--autofs-maps</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_cache.8.xml:156 @@ -13903,6 +13957,8 @@ msgid "" "<option>-h</option>,<option>--ssh-host</option> " "<replaceable>hostname</replaceable>" msgstr "" +"<option>-h</option>,<option>--ssh-host</option> <replaceable>ჰოსტისსახელი</" +"replaceable>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_cache.8.xml:168 @@ -13912,7 +13968,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_cache.8.xml:174 msgid "<option>-H</option>,<option>--ssh-hosts</option>" -msgstr "" +msgstr "<option>-H</option>,<option>--ssh-hosts</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_cache.8.xml:178 @@ -13936,7 +13992,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_cache.8.xml:197 msgid "<option>-R</option>,<option>--sudo-rules</option>" -msgstr "" +msgstr "<option>-R</option>,<option>--sudo-rules</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_cache.8.xml:201 @@ -13951,6 +14007,8 @@ msgid "" "<option>-d</option>,<option>--domain</option> " "<replaceable>domain</replaceable>" msgstr "" +"<option>-d</option>,<option>--domain</option> <replaceable>დომენი</" +"replaceable>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_cache.8.xml:214 @@ -14007,7 +14065,7 @@ msgstr "" #. type: Content of: <reference><refentry><refnamediv><refname> #: sss_debuglevel.8.xml:10 sss_debuglevel.8.xml:15 msgid "sss_debuglevel" -msgstr "" +msgstr "sss_debuglevel" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sss_debuglevel.8.xml:16 @@ -14033,7 +14091,7 @@ msgstr "" #. type: Content of: <reference><refentry><refnamediv><refname> #: sss_seed.8.xml:10 sss_seed.8.xml:15 msgid "sss_seed" -msgstr "" +msgstr "sss_seed" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sss_seed.8.xml:16 @@ -14092,6 +14150,7 @@ msgstr "" #: sss_seed.8.xml:76 msgid "<option>-u</option>,<option>--uid</option> <replaceable>UID</replaceable>" msgstr "" +"<option>-u</option>,<option>--uid</option> <replaceable>UID</replaceable>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_seed.8.xml:81 @@ -14102,6 +14161,7 @@ msgstr "" #: sss_seed.8.xml:88 msgid "<option>-g</option>,<option>--gid</option> <replaceable>GID</replaceable>" msgstr "" +"<option>-g</option>,<option>--gid</option> <replaceable>GID</replaceable>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_seed.8.xml:93 @@ -14114,6 +14174,8 @@ msgid "" "<option>-c</option>,<option>--gecos</option> " "<replaceable>COMMENT</replaceable>" msgstr "" +"<option>-c</option>,<option>--gecos</option> <replaceable>კომენტარი</" +"replaceable>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_seed.8.xml:105 @@ -14178,7 +14240,7 @@ msgstr "" #. type: Content of: <reference><refentry><refnamediv><refname> #: sssd-ifp.5.xml:10 sssd-ifp.5.xml:16 msgid "sssd-ifp" -msgstr "" +msgstr "sssd-ifp" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sssd-ifp.5.xml:17 @@ -14219,17 +14281,17 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> #: sssd-ifp.5.xml:48 sss_ssh_authorizedkeys.1.xml:92 msgid "ca_db" -msgstr "" +msgstr "ca_db" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> #: sssd-ifp.5.xml:49 sss_ssh_authorizedkeys.1.xml:93 msgid "p11_child_timeout" -msgstr "" +msgstr "p11_child_timeout" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> #: sssd-ifp.5.xml:50 sss_ssh_authorizedkeys.1.xml:94 msgid "certificate_verification" -msgstr "" +msgstr "certificate_verification" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sssd-ifp.5.xml:52 @@ -14274,7 +14336,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd-ifp.5.xml:107 msgid "name" -msgstr "" +msgstr "name" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd-ifp.5.xml:108 @@ -14284,7 +14346,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd-ifp.5.xml:111 msgid "uidNumber" -msgstr "" +msgstr "uidNumber" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd-ifp.5.xml:112 @@ -14294,7 +14356,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd-ifp.5.xml:115 msgid "gidNumber" -msgstr "" +msgstr "gidNumber" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd-ifp.5.xml:116 @@ -14304,7 +14366,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd-ifp.5.xml:119 msgid "gecos" -msgstr "" +msgstr "gecos" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd-ifp.5.xml:120 @@ -14314,12 +14376,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd-ifp.5.xml:123 msgid "homeDirectory" -msgstr "" +msgstr "homeDirectory" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd-ifp.5.xml:127 msgid "loginShell" -msgstr "" +msgstr "loginShell" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd-ifp.5.xml:128 @@ -14386,7 +14448,7 @@ msgstr "" #. type: Content of: <reference><refentry><refnamediv><refname> #: sss_rpcidmapd.5.xml:26 sss_rpcidmapd.5.xml:32 msgid "sss_rpcidmapd" -msgstr "" +msgstr "sss_rpcidmapd" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sss_rpcidmapd.5.xml:33 @@ -14396,7 +14458,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><title> #: sss_rpcidmapd.5.xml:37 msgid "CONFIGURATION FILE" -msgstr "" +msgstr "კონფიგურაციის ფაილი" #. type: Content of: <reference><refentry><refsect1><para> #: sss_rpcidmapd.5.xml:39 @@ -14445,7 +14507,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sss_rpcidmapd.5.xml:69 msgid "memcache (bool)" -msgstr "" +msgstr "memcache (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sss_rpcidmapd.5.xml:72 @@ -14500,7 +14562,7 @@ msgstr "" #. type: Content of: <refsect1><title> #: sss_rpcidmapd.5.xml:120 sssd-kcm.8.xml:316 include/seealso.xml:2 msgid "SEE ALSO" -msgstr "" +msgstr "ასევე იხილეთ" #. type: Content of: <reference><refentry><refsect1><para> #: sss_rpcidmapd.5.xml:122 @@ -14513,7 +14575,7 @@ msgstr "" #. type: Content of: <reference><refentry><refnamediv><refname> #: sss_ssh_authorizedkeys.1.xml:10 sss_ssh_authorizedkeys.1.xml:15 msgid "sss_ssh_authorizedkeys" -msgstr "" +msgstr "sss_ssh_authorizedkeys" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sss_ssh_authorizedkeys.1.xml:16 @@ -14655,7 +14717,7 @@ msgstr "" #. type: Content of: <reference><refentry><refnamediv><refname> #: sss_ssh_knownhosts.1.xml:10 sss_ssh_knownhosts.1.xml:15 msgid "sss_ssh_knownhosts" -msgstr "" +msgstr "sss_ssh_knownhosts" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sss_ssh_knownhosts.1.xml:16 @@ -14715,7 +14777,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_ssh_knownhosts.1.xml:75 msgid "<option>-o</option>,<option>--only-host-name</option>" -msgstr "" +msgstr "<option>-o</option>,<option>--only-host-name</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_ssh_knownhosts.1.xml:79 @@ -14773,7 +14835,7 @@ msgstr "" #. type: Content of: <reference><refentry><refnamediv><refname> #: idmap_sss.8.xml:10 idmap_sss.8.xml:15 msgid "idmap_sss" -msgstr "" +msgstr "idmap_sss" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: idmap_sss.8.xml:16 @@ -14845,7 +14907,7 @@ msgstr "" #. type: Content of: <reference><refentry><refnamediv><refname> #: sssctl.8.xml:10 sssctl.8.xml:15 msgid "sssctl" -msgstr "" +msgstr "sssctl" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sssctl.8.xml:16 @@ -14881,7 +14943,7 @@ msgstr "" #. type: Content of: <reference><refentry><refnamediv><refname> #: sssd-session-recording.5.xml:10 sssd-session-recording.5.xml:16 msgid "sssd-session-recording" -msgstr "" +msgstr "sssd-session-recording" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sssd-session-recording.5.xml:17 @@ -14946,7 +15008,7 @@ msgstr "" #. type: Content of: <reference><refentry><refnamediv><refname> #: sssd-kcm.8.xml:10 sssd-kcm.8.xml:16 msgid "sssd-kcm" -msgstr "" +msgstr "sssd-kcm" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sssd-kcm.8.xml:17 @@ -15109,6 +15171,9 @@ msgid "" "debug_level = 10\n" " " msgstr "" +"[kcm]\n" +"debug_level = 10\n" +" " #. type: Content of: <reference><refentry><refsect1><para><programlisting> #: sssd-kcm.8.xml:149 sssd-kcm.8.xml:211 @@ -15117,6 +15182,8 @@ msgid "" "systemctl restart sssd-kcm.service\n" " " msgstr "" +"systemctl restart sssd-kcm.service\n" +" " #. type: Content of: <reference><refentry><refsect1><para> #: sssd-kcm.8.xml:135 @@ -15146,7 +15213,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><title> #: sssd-kcm.8.xml:166 msgid "RENEWALS" -msgstr "" +msgstr "განახლებები" #. type: Content of: <reference><refentry><refsect1><para><programlisting> #: sssd-kcm.8.xml:174 @@ -15234,7 +15301,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd-kcm.8.xml:234 msgid "socket_path (string)" -msgstr "" +msgstr "socket_path (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd-kcm.8.xml:237 @@ -15245,6 +15312,7 @@ msgstr "" #: sssd-kcm.8.xml:240 msgid "Default: <replaceable>/var/run/.heim_org.h5l.kcm-socket</replaceable>" msgstr "" +"ნაგულისხმევი: <replaceable>/var/run/.heim_org.h5l.kcm-socket</replaceable>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd-kcm.8.xml:243 @@ -15257,7 +15325,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd-kcm.8.xml:252 msgid "max_ccaches (integer)" -msgstr "" +msgstr "max_ccaches (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd-kcm.8.xml:255 @@ -15272,7 +15340,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd-kcm.8.xml:264 msgid "max_uid_ccaches (integer)" -msgstr "" +msgstr "max_uid_ccaches (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd-kcm.8.xml:267 @@ -15284,12 +15352,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd-kcm.8.xml:272 msgid "Default: 64" -msgstr "" +msgstr "ნაგულისხმევი: 64" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd-kcm.8.xml:277 msgid "max_ccache_size (integer)" -msgstr "" +msgstr "max_ccache_size (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd-kcm.8.xml:280 @@ -15301,12 +15369,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd-kcm.8.xml:284 msgid "Default: 65536" -msgstr "" +msgstr "ნაგულისხმევი: 65536" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd-kcm.8.xml:289 msgid "tgt_renewal (bool)" -msgstr "" +msgstr "tgt_renewal (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd-kcm.8.xml:292 @@ -15321,7 +15389,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd-kcm.8.xml:300 msgid "tgt_renewal_inherit (string)" -msgstr "" +msgstr "tgt_renewal_inherit (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd-kcm.8.xml:303 @@ -15331,7 +15399,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd-kcm.8.xml:307 msgid "Default: NULL" -msgstr "" +msgstr "ნაგულისხმევი: NULL" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-kcm.8.xml:318 @@ -15345,12 +15413,12 @@ msgstr "" #. type: Content of: <reference><refentry><refnamediv><refname> #: sssd-systemtap.5.xml:10 sssd-systemtap.5.xml:16 msgid "sssd-systemtap" -msgstr "" +msgstr "sssd-systemtap" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sssd-systemtap.5.xml:17 msgid "SSSD systemtap information" -msgstr "" +msgstr "SSSD systemtap-ის ინფორმაცია" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-systemtap.5.xml:23 @@ -15383,7 +15451,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><title> #: sssd-systemtap.5.xml:57 msgid "PROBE POINTS" -msgstr "" +msgstr "ზონდირების წერტილები" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sssd-systemtap.5.xml:59 sssd-systemtap.5.xml:367 @@ -15640,6 +15708,8 @@ msgid "" "filter:string\n" " " msgstr "" +"filter:სტრიქონი\n" +" " #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd-systemtap.5.xml:288 @@ -15787,7 +15857,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd-systemtap.5.xml:422 msgid "dp_request.stp" -msgstr "" +msgstr "dp_request.stp" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd-systemtap.5.xml:425 @@ -15797,7 +15867,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd-systemtap.5.xml:430 msgid "id_perf.stp" -msgstr "" +msgstr "id_perf.stp" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd-systemtap.5.xml:433 @@ -15807,7 +15877,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd-systemtap.5.xml:439 msgid "ldap_perf.stp" -msgstr "" +msgstr "ldap_perf.stp" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd-systemtap.5.xml:442 @@ -15817,7 +15887,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd-systemtap.5.xml:447 msgid "nested_group_perf.stp" -msgstr "" +msgstr "nested_group_perf.stp" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd-systemtap.5.xml:450 @@ -15827,7 +15897,7 @@ msgstr "" #. type: Content of: <reference><refentry><refnamediv><refname> #: sssd-ldap-attributes.5.xml:10 sssd-ldap-attributes.5.xml:16 msgid "sssd-ldap-attributes" -msgstr "" +msgstr "sssd-ldap-attributes" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sssd-ldap-attributes.5.xml:17 @@ -15853,7 +15923,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:42 msgid "ldap_user_object_class (string)" -msgstr "" +msgstr "ldap_user_object_class (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:45 @@ -15863,12 +15933,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:48 msgid "Default: posixAccount" -msgstr "" +msgstr "ნაგულისხმევი: posixAccount" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:54 msgid "ldap_user_name (string)" -msgstr "" +msgstr "ldap_user_name (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:57 @@ -15883,7 +15953,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:68 msgid "ldap_user_uid_number (string)" -msgstr "" +msgstr "ldap_user_uid_number (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:71 @@ -15893,12 +15963,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:75 msgid "Default: uidNumber" -msgstr "" +msgstr "ნაგულისხმევი: uidNumber" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:81 msgid "ldap_user_gid_number (string)" -msgstr "" +msgstr "ldap_user_gid_number (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:84 @@ -15908,12 +15978,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:88 sssd-ldap-attributes.5.xml:700 msgid "Default: gidNumber" -msgstr "" +msgstr "ნაგულისხმევი: gidNumber" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:94 msgid "ldap_user_primary_group (string)" -msgstr "" +msgstr "ldap_user_primary_group (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:97 @@ -15931,7 +16001,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:109 msgid "ldap_user_gecos (string)" -msgstr "" +msgstr "ldap_user_gecos (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:112 @@ -15941,12 +16011,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:116 msgid "Default: gecos" -msgstr "" +msgstr "ნაგულისხმევი: gecos" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:122 msgid "ldap_user_home_directory (string)" -msgstr "" +msgstr "ldap_user_home_directory (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:125 @@ -15961,7 +16031,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:135 msgid "ldap_user_shell (string)" -msgstr "" +msgstr "ldap_user_shell (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:138 @@ -15971,12 +16041,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:142 msgid "Default: loginShell" -msgstr "" +msgstr "ნაგულისხმევი: loginShell" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:148 msgid "ldap_user_uuid (string)" -msgstr "" +msgstr "ldap_user_uuid (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:151 @@ -15993,7 +16063,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:162 msgid "ldap_user_objectsid (string)" -msgstr "" +msgstr "ldap_user_objectsid (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:165 @@ -16010,7 +16080,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:177 msgid "ldap_user_modify_timestamp (string)" -msgstr "" +msgstr "ldap_user_modify_timestamp (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:180 sssd-ldap-attributes.5.xml:751 @@ -16024,12 +16094,12 @@ msgstr "" #: sssd-ldap-attributes.5.xml:184 sssd-ldap-attributes.5.xml:755 #: sssd-ldap-attributes.5.xml:881 msgid "Default: modifyTimestamp" -msgstr "" +msgstr "ნაგულისხმევი: modifyTimestamp" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:190 msgid "ldap_user_shadow_last_change (string)" -msgstr "" +msgstr "ldap_user_shadow_last_change (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:193 @@ -16043,12 +16113,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:203 msgid "Default: shadowLastChange" -msgstr "" +msgstr "ნაგულისხმევი: shadowLastChange" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:209 msgid "ldap_user_shadow_min (string)" -msgstr "" +msgstr "ldap_user_shadow_min (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:212 @@ -16062,12 +16132,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:221 msgid "Default: shadowMin" -msgstr "" +msgstr "ნაგულისხმევი: shadowMin" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:227 msgid "ldap_user_shadow_max (string)" -msgstr "" +msgstr "ldap_user_shadow_max (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:230 @@ -16081,12 +16151,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:239 msgid "Default: shadowMax" -msgstr "" +msgstr "ნაგულისხმევი: shadowMax" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:245 msgid "ldap_user_shadow_warning (string)" -msgstr "" +msgstr "ldap_user_shadow_warning (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:248 @@ -16100,12 +16170,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:258 msgid "Default: shadowWarning" -msgstr "" +msgstr "ნაგულისხმევი: shadowWarning" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:264 msgid "ldap_user_shadow_inactive (string)" -msgstr "" +msgstr "ldap_user_shadow_inactive (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:267 @@ -16119,12 +16189,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:277 msgid "Default: shadowInactive" -msgstr "" +msgstr "ნაგულისხმევი: shadowInactive" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:283 msgid "ldap_user_shadow_expire (string)" -msgstr "" +msgstr "ldap_user_shadow_expire (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:286 @@ -16139,12 +16209,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:296 msgid "Default: shadowExpire" -msgstr "" +msgstr "ნაგულისხმევი: shadowExpire" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:302 msgid "ldap_user_krb_last_pwd_change (string)" -msgstr "" +msgstr "ldap_user_krb_last_pwd_change (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:305 @@ -16157,12 +16227,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:311 msgid "Default: krbLastPwdChange" -msgstr "" +msgstr "ნაგულისხმევი: krbLastPwdChange" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:317 msgid "ldap_user_krb_password_expiration (string)" -msgstr "" +msgstr "ldap_user_krb_password_expiration (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:320 @@ -16174,12 +16244,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:326 msgid "Default: krbPasswordExpiration" -msgstr "" +msgstr "ნაგულისხმევი: krbPasswordExpiration" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:332 msgid "ldap_user_ad_account_expires (string)" -msgstr "" +msgstr "ldap_user_ad_account_expires (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:335 @@ -16191,12 +16261,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:340 msgid "Default: accountExpires" -msgstr "" +msgstr "ნაგულისხმევი: accountExpires" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:346 msgid "ldap_user_ad_user_account_control (string)" -msgstr "" +msgstr "ldap_user_ad_user_account_control (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:349 @@ -16208,12 +16278,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:354 msgid "Default: userAccountControl" -msgstr "" +msgstr "ნაგულისხმევი: userAccountControl" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:360 msgid "ldap_ns_account_lock (string)" -msgstr "" +msgstr "ldap_ns_account_lock (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:363 @@ -16225,12 +16295,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:368 msgid "Default: nsAccountLock" -msgstr "" +msgstr "ნაგულისხმევი: nsAccountLock" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:374 msgid "ldap_user_nds_login_disabled (string)" -msgstr "" +msgstr "ldap_user_nds_login_disabled (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:377 @@ -16242,12 +16312,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:381 sssd-ldap-attributes.5.xml:395 msgid "Default: loginDisabled" -msgstr "" +msgstr "ნაგულისხმევი: loginDisabled" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:387 msgid "ldap_user_nds_login_expiration_time (string)" -msgstr "" +msgstr "ldap_user_nds_login_expiration_time (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:390 @@ -16259,7 +16329,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:401 msgid "ldap_user_nds_login_allowed_time_map (string)" -msgstr "" +msgstr "ldap_user_nds_login_allowed_time_map (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:404 @@ -16271,12 +16341,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:409 msgid "Default: loginAllowedTimeMap" -msgstr "" +msgstr "ნაგულისხმევი: loginAllowedTimeMap" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:415 msgid "ldap_user_principal (string)" -msgstr "" +msgstr "ldap_user_principal (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:418 @@ -16288,12 +16358,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:422 msgid "Default: krbPrincipalName" -msgstr "" +msgstr "ნაგულისხმევი: krbPrincipalName" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:428 msgid "ldap_user_extra_attrs (string)" -msgstr "" +msgstr "ldap_user_extra_attrs (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:431 @@ -16324,7 +16394,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:456 msgid "ldap_user_extra_attrs = telephoneNumber" -msgstr "" +msgstr "ldap_user_extra_attrs = telephoneNumber" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:459 @@ -16336,7 +16406,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:463 msgid "ldap_user_extra_attrs = phone:telephoneNumber" -msgstr "" +msgstr "ldap_user_extra_attrs = phone:telephoneNumber" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:466 @@ -16348,7 +16418,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:476 msgid "ldap_user_ssh_public_key (string)" -msgstr "" +msgstr "ldap_user_ssh_public_key (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:479 @@ -16358,12 +16428,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:483 sssd-ldap-attributes.5.xml:965 msgid "Default: sshPublicKey" -msgstr "" +msgstr "ნაგულისხმევი: sshPublicKey" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:489 msgid "ldap_user_fullname (string)" -msgstr "" +msgstr "ldap_user_fullname (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:492 @@ -16373,7 +16443,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:502 msgid "ldap_user_member_of (string)" -msgstr "" +msgstr "ldap_user_member_of (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:505 @@ -16383,12 +16453,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:509 sssd-ldap-attributes.5.xml:952 msgid "Default: memberOf" -msgstr "" +msgstr "ნაგულისხმევი: memberOf" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:515 msgid "ldap_user_authorized_service (string)" -msgstr "" +msgstr "ldap_user_authorized_service (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:518 @@ -16426,12 +16496,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:545 msgid "Default: authorizedService" -msgstr "" +msgstr "ნაგულისხმევი: authorizedService" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:551 msgid "ldap_user_authorized_host (string)" -msgstr "" +msgstr "ldap_user_authorized_host (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:554 @@ -16459,12 +16529,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:572 msgid "Default: host" -msgstr "" +msgstr "ნაგულისხმევი: host" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:578 msgid "ldap_user_authorized_rhost (string)" -msgstr "" +msgstr "ldap_user_authorized_rhost (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:581 @@ -16492,12 +16562,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:600 msgid "Default: rhost" -msgstr "" +msgstr "ნაგულისხმევი: rhost" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:606 msgid "ldap_user_certificate (string)" -msgstr "" +msgstr "ldap_user_certificate (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:609 @@ -16507,12 +16577,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:613 msgid "Default: userCertificate;binary" -msgstr "" +msgstr "ნაგულისხმევი: userCertificate;binary" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:619 msgid "ldap_user_email (string)" -msgstr "" +msgstr "ldap_user_email (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:622 @@ -16533,12 +16603,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:637 msgid "Default: mail" -msgstr "" +msgstr "ნაგულისხმევი: mail" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:642 msgid "ldap_user_passkey (string)" -msgstr "" +msgstr "ldap_user_passkey (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:645 @@ -16558,7 +16628,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:663 msgid "ldap_group_object_class (string)" -msgstr "" +msgstr "ldap_group_object_class (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:666 @@ -16568,12 +16638,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:669 msgid "Default: posixGroup" -msgstr "" +msgstr "ნაგულისხმევი: posixGroup" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:675 msgid "ldap_group_name (string)" -msgstr "" +msgstr "ldap_group_name (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:678 @@ -16587,12 +16657,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:686 msgid "Default: cn (rfc2307, rfc2307bis and IPA), sAMAccountName (AD)" -msgstr "" +msgstr "ნაგულისხმევი: cn (rfc2307, rfc2307bis და IPA), sAMAccountName (AD)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:693 msgid "ldap_group_gid_number (string)" -msgstr "" +msgstr "ldap_group_gid_number (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:696 @@ -16602,7 +16672,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:706 msgid "ldap_group_member (string)" -msgstr "" +msgstr "ldap_group_member (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:709 @@ -16612,12 +16682,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:713 msgid "Default: memberuid (rfc2307) / member (rfc2307bis)" -msgstr "" +msgstr "ნაგულისხმევი: memberuid (rfc2307) / member (rfc2307bis)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:719 msgid "ldap_group_uuid (string)" -msgstr "" +msgstr "ldap_group_uuid (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:722 @@ -16627,7 +16697,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:733 msgid "ldap_group_objectsid (string)" -msgstr "" +msgstr "ldap_group_objectsid (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:736 @@ -16639,12 +16709,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:748 msgid "ldap_group_modify_timestamp (string)" -msgstr "" +msgstr "ldap_group_modify_timestamp (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:761 msgid "ldap_group_type (string)" -msgstr "" +msgstr "ldap_group_type (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:764 @@ -16669,7 +16739,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:782 msgid "ldap_group_external_member (string)" -msgstr "" +msgstr "ldap_group_external_member (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:785 @@ -16691,7 +16761,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:805 msgid "ldap_netgroup_object_class (string)" -msgstr "" +msgstr "ldap_netgroup_object_class (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:808 @@ -16706,12 +16776,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:815 msgid "Default: nisNetgroup" -msgstr "" +msgstr "ნაგულისხმევი: nisNetgroup" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:821 msgid "ldap_netgroup_name (string)" -msgstr "" +msgstr "ldap_netgroup_name (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:824 @@ -16726,7 +16796,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:838 msgid "ldap_netgroup_member (string)" -msgstr "" +msgstr "ldap_netgroup_member (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:841 @@ -16741,12 +16811,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:849 msgid "Default: memberNisNetgroup" -msgstr "" +msgstr "ნაგულისხმევი: memberNisNetgroup" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:855 msgid "ldap_netgroup_triple (string)" -msgstr "" +msgstr "ldap_netgroup_triple (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:858 @@ -16761,12 +16831,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:865 msgid "Default: nisNetgroupTriple" -msgstr "" +msgstr "ნაგულისხმევი: nisNetgroupTriple" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:871 msgid "ldap_netgroup_modify_timestamp (string)" -msgstr "" +msgstr "ldap_netgroup_modify_timestamp (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><title> #: sssd-ldap-attributes.5.xml:890 @@ -16776,7 +16846,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:894 msgid "ldap_host_object_class (string)" -msgstr "" +msgstr "ldap_host_object_class (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:897 @@ -16786,12 +16856,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:900 sssd-ldap-attributes.5.xml:997 msgid "Default: ipService" -msgstr "" +msgstr "ნაგულისხმევი: ipService" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:906 msgid "ldap_host_name (string)" -msgstr "" +msgstr "ldap_host_name (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:909 sssd-ldap-attributes.5.xml:935 @@ -16801,7 +16871,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:919 msgid "ldap_host_fqdn (string)" -msgstr "" +msgstr "ldap_host_fqdn (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:922 @@ -16813,22 +16883,22 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:926 msgid "Default: fqdn" -msgstr "" +msgstr "ნაგულისხმევი: fqdn" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:932 msgid "ldap_host_serverhostname (string)" -msgstr "" +msgstr "ldap_host_serverhostname (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:939 msgid "Default: serverHostname" -msgstr "" +msgstr "ნაგულისხმევი: serverHostname" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:945 msgid "ldap_host_member_of (string)" -msgstr "" +msgstr "ldap_host_member_of (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:948 @@ -16838,7 +16908,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:958 msgid "ldap_host_ssh_public_key (string)" -msgstr "" +msgstr "ldap_host_ssh_public_key (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:961 @@ -16848,7 +16918,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:971 msgid "ldap_host_uuid (string)" -msgstr "" +msgstr "ldap_host_uuid (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:974 @@ -16863,7 +16933,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:991 msgid "ldap_service_object_class (string)" -msgstr "" +msgstr "ldap_service_object_class (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:994 @@ -16873,7 +16943,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1003 msgid "ldap_service_name (string)" -msgstr "" +msgstr "ldap_service_name (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1006 @@ -16885,7 +16955,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1016 msgid "ldap_service_port (string)" -msgstr "" +msgstr "ldap_service_port (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1019 @@ -16895,12 +16965,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1023 msgid "Default: ipServicePort" -msgstr "" +msgstr "ნაგულისხმევი: ipServicePort" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1029 msgid "ldap_service_proto (string)" -msgstr "" +msgstr "ldap_service_proto (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1032 @@ -16910,7 +16980,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1036 msgid "Default: ipServiceProtocol" -msgstr "" +msgstr "ნაგულისხმევი: ipServiceProtocol" #. type: Content of: <reference><refentry><refsect1><title> #: sssd-ldap-attributes.5.xml:1045 @@ -16920,7 +16990,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1049 msgid "ldap_sudorule_object_class (string)" -msgstr "" +msgstr "ldap_sudorule_object_class (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1052 @@ -16930,12 +17000,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1055 msgid "Default: sudoRole" -msgstr "" +msgstr "ნაგულისხმევი: sudoRole" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1061 msgid "ldap_sudorule_name (string)" -msgstr "" +msgstr "ldap_sudorule_name (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1064 @@ -16945,7 +17015,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1074 msgid "ldap_sudorule_command (string)" -msgstr "" +msgstr "ldap_sudorule_command (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1077 @@ -16955,12 +17025,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1081 msgid "Default: sudoCommand" -msgstr "" +msgstr "ნაგულისხმევი: sudoCommand" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1087 msgid "ldap_sudorule_host (string)" -msgstr "" +msgstr "ldap_sudorule_host (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1090 @@ -16972,12 +17042,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1095 msgid "Default: sudoHost" -msgstr "" +msgstr "ნაგულისხმევი: sudoHost" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1101 msgid "ldap_sudorule_user (string)" -msgstr "" +msgstr "ldap_sudorule_user (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1104 @@ -16989,12 +17059,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1108 msgid "Default: sudoUser" -msgstr "" +msgstr "ნაგულისხმევი: sudoUser" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1114 msgid "ldap_sudorule_option (string)" -msgstr "" +msgstr "ldap_sudorule_option (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1117 @@ -17004,12 +17074,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1121 msgid "Default: sudoOption" -msgstr "" +msgstr "ნაგულისხმევი: sudoOption" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1127 msgid "ldap_sudorule_runasuser (string)" -msgstr "" +msgstr "ldap_sudorule_runasuser (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1130 @@ -17021,12 +17091,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1134 msgid "Default: sudoRunAsUser" -msgstr "" +msgstr "ნაგულისხმევი: sudoRunAsUser" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1140 msgid "ldap_sudorule_runasgroup (string)" -msgstr "" +msgstr "ldap_sudorule_runasgroup (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1143 @@ -17038,12 +17108,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1147 msgid "Default: sudoRunAsGroup" -msgstr "" +msgstr "ნაგულისხმევი: sudoRunAsGroup" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1153 msgid "ldap_sudorule_notbefore (string)" -msgstr "" +msgstr "ldap_sudorule_notbefore (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1156 @@ -17055,12 +17125,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1160 msgid "Default: sudoNotBefore" -msgstr "" +msgstr "ნაგულისხმევი: sudoNotBefore" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1166 msgid "ldap_sudorule_notafter (string)" -msgstr "" +msgstr "ldap_sudorule_notafter (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1169 @@ -17072,12 +17142,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1174 msgid "Default: sudoNotAfter" -msgstr "" +msgstr "ნაგულისხმევი: sudoNotAfter" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1180 msgid "ldap_sudorule_order (string)" -msgstr "" +msgstr "ldap_sudorule_order (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1183 @@ -17087,7 +17157,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1187 msgid "Default: sudoOrder" -msgstr "" +msgstr "ნაგულისხმევი: sudoOrder" #. type: Content of: <reference><refentry><refsect1><title> #: sssd-ldap-attributes.5.xml:1196 @@ -17102,7 +17172,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1207 msgid "ldap_iphost_object_class (string)" -msgstr "" +msgstr "ldap_iphost_object_class (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1210 @@ -17112,12 +17182,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1213 msgid "Default: ipHost" -msgstr "" +msgstr "ნაგულისხმევი: ipHost" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1219 msgid "ldap_iphost_name (string)" -msgstr "" +msgstr "ldap_iphost_name (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1222 @@ -17129,7 +17199,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1232 msgid "ldap_iphost_number (string)" -msgstr "" +msgstr "ldap_iphost_number (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1235 @@ -17139,7 +17209,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1239 msgid "Default: ipHostNumber" -msgstr "" +msgstr "ნაგულისხმევი: ipHostNumber" #. type: Content of: <reference><refentry><refsect1><title> #: sssd-ldap-attributes.5.xml:1248 @@ -17149,7 +17219,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1252 msgid "ldap_ipnetwork_object_class (string)" -msgstr "" +msgstr "ldap_ipnetwork_object_class (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1255 @@ -17159,12 +17229,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1258 msgid "Default: ipNetwork" -msgstr "" +msgstr "ნაგულისხმევი: ipNetwork" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1264 msgid "ldap_ipnetwork_name (string)" -msgstr "" +msgstr "ldap_ipnetwork_name (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1267 @@ -17176,7 +17246,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1277 msgid "ldap_ipnetwork_number (string)" -msgstr "" +msgstr "ldap_ipnetwork_number (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1280 @@ -17186,12 +17256,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1284 msgid "Default: ipNetworkNumber" -msgstr "" +msgstr "ნაგულისხმევი: ipNetworkNumber" #. type: Content of: <reference><refentry><refnamediv><refname> #: sssd_krb5_localauth_plugin.8.xml:10 sssd_krb5_localauth_plugin.8.xml:15 msgid "sssd_krb5_localauth_plugin" -msgstr "" +msgstr "sssd_krb5_localauth_plugin" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sssd_krb5_localauth_plugin.8.xml:16 @@ -17230,7 +17300,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><title> #: sssd_krb5_localauth_plugin.8.xml:46 msgid "CONFIGURATION" -msgstr "" +msgstr "კონფიგურაცია" #. type: Content of: <reference><refentry><refsect1><para><programlisting> #: sssd_krb5_localauth_plugin.8.xml:56 @@ -17258,7 +17328,7 @@ msgstr "" #. type: Content of: <variablelist><varlistentry><term> #: include/autofs_attributes.xml:3 msgid "ldap_autofs_map_object_class (string)" -msgstr "" +msgstr "ldap_autofs_map_object_class (სტრიქონი)" #. type: Content of: <variablelist><varlistentry><listitem><para> #: include/autofs_attributes.xml:6 @@ -17273,7 +17343,7 @@ msgstr "" #. type: Content of: <variablelist><varlistentry><term> #: include/autofs_attributes.xml:16 msgid "ldap_autofs_map_name (string)" -msgstr "" +msgstr "ldap_autofs_map_name (სტრიქონი)" #. type: Content of: <variablelist><varlistentry><listitem><para> #: include/autofs_attributes.xml:19 @@ -17290,7 +17360,7 @@ msgstr "" #. type: Content of: <variablelist><varlistentry><term> #: include/autofs_attributes.xml:29 msgid "ldap_autofs_entry_object_class (string)" -msgstr "" +msgstr "ldap_autofs_entry_object_class (სტრიქონი)" #. type: Content of: <variablelist><varlistentry><listitem><para> #: include/autofs_attributes.xml:32 @@ -17307,7 +17377,7 @@ msgstr "" #. type: Content of: <variablelist><varlistentry><term> #: include/autofs_attributes.xml:44 msgid "ldap_autofs_entry_key (string)" -msgstr "" +msgstr "ldap_autofs_entry_key (სტრიქონი)" #. type: Content of: <variablelist><varlistentry><listitem><para> #: include/autofs_attributes.xml:47 include/autofs_attributes.xml:61 @@ -17324,7 +17394,7 @@ msgstr "" #. type: Content of: <variablelist><varlistentry><term> #: include/autofs_attributes.xml:58 msgid "ldap_autofs_entry_value (string)" -msgstr "" +msgstr "ldap_autofs_entry_value (სტრიქონი)" #. type: Content of: <variablelist><varlistentry><listitem><para> #: include/autofs_attributes.xml:65 @@ -17336,7 +17406,7 @@ msgstr "" #. type: Content of: <refsect1><title> #: include/service_discovery.xml:2 msgid "SERVICE DISCOVERY" -msgstr "" +msgstr "სერვისის აღმოჩენა" #. type: Content of: <refsect1><para> #: include/service_discovery.xml:4 @@ -17349,7 +17419,7 @@ msgstr "" #. type: Content of: <refsect1><refsect2><title> #: include/service_discovery.xml:9 include/ldap_id_mapping.xml:99 msgid "Configuration" -msgstr "" +msgstr "კონფიგურაცია" #. type: Content of: <refsect1><refsect2><para> #: include/service_discovery.xml:11 @@ -17366,7 +17436,7 @@ msgstr "" #. type: Content of: <refsect1><refsect2><title> #: include/service_discovery.xml:23 msgid "The domain name" -msgstr "" +msgstr "დომენის სახელი" #. type: Content of: <refsect1><refsect2><para> #: include/service_discovery.xml:25 @@ -17379,7 +17449,7 @@ msgstr "" #. type: Content of: <refsect1><refsect2><title> #: include/service_discovery.xml:35 msgid "The protocol" -msgstr "" +msgstr "პროტოკოლი" #. type: Content of: <refsect1><refsect2><para> #: include/service_discovery.xml:37 @@ -17391,7 +17461,7 @@ msgstr "" #. type: Content of: <refsect1><refsect2><title> #: include/service_discovery.xml:42 msgid "See Also" -msgstr "" +msgstr "ასევე იხილეთ" #. type: Content of: <refsect1><refsect2><para> #: include/service_discovery.xml:44 @@ -17408,12 +17478,12 @@ msgstr "" #. type: Content of: outside any tag (error?) #: include/upstream.xml:1 msgid "<placeholder type=\"refentryinfo\" id=\"0\"/>" -msgstr "" +msgstr "<placeholder type=\"refentryinfo\" id=\"0\"/>" #. type: Content of: <refsect1><title> #: include/failover.xml:2 msgid "FAILOVER" -msgstr "" +msgstr "გადართვა გათიშვისას" #. type: Content of: <refsect1><para> #: include/failover.xml:4 @@ -17503,7 +17573,7 @@ msgstr "" #. type: Content of: <refsect1><refsect2><para><variablelist><varlistentry><term> #: include/failover.xml:76 msgid "dns_resolver_server_timeout" -msgstr "" +msgstr "dns_resolver_server_timeout" #. type: Content of: <refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: include/failover.xml:80 @@ -17515,7 +17585,7 @@ msgstr "" #. type: Content of: <refsect1><refsect2><para><variablelist><varlistentry><term> #: include/failover.xml:90 msgid "dns_resolver_op_timeout" -msgstr "" +msgstr "dns_resolver_op_timeout" #. type: Content of: <refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: include/failover.xml:94 @@ -17528,7 +17598,7 @@ msgstr "" #. type: Content of: <refsect1><refsect2><para><variablelist><varlistentry><term> #: include/failover.xml:106 msgid "dns_resolver_timeout" -msgstr "" +msgstr "dns_resolver_timeout" #. type: Content of: <refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: include/failover.xml:110 @@ -17698,12 +17768,12 @@ msgstr "" #. type: Content of: <refsect1><refsect2><refsect3><title> #: include/ldap_id_mapping.xml:117 msgid "Advanced Configuration" -msgstr "" +msgstr "დამატებითი პარამეტრები" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><term> #: include/ldap_id_mapping.xml:120 msgid "ldap_idmap_range_min (integer)" -msgstr "" +msgstr "ldap_idmap_range_min (მთელი რიცხვი)" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> #: include/ldap_id_mapping.xml:123 @@ -17727,7 +17797,7 @@ msgstr "" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><term> #: include/ldap_id_mapping.xml:144 msgid "ldap_idmap_range_max (integer)" -msgstr "" +msgstr "ldap_idmap_range_max (მთელი რიცხვი)" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> #: include/ldap_id_mapping.xml:147 @@ -17752,7 +17822,7 @@ msgstr "" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><term> #: include/ldap_id_mapping.xml:170 msgid "ldap_idmap_range_size (integer)" -msgstr "" +msgstr "ldap_idmap_range_size (მთელი რიცხვი)" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> #: include/ldap_id_mapping.xml:173 @@ -17790,7 +17860,7 @@ msgstr "" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><term> #: include/ldap_id_mapping.xml:202 msgid "ldap_idmap_default_domain_sid (string)" -msgstr "" +msgstr "ldap_idmap_default_domain_sid (სტრიქონი)" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> #: include/ldap_id_mapping.xml:205 @@ -17803,7 +17873,7 @@ msgstr "" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><term> #: include/ldap_id_mapping.xml:216 msgid "ldap_idmap_default_domain (string)" -msgstr "" +msgstr "ldap_idmap_default_domain (სტრიქონი)" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> #: include/ldap_id_mapping.xml:219 @@ -17813,7 +17883,7 @@ msgstr "" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><term> #: include/ldap_id_mapping.xml:227 msgid "ldap_idmap_autorid_compat (boolean)" -msgstr "" +msgstr "ldap_idmap_autorid_compat (ლოგიკური)" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> #: include/ldap_id_mapping.xml:230 @@ -17842,7 +17912,7 @@ msgstr "" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><term> #: include/ldap_id_mapping.xml:255 msgid "ldap_idmap_helper_table_size (integer)" -msgstr "" +msgstr "ldap_idmap_helper_table_size (მთელი რიცხვი)" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> #: include/ldap_id_mapping.xml:258 @@ -17919,7 +17989,7 @@ msgstr "" #. type: Content of: <refsect1><refsect2><para><itemizedlist><listitem><para> #: include/ldap_id_mapping.xml:297 msgid "Built-in" -msgstr "" +msgstr "ჩაშენებული" #. type: Content of: <refsect1><refsect2><para> #: include/ldap_id_mapping.xml:299 @@ -17945,7 +18015,7 @@ msgstr "" #. type: Content of: <varlistentry><term> #: include/param_help.xml:3 msgid "<option>-?</option>,<option>--help</option>" -msgstr "" +msgstr "<option>-?</option>,<option>--help</option>" #. type: Content of: <varlistentry><listitem><para> #: include/param_help.xml:7 include/param_help_py.xml:7 @@ -17955,7 +18025,7 @@ msgstr "" #. type: Content of: <varlistentry><term> #: include/param_help_py.xml:3 msgid "<option>-h</option>,<option>--help</option>" -msgstr "" +msgstr "<option>-h</option>,<option>--help</option>" #. type: Content of: <listitem><para> #: include/debug_levels.xml:3 include/debug_levels_tools.xml:3 @@ -18197,12 +18267,12 @@ msgstr "" #: include/ldap_search_bases.xml:9 #, no-wrap msgid "search_base[?scope?[filter][?search_base?scope?[filter]]*]\n" -msgstr "" +msgstr "search_base[?scope?[filter][?search_base?scope?[filter]]*]\n" #. type: Content of: <listitem><para> #: include/ldap_search_bases.xml:7 msgid "syntax: <placeholder type=\"programlisting\" id=\"0\"/>" -msgstr "" +msgstr "სინტაქსი: <placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <listitem><para> #: include/ldap_search_bases.xml:13 @@ -18238,12 +18308,12 @@ msgstr "" #. type: Content of: <varlistentry><term> #: include/override_homedir.xml:2 msgid "override_homedir (string)" -msgstr "" +msgstr "override_homedir (სტრიქონი)" #. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: include/override_homedir.xml:16 msgid "UID number" -msgstr "" +msgstr "UID-ის ნომერი" #. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: include/override_homedir.xml:20 @@ -18253,7 +18323,7 @@ msgstr "" #. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><term> #: include/override_homedir.xml:23 msgid "%f" -msgstr "" +msgstr "%f" #. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: include/override_homedir.xml:24 @@ -18263,7 +18333,7 @@ msgstr "" #. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><term> #: include/override_homedir.xml:27 msgid "%l" -msgstr "" +msgstr "%l" #. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: include/override_homedir.xml:28 @@ -18278,7 +18348,7 @@ msgstr "" #. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><term> #: include/override_homedir.xml:35 msgid "%o" -msgstr "" +msgstr "%o" #. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: include/override_homedir.xml:38 @@ -18306,7 +18376,7 @@ msgstr "" #. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><term> #: include/override_homedir.xml:61 msgid "%H" -msgstr "" +msgstr "%H" #. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: include/override_homedir.xml:63 @@ -18324,7 +18394,7 @@ msgstr "" #. type: Content of: <varlistentry><listitem><para> #: include/override_homedir.xml:75 msgid "This option can also be set per-domain." -msgstr "" +msgstr "This option can also be set per-domain." #. type: Content of: <varlistentry><listitem><para><programlisting> #: include/override_homedir.xml:80 @@ -18353,7 +18423,7 @@ msgstr "" #. type: Content of: <varlistentry><term> #: include/homedir_substring.xml:2 msgid "homedir_substring (string)" -msgstr "" +msgstr "homedir_substring (სტრიქონი)" #. type: Content of: <varlistentry><listitem><para> #: include/homedir_substring.xml:5 @@ -18370,7 +18440,7 @@ msgstr "" #. type: Content of: <varlistentry><listitem><para> #: include/homedir_substring.xml:15 msgid "Default: /home" -msgstr "" +msgstr "ნაგულისხმევი: /home" #. type: Content of: <refsect1><title> #: include/ad_modified_defaults.xml:2 include/ipa_modified_defaults.xml:2 @@ -18393,12 +18463,12 @@ msgstr "" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ad_modified_defaults.xml:13 include/ipa_modified_defaults.xml:13 msgid "krb5_validate = true" -msgstr "" +msgstr "krb5_validate = true" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ad_modified_defaults.xml:18 msgid "krb5_use_enterprise_principal = true" -msgstr "" +msgstr "krb5_use_enterprise_principal = true" #. type: Content of: <refsect1><refsect2><title> #: include/ad_modified_defaults.xml:24 @@ -18408,37 +18478,37 @@ msgstr "" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ad_modified_defaults.xml:28 msgid "ldap_schema = ad" -msgstr "" +msgstr "ldap_schema = ad" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ad_modified_defaults.xml:33 include/ipa_modified_defaults.xml:38 msgid "ldap_force_upper_case_realm = true" -msgstr "" +msgstr "ldap_force_upper_case_realm = true" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ad_modified_defaults.xml:38 msgid "ldap_id_mapping = true" -msgstr "" +msgstr "ldap_id_mapping = true" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ad_modified_defaults.xml:43 msgid "ldap_sasl_mech = GSS-SPNEGO" -msgstr "" +msgstr "ldap_sasl_mech = GSS-SPNEGO" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ad_modified_defaults.xml:48 msgid "ldap_referrals = false" -msgstr "" +msgstr "ldap_referrals = false" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ad_modified_defaults.xml:53 msgid "ldap_account_expire_policy = ad" -msgstr "" +msgstr "ldap_account_expire_policy = ad" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ad_modified_defaults.xml:58 include/ipa_modified_defaults.xml:58 msgid "ldap_use_tokengroups = true" -msgstr "" +msgstr "ldap_use_tokengroups = true" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ad_modified_defaults.xml:63 @@ -18460,12 +18530,12 @@ msgstr "" #. type: Content of: <refsect1><refsect2><title> #: include/ad_modified_defaults.xml:80 msgid "NSS configuration" -msgstr "" +msgstr "NSS-ის მორგება" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ad_modified_defaults.xml:84 msgid "fallback_homedir = /home/%d/%u" -msgstr "" +msgstr "fallback_homedir = /home/%d/%u" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ad_modified_defaults.xml:87 @@ -18504,12 +18574,12 @@ msgstr "" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ipa_modified_defaults.xml:18 msgid "krb5_use_fast = try" -msgstr "" +msgstr "krb5_use_fast = try" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ipa_modified_defaults.xml:23 msgid "krb5_canonicalize = true" -msgstr "" +msgstr "krb5_canonicalize = true" #. type: Content of: <refsect1><refsect2><title> #: include/ipa_modified_defaults.xml:29 @@ -18519,47 +18589,47 @@ msgstr "" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ipa_modified_defaults.xml:33 msgid "ldap_schema = ipa_v1" -msgstr "" +msgstr "ldap_schema = ipa_v1" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ipa_modified_defaults.xml:43 msgid "ldap_sasl_mech = GSSAPI" -msgstr "" +msgstr "ldap_sasl_mech = GSSAPI" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ipa_modified_defaults.xml:48 msgid "ldap_sasl_minssf = 56" -msgstr "" +msgstr "ldap_sasl_minssf = 56" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ipa_modified_defaults.xml:53 msgid "ldap_account_expire_policy = ipa" -msgstr "" +msgstr "ldap_account_expire_policy = ipa" #. type: Content of: <refsect1><refsect2><title> #: include/ipa_modified_defaults.xml:64 msgid "LDAP Provider - User options" -msgstr "" +msgstr "LDAP Provider - User options" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ipa_modified_defaults.xml:68 msgid "ldap_user_member_of = memberOf" -msgstr "" +msgstr "ldap_user_member_of = memberOf" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ipa_modified_defaults.xml:73 msgid "ldap_user_uuid = ipaUniqueID" -msgstr "" +msgstr "ldap_user_uuid = ipaUniqueID" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ipa_modified_defaults.xml:78 msgid "ldap_user_ssh_public_key = ipaSshPubKey" -msgstr "" +msgstr "ldap_user_ssh_public_key = ipaSshPubKey" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ipa_modified_defaults.xml:83 msgid "ldap_user_auth_type = ipaUserAuthType" -msgstr "" +msgstr "ldap_user_auth_type = ipaUserAuthType" #. type: Content of: <refsect1><refsect2><title> #: include/ipa_modified_defaults.xml:89 @@ -18569,37 +18639,37 @@ msgstr "" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ipa_modified_defaults.xml:93 msgid "ldap_group_object_class = ipaUserGroup" -msgstr "" +msgstr "ldap_group_object_class = ipaUserGroup" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ipa_modified_defaults.xml:98 msgid "ldap_group_object_class_alt = posixGroup" -msgstr "" +msgstr "ldap_group_object_class_alt = posixGroup" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ipa_modified_defaults.xml:103 msgid "ldap_group_member = member" -msgstr "" +msgstr "ldap_group_member = member" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ipa_modified_defaults.xml:108 msgid "ldap_group_uuid = ipaUniqueID" -msgstr "" +msgstr "ldap_group_uuid = ipaUniqueID" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ipa_modified_defaults.xml:113 msgid "ldap_group_objectsid = ipaNTSecurityIdentifier" -msgstr "" +msgstr "ldap_group_objectsid = ipaNTSecurityIdentifier" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ipa_modified_defaults.xml:118 msgid "ldap_group_external_member = ipaExternalMember" -msgstr "" +msgstr "ldap_group_external_member = ipaExternalMember" #. type: Content of: <variablelist><varlistentry><term> #: include/krb5_options.xml:3 msgid "krb5_auth_timeout (integer)" -msgstr "" +msgstr "krb5_auth_timeout (მთელი რიცხვი)" #. type: Content of: <variablelist><varlistentry><listitem><para> #: include/krb5_options.xml:6 @@ -18643,7 +18713,7 @@ msgstr "" #. type: Content of: <variablelist><varlistentry><term> #: include/krb5_options.xml:44 msgid "krb5_renewable_lifetime (string)" -msgstr "" +msgstr "krb5_renewable_lifetime (სტრიქონი)" #. type: Content of: <variablelist><varlistentry><listitem><para> #: include/krb5_options.xml:47 @@ -18696,7 +18766,7 @@ msgstr "" #. type: Content of: <variablelist><varlistentry><term> #: include/krb5_options.xml:79 msgid "krb5_lifetime (string)" -msgstr "" +msgstr "krb5_lifetime (სტრიქონი)" #. type: Content of: <variablelist><varlistentry><listitem><para> #: include/krb5_options.xml:82 @@ -18725,7 +18795,7 @@ msgstr "" #. type: Content of: <variablelist><varlistentry><term> #: include/krb5_options.xml:114 msgid "krb5_renew_interval (string)" -msgstr "" +msgstr "krb5_renew_interval (სტრიქონი)" #. type: Content of: <variablelist><varlistentry><listitem><para> #: include/krb5_options.xml:117 diff --git a/src/man/po/ko.po b/src/man/po/ko.po index 0b0476671e1..97d61364c40 100644 --- a/src/man/po/ko.po +++ b/src/man/po/ko.po @@ -8,7 +8,7 @@ msgstr "" "Project-Id-Version: sssd-docs 2.5.2\n" "Report-Msgid-Bugs-To: sssd-devel@redhat.com\n" "POT-Creation-Date: 2021-07-12 20:51+0200\n" -"PO-Revision-Date: 2026-04-23 16:36+0000\n" +"PO-Revision-Date: 2026-10-05 17:12+0000\n" "Last-Translator: seo hojin <jinswhat@naver.com>\n" "Language-Team: Korean <https://translate.fedoraproject.org/projects/sssd/" "sssd-manpage-master/ko/>\n" @@ -17,7 +17,7 @@ msgstr "" "Content-Type: text/plain; charset=UTF-8\n" "Content-Transfer-Encoding: 8bit\n" "Plural-Forms: nplurals=1; plural=0;\n" -"X-Generator: Weblate 5.17\n" +"X-Generator: Weblate 2026.10\n" #. type: Content of: <reference><title> #: sss_groupmod.8.xml:5 sssd.conf.5.xml:5 sssd-ldap.5.xml:5 pam_sss.8.xml:5 @@ -755,6 +755,13 @@ msgid "" "permissions may result in a non-usable SSSD. The same may occur in case of " "changes of the user running the NSS responder. </phrase>" msgstr "" +"root 사용자로 실행하지 않도록 적절한 경우 권한을 낮출 사용자입니다. <phrase " +"condition=\"have_systemd\"> 이 옵션은 소켓 활성화 서비스를 실행할 때 " +"작동하지 않습니다. 프로세스를 실행하도록 설정된 사용자는 컴파일 시점에 " +"설정되기 때문입니다. systemd 단위 파일을 재정의하는 방법은 /etc/systemd/" +"system/에 적절한 파일을 만드는 것입니다. 소켓 사용자, 그룹 또는 권한을 " +"변경하면 SSSD를 사용할 수 없게 될 수 있습니다. NSS 응답자를 실행하는 " +"사용자를 변경하는 경우에도 동일한 문제가 발생할 수 있습니다. </phrase>" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:427 @@ -775,11 +782,10 @@ msgid "" "trusted domain. The option allows those users to log in just with their " "user name without giving a domain name as well." msgstr "" -"이와 같은 문자열은 도메인 이름 구성이 없는 모든 이름을 위해 기본 도메인 " -"이름으로 사용됩니다. 주요 사용 경우는 기본 도메인이 호스트 정책을 관리하고 " -"모든 사용자가 신뢰 할 수 있는 도메인에 있는 환경입니다. 이와 같은 옵션을 " -"사용하면 해당 사용자는 도메인 이름도 제공하지 않고 이들 사용자 이름만으로 " -"로그인 할 수 있습니다." +"이 문자열은 도메인 이름 구성 요소가 없는 모든 이름의 기본 도메인 이름으로 " +"사용됩니다. 주요 사용 사례는 기본 도메인이 호스트 정책 관리를 목적으로 하고 " +"모든 사용자가 신뢰할 수 있는 도메인에 있는 환경입니다. 이 옵션을 사용하면 " +"해당 사용자가 도메인 이름 없이 사용자 이름만으로 로그인할 수 있습니다." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:445 @@ -793,6 +799,13 @@ msgid "" "nss_files and therefore their output is not qualified even when the " "default_domain_suffix option is used." msgstr "" +"이 옵션이 설정되면 기본 도메인의 모든 사용자가 로그인 시 정규화된 이름(예: " +"user@domain.name)을 사용해야 합니다. 이 옵션을 설정하면 " +"use_fully_qualified_names의 기본값이 True로 변경됩니다. 이 옵션은 " +"use_fully_qualified_names가 False로 설정된 경우와 함께 사용할 수 없습니다. " +"이 규칙의 한 가지 예외는 <quote>id_provider=files</quote>인 도메인으로, 항상 " +"nss_files의 동작을 따르려 하기 때문에 default_domain_suffix 옵션을 " +"사용하더라도 출력이 정규화되지 않습니다." #. type: Content of: <variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:460 sssd-ldap.5.xml:772 sssd-ldap.5.xml:784 @@ -1001,6 +1014,9 @@ msgid "" "the related certificates. This option should be used to allow authentication " "when the system is offline and the CRL cannot be renewed." msgstr "" +"인증서 폐기 목록(CRL)이 만료된 경우 관련 인증서의 CRL 점검을 무시합니다. 이 " +"옵션은 시스템이 오프라인이고 CRL을 갱신할 수 없을 때 인증을 허용하기 위해 " +"사용해야 합니다." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:493 @@ -1062,6 +1078,8 @@ msgid "" "When this option is enabled, SSSD prepends an implicit domain with " "<quote>id_provider=files</quote> before any explicitly configured domains." msgstr "" +"이 옵션이 활성화되면 SSSD는 명시적으로 구성된 도메인 앞에 <quote>" +"id_provider=files</quote>를 사용하는 암묵적 도메인을 추가합니다." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:652 @@ -1078,11 +1096,11 @@ msgid "" "subdomains which are not listed as part of <quote>lookup_order</quote> will " "be looked up in a random order for each parent domain." msgstr "" -"따라야 할 조회 순서를 나타내는 쉼표로 구분된 도메인 및 하위 도메인의 목록. " -"목록은 누락된 도메인이 <quote>domains</quote> 구성에서 제공된 순서에 " -"기반하여 조회되는 모든 가능한 도메인을 포함하지 않아도 됩니다. <quote>" -"lookup_order</quote> 의 부분으로 나열되지 않은 하위 도메인은 각 상위 " -"도메인을 위해 무작위 순서로 조회됩니다." +"따라야 할 조회 순서를 나타내는 쉼표로 구분된 도메인 및 하위 도메인의 " +"목록입니다. 목록에 모든 가능한 도메인을 포함할 필요는 없습니다. 누락된 " +"도메인은 <quote>domains</quote> 구성 옵션에 표시된 순서에 따라 조회됩니다. " +"<quote>lookup_order</quote>의 일부로 나열되지 않은 하위 도메인은 각 상위 " +"도메인에 대해 임의의 순서로 조회됩니다." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:667 @@ -1100,6 +1118,16 @@ msgid "" "shortnames, making this workaround totally not recommended in cases where " "usernames may overlap between domains." msgstr "" +"이 옵션이 설정되면 파일 공급자가 관리하는 사용자를 제외한 모든 사용자에 대해 " +"입력에 짧은 이름을 사용하더라도 항상 모든 명령의 출력 형식이 정규화됩니다. " +"관리자가 출력을 정규화하지 않으려는 경우 다음과 같이 full_name_format 옵션을 " +"사용할 수 있습니다: <quote>full_name_format=%1$s</quote> 하지만 로그인 중에 " +"로그인 응용 프로그램이 <citerefentry> <refentrytitle>getpwnam</" +"refentrytitle> <manvolnum>3</manvolnum> </citerefentry>을 호출하여 사용자 " +"이름을 정규화하는 경우, 정규화된 입력에 대해 짧은 이름이 반환되면(여러 " +"도메인에 존재하는 사용자에 접근하려는 시도 중) 로그인 시도가 짧은 이름을 " +"사용하는 도메인으로 재라우팅될 수 있으므로, 사용자 이름이 도메인 간에 겹칠 " +"수 있는 경우에는 이 해결 방법을 사용하지 않는 것이 좋습니다." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:692 sssd.conf.5.xml:1659 sssd.conf.5.xml:3927 @@ -1117,6 +1145,11 @@ msgid "" "some other important options like the identity domains. <placeholder type=" "\"variablelist\" id=\"0\"/>" msgstr "" +"SSSD의 개별 기능은 SSSD와 함께 시작 및 종료되는 특수 SSSD 서비스에 의해 " +"제공됩니다. 이 서비스들은 흔히 <quote>모니터</quote>라고 불리는 특수 " +"서비스에 의해 관리됩니다. <quote>[sssd]</quote> 섹션은 모니터 설정뿐만 " +"아니라 ID 도메인과 같은 다른 중요한 옵션을 구성하는 데 사용됩니다. " +"<placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><title> #: sssd.conf.5.xml:703 @@ -1131,6 +1164,9 @@ msgid "" "section, for example, for NSS service, the section would be <quote>[nss]</" "quote>" msgstr "" +"다양한 서비스를 구성하는 데 사용할 수 있는 설정이 이 섹션에 설명되어 " +"있습니다. [<replaceable>$NAME</replaceable>] 섹션에 위치해야 합니다. 예를 " +"들어 NSS 서비스의 경우 <quote>[nss]</quote> 섹션이 됩니다" #. type: Content of: <reference><refentry><refsect1><refsect2><title> #: sssd.conf.5.xml:712 @@ -1156,6 +1192,10 @@ msgid "" "systems without this capability, the resulting value will be the lower value " "of this or the limits.conf \"hard\" limit." msgstr "" +"이 옵션은 이 SSSD 프로세스가 한 번에 열 수 있는 최대 파일 설명자 수를 " +"지정합니다. SSSD에 CAP_SYS_RESOURCE 기능이 부여된 시스템에서는 절대적인 " +"설정입니다. 이 기능이 없는 시스템에서는 이 값과 limits.conf의 \"hard\" 제한 " +"중 낮은 값이 결과값으로 사용됩니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:743 @@ -1176,6 +1216,10 @@ msgid "" "can't be shorter than 10 seconds. If a lower value is configured, it will be " "adjusted to 10 seconds." msgstr "" +"이 옵션은 SSSD 프로세스의 클라이언트가 통신하지 않고 파일 설명자를 유지할 수 " +"있는 시간(초)을 지정합니다. 이 값은 시스템의 리소스 고갈을 방지하기 위해 " +"제한됩니다. 시간 초과는 10초보다 짧을 수 없습니다. 더 낮은 값을 구성하면 " +"10초로 조정됩니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:760 @@ -1197,6 +1241,11 @@ msgid "" "time for the previous ones. After each unsuccessful attempt to go online, " "the new interval is recalculated by the following:" msgstr "" +"SSSD가 오프라인 모드로 전환되면 다시 온라인으로 돌아가기 전의 시간이 연결이 " +"끊긴 시간에 따라 증가합니다. 기본적으로 SSSD는 증분 방식을 사용하여 재시도 " +"사이의 지연을 계산합니다. 따라서 주어진 재시도의 대기 시간은 이전 재시도의 " +"대기 시간보다 깁니다. 온라인 전환에 실패할 때마다 새 간격은 다음 공식으로 " +"다시 계산됩니다:" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:779 sssd.conf.5.xml:835 @@ -1214,6 +1263,9 @@ msgid "" "value is 3600. The offline_timeout_random_offset default value is 30. The " "end result is amount of seconds before next retry." msgstr "" +"offline_timeout 기본값은 60입니다. offline_timeout_max 기본값은 " +"3600입니다. offline_timeout_random_offset 기본값은 30입니다. 최종 결과는 " +"다음 재시도 전까지의 시간(초)입니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:788 @@ -1221,6 +1273,8 @@ msgid "" "Note that the maximum length of each interval is defined by " "offline_timeout_max (apart of random part)." msgstr "" +"각 간격의 최대 길이는 offline_timeout_max에 의해 정의됩니다(무작위 부분 제외)" +"." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:792 sssd.conf.5.xml:1132 sssd.conf.5.xml:1486 @@ -1239,6 +1293,8 @@ msgid "" "Controls by how much the time between attempts to go online can be " "incremented following unsuccessful attempts to go online." msgstr "" +"온라인 전환에 실패한 후 온라인 전환 시도 사이의 시간을 얼마나 증가시킬 " +"것인지 제어합니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:805 @@ -1250,7 +1306,7 @@ msgstr "0의 값은 동작을 비활성화 합니다." msgid "" "The value of this parameter should be set in correlation to offline_timeout " "parameter value." -msgstr "" +msgstr "이 매개변수의 값은 offline_timeout 매개변수 값과 연관하여 설정해야 합니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:812 @@ -1260,6 +1316,9 @@ msgid "" "rule here should be to set offline_timeout_max to at least 4 times " "offline_timeout." msgstr "" +"offline_timeout이 60(기본값)으로 설정된 경우 offline_timeout_max를 120 " +"미만으로 설정하면 즉시 포화 상태가 되므로 의미가 없습니다. 일반적인 규칙은 " +"offline_timeout_max를 offline_timeout의 최소 4배로 설정하는 것입니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:818 @@ -1267,6 +1326,8 @@ msgid "" "Although a value between 0 and offline_timeout may be specified, it has the " "effect of overriding the offline_timeout value so is of little use." msgstr "" +"0과 offline_timeout 사이의 값을 지정할 수 있지만, offline_timeout 값을 " +"재정의하는 효과가 있으므로 실질적인 의미가 거의 없습니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:823 @@ -1293,6 +1354,8 @@ msgid "" "This parameter controls the value of the random offset used for the above " "equation. Final random_offset value will be random number in range:" msgstr "" +"이 매개변수는 위 수식에 사용되는 무작위 오프셋의 값을 제어합니다. 최종 " +"random_offset 값은 다음 범위의 무작위 수가 됩니다:" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:843 @@ -1325,6 +1388,11 @@ msgid "" "built with systemd support and when services are either socket or D-Bus " "activated." msgstr "" +"이 옵션은 SSSD 응답자 프로세스가 사용되지 않은 채로 유지될 수 있는 시간(초)" +"을 지정합니다. 이 값은 시스템의 리소스 고갈을 방지하기 위해 제한됩니다. 이 " +"옵션의 최소 허용 값은 60초입니다. 이 옵션을 0(영)으로 설정하면 응답자에 " +"시간 초과가 설정되지 않습니다. 이 옵션은 SSSD가 systemd 지원으로 빌드되고 " +"서비스가 소켓 또는 D-Bus로 활성화된 경우에만 효과가 있습니다." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:871 sssd.conf.5.xml:1145 sssd.conf.5.xml:2187 @@ -1343,6 +1411,8 @@ msgid "" "This option specifies whether the responder should query all caches before " "querying the Data Providers." msgstr "" +"이 옵션은 응답자가 자료 공급자를 질의하기 전에 모든 캐시를 질의해야 하는지 " +"여부를 지정합니다." #. type: Content of: <reference><refentry><refsect1><refsect2><title> #: sssd.conf.5.xml:891 @@ -1365,7 +1435,7 @@ msgstr "enum_cache_timeout (정수)" msgid "" "How many seconds should nss_sss cache enumerations (requests for info about " "all users)" -msgstr "nss_sss 캐쉬가 열거된 시간(초) (모든 사용자에 대한 정보를 위한 요청)" +msgstr "nss_sss가 열거(모든 사용자에 대한 정보 요청)를 캐시해야 하는 시간(초)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:905 @@ -1397,6 +1467,10 @@ msgid "" "but the SSSD will go and update the cache on its own, so that future " "requests will not need to block waiting for a cache update." msgstr "" +"예를 들어, 도메인의 entry_cache_timeout이 30초로 설정되고 " +"entry_cache_nowait_percentage가 50(퍼센트)로 설정된 경우, 마지막 캐시 " +"업데이트 후 15초 이후에 들어오는 항목은 즉시 반환되지만, SSSD가 독자적으로 " +"캐시를 업데이트하므로 향후 요청이 캐시 업데이트를 기다리며 차단되지 않습니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:929 @@ -1406,6 +1480,9 @@ msgid "" "percentage will never reduce the nowait timeout to less than 10 seconds. (0 " "disables this feature)" msgstr "" +"이 옵션의 유효한 값은 0-99이며 각 도메인의 entry_cache_timeout 백분율을 " +"나타냅니다. 성능상의 이유로 이 백분율은 nowait 시간 초과를 10초 미만으로 " +"줄이지 않습니다. (0은 이 기능을 비활성화합니다)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:937 sssd.conf.5.xml:1987 @@ -1424,6 +1501,9 @@ msgid "" "(that is, queries for invalid database entries, like nonexistent ones) " "before asking the back end again." msgstr "" +"nss_sss가 백엔드에 다시 요청하기 전에 네거티브 캐시 적중(존재하지 않는 것과 " +"같은 잘못된 데이터베이스 항목에 대한 조회)을 캐시해야 하는 시간(초)을 " +"지정합니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:951 sssd.conf.5.xml:2011 @@ -1442,6 +1522,9 @@ msgid "" "negative cache before trying to look it up in the back end again. Setting " "the option to 0 disables this feature." msgstr "" +"nss_sss가 백엔드에서 다시 조회를 시도하기 전에 로컬 사용자 및 그룹을 " +"네거티브 캐시에 유지해야 하는 시간(초)을 지정합니다. 이 옵션을 0으로 " +"설정하면 이 기능이 비활성화됩니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:965 @@ -1461,6 +1544,10 @@ msgid "" "also be set per-domain or include fully-qualified names to filter only users " "from the particular domain or by a user principal name (UPN)." msgstr "" +"sss NSS 데이터베이스에서 특정 사용자 또는 그룹을 가져오지 않도록 제외합니다. " +"시스템 계정에 특히 유용합니다. 이 옵션은 도메인별로 설정하거나 정규화된 " +"이름을 포함하여 특정 도메인의 사용자만 또는 사용자 주체 이름(UPN)으로 " +"필터링할 수도 있습니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:981 @@ -1470,6 +1557,10 @@ msgid "" "NSS. E.g. a group having a member group filtered out will still have the " "member users of the latter listed." msgstr "" +"참고: filter_groups 옵션은 중첩된 그룹 구성원의 상속에 영향을 주지 않습니다. " +"필터링은 NSS를 통해 반환하기 위해 전파된 후에 이루어지기 때문입니다. 예를 " +"들어 구성원 그룹이 필터링된 그룹에도 해당 그룹의 구성원 사용자가 여전히 " +"나열됩니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:989 @@ -1500,6 +1591,8 @@ msgid "" "Set a default template for a user's home directory if one is not specified " "explicitly by the domain's data provider." msgstr "" +"도메인의 자료 공급자가 명시적으로 지정하지 않은 경우 사용자의 홈 디렉토리에 " +"대한 기본 템플릿을 설정합니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1016 @@ -1542,6 +1635,8 @@ msgid "" "shell options if it takes effect and can be set either in the [nss] section " "or per-domain." msgstr "" +"모든 사용자의 로그인 쉘을 재정의합니다. 이 옵션이 적용되면 다른 모든 쉘 " +"옵션보다 우선하며 [nss] 섹션 또는 도메인별로 설정할 수 있습니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1041 @@ -1557,12 +1652,12 @@ msgstr "allowed_shells (문자열)" #: sssd.conf.5.xml:1050 msgid "" "Restrict user shell to one of the listed values. The order of evaluation is:" -msgstr "" +msgstr "사용자 쉘을 나열된 값 중 하나로 제한합니다. 평가 순서는 다음과 같습니다:" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1053 msgid "1. If the shell is present in <quote>/etc/shells</quote>, it is used." -msgstr "" +msgstr "1. 쉘이 <quote>/etc/shells</quote>에 있으면 해당 쉘이 사용됩니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1057 @@ -1570,6 +1665,8 @@ msgid "" "2. If the shell is in the allowed_shells list but not in <quote>/etc/shells</" "quote>, use the value of the shell_fallback parameter." msgstr "" +"2. 쉘이 allowed_shells 목록에는 있지만 <quote>/etc/shells</quote>에는 " +"없으면, shell_fallback 매개변수의 값을 사용합니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1062 @@ -1577,6 +1674,8 @@ msgid "" "3. If the shell is not in the allowed_shells list and not in <quote>/etc/" "shells</quote>, a nologin shell is used." msgstr "" +"3. 쉘이 allowed_shells 목록에도 없고 <quote>/etc/shells</quote>에도 없으면, " +"nologin 쉘이 사용됩니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1067 @@ -1590,6 +1689,9 @@ msgid "" "shell is not in <quote>/etc/shells</quote> and maintaining list of all " "allowed shells in allowed_shells would be to much overhead." msgstr "" +"(*)는 사용자의 쉘이 <quote>/etc/shells</quote>에 없을 때 shell_fallback을 " +"사용하려는 경우에 유용하며, allowed_shells에 모든 허용된 쉘 목록을 유지하는 " +"것이 부담스러울 때 사용합니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1077 @@ -1602,6 +1704,8 @@ msgid "" "The <quote>/etc/shells</quote> is only read on SSSD start up, which means " "that a restart of the SSSD is required in case a new shell is installed." msgstr "" +"<quote>/etc/shells</quote>는 SSSD 시작 시에만 읽히므로, 새 쉘이 설치된 경우 " +"SSSD를 다시 시작해야 합니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1084 @@ -1645,6 +1749,8 @@ msgid "" "The default shell to use if the provider does not return one during lookup. " "This option can be specified globally in the [nss] section or per-domain." msgstr "" +"공급자가 조회 중 쉘을 반환하지 않는 경우 사용할 기본 쉘입니다. 이 옵션은 " +"[nss] 섹션에서 전역적으로 또는 도메인별로 지정할 수 있습니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1118 @@ -1652,6 +1758,8 @@ msgid "" "Default: not set (Return NULL if no shell is specified and rely on libc to " "substitute something sensible when necessary, usually /bin/sh)" msgstr "" +"기본값: 설정되지 않음(쉘을 지정하지 않으면 NULL을 반환하고 필요 시 libc가 " +"적절한 값으로 대체하도록 합니다. 보통 /bin/sh)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1125 sssd.conf.5.xml:1479 @@ -1676,6 +1784,8 @@ msgid "" "Specifies time in seconds for which records in the in-memory cache will be " "valid. Setting this option to zero will disable the in-memory cache." msgstr "" +"메모리 내 캐시의 레코드가 유효한 시간(초)을 지정합니다. 이 옵션을 0으로 " +"설정하면 메모리 내 캐시가 비활성화됩니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1148 @@ -1683,6 +1793,8 @@ msgid "" "WARNING: Disabling the in-memory cache will have significant negative impact " "on SSSD's performance and should only be used for testing." msgstr "" +"경고: 메모리 내 캐시를 비활성화하면 SSSD 성능에 심각한 부정적인 영향을 " +"미치며 테스트 목적으로만 사용해야 합니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1154 sssd.conf.5.xml:1179 sssd.conf.5.xml:1204 @@ -1691,6 +1803,8 @@ msgid "" "NOTE: If the environment variable SSS_NSS_USE_MEMCACHE is set to \"NO\", " "client applications will not use the fast in-memory cache." msgstr "" +"참고: 환경 변수 SSS_NSS_USE_MEMCACHE가 \"NO\"로 설정된 경우, 클라이언트 응용 " +"프로그램은 빠른 메모리 내 캐시를 사용하지 않습니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1162 @@ -1704,6 +1818,8 @@ msgid "" "for passwd requests. Setting the size to 0 will disable the passwd in-" "memory cache." msgstr "" +"passwd 요청을 위해 빠른 캐쉬 메모리 내에 할당된 자료 테이블의 크기(megabytes)" +"입니다. 크기를 0으로 설정하면 메모리 내의 passwd 가 비활성화됩니다." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1171 sssd.conf.5.xml:2720 sssd-ldap.5.xml:513 @@ -1716,6 +1832,8 @@ msgid "" "WARNING: Disabled or too small in-memory cache can have significant negative " "impact on SSSD's performance." msgstr "" +"경고: 비활성화되었거나 너무 작은 메모리 내 캐시는 SSSD 성능에 심각한 " +"부정적인 영향을 미칠 수 있습니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1187 @@ -1729,6 +1847,8 @@ msgid "" "for group requests. Setting the size to 0 will disable the group in-memory " "cache." msgstr "" +"그룹 요청을 위한 빠른 캐쉬 메모리에 할당된 자료 테이블의 크기(megabytes). " +"크기를 0으로 설정하면 메모리 캐쉬에서 그룹이 비활성화됩니다." #. type: Content of: <variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1196 sssd.conf.5.xml:3515 sssd-ldap.5.xml:453 @@ -1748,6 +1868,9 @@ msgid "" "for initgroups requests. Setting the size to 0 will disable the initgroups " "in-memory cache." msgstr "" +"initgroups 요청을 위한 빠른 메모리 캐쉬에 안에 할당된 자료 테이블의 크기" +"(megabytes). 크기를 0으로 설정하면 메모리 캐쉬에 initgroups가 " +"비활성화됩니다." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.conf.5.xml:1237 sssd-ifp.5.xml:74 @@ -1764,6 +1887,11 @@ msgid "" "<citerefentry> <refentrytitle>sssd-ifp</refentrytitle> <manvolnum>5</" "manvolnum> </citerefentry> for details) but with no default values." msgstr "" +"일부 추가 NSS 응답자 요청은 NSS 인터페이스에 정의된 POSIX 속성보다 더 많은 " +"속성을 반환할 수 있습니다. 속성 목록은 이 옵션에 의해 제어됩니다. InfoPipe " +"응답자의 <quote>user_attributes</quote> 옵션과 동일한 방식으로 처리됩니다" +"(자세한 내용은 <citerefentry> <refentrytitle>sssd-ifp</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry> 참조). 다만 기본값은 없습니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1253 @@ -1771,6 +1899,8 @@ msgid "" "To make configuration more easy the NSS responder will check the InfoPipe " "option if it is not set for the NSS responder." msgstr "" +"구성을 더 쉽게 하기 위해 NSS 응답자에 대해 설정되지 않은 경우 NSS 응답자가 " +"InfoPipe 옵션을 확인합니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1258 @@ -1788,6 +1918,8 @@ msgid "" "The value that NSS operations that return users or groups will return for " "the <quote>password</quote> field." msgstr "" +"사용자 또는 그룹을 반환하는 NSS 연산이 <quote>password</quote> 필드에 대해 " +"반환하는 값입니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1271 @@ -1799,7 +1931,7 @@ msgstr "기본값: <quote>*</quote>" msgid "" "Note: This option can also be set per-domain which overwrites the value in " "[nss] section." -msgstr "" +msgstr "참고: 이 옵션은 도메인별로도 설정할 수 있으며 [nss] 섹션의 값을 덮어씁니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1278 @@ -1808,6 +1940,8 @@ msgid "" "files domain), <quote>x</quote> (proxy domain with nss_files and sssd-" "shadowutils target)" msgstr "" +"기본값: <quote>설정되지 않음</quote>(원격 도메인), <quote>x</quote>(파일 " +"도메인), <quote>x</quote>(nss_files 및 sssd-shadowutils 대상의 프록시 도메인)" #. type: Content of: <reference><refentry><refsect1><refsect2><title> #: sssd.conf.5.xml:1288 @@ -1832,6 +1966,8 @@ msgid "" "If the authentication provider is offline, how long should we allow cached " "logins (in days since the last successful online login)." msgstr "" +"인증 공급자가 오프라인인 경우 캐시된 로그인을 허용해야 하는 기간(마지막 " +"성공적인 온라인 로그인 이후 일 수)입니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1303 sssd.conf.5.xml:1316 @@ -1848,7 +1984,7 @@ msgstr "offline_failed_login_attempts (정수)" msgid "" "If the authentication provider is offline, how many failed login attempts " "are allowed." -msgstr "" +msgstr "인증 공급자가 오프라인인 경우 허용되는 로그인 시도 실패 횟수입니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1322 @@ -1861,6 +1997,8 @@ msgid "" "The time in minutes which has to pass after offline_failed_login_attempts " "has been reached before a new login attempt is possible." msgstr "" +"offline_failed_login_attempts에 도달한 후 새 로그인 시도가 가능해지기 전에 " +"경과해야 하는 시간(분)입니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1330 @@ -1869,6 +2007,9 @@ msgid "" "offline_failed_login_attempts has been reached. Only a successful online " "authentication can enable offline authentication again." msgstr "" +"0으로 설정하면 offline_failed_login_attempts에 도달한 경우 사용자가 " +"오프라인으로 인증할 수 없습니다. 성공적인 온라인 인증만이 오프라인 인증을 " +"다시 활성화할 수 있습니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1336 sssd.conf.5.xml:1446 @@ -1886,6 +2027,8 @@ msgid "" "Controls what kind of messages are shown to the user during authentication. " "The higher the number to more messages are displayed." msgstr "" +"인증 중 사용자에게 표시되는 메시지의 종류를 제어합니다. 숫자가 높을수록 더 " +"많은 메시지가 표시됩니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1350 @@ -1930,6 +2073,10 @@ msgid "" "responses sent to pam_sss e.g. messages displayed to the user or environment " "variables which should be set by pam_sss." msgstr "" +"PAM 응답자가 pam_sss PAM 모듈로 보내는 데이터를 제거(필터링)할 수 있는 " +"쉼표로 구분된 문자열 목록입니다. pam_sss로 전송되는 다양한 종류의 응답이 " +"있습니다. 예를 들어 사용자에게 표시되는 메시지 또는 pam_sss에 의해 " +"설정되어야 하는 환경 변수 등입니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1384 @@ -1937,6 +2084,8 @@ msgid "" "While messages already can be controlled with the help of the pam_verbosity " "option this option allows to filter out other kind of responses as well." msgstr "" +"메시지는 pam_verbosity 옵션의 도움으로 이미 제어할 수 있지만, 이 옵션은 다른 " +"종류의 응답도 필터링할 수 있게 합니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:1391 @@ -1946,7 +2095,7 @@ msgstr "ENV" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1392 msgid "Do not send any environment variables to any service." -msgstr "모든 환경 변수를 다른 서비스에 보낼 수 없습니다." +msgstr "모든 환경 변수를 어떤 서비스에도 보내지 않습니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:1395 @@ -1956,7 +2105,7 @@ msgstr "ENV:var_name" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1396 msgid "Do not send environment variable var_name to any service." -msgstr "환경 변수 var_name을 다른 어떤 서비스에 보내지 않습니다." +msgstr "환경 변수 var_name을 어떤 서비스에도 보내지 않습니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:1400 @@ -1987,6 +2136,11 @@ msgid "" "that either all list elements must have a '+' or '-' prefix or none. It is " "considered as an error to mix both styles." msgstr "" +"문자열 목록은 이 필터 목록을 설정하고 기본값을 덮어쓰는 필터 목록이 될 수 " +"있습니다. 또는 목록의 각 요소에 '+' 또는 '-' 문자를 접두사로 붙여 기존 " +"기본값에 필터를 추가하거나 기본값에서 제거할 수 있습니다. 모든 목록 요소에 " +"'+' 또는 '-' 접두사가 있거나 모두 없어야 합니다. 두 가지 스타일을 혼용하는 " +"것은 오류로 간주됩니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1419 @@ -2011,6 +2165,8 @@ msgid "" "immediately update the cached identity information for the user in order to " "ensure that authentication takes place with the latest information." msgstr "" +"SSSD가 온라인 상태일 때 모든 PAM 요청에 대해, SSSD는 최신 정보로 인증이 " +"이루어지도록 사용자의 캐시된 ID 정보를 즉시 업데이트하려고 시도합니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1438 @@ -2020,6 +2176,9 @@ msgid "" "client-application basis) how long (in seconds) we can cache the identity " "information to avoid excessive round-trips to the identity provider." msgstr "" +"완전한 PAM 대화는 계정 관리 및 세션 열기와 같은 여러 PAM 요청을 수행할 수 " +"있습니다. 이 옵션은 (클라이언트 응용 프로그램별로) ID 공급자에 대한 과도한 " +"왕복을 피하기 위해 ID 정보를 캐시할 수 있는 시간(초)을 제어합니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1452 @@ -2038,6 +2197,8 @@ msgid "" "expiration time of the password. If this information is missing, sssd " "cannot display a warning." msgstr "" +"백엔드 서버가 비밀번호의 만료 시간에 대한 정보를 제공해야 합니다. 이 정보가 " +"없으면 sssd는 경고를 표시할 수 없습니다." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1464 sssd.conf.5.xml:2747 @@ -2045,6 +2206,8 @@ msgid "" "If zero is set, then this filter is not applied, i.e. if the expiration " "warning was received from backend server, it will automatically be displayed." msgstr "" +"0으로 설정하면 이 필터가 적용되지 않습니다. 즉, 백엔드 서버에서 만료 경고를 " +"수신하면 자동으로 표시됩니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1469 @@ -2052,6 +2215,8 @@ msgid "" "This setting can be overridden by setting <emphasis>pwd_expiration_warning</" "emphasis> for a particular domain." msgstr "" +"이 설정은 특정 도메인에 대해 <emphasis>pwd_expiration_warning</emphasis>을 " +"설정하여 재정의할 수 있습니다." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1474 sssd.conf.5.xml:3709 sssd-ldap.5.xml:549 sssd.8.xml:79 @@ -2072,6 +2237,10 @@ msgid "" "<quote>pam_public_domains</quote>. User names are resolved to UIDs at " "startup." msgstr "" +"신뢰할 수 있는 도메인에 대해 PAM 대화를 실행할 수 있는 UID 값 또는 사용자 " +"이름의 쉼표로 구분된 목록을 지정합니다. 이 목록에 포함되지 않은 사용자는 " +"<quote>pam_public_domains</quote>로 공개로 표시된 도메인에만 접근할 수 " +"있습니다. 사용자 이름은 시작 시 UID로 확인됩니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1504 @@ -2084,6 +2253,8 @@ msgid "" "Please note that UID 0 is always allowed to access the PAM responder even in " "case it is not in the pam_trusted_users list." msgstr "" +"UID 0은 pam_trusted_users 목록에 없더라도 항상 PAM 응답자에 대한 접근이 " +"허용됩니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1515 @@ -2096,11 +2267,13 @@ msgid "" "Specifies the comma-separated list of domain names that are accessible even " "to untrusted users." msgstr "" +"신뢰할 수 없는 사용자도 접근할 수 있는 도메인 이름의 쉼표로 구분된 목록을 " +"지정합니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1522 msgid "Two special values for pam_public_domains option are defined:" -msgstr "" +msgstr "pam_public_domains 옵션에 대해 두 가지 특수 값이 정의되어 있습니다:" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1526 @@ -2135,6 +2308,8 @@ msgid "" "Allows a custom expiration message to be set, replacing the default " "'Permission denied' message." msgstr "" +"기본 '권한이 거부되었습니다' 메시지를 대체하는 사용자 지정 만료 메시지를 " +"설정할 수 있습니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1547 @@ -2142,6 +2317,8 @@ msgid "" "Note: Please be aware that message is only printed for the SSH service " "unless pam_verbosity is set to 3 (show all messages and debug information)." msgstr "" +"참고: pam_verbosity가 3(모든 메시지 및 디버그 정보 표시)으로 설정되지 않는 " +"한 메시지는 SSH 서비스에 대해서만 출력됩니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> #: sssd.conf.5.xml:1555 @@ -2164,6 +2341,8 @@ msgid "" "Allows a custom lockout message to be set, replacing the default 'Permission " "denied' message." msgstr "" +"기본 '권한이 거부되었습니다' 메시지를 대체하는 사용자 지정 잠금 메시지를 " +"설정할 수 있습니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> #: sssd.conf.5.xml:1574 @@ -2188,6 +2367,9 @@ msgid "" "additional communication with the Smartcard which will delay the " "authentication process this option is disabled by default." msgstr "" +"인증서 기반 스마트카드 인증을 활성화합니다. 스마트카드와의 추가 통신이 " +"필요하여 인증 프로세스가 지연되므로 이 옵션은 기본적으로 비활성화되어 " +"있습니다." #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1592 sssd-ldap.5.xml:590 sssd-ldap.5.xml:611 @@ -2234,6 +2416,10 @@ msgid "" "section. Supported options are the same of <quote>certificate_verification</" "quote>." msgstr "" +"이 매개변수를 사용하면 <quote>[sssd]</quote> 섹션의 <quote>" +"certificate_verification</quote> 값을 재정의하는 쉼표로 구분된 옵션 목록으로 " +"PAM 인증서 확인을 조정할 수 있습니다. 지원되는 옵션은 <quote>" +"certificate_verification</quote>과 동일합니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> #: sssd.conf.5.xml:1629 @@ -2251,6 +2437,8 @@ msgid "" "Default: not set, i.e. use default <quote>certificate_verification</quote> " "option defined in <quote>[sssd]</quote> section." msgstr "" +"기본값: 설정되지 않음. 즉, <quote>[sssd]</quote> 섹션에 정의된 기본 <quote>" +"certificate_verification</quote> 옵션을 사용합니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1640 @@ -2272,7 +2460,7 @@ msgstr "pam_app_services (문자열)" msgid "" "Which PAM services are permitted to contact domains of type " "<quote>application</quote>" -msgstr "" +msgstr "<quote>application</quote> 유형의 도메인에 접속할 수 있는 PAM 서비스" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1664 @@ -2307,6 +2495,12 @@ msgid "" "<quote>my_pam_service</quote>), you would use the following configuration: " "<placeholder type=\"programlisting\" id=\"0\"/>" msgstr "" +"<quote>+service_name</quote>을 사용하여 기본 집합에 다른 PAM 서비스 이름을 " +"추가하거나 <quote>-service_name</quote>을 사용하여 기본 집합에서 PAM 서비스 " +"이름을 명시적으로 제거할 수 있습니다. 예를 들어 스마트카드 인증을 위한 기본 " +"PAM 서비스 이름(예: <quote>login</quote>)을 사용자 지정 PAM 서비스 이름(예: " +"<quote>my_pam_service</quote>)으로 대체하려면 다음과 같이 구성합니다: " +"<placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1686 sssd-ad.5.xml:621 sssd-ad.5.xml:730 sssd-ad.5.xml:788 @@ -2371,6 +2565,8 @@ msgid "" "to p11_child_timeout should the PAM responder wait until a Smartcard is " "inserted." msgstr "" +"스마트카드 인증이 필요한 경우, PAM 응답기가 스마트카드 삽입을 기다려야 하는 " +"추가 시간(초)으로, p11_child_timeout에 더해집니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1753 @@ -2387,6 +2583,11 @@ msgid "" "first slot found. If multiple readers are connected p11_uri can be used to " "tell p11_child to use a specific reader." msgstr "" +"스마트카드 인증에 사용되는 장치 선택을 제한하는 데 사용할 수 있는 PKCS#11 " +"URI입니다(자세한 내용은 RFC-7512 참조). 기본적으로 SSSD의 p11_child는 " +"'removable' 플래그가 설정된 PKCS#11 슬롯(리더기)을 검색하고 처음 발견된 " +"슬롯에 삽입된 토큰에서 인증서를 읽습니다. 여러 리더기가 연결된 경우 " +"p11_uri를 사용하여 p11_child가 특정 리더기를 사용하도록 지정할 수 있습니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> #: sssd.conf.5.xml:1769 @@ -2417,6 +2618,10 @@ msgid "" "debug output of p11_child. As an alternative the GnuTLS utility 'p11tool' " "with e.g. the '--list-all' will show PKCS#11 URIs as well." msgstr "" +"예시: <placeholder type=\"programlisting\" id=\"0\"/> 또는 <placeholder " +"type=\"programlisting\" id=\"1\"/> 적합한 URI를 찾으려면 p11_child의 디버그 " +"출력을 확인하십시오. 대안으로 GnuTLS 유틸리티 'p11tool'을 '--list-all' 등의 " +"옵션과 함께 사용하면 PKCS#11 URI도 확인할 수 있습니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1786 @@ -2447,6 +2652,8 @@ msgid "" "Only do an online lookup if there is no active session of the user, i.e. if " "the user is currently not logged in" msgstr "" +"사용자의 활성 세션이 없는 경우, 즉 사용자가 현재 로그인되어 있지 않은 " +"경우에만 온라인 조회를 수행합니다" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:1805 @@ -2459,6 +2666,8 @@ msgid "" "Never force an online lookup, use the data from the cache as long as they " "are not expired" msgstr "" +"온라인 조회를 강제하지 않으며, 캐시 데이터가 만료되지 않은 한 캐시의 " +"데이터를 사용합니다" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1789 @@ -2468,6 +2677,9 @@ msgid "" "should be done and the following values are allowed: <placeholder type=" "\"variablelist\" id=\"0\"/>" msgstr "" +"PAM 응답기는 로그인을 시도하는 사용자의 현재 그룹 멤버십을 가져오기 위해 " +"온라인 조회를 강제할 수 있습니다. 이 옵션은 언제 이를 수행할지를 제어하며, " +"다음 값이 허용됩니다: <placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1813 @@ -2485,12 +2697,14 @@ msgid "" "Comma separated list of PAM services that are allowed to try GSSAPI " "authentication using pam_sss_gss.so module." msgstr "" +"pam_sss_gss.so 모듈을 사용하여 GSSAPI 인증을 시도할 수 있는 PAM 서비스의 " +"쉼표로 구분된 목록입니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1826 msgid "" "To disable GSSAPI authentication, set this option to <quote>-</quote> (dash)." -msgstr "" +msgstr "GSSAPI 인증을 비활성화하려면 이 옵션을 <quote>-</quote>(대시)로 설정하십시오." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1830 sssd.conf.5.xml:1861 sssd.conf.5.xml:1899 @@ -2499,6 +2713,9 @@ msgid "" "[pam] section. It can also be set for trusted domain which overwrites the " "value in the domain section." msgstr "" +"참고: 이 옵션은 도메인별로 설정할 수도 있으며, 이 경우 [pam] 섹션의 값을 " +"덮어씁니다. 또한 신뢰할 수 있는 도메인에 대해 설정할 수 있으며, 이 경우 " +"도메인 섹션의 값을 덮어씁니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> #: sssd.conf.5.xml:1838 @@ -2532,6 +2749,9 @@ msgid "" "successfully authenticated through GSSAPI can be associated with the user " "who is being authenticated. Authentication will fail if the check fails." msgstr "" +"True로 설정된 경우, SSSD는 GSSAPI를 통해 성공적으로 인증된 Kerberos 사용자 " +"주체가 인증 중인 사용자와 연결될 수 있어야 합니다. 확인에 실패하면 인증이 " +"실패합니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1857 @@ -2539,6 +2759,8 @@ msgid "" "If False, every user that is able to obtained required service ticket will " "be authenticated." msgstr "" +"False로 설정된 경우, 필요한 서비스 티켓을 획득할 수 있는 모든 사용자가 " +"인증됩니다." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1867 sssd-ad.5.xml:1243 sss_rpcidmapd.5.xml:76 @@ -2558,6 +2780,9 @@ msgid "" "a Kerberos ticket to access a PAM service that is allowed to try GSSAPI " "authentication using pam_sss_gss.so module." msgstr "" +"pam_sss_gss.so 모듈을 사용하여 GSSAPI 인증을 시도할 수 있는 PAM 서비스에 " +"액세스하기 위해 Kerberos 티켓에 포함되어야 하는 인증 지표의 쉼표로 구분된 " +"목록입니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1881 @@ -2573,6 +2798,14 @@ msgid "" "be denied. If the resulting list of indicators for the PAM service is empty, " "the check will not prevent the access." msgstr "" +"목록의 각 요소는 인증 지표 이름이거나 <quote>service:indicator</quote> 쌍일 " +"수 있습니다. PAM 서비스 이름이 접두사로 붙지 않은 지표는 <option>" +"pam_gssapi_services</option>.와 함께 사용하도록 구성된 모든 PAM 서비스에 " +"액세스하는 데 필요합니다. PAM 서비스별 지표 목록은 pam_sss_gss.so에 의한 " +"인증 중에 Kerberos 티켓의 지표와 대조하여 확인됩니다. 티켓의 지표 중 PAM " +"서비스의 지표 목록과 일치하는 항목이 있으면 액세스가 허용됩니다. 목록의 지표 " +"중 일치하는 항목이 없으면 액세스가 거부됩니다. PAM 서비스의 지표 목록이 비어 " +"있으면 해당 확인으로 인해 액세스가 차단되지 않습니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1894 @@ -2581,13 +2814,16 @@ msgid "" "</quote> (dash). To disable the check for a specific PAM service, add " "<quote>service:-</quote>." msgstr "" +"GSSAPI 인증 지표 확인을 비활성화하려면 이 옵션을 <quote>-</quote>(대시)로 " +"설정하십시오. 특정 PAM 서비스에 대한 확인을 비활성화하려면 <quote>service:-</" +"quote>.를 추가하십시오." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1905 msgid "" "Following authentication indicators are supported by IPA Kerberos " "deployments:" -msgstr "" +msgstr "다음 인증 지표는 IPA Kerberos 배포에서 지원됩니다:" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:1908 @@ -2595,6 +2831,8 @@ msgid "" "pkinit -- pre-authentication using X.509 certificates -- whether stored in " "files or on smart cards." msgstr "" +"pkinit -- X.509 인증서를 사용한 사전 인증 -- 파일 또는 스마트카드에 저장된 " +"경우 모두 해당됩니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:1911 @@ -2843,6 +3081,11 @@ msgid "" "the system defaults are used, but can be overwritten with the default_shell " "parameter." msgstr "" +"원격 사용자가 캐시에 존재하지 않는 경우 새로 생성됩니다. UID는 SID를 통해 " +"결정되며, 신뢰할 수 있는 도메인은 UPG를 가지고 GID는 UID와 동일한 값을 " +"갖습니다. 홈 디렉토리는 subdomain_homedir 파라미터를 기반으로 설정됩니다. " +"셸은 기본적으로 비어 있으며, 즉 시스템 기본값이 사용되지만 default_shell " +"파라미터로 덮어쓸 수 있습니다." #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:2147 @@ -2850,6 +3093,8 @@ msgid "" "If there are SIDs of groups from domains sssd knows about, the user will be " "added to those groups." msgstr "" +"SSSD가 알고 있는 도메인의 그룹 SID가 있는 경우, 해당 그룹에 사용자가 " +"추가됩니다." #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sssd.conf.5.xml:2153 @@ -2868,11 +3113,13 @@ msgid "" "allowed to access the PAC responder. User names are resolved to UIDs at " "startup." msgstr "" +"PAC 응답기에 액세스할 수 있는 UID 값 또는 사용자 이름의 쉼표로 구분된 목록을 " +"지정합니다. 사용자 이름은 시작 시 UID로 확인됩니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2166 msgid "Default: 0 (only the root user is allowed to access the PAC responder)" -msgstr "" +msgstr "기본값: 0 (root 사용자만 PAC 응답기에 접근 할 수 있습니다)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2170 @@ -8803,6 +9050,8 @@ msgid "" "This option can be used to specify which extended key usage the certificate " "should have. The following value can be used in a comma separated list:" msgstr "" +"이와 같은 옵션은 확장된 키 사용 값을 갖도록 지정하는 데 사용 될 수 있습니다. " +"다음 값은 쉼표로 분리된 목록에서 사용 될 수 있습니다:" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sss-certmap.5.xml:163 @@ -9397,6 +9646,8 @@ msgid "" "This template will add the DN string of the value which is stored in the " "directoryName component of the SAN." msgstr "" +"이와 같은 템플릿트는 SAN의 디렉토리명칭 구성 요소에서 저장된 것과 같은 DN " +"문자열이 추가됩니다." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:575 @@ -17093,6 +17344,8 @@ msgid "" "When using ldap_account_expire_policy=rhds or equivalent, this parameter " "determines if access is allowed or not." msgstr "" +"ldap_account_expire_policy=rhds 이거나 동일하게 사용 할 때에, 이와 같은 " +"매개변수는 접근 허용 여부를 결정합니다." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:368 @@ -17669,7 +17922,7 @@ msgstr "ldap_host_fqdn (문자열)" msgid "" "The LDAP attribute that corresponds to the host's fully-qualified domain " "name." -msgstr "" +msgstr "호스트의 정규화된 도메인 이름에 일치하는 LDAP 속성." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:907 diff --git a/src/man/po/lv.po b/src/man/po/lv.po index 8db96e2daa9..5f4aa39df2b 100644 --- a/src/man/po/lv.po +++ b/src/man/po/lv.po @@ -9,8 +9,8 @@ msgid "" msgstr "" "Project-Id-Version: sssd-docs 2.3.0\n" "Report-Msgid-Bugs-To: sssd-devel@redhat.com\n" -"POT-Creation-Date: 2026-01-14 15:00+0000\n" -"PO-Revision-Date: 2026-04-23 16:57+0000\n" +"POT-Creation-Date: 2026-10-05 16:14+0000\n" +"PO-Revision-Date: 2026-10-05 16:58+0000\n" "Last-Translator: Anonymous <noreply@weblate.org>\n" "Language-Team: Latvian <https://translate.fedoraproject.org/projects/sssd/" "sssd-manpage-master/lv/>\n" @@ -19,10 +19,10 @@ msgstr "" "Content-Type: text/plain; charset=UTF-8\n" "Content-Transfer-Encoding: 8bit\n" "Plural-Forms: nplurals=3; plural=n%10==1 && n%100!=11 ? 0 : n != 0 ? 1 : 2;\n" -"X-Generator: Weblate 5.17\n" +"X-Generator: Weblate 2026.10\n" #. type: Content of: <reference><title> -#: sssd.conf.5.xml:8 sssd-ldap.5.xml:5 pam_sss.8.xml:5 pam_sss_gss.8.xml:5 +#: sssd.conf.5.xml:10 sssd-ldap.5.xml:5 pam_sss.8.xml:5 pam_sss_gss.8.xml:5 #: sssd_krb5_locator_plugin.8.xml:5 sssd-simple.5.xml:5 sss-certmap.5.xml:5 #: sssd-ipa.5.xml:5 sssd-ad.5.xml:5 sssd-sudo.5.xml:5 sssd-idp.5.xml:5 #: sssd.8.xml:5 sss_obfuscate.8.xml:5 sss_override.8.xml:5 sssd-krb5.5.xml:5 @@ -35,12 +35,12 @@ msgid "SSSD Manual pages" msgstr "" #. type: Content of: <reference><refentry><refnamediv><refname> -#: sssd.conf.5.xml:13 sssd.conf.5.xml:19 +#: sssd.conf.5.xml:15 sssd.conf.5.xml:21 msgid "sssd.conf" msgstr "sssd.conf" #. type: Content of: <reference><refentry><refmeta><manvolnum> -#: sssd.conf.5.xml:14 sssd-ldap.5.xml:11 sssd-simple.5.xml:11 +#: sssd.conf.5.xml:16 sssd-ldap.5.xml:11 sssd-simple.5.xml:11 #: sss-certmap.5.xml:11 sssd-ipa.5.xml:11 sssd-ad.5.xml:11 sssd-sudo.5.xml:11 #: sssd-idp.5.xml:11 sssd-krb5.5.xml:11 sssd-ifp.5.xml:11 #: sss_rpcidmapd.5.xml:27 sssd-session-recording.5.xml:11 @@ -49,7 +49,7 @@ msgid "5" msgstr "5" #. type: Content of: <reference><refentry><refmeta><refmiscinfo> -#: sssd.conf.5.xml:15 sssd-ldap.5.xml:12 sssd-simple.5.xml:12 +#: sssd.conf.5.xml:17 sssd-ldap.5.xml:12 sssd-simple.5.xml:12 #: sss-certmap.5.xml:12 sssd-ipa.5.xml:12 sssd-ad.5.xml:12 sssd-sudo.5.xml:12 #: sssd-idp.5.xml:12 sssd-krb5.5.xml:12 sssd-ifp.5.xml:12 #: sss_rpcidmapd.5.xml:28 sssd-session-recording.5.xml:12 sssd-kcm.8.xml:12 @@ -58,17 +58,17 @@ msgid "File Formats and Conventions" msgstr "" #. type: Content of: <reference><refentry><refnamediv><refpurpose> -#: sssd.conf.5.xml:20 +#: sssd.conf.5.xml:22 msgid "the configuration file for SSSD" msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:24 +#: sssd.conf.5.xml:26 msgid "FILE FORMAT" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd.conf.5.xml:32 +#: sssd.conf.5.xml:34 #, no-wrap msgid "" "<replaceable>[section]</replaceable>\n" @@ -78,7 +78,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:27 +#: sssd.conf.5.xml:29 msgid "" "The file has an ini-style syntax and consists of sections and parameters. A " "section begins with the name of the section in square brackets and continues " @@ -87,47 +87,50 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:39 +#: sssd.conf.5.xml:41 msgid "" -"The data types used are string (no quotes needed), integer and bool (with " -"values of <quote>TRUE/FALSE</quote>)." +"The data types used are string (no quotes needed), integer and boolean (with " +"values of <quote>TRUE/FALSE</quote>). Boolean values are case-insensitive; " +"for example, <quote>TRUE</quote>, <quote>True</quote> and <quote>true</" +"quote> are all equivalent and valid; the same applies to <quote>FALSE</" +"quote>." msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:44 +#: sssd.conf.5.xml:49 msgid "" "A comment line starts with a hash sign (<quote>#</quote>) or a semicolon " "(<quote>;</quote>). Inline comments are not supported." msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:50 +#: sssd.conf.5.xml:55 msgid "" "All sections can have an optional <replaceable>description</replaceable> " "parameter. Its function is only as a label for the section." msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:56 +#: sssd.conf.5.xml:61 msgid "" "<filename>sssd.conf</filename> must be a regular file that is owned, " "readable, and writeable only by 'root'." msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:60 +#: sssd.conf.5.xml:65 msgid "" "<filename>sssd.conf</filename> must be a regular file that is accessible " "only by the user used to run SSSD service or root." msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:66 +#: sssd.conf.5.xml:71 msgid "CONFIGURATION SNIPPETS FROM INCLUDE DIRECTORY" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:69 +#: sssd.conf.5.xml:74 msgid "" "The configuration file <filename>sssd.conf</filename> will include " "configuration snippets using the include directory <filename>conf.d</" @@ -135,7 +138,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:75 +#: sssd.conf.5.xml:80 msgid "" "Any file placed in <filename>conf.d</filename> that ends in " "<quote><filename>.conf</filename></quote> and does not begin with a dot " @@ -144,7 +147,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:83 +#: sssd.conf.5.xml:88 msgid "" "The configuration snippets from <filename>conf.d</filename> have higher " "priority than <filename>sssd.conf</filename> and will override " @@ -157,39 +160,92 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:97 +#: sssd.conf.5.xml:102 msgid "" "The snippet files require the same owner and permissions as " "<filename>sssd.conf</filename>." msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:103 +#: sssd.conf.5.xml:108 +#, fuzzy +#| msgid "CONFIGURATION OPTIONS" +msgid "VENDOR PROVIDED CONFIGURATION" +msgstr "KONFIGURĒŠANAS IESPĒJAS" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:111 +msgid "" +"The vendor provided configuration file is installed in " +"<filename>&sssd_vendor_dir;/sssd.conf</filename>, but this file must not be " +"directly edited. It can be completely masked by creating the system specific " +"configuration file <filename>&sssd_conf_dir;/sssd.conf</filename>, or partly " +"overriden by creating config snippets in <filename>&sssd_conf_dir;/conf.d</" +"filename> directory." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><title> +#: sssd.conf.5.xml:120 +#, fuzzy +#| msgid "CONFIGURATION OPTIONS" +msgid "CONFIGURATION FILE HIERARCHY" +msgstr "KONFIGURĒŠANAS IESPĒJAS" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:122 +msgid "" +"When sssd reads the configuration it first tries to open the system specific " +"configuration file in <filename>&sssd_conf_dir;/sssd.conf</filename>. If it " +"exists, it is loaded and snippets from <filename>&sssd_conf_dir;/conf.d</" +"filename> are applied. The vendor provided configuration file " +"<filename>&sssd_vendor_dir;/sssd.conf</filename> is completely ignored in " +"this case." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:131 +msgid "" +"If the system specific configuration file <filename>&sssd_conf_dir;/" +"sssd.conf</filename> does not exist, then the vendor configuration file " +"<filename>&sssd_vendor_dir;/sssd.conf</filename> is loaded and snippets from " +"<filename>&sssd_conf_dir;/conf.d</filename> are applied." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd.conf.5.xml:141 msgid "GENERAL OPTIONS" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:105 +#: sssd.conf.5.xml:143 msgid "Following options are usable in more than one configuration sections." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:109 +#: sssd.conf.5.xml:147 msgid "Options usable in all sections" msgstr "" +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:149 +msgid "" +"Note: Below options are ignored in <quote>[session_recording]</quote> " +"section, see <quote>Session recording configuration options</quote> section " +"for more details." +msgstr "" + #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:113 +#: sssd.conf.5.xml:156 msgid "debug_level (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:117 +#: sssd.conf.5.xml:160 msgid "debug (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:120 +#: sssd.conf.5.xml:163 msgid "" "SSSD 1.14 and later also includes the <replaceable>debug</replaceable> alias " "for <replaceable>debug_level</replaceable> as a convenience feature. If both " @@ -198,61 +254,61 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:130 -msgid "debug_timestamps (bool)" +#: sssd.conf.5.xml:173 +msgid "debug_timestamps (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:133 +#: sssd.conf.5.xml:176 msgid "" "Add a timestamp to the debug messages. If journald is enabled for SSSD " "debug logging this option is ignored." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:138 sssd.conf.5.xml:175 sssd.conf.5.xml:337 -#: sssd.conf.5.xml:644 sssd.conf.5.xml:668 sssd.conf.5.xml:875 -#: sssd.conf.5.xml:979 sssd.conf.5.xml:2113 sssd-ldap.5.xml:979 -#: sssd-ldap.5.xml:1134 sssd-ldap.5.xml:1237 sssd-ldap.5.xml:1306 -#: sssd-ldap.5.xml:1714 sssd-ldap.5.xml:1848 sssd-ldap.5.xml:1913 -#: sssd-ipa.5.xml:346 sssd-ad.5.xml:252 sssd-ad.5.xml:367 sssd-ad.5.xml:1180 -#: sssd-ad.5.xml:1382 sssd-krb5.5.xml:358 +#: sssd.conf.5.xml:181 sssd.conf.5.xml:218 sssd.conf.5.xml:380 +#: sssd.conf.5.xml:687 sssd.conf.5.xml:711 sssd.conf.5.xml:827 +#: sssd.conf.5.xml:932 sssd.conf.5.xml:2149 sssd.conf.5.xml:4730 +#: sssd-ldap.5.xml:979 sssd-ldap.5.xml:1134 sssd-ldap.5.xml:1237 +#: sssd-ldap.5.xml:1306 sssd-ldap.5.xml:1714 sssd-ldap.5.xml:1848 +#: sssd-ldap.5.xml:1913 sssd-ipa.5.xml:341 sssd-ad.5.xml:252 sssd-ad.5.xml:367 +#: sssd-ad.5.xml:1180 sssd-ad.5.xml:1375 sssd-krb5.5.xml:358 msgid "Default: true" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:143 -msgid "debug_microseconds (bool)" +#: sssd.conf.5.xml:186 +msgid "debug_microseconds (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:146 +#: sssd.conf.5.xml:189 msgid "" "Add microseconds to the timestamp in debug messages. If journald is enabled " "for SSSD debug logging this option is ignored." msgstr "" #. type: Content of: <variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:151 sssd.conf.5.xml:2040 sssd.conf.5.xml:4158 +#: sssd.conf.5.xml:194 sssd.conf.5.xml:2072 sssd.conf.5.xml:4363 #: sssd-ldap.5.xml:363 sssd-ldap.5.xml:998 sssd-ldap.5.xml:1209 -#: sssd-ldap.5.xml:1663 sssd-ldap.5.xml:1937 sssd-ipa.5.xml:146 -#: sssd-ipa.5.xml:706 sssd-ad.5.xml:1135 sssd-krb5.5.xml:268 +#: sssd-ldap.5.xml:1663 sssd-ldap.5.xml:1937 sssd-ipa.5.xml:141 +#: sssd-ipa.5.xml:701 sssd-ad.5.xml:1140 sssd-idp.5.xml:287 sssd-krb5.5.xml:268 #: sssd-krb5.5.xml:330 sssd-krb5.5.xml:432 include/krb5_options.xml:163 msgid "Default: false" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:156 -msgid "debug_backtrace_enabled (bool)" +#: sssd.conf.5.xml:199 +msgid "debug_backtrace_enabled (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:159 +#: sssd.conf.5.xml:202 msgid "Enable debug backtrace." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:162 +#: sssd.conf.5.xml:205 msgid "" "In case SSSD is run with debug_level less than 9, everything is logged to a " "ring buffer in memory and flushed to a log file on any error up to and " @@ -262,14 +318,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:171 +#: sssd.conf.5.xml:214 msgid "" "Feature is only supported for `logger == files` (i.e. setting doesn't have " "effect for other logger types)." msgstr "" #. type: Content of: outside any tag (error?) -#: sssd.conf.5.xml:111 sssd.conf.5.xml:186 sssd-ldap.5.xml:1754 +#: sssd.conf.5.xml:154 sssd.conf.5.xml:229 sssd-ldap.5.xml:1754 #: sssd-ldap.5.xml:1960 sss-certmap.5.xml:645 sssd-systemtap.5.xml:82 #: sssd-systemtap.5.xml:143 sssd-systemtap.5.xml:236 sssd-systemtap.5.xml:274 #: sssd-systemtap.5.xml:330 sssd-ldap-attributes.5.xml:40 @@ -282,17 +338,17 @@ msgid "<placeholder type=\"variablelist\" id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:184 +#: sssd.conf.5.xml:227 msgid "Options usable in SERVICE and DOMAIN sections" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:188 +#: sssd.conf.5.xml:231 msgid "timeout (integer)" msgstr "noildze (vesels skaitlis)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:191 +#: sssd.conf.5.xml:234 msgid "" "Timeout in seconds between heartbeats for this service. This is used to " "ensure that the process is alive and capable of answering requests. Note " @@ -300,34 +356,36 @@ msgid "" msgstr "" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:198 sssd.conf.5.xml:1199 sssd.conf.5.xml:1673 -#: sssd.conf.5.xml:4174 sssd-ldap.5.xml:825 sssd-idp.5.xml:192 +#: sssd.conf.5.xml:241 sssd.conf.5.xml:1155 sssd.conf.5.xml:1665 +#: sssd.conf.5.xml:4379 sssd-ldap.5.xml:825 sssd-idp.5.xml:271 #: include/ldap_id_mapping.xml:270 msgid "Default: 10" msgstr "Noklusējuma: 10" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:208 +#: sssd.conf.5.xml:251 msgid "SPECIAL SECTIONS" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:211 +#: sssd.conf.5.xml:254 msgid "The [sssd] section" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><title> -#: sssd.conf.5.xml:220 +#: sssd.conf.5.xml:263 msgid "Section parameters" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:222 -msgid "services" +#: sssd.conf.5.xml:265 +#, fuzzy +#| msgid "services" +msgid "services (string)" msgstr "pakalpojumi" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:225 +#: sssd.conf.5.xml:268 msgid "" "Comma separated list of services that are started when sssd itself starts. " "<phrase condition=\"have_systemd\"> The services' list is optional on " @@ -336,7 +394,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:234 +#: sssd.conf.5.xml:277 msgid "" "Supported services: nss, pam, ifp <phrase condition=\"with_sudo\">, sudo</" "phrase> <phrase condition=\"with_autofs\">, autofs</phrase> <phrase " @@ -345,20 +403,20 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:241 +#: sssd.conf.5.xml:284 msgid "" "<phrase condition=\"have_systemd\"> By default, all services are disabled " "and the administrator must enable the ones allowed to be used by executing: " "\"systemctl enable sssd-@service@.socket\". </phrase>" msgstr "" -#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:250 -msgid "domains" -msgstr "domēni" +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sssd.conf.5.xml:293 sssd.conf.5.xml:4562 +msgid "domains (string)" +msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:253 +#: sssd.conf.5.xml:296 msgid "" "A domain is a database containing user information. SSSD can use more " "domains at the same time, but at least one must be configured or SSSD won't " @@ -369,19 +427,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:266 sssd.conf.5.xml:3467 +#: sssd.conf.5.xml:309 sssd.conf.5.xml:3598 msgid "re_expression (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:269 +#: sssd.conf.5.xml:312 msgid "" "Default regular expression that describes how to parse the string containing " "user name and domain into these components." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:274 +#: sssd.conf.5.xml:317 msgid "" "Each domain can have an individual regular expression configured. For some " "ID providers there are also default regular expressions. See DOMAIN SECTIONS " @@ -389,12 +447,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:283 sssd.conf.5.xml:3524 +#: sssd.conf.5.xml:326 sssd.conf.5.xml:3655 msgid "full_name_format (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:286 sssd.conf.5.xml:3527 +#: sssd.conf.5.xml:329 sssd.conf.5.xml:3658 msgid "" "A <citerefentry> <refentrytitle>printf</refentrytitle> <manvolnum>3</" "manvolnum> </citerefentry>-compatible format that describes how to compose a " @@ -402,70 +460,70 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:297 sssd.conf.5.xml:3538 +#: sssd.conf.5.xml:340 sssd.conf.5.xml:3669 msgid "%1$s" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:298 sssd.conf.5.xml:3539 +#: sssd.conf.5.xml:341 sssd.conf.5.xml:3670 msgid "user name" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:301 sssd.conf.5.xml:3542 +#: sssd.conf.5.xml:344 sssd.conf.5.xml:3673 msgid "%2$s" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:304 sssd.conf.5.xml:3545 +#: sssd.conf.5.xml:347 sssd.conf.5.xml:3676 msgid "domain name as specified in the SSSD config file." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:310 sssd.conf.5.xml:3551 +#: sssd.conf.5.xml:353 sssd.conf.5.xml:3682 msgid "%3$s" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:313 sssd.conf.5.xml:3554 +#: sssd.conf.5.xml:356 sssd.conf.5.xml:3685 msgid "" "domain flat name. Mostly usable for Active Directory domains, both directly " "configured or discovered via IPA trusts." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:294 sssd.conf.5.xml:3535 +#: sssd.conf.5.xml:337 sssd.conf.5.xml:3666 msgid "" "The following expansions are supported: <placeholder type=\"variablelist\" " "id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:323 +#: sssd.conf.5.xml:366 msgid "" "Each domain can have an individual format string configured. See DOMAIN " "SECTIONS for more info on this option." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:329 +#: sssd.conf.5.xml:372 msgid "monitor_resolv_conf (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:332 +#: sssd.conf.5.xml:375 msgid "" "Controls if SSSD should monitor the state of resolv.conf to identify when it " "needs to update its internal DNS resolver." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:342 +#: sssd.conf.5.xml:385 msgid "try_inotify (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:345 +#: sssd.conf.5.xml:388 msgid "" "By default, SSSD will attempt to use inotify to monitor configuration files " "changes and will fall back to polling every five seconds if inotify cannot " @@ -473,7 +531,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:351 +#: sssd.conf.5.xml:394 msgid "" "There are some limited situations where it is preferred that we should skip " "even trying to use inotify. In these rare cases, this option should be set " @@ -481,59 +539,59 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:357 +#: sssd.conf.5.xml:400 msgid "" "Default: true on platforms where inotify is supported. False on other " "platforms." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:361 +#: sssd.conf.5.xml:404 msgid "" "Note: this option will have no effect on platforms where inotify is " "unavailable. On these platforms, polling will always be used." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:368 +#: sssd.conf.5.xml:411 msgid "krb5_rcache_dir (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:371 +#: sssd.conf.5.xml:414 msgid "" "Directory on the filesystem where SSSD should store Kerberos replay cache " "files." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:375 +#: sssd.conf.5.xml:418 msgid "" "This option accepts a special value __LIBKRB5_DEFAULTS__ that will instruct " "SSSD to let libkrb5 decide the appropriate location for the replay cache." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:381 +#: sssd.conf.5.xml:424 msgid "" "Default: Distribution-specific and specified at build-time. " "(__LIBKRB5_DEFAULTS__ if not configured)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:388 +#: sssd.conf.5.xml:431 msgid "default_domain_suffix (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:391 +#: sssd.conf.5.xml:434 msgid "" "Please note that this option is deprecated and domain_resolution_order " "should be used." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:395 +#: sssd.conf.5.xml:438 msgid "" "This string will be used as a default domain name for all names without a " "domain name component. The main use case is environments where the primary " @@ -543,7 +601,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:405 +#: sssd.conf.5.xml:448 msgid "" "Please note that if this option is set all users from the primary domain " "have to use their fully qualified name, e.g. user@domain.name, to log in. " @@ -553,21 +611,21 @@ msgid "" msgstr "" #. type: Content of: <variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:414 sssd-ldap.5.xml:937 sssd-ldap.5.xml:949 -#: sssd-ldap.5.xml:1042 sssd-ad.5.xml:921 sssd-ad.5.xml:996 sssd-krb5.5.xml:468 -#: sssd-ldap-attributes.5.xml:470 sssd-ldap-attributes.5.xml:978 -#: include/ldap_id_mapping.xml:211 include/ldap_id_mapping.xml:222 -#: include/krb5_options.xml:148 +#: sssd.conf.5.xml:457 sssd.conf.5.xml:2006 sssd-ldap.5.xml:937 +#: sssd-ldap.5.xml:949 sssd-ldap.5.xml:1042 sssd-ad.5.xml:926 +#: sssd-ad.5.xml:1001 sssd-krb5.5.xml:468 sssd-ldap-attributes.5.xml:470 +#: sssd-ldap-attributes.5.xml:978 include/ldap_id_mapping.xml:211 +#: include/ldap_id_mapping.xml:222 include/krb5_options.xml:148 msgid "Default: not set" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:419 +#: sssd.conf.5.xml:462 msgid "override_space (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:422 +#: sssd.conf.5.xml:465 msgid "" "This parameter will replace spaces (space bar) with the given character for " "user and group names. e.g. (_). User name "john doe" will be " @@ -577,7 +635,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:431 +#: sssd.conf.5.xml:474 msgid "" "Please note it is a configuration error to use a replacement character that " "might be used in user or group names. If a name contains the replacement " @@ -586,22 +644,22 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:439 +#: sssd.conf.5.xml:482 msgid "Default: not set (spaces will not be replaced)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:444 +#: sssd.conf.5.xml:487 msgid "certificate_verification (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:452 +#: sssd.conf.5.xml:495 msgid "no_ocsp" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:454 +#: sssd.conf.5.xml:497 msgid "" "Disables Online Certificate Status Protocol (OCSP) checks. This might be " "needed if the OCSP servers defined in the certificate are not reachable from " @@ -609,12 +667,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:462 +#: sssd.conf.5.xml:505 msgid "soft_ocsp" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:464 +#: sssd.conf.5.xml:507 msgid "" "If a connection cannot be established to an OCSP responder the OCSP check is " "skipped. This option should be used to allow authentication when the system " @@ -622,61 +680,61 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:474 +#: sssd.conf.5.xml:517 msgid "ocsp_dgst" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:476 +#: sssd.conf.5.xml:519 msgid "" "Digest (hash) function used to create the certificate ID for the OCSP " "request. Allowed values are:" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:480 +#: sssd.conf.5.xml:523 msgid "sha1" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:481 +#: sssd.conf.5.xml:524 msgid "sha256" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:482 +#: sssd.conf.5.xml:525 msgid "sha384" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:483 +#: sssd.conf.5.xml:526 msgid "sha512" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:486 +#: sssd.conf.5.xml:529 msgid "Default: sha1 (to allow compatibility with RFC5019-compliant responder)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:492 +#: sssd.conf.5.xml:535 msgid "no_verification" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:494 +#: sssd.conf.5.xml:537 msgid "" "Disables verification completely. This option should only be used for " "testing." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:500 +#: sssd.conf.5.xml:543 msgid "partial_chain" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:502 +#: sssd.conf.5.xml:545 msgid "" "Allow verification to succeed even if a <replaceable>complete</replaceable> " "chain cannot be built to a self-signed trust-anchor, provided it is possible " @@ -684,12 +742,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:511 +#: sssd.conf.5.xml:554 msgid "ocsp_default_responder=URL" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:513 +#: sssd.conf.5.xml:556 msgid "" "Sets the OCSP default responder which should be used instead of the one " "mentioned in the certificate. URL must be replaced with the URL of the OCSP " @@ -697,24 +755,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:523 +#: sssd.conf.5.xml:566 msgid "ocsp_default_responder_signing_cert=NAME" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:525 +#: sssd.conf.5.xml:568 msgid "" "This option is currently ignored. All needed certificates must be available " "in the PEM file given by pam_cert_db_path." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:533 +#: sssd.conf.5.xml:576 msgid "crl_file=/PATH/TO/CRL/FILE" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:535 +#: sssd.conf.5.xml:578 msgid "" "Use the Certificate Revocation List (CRL) from the given file during the " "verification of the certificate. The CRL must be given in PEM format, see " @@ -723,12 +781,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:548 +#: sssd.conf.5.xml:591 msgid "soft_crl" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:551 +#: sssd.conf.5.xml:594 msgid "" "If a Certificate Revocation List (CRL) is expired ignore the expiration " "time of the CRL and check the related certificates with the expired CRL. " @@ -737,7 +795,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:447 +#: sssd.conf.5.xml:490 msgid "" "With this parameter the certificate verification can be tuned with a comma " "separated list of options. Supported options are: <placeholder " @@ -745,46 +803,48 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:564 +#: sssd.conf.5.xml:607 msgid "Unknown options are reported but ignored." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:567 +#: sssd.conf.5.xml:610 msgid "Default: not set, i.e. do not restrict certificate verification" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:573 +#: sssd.conf.5.xml:616 msgid "disable_netlink (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:576 +#: sssd.conf.5.xml:619 msgid "" "SSSD hooks into the netlink interface to monitor changes to routes, " "addresses, links and trigger certain actions." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:581 +#: sssd.conf.5.xml:624 msgid "" "The SSSD state changes caused by netlink events may be undesirable and can " "be disabled by setting this option to 'true'" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:586 +#: sssd.conf.5.xml:629 msgid "Default: false (netlink changes are detected)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:591 -msgid "domain_resolution_order" -msgstr "" +#: sssd.conf.5.xml:634 +#, fuzzy +#| msgid "timeout (integer)" +msgid "domain_resolution_order (string)" +msgstr "noildze (vesels skaitlis)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:594 +#: sssd.conf.5.xml:637 msgid "" "Comma separated list of domains and subdomains representing the lookup order " "that will be followed. The list doesn't have to include all possible " @@ -795,7 +855,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:606 +#: sssd.conf.5.xml:649 msgid "" "Please, note that when this option is set the output format of all commands " "is always fully-qualified even when using short names for input. In case " @@ -811,19 +871,20 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:630 sssd.conf.5.xml:1697 sssd.conf.5.xml:4224 -#: sssd-ad.5.xml:187 sssd-ad.5.xml:328 sssd-ad.5.xml:342 sssd-idp.5.xml:108 -#: sssd-idp.5.xml:132 sssd-idp.5.xml:145 sssd-idp.5.xml:159 sssd-idp.5.xml:180 +#: sssd.conf.5.xml:673 sssd.conf.5.xml:1026 sssd.conf.5.xml:1689 +#: sssd.conf.5.xml:4429 sssd-ad.5.xml:187 sssd-ad.5.xml:328 sssd-ad.5.xml:342 +#: sssd-idp.5.xml:112 sssd-idp.5.xml:136 sssd-idp.5.xml:149 sssd-idp.5.xml:167 +#: sssd-idp.5.xml:188 msgid "Default: Not set" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:635 +#: sssd.conf.5.xml:678 msgid "implicit_pac_responder (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:638 +#: sssd.conf.5.xml:681 msgid "" "The PAC responder is enabled automatically for the IPA and AD provider to " "evaluate and check the PAC. If it has to be disabled set this option to " @@ -831,12 +892,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:649 +#: sssd.conf.5.xml:692 msgid "core_dumpable (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:652 +#: sssd.conf.5.xml:695 msgid "" "This option can be used for general system hardening: setting it to 'false' " "forbids core dumps for all SSSD processes to avoid leaking plain text " @@ -845,7 +906,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:660 +#: sssd.conf.5.xml:703 msgid "" "Take a note that this setting has no effect for 'ldap_child', 'krb5_child' " "and 'sssd_pam' as those privileged binaries can have a copy of a host keytab " @@ -854,24 +915,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:673 +#: sssd.conf.5.xml:716 msgid "passkey_verification (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:681 +#: sssd.conf.5.xml:724 msgid "user_verification (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:683 +#: sssd.conf.5.xml:726 msgid "" "Enable or disable the user verification (i.e. PIN, fingerprint) during " "authentication. If enabled, the PIN will always be requested." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:689 +#: sssd.conf.5.xml:732 msgid "" "The default is that the key settings decide what to do. In the IPA or " "kerberos pre-authentication case, this value will be overwritten by the " @@ -879,7 +940,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:676 +#: sssd.conf.5.xml:719 msgid "" "With this parameter the passkey verification can be tuned with a comma " "separated list of options. Supported options are: <placeholder " @@ -887,7 +948,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:213 +#: sssd.conf.5.xml:256 msgid "" "Individual pieces of SSSD functionality are provided by special SSSD " "services that are started and stopped together with SSSD. The services are " @@ -898,12 +959,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:708 +#: sssd.conf.5.xml:751 msgid "SERVICES SECTIONS" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:710 +#: sssd.conf.5.xml:753 msgid "" "Settings that can be used to configure different services are described in " "this section. They should reside in the [<replaceable>$NAME</replaceable>] " @@ -912,42 +973,45 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:717 +#: sssd.conf.5.xml:760 msgid "General service configuration options" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:719 +#: sssd.conf.5.xml:762 msgid "These options can be used to configure any service." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:723 -msgid "fd_limit" -msgstr "" +#: sssd.conf.5.xml:766 +#, fuzzy +#| msgid "timeout (integer)" +msgid "fd_limit (integer)" +msgstr "noildze (vesels skaitlis)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:726 +#: sssd.conf.5.xml:769 msgid "" "This option specifies the maximum number of file descriptors that may be " -"opened at one time by this SSSD process. On systems where SSSD is granted " -"the CAP_SYS_RESOURCE capability, this will be an absolute setting. On " -"systems without this capability, the resulting value will be the lower value " -"of this or the limits.conf \"hard\" limit." +"opened at one time by this SSSD process. Note this value will be capped by " +"the init system at the startup of SSSD, see e.g. man systemd.exec for " +"details." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:735 +#: sssd.conf.5.xml:776 msgid "Default: 8192 (or limits.conf \"hard\" limit)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:740 -msgid "client_idle_timeout" -msgstr "" +#: sssd.conf.5.xml:781 +#, fuzzy +#| msgid "timeout (integer)" +msgid "client_idle_timeout (integer)" +msgstr "noildze (vesels skaitlis)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:743 +#: sssd.conf.5.xml:784 msgid "" "This option specifies the number of seconds that a client of an SSSD process " "can hold onto a file descriptor without communicating on it. This value is " @@ -957,150 +1021,21 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:752 +#: sssd.conf.5.xml:793 #, fuzzy #| msgid "Default: 300" msgid "Default: 60, KCM: 300" msgstr "Noklusējuma: 300" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:757 -msgid "offline_timeout (integer)" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:760 -msgid "" -"When SSSD switches to offline mode the amount of time before it tries to go " -"back online will increase based upon the time spent disconnected. By " -"default SSSD uses incremental behaviour to calculate delay in between " -"retries. So, the wait time for a given retry will be longer than the wait " -"time for the previous ones. After each unsuccessful attempt to go online, " -"the new interval is recalculated by the following:" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:771 sssd.conf.5.xml:827 -msgid "" -"new_delay = Minimum(old_delay * 2, offline_timeout_max) + " -"random[0...offline_timeout_random_offset]" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:774 -msgid "" -"The offline_timeout default value is 60. The offline_timeout_max default " -"value is 3600. The offline_timeout_random_offset default value is 30. The " -"end result is amount of seconds before next retry." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:780 -msgid "" -"Note that the maximum length of each interval is defined by " -"offline_timeout_max (apart of random part)." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:784 sssd.conf.5.xml:1110 sssd.conf.5.xml:1490 -#: sssd.conf.5.xml:1791 sssd-ldap.5.xml:550 -msgid "Default: 60" -msgstr "Noklusējuma: 60" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:789 -#, fuzzy -#| msgid "timeout (integer)" -msgid "offline_timeout_max (integer)" -msgstr "noildze (vesels skaitlis)" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:792 -msgid "" -"Controls by how much the time between attempts to go online can be " -"incremented following unsuccessful attempts to go online." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:797 -msgid "A value of 0 disables the incrementing behaviour." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:800 -msgid "" -"The value of this parameter should be set in correlation to offline_timeout " -"parameter value." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:804 -msgid "" -"With offline_timeout set to 60 (default value) there is no point in setting " -"offlinet_timeout_max to less than 120 as it will saturate instantly. General " -"rule here should be to set offline_timeout_max to at least 4 times " -"offline_timeout." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:810 -msgid "" -"Although a value between 0 and offline_timeout may be specified, it has the " -"effect of overriding the offline_timeout value so is of little use." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:815 -#, fuzzy -#| msgid "Default: 300" -msgid "Default: 3600" -msgstr "Noklusējuma: 300" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:820 +#: sssd.conf.5.xml:798 #, fuzzy #| msgid "timeout (integer)" -msgid "offline_timeout_random_offset (integer)" +msgid "responder_idle_timeout (integer)" msgstr "noildze (vesels skaitlis)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:823 -msgid "" -"When SSSD is in offline mode it keeps probing backend servers in specified " -"time intervals:" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:830 -msgid "" -"This parameter controls the value of the random offset used for the above " -"equation. Final random_offset value will be random number in range:" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:835 -msgid "[0 - offline_timeout_random_offset]" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:838 -msgid "A value of 0 disables the random offset addition." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:841 -#, fuzzy -#| msgid "Default: 300" -msgid "Default: 30" -msgstr "Noklusējuma: 300" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:846 -msgid "responder_idle_timeout" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:849 +#: sssd.conf.5.xml:801 msgid "" "This option specifies the number of seconds that an SSSD responder process " "can be up without being used. This value is limited in order to avoid " @@ -1112,58 +1047,59 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:863 sssd.conf.5.xml:1123 sssd.conf.5.xml:2248 +#: sssd.conf.5.xml:815 sssd.conf.5.xml:1079 sssd.conf.5.xml:2285 #: sssd-ldap.5.xml:377 msgid "Default: 300" msgstr "Noklusējuma: 300" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:868 -msgid "cache_first" +#: sssd.conf.5.xml:820 +msgid "cache_first (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:871 +#: sssd.conf.5.xml:823 msgid "" "This option specifies whether the responder should query all caches before " "querying the Data Providers." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:883 +#: sssd.conf.5.xml:835 msgid "NSS configuration options" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:885 +#: sssd.conf.5.xml:837 msgid "" -"These options can be used to configure the Name Service Switch (NSS) service." +"These options can be used to configure the Name Service Switch (NSS) service " +"and should be specified under the <quote>[nss]</quote> section." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:890 +#: sssd.conf.5.xml:843 msgid "enum_cache_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:893 +#: sssd.conf.5.xml:846 msgid "" "How many seconds should nss_sss cache enumerations (requests for info about " "all users)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:897 +#: sssd.conf.5.xml:850 msgid "Default: 120" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:902 +#: sssd.conf.5.xml:855 msgid "entry_cache_nowait_percentage (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:905 +#: sssd.conf.5.xml:858 msgid "" "The entry cache can be set to automatically update entries in the background " "if they are requested beyond a percentage of the entry_cache_timeout value " @@ -1171,7 +1107,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:911 +#: sssd.conf.5.xml:864 msgid "" "For example, if the domain's entry_cache_timeout is set to 30s and " "entry_cache_nowait_percentage is set to 50 (percent), entries that come in " @@ -1181,7 +1117,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:921 +#: sssd.conf.5.xml:874 msgid "" "Valid values for this option are 0-99 and represent a percentage of the " "entry_cache_timeout for each domain. For performance reasons, this " @@ -1190,17 +1126,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:929 sssd.conf.5.xml:2061 +#: sssd.conf.5.xml:882 sssd.conf.5.xml:2093 msgid "Default: 50" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:934 +#: sssd.conf.5.xml:887 msgid "entry_negative_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:937 +#: sssd.conf.5.xml:890 msgid "" "Specifies for how many seconds nss_sss should cache negative cache hits " "(that is, queries for invalid database entries, like nonexistent ones) " @@ -1208,17 +1144,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:943 sssd.conf.5.xml:1685 sssd.conf.5.xml:2085 +#: sssd.conf.5.xml:896 sssd.conf.5.xml:1677 sssd.conf.5.xml:2119 msgid "Default: 15" msgstr "Noklusējuma: 15" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:948 +#: sssd.conf.5.xml:901 msgid "filter_users, filter_groups (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:951 +#: sssd.conf.5.xml:904 msgid "" "Exclude certain users or groups from being fetched from the sss NSS " "database. This is particularly useful for system accounts. This option can " @@ -1227,7 +1163,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:959 +#: sssd.conf.5.xml:912 msgid "" "NOTE: The filter_groups option doesn't affect inheritance of nested group " "members, since filtering happens after they are propagated for returning via " @@ -1236,41 +1172,41 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:967 +#: sssd.conf.5.xml:920 msgid "Default: root" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:972 -msgid "filter_users_in_groups (bool)" +#: sssd.conf.5.xml:925 +msgid "filter_users_in_groups (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:975 +#: sssd.conf.5.xml:928 msgid "" -"If you want filtered user still be group members set this option to false." +"If you want filtered users to remain group members set this option to false" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:986 +#: sssd.conf.5.xml:939 msgid "fallback_homedir (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:989 +#: sssd.conf.5.xml:942 msgid "" "Set a default template for a user's home directory if one is not specified " "explicitly by the domain's data provider." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:994 +#: sssd.conf.5.xml:947 msgid "" "The available values for this option are the same as for override_homedir." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1000 +#: sssd.conf.5.xml:953 #, no-wrap msgid "" "fallback_homedir = /home/%u\n" @@ -1278,23 +1214,23 @@ msgid "" msgstr "" #. type: Content of: <varlistentry><listitem><para> -#: sssd.conf.5.xml:998 sssd.conf.5.xml:1557 sssd.conf.5.xml:1576 -#: sssd.conf.5.xml:1653 sssd-krb5.5.xml:451 include/override_homedir.xml:78 +#: sssd.conf.5.xml:951 sssd.conf.5.xml:1524 sssd.conf.5.xml:1543 +#: sssd.conf.5.xml:1645 sssd-krb5.5.xml:451 include/override_homedir.xml:78 msgid "example: <placeholder type=\"programlisting\" id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1004 +#: sssd.conf.5.xml:957 msgid "Default: not set (no substitution for unset home directories)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1010 +#: sssd.conf.5.xml:963 msgid "override_shell (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1013 +#: sssd.conf.5.xml:966 msgid "" "Override the login shell for all users. This option supersedes any other " "shell options if it takes effect and can be set either in the [nss] section " @@ -1302,47 +1238,47 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1019 +#: sssd.conf.5.xml:972 msgid "Default: not set (SSSD will use the value retrieved from LDAP)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1025 +#: sssd.conf.5.xml:978 msgid "allowed_shells (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1028 +#: sssd.conf.5.xml:981 msgid "" "Restrict user shell to one of the listed values. The order of evaluation is:" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1031 +#: sssd.conf.5.xml:984 msgid "1. If the shell is present in <quote>/etc/shells</quote>, it is used." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1035 +#: sssd.conf.5.xml:988 msgid "" "2. If the shell is in the allowed_shells list but not in <quote>/etc/shells</" "quote>, use the value of the shell_fallback parameter." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1040 +#: sssd.conf.5.xml:993 msgid "" "3. If the shell is not in the allowed_shells list and not in <quote>/etc/" "shells</quote>, a nologin shell is used." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1045 +#: sssd.conf.5.xml:998 msgid "The wildcard (*) can be used to allow any shell." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1048 +#: sssd.conf.5.xml:1001 msgid "" "The (*) is useful if you want to use shell_fallback in case that user's " "shell is not in <quote>/etc/shells</quote> and maintaining list of all " @@ -1350,115 +1286,121 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1055 +#: sssd.conf.5.xml:1008 msgid "An empty string for shell is passed as-is to libc." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1058 +#: sssd.conf.5.xml:1011 msgid "" "The <quote>/etc/shells</quote> is only read on SSSD start up, which means " "that a restart of the SSSD is required in case a new shell is installed." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1062 +#: sssd.conf.5.xml:1015 msgid "Default: Not set. The user shell is automatically used." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1067 +#: sssd.conf.5.xml:1020 msgid "vetoed_shells (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1070 +#: sssd.conf.5.xml:1023 msgid "Replace any instance of these shells with the shell_fallback" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1075 +#: sssd.conf.5.xml:1031 msgid "shell_fallback (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1078 +#: sssd.conf.5.xml:1034 msgid "" "The default shell to use if an allowed shell is not installed on the machine." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1082 +#: sssd.conf.5.xml:1038 msgid "Default: /bin/sh" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1087 -msgid "default_shell" +#: sssd.conf.5.xml:1043 +msgid "default_shell (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1090 +#: sssd.conf.5.xml:1046 msgid "" "The default shell to use if the provider does not return one during lookup. " "This option can be specified globally in the [nss] section or per-domain." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1096 +#: sssd.conf.5.xml:1052 msgid "" "Default: not set (Return NULL if no shell is specified and rely on libc to " "substitute something sensible when necessary, usually /bin/sh)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1103 sssd.conf.5.xml:1483 +#: sssd.conf.5.xml:1059 sssd.conf.5.xml:1450 msgid "get_domains_timeout (int)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1106 sssd.conf.5.xml:1486 +#: sssd.conf.5.xml:1062 sssd.conf.5.xml:1453 msgid "" "Specifies time in seconds for which the list of subdomains will be " "considered valid." msgstr "" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1066 sssd.conf.5.xml:1457 sssd.conf.5.xml:1788 +#: sssd.conf.5.xml:2862 sssd-ldap.5.xml:550 +msgid "Default: 60" +msgstr "Noklusējuma: 60" + #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1115 +#: sssd.conf.5.xml:1071 #, fuzzy #| msgid "timeout (integer)" msgid "memcache_timeout (integer)" msgstr "noildze (vesels skaitlis)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1118 +#: sssd.conf.5.xml:1074 msgid "" "Specifies time in seconds for which records in the in-memory cache will be " "valid. Setting this option to zero will disable the in-memory cache." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1126 +#: sssd.conf.5.xml:1082 msgid "" "WARNING: Disabling the in-memory cache will have significant negative impact " "on SSSD's performance and should only be used for testing." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1132 sssd.conf.5.xml:1157 sssd.conf.5.xml:1182 -#: sssd.conf.5.xml:1207 sssd.conf.5.xml:1234 +#: sssd.conf.5.xml:1088 sssd.conf.5.xml:1113 sssd.conf.5.xml:1138 +#: sssd.conf.5.xml:1163 sssd.conf.5.xml:1190 msgid "" "NOTE: If the environment variable SSS_NSS_USE_MEMCACHE is set to \"NO\", " "client applications will not use the fast in-memory cache." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1140 +#: sssd.conf.5.xml:1096 msgid "memcache_size_passwd (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1143 +#: sssd.conf.5.xml:1099 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for passwd requests. Setting the size to 0 will disable the passwd in-" @@ -1466,27 +1408,27 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1149 sssd.conf.5.xml:2888 sssd-ldap.5.xml:604 +#: sssd.conf.5.xml:1105 sssd.conf.5.xml:3013 sssd-ldap.5.xml:604 msgid "Default: 8" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1152 sssd.conf.5.xml:1177 sssd.conf.5.xml:1202 -#: sssd.conf.5.xml:1229 +#: sssd.conf.5.xml:1108 sssd.conf.5.xml:1133 sssd.conf.5.xml:1158 +#: sssd.conf.5.xml:1185 msgid "" "WARNING: Disabled or too small in-memory cache can have significant negative " "impact on SSSD's performance." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1165 +#: sssd.conf.5.xml:1121 #, fuzzy #| msgid "timeout (integer)" msgid "memcache_size_group (integer)" msgstr "noildze (vesels skaitlis)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1168 +#: sssd.conf.5.xml:1124 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for group requests. Setting the size to 0 will disable the group in-memory " @@ -1494,19 +1436,19 @@ msgid "" msgstr "" #. type: Content of: <variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1174 sssd.conf.5.xml:1226 sssd.conf.5.xml:3656 +#: sssd.conf.5.xml:1130 sssd.conf.5.xml:1182 sssd.conf.5.xml:3835 #: sssd-ldap.5.xml:534 sssd-ldap.5.xml:581 include/failover.xml:116 #: include/krb5_options.xml:11 msgid "Default: 6" msgstr "Noklusējuma: 6" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1190 +#: sssd.conf.5.xml:1146 msgid "memcache_size_initgroups (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1193 +#: sssd.conf.5.xml:1149 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for initgroups requests. Setting the size to 0 will disable the initgroups " @@ -1514,14 +1456,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1215 +#: sssd.conf.5.xml:1171 #, fuzzy #| msgid "timeout (integer)" msgid "memcache_size_sid (integer)" msgstr "noildze (vesels skaitlis)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1218 +#: sssd.conf.5.xml:1174 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for SID related requests. Only SID-by-ID and ID-by-SID requests are " @@ -1530,12 +1472,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1242 sssd-ifp.5.xml:90 +#: sssd.conf.5.xml:1198 sssd-ifp.5.xml:90 msgid "user_attributes (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1245 +#: sssd.conf.5.xml:1201 msgid "" "Some of the additional NSS responder requests can return more attributes " "than just the POSIX ones defined by the NSS interface. The list of " @@ -1546,105 +1488,111 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1258 +#: sssd.conf.5.xml:1214 msgid "" "To make configuration more easy the NSS responder will check the InfoPipe " "option if it is not set for the NSS responder." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1263 +#: sssd.conf.5.xml:1219 msgid "Default: not set, fallback to InfoPipe option" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1268 +#: sssd.conf.5.xml:1224 msgid "pwfield (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1271 +#: sssd.conf.5.xml:1227 msgid "" "The value that NSS operations that return users or groups will return for " "the <quote>password</quote> field." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1276 +#: sssd.conf.5.xml:1232 +msgid "" +"This option can also be set per-domain, which overwrites the value in the " +"<quote>[nss]</quote> section for that domain. This is particularly useful " +"when using a proxy domain with <option>proxy_lib_name=files</option> and a " +"<option>proxy_pam_target</option> other than <quote>sssd-shadowutils</" +"quote>. In that case, SSSD returns <quote>*</quote> for the password field " +"by default, which causes <command>pam_unix</command> to treat all accounts " +"as locked. Setting <option>pwfield = x</option> in the domain section " +"restores the expected behavior." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1246 #, fuzzy #| msgid "Default: <quote>permit</quote>" msgid "Default: <quote>*</quote>" msgstr "Noklusējuma: <quote>atļaut</quote>" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1279 -msgid "" -"Note: This option can also be set per-domain which overwrites the value in " -"[nss] section." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1283 +#: sssd.conf.5.xml:1249 msgid "" -"Default: <quote>not set</quote> (remote domains), <quote>x</quote> (proxy " -"domain with nss_files and sssd-shadowutils target)" +"Default (per-domain): <quote>not set</quote> (remote domains), <quote>x</" +"quote> (proxy domain with nss_files and sssd-shadowutils target)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:1292 +#: sssd.conf.5.xml:1258 msgid "PAM configuration options" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:1294 +#: sssd.conf.5.xml:1260 msgid "" "These options can be used to configure the Pluggable Authentication Module " -"(PAM) service." +"(PAM) service and should be specified under the <quote>[pam]</quote> section." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1299 +#: sssd.conf.5.xml:1266 msgid "offline_credentials_expiration (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1302 +#: sssd.conf.5.xml:1269 msgid "" "If the authentication provider is offline, how long should we allow cached " "logins (in days since the last successful online login)." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1307 sssd.conf.5.xml:1320 +#: sssd.conf.5.xml:1274 sssd.conf.5.xml:1287 msgid "Default: 0 (No limit)" msgstr "Noklusējuma: 0 (bez ierobežojuma)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1313 +#: sssd.conf.5.xml:1280 msgid "offline_failed_login_attempts (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1316 +#: sssd.conf.5.xml:1283 msgid "" "If the authentication provider is offline, how many failed login attempts " "are allowed." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1326 +#: sssd.conf.5.xml:1293 msgid "offline_failed_login_delay (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1329 +#: sssd.conf.5.xml:1296 msgid "" "The time in minutes which has to pass after offline_failed_login_attempts " "has been reached before a new login attempt is possible." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1334 +#: sssd.conf.5.xml:1301 msgid "" "If set to 0 the user cannot authenticate offline if " "offline_failed_login_attempts has been reached. Only a successful online " @@ -1652,59 +1600,59 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1340 sssd.conf.5.xml:1450 +#: sssd.conf.5.xml:1307 sssd.conf.5.xml:1417 msgid "Default: 5" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1346 +#: sssd.conf.5.xml:1313 msgid "pam_verbosity (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1349 +#: sssd.conf.5.xml:1316 msgid "" "Controls what kind of messages are shown to the user during authentication. " "The higher the number to more messages are displayed." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1354 +#: sssd.conf.5.xml:1321 msgid "Currently sssd supports the following values:" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1357 +#: sssd.conf.5.xml:1324 msgid "<emphasis>0</emphasis>: do not show any message" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1360 +#: sssd.conf.5.xml:1327 msgid "<emphasis>1</emphasis>: show only important messages" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1364 +#: sssd.conf.5.xml:1331 msgid "<emphasis>2</emphasis>: show informational messages" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1367 +#: sssd.conf.5.xml:1334 msgid "<emphasis>3</emphasis>: show all messages and debug information" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1371 sssd.8.xml:63 +#: sssd.conf.5.xml:1338 sssd.8.xml:63 msgid "Default: 1" msgstr "Noklusējuma: 1" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1377 +#: sssd.conf.5.xml:1344 msgid "pam_response_filter (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1380 +#: sssd.conf.5.xml:1347 msgid "" "A comma separated list of strings which allows to remove (filter) data sent " "by the PAM responder to pam_sss PAM module. There are different kind of " @@ -1713,51 +1661,51 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1388 +#: sssd.conf.5.xml:1355 msgid "" "While messages already can be controlled with the help of the pam_verbosity " "option this option allows to filter out other kind of responses as well." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1395 +#: sssd.conf.5.xml:1362 msgid "ENV" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1396 +#: sssd.conf.5.xml:1363 msgid "Do not send any environment variables to any service." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1399 +#: sssd.conf.5.xml:1366 msgid "ENV:var_name" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1400 +#: sssd.conf.5.xml:1367 msgid "Do not send environment variable var_name to any service." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1404 +#: sssd.conf.5.xml:1371 msgid "ENV:var_name:service" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1405 +#: sssd.conf.5.xml:1372 msgid "Do not send environment variable var_name to service." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1393 +#: sssd.conf.5.xml:1360 msgid "" "Currently the following filters are supported: <placeholder " "type=\"variablelist\" id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1412 +#: sssd.conf.5.xml:1379 msgid "" "The list of strings can either be the list of filters which would set this " "list of filters and overwrite the defaults. Or each element of the list can " @@ -1768,23 +1716,23 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1423 +#: sssd.conf.5.xml:1390 msgid "Default: ENV:KRB5CCNAME:sudo, ENV:KRB5CCNAME:sudo-i" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1426 +#: sssd.conf.5.xml:1393 msgid "" "Example: -ENV:KRB5CCNAME:sudo-i will remove the filter from the default list" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1433 +#: sssd.conf.5.xml:1400 msgid "pam_id_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1436 +#: sssd.conf.5.xml:1403 msgid "" "For any PAM request while SSSD is online, the SSSD will attempt to " "immediately update the cached identity information for the user in order to " @@ -1792,7 +1740,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1442 +#: sssd.conf.5.xml:1409 msgid "" "A complete PAM conversation may perform multiple PAM requests, such as " "account management and session opening. This option controls (on a per-" @@ -1801,17 +1749,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1456 +#: sssd.conf.5.xml:1423 msgid "pam_pwd_expiration_warning (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1459 sssd.conf.5.xml:2912 +#: sssd.conf.5.xml:1426 sssd.conf.5.xml:3037 msgid "Display a warning N days before the password expires." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1462 +#: sssd.conf.5.xml:1429 msgid "" "Please note that the backend server has to provide information about the " "expiration time of the password. If this information is missing, sssd " @@ -1819,32 +1767,32 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1468 sssd.conf.5.xml:2915 +#: sssd.conf.5.xml:1435 sssd.conf.5.xml:3040 msgid "" "If zero is set, then this filter is not applied, i.e. if the expiration " "warning was received from backend server, it will automatically be displayed." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1473 +#: sssd.conf.5.xml:1440 msgid "" "This setting can be overridden by setting <emphasis>pwd_expiration_warning</" "emphasis> for a particular domain." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1478 sssd.conf.5.xml:3913 sssd-ldap.5.xml:662 +#: sssd.conf.5.xml:1445 sssd.conf.5.xml:4118 sssd-ldap.5.xml:662 #: sssd-ldap.5.xml:1733 sssd.8.xml:79 msgid "Default: 0" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1495 +#: sssd.conf.5.xml:1462 msgid "pam_trusted_users (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1498 +#: sssd.conf.5.xml:1465 msgid "" "Specifies the comma-separated list of UID values or user names that are " "allowed to run PAM conversations against trusted domains. Users not " @@ -1854,74 +1802,74 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1508 +#: sssd.conf.5.xml:1475 msgid "Default: All users are considered trusted by default" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1512 +#: sssd.conf.5.xml:1479 msgid "" "Please note that UID 0 is always allowed to access the PAM responder even in " "case it is not in the pam_trusted_users list." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1519 +#: sssd.conf.5.xml:1486 msgid "pam_public_domains (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1522 +#: sssd.conf.5.xml:1489 msgid "" "Specifies the comma-separated list of domain names that are accessible even " "to untrusted users." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1526 +#: sssd.conf.5.xml:1493 msgid "Two special values for pam_public_domains option are defined:" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1530 +#: sssd.conf.5.xml:1497 msgid "" "all (Untrusted users are allowed to access all domains in PAM responder.)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1534 +#: sssd.conf.5.xml:1501 msgid "" "none (Untrusted users are not allowed to access any domains PAM in " "responder.)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1538 sssd.conf.5.xml:1563 sssd.conf.5.xml:1582 -#: sssd.conf.5.xml:1824 sssd.conf.5.xml:3842 sssd-ldap.5.xml:1270 +#: sssd.conf.5.xml:1505 sssd.conf.5.xml:1530 sssd.conf.5.xml:1549 +#: sssd.conf.5.xml:1821 sssd.conf.5.xml:4048 sssd-ldap.5.xml:1270 msgid "Default: none" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1543 +#: sssd.conf.5.xml:1510 msgid "pam_account_expired_message (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1546 +#: sssd.conf.5.xml:1513 msgid "" "Allows a custom expiration message to be set, replacing the default " "'Permission denied' message." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1551 +#: sssd.conf.5.xml:1518 msgid "" "Note: Please be aware that message is only printed for the SSH service " "unless pam_verbosity is set to 3 (show all messages and debug information)." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1559 +#: sssd.conf.5.xml:1526 #, no-wrap msgid "" "pam_account_expired_message = Account expired, please contact help desk.\n" @@ -1929,19 +1877,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1568 +#: sssd.conf.5.xml:1535 msgid "pam_account_locked_message (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1571 +#: sssd.conf.5.xml:1538 msgid "" "Allows a custom lockout message to be set, replacing the default 'Permission " "denied' message." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1578 +#: sssd.conf.5.xml:1545 #, no-wrap msgid "" "pam_account_locked_message = Account locked, please contact help desk.\n" @@ -1949,81 +1897,120 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1587 -msgid "pam_passkey_auth (bool)" +#: sssd.conf.5.xml:1554 +msgid "pam_passkey_auth (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1590 +#: sssd.conf.5.xml:1557 msgid "Enable passkey device based authentication." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1593 sssd.conf.5.xml:1910 sssd-ad.5.xml:1286 +#: sssd.conf.5.xml:1560 sssd.conf.5.xml:1907 sssd-ad.5.xml:1279 #: sss_rpcidmapd.5.xml:76 msgid "Default: True" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1598 -msgid "passkey_debug_libfido2 (bool)" +#: sssd.conf.5.xml:1565 +msgid "passkey_debug_libfido2 (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1601 +#: sssd.conf.5.xml:1568 msgid "Enable libfido2 library debug messages." msgstr "" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1604 sssd.conf.5.xml:1618 sssd-ldap.5.xml:727 -#: sssd-ldap.5.xml:752 sssd-ldap.5.xml:848 sssd-ldap.5.xml:1356 -#: sssd-ad.5.xml:506 sssd-ad.5.xml:582 sssd-ad.5.xml:1155 +#: sssd.conf.5.xml:1571 sssd.conf.5.xml:1585 sssd.conf.5.xml:4781 +#: sssd-ldap.5.xml:727 sssd-ldap.5.xml:752 sssd-ldap.5.xml:848 +#: sssd-ldap.5.xml:1356 sssd-ad.5.xml:506 sssd-ad.5.xml:582 sssd-ad.5.xml:1160 #: include/ldap_id_mapping.xml:250 msgid "Default: False" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1609 -msgid "pam_cert_auth (bool)" +#: sssd.conf.5.xml:1576 +msgid "pam_cert_auth (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1612 +#: sssd.conf.5.xml:1579 msgid "" "Enable certificate based Smartcard authentication. Since this requires " "additional communication with the Smartcard which will delay the " "authentication process this option is disabled by default." msgstr "" +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1588 +msgid "" +"Note: In case OpenSC is used for Smartcard access SSSD supports the " +"filesystem caching in OpenSC when enabled in opensc.conf. The cached files " +"are located in a common <quote>opensc</quote> directory in SSSD's state " +"directory. The behaviour can be changed in opensc.conf" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> +#: sssd.conf.5.xml:1597 +#, no-wrap +msgid "" +"app /usr/libexec/sssd/p11_child {\n" +" framework pkcs15 {\n" +" use_file_caching = no;\n" +" }\n" +"}\n" +"app /usr/libexec/sssd/krb5_child {\n" +" framework pkcs15 {\n" +" use_file_caching = no;\n" +" }\n" +"}\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1595 +msgid "" +"Example opensc.conf (*): <placeholder type=\"programlisting\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1610 +msgid "" +"(*) The actual <quote>libexec</quote> directory for p11_child and krb5_child " +"depends on the distribution." +msgstr "" + #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1623 +#: sssd.conf.5.xml:1615 msgid "pam_cert_db_path (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1626 +#: sssd.conf.5.xml:1618 msgid "The path to the certificate database." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1629 sssd.conf.5.xml:2163 sssd.conf.5.xml:4338 +#: sssd.conf.5.xml:1621 sssd.conf.5.xml:2199 sssd.conf.5.xml:4543 msgid "Default:" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1631 sssd.conf.5.xml:2165 +#: sssd.conf.5.xml:1623 sssd.conf.5.xml:2201 msgid "" "/etc/sssd/pki/sssd_auth_ca_db.pem (path to a file with trusted CA " "certificates in PEM format)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1641 +#: sssd.conf.5.xml:1633 msgid "pam_cert_verification (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1644 +#: sssd.conf.5.xml:1636 msgid "" "With this parameter the PAM certificate verification can be tuned with a " "comma separated list of options that override the " @@ -2033,7 +2020,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1655 +#: sssd.conf.5.xml:1647 #, no-wrap msgid "" "pam_cert_verification = partial_chain\n" @@ -2041,61 +2028,61 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1659 +#: sssd.conf.5.xml:1651 msgid "" "Default: not set, i.e. use default <quote>certificate_verification</quote> " "option defined in <quote>[sssd]</quote> section." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1666 +#: sssd.conf.5.xml:1658 msgid "p11_child_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1669 +#: sssd.conf.5.xml:1661 msgid "How many seconds will pam_sss wait for p11_child to finish." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1678 +#: sssd.conf.5.xml:1670 #, fuzzy #| msgid "timeout (integer)" msgid "passkey_child_timeout (integer)" msgstr "noildze (vesels skaitlis)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1681 +#: sssd.conf.5.xml:1673 msgid "" "How many seconds will the PAM responder wait for passkey_child to finish." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1690 +#: sssd.conf.5.xml:1682 msgid "pam_app_services (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1693 +#: sssd.conf.5.xml:1685 msgid "" "Which PAM services are permitted to contact domains of type " "<quote>application</quote>" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1702 +#: sssd.conf.5.xml:1694 msgid "pam_p11_allowed_services (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1705 +#: sssd.conf.5.xml:1697 msgid "" "A comma-separated list of PAM service names for which it will be allowed to " "use Smartcards." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1720 +#: sssd.conf.5.xml:1712 #, no-wrap msgid "" "pam_p11_allowed_services = +my_pam_service, -login\n" @@ -2103,7 +2090,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1709 +#: sssd.conf.5.xml:1701 msgid "" "It is possible to add another PAM service name to the default set by using " "<quote>+service_name</quote> or to explicitly remove a PAM service name from " @@ -2115,68 +2102,73 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1724 sssd-ad.5.xml:645 sssd-ad.5.xml:754 sssd-ad.5.xml:812 -#: sssd-ad.5.xml:870 sssd-ad.5.xml:948 +#: sssd.conf.5.xml:1716 sssd-ad.5.xml:645 sssd-ad.5.xml:759 sssd-ad.5.xml:817 +#: sssd-ad.5.xml:875 sssd-ad.5.xml:953 msgid "Default: the default set of PAM service names includes:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1729 sssd-ad.5.xml:649 +#: sssd.conf.5.xml:1721 sssd-ad.5.xml:649 msgid "login" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1734 sssd-ad.5.xml:654 +#: sssd.conf.5.xml:1726 sssd-ad.5.xml:654 msgid "su" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1739 sssd-ad.5.xml:659 +#: sssd.conf.5.xml:1731 sssd-ad.5.xml:659 msgid "su-l" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1744 sssd-ad.5.xml:674 +#: sssd.conf.5.xml:1736 sssd-ad.5.xml:674 msgid "gdm-smartcard" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1749 sssd-ad.5.xml:669 +#: sssd.conf.5.xml:1741 sssd-ad.5.xml:669 msgid "gdm-password" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1754 +#: sssd.conf.5.xml:1746 msgid "gdm-switchable-auth" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1759 sssd-ad.5.xml:679 +#: sssd.conf.5.xml:1751 sssd-ad.5.xml:679 msgid "kdm" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1764 sssd-ad.5.xml:957 +#: sssd.conf.5.xml:1756 sssd-ad.5.xml:694 +msgid "plasmalogin" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:1761 sssd-ad.5.xml:962 msgid "sudo" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1769 sssd-ad.5.xml:962 +#: sssd.conf.5.xml:1766 sssd-ad.5.xml:967 msgid "sudo-i" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1774 +#: sssd.conf.5.xml:1771 msgid "gnome-screensaver" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1782 +#: sssd.conf.5.xml:1779 msgid "p11_wait_for_card_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1785 +#: sssd.conf.5.xml:1782 msgid "" "If Smartcard authentication is required how many extra seconds in addition " "to p11_child_timeout should the PAM responder wait until a Smartcard is " @@ -2184,12 +2176,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1796 +#: sssd.conf.5.xml:1793 msgid "p11_uri (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1799 +#: sssd.conf.5.xml:1796 msgid "" "PKCS#11 URI (see RFC-7512 for details) which can be used to restrict the " "selection of devices used for Smartcard authentication. By default SSSD's " @@ -2200,7 +2192,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1812 +#: sssd.conf.5.xml:1809 #, no-wrap msgid "" "p11_uri = pkcs11:slot-description=My%20Smartcard%20Reader\n" @@ -2208,7 +2200,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1816 +#: sssd.conf.5.xml:1813 #, no-wrap msgid "" "p11_uri = pkcs11:library-description=OpenSC%20smartcard%20framework;slot-id=2\n" @@ -2216,7 +2208,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1810 +#: sssd.conf.5.xml:1807 msgid "" "Example: <placeholder type=\"programlisting\" id=\"0\"/> or <placeholder " "type=\"programlisting\" id=\"1\"/> To find suitable URI please check the " @@ -2225,47 +2217,47 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1829 -msgid "pam_initgroups_scheme" +#: sssd.conf.5.xml:1826 +msgid "pam_initgroups_scheme (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1837 +#: sssd.conf.5.xml:1834 msgid "always" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1838 +#: sssd.conf.5.xml:1835 msgid "" "Always do an online lookup, please note that pam_id_timeout still applies" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1842 +#: sssd.conf.5.xml:1839 msgid "no_session" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1843 +#: sssd.conf.5.xml:1840 msgid "" "Only do an online lookup if there is no active session of the user, i.e. if " "the user is currently not logged in" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1848 sssd-ldap.5.xml:189 +#: sssd.conf.5.xml:1845 sssd-ldap.5.xml:189 msgid "never" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1849 +#: sssd.conf.5.xml:1846 msgid "" "Never force an online lookup, use the data from the cache as long as they " "are not expired" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1832 +#: sssd.conf.5.xml:1829 msgid "" "The PAM responder can force an online lookup to get the current group " "memberships of the user trying to log in. This option controls when this " @@ -2274,30 +2266,30 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1856 +#: sssd.conf.5.xml:1853 msgid "Default: no_session" msgstr "" -#. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:1861 sssd.conf.5.xml:4277 -msgid "pam_gssapi_services" +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1858 +msgid "pam_gssapi_services (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1864 +#: sssd.conf.5.xml:1861 msgid "" "Comma separated list of PAM services that are allowed to try GSSAPI " "authentication using pam_sss_gss.so module." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1869 +#: sssd.conf.5.xml:1866 msgid "" "To disable GSSAPI authentication, set this option to <quote>-</quote> (dash)." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1873 sssd.conf.5.xml:1904 sssd.conf.5.xml:1942 +#: sssd.conf.5.xml:1870 sssd.conf.5.xml:1901 sssd.conf.5.xml:1939 msgid "" "Note: This option can also be set per-domain which overwrites the value in " "[pam] section. It can also be set for trusted domain which overwrites the " @@ -2305,7 +2297,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1881 +#: sssd.conf.5.xml:1878 #, no-wrap msgid "" "pam_gssapi_services = sudo, sudo-i\n" @@ -2313,22 +2305,22 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1879 sssd.conf.5.xml:1994 sssd.conf.5.xml:3836 +#: sssd.conf.5.xml:1876 sssd.conf.5.xml:2023 sssd.conf.5.xml:4042 msgid "Example: <placeholder type=\"programlisting\" id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1885 +#: sssd.conf.5.xml:1882 msgid "Default: - (GSSAPI authentication is disabled)" msgstr "" -#. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:1890 sssd.conf.5.xml:4278 -msgid "pam_gssapi_check_upn" +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1887 +msgid "pam_gssapi_check_upn (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1893 +#: sssd.conf.5.xml:1890 msgid "" "If True, SSSD will require that the Kerberos user principal that " "successfully authenticated through GSSAPI can be associated with the user " @@ -2336,19 +2328,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1900 +#: sssd.conf.5.xml:1897 msgid "" -"If False, every user that is able to obtained required service ticket will " +"If False, every user that is able to obtain a required service ticket will " "be authenticated." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1915 -msgid "pam_gssapi_indicators_map" +#: sssd.conf.5.xml:1912 +msgid "pam_gssapi_indicators_map (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1918 +#: sssd.conf.5.xml:1915 msgid "" "Comma separated list of authentication indicators required to be present in " "a Kerberos ticket to access a PAM service that is allowed to try GSSAPI " @@ -2356,7 +2348,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1924 +#: sssd.conf.5.xml:1921 msgid "" "Each element of the list can be either an authentication indicator name or a " "pair <quote>service:indicator</quote>. Indicators not prefixed with the PAM " @@ -2371,7 +2363,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1937 +#: sssd.conf.5.xml:1934 msgid "" "To disable GSSAPI authentication indicator check, set this option to <quote>-" "</quote> (dash). To disable the check for a specific PAM service, add " @@ -2379,83 +2371,124 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1948 +#: sssd.conf.5.xml:1945 msgid "" "Following authentication indicators are supported by IPA Kerberos " "deployments:" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1951 +#: sssd.conf.5.xml:1948 msgid "" "pkinit -- pre-authentication using X.509 certificates -- whether stored in " "files or on smart cards." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1954 +#: sssd.conf.5.xml:1951 msgid "" "hardened -- SPAKE pre-authentication or any pre-authentication wrapped in a " "FAST channel." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1957 +#: sssd.conf.5.xml:1954 msgid "radius -- pre-authentication with the help of a RADIUS server." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1960 +#: sssd.conf.5.xml:1957 msgid "" "otp -- pre-authentication using integrated two-factor authentication (2FA or " "one-time password, OTP) in IPA." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1963 +#: sssd.conf.5.xml:1960 msgid "idp -- pre-authentication using external identity provider." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1973 +#: sssd.conf.5.xml:1970 +#, no-wrap +msgid "" +"pam_gssapi_indicators_map = sudo:pkinit, sudo-i:pkinit\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1965 +msgid "" +"Example: to require access to SUDO services only for users which obtained " +"their Kerberos tickets with a X.509 certificate pre-authentication (PKINIT), " +"set <placeholder type=\"programlisting\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1974 +msgid "Default: not set (use of authentication indicators is not required)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1979 +msgid "pam_gssapi_indicators_apply (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1982 +msgid "" +"Comma separated list of triples to assign additional information from the " +"Kerberos ticket, e.g. a SID from the PAC, to authentication indicators." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1988 +#, fuzzy +#| msgid "The two mechanisms currently supported are:" +msgid "Currently supported is:" +msgstr "Divi pašlaik atbalstītie mehānismi ir:" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:1991 +msgid "SID:S-1-5-[domain]-[RID]:[authentication indicator]" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> +#: sssd.conf.5.xml:2002 #, no-wrap msgid "" -"pam_gssapi_indicators_map = sudo:pkinit, sudo-i:pkinit\n" +"pam_gssapi_indicators_apply = SID:S-1-5-12345-23456-34567-4321:pkinit\n" " " msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1968 +#: sssd.conf.5.xml:1996 msgid "" -"Example: to require access to SUDO services only for users which obtained " -"their Kerberos tickets with a X.509 certificate pre-authentication (PKINIT), " -"set <placeholder type=\"programlisting\" id=\"0\"/>" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1977 -msgid "Default: not set (use of authentication indicators is not required)" +"Example: To assign a SID, which is e.g. set by Active Directory's " +"Authentication Mechanism Assurance (AMA) if the AD user used a Smartcard for " +"authentication, to the 'pkinit' authentication indicator use: <placeholder " +"type=\"programlisting\" id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1982 +#: sssd.conf.5.xml:2011 msgid "pam_json_services (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1985 +#: sssd.conf.5.xml:2014 msgid "" "Comma separated list of PAM services which can handle the JSON protocol for " "selecting authentication mechanisms" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1990 +#: sssd.conf.5.xml:2019 msgid "To disable JSON protocol, set this option to <quote>-</quote> (dash)." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1996 +#: sssd.conf.5.xml:2025 #, no-wrap msgid "" "pam_json_services = gdm-switchable-auth\n" @@ -2463,52 +2496,59 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2000 +#: sssd.conf.5.xml:2029 msgid "Default: - (JSON protocol is disabled)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2003 +#: sssd.conf.5.xml:2032 msgid "" "Note: 2-Factor Authentication (2FA) is not supported. If 2FA is required, do " "not activate the JSON protocol." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:2013 +#: sssd.conf.5.xml:2042 msgid "SUDO configuration options" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2015 +#: sssd.conf.5.xml:2044 msgid "" -"These options can be used to configure the sudo service. The detailed " -"instructions for configuration of <citerefentry> <refentrytitle>sudo</" -"refentrytitle> <manvolnum>8</manvolnum> </citerefentry> to work with " -"<citerefentry> <refentrytitle>sssd</refentrytitle> <manvolnum>8</manvolnum> " -"</citerefentry> are in the manual page <citerefentry> <refentrytitle>sssd-" -"sudo</refentrytitle> <manvolnum>5</manvolnum> </citerefentry>." +"These options can be used to configure the sudo service and should be " +"specified under the <quote>[sudo]</quote> section." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:2048 +msgid "" +"The detailed instructions for configuration of <citerefentry> " +"<refentrytitle>sudo</refentrytitle> <manvolnum>8</manvolnum> </citerefentry> " +"to work with <citerefentry> <refentrytitle>sssd</refentrytitle> " +"<manvolnum>8</manvolnum> </citerefentry> are in the manual page " +"<citerefentry> <refentrytitle>sssd-sudo</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry>." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2032 -msgid "sudo_timed (bool)" +#: sssd.conf.5.xml:2064 +msgid "sudo_timed (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2035 +#: sssd.conf.5.xml:2067 msgid "" "Whether or not to evaluate the sudoNotBefore and sudoNotAfter attributes " "that implement time-dependent sudoers entries." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2047 +#: sssd.conf.5.xml:2079 msgid "sudo_threshold (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2050 +#: sssd.conf.5.xml:2082 msgid "" "Maximum number of expired rules that can be refreshed at once. If number of " "expired rules is below threshold, those rules are refreshed with " @@ -2518,22 +2558,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:2069 +#: sssd.conf.5.xml:2101 msgid "AUTOFS configuration options" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2071 -msgid "These options can be used to configure the autofs service." +#: sssd.conf.5.xml:2103 +msgid "" +"These options can be used to configure the autofs service and should be " +"specified under the <quote>[autofs]</quote> section." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2075 +#: sssd.conf.5.xml:2109 msgid "autofs_negative_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2078 +#: sssd.conf.5.xml:2112 msgid "" "Specifies for how many seconds should the autofs responder negative cache " "hits (that is, queries for invalid map entries, like nonexistent ones) " @@ -2541,22 +2583,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:2094 +#: sssd.conf.5.xml:2128 msgid "SSH configuration options" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2096 -msgid "These options can be used to configure the SSH service." +#: sssd.conf.5.xml:2130 +msgid "" +"These options can be used to configure the SSH service and should be " +"specified under the <quote>[ssh]</quote> section." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2100 -msgid "ssh_use_certificate_keys (bool)" +#: sssd.conf.5.xml:2136 +msgid "ssh_use_certificate_keys (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2103 +#: sssd.conf.5.xml:2139 msgid "" "If set to true the <command>sss_ssh_authorizedkeys</command> will return ssh " "keys derived from the public key of X.509 certificates stored in the user " @@ -2565,12 +2609,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2118 +#: sssd.conf.5.xml:2154 msgid "ssh_use_certificate_matching_rules (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2121 +#: sssd.conf.5.xml:2157 msgid "" "By default the ssh responder will use all available certificate matching " "rules to filter the certificates so that ssh keys are only derived from the " @@ -2580,7 +2624,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2130 +#: sssd.conf.5.xml:2166 msgid "" "There are two special key words 'all_rules' and 'no_rules' which will enable " "all or no rules, respectively. The latter means that no certificates will be " @@ -2588,7 +2632,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2137 +#: sssd.conf.5.xml:2173 msgid "" "If no rules are configured using 'all_rules' will enable a default rule " "which enables all certificates suitable for client authentication. This is " @@ -2597,38 +2641,38 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2144 +#: sssd.conf.5.xml:2180 msgid "" "A non-existing rule name is considered an error. If as a result no rule is " "selected all certificates will be ignored." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2149 +#: sssd.conf.5.xml:2185 msgid "" "Default: not set, equivalent to 'all_rules', all found rules or the default " "rule are used" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2155 +#: sssd.conf.5.xml:2191 msgid "ca_db (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2158 +#: sssd.conf.5.xml:2194 msgid "" "Path to a storage of trusted CA certificates. The option is used to validate " "user certificates before deriving public ssh keys from them." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:2178 +#: sssd.conf.5.xml:2214 msgid "PAC responder configuration options" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2180 +#: sssd.conf.5.xml:2216 msgid "" "The PAC responder works together with the authorization data plugin for MIT " "Kerberos sssd_pac_plugin.so and a sub-domain provider. The plugin sends the " @@ -2639,7 +2683,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:2189 +#: sssd.conf.5.xml:2225 msgid "" "If the remote user does not exist in the cache, it is created. The UID is " "determined with the help of the SID, trusted domains will have UPGs and the " @@ -2650,24 +2694,26 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:2197 +#: sssd.conf.5.xml:2233 msgid "" "If there are SIDs of groups from domains sssd knows about, the user will be " "added to those groups." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2203 -msgid "These options can be used to configure the PAC responder." +#: sssd.conf.5.xml:2239 +msgid "" +"These options can be used to configure the PAC responder and should be " +"specified under the <quote>[pac]</quote> section." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2207 sssd-ifp.5.xml:66 +#: sssd.conf.5.xml:2244 sssd-ifp.5.xml:66 msgid "allowed_uids (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2210 +#: sssd.conf.5.xml:2247 msgid "" "Specifies the comma-separated list of UID values or user names that are " "allowed to access the PAC responder. User names are resolved to UIDs at " @@ -2675,19 +2721,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2216 +#: sssd.conf.5.xml:2253 msgid "" "Default: 0, &sssd_user_name; (only root and SSSD service users are allowed " "to access the PAC responder)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2220 +#: sssd.conf.5.xml:2257 msgid "Default: 0 (only the root user is allowed to access the PAC responder)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2224 +#: sssd.conf.5.xml:2261 msgid "" "Please note that defaults will be overwritten with this option. If you still " "want to allow the root and/or '&sssd_user_name;' user to access the PAC " @@ -2696,7 +2742,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2231 +#: sssd.conf.5.xml:2268 msgid "" "Please note that although the UID 0 is used as the default it will be " "overwritten with this option. If you still want to allow the root user to " @@ -2705,24 +2751,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2240 +#: sssd.conf.5.xml:2277 msgid "pac_lifetime (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2243 +#: sssd.conf.5.xml:2280 msgid "" "Lifetime of the PAC entry in seconds. As long as the PAC is valid the PAC " "data can be used to determine the group memberships of a user." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2253 +#: sssd.conf.5.xml:2290 msgid "pac_check (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2256 +#: sssd.conf.5.xml:2293 msgid "" "Apply additional checks on the PAC of the Kerberos ticket which is available " "in Active Directory and FreeIPA domains, if configured. Please note that " @@ -2733,7 +2779,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2266 +#: sssd.conf.5.xml:2303 msgid "" "Please note that the checks listed below only apply to PACs issued by Active " "Directory or recent versions of FreeIPA. PACs issued e.g. by a plain MIT " @@ -2741,24 +2787,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2277 +#: sssd.conf.5.xml:2314 msgid "no_check" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2279 +#: sssd.conf.5.xml:2316 msgid "" "The PAC must not be present and even if it is present no additional checks " "will be done." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2285 +#: sssd.conf.5.xml:2322 msgid "pac_present" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2287 +#: sssd.conf.5.xml:2324 msgid "" "The PAC must be present in the service ticket which SSSD will request with " "the help of the user's TGT. If the PAC is not available the authentication " @@ -2766,24 +2812,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2295 +#: sssd.conf.5.xml:2332 msgid "check_upn" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2297 +#: sssd.conf.5.xml:2334 msgid "" "If the PAC is present check if the user principal name (UPN) information is " "consistent." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2303 +#: sssd.conf.5.xml:2340 msgid "check_upn_allow_missing" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2305 +#: sssd.conf.5.xml:2342 msgid "" "This option should be used together with 'check_upn' and handles the case " "where a UPN is set on the server-side but is not read by SSSD. The typical " @@ -2795,7 +2841,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2317 +#: sssd.conf.5.xml:2354 msgid "" "Currently this option is set by default to avoid regressions in such " "environments. A log message will be added to the system log and SSSD's debug " @@ -2806,60 +2852,60 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2331 +#: sssd.conf.5.xml:2368 msgid "upn_dns_info_present" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2333 +#: sssd.conf.5.xml:2370 msgid "The PAC must contain the UPN-DNS-INFO buffer, implies 'check_upn'." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2338 +#: sssd.conf.5.xml:2375 msgid "check_upn_dns_info_ex" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2340 +#: sssd.conf.5.xml:2377 msgid "" "If the PAC is present and the extension to the UPN-DNS-INFO buffer is " "available check if the information in the extension is consistent." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2347 +#: sssd.conf.5.xml:2384 msgid "upn_dns_info_ex_present" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2349 +#: sssd.conf.5.xml:2386 msgid "" "The PAC must contain the extension of the UPN-DNS-INFO buffer, implies " "'check_upn_dns_info_ex', 'upn_dns_info_present' and 'check_upn'." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2273 +#: sssd.conf.5.xml:2310 msgid "" "The following options can be used alone or in a comma-separated list: " "<placeholder type=\"variablelist\" id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2359 +#: sssd.conf.5.xml:2396 msgid "" "Default: no_check (AD and IPA provider 'check_upn, check_upn_allow_missing, " "check_upn_dns_info_ex')" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:2368 +#: sssd.conf.5.xml:2405 msgid "Session recording configuration options" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2370 +#: sssd.conf.5.xml:2407 msgid "" "Session recording works in conjunction with <citerefentry> " "<refentrytitle>tlog-rec-session</refentrytitle> <manvolnum>8</manvolnum> </" @@ -2869,66 +2915,78 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2383 -msgid "These options can be used to configure session recording." +#: sssd.conf.5.xml:2420 +msgid "" +"These options can be used to configure session recording and should be " +"specified under the <quote>[session_recording]</quote> section." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:2425 +msgid "" +"Note: Unlike other sections, the <quote>[session_recording]</quote> section " +"ignores <replaceable>debug*</replaceable> options and suitable " +"<replaceable>debug*</replaceable> options must be set in <quote>[pam]</" +"quote>, <quote>[nss]</quote> and <quote>[domain/<replaceable>NAME</" +"replaceable>]</quote> sections." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2387 sssd-session-recording.5.xml:64 +#: sssd.conf.5.xml:2433 sssd-session-recording.5.xml:64 msgid "scope (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2394 sssd-session-recording.5.xml:71 +#: sssd.conf.5.xml:2440 sssd-session-recording.5.xml:71 msgid "\"none\"" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2397 sssd-session-recording.5.xml:74 +#: sssd.conf.5.xml:2443 sssd-session-recording.5.xml:74 msgid "No users are recorded." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2402 sssd-session-recording.5.xml:79 +#: sssd.conf.5.xml:2448 sssd-session-recording.5.xml:79 msgid "\"some\"" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2405 sssd-session-recording.5.xml:82 +#: sssd.conf.5.xml:2451 sssd-session-recording.5.xml:82 msgid "" "Users/groups specified by <replaceable>users</replaceable> and " "<replaceable>groups</replaceable> options are recorded." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2414 sssd-session-recording.5.xml:91 +#: sssd.conf.5.xml:2460 sssd-session-recording.5.xml:91 msgid "\"all\"" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2417 sssd-session-recording.5.xml:94 +#: sssd.conf.5.xml:2463 sssd-session-recording.5.xml:94 msgid "All users are recorded." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2390 sssd-session-recording.5.xml:67 +#: sssd.conf.5.xml:2436 sssd-session-recording.5.xml:67 msgid "" "One of the following strings specifying the scope of session recording: " "<placeholder type=\"variablelist\" id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2424 sssd-session-recording.5.xml:101 +#: sssd.conf.5.xml:2470 sssd-session-recording.5.xml:101 msgid "Default: \"none\"" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2429 sssd-session-recording.5.xml:106 +#: sssd.conf.5.xml:2475 sssd-session-recording.5.xml:106 msgid "users (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2432 sssd-session-recording.5.xml:109 +#: sssd.conf.5.xml:2478 sssd-session-recording.5.xml:109 msgid "" "A comma-separated list of users which should have session recording enabled. " "Matches user names as returned by NSS. I.e. after the possible space " @@ -2936,17 +2994,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2438 sssd-session-recording.5.xml:115 +#: sssd.conf.5.xml:2484 sssd-session-recording.5.xml:115 msgid "Default: Empty. Matches no users." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2443 sssd-session-recording.5.xml:120 +#: sssd.conf.5.xml:2489 sssd-session-recording.5.xml:120 msgid "groups (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2446 sssd-session-recording.5.xml:123 +#: sssd.conf.5.xml:2492 sssd-session-recording.5.xml:123 msgid "" "A comma-separated list of groups, members of which should have session " "recording enabled. Matches group names as returned by NSS. I.e. after the " @@ -2954,7 +3012,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2452 sssd.conf.5.xml:2484 sssd-session-recording.5.xml:129 +#: sssd.conf.5.xml:2498 sssd.conf.5.xml:2530 sssd-session-recording.5.xml:129 #: sssd-session-recording.5.xml:161 msgid "" "NOTE: using this option (having it set to anything) has a considerable " @@ -2963,57 +3021,56 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2459 sssd-session-recording.5.xml:136 +#: sssd.conf.5.xml:2505 sssd-session-recording.5.xml:136 msgid "Default: Empty. Matches no groups." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2464 sssd-session-recording.5.xml:141 +#: sssd.conf.5.xml:2510 sssd-session-recording.5.xml:141 msgid "exclude_users (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2467 sssd-session-recording.5.xml:144 +#: sssd.conf.5.xml:2513 sssd-session-recording.5.xml:144 msgid "" "A comma-separated list of users to be excluded from recording, only " "applicable with 'scope=all'." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2471 sssd-session-recording.5.xml:148 +#: sssd.conf.5.xml:2517 sssd-session-recording.5.xml:148 msgid "Default: Empty. No users excluded." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2476 sssd-session-recording.5.xml:153 +#: sssd.conf.5.xml:2522 sssd-session-recording.5.xml:153 msgid "exclude_groups (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2479 sssd-session-recording.5.xml:156 +#: sssd.conf.5.xml:2525 sssd-session-recording.5.xml:156 msgid "" "A comma-separated list of groups, members of which should be excluded from " "recording. Only applicable with 'scope=all'." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2491 sssd-session-recording.5.xml:168 +#: sssd.conf.5.xml:2537 sssd-session-recording.5.xml:168 msgid "Default: Empty. No groups excluded." msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:2501 +#: sssd.conf.5.xml:2547 msgid "DOMAIN SECTIONS" msgstr "" -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry><para> -#: sssd.conf.5.xml:2508 sssd.conf.5.xml:3964 sssd.conf.5.xml:3965 -#: sssd.conf.5.xml:3968 -msgid "enabled" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2554 +msgid "enabled (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2511 +#: sssd.conf.5.xml:2557 msgid "" "Explicitly enable or disable the domain. If <quote>true</quote>, the domain " "is always <quote>enabled</quote>. If <quote>false</quote>, the domain is " @@ -3023,12 +3080,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2523 +#: sssd.conf.5.xml:2569 msgid "domain_type (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2526 +#: sssd.conf.5.xml:2572 msgid "" "Specifies whether the domain is meant to be used by POSIX-aware clients such " "as the Name Service Switch or by applications that do not need POSIX data to " @@ -3037,14 +3094,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2534 +#: sssd.conf.5.xml:2580 msgid "" "Allowed values for this option are <quote>posix</quote> and " "<quote>application</quote>." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2538 +#: sssd.conf.5.xml:2584 msgid "" "POSIX domains are reachable by all services. Application domains are only " "reachable from the InfoPipe responder (see <citerefentry> " @@ -3053,38 +3110,38 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2546 +#: sssd.conf.5.xml:2592 msgid "" "NOTE: The application domains are currently well tested with " "<quote>id_provider=ldap</quote> only." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2550 +#: sssd.conf.5.xml:2596 msgid "" "For an easy way to configure a non-POSIX domains, please see the " "<quote>Application domains</quote> section." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2554 +#: sssd.conf.5.xml:2600 msgid "Default: posix" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2560 +#: sssd.conf.5.xml:2606 msgid "min_id,max_id (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2563 +#: sssd.conf.5.xml:2609 msgid "" "UID and GID limits for the domain. If a domain contains an entry that is " "outside these limits, it is ignored." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2568 +#: sssd.conf.5.xml:2614 msgid "" "For users, this affects the primary GID limit. The user will not be returned " "to NSS if either the UID or the primary GID is outside the range. For non-" @@ -3093,24 +3150,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2575 +#: sssd.conf.5.xml:2621 msgid "" "These ID limits affect even saving entries to cache, not only returning them " "by name or ID." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2579 +#: sssd.conf.5.xml:2625 msgid "Default: 1 for min_id, 0 (no limit) for max_id" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2585 -msgid "enumerate (bool)" +#: sssd.conf.5.xml:2631 +msgid "enumerate (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2588 +#: sssd.conf.5.xml:2634 msgid "" "Determines if a domain can be enumerated, that is, whether the domain can " "list all the users and group it contains. Note that it is not required to " @@ -3119,36 +3176,36 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2596 +#: sssd.conf.5.xml:2642 msgid "TRUE = Users and groups are enumerated" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2599 +#: sssd.conf.5.xml:2645 msgid "FALSE = No enumerations for this domain" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2602 sssd.conf.5.xml:2867 sssd.conf.5.xml:3044 +#: sssd.conf.5.xml:2648 sssd.conf.5.xml:2992 sssd.conf.5.xml:3174 msgid "Default: FALSE" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2605 +#: sssd.conf.5.xml:2651 msgid "" "Enumerating a domain requires SSSD to download and store ALL user and group " "entries from the remote server." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2610 +#: sssd.conf.5.xml:2656 msgid "" "Feature is only supported for domains with id_provider = ldap or id_provider " "= proxy." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2614 +#: sssd.conf.5.xml:2660 msgid "" "Note: Enabling enumeration has a severe performance impact on SSSD while " "enumeration is running. It may take up to several minutes after SSSD startup " @@ -3162,14 +3219,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2629 +#: sssd.conf.5.xml:2675 msgid "" "While the first enumeration is running, requests for the complete user or " "group lists may return no results until it completes." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2634 +#: sssd.conf.5.xml:2680 msgid "" "Further, enabling enumeration may increase the time necessary to detect " "network disconnection, as longer timeouts are required to ensure that " @@ -3178,14 +3235,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2642 +#: sssd.conf.5.xml:2688 msgid "" "For the reasons cited above, enabling enumeration is not recommended, " "especially in large environments." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2647 +#: sssd.conf.5.xml:2693 msgid "" "Note: the proxy provider is tested with open source modules like " "'libnss_files' and 'libnss_ldap'. 3rd party modules must follow the " @@ -3193,19 +3250,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2656 +#: sssd.conf.5.xml:2702 msgid "entry_cache_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2659 +#: sssd.conf.5.xml:2705 msgid "" "How many seconds should nss_sss consider entries valid before asking the " "backend again" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2663 +#: sssd.conf.5.xml:2709 msgid "" "The cache expiration timestamps are stored as attributes of individual " "objects in the cache. Therefore, changing the cache timeout only has effect " @@ -3216,139 +3273,252 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2676 +#: sssd.conf.5.xml:2722 msgid "Default: 5400" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2682 +#: sssd.conf.5.xml:2728 msgid "entry_cache_user_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2685 +#: sssd.conf.5.xml:2731 msgid "" "How many seconds should nss_sss consider user entries valid before asking " "the backend again" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2689 sssd.conf.5.xml:2702 sssd.conf.5.xml:2715 -#: sssd.conf.5.xml:2728 sssd.conf.5.xml:2742 sssd.conf.5.xml:2755 -#: sssd.conf.5.xml:2769 sssd.conf.5.xml:2783 sssd.conf.5.xml:2796 +#: sssd.conf.5.xml:2735 sssd.conf.5.xml:2748 sssd.conf.5.xml:2761 +#: sssd.conf.5.xml:2774 sssd.conf.5.xml:2788 sssd.conf.5.xml:2801 +#: sssd.conf.5.xml:2815 sssd.conf.5.xml:2829 msgid "Default: entry_cache_timeout" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2695 +#: sssd.conf.5.xml:2741 msgid "entry_cache_group_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2698 +#: sssd.conf.5.xml:2744 msgid "" "How many seconds should nss_sss consider group entries valid before asking " "the backend again" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2708 +#: sssd.conf.5.xml:2754 msgid "entry_cache_netgroup_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2711 +#: sssd.conf.5.xml:2757 msgid "" "How many seconds should nss_sss consider netgroup entries valid before " "asking the backend again" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2721 +#: sssd.conf.5.xml:2767 msgid "entry_cache_service_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2724 +#: sssd.conf.5.xml:2770 msgid "" "How many seconds should nss_sss consider service entries valid before asking " "the backend again" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2734 +#: sssd.conf.5.xml:2780 msgid "entry_cache_resolver_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2737 +#: sssd.conf.5.xml:2783 msgid "" "How many seconds should nss_sss consider hosts and networks entries valid " "before asking the backend again" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2748 +#: sssd.conf.5.xml:2794 msgid "entry_cache_sudo_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2751 +#: sssd.conf.5.xml:2797 msgid "" "How many seconds should sudo consider rules valid before asking the backend " "again" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2761 +#: sssd.conf.5.xml:2807 msgid "entry_cache_autofs_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2764 +#: sssd.conf.5.xml:2810 msgid "" "How many seconds should the autofs service consider automounter maps valid " "before asking the backend again" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2775 +#: sssd.conf.5.xml:2821 msgid "entry_cache_ssh_host_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2778 +#: sssd.conf.5.xml:2824 msgid "" "How many seconds to keep a host ssh key after refresh. IE how long to cache " "the host key for." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2789 -msgid "entry_cache_computer_timeout (integer)" +#: sssd.conf.5.xml:2835 +msgid "offline_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2792 +#: sssd.conf.5.xml:2838 msgid "" -"How many seconds to keep the local computer entry before asking the backend " -"again" +"When SSSD switches to offline mode the amount of time before it tries to go " +"back online will increase based upon the time spent disconnected. By " +"default SSSD uses incremental behaviour to calculate delay in between " +"retries. So, the wait time for a given retry will be longer than the wait " +"time for the previous ones. After each unsuccessful attempt to go online, " +"the new interval is recalculated by the following:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2849 sssd.conf.5.xml:2907 +msgid "" +"new_delay = Minimum(old_delay * 2, offline_timeout_max) + " +"random[0...offline_timeout_random_offset]" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2852 +msgid "" +"The offline_timeout default value is 60. The offline_timeout_max default " +"value is 3600. The offline_timeout_random_offset default value is 30. The " +"end result is the number of seconds before next retry." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2858 +msgid "" +"Note that the maximum length of each interval is defined by " +"offline_timeout_max (apart from the random part)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2868 +#, fuzzy +#| msgid "timeout (integer)" +msgid "offline_timeout_max (integer)" +msgstr "noildze (vesels skaitlis)" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2871 +msgid "" +"Controls by how much the time between attempts to go online can be " +"incremented following unsuccessful attempts to go online." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2876 +msgid "A value of 0 disables the incrementing behaviour." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2879 +msgid "" +"The value of this parameter should be set in correlation to offline_timeout " +"parameter value." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2883 +msgid "" +"With offline_timeout set to 60 (default value) there is no point in setting " +"offline_timeout_max to less than 120 as it will saturate instantly. General " +"rule here should be to set offline_timeout_max to at least 4 times " +"offline_timeout." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2889 +msgid "" +"Although a value between 0 and offline_timeout may be specified, it has the " +"effect of overriding the offline_timeout value so is of little use." msgstr "" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2894 +#, fuzzy +#| msgid "Default: 300" +msgid "Default: 3600" +msgstr "Noklusējuma: 300" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2900 +#, fuzzy +#| msgid "timeout (integer)" +msgid "offline_timeout_random_offset (integer)" +msgstr "noildze (vesels skaitlis)" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2903 +msgid "" +"When SSSD is in offline mode it keeps probing backend servers in specified " +"time intervals:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2910 +msgid "" +"This parameter controls the value of the random offset used for the above " +"equation. Final random_offset value will be random number in range:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2915 +msgid "[0 - offline_timeout_random_offset]" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2918 +msgid "A value of 0 disables the random offset addition." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2921 +#, fuzzy +#| msgid "Default: 300" +msgid "Default: 30" +msgstr "Noklusējuma: 300" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2802 +#: sssd.conf.5.xml:2927 msgid "refresh_expired_interval (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2805 +#: sssd.conf.5.xml:2930 msgid "" "Specifies how many seconds SSSD has to wait before triggering a background " "refresh task which will refresh all expired or nearly expired records." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2810 +#: sssd.conf.5.xml:2935 msgid "" "The background refresh will process users, groups and netgroups in the " "cache. For users who have performed the initgroups (get group membership for " @@ -3357,17 +3527,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2818 +#: sssd.conf.5.xml:2943 msgid "This option is automatically inherited for all trusted domains." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2822 +#: sssd.conf.5.xml:2947 msgid "You can consider setting this value to 3/4 * entry_cache_timeout." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2826 +#: sssd.conf.5.xml:2951 msgid "" "Cache entry will be refreshed by background task when 2/3 of cache timeout " "has already passed. If there are existing cached entries, the background " @@ -3379,18 +3549,18 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2839 sssd-ldap.5.xml:406 sssd-ldap.5.xml:1834 -#: sssd-ipa.5.xml:255 +#: sssd.conf.5.xml:2964 sssd-ldap.5.xml:406 sssd-ldap.5.xml:1834 +#: sssd-ipa.5.xml:250 msgid "Default: 0 (disabled)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2845 -msgid "cache_credentials (bool)" +#: sssd.conf.5.xml:2970 +msgid "cache_credentials (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2848 +#: sssd.conf.5.xml:2973 msgid "" "Determines if user credentials are also cached in the local LDB cache. The " "cached credentials refer to passwords, which includes the first (long term) " @@ -3401,7 +3571,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2859 +#: sssd.conf.5.xml:2984 msgid "" "Take a note that while credentials are stored as a salted SHA512 hash, this " "still potentially poses some security risk in case an attacker manages to " @@ -3410,12 +3580,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2873 +#: sssd.conf.5.xml:2998 msgid "cache_credentials_minimal_first_factor_length (int)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2876 +#: sssd.conf.5.xml:3001 msgid "" "If 2-Factor-Authentication (2FA) is used and credentials should be saved " "this value determines the minimal length the first authentication factor " @@ -3423,19 +3593,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2883 +#: sssd.conf.5.xml:3008 msgid "" "This should avoid that the short PINs of a PIN based 2FA scheme are saved in " "the cache which would make them easy targets for brute-force attacks." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2894 +#: sssd.conf.5.xml:3019 msgid "account_cache_expiration (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2897 +#: sssd.conf.5.xml:3022 msgid "" "Number of days entries are left in cache after last successful login before " "being removed during a cleanup of the cache. 0 means keep forever. The " @@ -3444,17 +3614,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2904 +#: sssd.conf.5.xml:3029 msgid "Default: 0 (unlimited)" msgstr "Noklusējuma: 0 (neierobežots)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2909 +#: sssd.conf.5.xml:3034 msgid "pwd_expiration_warning (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2920 +#: sssd.conf.5.xml:3045 msgid "" "Please note that the backend server has to provide information about the " "expiration time of the password. If this information is missing, sssd " @@ -3463,28 +3633,28 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2927 +#: sssd.conf.5.xml:3052 msgid "Default: 7 (Kerberos), 0 (LDAP)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2933 +#: sssd.conf.5.xml:3058 msgid "id_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2936 +#: sssd.conf.5.xml:3061 msgid "" "The identification provider used for the domain. Supported ID providers are:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2940 +#: sssd.conf.5.xml:3065 msgid "<quote>proxy</quote>: Support a legacy NSS provider." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2943 +#: sssd.conf.5.xml:3068 msgid "" "<quote>ldap</quote>: LDAP provider. See <citerefentry> <refentrytitle>sssd-" "ldap</refentrytitle> <manvolnum>5</manvolnum> </citerefentry> for more " @@ -3492,8 +3662,8 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2951 sssd.conf.5.xml:3070 sssd.conf.5.xml:3129 -#: sssd.conf.5.xml:3192 +#: sssd.conf.5.xml:3076 sssd.conf.5.xml:3200 sssd.conf.5.xml:3259 +#: sssd.conf.5.xml:3322 msgid "" "<quote>ipa</quote>: FreeIPA and Red Hat Identity Management provider. See " "<citerefentry> <refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</" @@ -3501,8 +3671,8 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2960 sssd.conf.5.xml:3079 sssd.conf.5.xml:3138 -#: sssd.conf.5.xml:3201 +#: sssd.conf.5.xml:3085 sssd.conf.5.xml:3209 sssd.conf.5.xml:3268 +#: sssd.conf.5.xml:3331 msgid "" "<quote>ad</quote>: Active Directory provider. See <citerefentry> " "<refentrytitle>sssd-ad</refentrytitle> <manvolnum>5</manvolnum> </" @@ -3510,27 +3680,34 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2968 +#: sssd.conf.5.xml:3093 msgid "" "<quote>idp</quote>: Provider for OAuth 2.0/OIDC based Identity Providers " "(IdP). See <citerefentry> <refentrytitle>sssd-idp</refentrytitle> " "<manvolnum>5</manvolnum> </citerefentry> for more information." msgstr "" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3101 +msgid "" +"Default: Not set (This is a mandatory setting that must be explicitly " +"defined for each configured domain)." +msgstr "" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2979 -msgid "use_fully_qualified_names (bool)" +#: sssd.conf.5.xml:3109 +msgid "use_fully_qualified_names (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2982 +#: sssd.conf.5.xml:3112 msgid "" "Use the full name and domain (as formatted by the domain's full_name_format) " "as the user's login name reported to NSS." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2987 +#: sssd.conf.5.xml:3117 msgid "" "If set to TRUE, all requests to this domain must use fully qualified names. " "For example, if used in EXAMPLE domain that contains a \"test\" user, " @@ -3539,7 +3716,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2995 +#: sssd.conf.5.xml:3125 msgid "" "NOTE: This option has no effect on netgroup lookups due to their tendency to " "include nested netgroups without qualified names. For netgroups, all domains " @@ -3547,24 +3724,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3002 +#: sssd.conf.5.xml:3132 msgid "" "Default: FALSE (TRUE for trusted domain/sub-domains or if " "default_domain_suffix is used)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3009 -msgid "ignore_group_members (bool)" +#: sssd.conf.5.xml:3139 +msgid "ignore_group_members (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3012 +#: sssd.conf.5.xml:3142 msgid "Do not return group members for group lookups." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3015 +#: sssd.conf.5.xml:3145 msgid "" "If set to TRUE, the group membership attribute is not requested from the " "ldap server, and group members are not returned when processing group lookup " @@ -3576,7 +3753,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3033 +#: sssd.conf.5.xml:3163 msgid "" "Enabling this option can also make access provider checks for group " "membership significantly faster, especially for groups containing many " @@ -3584,7 +3761,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3039 sssd.conf.5.xml:3767 sssd-ldap.5.xml:401 +#: sssd.conf.5.xml:3169 sssd.conf.5.xml:3951 sssd-ldap.5.xml:401 #: sssd-ldap.5.xml:454 sssd-ldap.5.xml:529 sssd-ldap.5.xml:576 #: sssd-ldap.5.xml:599 sssd-ldap.5.xml:638 sssd-ldap.5.xml:657 #: sssd-ldap.5.xml:681 sssd-ldap.5.xml:1114 sssd-ldap.5.xml:1147 @@ -3594,19 +3771,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3049 +#: sssd.conf.5.xml:3179 msgid "auth_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3052 +#: sssd.conf.5.xml:3182 msgid "" "The authentication provider used for the domain. Supported auth providers " "are:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3056 sssd.conf.5.xml:3122 +#: sssd.conf.5.xml:3186 sssd.conf.5.xml:3252 msgid "" "<quote>ldap</quote> for native LDAP authentication. See <citerefentry> " "<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> </" @@ -3614,7 +3791,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3063 +#: sssd.conf.5.xml:3193 msgid "" "<quote>krb5</quote> for Kerberos authentication. See <citerefentry> " "<refentrytitle>sssd-krb5</refentrytitle> <manvolnum>5</manvolnum> </" @@ -3622,7 +3799,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3087 +#: sssd.conf.5.xml:3217 msgid "" "<quote>idp</quote>: Provider for OAuth 2.0/OIDC based authentication. See " "<citerefentry> <refentrytitle>sssd-idp</refentrytitle> <manvolnum>5</" @@ -3630,30 +3807,30 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3095 +#: sssd.conf.5.xml:3225 msgid "" "<quote>proxy</quote> for relaying authentication to some other PAM target." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3098 +#: sssd.conf.5.xml:3228 msgid "<quote>none</quote> disables authentication explicitly." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3101 +#: sssd.conf.5.xml:3231 msgid "" "Default: <quote>id_provider</quote> is used if it is set and can handle " "authentication requests." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3107 +#: sssd.conf.5.xml:3237 msgid "access_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3110 +#: sssd.conf.5.xml:3240 msgid "" "The access control provider used for the domain. There are two built-in " "access providers (in addition to any included in installed backends) " @@ -3661,17 +3838,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3116 +#: sssd.conf.5.xml:3246 msgid "<quote>permit</quote> always allow access." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3119 +#: sssd.conf.5.xml:3249 msgid "<quote>deny</quote> always deny access." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3146 +#: sssd.conf.5.xml:3276 msgid "" "<quote>simple</quote> access control based on access or deny lists. See " "<citerefentry> <refentrytitle>sssd-simple</refentrytitle> <manvolnum>5</" @@ -3680,7 +3857,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3153 +#: sssd.conf.5.xml:3283 msgid "" "<quote>krb5</quote>: .k5login based access control. See <citerefentry> " "<refentrytitle>sssd-krb5</refentrytitle> <manvolnum>5</manvolnum></" @@ -3688,29 +3865,29 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3160 +#: sssd.conf.5.xml:3290 msgid "<quote>proxy</quote> for relaying access control to another PAM module." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3163 +#: sssd.conf.5.xml:3293 msgid "Default: <quote>permit</quote>" msgstr "Noklusējuma: <quote>atļaut</quote>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3168 +#: sssd.conf.5.xml:3298 msgid "chpass_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3171 +#: sssd.conf.5.xml:3301 msgid "" "The provider which should handle change password operations for the domain. " "Supported change password providers are:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3176 +#: sssd.conf.5.xml:3306 msgid "" "<quote>ldap</quote> to change a password stored in a LDAP server. See " "<citerefentry> <refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</" @@ -3718,7 +3895,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3184 +#: sssd.conf.5.xml:3314 msgid "" "<quote>krb5</quote> to change the Kerberos password. See <citerefentry> " "<refentrytitle>sssd-krb5</refentrytitle> <manvolnum>5</manvolnum> </" @@ -3726,35 +3903,35 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3209 +#: sssd.conf.5.xml:3339 msgid "" "<quote>proxy</quote> for relaying password changes to some other PAM target." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3213 +#: sssd.conf.5.xml:3343 msgid "<quote>none</quote> disallows password changes explicitly." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3216 +#: sssd.conf.5.xml:3346 msgid "" "Default: <quote>auth_provider</quote> is used if it is set and can handle " "change password requests." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3223 +#: sssd.conf.5.xml:3353 msgid "sudo_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3226 +#: sssd.conf.5.xml:3356 msgid "The SUDO provider used for the domain. Supported SUDO providers are:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3230 +#: sssd.conf.5.xml:3360 msgid "" "<quote>ldap</quote> for rules stored in LDAP. See <citerefentry> " "<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> </" @@ -3762,33 +3939,33 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3238 +#: sssd.conf.5.xml:3368 msgid "" "<quote>ipa</quote> the same as <quote>ldap</quote> but with IPA default " "settings." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3242 +#: sssd.conf.5.xml:3372 msgid "" "<quote>ad</quote> the same as <quote>ldap</quote> but with AD default " "settings." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3246 +#: sssd.conf.5.xml:3376 msgid "<quote>none</quote> disables SUDO explicitly." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3249 +#: sssd.conf.5.xml:3379 msgid "" "Default: The value of <quote>id_provider</quote> is used if it is set and " "can handle sudo requests." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3253 +#: sssd.conf.5.xml:3383 msgid "" "The detailed instructions for configuration of sudo_provider are in the " "manual page <citerefentry> <refentrytitle>sssd-sudo</refentrytitle> " @@ -3799,7 +3976,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3268 +#: sssd.conf.5.xml:3398 msgid "" "<emphasis>NOTE:</emphasis> Sudo rules are periodically downloaded in the " "background unless the sudo provider is explicitly disabled. Set " @@ -3808,12 +3985,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3278 +#: sssd.conf.5.xml:3408 msgid "selinux_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3281 +#: sssd.conf.5.xml:3411 msgid "" "The provider which should handle loading of selinux settings. Note that this " "provider will be called right after access provider ends. Supported selinux " @@ -3821,7 +3998,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3287 +#: sssd.conf.5.xml:3417 msgid "" "<quote>ipa</quote> to load selinux settings from an IPA server. See " "<citerefentry> <refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</" @@ -3829,31 +4006,32 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3295 +#: sssd.conf.5.xml:3425 msgid "<quote>none</quote> disallows fetching selinux settings explicitly." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3298 +#: sssd.conf.5.xml:3428 msgid "" -"Default: <quote>id_provider</quote> is used if it is set and can handle " -"selinux loading requests." +"Default: the value of <quote>id_provider</quote> is used if it is set and " +"can handle selinux loading requests. Otherwise the result is the same as if " +"the selinux_provider is set to none." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3304 +#: sssd.conf.5.xml:3435 msgid "subdomains_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3307 +#: sssd.conf.5.xml:3438 msgid "" "The provider which should handle fetching of subdomains. This value should " "be always the same as id_provider. Supported subdomain providers are:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3313 +#: sssd.conf.5.xml:3444 msgid "" "<quote>ipa</quote> to load a list of subdomains from an IPA server. See " "<citerefentry> <refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</" @@ -3861,7 +4039,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3322 +#: sssd.conf.5.xml:3453 msgid "" "<quote>ad</quote> to load a list of subdomains from an Active Directory " "server. See <citerefentry> <refentrytitle>sssd-ad</refentrytitle> " @@ -3870,24 +4048,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3331 +#: sssd.conf.5.xml:3462 msgid "<quote>none</quote> disallows fetching subdomains explicitly." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3335 +#: sssd.conf.5.xml:3466 msgid "" "Default: The value of <quote>id_provider</quote> is used if it is set and " "can handle subdomain requests." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3341 +#: sssd.conf.5.xml:3472 msgid "session_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3344 +#: sssd.conf.5.xml:3475 msgid "" "The provider which configures and manages user session related tasks. The " "only user session task currently provided is the integration with Fleet " @@ -3895,36 +4073,36 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3351 +#: sssd.conf.5.xml:3482 msgid "<quote>ipa</quote> to allow performing user session related tasks." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3355 +#: sssd.conf.5.xml:3486 msgid "" "<quote>none</quote> does not perform any kind of user session related tasks." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3359 +#: sssd.conf.5.xml:3490 #, fuzzy #| msgid "Default: <quote>permit</quote>" msgid "Default: <quote>none</quote>." msgstr "Noklusējuma: <quote>atļaut</quote>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3365 +#: sssd.conf.5.xml:3496 msgid "autofs_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3368 +#: sssd.conf.5.xml:3499 msgid "" "The autofs provider used for the domain. Supported autofs providers are:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3372 +#: sssd.conf.5.xml:3503 msgid "" "<quote>ldap</quote> to load maps stored in LDAP. See <citerefentry> " "<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> </" @@ -3932,7 +4110,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3379 +#: sssd.conf.5.xml:3510 msgid "" "<quote>ipa</quote> to load maps stored in an IPA server. See <citerefentry> " "<refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</manvolnum> </" @@ -3940,7 +4118,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3387 +#: sssd.conf.5.xml:3518 msgid "" "<quote>ad</quote> to load maps stored in an AD server. See <citerefentry> " "<refentrytitle>sssd-ad</refentrytitle> <manvolnum>5</manvolnum> </" @@ -3948,31 +4126,31 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3396 +#: sssd.conf.5.xml:3527 msgid "<quote>none</quote> disables autofs explicitly." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3399 +#: sssd.conf.5.xml:3530 msgid "" "Default: The value of <quote>id_provider</quote> is used if it is set and " "can handle autofs requests." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3406 +#: sssd.conf.5.xml:3537 msgid "hostid_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3409 +#: sssd.conf.5.xml:3540 msgid "" "The provider used for retrieving host identity information. Supported " "hostid providers are:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3413 +#: sssd.conf.5.xml:3544 msgid "" "<quote>ipa</quote> to load host identity stored in an IPA server. See " "<citerefentry> <refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</" @@ -3980,38 +4158,38 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3421 +#: sssd.conf.5.xml:3552 msgid "<quote>none</quote> disables hostid explicitly." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3424 +#: sssd.conf.5.xml:3555 msgid "" "Default: The value of <quote>id_provider</quote> is used if it is set and " "can handle hostid requests." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3431 +#: sssd.conf.5.xml:3562 msgid "resolver_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3434 +#: sssd.conf.5.xml:3565 msgid "" "The provider which should handle hosts and networks lookups. Supported " "resolver providers are:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3438 +#: sssd.conf.5.xml:3569 msgid "" "<quote>proxy</quote> to forward lookups to another NSS library. See " "<quote>proxy_resolver_lib_name</quote>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3442 +#: sssd.conf.5.xml:3573 msgid "" "<quote>ldap</quote> to fetch hosts and networks stored in LDAP. See " "<citerefentry> <refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</" @@ -4019,7 +4197,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3449 +#: sssd.conf.5.xml:3580 msgid "" "<quote>ad</quote> to fetch hosts and networks stored in AD. See " "<citerefentry> <refentrytitle>sssd-ad</refentrytitle> <manvolnum>5</" @@ -4028,19 +4206,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3457 +#: sssd.conf.5.xml:3588 msgid "<quote>none</quote> disallows fetching hosts and networks explicitly." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3460 +#: sssd.conf.5.xml:3591 msgid "" "Default: The value of <quote>id_provider</quote> is used if it is set and " "can handle resolver requests." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3470 +#: sssd.conf.5.xml:3601 msgid "" "Regular expression for this domain that describes how to parse the string " "containing user name and domain into these components. The \"domain\" can " @@ -4050,24 +4228,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3479 +#: sssd.conf.5.xml:3610 msgid "" "Default: <quote>^((?P<name>.+)@(?P<domain>[^@]*)|(?P<name>" "[^@]+))$</quote> which allows two different styles for user names:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:3484 sssd.conf.5.xml:3498 +#: sssd.conf.5.xml:3615 sssd.conf.5.xml:3629 msgid "username" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:3487 sssd.conf.5.xml:3501 +#: sssd.conf.5.xml:3618 sssd.conf.5.xml:3632 msgid "username@domain.name" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3492 +#: sssd.conf.5.xml:3623 msgid "" "Default for the AD and IPA provider: <quote>^(((?P<domain>[^\\\\]+)\\\\" "(?P<name>.+))|((?P<name>.+)@(?P<domain>[^@]+))|((?" @@ -4076,19 +4254,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:3504 +#: sssd.conf.5.xml:3635 msgid "domain\\username" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3507 +#: sssd.conf.5.xml:3638 msgid "" "While the first two correspond to the general default the third one is " "introduced to allow easy integration of users from Windows domains." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3512 +#: sssd.conf.5.xml:3643 msgid "" "The default re_expression uses the <quote>@</quote> character as a separator " "between the name and the domain. As a result of this setting the default " @@ -4098,93 +4276,98 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3564 +#: sssd.conf.5.xml:3695 msgid "Default: <quote>%1$s@%2$s</quote>." msgstr "Noklusējuma: <quote>%1$s@%2$s</quote>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3570 +#: sssd.conf.5.xml:3701 msgid "lookup_family_order (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3573 +#: sssd.conf.5.xml:3704 msgid "" "Provides the ability to select preferred address family to use when " "performing DNS lookups." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3577 +#: sssd.conf.5.xml:3708 msgid "Supported values:" msgstr "Atbalstītās vērtības:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3580 +#: sssd.conf.5.xml:3711 msgid "ipv4_first: Try looking up IPv4 address, if that fails, try IPv6" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3583 +#: sssd.conf.5.xml:3714 msgid "ipv4_only: Only attempt to resolve hostnames to IPv4 addresses." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3586 +#: sssd.conf.5.xml:3717 msgid "ipv6_first: Try looking up IPv6 address, if that fails, try IPv4" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3589 +#: sssd.conf.5.xml:3720 msgid "ipv6_only: Only attempt to resolve hostnames to IPv6 addresses." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3592 +#: sssd.conf.5.xml:3723 msgid "Default: ipv4_first" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3598 +#: sssd.conf.5.xml:3729 #, fuzzy #| msgid "timeout (integer)" msgid "dns_resolver_server_timeout (integer)" msgstr "noildze (vesels skaitlis)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3601 +#: sssd.conf.5.xml:3732 msgid "" -"Defines the amount of time (in milliseconds) SSSD would try to talk to DNS " -"server before trying next DNS server." +"Defines the timeout duration (in milliseconds) SSSD waits for a DNS server " +"to respond before moving to the next one." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3606 +#: sssd.conf.5.xml:3737 msgid "" "The AD provider will use this option for the CLDAP ping timeouts as well." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3610 sssd.conf.5.xml:3630 sssd.conf.5.xml:3651 +#: sssd.conf.5.xml:3741 sssd.conf.5.xml:3777 sssd.conf.5.xml:3814 msgid "" -"Please see the section <quote>FAILOVER</quote> for more information about " -"the service resolution." +"Please see the section <quote>FAILOVER</quote> in <citerefentry> " +"<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> </" +"citerefentry>, <citerefentry> <refentrytitle>sssd-krb5</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry>, <citerefentry> <refentrytitle>sssd-" +"ipa</refentrytitle> <manvolnum>5</manvolnum> </citerefentry> or " +"<citerefentry> <refentrytitle>sssd-ad</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry> for more information about the service resolution." msgstr "" #. type: Content of: <refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3615 sssd-ldap.5.xml:700 include/failover.xml:84 +#: sssd.conf.5.xml:3762 sssd-ldap.5.xml:700 include/failover.xml:84 msgid "Default: 1000" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3621 +#: sssd.conf.5.xml:3768 #, fuzzy #| msgid "timeout (integer)" msgid "dns_resolver_op_timeout (integer)" msgstr "noildze (vesels skaitlis)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3624 +#: sssd.conf.5.xml:3771 msgid "" "Defines the amount of time (in seconds) to wait to resolve single DNS query " "(e.g. resolution of a hostname or an SRV record) before trying the next " @@ -4192,17 +4375,17 @@ msgid "" msgstr "" #. type: Content of: <refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3635 include/failover.xml:100 +#: sssd.conf.5.xml:3798 include/failover.xml:100 msgid "Default: 3" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3641 +#: sssd.conf.5.xml:3804 msgid "dns_resolver_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3644 +#: sssd.conf.5.xml:3807 msgid "" "Defines the amount of time (in seconds) to wait for a reply from the " "internal fail over service before assuming that the service is unreachable. " @@ -4211,14 +4394,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3662 +#: sssd.conf.5.xml:3841 #, fuzzy #| msgid "timeout (integer)" -msgid "dns_resolver_use_search_list (bool)" +msgid "dns_resolver_use_search_list (boolean)" msgstr "noildze (vesels skaitlis)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3665 +#: sssd.conf.5.xml:3844 msgid "" "Normally, the DNS resolver searches the domain list defined in the " "\"search\" directive from the resolv.conf file. This can lead to delays in " @@ -4226,7 +4409,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3671 +#: sssd.conf.5.xml:3850 msgid "" "If fully qualified domain names (or _srv_) are used in the SSSD " "configuration, setting this option to FALSE can prevent unnecessary DNS " @@ -4234,38 +4417,38 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3677 +#: sssd.conf.5.xml:3856 #, fuzzy #| msgid "Default: 6" msgid "Default: TRUE" msgstr "Noklusējuma: 6" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3683 +#: sssd.conf.5.xml:3862 msgid "dns_discovery_domain (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3686 +#: sssd.conf.5.xml:3865 msgid "" "If service discovery is used in the back end, specifies the domain part of " "the service discovery DNS query." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3690 +#: sssd.conf.5.xml:3869 msgid "Default: Use the domain part of machine's hostname" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3696 +#: sssd.conf.5.xml:3875 #, fuzzy #| msgid "timeout (integer)" msgid "failover_primary_timeout (integer)" msgstr "noildze (vesels skaitlis)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3699 +#: sssd.conf.5.xml:3878 msgid "" "When no primary server is available, SSSD fails over to a backup server. " "This option defines the number of seconds SSSD waits before attempting to " @@ -4273,59 +4456,68 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3706 +#: sssd.conf.5.xml:3885 msgid "Note: The minimum value is 31." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3709 +#: sssd.conf.5.xml:3888 #, fuzzy #| msgid "Default: 1" msgid "Default: 31" msgstr "Noklusējuma: 1" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3715 +#: sssd.conf.5.xml:3894 msgid "override_gid (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3718 -msgid "Override the primary GID value with the one specified." +#: sssd.conf.5.xml:3897 +msgid "" +"Override the primary GID value for all users in the domain with specified " +"value." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3901 +msgid "" +"Default: not set (Use the primary GID value retrieved from the identity " +"provider)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3724 +#: sssd.conf.5.xml:3908 msgid "case_sensitive (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3731 +#: sssd.conf.5.xml:3915 msgid "True" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3734 +#: sssd.conf.5.xml:3918 msgid "Case sensitive. This value is invalid for AD provider." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3740 +#: sssd.conf.5.xml:3924 msgid "False" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3742 +#: sssd.conf.5.xml:3926 msgid "Case insensitive." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3746 +#: sssd.conf.5.xml:3930 msgid "Preserving" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3749 +#: sssd.conf.5.xml:3933 msgid "" "Same as False (case insensitive), but does not lowercase names in the result " "of NSS operations. Note that name aliases (and in case of services also " @@ -4333,31 +4525,57 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3757 +#: sssd.conf.5.xml:3941 msgid "" "If you want to set this value for trusted domain with IPA provider, you need " "to set it on both the client and SSSD on the server." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3727 +#: sssd.conf.5.xml:3911 msgid "" "Treat user and group names as case sensitive. Possible option values are: " "<placeholder type=\"variablelist\" id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3772 +#: sssd.conf.5.xml:3956 msgid "Default: True (False for AD provider)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3778 +#: sssd.conf.5.xml:3962 +msgid "avoid_by_id_lookups (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3965 +msgid "" +"If this option is set to 'true' SSSD will try to avoid sending lookups by ID " +"to the backend and will switch to a lookup by name if a cached object with a " +"matching ID can be found." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3971 +msgid "" +"This option can e.g. be used in cases where searches by ID are expensive on " +"the server side because of missing indexes or are not even possible, e.g. " +"due to non-reversible POSIX id-mapping." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3978 +msgid "Default: False (True for IdP provider)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:3984 msgid "subdomain_inherit (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3781 +#: sssd.conf.5.xml:3987 msgid "" "Specifies a list of configuration parameters that should be inherited by a " "subdomain. Please note that only selected parameters can be inherited. " @@ -4365,95 +4583,95 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3787 +#: sssd.conf.5.xml:3993 msgid "ldap_search_timeout" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3790 +#: sssd.conf.5.xml:3996 msgid "ldap_network_timeout" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3793 +#: sssd.conf.5.xml:3999 msgid "ldap_opt_timeout" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3796 +#: sssd.conf.5.xml:4002 #, fuzzy #| msgid "timeout (integer)" msgid "ldap_offline_timeout" msgstr "noildze (vesels skaitlis)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3799 +#: sssd.conf.5.xml:4005 msgid "ldap_purge_cache_timeout" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3802 +#: sssd.conf.5.xml:4008 msgid "ldap_purge_cache_offset" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3805 +#: sssd.conf.5.xml:4011 msgid "" "ldap_krb5_keytab (the value of krb5_keytab will be used if ldap_krb5_keytab " "is not set explicitly)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3809 +#: sssd.conf.5.xml:4015 msgid "ldap_krb5_ticket_lifetime" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3812 +#: sssd.conf.5.xml:4018 #, fuzzy #| msgid "timeout (integer)" msgid "ldap_connection_expire_timeout" msgstr "noildze (vesels skaitlis)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3815 +#: sssd.conf.5.xml:4021 #, fuzzy #| msgid "timeout (integer)" msgid "ldap_connection_expire_offset" msgstr "noildze (vesels skaitlis)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3818 +#: sssd.conf.5.xml:4024 msgid "ldap_connection_idle_timeout" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3821 sssd-ldap.5.xml:446 +#: sssd.conf.5.xml:4027 sssd-ldap.5.xml:446 msgid "ldap_use_tokengroups" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3824 +#: sssd.conf.5.xml:4030 msgid "ldap_user_principal" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3827 +#: sssd.conf.5.xml:4033 msgid "ignore_group_members" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3830 +#: sssd.conf.5.xml:4036 msgid "auto_private_groups" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3833 +#: sssd.conf.5.xml:4039 msgid "case_sensitive" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:3838 +#: sssd.conf.5.xml:4044 #, no-wrap msgid "" "subdomain_inherit = ldap_purge_cache_timeout\n" @@ -4461,27 +4679,27 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3845 +#: sssd.conf.5.xml:4051 msgid "Note: This option only works with the IPA and AD provider." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3852 +#: sssd.conf.5.xml:4058 msgid "subdomain_homedir (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3863 +#: sssd.conf.5.xml:4069 msgid "%F" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3864 +#: sssd.conf.5.xml:4070 msgid "flat (NetBIOS) name of a subdomain." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3855 +#: sssd.conf.5.xml:4061 msgid "" "Use this homedir as default value for all subdomains within this domain in " "IPA AD trust. See <emphasis>override_homedir</emphasis> for info about " @@ -4491,55 +4709,55 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3869 +#: sssd.conf.5.xml:4075 msgid "" "The value can be overridden by <emphasis>override_homedir</emphasis> option." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3873 +#: sssd.conf.5.xml:4079 msgid "Default: <filename>/home/%d/%u</filename>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3878 +#: sssd.conf.5.xml:4084 msgid "realmd_tags (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3881 +#: sssd.conf.5.xml:4087 msgid "" "Various tags stored by the realmd configuration service for this domain." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3887 +#: sssd.conf.5.xml:4093 msgid "cached_auth_timeout (int)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3890 +#: sssd.conf.5.xml:4096 msgid "" -"Specifies time in seconds since last successful online authentication for " -"which user will be authenticated using cached credentials while SSSD is in " -"the online mode. If the credentials are incorrect, SSSD falls back to online " -"authentication." +"Specifies the number of seconds since the last successful online " +"authentication during which SSSD will authenticate users via cached " +"credentials, even while online. If the cached authentication fails, SSSD " +"immediately falls back to online authentication." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3898 +#: sssd.conf.5.xml:4103 msgid "" "This option's value is inherited by all trusted domains. At the moment it is " "not possible to set a different value per trusted domain." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3903 +#: sssd.conf.5.xml:4108 msgid "Special value 0 implies that this feature is disabled." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3907 +#: sssd.conf.5.xml:4112 msgid "" "Please note that if <quote>cached_auth_timeout</quote> is longer than " "<quote>pam_id_timeout</quote> then the back end could be called to handle " @@ -4547,12 +4765,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3918 +#: sssd.conf.5.xml:4123 msgid "local_auth_policy (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3921 +#: sssd.conf.5.xml:4126 msgid "" "Local authentication methods policy. Some backends (i.e. LDAP, proxy " "provider) only support a password based authentication, while others can " @@ -4564,7 +4782,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3933 +#: sssd.conf.5.xml:4138 msgid "" "There are three possible values for this option: match, only, enable. " "<quote>match</quote> is used to match offline and online states for Kerberos " @@ -4576,7 +4794,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3946 +#: sssd.conf.5.xml:4151 msgid "" "The following table shows which authentication methods, if configured " "properly, are currently enabled or disabled for each backend, with the " @@ -4584,42 +4802,47 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> -#: sssd.conf.5.xml:3959 +#: sssd.conf.5.xml:4164 msgid "local_auth_policy = match (default)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> -#: sssd.conf.5.xml:3960 +#: sssd.conf.5.xml:4165 msgid "Passkey" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> -#: sssd.conf.5.xml:3961 +#: sssd.conf.5.xml:4166 msgid "Smartcard" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:3964 sssd-ldap.5.xml:228 +#: sssd.conf.5.xml:4169 sssd-ldap.5.xml:228 msgid "IPA" msgstr "" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry><para> +#: sssd.conf.5.xml:4169 sssd.conf.5.xml:4170 sssd.conf.5.xml:4173 +msgid "enabled" +msgstr "" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:3967 sssd-ldap.5.xml:233 +#: sssd.conf.5.xml:4172 sssd-ldap.5.xml:233 msgid "AD" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry><para> -#: sssd.conf.5.xml:3967 sssd.conf.5.xml:3970 sssd.conf.5.xml:3971 +#: sssd.conf.5.xml:4172 sssd.conf.5.xml:4175 sssd.conf.5.xml:4176 msgid "disabled" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry> -#: sssd.conf.5.xml:3970 +#: sssd.conf.5.xml:4175 msgid "LDAP" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3975 +#: sssd.conf.5.xml:4180 msgid "" "Please note that if local Smartcard authentication is enabled and a " "Smartcard is present, Smartcard authentication will be preferred over the " @@ -4628,7 +4851,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:3987 +#: sssd.conf.5.xml:4192 #, no-wrap msgid "" "[domain/shadowutils]\n" @@ -4639,7 +4862,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3983 +#: sssd.conf.5.xml:4188 msgid "" "The following configuration example allows local users to authenticate " "locally using any enabled method (i.e. smartcard, passkey). <placeholder " @@ -4647,31 +4870,31 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3995 +#: sssd.conf.5.xml:4200 #, fuzzy #| msgid "Default: 6" msgid "Default: match" msgstr "Noklusējuma: 6" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4000 +#: sssd.conf.5.xml:4205 msgid "auto_private_groups (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4006 +#: sssd.conf.5.xml:4211 msgid "true" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4009 +#: sssd.conf.5.xml:4214 msgid "" "Create user's private group unconditionally from user's UID number. The GID " "number is ignored in this case." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4013 +#: sssd.conf.5.xml:4218 msgid "" "NOTE: Because the GID number and the user private group are inferred from " "the UID number, it is not supported to have multiple entries with the same " @@ -4680,24 +4903,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4022 +#: sssd.conf.5.xml:4227 msgid "false" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4025 +#: sssd.conf.5.xml:4230 msgid "" "Always use the user's primary GID number. The GID number must refer to a " "group object in the LDAP database." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4031 +#: sssd.conf.5.xml:4236 msgid "hybrid" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4034 +#: sssd.conf.5.xml:4239 msgid "" "A primary group is autogenerated for user entries whose UID and GID numbers " "have the same value and at the same time the GID number does not correspond " @@ -4707,14 +4930,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4047 +#: sssd.conf.5.xml:4252 msgid "" "If the UID and GID of a user are different, then the GID must correspond to " "a group entry, otherwise the GID is simply not resolvable." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4054 +#: sssd.conf.5.xml:4259 msgid "" "This feature is useful for environments that wish to stop maintaining a " "separate group objects for the user private groups, but also wish to retain " @@ -4722,14 +4945,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4003 +#: sssd.conf.5.xml:4208 msgid "" "This option takes any of three available values: <placeholder " "type=\"variablelist\" id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4066 +#: sssd.conf.5.xml:4271 msgid "" "For the LDAP based id providers (LDAP, IPA and AD) the default for the " "configured domain is typically False because the sources have the concept of " @@ -4739,14 +4962,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4075 +#: sssd.conf.5.xml:4280 msgid "" "For subdomains, the default value is False for subdomains that use assigned " "POSIX IDs and True for subdomains that use automatic ID-mapping." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:4083 +#: sssd.conf.5.xml:4288 #, no-wrap msgid "" "[domain/forest.domain/sub.domain]\n" @@ -4754,7 +4977,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:4089 +#: sssd.conf.5.xml:4294 #, no-wrap msgid "" "[domain/forest.domain]\n" @@ -4763,7 +4986,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4080 +#: sssd.conf.5.xml:4285 msgid "" "The value of auto_private_groups can either be set per subdomains in a " "subsection, for example: <placeholder type=\"programlisting\" id=\"0\"/> or " @@ -4772,7 +4995,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:2503 +#: sssd.conf.5.xml:2549 msgid "" "These configuration options can be present in a domain configuration " "section, that is, in a section called <quote>[domain/<replaceable>NAME</" @@ -4780,17 +5003,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4104 +#: sssd.conf.5.xml:4309 msgid "proxy_pam_target (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4107 +#: sssd.conf.5.xml:4312 msgid "The proxy target PAM proxies to." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4110 +#: sssd.conf.5.xml:4315 msgid "" "Default: not set by default, you have to take an existing pam configuration " "or create a new one and add the service name here. As an alternative you can " @@ -4798,12 +5021,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4120 +#: sssd.conf.5.xml:4325 msgid "proxy_lib_name (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4123 +#: sssd.conf.5.xml:4328 msgid "" "The name of the NSS library to use in proxy domains. The NSS functions " "searched for in the library are in the form of _nss_$(libName)_$(function), " @@ -4811,12 +5034,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4133 +#: sssd.conf.5.xml:4338 msgid "proxy_resolver_lib_name (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4136 +#: sssd.conf.5.xml:4341 msgid "" "The name of the NSS library to use for hosts and networks lookups in proxy " "domains. The NSS functions searched for in the library are in the form of " @@ -4824,12 +5047,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4147 +#: sssd.conf.5.xml:4352 msgid "proxy_fast_alias (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4150 +#: sssd.conf.5.xml:4355 msgid "" "When a user or group is looked up by name in the proxy provider, a second " "lookup by ID is performed to \"canonicalize\" the name in case the requested " @@ -4838,12 +5061,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4164 +#: sssd.conf.5.xml:4369 msgid "proxy_max_children (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4167 +#: sssd.conf.5.xml:4372 msgid "" "This option specifies the number of pre-forked proxy children. It is useful " "for high-load SSSD environments where sssd may run out of available child " @@ -4851,19 +5074,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4100 +#: sssd.conf.5.xml:4305 msgid "" "Options valid for proxy domains. <placeholder type=\"variablelist\" " "id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:4183 +#: sssd.conf.5.xml:4388 msgid "Application domains" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:4185 +#: sssd.conf.5.xml:4390 msgid "" "SSSD, with its D-Bus interface (see <citerefentry> <refentrytitle>sssd-ifp</" "refentrytitle> <manvolnum>5</manvolnum> </citerefentry>) is appealing to " @@ -4880,7 +5103,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:4205 +#: sssd.conf.5.xml:4410 msgid "" "Please note that the application domain must still be explicitly enabled in " "the <quote>domains</quote> parameter so that the lookup order between the " @@ -4888,17 +5111,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><title> -#: sssd.conf.5.xml:4211 +#: sssd.conf.5.xml:4416 msgid "Application domain parameters" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4213 +#: sssd.conf.5.xml:4418 msgid "inherit_from (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4216 +#: sssd.conf.5.xml:4421 msgid "" "The SSSD POSIX-type domain the application domain inherits all settings " "from. The application domain can moreover add its own settings to the " @@ -4907,7 +5130,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:4230 +#: sssd.conf.5.xml:4435 msgid "" "The following example illustrates the use of an application domain. In this " "setup, the POSIX domain is connected to an LDAP server and is used by the OS " @@ -4917,7 +5140,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><programlisting> -#: sssd.conf.5.xml:4238 +#: sssd.conf.5.xml:4443 #, no-wrap msgid "" "[sssd]\n" @@ -4937,12 +5160,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:4258 +#: sssd.conf.5.xml:4463 msgid "TRUSTED DOMAIN SECTION" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4260 +#: sssd.conf.5.xml:4465 msgid "" "Some options used in the domain section can also be used in the trusted " "domain section, that is, in a section called <quote>[domain/" @@ -4953,69 +5176,79 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4267 +#: sssd.conf.5.xml:4472 msgid "ldap_search_base," msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4268 +#: sssd.conf.5.xml:4473 msgid "ldap_user_search_base," msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4269 +#: sssd.conf.5.xml:4474 msgid "ldap_group_search_base," msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4270 +#: sssd.conf.5.xml:4475 msgid "ldap_netgroup_search_base," msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4271 +#: sssd.conf.5.xml:4476 msgid "ldap_service_search_base," msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4272 +#: sssd.conf.5.xml:4477 msgid "ldap_sasl_mech," msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4273 +#: sssd.conf.5.xml:4478 msgid "ad_server," msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4274 +#: sssd.conf.5.xml:4479 msgid "ad_backup_server," msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4275 +#: sssd.conf.5.xml:4480 msgid "ad_site," msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:4276 sssd-ipa.5.xml:934 +#: sssd.conf.5.xml:4481 sssd-ipa.5.xml:929 msgid "use_fully_qualified_names" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4280 +#: sssd.conf.5.xml:4482 +msgid "pam_gssapi_services" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:4483 +msgid "pam_gssapi_check_upn" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:4485 msgid "" "For more details about these options see their individual description in the " "manual page." msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:4286 +#: sssd.conf.5.xml:4491 msgid "CERTIFICATE MAPPING SECTION" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4288 +#: sssd.conf.5.xml:4493 msgid "" "To allow authentication with Smartcards and certificates SSSD must be able " "to map certificates to users. This can be done by adding the full " @@ -5028,7 +5261,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4302 +#: sssd.conf.5.xml:4507 msgid "" "To make the mapping more flexible mapping and matching rules were added to " "SSSD (see <citerefentry> <refentrytitle>sss-certmap</refentrytitle> " @@ -5036,7 +5269,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4311 +#: sssd.conf.5.xml:4516 msgid "" "A mapping and matching rule can be added to the SSSD configuration in a " "section on its own with a name like <quote>[certmap/" @@ -5045,55 +5278,50 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4318 +#: sssd.conf.5.xml:4523 msgid "matchrule (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4321 +#: sssd.conf.5.xml:4526 msgid "" "Only certificates from the Smartcard which matches this rule will be " "processed, all others are ignored." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4325 +#: sssd.conf.5.xml:4530 msgid "" "Default: KRB5:<EKU>clientAuth, i.e. only certificates which have the " "Extended Key Usage <quote>clientAuth</quote>" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4332 +#: sssd.conf.5.xml:4537 msgid "maprule (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4335 +#: sssd.conf.5.xml:4540 msgid "Defines how the user is found for a given certificate." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:4341 +#: sssd.conf.5.xml:4546 msgid "" "LDAP:(userCertificate;binary={cert!bin}) for LDAP based providers like " "<quote>ldap</quote>, <quote>AD</quote> or <quote>ipa</quote>." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:4347 +#: sssd.conf.5.xml:4552 msgid "" "If maprule is not set and provider is <quote>proxy</quote>, the RULE_NAME " "name is assumed to be the name of the matching user." msgstr "" -#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4357 -msgid "domains (string)" -msgstr "" - #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4360 +#: sssd.conf.5.xml:4565 msgid "" "Comma separated list of domain names the rule should be applied. By default " "a rule is only valid in the domain configured in sssd.conf. If the provider " @@ -5102,17 +5330,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4367 +#: sssd.conf.5.xml:4572 msgid "Default: the configured domain in sssd.conf" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4372 +#: sssd.conf.5.xml:4577 msgid "priority (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4375 +#: sssd.conf.5.xml:4580 msgid "" "Unsigned integer value defining the priority of the rule. The higher the " "number the lower the priority. <quote>0</quote> stands for the highest " @@ -5120,17 +5348,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4381 +#: sssd.conf.5.xml:4586 msgid "Default: the lowest priority" msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:4389 +#: sssd.conf.5.xml:4594 msgid "PROMPTING CONFIGURATION SECTION" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4391 +#: sssd.conf.5.xml:4596 msgid "" "If a special file (<filename>/var/lib/sss/pubconf/pam_preauth_available</" "filename>) exists SSSD's PAM module pam_sss will ask SSSD to figure out " @@ -5140,7 +5368,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4399 +#: sssd.conf.5.xml:4604 msgid "" "With the growing number of authentication methods and the possibility that " "there are multiple ones for a single user the heuristic used by pam_sss to " @@ -5149,59 +5377,59 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4411 +#: sssd.conf.5.xml:4616 msgid "[prompting/password]" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4414 +#: sssd.conf.5.xml:4619 msgid "password_prompt" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4415 +#: sssd.conf.5.xml:4620 msgid "to change the string of the password prompt" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4413 +#: sssd.conf.5.xml:4618 msgid "" "to configure password prompting, allowed options are: <placeholder " "type=\"variablelist\" id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4423 +#: sssd.conf.5.xml:4628 msgid "[prompting/2fa]" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4427 +#: sssd.conf.5.xml:4632 msgid "first_prompt" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4428 +#: sssd.conf.5.xml:4633 msgid "to change the string of the prompt for the first factor" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4431 +#: sssd.conf.5.xml:4636 msgid "second_prompt" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4432 +#: sssd.conf.5.xml:4637 msgid "to change the string of the prompt for the second factor" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4435 +#: sssd.conf.5.xml:4640 msgid "single_prompt" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4436 +#: sssd.conf.5.xml:4641 msgid "" "boolean value, if True there will be only a single prompt using the value of " "first_prompt where it is expected that both factors are entered as a single " @@ -5210,7 +5438,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4425 +#: sssd.conf.5.xml:4630 msgid "" "to configure two-factor authentication prompting, allowed options are: " "<placeholder type=\"variablelist\" id=\"0\"/> If the second factor is " @@ -5219,7 +5447,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4449 +#: sssd.conf.5.xml:4654 msgid "" "Some clients, such as SSH with 'PasswordAuthentication yes', generate their " "own prompts and do not use prompts provided by SSSD or other PAM modules. " @@ -5230,17 +5458,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4464 +#: sssd.conf.5.xml:4669 msgid "[prompting/passkey]" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:4470 sssd-ad.5.xml:1022 +#: sssd.conf.5.xml:4675 sssd.conf.5.xml:4719 sssd-ad.5.xml:1027 msgid "interactive" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4472 +#: sssd.conf.5.xml:4677 msgid "" "boolean value, if True prompt a message and wait before testing the presence " "of a passkey device. Recommended if your device doesn’t have a tactile " @@ -5248,55 +5476,131 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4480 +#: sssd.conf.5.xml:4685 sssd.conf.5.xml:4735 msgid "interactive_prompt" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4482 +#: sssd.conf.5.xml:4687 sssd.conf.5.xml:4737 msgid "to change the message of the interactive prompt." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4487 +#: sssd.conf.5.xml:4692 msgid "touch" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4489 +#: sssd.conf.5.xml:4694 msgid "" "boolean value, if True prompt a message to remind the user to touch the " "device." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4495 +#: sssd.conf.5.xml:4700 msgid "touch_prompt" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4497 +#: sssd.conf.5.xml:4702 msgid "to change the message of the touch prompt." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4466 +#: sssd.conf.5.xml:4671 msgid "" "to configure passkey authentication prompting, allowed options are: " "<placeholder type=\"variablelist\" id=\"0\"/>" msgstr "" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4713 +msgid "[prompting/oauth2]" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4721 +msgid "" +"boolean value, if True prompt a message after asking the user to " +"authenticate, and wait before requesting the access token." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4725 +msgid "" +"If False, make sure to set the <quote>idp_request_timeout</quote> " +"sufficiently high, to give the user time to authenticate." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4715 +msgid "" +"to configure OAuth2 authentication prompting, allowed options are: " +"<placeholder type=\"variablelist\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4748 +msgid "[prompting/cert_auth]" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4754 +msgid "pin_prompt" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4756 +msgid "" +"to change the message which asks the user to enter the PIN at the computer " +"keyboard. At the end of the message the token name is printed." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4764 +msgid "keypad_prompt" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4766 +msgid "" +"to change the message which asks the user to enter the PIN at keypad of the " +"Smartcard reader. At the end of the message the token name is printed." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4774 +msgid "user_name_hint" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4776 +msgid "" +"boolean value, if True ask for a user name if no name was given before and " +"the found certificate can be mapped to more than one user." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4750 +msgid "" +"to configure Smartcard authentication prompting, allowed options are: " +"<placeholder type=\"variablelist\" id=\"0\"/>" +msgstr "" + #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4406 +#: sssd.conf.5.xml:4611 msgid "" "Each supported authentication method has its own configuration subsection " "under <quote>[prompting/...]</quote>. Currently there are: <placeholder " "type=\"variablelist\" id=\"0\"/> <placeholder type=\"variablelist\" id=\"1\"/" -"> <placeholder type=\"variablelist\" id=\"2\"/>" +"> <placeholder type=\"variablelist\" id=\"2\"/> <placeholder " +"type=\"variablelist\" id=\"3\"/> <placeholder type=\"variablelist\" id=\"4\"/" +">" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4508 +#: sssd.conf.5.xml:4792 msgid "" "It is possible to add a subsection for specific PAM services, e.g. " "<quote>[prompting/password/sshd]</quote> to individual change the prompting " @@ -5304,12 +5608,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:4515 pam_sss_gss.8.xml:157 idmap_sss.8.xml:43 +#: sssd.conf.5.xml:4799 pam_sss_gss.8.xml:157 idmap_sss.8.xml:43 msgid "EXAMPLES" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd.conf.5.xml:4521 +#: sssd.conf.5.xml:4805 #, no-wrap msgid "" "[sssd]\n" @@ -5338,7 +5642,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4517 +#: sssd.conf.5.xml:4801 msgid "" "1. The following example shows a typical SSSD config. It does not describe " "configuration of the domains themselves - refer to documentation on " @@ -5347,7 +5651,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd.conf.5.xml:4553 +#: sssd.conf.5.xml:4837 #, no-wrap msgid "" "[domain/ipa.com/child.ad.com]\n" @@ -5355,7 +5659,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4547 +#: sssd.conf.5.xml:4831 msgid "" "2. The following example shows configuration of IPA AD trust where the AD " "forest consists of two domains in a parent-child structure. Suppose IPA " @@ -5366,7 +5670,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd.conf.5.xml:4564 +#: sssd.conf.5.xml:4848 #, no-wrap msgid "" "[certmap/my.domain/rule_name]\n" @@ -5377,7 +5681,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4558 +#: sssd.conf.5.xml:4842 msgid "" "3. The following example shows the configuration of a certificate mapping " "rule. It is valid for the configured domain <quote>my.domain</quote> and " @@ -5574,7 +5878,7 @@ msgid "" "defaultNamingContext does not exist or has an empty value namingContexts is " "used. The namingContexts attribute must have a single value with the DN of " "the search base of the LDAP server to make this work. Multiple values are " -"are not supported." +"not supported." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> @@ -5879,15 +6183,15 @@ msgid "Optional. Use the given string as search base for host objects." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap.5.xml:472 sssd-ipa.5.xml:506 sssd-ipa.5.xml:525 sssd-ipa.5.xml:544 -#: sssd-ipa.5.xml:563 +#: sssd-ldap.5.xml:472 sssd-ipa.5.xml:501 sssd-ipa.5.xml:520 sssd-ipa.5.xml:539 +#: sssd-ipa.5.xml:558 msgid "" "See <quote>ldap_search_base</quote> for information about configuring " "multiple search bases." msgstr "" #. type: Content of: <listitem><para> -#: sssd-ldap.5.xml:477 sssd-ipa.5.xml:511 include/ldap_search_bases.xml:27 +#: sssd-ldap.5.xml:477 sssd-ipa.5.xml:506 include/ldap_search_bases.xml:27 msgid "Default: the value of <emphasis>ldap_search_base</emphasis>" msgstr "" @@ -6011,7 +6315,7 @@ msgid "" "closed early to ensure that a new query cannot require the connection to " "remain open past its expiration. This implies that connections will always " "be closed immediately and will never be reused if " -"<emphasis>ldap_connection_expire_timeout <= ldap_opt_timout</emphasis>" +"<emphasis>ldap_connection_expire_timeout <= ldap_opt_timeout</emphasis>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> @@ -6195,7 +6499,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:831 -msgid "ldap_ignore_unreadable_references (bool)" +msgid "ldap_ignore_unreadable_references (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> @@ -6520,7 +6824,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap.5.xml:1152 sssd-ad.5.xml:1267 +#: sssd-ldap.5.xml:1152 sssd-ad.5.xml:1260 msgid "Default: 86400 (24 hours)" msgstr "Noklusējuma: 86400 (24 stundas)" @@ -6558,7 +6862,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ldap.5.xml:1187 sssd-ipa.5.xml:575 sssd-krb5.5.xml:103 +#: sssd-ldap.5.xml:1187 sssd-ipa.5.xml:570 sssd-krb5.5.xml:103 msgid "krb5_realm (string)" msgstr "" @@ -6714,7 +7018,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1339 -msgid "ldap_chpass_update_last_change (bool)" +msgid "ldap_chpass_update_last_change (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> @@ -6861,7 +7165,7 @@ msgid "ldap_access_order (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap.5.xml:1470 sssd-ipa.5.xml:405 +#: sssd-ldap.5.xml:1470 sssd-ipa.5.xml:400 msgid "Comma separated list of access control options. Allowed values are:" msgstr "" @@ -6906,7 +7210,7 @@ msgid "<emphasis>expire</emphasis>: use ldap_account_expire_policy" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap.5.xml:1515 sssd-ipa.5.xml:413 +#: sssd-ldap.5.xml:1515 sssd-ipa.5.xml:408 msgid "" "<emphasis>pwd_expire_policy_reject, pwd_expire_policy_warn, " "pwd_expire_policy_renew: </emphasis> These options are useful if users are " @@ -6916,24 +7220,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap.5.xml:1525 sssd-ipa.5.xml:423 +#: sssd-ldap.5.xml:1525 sssd-ipa.5.xml:418 msgid "" "The difference between these options is the action taken if user password is " "expired:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ldap.5.xml:1530 sssd-ipa.5.xml:428 +#: sssd-ldap.5.xml:1530 sssd-ipa.5.xml:423 msgid "pwd_expire_policy_reject - user is denied to log in," msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ldap.5.xml:1536 sssd-ipa.5.xml:434 +#: sssd-ldap.5.xml:1536 sssd-ipa.5.xml:429 msgid "pwd_expire_policy_warn - user is still able to log in," msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ldap.5.xml:1542 sssd-ipa.5.xml:440 +#: sssd-ldap.5.xml:1542 sssd-ipa.5.xml:435 msgid "" "pwd_expire_policy_renew - user is prompted to change their password " "immediately." @@ -7468,8 +7772,8 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd-ldap.5.xml:2032 sssd-simple.5.xml:169 sssd-ipa.5.xml:984 -#: sssd-ad.5.xml:1470 sssd-idp.5.xml:248 sssd-krb5.5.xml:483 +#: sssd-ldap.5.xml:2032 sssd-simple.5.xml:169 sssd-ipa.5.xml:979 +#: sssd-ad.5.xml:1463 sssd-idp.5.xml:343 sssd-krb5.5.xml:483 #: sss_rpcidmapd.5.xml:98 sssd-session-recording.5.xml:176 msgid "EXAMPLE" msgstr "PIEMĒRS" @@ -7497,7 +7801,7 @@ msgstr "" #. type: Content of: <refsect1><refsect2><para> #: sssd-ldap.5.xml:2039 sssd-ldap.5.xml:2057 sssd-simple.5.xml:177 -#: sssd-ipa.5.xml:992 sssd-ad.5.xml:1478 sssd-sudo.5.xml:56 sssd-krb5.5.xml:492 +#: sssd-ipa.5.xml:987 sssd-ad.5.xml:1471 sssd-sudo.5.xml:56 sssd-krb5.5.xml:492 #: sssd-session-recording.5.xml:182 include/ldap_id_mapping.xml:105 msgid "<placeholder type=\"programlisting\" id=\"0\"/>" msgstr "" @@ -7532,7 +7836,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><title> #: sssd-ldap.5.xml:2073 sssd_krb5_locator_plugin.8.xml:83 sssd-simple.5.xml:189 -#: sssd-ad.5.xml:1493 sssd.8.xml:270 sss_seed.8.xml:163 +#: sssd-ad.5.xml:1486 sssd.8.xml:270 sss_seed.8.xml:163 msgid "NOTES" msgstr "PIEZĪMES" @@ -8041,7 +8345,7 @@ msgstr "" #: pam_sss.8.xml:434 msgid "" "No authentication method was found by Kerberos. This might happen if the " -"user has a Smartcard assigned but the pkint plugin is not available on the " +"user has a Smartcard assigned but the pkinit plugin is not available on the " "client." msgstr "" @@ -8467,6 +8771,23 @@ msgid "" "first DNS resolving failure." msgstr "" +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_locator_plugin.8.xml:106 +msgid "" +"If the environment variable SSSD_KRB5_LOCATOR_KDC_ADDRESS is set to a KDC " +"address the plugin will use this address instead of reading the kdcinfo " +"file. The address format is the same as in the kdcinfo file (see above)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_locator_plugin.8.xml:112 +msgid "" +"If the environment variable SSSD_KRB5_LOCATOR_KPASSWD_ADDRESS is set to a " +"kpasswd server address the plugin will use this address instead of reading " +"the kpasswdinfo file. The address format is the same as in the kpasswdinfo " +"file (see above)." +msgstr "" + #. type: Content of: <reference><refentry><refnamediv><refname> #: sssd-simple.5.xml:10 sssd-simple.5.xml:16 msgid "sssd-simple" @@ -9852,7 +10173,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:129 sssd-ad.5.xml:1161 +#: sssd-ipa.5.xml:129 sssd-ad.5.xml:1166 msgid "dyndns_update (boolean)" msgstr "" @@ -9866,20 +10187,13 @@ msgid "" "quote> option." msgstr "" -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:141 sssd-ad.5.xml:1175 -msgid "" -"NOTE: On older systems (such as RHEL 5), for this behavior to work reliably, " -"the default Kerberos realm must be set properly in /etc/krb5.conf" -msgstr "" - #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:152 sssd-ad.5.xml:1186 +#: sssd-ipa.5.xml:147 sssd-ad.5.xml:1186 msgid "dyndns_ttl (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:155 sssd-ad.5.xml:1189 +#: sssd-ipa.5.xml:150 sssd-ad.5.xml:1189 msgid "" "The TTL to apply to the client DNS record when updating it. If " "dyndns_update is false this has no effect. This will override the TTL " @@ -9887,17 +10201,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:160 +#: sssd-ipa.5.xml:155 msgid "Default: 1200 (seconds)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:166 sssd-ad.5.xml:1200 +#: sssd-ipa.5.xml:161 sssd-ad.5.xml:1200 msgid "dyndns_iface (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:169 sssd-ad.5.xml:1203 +#: sssd-ipa.5.xml:164 sssd-ad.5.xml:1203 msgid "" "Optional. Applicable only when dyndns_update is true. Choose the interface " "or a list of interfaces whose IP addresses should be used for dynamic DNS " @@ -9909,24 +10223,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:182 +#: sssd-ipa.5.xml:177 msgid "" "Default: Use the IP addresses of the interface which is used for IPA LDAP " "connection" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:186 sssd-ad.5.xml:1226 +#: sssd-ipa.5.xml:181 sssd-ad.5.xml:1220 msgid "Example: dyndns_iface = em[12], !vnet1, vnet*" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:192 sssd-ad.5.xml:1232 +#: sssd-ipa.5.xml:187 sssd-ad.5.xml:1226 msgid "dyndns_address (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:195 sssd-ad.5.xml:1235 +#: sssd-ipa.5.xml:190 sssd-ad.5.xml:1229 msgid "" "Optional. Applicable only when <emphasis>dyndns_update</emphasis> is true. " "A list of IP addresses or IP networks to be used for dynamic DNS updates. " @@ -9937,22 +10251,22 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:206 sssd-ad.5.xml:1246 +#: sssd-ipa.5.xml:201 sssd-ad.5.xml:1240 msgid "Default: No filtering of IP addresses." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:209 sssd-ad.5.xml:1249 +#: sssd-ipa.5.xml:204 sssd-ad.5.xml:1243 msgid "Example: dyndns_address = 10.0.0.0/16, !10.0.1.0/24" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:215 sssd-ad.5.xml:1305 +#: sssd-ipa.5.xml:210 sssd-ad.5.xml:1298 msgid "dyndns_auth (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:218 sssd-ad.5.xml:1308 +#: sssd-ipa.5.xml:213 sssd-ad.5.xml:1301 msgid "" "Whether the nsupdate utility should use GSS-TSIG authentication for secure " "updates with the DNS server, insecure updates can be sent by setting this " @@ -9960,17 +10274,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:224 sssd-ad.5.xml:1314 +#: sssd-ipa.5.xml:219 sssd-ad.5.xml:1307 msgid "Default: GSS-TSIG" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:230 sssd-ad.5.xml:1320 +#: sssd-ipa.5.xml:225 sssd-ad.5.xml:1313 msgid "dyndns_auth_ptr (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:233 sssd-ad.5.xml:1323 +#: sssd-ipa.5.xml:228 sssd-ad.5.xml:1316 msgid "" "Whether the nsupdate utility should use GSS-TSIG authentication for secure " "PTR updates with the DNS server, insecure updates can be sent by setting " @@ -9978,17 +10292,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:239 sssd-ad.5.xml:1329 +#: sssd-ipa.5.xml:234 sssd-ad.5.xml:1322 msgid "Default: Same as dyndns_auth" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:245 sssd-ad.5.xml:1255 +#: sssd-ipa.5.xml:240 sssd-ad.5.xml:1249 msgid "dyndns_refresh_interval (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:248 +#: sssd-ipa.5.xml:243 msgid "" "How often should the back end perform periodic DNS update in addition to the " "automatic update performed when the back end goes online. This option is " @@ -9996,74 +10310,74 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:261 sssd-ad.5.xml:1273 -msgid "dyndns_update_ptr (bool)" +#: sssd-ipa.5.xml:256 sssd-ad.5.xml:1266 +msgid "dyndns_update_ptr (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:264 sssd-ad.5.xml:1276 +#: sssd-ipa.5.xml:259 sssd-ad.5.xml:1269 msgid "" "Whether the PTR record should also be explicitly updated when updating the " "client's DNS records. Applicable only when dyndns_update is true." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:269 +#: sssd-ipa.5.xml:264 msgid "" "This option should be False in most IPA deployments as the IPA server " "generates the PTR records automatically when forward records are changed." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:275 sssd-ad.5.xml:1281 +#: sssd-ipa.5.xml:270 sssd-ad.5.xml:1274 msgid "" "Note that <emphasis>dyndns_update_per_family</emphasis> parameter does not " "apply for PTR record updates. Those updates are always sent separately." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:280 +#: sssd-ipa.5.xml:275 msgid "Default: False (disabled)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:286 sssd-ad.5.xml:1292 -msgid "dyndns_force_tcp (bool)" +#: sssd-ipa.5.xml:281 sssd-ad.5.xml:1285 +msgid "dyndns_force_tcp (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:289 sssd-ad.5.xml:1295 +#: sssd-ipa.5.xml:284 sssd-ad.5.xml:1288 msgid "" "Whether the nsupdate utility should default to using TCP for communicating " "with the DNS server." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:293 sssd-ad.5.xml:1299 +#: sssd-ipa.5.xml:288 sssd-ad.5.xml:1292 msgid "Default: False (let nsupdate choose the protocol)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:299 sssd-ad.5.xml:1335 +#: sssd-ipa.5.xml:294 sssd-ad.5.xml:1328 msgid "dyndns_server (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:302 sssd-ad.5.xml:1338 +#: sssd-ipa.5.xml:297 sssd-ad.5.xml:1331 msgid "" "The DNS server to use when performing a DNS update. In most setups, it's " "recommended to leave this option unset." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:307 sssd-ad.5.xml:1343 +#: sssd-ipa.5.xml:302 sssd-ad.5.xml:1336 msgid "" "Setting this option makes sense for environments where the DNS server is " "different from the identity server or when we use encrypted DNS." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:312 sssd-ad.5.xml:1348 +#: sssd-ipa.5.xml:307 sssd-ad.5.xml:1341 msgid "" "The parameter can be a simple string containing DNS name or IP address. It " "can also be an URI. The URI can look like <emphasis>dns://servername/</" @@ -10071,7 +10385,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:319 sssd-ad.5.xml:1355 +#: sssd-ipa.5.xml:314 sssd-ad.5.xml:1348 msgid "" "The second example enables DNS-over-TLS protocol for DNS updates. The " "nsupdate utility must support DoT - check the <emphasis>man nsupdate</" @@ -10079,7 +10393,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:325 sssd-ad.5.xml:1361 +#: sssd-ipa.5.xml:320 sssd-ad.5.xml:1354 msgid "" "Please note that this option will be only used in fallback attempt when " "previous attempt using autodetected settings failed or when DNS-over-TLS is " @@ -10087,17 +10401,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:331 sssd-ad.5.xml:1367 +#: sssd-ipa.5.xml:326 sssd-ad.5.xml:1360 msgid "Default: None (let nsupdate choose the server)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:337 sssd-ad.5.xml:1373 +#: sssd-ipa.5.xml:332 sssd-ad.5.xml:1366 msgid "dyndns_update_per_family (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:340 sssd-ad.5.xml:1376 +#: sssd-ipa.5.xml:335 sssd-ad.5.xml:1369 msgid "" "DNS update is by default performed in two steps - IPv4 update and then IPv6 " "update. In some cases it might be desirable to perform IPv4 and IPv6 update " @@ -10105,12 +10419,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:352 sssd-ad.5.xml:1388 +#: sssd-ipa.5.xml:347 sssd-ad.5.xml:1381 msgid "dyndns_dot_cacert (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:355 sssd-ad.5.xml:1391 +#: sssd-ipa.5.xml:350 sssd-ad.5.xml:1384 msgid "" "This option specifies the file of the certificate authorities certificates " "(in PEM format) in order to verify the remote server TLS certificate when " @@ -10118,17 +10432,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:361 sssd-ad.5.xml:1397 +#: sssd-ipa.5.xml:356 sssd-ad.5.xml:1390 msgid "Default: None (use global certificate store)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:367 sssd-ad.5.xml:1403 +#: sssd-ipa.5.xml:362 sssd-ad.5.xml:1396 msgid "dyndns_dot_cert (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:370 sssd-ad.5.xml:1406 +#: sssd-ipa.5.xml:365 sssd-ad.5.xml:1399 msgid "" "This option sets the certificate(s) file for authentication for the DoT " "transport to the remote server. The certificate chain file is expected to be " @@ -10136,24 +10450,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:376 sssd-ad.5.xml:1412 +#: sssd-ipa.5.xml:371 sssd-ad.5.xml:1405 msgid "" "The <emphasis>dyndns_dot_cert</emphasis> and <emphasis>dyndns_dot_key</" "emphasis> options must be both set to achieve mutual TLS authentication." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:381 sssd-ipa.5.xml:396 sssd-ad.5.xml:1417 sssd-ad.5.xml:1432 +#: sssd-ipa.5.xml:376 sssd-ipa.5.xml:391 sssd-ad.5.xml:1410 sssd-ad.5.xml:1425 msgid "Default: None (Do not use TLS authentication)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:387 sssd-ad.5.xml:1423 +#: sssd-ipa.5.xml:382 sssd-ad.5.xml:1416 msgid "dyndns_dot_key (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:390 sssd-ad.5.xml:1426 +#: sssd-ipa.5.xml:385 sssd-ad.5.xml:1419 msgid "" "This option sets the key file for authenticated encryption for the DoT " "transport to the remote server. The private key file is expected to be in " @@ -10161,170 +10475,170 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:402 +#: sssd-ipa.5.xml:397 msgid "ipa_access_order (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:409 +#: sssd-ipa.5.xml:404 msgid "<emphasis>expire</emphasis>: use IPA's account expiration policy." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:448 +#: sssd-ipa.5.xml:443 msgid "" "Please note that 'access_provider = ipa' must be set for this feature to " "work." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:455 +#: sssd-ipa.5.xml:450 msgid "ipa_deskprofile_search_base (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:458 +#: sssd-ipa.5.xml:453 msgid "" "Optional. Use the given string as search base for Desktop Profile related " "objects." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:462 sssd-ipa.5.xml:484 +#: sssd-ipa.5.xml:457 sssd-ipa.5.xml:479 msgid "Default: Use base DN" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:468 +#: sssd-ipa.5.xml:463 msgid "ipa_subid_ranges_search_base (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:471 +#: sssd-ipa.5.xml:466 msgid "Deprecated. Use ldap_subid_ranges_search_base instead." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:477 +#: sssd-ipa.5.xml:472 msgid "ipa_hbac_search_base (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:480 +#: sssd-ipa.5.xml:475 msgid "Optional. Use the given string as search base for HBAC related objects." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:490 +#: sssd-ipa.5.xml:485 msgid "ipa_host_search_base (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:493 +#: sssd-ipa.5.xml:488 msgid "Deprecated. Use ldap_host_search_base instead." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:499 +#: sssd-ipa.5.xml:494 msgid "ipa_selinux_search_base (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:502 +#: sssd-ipa.5.xml:497 msgid "Optional. Use the given string as search base for SELinux user maps." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:518 +#: sssd-ipa.5.xml:513 msgid "ipa_subdomains_search_base (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:521 +#: sssd-ipa.5.xml:516 msgid "Optional. Use the given string as search base for trusted domains." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:530 +#: sssd-ipa.5.xml:525 msgid "Default: the value of <emphasis>cn=trusts,%basedn</emphasis>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:537 +#: sssd-ipa.5.xml:532 msgid "ipa_master_domain_search_base (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:540 +#: sssd-ipa.5.xml:535 msgid "Optional. Use the given string as search base for master domain object." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:549 +#: sssd-ipa.5.xml:544 msgid "Default: the value of <emphasis>cn=ad,cn=etc,%basedn</emphasis>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:556 +#: sssd-ipa.5.xml:551 msgid "ipa_views_search_base (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:559 +#: sssd-ipa.5.xml:554 msgid "Optional. Use the given string as search base for views containers." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:568 +#: sssd-ipa.5.xml:563 msgid "Default: the value of <emphasis>cn=views,cn=accounts,%basedn</emphasis>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:578 +#: sssd-ipa.5.xml:573 msgid "" "The name of the Kerberos realm. This is optional and defaults to the value " "of <quote>ipa_domain</quote>." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:582 +#: sssd-ipa.5.xml:577 msgid "" "The name of the Kerberos realm has a special meaning in IPA - it is " "converted into the base DN to use for performing LDAP operations." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:590 sssd-ad.5.xml:1441 +#: sssd-ipa.5.xml:585 sssd-ad.5.xml:1434 msgid "krb5_confd_path (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:593 sssd-ad.5.xml:1444 +#: sssd-ipa.5.xml:588 sssd-ad.5.xml:1437 msgid "" "Absolute path of a directory where SSSD should place Kerberos configuration " "snippets." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:597 sssd-ad.5.xml:1448 +#: sssd-ipa.5.xml:592 sssd-ad.5.xml:1441 msgid "" "To disable the creation of the configuration snippets set the parameter to " "'none'." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:601 sssd-ad.5.xml:1452 +#: sssd-ipa.5.xml:596 sssd-ad.5.xml:1445 msgid "" "Default: not set (krb5.include.d subdirectory of SSSD's pubconf directory)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:608 +#: sssd-ipa.5.xml:603 msgid "ipa_deskprofile_refresh (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:611 +#: sssd-ipa.5.xml:606 msgid "" "The amount of time between lookups of the Desktop Profile rules against the " "IPA server. This will reduce the latency and load on the IPA server if there " @@ -10332,34 +10646,34 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:618 sssd-ipa.5.xml:648 sssd-ipa.5.xml:664 sssd-ad.5.xml:600 +#: sssd-ipa.5.xml:613 sssd-ipa.5.xml:643 sssd-ipa.5.xml:659 sssd-ad.5.xml:600 msgid "Default: 5 (seconds)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:624 +#: sssd-ipa.5.xml:619 msgid "ipa_deskprofile_request_interval (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:627 +#: sssd-ipa.5.xml:622 msgid "" "The amount of time between lookups of the Desktop Profile rules against the " "IPA server in case the last request did not return any rule." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:632 +#: sssd-ipa.5.xml:627 msgid "Default: 60 (minutes)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:638 +#: sssd-ipa.5.xml:633 msgid "ipa_hbac_refresh (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:641 +#: sssd-ipa.5.xml:636 msgid "" "The amount of time between lookups of the HBAC rules against the IPA server. " "This will reduce the latency and load on the IPA server if there are many " @@ -10367,12 +10681,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:654 -msgid "ipa_hbac_selinux (integer)" -msgstr "" +#: sssd-ipa.5.xml:649 +#, fuzzy +#| msgid "timeout (integer)" +msgid "ipa_selinux_refresh (integer)" +msgstr "noildze (vesels skaitlis)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:657 +#: sssd-ipa.5.xml:652 msgid "" "The amount of time between lookups of the SELinux maps against the IPA " "server. This will reduce the latency and load on the IPA server if there are " @@ -10380,33 +10696,33 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:670 +#: sssd-ipa.5.xml:665 msgid "ipa_server_mode (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:673 +#: sssd-ipa.5.xml:668 msgid "" "This option will be set by the IPA installer (ipa-server-install) " "automatically and denotes if SSSD is running on an IPA server or not." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:678 +#: sssd-ipa.5.xml:673 msgid "" "On an IPA server SSSD will lookup users and groups from trusted domains " "directly while on a client it will ask an IPA server." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:683 +#: sssd-ipa.5.xml:678 msgid "" "NOTE: There are currently some assumptions that must be met when SSSD is " "running on an IPA server." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:688 +#: sssd-ipa.5.xml:683 msgid "" "The <quote>ipa_server</quote> option must be configured to point to the IPA " "server itself. This is already the default set by the IPA installer, so no " @@ -10414,59 +10730,59 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:697 +#: sssd-ipa.5.xml:692 msgid "" "The <quote>full_name_format</quote> option must not be tweaked to only print " "short names for users from trusted domains." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:712 +#: sssd-ipa.5.xml:707 msgid "ipa_automount_location (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:715 +#: sssd-ipa.5.xml:710 msgid "The automounter location this IPA client will be using" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:718 +#: sssd-ipa.5.xml:713 msgid "Default: The location named \"default\"" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd-ipa.5.xml:726 +#: sssd-ipa.5.xml:721 msgid "VIEWS AND OVERRIDES" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:735 +#: sssd-ipa.5.xml:730 msgid "ipa_view_class (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:738 +#: sssd-ipa.5.xml:733 msgid "Objectclass of the view container." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:741 +#: sssd-ipa.5.xml:736 msgid "Default: nsContainer" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:747 +#: sssd-ipa.5.xml:742 msgid "ipa_view_name (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:750 +#: sssd-ipa.5.xml:745 msgid "Name of the attribute holding the name of the view." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:754 sssd-ldap-attributes.5.xml:496 +#: sssd-ipa.5.xml:749 sssd-ldap-attributes.5.xml:496 #: sssd-ldap-attributes.5.xml:832 sssd-ldap-attributes.5.xml:913 #: sssd-ldap-attributes.5.xml:1010 sssd-ldap-attributes.5.xml:1068 #: sssd-ldap-attributes.5.xml:1226 sssd-ldap-attributes.5.xml:1271 @@ -10474,128 +10790,128 @@ msgid "Default: cn" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:760 +#: sssd-ipa.5.xml:755 msgid "ipa_override_object_class (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:763 +#: sssd-ipa.5.xml:758 msgid "Objectclass of the override objects." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:766 +#: sssd-ipa.5.xml:761 msgid "Default: ipaOverrideAnchor" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:772 +#: sssd-ipa.5.xml:767 msgid "ipa_anchor_uuid (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:775 +#: sssd-ipa.5.xml:770 msgid "" "Name of the attribute containing the reference to the original object in a " "remote domain." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:779 +#: sssd-ipa.5.xml:774 msgid "Default: ipaAnchorUUID" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:785 +#: sssd-ipa.5.xml:780 msgid "ipa_user_override_object_class (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:788 +#: sssd-ipa.5.xml:783 msgid "" "Name of the objectclass for user overrides. It is used to determine if the " "found override object is related to a user or a group." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:793 +#: sssd-ipa.5.xml:788 msgid "User overrides can contain attributes given by" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:796 +#: sssd-ipa.5.xml:791 msgid "ldap_user_name" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:799 +#: sssd-ipa.5.xml:794 msgid "ldap_user_uid_number" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:802 +#: sssd-ipa.5.xml:797 msgid "ldap_user_gid_number" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:805 +#: sssd-ipa.5.xml:800 msgid "ldap_user_gecos" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:808 +#: sssd-ipa.5.xml:803 msgid "ldap_user_home_directory" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:811 +#: sssd-ipa.5.xml:806 msgid "ldap_user_shell" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:814 +#: sssd-ipa.5.xml:809 msgid "ldap_user_ssh_public_key" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:819 +#: sssd-ipa.5.xml:814 msgid "Default: ipaUserOverride" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:825 +#: sssd-ipa.5.xml:820 msgid "ipa_group_override_object_class (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:828 +#: sssd-ipa.5.xml:823 msgid "" "Name of the objectclass for group overrides. It is used to determine if the " "found override object is related to a user or a group." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:833 +#: sssd-ipa.5.xml:828 msgid "Group overrides can contain attributes given by" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:836 +#: sssd-ipa.5.xml:831 msgid "ldap_group_name" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:839 +#: sssd-ipa.5.xml:834 msgid "ldap_group_gid_number" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:844 +#: sssd-ipa.5.xml:839 msgid "Default: ipaGroupOverride" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:728 +#: sssd-ipa.5.xml:723 msgid "" "SSSD can handle views and overrides which are offered by FreeIPA 4.1 and " "later version. Since all paths and objectclasses are fixed on the server " @@ -10605,19 +10921,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd-ipa.5.xml:856 +#: sssd-ipa.5.xml:851 msgid "SUBDOMAINS PROVIDER" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:858 +#: sssd-ipa.5.xml:853 msgid "" "The IPA subdomains provider behaves slightly differently if it is configured " "explicitly or implicitly." msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:862 +#: sssd-ipa.5.xml:857 msgid "" "If the option 'subdomains_provider = ipa' is found in the domain section of " "sssd.conf, the IPA subdomains provider is configured explicitly, and all " @@ -10625,7 +10941,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:868 +#: sssd-ipa.5.xml:863 msgid "" "If the option 'subdomains_provider' is not set in the domain section of " "sssd.conf but there is the option 'id_provider = ipa', the IPA subdomains " @@ -10637,12 +10953,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd-ipa.5.xml:879 +#: sssd-ipa.5.xml:874 msgid "TRUSTED DOMAINS CONFIGURATION" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-ipa.5.xml:887 +#: sssd-ipa.5.xml:882 #, no-wrap msgid "" "[domain/ipa.domain.com/ad.domain.com]\n" @@ -10650,7 +10966,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:881 +#: sssd-ipa.5.xml:876 msgid "" "Some configuration options can also be set for a trusted domain. A trusted " "domain configuration can be set using the trusted domain subsection as shown " @@ -10660,97 +10976,97 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:892 +#: sssd-ipa.5.xml:887 msgid "" "For more details, see the <citerefentry> <refentrytitle>sssd.conf</" "refentrytitle> <manvolnum>5</manvolnum> </citerefentry> manual page." msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:899 +#: sssd-ipa.5.xml:894 msgid "" "Different configuration options are tunable for a trusted domain depending " "on whether you are configuring SSSD on an IPA server or an IPA client." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd-ipa.5.xml:904 +#: sssd-ipa.5.xml:899 msgid "OPTIONS TUNABLE ON IPA MASTERS" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:906 +#: sssd-ipa.5.xml:901 msgid "" "The following options can be set in a subdomain section on an IPA master:" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:910 sssd-ipa.5.xml:950 +#: sssd-ipa.5.xml:905 sssd-ipa.5.xml:945 msgid "ad_server" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:913 +#: sssd-ipa.5.xml:908 msgid "ad_backup_server" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:916 sssd-ipa.5.xml:953 +#: sssd-ipa.5.xml:911 sssd-ipa.5.xml:948 msgid "ad_site" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:919 +#: sssd-ipa.5.xml:914 msgid "ipa_server" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:922 +#: sssd-ipa.5.xml:917 msgid "ipa_backup_server" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:925 +#: sssd-ipa.5.xml:920 msgid "ldap_search_base" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:928 +#: sssd-ipa.5.xml:923 msgid "ldap_user_search_base" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:931 +#: sssd-ipa.5.xml:926 msgid "ldap_group_search_base" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:939 +#: sssd-ipa.5.xml:934 msgid "" "Options prefixed with 'ad_' or 'ipa_' only apply to their respective " "subdomain type." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd-ipa.5.xml:944 +#: sssd-ipa.5.xml:939 msgid "OPTIONS TUNABLE ON IPA CLIENTS" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:946 +#: sssd-ipa.5.xml:941 msgid "" "The following options can be set in an AD subdomain section on an IPA client:" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:958 +#: sssd-ipa.5.xml:953 msgid "" "Note that if both options are set, only <quote>ad_server</quote> is " "evaluated." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:962 +#: sssd-ipa.5.xml:957 msgid "" "Since any request for a user or a group identity from a trusted domain " "triggered from an IPA client is resolved by the IPA server, the " @@ -10764,7 +11080,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:986 +#: sssd-ipa.5.xml:981 msgid "" "The following example assumes that SSSD is correctly configured and " "example.com is one of the domains in the <replaceable>[sssd]</replaceable> " @@ -10772,7 +11088,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-ipa.5.xml:993 +#: sssd-ipa.5.xml:988 #, no-wrap msgid "" "[domain/example.com]\n" @@ -11477,27 +11793,27 @@ msgid "lxdm" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:694 +#: sssd-ad.5.xml:699 msgid "sddm" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:699 +#: sssd-ad.5.xml:704 msgid "unity" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:704 +#: sssd-ad.5.xml:709 msgid "xdm" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:713 +#: sssd-ad.5.xml:718 msgid "ad_gpo_map_remote_interactive (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:716 +#: sssd-ad.5.xml:721 msgid "" "A comma-separated list of PAM service names for which GPO-based access " "control is evaluated based on the RemoteInteractiveLogonRight and " @@ -11513,7 +11829,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:735 +#: sssd-ad.5.xml:740 msgid "" "Note: Using the Group Policy Management Editor this value is called \"Allow " "log on through Remote Desktop Services\" and \"Deny log on through Remote " @@ -11521,7 +11837,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:750 +#: sssd-ad.5.xml:755 #, no-wrap msgid "" "ad_gpo_map_remote_interactive = +my_pam_service, -sshd\n" @@ -11529,7 +11845,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:741 +#: sssd-ad.5.xml:746 msgid "" "It is possible to add another PAM service name to the default set by using " "<quote>+service_name</quote> or to explicitly remove a PAM service name from " @@ -11541,22 +11857,22 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:758 +#: sssd-ad.5.xml:763 msgid "sshd" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:763 +#: sssd-ad.5.xml:768 msgid "cockpit" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:772 +#: sssd-ad.5.xml:777 msgid "ad_gpo_map_network (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:775 +#: sssd-ad.5.xml:780 msgid "" "A comma-separated list of PAM service names for which GPO-based access " "control is evaluated based on the NetworkLogonRight and " @@ -11572,7 +11888,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:793 +#: sssd-ad.5.xml:798 msgid "" "Note: Using the Group Policy Management Editor this value is called \"Access " "this computer from the network\" and \"Deny access to this computer from the " @@ -11580,7 +11896,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:808 +#: sssd-ad.5.xml:813 #, no-wrap msgid "" "ad_gpo_map_network = +my_pam_service, -ftp\n" @@ -11588,7 +11904,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:799 +#: sssd-ad.5.xml:804 msgid "" "It is possible to add another PAM service name to the default set by using " "<quote>+service_name</quote> or to explicitly remove a PAM service name from " @@ -11600,22 +11916,22 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:816 +#: sssd-ad.5.xml:821 msgid "ftp" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:821 +#: sssd-ad.5.xml:826 msgid "samba" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:830 +#: sssd-ad.5.xml:835 msgid "ad_gpo_map_batch (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:833 +#: sssd-ad.5.xml:838 msgid "" "A comma-separated list of PAM service names for which GPO-based access " "control is evaluated based on the BatchLogonRight and DenyBatchLogonRight " @@ -11630,14 +11946,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:851 +#: sssd-ad.5.xml:856 msgid "" "Note: Using the Group Policy Management Editor this value is called \"Allow " "log on as a batch job\" and \"Deny log on as a batch job\"." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:865 +#: sssd-ad.5.xml:870 #, no-wrap msgid "" "ad_gpo_map_batch = +my_pam_service, -crond\n" @@ -11645,7 +11961,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:856 +#: sssd-ad.5.xml:861 msgid "" "It is possible to add another PAM service name to the default set by using " "<quote>+service_name</quote> or to explicitly remove a PAM service name from " @@ -11657,23 +11973,23 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:868 +#: sssd-ad.5.xml:873 msgid "" "Note: Cron service name may differ depending on Linux distribution used." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:874 +#: sssd-ad.5.xml:879 msgid "crond" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:883 +#: sssd-ad.5.xml:888 msgid "ad_gpo_map_service (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:886 +#: sssd-ad.5.xml:891 msgid "" "A comma-separated list of PAM service names for which GPO-based access " "control is evaluated based on the ServiceLogonRight and " @@ -11689,14 +12005,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:904 +#: sssd-ad.5.xml:909 msgid "" "Note: Using the Group Policy Management Editor this value is called \"Allow " "log on as a service\" and \"Deny log on as a service\"." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:917 +#: sssd-ad.5.xml:922 #, no-wrap msgid "" "ad_gpo_map_service = +my_pam_service\n" @@ -11704,7 +12020,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:909 sssd-ad.5.xml:984 +#: sssd-ad.5.xml:914 sssd-ad.5.xml:989 msgid "" "It is possible to add a PAM service name to the default set by using " "<quote>+service_name</quote>. Since the default set is empty, it is not " @@ -11715,19 +12031,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:927 +#: sssd-ad.5.xml:932 msgid "ad_gpo_map_permit (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:930 +#: sssd-ad.5.xml:935 msgid "" "A comma-separated list of PAM service names for which GPO-based access is " "always granted, regardless of any GPO Logon Rights." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:944 +#: sssd-ad.5.xml:949 #, no-wrap msgid "" "ad_gpo_map_permit = +my_pam_service, -sudo\n" @@ -11735,7 +12051,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:935 +#: sssd-ad.5.xml:940 msgid "" "It is possible to add another PAM service name to the default set by using " "<quote>+service_name</quote> or to explicitly remove a PAM service name from " @@ -11747,29 +12063,29 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:952 +#: sssd-ad.5.xml:957 msgid "polkit-1" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:967 +#: sssd-ad.5.xml:972 msgid "systemd-user" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:976 +#: sssd-ad.5.xml:981 msgid "ad_gpo_map_deny (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:979 +#: sssd-ad.5.xml:984 msgid "" "A comma-separated list of PAM service names for which GPO-based access is " "always denied, regardless of any GPO Logon Rights." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:992 +#: sssd-ad.5.xml:997 #, no-wrap msgid "" "ad_gpo_map_deny = +my_pam_service\n" @@ -11777,12 +12093,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:1002 +#: sssd-ad.5.xml:1007 msgid "ad_gpo_default_right (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1005 +#: sssd-ad.5.xml:1010 msgid "" "This option defines how access control is evaluated for PAM service names " "that are not explicitly listed in one of the ad_gpo_map_* options. This " @@ -11795,52 +12111,52 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1018 +#: sssd-ad.5.xml:1023 msgid "Supported values for this option include:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1027 +#: sssd-ad.5.xml:1032 msgid "remote_interactive" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1032 +#: sssd-ad.5.xml:1037 msgid "network" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1037 +#: sssd-ad.5.xml:1042 msgid "batch" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1042 +#: sssd-ad.5.xml:1047 msgid "service" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1047 +#: sssd-ad.5.xml:1052 msgid "permit" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1052 +#: sssd-ad.5.xml:1057 msgid "deny" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1058 +#: sssd-ad.5.xml:1063 msgid "Default: deny" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:1064 +#: sssd-ad.5.xml:1069 msgid "ad_maximum_machine_account_password_age (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1067 +#: sssd-ad.5.xml:1072 msgid "" "SSSD will check once a day if the machine account password is older than the " "given age in days and try to renew it. A value of 0 will disable the renewal " @@ -11848,17 +12164,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1073 +#: sssd-ad.5.xml:1078 msgid "Default: 30 days" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:1079 +#: sssd-ad.5.xml:1084 msgid "ad_machine_account_password_renewal_opts (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1082 +#: sssd-ad.5.xml:1087 msgid "" "This option should only be used to test the machine account renewal task. " "The option expects 3 integers and a string separated by a colon (':'). The " @@ -11871,20 +12187,20 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1096 +#: sssd-ad.5.xml:1101 msgid "" "The optional fourth string value identifies the helper binary which should " "be used for the renewal. Currently <command>adcli</command> and " "<command>realm</command> are supported. If this value is missing or empty in " "the value string <command>realm</command> will be used. Since the helper is " "started as the user SSSD is running as there might be the chance that the " -"renewal will fail if this user does not has permissions to modify the keytab " -"file where the machine account credentials are stored. This will typically " -"be the case for <command>adcli</command>." +"renewal will fail if this user does not have permissions to modify the " +"keytab file where the machine account credentials are stored. This will " +"typically be the case for <command>adcli</command>." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1110 +#: sssd-ad.5.xml:1115 msgid "" "<command>realm</command> is not updating the keytab directly but is calling " "the <command>realmd</command> process, which runs as root user, for this " @@ -11894,17 +12210,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1119 +#: sssd-ad.5.xml:1124 msgid "Default: 86400:750:300:realm (24h, 12m30s and 5m)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:1125 +#: sssd-ad.5.xml:1130 msgid "ad_update_samba_machine_account_password (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1128 +#: sssd-ad.5.xml:1133 msgid "" "If enabled, when SSSD renews the machine account password, it will also be " "updated in Samba's database. This prevents Samba's copy of the machine " @@ -11913,23 +12229,23 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:1141 -msgid "ad_use_ldaps (bool)" +#: sssd-ad.5.xml:1146 +msgid "ad_use_ldaps (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1144 +#: sssd-ad.5.xml:1149 msgid "" "By default SSSD uses the plain LDAP port 389 and the Global Catalog port " -"3628. If this option is set to True SSSD will use the LDAPS port 636 and " -"Global Catalog port 3629 with LDAPS protection. Since AD does not allow to " +"3268. If this option is set to True SSSD will use the LDAPS port 636 and " +"Global Catalog port 3269 with LDAPS protection. Since AD does not allow to " "have multiple encryption layers on a single connection and we still want to " "use SASL/GSSAPI or SASL/GSS-SPNEGO for authentication the SASL security " "property maxssf is set to 0 (zero) for those connections." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1164 +#: sssd-ad.5.xml:1169 msgid "" "Optional. This option tells SSSD to automatically update the Active " "Directory DNS server with the IP address of this client. The update is " @@ -11947,30 +12263,21 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:1216 msgid "" -"NOTE: While it is still possible to use the old <emphasis>ipa_dyndns_iface</" -"emphasis> option, users should migrate to using <emphasis>dyndns_iface</" -"emphasis> in their config file." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1222 -msgid "" "Default: Use the IP addresses of the interface which is used for AD LDAP " "connection" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1258 +#: sssd-ad.5.xml:1252 msgid "" "How often should the back end perform periodic DNS update in addition to the " -"automatic update performed when the back end goes online. This option is " -"optional and applicable only when dyndns_update is true. Note that the " -"lowest possible value is 60 seconds in-case if value is provided less than " -"60, parameter will assume lowest value only." +"automatic update performed when the back end goes online. This is optional " +"and applicable only when dyndns_update is true. Note that the minimum value " +"is 60 seconds, any specified value below this threshold will default to 60." msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ad.5.xml:1472 +#: sssd-ad.5.xml:1465 msgid "" "The following example assumes that SSSD is correctly configured and " "example.com is one of the domains in the <replaceable>[sssd]</replaceable> " @@ -11978,7 +12285,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-ad.5.xml:1479 +#: sssd-ad.5.xml:1472 #, no-wrap msgid "" "[domain/EXAMPLE]\n" @@ -11993,7 +12300,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-ad.5.xml:1499 +#: sssd-ad.5.xml:1492 #, no-wrap msgid "" "access_provider = ldap\n" @@ -12002,7 +12309,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ad.5.xml:1495 +#: sssd-ad.5.xml:1488 msgid "" "The AD access control provider checks if the account is expired. It has the " "same effect as the following configuration of the LDAP provider: " @@ -12010,7 +12317,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ad.5.xml:1505 +#: sssd-ad.5.xml:1498 msgid "" "However, unless the <quote>ad</quote> access control provider is explicitly " "configured, the default access provider is <quote>permit</quote>. Please " @@ -12020,7 +12327,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ad.5.xml:1513 +#: sssd-ad.5.xml:1506 msgid "" "When the autofs provider is set to <quote>ad</quote>, the RFC2307 schema " "attribute mapping (nisMap, nisObject, ...) is used, because these attributes " @@ -12174,9 +12481,9 @@ msgstr "" #: sssd-sudo.5.xml:137 msgid "" "The <emphasis>smart refresh</emphasis> periodically downloads rules that are " -"new or were modified after the last update. Its primary goal is to keep the " -"database growing by fetching only small increments that do not generate " -"large amounts of network traffic." +"new or were modified after the last update. Its primary goal is to grow the " +"database incrementally by fetching only small updates, avoiding large " +"amounts of network traffic." msgstr "" #. type: Content of: <reference><refentry><refsect1><para> @@ -12358,24 +12665,27 @@ msgstr "" msgid "" "Depending on the IdP product additional platform specific options might " "follow the name separated by a colon (:). E.g. for Keycloak the base URI for " -"the user and group REST API must be given. For Entra ID this is not needed " -"because there is a generic endpoint for all tenants." +"the user and group REST API must be given. For Entra ID the base URI for the " +"Microsoft Graph API can be given to use sovereign or government cloud " +"endpoints instead of the default (https://graph.microsoft.com/v1.0). E.g. " +"<quote>entra_id:https://graph.microsoft.us/v1.0</quote> for the US " +"government cloud (GCC High)." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:78 sssd-idp.5.xml:94 sssd-idp.5.xml:119 +#: sssd-idp.5.xml:82 sssd-idp.5.xml:98 sssd-idp.5.xml:123 #, fuzzy #| msgid "Default: 0 (unlimited)" msgid "Default: Not set (Required)" msgstr "Noklusējuma: 0 (neierobežots)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:83 +#: sssd-idp.5.xml:87 msgid "idp_client_id (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:86 +#: sssd-idp.5.xml:90 msgid "" "ID of the IdP client used by SSSD to authenticate users and as a client to " "lookup user and group attributes. This client must offer device " @@ -12384,12 +12694,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:99 +#: sssd-idp.5.xml:103 msgid "idp_client_secret (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:102 +#: sssd-idp.5.xml:106 msgid "" "Password of the IdP client. The password is required for the id_provider. If " "only used as auth_provider it depends on the server side configuration if it " @@ -12397,66 +12707,73 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:113 +#: sssd-idp.5.xml:117 msgid "idp_token_endpoint (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:116 +#: sssd-idp.5.xml:120 msgid "IdP endpoint for requesting access tokens." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:124 +#: sssd-idp.5.xml:128 msgid "idp_device_auth_endpoint (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:127 +#: sssd-idp.5.xml:131 msgid "" "IdP endpoint for device authorization according to RFC-8628. This is " "required for user authentication." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:137 +#: sssd-idp.5.xml:141 msgid "idp_userinfo_endpoint (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:140 +#: sssd-idp.5.xml:144 msgid "" "IdP userinfo endpoint to request user attributes after a successful " "authentication of the user. Required for authentication." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:150 +#: sssd-idp.5.xml:154 msgid "idp_id_scope (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:153 +#: sssd-idp.5.xml:157 msgid "" "Scope required for looking up user and group attributes with the REST API. " "The scopes are used by the server to determine which attributes/claims are " "returned to the caller." msgstr "" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:163 +msgid "" +"Note: In previous versions of SSSD, this option was expected to already be " +"URL-encoded." +msgstr "" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:164 +#: sssd-idp.5.xml:172 msgid "idp_auth_scope (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:167 +#: sssd-idp.5.xml:175 msgid "" "Scope required during authentication. The scopes are used by the server to " "determine which attributes/claims are returned to the caller." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:172 +#: sssd-idp.5.xml:180 msgid "" "Currently the tokens returned during user authentication are not used for " "other purposes hence the only important claim is the subject identifier " @@ -12465,26 +12782,120 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:185 +#: sssd-idp.5.xml:193 +msgid "idp_auth_user_identifier_attr (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:196 +msgid "" +"Attribute used to identify the authenticated user in userinfo data or token " +"claims." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:200 +msgid "" +"For hybrid Active Directory and Entra ID deployments where " +"<quote>id_provider = ad</quote> and <quote>auth_provider = idp</quote>, this " +"option must be set explicitly. No value is derived from the identity " +"provider, because more than one attribute can link an Entra ID object to its " +"on-premises counterpart and only the administrator knows which one the " +"directory synchronization is configured to use." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:211 +msgid "" +"Setting this option to <quote>onPremisesImmutableId</quote> is the usual " +"choice for such deployments. Microsoft Entra Connect populates that " +"attribute with the base64-encoded form of the 16-byte Active Directory " +"<quote>objectGUID</quote> when objectGUID is used as the sourceAnchor. SSSD " +"decodes the value and converts the raw bytes with the same conversion used " +"for AD objectGUID attributes, so the result matches the UUID stored in the " +"SSSD cache for the AD user." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:224 +msgid "" +"Note that Microsoft Entra Connect 1.1.524.0 and later use <quote>ms-DS-" +"ConsistencyGuid</quote> as the sourceAnchor for user objects instead of " +"<quote>objectGUID</quote>. The value is normally copied from objectGUID for " +"objects that do not have it set yet, in which case the decoded identifier " +"still matches. It does not match if ms-DS-ConsistencyGuid was populated " +"independently, if users were moved between forests or domains, or if a " +"different attribute such as employeeID was selected as the sourceAnchor. See " +"<ulink url=\"https://learn.microsoft.com/en-us/entra/identity/hybrid/connect/" +"plan-connect-design-concepts\"> Microsoft Entra Connect: Design concepts</" +"ulink> for details on sourceAnchor selection." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:241 +msgid "" +"Microsoft Graph does not return <quote>onPremisesImmutableId</quote> by " +"default. The <quote>idp_userinfo_endpoint</quote> must request it with " +"<quote>$select</quote>, see the example below and <ulink url=\"https://" +"learn.microsoft.com/en-us/graph/api/resources/user\"> the Microsoft Graph " +"user resource type</ulink>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:251 +msgid "" +"If the configured attribute is missing or cannot be decoded (for example " +"cloud-only Entra ID users without <quote>onPremisesImmutableId</quote>), " +"authentication fails. SSSD does not fall back to another attribute when this " +"option is set." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:258 +msgid "" +"Default: not set, <quote>sub</quote> for Keycloak and <quote>id</quote> for " +"other IdP types" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-idp.5.xml:264 #, fuzzy #| msgid "timeout (integer)" msgid "idp_request_timeout (integer)" msgstr "noildze (vesels skaitlis)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:188 +#: sssd-idp.5.xml:267 msgid "Timeout in seconds for an individual request to the IdP." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:197 +#: sssd-idp.5.xml:276 +msgid "idp_auto_refresh (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:279 +msgid "" +"Refresh tokens automatically, after they have reached about half their " +"lifetime." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:283 +msgid "" +"Note: Scheduled token refreshes are not preserved across restarts of SSSD." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-idp.5.xml:292 #, fuzzy #| msgid "timeout (integer)" msgid "idmap_range_min (integer)" msgstr "noildze (vesels skaitlis)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:200 +#: sssd-idp.5.xml:295 msgid "" "Specifies the lower (inclusive) bound of the range of POSIX IDs to use for " "mapping IdP users and group to POSIX IDs. It is the first POSIX ID which can " @@ -12492,7 +12903,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:206 +#: sssd-idp.5.xml:301 msgid "" "The interval between <quote>idmap_range_min</quote> and " "<quote>idmap_range_max</quote> will be split into smaller ranges of size " @@ -12501,20 +12912,20 @@ msgid "" msgstr "" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:213 sssd-idp.5.xml:239 include/ldap_id_mapping.xml:139 +#: sssd-idp.5.xml:308 sssd-idp.5.xml:334 include/ldap_id_mapping.xml:139 #: include/ldap_id_mapping.xml:197 msgid "Default: 200000" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:218 +#: sssd-idp.5.xml:313 #, fuzzy #| msgid "timeout (integer)" msgid "idmap_range_max (integer)" msgstr "noildze (vesels skaitlis)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:221 +#: sssd-idp.5.xml:316 msgid "" "Specifies the upper (exclusive) bound of the range of POSIX IDs to use for " "mapping IdP users and groups to POSIX IDs. It is the first POSIX ID which " @@ -12522,47 +12933,70 @@ msgid "" msgstr "" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:227 include/ldap_id_mapping.xml:165 +#: sssd-idp.5.xml:322 include/ldap_id_mapping.xml:165 msgid "Default: 2000200000" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:232 +#: sssd-idp.5.xml:327 #, fuzzy #| msgid "timeout (integer)" msgid "idmap_range_size (integer)" msgstr "noildze (vesels skaitlis)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:235 +#: sssd-idp.5.xml:330 msgid "Specifies the number of POSIX IDs available for a single IdP domain." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-idp.5.xml:251 +#: sssd-idp.5.xml:346 #, no-wrap msgid "" "[domain/entra_id]\n" "id_provider = idp\n" "idp_type = entra_id\n" "idp_client_id = 12345678-abcd-0101-efef-ba9876543210\n" -"idp_client_secret = YOUR-CLIENT-SCERET\n" -"idp_token_endpoint = https://login.microsoftonline.com/TENNANT-ID/oauth2/v2.0/token\n" +"idp_client_secret = YOUR-CLIENT-SECRET\n" +"idp_token_endpoint = https://login.microsoftonline.com/TENANT-ID/oauth2/v2.0/token\n" "idp_userinfo_endpoint = https://graph.microsoft.com/v1.0/me\n" -"idp_device_auth_endpoint = https://login.microsoftonline.com/TENNANT-ID/oauth2/v2.0/devicecode\n" -"idp_id_scope = https%3A%2F%2Fgraph.microsoft.com%2F.default\n" +"idp_device_auth_endpoint = https://login.microsoftonline.com/TENANT-ID/oauth2/v2.0/devicecode\n" +"idp_id_scope = https://graph.microsoft.com/.default\n" +"idp_auth_scope = openid profile email\n" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><programlisting> +#: sssd-idp.5.xml:358 +#, no-wrap +msgid "" +"[domain/ad.example.com]\n" +"id_provider = ad\n" +"auth_provider = idp\n" +"access_provider = permit\n" +"\n" +"ad_domain = ad.example.com\n" +"krb5_realm = AD.EXAMPLE.COM\n" +"\n" +"idp_type = entra_id\n" +"idp_client_id = 12345678-abcd-0101-efef-ba9876543210\n" +"idp_client_secret = YOUR-CLIENT-SECRET\n" +"idp_token_endpoint = https://login.microsoftonline.com/TENANT-ID/oauth2/v2.0/token\n" +"idp_userinfo_endpoint = https://graph.microsoft.com/v1.0/me?$select=id,userPrincipalName,onPremisesImmutableId\n" +"idp_device_auth_endpoint = https://login.microsoftonline.com/TENANT-ID/oauth2/v2.0/devicecode\n" +"idp_id_scope = https://graph.microsoft.com/.default\n" "idp_auth_scope = openid profile email\n" +"idp_auth_user_identifier_attr = onPremisesImmutableId\n" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-idp.5.xml:263 +#: sssd-idp.5.xml:377 #, no-wrap msgid "" "[domain/keycloak]\n" "idp_type = keycloak:https://master.keycloak.test:8443/auth/admin/realms/master/\n" "id_provider = idp\n" "idp_client_id = myclient\n" -"idp_client_secret = YOUR-CLIENT-SCERET\n" +"idp_client_secret = YOUR-CLIENT-SECRET\n" "idp_token_endpoint = https://master.keycloak.test:8443/auth/realms/master/protocol/openid-connect/token\n" "idp_userinfo_endpoint = https://master.keycloak.test:8443/auth/realms/master/protocol/openid-connect/userinfo\n" "idp_device_auth_endpoint = https://master.keycloak.test:8443/auth/realms/master/protocol/openid-connect/auth/device\n" @@ -12571,10 +13005,22 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-idp.5.xml:250 +#: sssd-idp.5.xml:345 msgid "" "<placeholder type=\"programlisting\" id=\"0\"/> <placeholder " -"type=\"programlisting\" id=\"1\"/>" +"type=\"programlisting\" id=\"1\"/> <placeholder type=\"programlisting\" " +"id=\"2\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-idp.5.xml:390 +msgid "" +"In the hybrid Active Directory and Entra ID example above, " +"<quote>onPremisesImmutableId</quote> is used during authentication so the " +"IdP result matches the AD objectGUID UUID stored in the SSSD cache. The " +"attribute must be requested via <quote>$select</quote> on the Graph userinfo " +"endpoint and is only populated for users synchronized from Active Directory " +"with objectGUID as the sourceAnchor." msgstr "" #. type: Content of: <reference><refentry><refnamediv><refname> @@ -13540,7 +13986,7 @@ msgstr "" #: sssd-krb5.5.xml:291 msgid "" "<emphasis>demand</emphasis> to use FAST. The authentication fails if the " -"server does not require fast." +"server does not support FAST." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> @@ -14429,7 +14875,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sss_rpcidmapd.5.xml:69 -msgid "memcache (bool)" +msgid "memcache (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> @@ -14483,7 +14929,7 @@ msgid "" msgstr "" #. type: Content of: <refsect1><title> -#: sss_rpcidmapd.5.xml:120 sssd-kcm.8.xml:316 include/seealso.xml:2 +#: sss_rpcidmapd.5.xml:120 sssd-kcm.8.xml:315 include/seealso.xml:2 msgid "SEE ALSO" msgstr "SKATĪT ARĪ" @@ -14710,8 +15156,8 @@ msgstr "" #: sss_ssh_knownhosts.1.xml:93 msgid "" "The key lines retrieved from the backend are expected to respect the key " -"format as decribed in the <quote>SSH_KNOWN_HOSTS FILE FORMAT</quote> section " -"of <citerefentry><refentrytitle>sshd</refentrytitle> <manvolnum>8</" +"format as described in the <quote>SSH_KNOWN_HOSTS FILE FORMAT</quote> " +"section of <citerefentry><refentrytitle>sshd</refentrytitle> <manvolnum>8</" "manvolnum></citerefentry>. However, returning only the keytype and the key " "itself is tolerated, in which case, the hostname received as parameter will " "be added before the keytype to output a correctly formatted line. The " @@ -15187,14 +15633,13 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-kcm.8.xml:215 msgid "" -"The KCM service is configured in the <quote>kcm</quote> For a detailed " -"syntax reference, refer to the <quote>FILE FORMAT</quote> section of the " -"<citerefentry> <refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</" -"manvolnum> </citerefentry> manual page." +"For a detailed syntax reference, refer to the <quote>FILE FORMAT</quote> " +"section of the <citerefentry> <refentrytitle>sssd.conf</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry> manual page." msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-kcm.8.xml:223 +#: sssd-kcm.8.xml:222 msgid "" "The generic SSSD service options such as <quote>debug_level</quote> or " "<quote>fd_limit</quote> are accepted by the kcm service. Please refer to " @@ -15204,22 +15649,22 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:234 +#: sssd-kcm.8.xml:233 msgid "socket_path (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:237 +#: sssd-kcm.8.xml:236 msgid "The socket the KCM service will listen on." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:240 +#: sssd-kcm.8.xml:239 msgid "Default: <replaceable>/var/run/.heim_org.h5l.kcm-socket</replaceable>" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:243 +#: sssd-kcm.8.xml:242 msgid "" "<phrase condition=\"have_systemd\"> Note: on platforms where systemd is " "supported, the socket path is overwritten by the one defined in the sssd-" @@ -15227,88 +15672,88 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:252 +#: sssd-kcm.8.xml:251 msgid "max_ccaches (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:255 +#: sssd-kcm.8.xml:254 msgid "How many credential caches does the KCM database allow for all users." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:259 +#: sssd-kcm.8.xml:258 msgid "Default: 0 (unlimited, only the per-UID quota is enforced)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:264 +#: sssd-kcm.8.xml:263 msgid "max_uid_ccaches (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:267 +#: sssd-kcm.8.xml:266 msgid "" "How many credential caches does the KCM database allow per UID. This is " "equivalent to <quote>with how many principals you can kinit</quote>." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:272 +#: sssd-kcm.8.xml:271 msgid "Default: 64" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:277 +#: sssd-kcm.8.xml:276 msgid "max_ccache_size (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:280 +#: sssd-kcm.8.xml:279 msgid "" -"How big can a credential cache be per ccache. Each service ticket accounts " -"into this quota." +"How big a credential cache be per ccache. Each service ticket counts toward " +"this quota." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:284 +#: sssd-kcm.8.xml:283 msgid "Default: 65536" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:289 -msgid "tgt_renewal (bool)" +#: sssd-kcm.8.xml:288 +msgid "tgt_renewal (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:292 +#: sssd-kcm.8.xml:291 msgid "Enables TGT renewals functionality." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:295 +#: sssd-kcm.8.xml:294 msgid "Default: False (Automatic renewals disabled)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:300 +#: sssd-kcm.8.xml:299 msgid "tgt_renewal_inherit (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:303 +#: sssd-kcm.8.xml:302 msgid "Domain to inherit krb5_* options from, for use with TGT renewals." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:307 +#: sssd-kcm.8.xml:306 #, fuzzy #| msgid "Default: 1" msgid "Default: NULL" msgstr "Noklusējuma: 1" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-kcm.8.xml:318 +#: sssd-kcm.8.xml:317 msgid "" "<citerefentry> <refentrytitle>sssd</refentrytitle><manvolnum>8</manvolnum> </" "citerefentry>, <citerefentry> <refentrytitle>sssd.conf</" @@ -16212,8 +16657,8 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap-attributes.5.xml:381 sssd-ldap-attributes.5.xml:395 -msgid "Default: loginDisabled" +#: sssd-ldap-attributes.5.xml:381 +msgid "Default: loginDisabled (rfc2307, rfc2307bis and IPA), not set (AD)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> @@ -16228,6 +16673,12 @@ msgid "" "which date access is granted." msgstr "" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:395 +msgid "" +"Default: loginExpirationTime (rfc2307, rfc2307bis and IPA), not set (AD)" +msgstr "" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:401 msgid "ldap_user_nds_login_allowed_time_map (string)" @@ -16242,7 +16693,8 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:409 -msgid "Default: loginAllowedTimeMap" +msgid "" +"Default: loginAllowedTimeMap (rfc2307, rfc2307bis and IPA), not set (AD)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> @@ -16756,8 +17208,8 @@ msgid "The object class of a host entry in LDAP." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap-attributes.5.xml:900 sssd-ldap-attributes.5.xml:997 -msgid "Default: ipService" +#: sssd-ldap-attributes.5.xml:900 sssd-ldap-attributes.5.xml:1213 +msgid "Default: ipHost" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> @@ -16842,6 +17294,11 @@ msgstr "" msgid "The object class of a service entry in LDAP." msgstr "" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:997 +msgid "Default: ipService" +msgstr "" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1003 msgid "ldap_service_name (string)" @@ -17082,11 +17539,6 @@ msgstr "" msgid "The object class of an iphost entry in LDAP." msgstr "" -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap-attributes.5.xml:1213 -msgid "Default: ipHost" -msgstr "" - #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1219 msgid "ldap_iphost_name (string)" @@ -17322,6 +17774,7 @@ msgstr "KONFIGURĒŠANAS IESPĒJAS" msgid "" "[plugins]\n" " localauth = {\n" +" disable = an2ln\n" " module = sssd:/usr/lib64/sssd/modules/sssd_krb5_localauth_plugin.so\n" " }\n" msgstr "" @@ -17338,6 +17791,28 @@ msgid "" "the local Kerberos configuration the plugin will be enabled automatically." msgstr "" +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_localauth_plugin.8.xml:67 +msgid "" +"This configuration snippet also disables the <command>an2ln</command> module " +"provided by MIT Kerberos if SSSD is configured to use the AD or IPA " +"provider. In those environments <command>sssd_krb5_localauth_plugin</" +"command> can reliably map the system user names to Kerberos principals. A " +"fallback to <command>an2ln</command> might cause issues in environments " +"where users have the privilege to create Kerberos principals on their own " +"which might collide with names of other users used in the system. Other " +"modules provided by MIT Kerberos, e.g. <command>k5login</command> are not " +"affected." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_localauth_plugin.8.xml:79 +msgid "" +"Note: If using <quote>auth_provider = krb5</quote> then " +"<command>sssd_krb5_localauth_plugin</command> is not used, therefore the " +"above text is not applicable." +msgstr "" + #. type: Content of: <variablelist><varlistentry><term> #: include/autofs_attributes.xml:3 msgid "ldap_autofs_map_object_class (string)" @@ -18194,30 +18669,6 @@ msgid "" "failures; corresponds to setting 2 in decimal notation)" msgstr "" -#. type: Content of: <refsect1><title> -#: include/local.xml:2 -msgid "THE LOCAL DOMAIN" -msgstr "" - -#. type: Content of: <refsect1><para> -#: include/local.xml:4 -msgid "" -"In order to function correctly, a domain with <quote>id_provider=local</" -"quote> must be created and the SSSD must be running." -msgstr "" - -#. type: Content of: <refsect1><para> -#: include/local.xml:9 -msgid "" -"The administrator might want to use the SSSD local users instead of " -"traditional UNIX users in cases where the group nesting (see <citerefentry> " -"<refentrytitle>sss_groupadd</refentrytitle> <manvolnum>8</manvolnum> </" -"citerefentry>) is needed. The local users are also useful for testing and " -"development of the SSSD without having to deploy a full remote server. The " -"<command>sss_user*</command> and <command>sss_group*</command> tools use a " -"local LDB storage to store users and groups." -msgstr "" - #. type: Content of: <refsect1><para> #: include/seealso.xml:4 msgid "" @@ -18821,6 +19272,9 @@ msgid "" "feature is available with MIT Kerberos 1.7 and later versions." msgstr "" +#~ msgid "domains" +#~ msgstr "domēni" + #, fuzzy #~| msgid "timeout (integer)" #~ msgid "ldap_enumeration_refresh_timeout" diff --git a/src/man/po/nb_NO.po b/src/man/po/nb_NO.po index 0661379d0a9..9c1eb21f57a 100644 --- a/src/man/po/nb_NO.po +++ b/src/man/po/nb_NO.po @@ -8,16 +8,16 @@ msgstr "" "Project-Id-Version: sssd-docs 2.12.0\n" "Report-Msgid-Bugs-To: sssd-devel@redhat.com\n" "POT-Creation-Date: 2026-01-14 15:00+0000\n" -"PO-Revision-Date: 2026-04-23 16:31+0000\n" +"PO-Revision-Date: 2026-10-05 17:25+0000\n" "Last-Translator: Anonymous <noreply@weblate.org>\n" "Language-Team: Norwegian Bokmål <https://translate.fedoraproject.org/" -"projects/sssd/sssd-manpage-master/nb_NO/>\n" +"projects/sssd/sssd-manpage-master/nb/>\n" "Language: nb_NO\n" "MIME-Version: 1.0\n" "Content-Type: text/plain; charset=UTF-8\n" "Content-Transfer-Encoding: 8bit\n" "Plural-Forms: nplurals=2; plural=n != 1;\n" -"X-Generator: Weblate 5.17\n" +"X-Generator: Weblate 2026.10\n" #. type: Content of: <reference><title> #: sssd.conf.5.xml:8 sssd-ldap.5.xml:5 pam_sss.8.xml:5 pam_sss_gss.8.xml:5 diff --git a/src/man/po/nl.po b/src/man/po/nl.po index 03daa08a860..9eed1162dc9 100644 --- a/src/man/po/nl.po +++ b/src/man/po/nl.po @@ -8,8 +8,8 @@ msgid "" msgstr "" "Project-Id-Version: sssd-docs 2.3.0\n" "Report-Msgid-Bugs-To: sssd-devel@redhat.com\n" -"POT-Creation-Date: 2026-01-14 15:00+0000\n" -"PO-Revision-Date: 2026-04-23 16:28+0000\n" +"POT-Creation-Date: 2026-10-05 16:14+0000\n" +"PO-Revision-Date: 2026-10-05 17:00+0000\n" "Last-Translator: Anonymous <noreply@weblate.org>\n" "Language-Team: Dutch <https://translate.fedoraproject.org/projects/sssd/sssd-" "manpage-master/nl/>\n" @@ -18,10 +18,10 @@ msgstr "" "Content-Type: text/plain; charset=UTF-8\n" "Content-Transfer-Encoding: 8bit\n" "Plural-Forms: nplurals=2; plural=n != 1;\n" -"X-Generator: Weblate 5.17\n" +"X-Generator: Weblate 2026.10\n" #. type: Content of: <reference><title> -#: sssd.conf.5.xml:8 sssd-ldap.5.xml:5 pam_sss.8.xml:5 pam_sss_gss.8.xml:5 +#: sssd.conf.5.xml:10 sssd-ldap.5.xml:5 pam_sss.8.xml:5 pam_sss_gss.8.xml:5 #: sssd_krb5_locator_plugin.8.xml:5 sssd-simple.5.xml:5 sss-certmap.5.xml:5 #: sssd-ipa.5.xml:5 sssd-ad.5.xml:5 sssd-sudo.5.xml:5 sssd-idp.5.xml:5 #: sssd.8.xml:5 sss_obfuscate.8.xml:5 sss_override.8.xml:5 sssd-krb5.5.xml:5 @@ -34,12 +34,12 @@ msgid "SSSD Manual pages" msgstr "SSSD handleiding" #. type: Content of: <reference><refentry><refnamediv><refname> -#: sssd.conf.5.xml:13 sssd.conf.5.xml:19 +#: sssd.conf.5.xml:15 sssd.conf.5.xml:21 msgid "sssd.conf" msgstr "sssd.conf" #. type: Content of: <reference><refentry><refmeta><manvolnum> -#: sssd.conf.5.xml:14 sssd-ldap.5.xml:11 sssd-simple.5.xml:11 +#: sssd.conf.5.xml:16 sssd-ldap.5.xml:11 sssd-simple.5.xml:11 #: sss-certmap.5.xml:11 sssd-ipa.5.xml:11 sssd-ad.5.xml:11 sssd-sudo.5.xml:11 #: sssd-idp.5.xml:11 sssd-krb5.5.xml:11 sssd-ifp.5.xml:11 #: sss_rpcidmapd.5.xml:27 sssd-session-recording.5.xml:11 @@ -48,7 +48,7 @@ msgid "5" msgstr "5" #. type: Content of: <reference><refentry><refmeta><refmiscinfo> -#: sssd.conf.5.xml:15 sssd-ldap.5.xml:12 sssd-simple.5.xml:12 +#: sssd.conf.5.xml:17 sssd-ldap.5.xml:12 sssd-simple.5.xml:12 #: sss-certmap.5.xml:12 sssd-ipa.5.xml:12 sssd-ad.5.xml:12 sssd-sudo.5.xml:12 #: sssd-idp.5.xml:12 sssd-krb5.5.xml:12 sssd-ifp.5.xml:12 #: sss_rpcidmapd.5.xml:28 sssd-session-recording.5.xml:12 sssd-kcm.8.xml:12 @@ -57,17 +57,17 @@ msgid "File Formats and Conventions" msgstr "Bestandsformaten en conventies" #. type: Content of: <reference><refentry><refnamediv><refpurpose> -#: sssd.conf.5.xml:20 +#: sssd.conf.5.xml:22 msgid "the configuration file for SSSD" msgstr "het configuratiebestand voor SSSD" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:24 +#: sssd.conf.5.xml:26 msgid "FILE FORMAT" msgstr "BESTANDSFORMAAT" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd.conf.5.xml:32 +#: sssd.conf.5.xml:34 #, no-wrap msgid "" "<replaceable>[section]</replaceable>\n" @@ -77,7 +77,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:27 +#: sssd.conf.5.xml:29 msgid "" "The file has an ini-style syntax and consists of sections and parameters. A " "section begins with the name of the section in square brackets and continues " @@ -91,23 +91,24 @@ msgstr "" "type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:39 +#: sssd.conf.5.xml:41 msgid "" -"The data types used are string (no quotes needed), integer and bool (with " -"values of <quote>TRUE/FALSE</quote>)." +"The data types used are string (no quotes needed), integer and boolean (with " +"values of <quote>TRUE/FALSE</quote>). Boolean values are case-insensitive; " +"for example, <quote>TRUE</quote>, <quote>True</quote> and <quote>true</" +"quote> are all equivalent and valid; the same applies to <quote>FALSE</" +"quote>." msgstr "" -"De datatypes gebruikt zijn tekst (geen quotes vereisd), numeriek en " -"booleaans (met de waardes <quote>TRUE/FALSE</quote>)." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:44 +#: sssd.conf.5.xml:49 msgid "" "A comment line starts with a hash sign (<quote>#</quote>) or a semicolon " "(<quote>;</quote>). Inline comments are not supported." msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:50 +#: sssd.conf.5.xml:55 msgid "" "All sections can have an optional <replaceable>description</replaceable> " "parameter. Its function is only as a label for the section." @@ -116,7 +117,7 @@ msgstr "" "parameter bevatten. Dit fungeert slechts als label voor de sectie." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:56 +#: sssd.conf.5.xml:61 #, fuzzy #| msgid "" #| "<filename>sssd.conf</filename> must be a regular file, owned by root and " @@ -129,7 +130,7 @@ msgstr "" "moet root zijn en alleen root mag hem lezen en schrijven." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:60 +#: sssd.conf.5.xml:65 #, fuzzy #| msgid "" #| "<filename>sssd.conf</filename> must be a regular file, owned by root and " @@ -142,12 +143,12 @@ msgstr "" "moet root zijn en alleen root mag hem lezen en schrijven." #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:66 +#: sssd.conf.5.xml:71 msgid "CONFIGURATION SNIPPETS FROM INCLUDE DIRECTORY" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:69 +#: sssd.conf.5.xml:74 msgid "" "The configuration file <filename>sssd.conf</filename> will include " "configuration snippets using the include directory <filename>conf.d</" @@ -155,7 +156,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:75 +#: sssd.conf.5.xml:80 msgid "" "Any file placed in <filename>conf.d</filename> that ends in " "<quote><filename>.conf</filename></quote> and does not begin with a dot " @@ -164,7 +165,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:83 +#: sssd.conf.5.xml:88 msgid "" "The configuration snippets from <filename>conf.d</filename> have higher " "priority than <filename>sssd.conf</filename> and will override " @@ -177,39 +178,88 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:97 +#: sssd.conf.5.xml:102 msgid "" "The snippet files require the same owner and permissions as " "<filename>sssd.conf</filename>." msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:103 +#: sssd.conf.5.xml:108 +msgid "VENDOR PROVIDED CONFIGURATION" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:111 +msgid "" +"The vendor provided configuration file is installed in " +"<filename>&sssd_vendor_dir;/sssd.conf</filename>, but this file must not be " +"directly edited. It can be completely masked by creating the system specific " +"configuration file <filename>&sssd_conf_dir;/sssd.conf</filename>, or partly " +"overriden by creating config snippets in <filename>&sssd_conf_dir;/conf.d</" +"filename> directory." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><title> +#: sssd.conf.5.xml:120 +msgid "CONFIGURATION FILE HIERARCHY" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:122 +msgid "" +"When sssd reads the configuration it first tries to open the system specific " +"configuration file in <filename>&sssd_conf_dir;/sssd.conf</filename>. If it " +"exists, it is loaded and snippets from <filename>&sssd_conf_dir;/conf.d</" +"filename> are applied. The vendor provided configuration file " +"<filename>&sssd_vendor_dir;/sssd.conf</filename> is completely ignored in " +"this case." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:131 +msgid "" +"If the system specific configuration file <filename>&sssd_conf_dir;/" +"sssd.conf</filename> does not exist, then the vendor configuration file " +"<filename>&sssd_vendor_dir;/sssd.conf</filename> is loaded and snippets from " +"<filename>&sssd_conf_dir;/conf.d</filename> are applied." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd.conf.5.xml:141 msgid "GENERAL OPTIONS" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:105 +#: sssd.conf.5.xml:143 msgid "Following options are usable in more than one configuration sections." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:109 +#: sssd.conf.5.xml:147 msgid "Options usable in all sections" msgstr "" +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:149 +msgid "" +"Note: Below options are ignored in <quote>[session_recording]</quote> " +"section, see <quote>Session recording configuration options</quote> section " +"for more details." +msgstr "" + #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:113 +#: sssd.conf.5.xml:156 msgid "debug_level (integer)" msgstr "debug_level (numeriek)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:117 +#: sssd.conf.5.xml:160 msgid "debug (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:120 +#: sssd.conf.5.xml:163 msgid "" "SSSD 1.14 and later also includes the <replaceable>debug</replaceable> alias " "for <replaceable>debug_level</replaceable> as a convenience feature. If both " @@ -218,63 +268,67 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:130 -msgid "debug_timestamps (bool)" +#: sssd.conf.5.xml:173 +#, fuzzy +#| msgid "debug_timestamps (bool)" +msgid "debug_timestamps (boolean)" msgstr "debug_timestamps (bool)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:133 +#: sssd.conf.5.xml:176 msgid "" "Add a timestamp to the debug messages. If journald is enabled for SSSD " "debug logging this option is ignored." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:138 sssd.conf.5.xml:175 sssd.conf.5.xml:337 -#: sssd.conf.5.xml:644 sssd.conf.5.xml:668 sssd.conf.5.xml:875 -#: sssd.conf.5.xml:979 sssd.conf.5.xml:2113 sssd-ldap.5.xml:979 -#: sssd-ldap.5.xml:1134 sssd-ldap.5.xml:1237 sssd-ldap.5.xml:1306 -#: sssd-ldap.5.xml:1714 sssd-ldap.5.xml:1848 sssd-ldap.5.xml:1913 -#: sssd-ipa.5.xml:346 sssd-ad.5.xml:252 sssd-ad.5.xml:367 sssd-ad.5.xml:1180 -#: sssd-ad.5.xml:1382 sssd-krb5.5.xml:358 +#: sssd.conf.5.xml:181 sssd.conf.5.xml:218 sssd.conf.5.xml:380 +#: sssd.conf.5.xml:687 sssd.conf.5.xml:711 sssd.conf.5.xml:827 +#: sssd.conf.5.xml:932 sssd.conf.5.xml:2149 sssd.conf.5.xml:4730 +#: sssd-ldap.5.xml:979 sssd-ldap.5.xml:1134 sssd-ldap.5.xml:1237 +#: sssd-ldap.5.xml:1306 sssd-ldap.5.xml:1714 sssd-ldap.5.xml:1848 +#: sssd-ldap.5.xml:1913 sssd-ipa.5.xml:341 sssd-ad.5.xml:252 sssd-ad.5.xml:367 +#: sssd-ad.5.xml:1180 sssd-ad.5.xml:1375 sssd-krb5.5.xml:358 msgid "Default: true" msgstr "Standaard: true" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:143 -msgid "debug_microseconds (bool)" -msgstr "" +#: sssd.conf.5.xml:186 +#, fuzzy +#| msgid "debug_timestamps (bool)" +msgid "debug_microseconds (boolean)" +msgstr "debug_timestamps (bool)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:146 +#: sssd.conf.5.xml:189 msgid "" "Add microseconds to the timestamp in debug messages. If journald is enabled " "for SSSD debug logging this option is ignored." msgstr "" #. type: Content of: <variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:151 sssd.conf.5.xml:2040 sssd.conf.5.xml:4158 +#: sssd.conf.5.xml:194 sssd.conf.5.xml:2072 sssd.conf.5.xml:4363 #: sssd-ldap.5.xml:363 sssd-ldap.5.xml:998 sssd-ldap.5.xml:1209 -#: sssd-ldap.5.xml:1663 sssd-ldap.5.xml:1937 sssd-ipa.5.xml:146 -#: sssd-ipa.5.xml:706 sssd-ad.5.xml:1135 sssd-krb5.5.xml:268 +#: sssd-ldap.5.xml:1663 sssd-ldap.5.xml:1937 sssd-ipa.5.xml:141 +#: sssd-ipa.5.xml:701 sssd-ad.5.xml:1140 sssd-idp.5.xml:287 sssd-krb5.5.xml:268 #: sssd-krb5.5.xml:330 sssd-krb5.5.xml:432 include/krb5_options.xml:163 msgid "Default: false" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:156 +#: sssd.conf.5.xml:199 #, fuzzy #| msgid "debug_timestamps (bool)" -msgid "debug_backtrace_enabled (bool)" +msgid "debug_backtrace_enabled (boolean)" msgstr "debug_timestamps (bool)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:159 +#: sssd.conf.5.xml:202 msgid "Enable debug backtrace." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:162 +#: sssd.conf.5.xml:205 msgid "" "In case SSSD is run with debug_level less than 9, everything is logged to a " "ring buffer in memory and flushed to a log file on any error up to and " @@ -284,14 +338,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:171 +#: sssd.conf.5.xml:214 msgid "" "Feature is only supported for `logger == files` (i.e. setting doesn't have " "effect for other logger types)." msgstr "" #. type: Content of: outside any tag (error?) -#: sssd.conf.5.xml:111 sssd.conf.5.xml:186 sssd-ldap.5.xml:1754 +#: sssd.conf.5.xml:154 sssd.conf.5.xml:229 sssd-ldap.5.xml:1754 #: sssd-ldap.5.xml:1960 sss-certmap.5.xml:645 sssd-systemtap.5.xml:82 #: sssd-systemtap.5.xml:143 sssd-systemtap.5.xml:236 sssd-systemtap.5.xml:274 #: sssd-systemtap.5.xml:330 sssd-ldap-attributes.5.xml:40 @@ -304,17 +358,17 @@ msgid "<placeholder type=\"variablelist\" id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:184 +#: sssd.conf.5.xml:227 msgid "Options usable in SERVICE and DOMAIN sections" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:188 +#: sssd.conf.5.xml:231 msgid "timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:191 +#: sssd.conf.5.xml:234 msgid "" "Timeout in seconds between heartbeats for this service. This is used to " "ensure that the process is alive and capable of answering requests. Note " @@ -322,34 +376,36 @@ msgid "" msgstr "" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:198 sssd.conf.5.xml:1199 sssd.conf.5.xml:1673 -#: sssd.conf.5.xml:4174 sssd-ldap.5.xml:825 sssd-idp.5.xml:192 +#: sssd.conf.5.xml:241 sssd.conf.5.xml:1155 sssd.conf.5.xml:1665 +#: sssd.conf.5.xml:4379 sssd-ldap.5.xml:825 sssd-idp.5.xml:271 #: include/ldap_id_mapping.xml:270 msgid "Default: 10" msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:208 +#: sssd.conf.5.xml:251 msgid "SPECIAL SECTIONS" msgstr "SPECIALE SECTIES" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:211 +#: sssd.conf.5.xml:254 msgid "The [sssd] section" msgstr "De [sssd] sectie" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><title> -#: sssd.conf.5.xml:220 +#: sssd.conf.5.xml:263 msgid "Section parameters" msgstr "Sectie parameters" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:222 -msgid "services" -msgstr "diensten" +#: sssd.conf.5.xml:265 +#, fuzzy +#| msgid "re_expression (string)" +msgid "services (string)" +msgstr "re_expression (tekst)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:225 +#: sssd.conf.5.xml:268 msgid "" "Comma separated list of services that are started when sssd itself starts. " "<phrase condition=\"have_systemd\"> The services' list is optional on " @@ -358,7 +414,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:234 +#: sssd.conf.5.xml:277 msgid "" "Supported services: nss, pam, ifp <phrase condition=\"with_sudo\">, sudo</" "phrase> <phrase condition=\"with_autofs\">, autofs</phrase> <phrase " @@ -367,20 +423,20 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:241 +#: sssd.conf.5.xml:284 msgid "" "<phrase condition=\"have_systemd\"> By default, all services are disabled " "and the administrator must enable the ones allowed to be used by executing: " "\"systemctl enable sssd-@service@.socket\". </phrase>" msgstr "" -#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:250 -msgid "domains" -msgstr "domeinen" +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sssd.conf.5.xml:293 sssd.conf.5.xml:4562 +msgid "domains (string)" +msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:253 +#: sssd.conf.5.xml:296 msgid "" "A domain is a database containing user information. SSSD can use more " "domains at the same time, but at least one must be configured or SSSD won't " @@ -391,19 +447,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:266 sssd.conf.5.xml:3467 +#: sssd.conf.5.xml:309 sssd.conf.5.xml:3598 msgid "re_expression (string)" msgstr "re_expression (tekst)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:269 +#: sssd.conf.5.xml:312 msgid "" "Default regular expression that describes how to parse the string containing " "user name and domain into these components." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:274 +#: sssd.conf.5.xml:317 msgid "" "Each domain can have an individual regular expression configured. For some " "ID providers there are also default regular expressions. See DOMAIN SECTIONS " @@ -411,12 +467,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:283 sssd.conf.5.xml:3524 +#: sssd.conf.5.xml:326 sssd.conf.5.xml:3655 msgid "full_name_format (string)" msgstr "full_name_format (tekst)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:286 sssd.conf.5.xml:3527 +#: sssd.conf.5.xml:329 sssd.conf.5.xml:3658 msgid "" "A <citerefentry> <refentrytitle>printf</refentrytitle> <manvolnum>3</" "manvolnum> </citerefentry>-compatible format that describes how to compose a " @@ -424,70 +480,70 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:297 sssd.conf.5.xml:3538 +#: sssd.conf.5.xml:340 sssd.conf.5.xml:3669 msgid "%1$s" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:298 sssd.conf.5.xml:3539 +#: sssd.conf.5.xml:341 sssd.conf.5.xml:3670 msgid "user name" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:301 sssd.conf.5.xml:3542 +#: sssd.conf.5.xml:344 sssd.conf.5.xml:3673 msgid "%2$s" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:304 sssd.conf.5.xml:3545 +#: sssd.conf.5.xml:347 sssd.conf.5.xml:3676 msgid "domain name as specified in the SSSD config file." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:310 sssd.conf.5.xml:3551 +#: sssd.conf.5.xml:353 sssd.conf.5.xml:3682 msgid "%3$s" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:313 sssd.conf.5.xml:3554 +#: sssd.conf.5.xml:356 sssd.conf.5.xml:3685 msgid "" "domain flat name. Mostly usable for Active Directory domains, both directly " "configured or discovered via IPA trusts." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:294 sssd.conf.5.xml:3535 +#: sssd.conf.5.xml:337 sssd.conf.5.xml:3666 msgid "" "The following expansions are supported: <placeholder type=\"variablelist\" " "id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:323 +#: sssd.conf.5.xml:366 msgid "" "Each domain can have an individual format string configured. See DOMAIN " "SECTIONS for more info on this option." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:329 +#: sssd.conf.5.xml:372 msgid "monitor_resolv_conf (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:332 +#: sssd.conf.5.xml:375 msgid "" "Controls if SSSD should monitor the state of resolv.conf to identify when it " "needs to update its internal DNS resolver." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:342 +#: sssd.conf.5.xml:385 msgid "try_inotify (boolean)" msgstr "try_inotify (bool)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:345 +#: sssd.conf.5.xml:388 msgid "" "By default, SSSD will attempt to use inotify to monitor configuration files " "changes and will fall back to polling every five seconds if inotify cannot " @@ -495,7 +551,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:351 +#: sssd.conf.5.xml:394 msgid "" "There are some limited situations where it is preferred that we should skip " "even trying to use inotify. In these rare cases, this option should be set " @@ -506,7 +562,7 @@ msgstr "" "gezet worden" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:357 +#: sssd.conf.5.xml:400 msgid "" "Default: true on platforms where inotify is supported. False on other " "platforms." @@ -515,7 +571,7 @@ msgstr "" "systemen." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:361 +#: sssd.conf.5.xml:404 msgid "" "Note: this option will have no effect on platforms where inotify is " "unavailable. On these platforms, polling will always be used." @@ -525,12 +581,12 @@ msgstr "" "resolv.conf." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:368 +#: sssd.conf.5.xml:411 msgid "krb5_rcache_dir (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:371 +#: sssd.conf.5.xml:414 msgid "" "Directory on the filesystem where SSSD should store Kerberos replay cache " "files." @@ -539,33 +595,33 @@ msgstr "" "opslaan." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:375 +#: sssd.conf.5.xml:418 msgid "" "This option accepts a special value __LIBKRB5_DEFAULTS__ that will instruct " "SSSD to let libkrb5 decide the appropriate location for the replay cache." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:381 +#: sssd.conf.5.xml:424 msgid "" "Default: Distribution-specific and specified at build-time. " "(__LIBKRB5_DEFAULTS__ if not configured)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:388 +#: sssd.conf.5.xml:431 msgid "default_domain_suffix (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:391 +#: sssd.conf.5.xml:434 msgid "" "Please note that this option is deprecated and domain_resolution_order " "should be used." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:395 +#: sssd.conf.5.xml:438 msgid "" "This string will be used as a default domain name for all names without a " "domain name component. The main use case is environments where the primary " @@ -575,7 +631,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:405 +#: sssd.conf.5.xml:448 msgid "" "Please note that if this option is set all users from the primary domain " "have to use their fully qualified name, e.g. user@domain.name, to log in. " @@ -585,21 +641,21 @@ msgid "" msgstr "" #. type: Content of: <variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:414 sssd-ldap.5.xml:937 sssd-ldap.5.xml:949 -#: sssd-ldap.5.xml:1042 sssd-ad.5.xml:921 sssd-ad.5.xml:996 sssd-krb5.5.xml:468 -#: sssd-ldap-attributes.5.xml:470 sssd-ldap-attributes.5.xml:978 -#: include/ldap_id_mapping.xml:211 include/ldap_id_mapping.xml:222 -#: include/krb5_options.xml:148 +#: sssd.conf.5.xml:457 sssd.conf.5.xml:2006 sssd-ldap.5.xml:937 +#: sssd-ldap.5.xml:949 sssd-ldap.5.xml:1042 sssd-ad.5.xml:926 +#: sssd-ad.5.xml:1001 sssd-krb5.5.xml:468 sssd-ldap-attributes.5.xml:470 +#: sssd-ldap-attributes.5.xml:978 include/ldap_id_mapping.xml:211 +#: include/ldap_id_mapping.xml:222 include/krb5_options.xml:148 msgid "Default: not set" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:419 +#: sssd.conf.5.xml:462 msgid "override_space (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:422 +#: sssd.conf.5.xml:465 msgid "" "This parameter will replace spaces (space bar) with the given character for " "user and group names. e.g. (_). User name "john doe" will be " @@ -609,7 +665,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:431 +#: sssd.conf.5.xml:474 msgid "" "Please note it is a configuration error to use a replacement character that " "might be used in user or group names. If a name contains the replacement " @@ -618,22 +674,22 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:439 +#: sssd.conf.5.xml:482 msgid "Default: not set (spaces will not be replaced)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:444 +#: sssd.conf.5.xml:487 msgid "certificate_verification (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:452 +#: sssd.conf.5.xml:495 msgid "no_ocsp" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:454 +#: sssd.conf.5.xml:497 msgid "" "Disables Online Certificate Status Protocol (OCSP) checks. This might be " "needed if the OCSP servers defined in the certificate are not reachable from " @@ -641,12 +697,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:462 +#: sssd.conf.5.xml:505 msgid "soft_ocsp" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:464 +#: sssd.conf.5.xml:507 msgid "" "If a connection cannot be established to an OCSP responder the OCSP check is " "skipped. This option should be used to allow authentication when the system " @@ -654,61 +710,61 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:474 +#: sssd.conf.5.xml:517 msgid "ocsp_dgst" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:476 +#: sssd.conf.5.xml:519 msgid "" "Digest (hash) function used to create the certificate ID for the OCSP " "request. Allowed values are:" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:480 +#: sssd.conf.5.xml:523 msgid "sha1" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:481 +#: sssd.conf.5.xml:524 msgid "sha256" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:482 +#: sssd.conf.5.xml:525 msgid "sha384" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:483 +#: sssd.conf.5.xml:526 msgid "sha512" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:486 +#: sssd.conf.5.xml:529 msgid "Default: sha1 (to allow compatibility with RFC5019-compliant responder)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:492 +#: sssd.conf.5.xml:535 msgid "no_verification" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:494 +#: sssd.conf.5.xml:537 msgid "" "Disables verification completely. This option should only be used for " "testing." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:500 +#: sssd.conf.5.xml:543 msgid "partial_chain" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:502 +#: sssd.conf.5.xml:545 msgid "" "Allow verification to succeed even if a <replaceable>complete</replaceable> " "chain cannot be built to a self-signed trust-anchor, provided it is possible " @@ -716,12 +772,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:511 +#: sssd.conf.5.xml:554 msgid "ocsp_default_responder=URL" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:513 +#: sssd.conf.5.xml:556 msgid "" "Sets the OCSP default responder which should be used instead of the one " "mentioned in the certificate. URL must be replaced with the URL of the OCSP " @@ -729,24 +785,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:523 +#: sssd.conf.5.xml:566 msgid "ocsp_default_responder_signing_cert=NAME" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:525 +#: sssd.conf.5.xml:568 msgid "" "This option is currently ignored. All needed certificates must be available " "in the PEM file given by pam_cert_db_path." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:533 +#: sssd.conf.5.xml:576 msgid "crl_file=/PATH/TO/CRL/FILE" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:535 +#: sssd.conf.5.xml:578 msgid "" "Use the Certificate Revocation List (CRL) from the given file during the " "verification of the certificate. The CRL must be given in PEM format, see " @@ -755,12 +811,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:548 +#: sssd.conf.5.xml:591 msgid "soft_crl" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:551 +#: sssd.conf.5.xml:594 msgid "" "If a Certificate Revocation List (CRL) is expired ignore the expiration " "time of the CRL and check the related certificates with the expired CRL. " @@ -769,7 +825,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:447 +#: sssd.conf.5.xml:490 msgid "" "With this parameter the certificate verification can be tuned with a comma " "separated list of options. Supported options are: <placeholder " @@ -777,46 +833,48 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:564 +#: sssd.conf.5.xml:607 msgid "Unknown options are reported but ignored." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:567 +#: sssd.conf.5.xml:610 msgid "Default: not set, i.e. do not restrict certificate verification" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:573 +#: sssd.conf.5.xml:616 msgid "disable_netlink (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:576 +#: sssd.conf.5.xml:619 msgid "" "SSSD hooks into the netlink interface to monitor changes to routes, " "addresses, links and trigger certain actions." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:581 +#: sssd.conf.5.xml:624 msgid "" "The SSSD state changes caused by netlink events may be undesirable and can " "be disabled by setting this option to 'true'" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:586 +#: sssd.conf.5.xml:629 msgid "Default: false (netlink changes are detected)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:591 -msgid "domain_resolution_order" -msgstr "" +#: sssd.conf.5.xml:634 +#, fuzzy +#| msgid "re_expression (string)" +msgid "domain_resolution_order (string)" +msgstr "re_expression (tekst)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:594 +#: sssd.conf.5.xml:637 msgid "" "Comma separated list of domains and subdomains representing the lookup order " "that will be followed. The list doesn't have to include all possible " @@ -827,7 +885,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:606 +#: sssd.conf.5.xml:649 msgid "" "Please, note that when this option is set the output format of all commands " "is always fully-qualified even when using short names for input. In case " @@ -843,19 +901,20 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:630 sssd.conf.5.xml:1697 sssd.conf.5.xml:4224 -#: sssd-ad.5.xml:187 sssd-ad.5.xml:328 sssd-ad.5.xml:342 sssd-idp.5.xml:108 -#: sssd-idp.5.xml:132 sssd-idp.5.xml:145 sssd-idp.5.xml:159 sssd-idp.5.xml:180 +#: sssd.conf.5.xml:673 sssd.conf.5.xml:1026 sssd.conf.5.xml:1689 +#: sssd.conf.5.xml:4429 sssd-ad.5.xml:187 sssd-ad.5.xml:328 sssd-ad.5.xml:342 +#: sssd-idp.5.xml:112 sssd-idp.5.xml:136 sssd-idp.5.xml:149 sssd-idp.5.xml:167 +#: sssd-idp.5.xml:188 msgid "Default: Not set" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:635 +#: sssd.conf.5.xml:678 msgid "implicit_pac_responder (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:638 +#: sssd.conf.5.xml:681 msgid "" "The PAC responder is enabled automatically for the IPA and AD provider to " "evaluate and check the PAC. If it has to be disabled set this option to " @@ -863,12 +922,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:649 +#: sssd.conf.5.xml:692 msgid "core_dumpable (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:652 +#: sssd.conf.5.xml:695 msgid "" "This option can be used for general system hardening: setting it to 'false' " "forbids core dumps for all SSSD processes to avoid leaking plain text " @@ -877,7 +936,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:660 +#: sssd.conf.5.xml:703 msgid "" "Take a note that this setting has no effect for 'ldap_child', 'krb5_child' " "and 'sssd_pam' as those privileged binaries can have a copy of a host keytab " @@ -886,28 +945,28 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:673 +#: sssd.conf.5.xml:716 #, fuzzy #| msgid "re_expression (string)" msgid "passkey_verification (string)" msgstr "re_expression (tekst)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:681 +#: sssd.conf.5.xml:724 #, fuzzy #| msgid "re_expression (string)" msgid "user_verification (boolean)" msgstr "re_expression (tekst)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:683 +#: sssd.conf.5.xml:726 msgid "" "Enable or disable the user verification (i.e. PIN, fingerprint) during " "authentication. If enabled, the PIN will always be requested." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:689 +#: sssd.conf.5.xml:732 msgid "" "The default is that the key settings decide what to do. In the IPA or " "kerberos pre-authentication case, this value will be overwritten by the " @@ -915,7 +974,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:676 +#: sssd.conf.5.xml:719 msgid "" "With this parameter the passkey verification can be tuned with a comma " "separated list of options. Supported options are: <placeholder " @@ -923,7 +982,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:213 +#: sssd.conf.5.xml:256 msgid "" "Individual pieces of SSSD functionality are provided by special SSSD " "services that are started and stopped together with SSSD. The services are " @@ -934,12 +993,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:708 +#: sssd.conf.5.xml:751 msgid "SERVICES SECTIONS" msgstr "SERVICES SECTIE" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:710 +#: sssd.conf.5.xml:753 msgid "" "Settings that can be used to configure different services are described in " "this section. They should reside in the [<replaceable>$NAME</replaceable>] " @@ -948,42 +1007,45 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:717 +#: sssd.conf.5.xml:760 msgid "General service configuration options" msgstr "Algemene service configuratie-opties" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:719 +#: sssd.conf.5.xml:762 msgid "These options can be used to configure any service." msgstr "Deze opties kunnen gebruikt worden om services te configureren." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:723 -msgid "fd_limit" -msgstr "" +#: sssd.conf.5.xml:766 +#, fuzzy +#| msgid "debug_level (integer)" +msgid "fd_limit (integer)" +msgstr "debug_level (numeriek)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:726 +#: sssd.conf.5.xml:769 msgid "" "This option specifies the maximum number of file descriptors that may be " -"opened at one time by this SSSD process. On systems where SSSD is granted " -"the CAP_SYS_RESOURCE capability, this will be an absolute setting. On " -"systems without this capability, the resulting value will be the lower value " -"of this or the limits.conf \"hard\" limit." +"opened at one time by this SSSD process. Note this value will be capped by " +"the init system at the startup of SSSD, see e.g. man systemd.exec for " +"details." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:735 +#: sssd.conf.5.xml:776 msgid "Default: 8192 (or limits.conf \"hard\" limit)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:740 -msgid "client_idle_timeout" -msgstr "" +#: sssd.conf.5.xml:781 +#, fuzzy +#| msgid "entry_negative_timeout (integer)" +msgid "client_idle_timeout (integer)" +msgstr "entry_negative_timeout (numeriek)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:743 +#: sssd.conf.5.xml:784 msgid "" "This option specifies the number of seconds that a client of an SSSD process " "can hold onto a file descriptor without communicating on it. This value is " @@ -993,148 +1055,21 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:752 +#: sssd.conf.5.xml:793 #, fuzzy #| msgid "Default: 3" msgid "Default: 60, KCM: 300" msgstr "Standaard: 3" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:757 -msgid "offline_timeout (integer)" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:760 -msgid "" -"When SSSD switches to offline mode the amount of time before it tries to go " -"back online will increase based upon the time spent disconnected. By " -"default SSSD uses incremental behaviour to calculate delay in between " -"retries. So, the wait time for a given retry will be longer than the wait " -"time for the previous ones. After each unsuccessful attempt to go online, " -"the new interval is recalculated by the following:" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:771 sssd.conf.5.xml:827 -msgid "" -"new_delay = Minimum(old_delay * 2, offline_timeout_max) + " -"random[0...offline_timeout_random_offset]" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:774 -msgid "" -"The offline_timeout default value is 60. The offline_timeout_max default " -"value is 3600. The offline_timeout_random_offset default value is 30. The " -"end result is amount of seconds before next retry." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:780 -msgid "" -"Note that the maximum length of each interval is defined by " -"offline_timeout_max (apart of random part)." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:784 sssd.conf.5.xml:1110 sssd.conf.5.xml:1490 -#: sssd.conf.5.xml:1791 sssd-ldap.5.xml:550 -msgid "Default: 60" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:789 -#, fuzzy -#| msgid "enum_cache_timeout (integer)" -msgid "offline_timeout_max (integer)" -msgstr "enum_cache_timeout (numeriek)" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:792 -msgid "" -"Controls by how much the time between attempts to go online can be " -"incremented following unsuccessful attempts to go online." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:797 -msgid "A value of 0 disables the incrementing behaviour." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:800 -msgid "" -"The value of this parameter should be set in correlation to offline_timeout " -"parameter value." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:804 -msgid "" -"With offline_timeout set to 60 (default value) there is no point in setting " -"offlinet_timeout_max to less than 120 as it will saturate instantly. General " -"rule here should be to set offline_timeout_max to at least 4 times " -"offline_timeout." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:810 -msgid "" -"Although a value between 0 and offline_timeout may be specified, it has the " -"effect of overriding the offline_timeout value so is of little use." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:815 -#, fuzzy -#| msgid "Default: 3" -msgid "Default: 3600" -msgstr "Standaard: 3" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:820 -msgid "offline_timeout_random_offset (integer)" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:823 -msgid "" -"When SSSD is in offline mode it keeps probing backend servers in specified " -"time intervals:" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:830 -msgid "" -"This parameter controls the value of the random offset used for the above " -"equation. Final random_offset value will be random number in range:" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:835 -msgid "[0 - offline_timeout_random_offset]" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:838 -msgid "A value of 0 disables the random offset addition." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:841 +#: sssd.conf.5.xml:798 #, fuzzy -#| msgid "Default: 3" -msgid "Default: 30" -msgstr "Standaard: 3" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:846 -msgid "responder_idle_timeout" -msgstr "" +#| msgid "reconnection_retries (integer)" +msgid "responder_idle_timeout (integer)" +msgstr "reconnection_retries (numeriek)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:849 +#: sssd.conf.5.xml:801 msgid "" "This option specifies the number of seconds that an SSSD responder process " "can be up without being used. This value is limited in order to avoid " @@ -1146,43 +1081,50 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:863 sssd.conf.5.xml:1123 sssd.conf.5.xml:2248 +#: sssd.conf.5.xml:815 sssd.conf.5.xml:1079 sssd.conf.5.xml:2285 #: sssd-ldap.5.xml:377 msgid "Default: 300" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:868 -msgid "cache_first" -msgstr "" +#: sssd.conf.5.xml:820 +#, fuzzy +#| msgid "re_expression (string)" +msgid "cache_first (boolean)" +msgstr "re_expression (tekst)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:871 +#: sssd.conf.5.xml:823 msgid "" "This option specifies whether the responder should query all caches before " "querying the Data Providers." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:883 +#: sssd.conf.5.xml:835 msgid "NSS configuration options" msgstr "NSS configuratie-opties" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:885 +#: sssd.conf.5.xml:837 +#, fuzzy +#| msgid "" +#| "These options can be used to configure the Name Service Switch (NSS) " +#| "service." msgid "" -"These options can be used to configure the Name Service Switch (NSS) service." +"These options can be used to configure the Name Service Switch (NSS) service " +"and should be specified under the <quote>[nss]</quote> section." msgstr "" "Deze opties kunnen worden gebruikt om de Name Serice Switch (NSS) service te " "configurere." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:890 +#: sssd.conf.5.xml:843 msgid "enum_cache_timeout (integer)" msgstr "enum_cache_timeout (numeriek)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:893 +#: sssd.conf.5.xml:846 msgid "" "How many seconds should nss_sss cache enumerations (requests for info about " "all users)" @@ -1191,17 +1133,17 @@ msgstr "" "over alle gebruikers)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:897 +#: sssd.conf.5.xml:850 msgid "Default: 120" msgstr "Standaard: 120" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:902 +#: sssd.conf.5.xml:855 msgid "entry_cache_nowait_percentage (integer)" msgstr "entry_cache_nowait_percentage (numeriek)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:905 +#: sssd.conf.5.xml:858 msgid "" "The entry cache can be set to automatically update entries in the background " "if they are requested beyond a percentage of the entry_cache_timeout value " @@ -1209,7 +1151,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:911 +#: sssd.conf.5.xml:864 msgid "" "For example, if the domain's entry_cache_timeout is set to 30s and " "entry_cache_nowait_percentage is set to 50 (percent), entries that come in " @@ -1219,7 +1161,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:921 +#: sssd.conf.5.xml:874 msgid "" "Valid values for this option are 0-99 and represent a percentage of the " "entry_cache_timeout for each domain. For performance reasons, this " @@ -1228,17 +1170,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:929 sssd.conf.5.xml:2061 +#: sssd.conf.5.xml:882 sssd.conf.5.xml:2093 msgid "Default: 50" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:934 +#: sssd.conf.5.xml:887 msgid "entry_negative_timeout (integer)" msgstr "entry_negative_timeout (numeriek)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:937 +#: sssd.conf.5.xml:890 msgid "" "Specifies for how many seconds nss_sss should cache negative cache hits " "(that is, queries for invalid database entries, like nonexistent ones) " @@ -1246,17 +1188,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:943 sssd.conf.5.xml:1685 sssd.conf.5.xml:2085 +#: sssd.conf.5.xml:896 sssd.conf.5.xml:1677 sssd.conf.5.xml:2119 msgid "Default: 15" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:948 +#: sssd.conf.5.xml:901 msgid "filter_users, filter_groups (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:951 +#: sssd.conf.5.xml:904 msgid "" "Exclude certain users or groups from being fetched from the sss NSS " "database. This is particularly useful for system accounts. This option can " @@ -1265,7 +1207,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:959 +#: sssd.conf.5.xml:912 msgid "" "NOTE: The filter_groups option doesn't affect inheritance of nested group " "members, since filtering happens after they are propagated for returning via " @@ -1274,41 +1216,43 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:967 +#: sssd.conf.5.xml:920 msgid "Default: root" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:972 -msgid "filter_users_in_groups (bool)" -msgstr "" +#: sssd.conf.5.xml:925 +#, fuzzy +#| msgid "try_inotify (boolean)" +msgid "filter_users_in_groups (boolean)" +msgstr "try_inotify (bool)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:975 +#: sssd.conf.5.xml:928 msgid "" -"If you want filtered user still be group members set this option to false." +"If you want filtered users to remain group members set this option to false" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:986 +#: sssd.conf.5.xml:939 msgid "fallback_homedir (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:989 +#: sssd.conf.5.xml:942 msgid "" "Set a default template for a user's home directory if one is not specified " "explicitly by the domain's data provider." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:994 +#: sssd.conf.5.xml:947 msgid "" "The available values for this option are the same as for override_homedir." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1000 +#: sssd.conf.5.xml:953 #, no-wrap msgid "" "fallback_homedir = /home/%u\n" @@ -1316,23 +1260,23 @@ msgid "" msgstr "" #. type: Content of: <varlistentry><listitem><para> -#: sssd.conf.5.xml:998 sssd.conf.5.xml:1557 sssd.conf.5.xml:1576 -#: sssd.conf.5.xml:1653 sssd-krb5.5.xml:451 include/override_homedir.xml:78 +#: sssd.conf.5.xml:951 sssd.conf.5.xml:1524 sssd.conf.5.xml:1543 +#: sssd.conf.5.xml:1645 sssd-krb5.5.xml:451 include/override_homedir.xml:78 msgid "example: <placeholder type=\"programlisting\" id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1004 +#: sssd.conf.5.xml:957 msgid "Default: not set (no substitution for unset home directories)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1010 +#: sssd.conf.5.xml:963 msgid "override_shell (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1013 +#: sssd.conf.5.xml:966 msgid "" "Override the login shell for all users. This option supersedes any other " "shell options if it takes effect and can be set either in the [nss] section " @@ -1340,47 +1284,47 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1019 +#: sssd.conf.5.xml:972 msgid "Default: not set (SSSD will use the value retrieved from LDAP)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1025 +#: sssd.conf.5.xml:978 msgid "allowed_shells (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1028 +#: sssd.conf.5.xml:981 msgid "" "Restrict user shell to one of the listed values. The order of evaluation is:" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1031 +#: sssd.conf.5.xml:984 msgid "1. If the shell is present in <quote>/etc/shells</quote>, it is used." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1035 +#: sssd.conf.5.xml:988 msgid "" "2. If the shell is in the allowed_shells list but not in <quote>/etc/shells</" "quote>, use the value of the shell_fallback parameter." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1040 +#: sssd.conf.5.xml:993 msgid "" "3. If the shell is not in the allowed_shells list and not in <quote>/etc/" "shells</quote>, a nologin shell is used." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1045 +#: sssd.conf.5.xml:998 msgid "The wildcard (*) can be used to allow any shell." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1048 +#: sssd.conf.5.xml:1001 msgid "" "The (*) is useful if you want to use shell_fallback in case that user's " "shell is not in <quote>/etc/shells</quote> and maintaining list of all " @@ -1388,117 +1332,125 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1055 +#: sssd.conf.5.xml:1008 msgid "An empty string for shell is passed as-is to libc." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1058 +#: sssd.conf.5.xml:1011 msgid "" "The <quote>/etc/shells</quote> is only read on SSSD start up, which means " "that a restart of the SSSD is required in case a new shell is installed." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1062 +#: sssd.conf.5.xml:1015 msgid "Default: Not set. The user shell is automatically used." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1067 +#: sssd.conf.5.xml:1020 msgid "vetoed_shells (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1070 +#: sssd.conf.5.xml:1023 msgid "Replace any instance of these shells with the shell_fallback" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1075 +#: sssd.conf.5.xml:1031 msgid "shell_fallback (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1078 +#: sssd.conf.5.xml:1034 msgid "" "The default shell to use if an allowed shell is not installed on the machine." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1082 +#: sssd.conf.5.xml:1038 msgid "Default: /bin/sh" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1087 -msgid "default_shell" -msgstr "" +#: sssd.conf.5.xml:1043 +#, fuzzy +#| msgid "re_expression (string)" +msgid "default_shell (string)" +msgstr "re_expression (tekst)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1090 +#: sssd.conf.5.xml:1046 msgid "" "The default shell to use if the provider does not return one during lookup. " "This option can be specified globally in the [nss] section or per-domain." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1096 +#: sssd.conf.5.xml:1052 msgid "" "Default: not set (Return NULL if no shell is specified and rely on libc to " "substitute something sensible when necessary, usually /bin/sh)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1103 sssd.conf.5.xml:1483 +#: sssd.conf.5.xml:1059 sssd.conf.5.xml:1450 msgid "get_domains_timeout (int)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1106 sssd.conf.5.xml:1486 +#: sssd.conf.5.xml:1062 sssd.conf.5.xml:1453 msgid "" "Specifies time in seconds for which the list of subdomains will be " "considered valid." msgstr "" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1066 sssd.conf.5.xml:1457 sssd.conf.5.xml:1788 +#: sssd.conf.5.xml:2862 sssd-ldap.5.xml:550 +msgid "Default: 60" +msgstr "" + #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1115 +#: sssd.conf.5.xml:1071 #, fuzzy #| msgid "enum_cache_timeout (integer)" msgid "memcache_timeout (integer)" msgstr "enum_cache_timeout (numeriek)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1118 +#: sssd.conf.5.xml:1074 msgid "" "Specifies time in seconds for which records in the in-memory cache will be " "valid. Setting this option to zero will disable the in-memory cache." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1126 +#: sssd.conf.5.xml:1082 msgid "" "WARNING: Disabling the in-memory cache will have significant negative impact " "on SSSD's performance and should only be used for testing." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1132 sssd.conf.5.xml:1157 sssd.conf.5.xml:1182 -#: sssd.conf.5.xml:1207 sssd.conf.5.xml:1234 +#: sssd.conf.5.xml:1088 sssd.conf.5.xml:1113 sssd.conf.5.xml:1138 +#: sssd.conf.5.xml:1163 sssd.conf.5.xml:1190 msgid "" "NOTE: If the environment variable SSS_NSS_USE_MEMCACHE is set to \"NO\", " "client applications will not use the fast in-memory cache." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1140 +#: sssd.conf.5.xml:1096 #, fuzzy #| msgid "enum_cache_timeout (integer)" msgid "memcache_size_passwd (integer)" msgstr "enum_cache_timeout (numeriek)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1143 +#: sssd.conf.5.xml:1099 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for passwd requests. Setting the size to 0 will disable the passwd in-" @@ -1506,27 +1458,27 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1149 sssd.conf.5.xml:2888 sssd-ldap.5.xml:604 +#: sssd.conf.5.xml:1105 sssd.conf.5.xml:3013 sssd-ldap.5.xml:604 msgid "Default: 8" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1152 sssd.conf.5.xml:1177 sssd.conf.5.xml:1202 -#: sssd.conf.5.xml:1229 +#: sssd.conf.5.xml:1108 sssd.conf.5.xml:1133 sssd.conf.5.xml:1158 +#: sssd.conf.5.xml:1185 msgid "" "WARNING: Disabled or too small in-memory cache can have significant negative " "impact on SSSD's performance." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1165 +#: sssd.conf.5.xml:1121 #, fuzzy #| msgid "enum_cache_timeout (integer)" msgid "memcache_size_group (integer)" msgstr "enum_cache_timeout (numeriek)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1168 +#: sssd.conf.5.xml:1124 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for group requests. Setting the size to 0 will disable the group in-memory " @@ -1534,21 +1486,21 @@ msgid "" msgstr "" #. type: Content of: <variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1174 sssd.conf.5.xml:1226 sssd.conf.5.xml:3656 +#: sssd.conf.5.xml:1130 sssd.conf.5.xml:1182 sssd.conf.5.xml:3835 #: sssd-ldap.5.xml:534 sssd-ldap.5.xml:581 include/failover.xml:116 #: include/krb5_options.xml:11 msgid "Default: 6" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1190 +#: sssd.conf.5.xml:1146 #, fuzzy #| msgid "enum_cache_timeout (integer)" msgid "memcache_size_initgroups (integer)" msgstr "enum_cache_timeout (numeriek)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1193 +#: sssd.conf.5.xml:1149 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for initgroups requests. Setting the size to 0 will disable the initgroups " @@ -1556,14 +1508,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1215 +#: sssd.conf.5.xml:1171 #, fuzzy #| msgid "enum_cache_timeout (integer)" msgid "memcache_size_sid (integer)" msgstr "enum_cache_timeout (numeriek)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1218 +#: sssd.conf.5.xml:1174 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for SID related requests. Only SID-by-ID and ID-by-SID requests are " @@ -1572,12 +1524,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1242 sssd-ifp.5.xml:90 +#: sssd.conf.5.xml:1198 sssd-ifp.5.xml:90 msgid "user_attributes (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1245 +#: sssd.conf.5.xml:1201 msgid "" "Some of the additional NSS responder requests can return more attributes " "than just the POSIX ones defined by the NSS interface. The list of " @@ -1588,105 +1540,111 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1258 +#: sssd.conf.5.xml:1214 msgid "" "To make configuration more easy the NSS responder will check the InfoPipe " "option if it is not set for the NSS responder." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1263 +#: sssd.conf.5.xml:1219 msgid "Default: not set, fallback to InfoPipe option" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1268 +#: sssd.conf.5.xml:1224 msgid "pwfield (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1271 +#: sssd.conf.5.xml:1227 msgid "" "The value that NSS operations that return users or groups will return for " "the <quote>password</quote> field." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1276 +#: sssd.conf.5.xml:1232 +msgid "" +"This option can also be set per-domain, which overwrites the value in the " +"<quote>[nss]</quote> section for that domain. This is particularly useful " +"when using a proxy domain with <option>proxy_lib_name=files</option> and a " +"<option>proxy_pam_target</option> other than <quote>sssd-shadowutils</" +"quote>. In that case, SSSD returns <quote>*</quote> for the password field " +"by default, which causes <command>pam_unix</command> to treat all accounts " +"as locked. Setting <option>pwfield = x</option> in the domain section " +"restores the expected behavior." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1246 #, fuzzy #| msgid "Default: <quote>%1$s@%2$s</quote>." msgid "Default: <quote>*</quote>" msgstr "Standaard: <quote>%1$s@%2$s</quote>." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1279 -msgid "" -"Note: This option can also be set per-domain which overwrites the value in " -"[nss] section." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1283 +#: sssd.conf.5.xml:1249 msgid "" -"Default: <quote>not set</quote> (remote domains), <quote>x</quote> (proxy " -"domain with nss_files and sssd-shadowutils target)" +"Default (per-domain): <quote>not set</quote> (remote domains), <quote>x</" +"quote> (proxy domain with nss_files and sssd-shadowutils target)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:1292 +#: sssd.conf.5.xml:1258 msgid "PAM configuration options" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:1294 +#: sssd.conf.5.xml:1260 msgid "" "These options can be used to configure the Pluggable Authentication Module " -"(PAM) service." +"(PAM) service and should be specified under the <quote>[pam]</quote> section." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1299 +#: sssd.conf.5.xml:1266 msgid "offline_credentials_expiration (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1302 +#: sssd.conf.5.xml:1269 msgid "" "If the authentication provider is offline, how long should we allow cached " "logins (in days since the last successful online login)." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1307 sssd.conf.5.xml:1320 +#: sssd.conf.5.xml:1274 sssd.conf.5.xml:1287 msgid "Default: 0 (No limit)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1313 +#: sssd.conf.5.xml:1280 msgid "offline_failed_login_attempts (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1316 +#: sssd.conf.5.xml:1283 msgid "" "If the authentication provider is offline, how many failed login attempts " "are allowed." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1326 +#: sssd.conf.5.xml:1293 msgid "offline_failed_login_delay (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1329 +#: sssd.conf.5.xml:1296 msgid "" "The time in minutes which has to pass after offline_failed_login_attempts " "has been reached before a new login attempt is possible." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1334 +#: sssd.conf.5.xml:1301 msgid "" "If set to 0 the user cannot authenticate offline if " "offline_failed_login_attempts has been reached. Only a successful online " @@ -1694,61 +1652,61 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1340 sssd.conf.5.xml:1450 +#: sssd.conf.5.xml:1307 sssd.conf.5.xml:1417 msgid "Default: 5" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1346 +#: sssd.conf.5.xml:1313 msgid "pam_verbosity (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1349 +#: sssd.conf.5.xml:1316 msgid "" "Controls what kind of messages are shown to the user during authentication. " "The higher the number to more messages are displayed." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1354 +#: sssd.conf.5.xml:1321 msgid "Currently sssd supports the following values:" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1357 +#: sssd.conf.5.xml:1324 msgid "<emphasis>0</emphasis>: do not show any message" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1360 +#: sssd.conf.5.xml:1327 msgid "<emphasis>1</emphasis>: show only important messages" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1364 +#: sssd.conf.5.xml:1331 msgid "<emphasis>2</emphasis>: show informational messages" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1367 +#: sssd.conf.5.xml:1334 msgid "<emphasis>3</emphasis>: show all messages and debug information" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1371 sssd.8.xml:63 +#: sssd.conf.5.xml:1338 sssd.8.xml:63 msgid "Default: 1" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1377 +#: sssd.conf.5.xml:1344 #, fuzzy #| msgid "re_expression (string)" msgid "pam_response_filter (string)" msgstr "re_expression (tekst)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1380 +#: sssd.conf.5.xml:1347 msgid "" "A comma separated list of strings which allows to remove (filter) data sent " "by the PAM responder to pam_sss PAM module. There are different kind of " @@ -1757,51 +1715,51 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1388 +#: sssd.conf.5.xml:1355 msgid "" "While messages already can be controlled with the help of the pam_verbosity " "option this option allows to filter out other kind of responses as well." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1395 +#: sssd.conf.5.xml:1362 msgid "ENV" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1396 +#: sssd.conf.5.xml:1363 msgid "Do not send any environment variables to any service." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1399 +#: sssd.conf.5.xml:1366 msgid "ENV:var_name" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1400 +#: sssd.conf.5.xml:1367 msgid "Do not send environment variable var_name to any service." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1404 +#: sssd.conf.5.xml:1371 msgid "ENV:var_name:service" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1405 +#: sssd.conf.5.xml:1372 msgid "Do not send environment variable var_name to service." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1393 +#: sssd.conf.5.xml:1360 msgid "" "Currently the following filters are supported: <placeholder " "type=\"variablelist\" id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1412 +#: sssd.conf.5.xml:1379 msgid "" "The list of strings can either be the list of filters which would set this " "list of filters and overwrite the defaults. Or each element of the list can " @@ -1812,23 +1770,23 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1423 +#: sssd.conf.5.xml:1390 msgid "Default: ENV:KRB5CCNAME:sudo, ENV:KRB5CCNAME:sudo-i" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1426 +#: sssd.conf.5.xml:1393 msgid "" "Example: -ENV:KRB5CCNAME:sudo-i will remove the filter from the default list" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1433 +#: sssd.conf.5.xml:1400 msgid "pam_id_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1436 +#: sssd.conf.5.xml:1403 msgid "" "For any PAM request while SSSD is online, the SSSD will attempt to " "immediately update the cached identity information for the user in order to " @@ -1836,7 +1794,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1442 +#: sssd.conf.5.xml:1409 msgid "" "A complete PAM conversation may perform multiple PAM requests, such as " "account management and session opening. This option controls (on a per-" @@ -1845,17 +1803,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1456 +#: sssd.conf.5.xml:1423 msgid "pam_pwd_expiration_warning (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1459 sssd.conf.5.xml:2912 +#: sssd.conf.5.xml:1426 sssd.conf.5.xml:3037 msgid "Display a warning N days before the password expires." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1462 +#: sssd.conf.5.xml:1429 msgid "" "Please note that the backend server has to provide information about the " "expiration time of the password. If this information is missing, sssd " @@ -1863,32 +1821,32 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1468 sssd.conf.5.xml:2915 +#: sssd.conf.5.xml:1435 sssd.conf.5.xml:3040 msgid "" "If zero is set, then this filter is not applied, i.e. if the expiration " "warning was received from backend server, it will automatically be displayed." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1473 +#: sssd.conf.5.xml:1440 msgid "" "This setting can be overridden by setting <emphasis>pwd_expiration_warning</" "emphasis> for a particular domain." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1478 sssd.conf.5.xml:3913 sssd-ldap.5.xml:662 +#: sssd.conf.5.xml:1445 sssd.conf.5.xml:4118 sssd-ldap.5.xml:662 #: sssd-ldap.5.xml:1733 sssd.8.xml:79 msgid "Default: 0" msgstr "Standaard: 0" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1495 +#: sssd.conf.5.xml:1462 msgid "pam_trusted_users (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1498 +#: sssd.conf.5.xml:1465 msgid "" "Specifies the comma-separated list of UID values or user names that are " "allowed to run PAM conversations against trusted domains. Users not " @@ -1898,74 +1856,74 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1508 +#: sssd.conf.5.xml:1475 msgid "Default: All users are considered trusted by default" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1512 +#: sssd.conf.5.xml:1479 msgid "" "Please note that UID 0 is always allowed to access the PAM responder even in " "case it is not in the pam_trusted_users list." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1519 +#: sssd.conf.5.xml:1486 msgid "pam_public_domains (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1522 +#: sssd.conf.5.xml:1489 msgid "" "Specifies the comma-separated list of domain names that are accessible even " "to untrusted users." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1526 +#: sssd.conf.5.xml:1493 msgid "Two special values for pam_public_domains option are defined:" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1530 +#: sssd.conf.5.xml:1497 msgid "" "all (Untrusted users are allowed to access all domains in PAM responder.)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1534 +#: sssd.conf.5.xml:1501 msgid "" "none (Untrusted users are not allowed to access any domains PAM in " "responder.)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1538 sssd.conf.5.xml:1563 sssd.conf.5.xml:1582 -#: sssd.conf.5.xml:1824 sssd.conf.5.xml:3842 sssd-ldap.5.xml:1270 +#: sssd.conf.5.xml:1505 sssd.conf.5.xml:1530 sssd.conf.5.xml:1549 +#: sssd.conf.5.xml:1821 sssd.conf.5.xml:4048 sssd-ldap.5.xml:1270 msgid "Default: none" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1543 +#: sssd.conf.5.xml:1510 msgid "pam_account_expired_message (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1546 +#: sssd.conf.5.xml:1513 msgid "" "Allows a custom expiration message to be set, replacing the default " "'Permission denied' message." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1551 +#: sssd.conf.5.xml:1518 msgid "" "Note: Please be aware that message is only printed for the SSH service " "unless pam_verbosity is set to 3 (show all messages and debug information)." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1559 +#: sssd.conf.5.xml:1526 #, no-wrap msgid "" "pam_account_expired_message = Account expired, please contact help desk.\n" @@ -1973,19 +1931,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1568 +#: sssd.conf.5.xml:1535 msgid "pam_account_locked_message (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1571 +#: sssd.conf.5.xml:1538 msgid "" "Allows a custom lockout message to be set, replacing the default 'Permission " "denied' message." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1578 +#: sssd.conf.5.xml:1545 #, no-wrap msgid "" "pam_account_locked_message = Account locked, please contact help desk.\n" @@ -1993,83 +1951,126 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1587 -msgid "pam_passkey_auth (bool)" +#: sssd.conf.5.xml:1554 +msgid "pam_passkey_auth (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1590 +#: sssd.conf.5.xml:1557 msgid "Enable passkey device based authentication." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1593 sssd.conf.5.xml:1910 sssd-ad.5.xml:1286 +#: sssd.conf.5.xml:1560 sssd.conf.5.xml:1907 sssd-ad.5.xml:1279 #: sss_rpcidmapd.5.xml:76 msgid "Default: True" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1598 -msgid "passkey_debug_libfido2 (bool)" -msgstr "" +#: sssd.conf.5.xml:1565 +#, fuzzy +#| msgid "re_expression (string)" +msgid "passkey_debug_libfido2 (boolean)" +msgstr "re_expression (tekst)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1601 +#: sssd.conf.5.xml:1568 msgid "Enable libfido2 library debug messages." msgstr "" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1604 sssd.conf.5.xml:1618 sssd-ldap.5.xml:727 -#: sssd-ldap.5.xml:752 sssd-ldap.5.xml:848 sssd-ldap.5.xml:1356 -#: sssd-ad.5.xml:506 sssd-ad.5.xml:582 sssd-ad.5.xml:1155 +#: sssd.conf.5.xml:1571 sssd.conf.5.xml:1585 sssd.conf.5.xml:4781 +#: sssd-ldap.5.xml:727 sssd-ldap.5.xml:752 sssd-ldap.5.xml:848 +#: sssd-ldap.5.xml:1356 sssd-ad.5.xml:506 sssd-ad.5.xml:582 sssd-ad.5.xml:1160 #: include/ldap_id_mapping.xml:250 msgid "Default: False" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1609 -msgid "pam_cert_auth (bool)" -msgstr "" +#: sssd.conf.5.xml:1576 +#, fuzzy +#| msgid "re_expression (string)" +msgid "pam_cert_auth (boolean)" +msgstr "re_expression (tekst)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1612 +#: sssd.conf.5.xml:1579 msgid "" "Enable certificate based Smartcard authentication. Since this requires " "additional communication with the Smartcard which will delay the " "authentication process this option is disabled by default." msgstr "" +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1588 +msgid "" +"Note: In case OpenSC is used for Smartcard access SSSD supports the " +"filesystem caching in OpenSC when enabled in opensc.conf. The cached files " +"are located in a common <quote>opensc</quote> directory in SSSD's state " +"directory. The behaviour can be changed in opensc.conf" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> +#: sssd.conf.5.xml:1597 +#, no-wrap +msgid "" +"app /usr/libexec/sssd/p11_child {\n" +" framework pkcs15 {\n" +" use_file_caching = no;\n" +" }\n" +"}\n" +"app /usr/libexec/sssd/krb5_child {\n" +" framework pkcs15 {\n" +" use_file_caching = no;\n" +" }\n" +"}\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1595 +msgid "" +"Example opensc.conf (*): <placeholder type=\"programlisting\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1610 +msgid "" +"(*) The actual <quote>libexec</quote> directory for p11_child and krb5_child " +"depends on the distribution." +msgstr "" + #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1623 +#: sssd.conf.5.xml:1615 msgid "pam_cert_db_path (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1626 +#: sssd.conf.5.xml:1618 msgid "The path to the certificate database." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1629 sssd.conf.5.xml:2163 sssd.conf.5.xml:4338 +#: sssd.conf.5.xml:1621 sssd.conf.5.xml:2199 sssd.conf.5.xml:4543 msgid "Default:" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1631 sssd.conf.5.xml:2165 +#: sssd.conf.5.xml:1623 sssd.conf.5.xml:2201 msgid "" "/etc/sssd/pki/sssd_auth_ca_db.pem (path to a file with trusted CA " "certificates in PEM format)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1641 +#: sssd.conf.5.xml:1633 #, fuzzy #| msgid "re_expression (string)" msgid "pam_cert_verification (string)" msgstr "re_expression (tekst)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1644 +#: sssd.conf.5.xml:1636 msgid "" "With this parameter the PAM certificate verification can be tuned with a " "comma separated list of options that override the " @@ -2079,7 +2080,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1655 +#: sssd.conf.5.xml:1647 #, no-wrap msgid "" "pam_cert_verification = partial_chain\n" @@ -2087,63 +2088,63 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1659 +#: sssd.conf.5.xml:1651 msgid "" "Default: not set, i.e. use default <quote>certificate_verification</quote> " "option defined in <quote>[sssd]</quote> section." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1666 +#: sssd.conf.5.xml:1658 msgid "p11_child_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1669 +#: sssd.conf.5.xml:1661 msgid "How many seconds will pam_sss wait for p11_child to finish." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1678 +#: sssd.conf.5.xml:1670 #, fuzzy #| msgid "enum_cache_timeout (integer)" msgid "passkey_child_timeout (integer)" msgstr "enum_cache_timeout (numeriek)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1681 +#: sssd.conf.5.xml:1673 msgid "" "How many seconds will the PAM responder wait for passkey_child to finish." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1690 +#: sssd.conf.5.xml:1682 msgid "pam_app_services (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1693 +#: sssd.conf.5.xml:1685 msgid "" "Which PAM services are permitted to contact domains of type " "<quote>application</quote>" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1702 +#: sssd.conf.5.xml:1694 #, fuzzy #| msgid "re_expression (string)" msgid "pam_p11_allowed_services (string)" msgstr "re_expression (tekst)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1705 +#: sssd.conf.5.xml:1697 msgid "" "A comma-separated list of PAM service names for which it will be allowed to " "use Smartcards." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1720 +#: sssd.conf.5.xml:1712 #, no-wrap msgid "" "pam_p11_allowed_services = +my_pam_service, -login\n" @@ -2151,7 +2152,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1709 +#: sssd.conf.5.xml:1701 msgid "" "It is possible to add another PAM service name to the default set by using " "<quote>+service_name</quote> or to explicitly remove a PAM service name from " @@ -2163,68 +2164,73 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1724 sssd-ad.5.xml:645 sssd-ad.5.xml:754 sssd-ad.5.xml:812 -#: sssd-ad.5.xml:870 sssd-ad.5.xml:948 +#: sssd.conf.5.xml:1716 sssd-ad.5.xml:645 sssd-ad.5.xml:759 sssd-ad.5.xml:817 +#: sssd-ad.5.xml:875 sssd-ad.5.xml:953 msgid "Default: the default set of PAM service names includes:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1729 sssd-ad.5.xml:649 +#: sssd.conf.5.xml:1721 sssd-ad.5.xml:649 msgid "login" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1734 sssd-ad.5.xml:654 +#: sssd.conf.5.xml:1726 sssd-ad.5.xml:654 msgid "su" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1739 sssd-ad.5.xml:659 +#: sssd.conf.5.xml:1731 sssd-ad.5.xml:659 msgid "su-l" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1744 sssd-ad.5.xml:674 +#: sssd.conf.5.xml:1736 sssd-ad.5.xml:674 msgid "gdm-smartcard" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1749 sssd-ad.5.xml:669 +#: sssd.conf.5.xml:1741 sssd-ad.5.xml:669 msgid "gdm-password" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1754 +#: sssd.conf.5.xml:1746 msgid "gdm-switchable-auth" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1759 sssd-ad.5.xml:679 +#: sssd.conf.5.xml:1751 sssd-ad.5.xml:679 msgid "kdm" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1764 sssd-ad.5.xml:957 +#: sssd.conf.5.xml:1756 sssd-ad.5.xml:694 +msgid "plasmalogin" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:1761 sssd-ad.5.xml:962 msgid "sudo" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1769 sssd-ad.5.xml:962 +#: sssd.conf.5.xml:1766 sssd-ad.5.xml:967 msgid "sudo-i" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1774 +#: sssd.conf.5.xml:1771 msgid "gnome-screensaver" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1782 +#: sssd.conf.5.xml:1779 msgid "p11_wait_for_card_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1785 +#: sssd.conf.5.xml:1782 msgid "" "If Smartcard authentication is required how many extra seconds in addition " "to p11_child_timeout should the PAM responder wait until a Smartcard is " @@ -2232,12 +2238,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1796 +#: sssd.conf.5.xml:1793 msgid "p11_uri (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1799 +#: sssd.conf.5.xml:1796 msgid "" "PKCS#11 URI (see RFC-7512 for details) which can be used to restrict the " "selection of devices used for Smartcard authentication. By default SSSD's " @@ -2248,7 +2254,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1812 +#: sssd.conf.5.xml:1809 #, no-wrap msgid "" "p11_uri = pkcs11:slot-description=My%20Smartcard%20Reader\n" @@ -2256,7 +2262,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1816 +#: sssd.conf.5.xml:1813 #, no-wrap msgid "" "p11_uri = pkcs11:library-description=OpenSC%20smartcard%20framework;slot-id=2\n" @@ -2264,7 +2270,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1810 +#: sssd.conf.5.xml:1807 msgid "" "Example: <placeholder type=\"programlisting\" id=\"0\"/> or <placeholder " "type=\"programlisting\" id=\"1\"/> To find suitable URI please check the " @@ -2273,47 +2279,49 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1829 -msgid "pam_initgroups_scheme" -msgstr "" +#: sssd.conf.5.xml:1826 +#, fuzzy +#| msgid "re_expression (string)" +msgid "pam_initgroups_scheme (string)" +msgstr "re_expression (tekst)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1837 +#: sssd.conf.5.xml:1834 msgid "always" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1838 +#: sssd.conf.5.xml:1835 msgid "" "Always do an online lookup, please note that pam_id_timeout still applies" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1842 +#: sssd.conf.5.xml:1839 msgid "no_session" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1843 +#: sssd.conf.5.xml:1840 msgid "" "Only do an online lookup if there is no active session of the user, i.e. if " "the user is currently not logged in" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1848 sssd-ldap.5.xml:189 +#: sssd.conf.5.xml:1845 sssd-ldap.5.xml:189 msgid "never" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1849 +#: sssd.conf.5.xml:1846 msgid "" "Never force an online lookup, use the data from the cache as long as they " "are not expired" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1832 +#: sssd.conf.5.xml:1829 msgid "" "The PAM responder can force an online lookup to get the current group " "memberships of the user trying to log in. This option controls when this " @@ -2322,30 +2330,32 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1856 +#: sssd.conf.5.xml:1853 msgid "Default: no_session" msgstr "" -#. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:1861 sssd.conf.5.xml:4277 -msgid "pam_gssapi_services" -msgstr "" +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1858 +#, fuzzy +#| msgid "re_expression (string)" +msgid "pam_gssapi_services (string)" +msgstr "re_expression (tekst)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1864 +#: sssd.conf.5.xml:1861 msgid "" "Comma separated list of PAM services that are allowed to try GSSAPI " "authentication using pam_sss_gss.so module." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1869 +#: sssd.conf.5.xml:1866 msgid "" "To disable GSSAPI authentication, set this option to <quote>-</quote> (dash)." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1873 sssd.conf.5.xml:1904 sssd.conf.5.xml:1942 +#: sssd.conf.5.xml:1870 sssd.conf.5.xml:1901 sssd.conf.5.xml:1939 msgid "" "Note: This option can also be set per-domain which overwrites the value in " "[pam] section. It can also be set for trusted domain which overwrites the " @@ -2353,7 +2363,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1881 +#: sssd.conf.5.xml:1878 #, no-wrap msgid "" "pam_gssapi_services = sudo, sudo-i\n" @@ -2361,22 +2371,22 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1879 sssd.conf.5.xml:1994 sssd.conf.5.xml:3836 +#: sssd.conf.5.xml:1876 sssd.conf.5.xml:2023 sssd.conf.5.xml:4042 msgid "Example: <placeholder type=\"programlisting\" id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1885 +#: sssd.conf.5.xml:1882 msgid "Default: - (GSSAPI authentication is disabled)" msgstr "" -#. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:1890 sssd.conf.5.xml:4278 -msgid "pam_gssapi_check_upn" +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1887 +msgid "pam_gssapi_check_upn (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1893 +#: sssd.conf.5.xml:1890 msgid "" "If True, SSSD will require that the Kerberos user principal that " "successfully authenticated through GSSAPI can be associated with the user " @@ -2384,19 +2394,21 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1900 +#: sssd.conf.5.xml:1897 msgid "" -"If False, every user that is able to obtained required service ticket will " +"If False, every user that is able to obtain a required service ticket will " "be authenticated." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1915 -msgid "pam_gssapi_indicators_map" -msgstr "" +#: sssd.conf.5.xml:1912 +#, fuzzy +#| msgid "re_expression (string)" +msgid "pam_gssapi_indicators_map (string)" +msgstr "re_expression (tekst)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1918 +#: sssd.conf.5.xml:1915 msgid "" "Comma separated list of authentication indicators required to be present in " "a Kerberos ticket to access a PAM service that is allowed to try GSSAPI " @@ -2404,7 +2416,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1924 +#: sssd.conf.5.xml:1921 msgid "" "Each element of the list can be either an authentication indicator name or a " "pair <quote>service:indicator</quote>. Indicators not prefixed with the PAM " @@ -2419,7 +2431,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1937 +#: sssd.conf.5.xml:1934 msgid "" "To disable GSSAPI authentication indicator check, set this option to <quote>-" "</quote> (dash). To disable the check for a specific PAM service, add " @@ -2427,45 +2439,45 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1948 +#: sssd.conf.5.xml:1945 msgid "" "Following authentication indicators are supported by IPA Kerberos " "deployments:" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1951 +#: sssd.conf.5.xml:1948 msgid "" "pkinit -- pre-authentication using X.509 certificates -- whether stored in " "files or on smart cards." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1954 +#: sssd.conf.5.xml:1951 msgid "" "hardened -- SPAKE pre-authentication or any pre-authentication wrapped in a " "FAST channel." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1957 +#: sssd.conf.5.xml:1954 msgid "radius -- pre-authentication with the help of a RADIUS server." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1960 +#: sssd.conf.5.xml:1957 msgid "" "otp -- pre-authentication using integrated two-factor authentication (2FA or " "one-time password, OTP) in IPA." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1963 +#: sssd.conf.5.xml:1960 msgid "idp -- pre-authentication using external identity provider." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1973 +#: sssd.conf.5.xml:1970 #, no-wrap msgid "" "pam_gssapi_indicators_map = sudo:pkinit, sudo-i:pkinit\n" @@ -2473,7 +2485,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1968 +#: sssd.conf.5.xml:1965 msgid "" "Example: to require access to SUDO services only for users which obtained " "their Kerberos tickets with a X.509 certificate pre-authentication (PKINIT), " @@ -2481,31 +2493,72 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1977 +#: sssd.conf.5.xml:1974 msgid "Default: not set (use of authentication indicators is not required)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1979 +#, fuzzy +#| msgid "re_expression (string)" +msgid "pam_gssapi_indicators_apply (string)" +msgstr "re_expression (tekst)" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1982 +msgid "" +"Comma separated list of triples to assign additional information from the " +"Kerberos ticket, e.g. a SID from the PAC, to authentication indicators." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1988 +msgid "Currently supported is:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:1991 +msgid "SID:S-1-5-[domain]-[RID]:[authentication indicator]" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> +#: sssd.conf.5.xml:2002 +#, no-wrap +msgid "" +"pam_gssapi_indicators_apply = SID:S-1-5-12345-23456-34567-4321:pkinit\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1996 +msgid "" +"Example: To assign a SID, which is e.g. set by Active Directory's " +"Authentication Mechanism Assurance (AMA) if the AD user used a Smartcard for " +"authentication, to the 'pkinit' authentication indicator use: <placeholder " +"type=\"programlisting\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2011 #, fuzzy #| msgid "re_expression (string)" msgid "pam_json_services (string)" msgstr "re_expression (tekst)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1985 +#: sssd.conf.5.xml:2014 msgid "" "Comma separated list of PAM services which can handle the JSON protocol for " "selecting authentication mechanisms" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1990 +#: sssd.conf.5.xml:2019 msgid "To disable JSON protocol, set this option to <quote>-</quote> (dash)." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1996 +#: sssd.conf.5.xml:2025 #, no-wrap msgid "" "pam_json_services = gdm-switchable-auth\n" @@ -2513,52 +2566,67 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2000 +#: sssd.conf.5.xml:2029 msgid "Default: - (JSON protocol is disabled)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2003 +#: sssd.conf.5.xml:2032 msgid "" "Note: 2-Factor Authentication (2FA) is not supported. If 2FA is required, do " "not activate the JSON protocol." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:2013 +#: sssd.conf.5.xml:2042 msgid "SUDO configuration options" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2015 +#: sssd.conf.5.xml:2044 +#, fuzzy +#| msgid "" +#| "These options can be used to configure the Name Service Switch (NSS) " +#| "service." msgid "" -"These options can be used to configure the sudo service. The detailed " -"instructions for configuration of <citerefentry> <refentrytitle>sudo</" -"refentrytitle> <manvolnum>8</manvolnum> </citerefentry> to work with " -"<citerefentry> <refentrytitle>sssd</refentrytitle> <manvolnum>8</manvolnum> " -"</citerefentry> are in the manual page <citerefentry> <refentrytitle>sssd-" -"sudo</refentrytitle> <manvolnum>5</manvolnum> </citerefentry>." +"These options can be used to configure the sudo service and should be " +"specified under the <quote>[sudo]</quote> section." msgstr "" +"Deze opties kunnen worden gebruikt om de Name Serice Switch (NSS) service te " +"configurere." -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2032 -msgid "sudo_timed (bool)" +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:2048 +msgid "" +"The detailed instructions for configuration of <citerefentry> " +"<refentrytitle>sudo</refentrytitle> <manvolnum>8</manvolnum> </citerefentry> " +"to work with <citerefentry> <refentrytitle>sssd</refentrytitle> " +"<manvolnum>8</manvolnum> </citerefentry> are in the manual page " +"<citerefentry> <refentrytitle>sssd-sudo</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry>." msgstr "" +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2064 +#, fuzzy +#| msgid "try_inotify (boolean)" +msgid "sudo_timed (boolean)" +msgstr "try_inotify (bool)" + #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2035 +#: sssd.conf.5.xml:2067 msgid "" "Whether or not to evaluate the sudoNotBefore and sudoNotAfter attributes " "that implement time-dependent sudoers entries." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2047 +#: sssd.conf.5.xml:2079 msgid "sudo_threshold (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2050 +#: sssd.conf.5.xml:2082 msgid "" "Maximum number of expired rules that can be refreshed at once. If number of " "expired rules is below threshold, those rules are refreshed with " @@ -2568,22 +2636,30 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:2069 +#: sssd.conf.5.xml:2101 msgid "AUTOFS configuration options" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2071 -msgid "These options can be used to configure the autofs service." +#: sssd.conf.5.xml:2103 +#, fuzzy +#| msgid "" +#| "These options can be used to configure the Name Service Switch (NSS) " +#| "service." +msgid "" +"These options can be used to configure the autofs service and should be " +"specified under the <quote>[autofs]</quote> section." msgstr "" +"Deze opties kunnen worden gebruikt om de Name Serice Switch (NSS) service te " +"configurere." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2075 +#: sssd.conf.5.xml:2109 msgid "autofs_negative_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2078 +#: sssd.conf.5.xml:2112 msgid "" "Specifies for how many seconds should the autofs responder negative cache " "hits (that is, queries for invalid map entries, like nonexistent ones) " @@ -2591,22 +2667,32 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:2094 +#: sssd.conf.5.xml:2128 msgid "SSH configuration options" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2096 -msgid "These options can be used to configure the SSH service." +#: sssd.conf.5.xml:2130 +#, fuzzy +#| msgid "" +#| "These options can be used to configure the Name Service Switch (NSS) " +#| "service." +msgid "" +"These options can be used to configure the SSH service and should be " +"specified under the <quote>[ssh]</quote> section." msgstr "" +"Deze opties kunnen worden gebruikt om de Name Serice Switch (NSS) service te " +"configurere." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2100 -msgid "ssh_use_certificate_keys (bool)" -msgstr "" +#: sssd.conf.5.xml:2136 +#, fuzzy +#| msgid "re_expression (string)" +msgid "ssh_use_certificate_keys (boolean)" +msgstr "re_expression (tekst)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2103 +#: sssd.conf.5.xml:2139 msgid "" "If set to true the <command>sss_ssh_authorizedkeys</command> will return ssh " "keys derived from the public key of X.509 certificates stored in the user " @@ -2615,12 +2701,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2118 +#: sssd.conf.5.xml:2154 msgid "ssh_use_certificate_matching_rules (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2121 +#: sssd.conf.5.xml:2157 msgid "" "By default the ssh responder will use all available certificate matching " "rules to filter the certificates so that ssh keys are only derived from the " @@ -2630,7 +2716,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2130 +#: sssd.conf.5.xml:2166 msgid "" "There are two special key words 'all_rules' and 'no_rules' which will enable " "all or no rules, respectively. The latter means that no certificates will be " @@ -2638,7 +2724,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2137 +#: sssd.conf.5.xml:2173 msgid "" "If no rules are configured using 'all_rules' will enable a default rule " "which enables all certificates suitable for client authentication. This is " @@ -2647,38 +2733,38 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2144 +#: sssd.conf.5.xml:2180 msgid "" "A non-existing rule name is considered an error. If as a result no rule is " "selected all certificates will be ignored." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2149 +#: sssd.conf.5.xml:2185 msgid "" "Default: not set, equivalent to 'all_rules', all found rules or the default " "rule are used" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2155 +#: sssd.conf.5.xml:2191 msgid "ca_db (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2158 +#: sssd.conf.5.xml:2194 msgid "" "Path to a storage of trusted CA certificates. The option is used to validate " "user certificates before deriving public ssh keys from them." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:2178 +#: sssd.conf.5.xml:2214 msgid "PAC responder configuration options" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2180 +#: sssd.conf.5.xml:2216 msgid "" "The PAC responder works together with the authorization data plugin for MIT " "Kerberos sssd_pac_plugin.so and a sub-domain provider. The plugin sends the " @@ -2689,7 +2775,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:2189 +#: sssd.conf.5.xml:2225 msgid "" "If the remote user does not exist in the cache, it is created. The UID is " "determined with the help of the SID, trusted domains will have UPGs and the " @@ -2700,24 +2786,26 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:2197 +#: sssd.conf.5.xml:2233 msgid "" "If there are SIDs of groups from domains sssd knows about, the user will be " "added to those groups." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2203 -msgid "These options can be used to configure the PAC responder." +#: sssd.conf.5.xml:2239 +msgid "" +"These options can be used to configure the PAC responder and should be " +"specified under the <quote>[pac]</quote> section." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2207 sssd-ifp.5.xml:66 +#: sssd.conf.5.xml:2244 sssd-ifp.5.xml:66 msgid "allowed_uids (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2210 +#: sssd.conf.5.xml:2247 msgid "" "Specifies the comma-separated list of UID values or user names that are " "allowed to access the PAC responder. User names are resolved to UIDs at " @@ -2725,19 +2813,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2216 +#: sssd.conf.5.xml:2253 msgid "" "Default: 0, &sssd_user_name; (only root and SSSD service users are allowed " "to access the PAC responder)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2220 +#: sssd.conf.5.xml:2257 msgid "Default: 0 (only the root user is allowed to access the PAC responder)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2224 +#: sssd.conf.5.xml:2261 msgid "" "Please note that defaults will be overwritten with this option. If you still " "want to allow the root and/or '&sssd_user_name;' user to access the PAC " @@ -2746,7 +2834,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2231 +#: sssd.conf.5.xml:2268 msgid "" "Please note that although the UID 0 is used as the default it will be " "overwritten with this option. If you still want to allow the root user to " @@ -2755,26 +2843,26 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2240 +#: sssd.conf.5.xml:2277 msgid "pac_lifetime (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2243 +#: sssd.conf.5.xml:2280 msgid "" "Lifetime of the PAC entry in seconds. As long as the PAC is valid the PAC " "data can be used to determine the group memberships of a user." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2253 +#: sssd.conf.5.xml:2290 #, fuzzy #| msgid "re_expression (string)" msgid "pac_check (string)" msgstr "re_expression (tekst)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2256 +#: sssd.conf.5.xml:2293 msgid "" "Apply additional checks on the PAC of the Kerberos ticket which is available " "in Active Directory and FreeIPA domains, if configured. Please note that " @@ -2785,7 +2873,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2266 +#: sssd.conf.5.xml:2303 msgid "" "Please note that the checks listed below only apply to PACs issued by Active " "Directory or recent versions of FreeIPA. PACs issued e.g. by a plain MIT " @@ -2793,24 +2881,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2277 +#: sssd.conf.5.xml:2314 msgid "no_check" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2279 +#: sssd.conf.5.xml:2316 msgid "" "The PAC must not be present and even if it is present no additional checks " "will be done." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2285 +#: sssd.conf.5.xml:2322 msgid "pac_present" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2287 +#: sssd.conf.5.xml:2324 msgid "" "The PAC must be present in the service ticket which SSSD will request with " "the help of the user's TGT. If the PAC is not available the authentication " @@ -2818,24 +2906,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2295 +#: sssd.conf.5.xml:2332 msgid "check_upn" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2297 +#: sssd.conf.5.xml:2334 msgid "" "If the PAC is present check if the user principal name (UPN) information is " "consistent." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2303 +#: sssd.conf.5.xml:2340 msgid "check_upn_allow_missing" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2305 +#: sssd.conf.5.xml:2342 msgid "" "This option should be used together with 'check_upn' and handles the case " "where a UPN is set on the server-side but is not read by SSSD. The typical " @@ -2847,7 +2935,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2317 +#: sssd.conf.5.xml:2354 msgid "" "Currently this option is set by default to avoid regressions in such " "environments. A log message will be added to the system log and SSSD's debug " @@ -2858,60 +2946,60 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2331 +#: sssd.conf.5.xml:2368 msgid "upn_dns_info_present" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2333 +#: sssd.conf.5.xml:2370 msgid "The PAC must contain the UPN-DNS-INFO buffer, implies 'check_upn'." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2338 +#: sssd.conf.5.xml:2375 msgid "check_upn_dns_info_ex" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2340 +#: sssd.conf.5.xml:2377 msgid "" "If the PAC is present and the extension to the UPN-DNS-INFO buffer is " "available check if the information in the extension is consistent." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2347 +#: sssd.conf.5.xml:2384 msgid "upn_dns_info_ex_present" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2349 +#: sssd.conf.5.xml:2386 msgid "" "The PAC must contain the extension of the UPN-DNS-INFO buffer, implies " "'check_upn_dns_info_ex', 'upn_dns_info_present' and 'check_upn'." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2273 +#: sssd.conf.5.xml:2310 msgid "" "The following options can be used alone or in a comma-separated list: " "<placeholder type=\"variablelist\" id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2359 +#: sssd.conf.5.xml:2396 msgid "" "Default: no_check (AD and IPA provider 'check_upn, check_upn_allow_missing, " "check_upn_dns_info_ex')" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:2368 +#: sssd.conf.5.xml:2405 msgid "Session recording configuration options" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2370 +#: sssd.conf.5.xml:2407 msgid "" "Session recording works in conjunction with <citerefentry> " "<refentrytitle>tlog-rec-session</refentrytitle> <manvolnum>8</manvolnum> </" @@ -2921,66 +3009,78 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2383 -msgid "These options can be used to configure session recording." +#: sssd.conf.5.xml:2420 +msgid "" +"These options can be used to configure session recording and should be " +"specified under the <quote>[session_recording]</quote> section." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:2425 +msgid "" +"Note: Unlike other sections, the <quote>[session_recording]</quote> section " +"ignores <replaceable>debug*</replaceable> options and suitable " +"<replaceable>debug*</replaceable> options must be set in <quote>[pam]</" +"quote>, <quote>[nss]</quote> and <quote>[domain/<replaceable>NAME</" +"replaceable>]</quote> sections." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2387 sssd-session-recording.5.xml:64 +#: sssd.conf.5.xml:2433 sssd-session-recording.5.xml:64 msgid "scope (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2394 sssd-session-recording.5.xml:71 +#: sssd.conf.5.xml:2440 sssd-session-recording.5.xml:71 msgid "\"none\"" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2397 sssd-session-recording.5.xml:74 +#: sssd.conf.5.xml:2443 sssd-session-recording.5.xml:74 msgid "No users are recorded." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2402 sssd-session-recording.5.xml:79 +#: sssd.conf.5.xml:2448 sssd-session-recording.5.xml:79 msgid "\"some\"" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2405 sssd-session-recording.5.xml:82 +#: sssd.conf.5.xml:2451 sssd-session-recording.5.xml:82 msgid "" "Users/groups specified by <replaceable>users</replaceable> and " "<replaceable>groups</replaceable> options are recorded." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2414 sssd-session-recording.5.xml:91 +#: sssd.conf.5.xml:2460 sssd-session-recording.5.xml:91 msgid "\"all\"" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2417 sssd-session-recording.5.xml:94 +#: sssd.conf.5.xml:2463 sssd-session-recording.5.xml:94 msgid "All users are recorded." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2390 sssd-session-recording.5.xml:67 +#: sssd.conf.5.xml:2436 sssd-session-recording.5.xml:67 msgid "" "One of the following strings specifying the scope of session recording: " "<placeholder type=\"variablelist\" id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2424 sssd-session-recording.5.xml:101 +#: sssd.conf.5.xml:2470 sssd-session-recording.5.xml:101 msgid "Default: \"none\"" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2429 sssd-session-recording.5.xml:106 +#: sssd.conf.5.xml:2475 sssd-session-recording.5.xml:106 msgid "users (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2432 sssd-session-recording.5.xml:109 +#: sssd.conf.5.xml:2478 sssd-session-recording.5.xml:109 msgid "" "A comma-separated list of users which should have session recording enabled. " "Matches user names as returned by NSS. I.e. after the possible space " @@ -2988,17 +3088,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2438 sssd-session-recording.5.xml:115 +#: sssd.conf.5.xml:2484 sssd-session-recording.5.xml:115 msgid "Default: Empty. Matches no users." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2443 sssd-session-recording.5.xml:120 +#: sssd.conf.5.xml:2489 sssd-session-recording.5.xml:120 msgid "groups (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2446 sssd-session-recording.5.xml:123 +#: sssd.conf.5.xml:2492 sssd-session-recording.5.xml:123 msgid "" "A comma-separated list of groups, members of which should have session " "recording enabled. Matches group names as returned by NSS. I.e. after the " @@ -3006,7 +3106,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2452 sssd.conf.5.xml:2484 sssd-session-recording.5.xml:129 +#: sssd.conf.5.xml:2498 sssd.conf.5.xml:2530 sssd-session-recording.5.xml:129 #: sssd-session-recording.5.xml:161 msgid "" "NOTE: using this option (having it set to anything) has a considerable " @@ -3015,59 +3115,58 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2459 sssd-session-recording.5.xml:136 +#: sssd.conf.5.xml:2505 sssd-session-recording.5.xml:136 msgid "Default: Empty. Matches no groups." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2464 sssd-session-recording.5.xml:141 +#: sssd.conf.5.xml:2510 sssd-session-recording.5.xml:141 #, fuzzy #| msgid "re_expression (string)" msgid "exclude_users (string)" msgstr "re_expression (tekst)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2467 sssd-session-recording.5.xml:144 +#: sssd.conf.5.xml:2513 sssd-session-recording.5.xml:144 msgid "" "A comma-separated list of users to be excluded from recording, only " "applicable with 'scope=all'." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2471 sssd-session-recording.5.xml:148 +#: sssd.conf.5.xml:2517 sssd-session-recording.5.xml:148 msgid "Default: Empty. No users excluded." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2476 sssd-session-recording.5.xml:153 +#: sssd.conf.5.xml:2522 sssd-session-recording.5.xml:153 msgid "exclude_groups (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2479 sssd-session-recording.5.xml:156 +#: sssd.conf.5.xml:2525 sssd-session-recording.5.xml:156 msgid "" "A comma-separated list of groups, members of which should be excluded from " "recording. Only applicable with 'scope=all'." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2491 sssd-session-recording.5.xml:168 +#: sssd.conf.5.xml:2537 sssd-session-recording.5.xml:168 msgid "Default: Empty. No groups excluded." msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:2501 +#: sssd.conf.5.xml:2547 msgid "DOMAIN SECTIONS" msgstr "" -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry><para> -#: sssd.conf.5.xml:2508 sssd.conf.5.xml:3964 sssd.conf.5.xml:3965 -#: sssd.conf.5.xml:3968 -msgid "enabled" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2554 +msgid "enabled (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2511 +#: sssd.conf.5.xml:2557 msgid "" "Explicitly enable or disable the domain. If <quote>true</quote>, the domain " "is always <quote>enabled</quote>. If <quote>false</quote>, the domain is " @@ -3077,12 +3176,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2523 +#: sssd.conf.5.xml:2569 msgid "domain_type (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2526 +#: sssd.conf.5.xml:2572 msgid "" "Specifies whether the domain is meant to be used by POSIX-aware clients such " "as the Name Service Switch or by applications that do not need POSIX data to " @@ -3091,14 +3190,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2534 +#: sssd.conf.5.xml:2580 msgid "" "Allowed values for this option are <quote>posix</quote> and " "<quote>application</quote>." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2538 +#: sssd.conf.5.xml:2584 msgid "" "POSIX domains are reachable by all services. Application domains are only " "reachable from the InfoPipe responder (see <citerefentry> " @@ -3107,38 +3206,38 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2546 +#: sssd.conf.5.xml:2592 msgid "" "NOTE: The application domains are currently well tested with " "<quote>id_provider=ldap</quote> only." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2550 +#: sssd.conf.5.xml:2596 msgid "" "For an easy way to configure a non-POSIX domains, please see the " "<quote>Application domains</quote> section." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2554 +#: sssd.conf.5.xml:2600 msgid "Default: posix" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2560 +#: sssd.conf.5.xml:2606 msgid "min_id,max_id (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2563 +#: sssd.conf.5.xml:2609 msgid "" "UID and GID limits for the domain. If a domain contains an entry that is " "outside these limits, it is ignored." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2568 +#: sssd.conf.5.xml:2614 msgid "" "For users, this affects the primary GID limit. The user will not be returned " "to NSS if either the UID or the primary GID is outside the range. For non-" @@ -3147,24 +3246,26 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2575 +#: sssd.conf.5.xml:2621 msgid "" "These ID limits affect even saving entries to cache, not only returning them " "by name or ID." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2579 +#: sssd.conf.5.xml:2625 msgid "Default: 1 for min_id, 0 (no limit) for max_id" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2585 -msgid "enumerate (bool)" -msgstr "" +#: sssd.conf.5.xml:2631 +#, fuzzy +#| msgid "re_expression (string)" +msgid "enumerate (boolean)" +msgstr "re_expression (tekst)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2588 +#: sssd.conf.5.xml:2634 msgid "" "Determines if a domain can be enumerated, that is, whether the domain can " "list all the users and group it contains. Note that it is not required to " @@ -3173,36 +3274,36 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2596 +#: sssd.conf.5.xml:2642 msgid "TRUE = Users and groups are enumerated" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2599 +#: sssd.conf.5.xml:2645 msgid "FALSE = No enumerations for this domain" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2602 sssd.conf.5.xml:2867 sssd.conf.5.xml:3044 +#: sssd.conf.5.xml:2648 sssd.conf.5.xml:2992 sssd.conf.5.xml:3174 msgid "Default: FALSE" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2605 +#: sssd.conf.5.xml:2651 msgid "" "Enumerating a domain requires SSSD to download and store ALL user and group " "entries from the remote server." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2610 +#: sssd.conf.5.xml:2656 msgid "" "Feature is only supported for domains with id_provider = ldap or id_provider " "= proxy." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2614 +#: sssd.conf.5.xml:2660 msgid "" "Note: Enabling enumeration has a severe performance impact on SSSD while " "enumeration is running. It may take up to several minutes after SSSD startup " @@ -3216,14 +3317,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2629 +#: sssd.conf.5.xml:2675 msgid "" "While the first enumeration is running, requests for the complete user or " "group lists may return no results until it completes." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2634 +#: sssd.conf.5.xml:2680 msgid "" "Further, enabling enumeration may increase the time necessary to detect " "network disconnection, as longer timeouts are required to ensure that " @@ -3232,14 +3333,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2642 +#: sssd.conf.5.xml:2688 msgid "" "For the reasons cited above, enabling enumeration is not recommended, " "especially in large environments." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2647 +#: sssd.conf.5.xml:2693 msgid "" "Note: the proxy provider is tested with open source modules like " "'libnss_files' and 'libnss_ldap'. 3rd party modules must follow the " @@ -3247,19 +3348,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2656 +#: sssd.conf.5.xml:2702 msgid "entry_cache_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2659 +#: sssd.conf.5.xml:2705 msgid "" "How many seconds should nss_sss consider entries valid before asking the " "backend again" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2663 +#: sssd.conf.5.xml:2709 msgid "" "The cache expiration timestamps are stored as attributes of individual " "objects in the cache. Therefore, changing the cache timeout only has effect " @@ -3270,139 +3371,250 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2676 +#: sssd.conf.5.xml:2722 msgid "Default: 5400" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2682 +#: sssd.conf.5.xml:2728 msgid "entry_cache_user_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2685 +#: sssd.conf.5.xml:2731 msgid "" "How many seconds should nss_sss consider user entries valid before asking " "the backend again" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2689 sssd.conf.5.xml:2702 sssd.conf.5.xml:2715 -#: sssd.conf.5.xml:2728 sssd.conf.5.xml:2742 sssd.conf.5.xml:2755 -#: sssd.conf.5.xml:2769 sssd.conf.5.xml:2783 sssd.conf.5.xml:2796 +#: sssd.conf.5.xml:2735 sssd.conf.5.xml:2748 sssd.conf.5.xml:2761 +#: sssd.conf.5.xml:2774 sssd.conf.5.xml:2788 sssd.conf.5.xml:2801 +#: sssd.conf.5.xml:2815 sssd.conf.5.xml:2829 msgid "Default: entry_cache_timeout" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2695 +#: sssd.conf.5.xml:2741 msgid "entry_cache_group_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2698 +#: sssd.conf.5.xml:2744 msgid "" "How many seconds should nss_sss consider group entries valid before asking " "the backend again" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2708 +#: sssd.conf.5.xml:2754 msgid "entry_cache_netgroup_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2711 +#: sssd.conf.5.xml:2757 msgid "" "How many seconds should nss_sss consider netgroup entries valid before " "asking the backend again" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2721 +#: sssd.conf.5.xml:2767 msgid "entry_cache_service_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2724 +#: sssd.conf.5.xml:2770 msgid "" "How many seconds should nss_sss consider service entries valid before asking " "the backend again" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2734 +#: sssd.conf.5.xml:2780 msgid "entry_cache_resolver_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2737 +#: sssd.conf.5.xml:2783 msgid "" "How many seconds should nss_sss consider hosts and networks entries valid " "before asking the backend again" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2748 +#: sssd.conf.5.xml:2794 msgid "entry_cache_sudo_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2751 +#: sssd.conf.5.xml:2797 msgid "" "How many seconds should sudo consider rules valid before asking the backend " "again" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2761 +#: sssd.conf.5.xml:2807 msgid "entry_cache_autofs_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2764 +#: sssd.conf.5.xml:2810 msgid "" "How many seconds should the autofs service consider automounter maps valid " "before asking the backend again" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2775 +#: sssd.conf.5.xml:2821 msgid "entry_cache_ssh_host_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2778 +#: sssd.conf.5.xml:2824 msgid "" "How many seconds to keep a host ssh key after refresh. IE how long to cache " "the host key for." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2789 -msgid "entry_cache_computer_timeout (integer)" +#: sssd.conf.5.xml:2835 +msgid "offline_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2792 +#: sssd.conf.5.xml:2838 msgid "" -"How many seconds to keep the local computer entry before asking the backend " -"again" +"When SSSD switches to offline mode the amount of time before it tries to go " +"back online will increase based upon the time spent disconnected. By " +"default SSSD uses incremental behaviour to calculate delay in between " +"retries. So, the wait time for a given retry will be longer than the wait " +"time for the previous ones. After each unsuccessful attempt to go online, " +"the new interval is recalculated by the following:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2849 sssd.conf.5.xml:2907 +msgid "" +"new_delay = Minimum(old_delay * 2, offline_timeout_max) + " +"random[0...offline_timeout_random_offset]" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2852 +msgid "" +"The offline_timeout default value is 60. The offline_timeout_max default " +"value is 3600. The offline_timeout_random_offset default value is 30. The " +"end result is the number of seconds before next retry." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2858 +msgid "" +"Note that the maximum length of each interval is defined by " +"offline_timeout_max (apart from the random part)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2868 +#, fuzzy +#| msgid "enum_cache_timeout (integer)" +msgid "offline_timeout_max (integer)" +msgstr "enum_cache_timeout (numeriek)" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2871 +msgid "" +"Controls by how much the time between attempts to go online can be " +"incremented following unsuccessful attempts to go online." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2876 +msgid "A value of 0 disables the incrementing behaviour." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2879 +msgid "" +"The value of this parameter should be set in correlation to offline_timeout " +"parameter value." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2883 +msgid "" +"With offline_timeout set to 60 (default value) there is no point in setting " +"offline_timeout_max to less than 120 as it will saturate instantly. General " +"rule here should be to set offline_timeout_max to at least 4 times " +"offline_timeout." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2889 +msgid "" +"Although a value between 0 and offline_timeout may be specified, it has the " +"effect of overriding the offline_timeout value so is of little use." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2894 +#, fuzzy +#| msgid "Default: 3" +msgid "Default: 3600" +msgstr "Standaard: 3" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2900 +msgid "offline_timeout_random_offset (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2903 +msgid "" +"When SSSD is in offline mode it keeps probing backend servers in specified " +"time intervals:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2910 +msgid "" +"This parameter controls the value of the random offset used for the above " +"equation. Final random_offset value will be random number in range:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2915 +msgid "[0 - offline_timeout_random_offset]" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2918 +msgid "A value of 0 disables the random offset addition." msgstr "" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2921 +#, fuzzy +#| msgid "Default: 3" +msgid "Default: 30" +msgstr "Standaard: 3" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2802 +#: sssd.conf.5.xml:2927 msgid "refresh_expired_interval (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2805 +#: sssd.conf.5.xml:2930 msgid "" "Specifies how many seconds SSSD has to wait before triggering a background " "refresh task which will refresh all expired or nearly expired records." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2810 +#: sssd.conf.5.xml:2935 msgid "" "The background refresh will process users, groups and netgroups in the " "cache. For users who have performed the initgroups (get group membership for " @@ -3411,17 +3623,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2818 +#: sssd.conf.5.xml:2943 msgid "This option is automatically inherited for all trusted domains." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2822 +#: sssd.conf.5.xml:2947 msgid "You can consider setting this value to 3/4 * entry_cache_timeout." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2826 +#: sssd.conf.5.xml:2951 msgid "" "Cache entry will be refreshed by background task when 2/3 of cache timeout " "has already passed. If there are existing cached entries, the background " @@ -3433,18 +3645,18 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2839 sssd-ldap.5.xml:406 sssd-ldap.5.xml:1834 -#: sssd-ipa.5.xml:255 +#: sssd.conf.5.xml:2964 sssd-ldap.5.xml:406 sssd-ldap.5.xml:1834 +#: sssd-ipa.5.xml:250 msgid "Default: 0 (disabled)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2845 -msgid "cache_credentials (bool)" +#: sssd.conf.5.xml:2970 +msgid "cache_credentials (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2848 +#: sssd.conf.5.xml:2973 msgid "" "Determines if user credentials are also cached in the local LDB cache. The " "cached credentials refer to passwords, which includes the first (long term) " @@ -3455,7 +3667,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2859 +#: sssd.conf.5.xml:2984 msgid "" "Take a note that while credentials are stored as a salted SHA512 hash, this " "still potentially poses some security risk in case an attacker manages to " @@ -3464,12 +3676,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2873 +#: sssd.conf.5.xml:2998 msgid "cache_credentials_minimal_first_factor_length (int)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2876 +#: sssd.conf.5.xml:3001 msgid "" "If 2-Factor-Authentication (2FA) is used and credentials should be saved " "this value determines the minimal length the first authentication factor " @@ -3477,19 +3689,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2883 +#: sssd.conf.5.xml:3008 msgid "" "This should avoid that the short PINs of a PIN based 2FA scheme are saved in " "the cache which would make them easy targets for brute-force attacks." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2894 +#: sssd.conf.5.xml:3019 msgid "account_cache_expiration (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2897 +#: sssd.conf.5.xml:3022 msgid "" "Number of days entries are left in cache after last successful login before " "being removed during a cleanup of the cache. 0 means keep forever. The " @@ -3498,17 +3710,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2904 +#: sssd.conf.5.xml:3029 msgid "Default: 0 (unlimited)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2909 +#: sssd.conf.5.xml:3034 msgid "pwd_expiration_warning (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2920 +#: sssd.conf.5.xml:3045 msgid "" "Please note that the backend server has to provide information about the " "expiration time of the password. If this information is missing, sssd " @@ -3517,28 +3729,28 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2927 +#: sssd.conf.5.xml:3052 msgid "Default: 7 (Kerberos), 0 (LDAP)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2933 +#: sssd.conf.5.xml:3058 msgid "id_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2936 +#: sssd.conf.5.xml:3061 msgid "" "The identification provider used for the domain. Supported ID providers are:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2940 +#: sssd.conf.5.xml:3065 msgid "<quote>proxy</quote>: Support a legacy NSS provider." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2943 +#: sssd.conf.5.xml:3068 msgid "" "<quote>ldap</quote>: LDAP provider. See <citerefentry> <refentrytitle>sssd-" "ldap</refentrytitle> <manvolnum>5</manvolnum> </citerefentry> for more " @@ -3546,8 +3758,8 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2951 sssd.conf.5.xml:3070 sssd.conf.5.xml:3129 -#: sssd.conf.5.xml:3192 +#: sssd.conf.5.xml:3076 sssd.conf.5.xml:3200 sssd.conf.5.xml:3259 +#: sssd.conf.5.xml:3322 msgid "" "<quote>ipa</quote>: FreeIPA and Red Hat Identity Management provider. See " "<citerefentry> <refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</" @@ -3555,8 +3767,8 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2960 sssd.conf.5.xml:3079 sssd.conf.5.xml:3138 -#: sssd.conf.5.xml:3201 +#: sssd.conf.5.xml:3085 sssd.conf.5.xml:3209 sssd.conf.5.xml:3268 +#: sssd.conf.5.xml:3331 msgid "" "<quote>ad</quote>: Active Directory provider. See <citerefentry> " "<refentrytitle>sssd-ad</refentrytitle> <manvolnum>5</manvolnum> </" @@ -3564,27 +3776,34 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2968 +#: sssd.conf.5.xml:3093 msgid "" "<quote>idp</quote>: Provider for OAuth 2.0/OIDC based Identity Providers " "(IdP). See <citerefentry> <refentrytitle>sssd-idp</refentrytitle> " "<manvolnum>5</manvolnum> </citerefentry> for more information." msgstr "" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3101 +msgid "" +"Default: Not set (This is a mandatory setting that must be explicitly " +"defined for each configured domain)." +msgstr "" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2979 -msgid "use_fully_qualified_names (bool)" +#: sssd.conf.5.xml:3109 +msgid "use_fully_qualified_names (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2982 +#: sssd.conf.5.xml:3112 msgid "" "Use the full name and domain (as formatted by the domain's full_name_format) " "as the user's login name reported to NSS." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2987 +#: sssd.conf.5.xml:3117 msgid "" "If set to TRUE, all requests to this domain must use fully qualified names. " "For example, if used in EXAMPLE domain that contains a \"test\" user, " @@ -3593,7 +3812,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2995 +#: sssd.conf.5.xml:3125 msgid "" "NOTE: This option has no effect on netgroup lookups due to their tendency to " "include nested netgroups without qualified names. For netgroups, all domains " @@ -3601,24 +3820,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3002 +#: sssd.conf.5.xml:3132 msgid "" "Default: FALSE (TRUE for trusted domain/sub-domains or if " "default_domain_suffix is used)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3009 -msgid "ignore_group_members (bool)" +#: sssd.conf.5.xml:3139 +msgid "ignore_group_members (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3012 +#: sssd.conf.5.xml:3142 msgid "Do not return group members for group lookups." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3015 +#: sssd.conf.5.xml:3145 msgid "" "If set to TRUE, the group membership attribute is not requested from the " "ldap server, and group members are not returned when processing group lookup " @@ -3630,7 +3849,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3033 +#: sssd.conf.5.xml:3163 msgid "" "Enabling this option can also make access provider checks for group " "membership significantly faster, especially for groups containing many " @@ -3638,7 +3857,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3039 sssd.conf.5.xml:3767 sssd-ldap.5.xml:401 +#: sssd.conf.5.xml:3169 sssd.conf.5.xml:3951 sssd-ldap.5.xml:401 #: sssd-ldap.5.xml:454 sssd-ldap.5.xml:529 sssd-ldap.5.xml:576 #: sssd-ldap.5.xml:599 sssd-ldap.5.xml:638 sssd-ldap.5.xml:657 #: sssd-ldap.5.xml:681 sssd-ldap.5.xml:1114 sssd-ldap.5.xml:1147 @@ -3648,19 +3867,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3049 +#: sssd.conf.5.xml:3179 msgid "auth_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3052 +#: sssd.conf.5.xml:3182 msgid "" "The authentication provider used for the domain. Supported auth providers " "are:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3056 sssd.conf.5.xml:3122 +#: sssd.conf.5.xml:3186 sssd.conf.5.xml:3252 msgid "" "<quote>ldap</quote> for native LDAP authentication. See <citerefentry> " "<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> </" @@ -3668,7 +3887,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3063 +#: sssd.conf.5.xml:3193 msgid "" "<quote>krb5</quote> for Kerberos authentication. See <citerefentry> " "<refentrytitle>sssd-krb5</refentrytitle> <manvolnum>5</manvolnum> </" @@ -3676,7 +3895,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3087 +#: sssd.conf.5.xml:3217 msgid "" "<quote>idp</quote>: Provider for OAuth 2.0/OIDC based authentication. See " "<citerefentry> <refentrytitle>sssd-idp</refentrytitle> <manvolnum>5</" @@ -3684,30 +3903,30 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3095 +#: sssd.conf.5.xml:3225 msgid "" "<quote>proxy</quote> for relaying authentication to some other PAM target." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3098 +#: sssd.conf.5.xml:3228 msgid "<quote>none</quote> disables authentication explicitly." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3101 +#: sssd.conf.5.xml:3231 msgid "" "Default: <quote>id_provider</quote> is used if it is set and can handle " "authentication requests." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3107 +#: sssd.conf.5.xml:3237 msgid "access_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3110 +#: sssd.conf.5.xml:3240 msgid "" "The access control provider used for the domain. There are two built-in " "access providers (in addition to any included in installed backends) " @@ -3715,17 +3934,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3116 +#: sssd.conf.5.xml:3246 msgid "<quote>permit</quote> always allow access." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3119 +#: sssd.conf.5.xml:3249 msgid "<quote>deny</quote> always deny access." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3146 +#: sssd.conf.5.xml:3276 msgid "" "<quote>simple</quote> access control based on access or deny lists. See " "<citerefentry> <refentrytitle>sssd-simple</refentrytitle> <manvolnum>5</" @@ -3734,7 +3953,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3153 +#: sssd.conf.5.xml:3283 msgid "" "<quote>krb5</quote>: .k5login based access control. See <citerefentry> " "<refentrytitle>sssd-krb5</refentrytitle> <manvolnum>5</manvolnum></" @@ -3742,29 +3961,29 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3160 +#: sssd.conf.5.xml:3290 msgid "<quote>proxy</quote> for relaying access control to another PAM module." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3163 +#: sssd.conf.5.xml:3293 msgid "Default: <quote>permit</quote>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3168 +#: sssd.conf.5.xml:3298 msgid "chpass_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3171 +#: sssd.conf.5.xml:3301 msgid "" "The provider which should handle change password operations for the domain. " "Supported change password providers are:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3176 +#: sssd.conf.5.xml:3306 msgid "" "<quote>ldap</quote> to change a password stored in a LDAP server. See " "<citerefentry> <refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</" @@ -3772,7 +3991,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3184 +#: sssd.conf.5.xml:3314 msgid "" "<quote>krb5</quote> to change the Kerberos password. See <citerefentry> " "<refentrytitle>sssd-krb5</refentrytitle> <manvolnum>5</manvolnum> </" @@ -3780,35 +3999,35 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3209 +#: sssd.conf.5.xml:3339 msgid "" "<quote>proxy</quote> for relaying password changes to some other PAM target." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3213 +#: sssd.conf.5.xml:3343 msgid "<quote>none</quote> disallows password changes explicitly." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3216 +#: sssd.conf.5.xml:3346 msgid "" "Default: <quote>auth_provider</quote> is used if it is set and can handle " "change password requests." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3223 +#: sssd.conf.5.xml:3353 msgid "sudo_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3226 +#: sssd.conf.5.xml:3356 msgid "The SUDO provider used for the domain. Supported SUDO providers are:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3230 +#: sssd.conf.5.xml:3360 msgid "" "<quote>ldap</quote> for rules stored in LDAP. See <citerefentry> " "<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> </" @@ -3816,33 +4035,33 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3238 +#: sssd.conf.5.xml:3368 msgid "" "<quote>ipa</quote> the same as <quote>ldap</quote> but with IPA default " "settings." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3242 +#: sssd.conf.5.xml:3372 msgid "" "<quote>ad</quote> the same as <quote>ldap</quote> but with AD default " "settings." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3246 +#: sssd.conf.5.xml:3376 msgid "<quote>none</quote> disables SUDO explicitly." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3249 +#: sssd.conf.5.xml:3379 msgid "" "Default: The value of <quote>id_provider</quote> is used if it is set and " "can handle sudo requests." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3253 +#: sssd.conf.5.xml:3383 msgid "" "The detailed instructions for configuration of sudo_provider are in the " "manual page <citerefentry> <refentrytitle>sssd-sudo</refentrytitle> " @@ -3853,7 +4072,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3268 +#: sssd.conf.5.xml:3398 msgid "" "<emphasis>NOTE:</emphasis> Sudo rules are periodically downloaded in the " "background unless the sudo provider is explicitly disabled. Set " @@ -3862,12 +4081,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3278 +#: sssd.conf.5.xml:3408 msgid "selinux_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3281 +#: sssd.conf.5.xml:3411 msgid "" "The provider which should handle loading of selinux settings. Note that this " "provider will be called right after access provider ends. Supported selinux " @@ -3875,7 +4094,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3287 +#: sssd.conf.5.xml:3417 msgid "" "<quote>ipa</quote> to load selinux settings from an IPA server. See " "<citerefentry> <refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</" @@ -3883,31 +4102,32 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3295 +#: sssd.conf.5.xml:3425 msgid "<quote>none</quote> disallows fetching selinux settings explicitly." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3298 +#: sssd.conf.5.xml:3428 msgid "" -"Default: <quote>id_provider</quote> is used if it is set and can handle " -"selinux loading requests." +"Default: the value of <quote>id_provider</quote> is used if it is set and " +"can handle selinux loading requests. Otherwise the result is the same as if " +"the selinux_provider is set to none." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3304 +#: sssd.conf.5.xml:3435 msgid "subdomains_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3307 +#: sssd.conf.5.xml:3438 msgid "" "The provider which should handle fetching of subdomains. This value should " "be always the same as id_provider. Supported subdomain providers are:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3313 +#: sssd.conf.5.xml:3444 msgid "" "<quote>ipa</quote> to load a list of subdomains from an IPA server. See " "<citerefentry> <refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</" @@ -3915,7 +4135,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3322 +#: sssd.conf.5.xml:3453 msgid "" "<quote>ad</quote> to load a list of subdomains from an Active Directory " "server. See <citerefentry> <refentrytitle>sssd-ad</refentrytitle> " @@ -3924,24 +4144,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3331 +#: sssd.conf.5.xml:3462 msgid "<quote>none</quote> disallows fetching subdomains explicitly." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3335 +#: sssd.conf.5.xml:3466 msgid "" "Default: The value of <quote>id_provider</quote> is used if it is set and " "can handle subdomain requests." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3341 +#: sssd.conf.5.xml:3472 msgid "session_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3344 +#: sssd.conf.5.xml:3475 msgid "" "The provider which configures and manages user session related tasks. The " "only user session task currently provided is the integration with Fleet " @@ -3949,36 +4169,36 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3351 +#: sssd.conf.5.xml:3482 msgid "<quote>ipa</quote> to allow performing user session related tasks." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3355 +#: sssd.conf.5.xml:3486 msgid "" "<quote>none</quote> does not perform any kind of user session related tasks." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3359 +#: sssd.conf.5.xml:3490 #, fuzzy #| msgid "Default: <quote>%1$s@%2$s</quote>." msgid "Default: <quote>none</quote>." msgstr "Standaard: <quote>%1$s@%2$s</quote>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3365 +#: sssd.conf.5.xml:3496 msgid "autofs_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3368 +#: sssd.conf.5.xml:3499 msgid "" "The autofs provider used for the domain. Supported autofs providers are:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3372 +#: sssd.conf.5.xml:3503 msgid "" "<quote>ldap</quote> to load maps stored in LDAP. See <citerefentry> " "<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> </" @@ -3986,7 +4206,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3379 +#: sssd.conf.5.xml:3510 msgid "" "<quote>ipa</quote> to load maps stored in an IPA server. See <citerefentry> " "<refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</manvolnum> </" @@ -3994,7 +4214,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3387 +#: sssd.conf.5.xml:3518 msgid "" "<quote>ad</quote> to load maps stored in an AD server. See <citerefentry> " "<refentrytitle>sssd-ad</refentrytitle> <manvolnum>5</manvolnum> </" @@ -4002,31 +4222,31 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3396 +#: sssd.conf.5.xml:3527 msgid "<quote>none</quote> disables autofs explicitly." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3399 +#: sssd.conf.5.xml:3530 msgid "" "Default: The value of <quote>id_provider</quote> is used if it is set and " "can handle autofs requests." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3406 +#: sssd.conf.5.xml:3537 msgid "hostid_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3409 +#: sssd.conf.5.xml:3540 msgid "" "The provider used for retrieving host identity information. Supported " "hostid providers are:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3413 +#: sssd.conf.5.xml:3544 msgid "" "<quote>ipa</quote> to load host identity stored in an IPA server. See " "<citerefentry> <refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</" @@ -4034,38 +4254,38 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3421 +#: sssd.conf.5.xml:3552 msgid "<quote>none</quote> disables hostid explicitly." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3424 +#: sssd.conf.5.xml:3555 msgid "" "Default: The value of <quote>id_provider</quote> is used if it is set and " "can handle hostid requests." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3431 +#: sssd.conf.5.xml:3562 msgid "resolver_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3434 +#: sssd.conf.5.xml:3565 msgid "" "The provider which should handle hosts and networks lookups. Supported " "resolver providers are:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3438 +#: sssd.conf.5.xml:3569 msgid "" "<quote>proxy</quote> to forward lookups to another NSS library. See " "<quote>proxy_resolver_lib_name</quote>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3442 +#: sssd.conf.5.xml:3573 msgid "" "<quote>ldap</quote> to fetch hosts and networks stored in LDAP. See " "<citerefentry> <refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</" @@ -4073,7 +4293,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3449 +#: sssd.conf.5.xml:3580 msgid "" "<quote>ad</quote> to fetch hosts and networks stored in AD. See " "<citerefentry> <refentrytitle>sssd-ad</refentrytitle> <manvolnum>5</" @@ -4082,19 +4302,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3457 +#: sssd.conf.5.xml:3588 msgid "<quote>none</quote> disallows fetching hosts and networks explicitly." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3460 +#: sssd.conf.5.xml:3591 msgid "" "Default: The value of <quote>id_provider</quote> is used if it is set and " "can handle resolver requests." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3470 +#: sssd.conf.5.xml:3601 msgid "" "Regular expression for this domain that describes how to parse the string " "containing user name and domain into these components. The \"domain\" can " @@ -4104,24 +4324,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3479 +#: sssd.conf.5.xml:3610 msgid "" "Default: <quote>^((?P<name>.+)@(?P<domain>[^@]*)|(?P<name>" "[^@]+))$</quote> which allows two different styles for user names:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:3484 sssd.conf.5.xml:3498 +#: sssd.conf.5.xml:3615 sssd.conf.5.xml:3629 msgid "username" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:3487 sssd.conf.5.xml:3501 +#: sssd.conf.5.xml:3618 sssd.conf.5.xml:3632 msgid "username@domain.name" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3492 +#: sssd.conf.5.xml:3623 msgid "" "Default for the AD and IPA provider: <quote>^(((?P<domain>[^\\\\]+)\\\\" "(?P<name>.+))|((?P<name>.+)@(?P<domain>[^@]+))|((?" @@ -4130,19 +4350,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:3504 +#: sssd.conf.5.xml:3635 msgid "domain\\username" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3507 +#: sssd.conf.5.xml:3638 msgid "" "While the first two correspond to the general default the third one is " "introduced to allow easy integration of users from Windows domains." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3512 +#: sssd.conf.5.xml:3643 msgid "" "The default re_expression uses the <quote>@</quote> character as a separator " "between the name and the domain. As a result of this setting the default " @@ -4152,93 +4372,98 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3564 +#: sssd.conf.5.xml:3695 msgid "Default: <quote>%1$s@%2$s</quote>." msgstr "Standaard: <quote>%1$s@%2$s</quote>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3570 +#: sssd.conf.5.xml:3701 msgid "lookup_family_order (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3573 +#: sssd.conf.5.xml:3704 msgid "" "Provides the ability to select preferred address family to use when " "performing DNS lookups." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3577 +#: sssd.conf.5.xml:3708 msgid "Supported values:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3580 +#: sssd.conf.5.xml:3711 msgid "ipv4_first: Try looking up IPv4 address, if that fails, try IPv6" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3583 +#: sssd.conf.5.xml:3714 msgid "ipv4_only: Only attempt to resolve hostnames to IPv4 addresses." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3586 +#: sssd.conf.5.xml:3717 msgid "ipv6_first: Try looking up IPv6 address, if that fails, try IPv4" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3589 +#: sssd.conf.5.xml:3720 msgid "ipv6_only: Only attempt to resolve hostnames to IPv6 addresses." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3592 +#: sssd.conf.5.xml:3723 msgid "Default: ipv4_first" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3598 +#: sssd.conf.5.xml:3729 #, fuzzy #| msgid "entry_negative_timeout (integer)" msgid "dns_resolver_server_timeout (integer)" msgstr "entry_negative_timeout (numeriek)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3601 +#: sssd.conf.5.xml:3732 msgid "" -"Defines the amount of time (in milliseconds) SSSD would try to talk to DNS " -"server before trying next DNS server." +"Defines the timeout duration (in milliseconds) SSSD waits for a DNS server " +"to respond before moving to the next one." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3606 +#: sssd.conf.5.xml:3737 msgid "" "The AD provider will use this option for the CLDAP ping timeouts as well." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3610 sssd.conf.5.xml:3630 sssd.conf.5.xml:3651 +#: sssd.conf.5.xml:3741 sssd.conf.5.xml:3777 sssd.conf.5.xml:3814 msgid "" -"Please see the section <quote>FAILOVER</quote> for more information about " -"the service resolution." +"Please see the section <quote>FAILOVER</quote> in <citerefentry> " +"<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> </" +"citerefentry>, <citerefentry> <refentrytitle>sssd-krb5</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry>, <citerefentry> <refentrytitle>sssd-" +"ipa</refentrytitle> <manvolnum>5</manvolnum> </citerefentry> or " +"<citerefentry> <refentrytitle>sssd-ad</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry> for more information about the service resolution." msgstr "" #. type: Content of: <refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3615 sssd-ldap.5.xml:700 include/failover.xml:84 +#: sssd.conf.5.xml:3762 sssd-ldap.5.xml:700 include/failover.xml:84 msgid "Default: 1000" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3621 +#: sssd.conf.5.xml:3768 #, fuzzy #| msgid "entry_negative_timeout (integer)" msgid "dns_resolver_op_timeout (integer)" msgstr "entry_negative_timeout (numeriek)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3624 +#: sssd.conf.5.xml:3771 msgid "" "Defines the amount of time (in seconds) to wait to resolve single DNS query " "(e.g. resolution of a hostname or an SRV record) before trying the next " @@ -4246,17 +4471,17 @@ msgid "" msgstr "" #. type: Content of: <refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3635 include/failover.xml:100 +#: sssd.conf.5.xml:3798 include/failover.xml:100 msgid "Default: 3" msgstr "Standaard: 3" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3641 +#: sssd.conf.5.xml:3804 msgid "dns_resolver_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3644 +#: sssd.conf.5.xml:3807 msgid "" "Defines the amount of time (in seconds) to wait for a reply from the " "internal fail over service before assuming that the service is unreachable. " @@ -4265,14 +4490,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3662 +#: sssd.conf.5.xml:3841 #, fuzzy #| msgid "entry_negative_timeout (integer)" -msgid "dns_resolver_use_search_list (bool)" +msgid "dns_resolver_use_search_list (boolean)" msgstr "entry_negative_timeout (numeriek)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3665 +#: sssd.conf.5.xml:3844 msgid "" "Normally, the DNS resolver searches the domain list defined in the " "\"search\" directive from the resolv.conf file. This can lead to delays in " @@ -4280,7 +4505,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3671 +#: sssd.conf.5.xml:3850 msgid "" "If fully qualified domain names (or _srv_) are used in the SSSD " "configuration, setting this option to FALSE can prevent unnecessary DNS " @@ -4288,38 +4513,38 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3677 +#: sssd.conf.5.xml:3856 #, fuzzy #| msgid "Default: 3" msgid "Default: TRUE" msgstr "Standaard: 3" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3683 +#: sssd.conf.5.xml:3862 msgid "dns_discovery_domain (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3686 +#: sssd.conf.5.xml:3865 msgid "" "If service discovery is used in the back end, specifies the domain part of " "the service discovery DNS query." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3690 +#: sssd.conf.5.xml:3869 msgid "Default: Use the domain part of machine's hostname" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3696 +#: sssd.conf.5.xml:3875 #, fuzzy #| msgid "entry_negative_timeout (integer)" msgid "failover_primary_timeout (integer)" msgstr "entry_negative_timeout (numeriek)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3699 +#: sssd.conf.5.xml:3878 msgid "" "When no primary server is available, SSSD fails over to a backup server. " "This option defines the number of seconds SSSD waits before attempting to " @@ -4327,59 +4552,68 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3706 +#: sssd.conf.5.xml:3885 msgid "Note: The minimum value is 31." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3709 +#: sssd.conf.5.xml:3888 #, fuzzy #| msgid "Default: 3" msgid "Default: 31" msgstr "Standaard: 3" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3715 +#: sssd.conf.5.xml:3894 msgid "override_gid (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3718 -msgid "Override the primary GID value with the one specified." +#: sssd.conf.5.xml:3897 +msgid "" +"Override the primary GID value for all users in the domain with specified " +"value." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3901 +msgid "" +"Default: not set (Use the primary GID value retrieved from the identity " +"provider)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3724 +#: sssd.conf.5.xml:3908 msgid "case_sensitive (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3731 +#: sssd.conf.5.xml:3915 msgid "True" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3734 +#: sssd.conf.5.xml:3918 msgid "Case sensitive. This value is invalid for AD provider." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3740 +#: sssd.conf.5.xml:3924 msgid "False" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3742 +#: sssd.conf.5.xml:3926 msgid "Case insensitive." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3746 +#: sssd.conf.5.xml:3930 msgid "Preserving" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3749 +#: sssd.conf.5.xml:3933 msgid "" "Same as False (case insensitive), but does not lowercase names in the result " "of NSS operations. Note that name aliases (and in case of services also " @@ -4387,31 +4621,57 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3757 +#: sssd.conf.5.xml:3941 msgid "" "If you want to set this value for trusted domain with IPA provider, you need " "to set it on both the client and SSSD on the server." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3727 +#: sssd.conf.5.xml:3911 msgid "" "Treat user and group names as case sensitive. Possible option values are: " "<placeholder type=\"variablelist\" id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3772 +#: sssd.conf.5.xml:3956 msgid "Default: True (False for AD provider)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3778 +#: sssd.conf.5.xml:3962 +msgid "avoid_by_id_lookups (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3965 +msgid "" +"If this option is set to 'true' SSSD will try to avoid sending lookups by ID " +"to the backend and will switch to a lookup by name if a cached object with a " +"matching ID can be found." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3971 +msgid "" +"This option can e.g. be used in cases where searches by ID are expensive on " +"the server side because of missing indexes or are not even possible, e.g. " +"due to non-reversible POSIX id-mapping." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3978 +msgid "Default: False (True for IdP provider)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:3984 msgid "subdomain_inherit (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3781 +#: sssd.conf.5.xml:3987 msgid "" "Specifies a list of configuration parameters that should be inherited by a " "subdomain. Please note that only selected parameters can be inherited. " @@ -4419,95 +4679,95 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3787 +#: sssd.conf.5.xml:3993 msgid "ldap_search_timeout" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3790 +#: sssd.conf.5.xml:3996 msgid "ldap_network_timeout" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3793 +#: sssd.conf.5.xml:3999 msgid "ldap_opt_timeout" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3796 +#: sssd.conf.5.xml:4002 #, fuzzy #| msgid "enum_cache_timeout (integer)" msgid "ldap_offline_timeout" msgstr "enum_cache_timeout (numeriek)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3799 +#: sssd.conf.5.xml:4005 msgid "ldap_purge_cache_timeout" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3802 +#: sssd.conf.5.xml:4008 msgid "ldap_purge_cache_offset" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3805 +#: sssd.conf.5.xml:4011 msgid "" "ldap_krb5_keytab (the value of krb5_keytab will be used if ldap_krb5_keytab " "is not set explicitly)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3809 +#: sssd.conf.5.xml:4015 msgid "ldap_krb5_ticket_lifetime" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3812 +#: sssd.conf.5.xml:4018 #, fuzzy #| msgid "reconnection_retries (integer)" msgid "ldap_connection_expire_timeout" msgstr "reconnection_retries (numeriek)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3815 +#: sssd.conf.5.xml:4021 #, fuzzy #| msgid "reconnection_retries (integer)" msgid "ldap_connection_expire_offset" msgstr "reconnection_retries (numeriek)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3818 +#: sssd.conf.5.xml:4024 msgid "ldap_connection_idle_timeout" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3821 sssd-ldap.5.xml:446 +#: sssd.conf.5.xml:4027 sssd-ldap.5.xml:446 msgid "ldap_use_tokengroups" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3824 +#: sssd.conf.5.xml:4030 msgid "ldap_user_principal" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3827 +#: sssd.conf.5.xml:4033 msgid "ignore_group_members" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3830 +#: sssd.conf.5.xml:4036 msgid "auto_private_groups" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3833 +#: sssd.conf.5.xml:4039 msgid "case_sensitive" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:3838 +#: sssd.conf.5.xml:4044 #, no-wrap msgid "" "subdomain_inherit = ldap_purge_cache_timeout\n" @@ -4515,27 +4775,27 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3845 +#: sssd.conf.5.xml:4051 msgid "Note: This option only works with the IPA and AD provider." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3852 +#: sssd.conf.5.xml:4058 msgid "subdomain_homedir (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3863 +#: sssd.conf.5.xml:4069 msgid "%F" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3864 +#: sssd.conf.5.xml:4070 msgid "flat (NetBIOS) name of a subdomain." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3855 +#: sssd.conf.5.xml:4061 msgid "" "Use this homedir as default value for all subdomains within this domain in " "IPA AD trust. See <emphasis>override_homedir</emphasis> for info about " @@ -4545,55 +4805,55 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3869 +#: sssd.conf.5.xml:4075 msgid "" "The value can be overridden by <emphasis>override_homedir</emphasis> option." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3873 +#: sssd.conf.5.xml:4079 msgid "Default: <filename>/home/%d/%u</filename>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3878 +#: sssd.conf.5.xml:4084 msgid "realmd_tags (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3881 +#: sssd.conf.5.xml:4087 msgid "" "Various tags stored by the realmd configuration service for this domain." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3887 +#: sssd.conf.5.xml:4093 msgid "cached_auth_timeout (int)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3890 +#: sssd.conf.5.xml:4096 msgid "" -"Specifies time in seconds since last successful online authentication for " -"which user will be authenticated using cached credentials while SSSD is in " -"the online mode. If the credentials are incorrect, SSSD falls back to online " -"authentication." +"Specifies the number of seconds since the last successful online " +"authentication during which SSSD will authenticate users via cached " +"credentials, even while online. If the cached authentication fails, SSSD " +"immediately falls back to online authentication." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3898 +#: sssd.conf.5.xml:4103 msgid "" "This option's value is inherited by all trusted domains. At the moment it is " "not possible to set a different value per trusted domain." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3903 +#: sssd.conf.5.xml:4108 msgid "Special value 0 implies that this feature is disabled." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3907 +#: sssd.conf.5.xml:4112 msgid "" "Please note that if <quote>cached_auth_timeout</quote> is longer than " "<quote>pam_id_timeout</quote> then the back end could be called to handle " @@ -4601,14 +4861,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3918 +#: sssd.conf.5.xml:4123 #, fuzzy #| msgid "re_expression (string)" msgid "local_auth_policy (string)" msgstr "re_expression (tekst)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3921 +#: sssd.conf.5.xml:4126 msgid "" "Local authentication methods policy. Some backends (i.e. LDAP, proxy " "provider) only support a password based authentication, while others can " @@ -4620,7 +4880,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3933 +#: sssd.conf.5.xml:4138 msgid "" "There are three possible values for this option: match, only, enable. " "<quote>match</quote> is used to match offline and online states for Kerberos " @@ -4632,7 +4892,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3946 +#: sssd.conf.5.xml:4151 msgid "" "The following table shows which authentication methods, if configured " "properly, are currently enabled or disabled for each backend, with the " @@ -4640,44 +4900,49 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> -#: sssd.conf.5.xml:3959 +#: sssd.conf.5.xml:4164 #, fuzzy #| msgid "re_expression (string)" msgid "local_auth_policy = match (default)" msgstr "re_expression (tekst)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> -#: sssd.conf.5.xml:3960 +#: sssd.conf.5.xml:4165 msgid "Passkey" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> -#: sssd.conf.5.xml:3961 +#: sssd.conf.5.xml:4166 msgid "Smartcard" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:3964 sssd-ldap.5.xml:228 +#: sssd.conf.5.xml:4169 sssd-ldap.5.xml:228 msgid "IPA" msgstr "" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry><para> +#: sssd.conf.5.xml:4169 sssd.conf.5.xml:4170 sssd.conf.5.xml:4173 +msgid "enabled" +msgstr "" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:3967 sssd-ldap.5.xml:233 +#: sssd.conf.5.xml:4172 sssd-ldap.5.xml:233 msgid "AD" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry><para> -#: sssd.conf.5.xml:3967 sssd.conf.5.xml:3970 sssd.conf.5.xml:3971 +#: sssd.conf.5.xml:4172 sssd.conf.5.xml:4175 sssd.conf.5.xml:4176 msgid "disabled" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry> -#: sssd.conf.5.xml:3970 +#: sssd.conf.5.xml:4175 msgid "LDAP" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3975 +#: sssd.conf.5.xml:4180 msgid "" "Please note that if local Smartcard authentication is enabled and a " "Smartcard is present, Smartcard authentication will be preferred over the " @@ -4686,7 +4951,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:3987 +#: sssd.conf.5.xml:4192 #, no-wrap msgid "" "[domain/shadowutils]\n" @@ -4697,7 +4962,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3983 +#: sssd.conf.5.xml:4188 msgid "" "The following configuration example allows local users to authenticate " "locally using any enabled method (i.e. smartcard, passkey). <placeholder " @@ -4705,31 +4970,31 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3995 +#: sssd.conf.5.xml:4200 #, fuzzy #| msgid "Default: 3" msgid "Default: match" msgstr "Standaard: 3" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4000 +#: sssd.conf.5.xml:4205 msgid "auto_private_groups (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4006 +#: sssd.conf.5.xml:4211 msgid "true" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4009 +#: sssd.conf.5.xml:4214 msgid "" "Create user's private group unconditionally from user's UID number. The GID " "number is ignored in this case." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4013 +#: sssd.conf.5.xml:4218 msgid "" "NOTE: Because the GID number and the user private group are inferred from " "the UID number, it is not supported to have multiple entries with the same " @@ -4738,24 +5003,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4022 +#: sssd.conf.5.xml:4227 msgid "false" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4025 +#: sssd.conf.5.xml:4230 msgid "" "Always use the user's primary GID number. The GID number must refer to a " "group object in the LDAP database." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4031 +#: sssd.conf.5.xml:4236 msgid "hybrid" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4034 +#: sssd.conf.5.xml:4239 msgid "" "A primary group is autogenerated for user entries whose UID and GID numbers " "have the same value and at the same time the GID number does not correspond " @@ -4765,14 +5030,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4047 +#: sssd.conf.5.xml:4252 msgid "" "If the UID and GID of a user are different, then the GID must correspond to " "a group entry, otherwise the GID is simply not resolvable." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4054 +#: sssd.conf.5.xml:4259 msgid "" "This feature is useful for environments that wish to stop maintaining a " "separate group objects for the user private groups, but also wish to retain " @@ -4780,14 +5045,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4003 +#: sssd.conf.5.xml:4208 msgid "" "This option takes any of three available values: <placeholder " "type=\"variablelist\" id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4066 +#: sssd.conf.5.xml:4271 msgid "" "For the LDAP based id providers (LDAP, IPA and AD) the default for the " "configured domain is typically False because the sources have the concept of " @@ -4797,14 +5062,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4075 +#: sssd.conf.5.xml:4280 msgid "" "For subdomains, the default value is False for subdomains that use assigned " "POSIX IDs and True for subdomains that use automatic ID-mapping." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:4083 +#: sssd.conf.5.xml:4288 #, no-wrap msgid "" "[domain/forest.domain/sub.domain]\n" @@ -4812,7 +5077,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:4089 +#: sssd.conf.5.xml:4294 #, no-wrap msgid "" "[domain/forest.domain]\n" @@ -4821,7 +5086,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4080 +#: sssd.conf.5.xml:4285 msgid "" "The value of auto_private_groups can either be set per subdomains in a " "subsection, for example: <placeholder type=\"programlisting\" id=\"0\"/> or " @@ -4830,7 +5095,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:2503 +#: sssd.conf.5.xml:2549 msgid "" "These configuration options can be present in a domain configuration " "section, that is, in a section called <quote>[domain/<replaceable>NAME</" @@ -4838,17 +5103,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4104 +#: sssd.conf.5.xml:4309 msgid "proxy_pam_target (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4107 +#: sssd.conf.5.xml:4312 msgid "The proxy target PAM proxies to." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4110 +#: sssd.conf.5.xml:4315 msgid "" "Default: not set by default, you have to take an existing pam configuration " "or create a new one and add the service name here. As an alternative you can " @@ -4856,12 +5121,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4120 +#: sssd.conf.5.xml:4325 msgid "proxy_lib_name (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4123 +#: sssd.conf.5.xml:4328 msgid "" "The name of the NSS library to use in proxy domains. The NSS functions " "searched for in the library are in the form of _nss_$(libName)_$(function), " @@ -4869,12 +5134,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4133 +#: sssd.conf.5.xml:4338 msgid "proxy_resolver_lib_name (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4136 +#: sssd.conf.5.xml:4341 msgid "" "The name of the NSS library to use for hosts and networks lookups in proxy " "domains. The NSS functions searched for in the library are in the form of " @@ -4882,12 +5147,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4147 +#: sssd.conf.5.xml:4352 msgid "proxy_fast_alias (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4150 +#: sssd.conf.5.xml:4355 msgid "" "When a user or group is looked up by name in the proxy provider, a second " "lookup by ID is performed to \"canonicalize\" the name in case the requested " @@ -4896,12 +5161,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4164 +#: sssd.conf.5.xml:4369 msgid "proxy_max_children (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4167 +#: sssd.conf.5.xml:4372 msgid "" "This option specifies the number of pre-forked proxy children. It is useful " "for high-load SSSD environments where sssd may run out of available child " @@ -4909,19 +5174,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4100 +#: sssd.conf.5.xml:4305 msgid "" "Options valid for proxy domains. <placeholder type=\"variablelist\" " "id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:4183 +#: sssd.conf.5.xml:4388 msgid "Application domains" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:4185 +#: sssd.conf.5.xml:4390 msgid "" "SSSD, with its D-Bus interface (see <citerefentry> <refentrytitle>sssd-ifp</" "refentrytitle> <manvolnum>5</manvolnum> </citerefentry>) is appealing to " @@ -4938,7 +5203,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:4205 +#: sssd.conf.5.xml:4410 msgid "" "Please note that the application domain must still be explicitly enabled in " "the <quote>domains</quote> parameter so that the lookup order between the " @@ -4946,17 +5211,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><title> -#: sssd.conf.5.xml:4211 +#: sssd.conf.5.xml:4416 msgid "Application domain parameters" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4213 +#: sssd.conf.5.xml:4418 msgid "inherit_from (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4216 +#: sssd.conf.5.xml:4421 msgid "" "The SSSD POSIX-type domain the application domain inherits all settings " "from. The application domain can moreover add its own settings to the " @@ -4965,7 +5230,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:4230 +#: sssd.conf.5.xml:4435 msgid "" "The following example illustrates the use of an application domain. In this " "setup, the POSIX domain is connected to an LDAP server and is used by the OS " @@ -4975,7 +5240,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><programlisting> -#: sssd.conf.5.xml:4238 +#: sssd.conf.5.xml:4443 #, no-wrap msgid "" "[sssd]\n" @@ -4995,12 +5260,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:4258 +#: sssd.conf.5.xml:4463 msgid "TRUSTED DOMAIN SECTION" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4260 +#: sssd.conf.5.xml:4465 msgid "" "Some options used in the domain section can also be used in the trusted " "domain section, that is, in a section called <quote>[domain/" @@ -5011,69 +5276,79 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4267 +#: sssd.conf.5.xml:4472 msgid "ldap_search_base," msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4268 +#: sssd.conf.5.xml:4473 msgid "ldap_user_search_base," msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4269 +#: sssd.conf.5.xml:4474 msgid "ldap_group_search_base," msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4270 +#: sssd.conf.5.xml:4475 msgid "ldap_netgroup_search_base," msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4271 +#: sssd.conf.5.xml:4476 msgid "ldap_service_search_base," msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4272 +#: sssd.conf.5.xml:4477 msgid "ldap_sasl_mech," msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4273 +#: sssd.conf.5.xml:4478 msgid "ad_server," msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4274 +#: sssd.conf.5.xml:4479 msgid "ad_backup_server," msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4275 +#: sssd.conf.5.xml:4480 msgid "ad_site," msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:4276 sssd-ipa.5.xml:934 +#: sssd.conf.5.xml:4481 sssd-ipa.5.xml:929 msgid "use_fully_qualified_names" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4280 +#: sssd.conf.5.xml:4482 +msgid "pam_gssapi_services" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:4483 +msgid "pam_gssapi_check_upn" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:4485 msgid "" "For more details about these options see their individual description in the " "manual page." msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:4286 +#: sssd.conf.5.xml:4491 msgid "CERTIFICATE MAPPING SECTION" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4288 +#: sssd.conf.5.xml:4493 msgid "" "To allow authentication with Smartcards and certificates SSSD must be able " "to map certificates to users. This can be done by adding the full " @@ -5086,7 +5361,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4302 +#: sssd.conf.5.xml:4507 msgid "" "To make the mapping more flexible mapping and matching rules were added to " "SSSD (see <citerefentry> <refentrytitle>sss-certmap</refentrytitle> " @@ -5094,7 +5369,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4311 +#: sssd.conf.5.xml:4516 msgid "" "A mapping and matching rule can be added to the SSSD configuration in a " "section on its own with a name like <quote>[certmap/" @@ -5103,55 +5378,50 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4318 +#: sssd.conf.5.xml:4523 msgid "matchrule (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4321 +#: sssd.conf.5.xml:4526 msgid "" "Only certificates from the Smartcard which matches this rule will be " "processed, all others are ignored." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4325 +#: sssd.conf.5.xml:4530 msgid "" "Default: KRB5:<EKU>clientAuth, i.e. only certificates which have the " "Extended Key Usage <quote>clientAuth</quote>" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4332 +#: sssd.conf.5.xml:4537 msgid "maprule (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4335 +#: sssd.conf.5.xml:4540 msgid "Defines how the user is found for a given certificate." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:4341 +#: sssd.conf.5.xml:4546 msgid "" "LDAP:(userCertificate;binary={cert!bin}) for LDAP based providers like " "<quote>ldap</quote>, <quote>AD</quote> or <quote>ipa</quote>." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:4347 +#: sssd.conf.5.xml:4552 msgid "" "If maprule is not set and provider is <quote>proxy</quote>, the RULE_NAME " "name is assumed to be the name of the matching user." msgstr "" -#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4357 -msgid "domains (string)" -msgstr "" - #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4360 +#: sssd.conf.5.xml:4565 msgid "" "Comma separated list of domain names the rule should be applied. By default " "a rule is only valid in the domain configured in sssd.conf. If the provider " @@ -5160,17 +5430,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4367 +#: sssd.conf.5.xml:4572 msgid "Default: the configured domain in sssd.conf" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4372 +#: sssd.conf.5.xml:4577 msgid "priority (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4375 +#: sssd.conf.5.xml:4580 msgid "" "Unsigned integer value defining the priority of the rule. The higher the " "number the lower the priority. <quote>0</quote> stands for the highest " @@ -5178,17 +5448,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4381 +#: sssd.conf.5.xml:4586 msgid "Default: the lowest priority" msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:4389 +#: sssd.conf.5.xml:4594 msgid "PROMPTING CONFIGURATION SECTION" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4391 +#: sssd.conf.5.xml:4596 msgid "" "If a special file (<filename>/var/lib/sss/pubconf/pam_preauth_available</" "filename>) exists SSSD's PAM module pam_sss will ask SSSD to figure out " @@ -5198,7 +5468,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4399 +#: sssd.conf.5.xml:4604 msgid "" "With the growing number of authentication methods and the possibility that " "there are multiple ones for a single user the heuristic used by pam_sss to " @@ -5207,59 +5477,59 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4411 +#: sssd.conf.5.xml:4616 msgid "[prompting/password]" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4414 +#: sssd.conf.5.xml:4619 msgid "password_prompt" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4415 +#: sssd.conf.5.xml:4620 msgid "to change the string of the password prompt" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4413 +#: sssd.conf.5.xml:4618 msgid "" "to configure password prompting, allowed options are: <placeholder " "type=\"variablelist\" id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4423 +#: sssd.conf.5.xml:4628 msgid "[prompting/2fa]" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4427 +#: sssd.conf.5.xml:4632 msgid "first_prompt" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4428 +#: sssd.conf.5.xml:4633 msgid "to change the string of the prompt for the first factor" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4431 +#: sssd.conf.5.xml:4636 msgid "second_prompt" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4432 +#: sssd.conf.5.xml:4637 msgid "to change the string of the prompt for the second factor" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4435 +#: sssd.conf.5.xml:4640 msgid "single_prompt" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4436 +#: sssd.conf.5.xml:4641 msgid "" "boolean value, if True there will be only a single prompt using the value of " "first_prompt where it is expected that both factors are entered as a single " @@ -5268,7 +5538,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4425 +#: sssd.conf.5.xml:4630 msgid "" "to configure two-factor authentication prompting, allowed options are: " "<placeholder type=\"variablelist\" id=\"0\"/> If the second factor is " @@ -5277,7 +5547,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4449 +#: sssd.conf.5.xml:4654 msgid "" "Some clients, such as SSH with 'PasswordAuthentication yes', generate their " "own prompts and do not use prompts provided by SSSD or other PAM modules. " @@ -5288,17 +5558,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4464 +#: sssd.conf.5.xml:4669 msgid "[prompting/passkey]" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:4470 sssd-ad.5.xml:1022 +#: sssd.conf.5.xml:4675 sssd.conf.5.xml:4719 sssd-ad.5.xml:1027 msgid "interactive" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4472 +#: sssd.conf.5.xml:4677 msgid "" "boolean value, if True prompt a message and wait before testing the presence " "of a passkey device. Recommended if your device doesn’t have a tactile " @@ -5306,55 +5576,131 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4480 +#: sssd.conf.5.xml:4685 sssd.conf.5.xml:4735 msgid "interactive_prompt" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4482 +#: sssd.conf.5.xml:4687 sssd.conf.5.xml:4737 msgid "to change the message of the interactive prompt." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4487 +#: sssd.conf.5.xml:4692 msgid "touch" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4489 +#: sssd.conf.5.xml:4694 msgid "" "boolean value, if True prompt a message to remind the user to touch the " "device." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4495 +#: sssd.conf.5.xml:4700 msgid "touch_prompt" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4497 +#: sssd.conf.5.xml:4702 msgid "to change the message of the touch prompt." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4466 +#: sssd.conf.5.xml:4671 msgid "" "to configure passkey authentication prompting, allowed options are: " "<placeholder type=\"variablelist\" id=\"0\"/>" msgstr "" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4713 +msgid "[prompting/oauth2]" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4721 +msgid "" +"boolean value, if True prompt a message after asking the user to " +"authenticate, and wait before requesting the access token." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4725 +msgid "" +"If False, make sure to set the <quote>idp_request_timeout</quote> " +"sufficiently high, to give the user time to authenticate." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4715 +msgid "" +"to configure OAuth2 authentication prompting, allowed options are: " +"<placeholder type=\"variablelist\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4748 +msgid "[prompting/cert_auth]" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4754 +msgid "pin_prompt" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4756 +msgid "" +"to change the message which asks the user to enter the PIN at the computer " +"keyboard. At the end of the message the token name is printed." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4764 +msgid "keypad_prompt" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4766 +msgid "" +"to change the message which asks the user to enter the PIN at keypad of the " +"Smartcard reader. At the end of the message the token name is printed." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4774 +msgid "user_name_hint" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4776 +msgid "" +"boolean value, if True ask for a user name if no name was given before and " +"the found certificate can be mapped to more than one user." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4750 +msgid "" +"to configure Smartcard authentication prompting, allowed options are: " +"<placeholder type=\"variablelist\" id=\"0\"/>" +msgstr "" + #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4406 +#: sssd.conf.5.xml:4611 msgid "" "Each supported authentication method has its own configuration subsection " "under <quote>[prompting/...]</quote>. Currently there are: <placeholder " "type=\"variablelist\" id=\"0\"/> <placeholder type=\"variablelist\" id=\"1\"/" -"> <placeholder type=\"variablelist\" id=\"2\"/>" +"> <placeholder type=\"variablelist\" id=\"2\"/> <placeholder " +"type=\"variablelist\" id=\"3\"/> <placeholder type=\"variablelist\" id=\"4\"/" +">" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4508 +#: sssd.conf.5.xml:4792 msgid "" "It is possible to add a subsection for specific PAM services, e.g. " "<quote>[prompting/password/sshd]</quote> to individual change the prompting " @@ -5362,12 +5708,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:4515 pam_sss_gss.8.xml:157 idmap_sss.8.xml:43 +#: sssd.conf.5.xml:4799 pam_sss_gss.8.xml:157 idmap_sss.8.xml:43 msgid "EXAMPLES" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd.conf.5.xml:4521 +#: sssd.conf.5.xml:4805 #, no-wrap msgid "" "[sssd]\n" @@ -5396,7 +5742,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4517 +#: sssd.conf.5.xml:4801 msgid "" "1. The following example shows a typical SSSD config. It does not describe " "configuration of the domains themselves - refer to documentation on " @@ -5405,7 +5751,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd.conf.5.xml:4553 +#: sssd.conf.5.xml:4837 #, no-wrap msgid "" "[domain/ipa.com/child.ad.com]\n" @@ -5413,7 +5759,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4547 +#: sssd.conf.5.xml:4831 msgid "" "2. The following example shows configuration of IPA AD trust where the AD " "forest consists of two domains in a parent-child structure. Suppose IPA " @@ -5424,7 +5770,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd.conf.5.xml:4564 +#: sssd.conf.5.xml:4848 #, no-wrap msgid "" "[certmap/my.domain/rule_name]\n" @@ -5435,7 +5781,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4558 +#: sssd.conf.5.xml:4842 msgid "" "3. The following example shows the configuration of a certificate mapping " "rule. It is valid for the configured domain <quote>my.domain</quote> and " @@ -5632,7 +5978,7 @@ msgid "" "defaultNamingContext does not exist or has an empty value namingContexts is " "used. The namingContexts attribute must have a single value with the DN of " "the search base of the LDAP server to make this work. Multiple values are " -"are not supported." +"not supported." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> @@ -5937,15 +6283,15 @@ msgid "Optional. Use the given string as search base for host objects." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap.5.xml:472 sssd-ipa.5.xml:506 sssd-ipa.5.xml:525 sssd-ipa.5.xml:544 -#: sssd-ipa.5.xml:563 +#: sssd-ldap.5.xml:472 sssd-ipa.5.xml:501 sssd-ipa.5.xml:520 sssd-ipa.5.xml:539 +#: sssd-ipa.5.xml:558 msgid "" "See <quote>ldap_search_base</quote> for information about configuring " "multiple search bases." msgstr "" #. type: Content of: <listitem><para> -#: sssd-ldap.5.xml:477 sssd-ipa.5.xml:511 include/ldap_search_bases.xml:27 +#: sssd-ldap.5.xml:477 sssd-ipa.5.xml:506 include/ldap_search_bases.xml:27 msgid "Default: the value of <emphasis>ldap_search_base</emphasis>" msgstr "" @@ -6071,7 +6417,7 @@ msgid "" "closed early to ensure that a new query cannot require the connection to " "remain open past its expiration. This implies that connections will always " "be closed immediately and will never be reused if " -"<emphasis>ldap_connection_expire_timeout <= ldap_opt_timout</emphasis>" +"<emphasis>ldap_connection_expire_timeout <= ldap_opt_timeout</emphasis>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> @@ -6255,7 +6601,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:831 -msgid "ldap_ignore_unreadable_references (bool)" +msgid "ldap_ignore_unreadable_references (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> @@ -6580,7 +6926,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap.5.xml:1152 sssd-ad.5.xml:1267 +#: sssd-ldap.5.xml:1152 sssd-ad.5.xml:1260 msgid "Default: 86400 (24 hours)" msgstr "" @@ -6618,7 +6964,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ldap.5.xml:1187 sssd-ipa.5.xml:575 sssd-krb5.5.xml:103 +#: sssd-ldap.5.xml:1187 sssd-ipa.5.xml:570 sssd-krb5.5.xml:103 msgid "krb5_realm (string)" msgstr "" @@ -6774,8 +7120,10 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1339 -msgid "ldap_chpass_update_last_change (bool)" -msgstr "" +#, fuzzy +#| msgid "re_expression (string)" +msgid "ldap_chpass_update_last_change (boolean)" +msgstr "re_expression (tekst)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1342 @@ -6921,7 +7269,7 @@ msgid "ldap_access_order (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap.5.xml:1470 sssd-ipa.5.xml:405 +#: sssd-ldap.5.xml:1470 sssd-ipa.5.xml:400 msgid "Comma separated list of access control options. Allowed values are:" msgstr "" @@ -6966,7 +7314,7 @@ msgid "<emphasis>expire</emphasis>: use ldap_account_expire_policy" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap.5.xml:1515 sssd-ipa.5.xml:413 +#: sssd-ldap.5.xml:1515 sssd-ipa.5.xml:408 msgid "" "<emphasis>pwd_expire_policy_reject, pwd_expire_policy_warn, " "pwd_expire_policy_renew: </emphasis> These options are useful if users are " @@ -6976,24 +7324,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap.5.xml:1525 sssd-ipa.5.xml:423 +#: sssd-ldap.5.xml:1525 sssd-ipa.5.xml:418 msgid "" "The difference between these options is the action taken if user password is " "expired:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ldap.5.xml:1530 sssd-ipa.5.xml:428 +#: sssd-ldap.5.xml:1530 sssd-ipa.5.xml:423 msgid "pwd_expire_policy_reject - user is denied to log in," msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ldap.5.xml:1536 sssd-ipa.5.xml:434 +#: sssd-ldap.5.xml:1536 sssd-ipa.5.xml:429 msgid "pwd_expire_policy_warn - user is still able to log in," msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ldap.5.xml:1542 sssd-ipa.5.xml:440 +#: sssd-ldap.5.xml:1542 sssd-ipa.5.xml:435 msgid "" "pwd_expire_policy_renew - user is prompted to change their password " "immediately." @@ -7534,8 +7882,8 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd-ldap.5.xml:2032 sssd-simple.5.xml:169 sssd-ipa.5.xml:984 -#: sssd-ad.5.xml:1470 sssd-idp.5.xml:248 sssd-krb5.5.xml:483 +#: sssd-ldap.5.xml:2032 sssd-simple.5.xml:169 sssd-ipa.5.xml:979 +#: sssd-ad.5.xml:1463 sssd-idp.5.xml:343 sssd-krb5.5.xml:483 #: sss_rpcidmapd.5.xml:98 sssd-session-recording.5.xml:176 msgid "EXAMPLE" msgstr "" @@ -7563,7 +7911,7 @@ msgstr "" #. type: Content of: <refsect1><refsect2><para> #: sssd-ldap.5.xml:2039 sssd-ldap.5.xml:2057 sssd-simple.5.xml:177 -#: sssd-ipa.5.xml:992 sssd-ad.5.xml:1478 sssd-sudo.5.xml:56 sssd-krb5.5.xml:492 +#: sssd-ipa.5.xml:987 sssd-ad.5.xml:1471 sssd-sudo.5.xml:56 sssd-krb5.5.xml:492 #: sssd-session-recording.5.xml:182 include/ldap_id_mapping.xml:105 msgid "<placeholder type=\"programlisting\" id=\"0\"/>" msgstr "" @@ -7598,7 +7946,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><title> #: sssd-ldap.5.xml:2073 sssd_krb5_locator_plugin.8.xml:83 sssd-simple.5.xml:189 -#: sssd-ad.5.xml:1493 sssd.8.xml:270 sss_seed.8.xml:163 +#: sssd-ad.5.xml:1486 sssd.8.xml:270 sss_seed.8.xml:163 msgid "NOTES" msgstr "" @@ -8105,7 +8453,7 @@ msgstr "" #: pam_sss.8.xml:434 msgid "" "No authentication method was found by Kerberos. This might happen if the " -"user has a Smartcard assigned but the pkint plugin is not available on the " +"user has a Smartcard assigned but the pkinit plugin is not available on the " "client." msgstr "" @@ -8537,6 +8885,23 @@ msgid "" "first DNS resolving failure." msgstr "" +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_locator_plugin.8.xml:106 +msgid "" +"If the environment variable SSSD_KRB5_LOCATOR_KDC_ADDRESS is set to a KDC " +"address the plugin will use this address instead of reading the kdcinfo " +"file. The address format is the same as in the kdcinfo file (see above)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_locator_plugin.8.xml:112 +msgid "" +"If the environment variable SSSD_KRB5_LOCATOR_KPASSWD_ADDRESS is set to a " +"kpasswd server address the plugin will use this address instead of reading " +"the kpasswdinfo file. The address format is the same as in the kpasswdinfo " +"file (see above)." +msgstr "" + #. type: Content of: <reference><refentry><refnamediv><refname> #: sssd-simple.5.xml:10 sssd-simple.5.xml:16 msgid "sssd-simple" @@ -9920,7 +10285,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:129 sssd-ad.5.xml:1161 +#: sssd-ipa.5.xml:129 sssd-ad.5.xml:1166 msgid "dyndns_update (boolean)" msgstr "" @@ -9934,20 +10299,13 @@ msgid "" "quote> option." msgstr "" -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:141 sssd-ad.5.xml:1175 -msgid "" -"NOTE: On older systems (such as RHEL 5), for this behavior to work reliably, " -"the default Kerberos realm must be set properly in /etc/krb5.conf" -msgstr "" - #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:152 sssd-ad.5.xml:1186 +#: sssd-ipa.5.xml:147 sssd-ad.5.xml:1186 msgid "dyndns_ttl (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:155 sssd-ad.5.xml:1189 +#: sssd-ipa.5.xml:150 sssd-ad.5.xml:1189 msgid "" "The TTL to apply to the client DNS record when updating it. If " "dyndns_update is false this has no effect. This will override the TTL " @@ -9955,17 +10313,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:160 +#: sssd-ipa.5.xml:155 msgid "Default: 1200 (seconds)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:166 sssd-ad.5.xml:1200 +#: sssd-ipa.5.xml:161 sssd-ad.5.xml:1200 msgid "dyndns_iface (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:169 sssd-ad.5.xml:1203 +#: sssd-ipa.5.xml:164 sssd-ad.5.xml:1203 msgid "" "Optional. Applicable only when dyndns_update is true. Choose the interface " "or a list of interfaces whose IP addresses should be used for dynamic DNS " @@ -9977,26 +10335,26 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:182 +#: sssd-ipa.5.xml:177 msgid "" "Default: Use the IP addresses of the interface which is used for IPA LDAP " "connection" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:186 sssd-ad.5.xml:1226 +#: sssd-ipa.5.xml:181 sssd-ad.5.xml:1220 msgid "Example: dyndns_iface = em[12], !vnet1, vnet*" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:192 sssd-ad.5.xml:1232 +#: sssd-ipa.5.xml:187 sssd-ad.5.xml:1226 #, fuzzy #| msgid "re_expression (string)" msgid "dyndns_address (string)" msgstr "re_expression (tekst)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:195 sssd-ad.5.xml:1235 +#: sssd-ipa.5.xml:190 sssd-ad.5.xml:1229 msgid "" "Optional. Applicable only when <emphasis>dyndns_update</emphasis> is true. " "A list of IP addresses or IP networks to be used for dynamic DNS updates. " @@ -10007,22 +10365,22 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:206 sssd-ad.5.xml:1246 +#: sssd-ipa.5.xml:201 sssd-ad.5.xml:1240 msgid "Default: No filtering of IP addresses." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:209 sssd-ad.5.xml:1249 +#: sssd-ipa.5.xml:204 sssd-ad.5.xml:1243 msgid "Example: dyndns_address = 10.0.0.0/16, !10.0.1.0/24" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:215 sssd-ad.5.xml:1305 +#: sssd-ipa.5.xml:210 sssd-ad.5.xml:1298 msgid "dyndns_auth (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:218 sssd-ad.5.xml:1308 +#: sssd-ipa.5.xml:213 sssd-ad.5.xml:1301 msgid "" "Whether the nsupdate utility should use GSS-TSIG authentication for secure " "updates with the DNS server, insecure updates can be sent by setting this " @@ -10030,17 +10388,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:224 sssd-ad.5.xml:1314 +#: sssd-ipa.5.xml:219 sssd-ad.5.xml:1307 msgid "Default: GSS-TSIG" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:230 sssd-ad.5.xml:1320 +#: sssd-ipa.5.xml:225 sssd-ad.5.xml:1313 msgid "dyndns_auth_ptr (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:233 sssd-ad.5.xml:1323 +#: sssd-ipa.5.xml:228 sssd-ad.5.xml:1316 msgid "" "Whether the nsupdate utility should use GSS-TSIG authentication for secure " "PTR updates with the DNS server, insecure updates can be sent by setting " @@ -10048,17 +10406,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:239 sssd-ad.5.xml:1329 +#: sssd-ipa.5.xml:234 sssd-ad.5.xml:1322 msgid "Default: Same as dyndns_auth" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:245 sssd-ad.5.xml:1255 +#: sssd-ipa.5.xml:240 sssd-ad.5.xml:1249 msgid "dyndns_refresh_interval (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:248 +#: sssd-ipa.5.xml:243 msgid "" "How often should the back end perform periodic DNS update in addition to the " "automatic update performed when the back end goes online. This option is " @@ -10066,74 +10424,76 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:261 sssd-ad.5.xml:1273 -msgid "dyndns_update_ptr (bool)" -msgstr "" +#: sssd-ipa.5.xml:256 sssd-ad.5.xml:1266 +#, fuzzy +#| msgid "re_expression (string)" +msgid "dyndns_update_ptr (boolean)" +msgstr "re_expression (tekst)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:264 sssd-ad.5.xml:1276 +#: sssd-ipa.5.xml:259 sssd-ad.5.xml:1269 msgid "" "Whether the PTR record should also be explicitly updated when updating the " "client's DNS records. Applicable only when dyndns_update is true." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:269 +#: sssd-ipa.5.xml:264 msgid "" "This option should be False in most IPA deployments as the IPA server " "generates the PTR records automatically when forward records are changed." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:275 sssd-ad.5.xml:1281 +#: sssd-ipa.5.xml:270 sssd-ad.5.xml:1274 msgid "" "Note that <emphasis>dyndns_update_per_family</emphasis> parameter does not " "apply for PTR record updates. Those updates are always sent separately." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:280 +#: sssd-ipa.5.xml:275 msgid "Default: False (disabled)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:286 sssd-ad.5.xml:1292 -msgid "dyndns_force_tcp (bool)" +#: sssd-ipa.5.xml:281 sssd-ad.5.xml:1285 +msgid "dyndns_force_tcp (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:289 sssd-ad.5.xml:1295 +#: sssd-ipa.5.xml:284 sssd-ad.5.xml:1288 msgid "" "Whether the nsupdate utility should default to using TCP for communicating " "with the DNS server." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:293 sssd-ad.5.xml:1299 +#: sssd-ipa.5.xml:288 sssd-ad.5.xml:1292 msgid "Default: False (let nsupdate choose the protocol)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:299 sssd-ad.5.xml:1335 +#: sssd-ipa.5.xml:294 sssd-ad.5.xml:1328 msgid "dyndns_server (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:302 sssd-ad.5.xml:1338 +#: sssd-ipa.5.xml:297 sssd-ad.5.xml:1331 msgid "" "The DNS server to use when performing a DNS update. In most setups, it's " "recommended to leave this option unset." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:307 sssd-ad.5.xml:1343 +#: sssd-ipa.5.xml:302 sssd-ad.5.xml:1336 msgid "" "Setting this option makes sense for environments where the DNS server is " "different from the identity server or when we use encrypted DNS." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:312 sssd-ad.5.xml:1348 +#: sssd-ipa.5.xml:307 sssd-ad.5.xml:1341 msgid "" "The parameter can be a simple string containing DNS name or IP address. It " "can also be an URI. The URI can look like <emphasis>dns://servername/</" @@ -10141,7 +10501,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:319 sssd-ad.5.xml:1355 +#: sssd-ipa.5.xml:314 sssd-ad.5.xml:1348 msgid "" "The second example enables DNS-over-TLS protocol for DNS updates. The " "nsupdate utility must support DoT - check the <emphasis>man nsupdate</" @@ -10149,7 +10509,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:325 sssd-ad.5.xml:1361 +#: sssd-ipa.5.xml:320 sssd-ad.5.xml:1354 msgid "" "Please note that this option will be only used in fallback attempt when " "previous attempt using autodetected settings failed or when DNS-over-TLS is " @@ -10157,17 +10517,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:331 sssd-ad.5.xml:1367 +#: sssd-ipa.5.xml:326 sssd-ad.5.xml:1360 msgid "Default: None (let nsupdate choose the server)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:337 sssd-ad.5.xml:1373 +#: sssd-ipa.5.xml:332 sssd-ad.5.xml:1366 msgid "dyndns_update_per_family (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:340 sssd-ad.5.xml:1376 +#: sssd-ipa.5.xml:335 sssd-ad.5.xml:1369 msgid "" "DNS update is by default performed in two steps - IPv4 update and then IPv6 " "update. In some cases it might be desirable to perform IPv4 and IPv6 update " @@ -10175,12 +10535,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:352 sssd-ad.5.xml:1388 +#: sssd-ipa.5.xml:347 sssd-ad.5.xml:1381 msgid "dyndns_dot_cacert (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:355 sssd-ad.5.xml:1391 +#: sssd-ipa.5.xml:350 sssd-ad.5.xml:1384 msgid "" "This option specifies the file of the certificate authorities certificates " "(in PEM format) in order to verify the remote server TLS certificate when " @@ -10188,17 +10548,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:361 sssd-ad.5.xml:1397 +#: sssd-ipa.5.xml:356 sssd-ad.5.xml:1390 msgid "Default: None (use global certificate store)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:367 sssd-ad.5.xml:1403 +#: sssd-ipa.5.xml:362 sssd-ad.5.xml:1396 msgid "dyndns_dot_cert (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:370 sssd-ad.5.xml:1406 +#: sssd-ipa.5.xml:365 sssd-ad.5.xml:1399 msgid "" "This option sets the certificate(s) file for authentication for the DoT " "transport to the remote server. The certificate chain file is expected to be " @@ -10206,26 +10566,26 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:376 sssd-ad.5.xml:1412 +#: sssd-ipa.5.xml:371 sssd-ad.5.xml:1405 msgid "" "The <emphasis>dyndns_dot_cert</emphasis> and <emphasis>dyndns_dot_key</" "emphasis> options must be both set to achieve mutual TLS authentication." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:381 sssd-ipa.5.xml:396 sssd-ad.5.xml:1417 sssd-ad.5.xml:1432 +#: sssd-ipa.5.xml:376 sssd-ipa.5.xml:391 sssd-ad.5.xml:1410 sssd-ad.5.xml:1425 msgid "Default: None (Do not use TLS authentication)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:387 sssd-ad.5.xml:1423 +#: sssd-ipa.5.xml:382 sssd-ad.5.xml:1416 #, fuzzy #| msgid "re_expression (string)" msgid "dyndns_dot_key (string)" msgstr "re_expression (tekst)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:390 sssd-ad.5.xml:1426 +#: sssd-ipa.5.xml:385 sssd-ad.5.xml:1419 msgid "" "This option sets the key file for authenticated encryption for the DoT " "transport to the remote server. The private key file is expected to be in " @@ -10233,172 +10593,172 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:402 +#: sssd-ipa.5.xml:397 #, fuzzy #| msgid "re_expression (string)" msgid "ipa_access_order (string)" msgstr "re_expression (tekst)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:409 +#: sssd-ipa.5.xml:404 msgid "<emphasis>expire</emphasis>: use IPA's account expiration policy." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:448 +#: sssd-ipa.5.xml:443 msgid "" "Please note that 'access_provider = ipa' must be set for this feature to " "work." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:455 +#: sssd-ipa.5.xml:450 msgid "ipa_deskprofile_search_base (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:458 +#: sssd-ipa.5.xml:453 msgid "" "Optional. Use the given string as search base for Desktop Profile related " "objects." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:462 sssd-ipa.5.xml:484 +#: sssd-ipa.5.xml:457 sssd-ipa.5.xml:479 msgid "Default: Use base DN" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:468 +#: sssd-ipa.5.xml:463 msgid "ipa_subid_ranges_search_base (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:471 +#: sssd-ipa.5.xml:466 msgid "Deprecated. Use ldap_subid_ranges_search_base instead." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:477 +#: sssd-ipa.5.xml:472 msgid "ipa_hbac_search_base (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:480 +#: sssd-ipa.5.xml:475 msgid "Optional. Use the given string as search base for HBAC related objects." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:490 +#: sssd-ipa.5.xml:485 msgid "ipa_host_search_base (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:493 +#: sssd-ipa.5.xml:488 msgid "Deprecated. Use ldap_host_search_base instead." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:499 +#: sssd-ipa.5.xml:494 msgid "ipa_selinux_search_base (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:502 +#: sssd-ipa.5.xml:497 msgid "Optional. Use the given string as search base for SELinux user maps." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:518 +#: sssd-ipa.5.xml:513 msgid "ipa_subdomains_search_base (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:521 +#: sssd-ipa.5.xml:516 msgid "Optional. Use the given string as search base for trusted domains." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:530 +#: sssd-ipa.5.xml:525 msgid "Default: the value of <emphasis>cn=trusts,%basedn</emphasis>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:537 +#: sssd-ipa.5.xml:532 msgid "ipa_master_domain_search_base (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:540 +#: sssd-ipa.5.xml:535 msgid "Optional. Use the given string as search base for master domain object." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:549 +#: sssd-ipa.5.xml:544 msgid "Default: the value of <emphasis>cn=ad,cn=etc,%basedn</emphasis>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:556 +#: sssd-ipa.5.xml:551 msgid "ipa_views_search_base (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:559 +#: sssd-ipa.5.xml:554 msgid "Optional. Use the given string as search base for views containers." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:568 +#: sssd-ipa.5.xml:563 msgid "Default: the value of <emphasis>cn=views,cn=accounts,%basedn</emphasis>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:578 +#: sssd-ipa.5.xml:573 msgid "" "The name of the Kerberos realm. This is optional and defaults to the value " "of <quote>ipa_domain</quote>." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:582 +#: sssd-ipa.5.xml:577 msgid "" "The name of the Kerberos realm has a special meaning in IPA - it is " "converted into the base DN to use for performing LDAP operations." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:590 sssd-ad.5.xml:1441 +#: sssd-ipa.5.xml:585 sssd-ad.5.xml:1434 msgid "krb5_confd_path (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:593 sssd-ad.5.xml:1444 +#: sssd-ipa.5.xml:588 sssd-ad.5.xml:1437 msgid "" "Absolute path of a directory where SSSD should place Kerberos configuration " "snippets." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:597 sssd-ad.5.xml:1448 +#: sssd-ipa.5.xml:592 sssd-ad.5.xml:1441 msgid "" "To disable the creation of the configuration snippets set the parameter to " "'none'." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:601 sssd-ad.5.xml:1452 +#: sssd-ipa.5.xml:596 sssd-ad.5.xml:1445 msgid "" "Default: not set (krb5.include.d subdirectory of SSSD's pubconf directory)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:608 +#: sssd-ipa.5.xml:603 msgid "ipa_deskprofile_refresh (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:611 +#: sssd-ipa.5.xml:606 msgid "" "The amount of time between lookups of the Desktop Profile rules against the " "IPA server. This will reduce the latency and load on the IPA server if there " @@ -10406,34 +10766,34 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:618 sssd-ipa.5.xml:648 sssd-ipa.5.xml:664 sssd-ad.5.xml:600 +#: sssd-ipa.5.xml:613 sssd-ipa.5.xml:643 sssd-ipa.5.xml:659 sssd-ad.5.xml:600 msgid "Default: 5 (seconds)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:624 +#: sssd-ipa.5.xml:619 msgid "ipa_deskprofile_request_interval (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:627 +#: sssd-ipa.5.xml:622 msgid "" "The amount of time between lookups of the Desktop Profile rules against the " "IPA server in case the last request did not return any rule." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:632 +#: sssd-ipa.5.xml:627 msgid "Default: 60 (minutes)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:638 +#: sssd-ipa.5.xml:633 msgid "ipa_hbac_refresh (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:641 +#: sssd-ipa.5.xml:636 msgid "" "The amount of time between lookups of the HBAC rules against the IPA server. " "This will reduce the latency and load on the IPA server if there are many " @@ -10441,12 +10801,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:654 -msgid "ipa_hbac_selinux (integer)" -msgstr "" +#: sssd-ipa.5.xml:649 +#, fuzzy +#| msgid "reconnection_retries (integer)" +msgid "ipa_selinux_refresh (integer)" +msgstr "reconnection_retries (numeriek)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:657 +#: sssd-ipa.5.xml:652 msgid "" "The amount of time between lookups of the SELinux maps against the IPA " "server. This will reduce the latency and load on the IPA server if there are " @@ -10454,33 +10816,33 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:670 +#: sssd-ipa.5.xml:665 msgid "ipa_server_mode (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:673 +#: sssd-ipa.5.xml:668 msgid "" "This option will be set by the IPA installer (ipa-server-install) " "automatically and denotes if SSSD is running on an IPA server or not." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:678 +#: sssd-ipa.5.xml:673 msgid "" "On an IPA server SSSD will lookup users and groups from trusted domains " "directly while on a client it will ask an IPA server." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:683 +#: sssd-ipa.5.xml:678 msgid "" "NOTE: There are currently some assumptions that must be met when SSSD is " "running on an IPA server." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:688 +#: sssd-ipa.5.xml:683 msgid "" "The <quote>ipa_server</quote> option must be configured to point to the IPA " "server itself. This is already the default set by the IPA installer, so no " @@ -10488,59 +10850,59 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:697 +#: sssd-ipa.5.xml:692 msgid "" "The <quote>full_name_format</quote> option must not be tweaked to only print " "short names for users from trusted domains." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:712 +#: sssd-ipa.5.xml:707 msgid "ipa_automount_location (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:715 +#: sssd-ipa.5.xml:710 msgid "The automounter location this IPA client will be using" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:718 +#: sssd-ipa.5.xml:713 msgid "Default: The location named \"default\"" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd-ipa.5.xml:726 +#: sssd-ipa.5.xml:721 msgid "VIEWS AND OVERRIDES" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:735 +#: sssd-ipa.5.xml:730 msgid "ipa_view_class (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:738 +#: sssd-ipa.5.xml:733 msgid "Objectclass of the view container." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:741 +#: sssd-ipa.5.xml:736 msgid "Default: nsContainer" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:747 +#: sssd-ipa.5.xml:742 msgid "ipa_view_name (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:750 +#: sssd-ipa.5.xml:745 msgid "Name of the attribute holding the name of the view." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:754 sssd-ldap-attributes.5.xml:496 +#: sssd-ipa.5.xml:749 sssd-ldap-attributes.5.xml:496 #: sssd-ldap-attributes.5.xml:832 sssd-ldap-attributes.5.xml:913 #: sssd-ldap-attributes.5.xml:1010 sssd-ldap-attributes.5.xml:1068 #: sssd-ldap-attributes.5.xml:1226 sssd-ldap-attributes.5.xml:1271 @@ -10548,128 +10910,128 @@ msgid "Default: cn" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:760 +#: sssd-ipa.5.xml:755 msgid "ipa_override_object_class (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:763 +#: sssd-ipa.5.xml:758 msgid "Objectclass of the override objects." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:766 +#: sssd-ipa.5.xml:761 msgid "Default: ipaOverrideAnchor" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:772 +#: sssd-ipa.5.xml:767 msgid "ipa_anchor_uuid (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:775 +#: sssd-ipa.5.xml:770 msgid "" "Name of the attribute containing the reference to the original object in a " "remote domain." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:779 +#: sssd-ipa.5.xml:774 msgid "Default: ipaAnchorUUID" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:785 +#: sssd-ipa.5.xml:780 msgid "ipa_user_override_object_class (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:788 +#: sssd-ipa.5.xml:783 msgid "" "Name of the objectclass for user overrides. It is used to determine if the " "found override object is related to a user or a group." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:793 +#: sssd-ipa.5.xml:788 msgid "User overrides can contain attributes given by" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:796 +#: sssd-ipa.5.xml:791 msgid "ldap_user_name" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:799 +#: sssd-ipa.5.xml:794 msgid "ldap_user_uid_number" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:802 +#: sssd-ipa.5.xml:797 msgid "ldap_user_gid_number" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:805 +#: sssd-ipa.5.xml:800 msgid "ldap_user_gecos" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:808 +#: sssd-ipa.5.xml:803 msgid "ldap_user_home_directory" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:811 +#: sssd-ipa.5.xml:806 msgid "ldap_user_shell" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:814 +#: sssd-ipa.5.xml:809 msgid "ldap_user_ssh_public_key" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:819 +#: sssd-ipa.5.xml:814 msgid "Default: ipaUserOverride" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:825 +#: sssd-ipa.5.xml:820 msgid "ipa_group_override_object_class (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:828 +#: sssd-ipa.5.xml:823 msgid "" "Name of the objectclass for group overrides. It is used to determine if the " "found override object is related to a user or a group." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:833 +#: sssd-ipa.5.xml:828 msgid "Group overrides can contain attributes given by" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:836 +#: sssd-ipa.5.xml:831 msgid "ldap_group_name" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:839 +#: sssd-ipa.5.xml:834 msgid "ldap_group_gid_number" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:844 +#: sssd-ipa.5.xml:839 msgid "Default: ipaGroupOverride" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:728 +#: sssd-ipa.5.xml:723 msgid "" "SSSD can handle views and overrides which are offered by FreeIPA 4.1 and " "later version. Since all paths and objectclasses are fixed on the server " @@ -10679,19 +11041,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd-ipa.5.xml:856 +#: sssd-ipa.5.xml:851 msgid "SUBDOMAINS PROVIDER" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:858 +#: sssd-ipa.5.xml:853 msgid "" "The IPA subdomains provider behaves slightly differently if it is configured " "explicitly or implicitly." msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:862 +#: sssd-ipa.5.xml:857 msgid "" "If the option 'subdomains_provider = ipa' is found in the domain section of " "sssd.conf, the IPA subdomains provider is configured explicitly, and all " @@ -10699,7 +11061,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:868 +#: sssd-ipa.5.xml:863 msgid "" "If the option 'subdomains_provider' is not set in the domain section of " "sssd.conf but there is the option 'id_provider = ipa', the IPA subdomains " @@ -10711,12 +11073,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd-ipa.5.xml:879 +#: sssd-ipa.5.xml:874 msgid "TRUSTED DOMAINS CONFIGURATION" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-ipa.5.xml:887 +#: sssd-ipa.5.xml:882 #, no-wrap msgid "" "[domain/ipa.domain.com/ad.domain.com]\n" @@ -10724,7 +11086,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:881 +#: sssd-ipa.5.xml:876 msgid "" "Some configuration options can also be set for a trusted domain. A trusted " "domain configuration can be set using the trusted domain subsection as shown " @@ -10734,97 +11096,97 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:892 +#: sssd-ipa.5.xml:887 msgid "" "For more details, see the <citerefentry> <refentrytitle>sssd.conf</" "refentrytitle> <manvolnum>5</manvolnum> </citerefentry> manual page." msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:899 +#: sssd-ipa.5.xml:894 msgid "" "Different configuration options are tunable for a trusted domain depending " "on whether you are configuring SSSD on an IPA server or an IPA client." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd-ipa.5.xml:904 +#: sssd-ipa.5.xml:899 msgid "OPTIONS TUNABLE ON IPA MASTERS" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:906 +#: sssd-ipa.5.xml:901 msgid "" "The following options can be set in a subdomain section on an IPA master:" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:910 sssd-ipa.5.xml:950 +#: sssd-ipa.5.xml:905 sssd-ipa.5.xml:945 msgid "ad_server" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:913 +#: sssd-ipa.5.xml:908 msgid "ad_backup_server" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:916 sssd-ipa.5.xml:953 +#: sssd-ipa.5.xml:911 sssd-ipa.5.xml:948 msgid "ad_site" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:919 +#: sssd-ipa.5.xml:914 msgid "ipa_server" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:922 +#: sssd-ipa.5.xml:917 msgid "ipa_backup_server" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:925 +#: sssd-ipa.5.xml:920 msgid "ldap_search_base" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:928 +#: sssd-ipa.5.xml:923 msgid "ldap_user_search_base" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:931 +#: sssd-ipa.5.xml:926 msgid "ldap_group_search_base" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:939 +#: sssd-ipa.5.xml:934 msgid "" "Options prefixed with 'ad_' or 'ipa_' only apply to their respective " "subdomain type." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd-ipa.5.xml:944 +#: sssd-ipa.5.xml:939 msgid "OPTIONS TUNABLE ON IPA CLIENTS" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:946 +#: sssd-ipa.5.xml:941 msgid "" "The following options can be set in an AD subdomain section on an IPA client:" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:958 +#: sssd-ipa.5.xml:953 msgid "" "Note that if both options are set, only <quote>ad_server</quote> is " "evaluated." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:962 +#: sssd-ipa.5.xml:957 msgid "" "Since any request for a user or a group identity from a trusted domain " "triggered from an IPA client is resolved by the IPA server, the " @@ -10838,7 +11200,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:986 +#: sssd-ipa.5.xml:981 msgid "" "The following example assumes that SSSD is correctly configured and " "example.com is one of the domains in the <replaceable>[sssd]</replaceable> " @@ -10846,7 +11208,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-ipa.5.xml:993 +#: sssd-ipa.5.xml:988 #, no-wrap msgid "" "[domain/example.com]\n" @@ -11545,27 +11907,27 @@ msgid "lxdm" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:694 +#: sssd-ad.5.xml:699 msgid "sddm" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:699 +#: sssd-ad.5.xml:704 msgid "unity" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:704 +#: sssd-ad.5.xml:709 msgid "xdm" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:713 +#: sssd-ad.5.xml:718 msgid "ad_gpo_map_remote_interactive (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:716 +#: sssd-ad.5.xml:721 msgid "" "A comma-separated list of PAM service names for which GPO-based access " "control is evaluated based on the RemoteInteractiveLogonRight and " @@ -11581,7 +11943,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:735 +#: sssd-ad.5.xml:740 msgid "" "Note: Using the Group Policy Management Editor this value is called \"Allow " "log on through Remote Desktop Services\" and \"Deny log on through Remote " @@ -11589,7 +11951,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:750 +#: sssd-ad.5.xml:755 #, no-wrap msgid "" "ad_gpo_map_remote_interactive = +my_pam_service, -sshd\n" @@ -11597,7 +11959,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:741 +#: sssd-ad.5.xml:746 msgid "" "It is possible to add another PAM service name to the default set by using " "<quote>+service_name</quote> or to explicitly remove a PAM service name from " @@ -11609,22 +11971,22 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:758 +#: sssd-ad.5.xml:763 msgid "sshd" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:763 +#: sssd-ad.5.xml:768 msgid "cockpit" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:772 +#: sssd-ad.5.xml:777 msgid "ad_gpo_map_network (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:775 +#: sssd-ad.5.xml:780 msgid "" "A comma-separated list of PAM service names for which GPO-based access " "control is evaluated based on the NetworkLogonRight and " @@ -11640,7 +12002,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:793 +#: sssd-ad.5.xml:798 msgid "" "Note: Using the Group Policy Management Editor this value is called \"Access " "this computer from the network\" and \"Deny access to this computer from the " @@ -11648,7 +12010,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:808 +#: sssd-ad.5.xml:813 #, no-wrap msgid "" "ad_gpo_map_network = +my_pam_service, -ftp\n" @@ -11656,7 +12018,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:799 +#: sssd-ad.5.xml:804 msgid "" "It is possible to add another PAM service name to the default set by using " "<quote>+service_name</quote> or to explicitly remove a PAM service name from " @@ -11668,22 +12030,22 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:816 +#: sssd-ad.5.xml:821 msgid "ftp" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:821 +#: sssd-ad.5.xml:826 msgid "samba" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:830 +#: sssd-ad.5.xml:835 msgid "ad_gpo_map_batch (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:833 +#: sssd-ad.5.xml:838 msgid "" "A comma-separated list of PAM service names for which GPO-based access " "control is evaluated based on the BatchLogonRight and DenyBatchLogonRight " @@ -11698,14 +12060,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:851 +#: sssd-ad.5.xml:856 msgid "" "Note: Using the Group Policy Management Editor this value is called \"Allow " "log on as a batch job\" and \"Deny log on as a batch job\"." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:865 +#: sssd-ad.5.xml:870 #, no-wrap msgid "" "ad_gpo_map_batch = +my_pam_service, -crond\n" @@ -11713,7 +12075,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:856 +#: sssd-ad.5.xml:861 msgid "" "It is possible to add another PAM service name to the default set by using " "<quote>+service_name</quote> or to explicitly remove a PAM service name from " @@ -11725,23 +12087,23 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:868 +#: sssd-ad.5.xml:873 msgid "" "Note: Cron service name may differ depending on Linux distribution used." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:874 +#: sssd-ad.5.xml:879 msgid "crond" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:883 +#: sssd-ad.5.xml:888 msgid "ad_gpo_map_service (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:886 +#: sssd-ad.5.xml:891 msgid "" "A comma-separated list of PAM service names for which GPO-based access " "control is evaluated based on the ServiceLogonRight and " @@ -11757,14 +12119,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:904 +#: sssd-ad.5.xml:909 msgid "" "Note: Using the Group Policy Management Editor this value is called \"Allow " "log on as a service\" and \"Deny log on as a service\"." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:917 +#: sssd-ad.5.xml:922 #, no-wrap msgid "" "ad_gpo_map_service = +my_pam_service\n" @@ -11772,7 +12134,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:909 sssd-ad.5.xml:984 +#: sssd-ad.5.xml:914 sssd-ad.5.xml:989 msgid "" "It is possible to add a PAM service name to the default set by using " "<quote>+service_name</quote>. Since the default set is empty, it is not " @@ -11783,19 +12145,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:927 +#: sssd-ad.5.xml:932 msgid "ad_gpo_map_permit (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:930 +#: sssd-ad.5.xml:935 msgid "" "A comma-separated list of PAM service names for which GPO-based access is " "always granted, regardless of any GPO Logon Rights." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:944 +#: sssd-ad.5.xml:949 #, no-wrap msgid "" "ad_gpo_map_permit = +my_pam_service, -sudo\n" @@ -11803,7 +12165,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:935 +#: sssd-ad.5.xml:940 msgid "" "It is possible to add another PAM service name to the default set by using " "<quote>+service_name</quote> or to explicitly remove a PAM service name from " @@ -11815,29 +12177,29 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:952 +#: sssd-ad.5.xml:957 msgid "polkit-1" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:967 +#: sssd-ad.5.xml:972 msgid "systemd-user" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:976 +#: sssd-ad.5.xml:981 msgid "ad_gpo_map_deny (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:979 +#: sssd-ad.5.xml:984 msgid "" "A comma-separated list of PAM service names for which GPO-based access is " "always denied, regardless of any GPO Logon Rights." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:992 +#: sssd-ad.5.xml:997 #, no-wrap msgid "" "ad_gpo_map_deny = +my_pam_service\n" @@ -11845,12 +12207,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:1002 +#: sssd-ad.5.xml:1007 msgid "ad_gpo_default_right (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1005 +#: sssd-ad.5.xml:1010 msgid "" "This option defines how access control is evaluated for PAM service names " "that are not explicitly listed in one of the ad_gpo_map_* options. This " @@ -11863,52 +12225,52 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1018 +#: sssd-ad.5.xml:1023 msgid "Supported values for this option include:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1027 +#: sssd-ad.5.xml:1032 msgid "remote_interactive" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1032 +#: sssd-ad.5.xml:1037 msgid "network" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1037 +#: sssd-ad.5.xml:1042 msgid "batch" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1042 +#: sssd-ad.5.xml:1047 msgid "service" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1047 +#: sssd-ad.5.xml:1052 msgid "permit" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1052 +#: sssd-ad.5.xml:1057 msgid "deny" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1058 +#: sssd-ad.5.xml:1063 msgid "Default: deny" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:1064 +#: sssd-ad.5.xml:1069 msgid "ad_maximum_machine_account_password_age (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1067 +#: sssd-ad.5.xml:1072 msgid "" "SSSD will check once a day if the machine account password is older than the " "given age in days and try to renew it. A value of 0 will disable the renewal " @@ -11916,17 +12278,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1073 +#: sssd-ad.5.xml:1078 msgid "Default: 30 days" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:1079 +#: sssd-ad.5.xml:1084 msgid "ad_machine_account_password_renewal_opts (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1082 +#: sssd-ad.5.xml:1087 msgid "" "This option should only be used to test the machine account renewal task. " "The option expects 3 integers and a string separated by a colon (':'). The " @@ -11939,20 +12301,20 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1096 +#: sssd-ad.5.xml:1101 msgid "" "The optional fourth string value identifies the helper binary which should " "be used for the renewal. Currently <command>adcli</command> and " "<command>realm</command> are supported. If this value is missing or empty in " "the value string <command>realm</command> will be used. Since the helper is " "started as the user SSSD is running as there might be the chance that the " -"renewal will fail if this user does not has permissions to modify the keytab " -"file where the machine account credentials are stored. This will typically " -"be the case for <command>adcli</command>." +"renewal will fail if this user does not have permissions to modify the " +"keytab file where the machine account credentials are stored. This will " +"typically be the case for <command>adcli</command>." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1110 +#: sssd-ad.5.xml:1115 msgid "" "<command>realm</command> is not updating the keytab directly but is calling " "the <command>realmd</command> process, which runs as root user, for this " @@ -11962,17 +12324,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1119 +#: sssd-ad.5.xml:1124 msgid "Default: 86400:750:300:realm (24h, 12m30s and 5m)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:1125 +#: sssd-ad.5.xml:1130 msgid "ad_update_samba_machine_account_password (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1128 +#: sssd-ad.5.xml:1133 msgid "" "If enabled, when SSSD renews the machine account password, it will also be " "updated in Samba's database. This prevents Samba's copy of the machine " @@ -11981,23 +12343,25 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:1141 -msgid "ad_use_ldaps (bool)" -msgstr "" +#: sssd-ad.5.xml:1146 +#, fuzzy +#| msgid "re_expression (string)" +msgid "ad_use_ldaps (boolean)" +msgstr "re_expression (tekst)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1144 +#: sssd-ad.5.xml:1149 msgid "" "By default SSSD uses the plain LDAP port 389 and the Global Catalog port " -"3628. If this option is set to True SSSD will use the LDAPS port 636 and " -"Global Catalog port 3629 with LDAPS protection. Since AD does not allow to " +"3268. If this option is set to True SSSD will use the LDAPS port 636 and " +"Global Catalog port 3269 with LDAPS protection. Since AD does not allow to " "have multiple encryption layers on a single connection and we still want to " "use SASL/GSSAPI or SASL/GSS-SPNEGO for authentication the SASL security " "property maxssf is set to 0 (zero) for those connections." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1164 +#: sssd-ad.5.xml:1169 msgid "" "Optional. This option tells SSSD to automatically update the Active " "Directory DNS server with the IP address of this client. The update is " @@ -12015,30 +12379,21 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:1216 msgid "" -"NOTE: While it is still possible to use the old <emphasis>ipa_dyndns_iface</" -"emphasis> option, users should migrate to using <emphasis>dyndns_iface</" -"emphasis> in their config file." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1222 -msgid "" "Default: Use the IP addresses of the interface which is used for AD LDAP " "connection" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1258 +#: sssd-ad.5.xml:1252 msgid "" "How often should the back end perform periodic DNS update in addition to the " -"automatic update performed when the back end goes online. This option is " -"optional and applicable only when dyndns_update is true. Note that the " -"lowest possible value is 60 seconds in-case if value is provided less than " -"60, parameter will assume lowest value only." +"automatic update performed when the back end goes online. This is optional " +"and applicable only when dyndns_update is true. Note that the minimum value " +"is 60 seconds, any specified value below this threshold will default to 60." msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ad.5.xml:1472 +#: sssd-ad.5.xml:1465 msgid "" "The following example assumes that SSSD is correctly configured and " "example.com is one of the domains in the <replaceable>[sssd]</replaceable> " @@ -12046,7 +12401,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-ad.5.xml:1479 +#: sssd-ad.5.xml:1472 #, no-wrap msgid "" "[domain/EXAMPLE]\n" @@ -12061,7 +12416,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-ad.5.xml:1499 +#: sssd-ad.5.xml:1492 #, no-wrap msgid "" "access_provider = ldap\n" @@ -12070,7 +12425,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ad.5.xml:1495 +#: sssd-ad.5.xml:1488 msgid "" "The AD access control provider checks if the account is expired. It has the " "same effect as the following configuration of the LDAP provider: " @@ -12078,7 +12433,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ad.5.xml:1505 +#: sssd-ad.5.xml:1498 msgid "" "However, unless the <quote>ad</quote> access control provider is explicitly " "configured, the default access provider is <quote>permit</quote>. Please " @@ -12088,7 +12443,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ad.5.xml:1513 +#: sssd-ad.5.xml:1506 msgid "" "When the autofs provider is set to <quote>ad</quote>, the RFC2307 schema " "attribute mapping (nisMap, nisObject, ...) is used, because these attributes " @@ -12242,9 +12597,9 @@ msgstr "" #: sssd-sudo.5.xml:137 msgid "" "The <emphasis>smart refresh</emphasis> periodically downloads rules that are " -"new or were modified after the last update. Its primary goal is to keep the " -"database growing by fetching only small increments that do not generate " -"large amounts of network traffic." +"new or were modified after the last update. Its primary goal is to grow the " +"database incrementally by fetching only small updates, avoiding large " +"amounts of network traffic." msgstr "" #. type: Content of: <reference><refentry><refsect1><para> @@ -12426,26 +12781,29 @@ msgstr "" msgid "" "Depending on the IdP product additional platform specific options might " "follow the name separated by a colon (:). E.g. for Keycloak the base URI for " -"the user and group REST API must be given. For Entra ID this is not needed " -"because there is a generic endpoint for all tenants." +"the user and group REST API must be given. For Entra ID the base URI for the " +"Microsoft Graph API can be given to use sovereign or government cloud " +"endpoints instead of the default (https://graph.microsoft.com/v1.0). E.g. " +"<quote>entra_id:https://graph.microsoft.us/v1.0</quote> for the US " +"government cloud (GCC High)." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:78 sssd-idp.5.xml:94 sssd-idp.5.xml:119 +#: sssd-idp.5.xml:82 sssd-idp.5.xml:98 sssd-idp.5.xml:123 #, fuzzy #| msgid "Default: true" msgid "Default: Not set (Required)" msgstr "Standaard: true" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:83 +#: sssd-idp.5.xml:87 #, fuzzy #| msgid "re_expression (string)" msgid "idp_client_id (string)" msgstr "re_expression (tekst)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:86 +#: sssd-idp.5.xml:90 msgid "" "ID of the IdP client used by SSSD to authenticate users and as a client to " "lookup user and group attributes. This client must offer device " @@ -12454,14 +12812,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:99 +#: sssd-idp.5.xml:103 #, fuzzy #| msgid "re_expression (string)" msgid "idp_client_secret (string)" msgstr "re_expression (tekst)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:102 +#: sssd-idp.5.xml:106 msgid "" "Password of the IdP client. The password is required for the id_provider. If " "only used as auth_provider it depends on the server side configuration if it " @@ -12469,76 +12827,83 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:113 +#: sssd-idp.5.xml:117 #, fuzzy #| msgid "re_expression (string)" msgid "idp_token_endpoint (string)" msgstr "re_expression (tekst)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:116 +#: sssd-idp.5.xml:120 msgid "IdP endpoint for requesting access tokens." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:124 +#: sssd-idp.5.xml:128 #, fuzzy #| msgid "re_expression (string)" msgid "idp_device_auth_endpoint (string)" msgstr "re_expression (tekst)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:127 +#: sssd-idp.5.xml:131 msgid "" "IdP endpoint for device authorization according to RFC-8628. This is " "required for user authentication." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:137 +#: sssd-idp.5.xml:141 #, fuzzy #| msgid "re_expression (string)" msgid "idp_userinfo_endpoint (string)" msgstr "re_expression (tekst)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:140 +#: sssd-idp.5.xml:144 msgid "" "IdP userinfo endpoint to request user attributes after a successful " "authentication of the user. Required for authentication." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:150 +#: sssd-idp.5.xml:154 #, fuzzy #| msgid "re_expression (string)" msgid "idp_id_scope (string)" msgstr "re_expression (tekst)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:153 +#: sssd-idp.5.xml:157 msgid "" "Scope required for looking up user and group attributes with the REST API. " "The scopes are used by the server to determine which attributes/claims are " "returned to the caller." msgstr "" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:163 +msgid "" +"Note: In previous versions of SSSD, this option was expected to already be " +"URL-encoded." +msgstr "" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:164 +#: sssd-idp.5.xml:172 #, fuzzy #| msgid "re_expression (string)" msgid "idp_auth_scope (string)" msgstr "re_expression (tekst)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:167 +#: sssd-idp.5.xml:175 msgid "" "Scope required during authentication. The scopes are used by the server to " "determine which attributes/claims are returned to the caller." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:172 +#: sssd-idp.5.xml:180 msgid "" "Currently the tokens returned during user authentication are not used for " "other purposes hence the only important claim is the subject identifier " @@ -12547,26 +12912,122 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:185 +#: sssd-idp.5.xml:193 +#, fuzzy +#| msgid "re_expression (string)" +msgid "idp_auth_user_identifier_attr (string)" +msgstr "re_expression (tekst)" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:196 +msgid "" +"Attribute used to identify the authenticated user in userinfo data or token " +"claims." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:200 +msgid "" +"For hybrid Active Directory and Entra ID deployments where " +"<quote>id_provider = ad</quote> and <quote>auth_provider = idp</quote>, this " +"option must be set explicitly. No value is derived from the identity " +"provider, because more than one attribute can link an Entra ID object to its " +"on-premises counterpart and only the administrator knows which one the " +"directory synchronization is configured to use." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:211 +msgid "" +"Setting this option to <quote>onPremisesImmutableId</quote> is the usual " +"choice for such deployments. Microsoft Entra Connect populates that " +"attribute with the base64-encoded form of the 16-byte Active Directory " +"<quote>objectGUID</quote> when objectGUID is used as the sourceAnchor. SSSD " +"decodes the value and converts the raw bytes with the same conversion used " +"for AD objectGUID attributes, so the result matches the UUID stored in the " +"SSSD cache for the AD user." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:224 +msgid "" +"Note that Microsoft Entra Connect 1.1.524.0 and later use <quote>ms-DS-" +"ConsistencyGuid</quote> as the sourceAnchor for user objects instead of " +"<quote>objectGUID</quote>. The value is normally copied from objectGUID for " +"objects that do not have it set yet, in which case the decoded identifier " +"still matches. It does not match if ms-DS-ConsistencyGuid was populated " +"independently, if users were moved between forests or domains, or if a " +"different attribute such as employeeID was selected as the sourceAnchor. See " +"<ulink url=\"https://learn.microsoft.com/en-us/entra/identity/hybrid/connect/" +"plan-connect-design-concepts\"> Microsoft Entra Connect: Design concepts</" +"ulink> for details on sourceAnchor selection." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:241 +msgid "" +"Microsoft Graph does not return <quote>onPremisesImmutableId</quote> by " +"default. The <quote>idp_userinfo_endpoint</quote> must request it with " +"<quote>$select</quote>, see the example below and <ulink url=\"https://" +"learn.microsoft.com/en-us/graph/api/resources/user\"> the Microsoft Graph " +"user resource type</ulink>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:251 +msgid "" +"If the configured attribute is missing or cannot be decoded (for example " +"cloud-only Entra ID users without <quote>onPremisesImmutableId</quote>), " +"authentication fails. SSSD does not fall back to another attribute when this " +"option is set." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:258 +msgid "" +"Default: not set, <quote>sub</quote> for Keycloak and <quote>id</quote> for " +"other IdP types" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-idp.5.xml:264 #, fuzzy #| msgid "entry_negative_timeout (integer)" msgid "idp_request_timeout (integer)" msgstr "entry_negative_timeout (numeriek)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:188 +#: sssd-idp.5.xml:267 msgid "Timeout in seconds for an individual request to the IdP." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:197 +#: sssd-idp.5.xml:276 +msgid "idp_auto_refresh (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:279 +msgid "" +"Refresh tokens automatically, after they have reached about half their " +"lifetime." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:283 +msgid "" +"Note: Scheduled token refreshes are not preserved across restarts of SSSD." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-idp.5.xml:292 #, fuzzy #| msgid "enum_cache_timeout (integer)" msgid "idmap_range_min (integer)" msgstr "enum_cache_timeout (numeriek)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:200 +#: sssd-idp.5.xml:295 msgid "" "Specifies the lower (inclusive) bound of the range of POSIX IDs to use for " "mapping IdP users and group to POSIX IDs. It is the first POSIX ID which can " @@ -12574,7 +13035,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:206 +#: sssd-idp.5.xml:301 msgid "" "The interval between <quote>idmap_range_min</quote> and " "<quote>idmap_range_max</quote> will be split into smaller ranges of size " @@ -12583,20 +13044,20 @@ msgid "" msgstr "" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:213 sssd-idp.5.xml:239 include/ldap_id_mapping.xml:139 +#: sssd-idp.5.xml:308 sssd-idp.5.xml:334 include/ldap_id_mapping.xml:139 #: include/ldap_id_mapping.xml:197 msgid "Default: 200000" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:218 +#: sssd-idp.5.xml:313 #, fuzzy #| msgid "enum_cache_timeout (integer)" msgid "idmap_range_max (integer)" msgstr "enum_cache_timeout (numeriek)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:221 +#: sssd-idp.5.xml:316 msgid "" "Specifies the upper (exclusive) bound of the range of POSIX IDs to use for " "mapping IdP users and groups to POSIX IDs. It is the first POSIX ID which " @@ -12604,47 +13065,70 @@ msgid "" msgstr "" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:227 include/ldap_id_mapping.xml:165 +#: sssd-idp.5.xml:322 include/ldap_id_mapping.xml:165 msgid "Default: 2000200000" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:232 +#: sssd-idp.5.xml:327 #, fuzzy #| msgid "enum_cache_timeout (integer)" msgid "idmap_range_size (integer)" msgstr "enum_cache_timeout (numeriek)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:235 +#: sssd-idp.5.xml:330 msgid "Specifies the number of POSIX IDs available for a single IdP domain." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-idp.5.xml:251 +#: sssd-idp.5.xml:346 #, no-wrap msgid "" "[domain/entra_id]\n" "id_provider = idp\n" "idp_type = entra_id\n" "idp_client_id = 12345678-abcd-0101-efef-ba9876543210\n" -"idp_client_secret = YOUR-CLIENT-SCERET\n" -"idp_token_endpoint = https://login.microsoftonline.com/TENNANT-ID/oauth2/v2.0/token\n" +"idp_client_secret = YOUR-CLIENT-SECRET\n" +"idp_token_endpoint = https://login.microsoftonline.com/TENANT-ID/oauth2/v2.0/token\n" "idp_userinfo_endpoint = https://graph.microsoft.com/v1.0/me\n" -"idp_device_auth_endpoint = https://login.microsoftonline.com/TENNANT-ID/oauth2/v2.0/devicecode\n" -"idp_id_scope = https%3A%2F%2Fgraph.microsoft.com%2F.default\n" +"idp_device_auth_endpoint = https://login.microsoftonline.com/TENANT-ID/oauth2/v2.0/devicecode\n" +"idp_id_scope = https://graph.microsoft.com/.default\n" +"idp_auth_scope = openid profile email\n" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><programlisting> +#: sssd-idp.5.xml:358 +#, no-wrap +msgid "" +"[domain/ad.example.com]\n" +"id_provider = ad\n" +"auth_provider = idp\n" +"access_provider = permit\n" +"\n" +"ad_domain = ad.example.com\n" +"krb5_realm = AD.EXAMPLE.COM\n" +"\n" +"idp_type = entra_id\n" +"idp_client_id = 12345678-abcd-0101-efef-ba9876543210\n" +"idp_client_secret = YOUR-CLIENT-SECRET\n" +"idp_token_endpoint = https://login.microsoftonline.com/TENANT-ID/oauth2/v2.0/token\n" +"idp_userinfo_endpoint = https://graph.microsoft.com/v1.0/me?$select=id,userPrincipalName,onPremisesImmutableId\n" +"idp_device_auth_endpoint = https://login.microsoftonline.com/TENANT-ID/oauth2/v2.0/devicecode\n" +"idp_id_scope = https://graph.microsoft.com/.default\n" "idp_auth_scope = openid profile email\n" +"idp_auth_user_identifier_attr = onPremisesImmutableId\n" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-idp.5.xml:263 +#: sssd-idp.5.xml:377 #, no-wrap msgid "" "[domain/keycloak]\n" "idp_type = keycloak:https://master.keycloak.test:8443/auth/admin/realms/master/\n" "id_provider = idp\n" "idp_client_id = myclient\n" -"idp_client_secret = YOUR-CLIENT-SCERET\n" +"idp_client_secret = YOUR-CLIENT-SECRET\n" "idp_token_endpoint = https://master.keycloak.test:8443/auth/realms/master/protocol/openid-connect/token\n" "idp_userinfo_endpoint = https://master.keycloak.test:8443/auth/realms/master/protocol/openid-connect/userinfo\n" "idp_device_auth_endpoint = https://master.keycloak.test:8443/auth/realms/master/protocol/openid-connect/auth/device\n" @@ -12653,10 +13137,22 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-idp.5.xml:250 +#: sssd-idp.5.xml:345 msgid "" "<placeholder type=\"programlisting\" id=\"0\"/> <placeholder " -"type=\"programlisting\" id=\"1\"/>" +"type=\"programlisting\" id=\"1\"/> <placeholder type=\"programlisting\" " +"id=\"2\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-idp.5.xml:390 +msgid "" +"In the hybrid Active Directory and Entra ID example above, " +"<quote>onPremisesImmutableId</quote> is used during authentication so the " +"IdP result matches the AD objectGUID UUID stored in the SSSD cache. The " +"attribute must be requested via <quote>$select</quote> on the Graph userinfo " +"endpoint and is only populated for users synchronized from Active Directory " +"with objectGUID as the sourceAnchor." msgstr "" #. type: Content of: <reference><refentry><refnamediv><refname> @@ -13624,7 +14120,7 @@ msgstr "" #: sssd-krb5.5.xml:291 msgid "" "<emphasis>demand</emphasis> to use FAST. The authentication fails if the " -"server does not require fast." +"server does not support FAST." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> @@ -14513,7 +15009,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sss_rpcidmapd.5.xml:69 -msgid "memcache (bool)" +msgid "memcache (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> @@ -14567,7 +15063,7 @@ msgid "" msgstr "" #. type: Content of: <refsect1><title> -#: sss_rpcidmapd.5.xml:120 sssd-kcm.8.xml:316 include/seealso.xml:2 +#: sss_rpcidmapd.5.xml:120 sssd-kcm.8.xml:315 include/seealso.xml:2 msgid "SEE ALSO" msgstr "ZIE OOK" @@ -14802,8 +15298,8 @@ msgstr "" #: sss_ssh_knownhosts.1.xml:93 msgid "" "The key lines retrieved from the backend are expected to respect the key " -"format as decribed in the <quote>SSH_KNOWN_HOSTS FILE FORMAT</quote> section " -"of <citerefentry><refentrytitle>sshd</refentrytitle> <manvolnum>8</" +"format as described in the <quote>SSH_KNOWN_HOSTS FILE FORMAT</quote> " +"section of <citerefentry><refentrytitle>sshd</refentrytitle> <manvolnum>8</" "manvolnum></citerefentry>. However, returning only the keytype and the key " "itself is tolerated, in which case, the hostname received as parameter will " "be added before the keytype to output a correctly formatted line. The " @@ -15279,14 +15775,13 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-kcm.8.xml:215 msgid "" -"The KCM service is configured in the <quote>kcm</quote> For a detailed " -"syntax reference, refer to the <quote>FILE FORMAT</quote> section of the " -"<citerefentry> <refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</" -"manvolnum> </citerefentry> manual page." +"For a detailed syntax reference, refer to the <quote>FILE FORMAT</quote> " +"section of the <citerefentry> <refentrytitle>sssd.conf</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry> manual page." msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-kcm.8.xml:223 +#: sssd-kcm.8.xml:222 msgid "" "The generic SSSD service options such as <quote>debug_level</quote> or " "<quote>fd_limit</quote> are accepted by the kcm service. Please refer to " @@ -15296,22 +15791,22 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:234 +#: sssd-kcm.8.xml:233 msgid "socket_path (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:237 +#: sssd-kcm.8.xml:236 msgid "The socket the KCM service will listen on." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:240 +#: sssd-kcm.8.xml:239 msgid "Default: <replaceable>/var/run/.heim_org.h5l.kcm-socket</replaceable>" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:243 +#: sssd-kcm.8.xml:242 msgid "" "<phrase condition=\"have_systemd\"> Note: on platforms where systemd is " "supported, the socket path is overwritten by the one defined in the sssd-" @@ -15319,90 +15814,92 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:252 +#: sssd-kcm.8.xml:251 msgid "max_ccaches (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:255 +#: sssd-kcm.8.xml:254 msgid "How many credential caches does the KCM database allow for all users." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:259 +#: sssd-kcm.8.xml:258 msgid "Default: 0 (unlimited, only the per-UID quota is enforced)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:264 +#: sssd-kcm.8.xml:263 msgid "max_uid_ccaches (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:267 +#: sssd-kcm.8.xml:266 msgid "" "How many credential caches does the KCM database allow per UID. This is " "equivalent to <quote>with how many principals you can kinit</quote>." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:272 +#: sssd-kcm.8.xml:271 msgid "Default: 64" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:277 +#: sssd-kcm.8.xml:276 msgid "max_ccache_size (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:280 +#: sssd-kcm.8.xml:279 msgid "" -"How big can a credential cache be per ccache. Each service ticket accounts " -"into this quota." +"How big a credential cache be per ccache. Each service ticket counts toward " +"this quota." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:284 +#: sssd-kcm.8.xml:283 msgid "Default: 65536" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:289 -msgid "tgt_renewal (bool)" -msgstr "" +#: sssd-kcm.8.xml:288 +#, fuzzy +#| msgid "try_inotify (boolean)" +msgid "tgt_renewal (boolean)" +msgstr "try_inotify (bool)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:292 +#: sssd-kcm.8.xml:291 msgid "Enables TGT renewals functionality." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:295 +#: sssd-kcm.8.xml:294 msgid "Default: False (Automatic renewals disabled)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:300 +#: sssd-kcm.8.xml:299 #, fuzzy #| msgid "re_expression (string)" msgid "tgt_renewal_inherit (string)" msgstr "re_expression (tekst)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:303 +#: sssd-kcm.8.xml:302 msgid "Domain to inherit krb5_* options from, for use with TGT renewals." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:307 +#: sssd-kcm.8.xml:306 #, fuzzy #| msgid "Default: 3" msgid "Default: NULL" msgstr "Standaard: 3" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-kcm.8.xml:318 +#: sssd-kcm.8.xml:317 msgid "" "<citerefentry> <refentrytitle>sssd</refentrytitle><manvolnum>8</manvolnum> </" "citerefentry>, <citerefentry> <refentrytitle>sssd.conf</" @@ -16306,8 +16803,8 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap-attributes.5.xml:381 sssd-ldap-attributes.5.xml:395 -msgid "Default: loginDisabled" +#: sssd-ldap-attributes.5.xml:381 +msgid "Default: loginDisabled (rfc2307, rfc2307bis and IPA), not set (AD)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> @@ -16322,6 +16819,12 @@ msgid "" "which date access is granted." msgstr "" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:395 +msgid "" +"Default: loginExpirationTime (rfc2307, rfc2307bis and IPA), not set (AD)" +msgstr "" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:401 msgid "ldap_user_nds_login_allowed_time_map (string)" @@ -16336,7 +16839,8 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:409 -msgid "Default: loginAllowedTimeMap" +msgid "" +"Default: loginAllowedTimeMap (rfc2307, rfc2307bis and IPA), not set (AD)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> @@ -16852,8 +17356,8 @@ msgid "The object class of a host entry in LDAP." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap-attributes.5.xml:900 sssd-ldap-attributes.5.xml:997 -msgid "Default: ipService" +#: sssd-ldap-attributes.5.xml:900 sssd-ldap-attributes.5.xml:1213 +msgid "Default: ipHost" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> @@ -16938,6 +17442,11 @@ msgstr "" msgid "The object class of a service entry in LDAP." msgstr "" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:997 +msgid "Default: ipService" +msgstr "" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1003 msgid "ldap_service_name (string)" @@ -17178,11 +17687,6 @@ msgstr "" msgid "The object class of an iphost entry in LDAP." msgstr "" -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap-attributes.5.xml:1213 -msgid "Default: ipHost" -msgstr "" - #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1219 msgid "ldap_iphost_name (string)" @@ -17422,6 +17926,7 @@ msgstr "" msgid "" "[plugins]\n" " localauth = {\n" +" disable = an2ln\n" " module = sssd:/usr/lib64/sssd/modules/sssd_krb5_localauth_plugin.so\n" " }\n" msgstr "" @@ -17438,6 +17943,28 @@ msgid "" "the local Kerberos configuration the plugin will be enabled automatically." msgstr "" +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_localauth_plugin.8.xml:67 +msgid "" +"This configuration snippet also disables the <command>an2ln</command> module " +"provided by MIT Kerberos if SSSD is configured to use the AD or IPA " +"provider. In those environments <command>sssd_krb5_localauth_plugin</" +"command> can reliably map the system user names to Kerberos principals. A " +"fallback to <command>an2ln</command> might cause issues in environments " +"where users have the privilege to create Kerberos principals on their own " +"which might collide with names of other users used in the system. Other " +"modules provided by MIT Kerberos, e.g. <command>k5login</command> are not " +"affected." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_localauth_plugin.8.xml:79 +msgid "" +"Note: If using <quote>auth_provider = krb5</quote> then " +"<command>sssd_krb5_localauth_plugin</command> is not used, therefore the " +"above text is not applicable." +msgstr "" + #. type: Content of: <variablelist><varlistentry><term> #: include/autofs_attributes.xml:3 msgid "ldap_autofs_map_object_class (string)" @@ -18294,30 +18821,6 @@ msgid "" "failures; corresponds to setting 2 in decimal notation)" msgstr "" -#. type: Content of: <refsect1><title> -#: include/local.xml:2 -msgid "THE LOCAL DOMAIN" -msgstr "" - -#. type: Content of: <refsect1><para> -#: include/local.xml:4 -msgid "" -"In order to function correctly, a domain with <quote>id_provider=local</" -"quote> must be created and the SSSD must be running." -msgstr "" - -#. type: Content of: <refsect1><para> -#: include/local.xml:9 -msgid "" -"The administrator might want to use the SSSD local users instead of " -"traditional UNIX users in cases where the group nesting (see <citerefentry> " -"<refentrytitle>sss_groupadd</refentrytitle> <manvolnum>8</manvolnum> </" -"citerefentry>) is needed. The local users are also useful for testing and " -"development of the SSSD without having to deploy a full remote server. The " -"<command>sss_user*</command> and <command>sss_group*</command> tools use a " -"local LDB storage to store users and groups." -msgstr "" - #. type: Content of: <refsect1><para> #: include/seealso.xml:4 msgid "" @@ -18921,6 +19424,19 @@ msgid "" "feature is available with MIT Kerberos 1.7 and later versions." msgstr "" +#~ msgid "" +#~ "The data types used are string (no quotes needed), integer and bool (with " +#~ "values of <quote>TRUE/FALSE</quote>)." +#~ msgstr "" +#~ "De datatypes gebruikt zijn tekst (geen quotes vereisd), numeriek en " +#~ "booleaans (met de waardes <quote>TRUE/FALSE</quote>)." + +#~ msgid "services" +#~ msgstr "diensten" + +#~ msgid "domains" +#~ msgstr "domeinen" + #, fuzzy #~| msgid "reconnection_retries (integer)" #~ msgid "ldap_enumeration_refresh_timeout" @@ -18931,9 +19447,6 @@ msgstr "" #~ msgid "ldap_enumeration_search_timeout" #~ msgstr "reconnection_retries (numeriek)" -#~ msgid "reconnection_retries (integer)" -#~ msgstr "reconnection_retries (numeriek)" - #~ msgid "" #~ "Number of times services should attempt to reconnect in the event of a " #~ "Data Provider crash or restart before they give up" diff --git a/src/man/po/pl.po b/src/man/po/pl.po index 51ef7c19b13..0995ba4ec56 100644 --- a/src/man/po/pl.po +++ b/src/man/po/pl.po @@ -8,7 +8,7 @@ msgstr "" "Project-Id-Version: sssd-docs 2.8.0\n" "Report-Msgid-Bugs-To: sssd-devel@redhat.com\n" "POT-Creation-Date: 2022-07-04 11:58+0200\n" -"PO-Revision-Date: 2026-04-23 16:45+0000\n" +"PO-Revision-Date: 2026-10-05 17:14+0000\n" "Last-Translator: Weblate Translation Memory <noreply-mt-weblate-translation-" "memory@weblate.org>\n" "Language-Team: Polish <https://translate.fedoraproject.org/projects/sssd/" @@ -19,7 +19,7 @@ msgstr "" "Content-Transfer-Encoding: 8bit\n" "Plural-Forms: nplurals=3; plural=n==1 ? 0 : n%10>=2 && n%10<=4 && (n%100<10 " "|| n%100>=20) ? 1 : 2;\n" -"X-Generator: Weblate 5.17\n" +"X-Generator: Weblate 2026.10\n" #. type: Content of: <reference><title> #: sssd.conf.5.xml:5 sssd-ldap.5.xml:5 pam_sss.8.xml:5 pam_sss_gss.8.xml:5 diff --git a/src/man/po/pt.po b/src/man/po/pt.po index 93bac206ab4..b938e524972 100644 --- a/src/man/po/pt.po +++ b/src/man/po/pt.po @@ -8,8 +8,8 @@ msgid "" msgstr "" "Project-Id-Version: sssd-docs 2.3.0\n" "Report-Msgid-Bugs-To: sssd-devel@redhat.com\n" -"POT-Creation-Date: 2026-01-14 15:00+0000\n" -"PO-Revision-Date: 2026-04-23 17:01+0000\n" +"POT-Creation-Date: 2026-10-05 16:14+0000\n" +"PO-Revision-Date: 2026-10-05 21:20+0000\n" "Last-Translator: Américo Monteiro <a_monteiro@gmx.com>\n" "Language-Team: Portuguese <https://translate.fedoraproject.org/projects/sssd/" "sssd-manpage-master/pt/>\n" @@ -18,10 +18,10 @@ msgstr "" "Content-Type: text/plain; charset=UTF-8\n" "Content-Transfer-Encoding: 8bit\n" "Plural-Forms: nplurals=2; plural=(n != 1);\n" -"X-Generator: Weblate 5.17\n" +"X-Generator: Weblate 2026.10\n" #. type: Content of: <reference><title> -#: sssd.conf.5.xml:8 sssd-ldap.5.xml:5 pam_sss.8.xml:5 pam_sss_gss.8.xml:5 +#: sssd.conf.5.xml:10 sssd-ldap.5.xml:5 pam_sss.8.xml:5 pam_sss_gss.8.xml:5 #: sssd_krb5_locator_plugin.8.xml:5 sssd-simple.5.xml:5 sss-certmap.5.xml:5 #: sssd-ipa.5.xml:5 sssd-ad.5.xml:5 sssd-sudo.5.xml:5 sssd-idp.5.xml:5 #: sssd.8.xml:5 sss_obfuscate.8.xml:5 sss_override.8.xml:5 sssd-krb5.5.xml:5 @@ -34,12 +34,12 @@ msgid "SSSD Manual pages" msgstr "Manual do SSSD" #. type: Content of: <reference><refentry><refnamediv><refname> -#: sssd.conf.5.xml:13 sssd.conf.5.xml:19 +#: sssd.conf.5.xml:15 sssd.conf.5.xml:21 msgid "sssd.conf" msgstr "sssd.conf" #. type: Content of: <reference><refentry><refmeta><manvolnum> -#: sssd.conf.5.xml:14 sssd-ldap.5.xml:11 sssd-simple.5.xml:11 +#: sssd.conf.5.xml:16 sssd-ldap.5.xml:11 sssd-simple.5.xml:11 #: sss-certmap.5.xml:11 sssd-ipa.5.xml:11 sssd-ad.5.xml:11 sssd-sudo.5.xml:11 #: sssd-idp.5.xml:11 sssd-krb5.5.xml:11 sssd-ifp.5.xml:11 #: sss_rpcidmapd.5.xml:27 sssd-session-recording.5.xml:11 @@ -48,7 +48,7 @@ msgid "5" msgstr "5" #. type: Content of: <reference><refentry><refmeta><refmiscinfo> -#: sssd.conf.5.xml:15 sssd-ldap.5.xml:12 sssd-simple.5.xml:12 +#: sssd.conf.5.xml:17 sssd-ldap.5.xml:12 sssd-simple.5.xml:12 #: sss-certmap.5.xml:12 sssd-ipa.5.xml:12 sssd-ad.5.xml:12 sssd-sudo.5.xml:12 #: sssd-idp.5.xml:12 sssd-krb5.5.xml:12 sssd-ifp.5.xml:12 #: sss_rpcidmapd.5.xml:28 sssd-session-recording.5.xml:12 sssd-kcm.8.xml:12 @@ -57,17 +57,17 @@ msgid "File Formats and Conventions" msgstr "Formatos de Ficheiros e Convenções" #. type: Content of: <reference><refentry><refnamediv><refpurpose> -#: sssd.conf.5.xml:20 +#: sssd.conf.5.xml:22 msgid "the configuration file for SSSD" msgstr "o ficheiro de configuração para SSSD" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:24 +#: sssd.conf.5.xml:26 msgid "FILE FORMAT" msgstr "FORMATO DO FICHEIRO" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd.conf.5.xml:32 +#: sssd.conf.5.xml:34 #, no-wrap msgid "" "<replaceable>[section]</replaceable>\n" @@ -82,7 +82,7 @@ msgstr "" " " #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:27 +#: sssd.conf.5.xml:29 msgid "" "The file has an ini-style syntax and consists of sections and parameters. A " "section begins with the name of the section in square brackets and continues " @@ -95,16 +95,17 @@ msgstr "" "e de multi-valores: <placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:39 +#: sssd.conf.5.xml:41 msgid "" -"The data types used are string (no quotes needed), integer and bool (with " -"values of <quote>TRUE/FALSE</quote>)." +"The data types used are string (no quotes needed), integer and boolean (with " +"values of <quote>TRUE/FALSE</quote>). Boolean values are case-insensitive; " +"for example, <quote>TRUE</quote>, <quote>True</quote> and <quote>true</" +"quote> are all equivalent and valid; the same applies to <quote>FALSE</" +"quote>." msgstr "" -"Os tipos de dados usados são cadeia de caracteres (sem aspas necessárias), " -"inteiro e booleano (com valores de <quote>TRUE/FALSE</quote>)." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:44 +#: sssd.conf.5.xml:49 msgid "" "A comment line starts with a hash sign (<quote>#</quote>) or a semicolon " "(<quote>;</quote>). Inline comments are not supported." @@ -114,7 +115,7 @@ msgstr "" "linhas." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:50 +#: sssd.conf.5.xml:55 msgid "" "All sections can have an optional <replaceable>description</replaceable> " "parameter. Its function is only as a label for the section." @@ -123,7 +124,7 @@ msgstr "" "replaceable>. A sua função é apenas ser uma etiqueta para a secção." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:56 +#: sssd.conf.5.xml:61 msgid "" "<filename>sssd.conf</filename> must be a regular file that is owned, " "readable, and writeable only by 'root'." @@ -132,7 +133,7 @@ msgstr "" "é dono, e só ele pode ler e escrever." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:60 +#: sssd.conf.5.xml:65 msgid "" "<filename>sssd.conf</filename> must be a regular file that is accessible " "only by the user used to run SSSD service or root." @@ -141,12 +142,12 @@ msgstr "" "apenas pelo utilizador usado para correr o serviço SSSD ou o root." #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:66 +#: sssd.conf.5.xml:71 msgid "CONFIGURATION SNIPPETS FROM INCLUDE DIRECTORY" msgstr "TRECHOS DE CONFIGURAÇÃO DO DIRETÓRIO INCLUDE" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:69 +#: sssd.conf.5.xml:74 msgid "" "The configuration file <filename>sssd.conf</filename> will include " "configuration snippets using the include directory <filename>conf.d</" @@ -157,7 +158,7 @@ msgstr "" "filename>." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:75 +#: sssd.conf.5.xml:80 msgid "" "Any file placed in <filename>conf.d</filename> that ends in " "<quote><filename>.conf</filename></quote> and does not begin with a dot " @@ -170,7 +171,7 @@ msgstr "" "configurar o SSSD." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:83 +#: sssd.conf.5.xml:88 msgid "" "The configuration snippets from <filename>conf.d</filename> have higher " "priority than <filename>sssd.conf</filename> and will override " @@ -191,7 +192,7 @@ msgstr "" "visualizar a prioridade (número mais alto significa prioridade mais alta)." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:97 +#: sssd.conf.5.xml:102 msgid "" "The snippet files require the same owner and permissions as " "<filename>sssd.conf</filename>." @@ -200,33 +201,86 @@ msgstr "" "sssd.conf</filename>." #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:103 +#: sssd.conf.5.xml:108 +#, fuzzy +#| msgid "TRUSTED DOMAINS CONFIGURATION" +msgid "VENDOR PROVIDED CONFIGURATION" +msgstr "CONFIGURAÇÃO DE DOMÍNIOS DE CONFIANÇA" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:111 +msgid "" +"The vendor provided configuration file is installed in " +"<filename>&sssd_vendor_dir;/sssd.conf</filename>, but this file must not be " +"directly edited. It can be completely masked by creating the system specific " +"configuration file <filename>&sssd_conf_dir;/sssd.conf</filename>, or partly " +"overriden by creating config snippets in <filename>&sssd_conf_dir;/conf.d</" +"filename> directory." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><title> +#: sssd.conf.5.xml:120 +#, fuzzy +#| msgid "CONFIGURATION FILE" +msgid "CONFIGURATION FILE HIERARCHY" +msgstr "FICHEIRO DE CONFIGURAÇÃO" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:122 +msgid "" +"When sssd reads the configuration it first tries to open the system specific " +"configuration file in <filename>&sssd_conf_dir;/sssd.conf</filename>. If it " +"exists, it is loaded and snippets from <filename>&sssd_conf_dir;/conf.d</" +"filename> are applied. The vendor provided configuration file " +"<filename>&sssd_vendor_dir;/sssd.conf</filename> is completely ignored in " +"this case." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:131 +msgid "" +"If the system specific configuration file <filename>&sssd_conf_dir;/" +"sssd.conf</filename> does not exist, then the vendor configuration file " +"<filename>&sssd_vendor_dir;/sssd.conf</filename> is loaded and snippets from " +"<filename>&sssd_conf_dir;/conf.d</filename> are applied." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd.conf.5.xml:141 msgid "GENERAL OPTIONS" msgstr "OPÇÕES GERAIS" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:105 +#: sssd.conf.5.xml:143 msgid "Following options are usable in more than one configuration sections." msgstr "" "As seguinte opções são utilizáveis em mais do que uma secção de configuração." #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:109 +#: sssd.conf.5.xml:147 msgid "Options usable in all sections" msgstr "Opções utilizáveis em todas as secções" +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:149 +msgid "" +"Note: Below options are ignored in <quote>[session_recording]</quote> " +"section, see <quote>Session recording configuration options</quote> section " +"for more details." +msgstr "" + #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:113 +#: sssd.conf.5.xml:156 msgid "debug_level (integer)" msgstr "debug_level (inteiro)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:117 +#: sssd.conf.5.xml:160 msgid "debug (integer)" msgstr "debug (inteiro)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:120 +#: sssd.conf.5.xml:163 msgid "" "SSSD 1.14 and later also includes the <replaceable>debug</replaceable> alias " "for <replaceable>debug_level</replaceable> as a convenience feature. If both " @@ -239,12 +293,14 @@ msgstr "" "<replaceable>debug_level</replaceable>." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:130 -msgid "debug_timestamps (bool)" +#: sssd.conf.5.xml:173 +#, fuzzy +#| msgid "debug_timestamps (bool)" +msgid "debug_timestamps (boolean)" msgstr "debug_timestamps (booleano)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:133 +#: sssd.conf.5.xml:176 msgid "" "Add a timestamp to the debug messages. If journald is enabled for SSSD " "debug logging this option is ignored." @@ -253,23 +309,25 @@ msgstr "" "ativo para registos de depuração do SSSD esta opção é ignorada." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:138 sssd.conf.5.xml:175 sssd.conf.5.xml:337 -#: sssd.conf.5.xml:644 sssd.conf.5.xml:668 sssd.conf.5.xml:875 -#: sssd.conf.5.xml:979 sssd.conf.5.xml:2113 sssd-ldap.5.xml:979 -#: sssd-ldap.5.xml:1134 sssd-ldap.5.xml:1237 sssd-ldap.5.xml:1306 -#: sssd-ldap.5.xml:1714 sssd-ldap.5.xml:1848 sssd-ldap.5.xml:1913 -#: sssd-ipa.5.xml:346 sssd-ad.5.xml:252 sssd-ad.5.xml:367 sssd-ad.5.xml:1180 -#: sssd-ad.5.xml:1382 sssd-krb5.5.xml:358 +#: sssd.conf.5.xml:181 sssd.conf.5.xml:218 sssd.conf.5.xml:380 +#: sssd.conf.5.xml:687 sssd.conf.5.xml:711 sssd.conf.5.xml:827 +#: sssd.conf.5.xml:932 sssd.conf.5.xml:2149 sssd.conf.5.xml:4730 +#: sssd-ldap.5.xml:979 sssd-ldap.5.xml:1134 sssd-ldap.5.xml:1237 +#: sssd-ldap.5.xml:1306 sssd-ldap.5.xml:1714 sssd-ldap.5.xml:1848 +#: sssd-ldap.5.xml:1913 sssd-ipa.5.xml:341 sssd-ad.5.xml:252 sssd-ad.5.xml:367 +#: sssd-ad.5.xml:1180 sssd-ad.5.xml:1375 sssd-krb5.5.xml:358 msgid "Default: true" msgstr "Predefinição: true" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:143 -msgid "debug_microseconds (bool)" +#: sssd.conf.5.xml:186 +#, fuzzy +#| msgid "debug_microseconds (bool)" +msgid "debug_microseconds (boolean)" msgstr "debug_microseconds (booleano)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:146 +#: sssd.conf.5.xml:189 msgid "" "Add microseconds to the timestamp in debug messages. If journald is enabled " "for SSSD debug logging this option is ignored." @@ -279,26 +337,28 @@ msgstr "" "ignorada." #. type: Content of: <variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:151 sssd.conf.5.xml:2040 sssd.conf.5.xml:4158 +#: sssd.conf.5.xml:194 sssd.conf.5.xml:2072 sssd.conf.5.xml:4363 #: sssd-ldap.5.xml:363 sssd-ldap.5.xml:998 sssd-ldap.5.xml:1209 -#: sssd-ldap.5.xml:1663 sssd-ldap.5.xml:1937 sssd-ipa.5.xml:146 -#: sssd-ipa.5.xml:706 sssd-ad.5.xml:1135 sssd-krb5.5.xml:268 +#: sssd-ldap.5.xml:1663 sssd-ldap.5.xml:1937 sssd-ipa.5.xml:141 +#: sssd-ipa.5.xml:701 sssd-ad.5.xml:1140 sssd-idp.5.xml:287 sssd-krb5.5.xml:268 #: sssd-krb5.5.xml:330 sssd-krb5.5.xml:432 include/krb5_options.xml:163 msgid "Default: false" msgstr "Predefinição: false" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:156 -msgid "debug_backtrace_enabled (bool)" +#: sssd.conf.5.xml:199 +#, fuzzy +#| msgid "debug_backtrace_enabled (bool)" +msgid "debug_backtrace_enabled (boolean)" msgstr "debug_microseconds (booleano)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:159 +#: sssd.conf.5.xml:202 msgid "Enable debug backtrace." msgstr "Activa o seguimento de depuração." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:162 +#: sssd.conf.5.xml:205 msgid "" "In case SSSD is run with debug_level less than 9, everything is logged to a " "ring buffer in memory and flushed to a log file on any error up to and " @@ -313,7 +373,7 @@ msgstr "" "despoletar os registos, caso contrário até ao 2)." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:171 +#: sssd.conf.5.xml:214 msgid "" "Feature is only supported for `logger == files` (i.e. setting doesn't have " "effect for other logger types)." @@ -322,7 +382,7 @@ msgstr "" "definição não tem efeito para outros tipos de relatório)." #. type: Content of: outside any tag (error?) -#: sssd.conf.5.xml:111 sssd.conf.5.xml:186 sssd-ldap.5.xml:1754 +#: sssd.conf.5.xml:154 sssd.conf.5.xml:229 sssd-ldap.5.xml:1754 #: sssd-ldap.5.xml:1960 sss-certmap.5.xml:645 sssd-systemtap.5.xml:82 #: sssd-systemtap.5.xml:143 sssd-systemtap.5.xml:236 sssd-systemtap.5.xml:274 #: sssd-systemtap.5.xml:330 sssd-ldap-attributes.5.xml:40 @@ -335,17 +395,17 @@ msgid "<placeholder type=\"variablelist\" id=\"0\"/>" msgstr "<placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:184 +#: sssd.conf.5.xml:227 msgid "Options usable in SERVICE and DOMAIN sections" msgstr "Opções utilizáveis nas secções SERVICE e DOMAIN" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:188 +#: sssd.conf.5.xml:231 msgid "timeout (integer)" msgstr "tempo limite (inteiro)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:191 +#: sssd.conf.5.xml:234 msgid "" "Timeout in seconds between heartbeats for this service. This is used to " "ensure that the process is alive and capable of answering requests. Note " @@ -356,34 +416,36 @@ msgstr "" "após três batimentos em falta o processo irá terminar por ele próprio." #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:198 sssd.conf.5.xml:1199 sssd.conf.5.xml:1673 -#: sssd.conf.5.xml:4174 sssd-ldap.5.xml:825 sssd-idp.5.xml:192 +#: sssd.conf.5.xml:241 sssd.conf.5.xml:1155 sssd.conf.5.xml:1665 +#: sssd.conf.5.xml:4379 sssd-ldap.5.xml:825 sssd-idp.5.xml:271 #: include/ldap_id_mapping.xml:270 msgid "Default: 10" msgstr "Predefinido: 10" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:208 +#: sssd.conf.5.xml:251 msgid "SPECIAL SECTIONS" msgstr "SECÇÕES ESPECIAIS" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:211 +#: sssd.conf.5.xml:254 msgid "The [sssd] section" msgstr "A secção [sssd]" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><title> -#: sssd.conf.5.xml:220 +#: sssd.conf.5.xml:263 msgid "Section parameters" msgstr "Parâmetros de secção" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:222 -msgid "services" -msgstr "serviços" +#: sssd.conf.5.xml:265 +#, fuzzy +#| msgid "users (string)" +msgid "services (string)" +msgstr "users (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:225 +#: sssd.conf.5.xml:268 msgid "" "Comma separated list of services that are started when sssd itself starts. " "<phrase condition=\"have_systemd\"> The services' list is optional on " @@ -396,7 +458,7 @@ msgstr "" "ativados via socket ou D-Bus quando necessário. </phrase>" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:234 +#: sssd.conf.5.xml:277 msgid "" "Supported services: nss, pam, ifp <phrase condition=\"with_sudo\">, sudo</" "phrase> <phrase condition=\"with_autofs\">, autofs</phrase> <phrase " @@ -409,7 +471,7 @@ msgstr "" "condition=\"with_pac_responder\">, pac</phrase>" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:241 +#: sssd.conf.5.xml:284 msgid "" "<phrase condition=\"have_systemd\"> By default, all services are disabled " "and the administrator must enable the ones allowed to be used by executing: " @@ -419,13 +481,13 @@ msgstr "" "desativados e o administrador tem de activar os que permite serem usados ao " "executar: \"systemctl enable sssd-@service@.socket\". </phrase>" -#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:250 -msgid "domains" -msgstr "domínios" +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sssd.conf.5.xml:293 sssd.conf.5.xml:4562 +msgid "domains (string)" +msgstr "domains (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:253 +#: sssd.conf.5.xml:296 msgid "" "A domain is a database containing user information. SSSD can use more " "domains at the same time, but at least one must be configured or SSSD won't " @@ -442,12 +504,12 @@ msgstr "" "pontos e underscores. O caractere '/' é proibido." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:266 sssd.conf.5.xml:3467 +#: sssd.conf.5.xml:309 sssd.conf.5.xml:3598 msgid "re_expression (string)" msgstr "re_expression (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:269 +#: sssd.conf.5.xml:312 msgid "" "Default regular expression that describes how to parse the string containing " "user name and domain into these components." @@ -456,7 +518,7 @@ msgstr "" "contém o nome de utilizador e domínio nestes componentes." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:274 +#: sssd.conf.5.xml:317 msgid "" "Each domain can have an individual regular expression configured. For some " "ID providers there are also default regular expressions. See DOMAIN SECTIONS " @@ -467,12 +529,12 @@ msgstr "" "SECÇÕES DE DOMÍNIO para mais informação sobre essas expressões regulares." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:283 sssd.conf.5.xml:3524 +#: sssd.conf.5.xml:326 sssd.conf.5.xml:3655 msgid "full_name_format (string)" msgstr "full_name_format (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:286 sssd.conf.5.xml:3527 +#: sssd.conf.5.xml:329 sssd.conf.5.xml:3658 msgid "" "A <citerefentry> <refentrytitle>printf</refentrytitle> <manvolnum>3</" "manvolnum> </citerefentry>-compatible format that describes how to compose a " @@ -484,32 +546,32 @@ msgstr "" "domínio." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:297 sssd.conf.5.xml:3538 +#: sssd.conf.5.xml:340 sssd.conf.5.xml:3669 msgid "%1$s" msgstr "%1$s" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:298 sssd.conf.5.xml:3539 +#: sssd.conf.5.xml:341 sssd.conf.5.xml:3670 msgid "user name" msgstr "nome de utilizador" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:301 sssd.conf.5.xml:3542 +#: sssd.conf.5.xml:344 sssd.conf.5.xml:3673 msgid "%2$s" msgstr "%2$s" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:304 sssd.conf.5.xml:3545 +#: sssd.conf.5.xml:347 sssd.conf.5.xml:3676 msgid "domain name as specified in the SSSD config file." msgstr "nome de domínio como especificado no ficheiro de configuração do SSSD." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:310 sssd.conf.5.xml:3551 +#: sssd.conf.5.xml:353 sssd.conf.5.xml:3682 msgid "%3$s" msgstr "%3$s" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:313 sssd.conf.5.xml:3554 +#: sssd.conf.5.xml:356 sssd.conf.5.xml:3685 msgid "" "domain flat name. Mostly usable for Active Directory domains, both directly " "configured or discovered via IPA trusts." @@ -518,7 +580,7 @@ msgstr "" "diretamente configurados ou descobertos via confianças de IPA." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:294 sssd.conf.5.xml:3535 +#: sssd.conf.5.xml:337 sssd.conf.5.xml:3666 msgid "" "The following expansions are supported: <placeholder type=\"variablelist\" " "id=\"0\"/>" @@ -527,7 +589,7 @@ msgstr "" "id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:323 +#: sssd.conf.5.xml:366 msgid "" "Each domain can have an individual format string configured. See DOMAIN " "SECTIONS for more info on this option." @@ -536,12 +598,12 @@ msgstr "" "SECÇÕES DE DOMÍNIO para mais informação desta opção." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:329 +#: sssd.conf.5.xml:372 msgid "monitor_resolv_conf (boolean)" msgstr "monitor_resolv_conf (booleano)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:332 +#: sssd.conf.5.xml:375 msgid "" "Controls if SSSD should monitor the state of resolv.conf to identify when it " "needs to update its internal DNS resolver." @@ -550,12 +612,12 @@ msgstr "" "quando precisa de atualizar o seu resolver de DNS interno." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:342 +#: sssd.conf.5.xml:385 msgid "try_inotify (boolean)" msgstr "try_inotify (booleano)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:345 +#: sssd.conf.5.xml:388 msgid "" "By default, SSSD will attempt to use inotify to monitor configuration files " "changes and will fall back to polling every five seconds if inotify cannot " @@ -566,7 +628,7 @@ msgstr "" "se o inotify não puder ser usado." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:351 +#: sssd.conf.5.xml:394 msgid "" "There are some limited situations where it is preferred that we should skip " "even trying to use inotify. In these rare cases, this option should be set " @@ -577,7 +639,7 @@ msgstr "" "para 'false'" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:357 +#: sssd.conf.5.xml:400 msgid "" "Default: true on platforms where inotify is supported. False on other " "platforms." @@ -586,7 +648,7 @@ msgstr "" "plataformas." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:361 +#: sssd.conf.5.xml:404 msgid "" "Note: this option will have no effect on platforms where inotify is " "unavailable. On these platforms, polling will always be used." @@ -595,12 +657,12 @@ msgstr "" "disponível. Nestas plataformas será sempre usado polling." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:368 +#: sssd.conf.5.xml:411 msgid "krb5_rcache_dir (string)" msgstr "krb5_rcache_dir (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:371 +#: sssd.conf.5.xml:414 msgid "" "Directory on the filesystem where SSSD should store Kerberos replay cache " "files." @@ -609,7 +671,7 @@ msgstr "" "de cache de repetição do Kerberos." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:375 +#: sssd.conf.5.xml:418 msgid "" "This option accepts a special value __LIBKRB5_DEFAULTS__ that will instruct " "SSSD to let libkrb5 decide the appropriate location for the replay cache." @@ -619,7 +681,7 @@ msgstr "" "repetição." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:381 +#: sssd.conf.5.xml:424 msgid "" "Default: Distribution-specific and specified at build-time. " "(__LIBKRB5_DEFAULTS__ if not configured)" @@ -628,12 +690,12 @@ msgstr "" "compilação. (__LIBKRB5_DEFAULTS__ se não configurada)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:388 +#: sssd.conf.5.xml:431 msgid "default_domain_suffix (string)" msgstr "default_domain_suffix (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:391 +#: sssd.conf.5.xml:434 msgid "" "Please note that this option is deprecated and domain_resolution_order " "should be used." @@ -642,7 +704,7 @@ msgstr "" "domain_resolution_order." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:395 +#: sssd.conf.5.xml:438 msgid "" "This string will be used as a default domain name for all names without a " "domain name component. The main use case is environments where the primary " @@ -659,7 +721,7 @@ msgstr "" "domínio." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:405 +#: sssd.conf.5.xml:448 msgid "" "Please note that if this option is set all users from the primary domain " "have to use their fully qualified name, e.g. user@domain.name, to log in. " @@ -674,21 +736,21 @@ msgstr "" "conjunto com use_fully_qualified_names definido para False." #. type: Content of: <variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:414 sssd-ldap.5.xml:937 sssd-ldap.5.xml:949 -#: sssd-ldap.5.xml:1042 sssd-ad.5.xml:921 sssd-ad.5.xml:996 sssd-krb5.5.xml:468 -#: sssd-ldap-attributes.5.xml:470 sssd-ldap-attributes.5.xml:978 -#: include/ldap_id_mapping.xml:211 include/ldap_id_mapping.xml:222 -#: include/krb5_options.xml:148 +#: sssd.conf.5.xml:457 sssd.conf.5.xml:2006 sssd-ldap.5.xml:937 +#: sssd-ldap.5.xml:949 sssd-ldap.5.xml:1042 sssd-ad.5.xml:926 +#: sssd-ad.5.xml:1001 sssd-krb5.5.xml:468 sssd-ldap-attributes.5.xml:470 +#: sssd-ldap-attributes.5.xml:978 include/ldap_id_mapping.xml:211 +#: include/ldap_id_mapping.xml:222 include/krb5_options.xml:148 msgid "Default: not set" msgstr "Predefinição: não definida" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:419 +#: sssd.conf.5.xml:462 msgid "override_space (string)" msgstr "override_space (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:422 +#: sssd.conf.5.xml:465 msgid "" "This parameter will replace spaces (space bar) with the given character for " "user and group names. e.g. (_). User name "john doe" will be " @@ -704,7 +766,7 @@ msgstr "" "shell." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:431 +#: sssd.conf.5.xml:474 msgid "" "Please note it is a configuration error to use a replacement character that " "might be used in user or group names. If a name contains the replacement " @@ -717,22 +779,22 @@ msgstr "" "no geral o resultado duma procura é indefinido." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:439 +#: sssd.conf.5.xml:482 msgid "Default: not set (spaces will not be replaced)" msgstr "Predefinição: não definida (os espaços não serão substituídos)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:444 +#: sssd.conf.5.xml:487 msgid "certificate_verification (string)" msgstr "certificate_verification (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:452 +#: sssd.conf.5.xml:495 msgid "no_ocsp" msgstr "no_ocsp" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:454 +#: sssd.conf.5.xml:497 msgid "" "Disables Online Certificate Status Protocol (OCSP) checks. This might be " "needed if the OCSP servers defined in the certificate are not reachable from " @@ -743,12 +805,12 @@ msgstr "" "alcançáveis a partir do cliente." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:462 +#: sssd.conf.5.xml:505 msgid "soft_ocsp" msgstr "soft_ocsp" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:464 +#: sssd.conf.5.xml:507 msgid "" "If a connection cannot be established to an OCSP responder the OCSP check is " "skipped. This option should be used to allow authentication when the system " @@ -760,12 +822,12 @@ msgstr "" "alcançado." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:474 +#: sssd.conf.5.xml:517 msgid "ocsp_dgst" msgstr "ocsp_dgst" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:476 +#: sssd.conf.5.xml:519 msgid "" "Digest (hash) function used to create the certificate ID for the OCSP " "request. Allowed values are:" @@ -774,39 +836,39 @@ msgstr "" "OCSP. Os valores permitidos são:" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:480 +#: sssd.conf.5.xml:523 msgid "sha1" msgstr "sha1" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:481 +#: sssd.conf.5.xml:524 msgid "sha256" msgstr "sha256" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:482 +#: sssd.conf.5.xml:525 msgid "sha384" msgstr "sha384" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:483 +#: sssd.conf.5.xml:526 msgid "sha512" msgstr "sha512" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:486 +#: sssd.conf.5.xml:529 msgid "Default: sha1 (to allow compatibility with RFC5019-compliant responder)" msgstr "" "Predefinição: sha1 (para permitir compatibilidade com respondedor RFC5019-" "compatível)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:492 +#: sssd.conf.5.xml:535 msgid "no_verification" msgstr "no_verification" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:494 +#: sssd.conf.5.xml:537 msgid "" "Disables verification completely. This option should only be used for " "testing." @@ -815,12 +877,12 @@ msgstr "" "testes." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:500 +#: sssd.conf.5.xml:543 msgid "partial_chain" msgstr "partial_chain" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:502 +#: sssd.conf.5.xml:545 msgid "" "Allow verification to succeed even if a <replaceable>complete</replaceable> " "chain cannot be built to a self-signed trust-anchor, provided it is possible " @@ -832,12 +894,12 @@ msgstr "" "de confiança que pode não ser auto-assinado." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:511 +#: sssd.conf.5.xml:554 msgid "ocsp_default_responder=URL" msgstr "ocsp_default_responder=URL" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:513 +#: sssd.conf.5.xml:556 msgid "" "Sets the OCSP default responder which should be used instead of the one " "mentioned in the certificate. URL must be replaced with the URL of the OCSP " @@ -848,12 +910,12 @@ msgstr "" "respondedor predefinido do OCSP ex. http://exemplo.com:80/ocsp." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:523 +#: sssd.conf.5.xml:566 msgid "ocsp_default_responder_signing_cert=NAME" msgstr "ocsp_default_responder_signing_cert=NOME" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:525 +#: sssd.conf.5.xml:568 msgid "" "This option is currently ignored. All needed certificates must be available " "in the PEM file given by pam_cert_db_path." @@ -862,12 +924,12 @@ msgstr "" "de estar disponíveis no ficheiro PEM dado por pam_cert_db_path." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:533 +#: sssd.conf.5.xml:576 msgid "crl_file=/PATH/TO/CRL/FILE" msgstr "crl_file=/CAMINHO/PARA/FICHEIRO/CRL" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:535 +#: sssd.conf.5.xml:578 msgid "" "Use the Certificate Revocation List (CRL) from the given file during the " "verification of the certificate. The CRL must be given in PEM format, see " @@ -880,12 +942,12 @@ msgstr "" "manvolnum> </citerefentry> para detalhes." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:548 +#: sssd.conf.5.xml:591 msgid "soft_crl" msgstr "soft_crl" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:551 +#: sssd.conf.5.xml:594 msgid "" "If a Certificate Revocation List (CRL) is expired ignore the expiration " "time of the CRL and check the related certificates with the expired CRL. " @@ -898,7 +960,7 @@ msgstr "" "não pode ser renovada." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:447 +#: sssd.conf.5.xml:490 msgid "" "With this parameter the certificate verification can be tuned with a comma " "separated list of options. Supported options are: <placeholder " @@ -909,24 +971,24 @@ msgstr "" "<placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:564 +#: sssd.conf.5.xml:607 msgid "Unknown options are reported but ignored." msgstr "As opções desconhecidas são reportadas mas ignoradas." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:567 +#: sssd.conf.5.xml:610 msgid "Default: not set, i.e. do not restrict certificate verification" msgstr "" "Predefinição: não definida, isto é, não restringe a verificação de " "certificados" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:573 +#: sssd.conf.5.xml:616 msgid "disable_netlink (boolean)" msgstr "disable_netlink (booleano)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:576 +#: sssd.conf.5.xml:619 msgid "" "SSSD hooks into the netlink interface to monitor changes to routes, " "addresses, links and trigger certain actions." @@ -935,7 +997,7 @@ msgstr "" "endereços, ligações e despoleta certas acções." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:581 +#: sssd.conf.5.xml:624 msgid "" "The SSSD state changes caused by netlink events may be undesirable and can " "be disabled by setting this option to 'true'" @@ -944,17 +1006,19 @@ msgstr "" "indesejáveis e podem ser desativados ao definir esta opção para 'true'" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:586 +#: sssd.conf.5.xml:629 msgid "Default: false (netlink changes are detected)" msgstr "Predefinição: false (alterações netlink são detetadas)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:591 -msgid "domain_resolution_order" +#: sssd.conf.5.xml:634 +#, fuzzy +#| msgid "domain_resolution_order" +msgid "domain_resolution_order (string)" msgstr "domain_resolution_order" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:594 +#: sssd.conf.5.xml:637 msgid "" "Comma separated list of domains and subdomains representing the lookup order " "that will be followed. The list doesn't have to include all possible " @@ -971,7 +1035,7 @@ msgstr "" "irão ser vistos numa ordem aleatória para cada domínio pai." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:606 +#: sssd.conf.5.xml:649 msgid "" "Please, note that when this option is set the output format of all commands " "is always fully-qualified even when using short names for input. In case " @@ -1000,19 +1064,20 @@ msgstr "" "sobrepor-se entre domínios." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:630 sssd.conf.5.xml:1697 sssd.conf.5.xml:4224 -#: sssd-ad.5.xml:187 sssd-ad.5.xml:328 sssd-ad.5.xml:342 sssd-idp.5.xml:108 -#: sssd-idp.5.xml:132 sssd-idp.5.xml:145 sssd-idp.5.xml:159 sssd-idp.5.xml:180 +#: sssd.conf.5.xml:673 sssd.conf.5.xml:1026 sssd.conf.5.xml:1689 +#: sssd.conf.5.xml:4429 sssd-ad.5.xml:187 sssd-ad.5.xml:328 sssd-ad.5.xml:342 +#: sssd-idp.5.xml:112 sssd-idp.5.xml:136 sssd-idp.5.xml:149 sssd-idp.5.xml:167 +#: sssd-idp.5.xml:188 msgid "Default: Not set" msgstr "Predefinição: Não definida" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:635 +#: sssd.conf.5.xml:678 msgid "implicit_pac_responder (boolean)" msgstr "implicit_pac_responder (booleano)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:638 +#: sssd.conf.5.xml:681 msgid "" "The PAC responder is enabled automatically for the IPA and AD provider to " "evaluate and check the PAC. If it has to be disabled set this option to " @@ -1023,12 +1088,12 @@ msgstr "" "opção para 'false'." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:649 +#: sssd.conf.5.xml:692 msgid "core_dumpable (boolean)" msgstr "core_dumpable (booleano)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:652 +#: sssd.conf.5.xml:695 msgid "" "This option can be used for general system hardening: setting it to 'false' " "forbids core dumps for all SSSD processes to avoid leaking plain text " @@ -1042,7 +1107,7 @@ msgstr "" "detalhes." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:660 +#: sssd.conf.5.xml:703 msgid "" "Take a note that this setting has no effect for 'ldap_child', 'krb5_child' " "and 'sssd_pam' as those privileged binaries can have a copy of a host keytab " @@ -1055,17 +1120,17 @@ msgstr "" "governado pela definição de sistema /proc/sys/fs/suid_dumpable." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:673 +#: sssd.conf.5.xml:716 msgid "passkey_verification (string)" msgstr "passkey_verification (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:681 +#: sssd.conf.5.xml:724 msgid "user_verification (boolean)" msgstr "user_verification (boolean)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:683 +#: sssd.conf.5.xml:726 msgid "" "Enable or disable the user verification (i.e. PIN, fingerprint) during " "authentication. If enabled, the PIN will always be requested." @@ -1074,7 +1139,7 @@ msgstr "" "digital) durante a autenticação. Se ativo, o PIN será sempre pedido." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:689 +#: sssd.conf.5.xml:732 msgid "" "The default is that the key settings decide what to do. In the IPA or " "kerberos pre-authentication case, this value will be overwritten by the " @@ -1085,7 +1150,7 @@ msgstr "" "servidor." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:676 +#: sssd.conf.5.xml:719 msgid "" "With this parameter the passkey verification can be tuned with a comma " "separated list of options. Supported options are: <placeholder " @@ -1096,7 +1161,7 @@ msgstr "" "type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:213 +#: sssd.conf.5.xml:256 msgid "" "Individual pieces of SSSD functionality are provided by special SSSD " "services that are started and stopped together with SSSD. The services are " @@ -1113,12 +1178,12 @@ msgstr "" "<placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:708 +#: sssd.conf.5.xml:751 msgid "SERVICES SECTIONS" msgstr "SECÇÕES DE SERVIÇOS" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:710 +#: sssd.conf.5.xml:753 msgid "" "Settings that can be used to configure different services are described in " "this section. They should reside in the [<replaceable>$NAME</replaceable>] " @@ -1131,28 +1196,36 @@ msgstr "" "[nss]</quote>" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:717 +#: sssd.conf.5.xml:760 msgid "General service configuration options" msgstr "Opções de configuração de serviços gerais" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:719 +#: sssd.conf.5.xml:762 msgid "These options can be used to configure any service." msgstr "Estas opções podem ser usadas para configurar qualquer serviço." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:723 -msgid "fd_limit" -msgstr "fd_limit" +#: sssd.conf.5.xml:766 +#, fuzzy +#| msgid "wildcard_limit (integer)" +msgid "fd_limit (integer)" +msgstr "wildcard_limit (inteiro)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:726 +#: sssd.conf.5.xml:769 +#, fuzzy +#| msgid "" +#| "This option specifies the maximum number of file descriptors that may be " +#| "opened at one time by this SSSD process. On systems where SSSD is granted " +#| "the CAP_SYS_RESOURCE capability, this will be an absolute setting. On " +#| "systems without this capability, the resulting value will be the lower " +#| "value of this or the limits.conf \"hard\" limit." msgid "" "This option specifies the maximum number of file descriptors that may be " -"opened at one time by this SSSD process. On systems where SSSD is granted " -"the CAP_SYS_RESOURCE capability, this will be an absolute setting. On " -"systems without this capability, the resulting value will be the lower value " -"of this or the limits.conf \"hard\" limit." +"opened at one time by this SSSD process. Note this value will be capped by " +"the init system at the startup of SSSD, see e.g. man systemd.exec for " +"details." msgstr "" "Esta opção especifica o número máximo de descritores de ficheiro que podem " "ser abertos de uma vez por estes processos do SSSD. Em sistemas onde o SSSD " @@ -1161,17 +1234,19 @@ msgstr "" "valor disto ou limite \"hard\" do limits.conf." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:735 +#: sssd.conf.5.xml:776 msgid "Default: 8192 (or limits.conf \"hard\" limit)" msgstr "Predefinição: 8192 (ou limite \"hard\" de limits.conf)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:740 -msgid "client_idle_timeout" -msgstr "client_idle_timeout" +#: sssd.conf.5.xml:781 +#, fuzzy +#| msgid "offline_timeout (integer)" +msgid "client_idle_timeout (integer)" +msgstr "offline_timeout (inteiro)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:743 +#: sssd.conf.5.xml:784 msgid "" "This option specifies the number of seconds that a client of an SSSD process " "can hold onto a file descriptor without communicating on it. This value is " @@ -1186,168 +1261,19 @@ msgstr "" "menor, será ajustado para 10 segundos." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:752 +#: sssd.conf.5.xml:793 msgid "Default: 60, KCM: 300" msgstr "Predefinição: 60, KCM: 300" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:757 -msgid "offline_timeout (integer)" -msgstr "offline_timeout (inteiro)" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:760 -msgid "" -"When SSSD switches to offline mode the amount of time before it tries to go " -"back online will increase based upon the time spent disconnected. By " -"default SSSD uses incremental behaviour to calculate delay in between " -"retries. So, the wait time for a given retry will be longer than the wait " -"time for the previous ones. After each unsuccessful attempt to go online, " -"the new interval is recalculated by the following:" -msgstr "" -"Quando o SSSD comuta para modo offline a quantidade de tempo antes de tentar " -"voltar online irá aumentar com base no tempo que passou desligado. Por " -"predefinição o SSSD usa comportamento incremental para calcular o atraso " -"entre tentativas. Assim, o tempo de espera para uma dada tentativa será " -"maior que o tempo de espera das anteriores. Após cada tentativa sem " -"sucesso de ir online, o novo intervalo é recalculado pelo seguinte:" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:771 sssd.conf.5.xml:827 -msgid "" -"new_delay = Minimum(old_delay * 2, offline_timeout_max) + " -"random[0...offline_timeout_random_offset]" -msgstr "" -"new_delay = Minimum(old_delay * 2, offline_timeout_max) + " -"random[0...offline_timeout_random_offset]" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:774 -msgid "" -"The offline_timeout default value is 60. The offline_timeout_max default " -"value is 3600. The offline_timeout_random_offset default value is 30. The " -"end result is amount of seconds before next retry." -msgstr "" -"O valor predefinido de offline_timeout é 60. O valor predefinido de " -"offline_timeout_max é 3600. O valor predefinido de " -"offline_timeout_random_offset é 30. O resultado final é a quantidade de " -"segundos antes da próxima tentativa." - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:780 -msgid "" -"Note that the maximum length of each interval is defined by " -"offline_timeout_max (apart of random part)." -msgstr "" -"Note que a duração máxima de cada intervalo é definida por " -"offline_timeout_max (à parte da parte aleatória)." - -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:784 sssd.conf.5.xml:1110 sssd.conf.5.xml:1490 -#: sssd.conf.5.xml:1791 sssd-ldap.5.xml:550 -msgid "Default: 60" -msgstr "Predefinição: 60" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:789 -msgid "offline_timeout_max (integer)" -msgstr "offline_timeout_max (inteiro)" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:792 -msgid "" -"Controls by how much the time between attempts to go online can be " -"incremented following unsuccessful attempts to go online." -msgstr "" -"Controla quanto o tempo entre tentativas de ir online pode ser incrementado " -"a seguir a tentativas de ir online sem sucesso." - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:797 -msgid "A value of 0 disables the incrementing behaviour." -msgstr "Um valor de 0 desactiva o comportamento incremental." - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:800 -msgid "" -"The value of this parameter should be set in correlation to offline_timeout " -"parameter value." -msgstr "" -"O valor deste parâmetro deve ser definido em correlação com o valor do " -"parâmetro offline_timeout." - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:804 -msgid "" -"With offline_timeout set to 60 (default value) there is no point in setting " -"offlinet_timeout_max to less than 120 as it will saturate instantly. General " -"rule here should be to set offline_timeout_max to at least 4 times " -"offline_timeout." -msgstr "" -"Com offline_timeout definido para 60 (valor predefinido) não faz sentido " -"definir offline_timeout_max para menos de 120 pois isso iria saturar " -"instantaneamente. Geralmente a regra aqui deverá ser definir " -"offline_timeout_max para pelo menos 4 vezes o offline_timeout." - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:810 -msgid "" -"Although a value between 0 and offline_timeout may be specified, it has the " -"effect of overriding the offline_timeout value so is of little use." -msgstr "" -"Apesar de poder ser especificado um valor entre 0 e offline_timeout, isso " -"tem o efeito de sobrepor o valor offline_timeout, assim tem pouca utilidade." - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:815 -msgid "Default: 3600" -msgstr "Predefinição: 3600" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:820 -msgid "offline_timeout_random_offset (integer)" -msgstr "offline_timeout_random_offset (inteiro)" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:823 -msgid "" -"When SSSD is in offline mode it keeps probing backend servers in specified " -"time intervals:" -msgstr "" -"Quando o SSSD está em modo offline continua a fazer provas a servidores " -"backend em intervalos de tempo especificados:" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:830 -msgid "" -"This parameter controls the value of the random offset used for the above " -"equation. Final random_offset value will be random number in range:" -msgstr "" -"Este parâmetro controla o valor do desvio aleatório usado para a equação em " -"cima. O valor random_offset final será um número aleatório dentro da gama:" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:835 -msgid "[0 - offline_timeout_random_offset]" -msgstr "[0 - offline_timeout_random_offset]" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:838 -msgid "A value of 0 disables the random offset addition." -msgstr "Um valor de 0 desactiva a adição de desvio aleatório." - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:841 -msgid "Default: 30" -msgstr "Predefinição: 30" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:846 -msgid "responder_idle_timeout" +#: sssd.conf.5.xml:798 +#, fuzzy +#| msgid "responder_idle_timeout" +msgid "responder_idle_timeout (integer)" msgstr "responder_idle_timeout" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:849 +#: sssd.conf.5.xml:801 msgid "" "This option specifies the number of seconds that an SSSD responder process " "can be up without being used. This value is limited in order to avoid " @@ -1366,18 +1292,20 @@ msgstr "" "activados ou em socket ou em D-Bus." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:863 sssd.conf.5.xml:1123 sssd.conf.5.xml:2248 +#: sssd.conf.5.xml:815 sssd.conf.5.xml:1079 sssd.conf.5.xml:2285 #: sssd-ldap.5.xml:377 msgid "Default: 300" msgstr "Predefinição: 300" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:868 -msgid "cache_first" +#: sssd.conf.5.xml:820 +#, fuzzy +#| msgid "cache_first" +msgid "cache_first (boolean)" msgstr "cache_first" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:871 +#: sssd.conf.5.xml:823 msgid "" "This option specifies whether the responder should query all caches before " "querying the Data Providers." @@ -1386,25 +1314,30 @@ msgstr "" "de questionar os Provedores de Dados." #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:883 +#: sssd.conf.5.xml:835 msgid "NSS configuration options" msgstr "Opções de configuração do NSS" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:885 +#: sssd.conf.5.xml:837 +#, fuzzy +#| msgid "" +#| "These options can be used to configure the Name Service Switch (NSS) " +#| "service." msgid "" -"These options can be used to configure the Name Service Switch (NSS) service." +"These options can be used to configure the Name Service Switch (NSS) service " +"and should be specified under the <quote>[nss]</quote> section." msgstr "" "Estas opções podem ser usadas para configurar o serviço Name Service Switch " "(NSS)." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:890 +#: sssd.conf.5.xml:843 msgid "enum_cache_timeout (integer)" msgstr "enum_cache_timeout (inteiro)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:893 +#: sssd.conf.5.xml:846 msgid "" "How many seconds should nss_sss cache enumerations (requests for info about " "all users)" @@ -1413,17 +1346,17 @@ msgstr "" "informação sobre todos os utilizadores)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:897 +#: sssd.conf.5.xml:850 msgid "Default: 120" msgstr "Predefinição: 120" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:902 +#: sssd.conf.5.xml:855 msgid "entry_cache_nowait_percentage (integer)" msgstr "entry_cache_nowait_percentage (inteiro)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:905 +#: sssd.conf.5.xml:858 msgid "" "The entry cache can be set to automatically update entries in the background " "if they are requested beyond a percentage of the entry_cache_timeout value " @@ -1434,7 +1367,7 @@ msgstr "" "percentagem do valor entry_cache_timeout do domínio." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:911 +#: sssd.conf.5.xml:864 msgid "" "For example, if the domain's entry_cache_timeout is set to 30s and " "entry_cache_nowait_percentage is set to 50 (percent), entries that come in " @@ -1450,7 +1383,7 @@ msgstr "" "actualização à cache." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:921 +#: sssd.conf.5.xml:874 msgid "" "Valid values for this option are 0-99 and represent a percentage of the " "entry_cache_timeout for each domain. For performance reasons, this " @@ -1463,17 +1396,17 @@ msgstr "" "segundos. (0 desactiva esta funcionalidade)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:929 sssd.conf.5.xml:2061 +#: sssd.conf.5.xml:882 sssd.conf.5.xml:2093 msgid "Default: 50" msgstr "Predefinição: 50" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:934 +#: sssd.conf.5.xml:887 msgid "entry_negative_timeout (integer)" msgstr "entry_negative_timeout (inteiro)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:937 +#: sssd.conf.5.xml:890 msgid "" "Specifies for how many seconds nss_sss should cache negative cache hits " "(that is, queries for invalid database entries, like nonexistent ones) " @@ -1484,17 +1417,17 @@ msgstr "" "dados, como as não existentes) antes de perguntar de novo ao backend." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:943 sssd.conf.5.xml:1685 sssd.conf.5.xml:2085 +#: sssd.conf.5.xml:896 sssd.conf.5.xml:1677 sssd.conf.5.xml:2119 msgid "Default: 15" msgstr "Predefinição: 15" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:948 +#: sssd.conf.5.xml:901 msgid "filter_users, filter_groups (string)" msgstr "filter_users, filter_groups (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:951 +#: sssd.conf.5.xml:904 msgid "" "Exclude certain users or groups from being fetched from the sss NSS " "database. This is particularly useful for system accounts. This option can " @@ -1508,7 +1441,7 @@ msgstr "" "por um nome principal de utilizador (UPN)." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:959 +#: sssd.conf.5.xml:912 msgid "" "NOTE: The filter_groups option doesn't affect inheritance of nested group " "members, since filtering happens after they are propagated for returning via " @@ -1521,30 +1454,35 @@ msgstr "" "ter os utilizadores membros na listagem posterior." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:967 +#: sssd.conf.5.xml:920 msgid "Default: root" msgstr "Predefinição: root" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:972 -msgid "filter_users_in_groups (bool)" +#: sssd.conf.5.xml:925 +#, fuzzy +#| msgid "filter_users_in_groups (bool)" +msgid "filter_users_in_groups (boolean)" msgstr "filter_users_in_groups (booleano)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:975 +#: sssd.conf.5.xml:928 +#, fuzzy +#| msgid "" +#| "If you want filtered user still be group members set this option to false." msgid "" -"If you want filtered user still be group members set this option to false." +"If you want filtered users to remain group members set this option to false" msgstr "" "Se você deseja que o utilizador filtrado ainda seja membro de grupo defina " "esta opção para false." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:986 +#: sssd.conf.5.xml:939 msgid "fallback_homedir (string)" msgstr "fallback_homedir (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:989 +#: sssd.conf.5.xml:942 msgid "" "Set a default template for a user's home directory if one is not specified " "explicitly by the domain's data provider." @@ -1553,7 +1491,7 @@ msgstr "" "foi especificado explicitamente pelo provedor de dados do domínio." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:994 +#: sssd.conf.5.xml:947 msgid "" "The available values for this option are the same as for override_homedir." msgstr "" @@ -1561,7 +1499,7 @@ msgstr "" "override_homedir." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1000 +#: sssd.conf.5.xml:953 #, no-wrap msgid "" "fallback_homedir = /home/%u\n" @@ -1571,25 +1509,25 @@ msgstr "" " " #. type: Content of: <varlistentry><listitem><para> -#: sssd.conf.5.xml:998 sssd.conf.5.xml:1557 sssd.conf.5.xml:1576 -#: sssd.conf.5.xml:1653 sssd-krb5.5.xml:451 include/override_homedir.xml:78 +#: sssd.conf.5.xml:951 sssd.conf.5.xml:1524 sssd.conf.5.xml:1543 +#: sssd.conf.5.xml:1645 sssd-krb5.5.xml:451 include/override_homedir.xml:78 msgid "example: <placeholder type=\"programlisting\" id=\"0\"/>" msgstr "exemplo: <placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1004 +#: sssd.conf.5.xml:957 msgid "Default: not set (no substitution for unset home directories)" msgstr "" "Predefinição: não definida (nenhum substituição para directórios home não " "definidos)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1010 +#: sssd.conf.5.xml:963 msgid "override_shell (string)" msgstr "override_shell (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1013 +#: sssd.conf.5.xml:966 msgid "" "Override the login shell for all users. This option supersedes any other " "shell options if it takes effect and can be set either in the [nss] section " @@ -1600,17 +1538,17 @@ msgstr "" "secção [nss] ou por-domínio." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1019 +#: sssd.conf.5.xml:972 msgid "Default: not set (SSSD will use the value retrieved from LDAP)" msgstr "Predefinição: não definida (o SSSD irá usar o valor obtido de LDAP)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1025 +#: sssd.conf.5.xml:978 msgid "allowed_shells (string)" msgstr "allowed_shells (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1028 +#: sssd.conf.5.xml:981 msgid "" "Restrict user shell to one of the listed values. The order of evaluation is:" msgstr "" @@ -1618,12 +1556,12 @@ msgstr "" "avaliação é:" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1031 +#: sssd.conf.5.xml:984 msgid "1. If the shell is present in <quote>/etc/shells</quote>, it is used." msgstr "1. Se a shell está presente em <quote>/etc/shells</quote>, é usada." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1035 +#: sssd.conf.5.xml:988 msgid "" "2. If the shell is in the allowed_shells list but not in <quote>/etc/shells</" "quote>, use the value of the shell_fallback parameter." @@ -1632,7 +1570,7 @@ msgstr "" "quote>, usa o valor do parâmetro shell_fallback." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1040 +#: sssd.conf.5.xml:993 msgid "" "3. If the shell is not in the allowed_shells list and not in <quote>/etc/" "shells</quote>, a nologin shell is used." @@ -1641,12 +1579,12 @@ msgstr "" "shells</quote>, é usada uma shell nologin." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1045 +#: sssd.conf.5.xml:998 msgid "The wildcard (*) can be used to allow any shell." msgstr "O asterisco (*) pode ser usado para permitir qualquer shell." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1048 +#: sssd.conf.5.xml:1001 msgid "" "The (*) is useful if you want to use shell_fallback in case that user's " "shell is not in <quote>/etc/shells</quote> and maintaining list of all " @@ -1657,12 +1595,12 @@ msgstr "" "todas as shells permitidas em allowed_shells seria grande sobrecarga." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1055 +#: sssd.conf.5.xml:1008 msgid "An empty string for shell is passed as-is to libc." msgstr "Uma string vazia para shell é passada como está ao libc." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1058 +#: sssd.conf.5.xml:1011 msgid "" "The <quote>/etc/shells</quote> is only read on SSSD start up, which means " "that a restart of the SSSD is required in case a new shell is installed." @@ -1672,28 +1610,28 @@ msgstr "" "instalada." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1062 +#: sssd.conf.5.xml:1015 msgid "Default: Not set. The user shell is automatically used." msgstr "" "Predefinição: Não definida. A shell do utilizador é automaticamente usada." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1067 +#: sssd.conf.5.xml:1020 msgid "vetoed_shells (string)" msgstr "vetoed_shells (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1070 +#: sssd.conf.5.xml:1023 msgid "Replace any instance of these shells with the shell_fallback" msgstr "Substitui qualquer instância destas shells por shell_fallback" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1075 +#: sssd.conf.5.xml:1031 msgid "shell_fallback (string)" msgstr "shell_fallback (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1078 +#: sssd.conf.5.xml:1034 msgid "" "The default shell to use if an allowed shell is not installed on the machine." msgstr "" @@ -1701,17 +1639,17 @@ msgstr "" "máquina." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1082 +#: sssd.conf.5.xml:1038 msgid "Default: /bin/sh" msgstr "Predefinição: /bin/sh" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1087 -msgid "default_shell" -msgstr "default_shell" +#: sssd.conf.5.xml:1043 +msgid "default_shell (string)" +msgstr "default_shell (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1090 +#: sssd.conf.5.xml:1046 msgid "" "The default shell to use if the provider does not return one during lookup. " "This option can be specified globally in the [nss] section or per-domain." @@ -1721,7 +1659,7 @@ msgstr "" "por-domínio." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1096 +#: sssd.conf.5.xml:1052 msgid "" "Default: not set (Return NULL if no shell is specified and rely on libc to " "substitute something sensible when necessary, usually /bin/sh)" @@ -1731,12 +1669,12 @@ msgstr "" "bin/sh)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1103 sssd.conf.5.xml:1483 +#: sssd.conf.5.xml:1059 sssd.conf.5.xml:1450 msgid "get_domains_timeout (int)" msgstr "get_domains_timeout (inteiro)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1106 sssd.conf.5.xml:1486 +#: sssd.conf.5.xml:1062 sssd.conf.5.xml:1453 msgid "" "Specifies time in seconds for which the list of subdomains will be " "considered valid." @@ -1744,13 +1682,19 @@ msgstr "" "Especifica o tempo em segundos no qual a lista de subdomínios será " "considerada válida." +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1066 sssd.conf.5.xml:1457 sssd.conf.5.xml:1788 +#: sssd.conf.5.xml:2862 sssd-ldap.5.xml:550 +msgid "Default: 60" +msgstr "Predefinição: 60" + #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1115 +#: sssd.conf.5.xml:1071 msgid "memcache_timeout (integer)" msgstr "memcache_timeout (inteiro)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1118 +#: sssd.conf.5.xml:1074 msgid "" "Specifies time in seconds for which records in the in-memory cache will be " "valid. Setting this option to zero will disable the in-memory cache." @@ -1759,7 +1703,7 @@ msgstr "" "válidos. Definir esta opção para zero irá desactivar a cache em-memória." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1126 +#: sssd.conf.5.xml:1082 msgid "" "WARNING: Disabling the in-memory cache will have significant negative impact " "on SSSD's performance and should only be used for testing." @@ -1768,8 +1712,8 @@ msgstr "" "significante na performance do SSSD e apenas deve ser usado para testes." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1132 sssd.conf.5.xml:1157 sssd.conf.5.xml:1182 -#: sssd.conf.5.xml:1207 sssd.conf.5.xml:1234 +#: sssd.conf.5.xml:1088 sssd.conf.5.xml:1113 sssd.conf.5.xml:1138 +#: sssd.conf.5.xml:1163 sssd.conf.5.xml:1190 msgid "" "NOTE: If the environment variable SSS_NSS_USE_MEMCACHE is set to \"NO\", " "client applications will not use the fast in-memory cache." @@ -1778,12 +1722,12 @@ msgstr "" "\"NO\", as aplicações do cliente não irão usar a rápida cache em-memória." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1140 +#: sssd.conf.5.xml:1096 msgid "memcache_size_passwd (integer)" msgstr "memcache_size_passwd (inteiro)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1143 +#: sssd.conf.5.xml:1099 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for passwd requests. Setting the size to 0 will disable the passwd in-" @@ -1794,13 +1738,13 @@ msgstr "" "cache em-memória de passwd." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1149 sssd.conf.5.xml:2888 sssd-ldap.5.xml:604 +#: sssd.conf.5.xml:1105 sssd.conf.5.xml:3013 sssd-ldap.5.xml:604 msgid "Default: 8" msgstr "Predefinição: 8" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1152 sssd.conf.5.xml:1177 sssd.conf.5.xml:1202 -#: sssd.conf.5.xml:1229 +#: sssd.conf.5.xml:1108 sssd.conf.5.xml:1133 sssd.conf.5.xml:1158 +#: sssd.conf.5.xml:1185 msgid "" "WARNING: Disabled or too small in-memory cache can have significant negative " "impact on SSSD's performance." @@ -1809,12 +1753,12 @@ msgstr "" "negativo significante na performance do SSSD." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1165 +#: sssd.conf.5.xml:1121 msgid "memcache_size_group (integer)" msgstr "memcache_size_group (inteiro)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1168 +#: sssd.conf.5.xml:1124 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for group requests. Setting the size to 0 will disable the group in-memory " @@ -1825,19 +1769,19 @@ msgstr "" "cache em-memória de grupo." #. type: Content of: <variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1174 sssd.conf.5.xml:1226 sssd.conf.5.xml:3656 +#: sssd.conf.5.xml:1130 sssd.conf.5.xml:1182 sssd.conf.5.xml:3835 #: sssd-ldap.5.xml:534 sssd-ldap.5.xml:581 include/failover.xml:116 #: include/krb5_options.xml:11 msgid "Default: 6" msgstr "Predefinição: 6" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1190 +#: sssd.conf.5.xml:1146 msgid "memcache_size_initgroups (integer)" msgstr "memcache_size_initgroups (inteiro)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1193 +#: sssd.conf.5.xml:1149 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for initgroups requests. Setting the size to 0 will disable the initgroups " @@ -1848,12 +1792,12 @@ msgstr "" "a cache em-memória de initgroups." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1215 +#: sssd.conf.5.xml:1171 msgid "memcache_size_sid (integer)" msgstr "memcache_size_sid (inteiro)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1218 +#: sssd.conf.5.xml:1174 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for SID related requests. Only SID-by-ID and ID-by-SID requests are " @@ -1866,12 +1810,12 @@ msgstr "" "tamanho para 0 irá desactivar a cache em-memória de SID." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1242 sssd-ifp.5.xml:90 +#: sssd.conf.5.xml:1198 sssd-ifp.5.xml:90 msgid "user_attributes (string)" msgstr "user_attributes (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1245 +#: sssd.conf.5.xml:1201 msgid "" "Some of the additional NSS responder requests can return more attributes " "than just the POSIX ones defined by the NSS interface. The list of " @@ -1888,7 +1832,7 @@ msgstr "" "citerefentry> para detalhes) mas sem valores predefinidos." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1258 +#: sssd.conf.5.xml:1214 msgid "" "To make configuration more easy the NSS responder will check the InfoPipe " "option if it is not set for the NSS responder." @@ -1897,17 +1841,17 @@ msgstr "" "InfoPipe se não está definida para o respondedor NSS." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1263 +#: sssd.conf.5.xml:1219 msgid "Default: not set, fallback to InfoPipe option" msgstr "Predefinição: não definida, cai para a opção InfoPipe" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1268 +#: sssd.conf.5.xml:1224 msgid "pwfield (string)" msgstr "pwfield (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1271 +#: sssd.conf.5.xml:1227 msgid "" "The value that NSS operations that return users or groups will return for " "the <quote>password</quote> field." @@ -1916,49 +1860,61 @@ msgstr "" "retornar para o campo <quote>password</quote>." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1276 -msgid "Default: <quote>*</quote>" -msgstr "Predefinição: <quote>*</quote>" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1279 +#: sssd.conf.5.xml:1232 msgid "" -"Note: This option can also be set per-domain which overwrites the value in " -"[nss] section." +"This option can also be set per-domain, which overwrites the value in the " +"<quote>[nss]</quote> section for that domain. This is particularly useful " +"when using a proxy domain with <option>proxy_lib_name=files</option> and a " +"<option>proxy_pam_target</option> other than <quote>sssd-shadowutils</" +"quote>. In that case, SSSD returns <quote>*</quote> for the password field " +"by default, which causes <command>pam_unix</command> to treat all accounts " +"as locked. Setting <option>pwfield = x</option> in the domain section " +"restores the expected behavior." msgstr "" -"Nota: Esta opção também pode ser definida por-domínio o que sobrepõe o valor " -"na secção [nss]." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1283 +#: sssd.conf.5.xml:1246 +msgid "Default: <quote>*</quote>" +msgstr "Predefinição: <quote>*</quote>" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1249 +#, fuzzy +#| msgid "" +#| "Default: <quote>not set</quote> (remote domains), <quote>x</quote> (proxy " +#| "domain with nss_files and sssd-shadowutils target)" msgid "" -"Default: <quote>not set</quote> (remote domains), <quote>x</quote> (proxy " -"domain with nss_files and sssd-shadowutils target)" +"Default (per-domain): <quote>not set</quote> (remote domains), <quote>x</" +"quote> (proxy domain with nss_files and sssd-shadowutils target)" msgstr "" "Predefinição: <quote>não definida</quote> (domínios remotos), <quote>x</" "quote> (domínios proxy com nss_files e alvo sssd-shadowutils)" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:1292 +#: sssd.conf.5.xml:1258 msgid "PAM configuration options" msgstr "Opções de configuração do PAM" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:1294 +#: sssd.conf.5.xml:1260 +#, fuzzy +#| msgid "" +#| "These options can be used to configure the Pluggable Authentication " +#| "Module (PAM) service." msgid "" "These options can be used to configure the Pluggable Authentication Module " -"(PAM) service." +"(PAM) service and should be specified under the <quote>[pam]</quote> section." msgstr "" "Estas opções podem ser usadas para configurar o serviço Pluggable " "Authentication Module (PAM)." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1299 +#: sssd.conf.5.xml:1266 msgid "offline_credentials_expiration (integer)" msgstr "offline_credentials_expiration (inteiro)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1302 +#: sssd.conf.5.xml:1269 msgid "" "If the authentication provider is offline, how long should we allow cached " "logins (in days since the last successful online login)." @@ -1967,17 +1923,17 @@ msgstr "" "permitir logins em cache (em dias desde o último login online com sucesso)." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1307 sssd.conf.5.xml:1320 +#: sssd.conf.5.xml:1274 sssd.conf.5.xml:1287 msgid "Default: 0 (No limit)" msgstr "Predefinição: 0 (Sem Limite)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1313 +#: sssd.conf.5.xml:1280 msgid "offline_failed_login_attempts (integer)" msgstr "offline_failed_login_attempts (inteiro)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1316 +#: sssd.conf.5.xml:1283 msgid "" "If the authentication provider is offline, how many failed login attempts " "are allowed." @@ -1986,12 +1942,12 @@ msgstr "" "falhadas são permitidas." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1326 +#: sssd.conf.5.xml:1293 msgid "offline_failed_login_delay (integer)" msgstr "offline_failed_login_delay (inteiro)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1329 +#: sssd.conf.5.xml:1296 msgid "" "The time in minutes which has to pass after offline_failed_login_attempts " "has been reached before a new login attempt is possible." @@ -2001,7 +1957,7 @@ msgstr "" "login." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1334 +#: sssd.conf.5.xml:1301 msgid "" "If set to 0 the user cannot authenticate offline if " "offline_failed_login_attempts has been reached. Only a successful online " @@ -2012,17 +1968,17 @@ msgstr "" "sucesso pode activar a autenticação offline outra vez." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1340 sssd.conf.5.xml:1450 +#: sssd.conf.5.xml:1307 sssd.conf.5.xml:1417 msgid "Default: 5" msgstr "Predefinição: 5" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1346 +#: sssd.conf.5.xml:1313 msgid "pam_verbosity (integer)" msgstr "pam_verbosity (inteiro)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1349 +#: sssd.conf.5.xml:1316 msgid "" "Controls what kind of messages are shown to the user during authentication. " "The higher the number to more messages are displayed." @@ -2031,43 +1987,43 @@ msgstr "" "autenticação. Quanto mais alto o número mais mensagens são mostradas." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1354 +#: sssd.conf.5.xml:1321 msgid "Currently sssd supports the following values:" msgstr "Actualmente o sssd suporta os seguintes valores:" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1357 +#: sssd.conf.5.xml:1324 msgid "<emphasis>0</emphasis>: do not show any message" msgstr "<emphasis>0</emphasis>: não mostra nenhuma mensagem" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1360 +#: sssd.conf.5.xml:1327 msgid "<emphasis>1</emphasis>: show only important messages" msgstr "<emphasis>1</emphasis>: mostra apenas mensagens importantes" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1364 +#: sssd.conf.5.xml:1331 msgid "<emphasis>2</emphasis>: show informational messages" msgstr "<emphasis>2</emphasis>: mostra mensagens informativas" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1367 +#: sssd.conf.5.xml:1334 msgid "<emphasis>3</emphasis>: show all messages and debug information" msgstr "" "<emphasis>3</emphasis>: mostra todas as mensagens e informação de depuração" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1371 sssd.8.xml:63 +#: sssd.conf.5.xml:1338 sssd.8.xml:63 msgid "Default: 1" msgstr "Predefinição: 1" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1377 +#: sssd.conf.5.xml:1344 msgid "pam_response_filter (string)" msgstr "pam_response_filter (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1380 +#: sssd.conf.5.xml:1347 msgid "" "A comma separated list of strings which allows to remove (filter) data sent " "by the PAM responder to pam_sss PAM module. There are different kind of " @@ -2080,7 +2036,7 @@ msgstr "" "utilizador ou variáveis de ambiente que devem ser definidas pelo pam_sss." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1388 +#: sssd.conf.5.xml:1355 msgid "" "While messages already can be controlled with the help of the pam_verbosity " "option this option allows to filter out other kind of responses as well." @@ -2089,37 +2045,37 @@ msgstr "" "pam_verbosity, esta opção permite filtrar também outro tipo de respostas." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1395 +#: sssd.conf.5.xml:1362 msgid "ENV" msgstr "ENV" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1396 +#: sssd.conf.5.xml:1363 msgid "Do not send any environment variables to any service." msgstr "Não envia nenhumas variáveis de ambiente para nenhum serviço." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1399 +#: sssd.conf.5.xml:1366 msgid "ENV:var_name" msgstr "ENV:var_name" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1400 +#: sssd.conf.5.xml:1367 msgid "Do not send environment variable var_name to any service." msgstr "Não envia a variável de ambiente var_name para nenhum serviço." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1404 +#: sssd.conf.5.xml:1371 msgid "ENV:var_name:service" msgstr "ENV:var_name:service" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1405 +#: sssd.conf.5.xml:1372 msgid "Do not send environment variable var_name to service." msgstr "Não envia a variável de ambiente var_name para o serviço." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1393 +#: sssd.conf.5.xml:1360 msgid "" "Currently the following filters are supported: <placeholder " "type=\"variablelist\" id=\"0\"/>" @@ -2128,7 +2084,7 @@ msgstr "" "type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1412 +#: sssd.conf.5.xml:1379 msgid "" "The list of strings can either be the list of filters which would set this " "list of filters and overwrite the defaults. Or each element of the list can " @@ -2145,24 +2101,24 @@ msgstr "" "misturar ambos os estilos." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1423 +#: sssd.conf.5.xml:1390 msgid "Default: ENV:KRB5CCNAME:sudo, ENV:KRB5CCNAME:sudo-i" msgstr "Predefinição: ENV:KRB5CCNAME:sudo, ENV:KRB5CCNAME:sudo-i" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1426 +#: sssd.conf.5.xml:1393 msgid "" "Example: -ENV:KRB5CCNAME:sudo-i will remove the filter from the default list" msgstr "" "Exemplo: -ENV:KRB5CCNAME:sudo-i irá remover o filtro da lista predefinida" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1433 +#: sssd.conf.5.xml:1400 msgid "pam_id_timeout (integer)" msgstr "pam_id_timeout (inteiro)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1436 +#: sssd.conf.5.xml:1403 msgid "" "For any PAM request while SSSD is online, the SSSD will attempt to " "immediately update the cached identity information for the user in order to " @@ -2174,7 +2130,7 @@ msgstr "" "mais recente." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1442 +#: sssd.conf.5.xml:1409 msgid "" "A complete PAM conversation may perform multiple PAM requests, such as " "account management and session opening. This option controls (on a per-" @@ -2188,17 +2144,17 @@ msgstr "" "identidade." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1456 +#: sssd.conf.5.xml:1423 msgid "pam_pwd_expiration_warning (integer)" msgstr "pam_pwd_expiration_warning (inteiro)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1459 sssd.conf.5.xml:2912 +#: sssd.conf.5.xml:1426 sssd.conf.5.xml:3037 msgid "Display a warning N days before the password expires." msgstr "Mostra um aviso N dias antes da palavra passe expirar." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1462 +#: sssd.conf.5.xml:1429 msgid "" "Please note that the backend server has to provide information about the " "expiration time of the password. If this information is missing, sssd " @@ -2209,7 +2165,7 @@ msgstr "" "sssd não pode mostrar um aviso." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1468 sssd.conf.5.xml:2915 +#: sssd.conf.5.xml:1435 sssd.conf.5.xml:3040 msgid "" "If zero is set, then this filter is not applied, i.e. if the expiration " "warning was received from backend server, it will automatically be displayed." @@ -2218,7 +2174,7 @@ msgstr "" "de expiração foi recebido do servidor backend, será mostrado automaticamente." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1473 +#: sssd.conf.5.xml:1440 msgid "" "This setting can be overridden by setting <emphasis>pwd_expiration_warning</" "emphasis> for a particular domain." @@ -2227,18 +2183,18 @@ msgstr "" "pwd_expiration_warning</emphasis> para um domínio particular." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1478 sssd.conf.5.xml:3913 sssd-ldap.5.xml:662 +#: sssd.conf.5.xml:1445 sssd.conf.5.xml:4118 sssd-ldap.5.xml:662 #: sssd-ldap.5.xml:1733 sssd.8.xml:79 msgid "Default: 0" msgstr "Predefinição: 0" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1495 +#: sssd.conf.5.xml:1462 msgid "pam_trusted_users (string)" msgstr "pam_trusted_users (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1498 +#: sssd.conf.5.xml:1465 msgid "" "Specifies the comma-separated list of UID values or user names that are " "allowed to run PAM conversations against trusted domains. Users not " @@ -2253,14 +2209,14 @@ msgstr "" "nomes de utilizadores são resolvidos em UIDs no arranque." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1508 +#: sssd.conf.5.xml:1475 msgid "Default: All users are considered trusted by default" msgstr "" "Predefinição: Todos os utilizadores são considerados de confiança por " "predefinição" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1512 +#: sssd.conf.5.xml:1479 msgid "" "Please note that UID 0 is always allowed to access the PAM responder even in " "case it is not in the pam_trusted_users list." @@ -2269,12 +2225,12 @@ msgstr "" "mesmo no caso de não estar na lista pam_trusted_users." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1519 +#: sssd.conf.5.xml:1486 msgid "pam_public_domains (string)" msgstr "pam_public_domains (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1522 +#: sssd.conf.5.xml:1489 msgid "" "Specifies the comma-separated list of domain names that are accessible even " "to untrusted users." @@ -2283,12 +2239,12 @@ msgstr "" "acessíveis até para utilizadores não de confiança." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1526 +#: sssd.conf.5.xml:1493 msgid "Two special values for pam_public_domains option are defined:" msgstr "Dois valores especiais para a opção pam_public_domains são definidos:" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1530 +#: sssd.conf.5.xml:1497 msgid "" "all (Untrusted users are allowed to access all domains in PAM responder.)" msgstr "" @@ -2296,7 +2252,7 @@ msgstr "" "domínios no respondedor PAM.)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1534 +#: sssd.conf.5.xml:1501 msgid "" "none (Untrusted users are not allowed to access any domains PAM in " "responder.)" @@ -2305,18 +2261,18 @@ msgstr "" "domínio PAM no respondedor.)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1538 sssd.conf.5.xml:1563 sssd.conf.5.xml:1582 -#: sssd.conf.5.xml:1824 sssd.conf.5.xml:3842 sssd-ldap.5.xml:1270 +#: sssd.conf.5.xml:1505 sssd.conf.5.xml:1530 sssd.conf.5.xml:1549 +#: sssd.conf.5.xml:1821 sssd.conf.5.xml:4048 sssd-ldap.5.xml:1270 msgid "Default: none" msgstr "Predefinição: none" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1543 +#: sssd.conf.5.xml:1510 msgid "pam_account_expired_message (string)" msgstr "pam_account_expired_message (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1546 +#: sssd.conf.5.xml:1513 msgid "" "Allows a custom expiration message to be set, replacing the default " "'Permission denied' message." @@ -2325,7 +2281,7 @@ msgstr "" "a mensagem \"Permissão negada\" predefinida." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1551 +#: sssd.conf.5.xml:1518 msgid "" "Note: Please be aware that message is only printed for the SSH service " "unless pam_verbosity is set to 3 (show all messages and debug information)." @@ -2335,7 +2291,7 @@ msgstr "" "mensagens e informação de depuração)." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1559 +#: sssd.conf.5.xml:1526 #, no-wrap msgid "" "pam_account_expired_message = Account expired, please contact help desk.\n" @@ -2345,12 +2301,12 @@ msgstr "" " " #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1568 +#: sssd.conf.5.xml:1535 msgid "pam_account_locked_message (string)" msgstr "pam_account_locked_message (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1571 +#: sssd.conf.5.xml:1538 msgid "" "Allows a custom lockout message to be set, replacing the default 'Permission " "denied' message." @@ -2359,7 +2315,7 @@ msgstr "" "mensagem \"Permissão negada\" predefinida." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1578 +#: sssd.conf.5.xml:1545 #, no-wrap msgid "" "pam_account_locked_message = Account locked, please contact help desk.\n" @@ -2369,46 +2325,52 @@ msgstr "" " " #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1587 -msgid "pam_passkey_auth (bool)" +#: sssd.conf.5.xml:1554 +#, fuzzy +#| msgid "pam_passkey_auth (bool)" +msgid "pam_passkey_auth (boolean)" msgstr "pam_passkey_auth (booleano)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1590 +#: sssd.conf.5.xml:1557 msgid "Enable passkey device based authentication." msgstr "Activar autenticação baseada em dispositivo passkey." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1593 sssd.conf.5.xml:1910 sssd-ad.5.xml:1286 +#: sssd.conf.5.xml:1560 sssd.conf.5.xml:1907 sssd-ad.5.xml:1279 #: sss_rpcidmapd.5.xml:76 msgid "Default: True" msgstr "Predefinição: True" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1598 -msgid "passkey_debug_libfido2 (bool)" +#: sssd.conf.5.xml:1565 +#, fuzzy +#| msgid "passkey_debug_libfido2 (bool)" +msgid "passkey_debug_libfido2 (boolean)" msgstr "passkey_debug_libfido2 (booleano)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1601 +#: sssd.conf.5.xml:1568 msgid "Enable libfido2 library debug messages." msgstr "Ativa mensagens de depuração da biblioteca libfido2." #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1604 sssd.conf.5.xml:1618 sssd-ldap.5.xml:727 -#: sssd-ldap.5.xml:752 sssd-ldap.5.xml:848 sssd-ldap.5.xml:1356 -#: sssd-ad.5.xml:506 sssd-ad.5.xml:582 sssd-ad.5.xml:1155 +#: sssd.conf.5.xml:1571 sssd.conf.5.xml:1585 sssd.conf.5.xml:4781 +#: sssd-ldap.5.xml:727 sssd-ldap.5.xml:752 sssd-ldap.5.xml:848 +#: sssd-ldap.5.xml:1356 sssd-ad.5.xml:506 sssd-ad.5.xml:582 sssd-ad.5.xml:1160 #: include/ldap_id_mapping.xml:250 msgid "Default: False" msgstr "Predefinição: False" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1609 -msgid "pam_cert_auth (bool)" +#: sssd.conf.5.xml:1576 +#, fuzzy +#| msgid "pam_cert_auth (bool)" +msgid "pam_cert_auth (boolean)" msgstr "pam_cert_auth (booleano)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1612 +#: sssd.conf.5.xml:1579 msgid "" "Enable certificate based Smartcard authentication. Since this requires " "additional communication with the Smartcard which will delay the " @@ -2418,23 +2380,64 @@ msgstr "" "comunicação adicional com a Smartcard o que vai atrasar o processo de " "autenticação, esta opção vem desactivada por predefinição." +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1588 +msgid "" +"Note: In case OpenSC is used for Smartcard access SSSD supports the " +"filesystem caching in OpenSC when enabled in opensc.conf. The cached files " +"are located in a common <quote>opensc</quote> directory in SSSD's state " +"directory. The behaviour can be changed in opensc.conf" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> +#: sssd.conf.5.xml:1597 +#, no-wrap +msgid "" +"app /usr/libexec/sssd/p11_child {\n" +" framework pkcs15 {\n" +" use_file_caching = no;\n" +" }\n" +"}\n" +"app /usr/libexec/sssd/krb5_child {\n" +" framework pkcs15 {\n" +" use_file_caching = no;\n" +" }\n" +"}\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1595 +#, fuzzy +#| msgid "Example: <placeholder type=\"programlisting\" id=\"0\"/>" +msgid "" +"Example opensc.conf (*): <placeholder type=\"programlisting\" id=\"0\"/>" +msgstr "Exemplo: <placeholder type=\"programlisting\" id=\"0\"/>" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1610 +msgid "" +"(*) The actual <quote>libexec</quote> directory for p11_child and krb5_child " +"depends on the distribution." +msgstr "" + #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1623 +#: sssd.conf.5.xml:1615 msgid "pam_cert_db_path (string)" msgstr "pam_cert_db_path (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1626 +#: sssd.conf.5.xml:1618 msgid "The path to the certificate database." msgstr "O caminho para a base de dados de certificados." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1629 sssd.conf.5.xml:2163 sssd.conf.5.xml:4338 +#: sssd.conf.5.xml:1621 sssd.conf.5.xml:2199 sssd.conf.5.xml:4543 msgid "Default:" msgstr "Predefinição:" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1631 sssd.conf.5.xml:2165 +#: sssd.conf.5.xml:1623 sssd.conf.5.xml:2201 msgid "" "/etc/sssd/pki/sssd_auth_ca_db.pem (path to a file with trusted CA " "certificates in PEM format)" @@ -2443,12 +2446,12 @@ msgstr "" "CA de confiança em formato PEM)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1641 +#: sssd.conf.5.xml:1633 msgid "pam_cert_verification (string)" msgstr "pam_cert_verification (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1644 +#: sssd.conf.5.xml:1636 msgid "" "With this parameter the PAM certificate verification can be tuned with a " "comma separated list of options that override the " @@ -2462,7 +2465,7 @@ msgstr "" "opções suportadas são as mesmas de <quote>certificate_verification</quote>." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1655 +#: sssd.conf.5.xml:1647 #, no-wrap msgid "" "pam_cert_verification = partial_chain\n" @@ -2472,7 +2475,7 @@ msgstr "" " " #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1659 +#: sssd.conf.5.xml:1651 msgid "" "Default: not set, i.e. use default <quote>certificate_verification</quote> " "option defined in <quote>[sssd]</quote> section." @@ -2481,34 +2484,34 @@ msgstr "" "certificate_verification</quote> definida na secção <quote>[sssd]</quote>." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1666 +#: sssd.conf.5.xml:1658 msgid "p11_child_timeout (integer)" msgstr "p11_child_timeout (inteiro)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1669 +#: sssd.conf.5.xml:1661 msgid "How many seconds will pam_sss wait for p11_child to finish." msgstr "Quantos segundos irá o pam_sss esperar por p11_child terminar." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1678 +#: sssd.conf.5.xml:1670 msgid "passkey_child_timeout (integer)" msgstr "passkey_child_timeout (inteiro)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1681 +#: sssd.conf.5.xml:1673 msgid "" "How many seconds will the PAM responder wait for passkey_child to finish." msgstr "" "Quantos segundos irá o respondedor PAM esperar que a passkey_child termine." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1690 +#: sssd.conf.5.xml:1682 msgid "pam_app_services (string)" msgstr "pam_app_services (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1693 +#: sssd.conf.5.xml:1685 msgid "" "Which PAM services are permitted to contact domains of type " "<quote>application</quote>" @@ -2517,12 +2520,12 @@ msgstr "" "application</quote>" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1702 +#: sssd.conf.5.xml:1694 msgid "pam_p11_allowed_services (string)" msgstr "pam_p11_allowed_services (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1705 +#: sssd.conf.5.xml:1697 msgid "" "A comma-separated list of PAM service names for which it will be allowed to " "use Smartcards." @@ -2531,7 +2534,7 @@ msgstr "" "permitido usarem Smartcards." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1720 +#: sssd.conf.5.xml:1712 #, no-wrap msgid "" "pam_p11_allowed_services = +my_pam_service, -login\n" @@ -2541,7 +2544,7 @@ msgstr "" " " #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1709 +#: sssd.conf.5.xml:1701 msgid "" "It is possible to add another PAM service name to the default set by using " "<quote>+service_name</quote> or to explicitly remove a PAM service name from " @@ -2560,69 +2563,76 @@ msgstr "" "usar a seguinte configuração: <placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1724 sssd-ad.5.xml:645 sssd-ad.5.xml:754 sssd-ad.5.xml:812 -#: sssd-ad.5.xml:870 sssd-ad.5.xml:948 +#: sssd.conf.5.xml:1716 sssd-ad.5.xml:645 sssd-ad.5.xml:759 sssd-ad.5.xml:817 +#: sssd-ad.5.xml:875 sssd-ad.5.xml:953 msgid "Default: the default set of PAM service names includes:" msgstr "" "Predefinição: o conjunto predefinido de nomes de serviços do PAM inclui:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1729 sssd-ad.5.xml:649 +#: sssd.conf.5.xml:1721 sssd-ad.5.xml:649 msgid "login" msgstr "login" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1734 sssd-ad.5.xml:654 +#: sssd.conf.5.xml:1726 sssd-ad.5.xml:654 msgid "su" msgstr "su" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1739 sssd-ad.5.xml:659 +#: sssd.conf.5.xml:1731 sssd-ad.5.xml:659 msgid "su-l" msgstr "su-l" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1744 sssd-ad.5.xml:674 +#: sssd.conf.5.xml:1736 sssd-ad.5.xml:674 msgid "gdm-smartcard" msgstr "gdm-smartcard" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1749 sssd-ad.5.xml:669 +#: sssd.conf.5.xml:1741 sssd-ad.5.xml:669 msgid "gdm-password" msgstr "gdm-password" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1754 +#: sssd.conf.5.xml:1746 msgid "gdm-switchable-auth" msgstr "gdm-switchable-auth" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1759 sssd-ad.5.xml:679 +#: sssd.conf.5.xml:1751 sssd-ad.5.xml:679 msgid "kdm" msgstr "kdm" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1764 sssd-ad.5.xml:957 +#: sssd.conf.5.xml:1756 sssd-ad.5.xml:694 +#, fuzzy +#| msgid "login" +msgid "plasmalogin" +msgstr "login" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:1761 sssd-ad.5.xml:962 msgid "sudo" msgstr "sudo" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1769 sssd-ad.5.xml:962 +#: sssd.conf.5.xml:1766 sssd-ad.5.xml:967 msgid "sudo-i" msgstr "sudo-i" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1774 +#: sssd.conf.5.xml:1771 msgid "gnome-screensaver" msgstr "gnome-screensaver" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1782 +#: sssd.conf.5.xml:1779 msgid "p11_wait_for_card_timeout (integer)" msgstr "p11_wait_for_card_timeout (inteiro)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1785 +#: sssd.conf.5.xml:1782 msgid "" "If Smartcard authentication is required how many extra seconds in addition " "to p11_child_timeout should the PAM responder wait until a Smartcard is " @@ -2633,12 +2643,12 @@ msgstr "" "inserida." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1796 +#: sssd.conf.5.xml:1793 msgid "p11_uri (string)" msgstr "p11_uri (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1799 +#: sssd.conf.5.xml:1796 msgid "" "PKCS#11 URI (see RFC-7512 for details) which can be used to restrict the " "selection of devices used for Smartcard authentication. By default SSSD's " @@ -2656,7 +2666,7 @@ msgstr "" "usar um leitor específico." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1812 +#: sssd.conf.5.xml:1809 #, no-wrap msgid "" "p11_uri = pkcs11:slot-description=My%20Smartcard%20Reader\n" @@ -2666,7 +2676,7 @@ msgstr "" " " #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1816 +#: sssd.conf.5.xml:1813 #, no-wrap msgid "" "p11_uri = pkcs11:library-description=OpenSC%20smartcard%20framework;slot-id=2\n" @@ -2677,7 +2687,7 @@ msgstr "" " " #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1810 +#: sssd.conf.5.xml:1807 msgid "" "Example: <placeholder type=\"programlisting\" id=\"0\"/> or <placeholder " "type=\"programlisting\" id=\"1\"/> To find suitable URI please check the " @@ -2691,17 +2701,19 @@ msgstr "" "PKCS#11." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1829 -msgid "pam_initgroups_scheme" +#: sssd.conf.5.xml:1826 +#, fuzzy +#| msgid "pam_initgroups_scheme" +msgid "pam_initgroups_scheme (string)" msgstr "pam_initgroups_scheme" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1837 +#: sssd.conf.5.xml:1834 msgid "always" msgstr "always" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1838 +#: sssd.conf.5.xml:1835 msgid "" "Always do an online lookup, please note that pam_id_timeout still applies" msgstr "" @@ -2709,12 +2721,12 @@ msgstr "" "aplica" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1842 +#: sssd.conf.5.xml:1839 msgid "no_session" msgstr "no_session" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1843 +#: sssd.conf.5.xml:1840 msgid "" "Only do an online lookup if there is no active session of the user, i.e. if " "the user is currently not logged in" @@ -2723,12 +2735,12 @@ msgstr "" "isto é, se o utilizador presentemente não está \"logged in\"" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1848 sssd-ldap.5.xml:189 +#: sssd.conf.5.xml:1845 sssd-ldap.5.xml:189 msgid "never" msgstr "never" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1849 +#: sssd.conf.5.xml:1846 msgid "" "Never force an online lookup, use the data from the cache as long as they " "are not expired" @@ -2737,7 +2749,7 @@ msgstr "" "estejam expirados" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1832 +#: sssd.conf.5.xml:1829 msgid "" "The PAM responder can force an online lookup to get the current group " "memberships of the user trying to log in. This option controls when this " @@ -2750,17 +2762,19 @@ msgstr "" "type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1856 +#: sssd.conf.5.xml:1853 msgid "Default: no_session" msgstr "Predefinição: no_session" -#. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:1861 sssd.conf.5.xml:4277 -msgid "pam_gssapi_services" -msgstr "pam_gssapi_services" +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1858 +#, fuzzy +#| msgid "pam_app_services (string)" +msgid "pam_gssapi_services (string)" +msgstr "pam_app_services (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1864 +#: sssd.conf.5.xml:1861 msgid "" "Comma separated list of PAM services that are allowed to try GSSAPI " "authentication using pam_sss_gss.so module." @@ -2769,7 +2783,7 @@ msgstr "" "autenticação GSSAPI usando o módulo pam_sss_gss.so." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1869 +#: sssd.conf.5.xml:1866 msgid "" "To disable GSSAPI authentication, set this option to <quote>-</quote> (dash)." msgstr "" @@ -2777,7 +2791,7 @@ msgstr "" "quote> (traço)." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1873 sssd.conf.5.xml:1904 sssd.conf.5.xml:1942 +#: sssd.conf.5.xml:1870 sssd.conf.5.xml:1901 sssd.conf.5.xml:1939 msgid "" "Note: This option can also be set per-domain which overwrites the value in " "[pam] section. It can also be set for trusted domain which overwrites the " @@ -2788,7 +2802,7 @@ msgstr "" "sobrepõe o valor na secção domain." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1881 +#: sssd.conf.5.xml:1878 #, no-wrap msgid "" "pam_gssapi_services = sudo, sudo-i\n" @@ -2798,22 +2812,24 @@ msgstr "" " " #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1879 sssd.conf.5.xml:1994 sssd.conf.5.xml:3836 +#: sssd.conf.5.xml:1876 sssd.conf.5.xml:2023 sssd.conf.5.xml:4042 msgid "Example: <placeholder type=\"programlisting\" id=\"0\"/>" msgstr "Exemplo: <placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1885 +#: sssd.conf.5.xml:1882 msgid "Default: - (GSSAPI authentication is disabled)" msgstr "Predefinição: - (a autenticação GSSAPI é desactivada)" -#. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:1890 sssd.conf.5.xml:4278 -msgid "pam_gssapi_check_upn" +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1887 +#, fuzzy +#| msgid "pam_gssapi_check_upn" +msgid "pam_gssapi_check_upn (boolean)" msgstr "pam_gssapi_check_upn" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1893 +#: sssd.conf.5.xml:1890 msgid "" "If True, SSSD will require that the Kerberos user principal that " "successfully authenticated through GSSAPI can be associated with the user " @@ -2824,21 +2840,27 @@ msgstr "" "a ser autenticado. A autenticação irá falhar se a verificação falhar." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1900 +#: sssd.conf.5.xml:1897 +#, fuzzy +#| msgid "" +#| "If False, every user that is able to obtained required service ticket " +#| "will be authenticated." msgid "" -"If False, every user that is able to obtained required service ticket will " +"If False, every user that is able to obtain a required service ticket will " "be authenticated." msgstr "" "Se False, cada utilizador capaz de obter o requerido bilhete de serviço irá " "ser autenticado." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1915 -msgid "pam_gssapi_indicators_map" +#: sssd.conf.5.xml:1912 +#, fuzzy +#| msgid "pam_gssapi_indicators_map" +msgid "pam_gssapi_indicators_map (string)" msgstr "pam_gssapi_indicators_map" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1918 +#: sssd.conf.5.xml:1915 msgid "" "Comma separated list of authentication indicators required to be present in " "a Kerberos ticket to access a PAM service that is allowed to try GSSAPI " @@ -2849,7 +2871,7 @@ msgstr "" "permissão de tentar autenticação GSSAPI usando o módulo pam_sss_gss.so." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1924 +#: sssd.conf.5.xml:1921 msgid "" "Each element of the list can be either an authentication indicator name or a " "pair <quote>service:indicator</quote>. Indicators not prefixed with the PAM " @@ -2875,7 +2897,7 @@ msgstr "" "não irá prevenir o acesso." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1937 +#: sssd.conf.5.xml:1934 msgid "" "To disable GSSAPI authentication indicator check, set this option to <quote>-" "</quote> (dash). To disable the check for a specific PAM service, add " @@ -2886,7 +2908,7 @@ msgstr "" "um serviço PAM específico, adicione <quote>service:-</quote>." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1948 +#: sssd.conf.5.xml:1945 msgid "" "Following authentication indicators are supported by IPA Kerberos " "deployments:" @@ -2895,7 +2917,7 @@ msgstr "" "Kerberos IPA:" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1951 +#: sssd.conf.5.xml:1948 msgid "" "pkinit -- pre-authentication using X.509 certificates -- whether stored in " "files or on smart cards." @@ -2904,7 +2926,7 @@ msgstr "" "em ficheiros ou em smart cards." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1954 +#: sssd.conf.5.xml:1951 msgid "" "hardened -- SPAKE pre-authentication or any pre-authentication wrapped in a " "FAST channel." @@ -2913,12 +2935,12 @@ msgstr "" "num canal FAST." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1957 +#: sssd.conf.5.xml:1954 msgid "radius -- pre-authentication with the help of a RADIUS server." msgstr "radius -- pre-autenticação com a ajuda dum servidor RADIUS." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1960 +#: sssd.conf.5.xml:1957 msgid "" "otp -- pre-authentication using integrated two-factor authentication (2FA or " "one-time password, OTP) in IPA." @@ -2927,12 +2949,12 @@ msgstr "" "ou palavra passe de uma-vez, OTP) em IPA." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1963 +#: sssd.conf.5.xml:1960 msgid "idp -- pre-authentication using external identity provider." msgstr "idp -- pre-autenticação usando provedor de identidade externo." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1973 +#: sssd.conf.5.xml:1970 #, no-wrap msgid "" "pam_gssapi_indicators_map = sudo:pkinit, sudo-i:pkinit\n" @@ -2942,7 +2964,7 @@ msgstr "" " " #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1968 +#: sssd.conf.5.xml:1965 msgid "" "Example: to require access to SUDO services only for users which obtained " "their Kerberos tickets with a X.509 certificate pre-authentication (PKINIT), " @@ -2954,19 +2976,67 @@ msgstr "" "id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1977 +#: sssd.conf.5.xml:1974 msgid "Default: not set (use of authentication indicators is not required)" msgstr "" "Predefinição: não definida (o uso de indicadores de autenticação não é " "requerido)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1979 +#, fuzzy +#| msgid "pam_gssapi_indicators_map" +msgid "pam_gssapi_indicators_apply (string)" +msgstr "pam_gssapi_indicators_map" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1982 +msgid "" +"Comma separated list of triples to assign additional information from the " +"Kerberos ticket, e.g. a SID from the PAC, to authentication indicators." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1988 +#, fuzzy +#| msgid "Currently supported debug levels:" +msgid "Currently supported is:" +msgstr "Níveis de depuração actualmente suportados:" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:1991 +msgid "SID:S-1-5-[domain]-[RID]:[authentication indicator]" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> +#: sssd.conf.5.xml:2002 +#, fuzzy, no-wrap +#| msgid "" +#| "pam_gssapi_indicators_map = sudo:pkinit, sudo-i:pkinit\n" +#| " " +msgid "" +"pam_gssapi_indicators_apply = SID:S-1-5-12345-23456-34567-4321:pkinit\n" +" " +msgstr "" +"pam_gssapi_indicators_map = sudo:pkinit, sudo-i:pkinit\n" +" " + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1996 +msgid "" +"Example: To assign a SID, which is e.g. set by Active Directory's " +"Authentication Mechanism Assurance (AMA) if the AD user used a Smartcard for " +"authentication, to the 'pkinit' authentication indicator use: <placeholder " +"type=\"programlisting\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2011 msgid "pam_json_services (string)" msgstr "pam_json_services (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1985 +#: sssd.conf.5.xml:2014 msgid "" "Comma separated list of PAM services which can handle the JSON protocol for " "selecting authentication mechanisms" @@ -2975,14 +3045,14 @@ msgstr "" "JSON para selecionar mecanismos de autenticação" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1990 +#: sssd.conf.5.xml:2019 msgid "To disable JSON protocol, set this option to <quote>-</quote> (dash)." msgstr "" "Para desactivar o protocolo JSON, defina esta opção para <quote>-</quote> " "(traço)." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1996 +#: sssd.conf.5.xml:2025 #, no-wrap msgid "" "pam_json_services = gdm-switchable-auth\n" @@ -2992,12 +3062,12 @@ msgstr "" " " #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2000 +#: sssd.conf.5.xml:2029 msgid "Default: - (JSON protocol is disabled)" msgstr "Predefinição: - (o protocolo JSON é desativado)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2003 +#: sssd.conf.5.xml:2032 msgid "" "Note: 2-Factor Authentication (2FA) is not supported. If 2FA is required, do " "not activate the JSON protocol." @@ -3006,34 +3076,55 @@ msgstr "" "obrigatório, não ative o protocolo JSON." #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:2013 +#: sssd.conf.5.xml:2042 msgid "SUDO configuration options" msgstr "Opções de configuração do SUDO" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2015 +#: sssd.conf.5.xml:2044 +#, fuzzy +#| msgid "These options can be used to configure the session recording." msgid "" -"These options can be used to configure the sudo service. The detailed " -"instructions for configuration of <citerefentry> <refentrytitle>sudo</" -"refentrytitle> <manvolnum>8</manvolnum> </citerefentry> to work with " -"<citerefentry> <refentrytitle>sssd</refentrytitle> <manvolnum>8</manvolnum> " -"</citerefentry> are in the manual page <citerefentry> <refentrytitle>sssd-" -"sudo</refentrytitle> <manvolnum>5</manvolnum> </citerefentry>." +"These options can be used to configure the sudo service and should be " +"specified under the <quote>[sudo]</quote> section." +msgstr "Estas opções podem ser usadas para configurar o registo de sessão." + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:2048 +#, fuzzy +#| msgid "" +#| "These options can be used to configure the sudo service. The detailed " +#| "instructions for configuration of <citerefentry> <refentrytitle>sudo</" +#| "refentrytitle> <manvolnum>8</manvolnum> </citerefentry> to work with " +#| "<citerefentry> <refentrytitle>sssd</refentrytitle> <manvolnum>8</" +#| "manvolnum> </citerefentry> are in the manual page <citerefentry> " +#| "<refentrytitle>sssd-sudo</refentrytitle> <manvolnum>5</manvolnum> </" +#| "citerefentry>." +msgid "" +"The detailed instructions for configuration of <citerefentry> " +"<refentrytitle>sudo</refentrytitle> <manvolnum>8</manvolnum> </citerefentry> " +"to work with <citerefentry> <refentrytitle>sssd</refentrytitle> " +"<manvolnum>8</manvolnum> </citerefentry> are in the manual page " +"<citerefentry> <refentrytitle>sssd-sudo</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry>." msgstr "" "Estas opções podem ser usadas para configurar o serviço sudo. As " -"instruções detalhadas para configuração do <citerefentry> <refentrytitle>" -"sudo</refentrytitle> <manvolnum>8</manvolnum> </citerefentry> para trabalhar " -"com <citerefentry> <refentrytitle>sssd</refentrytitle> <manvolnum>8</" -"manvolnum> </citerefentry> estão no manual <citerefentry> <refentrytitle>" -"sssd-sudo</refentrytitle> <manvolnum>5</manvolnum> </citerefentry>." +"instruções detalhadas para configuração do <citerefentry> " +"<refentrytitle>sudo</refentrytitle> <manvolnum>8</manvolnum> </citerefentry> " +"para trabalhar com <citerefentry> <refentrytitle>sssd</refentrytitle> " +"<manvolnum>8</manvolnum> </citerefentry> estão no manual <citerefentry> " +"<refentrytitle>sssd-sudo</refentrytitle> <manvolnum>5</manvolnum> </" +"citerefentry>." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2032 -msgid "sudo_timed (bool)" +#: sssd.conf.5.xml:2064 +#, fuzzy +#| msgid "sudo_timed (bool)" +msgid "sudo_timed (boolean)" msgstr "sudo_timed (booleano)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2035 +#: sssd.conf.5.xml:2067 msgid "" "Whether or not to evaluate the sudoNotBefore and sudoNotAfter attributes " "that implement time-dependent sudoers entries." @@ -3042,12 +3133,12 @@ msgstr "" "implementam entradas de sudoers dependentes de tempo." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2047 +#: sssd.conf.5.xml:2079 msgid "sudo_threshold (integer)" msgstr "sudo_threshold (inteiro)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2050 +#: sssd.conf.5.xml:2082 msgid "" "Maximum number of expired rules that can be refreshed at once. If number of " "expired rules is below threshold, those rules are refreshed with " @@ -3063,22 +3154,26 @@ msgstr "" "a buscas de grupo de comando." #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:2069 +#: sssd.conf.5.xml:2101 msgid "AUTOFS configuration options" msgstr "Opções de configuração do AUTOFS" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2071 -msgid "These options can be used to configure the autofs service." +#: sssd.conf.5.xml:2103 +#, fuzzy +#| msgid "These options can be used to configure the autofs service." +msgid "" +"These options can be used to configure the autofs service and should be " +"specified under the <quote>[autofs]</quote> section." msgstr "Estas opções podem ser usadas para configurar o serviço autofs." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2075 +#: sssd.conf.5.xml:2109 msgid "autofs_negative_timeout (integer)" msgstr "autofs_negative_timeout (inteiro)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2078 +#: sssd.conf.5.xml:2112 msgid "" "Specifies for how many seconds should the autofs responder negative cache " "hits (that is, queries for invalid map entries, like nonexistent ones) " @@ -3089,22 +3184,28 @@ msgstr "" "como não existentes) antes de perguntar de novo ao backend." #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:2094 +#: sssd.conf.5.xml:2128 msgid "SSH configuration options" msgstr "Opções de configuração do SSH" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2096 -msgid "These options can be used to configure the SSH service." +#: sssd.conf.5.xml:2130 +#, fuzzy +#| msgid "These options can be used to configure the SSH service." +msgid "" +"These options can be used to configure the SSH service and should be " +"specified under the <quote>[ssh]</quote> section." msgstr "Estas opções podem ser usadas para configurar o serviço SSH." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2100 -msgid "ssh_use_certificate_keys (bool)" +#: sssd.conf.5.xml:2136 +#, fuzzy +#| msgid "ssh_use_certificate_keys (bool)" +msgid "ssh_use_certificate_keys (boolean)" msgstr "ssh_use_certificate_keys (booleano)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2103 +#: sssd.conf.5.xml:2139 msgid "" "If set to true the <command>sss_ssh_authorizedkeys</command> will return ssh " "keys derived from the public key of X.509 certificates stored in the user " @@ -3118,12 +3219,12 @@ msgstr "" "manvolnum> </citerefentry> para detalhes." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2118 +#: sssd.conf.5.xml:2154 msgid "ssh_use_certificate_matching_rules (string)" msgstr "ssh_use_certificate_matching_rules (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2121 +#: sssd.conf.5.xml:2157 msgid "" "By default the ssh responder will use all available certificate matching " "rules to filter the certificates so that ssh keys are only derived from the " @@ -3139,7 +3240,7 @@ msgstr "" "serão ignoradas." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2130 +#: sssd.conf.5.xml:2166 msgid "" "There are two special key words 'all_rules' and 'no_rules' which will enable " "all or no rules, respectively. The latter means that no certificates will be " @@ -3151,7 +3252,7 @@ msgstr "" "todos os certificados válidos." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2137 +#: sssd.conf.5.xml:2173 msgid "" "If no rules are configured using 'all_rules' will enable a default rule " "which enables all certificates suitable for client authentication. This is " @@ -3164,7 +3265,7 @@ msgstr "" "autenticação de certificados estiver activa." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2144 +#: sssd.conf.5.xml:2180 msgid "" "A non-existing rule name is considered an error. If as a result no rule is " "selected all certificates will be ignored." @@ -3173,7 +3274,7 @@ msgstr "" "nenhuma regra é selecionada e todos os certificados são ignorados." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2149 +#: sssd.conf.5.xml:2185 msgid "" "Default: not set, equivalent to 'all_rules', all found rules or the default " "rule are used" @@ -3182,12 +3283,12 @@ msgstr "" "regras encontradas, ou a regra predefinida" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2155 +#: sssd.conf.5.xml:2191 msgid "ca_db (string)" msgstr "ca_db (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2158 +#: sssd.conf.5.xml:2194 msgid "" "Path to a storage of trusted CA certificates. The option is used to validate " "user certificates before deriving public ssh keys from them." @@ -3197,12 +3298,12 @@ msgstr "" "a partir deles." #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:2178 +#: sssd.conf.5.xml:2214 msgid "PAC responder configuration options" msgstr "Opções de configuração do respondedor PAC" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2180 +#: sssd.conf.5.xml:2216 msgid "" "The PAC responder works together with the authorization data plugin for MIT " "Kerberos sssd_pac_plugin.so and a sub-domain provider. The plugin sends the " @@ -3220,7 +3321,7 @@ msgstr "" "das seguintes operações são feitas:" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:2189 +#: sssd.conf.5.xml:2225 msgid "" "If the remote user does not exist in the cache, it is created. The UID is " "determined with the help of the SID, trusted domains will have UPGs and the " @@ -3237,7 +3338,7 @@ msgstr "" "parâmetro default_shell." #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:2197 +#: sssd.conf.5.xml:2233 msgid "" "If there are SIDs of groups from domains sssd knows about, the user will be " "added to those groups." @@ -3246,17 +3347,21 @@ msgstr "" "será adicionado a esses grupos." #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2203 -msgid "These options can be used to configure the PAC responder." +#: sssd.conf.5.xml:2239 +#, fuzzy +#| msgid "These options can be used to configure the PAC responder." +msgid "" +"These options can be used to configure the PAC responder and should be " +"specified under the <quote>[pac]</quote> section." msgstr "Estas opções podem ser usadas para configurar o respondedor PAC." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2207 sssd-ifp.5.xml:66 +#: sssd.conf.5.xml:2244 sssd-ifp.5.xml:66 msgid "allowed_uids (string)" msgstr "allowed_uids (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2210 +#: sssd.conf.5.xml:2247 msgid "" "Specifies the comma-separated list of UID values or user names that are " "allowed to access the PAC responder. User names are resolved to UIDs at " @@ -3267,7 +3372,7 @@ msgstr "" "utilizadores são resolvidos em UIDs no arranque." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2216 +#: sssd.conf.5.xml:2253 msgid "" "Default: 0, &sssd_user_name; (only root and SSSD service users are allowed " "to access the PAC responder)" @@ -3276,14 +3381,14 @@ msgstr "" "SSSD têm permissão de acesso ao respondedor do PAC)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2220 +#: sssd.conf.5.xml:2257 msgid "Default: 0 (only the root user is allowed to access the PAC responder)" msgstr "" "Predefinição: 0 (apenas o utilizador root ter permissão de acesso ao " "respondedor do PAC)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2224 +#: sssd.conf.5.xml:2261 msgid "" "Please note that defaults will be overwritten with this option. If you still " "want to allow the root and/or '&sssd_user_name;' user to access the PAC " @@ -3296,7 +3401,7 @@ msgstr "" "lista dos UIDs permitidos explicitamente." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2231 +#: sssd.conf.5.xml:2268 msgid "" "Please note that although the UID 0 is used as the default it will be " "overwritten with this option. If you still want to allow the root user to " @@ -3309,12 +3414,12 @@ msgstr "" "adicionar 0 à lista de UIDs permitidos." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2240 +#: sssd.conf.5.xml:2277 msgid "pac_lifetime (integer)" msgstr "pac_lifetime (inteiro)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2243 +#: sssd.conf.5.xml:2280 msgid "" "Lifetime of the PAC entry in seconds. As long as the PAC is valid the PAC " "data can be used to determine the group memberships of a user." @@ -3323,12 +3428,12 @@ msgstr "" "do PAC podem ser usados para determinar os membros do grupo de um utilizador." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2253 +#: sssd.conf.5.xml:2290 msgid "pac_check (string)" msgstr "pac_check (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2256 +#: sssd.conf.5.xml:2293 msgid "" "Apply additional checks on the PAC of the Kerberos ticket which is available " "in Active Directory and FreeIPA domains, if configured. Please note that " @@ -3346,7 +3451,7 @@ msgstr "" "saltadas." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2266 +#: sssd.conf.5.xml:2303 msgid "" "Please note that the checks listed below only apply to PACs issued by Active " "Directory or recent versions of FreeIPA. PACs issued e.g. by a plain MIT " @@ -3358,12 +3463,12 @@ msgstr "" "de dados PAC necessários para correr as verificações." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2277 +#: sssd.conf.5.xml:2314 msgid "no_check" msgstr "no_check" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2279 +#: sssd.conf.5.xml:2316 msgid "" "The PAC must not be present and even if it is present no additional checks " "will be done." @@ -3372,12 +3477,12 @@ msgstr "" "verificação adicional será feita." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2285 +#: sssd.conf.5.xml:2322 msgid "pac_present" msgstr "pac_present" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2287 +#: sssd.conf.5.xml:2324 msgid "" "The PAC must be present in the service ticket which SSSD will request with " "the help of the user's TGT. If the PAC is not available the authentication " @@ -3388,12 +3493,12 @@ msgstr "" "autenticação irá falhar." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2295 +#: sssd.conf.5.xml:2332 msgid "check_upn" msgstr "check_upn" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2297 +#: sssd.conf.5.xml:2334 msgid "" "If the PAC is present check if the user principal name (UPN) information is " "consistent." @@ -3402,12 +3507,12 @@ msgstr "" "utilizador (UPN) é consistente." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2303 +#: sssd.conf.5.xml:2340 msgid "check_upn_allow_missing" msgstr "check_upn_allow_missing" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2305 +#: sssd.conf.5.xml:2342 msgid "" "This option should be used together with 'check_upn' and handles the case " "where a UPN is set on the server-side but is not read by SSSD. The typical " @@ -3426,7 +3531,7 @@ msgstr "" "bem e não há mais necessidade de definir 'ldap_user_principal'." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2317 +#: sssd.conf.5.xml:2354 msgid "" "Currently this option is set by default to avoid regressions in such " "environments. A log message will be added to the system log and SSSD's debug " @@ -3443,22 +3548,22 @@ msgstr "" "possível, remover 'check_upn' irá saltar o teste e evitar a mensagem no log." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2331 +#: sssd.conf.5.xml:2368 msgid "upn_dns_info_present" msgstr "upn_dns_info_present" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2333 +#: sssd.conf.5.xml:2370 msgid "The PAC must contain the UPN-DNS-INFO buffer, implies 'check_upn'." msgstr "O PAC tem de conter o buffer UPN-DNS-INFO, implica 'check_upn'." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2338 +#: sssd.conf.5.xml:2375 msgid "check_upn_dns_info_ex" msgstr "check_upn_dns_info_ex" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2340 +#: sssd.conf.5.xml:2377 msgid "" "If the PAC is present and the extension to the UPN-DNS-INFO buffer is " "available check if the information in the extension is consistent." @@ -3467,12 +3572,12 @@ msgstr "" "disponível verifica se a informação na extensão é consistente." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2347 +#: sssd.conf.5.xml:2384 msgid "upn_dns_info_ex_present" msgstr "upn_dns_info_ex_present" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2349 +#: sssd.conf.5.xml:2386 msgid "" "The PAC must contain the extension of the UPN-DNS-INFO buffer, implies " "'check_upn_dns_info_ex', 'upn_dns_info_present' and 'check_upn'." @@ -3481,7 +3586,7 @@ msgstr "" "'check_upn_dns_info_ex', 'upn_dns_info_present' e 'check_upn'." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2273 +#: sssd.conf.5.xml:2310 msgid "" "The following options can be used alone or in a comma-separated list: " "<placeholder type=\"variablelist\" id=\"0\"/>" @@ -3490,7 +3595,7 @@ msgstr "" "vírgulas: <placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2359 +#: sssd.conf.5.xml:2396 msgid "" "Default: no_check (AD and IPA provider 'check_upn, check_upn_allow_missing, " "check_upn_dns_info_ex')" @@ -3499,12 +3604,12 @@ msgstr "" "check_upn_allow_missing, check_upn_dns_info_ex')" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:2368 +#: sssd.conf.5.xml:2405 msgid "Session recording configuration options" msgstr "Opções de configuração de registo de sessão" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2370 +#: sssd.conf.5.xml:2407 msgid "" "Session recording works in conjunction with <citerefentry> " "<refentrytitle>tlog-rec-session</refentrytitle> <manvolnum>8</manvolnum> </" @@ -3520,32 +3625,46 @@ msgstr "" "manvolnum> </citerefentry>." #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2383 -msgid "These options can be used to configure session recording." +#: sssd.conf.5.xml:2420 +#, fuzzy +#| msgid "These options can be used to configure the session recording." +msgid "" +"These options can be used to configure session recording and should be " +"specified under the <quote>[session_recording]</quote> section." msgstr "Estas opções podem ser usadas para configurar o registo de sessão." +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:2425 +msgid "" +"Note: Unlike other sections, the <quote>[session_recording]</quote> section " +"ignores <replaceable>debug*</replaceable> options and suitable " +"<replaceable>debug*</replaceable> options must be set in <quote>[pam]</" +"quote>, <quote>[nss]</quote> and <quote>[domain/<replaceable>NAME</" +"replaceable>]</quote> sections." +msgstr "" + #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2387 sssd-session-recording.5.xml:64 +#: sssd.conf.5.xml:2433 sssd-session-recording.5.xml:64 msgid "scope (string)" msgstr "scope (string)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2394 sssd-session-recording.5.xml:71 +#: sssd.conf.5.xml:2440 sssd-session-recording.5.xml:71 msgid "\"none\"" msgstr "\"none\"" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2397 sssd-session-recording.5.xml:74 +#: sssd.conf.5.xml:2443 sssd-session-recording.5.xml:74 msgid "No users are recorded." msgstr "Nenhum utilizador é registado." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2402 sssd-session-recording.5.xml:79 +#: sssd.conf.5.xml:2448 sssd-session-recording.5.xml:79 msgid "\"some\"" msgstr "\"some\"" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2405 sssd-session-recording.5.xml:82 +#: sssd.conf.5.xml:2451 sssd-session-recording.5.xml:82 msgid "" "Users/groups specified by <replaceable>users</replaceable> and " "<replaceable>groups</replaceable> options are recorded." @@ -3554,17 +3673,17 @@ msgstr "" "replaceable> e <replaceable>groups</replaceable> são registados." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2414 sssd-session-recording.5.xml:91 +#: sssd.conf.5.xml:2460 sssd-session-recording.5.xml:91 msgid "\"all\"" msgstr "\"all\"" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2417 sssd-session-recording.5.xml:94 +#: sssd.conf.5.xml:2463 sssd-session-recording.5.xml:94 msgid "All users are recorded." msgstr "Todos os utilizadores são registados." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2390 sssd-session-recording.5.xml:67 +#: sssd.conf.5.xml:2436 sssd-session-recording.5.xml:67 msgid "" "One of the following strings specifying the scope of session recording: " "<placeholder type=\"variablelist\" id=\"0\"/>" @@ -3573,17 +3692,17 @@ msgstr "" "<placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2424 sssd-session-recording.5.xml:101 +#: sssd.conf.5.xml:2470 sssd-session-recording.5.xml:101 msgid "Default: \"none\"" msgstr "Predefinição: \"none\"" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2429 sssd-session-recording.5.xml:106 +#: sssd.conf.5.xml:2475 sssd-session-recording.5.xml:106 msgid "users (string)" msgstr "users (string)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2432 sssd-session-recording.5.xml:109 +#: sssd.conf.5.xml:2478 sssd-session-recording.5.xml:109 msgid "" "A comma-separated list of users which should have session recording enabled. " "Matches user names as returned by NSS. I.e. after the possible space " @@ -3595,17 +3714,17 @@ msgstr "" "maiúscula, etc." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2438 sssd-session-recording.5.xml:115 +#: sssd.conf.5.xml:2484 sssd-session-recording.5.xml:115 msgid "Default: Empty. Matches no users." msgstr "Predefinição: Vazio. Não corresponde a nenhum utilizador." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2443 sssd-session-recording.5.xml:120 +#: sssd.conf.5.xml:2489 sssd-session-recording.5.xml:120 msgid "groups (string)" msgstr "groups (string)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2446 sssd-session-recording.5.xml:123 +#: sssd.conf.5.xml:2492 sssd-session-recording.5.xml:123 msgid "" "A comma-separated list of groups, members of which should have session " "recording enabled. Matches group names as returned by NSS. I.e. after the " @@ -3617,7 +3736,7 @@ msgstr "" "maiúscula, etc." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2452 sssd.conf.5.xml:2484 sssd-session-recording.5.xml:129 +#: sssd.conf.5.xml:2498 sssd.conf.5.xml:2530 sssd-session-recording.5.xml:129 #: sssd-session-recording.5.xml:161 msgid "" "NOTE: using this option (having it set to anything) has a considerable " @@ -3629,17 +3748,17 @@ msgstr "" "requer obter e corresponder os grupos do qual o utilizador é membro." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2459 sssd-session-recording.5.xml:136 +#: sssd.conf.5.xml:2505 sssd-session-recording.5.xml:136 msgid "Default: Empty. Matches no groups." msgstr "Predefinição: Vazio. Não corresponde a nenhum grupo." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2464 sssd-session-recording.5.xml:141 +#: sssd.conf.5.xml:2510 sssd-session-recording.5.xml:141 msgid "exclude_users (string)" msgstr "exclude_users (string)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2467 sssd-session-recording.5.xml:144 +#: sssd.conf.5.xml:2513 sssd-session-recording.5.xml:144 msgid "" "A comma-separated list of users to be excluded from recording, only " "applicable with 'scope=all'." @@ -3648,17 +3767,17 @@ msgstr "" "aplicável com 'scope=all'." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2471 sssd-session-recording.5.xml:148 +#: sssd.conf.5.xml:2517 sssd-session-recording.5.xml:148 msgid "Default: Empty. No users excluded." msgstr "Predefinição: Empty. Nenhum utilizador excluído." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2476 sssd-session-recording.5.xml:153 +#: sssd.conf.5.xml:2522 sssd-session-recording.5.xml:153 msgid "exclude_groups (string)" msgstr "exclude_groups (string)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2479 sssd-session-recording.5.xml:156 +#: sssd.conf.5.xml:2525 sssd-session-recording.5.xml:156 msgid "" "A comma-separated list of groups, members of which should be excluded from " "recording. Only applicable with 'scope=all'." @@ -3667,23 +3786,24 @@ msgstr "" "excluídos do registo. Apenas aplicável com 'scope=all'." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2491 sssd-session-recording.5.xml:168 +#: sssd.conf.5.xml:2537 sssd-session-recording.5.xml:168 msgid "Default: Empty. No groups excluded." msgstr "Predefinição: Empty. Nenhum grupo excluído." #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:2501 +#: sssd.conf.5.xml:2547 msgid "DOMAIN SECTIONS" msgstr "SECÇÕES DE DOMÍNIO" -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry><para> -#: sssd.conf.5.xml:2508 sssd.conf.5.xml:3964 sssd.conf.5.xml:3965 -#: sssd.conf.5.xml:3968 -msgid "enabled" -msgstr "enabled" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2554 +#, fuzzy +#| msgid "ad_enable_gc (boolean)" +msgid "enabled (boolean)" +msgstr "ad_enable_gc (booleano)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2511 +#: sssd.conf.5.xml:2557 msgid "" "Explicitly enable or disable the domain. If <quote>true</quote>, the domain " "is always <quote>enabled</quote>. If <quote>false</quote>, the domain is " @@ -3698,12 +3818,12 @@ msgstr "" "<quote>[sssd]</quote>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2523 +#: sssd.conf.5.xml:2569 msgid "domain_type (string)" msgstr "domain_type (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2526 +#: sssd.conf.5.xml:2572 msgid "" "Specifies whether the domain is meant to be used by POSIX-aware clients such " "as the Name Service Switch or by applications that do not need POSIX data to " @@ -3717,7 +3837,7 @@ msgstr "" "operativo." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2534 +#: sssd.conf.5.xml:2580 msgid "" "Allowed values for this option are <quote>posix</quote> and " "<quote>application</quote>." @@ -3726,7 +3846,7 @@ msgstr "" "application</quote>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2538 +#: sssd.conf.5.xml:2584 msgid "" "POSIX domains are reachable by all services. Application domains are only " "reachable from the InfoPipe responder (see <citerefentry> " @@ -3739,7 +3859,7 @@ msgstr "" "manvolnum> </citerefentry>) e o respondedor PAM." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2546 +#: sssd.conf.5.xml:2592 msgid "" "NOTE: The application domains are currently well tested with " "<quote>id_provider=ldap</quote> only." @@ -3748,7 +3868,7 @@ msgstr "" "<quote>id_provider=ldap</quote>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2550 +#: sssd.conf.5.xml:2596 msgid "" "For an easy way to configure a non-POSIX domains, please see the " "<quote>Application domains</quote> section." @@ -3757,17 +3877,17 @@ msgstr "" "a secção <quote>Domínios Application</quote>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2554 +#: sssd.conf.5.xml:2600 msgid "Default: posix" msgstr "Predefinição: posix" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2560 +#: sssd.conf.5.xml:2606 msgid "min_id,max_id (integer)" msgstr "min_id,max_id (inteiro)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2563 +#: sssd.conf.5.xml:2609 msgid "" "UID and GID limits for the domain. If a domain contains an entry that is " "outside these limits, it is ignored." @@ -3776,7 +3896,7 @@ msgstr "" "está fora destes limites, ela é ignorada." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2568 +#: sssd.conf.5.xml:2614 msgid "" "For users, this affects the primary GID limit. The user will not be returned " "to NSS if either the UID or the primary GID is outside the range. For non-" @@ -3789,7 +3909,7 @@ msgstr "" "do alcance serão reportados como esperado." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2575 +#: sssd.conf.5.xml:2621 msgid "" "These ID limits affect even saving entries to cache, not only returning them " "by name or ID." @@ -3798,17 +3918,19 @@ msgstr "" "retornando eles por nome ou ID." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2579 +#: sssd.conf.5.xml:2625 msgid "Default: 1 for min_id, 0 (no limit) for max_id" msgstr "Predefinição: 1 para min_id, 0 (sem limite) para max_id" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2585 -msgid "enumerate (bool)" +#: sssd.conf.5.xml:2631 +#, fuzzy +#| msgid "enumerate (bool)" +msgid "enumerate (boolean)" msgstr "enumerate (booleano)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2588 +#: sssd.conf.5.xml:2634 msgid "" "Determines if a domain can be enumerated, that is, whether the domain can " "list all the users and group it contains. Note that it is not required to " @@ -3821,22 +3943,22 @@ msgstr "" "parâmetro pode ter um dos seguintes valores:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2596 +#: sssd.conf.5.xml:2642 msgid "TRUE = Users and groups are enumerated" msgstr "TRUE = Utilizadores e grupos são enumerados" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2599 +#: sssd.conf.5.xml:2645 msgid "FALSE = No enumerations for this domain" msgstr "FALSE = Nenhuma enumeração para este domínio" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2602 sssd.conf.5.xml:2867 sssd.conf.5.xml:3044 +#: sssd.conf.5.xml:2648 sssd.conf.5.xml:2992 sssd.conf.5.xml:3174 msgid "Default: FALSE" msgstr "Predefinição: FALSE" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2605 +#: sssd.conf.5.xml:2651 msgid "" "Enumerating a domain requires SSSD to download and store ALL user and group " "entries from the remote server." @@ -3845,7 +3967,7 @@ msgstr "" "de utilizadores e grupos a partir do servidor remoto." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2610 +#: sssd.conf.5.xml:2656 msgid "" "Feature is only supported for domains with id_provider = ldap or id_provider " "= proxy." @@ -3854,7 +3976,7 @@ msgstr "" "id_provider = proxy." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2614 +#: sssd.conf.5.xml:2660 msgid "" "Note: Enabling enumeration has a severe performance impact on SSSD while " "enumeration is running. It may take up to several minutes after SSSD startup " @@ -3877,7 +3999,7 @@ msgstr "" "responder ou até ser reiniciado por um watchdog interno." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2629 +#: sssd.conf.5.xml:2675 msgid "" "While the first enumeration is running, requests for the complete user or " "group lists may return no results until it completes." @@ -3887,7 +4009,7 @@ msgstr "" "complete." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2634 +#: sssd.conf.5.xml:2680 msgid "" "Further, enabling enumeration may increase the time necessary to detect " "network disconnection, as longer timeouts are required to ensure that " @@ -3900,7 +4022,7 @@ msgstr "" "mais informação, consulte o manual específico do provedor de id em uso." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2642 +#: sssd.conf.5.xml:2688 msgid "" "For the reasons cited above, enabling enumeration is not recommended, " "especially in large environments." @@ -3909,7 +4031,7 @@ msgstr "" "especialmente em grandes ambientes." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2647 +#: sssd.conf.5.xml:2693 msgid "" "Note: the proxy provider is tested with open source modules like " "'libnss_files' and 'libnss_ldap'. 3rd party modules must follow the " @@ -3921,12 +4043,12 @@ msgstr "" "configuração." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2656 +#: sssd.conf.5.xml:2702 msgid "entry_cache_timeout (integer)" msgstr "entry_cache_timeout (inteiro)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2659 +#: sssd.conf.5.xml:2705 msgid "" "How many seconds should nss_sss consider entries valid before asking the " "backend again" @@ -3935,7 +4057,7 @@ msgstr "" "de questionar o backend outra vez" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2663 +#: sssd.conf.5.xml:2709 msgid "" "The cache expiration timestamps are stored as attributes of individual " "objects in the cache. Therefore, changing the cache timeout only has effect " @@ -3952,17 +4074,17 @@ msgstr "" "das entradas que já estão em cache." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2676 +#: sssd.conf.5.xml:2722 msgid "Default: 5400" msgstr "Predefinição: 5400" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2682 +#: sssd.conf.5.xml:2728 msgid "entry_cache_user_timeout (integer)" msgstr "entry_cache_user_timeout (inteiro)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2685 +#: sssd.conf.5.xml:2731 msgid "" "How many seconds should nss_sss consider user entries valid before asking " "the backend again" @@ -3971,19 +4093,19 @@ msgstr "" "válidas antes de questionar o backend outra vez" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2689 sssd.conf.5.xml:2702 sssd.conf.5.xml:2715 -#: sssd.conf.5.xml:2728 sssd.conf.5.xml:2742 sssd.conf.5.xml:2755 -#: sssd.conf.5.xml:2769 sssd.conf.5.xml:2783 sssd.conf.5.xml:2796 +#: sssd.conf.5.xml:2735 sssd.conf.5.xml:2748 sssd.conf.5.xml:2761 +#: sssd.conf.5.xml:2774 sssd.conf.5.xml:2788 sssd.conf.5.xml:2801 +#: sssd.conf.5.xml:2815 sssd.conf.5.xml:2829 msgid "Default: entry_cache_timeout" msgstr "Predefinição: entry_cache_timeout" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2695 +#: sssd.conf.5.xml:2741 msgid "entry_cache_group_timeout (integer)" msgstr "entry_cache_group_timeout (inteiro)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2698 +#: sssd.conf.5.xml:2744 msgid "" "How many seconds should nss_sss consider group entries valid before asking " "the backend again" @@ -3992,12 +4114,12 @@ msgstr "" "válidas antes de questionar o backend outra vez" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2708 +#: sssd.conf.5.xml:2754 msgid "entry_cache_netgroup_timeout (integer)" msgstr "entry_cache_netgroup_timeout (inteiro)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2711 +#: sssd.conf.5.xml:2757 msgid "" "How many seconds should nss_sss consider netgroup entries valid before " "asking the backend again" @@ -4006,12 +4128,12 @@ msgstr "" "válidas antes de questionar o backend outra vez" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2721 +#: sssd.conf.5.xml:2767 msgid "entry_cache_service_timeout (integer)" msgstr "entry_cache_service_timeout (inteiro)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2724 +#: sssd.conf.5.xml:2770 msgid "" "How many seconds should nss_sss consider service entries valid before asking " "the backend again" @@ -4020,12 +4142,12 @@ msgstr "" "válidas antes de questionar o backend outra vez" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2734 +#: sssd.conf.5.xml:2780 msgid "entry_cache_resolver_timeout (integer)" msgstr "entry_cache_resolver_timeout (inteiro)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2737 +#: sssd.conf.5.xml:2783 msgid "" "How many seconds should nss_sss consider hosts and networks entries valid " "before asking the backend again" @@ -4034,68 +4156,214 @@ msgstr "" "redes válidas antes de questionar o backend outra vez" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2748 -msgid "entry_cache_sudo_timeout (integer)" -msgstr "entry_cache_sudo_timeout (inteiro)" +#: sssd.conf.5.xml:2794 +msgid "entry_cache_sudo_timeout (integer)" +msgstr "entry_cache_sudo_timeout (inteiro)" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2797 +msgid "" +"How many seconds should sudo consider rules valid before asking the backend " +"again" +msgstr "" +"Durante quantos segundos deve o sudo considerar as regras válidas antes de " +"questionar o backend outra vez" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2807 +msgid "entry_cache_autofs_timeout (integer)" +msgstr "entry_cache_autofs_timeout (inteiro)" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2810 +msgid "" +"How many seconds should the autofs service consider automounter maps valid " +"before asking the backend again" +msgstr "" +"Durante quantos segundos deve o serviço autofs considerar os mapas " +"automounter válidos antes de questionar o backend outra vez" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2821 +msgid "entry_cache_ssh_host_timeout (integer)" +msgstr "entry_cache_ssh_host_timeout (inteiro)" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2824 +msgid "" +"How many seconds to keep a host ssh key after refresh. IE how long to cache " +"the host key for." +msgstr "" +"Durante quantos segundos manter uma chave ssh de máquina após refrescar. " +"Isto é, durante quanto tempo manter a chave da máquina em cache." + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2835 +msgid "offline_timeout (integer)" +msgstr "offline_timeout (inteiro)" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2838 +msgid "" +"When SSSD switches to offline mode the amount of time before it tries to go " +"back online will increase based upon the time spent disconnected. By " +"default SSSD uses incremental behaviour to calculate delay in between " +"retries. So, the wait time for a given retry will be longer than the wait " +"time for the previous ones. After each unsuccessful attempt to go online, " +"the new interval is recalculated by the following:" +msgstr "" +"Quando o SSSD comuta para modo offline a quantidade de tempo antes de tentar " +"voltar online irá aumentar com base no tempo que passou desligado. Por " +"predefinição o SSSD usa comportamento incremental para calcular o atraso " +"entre tentativas. Assim, o tempo de espera para uma dada tentativa será " +"maior que o tempo de espera das anteriores. Após cada tentativa sem " +"sucesso de ir online, o novo intervalo é recalculado pelo seguinte:" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2849 sssd.conf.5.xml:2907 +msgid "" +"new_delay = Minimum(old_delay * 2, offline_timeout_max) + " +"random[0...offline_timeout_random_offset]" +msgstr "" +"new_delay = Minimum(old_delay * 2, offline_timeout_max) + " +"random[0...offline_timeout_random_offset]" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2852 +#, fuzzy +#| msgid "" +#| "The offline_timeout default value is 60. The offline_timeout_max default " +#| "value is 3600. The offline_timeout_random_offset default value is 30. " +#| "The end result is amount of seconds before next retry." +msgid "" +"The offline_timeout default value is 60. The offline_timeout_max default " +"value is 3600. The offline_timeout_random_offset default value is 30. The " +"end result is the number of seconds before next retry." +msgstr "" +"O valor predefinido de offline_timeout é 60. O valor predefinido de " +"offline_timeout_max é 3600. O valor predefinido de " +"offline_timeout_random_offset é 30. O resultado final é a quantidade de " +"segundos antes da próxima tentativa." + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2858 +#, fuzzy +#| msgid "" +#| "Note that the maximum length of each interval is defined by " +#| "offline_timeout_max (apart of random part)." +msgid "" +"Note that the maximum length of each interval is defined by " +"offline_timeout_max (apart from the random part)." +msgstr "" +"Note que a duração máxima de cada intervalo é definida por " +"offline_timeout_max (à parte da parte aleatória)." + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2868 +msgid "offline_timeout_max (integer)" +msgstr "offline_timeout_max (inteiro)" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2871 +msgid "" +"Controls by how much the time between attempts to go online can be " +"incremented following unsuccessful attempts to go online." +msgstr "" +"Controla quanto o tempo entre tentativas de ir online pode ser incrementado " +"a seguir a tentativas de ir online sem sucesso." + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2876 +msgid "A value of 0 disables the incrementing behaviour." +msgstr "Um valor de 0 desactiva o comportamento incremental." + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2879 +msgid "" +"The value of this parameter should be set in correlation to offline_timeout " +"parameter value." +msgstr "" +"O valor deste parâmetro deve ser definido em correlação com o valor do " +"parâmetro offline_timeout." + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2883 +#, fuzzy +#| msgid "" +#| "With offline_timeout set to 60 (default value) there is no point in " +#| "setting offlinet_timeout_max to less than 120 as it will saturate " +#| "instantly. General rule here should be to set offline_timeout_max to at " +#| "least 4 times offline_timeout." +msgid "" +"With offline_timeout set to 60 (default value) there is no point in setting " +"offline_timeout_max to less than 120 as it will saturate instantly. General " +"rule here should be to set offline_timeout_max to at least 4 times " +"offline_timeout." +msgstr "" +"Com offline_timeout definido para 60 (valor predefinido) não faz sentido " +"definir offline_timeout_max para menos de 120 pois isso iria saturar " +"instantaneamente. Geralmente a regra aqui deverá ser definir " +"offline_timeout_max para pelo menos 4 vezes o offline_timeout." + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2889 +msgid "" +"Although a value between 0 and offline_timeout may be specified, it has the " +"effect of overriding the offline_timeout value so is of little use." +msgstr "" +"Apesar de poder ser especificado um valor entre 0 e offline_timeout, isso " +"tem o efeito de sobrepor o valor offline_timeout, assim tem pouca utilidade." + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2894 +msgid "Default: 3600" +msgstr "Predefinição: 3600" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2900 +msgid "offline_timeout_random_offset (integer)" +msgstr "offline_timeout_random_offset (inteiro)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2751 +#: sssd.conf.5.xml:2903 msgid "" -"How many seconds should sudo consider rules valid before asking the backend " -"again" +"When SSSD is in offline mode it keeps probing backend servers in specified " +"time intervals:" msgstr "" -"Durante quantos segundos deve o sudo considerar as regras válidas antes de " -"questionar o backend outra vez" - -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2761 -msgid "entry_cache_autofs_timeout (integer)" -msgstr "entry_cache_autofs_timeout (inteiro)" +"Quando o SSSD está em modo offline continua a fazer provas a servidores " +"backend em intervalos de tempo especificados:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2764 +#: sssd.conf.5.xml:2910 msgid "" -"How many seconds should the autofs service consider automounter maps valid " -"before asking the backend again" +"This parameter controls the value of the random offset used for the above " +"equation. Final random_offset value will be random number in range:" msgstr "" -"Durante quantos segundos deve o serviço autofs considerar os mapas " -"automounter válidos antes de questionar o backend outra vez" - -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2775 -msgid "entry_cache_ssh_host_timeout (integer)" -msgstr "entry_cache_ssh_host_timeout (inteiro)" +"Este parâmetro controla o valor do desvio aleatório usado para a equação em " +"cima. O valor random_offset final será um número aleatório dentro da gama:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2778 -msgid "" -"How many seconds to keep a host ssh key after refresh. IE how long to cache " -"the host key for." -msgstr "" -"Durante quantos segundos manter uma chave ssh de máquina após refrescar. " -"Isto é, durante quanto tempo manter a chave da máquina em cache." +#: sssd.conf.5.xml:2915 +msgid "[0 - offline_timeout_random_offset]" +msgstr "[0 - offline_timeout_random_offset]" -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2789 -msgid "entry_cache_computer_timeout (integer)" -msgstr "entry_cache_computer_timeout (inteiro)" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2918 +msgid "A value of 0 disables the random offset addition." +msgstr "Um valor de 0 desactiva a adição de desvio aleatório." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2792 -msgid "" -"How many seconds to keep the local computer entry before asking the backend " -"again" -msgstr "" -"Durante quantos segundos manter a entrada de computador local antes de " -"questionar o backend outra vez" +#: sssd.conf.5.xml:2921 +msgid "Default: 30" +msgstr "Predefinição: 30" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2802 +#: sssd.conf.5.xml:2927 msgid "refresh_expired_interval (integer)" msgstr "refresh_expired_interval (inteiro)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2805 +#: sssd.conf.5.xml:2930 msgid "" "Specifies how many seconds SSSD has to wait before triggering a background " "refresh task which will refresh all expired or nearly expired records." @@ -4105,7 +4373,7 @@ msgstr "" "registos expirados ou quase expirados." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2810 +#: sssd.conf.5.xml:2935 msgid "" "The background refresh will process users, groups and netgroups in the " "cache. For users who have performed the initgroups (get group membership for " @@ -4119,18 +4387,18 @@ msgstr "" "actualizadas." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2818 +#: sssd.conf.5.xml:2943 msgid "This option is automatically inherited for all trusted domains." msgstr "" "Esta opção é herdada automaticamente para todos os domínios de confiança." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2822 +#: sssd.conf.5.xml:2947 msgid "You can consider setting this value to 3/4 * entry_cache_timeout." msgstr "Você pode considerar definir este valor para 3/4 * entry_cache_timeout." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2826 +#: sssd.conf.5.xml:2951 msgid "" "Cache entry will be refreshed by background task when 2/3 of cache timeout " "has already passed. If there are existing cached entries, the background " @@ -4151,18 +4419,20 @@ msgstr "" "invalidar manualmente a cache existente." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2839 sssd-ldap.5.xml:406 sssd-ldap.5.xml:1834 -#: sssd-ipa.5.xml:255 +#: sssd.conf.5.xml:2964 sssd-ldap.5.xml:406 sssd-ldap.5.xml:1834 +#: sssd-ipa.5.xml:250 msgid "Default: 0 (disabled)" msgstr "Predefinição: 0 (desactivado)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2845 -msgid "cache_credentials (bool)" +#: sssd.conf.5.xml:2970 +#, fuzzy +#| msgid "cache_credentials (bool)" +msgid "cache_credentials (boolean)" msgstr "cache_credentials (booleano)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2848 +#: sssd.conf.5.xml:2973 msgid "" "Determines if user credentials are also cached in the local LDB cache. The " "cached credentials refer to passwords, which includes the first (long term) " @@ -4179,7 +4449,7 @@ msgstr "" "esteja guardada na cache sem configuração adicional." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2859 +#: sssd.conf.5.xml:2984 msgid "" "Take a note that while credentials are stored as a salted SHA512 hash, this " "still potentially poses some security risk in case an attacker manages to " @@ -4193,12 +4463,12 @@ msgstr "" "bruta." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2873 +#: sssd.conf.5.xml:2998 msgid "cache_credentials_minimal_first_factor_length (int)" msgstr "cache_credentials_minimal_first_factor_length (inteiro)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2876 +#: sssd.conf.5.xml:3001 msgid "" "If 2-Factor-Authentication (2FA) is used and credentials should be saved " "this value determines the minimal length the first authentication factor " @@ -4210,7 +4480,7 @@ msgstr "" "SHA512 na cache." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2883 +#: sssd.conf.5.xml:3008 msgid "" "This should avoid that the short PINs of a PIN based 2FA scheme are saved in " "the cache which would make them easy targets for brute-force attacks." @@ -4220,12 +4490,12 @@ msgstr "" "bruta." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2894 +#: sssd.conf.5.xml:3019 msgid "account_cache_expiration (integer)" msgstr "account_cache_expiration (inteiro)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2897 +#: sssd.conf.5.xml:3022 msgid "" "Number of days entries are left in cache after last successful login before " "being removed during a cleanup of the cache. 0 means keep forever. The " @@ -4238,17 +4508,17 @@ msgstr "" "igual a offline_credentials_expiration." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2904 +#: sssd.conf.5.xml:3029 msgid "Default: 0 (unlimited)" msgstr "Predefinição: 0 (ilimitado)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2909 +#: sssd.conf.5.xml:3034 msgid "pwd_expiration_warning (integer)" msgstr "pwd_expiration_warning (inteiro)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2920 +#: sssd.conf.5.xml:3045 msgid "" "Please note that the backend server has to provide information about the " "expiration time of the password. If this information is missing, sssd " @@ -4261,17 +4531,17 @@ msgstr "" "de autenticação para o backend." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2927 +#: sssd.conf.5.xml:3052 msgid "Default: 7 (Kerberos), 0 (LDAP)" msgstr "Predefinição: 7 (Kerberos), 0 (LDAP)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2933 +#: sssd.conf.5.xml:3058 msgid "id_provider (string)" msgstr "id_provider (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2936 +#: sssd.conf.5.xml:3061 msgid "" "The identification provider used for the domain. Supported ID providers are:" msgstr "" @@ -4279,12 +4549,12 @@ msgstr "" "suportados são:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2940 +#: sssd.conf.5.xml:3065 msgid "<quote>proxy</quote>: Support a legacy NSS provider." msgstr "<quote>proxy</quote>: Suporta um provedor NSS legado." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2943 +#: sssd.conf.5.xml:3068 msgid "" "<quote>ldap</quote>: LDAP provider. See <citerefentry> <refentrytitle>sssd-" "ldap</refentrytitle> <manvolnum>5</manvolnum> </citerefentry> for more " @@ -4295,8 +4565,8 @@ msgstr "" "informação sobre configuração do LDAP." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2951 sssd.conf.5.xml:3070 sssd.conf.5.xml:3129 -#: sssd.conf.5.xml:3192 +#: sssd.conf.5.xml:3076 sssd.conf.5.xml:3200 sssd.conf.5.xml:3259 +#: sssd.conf.5.xml:3322 msgid "" "<quote>ipa</quote>: FreeIPA and Red Hat Identity Management provider. See " "<citerefentry> <refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</" @@ -4308,8 +4578,8 @@ msgstr "" "configuração do FreeIPA." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2960 sssd.conf.5.xml:3079 sssd.conf.5.xml:3138 -#: sssd.conf.5.xml:3201 +#: sssd.conf.5.xml:3085 sssd.conf.5.xml:3209 sssd.conf.5.xml:3268 +#: sssd.conf.5.xml:3331 msgid "" "<quote>ad</quote>: Active Directory provider. See <citerefentry> " "<refentrytitle>sssd-ad</refentrytitle> <manvolnum>5</manvolnum> </" @@ -4320,7 +4590,7 @@ msgstr "" "citerefentry> para mais informação sobre configurar Active Directory." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2968 +#: sssd.conf.5.xml:3093 msgid "" "<quote>idp</quote>: Provider for OAuth 2.0/OIDC based Identity Providers " "(IdP). See <citerefentry> <refentrytitle>sssd-idp</refentrytitle> " @@ -4330,13 +4600,22 @@ msgstr "" "baseado em OIDC. Veja <citerefentry> <refentrytitle>sssd-idp</refentrytitle> " "<manvolnum>5</manvolnum> </citerefentry> para mais informação." +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3101 +msgid "" +"Default: Not set (This is a mandatory setting that must be explicitly " +"defined for each configured domain)." +msgstr "" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2979 -msgid "use_fully_qualified_names (bool)" +#: sssd.conf.5.xml:3109 +#, fuzzy +#| msgid "use_fully_qualified_names (bool)" +msgid "use_fully_qualified_names (boolean)" msgstr "use_fully_qualified_names (booleano)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2982 +#: sssd.conf.5.xml:3112 msgid "" "Use the full name and domain (as formatted by the domain's full_name_format) " "as the user's login name reported to NSS." @@ -4345,7 +4624,7 @@ msgstr "" "como o nome de login do utilizador reportado ao NSS." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2987 +#: sssd.conf.5.xml:3117 msgid "" "If set to TRUE, all requests to this domain must use fully qualified names. " "For example, if used in EXAMPLE domain that contains a \"test\" user, " @@ -4359,7 +4638,7 @@ msgstr "" "command> já iria." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2995 +#: sssd.conf.5.xml:3125 msgid "" "NOTE: This option has no effect on netgroup lookups due to their tendency to " "include nested netgroups without qualified names. For netgroups, all domains " @@ -4370,7 +4649,7 @@ msgstr "" "os domínios serão pesquisados quando um nome não qualificado é requisitado." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3002 +#: sssd.conf.5.xml:3132 msgid "" "Default: FALSE (TRUE for trusted domain/sub-domains or if " "default_domain_suffix is used)" @@ -4379,17 +4658,19 @@ msgstr "" "default_domain_suffix for usado)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3009 -msgid "ignore_group_members (bool)" +#: sssd.conf.5.xml:3139 +#, fuzzy +#| msgid "ignore_group_members (bool)" +msgid "ignore_group_members (boolean)" msgstr "ignore_group_members (booleano)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3012 +#: sssd.conf.5.xml:3142 msgid "Do not return group members for group lookups." msgstr "Não retorna membros de grupo para pesquisas de grupo." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3015 +#: sssd.conf.5.xml:3145 msgid "" "If set to TRUE, the group membership attribute is not requested from the " "ldap server, and group members are not returned when processing group lookup " @@ -4409,7 +4690,7 @@ msgstr "" "vazio." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3033 +#: sssd.conf.5.xml:3163 msgid "" "Enabling this option can also make access provider checks for group " "membership significantly faster, especially for groups containing many " @@ -4420,7 +4701,7 @@ msgstr "" "grupos que contenham muitos membros." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3039 sssd.conf.5.xml:3767 sssd-ldap.5.xml:401 +#: sssd.conf.5.xml:3169 sssd.conf.5.xml:3951 sssd-ldap.5.xml:401 #: sssd-ldap.5.xml:454 sssd-ldap.5.xml:529 sssd-ldap.5.xml:576 #: sssd-ldap.5.xml:599 sssd-ldap.5.xml:638 sssd-ldap.5.xml:657 #: sssd-ldap.5.xml:681 sssd-ldap.5.xml:1114 sssd-ldap.5.xml:1147 @@ -4432,12 +4713,12 @@ msgstr "" "subdomain_inherit</emphasis>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3049 +#: sssd.conf.5.xml:3179 msgid "auth_provider (string)" msgstr "auth_provider (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3052 +#: sssd.conf.5.xml:3182 msgid "" "The authentication provider used for the domain. Supported auth providers " "are:" @@ -4446,7 +4727,7 @@ msgstr "" "autenticação suportados são:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3056 sssd.conf.5.xml:3122 +#: sssd.conf.5.xml:3186 sssd.conf.5.xml:3252 msgid "" "<quote>ldap</quote> for native LDAP authentication. See <citerefentry> " "<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> </" @@ -4457,7 +4738,7 @@ msgstr "" "citerefentry> para mais informação sobre configuração do LDAP." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3063 +#: sssd.conf.5.xml:3193 msgid "" "<quote>krb5</quote> for Kerberos authentication. See <citerefentry> " "<refentrytitle>sssd-krb5</refentrytitle> <manvolnum>5</manvolnum> </" @@ -4468,7 +4749,7 @@ msgstr "" "citerefentry> para mais informação sobre configuração do Kerberos." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3087 +#: sssd.conf.5.xml:3217 msgid "" "<quote>idp</quote>: Provider for OAuth 2.0/OIDC based authentication. See " "<citerefentry> <refentrytitle>sssd-idp</refentrytitle> <manvolnum>5</" @@ -4479,19 +4760,19 @@ msgstr "" "manvolnum> </citerefentry> para mais informação." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3095 +#: sssd.conf.5.xml:3225 msgid "" "<quote>proxy</quote> for relaying authentication to some other PAM target." msgstr "" "<quote>proxy</quote> para retransmitir a autenticação para outro alvo PAM." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3098 +#: sssd.conf.5.xml:3228 msgid "<quote>none</quote> disables authentication explicitly." msgstr "<quote>none</quote> desactiva explicitamente a autenticação." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3101 +#: sssd.conf.5.xml:3231 msgid "" "Default: <quote>id_provider</quote> is used if it is set and can handle " "authentication requests." @@ -4500,12 +4781,12 @@ msgstr "" "lidar com pedidos de autenticação." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3107 +#: sssd.conf.5.xml:3237 msgid "access_provider (string)" msgstr "access_provider (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3110 +#: sssd.conf.5.xml:3240 msgid "" "The access control provider used for the domain. There are two built-in " "access providers (in addition to any included in installed backends) " @@ -4516,17 +4797,17 @@ msgstr "" "instalados). Os provedores especiais internos são:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3116 +#: sssd.conf.5.xml:3246 msgid "<quote>permit</quote> always allow access." msgstr "<quote>permit</quote> permite sempre o acesso." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3119 +#: sssd.conf.5.xml:3249 msgid "<quote>deny</quote> always deny access." msgstr "<quote>deny</quote> nega sempre o acesso." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3146 +#: sssd.conf.5.xml:3276 msgid "" "<quote>simple</quote> access control based on access or deny lists. See " "<citerefentry> <refentrytitle>sssd-simple</refentrytitle> <manvolnum>5</" @@ -4539,7 +4820,7 @@ msgstr "" "configuração do módulo de acesso simple." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3153 +#: sssd.conf.5.xml:3283 msgid "" "<quote>krb5</quote>: .k5login based access control. See <citerefentry> " "<refentrytitle>sssd-krb5</refentrytitle> <manvolnum>5</manvolnum></" @@ -4551,24 +4832,24 @@ msgstr "" "Kerberos." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3160 +#: sssd.conf.5.xml:3290 msgid "<quote>proxy</quote> for relaying access control to another PAM module." msgstr "" "<quote>proxy</quote> para retransmitir o controle de acesso para outro " "módulo PAM." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3163 +#: sssd.conf.5.xml:3293 msgid "Default: <quote>permit</quote>" msgstr "Predefinição: <quote>permit</quote>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3168 +#: sssd.conf.5.xml:3298 msgid "chpass_provider (string)" msgstr "chpass_provider (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3171 +#: sssd.conf.5.xml:3301 msgid "" "The provider which should handle change password operations for the domain. " "Supported change password providers are:" @@ -4577,7 +4858,7 @@ msgstr "" "domínio. Os provedores de mudança de palavra passe suportados são:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3176 +#: sssd.conf.5.xml:3306 msgid "" "<quote>ldap</quote> to change a password stored in a LDAP server. See " "<citerefentry> <refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</" @@ -4588,7 +4869,7 @@ msgstr "" "manvolnum> </citerefentry> para mais informação sobre configuração do LDAP." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3184 +#: sssd.conf.5.xml:3314 msgid "" "<quote>krb5</quote> to change the Kerberos password. See <citerefentry> " "<refentrytitle>sssd-krb5</refentrytitle> <manvolnum>5</manvolnum> </" @@ -4599,7 +4880,7 @@ msgstr "" "citerefentry> para mais informação sobre configuração do Kerberos." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3209 +#: sssd.conf.5.xml:3339 msgid "" "<quote>proxy</quote> for relaying password changes to some other PAM target." msgstr "" @@ -4607,13 +4888,13 @@ msgstr "" "outro alvo PAM." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3213 +#: sssd.conf.5.xml:3343 msgid "<quote>none</quote> disallows password changes explicitly." msgstr "" "<quote>none</quote> desautoriza explicitamente mudanças de palavra passe." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3216 +#: sssd.conf.5.xml:3346 msgid "" "Default: <quote>auth_provider</quote> is used if it is set and can handle " "change password requests." @@ -4622,17 +4903,17 @@ msgstr "" "puder lidar com pedidos de mudança de palavra passe." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3223 +#: sssd.conf.5.xml:3353 msgid "sudo_provider (string)" msgstr "sudo_provider (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3226 +#: sssd.conf.5.xml:3356 msgid "The SUDO provider used for the domain. Supported SUDO providers are:" msgstr "O provedor SUDO usado para o domínio. Provedores SUDO suportados são:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3230 +#: sssd.conf.5.xml:3360 msgid "" "<quote>ldap</quote> for rules stored in LDAP. See <citerefentry> " "<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> </" @@ -4643,7 +4924,7 @@ msgstr "" "citerefentry> para mais informação sobre configuração do LDAP." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3238 +#: sssd.conf.5.xml:3368 msgid "" "<quote>ipa</quote> the same as <quote>ldap</quote> but with IPA default " "settings." @@ -4652,7 +4933,7 @@ msgstr "" "predefinidas de IPA." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3242 +#: sssd.conf.5.xml:3372 msgid "" "<quote>ad</quote> the same as <quote>ldap</quote> but with AD default " "settings." @@ -4661,12 +4942,12 @@ msgstr "" "predefinidas de AD." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3246 +#: sssd.conf.5.xml:3376 msgid "<quote>none</quote> disables SUDO explicitly." msgstr "<quote>none</quote> desactiva explicitamente SUDO." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3249 +#: sssd.conf.5.xml:3379 msgid "" "Default: The value of <quote>id_provider</quote> is used if it is set and " "can handle sudo requests." @@ -4675,7 +4956,7 @@ msgstr "" "definido." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3253 +#: sssd.conf.5.xml:3383 msgid "" "The detailed instructions for configuration of sudo_provider are in the " "manual page <citerefentry> <refentrytitle>sssd-sudo</refentrytitle> " @@ -4692,7 +4973,7 @@ msgstr "" "manvolnum> </citerefentry>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3268 +#: sssd.conf.5.xml:3398 msgid "" "<emphasis>NOTE:</emphasis> Sudo rules are periodically downloaded in the " "background unless the sudo provider is explicitly disabled. Set " @@ -4706,12 +4987,12 @@ msgstr "" "sudo com SSSD." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3278 +#: sssd.conf.5.xml:3408 msgid "selinux_provider (string)" msgstr "selinux_provider (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3281 +#: sssd.conf.5.xml:3411 msgid "" "The provider which should handle loading of selinux settings. Note that this " "provider will be called right after access provider ends. Supported selinux " @@ -4722,7 +5003,7 @@ msgstr "" "provedores selinux suportados são:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3287 +#: sssd.conf.5.xml:3417 msgid "" "<quote>ipa</quote> to load selinux settings from an IPA server. See " "<citerefentry> <refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</" @@ -4733,28 +5014,33 @@ msgstr "" "manvolnum> </citerefentry> para mais informação sobre configuração de IPA." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3295 +#: sssd.conf.5.xml:3425 msgid "<quote>none</quote> disallows fetching selinux settings explicitly." msgstr "" "<quote>none</quote> desactiva explicitamente o obtenção de definições " "selinux." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3298 +#: sssd.conf.5.xml:3428 +#, fuzzy +#| msgid "" +#| "Default: The value of <quote>id_provider</quote> is used if it is set and " +#| "can handle subdomain requests." msgid "" -"Default: <quote>id_provider</quote> is used if it is set and can handle " -"selinux loading requests." +"Default: the value of <quote>id_provider</quote> is used if it is set and " +"can handle selinux loading requests. Otherwise the result is the same as if " +"the selinux_provider is set to none." msgstr "" -"Predefinição: é usado <quote>id_provider</quote> se estiver definido e puder " -"lidar com pedidos de carregamento selinux." +"Predefinição: O valor de <quote>id_provider</quote> é usado se estiver " +"definido e puder lidar com pedidos de sub-domínio." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3304 +#: sssd.conf.5.xml:3435 msgid "subdomains_provider (string)" msgstr "subdomains_provider (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3307 +#: sssd.conf.5.xml:3438 msgid "" "The provider which should handle fetching of subdomains. This value should " "be always the same as id_provider. Supported subdomain providers are:" @@ -4763,7 +5049,7 @@ msgstr "" "o mesmo que id_provider. Os provedores de subdomínio suportados são:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3313 +#: sssd.conf.5.xml:3444 msgid "" "<quote>ipa</quote> to load a list of subdomains from an IPA server. See " "<citerefentry> <refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</" @@ -4774,7 +5060,7 @@ msgstr "" "5</manvolnum> </citerefentry> para mais informação sobre configuração de IPA." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3322 +#: sssd.conf.5.xml:3453 msgid "" "<quote>ad</quote> to load a list of subdomains from an Active Directory " "server. See <citerefentry> <refentrytitle>sssd-ad</refentrytitle> " @@ -4787,12 +5073,12 @@ msgstr "" "configuração de provedor AD." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3331 +#: sssd.conf.5.xml:3462 msgid "<quote>none</quote> disallows fetching subdomains explicitly." msgstr "<quote>none</quote> desactiva explicitamente o obtenção de subdomínios." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3335 +#: sssd.conf.5.xml:3466 msgid "" "Default: The value of <quote>id_provider</quote> is used if it is set and " "can handle subdomain requests." @@ -4801,12 +5087,12 @@ msgstr "" "definido e puder lidar com pedidos de sub-domínio." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3341 +#: sssd.conf.5.xml:3472 msgid "session_provider (string)" msgstr "session_provider (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3344 +#: sssd.conf.5.xml:3475 msgid "" "The provider which configures and manages user session related tasks. The " "only user session task currently provided is the integration with Fleet " @@ -4818,14 +5104,14 @@ msgstr "" "provedores de sessão suportados são:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3351 +#: sssd.conf.5.xml:3482 msgid "<quote>ipa</quote> to allow performing user session related tasks." msgstr "" "<quote>ipa</quote> para permitir a execução de tarefas relacionadas com a " "sessão de utilizador." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3355 +#: sssd.conf.5.xml:3486 msgid "" "<quote>none</quote> does not perform any kind of user session related tasks." msgstr "" @@ -4833,24 +5119,24 @@ msgstr "" "sessão de utilizador." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3359 +#: sssd.conf.5.xml:3490 msgid "Default: <quote>none</quote>." msgstr "Predefinição: <quote>none</quote>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3365 +#: sssd.conf.5.xml:3496 msgid "autofs_provider (string)" msgstr "autofs_provider (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3368 +#: sssd.conf.5.xml:3499 msgid "" "The autofs provider used for the domain. Supported autofs providers are:" msgstr "" "O provedor de autofs para o domínio. Os provedores autofs suportados são:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3372 +#: sssd.conf.5.xml:3503 msgid "" "<quote>ldap</quote> to load maps stored in LDAP. See <citerefentry> " "<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> </" @@ -4861,7 +5147,7 @@ msgstr "" "manvolnum> </citerefentry> para mais informação sobre configuração do LDAP." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3379 +#: sssd.conf.5.xml:3510 msgid "" "<quote>ipa</quote> to load maps stored in an IPA server. See <citerefentry> " "<refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</manvolnum> </" @@ -4872,7 +5158,7 @@ msgstr "" "manvolnum> </citerefentry> para mais informação sobre configuração de IPA." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3387 +#: sssd.conf.5.xml:3518 msgid "" "<quote>ad</quote> to load maps stored in an AD server. See <citerefentry> " "<refentrytitle>sssd-ad</refentrytitle> <manvolnum>5</manvolnum> </" @@ -4884,12 +5170,12 @@ msgstr "" "provedor AD." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3396 +#: sssd.conf.5.xml:3527 msgid "<quote>none</quote> disables autofs explicitly." msgstr "<quote>none</quote> desactiva explicitamente o autofs." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3399 +#: sssd.conf.5.xml:3530 msgid "" "Default: The value of <quote>id_provider</quote> is used if it is set and " "can handle autofs requests." @@ -4898,12 +5184,12 @@ msgstr "" "definido e puder lidar com pedidos de autofs." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3406 +#: sssd.conf.5.xml:3537 msgid "hostid_provider (string)" msgstr "hostid_provider (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3409 +#: sssd.conf.5.xml:3540 msgid "" "The provider used for retrieving host identity information. Supported " "hostid providers are:" @@ -4912,7 +5198,7 @@ msgstr "" "provedores hostid suportados são:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3413 +#: sssd.conf.5.xml:3544 msgid "" "<quote>ipa</quote> to load host identity stored in an IPA server. See " "<citerefentry> <refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</" @@ -4924,12 +5210,12 @@ msgstr "" "configuração de IPA." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3421 +#: sssd.conf.5.xml:3552 msgid "<quote>none</quote> disables hostid explicitly." msgstr "<quote>none</quote> desactiva explicitamente hostid." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3424 +#: sssd.conf.5.xml:3555 msgid "" "Default: The value of <quote>id_provider</quote> is used if it is set and " "can handle hostid requests." @@ -4938,12 +5224,12 @@ msgstr "" "definido e puder lidar com pedidos de hostid." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3431 +#: sssd.conf.5.xml:3562 msgid "resolver_provider (string)" msgstr "resolver_provider (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3434 +#: sssd.conf.5.xml:3565 msgid "" "The provider which should handle hosts and networks lookups. Supported " "resolver providers are:" @@ -4952,7 +5238,7 @@ msgstr "" "resolver são:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3438 +#: sssd.conf.5.xml:3569 msgid "" "<quote>proxy</quote> to forward lookups to another NSS library. See " "<quote>proxy_resolver_lib_name</quote>" @@ -4961,7 +5247,7 @@ msgstr "" "Veja <quote>proxy_resolver_lib_name</quote>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3442 +#: sssd.conf.5.xml:3573 msgid "" "<quote>ldap</quote> to fetch hosts and networks stored in LDAP. See " "<citerefentry> <refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</" @@ -4972,7 +5258,7 @@ msgstr "" "manvolnum> </citerefentry> para mais informação sobre configuração do LDAP." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3449 +#: sssd.conf.5.xml:3580 msgid "" "<quote>ad</quote> to fetch hosts and networks stored in AD. See " "<citerefentry> <refentrytitle>sssd-ad</refentrytitle> <manvolnum>5</" @@ -4985,13 +5271,13 @@ msgstr "" "provedor AD." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3457 +#: sssd.conf.5.xml:3588 msgid "<quote>none</quote> disallows fetching hosts and networks explicitly." msgstr "" "<quote>none</quote> desactiva explicitamente a obtenção máquinas e redes." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3460 +#: sssd.conf.5.xml:3591 msgid "" "Default: The value of <quote>id_provider</quote> is used if it is set and " "can handle resolver requests." @@ -5000,7 +5286,7 @@ msgstr "" "definido e puder lidar com pedidos de resolvedor." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3470 +#: sssd.conf.5.xml:3601 msgid "" "Regular expression for this domain that describes how to parse the string " "containing user name and domain into these components. The \"domain\" can " @@ -5015,7 +5301,7 @@ msgstr "" "(NetBIOS) do domínio." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3479 +#: sssd.conf.5.xml:3610 msgid "" "Default: <quote>^((?P<name>.+)@(?P<domain>[^@]*)|(?P<name>" "[^@]+))$</quote> which allows two different styles for user names:" @@ -5025,17 +5311,17 @@ msgstr "" "nomes de utilizador:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:3484 sssd.conf.5.xml:3498 +#: sssd.conf.5.xml:3615 sssd.conf.5.xml:3629 msgid "username" msgstr "nome de utilizador" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:3487 sssd.conf.5.xml:3501 +#: sssd.conf.5.xml:3618 sssd.conf.5.xml:3632 msgid "username@domain.name" msgstr "nome-utilizador@nome.domínio" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3492 +#: sssd.conf.5.xml:3623 msgid "" "Default for the AD and IPA provider: <quote>^(((?P<domain>[^\\\\]+)\\\\" "(?P<name>.+))|((?P<name>.+)@(?P<domain>[^@]+))|((?" @@ -5048,14 +5334,14 @@ msgstr "" "diferentes para nomes de utilizador:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:3504 +#: sssd.conf.5.xml:3635 msgid "domain\\username" msgstr "" "domínio\\n" "ome-utilizador" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3507 +#: sssd.conf.5.xml:3638 msgid "" "While the first two correspond to the general default the third one is " "introduced to allow easy integration of users from Windows domains." @@ -5065,7 +5351,7 @@ msgstr "" "Windows." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3512 +#: sssd.conf.5.xml:3643 msgid "" "The default re_expression uses the <quote>@</quote> character as a separator " "between the name and the domain. As a result of this setting the default " @@ -5080,17 +5366,17 @@ msgstr "" "@</quote> ele tem de criar a sua própria re-expressão." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3564 +#: sssd.conf.5.xml:3695 msgid "Default: <quote>%1$s@%2$s</quote>." msgstr "Predefinição: <quote>%1$s@%2$s</quote>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3570 +#: sssd.conf.5.xml:3701 msgid "lookup_family_order (string)" msgstr "lookup_family_order (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3573 +#: sssd.conf.5.xml:3704 msgid "" "Provides the ability to select preferred address family to use when " "performing DNS lookups." @@ -5099,77 +5385,98 @@ msgstr "" "quando executa pesquisas DNS." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3577 +#: sssd.conf.5.xml:3708 msgid "Supported values:" msgstr "Valores suportados:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3580 +#: sssd.conf.5.xml:3711 msgid "ipv4_first: Try looking up IPv4 address, if that fails, try IPv6" msgstr "ipv4_first: Tenta pesquisar endereços IPv4, se isso falhar, tenta IPv6" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3583 +#: sssd.conf.5.xml:3714 msgid "ipv4_only: Only attempt to resolve hostnames to IPv4 addresses." msgstr "ipv4_only: Apenas tenta resolver nomes-de-máquinas em endereços IPv4." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3586 +#: sssd.conf.5.xml:3717 msgid "ipv6_first: Try looking up IPv6 address, if that fails, try IPv4" msgstr "ipv6_first: Tenta pesquisar endereços IPv6, se isso falhar, tenta IPv4" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3589 +#: sssd.conf.5.xml:3720 msgid "ipv6_only: Only attempt to resolve hostnames to IPv6 addresses." msgstr "ipv6_only: Apenas tenta resolver nomes-de-máquinas em endereços IPv6." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3592 +#: sssd.conf.5.xml:3723 msgid "Default: ipv4_first" msgstr "Predefinição: ipv4_first" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3598 +#: sssd.conf.5.xml:3729 msgid "dns_resolver_server_timeout (integer)" msgstr "dns_resolver_server_timeout (inteiro)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3601 +#: sssd.conf.5.xml:3732 +#, fuzzy +#| msgid "" +#| "Defines the amount of time (in milliseconds) SSSD would try to talk to " +#| "DNS server before trying next DNS server." msgid "" -"Defines the amount of time (in milliseconds) SSSD would try to talk to DNS " -"server before trying next DNS server." +"Defines the timeout duration (in milliseconds) SSSD waits for a DNS server " +"to respond before moving to the next one." msgstr "" "Define a quantidade de tempo (em milissegundos) que o SSSD deve tentar falar " "com o servidor DNS antes de tentar o próximo servidor DNS." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3606 +#: sssd.conf.5.xml:3737 msgid "" "The AD provider will use this option for the CLDAP ping timeouts as well." msgstr "" "O provedor AD irá também usar esta opção para o tempo limite de ping CLDAP." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3610 sssd.conf.5.xml:3630 sssd.conf.5.xml:3651 -msgid "" -"Please see the section <quote>FAILOVER</quote> for more information about " -"the service resolution." +#: sssd.conf.5.xml:3741 sssd.conf.5.xml:3777 sssd.conf.5.xml:3814 +#, fuzzy +#| msgid "" +#| "Specifies the timeout (in seconds) after which the <citerefentry> " +#| "<refentrytitle>poll</refentrytitle> <manvolnum>2</manvolnum> </" +#| "citerefentry>/<citerefentry> <refentrytitle>select</refentrytitle> " +#| "<manvolnum>2</manvolnum> </citerefentry> following a <citerefentry> " +#| "<refentrytitle>connect</refentrytitle> <manvolnum>2</manvolnum> </" +#| "citerefentry> returns in case of no activity." +msgid "" +"Please see the section <quote>FAILOVER</quote> in <citerefentry> " +"<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> </" +"citerefentry>, <citerefentry> <refentrytitle>sssd-krb5</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry>, <citerefentry> <refentrytitle>sssd-" +"ipa</refentrytitle> <manvolnum>5</manvolnum> </citerefentry> or " +"<citerefentry> <refentrytitle>sssd-ad</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry> for more information about the service resolution." msgstr "" -"Por favor veja a secção <quote>FAILOVER</quote> para mais informação sobre a " -"resolução de serviço." +"Especifica o tempo limite (em segundos) após o qual o <citerefentry> " +"<refentrytitle>poll</refentrytitle> <manvolnum>2</manvolnum> </citerefentry>/" +"<citerefentry> <refentrytitle>select</refentrytitle> <manvolnum>2</" +"manvolnum> </citerefentry> seguindo de um <citerefentry> " +"<refentrytitle>connect</refentrytitle> <manvolnum>2</manvolnum> </" +"citerefentry> retorna em caso de nenhuma atividade." #. type: Content of: <refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3615 sssd-ldap.5.xml:700 include/failover.xml:84 +#: sssd.conf.5.xml:3762 sssd-ldap.5.xml:700 include/failover.xml:84 msgid "Default: 1000" msgstr "Predefinição: 1000" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3621 +#: sssd.conf.5.xml:3768 msgid "dns_resolver_op_timeout (integer)" msgstr "dns_resolver_op_timeout (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3624 +#: sssd.conf.5.xml:3771 msgid "" "Defines the amount of time (in seconds) to wait to resolve single DNS query " "(e.g. resolution of a hostname or an SRV record) before trying the next " @@ -5180,17 +5487,17 @@ msgstr "" "tentar o próximo nome de máquina ou descoberta DNS." #. type: Content of: <refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3635 include/failover.xml:100 +#: sssd.conf.5.xml:3798 include/failover.xml:100 msgid "Default: 3" msgstr "Predefinição: 3" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3641 +#: sssd.conf.5.xml:3804 msgid "dns_resolver_timeout (integer)" msgstr "dns_resolver_timeout (inteiro)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3644 +#: sssd.conf.5.xml:3807 msgid "" "Defines the amount of time (in seconds) to wait for a reply from the " "internal fail over service before assuming that the service is unreachable. " @@ -5203,12 +5510,14 @@ msgstr "" "offline." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3662 -msgid "dns_resolver_use_search_list (bool)" +#: sssd.conf.5.xml:3841 +#, fuzzy +#| msgid "dns_resolver_use_search_list (bool)" +msgid "dns_resolver_use_search_list (boolean)" msgstr "dns_resolver_use_search_list (booleano)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3665 +#: sssd.conf.5.xml:3844 msgid "" "Normally, the DNS resolver searches the domain list defined in the " "\"search\" directive from the resolv.conf file. This can lead to delays in " @@ -5219,7 +5528,7 @@ msgstr "" "com DNS configurado de modo inapropriado." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3671 +#: sssd.conf.5.xml:3850 msgid "" "If fully qualified domain names (or _srv_) are used in the SSSD " "configuration, setting this option to FALSE can prevent unnecessary DNS " @@ -5230,17 +5539,17 @@ msgstr "" "DNS desnecessárias em tais ambientes." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3677 +#: sssd.conf.5.xml:3856 msgid "Default: TRUE" msgstr "Predefinição: TRUE" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3683 +#: sssd.conf.5.xml:3862 msgid "dns_discovery_domain (string)" msgstr "dns_discovery_domain (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3686 +#: sssd.conf.5.xml:3865 msgid "" "If service discovery is used in the back end, specifies the domain part of " "the service discovery DNS query." @@ -5249,17 +5558,17 @@ msgstr "" "domínio da consulta DNS de descoberta de serviço." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3690 +#: sssd.conf.5.xml:3869 msgid "Default: Use the domain part of machine's hostname" msgstr "Predefinição: Usa a parte de domínio do nome-de-máquina das máquinas" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3696 +#: sssd.conf.5.xml:3875 msgid "failover_primary_timeout (integer)" msgstr "failover_primary_timeout (inteiro)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3699 +#: sssd.conf.5.xml:3878 msgid "" "When no primary server is available, SSSD fails over to a backup server. " "This option defines the number of seconds SSSD waits before attempting to " @@ -5270,58 +5579,71 @@ msgstr "" "antes de tentar se re-ligar ao servidor principal." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3706 +#: sssd.conf.5.xml:3885 msgid "Note: The minimum value is 31." msgstr "Nota: O valor mínimo é 31." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3709 +#: sssd.conf.5.xml:3888 msgid "Default: 31" msgstr "Predefinição: 31" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3715 +#: sssd.conf.5.xml:3894 msgid "override_gid (integer)" msgstr "override_gid (inteiro)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3718 -msgid "Override the primary GID value with the one specified." +#: sssd.conf.5.xml:3897 +#, fuzzy +#| msgid "Override the primary GID value with the one specified." +msgid "" +"Override the primary GID value for all users in the domain with specified " +"value." msgstr "Sobrepõe o valor GID principal com o que é especificado." +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3901 +#, fuzzy +#| msgid "Default: not set (SSSD will use the value retrieved from LDAP)" +msgid "" +"Default: not set (Use the primary GID value retrieved from the identity " +"provider)" +msgstr "Predefinição: não definida (o SSSD irá usar o valor obtido de LDAP)" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3724 +#: sssd.conf.5.xml:3908 msgid "case_sensitive (string)" msgstr "case_sensitive (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3731 +#: sssd.conf.5.xml:3915 msgid "True" msgstr "True" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3734 +#: sssd.conf.5.xml:3918 msgid "Case sensitive. This value is invalid for AD provider." msgstr "" "Sensível a maiúsculas/minúsculas. Este valor é inválido para provedor AD." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3740 +#: sssd.conf.5.xml:3924 msgid "False" msgstr "False" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3742 +#: sssd.conf.5.xml:3926 msgid "Case insensitive." msgstr "Insensível a maiúsculas/minúsculas." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3746 +#: sssd.conf.5.xml:3930 msgid "Preserving" msgstr "Preserving" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3749 +#: sssd.conf.5.xml:3933 msgid "" "Same as False (case insensitive), but does not lowercase names in the result " "of NSS operations. Note that name aliases (and in case of services also " @@ -5333,7 +5655,7 @@ msgstr "" "reduzidos a minúsculas nos resultados." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3757 +#: sssd.conf.5.xml:3941 msgid "" "If you want to set this value for trusted domain with IPA provider, you need " "to set it on both the client and SSSD on the server." @@ -5342,7 +5664,7 @@ msgstr "" "IPA, você precisa de defini-lo em ambos o cliente e no SSSD no servidor." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3727 +#: sssd.conf.5.xml:3911 msgid "" "Treat user and group names as case sensitive. Possible option values are: " "<placeholder type=\"variablelist\" id=\"0\"/>" @@ -5351,17 +5673,47 @@ msgstr "" "valores de opção possíveis são: <placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3772 +#: sssd.conf.5.xml:3956 msgid "Default: True (False for AD provider)" msgstr "Predefinição: True (False para provedor AD)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3778 +#: sssd.conf.5.xml:3962 +#, fuzzy +#| msgid "ad_enable_dns_sites (boolean)" +msgid "avoid_by_id_lookups (boolean)" +msgstr "ad_enable_dns_sites (booleano)" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3965 +msgid "" +"If this option is set to 'true' SSSD will try to avoid sending lookups by ID " +"to the backend and will switch to a lookup by name if a cached object with a " +"matching ID can be found." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3971 +msgid "" +"This option can e.g. be used in cases where searches by ID are expensive on " +"the server side because of missing indexes or are not even possible, e.g. " +"due to non-reversible POSIX id-mapping." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3978 +#, fuzzy +#| msgid "Default: True (False for AD provider)" +msgid "Default: False (True for IdP provider)" +msgstr "Predefinição: True (False para provedor AD)" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:3984 msgid "subdomain_inherit (string)" msgstr "subdomain_inherit (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3781 +#: sssd.conf.5.xml:3987 msgid "" "Specifies a list of configuration parameters that should be inherited by a " "subdomain. Please note that only selected parameters can be inherited. " @@ -5372,37 +5724,37 @@ msgstr "" "podem ser herdados. Actualmente as seguintes opções podem ser herdadas:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3787 +#: sssd.conf.5.xml:3993 msgid "ldap_search_timeout" msgstr "ldap_search_timeout" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3790 +#: sssd.conf.5.xml:3996 msgid "ldap_network_timeout" msgstr "ldap_network_timeout" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3793 +#: sssd.conf.5.xml:3999 msgid "ldap_opt_timeout" msgstr "ldap_opt_timeout" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3796 +#: sssd.conf.5.xml:4002 msgid "ldap_offline_timeout" msgstr "ldap_offline_timeout" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3799 +#: sssd.conf.5.xml:4005 msgid "ldap_purge_cache_timeout" msgstr "ldap_purge_cache_timeout" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3802 +#: sssd.conf.5.xml:4008 msgid "ldap_purge_cache_offset" msgstr "ldap_purge_cache_offset" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3805 +#: sssd.conf.5.xml:4011 msgid "" "ldap_krb5_keytab (the value of krb5_keytab will be used if ldap_krb5_keytab " "is not set explicitly)" @@ -5411,52 +5763,52 @@ msgstr "" "estiver definido explicitamente)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3809 +#: sssd.conf.5.xml:4015 msgid "ldap_krb5_ticket_lifetime" msgstr "ldap_krb5_ticket_lifetime" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3812 +#: sssd.conf.5.xml:4018 msgid "ldap_connection_expire_timeout" msgstr "ldap_connection_expire_timeout" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3815 +#: sssd.conf.5.xml:4021 msgid "ldap_connection_expire_offset" msgstr "ldap_connection_expire_offset" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3818 +#: sssd.conf.5.xml:4024 msgid "ldap_connection_idle_timeout" msgstr "ldap_connection_idle_timeout" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3821 sssd-ldap.5.xml:446 +#: sssd.conf.5.xml:4027 sssd-ldap.5.xml:446 msgid "ldap_use_tokengroups" msgstr "ldap_use_tokengroups" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3824 +#: sssd.conf.5.xml:4030 msgid "ldap_user_principal" msgstr "ldap_user_principal" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3827 +#: sssd.conf.5.xml:4033 msgid "ignore_group_members" msgstr "ignore_group_members" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3830 +#: sssd.conf.5.xml:4036 msgid "auto_private_groups" msgstr "auto_private_groups" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3833 +#: sssd.conf.5.xml:4039 msgid "case_sensitive" msgstr "case_sensitive" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:3838 +#: sssd.conf.5.xml:4044 #, no-wrap msgid "" "subdomain_inherit = ldap_purge_cache_timeout\n" @@ -5466,27 +5818,27 @@ msgstr "" " " #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3845 +#: sssd.conf.5.xml:4051 msgid "Note: This option only works with the IPA and AD provider." msgstr "Nota: Esta opção apenas funciona com provedores IPA e AD." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3852 +#: sssd.conf.5.xml:4058 msgid "subdomain_homedir (string)" msgstr "subdomain_homedir (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3863 +#: sssd.conf.5.xml:4069 msgid "%F" msgstr "%F" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3864 +#: sssd.conf.5.xml:4070 msgid "flat (NetBIOS) name of a subdomain." msgstr "nome simples (NetBIOS) de um subdomínio." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3855 +#: sssd.conf.5.xml:4061 msgid "" "Use this homedir as default value for all subdomains within this domain in " "IPA AD trust. See <emphasis>override_homedir</emphasis> for info about " @@ -5501,24 +5853,24 @@ msgstr "" "emphasis>. <placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3869 +#: sssd.conf.5.xml:4075 msgid "" "The value can be overridden by <emphasis>override_homedir</emphasis> option." msgstr "" "O valor pode ser sobreposto pela opção <emphasis>override_homedir</emphasis>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3873 +#: sssd.conf.5.xml:4079 msgid "Default: <filename>/home/%d/%u</filename>" msgstr "Predefinição: <filename>/home/%d/%u</filename>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3878 +#: sssd.conf.5.xml:4084 msgid "realmd_tags (string)" msgstr "realmd_tags (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3881 +#: sssd.conf.5.xml:4087 msgid "" "Various tags stored by the realmd configuration service for this domain." msgstr "" @@ -5526,17 +5878,23 @@ msgstr "" "domínio." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3887 +#: sssd.conf.5.xml:4093 msgid "cached_auth_timeout (int)" msgstr "cached_auth_timeout (inteiro)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3890 +#: sssd.conf.5.xml:4096 +#, fuzzy +#| msgid "" +#| "Specifies time in seconds since last successful online authentication for " +#| "which user will be authenticated using cached credentials while SSSD is " +#| "in the online mode. If the credentials are incorrect, SSSD falls back to " +#| "online authentication." msgid "" -"Specifies time in seconds since last successful online authentication for " -"which user will be authenticated using cached credentials while SSSD is in " -"the online mode. If the credentials are incorrect, SSSD falls back to online " -"authentication." +"Specifies the number of seconds since the last successful online " +"authentication during which SSSD will authenticate users via cached " +"credentials, even while online. If the cached authentication fails, SSSD " +"immediately falls back to online authentication." msgstr "" "Especifica o tempo em segundos desde a última autenticação online com " "sucesso para qual o utilizador será autenticado usando credenciais em cache " @@ -5544,7 +5902,7 @@ msgstr "" "o SSSD regressa à autenticação online." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3898 +#: sssd.conf.5.xml:4103 msgid "" "This option's value is inherited by all trusted domains. At the moment it is " "not possible to set a different value per trusted domain." @@ -5553,12 +5911,12 @@ msgstr "" "momento não é possível definir um valor diferente por domínio de confiança." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3903 +#: sssd.conf.5.xml:4108 msgid "Special value 0 implies that this feature is disabled." msgstr "O valor especial 0 implica que esta funcionalidade é desactivada." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3907 +#: sssd.conf.5.xml:4112 msgid "" "Please note that if <quote>cached_auth_timeout</quote> is longer than " "<quote>pam_id_timeout</quote> then the back end could be called to handle " @@ -5569,12 +5927,12 @@ msgstr "" "com <quote>initgroups.</quote>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3918 +#: sssd.conf.5.xml:4123 msgid "local_auth_policy (string)" msgstr "local_auth_policy (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3921 +#: sssd.conf.5.xml:4126 msgid "" "Local authentication methods policy. Some backends (i.e. LDAP, proxy " "provider) only support a password based authentication, while others can " @@ -5594,7 +5952,7 @@ msgstr "" "localmente." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3933 +#: sssd.conf.5.xml:4138 msgid "" "There are three possible values for this option: match, only, enable. " "<quote>match</quote> is used to match offline and online states for Kerberos " @@ -5614,7 +5972,7 @@ msgstr "" "enable:smartcard</quote>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3946 +#: sssd.conf.5.xml:4151 msgid "" "The following table shows which authentication methods, if configured " "properly, are currently enabled or disabled for each backend, with the " @@ -5625,42 +5983,47 @@ msgstr "" "a local_auth_policy predefinida: <quote>match</quote>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> -#: sssd.conf.5.xml:3959 +#: sssd.conf.5.xml:4164 msgid "local_auth_policy = match (default)" msgstr "local_auth_policy = match (predefinição)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> -#: sssd.conf.5.xml:3960 +#: sssd.conf.5.xml:4165 msgid "Passkey" msgstr "Passkey" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> -#: sssd.conf.5.xml:3961 +#: sssd.conf.5.xml:4166 msgid "Smartcard" msgstr "Smartcard" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:3964 sssd-ldap.5.xml:228 +#: sssd.conf.5.xml:4169 sssd-ldap.5.xml:228 msgid "IPA" msgstr "IPA" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry><para> +#: sssd.conf.5.xml:4169 sssd.conf.5.xml:4170 sssd.conf.5.xml:4173 +msgid "enabled" +msgstr "enabled" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:3967 sssd-ldap.5.xml:233 +#: sssd.conf.5.xml:4172 sssd-ldap.5.xml:233 msgid "AD" msgstr "AD" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry><para> -#: sssd.conf.5.xml:3967 sssd.conf.5.xml:3970 sssd.conf.5.xml:3971 +#: sssd.conf.5.xml:4172 sssd.conf.5.xml:4175 sssd.conf.5.xml:4176 msgid "disabled" msgstr "desactivado" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry> -#: sssd.conf.5.xml:3970 +#: sssd.conf.5.xml:4175 msgid "LDAP" msgstr "LDAP" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3975 +#: sssd.conf.5.xml:4180 msgid "" "Please note that if local Smartcard authentication is enabled and a " "Smartcard is present, Smartcard authentication will be preferred over the " @@ -5673,7 +6036,7 @@ msgstr "" "em vez de, por exemplo, um pedido de palavra passe." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:3987 +#: sssd.conf.5.xml:4192 #, no-wrap msgid "" "[domain/shadowutils]\n" @@ -5689,7 +6052,7 @@ msgstr "" "local_auth_policy = only\n" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3983 +#: sssd.conf.5.xml:4188 msgid "" "The following configuration example allows local users to authenticate " "locally using any enabled method (i.e. smartcard, passkey). <placeholder " @@ -5700,22 +6063,22 @@ msgstr "" "passkey). <placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3995 +#: sssd.conf.5.xml:4200 msgid "Default: match" msgstr "Predefinição: match" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4000 +#: sssd.conf.5.xml:4205 msgid "auto_private_groups (string)" msgstr "auto_private_groups (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4006 +#: sssd.conf.5.xml:4211 msgid "true" msgstr "true" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4009 +#: sssd.conf.5.xml:4214 msgid "" "Create user's private group unconditionally from user's UID number. The GID " "number is ignored in this case." @@ -5724,7 +6087,7 @@ msgstr "" "do utilizador. O número GID é ignorado neste caso." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4013 +#: sssd.conf.5.xml:4218 msgid "" "NOTE: Because the GID number and the user private group are inferred from " "the UID number, it is not supported to have multiple entries with the same " @@ -5737,12 +6100,12 @@ msgstr "" "reforça a singularidade entre o espaço de ID." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4022 +#: sssd.conf.5.xml:4227 msgid "false" msgstr "false" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4025 +#: sssd.conf.5.xml:4230 msgid "" "Always use the user's primary GID number. The GID number must refer to a " "group object in the LDAP database." @@ -5751,12 +6114,12 @@ msgstr "" "referir a um objecto grupo na base de dados do LDAP." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4031 +#: sssd.conf.5.xml:4236 msgid "hybrid" msgstr "hybrid" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4034 +#: sssd.conf.5.xml:4239 msgid "" "A primary group is autogenerated for user entries whose UID and GID numbers " "have the same value and at the same time the GID number does not correspond " @@ -5771,7 +6134,7 @@ msgstr "" "GID primário do utilizador resolve para esse objecto grupo." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4047 +#: sssd.conf.5.xml:4252 msgid "" "If the UID and GID of a user are different, then the GID must correspond to " "a group entry, otherwise the GID is simply not resolvable." @@ -5781,7 +6144,7 @@ msgstr "" "resolvível." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4054 +#: sssd.conf.5.xml:4259 msgid "" "This feature is useful for environments that wish to stop maintaining a " "separate group objects for the user private groups, but also wish to retain " @@ -5792,7 +6155,7 @@ msgstr "" "deseja reter os grupos privados existentes de utilizador." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4003 +#: sssd.conf.5.xml:4208 msgid "" "This option takes any of three available values: <placeholder " "type=\"variablelist\" id=\"0\"/>" @@ -5801,7 +6164,7 @@ msgstr "" "type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4066 +#: sssd.conf.5.xml:4271 msgid "" "For the LDAP based id providers (LDAP, IPA and AD) the default for the " "configured domain is typically False because the sources have the concept of " @@ -5816,7 +6179,7 @@ msgstr "" "phrase>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4075 +#: sssd.conf.5.xml:4280 msgid "" "For subdomains, the default value is False for subdomains that use assigned " "POSIX IDs and True for subdomains that use automatic ID-mapping." @@ -5825,7 +6188,7 @@ msgstr "" "POSIX assinados e True para subdomínios que usam mapeamento de ID automático." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:4083 +#: sssd.conf.5.xml:4288 #, no-wrap msgid "" "[domain/forest.domain/sub.domain]\n" @@ -5835,7 +6198,7 @@ msgstr "" "auto_private_groups = false\n" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:4089 +#: sssd.conf.5.xml:4294 #, no-wrap msgid "" "[domain/forest.domain]\n" @@ -5847,7 +6210,7 @@ msgstr "" "auto_private_groups = false\n" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4080 +#: sssd.conf.5.xml:4285 msgid "" "The value of auto_private_groups can either be set per subdomains in a " "subsection, for example: <placeholder type=\"programlisting\" id=\"0\"/> or " @@ -5860,7 +6223,7 @@ msgstr "" "a opção subdomain_inherit: <placeholder type=\"programlisting\" id=\"1\"/>" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:2503 +#: sssd.conf.5.xml:2549 msgid "" "These configuration options can be present in a domain configuration " "section, that is, in a section called <quote>[domain/<replaceable>NAME</" @@ -5872,17 +6235,17 @@ msgstr "" "id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4104 +#: sssd.conf.5.xml:4309 msgid "proxy_pam_target (string)" msgstr "proxy_pam_target (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4107 +#: sssd.conf.5.xml:4312 msgid "The proxy target PAM proxies to." msgstr "O alvo proxy que o PAM \"proxia\"." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4110 +#: sssd.conf.5.xml:4315 msgid "" "Default: not set by default, you have to take an existing pam configuration " "or create a new one and add the service name here. As an alternative you can " @@ -5894,12 +6257,12 @@ msgstr "" "local_auth_policy." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4120 +#: sssd.conf.5.xml:4325 msgid "proxy_lib_name (string)" msgstr "proxy_lib_name (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4123 +#: sssd.conf.5.xml:4328 msgid "" "The name of the NSS library to use in proxy domains. The NSS functions " "searched for in the library are in the form of _nss_$(libName)_$(function), " @@ -5910,12 +6273,12 @@ msgstr "" "_nss_files_getpwent." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4133 +#: sssd.conf.5.xml:4338 msgid "proxy_resolver_lib_name (string)" msgstr "proxy_resolver_lib_name (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4136 +#: sssd.conf.5.xml:4341 msgid "" "The name of the NSS library to use for hosts and networks lookups in proxy " "domains. The NSS functions searched for in the library are in the form of " @@ -5926,12 +6289,12 @@ msgstr "" "(libName)_$(function), por exemplo _nss_dns_gethostbyname2_r." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4147 +#: sssd.conf.5.xml:4352 msgid "proxy_fast_alias (boolean)" msgstr "proxy_fast_alias (booleano)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4150 +#: sssd.conf.5.xml:4355 msgid "" "When a user or group is looked up by name in the proxy provider, a second " "lookup by ID is performed to \"canonicalize\" the name in case the requested " @@ -5944,12 +6307,12 @@ msgstr "" "SSSD execute a procura de ID a partir da cache por razões de performance." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4164 +#: sssd.conf.5.xml:4369 msgid "proxy_max_children (integer)" msgstr "proxy_max_children (inteiro)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4167 +#: sssd.conf.5.xml:4372 msgid "" "This option specifies the number of pre-forked proxy children. It is useful " "for high-load SSSD environments where sssd may run out of available child " @@ -5961,7 +6324,7 @@ msgstr "" "postos em fila de espera." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4100 +#: sssd.conf.5.xml:4305 msgid "" "Options valid for proxy domains. <placeholder type=\"variablelist\" " "id=\"0\"/>" @@ -5970,12 +6333,12 @@ msgstr "" "id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:4183 +#: sssd.conf.5.xml:4388 msgid "Application domains" msgstr "Domínios Application" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:4185 +#: sssd.conf.5.xml:4390 msgid "" "SSSD, with its D-Bus interface (see <citerefentry> <refentrytitle>sssd-ifp</" "refentrytitle> <manvolnum>5</manvolnum> </citerefentry>) is appealing to " @@ -6004,7 +6367,7 @@ msgstr "" "<quote>application</quote> a partir de um domínio tradicional SSSD." #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:4205 +#: sssd.conf.5.xml:4410 msgid "" "Please note that the application domain must still be explicitly enabled in " "the <quote>domains</quote> parameter so that the lookup order between the " @@ -6016,17 +6379,17 @@ msgstr "" "corretamente." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><title> -#: sssd.conf.5.xml:4211 +#: sssd.conf.5.xml:4416 msgid "Application domain parameters" msgstr "Parâmetros de domínio Application" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4213 +#: sssd.conf.5.xml:4418 msgid "inherit_from (string)" msgstr "inherit_from (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4216 +#: sssd.conf.5.xml:4421 msgid "" "The SSSD POSIX-type domain the application domain inherits all settings " "from. The application domain can moreover add its own settings to the " @@ -6039,7 +6402,7 @@ msgstr "" "<quote>sibling</quote>." #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:4230 +#: sssd.conf.5.xml:4435 msgid "" "The following example illustrates the use of an application domain. In this " "setup, the POSIX domain is connected to an LDAP server and is used by the OS " @@ -6054,7 +6417,7 @@ msgstr "" "na cache e torna o atributo telefone acessível através da interface D-Bus." #. type: Content of: <reference><refentry><refsect1><refsect2><programlisting> -#: sssd.conf.5.xml:4238 +#: sssd.conf.5.xml:4443 #, no-wrap msgid "" "[sssd]\n" @@ -6088,12 +6451,12 @@ msgstr "" "ldap_user_extra_attrs = phone:telephoneNumber\n" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:4258 +#: sssd.conf.5.xml:4463 msgid "TRUSTED DOMAIN SECTION" msgstr "SECÇÃO DE DOMÍNIO DE CONFIANÇA" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4260 +#: sssd.conf.5.xml:4465 msgid "" "Some options used in the domain section can also be used in the trusted " "domain section, that is, in a section called <quote>[domain/" @@ -6110,57 +6473,67 @@ msgstr "" "suportadas na secção de domínio de confiança são:" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4267 +#: sssd.conf.5.xml:4472 msgid "ldap_search_base," msgstr "ldap_search_base," #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4268 +#: sssd.conf.5.xml:4473 msgid "ldap_user_search_base," msgstr "ldap_user_search_base," #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4269 +#: sssd.conf.5.xml:4474 msgid "ldap_group_search_base," msgstr "ldap_group_search_base," #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4270 +#: sssd.conf.5.xml:4475 msgid "ldap_netgroup_search_base," msgstr "ldap_netgroup_search_base," #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4271 +#: sssd.conf.5.xml:4476 msgid "ldap_service_search_base," msgstr "ldap_service_search_base," #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4272 +#: sssd.conf.5.xml:4477 msgid "ldap_sasl_mech," msgstr "ldap_sasl_mech," #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4273 +#: sssd.conf.5.xml:4478 msgid "ad_server," msgstr "ad_server," #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4274 +#: sssd.conf.5.xml:4479 msgid "ad_backup_server," msgstr "ad_backup_server," #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4275 +#: sssd.conf.5.xml:4480 msgid "ad_site," msgstr "ad_site," #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:4276 sssd-ipa.5.xml:934 +#: sssd.conf.5.xml:4481 sssd-ipa.5.xml:929 msgid "use_fully_qualified_names" msgstr "use_fully_qualified_names" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4280 +#: sssd.conf.5.xml:4482 +msgid "pam_gssapi_services" +msgstr "pam_gssapi_services" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:4483 +msgid "pam_gssapi_check_upn" +msgstr "pam_gssapi_check_upn" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:4485 msgid "" "For more details about these options see their individual description in the " "manual page." @@ -6169,12 +6542,12 @@ msgstr "" "no manual." #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:4286 +#: sssd.conf.5.xml:4491 msgid "CERTIFICATE MAPPING SECTION" msgstr "SECÇÃO DE MAPEAMENTO DE CERTIFICADO" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4288 +#: sssd.conf.5.xml:4493 msgid "" "To allow authentication with Smartcards and certificates SSSD must be able " "to map certificates to users. This can be done by adding the full " @@ -6196,7 +6569,7 @@ msgstr "" "usam PAM para autenticação.." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4302 +#: sssd.conf.5.xml:4507 msgid "" "To make the mapping more flexible mapping and matching rules were added to " "SSSD (see <citerefentry> <refentrytitle>sss-certmap</refentrytitle> " @@ -6208,7 +6581,7 @@ msgstr "" "citerefentry> para detalhes)." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4311 +#: sssd.conf.5.xml:4516 msgid "" "A mapping and matching rule can be added to the SSSD configuration in a " "section on its own with a name like <quote>[certmap/" @@ -6221,12 +6594,12 @@ msgstr "" "Nesta secção são permitidas as seguintes opções:" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4318 +#: sssd.conf.5.xml:4523 msgid "matchrule (string)" msgstr "matchrule (string)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4321 +#: sssd.conf.5.xml:4526 msgid "" "Only certificates from the Smartcard which matches this rule will be " "processed, all others are ignored." @@ -6235,7 +6608,7 @@ msgstr "" "processados, todos os outros serão ignorados." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4325 +#: sssd.conf.5.xml:4530 msgid "" "Default: KRB5:<EKU>clientAuth, i.e. only certificates which have the " "Extended Key Usage <quote>clientAuth</quote>" @@ -6244,17 +6617,17 @@ msgstr "" "têm a Utilização de Chave Estendida <quote>clientAuth</quote>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4332 +#: sssd.conf.5.xml:4537 msgid "maprule (string)" msgstr "maprule (string)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4335 +#: sssd.conf.5.xml:4540 msgid "Defines how the user is found for a given certificate." msgstr "Define como um utilizador é encontrado para um dado certificado." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:4341 +#: sssd.conf.5.xml:4546 msgid "" "LDAP:(userCertificate;binary={cert!bin}) for LDAP based providers like " "<quote>ldap</quote>, <quote>AD</quote> or <quote>ipa</quote>." @@ -6263,7 +6636,7 @@ msgstr "" "como <quote>ldap</quote>, <quote>AD</quote> ou <quote>ipa</quote>." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:4347 +#: sssd.conf.5.xml:4552 msgid "" "If maprule is not set and provider is <quote>proxy</quote>, the RULE_NAME " "name is assumed to be the name of the matching user." @@ -6271,13 +6644,8 @@ msgstr "" "se maprule não estiver definida e o provedor for <quote>proxy</quote>, o " "nome RULE_NAME é assumido para ser o nome do utilizador correspondente." -#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4357 -msgid "domains (string)" -msgstr "domains (string)" - #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4360 +#: sssd.conf.5.xml:4565 msgid "" "Comma separated list of domain names the rule should be applied. By default " "a rule is only valid in the domain configured in sssd.conf. If the provider " @@ -6290,17 +6658,17 @@ msgstr "" "para adicionar a regra também a subdomínios." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4367 +#: sssd.conf.5.xml:4572 msgid "Default: the configured domain in sssd.conf" msgstr "Predefinição: o domínio configurado em sssd.conf" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4372 +#: sssd.conf.5.xml:4577 msgid "priority (integer)" msgstr "priority (inteiro)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4375 +#: sssd.conf.5.xml:4580 msgid "" "Unsigned integer value defining the priority of the rule. The higher the " "number the lower the priority. <quote>0</quote> stands for the highest " @@ -6311,17 +6679,17 @@ msgstr "" "alta prioridade enquanto <quote>4294967295</quote> é a mais baixa." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4381 +#: sssd.conf.5.xml:4586 msgid "Default: the lowest priority" msgstr "Predefinição: a prioridade mais baixa" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:4389 +#: sssd.conf.5.xml:4594 msgid "PROMPTING CONFIGURATION SECTION" msgstr "SECÇÃO DE CONFIGURAÇÃO DE INCITAÇÃO" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4391 +#: sssd.conf.5.xml:4596 msgid "" "If a special file (<filename>/var/lib/sss/pubconf/pam_preauth_available</" "filename>) exists SSSD's PAM module pam_sss will ask SSSD to figure out " @@ -6336,7 +6704,7 @@ msgstr "" "resultados o pam_sss irá incitar o utilizador pelas credenciais apropriadas." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4399 +#: sssd.conf.5.xml:4604 msgid "" "With the growing number of authentication methods and the possibility that " "there are multiple ones for a single user the heuristic used by pam_sss to " @@ -6349,22 +6717,22 @@ msgstr "" "seguintes opções fornecem melhor flexibilidade aqui." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4411 +#: sssd.conf.5.xml:4616 msgid "[prompting/password]" msgstr "[prompting/password]" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4414 +#: sssd.conf.5.xml:4619 msgid "password_prompt" msgstr "password_prompt" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4415 +#: sssd.conf.5.xml:4620 msgid "to change the string of the password prompt" msgstr "para alterar o texto da incitação da palavra passe" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4413 +#: sssd.conf.5.xml:4618 msgid "" "to configure password prompting, allowed options are: <placeholder " "type=\"variablelist\" id=\"0\"/>" @@ -6373,37 +6741,37 @@ msgstr "" "<placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4423 +#: sssd.conf.5.xml:4628 msgid "[prompting/2fa]" msgstr "[prompting/2fa]" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4427 +#: sssd.conf.5.xml:4632 msgid "first_prompt" msgstr "first_prompt" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4428 +#: sssd.conf.5.xml:4633 msgid "to change the string of the prompt for the first factor" msgstr "para alterar a string da incitação para o primeiro factor" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4431 +#: sssd.conf.5.xml:4636 msgid "second_prompt" msgstr "second_prompt" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4432 +#: sssd.conf.5.xml:4637 msgid "to change the string of the prompt for the second factor" msgstr "para alterar o texto da incitação para o segundo factor" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4435 +#: sssd.conf.5.xml:4640 msgid "single_prompt" msgstr "single_prompt" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4436 +#: sssd.conf.5.xml:4641 msgid "" "boolean value, if True there will be only a single prompt using the value of " "first_prompt where it is expected that both factors are entered as a single " @@ -6416,7 +6784,7 @@ msgstr "" "que o segundo factor seja opcional." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4425 +#: sssd.conf.5.xml:4630 msgid "" "to configure two-factor authentication prompting, allowed options are: " "<placeholder type=\"variablelist\" id=\"0\"/> If the second factor is " @@ -6429,7 +6797,7 @@ msgstr "" "passe ou com ambos factores a incitação de dois-passos tem de ser usada." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4449 +#: sssd.conf.5.xml:4654 msgid "" "Some clients, such as SSH with 'PasswordAuthentication yes', generate their " "own prompts and do not use prompts provided by SSSD or other PAM modules. " @@ -6447,17 +6815,17 @@ msgstr "" "opcional." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4464 +#: sssd.conf.5.xml:4669 msgid "[prompting/passkey]" msgstr "[prompting/passkey]" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:4470 sssd-ad.5.xml:1022 +#: sssd.conf.5.xml:4675 sssd.conf.5.xml:4719 sssd-ad.5.xml:1027 msgid "interactive" msgstr "interactive" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4472 +#: sssd.conf.5.xml:4677 msgid "" "boolean value, if True prompt a message and wait before testing the presence " "of a passkey device. Recommended if your device doesn’t have a tactile " @@ -6468,22 +6836,22 @@ msgstr "" "tiver um gatilho táctico." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4480 +#: sssd.conf.5.xml:4685 sssd.conf.5.xml:4735 msgid "interactive_prompt" msgstr "interactive_prompt" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4482 +#: sssd.conf.5.xml:4687 sssd.conf.5.xml:4737 msgid "to change the message of the interactive prompt." msgstr "para alterar a mensagem da incitação interactiva." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4487 +#: sssd.conf.5.xml:4692 msgid "touch" msgstr "touch" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4489 +#: sssd.conf.5.xml:4694 msgid "" "boolean value, if True prompt a message to remind the user to touch the " "device." @@ -6492,17 +6860,17 @@ msgstr "" "no dispositivo." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4495 +#: sssd.conf.5.xml:4700 msgid "touch_prompt" msgstr "touch_prompt" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4497 +#: sssd.conf.5.xml:4702 msgid "to change the message of the touch prompt." msgstr "para mudar a mensagem do aviso de toque." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4466 +#: sssd.conf.5.xml:4671 msgid "" "to configure passkey authentication prompting, allowed options are: " "<placeholder type=\"variablelist\" id=\"0\"/>" @@ -6510,21 +6878,131 @@ msgstr "" "para configura a incitação a autenticação passkey, as opções permitidas são: " "<placeholder type=\"variablelist\" id=\"0\"/>" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4713 +#, fuzzy +#| msgid "[prompting/2fa]" +msgid "[prompting/oauth2]" +msgstr "[prompting/2fa]" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4721 +#, fuzzy +#| msgid "" +#| "boolean value, if True prompt a message to remind the user to touch the " +#| "device." +msgid "" +"boolean value, if True prompt a message after asking the user to " +"authenticate, and wait before requesting the access token." +msgstr "" +"valor booleano, se True incita uma mensagem a lembrar o utilizador a tocar " +"no dispositivo." + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4725 +msgid "" +"If False, make sure to set the <quote>idp_request_timeout</quote> " +"sufficiently high, to give the user time to authenticate." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4715 +#, fuzzy +#| msgid "" +#| "to configure passkey authentication prompting, allowed options are: " +#| "<placeholder type=\"variablelist\" id=\"0\"/>" +msgid "" +"to configure OAuth2 authentication prompting, allowed options are: " +"<placeholder type=\"variablelist\" id=\"0\"/>" +msgstr "" +"para configura a incitação a autenticação passkey, as opções permitidas são: " +"<placeholder type=\"variablelist\" id=\"0\"/>" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4748 +#, fuzzy +#| msgid "[prompting/2fa]" +msgid "[prompting/cert_auth]" +msgstr "[prompting/2fa]" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4754 +#, fuzzy +#| msgid "single_prompt" +msgid "pin_prompt" +msgstr "single_prompt" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4756 +msgid "" +"to change the message which asks the user to enter the PIN at the computer " +"keyboard. At the end of the message the token name is printed." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4764 +#, fuzzy +#| msgid "password_prompt" +msgid "keypad_prompt" +msgstr "password_prompt" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4766 +msgid "" +"to change the message which asks the user to enter the PIN at keypad of the " +"Smartcard reader. At the end of the message the token name is printed." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4774 +#, fuzzy +#| msgid "username" +msgid "user_name_hint" +msgstr "nome de utilizador" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4776 +msgid "" +"boolean value, if True ask for a user name if no name was given before and " +"the found certificate can be mapped to more than one user." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4750 +#, fuzzy +#| msgid "" +#| "to configure passkey authentication prompting, allowed options are: " +#| "<placeholder type=\"variablelist\" id=\"0\"/>" +msgid "" +"to configure Smartcard authentication prompting, allowed options are: " +"<placeholder type=\"variablelist\" id=\"0\"/>" +msgstr "" +"para configura a incitação a autenticação passkey, as opções permitidas são: " +"<placeholder type=\"variablelist\" id=\"0\"/>" + #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4406 +#: sssd.conf.5.xml:4611 +#, fuzzy +#| msgid "" +#| "Each supported authentication method has its own configuration subsection " +#| "under <quote>[prompting/...]</quote>. Currently there are: <placeholder " +#| "type=\"variablelist\" id=\"0\"/> <placeholder type=\"variablelist\" " +#| "id=\"1\"/> <placeholder type=\"variablelist\" id=\"2\"/>" msgid "" "Each supported authentication method has its own configuration subsection " "under <quote>[prompting/...]</quote>. Currently there are: <placeholder " "type=\"variablelist\" id=\"0\"/> <placeholder type=\"variablelist\" id=\"1\"/" -"> <placeholder type=\"variablelist\" id=\"2\"/>" +"> <placeholder type=\"variablelist\" id=\"2\"/> <placeholder " +"type=\"variablelist\" id=\"3\"/> <placeholder type=\"variablelist\" id=\"4\"/" +">" msgstr "" "Cada método de autenticação suportado tem a sua sub-secção de configuração " "sub <quote>[prompting/...]</quote>. Actualmente existem: <placeholder " -"type=\"variablelist\" id=\"0\"/> <placeholder type=\"variablelist\" " -"id=\"1\"/> <placeholder type=\"variablelist\" id=\"2\"/>" +"type=\"variablelist\" id=\"0\"/> <placeholder type=\"variablelist\" id=\"1\"/" +"> <placeholder type=\"variablelist\" id=\"2\"/>" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4508 +#: sssd.conf.5.xml:4792 msgid "" "It is possible to add a subsection for specific PAM services, e.g. " "<quote>[prompting/password/sshd]</quote> to individual change the prompting " @@ -6535,12 +7013,12 @@ msgstr "" "incitação para este serviço." #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:4515 pam_sss_gss.8.xml:157 idmap_sss.8.xml:43 +#: sssd.conf.5.xml:4799 pam_sss_gss.8.xml:157 idmap_sss.8.xml:43 msgid "EXAMPLES" msgstr "EXEMPLOS" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd.conf.5.xml:4521 +#: sssd.conf.5.xml:4805 #, no-wrap msgid "" "[sssd]\n" @@ -6592,7 +7070,7 @@ msgstr "" "enumerate = False\n" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4517 +#: sssd.conf.5.xml:4801 msgid "" "1. The following example shows a typical SSSD config. It does not describe " "configuration of the domains themselves - refer to documentation on " @@ -6605,7 +7083,7 @@ msgstr "" "type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd.conf.5.xml:4553 +#: sssd.conf.5.xml:4837 #, no-wrap msgid "" "[domain/ipa.com/child.ad.com]\n" @@ -6615,7 +7093,7 @@ msgstr "" "use_fully_qualified_names = false\n" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4547 +#: sssd.conf.5.xml:4831 msgid "" "2. The following example shows configuration of IPA AD trust where the AD " "forest consists of two domains in a parent-child structure. Suppose IPA " @@ -6632,7 +7110,7 @@ msgstr "" "type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd.conf.5.xml:4564 +#: sssd.conf.5.xml:4848 #, no-wrap msgid "" "[certmap/my.domain/rule_name]\n" @@ -6648,7 +7126,7 @@ msgstr "" "priority = 10\n" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4558 +#: sssd.conf.5.xml:4842 msgid "" "3. The following example shows the configuration of a certificate mapping " "rule. It is valid for the configured domain <quote>my.domain</quote> and " @@ -6883,13 +7361,21 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:151 +#, fuzzy +#| msgid "" +#| "Default: If not set, the value of the defaultNamingContext or " +#| "namingContexts attribute from the RootDSE of the LDAP server is used. If " +#| "defaultNamingContext does not exist or has an empty value namingContexts " +#| "is used. The namingContexts attribute must have a single value with the " +#| "DN of the search base of the LDAP server to make this work. Multiple " +#| "values are are not supported." msgid "" "Default: If not set, the value of the defaultNamingContext or namingContexts " "attribute from the RootDSE of the LDAP server is used. If " "defaultNamingContext does not exist or has an empty value namingContexts is " "used. The namingContexts attribute must have a single value with the DN of " "the search base of the LDAP server to make this work. Multiple values are " -"are not supported." +"not supported." msgstr "" "Predefinição: Se não definida, é usado o valor do atributo " "defaultNamingContext ou namingContexts a partir de RootDSE do servidor LDAP. " @@ -7259,8 +7745,8 @@ msgstr "" "anfitrião." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap.5.xml:472 sssd-ipa.5.xml:506 sssd-ipa.5.xml:525 sssd-ipa.5.xml:544 -#: sssd-ipa.5.xml:563 +#: sssd-ldap.5.xml:472 sssd-ipa.5.xml:501 sssd-ipa.5.xml:520 sssd-ipa.5.xml:539 +#: sssd-ipa.5.xml:558 msgid "" "See <quote>ldap_search_base</quote> for information about configuring " "multiple search bases." @@ -7269,7 +7755,7 @@ msgstr "" "múltiplas bases de busca." #. type: Content of: <listitem><para> -#: sssd-ldap.5.xml:477 sssd-ipa.5.xml:511 include/ldap_search_bases.xml:27 +#: sssd-ldap.5.xml:477 sssd-ipa.5.xml:506 include/ldap_search_bases.xml:27 msgid "Default: the value of <emphasis>ldap_search_base</emphasis>" msgstr "Predefinição: o valor de <emphasis>ldap_search_base</emphasis>" @@ -7416,13 +7902,21 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:621 +#, fuzzy +#| msgid "" +#| "If the connection is idle (not actively running an operation) within " +#| "<emphasis>ldap_opt_timeout</emphasis> seconds of expiration, then it will " +#| "be closed early to ensure that a new query cannot require the connection " +#| "to remain open past its expiration. This implies that connections will " +#| "always be closed immediately and will never be reused if " +#| "<emphasis>ldap_connection_expire_timeout <= ldap_opt_timout</emphasis>" msgid "" "If the connection is idle (not actively running an operation) within " "<emphasis>ldap_opt_timeout</emphasis> seconds of expiration, then it will be " "closed early to ensure that a new query cannot require the connection to " "remain open past its expiration. This implies that connections will always " "be closed immediately and will never be reused if " -"<emphasis>ldap_connection_expire_timeout <= ldap_opt_timout</emphasis>" +"<emphasis>ldap_connection_expire_timeout <= ldap_opt_timeout</emphasis>" msgstr "" "Se a ligação estiver em espera (não ativamente a correr uma operação) dentro " "de <emphasis>ldap_opt_timeout</emphasis> segundos de expirar, então será " @@ -7660,7 +8154,9 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:831 -msgid "ldap_ignore_unreadable_references (bool)" +#, fuzzy +#| msgid "ldap_ignore_unreadable_references (bool)" +msgid "ldap_ignore_unreadable_references (boolean)" msgstr "ldap_ignore_unreadable_references (booleano)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> @@ -8068,7 +8564,7 @@ msgstr "" "SPNEGO." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap.5.xml:1152 sssd-ad.5.xml:1267 +#: sssd-ldap.5.xml:1152 sssd-ad.5.xml:1260 msgid "Default: 86400 (24 hours)" msgstr "Predefinição: 86400 (24 horas)" @@ -8120,7 +8616,7 @@ msgstr "" "krb5_server</quote> em vez disto." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ldap.5.xml:1187 sssd-ipa.5.xml:575 sssd-krb5.5.xml:103 +#: sssd-ldap.5.xml:1187 sssd-ipa.5.xml:570 sssd-krb5.5.xml:103 msgid "krb5_realm (string)" msgstr "krb5_realm (string)" @@ -8319,7 +8815,9 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1339 -msgid "ldap_chpass_update_last_change (bool)" +#, fuzzy +#| msgid "ldap_chpass_update_last_change (bool)" +msgid "ldap_chpass_update_last_change (boolean)" msgstr "ldap_chpass_update_last_change (booleano)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> @@ -8514,7 +9012,7 @@ msgid "ldap_access_order (string)" msgstr "ldap_access_order (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap.5.xml:1470 sssd-ipa.5.xml:405 +#: sssd-ldap.5.xml:1470 sssd-ipa.5.xml:400 msgid "Comma separated list of access control options. Allowed values are:" msgstr "" "Lista separada por vírgulas de opções de controlo de acesso. Os valores " @@ -8577,7 +9075,7 @@ msgid "<emphasis>expire</emphasis>: use ldap_account_expire_policy" msgstr "<emphasis>expire</emphasis>: usa ldap_account_expire_policy" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap.5.xml:1515 sssd-ipa.5.xml:413 +#: sssd-ldap.5.xml:1515 sssd-ipa.5.xml:408 msgid "" "<emphasis>pwd_expire_policy_reject, pwd_expire_policy_warn, " "pwd_expire_policy_renew: </emphasis> These options are useful if users are " @@ -8592,7 +9090,7 @@ msgstr "" "diferente que palavras passe - por exemplo chaves SSH." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap.5.xml:1525 sssd-ipa.5.xml:423 +#: sssd-ldap.5.xml:1525 sssd-ipa.5.xml:418 msgid "" "The difference between these options is the action taken if user password is " "expired:" @@ -8601,17 +9099,17 @@ msgstr "" "utilizador estiver expirada:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ldap.5.xml:1530 sssd-ipa.5.xml:428 +#: sssd-ldap.5.xml:1530 sssd-ipa.5.xml:423 msgid "pwd_expire_policy_reject - user is denied to log in," msgstr "pwd_expire_policy_reject - é negado o login ao utilizador," #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ldap.5.xml:1536 sssd-ipa.5.xml:434 +#: sssd-ldap.5.xml:1536 sssd-ipa.5.xml:429 msgid "pwd_expire_policy_warn - user is still able to log in," msgstr "pwd_expire_policy_warn - o utilizador ainda é capaz de fazer login," #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ldap.5.xml:1542 sssd-ipa.5.xml:440 +#: sssd-ldap.5.xml:1542 sssd-ipa.5.xml:435 msgid "" "pwd_expire_policy_renew - user is prompted to change their password " "immediately." @@ -9273,8 +9771,8 @@ msgstr "" "type=\"variablelist\" id=\"1\"/>" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd-ldap.5.xml:2032 sssd-simple.5.xml:169 sssd-ipa.5.xml:984 -#: sssd-ad.5.xml:1470 sssd-idp.5.xml:248 sssd-krb5.5.xml:483 +#: sssd-ldap.5.xml:2032 sssd-simple.5.xml:169 sssd-ipa.5.xml:979 +#: sssd-ad.5.xml:1463 sssd-idp.5.xml:343 sssd-krb5.5.xml:483 #: sss_rpcidmapd.5.xml:98 sssd-session-recording.5.xml:176 msgid "EXAMPLE" msgstr "EXEMPLO" @@ -9312,7 +9810,7 @@ msgstr "" #. type: Content of: <refsect1><refsect2><para> #: sssd-ldap.5.xml:2039 sssd-ldap.5.xml:2057 sssd-simple.5.xml:177 -#: sssd-ipa.5.xml:992 sssd-ad.5.xml:1478 sssd-sudo.5.xml:56 sssd-krb5.5.xml:492 +#: sssd-ipa.5.xml:987 sssd-ad.5.xml:1471 sssd-sudo.5.xml:56 sssd-krb5.5.xml:492 #: sssd-session-recording.5.xml:182 include/ldap_id_mapping.xml:105 msgid "<placeholder type=\"programlisting\" id=\"0\"/>" msgstr "<placeholder type=\"programlisting\" id=\"0\"/>" @@ -9359,7 +9857,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><title> #: sssd-ldap.5.xml:2073 sssd_krb5_locator_plugin.8.xml:83 sssd-simple.5.xml:189 -#: sssd-ad.5.xml:1493 sssd.8.xml:270 sss_seed.8.xml:163 +#: sssd-ad.5.xml:1486 sssd.8.xml:270 sss_seed.8.xml:163 msgid "NOTES" msgstr "NOTAS" @@ -9978,9 +10476,14 @@ msgstr "PAM_NO_MODULE_DATA" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:434 +#, fuzzy +#| msgid "" +#| "No authentication method was found by Kerberos. This might happen if the " +#| "user has a Smartcard assigned but the pkint plugin is not available on " +#| "the client." msgid "" "No authentication method was found by Kerberos. This might happen if the " -"user has a Smartcard assigned but the pkint plugin is not available on the " +"user has a Smartcard assigned but the pkinit plugin is not available on the " "client." msgstr "" "Nenhum método de autenticação encontrado pelo Kerberos. Isto pode acontecer " @@ -10486,8 +10989,8 @@ msgid "" "this file." msgstr "" "Provedor de autenticação krb5 do SSSD o qual é usado pelos provedores IPA e " -"AD assim como adiciona os endereços do KDC actual ou controlador de domínio " -"que o SSSD está usar para este ficheiro." +"AD também adiciona os endereços do KDC atual ou controlador de domínio que o " +"SSSD está usar para este ficheiro." #. type: Content of: <reference><refentry><refsect1><para> #: sssd_krb5_locator_plugin.8.xml:70 @@ -10556,6 +11059,23 @@ msgstr "" "no ficheiro kdcinfo. Por predefinição o plugin retorna KRB5_PLUGIN_NO_HANDLE " "ao chamador imediatamente na primeira falha ao resolver DNS." +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_locator_plugin.8.xml:106 +msgid "" +"If the environment variable SSSD_KRB5_LOCATOR_KDC_ADDRESS is set to a KDC " +"address the plugin will use this address instead of reading the kdcinfo " +"file. The address format is the same as in the kdcinfo file (see above)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_locator_plugin.8.xml:112 +msgid "" +"If the environment variable SSSD_KRB5_LOCATOR_KPASSWD_ADDRESS is set to a " +"kpasswd server address the plugin will use this address instead of reading " +"the kpasswdinfo file. The address format is the same as in the kpasswdinfo " +"file (see above)." +msgstr "" + #. type: Content of: <reference><refentry><refnamediv><refname> #: sssd-simple.5.xml:10 sssd-simple.5.xml:16 msgid "sssd-simple" @@ -12276,7 +12796,7 @@ msgstr "" "esta máquina. O nome de máquina tem de ser totalmente qualificado." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:129 sssd-ad.5.xml:1161 +#: sssd-ipa.5.xml:129 sssd-ad.5.xml:1166 msgid "dyndns_update (boolean)" msgstr "dyndns_update (booleano)" @@ -12295,23 +12815,13 @@ msgstr "" "actualizações, se não for caso contrário especificado ao se usar a opção " "<quote>dyndns_iface</quote>." -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:141 sssd-ad.5.xml:1175 -msgid "" -"NOTE: On older systems (such as RHEL 5), for this behavior to work reliably, " -"the default Kerberos realm must be set properly in /etc/krb5.conf" -msgstr "" -"NOTA: Em sistemas antigos (como o RHEL 5), para este comportamento poder ter " -"fiabilidade de funcionamento, o reino Kerberos predefinido tem de ser " -"definido apropriadamente em /etc/krb5.conf" - #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:152 sssd-ad.5.xml:1186 +#: sssd-ipa.5.xml:147 sssd-ad.5.xml:1186 msgid "dyndns_ttl (integer)" msgstr "dyndns_ttl (inteiro)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:155 sssd-ad.5.xml:1189 +#: sssd-ipa.5.xml:150 sssd-ad.5.xml:1189 msgid "" "The TTL to apply to the client DNS record when updating it. If " "dyndns_update is false this has no effect. This will override the TTL " @@ -12322,17 +12832,17 @@ msgstr "" "servidor se definido por um administrador." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:160 +#: sssd-ipa.5.xml:155 msgid "Default: 1200 (seconds)" msgstr "Predefinição: 1200 (segundos)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:166 sssd-ad.5.xml:1200 +#: sssd-ipa.5.xml:161 sssd-ad.5.xml:1200 msgid "dyndns_iface (string)" msgstr "dyndns_iface (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:169 sssd-ad.5.xml:1203 +#: sssd-ipa.5.xml:164 sssd-ad.5.xml:1203 msgid "" "Optional. Applicable only when dyndns_update is true. Choose the interface " "or a list of interfaces whose IP addresses should be used for dynamic DNS " @@ -12352,7 +12862,7 @@ msgstr "" "detalhes sobre padrões." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:182 +#: sssd-ipa.5.xml:177 msgid "" "Default: Use the IP addresses of the interface which is used for IPA LDAP " "connection" @@ -12361,17 +12871,17 @@ msgstr "" "LDAP" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:186 sssd-ad.5.xml:1226 +#: sssd-ipa.5.xml:181 sssd-ad.5.xml:1220 msgid "Example: dyndns_iface = em[12], !vnet1, vnet*" msgstr "Exemplo: dyndns_iface = em[12], !vnet1, vnet*" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:192 sssd-ad.5.xml:1232 +#: sssd-ipa.5.xml:187 sssd-ad.5.xml:1226 msgid "dyndns_address (string)" msgstr "dyndns_address (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:195 sssd-ad.5.xml:1235 +#: sssd-ipa.5.xml:190 sssd-ad.5.xml:1229 msgid "" "Optional. Applicable only when <emphasis>dyndns_update</emphasis> is true. " "A list of IP addresses or IP networks to be used for dynamic DNS updates. " @@ -12389,22 +12899,22 @@ msgstr "" "precedência)." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:206 sssd-ad.5.xml:1246 +#: sssd-ipa.5.xml:201 sssd-ad.5.xml:1240 msgid "Default: No filtering of IP addresses." msgstr "Predefinição: Nenhuma filtragem de endereços IP." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:209 sssd-ad.5.xml:1249 +#: sssd-ipa.5.xml:204 sssd-ad.5.xml:1243 msgid "Example: dyndns_address = 10.0.0.0/16, !10.0.1.0/24" msgstr "Exemplo: dyndns_address = 10.0.0.0/16, !10.0.1.0/24" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:215 sssd-ad.5.xml:1305 +#: sssd-ipa.5.xml:210 sssd-ad.5.xml:1298 msgid "dyndns_auth (string)" msgstr "dyndns_auth (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:218 sssd-ad.5.xml:1308 +#: sssd-ipa.5.xml:213 sssd-ad.5.xml:1301 msgid "" "Whether the nsupdate utility should use GSS-TSIG authentication for secure " "updates with the DNS server, insecure updates can be sent by setting this " @@ -12415,17 +12925,17 @@ msgstr "" "enviadas ao definir esta opção para 'none'." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:224 sssd-ad.5.xml:1314 +#: sssd-ipa.5.xml:219 sssd-ad.5.xml:1307 msgid "Default: GSS-TSIG" msgstr "Predefinição: GSS-TSIG" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:230 sssd-ad.5.xml:1320 +#: sssd-ipa.5.xml:225 sssd-ad.5.xml:1313 msgid "dyndns_auth_ptr (string)" msgstr "dyndns_auth_ptr (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:233 sssd-ad.5.xml:1323 +#: sssd-ipa.5.xml:228 sssd-ad.5.xml:1316 msgid "" "Whether the nsupdate utility should use GSS-TSIG authentication for secure " "PTR updates with the DNS server, insecure updates can be sent by setting " @@ -12436,17 +12946,17 @@ msgstr "" "enviadas ao definir esta opção para 'none'." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:239 sssd-ad.5.xml:1329 +#: sssd-ipa.5.xml:234 sssd-ad.5.xml:1322 msgid "Default: Same as dyndns_auth" msgstr "Predefinição: O mesmo que dyndns_auth" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:245 sssd-ad.5.xml:1255 +#: sssd-ipa.5.xml:240 sssd-ad.5.xml:1249 msgid "dyndns_refresh_interval (integer)" msgstr "dyndns_refresh_interval (inteiro)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:248 +#: sssd-ipa.5.xml:243 msgid "" "How often should the back end perform periodic DNS update in addition to the " "automatic update performed when the back end goes online. This option is " @@ -12457,12 +12967,14 @@ msgstr "" "Esta opção é opcional e aplicável apenas quando dyndns_update é true." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:261 sssd-ad.5.xml:1273 -msgid "dyndns_update_ptr (bool)" +#: sssd-ipa.5.xml:256 sssd-ad.5.xml:1266 +#, fuzzy +#| msgid "dyndns_update_ptr (bool)" +msgid "dyndns_update_ptr (boolean)" msgstr "dyndns_update_ptr (booleano)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:264 sssd-ad.5.xml:1276 +#: sssd-ipa.5.xml:259 sssd-ad.5.xml:1269 msgid "" "Whether the PTR record should also be explicitly updated when updating the " "client's DNS records. Applicable only when dyndns_update is true." @@ -12472,7 +12984,7 @@ msgstr "" "dyndns_update é true." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:269 +#: sssd-ipa.5.xml:264 msgid "" "This option should be False in most IPA deployments as the IPA server " "generates the PTR records automatically when forward records are changed." @@ -12482,7 +12994,7 @@ msgstr "" "modificados." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:275 sssd-ad.5.xml:1281 +#: sssd-ipa.5.xml:270 sssd-ad.5.xml:1274 msgid "" "Note that <emphasis>dyndns_update_per_family</emphasis> parameter does not " "apply for PTR record updates. Those updates are always sent separately." @@ -12492,17 +13004,19 @@ msgstr "" "enviadas em separado." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:280 +#: sssd-ipa.5.xml:275 msgid "Default: False (disabled)" msgstr "Predefinição: False (desactivado)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:286 sssd-ad.5.xml:1292 -msgid "dyndns_force_tcp (bool)" +#: sssd-ipa.5.xml:281 sssd-ad.5.xml:1285 +#, fuzzy +#| msgid "dyndns_force_tcp (bool)" +msgid "dyndns_force_tcp (boolean)" msgstr "dyndns_force_tcp (booleano)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:289 sssd-ad.5.xml:1295 +#: sssd-ipa.5.xml:284 sssd-ad.5.xml:1288 msgid "" "Whether the nsupdate utility should default to using TCP for communicating " "with the DNS server." @@ -12511,17 +13025,17 @@ msgstr "" "servidor DNS." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:293 sssd-ad.5.xml:1299 +#: sssd-ipa.5.xml:288 sssd-ad.5.xml:1292 msgid "Default: False (let nsupdate choose the protocol)" msgstr "Predefinição: False (deixa o nsupdate escolher o protocolo)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:299 sssd-ad.5.xml:1335 +#: sssd-ipa.5.xml:294 sssd-ad.5.xml:1328 msgid "dyndns_server (string)" msgstr "dyndns_server (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:302 sssd-ad.5.xml:1338 +#: sssd-ipa.5.xml:297 sssd-ad.5.xml:1331 msgid "" "The DNS server to use when performing a DNS update. In most setups, it's " "recommended to leave this option unset." @@ -12530,7 +13044,7 @@ msgstr "" "configurações, é recomendado deixar esta opção por definir." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:307 sssd-ad.5.xml:1343 +#: sssd-ipa.5.xml:302 sssd-ad.5.xml:1336 msgid "" "Setting this option makes sense for environments where the DNS server is " "different from the identity server or when we use encrypted DNS." @@ -12539,7 +13053,7 @@ msgstr "" "do servidor de identidade ou quando usamos DNS encriptado." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:312 sssd-ad.5.xml:1348 +#: sssd-ipa.5.xml:307 sssd-ad.5.xml:1341 msgid "" "The parameter can be a simple string containing DNS name or IP address. It " "can also be an URI. The URI can look like <emphasis>dns://servername/</" @@ -12551,7 +13065,7 @@ msgstr "" "emphasis>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:319 sssd-ad.5.xml:1355 +#: sssd-ipa.5.xml:314 sssd-ad.5.xml:1348 msgid "" "The second example enables DNS-over-TLS protocol for DNS updates. The " "nsupdate utility must support DoT - check the <emphasis>man nsupdate</" @@ -12562,7 +13076,7 @@ msgstr "" "nsupdate</emphasis> antes de o ativar no SSSD." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:325 sssd-ad.5.xml:1361 +#: sssd-ipa.5.xml:320 sssd-ad.5.xml:1354 msgid "" "Please note that this option will be only used in fallback attempt when " "previous attempt using autodetected settings failed or when DNS-over-TLS is " @@ -12573,17 +13087,17 @@ msgstr "" "sobre-TLS estiver ativo." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:331 sssd-ad.5.xml:1367 +#: sssd-ipa.5.xml:326 sssd-ad.5.xml:1360 msgid "Default: None (let nsupdate choose the server)" msgstr "Predefinição: None (deixa o nsupdate escolher o servidor)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:337 sssd-ad.5.xml:1373 +#: sssd-ipa.5.xml:332 sssd-ad.5.xml:1366 msgid "dyndns_update_per_family (boolean)" msgstr "dyndns_update_per_family (booleano)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:340 sssd-ad.5.xml:1376 +#: sssd-ipa.5.xml:335 sssd-ad.5.xml:1369 msgid "" "DNS update is by default performed in two steps - IPv4 update and then IPv6 " "update. In some cases it might be desirable to perform IPv4 and IPv6 update " @@ -12594,12 +13108,12 @@ msgstr "" "actualização IPv4 e IPv6 num único passo." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:352 sssd-ad.5.xml:1388 +#: sssd-ipa.5.xml:347 sssd-ad.5.xml:1381 msgid "dyndns_dot_cacert (string)" msgstr "dyndns_dot_cacert (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:355 sssd-ad.5.xml:1391 +#: sssd-ipa.5.xml:350 sssd-ad.5.xml:1384 msgid "" "This option specifies the file of the certificate authorities certificates " "(in PEM format) in order to verify the remote server TLS certificate when " @@ -12610,17 +13124,17 @@ msgstr "" "servidor remoto quando se usa DoT." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:361 sssd-ad.5.xml:1397 +#: sssd-ipa.5.xml:356 sssd-ad.5.xml:1390 msgid "Default: None (use global certificate store)" msgstr "Predefinição: Nenhum (usa o armazém de certificados global)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:367 sssd-ad.5.xml:1403 +#: sssd-ipa.5.xml:362 sssd-ad.5.xml:1396 msgid "dyndns_dot_cert (string)" msgstr "dyndns_dot_cert (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:370 sssd-ad.5.xml:1406 +#: sssd-ipa.5.xml:365 sssd-ad.5.xml:1399 msgid "" "This option sets the certificate(s) file for authentication for the DoT " "transport to the remote server. The certificate chain file is expected to be " @@ -12631,7 +13145,7 @@ msgstr "" "de certificados esteja em formato PEM." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:376 sssd-ad.5.xml:1412 +#: sssd-ipa.5.xml:371 sssd-ad.5.xml:1405 msgid "" "The <emphasis>dyndns_dot_cert</emphasis> and <emphasis>dyndns_dot_key</" "emphasis> options must be both set to achieve mutual TLS authentication." @@ -12641,17 +13155,17 @@ msgstr "" "mútua." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:381 sssd-ipa.5.xml:396 sssd-ad.5.xml:1417 sssd-ad.5.xml:1432 +#: sssd-ipa.5.xml:376 sssd-ipa.5.xml:391 sssd-ad.5.xml:1410 sssd-ad.5.xml:1425 msgid "Default: None (Do not use TLS authentication)" msgstr "Predefinição: Nenhuma (Não usa autenticação TLS)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:387 sssd-ad.5.xml:1423 +#: sssd-ipa.5.xml:382 sssd-ad.5.xml:1416 msgid "dyndns_dot_key (string)" msgstr "dyndns_dot_key (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:390 sssd-ad.5.xml:1426 +#: sssd-ipa.5.xml:385 sssd-ad.5.xml:1419 msgid "" "This option sets the key file for authenticated encryption for the DoT " "transport to the remote server. The private key file is expected to be in " @@ -12662,17 +13176,17 @@ msgstr "" "privada esteja em formato PEM." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:402 +#: sssd-ipa.5.xml:397 msgid "ipa_access_order (string)" msgstr "ipa_access_order (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:409 +#: sssd-ipa.5.xml:404 msgid "<emphasis>expire</emphasis>: use IPA's account expiration policy." msgstr "<emphasis>expire</emphasis>: usa política de expiração de conta do IPA." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:448 +#: sssd-ipa.5.xml:443 msgid "" "Please note that 'access_provider = ipa' must be set for this feature to " "work." @@ -12681,12 +13195,12 @@ msgstr "" "funcionalidade funcionar." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:455 +#: sssd-ipa.5.xml:450 msgid "ipa_deskprofile_search_base (string)" msgstr "ipa_deskprofile_search_base (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:458 +#: sssd-ipa.5.xml:453 msgid "" "Optional. Use the given string as search base for Desktop Profile related " "objects." @@ -12695,108 +13209,108 @@ msgstr "" "com Desktop Profile." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:462 sssd-ipa.5.xml:484 +#: sssd-ipa.5.xml:457 sssd-ipa.5.xml:479 msgid "Default: Use base DN" msgstr "Predefinição: Usa base DN" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:468 +#: sssd-ipa.5.xml:463 msgid "ipa_subid_ranges_search_base (string)" msgstr "ipa_subid_ranges_search_base (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:471 +#: sssd-ipa.5.xml:466 msgid "Deprecated. Use ldap_subid_ranges_search_base instead." msgstr "Descontinuado. Use ldap_subid_ranges_search_base em vez disto." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:477 +#: sssd-ipa.5.xml:472 msgid "ipa_hbac_search_base (string)" msgstr "ipa_hbac_search_base (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:480 +#: sssd-ipa.5.xml:475 msgid "Optional. Use the given string as search base for HBAC related objects." msgstr "" "Opcional. Usa a string dada como base de busca para objectos relacionados " "com HBAC." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:490 +#: sssd-ipa.5.xml:485 msgid "ipa_host_search_base (string)" msgstr "ipa_host_search_base (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:493 +#: sssd-ipa.5.xml:488 msgid "Deprecated. Use ldap_host_search_base instead." msgstr "Descontinuado. Use ldap_host_search_base em vez disto." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:499 +#: sssd-ipa.5.xml:494 msgid "ipa_selinux_search_base (string)" msgstr "ipa_selinux_search_base (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:502 +#: sssd-ipa.5.xml:497 msgid "Optional. Use the given string as search base for SELinux user maps." msgstr "" "Opcional. Usa a string fornecida como base de busca para mapas de utilizador " "SELinux." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:518 +#: sssd-ipa.5.xml:513 msgid "ipa_subdomains_search_base (string)" msgstr "ipa_subdomains_search_base (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:521 +#: sssd-ipa.5.xml:516 msgid "Optional. Use the given string as search base for trusted domains." msgstr "" "Opcional. Usa a string fornecida como base de busca para domínios de " "confiança." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:530 +#: sssd-ipa.5.xml:525 msgid "Default: the value of <emphasis>cn=trusts,%basedn</emphasis>" msgstr "Predefinição: o valor de <emphasis>cn=trusts,%basedn</emphasis>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:537 +#: sssd-ipa.5.xml:532 msgid "ipa_master_domain_search_base (string)" msgstr "ipa_master_domain_search_base (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:540 +#: sssd-ipa.5.xml:535 msgid "Optional. Use the given string as search base for master domain object." msgstr "" "Opcional. Usa a string fornecida como base de busca para objecto de domínio " "mestre." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:549 +#: sssd-ipa.5.xml:544 msgid "Default: the value of <emphasis>cn=ad,cn=etc,%basedn</emphasis>" msgstr "Predefinição: o valor de <emphasis>cn=ad,cn=etc,%basedn</emphasis>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:556 +#: sssd-ipa.5.xml:551 msgid "ipa_views_search_base (string)" msgstr "ipa_views_search_base (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:559 +#: sssd-ipa.5.xml:554 msgid "Optional. Use the given string as search base for views containers." msgstr "" "Opcional. Usa a string fornecida como base de busca para recipientes de " "visualizações." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:568 +#: sssd-ipa.5.xml:563 msgid "Default: the value of <emphasis>cn=views,cn=accounts,%basedn</emphasis>" msgstr "" "Predefinição: o valor de <emphasis>cn=views,cn=accounts,%basedn</emphasis>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:578 +#: sssd-ipa.5.xml:573 msgid "" "The name of the Kerberos realm. This is optional and defaults to the value " "of <quote>ipa_domain</quote>." @@ -12805,7 +13319,7 @@ msgstr "" "<quote>ipa_domain</quote>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:582 +#: sssd-ipa.5.xml:577 msgid "" "The name of the Kerberos realm has a special meaning in IPA - it is " "converted into the base DN to use for performing LDAP operations." @@ -12814,12 +13328,12 @@ msgstr "" "num DN base a usar para executar operações de LDAP." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:590 sssd-ad.5.xml:1441 +#: sssd-ipa.5.xml:585 sssd-ad.5.xml:1434 msgid "krb5_confd_path (string)" msgstr "krb5_confd_path (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:593 sssd-ad.5.xml:1444 +#: sssd-ipa.5.xml:588 sssd-ad.5.xml:1437 msgid "" "Absolute path of a directory where SSSD should place Kerberos configuration " "snippets." @@ -12828,7 +13342,7 @@ msgstr "" "configuração do Kerberos." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:597 sssd-ad.5.xml:1448 +#: sssd-ipa.5.xml:592 sssd-ad.5.xml:1441 msgid "" "To disable the creation of the configuration snippets set the parameter to " "'none'." @@ -12837,7 +13351,7 @@ msgstr "" "'none'." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:601 sssd-ad.5.xml:1452 +#: sssd-ipa.5.xml:596 sssd-ad.5.xml:1445 msgid "" "Default: not set (krb5.include.d subdirectory of SSSD's pubconf directory)" msgstr "" @@ -12845,12 +13359,12 @@ msgstr "" "pubconf do SSSD)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:608 +#: sssd-ipa.5.xml:603 msgid "ipa_deskprofile_refresh (integer)" msgstr "ipa_deskprofile_refresh (inteiro)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:611 +#: sssd-ipa.5.xml:606 msgid "" "The amount of time between lookups of the Desktop Profile rules against the " "IPA server. This will reduce the latency and load on the IPA server if there " @@ -12861,17 +13375,17 @@ msgstr "" "existirem muitos pedidos de perfil de desktop feitos num curto período." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:618 sssd-ipa.5.xml:648 sssd-ipa.5.xml:664 sssd-ad.5.xml:600 +#: sssd-ipa.5.xml:613 sssd-ipa.5.xml:643 sssd-ipa.5.xml:659 sssd-ad.5.xml:600 msgid "Default: 5 (seconds)" msgstr "Predefinição: 5 (segundos)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:624 +#: sssd-ipa.5.xml:619 msgid "ipa_deskprofile_request_interval (integer)" msgstr "ipa_deskprofile_request_interval (inteiro)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:627 +#: sssd-ipa.5.xml:622 msgid "" "The amount of time between lookups of the Desktop Profile rules against the " "IPA server in case the last request did not return any rule." @@ -12880,17 +13394,17 @@ msgstr "" "servidor IPA no caso do último pedido não ter retornado nenhuma regra." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:632 +#: sssd-ipa.5.xml:627 msgid "Default: 60 (minutes)" msgstr "Predefinição: 60 (minutos)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:638 +#: sssd-ipa.5.xml:633 msgid "ipa_hbac_refresh (integer)" msgstr "ipa_hbac_refresh (inteiro)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:641 +#: sssd-ipa.5.xml:636 msgid "" "The amount of time between lookups of the HBAC rules against the IPA server. " "This will reduce the latency and load on the IPA server if there are many " @@ -12901,12 +13415,14 @@ msgstr "" "pedidos de controle de acesso feitos num curto período." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:654 -msgid "ipa_hbac_selinux (integer)" -msgstr "ipa_hbac_selinux (inteiro)" +#: sssd-ipa.5.xml:649 +#, fuzzy +#| msgid "ipa_hbac_refresh (integer)" +msgid "ipa_selinux_refresh (integer)" +msgstr "ipa_hbac_refresh (inteiro)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:657 +#: sssd-ipa.5.xml:652 msgid "" "The amount of time between lookups of the SELinux maps against the IPA " "server. This will reduce the latency and load on the IPA server if there are " @@ -12917,12 +13433,12 @@ msgstr "" "pedidos de login de utilizador feitos num curto período." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:670 +#: sssd-ipa.5.xml:665 msgid "ipa_server_mode (boolean)" msgstr "ipa_server_mode (booleano)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:673 +#: sssd-ipa.5.xml:668 msgid "" "This option will be set by the IPA installer (ipa-server-install) " "automatically and denotes if SSSD is running on an IPA server or not." @@ -12931,7 +13447,7 @@ msgstr "" "install) e denota se o SSSD está a correr num servidor IPA ou não." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:678 +#: sssd-ipa.5.xml:673 msgid "" "On an IPA server SSSD will lookup users and groups from trusted domains " "directly while on a client it will ask an IPA server." @@ -12941,7 +13457,7 @@ msgstr "" "IPA." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:683 +#: sssd-ipa.5.xml:678 msgid "" "NOTE: There are currently some assumptions that must be met when SSSD is " "running on an IPA server." @@ -12950,7 +13466,7 @@ msgstr "" "quando o SSSD corre num servidor IPA." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:688 +#: sssd-ipa.5.xml:683 msgid "" "The <quote>ipa_server</quote> option must be configured to point to the IPA " "server itself. This is already the default set by the IPA installer, so no " @@ -12961,7 +13477,7 @@ msgstr "" "do IPA, portanto não é requerida nenhuma alteração manual." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:697 +#: sssd-ipa.5.xml:692 msgid "" "The <quote>full_name_format</quote> option must not be tweaked to only print " "short names for users from trusted domains." @@ -12970,52 +13486,52 @@ msgstr "" "escrever nomes curtos para utilizadores de domínios de confiança." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:712 +#: sssd-ipa.5.xml:707 msgid "ipa_automount_location (string)" msgstr "ipa_automount_location (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:715 +#: sssd-ipa.5.xml:710 msgid "The automounter location this IPA client will be using" msgstr "A localização de automounter que este cliente IPA irá usar" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:718 +#: sssd-ipa.5.xml:713 msgid "Default: The location named \"default\"" msgstr "Predefinição: A localização chamada \"default\"" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd-ipa.5.xml:726 +#: sssd-ipa.5.xml:721 msgid "VIEWS AND OVERRIDES" msgstr "VISUALIZAÇÕES E SOBREPOSIÇÕES" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:735 +#: sssd-ipa.5.xml:730 msgid "ipa_view_class (string)" msgstr "ipa_view_class (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:738 +#: sssd-ipa.5.xml:733 msgid "Objectclass of the view container." msgstr "Objectclass do recipiente de vista." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:741 +#: sssd-ipa.5.xml:736 msgid "Default: nsContainer" msgstr "Predefinição: nsContainer" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:747 +#: sssd-ipa.5.xml:742 msgid "ipa_view_name (string)" msgstr "ipa_view_name (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:750 +#: sssd-ipa.5.xml:745 msgid "Name of the attribute holding the name of the view." msgstr "Nome do atributo que contém o nome da vista." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:754 sssd-ldap-attributes.5.xml:496 +#: sssd-ipa.5.xml:749 sssd-ldap-attributes.5.xml:496 #: sssd-ldap-attributes.5.xml:832 sssd-ldap-attributes.5.xml:913 #: sssd-ldap-attributes.5.xml:1010 sssd-ldap-attributes.5.xml:1068 #: sssd-ldap-attributes.5.xml:1226 sssd-ldap-attributes.5.xml:1271 @@ -13023,27 +13539,27 @@ msgid "Default: cn" msgstr "Predefinição: cn" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:760 +#: sssd-ipa.5.xml:755 msgid "ipa_override_object_class (string)" msgstr "ipa_override_object_class (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:763 +#: sssd-ipa.5.xml:758 msgid "Objectclass of the override objects." msgstr "Objectclass dos objectos de sobreposição." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:766 +#: sssd-ipa.5.xml:761 msgid "Default: ipaOverrideAnchor" msgstr "Predefinição: ipaOverrideAnchor" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:772 +#: sssd-ipa.5.xml:767 msgid "ipa_anchor_uuid (string)" msgstr "ipa_anchor_uuid (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:775 +#: sssd-ipa.5.xml:770 msgid "" "Name of the attribute containing the reference to the original object in a " "remote domain." @@ -13052,17 +13568,17 @@ msgstr "" "remoto." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:779 +#: sssd-ipa.5.xml:774 msgid "Default: ipaAnchorUUID" msgstr "Predefinição: ipaAnchorUUID" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:785 +#: sssd-ipa.5.xml:780 msgid "ipa_user_override_object_class (string)" msgstr "ipa_user_override_object_class (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:788 +#: sssd-ipa.5.xml:783 msgid "" "Name of the objectclass for user overrides. It is used to determine if the " "found override object is related to a user or a group." @@ -13072,57 +13588,57 @@ msgstr "" "utilizador ou um grupo." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:793 +#: sssd-ipa.5.xml:788 msgid "User overrides can contain attributes given by" msgstr "As sobreposições de utilizador podem conter atributos dados por" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:796 +#: sssd-ipa.5.xml:791 msgid "ldap_user_name" msgstr "ldap_user_name" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:799 +#: sssd-ipa.5.xml:794 msgid "ldap_user_uid_number" msgstr "ldap_user_uid_number" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:802 +#: sssd-ipa.5.xml:797 msgid "ldap_user_gid_number" msgstr "ldap_user_gid_number" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:805 +#: sssd-ipa.5.xml:800 msgid "ldap_user_gecos" msgstr "ldap_user_gecos" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:808 +#: sssd-ipa.5.xml:803 msgid "ldap_user_home_directory" msgstr "ldap_user_home_directory" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:811 +#: sssd-ipa.5.xml:806 msgid "ldap_user_shell" msgstr "ldap_user_shell" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:814 +#: sssd-ipa.5.xml:809 msgid "ldap_user_ssh_public_key" msgstr "ldap_user_ssh_public_key" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:819 +#: sssd-ipa.5.xml:814 msgid "Default: ipaUserOverride" msgstr "Predefinição: ipaUserOverride" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:825 +#: sssd-ipa.5.xml:820 msgid "ipa_group_override_object_class (string)" msgstr "ipa_group_override_object_class (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:828 +#: sssd-ipa.5.xml:823 msgid "" "Name of the objectclass for group overrides. It is used to determine if the " "found override object is related to a user or a group." @@ -13132,27 +13648,27 @@ msgstr "" "um grupo." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:833 +#: sssd-ipa.5.xml:828 msgid "Group overrides can contain attributes given by" msgstr "As sobreposições de grupo podem conter atributos dados por" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:836 +#: sssd-ipa.5.xml:831 msgid "ldap_group_name" msgstr "ldap_group_name" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:839 +#: sssd-ipa.5.xml:834 msgid "ldap_group_gid_number" msgstr "ldap_group_gid_number" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:844 +#: sssd-ipa.5.xml:839 msgid "Default: ipaGroupOverride" msgstr "Predefinição: ipaGroupOverride" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:728 +#: sssd-ipa.5.xml:723 msgid "" "SSSD can handle views and overrides which are offered by FreeIPA 4.1 and " "later version. Since all paths and objectclasses are fixed on the server " @@ -13168,12 +13684,12 @@ msgstr "" "id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd-ipa.5.xml:856 +#: sssd-ipa.5.xml:851 msgid "SUBDOMAINS PROVIDER" msgstr "FORNECEDOR DE SUBDOMÍNIOS" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:858 +#: sssd-ipa.5.xml:853 msgid "" "The IPA subdomains provider behaves slightly differently if it is configured " "explicitly or implicitly." @@ -13182,7 +13698,7 @@ msgstr "" "for configurado explicitamente ou implicitamente." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:862 +#: sssd-ipa.5.xml:857 msgid "" "If the option 'subdomains_provider = ipa' is found in the domain section of " "sssd.conf, the IPA subdomains provider is configured explicitly, and all " @@ -13194,7 +13710,7 @@ msgstr "" "servidor IPA se tal for necessário." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:868 +#: sssd-ipa.5.xml:863 msgid "" "If the option 'subdomains_provider' is not set in the domain section of " "sssd.conf but there is the option 'id_provider = ipa', the IPA subdomains " @@ -13213,12 +13729,12 @@ msgstr "" "sub-domínios é activado de novo." #. type: Content of: <reference><refentry><refsect1><title> -#: sssd-ipa.5.xml:879 +#: sssd-ipa.5.xml:874 msgid "TRUSTED DOMAINS CONFIGURATION" msgstr "CONFIGURAÇÃO DE DOMÍNIOS DE CONFIANÇA" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-ipa.5.xml:887 +#: sssd-ipa.5.xml:882 #, no-wrap msgid "" "[domain/ipa.domain.com/ad.domain.com]\n" @@ -13228,7 +13744,7 @@ msgstr "" "ad_server = dc.ad.domain.com\n" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:881 +#: sssd-ipa.5.xml:876 msgid "" "Some configuration options can also be set for a trusted domain. A trusted " "domain configuration can be set using the trusted domain subsection as shown " @@ -13243,7 +13759,7 @@ msgstr "" "<placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:892 +#: sssd-ipa.5.xml:887 msgid "" "For more details, see the <citerefentry> <refentrytitle>sssd.conf</" "refentrytitle> <manvolnum>5</manvolnum> </citerefentry> manual page." @@ -13252,7 +13768,7 @@ msgstr "" "refentrytitle> <manvolnum>5</manvolnum> </citerefentry>." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:899 +#: sssd-ipa.5.xml:894 msgid "" "Different configuration options are tunable for a trusted domain depending " "on whether you are configuring SSSD on an IPA server or an IPA client." @@ -13262,59 +13778,59 @@ msgstr "" "cliente IPA." #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd-ipa.5.xml:904 +#: sssd-ipa.5.xml:899 msgid "OPTIONS TUNABLE ON IPA MASTERS" msgstr "OPÇÕES AFINÁVEIS EM MESTRES IPA" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:906 +#: sssd-ipa.5.xml:901 msgid "" "The following options can be set in a subdomain section on an IPA master:" msgstr "" "As seguinte opções podem ser definidas na secção subdomain dum mestre IPA:" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:910 sssd-ipa.5.xml:950 +#: sssd-ipa.5.xml:905 sssd-ipa.5.xml:945 msgid "ad_server" msgstr "ad_server" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:913 +#: sssd-ipa.5.xml:908 msgid "ad_backup_server" msgstr "ad_backup_server" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:916 sssd-ipa.5.xml:953 +#: sssd-ipa.5.xml:911 sssd-ipa.5.xml:948 msgid "ad_site" msgstr "ad_site" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:919 +#: sssd-ipa.5.xml:914 msgid "ipa_server" msgstr "ipa_server" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:922 +#: sssd-ipa.5.xml:917 msgid "ipa_backup_server" msgstr "ipa_backup_server" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:925 +#: sssd-ipa.5.xml:920 msgid "ldap_search_base" msgstr "ldap_search_base" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:928 +#: sssd-ipa.5.xml:923 msgid "ldap_user_search_base" msgstr "ldap_user_search_base" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:931 +#: sssd-ipa.5.xml:926 msgid "ldap_group_search_base" msgstr "ldap_group_search_base" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:939 +#: sssd-ipa.5.xml:934 msgid "" "Options prefixed with 'ad_' or 'ipa_' only apply to their respective " "subdomain type." @@ -13323,12 +13839,12 @@ msgstr "" "sub-domínio respectivos." #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd-ipa.5.xml:944 +#: sssd-ipa.5.xml:939 msgid "OPTIONS TUNABLE ON IPA CLIENTS" msgstr "OPÇÕES AFINÁVEIS EM CLIENTES IPA" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:946 +#: sssd-ipa.5.xml:941 msgid "" "The following options can be set in an AD subdomain section on an IPA client:" msgstr "" @@ -13336,7 +13852,7 @@ msgstr "" "IPA:" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:958 +#: sssd-ipa.5.xml:953 msgid "" "Note that if both options are set, only <quote>ad_server</quote> is " "evaluated." @@ -13345,7 +13861,7 @@ msgstr "" "quote> é avaliada." #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:962 +#: sssd-ipa.5.xml:957 msgid "" "Since any request for a user or a group identity from a trusted domain " "triggered from an IPA client is resolved by the IPA server, the " @@ -13368,7 +13884,7 @@ msgstr "" "sobre o plugin locador do Kerberos." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:986 +#: sssd-ipa.5.xml:981 msgid "" "The following example assumes that SSSD is correctly configured and " "example.com is one of the domains in the <replaceable>[sssd]</replaceable> " @@ -13379,7 +13895,7 @@ msgstr "" "Este exemplo mostra apenas as opções específicas do provedor ipa." #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-ipa.5.xml:993 +#: sssd-ipa.5.xml:988 #, no-wrap msgid "" "[domain/example.com]\n" @@ -14331,27 +14847,27 @@ msgid "lxdm" msgstr "lxdm" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:694 +#: sssd-ad.5.xml:699 msgid "sddm" msgstr "sddm" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:699 +#: sssd-ad.5.xml:704 msgid "unity" msgstr "unity" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:704 +#: sssd-ad.5.xml:709 msgid "xdm" msgstr "xdm" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:713 +#: sssd-ad.5.xml:718 msgid "ad_gpo_map_remote_interactive (string)" msgstr "ad_gpo_map_remote_interactive (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:716 +#: sssd-ad.5.xml:721 msgid "" "A comma-separated list of PAM service names for which GPO-based access " "control is evaluated based on the RemoteInteractiveLogonRight and " @@ -14379,7 +14895,7 @@ msgstr "" "menos um dos seus grupos fizer parte das definições de política." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:735 +#: sssd-ad.5.xml:740 msgid "" "Note: Using the Group Policy Management Editor this value is called \"Allow " "log on through Remote Desktop Services\" and \"Deny log on through Remote " @@ -14390,7 +14906,7 @@ msgstr "" "Remote Desktop Services\"." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:750 +#: sssd-ad.5.xml:755 #, no-wrap msgid "" "ad_gpo_map_remote_interactive = +my_pam_service, -sshd\n" @@ -14400,7 +14916,7 @@ msgstr "" " " #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:741 +#: sssd-ad.5.xml:746 msgid "" "It is possible to add another PAM service name to the default set by using " "<quote>+service_name</quote> or to explicitly remove a PAM service name from " @@ -14419,22 +14935,22 @@ msgstr "" "seguinte configuração: <placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:758 +#: sssd-ad.5.xml:763 msgid "sshd" msgstr "sshd" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:763 +#: sssd-ad.5.xml:768 msgid "cockpit" msgstr "cockpit" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:772 +#: sssd-ad.5.xml:777 msgid "ad_gpo_map_network (string)" msgstr "ad_gpo_map_network (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:775 +#: sssd-ad.5.xml:780 msgid "" "A comma-separated list of PAM service names for which GPO-based access " "control is evaluated based on the NetworkLogonRight and " @@ -14462,7 +14978,7 @@ msgstr "" "das definições de política." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:793 +#: sssd-ad.5.xml:798 msgid "" "Note: Using the Group Policy Management Editor this value is called \"Access " "this computer from the network\" and \"Deny access to this computer from the " @@ -14473,7 +14989,7 @@ msgstr "" "from the network\"." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:808 +#: sssd-ad.5.xml:813 #, no-wrap msgid "" "ad_gpo_map_network = +my_pam_service, -ftp\n" @@ -14483,7 +14999,7 @@ msgstr "" " " #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:799 +#: sssd-ad.5.xml:804 msgid "" "It is possible to add another PAM service name to the default set by using " "<quote>+service_name</quote> or to explicitly remove a PAM service name from " @@ -14502,22 +15018,22 @@ msgstr "" "seguinte configuração: <placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:816 +#: sssd-ad.5.xml:821 msgid "ftp" msgstr "ftp" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:821 +#: sssd-ad.5.xml:826 msgid "samba" msgstr "samba" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:830 +#: sssd-ad.5.xml:835 msgid "ad_gpo_map_batch (string)" msgstr "ad_gpo_map_batch (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:833 +#: sssd-ad.5.xml:838 msgid "" "A comma-separated list of PAM service names for which GPO-based access " "control is evaluated based on the BatchLogonRight and DenyBatchLogonRight " @@ -14544,7 +15060,7 @@ msgstr "" "das definições de política." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:851 +#: sssd-ad.5.xml:856 msgid "" "Note: Using the Group Policy Management Editor this value is called \"Allow " "log on as a batch job\" and \"Deny log on as a batch job\"." @@ -14553,7 +15069,7 @@ msgstr "" "\"Allow log on as a batch job\" e \"Deny log on as a batch job\"." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:865 +#: sssd-ad.5.xml:870 #, no-wrap msgid "" "ad_gpo_map_batch = +my_pam_service, -crond\n" @@ -14563,7 +15079,7 @@ msgstr "" " " #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:856 +#: sssd-ad.5.xml:861 msgid "" "It is possible to add another PAM service name to the default set by using " "<quote>+service_name</quote> or to explicitly remove a PAM service name from " @@ -14582,7 +15098,7 @@ msgstr "" "seguinte configuração: <placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:868 +#: sssd-ad.5.xml:873 msgid "" "Note: Cron service name may differ depending on Linux distribution used." msgstr "" @@ -14590,17 +15106,17 @@ msgstr "" "usada." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:874 +#: sssd-ad.5.xml:879 msgid "crond" msgstr "crond" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:883 +#: sssd-ad.5.xml:888 msgid "ad_gpo_map_service (string)" msgstr "ad_gpo_map_service (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:886 +#: sssd-ad.5.xml:891 msgid "" "A comma-separated list of PAM service names for which GPO-based access " "control is evaluated based on the ServiceLogonRight and " @@ -14627,7 +15143,7 @@ msgstr "" "menos um dos seus grupos fizer parte das definições de política." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:904 +#: sssd-ad.5.xml:909 msgid "" "Note: Using the Group Policy Management Editor this value is called \"Allow " "log on as a service\" and \"Deny log on as a service\"." @@ -14636,7 +15152,7 @@ msgstr "" "\"Allow log on as a service\" e \"Deny log on as a service\"." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:917 +#: sssd-ad.5.xml:922 #, no-wrap msgid "" "ad_gpo_map_service = +my_pam_service\n" @@ -14646,7 +15162,7 @@ msgstr "" " " #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:909 sssd-ad.5.xml:984 +#: sssd-ad.5.xml:914 sssd-ad.5.xml:989 msgid "" "It is possible to add a PAM service name to the default set by using " "<quote>+service_name</quote>. Since the default set is empty, it is not " @@ -14663,12 +15179,12 @@ msgstr "" "<placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:927 +#: sssd-ad.5.xml:932 msgid "ad_gpo_map_permit (string)" msgstr "ad_gpo_map_permit (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:930 +#: sssd-ad.5.xml:935 msgid "" "A comma-separated list of PAM service names for which GPO-based access is " "always granted, regardless of any GPO Logon Rights." @@ -14678,7 +15194,7 @@ msgstr "" "Direitos de Logon GPO." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:944 +#: sssd-ad.5.xml:949 #, no-wrap msgid "" "ad_gpo_map_permit = +my_pam_service, -sudo\n" @@ -14688,7 +15204,7 @@ msgstr "" " " #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:935 +#: sssd-ad.5.xml:940 msgid "" "It is possible to add another PAM service name to the default set by using " "<quote>+service_name</quote> or to explicitly remove a PAM service name from " @@ -14708,22 +15224,22 @@ msgstr "" "id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:952 +#: sssd-ad.5.xml:957 msgid "polkit-1" msgstr "polkit-1" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:967 +#: sssd-ad.5.xml:972 msgid "systemd-user" msgstr "systemd-user" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:976 +#: sssd-ad.5.xml:981 msgid "ad_gpo_map_deny (string)" msgstr "ad_gpo_map_deny (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:979 +#: sssd-ad.5.xml:984 msgid "" "A comma-separated list of PAM service names for which GPO-based access is " "always denied, regardless of any GPO Logon Rights." @@ -14733,7 +15249,7 @@ msgstr "" "Direitos de Logon GPO." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:992 +#: sssd-ad.5.xml:997 #, no-wrap msgid "" "ad_gpo_map_deny = +my_pam_service\n" @@ -14743,12 +15259,12 @@ msgstr "" " " #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:1002 +#: sssd-ad.5.xml:1007 msgid "ad_gpo_default_right (string)" msgstr "ad_gpo_default_right (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1005 +#: sssd-ad.5.xml:1010 msgid "" "This option defines how access control is evaluated for PAM service names " "that are not explicitly listed in one of the ad_gpo_map_* options. This " @@ -14770,52 +15286,52 @@ msgstr "" "sempre o acesso a nomes de serviços PAM não mapeados." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1018 +#: sssd-ad.5.xml:1023 msgid "Supported values for this option include:" msgstr "Os valores suportados para esta opção incluem:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1027 +#: sssd-ad.5.xml:1032 msgid "remote_interactive" msgstr "remote_interactive" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1032 +#: sssd-ad.5.xml:1037 msgid "network" msgstr "network" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1037 +#: sssd-ad.5.xml:1042 msgid "batch" msgstr "batch" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1042 +#: sssd-ad.5.xml:1047 msgid "service" msgstr "service" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1047 +#: sssd-ad.5.xml:1052 msgid "permit" msgstr "permit" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1052 +#: sssd-ad.5.xml:1057 msgid "deny" msgstr "deny" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1058 +#: sssd-ad.5.xml:1063 msgid "Default: deny" msgstr "Predefinição: deny" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:1064 +#: sssd-ad.5.xml:1069 msgid "ad_maximum_machine_account_password_age (integer)" msgstr "ad_maximum_machine_account_password_age (inteiro)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1067 +#: sssd-ad.5.xml:1072 msgid "" "SSSD will check once a day if the machine account password is older than the " "given age in days and try to renew it. A value of 0 will disable the renewal " @@ -14826,17 +15342,17 @@ msgstr "" "desactivar a tentativa de renovação." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1073 +#: sssd-ad.5.xml:1078 msgid "Default: 30 days" msgstr "Predefinição: 30 dias" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:1079 +#: sssd-ad.5.xml:1084 msgid "ad_machine_account_password_renewal_opts (string)" msgstr "ad_machine_account_password_renewal_opts (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1082 +#: sssd-ad.5.xml:1087 msgid "" "This option should only be used to test the machine account renewal task. " "The option expects 3 integers and a string separated by a colon (':'). The " @@ -14858,16 +15374,26 @@ msgstr "" "string '0'." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1096 +#: sssd-ad.5.xml:1101 +#, fuzzy +#| msgid "" +#| "The optional fourth string value identifies the helper binary which " +#| "should be used for the renewal. Currently <command>adcli</command> and " +#| "<command>realm</command> are supported. If this value is missing or empty " +#| "in the value string <command>realm</command> will be used. Since the " +#| "helper is started as the user SSSD is running as there might be the " +#| "chance that the renewal will fail if this user does not has permissions " +#| "to modify the keytab file where the machine account credentials are " +#| "stored. This will typically be the case for <command>adcli</command>." msgid "" "The optional fourth string value identifies the helper binary which should " "be used for the renewal. Currently <command>adcli</command> and " "<command>realm</command> are supported. If this value is missing or empty in " "the value string <command>realm</command> will be used. Since the helper is " "started as the user SSSD is running as there might be the chance that the " -"renewal will fail if this user does not has permissions to modify the keytab " -"file where the machine account credentials are stored. This will typically " -"be the case for <command>adcli</command>." +"renewal will fail if this user does not have permissions to modify the " +"keytab file where the machine account credentials are stored. This will " +"typically be the case for <command>adcli</command>." msgstr "" "O quarto valor string opcional identifica o binário ajudante que deve ser " "usado para a renovação. Atualmente são suportados <command>adcli</command> " @@ -14879,7 +15405,7 @@ msgstr "" "Este será tipicamente o caso de <command>adcli</command>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1110 +#: sssd-ad.5.xml:1115 msgid "" "<command>realm</command> is not updating the keytab directly but is calling " "the <command>realmd</command> process, which runs as root user, for this " @@ -14895,17 +15421,17 @@ msgstr "" "como." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1119 +#: sssd-ad.5.xml:1124 msgid "Default: 86400:750:300:realm (24h, 12m30s and 5m)" msgstr "Predefinição: 86400:750:300:realm (24h, 12m30s and 5m)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:1125 +#: sssd-ad.5.xml:1130 msgid "ad_update_samba_machine_account_password (boolean)" msgstr "ad_update_samba_machine_account_password (booleano)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1128 +#: sssd-ad.5.xml:1133 msgid "" "If enabled, when SSSD renews the machine account password, it will also be " "updated in Samba's database. This prevents Samba's copy of the machine " @@ -14918,16 +15444,26 @@ msgstr "" "configurada para usar AD para autenticação." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:1141 -msgid "ad_use_ldaps (bool)" +#: sssd-ad.5.xml:1146 +#, fuzzy +#| msgid "ad_use_ldaps (bool)" +msgid "ad_use_ldaps (boolean)" msgstr "ad_use_ldaps (booleano)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1144 +#: sssd-ad.5.xml:1149 +#, fuzzy +#| msgid "" +#| "By default SSSD uses the plain LDAP port 389 and the Global Catalog port " +#| "3628. If this option is set to True SSSD will use the LDAPS port 636 and " +#| "Global Catalog port 3629 with LDAPS protection. Since AD does not allow " +#| "to have multiple encryption layers on a single connection and we still " +#| "want to use SASL/GSSAPI or SASL/GSS-SPNEGO for authentication the SASL " +#| "security property maxssf is set to 0 (zero) for those connections." msgid "" "By default SSSD uses the plain LDAP port 389 and the Global Catalog port " -"3628. If this option is set to True SSSD will use the LDAPS port 636 and " -"Global Catalog port 3629 with LDAPS protection. Since AD does not allow to " +"3268. If this option is set to True SSSD will use the LDAPS port 636 and " +"Global Catalog port 3269 with LDAPS protection. Since AD does not allow to " "have multiple encryption layers on a single connection and we still want to " "use SASL/GSSAPI or SASL/GSS-SPNEGO for authentication the SASL security " "property maxssf is set to 0 (zero) for those connections." @@ -14941,7 +15477,7 @@ msgstr "" "ligações." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1164 +#: sssd-ad.5.xml:1169 msgid "" "Optional. This option tells SSSD to automatically update the Active " "Directory DNS server with the IP address of this client. The update is " @@ -14965,30 +15501,25 @@ msgstr "Predefinição: 3600 (segundos)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:1216 msgid "" -"NOTE: While it is still possible to use the old <emphasis>ipa_dyndns_iface</" -"emphasis> option, users should migrate to using <emphasis>dyndns_iface</" -"emphasis> in their config file." -msgstr "" -"NOTA: Apesar de ainda ser possível usar a opção antiga <emphasis>" -"ipa_dyndns_iface</emphasis>, os utilizadores devem migrar para usar " -"<emphasis>dyndns_iface</emphasis> no seu ficheiro de configuração." - -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1222 -msgid "" "Default: Use the IP addresses of the interface which is used for AD LDAP " "connection" msgstr "" "Predefinição: Usa o endereço IP da interface que é usada para ligação AD LDAP" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1258 +#: sssd-ad.5.xml:1252 +#, fuzzy +#| msgid "" +#| "How often should the back end perform periodic DNS update in addition to " +#| "the automatic update performed when the back end goes online. This " +#| "option is optional and applicable only when dyndns_update is true. Note " +#| "that the lowest possible value is 60 seconds in-case if value is provided " +#| "less than 60, parameter will assume lowest value only." msgid "" "How often should the back end perform periodic DNS update in addition to the " -"automatic update performed when the back end goes online. This option is " -"optional and applicable only when dyndns_update is true. Note that the " -"lowest possible value is 60 seconds in-case if value is provided less than " -"60, parameter will assume lowest value only." +"automatic update performed when the back end goes online. This is optional " +"and applicable only when dyndns_update is true. Note that the minimum value " +"is 60 seconds, any specified value below this threshold will default to 60." msgstr "" "Quão frequente deve o backend executar a actualização DNS periódica em " "adição à actualização automática executada quando o backend fica online. " @@ -14997,7 +15528,7 @@ msgstr "" "ser inferior a 60, o parâmetro irá assumir apenas o menor valor." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ad.5.xml:1472 +#: sssd-ad.5.xml:1465 msgid "" "The following example assumes that SSSD is correctly configured and " "example.com is one of the domains in the <replaceable>[sssd]</replaceable> " @@ -15008,7 +15539,7 @@ msgstr "" "Este exemplo mostra apenas as opções específicas do provedor AD." #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-ad.5.xml:1479 +#: sssd-ad.5.xml:1472 #, no-wrap msgid "" "[domain/EXAMPLE]\n" @@ -15032,7 +15563,7 @@ msgstr "" "ad_domain = example.com\n" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-ad.5.xml:1499 +#: sssd-ad.5.xml:1492 #, no-wrap msgid "" "access_provider = ldap\n" @@ -15044,7 +15575,7 @@ msgstr "" "ldap_account_expire_policy = ad\n" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ad.5.xml:1495 +#: sssd-ad.5.xml:1488 msgid "" "The AD access control provider checks if the account is expired. It has the " "same effect as the following configuration of the LDAP provider: " @@ -15055,7 +15586,7 @@ msgstr "" "type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ad.5.xml:1505 +#: sssd-ad.5.xml:1498 msgid "" "However, unless the <quote>ad</quote> access control provider is explicitly " "configured, the default access provider is <quote>permit</quote>. Please " @@ -15070,7 +15601,7 @@ msgstr "" "ligação (tal como URIs do LDAP e detalhes de encriptação) manualmente." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ad.5.xml:1513 +#: sssd-ad.5.xml:1506 msgid "" "When the autofs provider is set to <quote>ad</quote>, the RFC2307 schema " "attribute mapping (nisMap, nisObject, ...) is used, because these attributes " @@ -15282,11 +15813,17 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-sudo.5.xml:137 +#, fuzzy +#| msgid "" +#| "The <emphasis>smart refresh</emphasis> periodically downloads rules that " +#| "are new or were modified after the last update. Its primary goal is to " +#| "keep the database growing by fetching only small increments that do not " +#| "generate large amounts of network traffic." msgid "" "The <emphasis>smart refresh</emphasis> periodically downloads rules that are " -"new or were modified after the last update. Its primary goal is to keep the " -"database growing by fetching only small increments that do not generate " -"large amounts of network traffic." +"new or were modified after the last update. Its primary goal is to grow the " +"database incrementally by fetching only small updates, avoiding large " +"amounts of network traffic." msgstr "" "O <emphasis>smart refresh</emphasis> descarrega periodicamente regras que " "são novas ou foram modificadas após a última actualização. O seu objectivo " @@ -15528,11 +16065,20 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-idp.5.xml:70 +#, fuzzy +#| msgid "" +#| "Depending on the IdP product additional platform specific options might " +#| "follow the name separated by a colon (:). E.g. for Keycloak the base URI " +#| "for the user and group REST API must be given. For Entra ID this is not " +#| "needed because there is a generic endpoint for all tenants." msgid "" "Depending on the IdP product additional platform specific options might " "follow the name separated by a colon (:). E.g. for Keycloak the base URI for " -"the user and group REST API must be given. For Entra ID this is not needed " -"because there is a generic endpoint for all tenants." +"the user and group REST API must be given. For Entra ID the base URI for the " +"Microsoft Graph API can be given to use sovereign or government cloud " +"endpoints instead of the default (https://graph.microsoft.com/v1.0). E.g. " +"<quote>entra_id:https://graph.microsoft.us/v1.0</quote> for the US " +"government cloud (GCC High)." msgstr "" "Dependendo d produto IdP opções adicionais especificas da plataforma podem " "ter o nome separado por dois-pontos (:). Ex. para Keycloak o URI base para o " @@ -15540,17 +16086,17 @@ msgstr "" "necessário porque é um endpoint genérico para todos os tenants." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:78 sssd-idp.5.xml:94 sssd-idp.5.xml:119 +#: sssd-idp.5.xml:82 sssd-idp.5.xml:98 sssd-idp.5.xml:123 msgid "Default: Not set (Required)" msgstr "Predefinição: Não definida (Requerido)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:83 +#: sssd-idp.5.xml:87 msgid "idp_client_id (string)" msgstr "idp_client_id (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:86 +#: sssd-idp.5.xml:90 msgid "" "ID of the IdP client used by SSSD to authenticate users and as a client to " "lookup user and group attributes. This client must offer device " @@ -15563,12 +16109,12 @@ msgstr "" "permissão para procurar e ler atributos de utilizador e grupo." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:99 +#: sssd-idp.5.xml:103 msgid "idp_client_secret (string)" msgstr "idp_client_secret (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:102 +#: sssd-idp.5.xml:106 msgid "" "Password of the IdP client. The password is required for the id_provider. If " "only used as auth_provider it depends on the server side configuration if it " @@ -15579,22 +16125,22 @@ msgstr "" "lado do servidor se é requerida ou não." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:113 +#: sssd-idp.5.xml:117 msgid "idp_token_endpoint (string)" msgstr "idp_token_endpoint (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:116 +#: sssd-idp.5.xml:120 msgid "IdP endpoint for requesting access tokens." msgstr "Endpoint IdP para requisitar testemunhos de acesso." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:124 +#: sssd-idp.5.xml:128 msgid "idp_device_auth_endpoint (string)" msgstr "idp_device_auth_endpoint (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:127 +#: sssd-idp.5.xml:131 msgid "" "IdP endpoint for device authorization according to RFC-8628. This is " "required for user authentication." @@ -15603,12 +16149,12 @@ msgstr "" "requerido para autenticação de utilizador." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:137 +#: sssd-idp.5.xml:141 msgid "idp_userinfo_endpoint (string)" msgstr "idp_userinfo_endpoint (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:140 +#: sssd-idp.5.xml:144 msgid "" "IdP userinfo endpoint to request user attributes after a successful " "authentication of the user. Required for authentication." @@ -15618,12 +16164,12 @@ msgstr "" "autenticação." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:150 +#: sssd-idp.5.xml:154 msgid "idp_id_scope (string)" msgstr "idp_id_scope (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:153 +#: sssd-idp.5.xml:157 msgid "" "Scope required for looking up user and group attributes with the REST API. " "The scopes are used by the server to determine which attributes/claims are " @@ -15633,13 +16179,20 @@ msgstr "" "API. Os escopos são usados pelo servidor para determinar que atributos/" "reivindicações são retornados ao chamador." +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:163 +msgid "" +"Note: In previous versions of SSSD, this option was expected to already be " +"URL-encoded." +msgstr "" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:164 +#: sssd-idp.5.xml:172 msgid "idp_auth_scope (string)" msgstr "idp_auth_scope (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:167 +#: sssd-idp.5.xml:175 msgid "" "Scope required during authentication. The scopes are used by the server to " "determine which attributes/claims are returned to the caller." @@ -15648,7 +16201,7 @@ msgstr "" "para determinar que atributos/reivindicações são retornados ao chamador." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:172 +#: sssd-idp.5.xml:180 msgid "" "Currently the tokens returned during user authentication are not used for " "other purposes hence the only important claim is the subject identifier " @@ -15662,22 +16215,120 @@ msgstr "" "a mudar no futuro." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:185 +#: sssd-idp.5.xml:193 +#, fuzzy +#| msgid "ldap_user_extra_attrs (string)" +msgid "idp_auth_user_identifier_attr (string)" +msgstr "ldap_user_extra_attrs (string)" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:196 +msgid "" +"Attribute used to identify the authenticated user in userinfo data or token " +"claims." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:200 +msgid "" +"For hybrid Active Directory and Entra ID deployments where " +"<quote>id_provider = ad</quote> and <quote>auth_provider = idp</quote>, this " +"option must be set explicitly. No value is derived from the identity " +"provider, because more than one attribute can link an Entra ID object to its " +"on-premises counterpart and only the administrator knows which one the " +"directory synchronization is configured to use." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:211 +msgid "" +"Setting this option to <quote>onPremisesImmutableId</quote> is the usual " +"choice for such deployments. Microsoft Entra Connect populates that " +"attribute with the base64-encoded form of the 16-byte Active Directory " +"<quote>objectGUID</quote> when objectGUID is used as the sourceAnchor. SSSD " +"decodes the value and converts the raw bytes with the same conversion used " +"for AD objectGUID attributes, so the result matches the UUID stored in the " +"SSSD cache for the AD user." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:224 +msgid "" +"Note that Microsoft Entra Connect 1.1.524.0 and later use <quote>ms-DS-" +"ConsistencyGuid</quote> as the sourceAnchor for user objects instead of " +"<quote>objectGUID</quote>. The value is normally copied from objectGUID for " +"objects that do not have it set yet, in which case the decoded identifier " +"still matches. It does not match if ms-DS-ConsistencyGuid was populated " +"independently, if users were moved between forests or domains, or if a " +"different attribute such as employeeID was selected as the sourceAnchor. See " +"<ulink url=\"https://learn.microsoft.com/en-us/entra/identity/hybrid/connect/" +"plan-connect-design-concepts\"> Microsoft Entra Connect: Design concepts</" +"ulink> for details on sourceAnchor selection." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:241 +msgid "" +"Microsoft Graph does not return <quote>onPremisesImmutableId</quote> by " +"default. The <quote>idp_userinfo_endpoint</quote> must request it with " +"<quote>$select</quote>, see the example below and <ulink url=\"https://" +"learn.microsoft.com/en-us/graph/api/resources/user\"> the Microsoft Graph " +"user resource type</ulink>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:251 +msgid "" +"If the configured attribute is missing or cannot be decoded (for example " +"cloud-only Entra ID users without <quote>onPremisesImmutableId</quote>), " +"authentication fails. SSSD does not fall back to another attribute when this " +"option is set." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:258 +msgid "" +"Default: not set, <quote>sub</quote> for Keycloak and <quote>id</quote> for " +"other IdP types" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-idp.5.xml:264 msgid "idp_request_timeout (integer)" msgstr "idp_request_timeout (inteiro)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:188 +#: sssd-idp.5.xml:267 msgid "Timeout in seconds for an individual request to the IdP." msgstr "Tempo limite em segundos para um pedido individual ao IdP." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:197 +#: sssd-idp.5.xml:276 +#, fuzzy +#| msgid "ldap_referrals (boolean)" +msgid "idp_auto_refresh (boolean)" +msgstr "ldap_referrals (booleano)" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:279 +msgid "" +"Refresh tokens automatically, after they have reached about half their " +"lifetime." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:283 +msgid "" +"Note: Scheduled token refreshes are not preserved across restarts of SSSD." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-idp.5.xml:292 msgid "idmap_range_min (integer)" msgstr "idmap_range_min (inteiro)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:200 +#: sssd-idp.5.xml:295 msgid "" "Specifies the lower (inclusive) bound of the range of POSIX IDs to use for " "mapping IdP users and group to POSIX IDs. It is the first POSIX ID which can " @@ -15688,7 +16339,7 @@ msgstr "" "ID que pode ser usado para o mapeamento." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:206 +#: sssd-idp.5.xml:301 msgid "" "The interval between <quote>idmap_range_min</quote> and " "<quote>idmap_range_max</quote> will be split into smaller ranges of size " @@ -15700,18 +16351,18 @@ msgstr "" "quote> que serão usadas por um domínio IdP individual." #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:213 sssd-idp.5.xml:239 include/ldap_id_mapping.xml:139 +#: sssd-idp.5.xml:308 sssd-idp.5.xml:334 include/ldap_id_mapping.xml:139 #: include/ldap_id_mapping.xml:197 msgid "Default: 200000" msgstr "Predefinição: 200000" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:218 +#: sssd-idp.5.xml:313 msgid "idmap_range_max (integer)" msgstr "idmap_range_max (inteiro)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:221 +#: sssd-idp.5.xml:316 msgid "" "Specifies the upper (exclusive) bound of the range of POSIX IDs to use for " "mapping IdP users and groups to POSIX IDs. It is the first POSIX ID which " @@ -15722,57 +16373,121 @@ msgstr "" "ID que não vai ser mais usado para o mapeamento de ID POSIX." #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:227 include/ldap_id_mapping.xml:165 +#: sssd-idp.5.xml:322 include/ldap_id_mapping.xml:165 msgid "Default: 2000200000" msgstr "Predefinição: 2000200000" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:232 +#: sssd-idp.5.xml:327 msgid "idmap_range_size (integer)" msgstr "idmap_range_size (inteiro)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:235 +#: sssd-idp.5.xml:330 msgid "Specifies the number of POSIX IDs available for a single IdP domain." msgstr "Especifica o número de IDs POSIX disponíveis para um único domínio IdP." #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-idp.5.xml:251 -#, no-wrap +#: sssd-idp.5.xml:346 +#, fuzzy, no-wrap +#| msgid "" +#| "[domain/entra_id]\n" +#| "id_provider = idp\n" +#| "idp_type = entra_id\n" +#| "idp_client_id = 12345678-abcd-0101-efef-ba9876543210\n" +#| "idp_client_secret = YOUR-CLIENT-SCERET\n" +#| "idp_token_endpoint = https://login.microsoftonline.com/TENNANT-ID/oauth2/v2.0/token\n" +#| "idp_userinfo_endpoint = https://graph.microsoft.com/v1.0/me\n" +#| "idp_device_auth_endpoint = https://login.microsoftonline.com/TENNANT-ID/oauth2/v2.0/devicecode\n" +#| "idp_id_scope = https%3A%2F%2Fgraph.microsoft.com%2F.default\n" +#| "idp_auth_scope = openid profile email\n" msgid "" "[domain/entra_id]\n" "id_provider = idp\n" "idp_type = entra_id\n" "idp_client_id = 12345678-abcd-0101-efef-ba9876543210\n" +"idp_client_secret = YOUR-CLIENT-SECRET\n" +"idp_token_endpoint = https://login.microsoftonline.com/TENANT-ID/oauth2/v2.0/token\n" +"idp_userinfo_endpoint = https://graph.microsoft.com/v1.0/me\n" +"idp_device_auth_endpoint = https://login.microsoftonline.com/TENANT-ID/oauth2/v2.0/devicecode\n" +"idp_id_scope = https://graph.microsoft.com/.default\n" +"idp_auth_scope = openid profile email\n" +msgstr "" +"[domain/entra_id]\n" +"id_provider = idp\n" +"idp_type = entra_id\n" +"idp_client_id = 12345678-abcd-0101-efef-ba9876543210\n" "idp_client_secret = YOUR-CLIENT-SCERET\n" "idp_token_endpoint = https://login.microsoftonline.com/TENNANT-ID/oauth2/v2.0/token\n" "idp_userinfo_endpoint = https://graph.microsoft.com/v1.0/me\n" "idp_device_auth_endpoint = https://login.microsoftonline.com/TENNANT-ID/oauth2/v2.0/devicecode\n" "idp_id_scope = https%3A%2F%2Fgraph.microsoft.com%2F.default\n" "idp_auth_scope = openid profile email\n" + +#. type: Content of: <reference><refentry><refsect1><para><programlisting> +#: sssd-idp.5.xml:358 +#, fuzzy, no-wrap +#| msgid "" +#| "[domain/entra_id]\n" +#| "id_provider = idp\n" +#| "idp_type = entra_id\n" +#| "idp_client_id = 12345678-abcd-0101-efef-ba9876543210\n" +#| "idp_client_secret = YOUR-CLIENT-SCERET\n" +#| "idp_token_endpoint = https://login.microsoftonline.com/TENNANT-ID/oauth2/v2.0/token\n" +#| "idp_userinfo_endpoint = https://graph.microsoft.com/v1.0/me\n" +#| "idp_device_auth_endpoint = https://login.microsoftonline.com/TENNANT-ID/oauth2/v2.0/devicecode\n" +#| "idp_id_scope = https%3A%2F%2Fgraph.microsoft.com%2F.default\n" +#| "idp_auth_scope = openid profile email\n" +msgid "" +"[domain/ad.example.com]\n" +"id_provider = ad\n" +"auth_provider = idp\n" +"access_provider = permit\n" +"\n" +"ad_domain = ad.example.com\n" +"krb5_realm = AD.EXAMPLE.COM\n" +"\n" +"idp_type = entra_id\n" +"idp_client_id = 12345678-abcd-0101-efef-ba9876543210\n" +"idp_client_secret = YOUR-CLIENT-SECRET\n" +"idp_token_endpoint = https://login.microsoftonline.com/TENANT-ID/oauth2/v2.0/token\n" +"idp_userinfo_endpoint = https://graph.microsoft.com/v1.0/me?$select=id,userPrincipalName,onPremisesImmutableId\n" +"idp_device_auth_endpoint = https://login.microsoftonline.com/TENANT-ID/oauth2/v2.0/devicecode\n" +"idp_id_scope = https://graph.microsoft.com/.default\n" +"idp_auth_scope = openid profile email\n" +"idp_auth_user_identifier_attr = onPremisesImmutableId\n" msgstr "" "[domain/entra_id]\n" "id_provider = idp\n" "idp_type = entra_id\n" "idp_client_id = 12345678-abcd-0101-efef-ba9876543210\n" "idp_client_secret = YOUR-CLIENT-SCERET\n" -"idp_token_endpoint = https://login.microsoftonline.com/TENNANT-ID/oauth2/" -"v2.0/token\n" +"idp_token_endpoint = https://login.microsoftonline.com/TENNANT-ID/oauth2/v2.0/token\n" "idp_userinfo_endpoint = https://graph.microsoft.com/v1.0/me\n" -"idp_device_auth_endpoint = https://login.microsoftonline.com/TENNANT-ID/" -"oauth2/v2.0/devicecode\n" +"idp_device_auth_endpoint = https://login.microsoftonline.com/TENNANT-ID/oauth2/v2.0/devicecode\n" "idp_id_scope = https%3A%2F%2Fgraph.microsoft.com%2F.default\n" "idp_auth_scope = openid profile email\n" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-idp.5.xml:263 -#, no-wrap +#: sssd-idp.5.xml:377 +#, fuzzy, no-wrap +#| msgid "" +#| "[domain/keycloak]\n" +#| "idp_type = keycloak:https://master.keycloak.test:8443/auth/admin/realms/master/\n" +#| "id_provider = idp\n" +#| "idp_client_id = myclient\n" +#| "idp_client_secret = YOUR-CLIENT-SCERET\n" +#| "idp_token_endpoint = https://master.keycloak.test:8443/auth/realms/master/protocol/openid-connect/token\n" +#| "idp_userinfo_endpoint = https://master.keycloak.test:8443/auth/realms/master/protocol/openid-connect/userinfo\n" +#| "idp_device_auth_endpoint = https://master.keycloak.test:8443/auth/realms/master/protocol/openid-connect/auth/device\n" +#| "idp_id_scope = profile\n" +#| "idp_auth_scope = openid profile email\n" msgid "" "[domain/keycloak]\n" "idp_type = keycloak:https://master.keycloak.test:8443/auth/admin/realms/master/\n" "id_provider = idp\n" "idp_client_id = myclient\n" -"idp_client_secret = YOUR-CLIENT-SCERET\n" +"idp_client_secret = YOUR-CLIENT-SECRET\n" "idp_token_endpoint = https://master.keycloak.test:8443/auth/realms/master/protocol/openid-connect/token\n" "idp_userinfo_endpoint = https://master.keycloak.test:8443/auth/realms/master/protocol/openid-connect/userinfo\n" "idp_device_auth_endpoint = https://master.keycloak.test:8443/auth/realms/master/protocol/openid-connect/auth/device\n" @@ -15780,29 +16495,41 @@ msgid "" "idp_auth_scope = openid profile email\n" msgstr "" "[domain/keycloak]\n" -"idp_type = keycloak:https://master.keycloak.test:8443/auth/admin/realms/" -"master/\n" +"idp_type = keycloak:https://master.keycloak.test:8443/auth/admin/realms/master/\n" "id_provider = idp\n" "idp_client_id = myclient\n" "idp_client_secret = YOUR-CLIENT-SCERET\n" -"idp_token_endpoint = https://master.keycloak.test:8443/auth/realms/master/" -"protocol/openid-connect/token\n" -"idp_userinfo_endpoint = https://master.keycloak.test:8443/auth/realms/master/" -"protocol/openid-connect/userinfo\n" -"idp_device_auth_endpoint = https://master.keycloak.test:8443/auth/realms/" -"master/protocol/openid-connect/auth/device\n" +"idp_token_endpoint = https://master.keycloak.test:8443/auth/realms/master/protocol/openid-connect/token\n" +"idp_userinfo_endpoint = https://master.keycloak.test:8443/auth/realms/master/protocol/openid-connect/userinfo\n" +"idp_device_auth_endpoint = https://master.keycloak.test:8443/auth/realms/master/protocol/openid-connect/auth/device\n" "idp_id_scope = profile\n" "idp_auth_scope = openid profile email\n" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-idp.5.xml:250 +#: sssd-idp.5.xml:345 +#, fuzzy +#| msgid "" +#| "<placeholder type=\"programlisting\" id=\"0\"/> <placeholder " +#| "type=\"programlisting\" id=\"1\"/>" msgid "" "<placeholder type=\"programlisting\" id=\"0\"/> <placeholder " -"type=\"programlisting\" id=\"1\"/>" +"type=\"programlisting\" id=\"1\"/> <placeholder type=\"programlisting\" " +"id=\"2\"/>" msgstr "" "<placeholder type=\"programlisting\" id=\"0\"/> <placeholder " "type=\"programlisting\" id=\"1\"/>" +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-idp.5.xml:390 +msgid "" +"In the hybrid Active Directory and Entra ID example above, " +"<quote>onPremisesImmutableId</quote> is used during authentication so the " +"IdP result matches the AD objectGUID UUID stored in the SSSD cache. The " +"attribute must be requested via <quote>$select</quote> on the Graph userinfo " +"endpoint and is only populated for users synchronized from Active Directory " +"with objectGUID as the sourceAnchor." +msgstr "" + #. type: Content of: <reference><refentry><refnamediv><refname> #: sssd.8.xml:10 sssd.8.xml:15 msgid "sssd" @@ -16982,9 +17709,13 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:291 +#, fuzzy +#| msgid "" +#| "<emphasis>demand</emphasis> to use FAST. The authentication fails if the " +#| "server does not require fast." msgid "" "<emphasis>demand</emphasis> to use FAST. The authentication fails if the " -"server does not require fast." +"server does not support FAST." msgstr "" "<emphasis>demand</emphasis> (obriga) a usar FAST. A autenticação falha se o " "servidor não requerer fast." @@ -18098,7 +18829,9 @@ msgstr "Atributos de configuração" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sss_rpcidmapd.5.xml:69 -msgid "memcache (bool)" +#, fuzzy +#| msgid "memcache (bool)" +msgid "memcache (boolean)" msgstr "memcache (booleano)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> @@ -18171,7 +18904,7 @@ msgstr "" "<placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <refsect1><title> -#: sss_rpcidmapd.5.xml:120 sssd-kcm.8.xml:316 include/seealso.xml:2 +#: sss_rpcidmapd.5.xml:120 sssd-kcm.8.xml:315 include/seealso.xml:2 msgid "SEE ALSO" msgstr "VEJA TAMBÉM" @@ -18481,10 +19214,21 @@ msgstr "OBTENÇÃO DE CHAVE" #. type: Content of: <reference><refentry><refsect1><para> #: sss_ssh_knownhosts.1.xml:93 +#, fuzzy +#| msgid "" +#| "The key lines retrieved from the backend are expected to respect the key " +#| "format as decribed in the <quote>SSH_KNOWN_HOSTS FILE FORMAT</quote> " +#| "section of <citerefentry><refentrytitle>sshd</refentrytitle> " +#| "<manvolnum>8</manvolnum></citerefentry>. However, returning only the " +#| "keytype and the key itself is tolerated, in which case, the hostname " +#| "received as parameter will be added before the keytype to output a " +#| "correctly formatted line. The hostname will be added unmodified or just " +#| "the hostname (no port number), depending on whether the <option>-o</" +#| "option>,<option>--only-host-name</option> option was provided." msgid "" "The key lines retrieved from the backend are expected to respect the key " -"format as decribed in the <quote>SSH_KNOWN_HOSTS FILE FORMAT</quote> section " -"of <citerefentry><refentrytitle>sshd</refentrytitle> <manvolnum>8</" +"format as described in the <quote>SSH_KNOWN_HOSTS FILE FORMAT</quote> " +"section of <citerefentry><refentrytitle>sshd</refentrytitle> <manvolnum>8</" "manvolnum></citerefentry>. However, returning only the keytype and the key " "itself is tolerated, in which case, the hostname received as parameter will " "be added before the keytype to output a correctly formatted line. The " @@ -19143,19 +19887,24 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-kcm.8.xml:215 +#, fuzzy +#| msgid "" +#| "The KCM service is configured in the <quote>kcm</quote> For a detailed " +#| "syntax reference, refer to the <quote>FILE FORMAT</quote> section of the " +#| "<citerefentry> <refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</" +#| "manvolnum> </citerefentry> manual page." msgid "" -"The KCM service is configured in the <quote>kcm</quote> For a detailed " -"syntax reference, refer to the <quote>FILE FORMAT</quote> section of the " -"<citerefentry> <refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</" -"manvolnum> </citerefentry> manual page." +"For a detailed syntax reference, refer to the <quote>FILE FORMAT</quote> " +"section of the <citerefentry> <refentrytitle>sssd.conf</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry> manual page." msgstr "" "O serviço KCM é configurado em <quote>kcm</quote> Para uma referência " "detalhada de sintaxe, consulte a secção <quote>FORMATO DE FICHEIRO</quote> " -"do manual <citerefentry> <refentrytitle>sssd.conf</refentrytitle> <manvolnum>" -"5</manvolnum> </citerefentry>." +"do manual <citerefentry> <refentrytitle>sssd.conf</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry>." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-kcm.8.xml:223 +#: sssd-kcm.8.xml:222 msgid "" "The generic SSSD service options such as <quote>debug_level</quote> or " "<quote>fd_limit</quote> are accepted by the kcm service. Please refer to " @@ -19170,23 +19919,23 @@ msgstr "" "também algumas opções específicas do KCM." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:234 +#: sssd-kcm.8.xml:233 msgid "socket_path (string)" msgstr "socket_path (string)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:237 +#: sssd-kcm.8.xml:236 msgid "The socket the KCM service will listen on." msgstr "O socket que o serviço KCM irá escutar." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:240 +#: sssd-kcm.8.xml:239 msgid "Default: <replaceable>/var/run/.heim_org.h5l.kcm-socket</replaceable>" msgstr "" "Predefinição: <replaceable>/var/run/.heim_org.h5l.kcm-socket</replaceable>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:243 +#: sssd-kcm.8.xml:242 msgid "" "<phrase condition=\"have_systemd\"> Note: on platforms where systemd is " "supported, the socket path is overwritten by the one defined in the sssd-" @@ -19197,29 +19946,29 @@ msgstr "" "unidade sssd-kcm.socket. </phrase>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:252 +#: sssd-kcm.8.xml:251 msgid "max_ccaches (integer)" msgstr "max_ccaches (inteiro)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:255 +#: sssd-kcm.8.xml:254 msgid "How many credential caches does the KCM database allow for all users." msgstr "" "Quantas caches de credenciais a base de dados KCM permite para todos os " "utilizadores." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:259 +#: sssd-kcm.8.xml:258 msgid "Default: 0 (unlimited, only the per-UID quota is enforced)" msgstr "Predefinição: 0 (ilimitado, apenas a quota por-UID é forçada)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:264 +#: sssd-kcm.8.xml:263 msgid "max_uid_ccaches (integer)" msgstr "max_uid_ccaches (inteiro)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:267 +#: sssd-kcm.8.xml:266 msgid "" "How many credential caches does the KCM database allow per UID. This is " "equivalent to <quote>with how many principals you can kinit</quote>." @@ -19228,61 +19977,67 @@ msgstr "" "equivalente a <quote>com quantos principais você pode kinit</quote>." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:272 +#: sssd-kcm.8.xml:271 msgid "Default: 64" msgstr "Predefinição: 64" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:277 +#: sssd-kcm.8.xml:276 msgid "max_ccache_size (integer)" msgstr "max_ccache_size (inteiro)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:280 +#: sssd-kcm.8.xml:279 +#, fuzzy +#| msgid "" +#| "How big can a credential cache be per ccache. Each service ticket " +#| "accounts into this quota." msgid "" -"How big can a credential cache be per ccache. Each service ticket accounts " -"into this quota." +"How big a credential cache be per ccache. Each service ticket counts toward " +"this quota." msgstr "" "Quão grande pode ser uma cache de credenciais por ccache. Cada bilhete de " "serviço conta para esta cota." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:284 +#: sssd-kcm.8.xml:283 msgid "Default: 65536" msgstr "Predefinição: 65536" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:289 -msgid "tgt_renewal (bool)" +#: sssd-kcm.8.xml:288 +#, fuzzy +#| msgid "tgt_renewal (bool)" +msgid "tgt_renewal (boolean)" msgstr "tgt_renewal (booleano)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:292 +#: sssd-kcm.8.xml:291 msgid "Enables TGT renewals functionality." msgstr "Activa a funcionalidade de renovações TGT." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:295 +#: sssd-kcm.8.xml:294 msgid "Default: False (Automatic renewals disabled)" msgstr "Predefinição: False (Renovações automáticas desactivadas)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:300 +#: sssd-kcm.8.xml:299 msgid "tgt_renewal_inherit (string)" msgstr "tgt_renewal_inherit (string)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:303 +#: sssd-kcm.8.xml:302 msgid "Domain to inherit krb5_* options from, for use with TGT renewals." msgstr "Domínio de onde herdar opções krb5_*, para usar com renovações TGT." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:307 +#: sssd-kcm.8.xml:306 msgid "Default: NULL" msgstr "Predefinição: NULL" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-kcm.8.xml:318 +#: sssd-kcm.8.xml:317 msgid "" "<citerefentry> <refentrytitle>sssd</refentrytitle><manvolnum>8</manvolnum> </" "citerefentry>, <citerefentry> <refentrytitle>sssd.conf</" @@ -20314,9 +21069,11 @@ msgstr "" "acesso é concedido ou não." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap-attributes.5.xml:381 sssd-ldap-attributes.5.xml:395 -msgid "Default: loginDisabled" -msgstr "Predefinição: loginDisabled" +#: sssd-ldap-attributes.5.xml:381 +#, fuzzy +#| msgid "Default: uid (rfc2307, rfc2307bis and IPA), sAMAccountName (AD)" +msgid "Default: loginDisabled (rfc2307, rfc2307bis and IPA), not set (AD)" +msgstr "Predefinição: uid (rfc2307, rfc2307bis e IPA), sAMAccountName (AD)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:387 @@ -20332,6 +21089,14 @@ msgstr "" "Quando se usa ldap_account_expire_policy=nds, este atributo determina até " "que data o acesso é concedido." +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:395 +#, fuzzy +#| msgid "Default: cn (rfc2307, rfc2307bis and IPA), sAMAccountName (AD)" +msgid "" +"Default: loginExpirationTime (rfc2307, rfc2307bis and IPA), not set (AD)" +msgstr "Predefinição: cn (rfc2307, rfc2307bis e IPA), sAMAccountName (AD)" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:401 msgid "ldap_user_nds_login_allowed_time_map (string)" @@ -20348,8 +21113,11 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:409 -msgid "Default: loginAllowedTimeMap" -msgstr "Predefinição: loginAllowedTimeMap" +#, fuzzy +#| msgid "Default: uid (rfc2307, rfc2307bis and IPA), sAMAccountName (AD)" +msgid "" +"Default: loginAllowedTimeMap (rfc2307, rfc2307bis and IPA), not set (AD)" +msgstr "Predefinição: uid (rfc2307, rfc2307bis e IPA), sAMAccountName (AD)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:415 @@ -20937,9 +21705,9 @@ msgid "The object class of a host entry in LDAP." msgstr "A classe de objecto de uma entrada de máquina em LDAP." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap-attributes.5.xml:900 sssd-ldap-attributes.5.xml:997 -msgid "Default: ipService" -msgstr "Predefinição: ipService" +#: sssd-ldap-attributes.5.xml:900 sssd-ldap-attributes.5.xml:1213 +msgid "Default: ipHost" +msgstr "Predefinição: ipHost" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:906 @@ -21026,6 +21794,11 @@ msgstr "ldap_service_object_class (string)" msgid "The object class of a service entry in LDAP." msgstr "A classe de objecto de uma entrada de serviço em LDAP." +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:997 +msgid "Default: ipService" +msgstr "Predefinição: ipService" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1003 msgid "ldap_service_name (string)" @@ -21281,11 +22054,6 @@ msgstr "ldap_iphost_object_class (string)" msgid "The object class of an iphost entry in LDAP." msgstr "A classe de objecto de uma entrada iphost no LDAP." -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap-attributes.5.xml:1213 -msgid "Default: ipHost" -msgstr "Predefinição: ipHost" - #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1219 msgid "ldap_iphost_name (string)" @@ -21377,7 +22145,7 @@ msgstr "ldap_subuid_object_class (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1300 msgid "The object class of an subid entry in LDAP." -msgstr "A classe de objecto de uma entrada de subid em LDAP." +msgstr "A classe de objecto de uma entrada sub-id em LDAP." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1303 @@ -21520,10 +22288,16 @@ msgstr "CONFIGURAÇÃO" #. type: Content of: <reference><refentry><refsect1><para><programlisting> #: sssd_krb5_localauth_plugin.8.xml:56 -#, no-wrap +#, fuzzy, no-wrap +#| msgid "" +#| "[plugins]\n" +#| " localauth = {\n" +#| " module = sssd:/usr/lib64/sssd/modules/sssd_krb5_localauth_plugin.so\n" +#| " }\n" msgid "" "[plugins]\n" " localauth = {\n" +" disable = an2ln\n" " module = sssd:/usr/lib64/sssd/modules/sssd_krb5_localauth_plugin.so\n" " }\n" msgstr "" @@ -21552,6 +22326,28 @@ msgstr "" "incluído na configuração Kerberos local o plugin será activado " "automaticamente." +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_localauth_plugin.8.xml:67 +msgid "" +"This configuration snippet also disables the <command>an2ln</command> module " +"provided by MIT Kerberos if SSSD is configured to use the AD or IPA " +"provider. In those environments <command>sssd_krb5_localauth_plugin</" +"command> can reliably map the system user names to Kerberos principals. A " +"fallback to <command>an2ln</command> might cause issues in environments " +"where users have the privilege to create Kerberos principals on their own " +"which might collide with names of other users used in the system. Other " +"modules provided by MIT Kerberos, e.g. <command>k5login</command> are not " +"affected." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_localauth_plugin.8.xml:79 +msgid "" +"Note: If using <quote>auth_provider = krb5</quote> then " +"<command>sssd_krb5_localauth_plugin</command> is not used, therefore the " +"above text is not applicable." +msgstr "" + #. type: Content of: <variablelist><varlistentry><term> #: include/autofs_attributes.xml:3 msgid "ldap_autofs_map_object_class (string)" @@ -22673,40 +23469,6 @@ msgstr "" "<emphasis>Predefinição</emphasis>: 0x0070 (isto é, falhas fatais, críticas e " "sérias; corresponde à definição 2 na notação decimal)" -#. type: Content of: <refsect1><title> -#: include/local.xml:2 -msgid "THE LOCAL DOMAIN" -msgstr "O DOMÍNIO LOCAL" - -#. type: Content of: <refsect1><para> -#: include/local.xml:4 -msgid "" -"In order to function correctly, a domain with <quote>id_provider=local</" -"quote> must be created and the SSSD must be running." -msgstr "" -"De modo a funcionar correctamente, tem de ser criado um domínio com <quote>" -"id_provider=local</quote> e o SSSD tem de estar a correr." - -#. type: Content of: <refsect1><para> -#: include/local.xml:9 -msgid "" -"The administrator might want to use the SSSD local users instead of " -"traditional UNIX users in cases where the group nesting (see <citerefentry> " -"<refentrytitle>sss_groupadd</refentrytitle> <manvolnum>8</manvolnum> </" -"citerefentry>) is needed. The local users are also useful for testing and " -"development of the SSSD without having to deploy a full remote server. The " -"<command>sss_user*</command> and <command>sss_group*</command> tools use a " -"local LDB storage to store users and groups." -msgstr "" -"O administrador pode querer usar os utilizadores locais do SSSD em vez dos " -"utilizadores tradicionais UNIX em casos onde o aninhamento de grupos (veja " -"<citerefentry> <refentrytitle>sss_groupadd</refentrytitle> <manvolnum>8</" -"manvolnum> </citerefentry>) é necessário. Os utilizadores locais são também " -"úteis para testes e desenvolvimento do SSSD sem se ter que implementar um " -"servidor remoto completo. As ferramentas <command>sss_user*</command> e " -"<command>sss_group*</command> usam um armazenamento LDB local para guardar " -"utilizadores e grupos." - #. type: Content of: <refsect1><para> #: include/seealso.xml:4 msgid "" @@ -23440,6 +24202,118 @@ msgstr "" "Especifica se a máquina e o principal utilizador devem ser canonizados. Esta " "funcionalidade está disponível com o MIT Kerberos 1.7 e versões posteriores." +#~ msgid "" +#~ "The data types used are string (no quotes needed), integer and bool (with " +#~ "values of <quote>TRUE/FALSE</quote>)." +#~ msgstr "" +#~ "Os tipos de dados usados são cadeia de caracteres (sem aspas " +#~ "necessárias), inteiro e booleano (com valores de <quote>TRUE/FALSE</" +#~ "quote>)." + +#~ msgid "services" +#~ msgstr "serviços" + +#~ msgid "domains" +#~ msgstr "domínios" + +#~ msgid "fd_limit" +#~ msgstr "fd_limit" + +#~ msgid "client_idle_timeout" +#~ msgstr "client_idle_timeout" + +#~ msgid "default_shell" +#~ msgstr "default_shell" + +#~ msgid "" +#~ "Note: This option can also be set per-domain which overwrites the value " +#~ "in [nss] section." +#~ msgstr "" +#~ "Nota: Esta opção também pode ser definida por-domínio o que sobrepõe o " +#~ "valor na secção [nss]." + +#~ msgid "These options can be used to configure session recording." +#~ msgstr "Estas opções podem ser usadas para configurar o registo de sessão." + +#~ msgid "entry_cache_computer_timeout (integer)" +#~ msgstr "entry_cache_computer_timeout (inteiro)" + +#~ msgid "" +#~ "How many seconds to keep the local computer entry before asking the " +#~ "backend again" +#~ msgstr "" +#~ "Durante quantos segundos manter a entrada de computador local antes de " +#~ "questionar o backend outra vez" + +#~ msgid "" +#~ "Default: <quote>id_provider</quote> is used if it is set and can handle " +#~ "selinux loading requests." +#~ msgstr "" +#~ "Predefinição: é usado <quote>id_provider</quote> se estiver definido e " +#~ "puder lidar com pedidos de carregamento selinux." + +#~ msgid "" +#~ "Please see the section <quote>FAILOVER</quote> for more information about " +#~ "the service resolution." +#~ msgstr "" +#~ "Por favor veja a secção <quote>FAILOVER</quote> para mais informação " +#~ "sobre a resolução de serviço." + +#~ msgid "" +#~ "NOTE: On older systems (such as RHEL 5), for this behavior to work " +#~ "reliably, the default Kerberos realm must be set properly in /etc/" +#~ "krb5.conf" +#~ msgstr "" +#~ "NOTA: Em sistemas antigos (como o RHEL 5), para este comportamento poder " +#~ "ter fiabilidade de funcionamento, o reino Kerberos predefinido tem de ser " +#~ "definido apropriadamente em /etc/krb5.conf" + +#~ msgid "ipa_hbac_selinux (integer)" +#~ msgstr "ipa_hbac_selinux (inteiro)" + +#~ msgid "" +#~ "NOTE: While it is still possible to use the old " +#~ "<emphasis>ipa_dyndns_iface</emphasis> option, users should migrate to " +#~ "using <emphasis>dyndns_iface</emphasis> in their config file." +#~ msgstr "" +#~ "NOTA: Apesar de ainda ser possível usar a opção antiga " +#~ "<emphasis>ipa_dyndns_iface</emphasis>, os utilizadores devem migrar para " +#~ "usar <emphasis>dyndns_iface</emphasis> no seu ficheiro de configuração." + +#~ msgid "Default: loginDisabled" +#~ msgstr "Predefinição: loginDisabled" + +#~ msgid "Default: loginAllowedTimeMap" +#~ msgstr "Predefinição: loginAllowedTimeMap" + +#~ msgid "THE LOCAL DOMAIN" +#~ msgstr "O DOMÍNIO LOCAL" + +#~ msgid "" +#~ "In order to function correctly, a domain with <quote>id_provider=local</" +#~ "quote> must be created and the SSSD must be running." +#~ msgstr "" +#~ "De modo a funcionar correctamente, tem de ser criado um domínio com " +#~ "<quote>id_provider=local</quote> e o SSSD tem de estar a correr." + +#~ msgid "" +#~ "The administrator might want to use the SSSD local users instead of " +#~ "traditional UNIX users in cases where the group nesting (see " +#~ "<citerefentry> <refentrytitle>sss_groupadd</refentrytitle> <manvolnum>8</" +#~ "manvolnum> </citerefentry>) is needed. The local users are also useful " +#~ "for testing and development of the SSSD without having to deploy a full " +#~ "remote server. The <command>sss_user*</command> and <command>sss_group*</" +#~ "command> tools use a local LDB storage to store users and groups." +#~ msgstr "" +#~ "O administrador pode querer usar os utilizadores locais do SSSD em vez " +#~ "dos utilizadores tradicionais UNIX em casos onde o aninhamento de grupos " +#~ "(veja <citerefentry> <refentrytitle>sss_groupadd</refentrytitle> " +#~ "<manvolnum>8</manvolnum> </citerefentry>) é necessário. Os utilizadores " +#~ "locais são também úteis para testes e desenvolvimento do SSSD sem se ter " +#~ "que implementar um servidor remoto completo. As ferramentas " +#~ "<command>sss_user*</command> e <command>sss_group*</command> usam um " +#~ "armazenamento LDB local para guardar utilizadores e grupos." + #~ msgid "subdomain_enumerate (string)" #~ msgstr "subdomain_enumerate (string)" @@ -23676,9 +24550,6 @@ msgstr "" #~ msgid "The local domain section" #~ msgstr "A secção de domínio local" -#~ msgid "default_shell (string)" -#~ msgstr "default_shell (string)" - #~ msgid "Default: <filename>/bin/bash</filename>" #~ msgstr "Padrão: <filename>bash/bin/bash</filename>" diff --git a/src/man/po/pt_BR.po b/src/man/po/pt_BR.po index ca104bd01fc..96c35638c1f 100644 --- a/src/man/po/pt_BR.po +++ b/src/man/po/pt_BR.po @@ -4,8 +4,8 @@ msgid "" msgstr "" "Project-Id-Version: sssd-docs 2.3.0\n" "Report-Msgid-Bugs-To: sssd-devel@redhat.com\n" -"POT-Creation-Date: 2026-01-14 15:00+0000\n" -"PO-Revision-Date: 2026-04-23 16:56+0000\n" +"POT-Creation-Date: 2026-10-05 16:14+0000\n" +"PO-Revision-Date: 2026-10-05 17:03+0000\n" "Last-Translator: Nari Ivy <nki.life@pm.me>\n" "Language-Team: Portuguese (Brazil) <https://translate.fedoraproject.org/" "projects/sssd/sssd-manpage-master/pt_BR/>\n" @@ -14,10 +14,10 @@ msgstr "" "Content-Type: text/plain; charset=UTF-8\n" "Content-Transfer-Encoding: 8bit\n" "Plural-Forms: nplurals=2; plural=(n != 1);\n" -"X-Generator: Weblate 5.17\n" +"X-Generator: Weblate 2026.10\n" #. type: Content of: <reference><title> -#: sssd.conf.5.xml:8 sssd-ldap.5.xml:5 pam_sss.8.xml:5 pam_sss_gss.8.xml:5 +#: sssd.conf.5.xml:10 sssd-ldap.5.xml:5 pam_sss.8.xml:5 pam_sss_gss.8.xml:5 #: sssd_krb5_locator_plugin.8.xml:5 sssd-simple.5.xml:5 sss-certmap.5.xml:5 #: sssd-ipa.5.xml:5 sssd-ad.5.xml:5 sssd-sudo.5.xml:5 sssd-idp.5.xml:5 #: sssd.8.xml:5 sss_obfuscate.8.xml:5 sss_override.8.xml:5 sssd-krb5.5.xml:5 @@ -30,12 +30,12 @@ msgid "SSSD Manual pages" msgstr "Páginas de manual do SSSD" #. type: Content of: <reference><refentry><refnamediv><refname> -#: sssd.conf.5.xml:13 sssd.conf.5.xml:19 +#: sssd.conf.5.xml:15 sssd.conf.5.xml:21 msgid "sssd.conf" msgstr "ssd.conf" #. type: Content of: <reference><refentry><refmeta><manvolnum> -#: sssd.conf.5.xml:14 sssd-ldap.5.xml:11 sssd-simple.5.xml:11 +#: sssd.conf.5.xml:16 sssd-ldap.5.xml:11 sssd-simple.5.xml:11 #: sss-certmap.5.xml:11 sssd-ipa.5.xml:11 sssd-ad.5.xml:11 sssd-sudo.5.xml:11 #: sssd-idp.5.xml:11 sssd-krb5.5.xml:11 sssd-ifp.5.xml:11 #: sss_rpcidmapd.5.xml:27 sssd-session-recording.5.xml:11 @@ -44,7 +44,7 @@ msgid "5" msgstr "5" #. type: Content of: <reference><refentry><refmeta><refmiscinfo> -#: sssd.conf.5.xml:15 sssd-ldap.5.xml:12 sssd-simple.5.xml:12 +#: sssd.conf.5.xml:17 sssd-ldap.5.xml:12 sssd-simple.5.xml:12 #: sss-certmap.5.xml:12 sssd-ipa.5.xml:12 sssd-ad.5.xml:12 sssd-sudo.5.xml:12 #: sssd-idp.5.xml:12 sssd-krb5.5.xml:12 sssd-ifp.5.xml:12 #: sss_rpcidmapd.5.xml:28 sssd-session-recording.5.xml:12 sssd-kcm.8.xml:12 @@ -53,17 +53,17 @@ msgid "File Formats and Conventions" msgstr "Formatos de arquivo e convenções" #. type: Content of: <reference><refentry><refnamediv><refpurpose> -#: sssd.conf.5.xml:20 +#: sssd.conf.5.xml:22 msgid "the configuration file for SSSD" msgstr "O arquivo de configuração para SSSD" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:24 +#: sssd.conf.5.xml:26 msgid "FILE FORMAT" msgstr "FORMATO DO ARQUIVO" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd.conf.5.xml:32 +#: sssd.conf.5.xml:34 #, no-wrap msgid "" "<replaceable>[section]</replaceable>\n" @@ -73,7 +73,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:27 +#: sssd.conf.5.xml:29 msgid "" "The file has an ini-style syntax and consists of sections and parameters. A " "section begins with the name of the section in square brackets and continues " @@ -82,47 +82,50 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:39 +#: sssd.conf.5.xml:41 msgid "" -"The data types used are string (no quotes needed), integer and bool (with " -"values of <quote>TRUE/FALSE</quote>)." +"The data types used are string (no quotes needed), integer and boolean (with " +"values of <quote>TRUE/FALSE</quote>). Boolean values are case-insensitive; " +"for example, <quote>TRUE</quote>, <quote>True</quote> and <quote>true</" +"quote> are all equivalent and valid; the same applies to <quote>FALSE</" +"quote>." msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:44 +#: sssd.conf.5.xml:49 msgid "" "A comment line starts with a hash sign (<quote>#</quote>) or a semicolon " "(<quote>;</quote>). Inline comments are not supported." msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:50 +#: sssd.conf.5.xml:55 msgid "" "All sections can have an optional <replaceable>description</replaceable> " "parameter. Its function is only as a label for the section." msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:56 +#: sssd.conf.5.xml:61 msgid "" "<filename>sssd.conf</filename> must be a regular file that is owned, " "readable, and writeable only by 'root'." msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:60 +#: sssd.conf.5.xml:65 msgid "" "<filename>sssd.conf</filename> must be a regular file that is accessible " "only by the user used to run SSSD service or root." msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:66 +#: sssd.conf.5.xml:71 msgid "CONFIGURATION SNIPPETS FROM INCLUDE DIRECTORY" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:69 +#: sssd.conf.5.xml:74 msgid "" "The configuration file <filename>sssd.conf</filename> will include " "configuration snippets using the include directory <filename>conf.d</" @@ -130,7 +133,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:75 +#: sssd.conf.5.xml:80 msgid "" "Any file placed in <filename>conf.d</filename> that ends in " "<quote><filename>.conf</filename></quote> and does not begin with a dot " @@ -139,7 +142,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:83 +#: sssd.conf.5.xml:88 msgid "" "The configuration snippets from <filename>conf.d</filename> have higher " "priority than <filename>sssd.conf</filename> and will override " @@ -152,39 +155,88 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:97 +#: sssd.conf.5.xml:102 msgid "" "The snippet files require the same owner and permissions as " "<filename>sssd.conf</filename>." msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:103 +#: sssd.conf.5.xml:108 +msgid "VENDOR PROVIDED CONFIGURATION" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:111 +msgid "" +"The vendor provided configuration file is installed in " +"<filename>&sssd_vendor_dir;/sssd.conf</filename>, but this file must not be " +"directly edited. It can be completely masked by creating the system specific " +"configuration file <filename>&sssd_conf_dir;/sssd.conf</filename>, or partly " +"overriden by creating config snippets in <filename>&sssd_conf_dir;/conf.d</" +"filename> directory." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><title> +#: sssd.conf.5.xml:120 +msgid "CONFIGURATION FILE HIERARCHY" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:122 +msgid "" +"When sssd reads the configuration it first tries to open the system specific " +"configuration file in <filename>&sssd_conf_dir;/sssd.conf</filename>. If it " +"exists, it is loaded and snippets from <filename>&sssd_conf_dir;/conf.d</" +"filename> are applied. The vendor provided configuration file " +"<filename>&sssd_vendor_dir;/sssd.conf</filename> is completely ignored in " +"this case." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:131 +msgid "" +"If the system specific configuration file <filename>&sssd_conf_dir;/" +"sssd.conf</filename> does not exist, then the vendor configuration file " +"<filename>&sssd_vendor_dir;/sssd.conf</filename> is loaded and snippets from " +"<filename>&sssd_conf_dir;/conf.d</filename> are applied." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd.conf.5.xml:141 msgid "GENERAL OPTIONS" msgstr "OPÇÕES GERAIS" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:105 +#: sssd.conf.5.xml:143 msgid "Following options are usable in more than one configuration sections." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:109 +#: sssd.conf.5.xml:147 msgid "Options usable in all sections" msgstr "" +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:149 +msgid "" +"Note: Below options are ignored in <quote>[session_recording]</quote> " +"section, see <quote>Session recording configuration options</quote> section " +"for more details." +msgstr "" + #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:113 +#: sssd.conf.5.xml:156 msgid "debug_level (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:117 +#: sssd.conf.5.xml:160 msgid "debug (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:120 +#: sssd.conf.5.xml:163 msgid "" "SSSD 1.14 and later also includes the <replaceable>debug</replaceable> alias " "for <replaceable>debug_level</replaceable> as a convenience feature. If both " @@ -193,61 +245,61 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:130 -msgid "debug_timestamps (bool)" +#: sssd.conf.5.xml:173 +msgid "debug_timestamps (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:133 +#: sssd.conf.5.xml:176 msgid "" "Add a timestamp to the debug messages. If journald is enabled for SSSD " "debug logging this option is ignored." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:138 sssd.conf.5.xml:175 sssd.conf.5.xml:337 -#: sssd.conf.5.xml:644 sssd.conf.5.xml:668 sssd.conf.5.xml:875 -#: sssd.conf.5.xml:979 sssd.conf.5.xml:2113 sssd-ldap.5.xml:979 -#: sssd-ldap.5.xml:1134 sssd-ldap.5.xml:1237 sssd-ldap.5.xml:1306 -#: sssd-ldap.5.xml:1714 sssd-ldap.5.xml:1848 sssd-ldap.5.xml:1913 -#: sssd-ipa.5.xml:346 sssd-ad.5.xml:252 sssd-ad.5.xml:367 sssd-ad.5.xml:1180 -#: sssd-ad.5.xml:1382 sssd-krb5.5.xml:358 +#: sssd.conf.5.xml:181 sssd.conf.5.xml:218 sssd.conf.5.xml:380 +#: sssd.conf.5.xml:687 sssd.conf.5.xml:711 sssd.conf.5.xml:827 +#: sssd.conf.5.xml:932 sssd.conf.5.xml:2149 sssd.conf.5.xml:4730 +#: sssd-ldap.5.xml:979 sssd-ldap.5.xml:1134 sssd-ldap.5.xml:1237 +#: sssd-ldap.5.xml:1306 sssd-ldap.5.xml:1714 sssd-ldap.5.xml:1848 +#: sssd-ldap.5.xml:1913 sssd-ipa.5.xml:341 sssd-ad.5.xml:252 sssd-ad.5.xml:367 +#: sssd-ad.5.xml:1180 sssd-ad.5.xml:1375 sssd-krb5.5.xml:358 msgid "Default: true" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:143 -msgid "debug_microseconds (bool)" +#: sssd.conf.5.xml:186 +msgid "debug_microseconds (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:146 +#: sssd.conf.5.xml:189 msgid "" "Add microseconds to the timestamp in debug messages. If journald is enabled " "for SSSD debug logging this option is ignored." msgstr "" #. type: Content of: <variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:151 sssd.conf.5.xml:2040 sssd.conf.5.xml:4158 +#: sssd.conf.5.xml:194 sssd.conf.5.xml:2072 sssd.conf.5.xml:4363 #: sssd-ldap.5.xml:363 sssd-ldap.5.xml:998 sssd-ldap.5.xml:1209 -#: sssd-ldap.5.xml:1663 sssd-ldap.5.xml:1937 sssd-ipa.5.xml:146 -#: sssd-ipa.5.xml:706 sssd-ad.5.xml:1135 sssd-krb5.5.xml:268 +#: sssd-ldap.5.xml:1663 sssd-ldap.5.xml:1937 sssd-ipa.5.xml:141 +#: sssd-ipa.5.xml:701 sssd-ad.5.xml:1140 sssd-idp.5.xml:287 sssd-krb5.5.xml:268 #: sssd-krb5.5.xml:330 sssd-krb5.5.xml:432 include/krb5_options.xml:163 msgid "Default: false" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:156 -msgid "debug_backtrace_enabled (bool)" +#: sssd.conf.5.xml:199 +msgid "debug_backtrace_enabled (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:159 +#: sssd.conf.5.xml:202 msgid "Enable debug backtrace." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:162 +#: sssd.conf.5.xml:205 msgid "" "In case SSSD is run with debug_level less than 9, everything is logged to a " "ring buffer in memory and flushed to a log file on any error up to and " @@ -257,14 +309,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:171 +#: sssd.conf.5.xml:214 msgid "" "Feature is only supported for `logger == files` (i.e. setting doesn't have " "effect for other logger types)." msgstr "" #. type: Content of: outside any tag (error?) -#: sssd.conf.5.xml:111 sssd.conf.5.xml:186 sssd-ldap.5.xml:1754 +#: sssd.conf.5.xml:154 sssd.conf.5.xml:229 sssd-ldap.5.xml:1754 #: sssd-ldap.5.xml:1960 sss-certmap.5.xml:645 sssd-systemtap.5.xml:82 #: sssd-systemtap.5.xml:143 sssd-systemtap.5.xml:236 sssd-systemtap.5.xml:274 #: sssd-systemtap.5.xml:330 sssd-ldap-attributes.5.xml:40 @@ -277,17 +329,17 @@ msgid "<placeholder type=\"variablelist\" id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:184 +#: sssd.conf.5.xml:227 msgid "Options usable in SERVICE and DOMAIN sections" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:188 +#: sssd.conf.5.xml:231 msgid "timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:191 +#: sssd.conf.5.xml:234 msgid "" "Timeout in seconds between heartbeats for this service. This is used to " "ensure that the process is alive and capable of answering requests. Note " @@ -295,34 +347,34 @@ msgid "" msgstr "" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:198 sssd.conf.5.xml:1199 sssd.conf.5.xml:1673 -#: sssd.conf.5.xml:4174 sssd-ldap.5.xml:825 sssd-idp.5.xml:192 +#: sssd.conf.5.xml:241 sssd.conf.5.xml:1155 sssd.conf.5.xml:1665 +#: sssd.conf.5.xml:4379 sssd-ldap.5.xml:825 sssd-idp.5.xml:271 #: include/ldap_id_mapping.xml:270 msgid "Default: 10" msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:208 +#: sssd.conf.5.xml:251 msgid "SPECIAL SECTIONS" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:211 +#: sssd.conf.5.xml:254 msgid "The [sssd] section" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><title> -#: sssd.conf.5.xml:220 +#: sssd.conf.5.xml:263 msgid "Section parameters" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:222 -msgid "services" +#: sssd.conf.5.xml:265 +msgid "services (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:225 +#: sssd.conf.5.xml:268 msgid "" "Comma separated list of services that are started when sssd itself starts. " "<phrase condition=\"have_systemd\"> The services' list is optional on " @@ -331,7 +383,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:234 +#: sssd.conf.5.xml:277 msgid "" "Supported services: nss, pam, ifp <phrase condition=\"with_sudo\">, sudo</" "phrase> <phrase condition=\"with_autofs\">, autofs</phrase> <phrase " @@ -340,20 +392,20 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:241 +#: sssd.conf.5.xml:284 msgid "" "<phrase condition=\"have_systemd\"> By default, all services are disabled " "and the administrator must enable the ones allowed to be used by executing: " "\"systemctl enable sssd-@service@.socket\". </phrase>" msgstr "" -#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:250 -msgid "domains" +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sssd.conf.5.xml:293 sssd.conf.5.xml:4562 +msgid "domains (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:253 +#: sssd.conf.5.xml:296 msgid "" "A domain is a database containing user information. SSSD can use more " "domains at the same time, but at least one must be configured or SSSD won't " @@ -364,19 +416,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:266 sssd.conf.5.xml:3467 +#: sssd.conf.5.xml:309 sssd.conf.5.xml:3598 msgid "re_expression (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:269 +#: sssd.conf.5.xml:312 msgid "" "Default regular expression that describes how to parse the string containing " "user name and domain into these components." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:274 +#: sssd.conf.5.xml:317 msgid "" "Each domain can have an individual regular expression configured. For some " "ID providers there are also default regular expressions. See DOMAIN SECTIONS " @@ -384,12 +436,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:283 sssd.conf.5.xml:3524 +#: sssd.conf.5.xml:326 sssd.conf.5.xml:3655 msgid "full_name_format (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:286 sssd.conf.5.xml:3527 +#: sssd.conf.5.xml:329 sssd.conf.5.xml:3658 msgid "" "A <citerefentry> <refentrytitle>printf</refentrytitle> <manvolnum>3</" "manvolnum> </citerefentry>-compatible format that describes how to compose a " @@ -397,70 +449,72 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:297 sssd.conf.5.xml:3538 +#: sssd.conf.5.xml:340 sssd.conf.5.xml:3669 msgid "%1$s" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:298 sssd.conf.5.xml:3539 +#: sssd.conf.5.xml:341 sssd.conf.5.xml:3670 msgid "user name" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:301 sssd.conf.5.xml:3542 +#: sssd.conf.5.xml:344 sssd.conf.5.xml:3673 msgid "%2$s" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:304 sssd.conf.5.xml:3545 +#: sssd.conf.5.xml:347 sssd.conf.5.xml:3676 msgid "domain name as specified in the SSSD config file." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:310 sssd.conf.5.xml:3551 +#: sssd.conf.5.xml:353 sssd.conf.5.xml:3682 msgid "%3$s" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:313 sssd.conf.5.xml:3554 +#: sssd.conf.5.xml:356 sssd.conf.5.xml:3685 msgid "" "domain flat name. Mostly usable for Active Directory domains, both directly " "configured or discovered via IPA trusts." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:294 sssd.conf.5.xml:3535 +#: sssd.conf.5.xml:337 sssd.conf.5.xml:3666 msgid "" "The following expansions are supported: <placeholder type=\"variablelist\" " "id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:323 +#: sssd.conf.5.xml:366 msgid "" "Each domain can have an individual format string configured. See DOMAIN " "SECTIONS for more info on this option." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:329 +#: sssd.conf.5.xml:372 msgid "monitor_resolv_conf (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:332 +#: sssd.conf.5.xml:375 msgid "" "Controls if SSSD should monitor the state of resolv.conf to identify when it " "needs to update its internal DNS resolver." msgstr "" +"Controla se SSSD deve monitorar o estado de resolv.conf para identificar " +"quando ele precisa atualizar seu resolvedor interno de DNS." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:342 +#: sssd.conf.5.xml:385 msgid "try_inotify (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:345 +#: sssd.conf.5.xml:388 msgid "" "By default, SSSD will attempt to use inotify to monitor configuration files " "changes and will fall back to polling every five seconds if inotify cannot " @@ -468,7 +522,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:351 +#: sssd.conf.5.xml:394 msgid "" "There are some limited situations where it is preferred that we should skip " "even trying to use inotify. In these rare cases, this option should be set " @@ -476,59 +530,61 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:357 +#: sssd.conf.5.xml:400 msgid "" "Default: true on platforms where inotify is supported. False on other " "platforms." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:361 +#: sssd.conf.5.xml:404 msgid "" "Note: this option will have no effect on platforms where inotify is " "unavailable. On these platforms, polling will always be used." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:368 +#: sssd.conf.5.xml:411 msgid "krb5_rcache_dir (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:371 +#: sssd.conf.5.xml:414 msgid "" "Directory on the filesystem where SSSD should store Kerberos replay cache " "files." msgstr "" +"Diretório no sistema de arquivos no qual SSSD deve armazenar arquivos cache " +"de reprodução de Kerberos." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:375 +#: sssd.conf.5.xml:418 msgid "" "This option accepts a special value __LIBKRB5_DEFAULTS__ that will instruct " "SSSD to let libkrb5 decide the appropriate location for the replay cache." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:381 +#: sssd.conf.5.xml:424 msgid "" "Default: Distribution-specific and specified at build-time. " "(__LIBKRB5_DEFAULTS__ if not configured)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:388 +#: sssd.conf.5.xml:431 msgid "default_domain_suffix (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:391 +#: sssd.conf.5.xml:434 msgid "" "Please note that this option is deprecated and domain_resolution_order " "should be used." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:395 +#: sssd.conf.5.xml:438 msgid "" "This string will be used as a default domain name for all names without a " "domain name component. The main use case is environments where the primary " @@ -538,7 +594,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:405 +#: sssd.conf.5.xml:448 msgid "" "Please note that if this option is set all users from the primary domain " "have to use their fully qualified name, e.g. user@domain.name, to log in. " @@ -548,21 +604,21 @@ msgid "" msgstr "" #. type: Content of: <variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:414 sssd-ldap.5.xml:937 sssd-ldap.5.xml:949 -#: sssd-ldap.5.xml:1042 sssd-ad.5.xml:921 sssd-ad.5.xml:996 sssd-krb5.5.xml:468 -#: sssd-ldap-attributes.5.xml:470 sssd-ldap-attributes.5.xml:978 -#: include/ldap_id_mapping.xml:211 include/ldap_id_mapping.xml:222 -#: include/krb5_options.xml:148 +#: sssd.conf.5.xml:457 sssd.conf.5.xml:2006 sssd-ldap.5.xml:937 +#: sssd-ldap.5.xml:949 sssd-ldap.5.xml:1042 sssd-ad.5.xml:926 +#: sssd-ad.5.xml:1001 sssd-krb5.5.xml:468 sssd-ldap-attributes.5.xml:470 +#: sssd-ldap-attributes.5.xml:978 include/ldap_id_mapping.xml:211 +#: include/ldap_id_mapping.xml:222 include/krb5_options.xml:148 msgid "Default: not set" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:419 +#: sssd.conf.5.xml:462 msgid "override_space (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:422 +#: sssd.conf.5.xml:465 msgid "" "This parameter will replace spaces (space bar) with the given character for " "user and group names. e.g. (_). User name "john doe" will be " @@ -572,7 +628,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:431 +#: sssd.conf.5.xml:474 msgid "" "Please note it is a configuration error to use a replacement character that " "might be used in user or group names. If a name contains the replacement " @@ -581,22 +637,22 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:439 +#: sssd.conf.5.xml:482 msgid "Default: not set (spaces will not be replaced)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:444 +#: sssd.conf.5.xml:487 msgid "certificate_verification (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:452 +#: sssd.conf.5.xml:495 msgid "no_ocsp" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:454 +#: sssd.conf.5.xml:497 msgid "" "Disables Online Certificate Status Protocol (OCSP) checks. This might be " "needed if the OCSP servers defined in the certificate are not reachable from " @@ -604,12 +660,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:462 +#: sssd.conf.5.xml:505 msgid "soft_ocsp" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:464 +#: sssd.conf.5.xml:507 msgid "" "If a connection cannot be established to an OCSP responder the OCSP check is " "skipped. This option should be used to allow authentication when the system " @@ -617,61 +673,61 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:474 +#: sssd.conf.5.xml:517 msgid "ocsp_dgst" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:476 +#: sssd.conf.5.xml:519 msgid "" "Digest (hash) function used to create the certificate ID for the OCSP " "request. Allowed values are:" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:480 +#: sssd.conf.5.xml:523 msgid "sha1" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:481 +#: sssd.conf.5.xml:524 msgid "sha256" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:482 +#: sssd.conf.5.xml:525 msgid "sha384" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:483 +#: sssd.conf.5.xml:526 msgid "sha512" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:486 +#: sssd.conf.5.xml:529 msgid "Default: sha1 (to allow compatibility with RFC5019-compliant responder)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:492 +#: sssd.conf.5.xml:535 msgid "no_verification" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:494 +#: sssd.conf.5.xml:537 msgid "" "Disables verification completely. This option should only be used for " "testing." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:500 +#: sssd.conf.5.xml:543 msgid "partial_chain" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:502 +#: sssd.conf.5.xml:545 msgid "" "Allow verification to succeed even if a <replaceable>complete</replaceable> " "chain cannot be built to a self-signed trust-anchor, provided it is possible " @@ -679,12 +735,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:511 +#: sssd.conf.5.xml:554 msgid "ocsp_default_responder=URL" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:513 +#: sssd.conf.5.xml:556 msgid "" "Sets the OCSP default responder which should be used instead of the one " "mentioned in the certificate. URL must be replaced with the URL of the OCSP " @@ -692,24 +748,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:523 +#: sssd.conf.5.xml:566 msgid "ocsp_default_responder_signing_cert=NAME" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:525 +#: sssd.conf.5.xml:568 msgid "" "This option is currently ignored. All needed certificates must be available " "in the PEM file given by pam_cert_db_path." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:533 +#: sssd.conf.5.xml:576 msgid "crl_file=/PATH/TO/CRL/FILE" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:535 +#: sssd.conf.5.xml:578 msgid "" "Use the Certificate Revocation List (CRL) from the given file during the " "verification of the certificate. The CRL must be given in PEM format, see " @@ -718,12 +774,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:548 +#: sssd.conf.5.xml:591 msgid "soft_crl" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:551 +#: sssd.conf.5.xml:594 msgid "" "If a Certificate Revocation List (CRL) is expired ignore the expiration " "time of the CRL and check the related certificates with the expired CRL. " @@ -732,7 +788,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:447 +#: sssd.conf.5.xml:490 msgid "" "With this parameter the certificate verification can be tuned with a comma " "separated list of options. Supported options are: <placeholder " @@ -740,46 +796,46 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:564 +#: sssd.conf.5.xml:607 msgid "Unknown options are reported but ignored." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:567 +#: sssd.conf.5.xml:610 msgid "Default: not set, i.e. do not restrict certificate verification" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:573 +#: sssd.conf.5.xml:616 msgid "disable_netlink (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:576 +#: sssd.conf.5.xml:619 msgid "" "SSSD hooks into the netlink interface to monitor changes to routes, " "addresses, links and trigger certain actions." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:581 +#: sssd.conf.5.xml:624 msgid "" "The SSSD state changes caused by netlink events may be undesirable and can " "be disabled by setting this option to 'true'" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:586 +#: sssd.conf.5.xml:629 msgid "Default: false (netlink changes are detected)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:591 -msgid "domain_resolution_order" +#: sssd.conf.5.xml:634 +msgid "domain_resolution_order (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:594 +#: sssd.conf.5.xml:637 msgid "" "Comma separated list of domains and subdomains representing the lookup order " "that will be followed. The list doesn't have to include all possible " @@ -790,7 +846,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:606 +#: sssd.conf.5.xml:649 msgid "" "Please, note that when this option is set the output format of all commands " "is always fully-qualified even when using short names for input. In case " @@ -806,19 +862,20 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:630 sssd.conf.5.xml:1697 sssd.conf.5.xml:4224 -#: sssd-ad.5.xml:187 sssd-ad.5.xml:328 sssd-ad.5.xml:342 sssd-idp.5.xml:108 -#: sssd-idp.5.xml:132 sssd-idp.5.xml:145 sssd-idp.5.xml:159 sssd-idp.5.xml:180 +#: sssd.conf.5.xml:673 sssd.conf.5.xml:1026 sssd.conf.5.xml:1689 +#: sssd.conf.5.xml:4429 sssd-ad.5.xml:187 sssd-ad.5.xml:328 sssd-ad.5.xml:342 +#: sssd-idp.5.xml:112 sssd-idp.5.xml:136 sssd-idp.5.xml:149 sssd-idp.5.xml:167 +#: sssd-idp.5.xml:188 msgid "Default: Not set" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:635 +#: sssd.conf.5.xml:678 msgid "implicit_pac_responder (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:638 +#: sssd.conf.5.xml:681 msgid "" "The PAC responder is enabled automatically for the IPA and AD provider to " "evaluate and check the PAC. If it has to be disabled set this option to " @@ -826,12 +883,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:649 +#: sssd.conf.5.xml:692 msgid "core_dumpable (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:652 +#: sssd.conf.5.xml:695 msgid "" "This option can be used for general system hardening: setting it to 'false' " "forbids core dumps for all SSSD processes to avoid leaking plain text " @@ -840,7 +897,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:660 +#: sssd.conf.5.xml:703 msgid "" "Take a note that this setting has no effect for 'ldap_child', 'krb5_child' " "and 'sssd_pam' as those privileged binaries can have a copy of a host keytab " @@ -849,24 +906,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:673 +#: sssd.conf.5.xml:716 msgid "passkey_verification (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:681 +#: sssd.conf.5.xml:724 msgid "user_verification (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:683 +#: sssd.conf.5.xml:726 msgid "" "Enable or disable the user verification (i.e. PIN, fingerprint) during " "authentication. If enabled, the PIN will always be requested." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:689 +#: sssd.conf.5.xml:732 msgid "" "The default is that the key settings decide what to do. In the IPA or " "kerberos pre-authentication case, this value will be overwritten by the " @@ -874,7 +931,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:676 +#: sssd.conf.5.xml:719 msgid "" "With this parameter the passkey verification can be tuned with a comma " "separated list of options. Supported options are: <placeholder " @@ -882,7 +939,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:213 +#: sssd.conf.5.xml:256 msgid "" "Individual pieces of SSSD functionality are provided by special SSSD " "services that are started and stopped together with SSSD. The services are " @@ -893,12 +950,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:708 +#: sssd.conf.5.xml:751 msgid "SERVICES SECTIONS" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:710 +#: sssd.conf.5.xml:753 msgid "" "Settings that can be used to configure different services are described in " "this section. They should reside in the [<replaceable>$NAME</replaceable>] " @@ -907,42 +964,41 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:717 +#: sssd.conf.5.xml:760 msgid "General service configuration options" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:719 +#: sssd.conf.5.xml:762 msgid "These options can be used to configure any service." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:723 -msgid "fd_limit" +#: sssd.conf.5.xml:766 +msgid "fd_limit (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:726 +#: sssd.conf.5.xml:769 msgid "" "This option specifies the maximum number of file descriptors that may be " -"opened at one time by this SSSD process. On systems where SSSD is granted " -"the CAP_SYS_RESOURCE capability, this will be an absolute setting. On " -"systems without this capability, the resulting value will be the lower value " -"of this or the limits.conf \"hard\" limit." +"opened at one time by this SSSD process. Note this value will be capped by " +"the init system at the startup of SSSD, see e.g. man systemd.exec for " +"details." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:735 +#: sssd.conf.5.xml:776 msgid "Default: 8192 (or limits.conf \"hard\" limit)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:740 -msgid "client_idle_timeout" +#: sssd.conf.5.xml:781 +msgid "client_idle_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:743 +#: sssd.conf.5.xml:784 msgid "" "This option specifies the number of seconds that a client of an SSSD process " "can hold onto a file descriptor without communicating on it. This value is " @@ -952,140 +1008,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:752 +#: sssd.conf.5.xml:793 msgid "Default: 60, KCM: 300" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:757 -msgid "offline_timeout (integer)" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:760 -msgid "" -"When SSSD switches to offline mode the amount of time before it tries to go " -"back online will increase based upon the time spent disconnected. By " -"default SSSD uses incremental behaviour to calculate delay in between " -"retries. So, the wait time for a given retry will be longer than the wait " -"time for the previous ones. After each unsuccessful attempt to go online, " -"the new interval is recalculated by the following:" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:771 sssd.conf.5.xml:827 -msgid "" -"new_delay = Minimum(old_delay * 2, offline_timeout_max) + " -"random[0...offline_timeout_random_offset]" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:774 -msgid "" -"The offline_timeout default value is 60. The offline_timeout_max default " -"value is 3600. The offline_timeout_random_offset default value is 30. The " -"end result is amount of seconds before next retry." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:780 -msgid "" -"Note that the maximum length of each interval is defined by " -"offline_timeout_max (apart of random part)." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:784 sssd.conf.5.xml:1110 sssd.conf.5.xml:1490 -#: sssd.conf.5.xml:1791 sssd-ldap.5.xml:550 -msgid "Default: 60" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:789 -msgid "offline_timeout_max (integer)" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:792 -msgid "" -"Controls by how much the time between attempts to go online can be " -"incremented following unsuccessful attempts to go online." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:797 -msgid "A value of 0 disables the incrementing behaviour." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:800 -msgid "" -"The value of this parameter should be set in correlation to offline_timeout " -"parameter value." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:804 -msgid "" -"With offline_timeout set to 60 (default value) there is no point in setting " -"offlinet_timeout_max to less than 120 as it will saturate instantly. General " -"rule here should be to set offline_timeout_max to at least 4 times " -"offline_timeout." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:810 -msgid "" -"Although a value between 0 and offline_timeout may be specified, it has the " -"effect of overriding the offline_timeout value so is of little use." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:815 -msgid "Default: 3600" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:820 -msgid "offline_timeout_random_offset (integer)" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:823 -msgid "" -"When SSSD is in offline mode it keeps probing backend servers in specified " -"time intervals:" +#: sssd.conf.5.xml:798 +msgid "responder_idle_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:830 -msgid "" -"This parameter controls the value of the random offset used for the above " -"equation. Final random_offset value will be random number in range:" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:835 -msgid "[0 - offline_timeout_random_offset]" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:838 -msgid "A value of 0 disables the random offset addition." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:841 -msgid "Default: 30" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:846 -msgid "responder_idle_timeout" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:849 +#: sssd.conf.5.xml:801 msgid "" "This option specifies the number of seconds that an SSSD responder process " "can be up without being used. This value is limited in order to avoid " @@ -1097,66 +1030,70 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:863 sssd.conf.5.xml:1123 sssd.conf.5.xml:2248 +#: sssd.conf.5.xml:815 sssd.conf.5.xml:1079 sssd.conf.5.xml:2285 #: sssd-ldap.5.xml:377 msgid "Default: 300" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:868 -msgid "cache_first" +#: sssd.conf.5.xml:820 +msgid "cache_first (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:871 +#: sssd.conf.5.xml:823 msgid "" "This option specifies whether the responder should query all caches before " "querying the Data Providers." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:883 +#: sssd.conf.5.xml:835 msgid "NSS configuration options" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:885 +#: sssd.conf.5.xml:837 msgid "" -"These options can be used to configure the Name Service Switch (NSS) service." +"These options can be used to configure the Name Service Switch (NSS) service " +"and should be specified under the <quote>[nss]</quote> section." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:890 +#: sssd.conf.5.xml:843 msgid "enum_cache_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:893 +#: sssd.conf.5.xml:846 msgid "" "How many seconds should nss_sss cache enumerations (requests for info about " "all users)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:897 +#: sssd.conf.5.xml:850 msgid "Default: 120" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:902 +#: sssd.conf.5.xml:855 msgid "entry_cache_nowait_percentage (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:905 +#: sssd.conf.5.xml:858 msgid "" "The entry cache can be set to automatically update entries in the background " "if they are requested beyond a percentage of the entry_cache_timeout value " "for the domain." msgstr "" +"O cache de entrada pode ser definido para atualizar automaticamente entradas " +"em segundo plano se elas forem solicitadas além de uma porcentagem do valor " +"entry_cache_timeout para o domínio." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:911 +#: sssd.conf.5.xml:864 msgid "" "For example, if the domain's entry_cache_timeout is set to 30s and " "entry_cache_nowait_percentage is set to 50 (percent), entries that come in " @@ -1166,7 +1103,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:921 +#: sssd.conf.5.xml:874 msgid "" "Valid values for this option are 0-99 and represent a percentage of the " "entry_cache_timeout for each domain. For performance reasons, this " @@ -1175,17 +1112,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:929 sssd.conf.5.xml:2061 +#: sssd.conf.5.xml:882 sssd.conf.5.xml:2093 msgid "Default: 50" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:934 +#: sssd.conf.5.xml:887 msgid "entry_negative_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:937 +#: sssd.conf.5.xml:890 msgid "" "Specifies for how many seconds nss_sss should cache negative cache hits " "(that is, queries for invalid database entries, like nonexistent ones) " @@ -1193,17 +1130,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:943 sssd.conf.5.xml:1685 sssd.conf.5.xml:2085 +#: sssd.conf.5.xml:896 sssd.conf.5.xml:1677 sssd.conf.5.xml:2119 msgid "Default: 15" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:948 +#: sssd.conf.5.xml:901 msgid "filter_users, filter_groups (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:951 +#: sssd.conf.5.xml:904 msgid "" "Exclude certain users or groups from being fetched from the sss NSS " "database. This is particularly useful for system accounts. This option can " @@ -1212,7 +1149,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:959 +#: sssd.conf.5.xml:912 msgid "" "NOTE: The filter_groups option doesn't affect inheritance of nested group " "members, since filtering happens after they are propagated for returning via " @@ -1221,41 +1158,41 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:967 +#: sssd.conf.5.xml:920 msgid "Default: root" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:972 -msgid "filter_users_in_groups (bool)" +#: sssd.conf.5.xml:925 +msgid "filter_users_in_groups (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:975 +#: sssd.conf.5.xml:928 msgid "" -"If you want filtered user still be group members set this option to false." +"If you want filtered users to remain group members set this option to false" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:986 +#: sssd.conf.5.xml:939 msgid "fallback_homedir (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:989 +#: sssd.conf.5.xml:942 msgid "" "Set a default template for a user's home directory if one is not specified " "explicitly by the domain's data provider." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:994 +#: sssd.conf.5.xml:947 msgid "" "The available values for this option are the same as for override_homedir." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1000 +#: sssd.conf.5.xml:953 #, no-wrap msgid "" "fallback_homedir = /home/%u\n" @@ -1263,23 +1200,23 @@ msgid "" msgstr "" #. type: Content of: <varlistentry><listitem><para> -#: sssd.conf.5.xml:998 sssd.conf.5.xml:1557 sssd.conf.5.xml:1576 -#: sssd.conf.5.xml:1653 sssd-krb5.5.xml:451 include/override_homedir.xml:78 +#: sssd.conf.5.xml:951 sssd.conf.5.xml:1524 sssd.conf.5.xml:1543 +#: sssd.conf.5.xml:1645 sssd-krb5.5.xml:451 include/override_homedir.xml:78 msgid "example: <placeholder type=\"programlisting\" id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1004 +#: sssd.conf.5.xml:957 msgid "Default: not set (no substitution for unset home directories)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1010 +#: sssd.conf.5.xml:963 msgid "override_shell (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1013 +#: sssd.conf.5.xml:966 msgid "" "Override the login shell for all users. This option supersedes any other " "shell options if it takes effect and can be set either in the [nss] section " @@ -1287,47 +1224,47 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1019 +#: sssd.conf.5.xml:972 msgid "Default: not set (SSSD will use the value retrieved from LDAP)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1025 +#: sssd.conf.5.xml:978 msgid "allowed_shells (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1028 +#: sssd.conf.5.xml:981 msgid "" "Restrict user shell to one of the listed values. The order of evaluation is:" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1031 +#: sssd.conf.5.xml:984 msgid "1. If the shell is present in <quote>/etc/shells</quote>, it is used." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1035 +#: sssd.conf.5.xml:988 msgid "" "2. If the shell is in the allowed_shells list but not in <quote>/etc/shells</" "quote>, use the value of the shell_fallback parameter." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1040 +#: sssd.conf.5.xml:993 msgid "" "3. If the shell is not in the allowed_shells list and not in <quote>/etc/" "shells</quote>, a nologin shell is used." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1045 +#: sssd.conf.5.xml:998 msgid "The wildcard (*) can be used to allow any shell." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1048 +#: sssd.conf.5.xml:1001 msgid "" "The (*) is useful if you want to use shell_fallback in case that user's " "shell is not in <quote>/etc/shells</quote> and maintaining list of all " @@ -1335,113 +1272,121 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1055 +#: sssd.conf.5.xml:1008 msgid "An empty string for shell is passed as-is to libc." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1058 +#: sssd.conf.5.xml:1011 msgid "" "The <quote>/etc/shells</quote> is only read on SSSD start up, which means " "that a restart of the SSSD is required in case a new shell is installed." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1062 +#: sssd.conf.5.xml:1015 msgid "Default: Not set. The user shell is automatically used." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1067 +#: sssd.conf.5.xml:1020 msgid "vetoed_shells (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1070 +#: sssd.conf.5.xml:1023 msgid "Replace any instance of these shells with the shell_fallback" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1075 +#: sssd.conf.5.xml:1031 msgid "shell_fallback (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1078 +#: sssd.conf.5.xml:1034 msgid "" "The default shell to use if an allowed shell is not installed on the machine." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1082 +#: sssd.conf.5.xml:1038 msgid "Default: /bin/sh" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1087 -msgid "default_shell" +#: sssd.conf.5.xml:1043 +msgid "default_shell (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1090 +#: sssd.conf.5.xml:1046 msgid "" "The default shell to use if the provider does not return one during lookup. " "This option can be specified globally in the [nss] section or per-domain." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1096 +#: sssd.conf.5.xml:1052 msgid "" "Default: not set (Return NULL if no shell is specified and rely on libc to " "substitute something sensible when necessary, usually /bin/sh)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1103 sssd.conf.5.xml:1483 +#: sssd.conf.5.xml:1059 sssd.conf.5.xml:1450 msgid "get_domains_timeout (int)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1106 sssd.conf.5.xml:1486 +#: sssd.conf.5.xml:1062 sssd.conf.5.xml:1453 msgid "" "Specifies time in seconds for which the list of subdomains will be " "considered valid." msgstr "" +"Especifica o tempo em segundos pelo qual a lista de subdomínios será " +"considerada válida." + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1066 sssd.conf.5.xml:1457 sssd.conf.5.xml:1788 +#: sssd.conf.5.xml:2862 sssd-ldap.5.xml:550 +msgid "Default: 60" +msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1115 +#: sssd.conf.5.xml:1071 msgid "memcache_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1118 +#: sssd.conf.5.xml:1074 msgid "" "Specifies time in seconds for which records in the in-memory cache will be " "valid. Setting this option to zero will disable the in-memory cache." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1126 +#: sssd.conf.5.xml:1082 msgid "" "WARNING: Disabling the in-memory cache will have significant negative impact " "on SSSD's performance and should only be used for testing." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1132 sssd.conf.5.xml:1157 sssd.conf.5.xml:1182 -#: sssd.conf.5.xml:1207 sssd.conf.5.xml:1234 +#: sssd.conf.5.xml:1088 sssd.conf.5.xml:1113 sssd.conf.5.xml:1138 +#: sssd.conf.5.xml:1163 sssd.conf.5.xml:1190 msgid "" "NOTE: If the environment variable SSS_NSS_USE_MEMCACHE is set to \"NO\", " "client applications will not use the fast in-memory cache." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1140 +#: sssd.conf.5.xml:1096 msgid "memcache_size_passwd (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1143 +#: sssd.conf.5.xml:1099 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for passwd requests. Setting the size to 0 will disable the passwd in-" @@ -1449,25 +1394,25 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1149 sssd.conf.5.xml:2888 sssd-ldap.5.xml:604 +#: sssd.conf.5.xml:1105 sssd.conf.5.xml:3013 sssd-ldap.5.xml:604 msgid "Default: 8" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1152 sssd.conf.5.xml:1177 sssd.conf.5.xml:1202 -#: sssd.conf.5.xml:1229 +#: sssd.conf.5.xml:1108 sssd.conf.5.xml:1133 sssd.conf.5.xml:1158 +#: sssd.conf.5.xml:1185 msgid "" "WARNING: Disabled or too small in-memory cache can have significant negative " "impact on SSSD's performance." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1165 +#: sssd.conf.5.xml:1121 msgid "memcache_size_group (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1168 +#: sssd.conf.5.xml:1124 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for group requests. Setting the size to 0 will disable the group in-memory " @@ -1475,19 +1420,19 @@ msgid "" msgstr "" #. type: Content of: <variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1174 sssd.conf.5.xml:1226 sssd.conf.5.xml:3656 +#: sssd.conf.5.xml:1130 sssd.conf.5.xml:1182 sssd.conf.5.xml:3835 #: sssd-ldap.5.xml:534 sssd-ldap.5.xml:581 include/failover.xml:116 #: include/krb5_options.xml:11 msgid "Default: 6" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1190 +#: sssd.conf.5.xml:1146 msgid "memcache_size_initgroups (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1193 +#: sssd.conf.5.xml:1149 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for initgroups requests. Setting the size to 0 will disable the initgroups " @@ -1495,12 +1440,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1215 +#: sssd.conf.5.xml:1171 msgid "memcache_size_sid (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1218 +#: sssd.conf.5.xml:1174 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for SID related requests. Only SID-by-ID and ID-by-SID requests are " @@ -1509,12 +1454,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1242 sssd-ifp.5.xml:90 +#: sssd.conf.5.xml:1198 sssd-ifp.5.xml:90 msgid "user_attributes (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1245 +#: sssd.conf.5.xml:1201 msgid "" "Some of the additional NSS responder requests can return more attributes " "than just the POSIX ones defined by the NSS interface. The list of " @@ -1525,103 +1470,109 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1258 +#: sssd.conf.5.xml:1214 msgid "" "To make configuration more easy the NSS responder will check the InfoPipe " "option if it is not set for the NSS responder." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1263 +#: sssd.conf.5.xml:1219 msgid "Default: not set, fallback to InfoPipe option" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1268 +#: sssd.conf.5.xml:1224 msgid "pwfield (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1271 +#: sssd.conf.5.xml:1227 msgid "" "The value that NSS operations that return users or groups will return for " "the <quote>password</quote> field." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1276 -msgid "Default: <quote>*</quote>" +#: sssd.conf.5.xml:1232 +msgid "" +"This option can also be set per-domain, which overwrites the value in the " +"<quote>[nss]</quote> section for that domain. This is particularly useful " +"when using a proxy domain with <option>proxy_lib_name=files</option> and a " +"<option>proxy_pam_target</option> other than <quote>sssd-shadowutils</" +"quote>. In that case, SSSD returns <quote>*</quote> for the password field " +"by default, which causes <command>pam_unix</command> to treat all accounts " +"as locked. Setting <option>pwfield = x</option> in the domain section " +"restores the expected behavior." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1279 -msgid "" -"Note: This option can also be set per-domain which overwrites the value in " -"[nss] section." +#: sssd.conf.5.xml:1246 +msgid "Default: <quote>*</quote>" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1283 +#: sssd.conf.5.xml:1249 msgid "" -"Default: <quote>not set</quote> (remote domains), <quote>x</quote> (proxy " -"domain with nss_files and sssd-shadowutils target)" +"Default (per-domain): <quote>not set</quote> (remote domains), <quote>x</" +"quote> (proxy domain with nss_files and sssd-shadowutils target)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:1292 +#: sssd.conf.5.xml:1258 msgid "PAM configuration options" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:1294 +#: sssd.conf.5.xml:1260 msgid "" "These options can be used to configure the Pluggable Authentication Module " -"(PAM) service." +"(PAM) service and should be specified under the <quote>[pam]</quote> section." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1299 +#: sssd.conf.5.xml:1266 msgid "offline_credentials_expiration (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1302 +#: sssd.conf.5.xml:1269 msgid "" "If the authentication provider is offline, how long should we allow cached " "logins (in days since the last successful online login)." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1307 sssd.conf.5.xml:1320 +#: sssd.conf.5.xml:1274 sssd.conf.5.xml:1287 msgid "Default: 0 (No limit)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1313 +#: sssd.conf.5.xml:1280 msgid "offline_failed_login_attempts (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1316 +#: sssd.conf.5.xml:1283 msgid "" "If the authentication provider is offline, how many failed login attempts " "are allowed." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1326 +#: sssd.conf.5.xml:1293 msgid "offline_failed_login_delay (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1329 +#: sssd.conf.5.xml:1296 msgid "" "The time in minutes which has to pass after offline_failed_login_attempts " "has been reached before a new login attempt is possible." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1334 +#: sssd.conf.5.xml:1301 msgid "" "If set to 0 the user cannot authenticate offline if " "offline_failed_login_attempts has been reached. Only a successful online " @@ -1629,59 +1580,59 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1340 sssd.conf.5.xml:1450 +#: sssd.conf.5.xml:1307 sssd.conf.5.xml:1417 msgid "Default: 5" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1346 +#: sssd.conf.5.xml:1313 msgid "pam_verbosity (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1349 +#: sssd.conf.5.xml:1316 msgid "" "Controls what kind of messages are shown to the user during authentication. " "The higher the number to more messages are displayed." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1354 +#: sssd.conf.5.xml:1321 msgid "Currently sssd supports the following values:" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1357 +#: sssd.conf.5.xml:1324 msgid "<emphasis>0</emphasis>: do not show any message" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1360 +#: sssd.conf.5.xml:1327 msgid "<emphasis>1</emphasis>: show only important messages" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1364 +#: sssd.conf.5.xml:1331 msgid "<emphasis>2</emphasis>: show informational messages" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1367 +#: sssd.conf.5.xml:1334 msgid "<emphasis>3</emphasis>: show all messages and debug information" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1371 sssd.8.xml:63 +#: sssd.conf.5.xml:1338 sssd.8.xml:63 msgid "Default: 1" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1377 +#: sssd.conf.5.xml:1344 msgid "pam_response_filter (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1380 +#: sssd.conf.5.xml:1347 msgid "" "A comma separated list of strings which allows to remove (filter) data sent " "by the PAM responder to pam_sss PAM module. There are different kind of " @@ -1690,51 +1641,51 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1388 +#: sssd.conf.5.xml:1355 msgid "" "While messages already can be controlled with the help of the pam_verbosity " "option this option allows to filter out other kind of responses as well." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1395 +#: sssd.conf.5.xml:1362 msgid "ENV" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1396 +#: sssd.conf.5.xml:1363 msgid "Do not send any environment variables to any service." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1399 +#: sssd.conf.5.xml:1366 msgid "ENV:var_name" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1400 +#: sssd.conf.5.xml:1367 msgid "Do not send environment variable var_name to any service." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1404 +#: sssd.conf.5.xml:1371 msgid "ENV:var_name:service" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1405 +#: sssd.conf.5.xml:1372 msgid "Do not send environment variable var_name to service." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1393 +#: sssd.conf.5.xml:1360 msgid "" "Currently the following filters are supported: <placeholder " "type=\"variablelist\" id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1412 +#: sssd.conf.5.xml:1379 msgid "" "The list of strings can either be the list of filters which would set this " "list of filters and overwrite the defaults. Or each element of the list can " @@ -1745,23 +1696,23 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1423 +#: sssd.conf.5.xml:1390 msgid "Default: ENV:KRB5CCNAME:sudo, ENV:KRB5CCNAME:sudo-i" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1426 +#: sssd.conf.5.xml:1393 msgid "" "Example: -ENV:KRB5CCNAME:sudo-i will remove the filter from the default list" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1433 +#: sssd.conf.5.xml:1400 msgid "pam_id_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1436 +#: sssd.conf.5.xml:1403 msgid "" "For any PAM request while SSSD is online, the SSSD will attempt to " "immediately update the cached identity information for the user in order to " @@ -1769,7 +1720,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1442 +#: sssd.conf.5.xml:1409 msgid "" "A complete PAM conversation may perform multiple PAM requests, such as " "account management and session opening. This option controls (on a per-" @@ -1778,17 +1729,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1456 +#: sssd.conf.5.xml:1423 msgid "pam_pwd_expiration_warning (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1459 sssd.conf.5.xml:2912 +#: sssd.conf.5.xml:1426 sssd.conf.5.xml:3037 msgid "Display a warning N days before the password expires." -msgstr "" +msgstr "Exibe um aviso N dias antes da expiração da senha." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1462 +#: sssd.conf.5.xml:1429 msgid "" "Please note that the backend server has to provide information about the " "expiration time of the password. If this information is missing, sssd " @@ -1796,32 +1747,32 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1468 sssd.conf.5.xml:2915 +#: sssd.conf.5.xml:1435 sssd.conf.5.xml:3040 msgid "" "If zero is set, then this filter is not applied, i.e. if the expiration " "warning was received from backend server, it will automatically be displayed." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1473 +#: sssd.conf.5.xml:1440 msgid "" "This setting can be overridden by setting <emphasis>pwd_expiration_warning</" "emphasis> for a particular domain." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1478 sssd.conf.5.xml:3913 sssd-ldap.5.xml:662 +#: sssd.conf.5.xml:1445 sssd.conf.5.xml:4118 sssd-ldap.5.xml:662 #: sssd-ldap.5.xml:1733 sssd.8.xml:79 msgid "Default: 0" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1495 +#: sssd.conf.5.xml:1462 msgid "pam_trusted_users (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1498 +#: sssd.conf.5.xml:1465 msgid "" "Specifies the comma-separated list of UID values or user names that are " "allowed to run PAM conversations against trusted domains. Users not " @@ -1831,74 +1782,74 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1508 +#: sssd.conf.5.xml:1475 msgid "Default: All users are considered trusted by default" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1512 +#: sssd.conf.5.xml:1479 msgid "" "Please note that UID 0 is always allowed to access the PAM responder even in " "case it is not in the pam_trusted_users list." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1519 +#: sssd.conf.5.xml:1486 msgid "pam_public_domains (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1522 +#: sssd.conf.5.xml:1489 msgid "" "Specifies the comma-separated list of domain names that are accessible even " "to untrusted users." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1526 +#: sssd.conf.5.xml:1493 msgid "Two special values for pam_public_domains option are defined:" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1530 +#: sssd.conf.5.xml:1497 msgid "" "all (Untrusted users are allowed to access all domains in PAM responder.)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1534 +#: sssd.conf.5.xml:1501 msgid "" "none (Untrusted users are not allowed to access any domains PAM in " "responder.)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1538 sssd.conf.5.xml:1563 sssd.conf.5.xml:1582 -#: sssd.conf.5.xml:1824 sssd.conf.5.xml:3842 sssd-ldap.5.xml:1270 +#: sssd.conf.5.xml:1505 sssd.conf.5.xml:1530 sssd.conf.5.xml:1549 +#: sssd.conf.5.xml:1821 sssd.conf.5.xml:4048 sssd-ldap.5.xml:1270 msgid "Default: none" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1543 +#: sssd.conf.5.xml:1510 msgid "pam_account_expired_message (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1546 +#: sssd.conf.5.xml:1513 msgid "" "Allows a custom expiration message to be set, replacing the default " "'Permission denied' message." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1551 +#: sssd.conf.5.xml:1518 msgid "" "Note: Please be aware that message is only printed for the SSH service " "unless pam_verbosity is set to 3 (show all messages and debug information)." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1559 +#: sssd.conf.5.xml:1526 #, no-wrap msgid "" "pam_account_expired_message = Account expired, please contact help desk.\n" @@ -1906,19 +1857,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1568 +#: sssd.conf.5.xml:1535 msgid "pam_account_locked_message (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1571 +#: sssd.conf.5.xml:1538 msgid "" "Allows a custom lockout message to be set, replacing the default 'Permission " "denied' message." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1578 +#: sssd.conf.5.xml:1545 #, no-wrap msgid "" "pam_account_locked_message = Account locked, please contact help desk.\n" @@ -1926,81 +1877,120 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1587 -msgid "pam_passkey_auth (bool)" +#: sssd.conf.5.xml:1554 +msgid "pam_passkey_auth (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1590 +#: sssd.conf.5.xml:1557 msgid "Enable passkey device based authentication." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1593 sssd.conf.5.xml:1910 sssd-ad.5.xml:1286 +#: sssd.conf.5.xml:1560 sssd.conf.5.xml:1907 sssd-ad.5.xml:1279 #: sss_rpcidmapd.5.xml:76 msgid "Default: True" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1598 -msgid "passkey_debug_libfido2 (bool)" +#: sssd.conf.5.xml:1565 +msgid "passkey_debug_libfido2 (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1601 +#: sssd.conf.5.xml:1568 msgid "Enable libfido2 library debug messages." msgstr "" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1604 sssd.conf.5.xml:1618 sssd-ldap.5.xml:727 -#: sssd-ldap.5.xml:752 sssd-ldap.5.xml:848 sssd-ldap.5.xml:1356 -#: sssd-ad.5.xml:506 sssd-ad.5.xml:582 sssd-ad.5.xml:1155 +#: sssd.conf.5.xml:1571 sssd.conf.5.xml:1585 sssd.conf.5.xml:4781 +#: sssd-ldap.5.xml:727 sssd-ldap.5.xml:752 sssd-ldap.5.xml:848 +#: sssd-ldap.5.xml:1356 sssd-ad.5.xml:506 sssd-ad.5.xml:582 sssd-ad.5.xml:1160 #: include/ldap_id_mapping.xml:250 msgid "Default: False" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1609 -msgid "pam_cert_auth (bool)" +#: sssd.conf.5.xml:1576 +msgid "pam_cert_auth (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1612 +#: sssd.conf.5.xml:1579 msgid "" "Enable certificate based Smartcard authentication. Since this requires " "additional communication with the Smartcard which will delay the " "authentication process this option is disabled by default." msgstr "" +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1588 +msgid "" +"Note: In case OpenSC is used for Smartcard access SSSD supports the " +"filesystem caching in OpenSC when enabled in opensc.conf. The cached files " +"are located in a common <quote>opensc</quote> directory in SSSD's state " +"directory. The behaviour can be changed in opensc.conf" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> +#: sssd.conf.5.xml:1597 +#, no-wrap +msgid "" +"app /usr/libexec/sssd/p11_child {\n" +" framework pkcs15 {\n" +" use_file_caching = no;\n" +" }\n" +"}\n" +"app /usr/libexec/sssd/krb5_child {\n" +" framework pkcs15 {\n" +" use_file_caching = no;\n" +" }\n" +"}\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1595 +msgid "" +"Example opensc.conf (*): <placeholder type=\"programlisting\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1610 +msgid "" +"(*) The actual <quote>libexec</quote> directory for p11_child and krb5_child " +"depends on the distribution." +msgstr "" + #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1623 +#: sssd.conf.5.xml:1615 msgid "pam_cert_db_path (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1626 +#: sssd.conf.5.xml:1618 msgid "The path to the certificate database." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1629 sssd.conf.5.xml:2163 sssd.conf.5.xml:4338 +#: sssd.conf.5.xml:1621 sssd.conf.5.xml:2199 sssd.conf.5.xml:4543 msgid "Default:" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1631 sssd.conf.5.xml:2165 +#: sssd.conf.5.xml:1623 sssd.conf.5.xml:2201 msgid "" "/etc/sssd/pki/sssd_auth_ca_db.pem (path to a file with trusted CA " "certificates in PEM format)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1641 +#: sssd.conf.5.xml:1633 msgid "pam_cert_verification (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1644 +#: sssd.conf.5.xml:1636 msgid "" "With this parameter the PAM certificate verification can be tuned with a " "comma separated list of options that override the " @@ -2010,7 +2000,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1655 +#: sssd.conf.5.xml:1647 #, no-wrap msgid "" "pam_cert_verification = partial_chain\n" @@ -2018,59 +2008,59 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1659 +#: sssd.conf.5.xml:1651 msgid "" "Default: not set, i.e. use default <quote>certificate_verification</quote> " "option defined in <quote>[sssd]</quote> section." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1666 +#: sssd.conf.5.xml:1658 msgid "p11_child_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1669 +#: sssd.conf.5.xml:1661 msgid "How many seconds will pam_sss wait for p11_child to finish." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1678 +#: sssd.conf.5.xml:1670 msgid "passkey_child_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1681 +#: sssd.conf.5.xml:1673 msgid "" "How many seconds will the PAM responder wait for passkey_child to finish." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1690 +#: sssd.conf.5.xml:1682 msgid "pam_app_services (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1693 +#: sssd.conf.5.xml:1685 msgid "" "Which PAM services are permitted to contact domains of type " "<quote>application</quote>" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1702 +#: sssd.conf.5.xml:1694 msgid "pam_p11_allowed_services (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1705 +#: sssd.conf.5.xml:1697 msgid "" "A comma-separated list of PAM service names for which it will be allowed to " "use Smartcards." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1720 +#: sssd.conf.5.xml:1712 #, no-wrap msgid "" "pam_p11_allowed_services = +my_pam_service, -login\n" @@ -2078,7 +2068,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1709 +#: sssd.conf.5.xml:1701 msgid "" "It is possible to add another PAM service name to the default set by using " "<quote>+service_name</quote> or to explicitly remove a PAM service name from " @@ -2090,68 +2080,73 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1724 sssd-ad.5.xml:645 sssd-ad.5.xml:754 sssd-ad.5.xml:812 -#: sssd-ad.5.xml:870 sssd-ad.5.xml:948 +#: sssd.conf.5.xml:1716 sssd-ad.5.xml:645 sssd-ad.5.xml:759 sssd-ad.5.xml:817 +#: sssd-ad.5.xml:875 sssd-ad.5.xml:953 msgid "Default: the default set of PAM service names includes:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1729 sssd-ad.5.xml:649 +#: sssd.conf.5.xml:1721 sssd-ad.5.xml:649 msgid "login" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1734 sssd-ad.5.xml:654 +#: sssd.conf.5.xml:1726 sssd-ad.5.xml:654 msgid "su" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1739 sssd-ad.5.xml:659 +#: sssd.conf.5.xml:1731 sssd-ad.5.xml:659 msgid "su-l" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1744 sssd-ad.5.xml:674 +#: sssd.conf.5.xml:1736 sssd-ad.5.xml:674 msgid "gdm-smartcard" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1749 sssd-ad.5.xml:669 +#: sssd.conf.5.xml:1741 sssd-ad.5.xml:669 msgid "gdm-password" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1754 +#: sssd.conf.5.xml:1746 msgid "gdm-switchable-auth" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1759 sssd-ad.5.xml:679 +#: sssd.conf.5.xml:1751 sssd-ad.5.xml:679 msgid "kdm" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1764 sssd-ad.5.xml:957 +#: sssd.conf.5.xml:1756 sssd-ad.5.xml:694 +msgid "plasmalogin" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:1761 sssd-ad.5.xml:962 msgid "sudo" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1769 sssd-ad.5.xml:962 +#: sssd.conf.5.xml:1766 sssd-ad.5.xml:967 msgid "sudo-i" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1774 +#: sssd.conf.5.xml:1771 msgid "gnome-screensaver" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1782 +#: sssd.conf.5.xml:1779 msgid "p11_wait_for_card_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1785 +#: sssd.conf.5.xml:1782 msgid "" "If Smartcard authentication is required how many extra seconds in addition " "to p11_child_timeout should the PAM responder wait until a Smartcard is " @@ -2159,12 +2154,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1796 +#: sssd.conf.5.xml:1793 msgid "p11_uri (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1799 +#: sssd.conf.5.xml:1796 msgid "" "PKCS#11 URI (see RFC-7512 for details) which can be used to restrict the " "selection of devices used for Smartcard authentication. By default SSSD's " @@ -2175,7 +2170,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1812 +#: sssd.conf.5.xml:1809 #, no-wrap msgid "" "p11_uri = pkcs11:slot-description=My%20Smartcard%20Reader\n" @@ -2183,7 +2178,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1816 +#: sssd.conf.5.xml:1813 #, no-wrap msgid "" "p11_uri = pkcs11:library-description=OpenSC%20smartcard%20framework;slot-id=2\n" @@ -2191,7 +2186,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1810 +#: sssd.conf.5.xml:1807 msgid "" "Example: <placeholder type=\"programlisting\" id=\"0\"/> or <placeholder " "type=\"programlisting\" id=\"1\"/> To find suitable URI please check the " @@ -2200,47 +2195,47 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1829 -msgid "pam_initgroups_scheme" +#: sssd.conf.5.xml:1826 +msgid "pam_initgroups_scheme (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1837 +#: sssd.conf.5.xml:1834 msgid "always" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1838 +#: sssd.conf.5.xml:1835 msgid "" "Always do an online lookup, please note that pam_id_timeout still applies" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1842 +#: sssd.conf.5.xml:1839 msgid "no_session" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1843 +#: sssd.conf.5.xml:1840 msgid "" "Only do an online lookup if there is no active session of the user, i.e. if " "the user is currently not logged in" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1848 sssd-ldap.5.xml:189 +#: sssd.conf.5.xml:1845 sssd-ldap.5.xml:189 msgid "never" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1849 +#: sssd.conf.5.xml:1846 msgid "" "Never force an online lookup, use the data from the cache as long as they " "are not expired" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1832 +#: sssd.conf.5.xml:1829 msgid "" "The PAM responder can force an online lookup to get the current group " "memberships of the user trying to log in. This option controls when this " @@ -2249,30 +2244,30 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1856 +#: sssd.conf.5.xml:1853 msgid "Default: no_session" msgstr "" -#. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:1861 sssd.conf.5.xml:4277 -msgid "pam_gssapi_services" +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1858 +msgid "pam_gssapi_services (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1864 +#: sssd.conf.5.xml:1861 msgid "" "Comma separated list of PAM services that are allowed to try GSSAPI " "authentication using pam_sss_gss.so module." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1869 +#: sssd.conf.5.xml:1866 msgid "" "To disable GSSAPI authentication, set this option to <quote>-</quote> (dash)." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1873 sssd.conf.5.xml:1904 sssd.conf.5.xml:1942 +#: sssd.conf.5.xml:1870 sssd.conf.5.xml:1901 sssd.conf.5.xml:1939 msgid "" "Note: This option can also be set per-domain which overwrites the value in " "[pam] section. It can also be set for trusted domain which overwrites the " @@ -2280,7 +2275,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1881 +#: sssd.conf.5.xml:1878 #, no-wrap msgid "" "pam_gssapi_services = sudo, sudo-i\n" @@ -2288,22 +2283,22 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1879 sssd.conf.5.xml:1994 sssd.conf.5.xml:3836 +#: sssd.conf.5.xml:1876 sssd.conf.5.xml:2023 sssd.conf.5.xml:4042 msgid "Example: <placeholder type=\"programlisting\" id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1885 +#: sssd.conf.5.xml:1882 msgid "Default: - (GSSAPI authentication is disabled)" msgstr "" -#. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:1890 sssd.conf.5.xml:4278 -msgid "pam_gssapi_check_upn" +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1887 +msgid "pam_gssapi_check_upn (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1893 +#: sssd.conf.5.xml:1890 msgid "" "If True, SSSD will require that the Kerberos user principal that " "successfully authenticated through GSSAPI can be associated with the user " @@ -2311,19 +2306,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1900 +#: sssd.conf.5.xml:1897 msgid "" -"If False, every user that is able to obtained required service ticket will " +"If False, every user that is able to obtain a required service ticket will " "be authenticated." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1915 -msgid "pam_gssapi_indicators_map" +#: sssd.conf.5.xml:1912 +msgid "pam_gssapi_indicators_map (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1918 +#: sssd.conf.5.xml:1915 msgid "" "Comma separated list of authentication indicators required to be present in " "a Kerberos ticket to access a PAM service that is allowed to try GSSAPI " @@ -2331,7 +2326,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1924 +#: sssd.conf.5.xml:1921 msgid "" "Each element of the list can be either an authentication indicator name or a " "pair <quote>service:indicator</quote>. Indicators not prefixed with the PAM " @@ -2346,7 +2341,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1937 +#: sssd.conf.5.xml:1934 msgid "" "To disable GSSAPI authentication indicator check, set this option to <quote>-" "</quote> (dash). To disable the check for a specific PAM service, add " @@ -2354,83 +2349,122 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1948 +#: sssd.conf.5.xml:1945 msgid "" "Following authentication indicators are supported by IPA Kerberos " "deployments:" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1951 +#: sssd.conf.5.xml:1948 msgid "" "pkinit -- pre-authentication using X.509 certificates -- whether stored in " "files or on smart cards." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1954 +#: sssd.conf.5.xml:1951 msgid "" "hardened -- SPAKE pre-authentication or any pre-authentication wrapped in a " "FAST channel." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1957 +#: sssd.conf.5.xml:1954 msgid "radius -- pre-authentication with the help of a RADIUS server." msgstr "" -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1960 -msgid "" -"otp -- pre-authentication using integrated two-factor authentication (2FA or " -"one-time password, OTP) in IPA." +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:1957 +msgid "" +"otp -- pre-authentication using integrated two-factor authentication (2FA or " +"one-time password, OTP) in IPA." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:1960 +msgid "idp -- pre-authentication using external identity provider." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> +#: sssd.conf.5.xml:1970 +#, no-wrap +msgid "" +"pam_gssapi_indicators_map = sudo:pkinit, sudo-i:pkinit\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1965 +msgid "" +"Example: to require access to SUDO services only for users which obtained " +"their Kerberos tickets with a X.509 certificate pre-authentication (PKINIT), " +"set <placeholder type=\"programlisting\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1974 +msgid "Default: not set (use of authentication indicators is not required)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1979 +msgid "pam_gssapi_indicators_apply (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1982 +msgid "" +"Comma separated list of triples to assign additional information from the " +"Kerberos ticket, e.g. a SID from the PAC, to authentication indicators." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1988 +msgid "Currently supported is:" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1963 -msgid "idp -- pre-authentication using external identity provider." +#: sssd.conf.5.xml:1991 +msgid "SID:S-1-5-[domain]-[RID]:[authentication indicator]" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1973 +#: sssd.conf.5.xml:2002 #, no-wrap msgid "" -"pam_gssapi_indicators_map = sudo:pkinit, sudo-i:pkinit\n" +"pam_gssapi_indicators_apply = SID:S-1-5-12345-23456-34567-4321:pkinit\n" " " msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1968 +#: sssd.conf.5.xml:1996 msgid "" -"Example: to require access to SUDO services only for users which obtained " -"their Kerberos tickets with a X.509 certificate pre-authentication (PKINIT), " -"set <placeholder type=\"programlisting\" id=\"0\"/>" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1977 -msgid "Default: not set (use of authentication indicators is not required)" +"Example: To assign a SID, which is e.g. set by Active Directory's " +"Authentication Mechanism Assurance (AMA) if the AD user used a Smartcard for " +"authentication, to the 'pkinit' authentication indicator use: <placeholder " +"type=\"programlisting\" id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1982 +#: sssd.conf.5.xml:2011 msgid "pam_json_services (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1985 +#: sssd.conf.5.xml:2014 msgid "" "Comma separated list of PAM services which can handle the JSON protocol for " "selecting authentication mechanisms" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1990 +#: sssd.conf.5.xml:2019 msgid "To disable JSON protocol, set this option to <quote>-</quote> (dash)." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1996 +#: sssd.conf.5.xml:2025 #, no-wrap msgid "" "pam_json_services = gdm-switchable-auth\n" @@ -2438,52 +2472,59 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2000 +#: sssd.conf.5.xml:2029 msgid "Default: - (JSON protocol is disabled)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2003 +#: sssd.conf.5.xml:2032 msgid "" "Note: 2-Factor Authentication (2FA) is not supported. If 2FA is required, do " "not activate the JSON protocol." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:2013 +#: sssd.conf.5.xml:2042 msgid "SUDO configuration options" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2015 +#: sssd.conf.5.xml:2044 msgid "" -"These options can be used to configure the sudo service. The detailed " -"instructions for configuration of <citerefentry> <refentrytitle>sudo</" -"refentrytitle> <manvolnum>8</manvolnum> </citerefentry> to work with " -"<citerefentry> <refentrytitle>sssd</refentrytitle> <manvolnum>8</manvolnum> " -"</citerefentry> are in the manual page <citerefentry> <refentrytitle>sssd-" -"sudo</refentrytitle> <manvolnum>5</manvolnum> </citerefentry>." +"These options can be used to configure the sudo service and should be " +"specified under the <quote>[sudo]</quote> section." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:2048 +msgid "" +"The detailed instructions for configuration of <citerefentry> " +"<refentrytitle>sudo</refentrytitle> <manvolnum>8</manvolnum> </citerefentry> " +"to work with <citerefentry> <refentrytitle>sssd</refentrytitle> " +"<manvolnum>8</manvolnum> </citerefentry> are in the manual page " +"<citerefentry> <refentrytitle>sssd-sudo</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry>." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2032 -msgid "sudo_timed (bool)" +#: sssd.conf.5.xml:2064 +msgid "sudo_timed (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2035 +#: sssd.conf.5.xml:2067 msgid "" "Whether or not to evaluate the sudoNotBefore and sudoNotAfter attributes " "that implement time-dependent sudoers entries." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2047 +#: sssd.conf.5.xml:2079 msgid "sudo_threshold (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2050 +#: sssd.conf.5.xml:2082 msgid "" "Maximum number of expired rules that can be refreshed at once. If number of " "expired rules is below threshold, those rules are refreshed with " @@ -2493,22 +2534,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:2069 +#: sssd.conf.5.xml:2101 msgid "AUTOFS configuration options" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2071 -msgid "These options can be used to configure the autofs service." +#: sssd.conf.5.xml:2103 +msgid "" +"These options can be used to configure the autofs service and should be " +"specified under the <quote>[autofs]</quote> section." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2075 +#: sssd.conf.5.xml:2109 msgid "autofs_negative_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2078 +#: sssd.conf.5.xml:2112 msgid "" "Specifies for how many seconds should the autofs responder negative cache " "hits (that is, queries for invalid map entries, like nonexistent ones) " @@ -2516,22 +2559,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:2094 +#: sssd.conf.5.xml:2128 msgid "SSH configuration options" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2096 -msgid "These options can be used to configure the SSH service." +#: sssd.conf.5.xml:2130 +msgid "" +"These options can be used to configure the SSH service and should be " +"specified under the <quote>[ssh]</quote> section." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2100 -msgid "ssh_use_certificate_keys (bool)" +#: sssd.conf.5.xml:2136 +msgid "ssh_use_certificate_keys (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2103 +#: sssd.conf.5.xml:2139 msgid "" "If set to true the <command>sss_ssh_authorizedkeys</command> will return ssh " "keys derived from the public key of X.509 certificates stored in the user " @@ -2540,12 +2585,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2118 +#: sssd.conf.5.xml:2154 msgid "ssh_use_certificate_matching_rules (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2121 +#: sssd.conf.5.xml:2157 msgid "" "By default the ssh responder will use all available certificate matching " "rules to filter the certificates so that ssh keys are only derived from the " @@ -2555,7 +2600,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2130 +#: sssd.conf.5.xml:2166 msgid "" "There are two special key words 'all_rules' and 'no_rules' which will enable " "all or no rules, respectively. The latter means that no certificates will be " @@ -2563,7 +2608,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2137 +#: sssd.conf.5.xml:2173 msgid "" "If no rules are configured using 'all_rules' will enable a default rule " "which enables all certificates suitable for client authentication. This is " @@ -2572,38 +2617,38 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2144 +#: sssd.conf.5.xml:2180 msgid "" "A non-existing rule name is considered an error. If as a result no rule is " "selected all certificates will be ignored." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2149 +#: sssd.conf.5.xml:2185 msgid "" "Default: not set, equivalent to 'all_rules', all found rules or the default " "rule are used" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2155 +#: sssd.conf.5.xml:2191 msgid "ca_db (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2158 +#: sssd.conf.5.xml:2194 msgid "" "Path to a storage of trusted CA certificates. The option is used to validate " "user certificates before deriving public ssh keys from them." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:2178 +#: sssd.conf.5.xml:2214 msgid "PAC responder configuration options" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2180 +#: sssd.conf.5.xml:2216 msgid "" "The PAC responder works together with the authorization data plugin for MIT " "Kerberos sssd_pac_plugin.so and a sub-domain provider. The plugin sends the " @@ -2614,7 +2659,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:2189 +#: sssd.conf.5.xml:2225 msgid "" "If the remote user does not exist in the cache, it is created. The UID is " "determined with the help of the SID, trusted domains will have UPGs and the " @@ -2625,24 +2670,26 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:2197 +#: sssd.conf.5.xml:2233 msgid "" "If there are SIDs of groups from domains sssd knows about, the user will be " "added to those groups." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2203 -msgid "These options can be used to configure the PAC responder." +#: sssd.conf.5.xml:2239 +msgid "" +"These options can be used to configure the PAC responder and should be " +"specified under the <quote>[pac]</quote> section." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2207 sssd-ifp.5.xml:66 +#: sssd.conf.5.xml:2244 sssd-ifp.5.xml:66 msgid "allowed_uids (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2210 +#: sssd.conf.5.xml:2247 msgid "" "Specifies the comma-separated list of UID values or user names that are " "allowed to access the PAC responder. User names are resolved to UIDs at " @@ -2650,19 +2697,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2216 +#: sssd.conf.5.xml:2253 msgid "" "Default: 0, &sssd_user_name; (only root and SSSD service users are allowed " "to access the PAC responder)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2220 +#: sssd.conf.5.xml:2257 msgid "Default: 0 (only the root user is allowed to access the PAC responder)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2224 +#: sssd.conf.5.xml:2261 msgid "" "Please note that defaults will be overwritten with this option. If you still " "want to allow the root and/or '&sssd_user_name;' user to access the PAC " @@ -2671,7 +2718,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2231 +#: sssd.conf.5.xml:2268 msgid "" "Please note that although the UID 0 is used as the default it will be " "overwritten with this option. If you still want to allow the root user to " @@ -2680,24 +2727,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2240 +#: sssd.conf.5.xml:2277 msgid "pac_lifetime (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2243 +#: sssd.conf.5.xml:2280 msgid "" "Lifetime of the PAC entry in seconds. As long as the PAC is valid the PAC " "data can be used to determine the group memberships of a user." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2253 +#: sssd.conf.5.xml:2290 msgid "pac_check (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2256 +#: sssd.conf.5.xml:2293 msgid "" "Apply additional checks on the PAC of the Kerberos ticket which is available " "in Active Directory and FreeIPA domains, if configured. Please note that " @@ -2708,7 +2755,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2266 +#: sssd.conf.5.xml:2303 msgid "" "Please note that the checks listed below only apply to PACs issued by Active " "Directory or recent versions of FreeIPA. PACs issued e.g. by a plain MIT " @@ -2716,24 +2763,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2277 +#: sssd.conf.5.xml:2314 msgid "no_check" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2279 +#: sssd.conf.5.xml:2316 msgid "" "The PAC must not be present and even if it is present no additional checks " "will be done." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2285 +#: sssd.conf.5.xml:2322 msgid "pac_present" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2287 +#: sssd.conf.5.xml:2324 msgid "" "The PAC must be present in the service ticket which SSSD will request with " "the help of the user's TGT. If the PAC is not available the authentication " @@ -2741,24 +2788,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2295 +#: sssd.conf.5.xml:2332 msgid "check_upn" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2297 +#: sssd.conf.5.xml:2334 msgid "" "If the PAC is present check if the user principal name (UPN) information is " "consistent." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2303 +#: sssd.conf.5.xml:2340 msgid "check_upn_allow_missing" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2305 +#: sssd.conf.5.xml:2342 msgid "" "This option should be used together with 'check_upn' and handles the case " "where a UPN is set on the server-side but is not read by SSSD. The typical " @@ -2770,7 +2817,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2317 +#: sssd.conf.5.xml:2354 msgid "" "Currently this option is set by default to avoid regressions in such " "environments. A log message will be added to the system log and SSSD's debug " @@ -2781,60 +2828,60 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2331 +#: sssd.conf.5.xml:2368 msgid "upn_dns_info_present" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2333 +#: sssd.conf.5.xml:2370 msgid "The PAC must contain the UPN-DNS-INFO buffer, implies 'check_upn'." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2338 +#: sssd.conf.5.xml:2375 msgid "check_upn_dns_info_ex" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2340 +#: sssd.conf.5.xml:2377 msgid "" "If the PAC is present and the extension to the UPN-DNS-INFO buffer is " "available check if the information in the extension is consistent." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2347 +#: sssd.conf.5.xml:2384 msgid "upn_dns_info_ex_present" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2349 +#: sssd.conf.5.xml:2386 msgid "" "The PAC must contain the extension of the UPN-DNS-INFO buffer, implies " "'check_upn_dns_info_ex', 'upn_dns_info_present' and 'check_upn'." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2273 +#: sssd.conf.5.xml:2310 msgid "" "The following options can be used alone or in a comma-separated list: " "<placeholder type=\"variablelist\" id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2359 +#: sssd.conf.5.xml:2396 msgid "" "Default: no_check (AD and IPA provider 'check_upn, check_upn_allow_missing, " "check_upn_dns_info_ex')" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:2368 +#: sssd.conf.5.xml:2405 msgid "Session recording configuration options" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2370 +#: sssd.conf.5.xml:2407 msgid "" "Session recording works in conjunction with <citerefentry> " "<refentrytitle>tlog-rec-session</refentrytitle> <manvolnum>8</manvolnum> </" @@ -2844,92 +2891,112 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2383 -msgid "These options can be used to configure session recording." +#: sssd.conf.5.xml:2420 +msgid "" +"These options can be used to configure session recording and should be " +"specified under the <quote>[session_recording]</quote> section." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:2425 +msgid "" +"Note: Unlike other sections, the <quote>[session_recording]</quote> section " +"ignores <replaceable>debug*</replaceable> options and suitable " +"<replaceable>debug*</replaceable> options must be set in <quote>[pam]</" +"quote>, <quote>[nss]</quote> and <quote>[domain/<replaceable>NAME</" +"replaceable>]</quote> sections." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2387 sssd-session-recording.5.xml:64 +#: sssd.conf.5.xml:2433 sssd-session-recording.5.xml:64 msgid "scope (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2394 sssd-session-recording.5.xml:71 +#: sssd.conf.5.xml:2440 sssd-session-recording.5.xml:71 msgid "\"none\"" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2397 sssd-session-recording.5.xml:74 +#: sssd.conf.5.xml:2443 sssd-session-recording.5.xml:74 msgid "No users are recorded." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2402 sssd-session-recording.5.xml:79 +#: sssd.conf.5.xml:2448 sssd-session-recording.5.xml:79 msgid "\"some\"" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2405 sssd-session-recording.5.xml:82 +#: sssd.conf.5.xml:2451 sssd-session-recording.5.xml:82 msgid "" "Users/groups specified by <replaceable>users</replaceable> and " "<replaceable>groups</replaceable> options are recorded." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2414 sssd-session-recording.5.xml:91 +#: sssd.conf.5.xml:2460 sssd-session-recording.5.xml:91 msgid "\"all\"" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2417 sssd-session-recording.5.xml:94 +#: sssd.conf.5.xml:2463 sssd-session-recording.5.xml:94 msgid "All users are recorded." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2390 sssd-session-recording.5.xml:67 +#: sssd.conf.5.xml:2436 sssd-session-recording.5.xml:67 msgid "" "One of the following strings specifying the scope of session recording: " "<placeholder type=\"variablelist\" id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2424 sssd-session-recording.5.xml:101 +#: sssd.conf.5.xml:2470 sssd-session-recording.5.xml:101 msgid "Default: \"none\"" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2429 sssd-session-recording.5.xml:106 +#: sssd.conf.5.xml:2475 sssd-session-recording.5.xml:106 msgid "users (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2432 sssd-session-recording.5.xml:109 +#: sssd.conf.5.xml:2478 sssd-session-recording.5.xml:109 msgid "" "A comma-separated list of users which should have session recording enabled. " "Matches user names as returned by NSS. I.e. after the possible space " "replacement, case changes, etc." msgstr "" +"Uma lista de usuários separados por vírgula que devem ter a gravação de " +"sessão ativada. Corresponde aos nomes de usuário retornados pelo NSS, ou " +"seja, após possíveis substituições de espaços, alterações de maiúsculas e " +"minúsculas, etc." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2438 sssd-session-recording.5.xml:115 +#: sssd.conf.5.xml:2484 sssd-session-recording.5.xml:115 msgid "Default: Empty. Matches no users." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2443 sssd-session-recording.5.xml:120 +#: sssd.conf.5.xml:2489 sssd-session-recording.5.xml:120 msgid "groups (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2446 sssd-session-recording.5.xml:123 +#: sssd.conf.5.xml:2492 sssd-session-recording.5.xml:123 msgid "" "A comma-separated list of groups, members of which should have session " "recording enabled. Matches group names as returned by NSS. I.e. after the " "possible space replacement, case changes, etc." msgstr "" +"Uma lista de grupos separados por vírgulas, cujos membros devem ter a " +"gravação de sessão ativada. Corresponde aos nomes dos grupos conforme " +"retornados pelo NSS, ou seja, após a possível substituição de espaços, " +"alterações de maiúsculas e minúsculas, etc." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2452 sssd.conf.5.xml:2484 sssd-session-recording.5.xml:129 +#: sssd.conf.5.xml:2498 sssd.conf.5.xml:2530 sssd-session-recording.5.xml:129 #: sssd-session-recording.5.xml:161 msgid "" "NOTE: using this option (having it set to anything) has a considerable " @@ -2938,57 +3005,56 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2459 sssd-session-recording.5.xml:136 +#: sssd.conf.5.xml:2505 sssd-session-recording.5.xml:136 msgid "Default: Empty. Matches no groups." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2464 sssd-session-recording.5.xml:141 +#: sssd.conf.5.xml:2510 sssd-session-recording.5.xml:141 msgid "exclude_users (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2467 sssd-session-recording.5.xml:144 +#: sssd.conf.5.xml:2513 sssd-session-recording.5.xml:144 msgid "" "A comma-separated list of users to be excluded from recording, only " "applicable with 'scope=all'." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2471 sssd-session-recording.5.xml:148 +#: sssd.conf.5.xml:2517 sssd-session-recording.5.xml:148 msgid "Default: Empty. No users excluded." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2476 sssd-session-recording.5.xml:153 +#: sssd.conf.5.xml:2522 sssd-session-recording.5.xml:153 msgid "exclude_groups (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2479 sssd-session-recording.5.xml:156 +#: sssd.conf.5.xml:2525 sssd-session-recording.5.xml:156 msgid "" "A comma-separated list of groups, members of which should be excluded from " "recording. Only applicable with 'scope=all'." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2491 sssd-session-recording.5.xml:168 +#: sssd.conf.5.xml:2537 sssd-session-recording.5.xml:168 msgid "Default: Empty. No groups excluded." msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:2501 +#: sssd.conf.5.xml:2547 msgid "DOMAIN SECTIONS" msgstr "" -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry><para> -#: sssd.conf.5.xml:2508 sssd.conf.5.xml:3964 sssd.conf.5.xml:3965 -#: sssd.conf.5.xml:3968 -msgid "enabled" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2554 +msgid "enabled (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2511 +#: sssd.conf.5.xml:2557 msgid "" "Explicitly enable or disable the domain. If <quote>true</quote>, the domain " "is always <quote>enabled</quote>. If <quote>false</quote>, the domain is " @@ -2998,12 +3064,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2523 +#: sssd.conf.5.xml:2569 msgid "domain_type (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2526 +#: sssd.conf.5.xml:2572 msgid "" "Specifies whether the domain is meant to be used by POSIX-aware clients such " "as the Name Service Switch or by applications that do not need POSIX data to " @@ -3012,14 +3078,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2534 +#: sssd.conf.5.xml:2580 msgid "" "Allowed values for this option are <quote>posix</quote> and " "<quote>application</quote>." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2538 +#: sssd.conf.5.xml:2584 msgid "" "POSIX domains are reachable by all services. Application domains are only " "reachable from the InfoPipe responder (see <citerefentry> " @@ -3028,38 +3094,38 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2546 +#: sssd.conf.5.xml:2592 msgid "" "NOTE: The application domains are currently well tested with " "<quote>id_provider=ldap</quote> only." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2550 +#: sssd.conf.5.xml:2596 msgid "" "For an easy way to configure a non-POSIX domains, please see the " "<quote>Application domains</quote> section." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2554 +#: sssd.conf.5.xml:2600 msgid "Default: posix" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2560 +#: sssd.conf.5.xml:2606 msgid "min_id,max_id (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2563 +#: sssd.conf.5.xml:2609 msgid "" "UID and GID limits for the domain. If a domain contains an entry that is " "outside these limits, it is ignored." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2568 +#: sssd.conf.5.xml:2614 msgid "" "For users, this affects the primary GID limit. The user will not be returned " "to NSS if either the UID or the primary GID is outside the range. For non-" @@ -3068,24 +3134,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2575 +#: sssd.conf.5.xml:2621 msgid "" "These ID limits affect even saving entries to cache, not only returning them " "by name or ID." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2579 +#: sssd.conf.5.xml:2625 msgid "Default: 1 for min_id, 0 (no limit) for max_id" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2585 -msgid "enumerate (bool)" +#: sssd.conf.5.xml:2631 +msgid "enumerate (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2588 +#: sssd.conf.5.xml:2634 msgid "" "Determines if a domain can be enumerated, that is, whether the domain can " "list all the users and group it contains. Note that it is not required to " @@ -3094,36 +3160,36 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2596 +#: sssd.conf.5.xml:2642 msgid "TRUE = Users and groups are enumerated" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2599 +#: sssd.conf.5.xml:2645 msgid "FALSE = No enumerations for this domain" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2602 sssd.conf.5.xml:2867 sssd.conf.5.xml:3044 +#: sssd.conf.5.xml:2648 sssd.conf.5.xml:2992 sssd.conf.5.xml:3174 msgid "Default: FALSE" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2605 +#: sssd.conf.5.xml:2651 msgid "" "Enumerating a domain requires SSSD to download and store ALL user and group " "entries from the remote server." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2610 +#: sssd.conf.5.xml:2656 msgid "" "Feature is only supported for domains with id_provider = ldap or id_provider " "= proxy." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2614 +#: sssd.conf.5.xml:2660 msgid "" "Note: Enabling enumeration has a severe performance impact on SSSD while " "enumeration is running. It may take up to several minutes after SSSD startup " @@ -3137,14 +3203,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2629 +#: sssd.conf.5.xml:2675 msgid "" "While the first enumeration is running, requests for the complete user or " "group lists may return no results until it completes." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2634 +#: sssd.conf.5.xml:2680 msgid "" "Further, enabling enumeration may increase the time necessary to detect " "network disconnection, as longer timeouts are required to ensure that " @@ -3153,14 +3219,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2642 +#: sssd.conf.5.xml:2688 msgid "" "For the reasons cited above, enabling enumeration is not recommended, " "especially in large environments." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2647 +#: sssd.conf.5.xml:2693 msgid "" "Note: the proxy provider is tested with open source modules like " "'libnss_files' and 'libnss_ldap'. 3rd party modules must follow the " @@ -3168,19 +3234,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2656 +#: sssd.conf.5.xml:2702 msgid "entry_cache_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2659 +#: sssd.conf.5.xml:2705 msgid "" "How many seconds should nss_sss consider entries valid before asking the " "backend again" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2663 +#: sssd.conf.5.xml:2709 msgid "" "The cache expiration timestamps are stored as attributes of individual " "objects in the cache. Therefore, changing the cache timeout only has effect " @@ -3191,139 +3257,246 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2676 +#: sssd.conf.5.xml:2722 msgid "Default: 5400" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2682 +#: sssd.conf.5.xml:2728 msgid "entry_cache_user_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2685 +#: sssd.conf.5.xml:2731 msgid "" "How many seconds should nss_sss consider user entries valid before asking " "the backend again" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2689 sssd.conf.5.xml:2702 sssd.conf.5.xml:2715 -#: sssd.conf.5.xml:2728 sssd.conf.5.xml:2742 sssd.conf.5.xml:2755 -#: sssd.conf.5.xml:2769 sssd.conf.5.xml:2783 sssd.conf.5.xml:2796 +#: sssd.conf.5.xml:2735 sssd.conf.5.xml:2748 sssd.conf.5.xml:2761 +#: sssd.conf.5.xml:2774 sssd.conf.5.xml:2788 sssd.conf.5.xml:2801 +#: sssd.conf.5.xml:2815 sssd.conf.5.xml:2829 msgid "Default: entry_cache_timeout" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2695 +#: sssd.conf.5.xml:2741 msgid "entry_cache_group_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2698 +#: sssd.conf.5.xml:2744 msgid "" "How many seconds should nss_sss consider group entries valid before asking " "the backend again" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2708 +#: sssd.conf.5.xml:2754 msgid "entry_cache_netgroup_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2711 +#: sssd.conf.5.xml:2757 msgid "" "How many seconds should nss_sss consider netgroup entries valid before " "asking the backend again" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2721 +#: sssd.conf.5.xml:2767 msgid "entry_cache_service_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2724 +#: sssd.conf.5.xml:2770 msgid "" "How many seconds should nss_sss consider service entries valid before asking " "the backend again" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2734 +#: sssd.conf.5.xml:2780 msgid "entry_cache_resolver_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2737 +#: sssd.conf.5.xml:2783 msgid "" "How many seconds should nss_sss consider hosts and networks entries valid " "before asking the backend again" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2748 +#: sssd.conf.5.xml:2794 msgid "entry_cache_sudo_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2751 +#: sssd.conf.5.xml:2797 msgid "" "How many seconds should sudo consider rules valid before asking the backend " "again" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2761 +#: sssd.conf.5.xml:2807 msgid "entry_cache_autofs_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2764 +#: sssd.conf.5.xml:2810 msgid "" "How many seconds should the autofs service consider automounter maps valid " "before asking the backend again" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2775 +#: sssd.conf.5.xml:2821 msgid "entry_cache_ssh_host_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2778 +#: sssd.conf.5.xml:2824 msgid "" "How many seconds to keep a host ssh key after refresh. IE how long to cache " "the host key for." msgstr "" +"Por quantos segundos manter uma chave SSH do host após a atualização. Ou " +"seja, por quanto tempo armazenar a chave do host em cache." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2789 -msgid "entry_cache_computer_timeout (integer)" +#: sssd.conf.5.xml:2835 +msgid "offline_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2792 +#: sssd.conf.5.xml:2838 msgid "" -"How many seconds to keep the local computer entry before asking the backend " -"again" +"When SSSD switches to offline mode the amount of time before it tries to go " +"back online will increase based upon the time spent disconnected. By " +"default SSSD uses incremental behaviour to calculate delay in between " +"retries. So, the wait time for a given retry will be longer than the wait " +"time for the previous ones. After each unsuccessful attempt to go online, " +"the new interval is recalculated by the following:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2849 sssd.conf.5.xml:2907 +msgid "" +"new_delay = Minimum(old_delay * 2, offline_timeout_max) + " +"random[0...offline_timeout_random_offset]" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2852 +msgid "" +"The offline_timeout default value is 60. The offline_timeout_max default " +"value is 3600. The offline_timeout_random_offset default value is 30. The " +"end result is the number of seconds before next retry." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2858 +msgid "" +"Note that the maximum length of each interval is defined by " +"offline_timeout_max (apart from the random part)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2868 +msgid "offline_timeout_max (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2871 +msgid "" +"Controls by how much the time between attempts to go online can be " +"incremented following unsuccessful attempts to go online." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2876 +msgid "A value of 0 disables the incrementing behaviour." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2879 +msgid "" +"The value of this parameter should be set in correlation to offline_timeout " +"parameter value." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2883 +msgid "" +"With offline_timeout set to 60 (default value) there is no point in setting " +"offline_timeout_max to less than 120 as it will saturate instantly. General " +"rule here should be to set offline_timeout_max to at least 4 times " +"offline_timeout." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2889 +msgid "" +"Although a value between 0 and offline_timeout may be specified, it has the " +"effect of overriding the offline_timeout value so is of little use." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2894 +msgid "Default: 3600" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2900 +msgid "offline_timeout_random_offset (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2903 +msgid "" +"When SSSD is in offline mode it keeps probing backend servers in specified " +"time intervals:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2910 +msgid "" +"This parameter controls the value of the random offset used for the above " +"equation. Final random_offset value will be random number in range:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2915 +msgid "[0 - offline_timeout_random_offset]" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2918 +msgid "A value of 0 disables the random offset addition." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2921 +msgid "Default: 30" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2802 +#: sssd.conf.5.xml:2927 msgid "refresh_expired_interval (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2805 +#: sssd.conf.5.xml:2930 msgid "" "Specifies how many seconds SSSD has to wait before triggering a background " "refresh task which will refresh all expired or nearly expired records." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2810 +#: sssd.conf.5.xml:2935 msgid "" "The background refresh will process users, groups and netgroups in the " "cache. For users who have performed the initgroups (get group membership for " @@ -3332,17 +3505,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2818 +#: sssd.conf.5.xml:2943 msgid "This option is automatically inherited for all trusted domains." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2822 +#: sssd.conf.5.xml:2947 msgid "You can consider setting this value to 3/4 * entry_cache_timeout." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2826 +#: sssd.conf.5.xml:2951 msgid "" "Cache entry will be refreshed by background task when 2/3 of cache timeout " "has already passed. If there are existing cached entries, the background " @@ -3354,18 +3527,18 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2839 sssd-ldap.5.xml:406 sssd-ldap.5.xml:1834 -#: sssd-ipa.5.xml:255 +#: sssd.conf.5.xml:2964 sssd-ldap.5.xml:406 sssd-ldap.5.xml:1834 +#: sssd-ipa.5.xml:250 msgid "Default: 0 (disabled)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2845 -msgid "cache_credentials (bool)" +#: sssd.conf.5.xml:2970 +msgid "cache_credentials (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2848 +#: sssd.conf.5.xml:2973 msgid "" "Determines if user credentials are also cached in the local LDB cache. The " "cached credentials refer to passwords, which includes the first (long term) " @@ -3376,7 +3549,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2859 +#: sssd.conf.5.xml:2984 msgid "" "Take a note that while credentials are stored as a salted SHA512 hash, this " "still potentially poses some security risk in case an attacker manages to " @@ -3385,32 +3558,36 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2873 +#: sssd.conf.5.xml:2998 msgid "cache_credentials_minimal_first_factor_length (int)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2876 +#: sssd.conf.5.xml:3001 msgid "" "If 2-Factor-Authentication (2FA) is used and credentials should be saved " "this value determines the minimal length the first authentication factor " "(long term password) must have to be saved as SHA512 hash into the cache." msgstr "" +"Se a autenticação de dois fatores (2FA) for usada e as credenciais devem ser " +"salvas, este valor determina o comprimento mínimo que o primeiro fator de " +"autenticação (senha de longo prazo) deve ter para ser salvo como hash SHA512 " +"no cache." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2883 +#: sssd.conf.5.xml:3008 msgid "" "This should avoid that the short PINs of a PIN based 2FA scheme are saved in " "the cache which would make them easy targets for brute-force attacks." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2894 +#: sssd.conf.5.xml:3019 msgid "account_cache_expiration (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2897 +#: sssd.conf.5.xml:3022 msgid "" "Number of days entries are left in cache after last successful login before " "being removed during a cleanup of the cache. 0 means keep forever. The " @@ -3419,17 +3596,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2904 +#: sssd.conf.5.xml:3029 msgid "Default: 0 (unlimited)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2909 +#: sssd.conf.5.xml:3034 msgid "pwd_expiration_warning (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2920 +#: sssd.conf.5.xml:3045 msgid "" "Please note that the backend server has to provide information about the " "expiration time of the password. If this information is missing, sssd " @@ -3438,28 +3615,28 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2927 +#: sssd.conf.5.xml:3052 msgid "Default: 7 (Kerberos), 0 (LDAP)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2933 +#: sssd.conf.5.xml:3058 msgid "id_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2936 +#: sssd.conf.5.xml:3061 msgid "" "The identification provider used for the domain. Supported ID providers are:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2940 +#: sssd.conf.5.xml:3065 msgid "<quote>proxy</quote>: Support a legacy NSS provider." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2943 +#: sssd.conf.5.xml:3068 msgid "" "<quote>ldap</quote>: LDAP provider. See <citerefentry> <refentrytitle>sssd-" "ldap</refentrytitle> <manvolnum>5</manvolnum> </citerefentry> for more " @@ -3467,8 +3644,8 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2951 sssd.conf.5.xml:3070 sssd.conf.5.xml:3129 -#: sssd.conf.5.xml:3192 +#: sssd.conf.5.xml:3076 sssd.conf.5.xml:3200 sssd.conf.5.xml:3259 +#: sssd.conf.5.xml:3322 msgid "" "<quote>ipa</quote>: FreeIPA and Red Hat Identity Management provider. See " "<citerefentry> <refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</" @@ -3476,8 +3653,8 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2960 sssd.conf.5.xml:3079 sssd.conf.5.xml:3138 -#: sssd.conf.5.xml:3201 +#: sssd.conf.5.xml:3085 sssd.conf.5.xml:3209 sssd.conf.5.xml:3268 +#: sssd.conf.5.xml:3331 msgid "" "<quote>ad</quote>: Active Directory provider. See <citerefentry> " "<refentrytitle>sssd-ad</refentrytitle> <manvolnum>5</manvolnum> </" @@ -3485,27 +3662,34 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2968 +#: sssd.conf.5.xml:3093 msgid "" "<quote>idp</quote>: Provider for OAuth 2.0/OIDC based Identity Providers " "(IdP). See <citerefentry> <refentrytitle>sssd-idp</refentrytitle> " "<manvolnum>5</manvolnum> </citerefentry> for more information." msgstr "" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3101 +msgid "" +"Default: Not set (This is a mandatory setting that must be explicitly " +"defined for each configured domain)." +msgstr "" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2979 -msgid "use_fully_qualified_names (bool)" +#: sssd.conf.5.xml:3109 +msgid "use_fully_qualified_names (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2982 +#: sssd.conf.5.xml:3112 msgid "" "Use the full name and domain (as formatted by the domain's full_name_format) " "as the user's login name reported to NSS." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2987 +#: sssd.conf.5.xml:3117 msgid "" "If set to TRUE, all requests to this domain must use fully qualified names. " "For example, if used in EXAMPLE domain that contains a \"test\" user, " @@ -3514,7 +3698,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2995 +#: sssd.conf.5.xml:3125 msgid "" "NOTE: This option has no effect on netgroup lookups due to their tendency to " "include nested netgroups without qualified names. For netgroups, all domains " @@ -3522,24 +3706,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3002 +#: sssd.conf.5.xml:3132 msgid "" "Default: FALSE (TRUE for trusted domain/sub-domains or if " "default_domain_suffix is used)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3009 -msgid "ignore_group_members (bool)" +#: sssd.conf.5.xml:3139 +msgid "ignore_group_members (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3012 +#: sssd.conf.5.xml:3142 msgid "Do not return group members for group lookups." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3015 +#: sssd.conf.5.xml:3145 msgid "" "If set to TRUE, the group membership attribute is not requested from the " "ldap server, and group members are not returned when processing group lookup " @@ -3551,7 +3735,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3033 +#: sssd.conf.5.xml:3163 msgid "" "Enabling this option can also make access provider checks for group " "membership significantly faster, especially for groups containing many " @@ -3559,7 +3743,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3039 sssd.conf.5.xml:3767 sssd-ldap.5.xml:401 +#: sssd.conf.5.xml:3169 sssd.conf.5.xml:3951 sssd-ldap.5.xml:401 #: sssd-ldap.5.xml:454 sssd-ldap.5.xml:529 sssd-ldap.5.xml:576 #: sssd-ldap.5.xml:599 sssd-ldap.5.xml:638 sssd-ldap.5.xml:657 #: sssd-ldap.5.xml:681 sssd-ldap.5.xml:1114 sssd-ldap.5.xml:1147 @@ -3569,19 +3753,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3049 +#: sssd.conf.5.xml:3179 msgid "auth_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3052 +#: sssd.conf.5.xml:3182 msgid "" "The authentication provider used for the domain. Supported auth providers " "are:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3056 sssd.conf.5.xml:3122 +#: sssd.conf.5.xml:3186 sssd.conf.5.xml:3252 msgid "" "<quote>ldap</quote> for native LDAP authentication. See <citerefentry> " "<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> </" @@ -3589,7 +3773,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3063 +#: sssd.conf.5.xml:3193 msgid "" "<quote>krb5</quote> for Kerberos authentication. See <citerefentry> " "<refentrytitle>sssd-krb5</refentrytitle> <manvolnum>5</manvolnum> </" @@ -3597,7 +3781,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3087 +#: sssd.conf.5.xml:3217 msgid "" "<quote>idp</quote>: Provider for OAuth 2.0/OIDC based authentication. See " "<citerefentry> <refentrytitle>sssd-idp</refentrytitle> <manvolnum>5</" @@ -3605,30 +3789,30 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3095 +#: sssd.conf.5.xml:3225 msgid "" "<quote>proxy</quote> for relaying authentication to some other PAM target." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3098 +#: sssd.conf.5.xml:3228 msgid "<quote>none</quote> disables authentication explicitly." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3101 +#: sssd.conf.5.xml:3231 msgid "" "Default: <quote>id_provider</quote> is used if it is set and can handle " "authentication requests." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3107 +#: sssd.conf.5.xml:3237 msgid "access_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3110 +#: sssd.conf.5.xml:3240 msgid "" "The access control provider used for the domain. There are two built-in " "access providers (in addition to any included in installed backends) " @@ -3636,17 +3820,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3116 +#: sssd.conf.5.xml:3246 msgid "<quote>permit</quote> always allow access." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3119 +#: sssd.conf.5.xml:3249 msgid "<quote>deny</quote> always deny access." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3146 +#: sssd.conf.5.xml:3276 msgid "" "<quote>simple</quote> access control based on access or deny lists. See " "<citerefentry> <refentrytitle>sssd-simple</refentrytitle> <manvolnum>5</" @@ -3655,7 +3839,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3153 +#: sssd.conf.5.xml:3283 msgid "" "<quote>krb5</quote>: .k5login based access control. See <citerefentry> " "<refentrytitle>sssd-krb5</refentrytitle> <manvolnum>5</manvolnum></" @@ -3663,29 +3847,29 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3160 +#: sssd.conf.5.xml:3290 msgid "<quote>proxy</quote> for relaying access control to another PAM module." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3163 +#: sssd.conf.5.xml:3293 msgid "Default: <quote>permit</quote>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3168 +#: sssd.conf.5.xml:3298 msgid "chpass_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3171 +#: sssd.conf.5.xml:3301 msgid "" "The provider which should handle change password operations for the domain. " "Supported change password providers are:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3176 +#: sssd.conf.5.xml:3306 msgid "" "<quote>ldap</quote> to change a password stored in a LDAP server. See " "<citerefentry> <refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</" @@ -3693,7 +3877,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3184 +#: sssd.conf.5.xml:3314 msgid "" "<quote>krb5</quote> to change the Kerberos password. See <citerefentry> " "<refentrytitle>sssd-krb5</refentrytitle> <manvolnum>5</manvolnum> </" @@ -3701,35 +3885,35 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3209 +#: sssd.conf.5.xml:3339 msgid "" "<quote>proxy</quote> for relaying password changes to some other PAM target." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3213 +#: sssd.conf.5.xml:3343 msgid "<quote>none</quote> disallows password changes explicitly." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3216 +#: sssd.conf.5.xml:3346 msgid "" "Default: <quote>auth_provider</quote> is used if it is set and can handle " "change password requests." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3223 +#: sssd.conf.5.xml:3353 msgid "sudo_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3226 +#: sssd.conf.5.xml:3356 msgid "The SUDO provider used for the domain. Supported SUDO providers are:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3230 +#: sssd.conf.5.xml:3360 msgid "" "<quote>ldap</quote> for rules stored in LDAP. See <citerefentry> " "<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> </" @@ -3737,33 +3921,33 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3238 +#: sssd.conf.5.xml:3368 msgid "" "<quote>ipa</quote> the same as <quote>ldap</quote> but with IPA default " "settings." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3242 +#: sssd.conf.5.xml:3372 msgid "" "<quote>ad</quote> the same as <quote>ldap</quote> but with AD default " "settings." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3246 +#: sssd.conf.5.xml:3376 msgid "<quote>none</quote> disables SUDO explicitly." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3249 +#: sssd.conf.5.xml:3379 msgid "" "Default: The value of <quote>id_provider</quote> is used if it is set and " "can handle sudo requests." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3253 +#: sssd.conf.5.xml:3383 msgid "" "The detailed instructions for configuration of sudo_provider are in the " "manual page <citerefentry> <refentrytitle>sssd-sudo</refentrytitle> " @@ -3774,7 +3958,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3268 +#: sssd.conf.5.xml:3398 msgid "" "<emphasis>NOTE:</emphasis> Sudo rules are periodically downloaded in the " "background unless the sudo provider is explicitly disabled. Set " @@ -3783,12 +3967,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3278 +#: sssd.conf.5.xml:3408 msgid "selinux_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3281 +#: sssd.conf.5.xml:3411 msgid "" "The provider which should handle loading of selinux settings. Note that this " "provider will be called right after access provider ends. Supported selinux " @@ -3796,7 +3980,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3287 +#: sssd.conf.5.xml:3417 msgid "" "<quote>ipa</quote> to load selinux settings from an IPA server. See " "<citerefentry> <refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</" @@ -3804,31 +3988,32 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3295 +#: sssd.conf.5.xml:3425 msgid "<quote>none</quote> disallows fetching selinux settings explicitly." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3298 +#: sssd.conf.5.xml:3428 msgid "" -"Default: <quote>id_provider</quote> is used if it is set and can handle " -"selinux loading requests." +"Default: the value of <quote>id_provider</quote> is used if it is set and " +"can handle selinux loading requests. Otherwise the result is the same as if " +"the selinux_provider is set to none." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3304 +#: sssd.conf.5.xml:3435 msgid "subdomains_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3307 +#: sssd.conf.5.xml:3438 msgid "" "The provider which should handle fetching of subdomains. This value should " "be always the same as id_provider. Supported subdomain providers are:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3313 +#: sssd.conf.5.xml:3444 msgid "" "<quote>ipa</quote> to load a list of subdomains from an IPA server. See " "<citerefentry> <refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</" @@ -3836,7 +4021,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3322 +#: sssd.conf.5.xml:3453 msgid "" "<quote>ad</quote> to load a list of subdomains from an Active Directory " "server. See <citerefentry> <refentrytitle>sssd-ad</refentrytitle> " @@ -3845,24 +4030,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3331 +#: sssd.conf.5.xml:3462 msgid "<quote>none</quote> disallows fetching subdomains explicitly." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3335 +#: sssd.conf.5.xml:3466 msgid "" "Default: The value of <quote>id_provider</quote> is used if it is set and " "can handle subdomain requests." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3341 +#: sssd.conf.5.xml:3472 msgid "session_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3344 +#: sssd.conf.5.xml:3475 msgid "" "The provider which configures and manages user session related tasks. The " "only user session task currently provided is the integration with Fleet " @@ -3870,34 +4055,34 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3351 +#: sssd.conf.5.xml:3482 msgid "<quote>ipa</quote> to allow performing user session related tasks." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3355 +#: sssd.conf.5.xml:3486 msgid "" "<quote>none</quote> does not perform any kind of user session related tasks." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3359 +#: sssd.conf.5.xml:3490 msgid "Default: <quote>none</quote>." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3365 +#: sssd.conf.5.xml:3496 msgid "autofs_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3368 +#: sssd.conf.5.xml:3499 msgid "" "The autofs provider used for the domain. Supported autofs providers are:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3372 +#: sssd.conf.5.xml:3503 msgid "" "<quote>ldap</quote> to load maps stored in LDAP. See <citerefentry> " "<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> </" @@ -3905,7 +4090,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3379 +#: sssd.conf.5.xml:3510 msgid "" "<quote>ipa</quote> to load maps stored in an IPA server. See <citerefentry> " "<refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</manvolnum> </" @@ -3913,7 +4098,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3387 +#: sssd.conf.5.xml:3518 msgid "" "<quote>ad</quote> to load maps stored in an AD server. See <citerefentry> " "<refentrytitle>sssd-ad</refentrytitle> <manvolnum>5</manvolnum> </" @@ -3921,31 +4106,31 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3396 +#: sssd.conf.5.xml:3527 msgid "<quote>none</quote> disables autofs explicitly." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3399 +#: sssd.conf.5.xml:3530 msgid "" "Default: The value of <quote>id_provider</quote> is used if it is set and " "can handle autofs requests." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3406 +#: sssd.conf.5.xml:3537 msgid "hostid_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3409 +#: sssd.conf.5.xml:3540 msgid "" "The provider used for retrieving host identity information. Supported " "hostid providers are:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3413 +#: sssd.conf.5.xml:3544 msgid "" "<quote>ipa</quote> to load host identity stored in an IPA server. See " "<citerefentry> <refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</" @@ -3953,38 +4138,38 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3421 +#: sssd.conf.5.xml:3552 msgid "<quote>none</quote> disables hostid explicitly." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3424 +#: sssd.conf.5.xml:3555 msgid "" "Default: The value of <quote>id_provider</quote> is used if it is set and " "can handle hostid requests." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3431 +#: sssd.conf.5.xml:3562 msgid "resolver_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3434 +#: sssd.conf.5.xml:3565 msgid "" "The provider which should handle hosts and networks lookups. Supported " "resolver providers are:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3438 +#: sssd.conf.5.xml:3569 msgid "" "<quote>proxy</quote> to forward lookups to another NSS library. See " "<quote>proxy_resolver_lib_name</quote>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3442 +#: sssd.conf.5.xml:3573 msgid "" "<quote>ldap</quote> to fetch hosts and networks stored in LDAP. See " "<citerefentry> <refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</" @@ -3992,7 +4177,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3449 +#: sssd.conf.5.xml:3580 msgid "" "<quote>ad</quote> to fetch hosts and networks stored in AD. See " "<citerefentry> <refentrytitle>sssd-ad</refentrytitle> <manvolnum>5</" @@ -4001,19 +4186,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3457 +#: sssd.conf.5.xml:3588 msgid "<quote>none</quote> disallows fetching hosts and networks explicitly." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3460 +#: sssd.conf.5.xml:3591 msgid "" "Default: The value of <quote>id_provider</quote> is used if it is set and " "can handle resolver requests." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3470 +#: sssd.conf.5.xml:3601 msgid "" "Regular expression for this domain that describes how to parse the string " "containing user name and domain into these components. The \"domain\" can " @@ -4023,24 +4208,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3479 +#: sssd.conf.5.xml:3610 msgid "" "Default: <quote>^((?P<name>.+)@(?P<domain>[^@]*)|(?P<name>" "[^@]+))$</quote> which allows two different styles for user names:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:3484 sssd.conf.5.xml:3498 +#: sssd.conf.5.xml:3615 sssd.conf.5.xml:3629 msgid "username" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:3487 sssd.conf.5.xml:3501 +#: sssd.conf.5.xml:3618 sssd.conf.5.xml:3632 msgid "username@domain.name" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3492 +#: sssd.conf.5.xml:3623 msgid "" "Default for the AD and IPA provider: <quote>^(((?P<domain>[^\\\\]+)\\\\" "(?P<name>.+))|((?P<name>.+)@(?P<domain>[^@]+))|((?" @@ -4049,19 +4234,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:3504 +#: sssd.conf.5.xml:3635 msgid "domain\\username" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3507 +#: sssd.conf.5.xml:3638 msgid "" "While the first two correspond to the general default the third one is " "introduced to allow easy integration of users from Windows domains." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3512 +#: sssd.conf.5.xml:3643 msgid "" "The default re_expression uses the <quote>@</quote> character as a separator " "between the name and the domain. As a result of this setting the default " @@ -4071,89 +4256,94 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3564 +#: sssd.conf.5.xml:3695 msgid "Default: <quote>%1$s@%2$s</quote>." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3570 +#: sssd.conf.5.xml:3701 msgid "lookup_family_order (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3573 +#: sssd.conf.5.xml:3704 msgid "" "Provides the ability to select preferred address family to use when " "performing DNS lookups." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3577 +#: sssd.conf.5.xml:3708 msgid "Supported values:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3580 +#: sssd.conf.5.xml:3711 msgid "ipv4_first: Try looking up IPv4 address, if that fails, try IPv6" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3583 +#: sssd.conf.5.xml:3714 msgid "ipv4_only: Only attempt to resolve hostnames to IPv4 addresses." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3586 +#: sssd.conf.5.xml:3717 msgid "ipv6_first: Try looking up IPv6 address, if that fails, try IPv4" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3589 +#: sssd.conf.5.xml:3720 msgid "ipv6_only: Only attempt to resolve hostnames to IPv6 addresses." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3592 +#: sssd.conf.5.xml:3723 msgid "Default: ipv4_first" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3598 +#: sssd.conf.5.xml:3729 msgid "dns_resolver_server_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3601 +#: sssd.conf.5.xml:3732 msgid "" -"Defines the amount of time (in milliseconds) SSSD would try to talk to DNS " -"server before trying next DNS server." +"Defines the timeout duration (in milliseconds) SSSD waits for a DNS server " +"to respond before moving to the next one." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3606 +#: sssd.conf.5.xml:3737 msgid "" "The AD provider will use this option for the CLDAP ping timeouts as well." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3610 sssd.conf.5.xml:3630 sssd.conf.5.xml:3651 +#: sssd.conf.5.xml:3741 sssd.conf.5.xml:3777 sssd.conf.5.xml:3814 msgid "" -"Please see the section <quote>FAILOVER</quote> for more information about " -"the service resolution." +"Please see the section <quote>FAILOVER</quote> in <citerefentry> " +"<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> </" +"citerefentry>, <citerefentry> <refentrytitle>sssd-krb5</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry>, <citerefentry> <refentrytitle>sssd-" +"ipa</refentrytitle> <manvolnum>5</manvolnum> </citerefentry> or " +"<citerefentry> <refentrytitle>sssd-ad</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry> for more information about the service resolution." msgstr "" #. type: Content of: <refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3615 sssd-ldap.5.xml:700 include/failover.xml:84 +#: sssd.conf.5.xml:3762 sssd-ldap.5.xml:700 include/failover.xml:84 msgid "Default: 1000" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3621 +#: sssd.conf.5.xml:3768 msgid "dns_resolver_op_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3624 +#: sssd.conf.5.xml:3771 msgid "" "Defines the amount of time (in seconds) to wait to resolve single DNS query " "(e.g. resolution of a hostname or an SRV record) before trying the next " @@ -4161,17 +4351,17 @@ msgid "" msgstr "" #. type: Content of: <refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3635 include/failover.xml:100 +#: sssd.conf.5.xml:3798 include/failover.xml:100 msgid "Default: 3" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3641 +#: sssd.conf.5.xml:3804 msgid "dns_resolver_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3644 +#: sssd.conf.5.xml:3807 msgid "" "Defines the amount of time (in seconds) to wait for a reply from the " "internal fail over service before assuming that the service is unreachable. " @@ -4180,12 +4370,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3662 -msgid "dns_resolver_use_search_list (bool)" +#: sssd.conf.5.xml:3841 +msgid "dns_resolver_use_search_list (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3665 +#: sssd.conf.5.xml:3844 msgid "" "Normally, the DNS resolver searches the domain list defined in the " "\"search\" directive from the resolv.conf file. This can lead to delays in " @@ -4193,7 +4383,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3671 +#: sssd.conf.5.xml:3850 msgid "" "If fully qualified domain names (or _srv_) are used in the SSSD " "configuration, setting this option to FALSE can prevent unnecessary DNS " @@ -4201,34 +4391,34 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3677 +#: sssd.conf.5.xml:3856 msgid "Default: TRUE" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3683 +#: sssd.conf.5.xml:3862 msgid "dns_discovery_domain (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3686 +#: sssd.conf.5.xml:3865 msgid "" "If service discovery is used in the back end, specifies the domain part of " "the service discovery DNS query." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3690 +#: sssd.conf.5.xml:3869 msgid "Default: Use the domain part of machine's hostname" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3696 +#: sssd.conf.5.xml:3875 msgid "failover_primary_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3699 +#: sssd.conf.5.xml:3878 msgid "" "When no primary server is available, SSSD fails over to a backup server. " "This option defines the number of seconds SSSD waits before attempting to " @@ -4236,57 +4426,66 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3706 +#: sssd.conf.5.xml:3885 msgid "Note: The minimum value is 31." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3709 +#: sssd.conf.5.xml:3888 msgid "Default: 31" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3715 +#: sssd.conf.5.xml:3894 msgid "override_gid (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3718 -msgid "Override the primary GID value with the one specified." +#: sssd.conf.5.xml:3897 +msgid "" +"Override the primary GID value for all users in the domain with specified " +"value." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3901 +msgid "" +"Default: not set (Use the primary GID value retrieved from the identity " +"provider)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3724 +#: sssd.conf.5.xml:3908 msgid "case_sensitive (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3731 +#: sssd.conf.5.xml:3915 msgid "True" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3734 +#: sssd.conf.5.xml:3918 msgid "Case sensitive. This value is invalid for AD provider." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3740 +#: sssd.conf.5.xml:3924 msgid "False" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3742 +#: sssd.conf.5.xml:3926 msgid "Case insensitive." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3746 +#: sssd.conf.5.xml:3930 msgid "Preserving" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3749 +#: sssd.conf.5.xml:3933 msgid "" "Same as False (case insensitive), but does not lowercase names in the result " "of NSS operations. Note that name aliases (and in case of services also " @@ -4294,31 +4493,57 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3757 +#: sssd.conf.5.xml:3941 msgid "" "If you want to set this value for trusted domain with IPA provider, you need " "to set it on both the client and SSSD on the server." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3727 +#: sssd.conf.5.xml:3911 msgid "" "Treat user and group names as case sensitive. Possible option values are: " "<placeholder type=\"variablelist\" id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3772 +#: sssd.conf.5.xml:3956 msgid "Default: True (False for AD provider)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3778 +#: sssd.conf.5.xml:3962 +msgid "avoid_by_id_lookups (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3965 +msgid "" +"If this option is set to 'true' SSSD will try to avoid sending lookups by ID " +"to the backend and will switch to a lookup by name if a cached object with a " +"matching ID can be found." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3971 +msgid "" +"This option can e.g. be used in cases where searches by ID are expensive on " +"the server side because of missing indexes or are not even possible, e.g. " +"due to non-reversible POSIX id-mapping." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3978 +msgid "Default: False (True for IdP provider)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:3984 msgid "subdomain_inherit (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3781 +#: sssd.conf.5.xml:3987 msgid "" "Specifies a list of configuration parameters that should be inherited by a " "subdomain. Please note that only selected parameters can be inherited. " @@ -4326,89 +4551,89 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3787 +#: sssd.conf.5.xml:3993 msgid "ldap_search_timeout" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3790 +#: sssd.conf.5.xml:3996 msgid "ldap_network_timeout" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3793 +#: sssd.conf.5.xml:3999 msgid "ldap_opt_timeout" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3796 +#: sssd.conf.5.xml:4002 msgid "ldap_offline_timeout" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3799 +#: sssd.conf.5.xml:4005 msgid "ldap_purge_cache_timeout" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3802 +#: sssd.conf.5.xml:4008 msgid "ldap_purge_cache_offset" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3805 +#: sssd.conf.5.xml:4011 msgid "" "ldap_krb5_keytab (the value of krb5_keytab will be used if ldap_krb5_keytab " "is not set explicitly)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3809 +#: sssd.conf.5.xml:4015 msgid "ldap_krb5_ticket_lifetime" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3812 +#: sssd.conf.5.xml:4018 msgid "ldap_connection_expire_timeout" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3815 +#: sssd.conf.5.xml:4021 msgid "ldap_connection_expire_offset" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3818 +#: sssd.conf.5.xml:4024 msgid "ldap_connection_idle_timeout" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3821 sssd-ldap.5.xml:446 +#: sssd.conf.5.xml:4027 sssd-ldap.5.xml:446 msgid "ldap_use_tokengroups" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3824 +#: sssd.conf.5.xml:4030 msgid "ldap_user_principal" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3827 +#: sssd.conf.5.xml:4033 msgid "ignore_group_members" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3830 +#: sssd.conf.5.xml:4036 msgid "auto_private_groups" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3833 +#: sssd.conf.5.xml:4039 msgid "case_sensitive" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:3838 +#: sssd.conf.5.xml:4044 #, no-wrap msgid "" "subdomain_inherit = ldap_purge_cache_timeout\n" @@ -4416,27 +4641,27 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3845 +#: sssd.conf.5.xml:4051 msgid "Note: This option only works with the IPA and AD provider." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3852 +#: sssd.conf.5.xml:4058 msgid "subdomain_homedir (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3863 +#: sssd.conf.5.xml:4069 msgid "%F" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3864 +#: sssd.conf.5.xml:4070 msgid "flat (NetBIOS) name of a subdomain." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3855 +#: sssd.conf.5.xml:4061 msgid "" "Use this homedir as default value for all subdomains within this domain in " "IPA AD trust. See <emphasis>override_homedir</emphasis> for info about " @@ -4446,55 +4671,57 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3869 +#: sssd.conf.5.xml:4075 msgid "" "The value can be overridden by <emphasis>override_homedir</emphasis> option." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3873 +#: sssd.conf.5.xml:4079 msgid "Default: <filename>/home/%d/%u</filename>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3878 +#: sssd.conf.5.xml:4084 msgid "realmd_tags (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3881 +#: sssd.conf.5.xml:4087 msgid "" "Various tags stored by the realmd configuration service for this domain." msgstr "" +"Várias tags armazenadas pelo serviço de configuração realmd para este " +"domínio." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3887 +#: sssd.conf.5.xml:4093 msgid "cached_auth_timeout (int)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3890 +#: sssd.conf.5.xml:4096 msgid "" -"Specifies time in seconds since last successful online authentication for " -"which user will be authenticated using cached credentials while SSSD is in " -"the online mode. If the credentials are incorrect, SSSD falls back to online " -"authentication." +"Specifies the number of seconds since the last successful online " +"authentication during which SSSD will authenticate users via cached " +"credentials, even while online. If the cached authentication fails, SSSD " +"immediately falls back to online authentication." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3898 +#: sssd.conf.5.xml:4103 msgid "" "This option's value is inherited by all trusted domains. At the moment it is " "not possible to set a different value per trusted domain." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3903 +#: sssd.conf.5.xml:4108 msgid "Special value 0 implies that this feature is disabled." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3907 +#: sssd.conf.5.xml:4112 msgid "" "Please note that if <quote>cached_auth_timeout</quote> is longer than " "<quote>pam_id_timeout</quote> then the back end could be called to handle " @@ -4502,12 +4729,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3918 +#: sssd.conf.5.xml:4123 msgid "local_auth_policy (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3921 +#: sssd.conf.5.xml:4126 msgid "" "Local authentication methods policy. Some backends (i.e. LDAP, proxy " "provider) only support a password based authentication, while others can " @@ -4519,7 +4746,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3933 +#: sssd.conf.5.xml:4138 msgid "" "There are three possible values for this option: match, only, enable. " "<quote>match</quote> is used to match offline and online states for Kerberos " @@ -4531,7 +4758,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3946 +#: sssd.conf.5.xml:4151 msgid "" "The following table shows which authentication methods, if configured " "properly, are currently enabled or disabled for each backend, with the " @@ -4539,42 +4766,47 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> -#: sssd.conf.5.xml:3959 +#: sssd.conf.5.xml:4164 msgid "local_auth_policy = match (default)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> -#: sssd.conf.5.xml:3960 +#: sssd.conf.5.xml:4165 msgid "Passkey" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> -#: sssd.conf.5.xml:3961 +#: sssd.conf.5.xml:4166 msgid "Smartcard" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:3964 sssd-ldap.5.xml:228 +#: sssd.conf.5.xml:4169 sssd-ldap.5.xml:228 msgid "IPA" msgstr "" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry><para> +#: sssd.conf.5.xml:4169 sssd.conf.5.xml:4170 sssd.conf.5.xml:4173 +msgid "enabled" +msgstr "" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:3967 sssd-ldap.5.xml:233 +#: sssd.conf.5.xml:4172 sssd-ldap.5.xml:233 msgid "AD" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry><para> -#: sssd.conf.5.xml:3967 sssd.conf.5.xml:3970 sssd.conf.5.xml:3971 +#: sssd.conf.5.xml:4172 sssd.conf.5.xml:4175 sssd.conf.5.xml:4176 msgid "disabled" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry> -#: sssd.conf.5.xml:3970 +#: sssd.conf.5.xml:4175 msgid "LDAP" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3975 +#: sssd.conf.5.xml:4180 msgid "" "Please note that if local Smartcard authentication is enabled and a " "Smartcard is present, Smartcard authentication will be preferred over the " @@ -4583,7 +4815,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:3987 +#: sssd.conf.5.xml:4192 #, no-wrap msgid "" "[domain/shadowutils]\n" @@ -4594,7 +4826,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3983 +#: sssd.conf.5.xml:4188 msgid "" "The following configuration example allows local users to authenticate " "locally using any enabled method (i.e. smartcard, passkey). <placeholder " @@ -4602,29 +4834,29 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3995 +#: sssd.conf.5.xml:4200 msgid "Default: match" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4000 +#: sssd.conf.5.xml:4205 msgid "auto_private_groups (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4006 +#: sssd.conf.5.xml:4211 msgid "true" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4009 +#: sssd.conf.5.xml:4214 msgid "" "Create user's private group unconditionally from user's UID number. The GID " "number is ignored in this case." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4013 +#: sssd.conf.5.xml:4218 msgid "" "NOTE: Because the GID number and the user private group are inferred from " "the UID number, it is not supported to have multiple entries with the same " @@ -4633,24 +4865,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4022 +#: sssd.conf.5.xml:4227 msgid "false" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4025 +#: sssd.conf.5.xml:4230 msgid "" "Always use the user's primary GID number. The GID number must refer to a " "group object in the LDAP database." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4031 +#: sssd.conf.5.xml:4236 msgid "hybrid" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4034 +#: sssd.conf.5.xml:4239 msgid "" "A primary group is autogenerated for user entries whose UID and GID numbers " "have the same value and at the same time the GID number does not correspond " @@ -4660,14 +4892,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4047 +#: sssd.conf.5.xml:4252 msgid "" "If the UID and GID of a user are different, then the GID must correspond to " "a group entry, otherwise the GID is simply not resolvable." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4054 +#: sssd.conf.5.xml:4259 msgid "" "This feature is useful for environments that wish to stop maintaining a " "separate group objects for the user private groups, but also wish to retain " @@ -4675,14 +4907,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4003 +#: sssd.conf.5.xml:4208 msgid "" "This option takes any of three available values: <placeholder " "type=\"variablelist\" id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4066 +#: sssd.conf.5.xml:4271 msgid "" "For the LDAP based id providers (LDAP, IPA and AD) the default for the " "configured domain is typically False because the sources have the concept of " @@ -4692,14 +4924,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4075 +#: sssd.conf.5.xml:4280 msgid "" "For subdomains, the default value is False for subdomains that use assigned " "POSIX IDs and True for subdomains that use automatic ID-mapping." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:4083 +#: sssd.conf.5.xml:4288 #, no-wrap msgid "" "[domain/forest.domain/sub.domain]\n" @@ -4707,7 +4939,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:4089 +#: sssd.conf.5.xml:4294 #, no-wrap msgid "" "[domain/forest.domain]\n" @@ -4716,7 +4948,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4080 +#: sssd.conf.5.xml:4285 msgid "" "The value of auto_private_groups can either be set per subdomains in a " "subsection, for example: <placeholder type=\"programlisting\" id=\"0\"/> or " @@ -4725,7 +4957,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:2503 +#: sssd.conf.5.xml:2549 msgid "" "These configuration options can be present in a domain configuration " "section, that is, in a section called <quote>[domain/<replaceable>NAME</" @@ -4733,17 +4965,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4104 +#: sssd.conf.5.xml:4309 msgid "proxy_pam_target (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4107 +#: sssd.conf.5.xml:4312 msgid "The proxy target PAM proxies to." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4110 +#: sssd.conf.5.xml:4315 msgid "" "Default: not set by default, you have to take an existing pam configuration " "or create a new one and add the service name here. As an alternative you can " @@ -4751,12 +4983,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4120 +#: sssd.conf.5.xml:4325 msgid "proxy_lib_name (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4123 +#: sssd.conf.5.xml:4328 msgid "" "The name of the NSS library to use in proxy domains. The NSS functions " "searched for in the library are in the form of _nss_$(libName)_$(function), " @@ -4764,12 +4996,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4133 +#: sssd.conf.5.xml:4338 msgid "proxy_resolver_lib_name (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4136 +#: sssd.conf.5.xml:4341 msgid "" "The name of the NSS library to use for hosts and networks lookups in proxy " "domains. The NSS functions searched for in the library are in the form of " @@ -4777,12 +5009,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4147 +#: sssd.conf.5.xml:4352 msgid "proxy_fast_alias (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4150 +#: sssd.conf.5.xml:4355 msgid "" "When a user or group is looked up by name in the proxy provider, a second " "lookup by ID is performed to \"canonicalize\" the name in case the requested " @@ -4791,12 +5023,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4164 +#: sssd.conf.5.xml:4369 msgid "proxy_max_children (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4167 +#: sssd.conf.5.xml:4372 msgid "" "This option specifies the number of pre-forked proxy children. It is useful " "for high-load SSSD environments where sssd may run out of available child " @@ -4804,19 +5036,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4100 +#: sssd.conf.5.xml:4305 msgid "" "Options valid for proxy domains. <placeholder type=\"variablelist\" " "id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:4183 +#: sssd.conf.5.xml:4388 msgid "Application domains" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:4185 +#: sssd.conf.5.xml:4390 msgid "" "SSSD, with its D-Bus interface (see <citerefentry> <refentrytitle>sssd-ifp</" "refentrytitle> <manvolnum>5</manvolnum> </citerefentry>) is appealing to " @@ -4833,7 +5065,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:4205 +#: sssd.conf.5.xml:4410 msgid "" "Please note that the application domain must still be explicitly enabled in " "the <quote>domains</quote> parameter so that the lookup order between the " @@ -4841,17 +5073,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><title> -#: sssd.conf.5.xml:4211 +#: sssd.conf.5.xml:4416 msgid "Application domain parameters" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4213 +#: sssd.conf.5.xml:4418 msgid "inherit_from (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4216 +#: sssd.conf.5.xml:4421 msgid "" "The SSSD POSIX-type domain the application domain inherits all settings " "from. The application domain can moreover add its own settings to the " @@ -4860,7 +5092,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:4230 +#: sssd.conf.5.xml:4435 msgid "" "The following example illustrates the use of an application domain. In this " "setup, the POSIX domain is connected to an LDAP server and is used by the OS " @@ -4870,7 +5102,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><programlisting> -#: sssd.conf.5.xml:4238 +#: sssd.conf.5.xml:4443 #, no-wrap msgid "" "[sssd]\n" @@ -4890,12 +5122,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:4258 +#: sssd.conf.5.xml:4463 msgid "TRUSTED DOMAIN SECTION" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4260 +#: sssd.conf.5.xml:4465 msgid "" "Some options used in the domain section can also be used in the trusted " "domain section, that is, in a section called <quote>[domain/" @@ -4906,69 +5138,79 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4267 +#: sssd.conf.5.xml:4472 msgid "ldap_search_base," msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4268 +#: sssd.conf.5.xml:4473 msgid "ldap_user_search_base," msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4269 +#: sssd.conf.5.xml:4474 msgid "ldap_group_search_base," msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4270 +#: sssd.conf.5.xml:4475 msgid "ldap_netgroup_search_base," msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4271 +#: sssd.conf.5.xml:4476 msgid "ldap_service_search_base," msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4272 +#: sssd.conf.5.xml:4477 msgid "ldap_sasl_mech," msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4273 +#: sssd.conf.5.xml:4478 msgid "ad_server," msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4274 +#: sssd.conf.5.xml:4479 msgid "ad_backup_server," msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4275 +#: sssd.conf.5.xml:4480 msgid "ad_site," msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:4276 sssd-ipa.5.xml:934 +#: sssd.conf.5.xml:4481 sssd-ipa.5.xml:929 msgid "use_fully_qualified_names" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4280 +#: sssd.conf.5.xml:4482 +msgid "pam_gssapi_services" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:4483 +msgid "pam_gssapi_check_upn" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:4485 msgid "" "For more details about these options see their individual description in the " "manual page." msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:4286 +#: sssd.conf.5.xml:4491 msgid "CERTIFICATE MAPPING SECTION" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4288 +#: sssd.conf.5.xml:4493 msgid "" "To allow authentication with Smartcards and certificates SSSD must be able " "to map certificates to users. This can be done by adding the full " @@ -4981,7 +5223,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4302 +#: sssd.conf.5.xml:4507 msgid "" "To make the mapping more flexible mapping and matching rules were added to " "SSSD (see <citerefentry> <refentrytitle>sss-certmap</refentrytitle> " @@ -4989,7 +5231,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4311 +#: sssd.conf.5.xml:4516 msgid "" "A mapping and matching rule can be added to the SSSD configuration in a " "section on its own with a name like <quote>[certmap/" @@ -4998,55 +5240,50 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4318 +#: sssd.conf.5.xml:4523 msgid "matchrule (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4321 +#: sssd.conf.5.xml:4526 msgid "" "Only certificates from the Smartcard which matches this rule will be " "processed, all others are ignored." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4325 +#: sssd.conf.5.xml:4530 msgid "" "Default: KRB5:<EKU>clientAuth, i.e. only certificates which have the " "Extended Key Usage <quote>clientAuth</quote>" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4332 +#: sssd.conf.5.xml:4537 msgid "maprule (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4335 +#: sssd.conf.5.xml:4540 msgid "Defines how the user is found for a given certificate." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:4341 +#: sssd.conf.5.xml:4546 msgid "" "LDAP:(userCertificate;binary={cert!bin}) for LDAP based providers like " "<quote>ldap</quote>, <quote>AD</quote> or <quote>ipa</quote>." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:4347 +#: sssd.conf.5.xml:4552 msgid "" "If maprule is not set and provider is <quote>proxy</quote>, the RULE_NAME " "name is assumed to be the name of the matching user." msgstr "" -#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4357 -msgid "domains (string)" -msgstr "" - #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4360 +#: sssd.conf.5.xml:4565 msgid "" "Comma separated list of domain names the rule should be applied. By default " "a rule is only valid in the domain configured in sssd.conf. If the provider " @@ -5055,17 +5292,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4367 +#: sssd.conf.5.xml:4572 msgid "Default: the configured domain in sssd.conf" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4372 +#: sssd.conf.5.xml:4577 msgid "priority (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4375 +#: sssd.conf.5.xml:4580 msgid "" "Unsigned integer value defining the priority of the rule. The higher the " "number the lower the priority. <quote>0</quote> stands for the highest " @@ -5073,17 +5310,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4381 +#: sssd.conf.5.xml:4586 msgid "Default: the lowest priority" msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:4389 +#: sssd.conf.5.xml:4594 msgid "PROMPTING CONFIGURATION SECTION" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4391 +#: sssd.conf.5.xml:4596 msgid "" "If a special file (<filename>/var/lib/sss/pubconf/pam_preauth_available</" "filename>) exists SSSD's PAM module pam_sss will ask SSSD to figure out " @@ -5093,7 +5330,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4399 +#: sssd.conf.5.xml:4604 msgid "" "With the growing number of authentication methods and the possibility that " "there are multiple ones for a single user the heuristic used by pam_sss to " @@ -5102,59 +5339,59 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4411 +#: sssd.conf.5.xml:4616 msgid "[prompting/password]" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4414 +#: sssd.conf.5.xml:4619 msgid "password_prompt" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4415 +#: sssd.conf.5.xml:4620 msgid "to change the string of the password prompt" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4413 +#: sssd.conf.5.xml:4618 msgid "" "to configure password prompting, allowed options are: <placeholder " "type=\"variablelist\" id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4423 +#: sssd.conf.5.xml:4628 msgid "[prompting/2fa]" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4427 +#: sssd.conf.5.xml:4632 msgid "first_prompt" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4428 +#: sssd.conf.5.xml:4633 msgid "to change the string of the prompt for the first factor" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4431 +#: sssd.conf.5.xml:4636 msgid "second_prompt" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4432 +#: sssd.conf.5.xml:4637 msgid "to change the string of the prompt for the second factor" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4435 +#: sssd.conf.5.xml:4640 msgid "single_prompt" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4436 +#: sssd.conf.5.xml:4641 msgid "" "boolean value, if True there will be only a single prompt using the value of " "first_prompt where it is expected that both factors are entered as a single " @@ -5163,7 +5400,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4425 +#: sssd.conf.5.xml:4630 msgid "" "to configure two-factor authentication prompting, allowed options are: " "<placeholder type=\"variablelist\" id=\"0\"/> If the second factor is " @@ -5172,7 +5409,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4449 +#: sssd.conf.5.xml:4654 msgid "" "Some clients, such as SSH with 'PasswordAuthentication yes', generate their " "own prompts and do not use prompts provided by SSSD or other PAM modules. " @@ -5183,17 +5420,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4464 +#: sssd.conf.5.xml:4669 msgid "[prompting/passkey]" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:4470 sssd-ad.5.xml:1022 +#: sssd.conf.5.xml:4675 sssd.conf.5.xml:4719 sssd-ad.5.xml:1027 msgid "interactive" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4472 +#: sssd.conf.5.xml:4677 msgid "" "boolean value, if True prompt a message and wait before testing the presence " "of a passkey device. Recommended if your device doesn’t have a tactile " @@ -5201,55 +5438,131 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4480 +#: sssd.conf.5.xml:4685 sssd.conf.5.xml:4735 msgid "interactive_prompt" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4482 +#: sssd.conf.5.xml:4687 sssd.conf.5.xml:4737 msgid "to change the message of the interactive prompt." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4487 +#: sssd.conf.5.xml:4692 msgid "touch" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4489 +#: sssd.conf.5.xml:4694 msgid "" "boolean value, if True prompt a message to remind the user to touch the " "device." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4495 +#: sssd.conf.5.xml:4700 msgid "touch_prompt" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4497 +#: sssd.conf.5.xml:4702 msgid "to change the message of the touch prompt." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4466 +#: sssd.conf.5.xml:4671 msgid "" "to configure passkey authentication prompting, allowed options are: " "<placeholder type=\"variablelist\" id=\"0\"/>" msgstr "" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4713 +msgid "[prompting/oauth2]" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4721 +msgid "" +"boolean value, if True prompt a message after asking the user to " +"authenticate, and wait before requesting the access token." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4725 +msgid "" +"If False, make sure to set the <quote>idp_request_timeout</quote> " +"sufficiently high, to give the user time to authenticate." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4715 +msgid "" +"to configure OAuth2 authentication prompting, allowed options are: " +"<placeholder type=\"variablelist\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4748 +msgid "[prompting/cert_auth]" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4754 +msgid "pin_prompt" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4756 +msgid "" +"to change the message which asks the user to enter the PIN at the computer " +"keyboard. At the end of the message the token name is printed." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4764 +msgid "keypad_prompt" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4766 +msgid "" +"to change the message which asks the user to enter the PIN at keypad of the " +"Smartcard reader. At the end of the message the token name is printed." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4774 +msgid "user_name_hint" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4776 +msgid "" +"boolean value, if True ask for a user name if no name was given before and " +"the found certificate can be mapped to more than one user." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4750 +msgid "" +"to configure Smartcard authentication prompting, allowed options are: " +"<placeholder type=\"variablelist\" id=\"0\"/>" +msgstr "" + #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4406 +#: sssd.conf.5.xml:4611 msgid "" "Each supported authentication method has its own configuration subsection " "under <quote>[prompting/...]</quote>. Currently there are: <placeholder " "type=\"variablelist\" id=\"0\"/> <placeholder type=\"variablelist\" id=\"1\"/" -"> <placeholder type=\"variablelist\" id=\"2\"/>" +"> <placeholder type=\"variablelist\" id=\"2\"/> <placeholder " +"type=\"variablelist\" id=\"3\"/> <placeholder type=\"variablelist\" id=\"4\"/" +">" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4508 +#: sssd.conf.5.xml:4792 msgid "" "It is possible to add a subsection for specific PAM services, e.g. " "<quote>[prompting/password/sshd]</quote> to individual change the prompting " @@ -5257,12 +5570,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:4515 pam_sss_gss.8.xml:157 idmap_sss.8.xml:43 +#: sssd.conf.5.xml:4799 pam_sss_gss.8.xml:157 idmap_sss.8.xml:43 msgid "EXAMPLES" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd.conf.5.xml:4521 +#: sssd.conf.5.xml:4805 #, no-wrap msgid "" "[sssd]\n" @@ -5291,7 +5604,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4517 +#: sssd.conf.5.xml:4801 msgid "" "1. The following example shows a typical SSSD config. It does not describe " "configuration of the domains themselves - refer to documentation on " @@ -5300,7 +5613,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd.conf.5.xml:4553 +#: sssd.conf.5.xml:4837 #, no-wrap msgid "" "[domain/ipa.com/child.ad.com]\n" @@ -5308,7 +5621,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4547 +#: sssd.conf.5.xml:4831 msgid "" "2. The following example shows configuration of IPA AD trust where the AD " "forest consists of two domains in a parent-child structure. Suppose IPA " @@ -5319,7 +5632,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd.conf.5.xml:4564 +#: sssd.conf.5.xml:4848 #, no-wrap msgid "" "[certmap/my.domain/rule_name]\n" @@ -5330,7 +5643,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4558 +#: sssd.conf.5.xml:4842 msgid "" "3. The following example shows the configuration of a certificate mapping " "rule. It is valid for the configured domain <quote>my.domain</quote> and " @@ -5527,7 +5840,7 @@ msgid "" "defaultNamingContext does not exist or has an empty value namingContexts is " "used. The namingContexts attribute must have a single value with the DN of " "the search base of the LDAP server to make this work. Multiple values are " -"are not supported." +"not supported." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> @@ -5828,15 +6141,15 @@ msgid "Optional. Use the given string as search base for host objects." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap.5.xml:472 sssd-ipa.5.xml:506 sssd-ipa.5.xml:525 sssd-ipa.5.xml:544 -#: sssd-ipa.5.xml:563 +#: sssd-ldap.5.xml:472 sssd-ipa.5.xml:501 sssd-ipa.5.xml:520 sssd-ipa.5.xml:539 +#: sssd-ipa.5.xml:558 msgid "" "See <quote>ldap_search_base</quote> for information about configuring " "multiple search bases." msgstr "" #. type: Content of: <listitem><para> -#: sssd-ldap.5.xml:477 sssd-ipa.5.xml:511 include/ldap_search_bases.xml:27 +#: sssd-ldap.5.xml:477 sssd-ipa.5.xml:506 include/ldap_search_bases.xml:27 msgid "Default: the value of <emphasis>ldap_search_base</emphasis>" msgstr "" @@ -5960,7 +6273,7 @@ msgid "" "closed early to ensure that a new query cannot require the connection to " "remain open past its expiration. This implies that connections will always " "be closed immediately and will never be reused if " -"<emphasis>ldap_connection_expire_timeout <= ldap_opt_timout</emphasis>" +"<emphasis>ldap_connection_expire_timeout <= ldap_opt_timeout</emphasis>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> @@ -6142,7 +6455,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:831 -msgid "ldap_ignore_unreadable_references (bool)" +msgid "ldap_ignore_unreadable_references (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> @@ -6467,7 +6780,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap.5.xml:1152 sssd-ad.5.xml:1267 +#: sssd-ldap.5.xml:1152 sssd-ad.5.xml:1260 msgid "Default: 86400 (24 hours)" msgstr "" @@ -6505,7 +6818,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ldap.5.xml:1187 sssd-ipa.5.xml:575 sssd-krb5.5.xml:103 +#: sssd-ldap.5.xml:1187 sssd-ipa.5.xml:570 sssd-krb5.5.xml:103 msgid "krb5_realm (string)" msgstr "" @@ -6661,7 +6974,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1339 -msgid "ldap_chpass_update_last_change (bool)" +msgid "ldap_chpass_update_last_change (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> @@ -6808,7 +7121,7 @@ msgid "ldap_access_order (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap.5.xml:1470 sssd-ipa.5.xml:405 +#: sssd-ldap.5.xml:1470 sssd-ipa.5.xml:400 msgid "Comma separated list of access control options. Allowed values are:" msgstr "" @@ -6853,7 +7166,7 @@ msgid "<emphasis>expire</emphasis>: use ldap_account_expire_policy" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap.5.xml:1515 sssd-ipa.5.xml:413 +#: sssd-ldap.5.xml:1515 sssd-ipa.5.xml:408 msgid "" "<emphasis>pwd_expire_policy_reject, pwd_expire_policy_warn, " "pwd_expire_policy_renew: </emphasis> These options are useful if users are " @@ -6863,24 +7176,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap.5.xml:1525 sssd-ipa.5.xml:423 +#: sssd-ldap.5.xml:1525 sssd-ipa.5.xml:418 msgid "" "The difference between these options is the action taken if user password is " "expired:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ldap.5.xml:1530 sssd-ipa.5.xml:428 +#: sssd-ldap.5.xml:1530 sssd-ipa.5.xml:423 msgid "pwd_expire_policy_reject - user is denied to log in," msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ldap.5.xml:1536 sssd-ipa.5.xml:434 +#: sssd-ldap.5.xml:1536 sssd-ipa.5.xml:429 msgid "pwd_expire_policy_warn - user is still able to log in," msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ldap.5.xml:1542 sssd-ipa.5.xml:440 +#: sssd-ldap.5.xml:1542 sssd-ipa.5.xml:435 msgid "" "pwd_expire_policy_renew - user is prompted to change their password " "immediately." @@ -7415,8 +7728,8 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd-ldap.5.xml:2032 sssd-simple.5.xml:169 sssd-ipa.5.xml:984 -#: sssd-ad.5.xml:1470 sssd-idp.5.xml:248 sssd-krb5.5.xml:483 +#: sssd-ldap.5.xml:2032 sssd-simple.5.xml:169 sssd-ipa.5.xml:979 +#: sssd-ad.5.xml:1463 sssd-idp.5.xml:343 sssd-krb5.5.xml:483 #: sss_rpcidmapd.5.xml:98 sssd-session-recording.5.xml:176 msgid "EXAMPLE" msgstr "" @@ -7444,7 +7757,7 @@ msgstr "" #. type: Content of: <refsect1><refsect2><para> #: sssd-ldap.5.xml:2039 sssd-ldap.5.xml:2057 sssd-simple.5.xml:177 -#: sssd-ipa.5.xml:992 sssd-ad.5.xml:1478 sssd-sudo.5.xml:56 sssd-krb5.5.xml:492 +#: sssd-ipa.5.xml:987 sssd-ad.5.xml:1471 sssd-sudo.5.xml:56 sssd-krb5.5.xml:492 #: sssd-session-recording.5.xml:182 include/ldap_id_mapping.xml:105 msgid "<placeholder type=\"programlisting\" id=\"0\"/>" msgstr "" @@ -7479,7 +7792,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><title> #: sssd-ldap.5.xml:2073 sssd_krb5_locator_plugin.8.xml:83 sssd-simple.5.xml:189 -#: sssd-ad.5.xml:1493 sssd.8.xml:270 sss_seed.8.xml:163 +#: sssd-ad.5.xml:1486 sssd.8.xml:270 sss_seed.8.xml:163 msgid "NOTES" msgstr "" @@ -7986,7 +8299,7 @@ msgstr "" #: pam_sss.8.xml:434 msgid "" "No authentication method was found by Kerberos. This might happen if the " -"user has a Smartcard assigned but the pkint plugin is not available on the " +"user has a Smartcard assigned but the pkinit plugin is not available on the " "client." msgstr "" @@ -8410,6 +8723,23 @@ msgid "" "first DNS resolving failure." msgstr "" +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_locator_plugin.8.xml:106 +msgid "" +"If the environment variable SSSD_KRB5_LOCATOR_KDC_ADDRESS is set to a KDC " +"address the plugin will use this address instead of reading the kdcinfo " +"file. The address format is the same as in the kdcinfo file (see above)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_locator_plugin.8.xml:112 +msgid "" +"If the environment variable SSSD_KRB5_LOCATOR_KPASSWD_ADDRESS is set to a " +"kpasswd server address the plugin will use this address instead of reading " +"the kpasswdinfo file. The address format is the same as in the kpasswdinfo " +"file (see above)." +msgstr "" + #. type: Content of: <reference><refentry><refnamediv><refname> #: sssd-simple.5.xml:10 sssd-simple.5.xml:16 msgid "sssd-simple" @@ -9793,7 +10123,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:129 sssd-ad.5.xml:1161 +#: sssd-ipa.5.xml:129 sssd-ad.5.xml:1166 msgid "dyndns_update (boolean)" msgstr "" @@ -9807,20 +10137,13 @@ msgid "" "quote> option." msgstr "" -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:141 sssd-ad.5.xml:1175 -msgid "" -"NOTE: On older systems (such as RHEL 5), for this behavior to work reliably, " -"the default Kerberos realm must be set properly in /etc/krb5.conf" -msgstr "" - #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:152 sssd-ad.5.xml:1186 +#: sssd-ipa.5.xml:147 sssd-ad.5.xml:1186 msgid "dyndns_ttl (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:155 sssd-ad.5.xml:1189 +#: sssd-ipa.5.xml:150 sssd-ad.5.xml:1189 msgid "" "The TTL to apply to the client DNS record when updating it. If " "dyndns_update is false this has no effect. This will override the TTL " @@ -9828,17 +10151,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:160 +#: sssd-ipa.5.xml:155 msgid "Default: 1200 (seconds)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:166 sssd-ad.5.xml:1200 +#: sssd-ipa.5.xml:161 sssd-ad.5.xml:1200 msgid "dyndns_iface (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:169 sssd-ad.5.xml:1203 +#: sssd-ipa.5.xml:164 sssd-ad.5.xml:1203 msgid "" "Optional. Applicable only when dyndns_update is true. Choose the interface " "or a list of interfaces whose IP addresses should be used for dynamic DNS " @@ -9850,24 +10173,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:182 +#: sssd-ipa.5.xml:177 msgid "" "Default: Use the IP addresses of the interface which is used for IPA LDAP " "connection" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:186 sssd-ad.5.xml:1226 +#: sssd-ipa.5.xml:181 sssd-ad.5.xml:1220 msgid "Example: dyndns_iface = em[12], !vnet1, vnet*" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:192 sssd-ad.5.xml:1232 +#: sssd-ipa.5.xml:187 sssd-ad.5.xml:1226 msgid "dyndns_address (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:195 sssd-ad.5.xml:1235 +#: sssd-ipa.5.xml:190 sssd-ad.5.xml:1229 msgid "" "Optional. Applicable only when <emphasis>dyndns_update</emphasis> is true. " "A list of IP addresses or IP networks to be used for dynamic DNS updates. " @@ -9878,22 +10201,22 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:206 sssd-ad.5.xml:1246 +#: sssd-ipa.5.xml:201 sssd-ad.5.xml:1240 msgid "Default: No filtering of IP addresses." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:209 sssd-ad.5.xml:1249 +#: sssd-ipa.5.xml:204 sssd-ad.5.xml:1243 msgid "Example: dyndns_address = 10.0.0.0/16, !10.0.1.0/24" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:215 sssd-ad.5.xml:1305 +#: sssd-ipa.5.xml:210 sssd-ad.5.xml:1298 msgid "dyndns_auth (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:218 sssd-ad.5.xml:1308 +#: sssd-ipa.5.xml:213 sssd-ad.5.xml:1301 msgid "" "Whether the nsupdate utility should use GSS-TSIG authentication for secure " "updates with the DNS server, insecure updates can be sent by setting this " @@ -9901,17 +10224,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:224 sssd-ad.5.xml:1314 +#: sssd-ipa.5.xml:219 sssd-ad.5.xml:1307 msgid "Default: GSS-TSIG" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:230 sssd-ad.5.xml:1320 +#: sssd-ipa.5.xml:225 sssd-ad.5.xml:1313 msgid "dyndns_auth_ptr (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:233 sssd-ad.5.xml:1323 +#: sssd-ipa.5.xml:228 sssd-ad.5.xml:1316 msgid "" "Whether the nsupdate utility should use GSS-TSIG authentication for secure " "PTR updates with the DNS server, insecure updates can be sent by setting " @@ -9919,17 +10242,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:239 sssd-ad.5.xml:1329 +#: sssd-ipa.5.xml:234 sssd-ad.5.xml:1322 msgid "Default: Same as dyndns_auth" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:245 sssd-ad.5.xml:1255 +#: sssd-ipa.5.xml:240 sssd-ad.5.xml:1249 msgid "dyndns_refresh_interval (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:248 +#: sssd-ipa.5.xml:243 msgid "" "How often should the back end perform periodic DNS update in addition to the " "automatic update performed when the back end goes online. This option is " @@ -9937,74 +10260,74 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:261 sssd-ad.5.xml:1273 -msgid "dyndns_update_ptr (bool)" +#: sssd-ipa.5.xml:256 sssd-ad.5.xml:1266 +msgid "dyndns_update_ptr (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:264 sssd-ad.5.xml:1276 +#: sssd-ipa.5.xml:259 sssd-ad.5.xml:1269 msgid "" "Whether the PTR record should also be explicitly updated when updating the " "client's DNS records. Applicable only when dyndns_update is true." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:269 +#: sssd-ipa.5.xml:264 msgid "" "This option should be False in most IPA deployments as the IPA server " "generates the PTR records automatically when forward records are changed." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:275 sssd-ad.5.xml:1281 +#: sssd-ipa.5.xml:270 sssd-ad.5.xml:1274 msgid "" "Note that <emphasis>dyndns_update_per_family</emphasis> parameter does not " "apply for PTR record updates. Those updates are always sent separately." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:280 +#: sssd-ipa.5.xml:275 msgid "Default: False (disabled)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:286 sssd-ad.5.xml:1292 -msgid "dyndns_force_tcp (bool)" +#: sssd-ipa.5.xml:281 sssd-ad.5.xml:1285 +msgid "dyndns_force_tcp (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:289 sssd-ad.5.xml:1295 +#: sssd-ipa.5.xml:284 sssd-ad.5.xml:1288 msgid "" "Whether the nsupdate utility should default to using TCP for communicating " "with the DNS server." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:293 sssd-ad.5.xml:1299 +#: sssd-ipa.5.xml:288 sssd-ad.5.xml:1292 msgid "Default: False (let nsupdate choose the protocol)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:299 sssd-ad.5.xml:1335 +#: sssd-ipa.5.xml:294 sssd-ad.5.xml:1328 msgid "dyndns_server (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:302 sssd-ad.5.xml:1338 +#: sssd-ipa.5.xml:297 sssd-ad.5.xml:1331 msgid "" "The DNS server to use when performing a DNS update. In most setups, it's " "recommended to leave this option unset." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:307 sssd-ad.5.xml:1343 +#: sssd-ipa.5.xml:302 sssd-ad.5.xml:1336 msgid "" "Setting this option makes sense for environments where the DNS server is " "different from the identity server or when we use encrypted DNS." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:312 sssd-ad.5.xml:1348 +#: sssd-ipa.5.xml:307 sssd-ad.5.xml:1341 msgid "" "The parameter can be a simple string containing DNS name or IP address. It " "can also be an URI. The URI can look like <emphasis>dns://servername/</" @@ -10012,7 +10335,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:319 sssd-ad.5.xml:1355 +#: sssd-ipa.5.xml:314 sssd-ad.5.xml:1348 msgid "" "The second example enables DNS-over-TLS protocol for DNS updates. The " "nsupdate utility must support DoT - check the <emphasis>man nsupdate</" @@ -10020,7 +10343,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:325 sssd-ad.5.xml:1361 +#: sssd-ipa.5.xml:320 sssd-ad.5.xml:1354 msgid "" "Please note that this option will be only used in fallback attempt when " "previous attempt using autodetected settings failed or when DNS-over-TLS is " @@ -10028,17 +10351,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:331 sssd-ad.5.xml:1367 +#: sssd-ipa.5.xml:326 sssd-ad.5.xml:1360 msgid "Default: None (let nsupdate choose the server)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:337 sssd-ad.5.xml:1373 +#: sssd-ipa.5.xml:332 sssd-ad.5.xml:1366 msgid "dyndns_update_per_family (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:340 sssd-ad.5.xml:1376 +#: sssd-ipa.5.xml:335 sssd-ad.5.xml:1369 msgid "" "DNS update is by default performed in two steps - IPv4 update and then IPv6 " "update. In some cases it might be desirable to perform IPv4 and IPv6 update " @@ -10046,12 +10369,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:352 sssd-ad.5.xml:1388 +#: sssd-ipa.5.xml:347 sssd-ad.5.xml:1381 msgid "dyndns_dot_cacert (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:355 sssd-ad.5.xml:1391 +#: sssd-ipa.5.xml:350 sssd-ad.5.xml:1384 msgid "" "This option specifies the file of the certificate authorities certificates " "(in PEM format) in order to verify the remote server TLS certificate when " @@ -10059,17 +10382,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:361 sssd-ad.5.xml:1397 +#: sssd-ipa.5.xml:356 sssd-ad.5.xml:1390 msgid "Default: None (use global certificate store)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:367 sssd-ad.5.xml:1403 +#: sssd-ipa.5.xml:362 sssd-ad.5.xml:1396 msgid "dyndns_dot_cert (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:370 sssd-ad.5.xml:1406 +#: sssd-ipa.5.xml:365 sssd-ad.5.xml:1399 msgid "" "This option sets the certificate(s) file for authentication for the DoT " "transport to the remote server. The certificate chain file is expected to be " @@ -10077,24 +10400,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:376 sssd-ad.5.xml:1412 +#: sssd-ipa.5.xml:371 sssd-ad.5.xml:1405 msgid "" "The <emphasis>dyndns_dot_cert</emphasis> and <emphasis>dyndns_dot_key</" "emphasis> options must be both set to achieve mutual TLS authentication." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:381 sssd-ipa.5.xml:396 sssd-ad.5.xml:1417 sssd-ad.5.xml:1432 +#: sssd-ipa.5.xml:376 sssd-ipa.5.xml:391 sssd-ad.5.xml:1410 sssd-ad.5.xml:1425 msgid "Default: None (Do not use TLS authentication)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:387 sssd-ad.5.xml:1423 +#: sssd-ipa.5.xml:382 sssd-ad.5.xml:1416 msgid "dyndns_dot_key (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:390 sssd-ad.5.xml:1426 +#: sssd-ipa.5.xml:385 sssd-ad.5.xml:1419 msgid "" "This option sets the key file for authenticated encryption for the DoT " "transport to the remote server. The private key file is expected to be in " @@ -10102,170 +10425,170 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:402 +#: sssd-ipa.5.xml:397 msgid "ipa_access_order (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:409 +#: sssd-ipa.5.xml:404 msgid "<emphasis>expire</emphasis>: use IPA's account expiration policy." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:448 +#: sssd-ipa.5.xml:443 msgid "" "Please note that 'access_provider = ipa' must be set for this feature to " "work." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:455 +#: sssd-ipa.5.xml:450 msgid "ipa_deskprofile_search_base (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:458 +#: sssd-ipa.5.xml:453 msgid "" "Optional. Use the given string as search base for Desktop Profile related " "objects." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:462 sssd-ipa.5.xml:484 +#: sssd-ipa.5.xml:457 sssd-ipa.5.xml:479 msgid "Default: Use base DN" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:468 +#: sssd-ipa.5.xml:463 msgid "ipa_subid_ranges_search_base (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:471 +#: sssd-ipa.5.xml:466 msgid "Deprecated. Use ldap_subid_ranges_search_base instead." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:477 +#: sssd-ipa.5.xml:472 msgid "ipa_hbac_search_base (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:480 +#: sssd-ipa.5.xml:475 msgid "Optional. Use the given string as search base for HBAC related objects." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:490 +#: sssd-ipa.5.xml:485 msgid "ipa_host_search_base (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:493 +#: sssd-ipa.5.xml:488 msgid "Deprecated. Use ldap_host_search_base instead." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:499 +#: sssd-ipa.5.xml:494 msgid "ipa_selinux_search_base (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:502 +#: sssd-ipa.5.xml:497 msgid "Optional. Use the given string as search base for SELinux user maps." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:518 +#: sssd-ipa.5.xml:513 msgid "ipa_subdomains_search_base (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:521 +#: sssd-ipa.5.xml:516 msgid "Optional. Use the given string as search base for trusted domains." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:530 +#: sssd-ipa.5.xml:525 msgid "Default: the value of <emphasis>cn=trusts,%basedn</emphasis>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:537 +#: sssd-ipa.5.xml:532 msgid "ipa_master_domain_search_base (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:540 +#: sssd-ipa.5.xml:535 msgid "Optional. Use the given string as search base for master domain object." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:549 +#: sssd-ipa.5.xml:544 msgid "Default: the value of <emphasis>cn=ad,cn=etc,%basedn</emphasis>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:556 +#: sssd-ipa.5.xml:551 msgid "ipa_views_search_base (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:559 +#: sssd-ipa.5.xml:554 msgid "Optional. Use the given string as search base for views containers." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:568 +#: sssd-ipa.5.xml:563 msgid "Default: the value of <emphasis>cn=views,cn=accounts,%basedn</emphasis>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:578 +#: sssd-ipa.5.xml:573 msgid "" "The name of the Kerberos realm. This is optional and defaults to the value " "of <quote>ipa_domain</quote>." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:582 +#: sssd-ipa.5.xml:577 msgid "" "The name of the Kerberos realm has a special meaning in IPA - it is " "converted into the base DN to use for performing LDAP operations." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:590 sssd-ad.5.xml:1441 +#: sssd-ipa.5.xml:585 sssd-ad.5.xml:1434 msgid "krb5_confd_path (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:593 sssd-ad.5.xml:1444 +#: sssd-ipa.5.xml:588 sssd-ad.5.xml:1437 msgid "" "Absolute path of a directory where SSSD should place Kerberos configuration " "snippets." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:597 sssd-ad.5.xml:1448 +#: sssd-ipa.5.xml:592 sssd-ad.5.xml:1441 msgid "" "To disable the creation of the configuration snippets set the parameter to " "'none'." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:601 sssd-ad.5.xml:1452 +#: sssd-ipa.5.xml:596 sssd-ad.5.xml:1445 msgid "" "Default: not set (krb5.include.d subdirectory of SSSD's pubconf directory)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:608 +#: sssd-ipa.5.xml:603 msgid "ipa_deskprofile_refresh (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:611 +#: sssd-ipa.5.xml:606 msgid "" "The amount of time between lookups of the Desktop Profile rules against the " "IPA server. This will reduce the latency and load on the IPA server if there " @@ -10273,34 +10596,34 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:618 sssd-ipa.5.xml:648 sssd-ipa.5.xml:664 sssd-ad.5.xml:600 +#: sssd-ipa.5.xml:613 sssd-ipa.5.xml:643 sssd-ipa.5.xml:659 sssd-ad.5.xml:600 msgid "Default: 5 (seconds)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:624 +#: sssd-ipa.5.xml:619 msgid "ipa_deskprofile_request_interval (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:627 +#: sssd-ipa.5.xml:622 msgid "" "The amount of time between lookups of the Desktop Profile rules against the " "IPA server in case the last request did not return any rule." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:632 +#: sssd-ipa.5.xml:627 msgid "Default: 60 (minutes)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:638 +#: sssd-ipa.5.xml:633 msgid "ipa_hbac_refresh (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:641 +#: sssd-ipa.5.xml:636 msgid "" "The amount of time between lookups of the HBAC rules against the IPA server. " "This will reduce the latency and load on the IPA server if there are many " @@ -10308,12 +10631,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:654 -msgid "ipa_hbac_selinux (integer)" +#: sssd-ipa.5.xml:649 +msgid "ipa_selinux_refresh (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:657 +#: sssd-ipa.5.xml:652 msgid "" "The amount of time between lookups of the SELinux maps against the IPA " "server. This will reduce the latency and load on the IPA server if there are " @@ -10321,33 +10644,33 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:670 +#: sssd-ipa.5.xml:665 msgid "ipa_server_mode (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:673 +#: sssd-ipa.5.xml:668 msgid "" "This option will be set by the IPA installer (ipa-server-install) " "automatically and denotes if SSSD is running on an IPA server or not." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:678 +#: sssd-ipa.5.xml:673 msgid "" "On an IPA server SSSD will lookup users and groups from trusted domains " "directly while on a client it will ask an IPA server." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:683 +#: sssd-ipa.5.xml:678 msgid "" "NOTE: There are currently some assumptions that must be met when SSSD is " "running on an IPA server." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:688 +#: sssd-ipa.5.xml:683 msgid "" "The <quote>ipa_server</quote> option must be configured to point to the IPA " "server itself. This is already the default set by the IPA installer, so no " @@ -10355,59 +10678,59 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:697 +#: sssd-ipa.5.xml:692 msgid "" "The <quote>full_name_format</quote> option must not be tweaked to only print " "short names for users from trusted domains." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:712 +#: sssd-ipa.5.xml:707 msgid "ipa_automount_location (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:715 +#: sssd-ipa.5.xml:710 msgid "The automounter location this IPA client will be using" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:718 +#: sssd-ipa.5.xml:713 msgid "Default: The location named \"default\"" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd-ipa.5.xml:726 +#: sssd-ipa.5.xml:721 msgid "VIEWS AND OVERRIDES" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:735 +#: sssd-ipa.5.xml:730 msgid "ipa_view_class (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:738 +#: sssd-ipa.5.xml:733 msgid "Objectclass of the view container." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:741 +#: sssd-ipa.5.xml:736 msgid "Default: nsContainer" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:747 +#: sssd-ipa.5.xml:742 msgid "ipa_view_name (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:750 +#: sssd-ipa.5.xml:745 msgid "Name of the attribute holding the name of the view." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:754 sssd-ldap-attributes.5.xml:496 +#: sssd-ipa.5.xml:749 sssd-ldap-attributes.5.xml:496 #: sssd-ldap-attributes.5.xml:832 sssd-ldap-attributes.5.xml:913 #: sssd-ldap-attributes.5.xml:1010 sssd-ldap-attributes.5.xml:1068 #: sssd-ldap-attributes.5.xml:1226 sssd-ldap-attributes.5.xml:1271 @@ -10415,128 +10738,128 @@ msgid "Default: cn" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:760 +#: sssd-ipa.5.xml:755 msgid "ipa_override_object_class (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:763 +#: sssd-ipa.5.xml:758 msgid "Objectclass of the override objects." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:766 +#: sssd-ipa.5.xml:761 msgid "Default: ipaOverrideAnchor" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:772 +#: sssd-ipa.5.xml:767 msgid "ipa_anchor_uuid (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:775 +#: sssd-ipa.5.xml:770 msgid "" "Name of the attribute containing the reference to the original object in a " "remote domain." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:779 +#: sssd-ipa.5.xml:774 msgid "Default: ipaAnchorUUID" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:785 +#: sssd-ipa.5.xml:780 msgid "ipa_user_override_object_class (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:788 +#: sssd-ipa.5.xml:783 msgid "" "Name of the objectclass for user overrides. It is used to determine if the " "found override object is related to a user or a group." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:793 +#: sssd-ipa.5.xml:788 msgid "User overrides can contain attributes given by" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:796 +#: sssd-ipa.5.xml:791 msgid "ldap_user_name" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:799 +#: sssd-ipa.5.xml:794 msgid "ldap_user_uid_number" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:802 +#: sssd-ipa.5.xml:797 msgid "ldap_user_gid_number" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:805 +#: sssd-ipa.5.xml:800 msgid "ldap_user_gecos" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:808 +#: sssd-ipa.5.xml:803 msgid "ldap_user_home_directory" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:811 +#: sssd-ipa.5.xml:806 msgid "ldap_user_shell" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:814 +#: sssd-ipa.5.xml:809 msgid "ldap_user_ssh_public_key" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:819 +#: sssd-ipa.5.xml:814 msgid "Default: ipaUserOverride" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:825 +#: sssd-ipa.5.xml:820 msgid "ipa_group_override_object_class (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:828 +#: sssd-ipa.5.xml:823 msgid "" "Name of the objectclass for group overrides. It is used to determine if the " "found override object is related to a user or a group." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:833 +#: sssd-ipa.5.xml:828 msgid "Group overrides can contain attributes given by" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:836 +#: sssd-ipa.5.xml:831 msgid "ldap_group_name" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:839 +#: sssd-ipa.5.xml:834 msgid "ldap_group_gid_number" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:844 +#: sssd-ipa.5.xml:839 msgid "Default: ipaGroupOverride" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:728 +#: sssd-ipa.5.xml:723 msgid "" "SSSD can handle views and overrides which are offered by FreeIPA 4.1 and " "later version. Since all paths and objectclasses are fixed on the server " @@ -10546,19 +10869,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd-ipa.5.xml:856 +#: sssd-ipa.5.xml:851 msgid "SUBDOMAINS PROVIDER" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:858 +#: sssd-ipa.5.xml:853 msgid "" "The IPA subdomains provider behaves slightly differently if it is configured " "explicitly or implicitly." msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:862 +#: sssd-ipa.5.xml:857 msgid "" "If the option 'subdomains_provider = ipa' is found in the domain section of " "sssd.conf, the IPA subdomains provider is configured explicitly, and all " @@ -10566,7 +10889,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:868 +#: sssd-ipa.5.xml:863 msgid "" "If the option 'subdomains_provider' is not set in the domain section of " "sssd.conf but there is the option 'id_provider = ipa', the IPA subdomains " @@ -10578,12 +10901,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd-ipa.5.xml:879 +#: sssd-ipa.5.xml:874 msgid "TRUSTED DOMAINS CONFIGURATION" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-ipa.5.xml:887 +#: sssd-ipa.5.xml:882 #, no-wrap msgid "" "[domain/ipa.domain.com/ad.domain.com]\n" @@ -10591,7 +10914,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:881 +#: sssd-ipa.5.xml:876 msgid "" "Some configuration options can also be set for a trusted domain. A trusted " "domain configuration can be set using the trusted domain subsection as shown " @@ -10601,97 +10924,97 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:892 +#: sssd-ipa.5.xml:887 msgid "" "For more details, see the <citerefentry> <refentrytitle>sssd.conf</" "refentrytitle> <manvolnum>5</manvolnum> </citerefentry> manual page." msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:899 +#: sssd-ipa.5.xml:894 msgid "" "Different configuration options are tunable for a trusted domain depending " "on whether you are configuring SSSD on an IPA server or an IPA client." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd-ipa.5.xml:904 +#: sssd-ipa.5.xml:899 msgid "OPTIONS TUNABLE ON IPA MASTERS" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:906 +#: sssd-ipa.5.xml:901 msgid "" "The following options can be set in a subdomain section on an IPA master:" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:910 sssd-ipa.5.xml:950 +#: sssd-ipa.5.xml:905 sssd-ipa.5.xml:945 msgid "ad_server" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:913 +#: sssd-ipa.5.xml:908 msgid "ad_backup_server" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:916 sssd-ipa.5.xml:953 +#: sssd-ipa.5.xml:911 sssd-ipa.5.xml:948 msgid "ad_site" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:919 +#: sssd-ipa.5.xml:914 msgid "ipa_server" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:922 +#: sssd-ipa.5.xml:917 msgid "ipa_backup_server" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:925 +#: sssd-ipa.5.xml:920 msgid "ldap_search_base" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:928 +#: sssd-ipa.5.xml:923 msgid "ldap_user_search_base" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:931 +#: sssd-ipa.5.xml:926 msgid "ldap_group_search_base" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:939 +#: sssd-ipa.5.xml:934 msgid "" "Options prefixed with 'ad_' or 'ipa_' only apply to their respective " "subdomain type." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd-ipa.5.xml:944 +#: sssd-ipa.5.xml:939 msgid "OPTIONS TUNABLE ON IPA CLIENTS" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:946 +#: sssd-ipa.5.xml:941 msgid "" "The following options can be set in an AD subdomain section on an IPA client:" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:958 +#: sssd-ipa.5.xml:953 msgid "" "Note that if both options are set, only <quote>ad_server</quote> is " "evaluated." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:962 +#: sssd-ipa.5.xml:957 msgid "" "Since any request for a user or a group identity from a trusted domain " "triggered from an IPA client is resolved by the IPA server, the " @@ -10705,7 +11028,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:986 +#: sssd-ipa.5.xml:981 msgid "" "The following example assumes that SSSD is correctly configured and " "example.com is one of the domains in the <replaceable>[sssd]</replaceable> " @@ -10713,7 +11036,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-ipa.5.xml:993 +#: sssd-ipa.5.xml:988 #, no-wrap msgid "" "[domain/example.com]\n" @@ -11412,27 +11735,27 @@ msgid "lxdm" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:694 +#: sssd-ad.5.xml:699 msgid "sddm" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:699 +#: sssd-ad.5.xml:704 msgid "unity" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:704 +#: sssd-ad.5.xml:709 msgid "xdm" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:713 +#: sssd-ad.5.xml:718 msgid "ad_gpo_map_remote_interactive (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:716 +#: sssd-ad.5.xml:721 msgid "" "A comma-separated list of PAM service names for which GPO-based access " "control is evaluated based on the RemoteInteractiveLogonRight and " @@ -11448,7 +11771,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:735 +#: sssd-ad.5.xml:740 msgid "" "Note: Using the Group Policy Management Editor this value is called \"Allow " "log on through Remote Desktop Services\" and \"Deny log on through Remote " @@ -11456,7 +11779,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:750 +#: sssd-ad.5.xml:755 #, no-wrap msgid "" "ad_gpo_map_remote_interactive = +my_pam_service, -sshd\n" @@ -11464,7 +11787,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:741 +#: sssd-ad.5.xml:746 msgid "" "It is possible to add another PAM service name to the default set by using " "<quote>+service_name</quote> or to explicitly remove a PAM service name from " @@ -11476,22 +11799,22 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:758 +#: sssd-ad.5.xml:763 msgid "sshd" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:763 +#: sssd-ad.5.xml:768 msgid "cockpit" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:772 +#: sssd-ad.5.xml:777 msgid "ad_gpo_map_network (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:775 +#: sssd-ad.5.xml:780 msgid "" "A comma-separated list of PAM service names for which GPO-based access " "control is evaluated based on the NetworkLogonRight and " @@ -11507,7 +11830,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:793 +#: sssd-ad.5.xml:798 msgid "" "Note: Using the Group Policy Management Editor this value is called \"Access " "this computer from the network\" and \"Deny access to this computer from the " @@ -11515,7 +11838,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:808 +#: sssd-ad.5.xml:813 #, no-wrap msgid "" "ad_gpo_map_network = +my_pam_service, -ftp\n" @@ -11523,7 +11846,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:799 +#: sssd-ad.5.xml:804 msgid "" "It is possible to add another PAM service name to the default set by using " "<quote>+service_name</quote> or to explicitly remove a PAM service name from " @@ -11535,22 +11858,22 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:816 +#: sssd-ad.5.xml:821 msgid "ftp" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:821 +#: sssd-ad.5.xml:826 msgid "samba" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:830 +#: sssd-ad.5.xml:835 msgid "ad_gpo_map_batch (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:833 +#: sssd-ad.5.xml:838 msgid "" "A comma-separated list of PAM service names for which GPO-based access " "control is evaluated based on the BatchLogonRight and DenyBatchLogonRight " @@ -11565,14 +11888,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:851 +#: sssd-ad.5.xml:856 msgid "" "Note: Using the Group Policy Management Editor this value is called \"Allow " "log on as a batch job\" and \"Deny log on as a batch job\"." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:865 +#: sssd-ad.5.xml:870 #, no-wrap msgid "" "ad_gpo_map_batch = +my_pam_service, -crond\n" @@ -11580,7 +11903,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:856 +#: sssd-ad.5.xml:861 msgid "" "It is possible to add another PAM service name to the default set by using " "<quote>+service_name</quote> or to explicitly remove a PAM service name from " @@ -11592,23 +11915,23 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:868 +#: sssd-ad.5.xml:873 msgid "" "Note: Cron service name may differ depending on Linux distribution used." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:874 +#: sssd-ad.5.xml:879 msgid "crond" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:883 +#: sssd-ad.5.xml:888 msgid "ad_gpo_map_service (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:886 +#: sssd-ad.5.xml:891 msgid "" "A comma-separated list of PAM service names for which GPO-based access " "control is evaluated based on the ServiceLogonRight and " @@ -11624,14 +11947,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:904 +#: sssd-ad.5.xml:909 msgid "" "Note: Using the Group Policy Management Editor this value is called \"Allow " "log on as a service\" and \"Deny log on as a service\"." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:917 +#: sssd-ad.5.xml:922 #, no-wrap msgid "" "ad_gpo_map_service = +my_pam_service\n" @@ -11639,7 +11962,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:909 sssd-ad.5.xml:984 +#: sssd-ad.5.xml:914 sssd-ad.5.xml:989 msgid "" "It is possible to add a PAM service name to the default set by using " "<quote>+service_name</quote>. Since the default set is empty, it is not " @@ -11650,19 +11973,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:927 +#: sssd-ad.5.xml:932 msgid "ad_gpo_map_permit (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:930 +#: sssd-ad.5.xml:935 msgid "" "A comma-separated list of PAM service names for which GPO-based access is " "always granted, regardless of any GPO Logon Rights." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:944 +#: sssd-ad.5.xml:949 #, no-wrap msgid "" "ad_gpo_map_permit = +my_pam_service, -sudo\n" @@ -11670,7 +11993,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:935 +#: sssd-ad.5.xml:940 msgid "" "It is possible to add another PAM service name to the default set by using " "<quote>+service_name</quote> or to explicitly remove a PAM service name from " @@ -11682,29 +12005,29 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:952 +#: sssd-ad.5.xml:957 msgid "polkit-1" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:967 +#: sssd-ad.5.xml:972 msgid "systemd-user" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:976 +#: sssd-ad.5.xml:981 msgid "ad_gpo_map_deny (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:979 +#: sssd-ad.5.xml:984 msgid "" "A comma-separated list of PAM service names for which GPO-based access is " "always denied, regardless of any GPO Logon Rights." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:992 +#: sssd-ad.5.xml:997 #, no-wrap msgid "" "ad_gpo_map_deny = +my_pam_service\n" @@ -11712,12 +12035,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:1002 +#: sssd-ad.5.xml:1007 msgid "ad_gpo_default_right (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1005 +#: sssd-ad.5.xml:1010 msgid "" "This option defines how access control is evaluated for PAM service names " "that are not explicitly listed in one of the ad_gpo_map_* options. This " @@ -11730,52 +12053,52 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1018 +#: sssd-ad.5.xml:1023 msgid "Supported values for this option include:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1027 +#: sssd-ad.5.xml:1032 msgid "remote_interactive" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1032 +#: sssd-ad.5.xml:1037 msgid "network" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1037 +#: sssd-ad.5.xml:1042 msgid "batch" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1042 +#: sssd-ad.5.xml:1047 msgid "service" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1047 +#: sssd-ad.5.xml:1052 msgid "permit" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1052 +#: sssd-ad.5.xml:1057 msgid "deny" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1058 +#: sssd-ad.5.xml:1063 msgid "Default: deny" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:1064 +#: sssd-ad.5.xml:1069 msgid "ad_maximum_machine_account_password_age (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1067 +#: sssd-ad.5.xml:1072 msgid "" "SSSD will check once a day if the machine account password is older than the " "given age in days and try to renew it. A value of 0 will disable the renewal " @@ -11783,17 +12106,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1073 +#: sssd-ad.5.xml:1078 msgid "Default: 30 days" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:1079 +#: sssd-ad.5.xml:1084 msgid "ad_machine_account_password_renewal_opts (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1082 +#: sssd-ad.5.xml:1087 msgid "" "This option should only be used to test the machine account renewal task. " "The option expects 3 integers and a string separated by a colon (':'). The " @@ -11806,20 +12129,20 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1096 +#: sssd-ad.5.xml:1101 msgid "" "The optional fourth string value identifies the helper binary which should " "be used for the renewal. Currently <command>adcli</command> and " "<command>realm</command> are supported. If this value is missing or empty in " "the value string <command>realm</command> will be used. Since the helper is " "started as the user SSSD is running as there might be the chance that the " -"renewal will fail if this user does not has permissions to modify the keytab " -"file where the machine account credentials are stored. This will typically " -"be the case for <command>adcli</command>." +"renewal will fail if this user does not have permissions to modify the " +"keytab file where the machine account credentials are stored. This will " +"typically be the case for <command>adcli</command>." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1110 +#: sssd-ad.5.xml:1115 msgid "" "<command>realm</command> is not updating the keytab directly but is calling " "the <command>realmd</command> process, which runs as root user, for this " @@ -11829,17 +12152,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1119 +#: sssd-ad.5.xml:1124 msgid "Default: 86400:750:300:realm (24h, 12m30s and 5m)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:1125 +#: sssd-ad.5.xml:1130 msgid "ad_update_samba_machine_account_password (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1128 +#: sssd-ad.5.xml:1133 msgid "" "If enabled, when SSSD renews the machine account password, it will also be " "updated in Samba's database. This prevents Samba's copy of the machine " @@ -11848,23 +12171,23 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:1141 -msgid "ad_use_ldaps (bool)" +#: sssd-ad.5.xml:1146 +msgid "ad_use_ldaps (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1144 +#: sssd-ad.5.xml:1149 msgid "" "By default SSSD uses the plain LDAP port 389 and the Global Catalog port " -"3628. If this option is set to True SSSD will use the LDAPS port 636 and " -"Global Catalog port 3629 with LDAPS protection. Since AD does not allow to " +"3268. If this option is set to True SSSD will use the LDAPS port 636 and " +"Global Catalog port 3269 with LDAPS protection. Since AD does not allow to " "have multiple encryption layers on a single connection and we still want to " "use SASL/GSSAPI or SASL/GSS-SPNEGO for authentication the SASL security " "property maxssf is set to 0 (zero) for those connections." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1164 +#: sssd-ad.5.xml:1169 msgid "" "Optional. This option tells SSSD to automatically update the Active " "Directory DNS server with the IP address of this client. The update is " @@ -11882,30 +12205,21 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:1216 msgid "" -"NOTE: While it is still possible to use the old <emphasis>ipa_dyndns_iface</" -"emphasis> option, users should migrate to using <emphasis>dyndns_iface</" -"emphasis> in their config file." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1222 -msgid "" "Default: Use the IP addresses of the interface which is used for AD LDAP " "connection" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1258 +#: sssd-ad.5.xml:1252 msgid "" "How often should the back end perform periodic DNS update in addition to the " -"automatic update performed when the back end goes online. This option is " -"optional and applicable only when dyndns_update is true. Note that the " -"lowest possible value is 60 seconds in-case if value is provided less than " -"60, parameter will assume lowest value only." +"automatic update performed when the back end goes online. This is optional " +"and applicable only when dyndns_update is true. Note that the minimum value " +"is 60 seconds, any specified value below this threshold will default to 60." msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ad.5.xml:1472 +#: sssd-ad.5.xml:1465 msgid "" "The following example assumes that SSSD is correctly configured and " "example.com is one of the domains in the <replaceable>[sssd]</replaceable> " @@ -11913,7 +12227,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-ad.5.xml:1479 +#: sssd-ad.5.xml:1472 #, no-wrap msgid "" "[domain/EXAMPLE]\n" @@ -11928,7 +12242,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-ad.5.xml:1499 +#: sssd-ad.5.xml:1492 #, no-wrap msgid "" "access_provider = ldap\n" @@ -11937,7 +12251,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ad.5.xml:1495 +#: sssd-ad.5.xml:1488 msgid "" "The AD access control provider checks if the account is expired. It has the " "same effect as the following configuration of the LDAP provider: " @@ -11945,7 +12259,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ad.5.xml:1505 +#: sssd-ad.5.xml:1498 msgid "" "However, unless the <quote>ad</quote> access control provider is explicitly " "configured, the default access provider is <quote>permit</quote>. Please " @@ -11955,7 +12269,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ad.5.xml:1513 +#: sssd-ad.5.xml:1506 msgid "" "When the autofs provider is set to <quote>ad</quote>, the RFC2307 schema " "attribute mapping (nisMap, nisObject, ...) is used, because these attributes " @@ -12109,9 +12423,9 @@ msgstr "" #: sssd-sudo.5.xml:137 msgid "" "The <emphasis>smart refresh</emphasis> periodically downloads rules that are " -"new or were modified after the last update. Its primary goal is to keep the " -"database growing by fetching only small increments that do not generate " -"large amounts of network traffic." +"new or were modified after the last update. Its primary goal is to grow the " +"database incrementally by fetching only small updates, avoiding large " +"amounts of network traffic." msgstr "" #. type: Content of: <reference><refentry><refsect1><para> @@ -12291,22 +12605,25 @@ msgstr "" msgid "" "Depending on the IdP product additional platform specific options might " "follow the name separated by a colon (:). E.g. for Keycloak the base URI for " -"the user and group REST API must be given. For Entra ID this is not needed " -"because there is a generic endpoint for all tenants." +"the user and group REST API must be given. For Entra ID the base URI for the " +"Microsoft Graph API can be given to use sovereign or government cloud " +"endpoints instead of the default (https://graph.microsoft.com/v1.0). E.g. " +"<quote>entra_id:https://graph.microsoft.us/v1.0</quote> for the US " +"government cloud (GCC High)." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:78 sssd-idp.5.xml:94 sssd-idp.5.xml:119 +#: sssd-idp.5.xml:82 sssd-idp.5.xml:98 sssd-idp.5.xml:123 msgid "Default: Not set (Required)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:83 +#: sssd-idp.5.xml:87 msgid "idp_client_id (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:86 +#: sssd-idp.5.xml:90 msgid "" "ID of the IdP client used by SSSD to authenticate users and as a client to " "lookup user and group attributes. This client must offer device " @@ -12315,12 +12632,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:99 +#: sssd-idp.5.xml:103 msgid "idp_client_secret (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:102 +#: sssd-idp.5.xml:106 msgid "" "Password of the IdP client. The password is required for the id_provider. If " "only used as auth_provider it depends on the server side configuration if it " @@ -12328,66 +12645,73 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:113 +#: sssd-idp.5.xml:117 msgid "idp_token_endpoint (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:116 +#: sssd-idp.5.xml:120 msgid "IdP endpoint for requesting access tokens." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:124 +#: sssd-idp.5.xml:128 msgid "idp_device_auth_endpoint (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:127 +#: sssd-idp.5.xml:131 msgid "" "IdP endpoint for device authorization according to RFC-8628. This is " "required for user authentication." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:137 +#: sssd-idp.5.xml:141 msgid "idp_userinfo_endpoint (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:140 +#: sssd-idp.5.xml:144 msgid "" "IdP userinfo endpoint to request user attributes after a successful " "authentication of the user. Required for authentication." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:150 +#: sssd-idp.5.xml:154 msgid "idp_id_scope (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:153 +#: sssd-idp.5.xml:157 msgid "" "Scope required for looking up user and group attributes with the REST API. " "The scopes are used by the server to determine which attributes/claims are " "returned to the caller." msgstr "" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:163 +msgid "" +"Note: In previous versions of SSSD, this option was expected to already be " +"URL-encoded." +msgstr "" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:164 +#: sssd-idp.5.xml:172 msgid "idp_auth_scope (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:167 +#: sssd-idp.5.xml:175 msgid "" "Scope required during authentication. The scopes are used by the server to " "determine which attributes/claims are returned to the caller." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:172 +#: sssd-idp.5.xml:180 msgid "" "Currently the tokens returned during user authentication are not used for " "other purposes hence the only important claim is the subject identifier " @@ -12396,22 +12720,116 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:185 +#: sssd-idp.5.xml:193 +msgid "idp_auth_user_identifier_attr (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:196 +msgid "" +"Attribute used to identify the authenticated user in userinfo data or token " +"claims." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:200 +msgid "" +"For hybrid Active Directory and Entra ID deployments where " +"<quote>id_provider = ad</quote> and <quote>auth_provider = idp</quote>, this " +"option must be set explicitly. No value is derived from the identity " +"provider, because more than one attribute can link an Entra ID object to its " +"on-premises counterpart and only the administrator knows which one the " +"directory synchronization is configured to use." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:211 +msgid "" +"Setting this option to <quote>onPremisesImmutableId</quote> is the usual " +"choice for such deployments. Microsoft Entra Connect populates that " +"attribute with the base64-encoded form of the 16-byte Active Directory " +"<quote>objectGUID</quote> when objectGUID is used as the sourceAnchor. SSSD " +"decodes the value and converts the raw bytes with the same conversion used " +"for AD objectGUID attributes, so the result matches the UUID stored in the " +"SSSD cache for the AD user." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:224 +msgid "" +"Note that Microsoft Entra Connect 1.1.524.0 and later use <quote>ms-DS-" +"ConsistencyGuid</quote> as the sourceAnchor for user objects instead of " +"<quote>objectGUID</quote>. The value is normally copied from objectGUID for " +"objects that do not have it set yet, in which case the decoded identifier " +"still matches. It does not match if ms-DS-ConsistencyGuid was populated " +"independently, if users were moved between forests or domains, or if a " +"different attribute such as employeeID was selected as the sourceAnchor. See " +"<ulink url=\"https://learn.microsoft.com/en-us/entra/identity/hybrid/connect/" +"plan-connect-design-concepts\"> Microsoft Entra Connect: Design concepts</" +"ulink> for details on sourceAnchor selection." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:241 +msgid "" +"Microsoft Graph does not return <quote>onPremisesImmutableId</quote> by " +"default. The <quote>idp_userinfo_endpoint</quote> must request it with " +"<quote>$select</quote>, see the example below and <ulink url=\"https://" +"learn.microsoft.com/en-us/graph/api/resources/user\"> the Microsoft Graph " +"user resource type</ulink>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:251 +msgid "" +"If the configured attribute is missing or cannot be decoded (for example " +"cloud-only Entra ID users without <quote>onPremisesImmutableId</quote>), " +"authentication fails. SSSD does not fall back to another attribute when this " +"option is set." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:258 +msgid "" +"Default: not set, <quote>sub</quote> for Keycloak and <quote>id</quote> for " +"other IdP types" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-idp.5.xml:264 msgid "idp_request_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:188 +#: sssd-idp.5.xml:267 msgid "Timeout in seconds for an individual request to the IdP." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:197 +#: sssd-idp.5.xml:276 +msgid "idp_auto_refresh (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:279 +msgid "" +"Refresh tokens automatically, after they have reached about half their " +"lifetime." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:283 +msgid "" +"Note: Scheduled token refreshes are not preserved across restarts of SSSD." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-idp.5.xml:292 msgid "idmap_range_min (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:200 +#: sssd-idp.5.xml:295 msgid "" "Specifies the lower (inclusive) bound of the range of POSIX IDs to use for " "mapping IdP users and group to POSIX IDs. It is the first POSIX ID which can " @@ -12419,7 +12837,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:206 +#: sssd-idp.5.xml:301 msgid "" "The interval between <quote>idmap_range_min</quote> and " "<quote>idmap_range_max</quote> will be split into smaller ranges of size " @@ -12428,18 +12846,18 @@ msgid "" msgstr "" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:213 sssd-idp.5.xml:239 include/ldap_id_mapping.xml:139 +#: sssd-idp.5.xml:308 sssd-idp.5.xml:334 include/ldap_id_mapping.xml:139 #: include/ldap_id_mapping.xml:197 msgid "Default: 200000" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:218 +#: sssd-idp.5.xml:313 msgid "idmap_range_max (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:221 +#: sssd-idp.5.xml:316 msgid "" "Specifies the upper (exclusive) bound of the range of POSIX IDs to use for " "mapping IdP users and groups to POSIX IDs. It is the first POSIX ID which " @@ -12447,45 +12865,68 @@ msgid "" msgstr "" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:227 include/ldap_id_mapping.xml:165 +#: sssd-idp.5.xml:322 include/ldap_id_mapping.xml:165 msgid "Default: 2000200000" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:232 +#: sssd-idp.5.xml:327 msgid "idmap_range_size (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:235 +#: sssd-idp.5.xml:330 msgid "Specifies the number of POSIX IDs available for a single IdP domain." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-idp.5.xml:251 +#: sssd-idp.5.xml:346 #, no-wrap msgid "" "[domain/entra_id]\n" "id_provider = idp\n" "idp_type = entra_id\n" "idp_client_id = 12345678-abcd-0101-efef-ba9876543210\n" -"idp_client_secret = YOUR-CLIENT-SCERET\n" -"idp_token_endpoint = https://login.microsoftonline.com/TENNANT-ID/oauth2/v2.0/token\n" +"idp_client_secret = YOUR-CLIENT-SECRET\n" +"idp_token_endpoint = https://login.microsoftonline.com/TENANT-ID/oauth2/v2.0/token\n" "idp_userinfo_endpoint = https://graph.microsoft.com/v1.0/me\n" -"idp_device_auth_endpoint = https://login.microsoftonline.com/TENNANT-ID/oauth2/v2.0/devicecode\n" -"idp_id_scope = https%3A%2F%2Fgraph.microsoft.com%2F.default\n" +"idp_device_auth_endpoint = https://login.microsoftonline.com/TENANT-ID/oauth2/v2.0/devicecode\n" +"idp_id_scope = https://graph.microsoft.com/.default\n" +"idp_auth_scope = openid profile email\n" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><programlisting> +#: sssd-idp.5.xml:358 +#, no-wrap +msgid "" +"[domain/ad.example.com]\n" +"id_provider = ad\n" +"auth_provider = idp\n" +"access_provider = permit\n" +"\n" +"ad_domain = ad.example.com\n" +"krb5_realm = AD.EXAMPLE.COM\n" +"\n" +"idp_type = entra_id\n" +"idp_client_id = 12345678-abcd-0101-efef-ba9876543210\n" +"idp_client_secret = YOUR-CLIENT-SECRET\n" +"idp_token_endpoint = https://login.microsoftonline.com/TENANT-ID/oauth2/v2.0/token\n" +"idp_userinfo_endpoint = https://graph.microsoft.com/v1.0/me?$select=id,userPrincipalName,onPremisesImmutableId\n" +"idp_device_auth_endpoint = https://login.microsoftonline.com/TENANT-ID/oauth2/v2.0/devicecode\n" +"idp_id_scope = https://graph.microsoft.com/.default\n" "idp_auth_scope = openid profile email\n" +"idp_auth_user_identifier_attr = onPremisesImmutableId\n" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-idp.5.xml:263 +#: sssd-idp.5.xml:377 #, no-wrap msgid "" "[domain/keycloak]\n" "idp_type = keycloak:https://master.keycloak.test:8443/auth/admin/realms/master/\n" "id_provider = idp\n" "idp_client_id = myclient\n" -"idp_client_secret = YOUR-CLIENT-SCERET\n" +"idp_client_secret = YOUR-CLIENT-SECRET\n" "idp_token_endpoint = https://master.keycloak.test:8443/auth/realms/master/protocol/openid-connect/token\n" "idp_userinfo_endpoint = https://master.keycloak.test:8443/auth/realms/master/protocol/openid-connect/userinfo\n" "idp_device_auth_endpoint = https://master.keycloak.test:8443/auth/realms/master/protocol/openid-connect/auth/device\n" @@ -12494,10 +12935,22 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-idp.5.xml:250 +#: sssd-idp.5.xml:345 msgid "" "<placeholder type=\"programlisting\" id=\"0\"/> <placeholder " -"type=\"programlisting\" id=\"1\"/>" +"type=\"programlisting\" id=\"1\"/> <placeholder type=\"programlisting\" " +"id=\"2\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-idp.5.xml:390 +msgid "" +"In the hybrid Active Directory and Entra ID example above, " +"<quote>onPremisesImmutableId</quote> is used during authentication so the " +"IdP result matches the AD objectGUID UUID stored in the SSSD cache. The " +"attribute must be requested via <quote>$select</quote> on the Graph userinfo " +"endpoint and is only populated for users synchronized from Active Directory " +"with objectGUID as the sourceAnchor." msgstr "" #. type: Content of: <reference><refentry><refnamediv><refname> @@ -13463,7 +13916,7 @@ msgstr "" #: sssd-krb5.5.xml:291 msgid "" "<emphasis>demand</emphasis> to use FAST. The authentication fails if the " -"server does not require fast." +"server does not support FAST." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> @@ -14352,7 +14805,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sss_rpcidmapd.5.xml:69 -msgid "memcache (bool)" +msgid "memcache (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> @@ -14406,7 +14859,7 @@ msgid "" msgstr "" #. type: Content of: <refsect1><title> -#: sss_rpcidmapd.5.xml:120 sssd-kcm.8.xml:316 include/seealso.xml:2 +#: sss_rpcidmapd.5.xml:120 sssd-kcm.8.xml:315 include/seealso.xml:2 msgid "SEE ALSO" msgstr "" @@ -14633,8 +15086,8 @@ msgstr "" #: sss_ssh_knownhosts.1.xml:93 msgid "" "The key lines retrieved from the backend are expected to respect the key " -"format as decribed in the <quote>SSH_KNOWN_HOSTS FILE FORMAT</quote> section " -"of <citerefentry><refentrytitle>sshd</refentrytitle> <manvolnum>8</" +"format as described in the <quote>SSH_KNOWN_HOSTS FILE FORMAT</quote> " +"section of <citerefentry><refentrytitle>sshd</refentrytitle> <manvolnum>8</" "manvolnum></citerefentry>. However, returning only the keytype and the key " "itself is tolerated, in which case, the hostname received as parameter will " "be added before the keytype to output a correctly formatted line. The " @@ -15110,14 +15563,13 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-kcm.8.xml:215 msgid "" -"The KCM service is configured in the <quote>kcm</quote> For a detailed " -"syntax reference, refer to the <quote>FILE FORMAT</quote> section of the " -"<citerefentry> <refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</" -"manvolnum> </citerefentry> manual page." +"For a detailed syntax reference, refer to the <quote>FILE FORMAT</quote> " +"section of the <citerefentry> <refentrytitle>sssd.conf</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry> manual page." msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-kcm.8.xml:223 +#: sssd-kcm.8.xml:222 msgid "" "The generic SSSD service options such as <quote>debug_level</quote> or " "<quote>fd_limit</quote> are accepted by the kcm service. Please refer to " @@ -15127,22 +15579,22 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:234 +#: sssd-kcm.8.xml:233 msgid "socket_path (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:237 +#: sssd-kcm.8.xml:236 msgid "The socket the KCM service will listen on." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:240 +#: sssd-kcm.8.xml:239 msgid "Default: <replaceable>/var/run/.heim_org.h5l.kcm-socket</replaceable>" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:243 +#: sssd-kcm.8.xml:242 msgid "" "<phrase condition=\"have_systemd\"> Note: on platforms where systemd is " "supported, the socket path is overwritten by the one defined in the sssd-" @@ -15150,86 +15602,86 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:252 +#: sssd-kcm.8.xml:251 msgid "max_ccaches (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:255 +#: sssd-kcm.8.xml:254 msgid "How many credential caches does the KCM database allow for all users." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:259 +#: sssd-kcm.8.xml:258 msgid "Default: 0 (unlimited, only the per-UID quota is enforced)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:264 +#: sssd-kcm.8.xml:263 msgid "max_uid_ccaches (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:267 +#: sssd-kcm.8.xml:266 msgid "" "How many credential caches does the KCM database allow per UID. This is " "equivalent to <quote>with how many principals you can kinit</quote>." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:272 +#: sssd-kcm.8.xml:271 msgid "Default: 64" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:277 +#: sssd-kcm.8.xml:276 msgid "max_ccache_size (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:280 +#: sssd-kcm.8.xml:279 msgid "" -"How big can a credential cache be per ccache. Each service ticket accounts " -"into this quota." +"How big a credential cache be per ccache. Each service ticket counts toward " +"this quota." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:284 +#: sssd-kcm.8.xml:283 msgid "Default: 65536" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:289 -msgid "tgt_renewal (bool)" +#: sssd-kcm.8.xml:288 +msgid "tgt_renewal (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:292 +#: sssd-kcm.8.xml:291 msgid "Enables TGT renewals functionality." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:295 +#: sssd-kcm.8.xml:294 msgid "Default: False (Automatic renewals disabled)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:300 +#: sssd-kcm.8.xml:299 msgid "tgt_renewal_inherit (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:303 +#: sssd-kcm.8.xml:302 msgid "Domain to inherit krb5_* options from, for use with TGT renewals." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:307 +#: sssd-kcm.8.xml:306 msgid "Default: NULL" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-kcm.8.xml:318 +#: sssd-kcm.8.xml:317 msgid "" "<citerefentry> <refentrytitle>sssd</refentrytitle><manvolnum>8</manvolnum> </" "citerefentry>, <citerefentry> <refentrytitle>sssd.conf</" @@ -16133,8 +16585,8 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap-attributes.5.xml:381 sssd-ldap-attributes.5.xml:395 -msgid "Default: loginDisabled" +#: sssd-ldap-attributes.5.xml:381 +msgid "Default: loginDisabled (rfc2307, rfc2307bis and IPA), not set (AD)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> @@ -16149,6 +16601,12 @@ msgid "" "which date access is granted." msgstr "" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:395 +msgid "" +"Default: loginExpirationTime (rfc2307, rfc2307bis and IPA), not set (AD)" +msgstr "" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:401 msgid "ldap_user_nds_login_allowed_time_map (string)" @@ -16163,7 +16621,8 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:409 -msgid "Default: loginAllowedTimeMap" +msgid "" +"Default: loginAllowedTimeMap (rfc2307, rfc2307bis and IPA), not set (AD)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> @@ -16588,7 +17047,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:808 msgid "The object class of a netgroup entry in LDAP." -msgstr "" +msgstr "A classe de objeto de uma entrada de grupo de rede no LDAP." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:811 @@ -16608,7 +17067,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:824 msgid "The LDAP attribute that corresponds to the netgroup name." -msgstr "" +msgstr "O atributo LDAP que corresponde ao nome do grupo de rede." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:828 @@ -16623,7 +17082,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:841 msgid "The LDAP attribute that contains the names of the netgroup's members." -msgstr "" +msgstr "O atributo LDAP que contém os nomes dos membros do grupo de rede." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:845 @@ -16674,11 +17133,11 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:897 msgid "The object class of a host entry in LDAP." -msgstr "" +msgstr "A classe de objeto de uma entrada de host no LDAP." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap-attributes.5.xml:900 sssd-ldap-attributes.5.xml:997 -msgid "Default: ipService" +#: sssd-ldap-attributes.5.xml:900 sssd-ldap-attributes.5.xml:1213 +msgid "Default: ipHost" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> @@ -16736,7 +17195,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:961 msgid "The LDAP attribute that contains the host's SSH public keys." -msgstr "" +msgstr "O atributo LDAP que contém as chaves públicas SSH do host." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:971 @@ -16763,6 +17222,11 @@ msgstr "" msgid "The object class of a service entry in LDAP." msgstr "" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:997 +msgid "Default: ipService" +msgstr "" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1003 msgid "ldap_service_name (string)" @@ -17003,11 +17467,6 @@ msgstr "" msgid "The object class of an iphost entry in LDAP." msgstr "" -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap-attributes.5.xml:1213 -msgid "Default: ipHost" -msgstr "" - #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1219 msgid "ldap_iphost_name (string)" @@ -17227,6 +17686,7 @@ msgstr "" msgid "" "[plugins]\n" " localauth = {\n" +" disable = an2ln\n" " module = sssd:/usr/lib64/sssd/modules/sssd_krb5_localauth_plugin.so\n" " }\n" msgstr "" @@ -17243,6 +17703,28 @@ msgid "" "the local Kerberos configuration the plugin will be enabled automatically." msgstr "" +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_localauth_plugin.8.xml:67 +msgid "" +"This configuration snippet also disables the <command>an2ln</command> module " +"provided by MIT Kerberos if SSSD is configured to use the AD or IPA " +"provider. In those environments <command>sssd_krb5_localauth_plugin</" +"command> can reliably map the system user names to Kerberos principals. A " +"fallback to <command>an2ln</command> might cause issues in environments " +"where users have the privilege to create Kerberos principals on their own " +"which might collide with names of other users used in the system. Other " +"modules provided by MIT Kerberos, e.g. <command>k5login</command> are not " +"affected." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_localauth_plugin.8.xml:79 +msgid "" +"Note: If using <quote>auth_provider = krb5</quote> then " +"<command>sssd_krb5_localauth_plugin</command> is not used, therefore the " +"above text is not applicable." +msgstr "" + #. type: Content of: <variablelist><varlistentry><term> #: include/autofs_attributes.xml:3 msgid "ldap_autofs_map_object_class (string)" @@ -18099,30 +18581,6 @@ msgid "" "failures; corresponds to setting 2 in decimal notation)" msgstr "" -#. type: Content of: <refsect1><title> -#: include/local.xml:2 -msgid "THE LOCAL DOMAIN" -msgstr "" - -#. type: Content of: <refsect1><para> -#: include/local.xml:4 -msgid "" -"In order to function correctly, a domain with <quote>id_provider=local</" -"quote> must be created and the SSSD must be running." -msgstr "" - -#. type: Content of: <refsect1><para> -#: include/local.xml:9 -msgid "" -"The administrator might want to use the SSSD local users instead of " -"traditional UNIX users in cases where the group nesting (see <citerefentry> " -"<refentrytitle>sss_groupadd</refentrytitle> <manvolnum>8</manvolnum> </" -"citerefentry>) is needed. The local users are also useful for testing and " -"development of the SSSD without having to deploy a full remote server. The " -"<command>sss_user*</command> and <command>sss_group*</command> tools use a " -"local LDB storage to store users and groups." -msgstr "" - #. type: Content of: <refsect1><para> #: include/seealso.xml:4 msgid "" diff --git a/src/man/po/ro.po b/src/man/po/ro.po new file mode 100644 index 00000000000..d869f88b278 --- /dev/null +++ b/src/man/po/ro.po @@ -0,0 +1,19231 @@ +# SOME DESCRIPTIVE TITLE +# Copyright (C) YEAR Red Hat +# This file is distributed under the same license as the sssd-docs package. +# FIRST AUTHOR <EMAIL@ADDRESS>, YEAR. +# +msgid "" +msgstr "" +"Project-Id-Version: sssd-docs 2.14.0\n" +"Report-Msgid-Bugs-To: sssd-devel@redhat.com\n" +"POT-Creation-Date: 2026-10-05 16:14+0000\n" +"PO-Revision-Date: 2026-10-05 17:28+0000\n" +"Last-Translator: Petru Rebeja <petru@rebeja.eu>\n" +"Language-Team: Romanian <https://translate.fedoraproject.org/projects/sssd/" +"sssd-manpage-master/ro/>\n" +"Language: ro\n" +"MIME-Version: 1.0\n" +"Content-Type: text/plain; charset=UTF-8\n" +"Content-Transfer-Encoding: 8bit\n" +"Plural-Forms: nplurals=3; plural=n==1 ? 0 : (n==0 || (n%100 > 0 && n%100 < " +"20)) ? 1 : 2;\n" +"X-Generator: Weblate 2026.10\n" + +#. type: Content of: <reference><title> +#: sssd.conf.5.xml:10 sssd-ldap.5.xml:5 pam_sss.8.xml:5 pam_sss_gss.8.xml:5 +#: sssd_krb5_locator_plugin.8.xml:5 sssd-simple.5.xml:5 sss-certmap.5.xml:5 +#: sssd-ipa.5.xml:5 sssd-ad.5.xml:5 sssd-sudo.5.xml:5 sssd-idp.5.xml:5 +#: sssd.8.xml:5 sss_obfuscate.8.xml:5 sss_override.8.xml:5 sssd-krb5.5.xml:5 +#: sss_cache.8.xml:5 sss_debuglevel.8.xml:5 sss_seed.8.xml:5 sssd-ifp.5.xml:5 +#: sss_rpcidmapd.5.xml:5 sss_ssh_authorizedkeys.1.xml:5 +#: sss_ssh_knownhosts.1.xml:5 idmap_sss.8.xml:5 sssctl.8.xml:5 +#: sssd-session-recording.5.xml:5 sssd-kcm.8.xml:5 sssd-systemtap.5.xml:5 +#: sssd-ldap-attributes.5.xml:5 sssd_krb5_localauth_plugin.8.xml:5 +msgid "SSSD Manual pages" +msgstr "Pagini ale manualului SSSD" + +#. type: Content of: <reference><refentry><refnamediv><refname> +#: sssd.conf.5.xml:15 sssd.conf.5.xml:21 +msgid "sssd.conf" +msgstr "sssd.conf" + +#. type: Content of: <reference><refentry><refmeta><manvolnum> +#: sssd.conf.5.xml:16 sssd-ldap.5.xml:11 sssd-simple.5.xml:11 +#: sss-certmap.5.xml:11 sssd-ipa.5.xml:11 sssd-ad.5.xml:11 sssd-sudo.5.xml:11 +#: sssd-idp.5.xml:11 sssd-krb5.5.xml:11 sssd-ifp.5.xml:11 +#: sss_rpcidmapd.5.xml:27 sssd-session-recording.5.xml:11 +#: sssd-systemtap.5.xml:11 sssd-ldap-attributes.5.xml:11 +msgid "5" +msgstr "5" + +#. type: Content of: <reference><refentry><refmeta><refmiscinfo> +#: sssd.conf.5.xml:17 sssd-ldap.5.xml:12 sssd-simple.5.xml:12 +#: sss-certmap.5.xml:12 sssd-ipa.5.xml:12 sssd-ad.5.xml:12 sssd-sudo.5.xml:12 +#: sssd-idp.5.xml:12 sssd-krb5.5.xml:12 sssd-ifp.5.xml:12 +#: sss_rpcidmapd.5.xml:28 sssd-session-recording.5.xml:12 sssd-kcm.8.xml:12 +#: sssd-systemtap.5.xml:12 sssd-ldap-attributes.5.xml:12 +msgid "File Formats and Conventions" +msgstr "Formate ale fișierelor și convenții" + +#. type: Content of: <reference><refentry><refnamediv><refpurpose> +#: sssd.conf.5.xml:22 +msgid "the configuration file for SSSD" +msgstr "fișierul de configurare al SSSD" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd.conf.5.xml:26 +msgid "FILE FORMAT" +msgstr "FORMAT FIȘIER" + +#. type: Content of: <reference><refentry><refsect1><para><programlisting> +#: sssd.conf.5.xml:34 +#, no-wrap +msgid "" +"<replaceable>[section]</replaceable>\n" +"<replaceable>key</replaceable> = <replaceable>value</replaceable>\n" +"<replaceable>key2</replaceable> = <replaceable>value2,value3</replaceable>\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:29 +msgid "" +"The file has an ini-style syntax and consists of sections and parameters. A " +"section begins with the name of the section in square brackets and continues " +"until the next section begins. An example of section with single and " +"multi-valued parameters: <placeholder type=\"programlisting\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:41 +msgid "" +"The data types used are string (no quotes needed), integer and boolean (with " +"values of <quote>TRUE/FALSE</quote>). Boolean values are case-insensitive; " +"for example, <quote>TRUE</quote>, <quote>True</quote> and " +"<quote>true</quote> are all equivalent and valid; the same applies to " +"<quote>FALSE</quote>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:49 +msgid "" +"A comment line starts with a hash sign (<quote>#</quote>) or a semicolon " +"(<quote>;</quote>). Inline comments are not supported." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:55 +msgid "" +"All sections can have an optional <replaceable>description</replaceable> " +"parameter. Its function is only as a label for the section." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:61 +msgid "" +"<filename>sssd.conf</filename> must be a regular file that is owned, " +"readable, and writeable only by 'root'." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:65 +msgid "" +"<filename>sssd.conf</filename> must be a regular file that is accessible " +"only by the user used to run SSSD service or root." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd.conf.5.xml:71 +msgid "CONFIGURATION SNIPPETS FROM INCLUDE DIRECTORY" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:74 +msgid "" +"The configuration file <filename>sssd.conf</filename> will include " +"configuration snippets using the include directory " +"<filename>conf.d</filename>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:80 +msgid "" +"Any file placed in <filename>conf.d</filename> that ends in " +"<quote><filename>.conf</filename></quote> and does not begin with a dot " +"(<quote>.</quote>) will be used together with <filename>sssd.conf</filename> " +"to configure SSSD." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:88 +msgid "" +"The configuration snippets from <filename>conf.d</filename> have higher " +"priority than <filename>sssd.conf</filename> and will override " +"<filename>sssd.conf</filename> when conflicts occur. If several snippets are " +"present in <filename>conf.d</filename>, then they are included in " +"alphabetical order (based on locale). Files included later have higher " +"priority. Numerical prefixes (<filename>01_snippet.conf</filename>, " +"<filename>02_snippet.conf</filename> etc.) can help visualize the priority " +"(higher number means higher priority)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:102 +msgid "" +"The snippet files require the same owner and permissions as " +"<filename>sssd.conf</filename>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd.conf.5.xml:108 +msgid "VENDOR PROVIDED CONFIGURATION" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:111 +msgid "" +"The vendor provided configuration file is installed in " +"<filename>&sssd_vendor_dir;/sssd.conf</filename>, but this file must not be " +"directly edited. It can be completely masked by creating the system specific " +"configuration file <filename>&sssd_conf_dir;/sssd.conf</filename>, or partly " +"overriden by creating config snippets in " +"<filename>&sssd_conf_dir;/conf.d</filename> directory." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><title> +#: sssd.conf.5.xml:120 +msgid "CONFIGURATION FILE HIERARCHY" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:122 +msgid "" +"When sssd reads the configuration it first tries to open the system specific " +"configuration file in <filename>&sssd_conf_dir;/sssd.conf</filename>. If it " +"exists, it is loaded and snippets from " +"<filename>&sssd_conf_dir;/conf.d</filename> are applied. The vendor provided " +"configuration file <filename>&sssd_vendor_dir;/sssd.conf</filename> is " +"completely ignored in this case." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:131 +msgid "" +"If the system specific configuration file " +"<filename>&sssd_conf_dir;/sssd.conf</filename> does not exist, then the " +"vendor configuration file <filename>&sssd_vendor_dir;/sssd.conf</filename> " +"is loaded and snippets from <filename>&sssd_conf_dir;/conf.d</filename> are " +"applied." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd.conf.5.xml:141 +msgid "GENERAL OPTIONS" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:143 +msgid "Following options are usable in more than one configuration sections." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><title> +#: sssd.conf.5.xml:147 +msgid "Options usable in all sections" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:149 +msgid "" +"Note: Below options are ignored in <quote>[session_recording]</quote> " +"section, see <quote>Session recording configuration options</quote> section " +"for more details." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:156 +msgid "debug_level (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:160 +msgid "debug (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:163 +msgid "" +"SSSD 1.14 and later also includes the <replaceable>debug</replaceable> alias " +"for <replaceable>debug_level</replaceable> as a convenience feature. If both " +"are specified, the value of <replaceable>debug_level</replaceable> will be " +"used." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:173 +msgid "debug_timestamps (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:176 +msgid "" +"Add a timestamp to the debug messages. If journald is enabled for SSSD " +"debug logging this option is ignored." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:181 sssd.conf.5.xml:218 sssd.conf.5.xml:380 +#: sssd.conf.5.xml:687 sssd.conf.5.xml:711 sssd.conf.5.xml:827 +#: sssd.conf.5.xml:932 sssd.conf.5.xml:2149 sssd.conf.5.xml:4730 +#: sssd-ldap.5.xml:979 sssd-ldap.5.xml:1134 sssd-ldap.5.xml:1237 +#: sssd-ldap.5.xml:1306 sssd-ldap.5.xml:1714 sssd-ldap.5.xml:1848 +#: sssd-ldap.5.xml:1913 sssd-ipa.5.xml:341 sssd-ad.5.xml:252 sssd-ad.5.xml:367 +#: sssd-ad.5.xml:1180 sssd-ad.5.xml:1375 sssd-krb5.5.xml:358 +msgid "Default: true" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:186 +msgid "debug_microseconds (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:189 +msgid "" +"Add microseconds to the timestamp in debug messages. If journald is enabled " +"for SSSD debug logging this option is ignored." +msgstr "" + +#. type: Content of: <variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:194 sssd.conf.5.xml:2072 sssd.conf.5.xml:4363 +#: sssd-ldap.5.xml:363 sssd-ldap.5.xml:998 sssd-ldap.5.xml:1209 +#: sssd-ldap.5.xml:1663 sssd-ldap.5.xml:1937 sssd-ipa.5.xml:141 +#: sssd-ipa.5.xml:701 sssd-ad.5.xml:1140 sssd-idp.5.xml:287 sssd-krb5.5.xml:268 +#: sssd-krb5.5.xml:330 sssd-krb5.5.xml:432 include/krb5_options.xml:163 +msgid "Default: false" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:199 +msgid "debug_backtrace_enabled (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:202 +msgid "Enable debug backtrace." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:205 +msgid "" +"In case SSSD is run with debug_level less than 9, everything is logged to a " +"ring buffer in memory and flushed to a log file on any error up to and " +"including `min(0x0040, debug_level)` (i.e. if debug_level is explicitly set " +"to 0 or 1 then only those error levels will trigger backtrace, otherwise up " +"to 2)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:214 +msgid "" +"Feature is only supported for `logger == files` (i.e. setting doesn't have " +"effect for other logger types)." +msgstr "" + +#. type: Content of: outside any tag (error?) +#: sssd.conf.5.xml:154 sssd.conf.5.xml:229 sssd-ldap.5.xml:1754 +#: sssd-ldap.5.xml:1960 sss-certmap.5.xml:645 sssd-systemtap.5.xml:82 +#: sssd-systemtap.5.xml:143 sssd-systemtap.5.xml:236 sssd-systemtap.5.xml:274 +#: sssd-systemtap.5.xml:330 sssd-ldap-attributes.5.xml:40 +#: sssd-ldap-attributes.5.xml:661 sssd-ldap-attributes.5.xml:803 +#: sssd-ldap-attributes.5.xml:892 sssd-ldap-attributes.5.xml:989 +#: sssd-ldap-attributes.5.xml:1047 sssd-ldap-attributes.5.xml:1205 +#: sssd-ldap-attributes.5.xml:1250 sssd-ldap-attributes.5.xml:1295 +#: include/autofs_attributes.xml:1 include/krb5_options.xml:1 +msgid "<placeholder type=\"variablelist\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><title> +#: sssd.conf.5.xml:227 +msgid "Options usable in SERVICE and DOMAIN sections" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:231 +msgid "timeout (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:234 +msgid "" +"Timeout in seconds between heartbeats for this service. This is used to " +"ensure that the process is alive and capable of answering requests. Note " +"that after three missed heartbeats the process will terminate itself." +msgstr "" + +#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:241 sssd.conf.5.xml:1155 sssd.conf.5.xml:1665 +#: sssd.conf.5.xml:4379 sssd-ldap.5.xml:825 sssd-idp.5.xml:271 +#: include/ldap_id_mapping.xml:270 +msgid "Default: 10" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd.conf.5.xml:251 +msgid "SPECIAL SECTIONS" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><title> +#: sssd.conf.5.xml:254 +msgid "The [sssd] section" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><title> +#: sssd.conf.5.xml:263 +msgid "Section parameters" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:265 +msgid "services (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:268 +msgid "" +"Comma separated list of services that are started when sssd itself starts. " +"<phrase condition=\"have_systemd\"> The services' list is optional on " +"platforms where systemd is supported, as they will either be socket or D-Bus " +"activated when needed. </phrase>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:277 +msgid "" +"Supported services: nss, pam, ifp <phrase condition=\"with_sudo\">, " +"sudo</phrase> <phrase condition=\"with_autofs\">, autofs</phrase> <phrase " +"condition=\"with_ssh\">, ssh</phrase> <phrase " +"condition=\"with_pac_responder\">, pac</phrase>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:284 +msgid "" +"<phrase condition=\"have_systemd\"> By default, all services are disabled " +"and the administrator must enable the ones allowed to be used by executing: " +"\"systemctl enable sssd-@service@.socket\". </phrase>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sssd.conf.5.xml:293 sssd.conf.5.xml:4562 +msgid "domains (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:296 +msgid "" +"A domain is a database containing user information. SSSD can use more " +"domains at the same time, but at least one must be configured or SSSD won't " +"start. This parameter describes the list of domains in the order you want " +"them to be queried. A domain name is recommended to contain only " +"alphanumeric ASCII characters, dashes, dots and underscores. '/' character " +"is forbidden." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:309 sssd.conf.5.xml:3598 +msgid "re_expression (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:312 +msgid "" +"Default regular expression that describes how to parse the string containing " +"user name and domain into these components." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:317 +msgid "" +"Each domain can have an individual regular expression configured. For some " +"ID providers there are also default regular expressions. See DOMAIN SECTIONS " +"for more info on these regular expressions." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:326 sssd.conf.5.xml:3655 +msgid "full_name_format (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:329 sssd.conf.5.xml:3658 +msgid "" +"A <citerefentry> <refentrytitle>printf</refentrytitle> " +"<manvolnum>3</manvolnum> </citerefentry>-compatible format that describes " +"how to compose a fully qualified name from user name and domain name " +"components." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:340 sssd.conf.5.xml:3669 +msgid "%1$s" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:341 sssd.conf.5.xml:3670 +msgid "user name" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:344 sssd.conf.5.xml:3673 +msgid "%2$s" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:347 sssd.conf.5.xml:3676 +msgid "domain name as specified in the SSSD config file." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:353 sssd.conf.5.xml:3682 +msgid "%3$s" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:356 sssd.conf.5.xml:3685 +msgid "" +"domain flat name. Mostly usable for Active Directory domains, both directly " +"configured or discovered via IPA trusts." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:337 sssd.conf.5.xml:3666 +msgid "" +"The following expansions are supported: <placeholder type=\"variablelist\" " +"id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:366 +msgid "" +"Each domain can have an individual format string configured. See DOMAIN " +"SECTIONS for more info on this option." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:372 +msgid "monitor_resolv_conf (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:375 +msgid "" +"Controls if SSSD should monitor the state of resolv.conf to identify when it " +"needs to update its internal DNS resolver." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:385 +msgid "try_inotify (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:388 +msgid "" +"By default, SSSD will attempt to use inotify to monitor configuration files " +"changes and will fall back to polling every five seconds if inotify cannot " +"be used." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:394 +msgid "" +"There are some limited situations where it is preferred that we should skip " +"even trying to use inotify. In these rare cases, this option should be set " +"to 'false'" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:400 +msgid "" +"Default: true on platforms where inotify is supported. False on other " +"platforms." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:404 +msgid "" +"Note: this option will have no effect on platforms where inotify is " +"unavailable. On these platforms, polling will always be used." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:411 +msgid "krb5_rcache_dir (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:414 +msgid "" +"Directory on the filesystem where SSSD should store Kerberos replay cache " +"files." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:418 +msgid "" +"This option accepts a special value __LIBKRB5_DEFAULTS__ that will instruct " +"SSSD to let libkrb5 decide the appropriate location for the replay cache." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:424 +msgid "" +"Default: Distribution-specific and specified at " +"build-time. (__LIBKRB5_DEFAULTS__ if not configured)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:431 +msgid "default_domain_suffix (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:434 +msgid "" +"Please note that this option is deprecated and domain_resolution_order " +"should be used." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:438 +msgid "" +"This string will be used as a default domain name for all names without a " +"domain name component. The main use case is environments where the primary " +"domain is intended for managing host policies and all users are located in a " +"trusted domain. The option allows those users to log in just with their " +"user name without giving a domain name as well." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:448 +msgid "" +"Please note that if this option is set all users from the primary domain " +"have to use their fully qualified name, e.g. user@domain.name, to log " +"in. Setting this option changes default of use_fully_qualified_names to " +"True. It is not allowed to use this option together with " +"use_fully_qualified_names set to False." +msgstr "" + +#. type: Content of: <variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:457 sssd.conf.5.xml:2006 sssd-ldap.5.xml:937 +#: sssd-ldap.5.xml:949 sssd-ldap.5.xml:1042 sssd-ad.5.xml:926 +#: sssd-ad.5.xml:1001 sssd-krb5.5.xml:468 sssd-ldap-attributes.5.xml:470 +#: sssd-ldap-attributes.5.xml:978 include/ldap_id_mapping.xml:211 +#: include/ldap_id_mapping.xml:222 include/krb5_options.xml:148 +msgid "Default: not set" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:462 +msgid "override_space (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:465 +msgid "" +"This parameter will replace spaces (space bar) with the given character for " +"user and group names. e.g. (_). User name "john doe" will be " +""john_doe" This feature was added to help compatibility with shell " +"scripts that have difficulty handling spaces, due to the default field " +"separator in the shell." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:474 +msgid "" +"Please note it is a configuration error to use a replacement character that " +"might be used in user or group names. If a name contains the replacement " +"character SSSD tries to return the unmodified name but in general the result " +"of a lookup is undefined." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:482 +msgid "Default: not set (spaces will not be replaced)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:487 +msgid "certificate_verification (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:495 +msgid "no_ocsp" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:497 +msgid "" +"Disables Online Certificate Status Protocol (OCSP) checks. This might be " +"needed if the OCSP servers defined in the certificate are not reachable from " +"the client." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:505 +msgid "soft_ocsp" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:507 +msgid "" +"If a connection cannot be established to an OCSP responder the OCSP check is " +"skipped. This option should be used to allow authentication when the system " +"is offline and the OCSP responder cannot be reached." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:517 +msgid "ocsp_dgst" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:519 +msgid "" +"Digest (hash) function used to create the certificate ID for the OCSP " +"request. Allowed values are:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:523 +msgid "sha1" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:524 +msgid "sha256" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:525 +msgid "sha384" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:526 +msgid "sha512" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:529 +msgid "Default: sha1 (to allow compatibility with RFC5019-compliant responder)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:535 +msgid "no_verification" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:537 +msgid "" +"Disables verification completely. This option should only be used for " +"testing." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:543 +msgid "partial_chain" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:545 +msgid "" +"Allow verification to succeed even if a <replaceable>complete</replaceable> " +"chain cannot be built to a self-signed trust-anchor, provided it is possible " +"to construct a chain to a trusted certificate that might not be self-signed." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:554 +msgid "ocsp_default_responder=URL" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:556 +msgid "" +"Sets the OCSP default responder which should be used instead of the one " +"mentioned in the certificate. URL must be replaced with the URL of the OCSP " +"default responder e.g. http://example.com:80/ocsp." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:566 +msgid "ocsp_default_responder_signing_cert=NAME" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:568 +msgid "" +"This option is currently ignored. All needed certificates must be available " +"in the PEM file given by pam_cert_db_path." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:576 +msgid "crl_file=/PATH/TO/CRL/FILE" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:578 +msgid "" +"Use the Certificate Revocation List (CRL) from the given file during the " +"verification of the certificate. The CRL must be given in PEM format, see " +"<citerefentry> <refentrytitle>crl</refentrytitle> " +"<manvolnum>1ssl</manvolnum> </citerefentry> for details." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:591 +msgid "soft_crl" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:594 +msgid "" +"If a Certificate Revocation List (CRL) is expired ignore the expiration " +"time of the CRL and check the related certificates with the expired " +"CRL. This option should be used to allow authentication when the system is " +"offline and the CRL cannot be renewed." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:490 +msgid "" +"With this parameter the certificate verification can be tuned with a comma " +"separated list of options. Supported options are: <placeholder " +"type=\"variablelist\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:607 +msgid "Unknown options are reported but ignored." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:610 +msgid "Default: not set, i.e. do not restrict certificate verification" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:616 +msgid "disable_netlink (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:619 +msgid "" +"SSSD hooks into the netlink interface to monitor changes to routes, " +"addresses, links and trigger certain actions." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:624 +msgid "" +"The SSSD state changes caused by netlink events may be undesirable and can " +"be disabled by setting this option to 'true'" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:629 +msgid "Default: false (netlink changes are detected)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:634 +msgid "domain_resolution_order (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:637 +msgid "" +"Comma separated list of domains and subdomains representing the lookup order " +"that will be followed. The list doesn't have to include all possible " +"domains as the missing domains will be looked up based on the order they're " +"presented in the <quote>domains</quote> configuration option. The " +"subdomains which are not listed as part of <quote>lookup_order</quote> will " +"be looked up in a random order for each parent domain." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:649 +msgid "" +"Please, note that when this option is set the output format of all commands " +"is always fully-qualified even when using short names for input. In case " +"the administrator wants the output not fully-qualified, the full_name_format " +"option can be used as shown below: <quote>full_name_format=%1$s</quote> " +"However, keep in mind that during login, login applications often " +"canonicalize the username by calling <citerefentry> " +"<refentrytitle>getpwnam</refentrytitle> <manvolnum>3</manvolnum> " +"</citerefentry> which, if a shortname is returned for a qualified input " +"(while trying to reach a user which exists in multiple domains) might " +"re-route the login attempt into the domain which uses shortnames, making " +"this workaround totally not recommended in cases where usernames may overlap " +"between domains." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:673 sssd.conf.5.xml:1026 sssd.conf.5.xml:1689 +#: sssd.conf.5.xml:4429 sssd-ad.5.xml:187 sssd-ad.5.xml:328 sssd-ad.5.xml:342 +#: sssd-idp.5.xml:112 sssd-idp.5.xml:136 sssd-idp.5.xml:149 sssd-idp.5.xml:167 +#: sssd-idp.5.xml:188 +msgid "Default: Not set" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:678 +msgid "implicit_pac_responder (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:681 +msgid "" +"The PAC responder is enabled automatically for the IPA and AD provider to " +"evaluate and check the PAC. If it has to be disabled set this option to " +"'false'." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:692 +msgid "core_dumpable (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:695 +msgid "" +"This option can be used for general system hardening: setting it to 'false' " +"forbids core dumps for all SSSD processes to avoid leaking plain text " +"passwords. See man page prctl:PR_SET_DUMPABLE on Linux or " +"procctl:PROC_TRACE_CTL on FreeBSD for details." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:703 +msgid "" +"Take a note that this setting has no effect for 'ldap_child', 'krb5_child' " +"and 'sssd_pam' as those privileged binaries can have a copy of a host keytab " +"data in a memory and their behavior in this regards is governed by " +"/proc/sys/fs/suid_dumpable system setting." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:716 +msgid "passkey_verification (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:724 +msgid "user_verification (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:726 +msgid "" +"Enable or disable the user verification (i.e. PIN, fingerprint) during " +"authentication. If enabled, the PIN will always be requested." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:732 +msgid "" +"The default is that the key settings decide what to do. In the IPA or " +"kerberos pre-authentication case, this value will be overwritten by the " +"server." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:719 +msgid "" +"With this parameter the passkey verification can be tuned with a comma " +"separated list of options. Supported options are: <placeholder " +"type=\"variablelist\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:256 +msgid "" +"Individual pieces of SSSD functionality are provided by special SSSD " +"services that are started and stopped together with SSSD. The services are " +"managed by a special service frequently called <quote>monitor</quote>. The " +"<quote>[sssd]</quote> section is used to configure the monitor as well as " +"some other important options like the identity domains. <placeholder " +"type=\"variablelist\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd.conf.5.xml:751 +msgid "SERVICES SECTIONS" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:753 +msgid "" +"Settings that can be used to configure different services are described in " +"this section. They should reside in the [<replaceable>$NAME</replaceable>] " +"section, for example, for NSS service, the section would be " +"<quote>[nss]</quote>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><title> +#: sssd.conf.5.xml:760 +msgid "General service configuration options" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:762 +msgid "These options can be used to configure any service." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:766 +msgid "fd_limit (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:769 +msgid "" +"This option specifies the maximum number of file descriptors that may be " +"opened at one time by this SSSD process. Note this value will be capped by " +"the init system at the startup of SSSD, see e.g. man systemd.exec for " +"details." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:776 +msgid "Default: 8192 (or limits.conf \"hard\" limit)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:781 +msgid "client_idle_timeout (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:784 +msgid "" +"This option specifies the number of seconds that a client of an SSSD process " +"can hold onto a file descriptor without communicating on it. This value is " +"limited in order to avoid resource exhaustion on the system. The timeout " +"can't be shorter than 10 seconds. If a lower value is configured, it will be " +"adjusted to 10 seconds." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:793 +msgid "Default: 60, KCM: 300" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:798 +msgid "responder_idle_timeout (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:801 +msgid "" +"This option specifies the number of seconds that an SSSD responder process " +"can be up without being used. This value is limited in order to avoid " +"resource exhaustion on the system. The minimum acceptable value for this " +"option is 60 seconds. Setting this option to 0 (zero) means that no timeout " +"will be set up to the responder. This option only has effect when SSSD is " +"built with systemd support and when services are either socket or D-Bus " +"activated." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:815 sssd.conf.5.xml:1079 sssd.conf.5.xml:2285 +#: sssd-ldap.5.xml:377 +msgid "Default: 300" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:820 +msgid "cache_first (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:823 +msgid "" +"This option specifies whether the responder should query all caches before " +"querying the Data Providers." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><title> +#: sssd.conf.5.xml:835 +msgid "NSS configuration options" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:837 +msgid "" +"These options can be used to configure the Name Service Switch (NSS) service " +"and should be specified under the <quote>[nss]</quote> section." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:843 +msgid "enum_cache_timeout (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:846 +msgid "" +"How many seconds should nss_sss cache enumerations (requests for info about " +"all users)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:850 +msgid "Default: 120" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:855 +msgid "entry_cache_nowait_percentage (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:858 +msgid "" +"The entry cache can be set to automatically update entries in the background " +"if they are requested beyond a percentage of the entry_cache_timeout value " +"for the domain." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:864 +msgid "" +"For example, if the domain's entry_cache_timeout is set to 30s and " +"entry_cache_nowait_percentage is set to 50 (percent), entries that come in " +"after 15 seconds past the last cache update will be returned immediately, " +"but the SSSD will go and update the cache on its own, so that future " +"requests will not need to block waiting for a cache update." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:874 +msgid "" +"Valid values for this option are 0-99 and represent a percentage of the " +"entry_cache_timeout for each domain. For performance reasons, this " +"percentage will never reduce the nowait timeout to less than 10 seconds. (0 " +"disables this feature)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:882 sssd.conf.5.xml:2093 +msgid "Default: 50" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:887 +msgid "entry_negative_timeout (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:890 +msgid "" +"Specifies for how many seconds nss_sss should cache negative cache hits " +"(that is, queries for invalid database entries, like nonexistent ones) " +"before asking the back end again." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:896 sssd.conf.5.xml:1677 sssd.conf.5.xml:2119 +msgid "Default: 15" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:901 +msgid "filter_users, filter_groups (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:904 +msgid "" +"Exclude certain users or groups from being fetched from the sss NSS " +"database. This is particularly useful for system accounts. This option can " +"also be set per-domain or include fully-qualified names to filter only users " +"from the particular domain or by a user principal name (UPN)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:912 +msgid "" +"NOTE: The filter_groups option doesn't affect inheritance of nested group " +"members, since filtering happens after they are propagated for returning via " +"NSS. E.g. a group having a member group filtered out will still have the " +"member users of the latter listed." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:920 +msgid "Default: root" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:925 +msgid "filter_users_in_groups (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:928 +msgid "If you want filtered users to remain group members set this option to false" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:939 +msgid "fallback_homedir (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:942 +msgid "" +"Set a default template for a user's home directory if one is not specified " +"explicitly by the domain's data provider." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:947 +msgid "The available values for this option are the same as for override_homedir." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> +#: sssd.conf.5.xml:953 +#, no-wrap +msgid "" +"fallback_homedir = /home/%u\n" +" " +msgstr "" + +#. type: Content of: <varlistentry><listitem><para> +#: sssd.conf.5.xml:951 sssd.conf.5.xml:1524 sssd.conf.5.xml:1543 +#: sssd.conf.5.xml:1645 sssd-krb5.5.xml:451 include/override_homedir.xml:78 +msgid "example: <placeholder type=\"programlisting\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:957 +msgid "Default: not set (no substitution for unset home directories)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:963 +msgid "override_shell (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:966 +msgid "" +"Override the login shell for all users. This option supersedes any other " +"shell options if it takes effect and can be set either in the [nss] section " +"or per-domain." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:972 +msgid "Default: not set (SSSD will use the value retrieved from LDAP)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:978 +msgid "allowed_shells (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:981 +msgid "Restrict user shell to one of the listed values. The order of evaluation is:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:984 +msgid "1. If the shell is present in <quote>/etc/shells</quote>, it is used." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:988 +msgid "" +"2. If the shell is in the allowed_shells list but not in " +"<quote>/etc/shells</quote>, use the value of the shell_fallback parameter." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:993 +msgid "" +"3. If the shell is not in the allowed_shells list and not in " +"<quote>/etc/shells</quote>, a nologin shell is used." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:998 +msgid "The wildcard (*) can be used to allow any shell." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1001 +msgid "" +"The (*) is useful if you want to use shell_fallback in case that user's " +"shell is not in <quote>/etc/shells</quote> and maintaining list of all " +"allowed shells in allowed_shells would be to much overhead." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1008 +msgid "An empty string for shell is passed as-is to libc." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1011 +msgid "" +"The <quote>/etc/shells</quote> is only read on SSSD start up, which means " +"that a restart of the SSSD is required in case a new shell is installed." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1015 +msgid "Default: Not set. The user shell is automatically used." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1020 +msgid "vetoed_shells (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1023 +msgid "Replace any instance of these shells with the shell_fallback" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1031 +msgid "shell_fallback (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1034 +msgid "" +"The default shell to use if an allowed shell is not installed on the " +"machine." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1038 +msgid "Default: /bin/sh" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1043 +msgid "default_shell (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1046 +msgid "" +"The default shell to use if the provider does not return one during " +"lookup. This option can be specified globally in the [nss] section or " +"per-domain." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1052 +msgid "" +"Default: not set (Return NULL if no shell is specified and rely on libc to " +"substitute something sensible when necessary, usually /bin/sh)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1059 sssd.conf.5.xml:1450 +msgid "get_domains_timeout (int)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1062 sssd.conf.5.xml:1453 +msgid "" +"Specifies time in seconds for which the list of subdomains will be " +"considered valid." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1066 sssd.conf.5.xml:1457 sssd.conf.5.xml:1788 +#: sssd.conf.5.xml:2862 sssd-ldap.5.xml:550 +msgid "Default: 60" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1071 +msgid "memcache_timeout (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1074 +msgid "" +"Specifies time in seconds for which records in the in-memory cache will be " +"valid. Setting this option to zero will disable the in-memory cache." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1082 +msgid "" +"WARNING: Disabling the in-memory cache will have significant negative impact " +"on SSSD's performance and should only be used for testing." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1088 sssd.conf.5.xml:1113 sssd.conf.5.xml:1138 +#: sssd.conf.5.xml:1163 sssd.conf.5.xml:1190 +msgid "" +"NOTE: If the environment variable SSS_NSS_USE_MEMCACHE is set to \"NO\", " +"client applications will not use the fast in-memory cache." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1096 +msgid "memcache_size_passwd (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1099 +msgid "" +"Size (in megabytes) of the data table allocated inside fast in-memory cache " +"for passwd requests. Setting the size to 0 will disable the passwd " +"in-memory cache." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1105 sssd.conf.5.xml:3013 sssd-ldap.5.xml:604 +msgid "Default: 8" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1108 sssd.conf.5.xml:1133 sssd.conf.5.xml:1158 +#: sssd.conf.5.xml:1185 +msgid "" +"WARNING: Disabled or too small in-memory cache can have significant negative " +"impact on SSSD's performance." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1121 +msgid "memcache_size_group (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1124 +msgid "" +"Size (in megabytes) of the data table allocated inside fast in-memory cache " +"for group requests. Setting the size to 0 will disable the group in-memory " +"cache." +msgstr "" + +#. type: Content of: <variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1130 sssd.conf.5.xml:1182 sssd.conf.5.xml:3835 +#: sssd-ldap.5.xml:534 sssd-ldap.5.xml:581 include/failover.xml:116 +#: include/krb5_options.xml:11 +msgid "Default: 6" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1146 +msgid "memcache_size_initgroups (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1149 +msgid "" +"Size (in megabytes) of the data table allocated inside fast in-memory cache " +"for initgroups requests. Setting the size to 0 will disable the initgroups " +"in-memory cache." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1171 +msgid "memcache_size_sid (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1174 +msgid "" +"Size (in megabytes) of the data table allocated inside fast in-memory cache " +"for SID related requests. Only SID-by-ID and ID-by-SID requests are " +"currently cached in fast in-memory cache. Setting the size to 0 will " +"disable the SID in-memory cache." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1198 sssd-ifp.5.xml:90 +msgid "user_attributes (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1201 +msgid "" +"Some of the additional NSS responder requests can return more attributes " +"than just the POSIX ones defined by the NSS interface. The list of " +"attributes is controlled by this option. It is handled the same way as the " +"<quote>user_attributes</quote> option of the InfoPipe responder (see " +"<citerefentry> <refentrytitle>sssd-ifp</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry> for details) but with no default " +"values." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1214 +msgid "" +"To make configuration more easy the NSS responder will check the InfoPipe " +"option if it is not set for the NSS responder." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1219 +msgid "Default: not set, fallback to InfoPipe option" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1224 +msgid "pwfield (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1227 +msgid "" +"The value that NSS operations that return users or groups will return for " +"the <quote>password</quote> field." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1232 +msgid "" +"This option can also be set per-domain, which overwrites the value in the " +"<quote>[nss]</quote> section for that domain. This is particularly useful " +"when using a proxy domain with <option>proxy_lib_name=files</option> and a " +"<option>proxy_pam_target</option> other than " +"<quote>sssd-shadowutils</quote>. In that case, SSSD returns <quote>*</quote> " +"for the password field by default, which causes <command>pam_unix</command> " +"to treat all accounts as locked. Setting <option>pwfield = x</option> in the " +"domain section restores the expected behavior." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1246 +msgid "Default: <quote>*</quote>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1249 +msgid "" +"Default (per-domain): <quote>not set</quote> (remote domains), " +"<quote>x</quote> (proxy domain with nss_files and sssd-shadowutils target)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><title> +#: sssd.conf.5.xml:1258 +msgid "PAM configuration options" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:1260 +msgid "" +"These options can be used to configure the Pluggable Authentication Module " +"(PAM) service and should be specified under the <quote>[pam]</quote> " +"section." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1266 +msgid "offline_credentials_expiration (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1269 +msgid "" +"If the authentication provider is offline, how long should we allow cached " +"logins (in days since the last successful online login)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1274 sssd.conf.5.xml:1287 +msgid "Default: 0 (No limit)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1280 +msgid "offline_failed_login_attempts (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1283 +msgid "" +"If the authentication provider is offline, how many failed login attempts " +"are allowed." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1293 +msgid "offline_failed_login_delay (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1296 +msgid "" +"The time in minutes which has to pass after offline_failed_login_attempts " +"has been reached before a new login attempt is possible." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1301 +msgid "" +"If set to 0 the user cannot authenticate offline if " +"offline_failed_login_attempts has been reached. Only a successful online " +"authentication can enable offline authentication again." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1307 sssd.conf.5.xml:1417 +msgid "Default: 5" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1313 +msgid "pam_verbosity (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1316 +msgid "" +"Controls what kind of messages are shown to the user during " +"authentication. The higher the number to more messages are displayed." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1321 +msgid "Currently sssd supports the following values:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1324 +msgid "<emphasis>0</emphasis>: do not show any message" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1327 +msgid "<emphasis>1</emphasis>: show only important messages" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1331 +msgid "<emphasis>2</emphasis>: show informational messages" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1334 +msgid "<emphasis>3</emphasis>: show all messages and debug information" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1338 sssd.8.xml:63 +msgid "Default: 1" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1344 +msgid "pam_response_filter (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1347 +msgid "" +"A comma separated list of strings which allows to remove (filter) data sent " +"by the PAM responder to pam_sss PAM module. There are different kind of " +"responses sent to pam_sss e.g. messages displayed to the user or environment " +"variables which should be set by pam_sss." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1355 +msgid "" +"While messages already can be controlled with the help of the pam_verbosity " +"option this option allows to filter out other kind of responses as well." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1362 +msgid "ENV" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1363 +msgid "Do not send any environment variables to any service." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1366 +msgid "ENV:var_name" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1367 +msgid "Do not send environment variable var_name to any service." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1371 +msgid "ENV:var_name:service" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1372 +msgid "Do not send environment variable var_name to service." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1360 +msgid "" +"Currently the following filters are supported: <placeholder " +"type=\"variablelist\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1379 +msgid "" +"The list of strings can either be the list of filters which would set this " +"list of filters and overwrite the defaults. Or each element of the list can " +"be prefixed by a '+' or '-' character which would add the filter to the " +"existing default or remove it from the defaults, respectively. Please note " +"that either all list elements must have a '+' or '-' prefix or none. It is " +"considered as an error to mix both styles." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1390 +msgid "Default: ENV:KRB5CCNAME:sudo, ENV:KRB5CCNAME:sudo-i" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1393 +msgid "Example: -ENV:KRB5CCNAME:sudo-i will remove the filter from the default list" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1400 +msgid "pam_id_timeout (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1403 +msgid "" +"For any PAM request while SSSD is online, the SSSD will attempt to " +"immediately update the cached identity information for the user in order to " +"ensure that authentication takes place with the latest information." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1409 +msgid "" +"A complete PAM conversation may perform multiple PAM requests, such as " +"account management and session opening. This option controls (on a " +"per-client-application basis) how long (in seconds) we can cache the " +"identity information to avoid excessive round-trips to the identity " +"provider." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1423 +msgid "pam_pwd_expiration_warning (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1426 sssd.conf.5.xml:3037 +msgid "Display a warning N days before the password expires." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1429 +msgid "" +"Please note that the backend server has to provide information about the " +"expiration time of the password. If this information is missing, sssd " +"cannot display a warning." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1435 sssd.conf.5.xml:3040 +msgid "" +"If zero is set, then this filter is not applied, i.e. if the expiration " +"warning was received from backend server, it will automatically be " +"displayed." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1440 +msgid "" +"This setting can be overridden by setting " +"<emphasis>pwd_expiration_warning</emphasis> for a particular domain." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1445 sssd.conf.5.xml:4118 sssd-ldap.5.xml:662 +#: sssd-ldap.5.xml:1733 sssd.8.xml:79 +msgid "Default: 0" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1462 +msgid "pam_trusted_users (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1465 +msgid "" +"Specifies the comma-separated list of UID values or user names that are " +"allowed to run PAM conversations against trusted domains. Users not " +"included in this list can only access domains marked as public with " +"<quote>pam_public_domains</quote>. User names are resolved to UIDs at " +"startup." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1475 +msgid "Default: All users are considered trusted by default" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1479 +msgid "" +"Please note that UID 0 is always allowed to access the PAM responder even in " +"case it is not in the pam_trusted_users list." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1486 +msgid "pam_public_domains (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1489 +msgid "" +"Specifies the comma-separated list of domain names that are accessible even " +"to untrusted users." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1493 +msgid "Two special values for pam_public_domains option are defined:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1497 +msgid "all (Untrusted users are allowed to access all domains in PAM responder.)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1501 +msgid "" +"none (Untrusted users are not allowed to access any domains PAM in " +"responder.)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1505 sssd.conf.5.xml:1530 sssd.conf.5.xml:1549 +#: sssd.conf.5.xml:1821 sssd.conf.5.xml:4048 sssd-ldap.5.xml:1270 +msgid "Default: none" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1510 +msgid "pam_account_expired_message (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1513 +msgid "" +"Allows a custom expiration message to be set, replacing the default " +"'Permission denied' message." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1518 +msgid "" +"Note: Please be aware that message is only printed for the SSH service " +"unless pam_verbosity is set to 3 (show all messages and debug information)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> +#: sssd.conf.5.xml:1526 +#, no-wrap +msgid "" +"pam_account_expired_message = Account expired, please contact help desk.\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1535 +msgid "pam_account_locked_message (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1538 +msgid "" +"Allows a custom lockout message to be set, replacing the default 'Permission " +"denied' message." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> +#: sssd.conf.5.xml:1545 +#, no-wrap +msgid "" +"pam_account_locked_message = Account locked, please contact help desk.\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1554 +msgid "pam_passkey_auth (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1557 +msgid "Enable passkey device based authentication." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1560 sssd.conf.5.xml:1907 sssd-ad.5.xml:1279 +#: sss_rpcidmapd.5.xml:76 +msgid "Default: True" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1565 +msgid "passkey_debug_libfido2 (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1568 +msgid "Enable libfido2 library debug messages." +msgstr "" + +#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1571 sssd.conf.5.xml:1585 sssd.conf.5.xml:4781 +#: sssd-ldap.5.xml:727 sssd-ldap.5.xml:752 sssd-ldap.5.xml:848 +#: sssd-ldap.5.xml:1356 sssd-ad.5.xml:506 sssd-ad.5.xml:582 sssd-ad.5.xml:1160 +#: include/ldap_id_mapping.xml:250 +msgid "Default: False" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1576 +msgid "pam_cert_auth (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1579 +msgid "" +"Enable certificate based Smartcard authentication. Since this requires " +"additional communication with the Smartcard which will delay the " +"authentication process this option is disabled by default." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1588 +msgid "" +"Note: In case OpenSC is used for Smartcard access SSSD supports the " +"filesystem caching in OpenSC when enabled in opensc.conf. The cached files " +"are located in a common <quote>opensc</quote> directory in SSSD's state " +"directory. The behaviour can be changed in opensc.conf" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> +#: sssd.conf.5.xml:1597 +#, no-wrap +msgid "" +"app /usr/libexec/sssd/p11_child {\n" +" framework pkcs15 {\n" +" use_file_caching = no;\n" +" }\n" +"}\n" +"app /usr/libexec/sssd/krb5_child {\n" +" framework pkcs15 {\n" +" use_file_caching = no;\n" +" }\n" +"}\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1595 +msgid "Example opensc.conf (*): <placeholder type=\"programlisting\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1610 +msgid "" +"(*) The actual <quote>libexec</quote> directory for p11_child and krb5_child " +"depends on the distribution." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1615 +msgid "pam_cert_db_path (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1618 +msgid "The path to the certificate database." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1621 sssd.conf.5.xml:2199 sssd.conf.5.xml:4543 +msgid "Default:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:1623 sssd.conf.5.xml:2201 +msgid "" +"/etc/sssd/pki/sssd_auth_ca_db.pem (path to a file with trusted CA " +"certificates in PEM format)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1633 +msgid "pam_cert_verification (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1636 +msgid "" +"With this parameter the PAM certificate verification can be tuned with a " +"comma separated list of options that override the " +"<quote>certificate_verification</quote> value in <quote>[sssd]</quote> " +"section. Supported options are the same of " +"<quote>certificate_verification</quote>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> +#: sssd.conf.5.xml:1647 +#, no-wrap +msgid "" +"pam_cert_verification = partial_chain\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1651 +msgid "" +"Default: not set, i.e. use default <quote>certificate_verification</quote> " +"option defined in <quote>[sssd]</quote> section." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1658 +msgid "p11_child_timeout (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1661 +msgid "How many seconds will pam_sss wait for p11_child to finish." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1670 +msgid "passkey_child_timeout (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1673 +msgid "How many seconds will the PAM responder wait for passkey_child to finish." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1682 +msgid "pam_app_services (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1685 +msgid "" +"Which PAM services are permitted to contact domains of type " +"<quote>application</quote>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1694 +msgid "pam_p11_allowed_services (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1697 +msgid "" +"A comma-separated list of PAM service names for which it will be allowed to " +"use Smartcards." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> +#: sssd.conf.5.xml:1712 +#, no-wrap +msgid "" +"pam_p11_allowed_services = +my_pam_service, -login\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1701 +msgid "" +"It is possible to add another PAM service name to the default set by using " +"<quote>+service_name</quote> or to explicitly remove a PAM service name from " +"the default set by using <quote>-service_name</quote>. For example, in order " +"to replace a default PAM service name for authentication with Smartcards " +"(e.g. <quote>login</quote>) with a custom PAM service name " +"(e.g. <quote>my_pam_service</quote>), you would use the following " +"configuration: <placeholder type=\"programlisting\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1716 sssd-ad.5.xml:645 sssd-ad.5.xml:759 sssd-ad.5.xml:817 +#: sssd-ad.5.xml:875 sssd-ad.5.xml:953 +msgid "Default: the default set of PAM service names includes:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:1721 sssd-ad.5.xml:649 +msgid "login" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:1726 sssd-ad.5.xml:654 +msgid "su" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:1731 sssd-ad.5.xml:659 +msgid "su-l" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:1736 sssd-ad.5.xml:674 +msgid "gdm-smartcard" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:1741 sssd-ad.5.xml:669 +msgid "gdm-password" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:1746 +msgid "gdm-switchable-auth" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:1751 sssd-ad.5.xml:679 +msgid "kdm" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:1756 sssd-ad.5.xml:694 +msgid "plasmalogin" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:1761 sssd-ad.5.xml:962 +msgid "sudo" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:1766 sssd-ad.5.xml:967 +msgid "sudo-i" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:1771 +msgid "gnome-screensaver" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1779 +msgid "p11_wait_for_card_timeout (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1782 +msgid "" +"If Smartcard authentication is required how many extra seconds in addition " +"to p11_child_timeout should the PAM responder wait until a Smartcard is " +"inserted." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1793 +msgid "p11_uri (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1796 +msgid "" +"PKCS#11 URI (see RFC-7512 for details) which can be used to restrict the " +"selection of devices used for Smartcard authentication. By default SSSD's " +"p11_child will search for a PKCS#11 slot (reader) where the 'removable' " +"flags is set and read the certificates from the inserted token from the " +"first slot found. If multiple readers are connected p11_uri can be used to " +"tell p11_child to use a specific reader." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> +#: sssd.conf.5.xml:1809 +#, no-wrap +msgid "" +"p11_uri = pkcs11:slot-description=My%20Smartcard%20Reader\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> +#: sssd.conf.5.xml:1813 +#, no-wrap +msgid "" +"p11_uri = " +"pkcs11:library-description=OpenSC%20smartcard%20framework;slot-id=2\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1807 +msgid "" +"Example: <placeholder type=\"programlisting\" id=\"0\"/> or <placeholder " +"type=\"programlisting\" id=\"1\"/> To find suitable URI please check the " +"debug output of p11_child. As an alternative the GnuTLS utility 'p11tool' " +"with e.g. the '--list-all' will show PKCS#11 URIs as well." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1826 +msgid "pam_initgroups_scheme (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1834 +msgid "always" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1835 +msgid "Always do an online lookup, please note that pam_id_timeout still applies" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1839 +msgid "no_session" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1840 +msgid "" +"Only do an online lookup if there is no active session of the user, i.e. if " +"the user is currently not logged in" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:1845 sssd-ldap.5.xml:189 +msgid "never" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1846 +msgid "" +"Never force an online lookup, use the data from the cache as long as they " +"are not expired" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1829 +msgid "" +"The PAM responder can force an online lookup to get the current group " +"memberships of the user trying to log in. This option controls when this " +"should be done and the following values are allowed: <placeholder " +"type=\"variablelist\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1853 +msgid "Default: no_session" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1858 +msgid "pam_gssapi_services (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1861 +msgid "" +"Comma separated list of PAM services that are allowed to try GSSAPI " +"authentication using pam_sss_gss.so module." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1866 +msgid "" +"To disable GSSAPI authentication, set this option to <quote>-</quote> " +"(dash)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1870 sssd.conf.5.xml:1901 sssd.conf.5.xml:1939 +msgid "" +"Note: This option can also be set per-domain which overwrites the value in " +"[pam] section. It can also be set for trusted domain which overwrites the " +"value in the domain section." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> +#: sssd.conf.5.xml:1878 +#, no-wrap +msgid "" +"pam_gssapi_services = sudo, sudo-i\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1876 sssd.conf.5.xml:2023 sssd.conf.5.xml:4042 +msgid "Example: <placeholder type=\"programlisting\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1882 +msgid "Default: - (GSSAPI authentication is disabled)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1887 +msgid "pam_gssapi_check_upn (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1890 +msgid "" +"If True, SSSD will require that the Kerberos user principal that " +"successfully authenticated through GSSAPI can be associated with the user " +"who is being authenticated. Authentication will fail if the check fails." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1897 +msgid "" +"If False, every user that is able to obtain a required service ticket will " +"be authenticated." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1912 +msgid "pam_gssapi_indicators_map (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1915 +msgid "" +"Comma separated list of authentication indicators required to be present in " +"a Kerberos ticket to access a PAM service that is allowed to try GSSAPI " +"authentication using pam_sss_gss.so module." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1921 +msgid "" +"Each element of the list can be either an authentication indicator name or a " +"pair <quote>service:indicator</quote>. Indicators not prefixed with the PAM " +"service name will be required to access any PAM service configured to be " +"used with <option>pam_gssapi_services</option>. A resulting list of " +"indicators per PAM service is then checked against indicators in the " +"Kerberos ticket during authentication by pam_sss_gss.so. Any indicator from " +"the ticket that matches the resulting list of indicators for the PAM service " +"would grant access. If none of the indicators in the list match, access will " +"be denied. If the resulting list of indicators for the PAM service is empty, " +"the check will not prevent the access." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1934 +msgid "" +"To disable GSSAPI authentication indicator check, set this option to " +"<quote>-</quote> (dash). To disable the check for a specific PAM service, " +"add <quote>service:-</quote>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1945 +msgid "" +"Following authentication indicators are supported by IPA Kerberos " +"deployments:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:1948 +msgid "" +"pkinit -- pre-authentication using X.509 certificates -- whether stored in " +"files or on smart cards." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:1951 +msgid "" +"hardened -- SPAKE pre-authentication or any pre-authentication wrapped in a " +"FAST channel." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:1954 +msgid "radius -- pre-authentication with the help of a RADIUS server." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:1957 +msgid "" +"otp -- pre-authentication using integrated two-factor authentication (2FA or " +"one-time password, OTP) in IPA." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:1960 +msgid "idp -- pre-authentication using external identity provider." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> +#: sssd.conf.5.xml:1970 +#, no-wrap +msgid "" +"pam_gssapi_indicators_map = sudo:pkinit, sudo-i:pkinit\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1965 +msgid "" +"Example: to require access to SUDO services only for users which obtained " +"their Kerberos tickets with a X.509 certificate pre-authentication (PKINIT), " +"set <placeholder type=\"programlisting\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1974 +msgid "Default: not set (use of authentication indicators is not required)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1979 +msgid "pam_gssapi_indicators_apply (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1982 +msgid "" +"Comma separated list of triples to assign additional information from the " +"Kerberos ticket, e.g. a SID from the PAC, to authentication indicators." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1988 +msgid "Currently supported is:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:1991 +msgid "SID:S-1-5-[domain]-[RID]:[authentication indicator]" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> +#: sssd.conf.5.xml:2002 +#, no-wrap +msgid "" +"pam_gssapi_indicators_apply = SID:S-1-5-12345-23456-34567-4321:pkinit\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1996 +msgid "" +"Example: To assign a SID, which is e.g. set by Active Directory's " +"Authentication Mechanism Assurance (AMA) if the AD user used a Smartcard for " +"authentication, to the 'pkinit' authentication indicator use: <placeholder " +"type=\"programlisting\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2011 +msgid "pam_json_services (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2014 +msgid "" +"Comma separated list of PAM services which can handle the JSON protocol for " +"selecting authentication mechanisms" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2019 +msgid "To disable JSON protocol, set this option to <quote>-</quote> (dash)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> +#: sssd.conf.5.xml:2025 +#, no-wrap +msgid "" +"pam_json_services = gdm-switchable-auth\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2029 +msgid "Default: - (JSON protocol is disabled)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2032 +msgid "" +"Note: 2-Factor Authentication (2FA) is not supported. If 2FA is required, do " +"not activate the JSON protocol." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><title> +#: sssd.conf.5.xml:2042 +msgid "SUDO configuration options" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:2044 +msgid "" +"These options can be used to configure the sudo service and should be " +"specified under the <quote>[sudo]</quote> section." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:2048 +msgid "" +"The detailed instructions for configuration of <citerefentry> " +"<refentrytitle>sudo</refentrytitle> <manvolnum>8</manvolnum> </citerefentry> " +"to work with <citerefentry> <refentrytitle>sssd</refentrytitle> " +"<manvolnum>8</manvolnum> </citerefentry> are in the manual page " +"<citerefentry> <refentrytitle>sssd-sudo</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2064 +msgid "sudo_timed (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2067 +msgid "" +"Whether or not to evaluate the sudoNotBefore and sudoNotAfter attributes " +"that implement time-dependent sudoers entries." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2079 +msgid "sudo_threshold (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2082 +msgid "" +"Maximum number of expired rules that can be refreshed at once. If number of " +"expired rules is below threshold, those rules are refreshed with " +"<quote>rules refresh</quote> mechanism. If the threshold is exceeded a " +"<quote>full refresh</quote> of sudo rules is triggered instead. This " +"threshold number also applies to IPA sudo command and command group " +"searches." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><title> +#: sssd.conf.5.xml:2101 +msgid "AUTOFS configuration options" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:2103 +msgid "" +"These options can be used to configure the autofs service and should be " +"specified under the <quote>[autofs]</quote> section." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2109 +msgid "autofs_negative_timeout (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2112 +msgid "" +"Specifies for how many seconds should the autofs responder negative cache " +"hits (that is, queries for invalid map entries, like nonexistent ones) " +"before asking the back end again." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><title> +#: sssd.conf.5.xml:2128 +msgid "SSH configuration options" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:2130 +msgid "" +"These options can be used to configure the SSH service and should be " +"specified under the <quote>[ssh]</quote> section." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2136 +msgid "ssh_use_certificate_keys (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2139 +msgid "" +"If set to true the <command>sss_ssh_authorizedkeys</command> will return ssh " +"keys derived from the public key of X.509 certificates stored in the user " +"entry as well. See <citerefentry> " +"<refentrytitle>sss_ssh_authorizedkeys</refentrytitle> " +"<manvolnum>1</manvolnum> </citerefentry> for details." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2154 +msgid "ssh_use_certificate_matching_rules (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2157 +msgid "" +"By default the ssh responder will use all available certificate matching " +"rules to filter the certificates so that ssh keys are only derived from the " +"matching ones. With this option the used rules can be restricted with a " +"comma separated list of mapping and matching rule names. All other rules " +"will be ignored." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2166 +msgid "" +"There are two special key words 'all_rules' and 'no_rules' which will enable " +"all or no rules, respectively. The latter means that no certificates will be " +"filtered out and ssh keys will be generated from all valid certificates." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2173 +msgid "" +"If no rules are configured using 'all_rules' will enable a default rule " +"which enables all certificates suitable for client authentication. This is " +"the same behavior as for the PAM responder if certificate authentication is " +"enabled." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2180 +msgid "" +"A non-existing rule name is considered an error. If as a result no rule is " +"selected all certificates will be ignored." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2185 +msgid "" +"Default: not set, equivalent to 'all_rules', all found rules or the default " +"rule are used" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2191 +msgid "ca_db (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2194 +msgid "" +"Path to a storage of trusted CA certificates. The option is used to validate " +"user certificates before deriving public ssh keys from them." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><title> +#: sssd.conf.5.xml:2214 +msgid "PAC responder configuration options" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:2216 +msgid "" +"The PAC responder works together with the authorization data plugin for MIT " +"Kerberos sssd_pac_plugin.so and a sub-domain provider. The plugin sends the " +"PAC data during a GSSAPI authentication to the PAC responder. The sub-domain " +"provider collects domain SID and ID ranges of the domain the client is " +"joined to and of remote trusted domains from the local domain controller. If " +"the PAC is decoded and evaluated some of the following operations are done:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:2225 +msgid "" +"If the remote user does not exist in the cache, it is created. The UID is " +"determined with the help of the SID, trusted domains will have UPGs and the " +"GID will have the same value as the UID. The home directory is set based on " +"the subdomain_homedir parameter. The shell will be empty by default, " +"i.e. the system defaults are used, but can be overwritten with the " +"default_shell parameter." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:2233 +msgid "" +"If there are SIDs of groups from domains sssd knows about, the user will be " +"added to those groups." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:2239 +msgid "" +"These options can be used to configure the PAC responder and should be " +"specified under the <quote>[pac]</quote> section." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2244 sssd-ifp.5.xml:66 +msgid "allowed_uids (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2247 +msgid "" +"Specifies the comma-separated list of UID values or user names that are " +"allowed to access the PAC responder. User names are resolved to UIDs at " +"startup." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2253 +msgid "" +"Default: 0, &sssd_user_name; (only root and SSSD service users are allowed " +"to access the PAC responder)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2257 +msgid "Default: 0 (only the root user is allowed to access the PAC responder)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2261 +msgid "" +"Please note that defaults will be overwritten with this option. If you still " +"want to allow the root and/or '&sssd_user_name;' user to access the PAC " +"responder, which would be the typical case, you have to add those to the " +"list of allowed UIDs explicitly." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2268 +msgid "" +"Please note that although the UID 0 is used as the default it will be " +"overwritten with this option. If you still want to allow the root user to " +"access the PAC responder, which would be the typical case, you have to add 0 " +"to the list of allowed UIDs as well." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2277 +msgid "pac_lifetime (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2280 +msgid "" +"Lifetime of the PAC entry in seconds. As long as the PAC is valid the PAC " +"data can be used to determine the group memberships of a user." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2290 +msgid "pac_check (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2293 +msgid "" +"Apply additional checks on the PAC of the Kerberos ticket which is available " +"in Active Directory and FreeIPA domains, if configured. Please note that " +"Kerberos ticket validation must be enabled to be able to check the PAC, " +"i.e. the krb5_validate option must be set to 'True' which is the default for " +"the IPA and AD provider. If krb5_validate is set to 'False' the PAC checks " +"will be skipped." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2303 +msgid "" +"Please note that the checks listed below only apply to PACs issued by Active " +"Directory or recent versions of FreeIPA. PACs issued e.g. by a plain MIT " +"Kerberos KDC will not contain the needed PAC data buffers to run the checks." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2314 +msgid "no_check" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2316 +msgid "" +"The PAC must not be present and even if it is present no additional checks " +"will be done." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2322 +msgid "pac_present" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2324 +msgid "" +"The PAC must be present in the service ticket which SSSD will request with " +"the help of the user's TGT. If the PAC is not available the authentication " +"will fail." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2332 +msgid "check_upn" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2334 +msgid "" +"If the PAC is present check if the user principal name (UPN) information is " +"consistent." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2340 +msgid "check_upn_allow_missing" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2342 +msgid "" +"This option should be used together with 'check_upn' and handles the case " +"where a UPN is set on the server-side but is not read by SSSD. The typical " +"example is a FreeIPA domain where 'ldap_user_principal' is set to a not " +"existing attribute name. This was typically done to work-around issues in " +"the handling of enterprise principals. But this is fixed since quite some " +"time and FreeIPA can handle enterprise principals just fine and there is no " +"need anymore to set 'ldap_user_principal'." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2354 +msgid "" +"Currently this option is set by default to avoid regressions in such " +"environments. A log message will be added to the system log and SSSD's debug " +"log in case a UPN is found in the PAC but not in SSSD's cache. To avoid this " +"log message it would be best to evaluate if the 'ldap_user_principal' option " +"can be removed. If this is not possible, removing 'check_upn' will skip the " +"test and avoid the log message." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2368 +msgid "upn_dns_info_present" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2370 +msgid "The PAC must contain the UPN-DNS-INFO buffer, implies 'check_upn'." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2375 +msgid "check_upn_dns_info_ex" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2377 +msgid "" +"If the PAC is present and the extension to the UPN-DNS-INFO buffer is " +"available check if the information in the extension is consistent." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2384 +msgid "upn_dns_info_ex_present" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2386 +msgid "" +"The PAC must contain the extension of the UPN-DNS-INFO buffer, implies " +"'check_upn_dns_info_ex', 'upn_dns_info_present' and 'check_upn'." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2310 +msgid "" +"The following options can be used alone or in a comma-separated list: " +"<placeholder type=\"variablelist\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2396 +msgid "" +"Default: no_check (AD and IPA provider 'check_upn, check_upn_allow_missing, " +"check_upn_dns_info_ex')" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><title> +#: sssd.conf.5.xml:2405 +msgid "Session recording configuration options" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:2407 +msgid "" +"Session recording works in conjunction with <citerefentry> " +"<refentrytitle>tlog-rec-session</refentrytitle> <manvolnum>8</manvolnum> " +"</citerefentry>, a part of tlog package, to log what users see and type when " +"they log in on a text terminal. See also <citerefentry> " +"<refentrytitle>sssd-session-recording</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:2420 +msgid "" +"These options can be used to configure session recording and should be " +"specified under the <quote>[session_recording]</quote> section." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:2425 +msgid "" +"Note: Unlike other sections, the <quote>[session_recording]</quote> section " +"ignores <replaceable>debug*</replaceable> options and suitable " +"<replaceable>debug*</replaceable> options must be set in " +"<quote>[pam]</quote>, <quote>[nss]</quote> and " +"<quote>[domain/<replaceable>NAME</replaceable>]</quote> sections." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2433 sssd-session-recording.5.xml:64 +msgid "scope (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2440 sssd-session-recording.5.xml:71 +msgid "\"none\"" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2443 sssd-session-recording.5.xml:74 +msgid "No users are recorded." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2448 sssd-session-recording.5.xml:79 +msgid "\"some\"" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2451 sssd-session-recording.5.xml:82 +msgid "" +"Users/groups specified by <replaceable>users</replaceable> and " +"<replaceable>groups</replaceable> options are recorded." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2460 sssd-session-recording.5.xml:91 +msgid "\"all\"" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2463 sssd-session-recording.5.xml:94 +msgid "All users are recorded." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2436 sssd-session-recording.5.xml:67 +msgid "" +"One of the following strings specifying the scope of session recording: " +"<placeholder type=\"variablelist\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2470 sssd-session-recording.5.xml:101 +msgid "Default: \"none\"" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2475 sssd-session-recording.5.xml:106 +msgid "users (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2478 sssd-session-recording.5.xml:109 +msgid "" +"A comma-separated list of users which should have session recording " +"enabled. Matches user names as returned by NSS. I.e. after the possible " +"space replacement, case changes, etc." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2484 sssd-session-recording.5.xml:115 +msgid "Default: Empty. Matches no users." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2489 sssd-session-recording.5.xml:120 +msgid "groups (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2492 sssd-session-recording.5.xml:123 +msgid "" +"A comma-separated list of groups, members of which should have session " +"recording enabled. Matches group names as returned by NSS. I.e. after the " +"possible space replacement, case changes, etc." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2498 sssd.conf.5.xml:2530 sssd-session-recording.5.xml:129 +#: sssd-session-recording.5.xml:161 +msgid "" +"NOTE: using this option (having it set to anything) has a considerable " +"performance cost, because each uncached request for a user requires " +"retrieving and matching the groups the user is member of." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2505 sssd-session-recording.5.xml:136 +msgid "Default: Empty. Matches no groups." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2510 sssd-session-recording.5.xml:141 +msgid "exclude_users (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2513 sssd-session-recording.5.xml:144 +msgid "" +"A comma-separated list of users to be excluded from recording, only " +"applicable with 'scope=all'." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2517 sssd-session-recording.5.xml:148 +msgid "Default: Empty. No users excluded." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2522 sssd-session-recording.5.xml:153 +msgid "exclude_groups (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2525 sssd-session-recording.5.xml:156 +msgid "" +"A comma-separated list of groups, members of which should be excluded from " +"recording. Only applicable with 'scope=all'." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2537 sssd-session-recording.5.xml:168 +msgid "Default: Empty. No groups excluded." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd.conf.5.xml:2547 +msgid "DOMAIN SECTIONS" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2554 +msgid "enabled (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2557 +msgid "" +"Explicitly enable or disable the domain. If <quote>true</quote>, the domain " +"is always <quote>enabled</quote>. If <quote>false</quote>, the domain is " +"always <quote>disabled</quote>. If this option is not set, the domain is " +"enabled only if it is listed in the domains option in the " +"<quote>[sssd]</quote> section." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2569 +msgid "domain_type (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2572 +msgid "" +"Specifies whether the domain is meant to be used by POSIX-aware clients such " +"as the Name Service Switch or by applications that do not need POSIX data to " +"be present or generated. Only objects from POSIX domains are available to " +"the operating system interfaces and utilities." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2580 +msgid "" +"Allowed values for this option are <quote>posix</quote> and " +"<quote>application</quote>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2584 +msgid "" +"POSIX domains are reachable by all services. Application domains are only " +"reachable from the InfoPipe responder (see <citerefentry> " +"<refentrytitle>sssd-ifp</refentrytitle> <manvolnum>5</manvolnum> " +"</citerefentry>) and the PAM responder." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2592 +msgid "" +"NOTE: The application domains are currently well tested with " +"<quote>id_provider=ldap</quote> only." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2596 +msgid "" +"For an easy way to configure a non-POSIX domains, please see the " +"<quote>Application domains</quote> section." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2600 +msgid "Default: posix" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2606 +msgid "min_id,max_id (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2609 +msgid "" +"UID and GID limits for the domain. If a domain contains an entry that is " +"outside these limits, it is ignored." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2614 +msgid "" +"For users, this affects the primary GID limit. The user will not be returned " +"to NSS if either the UID or the primary GID is outside the range. For " +"non-primary group memberships, those that are in range will be reported as " +"expected." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2621 +msgid "" +"These ID limits affect even saving entries to cache, not only returning them " +"by name or ID." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2625 +msgid "Default: 1 for min_id, 0 (no limit) for max_id" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2631 +msgid "enumerate (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2634 +msgid "" +"Determines if a domain can be enumerated, that is, whether the domain can " +"list all the users and group it contains. Note that it is not required to " +"enable enumeration in order for secondary groups to be displayed. This " +"parameter can have one of the following values:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2642 +msgid "TRUE = Users and groups are enumerated" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2645 +msgid "FALSE = No enumerations for this domain" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2648 sssd.conf.5.xml:2992 sssd.conf.5.xml:3174 +msgid "Default: FALSE" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2651 +msgid "" +"Enumerating a domain requires SSSD to download and store ALL user and group " +"entries from the remote server." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2656 +msgid "" +"Feature is only supported for domains with id_provider = ldap or id_provider " +"= proxy." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2660 +msgid "" +"Note: Enabling enumeration has a severe performance impact on SSSD while " +"enumeration is running. It may take up to several minutes after SSSD startup " +"to fully complete enumerations. During this time, individual requests for " +"information will go directly to LDAP, though it may be slow, due to the " +"heavy enumeration processing. Saving a large number of entries to cache " +"after the enumeration completes might also be CPU intensive as the " +"memberships have to be recomputed. This can lead to the " +"<quote>sssd_be</quote> process becoming unresponsive or even restarted by " +"the internal watchdog." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2675 +msgid "" +"While the first enumeration is running, requests for the complete user or " +"group lists may return no results until it completes." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2680 +msgid "" +"Further, enabling enumeration may increase the time necessary to detect " +"network disconnection, as longer timeouts are required to ensure that " +"enumeration lookups are completed successfully. For more information, refer " +"to the man pages for the specific id_provider in use." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2688 +msgid "" +"For the reasons cited above, enabling enumeration is not recommended, " +"especially in large environments." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2693 +msgid "" +"Note: the proxy provider is tested with open source modules like " +"'libnss_files' and 'libnss_ldap'. 3rd party modules must follow the " +"documented behavior of nss modules to be used in this configuration." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2702 +msgid "entry_cache_timeout (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2705 +msgid "" +"How many seconds should nss_sss consider entries valid before asking the " +"backend again" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2709 +msgid "" +"The cache expiration timestamps are stored as attributes of individual " +"objects in the cache. Therefore, changing the cache timeout only has effect " +"for newly added or expired entries. You should run the <citerefentry> " +"<refentrytitle>sss_cache</refentrytitle> <manvolnum>8</manvolnum> " +"</citerefentry> tool in order to force refresh of entries that have already " +"been cached." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2722 +msgid "Default: 5400" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2728 +msgid "entry_cache_user_timeout (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2731 +msgid "" +"How many seconds should nss_sss consider user entries valid before asking " +"the backend again" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2735 sssd.conf.5.xml:2748 sssd.conf.5.xml:2761 +#: sssd.conf.5.xml:2774 sssd.conf.5.xml:2788 sssd.conf.5.xml:2801 +#: sssd.conf.5.xml:2815 sssd.conf.5.xml:2829 +msgid "Default: entry_cache_timeout" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2741 +msgid "entry_cache_group_timeout (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2744 +msgid "" +"How many seconds should nss_sss consider group entries valid before asking " +"the backend again" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2754 +msgid "entry_cache_netgroup_timeout (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2757 +msgid "" +"How many seconds should nss_sss consider netgroup entries valid before " +"asking the backend again" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2767 +msgid "entry_cache_service_timeout (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2770 +msgid "" +"How many seconds should nss_sss consider service entries valid before asking " +"the backend again" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2780 +msgid "entry_cache_resolver_timeout (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2783 +msgid "" +"How many seconds should nss_sss consider hosts and networks entries valid " +"before asking the backend again" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2794 +msgid "entry_cache_sudo_timeout (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2797 +msgid "" +"How many seconds should sudo consider rules valid before asking the backend " +"again" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2807 +msgid "entry_cache_autofs_timeout (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2810 +msgid "" +"How many seconds should the autofs service consider automounter maps valid " +"before asking the backend again" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2821 +msgid "entry_cache_ssh_host_timeout (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2824 +msgid "" +"How many seconds to keep a host ssh key after refresh. IE how long to cache " +"the host key for." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2835 +msgid "offline_timeout (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2838 +msgid "" +"When SSSD switches to offline mode the amount of time before it tries to go " +"back online will increase based upon the time spent disconnected. By " +"default SSSD uses incremental behaviour to calculate delay in between " +"retries. So, the wait time for a given retry will be longer than the wait " +"time for the previous ones. After each unsuccessful attempt to go online, " +"the new interval is recalculated by the following:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2849 sssd.conf.5.xml:2907 +msgid "" +"new_delay = Minimum(old_delay * 2, offline_timeout_max) + " +"random[0...offline_timeout_random_offset]" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2852 +msgid "" +"The offline_timeout default value is 60. The offline_timeout_max default " +"value is 3600. The offline_timeout_random_offset default value is 30. The " +"end result is the number of seconds before next retry." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2858 +msgid "" +"Note that the maximum length of each interval is defined by " +"offline_timeout_max (apart from the random part)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2868 +msgid "offline_timeout_max (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2871 +msgid "" +"Controls by how much the time between attempts to go online can be " +"incremented following unsuccessful attempts to go online." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2876 +msgid "A value of 0 disables the incrementing behaviour." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2879 +msgid "" +"The value of this parameter should be set in correlation to offline_timeout " +"parameter value." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2883 +msgid "" +"With offline_timeout set to 60 (default value) there is no point in setting " +"offline_timeout_max to less than 120 as it will saturate instantly. General " +"rule here should be to set offline_timeout_max to at least 4 times " +"offline_timeout." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2889 +msgid "" +"Although a value between 0 and offline_timeout may be specified, it has the " +"effect of overriding the offline_timeout value so is of little use." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2894 +msgid "Default: 3600" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2900 +msgid "offline_timeout_random_offset (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2903 +msgid "" +"When SSSD is in offline mode it keeps probing backend servers in specified " +"time intervals:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2910 +msgid "" +"This parameter controls the value of the random offset used for the above " +"equation. Final random_offset value will be random number in range:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2915 +msgid "[0 - offline_timeout_random_offset]" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2918 +msgid "A value of 0 disables the random offset addition." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2921 +msgid "Default: 30" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2927 +msgid "refresh_expired_interval (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2930 +msgid "" +"Specifies how many seconds SSSD has to wait before triggering a background " +"refresh task which will refresh all expired or nearly expired records." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2935 +msgid "" +"The background refresh will process users, groups and netgroups in the " +"cache. For users who have performed the initgroups (get group membership for " +"user, typically ran at login) operation in the past, both the user entry " +"and the group membership are updated." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2943 +msgid "This option is automatically inherited for all trusted domains." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2947 +msgid "You can consider setting this value to 3/4 * entry_cache_timeout." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2951 +msgid "" +"Cache entry will be refreshed by background task when 2/3 of cache timeout " +"has already passed. If there are existing cached entries, the background " +"task will refer to their original cache timeout values instead of current " +"configuration value. This may lead to a situation in which background " +"refresh task appears to not be working. This is done by design to improve " +"offline mode operation and reuse of existing valid cache entries. To make " +"this change instant the user may want to manually invalidate existing cache." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2964 sssd-ldap.5.xml:406 sssd-ldap.5.xml:1834 +#: sssd-ipa.5.xml:250 +msgid "Default: 0 (disabled)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2970 +msgid "cache_credentials (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2973 +msgid "" +"Determines if user credentials are also cached in the local LDB cache. The " +"cached credentials refer to passwords, which includes the first (long term) " +"factor of two-factor authentication, not other authentication " +"mechanisms. Passkey and Smartcard authentications are expected to work " +"offline as long as a successful online authentication is recorded in the " +"cache without additional configuration." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2984 +msgid "" +"Take a note that while credentials are stored as a salted SHA512 hash, this " +"still potentially poses some security risk in case an attacker manages to " +"get access to a cache file (normally requires privileged access) and to " +"break a password using brute force attack." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2998 +msgid "cache_credentials_minimal_first_factor_length (int)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3001 +msgid "" +"If 2-Factor-Authentication (2FA) is used and credentials should be saved " +"this value determines the minimal length the first authentication factor " +"(long term password) must have to be saved as SHA512 hash into the cache." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3008 +msgid "" +"This should avoid that the short PINs of a PIN based 2FA scheme are saved in " +"the cache which would make them easy targets for brute-force attacks." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:3019 +msgid "account_cache_expiration (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3022 +msgid "" +"Number of days entries are left in cache after last successful login before " +"being removed during a cleanup of the cache. 0 means keep forever. The " +"value of this parameter must be greater than or equal to " +"offline_credentials_expiration." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3029 +msgid "Default: 0 (unlimited)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:3034 +msgid "pwd_expiration_warning (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3045 +msgid "" +"Please note that the backend server has to provide information about the " +"expiration time of the password. If this information is missing, sssd " +"cannot display a warning. Also an auth provider has to be configured for the " +"backend." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3052 +msgid "Default: 7 (Kerberos), 0 (LDAP)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:3058 +msgid "id_provider (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3061 +msgid "" +"The identification provider used for the domain. Supported ID providers " +"are:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3065 +msgid "<quote>proxy</quote>: Support a legacy NSS provider." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3068 +msgid "" +"<quote>ldap</quote>: LDAP provider. See <citerefentry> " +"<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> " +"</citerefentry> for more information on configuring LDAP." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3076 sssd.conf.5.xml:3200 sssd.conf.5.xml:3259 +#: sssd.conf.5.xml:3322 +msgid "" +"<quote>ipa</quote>: FreeIPA and Red Hat Identity Management provider. See " +"<citerefentry> <refentrytitle>sssd-ipa</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry> for more information on configuring " +"FreeIPA." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3085 sssd.conf.5.xml:3209 sssd.conf.5.xml:3268 +#: sssd.conf.5.xml:3331 +msgid "" +"<quote>ad</quote>: Active Directory provider. See <citerefentry> " +"<refentrytitle>sssd-ad</refentrytitle> <manvolnum>5</manvolnum> " +"</citerefentry> for more information on configuring Active Directory." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3093 +msgid "" +"<quote>idp</quote>: Provider for OAuth 2.0/OIDC based Identity Providers " +"(IdP). See <citerefentry> <refentrytitle>sssd-idp</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry> for more information." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3101 +msgid "" +"Default: Not set (This is a mandatory setting that must be explicitly " +"defined for each configured domain)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:3109 +msgid "use_fully_qualified_names (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3112 +msgid "" +"Use the full name and domain (as formatted by the domain's full_name_format) " +"as the user's login name reported to NSS." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3117 +msgid "" +"If set to TRUE, all requests to this domain must use fully qualified " +"names. For example, if used in EXAMPLE domain that contains a \"test\" user, " +"<command>getent passwd test</command> wouldn't find the user while " +"<command>getent passwd test@EXAMPLE</command> would." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3125 +msgid "" +"NOTE: This option has no effect on netgroup lookups due to their tendency to " +"include nested netgroups without qualified names. For netgroups, all domains " +"will be searched when an unqualified name is requested." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3132 +msgid "" +"Default: FALSE (TRUE for trusted domain/sub-domains or if " +"default_domain_suffix is used)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:3139 +msgid "ignore_group_members (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3142 +msgid "Do not return group members for group lookups." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3145 +msgid "" +"If set to TRUE, the group membership attribute is not requested from the " +"ldap server, and group members are not returned when processing group lookup " +"calls, such as <citerefentry> <refentrytitle>getgrnam</refentrytitle> " +"<manvolnum>3</manvolnum> </citerefentry> or <citerefentry> " +"<refentrytitle>getgrgid</refentrytitle> <manvolnum>3</manvolnum> " +"</citerefentry>. As an effect, <quote>getent group $groupname</quote> would " +"return the requested group as if it was empty." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3163 +msgid "" +"Enabling this option can also make access provider checks for group " +"membership significantly faster, especially for groups containing many " +"members." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3169 sssd.conf.5.xml:3951 sssd-ldap.5.xml:401 +#: sssd-ldap.5.xml:454 sssd-ldap.5.xml:529 sssd-ldap.5.xml:576 +#: sssd-ldap.5.xml:599 sssd-ldap.5.xml:638 sssd-ldap.5.xml:657 +#: sssd-ldap.5.xml:681 sssd-ldap.5.xml:1114 sssd-ldap.5.xml:1147 +msgid "" +"This option can be also set per subdomain or inherited via " +"<emphasis>subdomain_inherit</emphasis>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:3179 +msgid "auth_provider (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3182 +msgid "" +"The authentication provider used for the domain. Supported auth providers " +"are:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3186 sssd.conf.5.xml:3252 +msgid "" +"<quote>ldap</quote> for native LDAP authentication. See <citerefentry> " +"<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> " +"</citerefentry> for more information on configuring LDAP." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3193 +msgid "" +"<quote>krb5</quote> for Kerberos authentication. See <citerefentry> " +"<refentrytitle>sssd-krb5</refentrytitle> <manvolnum>5</manvolnum> " +"</citerefentry> for more information on configuring Kerberos." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3217 +msgid "" +"<quote>idp</quote>: Provider for OAuth 2.0/OIDC based authentication. See " +"<citerefentry> <refentrytitle>sssd-idp</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry> for more information." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3225 +msgid "<quote>proxy</quote> for relaying authentication to some other PAM target." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3228 +msgid "<quote>none</quote> disables authentication explicitly." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3231 +msgid "" +"Default: <quote>id_provider</quote> is used if it is set and can handle " +"authentication requests." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:3237 +msgid "access_provider (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3240 +msgid "" +"The access control provider used for the domain. There are two built-in " +"access providers (in addition to any included in installed backends) " +"Internal special providers are:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3246 +msgid "<quote>permit</quote> always allow access." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3249 +msgid "<quote>deny</quote> always deny access." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3276 +msgid "" +"<quote>simple</quote> access control based on access or deny lists. See " +"<citerefentry> <refentrytitle>sssd-simple</refentrytitle> " +"<manvolnum>5</manvolnum></citerefentry> for more information on configuring " +"the simple access module." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3283 +msgid "" +"<quote>krb5</quote>: .k5login based access control. See <citerefentry> " +"<refentrytitle>sssd-krb5</refentrytitle> " +"<manvolnum>5</manvolnum></citerefentry> for more information on configuring " +"Kerberos." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3290 +msgid "<quote>proxy</quote> for relaying access control to another PAM module." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3293 +msgid "Default: <quote>permit</quote>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:3298 +msgid "chpass_provider (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3301 +msgid "" +"The provider which should handle change password operations for the domain. " +"Supported change password providers are:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3306 +msgid "" +"<quote>ldap</quote> to change a password stored in a LDAP server. See " +"<citerefentry> <refentrytitle>sssd-ldap</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry> for more information on configuring " +"LDAP." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3314 +msgid "" +"<quote>krb5</quote> to change the Kerberos password. See <citerefentry> " +"<refentrytitle>sssd-krb5</refentrytitle> <manvolnum>5</manvolnum> " +"</citerefentry> for more information on configuring Kerberos." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3339 +msgid "<quote>proxy</quote> for relaying password changes to some other PAM target." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3343 +msgid "<quote>none</quote> disallows password changes explicitly." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3346 +msgid "" +"Default: <quote>auth_provider</quote> is used if it is set and can handle " +"change password requests." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:3353 +msgid "sudo_provider (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3356 +msgid "The SUDO provider used for the domain. Supported SUDO providers are:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3360 +msgid "" +"<quote>ldap</quote> for rules stored in LDAP. See <citerefentry> " +"<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> " +"</citerefentry> for more information on configuring LDAP." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3368 +msgid "" +"<quote>ipa</quote> the same as <quote>ldap</quote> but with IPA default " +"settings." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3372 +msgid "" +"<quote>ad</quote> the same as <quote>ldap</quote> but with AD default " +"settings." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3376 +msgid "<quote>none</quote> disables SUDO explicitly." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3379 +msgid "" +"Default: The value of <quote>id_provider</quote> is used if it is set and " +"can handle sudo requests." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3383 +msgid "" +"The detailed instructions for configuration of sudo_provider are in the " +"manual page <citerefentry> <refentrytitle>sssd-sudo</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry>. There are many configuration " +"options that can be used to adjust the behavior. Please refer to " +"\"ldap_sudo_*\" in <citerefentry> <refentrytitle>sssd-ldap</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3398 +msgid "" +"<emphasis>NOTE:</emphasis> Sudo rules are periodically downloaded in the " +"background unless the sudo provider is explicitly disabled. Set " +"<emphasis>sudo_provider = None</emphasis> to disable all sudo-related " +"activity in SSSD if you do not want to use sudo with SSSD at all." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:3408 +msgid "selinux_provider (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3411 +msgid "" +"The provider which should handle loading of selinux settings. Note that this " +"provider will be called right after access provider ends. Supported selinux " +"providers are:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3417 +msgid "" +"<quote>ipa</quote> to load selinux settings from an IPA server. See " +"<citerefentry> <refentrytitle>sssd-ipa</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry> for more information on configuring " +"IPA." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3425 +msgid "<quote>none</quote> disallows fetching selinux settings explicitly." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3428 +msgid "" +"Default: the value of <quote>id_provider</quote> is used if it is set and " +"can handle selinux loading requests. Otherwise the result is the same as if " +"the selinux_provider is set to none." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:3435 +msgid "subdomains_provider (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3438 +msgid "" +"The provider which should handle fetching of subdomains. This value should " +"be always the same as id_provider. Supported subdomain providers are:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3444 +msgid "" +"<quote>ipa</quote> to load a list of subdomains from an IPA server. See " +"<citerefentry> <refentrytitle>sssd-ipa</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry> for more information on configuring " +"IPA." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3453 +msgid "" +"<quote>ad</quote> to load a list of subdomains from an Active Directory " +"server. See <citerefentry> <refentrytitle>sssd-ad</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry> for more information on configuring " +"the AD provider." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3462 +msgid "<quote>none</quote> disallows fetching subdomains explicitly." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3466 +msgid "" +"Default: The value of <quote>id_provider</quote> is used if it is set and " +"can handle subdomain requests." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:3472 +msgid "session_provider (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3475 +msgid "" +"The provider which configures and manages user session related tasks. The " +"only user session task currently provided is the integration with Fleet " +"Commander, which works only with IPA. Supported session providers are:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3482 +msgid "<quote>ipa</quote> to allow performing user session related tasks." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3486 +msgid "<quote>none</quote> does not perform any kind of user session related tasks." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3490 +msgid "Default: <quote>none</quote>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:3496 +msgid "autofs_provider (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3499 +msgid "The autofs provider used for the domain. Supported autofs providers are:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3503 +msgid "" +"<quote>ldap</quote> to load maps stored in LDAP. See <citerefentry> " +"<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> " +"</citerefentry> for more information on configuring LDAP." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3510 +msgid "" +"<quote>ipa</quote> to load maps stored in an IPA server. See <citerefentry> " +"<refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</manvolnum> " +"</citerefentry> for more information on configuring IPA." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3518 +msgid "" +"<quote>ad</quote> to load maps stored in an AD server. See <citerefentry> " +"<refentrytitle>sssd-ad</refentrytitle> <manvolnum>5</manvolnum> " +"</citerefentry> for more information on configuring the AD provider." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3527 +msgid "<quote>none</quote> disables autofs explicitly." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3530 +msgid "" +"Default: The value of <quote>id_provider</quote> is used if it is set and " +"can handle autofs requests." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:3537 +msgid "hostid_provider (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3540 +msgid "" +"The provider used for retrieving host identity information. Supported " +"hostid providers are:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3544 +msgid "" +"<quote>ipa</quote> to load host identity stored in an IPA server. See " +"<citerefentry> <refentrytitle>sssd-ipa</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry> for more information on configuring " +"IPA." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3552 +msgid "<quote>none</quote> disables hostid explicitly." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3555 +msgid "" +"Default: The value of <quote>id_provider</quote> is used if it is set and " +"can handle hostid requests." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:3562 +msgid "resolver_provider (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3565 +msgid "" +"The provider which should handle hosts and networks lookups. Supported " +"resolver providers are:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3569 +msgid "" +"<quote>proxy</quote> to forward lookups to another NSS library. See " +"<quote>proxy_resolver_lib_name</quote>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3573 +msgid "" +"<quote>ldap</quote> to fetch hosts and networks stored in LDAP. See " +"<citerefentry> <refentrytitle>sssd-ldap</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry> for more information on configuring " +"LDAP." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3580 +msgid "" +"<quote>ad</quote> to fetch hosts and networks stored in AD. See " +"<citerefentry> <refentrytitle>sssd-ad</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry> for more information on configuring " +"the AD provider." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3588 +msgid "<quote>none</quote> disallows fetching hosts and networks explicitly." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3591 +msgid "" +"Default: The value of <quote>id_provider</quote> is used if it is set and " +"can handle resolver requests." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3601 +msgid "" +"Regular expression for this domain that describes how to parse the string " +"containing user name and domain into these components. The \"domain\" can " +"match either the SSSD configuration domain name, or, in the case of IPA " +"trust subdomains and Active Directory domains, the flat (NetBIOS) name of " +"the domain." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3610 +msgid "" +"Default: " +"<quote>^((?P<name>.+)@(?P<domain>[^@]*)|(?P<name>[^@]+))$</quote> " +"which allows two different styles for user names:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:3615 sssd.conf.5.xml:3629 +msgid "username" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:3618 sssd.conf.5.xml:3632 +msgid "username@domain.name" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3623 +msgid "" +"Default for the AD and IPA provider: " +"<quote>^(((?P<domain>[^\\\\]+)\\\\(?P<name>.+))|((?P<name>.+)@(?P<domain>[^@]+))|((?P<name>[^@\\\\]+)))$</quote> " +"which allows three different styles for user names:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:3635 +msgid "domain\\username" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3638 +msgid "" +"While the first two correspond to the general default the third one is " +"introduced to allow easy integration of users from Windows domains." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3643 +msgid "" +"The default re_expression uses the <quote>@</quote> character as a separator " +"between the name and the domain. As a result of this setting the default " +"does not accept the <quote>@</quote> character in short names (as it is " +"allowed in Windows group names). If a user wishes to use short names with " +"<quote>@</quote> they must create their own re_expression." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3695 +msgid "Default: <quote>%1$s@%2$s</quote>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:3701 +msgid "lookup_family_order (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3704 +msgid "" +"Provides the ability to select preferred address family to use when " +"performing DNS lookups." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3708 +msgid "Supported values:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3711 +msgid "ipv4_first: Try looking up IPv4 address, if that fails, try IPv6" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3714 +msgid "ipv4_only: Only attempt to resolve hostnames to IPv4 addresses." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3717 +msgid "ipv6_first: Try looking up IPv6 address, if that fails, try IPv4" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3720 +msgid "ipv6_only: Only attempt to resolve hostnames to IPv6 addresses." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3723 +msgid "Default: ipv4_first" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:3729 +msgid "dns_resolver_server_timeout (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3732 +msgid "" +"Defines the timeout duration (in milliseconds) SSSD waits for a DNS server " +"to respond before moving to the next one." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3737 +msgid "The AD provider will use this option for the CLDAP ping timeouts as well." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3741 sssd.conf.5.xml:3777 sssd.conf.5.xml:3814 +msgid "" +"Please see the section <quote>FAILOVER</quote> in <citerefentry> " +"<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> " +"</citerefentry>, <citerefentry> <refentrytitle>sssd-krb5</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry>, <citerefentry> " +"<refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</manvolnum> " +"</citerefentry> or <citerefentry> <refentrytitle>sssd-ad</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry> for more information about the " +"service resolution." +msgstr "" + +#. type: Content of: <refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3762 sssd-ldap.5.xml:700 include/failover.xml:84 +msgid "Default: 1000" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:3768 +msgid "dns_resolver_op_timeout (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3771 +msgid "" +"Defines the amount of time (in seconds) to wait to resolve single DNS query " +"(e.g. resolution of a hostname or an SRV record) before trying the next " +"hostname or DNS discovery." +msgstr "" + +#. type: Content of: <refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3798 include/failover.xml:100 +msgid "Default: 3" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:3804 +msgid "dns_resolver_timeout (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3807 +msgid "" +"Defines the amount of time (in seconds) to wait for a reply from the " +"internal fail over service before assuming that the service is " +"unreachable. If this timeout is reached, the domain will continue to operate " +"in offline mode." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:3841 +msgid "dns_resolver_use_search_list (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3844 +msgid "" +"Normally, the DNS resolver searches the domain list defined in the " +"\"search\" directive from the resolv.conf file. This can lead to delays in " +"environments with improperly configured DNS." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3850 +msgid "" +"If fully qualified domain names (or _srv_) are used in the SSSD " +"configuration, setting this option to FALSE can prevent unnecessary DNS " +"lookups in such environments." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3856 +msgid "Default: TRUE" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:3862 +msgid "dns_discovery_domain (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3865 +msgid "" +"If service discovery is used in the back end, specifies the domain part of " +"the service discovery DNS query." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3869 +msgid "Default: Use the domain part of machine's hostname" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:3875 +msgid "failover_primary_timeout (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3878 +msgid "" +"When no primary server is available, SSSD fails over to a backup " +"server. This option defines the number of seconds SSSD waits before " +"attempting to reconnect to the primary server." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3885 +msgid "Note: The minimum value is 31." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3888 +msgid "Default: 31" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:3894 +msgid "override_gid (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3897 +msgid "" +"Override the primary GID value for all users in the domain with specified " +"value." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3901 +msgid "" +"Default: not set (Use the primary GID value retrieved from the identity " +"provider)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:3908 +msgid "case_sensitive (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:3915 +msgid "True" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3918 +msgid "Case sensitive. This value is invalid for AD provider." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:3924 +msgid "False" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3926 +msgid "Case insensitive." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:3930 +msgid "Preserving" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3933 +msgid "" +"Same as False (case insensitive), but does not lowercase names in the result " +"of NSS operations. Note that name aliases (and in case of services also " +"protocol names) are still lowercased in the output." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3941 +msgid "" +"If you want to set this value for trusted domain with IPA provider, you need " +"to set it on both the client and SSSD on the server." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3911 +msgid "" +"Treat user and group names as case sensitive. Possible option values are: " +"<placeholder type=\"variablelist\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3956 +msgid "Default: True (False for AD provider)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:3962 +msgid "avoid_by_id_lookups (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3965 +msgid "" +"If this option is set to 'true' SSSD will try to avoid sending lookups by ID " +"to the backend and will switch to a lookup by name if a cached object with a " +"matching ID can be found." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3971 +msgid "" +"This option can e.g. be used in cases where searches by ID are expensive on " +"the server side because of missing indexes or are not even possible, " +"e.g. due to non-reversible POSIX id-mapping." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3978 +msgid "Default: False (True for IdP provider)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:3984 +msgid "subdomain_inherit (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3987 +msgid "" +"Specifies a list of configuration parameters that should be inherited by a " +"subdomain. Please note that only selected parameters can be inherited. " +"Currently the following options can be inherited:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3993 +msgid "ldap_search_timeout" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3996 +msgid "ldap_network_timeout" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3999 +msgid "ldap_opt_timeout" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4002 +msgid "ldap_offline_timeout" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4005 +msgid "ldap_purge_cache_timeout" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4008 +msgid "ldap_purge_cache_offset" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4011 +msgid "" +"ldap_krb5_keytab (the value of krb5_keytab will be used if ldap_krb5_keytab " +"is not set explicitly)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4015 +msgid "ldap_krb5_ticket_lifetime" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4018 +msgid "ldap_connection_expire_timeout" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4021 +msgid "ldap_connection_expire_offset" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4024 +msgid "ldap_connection_idle_timeout" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4027 sssd-ldap.5.xml:446 +msgid "ldap_use_tokengroups" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4030 +msgid "ldap_user_principal" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4033 +msgid "ignore_group_members" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4036 +msgid "auto_private_groups" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4039 +msgid "case_sensitive" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> +#: sssd.conf.5.xml:4044 +#, no-wrap +msgid "" +"subdomain_inherit = ldap_purge_cache_timeout\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4051 +msgid "Note: This option only works with the IPA and AD provider." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4058 +msgid "subdomain_homedir (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4069 +msgid "%F" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4070 +msgid "flat (NetBIOS) name of a subdomain." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4061 +msgid "" +"Use this homedir as default value for all subdomains within this domain in " +"IPA AD trust. See <emphasis>override_homedir</emphasis> for info about " +"possible values. In addition to those, the expansion below can only be used " +"with <emphasis>subdomain_homedir</emphasis>. <placeholder " +"type=\"variablelist\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4075 +msgid "The value can be overridden by <emphasis>override_homedir</emphasis> option." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4079 +msgid "Default: <filename>/home/%d/%u</filename>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4084 +msgid "realmd_tags (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4087 +msgid "Various tags stored by the realmd configuration service for this domain." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4093 +msgid "cached_auth_timeout (int)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4096 +msgid "" +"Specifies the number of seconds since the last successful online " +"authentication during which SSSD will authenticate users via cached " +"credentials, even while online. If the cached authentication fails, SSSD " +"immediately falls back to online authentication." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4103 +msgid "" +"This option's value is inherited by all trusted domains. At the moment it is " +"not possible to set a different value per trusted domain." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4108 +msgid "Special value 0 implies that this feature is disabled." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4112 +msgid "" +"Please note that if <quote>cached_auth_timeout</quote> is longer than " +"<quote>pam_id_timeout</quote> then the back end could be called to handle " +"<quote>initgroups.</quote>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4123 +msgid "local_auth_policy (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4126 +msgid "" +"Local authentication methods policy. Some backends (i.e. LDAP, proxy " +"provider) only support a password based authentication, while others can " +"handle PKINIT based Smartcard authentication (AD, IPA), two-factor " +"authentication (IPA), or other methods against a central instance. By " +"default in such cases authentication is only performed with the methods " +"supported by the backend. With this option additional methods can be enabled " +"which are evaluated and checked locally." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4138 +msgid "" +"There are three possible values for this option: match, only, " +"enable. <quote>match</quote> is used to match offline and online states for " +"Kerberos methods. <quote>only</quote> ignores the online methods and only " +"offer the local ones. enable allows explicitly defining the methods for " +"local authentication. As an example, <quote>enable:passkey</quote>, only " +"enables passkey for local authentication. Multiple enable values should be " +"comma-separated, such as <quote>enable:passkey, enable:smartcard</quote>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4151 +msgid "" +"The following table shows which authentication methods, if configured " +"properly, are currently enabled or disabled for each backend, with the " +"default local_auth_policy: <quote>match</quote>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> +#: sssd.conf.5.xml:4164 +msgid "local_auth_policy = match (default)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> +#: sssd.conf.5.xml:4165 +msgid "Passkey" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> +#: sssd.conf.5.xml:4166 +msgid "Smartcard" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:4169 sssd-ldap.5.xml:228 +msgid "IPA" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry><para> +#: sssd.conf.5.xml:4169 sssd.conf.5.xml:4170 sssd.conf.5.xml:4173 +msgid "enabled" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:4172 sssd-ldap.5.xml:233 +msgid "AD" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry><para> +#: sssd.conf.5.xml:4172 sssd.conf.5.xml:4175 sssd.conf.5.xml:4176 +msgid "disabled" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry> +#: sssd.conf.5.xml:4175 +msgid "LDAP" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4180 +msgid "" +"Please note that if local Smartcard authentication is enabled and a " +"Smartcard is present, Smartcard authentication will be preferred over the " +"authentication methods supported by the backend. I.e. there will be a PIN " +"prompt instead of e.g. a password prompt." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> +#: sssd.conf.5.xml:4192 +#, no-wrap +msgid "" +"[domain/shadowutils]\n" +"id_provider = proxy\n" +"proxy_lib_name = files\n" +"auth_provider = none\n" +"local_auth_policy = only\n" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4188 +msgid "" +"The following configuration example allows local users to authenticate " +"locally using any enabled method (i.e. smartcard, passkey). <placeholder " +"type=\"programlisting\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4200 +msgid "Default: match" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4205 +msgid "auto_private_groups (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4211 +msgid "true" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4214 +msgid "" +"Create user's private group unconditionally from user's UID number. The GID " +"number is ignored in this case." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4218 +msgid "" +"NOTE: Because the GID number and the user private group are inferred from " +"the UID number, it is not supported to have multiple entries with the same " +"UID or GID number with this option. In other words, enabling this option " +"enforces uniqueness across the ID space." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4227 +msgid "false" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4230 +msgid "" +"Always use the user's primary GID number. The GID number must refer to a " +"group object in the LDAP database." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4236 +msgid "hybrid" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4239 +msgid "" +"A primary group is autogenerated for user entries whose UID and GID numbers " +"have the same value and at the same time the GID number does not correspond " +"to a real group object in LDAP. If the values are the same, but the primary " +"GID in the user entry is also used by a group object, the primary GID of the " +"user resolves to that group object." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4252 +msgid "" +"If the UID and GID of a user are different, then the GID must correspond to " +"a group entry, otherwise the GID is simply not resolvable." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4259 +msgid "" +"This feature is useful for environments that wish to stop maintaining a " +"separate group objects for the user private groups, but also wish to retain " +"the existing user private groups." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4208 +msgid "" +"This option takes any of three available values: <placeholder " +"type=\"variablelist\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4271 +msgid "" +"For the LDAP based id providers (LDAP, IPA and AD) the default for the " +"configured domain is typically False because the sources have the concept of " +"a primary group. <phrase condition=\"with_idp_provider\">The IdP id " +"provider is using True because IdPs typically do not have primary " +"groups.</phrase>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4280 +msgid "" +"For subdomains, the default value is False for subdomains that use assigned " +"POSIX IDs and True for subdomains that use automatic ID-mapping." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> +#: sssd.conf.5.xml:4288 +#, no-wrap +msgid "" +"[domain/forest.domain/sub.domain]\n" +"auto_private_groups = false\n" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> +#: sssd.conf.5.xml:4294 +#, no-wrap +msgid "" +"[domain/forest.domain]\n" +"subdomain_inherit = auto_private_groups\n" +"auto_private_groups = false\n" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4285 +msgid "" +"The value of auto_private_groups can either be set per subdomains in a " +"subsection, for example: <placeholder type=\"programlisting\" id=\"0\"/> or " +"globally for all subdomains in the main domain section using the " +"subdomain_inherit option: <placeholder type=\"programlisting\" id=\"1\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:2549 +msgid "" +"These configuration options can be present in a domain configuration " +"section, that is, in a section called " +"<quote>[domain/<replaceable>NAME</replaceable>]</quote> <placeholder " +"type=\"variablelist\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4309 +msgid "proxy_pam_target (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4312 +msgid "The proxy target PAM proxies to." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4315 +msgid "" +"Default: not set by default, you have to take an existing pam configuration " +"or create a new one and add the service name here. As an alternative you can " +"enable local authentication with the local_auth_policy option." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4325 +msgid "proxy_lib_name (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4328 +msgid "" +"The name of the NSS library to use in proxy domains. The NSS functions " +"searched for in the library are in the form of _nss_$(libName)_$(function), " +"for example _nss_files_getpwent." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4338 +msgid "proxy_resolver_lib_name (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4341 +msgid "" +"The name of the NSS library to use for hosts and networks lookups in proxy " +"domains. The NSS functions searched for in the library are in the form of " +"_nss_$(libName)_$(function), for example _nss_dns_gethostbyname2_r." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4352 +msgid "proxy_fast_alias (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4355 +msgid "" +"When a user or group is looked up by name in the proxy provider, a second " +"lookup by ID is performed to \"canonicalize\" the name in case the requested " +"name was an alias. Setting this option to true would cause the SSSD to " +"perform the ID lookup from cache for performance reasons." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4369 +msgid "proxy_max_children (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4372 +msgid "" +"This option specifies the number of pre-forked proxy children. It is useful " +"for high-load SSSD environments where sssd may run out of available child " +"slots, which would cause some issues due to the requests being queued." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:4305 +msgid "" +"Options valid for proxy domains. <placeholder type=\"variablelist\" " +"id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><title> +#: sssd.conf.5.xml:4388 +msgid "Application domains" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:4390 +msgid "" +"SSSD, with its D-Bus interface (see <citerefentry> " +"<refentrytitle>sssd-ifp</refentrytitle> <manvolnum>5</manvolnum> " +"</citerefentry>) is appealing to applications as a gateway to an LDAP " +"directory where users and groups are stored. However, contrary to the " +"traditional SSSD deployment where all users and groups either have POSIX " +"attributes or those attributes can be inferred from the Windows SIDs, in " +"many cases the users and groups in the application support scenario have no " +"POSIX attributes. Instead of setting a " +"<quote>[domain/<replaceable>NAME</replaceable>]</quote> section, the " +"administrator can set up an " +"<quote>[application/<replaceable>NAME</replaceable>]</quote> section that " +"internally represents a domain with type <quote>application</quote> " +"optionally inherits settings from a tradition SSSD domain." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:4410 +msgid "" +"Please note that the application domain must still be explicitly enabled in " +"the <quote>domains</quote> parameter so that the lookup order between the " +"application domain and its POSIX sibling domain is set correctly." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><title> +#: sssd.conf.5.xml:4416 +msgid "Application domain parameters" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4418 +msgid "inherit_from (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4421 +msgid "" +"The SSSD POSIX-type domain the application domain inherits all settings " +"from. The application domain can moreover add its own settings to the " +"application settings that augment or override the <quote>sibling</quote> " +"domain settings." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:4435 +msgid "" +"The following example illustrates the use of an application domain. In this " +"setup, the POSIX domain is connected to an LDAP server and is used by the OS " +"through the NSS responder. In addition, the application domain also requests " +"the telephoneNumber attribute, stores it as the phone attribute in the cache " +"and makes the phone attribute reachable through the D-Bus interface." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><programlisting> +#: sssd.conf.5.xml:4443 +#, no-wrap +msgid "" +"[sssd]\n" +"domains = appdom, posixdom\n" +"\n" +"[ifp]\n" +"user_attributes = +phone\n" +"\n" +"[domain/posixdom]\n" +"id_provider = ldap\n" +"ldap_uri = ldap://ldap.example.com\n" +"ldap_search_base = dc=example,dc=com\n" +"\n" +"[application/appdom]\n" +"inherit_from = posixdom\n" +"ldap_user_extra_attrs = phone:telephoneNumber\n" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd.conf.5.xml:4463 +msgid "TRUSTED DOMAIN SECTION" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:4465 +msgid "" +"Some options used in the domain section can also be used in the trusted " +"domain section, that is, in a section called " +"<quote>[domain/<replaceable>DOMAIN_NAME</replaceable>/<replaceable>TRUSTED_DOMAIN_NAME</replaceable>]</quote>. " +"Where DOMAIN_NAME is the actual joined-to base domain. Please refer to " +"examples below for explanation. Currently supported options in the trusted " +"domain section are:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:4472 +msgid "ldap_search_base," +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:4473 +msgid "ldap_user_search_base," +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:4474 +msgid "ldap_group_search_base," +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:4475 +msgid "ldap_netgroup_search_base," +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:4476 +msgid "ldap_service_search_base," +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:4477 +msgid "ldap_sasl_mech," +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:4478 +msgid "ad_server," +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:4479 +msgid "ad_backup_server," +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:4480 +msgid "ad_site," +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:4481 sssd-ipa.5.xml:929 +msgid "use_fully_qualified_names" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:4482 +msgid "pam_gssapi_services" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:4483 +msgid "pam_gssapi_check_upn" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:4485 +msgid "" +"For more details about these options see their individual description in the " +"manual page." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd.conf.5.xml:4491 +msgid "CERTIFICATE MAPPING SECTION" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:4493 +msgid "" +"To allow authentication with Smartcards and certificates SSSD must be able " +"to map certificates to users. This can be done by adding the full " +"certificate to the LDAP object of the user or to a local override. While " +"using the full certificate is required to use the Smartcard authentication " +"feature of SSH (see <citerefentry> " +"<refentrytitle>sss_ssh_authorizedkeys</refentrytitle> " +"<manvolnum>8</manvolnum> </citerefentry> for details) it might be cumbersome " +"or not even possible to do this for the general case where local services " +"use PAM for authentication." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:4507 +msgid "" +"To make the mapping more flexible mapping and matching rules were added to " +"SSSD (see <citerefentry> <refentrytitle>sss-certmap</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry> for details)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:4516 +msgid "" +"A mapping and matching rule can be added to the SSSD configuration in a " +"section on its own with a name like " +"<quote>[certmap/<replaceable>DOMAIN_NAME</replaceable>/<replaceable>RULE_NAME</replaceable>]</quote>. " +"In this section the following options are allowed:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4523 +msgid "matchrule (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4526 +msgid "" +"Only certificates from the Smartcard which matches this rule will be " +"processed, all others are ignored." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4530 +msgid "" +"Default: KRB5:<EKU>clientAuth, i.e. only certificates which have the " +"Extended Key Usage <quote>clientAuth</quote>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4537 +msgid "maprule (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4540 +msgid "Defines how the user is found for a given certificate." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:4546 +msgid "" +"LDAP:(userCertificate;binary={cert!bin}) for LDAP based providers like " +"<quote>ldap</quote>, <quote>AD</quote> or <quote>ipa</quote>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:4552 +msgid "" +"If maprule is not set and provider is <quote>proxy</quote>, the RULE_NAME " +"name is assumed to be the name of the matching user." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4565 +msgid "" +"Comma separated list of domain names the rule should be applied. By default " +"a rule is only valid in the domain configured in sssd.conf. If the provider " +"supports subdomains this option can be used to add the rule to subdomains as " +"well." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4572 +msgid "Default: the configured domain in sssd.conf" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4577 +msgid "priority (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4580 +msgid "" +"Unsigned integer value defining the priority of the rule. The higher the " +"number the lower the priority. <quote>0</quote> stands for the highest " +"priority while <quote>4294967295</quote> is the lowest." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4586 +msgid "Default: the lowest priority" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd.conf.5.xml:4594 +msgid "PROMPTING CONFIGURATION SECTION" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:4596 +msgid "" +"If a special file " +"(<filename>/var/lib/sss/pubconf/pam_preauth_available</filename>) exists " +"SSSD's PAM module pam_sss will ask SSSD to figure out which authentication " +"methods are available for the user trying to log in. Based on the results " +"pam_sss will prompt the user for appropriate credentials." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:4604 +msgid "" +"With the growing number of authentication methods and the possibility that " +"there are multiple ones for a single user the heuristic used by pam_sss to " +"select the prompting might not be suitable for all use cases. The following " +"options should provide a better flexibility here." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4616 +msgid "[prompting/password]" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4619 +msgid "password_prompt" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4620 +msgid "to change the string of the password prompt" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4618 +msgid "" +"to configure password prompting, allowed options are: <placeholder " +"type=\"variablelist\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4628 +msgid "[prompting/2fa]" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4632 +msgid "first_prompt" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4633 +msgid "to change the string of the prompt for the first factor" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4636 +msgid "second_prompt" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4637 +msgid "to change the string of the prompt for the second factor" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4640 +msgid "single_prompt" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4641 +msgid "" +"boolean value, if True there will be only a single prompt using the value of " +"first_prompt where it is expected that both factors are entered as a single " +"string. Please note that both factors have to be entered here, even if the " +"second factor is optional." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4630 +msgid "" +"to configure two-factor authentication prompting, allowed options are: " +"<placeholder type=\"variablelist\" id=\"0\"/> If the second factor is " +"optional and it should be possible to log in either only with the password " +"or with both factors two-step prompting has to be used." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4654 +msgid "" +"Some clients, such as SSH with 'PasswordAuthentication yes', generate their " +"own prompts and do not use prompts provided by SSSD or other PAM " +"modules. Additionally, for SSH with PasswordAuthentication, if two-factor " +"authentication is available, SSSD expects that the credentials entered by " +"the user at the SSH password prompt will always be the two factors in a " +"single string, even if two-factor authentication is optional." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4669 +msgid "[prompting/passkey]" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:4675 sssd.conf.5.xml:4719 sssd-ad.5.xml:1027 +msgid "interactive" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4677 +msgid "" +"boolean value, if True prompt a message and wait before testing the presence " +"of a passkey device. Recommended if your device doesn’t have a tactile " +"trigger." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4685 sssd.conf.5.xml:4735 +msgid "interactive_prompt" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4687 sssd.conf.5.xml:4737 +msgid "to change the message of the interactive prompt." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4692 +msgid "touch" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4694 +msgid "" +"boolean value, if True prompt a message to remind the user to touch the " +"device." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4700 +msgid "touch_prompt" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4702 +msgid "to change the message of the touch prompt." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4671 +msgid "" +"to configure passkey authentication prompting, allowed options are: " +"<placeholder type=\"variablelist\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4713 +msgid "[prompting/oauth2]" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4721 +msgid "" +"boolean value, if True prompt a message after asking the user to " +"authenticate, and wait before requesting the access token." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4725 +msgid "" +"If False, make sure to set the <quote>idp_request_timeout</quote> " +"sufficiently high, to give the user time to authenticate." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4715 +msgid "" +"to configure OAuth2 authentication prompting, allowed options are: " +"<placeholder type=\"variablelist\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4748 +msgid "[prompting/cert_auth]" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4754 +msgid "pin_prompt" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4756 +msgid "" +"to change the message which asks the user to enter the PIN at the computer " +"keyboard. At the end of the message the token name is printed." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4764 +msgid "keypad_prompt" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4766 +msgid "" +"to change the message which asks the user to enter the PIN at keypad of the " +"Smartcard reader. At the end of the message the token name is printed." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4774 +msgid "user_name_hint" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4776 +msgid "" +"boolean value, if True ask for a user name if no name was given before and " +"the found certificate can be mapped to more than one user." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4750 +msgid "" +"to configure Smartcard authentication prompting, allowed options are: " +"<placeholder type=\"variablelist\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:4611 +msgid "" +"Each supported authentication method has its own configuration subsection " +"under <quote>[prompting/...]</quote>. Currently there are: <placeholder " +"type=\"variablelist\" id=\"0\"/> <placeholder type=\"variablelist\" " +"id=\"1\"/> <placeholder type=\"variablelist\" id=\"2\"/> <placeholder " +"type=\"variablelist\" id=\"3\"/> <placeholder type=\"variablelist\" " +"id=\"4\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:4792 +msgid "" +"It is possible to add a subsection for specific PAM services, " +"e.g. <quote>[prompting/password/sshd]</quote> to individual change the " +"prompting for this service." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd.conf.5.xml:4799 pam_sss_gss.8.xml:157 idmap_sss.8.xml:43 +msgid "EXAMPLES" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><programlisting> +#: sssd.conf.5.xml:4805 +#, no-wrap +msgid "" +"[sssd]\n" +"domains = LDAP\n" +"services = nss, pam\n" +"\n" +"[nss]\n" +"filter_groups = root\n" +"filter_users = root\n" +"\n" +"[pam]\n" +"\n" +"[domain/LDAP]\n" +"id_provider = ldap\n" +"ldap_uri = ldap://ldap.example.com\n" +"ldap_search_base = dc=example,dc=com\n" +"\n" +"auth_provider = krb5\n" +"krb5_server = kerberos.example.com\n" +"krb5_realm = EXAMPLE.COM\n" +"cache_credentials = true\n" +"\n" +"min_id = 10000\n" +"max_id = 20000\n" +"enumerate = False\n" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:4801 +msgid "" +"1. The following example shows a typical SSSD config. It does not describe " +"configuration of the domains themselves - refer to documentation on " +"configuring domains for more details. <placeholder type=\"programlisting\" " +"id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><programlisting> +#: sssd.conf.5.xml:4837 +#, no-wrap +msgid "" +"[domain/ipa.com/child.ad.com]\n" +"use_fully_qualified_names = false\n" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:4831 +msgid "" +"2. The following example shows configuration of IPA AD trust where the AD " +"forest consists of two domains in a parent-child structure. Suppose IPA " +"domain (ipa.com) has trust with AD domain(ad.com). ad.com has child domain " +"(child.ad.com). To enable shortnames in the child domain the following " +"configuration should be used. <placeholder type=\"programlisting\" " +"id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><programlisting> +#: sssd.conf.5.xml:4848 +#, no-wrap +msgid "" +"[certmap/my.domain/rule_name]\n" +"matchrule = <ISSUER>^CN=My-CA,DC=MY,DC=DOMAIN$\n" +"maprule = (userCertificate;binary={cert!bin})\n" +"domains = my.domain, your.domain\n" +"priority = 10\n" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:4842 +msgid "" +"3. The following example shows the configuration of a certificate mapping " +"rule. It is valid for the configured domain <quote>my.domain</quote> and " +"additionally for the subdomains <quote>your.domain</quote> and uses the full " +"certificate in the search filter. <placeholder type=\"programlisting\" " +"id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refname> +#: sssd-ldap.5.xml:10 sssd-ldap.5.xml:16 +msgid "sssd-ldap" +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refpurpose> +#: sssd-ldap.5.xml:17 +msgid "SSSD LDAP provider" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd-ldap.5.xml:21 pam_sss.8.xml:66 pam_sss_gss.8.xml:30 +#: sssd_krb5_locator_plugin.8.xml:20 sssd-simple.5.xml:22 sss-certmap.5.xml:21 +#: sssd-ipa.5.xml:21 sssd-ad.5.xml:21 sssd-sudo.5.xml:21 sssd-idp.5.xml:21 +#: sssd.8.xml:29 sss_obfuscate.8.xml:30 sss_override.8.xml:30 +#: sssd-krb5.5.xml:21 sss_cache.8.xml:29 sss_debuglevel.8.xml:30 +#: sss_seed.8.xml:31 sssd-ifp.5.xml:21 sss_ssh_authorizedkeys.1.xml:30 +#: sss_ssh_knownhosts.1.xml:30 idmap_sss.8.xml:20 sssctl.8.xml:30 +#: sssd-session-recording.5.xml:21 sssd-kcm.8.xml:21 sssd-systemtap.5.xml:21 +#: sssd-ldap-attributes.5.xml:21 sssd_krb5_localauth_plugin.8.xml:20 +msgid "DESCRIPTION" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-ldap.5.xml:23 +msgid "" +"This manual page describes the configuration of LDAP domains for " +"<citerefentry> <refentrytitle>sssd</refentrytitle> <manvolnum>8</manvolnum> " +"</citerefentry>. Refer to the <quote>FILE FORMAT</quote> section of the " +"<citerefentry> <refentrytitle>sssd.conf</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry> manual page for detailed syntax " +"information." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-ldap.5.xml:35 +msgid "You can configure SSSD to use more than one LDAP domain." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-ldap.5.xml:38 +msgid "" +"LDAP back end supports id, auth, access and chpass providers. If you want to " +"authenticate against an LDAP server either TLS/SSL or LDAPS is " +"required. <command>sssd</command> <emphasis>does not</emphasis> support " +"authentication over an unencrypted channel. Even if the LDAP server is used " +"only as an identity provider, an encrypted channel is strongly " +"recommended. Please refer to the <quote>ldap_access_filter</quote> config " +"option for more information about using LDAP as an access provider." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd-ldap.5.xml:50 sssd-simple.5.xml:82 sssd-ipa.5.xml:82 sssd-ad.5.xml:130 +#: sssd-idp.5.xml:54 sssd-krb5.5.xml:63 sssd-ifp.5.xml:60 +#: sssd-session-recording.5.xml:58 sssd-kcm.8.xml:202 +msgid "CONFIGURATION OPTIONS" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:67 +msgid "ldap_uri, ldap_backup_uri (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:70 +msgid "" +"Specifies the comma-separated list of URIs of the LDAP servers to which SSSD " +"should connect in the order of preference. Refer to the " +"<quote>FAILOVER</quote> section for more information on failover and server " +"redundancy. If neither option is specified, service discovery is " +"enabled. For more information, refer to the <quote>SERVICE DISCOVERY</quote> " +"section." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:77 +msgid "The format of the URI must match the format defined in RFC 2732:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:80 +msgid "ldap[s]://<host>[:port]" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:83 +msgid "For explicit IPv6 addresses, <host> must be enclosed in brackets []" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:86 +msgid "example: ldap://[fc00::126:25]:389" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:92 +msgid "ldap_chpass_uri, ldap_chpass_backup_uri (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:95 +msgid "" +"Specifies the comma-separated list of URIs of the LDAP servers to which SSSD " +"should connect in the order of preference to change the password of a " +"user. Refer to the <quote>FAILOVER</quote> section for more information on " +"failover and server redundancy." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:102 +msgid "To enable service discovery ldap_chpass_dns_service_name must be set." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:106 +msgid "Default: empty, i.e. ldap_uri is used." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:112 +msgid "ldap_search_base (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:115 +msgid "The default base DN to use for performing LDAP user operations." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:119 +msgid "" +"Starting with SSSD 1.7.0, SSSD supports multiple search bases using the " +"syntax:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:123 +msgid "search_base[?scope?[filter][?search_base?scope?[filter]]*]" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:126 +msgid "The scope can be one of \"base\", \"onelevel\" or \"subtree\"." +msgstr "" + +#. type: Content of: <listitem><para> +#: sssd-ldap.5.xml:129 include/ldap_search_bases.xml:18 +msgid "" +"The filter must be a valid LDAP search filter as specified by " +"http://www.ietf.org/rfc/rfc2254.txt" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:133 sssd-ad.5.xml:312 sss_override.8.xml:143 +#: sss_override.8.xml:240 sssd-ldap-attributes.5.xml:453 +msgid "Examples:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:136 +msgid "" +"ldap_search_base = dc=example,dc=com (which is equivalent to) " +"ldap_search_base = dc=example,dc=com?subtree?" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:141 +msgid "" +"ldap_search_base = " +"cn=host_specific,dc=example,dc=com?subtree?(host=thishost)?dc=example.com?subtree?" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:144 +msgid "" +"Note: It is unsupported to have multiple search bases which reference " +"identically-named objects (for example, groups with the same name in two " +"different search bases). This will lead to unpredictable behavior on client " +"machines." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:151 +msgid "" +"Default: If not set, the value of the defaultNamingContext or namingContexts " +"attribute from the RootDSE of the LDAP server is used. If " +"defaultNamingContext does not exist or has an empty value namingContexts is " +"used. The namingContexts attribute must have a single value with the DN of " +"the search base of the LDAP server to make this work. Multiple values are " +"not supported." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:165 +msgid "ldap_read_rootdse (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:168 +msgid "" +"SSSD reads RootDSE to get information about LDAP and its capabilities. By " +"default, this is done anonymously. However, this may not be permitted by the " +"LDAP server. In such cases we can use this option to influence SSSD " +"behavior." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:175 +msgid "Allowed values are:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd-ldap.5.xml:179 +msgid "anonymous" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd-ldap.5.xml:184 +msgid "authenticated" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:193 +msgid "" +"By default, using the \"anonymous\" option, SSSD tries to read RootDSE " +"anonymously. If this fails SSSD retries the attempt with authentication." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:198 +msgid "Default: anonymous" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:204 +msgid "ldap_schema (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:207 +msgid "" +"Specifies the Schema Type in use on the target LDAP server. Depending on " +"the selected schema, the default attribute names retrieved from the servers " +"may vary. The way that some attributes are handled may also differ." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:214 +msgid "Four schema types are currently supported:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd-ldap.5.xml:218 +msgid "rfc2307" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd-ldap.5.xml:223 +msgid "rfc2307bis" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:239 +msgid "" +"The main difference between these schema types is how group memberships are " +"recorded in the server. With rfc2307, group members are listed by name in " +"the <emphasis>memberUid</emphasis> attribute. With rfc2307bis and IPA, " +"group members are listed by DN and stored in the <emphasis>member</emphasis> " +"attribute. The AD schema type sets the attributes to correspond with Active " +"Directory 2008r2 values." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:249 +msgid "Default: rfc2307" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:255 +msgid "ldap_pwmodify_mode (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:258 +msgid "Specify the operation that is used to modify user password." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:262 +msgid "Two modes are currently supported:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd-ldap.5.xml:266 +msgid "exop - Password Modify Extended Operation (RFC 3062)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd-ldap.5.xml:272 +msgid "ldap_modify - Direct modification of userPassword (not recommended)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd-ldap.5.xml:278 +msgid "" +"exop_force - Try Password Modify Extended Operation (RFC 3062) even if there " +"are no grace logins left. Depending on the type and configuration of the " +"LDAP server the password change might fail because an authenticated bind is " +"not possible." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:290 +msgid "" +"Note: First, a new connection is established to verify current password by " +"binding as the user that requested password change. If successful, this " +"connection is used to change the password therefore the user must have write " +"access to userPassword attribute." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:298 +msgid "Default: exop" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:304 +msgid "ldap_default_bind_dn (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:307 +msgid "The default bind DN to use for performing LDAP operations." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:314 +msgid "ldap_default_authtok_type (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:317 +msgid "The type of the authentication token of the default bind DN." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:321 +msgid "The two mechanisms currently supported are:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:324 +msgid "password" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:327 +msgid "obfuscated_password" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:330 +msgid "Default: password" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:333 +msgid "" +"See the <citerefentry> <refentrytitle>sss_obfuscate</refentrytitle> " +"<manvolnum>8</manvolnum> </citerefentry> manual page for more information." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:344 +msgid "ldap_default_authtok (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:347 +msgid "The authentication token of the default bind DN." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:353 +msgid "ldap_force_upper_case_realm (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:356 +msgid "" +"Some directory servers, for example Active Directory, might deliver the " +"realm part of the UPN in lower case, which might cause the authentication to " +"fail. Set this option to a non-zero value if you want to use an upper-case " +"realm." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:369 +msgid "ldap_enumeration_refresh_timeout (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:372 +msgid "" +"Specifies how many seconds SSSD has to wait before refreshing its cache of " +"enumerated records." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:383 +msgid "ldap_purge_cache_timeout (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:386 +msgid "" +"Determine how often to check the cache for inactive entries (such as groups " +"with no members and users who have never logged in) and remove them to save " +"space." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:392 +msgid "" +"Setting this option to zero will disable the cache cleanup operation. Please " +"note that if enumeration is enabled, the cleanup task is required in order " +"to detect entries removed from the server and can't be disabled. By default, " +"the cleanup task will run every 3 hours with enumeration enabled." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:412 +msgid "ldap_group_nesting_level (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:415 +msgid "" +"If ldap_schema is set to a schema format that supports nested groups " +"(e.g. RFC2307bis), then this option controls how many levels of nesting SSSD " +"will follow. This option has no effect on the RFC2307 schema." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:422 +msgid "" +"Note: This option specifies the guaranteed level of nested groups to be " +"processed for any lookup. However, nested groups beyond this limit " +"<emphasis>may be</emphasis> returned if previous lookups already resolved " +"the deeper nesting levels. Also, subsequent lookups for other groups may " +"enlarge the result set for original lookup if re-queried." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:431 +msgid "" +"If ldap_group_nesting_level is set to 0 then no nested groups are processed " +"at all. However, when connected to Active-Directory Server 2008 and later " +"using <quote>id_provider=ad</quote> it is furthermore required to disable " +"usage of Token-Groups by setting ldap_use_tokengroups to false in order to " +"restrict group nesting." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:440 +msgid "Default: 2" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:449 +msgid "" +"This options enables or disables use of Token-Groups attribute when " +"performing initgroup for users from Active Directory Server 2008 and later." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:459 +msgid "Default: True for AD and IPA otherwise False." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:465 +msgid "ldap_host_search_base (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:468 +msgid "Optional. Use the given string as search base for host objects." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:472 sssd-ipa.5.xml:501 sssd-ipa.5.xml:520 sssd-ipa.5.xml:539 +#: sssd-ipa.5.xml:558 +msgid "" +"See <quote>ldap_search_base</quote> for information about configuring " +"multiple search bases." +msgstr "" + +#. type: Content of: <listitem><para> +#: sssd-ldap.5.xml:477 sssd-ipa.5.xml:506 include/ldap_search_bases.xml:27 +msgid "Default: the value of <emphasis>ldap_search_base</emphasis>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:484 +msgid "ldap_subid_ranges_search_base (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:487 +msgid "" +"Optional. Use the given string as search base for subordinate ranges related " +"objects." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:491 +msgid "" +"Default: the value of <emphasis>cn=subids,%basedn</emphasis> for IPA " +"otherwise <emphasis>ldap_search_base</emphasis>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:499 +msgid "ldap_service_search_base (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:504 +msgid "ldap_iphost_search_base (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:509 +msgid "ldap_ipnetwork_search_base (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:514 +msgid "ldap_search_timeout (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:517 +msgid "" +"Specifies the timeout (in seconds) that ldap searches are allowed to run " +"before they are cancelled and cached results are returned (and offline mode " +"is entered)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:523 +msgid "" +"Note: this option is subject to change in future versions of the SSSD. It " +"will likely be replaced at some point by a series of timeouts for specific " +"lookup types." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:540 +msgid "ldap_enumeration_search_timeout (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:543 +msgid "" +"Specifies the timeout (in seconds) that ldap searches for user and group " +"enumerations are allowed to run before they are cancelled and cached results " +"are returned (and offline mode is entered)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:556 +msgid "ldap_network_timeout (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:559 +msgid "" +"Specifies the timeout (in seconds) after which the <citerefentry> " +"<refentrytitle>poll</refentrytitle> <manvolnum>2</manvolnum> " +"</citerefentry>/<citerefentry> <refentrytitle>select</refentrytitle> " +"<manvolnum>2</manvolnum> </citerefentry> following a <citerefentry> " +"<refentrytitle>connect</refentrytitle> <manvolnum>2</manvolnum> " +"</citerefentry> returns in case of no activity." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:587 +msgid "ldap_opt_timeout (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:590 +msgid "" +"Specifies a timeout (in seconds) after which calls to synchronous LDAP APIs " +"will abort if no response is received. Also controls the timeout when " +"communicating with the KDC in case of SASL bind, the timeout of an LDAP bind " +"operation, password change extended operation and the StartTLS operation." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:610 +msgid "ldap_connection_expire_timeout (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:613 +msgid "" +"Specifies a timeout (in seconds) that a connection to an LDAP server will be " +"maintained. After this time, the connection will be re-established. If used " +"in parallel with SASL/GSSAPI, the sooner of the two values (this value " +"vs. the TGT lifetime) will be used." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:621 +msgid "" +"If the connection is idle (not actively running an operation) within " +"<emphasis>ldap_opt_timeout</emphasis> seconds of expiration, then it will be " +"closed early to ensure that a new query cannot require the connection to " +"remain open past its expiration. This implies that connections will always " +"be closed immediately and will never be reused if " +"<emphasis>ldap_connection_expire_timeout <= ldap_opt_timeout</emphasis>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:633 +msgid "" +"This timeout can be extended of a random value specified by " +"<emphasis>ldap_connection_expire_offset</emphasis>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:643 sssd-ldap.5.xml:686 sssd-ldap.5.xml:1809 +msgid "Default: 900 (15 minutes)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:649 +msgid "ldap_connection_expire_offset (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:652 +msgid "" +"Random offset between 0 and configured value is added to " +"<emphasis>ldap_connection_expire_timeout</emphasis>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:668 +msgid "ldap_connection_idle_timeout (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:671 +msgid "" +"Specifies a timeout (in seconds) that an idle connection to an LDAP server " +"will be maintained. If the connection is idle for more than this time then " +"the connection will be closed." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:677 +msgid "You can disable this timeout by setting the value to 0." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:692 +msgid "ldap_page_size (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:695 +msgid "" +"Specify the number of records to retrieve from LDAP in a single " +"request. Some LDAP servers enforce a maximum limit per-request." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:706 +msgid "ldap_disable_paging (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:709 +msgid "" +"Disable the LDAP paging control. This option should be used if the LDAP " +"server reports that it supports the LDAP paging control in its RootDSE but " +"it is not enabled or does not behave properly." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:715 +msgid "" +"Example: OpenLDAP servers with the paging control module installed on the " +"server but not enabled will report it in the RootDSE but be unable to use " +"it." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:721 +msgid "" +"Example: 389 DS has a bug where it can only support a one paging control at " +"a time on a single connection. On busy clients, this can result in some " +"requests being denied." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:733 +msgid "ldap_disable_range_retrieval (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:736 +msgid "Disable Active Directory range retrieval." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:739 +msgid "" +"Active Directory limits the number of members that can be retrieved in a " +"single lookup using the MaxValRange policy, which defaults to 1500 " +"members. If a group contains more than 1500 members, the reply includes an " +"AD-specific range extension. When enabled, this option prevents SSSD from " +"parsing the range extension. As a result large groups will appear as they " +"have no members. This option does not enable SSSD to read subsequent " +"ranges. To retrieve all members of a group, you must increase the " +"MaxValRange setting in Active Directory." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:758 +msgid "ldap_sasl_minssf (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:761 +msgid "" +"When communicating with an LDAP server using SASL, specify the minimum " +"security level necessary to establish the connection. The values of this " +"option are defined by OpenLDAP." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:767 sssd-ldap.5.xml:783 +msgid "Default: Use the system default (usually specified by ldap.conf)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:774 +msgid "ldap_sasl_maxssf (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:777 +msgid "" +"When communicating with an LDAP server using SASL, specify the maximal " +"security level necessary to establish the connection. The values of this " +"option are defined by OpenLDAP." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:790 +msgid "ldap_deref_threshold (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:793 +msgid "" +"Specify the number of group members that must be missing from the internal " +"cache in order to trigger a dereference lookup. If less members are missing, " +"they are looked up individually." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:799 +msgid "" +"You can turn off dereference lookups completely by setting the value to " +"0. Please note that there are some codepaths in SSSD, like the IPA HBAC " +"provider, that are only implemented using the dereference call, so even with " +"dereference explicitly disabled, those parts will still use dereference if " +"the server supports it and advertises the dereference control in the rootDSE " +"object." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:810 +msgid "" +"A dereference lookup is a means of fetching all group members in a single " +"LDAP call. Different LDAP servers may implement different dereference " +"methods. The currently supported servers are 389/RHDS, OpenLDAP and Active " +"Directory." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:818 +msgid "" +"<emphasis>Note:</emphasis> If any of the search bases specifies a search " +"filter, then the dereference lookup performance enhancement will be disabled " +"regardless of this setting." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:831 +msgid "ldap_ignore_unreadable_references (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:834 +msgid "" +"Ignore unreadable LDAP entries referenced in group's member attribute. If " +"this parameter is set to false an error will be returned and the operation " +"will fail instead of just ignoring the unreadable entry." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:841 +msgid "" +"This parameter may be useful when using the AD provider and the computer " +"account that sssd uses to connect to AD does not have access to a particular " +"entry or LDAP sub-tree for security reasons." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:854 +msgid "ldap_tls_reqcert (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:857 +msgid "" +"Specifies what checks to perform on server certificates in a TLS session, if " +"any. It can be specified as one of the following values:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:863 +msgid "" +"<emphasis>never</emphasis> = The client will not request or check any server " +"certificate." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:867 +msgid "" +"<emphasis>allow</emphasis> = The server certificate is requested. If no " +"certificate is provided, the session proceeds normally. If a bad certificate " +"is provided, it will be ignored and the session proceeds normally." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:874 +msgid "" +"<emphasis>try</emphasis> = The server certificate is requested. If no " +"certificate is provided, the session proceeds normally. If a bad certificate " +"is provided, the session is immediately terminated." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:880 +msgid "" +"<emphasis>demand</emphasis> = The server certificate is requested. If no " +"certificate is provided, or a bad certificate is provided, the session is " +"immediately terminated." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:886 +msgid "<emphasis>hard</emphasis> = Same as <quote>demand</quote>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:890 +msgid "Default: hard" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:896 +msgid "ldap_tls_cacert (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:899 +msgid "" +"Specifies the file that contains certificates for all of the Certificate " +"Authorities that <command>sssd</command> will recognize." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:904 sssd-ldap.5.xml:923 sssd-ldap.5.xml:964 +msgid "" +"Default: use OpenLDAP defaults, typically in " +"<filename>/etc/openldap/ldap.conf</filename>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:911 +msgid "ldap_tls_cacertdir (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:914 +msgid "" +"Specifies the path of a directory that contains Certificate Authority " +"certificates in separate individual files. Typically the file names need to " +"be the hash of the certificate followed by '.0'. If available, " +"<command>openssl rehash</command> or <command>c_rehash</command> can be used " +"to create the correct names." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:930 +msgid "ldap_tls_cert (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:933 +msgid "Specifies the file that contains the certificate for the client's key." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:943 +msgid "ldap_tls_key (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:946 +msgid "Specifies the file that contains the client's key." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:955 +msgid "ldap_tls_cipher_suite (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:958 +msgid "" +"Specifies acceptable cipher suites. Typically this is a colon separated " +"list. See <citerefentry><refentrytitle>ldap.conf</refentrytitle> " +"<manvolnum>5</manvolnum></citerefentry> for format." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:971 +msgid "ldap_id_use_start_tls (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:974 +msgid "" +"Specifies that the id_provider connection must also use <systemitem " +"class=\"protocol\">tls</systemitem> to protect the channel. " +"<emphasis>true</emphasis> is strongly recommended for security reasons." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:985 +msgid "ldap_id_mapping (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:988 +msgid "" +"Specifies that SSSD should attempt to map user and group IDs from the " +"ldap_user_objectsid and ldap_group_objectsid attributes instead of relying " +"on ldap_user_uid_number and ldap_group_gid_number." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:994 +msgid "Currently this feature supports only ActiveDirectory objectSID mapping." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:1004 +msgid "ldap_min_id, ldap_max_id (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1007 +msgid "" +"In contrast to the SID based ID mapping which is used if ldap_id_mapping is " +"set to true the allowed ID range for ldap_user_uid_number and " +"ldap_group_gid_number is unbound. In a setup with sub/trusted-domains this " +"might lead to ID collisions. To avoid collisions ldap_min_id and ldap_max_id " +"can be set to restrict the allowed range for the IDs which are read directly " +"from the server. Sub-domains can then pick other ranges to map IDs." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1019 +msgid "Default: not set (both options are set to 0)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:1025 +msgid "ldap_sasl_mech (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1028 +msgid "" +"Specify the SASL mechanism to use. Currently only GSSAPI and GSS-SPNEGO are " +"tested and supported." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1032 +msgid "" +"If the backend supports sub-domains the value of ldap_sasl_mech is " +"automatically inherited to the sub-domains. If a different value is needed " +"for a sub-domain it can be overwritten by setting ldap_sasl_mech for this " +"sub-domain explicitly. Please see TRUSTED DOMAIN SECTION in " +"<citerefentry><refentrytitle>sssd.conf</refentrytitle> " +"<manvolnum>5</manvolnum></citerefentry> for details." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:1048 +msgid "ldap_sasl_authid (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> +#: sssd-ldap.5.xml:1060 +#, no-wrap +msgid "" +"hostname@REALM\n" +"netbiosname$@REALM\n" +"host/hostname@REALM\n" +"*$@REALM\n" +"host/*@REALM\n" +"netbiosname$@*\n" +"host/*\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1051 +msgid "" +"Specify the SASL authorization id to use. When GSSAPI/GSS-SPNEGO are used, " +"this represents the Kerberos principal used for authentication to the " +"directory. This option can either contain the full principal (for example " +"host/myhost@EXAMPLE.COM) or just the principal name (for example " +"host/myhost). By default, the value is not set and the following principals " +"are used: <placeholder type=\"programlisting\" id=\"0\"/> If none of them " +"are found, the first principal in keytab is returned." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1072 +msgid "Default: host/hostname@REALM" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:1078 +msgid "ldap_sasl_realm (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1081 +msgid "" +"Specify the SASL realm to use. When not specified, this option defaults to " +"the value of krb5_realm. If the ldap_sasl_authid contains the realm as " +"well, this option is ignored." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1087 +msgid "Default: the value of krb5_realm." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:1093 +msgid "ldap_sasl_canonicalize (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1096 +msgid "" +"If set to true, the LDAP library would perform a reverse lookup to " +"canonicalize the host name during a SASL bind." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1101 +msgid "Default: false;" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:1107 +msgid "ldap_krb5_keytab (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1110 +msgid "Specify the keytab to use when using SASL/GSSAPI/GSS-SPNEGO." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1119 sssd-krb5.5.xml:247 +msgid "Default: System keytab, normally <filename>/etc/krb5.keytab</filename>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:1125 +msgid "ldap_krb5_init_creds (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1128 +msgid "" +"Specifies that the id_provider should init Kerberos credentials (TGT). This " +"action is performed only if SASL is used and the mechanism selected is " +"GSSAPI or GSS-SPNEGO." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:1140 +msgid "ldap_krb5_ticket_lifetime (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1143 +msgid "" +"Specifies the lifetime in seconds of the TGT if GSSAPI or GSS-SPNEGO is " +"used." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1152 sssd-ad.5.xml:1260 +msgid "Default: 86400 (24 hours)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:1158 sssd-krb5.5.xml:74 +msgid "krb5_server, krb5_backup_server (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1161 +msgid "" +"Specifies the comma-separated list of IP addresses or hostnames of the " +"Kerberos servers to which SSSD should connect in the order of " +"preference. For more information on failover and server redundancy, see the " +"<quote>FAILOVER</quote> section. An optional port number (preceded by a " +"colon) may be appended to the addresses or hostnames. If empty, service " +"discovery is enabled - for more information, refer to the <quote>SERVICE " +"DISCOVERY</quote> section." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1173 sssd-krb5.5.xml:89 +msgid "" +"When using service discovery for KDC or kpasswd servers, SSSD first searches " +"for DNS entries that specify _udp as the protocol and falls back to _tcp if " +"none are found." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1178 sssd-krb5.5.xml:94 +msgid "" +"This option was named <quote>krb5_kdcip</quote> in earlier releases of " +"SSSD. While the legacy name is recognized for the time being, users are " +"advised to migrate their config files to use <quote>krb5_server</quote> " +"instead." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:1187 sssd-ipa.5.xml:570 sssd-krb5.5.xml:103 +msgid "krb5_realm (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1190 +msgid "Specify the Kerberos REALM (for SASL/GSSAPI/GSS-SPNEGO auth)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1194 +msgid "Default: System defaults, see <filename>/etc/krb5.conf</filename>" +msgstr "" + +#. type: Content of: <variablelist><varlistentry><term> +#: sssd-ldap.5.xml:1200 include/krb5_options.xml:154 +msgid "krb5_canonicalize (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1203 +msgid "" +"Specifies if the host principal should be canonicalized when connecting to " +"LDAP server. This feature is available with MIT Kerberos >= 1.7" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:1215 sssd-krb5.5.xml:336 +msgid "krb5_use_kdcinfo (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1218 sssd-krb5.5.xml:339 +msgid "" +"Specifies if the SSSD should instruct the Kerberos libraries what realm and " +"which KDCs to use. This option is on by default, if you disable it, you need " +"to configure the Kerberos library using the <citerefentry> " +"<refentrytitle>krb5.conf</refentrytitle> <manvolnum>5</manvolnum> " +"</citerefentry> configuration file." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1229 sssd-krb5.5.xml:350 +msgid "" +"See the <citerefentry> " +"<refentrytitle>sssd_krb5_locator_plugin</refentrytitle> " +"<manvolnum>8</manvolnum> </citerefentry> manual page for more information on " +"the locator plugin." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:1243 +msgid "ldap_pwd_policy (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1246 +msgid "" +"Select the policy to evaluate the password expiration on the client " +"side. The following values are allowed:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1251 +msgid "" +"<emphasis>none</emphasis> - No evaluation on the client side. This option " +"cannot disable server-side password policies." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1256 +msgid "" +"<emphasis>shadow</emphasis> - Use " +"<citerefentry><refentrytitle>shadow</refentrytitle> " +"<manvolnum>5</manvolnum></citerefentry> style attributes to evaluate if the " +"password has expired. Please see option \"ldap_chpass_update_last_change\" " +"as well." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1264 +msgid "" +"<emphasis>mit_kerberos</emphasis> - Use the attributes used by MIT Kerberos " +"to determine if the password has expired. Use chpass_provider=krb5 to update " +"these attributes when the password is changed." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1273 +msgid "" +"<emphasis>Note</emphasis>: if a password policy is configured on server " +"side, it always takes precedence over policy set with this option." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:1281 +msgid "ldap_referrals (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1284 +msgid "Specifies whether automatic referral chasing should be enabled." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1288 +msgid "" +"Please note that sssd only supports referral chasing when it is compiled " +"with OpenLDAP version 2.4.13 or higher." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1293 +msgid "" +"Chasing referrals may incur a performance penalty in environments that use " +"them heavily, a notable example is Microsoft Active Directory. If your setup " +"does not in fact require the use of referrals, setting this option to false " +"might bring a noticeable performance improvement. Setting this option to " +"false is therefore recommended in case the SSSD LDAP provider is used " +"together with Microsoft Active Directory as a backend. Even if SSSD would be " +"able to follow the referral to a different AD DC no additional data would be " +"available." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:1312 +msgid "ldap_dns_service_name (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1315 +msgid "Specifies the service name to use when service discovery is enabled." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1319 +msgid "Default: ldap" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:1325 +msgid "ldap_chpass_dns_service_name (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1328 +msgid "" +"Specifies the service name to use to find an LDAP server which allows " +"password changes when service discovery is enabled." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1333 +msgid "Default: not set, i.e. service discovery is disabled" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:1339 +msgid "ldap_chpass_update_last_change (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1342 +msgid "" +"Specifies whether to update the ldap_user_shadow_last_change attribute with " +"days since the Epoch after a password change operation." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1348 +msgid "" +"It is recommended to set this option explicitly if \"ldap_pwd_policy = " +"shadow\" is used to let SSSD know if the LDAP server will update " +"shadowLastChange LDAP attribute automatically after a password change or if " +"SSSD has to update it." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:1362 +msgid "ldap_access_filter (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1365 +msgid "" +"If using access_provider = ldap and ldap_access_order = filter (default), " +"this option is mandatory. It specifies an LDAP search filter criteria that " +"must be met for the user to be granted access on this host. If " +"access_provider = ldap, ldap_access_order = filter and this option is not " +"set, it will result in all users being denied access. Use access_provider = " +"permit to change this default behavior. Please note that this filter is " +"applied on the LDAP user entry only and thus filtering based on nested " +"groups may not work (e.g. memberOf attribute on AD entries points only to " +"direct parents). If filtering based on nested groups is required, please see " +"<citerefentry> " +"<refentrytitle>sssd-simple</refentrytitle><manvolnum>5</manvolnum> " +"</citerefentry>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1385 +msgid "Example:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><programlisting> +#: sssd-ldap.5.xml:1388 +#, no-wrap +msgid "" +"access_provider = ldap\n" +"ldap_access_filter = (employeeType=admin)\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1392 +msgid "" +"This example means that access to this host is restricted to users whose " +"employeeType attribute is set to \"admin\"." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1397 +msgid "" +"Offline caching for this feature is limited to determining whether the " +"user's last online login was granted access permission. If they were granted " +"access during their last login, they will continue to be granted access " +"while offline and vice versa." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1405 sssd-ldap.5.xml:1461 +msgid "Default: Empty" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:1411 +msgid "ldap_account_expire_policy (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1414 +msgid "" +"With this option a client side evaluation of access control attributes can " +"be enabled." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1418 +msgid "" +"Please note that it is always recommended to use server side access control, " +"i.e. the LDAP server should deny the bind request with a suitable error code " +"even if the password is correct." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1425 +msgid "The following values are allowed:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1428 +msgid "" +"<emphasis>shadow</emphasis>: use the value of ldap_user_shadow_expire to " +"determine if the account is expired." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1433 +msgid "" +"<emphasis>ad</emphasis>: use the value of the 32bit field " +"ldap_user_ad_user_account_control and allow access if the second bit is not " +"set. If the attribute is missing access is granted. Also the expiration time " +"of the account is checked." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1440 +msgid "" +"<emphasis>rhds</emphasis>, <emphasis>ipa</emphasis>, " +"<emphasis>389ds</emphasis>: use the value of ldap_ns_account_lock to check " +"if access is allowed or not." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1446 +msgid "" +"<emphasis>nds</emphasis>: the values of " +"ldap_user_nds_login_allowed_time_map, ldap_user_nds_login_disabled and " +"ldap_user_nds_login_expiration_time are used to check if access is " +"allowed. If both attributes are missing access is granted." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1454 +msgid "" +"Please note that the ldap_access_order configuration option " +"<emphasis>must</emphasis> include <quote>expire</quote> in order for the " +"ldap_account_expire_policy option to work." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:1467 +msgid "ldap_access_order (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1470 sssd-ipa.5.xml:400 +msgid "Comma separated list of access control options. Allowed values are:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1474 +msgid "<emphasis>filter</emphasis>: use ldap_access_filter" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1477 +msgid "" +"<emphasis>lockout</emphasis>: use account locking. If set, this option " +"denies access in case that ldap attribute 'pwdAccountLockedTime' is present " +"and has value of '000001010000Z'. Please see the option ldap_pwdlockout_dn. " +"Please note that 'access_provider = ldap' must be set for this feature to " +"work." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1487 +msgid "" +"<emphasis> Please note that this option is superseded by the " +"<quote>ppolicy</quote> option and might be removed in a future release. " +"</emphasis>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1494 +msgid "" +"<emphasis>ppolicy</emphasis>: use account locking. If set, this option " +"denies access in case that ldap attribute 'pwdAccountLockedTime' is present " +"and has value of '000001010000Z' or represents any time in the past. The " +"value of the 'pwdAccountLockedTime' attribute must end with 'Z', which " +"denotes the UTC time zone. Other time zones are not currently supported and " +"will result in \"access-denied\" when users attempt to log in. Please see " +"the option ldap_pwdlockout_dn. Please note that 'access_provider = ldap' " +"must be set for this feature to work." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1511 +msgid "<emphasis>expire</emphasis>: use ldap_account_expire_policy" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1515 sssd-ipa.5.xml:408 +msgid "" +"<emphasis>pwd_expire_policy_reject, pwd_expire_policy_warn, " +"pwd_expire_policy_renew: </emphasis> These options are useful if users are " +"interested in being warned that password is about to expire and " +"authentication is based on using a different method than passwords - for " +"example SSH keys." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1525 sssd-ipa.5.xml:418 +msgid "" +"The difference between these options is the action taken if user password is " +"expired:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd-ldap.5.xml:1530 sssd-ipa.5.xml:423 +msgid "pwd_expire_policy_reject - user is denied to log in," +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd-ldap.5.xml:1536 sssd-ipa.5.xml:429 +msgid "pwd_expire_policy_warn - user is still able to log in," +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd-ldap.5.xml:1542 sssd-ipa.5.xml:435 +msgid "" +"pwd_expire_policy_renew - user is prompted to change their password " +"immediately." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1550 +msgid "" +"Please note that 'access_provider = ldap' must be set for this feature to " +"work. Also 'ldap_pwd_policy' must be set to shadow or mit_kerberos, these " +"options do not work with server-side password policies." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1556 +msgid "" +"<emphasis>authorized_service</emphasis>: use the authorizedService attribute " +"to determine access" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1561 +msgid "<emphasis>host</emphasis>: use the host attribute to determine access" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1565 +msgid "" +"<emphasis>rhost</emphasis>: use the rhost attribute to determine whether " +"remote host can access" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1569 +msgid "" +"Please note, rhost field in pam is set by application, it is better to check " +"what the application sends to pam, before enabling this access control " +"option" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1574 +msgid "Default: filter" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1577 +msgid "" +"Please note that it is a configuration error if a value is used more than " +"once." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:1584 +msgid "ldap_pwdlockout_dn (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1587 +msgid "" +"This option specifies the DN of password policy entry on LDAP server. Please " +"note that absence of this option in sssd.conf in case of enabled account " +"lockout checking will yield access denied as ppolicy attributes on LDAP " +"server cannot be checked properly." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1595 +msgid "Example: cn=ppolicy,ou=policies,dc=example,dc=com" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1598 +msgid "Default: cn=ppolicy,ou=policies,$ldap_search_base" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:1604 +msgid "ldap_deref (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1607 +msgid "" +"Specifies how alias dereferencing is done when performing a search. The " +"following options are allowed:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1612 +msgid "<emphasis>never</emphasis>: Aliases are never dereferenced." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1616 +msgid "" +"<emphasis>searching</emphasis>: Aliases are dereferenced in subordinates of " +"the base object, but not in locating the base object of the search." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1621 +msgid "" +"<emphasis>finding</emphasis>: Aliases are only dereferenced when locating " +"the base object of the search." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1626 +msgid "" +"<emphasis>always</emphasis>: Aliases are dereferenced both in searching and " +"in locating the base object of the search." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1631 +msgid "" +"Default: Empty (this is handled as <emphasis>never</emphasis> by the LDAP " +"client libraries)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:1639 +msgid "ldap_rfc2307_fallback_to_local_users (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1642 +msgid "" +"Allows to retain local users as members of an LDAP group for servers that " +"use the RFC2307 schema." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1646 +msgid "" +"In some environments where the RFC2307 schema is used, local users are made " +"members of LDAP groups by adding their names to the memberUid attribute. " +"The self-consistency of the domain is compromised when this is done, so SSSD " +"would normally remove the \"missing\" users from the cached group " +"memberships as soon as nsswitch tries to fetch information about the user " +"via getpw*() or initgroups() calls." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1657 +msgid "" +"This option falls back to checking if local users are referenced, and caches " +"them so that later initgroups() calls will augment the local users with the " +"additional LDAP groups." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:1669 sssd-ifp.5.xml:158 +msgid "wildcard_limit (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1672 +msgid "" +"Specifies an upper limit on the number of entries that are downloaded during " +"a wildcard lookup." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1676 +msgid "At the moment, only the InfoPipe responder supports wildcard lookups." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1680 +msgid "Default: 1000 (often the size of one page)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:1686 +msgid "ldap_library_debug_level (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1689 +msgid "" +"Switches on libldap debugging with the given level. The libldap debug " +"messages will be written independent of the general debug_level." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1694 +msgid "" +"OpenLDAP uses a bitmap to enable debugging for specific components, -1 will " +"enable full debug output." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1699 +msgid "Default: 0 (libldap debugging disabled)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:1705 +msgid "ldap_use_ppolicy (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1708 +msgid "" +"Turns on requesting and relying on the server-side password policy " +"controls. Disabling this allows interacting with services which send back " +"invalid ppolicy extension." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:1720 +msgid "ldap_ppolicy_pwd_change_threshold (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1723 +msgid "" +"Forces a password change when server side password policy controls are " +"enabled and remaining grace logins returned by the server after the " +"authentication reach or go below the threshold. Note that the minimum " +"useful value is 2, as changing the password consumes 2 additional grace " +"logins, one to verify the current password and a second one to perform the " +"password change." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-ldap.5.xml:52 +msgid "" +"All of the common configuration options that apply to SSSD domains also " +"apply to LDAP domains. Refer to the <quote>DOMAIN SECTIONS</quote> section " +"of the <citerefentry> <refentrytitle>sssd.conf</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry> manual page for full details. Note " +"that SSSD LDAP mapping attributes are described in the <citerefentry> " +"<refentrytitle>sssd-ldap-attributes</refentrytitle> <manvolnum>5</manvolnum> " +"</citerefentry> manual page. <placeholder type=\"variablelist\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd-ldap.5.xml:1743 +msgid "SUDO OPTIONS" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-ldap.5.xml:1745 +msgid "" +"The detailed instructions for configuration of sudo_provider are in the " +"manual page <citerefentry> <refentrytitle>sssd-sudo</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:1756 +msgid "ldap_sudo_full_refresh_interval (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1759 +msgid "" +"How many seconds SSSD will wait between executing a full refresh of sudo " +"rules (which downloads all rules that are stored on the server)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1764 +msgid "" +"The value must be greater than <emphasis>ldap_sudo_smart_refresh_interval " +"</emphasis>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1769 +msgid "" +"You can disable full refresh by setting this option to 0. However, either " +"smart or full refresh must be enabled." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1774 +msgid "Default: 21600 (6 hours)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:1780 +msgid "ldap_sudo_smart_refresh_interval (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1783 +msgid "" +"How many seconds SSSD has to wait before executing a smart refresh of sudo " +"rules (which downloads all rules that have USN higher than the highest " +"server USN value that is currently known by SSSD)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1789 +msgid "" +"If USN attributes are not supported by the server, the modifyTimestamp " +"attribute is used instead." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1793 +msgid "" +"<emphasis>Note:</emphasis> the highest USN value can be updated by three " +"tasks: 1) By sudo full and smart refresh (if updated rules are found), 2) by " +"enumeration of users and groups (if enabled and updated users or groups are " +"found) and 3) by reconnecting to the server (by default every 15 minutes, " +"see <emphasis>ldap_connection_expire_timeout</emphasis>)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1804 +msgid "" +"You can disable smart refresh by setting this option to 0. However, either " +"smart or full refresh must be enabled." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:1815 +msgid "ldap_sudo_random_offset (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1818 +msgid "" +"Random offset between 0 and configured value is added to smart and full " +"refresh periods each time the periodic task is scheduled. The value is in " +"seconds." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1824 +msgid "" +"Note that this random offset is also applied on the first SSSD start which " +"delays the first sudo rules refresh. This prolongs the time when the sudo " +"rules are not available for use." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1830 +msgid "You can disable this offset by setting the value to 0." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:1840 +msgid "ldap_sudo_use_host_filter (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1843 +msgid "" +"If true, SSSD will download only rules that are applicable to this machine " +"(using the IPv4 or IPv6 host/network addresses and hostnames)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:1854 +msgid "ldap_sudo_hostnames (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1857 +msgid "" +"Space separated list of hostnames or fully qualified domain names that " +"should be used to filter the rules." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1862 +msgid "" +"If this option is empty, SSSD will try to discover the hostname and the " +"fully qualified domain name automatically." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1867 sssd-ldap.5.xml:1890 sssd-ldap.5.xml:1908 +#: sssd-ldap.5.xml:1926 +msgid "" +"If <emphasis>ldap_sudo_use_host_filter</emphasis> is " +"<emphasis>false</emphasis> then this option has no effect." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1872 sssd-ldap.5.xml:1895 +msgid "Default: not specified" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:1878 +msgid "ldap_sudo_ip (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1881 +msgid "" +"Space separated list of IPv4 or IPv6 host/network addresses that should be " +"used to filter the rules." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1886 +msgid "" +"If this option is empty, SSSD will try to discover the addresses " +"automatically." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:1901 +msgid "ldap_sudo_include_netgroups (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1904 +msgid "" +"If true then SSSD will download every rule that contains a netgroup in " +"sudoHost attribute." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:1919 +msgid "ldap_sudo_include_regexp (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1922 +msgid "" +"If true then SSSD will download every rule that contains a wildcard in " +"sudoHost attribute." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><note><para> +#: sssd-ldap.5.xml:1932 +msgid "" +"Using wildcard is an operation that is very costly to evaluate on the LDAP " +"server side!" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-ldap.5.xml:1944 +msgid "" +"This manual page only describes attribute name mapping. For detailed " +"explanation of sudo related attribute semantics, see <citerefentry> " +"<refentrytitle>sudoers.ldap</refentrytitle><manvolnum>5</manvolnum> " +"</citerefentry>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd-ldap.5.xml:1954 +msgid "AUTOFS OPTIONS" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-ldap.5.xml:1956 +msgid "" +"Some of the defaults for the parameters below are dependent on the LDAP " +"schema." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:1962 +msgid "ldap_autofs_map_master_name (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1965 +msgid "The name of the automount master map in LDAP." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1968 +msgid "Default: auto.master" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd-ldap.5.xml:1979 +msgid "ADVANCED OPTIONS" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:1986 +msgid "ldap_netgroup_search_base (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:1991 +msgid "ldap_user_search_base (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:1996 +msgid "ldap_group_search_base (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><note> +#: sssd-ldap.5.xml:2001 +msgid "<note>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><note><para> +#: sssd-ldap.5.xml:2003 +msgid "" +"If the option <quote>ldap_use_tokengroups</quote> is enabled, the searches " +"against Active Directory will not be restricted and return all groups " +"memberships, even with no GID mapping. It is recommended to disable this " +"feature, if group names are not being displayed correctly." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist> +#: sssd-ldap.5.xml:2010 +msgid "</note>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:2012 +msgid "ldap_sudo_search_base (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:2017 +msgid "ldap_autofs_search_base (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-ldap.5.xml:1981 +msgid "" +"These options are supported by LDAP domains, but they should be used with " +"caution. Please include them in your configuration only if you know what you " +"are doing. <placeholder type=\"variablelist\" id=\"0\"/> <placeholder " +"type=\"variablelist\" id=\"1\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd-ldap.5.xml:2032 sssd-simple.5.xml:169 sssd-ipa.5.xml:979 +#: sssd-ad.5.xml:1463 sssd-idp.5.xml:343 sssd-krb5.5.xml:483 +#: sss_rpcidmapd.5.xml:98 sssd-session-recording.5.xml:176 +msgid "EXAMPLE" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-ldap.5.xml:2034 +msgid "" +"The following example assumes that SSSD is correctly configured and LDAP is " +"set to one of the domains in the <replaceable>[domains]</replaceable> " +"section." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><programlisting> +#: sssd-ldap.5.xml:2040 +#, no-wrap +msgid "" +"[domain/LDAP]\n" +"id_provider = ldap\n" +"auth_provider = ldap\n" +"ldap_uri = ldap://ldap.mydomain.org\n" +"ldap_search_base = dc=mydomain,dc=org\n" +"ldap_tls_reqcert = demand\n" +"cache_credentials = true\n" +msgstr "" + +#. type: Content of: <refsect1><refsect2><para> +#: sssd-ldap.5.xml:2039 sssd-ldap.5.xml:2057 sssd-simple.5.xml:177 +#: sssd-ipa.5.xml:987 sssd-ad.5.xml:1471 sssd-sudo.5.xml:56 sssd-krb5.5.xml:492 +#: sssd-session-recording.5.xml:182 include/ldap_id_mapping.xml:105 +msgid "<placeholder type=\"programlisting\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd-ldap.5.xml:2051 +msgid "LDAP ACCESS FILTER EXAMPLE" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-ldap.5.xml:2053 +msgid "" +"The following example assumes that SSSD is correctly configured and to use " +"the ldap_access_order=lockout." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><programlisting> +#: sssd-ldap.5.xml:2058 +#, no-wrap +msgid "" +"[domain/LDAP]\n" +"id_provider = ldap\n" +"auth_provider = ldap\n" +"access_provider = ldap\n" +"ldap_access_order = lockout\n" +"ldap_pwdlockout_dn = cn=ppolicy,ou=policies,dc=mydomain,dc=org\n" +"ldap_uri = ldap://ldap.mydomain.org\n" +"ldap_search_base = dc=mydomain,dc=org\n" +"ldap_tls_reqcert = demand\n" +"cache_credentials = true\n" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd-ldap.5.xml:2073 sssd_krb5_locator_plugin.8.xml:83 sssd-simple.5.xml:189 +#: sssd-ad.5.xml:1486 sssd.8.xml:270 sss_seed.8.xml:163 +msgid "NOTES" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-ldap.5.xml:2075 +msgid "" +"The descriptions of some of the configuration options in this manual page " +"are based on the <citerefentry> <refentrytitle>ldap.conf</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry> manual page from the OpenLDAP 2.4 " +"distribution." +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refname> +#: pam_sss.8.xml:11 pam_sss.8.xml:16 +msgid "pam_sss" +msgstr "" + +#. type: Content of: <reference><refentry><refmeta><manvolnum> +#: pam_sss.8.xml:12 pam_sss_gss.8.xml:12 sssd_krb5_locator_plugin.8.xml:11 +#: sssd.8.xml:11 sss_obfuscate.8.xml:11 sss_override.8.xml:11 +#: sss_cache.8.xml:11 sss_debuglevel.8.xml:11 sss_seed.8.xml:11 +#: idmap_sss.8.xml:11 sssctl.8.xml:11 sssd-kcm.8.xml:11 +#: sssd_krb5_localauth_plugin.8.xml:11 +msgid "8" +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refpurpose> +#: pam_sss.8.xml:17 +msgid "PAM module for SSSD" +msgstr "" + +#. type: Content of: <reference><refentry><refsynopsisdiv><cmdsynopsis> +#: pam_sss.8.xml:22 +msgid "" +"<command>pam_sss.so</command> <arg choice='opt'> " +"<replaceable>quiet</replaceable> </arg> <arg choice='opt'> " +"<replaceable>forward_pass</replaceable> </arg> <arg choice='opt'> " +"<replaceable>use_first_pass</replaceable> </arg> <arg choice='opt'> " +"<replaceable>use_authtok</replaceable> </arg> <arg choice='opt'> " +"<replaceable>retry=N</replaceable> </arg> <arg choice='opt'> " +"<replaceable>ignore_unknown_user</replaceable> </arg> <arg choice='opt'> " +"<replaceable>ignore_authinfo_unavail</replaceable> </arg> <arg choice='opt'> " +"<replaceable>domains=X</replaceable> </arg> <arg choice='opt'> " +"<replaceable>allow_missing_name</replaceable> </arg> <arg choice='opt'> " +"<replaceable>prompt_always</replaceable> </arg> <arg choice='opt'> " +"<replaceable>try_cert_auth</replaceable> </arg> <arg choice='opt'> " +"<replaceable>require_cert_auth</replaceable> </arg> <arg choice='opt'> " +"<replaceable>allow_chauthtok_by_root</replaceable> </arg>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: pam_sss.8.xml:67 +msgid "" +"<command>pam_sss.so</command> is the PAM interface to the System Security " +"Services daemon (SSSD). Errors and results are logged through " +"<command>syslog(3)</command> with the LOG_AUTHPRIV facility." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: pam_sss.8.xml:73 pam_sss_gss.8.xml:89 sssd.8.xml:42 sss_obfuscate.8.xml:58 +#: sss_cache.8.xml:39 sss_seed.8.xml:42 sss_ssh_authorizedkeys.1.xml:123 +#: sss_ssh_knownhosts.1.xml:59 +msgid "OPTIONS" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: pam_sss.8.xml:77 +msgid "<option>quiet</option>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: pam_sss.8.xml:80 +msgid "Suppress log messages for unknown users." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: pam_sss.8.xml:85 +msgid "<option>forward_pass</option>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: pam_sss.8.xml:88 +msgid "" +"If <option>forward_pass</option> is set the entered password is put on the " +"stack for other PAM modules to use." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: pam_sss.8.xml:95 +msgid "<option>use_first_pass</option>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: pam_sss.8.xml:98 +msgid "" +"The argument use_first_pass forces the module to use a previous stacked " +"modules password and will never prompt the user - if no password is " +"available or the password is not appropriate, the user will be denied " +"access." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: pam_sss.8.xml:106 +msgid "<option>use_authtok</option>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: pam_sss.8.xml:109 +msgid "" +"When password changing enforce the module to set the new password to the one " +"provided by a previously stacked password module." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: pam_sss.8.xml:116 +msgid "<option>retry=N</option>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: pam_sss.8.xml:119 +msgid "" +"If specified the user is asked another N times for a password if " +"authentication fails. Default is 0." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: pam_sss.8.xml:121 +msgid "" +"Please note that this option might not work as expected if the application " +"calling PAM handles the user dialog on its own. A typical example is " +"<command>sshd</command> with <option>PasswordAuthentication</option>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: pam_sss.8.xml:130 +msgid "<option>ignore_unknown_user</option>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: pam_sss.8.xml:133 +msgid "" +"If this option is specified and the user does not exist, the PAM module will " +"return PAM_IGNORE. This causes the PAM framework to ignore this module." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: pam_sss.8.xml:140 +msgid "<option>ignore_authinfo_unavail</option>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: pam_sss.8.xml:144 +msgid "" +"Specifies that the PAM module should return PAM_IGNORE if it cannot contact " +"the SSSD daemon. This causes the PAM framework to ignore this module." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: pam_sss.8.xml:151 +msgid "<option>domains</option>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: pam_sss.8.xml:155 +msgid "" +"Allows the administrator to restrict the domains a particular PAM service is " +"allowed to authenticate against. The format is a comma-separated list of " +"SSSD domain names, as specified in the sssd.conf file." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: pam_sss.8.xml:161 +msgid "" +"NOTE: If this is used for a service not running as root user, e.g. a " +"web-server, it must be used in conjunction with the " +"<quote>pam_trusted_users</quote> and <quote>pam_public_domains</quote> " +"options. Please see the <citerefentry> " +"<refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</manvolnum> " +"</citerefentry> manual page for more information on these two PAM responder " +"options." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: pam_sss.8.xml:176 +msgid "<option>allow_missing_name</option>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: pam_sss.8.xml:180 +msgid "" +"The main purpose of this option is to let SSSD determine the user name based " +"on additional information, e.g. the certificate from a Smartcard." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><programlisting> +#: pam_sss.8.xml:190 +#, no-wrap +msgid "" +"auth sufficient pam_sss.so allow_missing_name\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: pam_sss.8.xml:185 +msgid "" +"The current use case are login managers which can monitor a Smartcard reader " +"for card events. In case a Smartcard is inserted the login manager will call " +"a PAM stack which includes a line like <placeholder type=\"programlisting\" " +"id=\"0\"/> In this case SSSD will try to determine the user name based on " +"the content of the Smartcard, returns it to pam_sss which will finally put " +"it on the PAM stack." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: pam_sss.8.xml:200 +msgid "<option>prompt_always</option>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: pam_sss.8.xml:204 +msgid "" +"Always prompt the user for credentials. With this option credentials " +"requested by other PAM modules, typically a password, will be ignored and " +"pam_sss will prompt for credentials again. Based on the pre-auth reply by " +"SSSD pam_sss might prompt for a password, a Smartcard PIN or other " +"credentials." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: pam_sss.8.xml:215 +msgid "<option>try_cert_auth</option>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: pam_sss.8.xml:219 +msgid "" +"Try to use certificate based authentication, i.e. authentication with a " +"Smartcard or similar devices. If a Smartcard is available and the service is " +"allowed for Smartcard authentication the user will be prompted for a PIN and " +"the certificate based authentication will continue" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: pam_sss.8.xml:227 +msgid "" +"If no Smartcard is available or certificate based authentication is not " +"allowed for the current service PAM_AUTHINFO_UNAVAIL is returned." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: pam_sss.8.xml:235 +msgid "<option>require_cert_auth</option>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: pam_sss.8.xml:239 +msgid "" +"Do certificate based authentication, i.e. authentication with a Smartcard " +"or similar devices. If a Smartcard is not available the user will be " +"prompted to insert one. SSSD will wait for a Smartcard until the timeout " +"defined by p11_wait_for_card_timeout passed, please see " +"<citerefentry><refentrytitle>sssd.conf</refentrytitle> " +"<manvolnum>5</manvolnum></citerefentry> for details." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: pam_sss.8.xml:249 +msgid "" +"If no Smartcard is available after the timeout or certificate based " +"authentication is not allowed for the current service PAM_AUTHINFO_UNAVAIL " +"is returned." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: pam_sss.8.xml:257 +msgid "<option>allow_chauthtok_by_root</option>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: pam_sss.8.xml:261 +msgid "" +"By default the chauthtok PAM action will short-circuit to returning " +"PAM_SUCCESS when pam_sss.so is invoked by root user." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: pam_sss.8.xml:266 +msgid "" +"This option disables this behavior allowing to change auth tokens when " +"running as root." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: pam_sss.8.xml:275 pam_sss_gss.8.xml:103 +msgid "MODULE TYPES PROVIDED" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: pam_sss.8.xml:276 +msgid "" +"All module types (<option>account</option>, <option>auth</option>, " +"<option>password</option> and <option>session</option>) are provided." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: pam_sss.8.xml:279 +msgid "" +"If SSSD's PAM responder is not running, e.g. if the PAM responder socket is " +"not available, pam_sss will return PAM_USER_UNKNOWN when called as " +"<option>account</option> module to avoid issues with users from other " +"sources during access control." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: pam_sss.8.xml:286 pam_sss_gss.8.xml:108 +msgid "RETURN VALUES" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: pam_sss.8.xml:289 pam_sss_gss.8.xml:111 +msgid "PAM_SUCCESS" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: pam_sss.8.xml:292 pam_sss_gss.8.xml:114 +msgid "The PAM operation finished successfully." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: pam_sss.8.xml:297 pam_sss_gss.8.xml:119 +msgid "PAM_USER_UNKNOWN" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: pam_sss.8.xml:300 +msgid "" +"The user is not known to the authentication service or the SSSD's PAM " +"responder is not running." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: pam_sss.8.xml:306 pam_sss_gss.8.xml:128 +msgid "PAM_AUTH_ERR" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: pam_sss.8.xml:309 +msgid "" +"Authentication failure. Also, could be returned when there is a problem with " +"getting the certificate." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: pam_sss.8.xml:315 +msgid "PAM_PERM_DENIED" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: pam_sss.8.xml:318 +msgid "" +"Permission denied. The SSSD log files may contain additional information " +"about the error." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: pam_sss.8.xml:324 +msgid "PAM_IGNORE" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: pam_sss.8.xml:327 +msgid "" +"See options <option>ignore_unknown_user</option> and " +"<option>ignore_authinfo_unavail</option>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: pam_sss.8.xml:333 +msgid "PAM_AUTHTOK_ERR" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: pam_sss.8.xml:336 +msgid "" +"Unable to obtain the new authentication token. Also, could be returned when " +"the user authenticates with certificates and multiple certificates are " +"available, but the installed version of GDM does not support selection from " +"multiple certificates." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: pam_sss.8.xml:344 pam_sss_gss.8.xml:136 +msgid "PAM_AUTHINFO_UNAVAIL" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: pam_sss.8.xml:347 pam_sss_gss.8.xml:139 +msgid "" +"Unable to access the authentication information. This might be due to a " +"network or hardware failure." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: pam_sss.8.xml:353 +msgid "PAM_BUF_ERR" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: pam_sss.8.xml:356 +msgid "" +"A memory error occurred. Also, could be returned when options use_first_pass " +"or use_authtok were set, but no password was found from the previously " +"stacked PAM module." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: pam_sss.8.xml:363 pam_sss_gss.8.xml:145 +msgid "PAM_SYSTEM_ERR" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: pam_sss.8.xml:366 pam_sss_gss.8.xml:148 +msgid "" +"A system error occurred. The SSSD log files may contain additional " +"information about the error." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: pam_sss.8.xml:372 +msgid "PAM_CRED_ERR" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: pam_sss.8.xml:375 +msgid "Unable to set the credentials of the user." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: pam_sss.8.xml:380 +msgid "PAM_CRED_INSUFFICIENT" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: pam_sss.8.xml:383 +msgid "" +"The application does not have sufficient credentials to authenticate the " +"user. For example, missing PIN during smartcard authentication or missing " +"factor during two-factor authentication." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: pam_sss.8.xml:391 +msgid "PAM_SERVICE_ERR" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: pam_sss.8.xml:394 +msgid "Error in service module." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: pam_sss.8.xml:399 +msgid "PAM_NEW_AUTHTOK_REQD" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: pam_sss.8.xml:402 +msgid "The user's authentication token has expired." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: pam_sss.8.xml:407 +msgid "PAM_ACCT_EXPIRED" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: pam_sss.8.xml:410 +msgid "The user account has expired." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: pam_sss.8.xml:415 +msgid "PAM_SESSION_ERR" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: pam_sss.8.xml:418 +msgid "Unable to fetch IPA Desktop Profile rules or user info." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: pam_sss.8.xml:423 +msgid "PAM_CRED_UNAVAIL" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: pam_sss.8.xml:426 +msgid "Unable to retrieve Kerberos user credentials." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: pam_sss.8.xml:431 +msgid "PAM_NO_MODULE_DATA" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: pam_sss.8.xml:434 +msgid "" +"No authentication method was found by Kerberos. This might happen if the " +"user has a Smartcard assigned but the pkinit plugin is not available on the " +"client." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: pam_sss.8.xml:441 +msgid "PAM_CONV_ERR" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: pam_sss.8.xml:444 +msgid "Conversation failure." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: pam_sss.8.xml:449 +msgid "PAM_AUTHTOK_LOCK_BUSY" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: pam_sss.8.xml:452 +msgid "No KDC suitable for password change is available." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: pam_sss.8.xml:457 +msgid "PAM_ABORT" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: pam_sss.8.xml:460 +msgid "Unknown PAM call." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: pam_sss.8.xml:465 +msgid "PAM_MODULE_UNKNOWN" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: pam_sss.8.xml:468 +msgid "Unsupported PAM task or command." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: pam_sss.8.xml:473 +msgid "PAM_BAD_ITEM" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: pam_sss.8.xml:476 +msgid "The authentication module cannot handle Smartcard credentials." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: pam_sss.8.xml:484 +msgid "FILES" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: pam_sss.8.xml:485 +msgid "" +"If a password reset by root fails, because the corresponding SSSD provider " +"does not support password resets, an individual message can be " +"displayed. This message can e.g. contain instructions about how to reset a " +"password." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: pam_sss.8.xml:490 +msgid "" +"The message is read from the file " +"<filename>pam_sss_pw_reset_message.LOC</filename> where LOC stands for a " +"locale string returned by <citerefentry> " +"<refentrytitle>setlocale</refentrytitle><manvolnum>3</manvolnum> " +"</citerefentry>. If there is no matching file the content of " +"<filename>pam_sss_pw_reset_message.txt</filename> is displayed. Root must be " +"the owner of the files and only root may have read and write permissions " +"while all other users must have only read permissions." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: pam_sss.8.xml:500 +msgid "" +"These files are searched in the directory " +"<filename>/etc/sssd/customize/DOMAIN_NAME/</filename>. If no matching file " +"is present a generic message is displayed." +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refname> +#: pam_sss_gss.8.xml:11 pam_sss_gss.8.xml:16 +msgid "pam_sss_gss" +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refpurpose> +#: pam_sss_gss.8.xml:17 +msgid "PAM module for SSSD GSSAPI authentication" +msgstr "" + +#. type: Content of: <reference><refentry><refsynopsisdiv><cmdsynopsis> +#: pam_sss_gss.8.xml:22 +msgid "" +"<command>pam_sss_gss.so</command> <arg choice='opt'> " +"<replaceable>debug</replaceable> </arg>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: pam_sss_gss.8.xml:32 +msgid "" +"<command>pam_sss_gss.so</command> authenticates user over GSSAPI in " +"cooperation with SSSD." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: pam_sss_gss.8.xml:36 +msgid "" +"This module will try to authenticate the user using the GSSAPI hostbased " +"service name host@hostname which translates to host/hostname@REALM Kerberos " +"principal. The <emphasis>REALM</emphasis> part of the Kerberos principal " +"name is derived by Kerberos internal mechanisms and it can be set explicitly " +"in configuration of [domain_realm] section in /etc/krb5.conf." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: pam_sss_gss.8.xml:44 +msgid "" +"SSSD is used to provide desired service name and to validate the user's " +"credentials using GSSAPI calls. If the service ticket is already present in " +"the Kerberos credentials cache or if user's ticket granting ticket can be " +"used to get the correct service ticket then the user will be authenticated." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: pam_sss_gss.8.xml:51 +msgid "" +"If <option>pam_gssapi_check_upn</option> is True (default) then SSSD " +"requires that the credentials used to obtain the service tickets can be " +"associated with the user. This means that the principal that owns the " +"Kerberos credentials must match with the user principal name as defined in " +"LDAP." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: pam_sss_gss.8.xml:58 +msgid "" +"To enable GSSAPI authentication in SSSD, set " +"<option>pam_gssapi_services</option> option in [pam] or domain section of " +"sssd.conf. The service credentials need to be stored in SSSD's keytab (it is " +"already present if you use ipa or ad provider). The keytab location can be " +"set with <option>krb5_keytab</option> option. See <citerefentry> " +"<refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</manvolnum> " +"</citerefentry> and <citerefentry> <refentrytitle>sssd-krb5</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry> for more details on these options." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: pam_sss_gss.8.xml:74 +msgid "" +"Some Kerberos deployments allow to associate authentication indicators with " +"a particular pre-authentication method used to obtain the ticket granting " +"ticket by the user. <command>pam_sss_gss.so</command> allows to enforce " +"presence of authentication indicators in the service tickets before a " +"particular PAM service can be accessed." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: pam_sss_gss.8.xml:82 +msgid "" +"If <option>pam_gssapi_indicators_map</option> is set in the [pam] or domain " +"section of sssd.conf, then SSSD will perform a check of the presence of any " +"configured indicators in the service ticket." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: pam_sss_gss.8.xml:93 +msgid "<option>debug</option>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: pam_sss_gss.8.xml:96 +msgid "Print debugging information." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: pam_sss_gss.8.xml:104 +msgid "Only the <option>auth</option> module type is provided." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: pam_sss_gss.8.xml:122 +msgid "" +"The user is not known to the authentication service or the GSSAPI " +"authentication is not supported." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: pam_sss_gss.8.xml:131 +msgid "Authentication failure." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: pam_sss_gss.8.xml:159 +msgid "" +"The main use case is to provide password-less authentication in sudo but " +"without the need to disable authentication completely. To achieve this, " +"first enable GSSAPI authentication for sudo in sssd.conf:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><programlisting> +#: pam_sss_gss.8.xml:165 +#, no-wrap +msgid "" +"[domain/MYDOMAIN]\n" +"pam_gssapi_services = sudo, sudo-i\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: pam_sss_gss.8.xml:169 +msgid "" +"And then enable the module in desired PAM stack (e.g. /etc/pam.d/sudo and " +"/etc/pam.d/sudo-i)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><programlisting> +#: pam_sss_gss.8.xml:173 +#, no-wrap +msgid "" +"...\n" +"auth sufficient pam_sss_gss.so\n" +"...\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: pam_sss_gss.8.xml:180 +msgid "TROUBLESHOOTING" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: pam_sss_gss.8.xml:182 +msgid "" +"SSSD logs, pam_sss_gss debug output and syslog may contain helpful " +"information about the error. Here are some common issues:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: pam_sss_gss.8.xml:186 +msgid "" +"1. I have KRB5CCNAME environment variable set and the authentication does " +"not work: Depending on your sudo version, it is possible that sudo does not " +"pass this variable to the PAM environment. Try adding KRB5CCNAME to " +"<option>env_keep</option> in /etc/sudoers or in your LDAP sudo rules default " +"options." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: pam_sss_gss.8.xml:193 +msgid "" +"2. Authentication does not work and syslog contains \"Server not found in " +"Kerberos database\": Kerberos is probably not able to resolve correct realm " +"for the service ticket based on the hostname. Try adding the hostname " +"directly to <option>[domain_realm]</option> in /etc/krb5.conf like so:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: pam_sss_gss.8.xml:200 +msgid "" +"3. Authentication does not work and syslog contains \"No Kerberos " +"credentials available\": You don't have any credentials that can be used to " +"obtain the required service ticket. Use kinit or authenticate over SSSD to " +"acquire those credentials." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: pam_sss_gss.8.xml:206 +msgid "" +"4. Authentication does not work and SSSD sssd-pam log contains \"User with " +"UPN [$UPN] was not found.\" or \"UPN [$UPN] does not match target user " +"[$username].\": You are using credentials that can not be mapped to the user " +"that is being authenticated. Try to use kswitch to select different " +"principal, make sure you authenticated with SSSD or consider disabling " +"<option>pam_gssapi_check_upn</option>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><programlisting> +#: pam_sss_gss.8.xml:214 +#, no-wrap +msgid "" +"[domain_realm]\n" +".myhostname = MYREALM\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refname> +#: sssd_krb5_locator_plugin.8.xml:10 sssd_krb5_locator_plugin.8.xml:15 +msgid "sssd_krb5_locator_plugin" +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refpurpose> +#: sssd_krb5_locator_plugin.8.xml:16 +msgid "Kerberos locator plugin" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_locator_plugin.8.xml:22 +msgid "" +"The Kerberos locator plugin <command>sssd_krb5_locator_plugin</command> is " +"used by libkrb5 to find KDCs for a given Kerberos realm. SSSD provides such " +"a plugin to guide all Kerberos clients on a system to a single KDC. In " +"general it should not matter to which KDC a client process is talking to. " +"But there are cases, e.g. after a password change, where not all KDCs are in " +"the same state because the new data has to be replicated first. To avoid " +"unexpected authentication failures and maybe even account lockings it would " +"be good to talk to a single KDC as long as possible." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_locator_plugin.8.xml:34 +msgid "" +"libkrb5 will search the locator plugin in the libkrb5 sub-directory of the " +"Kerberos plugin directory, see plugin_base_dir in <citerefentry> " +"<refentrytitle>krb5.conf</refentrytitle> <manvolnum>5</manvolnum> " +"</citerefentry> for details. The plugin can only be disabled by removing the " +"plugin file. There is no option in the Kerberos configuration to disable " +"it. But the SSSD_KRB5_LOCATOR_DISABLE environment variable can be used to " +"disable the plugin for individual commands. Alternatively the SSSD option " +"krb5_use_kdcinfo=False can be used to not generate the data needed by the " +"plugin. With this the plugin is still called but will provide no data to the " +"caller so that libkrb5 can fall back to other methods defined in krb5.conf." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_locator_plugin.8.xml:50 +msgid "" +"The plugin reads the information about the KDCs of a given realm from a file " +"called <filename>kdcinfo.REALM</filename>. The file should contain one or " +"more DNS names or IP addresses either in dotted-decimal IPv4 notation or the " +"hexadecimal IPv6 notation. An optional port number can be added to the end " +"separated with a colon, the IPv6 address has to be enclosed in squared " +"brackets in this case as usual. Valid entries are:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><itemizedlist><listitem><para> +#: sssd_krb5_locator_plugin.8.xml:58 +msgid "kdc.example.com" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><itemizedlist><listitem><para> +#: sssd_krb5_locator_plugin.8.xml:59 +msgid "kdc.example.com:321" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><itemizedlist><listitem><para> +#: sssd_krb5_locator_plugin.8.xml:60 +msgid "1.2.3.4" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><itemizedlist><listitem><para> +#: sssd_krb5_locator_plugin.8.xml:61 +msgid "5.6.7.8:99" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><itemizedlist><listitem><para> +#: sssd_krb5_locator_plugin.8.xml:62 +msgid "2001:db8:85a3::8a2e:370:7334" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><itemizedlist><listitem><para> +#: sssd_krb5_locator_plugin.8.xml:63 +msgid "[2001:db8:85a3::8a2e:370:7334]:321" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_locator_plugin.8.xml:65 +msgid "" +"SSSD's krb5 auth-provider which is used by the IPA and AD providers as well " +"adds the address of the current KDC or domain controller SSSD is using to " +"this file." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_locator_plugin.8.xml:70 +msgid "" +"In environments with read-only and read-write KDCs where clients are " +"expected to use the read-only instances for the general operations and only " +"the read-write KDC for config changes like password changes a " +"<filename>kpasswdinfo.REALM</filename> is used as well to identify " +"read-write KDCs. If this file exists for the given realm the content will be " +"used by the plugin to reply to requests for a kpasswd or kadmin server or " +"for the MIT Kerberos specific master KDC. If the address contains a port " +"number the default KDC port 88 will be used for the latter." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_locator_plugin.8.xml:85 +msgid "" +"Not all Kerberos implementations support the use of plugins. If " +"<command>sssd_krb5_locator_plugin</command> is not available on your system " +"you have to edit /etc/krb5.conf to reflect your Kerberos setup." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_locator_plugin.8.xml:91 +msgid "" +"If the environment variable SSSD_KRB5_LOCATOR_DEBUG is set to any value " +"debug messages will be sent to stderr." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_locator_plugin.8.xml:95 +msgid "" +"If the environment variable SSSD_KRB5_LOCATOR_DISABLE is set to any value " +"the plugin is disabled and will just return KRB5_PLUGIN_NO_HANDLE to the " +"caller." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_locator_plugin.8.xml:100 +msgid "" +"If the environment variable SSSD_KRB5_LOCATOR_IGNORE_DNS_FAILURES is set to " +"any value plugin will try to resolve all DNS names in kdcinfo file. By " +"default plugin returns KRB5_PLUGIN_NO_HANDLE to the caller immediately on " +"first DNS resolving failure." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_locator_plugin.8.xml:106 +msgid "" +"If the environment variable SSSD_KRB5_LOCATOR_KDC_ADDRESS is set to a KDC " +"address the plugin will use this address instead of reading the kdcinfo " +"file. The address format is the same as in the kdcinfo file (see above)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_locator_plugin.8.xml:112 +msgid "" +"If the environment variable SSSD_KRB5_LOCATOR_KPASSWD_ADDRESS is set to a " +"kpasswd server address the plugin will use this address instead of reading " +"the kpasswdinfo file. The address format is the same as in the kpasswdinfo " +"file (see above)." +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refname> +#: sssd-simple.5.xml:10 sssd-simple.5.xml:16 +msgid "sssd-simple" +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refpurpose> +#: sssd-simple.5.xml:17 +msgid "the configuration file for SSSD's 'simple' access-control provider" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-simple.5.xml:24 +msgid "" +"This manual page describes the configuration of the simple access-control " +"provider for <citerefentry> <refentrytitle>sssd</refentrytitle> " +"<manvolnum>8</manvolnum> </citerefentry>. For a detailed syntax reference, " +"refer to the <quote>FILE FORMAT</quote> section of the <citerefentry> " +"<refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</manvolnum> " +"</citerefentry> manual page." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-simple.5.xml:38 +msgid "" +"The simple access provider grants or denies access based on an access or " +"deny list of user or group names." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-simple.5.xml:42 +msgid "" +"Groups from other domains configured in sssd.conf, even if the simple access " +"provider is used there as well, and groups managed outside of SSSD are not " +"evaluated." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-simple.5.xml:47 +msgid "The following rules apply:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><itemizedlist><listitem><para> +#: sssd-simple.5.xml:51 +msgid "" +"It is not recommended to leave an option empty, it might cause errors. If " +"you want to allow all users, do not specify any `simple_allow_users` or " +"`simple_allow_groups`." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><itemizedlist><listitem><para> +#: sssd-simple.5.xml:58 +msgid "" +"If any list is provided, the order of evaluation is: allow → deny. This " +"means that any matching deny rule will supersede any matched allow rule." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><itemizedlist><listitem><para> +#: sssd-simple.5.xml:65 +msgid "" +"If either or both \"allow\" lists are provided, all users are denied unless " +"they appear in at least one of these lists (OR condition)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><itemizedlist><listitem><para> +#: sssd-simple.5.xml:72 +msgid "" +"If either or both \"deny\" lists are provided, all users are granted access " +"unless they appear in at least one of these lists (OR condition)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-simple.5.xml:91 +msgid "simple_allow_users (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-simple.5.xml:94 +msgid "" +"Comma-separated list of users who are allowed to log in. If this option is " +"specified, all other users are denied unless they are members of groups " +"listed in`simple_allow_groups`." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-simple.5.xml:103 +msgid "simple_deny_users (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-simple.5.xml:106 +msgid "" +"Comma-separated list of users who are explicitly denied access. If this " +"option is specified, these users will be denied regardless of whether they " +"appear in `simple_allow_users` or `simple_allow_groups`." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-simple.5.xml:112 +msgid "" +"OR Logic Applies: A user will be denied access if they are listed in " +"`simple_deny_users` or if they are a member of a group in " +"`simple_deny_groups`." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-simple.5.xml:120 +msgid "simple_allow_groups (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-simple.5.xml:123 +msgid "" +"Comma-separated list of groups that are allowed to log in. If this option is " +"specified, all other users are denied unless they are explicitly listed in " +"`simple_allow_users`." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-simple.5.xml:129 +msgid "" +"OR Logic Applies: A user can log in if they are listed in " +"`simple_allow_users` or if they belong to a group in `simple_allow_groups`." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-simple.5.xml:134 sssd-simple.5.xml:154 +msgid "" +"This applies only to groups within this SSSD domain. Local groups are not " +"evaluated." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-simple.5.xml:141 +msgid "simple_deny_groups (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-simple.5.xml:144 +msgid "" +"Comma-separated list of groups that are explicitly denied access. This " +"applies only to groups within this SSSD domain. Local groups are not " +"evaluated." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-simple.5.xml:149 +msgid "" +"OR Logic Applies: A user will be denied access if they are listed in " +"`simple_deny_users` or if they are a member of any group in " +"`simple_deny_groups`." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-simple.5.xml:83 sssd-ipa.5.xml:83 sssd-ad.5.xml:131 sssd-idp.5.xml:55 +msgid "" +"Refer to the section <quote>DOMAIN SECTIONS</quote> of the <citerefentry> " +"<refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</manvolnum> " +"</citerefentry> manual page for details on the configuration of an SSSD " +"domain. <placeholder type=\"variablelist\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-simple.5.xml:162 +msgid "" +"Specifying no values for any of the lists is equivalent to skipping it " +"entirely. Beware of this while generating parameters for the simple provider " +"using automated scripts." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-simple.5.xml:171 +msgid "" +"The following example assumes that SSSD is correctly configured and " +"example.com is one of the domains in the <replaceable>[sssd]</replaceable> " +"section. This example shows only the simple access provider-specific " +"options." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><programlisting> +#: sssd-simple.5.xml:178 +#, no-wrap +msgid "" +"[domain/example.com]\n" +"access_provider = simple\n" +"simple_allow_users = user1, user2\n" +"simple_deny_users = user3, user4\n" +"simple_allow_groups = allowed_group1\n" +"simple_deny_groups = denied_group1\n" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-simple.5.xml:191 +msgid "" +"The complete group membership hierarchy is resolved before the access check, " +"thus even nested groups can be included in the access lists. Please be " +"aware that the <quote>ldap_group_nesting_level</quote> option may impact the " +"results and should be set to a sufficient value. (<citerefentry> " +"<refentrytitle>sssd-ldap</refentrytitle><manvolnum>5</manvolnum> " +"</citerefentry>) option." +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refname> +#: sss-certmap.5.xml:10 sss-certmap.5.xml:16 +msgid "sss-certmap" +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refpurpose> +#: sss-certmap.5.xml:17 +msgid "SSSD Certificate Matching and Mapping Rules" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sss-certmap.5.xml:23 +msgid "" +"The manual page describes the rules which can be used by SSSD and other " +"components to match X.509 certificates and map them to accounts." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sss-certmap.5.xml:28 +msgid "" +"Each rule has four components, a <quote>priority</quote>, a <quote>matching " +"rule</quote>, a <quote>mapping rule</quote> and a <quote>domain " +"list</quote>. All components are optional. A missing <quote>priority</quote> " +"will add the rule with the lowest priority. The default <quote>matching " +"rule</quote> will match certificates with the digitalSignature key usage and " +"clientAuth extended key usage. If the <quote>mapping rule</quote> is empty " +"the certificates will be searched in the userCertificate attribute as DER " +"encoded binary. If no domains are given only the local domain will be " +"searched." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sss-certmap.5.xml:39 +msgid "" +"To allow extensions or completely different style of rule the " +"<quote>mapping</quote> and <quote>matching rules</quote> can contain a " +"prefix separated with a ':' from the main part of the rule. The prefix may " +"only contain upper-case ASCII letters and numbers. If the prefix is omitted " +"the default type will be used which is 'KRB5' for the matching rules and " +"'LDAP' for the mapping rules." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sss-certmap.5.xml:48 +msgid "" +"The 'sssctl' utility provides the 'cert-eval-rule' command to check if a " +"given certificate matches a matching rules and how the output of a mapping " +"rule would look like." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sss-certmap.5.xml:55 +msgid "RULE COMPONENTS" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><title> +#: sss-certmap.5.xml:57 +msgid "PRIORITY" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sss-certmap.5.xml:59 +msgid "" +"The rules are processed by priority while the number '0' (zero) indicates " +"the highest priority. The higher the number the lower is the priority. A " +"missing value indicates the lowest priority. The rules processing is stopped " +"when a matched rule is found and no further rules are checked." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sss-certmap.5.xml:66 +msgid "" +"Internally the priority is treated as unsigned 32bit integer, using a " +"priority value larger than 4294967295 will cause an error." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sss-certmap.5.xml:70 +msgid "" +"If multiple rules have the same priority and only one of the related " +"matching rules applies, this rule will be chosen. If there are multiple " +"rules with the same priority which matches, one is chosen but which one is " +"undefined. To avoid this undefined behavior either use different priorities " +"or make the matching rules more specific e.g. by using distinct " +"<ISSUER> patterns." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><title> +#: sss-certmap.5.xml:79 +msgid "MATCHING RULE" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sss-certmap.5.xml:81 +msgid "" +"The matching rule is used to select a certificate to which the mapping rule " +"should be applied. It uses a system similar to the one used by " +"<quote>pkinit_cert_match</quote> option of MIT Kerberos. It consists of a " +"keyword enclosed by '<' and '>' which identified a certain part of the " +"certificate and a pattern which should be found for the rule to " +"match. Multiple keyword pattern pairs can be either joined with '&&' " +"(and) or '||' (or)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sss-certmap.5.xml:90 +msgid "" +"Given the similarity to MIT Kerberos the type prefix for this rule is " +"'KRB5'. But 'KRB5' will also be the default for <quote>matching " +"rules</quote> so that \"<SUBJECT>.*,DC=MY,DC=DOMAIN\" and " +"\"KRB5:<SUBJECT>.*,DC=MY,DC=DOMAIN\" are equivalent." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sss-certmap.5.xml:99 +msgid "<SUBJECT>regular-expression" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:102 +msgid "" +"With this a part or the whole subject name of the certificate can be " +"matched. For the matching POSIX Extended Regular Expression syntax is used, " +"see regex(7) for details." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:108 +msgid "" +"For the matching the subject name stored in the certificate in DER encoded " +"ASN.1 is converted into a string according to RFC 4514. This means the most " +"specific name component comes first. Please note that not all possible " +"attribute names are covered by RFC 4514. The names included are 'CN', 'L', " +"'ST', 'O', 'OU', 'C', 'STREET', 'DC' and 'UID'. Other attribute names might " +"be shown differently on different platform and by different tools. To avoid " +"confusion those attribute names are best not used or covered by a suitable " +"regular-expression." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:121 +msgid "Example: <SUBJECT>.*,DC=MY,DC=DOMAIN" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:124 +msgid "" +"Please note that the characters \"^.[$()|*+?{\\\" have a special meaning in " +"regular expressions and must be escaped with the help of the '\\' character " +"so that they are matched as ordinary characters." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:130 +msgid "Example: <SUBJECT>^CN=.* \\(Admin\\),DC=MY,DC=DOMAIN$" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sss-certmap.5.xml:135 +msgid "<ISSUER>regular-expression" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:138 +msgid "" +"With this a part or the whole issuer name of the certificate can be " +"matched. All comments for <SUBJECT> apply her as well." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:143 +msgid "Example: <ISSUER>^CN=My-CA,DC=MY,DC=DOMAIN$" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sss-certmap.5.xml:148 +msgid "<KU>key-usage" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:151 +msgid "" +"This option can be used to specify which key usage values the certificate " +"should have. The following values can be used in a comma separated list:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sss-certmap.5.xml:155 +msgid "digitalSignature" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sss-certmap.5.xml:156 +msgid "nonRepudiation" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sss-certmap.5.xml:157 +msgid "keyEncipherment" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sss-certmap.5.xml:158 +msgid "dataEncipherment" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sss-certmap.5.xml:159 +msgid "keyAgreement" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sss-certmap.5.xml:160 +msgid "keyCertSign" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sss-certmap.5.xml:161 +msgid "cRLSign" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sss-certmap.5.xml:162 +msgid "encipherOnly" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sss-certmap.5.xml:163 +msgid "decipherOnly" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:167 +msgid "" +"A numerical value in the range of a 32bit unsigned integer can be used as " +"well to cover special use cases." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:171 +msgid "Example: <KU>digitalSignature,keyEncipherment" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sss-certmap.5.xml:176 +msgid "<EKU>extended-key-usage" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:179 +msgid "" +"This option can be used to specify which extended key usage the certificate " +"should have. The following value can be used in a comma separated list:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sss-certmap.5.xml:183 +msgid "serverAuth" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sss-certmap.5.xml:184 +msgid "clientAuth" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sss-certmap.5.xml:185 +msgid "codeSigning" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sss-certmap.5.xml:186 +msgid "emailProtection" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sss-certmap.5.xml:187 +msgid "timeStamping" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sss-certmap.5.xml:188 +msgid "OCSPSigning" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sss-certmap.5.xml:189 +msgid "KPClientAuth" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sss-certmap.5.xml:190 +msgid "pkinit" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sss-certmap.5.xml:191 +msgid "msScLogin" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:195 +msgid "" +"Extended key usages which are not listed above can be specified with their " +"OID in dotted-decimal notation." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:199 +msgid "Example: <EKU>clientAuth,1.3.6.1.5.2.3.4" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sss-certmap.5.xml:204 +msgid "<SAN>regular-expression" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:207 +msgid "" +"To be compatible with the usage of MIT Kerberos this option will match the " +"Kerberos principals in the PKINIT or AD NT Principal SAN as " +"<SAN:Principal> does." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:212 +msgid "Example: <SAN>.*@MY\\.REALM" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sss-certmap.5.xml:217 +msgid "<SAN:Principal>regular-expression" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:220 +msgid "Match the Kerberos principals in the PKINIT or AD NT Principal SAN." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:224 +msgid "Example: <SAN:Principal>.*@MY\\.REALM" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sss-certmap.5.xml:229 +msgid "<SAN:ntPrincipalName>regular-expression" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:232 +msgid "Match the Kerberos principals from the AD NT Principal SAN." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:236 +msgid "Example: <SAN:ntPrincipalName>.*@MY.AD.REALM" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sss-certmap.5.xml:241 +msgid "<SAN:pkinit>regular-expression" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:244 +msgid "Match the Kerberos principals from the PKINIT SAN." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:247 +msgid "Example: <SAN:ntPrincipalName>.*@MY\\.PKINIT\\.REALM" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sss-certmap.5.xml:252 +msgid "<SAN:dotted-decimal-oid>regular-expression" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:255 +msgid "" +"Take the value of the otherName SAN component given by the OID in " +"dotted-decimal notation, interpret it as string and try to match it against " +"the regular expression." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:261 +msgid "Example: <SAN:1.2.3.4>test" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sss-certmap.5.xml:266 +msgid "<SAN:otherName>base64-string" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:269 +msgid "" +"Do a binary match with the base64 encoded blob against all otherName SAN " +"components. With this option it is possible to match against custom " +"otherName components with special encodings which could not be treated as " +"strings." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:276 +msgid "Example: <SAN:otherName>MTIz" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sss-certmap.5.xml:281 +msgid "<SAN:rfc822Name>regular-expression" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:284 +msgid "Match the value of the rfc822Name SAN." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:287 +msgid "Example: <SAN:rfc822Name>.*@email\\.domain" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sss-certmap.5.xml:292 +msgid "<SAN:dNSName>regular-expression" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:295 +msgid "Match the value of the dNSName SAN." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:298 +msgid "Example: <SAN:dNSName>.*\\.my\\.dns\\.domain" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sss-certmap.5.xml:303 +msgid "<SAN:x400Address>base64-string" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:306 +msgid "Binary match the value of the x400Address SAN." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:309 +msgid "Example: <SAN:x400Address>MTIz" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sss-certmap.5.xml:314 +msgid "<SAN:directoryName>regular-expression" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:317 +msgid "" +"Match the value of the directoryName SAN. The same comments as given for " +"<ISSUER> and <SUBJECT> apply here as well." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:322 +msgid "Example: <SAN:directoryName>.*,DC=com" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sss-certmap.5.xml:327 +msgid "<SAN:ediPartyName>base64-string" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:330 +msgid "Binary match the value of the ediPartyName SAN." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:333 +msgid "Example: <SAN:ediPartyName>MTIz" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sss-certmap.5.xml:338 +msgid "<SAN:uniformResourceIdentifier>regular-expression" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:341 +msgid "Match the value of the uniformResourceIdentifier SAN." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:344 +msgid "Example: <SAN:uniformResourceIdentifier>URN:.*" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sss-certmap.5.xml:349 +msgid "<SAN:iPAddress>regular-expression" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:352 +msgid "Match the value of the iPAddress SAN." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:355 +msgid "Example: <SAN:iPAddress>192\\.168\\..*" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sss-certmap.5.xml:360 +msgid "<SAN:registeredID>regular-expression" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:363 +msgid "Match the value of the registeredID SAN as dotted-decimal string." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:367 +msgid "Example: <SAN:registeredID>1\\.2\\.3\\..*" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sss-certmap.5.xml:96 +msgid "The available options are: <placeholder type=\"variablelist\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><title> +#: sss-certmap.5.xml:375 +msgid "MAPPING RULE" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sss-certmap.5.xml:377 +msgid "" +"The mapping rule is used to associate a certificate with one or more " +"accounts. A Smartcard with the certificate and the matching private key can " +"then be used to authenticate as one of those accounts." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sss-certmap.5.xml:382 +msgid "" +"Currently SSSD basically only supports LDAP to lookup user information (the " +"exception is the proxy provider which is not of relevance here). Because of " +"this the mapping rule is based on LDAP search filter syntax with templates " +"to add certificate content to the filter. It is expected that the filter " +"will only contain the specific data needed for the mapping and that the " +"caller will embed it in another filter to do the actual search. Because of " +"this the filter string should start and stop with '(' and ')' respectively." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sss-certmap.5.xml:392 +msgid "" +"In general it is recommended to use attributes from the certificate and add " +"them to special attributes to the LDAP user object. E.g. the " +"'altSecurityIdentities' attribute in AD or the 'ipaCertMapData' attribute " +"for IPA can be used." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sss-certmap.5.xml:398 +msgid "" +"This should be preferred to read user specific data from the certificate " +"like e.g. an email address and search for it in the LDAP server. The reason " +"is that the user specific data in LDAP might change for various reasons " +"would break the mapping. On the other hand it would be hard to break the " +"mapping on purpose for a specific user." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sss-certmap.5.xml:406 +msgid "" +"The default <quote>mapping rule</quote> type is 'LDAP' which can be added as " +"a prefix to a rule like e.g. " +"'LDAP:(userCertificate;binary={cert!bin})'. There is an extension called " +"'LDAPU1' which offer more templates for more flexibility. To allow older " +"versions of this library to ignore the extension the prefix 'LDAPU1' must be " +"used when using the new templates in a <quote>mapping rule</quote> otherwise " +"the old version of this library will fail with a parsing error. The new " +"templates are described in section <xref linkend=\"map_ldapu1\"/>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sss-certmap.5.xml:424 +msgid "{issuer_dn[!((ad|ad_x500)|ad_ldap|nss_x500|(nss|nss_ldap))]}" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:427 +msgid "" +"This template will add the full issuer DN converted to a string according to " +"RFC 4514. If X.500 ordering (most specific RDN comes last) an option with " +"the '_x500' prefix should be used." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:433 sss-certmap.5.xml:459 +msgid "" +"The conversion options starting with 'ad_' will use attribute names as used " +"by AD, e.g. 'S' instead of 'ST'." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:437 sss-certmap.5.xml:463 +msgid "" +"The conversion options starting with 'nss_' will use attribute names as used " +"by NSS." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:441 sss-certmap.5.xml:467 +msgid "" +"The default conversion option is 'nss', i.e. attribute names according to " +"NSS and LDAP/RFC 4514 ordering." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:445 +msgid "" +"Example: " +"(ipacertmapdata=X509:<I>{issuer_dn!ad}<S>{subject_dn!ad})" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sss-certmap.5.xml:450 +msgid "{subject_dn[!((ad|ad_x500)|ad_ldap|nss_x500|(nss|nss_ldap))]}" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:453 +msgid "" +"This template will add the full subject DN converted to string according to " +"RFC 4514. If X.500 ordering (most specific RDN comes last) an option with " +"the '_x500' prefix should be used." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:471 +msgid "" +"Example: " +"(ipacertmapdata=X509:<I>{issuer_dn!nss_x500}<S>{subject_dn!nss_x500})" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sss-certmap.5.xml:476 +msgid "{cert[!(bin|base64)]}" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:479 +msgid "" +"This template will add the whole DER encoded certificate as a string to the " +"search filter. Depending on the conversion option the binary certificate is " +"either converted to an escaped hex sequence '\\xx' or base64. The escaped " +"hex sequence is the default and can e.g. be used with the LDAP attribute " +"'userCertificate;binary'." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:487 +msgid "Example: (userCertificate;binary={cert!bin})" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sss-certmap.5.xml:492 +msgid "{subject_principal[.short_name]}" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:495 +msgid "" +"This template will add the Kerberos principal which is taken either from the " +"SAN used by pkinit or the one used by AD. The 'short_name' component " +"represents the first part of the principal before the '@' sign." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:501 +msgid "" +"Example: " +"(|(userPrincipal={subject_principal})(samAccountName={subject_principal.short_name}))" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sss-certmap.5.xml:506 +msgid "{subject_pkinit_principal[.short_name]}" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:509 +msgid "" +"This template will add the Kerberos principal which is given by the SAN used " +"by pkinit. The 'short_name' component represents the first part of the " +"principal before the '@' sign." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:515 +msgid "" +"Example: " +"(|(userPrincipal={subject_pkinit_principal})(uid={subject_pkinit_principal.short_name}))" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sss-certmap.5.xml:520 +msgid "{subject_nt_principal[.short_name]}" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:523 +msgid "" +"This template will add the Kerberos principal which is given by the SAN used " +"by AD. The 'short_name' component represent the first part of the principal " +"before the '@' sign." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:529 +msgid "" +"Example: " +"(|(userPrincipalName={subject_nt_principal})(samAccountName={subject_nt_principal.short_name}))" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sss-certmap.5.xml:534 +msgid "{subject_rfc822_name[.short_name]}" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:537 +msgid "" +"This template will add the string which is stored in the rfc822Name " +"component of the SAN, typically an email address. The 'short_name' component " +"represents the first part of the address before the '@' sign." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:543 +msgid "" +"Example: " +"(|(mail={subject_rfc822_name})(uid={subject_rfc822_name.short_name}))" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sss-certmap.5.xml:548 +msgid "{subject_dns_name[.short_name]}" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:551 +msgid "" +"This template will add the string which is stored in the dNSName component " +"of the SAN, typically a fully-qualified host name. The 'short_name' " +"component represents the first part of the name before the first '.' sign." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:557 +msgid "Example: (|(fqdn={subject_dns_name})(host={subject_dns_name.short_name}))" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sss-certmap.5.xml:562 +msgid "{subject_uri}" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:565 +msgid "" +"This template will add the string which is stored in the " +"uniformResourceIdentifier component of the SAN." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:569 +msgid "Example: (uri={subject_uri})" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sss-certmap.5.xml:574 +msgid "{subject_ip_address}" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:577 +msgid "" +"This template will add the string which is stored in the iPAddress component " +"of the SAN." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:581 +msgid "Example: (ip={subject_ip_address})" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sss-certmap.5.xml:586 +msgid "{subject_x400_address}" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:589 +msgid "" +"This template will add the value which is stored in the x400Address " +"component of the SAN as escaped hex sequence." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:594 +msgid "Example: (attr:binary={subject_x400_address})" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sss-certmap.5.xml:599 +msgid "{subject_directory_name[!((ad|ad_x500)|ad_ldap|nss_x500|(nss|nss_ldap))]}" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:602 +msgid "" +"This template will add the DN string of the value which is stored in the " +"directoryName component of the SAN." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:606 +msgid "Example: (orig_dn={subject_directory_name})" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sss-certmap.5.xml:611 +msgid "{subject_ediparty_name}" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:614 +msgid "" +"This template will add the value which is stored in the ediPartyName " +"component of the SAN as escaped hex sequence." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:619 +msgid "Example: (attr:binary={subject_ediparty_name})" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sss-certmap.5.xml:624 +msgid "{subject_registered_id}" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:627 +msgid "" +"This template will add the OID which is stored in the registeredID component " +"of the SAN as a dotted-decimal string." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:632 +msgid "Example: (oid={subject_registered_id})" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sss-certmap.5.xml:417 +msgid "" +"The templates to add certificate data to the search filter are based on " +"Python-style formatting strings. They consist of a keyword in curly braces " +"with an optional sub-component specifier separated by a '.' or an optional " +"conversion/formatting option separated by a '!'. Allowed values are: " +"<placeholder type=\"variablelist\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><title> +#: sss-certmap.5.xml:639 +msgid "LDAPU1 extension" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para> +#: sss-certmap.5.xml:641 +msgid "The following templates are available when using the 'LDAPU1' extension:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><term> +#: sss-certmap.5.xml:647 +msgid "{serial_number[!(dec|hex[_ucr])]}" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:650 +msgid "" +"This template will add the serial number of the certificate. By default it " +"will be printed as a hexadecimal number with lower-case letters." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:655 +msgid "" +"With the formatting option '!dec' the number will be printed as decimal " +"string. The hexadecimal output can be printed with upper-case letters " +"('!hex_u'), with a colon separating the hexadecimal bytes ('!hex_c') or with " +"the hexadecimal bytes in reverse order ('!hex_r'). The postfix letters can " +"be combined so that e.g. '!hex_uc' will produce a colon-separated " +"hexadecimal string with upper-case letters." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:665 +msgid "Example: LDAPU1:(serial={serial_number})" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><term> +#: sss-certmap.5.xml:671 +msgid "{subject_key_id[!hex[_ucr]]}" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:674 +msgid "" +"This template will add the subject key id of the certificate. By default it " +"will be printed as a hexadecimal number with lower-case letters." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:679 +msgid "" +"The hexadecimal output can be printed with upper-case letters ('!hex_u'), " +"with a colon separating the hexadecimal bytes ('!hex_c') or with the " +"hexadecimal bytes in reverse order ('!hex_r'). The postfix letters can be " +"combined so that e.g. '!hex_uc' will produce a colon-separated hexadecimal " +"string with upper-case letters." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:688 +msgid "Example: LDAPU1:(ski={subject_key_id})" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><term> +#: sss-certmap.5.xml:694 +msgid "{cert[!DIGEST[_ucr]]}" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:697 +msgid "" +"This template will add the hexadecimal digest/hash of the certificate where " +"DIGEST must be replaced with the name of a digest/hash function supported by " +"OpenSSL, e.g. 'sha512'." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:703 +msgid "" +"The hexadecimal output can be printed with upper-case letters ('!sha512_u'), " +"with a colon separating the hexadecimal bytes ('!sha512_c') or with the " +"hexadecimal bytes in reverse order ('!sha512_r'). The postfix letters can be " +"combined so that e.g. '!sha512_uc' will produce a colon-separated " +"hexadecimal string with upper-case letters." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:712 +msgid "Example: LDAPU1:(dgst={cert!sha256})" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><term> +#: sss-certmap.5.xml:718 +msgid "{subject_dn_component[(.attr_name|[number]]}" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:721 +msgid "" +"This template will add an attribute value of a component of the subject DN, " +"by default the value of the most specific component." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:726 +msgid "" +"A different component can be selected by either attribute name, " +"e.g. {subject_dn_component.uid} or by position, " +"e.g. {subject_dn_component.[2]} where positive numbers start counting from " +"the most specific component and negative numbers start counting from the " +"least specific component. Attribute name and the position can be combined as " +"e.g. {subject_dn_component.uid[2]} which means that the name of the second " +"component must be 'uid'." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:737 +msgid "Example: LDAPU1:(uid={subject_dn_component.uid})" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><term> +#: sss-certmap.5.xml:743 +msgid "{issuer_dn_component[(.attr_name|[number]]}" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:746 +msgid "" +"This template will add an attribute value of a component of the issuer DN, " +"by default the value of the most specific component." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:751 +msgid "" +"See 'subject_dn_component' for details about the attribute name and position " +"specifiers." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:755 +msgid "" +"Example: " +"LDAPU1:(domain={issuer_dn_component.[-2]}.{issuer_dn_component.dc[-1]})" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><term> +#: sss-certmap.5.xml:760 +msgid "{sid[.rid]}" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:763 +msgid "" +"This template will add the SID if the corresponding extension introduced by " +"Microsoft with the OID 1.3.6.1.4.1.311.25.2 is available. With the '.rid' " +"selector only the last component, i.e. the RID, will be added." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:770 +msgid "Example: LDAPU1:(objectsid={sid})" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><title> +#: sss-certmap.5.xml:779 +msgid "DOMAIN LIST" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sss-certmap.5.xml:781 +msgid "" +"If the domain list is not empty users mapped to a given certificate are not " +"only searched in the local domain but in the listed domains as well as long " +"as they are know by SSSD. Domains not know to SSSD will be ignored." +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refname> +#: sssd-ipa.5.xml:10 sssd-ipa.5.xml:16 +msgid "sssd-ipa" +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refpurpose> +#: sssd-ipa.5.xml:17 +msgid "SSSD IPA provider" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-ipa.5.xml:23 +msgid "" +"This manual page describes the configuration of the IPA provider for " +"<citerefentry> <refentrytitle>sssd</refentrytitle> <manvolnum>8</manvolnum> " +"</citerefentry>. For a detailed syntax reference, refer to the <quote>FILE " +"FORMAT</quote> section of the <citerefentry> " +"<refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</manvolnum> " +"</citerefentry> manual page." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-ipa.5.xml:36 +msgid "" +"The IPA provider is a back end used to connect to an IPA server. (Refer to " +"the freeipa.org web site for information about IPA servers.) This provider " +"requires that the machine be joined to the IPA domain; configuration is " +"almost entirely self-discovered and obtained directly from the server." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-ipa.5.xml:43 +msgid "" +"The IPA provider enables SSSD to use the <citerefentry> " +"<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> " +"</citerefentry> identity provider and the <citerefentry> " +"<refentrytitle>sssd-krb5</refentrytitle> <manvolnum>5</manvolnum> " +"</citerefentry> authentication provider with optimizations for IPA " +"environments. The IPA provider accepts the same options used by the " +"sssd-ldap and sssd-krb5 providers with some exceptions. However, it is " +"neither necessary nor recommended to set these options." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-ipa.5.xml:57 +msgid "" +"The IPA provider primarily copies the traditional ldap and krb5 provider " +"default options with some exceptions, the differences are listed in the " +"<quote>MODIFIED DEFAULT OPTIONS</quote> section." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-ipa.5.xml:62 +msgid "" +"As an access provider, the IPA provider has a minimal configuration (see " +"<quote>ipa_access_order</quote>) as it mainly uses HBAC (host-based access " +"control) rules. Please refer to freeipa.org for more information about HBAC." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-ipa.5.xml:68 +msgid "" +"If <quote>auth_provider=ipa</quote> or <quote>access_provider=ipa</quote> is " +"configured in sssd.conf then the id_provider must also be set to " +"<quote>ipa</quote>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-ipa.5.xml:74 +msgid "" +"The IPA provider will use the PAC responder if the Kerberos tickets of users " +"from trusted realms contain a PAC. To make configuration easier the PAC " +"responder is started automatically if the IPA ID provider is configured." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ipa.5.xml:90 +msgid "ipa_domain (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:93 +msgid "" +"Specifies the name of the IPA domain. This is optional. If not provided, " +"the configuration domain name is used." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ipa.5.xml:101 +msgid "ipa_server, ipa_backup_server (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:104 +msgid "" +"The comma-separated list of IP addresses or hostnames of the IPA servers to " +"which SSSD should connect in the order of preference. For more information " +"on failover and server redundancy, see the <quote>FAILOVER</quote> section. " +"This is optional if autodiscovery is enabled. For more information on " +"service discovery, refer to the <quote>SERVICE DISCOVERY</quote> section." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ipa.5.xml:117 +msgid "ipa_hostname (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:120 +msgid "" +"Optional. May be set on machines where the hostname(5) does not reflect the " +"fully qualified name used in the IPA domain to identify this host. The " +"hostname must be fully qualified." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ipa.5.xml:129 sssd-ad.5.xml:1166 +msgid "dyndns_update (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:132 +msgid "" +"Optional. This option tells SSSD to automatically update the DNS server " +"built into FreeIPA with the IP address of this client. The update is secured " +"using GSS-TSIG. The IP address of the IPA LDAP connection is used for the " +"updates, if it is not otherwise specified by using the " +"<quote>dyndns_iface</quote> option." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ipa.5.xml:147 sssd-ad.5.xml:1186 +msgid "dyndns_ttl (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:150 sssd-ad.5.xml:1189 +msgid "" +"The TTL to apply to the client DNS record when updating it. If " +"dyndns_update is false this has no effect. This will override the TTL " +"serverside if set by an administrator." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:155 +msgid "Default: 1200 (seconds)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ipa.5.xml:161 sssd-ad.5.xml:1200 +msgid "dyndns_iface (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:164 sssd-ad.5.xml:1203 +msgid "" +"Optional. Applicable only when dyndns_update is true. Choose the interface " +"or a list of interfaces whose IP addresses should be used for dynamic DNS " +"updates. The name of interface can be a wildcard pattern prefixed with " +"<emphasis>!</emphasis> for interface excluding. First match stops the " +"evaluation. For example list <emphasis>!eth1, *</emphasis> instruct SSSD to " +"use all interfaces except <emphasis>eth1</emphasis>. See <emphasis>man 7 " +"glob</emphasis> for details about patterns." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:177 +msgid "" +"Default: Use the IP addresses of the interface which is used for IPA LDAP " +"connection" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:181 sssd-ad.5.xml:1220 +msgid "Example: dyndns_iface = em[12], !vnet1, vnet*" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ipa.5.xml:187 sssd-ad.5.xml:1226 +msgid "dyndns_address (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:190 sssd-ad.5.xml:1229 +msgid "" +"Optional. Applicable only when <emphasis>dyndns_update</emphasis> is true. " +"A list of IP addresses or IP networks to be used for dynamic DNS " +"updates. Network addresses must be in CIDR format. An entry can be prefixed " +"with <emphasis>!</emphasis> to indicate exclusion. The <emphasis>best " +"match</emphasis> is used to determine whether an address is included or " +"excluded (i.e., a longer prefix takes precedence)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:201 sssd-ad.5.xml:1240 +msgid "Default: No filtering of IP addresses." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:204 sssd-ad.5.xml:1243 +msgid "Example: dyndns_address = 10.0.0.0/16, !10.0.1.0/24" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ipa.5.xml:210 sssd-ad.5.xml:1298 +msgid "dyndns_auth (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:213 sssd-ad.5.xml:1301 +msgid "" +"Whether the nsupdate utility should use GSS-TSIG authentication for secure " +"updates with the DNS server, insecure updates can be sent by setting this " +"option to 'none'." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:219 sssd-ad.5.xml:1307 +msgid "Default: GSS-TSIG" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ipa.5.xml:225 sssd-ad.5.xml:1313 +msgid "dyndns_auth_ptr (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:228 sssd-ad.5.xml:1316 +msgid "" +"Whether the nsupdate utility should use GSS-TSIG authentication for secure " +"PTR updates with the DNS server, insecure updates can be sent by setting " +"this option to 'none'." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:234 sssd-ad.5.xml:1322 +msgid "Default: Same as dyndns_auth" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ipa.5.xml:240 sssd-ad.5.xml:1249 +msgid "dyndns_refresh_interval (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:243 +msgid "" +"How often should the back end perform periodic DNS update in addition to the " +"automatic update performed when the back end goes online. This option is " +"optional and applicable only when dyndns_update is true." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ipa.5.xml:256 sssd-ad.5.xml:1266 +msgid "dyndns_update_ptr (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:259 sssd-ad.5.xml:1269 +msgid "" +"Whether the PTR record should also be explicitly updated when updating the " +"client's DNS records. Applicable only when dyndns_update is true." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:264 +msgid "" +"This option should be False in most IPA deployments as the IPA server " +"generates the PTR records automatically when forward records are changed." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:270 sssd-ad.5.xml:1274 +msgid "" +"Note that <emphasis>dyndns_update_per_family</emphasis> parameter does not " +"apply for PTR record updates. Those updates are always sent separately." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:275 +msgid "Default: False (disabled)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ipa.5.xml:281 sssd-ad.5.xml:1285 +msgid "dyndns_force_tcp (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:284 sssd-ad.5.xml:1288 +msgid "" +"Whether the nsupdate utility should default to using TCP for communicating " +"with the DNS server." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:288 sssd-ad.5.xml:1292 +msgid "Default: False (let nsupdate choose the protocol)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ipa.5.xml:294 sssd-ad.5.xml:1328 +msgid "dyndns_server (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:297 sssd-ad.5.xml:1331 +msgid "" +"The DNS server to use when performing a DNS update. In most setups, it's " +"recommended to leave this option unset." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:302 sssd-ad.5.xml:1336 +msgid "" +"Setting this option makes sense for environments where the DNS server is " +"different from the identity server or when we use encrypted DNS." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:307 sssd-ad.5.xml:1341 +msgid "" +"The parameter can be a simple string containing DNS name or IP address. It " +"can also be an URI. The URI can look like " +"<emphasis>dns://servername/</emphasis> or " +"<emphasis>dns+tls://1.2.3.4:853#servername/</emphasis>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:314 sssd-ad.5.xml:1348 +msgid "" +"The second example enables DNS-over-TLS protocol for DNS updates. The " +"nsupdate utility must support DoT - check the <emphasis>man " +"nsupdate</emphasis> before enabling it in SSSD." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:320 sssd-ad.5.xml:1354 +msgid "" +"Please note that this option will be only used in fallback attempt when " +"previous attempt using autodetected settings failed or when DNS-over-TLS is " +"enabled." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:326 sssd-ad.5.xml:1360 +msgid "Default: None (let nsupdate choose the server)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ipa.5.xml:332 sssd-ad.5.xml:1366 +msgid "dyndns_update_per_family (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:335 sssd-ad.5.xml:1369 +msgid "" +"DNS update is by default performed in two steps - IPv4 update and then IPv6 " +"update. In some cases it might be desirable to perform IPv4 and IPv6 update " +"in single step." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ipa.5.xml:347 sssd-ad.5.xml:1381 +msgid "dyndns_dot_cacert (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:350 sssd-ad.5.xml:1384 +msgid "" +"This option specifies the file of the certificate authorities certificates " +"(in PEM format) in order to verify the remote server TLS certificate when " +"using DoT." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:356 sssd-ad.5.xml:1390 +msgid "Default: None (use global certificate store)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ipa.5.xml:362 sssd-ad.5.xml:1396 +msgid "dyndns_dot_cert (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:365 sssd-ad.5.xml:1399 +msgid "" +"This option sets the certificate(s) file for authentication for the DoT " +"transport to the remote server. The certificate chain file is expected to be " +"in PEM format." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:371 sssd-ad.5.xml:1405 +msgid "" +"The <emphasis>dyndns_dot_cert</emphasis> and " +"<emphasis>dyndns_dot_key</emphasis> options must be both set to achieve " +"mutual TLS authentication." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:376 sssd-ipa.5.xml:391 sssd-ad.5.xml:1410 sssd-ad.5.xml:1425 +msgid "Default: None (Do not use TLS authentication)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ipa.5.xml:382 sssd-ad.5.xml:1416 +msgid "dyndns_dot_key (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:385 sssd-ad.5.xml:1419 +msgid "" +"This option sets the key file for authenticated encryption for the DoT " +"transport to the remote server. The private key file is expected to be in " +"PEM format." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ipa.5.xml:397 +msgid "ipa_access_order (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:404 +msgid "<emphasis>expire</emphasis>: use IPA's account expiration policy." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:443 +msgid "" +"Please note that 'access_provider = ipa' must be set for this feature to " +"work." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ipa.5.xml:450 +msgid "ipa_deskprofile_search_base (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:453 +msgid "" +"Optional. Use the given string as search base for Desktop Profile related " +"objects." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:457 sssd-ipa.5.xml:479 +msgid "Default: Use base DN" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ipa.5.xml:463 +msgid "ipa_subid_ranges_search_base (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:466 +msgid "Deprecated. Use ldap_subid_ranges_search_base instead." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ipa.5.xml:472 +msgid "ipa_hbac_search_base (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:475 +msgid "Optional. Use the given string as search base for HBAC related objects." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ipa.5.xml:485 +msgid "ipa_host_search_base (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:488 +msgid "Deprecated. Use ldap_host_search_base instead." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ipa.5.xml:494 +msgid "ipa_selinux_search_base (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:497 +msgid "Optional. Use the given string as search base for SELinux user maps." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ipa.5.xml:513 +msgid "ipa_subdomains_search_base (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:516 +msgid "Optional. Use the given string as search base for trusted domains." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:525 +msgid "Default: the value of <emphasis>cn=trusts,%basedn</emphasis>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ipa.5.xml:532 +msgid "ipa_master_domain_search_base (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:535 +msgid "Optional. Use the given string as search base for master domain object." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:544 +msgid "Default: the value of <emphasis>cn=ad,cn=etc,%basedn</emphasis>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ipa.5.xml:551 +msgid "ipa_views_search_base (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:554 +msgid "Optional. Use the given string as search base for views containers." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:563 +msgid "Default: the value of <emphasis>cn=views,cn=accounts,%basedn</emphasis>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:573 +msgid "" +"The name of the Kerberos realm. This is optional and defaults to the value " +"of <quote>ipa_domain</quote>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:577 +msgid "" +"The name of the Kerberos realm has a special meaning in IPA - it is " +"converted into the base DN to use for performing LDAP operations." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ipa.5.xml:585 sssd-ad.5.xml:1434 +msgid "krb5_confd_path (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:588 sssd-ad.5.xml:1437 +msgid "" +"Absolute path of a directory where SSSD should place Kerberos configuration " +"snippets." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:592 sssd-ad.5.xml:1441 +msgid "" +"To disable the creation of the configuration snippets set the parameter to " +"'none'." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:596 sssd-ad.5.xml:1445 +msgid "Default: not set (krb5.include.d subdirectory of SSSD's pubconf directory)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ipa.5.xml:603 +msgid "ipa_deskprofile_refresh (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:606 +msgid "" +"The amount of time between lookups of the Desktop Profile rules against the " +"IPA server. This will reduce the latency and load on the IPA server if there " +"are many desktop profiles requests made in a short period." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:613 sssd-ipa.5.xml:643 sssd-ipa.5.xml:659 sssd-ad.5.xml:600 +msgid "Default: 5 (seconds)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ipa.5.xml:619 +msgid "ipa_deskprofile_request_interval (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:622 +msgid "" +"The amount of time between lookups of the Desktop Profile rules against the " +"IPA server in case the last request did not return any rule." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:627 +msgid "Default: 60 (minutes)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ipa.5.xml:633 +msgid "ipa_hbac_refresh (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:636 +msgid "" +"The amount of time between lookups of the HBAC rules against the IPA " +"server. This will reduce the latency and load on the IPA server if there are " +"many access-control requests made in a short period." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ipa.5.xml:649 +msgid "ipa_selinux_refresh (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:652 +msgid "" +"The amount of time between lookups of the SELinux maps against the IPA " +"server. This will reduce the latency and load on the IPA server if there are " +"many user login requests made in a short period." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ipa.5.xml:665 +msgid "ipa_server_mode (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:668 +msgid "" +"This option will be set by the IPA installer (ipa-server-install) " +"automatically and denotes if SSSD is running on an IPA server or not." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:673 +msgid "" +"On an IPA server SSSD will lookup users and groups from trusted domains " +"directly while on a client it will ask an IPA server." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:678 +msgid "" +"NOTE: There are currently some assumptions that must be met when SSSD is " +"running on an IPA server." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd-ipa.5.xml:683 +msgid "" +"The <quote>ipa_server</quote> option must be configured to point to the IPA " +"server itself. This is already the default set by the IPA installer, so no " +"manual change is required." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd-ipa.5.xml:692 +msgid "" +"The <quote>full_name_format</quote> option must not be tweaked to only print " +"short names for users from trusted domains." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ipa.5.xml:707 +msgid "ipa_automount_location (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:710 +msgid "The automounter location this IPA client will be using" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:713 +msgid "Default: The location named \"default\"" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><title> +#: sssd-ipa.5.xml:721 +msgid "VIEWS AND OVERRIDES" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sssd-ipa.5.xml:730 +msgid "ipa_view_class (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:733 +msgid "Objectclass of the view container." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:736 +msgid "Default: nsContainer" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sssd-ipa.5.xml:742 +msgid "ipa_view_name (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:745 +msgid "Name of the attribute holding the name of the view." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:749 sssd-ldap-attributes.5.xml:496 +#: sssd-ldap-attributes.5.xml:832 sssd-ldap-attributes.5.xml:913 +#: sssd-ldap-attributes.5.xml:1010 sssd-ldap-attributes.5.xml:1068 +#: sssd-ldap-attributes.5.xml:1226 sssd-ldap-attributes.5.xml:1271 +msgid "Default: cn" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sssd-ipa.5.xml:755 +msgid "ipa_override_object_class (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:758 +msgid "Objectclass of the override objects." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:761 +msgid "Default: ipaOverrideAnchor" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sssd-ipa.5.xml:767 +msgid "ipa_anchor_uuid (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:770 +msgid "" +"Name of the attribute containing the reference to the original object in a " +"remote domain." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:774 +msgid "Default: ipaAnchorUUID" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sssd-ipa.5.xml:780 +msgid "ipa_user_override_object_class (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:783 +msgid "" +"Name of the objectclass for user overrides. It is used to determine if the " +"found override object is related to a user or a group." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:788 +msgid "User overrides can contain attributes given by" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd-ipa.5.xml:791 +msgid "ldap_user_name" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd-ipa.5.xml:794 +msgid "ldap_user_uid_number" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd-ipa.5.xml:797 +msgid "ldap_user_gid_number" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd-ipa.5.xml:800 +msgid "ldap_user_gecos" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd-ipa.5.xml:803 +msgid "ldap_user_home_directory" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd-ipa.5.xml:806 +msgid "ldap_user_shell" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd-ipa.5.xml:809 +msgid "ldap_user_ssh_public_key" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:814 +msgid "Default: ipaUserOverride" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sssd-ipa.5.xml:820 +msgid "ipa_group_override_object_class (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:823 +msgid "" +"Name of the objectclass for group overrides. It is used to determine if the " +"found override object is related to a user or a group." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:828 +msgid "Group overrides can contain attributes given by" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd-ipa.5.xml:831 +msgid "ldap_group_name" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd-ipa.5.xml:834 +msgid "ldap_group_gid_number" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:839 +msgid "Default: ipaGroupOverride" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd-ipa.5.xml:723 +msgid "" +"SSSD can handle views and overrides which are offered by FreeIPA 4.1 and " +"later version. Since all paths and objectclasses are fixed on the server " +"side there is basically no need to configure anything. For completeness the " +"related options are listed here with their default values. <placeholder " +"type=\"variablelist\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd-ipa.5.xml:851 +msgid "SUBDOMAINS PROVIDER" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-ipa.5.xml:853 +msgid "" +"The IPA subdomains provider behaves slightly differently if it is configured " +"explicitly or implicitly." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-ipa.5.xml:857 +msgid "" +"If the option 'subdomains_provider = ipa' is found in the domain section of " +"sssd.conf, the IPA subdomains provider is configured explicitly, and all " +"subdomain requests are sent to the IPA server if necessary." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-ipa.5.xml:863 +msgid "" +"If the option 'subdomains_provider' is not set in the domain section of " +"sssd.conf but there is the option 'id_provider = ipa', the IPA subdomains " +"provider is configured implicitly. In this case, if a subdomain request " +"fails and indicates that the server does not support subdomains, i.e. is not " +"configured for trusts, the IPA subdomains provider is disabled. After an " +"hour or after the IPA provider goes online, the subdomains provider is " +"enabled again." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd-ipa.5.xml:874 +msgid "TRUSTED DOMAINS CONFIGURATION" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><programlisting> +#: sssd-ipa.5.xml:882 +#, no-wrap +msgid "" +"[domain/ipa.domain.com/ad.domain.com]\n" +"ad_server = dc.ad.domain.com\n" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-ipa.5.xml:876 +msgid "" +"Some configuration options can also be set for a trusted domain. A trusted " +"domain configuration can be set using the trusted domain subsection as shown " +"in the example below. Alternatively, the <quote>subdomain_inherit</quote> " +"option can be used in the parent domain. <placeholder " +"type=\"programlisting\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-ipa.5.xml:887 +msgid "" +"For more details, see the <citerefentry> " +"<refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</manvolnum> " +"</citerefentry> manual page." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-ipa.5.xml:894 +msgid "" +"Different configuration options are tunable for a trusted domain depending " +"on whether you are configuring SSSD on an IPA server or an IPA client." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><title> +#: sssd-ipa.5.xml:899 +msgid "OPTIONS TUNABLE ON IPA MASTERS" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd-ipa.5.xml:901 +msgid "The following options can be set in a subdomain section on an IPA master:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> +#: sssd-ipa.5.xml:905 sssd-ipa.5.xml:945 +msgid "ad_server" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> +#: sssd-ipa.5.xml:908 +msgid "ad_backup_server" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> +#: sssd-ipa.5.xml:911 sssd-ipa.5.xml:948 +msgid "ad_site" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> +#: sssd-ipa.5.xml:914 +msgid "ipa_server" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> +#: sssd-ipa.5.xml:917 +msgid "ipa_backup_server" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> +#: sssd-ipa.5.xml:920 +msgid "ldap_search_base" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> +#: sssd-ipa.5.xml:923 +msgid "ldap_user_search_base" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> +#: sssd-ipa.5.xml:926 +msgid "ldap_group_search_base" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd-ipa.5.xml:934 +msgid "" +"Options prefixed with 'ad_' or 'ipa_' only apply to their respective " +"subdomain type." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><title> +#: sssd-ipa.5.xml:939 +msgid "OPTIONS TUNABLE ON IPA CLIENTS" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd-ipa.5.xml:941 +msgid "" +"The following options can be set in an AD subdomain section on an IPA " +"client:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd-ipa.5.xml:953 +msgid "" +"Note that if both options are set, only <quote>ad_server</quote> is " +"evaluated." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd-ipa.5.xml:957 +msgid "" +"Since any request for a user or a group identity from a trusted domain " +"triggered from an IPA client is resolved by the IPA server, the " +"<quote>ad_server</quote> and <quote>ad_site</quote> options only affect " +"which AD DC will the authentication be performed against. In particular, the " +"addresses resolved from these lists will be written to " +"<quote>kdcinfo</quote> files read by the Kerberos locator plugin. Please " +"refer to the <citerefentry> " +"<refentrytitle>sssd_krb5_locator_plugin</refentrytitle> " +"<manvolnum>8</manvolnum> </citerefentry> manual page for more details on the " +"Kerberos locator plugin." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-ipa.5.xml:981 +msgid "" +"The following example assumes that SSSD is correctly configured and " +"example.com is one of the domains in the <replaceable>[sssd]</replaceable> " +"section. This examples shows only the ipa provider-specific options." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><programlisting> +#: sssd-ipa.5.xml:988 +#, no-wrap +msgid "" +"[domain/example.com]\n" +"id_provider = ipa\n" +"ipa_server = ipaserver.example.com\n" +"ipa_hostname = myhost.example.com\n" +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refname> +#: sssd-ad.5.xml:10 sssd-ad.5.xml:16 +msgid "sssd-ad" +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refpurpose> +#: sssd-ad.5.xml:17 +msgid "SSSD Active Directory provider" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-ad.5.xml:23 +msgid "" +"This manual page describes the configuration of the AD provider for " +"<citerefentry> <refentrytitle>sssd</refentrytitle> <manvolnum>8</manvolnum> " +"</citerefentry>. For a detailed syntax reference, refer to the <quote>FILE " +"FORMAT</quote> section of the <citerefentry> " +"<refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</manvolnum> " +"</citerefentry> manual page." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-ad.5.xml:36 +msgid "" +"The AD provider is a back end used to connect to an Active Directory " +"server. This provider requires that the machine be joined to the AD domain " +"and a keytab is available. Back end communication occurs over a " +"GSSAPI-encrypted channel, SSL/TLS options should not be used with the AD " +"provider and will be superseded by Kerberos usage." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-ad.5.xml:44 +msgid "" +"The AD provider supports connecting to Active Directory 2008 R2 or " +"later. Earlier versions may work, but are unsupported." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-ad.5.xml:48 +msgid "" +"The AD provider can be used to get user information and authenticate users " +"from trusted domains. Currently only trusted domains in the same forest are " +"recognized. In addition servers from trusted domains are always " +"auto-discovered." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-ad.5.xml:54 +msgid "" +"The AD provider enables SSSD to use the <citerefentry> " +"<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> " +"</citerefentry> identity provider and the <citerefentry> " +"<refentrytitle>sssd-krb5</refentrytitle> <manvolnum>5</manvolnum> " +"</citerefentry> authentication provider with optimizations for Active " +"Directory environments. The AD provider accepts the same options used by the " +"sssd-ldap and sssd-krb5 providers with some exceptions. However, it is " +"neither necessary nor recommended to set these options." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-ad.5.xml:69 +msgid "" +"The AD provider primarily copies the traditional ldap and krb5 provider " +"default options with some exceptions, the differences are listed in the " +"<quote>MODIFIED DEFAULT OPTIONS</quote> section." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-ad.5.xml:74 +msgid "" +"The AD provider can also be used as an access, chpass, sudo and autofs " +"provider. No configuration of the access provider is required on the client " +"side." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-ad.5.xml:79 +msgid "" +"If <quote>auth_provider=ad</quote> or <quote>access_provider=ad</quote> is " +"configured in sssd.conf then the id_provider must also be set to " +"<quote>ad</quote>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><programlisting> +#: sssd-ad.5.xml:91 +#, no-wrap +msgid "" +"ldap_id_mapping = False\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-ad.5.xml:85 +msgid "" +"By default, the AD provider will map UID and GID values from the objectSID " +"parameter in Active Directory. For details on this, see the <quote>ID " +"MAPPING</quote> section below. If you want to disable ID mapping and instead " +"rely on POSIX attributes defined in Active Directory, you should set " +"<placeholder type=\"programlisting\" id=\"0\"/> If POSIX attributes should " +"be used, it is recommended for performance reasons that the attributes are " +"also replicated to the Global Catalog. If POSIX attributes are replicated, " +"SSSD will attempt to locate the domain of a requested numerical ID with the " +"help of the Global Catalog and only search that domain. In contrast, if " +"POSIX attributes are not replicated to the Global Catalog, SSSD must search " +"all the domains in the forest sequentially. Please note that the " +"<quote>cache_first</quote> option might be also helpful in speeding up " +"domainless searches. Note that if only a subset of POSIX attributes is " +"present in the Global Catalog, the non-replicated attributes are currently " +"not read from the LDAP port." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-ad.5.xml:108 +msgid "" +"Users, groups and other entities served by SSSD are always treated as " +"case-insensitive in the AD provider for compatibility with Active " +"Directory's LDAP implementation." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-ad.5.xml:113 +msgid "" +"SSSD only resolves Active Directory Security Groups. For more information " +"about AD group types see: <ulink " +"url=\"https://docs.microsoft.com/en-us/windows-server/identity/ad-ds/manage/understand-security-groups\"> " +"Active Directory security groups</ulink>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-ad.5.xml:120 +msgid "" +"SSSD filters out Domain Local groups from remote domains in the AD " +"forest. By default they are filtered out e.g. when following a nested group " +"hierarchy in remote domains because they are not valid in the local " +"domain. This is done to be in agreement with Active Directory's " +"group-membership assignment which can be seen in the PAC of the Kerberos " +"ticket of a user issued by Active Directory." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ad.5.xml:138 +msgid "ad_domain (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:141 +msgid "" +"Specifies the name of the Active Directory domain. This is optional. If not " +"provided, the configuration domain name is used." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:146 +msgid "" +"For proper operation, this option should be specified as the lower-case " +"version of the long version of the Active Directory domain." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:151 +msgid "" +"The short domain name (also known as the NetBIOS or the flat name) is " +"autodetected by the SSSD." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ad.5.xml:158 +msgid "ad_enabled_domains (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:161 +msgid "" +"A comma-separated list of enabled Active Directory domains. If provided, " +"SSSD will ignore any domains not listed in this option. If left unset, all " +"discovered domains from the AD forest will be available." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:168 +msgid "" +"During the discovery of the domains SSSD will filter out some domains where " +"flags or attributes indicate that they do not belong to the local forest or " +"are not trusted. If ad_enabled_domains is set, SSSD will try to enable all " +"listed domains." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> +#: sssd-ad.5.xml:179 +#, no-wrap +msgid "" +"ad_enabled_domains = sales.example.com, eng.example.com\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:175 +msgid "" +"For proper operation, this option must be specified in all lower-case and as " +"the fully qualified domain name of the Active Directory domain. For example: " +"<placeholder type=\"programlisting\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:183 +msgid "" +"The short domain name (also known as the NetBIOS or the flat name) will be " +"autodetected by SSSD." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ad.5.xml:193 +msgid "ad_server, ad_backup_server (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:196 +msgid "" +"The comma-separated list of hostnames of the AD servers to which SSSD should " +"connect in order of preference. For more information on failover and server " +"redundancy, see the <quote>FAILOVER</quote> section." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:203 +msgid "" +"This is optional if autodiscovery is enabled. For more information on " +"service discovery, refer to the <quote>SERVICE DISCOVERY</quote> section." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:208 +msgid "" +"Note: Trusted domains will always auto-discover servers even if the primary " +"server is explicitly defined in the ad_server option." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ad.5.xml:216 +msgid "ad_hostname (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:219 +msgid "" +"Optional. On machines where the hostname(5) does not reflect the fully " +"qualified name, sssd will try to expand the short name. If it is not " +"possible or the short name should be really used instead, set this parameter " +"explicitly." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:226 +msgid "" +"This field is used to determine the host principal in use in the keytab and " +"to perform dynamic DNS updates. It must match the hostname for which the " +"keytab was issued." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ad.5.xml:235 +msgid "ad_enable_dns_sites (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:238 +msgid "Enables DNS sites - location based service discovery." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:242 +msgid "" +"If true and service discovery (see Service Discovery paragraph at the bottom " +"of the man page) is enabled, the SSSD will first attempt to discover the " +"Active Directory server to connect to using the Active Directory Site " +"Discovery and fall back to the DNS SRV records if no AD site is found. The " +"DNS SRV configuration, including the discovery domain, is used during site " +"discovery as well." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ad.5.xml:258 +msgid "ad_access_filter (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:261 +msgid "" +"Specifies an LDAP access control filter that a user must match to gain " +"access. The <quote>access_provider</quote> option must be explicitly set to " +"<quote>ad</quote> for this option to take effect. If you want to use the " +"<quote>ad_access_filter</quote> as the only access control scheme, you must " +"disable GPO based access control (see option " +"<quote>ad_gpo_access_control</quote> for details)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:270 +msgid "" +"The option also supports specifying different filters per domain or " +"forest. This extended filter would consist of: " +"<quote>KEYWORD:NAME:FILTER</quote>. The keyword can be either " +"<quote>DOM</quote>, <quote>FOREST</quote> or missing." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:278 +msgid "" +"If the keyword equals to <quote>DOM</quote> or is missing, then " +"<quote>NAME</quote> specifies the domain or subdomain the filter applies " +"to. If the keyword equals to <quote>FOREST</quote>, then the filter equals " +"to all domains from the forest specified by <quote>NAME</quote>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:286 +msgid "" +"Multiple filters can be separated with the <quote>?</quote> character, " +"similarly to how search bases work." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:291 +msgid "" +"Nested group membership must be searched for using a special OID " +"<quote>:1.2.840.113556.1.4.1941:</quote> in addition to the full " +"DOM:domain.example.org: syntax to ensure the parser does not attempt to " +"interpret the colon characters associated with the OID. If you do not use " +"this OID then nested group membership will not be resolved. See usage " +"example below and refer here for further information about the OID: <ulink " +"url=\"https://msdn.microsoft.com/en-us/library/cc223367.aspx\"> [MS-ADTS] " +"section LDAP extensions</ulink>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:304 +msgid "" +"The most specific match is always used. For example, if the option specified " +"filter for a domain the user is a member of and a global filter, the " +"per-domain filter would be applied. If there are more matches with the same " +"specification, the first one is used." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><programlisting> +#: sssd-ad.5.xml:315 +#, no-wrap +msgid "" +"# apply filter on domain called dom1 only:\n" +"dom1:(memberOf=cn=admins,ou=groups,dc=dom1,dc=com)\n" +"\n" +"# apply filter on domain called dom2 only:\n" +"DOM:dom2:(memberOf=cn=admins,ou=groups,dc=dom2,dc=com)\n" +"\n" +"# apply filter on forest called EXAMPLE.COM only:\n" +"FOREST:EXAMPLE.COM:(memberOf=cn=admins,ou=groups,dc=example,dc=com)\n" +"\n" +"# apply filter for a member of a nested group in dom1:\n" +"DOM:dom1:(memberOf:1.2.840.113556.1.4.1941:=cn=nestedgroup,ou=groups,dc=example,dc=com)\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ad.5.xml:334 +msgid "ad_site (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:337 +msgid "" +"Specify AD site to which client should try to connect. If this option is " +"not provided, the AD site will be auto-discovered." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ad.5.xml:348 +msgid "ad_enable_gc (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:351 +msgid "" +"By default, the SSSD connects to the Global Catalog first to retrieve users " +"from trusted domains and uses the LDAP port to retrieve group memberships or " +"as a fallback. Disabling this option makes the SSSD only connect to the LDAP " +"port of the current AD server." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:359 +msgid "" +"Please note that disabling Global Catalog support does not disable " +"retrieving users from trusted domains. The SSSD would connect to the LDAP " +"port of trusted domains instead. However, Global Catalog must be used in " +"order to resolve cross-domain group memberships." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ad.5.xml:373 +msgid "ad_gpo_access_control (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:376 +msgid "" +"This option specifies the operation mode for GPO-based access control " +"functionality: whether it operates in disabled mode, enforcing mode, or " +"permissive mode. Please note that the <quote>access_provider</quote> option " +"must be explicitly set to <quote>ad</quote> in order for this option to have " +"an effect." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:385 +msgid "" +"GPO-based access control functionality uses GPO policy settings to determine " +"whether or not a particular user is allowed to logon to the host. For more " +"information on the supported policy settings please refer to the " +"<quote>ad_gpo_map</quote> options." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:393 +msgid "" +"Please note that current version of SSSD does not support Active Directory's " +"built-in groups. Built-in groups (such as Administrators with SID " +"S-1-5-32-544) in GPO access control rules will be ignored by SSSD. See " +"upstream issue tracker https://github.com/SSSD/sssd/issues/5063 ." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:402 +msgid "" +"Before performing access control SSSD applies group policy security " +"filtering on the GPOs. For every single user login, the applicability of the " +"GPOs that are linked to the host is checked. In order for a GPO to apply to " +"a user, the user or at least one of the groups to which it belongs must have " +"following permissions on the GPO:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd-ad.5.xml:412 +msgid "" +"Read: The user or one of its groups must have read access to the properties " +"of the GPO (RIGHT_DS_READ_PROPERTY)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd-ad.5.xml:419 +msgid "" +"Apply Group Policy: The user or at least one of its groups must be allowed " +"to apply the GPO (RIGHT_DS_CONTROL_ACCESS)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:427 +msgid "" +"By default, the Authenticated Users group is present on a GPO and this group " +"has both Read and Apply Group Policy access rights. Since authentication of " +"a user must have been completed successfully before GPO security filtering " +"and access control are started, the Authenticated Users group permissions on " +"the GPO always apply also to the user." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:436 +msgid "" +"NOTE: If the operation mode is set to enforcing, it is possible that users " +"that were previously allowed logon access will now be denied logon access " +"(as dictated by the GPO policy settings). In order to facilitate a smooth " +"transition for administrators, a permissive mode is available that will not " +"enforce the access control rules, but will evaluate them and will output a " +"syslog message if access would have been denied. By examining the logs, " +"administrators can then make the necessary changes before setting the mode " +"to enforcing. For logging GPO-based access control debug level 'trace " +"functions' is required (see <citerefentry> " +"<refentrytitle>sssctl</refentrytitle> <manvolnum>8</manvolnum> " +"</citerefentry> manual page)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:455 +msgid "There are three supported values for this option:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd-ad.5.xml:459 +msgid "disabled: GPO-based access control rules are neither evaluated nor enforced." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd-ad.5.xml:465 +msgid "enforcing: GPO-based access control rules are evaluated and enforced." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd-ad.5.xml:471 +msgid "" +"permissive: GPO-based access control rules are evaluated, but not enforced. " +"Instead, a syslog message will be emitted indicating that the user would " +"have been denied access if this option's value were set to enforcing." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:482 +msgid "Default: permissive" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:485 +msgid "Default: enforcing" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ad.5.xml:491 +msgid "ad_gpo_implicit_deny (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:494 +msgid "" +"Normally when no applicable GPOs are found the users are allowed " +"access. When this option is set to True users will be allowed access only " +"when explicitly allowed by a GPO rule. Otherwise users will be denied " +"access. This can be used to harden security but be careful when using this " +"option because it can deny access even to users in the built-in " +"Administrators group if no GPO rules apply to them." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:510 +msgid "" +"The following 2 tables should illustrate when a user is allowed or rejected " +"based on the allow and deny login rights defined on the server-side and the " +"setting of ad_gpo_implicit_deny." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> +#: sssd-ad.5.xml:522 +msgid "ad_gpo_implicit_deny = False (default)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> +#: sssd-ad.5.xml:523 sssd-ad.5.xml:549 +msgid "allow-rules" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> +#: sssd-ad.5.xml:523 sssd-ad.5.xml:549 +msgid "deny-rules" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> +#: sssd-ad.5.xml:524 sssd-ad.5.xml:550 +msgid "results" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry> +#: sssd-ad.5.xml:527 sssd-ad.5.xml:530 sssd-ad.5.xml:533 sssd-ad.5.xml:553 +#: sssd-ad.5.xml:556 sssd-ad.5.xml:559 +msgid "missing" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry><para> +#: sssd-ad.5.xml:528 +msgid "all users are allowed" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry> +#: sssd-ad.5.xml:530 sssd-ad.5.xml:533 sssd-ad.5.xml:536 sssd-ad.5.xml:556 +#: sssd-ad.5.xml:559 sssd-ad.5.xml:562 +msgid "present" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry><para> +#: sssd-ad.5.xml:531 +msgid "only users not in deny-rules are allowed" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry><para> +#: sssd-ad.5.xml:534 sssd-ad.5.xml:560 +msgid "only users in allow-rules are allowed" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry><para> +#: sssd-ad.5.xml:537 sssd-ad.5.xml:563 +msgid "only users in allow-rules and not in deny-rules are allowed" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> +#: sssd-ad.5.xml:548 +msgid "ad_gpo_implicit_deny = True" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry><para> +#: sssd-ad.5.xml:554 sssd-ad.5.xml:557 +msgid "no users are allowed" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ad.5.xml:570 +msgid "ad_gpo_ignore_unreadable (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:573 +msgid "" +"Normally when some group policy containers (AD object) of applicable group " +"policy objects are not readable by SSSD then users are denied access. This " +"option allows to ignore group policy containers and with them associated " +"policies if their attributes in group policy containers are not readable for " +"SSSD." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ad.5.xml:590 +msgid "ad_gpo_cache_timeout (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:593 +msgid "" +"The amount of time between lookups of GPO policy files against the AD " +"server. This will reduce the latency and load on the AD server if there are " +"many access-control requests made in a short period." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ad.5.xml:606 +msgid "ad_gpo_map_interactive (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:609 +msgid "" +"A comma-separated list of PAM service names for which GPO-based access " +"control is evaluated based on the InteractiveLogonRight and " +"DenyInteractiveLogonRight policy settings. Only those GPOs are evaluated " +"for which the user has Read and Apply Group Policy permission (see option " +"<quote>ad_gpo_access_control</quote>). If an evaluated GPO contains the " +"deny interactive logon setting for the user or one of its groups, the user " +"is denied local access. If none of the evaluated GPOs has an interactive " +"logon right defined, the user is granted local access. If at least one " +"evaluated GPO contains interactive logon right settings, the user is granted " +"local access only, if it or at least one of its groups is part of the policy " +"settings." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:627 +msgid "" +"Note: Using the Group Policy Management Editor this value is called \"Allow " +"log on locally\" and \"Deny log on locally\"." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> +#: sssd-ad.5.xml:641 +#, no-wrap +msgid "" +"ad_gpo_map_interactive = +my_pam_service, -login\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:632 +msgid "" +"It is possible to add another PAM service name to the default set by using " +"<quote>+service_name</quote> or to explicitly remove a PAM service name from " +"the default set by using <quote>-service_name</quote>. For example, in " +"order to replace a default PAM service name for this logon right " +"(e.g. <quote>login</quote>) with a custom pam service name " +"(e.g. <quote>my_pam_service</quote>), you would use the following " +"configuration: <placeholder type=\"programlisting\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd-ad.5.xml:664 +msgid "gdm-fingerprint" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd-ad.5.xml:684 +msgid "lightdm" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd-ad.5.xml:689 +msgid "lxdm" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd-ad.5.xml:699 +msgid "sddm" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd-ad.5.xml:704 +msgid "unity" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd-ad.5.xml:709 +msgid "xdm" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ad.5.xml:718 +msgid "ad_gpo_map_remote_interactive (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:721 +msgid "" +"A comma-separated list of PAM service names for which GPO-based access " +"control is evaluated based on the RemoteInteractiveLogonRight and " +"DenyRemoteInteractiveLogonRight policy settings. Only those GPOs are " +"evaluated for which the user has Read and Apply Group Policy permission (see " +"option <quote>ad_gpo_access_control</quote>). If an evaluated GPO contains " +"the deny remote logon setting for the user or one of its groups, the user is " +"denied remote interactive access. If none of the evaluated GPOs has a " +"remote interactive logon right defined, the user is granted remote " +"access. If at least one evaluated GPO contains remote interactive logon " +"right settings, the user is granted remote access only, if it or at least " +"one of its groups is part of the policy settings." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:740 +msgid "" +"Note: Using the Group Policy Management Editor this value is called \"Allow " +"log on through Remote Desktop Services\" and \"Deny log on through Remote " +"Desktop Services\"." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> +#: sssd-ad.5.xml:755 +#, no-wrap +msgid "" +"ad_gpo_map_remote_interactive = +my_pam_service, -sshd\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:746 +msgid "" +"It is possible to add another PAM service name to the default set by using " +"<quote>+service_name</quote> or to explicitly remove a PAM service name from " +"the default set by using <quote>-service_name</quote>. For example, in " +"order to replace a default PAM service name for this logon right " +"(e.g. <quote>sshd</quote>) with a custom pam service name " +"(e.g. <quote>my_pam_service</quote>), you would use the following " +"configuration: <placeholder type=\"programlisting\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd-ad.5.xml:763 +msgid "sshd" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd-ad.5.xml:768 +msgid "cockpit" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ad.5.xml:777 +msgid "ad_gpo_map_network (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:780 +msgid "" +"A comma-separated list of PAM service names for which GPO-based access " +"control is evaluated based on the NetworkLogonRight and " +"DenyNetworkLogonRight policy settings. Only those GPOs are evaluated for " +"which the user has Read and Apply Group Policy permission (see option " +"<quote>ad_gpo_access_control</quote>). If an evaluated GPO contains the " +"deny network logon setting for the user or one of its groups, the user is " +"denied network logon access. If none of the evaluated GPOs has a network " +"logon right defined, the user is granted logon access. If at least one " +"evaluated GPO contains network logon right settings, the user is granted " +"logon access only, if it or at least one of its groups is part of the policy " +"settings." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:798 +msgid "" +"Note: Using the Group Policy Management Editor this value is called \"Access " +"this computer from the network\" and \"Deny access to this computer from the " +"network\"." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> +#: sssd-ad.5.xml:813 +#, no-wrap +msgid "" +"ad_gpo_map_network = +my_pam_service, -ftp\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:804 +msgid "" +"It is possible to add another PAM service name to the default set by using " +"<quote>+service_name</quote> or to explicitly remove a PAM service name from " +"the default set by using <quote>-service_name</quote>. For example, in " +"order to replace a default PAM service name for this logon right " +"(e.g. <quote>ftp</quote>) with a custom pam service name " +"(e.g. <quote>my_pam_service</quote>), you would use the following " +"configuration: <placeholder type=\"programlisting\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd-ad.5.xml:821 +msgid "ftp" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd-ad.5.xml:826 +msgid "samba" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ad.5.xml:835 +msgid "ad_gpo_map_batch (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:838 +msgid "" +"A comma-separated list of PAM service names for which GPO-based access " +"control is evaluated based on the BatchLogonRight and DenyBatchLogonRight " +"policy settings. Only those GPOs are evaluated for which the user has Read " +"and Apply Group Policy permission (see option " +"<quote>ad_gpo_access_control</quote>). If an evaluated GPO contains the " +"deny batch logon setting for the user or one of its groups, the user is " +"denied batch logon access. If none of the evaluated GPOs has a batch logon " +"right defined, the user is granted logon access. If at least one evaluated " +"GPO contains batch logon right settings, the user is granted logon access " +"only, if it or at least one of its groups is part of the policy settings." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:856 +msgid "" +"Note: Using the Group Policy Management Editor this value is called \"Allow " +"log on as a batch job\" and \"Deny log on as a batch job\"." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> +#: sssd-ad.5.xml:870 +#, no-wrap +msgid "" +"ad_gpo_map_batch = +my_pam_service, -crond\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:861 +msgid "" +"It is possible to add another PAM service name to the default set by using " +"<quote>+service_name</quote> or to explicitly remove a PAM service name from " +"the default set by using <quote>-service_name</quote>. For example, in " +"order to replace a default PAM service name for this logon right " +"(e.g. <quote>crond</quote>) with a custom pam service name " +"(e.g. <quote>my_pam_service</quote>), you would use the following " +"configuration: <placeholder type=\"programlisting\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:873 +msgid "Note: Cron service name may differ depending on Linux distribution used." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd-ad.5.xml:879 +msgid "crond" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ad.5.xml:888 +msgid "ad_gpo_map_service (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:891 +msgid "" +"A comma-separated list of PAM service names for which GPO-based access " +"control is evaluated based on the ServiceLogonRight and " +"DenyServiceLogonRight policy settings. Only those GPOs are evaluated for " +"which the user has Read and Apply Group Policy permission (see option " +"<quote>ad_gpo_access_control</quote>). If an evaluated GPO contains the " +"deny service logon setting for the user or one of its groups, the user is " +"denied service logon access. If none of the evaluated GPOs has a service " +"logon right defined, the user is granted logon access. If at least one " +"evaluated GPO contains service logon right settings, the user is granted " +"logon access only, if it or at least one of its groups is part of the policy " +"settings." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:909 +msgid "" +"Note: Using the Group Policy Management Editor this value is called \"Allow " +"log on as a service\" and \"Deny log on as a service\"." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> +#: sssd-ad.5.xml:922 +#, no-wrap +msgid "" +"ad_gpo_map_service = +my_pam_service\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:914 sssd-ad.5.xml:989 +msgid "" +"It is possible to add a PAM service name to the default set by using " +"<quote>+service_name</quote>. Since the default set is empty, it is not " +"possible to remove a PAM service name from the default set. For example, in " +"order to add a custom pam service name (e.g. <quote>my_pam_service</quote>), " +"you would use the following configuration: <placeholder " +"type=\"programlisting\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ad.5.xml:932 +msgid "ad_gpo_map_permit (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:935 +msgid "" +"A comma-separated list of PAM service names for which GPO-based access is " +"always granted, regardless of any GPO Logon Rights." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> +#: sssd-ad.5.xml:949 +#, no-wrap +msgid "" +"ad_gpo_map_permit = +my_pam_service, -sudo\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:940 +msgid "" +"It is possible to add another PAM service name to the default set by using " +"<quote>+service_name</quote> or to explicitly remove a PAM service name from " +"the default set by using <quote>-service_name</quote>. For example, in " +"order to replace a default PAM service name for unconditionally permitted " +"access (e.g. <quote>sudo</quote>) with a custom pam service name " +"(e.g. <quote>my_pam_service</quote>), you would use the following " +"configuration: <placeholder type=\"programlisting\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd-ad.5.xml:957 +msgid "polkit-1" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd-ad.5.xml:972 +msgid "systemd-user" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ad.5.xml:981 +msgid "ad_gpo_map_deny (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:984 +msgid "" +"A comma-separated list of PAM service names for which GPO-based access is " +"always denied, regardless of any GPO Logon Rights." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> +#: sssd-ad.5.xml:997 +#, no-wrap +msgid "" +"ad_gpo_map_deny = +my_pam_service\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ad.5.xml:1007 +msgid "ad_gpo_default_right (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:1010 +msgid "" +"This option defines how access control is evaluated for PAM service names " +"that are not explicitly listed in one of the ad_gpo_map_* options. This " +"option can be set in two different manners. First, this option can be set to " +"use a default logon right. For example, if this option is set to " +"'interactive', it means that unmapped PAM service names will be processed " +"based on the InteractiveLogonRight and DenyInteractiveLogonRight policy " +"settings. Alternatively, this option can be set to either always permit or " +"always deny access for unmapped PAM service names." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:1023 +msgid "Supported values for this option include:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd-ad.5.xml:1032 +msgid "remote_interactive" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd-ad.5.xml:1037 +msgid "network" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd-ad.5.xml:1042 +msgid "batch" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd-ad.5.xml:1047 +msgid "service" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd-ad.5.xml:1052 +msgid "permit" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd-ad.5.xml:1057 +msgid "deny" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:1063 +msgid "Default: deny" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ad.5.xml:1069 +msgid "ad_maximum_machine_account_password_age (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:1072 +msgid "" +"SSSD will check once a day if the machine account password is older than the " +"given age in days and try to renew it. A value of 0 will disable the renewal " +"attempt." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:1078 +msgid "Default: 30 days" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ad.5.xml:1084 +msgid "ad_machine_account_password_renewal_opts (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:1087 +msgid "" +"This option should only be used to test the machine account renewal " +"task. The option expects 3 integers and a string separated by a colon " +"(':'). The first integer defines the interval in seconds how often the task " +"is run. The second specifies the initial timeout in seconds before the task " +"is run for the first time after startup. The optional third value specifies " +"a maximal random offset to the previous two values to avoid updates of many " +"hosts at the same time (\"thundering herd problem\"). If this value is " +"missing or empty in the value string '0' will be used." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:1101 +msgid "" +"The optional fourth string value identifies the helper binary which should " +"be used for the renewal. Currently <command>adcli</command> and " +"<command>realm</command> are supported. If this value is missing or empty in " +"the value string <command>realm</command> will be used. Since the helper is " +"started as the user SSSD is running as there might be the chance that the " +"renewal will fail if this user does not have permissions to modify the " +"keytab file where the machine account credentials are stored. This will " +"typically be the case for <command>adcli</command>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:1115 +msgid "" +"<command>realm</command> is not updating the keytab directly but is calling " +"the <command>realmd</command> process, which runs as root user, for this " +"task. <command>realmd</command> can allow access to non-privileged users " +"with the help of PolicyKit and by default SSSD provides suitable rules for " +"the user SSSD is running as." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:1124 +msgid "Default: 86400:750:300:realm (24h, 12m30s and 5m)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ad.5.xml:1130 +msgid "ad_update_samba_machine_account_password (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:1133 +msgid "" +"If enabled, when SSSD renews the machine account password, it will also be " +"updated in Samba's database. This prevents Samba's copy of the machine " +"account password from getting out of date when it is set up to use AD for " +"authentication." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ad.5.xml:1146 +msgid "ad_use_ldaps (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:1149 +msgid "" +"By default SSSD uses the plain LDAP port 389 and the Global Catalog port " +"3268. If this option is set to True SSSD will use the LDAPS port 636 and " +"Global Catalog port 3269 with LDAPS protection. Since AD does not allow to " +"have multiple encryption layers on a single connection and we still want to " +"use SASL/GSSAPI or SASL/GSS-SPNEGO for authentication the SASL security " +"property maxssf is set to 0 (zero) for those connections." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:1169 +msgid "" +"Optional. This option tells SSSD to automatically update the Active " +"Directory DNS server with the IP address of this client. The update is " +"secured using GSS-TSIG. As a consequence, the Active Directory administrator " +"only needs to allow secure updates for the DNS zone. The IP address of the " +"AD LDAP connection is used for the updates, if it is not otherwise specified " +"by using the <quote>dyndns_iface</quote> option." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:1194 +msgid "Default: 3600 (seconds)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:1216 +msgid "" +"Default: Use the IP addresses of the interface which is used for AD LDAP " +"connection" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:1252 +msgid "" +"How often should the back end perform periodic DNS update in addition to the " +"automatic update performed when the back end goes online. This is optional " +"and applicable only when dyndns_update is true. Note that the minimum value " +"is 60 seconds, any specified value below this threshold will default to 60." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-ad.5.xml:1465 +msgid "" +"The following example assumes that SSSD is correctly configured and " +"example.com is one of the domains in the <replaceable>[sssd]</replaceable> " +"section. This example shows only the AD provider-specific options." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><programlisting> +#: sssd-ad.5.xml:1472 +#, no-wrap +msgid "" +"[domain/EXAMPLE]\n" +"id_provider = ad\n" +"auth_provider = ad\n" +"access_provider = ad\n" +"chpass_provider = ad\n" +"\n" +"ad_server = dc1.example.com\n" +"ad_hostname = client.example.com\n" +"ad_domain = example.com\n" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><programlisting> +#: sssd-ad.5.xml:1492 +#, no-wrap +msgid "" +"access_provider = ldap\n" +"ldap_access_order = expire\n" +"ldap_account_expire_policy = ad\n" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-ad.5.xml:1488 +msgid "" +"The AD access control provider checks if the account is expired. It has the " +"same effect as the following configuration of the LDAP provider: " +"<placeholder type=\"programlisting\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-ad.5.xml:1498 +msgid "" +"However, unless the <quote>ad</quote> access control provider is explicitly " +"configured, the default access provider is <quote>permit</quote>. Please " +"note that if you configure an access provider other than <quote>ad</quote>, " +"you need to set all the connection parameters (such as LDAP URIs and " +"encryption details) manually." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-ad.5.xml:1506 +msgid "" +"When the autofs provider is set to <quote>ad</quote>, the RFC2307 schema " +"attribute mapping (nisMap, nisObject, ...) is used, because these attributes " +"are included in the default Active Directory schema." +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refname> +#: sssd-sudo.5.xml:10 sssd-sudo.5.xml:16 +msgid "sssd-sudo" +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refpurpose> +#: sssd-sudo.5.xml:17 +msgid "Configuring sudo with the SSSD back end" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-sudo.5.xml:23 +msgid "" +"This manual page describes how to configure <citerefentry> " +"<refentrytitle>sudo</refentrytitle> <manvolnum>8</manvolnum> </citerefentry> " +"to work with <citerefentry> <refentrytitle>sssd</refentrytitle> " +"<manvolnum>8</manvolnum> </citerefentry> and how SSSD caches sudo rules." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd-sudo.5.xml:36 +msgid "Configuring sudo to cooperate with SSSD" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-sudo.5.xml:38 +msgid "" +"To enable SSSD as a source for sudo rules, add <emphasis>sss</emphasis> to " +"the <emphasis>sudoers</emphasis> entry in <citerefentry> " +"<refentrytitle>nsswitch.conf</refentrytitle> <manvolnum>5</manvolnum> " +"</citerefentry>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-sudo.5.xml:47 +msgid "" +"For example, to configure sudo to first lookup rules in the standard " +"<citerefentry> <refentrytitle>sudoers</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry> file (which should contain rules " +"that apply to local users) and then in SSSD, the nsswitch.conf file should " +"contain the following line:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><programlisting> +#: sssd-sudo.5.xml:57 +#, no-wrap +msgid "sudoers: files sss\n" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-sudo.5.xml:61 +msgid "" +"More information about configuring the sudoers search order from the " +"nsswitch.conf file as well as information about the LDAP schema that is used " +"to store sudo rules in the directory can be found in <citerefentry> " +"<refentrytitle>sudoers.ldap</refentrytitle> <manvolnum>5</manvolnum> " +"</citerefentry>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-sudo.5.xml:70 +msgid "" +"<emphasis>Note</emphasis>: in order to use netgroups or IPA hostgroups in " +"sudo rules, you also need to correctly set <citerefentry> " +"<refentrytitle>nisdomainname</refentrytitle> <manvolnum>1</manvolnum> " +"</citerefentry> to your NIS domain name (which equals to IPA domain name " +"when using hostgroups)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd-sudo.5.xml:82 +msgid "Configuring SSSD to fetch sudo rules" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-sudo.5.xml:84 +msgid "" +"All configuration that is needed on SSSD side is to extend the list of " +"<emphasis>services</emphasis> with \"sudo\" in [sssd] section of " +"<citerefentry> <refentrytitle>sssd.conf</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry>. To speed up the LDAP lookups, you " +"can also set search base for sudo rules using " +"<emphasis>ldap_sudo_search_base</emphasis> option." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-sudo.5.xml:94 +msgid "" +"The following example shows how to configure SSSD to download sudo rules " +"from an LDAP server." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><programlisting> +#: sssd-sudo.5.xml:99 +#, no-wrap +msgid "" +"[sssd]\n" +"services = nss, pam, sudo\n" +"domains = EXAMPLE\n" +"\n" +"[domain/EXAMPLE]\n" +"id_provider = ldap\n" +"sudo_provider = ldap\n" +"ldap_uri = ldap://example.com\n" +"ldap_sudo_search_base = ou=sudoers,dc=example,dc=com\n" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-sudo.5.xml:98 +msgid "" +"<placeholder type=\"programlisting\" id=\"0\"/> <phrase " +"condition=\"have_systemd\"> It's important to note that on platforms where " +"systemd is supported there's no need to add the \"sudo\" provider to the " +"list of services, as it became optional. However, sssd-sudo.socket must be " +"enabled instead. </phrase>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-sudo.5.xml:117 +msgid "" +"When SSSD is configured to use IPA as the ID provider, the sudo provider is " +"automatically enabled. The sudo search base is configured to use the IPA " +"native LDAP tree (cn=sudo,$SUFFIX). If any other search base is defined in " +"sssd.conf, this value will be used instead. The compat tree " +"(ou=sudoers,$SUFFIX) is no longer required for IPA sudo functionality." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd-sudo.5.xml:127 +msgid "The SUDO rule caching mechanism" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-sudo.5.xml:129 +msgid "" +"The biggest challenge, when developing sudo support in SSSD, was to ensure " +"that running sudo with SSSD as the data source provides the same user " +"experience and is as fast as sudo but keeps providing the most current set " +"of rules as possible. To satisfy these requirements, SSSD uses three kinds " +"of updates. They are referred to as full refresh, smart refresh and rules " +"refresh." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-sudo.5.xml:137 +msgid "" +"The <emphasis>smart refresh</emphasis> periodically downloads rules that are " +"new or were modified after the last update. Its primary goal is to grow the " +"database incrementally by fetching only small updates, avoiding large " +"amounts of network traffic." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-sudo.5.xml:143 +msgid "" +"The <emphasis>full refresh</emphasis> simply deletes all sudo rules stored " +"in the cache and replaces them with all rules that are stored on the " +"server. This is used to keep the cache consistent by removing every rule " +"which was deleted from the server. However, full refresh may produce a lot " +"of traffic and thus it should be run only occasionally depending on the size " +"and stability of the sudo rules." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-sudo.5.xml:151 +msgid "" +"The <emphasis>rules refresh</emphasis> ensures that we do not grant the user " +"more permission than defined. It is triggered each time the user runs " +"sudo. Rules refresh will find all rules that apply to this user, check their " +"expiration time and redownload them if expired. In the case that any of " +"these rules are missing on the server, the SSSD will do an out of band full " +"refresh because more rules (that apply to other users) may have been " +"deleted." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-sudo.5.xml:160 +msgid "" +"If enabled, SSSD will store only rules that can be applied to this " +"machine. This means rules that contain one of the following values in " +"<emphasis>sudoHost</emphasis> attribute:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><itemizedlist><listitem><para> +#: sssd-sudo.5.xml:167 +msgid "keyword ALL" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><itemizedlist><listitem><para> +#: sssd-sudo.5.xml:172 +msgid "wildcard" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><itemizedlist><listitem><para> +#: sssd-sudo.5.xml:177 +msgid "netgroup (in the form \"+netgroup\")" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><itemizedlist><listitem><para> +#: sssd-sudo.5.xml:182 +msgid "hostname or fully qualified domain name of this machine" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><itemizedlist><listitem><para> +#: sssd-sudo.5.xml:187 +msgid "one of the IP addresses of this machine" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><itemizedlist><listitem><para> +#: sssd-sudo.5.xml:192 +msgid "one of the IP addresses of the network (in the form \"address/mask\")" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-sudo.5.xml:198 +msgid "" +"There are many configuration options that can be used to adjust the " +"behavior. Please refer to \"ldap_sudo_*\" in <citerefentry> " +"<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> " +"</citerefentry> and \"sudo_*\" in <citerefentry> " +"<refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</manvolnum> " +"</citerefentry>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd-sudo.5.xml:212 +msgid "Tuning the performance" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-sudo.5.xml:214 +msgid "" +"SSSD uses different kinds of mechanisms with more or less complex LDAP " +"filters to keep the cached sudo rules up to date. The default configuration " +"is set to values that should satisfy most of our users, but the following " +"paragraphs contain few tips on how to fine- tune the configuration to your " +"requirements." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-sudo.5.xml:221 +msgid "" +"1. <emphasis>Index LDAP attributes</emphasis>. Make sure that following LDAP " +"attributes are indexed: objectClass, cn, entryUSN or modifyTimestamp." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-sudo.5.xml:226 +msgid "" +"2. <emphasis>Set ldap_sudo_search_base</emphasis>. Set the search base to " +"the container that holds the sudo rules to limit the scope of the lookup." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-sudo.5.xml:231 +msgid "" +"3. <emphasis>Set full and smart refresh interval</emphasis>. If your sudo " +"rules do not change often and you do not require quick update of cached " +"rules on your clients, you may consider increasing the " +"<emphasis>ldap_sudo_full_refresh_interval</emphasis> and " +"<emphasis>ldap_sudo_smart_refresh_interval</emphasis>. You may also consider " +"disabling the smart refresh by setting " +"<emphasis>ldap_sudo_smart_refresh_interval = 0</emphasis>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-sudo.5.xml:240 +msgid "" +"4. If you have large number of clients, you may consider increasing the " +"value of <emphasis>ldap_sudo_random_offset</emphasis> to distribute the load " +"on the server better." +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refname> +#: sssd-idp.5.xml:10 sssd-idp.5.xml:16 +msgid "sssd-idp" +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refpurpose> +#: sssd-idp.5.xml:17 +msgid "SSSD IdP provider" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-idp.5.xml:23 +msgid "" +"This manual page describes the configuration of the IdP provider for " +"<citerefentry> <refentrytitle>sssd</refentrytitle> <manvolnum>8</manvolnum> " +"</citerefentry>. For a detailed syntax reference, refer to the <quote>FILE " +"FORMAT</quote> section of the <citerefentry> " +"<refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</manvolnum> " +"</citerefentry> manual page." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-idp.5.xml:36 +msgid "" +"The IdP provider is a back end used to connect to an OAuth 2.0 and REST " +"based identity provider (IdP). Since products might have individual " +"implementation of the REST API for looking up user and group attributes " +"dedicated code might be required, see the <quote>idp_type</quote> option for " +"details." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-idp.5.xml:43 +msgid "" +"IdPs typically do not provide POSIX attributes like e.g. user Id (UID) or " +"home directory. SSSD's IdP provider will autogenerate the needed " +"attributes. The default algorithm to generate user IDs (UIDs) and group IDs " +"(GIDs) aims to create reproducible IDs on different systems. As a drawback " +"it might happen that the algorithm assigns the same ID to different objects " +"and only the first one requested via SSSD will be available." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-idp.5.xml:62 +msgid "idp_type (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:65 +msgid "" +"Required option that specifies the IdP product. Currently Entra ID " +"(entra_id) and Keycloak (keycloak) are supported." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:70 +msgid "" +"Depending on the IdP product additional platform specific options might " +"follow the name separated by a colon (:). E.g. for Keycloak the base URI for " +"the user and group REST API must be given. For Entra ID the base URI for the " +"Microsoft Graph API can be given to use sovereign or government cloud " +"endpoints instead of the default (https://graph.microsoft.com/v1.0). E.g. " +"<quote>entra_id:https://graph.microsoft.us/v1.0</quote> for the US " +"government cloud (GCC High)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:82 sssd-idp.5.xml:98 sssd-idp.5.xml:123 +msgid "Default: Not set (Required)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-idp.5.xml:87 +msgid "idp_client_id (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:90 +msgid "" +"ID of the IdP client used by SSSD to authenticate users and as a client to " +"lookup user and group attributes. This client must offer device " +"authorization according to RFC-8628 and must have permissions to search and " +"read user and group attributes." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-idp.5.xml:103 +msgid "idp_client_secret (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:106 +msgid "" +"Password of the IdP client. The password is required for the id_provider. If " +"only used as auth_provider it depends on the server side configuration if it " +"is required or not." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-idp.5.xml:117 +msgid "idp_token_endpoint (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:120 +msgid "IdP endpoint for requesting access tokens." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-idp.5.xml:128 +msgid "idp_device_auth_endpoint (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:131 +msgid "" +"IdP endpoint for device authorization according to RFC-8628. This is " +"required for user authentication." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-idp.5.xml:141 +msgid "idp_userinfo_endpoint (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:144 +msgid "" +"IdP userinfo endpoint to request user attributes after a successful " +"authentication of the user. Required for authentication." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-idp.5.xml:154 +msgid "idp_id_scope (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:157 +msgid "" +"Scope required for looking up user and group attributes with the REST " +"API. The scopes are used by the server to determine which attributes/claims " +"are returned to the caller." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:163 +msgid "" +"Note: In previous versions of SSSD, this option was expected to already be " +"URL-encoded." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-idp.5.xml:172 +msgid "idp_auth_scope (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:175 +msgid "" +"Scope required during authentication. The scopes are used by the server to " +"determine which attributes/claims are returned to the caller." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:180 +msgid "" +"Currently the tokens returned during user authentication are not used for " +"other purposes hence the only important claim is the subject identifier " +"'sub' which is used to check if the authenticated user is the one trying to " +"log in. This might change in future." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-idp.5.xml:193 +msgid "idp_auth_user_identifier_attr (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:196 +msgid "" +"Attribute used to identify the authenticated user in userinfo data or token " +"claims." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:200 +msgid "" +"For hybrid Active Directory and Entra ID deployments where " +"<quote>id_provider = ad</quote> and <quote>auth_provider = idp</quote>, this " +"option must be set explicitly. No value is derived from the identity " +"provider, because more than one attribute can link an Entra ID object to its " +"on-premises counterpart and only the administrator knows which one the " +"directory synchronization is configured to use." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:211 +msgid "" +"Setting this option to <quote>onPremisesImmutableId</quote> is the usual " +"choice for such deployments. Microsoft Entra Connect populates that " +"attribute with the base64-encoded form of the 16-byte Active Directory " +"<quote>objectGUID</quote> when objectGUID is used as the sourceAnchor. SSSD " +"decodes the value and converts the raw bytes with the same conversion used " +"for AD objectGUID attributes, so the result matches the UUID stored in the " +"SSSD cache for the AD user." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:224 +msgid "" +"Note that Microsoft Entra Connect 1.1.524.0 and later use " +"<quote>ms-DS-ConsistencyGuid</quote> as the sourceAnchor for user objects " +"instead of <quote>objectGUID</quote>. The value is normally copied from " +"objectGUID for objects that do not have it set yet, in which case the " +"decoded identifier still matches. It does not match if ms-DS-ConsistencyGuid " +"was populated independently, if users were moved between forests or domains, " +"or if a different attribute such as employeeID was selected as the " +"sourceAnchor. See <ulink " +"url=\"https://learn.microsoft.com/en-us/entra/identity/hybrid/connect/plan-connect-design-concepts\"> " +"Microsoft Entra Connect: Design concepts</ulink> for details on sourceAnchor " +"selection." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:241 +msgid "" +"Microsoft Graph does not return <quote>onPremisesImmutableId</quote> by " +"default. The <quote>idp_userinfo_endpoint</quote> must request it with " +"<quote>$select</quote>, see the example below and <ulink " +"url=\"https://learn.microsoft.com/en-us/graph/api/resources/user\"> the " +"Microsoft Graph user resource type</ulink>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:251 +msgid "" +"If the configured attribute is missing or cannot be decoded (for example " +"cloud-only Entra ID users without <quote>onPremisesImmutableId</quote>), " +"authentication fails. SSSD does not fall back to another attribute when this " +"option is set." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:258 +msgid "" +"Default: not set, <quote>sub</quote> for Keycloak and <quote>id</quote> for " +"other IdP types" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-idp.5.xml:264 +msgid "idp_request_timeout (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:267 +msgid "Timeout in seconds for an individual request to the IdP." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-idp.5.xml:276 +msgid "idp_auto_refresh (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:279 +msgid "" +"Refresh tokens automatically, after they have reached about half their " +"lifetime." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:283 +msgid "Note: Scheduled token refreshes are not preserved across restarts of SSSD." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-idp.5.xml:292 +msgid "idmap_range_min (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:295 +msgid "" +"Specifies the lower (inclusive) bound of the range of POSIX IDs to use for " +"mapping IdP users and group to POSIX IDs. It is the first POSIX ID which can " +"be used for the mapping." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:301 +msgid "" +"The interval between <quote>idmap_range_min</quote> and " +"<quote>idmap_range_max</quote> will be split into smaller ranges of size " +"<quote>idmap_range_size</quote> which will be used by an individual IdP " +"domain." +msgstr "" + +#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:308 sssd-idp.5.xml:334 include/ldap_id_mapping.xml:139 +#: include/ldap_id_mapping.xml:197 +msgid "Default: 200000" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-idp.5.xml:313 +msgid "idmap_range_max (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:316 +msgid "" +"Specifies the upper (exclusive) bound of the range of POSIX IDs to use for " +"mapping IdP users and groups to POSIX IDs. It is the first POSIX ID which " +"will not be used for POSIX ID-mapping anymore." +msgstr "" + +#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:322 include/ldap_id_mapping.xml:165 +msgid "Default: 2000200000" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-idp.5.xml:327 +msgid "idmap_range_size (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:330 +msgid "Specifies the number of POSIX IDs available for a single IdP domain." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><programlisting> +#: sssd-idp.5.xml:346 +#, no-wrap +msgid "" +"[domain/entra_id]\n" +"id_provider = idp\n" +"idp_type = entra_id\n" +"idp_client_id = 12345678-abcd-0101-efef-ba9876543210\n" +"idp_client_secret = YOUR-CLIENT-SECRET\n" +"idp_token_endpoint = " +"https://login.microsoftonline.com/TENANT-ID/oauth2/v2.0/token\n" +"idp_userinfo_endpoint = https://graph.microsoft.com/v1.0/me\n" +"idp_device_auth_endpoint = " +"https://login.microsoftonline.com/TENANT-ID/oauth2/v2.0/devicecode\n" +"idp_id_scope = https://graph.microsoft.com/.default\n" +"idp_auth_scope = openid profile email\n" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><programlisting> +#: sssd-idp.5.xml:358 +#, no-wrap +msgid "" +"[domain/ad.example.com]\n" +"id_provider = ad\n" +"auth_provider = idp\n" +"access_provider = permit\n" +"\n" +"ad_domain = ad.example.com\n" +"krb5_realm = AD.EXAMPLE.COM\n" +"\n" +"idp_type = entra_id\n" +"idp_client_id = 12345678-abcd-0101-efef-ba9876543210\n" +"idp_client_secret = YOUR-CLIENT-SECRET\n" +"idp_token_endpoint = " +"https://login.microsoftonline.com/TENANT-ID/oauth2/v2.0/token\n" +"idp_userinfo_endpoint = " +"https://graph.microsoft.com/v1.0/me?$select=id,userPrincipalName,onPremisesImmutableId\n" +"idp_device_auth_endpoint = " +"https://login.microsoftonline.com/TENANT-ID/oauth2/v2.0/devicecode\n" +"idp_id_scope = https://graph.microsoft.com/.default\n" +"idp_auth_scope = openid profile email\n" +"idp_auth_user_identifier_attr = onPremisesImmutableId\n" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><programlisting> +#: sssd-idp.5.xml:377 +#, no-wrap +msgid "" +"[domain/keycloak]\n" +"idp_type = " +"keycloak:https://master.keycloak.test:8443/auth/admin/realms/master/\n" +"id_provider = idp\n" +"idp_client_id = myclient\n" +"idp_client_secret = YOUR-CLIENT-SECRET\n" +"idp_token_endpoint = " +"https://master.keycloak.test:8443/auth/realms/master/protocol/openid-connect/token\n" +"idp_userinfo_endpoint = " +"https://master.keycloak.test:8443/auth/realms/master/protocol/openid-connect/userinfo\n" +"idp_device_auth_endpoint = " +"https://master.keycloak.test:8443/auth/realms/master/protocol/openid-connect/auth/device\n" +"idp_id_scope = profile\n" +"idp_auth_scope = openid profile email\n" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-idp.5.xml:345 +msgid "" +"<placeholder type=\"programlisting\" id=\"0\"/> <placeholder " +"type=\"programlisting\" id=\"1\"/> <placeholder type=\"programlisting\" " +"id=\"2\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-idp.5.xml:390 +msgid "" +"In the hybrid Active Directory and Entra ID example above, " +"<quote>onPremisesImmutableId</quote> is used during authentication so the " +"IdP result matches the AD objectGUID UUID stored in the SSSD cache. The " +"attribute must be requested via <quote>$select</quote> on the Graph userinfo " +"endpoint and is only populated for users synchronized from Active Directory " +"with objectGUID as the sourceAnchor." +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refname> +#: sssd.8.xml:10 sssd.8.xml:15 +msgid "sssd" +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refpurpose> +#: sssd.8.xml:16 +msgid "System Security Services Daemon" +msgstr "" + +#. type: Content of: <reference><refentry><refsynopsisdiv><cmdsynopsis> +#: sssd.8.xml:21 +msgid "" +"<command>sssd</command> <arg choice='opt'> " +"<replaceable>options</replaceable> </arg>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.8.xml:31 +msgid "" +"<command>SSSD</command> provides a set of daemons to manage access to remote " +"directories and authentication mechanisms. It provides an NSS and PAM " +"interface toward the system and a pluggable backend system to connect to " +"multiple different account sources as well as D-Bus interface. It is also " +"the basis to provide client auditing and policy services for projects like " +"FreeIPA. It provides a more robust database to store local users as well as " +"extended user data." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sssd.8.xml:46 +msgid "" +"<option>-d</option>,<option>--debug-level</option> " +"<replaceable>LEVEL</replaceable>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sssd.8.xml:53 +msgid "<option>--debug-timestamps=</option><replaceable>mode</replaceable>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd.8.xml:57 +msgid "<emphasis>1</emphasis>: Add a timestamp to the debug messages" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd.8.xml:60 +msgid "<emphasis>0</emphasis>: Disable timestamp in the debug messages" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sssd.8.xml:69 +msgid "<option>--debug-microseconds=</option><replaceable>mode</replaceable>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd.8.xml:73 +msgid "<emphasis>1</emphasis>: Add microseconds to the timestamp in debug messages" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd.8.xml:76 +msgid "<emphasis>0</emphasis>: Disable microseconds in timestamp" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sssd.8.xml:85 +msgid "<option>--logger=</option><replaceable>value</replaceable>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd.8.xml:89 +msgid "Location where SSSD will send log messages." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd.8.xml:92 +msgid "" +"<emphasis>stderr</emphasis>: Redirect debug messages to standard error " +"output." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd.8.xml:96 +msgid "" +"<emphasis>files</emphasis>: Redirect debug messages to the log files. By " +"default, the log files are stored in <filename>/var/log/sssd</filename> and " +"there are separate log files for every SSSD service and domain." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd.8.xml:102 +msgid "<emphasis>journald</emphasis>: Redirect debug messages to systemd-journald" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd.8.xml:106 +msgid "Default: not set (fall back to journald if available, otherwise to stderr)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sssd.8.xml:113 +msgid "<option>-D</option>,<option>--daemon</option>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd.8.xml:117 +msgid "Become a daemon after starting up." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sssd.8.xml:123 sss_seed.8.xml:136 +msgid "<option>-i</option>,<option>--interactive</option>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd.8.xml:127 +msgid "Run in the foreground, don't become a daemon." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sssd.8.xml:133 +msgid "<option>-c</option>,<option>--config</option>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd.8.xml:137 +msgid "" +"Specify a non-default config file. The default is " +"<filename>/etc/sssd/sssd.conf</filename>. For reference on the config file " +"syntax and options, consult the <citerefentry> " +"<refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</manvolnum> " +"</citerefentry> manual page." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sssd.8.xml:151 +msgid "<option>--version</option>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd.8.xml:155 +msgid "Print version number and exit." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd.8.xml:163 +msgid "Signals" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sssd.8.xml:166 +msgid "SIGTERM/SIGINT" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd.8.xml:169 +msgid "" +"Informs the SSSD to gracefully terminate all of its child processes and then " +"shut down the monitor." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sssd.8.xml:175 +msgid "SIGHUP" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd.8.xml:178 +msgid "" +"Tells the SSSD to stop writing to its current debug file descriptors and to " +"close and reopen them. This is meant to facilitate log rolling with programs " +"like logrotate." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sssd.8.xml:186 +msgid "SIGUSR1" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd.8.xml:189 +msgid "" +"Tells the SSSD to simulate offline operation for the duration of the " +"<quote>offline_timeout</quote> parameter. This is useful for testing. The " +"signal can be sent to either the sssd process or any sssd_be process " +"directly." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sssd.8.xml:198 +msgid "SIGUSR2" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd.8.xml:201 +msgid "" +"Tells the SSSD to go online immediately. This is useful for testing. The " +"signal can be sent to either the sssd process or any sssd_be process " +"directly." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sssd.8.xml:208 +msgid "SIGRTMIN+1" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd.8.xml:211 +msgid "" +"Tells the SSSD to reschedule the periodic tasks. The internal watchdog sends " +"this signal to the providers when a clock shift is detected although it can " +"be sent to any sssd_be process directly." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd.8.xml:223 sss_ssh_authorizedkeys.1.xml:141 sss_ssh_knownhosts.1.xml:116 +msgid "EXIT STATUS" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sssd.8.xml:226 +msgid "0" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd.8.xml:229 +msgid "SSSD was shutdown gracefully." +msgstr "" + +#. type: Content of: <reference><refentry><refmeta><manvolnum> +#: sssd.8.xml:234 sss_ssh_authorizedkeys.1.xml:11 sss_ssh_knownhosts.1.xml:11 +msgid "1" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd.8.xml:237 +msgid "Bad configuration or command line option." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sssd.8.xml:242 +msgid "2" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd.8.xml:245 +msgid "Memory allocation error." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sssd.8.xml:250 +msgid "6" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd.8.xml:253 +msgid "SSSD is already running." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sssd.8.xml:258 +msgid "Other codes" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd.8.xml:261 +msgid "" +"Other codes denote different errors, most probably about missing required " +"access rights. See SSSD and system logs for details." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.8.xml:272 +msgid "" +"If the environment variable SSS_NSS_USE_MEMCACHE is set to \"NO\", client " +"applications will not use the fast in-memory cache." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.8.xml:276 +msgid "" +"If the environment variable SSS_LOCKFREE is set to \"NO\", requests from " +"multiple threads of a single application will be serialized." +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refname> +#: sss_obfuscate.8.xml:10 sss_obfuscate.8.xml:15 +msgid "sss_obfuscate" +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refpurpose> +#: sss_obfuscate.8.xml:16 +msgid "obfuscate a clear text password" +msgstr "" + +#. type: Content of: <reference><refentry><refsynopsisdiv><cmdsynopsis> +#: sss_obfuscate.8.xml:21 +msgid "" +"<command>sss_obfuscate</command> <arg choice='opt'> " +"<replaceable>options</replaceable> </arg> <arg " +"choice='plain'><replaceable>[PASSWORD]</replaceable></arg>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sss_obfuscate.8.xml:32 +msgid "" +"<command>sss_obfuscate</command> converts a given password into " +"human-unreadable format and places it into appropriate domain section of the " +"SSSD config file." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sss_obfuscate.8.xml:37 +msgid "" +"The cleartext password is read from standard input or entered " +"interactively. The obfuscated password is put into " +"<quote>ldap_default_authtok</quote> parameter of a given SSSD domain and the " +"<quote>ldap_default_authtok_type</quote> parameter is set to " +"<quote>obfuscated_password</quote>. Refer to <citerefentry> " +"<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> " +"</citerefentry> for more details on these parameters." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sss_obfuscate.8.xml:49 +msgid "" +"Please note that obfuscating the password provides <emphasis>no real " +"security benefit</emphasis> as it is still possible for an attacker to " +"reverse-engineer the password back. Using better authentication mechanisms " +"such as client side certificates or GSSAPI is <emphasis>strongly</emphasis> " +"advised." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sss_obfuscate.8.xml:63 +msgid "<option>-s</option>,<option>--stdin</option>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sss_obfuscate.8.xml:67 +msgid "The password to obfuscate will be read from standard input." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sss_obfuscate.8.xml:74 sss_ssh_authorizedkeys.1.xml:127 +#: sss_ssh_knownhosts.1.xml:63 +msgid "" +"<option>-d</option>,<option>--domain</option> " +"<replaceable>DOMAIN</replaceable>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sss_obfuscate.8.xml:79 +msgid "" +"The SSSD domain to use the password in. The default name is " +"<quote>default</quote>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sss_obfuscate.8.xml:86 +msgid "<option>-f</option>,<option>--file</option> <replaceable>FILE</replaceable>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sss_obfuscate.8.xml:91 +msgid "Read the config file specified by the positional parameter." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sss_obfuscate.8.xml:95 +msgid "Default: <filename>/etc/sssd/sssd.conf</filename>" +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refname> +#: sss_override.8.xml:10 sss_override.8.xml:15 +msgid "sss_override" +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refpurpose> +#: sss_override.8.xml:16 +msgid "create local overrides of user and group attributes" +msgstr "" + +#. type: Content of: <reference><refentry><refsynopsisdiv><cmdsynopsis> +#: sss_override.8.xml:21 +msgid "" +"<command>sss_override</command> <arg " +"choice='plain'><replaceable>COMMAND</replaceable></arg> <arg choice='opt'> " +"<replaceable>options</replaceable> </arg>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sss_override.8.xml:32 +msgid "" +"<command>sss_override</command> enables to create a client-side view and " +"allows to change selected values of specific user and groups. This change " +"takes effect only on local machine." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sss_override.8.xml:37 +msgid "" +"Overrides data are stored in the SSSD cache. If the cache is deleted, all " +"local overrides are lost. Please note that after the first override is " +"created using any of the following <emphasis>user-add</emphasis>, " +"<emphasis>group-add</emphasis>, <emphasis>user-import</emphasis> or " +"<emphasis>group-import</emphasis> command. SSSD needs to be restarted to " +"take effect. <emphasis>sss_override</emphasis> prints message when a " +"restart is required." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sss_override.8.xml:48 +msgid "" +"<emphasis>NOTE:</emphasis> The options provided in this man page only work " +"with <quote>ldap</quote> and <quote>AD</quote> <quote> " +"id_provider</quote>. IPA overrides can be managed centrally on the IPA " +"server." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sss_override.8.xml:56 sssctl.8.xml:41 +msgid "AVAILABLE COMMANDS" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sss_override.8.xml:58 +msgid "" +"Argument <emphasis>NAME</emphasis> is the name of original object in all " +"commands. It is not possible to override <emphasis>uid</emphasis> or " +"<emphasis>gid</emphasis> to 0." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sss_override.8.xml:65 +msgid "" +"<option>user-add</option> <emphasis>NAME</emphasis> " +"<optional><option>-n,--name</option> NAME</optional> " +"<optional><option>-u,--uid</option> UID</optional> " +"<optional><option>-g,--gid</option> GID</optional> " +"<optional><option>-h,--home</option> HOME</optional> " +"<optional><option>-s,--shell</option> SHELL</optional> " +"<optional><option>-c,--gecos</option> GECOS</optional> " +"<optional><option>-x,--certificate</option> BASE64 ENCODED " +"CERTIFICATE</optional>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sss_override.8.xml:78 +msgid "" +"Override attributes of an user. Please be aware that calling this command " +"will replace any previous override for the (NAMEd) user." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sss_override.8.xml:86 +msgid "<option>user-del</option> <emphasis>NAME</emphasis>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sss_override.8.xml:91 +msgid "" +"Remove user overrides. However be aware that overridden attributes might be " +"returned from memory cache. Please see SSSD option " +"<emphasis>memcache_timeout</emphasis> for more details." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sss_override.8.xml:100 +msgid "" +"<option>user-find</option> <optional><option>-d,--domain</option> " +"DOMAIN</optional>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sss_override.8.xml:105 +msgid "" +"List all users with set overrides. If <emphasis>DOMAIN</emphasis> parameter " +"is set, only users from the domain are listed." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sss_override.8.xml:113 +msgid "<option>user-show</option> <emphasis>NAME</emphasis>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sss_override.8.xml:118 +msgid "Show user overrides." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sss_override.8.xml:124 +msgid "<option>user-import</option> <emphasis>FILE</emphasis>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sss_override.8.xml:129 +msgid "" +"Import user overrides from <emphasis>FILE</emphasis>. Data format is " +"similar to standard passwd file. The format is:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sss_override.8.xml:134 +msgid "original_name:name:uid:gid:gecos:home:shell:base64_encoded_certificate" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sss_override.8.xml:137 +msgid "" +"where original_name is original name of the user whose attributes should be " +"overridden. The rest of fields correspond to new values. You can omit a " +"value simply by leaving corresponding field empty." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sss_override.8.xml:146 +msgid "ckent:superman::::::" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sss_override.8.xml:149 +msgid "ckent@krypton.com::501:501:Superman:/home/earth:/bin/bash:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sss_override.8.xml:155 +msgid "<option>user-export</option> <emphasis>FILE</emphasis>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sss_override.8.xml:160 +msgid "" +"Export all overridden attributes and store them in " +"<emphasis>FILE</emphasis>. See <emphasis>user-import</emphasis> for data " +"format." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sss_override.8.xml:168 +msgid "" +"<option>group-add</option> <emphasis>NAME</emphasis> " +"<optional><option>-n,--name</option> NAME</optional> " +"<optional><option>-g,--gid</option> GID</optional>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sss_override.8.xml:175 +msgid "" +"Override attributes of a group. Please be aware that calling this command " +"will replace any previous override for the (NAMEd) group." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sss_override.8.xml:183 +msgid "<option>group-del</option> <emphasis>NAME</emphasis>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sss_override.8.xml:188 +msgid "" +"Remove group overrides. However be aware that overridden attributes might be " +"returned from memory cache. Please see SSSD option " +"<emphasis>memcache_timeout</emphasis> for more details." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sss_override.8.xml:197 +msgid "" +"<option>group-find</option> <optional><option>-d,--domain</option> " +"DOMAIN</optional>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sss_override.8.xml:202 +msgid "" +"List all groups with set overrides. If <emphasis>DOMAIN</emphasis> " +"parameter is set, only groups from the domain are listed." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sss_override.8.xml:210 +msgid "<option>group-show</option> <emphasis>NAME</emphasis>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sss_override.8.xml:215 +msgid "Show group overrides." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sss_override.8.xml:221 +msgid "<option>group-import</option> <emphasis>FILE</emphasis>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sss_override.8.xml:226 +msgid "" +"Import group overrides from <emphasis>FILE</emphasis>. Data format is " +"similar to standard group file. The format is:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sss_override.8.xml:231 +msgid "original_name:name:gid" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sss_override.8.xml:234 +msgid "" +"where original_name is original name of the group whose attributes should be " +"overridden. The rest of fields correspond to new values. You can omit a " +"value simply by leaving corresponding field empty." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sss_override.8.xml:243 +msgid "admins:administrators:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sss_override.8.xml:246 +msgid "Domain Users:Users:501" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sss_override.8.xml:252 +msgid "<option>group-export</option> <emphasis>FILE</emphasis>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sss_override.8.xml:257 +msgid "" +"Export all overridden attributes and store them in " +"<emphasis>FILE</emphasis>. See <emphasis>group-import</emphasis> for data " +"format." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sss_override.8.xml:267 sssctl.8.xml:50 +msgid "COMMON OPTIONS" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sss_override.8.xml:269 sssctl.8.xml:52 +msgid "Those options are available with all commands." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sss_override.8.xml:274 sssctl.8.xml:57 +msgid "<option>--debug</option> <replaceable>LEVEL</replaceable>" +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refname> +#: sssd-krb5.5.xml:10 sssd-krb5.5.xml:16 +msgid "sssd-krb5" +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refpurpose> +#: sssd-krb5.5.xml:17 +msgid "SSSD Kerberos provider" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-krb5.5.xml:23 +msgid "" +"This manual page describes the configuration of the Kerberos 5 " +"authentication backend for <citerefentry> " +"<refentrytitle>sssd</refentrytitle> <manvolnum>8</manvolnum> " +"</citerefentry>. For a detailed syntax reference, please refer to the " +"<quote>FILE FORMAT</quote> section of the <citerefentry> " +"<refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</manvolnum> " +"</citerefentry> manual page." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-krb5.5.xml:36 +msgid "" +"The Kerberos 5 authentication backend contains auth and chpass providers. It " +"must be paired with an identity provider in order to function properly (for " +"example, id_provider = ldap). Some information required by the Kerberos 5 " +"authentication backend must be provided by the identity provider, such as " +"the user's Kerberos Principal Name (UPN). The configuration of the identity " +"provider should have an entry to specify the UPN. Please refer to the man " +"page for the applicable identity provider for details on how to configure " +"this." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-krb5.5.xml:47 +msgid "" +"This backend also provides access control based on the .k5login file in the " +"home directory of the user. See <citerefentry> " +"<refentrytitle>k5login</refentrytitle><manvolnum>5</manvolnum> " +"</citerefentry> for more details. Please note that an empty .k5login file " +"will deny all access to this user. To activate this feature, use " +"'access_provider = krb5' in your SSSD configuration." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-krb5.5.xml:55 +msgid "" +"In the case where the UPN is not available in the identity backend, " +"<command>sssd</command> will construct a UPN using the format " +"<replaceable>username</replaceable>@<replaceable>krb5_realm</replaceable>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-krb5.5.xml:77 +msgid "" +"Specifies the comma-separated list of IP addresses or hostnames of the " +"Kerberos servers to which SSSD should connect, in the order of " +"preference. For more information on failover and server redundancy, see the " +"<quote>FAILOVER</quote> section. An optional port number (preceded by a " +"colon) may be appended to the addresses or hostnames. If empty, service " +"discovery is enabled; for more information, refer to the <quote>SERVICE " +"DISCOVERY</quote> section." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-krb5.5.xml:106 +msgid "" +"The name of the Kerberos realm. This option is required and must be " +"specified." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-krb5.5.xml:113 +msgid "krb5_kpasswd, krb5_backup_kpasswd (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-krb5.5.xml:116 +msgid "" +"If the change password service is not running on the KDC, alternative " +"servers can be defined here. An optional port number (preceded by a colon) " +"may be appended to the addresses or hostnames." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-krb5.5.xml:122 +msgid "" +"For more information on failover and server redundancy, see the " +"<quote>FAILOVER</quote> section. NOTE: Even if there are no more kpasswd " +"servers to try, the backend is not switched to operate offline if " +"authentication against the KDC is still possible." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-krb5.5.xml:129 +msgid "Default: Use the KDC" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-krb5.5.xml:135 +msgid "krb5_ccachedir (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-krb5.5.xml:138 +msgid "" +"Directory to store credential caches. All the substitution sequences of " +"krb5_ccname_template can be used here, too, except %d and %P. The directory " +"is created as private and owned by the user, with permissions set to 0700." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-krb5.5.xml:145 +msgid "Default: /tmp" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-krb5.5.xml:151 +msgid "krb5_ccname_template (string)" +msgstr "" + +#. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd-krb5.5.xml:165 include/override_homedir.xml:11 +msgid "%u" +msgstr "" + +#. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd-krb5.5.xml:166 include/override_homedir.xml:12 +msgid "login name" +msgstr "" + +#. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd-krb5.5.xml:169 include/override_homedir.xml:15 +msgid "%U" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd-krb5.5.xml:170 +msgid "login UID" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd-krb5.5.xml:173 +msgid "%p" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd-krb5.5.xml:174 +msgid "principal name" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd-krb5.5.xml:178 +msgid "%r" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd-krb5.5.xml:179 +msgid "realm name" +msgstr "" + +#. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd-krb5.5.xml:182 include/override_homedir.xml:53 +msgid "%h" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd-krb5.5.xml:183 sssd-ifp.5.xml:128 +msgid "home directory" +msgstr "" + +#. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd-krb5.5.xml:187 include/override_homedir.xml:19 +msgid "%d" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd-krb5.5.xml:188 +msgid "value of krb5_ccachedir" +msgstr "" + +#. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd-krb5.5.xml:193 include/override_homedir.xml:31 +msgid "%P" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd-krb5.5.xml:194 +msgid "the process ID of the SSSD client" +msgstr "" + +#. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd-krb5.5.xml:199 include/override_homedir.xml:68 +msgid "%%" +msgstr "" + +#. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd-krb5.5.xml:200 include/override_homedir.xml:69 +msgid "a literal '%'" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-krb5.5.xml:154 +msgid "" +"Location of the user's credential cache. Three credential cache types are " +"currently supported: <quote>FILE</quote>, <quote>DIR</quote> and " +"<quote>KEYRING:persistent</quote>. The cache can be specified either as " +"<replaceable>TYPE:RESIDUAL</replaceable>, or as an absolute path, which " +"implies the <quote>FILE</quote> type. In the template, the following " +"sequences are substituted: <placeholder type=\"variablelist\" id=\"0\"/> If " +"the template ends with 'XXXXXX' mkstemp(3) is used to create a unique " +"filename in a safe way." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-krb5.5.xml:208 +msgid "" +"When using KEYRING types, the only supported mechanism is " +"<quote>KEYRING:persistent:%U</quote>, which uses the Linux kernel keyring to " +"store credentials on a per-UID basis. This is also the recommended choice, " +"as it is the most secure and predictable method." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-krb5.5.xml:216 +msgid "" +"The default value for the credential cache name is sourced from the profile " +"stored in the system wide krb5.conf configuration file in the [libdefaults] " +"section. The option name is default_ccache_name. See krb5.conf(5)'s " +"PARAMETER EXPANSION paragraph for additional information on the expansion " +"format defined by krb5.conf." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-krb5.5.xml:225 +msgid "" +"NOTE: Please be aware that libkrb5 ccache expansion template from " +"<citerefentry> <refentrytitle>krb5.conf</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry> uses different expansion sequences " +"than SSSD." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-krb5.5.xml:234 +msgid "Default: (from libkrb5)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-krb5.5.xml:240 +msgid "krb5_keytab (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-krb5.5.xml:243 +msgid "" +"The location of the keytab to use when validating credentials obtained from " +"KDCs." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-krb5.5.xml:253 +msgid "krb5_store_password_if_offline (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-krb5.5.xml:256 +msgid "" +"Store the password of the user if the provider is offline and use it to " +"request a TGT when the provider comes online again." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-krb5.5.xml:261 +msgid "" +"NOTE: this feature is only available on Linux. Passwords stored in this way " +"are kept in plaintext in the kernel keyring and are potentially accessible " +"by the root user (with difficulty)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-krb5.5.xml:274 +msgid "krb5_use_fast (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-krb5.5.xml:277 +msgid "" +"Enables flexible authentication secure tunneling (FAST) for Kerberos " +"pre-authentication. The following options are supported:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-krb5.5.xml:282 +msgid "" +"<emphasis>never</emphasis> use FAST. This is equivalent to not setting this " +"option at all." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-krb5.5.xml:286 +msgid "" +"<emphasis>try</emphasis> to use FAST. If the server does not support FAST, " +"continue the authentication without it." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-krb5.5.xml:291 +msgid "" +"<emphasis>demand</emphasis> to use FAST. The authentication fails if the " +"server does not support FAST." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-krb5.5.xml:296 +msgid "Default: not set, i.e. FAST is not used." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-krb5.5.xml:299 +msgid "NOTE: a keytab or support for anonymous PKINIT is required to use FAST." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-krb5.5.xml:303 +msgid "" +"NOTE: SSSD supports FAST only with MIT Kerberos version 1.8 and later. If " +"SSSD is used with an older version of MIT Kerberos, using this option is a " +"configuration error." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-krb5.5.xml:312 +msgid "krb5_fast_principal (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-krb5.5.xml:315 +msgid "Specifies the server principal to use for FAST." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-krb5.5.xml:321 +msgid "krb5_fast_use_anonymous_pkinit (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-krb5.5.xml:324 +msgid "" +"If set to true try to use anonymous PKINIT instead of a keytab to get the " +"required credential for FAST. The krb5_fast_principal options is ignored in " +"this case." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-krb5.5.xml:364 +msgid "krb5_kdcinfo_lookahead (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-krb5.5.xml:367 +msgid "" +"When krb5_use_kdcinfo is set to true, you can limit the amount of servers " +"handed to <citerefentry> " +"<refentrytitle>sssd_krb5_locator_plugin</refentrytitle> " +"<manvolnum>8</manvolnum> </citerefentry>. This might be helpful when there " +"are too many servers discovered using SRV record." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-krb5.5.xml:377 +msgid "" +"The krb5_kdcinfo_lookahead option contains two numbers separated by a " +"colon. The first number represents number of primary servers used and the " +"second number specifies the number of backup servers." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-krb5.5.xml:383 +msgid "" +"For example <emphasis>10:0</emphasis> means that up to 10 primary servers " +"will be handed to <citerefentry> " +"<refentrytitle>sssd_krb5_locator_plugin</refentrytitle> " +"<manvolnum>8</manvolnum> </citerefentry> but no backup servers." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-krb5.5.xml:392 +msgid "Default: 3:1" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-krb5.5.xml:398 +msgid "krb5_use_enterprise_principal (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-krb5.5.xml:401 +msgid "" +"Specifies if the user principal should be treated as enterprise " +"principal. See section 5 of RFC 6806 for more details about enterprise " +"principals." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-krb5.5.xml:407 +msgid "Default: false (AD provider: true)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-krb5.5.xml:410 +msgid "" +"The IPA provider will set to option to 'true' if it detects that the server " +"is capable of handling enterprise principals and the option is not set " +"explicitly in the config file." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-krb5.5.xml:419 +msgid "krb5_use_subdomain_realm (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-krb5.5.xml:422 +msgid "" +"Specifies to use subdomains realms for the authentication of users from " +"trusted domains. This option can be set to 'true' if enterprise principals " +"are used with upnSuffixes which are not known on the parent domain KDCs. If " +"the option is set to 'true' SSSD will try to send the request directly to a " +"KDC of the trusted domain the user is coming from." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-krb5.5.xml:438 +msgid "krb5_map_user (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-krb5.5.xml:441 +msgid "" +"The list of mappings is given as a comma-separated list of pairs " +"<quote>username:primary</quote> where <quote>username</quote> is a UNIX user " +"name and <quote>primary</quote> is a user part of a kerberos principal. This " +"mapping is used when user is authenticating using <quote>auth_provider = " +"krb5</quote>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> +#: sssd-krb5.5.xml:453 +#, no-wrap +msgid "" +"krb5_realm = REALM\n" +"krb5_map_user = joe:juser,dick:richard\n" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-krb5.5.xml:458 +msgid "" +"<quote>joe</quote> and <quote>dick</quote> are UNIX user names and " +"<quote>juser</quote> and <quote>richard</quote> are primaries of kerberos " +"principals. For user <quote>joe</quote> resp. <quote>dick</quote> SSSD will " +"try to kinit as <quote>juser@REALM</quote> resp. " +"<quote>richard@REALM</quote>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-krb5.5.xml:65 +msgid "" +"If the auth-module krb5 is used in an SSSD domain, the following options " +"must be used. See the <citerefentry> " +"<refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</manvolnum> " +"</citerefentry> manual page, section <quote>DOMAIN SECTIONS</quote>, for " +"details on the configuration of an SSSD domain. <placeholder " +"type=\"variablelist\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-krb5.5.xml:485 +msgid "" +"The following example assumes that SSSD is correctly configured and FOO is " +"one of the domains in the <replaceable>[sssd]</replaceable> section. This " +"example shows only configuration of Kerberos authentication; it does not " +"include any identity provider." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><programlisting> +#: sssd-krb5.5.xml:493 +#, no-wrap +msgid "" +"[domain/FOO]\n" +"auth_provider = krb5\n" +"krb5_server = 192.168.1.1\n" +"krb5_realm = EXAMPLE.COM\n" +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refname> +#: sss_cache.8.xml:10 sss_cache.8.xml:15 +msgid "sss_cache" +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refpurpose> +#: sss_cache.8.xml:16 +msgid "perform cache cleanup" +msgstr "" + +#. type: Content of: <reference><refentry><refsynopsisdiv><cmdsynopsis> +#: sss_cache.8.xml:21 +msgid "" +"<command>sss_cache</command> <arg choice='opt'> " +"<replaceable>options</replaceable> </arg>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sss_cache.8.xml:31 +msgid "" +"<command>sss_cache</command> invalidates records in SSSD cache. Invalidated " +"records are forced to be reloaded from server as soon as related SSSD " +"backend is online. Options that invalidate a single object only accept a " +"single provided argument." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sss_cache.8.xml:43 +msgid "<option>-E</option>,<option>--everything</option>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sss_cache.8.xml:47 +msgid "Invalidate all cached entries." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sss_cache.8.xml:53 +msgid "<option>-u</option>,<option>--user</option> <replaceable>login</replaceable>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sss_cache.8.xml:58 +msgid "Invalidate specific user." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sss_cache.8.xml:64 +msgid "<option>-U</option>,<option>--users</option>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sss_cache.8.xml:68 +msgid "" +"Invalidate all user records. This option overrides invalidation of specific " +"user if it was also set." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sss_cache.8.xml:75 +msgid "" +"<option>-g</option>,<option>--group</option> " +"<replaceable>group</replaceable>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sss_cache.8.xml:80 +msgid "Invalidate specific group." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sss_cache.8.xml:86 +msgid "<option>-G</option>,<option>--groups</option>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sss_cache.8.xml:90 +msgid "" +"Invalidate all group records. This option overrides invalidation of specific " +"group if it was also set." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sss_cache.8.xml:97 +msgid "" +"<option>-n</option>,<option>--netgroup</option> " +"<replaceable>netgroup</replaceable>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sss_cache.8.xml:102 +msgid "Invalidate specific netgroup." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sss_cache.8.xml:108 +msgid "<option>-N</option>,<option>--netgroups</option>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sss_cache.8.xml:112 +msgid "" +"Invalidate all netgroup records. This option overrides invalidation of " +"specific netgroup if it was also set." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sss_cache.8.xml:119 +msgid "" +"<option>-s</option>,<option>--service</option> " +"<replaceable>service</replaceable>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sss_cache.8.xml:124 +msgid "Invalidate specific service." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sss_cache.8.xml:130 +msgid "<option>-S</option>,<option>--services</option>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sss_cache.8.xml:134 +msgid "" +"Invalidate all service records. This option overrides invalidation of " +"specific service if it was also set." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sss_cache.8.xml:141 +msgid "" +"<option>-a</option>,<option>--autofs-map</option> " +"<replaceable>autofs-map</replaceable>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sss_cache.8.xml:146 +msgid "Invalidate specific autofs maps." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sss_cache.8.xml:152 +msgid "<option>-A</option>,<option>--autofs-maps</option>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sss_cache.8.xml:156 +msgid "" +"Invalidate all autofs maps. This option overrides invalidation of specific " +"map if it was also set." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sss_cache.8.xml:163 +msgid "" +"<option>-h</option>,<option>--ssh-host</option> " +"<replaceable>hostname</replaceable>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sss_cache.8.xml:168 +msgid "Invalidate SSH public keys of a specific host." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sss_cache.8.xml:174 +msgid "<option>-H</option>,<option>--ssh-hosts</option>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sss_cache.8.xml:178 +msgid "" +"Invalidate SSH public keys of all hosts. This option overrides invalidation " +"of SSH public keys of specific host if it was also set." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sss_cache.8.xml:186 +msgid "" +"<option>-r</option>,<option>--sudo-rule</option> " +"<replaceable>rule</replaceable>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sss_cache.8.xml:191 +msgid "Invalidate particular sudo rule." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sss_cache.8.xml:197 +msgid "<option>-R</option>,<option>--sudo-rules</option>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sss_cache.8.xml:201 +msgid "" +"Invalidate all cached sudo rules. This option overrides invalidation of " +"specific sudo rule if it was also set." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sss_cache.8.xml:209 +msgid "" +"<option>-d</option>,<option>--domain</option> " +"<replaceable>domain</replaceable>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sss_cache.8.xml:214 +msgid "Restrict invalidation process only to a particular domain." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sss_cache.8.xml:224 +msgid "EFFECTS ON THE FAST MEMORY CACHE" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sss_cache.8.xml:226 +msgid "" +"<command>sss_cache</command> also invalidates the memory cache. Since the " +"memory cache is a file which is mapped into the memory of each process which " +"called SSSD to resolve users or groups the file cannot be truncated. A " +"special flag is set in the header of the file to indicate that the content " +"is invalid and then the file is unlinked by SSSD's NSS responder and a new " +"cache file is created. Whenever a process is now doing a new lookup for a " +"user or a group it will see the flag, close the old memory cache file and " +"map the new one into its memory. When all processes which had opened the old " +"memory cache file have closed it while looking up a user or a group the " +"kernel can release the occupied disk space and the old memory cache file is " +"finally removed completely." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sss_cache.8.xml:240 +msgid "" +"A special case is long running processes which are doing user or group " +"lookups only at startup, e.g. to determine the name of the user the process " +"is running as. For those lookups the memory cache file is mapped into the " +"memory of the process. But since there will be no further lookups this " +"process would never detect if the memory cache file was invalidated and " +"hence it will be kept in memory and will occupy disk space until the process " +"stops. As a result calling <command>sss_cache</command> might increase the " +"disk usage because old memory cache files cannot be removed from the disk " +"because they are still mapped by long running processes." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sss_cache.8.xml:252 +msgid "" +"A possible work-around for long running processes which are looking up users " +"and groups only at startup or very rarely is to run them with the " +"environment variable SSS_NSS_USE_MEMCACHE set to \"NO\" so that they won't " +"use the memory cache at all and not map the memory cache file into the " +"memory. In general a better solution is to tune the cache timeout parameters " +"so that they meet the local expectations and calling " +"<command>sss_cache</command> is not needed." +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refname> +#: sss_debuglevel.8.xml:10 sss_debuglevel.8.xml:15 +msgid "sss_debuglevel" +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refpurpose> +#: sss_debuglevel.8.xml:16 +msgid "[DEPRECATED] change debug level while SSSD is running" +msgstr "" + +#. type: Content of: <reference><refentry><refsynopsisdiv><cmdsynopsis> +#: sss_debuglevel.8.xml:21 +msgid "" +"<command>sss_debuglevel</command> <arg choice='opt'> " +"<replaceable>options</replaceable> </arg> <arg " +"choice='plain'><replaceable>NEW_DEBUG_LEVEL</replaceable></arg>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sss_debuglevel.8.xml:32 +msgid "" +"<command>sss_debuglevel</command> is deprecated and replaced by the sssctl " +"debug-level command. Please refer to the <command>sssctl</command> man page " +"for more information on sssctl usage." +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refname> +#: sss_seed.8.xml:10 sss_seed.8.xml:15 +msgid "sss_seed" +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refpurpose> +#: sss_seed.8.xml:16 +msgid "seed the SSSD cache with a user" +msgstr "" + +#. type: Content of: <reference><refentry><refsynopsisdiv><cmdsynopsis> +#: sss_seed.8.xml:21 +msgid "" +"<command>sss_seed</command> <arg choice='opt'> " +"<replaceable>options</replaceable> </arg> <arg choice='plain'>-D " +"<replaceable>DOMAIN</replaceable></arg> <arg choice='plain'>-n " +"<replaceable>USER</replaceable></arg>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sss_seed.8.xml:33 +msgid "" +"<command>sss_seed</command> seeds the SSSD cache with a user entry and " +"temporary password. If a user entry is already present in the SSSD cache " +"then the entry is updated with the temporary password." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sss_seed.8.xml:46 +msgid "" +"<option>-D</option>,<option>--domain</option> " +"<replaceable>DOMAIN</replaceable>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sss_seed.8.xml:51 +msgid "" +"Provide the name of the domain in which the user is a member of. The domain " +"is also used to retrieve user information. The domain must be configured in " +"sssd.conf. The <replaceable>DOMAIN</replaceable> option must be provided. " +"Information retrieved from the domain overrides what is provided in the " +"options." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sss_seed.8.xml:63 +msgid "" +"<option>-n</option>,<option>--username</option> " +"<replaceable>USER</replaceable>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sss_seed.8.xml:68 +msgid "" +"The username of the entry to be created or modified in the cache. The " +"<replaceable>USER</replaceable> option must be provided." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sss_seed.8.xml:76 +msgid "<option>-u</option>,<option>--uid</option> <replaceable>UID</replaceable>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sss_seed.8.xml:81 +msgid "Set the UID of the user to <replaceable>UID</replaceable>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sss_seed.8.xml:88 +msgid "<option>-g</option>,<option>--gid</option> <replaceable>GID</replaceable>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sss_seed.8.xml:93 +msgid "Set the GID of the user to <replaceable>GID</replaceable>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sss_seed.8.xml:100 +msgid "" +"<option>-c</option>,<option>--gecos</option> " +"<replaceable>COMMENT</replaceable>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sss_seed.8.xml:105 +msgid "" +"Any text string describing the user. Often used as the field for the user's " +"full name." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sss_seed.8.xml:112 +msgid "" +"<option>-h</option>,<option>--home</option> " +"<replaceable>HOME_DIR</replaceable>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sss_seed.8.xml:117 +msgid "Set the home directory of the user to <replaceable>HOME_DIR</replaceable>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sss_seed.8.xml:124 +msgid "" +"<option>-s</option>,<option>--shell</option> " +"<replaceable>SHELL</replaceable>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sss_seed.8.xml:129 +msgid "Set the login shell of the user to <replaceable>SHELL</replaceable>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sss_seed.8.xml:140 +msgid "" +"Interactive mode for entering user information. This option will only prompt " +"for information not provided in the options or retrieved from the domain." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sss_seed.8.xml:148 +msgid "" +"<option>-p</option>,<option>--password-file</option> " +"<replaceable>PASS_FILE</replaceable>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sss_seed.8.xml:153 +msgid "" +"Specify file to read user's password from. (if not specified password is " +"prompted for)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sss_seed.8.xml:165 +msgid "" +"The length of the password (or the size of file specified with -p or " +"--password-file option) must be less than or equal to PASS_MAX bytes (64 " +"bytes on systems with no globally-defined PASS_MAX value)." +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refname> +#: sssd-ifp.5.xml:10 sssd-ifp.5.xml:16 +msgid "sssd-ifp" +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refpurpose> +#: sssd-ifp.5.xml:17 +msgid "SSSD InfoPipe responder" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-ifp.5.xml:23 +msgid "" +"This manual page describes the configuration of the InfoPipe responder for " +"<citerefentry> <refentrytitle>sssd</refentrytitle> <manvolnum>8</manvolnum> " +"</citerefentry>. For a detailed syntax reference, refer to the <quote>FILE " +"FORMAT</quote> section of the <citerefentry> " +"<refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</manvolnum> " +"</citerefentry> manual page." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-ifp.5.xml:36 +msgid "" +"The InfoPipe responder provides a public D-Bus interface accessible over the " +"system bus. The interface allows the user to query information about remote " +"users and groups over the system bus." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><title> +#: sssd-ifp.5.xml:43 +msgid "FIND BY VALID CERTIFICATE" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd-ifp.5.xml:45 +msgid "" +"The following options can be used to control how the certificates are " +"validated when using the FindByValidCertificate() API:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> +#: sssd-ifp.5.xml:48 sss_ssh_authorizedkeys.1.xml:92 +msgid "ca_db" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> +#: sssd-ifp.5.xml:49 sss_ssh_authorizedkeys.1.xml:93 +msgid "p11_child_timeout" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> +#: sssd-ifp.5.xml:50 sss_ssh_authorizedkeys.1.xml:94 +msgid "certificate_verification" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd-ifp.5.xml:52 +msgid "" +"For more details about the options see " +"<citerefentry><refentrytitle>sssd.conf</refentrytitle> " +"<manvolnum>5</manvolnum></citerefentry>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-ifp.5.xml:62 +msgid "These options can be used to configure the InfoPipe responder." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd-ifp.5.xml:69 +msgid "" +"Specifies the comma-separated list of UID values or user names that are " +"allowed to access the InfoPipe responder. User names are resolved to UIDs at " +"startup." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd-ifp.5.xml:75 +msgid "Default: 0 (only the root user is allowed to access the InfoPipe responder)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd-ifp.5.xml:79 +msgid "" +"Please note that although the UID 0 is used as the default it will be " +"overwritten with this option. If you still want to allow the root user to " +"access the InfoPipe responder, which would be the typical case, you have to " +"add 0 to the list of allowed UIDs as well." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd-ifp.5.xml:93 +msgid "" +"Specifies the comma-separated list of white or blacklisted attributes. This " +"option only applies to the <quote>Users</quote> interface. The deprecated " +"<quote>GetUserAttr</quote> interface does not utilize this option, it allows " +"any attribute requested." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd-ifp.5.xml:111 +msgid "name" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd-ifp.5.xml:112 +msgid "user's login name" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd-ifp.5.xml:115 +msgid "uidNumber" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd-ifp.5.xml:116 +msgid "user ID" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd-ifp.5.xml:119 +msgid "gidNumber" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd-ifp.5.xml:120 +msgid "primary group ID" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd-ifp.5.xml:123 +msgid "gecos" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd-ifp.5.xml:124 +msgid "user information, typically full name" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd-ifp.5.xml:127 +msgid "homeDirectory" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd-ifp.5.xml:131 +msgid "loginShell" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd-ifp.5.xml:132 +msgid "user shell" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd-ifp.5.xml:101 +msgid "" +"By default, the InfoPipe responder `/Users` interface only allows the " +"default set of POSIX attributes to be requested. This set is the same as " +"returned by <citerefentry> <refentrytitle>getpwnam</refentrytitle> " +"<manvolnum>3</manvolnum> </citerefentry> and includes: <placeholder " +"type=\"variablelist\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><programlisting> +#: sssd-ifp.5.xml:147 +#, no-wrap +msgid "" +"user_attributes = +telephoneNumber, -loginShell\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd-ifp.5.xml:137 +msgid "" +"It is possible to add another attribute to this set by using " +"<quote>+attr_name</quote> or explicitly remove an attribute using " +"<quote>-attr_name</quote>. Added attributes will be made available in the " +"<quote>extraAttributes</quote> array. For example, to allow " +"<quote>telephoneNumber</quote> but deny <quote>loginShell</quote>, you would " +"use the following configuration: <placeholder type=\"programlisting\" " +"id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd-ifp.5.xml:151 +msgid "Default: not set. Only the default set of POSIX attributes is allowed." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd-ifp.5.xml:161 +msgid "" +"Specifies an upper limit on the number of entries that are downloaded during " +"a wildcard lookup that overrides caller-supplied limit." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd-ifp.5.xml:166 +msgid "Default: 0 (let the caller set an upper limit)" +msgstr "" + +#. type: Content of: <reference><refentry><refentryinfo> +#: sss_rpcidmapd.5.xml:8 +msgid "" +"<productname>sss rpc.idmapd plugin</productname> <author> " +"<firstname>Noam</firstname> <surname>Meltzer</surname> <affiliation> " +"<orgname>Primary Data Inc.</orgname> </affiliation> <contrib>Developer " +"(2013-2014)</contrib> </author> <author> <firstname>Noam</firstname> " +"<surname>Meltzer</surname> <contrib>Developer (2014-)</contrib> " +"<email>tsnoam@gmail.com</email> </author>" +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refname> +#: sss_rpcidmapd.5.xml:26 sss_rpcidmapd.5.xml:32 +msgid "sss_rpcidmapd" +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refpurpose> +#: sss_rpcidmapd.5.xml:33 +msgid "sss plugin configuration directives for rpc.idmapd" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sss_rpcidmapd.5.xml:37 +msgid "CONFIGURATION FILE" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sss_rpcidmapd.5.xml:39 +msgid "" +"rpc.idmapd configuration file is usually found at " +"<emphasis>/etc/idmapd.conf</emphasis>. See <citerefentry> " +"<refentrytitle>idmapd.conf</refentrytitle> <manvolnum>5</manvolnum> " +"</citerefentry> for more information." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sss_rpcidmapd.5.xml:49 +msgid "SSS CONFIGURATION EXTENSION" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><title> +#: sss_rpcidmapd.5.xml:51 +msgid "Enable SSS plugin" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sss_rpcidmapd.5.xml:53 +msgid "" +"In section <quote>[Translation]</quote>, modify/set <quote>Method</quote> " +"attribute to contain <emphasis>sss</emphasis>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><title> +#: sss_rpcidmapd.5.xml:59 +msgid "[sss] config section" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sss_rpcidmapd.5.xml:61 +msgid "" +"In order to change the default of one of the configuration attributes of the " +"<emphasis>sss</emphasis> plugin listed below you will need to create a " +"config section for it, named <quote>[sss]</quote>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><title> +#: sss_rpcidmapd.5.xml:67 +msgid "Configuration attributes" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sss_rpcidmapd.5.xml:69 +msgid "memcache (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sss_rpcidmapd.5.xml:72 +msgid "Indicates whether or not to use memcache optimisation technique." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sss_rpcidmapd.5.xml:85 +msgid "SSSD INTEGRATION" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sss_rpcidmapd.5.xml:87 +msgid "" +"The sss plugin requires the <emphasis>NSS Responder</emphasis> to be enabled " +"in sssd." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sss_rpcidmapd.5.xml:91 +msgid "" +"The attribute <quote>use_fully_qualified_names</quote> must be enabled on " +"all domains (NFSv4 clients expect a fully qualified name to be sent on the " +"wire)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><programlisting> +#: sss_rpcidmapd.5.xml:103 +#, no-wrap +msgid "" +"[General]\n" +"Verbosity = 2\n" +"# domain must be synced between NFSv4 server and clients\n" +"# Solaris/Illumos/AIX use \"localdomain\" as default!\n" +"Domain = default\n" +"\n" +"[Mapping]\n" +"Nobody-User = nfsnobody\n" +"Nobody-Group = nfsnobody\n" +"\n" +"[Translation]\n" +"Method = sss\n" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sss_rpcidmapd.5.xml:100 +msgid "" +"The following example shows a minimal idmapd.conf which makes use of the sss " +"plugin. <placeholder type=\"programlisting\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <refsect1><title> +#: sss_rpcidmapd.5.xml:120 sssd-kcm.8.xml:315 include/seealso.xml:2 +msgid "SEE ALSO" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sss_rpcidmapd.5.xml:122 +msgid "" +"<citerefentry> <refentrytitle>sssd</refentrytitle><manvolnum>8</manvolnum> " +"</citerefentry>, <citerefentry> <refentrytitle>idmapd.conf</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry>" +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refname> +#: sss_ssh_authorizedkeys.1.xml:10 sss_ssh_authorizedkeys.1.xml:15 +msgid "sss_ssh_authorizedkeys" +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refpurpose> +#: sss_ssh_authorizedkeys.1.xml:16 +msgid "get OpenSSH authorized keys" +msgstr "" + +#. type: Content of: <reference><refentry><refsynopsisdiv><cmdsynopsis> +#: sss_ssh_authorizedkeys.1.xml:21 +msgid "" +"<command>sss_ssh_authorizedkeys</command> <arg choice='opt'> " +"<replaceable>options</replaceable> </arg> <arg " +"choice='plain'><replaceable>USER</replaceable></arg>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sss_ssh_authorizedkeys.1.xml:32 +msgid "" +"<command>sss_ssh_authorizedkeys</command> acquires SSH public keys for user " +"<replaceable>USER</replaceable> and outputs them in OpenSSH authorized_keys " +"format (see the <quote>AUTHORIZED_KEYS FILE FORMAT</quote> section of " +"<citerefentry><refentrytitle>sshd</refentrytitle> " +"<manvolnum>8</manvolnum></citerefentry> for more information)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sss_ssh_authorizedkeys.1.xml:41 +msgid "" +"<citerefentry><refentrytitle>sshd</refentrytitle> " +"<manvolnum>8</manvolnum></citerefentry> can be configured to use " +"<command>sss_ssh_authorizedkeys</command> for public key user authentication " +"if it is compiled with support for <quote>AuthorizedKeysCommand</quote> " +"option. Please refer to the <citerefentry> " +"<refentrytitle>sshd_config</refentrytitle> " +"<manvolnum>5</manvolnum></citerefentry> man page for more details about this " +"option." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><programlisting> +#: sss_ssh_authorizedkeys.1.xml:59 +#, no-wrap +msgid "" +" AuthorizedKeysCommand /usr/bin/sss_ssh_authorizedkeys\n" +" AuthorizedKeysCommandUser nobody\n" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sss_ssh_authorizedkeys.1.xml:52 +msgid "" +"If <quote>AuthorizedKeysCommand</quote> is supported, " +"<citerefentry><refentrytitle>sshd</refentrytitle> " +"<manvolnum>8</manvolnum></citerefentry> can be configured to use it by " +"putting the following directives in <citerefentry> " +"<refentrytitle>sshd_config</refentrytitle> " +"<manvolnum>5</manvolnum></citerefentry>: <placeholder " +"type=\"programlisting\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><title> +#: sss_ssh_authorizedkeys.1.xml:65 +msgid "KEYS FROM CERTIFICATES" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sss_ssh_authorizedkeys.1.xml:67 +msgid "" +"In addition to the public SSH keys for user <replaceable>USER</replaceable> " +"<command>sss_ssh_authorizedkeys</command> can return public SSH keys derived " +"from the public key of a X.509 certificate as well." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sss_ssh_authorizedkeys.1.xml:73 +msgid "" +"To enable this the <quote>ssh_use_certificate_keys</quote> option must be " +"set to true (default) in the [ssh] section of " +"<filename>sssd.conf</filename>. If the user entry contains certificates (see " +"<quote>ldap_user_certificate</quote> in " +"<citerefentry><refentrytitle>sssd-ldap</refentrytitle> " +"<manvolnum>5</manvolnum></citerefentry> for details) or there is a " +"certificate in an override entry for the user (see " +"<citerefentry><refentrytitle>sss_override</refentrytitle> " +"<manvolnum>8</manvolnum></citerefentry> or " +"<citerefentry><refentrytitle>sssd-ipa</refentrytitle> " +"<manvolnum>5</manvolnum></citerefentry> for details) and the certificate is " +"valid SSSD will extract the public key from the certificate and convert it " +"into the format expected by sshd." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sss_ssh_authorizedkeys.1.xml:90 +msgid "Besides <quote>ssh_use_certificate_keys</quote> the options" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sss_ssh_authorizedkeys.1.xml:96 +msgid "" +"can be used to control how the certificates are validated (see " +"<citerefentry><refentrytitle>sssd.conf</refentrytitle> " +"<manvolnum>5</manvolnum></citerefentry> for details)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sss_ssh_authorizedkeys.1.xml:101 +msgid "" +"The validation is the benefit of using X.509 certificates instead of SSH " +"keys directly because e.g. it gives a better control of the lifetime of the " +"keys. When the ssh client is configured to use the private keys from a " +"Smartcard with the help of a PKCS#11 shared library (see " +"<citerefentry><refentrytitle>ssh</refentrytitle> " +"<manvolnum>1</manvolnum></citerefentry> for details) it might be irritating " +"that authentication is still working even if the related X.509 certificate " +"on the Smartcard is already expired because neither <command>ssh</command> " +"nor <command>sshd</command> will look at the certificate at all." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sss_ssh_authorizedkeys.1.xml:114 +msgid "" +"It has to be noted that the derived public SSH key can still be added to the " +"<filename>authorized_keys</filename> file of the user to bypass the " +"certificate validation if the <command>sshd</command> configuration permits " +"this." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sss_ssh_authorizedkeys.1.xml:132 +msgid "" +"Search for user public keys in SSSD domain " +"<replaceable>DOMAIN</replaceable>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sss_ssh_authorizedkeys.1.xml:143 +msgid "" +"In case of success, an exit value of 0 is returned. Otherwise, 1 is " +"returned." +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refname> +#: sss_ssh_knownhosts.1.xml:10 sss_ssh_knownhosts.1.xml:15 +msgid "sss_ssh_knownhosts" +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refpurpose> +#: sss_ssh_knownhosts.1.xml:16 +msgid "get OpenSSH known hosts public keys" +msgstr "" + +#. type: Content of: <reference><refentry><refsynopsisdiv><cmdsynopsis> +#: sss_ssh_knownhosts.1.xml:21 +msgid "" +"<command>sss_ssh_knownhosts</command> <arg choice='opt'> " +"<replaceable>options</replaceable> </arg> <arg " +"choice='plain'><replaceable>HOST</replaceable></arg>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sss_ssh_knownhosts.1.xml:32 +msgid "" +"<command>sss_ssh_knownhosts</command> acquires SSH public keys for host " +"<replaceable>HOST</replaceable> and outputs them in OpenSSH known_hosts key " +"format (see the <quote>SSH_KNOWN_HOSTS FILE FORMAT</quote> section of " +"<citerefentry><refentrytitle>sshd</refentrytitle> " +"<manvolnum>8</manvolnum></citerefentry> for more information)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><programlisting> +#: sss_ssh_knownhosts.1.xml:47 +#, no-wrap +msgid "" +" KnownHostsCommand /usr/bin/sss_ssh_knownhosts %H\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sss_ssh_knownhosts.1.xml:41 +msgid "" +"<citerefentry><refentrytitle>ssh</refentrytitle> " +"<manvolnum>1</manvolnum></citerefentry> can be configured to use " +"<command>sss_ssh_knownhosts</command> for public key host authentication " +"using the <quote>KnownHostsCommand</quote> option: <placeholder " +"type=\"programlisting\" id=\"0\"/> Please refer to the <citerefentry> " +"<refentrytitle>ssh_config</refentrytitle><manvolnum>5</manvolnum> " +"</citerefentry> man page for more details about this option." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sss_ssh_knownhosts.1.xml:54 +msgid "This tool requires that SSSD's ssh service is enabled to work properly." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sss_ssh_knownhosts.1.xml:68 +msgid "" +"Search for host public keys in SSSD domain " +"<replaceable>DOMAIN</replaceable>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sss_ssh_knownhosts.1.xml:75 +msgid "<option>-o</option>,<option>--only-host-name</option>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sss_ssh_knownhosts.1.xml:79 +msgid "" +"When the keys retrieved from the backend do not include the hostname, this " +"tool will add the unmodified hostname as provided by the caller. If this " +"flag is set, only the hostname (no port number) will be added to the keys." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sss_ssh_knownhosts.1.xml:91 +msgid "KEY RETRIEVAL" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sss_ssh_knownhosts.1.xml:93 +msgid "" +"The key lines retrieved from the backend are expected to respect the key " +"format as described in the <quote>SSH_KNOWN_HOSTS FILE FORMAT</quote> " +"section of <citerefentry><refentrytitle>sshd</refentrytitle> " +"<manvolnum>8</manvolnum></citerefentry>. However, returning only the keytype " +"and the key itself is tolerated, in which case, the hostname received as " +"parameter will be added before the keytype to output a correctly formatted " +"line. The hostname will be added unmodified or just the hostname (no port " +"number), depending on whether the " +"<option>-o</option>,<option>--only-host-name</option> option was provided." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><programlisting> +#: sss_ssh_knownhosts.1.xml:110 +#, no-wrap +msgid "" +" [canonical.host.name]:2222 <keytype> " +"<base64-encoded key>\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sss_ssh_knownhosts.1.xml:105 +msgid "" +"When the SSH server is listening on a non-default port, the backend MUST " +"provide the hostname including the port number in the correct format and " +"position as part of the key line. For example, the minimal key line would " +"be: <placeholder type=\"programlisting\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sss_ssh_knownhosts.1.xml:118 +msgid "" +"In case of successful execution, even if no key was found for that host or " +"if the ssh responder could not be contacted, 0 is returned. 1 is returned " +"in case of any other error." +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refname> +#: idmap_sss.8.xml:10 idmap_sss.8.xml:15 +msgid "idmap_sss" +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refpurpose> +#: idmap_sss.8.xml:16 +msgid "SSSD's idmap_sss Backend for Winbind" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: idmap_sss.8.xml:22 +msgid "" +"The idmap_sss module provides a way to call SSSD to map UIDs/GIDs and " +"SIDs. No database is required in this case as the mapping is done by SSSD." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: idmap_sss.8.xml:29 +msgid "IDMAP OPTIONS" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: idmap_sss.8.xml:33 +msgid "range = low - high" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: idmap_sss.8.xml:35 +msgid "" +"Defines the available matching UID and GID range for which the backend is " +"authoritative." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: idmap_sss.8.xml:45 +msgid "This example shows how to configure idmap_sss as the default mapping module." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><programlisting> +#: idmap_sss.8.xml:50 +#, no-wrap +msgid "" +"[global]\n" +"security = ads\n" +"workgroup = <AD-DOMAIN-SHORTNAME>\n" +"\n" +"idmap config <AD-DOMAIN-SHORTNAME> : backend = sss\n" +"idmap config <AD-DOMAIN-SHORTNAME> : range = " +"200000-2147483647\n" +"\n" +"idmap config * : backend = tdb\n" +"idmap config * : range = 100000-199999\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: idmap_sss.8.xml:62 +msgid "" +"Please replace <AD-DOMAIN-SHORTNAME> with the NetBIOS domain name of " +"the AD domain. If multiple AD domains should be used each domain needs an " +"<literal>idmap config</literal> line with <literal>backend = sss</literal> " +"and a line with a suitable <literal>range</literal>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: idmap_sss.8.xml:69 +msgid "" +"Since Winbind requires a writeable default backend and idmap_sss is " +"read-only the example includes <literal>backend = tdb</literal> as default." +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refname> +#: sssctl.8.xml:10 sssctl.8.xml:15 +msgid "sssctl" +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refpurpose> +#: sssctl.8.xml:16 +msgid "SSSD control and status utility" +msgstr "" + +#. type: Content of: <reference><refentry><refsynopsisdiv><cmdsynopsis> +#: sssctl.8.xml:21 +msgid "" +"<command>sssctl</command> <arg " +"choice='plain'><replaceable>COMMAND</replaceable></arg> <arg choice='opt'> " +"<replaceable>options</replaceable> </arg>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssctl.8.xml:32 +msgid "" +"<command>sssctl</command> provides a simple and unified way to obtain " +"information about SSSD status, such as active server, auto-discovered " +"servers, domains and cached objects. In addition, it can manage SSSD data " +"files for troubleshooting in such a way that is safe to manipulate while " +"SSSD is running." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssctl.8.xml:43 +msgid "" +"To list all available commands run <command>sssctl</command> without any " +"parameters. To print help for selected command run <command>sssctl COMMAND " +"--help</command>." +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refname> +#: sssd-session-recording.5.xml:10 sssd-session-recording.5.xml:16 +msgid "sssd-session-recording" +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refpurpose> +#: sssd-session-recording.5.xml:17 +msgid "Configuring session recording with SSSD" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-session-recording.5.xml:23 +msgid "" +"This manual page describes how to configure <citerefentry> " +"<refentrytitle>sssd</refentrytitle> <manvolnum>8</manvolnum> </citerefentry> " +"to work with <citerefentry> <refentrytitle>tlog-rec-session</refentrytitle> " +"<manvolnum>8</manvolnum> </citerefentry>, a part of tlog package, to " +"implement user session recording on text terminals. For a detailed " +"configuration syntax reference, refer to the <quote>FILE FORMAT</quote> " +"section of the <citerefentry> <refentrytitle>sssd.conf</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry> manual page." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-session-recording.5.xml:41 +msgid "" +"SSSD can be set up to enable recording of everything specific users see or " +"type during their sessions on text terminals. E.g. when users log in on the " +"console, or via SSH. SSSD itself doesn't record anything, but makes sure " +"tlog-rec-session is started upon user login, so it can record according to " +"its configuration." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-session-recording.5.xml:48 +msgid "" +"For users with session recording enabled, SSSD replaces the user shell with " +"tlog-rec-session in NSS responses, and adds a variable specifying the " +"original shell to the user environment, upon PAM session setup. This way " +"tlog-rec-session can be started in place of the user shell, and know which " +"actual shell to start, once it set up the recording." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-session-recording.5.xml:60 +msgid "These options can be used to configure the session recording." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-session-recording.5.xml:178 +msgid "" +"The following snippet of sssd.conf enables session recording for users " +"\"contractor1\" and \"contractor2\", and group \"students\"." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><programlisting> +#: sssd-session-recording.5.xml:183 +#, no-wrap +msgid "" +"[session_recording]\n" +"scope = some\n" +"users = contractor1, contractor2\n" +"groups = students\n" +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refname> +#: sssd-kcm.8.xml:10 sssd-kcm.8.xml:16 +msgid "sssd-kcm" +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refpurpose> +#: sssd-kcm.8.xml:17 +msgid "SSSD Kerberos Cache Manager" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-kcm.8.xml:23 +msgid "" +"This manual page describes the configuration of the SSSD Kerberos Cache " +"Manager (KCM). KCM is a process that stores, tracks and manages Kerberos " +"credential caches. It originates in the Heimdal Kerberos project, although " +"the MIT Kerberos library also provides client side (more details on that " +"below) support for the KCM credential cache." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-kcm.8.xml:31 +msgid "" +"In a setup where Kerberos caches are managed by KCM, the Kerberos library " +"(typically used through an application, like e.g., <citerefentry> " +"<refentrytitle>kinit</refentrytitle><manvolnum>1</manvolnum> " +"</citerefentry>, is a <quote>\"KCM client\"</quote> and the KCM daemon is " +"being referred to as a <quote>\"KCM server\"</quote>. The client and server " +"communicate over a UNIX socket." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-kcm.8.xml:42 +msgid "" +"The KCM server keeps track of each credential caches's owner and performs " +"access check control based on the UID and GID of the KCM client." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-kcm.8.xml:47 +msgid "The KCM credential cache has several interesting properties:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><itemizedlist><listitem><para> +#: sssd-kcm.8.xml:51 +msgid "" +"since the process runs in userspace, it is subject to UID namespacing, " +"unlike the kernel keyring" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><itemizedlist><listitem><para> +#: sssd-kcm.8.xml:56 +msgid "" +"unlike the kernel keyring-based cache, which is shared between all " +"containers, the KCM server is a separate process whose entry point is a UNIX " +"socket" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><itemizedlist><listitem><para> +#: sssd-kcm.8.xml:61 +msgid "" +"the SSSD implementation stores the ccaches in a database, typically located " +"at <replaceable>/var/lib/sss/secrets</replaceable> allowing the ccaches to " +"survive KCM server restarts or machine reboots." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-kcm.8.xml:67 +msgid "" +"This allows the system to use a collection-aware credential cache, yet share " +"the credential cache between some or no containers by bind-mounting the " +"socket." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-kcm.8.xml:72 +msgid "" +"The KCM default client idle timeout is 5 minutes, this allows more time for " +"user interaction with command line tools such as kinit." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd-kcm.8.xml:78 +msgid "USING THE KCM CREDENTIAL CACHE" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><programlisting> +#: sssd-kcm.8.xml:88 +#, no-wrap +msgid "" +"[libdefaults]\n" +" default_ccache_name = KCM:\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-kcm.8.xml:80 +msgid "" +"In order to use KCM credential cache, it must be selected as the default " +"credential type in <citerefentry> " +"<refentrytitle>krb5.conf</refentrytitle><manvolnum>5</manvolnum> " +"</citerefentry>, The credentials cache name must be only <quote>KCM:</quote> " +"without any template expansions. For example: <placeholder " +"type=\"programlisting\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-kcm.8.xml:93 +msgid "" +"Next, make sure the Kerberos client libraries and the KCM server must agree " +"on the UNIX socket path. By default, both use the same path " +"<replaceable>/var/run/.heim_org.h5l.kcm-socket</replaceable>. To configure " +"the Kerberos library, change its <quote>kcm_socket</quote> option which is " +"described in the <citerefentry> " +"<refentrytitle>krb5.conf</refentrytitle><manvolnum>5</manvolnum> " +"</citerefentry> manual page." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><programlisting> +#: sssd-kcm.8.xml:115 +#, no-wrap +msgid "" +"systemctl start sssd-kcm.socket\n" +"systemctl enable sssd-kcm.socket\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-kcm.8.xml:104 +msgid "" +"Finally, make sure the SSSD KCM server can be contacted. The KCM service is " +"typically socket-activated by <citerefentry> " +"<refentrytitle>systemd</refentrytitle> <manvolnum>1</manvolnum> " +"</citerefentry>. Unlike other SSSD services, it cannot be started by adding " +"the <quote>kcm</quote> string to the <quote>service</quote> directive. " +"<placeholder type=\"programlisting\" id=\"0\"/> Please note your " +"distribution may already configure the units for you." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd-kcm.8.xml:124 +msgid "THE CREDENTIAL CACHE STORAGE" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-kcm.8.xml:126 +msgid "" +"The credential caches are stored in a database, much like SSSD caches user " +"or group entries. The database is typically located at " +"<quote>/var/lib/sss/secrets</quote>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd-kcm.8.xml:133 +msgid "OBTAINING DEBUG LOGS" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><programlisting> +#: sssd-kcm.8.xml:144 +#, no-wrap +msgid "" +"[kcm]\n" +"debug_level = 10\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><programlisting> +#: sssd-kcm.8.xml:149 sssd-kcm.8.xml:211 +#, no-wrap +msgid "" +"systemctl restart sssd-kcm.service\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-kcm.8.xml:135 +msgid "" +"The sssd-kcm service is typically socket-activated <citerefentry> " +"<refentrytitle>systemd</refentrytitle> <manvolnum>1</manvolnum> " +"</citerefentry>. To generate debug logs, add the following either to the " +"<filename>/etc/sssd/sssd.conf</filename> file directly or as a configuration " +"snippet to <filename>/etc/sssd/conf.d/</filename> directory: <placeholder " +"type=\"programlisting\" id=\"0\"/> Then, restart the sssd-kcm service: " +"<placeholder type=\"programlisting\" id=\"1\"/> Finally, run whatever " +"use-case doesn't work for you. The KCM logs will be generated at " +"<filename>/var/log/sssd/sssd_kcm.log</filename>. It is recommended to " +"disable the debug logs when you no longer need the debugging to be enabled " +"as the sssd-kcm service can generate quite a large amount of debugging " +"information." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-kcm.8.xml:159 +msgid "" +"Please note that configuration snippets are, at the moment, only processed " +"if the main configuration file at <filename>/etc/sssd/sssd.conf</filename> " +"exists at all." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd-kcm.8.xml:166 +msgid "RENEWALS" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><programlisting> +#: sssd-kcm.8.xml:174 +#, no-wrap +msgid "" +"tgt_renewal = true\n" +"krb5_renew_interval = 60m\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-kcm.8.xml:168 +msgid "" +"The sssd-kcm service can be configured to attempt TGT renewal for renewable " +"TGTs stored in the KCM ccache. Renewals are only attempted when half of the " +"ticket lifetime has been reached. KCM Renewals are configured when the " +"following options are set in the [kcm] section: <placeholder " +"type=\"programlisting\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-kcm.8.xml:179 +msgid "SSSD can also inherit krb5 options for renewals from an existing domain." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><programlisting> +#: sssd-kcm.8.xml:183 +#, no-wrap +msgid "" +"tgt_renewal = true\n" +"tgt_renewal_inherit = domain-name\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><programlisting> +#: sssd-kcm.8.xml:191 +#, no-wrap +msgid "" +"krb5_renew_interval\n" +"krb5_renewable_lifetime\n" +"krb5_lifetime\n" +"krb5_validate\n" +"krb5_canonicalize\n" +"krb5_auth_timeout\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-kcm.8.xml:187 +msgid "" +"The following krb5 options can be configured in the [kcm] section to control " +"renewal behavior, these options are described in detail below <placeholder " +"type=\"programlisting\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-kcm.8.xml:204 +msgid "" +"The KCM service is configured in the <quote>kcm</quote> section of the " +"sssd.conf file. Please note that because the KCM service is typically " +"socket-activated, it is enough to just restart the <quote>sssd-kcm</quote> " +"service after changing options in the <quote>kcm</quote> section of " +"sssd.conf: <placeholder type=\"programlisting\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-kcm.8.xml:215 +msgid "" +"For a detailed syntax reference, refer to the <quote>FILE FORMAT</quote> " +"section of the <citerefentry> <refentrytitle>sssd.conf</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry> manual page." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-kcm.8.xml:222 +msgid "" +"The generic SSSD service options such as <quote>debug_level</quote> or " +"<quote>fd_limit</quote> are accepted by the kcm service. Please refer to " +"the <citerefentry> <refentrytitle>sssd.conf</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry> manual page for a complete list. In " +"addition, there are some KCM-specific options as well." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sssd-kcm.8.xml:233 +msgid "socket_path (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd-kcm.8.xml:236 +msgid "The socket the KCM service will listen on." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd-kcm.8.xml:239 +msgid "Default: <replaceable>/var/run/.heim_org.h5l.kcm-socket</replaceable>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd-kcm.8.xml:242 +msgid "" +"<phrase condition=\"have_systemd\"> Note: on platforms where systemd is " +"supported, the socket path is overwritten by the one defined in the " +"sssd-kcm.socket unit file. </phrase>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sssd-kcm.8.xml:251 +msgid "max_ccaches (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd-kcm.8.xml:254 +msgid "How many credential caches does the KCM database allow for all users." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd-kcm.8.xml:258 +msgid "Default: 0 (unlimited, only the per-UID quota is enforced)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sssd-kcm.8.xml:263 +msgid "max_uid_ccaches (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd-kcm.8.xml:266 +msgid "" +"How many credential caches does the KCM database allow per UID. This is " +"equivalent to <quote>with how many principals you can kinit</quote>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd-kcm.8.xml:271 +msgid "Default: 64" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sssd-kcm.8.xml:276 +msgid "max_ccache_size (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd-kcm.8.xml:279 +msgid "" +"How big a credential cache be per ccache. Each service ticket counts toward " +"this quota." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd-kcm.8.xml:283 +msgid "Default: 65536" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sssd-kcm.8.xml:288 +msgid "tgt_renewal (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd-kcm.8.xml:291 +msgid "Enables TGT renewals functionality." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd-kcm.8.xml:294 +msgid "Default: False (Automatic renewals disabled)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sssd-kcm.8.xml:299 +msgid "tgt_renewal_inherit (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd-kcm.8.xml:302 +msgid "Domain to inherit krb5_* options from, for use with TGT renewals." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd-kcm.8.xml:306 +msgid "Default: NULL" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-kcm.8.xml:317 +msgid "" +"<citerefentry> <refentrytitle>sssd</refentrytitle><manvolnum>8</manvolnum> " +"</citerefentry>, <citerefentry> " +"<refentrytitle>sssd.conf</refentrytitle><manvolnum>5</manvolnum> " +"</citerefentry>," +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refname> +#: sssd-systemtap.5.xml:10 sssd-systemtap.5.xml:16 +msgid "sssd-systemtap" +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refpurpose> +#: sssd-systemtap.5.xml:17 +msgid "SSSD systemtap information" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-systemtap.5.xml:23 +msgid "" +"This manual page provides information about the systemtap functionality in " +"<citerefentry> <refentrytitle>sssd</refentrytitle> <manvolnum>8</manvolnum> " +"</citerefentry>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-systemtap.5.xml:32 +msgid "" +"SystemTap Probe points have been added into various locations in SSSD code " +"to assist in troubleshooting and analyzing performance related issues." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><itemizedlist><listitem><para> +#: sssd-systemtap.5.xml:40 +msgid "Sample SystemTap scripts are provided in /usr/share/sssd/systemtap/" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><itemizedlist><listitem><para> +#: sssd-systemtap.5.xml:46 +msgid "" +"Probes and miscellaneous functions are defined in " +"/usr/share/systemtap/tapset/sssd.stp and " +"/usr/share/systemtap/tapset/sssd_functions.stp respectively." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd-systemtap.5.xml:57 +msgid "PROBE POINTS" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd-systemtap.5.xml:59 sssd-systemtap.5.xml:367 +msgid "" +"The information below lists the probe points and arguments available in the " +"following format:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sssd-systemtap.5.xml:64 +msgid "probe $name" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd-systemtap.5.xml:67 +msgid "Description of probe point" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><programlisting> +#: sssd-systemtap.5.xml:70 +#, no-wrap +msgid "" +"variable1:datatype\n" +"variable2:datatype\n" +"variable3:datatype\n" +"...\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><title> +#: sssd-systemtap.5.xml:80 +msgid "Database Transaction Probes" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sssd-systemtap.5.xml:84 +msgid "probe sssd_transaction_start" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd-systemtap.5.xml:87 +msgid "Start of a sysdb transaction, probes the sysdb_transaction_start() function." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><programlisting> +#: sssd-systemtap.5.xml:91 sssd-systemtap.5.xml:105 sssd-systemtap.5.xml:118 +#: sssd-systemtap.5.xml:131 +#, no-wrap +msgid "" +"nesting:integer\n" +"probestr:string\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sssd-systemtap.5.xml:97 +msgid "probe sssd_transaction_cancel" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd-systemtap.5.xml:100 +msgid "" +"Cancellation of a sysdb transaction, probes the sysdb_transaction_cancel() " +"function." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sssd-systemtap.5.xml:111 +msgid "probe sssd_transaction_commit_before" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd-systemtap.5.xml:114 +msgid "Probes the sysdb_transaction_commit_before() function." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sssd-systemtap.5.xml:124 +msgid "probe sssd_transaction_commit_after" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd-systemtap.5.xml:127 +msgid "Probes the sysdb_transaction_commit_after() function." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><title> +#: sssd-systemtap.5.xml:141 +msgid "LDAP Search Probes" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sssd-systemtap.5.xml:145 +msgid "probe sdap_search_send" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd-systemtap.5.xml:148 +msgid "Probes the sdap_get_generic_ext_send() function." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><programlisting> +#: sssd-systemtap.5.xml:152 +#, no-wrap +msgid "" +"base:string\n" +"scope:integer\n" +"filter:string\n" +"attrs:string\n" +"probestr:string\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sssd-systemtap.5.xml:161 +msgid "probe sdap_search_recv" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd-systemtap.5.xml:164 +msgid "Probes the sdap_get_generic_ext_recv() function." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><programlisting> +#: sssd-systemtap.5.xml:168 sssd-systemtap.5.xml:222 +#, no-wrap +msgid "" +"base:string\n" +"scope:integer\n" +"filter:string\n" +"probestr:string\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sssd-systemtap.5.xml:176 +msgid "probe sdap_parse_entry" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd-systemtap.5.xml:179 +msgid "" +"Probes the sdap_parse_entry() function. It is called repeatedly with every " +"received attribute." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><programlisting> +#: sssd-systemtap.5.xml:184 +#, no-wrap +msgid "" +"attr:string\n" +"value:string\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sssd-systemtap.5.xml:190 +msgid "probe sdap_parse_entry_done" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd-systemtap.5.xml:193 +msgid "" +"Probes the sdap_parse_entry() function. It is called when parsing of " +"received object is finished." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sssd-systemtap.5.xml:201 +msgid "probe sdap_deref_send" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd-systemtap.5.xml:204 +msgid "Probes the sdap_deref_search_send() function." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><programlisting> +#: sssd-systemtap.5.xml:208 +#, no-wrap +msgid "" +"base_dn:string\n" +"deref_attr:string\n" +"probestr:string\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sssd-systemtap.5.xml:215 +msgid "probe sdap_deref_recv" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd-systemtap.5.xml:218 +msgid "Probes the sdap_deref_search_recv() function." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><title> +#: sssd-systemtap.5.xml:234 +msgid "LDAP Account Request Probes" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sssd-systemtap.5.xml:238 +msgid "probe sdap_acct_req_send" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd-systemtap.5.xml:241 +msgid "Probes the sdap_acct_req_send() function." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><programlisting> +#: sssd-systemtap.5.xml:245 sssd-systemtap.5.xml:260 +#, no-wrap +msgid "" +"entry_type:int\n" +"filter_type:int\n" +"filter_value:string\n" +"extra_value:string\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sssd-systemtap.5.xml:253 +msgid "probe sdap_acct_req_recv" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd-systemtap.5.xml:256 +msgid "Probes the sdap_acct_req_recv() function." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><title> +#: sssd-systemtap.5.xml:272 +msgid "LDAP User Search Probes" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sssd-systemtap.5.xml:276 +msgid "probe sdap_search_user_send" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd-systemtap.5.xml:279 +msgid "Probes the sdap_search_user_send() function." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><programlisting> +#: sssd-systemtap.5.xml:283 sssd-systemtap.5.xml:295 sssd-systemtap.5.xml:307 +#: sssd-systemtap.5.xml:319 +#, no-wrap +msgid "" +"filter:string\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sssd-systemtap.5.xml:288 +msgid "probe sdap_search_user_recv" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd-systemtap.5.xml:291 +msgid "Probes the sdap_search_user_recv() function." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sssd-systemtap.5.xml:300 +msgid "probe sdap_search_user_save_begin" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd-systemtap.5.xml:303 +msgid "Probes the sdap_search_user_save_begin() function." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sssd-systemtap.5.xml:312 +msgid "probe sdap_search_user_save_end" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd-systemtap.5.xml:315 +msgid "Probes the sdap_search_user_save_end() function." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><title> +#: sssd-systemtap.5.xml:328 +msgid "Data Provider Request Probes" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sssd-systemtap.5.xml:332 +msgid "probe dp_req_send" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd-systemtap.5.xml:335 +msgid "A Data Provider request is submitted." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><programlisting> +#: sssd-systemtap.5.xml:338 +#, no-wrap +msgid "" +"dp_req_domain:string\n" +"dp_req_name:string\n" +"dp_req_target:int\n" +"dp_req_method:int\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sssd-systemtap.5.xml:346 +msgid "probe dp_req_done" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd-systemtap.5.xml:349 +msgid "A Data Provider request is completed." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><programlisting> +#: sssd-systemtap.5.xml:352 +#, no-wrap +msgid "" +"dp_req_name:string\n" +"dp_req_target:int\n" +"dp_req_method:int\n" +"dp_ret:int\n" +"dp_errorstr:string\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><title> +#: sssd-systemtap.5.xml:365 +msgid "MISCELLANEOUS FUNCTIONS" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd-systemtap.5.xml:372 +msgid "function acct_req_desc(entry_type)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd-systemtap.5.xml:375 +msgid "Convert entry_type to string and return string" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd-systemtap.5.xml:380 +msgid "" +"function sssd_acct_req_probestr(fc_name, entry_type, filter_type, " +"filter_value, extra_value)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd-systemtap.5.xml:384 +msgid "Create probe string based on filter type" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd-systemtap.5.xml:389 +msgid "function dp_target_str(target)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd-systemtap.5.xml:392 +msgid "Convert target to string and return string" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd-systemtap.5.xml:397 +msgid "function dp_method_str(target)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd-systemtap.5.xml:400 +msgid "Convert method to string and return string" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd-systemtap.5.xml:410 +msgid "SAMPLE SYSTEMTAP SCRIPTS" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-systemtap.5.xml:412 +msgid "" +"Start the SystemTap script (<command>stap " +"/usr/share/sssd/systemtap/<script_name>.stp</command>), then perform " +"an identity operation and the script will collect information from probes." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-systemtap.5.xml:418 +msgid "Provided SystemTap scripts are:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sssd-systemtap.5.xml:422 +msgid "dp_request.stp" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd-systemtap.5.xml:425 +msgid "Monitoring of data provider request performance." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sssd-systemtap.5.xml:430 +msgid "id_perf.stp" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd-systemtap.5.xml:433 +msgid "Monitoring of <command>id</command> command performance." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sssd-systemtap.5.xml:439 +msgid "ldap_perf.stp" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd-systemtap.5.xml:442 +msgid "Monitoring of LDAP queries." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sssd-systemtap.5.xml:447 +msgid "nested_group_perf.stp" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd-systemtap.5.xml:450 +msgid "Performance of nested groups resolving." +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refname> +#: sssd-ldap-attributes.5.xml:10 sssd-ldap-attributes.5.xml:16 +msgid "sssd-ldap-attributes" +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refpurpose> +#: sssd-ldap-attributes.5.xml:17 +msgid "SSSD LDAP Provider: Mapping Attributes" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-ldap-attributes.5.xml:23 +msgid "" +"This manual page describes the mapping attributes of SSSD LDAP provider " +"<citerefentry> <refentrytitle>sssd-ldap</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry>. Refer to the <citerefentry> " +"<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> " +"</citerefentry> manual page for full details about SSSD LDAP provider " +"configuration options." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd-ldap-attributes.5.xml:38 +msgid "USER ATTRIBUTES" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:42 +msgid "ldap_user_object_class (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:45 +msgid "The object class of a user entry in LDAP." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:48 +msgid "Default: posixAccount" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:54 +msgid "ldap_user_name (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:57 +msgid "The LDAP attribute that corresponds to the user's login name." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:61 +msgid "Default: uid (rfc2307, rfc2307bis and IPA), sAMAccountName (AD)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:68 +msgid "ldap_user_uid_number (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:71 +msgid "The LDAP attribute that corresponds to the user's id." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:75 +msgid "Default: uidNumber" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:81 +msgid "ldap_user_gid_number (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:84 +msgid "The LDAP attribute that corresponds to the user's primary group id." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:88 sssd-ldap-attributes.5.xml:700 +msgid "Default: gidNumber" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:94 +msgid "ldap_user_primary_group (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:97 +msgid "" +"Active Directory primary group attribute for ID-mapping. Note that this " +"attribute should only be set manually if you are running the " +"<quote>ldap</quote> provider with ID mapping." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:103 +msgid "Default: unset (LDAP), primaryGroupID (AD)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:109 +msgid "ldap_user_gecos (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:112 +msgid "The LDAP attribute that corresponds to the user's gecos field." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:116 +msgid "Default: gecos" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:122 +msgid "ldap_user_home_directory (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:125 +msgid "The LDAP attribute that contains the name of the user's home directory." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:129 +msgid "Default: homeDirectory (LDAP and IPA), unixHomeDirectory (AD)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:135 +msgid "ldap_user_shell (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:138 +msgid "The LDAP attribute that contains the path to the user's default shell." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:142 +msgid "Default: loginShell" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:148 +msgid "ldap_user_uuid (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:151 +msgid "The LDAP attribute that contains the UUID/GUID of an LDAP user object." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:155 sssd-ldap-attributes.5.xml:726 +msgid "" +"Default: not set in the general case, objectGUID for AD and ipaUniqueID for " +"IPA" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:162 +msgid "ldap_user_objectsid (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:165 +msgid "" +"The LDAP attribute that contains the objectSID of an LDAP user object. This " +"is usually only necessary for ActiveDirectory servers." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:170 sssd-ldap-attributes.5.xml:741 +msgid "Default: objectSid for ActiveDirectory, not set for other servers." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:177 +msgid "ldap_user_modify_timestamp (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:180 sssd-ldap-attributes.5.xml:751 +#: sssd-ldap-attributes.5.xml:874 +msgid "" +"The LDAP attribute that contains timestamp of the last modification of the " +"parent object." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:184 sssd-ldap-attributes.5.xml:755 +#: sssd-ldap-attributes.5.xml:881 +msgid "Default: modifyTimestamp" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:190 +msgid "ldap_user_shadow_last_change (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:193 +msgid "" +"When using ldap_pwd_policy=shadow, this parameter contains the name of an " +"LDAP attribute corresponding to its <citerefentry> " +"<refentrytitle>shadow</refentrytitle> <manvolnum>5</manvolnum> " +"</citerefentry> counterpart (date of the last password change)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:203 +msgid "Default: shadowLastChange" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:209 +msgid "ldap_user_shadow_min (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:212 +msgid "" +"When using ldap_pwd_policy=shadow, this parameter contains the name of an " +"LDAP attribute corresponding to its <citerefentry> " +"<refentrytitle>shadow</refentrytitle> <manvolnum>5</manvolnum> " +"</citerefentry> counterpart (minimum password age)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:221 +msgid "Default: shadowMin" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:227 +msgid "ldap_user_shadow_max (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:230 +msgid "" +"When using ldap_pwd_policy=shadow, this parameter contains the name of an " +"LDAP attribute corresponding to its <citerefentry> " +"<refentrytitle>shadow</refentrytitle> <manvolnum>5</manvolnum> " +"</citerefentry> counterpart (maximum password age)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:239 +msgid "Default: shadowMax" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:245 +msgid "ldap_user_shadow_warning (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:248 +msgid "" +"When using ldap_pwd_policy=shadow, this parameter contains the name of an " +"LDAP attribute corresponding to its <citerefentry> " +"<refentrytitle>shadow</refentrytitle> <manvolnum>5</manvolnum> " +"</citerefentry> counterpart (password warning period)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:258 +msgid "Default: shadowWarning" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:264 +msgid "ldap_user_shadow_inactive (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:267 +msgid "" +"When using ldap_pwd_policy=shadow, this parameter contains the name of an " +"LDAP attribute corresponding to its <citerefentry> " +"<refentrytitle>shadow</refentrytitle> <manvolnum>5</manvolnum> " +"</citerefentry> counterpart (password inactivity period)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:277 +msgid "Default: shadowInactive" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:283 +msgid "ldap_user_shadow_expire (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:286 +msgid "" +"When using ldap_pwd_policy=shadow or ldap_account_expire_policy=shadow, this " +"parameter contains the name of an LDAP attribute corresponding to its " +"<citerefentry> <refentrytitle>shadow</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry> counterpart (account expiration " +"date)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:296 +msgid "Default: shadowExpire" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:302 +msgid "ldap_user_krb_last_pwd_change (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:305 +msgid "" +"When using ldap_pwd_policy=mit_kerberos, this parameter contains the name of " +"an LDAP attribute storing the date and time of last password change in " +"kerberos." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:311 +msgid "Default: krbLastPwdChange" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:317 +msgid "ldap_user_krb_password_expiration (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:320 +msgid "" +"When using ldap_pwd_policy=mit_kerberos, this parameter contains the name of " +"an LDAP attribute storing the date and time when current password expires." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:326 +msgid "Default: krbPasswordExpiration" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:332 +msgid "ldap_user_ad_account_expires (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:335 +msgid "" +"When using ldap_account_expire_policy=ad, this parameter contains the name " +"of an LDAP attribute storing the expiration time of the account." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:340 +msgid "Default: accountExpires" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:346 +msgid "ldap_user_ad_user_account_control (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:349 +msgid "" +"When using ldap_account_expire_policy=ad, this parameter contains the name " +"of an LDAP attribute storing the user account control bit field." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:354 +msgid "Default: userAccountControl" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:360 +msgid "ldap_ns_account_lock (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:363 +msgid "" +"When using ldap_account_expire_policy=rhds or equivalent, this parameter " +"determines if access is allowed or not." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:368 +msgid "Default: nsAccountLock" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:374 +msgid "ldap_user_nds_login_disabled (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:377 +msgid "" +"When using ldap_account_expire_policy=nds, this attribute determines if " +"access is allowed or not." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:381 +msgid "Default: loginDisabled (rfc2307, rfc2307bis and IPA), not set (AD)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:387 +msgid "ldap_user_nds_login_expiration_time (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:390 +msgid "" +"When using ldap_account_expire_policy=nds, this attribute determines until " +"which date access is granted." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:395 +msgid "Default: loginExpirationTime (rfc2307, rfc2307bis and IPA), not set (AD)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:401 +msgid "ldap_user_nds_login_allowed_time_map (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:404 +msgid "" +"When using ldap_account_expire_policy=nds, this attribute determines the " +"hours of a day in a week when access is granted." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:409 +msgid "Default: loginAllowedTimeMap (rfc2307, rfc2307bis and IPA), not set (AD)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:415 +msgid "ldap_user_principal (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:418 +msgid "" +"The LDAP attribute that contains the user's Kerberos User Principal Name " +"(UPN)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:422 +msgid "Default: krbPrincipalName" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:428 +msgid "ldap_user_extra_attrs (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:431 +msgid "" +"Comma-separated list of LDAP attributes that SSSD would fetch along with the " +"usual set of user attributes." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:436 +msgid "" +"The list can either contain LDAP attribute names only, or colon-separated " +"tuples of SSSD cache attribute name and LDAP attribute name. In case only " +"LDAP attribute name is specified, the attribute is saved to the cache " +"verbatim. Using a custom SSSD attribute name might be required by " +"environments that configure several SSSD domains with different LDAP " +"schemas." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:446 +msgid "" +"Please note that several attribute names are reserved by SSSD, notably the " +"<quote>name</quote> attribute. SSSD would report an error if any of the " +"reserved attribute names is used as an extra attribute name." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:456 +msgid "ldap_user_extra_attrs = telephoneNumber" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:459 +msgid "" +"Save the <quote>telephoneNumber</quote> attribute from LDAP as " +"<quote>telephoneNumber</quote> to the cache." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:463 +msgid "ldap_user_extra_attrs = phone:telephoneNumber" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:466 +msgid "" +"Save the <quote>telephoneNumber</quote> attribute from LDAP as " +"<quote>phone</quote> to the cache." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:476 +msgid "ldap_user_ssh_public_key (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:479 +msgid "The LDAP attribute that contains the user's SSH public keys." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:483 sssd-ldap-attributes.5.xml:965 +msgid "Default: sshPublicKey" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:489 +msgid "ldap_user_fullname (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:492 +msgid "The LDAP attribute that corresponds to the user's full name." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:502 +msgid "ldap_user_member_of (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:505 +msgid "The LDAP attribute that lists the user's group memberships." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:509 sssd-ldap-attributes.5.xml:952 +msgid "Default: memberOf" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:515 +msgid "ldap_user_authorized_service (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:518 +msgid "" +"If access_provider=ldap and ldap_access_order=authorized_service, SSSD will " +"use the presence of the authorizedService attribute in the user's LDAP entry " +"to determine access privilege." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:525 +msgid "" +"An explicit deny (!svc) is resolved first. Second, SSSD searches for " +"explicit allow (svc) and finally for allow_all (*)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:530 +msgid "" +"Please note that the ldap_access_order configuration option " +"<emphasis>must</emphasis> include <quote>authorized_service</quote> in order " +"for the ldap_user_authorized_service option to work." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:537 +msgid "" +"Some distributions (such as Fedora-29+ or RHEL-8) always include the " +"<quote>systemd-user</quote> PAM service as part of the login " +"process. Therefore when using service-based access control, the " +"<quote>systemd-user</quote> service might need to be added to the list of " +"allowed services." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:545 +msgid "Default: authorizedService" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:551 +msgid "ldap_user_authorized_host (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:554 +msgid "" +"If access_provider=ldap and ldap_access_order=host, SSSD will use the " +"presence of the host attribute in the user's LDAP entry to determine access " +"privilege." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:560 +msgid "" +"An explicit deny (!host) is resolved first. Second, SSSD searches for " +"explicit allow (host) and finally for allow_all (*)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:565 +msgid "" +"Please note that the ldap_access_order configuration option " +"<emphasis>must</emphasis> include <quote>host</quote> in order for the " +"ldap_user_authorized_host option to work." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:572 +msgid "Default: host" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:578 +msgid "ldap_user_authorized_rhost (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:581 +msgid "" +"If access_provider=ldap and ldap_access_order=rhost, SSSD will use the " +"presence of the rhost attribute in the user's LDAP entry to determine access " +"privilege. Similarly to host verification process." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:588 +msgid "" +"An explicit deny (!rhost) is resolved first. Second, SSSD searches for " +"explicit allow (rhost) and finally for allow_all (*)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:593 +msgid "" +"Please note that the ldap_access_order configuration option " +"<emphasis>must</emphasis> include <quote>rhost</quote> in order for the " +"ldap_user_authorized_rhost option to work." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:600 +msgid "Default: rhost" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:606 +msgid "ldap_user_certificate (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:609 +msgid "Name of the LDAP attribute containing the X509 certificate of the user." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:613 +msgid "Default: userCertificate;binary" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:619 +msgid "ldap_user_email (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:622 +msgid "Name of the LDAP attribute containing the email address of the user." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:626 +msgid "" +"Note: If an email address of a user conflicts with an email address or fully " +"qualified name of another user, then SSSD will not be able to serve those " +"users properly. This option allows users to login by (1) username, and (2) " +"e-mail address. If for some reason several users need to share the same " +"email address then set this option to a nonexistent attribute name in order " +"to disable user lookup/login by email." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:637 +msgid "Default: mail" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:642 +msgid "ldap_user_passkey (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:645 +msgid "Name of the LDAP attribute containing the passkey mapping data of the user." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:649 +msgid "Default: passkey (LDAP), ipaPassKey (IPA), altSecurityIdentities (AD)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd-ldap-attributes.5.xml:659 +msgid "GROUP ATTRIBUTES" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:663 +msgid "ldap_group_object_class (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:666 +msgid "The object class of a group entry in LDAP." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:669 +msgid "Default: posixGroup" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:675 +msgid "ldap_group_name (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:678 +msgid "" +"The LDAP attribute that corresponds to the group name. In an environment " +"with nested groups, this value must be an LDAP attribute which has a unique " +"name for every group. This requirement includes non-POSIX groups in the tree " +"of nested groups." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:686 +msgid "Default: cn (rfc2307, rfc2307bis and IPA), sAMAccountName (AD)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:693 +msgid "ldap_group_gid_number (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:696 +msgid "The LDAP attribute that corresponds to the group's id." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:706 +msgid "ldap_group_member (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:709 +msgid "The LDAP attribute that contains the names of the group's members." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:713 +msgid "Default: memberuid (rfc2307) / member (rfc2307bis)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:719 +msgid "ldap_group_uuid (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:722 +msgid "The LDAP attribute that contains the UUID/GUID of an LDAP group object." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:733 +msgid "ldap_group_objectsid (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:736 +msgid "" +"The LDAP attribute that contains the objectSID of an LDAP group object. This " +"is usually only necessary for ActiveDirectory servers." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:748 +msgid "ldap_group_modify_timestamp (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:761 +msgid "ldap_group_type (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:764 +msgid "" +"The LDAP attribute that contains an integer value indicating the type of the " +"group and maybe other flags." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:769 +msgid "" +"This attribute is currently only used by the AD provider to determine if a " +"group is a domain local groups and has to be filtered out for trusted " +"domains." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:775 +msgid "Default: groupType in the AD provider, otherwise not set" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:782 +msgid "ldap_group_external_member (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:785 +msgid "" +"The LDAP attribute that references group members that are defined in an " +"external domain. At the moment, only IPA's external members are supported." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:791 +msgid "Default: ipaExternalMember in the IPA provider, otherwise unset." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd-ldap-attributes.5.xml:801 +msgid "NETGROUP ATTRIBUTES" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:805 +msgid "ldap_netgroup_object_class (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:808 +msgid "The object class of a netgroup entry in LDAP." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:811 +msgid "In IPA provider, ipa_netgroup_object_class should be used instead." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:815 +msgid "Default: nisNetgroup" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:821 +msgid "ldap_netgroup_name (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:824 +msgid "The LDAP attribute that corresponds to the netgroup name." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:828 +msgid "In IPA provider, ipa_netgroup_name should be used instead." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:838 +msgid "ldap_netgroup_member (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:841 +msgid "The LDAP attribute that contains the names of the netgroup's members." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:845 +msgid "In IPA provider, ipa_netgroup_member should be used instead." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:849 +msgid "Default: memberNisNetgroup" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:855 +msgid "ldap_netgroup_triple (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:858 +msgid "The LDAP attribute that contains the (host, user, domain) netgroup triples." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:862 sssd-ldap-attributes.5.xml:878 +msgid "This option is not available in IPA provider." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:865 +msgid "Default: nisNetgroupTriple" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:871 +msgid "ldap_netgroup_modify_timestamp (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd-ldap-attributes.5.xml:890 +msgid "HOST ATTRIBUTES" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:894 +msgid "ldap_host_object_class (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:897 +msgid "The object class of a host entry in LDAP." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:900 sssd-ldap-attributes.5.xml:1213 +msgid "Default: ipHost" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:906 +msgid "ldap_host_name (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:909 sssd-ldap-attributes.5.xml:935 +msgid "The LDAP attribute that corresponds to the host's name." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:919 +msgid "ldap_host_fqdn (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:922 +msgid "" +"The LDAP attribute that corresponds to the host's fully-qualified domain " +"name." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:926 +msgid "Default: fqdn" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:932 +msgid "ldap_host_serverhostname (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:939 +msgid "Default: serverHostname" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:945 +msgid "ldap_host_member_of (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:948 +msgid "The LDAP attribute that lists the host's group memberships." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:958 +msgid "ldap_host_ssh_public_key (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:961 +msgid "The LDAP attribute that contains the host's SSH public keys." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:971 +msgid "ldap_host_uuid (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:974 +msgid "The LDAP attribute that contains the UUID/GUID of an LDAP host object." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd-ldap-attributes.5.xml:987 +msgid "SERVICE ATTRIBUTES" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:991 +msgid "ldap_service_object_class (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:994 +msgid "The object class of a service entry in LDAP." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:997 +msgid "Default: ipService" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:1003 +msgid "ldap_service_name (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:1006 +msgid "" +"The LDAP attribute that contains the name of service attributes and their " +"aliases." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:1016 +msgid "ldap_service_port (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:1019 +msgid "The LDAP attribute that contains the port managed by this service." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:1023 +msgid "Default: ipServicePort" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:1029 +msgid "ldap_service_proto (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:1032 +msgid "The LDAP attribute that contains the protocols understood by this service." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:1036 +msgid "Default: ipServiceProtocol" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd-ldap-attributes.5.xml:1045 +msgid "SUDO ATTRIBUTES" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:1049 +msgid "ldap_sudorule_object_class (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:1052 +msgid "The object class of a sudo rule entry in LDAP." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:1055 +msgid "Default: sudoRole" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:1061 +msgid "ldap_sudorule_name (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:1064 +msgid "The LDAP attribute that corresponds to the sudo rule name." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:1074 +msgid "ldap_sudorule_command (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:1077 +msgid "The LDAP attribute that corresponds to the command name." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:1081 +msgid "Default: sudoCommand" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:1087 +msgid "ldap_sudorule_host (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:1090 +msgid "" +"The LDAP attribute that corresponds to the host name (or host IP address, " +"host IP network, or host netgroup)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:1095 +msgid "Default: sudoHost" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:1101 +msgid "ldap_sudorule_user (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:1104 +msgid "" +"The LDAP attribute that corresponds to the user name (or UID, group name or " +"user's netgroup)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:1108 +msgid "Default: sudoUser" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:1114 +msgid "ldap_sudorule_option (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:1117 +msgid "The LDAP attribute that corresponds to the sudo options." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:1121 +msgid "Default: sudoOption" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:1127 +msgid "ldap_sudorule_runasuser (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:1130 +msgid "" +"The LDAP attribute that corresponds to the user name that commands may be " +"run as." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:1134 +msgid "Default: sudoRunAsUser" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:1140 +msgid "ldap_sudorule_runasgroup (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:1143 +msgid "" +"The LDAP attribute that corresponds to the group name or group GID that " +"commands may be run as." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:1147 +msgid "Default: sudoRunAsGroup" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:1153 +msgid "ldap_sudorule_notbefore (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:1156 +msgid "" +"The LDAP attribute that corresponds to the start date/time for when the sudo " +"rule is valid." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:1160 +msgid "Default: sudoNotBefore" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:1166 +msgid "ldap_sudorule_notafter (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:1169 +msgid "" +"The LDAP attribute that corresponds to the expiration date/time, after which " +"the sudo rule will no longer be valid." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:1174 +msgid "Default: sudoNotAfter" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:1180 +msgid "ldap_sudorule_order (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:1183 +msgid "The LDAP attribute that corresponds to the ordering index of the rule." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:1187 +msgid "Default: sudoOrder" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd-ldap-attributes.5.xml:1196 +msgid "AUTOFS ATTRIBUTES" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd-ldap-attributes.5.xml:1203 +msgid "IP HOST ATTRIBUTES" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:1207 +msgid "ldap_iphost_object_class (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:1210 +msgid "The object class of an iphost entry in LDAP." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:1219 +msgid "ldap_iphost_name (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:1222 +msgid "" +"The LDAP attribute that contains the name of the IP host attributes and " +"their aliases." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:1232 +msgid "ldap_iphost_number (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:1235 +msgid "The LDAP attribute that contains the IP host address." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:1239 +msgid "Default: ipHostNumber" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd-ldap-attributes.5.xml:1248 +msgid "IP NETWORK ATTRIBUTES" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:1252 +msgid "ldap_ipnetwork_object_class (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:1255 +msgid "The object class of an ipnetwork entry in LDAP." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:1258 +msgid "Default: ipNetwork" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:1264 +msgid "ldap_ipnetwork_name (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:1267 +msgid "" +"The LDAP attribute that contains the name of the IP network attributes and " +"their aliases." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:1277 +msgid "ldap_ipnetwork_number (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:1280 +msgid "The LDAP attribute that contains the IP network address." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:1284 +msgid "Default: ipNetworkNumber" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd-ldap-attributes.5.xml:1293 +msgid "SUBID ATTRIBUTES" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:1297 +msgid "ldap_subuid_object_class (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:1300 +msgid "The object class of an subid entry in LDAP." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:1303 +msgid "Default: subordinateIdEntry" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:1309 +msgid "ldap_subuid_count (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:1312 +msgid "Subordinate user ID count (range size)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:1315 +msgid "Default: subUidCount" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:1321 +msgid "ldap_subgid_count (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:1324 +msgid "Subordinate group ID count (range size)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:1327 +msgid "Default: subGidCount" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:1333 +msgid "ldap_subuid_number (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:1336 +msgid "Numerical subordinate user ID (range start value)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:1339 +msgid "Default: subUidNumber" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:1345 +msgid "ldap_subgid_number (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:1348 +msgid "Numerical subordinate group ID (range start value)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:1351 +msgid "Default: subGidNumber" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:1357 +msgid "ldap_subid_range_owner (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:1360 +msgid "Owner of an entry" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:1363 +msgid "Default: subidRangeOwner" +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refname> +#: sssd_krb5_localauth_plugin.8.xml:10 sssd_krb5_localauth_plugin.8.xml:15 +msgid "sssd_krb5_localauth_plugin" +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refpurpose> +#: sssd_krb5_localauth_plugin.8.xml:16 +msgid "Kerberos local authorization plugin" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_localauth_plugin.8.xml:22 +msgid "" +"The Kerberos local authorization plugin " +"<command>sssd_krb5_localauth_plugin</command> is used by libkrb5 to either " +"find the local name for a given Kerberos principal or to check if a given " +"local name and a given Kerberos principal relate to each other." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_localauth_plugin.8.xml:29 +msgid "" +"SSSD handles the local names for users from a remote source and can read the " +"Kerberos user principal name from the remote source as well. With this " +"information SSSD can easily handle the mappings mentioned above even if the " +"local name and the Kerberos principal differ considerably." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_localauth_plugin.8.xml:36 +msgid "" +"Additionally with the information read from the remote source SSSD can help " +"to prevent unexpected or unwanted mappings in case the user part of the " +"Kerberos principal accidentally corresponds to a local name of a different " +"user. By default libkrb5 might just strip the realm part of the Kerberos " +"principal to get the local name which would lead to wrong mappings in this " +"case." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd_krb5_localauth_plugin.8.xml:46 +msgid "CONFIGURATION" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><programlisting> +#: sssd_krb5_localauth_plugin.8.xml:56 +#, no-wrap +msgid "" +"[plugins]\n" +" localauth = {\n" +" disable = an2ln\n" +" module = sssd:/usr/lib64/sssd/modules/sssd_krb5_localauth_plugin.so\n" +" }\n" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_localauth_plugin.8.xml:48 +msgid "" +"The Kerberos local authorization plugin must be enabled explicitly in the " +"Kerberos configuration, see <citerefentry> " +"<refentrytitle>krb5.conf</refentrytitle> <manvolnum>5</manvolnum> " +"</citerefentry>. SSSD will create a config snippet with the content like " +"e.g. <placeholder type=\"programlisting\" id=\"0\"/> automatically in the " +"SSSD's public Kerberos configuration snippet directory. If this directory is " +"included in the local Kerberos configuration the plugin will be enabled " +"automatically." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_localauth_plugin.8.xml:67 +msgid "" +"This configuration snippet also disables the <command>an2ln</command> module " +"provided by MIT Kerberos if SSSD is configured to use the AD or IPA " +"provider. In those environments " +"<command>sssd_krb5_localauth_plugin</command> can reliably map the system " +"user names to Kerberos principals. A fallback to <command>an2ln</command> " +"might cause issues in environments where users have the privilege to create " +"Kerberos principals on their own which might collide with names of other " +"users used in the system. Other modules provided by MIT Kerberos, e.g. " +"<command>k5login</command> are not affected." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_localauth_plugin.8.xml:79 +msgid "" +"Note: If using <quote>auth_provider = krb5</quote> then " +"<command>sssd_krb5_localauth_plugin</command> is not used, therefore the " +"above text is not applicable." +msgstr "" + +#. type: Content of: <variablelist><varlistentry><term> +#: include/autofs_attributes.xml:3 +msgid "ldap_autofs_map_object_class (string)" +msgstr "" + +#. type: Content of: <variablelist><varlistentry><listitem><para> +#: include/autofs_attributes.xml:6 +msgid "The object class of an automount map entry in LDAP." +msgstr "" + +#. type: Content of: <variablelist><varlistentry><listitem><para> +#: include/autofs_attributes.xml:9 +msgid "Default: nisMap (rfc2307, autofs_provider=ad), otherwise automountMap" +msgstr "" + +#. type: Content of: <variablelist><varlistentry><term> +#: include/autofs_attributes.xml:16 +msgid "ldap_autofs_map_name (string)" +msgstr "" + +#. type: Content of: <variablelist><varlistentry><listitem><para> +#: include/autofs_attributes.xml:19 +msgid "The name of an automount map entry in LDAP." +msgstr "" + +#. type: Content of: <variablelist><varlistentry><listitem><para> +#: include/autofs_attributes.xml:22 +msgid "" +"Default: nisMapName (rfc2307, autofs_provider=ad), otherwise " +"automountMapName" +msgstr "" + +#. type: Content of: <variablelist><varlistentry><term> +#: include/autofs_attributes.xml:29 +msgid "ldap_autofs_entry_object_class (string)" +msgstr "" + +#. type: Content of: <variablelist><varlistentry><listitem><para> +#: include/autofs_attributes.xml:32 +msgid "" +"The object class of an automount entry in LDAP. The entry usually " +"corresponds to a mount point." +msgstr "" + +#. type: Content of: <variablelist><varlistentry><listitem><para> +#: include/autofs_attributes.xml:37 +msgid "Default: nisObject (rfc2307, autofs_provider=ad), otherwise automount" +msgstr "" + +#. type: Content of: <variablelist><varlistentry><term> +#: include/autofs_attributes.xml:44 +msgid "ldap_autofs_entry_key (string)" +msgstr "" + +#. type: Content of: <variablelist><varlistentry><listitem><para> +#: include/autofs_attributes.xml:47 include/autofs_attributes.xml:61 +msgid "" +"The key of an automount entry in LDAP. The entry usually corresponds to a " +"mount point." +msgstr "" + +#. type: Content of: <variablelist><varlistentry><listitem><para> +#: include/autofs_attributes.xml:51 +msgid "Default: cn (rfc2307, autofs_provider=ad), otherwise automountKey" +msgstr "" + +#. type: Content of: <variablelist><varlistentry><term> +#: include/autofs_attributes.xml:58 +msgid "ldap_autofs_entry_value (string)" +msgstr "" + +#. type: Content of: <variablelist><varlistentry><listitem><para> +#: include/autofs_attributes.xml:65 +msgid "" +"Default: nisMapEntry (rfc2307, autofs_provider=ad), otherwise " +"automountInformation" +msgstr "" + +#. type: Content of: <refsect1><title> +#: include/service_discovery.xml:2 +msgid "SERVICE DISCOVERY" +msgstr "" + +#. type: Content of: <refsect1><para> +#: include/service_discovery.xml:4 +msgid "" +"The service discovery feature allows back ends to automatically find the " +"appropriate servers to connect to using a special DNS query. This feature is " +"not supported for backup servers." +msgstr "" + +#. type: Content of: <refsect1><refsect2><title> +#: include/service_discovery.xml:9 include/ldap_id_mapping.xml:99 +msgid "Configuration" +msgstr "" + +#. type: Content of: <refsect1><refsect2><para> +#: include/service_discovery.xml:11 +msgid "" +"If no servers are specified, the back end automatically uses service " +"discovery to try to find a server. Optionally, the user may choose to use " +"both fixed server addresses and service discovery by inserting a special " +"keyword, <quote>_srv_</quote>, in the list of servers. The order of " +"preference is maintained. This feature is useful if, for example, the user " +"prefers to use service discovery whenever possible, and fall back to a " +"specific server when no servers can be discovered using DNS." +msgstr "" + +#. type: Content of: <refsect1><refsect2><title> +#: include/service_discovery.xml:23 +msgid "The domain name" +msgstr "" + +#. type: Content of: <refsect1><refsect2><para> +#: include/service_discovery.xml:25 +msgid "" +"Please refer to the <quote>dns_discovery_domain</quote> parameter in the " +"<citerefentry> <refentrytitle>sssd.conf</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry> manual page for more details." +msgstr "" + +#. type: Content of: <refsect1><refsect2><title> +#: include/service_discovery.xml:35 +msgid "The protocol" +msgstr "" + +#. type: Content of: <refsect1><refsect2><para> +#: include/service_discovery.xml:37 +msgid "" +"The queries usually specify _tcp as the protocol. Exceptions are documented " +"in respective option description." +msgstr "" + +#. type: Content of: <refsect1><refsect2><title> +#: include/service_discovery.xml:42 +msgid "See Also" +msgstr "" + +#. type: Content of: <refsect1><refsect2><para> +#: include/service_discovery.xml:44 +msgid "For more information on the service discovery mechanism, refer to RFC 2782." +msgstr "" + +#. type: Content of: <refentryinfo> +#: include/upstream.xml:2 +msgid "" +"<productname>SSSD</productname> <orgname>The SSSD upstream - " +"https://github.com/SSSD/sssd/</orgname>" +msgstr "" + +#. type: Content of: outside any tag (error?) +#: include/upstream.xml:1 +msgid "<placeholder type=\"refentryinfo\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <refsect1><title> +#: include/failover.xml:2 +msgid "FAILOVER" +msgstr "" + +#. type: Content of: <refsect1><para> +#: include/failover.xml:4 +msgid "" +"The failover feature allows back ends to automatically switch to a different " +"server if the current server fails." +msgstr "" + +#. type: Content of: <refsect1><refsect2><title> +#: include/failover.xml:8 +msgid "Failover Syntax" +msgstr "" + +#. type: Content of: <refsect1><refsect2><para> +#: include/failover.xml:10 +msgid "" +"The list of servers is given as a comma-separated list; any number of spaces " +"is allowed around the comma. The servers are listed in order of " +"preference. The list can contain any number of servers." +msgstr "" + +#. type: Content of: <refsect1><refsect2><para> +#: include/failover.xml:16 +msgid "" +"For each failover-enabled config option, two variants exist: " +"<emphasis>primary</emphasis> and <emphasis>backup</emphasis>. The idea is " +"that servers in the primary list are preferred and backup servers are only " +"searched if no primary servers can be reached. If a backup server is " +"selected, a timeout of 31 seconds is set. After this timeout SSSD will " +"periodically try to reconnect to one of the primary servers. If it succeeds, " +"it will replace the current active (backup) server." +msgstr "" + +#. type: Content of: <refsect1><refsect2><title> +#: include/failover.xml:27 +msgid "The Failover Mechanism" +msgstr "" + +#. type: Content of: <refsect1><refsect2><para> +#: include/failover.xml:29 +msgid "" +"The failover mechanism distinguishes between a machine and a service. The " +"back end first tries to resolve the hostname of a given machine; if this " +"resolution attempt fails, the machine is considered offline. No further " +"attempts are made to connect to this machine for any other service. If the " +"resolution attempt succeeds, the back end tries to connect to a service on " +"this machine. If the service connection attempt fails, then only this " +"particular service is considered offline and the back end automatically " +"switches over to the next service. The machine is still considered online " +"and might still be tried for another service." +msgstr "" + +#. type: Content of: <refsect1><refsect2><para> +#: include/failover.xml:42 +msgid "" +"Further connection attempts are made to machines or services marked as " +"offline after a specified period of time; this is currently hard coded to 30 " +"seconds." +msgstr "" + +#. type: Content of: <refsect1><refsect2><para> +#: include/failover.xml:47 +msgid "" +"If there are no more machines to try, the back end as a whole switches to " +"offline mode, and then attempts to reconnect every 30 seconds." +msgstr "" + +#. type: Content of: <refsect1><refsect2><title> +#: include/failover.xml:53 +msgid "Failover time outs and tuning" +msgstr "" + +#. type: Content of: <refsect1><refsect2><para> +#: include/failover.xml:55 +msgid "" +"Resolving a server to connect to can be as simple as running a single DNS " +"query or can involve several steps, such as finding the correct site or " +"trying out multiple host names in case some of the configured servers are " +"not reachable. The more complex scenarios can take some time and SSSD needs " +"to balance between providing enough time to finish the resolution process " +"but on the other hand, not trying for too long before falling back to " +"offline mode. If the SSSD debug logs show that the server resolution is " +"timing out before a live server is contacted, you can consider changing the " +"time outs." +msgstr "" + +#. type: Content of: <refsect1><refsect2><para><variablelist><varlistentry><term> +#: include/failover.xml:76 +msgid "dns_resolver_server_timeout" +msgstr "" + +#. type: Content of: <refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: include/failover.xml:80 +msgid "" +"Time in milliseconds that sets how long would SSSD talk to a single DNS " +"server before trying next one." +msgstr "" + +#. type: Content of: <refsect1><refsect2><para><variablelist><varlistentry><term> +#: include/failover.xml:90 +msgid "dns_resolver_op_timeout" +msgstr "" + +#. type: Content of: <refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: include/failover.xml:94 +msgid "" +"Time in seconds to tell how long would SSSD try to resolve single DNS query " +"(e.g. resolution of a hostname or an SRV record) before trying the next " +"hostname or discovery domain." +msgstr "" + +#. type: Content of: <refsect1><refsect2><para><variablelist><varlistentry><term> +#: include/failover.xml:106 +msgid "dns_resolver_timeout" +msgstr "" + +#. type: Content of: <refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: include/failover.xml:110 +msgid "" +"How long would SSSD try to resolve a failover service. This service " +"resolution internally might include several steps, such as resolving DNS SRV " +"queries or locating the site." +msgstr "" + +#. type: Content of: <refsect1><refsect2><para> +#: include/failover.xml:67 +msgid "" +"This section lists the available tunables. Please refer to their description " +"in the <citerefentry> " +"<refentrytitle>sssd.conf</refentrytitle><manvolnum>5</manvolnum> " +"</citerefentry>, manual page. <placeholder type=\"variablelist\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <refsect1><refsect2><para> +#: include/failover.xml:123 +msgid "" +"For LDAP-based providers, the resolve operation is performed as part of an " +"LDAP connection operation. Therefore, also the " +"<quote>ldap_opt_timeout</quote> timeout should be set to a larger value than " +"<quote>dns_resolver_timeout</quote> which in turn should be set to a larger " +"value than <quote>dns_resolver_op_timeout</quote> which should be larger " +"than <quote>dns_resolver_server_timeout</quote>." +msgstr "" + +#. type: Content of: <refsect1><title> +#: include/ldap_id_mapping.xml:2 +msgid "ID MAPPING" +msgstr "" + +#. type: Content of: <refsect1><para> +#: include/ldap_id_mapping.xml:4 +msgid "" +"The ID-mapping feature allows SSSD to act as a client of Active Directory " +"without requiring administrators to extend user attributes to support POSIX " +"attributes for user and group identifiers." +msgstr "" + +#. type: Content of: <refsect1><para> +#: include/ldap_id_mapping.xml:9 +msgid "" +"NOTE: When ID-mapping is enabled, the uidNumber and gidNumber attributes are " +"ignored. This is to avoid the possibility of conflicts between " +"automatically-assigned and manually-assigned values. If you need to use " +"manually-assigned values, ALL values must be manually-assigned." +msgstr "" + +#. type: Content of: <refsect1><para> +#: include/ldap_id_mapping.xml:16 +msgid "" +"Please note that changing the ID mapping related configuration options will " +"cause user and group IDs to change. At the moment, SSSD does not support " +"changing IDs, so the SSSD database must be removed. Because cached passwords " +"are also stored in the database, removing the database should only be " +"performed while the authentication servers are reachable, otherwise users " +"might get locked out. In order to cache the password, an authentication must " +"be performed. It is not sufficient to use <citerefentry> " +"<refentrytitle>sss_cache</refentrytitle> <manvolnum>8</manvolnum> " +"</citerefentry> to remove the database, rather the process consists of:" +msgstr "" + +#. type: Content of: <refsect1><para><itemizedlist><listitem><para> +#: include/ldap_id_mapping.xml:33 +msgid "Making sure the remote servers are reachable" +msgstr "" + +#. type: Content of: <refsect1><para><itemizedlist><listitem><para> +#: include/ldap_id_mapping.xml:38 +msgid "Stopping the SSSD service" +msgstr "" + +#. type: Content of: <refsect1><para><itemizedlist><listitem><para> +#: include/ldap_id_mapping.xml:43 +msgid "Removing the database" +msgstr "" + +#. type: Content of: <refsect1><para><itemizedlist><listitem><para> +#: include/ldap_id_mapping.xml:48 +msgid "Starting the SSSD service" +msgstr "" + +#. type: Content of: <refsect1><para> +#: include/ldap_id_mapping.xml:52 +msgid "" +"Moreover, as the change of IDs might necessitate the adjustment of other " +"system properties such as file and directory ownership, it's advisable to " +"plan ahead and test the ID mapping configuration thoroughly." +msgstr "" + +#. type: Content of: <refsect1><refsect2><title> +#: include/ldap_id_mapping.xml:59 +msgid "Mapping Algorithm" +msgstr "" + +#. type: Content of: <refsect1><refsect2><para> +#: include/ldap_id_mapping.xml:61 +msgid "" +"Active Directory provides an objectSID for every user and group object in " +"the directory. This objectSID can be broken up into components that " +"represent the Active Directory domain identity and the relative identifier " +"(RID) of the user or group object." +msgstr "" + +#. type: Content of: <refsect1><refsect2><para> +#: include/ldap_id_mapping.xml:67 +msgid "" +"The SSSD ID-mapping algorithm takes a range of available UIDs and divides it " +"into equally-sized component sections - called \"slices\". Each slice " +"represents the space available to an Active Directory domain." +msgstr "" + +#. type: Content of: <refsect1><refsect2><para> +#: include/ldap_id_mapping.xml:73 +msgid "" +"When a user or group entry for a particular domain is encountered for the " +"first time, the SSSD allocates one of the available slices for that " +"domain. In order to make this slice-assignment repeatable on different " +"client machines, we select the slice based on the following algorithm:" +msgstr "" + +#. type: Content of: <refsect1><refsect2><para> +#: include/ldap_id_mapping.xml:80 +msgid "" +"The SID string is passed through the murmurhash3 algorithm to convert it to " +"a 32-bit hashed value. We then take the modulus of this value with the total " +"number of available slices to pick the slice." +msgstr "" + +#. type: Content of: <refsect1><refsect2><para> +#: include/ldap_id_mapping.xml:86 +msgid "" +"NOTE: It is possible to encounter collisions in the hash and subsequent " +"modulus. In these situations, we will select the next available slice, but " +"it may not be possible to reproduce the same exact set of slices on other " +"machines (since the order that they are encountered will determine their " +"slice). In this situation, it is recommended to either switch to using " +"explicit POSIX attributes in Active Directory (disabling ID-mapping) or " +"configure a default domain to guarantee that at least one is always " +"consistent. See <quote>Configuration</quote> for details." +msgstr "" + +#. type: Content of: <refsect1><refsect2><para> +#: include/ldap_id_mapping.xml:101 +msgid "Minimum configuration (in the <quote>[domain/DOMAINNAME]</quote> section):" +msgstr "" + +#. type: Content of: <refsect1><refsect2><para><programlisting> +#: include/ldap_id_mapping.xml:106 +#, no-wrap +msgid "" +"ldap_id_mapping = True\n" +"ldap_schema = ad\n" +msgstr "" + +#. type: Content of: <refsect1><refsect2><para> +#: include/ldap_id_mapping.xml:111 +msgid "" +"The default configuration results in configuring 10,000 slices, each capable " +"of holding up to 200,000 IDs, starting from 200,000 and going up to " +"2,000,200,000. This should be sufficient for most deployments." +msgstr "" + +#. type: Content of: <refsect1><refsect2><refsect3><title> +#: include/ldap_id_mapping.xml:117 +msgid "Advanced Configuration" +msgstr "" + +#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><term> +#: include/ldap_id_mapping.xml:120 +msgid "ldap_idmap_range_min (integer)" +msgstr "" + +#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> +#: include/ldap_id_mapping.xml:123 +msgid "" +"Specifies the lower (inclusive) bound of the range of POSIX IDs to use for " +"mapping Active Directory user and group SIDs. It is the first POSIX ID which " +"can be used for the mapping." +msgstr "" + +#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> +#: include/ldap_id_mapping.xml:129 +msgid "" +"NOTE: This option is different from <quote>min_id</quote> in that " +"<quote>min_id</quote> acts to filter the output of requests to this domain, " +"whereas this option controls the range of ID assignment. This is a subtle " +"distinction, but the good general advice would be to have " +"<quote>min_id</quote> be less-than or equal to " +"<quote>ldap_idmap_range_min</quote>" +msgstr "" + +#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><term> +#: include/ldap_id_mapping.xml:144 +msgid "ldap_idmap_range_max (integer)" +msgstr "" + +#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> +#: include/ldap_id_mapping.xml:147 +msgid "" +"Specifies the upper (exclusive) bound of the range of POSIX IDs to use for " +"mapping Active Directory user and group SIDs. It is the first POSIX ID which " +"cannot be used for the mapping anymore, i.e. one larger than the last one " +"which can be used for the mapping." +msgstr "" + +#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> +#: include/ldap_id_mapping.xml:155 +msgid "" +"NOTE: This option is different from <quote>max_id</quote> in that " +"<quote>max_id</quote> acts to filter the output of requests to this domain, " +"whereas this option controls the range of ID assignment. This is a subtle " +"distinction, but the good general advice would be to have " +"<quote>max_id</quote> be greater-than or equal to " +"<quote>ldap_idmap_range_max</quote>" +msgstr "" + +#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><term> +#: include/ldap_id_mapping.xml:170 +msgid "ldap_idmap_range_size (integer)" +msgstr "" + +#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> +#: include/ldap_id_mapping.xml:173 +msgid "" +"Specifies the number of IDs available for each slice. If the range size " +"does not divide evenly into the min and max values, it will create as many " +"complete slices as it can." +msgstr "" + +#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> +#: include/ldap_id_mapping.xml:179 +msgid "" +"NOTE: The value of this option must be at least as large as the highest user " +"RID planned for use on the Active Directory server. User lookups and login " +"will fail for any user whose RID is greater than this value." +msgstr "" + +#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> +#: include/ldap_id_mapping.xml:185 +msgid "" +"For example, if your most recently-added Active Directory user has " +"objectSid=S-1-5-21-2153326666-2176343378-3404031434-1107, " +"<quote>ldap_idmap_range_size</quote> must be at least 1108 as range size is " +"equal to maximal RID minus minimal RID plus one (e.g. 1108 = 1107 - 0 + 1)." +msgstr "" + +#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> +#: include/ldap_id_mapping.xml:192 +msgid "" +"It is important to plan ahead for future expansion, as changing this value " +"will result in changing all of the ID mappings on the system, leading to " +"users with different local IDs than they previously had." +msgstr "" + +#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><term> +#: include/ldap_id_mapping.xml:202 +msgid "ldap_idmap_default_domain_sid (string)" +msgstr "" + +#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> +#: include/ldap_id_mapping.xml:205 +msgid "" +"Specify the domain SID of the default domain. This will guarantee that this " +"domain will always be assigned to slice zero in the ID map, bypassing the " +"murmurhash algorithm described above." +msgstr "" + +#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><term> +#: include/ldap_id_mapping.xml:216 +msgid "ldap_idmap_default_domain (string)" +msgstr "" + +#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> +#: include/ldap_id_mapping.xml:219 +msgid "Specify the name of the default domain." +msgstr "" + +#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><term> +#: include/ldap_id_mapping.xml:227 +msgid "ldap_idmap_autorid_compat (boolean)" +msgstr "" + +#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> +#: include/ldap_id_mapping.xml:230 +msgid "" +"Changes the behavior of the ID-mapping algorithm to behave more similarly to " +"winbind's <quote>idmap_autorid</quote> algorithm." +msgstr "" + +#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> +#: include/ldap_id_mapping.xml:235 +msgid "" +"When this option is configured, domains will be allocated starting with " +"slice zero and increasing monotonically with each additional domain." +msgstr "" + +#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> +#: include/ldap_id_mapping.xml:240 +msgid "" +"NOTE: This algorithm is non-deterministic (it depends on the order that " +"users and groups are requested). If this mode is required for compatibility " +"with machines running winbind, it is recommended to also use the " +"<quote>ldap_idmap_default_domain_sid</quote> option to guarantee that at " +"least one domain is consistently allocated to slice zero." +msgstr "" + +#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><term> +#: include/ldap_id_mapping.xml:255 +msgid "ldap_idmap_helper_table_size (integer)" +msgstr "" + +#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> +#: include/ldap_id_mapping.xml:258 +msgid "" +"Maximal number of secondary slices that is tried when performing mapping " +"from UNIX id to SID." +msgstr "" + +#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> +#: include/ldap_id_mapping.xml:262 +msgid "" +"Note: Additional secondary slices might be generated when SID is being " +"mapped to UNIX id and RID part of SID is out of range for secondary slices " +"generated so far. If value of ldap_idmap_helper_table_size is equal to 0 " +"then no additional secondary slices are generated." +msgstr "" + +#. type: Content of: <refsect1><refsect2><title> +#: include/ldap_id_mapping.xml:279 +msgid "Well-Known SIDs" +msgstr "" + +#. type: Content of: <refsect1><refsect2><para> +#: include/ldap_id_mapping.xml:281 +msgid "" +"SSSD supports to look up the names of Well-Known SIDs, i.e. SIDs with a " +"special hardcoded meaning. Since the generic users and groups related to " +"those Well-Known SIDs have no equivalent in a Linux/UNIX environment no " +"POSIX IDs are available for those objects." +msgstr "" + +#. type: Content of: <refsect1><refsect2><para> +#: include/ldap_id_mapping.xml:287 +msgid "" +"The SID name space is organized in authorities which can be seen as " +"different domains. The authorities for the Well-Known SIDs are" +msgstr "" + +#. type: Content of: <refsect1><refsect2><para><itemizedlist><listitem><para> +#: include/ldap_id_mapping.xml:290 +msgid "Null Authority" +msgstr "" + +#. type: Content of: <refsect1><refsect2><para><itemizedlist><listitem><para> +#: include/ldap_id_mapping.xml:291 +msgid "World Authority" +msgstr "" + +#. type: Content of: <refsect1><refsect2><para><itemizedlist><listitem><para> +#: include/ldap_id_mapping.xml:292 +msgid "Local Authority" +msgstr "" + +#. type: Content of: <refsect1><refsect2><para><itemizedlist><listitem><para> +#: include/ldap_id_mapping.xml:293 +msgid "Creator Authority" +msgstr "" + +#. type: Content of: <refsect1><refsect2><para><itemizedlist><listitem><para> +#: include/ldap_id_mapping.xml:294 +msgid "Mandatory Label Authority" +msgstr "" + +#. type: Content of: <refsect1><refsect2><para><itemizedlist><listitem><para> +#: include/ldap_id_mapping.xml:295 +msgid "Authentication Authority" +msgstr "" + +#. type: Content of: <refsect1><refsect2><para><itemizedlist><listitem><para> +#: include/ldap_id_mapping.xml:296 +msgid "NT Authority" +msgstr "" + +#. type: Content of: <refsect1><refsect2><para><itemizedlist><listitem><para> +#: include/ldap_id_mapping.xml:297 +msgid "Built-in" +msgstr "" + +#. type: Content of: <refsect1><refsect2><para> +#: include/ldap_id_mapping.xml:299 +msgid "" +"The capitalized version of these names are used as domain names when " +"returning the fully qualified name of a Well-Known SID." +msgstr "" + +#. type: Content of: <refsect1><refsect2><para> +#: include/ldap_id_mapping.xml:303 +msgid "" +"Since some utilities allow to modify SID based access control information " +"with the help of a name instead of using the SID directly SSSD supports to " +"look up the SID by the name as well. To avoid collisions only the fully " +"qualified names can be used to look up Well-Known SIDs. As a result the " +"domain names <quote>NULL AUTHORITY</quote>, <quote>WORLD AUTHORITY</quote>, " +"<quote>LOCAL AUTHORITY</quote>, <quote>CREATOR AUTHORITY</quote>, " +"<quote>MANDATORY LABEL AUTHORITY</quote>, <quote>AUTHENTICATION " +"AUTHORITY</quote>, <quote>NT AUTHORITY</quote> and <quote>BUILTIN</quote> " +"should not be used as domain names in <filename>sssd.conf</filename>." +msgstr "" + +#. type: Content of: <varlistentry><term> +#: include/param_help.xml:3 +msgid "<option>-?</option>,<option>--help</option>" +msgstr "" + +#. type: Content of: <varlistentry><listitem><para> +#: include/param_help.xml:7 include/param_help_py.xml:7 +msgid "Display help message and exit." +msgstr "" + +#. type: Content of: <varlistentry><term> +#: include/param_help_py.xml:3 +msgid "<option>-h</option>,<option>--help</option>" +msgstr "" + +#. type: Content of: <listitem><para> +#: include/debug_levels.xml:3 include/debug_levels_tools.xml:3 +msgid "" +"SSSD supports two representations for specifying the debug level. The " +"simplest is to specify a decimal value from 0-9, which represents enabling " +"that level and all lower-level debug messages. The more comprehensive option " +"is to specify a hexadecimal bitmask to enable or disable specific levels " +"(such as if you wish to suppress a level)." +msgstr "" + +#. type: Content of: <listitem><para> +#: include/debug_levels.xml:10 +msgid "" +"Please note that each SSSD service logs into its own log file. Also please " +"note that enabling <quote>debug_level</quote> in the <quote>[sssd]</quote> " +"section only enables debugging just for the sssd process itself, not for the " +"responder or provider processes. The <quote>debug_level</quote> parameter " +"should be added to all sections that you wish to produce debug logs from." +msgstr "" + +#. type: Content of: <listitem><para> +#: include/debug_levels.xml:18 +msgid "" +"In addition to changing the log level in the config file using the " +"<quote>debug_level</quote> parameter, which is persistent, but requires SSSD " +"restart, it is also possible to change the debug level on the fly using the " +"<citerefentry> <refentrytitle>sss_debuglevel</refentrytitle> " +"<manvolnum>8</manvolnum> </citerefentry> tool." +msgstr "" + +#. type: Content of: <listitem><para> +#: include/debug_levels.xml:29 include/debug_levels_tools.xml:10 +msgid "Currently supported debug levels:" +msgstr "" + +#. type: Content of: <listitem><para> +#: include/debug_levels.xml:32 include/debug_levels_tools.xml:13 +msgid "" +"<emphasis>0</emphasis>, <emphasis>0x0010</emphasis>: Fatal " +"failures. Anything that would prevent SSSD from starting up or causes it to " +"cease running." +msgstr "" + +#. type: Content of: <listitem><para> +#: include/debug_levels.xml:38 include/debug_levels_tools.xml:19 +msgid "" +"<emphasis>1</emphasis>, <emphasis>0x0020</emphasis>: Critical failures. An " +"error that doesn't kill SSSD, but one that indicates that at least one major " +"feature is not going to work properly." +msgstr "" + +#. type: Content of: <listitem><para> +#: include/debug_levels.xml:45 include/debug_levels_tools.xml:26 +msgid "" +"<emphasis>2</emphasis>, <emphasis>0x0040</emphasis>: Serious failures. An " +"error announcing that a particular request or operation has failed." +msgstr "" + +#. type: Content of: <listitem><para> +#: include/debug_levels.xml:50 include/debug_levels_tools.xml:31 +msgid "" +"<emphasis>3</emphasis>, <emphasis>0x0080</emphasis>: Minor failures. These " +"are the errors that would percolate down to cause the operation failure of " +"2." +msgstr "" + +#. type: Content of: <listitem><para> +#: include/debug_levels.xml:55 include/debug_levels_tools.xml:36 +msgid "<emphasis>4</emphasis>, <emphasis>0x0100</emphasis>: Configuration settings." +msgstr "" + +#. type: Content of: <listitem><para> +#: include/debug_levels.xml:59 include/debug_levels_tools.xml:40 +msgid "<emphasis>5</emphasis>, <emphasis>0x0200</emphasis>: Function data." +msgstr "" + +#. type: Content of: <listitem><para> +#: include/debug_levels.xml:63 include/debug_levels_tools.xml:44 +msgid "" +"<emphasis>6</emphasis>, <emphasis>0x0400</emphasis>: Trace messages for " +"operation functions." +msgstr "" + +#. type: Content of: <listitem><para> +#: include/debug_levels.xml:67 include/debug_levels_tools.xml:48 +msgid "" +"<emphasis>7</emphasis>, <emphasis>0x1000</emphasis>: Trace messages for " +"internal control functions." +msgstr "" + +#. type: Content of: <listitem><para> +#: include/debug_levels.xml:72 include/debug_levels_tools.xml:53 +msgid "" +"<emphasis>8</emphasis>, <emphasis>0x2000</emphasis>: Contents of " +"function-internal variables that may be interesting." +msgstr "" + +#. type: Content of: <listitem><para> +#: include/debug_levels.xml:77 include/debug_levels_tools.xml:58 +msgid "" +"<emphasis>9</emphasis>, <emphasis>0x4000</emphasis>: Extremely low-level " +"tracing information." +msgstr "" + +#. type: Content of: <listitem><para> +#: include/debug_levels.xml:81 +msgid "" +"<emphasis>9</emphasis>, <emphasis>0x20000</emphasis>: Performance and " +"statistical data, please note that due to the way requests are processed " +"internally the logged execution time of a request might be longer than it " +"actually was." +msgstr "" + +#. type: Content of: <listitem><para> +#: include/debug_levels.xml:88 include/debug_levels_tools.xml:62 +msgid "" +"<emphasis>10</emphasis>, <emphasis>0x10000</emphasis>: Even more low-level " +"libldb tracing information. Almost never really required." +msgstr "" + +#. type: Content of: <listitem><para> +#: include/debug_levels.xml:93 include/debug_levels_tools.xml:67 +msgid "" +"To log required bitmask debug levels, simply add their numbers together as " +"shown in following examples:" +msgstr "" + +#. type: Content of: <listitem><para> +#: include/debug_levels.xml:97 include/debug_levels_tools.xml:71 +msgid "" +"<emphasis>Example</emphasis>: To log fatal failures, critical failures, " +"serious failures and function data use 0x0270." +msgstr "" + +#. type: Content of: <listitem><para> +#: include/debug_levels.xml:101 include/debug_levels_tools.xml:75 +msgid "" +"<emphasis>Example</emphasis>: To log fatal failures, configuration settings, " +"function data, trace messages for internal control functions use 0x1310." +msgstr "" + +#. type: Content of: <listitem><para> +#: include/debug_levels.xml:106 include/debug_levels_tools.xml:80 +msgid "" +"<emphasis>Note</emphasis>: The bitmask format of debug levels was introduced " +"in 1.7.0." +msgstr "" + +#. type: Content of: <listitem><para> +#: include/debug_levels.xml:110 include/debug_levels_tools.xml:84 +msgid "" +"<emphasis>Default</emphasis>: 0x0070 (i.e. fatal, critical and serious " +"failures; corresponds to setting 2 in decimal notation)" +msgstr "" + +#. type: Content of: <refsect1><para> +#: include/seealso.xml:4 +msgid "" +"<citerefentry> <refentrytitle>sssd</refentrytitle><manvolnum>8</manvolnum> " +"</citerefentry>, <citerefentry> " +"<refentrytitle>sssd.conf</refentrytitle><manvolnum>5</manvolnum> " +"</citerefentry>, <citerefentry> " +"<refentrytitle>sssd-ldap</refentrytitle><manvolnum>5</manvolnum> " +"</citerefentry>, <citerefentry> " +"<refentrytitle>sssd-ldap-attributes</refentrytitle><manvolnum>5</manvolnum> " +"</citerefentry>, <citerefentry> " +"<refentrytitle>sssd-krb5</refentrytitle><manvolnum>5</manvolnum> " +"</citerefentry>, <citerefentry> " +"<refentrytitle>sssd-simple</refentrytitle><manvolnum>5</manvolnum> " +"</citerefentry>, <citerefentry> " +"<refentrytitle>sssd-ipa</refentrytitle><manvolnum>5</manvolnum> " +"</citerefentry>, <citerefentry> " +"<refentrytitle>sssd-ad</refentrytitle><manvolnum>5</manvolnum> " +"</citerefentry>, <phrase condition=\"with_idp_provider\"> <citerefentry> " +"<refentrytitle>sssd-idp</refentrytitle> <manvolnum>5</manvolnum> " +"</citerefentry>, </phrase> <phrase condition=\"with_sudo\"> <citerefentry> " +"<refentrytitle>sssd-sudo</refentrytitle> <manvolnum>5</manvolnum> " +"</citerefentry>, </phrase> <citerefentry> " +"<refentrytitle>sssd-session-recording</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry>, <citerefentry> " +"<refentrytitle>sss_cache</refentrytitle><manvolnum>8</manvolnum> " +"</citerefentry>, <citerefentry> " +"<refentrytitle>sss_debuglevel</refentrytitle><manvolnum>8</manvolnum> " +"</citerefentry>, <citerefentry> " +"<refentrytitle>sss_obfuscate</refentrytitle><manvolnum>8</manvolnum> " +"</citerefentry>, <citerefentry> " +"<refentrytitle>sss_seed</refentrytitle><manvolnum>8</manvolnum> " +"</citerefentry>, <citerefentry> " +"<refentrytitle>sssd_krb5_locator_plugin</refentrytitle><manvolnum>8</manvolnum> " +"</citerefentry>, <phrase condition=\"with_ssh\"> <citerefentry> " +"<refentrytitle>sss_ssh_authorizedkeys</refentrytitle> " +"<manvolnum>1</manvolnum> </citerefentry>, <citerefentry> " +"<refentrytitle>sss_ssh_knownhosts</refentrytitle> <manvolnum>1</manvolnum> " +"</citerefentry>, </phrase> <citerefentry> " +"<refentrytitle>sssd-ifp</refentrytitle> <manvolnum>5</manvolnum> " +"</citerefentry>, <citerefentry> " +"<refentrytitle>pam_sss</refentrytitle><manvolnum>8</manvolnum> " +"</citerefentry>. <citerefentry> " +"<refentrytitle>sss_rpcidmapd</refentrytitle> <manvolnum>5</manvolnum> " +"</citerefentry> <phrase condition=\"with_stap\"> <citerefentry> " +"<refentrytitle>sssd-systemtap</refentrytitle> <manvolnum>5</manvolnum> " +"</citerefentry> </phrase>" +msgstr "" + +#. type: Content of: <listitem><para> +#: include/ldap_search_bases.xml:3 +msgid "" +"An optional base DN, search scope and LDAP filter to restrict LDAP searches " +"for this attribute type." +msgstr "" + +#. type: Content of: <listitem><para><programlisting> +#: include/ldap_search_bases.xml:9 +#, no-wrap +msgid "search_base[?scope?[filter][?search_base?scope?[filter]]*]\n" +msgstr "" + +#. type: Content of: <listitem><para> +#: include/ldap_search_bases.xml:7 +msgid "syntax: <placeholder type=\"programlisting\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <listitem><para> +#: include/ldap_search_bases.xml:13 +msgid "" +"The scope can be one of \"base\", \"onelevel\" or \"subtree\". The scope " +"functions as specified in section 4.5.1.2 of " +"http://tools.ietf.org/html/rfc4511" +msgstr "" + +#. type: Content of: <listitem><para> +#: include/ldap_search_bases.xml:23 +msgid "" +"For examples of this syntax, please refer to the " +"<quote>ldap_search_base</quote> examples section." +msgstr "" + +#. type: Content of: <listitem><para> +#: include/ldap_search_bases.xml:31 +msgid "" +"Please note that specifying scope or filter is not supported for searches " +"against an Active Directory Server that might yield a large number of " +"results and trigger the Range Retrieval extension in the response." +msgstr "" + +#. type: Content of: <para> +#: include/autofs_restart.xml:2 +msgid "" +"Please note that the automounter only reads the master map on startup, so if " +"any autofs-related changes are made to the sssd.conf, you typically also " +"need to restart the automounter daemon after restarting the SSSD." +msgstr "" + +#. type: Content of: <varlistentry><term> +#: include/override_homedir.xml:2 +msgid "override_homedir (string)" +msgstr "" + +#. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: include/override_homedir.xml:16 +msgid "UID number" +msgstr "" + +#. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: include/override_homedir.xml:20 +msgid "domain name" +msgstr "" + +#. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><term> +#: include/override_homedir.xml:23 +msgid "%f" +msgstr "" + +#. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: include/override_homedir.xml:24 +msgid "fully qualified user name (user@domain)" +msgstr "" + +#. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><term> +#: include/override_homedir.xml:27 +msgid "%l" +msgstr "" + +#. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: include/override_homedir.xml:28 +msgid "The first letter of the login name." +msgstr "" + +#. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: include/override_homedir.xml:32 +msgid "UPN - User Principal Name (name@REALM)" +msgstr "" + +#. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><term> +#: include/override_homedir.xml:35 +msgid "%o" +msgstr "" + +#. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: include/override_homedir.xml:38 +msgid "The homedir value that is defined in the directory of the identity provider." +msgstr "" + +#. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: include/override_homedir.xml:42 +msgid "" +"This substitution is designed to be used in an IPA-AD trust scenario. If " +"this substitution is used for the <emphasis>subdomain_homedir</emphasis> " +"option, it propagates the home directory value from the AD domain to the IPA " +"clients. In this scenario, the option must be set in the SSSD configuration " +"on the IPA server where SSSD is running in server mode." +msgstr "" + +#. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: include/override_homedir.xml:55 +msgid "" +"The path defined for the homedir directory attribute of the identity " +"provider, but in lower case. For details of use, see " +"<emphasis>%o</emphasis>." +msgstr "" + +#. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><term> +#: include/override_homedir.xml:61 +msgid "%H" +msgstr "" + +#. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: include/override_homedir.xml:63 +msgid "The value of configure option <emphasis>homedir_substring</emphasis>." +msgstr "" + +#. type: Content of: <varlistentry><listitem><para> +#: include/override_homedir.xml:5 +msgid "" +"Override the user's home directory. You can either provide an absolute value " +"or a template. In the template, the following sequences are substituted: " +"<placeholder type=\"variablelist\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <varlistentry><listitem><para> +#: include/override_homedir.xml:75 +msgid "This option can also be set per-domain." +msgstr "" + +#. type: Content of: <varlistentry><listitem><para><programlisting> +#: include/override_homedir.xml:80 +#, no-wrap +msgid "" +"override_homedir = /home/%u\n" +" " +msgstr "" + +#. type: Content of: <varlistentry><listitem><para> +#: include/override_homedir.xml:84 +msgid "Default: Not set (SSSD will use the value retrieved from LDAP)" +msgstr "" + +#. type: Content of: <varlistentry><listitem><para> +#: include/override_homedir.xml:88 +msgid "" +"Please note, the home directory from a specific override for the user, " +"either locally (see " +"<citerefentry><refentrytitle>sss_override</refentrytitle> " +"<manvolnum>8</manvolnum></citerefentry>) or centrally managed IPA " +"id-overrides, has a higher precedence and will be used instead of the value " +"given by override_homedir." +msgstr "" + +#. type: Content of: <varlistentry><term> +#: include/homedir_substring.xml:2 +msgid "homedir_substring (string)" +msgstr "" + +#. type: Content of: <varlistentry><listitem><para> +#: include/homedir_substring.xml:5 +msgid "" +"The value of this option will be used in the expansion of the " +"<emphasis>override_homedir</emphasis> option if the template contains the " +"format string <emphasis>%H</emphasis>. An LDAP directory entry can directly " +"contain this template so that this option can be used to expand the home " +"directory path for each client machine (or operating system). It can be set " +"per-domain or globally in the [nss] section. A value specified in a domain " +"section will override one set in the [nss] section." +msgstr "" + +#. type: Content of: <varlistentry><listitem><para> +#: include/homedir_substring.xml:15 +msgid "Default: /home" +msgstr "" + +#. type: Content of: <refsect1><title> +#: include/ad_modified_defaults.xml:2 include/ipa_modified_defaults.xml:2 +msgid "MODIFIED DEFAULT OPTIONS" +msgstr "" + +#. type: Content of: <refsect1><para> +#: include/ad_modified_defaults.xml:4 +msgid "" +"Certain option defaults do not match their respective backend provider " +"defaults, these option names and AD provider-specific defaults are listed " +"below:" +msgstr "" + +#. type: Content of: <refsect1><refsect2><title> +#: include/ad_modified_defaults.xml:9 include/ipa_modified_defaults.xml:9 +msgid "KRB5 Provider" +msgstr "" + +#. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> +#: include/ad_modified_defaults.xml:13 include/ipa_modified_defaults.xml:13 +msgid "krb5_validate = true" +msgstr "" + +#. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> +#: include/ad_modified_defaults.xml:18 +msgid "krb5_use_enterprise_principal = true" +msgstr "" + +#. type: Content of: <refsect1><refsect2><title> +#: include/ad_modified_defaults.xml:24 +msgid "LDAP Provider" +msgstr "" + +#. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> +#: include/ad_modified_defaults.xml:28 +msgid "ldap_schema = ad" +msgstr "" + +#. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> +#: include/ad_modified_defaults.xml:33 include/ipa_modified_defaults.xml:38 +msgid "ldap_force_upper_case_realm = true" +msgstr "" + +#. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> +#: include/ad_modified_defaults.xml:38 +msgid "ldap_id_mapping = true" +msgstr "" + +#. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> +#: include/ad_modified_defaults.xml:43 +msgid "ldap_sasl_mech = GSS-SPNEGO" +msgstr "" + +#. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> +#: include/ad_modified_defaults.xml:48 +msgid "ldap_referrals = false" +msgstr "" + +#. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> +#: include/ad_modified_defaults.xml:53 +msgid "ldap_account_expire_policy = ad" +msgstr "" + +#. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> +#: include/ad_modified_defaults.xml:58 include/ipa_modified_defaults.xml:58 +msgid "ldap_use_tokengroups = true" +msgstr "" + +#. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> +#: include/ad_modified_defaults.xml:63 +msgid "ldap_sasl_authid = sAMAccountName@REALM (typically SHORTNAME$@REALM)" +msgstr "" + +#. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> +#: include/ad_modified_defaults.xml:66 +msgid "" +"The AD provider looks for a different principal than the LDAP provider by " +"default, because in an Active Directory environment the principals are " +"divided into two groups - User Principals and Service Principals. Only User " +"Principal can be used to obtain a TGT and by default, computer object's " +"principal is constructed from its sAMAccountName and the AD realm. The " +"well-known host/hostname@REALM principal is a Service Principal and thus " +"cannot be used to get a TGT with." +msgstr "" + +#. type: Content of: <refsect1><refsect2><title> +#: include/ad_modified_defaults.xml:80 +msgid "NSS configuration" +msgstr "" + +#. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> +#: include/ad_modified_defaults.xml:84 +msgid "fallback_homedir = /home/%d/%u" +msgstr "" + +#. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> +#: include/ad_modified_defaults.xml:87 +msgid "" +"The AD provider automatically sets \"fallback_homedir = /home/%d/%u\" to " +"provide personal home directories for users without the homeDirectory " +"attribute. If your AD Domain is properly populated with Posix attributes, " +"and you want to avoid this fallback behavior, you can explicitly set " +"\"fallback_homedir = %o\"." +msgstr "" + +#. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> +#: include/ad_modified_defaults.xml:96 +msgid "" +"Note that the system typically expects a home directory in /home/%u " +"folder. If you decide to use a different directory structure, some other " +"parts of your system may need adjustments." +msgstr "" + +#. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> +#: include/ad_modified_defaults.xml:102 +msgid "" +"For example automated creation of home directories in combination with " +"selinux requires selinux adjustment, otherwise the home directory will be " +"created with wrong selinux context." +msgstr "" + +#. type: Content of: <refsect1><para> +#: include/ipa_modified_defaults.xml:4 +msgid "" +"Certain option defaults do not match their respective backend provider " +"defaults, these option names and IPA provider-specific defaults are listed " +"below:" +msgstr "" + +#. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> +#: include/ipa_modified_defaults.xml:18 +msgid "krb5_use_fast = try" +msgstr "" + +#. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> +#: include/ipa_modified_defaults.xml:23 +msgid "krb5_canonicalize = true" +msgstr "" + +#. type: Content of: <refsect1><refsect2><title> +#: include/ipa_modified_defaults.xml:29 +msgid "LDAP Provider - General" +msgstr "" + +#. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> +#: include/ipa_modified_defaults.xml:33 +msgid "ldap_schema = ipa_v1" +msgstr "" + +#. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> +#: include/ipa_modified_defaults.xml:43 +msgid "ldap_sasl_mech = GSSAPI" +msgstr "" + +#. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> +#: include/ipa_modified_defaults.xml:48 +msgid "ldap_sasl_minssf = 56" +msgstr "" + +#. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> +#: include/ipa_modified_defaults.xml:53 +msgid "ldap_account_expire_policy = ipa" +msgstr "" + +#. type: Content of: <refsect1><refsect2><title> +#: include/ipa_modified_defaults.xml:64 +msgid "LDAP Provider - User options" +msgstr "" + +#. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> +#: include/ipa_modified_defaults.xml:68 +msgid "ldap_user_member_of = memberOf" +msgstr "" + +#. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> +#: include/ipa_modified_defaults.xml:73 +msgid "ldap_user_uuid = ipaUniqueID" +msgstr "" + +#. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> +#: include/ipa_modified_defaults.xml:78 +msgid "ldap_user_ssh_public_key = ipaSshPubKey" +msgstr "" + +#. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> +#: include/ipa_modified_defaults.xml:83 +msgid "ldap_user_auth_type = ipaUserAuthType" +msgstr "" + +#. type: Content of: <refsect1><refsect2><title> +#: include/ipa_modified_defaults.xml:89 +msgid "LDAP Provider - Group options" +msgstr "" + +#. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> +#: include/ipa_modified_defaults.xml:93 +msgid "ldap_group_object_class = ipaUserGroup" +msgstr "" + +#. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> +#: include/ipa_modified_defaults.xml:98 +msgid "ldap_group_object_class_alt = posixGroup" +msgstr "" + +#. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> +#: include/ipa_modified_defaults.xml:103 +msgid "ldap_group_member = member" +msgstr "" + +#. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> +#: include/ipa_modified_defaults.xml:108 +msgid "ldap_group_uuid = ipaUniqueID" +msgstr "" + +#. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> +#: include/ipa_modified_defaults.xml:113 +msgid "ldap_group_objectsid = ipaNTSecurityIdentifier" +msgstr "" + +#. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> +#: include/ipa_modified_defaults.xml:118 +msgid "ldap_group_external_member = ipaExternalMember" +msgstr "" + +#. type: Content of: <variablelist><varlistentry><term> +#: include/krb5_options.xml:3 +msgid "krb5_auth_timeout (integer)" +msgstr "" + +#. type: Content of: <variablelist><varlistentry><listitem><para> +#: include/krb5_options.xml:6 +msgid "" +"Timeout in seconds after an online authentication request or change password " +"request is aborted. If possible, the authentication request is continued " +"offline." +msgstr "" + +#. type: Content of: <variablelist><varlistentry><term> +#: include/krb5_options.xml:17 +msgid "krb5_validate (boolean)" +msgstr "" + +#. type: Content of: <variablelist><varlistentry><listitem><para> +#: include/krb5_options.xml:20 +msgid "" +"Verify with the help of krb5_keytab that the TGT obtained has not been " +"spoofed. The keytab is checked for entries sequentially, and the first entry " +"with a matching realm is used for validation. If no entry matches the realm, " +"the last entry in the keytab is used. This process can be used to validate " +"environments using cross-realm trust by placing the appropriate keytab entry " +"as the last entry or the only entry in the keytab file." +msgstr "" + +#. type: Content of: <variablelist><varlistentry><listitem><para> +#: include/krb5_options.xml:29 +msgid "Default: false (IPA and AD provider: true)" +msgstr "" + +#. type: Content of: <variablelist><varlistentry><listitem><para> +#: include/krb5_options.xml:32 +msgid "" +"Please note that the ticket validation is the first step when checking the " +"PAC (see 'pac_check' in the <citerefentry> " +"<refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</manvolnum> " +"</citerefentry> manual page for details). If ticket validation is disabled " +"the PAC checks will be skipped as well." +msgstr "" + +#. type: Content of: <variablelist><varlistentry><term> +#: include/krb5_options.xml:44 +msgid "krb5_renewable_lifetime (string)" +msgstr "" + +#. type: Content of: <variablelist><varlistentry><listitem><para> +#: include/krb5_options.xml:47 +msgid "" +"Request a renewable ticket with a total lifetime, given as an integer " +"immediately followed by a time unit:" +msgstr "" + +#. type: Content of: <variablelist><varlistentry><listitem><para> +#: include/krb5_options.xml:52 include/krb5_options.xml:86 +#: include/krb5_options.xml:123 +msgid "<emphasis>s</emphasis> for seconds" +msgstr "" + +#. type: Content of: <variablelist><varlistentry><listitem><para> +#: include/krb5_options.xml:55 include/krb5_options.xml:89 +#: include/krb5_options.xml:126 +msgid "<emphasis>m</emphasis> for minutes" +msgstr "" + +#. type: Content of: <variablelist><varlistentry><listitem><para> +#: include/krb5_options.xml:58 include/krb5_options.xml:92 +#: include/krb5_options.xml:129 +msgid "<emphasis>h</emphasis> for hours" +msgstr "" + +#. type: Content of: <variablelist><varlistentry><listitem><para> +#: include/krb5_options.xml:61 include/krb5_options.xml:95 +#: include/krb5_options.xml:132 +msgid "<emphasis>d</emphasis> for days." +msgstr "" + +#. type: Content of: <variablelist><varlistentry><listitem><para> +#: include/krb5_options.xml:64 include/krb5_options.xml:135 +msgid "If there is no unit given, <emphasis>s</emphasis> is assumed." +msgstr "" + +#. type: Content of: <variablelist><varlistentry><listitem><para> +#: include/krb5_options.xml:68 include/krb5_options.xml:139 +msgid "" +"NOTE: It is not possible to mix units. To set the renewable lifetime to one " +"and a half hours, use '90m' instead of '1h30m'." +msgstr "" + +#. type: Content of: <variablelist><varlistentry><listitem><para> +#: include/krb5_options.xml:73 +msgid "Default: not set, i.e. the TGT is not renewable" +msgstr "" + +#. type: Content of: <variablelist><varlistentry><term> +#: include/krb5_options.xml:79 +msgid "krb5_lifetime (string)" +msgstr "" + +#. type: Content of: <variablelist><varlistentry><listitem><para> +#: include/krb5_options.xml:82 +msgid "" +"Request ticket with a lifetime, given as an integer immediately followed by " +"a time unit:" +msgstr "" + +#. type: Content of: <variablelist><varlistentry><listitem><para> +#: include/krb5_options.xml:98 +msgid "If there is no unit given <emphasis>s</emphasis> is assumed." +msgstr "" + +#. type: Content of: <variablelist><varlistentry><listitem><para> +#: include/krb5_options.xml:102 +msgid "" +"NOTE: It is not possible to mix units. To set the lifetime to one and a " +"half hours please use '90m' instead of '1h30m'." +msgstr "" + +#. type: Content of: <variablelist><varlistentry><listitem><para> +#: include/krb5_options.xml:107 +msgid "Default: not set, i.e. the default ticket lifetime configured on the KDC." +msgstr "" + +#. type: Content of: <variablelist><varlistentry><term> +#: include/krb5_options.xml:114 +msgid "krb5_renew_interval (string)" +msgstr "" + +#. type: Content of: <variablelist><varlistentry><listitem><para> +#: include/krb5_options.xml:117 +msgid "" +"The time in seconds between two checks if the TGT should be renewed. TGTs " +"are renewed if about half of their lifetime is exceeded, given as an integer " +"immediately followed by a time unit:" +msgstr "" + +#. type: Content of: <variablelist><varlistentry><listitem><para> +#: include/krb5_options.xml:144 +msgid "If this option is not set or is 0 the automatic renewal is disabled." +msgstr "" + +#. type: Content of: <variablelist><varlistentry><listitem><para> +#: include/krb5_options.xml:157 +msgid "" +"Specifies if the host and user principal should be canonicalized. This " +"feature is available with MIT Kerberos 1.7 and later versions." +msgstr "" diff --git a/src/man/po/ru.po b/src/man/po/ru.po index 954197f6a6a..7248be5ef0f 100644 --- a/src/man/po/ru.po +++ b/src/man/po/ru.po @@ -8,9 +8,9 @@ msgid "" msgstr "" "Project-Id-Version: sssd-docs 2.3.0\n" "Report-Msgid-Bugs-To: sssd-devel@redhat.com\n" -"POT-Creation-Date: 2026-01-14 15:00+0000\n" -"PO-Revision-Date: 2026-04-23 16:52+0000\n" -"Last-Translator: Vik <k3kelm4vw@mozmail.com>\n" +"POT-Creation-Date: 2026-10-05 16:14+0000\n" +"PO-Revision-Date: 2026-10-05 21:20+0000\n" +"Last-Translator: Andrei Stepanov <adem4ik@gmail.com>\n" "Language-Team: Russian <https://translate.fedoraproject.org/projects/sssd/" "sssd-manpage-master/ru/>\n" "Language: ru\n" @@ -19,10 +19,10 @@ msgstr "" "Content-Transfer-Encoding: 8bit\n" "Plural-Forms: nplurals=3; plural=n%10==1 && n%100!=11 ? 0 : n%10>=2 && " "n%10<=4 && (n%100<10 || n%100>=20) ? 1 : 2;\n" -"X-Generator: Weblate 5.17\n" +"X-Generator: Weblate 2026.10\n" #. type: Content of: <reference><title> -#: sssd.conf.5.xml:8 sssd-ldap.5.xml:5 pam_sss.8.xml:5 pam_sss_gss.8.xml:5 +#: sssd.conf.5.xml:10 sssd-ldap.5.xml:5 pam_sss.8.xml:5 pam_sss_gss.8.xml:5 #: sssd_krb5_locator_plugin.8.xml:5 sssd-simple.5.xml:5 sss-certmap.5.xml:5 #: sssd-ipa.5.xml:5 sssd-ad.5.xml:5 sssd-sudo.5.xml:5 sssd-idp.5.xml:5 #: sssd.8.xml:5 sss_obfuscate.8.xml:5 sss_override.8.xml:5 sssd-krb5.5.xml:5 @@ -35,12 +35,12 @@ msgid "SSSD Manual pages" msgstr "Справка по SSSD" #. type: Content of: <reference><refentry><refnamediv><refname> -#: sssd.conf.5.xml:13 sssd.conf.5.xml:19 +#: sssd.conf.5.xml:15 sssd.conf.5.xml:21 msgid "sssd.conf" msgstr "sssd.conf" #. type: Content of: <reference><refentry><refmeta><manvolnum> -#: sssd.conf.5.xml:14 sssd-ldap.5.xml:11 sssd-simple.5.xml:11 +#: sssd.conf.5.xml:16 sssd-ldap.5.xml:11 sssd-simple.5.xml:11 #: sss-certmap.5.xml:11 sssd-ipa.5.xml:11 sssd-ad.5.xml:11 sssd-sudo.5.xml:11 #: sssd-idp.5.xml:11 sssd-krb5.5.xml:11 sssd-ifp.5.xml:11 #: sss_rpcidmapd.5.xml:27 sssd-session-recording.5.xml:11 @@ -49,7 +49,7 @@ msgid "5" msgstr "5" #. type: Content of: <reference><refentry><refmeta><refmiscinfo> -#: sssd.conf.5.xml:15 sssd-ldap.5.xml:12 sssd-simple.5.xml:12 +#: sssd.conf.5.xml:17 sssd-ldap.5.xml:12 sssd-simple.5.xml:12 #: sss-certmap.5.xml:12 sssd-ipa.5.xml:12 sssd-ad.5.xml:12 sssd-sudo.5.xml:12 #: sssd-idp.5.xml:12 sssd-krb5.5.xml:12 sssd-ifp.5.xml:12 #: sss_rpcidmapd.5.xml:28 sssd-session-recording.5.xml:12 sssd-kcm.8.xml:12 @@ -58,17 +58,17 @@ msgid "File Formats and Conventions" msgstr "Форматы файлов и рекомендации" #. type: Content of: <reference><refentry><refnamediv><refpurpose> -#: sssd.conf.5.xml:20 +#: sssd.conf.5.xml:22 msgid "the configuration file for SSSD" msgstr "файл конфигурации SSSD" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:24 +#: sssd.conf.5.xml:26 msgid "FILE FORMAT" msgstr "ФОРМАТ ФАЙЛА" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd.conf.5.xml:32 +#: sssd.conf.5.xml:34 #, no-wrap msgid "" "<replaceable>[section]</replaceable>\n" @@ -83,7 +83,7 @@ msgstr "" " " #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:27 +#: sssd.conf.5.xml:29 msgid "" "The file has an ini-style syntax and consists of sections and parameters. A " "section begins with the name of the section in square brackets and continues " @@ -97,16 +97,22 @@ msgstr "" "type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:39 +#: sssd.conf.5.xml:41 msgid "" -"The data types used are string (no quotes needed), integer and bool (with " -"values of <quote>TRUE/FALSE</quote>)." +"The data types used are string (no quotes needed), integer and boolean (with " +"values of <quote>TRUE/FALSE</quote>). Boolean values are case-insensitive; " +"for example, <quote>TRUE</quote>, <quote>True</quote> and <quote>true</" +"quote> are all equivalent and valid; the same applies to <quote>FALSE</" +"quote>." msgstr "" -"Используемые типы данных: строка (кавычки не требуются), целое число и " -"логическое значение (возможные значения: <quote>TRUE/FALSE</quote>)." +"Используются типы данных: строка (кавычки не требуются), целое число и " +"логическое значение (со значениями <quote>TRUE/FALSE</quote>). Логические " +"значения нечувствительны к регистру; например, <quote>TRUE</quote>, <quote>" +"True</quote> и <quote>true</quote> эквивалентны и допустимы; то же самое " +"относится к <quote>FALSE</quote>." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:44 +#: sssd.conf.5.xml:49 msgid "" "A comment line starts with a hash sign (<quote>#</quote>) or a semicolon " "(<quote>;</quote>). Inline comments are not supported." @@ -116,7 +122,7 @@ msgstr "" "предусмотрена." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:50 +#: sssd.conf.5.xml:55 msgid "" "All sections can have an optional <replaceable>description</replaceable> " "parameter. Its function is only as a label for the section." @@ -125,7 +131,7 @@ msgstr "" "description</replaceable>. Он предназначен только для обозначения раздела." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:56 +#: sssd.conf.5.xml:61 msgid "" "<filename>sssd.conf</filename> must be a regular file that is owned, " "readable, and writeable only by 'root'." @@ -134,7 +140,7 @@ msgstr "" "принадлежать и быть доступен для чтения и записи только пользователю «root»." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:60 +#: sssd.conf.5.xml:65 msgid "" "<filename>sssd.conf</filename> must be a regular file that is accessible " "only by the user used to run SSSD service or root." @@ -143,12 +149,12 @@ msgstr "" "пользователю, используемому для запуска службы SSSD, или пользователю root." #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:66 +#: sssd.conf.5.xml:71 msgid "CONFIGURATION SNIPPETS FROM INCLUDE DIRECTORY" msgstr "ФРАГМЕНТЫ КОНФИГУРАЦИИ ИЗ КАТАЛОГА ВКЛЮЧЕНИЯ" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:69 +#: sssd.conf.5.xml:74 msgid "" "The configuration file <filename>sssd.conf</filename> will include " "configuration snippets using the include directory <filename>conf.d</" @@ -158,7 +164,7 @@ msgstr "" "конфигурации из каталога <filename>conf.d</filename>." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:75 +#: sssd.conf.5.xml:80 msgid "" "Any file placed in <filename>conf.d</filename> that ends in " "<quote><filename>.conf</filename></quote> and does not begin with a dot " @@ -171,7 +177,7 @@ msgstr "" "SSSD вместе с файлом <filename>sssd.conf</filename>." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:83 +#: sssd.conf.5.xml:88 msgid "" "The configuration snippets from <filename>conf.d</filename> have higher " "priority than <filename>sssd.conf</filename> and will override " @@ -193,7 +199,7 @@ msgstr "" "приоритет (чем больше число, тем выше приоритет)." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:97 +#: sssd.conf.5.xml:102 msgid "" "The snippet files require the same owner and permissions as " "<filename>sssd.conf</filename>." @@ -202,32 +208,100 @@ msgstr "" "файл <filename>sssd.conf</filename>." #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:103 +#: sssd.conf.5.xml:108 +msgid "VENDOR PROVIDED CONFIGURATION" +msgstr "КОНФИГУРАЦИЯ, ПРЕДОСТАВЛЯЕМАЯ ПОСТАВЩИКОМ" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:111 +msgid "" +"The vendor provided configuration file is installed in " +"<filename>&sssd_vendor_dir;/sssd.conf</filename>, but this file must not be " +"directly edited. It can be completely masked by creating the system specific " +"configuration file <filename>&sssd_conf_dir;/sssd.conf</filename>, or partly " +"overriden by creating config snippets in <filename>&sssd_conf_dir;/conf.d</" +"filename> directory." +msgstr "" +"Файл конфигурации, предоставляемый поставщиком, устанавливается в <filename>" +"&sssd_vendor_dir;/sssd.conf</filename>, но этот файл не должен " +"редактироваться напрямую. Его можно полностью перекрыть, создав " +"общесистемный файл конфигурации <filename>&sssd_conf_dir;/sssd.conf</" +"filename>, или частично переопределить, создав фрагменты конфигурации в " +"каталоге <filename>&sssd_conf_dir;/conf.d</filename>." + +#. type: Content of: <reference><refentry><refsect1><refsect2><title> +#: sssd.conf.5.xml:120 +msgid "CONFIGURATION FILE HIERARCHY" +msgstr "ИЕРАРХИЯ ФАЙЛОВ КОНФИГУРАЦИИ" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:122 +msgid "" +"When sssd reads the configuration it first tries to open the system specific " +"configuration file in <filename>&sssd_conf_dir;/sssd.conf</filename>. If it " +"exists, it is loaded and snippets from <filename>&sssd_conf_dir;/conf.d</" +"filename> are applied. The vendor provided configuration file " +"<filename>&sssd_vendor_dir;/sssd.conf</filename> is completely ignored in " +"this case." +msgstr "" +"Когда sssd читает конфигурацию, он сначала пытается открыть общесистемный " +"файл конфигурации в <filename>&sssd_conf_dir;/sssd.conf</filename>. Если он " +"существует, он загружается и применяются фрагменты из <filename>" +"&sssd_conf_dir;/conf.d</filename>. Файл конфигурации, предоставляемый " +"поставщиком <filename>&sssd_vendor_dir;/sssd.conf</filename>, в этом случае " +"полностью игнорируется." + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:131 +msgid "" +"If the system specific configuration file <filename>&sssd_conf_dir;/" +"sssd.conf</filename> does not exist, then the vendor configuration file " +"<filename>&sssd_vendor_dir;/sssd.conf</filename> is loaded and snippets from " +"<filename>&sssd_conf_dir;/conf.d</filename> are applied." +msgstr "" +"Если общесистемный файл конфигурации <filename>&sssd_conf_dir;/sssd.conf</" +"filename> не существует, загружается файл конфигурации поставщика <filename>" +"&sssd_vendor_dir;/sssd.conf</filename> и применяются фрагменты из <filename>" +"&sssd_conf_dir;/conf.d</filename>." + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd.conf.5.xml:141 msgid "GENERAL OPTIONS" msgstr "ОБЩИЕ ПАРАМЕТРЫ" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:105 +#: sssd.conf.5.xml:143 msgid "Following options are usable in more than one configuration sections." msgstr "Следующие параметры используются в нескольких разделах конфигурации." #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:109 +#: sssd.conf.5.xml:147 msgid "Options usable in all sections" msgstr "Параметры, используемые во всех разделах" +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:149 +msgid "" +"Note: Below options are ignored in <quote>[session_recording]</quote> " +"section, see <quote>Session recording configuration options</quote> section " +"for more details." +msgstr "" +"Примечание. Приведённые ниже параметры игнорируются в разделе <quote>" +"[session_recording]</quote>; подробности см. в разделе <quote>Параметры " +"конфигурации записи сеансов</quote>." + #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:113 +#: sssd.conf.5.xml:156 msgid "debug_level (integer)" msgstr "debug_level (целое число)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:117 +#: sssd.conf.5.xml:160 msgid "debug (integer)" msgstr "debug (целое число)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:120 +#: sssd.conf.5.xml:163 msgid "" "SSSD 1.14 and later also includes the <replaceable>debug</replaceable> alias " "for <replaceable>debug_level</replaceable> as a convenience feature. If both " @@ -240,12 +314,12 @@ msgstr "" "<replaceable>debug_level</replaceable>." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:130 -msgid "debug_timestamps (bool)" +#: sssd.conf.5.xml:173 +msgid "debug_timestamps (boolean)" msgstr "debug_timestamps (логическое значение)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:133 +#: sssd.conf.5.xml:176 msgid "" "Add a timestamp to the debug messages. If journald is enabled for SSSD " "debug logging this option is ignored." @@ -254,23 +328,23 @@ msgstr "" "отладки SSSD включена служба journald, этот параметр будет игнорироваться." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:138 sssd.conf.5.xml:175 sssd.conf.5.xml:337 -#: sssd.conf.5.xml:644 sssd.conf.5.xml:668 sssd.conf.5.xml:875 -#: sssd.conf.5.xml:979 sssd.conf.5.xml:2113 sssd-ldap.5.xml:979 -#: sssd-ldap.5.xml:1134 sssd-ldap.5.xml:1237 sssd-ldap.5.xml:1306 -#: sssd-ldap.5.xml:1714 sssd-ldap.5.xml:1848 sssd-ldap.5.xml:1913 -#: sssd-ipa.5.xml:346 sssd-ad.5.xml:252 sssd-ad.5.xml:367 sssd-ad.5.xml:1180 -#: sssd-ad.5.xml:1382 sssd-krb5.5.xml:358 +#: sssd.conf.5.xml:181 sssd.conf.5.xml:218 sssd.conf.5.xml:380 +#: sssd.conf.5.xml:687 sssd.conf.5.xml:711 sssd.conf.5.xml:827 +#: sssd.conf.5.xml:932 sssd.conf.5.xml:2149 sssd.conf.5.xml:4730 +#: sssd-ldap.5.xml:979 sssd-ldap.5.xml:1134 sssd-ldap.5.xml:1237 +#: sssd-ldap.5.xml:1306 sssd-ldap.5.xml:1714 sssd-ldap.5.xml:1848 +#: sssd-ldap.5.xml:1913 sssd-ipa.5.xml:341 sssd-ad.5.xml:252 sssd-ad.5.xml:367 +#: sssd-ad.5.xml:1180 sssd-ad.5.xml:1375 sssd-krb5.5.xml:358 msgid "Default: true" msgstr "По умолчанию: true" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:143 -msgid "debug_microseconds (bool)" +#: sssd.conf.5.xml:186 +msgid "debug_microseconds (boolean)" msgstr "debug_microseconds (логическое значение)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:146 +#: sssd.conf.5.xml:189 msgid "" "Add microseconds to the timestamp in debug messages. If journald is enabled " "for SSSD debug logging this option is ignored." @@ -280,26 +354,26 @@ msgstr "" "игнорироваться." #. type: Content of: <variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:151 sssd.conf.5.xml:2040 sssd.conf.5.xml:4158 +#: sssd.conf.5.xml:194 sssd.conf.5.xml:2072 sssd.conf.5.xml:4363 #: sssd-ldap.5.xml:363 sssd-ldap.5.xml:998 sssd-ldap.5.xml:1209 -#: sssd-ldap.5.xml:1663 sssd-ldap.5.xml:1937 sssd-ipa.5.xml:146 -#: sssd-ipa.5.xml:706 sssd-ad.5.xml:1135 sssd-krb5.5.xml:268 +#: sssd-ldap.5.xml:1663 sssd-ldap.5.xml:1937 sssd-ipa.5.xml:141 +#: sssd-ipa.5.xml:701 sssd-ad.5.xml:1140 sssd-idp.5.xml:287 sssd-krb5.5.xml:268 #: sssd-krb5.5.xml:330 sssd-krb5.5.xml:432 include/krb5_options.xml:163 msgid "Default: false" msgstr "По умолчанию: false" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:156 -msgid "debug_backtrace_enabled (bool)" +#: sssd.conf.5.xml:199 +msgid "debug_backtrace_enabled (boolean)" msgstr "debug_backtrace_enabled (логическое значение)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:159 +#: sssd.conf.5.xml:202 msgid "Enable debug backtrace." msgstr "Включить обратную трассировку отладки." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:162 +#: sssd.conf.5.xml:205 msgid "" "In case SSSD is run with debug_level less than 9, everything is logged to a " "ring buffer in memory and flushed to a log file on any error up to and " @@ -315,7 +389,7 @@ msgstr "" "случае — до 2)." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:171 +#: sssd.conf.5.xml:214 msgid "" "Feature is only supported for `logger == files` (i.e. setting doesn't have " "effect for other logger types)." @@ -324,7 +398,7 @@ msgstr "" "на другие типы журнала)." #. type: Content of: outside any tag (error?) -#: sssd.conf.5.xml:111 sssd.conf.5.xml:186 sssd-ldap.5.xml:1754 +#: sssd.conf.5.xml:154 sssd.conf.5.xml:229 sssd-ldap.5.xml:1754 #: sssd-ldap.5.xml:1960 sss-certmap.5.xml:645 sssd-systemtap.5.xml:82 #: sssd-systemtap.5.xml:143 sssd-systemtap.5.xml:236 sssd-systemtap.5.xml:274 #: sssd-systemtap.5.xml:330 sssd-ldap-attributes.5.xml:40 @@ -337,17 +411,17 @@ msgid "<placeholder type=\"variablelist\" id=\"0\"/>" msgstr "<placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:184 +#: sssd.conf.5.xml:227 msgid "Options usable in SERVICE and DOMAIN sections" msgstr "Параметры, используемые в разделах SERVICE и DOMAIN" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:188 +#: sssd.conf.5.xml:231 msgid "timeout (integer)" msgstr "timeout (целое число)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:191 +#: sssd.conf.5.xml:234 msgid "" "Timeout in seconds between heartbeats for this service. This is used to " "ensure that the process is alive and capable of answering requests. Note " @@ -359,34 +433,34 @@ msgstr "" "завершит свою работу." #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:198 sssd.conf.5.xml:1199 sssd.conf.5.xml:1673 -#: sssd.conf.5.xml:4174 sssd-ldap.5.xml:825 sssd-idp.5.xml:192 +#: sssd.conf.5.xml:241 sssd.conf.5.xml:1155 sssd.conf.5.xml:1665 +#: sssd.conf.5.xml:4379 sssd-ldap.5.xml:825 sssd-idp.5.xml:271 #: include/ldap_id_mapping.xml:270 msgid "Default: 10" msgstr "По умолчанию: 10" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:208 +#: sssd.conf.5.xml:251 msgid "SPECIAL SECTIONS" msgstr "ОСОБЫЕ РАЗДЕЛЫ" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:211 +#: sssd.conf.5.xml:254 msgid "The [sssd] section" msgstr "Раздел [sssd]" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><title> -#: sssd.conf.5.xml:220 +#: sssd.conf.5.xml:263 msgid "Section parameters" msgstr "Параметры раздела" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:222 -msgid "services" -msgstr "services" +#: sssd.conf.5.xml:265 +msgid "services (string)" +msgstr "services (строка)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:225 +#: sssd.conf.5.xml:268 msgid "" "Comma separated list of services that are started when sssd itself starts. " "<phrase condition=\"have_systemd\"> The services' list is optional on " @@ -399,7 +473,7 @@ msgstr "" "необходимости будут активированы с помощью сокета или D-Bus. </phrase>" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:234 +#: sssd.conf.5.xml:277 msgid "" "Supported services: nss, pam, ifp <phrase condition=\"with_sudo\">, sudo</" "phrase> <phrase condition=\"with_autofs\">, autofs</phrase> <phrase " @@ -412,7 +486,7 @@ msgstr "" "condition=\"with_pac_responder\">, pac</phrase>" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:241 +#: sssd.conf.5.xml:284 msgid "" "<phrase condition=\"have_systemd\"> By default, all services are disabled " "and the administrator must enable the ones allowed to be used by executing: " @@ -422,13 +496,13 @@ msgstr "" "Администратор должен включить разрешённые для использования службы с помощью " "следующей команды: «systemctl enable sssd-@service@.socket». </phrase>" -#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:250 -msgid "domains" -msgstr "domains" +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sssd.conf.5.xml:293 sssd.conf.5.xml:4562 +msgid "domains (string)" +msgstr "domains (строка)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:253 +#: sssd.conf.5.xml:296 msgid "" "A domain is a database containing user information. SSSD can use more " "domains at the same time, but at least one must be configured or SSSD won't " @@ -446,12 +520,12 @@ msgstr "" "Символ «/» использовать нельзя." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:266 sssd.conf.5.xml:3467 +#: sssd.conf.5.xml:309 sssd.conf.5.xml:3598 msgid "re_expression (string)" msgstr "re_expression (строка)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:269 +#: sssd.conf.5.xml:312 msgid "" "Default regular expression that describes how to parse the string containing " "user name and domain into these components." @@ -460,7 +534,7 @@ msgstr "" "содержащей имя пользователя и домен, для выделения этих частей." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:274 +#: sssd.conf.5.xml:317 msgid "" "Each domain can have an individual regular expression configured. For some " "ID providers there are also default regular expressions. See DOMAIN SECTIONS " @@ -472,12 +546,12 @@ msgstr "" "разделе справки «РАЗДЕЛЫ ДОМЕНА»." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:283 sssd.conf.5.xml:3524 +#: sssd.conf.5.xml:326 sssd.conf.5.xml:3655 msgid "full_name_format (string)" msgstr "full_name_format (строка)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:286 sssd.conf.5.xml:3527 +#: sssd.conf.5.xml:329 sssd.conf.5.xml:3658 msgid "" "A <citerefentry> <refentrytitle>printf</refentrytitle> <manvolnum>3</" "manvolnum> </citerefentry>-compatible format that describes how to compose a " @@ -488,32 +562,32 @@ msgstr "" "создания полностью определённого имени из имени пользователя и имени домена." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:297 sssd.conf.5.xml:3538 +#: sssd.conf.5.xml:340 sssd.conf.5.xml:3669 msgid "%1$s" msgstr "%1$s" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:298 sssd.conf.5.xml:3539 +#: sssd.conf.5.xml:341 sssd.conf.5.xml:3670 msgid "user name" msgstr "имя пользователя" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:301 sssd.conf.5.xml:3542 +#: sssd.conf.5.xml:344 sssd.conf.5.xml:3673 msgid "%2$s" msgstr "%2$s" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:304 sssd.conf.5.xml:3545 +#: sssd.conf.5.xml:347 sssd.conf.5.xml:3676 msgid "domain name as specified in the SSSD config file." msgstr "имя домена, указанное в файле конфигурации SSSD." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:310 sssd.conf.5.xml:3551 +#: sssd.conf.5.xml:353 sssd.conf.5.xml:3682 msgid "%3$s" msgstr "%3$s" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:313 sssd.conf.5.xml:3554 +#: sssd.conf.5.xml:356 sssd.conf.5.xml:3685 msgid "" "domain flat name. Mostly usable for Active Directory domains, both directly " "configured or discovered via IPA trusts." @@ -523,7 +597,7 @@ msgstr "" "доверия IPA." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:294 sssd.conf.5.xml:3535 +#: sssd.conf.5.xml:337 sssd.conf.5.xml:3666 msgid "" "The following expansions are supported: <placeholder type=\"variablelist\" " "id=\"0\"/>" @@ -532,7 +606,7 @@ msgstr "" "id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:323 +#: sssd.conf.5.xml:366 msgid "" "Each domain can have an individual format string configured. See DOMAIN " "SECTIONS for more info on this option." @@ -541,12 +615,12 @@ msgstr "" "сведения об этом параметре доступны в разделе справки «РАЗДЕЛЫ ДОМЕНОВ»." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:329 +#: sssd.conf.5.xml:372 msgid "monitor_resolv_conf (boolean)" msgstr "monitor_resolv_conf (логическое значение)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:332 +#: sssd.conf.5.xml:375 msgid "" "Controls if SSSD should monitor the state of resolv.conf to identify when it " "needs to update its internal DNS resolver." @@ -556,12 +630,12 @@ msgstr "" "сопоставителя DNS." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:342 +#: sssd.conf.5.xml:385 msgid "try_inotify (boolean)" msgstr "try_inotify (логическое значение)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:345 +#: sssd.conf.5.xml:388 msgid "" "By default, SSSD will attempt to use inotify to monitor configuration files " "changes and will fall back to polling every five seconds if inotify cannot " @@ -572,7 +646,7 @@ msgstr "" "этого снова будет выполняться опрос каждые пять секунд." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:351 +#: sssd.conf.5.xml:394 msgid "" "There are some limited situations where it is preferred that we should skip " "even trying to use inotify. In these rare cases, this option should be set " @@ -582,7 +656,7 @@ msgstr "" "В таких случаях в этот параметр следует установить значение «false»" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:357 +#: sssd.conf.5.xml:400 msgid "" "Default: true on platforms where inotify is supported. False on other " "platforms." @@ -591,7 +665,7 @@ msgstr "" "других платформах." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:361 +#: sssd.conf.5.xml:404 msgid "" "Note: this option will have no effect on platforms where inotify is " "unavailable. On these platforms, polling will always be used." @@ -601,12 +675,12 @@ msgstr "" "использоваться опрос." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:368 +#: sssd.conf.5.xml:411 msgid "krb5_rcache_dir (string)" msgstr "krb5_rcache_dir (строка)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:371 +#: sssd.conf.5.xml:414 msgid "" "Directory on the filesystem where SSSD should store Kerberos replay cache " "files." @@ -615,7 +689,7 @@ msgstr "" "повтора Kerberos." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:375 +#: sssd.conf.5.xml:418 msgid "" "This option accepts a special value __LIBKRB5_DEFAULTS__ that will instruct " "SSSD to let libkrb5 decide the appropriate location for the replay cache." @@ -625,7 +699,7 @@ msgstr "" "повтора." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:381 +#: sssd.conf.5.xml:424 msgid "" "Default: Distribution-specific and specified at build-time. " "(__LIBKRB5_DEFAULTS__ if not configured)" @@ -634,12 +708,12 @@ msgstr "" "(__LIBKRB5_DEFAULTS__, если не настроено)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:388 +#: sssd.conf.5.xml:431 msgid "default_domain_suffix (string)" msgstr "default_domain_suffix (строка)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:391 +#: sssd.conf.5.xml:434 msgid "" "Please note that this option is deprecated and domain_resolution_order " "should be used." @@ -648,7 +722,7 @@ msgstr "" "него domain_resolution_order." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:395 +#: sssd.conf.5.xml:438 msgid "" "This string will be used as a default domain name for all names without a " "domain name component. The main use case is environments where the primary " @@ -664,7 +738,7 @@ msgstr "" "не указывая имя домена." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:405 +#: sssd.conf.5.xml:448 msgid "" "Please note that if this option is set all users from the primary domain " "have to use their fully qualified name, e.g. user@domain.name, to log in. " @@ -680,21 +754,21 @@ msgstr "" "установленным в значение «False»." #. type: Content of: <variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:414 sssd-ldap.5.xml:937 sssd-ldap.5.xml:949 -#: sssd-ldap.5.xml:1042 sssd-ad.5.xml:921 sssd-ad.5.xml:996 sssd-krb5.5.xml:468 -#: sssd-ldap-attributes.5.xml:470 sssd-ldap-attributes.5.xml:978 -#: include/ldap_id_mapping.xml:211 include/ldap_id_mapping.xml:222 -#: include/krb5_options.xml:148 +#: sssd.conf.5.xml:457 sssd.conf.5.xml:2006 sssd-ldap.5.xml:937 +#: sssd-ldap.5.xml:949 sssd-ldap.5.xml:1042 sssd-ad.5.xml:926 +#: sssd-ad.5.xml:1001 sssd-krb5.5.xml:468 sssd-ldap-attributes.5.xml:470 +#: sssd-ldap-attributes.5.xml:978 include/ldap_id_mapping.xml:211 +#: include/ldap_id_mapping.xml:222 include/krb5_options.xml:148 msgid "Default: not set" msgstr "По умолчанию: не задано" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:419 +#: sssd.conf.5.xml:462 msgid "override_space (string)" msgstr "override_space (строка)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:422 +#: sssd.conf.5.xml:465 msgid "" "This parameter will replace spaces (space bar) with the given character for " "user and group names. e.g. (_). User name "john doe" will be " @@ -710,7 +784,7 @@ msgstr "" "пробел является стандартным разделителем полей." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:431 +#: sssd.conf.5.xml:474 msgid "" "Please note it is a configuration error to use a replacement character that " "might be used in user or group names. If a name contains the replacement " @@ -723,22 +797,22 @@ msgstr "" "вернуть неизменённое имя, но в целом результат поиска будет не определён." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:439 +#: sssd.conf.5.xml:482 msgid "Default: not set (spaces will not be replaced)" msgstr "По умолчанию: не задано (пробелы не будут заменены)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:444 +#: sssd.conf.5.xml:487 msgid "certificate_verification (string)" msgstr "certificate_verification (строка)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:452 +#: sssd.conf.5.xml:495 msgid "no_ocsp" msgstr "no_ocsp" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:454 +#: sssd.conf.5.xml:497 msgid "" "Disables Online Certificate Status Protocol (OCSP) checks. This might be " "needed if the OCSP servers defined in the certificate are not reachable from " @@ -748,12 +822,12 @@ msgstr "" "сертификате серверы OCSP недоступны со стороны клиента." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:462 +#: sssd.conf.5.xml:505 msgid "soft_ocsp" msgstr "soft_ocsp" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:464 +#: sssd.conf.5.xml:507 msgid "" "If a connection cannot be established to an OCSP responder the OCSP check is " "skipped. This option should be used to allow authentication when the system " @@ -765,12 +839,12 @@ msgstr "" "связаться с ответчиком OCSP." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:474 +#: sssd.conf.5.xml:517 msgid "ocsp_dgst" msgstr "ocsp_dgst" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:476 +#: sssd.conf.5.xml:519 msgid "" "Digest (hash) function used to create the certificate ID for the OCSP " "request. Allowed values are:" @@ -779,39 +853,39 @@ msgstr "" "сертификата для запроса OCSP. Допустимые значения:" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:480 +#: sssd.conf.5.xml:523 msgid "sha1" msgstr "sha1" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:481 +#: sssd.conf.5.xml:524 msgid "sha256" msgstr "sha256" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:482 +#: sssd.conf.5.xml:525 msgid "sha384" msgstr "sha384" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:483 +#: sssd.conf.5.xml:526 msgid "sha512" msgstr "sha512" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:486 +#: sssd.conf.5.xml:529 msgid "Default: sha1 (to allow compatibility with RFC5019-compliant responder)" msgstr "" "По умолчанию: sha1 (для обеспечения совместимости с ответчиком, " "соответствующим стандарту RFC5019)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:492 +#: sssd.conf.5.xml:535 msgid "no_verification" msgstr "no_verification" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:494 +#: sssd.conf.5.xml:537 msgid "" "Disables verification completely. This option should only be used for " "testing." @@ -820,12 +894,12 @@ msgstr "" "тестирования." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:500 +#: sssd.conf.5.xml:543 msgid "partial_chain" msgstr "partial_chain" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:502 +#: sssd.conf.5.xml:545 msgid "" "Allow verification to succeed even if a <replaceable>complete</replaceable> " "chain cannot be built to a self-signed trust-anchor, provided it is possible " @@ -837,12 +911,12 @@ msgstr "" "сертификата, который может быть не самоподписанным." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:511 +#: sssd.conf.5.xml:554 msgid "ocsp_default_responder=URL" msgstr "ocsp_default_responder=URL" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:513 +#: sssd.conf.5.xml:556 msgid "" "Sets the OCSP default responder which should be used instead of the one " "mentioned in the certificate. URL must be replaced with the URL of the OCSP " @@ -853,12 +927,12 @@ msgstr "" "стандартного ответчика OCSP, например: http://example.com:80/ocsp." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:523 +#: sssd.conf.5.xml:566 msgid "ocsp_default_responder_signing_cert=NAME" msgstr "ocsp_default_responder_signing_cert=NAME" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:525 +#: sssd.conf.5.xml:568 msgid "" "This option is currently ignored. All needed certificates must be available " "in the PEM file given by pam_cert_db_path." @@ -867,12 +941,12 @@ msgstr "" "должны быть доступны в файле PEM, указанном параметром pam_cert_db_path." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:533 +#: sssd.conf.5.xml:576 msgid "crl_file=/PATH/TO/CRL/FILE" msgstr "crl_file=/ПУТЬ/К/ФАЙЛУ/CRL" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:535 +#: sssd.conf.5.xml:578 msgid "" "Use the Certificate Revocation List (CRL) from the given file during the " "verification of the certificate. The CRL must be given in PEM format, see " @@ -885,12 +959,12 @@ msgstr "" "manvolnum> </citerefentry>." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:548 +#: sssd.conf.5.xml:591 msgid "soft_crl" msgstr "soft_crl" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:551 +#: sssd.conf.5.xml:594 msgid "" "If a Certificate Revocation List (CRL) is expired ignore the expiration " "time of the CRL and check the related certificates with the expired CRL. " @@ -903,7 +977,7 @@ msgstr "" "в автономном режиме и нельзя обновить CRL." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:447 +#: sssd.conf.5.xml:490 msgid "" "With this parameter the certificate verification can be tuned with a comma " "separated list of options. Supported options are: <placeholder " @@ -914,22 +988,22 @@ msgstr "" "<placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:564 +#: sssd.conf.5.xml:607 msgid "Unknown options are reported but ignored." msgstr "Неизвестные параметры передаются, но игнорируются." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:567 +#: sssd.conf.5.xml:610 msgid "Default: not set, i.e. do not restrict certificate verification" msgstr "По умолчанию: не задано, то есть не ограничивать проверку сертификатов" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:573 +#: sssd.conf.5.xml:616 msgid "disable_netlink (boolean)" msgstr "disable_netlink (логическое значение)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:576 +#: sssd.conf.5.xml:619 msgid "" "SSSD hooks into the netlink interface to monitor changes to routes, " "addresses, links and trigger certain actions." @@ -938,7 +1012,7 @@ msgstr "" "маршрутах,адресах, ссылках и вызова определённых действий." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:581 +#: sssd.conf.5.xml:624 msgid "" "The SSSD state changes caused by netlink events may be undesirable and can " "be disabled by setting this option to 'true'" @@ -948,17 +1022,17 @@ msgstr "" "»" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:586 +#: sssd.conf.5.xml:629 msgid "Default: false (netlink changes are detected)" msgstr "По умолчанию: false (изменения netlink обнаруживаются)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:591 -msgid "domain_resolution_order" -msgstr "domain_resolution_order" +#: sssd.conf.5.xml:634 +msgid "domain_resolution_order (string)" +msgstr "domain_resolution_order (строка)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:594 +#: sssd.conf.5.xml:637 msgid "" "Comma separated list of domains and subdomains representing the lookup order " "that will be followed. The list doesn't have to include all possible " @@ -975,7 +1049,7 @@ msgstr "" "будет выполняться в случайном порядке для каждого родительского домена." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:606 +#: sssd.conf.5.xml:649 msgid "" "Please, note that when this option is set the output format of all commands " "is always fully-qualified even when using short names for input. In case " @@ -1004,19 +1078,20 @@ msgstr "" "доменах могут быть одинаковыми." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:630 sssd.conf.5.xml:1697 sssd.conf.5.xml:4224 -#: sssd-ad.5.xml:187 sssd-ad.5.xml:328 sssd-ad.5.xml:342 sssd-idp.5.xml:108 -#: sssd-idp.5.xml:132 sssd-idp.5.xml:145 sssd-idp.5.xml:159 sssd-idp.5.xml:180 +#: sssd.conf.5.xml:673 sssd.conf.5.xml:1026 sssd.conf.5.xml:1689 +#: sssd.conf.5.xml:4429 sssd-ad.5.xml:187 sssd-ad.5.xml:328 sssd-ad.5.xml:342 +#: sssd-idp.5.xml:112 sssd-idp.5.xml:136 sssd-idp.5.xml:149 sssd-idp.5.xml:167 +#: sssd-idp.5.xml:188 msgid "Default: Not set" msgstr "По умолчанию: не задано" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:635 +#: sssd.conf.5.xml:678 msgid "implicit_pac_responder (boolean)" msgstr "implicit_pac_responder (логическое значение)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:638 +#: sssd.conf.5.xml:681 msgid "" "The PAC responder is enabled automatically for the IPA and AD provider to " "evaluate and check the PAC. If it has to be disabled set this option to " @@ -1027,12 +1102,12 @@ msgstr "" "значение «false»." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:649 +#: sssd.conf.5.xml:692 msgid "core_dumpable (boolean)" msgstr "core_dumpable (логическое значение)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:652 +#: sssd.conf.5.xml:695 msgid "" "This option can be used for general system hardening: setting it to 'false' " "forbids core dumps for all SSSD processes to avoid leaking plain text " @@ -1046,7 +1121,7 @@ msgstr "" "procctl:PROC_TRACE_CTL в FreeBSD." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:660 +#: sssd.conf.5.xml:703 msgid "" "Take a note that this setting has no effect for 'ldap_child', 'krb5_child' " "and 'sssd_pam' as those privileged binaries can have a copy of a host keytab " @@ -1059,17 +1134,17 @@ msgstr "" "системным параметром /proc/sys/fs/suid_dumpable." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:673 +#: sssd.conf.5.xml:716 msgid "passkey_verification (string)" msgstr "passkey_verification (строка)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:681 +#: sssd.conf.5.xml:724 msgid "user_verification (boolean)" msgstr "user_verification (логическое значение)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:683 +#: sssd.conf.5.xml:726 msgid "" "Enable or disable the user verification (i.e. PIN, fingerprint) during " "authentication. If enabled, the PIN will always be requested." @@ -1079,7 +1154,7 @@ msgstr "" "запрашиваться всегда." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:689 +#: sssd.conf.5.xml:732 msgid "" "The default is that the key settings decide what to do. In the IPA or " "kerberos pre-authentication case, this value will be overwritten by the " @@ -1090,7 +1165,7 @@ msgstr "" "перезаписано сервером." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:676 +#: sssd.conf.5.xml:719 msgid "" "With this parameter the passkey verification can be tuned with a comma " "separated list of options. Supported options are: <placeholder " @@ -1101,7 +1176,7 @@ msgstr "" "<placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:213 +#: sssd.conf.5.xml:256 msgid "" "Individual pieces of SSSD functionality are provided by special SSSD " "services that are started and stopped together with SSSD. The services are " @@ -1118,12 +1193,12 @@ msgstr "" "[sssd]</quote>. <placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:708 +#: sssd.conf.5.xml:751 msgid "SERVICES SECTIONS" msgstr "РАЗДЕЛЫ СЛУЖБ" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:710 +#: sssd.conf.5.xml:753 msgid "" "Settings that can be used to configure different services are described in " "this section. They should reside in the [<replaceable>$NAME</replaceable>] " @@ -1136,48 +1211,45 @@ msgstr "" "раздел <quote>[nss]</quote>" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:717 +#: sssd.conf.5.xml:760 msgid "General service configuration options" msgstr "Общие параметры настройки служб" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:719 +#: sssd.conf.5.xml:762 msgid "These options can be used to configure any service." msgstr "Эти параметры можно использовать для настройки любых служб." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:723 -msgid "fd_limit" -msgstr "fd_limit" +#: sssd.conf.5.xml:766 +msgid "fd_limit (integer)" +msgstr "fd_limit (целое число)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:726 +#: sssd.conf.5.xml:769 msgid "" "This option specifies the maximum number of file descriptors that may be " -"opened at one time by this SSSD process. On systems where SSSD is granted " -"the CAP_SYS_RESOURCE capability, this will be an absolute setting. On " -"systems without this capability, the resulting value will be the lower value " -"of this or the limits.conf \"hard\" limit." +"opened at one time by this SSSD process. Note this value will be capped by " +"the init system at the startup of SSSD, see e.g. man systemd.exec for " +"details." msgstr "" "Этот параметр задаёт максимальное количество файловых дескрипторов, которые " -"может одновременно открыть этот процесс SSSD. В системах, где у SSSD имеется " -"возможность CAP_SYS_RESOURCE, этот параметр будет использоваться независимо " -"от других параметров системы. В системах без такой возможности количество " -"дескрипторов будет определяться наименьшим значением этого параметра или " -"ограничением «hard» в limits.conf." +"может одновременно открыть этот процесс SSSD. Обратите внимание, что это " +"значение будет ограничено системой инициализации при запуске SSSD, см., " +"например, man systemd.exec." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:735 +#: sssd.conf.5.xml:776 msgid "Default: 8192 (or limits.conf \"hard\" limit)" msgstr "По умолчанию: 8192 (или ограничение «hard» в limits.conf)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:740 -msgid "client_idle_timeout" -msgstr "client_idle_timeout" +#: sssd.conf.5.xml:781 +msgid "client_idle_timeout (integer)" +msgstr "client_idle_timeout (целое число)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:743 +#: sssd.conf.5.xml:784 msgid "" "This option specifies the number of seconds that a client of an SSSD process " "can hold onto a file descriptor without communicating on it. This value is " @@ -1192,172 +1264,17 @@ msgstr "" "на 10 секунд." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:752 +#: sssd.conf.5.xml:793 msgid "Default: 60, KCM: 300" msgstr "По умолчанию: 60, KCM: 300" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:757 -msgid "offline_timeout (integer)" -msgstr "offline_timeout (целое число)" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:760 -msgid "" -"When SSSD switches to offline mode the amount of time before it tries to go " -"back online will increase based upon the time spent disconnected. By " -"default SSSD uses incremental behaviour to calculate delay in between " -"retries. So, the wait time for a given retry will be longer than the wait " -"time for the previous ones. After each unsuccessful attempt to go online, " -"the new interval is recalculated by the following:" -msgstr "" -"Когда SSSD переключается в автономный режим, количество времени до " -"выполнения попытки вернуться в сеть будет увеличиваться в соответствии со " -"временем, проведённым без подключения. По умолчанию SSSD использует " -"приращение для расчёта задержки между повторными попытками. Поэтому время " -"ожидания для конкретной попытки будет больше, чем для предыдущих. После " -"каждой неудачной попытки вернуться в сеть интервал будет пересчитываться по " -"следующей формуле:" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:771 sssd.conf.5.xml:827 -msgid "" -"new_delay = Minimum(old_delay * 2, offline_timeout_max) + " -"random[0...offline_timeout_random_offset]" -msgstr "" -"new_delay = Minimum(old_delay * 2, offline_timeout_max) + " -"random[0...offline_timeout_random_offset]" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:774 -msgid "" -"The offline_timeout default value is 60. The offline_timeout_max default " -"value is 3600. The offline_timeout_random_offset default value is 30. The " -"end result is amount of seconds before next retry." -msgstr "" -"Стандартное значение offline_timeout составляет 60. Стандартное значение " -"offline_timeout_max — 3600. Стандартное значение " -"offline_timeout_random_offset — 30. Конечный результат представляет собой " -"количество секунд до следующей попытки." - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:780 -msgid "" -"Note that the maximum length of each interval is defined by " -"offline_timeout_max (apart of random part)." -msgstr "" -"Обратите внимание, что максимальная длительность каждого интервала задана " -"параметром offline_timeout_max (кроме случайной части)." - -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:784 sssd.conf.5.xml:1110 sssd.conf.5.xml:1490 -#: sssd.conf.5.xml:1791 sssd-ldap.5.xml:550 -msgid "Default: 60" -msgstr "По умолчанию: 60" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:789 -msgid "offline_timeout_max (integer)" -msgstr "offline_timeout_max (целое число)" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:792 -msgid "" -"Controls by how much the time between attempts to go online can be " -"incremented following unsuccessful attempts to go online." -msgstr "" -"Управляет тем, насколько можно увеличить время между попытками вернуться в " -"сеть после неудачных попыток восстановления подключения." - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:797 -msgid "A value of 0 disables the incrementing behaviour." -msgstr "Значение «0» отключает использование приращения." - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:800 -msgid "" -"The value of this parameter should be set in correlation to offline_timeout " -"parameter value." -msgstr "" -"Значение этого параметра следует устанавливать с учётом значения параметра " -"offline_timeout." - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:804 -msgid "" -"With offline_timeout set to 60 (default value) there is no point in setting " -"offlinet_timeout_max to less than 120 as it will saturate instantly. General " -"rule here should be to set offline_timeout_max to at least 4 times " -"offline_timeout." -msgstr "" -"Если параметр offline_timeout установлен в значение «60» (значение по " -"умолчанию), нет смысла указывать для параметра offlinet_timeout_max значение " -"меньше 120, поскольку первый же шаг увеличения приведёт к его превышению. " -"Общее правило таково: значение offline_timeout_max должно по крайней мере в " -"4 раза превышать значение offline_timeout." - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:810 -msgid "" -"Although a value between 0 and offline_timeout may be specified, it has the " -"effect of overriding the offline_timeout value so is of little use." -msgstr "" -"Несмотря на то, что возможно указать значение от 0 до offline_timeout, " -"результатом этого станет переопределение значения offline_timeout, что не " -"имеет практического смысла." - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:815 -msgid "Default: 3600" -msgstr "По умолчанию: 3600" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:820 -msgid "offline_timeout_random_offset (integer)" -msgstr "offline_timeout_random_offset (целое число)" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:823 -msgid "" -"When SSSD is in offline mode it keeps probing backend servers in specified " -"time intervals:" -msgstr "" -"Когда сервис SSSD находится в автономном режиме, он продолжает обращаться к " -"внутренним серверам через заданные промежутки времени:" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:830 -msgid "" -"This parameter controls the value of the random offset used for the above " -"equation. Final random_offset value will be random number in range:" -msgstr "" -"Этот параметр управляет значением случайной задержки, которое используется " -"для приведённого выше уравнения. Итоговым значением random_offset будет " -"случайное число, принадлежащее диапазону:" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:835 -msgid "[0 - offline_timeout_random_offset]" -msgstr "[0 - offline_timeout_random_offset]" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:838 -msgid "A value of 0 disables the random offset addition." -msgstr "Значение «0» отключает добавление случайной задержки." - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:841 -msgid "Default: 30" -msgstr "По умолчанию: 30" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:846 -msgid "responder_idle_timeout" -msgstr "responder_idle_timeout" +#: sssd.conf.5.xml:798 +msgid "responder_idle_timeout (integer)" +msgstr "responder_idle_timeout (целое число)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:849 +#: sssd.conf.5.xml:801 msgid "" "This option specifies the number of seconds that an SSSD responder process " "can be up without being used. This value is limited in order to avoid " @@ -1376,18 +1293,18 @@ msgstr "" "активируются с помощью сокетов или D-Bus." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:863 sssd.conf.5.xml:1123 sssd.conf.5.xml:2248 +#: sssd.conf.5.xml:815 sssd.conf.5.xml:1079 sssd.conf.5.xml:2285 #: sssd-ldap.5.xml:377 msgid "Default: 300" msgstr "По умолчанию: 300" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:868 -msgid "cache_first" -msgstr "cache_first" +#: sssd.conf.5.xml:820 +msgid "cache_first (boolean)" +msgstr "cache_first (логическое значение)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:871 +#: sssd.conf.5.xml:823 msgid "" "This option specifies whether the responder should query all caches before " "querying the Data Providers." @@ -1396,25 +1313,26 @@ msgstr "" "опросом поставщиков данных." #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:883 +#: sssd.conf.5.xml:835 msgid "NSS configuration options" msgstr "Параметры настройки NSS" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:885 +#: sssd.conf.5.xml:837 msgid "" -"These options can be used to configure the Name Service Switch (NSS) service." +"These options can be used to configure the Name Service Switch (NSS) service " +"and should be specified under the <quote>[nss]</quote> section." msgstr "" "Эти параметры можно использовать для настройки службы диспетчера службы имён " -"(NSS)." +"(NSS) и должны указываться в разделе <quote>[nss]</quote>." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:890 +#: sssd.conf.5.xml:843 msgid "enum_cache_timeout (integer)" msgstr "enum_cache_timeout (целое число)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:893 +#: sssd.conf.5.xml:846 msgid "" "How many seconds should nss_sss cache enumerations (requests for info about " "all users)" @@ -1423,17 +1341,17 @@ msgstr "" "пользователях) в кэше nss_sss в секундах" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:897 +#: sssd.conf.5.xml:850 msgid "Default: 120" msgstr "По умолчанию: 120" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:902 +#: sssd.conf.5.xml:855 msgid "entry_cache_nowait_percentage (integer)" msgstr "entry_cache_nowait_percentage (целое число)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:905 +#: sssd.conf.5.xml:858 msgid "" "The entry cache can be set to automatically update entries in the background " "if they are requested beyond a percentage of the entry_cache_timeout value " @@ -1444,7 +1362,7 @@ msgstr "" "значения entry_cache_timeout для домена." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:911 +#: sssd.conf.5.xml:864 msgid "" "For example, if the domain's entry_cache_timeout is set to 30s and " "entry_cache_nowait_percentage is set to 50 (percent), entries that come in " @@ -1460,31 +1378,31 @@ msgstr "" "кэша." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:921 +#: sssd.conf.5.xml:874 msgid "" "Valid values for this option are 0-99 and represent a percentage of the " "entry_cache_timeout for each domain. For performance reasons, this " "percentage will never reduce the nowait timeout to less than 10 seconds. (0 " "disables this feature)" msgstr "" -"Корректные значения этого параметра находятся в диапазоне 0-99 и " -"представляют собой значение в процентах от entry_cache_timeout для каждого " -"домена. Чтобы сохранить производительность, это значение никогда не " -"уменьшает тайм-аут nowait так, что он становится меньше 10 секунд. Установка " -"значения «0» отключает эту возможность." +"Верные значения этого параметра находятся в диапазоне 0-99 и представляют " +"собой значение в процентах от entry_cache_timeout для каждого домена. Чтобы " +"сохранить производительность, это значение никогда не уменьшает тайм-аут " +"nowait так, что он становится меньше 10 секунд. Установка значения «0» " +"отключает эту возможность" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:929 sssd.conf.5.xml:2061 +#: sssd.conf.5.xml:882 sssd.conf.5.xml:2093 msgid "Default: 50" msgstr "По умолчанию: 50" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:934 +#: sssd.conf.5.xml:887 msgid "entry_negative_timeout (integer)" msgstr "entry_negative_timeout (целое число)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:937 +#: sssd.conf.5.xml:890 msgid "" "Specifies for how many seconds nss_sss should cache negative cache hits " "(that is, queries for invalid database entries, like nonexistent ones) " @@ -1496,17 +1414,17 @@ msgstr "" "серверу." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:943 sssd.conf.5.xml:1685 sssd.conf.5.xml:2085 +#: sssd.conf.5.xml:896 sssd.conf.5.xml:1677 sssd.conf.5.xml:2119 msgid "Default: 15" msgstr "По умолчанию: 15" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:948 +#: sssd.conf.5.xml:901 msgid "filter_users, filter_groups (string)" msgstr "filter_users, filter_groups (строка)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:951 +#: sssd.conf.5.xml:904 msgid "" "Exclude certain users or groups from being fetched from the sss NSS " "database. This is particularly useful for system accounts. This option can " @@ -1521,7 +1439,7 @@ msgstr "" "(UPN)." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:959 +#: sssd.conf.5.xml:912 msgid "" "NOTE: The filter_groups option doesn't affect inheritance of nested group " "members, since filtering happens after they are propagated for returning via " @@ -1535,30 +1453,30 @@ msgstr "" "отфильтрованной вложенной группы." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:967 +#: sssd.conf.5.xml:920 msgid "Default: root" msgstr "По умолчанию: root" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:972 -msgid "filter_users_in_groups (bool)" +#: sssd.conf.5.xml:925 +msgid "filter_users_in_groups (boolean)" msgstr "filter_users_in_groups (логическое значение)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:975 +#: sssd.conf.5.xml:928 msgid "" -"If you want filtered user still be group members set this option to false." +"If you want filtered users to remain group members set this option to false" msgstr "" -"Если отфильтрованные пользователи должны оставаться участниками групп, " -"установите этот параметр в значение «false»." +"Если вы хотите, чтобы отфильтрованные пользователи оставались участниками " +"групп, установите этот параметр в значение false" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:986 +#: sssd.conf.5.xml:939 msgid "fallback_homedir (string)" msgstr "fallback_homedir (строка)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:989 +#: sssd.conf.5.xml:942 msgid "" "Set a default template for a user's home directory if one is not specified " "explicitly by the domain's data provider." @@ -1567,7 +1485,7 @@ msgstr "" "явно не указан поставщиком данных домена." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:994 +#: sssd.conf.5.xml:947 msgid "" "The available values for this option are the same as for override_homedir." msgstr "" @@ -1575,7 +1493,7 @@ msgstr "" "параметра override_homedir." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1000 +#: sssd.conf.5.xml:953 #, no-wrap msgid "" "fallback_homedir = /home/%u\n" @@ -1585,23 +1503,23 @@ msgstr "" " " #. type: Content of: <varlistentry><listitem><para> -#: sssd.conf.5.xml:998 sssd.conf.5.xml:1557 sssd.conf.5.xml:1576 -#: sssd.conf.5.xml:1653 sssd-krb5.5.xml:451 include/override_homedir.xml:78 +#: sssd.conf.5.xml:951 sssd.conf.5.xml:1524 sssd.conf.5.xml:1543 +#: sssd.conf.5.xml:1645 sssd-krb5.5.xml:451 include/override_homedir.xml:78 msgid "example: <placeholder type=\"programlisting\" id=\"0\"/>" msgstr "пример: <placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1004 +#: sssd.conf.5.xml:957 msgid "Default: not set (no substitution for unset home directories)" msgstr "По умолчанию: не задано (без замен для незаданных домашних каталогов)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1010 +#: sssd.conf.5.xml:963 msgid "override_shell (string)" msgstr "override_shell (строка)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1013 +#: sssd.conf.5.xml:966 msgid "" "Override the login shell for all users. This option supersedes any other " "shell options if it takes effect and can be set either in the [nss] section " @@ -1613,19 +1531,19 @@ msgstr "" "домена отдельно." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1019 +#: sssd.conf.5.xml:972 msgid "Default: not set (SSSD will use the value retrieved from LDAP)" msgstr "" "По умолчанию: не задано (SSSD будет использовать значение, полученное от " "LDAP)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1025 +#: sssd.conf.5.xml:978 msgid "allowed_shells (string)" msgstr "allowed_shells (строка)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1028 +#: sssd.conf.5.xml:981 msgid "" "Restrict user shell to one of the listed values. The order of evaluation is:" msgstr "" @@ -1633,14 +1551,14 @@ msgstr "" "Порядок вычисления:" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1031 +#: sssd.conf.5.xml:984 msgid "1. If the shell is present in <quote>/etc/shells</quote>, it is used." msgstr "" "1. Если оболочка присутствует в файле <quote>/etc/shells</quote>, будет " "использована она." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1035 +#: sssd.conf.5.xml:988 msgid "" "2. If the shell is in the allowed_shells list but not in <quote>/etc/shells</" "quote>, use the value of the shell_fallback parameter." @@ -1649,7 +1567,7 @@ msgstr "" "etc/shells</quote>, использовать значение параметра shell_fallback." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1040 +#: sssd.conf.5.xml:993 msgid "" "3. If the shell is not in the allowed_shells list and not in <quote>/etc/" "shells</quote>, a nologin shell is used." @@ -1658,14 +1576,14 @@ msgstr "" "shells</quote>, будет использована оболочка, которая не требует входа." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1045 +#: sssd.conf.5.xml:998 msgid "The wildcard (*) can be used to allow any shell." msgstr "" "Чтобы разрешить использование любой оболочки, можно использовать " "подстановочный знак (*)." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1048 +#: sssd.conf.5.xml:1001 msgid "" "The (*) is useful if you want to use shell_fallback in case that user's " "shell is not in <quote>/etc/shells</quote> and maintaining list of all " @@ -1676,12 +1594,12 @@ msgstr "" "ведение списка всех разрешённых оболочек в allowed_shells было бы излишним." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1055 +#: sssd.conf.5.xml:1008 msgid "An empty string for shell is passed as-is to libc." msgstr "Пустая строка оболочки передаётся libc «как есть»." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1058 +#: sssd.conf.5.xml:1011 msgid "" "The <quote>/etc/shells</quote> is only read on SSSD start up, which means " "that a restart of the SSSD is required in case a new shell is installed." @@ -1690,28 +1608,28 @@ msgstr "" "Следовательно, в случае установки новой оболочки потребуется перезапуск SSSD." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1062 +#: sssd.conf.5.xml:1015 msgid "Default: Not set. The user shell is automatically used." msgstr "" "По умолчанию: не задано. Автоматически используется оболочка пользователя." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1067 +#: sssd.conf.5.xml:1020 msgid "vetoed_shells (string)" msgstr "vetoed_shells (строка)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1070 +#: sssd.conf.5.xml:1023 msgid "Replace any instance of these shells with the shell_fallback" msgstr "Заменять все экземпляры этих оболочек на shell_fallback" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1075 +#: sssd.conf.5.xml:1031 msgid "shell_fallback (string)" msgstr "shell_fallback (строка)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1078 +#: sssd.conf.5.xml:1034 msgid "" "The default shell to use if an allowed shell is not installed on the machine." msgstr "" @@ -1719,17 +1637,17 @@ msgstr "" "оболочка не установлена на компьютере." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1082 +#: sssd.conf.5.xml:1038 msgid "Default: /bin/sh" msgstr "По умолчанию: /bin/sh" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1087 -msgid "default_shell" -msgstr "default_shell" +#: sssd.conf.5.xml:1043 +msgid "default_shell (string)" +msgstr "default_shell (строка)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1090 +#: sssd.conf.5.xml:1046 msgid "" "The default shell to use if the provider does not return one during lookup. " "This option can be specified globally in the [nss] section or per-domain." @@ -1739,7 +1657,7 @@ msgstr "" "разделе [nss] или для каждого домена отдельно." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1096 +#: sssd.conf.5.xml:1052 msgid "" "Default: not set (Return NULL if no shell is specified and rely on libc to " "substitute something sensible when necessary, usually /bin/sh)" @@ -1748,12 +1666,12 @@ msgstr "" "положиться на libc в плане подстановки подходящего варианта, обычно /bin/sh)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1103 sssd.conf.5.xml:1483 +#: sssd.conf.5.xml:1059 sssd.conf.5.xml:1450 msgid "get_domains_timeout (int)" msgstr "get_domains_timeout (целое число)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1106 sssd.conf.5.xml:1486 +#: sssd.conf.5.xml:1062 sssd.conf.5.xml:1453 msgid "" "Specifies time in seconds for which the list of subdomains will be " "considered valid." @@ -1761,13 +1679,19 @@ msgstr "" "Указывает время в секундах, в течение которого список поддоменов считается " "действительным." +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1066 sssd.conf.5.xml:1457 sssd.conf.5.xml:1788 +#: sssd.conf.5.xml:2862 sssd-ldap.5.xml:550 +msgid "Default: 60" +msgstr "По умолчанию: 60" + #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1115 +#: sssd.conf.5.xml:1071 msgid "memcache_timeout (integer)" msgstr "memcache_timeout (целое число)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1118 +#: sssd.conf.5.xml:1074 msgid "" "Specifies time in seconds for which records in the in-memory cache will be " "valid. Setting this option to zero will disable the in-memory cache." @@ -1777,7 +1701,7 @@ msgstr "" "отключит кэш в памяти." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1126 +#: sssd.conf.5.xml:1082 msgid "" "WARNING: Disabling the in-memory cache will have significant negative impact " "on SSSD's performance and should only be used for testing." @@ -1787,8 +1711,8 @@ msgstr "" "только для тестирования." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1132 sssd.conf.5.xml:1157 sssd.conf.5.xml:1182 -#: sssd.conf.5.xml:1207 sssd.conf.5.xml:1234 +#: sssd.conf.5.xml:1088 sssd.conf.5.xml:1113 sssd.conf.5.xml:1138 +#: sssd.conf.5.xml:1163 sssd.conf.5.xml:1190 msgid "" "NOTE: If the environment variable SSS_NSS_USE_MEMCACHE is set to \"NO\", " "client applications will not use the fast in-memory cache." @@ -1798,12 +1722,12 @@ msgstr "" "памяти." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1140 +#: sssd.conf.5.xml:1096 msgid "memcache_size_passwd (integer)" msgstr "memcache_size_passwd (целое число)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1143 +#: sssd.conf.5.xml:1099 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for passwd requests. Setting the size to 0 will disable the passwd in-" @@ -1814,13 +1738,13 @@ msgstr "" "памяти для запросов passwd." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1149 sssd.conf.5.xml:2888 sssd-ldap.5.xml:604 +#: sssd.conf.5.xml:1105 sssd.conf.5.xml:3013 sssd-ldap.5.xml:604 msgid "Default: 8" msgstr "По умолчанию: 8" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1152 sssd.conf.5.xml:1177 sssd.conf.5.xml:1202 -#: sssd.conf.5.xml:1229 +#: sssd.conf.5.xml:1108 sssd.conf.5.xml:1133 sssd.conf.5.xml:1158 +#: sssd.conf.5.xml:1185 msgid "" "WARNING: Disabled or too small in-memory cache can have significant negative " "impact on SSSD's performance." @@ -1829,12 +1753,12 @@ msgstr "" "значительное негативное воздействие на производительность SSSD." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1165 +#: sssd.conf.5.xml:1121 msgid "memcache_size_group (integer)" msgstr "memcache_size_group (целое число)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1168 +#: sssd.conf.5.xml:1124 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for group requests. Setting the size to 0 will disable the group in-memory " @@ -1845,19 +1769,19 @@ msgstr "" "памяти для запросов group." #. type: Content of: <variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1174 sssd.conf.5.xml:1226 sssd.conf.5.xml:3656 +#: sssd.conf.5.xml:1130 sssd.conf.5.xml:1182 sssd.conf.5.xml:3835 #: sssd-ldap.5.xml:534 sssd-ldap.5.xml:581 include/failover.xml:116 #: include/krb5_options.xml:11 msgid "Default: 6" msgstr "По умолчанию: 6" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1190 +#: sssd.conf.5.xml:1146 msgid "memcache_size_initgroups (integer)" msgstr "memcache_size_initgroups (целое число)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1193 +#: sssd.conf.5.xml:1149 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for initgroups requests. Setting the size to 0 will disable the initgroups " @@ -1868,12 +1792,12 @@ msgstr "" "отключит кэш в памяти для запросов групп инициализации." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1215 +#: sssd.conf.5.xml:1171 msgid "memcache_size_sid (integer)" msgstr "memcache_size_sid (целое число)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1218 +#: sssd.conf.5.xml:1174 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for SID related requests. Only SID-by-ID and ID-by-SID requests are " @@ -1886,12 +1810,12 @@ msgstr "" "размера в значение «0» отключит кэш SID в памяти." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1242 sssd-ifp.5.xml:90 +#: sssd.conf.5.xml:1198 sssd-ifp.5.xml:90 msgid "user_attributes (string)" msgstr "user_attributes (строка)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1245 +#: sssd.conf.5.xml:1201 msgid "" "Some of the additional NSS responder requests can return more attributes " "than just the POSIX ones defined by the NSS interface. The list of " @@ -1908,7 +1832,7 @@ msgstr "" "manvolnum> </citerefentry>), но без стандартных значений." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1258 +#: sssd.conf.5.xml:1214 msgid "" "To make configuration more easy the NSS responder will check the InfoPipe " "option if it is not set for the NSS responder." @@ -1917,17 +1841,17 @@ msgstr "" "ли он для ответчика NSS." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1263 +#: sssd.conf.5.xml:1219 msgid "Default: not set, fallback to InfoPipe option" msgstr "По умолчанию: не задано, использовать параметр InfoPipe" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1268 +#: sssd.conf.5.xml:1224 msgid "pwfield (string)" msgstr "pwfield (строка)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1271 +#: sssd.conf.5.xml:1227 msgid "" "The value that NSS operations that return users or groups will return for " "the <quote>password</quote> field." @@ -1936,49 +1860,62 @@ msgstr "" "вернут для поля <quote>password</quote>." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1276 -msgid "Default: <quote>*</quote>" -msgstr "По умолчанию: <quote>*</quote>" +#: sssd.conf.5.xml:1232 +msgid "" +"This option can also be set per-domain, which overwrites the value in the " +"<quote>[nss]</quote> section for that domain. This is particularly useful " +"when using a proxy domain with <option>proxy_lib_name=files</option> and a " +"<option>proxy_pam_target</option> other than <quote>sssd-shadowutils</" +"quote>. In that case, SSSD returns <quote>*</quote> for the password field " +"by default, which causes <command>pam_unix</command> to treat all accounts " +"as locked. Setting <option>pwfield = x</option> in the domain section " +"restores the expected behavior." +msgstr "" +"Этот параметр также можно задать отдельно для каждого домена, что " +"переопределяет значение в разделе <quote>[nss]</quote> для этого домена. Это " +"особенно полезно при использовании прокси-домена с <option>" +"proxy_lib_name=files</option> и <option>proxy_pam_target</option>, отличным " +"от <quote>sssd-shadowutils</quote>. В этом случае SSSD по умолчанию " +"возвращает <quote>*</quote> для поля пароля, из-за чего <command>pam_unix</" +"command> считает все учётные записи заблокированными. Установка <option>" +"pwfield = x</option> в разделе домена восстанавливает ожидаемое поведение." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1279 -msgid "" -"Note: This option can also be set per-domain which overwrites the value in " -"[nss] section." -msgstr "" -"Примечание: этот параметр также можно задать для каждого домена отдельно, " -"что будет иметь приоритет над значением в разделе [nss]." +#: sssd.conf.5.xml:1246 +msgid "Default: <quote>*</quote>" +msgstr "По умолчанию: <quote>*</quote>" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1283 +#: sssd.conf.5.xml:1249 msgid "" -"Default: <quote>not set</quote> (remote domains), <quote>x</quote> (proxy " -"domain with nss_files and sssd-shadowutils target)" +"Default (per-domain): <quote>not set</quote> (remote domains), <quote>x</" +"quote> (proxy domain with nss_files and sssd-shadowutils target)" msgstr "" -"По умолчанию: <quote>не задано</quote> (удалённые домены), <quote>x</quote> " -"(домен прокси с nss_files и целью sssd-shadowutils)" +"По умолчанию (для домена): <quote>не задано</quote> (удалённые домены), " +"<quote>x</quote> (домен прокси с nss_files и целью sssd-shadowutils)" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:1292 +#: sssd.conf.5.xml:1258 msgid "PAM configuration options" msgstr "Параметры настройки PAM" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:1294 +#: sssd.conf.5.xml:1260 msgid "" "These options can be used to configure the Pluggable Authentication Module " -"(PAM) service." +"(PAM) service and should be specified under the <quote>[pam]</quote> section." msgstr "" "Эти параметры можно использовать для настройки службы подключаемых модулей " -"проверки подлинности (PAM)." +"проверки подлинности (PAM) и должны указываться в разделе <quote>[pam]</" +"quote>." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1299 +#: sssd.conf.5.xml:1266 msgid "offline_credentials_expiration (integer)" msgstr "offline_credentials_expiration (целое число)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1302 +#: sssd.conf.5.xml:1269 msgid "" "If the authentication provider is offline, how long should we allow cached " "logins (in days since the last successful online login)." @@ -1988,17 +1925,17 @@ msgstr "" "момента последнего успешного входа)." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1307 sssd.conf.5.xml:1320 +#: sssd.conf.5.xml:1274 sssd.conf.5.xml:1287 msgid "Default: 0 (No limit)" msgstr "По умолчанию: 0 (без ограничений)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1313 +#: sssd.conf.5.xml:1280 msgid "offline_failed_login_attempts (integer)" msgstr "offline_failed_login_attempts (целое число)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1316 +#: sssd.conf.5.xml:1283 msgid "" "If the authentication provider is offline, how many failed login attempts " "are allowed." @@ -2007,12 +1944,12 @@ msgstr "" "режиме, сколько следует допускать неудачных попыток входа." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1326 +#: sssd.conf.5.xml:1293 msgid "offline_failed_login_delay (integer)" msgstr "offline_failed_login_delay (целое число)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1329 +#: sssd.conf.5.xml:1296 msgid "" "The time in minutes which has to pass after offline_failed_login_attempts " "has been reached before a new login attempt is possible." @@ -2022,7 +1959,7 @@ msgstr "" "входа." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1334 +#: sssd.conf.5.xml:1301 msgid "" "If set to 0 the user cannot authenticate offline if " "offline_failed_login_attempts has been reached. Only a successful online " @@ -2034,17 +1971,17 @@ msgstr "" "возможной, необходимо успешно пройти проверку подлинности в сетевом режиме." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1340 sssd.conf.5.xml:1450 +#: sssd.conf.5.xml:1307 sssd.conf.5.xml:1417 msgid "Default: 5" msgstr "По умолчанию: 5" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1346 +#: sssd.conf.5.xml:1313 msgid "pam_verbosity (integer)" msgstr "pam_verbosity (целое число)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1349 +#: sssd.conf.5.xml:1316 msgid "" "Controls what kind of messages are shown to the user during authentication. " "The higher the number to more messages are displayed." @@ -2053,43 +1990,43 @@ msgstr "" "подлинности. Чем больше число, тем больше сообщений будет показано." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1354 +#: sssd.conf.5.xml:1321 msgid "Currently sssd supports the following values:" msgstr "В настоящее время sssd поддерживает следующие значения:" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1357 +#: sssd.conf.5.xml:1324 msgid "<emphasis>0</emphasis>: do not show any message" msgstr "<emphasis>0</emphasis>: не показывать никаких сообщений" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1360 +#: sssd.conf.5.xml:1327 msgid "<emphasis>1</emphasis>: show only important messages" msgstr "<emphasis>1</emphasis>: показывать только важные сообщения" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1364 +#: sssd.conf.5.xml:1331 msgid "<emphasis>2</emphasis>: show informational messages" msgstr "<emphasis>2</emphasis>: показывать информационные сообщения" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1367 +#: sssd.conf.5.xml:1334 msgid "<emphasis>3</emphasis>: show all messages and debug information" msgstr "" "<emphasis>3</emphasis>: показывать все сообщения и отладочную информацию" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1371 sssd.8.xml:63 +#: sssd.conf.5.xml:1338 sssd.8.xml:63 msgid "Default: 1" msgstr "По умолчанию: 1" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1377 +#: sssd.conf.5.xml:1344 msgid "pam_response_filter (string)" msgstr "pam_response_filter (строка)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1380 +#: sssd.conf.5.xml:1347 msgid "" "A comma separated list of strings which allows to remove (filter) data sent " "by the PAM responder to pam_sss PAM module. There are different kind of " @@ -2103,7 +2040,7 @@ msgstr "" "установлены pam_sss)." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1388 +#: sssd.conf.5.xml:1355 msgid "" "While messages already can be controlled with the help of the pam_verbosity " "option this option allows to filter out other kind of responses as well." @@ -2112,37 +2049,37 @@ msgstr "" "параметр позволяет отфильтровать также и другие типы ответов." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1395 +#: sssd.conf.5.xml:1362 msgid "ENV" msgstr "ENV" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1396 +#: sssd.conf.5.xml:1363 msgid "Do not send any environment variables to any service." msgstr "Не отправлять никаким службам никакие переменные среды." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1399 +#: sssd.conf.5.xml:1366 msgid "ENV:var_name" msgstr "ENV:var_name" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1400 +#: sssd.conf.5.xml:1367 msgid "Do not send environment variable var_name to any service." msgstr "Не отправлять переменную среды var_name никаким службам." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1404 +#: sssd.conf.5.xml:1371 msgid "ENV:var_name:service" msgstr "ENV:var_name:service" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1405 +#: sssd.conf.5.xml:1372 msgid "Do not send environment variable var_name to service." msgstr "Не отправлять переменную среды var_name указанной службе." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1393 +#: sssd.conf.5.xml:1360 msgid "" "Currently the following filters are supported: <placeholder " "type=\"variablelist\" id=\"0\"/>" @@ -2151,7 +2088,7 @@ msgstr "" "type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1412 +#: sssd.conf.5.xml:1379 msgid "" "The list of strings can either be the list of filters which would set this " "list of filters and overwrite the defaults. Or each element of the list can " @@ -2169,23 +2106,23 @@ msgstr "" "префикса только для части элементов списка считается ошибкой." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1423 +#: sssd.conf.5.xml:1390 msgid "Default: ENV:KRB5CCNAME:sudo, ENV:KRB5CCNAME:sudo-i" msgstr "По умолчанию: ENV:KRB5CCNAME:sudo, ENV:KRB5CCNAME:sudo-i" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1426 +#: sssd.conf.5.xml:1393 msgid "" "Example: -ENV:KRB5CCNAME:sudo-i will remove the filter from the default list" msgstr "Пример: -ENV:KRB5CCNAME:sudo-i удалит фильтр из списка стандартных" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1433 +#: sssd.conf.5.xml:1400 msgid "pam_id_timeout (integer)" msgstr "pam_id_timeout (целое число)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1436 +#: sssd.conf.5.xml:1403 msgid "" "For any PAM request while SSSD is online, the SSSD will attempt to " "immediately update the cached identity information for the user in order to " @@ -2197,7 +2134,7 @@ msgstr "" "данные." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1442 +#: sssd.conf.5.xml:1409 msgid "" "A complete PAM conversation may perform multiple PAM requests, such as " "account management and session opening. This option controls (on a per-" @@ -2211,17 +2148,17 @@ msgstr "" "обменов данными с поставщиком данных идентификации." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1456 +#: sssd.conf.5.xml:1423 msgid "pam_pwd_expiration_warning (integer)" msgstr "pam_pwd_expiration_warning (целое число)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1459 sssd.conf.5.xml:2912 +#: sssd.conf.5.xml:1426 sssd.conf.5.xml:3037 msgid "Display a warning N days before the password expires." msgstr "Показать предупреждение за N дней до истечения срока действия пароля." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1462 +#: sssd.conf.5.xml:1429 msgid "" "Please note that the backend server has to provide information about the " "expiration time of the password. If this information is missing, sssd " @@ -2232,7 +2169,7 @@ msgstr "" "сможет показать предупреждение." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1468 sssd.conf.5.xml:2915 +#: sssd.conf.5.xml:1435 sssd.conf.5.xml:3040 msgid "" "If zero is set, then this filter is not applied, i.e. if the expiration " "warning was received from backend server, it will automatically be displayed." @@ -2242,7 +2179,7 @@ msgstr "" "показано автоматически." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1473 +#: sssd.conf.5.xml:1440 msgid "" "This setting can be overridden by setting <emphasis>pwd_expiration_warning</" "emphasis> for a particular domain." @@ -2251,18 +2188,18 @@ msgstr "" "pwd_expiration_warning</emphasis> для конкретного домена." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1478 sssd.conf.5.xml:3913 sssd-ldap.5.xml:662 +#: sssd.conf.5.xml:1445 sssd.conf.5.xml:4118 sssd-ldap.5.xml:662 #: sssd-ldap.5.xml:1733 sssd.8.xml:79 msgid "Default: 0" msgstr "По умолчанию: 0" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1495 +#: sssd.conf.5.xml:1462 msgid "pam_trusted_users (string)" msgstr "pam_trusted_users (строка)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1498 +#: sssd.conf.5.xml:1465 msgid "" "Specifies the comma-separated list of UID values or user names that are " "allowed to run PAM conversations against trusted domains. Users not " @@ -2277,12 +2214,12 @@ msgstr "" "quote>. Имена пользователей разрешаются в UID при запуске." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1508 +#: sssd.conf.5.xml:1475 msgid "Default: All users are considered trusted by default" msgstr "По умолчанию: все пользователи считаются доверенными по умолчанию" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1512 +#: sssd.conf.5.xml:1479 msgid "" "Please note that UID 0 is always allowed to access the PAM responder even in " "case it is not in the pam_trusted_users list." @@ -2291,12 +2228,12 @@ msgstr "" "если этот идентификатор пользователя отсутствует в списке pam_trusted_users." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1519 +#: sssd.conf.5.xml:1486 msgid "pam_public_domains (string)" msgstr "pam_public_domains (строка)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1522 +#: sssd.conf.5.xml:1489 msgid "" "Specifies the comma-separated list of domain names that are accessible even " "to untrusted users." @@ -2305,12 +2242,12 @@ msgstr "" "недоверенных пользователей." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1526 +#: sssd.conf.5.xml:1493 msgid "Two special values for pam_public_domains option are defined:" msgstr "Для параметра pam_public_domains определены два специальных значения:" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1530 +#: sssd.conf.5.xml:1497 msgid "" "all (Untrusted users are allowed to access all domains in PAM responder.)" msgstr "" @@ -2318,7 +2255,7 @@ msgstr "" "PAM)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1534 +#: sssd.conf.5.xml:1501 msgid "" "none (Untrusted users are not allowed to access any domains PAM in " "responder.)" @@ -2327,18 +2264,18 @@ msgstr "" "PAM)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1538 sssd.conf.5.xml:1563 sssd.conf.5.xml:1582 -#: sssd.conf.5.xml:1824 sssd.conf.5.xml:3842 sssd-ldap.5.xml:1270 +#: sssd.conf.5.xml:1505 sssd.conf.5.xml:1530 sssd.conf.5.xml:1549 +#: sssd.conf.5.xml:1821 sssd.conf.5.xml:4048 sssd-ldap.5.xml:1270 msgid "Default: none" msgstr "По умолчанию: none" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1543 +#: sssd.conf.5.xml:1510 msgid "pam_account_expired_message (string)" msgstr "pam_account_expired_message (строка)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1546 +#: sssd.conf.5.xml:1513 msgid "" "Allows a custom expiration message to be set, replacing the default " "'Permission denied' message." @@ -2347,7 +2284,7 @@ msgstr "" "которое заменит стандартное сообщение «Доступ запрещён»." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1551 +#: sssd.conf.5.xml:1518 msgid "" "Note: Please be aware that message is only printed for the SSH service " "unless pam_verbosity is set to 3 (show all messages and debug information)." @@ -2357,7 +2294,7 @@ msgstr "" "(показывать все сообщения и отладочную информацию)." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1559 +#: sssd.conf.5.xml:1526 #, no-wrap msgid "" "pam_account_expired_message = Account expired, please contact help desk.\n" @@ -2368,12 +2305,12 @@ msgstr "" " " #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1568 +#: sssd.conf.5.xml:1535 msgid "pam_account_locked_message (string)" msgstr "pam_account_locked_message (строка)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1571 +#: sssd.conf.5.xml:1538 msgid "" "Allows a custom lockout message to be set, replacing the default 'Permission " "denied' message." @@ -2382,7 +2319,7 @@ msgstr "" "стандартное сообщение «Доступ запрещён»." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1578 +#: sssd.conf.5.xml:1545 #, no-wrap msgid "" "pam_account_locked_message = Account locked, please contact help desk.\n" @@ -2393,46 +2330,46 @@ msgstr "" " " #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1587 -msgid "pam_passkey_auth (bool)" +#: sssd.conf.5.xml:1554 +msgid "pam_passkey_auth (boolean)" msgstr "pam_passkey_auth (логическое значение)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1590 +#: sssd.conf.5.xml:1557 msgid "Enable passkey device based authentication." msgstr "Включить аутентификацию на основе ключа доступа." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1593 sssd.conf.5.xml:1910 sssd-ad.5.xml:1286 +#: sssd.conf.5.xml:1560 sssd.conf.5.xml:1907 sssd-ad.5.xml:1279 #: sss_rpcidmapd.5.xml:76 msgid "Default: True" msgstr "По умолчанию: true" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1598 -msgid "passkey_debug_libfido2 (bool)" +#: sssd.conf.5.xml:1565 +msgid "passkey_debug_libfido2 (boolean)" msgstr "passkey_debug_libfido2 (логическое значение)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1601 +#: sssd.conf.5.xml:1568 msgid "Enable libfido2 library debug messages." msgstr "Включить отладочные сообщения библиотеки libfido2." #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1604 sssd.conf.5.xml:1618 sssd-ldap.5.xml:727 -#: sssd-ldap.5.xml:752 sssd-ldap.5.xml:848 sssd-ldap.5.xml:1356 -#: sssd-ad.5.xml:506 sssd-ad.5.xml:582 sssd-ad.5.xml:1155 +#: sssd.conf.5.xml:1571 sssd.conf.5.xml:1585 sssd.conf.5.xml:4781 +#: sssd-ldap.5.xml:727 sssd-ldap.5.xml:752 sssd-ldap.5.xml:848 +#: sssd-ldap.5.xml:1356 sssd-ad.5.xml:506 sssd-ad.5.xml:582 sssd-ad.5.xml:1160 #: include/ldap_id_mapping.xml:250 msgid "Default: False" msgstr "По умолчанию: false" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1609 -msgid "pam_cert_auth (bool)" +#: sssd.conf.5.xml:1576 +msgid "pam_cert_auth (boolean)" msgstr "pam_cert_auth (логическое значение)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1612 +#: sssd.conf.5.xml:1579 msgid "" "Enable certificate based Smartcard authentication. Since this requires " "additional communication with the Smartcard which will delay the " @@ -2442,23 +2379,79 @@ msgstr "" "для этого требуется дополнительный обмен данными со смарт-картой, который " "задержит процесс проверки подлинности, по умолчанию этот параметр отключён." +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1588 +msgid "" +"Note: In case OpenSC is used for Smartcard access SSSD supports the " +"filesystem caching in OpenSC when enabled in opensc.conf. The cached files " +"are located in a common <quote>opensc</quote> directory in SSSD's state " +"directory. The behaviour can be changed in opensc.conf" +msgstr "" +"Примечание. Если для доступа к смарт-карте используется OpenSC, SSSD " +"поддерживает файловый кэш OpenSC, когда он включён в opensc.conf. " +"Кэшированные файлы находятся в общем каталоге <quote>opensc</quote> в " +"каталоге состояния SSSD. Поведение можно изменить в opensc.conf" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> +#: sssd.conf.5.xml:1597 +#, no-wrap +msgid "" +"app /usr/libexec/sssd/p11_child {\n" +" framework pkcs15 {\n" +" use_file_caching = no;\n" +" }\n" +"}\n" +"app /usr/libexec/sssd/krb5_child {\n" +" framework pkcs15 {\n" +" use_file_caching = no;\n" +" }\n" +"}\n" +" " +msgstr "" +"app /usr/libexec/sssd/p11_child {\n" +" framework pkcs15 {\n" +" use_file_caching = no;\n" +" }\n" +"}\n" +"app /usr/libexec/sssd/krb5_child {\n" +" framework pkcs15 {\n" +" use_file_caching = no;\n" +" }\n" +"}\n" +" " + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1595 +msgid "" +"Example opensc.conf (*): <placeholder type=\"programlisting\" id=\"0\"/>" +msgstr "Пример opensc.conf (*): <placeholder type=\"programlisting\" id=\"0\"/>" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1610 +msgid "" +"(*) The actual <quote>libexec</quote> directory for p11_child and krb5_child " +"depends on the distribution." +msgstr "" +"(*) Фактический каталог <quote>libexec</quote> для p11_child и krb5_child " +"зависит от дистрибутива." + #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1623 +#: sssd.conf.5.xml:1615 msgid "pam_cert_db_path (string)" msgstr "pam_cert_db_path (строка)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1626 +#: sssd.conf.5.xml:1618 msgid "The path to the certificate database." msgstr "Путь к базе данных сертификатов." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1629 sssd.conf.5.xml:2163 sssd.conf.5.xml:4338 +#: sssd.conf.5.xml:1621 sssd.conf.5.xml:2199 sssd.conf.5.xml:4543 msgid "Default:" msgstr "По умолчанию:" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1631 sssd.conf.5.xml:2165 +#: sssd.conf.5.xml:1623 sssd.conf.5.xml:2201 msgid "" "/etc/sssd/pki/sssd_auth_ca_db.pem (path to a file with trusted CA " "certificates in PEM format)" @@ -2467,12 +2460,12 @@ msgstr "" "CA в формате PEM)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1641 +#: sssd.conf.5.xml:1633 msgid "pam_cert_verification (string)" msgstr "pam_cert_verification (строка)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1644 +#: sssd.conf.5.xml:1636 msgid "" "With this parameter the PAM certificate verification can be tuned with a " "comma separated list of options that override the " @@ -2487,7 +2480,7 @@ msgstr "" "certificate_verification</quote>." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1655 +#: sssd.conf.5.xml:1647 #, no-wrap msgid "" "pam_cert_verification = partial_chain\n" @@ -2497,7 +2490,7 @@ msgstr "" " " #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1659 +#: sssd.conf.5.xml:1651 msgid "" "Default: not set, i.e. use default <quote>certificate_verification</quote> " "option defined in <quote>[sssd]</quote> section." @@ -2507,24 +2500,24 @@ msgstr "" "quote>." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1666 +#: sssd.conf.5.xml:1658 msgid "p11_child_timeout (integer)" msgstr "p11_child_timeout (целое число)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1669 +#: sssd.conf.5.xml:1661 msgid "How many seconds will pam_sss wait for p11_child to finish." msgstr "" "Разрешённое количество секунд, в течение которого pam_sss ожидает завершения " "работы p11_child." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1678 +#: sssd.conf.5.xml:1670 msgid "passkey_child_timeout (integer)" msgstr "passkey_child_timeout (целое число)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1681 +#: sssd.conf.5.xml:1673 msgid "" "How many seconds will the PAM responder wait for passkey_child to finish." msgstr "" @@ -2532,12 +2525,12 @@ msgstr "" "завершения работы passkey_child." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1690 +#: sssd.conf.5.xml:1682 msgid "pam_app_services (string)" msgstr "pam_app_services (строка)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1693 +#: sssd.conf.5.xml:1685 msgid "" "Which PAM services are permitted to contact domains of type " "<quote>application</quote>" @@ -2546,12 +2539,12 @@ msgstr "" "типа <quote>application</quote>" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1702 +#: sssd.conf.5.xml:1694 msgid "pam_p11_allowed_services (string)" msgstr "pam_p11_allowed_services (строка)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1705 +#: sssd.conf.5.xml:1697 msgid "" "A comma-separated list of PAM service names for which it will be allowed to " "use Smartcards." @@ -2560,7 +2553,7 @@ msgstr "" "использовать смарт-карты." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1720 +#: sssd.conf.5.xml:1712 #, no-wrap msgid "" "pam_p11_allowed_services = +my_pam_service, -login\n" @@ -2570,7 +2563,7 @@ msgstr "" " " #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1709 +#: sssd.conf.5.xml:1701 msgid "" "It is possible to add another PAM service name to the default set by using " "<quote>+service_name</quote> or to explicitly remove a PAM service name from " @@ -2589,68 +2582,73 @@ msgstr "" "конфигурацию: <placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1724 sssd-ad.5.xml:645 sssd-ad.5.xml:754 sssd-ad.5.xml:812 -#: sssd-ad.5.xml:870 sssd-ad.5.xml:948 +#: sssd.conf.5.xml:1716 sssd-ad.5.xml:645 sssd-ad.5.xml:759 sssd-ad.5.xml:817 +#: sssd-ad.5.xml:875 sssd-ad.5.xml:953 msgid "Default: the default set of PAM service names includes:" msgstr "По умолчанию: стандартный набор имён служб PAM включает:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1729 sssd-ad.5.xml:649 +#: sssd.conf.5.xml:1721 sssd-ad.5.xml:649 msgid "login" msgstr "login" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1734 sssd-ad.5.xml:654 +#: sssd.conf.5.xml:1726 sssd-ad.5.xml:654 msgid "su" msgstr "su" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1739 sssd-ad.5.xml:659 +#: sssd.conf.5.xml:1731 sssd-ad.5.xml:659 msgid "su-l" msgstr "su-l" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1744 sssd-ad.5.xml:674 +#: sssd.conf.5.xml:1736 sssd-ad.5.xml:674 msgid "gdm-smartcard" msgstr "gdm-smartcard" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1749 sssd-ad.5.xml:669 +#: sssd.conf.5.xml:1741 sssd-ad.5.xml:669 msgid "gdm-password" msgstr "gdm-password" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1754 +#: sssd.conf.5.xml:1746 msgid "gdm-switchable-auth" msgstr "gdm-switchable-auth" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1759 sssd-ad.5.xml:679 +#: sssd.conf.5.xml:1751 sssd-ad.5.xml:679 msgid "kdm" msgstr "kdm" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1764 sssd-ad.5.xml:957 +#: sssd.conf.5.xml:1756 sssd-ad.5.xml:694 +msgid "plasmalogin" +msgstr "plasmalogin" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:1761 sssd-ad.5.xml:962 msgid "sudo" msgstr "sudo" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1769 sssd-ad.5.xml:962 +#: sssd.conf.5.xml:1766 sssd-ad.5.xml:967 msgid "sudo-i" msgstr "sudo-i" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1774 +#: sssd.conf.5.xml:1771 msgid "gnome-screensaver" msgstr "gnome-screensaver" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1782 +#: sssd.conf.5.xml:1779 msgid "p11_wait_for_card_timeout (integer)" msgstr "p11_wait_for_card_timeout (целое число)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1785 +#: sssd.conf.5.xml:1782 msgid "" "If Smartcard authentication is required how many extra seconds in addition " "to p11_child_timeout should the PAM responder wait until a Smartcard is " @@ -2661,12 +2659,12 @@ msgstr "" "p11_child_timeout) ответчик PAM должен ожидать вставки смарт-карты." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1796 +#: sssd.conf.5.xml:1793 msgid "p11_uri (string)" msgstr "p11_uri (строка)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1799 +#: sssd.conf.5.xml:1796 msgid "" "PKCS#11 URI (see RFC-7512 for details) which can be used to restrict the " "selection of devices used for Smartcard authentication. By default SSSD's " @@ -2684,7 +2682,7 @@ msgstr "" "чтения." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1812 +#: sssd.conf.5.xml:1809 #, no-wrap msgid "" "p11_uri = pkcs11:slot-description=My%20Smartcard%20Reader\n" @@ -2694,7 +2692,7 @@ msgstr "" " " #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1816 +#: sssd.conf.5.xml:1813 #, no-wrap msgid "" "p11_uri = pkcs11:library-description=OpenSC%20smartcard%20framework;slot-id=2\n" @@ -2705,7 +2703,7 @@ msgstr "" " " #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1810 +#: sssd.conf.5.xml:1807 msgid "" "Example: <placeholder type=\"programlisting\" id=\"0\"/> or <placeholder " "type=\"programlisting\" id=\"1\"/> To find suitable URI please check the " @@ -2719,17 +2717,17 @@ msgstr "" "URI PKCS#11." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1829 -msgid "pam_initgroups_scheme" -msgstr "pam_initgroups_scheme" +#: sssd.conf.5.xml:1826 +msgid "pam_initgroups_scheme (string)" +msgstr "pam_initgroups_scheme (строка)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1837 +#: sssd.conf.5.xml:1834 msgid "always" msgstr "always" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1838 +#: sssd.conf.5.xml:1835 msgid "" "Always do an online lookup, please note that pam_id_timeout still applies" msgstr "" @@ -2737,12 +2735,12 @@ msgstr "" "pam_id_timeout всё равно применяется)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1842 +#: sssd.conf.5.xml:1839 msgid "no_session" msgstr "no_session" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1843 +#: sssd.conf.5.xml:1840 msgid "" "Only do an online lookup if there is no active session of the user, i.e. if " "the user is currently not logged in" @@ -2751,12 +2749,12 @@ msgstr "" "то есть тогда, когда пользователь не находится в системе" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1848 sssd-ldap.5.xml:189 +#: sssd.conf.5.xml:1845 sssd-ldap.5.xml:189 msgid "never" msgstr "never" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1849 +#: sssd.conf.5.xml:1846 msgid "" "Never force an online lookup, use the data from the cache as long as they " "are not expired" @@ -2765,7 +2763,7 @@ msgstr "" "до тех пор, пока они не устареют" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1832 +#: sssd.conf.5.xml:1829 msgid "" "The PAM responder can force an online lookup to get the current group " "memberships of the user trying to log in. This option controls when this " @@ -2778,17 +2776,17 @@ msgstr "" "допустимые значения: <placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1856 +#: sssd.conf.5.xml:1853 msgid "Default: no_session" msgstr "По умолчанию: no_session" -#. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:1861 sssd.conf.5.xml:4277 -msgid "pam_gssapi_services" -msgstr "pam_gssapi_services" +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1858 +msgid "pam_gssapi_services (string)" +msgstr "pam_gssapi_services (строка)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1864 +#: sssd.conf.5.xml:1861 msgid "" "Comma separated list of PAM services that are allowed to try GSSAPI " "authentication using pam_sss_gss.so module." @@ -2797,7 +2795,7 @@ msgstr "" "проверку подлинности по GSSAPI с помощью модуля pam_sss_gss.so." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1869 +#: sssd.conf.5.xml:1866 msgid "" "To disable GSSAPI authentication, set this option to <quote>-</quote> (dash)." msgstr "" @@ -2805,7 +2803,7 @@ msgstr "" "параметр в значение <quote>-</quote> (дефис)." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1873 sssd.conf.5.xml:1904 sssd.conf.5.xml:1942 +#: sssd.conf.5.xml:1870 sssd.conf.5.xml:1901 sssd.conf.5.xml:1939 msgid "" "Note: This option can also be set per-domain which overwrites the value in " "[pam] section. It can also be set for trusted domain which overwrites the " @@ -2817,7 +2815,7 @@ msgstr "" "в разделе домена." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1881 +#: sssd.conf.5.xml:1878 #, no-wrap msgid "" "pam_gssapi_services = sudo, sudo-i\n" @@ -2827,22 +2825,22 @@ msgstr "" " " #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1879 sssd.conf.5.xml:1994 sssd.conf.5.xml:3836 +#: sssd.conf.5.xml:1876 sssd.conf.5.xml:2023 sssd.conf.5.xml:4042 msgid "Example: <placeholder type=\"programlisting\" id=\"0\"/>" msgstr "Пример: <placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1885 +#: sssd.conf.5.xml:1882 msgid "Default: - (GSSAPI authentication is disabled)" msgstr "По умолчанию: - (проверка подлинности с помощью GSSAPI отключена)" -#. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:1890 sssd.conf.5.xml:4278 -msgid "pam_gssapi_check_upn" -msgstr "pam_gssapi_check_upn" +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1887 +msgid "pam_gssapi_check_upn (boolean)" +msgstr "pam_gssapi_check_upn (логическое значение)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1893 +#: sssd.conf.5.xml:1890 msgid "" "If True, SSSD will require that the Kerberos user principal that " "successfully authenticated through GSSAPI can be associated with the user " @@ -2854,21 +2852,21 @@ msgstr "" "такой привязки нет, проверка подлинности завершится ошибкой." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1900 +#: sssd.conf.5.xml:1897 msgid "" -"If False, every user that is able to obtained required service ticket will " +"If False, every user that is able to obtain a required service ticket will " "be authenticated." msgstr "" "Если значение «False», проверка подлинности будет выполняться для всех " "пользователей, получивших необходимый билет службы." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1915 -msgid "pam_gssapi_indicators_map" -msgstr "pam_gssapi_indicators_map" +#: sssd.conf.5.xml:1912 +msgid "pam_gssapi_indicators_map (string)" +msgstr "pam_gssapi_indicators_map (строка)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1918 +#: sssd.conf.5.xml:1915 msgid "" "Comma separated list of authentication indicators required to be present in " "a Kerberos ticket to access a PAM service that is allowed to try GSSAPI " @@ -2880,7 +2878,7 @@ msgstr "" "pam_sss_gss.so." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1924 +#: sssd.conf.5.xml:1921 msgid "" "Each element of the list can be either an authentication indicator name or a " "pair <quote>service:indicator</quote>. Indicators not prefixed with the PAM " @@ -2907,7 +2905,7 @@ msgstr "" "доступ." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1937 +#: sssd.conf.5.xml:1934 msgid "" "To disable GSSAPI authentication indicator check, set this option to <quote>-" "</quote> (dash). To disable the check for a specific PAM service, add " @@ -2919,7 +2917,7 @@ msgstr "" "service:-</quote>." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1948 +#: sssd.conf.5.xml:1945 msgid "" "Following authentication indicators are supported by IPA Kerberos " "deployments:" @@ -2928,7 +2926,7 @@ msgstr "" "индикаторов проверки подлинности:" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1951 +#: sssd.conf.5.xml:1948 msgid "" "pkinit -- pre-authentication using X.509 certificates -- whether stored in " "files or on smart cards." @@ -2937,7 +2935,7 @@ msgstr "" "которые хранятся в файлах или на смарт-картах." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1954 +#: sssd.conf.5.xml:1951 msgid "" "hardened -- SPAKE pre-authentication or any pre-authentication wrapped in a " "FAST channel." @@ -2946,12 +2944,12 @@ msgstr "" "предварительная проверка подлинности, помещённая в канал FAST." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1957 +#: sssd.conf.5.xml:1954 msgid "radius -- pre-authentication with the help of a RADIUS server." msgstr "radius — предварительная проверка подлинности с помощью сервера RADIUS." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1960 +#: sssd.conf.5.xml:1957 msgid "" "otp -- pre-authentication using integrated two-factor authentication (2FA or " "one-time password, OTP) in IPA." @@ -2960,14 +2958,14 @@ msgstr "" "двухфакторной аутентификации (2FA или одноразовый пароль, OTP) в IPA." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1963 +#: sssd.conf.5.xml:1960 msgid "idp -- pre-authentication using external identity provider." msgstr "" "idp -- предварительная аутентификация с использованием внешнего поставщика " "удостоверений." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1973 +#: sssd.conf.5.xml:1970 #, no-wrap msgid "" "pam_gssapi_indicators_map = sudo:pkinit, sudo-i:pkinit\n" @@ -2977,7 +2975,7 @@ msgstr "" " " #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1968 +#: sssd.conf.5.xml:1965 msgid "" "Example: to require access to SUDO services only for users which obtained " "their Kerberos tickets with a X.509 certificate pre-authentication (PKINIT), " @@ -2989,35 +2987,83 @@ msgstr "" "type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1977 +#: sssd.conf.5.xml:1974 msgid "Default: not set (use of authentication indicators is not required)" msgstr "" "По умолчанию: не задано (использование индикаторов проверки подлинности не " "требуется)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1979 +msgid "pam_gssapi_indicators_apply (string)" +msgstr "pam_gssapi_indicators_apply (строка)" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1982 +msgid "" +"Comma separated list of triples to assign additional information from the " +"Kerberos ticket, e.g. a SID from the PAC, to authentication indicators." +msgstr "" +"Разделённый запятыми список троек для назначения дополнительной информации " +"из билета Kerberos, например SID из PAC, индикаторам проверки подлинности." + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1988 +msgid "Currently supported is:" +msgstr "В настоящее время поддерживается:" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:1991 +msgid "SID:S-1-5-[domain]-[RID]:[authentication indicator]" +msgstr "SID:S-1-5-[domain]-[RID]:[authentication indicator]" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> +#: sssd.conf.5.xml:2002 +#, no-wrap +msgid "" +"pam_gssapi_indicators_apply = SID:S-1-5-12345-23456-34567-4321:pkinit\n" +" " +msgstr "" +"pam_gssapi_indicators_apply = SID:S-1-5-12345-23456-34567-4321:pkinit\n" +" " + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1996 +msgid "" +"Example: To assign a SID, which is e.g. set by Active Directory's " +"Authentication Mechanism Assurance (AMA) if the AD user used a Smartcard for " +"authentication, to the 'pkinit' authentication indicator use: <placeholder " +"type=\"programlisting\" id=\"0\"/>" +msgstr "" +"Пример. Чтобы назначить SID, который, например, устанавливается механизмом " +"Authentication Mechanism Assurance (AMA) Active Directory, если пользователь " +"AD использовал смарт-карту для проверки подлинности, индикатору проверки " +"подлинности 'pkinit', используйте: <placeholder type=\"programlisting\" " +"id=\"0\"/>" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2011 msgid "pam_json_services (string)" msgstr "pam_json_services (строка)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1985 +#: sssd.conf.5.xml:2014 msgid "" "Comma separated list of PAM services which can handle the JSON protocol for " "selecting authentication mechanisms" msgstr "" "Разделённый запятыми список служб PAM, которые поддерживают JSON-протокол " -"для выбора механизмов аутентификации." +"для выбора механизмов аутентификации" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1990 +#: sssd.conf.5.xml:2019 msgid "To disable JSON protocol, set this option to <quote>-</quote> (dash)." msgstr "" "Чтобы отключить JSON-протокол, установите этот параметр в значение <quote>-</" "quote> (дефис)." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1996 +#: sssd.conf.5.xml:2025 #, no-wrap msgid "" "pam_json_services = gdm-switchable-auth\n" @@ -3027,12 +3073,12 @@ msgstr "" " " #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2000 +#: sssd.conf.5.xml:2029 msgid "Default: - (JSON protocol is disabled)" msgstr "По умолчанию: - (JSON-протокол отключён)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2003 +#: sssd.conf.5.xml:2032 msgid "" "Note: 2-Factor Authentication (2FA) is not supported. If 2FA is required, do " "not activate the JSON protocol." @@ -3041,34 +3087,43 @@ msgstr "" "требуется 2FA, не включайте JSON-протокол." #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:2013 +#: sssd.conf.5.xml:2042 msgid "SUDO configuration options" msgstr "Параметры настройки SUDO" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2015 +#: sssd.conf.5.xml:2044 msgid "" -"These options can be used to configure the sudo service. The detailed " -"instructions for configuration of <citerefentry> <refentrytitle>sudo</" -"refentrytitle> <manvolnum>8</manvolnum> </citerefentry> to work with " -"<citerefentry> <refentrytitle>sssd</refentrytitle> <manvolnum>8</manvolnum> " -"</citerefentry> are in the manual page <citerefentry> <refentrytitle>sssd-" -"sudo</refentrytitle> <manvolnum>5</manvolnum> </citerefentry>." +"These options can be used to configure the sudo service and should be " +"specified under the <quote>[sudo]</quote> section." msgstr "" -"Эти параметры можно использовать для настройки службы sudo. Подробные " -"инструкции по настройке <citerefentry> <refentrytitle>sudo</refentrytitle> " -"<manvolnum>8</manvolnum> </citerefentry> для работы с <citerefentry> " -"<refentrytitle>sssd</refentrytitle> <manvolnum>8</manvolnum> </citerefentry> " -"доступны на справочной странице <citerefentry> <refentrytitle>sssd-sudo</" -"refentrytitle> <manvolnum>5</manvolnum> </citerefentry>." +"Эти параметры можно использовать для настройки службы sudo и должны " +"указываться в разделе <quote>[sudo]</quote>." + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:2048 +msgid "" +"The detailed instructions for configuration of <citerefentry> " +"<refentrytitle>sudo</refentrytitle> <manvolnum>8</manvolnum> </citerefentry> " +"to work with <citerefentry> <refentrytitle>sssd</refentrytitle> " +"<manvolnum>8</manvolnum> </citerefentry> are in the manual page " +"<citerefentry> <refentrytitle>sssd-sudo</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry>." +msgstr "" +"Подробные инструкции по настройке <citerefentry> <refentrytitle>sudo</" +"refentrytitle> <manvolnum>8</manvolnum> </citerefentry> для работы с " +"<citerefentry> <refentrytitle>sssd</refentrytitle> <manvolnum>8</manvolnum> " +"</citerefentry> доступны на справочной странице <citerefentry> " +"<refentrytitle>sssd-sudo</refentrytitle> <manvolnum>5</manvolnum> </" +"citerefentry>." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2032 -msgid "sudo_timed (bool)" +#: sssd.conf.5.xml:2064 +msgid "sudo_timed (boolean)" msgstr "sudo_timed (логическое значение)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2035 +#: sssd.conf.5.xml:2067 msgid "" "Whether or not to evaluate the sudoNotBefore and sudoNotAfter attributes " "that implement time-dependent sudoers entries." @@ -3077,12 +3132,12 @@ msgstr "" "предназначенные для определения временных ограничений для записей sudoers." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2047 +#: sssd.conf.5.xml:2079 msgid "sudo_threshold (integer)" msgstr "sudo_threshold (целое число)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2050 +#: sssd.conf.5.xml:2082 msgid "" "Maximum number of expired rules that can be refreshed at once. If number of " "expired rules is below threshold, those rules are refreshed with " @@ -3098,22 +3153,26 @@ msgstr "" "поискам команд и групп команд sudo IPA." #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:2069 +#: sssd.conf.5.xml:2101 msgid "AUTOFS configuration options" msgstr "Параметры настройки AUTOFS" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2071 -msgid "These options can be used to configure the autofs service." -msgstr "Эти параметры можно использовать для настройки службы autofs." +#: sssd.conf.5.xml:2103 +msgid "" +"These options can be used to configure the autofs service and should be " +"specified under the <quote>[autofs]</quote> section." +msgstr "" +"Эти параметры можно использовать для настройки службы autofs и должны " +"указываться в разделе <quote>[autofs]</quote>." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2075 +#: sssd.conf.5.xml:2109 msgid "autofs_negative_timeout (integer)" msgstr "autofs_negative_timeout (целое число)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2078 +#: sssd.conf.5.xml:2112 msgid "" "Specifies for how many seconds should the autofs responder negative cache " "hits (that is, queries for invalid map entries, like nonexistent ones) " @@ -3124,22 +3183,26 @@ msgstr "" "например, несуществующих) перед повторным запросом к внутреннему серверу." #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:2094 +#: sssd.conf.5.xml:2128 msgid "SSH configuration options" msgstr "Параметры настройки SSH" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2096 -msgid "These options can be used to configure the SSH service." -msgstr "Эти параметры можно использовать для настройки службы SSH." +#: sssd.conf.5.xml:2130 +msgid "" +"These options can be used to configure the SSH service and should be " +"specified under the <quote>[ssh]</quote> section." +msgstr "" +"Эти параметры можно использовать для настройки службы SSH и должны " +"указываться в разделе <quote>[ssh]</quote>." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2100 -msgid "ssh_use_certificate_keys (bool)" +#: sssd.conf.5.xml:2136 +msgid "ssh_use_certificate_keys (boolean)" msgstr "ssh_use_certificate_keys (логическое значение)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2103 +#: sssd.conf.5.xml:2139 msgid "" "If set to true the <command>sss_ssh_authorizedkeys</command> will return ssh " "keys derived from the public key of X.509 certificates stored in the user " @@ -3153,12 +3216,12 @@ msgstr "" "<manvolnum>1</manvolnum> </citerefentry>." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2118 +#: sssd.conf.5.xml:2154 msgid "ssh_use_certificate_matching_rules (string)" msgstr "ssh_use_certificate_matching_rules (строка)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2121 +#: sssd.conf.5.xml:2157 msgid "" "By default the ssh responder will use all available certificate matching " "rules to filter the certificates so that ssh keys are only derived from the " @@ -3174,7 +3237,7 @@ msgstr "" "другие правила будут игнорироваться." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2130 +#: sssd.conf.5.xml:2166 msgid "" "There are two special key words 'all_rules' and 'no_rules' which will enable " "all or no rules, respectively. The latter means that no certificates will be " @@ -3186,7 +3249,7 @@ msgstr "" "ключи SSH будут создаваться на основе всех действительных сертификатов." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2137 +#: sssd.conf.5.xml:2173 msgid "" "If no rules are configured using 'all_rules' will enable a default rule " "which enables all certificates suitable for client authentication. This is " @@ -3200,7 +3263,7 @@ msgstr "" "подлинности сертификатов." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2144 +#: sssd.conf.5.xml:2180 msgid "" "A non-existing rule name is considered an error. If as a result no rule is " "selected all certificates will be ignored." @@ -3209,7 +3272,7 @@ msgstr "" "выбрано ни одного правила, все сертификаты будут проигнорированы." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2149 +#: sssd.conf.5.xml:2185 msgid "" "Default: not set, equivalent to 'all_rules', all found rules or the default " "rule are used" @@ -3218,12 +3281,12 @@ msgstr "" "правила или правило по умолчанию" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2155 +#: sssd.conf.5.xml:2191 msgid "ca_db (string)" msgstr "ca_db (строка)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2158 +#: sssd.conf.5.xml:2194 msgid "" "Path to a storage of trusted CA certificates. The option is used to validate " "user certificates before deriving public ssh keys from them." @@ -3233,12 +3296,12 @@ msgstr "" "SSH." #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:2178 +#: sssd.conf.5.xml:2214 msgid "PAC responder configuration options" msgstr "Параметры настройки ответчика PAC" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2180 +#: sssd.conf.5.xml:2216 msgid "" "The PAC responder works together with the authorization data plugin for MIT " "Kerberos sssd_pac_plugin.so and a sub-domain provider. The plugin sends the " @@ -3256,7 +3319,7 @@ msgstr "" "обрабатывается, выполняются некоторые из следующих операций:" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:2189 +#: sssd.conf.5.xml:2225 msgid "" "If the remote user does not exist in the cache, it is created. The UID is " "determined with the help of the SID, trusted domains will have UPGs and the " @@ -3273,7 +3336,7 @@ msgstr "" "можно переопределить с помощью параметра default_shell." #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:2197 +#: sssd.conf.5.xml:2233 msgid "" "If there are SIDs of groups from domains sssd knows about, the user will be " "added to those groups." @@ -3282,17 +3345,21 @@ msgstr "" "добавлен в эти группы." #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2203 -msgid "These options can be used to configure the PAC responder." -msgstr "Эти параметры можно использовать для настройки ответчика PAC." +#: sssd.conf.5.xml:2239 +msgid "" +"These options can be used to configure the PAC responder and should be " +"specified under the <quote>[pac]</quote> section." +msgstr "" +"Эти параметры можно использовать для настройки ответчика PAC и должны " +"указываться в разделе <quote>[pac]</quote>." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2207 sssd-ifp.5.xml:66 +#: sssd.conf.5.xml:2244 sssd-ifp.5.xml:66 msgid "allowed_uids (string)" msgstr "allowed_uids (строка)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2210 +#: sssd.conf.5.xml:2247 msgid "" "Specifies the comma-separated list of UID values or user names that are " "allowed to access the PAC responder. User names are resolved to UIDs at " @@ -3303,7 +3370,7 @@ msgstr "" "запуске." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2216 +#: sssd.conf.5.xml:2253 msgid "" "Default: 0, &sssd_user_name; (only root and SSSD service users are allowed " "to access the PAC responder)" @@ -3312,13 +3379,13 @@ msgstr "" "root и пользователям службы SSSD)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2220 +#: sssd.conf.5.xml:2257 msgid "Default: 0 (only the root user is allowed to access the PAC responder)" msgstr "" "По умолчанию: 0 (доступ к ответчику PAC разрешён только пользователю root)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2224 +#: sssd.conf.5.xml:2261 msgid "" "Please note that defaults will be overwritten with this option. If you still " "want to allow the root and/or '&sssd_user_name;' user to access the PAC " @@ -3331,7 +3398,7 @@ msgstr "" ", необходимо явно добавить их в список разрешенных UID." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2231 +#: sssd.conf.5.xml:2268 msgid "" "Please note that although the UID 0 is used as the default it will be " "overwritten with this option. If you still want to allow the root user to " @@ -3345,12 +3412,12 @@ msgstr "" "доступ." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2240 +#: sssd.conf.5.xml:2277 msgid "pac_lifetime (integer)" msgstr "pac_lifetime (целое число)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2243 +#: sssd.conf.5.xml:2280 msgid "" "Lifetime of the PAC entry in seconds. As long as the PAC is valid the PAC " "data can be used to determine the group memberships of a user." @@ -3359,12 +3426,12 @@ msgstr "" "PAC можно использовать для определения участия пользователя в группах." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2253 +#: sssd.conf.5.xml:2290 msgid "pac_check (string)" msgstr "pac_check (строка)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2256 +#: sssd.conf.5.xml:2293 msgid "" "Apply additional checks on the PAC of the Kerberos ticket which is available " "in Active Directory and FreeIPA domains, if configured. Please note that " @@ -3382,7 +3449,7 @@ msgstr "" "пропущена." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2266 +#: sssd.conf.5.xml:2303 msgid "" "Please note that the checks listed below only apply to PACs issued by Active " "Directory or recent versions of FreeIPA. PACs issued e.g. by a plain MIT " @@ -3394,12 +3461,12 @@ msgstr "" "буферов данных PAC для выполнения этих проверок." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2277 +#: sssd.conf.5.xml:2314 msgid "no_check" msgstr "no_check" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2279 +#: sssd.conf.5.xml:2316 msgid "" "The PAC must not be present and even if it is present no additional checks " "will be done." @@ -3408,12 +3475,12 @@ msgstr "" "проверки выполняться не будут." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2285 +#: sssd.conf.5.xml:2322 msgid "pac_present" msgstr "pac_present" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2287 +#: sssd.conf.5.xml:2324 msgid "" "The PAC must be present in the service ticket which SSSD will request with " "the help of the user's TGT. If the PAC is not available the authentication " @@ -3424,12 +3491,12 @@ msgstr "" "ошибкой." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2295 +#: sssd.conf.5.xml:2332 msgid "check_upn" msgstr "check_upn" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2297 +#: sssd.conf.5.xml:2334 msgid "" "If the PAC is present check if the user principal name (UPN) information is " "consistent." @@ -3438,12 +3505,12 @@ msgstr "" "пользователя (UPN) верна." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2303 +#: sssd.conf.5.xml:2340 msgid "check_upn_allow_missing" msgstr "check_upn_allow_missing" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2305 +#: sssd.conf.5.xml:2342 msgid "" "This option should be used together with 'check_upn' and handles the case " "where a UPN is set on the server-side but is not read by SSSD. The typical " @@ -3463,7 +3530,7 @@ msgstr "" "устанавливать 'ldap_user_principal'." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2317 +#: sssd.conf.5.xml:2354 msgid "" "Currently this option is set by default to avoid regressions in such " "environments. A log message will be added to the system log and SSSD's debug " @@ -3480,24 +3547,24 @@ msgstr "" "пропуску проверки и сообщение не появится в журнале." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2331 +#: sssd.conf.5.xml:2368 msgid "upn_dns_info_present" msgstr "upn_dns_info_present" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2333 +#: sssd.conf.5.xml:2370 msgid "The PAC must contain the UPN-DNS-INFO buffer, implies 'check_upn'." msgstr "" "PAC должен содержать буфер UPN-DNS-INFO, неявным образом устанавливает " "'check_upn'." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2338 +#: sssd.conf.5.xml:2375 msgid "check_upn_dns_info_ex" msgstr "check_upn_dns_info_ex" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2340 +#: sssd.conf.5.xml:2377 msgid "" "If the PAC is present and the extension to the UPN-DNS-INFO buffer is " "available check if the information in the extension is consistent." @@ -3506,12 +3573,12 @@ msgstr "" "согласованы ли данные в расширении." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2347 +#: sssd.conf.5.xml:2384 msgid "upn_dns_info_ex_present" msgstr "upn_dns_info_ex_present" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2349 +#: sssd.conf.5.xml:2386 msgid "" "The PAC must contain the extension of the UPN-DNS-INFO buffer, implies " "'check_upn_dns_info_ex', 'upn_dns_info_present' and 'check_upn'." @@ -3520,7 +3587,7 @@ msgstr "" "устанавливает 'check_upn_dns_info_ex', 'upn_dns_info_present' и 'check_upn'." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2273 +#: sssd.conf.5.xml:2310 msgid "" "The following options can be used alone or in a comma-separated list: " "<placeholder type=\"variablelist\" id=\"0\"/>" @@ -3529,7 +3596,7 @@ msgstr "" "запятыми списка: <placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2359 +#: sssd.conf.5.xml:2396 msgid "" "Default: no_check (AD and IPA provider 'check_upn, check_upn_allow_missing, " "check_upn_dns_info_ex')" @@ -3538,12 +3605,12 @@ msgstr "" "check_upn_allow_missing, check_upn_dns_info_ex')" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:2368 +#: sssd.conf.5.xml:2405 msgid "Session recording configuration options" msgstr "Параметры настройки записи сеансов" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2370 +#: sssd.conf.5.xml:2407 msgid "" "Session recording works in conjunction with <citerefentry> " "<refentrytitle>tlog-rec-session</refentrytitle> <manvolnum>8</manvolnum> </" @@ -3559,32 +3626,51 @@ msgstr "" "manvolnum> </citerefentry>." #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2383 -msgid "These options can be used to configure session recording." -msgstr "Эти параметры можно использовать для настройки записи сеансов." +#: sssd.conf.5.xml:2420 +msgid "" +"These options can be used to configure session recording and should be " +"specified under the <quote>[session_recording]</quote> section." +msgstr "" +"Эти параметры можно использовать для настройки записи сеансов и должны " +"указываться в разделе <quote>[session_recording]</quote>." + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:2425 +msgid "" +"Note: Unlike other sections, the <quote>[session_recording]</quote> section " +"ignores <replaceable>debug*</replaceable> options and suitable " +"<replaceable>debug*</replaceable> options must be set in <quote>[pam]</" +"quote>, <quote>[nss]</quote> and <quote>[domain/<replaceable>NAME</" +"replaceable>]</quote> sections." +msgstr "" +"Примечание. В отличие от других разделов, раздел <quote>[session_recording]</" +"quote> игнорирует параметры <replaceable>debug*</replaceable>; " +"соответствующие параметры <replaceable>debug*</replaceable> должны быть " +"заданы в разделах <quote>[pam]</quote>, <quote>[nss]</quote> и <quote>" +"[domain/<replaceable>NAME</replaceable>]</quote>." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2387 sssd-session-recording.5.xml:64 +#: sssd.conf.5.xml:2433 sssd-session-recording.5.xml:64 msgid "scope (string)" msgstr "scope (строка)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2394 sssd-session-recording.5.xml:71 +#: sssd.conf.5.xml:2440 sssd-session-recording.5.xml:71 msgid "\"none\"" msgstr "«none»" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2397 sssd-session-recording.5.xml:74 +#: sssd.conf.5.xml:2443 sssd-session-recording.5.xml:74 msgid "No users are recorded." msgstr "Пользователи не записываются." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2402 sssd-session-recording.5.xml:79 +#: sssd.conf.5.xml:2448 sssd-session-recording.5.xml:79 msgid "\"some\"" msgstr "«some»" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2405 sssd-session-recording.5.xml:82 +#: sssd.conf.5.xml:2451 sssd-session-recording.5.xml:82 msgid "" "Users/groups specified by <replaceable>users</replaceable> and " "<replaceable>groups</replaceable> options are recorded." @@ -3593,17 +3679,17 @@ msgstr "" "<replaceable>users</replaceable> и <replaceable>groups</replaceable>." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2414 sssd-session-recording.5.xml:91 +#: sssd.conf.5.xml:2460 sssd-session-recording.5.xml:91 msgid "\"all\"" msgstr "«all»" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2417 sssd-session-recording.5.xml:94 +#: sssd.conf.5.xml:2463 sssd-session-recording.5.xml:94 msgid "All users are recorded." msgstr "Записываются все пользователи." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2390 sssd-session-recording.5.xml:67 +#: sssd.conf.5.xml:2436 sssd-session-recording.5.xml:67 msgid "" "One of the following strings specifying the scope of session recording: " "<placeholder type=\"variablelist\" id=\"0\"/>" @@ -3612,17 +3698,17 @@ msgstr "" "<placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2424 sssd-session-recording.5.xml:101 +#: sssd.conf.5.xml:2470 sssd-session-recording.5.xml:101 msgid "Default: \"none\"" msgstr "По умолчанию: «none»" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2429 sssd-session-recording.5.xml:106 +#: sssd.conf.5.xml:2475 sssd-session-recording.5.xml:106 msgid "users (string)" msgstr "users (строка)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2432 sssd-session-recording.5.xml:109 +#: sssd.conf.5.xml:2478 sssd-session-recording.5.xml:109 msgid "" "A comma-separated list of users which should have session recording enabled. " "Matches user names as returned by NSS. I.e. after the possible space " @@ -3634,17 +3720,17 @@ msgstr "" "так далее." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2438 sssd-session-recording.5.xml:115 +#: sssd.conf.5.xml:2484 sssd-session-recording.5.xml:115 msgid "Default: Empty. Matches no users." msgstr "По умолчанию: пусто. Не соответствует ни одному пользователю." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2443 sssd-session-recording.5.xml:120 +#: sssd.conf.5.xml:2489 sssd-session-recording.5.xml:120 msgid "groups (string)" msgstr "groups (строка)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2446 sssd-session-recording.5.xml:123 +#: sssd.conf.5.xml:2492 sssd-session-recording.5.xml:123 msgid "" "A comma-separated list of groups, members of which should have session " "recording enabled. Matches group names as returned by NSS. I.e. after the " @@ -3655,7 +3741,7 @@ msgstr "" "NSS, то есть после возможной замены пробелов, смены регистра и так далее." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2452 sssd.conf.5.xml:2484 sssd-session-recording.5.xml:129 +#: sssd.conf.5.xml:2498 sssd.conf.5.xml:2530 sssd-session-recording.5.xml:129 #: sssd-session-recording.5.xml:161 msgid "" "NOTE: using this option (having it set to anything) has a considerable " @@ -3668,17 +3754,17 @@ msgstr "" "установление соответствия групп, участником которых он является." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2459 sssd-session-recording.5.xml:136 +#: sssd.conf.5.xml:2505 sssd-session-recording.5.xml:136 msgid "Default: Empty. Matches no groups." msgstr "По умолчанию: пусто. Не соответствует ни одной группе." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2464 sssd-session-recording.5.xml:141 +#: sssd.conf.5.xml:2510 sssd-session-recording.5.xml:141 msgid "exclude_users (string)" msgstr "exclude_users (строка)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2467 sssd-session-recording.5.xml:144 +#: sssd.conf.5.xml:2513 sssd-session-recording.5.xml:144 msgid "" "A comma-separated list of users to be excluded from recording, only " "applicable with 'scope=all'." @@ -3687,17 +3773,17 @@ msgstr "" "применимо только при «scope=all»." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2471 sssd-session-recording.5.xml:148 +#: sssd.conf.5.xml:2517 sssd-session-recording.5.xml:148 msgid "Default: Empty. No users excluded." msgstr "По умолчанию: пусто. Не исключается ни один пользователь." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2476 sssd-session-recording.5.xml:153 +#: sssd.conf.5.xml:2522 sssd-session-recording.5.xml:153 msgid "exclude_groups (string)" msgstr "exclude_groups (строка)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2479 sssd-session-recording.5.xml:156 +#: sssd.conf.5.xml:2525 sssd-session-recording.5.xml:156 msgid "" "A comma-separated list of groups, members of which should be excluded from " "recording. Only applicable with 'scope=all'." @@ -3706,23 +3792,22 @@ msgstr "" "применимо только при «scope=all»." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2491 sssd-session-recording.5.xml:168 +#: sssd.conf.5.xml:2537 sssd-session-recording.5.xml:168 msgid "Default: Empty. No groups excluded." msgstr "По умолчанию: пусто. Не исключается ни одна группа." #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:2501 +#: sssd.conf.5.xml:2547 msgid "DOMAIN SECTIONS" msgstr "РАЗДЕЛЫ ДОМЕНА" -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry><para> -#: sssd.conf.5.xml:2508 sssd.conf.5.xml:3964 sssd.conf.5.xml:3965 -#: sssd.conf.5.xml:3968 -msgid "enabled" -msgstr "enabled" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2554 +msgid "enabled (boolean)" +msgstr "enabled (логическое значение)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2511 +#: sssd.conf.5.xml:2557 msgid "" "Explicitly enable or disable the domain. If <quote>true</quote>, the domain " "is always <quote>enabled</quote>. If <quote>false</quote>, the domain is " @@ -3737,12 +3822,12 @@ msgstr "" "параметра domains в разделе <quote>[sssd]</quote>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2523 +#: sssd.conf.5.xml:2569 msgid "domain_type (string)" msgstr "domain_type (строка)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2526 +#: sssd.conf.5.xml:2572 msgid "" "Specifies whether the domain is meant to be used by POSIX-aware clients such " "as the Name Service Switch or by applications that do not need POSIX data to " @@ -3755,7 +3840,7 @@ msgstr "" "операционной системы доступны только объекты из доменов POSIX." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2534 +#: sssd.conf.5.xml:2580 msgid "" "Allowed values for this option are <quote>posix</quote> and " "<quote>application</quote>." @@ -3764,7 +3849,7 @@ msgstr "" "application</quote>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2538 +#: sssd.conf.5.xml:2584 msgid "" "POSIX domains are reachable by all services. Application domains are only " "reachable from the InfoPipe responder (see <citerefentry> " @@ -3776,7 +3861,7 @@ msgstr "" "refentrytitle> <manvolnum>5</manvolnum> </citerefentry>) и ответчика PAM." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2546 +#: sssd.conf.5.xml:2592 msgid "" "NOTE: The application domains are currently well tested with " "<quote>id_provider=ldap</quote> only." @@ -3785,7 +3870,7 @@ msgstr "" "с <quote>id_provider=ldap</quote>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2550 +#: sssd.conf.5.xml:2596 msgid "" "For an easy way to configure a non-POSIX domains, please see the " "<quote>Application domains</quote> section." @@ -3794,17 +3879,17 @@ msgstr "" "<quote>Домены приложений</quote>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2554 +#: sssd.conf.5.xml:2600 msgid "Default: posix" msgstr "По умолчанию: posix" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2560 +#: sssd.conf.5.xml:2606 msgid "min_id,max_id (integer)" msgstr "min_id,max_id (целое число)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2563 +#: sssd.conf.5.xml:2609 msgid "" "UID and GID limits for the domain. If a domain contains an entry that is " "outside these limits, it is ignored." @@ -3813,7 +3898,7 @@ msgstr "" "находящуюся вне указанного диапазона, она будет проигнорирована." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2568 +#: sssd.conf.5.xml:2614 msgid "" "For users, this affects the primary GID limit. The user will not be returned " "to NSS if either the UID or the primary GID is outside the range. For non-" @@ -3827,7 +3912,7 @@ msgstr "" "группы, будут выведены в обычном режиме." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2575 +#: sssd.conf.5.xml:2621 msgid "" "These ID limits affect even saving entries to cache, not only returning them " "by name or ID." @@ -3836,17 +3921,17 @@ msgstr "" "кэш, а не только на их возврат по имени или идентификатору." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2579 +#: sssd.conf.5.xml:2625 msgid "Default: 1 for min_id, 0 (no limit) for max_id" msgstr "По умолчанию: 1 для min_id, 0 (без ограничений) для max_id" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2585 -msgid "enumerate (bool)" +#: sssd.conf.5.xml:2631 +msgid "enumerate (boolean)" msgstr "enumerate (логическое значение)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2588 +#: sssd.conf.5.xml:2634 msgid "" "Determines if a domain can be enumerated, that is, whether the domain can " "list all the users and group it contains. Note that it is not required to " @@ -3859,22 +3944,22 @@ msgstr "" "вторичных групп. Этот параметр может иметь одно из следующих значений:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2596 +#: sssd.conf.5.xml:2642 msgid "TRUE = Users and groups are enumerated" msgstr "TRUE = пользователи и группы перечисляются" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2599 +#: sssd.conf.5.xml:2645 msgid "FALSE = No enumerations for this domain" msgstr "FALSE = для этого домена не выполняется перечисление" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2602 sssd.conf.5.xml:2867 sssd.conf.5.xml:3044 +#: sssd.conf.5.xml:2648 sssd.conf.5.xml:2992 sssd.conf.5.xml:3174 msgid "Default: FALSE" msgstr "По умолчанию: FALSE" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2605 +#: sssd.conf.5.xml:2651 msgid "" "Enumerating a domain requires SSSD to download and store ALL user and group " "entries from the remote server." @@ -3883,7 +3968,7 @@ msgstr "" "сохранить ВСЕ записи пользователей и групп с удалённого сервера." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2610 +#: sssd.conf.5.xml:2656 msgid "" "Feature is only supported for domains with id_provider = ldap or id_provider " "= proxy." @@ -3892,7 +3977,7 @@ msgstr "" "id_provider = proxy." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2614 +#: sssd.conf.5.xml:2660 msgid "" "Note: Enabling enumeration has a severe performance impact on SSSD while " "enumeration is running. It may take up to several minutes after SSSD startup " @@ -3916,7 +4001,7 @@ msgstr "" "перезапущен внутренним сторожевым таймером." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2629 +#: sssd.conf.5.xml:2675 msgid "" "While the first enumeration is running, requests for the complete user or " "group lists may return no results until it completes." @@ -3925,7 +4010,7 @@ msgstr "" "или групп могут не вернуть результатов до момента завершения перечисления." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2634 +#: sssd.conf.5.xml:2680 msgid "" "Further, enabling enumeration may increase the time necessary to detect " "network disconnection, as longer timeouts are required to ensure that " @@ -3939,7 +4024,7 @@ msgstr "" "идентификаторов (id_provider)." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2642 +#: sssd.conf.5.xml:2688 msgid "" "For the reasons cited above, enabling enumeration is not recommended, " "especially in large environments." @@ -3948,7 +4033,7 @@ msgstr "" "средах большого размера." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2647 +#: sssd.conf.5.xml:2693 msgid "" "Note: the proxy provider is tested with open source modules like " "'libnss_files' and 'libnss_ldap'. 3rd party modules must follow the " @@ -3960,12 +4045,12 @@ msgstr "" "этой конфигурации." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2656 +#: sssd.conf.5.xml:2702 msgid "entry_cache_timeout (integer)" msgstr "entry_cache_timeout (целое число)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2659 +#: sssd.conf.5.xml:2705 msgid "" "How many seconds should nss_sss consider entries valid before asking the " "backend again" @@ -3974,7 +4059,7 @@ msgstr "" "действительными, прежде чем снова обратиться к внутреннему серверу" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2663 +#: sssd.conf.5.xml:2709 msgid "" "The cache expiration timestamps are stored as attributes of individual " "objects in the cache. Therefore, changing the cache timeout only has effect " @@ -3991,17 +4076,17 @@ msgstr "" "уже были кэшированы." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2676 +#: sssd.conf.5.xml:2722 msgid "Default: 5400" msgstr "По умолчанию: 5400" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2682 +#: sssd.conf.5.xml:2728 msgid "entry_cache_user_timeout (integer)" msgstr "entry_cache_user_timeout (целое число)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2685 +#: sssd.conf.5.xml:2731 msgid "" "How many seconds should nss_sss consider user entries valid before asking " "the backend again" @@ -4011,19 +4096,19 @@ msgstr "" "серверу" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2689 sssd.conf.5.xml:2702 sssd.conf.5.xml:2715 -#: sssd.conf.5.xml:2728 sssd.conf.5.xml:2742 sssd.conf.5.xml:2755 -#: sssd.conf.5.xml:2769 sssd.conf.5.xml:2783 sssd.conf.5.xml:2796 +#: sssd.conf.5.xml:2735 sssd.conf.5.xml:2748 sssd.conf.5.xml:2761 +#: sssd.conf.5.xml:2774 sssd.conf.5.xml:2788 sssd.conf.5.xml:2801 +#: sssd.conf.5.xml:2815 sssd.conf.5.xml:2829 msgid "Default: entry_cache_timeout" msgstr "По умолчанию: entry_cache_timeout" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2695 +#: sssd.conf.5.xml:2741 msgid "entry_cache_group_timeout (integer)" msgstr "entry_cache_group_timeout (целое число)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2698 +#: sssd.conf.5.xml:2744 msgid "" "How many seconds should nss_sss consider group entries valid before asking " "the backend again" @@ -4032,12 +4117,12 @@ msgstr "" "действительными, прежде чем снова обратиться к внутреннему серверу" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2708 +#: sssd.conf.5.xml:2754 msgid "entry_cache_netgroup_timeout (integer)" msgstr "entry_cache_netgroup_timeout (целое число)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2711 +#: sssd.conf.5.xml:2757 msgid "" "How many seconds should nss_sss consider netgroup entries valid before " "asking the backend again" @@ -4046,12 +4131,12 @@ msgstr "" "групп действительными, прежде чем снова обратиться к внутреннему серверу" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2721 +#: sssd.conf.5.xml:2767 msgid "entry_cache_service_timeout (integer)" msgstr "entry_cache_service_timeout (целое число)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2724 +#: sssd.conf.5.xml:2770 msgid "" "How many seconds should nss_sss consider service entries valid before asking " "the backend again" @@ -4060,12 +4145,12 @@ msgstr "" "действительными, прежде чем снова обратиться к внутреннему серверу" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2734 +#: sssd.conf.5.xml:2780 msgid "entry_cache_resolver_timeout (integer)" msgstr "entry_cache_resolver_timeout (целое число)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2737 +#: sssd.conf.5.xml:2783 msgid "" "How many seconds should nss_sss consider hosts and networks entries valid " "before asking the backend again" @@ -4074,12 +4159,12 @@ msgstr "" "сетей действительными, прежде чем снова обратиться к внутреннему серверу" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2748 +#: sssd.conf.5.xml:2794 msgid "entry_cache_sudo_timeout (integer)" msgstr "entry_cache_sudo_timeout (целое число)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2751 +#: sssd.conf.5.xml:2797 msgid "" "How many seconds should sudo consider rules valid before asking the backend " "again" @@ -4088,12 +4173,12 @@ msgstr "" "действительными, прежде чем снова обратиться к внутреннему серверу" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2761 +#: sssd.conf.5.xml:2807 msgid "entry_cache_autofs_timeout (integer)" msgstr "entry_cache_autofs_timeout (целое число)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2764 +#: sssd.conf.5.xml:2810 msgid "" "How many seconds should the autofs service consider automounter maps valid " "before asking the backend again" @@ -4103,12 +4188,12 @@ msgstr "" "внутреннему серверу" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2775 +#: sssd.conf.5.xml:2821 msgid "entry_cache_ssh_host_timeout (integer)" msgstr "entry_cache_ssh_host_timeout (целое число)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2778 +#: sssd.conf.5.xml:2824 msgid "" "How many seconds to keep a host ssh key after refresh. IE how long to cache " "the host key for." @@ -4118,26 +4203,161 @@ msgstr "" "узла в кэше." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2789 -msgid "entry_cache_computer_timeout (integer)" -msgstr "entry_cache_computer_timeout (целое число)" +#: sssd.conf.5.xml:2835 +msgid "offline_timeout (integer)" +msgstr "offline_timeout (целое число)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2792 +#: sssd.conf.5.xml:2838 msgid "" -"How many seconds to keep the local computer entry before asking the backend " -"again" +"When SSSD switches to offline mode the amount of time before it tries to go " +"back online will increase based upon the time spent disconnected. By " +"default SSSD uses incremental behaviour to calculate delay in between " +"retries. So, the wait time for a given retry will be longer than the wait " +"time for the previous ones. After each unsuccessful attempt to go online, " +"the new interval is recalculated by the following:" +msgstr "" +"Когда SSSD переключается в автономный режим, количество времени до " +"выполнения попытки вернуться в сеть будет увеличиваться в соответствии со " +"временем, проведённым без подключения. По умолчанию SSSD использует " +"приращение для расчёта задержки между повторными попытками. Поэтому время " +"ожидания для конкретной попытки будет больше, чем для предыдущих. После " +"каждой неудачной попытки вернуться в сеть интервал будет пересчитываться по " +"следующей формуле:" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2849 sssd.conf.5.xml:2907 +msgid "" +"new_delay = Minimum(old_delay * 2, offline_timeout_max) + " +"random[0...offline_timeout_random_offset]" +msgstr "" +"new_delay = Minimum(old_delay * 2, offline_timeout_max) + " +"random[0...offline_timeout_random_offset]" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2852 +msgid "" +"The offline_timeout default value is 60. The offline_timeout_max default " +"value is 3600. The offline_timeout_random_offset default value is 30. The " +"end result is the number of seconds before next retry." +msgstr "" +"Стандартное значение offline_timeout составляет 60. Стандартное значение " +"offline_timeout_max — 3600. Стандартное значение " +"offline_timeout_random_offset — 30. Конечный результат представляет собой " +"количество секунд до следующей попытки." + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2858 +msgid "" +"Note that the maximum length of each interval is defined by " +"offline_timeout_max (apart from the random part)." +msgstr "" +"Обратите внимание, что максимальная длительность каждого интервала задана " +"параметром offline_timeout_max (кроме случайной части)." + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2868 +msgid "offline_timeout_max (integer)" +msgstr "offline_timeout_max (целое число)" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2871 +msgid "" +"Controls by how much the time between attempts to go online can be " +"incremented following unsuccessful attempts to go online." +msgstr "" +"Управляет тем, насколько можно увеличить время между попытками вернуться в " +"сеть после неудачных попыток восстановления подключения." + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2876 +msgid "A value of 0 disables the incrementing behaviour." +msgstr "Значение «0» отключает использование приращения." + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2879 +msgid "" +"The value of this parameter should be set in correlation to offline_timeout " +"parameter value." +msgstr "" +"Значение этого параметра следует устанавливать с учётом значения параметра " +"offline_timeout." + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2883 +msgid "" +"With offline_timeout set to 60 (default value) there is no point in setting " +"offline_timeout_max to less than 120 as it will saturate instantly. General " +"rule here should be to set offline_timeout_max to at least 4 times " +"offline_timeout." +msgstr "" +"Если параметр offline_timeout установлен в значение «60» (значение по " +"умолчанию), нет смысла указывать для параметра offline_timeout_max значение " +"меньше 120, поскольку первый же шаг увеличения приведёт к его превышению. " +"Общее правило таково: значение offline_timeout_max должно по крайней мере в " +"4 раза превышать значение offline_timeout." + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2889 +msgid "" +"Although a value between 0 and offline_timeout may be specified, it has the " +"effect of overriding the offline_timeout value so is of little use." +msgstr "" +"Несмотря на то, что возможно указать значение от 0 до offline_timeout, " +"результатом этого станет переопределение значения offline_timeout, что не " +"имеет практического смысла." + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2894 +msgid "Default: 3600" +msgstr "По умолчанию: 3600" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2900 +msgid "offline_timeout_random_offset (integer)" +msgstr "offline_timeout_random_offset (целое число)" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2903 +msgid "" +"When SSSD is in offline mode it keeps probing backend servers in specified " +"time intervals:" +msgstr "" +"Когда сервис SSSD находится в автономном режиме, он продолжает обращаться к " +"внутренним серверам через заданные промежутки времени:" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2910 +msgid "" +"This parameter controls the value of the random offset used for the above " +"equation. Final random_offset value will be random number in range:" msgstr "" -"Количество секунд, в течение которого следует хранить запись локального " -"компьютера, прежде чем снова обратиться к внутреннему серверу" +"Этот параметр управляет значением случайной задержки, которое используется " +"для приведённого выше уравнения. Итоговым значением random_offset будет " +"случайное число, принадлежащее диапазону:" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2915 +msgid "[0 - offline_timeout_random_offset]" +msgstr "[0 - offline_timeout_random_offset]" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2918 +msgid "A value of 0 disables the random offset addition." +msgstr "Значение «0» отключает добавление случайной задержки." + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2921 +msgid "Default: 30" +msgstr "По умолчанию: 30" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2802 +#: sssd.conf.5.xml:2927 msgid "refresh_expired_interval (integer)" msgstr "refresh_expired_interval (целое число)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2805 +#: sssd.conf.5.xml:2930 msgid "" "Specifies how many seconds SSSD has to wait before triggering a background " "refresh task which will refresh all expired or nearly expired records." @@ -4146,7 +4366,7 @@ msgstr "" "обновления всех устаревших или почти устаревших записей." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2810 +#: sssd.conf.5.xml:2935 msgid "" "The background refresh will process users, groups and netgroups in the " "cache. For users who have performed the initgroups (get group membership for " @@ -4160,17 +4380,17 @@ msgstr "" "пользователя в группах, обычно выполняется при запуске)." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2818 +#: sssd.conf.5.xml:2943 msgid "This option is automatically inherited for all trusted domains." msgstr "Этот параметр автоматически наследуется для всех доверенных доменов." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2822 +#: sssd.conf.5.xml:2947 msgid "You can consider setting this value to 3/4 * entry_cache_timeout." msgstr "Рекомендуется установить это значение равным 3/4 * entry_cache_timeout." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2826 +#: sssd.conf.5.xml:2951 msgid "" "Cache entry will be refreshed by background task when 2/3 of cache timeout " "has already passed. If there are existing cached entries, the background " @@ -4191,18 +4411,18 @@ msgstr "" "существующего кэша." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2839 sssd-ldap.5.xml:406 sssd-ldap.5.xml:1834 -#: sssd-ipa.5.xml:255 +#: sssd.conf.5.xml:2964 sssd-ldap.5.xml:406 sssd-ldap.5.xml:1834 +#: sssd-ipa.5.xml:250 msgid "Default: 0 (disabled)" msgstr "По умолчанию: 0 (отключено)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2845 -msgid "cache_credentials (bool)" +#: sssd.conf.5.xml:2970 +msgid "cache_credentials (boolean)" msgstr "cache_credentials (логическое значение)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2848 +#: sssd.conf.5.xml:2973 msgid "" "Determines if user credentials are also cached in the local LDB cache. The " "cached credentials refer to passwords, which includes the first (long term) " @@ -4219,7 +4439,7 @@ msgstr "" "аутентификация записывается в кэш без дополнительной настройки." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2859 +#: sssd.conf.5.xml:2984 msgid "" "Take a note that while credentials are stored as a salted SHA512 hash, this " "still potentially poses some security risk in case an attacker manages to " @@ -4233,12 +4453,12 @@ msgstr "" "пароль с помощью атаки грубой силы." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2873 +#: sssd.conf.5.xml:2998 msgid "cache_credentials_minimal_first_factor_length (int)" msgstr "cache_credentials_minimal_first_factor_length (целое число)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2876 +#: sssd.conf.5.xml:3001 msgid "" "If 2-Factor-Authentication (2FA) is used and credentials should be saved " "this value determines the minimal length the first authentication factor " @@ -4250,7 +4470,7 @@ msgstr "" "сохранён в формате контрольной суммы SHA512 в кэше." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2883 +#: sssd.conf.5.xml:3008 msgid "" "This should avoid that the short PINs of a PIN based 2FA scheme are saved in " "the cache which would make them easy targets for brute-force attacks." @@ -4260,12 +4480,12 @@ msgstr "" "мишенью для атак методом подбора." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2894 +#: sssd.conf.5.xml:3019 msgid "account_cache_expiration (integer)" msgstr "account_cache_expiration (целое число)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2897 +#: sssd.conf.5.xml:3022 msgid "" "Number of days entries are left in cache after last successful login before " "being removed during a cleanup of the cache. 0 means keep forever. The " @@ -4278,17 +4498,17 @@ msgstr "" "быть больше или равно значению offline_credentials_expiration." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2904 +#: sssd.conf.5.xml:3029 msgid "Default: 0 (unlimited)" msgstr "По умолчанию: 0 (без ограничений)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2909 +#: sssd.conf.5.xml:3034 msgid "pwd_expiration_warning (integer)" msgstr "pwd_expiration_warning (целое число)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2920 +#: sssd.conf.5.xml:3045 msgid "" "Please note that the backend server has to provide information about the " "expiration time of the password. If this information is missing, sssd " @@ -4301,17 +4521,17 @@ msgstr "" "настроить поставщика данных проверки подлинности." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2927 +#: sssd.conf.5.xml:3052 msgid "Default: 7 (Kerberos), 0 (LDAP)" msgstr "По умолчанию: 7 (Kerberos), 0 (LDAP)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2933 +#: sssd.conf.5.xml:3058 msgid "id_provider (string)" msgstr "id_provider (строка)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2936 +#: sssd.conf.5.xml:3061 msgid "" "The identification provider used for the domain. Supported ID providers are:" msgstr "" @@ -4319,12 +4539,12 @@ msgstr "" "Поддерживаемые поставщики ID:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2940 +#: sssd.conf.5.xml:3065 msgid "<quote>proxy</quote>: Support a legacy NSS provider." msgstr "<quote>proxy</quote>: поддержка устаревшего поставщика NSS." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2943 +#: sssd.conf.5.xml:3068 msgid "" "<quote>ldap</quote>: LDAP provider. See <citerefentry> <refentrytitle>sssd-" "ldap</refentrytitle> <manvolnum>5</manvolnum> </citerefentry> for more " @@ -4335,8 +4555,8 @@ msgstr "" "<manvolnum>5</manvolnum> </citerefentry>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2951 sssd.conf.5.xml:3070 sssd.conf.5.xml:3129 -#: sssd.conf.5.xml:3192 +#: sssd.conf.5.xml:3076 sssd.conf.5.xml:3200 sssd.conf.5.xml:3259 +#: sssd.conf.5.xml:3322 msgid "" "<quote>ipa</quote>: FreeIPA and Red Hat Identity Management provider. See " "<citerefentry> <refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</" @@ -4347,8 +4567,8 @@ msgstr "" "sssd-ipa</refentrytitle> <manvolnum>5</manvolnum> </citerefentry>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2960 sssd.conf.5.xml:3079 sssd.conf.5.xml:3138 -#: sssd.conf.5.xml:3201 +#: sssd.conf.5.xml:3085 sssd.conf.5.xml:3209 sssd.conf.5.xml:3268 +#: sssd.conf.5.xml:3331 msgid "" "<quote>ad</quote>: Active Directory provider. See <citerefentry> " "<refentrytitle>sssd-ad</refentrytitle> <manvolnum>5</manvolnum> </" @@ -4359,7 +4579,7 @@ msgstr "" "ad</refentrytitle> <manvolnum>5</manvolnum> </citerefentry>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2968 +#: sssd.conf.5.xml:3093 msgid "" "<quote>idp</quote>: Provider for OAuth 2.0/OIDC based Identity Providers " "(IdP). See <citerefentry> <refentrytitle>sssd-idp</refentrytitle> " @@ -4370,13 +4590,22 @@ msgstr "" "<refentrytitle>sssd-idp</refentrytitle> <manvolnum>5</manvolnum> </" "citerefentry>." +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3101 +msgid "" +"Default: Not set (This is a mandatory setting that must be explicitly " +"defined for each configured domain)." +msgstr "" +"По умолчанию: не задано (это обязательный параметр, который должен быть явно " +"определён для каждого настроенного домена)." + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2979 -msgid "use_fully_qualified_names (bool)" +#: sssd.conf.5.xml:3109 +msgid "use_fully_qualified_names (boolean)" msgstr "use_fully_qualified_names (логическое значение)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2982 +#: sssd.conf.5.xml:3112 msgid "" "Use the full name and domain (as formatted by the domain's full_name_format) " "as the user's login name reported to NSS." @@ -4385,7 +4614,7 @@ msgstr "" "домена) в качестве имени для входа пользователя, которое сообщается NSS." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2987 +#: sssd.conf.5.xml:3117 msgid "" "If set to TRUE, all requests to this domain must use fully qualified names. " "For example, if used in EXAMPLE domain that contains a \"test\" user, " @@ -4399,7 +4628,7 @@ msgstr "" "passwd test@EXAMPLE</command> получится это сделать." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2995 +#: sssd.conf.5.xml:3125 msgid "" "NOTE: This option has no effect on netgroup lookups due to their tendency to " "include nested netgroups without qualified names. For netgroups, all domains " @@ -4410,7 +4639,7 @@ msgstr "" "групп выполняется поиск во всех доменах, когда запрашивается неполное имя." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3002 +#: sssd.conf.5.xml:3132 msgid "" "Default: FALSE (TRUE for trusted domain/sub-domains or if " "default_domain_suffix is used)" @@ -4419,17 +4648,17 @@ msgstr "" "использования default_domain_suffix)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3009 -msgid "ignore_group_members (bool)" +#: sssd.conf.5.xml:3139 +msgid "ignore_group_members (boolean)" msgstr "ignore_group_members (логическое значение)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3012 +#: sssd.conf.5.xml:3142 msgid "Do not return group members for group lookups." msgstr "Не возвращать участников групп для поиска групп." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3015 +#: sssd.conf.5.xml:3145 msgid "" "If set to TRUE, the group membership attribute is not requested from the " "ldap server, and group members are not returned when processing group lookup " @@ -4448,7 +4677,7 @@ msgstr "" "запрошенную группу так, как будто она пуста." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3033 +#: sssd.conf.5.xml:3163 msgid "" "Enabling this option can also make access provider checks for group " "membership significantly faster, especially for groups containing many " @@ -4459,7 +4688,7 @@ msgstr "" "количество участников)." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3039 sssd.conf.5.xml:3767 sssd-ldap.5.xml:401 +#: sssd.conf.5.xml:3169 sssd.conf.5.xml:3951 sssd-ldap.5.xml:401 #: sssd-ldap.5.xml:454 sssd-ldap.5.xml:529 sssd-ldap.5.xml:576 #: sssd-ldap.5.xml:599 sssd-ldap.5.xml:638 sssd-ldap.5.xml:657 #: sssd-ldap.5.xml:681 sssd-ldap.5.xml:1114 sssd-ldap.5.xml:1147 @@ -4471,12 +4700,12 @@ msgstr "" "унаследован с помощью <emphasis>subdomain_inherit</emphasis>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3049 +#: sssd.conf.5.xml:3179 msgid "auth_provider (string)" msgstr "auth_provider (строка)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3052 +#: sssd.conf.5.xml:3182 msgid "" "The authentication provider used for the domain. Supported auth providers " "are:" @@ -4485,7 +4714,7 @@ msgstr "" "Поддерживаемые поставщики данных для проверки подлинности:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3056 sssd.conf.5.xml:3122 +#: sssd.conf.5.xml:3186 sssd.conf.5.xml:3252 msgid "" "<quote>ldap</quote> for native LDAP authentication. See <citerefentry> " "<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> </" @@ -4496,7 +4725,7 @@ msgstr "" "ldap</refentrytitle> <manvolnum>5</manvolnum> </citerefentry>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3063 +#: sssd.conf.5.xml:3193 msgid "" "<quote>krb5</quote> for Kerberos authentication. See <citerefentry> " "<refentrytitle>sssd-krb5</refentrytitle> <manvolnum>5</manvolnum> </" @@ -4507,7 +4736,7 @@ msgstr "" "sssd-krb5</refentrytitle> <manvolnum>5</manvolnum> </citerefentry>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3087 +#: sssd.conf.5.xml:3217 msgid "" "<quote>idp</quote>: Provider for OAuth 2.0/OIDC based authentication. See " "<citerefentry> <refentrytitle>sssd-idp</refentrytitle> <manvolnum>5</" @@ -4518,7 +4747,7 @@ msgstr "" "refentrytitle> <manvolnum>5</manvolnum> </citerefentry>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3095 +#: sssd.conf.5.xml:3225 msgid "" "<quote>proxy</quote> for relaying authentication to some other PAM target." msgstr "" @@ -4526,12 +4755,12 @@ msgstr "" "PAM." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3098 +#: sssd.conf.5.xml:3228 msgid "<quote>none</quote> disables authentication explicitly." msgstr "<quote>none</quote> — явно отключить проверку подлинности." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3101 +#: sssd.conf.5.xml:3231 msgid "" "Default: <quote>id_provider</quote> is used if it is set and can handle " "authentication requests." @@ -4540,12 +4769,12 @@ msgstr "" "задан и поддерживает обработку запросов проверки подлинности." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3107 +#: sssd.conf.5.xml:3237 msgid "access_provider (string)" msgstr "access_provider (строка)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3110 +#: sssd.conf.5.xml:3240 msgid "" "The access control provider used for the domain. There are two built-in " "access providers (in addition to any included in installed backends) " @@ -4556,17 +4785,17 @@ msgstr "" "включены в установленные внутренние серверы). Внутренние особые поставщики:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3116 +#: sssd.conf.5.xml:3246 msgid "<quote>permit</quote> always allow access." msgstr "<quote>permit</quote> — всегда разрешать доступ." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3119 +#: sssd.conf.5.xml:3249 msgid "<quote>deny</quote> always deny access." msgstr "<quote>deny</quote> — всегда отказывать в доступе." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3146 +#: sssd.conf.5.xml:3276 msgid "" "<quote>simple</quote> access control based on access or deny lists. See " "<citerefentry> <refentrytitle>sssd-simple</refentrytitle> <manvolnum>5</" @@ -4579,7 +4808,7 @@ msgstr "" "5</manvolnum></citerefentry>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3153 +#: sssd.conf.5.xml:3283 msgid "" "<quote>krb5</quote>: .k5login based access control. See <citerefentry> " "<refentrytitle>sssd-krb5</refentrytitle> <manvolnum>5</manvolnum></" @@ -4590,22 +4819,22 @@ msgstr "" "refentrytitle> <manvolnum>5</manvolnum> </citerefentry>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3160 +#: sssd.conf.5.xml:3290 msgid "<quote>proxy</quote> for relaying access control to another PAM module." msgstr "<quote>proxy</quote> — передать управление доступом другому модулю PAM." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3163 +#: sssd.conf.5.xml:3293 msgid "Default: <quote>permit</quote>" msgstr "По умолчанию: <quote>permit</quote>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3168 +#: sssd.conf.5.xml:3298 msgid "chpass_provider (string)" msgstr "chpass_provider (строка)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3171 +#: sssd.conf.5.xml:3301 msgid "" "The provider which should handle change password operations for the domain. " "Supported change password providers are:" @@ -4614,7 +4843,7 @@ msgstr "" "домена. Поддерживаемые поставщики данных смены пароля:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3176 +#: sssd.conf.5.xml:3306 msgid "" "<quote>ldap</quote> to change a password stored in a LDAP server. See " "<citerefentry> <refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</" @@ -4625,7 +4854,7 @@ msgstr "" "ldap</refentrytitle> <manvolnum>5</manvolnum> </citerefentry>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3184 +#: sssd.conf.5.xml:3314 msgid "" "<quote>krb5</quote> to change the Kerberos password. See <citerefentry> " "<refentrytitle>sssd-krb5</refentrytitle> <manvolnum>5</manvolnum> </" @@ -4636,19 +4865,19 @@ msgstr "" "<manvolnum>5</manvolnum> </citerefentry>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3209 +#: sssd.conf.5.xml:3339 msgid "" "<quote>proxy</quote> for relaying password changes to some other PAM target." msgstr "" "<quote>proxy</quote> — передать смену пароля какой-либо другой цели PAM." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3213 +#: sssd.conf.5.xml:3343 msgid "<quote>none</quote> disallows password changes explicitly." msgstr "<quote>none</quote> — явно запретить смену пароля." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3216 +#: sssd.conf.5.xml:3346 msgid "" "Default: <quote>auth_provider</quote> is used if it is set and can handle " "change password requests." @@ -4657,19 +4886,19 @@ msgstr "" "задан и поддерживает обработку запросов смены пароля." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3223 +#: sssd.conf.5.xml:3353 msgid "sudo_provider (string)" msgstr "sudo_provider (строка)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3226 +#: sssd.conf.5.xml:3356 msgid "The SUDO provider used for the domain. Supported SUDO providers are:" msgstr "" "Поставщик данных SUDO, который используется для домена. Поддерживаемые " "поставщики данных SUDO:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3230 +#: sssd.conf.5.xml:3360 msgid "" "<quote>ldap</quote> for rules stored in LDAP. See <citerefentry> " "<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> </" @@ -4680,7 +4909,7 @@ msgstr "" "refentrytitle> <manvolnum>5</manvolnum> </citerefentry>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3238 +#: sssd.conf.5.xml:3368 msgid "" "<quote>ipa</quote> the same as <quote>ldap</quote> but with IPA default " "settings." @@ -4689,7 +4918,7 @@ msgstr "" "параметрами IPA." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3242 +#: sssd.conf.5.xml:3372 msgid "" "<quote>ad</quote> the same as <quote>ldap</quote> but with AD default " "settings." @@ -4698,12 +4927,12 @@ msgstr "" "параметрами AD." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3246 +#: sssd.conf.5.xml:3376 msgid "<quote>none</quote> disables SUDO explicitly." msgstr "<quote>none</quote> — явно отключить SUDO." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3249 +#: sssd.conf.5.xml:3379 msgid "" "Default: The value of <quote>id_provider</quote> is used if it is set and " "can handle sudo requests." @@ -4712,7 +4941,7 @@ msgstr "" "установлен и может обрабатывать запросы sudo." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3253 +#: sssd.conf.5.xml:3383 msgid "" "The detailed instructions for configuration of sudo_provider are in the " "manual page <citerefentry> <refentrytitle>sssd-sudo</refentrytitle> " @@ -4729,7 +4958,7 @@ msgstr "" "refentrytitle> <manvolnum>5</manvolnum> </citerefentry>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3268 +#: sssd.conf.5.xml:3398 msgid "" "<emphasis>NOTE:</emphasis> Sudo rules are periodically downloaded in the " "background unless the sudo provider is explicitly disabled. Set " @@ -4743,12 +4972,12 @@ msgstr "" "планируется использовать sudo." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3278 +#: sssd.conf.5.xml:3408 msgid "selinux_provider (string)" msgstr "selinux_provider (строка)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3281 +#: sssd.conf.5.xml:3411 msgid "" "The provider which should handle loading of selinux settings. Note that this " "provider will be called right after access provider ends. Supported selinux " @@ -4759,7 +4988,7 @@ msgstr "" "работы поставщика доступа. Поддерживаемые поставщики данных SELinux:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3287 +#: sssd.conf.5.xml:3417 msgid "" "<quote>ipa</quote> to load selinux settings from an IPA server. See " "<citerefentry> <refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</" @@ -4770,26 +4999,29 @@ msgstr "" "ipa</refentrytitle> <manvolnum>5</manvolnum> </citerefentry>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3295 +#: sssd.conf.5.xml:3425 msgid "<quote>none</quote> disallows fetching selinux settings explicitly." msgstr "<quote>none</quote> — явно отключает получение параметров SELinux." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3298 +#: sssd.conf.5.xml:3428 msgid "" -"Default: <quote>id_provider</quote> is used if it is set and can handle " -"selinux loading requests." +"Default: the value of <quote>id_provider</quote> is used if it is set and " +"can handle selinux loading requests. Otherwise the result is the same as if " +"the selinux_provider is set to none." msgstr "" -"По умолчанию: использовать <quote>id_provider</quote>, если этот параметр " -"задан и поддерживает обработку запросов загрузки параметров SELinux." +"По умолчанию: используется значение <quote>id_provider</quote>, если оно " +"задано и может обрабатывать запросы загрузки selinux. В противном случае " +"результат такой же, как если бы для selinux_provider было задано значение " +"none." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3304 +#: sssd.conf.5.xml:3435 msgid "subdomains_provider (string)" msgstr "subdomains_provider (строка)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3307 +#: sssd.conf.5.xml:3438 msgid "" "The provider which should handle fetching of subdomains. This value should " "be always the same as id_provider. Supported subdomain providers are:" @@ -4799,7 +5031,7 @@ msgstr "" "Поддерживаемые поставщики данных поддоменов:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3313 +#: sssd.conf.5.xml:3444 msgid "" "<quote>ipa</quote> to load a list of subdomains from an IPA server. See " "<citerefentry> <refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</" @@ -4810,7 +5042,7 @@ msgstr "" "ipa</refentrytitle> <manvolnum>5</manvolnum> </citerefentry>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3322 +#: sssd.conf.5.xml:3453 msgid "" "<quote>ad</quote> to load a list of subdomains from an Active Directory " "server. See <citerefentry> <refentrytitle>sssd-ad</refentrytitle> " @@ -4823,12 +5055,12 @@ msgstr "" "citerefentry>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3331 +#: sssd.conf.5.xml:3462 msgid "<quote>none</quote> disallows fetching subdomains explicitly." msgstr "<quote>none</quote> — явно отключает получение данных поддоменов." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3335 +#: sssd.conf.5.xml:3466 msgid "" "Default: The value of <quote>id_provider</quote> is used if it is set and " "can handle subdomain requests." @@ -4837,12 +5069,12 @@ msgstr "" "установлен и может обрабатывать запросы поддоменов." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3341 +#: sssd.conf.5.xml:3472 msgid "session_provider (string)" msgstr "session_provider (строка)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3344 +#: sssd.conf.5.xml:3475 msgid "" "The provider which configures and manages user session related tasks. The " "only user session task currently provided is the integration with Fleet " @@ -4854,14 +5086,14 @@ msgstr "" "Commander (работает только c IPA). Поддерживаемые поставщики данных сеансов:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3351 +#: sssd.conf.5.xml:3482 msgid "<quote>ipa</quote> to allow performing user session related tasks." msgstr "" "<quote>ipa</quote> — разрешить выполнение заданий, связанных с сеансами " "пользователей." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3355 +#: sssd.conf.5.xml:3486 msgid "" "<quote>none</quote> does not perform any kind of user session related tasks." msgstr "" @@ -4869,17 +5101,17 @@ msgstr "" "пользователей." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3359 +#: sssd.conf.5.xml:3490 msgid "Default: <quote>none</quote>." msgstr "По умолчанию: <quote>none</quote>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3365 +#: sssd.conf.5.xml:3496 msgid "autofs_provider (string)" msgstr "autofs_provider (строка)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3368 +#: sssd.conf.5.xml:3499 msgid "" "The autofs provider used for the domain. Supported autofs providers are:" msgstr "" @@ -4887,7 +5119,7 @@ msgstr "" "поставщики данных autofs:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3372 +#: sssd.conf.5.xml:3503 msgid "" "<quote>ldap</quote> to load maps stored in LDAP. See <citerefentry> " "<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> </" @@ -4898,7 +5130,7 @@ msgstr "" "ldap</refentrytitle> <manvolnum>5</manvolnum> </citerefentry>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3379 +#: sssd.conf.5.xml:3510 msgid "" "<quote>ipa</quote> to load maps stored in an IPA server. See <citerefentry> " "<refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</manvolnum> </" @@ -4909,7 +5141,7 @@ msgstr "" "ipa</refentrytitle> <manvolnum>5</manvolnum> </citerefentry>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3387 +#: sssd.conf.5.xml:3518 msgid "" "<quote>ad</quote> to load maps stored in an AD server. See <citerefentry> " "<refentrytitle>sssd-ad</refentrytitle> <manvolnum>5</manvolnum> </" @@ -4921,12 +5153,12 @@ msgstr "" "citerefentry>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3396 +#: sssd.conf.5.xml:3527 msgid "<quote>none</quote> disables autofs explicitly." msgstr "<quote>none</quote> — явно отключить autofs." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3399 +#: sssd.conf.5.xml:3530 msgid "" "Default: The value of <quote>id_provider</quote> is used if it is set and " "can handle autofs requests." @@ -4935,12 +5167,12 @@ msgstr "" "установлен и может обрабатывать запросы autofs." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3406 +#: sssd.conf.5.xml:3537 msgid "hostid_provider (string)" msgstr "hostid_provider (строка)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3409 +#: sssd.conf.5.xml:3540 msgid "" "The provider used for retrieving host identity information. Supported " "hostid providers are:" @@ -4949,7 +5181,7 @@ msgstr "" "узла. Поддерживаемые поставщики hostid:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3413 +#: sssd.conf.5.xml:3544 msgid "" "<quote>ipa</quote> to load host identity stored in an IPA server. See " "<citerefentry> <refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</" @@ -4961,12 +5193,12 @@ msgstr "" "citerefentry>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3421 +#: sssd.conf.5.xml:3552 msgid "<quote>none</quote> disables hostid explicitly." msgstr "<quote>none</quote> — явно отключить hostid." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3424 +#: sssd.conf.5.xml:3555 msgid "" "Default: The value of <quote>id_provider</quote> is used if it is set and " "can handle hostid requests." @@ -4975,12 +5207,12 @@ msgstr "" "установлен и может обрабатывать запросы hostid." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3431 +#: sssd.conf.5.xml:3562 msgid "resolver_provider (string)" msgstr "resolver_provider (строка)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3434 +#: sssd.conf.5.xml:3565 msgid "" "The provider which should handle hosts and networks lookups. Supported " "resolver providers are:" @@ -4989,7 +5221,7 @@ msgstr "" "Поддерживаемые поставщики данных сопоставления:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3438 +#: sssd.conf.5.xml:3569 msgid "" "<quote>proxy</quote> to forward lookups to another NSS library. See " "<quote>proxy_resolver_lib_name</quote>" @@ -4998,7 +5230,7 @@ msgstr "" "NSS. См. <quote>proxy_resolver_lib_name</quote>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3442 +#: sssd.conf.5.xml:3573 msgid "" "<quote>ldap</quote> to fetch hosts and networks stored in LDAP. See " "<citerefentry> <refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</" @@ -5010,7 +5242,7 @@ msgstr "" "citerefentry>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3449 +#: sssd.conf.5.xml:3580 msgid "" "<quote>ad</quote> to fetch hosts and networks stored in AD. See " "<citerefentry> <refentrytitle>sssd-ad</refentrytitle> <manvolnum>5</" @@ -5023,12 +5255,12 @@ msgstr "" "manvolnum> </citerefentry>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3457 +#: sssd.conf.5.xml:3588 msgid "<quote>none</quote> disallows fetching hosts and networks explicitly." msgstr "<quote>none</quote> — явно отключает получение записей узлов и сетей." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3460 +#: sssd.conf.5.xml:3591 msgid "" "Default: The value of <quote>id_provider</quote> is used if it is set and " "can handle resolver requests." @@ -5037,7 +5269,7 @@ msgstr "" "установлен и может обрабатывать запросы резолвера." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3470 +#: sssd.conf.5.xml:3601 msgid "" "Regular expression for this domain that describes how to parse the string " "containing user name and domain into these components. The \"domain\" can " @@ -5052,7 +5284,7 @@ msgstr "" "домена." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3479 +#: sssd.conf.5.xml:3610 msgid "" "Default: <quote>^((?P<name>.+)@(?P<domain>[^@]*)|(?P<name>" "[^@]+))$</quote> which allows two different styles for user names:" @@ -5062,17 +5294,17 @@ msgstr "" "записи имён пользователей:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:3484 sssd.conf.5.xml:3498 +#: sssd.conf.5.xml:3615 sssd.conf.5.xml:3629 msgid "username" msgstr "username" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:3487 sssd.conf.5.xml:3501 +#: sssd.conf.5.xml:3618 sssd.conf.5.xml:3632 msgid "username@domain.name" msgstr "username@domain.name" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3492 +#: sssd.conf.5.xml:3623 msgid "" "Default for the AD and IPA provider: <quote>^(((?P<domain>[^\\\\]+)\\\\" "(?P<name>.+))|((?P<name>.+)@(?P<domain>[^@]+))|((?" @@ -5085,12 +5317,12 @@ msgstr "" "позволяет назначать три разных стиля записи имён пользователей:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:3504 +#: sssd.conf.5.xml:3635 msgid "domain\\username" msgstr "domain\\username" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3507 +#: sssd.conf.5.xml:3638 msgid "" "While the first two correspond to the general default the third one is " "introduced to allow easy integration of users from Windows domains." @@ -5099,7 +5331,7 @@ msgstr "" "обеспечения простой интеграции пользователей из доменов Windows." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3512 +#: sssd.conf.5.xml:3643 msgid "" "The default re_expression uses the <quote>@</quote> character as a separator " "between the name and the domain. As a result of this setting the default " @@ -5115,17 +5347,17 @@ msgstr "" "создать собственное re_expression." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3564 +#: sssd.conf.5.xml:3695 msgid "Default: <quote>%1$s@%2$s</quote>." msgstr "По умолчанию: <quote>%1$s@%2$s</quote>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3570 +#: sssd.conf.5.xml:3701 msgid "lookup_family_order (string)" msgstr "lookup_family_order (строка)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3573 +#: sssd.conf.5.xml:3704 msgid "" "Provides the ability to select preferred address family to use when " "performing DNS lookups." @@ -5134,56 +5366,55 @@ msgstr "" "следует использовать при выполнении запросов DNS." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3577 +#: sssd.conf.5.xml:3708 msgid "Supported values:" msgstr "Поддерживаемые значения:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3580 +#: sssd.conf.5.xml:3711 msgid "ipv4_first: Try looking up IPv4 address, if that fails, try IPv6" msgstr "" "ipv4_first: попытаться найти адрес IPv4, в случае неудачи попытаться найти " "адрес IPv6" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3583 +#: sssd.conf.5.xml:3714 msgid "ipv4_only: Only attempt to resolve hostnames to IPv4 addresses." msgstr "ipv4_only: пытаться разрешать имена узлов только в адреса IPv4." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3586 +#: sssd.conf.5.xml:3717 msgid "ipv6_first: Try looking up IPv6 address, if that fails, try IPv4" msgstr "" "ipv6_first: попытаться найти адрес IPv6, в случае неудачи попытаться найти " "адрес IPv4" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3589 +#: sssd.conf.5.xml:3720 msgid "ipv6_only: Only attempt to resolve hostnames to IPv6 addresses." msgstr "ipv6_only: пытаться разрешать имена узлов только в адреса IPv6." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3592 +#: sssd.conf.5.xml:3723 msgid "Default: ipv4_first" msgstr "По умолчанию: ipv4_first" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3598 +#: sssd.conf.5.xml:3729 msgid "dns_resolver_server_timeout (integer)" msgstr "dns_resolver_server_timeout (целое число)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3601 +#: sssd.conf.5.xml:3732 msgid "" -"Defines the amount of time (in milliseconds) SSSD would try to talk to DNS " -"server before trying next DNS server." +"Defines the timeout duration (in milliseconds) SSSD waits for a DNS server " +"to respond before moving to the next one." msgstr "" -"Определяет количество времени (в миллисекундах), в течение которого SSSD " -"будет пытаться обменяться данными с сервером DNS перед переходом к " -"следующему." +"Определяет длительность тайм-аута (в миллисекундах), в течение которого SSSD " +"ожидает ответа от сервера DNS, прежде чем перейти к следующему." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3606 +#: sssd.conf.5.xml:3737 msgid "" "The AD provider will use this option for the CLDAP ping timeouts as well." msgstr "" @@ -5191,26 +5422,36 @@ msgstr "" "времени проверки связи CLDAP." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3610 sssd.conf.5.xml:3630 sssd.conf.5.xml:3651 +#: sssd.conf.5.xml:3741 sssd.conf.5.xml:3777 sssd.conf.5.xml:3814 msgid "" -"Please see the section <quote>FAILOVER</quote> for more information about " -"the service resolution." +"Please see the section <quote>FAILOVER</quote> in <citerefentry> " +"<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> </" +"citerefentry>, <citerefentry> <refentrytitle>sssd-krb5</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry>, <citerefentry> <refentrytitle>sssd-" +"ipa</refentrytitle> <manvolnum>5</manvolnum> </citerefentry> or " +"<citerefentry> <refentrytitle>sssd-ad</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry> for more information about the service resolution." msgstr "" -"Более подробные сведения о разрешении служб доступны в разделе <quote>" -"ОБРАБОТКА ОТКАЗА</quote>." +"Дополнительную информацию о разрешении служб см. в разделе <quote>FAILOVER</" +"quote> справочных страниц <citerefentry> <refentrytitle>sssd-ldap</" +"refentrytitle> <manvolnum>5</manvolnum> </citerefentry>, <citerefentry> " +"<refentrytitle>sssd-krb5</refentrytitle> <manvolnum>5</manvolnum> </" +"citerefentry>, <citerefentry> <refentrytitle>sssd-ipa</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry> или <citerefentry> <refentrytitle>" +"sssd-ad</refentrytitle> <manvolnum>5</manvolnum> </citerefentry>." #. type: Content of: <refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3615 sssd-ldap.5.xml:700 include/failover.xml:84 +#: sssd.conf.5.xml:3762 sssd-ldap.5.xml:700 include/failover.xml:84 msgid "Default: 1000" msgstr "По умолчанию: 1000" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3621 +#: sssd.conf.5.xml:3768 msgid "dns_resolver_op_timeout (integer)" msgstr "dns_resolver_op_timeout (целое число)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3624 +#: sssd.conf.5.xml:3771 msgid "" "Defines the amount of time (in seconds) to wait to resolve single DNS query " "(e.g. resolution of a hostname or an SRV record) before trying the next " @@ -5222,17 +5463,17 @@ msgstr "" "следующего DNS." #. type: Content of: <refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3635 include/failover.xml:100 +#: sssd.conf.5.xml:3798 include/failover.xml:100 msgid "Default: 3" msgstr "По умолчанию: 3" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3641 +#: sssd.conf.5.xml:3804 msgid "dns_resolver_timeout (integer)" msgstr "dns_resolver_timeout (целое число)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3644 +#: sssd.conf.5.xml:3807 msgid "" "Defines the amount of time (in seconds) to wait for a reply from the " "internal fail over service before assuming that the service is unreachable. " @@ -5245,12 +5486,12 @@ msgstr "" "работу в автономном режиме." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3662 -msgid "dns_resolver_use_search_list (bool)" +#: sssd.conf.5.xml:3841 +msgid "dns_resolver_use_search_list (boolean)" msgstr "dns_resolver_use_search_list (логическое значение)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3665 +#: sssd.conf.5.xml:3844 msgid "" "Normally, the DNS resolver searches the domain list defined in the " "\"search\" directive from the resolv.conf file. This can lead to delays in " @@ -5261,7 +5502,7 @@ msgstr "" "средах с неправильно настроенным DNS." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3671 +#: sssd.conf.5.xml:3850 msgid "" "If fully qualified domain names (or _srv_) are used in the SSSD " "configuration, setting this option to FALSE can prevent unnecessary DNS " @@ -5272,17 +5513,17 @@ msgstr "" "запросы DNS в таких средах." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3677 +#: sssd.conf.5.xml:3856 msgid "Default: TRUE" msgstr "По умолчанию: TRUE" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3683 +#: sssd.conf.5.xml:3862 msgid "dns_discovery_domain (string)" msgstr "dns_discovery_domain (строка)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3686 +#: sssd.conf.5.xml:3865 msgid "" "If service discovery is used in the back end, specifies the domain part of " "the service discovery DNS query." @@ -5291,17 +5532,17 @@ msgstr "" "доменную часть запроса обнаружения служб DNS." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3690 +#: sssd.conf.5.xml:3869 msgid "Default: Use the domain part of machine's hostname" msgstr "По умолчанию: использовать доменную часть имени узла компьютера" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3696 +#: sssd.conf.5.xml:3875 msgid "failover_primary_timeout (integer)" msgstr "failover_primary_timeout (целое число)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3699 +#: sssd.conf.5.xml:3878 msgid "" "When no primary server is available, SSSD fails over to a backup server. " "This option defines the number of seconds SSSD waits before attempting to " @@ -5312,59 +5553,72 @@ msgstr "" "повторного подключения к основному серверу." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3706 +#: sssd.conf.5.xml:3885 msgid "Note: The minimum value is 31." msgstr "Примечание: минимальное значение — 31." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3709 +#: sssd.conf.5.xml:3888 msgid "Default: 31" msgstr "По умолчанию: 31" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3715 +#: sssd.conf.5.xml:3894 msgid "override_gid (integer)" msgstr "override_gid (целое число)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3718 -msgid "Override the primary GID value with the one specified." -msgstr "Переопределить значение основного GID указанным значением." +#: sssd.conf.5.xml:3897 +msgid "" +"Override the primary GID value for all users in the domain with specified " +"value." +msgstr "" +"Переопределить значение основного GID для всех пользователей в домене " +"указанным значением." + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3901 +msgid "" +"Default: not set (Use the primary GID value retrieved from the identity " +"provider)" +msgstr "" +"По умолчанию: не задано (используется значение основного GID, полученное от " +"поставщика удостоверений)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3724 +#: sssd.conf.5.xml:3908 msgid "case_sensitive (string)" msgstr "case_sensitive (строка)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3731 +#: sssd.conf.5.xml:3915 msgid "True" msgstr "True" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3734 +#: sssd.conf.5.xml:3918 msgid "Case sensitive. This value is invalid for AD provider." msgstr "" "С учётом регистра. Это значение не является корректным для поставщика данных " "AD." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3740 +#: sssd.conf.5.xml:3924 msgid "False" msgstr "False" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3742 +#: sssd.conf.5.xml:3926 msgid "Case insensitive." msgstr "Без учёта регистра." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3746 +#: sssd.conf.5.xml:3930 msgid "Preserving" msgstr "Preserving" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3749 +#: sssd.conf.5.xml:3933 msgid "" "Same as False (case insensitive), but does not lowercase names in the result " "of NSS operations. Note that name aliases (and in case of services also " @@ -5376,7 +5630,7 @@ msgstr "" "регистр в выведенных данных." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3757 +#: sssd.conf.5.xml:3941 msgid "" "If you want to set this value for trusted domain with IPA provider, you need " "to set it on both the client and SSSD on the server." @@ -5386,7 +5640,7 @@ msgstr "" "на сервере." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3727 +#: sssd.conf.5.xml:3911 msgid "" "Treat user and group names as case sensitive. Possible option values are: " "<placeholder type=\"variablelist\" id=\"0\"/>" @@ -5395,17 +5649,49 @@ msgstr "" "значения: <placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3772 +#: sssd.conf.5.xml:3956 msgid "Default: True (False for AD provider)" msgstr "По умолчанию: True (False для поставщика данных AD)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3778 +#: sssd.conf.5.xml:3962 +msgid "avoid_by_id_lookups (boolean)" +msgstr "avoid_by_id_lookups (логическое значение)" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3965 +msgid "" +"If this option is set to 'true' SSSD will try to avoid sending lookups by ID " +"to the backend and will switch to a lookup by name if a cached object with a " +"matching ID can be found." +msgstr "" +"Если этот параметр установлен в значение 'true', SSSD будет стараться " +"избегать отправки в серверную часть запросов поиска по ID и переключится на " +"поиск по имени, если может быть найден кэшированный объект с совпадающим ID." + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3971 +msgid "" +"This option can e.g. be used in cases where searches by ID are expensive on " +"the server side because of missing indexes or are not even possible, e.g. " +"due to non-reversible POSIX id-mapping." +msgstr "" +"Этот параметр можно, например, использовать в случаях, когда поиск по ID " +"дорого обходится на стороне сервера из-за отсутствующих индексов или вообще " +"невозможен, например из-за необратимого отображения POSIX ID." + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3978 +msgid "Default: False (True for IdP provider)" +msgstr "По умолчанию: False (True для поставщика IdP)" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:3984 msgid "subdomain_inherit (string)" msgstr "subdomain_inherit (строка)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3781 +#: sssd.conf.5.xml:3987 msgid "" "Specifies a list of configuration parameters that should be inherited by a " "subdomain. Please note that only selected parameters can be inherited. " @@ -5417,37 +5703,37 @@ msgstr "" "параметров:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3787 +#: sssd.conf.5.xml:3993 msgid "ldap_search_timeout" msgstr "ldap_search_timeout" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3790 +#: sssd.conf.5.xml:3996 msgid "ldap_network_timeout" msgstr "ldap_network_timeout" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3793 +#: sssd.conf.5.xml:3999 msgid "ldap_opt_timeout" msgstr "ldap_opt_timeout" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3796 +#: sssd.conf.5.xml:4002 msgid "ldap_offline_timeout" msgstr "ldap_offline_timeout" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3799 +#: sssd.conf.5.xml:4005 msgid "ldap_purge_cache_timeout" msgstr "ldap_purge_cache_timeout" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3802 +#: sssd.conf.5.xml:4008 msgid "ldap_purge_cache_offset" msgstr "ldap_purge_cache_offset" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3805 +#: sssd.conf.5.xml:4011 msgid "" "ldap_krb5_keytab (the value of krb5_keytab will be used if ldap_krb5_keytab " "is not set explicitly)" @@ -5456,52 +5742,52 @@ msgstr "" "ldap_krb5_keytab не задан явно)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3809 +#: sssd.conf.5.xml:4015 msgid "ldap_krb5_ticket_lifetime" msgstr "ldap_krb5_ticket_lifetime" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3812 +#: sssd.conf.5.xml:4018 msgid "ldap_connection_expire_timeout" msgstr "ldap_connection_expire_timeout" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3815 +#: sssd.conf.5.xml:4021 msgid "ldap_connection_expire_offset" msgstr "ldap_connection_expire_offset" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3818 +#: sssd.conf.5.xml:4024 msgid "ldap_connection_idle_timeout" msgstr "ldap_connection_idle_timeout" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3821 sssd-ldap.5.xml:446 +#: sssd.conf.5.xml:4027 sssd-ldap.5.xml:446 msgid "ldap_use_tokengroups" msgstr "ldap_use_tokengroups" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3824 +#: sssd.conf.5.xml:4030 msgid "ldap_user_principal" msgstr "ldap_user_principal" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3827 +#: sssd.conf.5.xml:4033 msgid "ignore_group_members" msgstr "ignore_group_members" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3830 +#: sssd.conf.5.xml:4036 msgid "auto_private_groups" msgstr "auto_private_groups" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3833 +#: sssd.conf.5.xml:4039 msgid "case_sensitive" msgstr "case_sensitive" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:3838 +#: sssd.conf.5.xml:4044 #, no-wrap msgid "" "subdomain_inherit = ldap_purge_cache_timeout\n" @@ -5511,28 +5797,28 @@ msgstr "" " " #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3845 +#: sssd.conf.5.xml:4051 msgid "Note: This option only works with the IPA and AD provider." msgstr "" "Примечание: этот параметр работает только для поставщиков данных IPA и AD." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3852 +#: sssd.conf.5.xml:4058 msgid "subdomain_homedir (string)" msgstr "subdomain_homedir (строка)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3863 +#: sssd.conf.5.xml:4069 msgid "%F" msgstr "%F" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3864 +#: sssd.conf.5.xml:4070 msgid "flat (NetBIOS) name of a subdomain." msgstr "плоское (NetBIOS) имя поддомена." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3855 +#: sssd.conf.5.xml:4061 msgid "" "Use this homedir as default value for all subdomains within this domain in " "IPA AD trust. See <emphasis>override_homedir</emphasis> for info about " @@ -5548,7 +5834,7 @@ msgstr "" "id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3869 +#: sssd.conf.5.xml:4075 msgid "" "The value can be overridden by <emphasis>override_homedir</emphasis> option." msgstr "" @@ -5556,42 +5842,42 @@ msgstr "" "override_homedir</emphasis>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3873 +#: sssd.conf.5.xml:4079 msgid "Default: <filename>/home/%d/%u</filename>" msgstr "По умолчанию: <filename>/home/%d/%u</filename>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3878 +#: sssd.conf.5.xml:4084 msgid "realmd_tags (string)" msgstr "realmd_tags (строка)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3881 +#: sssd.conf.5.xml:4087 msgid "" "Various tags stored by the realmd configuration service for this domain." msgstr "Различные метки, сохранённые службой настройки realmd для этого домена." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3887 +#: sssd.conf.5.xml:4093 msgid "cached_auth_timeout (int)" msgstr "cached_auth_timeout (целое число)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3890 +#: sssd.conf.5.xml:4096 msgid "" -"Specifies time in seconds since last successful online authentication for " -"which user will be authenticated using cached credentials while SSSD is in " -"the online mode. If the credentials are incorrect, SSSD falls back to online " -"authentication." +"Specifies the number of seconds since the last successful online " +"authentication during which SSSD will authenticate users via cached " +"credentials, even while online. If the cached authentication fails, SSSD " +"immediately falls back to online authentication." msgstr "" -"Указывает время в секундах с момента последней успешной проверки подлинности " -"в сетевом режиме, в течение которого пользователь будет распознан с помощью " -"кэшированных учётных данных, когда SSSD находится в сетевом режиме. Если " -"учётные данные некорректны, SSSD будет использовать проверку подлинности в " -"сетевом режиме." +"Указывает количество секунд с момента последней успешной проверки " +"подлинности в сетевом режиме, в течение которых SSSD будет проверять " +"подлинность пользователей с помощью кэшированных учётных данных, даже " +"находясь в сетевом режиме. Если кэшированная проверка подлинности не " +"удалась, SSSD немедленно возвращается к сетевой проверке подлинности." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3898 +#: sssd.conf.5.xml:4103 msgid "" "This option's value is inherited by all trusted domains. At the moment it is " "not possible to set a different value per trusted domain." @@ -5601,12 +5887,12 @@ msgstr "" "значения." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3903 +#: sssd.conf.5.xml:4108 msgid "Special value 0 implies that this feature is disabled." msgstr "Специальное значение «0» подразумевает, что эта возможность отключена." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3907 +#: sssd.conf.5.xml:4112 msgid "" "Please note that if <quote>cached_auth_timeout</quote> is longer than " "<quote>pam_id_timeout</quote> then the back end could be called to handle " @@ -5617,12 +5903,12 @@ msgstr "" "<quote>initgroups.</quote>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3918 +#: sssd.conf.5.xml:4123 msgid "local_auth_policy (string)" msgstr "local_auth_policy (строка)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3921 +#: sssd.conf.5.xml:4126 msgid "" "Local authentication methods policy. Some backends (i.e. LDAP, proxy " "provider) only support a password based authentication, while others can " @@ -5642,7 +5928,7 @@ msgstr "" "и проверяются локально." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3933 +#: sssd.conf.5.xml:4138 msgid "" "There are three possible values for this option: match, only, enable. " "<quote>match</quote> is used to match offline and online states for Kerberos " @@ -5662,7 +5948,7 @@ msgstr "" "запятыми, например, <quote>enable:passkey, enable:smartcard</quote>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3946 +#: sssd.conf.5.xml:4151 msgid "" "The following table shows which authentication methods, if configured " "properly, are currently enabled or disabled for each backend, with the " @@ -5674,42 +5960,47 @@ msgstr "" "local_auth_policy: <quote>match</quote>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> -#: sssd.conf.5.xml:3959 +#: sssd.conf.5.xml:4164 msgid "local_auth_policy = match (default)" msgstr "local_auth_policy = match (по умолчанию)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> -#: sssd.conf.5.xml:3960 +#: sssd.conf.5.xml:4165 msgid "Passkey" msgstr "Ключ" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> -#: sssd.conf.5.xml:3961 +#: sssd.conf.5.xml:4166 msgid "Smartcard" msgstr "Смарт-карта" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:3964 sssd-ldap.5.xml:228 +#: sssd.conf.5.xml:4169 sssd-ldap.5.xml:228 msgid "IPA" msgstr "IPA" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry><para> +#: sssd.conf.5.xml:4169 sssd.conf.5.xml:4170 sssd.conf.5.xml:4173 +msgid "enabled" +msgstr "enabled" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:3967 sssd-ldap.5.xml:233 +#: sssd.conf.5.xml:4172 sssd-ldap.5.xml:233 msgid "AD" msgstr "AD" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry><para> -#: sssd.conf.5.xml:3967 sssd.conf.5.xml:3970 sssd.conf.5.xml:3971 +#: sssd.conf.5.xml:4172 sssd.conf.5.xml:4175 sssd.conf.5.xml:4176 msgid "disabled" msgstr "выключено" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry> -#: sssd.conf.5.xml:3970 +#: sssd.conf.5.xml:4175 msgid "LDAP" msgstr "LDAP" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3975 +#: sssd.conf.5.xml:4180 msgid "" "Please note that if local Smartcard authentication is enabled and a " "Smartcard is present, Smartcard authentication will be preferred over the " @@ -5722,7 +6013,7 @@ msgstr "" "Т.е., например, вместо запроса пароля будет предложено ввести PIN-код." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:3987 +#: sssd.conf.5.xml:4192 #, no-wrap msgid "" "[domain/shadowutils]\n" @@ -5738,7 +6029,7 @@ msgstr "" "local_auth_policy = only\n" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3983 +#: sssd.conf.5.xml:4188 msgid "" "The following configuration example allows local users to authenticate " "locally using any enabled method (i.e. smartcard, passkey). <placeholder " @@ -5750,22 +6041,22 @@ msgstr "" "type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3995 +#: sssd.conf.5.xml:4200 msgid "Default: match" msgstr "По умолчанию: match" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4000 +#: sssd.conf.5.xml:4205 msgid "auto_private_groups (string)" msgstr "auto_private_groups (строка)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4006 +#: sssd.conf.5.xml:4211 msgid "true" msgstr "true" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4009 +#: sssd.conf.5.xml:4214 msgid "" "Create user's private group unconditionally from user's UID number. The GID " "number is ignored in this case." @@ -5774,7 +6065,7 @@ msgstr "" "UID пользователя. Номер GID в этом случае игнорируется." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4013 +#: sssd.conf.5.xml:4218 msgid "" "NOTE: Because the GID number and the user private group are inferred from " "the UID number, it is not supported to have multiple entries with the same " @@ -5788,12 +6079,12 @@ msgstr "" "пространстве идентификаторов." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4022 +#: sssd.conf.5.xml:4227 msgid "false" msgstr "false" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4025 +#: sssd.conf.5.xml:4230 msgid "" "Always use the user's primary GID number. The GID number must refer to a " "group object in the LDAP database." @@ -5802,12 +6093,12 @@ msgstr "" "ссылаться на объект группы в базе данных LDAP." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4031 +#: sssd.conf.5.xml:4236 msgid "hybrid" msgstr "hybrid" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4034 +#: sssd.conf.5.xml:4239 msgid "" "A primary group is autogenerated for user entries whose UID and GID numbers " "have the same value and at the same time the GID number does not correspond " @@ -5822,7 +6113,7 @@ msgstr "" "основной GID этого пользователя разрешается в этот объект группы." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4047 +#: sssd.conf.5.xml:4252 msgid "" "If the UID and GID of a user are different, then the GID must correspond to " "a group entry, otherwise the GID is simply not resolvable." @@ -5831,7 +6122,7 @@ msgstr "" "группы; в ином случае GID просто будет невозможно разрешить." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4054 +#: sssd.conf.5.xml:4259 msgid "" "This feature is useful for environments that wish to stop maintaining a " "separate group objects for the user private groups, but also wish to retain " @@ -5842,7 +6133,7 @@ msgstr "" "сохранить существующие закрытые группы пользователей." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4003 +#: sssd.conf.5.xml:4208 msgid "" "This option takes any of three available values: <placeholder " "type=\"variablelist\" id=\"0\"/>" @@ -5851,7 +6142,7 @@ msgstr "" "type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4066 +#: sssd.conf.5.xml:4271 msgid "" "For the LDAP based id providers (LDAP, IPA and AD) the default for the " "configured domain is typically False because the sources have the concept of " @@ -5866,7 +6157,7 @@ msgstr "" "первичных групп.</phrase>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4075 +#: sssd.conf.5.xml:4280 msgid "" "For subdomains, the default value is False for subdomains that use assigned " "POSIX IDs and True for subdomains that use automatic ID-mapping." @@ -5876,7 +6167,7 @@ msgstr "" "поддоменов, которые используют автоматическое сопоставление идентификаторов." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:4083 +#: sssd.conf.5.xml:4288 #, no-wrap msgid "" "[domain/forest.domain/sub.domain]\n" @@ -5886,7 +6177,7 @@ msgstr "" "auto_private_groups = false\n" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:4089 +#: sssd.conf.5.xml:4294 #, no-wrap msgid "" "[domain/forest.domain]\n" @@ -5898,7 +6189,7 @@ msgstr "" "auto_private_groups = false\n" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4080 +#: sssd.conf.5.xml:4285 msgid "" "The value of auto_private_groups can either be set per subdomains in a " "subsection, for example: <placeholder type=\"programlisting\" id=\"0\"/> or " @@ -5912,7 +6203,7 @@ msgstr "" "type=\"programlisting\" id=\"1\"/>" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:2503 +#: sssd.conf.5.xml:2549 msgid "" "These configuration options can be present in a domain configuration " "section, that is, in a section called <quote>[domain/<replaceable>NAME</" @@ -5923,17 +6214,17 @@ msgstr "" "replaceable>]</quote> <placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4104 +#: sssd.conf.5.xml:4309 msgid "proxy_pam_target (string)" msgstr "proxy_pam_target (строка)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4107 +#: sssd.conf.5.xml:4312 msgid "The proxy target PAM proxies to." msgstr "Цель, которой пересылает данные прокси PAM." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4110 +#: sssd.conf.5.xml:4315 msgid "" "Default: not set by default, you have to take an existing pam configuration " "or create a new one and add the service name here. As an alternative you can " @@ -5945,12 +6236,12 @@ msgstr "" "local_auth_policy." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4120 +#: sssd.conf.5.xml:4325 msgid "proxy_lib_name (string)" msgstr "proxy_lib_name (строка)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4123 +#: sssd.conf.5.xml:4328 msgid "" "The name of the NSS library to use in proxy domains. The NSS functions " "searched for in the library are in the form of _nss_$(libName)_$(function), " @@ -5961,12 +6252,12 @@ msgstr "" "(function), например: _nss_files_getpwent." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4133 +#: sssd.conf.5.xml:4338 msgid "proxy_resolver_lib_name (string)" msgstr "proxy_resolver_lib_name (строка)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4136 +#: sssd.conf.5.xml:4341 msgid "" "The name of the NSS library to use for hosts and networks lookups in proxy " "domains. The NSS functions searched for in the library are in the form of " @@ -5977,12 +6268,12 @@ msgstr "" "вид _nss_$(libName)_$(function), например: _nss_dns_gethostbyname2_r." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4147 +#: sssd.conf.5.xml:4352 msgid "proxy_fast_alias (boolean)" msgstr "proxy_fast_alias (логическое значение)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4150 +#: sssd.conf.5.xml:4355 msgid "" "When a user or group is looked up by name in the proxy provider, a second " "lookup by ID is performed to \"canonicalize\" the name in case the requested " @@ -5996,12 +6287,12 @@ msgstr "" "идентификатора в кэше в целях ускорения предоставления результатов." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4164 +#: sssd.conf.5.xml:4369 msgid "proxy_max_children (integer)" msgstr "proxy_max_children (целое число)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4167 +#: sssd.conf.5.xml:4372 msgid "" "This option specifies the number of pre-forked proxy children. It is useful " "for high-load SSSD environments where sssd may run out of available child " @@ -6013,7 +6304,7 @@ msgstr "" "постановки запросов в очередь." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4100 +#: sssd.conf.5.xml:4305 msgid "" "Options valid for proxy domains. <placeholder type=\"variablelist\" " "id=\"0\"/>" @@ -6022,12 +6313,12 @@ msgstr "" "<placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:4183 +#: sssd.conf.5.xml:4388 msgid "Application domains" msgstr "Домены приложений" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:4185 +#: sssd.conf.5.xml:4390 msgid "" "SSSD, with its D-Bus interface (see <citerefentry> <refentrytitle>sssd-ifp</" "refentrytitle> <manvolnum>5</manvolnum> </citerefentry>) is appealing to " @@ -6056,7 +6347,7 @@ msgstr "" "домена SSSD." #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:4205 +#: sssd.conf.5.xml:4410 msgid "" "Please note that the application domain must still be explicitly enabled in " "the <quote>domains</quote> parameter so that the lookup order between the " @@ -6067,17 +6358,17 @@ msgstr "" "порядок поиска для домена приложений и его родственного домена POSIX." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><title> -#: sssd.conf.5.xml:4211 +#: sssd.conf.5.xml:4416 msgid "Application domain parameters" msgstr "Параметры доменов приложений" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4213 +#: sssd.conf.5.xml:4418 msgid "inherit_from (string)" msgstr "inherit_from (строка)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4216 +#: sssd.conf.5.xml:4421 msgid "" "The SSSD POSIX-type domain the application domain inherits all settings " "from. The application domain can moreover add its own settings to the " @@ -6090,7 +6381,7 @@ msgstr "" "родственного</quote> домена." #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:4230 +#: sssd.conf.5.xml:4435 msgid "" "The following example illustrates the use of an application domain. In this " "setup, the POSIX domain is connected to an LDAP server and is used by the OS " @@ -6105,7 +6396,7 @@ msgstr "" "атрибут phone доступным через интерфейс D-Bus." #. type: Content of: <reference><refentry><refsect1><refsect2><programlisting> -#: sssd.conf.5.xml:4238 +#: sssd.conf.5.xml:4443 #, no-wrap msgid "" "[sssd]\n" @@ -6139,12 +6430,12 @@ msgstr "" "ldap_user_extra_attrs = phone:telephoneNumber\n" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:4258 +#: sssd.conf.5.xml:4463 msgid "TRUSTED DOMAIN SECTION" msgstr "РАЗДЕЛ ДОВЕРЕННЫХ ДОМЕНОВ" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4260 +#: sssd.conf.5.xml:4465 msgid "" "Some options used in the domain section can also be used in the trusted " "domain section, that is, in a section called <quote>[domain/" @@ -6162,57 +6453,67 @@ msgstr "" "поддерживаются следующие параметры:" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4267 +#: sssd.conf.5.xml:4472 msgid "ldap_search_base," msgstr "ldap_search_base," #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4268 +#: sssd.conf.5.xml:4473 msgid "ldap_user_search_base," msgstr "ldap_user_search_base," #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4269 +#: sssd.conf.5.xml:4474 msgid "ldap_group_search_base," msgstr "ldap_group_search_base," #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4270 +#: sssd.conf.5.xml:4475 msgid "ldap_netgroup_search_base," msgstr "ldap_netgroup_search_base," #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4271 +#: sssd.conf.5.xml:4476 msgid "ldap_service_search_base," msgstr "ldap_service_search_base," #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4272 +#: sssd.conf.5.xml:4477 msgid "ldap_sasl_mech," msgstr "ldap_sasl_mech," #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4273 +#: sssd.conf.5.xml:4478 msgid "ad_server," msgstr "ad_server," #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4274 +#: sssd.conf.5.xml:4479 msgid "ad_backup_server," msgstr "ad_backup_server," #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4275 +#: sssd.conf.5.xml:4480 msgid "ad_site," msgstr "ad_site," #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:4276 sssd-ipa.5.xml:934 +#: sssd.conf.5.xml:4481 sssd-ipa.5.xml:929 msgid "use_fully_qualified_names" msgstr "use_fully_qualified_names" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4280 +#: sssd.conf.5.xml:4482 +msgid "pam_gssapi_services" +msgstr "pam_gssapi_services" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:4483 +msgid "pam_gssapi_check_upn" +msgstr "pam_gssapi_check_upn" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:4485 msgid "" "For more details about these options see their individual description in the " "manual page." @@ -6221,12 +6522,12 @@ msgstr "" "справочной странице." #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:4286 +#: sssd.conf.5.xml:4491 msgid "CERTIFICATE MAPPING SECTION" msgstr "РАЗДЕЛ СОПОСТАВЛЕНИЯ СЕРТИФИКАТОВ" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4288 +#: sssd.conf.5.xml:4493 msgid "" "To allow authentication with Smartcards and certificates SSSD must be able " "to map certificates to users. This can be done by adding the full " @@ -6248,7 +6549,7 @@ msgstr "" "случае, когда локальные службы используют PAM для проверки подлинности." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4302 +#: sssd.conf.5.xml:4507 msgid "" "To make the mapping more flexible mapping and matching rules were added to " "SSSD (see <citerefentry> <refentrytitle>sss-certmap</refentrytitle> " @@ -6259,7 +6560,7 @@ msgstr "" "refentrytitle> <manvolnum>5</manvolnum> </citerefentry>)." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4311 +#: sssd.conf.5.xml:4516 msgid "" "A mapping and matching rule can be added to the SSSD configuration in a " "section on its own with a name like <quote>[certmap/" @@ -6272,12 +6573,12 @@ msgstr "" "этом разделе допустимы следующие параметры:" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4318 +#: sssd.conf.5.xml:4523 msgid "matchrule (string)" msgstr "matchrule (строка)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4321 +#: sssd.conf.5.xml:4526 msgid "" "Only certificates from the Smartcard which matches this rule will be " "processed, all others are ignored." @@ -6286,7 +6587,7 @@ msgstr "" "соответствуют этому правилу. Все остальные будут игнорироваться." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4325 +#: sssd.conf.5.xml:4530 msgid "" "Default: KRB5:<EKU>clientAuth, i.e. only certificates which have the " "Extended Key Usage <quote>clientAuth</quote>" @@ -6296,17 +6597,17 @@ msgstr "" "clientAuth</quote>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4332 +#: sssd.conf.5.xml:4537 msgid "maprule (string)" msgstr "maprule (строка)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4335 +#: sssd.conf.5.xml:4540 msgid "Defines how the user is found for a given certificate." msgstr "Определяет способ поиска пользователя для указанного сертификата." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:4341 +#: sssd.conf.5.xml:4546 msgid "" "LDAP:(userCertificate;binary={cert!bin}) for LDAP based providers like " "<quote>ldap</quote>, <quote>AD</quote> or <quote>ipa</quote>." @@ -6316,21 +6617,16 @@ msgstr "" "." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:4347 +#: sssd.conf.5.xml:4552 msgid "" "If maprule is not set and provider is <quote>proxy</quote>, the RULE_NAME " "name is assumed to be the name of the matching user." msgstr "" "Если значение maprule не установлено и поставщиком данных является <quote>" -"proxy</quote>, именем совпадающего пользователя считается RULE_NAME." - -#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4357 -msgid "domains (string)" -msgstr "domains (строка)" +"proxy</quote>, именем совпадающего пользователя считается RULE_NAME." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4360 +#: sssd.conf.5.xml:4565 msgid "" "Comma separated list of domain names the rule should be applied. By default " "a rule is only valid in the domain configured in sssd.conf. If the provider " @@ -6343,17 +6639,17 @@ msgstr "" "параметра можно добавить правило также и в поддомены." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4367 +#: sssd.conf.5.xml:4572 msgid "Default: the configured domain in sssd.conf" msgstr "По умолчанию: настроенный домен в sssd.conf" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4372 +#: sssd.conf.5.xml:4577 msgid "priority (integer)" msgstr "priority (целое число)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4375 +#: sssd.conf.5.xml:4580 msgid "" "Unsigned integer value defining the priority of the rule. The higher the " "number the lower the priority. <quote>0</quote> stands for the highest " @@ -6364,17 +6660,17 @@ msgstr "" "приоритет, а <quote>4294967295</quote> — самый низкий." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4381 +#: sssd.conf.5.xml:4586 msgid "Default: the lowest priority" msgstr "По умолчанию: самый низкий приоритет" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:4389 +#: sssd.conf.5.xml:4594 msgid "PROMPTING CONFIGURATION SECTION" msgstr "РАЗДЕЛ НАСТРОЙКИ ЗАПРОСОВ" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4391 +#: sssd.conf.5.xml:4596 msgid "" "If a special file (<filename>/var/lib/sss/pubconf/pam_preauth_available</" "filename>) exists SSSD's PAM module pam_sss will ask SSSD to figure out " @@ -6389,7 +6685,7 @@ msgstr "" "запросит у пользователя соответствующие учётные данные." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4399 +#: sssd.conf.5.xml:4604 msgid "" "With the growing number of authentication methods and the possibility that " "there are multiple ones for a single user the heuristic used by pam_sss to " @@ -6402,22 +6698,22 @@ msgstr "" "Следующие параметры обеспечивают более гибкую настройку." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4411 +#: sssd.conf.5.xml:4616 msgid "[prompting/password]" msgstr "[prompting/password]" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4414 +#: sssd.conf.5.xml:4619 msgid "password_prompt" msgstr "password_prompt" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4415 +#: sssd.conf.5.xml:4620 msgid "to change the string of the password prompt" msgstr "изменить строку запроса пароля" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4413 +#: sssd.conf.5.xml:4618 msgid "" "to configure password prompting, allowed options are: <placeholder " "type=\"variablelist\" id=\"0\"/>" @@ -6426,37 +6722,37 @@ msgstr "" "type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4423 +#: sssd.conf.5.xml:4628 msgid "[prompting/2fa]" msgstr "[prompting/2fa]" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4427 +#: sssd.conf.5.xml:4632 msgid "first_prompt" msgstr "first_prompt" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4428 +#: sssd.conf.5.xml:4633 msgid "to change the string of the prompt for the first factor" msgstr "изменить строку запроса первого фактора" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4431 +#: sssd.conf.5.xml:4636 msgid "second_prompt" msgstr "second_prompt" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4432 +#: sssd.conf.5.xml:4637 msgid "to change the string of the prompt for the second factor" msgstr "изменить строку запроса второго фактора" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4435 +#: sssd.conf.5.xml:4640 msgid "single_prompt" msgstr "single_prompt" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4436 +#: sssd.conf.5.xml:4641 msgid "" "boolean value, if True there will be only a single prompt using the value of " "first_prompt where it is expected that both factors are entered as a single " @@ -6469,7 +6765,7 @@ msgstr "" "фактора, даже если второй фактор является необязательным." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4425 +#: sssd.conf.5.xml:4630 msgid "" "to configure two-factor authentication prompting, allowed options are: " "<placeholder type=\"variablelist\" id=\"0\"/> If the second factor is " @@ -6482,7 +6778,7 @@ msgstr "" "пароль, либо оба фактора, следует использовать двухэтапный запрос." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4449 +#: sssd.conf.5.xml:4654 msgid "" "Some clients, such as SSH with 'PasswordAuthentication yes', generate their " "own prompts and do not use prompts provided by SSSD or other PAM modules. " @@ -6500,17 +6796,17 @@ msgstr "" "аутентификация необязательна." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4464 +#: sssd.conf.5.xml:4669 msgid "[prompting/passkey]" msgstr "[prompting/passkey]" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:4470 sssd-ad.5.xml:1022 +#: sssd.conf.5.xml:4675 sssd.conf.5.xml:4719 sssd-ad.5.xml:1027 msgid "interactive" msgstr "interactive" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4472 +#: sssd.conf.5.xml:4677 msgid "" "boolean value, if True prompt a message and wait before testing the presence " "of a passkey device. Recommended if your device doesn’t have a tactile " @@ -6521,22 +6817,22 @@ msgstr "" "тактильного переключателя." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4480 +#: sssd.conf.5.xml:4685 sssd.conf.5.xml:4735 msgid "interactive_prompt" msgstr "interactive_prompt" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4482 +#: sssd.conf.5.xml:4687 sssd.conf.5.xml:4737 msgid "to change the message of the interactive prompt." msgstr "изменить сообщение интерактивного запроса." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4487 +#: sssd.conf.5.xml:4692 msgid "touch" msgstr "touch" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4489 +#: sssd.conf.5.xml:4694 msgid "" "boolean value, if True prompt a message to remind the user to touch the " "device." @@ -6545,17 +6841,17 @@ msgstr "" "пользователю о необходимости коснуться устройства." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4495 +#: sssd.conf.5.xml:4700 msgid "touch_prompt" msgstr "touch_prompt" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4497 +#: sssd.conf.5.xml:4702 msgid "to change the message of the touch prompt." msgstr "изменить сообщение запроса касания." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4466 +#: sssd.conf.5.xml:4671 msgid "" "to configure passkey authentication prompting, allowed options are: " "<placeholder type=\"variablelist\" id=\"0\"/>" @@ -6563,22 +6859,114 @@ msgstr "" "допустимые параметры для настройки аутентификации по ключу доступа: " "<placeholder type=\"variablelist\" id=\"0\"/>" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4713 +msgid "[prompting/oauth2]" +msgstr "[prompting/oauth2]" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4721 +msgid "" +"boolean value, if True prompt a message after asking the user to " +"authenticate, and wait before requesting the access token." +msgstr "" +"логическое значение; если True, вывести сообщение после запроса " +"аутентификации у пользователя и подождать перед запросом токена доступа." + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4725 +msgid "" +"If False, make sure to set the <quote>idp_request_timeout</quote> " +"sufficiently high, to give the user time to authenticate." +msgstr "" +"Если False, обязательно задайте <quote>idp_request_timeout</quote> " +"достаточно большим, чтобы дать пользователю время пройти аутентификацию." + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4715 +msgid "" +"to configure OAuth2 authentication prompting, allowed options are: " +"<placeholder type=\"variablelist\" id=\"0\"/>" +msgstr "" +"для настройки приглашения аутентификации OAuth2 допустимы следующие " +"параметры: <placeholder type=\"variablelist\" id=\"0\"/>" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4748 +msgid "[prompting/cert_auth]" +msgstr "[prompting/cert_auth]" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4754 +msgid "pin_prompt" +msgstr "pin_prompt" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4756 +msgid "" +"to change the message which asks the user to enter the PIN at the computer " +"keyboard. At the end of the message the token name is printed." +msgstr "" +"для изменения сообщения, которое просит пользователя ввести PIN на " +"клавиатуре компьютера. В конце сообщения выводится имя токена." + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4764 +msgid "keypad_prompt" +msgstr "keypad_prompt" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4766 +msgid "" +"to change the message which asks the user to enter the PIN at keypad of the " +"Smartcard reader. At the end of the message the token name is printed." +msgstr "" +"для изменения сообщения, которое просит пользователя ввести PIN на " +"клавиатуре считывателя смарт-карт. В конце сообщения выводится имя токена." + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4774 +msgid "user_name_hint" +msgstr "user_name_hint" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4776 +msgid "" +"boolean value, if True ask for a user name if no name was given before and " +"the found certificate can be mapped to more than one user." +msgstr "" +"логическое значение; если True, запросить имя пользователя, если ранее имя " +"не было указано, а найденный сертификат может быть сопоставлен более чем " +"одному пользователю." + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4750 +msgid "" +"to configure Smartcard authentication prompting, allowed options are: " +"<placeholder type=\"variablelist\" id=\"0\"/>" +msgstr "" +"для настройки приглашения аутентификации по смарт-карте допустимы следующие " +"параметры: <placeholder type=\"variablelist\" id=\"0\"/>" + #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4406 +#: sssd.conf.5.xml:4611 msgid "" "Each supported authentication method has its own configuration subsection " "under <quote>[prompting/...]</quote>. Currently there are: <placeholder " "type=\"variablelist\" id=\"0\"/> <placeholder type=\"variablelist\" id=\"1\"/" -"> <placeholder type=\"variablelist\" id=\"2\"/>" +"> <placeholder type=\"variablelist\" id=\"2\"/> <placeholder " +"type=\"variablelist\" id=\"3\"/> <placeholder type=\"variablelist\" id=\"4\"/" +">" msgstr "" "Для каждого поддерживаемого способа проверки подлинности предусмотрен " "отдельный подраздел конфигурации: <quote>[prompting/...]</quote>. В " "настоящее время это: <placeholder type=\"variablelist\" id=\"0\"/> " "<placeholder type=\"variablelist\" id=\"1\"/> <placeholder " -"type=\"variablelist\" id=\"2\"/>" +"type=\"variablelist\" id=\"2\"/> <placeholder type=\"variablelist\" " +"id=\"3\"/> <placeholder type=\"variablelist\" id=\"4\"/>" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4508 +#: sssd.conf.5.xml:4792 msgid "" "It is possible to add a subsection for specific PAM services, e.g. " "<quote>[prompting/password/sshd]</quote> to individual change the prompting " @@ -6589,12 +6977,12 @@ msgstr "" "для этой службы." #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:4515 pam_sss_gss.8.xml:157 idmap_sss.8.xml:43 +#: sssd.conf.5.xml:4799 pam_sss_gss.8.xml:157 idmap_sss.8.xml:43 msgid "EXAMPLES" msgstr "ПРИМЕРЫ" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd.conf.5.xml:4521 +#: sssd.conf.5.xml:4805 #, no-wrap msgid "" "[sssd]\n" @@ -6646,7 +7034,7 @@ msgstr "" "enumerate = False\n" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4517 +#: sssd.conf.5.xml:4801 msgid "" "1. The following example shows a typical SSSD config. It does not describe " "configuration of the domains themselves - refer to documentation on " @@ -6658,7 +7046,7 @@ msgstr "" "документации. <placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd.conf.5.xml:4553 +#: sssd.conf.5.xml:4837 #, no-wrap msgid "" "[domain/ipa.com/child.ad.com]\n" @@ -6668,7 +7056,7 @@ msgstr "" "use_fully_qualified_names = false\n" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4547 +#: sssd.conf.5.xml:4831 msgid "" "2. The following example shows configuration of IPA AD trust where the AD " "forest consists of two domains in a parent-child structure. Suppose IPA " @@ -6685,7 +7073,7 @@ msgstr "" "type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd.conf.5.xml:4564 +#: sssd.conf.5.xml:4848 #, no-wrap msgid "" "[certmap/my.domain/rule_name]\n" @@ -6701,7 +7089,7 @@ msgstr "" "priority = 10\n" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4558 +#: sssd.conf.5.xml:4842 msgid "" "3. The following example shows the configuration of a certificate mapping " "rule. It is valid for the configured domain <quote>my.domain</quote> and " @@ -6948,7 +7336,7 @@ msgid "" "defaultNamingContext does not exist or has an empty value namingContexts is " "used. The namingContexts attribute must have a single value with the DN of " "the search base of the LDAP server to make this work. Multiple values are " -"are not supported." +"not supported." msgstr "" "По умолчанию: если не задано, используется значение атрибута " "defaultNamingContext или namingContexts из RootDSE сервера LDAP. Если " @@ -7321,8 +7709,8 @@ msgstr "" "объектов узлов." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap.5.xml:472 sssd-ipa.5.xml:506 sssd-ipa.5.xml:525 sssd-ipa.5.xml:544 -#: sssd-ipa.5.xml:563 +#: sssd-ldap.5.xml:472 sssd-ipa.5.xml:501 sssd-ipa.5.xml:520 sssd-ipa.5.xml:539 +#: sssd-ipa.5.xml:558 msgid "" "See <quote>ldap_search_base</quote> for information about configuring " "multiple search bases." @@ -7331,7 +7719,7 @@ msgstr "" "<quote>ldap_search_base</quote>." #. type: Content of: <listitem><para> -#: sssd-ldap.5.xml:477 sssd-ipa.5.xml:511 include/ldap_search_bases.xml:27 +#: sssd-ldap.5.xml:477 sssd-ipa.5.xml:506 include/ldap_search_bases.xml:27 msgid "Default: the value of <emphasis>ldap_search_base</emphasis>" msgstr "По умолчанию: значение <emphasis>ldap_search_base</emphasis>" @@ -7484,7 +7872,7 @@ msgid "" "closed early to ensure that a new query cannot require the connection to " "remain open past its expiration. This implies that connections will always " "be closed immediately and will never be reused if " -"<emphasis>ldap_connection_expire_timeout <= ldap_opt_timout</emphasis>" +"<emphasis>ldap_connection_expire_timeout <= ldap_opt_timeout</emphasis>" msgstr "" "Если соединение простаивает (активные операции не выполняются) в течение " "<emphasis>ldap_opt_timeout</emphasis> секунд после истечения срока действия, " @@ -7492,7 +7880,7 @@ msgstr "" "требовать, чтобы соединение оставалось открытым после истечения срока его " "действия. Это означает, что соединения всегда будут закрываться немедленно, " "и не будут использоваться повторно, если <emphasis>" -"ldap_connection_expire_timeout <= ldap_opt_timout</emphasis>" +"ldap_connection_expire_timeout <= ldap_opt_timeout</emphasis>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:633 @@ -7728,7 +8116,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:831 -msgid "ldap_ignore_unreadable_references (bool)" +msgid "ldap_ignore_unreadable_references (boolean)" msgstr "ldap_ignore_unreadable_references (логическое значение)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> @@ -8147,7 +8535,7 @@ msgstr "" "GSS-SPNEGO." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap.5.xml:1152 sssd-ad.5.xml:1267 +#: sssd-ldap.5.xml:1152 sssd-ad.5.xml:1260 msgid "Default: 86400 (24 hours)" msgstr "По умолчанию: 86400 (24 часа)" @@ -8199,7 +8587,7 @@ msgstr "" "перейти на использование <quote>krb5_server</quote> в файлах конфигурации." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ldap.5.xml:1187 sssd-ipa.5.xml:575 sssd-krb5.5.xml:103 +#: sssd-ldap.5.xml:1187 sssd-ipa.5.xml:570 sssd-krb5.5.xml:103 msgid "krb5_realm (string)" msgstr "krb5_realm (строка)" @@ -8401,7 +8789,7 @@ msgstr "По умолчанию: не задано, то есть обнаруж #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1339 -msgid "ldap_chpass_update_last_change (bool)" +msgid "ldap_chpass_update_last_change (boolean)" msgstr "ldap_chpass_update_last_change (логическое значение)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> @@ -8599,7 +8987,7 @@ msgid "ldap_access_order (string)" msgstr "ldap_access_order (строка)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap.5.xml:1470 sssd-ipa.5.xml:405 +#: sssd-ldap.5.xml:1470 sssd-ipa.5.xml:400 msgid "Comma separated list of access control options. Allowed values are:" msgstr "" "Разделённый запятыми список параметров управления доступом. Допустимые " @@ -8665,7 +9053,7 @@ msgid "<emphasis>expire</emphasis>: use ldap_account_expire_policy" msgstr "<emphasis>expire</emphasis>: использовать ldap_account_expire_policy" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap.5.xml:1515 sssd-ipa.5.xml:413 +#: sssd-ldap.5.xml:1515 sssd-ipa.5.xml:408 msgid "" "<emphasis>pwd_expire_policy_reject, pwd_expire_policy_warn, " "pwd_expire_policy_renew: </emphasis> These options are useful if users are " @@ -8679,7 +9067,7 @@ msgstr "" "и для проверки подлинности используются не пароли, а, например, ключи SSH." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap.5.xml:1525 sssd-ipa.5.xml:423 +#: sssd-ldap.5.xml:1525 sssd-ipa.5.xml:418 msgid "" "The difference between these options is the action taken if user password is " "expired:" @@ -8688,18 +9076,18 @@ msgstr "" "предпринимаются, если срок действия пароля пользователя истёк:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ldap.5.xml:1530 sssd-ipa.5.xml:428 +#: sssd-ldap.5.xml:1530 sssd-ipa.5.xml:423 msgid "pwd_expire_policy_reject - user is denied to log in," msgstr "pwd_expire_policy_reject — пользователю отказано во входе в систему," #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ldap.5.xml:1536 sssd-ipa.5.xml:434 +#: sssd-ldap.5.xml:1536 sssd-ipa.5.xml:429 msgid "pwd_expire_policy_warn - user is still able to log in," msgstr "" "pwd_expire_policy_warn — пользователь по-прежнему может войти в систему," #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ldap.5.xml:1542 sssd-ipa.5.xml:440 +#: sssd-ldap.5.xml:1542 sssd-ipa.5.xml:435 msgid "" "pwd_expire_policy_renew - user is prompted to change their password " "immediately." @@ -9367,8 +9755,8 @@ msgstr "" "<placeholder type=\"variablelist\" id=\"1\"/>" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd-ldap.5.xml:2032 sssd-simple.5.xml:169 sssd-ipa.5.xml:984 -#: sssd-ad.5.xml:1470 sssd-idp.5.xml:248 sssd-krb5.5.xml:483 +#: sssd-ldap.5.xml:2032 sssd-simple.5.xml:169 sssd-ipa.5.xml:979 +#: sssd-ad.5.xml:1463 sssd-idp.5.xml:343 sssd-krb5.5.xml:483 #: sss_rpcidmapd.5.xml:98 sssd-session-recording.5.xml:176 msgid "EXAMPLE" msgstr "ПРИМЕР" @@ -9406,7 +9794,7 @@ msgstr "" #. type: Content of: <refsect1><refsect2><para> #: sssd-ldap.5.xml:2039 sssd-ldap.5.xml:2057 sssd-simple.5.xml:177 -#: sssd-ipa.5.xml:992 sssd-ad.5.xml:1478 sssd-sudo.5.xml:56 sssd-krb5.5.xml:492 +#: sssd-ipa.5.xml:987 sssd-ad.5.xml:1471 sssd-sudo.5.xml:56 sssd-krb5.5.xml:492 #: sssd-session-recording.5.xml:182 include/ldap_id_mapping.xml:105 msgid "<placeholder type=\"programlisting\" id=\"0\"/>" msgstr "<placeholder type=\"programlisting\" id=\"0\"/>" @@ -9453,7 +9841,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><title> #: sssd-ldap.5.xml:2073 sssd_krb5_locator_plugin.8.xml:83 sssd-simple.5.xml:189 -#: sssd-ad.5.xml:1493 sssd.8.xml:270 sss_seed.8.xml:163 +#: sssd-ad.5.xml:1486 sssd.8.xml:270 sss_seed.8.xml:163 msgid "NOTES" msgstr "ПРИМЕЧАНИЯ" @@ -10079,12 +10467,11 @@ msgstr "PAM_NO_MODULE_DATA" #: pam_sss.8.xml:434 msgid "" "No authentication method was found by Kerberos. This might happen if the " -"user has a Smartcard assigned but the pkint plugin is not available on the " +"user has a Smartcard assigned but the pkinit plugin is not available on the " "client." msgstr "" -"Kerberos не был найден способ проверки подлинности. Это могло произойти, " -"если для записи пользователя назначена смарт-карта, но на клиенте недоступен " -"модуль pkint." +"Kerberos не нашёл способ проверки подлинности. Это может произойти, если за " +"пользователем закреплена смарт-карта, но на клиенте недоступен модуль pkinit." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:441 @@ -10656,6 +11043,30 @@ msgstr "" "kdcinfo. По умолчанию модуль возвращает вызывающей стороне " "KRB5_PLUGIN_NO_HANDLE сразу после первой неудачи при разрешении DNS." +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_locator_plugin.8.xml:106 +msgid "" +"If the environment variable SSSD_KRB5_LOCATOR_KDC_ADDRESS is set to a KDC " +"address the plugin will use this address instead of reading the kdcinfo " +"file. The address format is the same as in the kdcinfo file (see above)." +msgstr "" +"Если переменная окружения SSSD_KRB5_LOCATOR_KDC_ADDRESS установлена в адрес " +"KDC, плагин будет использовать этот адрес вместо чтения файла kdcinfo. " +"Формат адреса такой же, как в файле kdcinfo (см. выше)." + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_locator_plugin.8.xml:112 +msgid "" +"If the environment variable SSSD_KRB5_LOCATOR_KPASSWD_ADDRESS is set to a " +"kpasswd server address the plugin will use this address instead of reading " +"the kpasswdinfo file. The address format is the same as in the kpasswdinfo " +"file (see above)." +msgstr "" +"Если переменная окружения SSSD_KRB5_LOCATOR_KPASSWD_ADDRESS установлена в " +"адрес сервера kpasswd, плагин будет использовать этот адрес вместо чтения " +"файла kpasswdinfo. Формат адреса такой же, как в файле kpasswdinfo (см. выше)" +"." + #. type: Content of: <reference><refentry><refnamediv><refname> #: sssd-simple.5.xml:10 sssd-simple.5.xml:16 msgid "sssd-simple" @@ -12389,7 +12800,7 @@ msgstr "" "домене IPA. Имя узла должно быть полным." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:129 sssd-ad.5.xml:1161 +#: sssd-ipa.5.xml:129 sssd-ad.5.xml:1166 msgid "dyndns_update (boolean)" msgstr "dyndns_update (логическое значение)" @@ -12408,23 +12819,13 @@ msgstr "" "использован IP-адрес LDAP-соединения IPA, если с помощью параметра <quote>" "dyndns_iface</quote> не указано иное." -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:141 sssd-ad.5.xml:1175 -msgid "" -"NOTE: On older systems (such as RHEL 5), for this behavior to work reliably, " -"the default Kerberos realm must be set properly in /etc/krb5.conf" -msgstr "" -"ПРИМЕЧАНИЕ: на устаревших системах (например, RHEL 5) для корректной работы " -"в этом режиме необходимо надлежащим образом задать стандартную область " -"Kerberos в /etc/krb5.conf" - #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:152 sssd-ad.5.xml:1186 +#: sssd-ipa.5.xml:147 sssd-ad.5.xml:1186 msgid "dyndns_ttl (integer)" msgstr "dyndns_ttl (целое число)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:155 sssd-ad.5.xml:1189 +#: sssd-ipa.5.xml:150 sssd-ad.5.xml:1189 msgid "" "The TTL to apply to the client DNS record when updating it. If " "dyndns_update is false this has no effect. This will override the TTL " @@ -12436,17 +12837,17 @@ msgstr "" "сервера, оно будет переопределено этим параметром." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:160 +#: sssd-ipa.5.xml:155 msgid "Default: 1200 (seconds)" msgstr "По умолчанию: 1200 (секунд)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:166 sssd-ad.5.xml:1200 +#: sssd-ipa.5.xml:161 sssd-ad.5.xml:1200 msgid "dyndns_iface (string)" msgstr "dyndns_iface (строка)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:169 sssd-ad.5.xml:1203 +#: sssd-ipa.5.xml:164 sssd-ad.5.xml:1203 msgid "" "Optional. Applicable only when dyndns_update is true. Choose the interface " "or a list of interfaces whose IP addresses should be used for dynamic DNS " @@ -12467,7 +12868,7 @@ msgstr "" "шаблонах см. в <emphasis>man 7 glob</emphasis>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:182 +#: sssd-ipa.5.xml:177 msgid "" "Default: Use the IP addresses of the interface which is used for IPA LDAP " "connection" @@ -12476,17 +12877,17 @@ msgstr "" "подключения LDAP IPA" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:186 sssd-ad.5.xml:1226 +#: sssd-ipa.5.xml:181 sssd-ad.5.xml:1220 msgid "Example: dyndns_iface = em[12], !vnet1, vnet*" msgstr "Пример: dyndns_iface = em[12], !vnet1, vnet*" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:192 sssd-ad.5.xml:1232 +#: sssd-ipa.5.xml:187 sssd-ad.5.xml:1226 msgid "dyndns_address (string)" msgstr "dyndns_address (строка)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:195 sssd-ad.5.xml:1235 +#: sssd-ipa.5.xml:190 sssd-ad.5.xml:1229 msgid "" "Optional. Applicable only when <emphasis>dyndns_update</emphasis> is true. " "A list of IP addresses or IP networks to be used for dynamic DNS updates. " @@ -12505,22 +12906,22 @@ msgstr "" "префикс)." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:206 sssd-ad.5.xml:1246 +#: sssd-ipa.5.xml:201 sssd-ad.5.xml:1240 msgid "Default: No filtering of IP addresses." msgstr "По умолчанию: фильтрация IP-адресов не выполняется." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:209 sssd-ad.5.xml:1249 +#: sssd-ipa.5.xml:204 sssd-ad.5.xml:1243 msgid "Example: dyndns_address = 10.0.0.0/16, !10.0.1.0/24" msgstr "Пример: dyndns_address = 10.0.0.0/16, !10.0.1.0/24" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:215 sssd-ad.5.xml:1305 +#: sssd-ipa.5.xml:210 sssd-ad.5.xml:1298 msgid "dyndns_auth (string)" msgstr "dyndns_auth (строка)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:218 sssd-ad.5.xml:1308 +#: sssd-ipa.5.xml:213 sssd-ad.5.xml:1301 msgid "" "Whether the nsupdate utility should use GSS-TSIG authentication for secure " "updates with the DNS server, insecure updates can be sent by setting this " @@ -12531,17 +12932,17 @@ msgstr "" "отправлять, установив этот параметр в значение «none»." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:224 sssd-ad.5.xml:1314 +#: sssd-ipa.5.xml:219 sssd-ad.5.xml:1307 msgid "Default: GSS-TSIG" msgstr "По умолчанию: GSS-TSIG" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:230 sssd-ad.5.xml:1320 +#: sssd-ipa.5.xml:225 sssd-ad.5.xml:1313 msgid "dyndns_auth_ptr (string)" msgstr "dyndns_auth_ptr (строка)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:233 sssd-ad.5.xml:1323 +#: sssd-ipa.5.xml:228 sssd-ad.5.xml:1316 msgid "" "Whether the nsupdate utility should use GSS-TSIG authentication for secure " "PTR updates with the DNS server, insecure updates can be sent by setting " @@ -12552,17 +12953,17 @@ msgstr "" "отправлять, установив этот параметр в значение «none»." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:239 sssd-ad.5.xml:1329 +#: sssd-ipa.5.xml:234 sssd-ad.5.xml:1322 msgid "Default: Same as dyndns_auth" msgstr "По умолчанию: то же, что и dyndns_auth" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:245 sssd-ad.5.xml:1255 +#: sssd-ipa.5.xml:240 sssd-ad.5.xml:1249 msgid "dyndns_refresh_interval (integer)" msgstr "dyndns_refresh_interval (целое число)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:248 +#: sssd-ipa.5.xml:243 msgid "" "How often should the back end perform periodic DNS update in addition to the " "automatic update performed when the back end goes online. This option is " @@ -12575,12 +12976,12 @@ msgstr "" "«true»." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:261 sssd-ad.5.xml:1273 -msgid "dyndns_update_ptr (bool)" +#: sssd-ipa.5.xml:256 sssd-ad.5.xml:1266 +msgid "dyndns_update_ptr (boolean)" msgstr "dyndns_update_ptr (логическое значение)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:264 sssd-ad.5.xml:1276 +#: sssd-ipa.5.xml:259 sssd-ad.5.xml:1269 msgid "" "Whether the PTR record should also be explicitly updated when updating the " "client's DNS records. Applicable only when dyndns_update is true." @@ -12590,7 +12991,7 @@ msgstr "" "значение «true»." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:269 +#: sssd-ipa.5.xml:264 msgid "" "This option should be False in most IPA deployments as the IPA server " "generates the PTR records automatically when forward records are changed." @@ -12600,7 +13001,7 @@ msgstr "" "автоматически при смене записей перенаправления." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:275 sssd-ad.5.xml:1281 +#: sssd-ipa.5.xml:270 sssd-ad.5.xml:1274 msgid "" "Note that <emphasis>dyndns_update_per_family</emphasis> parameter does not " "apply for PTR record updates. Those updates are always sent separately." @@ -12610,17 +13011,17 @@ msgstr "" "отправляются отдельно." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:280 +#: sssd-ipa.5.xml:275 msgid "Default: False (disabled)" msgstr "По умолчанию: false (отключено)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:286 sssd-ad.5.xml:1292 -msgid "dyndns_force_tcp (bool)" +#: sssd-ipa.5.xml:281 sssd-ad.5.xml:1285 +msgid "dyndns_force_tcp (boolean)" msgstr "dyndns_force_tcp (логическое значение)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:289 sssd-ad.5.xml:1295 +#: sssd-ipa.5.xml:284 sssd-ad.5.xml:1288 msgid "" "Whether the nsupdate utility should default to using TCP for communicating " "with the DNS server." @@ -12629,17 +13030,17 @@ msgstr "" "с сервером DNS." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:293 sssd-ad.5.xml:1299 +#: sssd-ipa.5.xml:288 sssd-ad.5.xml:1292 msgid "Default: False (let nsupdate choose the protocol)" msgstr "По умолчанию: false (разрешить nsupdate выбрать протокол)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:299 sssd-ad.5.xml:1335 +#: sssd-ipa.5.xml:294 sssd-ad.5.xml:1328 msgid "dyndns_server (string)" msgstr "dyndns_server (строка)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:302 sssd-ad.5.xml:1338 +#: sssd-ipa.5.xml:297 sssd-ad.5.xml:1331 msgid "" "The DNS server to use when performing a DNS update. In most setups, it's " "recommended to leave this option unset." @@ -12649,7 +13050,7 @@ msgstr "" "параметра." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:307 sssd-ad.5.xml:1343 +#: sssd-ipa.5.xml:302 sssd-ad.5.xml:1336 msgid "" "Setting this option makes sense for environments where the DNS server is " "different from the identity server or when we use encrypted DNS." @@ -12659,7 +13060,7 @@ msgstr "" "зашифрованный DNS." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:312 sssd-ad.5.xml:1348 +#: sssd-ipa.5.xml:307 sssd-ad.5.xml:1341 msgid "" "The parameter can be a simple string containing DNS name or IP address. It " "can also be an URI. The URI can look like <emphasis>dns://servername/</" @@ -12670,7 +13071,7 @@ msgstr "" "emphasis> или <emphasis>dns+tls://1.2.3.4:853#servername/</emphasis>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:319 sssd-ad.5.xml:1355 +#: sssd-ipa.5.xml:314 sssd-ad.5.xml:1348 msgid "" "The second example enables DNS-over-TLS protocol for DNS updates. The " "nsupdate utility must support DoT - check the <emphasis>man nsupdate</" @@ -12681,7 +13082,7 @@ msgstr "" "emphasis> перед её включением в SSSD." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:325 sssd-ad.5.xml:1361 +#: sssd-ipa.5.xml:320 sssd-ad.5.xml:1354 msgid "" "Please note that this option will be only used in fallback attempt when " "previous attempt using autodetected settings failed or when DNS-over-TLS is " @@ -12693,17 +13094,17 @@ msgstr "" "или когда включен DNS-over-TLS." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:331 sssd-ad.5.xml:1367 +#: sssd-ipa.5.xml:326 sssd-ad.5.xml:1360 msgid "Default: None (let nsupdate choose the server)" msgstr "По умолчанию: none (разрешить nsupdate выбрать сервер)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:337 sssd-ad.5.xml:1373 +#: sssd-ipa.5.xml:332 sssd-ad.5.xml:1366 msgid "dyndns_update_per_family (boolean)" msgstr "dyndns_update_per_family (логическое значение)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:340 sssd-ad.5.xml:1376 +#: sssd-ipa.5.xml:335 sssd-ad.5.xml:1369 msgid "" "DNS update is by default performed in two steps - IPv4 update and then IPv6 " "update. In some cases it might be desirable to perform IPv4 and IPv6 update " @@ -12714,12 +13115,12 @@ msgstr "" "обновление IPv4 и IPv6 за один шаг." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:352 sssd-ad.5.xml:1388 +#: sssd-ipa.5.xml:347 sssd-ad.5.xml:1381 msgid "dyndns_dot_cacert (string)" msgstr "dyndns_dot_cacert (строка)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:355 sssd-ad.5.xml:1391 +#: sssd-ipa.5.xml:350 sssd-ad.5.xml:1384 msgid "" "This option specifies the file of the certificate authorities certificates " "(in PEM format) in order to verify the remote server TLS certificate when " @@ -12729,17 +13130,17 @@ msgstr "" "PEM) для проверки TLS-сертификата удаленного сервера при использовании DoT." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:361 sssd-ad.5.xml:1397 +#: sssd-ipa.5.xml:356 sssd-ad.5.xml:1390 msgid "Default: None (use global certificate store)" msgstr "По умолчанию: none (использовать глобальное хранилище сертификатов)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:367 sssd-ad.5.xml:1403 +#: sssd-ipa.5.xml:362 sssd-ad.5.xml:1396 msgid "dyndns_dot_cert (string)" msgstr "dyndns_dot_cert (строка)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:370 sssd-ad.5.xml:1406 +#: sssd-ipa.5.xml:365 sssd-ad.5.xml:1399 msgid "" "This option sets the certificate(s) file for authentication for the DoT " "transport to the remote server. The certificate chain file is expected to be " @@ -12750,7 +13151,7 @@ msgstr "" "сертификатов будет в формате PEM." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:376 sssd-ad.5.xml:1412 +#: sssd-ipa.5.xml:371 sssd-ad.5.xml:1405 msgid "" "The <emphasis>dyndns_dot_cert</emphasis> and <emphasis>dyndns_dot_key</" "emphasis> options must be both set to achieve mutual TLS authentication." @@ -12760,17 +13161,17 @@ msgstr "" "emphasis>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:381 sssd-ipa.5.xml:396 sssd-ad.5.xml:1417 sssd-ad.5.xml:1432 +#: sssd-ipa.5.xml:376 sssd-ipa.5.xml:391 sssd-ad.5.xml:1410 sssd-ad.5.xml:1425 msgid "Default: None (Do not use TLS authentication)" msgstr "По умолчанию: none (не использовать TLS-аутентификацию)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:387 sssd-ad.5.xml:1423 +#: sssd-ipa.5.xml:382 sssd-ad.5.xml:1416 msgid "dyndns_dot_key (string)" msgstr "dyndns_dot_key (строка)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:390 sssd-ad.5.xml:1426 +#: sssd-ipa.5.xml:385 sssd-ad.5.xml:1419 msgid "" "This option sets the key file for authenticated encryption for the DoT " "transport to the remote server. The private key file is expected to be in " @@ -12781,19 +13182,19 @@ msgstr "" "закрытого ключа будет в формате PEM." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:402 +#: sssd-ipa.5.xml:397 msgid "ipa_access_order (string)" msgstr "ipa_access_order (строка)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:409 +#: sssd-ipa.5.xml:404 msgid "<emphasis>expire</emphasis>: use IPA's account expiration policy." msgstr "" "<emphasis>expire</emphasis>: использовать политику истечения срока действия " "учетной записи IPA." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:448 +#: sssd-ipa.5.xml:443 msgid "" "Please note that 'access_provider = ipa' must be set for this feature to " "work." @@ -12802,12 +13203,12 @@ msgstr "" "access_provider = ipa»." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:455 +#: sssd-ipa.5.xml:450 msgid "ipa_deskprofile_search_base (string)" msgstr "ipa_deskprofile_search_base (строка)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:458 +#: sssd-ipa.5.xml:453 msgid "" "Optional. Use the given string as search base for Desktop Profile related " "objects." @@ -12816,108 +13217,108 @@ msgstr "" "объектов, связанных с профилями рабочего стола." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:462 sssd-ipa.5.xml:484 +#: sssd-ipa.5.xml:457 sssd-ipa.5.xml:479 msgid "Default: Use base DN" msgstr "По умолчанию: использовать base DN" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:468 +#: sssd-ipa.5.xml:463 msgid "ipa_subid_ranges_search_base (string)" msgstr "ipa_subid_ranges_search_base (строка)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:471 +#: sssd-ipa.5.xml:466 msgid "Deprecated. Use ldap_subid_ranges_search_base instead." msgstr "Не рекомендуется. Используйте ldap_subid_ranges_search_base." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:477 +#: sssd-ipa.5.xml:472 msgid "ipa_hbac_search_base (string)" msgstr "ipa_hbac_search_base (строка)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:480 +#: sssd-ipa.5.xml:475 msgid "Optional. Use the given string as search base for HBAC related objects." msgstr "" "Необязательный параметр. Использовать указанную строку как базу поиска " "объектов, связанных с HBAC." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:490 +#: sssd-ipa.5.xml:485 msgid "ipa_host_search_base (string)" msgstr "ipa_host_search_base (строка)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:493 +#: sssd-ipa.5.xml:488 msgid "Deprecated. Use ldap_host_search_base instead." msgstr "Не рекомендуется. Используйте ldap_host_search_base." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:499 +#: sssd-ipa.5.xml:494 msgid "ipa_selinux_search_base (string)" msgstr "ipa_selinux_search_base (строка)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:502 +#: sssd-ipa.5.xml:497 msgid "Optional. Use the given string as search base for SELinux user maps." msgstr "" "Необязательный параметр. Использовать указанную строку как базу поиска карт " "пользователей SELinux." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:518 +#: sssd-ipa.5.xml:513 msgid "ipa_subdomains_search_base (string)" msgstr "ipa_subdomains_search_base (строка)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:521 +#: sssd-ipa.5.xml:516 msgid "Optional. Use the given string as search base for trusted domains." msgstr "" "Необязательный параметр. Использовать указанную строку как базу поиска " "доверенных доменов." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:530 +#: sssd-ipa.5.xml:525 msgid "Default: the value of <emphasis>cn=trusts,%basedn</emphasis>" msgstr "По умолчанию: значение <emphasis>cn=trusts,%basedn</emphasis>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:537 +#: sssd-ipa.5.xml:532 msgid "ipa_master_domain_search_base (string)" msgstr "ipa_master_domain_search_base (строка)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:540 +#: sssd-ipa.5.xml:535 msgid "Optional. Use the given string as search base for master domain object." msgstr "" "Необязательный параметр. Использовать указанную строку как базу поиска " "объекта главного домена." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:549 +#: sssd-ipa.5.xml:544 msgid "Default: the value of <emphasis>cn=ad,cn=etc,%basedn</emphasis>" msgstr "По умолчанию: значение <emphasis>cn=ad,cn=etc,%basedn</emphasis>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:556 +#: sssd-ipa.5.xml:551 msgid "ipa_views_search_base (string)" msgstr "ipa_views_search_base (строка)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:559 +#: sssd-ipa.5.xml:554 msgid "Optional. Use the given string as search base for views containers." msgstr "" "Необязательный параметр. Использовать указанную строку как базу поиска " "контейнеров просмотра." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:568 +#: sssd-ipa.5.xml:563 msgid "Default: the value of <emphasis>cn=views,cn=accounts,%basedn</emphasis>" msgstr "" "По умолчанию: значение <emphasis>cn=views,cn=accounts,%basedn</emphasis>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:578 +#: sssd-ipa.5.xml:573 msgid "" "The name of the Kerberos realm. This is optional and defaults to the value " "of <quote>ipa_domain</quote>." @@ -12926,7 +13327,7 @@ msgstr "" "значение <quote>ipa_domain</quote>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:582 +#: sssd-ipa.5.xml:577 msgid "" "The name of the Kerberos realm has a special meaning in IPA - it is " "converted into the base DN to use for performing LDAP operations." @@ -12935,12 +13336,12 @@ msgstr "" "DN, которое следует использовать для выполнения действий LDAP." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:590 sssd-ad.5.xml:1441 +#: sssd-ipa.5.xml:585 sssd-ad.5.xml:1434 msgid "krb5_confd_path (string)" msgstr "krb5_confd_path (строка)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:593 sssd-ad.5.xml:1444 +#: sssd-ipa.5.xml:588 sssd-ad.5.xml:1437 msgid "" "Absolute path of a directory where SSSD should place Kerberos configuration " "snippets." @@ -12949,7 +13350,7 @@ msgstr "" "конфигурации Kerberos." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:597 sssd-ad.5.xml:1448 +#: sssd-ipa.5.xml:592 sssd-ad.5.xml:1441 msgid "" "To disable the creation of the configuration snippets set the parameter to " "'none'." @@ -12958,19 +13359,19 @@ msgstr "" "значение «none»." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:601 sssd-ad.5.xml:1452 +#: sssd-ipa.5.xml:596 sssd-ad.5.xml:1445 msgid "" "Default: not set (krb5.include.d subdirectory of SSSD's pubconf directory)" msgstr "" "По умолчанию: не задано (подкаталог krb5.include.d каталога pubconf SSSD)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:608 +#: sssd-ipa.5.xml:603 msgid "ipa_deskprofile_refresh (integer)" msgstr "ipa_deskprofile_refresh (целое число)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:611 +#: sssd-ipa.5.xml:606 msgid "" "The amount of time between lookups of the Desktop Profile rules against the " "IPA server. This will reduce the latency and load on the IPA server if there " @@ -12981,17 +13382,17 @@ msgstr "" "короткое время поступает много запросов на профили рабочего стола." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:618 sssd-ipa.5.xml:648 sssd-ipa.5.xml:664 sssd-ad.5.xml:600 +#: sssd-ipa.5.xml:613 sssd-ipa.5.xml:643 sssd-ipa.5.xml:659 sssd-ad.5.xml:600 msgid "Default: 5 (seconds)" msgstr "По умолчанию: 5 (секунд)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:624 +#: sssd-ipa.5.xml:619 msgid "ipa_deskprofile_request_interval (integer)" msgstr "ipa_deskprofile_request_interval (целое число)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:627 +#: sssd-ipa.5.xml:622 msgid "" "The amount of time between lookups of the Desktop Profile rules against the " "IPA server in case the last request did not return any rule." @@ -13000,17 +13401,17 @@ msgstr "" "сервере IPA, если при последнем запросе не было возвращено ни одного правила." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:632 +#: sssd-ipa.5.xml:627 msgid "Default: 60 (minutes)" msgstr "По умолчанию: 60 (минут)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:638 +#: sssd-ipa.5.xml:633 msgid "ipa_hbac_refresh (integer)" msgstr "ipa_hbac_refresh (целое число)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:641 +#: sssd-ipa.5.xml:636 msgid "" "The amount of time between lookups of the HBAC rules against the IPA server. " "This will reduce the latency and load on the IPA server if there are many " @@ -13021,12 +13422,12 @@ msgstr "" "поступает много запросов на управление доступом." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:654 -msgid "ipa_hbac_selinux (integer)" -msgstr "ipa_hbac_selinux (целое число)" +#: sssd-ipa.5.xml:649 +msgid "ipa_selinux_refresh (integer)" +msgstr "ipa_selinux_refresh (целое число)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:657 +#: sssd-ipa.5.xml:652 msgid "" "The amount of time between lookups of the SELinux maps against the IPA " "server. This will reduce the latency and load on the IPA server if there are " @@ -13037,12 +13438,12 @@ msgstr "" "поступает много запросов на вход пользователей." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:670 +#: sssd-ipa.5.xml:665 msgid "ipa_server_mode (boolean)" msgstr "ipa_server_mode (логическое значение)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:673 +#: sssd-ipa.5.xml:668 msgid "" "This option will be set by the IPA installer (ipa-server-install) " "automatically and denotes if SSSD is running on an IPA server or not." @@ -13051,7 +13452,7 @@ msgstr "" "server-install). Оно определяет, работает SSSD на сервере IPA или нет." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:678 +#: sssd-ipa.5.xml:673 msgid "" "On an IPA server SSSD will lookup users and groups from trusted domains " "directly while on a client it will ask an IPA server." @@ -13060,7 +13461,7 @@ msgstr "" "доменов напрямую, но на клиенте SSSD отправит запрос серверу IPA." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:683 +#: sssd-ipa.5.xml:678 msgid "" "NOTE: There are currently some assumptions that must be met when SSSD is " "running on an IPA server." @@ -13069,7 +13470,7 @@ msgstr "" "сервере IPA." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:688 +#: sssd-ipa.5.xml:683 msgid "" "The <quote>ipa_server</quote> option must be configured to point to the IPA " "server itself. This is already the default set by the IPA installer, so no " @@ -13080,7 +13481,7 @@ msgstr "" "установщиком IPA, поэтому вносить изменения вручную не требуется." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:697 +#: sssd-ipa.5.xml:692 msgid "" "The <quote>full_name_format</quote> option must not be tweaked to only print " "short names for users from trusted domains." @@ -13090,54 +13491,54 @@ msgstr "" "доменов." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:712 +#: sssd-ipa.5.xml:707 msgid "ipa_automount_location (string)" msgstr "ipa_automount_location (строка)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:715 +#: sssd-ipa.5.xml:710 msgid "The automounter location this IPA client will be using" msgstr "" "Расположение автоматического монтирования, которое будет использовать этот " "клиент IPA" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:718 +#: sssd-ipa.5.xml:713 msgid "Default: The location named \"default\"" msgstr "По умолчанию: расположение с именем «default»" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd-ipa.5.xml:726 +#: sssd-ipa.5.xml:721 msgid "VIEWS AND OVERRIDES" msgstr "ПРЕДСТАВЛЕНИЯ И ПЕРЕОПРЕДЕЛЕНИЯ" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:735 +#: sssd-ipa.5.xml:730 msgid "ipa_view_class (string)" msgstr "ipa_view_class (строка)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:738 +#: sssd-ipa.5.xml:733 msgid "Objectclass of the view container." msgstr "Класс объектов контейнера просмотра." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:741 +#: sssd-ipa.5.xml:736 msgid "Default: nsContainer" msgstr "По умолчанию: nsContainer" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:747 +#: sssd-ipa.5.xml:742 msgid "ipa_view_name (string)" msgstr "ipa_view_name (строка)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:750 +#: sssd-ipa.5.xml:745 msgid "Name of the attribute holding the name of the view." msgstr "Имя атрибута, в котором хранится имя представления." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:754 sssd-ldap-attributes.5.xml:496 +#: sssd-ipa.5.xml:749 sssd-ldap-attributes.5.xml:496 #: sssd-ldap-attributes.5.xml:832 sssd-ldap-attributes.5.xml:913 #: sssd-ldap-attributes.5.xml:1010 sssd-ldap-attributes.5.xml:1068 #: sssd-ldap-attributes.5.xml:1226 sssd-ldap-attributes.5.xml:1271 @@ -13145,44 +13546,44 @@ msgid "Default: cn" msgstr "По умолчанию: cn" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:760 +#: sssd-ipa.5.xml:755 msgid "ipa_override_object_class (string)" msgstr "ipa_override_object_class (строка)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:763 +#: sssd-ipa.5.xml:758 msgid "Objectclass of the override objects." msgstr "Объектный класс переопределяемых объектов." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:766 +#: sssd-ipa.5.xml:761 msgid "Default: ipaOverrideAnchor" msgstr "По умолчанию: ipaOverrideAnchor" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:772 +#: sssd-ipa.5.xml:767 msgid "ipa_anchor_uuid (string)" msgstr "ipa_anchor_uuid (строка)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:775 +#: sssd-ipa.5.xml:770 msgid "" "Name of the attribute containing the reference to the original object in a " "remote domain." msgstr "Имя атрибута, содержащего ссылку на исходный объект в удалённом домене." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:779 +#: sssd-ipa.5.xml:774 msgid "Default: ipaAnchorUUID" msgstr "По умолчанию: ipaAnchorUUID" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:785 +#: sssd-ipa.5.xml:780 msgid "ipa_user_override_object_class (string)" msgstr "ipa_user_override_object_class (строка)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:788 +#: sssd-ipa.5.xml:783 msgid "" "Name of the objectclass for user overrides. It is used to determine if the " "found override object is related to a user or a group." @@ -13192,58 +13593,58 @@ msgstr "" "или группой." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:793 +#: sssd-ipa.5.xml:788 msgid "User overrides can contain attributes given by" msgstr "" "Переопределения пользователя могут содержать атрибуты, указанные с помощью" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:796 +#: sssd-ipa.5.xml:791 msgid "ldap_user_name" msgstr "ldap_user_name" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:799 +#: sssd-ipa.5.xml:794 msgid "ldap_user_uid_number" msgstr "ldap_user_uid_number" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:802 +#: sssd-ipa.5.xml:797 msgid "ldap_user_gid_number" msgstr "ldap_user_gid_number" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:805 +#: sssd-ipa.5.xml:800 msgid "ldap_user_gecos" msgstr "ldap_user_gecos" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:808 +#: sssd-ipa.5.xml:803 msgid "ldap_user_home_directory" msgstr "ldap_user_home_directory" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:811 +#: sssd-ipa.5.xml:806 msgid "ldap_user_shell" msgstr "ldap_user_shell" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:814 +#: sssd-ipa.5.xml:809 msgid "ldap_user_ssh_public_key" msgstr "ldap_user_ssh_public_key" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:819 +#: sssd-ipa.5.xml:814 msgid "Default: ipaUserOverride" msgstr "По умолчанию: ipaUserOverride" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:825 +#: sssd-ipa.5.xml:820 msgid "ipa_group_override_object_class (string)" msgstr "ipa_group_override_object_class (строка)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:828 +#: sssd-ipa.5.xml:823 msgid "" "Name of the objectclass for group overrides. It is used to determine if the " "found override object is related to a user or a group." @@ -13253,27 +13654,27 @@ msgstr "" "группой." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:833 +#: sssd-ipa.5.xml:828 msgid "Group overrides can contain attributes given by" msgstr "Переопределения группы могут содержать атрибуты, указанные с помощью" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:836 +#: sssd-ipa.5.xml:831 msgid "ldap_group_name" msgstr "ldap_group_name" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:839 +#: sssd-ipa.5.xml:834 msgid "ldap_group_gid_number" msgstr "ldap_group_gid_number" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:844 +#: sssd-ipa.5.xml:839 msgid "Default: ipaGroupOverride" msgstr "По умолчанию: ipaGroupOverride" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:728 +#: sssd-ipa.5.xml:723 msgid "" "SSSD can handle views and overrides which are offered by FreeIPA 4.1 and " "later version. Since all paths and objectclasses are fixed on the server " @@ -13288,12 +13689,12 @@ msgstr "" "их стандартные значения. <placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd-ipa.5.xml:856 +#: sssd-ipa.5.xml:851 msgid "SUBDOMAINS PROVIDER" msgstr "ПОСТАВЩИК ДАННЫХ ПОДДОМЕНОВ" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:858 +#: sssd-ipa.5.xml:853 msgid "" "The IPA subdomains provider behaves slightly differently if it is configured " "explicitly or implicitly." @@ -13302,7 +13703,7 @@ msgstr "" "неявным образом, его поведение будет немного отличаться." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:862 +#: sssd-ipa.5.xml:857 msgid "" "If the option 'subdomains_provider = ipa' is found in the domain section of " "sssd.conf, the IPA subdomains provider is configured explicitly, and all " @@ -13313,7 +13714,7 @@ msgstr "" "все запросы поддоменов отправляются серверу IPA." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:868 +#: sssd-ipa.5.xml:863 msgid "" "If the option 'subdomains_provider' is not set in the domain section of " "sssd.conf but there is the option 'id_provider = ipa', the IPA subdomains " @@ -13332,12 +13733,12 @@ msgstr "" "сеть, поставщик данных поддоменов включается снова." #. type: Content of: <reference><refentry><refsect1><title> -#: sssd-ipa.5.xml:879 +#: sssd-ipa.5.xml:874 msgid "TRUSTED DOMAINS CONFIGURATION" msgstr "КОНФИГУРАЦИЯ ДОВЕРЕННЫХ ДОМЕНОВ" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-ipa.5.xml:887 +#: sssd-ipa.5.xml:882 #, no-wrap msgid "" "[domain/ipa.domain.com/ad.domain.com]\n" @@ -13347,7 +13748,7 @@ msgstr "" "ad_server = dc.ad.domain.com\n" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:881 +#: sssd-ipa.5.xml:876 msgid "" "Some configuration options can also be set for a trusted domain. A trusted " "domain configuration can be set using the trusted domain subsection as shown " @@ -13362,7 +13763,7 @@ msgstr "" "<placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:892 +#: sssd-ipa.5.xml:887 msgid "" "For more details, see the <citerefentry> <refentrytitle>sssd.conf</" "refentrytitle> <manvolnum>5</manvolnum> </citerefentry> manual page." @@ -13372,7 +13773,7 @@ msgstr "" "citerefentry>." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:899 +#: sssd-ipa.5.xml:894 msgid "" "Different configuration options are tunable for a trusted domain depending " "on whether you are configuring SSSD on an IPA server or an IPA client." @@ -13382,12 +13783,12 @@ msgstr "" "или на клиенте IPA." #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd-ipa.5.xml:904 +#: sssd-ipa.5.xml:899 msgid "OPTIONS TUNABLE ON IPA MASTERS" msgstr "ПАРАМЕТРЫ, КОТОРЫЕ МОЖНО НАСТРОИТЬ НА ОСНОВНЫХ СЕРВЕРАХ IPA" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:906 +#: sssd-ipa.5.xml:901 msgid "" "The following options can be set in a subdomain section on an IPA master:" msgstr "" @@ -13395,47 +13796,47 @@ msgstr "" "параметры:" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:910 sssd-ipa.5.xml:950 +#: sssd-ipa.5.xml:905 sssd-ipa.5.xml:945 msgid "ad_server" msgstr "ad_server" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:913 +#: sssd-ipa.5.xml:908 msgid "ad_backup_server" msgstr "ad_backup_server" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:916 sssd-ipa.5.xml:953 +#: sssd-ipa.5.xml:911 sssd-ipa.5.xml:948 msgid "ad_site" msgstr "ad_site" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:919 +#: sssd-ipa.5.xml:914 msgid "ipa_server" msgstr "ipa_server" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:922 +#: sssd-ipa.5.xml:917 msgid "ipa_backup_server" msgstr "ipa_backup_server" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:925 +#: sssd-ipa.5.xml:920 msgid "ldap_search_base" msgstr "ldap_search_base" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:928 +#: sssd-ipa.5.xml:923 msgid "ldap_user_search_base" msgstr "ldap_user_search_base" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:931 +#: sssd-ipa.5.xml:926 msgid "ldap_group_search_base" msgstr "ldap_group_search_base" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:939 +#: sssd-ipa.5.xml:934 msgid "" "Options prefixed with 'ad_' or 'ipa_' only apply to their respective " "subdomain type." @@ -13444,19 +13845,19 @@ msgstr "" "типу поддомена." #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd-ipa.5.xml:944 +#: sssd-ipa.5.xml:939 msgid "OPTIONS TUNABLE ON IPA CLIENTS" msgstr "ПАРАМЕТРЫ, КОТОРЫЕ МОЖНО НАСТРОИТЬ НА КЛИЕНТАХ IPA" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:946 +#: sssd-ipa.5.xml:941 msgid "" "The following options can be set in an AD subdomain section on an IPA client:" msgstr "" "В разделе поддомена AD на клиенте IPA можно настроить следующие параметры:" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:958 +#: sssd-ipa.5.xml:953 msgid "" "Note that if both options are set, only <quote>ad_server</quote> is " "evaluated." @@ -13465,7 +13866,7 @@ msgstr "" "ad_server</quote>." #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:962 +#: sssd-ipa.5.xml:957 msgid "" "Since any request for a user or a group identity from a trusted domain " "triggered from an IPA client is resolved by the IPA server, the " @@ -13488,7 +13889,7 @@ msgstr "" "refentrytitle> <manvolnum>8</manvolnum> </citerefentry>." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:986 +#: sssd-ipa.5.xml:981 msgid "" "The following example assumes that SSSD is correctly configured and " "example.com is one of the domains in the <replaceable>[sssd]</replaceable> " @@ -13499,7 +13900,7 @@ msgstr "" "примере показаны только параметры, относящиеся к поставщику данных IPA." #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-ipa.5.xml:993 +#: sssd-ipa.5.xml:988 #, no-wrap msgid "" "[domain/example.com]\n" @@ -14471,27 +14872,27 @@ msgid "lxdm" msgstr "lxdm" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:694 +#: sssd-ad.5.xml:699 msgid "sddm" msgstr "sddm" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:699 +#: sssd-ad.5.xml:704 msgid "unity" msgstr "unity" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:704 +#: sssd-ad.5.xml:709 msgid "xdm" msgstr "xdm" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:713 +#: sssd-ad.5.xml:718 msgid "ad_gpo_map_remote_interactive (string)" msgstr "ad_gpo_map_remote_interactive (строка)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:716 +#: sssd-ad.5.xml:721 msgid "" "A comma-separated list of PAM service names for which GPO-based access " "control is evaluated based on the RemoteInteractiveLogonRight and " @@ -14520,7 +14921,7 @@ msgstr "" "если он или хотя бы одна из его групп являются частью параметров политики." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:735 +#: sssd-ad.5.xml:740 msgid "" "Note: Using the Group Policy Management Editor this value is called \"Allow " "log on through Remote Desktop Services\" and \"Deny log on through Remote " @@ -14532,7 +14933,7 @@ msgstr "" "удалённых рабочих столов» («Deny log on through Remote Desktop Services»)." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:750 +#: sssd-ad.5.xml:755 #, no-wrap msgid "" "ad_gpo_map_remote_interactive = +my_pam_service, -sshd\n" @@ -14542,7 +14943,7 @@ msgstr "" " " #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:741 +#: sssd-ad.5.xml:746 msgid "" "It is possible to add another PAM service name to the default set by using " "<quote>+service_name</quote> or to explicitly remove a PAM service name from " @@ -14561,22 +14962,22 @@ msgstr "" "<placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:758 +#: sssd-ad.5.xml:763 msgid "sshd" msgstr "sshd" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:763 +#: sssd-ad.5.xml:768 msgid "cockpit" msgstr "cockpit" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:772 +#: sssd-ad.5.xml:777 msgid "ad_gpo_map_network (string)" msgstr "ad_gpo_map_network (строка)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:775 +#: sssd-ad.5.xml:780 msgid "" "A comma-separated list of PAM service names for which GPO-based access " "control is evaluated based on the NetworkLogonRight and " @@ -14604,7 +15005,7 @@ msgstr "" "хотя бы одна из его групп являются частью параметров политики." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:793 +#: sssd-ad.5.xml:798 msgid "" "Note: Using the Group Policy Management Editor this value is called \"Access " "this computer from the network\" and \"Deny access to this computer from the " @@ -14616,7 +15017,7 @@ msgstr "" "to this computer from the network»)." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:808 +#: sssd-ad.5.xml:813 #, no-wrap msgid "" "ad_gpo_map_network = +my_pam_service, -ftp\n" @@ -14626,7 +15027,7 @@ msgstr "" " " #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:799 +#: sssd-ad.5.xml:804 msgid "" "It is possible to add another PAM service name to the default set by using " "<quote>+service_name</quote> or to explicitly remove a PAM service name from " @@ -14645,22 +15046,22 @@ msgstr "" "<placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:816 +#: sssd-ad.5.xml:821 msgid "ftp" msgstr "ftp" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:821 +#: sssd-ad.5.xml:826 msgid "samba" msgstr "samba" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:830 +#: sssd-ad.5.xml:835 msgid "ad_gpo_map_batch (string)" msgstr "ad_gpo_map_batch (строка)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:833 +#: sssd-ad.5.xml:838 msgid "" "A comma-separated list of PAM service names for which GPO-based access " "control is evaluated based on the BatchLogonRight and DenyBatchLogonRight " @@ -14688,7 +15089,7 @@ msgstr "" "политики." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:851 +#: sssd-ad.5.xml:856 msgid "" "Note: Using the Group Policy Management Editor this value is called \"Allow " "log on as a batch job\" and \"Deny log on as a batch job\"." @@ -14699,7 +15100,7 @@ msgstr "" "a batch job»)." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:865 +#: sssd-ad.5.xml:870 #, no-wrap msgid "" "ad_gpo_map_batch = +my_pam_service, -crond\n" @@ -14709,7 +15110,7 @@ msgstr "" " " #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:856 +#: sssd-ad.5.xml:861 msgid "" "It is possible to add another PAM service name to the default set by using " "<quote>+service_name</quote> or to explicitly remove a PAM service name from " @@ -14728,7 +15129,7 @@ msgstr "" "<placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:868 +#: sssd-ad.5.xml:873 msgid "" "Note: Cron service name may differ depending on Linux distribution used." msgstr "" @@ -14736,17 +15137,17 @@ msgstr "" "дистрибутива Linux." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:874 +#: sssd-ad.5.xml:879 msgid "crond" msgstr "crond" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:883 +#: sssd-ad.5.xml:888 msgid "ad_gpo_map_service (string)" msgstr "ad_gpo_map_service (строка)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:886 +#: sssd-ad.5.xml:891 msgid "" "A comma-separated list of PAM service names for which GPO-based access " "control is evaluated based on the ServiceLogonRight and " @@ -14774,7 +15175,7 @@ msgstr "" "хотя бы одна из его групп являются частью параметров политики." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:904 +#: sssd-ad.5.xml:909 msgid "" "Note: Using the Group Policy Management Editor this value is called \"Allow " "log on as a service\" and \"Deny log on as a service\"." @@ -14784,7 +15185,7 @@ msgstr "" "и «Запретить вход в качестве службы» («Deny log on as a service»)." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:917 +#: sssd-ad.5.xml:922 #, no-wrap msgid "" "ad_gpo_map_service = +my_pam_service\n" @@ -14794,7 +15195,7 @@ msgstr "" " " #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:909 sssd-ad.5.xml:984 +#: sssd-ad.5.xml:914 sssd-ad.5.xml:989 msgid "" "It is possible to add a PAM service name to the default set by using " "<quote>+service_name</quote>. Since the default set is empty, it is not " @@ -14811,12 +15212,12 @@ msgstr "" "id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:927 +#: sssd-ad.5.xml:932 msgid "ad_gpo_map_permit (string)" msgstr "ad_gpo_map_permit (строка)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:930 +#: sssd-ad.5.xml:935 msgid "" "A comma-separated list of PAM service names for which GPO-based access is " "always granted, regardless of any GPO Logon Rights." @@ -14825,7 +15226,7 @@ msgstr "" "доступ на основе GPO, независимо от прав входа GPO." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:944 +#: sssd-ad.5.xml:949 #, no-wrap msgid "" "ad_gpo_map_permit = +my_pam_service, -sudo\n" @@ -14835,7 +15236,7 @@ msgstr "" " " #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:935 +#: sssd-ad.5.xml:940 msgid "" "It is possible to add another PAM service name to the default set by using " "<quote>+service_name</quote> or to explicitly remove a PAM service name from " @@ -14854,22 +15255,22 @@ msgstr "" "конфигурацию: <placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:952 +#: sssd-ad.5.xml:957 msgid "polkit-1" msgstr "polkit-1" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:967 +#: sssd-ad.5.xml:972 msgid "systemd-user" msgstr "systemd-user" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:976 +#: sssd-ad.5.xml:981 msgid "ad_gpo_map_deny (string)" msgstr "ad_gpo_map_deny (строка)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:979 +#: sssd-ad.5.xml:984 msgid "" "A comma-separated list of PAM service names for which GPO-based access is " "always denied, regardless of any GPO Logon Rights." @@ -14878,7 +15279,7 @@ msgstr "" "доступ на основе GPO, независимо от прав входа GPO." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:992 +#: sssd-ad.5.xml:997 #, no-wrap msgid "" "ad_gpo_map_deny = +my_pam_service\n" @@ -14888,12 +15289,12 @@ msgstr "" " " #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:1002 +#: sssd-ad.5.xml:1007 msgid "ad_gpo_default_right (string)" msgstr "ad_gpo_default_right (строка)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1005 +#: sssd-ad.5.xml:1010 msgid "" "This option defines how access control is evaluated for PAM service names " "that are not explicitly listed in one of the ad_gpo_map_* options. This " @@ -14915,52 +15316,52 @@ msgstr "" "доступ для несопоставленных имён служб PAM." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1018 +#: sssd-ad.5.xml:1023 msgid "Supported values for this option include:" msgstr "Для этого параметра поддерживаются следующие значения:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1027 +#: sssd-ad.5.xml:1032 msgid "remote_interactive" msgstr "remote_interactive" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1032 +#: sssd-ad.5.xml:1037 msgid "network" msgstr "network" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1037 +#: sssd-ad.5.xml:1042 msgid "batch" msgstr "batch" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1042 +#: sssd-ad.5.xml:1047 msgid "service" msgstr "service" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1047 +#: sssd-ad.5.xml:1052 msgid "permit" msgstr "permit" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1052 +#: sssd-ad.5.xml:1057 msgid "deny" msgstr "deny" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1058 +#: sssd-ad.5.xml:1063 msgid "Default: deny" msgstr "По умолчанию: deny" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:1064 +#: sssd-ad.5.xml:1069 msgid "ad_maximum_machine_account_password_age (integer)" msgstr "ad_maximum_machine_account_password_age (целое число)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1067 +#: sssd-ad.5.xml:1072 msgid "" "SSSD will check once a day if the machine account password is older than the " "given age in days and try to renew it. A value of 0 will disable the renewal " @@ -14971,17 +15372,17 @@ msgstr "" "его. Значение «0» отключает попытку обновления." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1073 +#: sssd-ad.5.xml:1078 msgid "Default: 30 days" msgstr "По умолчанию: 30 дней" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:1079 +#: sssd-ad.5.xml:1084 msgid "ad_machine_account_password_renewal_opts (string)" msgstr "ad_machine_account_password_renewal_opts (строка)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1082 +#: sssd-ad.5.xml:1087 msgid "" "This option should only be used to test the machine account renewal task. " "The option expects 3 integers and a string separated by a colon (':'). The " @@ -15004,16 +15405,16 @@ msgstr "" "значение «0»." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1096 +#: sssd-ad.5.xml:1101 msgid "" "The optional fourth string value identifies the helper binary which should " "be used for the renewal. Currently <command>adcli</command> and " "<command>realm</command> are supported. If this value is missing or empty in " "the value string <command>realm</command> will be used. Since the helper is " "started as the user SSSD is running as there might be the chance that the " -"renewal will fail if this user does not has permissions to modify the keytab " -"file where the machine account credentials are stored. This will typically " -"be the case for <command>adcli</command>." +"renewal will fail if this user does not have permissions to modify the " +"keytab file where the machine account credentials are stored. This will " +"typically be the case for <command>adcli</command>." msgstr "" "Необязательное четвёртое строковое значение указывает вспомогательную " "утилиту, которая должна использоваться для обновления. В настоящее время " @@ -15026,7 +15427,7 @@ msgstr "" "машины. Обычно это относится <command>adcli</command>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1110 +#: sssd-ad.5.xml:1115 msgid "" "<command>realm</command> is not updating the keytab directly but is calling " "the <command>realmd</command> process, which runs as root user, for this " @@ -15042,18 +15443,18 @@ msgstr "" "работает SSSD." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1119 +#: sssd-ad.5.xml:1124 msgid "Default: 86400:750:300:realm (24h, 12m30s and 5m)" msgstr "" "По умолчанию: 86400:750:300:realm (24 часа, 12 минут 30 секунд и 5 минут)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:1125 +#: sssd-ad.5.xml:1130 msgid "ad_update_samba_machine_account_password (boolean)" msgstr "ad_update_samba_machine_account_password (логическое значение)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1128 +#: sssd-ad.5.xml:1133 msgid "" "If enabled, when SSSD renews the machine account password, it will also be " "updated in Samba's database. This prevents Samba's copy of the machine " @@ -15066,30 +15467,30 @@ msgstr "" "когда программа настроена на использование AD для проверки подлинности." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:1141 -msgid "ad_use_ldaps (bool)" +#: sssd-ad.5.xml:1146 +msgid "ad_use_ldaps (boolean)" msgstr "ad_use_ldaps (логическое значение)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1144 +#: sssd-ad.5.xml:1149 msgid "" "By default SSSD uses the plain LDAP port 389 and the Global Catalog port " -"3628. If this option is set to True SSSD will use the LDAPS port 636 and " -"Global Catalog port 3629 with LDAPS protection. Since AD does not allow to " +"3268. If this option is set to True SSSD will use the LDAPS port 636 and " +"Global Catalog port 3269 with LDAPS protection. Since AD does not allow to " "have multiple encryption layers on a single connection and we still want to " "use SASL/GSSAPI or SASL/GSS-SPNEGO for authentication the SASL security " "property maxssf is set to 0 (zero) for those connections." msgstr "" "По умолчанию SSSD использует простой порт LDAP 389 и порт глобального " -"каталога 3628. Если этот параметр установлен в значение «True», SSSD будет " -"использовать порт LDAPS 636 и порт глобального каталога 3629 с защитой " +"каталога 3268. Если этот параметр установлен в значение «True», SSSD будет " +"использовать порт LDAPS 636 и порт глобального каталога 3269 с защитой " "LDAPS. Так как AD не разрешает использование нескольких слоёв шифрования для " "одного подключения и всё ещё требуется использовать SASL/GSSAPI или SASL/GSS-" "SPNEGO для проверки подлинности, свойство безопасности SASL maxssf для таких " "подключений будет установлено в значение «0» (ноль)." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1164 +#: sssd-ad.5.xml:1169 msgid "" "Optional. This option tells SSSD to automatically update the Active " "Directory DNS server with the IP address of this client. The update is " @@ -15113,18 +15514,6 @@ msgstr "По умолчанию: 3600 (секунд)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:1216 msgid "" -"NOTE: While it is still possible to use the old <emphasis>ipa_dyndns_iface</" -"emphasis> option, users should migrate to using <emphasis>dyndns_iface</" -"emphasis> in their config file." -msgstr "" -"ПРИМЕЧАНИЕ: прежнее имя параметра, <emphasis>ipa_dyndns_iface</emphasis>, " -"всё ещё можно использовать, но пользователям рекомендуется перейти на " -"использование нового имени, <emphasis>dyndns_iface</emphasis>, в файле " -"конфигурации." - -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1222 -msgid "" "Default: Use the IP addresses of the interface which is used for AD LDAP " "connection" msgstr "" @@ -15132,13 +15521,12 @@ msgstr "" "подключения LDAP AD" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1258 +#: sssd-ad.5.xml:1252 msgid "" "How often should the back end perform periodic DNS update in addition to the " -"automatic update performed when the back end goes online. This option is " -"optional and applicable only when dyndns_update is true. Note that the " -"lowest possible value is 60 seconds in-case if value is provided less than " -"60, parameter will assume lowest value only." +"automatic update performed when the back end goes online. This is optional " +"and applicable only when dyndns_update is true. Note that the minimum value " +"is 60 seconds, any specified value below this threshold will default to 60." msgstr "" "Как часто внутреннему серверу следует выполнять периодическое обновление DNS " "в дополнение к автоматическому обновлению, которое выполняется при переходе " @@ -15149,7 +15537,7 @@ msgstr "" "допустимое значение (60 секунд)." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ad.5.xml:1472 +#: sssd-ad.5.xml:1465 msgid "" "The following example assumes that SSSD is correctly configured and " "example.com is one of the domains in the <replaceable>[sssd]</replaceable> " @@ -15160,7 +15548,7 @@ msgstr "" "примере показаны только параметры, относящиеся к поставщику данных AD." #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-ad.5.xml:1479 +#: sssd-ad.5.xml:1472 #, no-wrap msgid "" "[domain/EXAMPLE]\n" @@ -15184,7 +15572,7 @@ msgstr "" "ad_domain = example.com\n" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-ad.5.xml:1499 +#: sssd-ad.5.xml:1492 #, no-wrap msgid "" "access_provider = ldap\n" @@ -15196,7 +15584,7 @@ msgstr "" "ldap_account_expire_policy = ad\n" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ad.5.xml:1495 +#: sssd-ad.5.xml:1488 msgid "" "The AD access control provider checks if the account is expired. It has the " "same effect as the following configuration of the LDAP provider: " @@ -15207,7 +15595,7 @@ msgstr "" "данных LDAP: <placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ad.5.xml:1505 +#: sssd-ad.5.xml:1498 msgid "" "However, unless the <quote>ad</quote> access control provider is explicitly " "configured, the default access provider is <quote>permit</quote>. Please " @@ -15222,7 +15610,7 @@ msgstr "" "подключения, такие как URI LDAP и параметры шифрования." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ad.5.xml:1513 +#: sssd-ad.5.xml:1506 msgid "" "When the autofs provider is set to <quote>ad</quote>, the RFC2307 schema " "attribute mapping (nisMap, nisObject, ...) is used, because these attributes " @@ -15435,9 +15823,9 @@ msgstr "" #: sssd-sudo.5.xml:137 msgid "" "The <emphasis>smart refresh</emphasis> periodically downloads rules that are " -"new or were modified after the last update. Its primary goal is to keep the " -"database growing by fetching only small increments that do not generate " -"large amounts of network traffic." +"new or were modified after the last update. Its primary goal is to grow the " +"database incrementally by fetching only small updates, avoiding large " +"amounts of network traffic." msgstr "" "<emphasis>Интеллектуальное обновление</emphasis> периодически загружает " "правила, которые являются новыми или были изменены после последнего " @@ -15686,27 +16074,33 @@ msgstr "" msgid "" "Depending on the IdP product additional platform specific options might " "follow the name separated by a colon (:). E.g. for Keycloak the base URI for " -"the user and group REST API must be given. For Entra ID this is not needed " -"because there is a generic endpoint for all tenants." -msgstr "" -"В зависимости от используемого продукта IdP, за именем могут следовать " -"дополнительные параметры, специфичные для платформы, разделенные двоеточием " -"(:) . Например, для Keycloak необходимо указать базовый URI для REST API " -"пользователей и групп. Для Entra ID это не требуется, так как для всех " -"арендаторов существует универсальная конечная точка." - -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:78 sssd-idp.5.xml:94 sssd-idp.5.xml:119 +"the user and group REST API must be given. For Entra ID the base URI for the " +"Microsoft Graph API can be given to use sovereign or government cloud " +"endpoints instead of the default (https://graph.microsoft.com/v1.0). E.g. " +"<quote>entra_id:https://graph.microsoft.us/v1.0</quote> for the US " +"government cloud (GCC High)." +msgstr "" +"В зависимости от продукта IdP за именем могут следовать дополнительные " +"параметры, специфичные для платформы, разделённые двоеточием (:). Например, " +"для Keycloak необходимо указать базовый URI для REST API пользователей и " +"групп. Для Entra ID можно указать базовый URI для Microsoft Graph API, чтобы " +"использовать суверенные или государственные облачные конечные точки вместо " +"конечной точки по умолчанию (https://graph.microsoft.com/v1.0). Например, " +"<quote>entra_id:https://graph.microsoft.us/v1.0</quote> для облака " +"правительства США (GCC High)." + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:82 sssd-idp.5.xml:98 sssd-idp.5.xml:123 msgid "Default: Not set (Required)" msgstr "По умолчанию: не задано (обязательно)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:83 +#: sssd-idp.5.xml:87 msgid "idp_client_id (string)" msgstr "idp_client_id (строка)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:86 +#: sssd-idp.5.xml:90 msgid "" "ID of the IdP client used by SSSD to authenticate users and as a client to " "lookup user and group attributes. This client must offer device " @@ -15720,12 +16114,12 @@ msgstr "" "групп." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:99 +#: sssd-idp.5.xml:103 msgid "idp_client_secret (string)" msgstr "idp_client_secret (строка)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:102 +#: sssd-idp.5.xml:106 msgid "" "Password of the IdP client. The password is required for the id_provider. If " "only used as auth_provider it depends on the server side configuration if it " @@ -15736,22 +16130,22 @@ msgstr "" "конфигурации сервера на стороне сервера." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:113 +#: sssd-idp.5.xml:117 msgid "idp_token_endpoint (string)" msgstr "idp_token_endpoint (строка)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:116 +#: sssd-idp.5.xml:120 msgid "IdP endpoint for requesting access tokens." msgstr "Конечная точка IdP для запроса токенов доступа." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:124 +#: sssd-idp.5.xml:128 msgid "idp_device_auth_endpoint (string)" msgstr "idp_device_auth_endpoint (строка)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:127 +#: sssd-idp.5.xml:131 msgid "" "IdP endpoint for device authorization according to RFC-8628. This is " "required for user authentication." @@ -15760,12 +16154,12 @@ msgstr "" "для аутентификации пользователя." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:137 +#: sssd-idp.5.xml:141 msgid "idp_userinfo_endpoint (string)" msgstr "idp_userinfo_endpoint (строка)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:140 +#: sssd-idp.5.xml:144 msgid "" "IdP userinfo endpoint to request user attributes after a successful " "authentication of the user. Required for authentication." @@ -15774,12 +16168,12 @@ msgstr "" "успешной аутентификации пользователя. Требуется для аутентификации." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:150 +#: sssd-idp.5.xml:154 msgid "idp_id_scope (string)" msgstr "idp_id_scope (строка)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:153 +#: sssd-idp.5.xml:157 msgid "" "Scope required for looking up user and group attributes with the REST API. " "The scopes are used by the server to determine which attributes/claims are " @@ -15789,13 +16183,22 @@ msgstr "" "REST API. Области используются сервером для определения того, какие атрибуты/" "инструкции следует возвращать стороне, со стороны которой произошел вызов." +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:163 +msgid "" +"Note: In previous versions of SSSD, this option was expected to already be " +"URL-encoded." +msgstr "" +"Примечание. В предыдущих версиях SSSD предполагалось, что этот параметр уже " +"закодирован в URL." + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:164 +#: sssd-idp.5.xml:172 msgid "idp_auth_scope (string)" msgstr "idp_auth_scope (строка)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:167 +#: sssd-idp.5.xml:175 msgid "" "Scope required during authentication. The scopes are used by the server to " "determine which attributes/claims are returned to the caller." @@ -15805,7 +16208,7 @@ msgstr "" "которым был совершен вызов." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:172 +#: sssd-idp.5.xml:180 msgid "" "Currently the tokens returned during user authentication are not used for " "other purposes hence the only important claim is the subject identifier " @@ -15819,22 +16222,157 @@ msgstr "" "систему. Это может измениться в будущих версиях." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:185 +#: sssd-idp.5.xml:193 +msgid "idp_auth_user_identifier_attr (string)" +msgstr "idp_auth_user_identifier_attr (строка)" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:196 +msgid "" +"Attribute used to identify the authenticated user in userinfo data or token " +"claims." +msgstr "" +"Атрибут, используемый для идентификации аутентифицированного пользователя в " +"данных userinfo или утверждениях токена." + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:200 +msgid "" +"For hybrid Active Directory and Entra ID deployments where " +"<quote>id_provider = ad</quote> and <quote>auth_provider = idp</quote>, this " +"option must be set explicitly. No value is derived from the identity " +"provider, because more than one attribute can link an Entra ID object to its " +"on-premises counterpart and only the administrator knows which one the " +"directory synchronization is configured to use." +msgstr "" +"Для гибридных развёртываний Active Directory и Entra ID, где <quote>" +"id_provider = ad</quote> и <quote>auth_provider = idp</quote>, этот параметр " +"должен быть задан явно. Никакое значение не выводится из поставщика " +"удостоверений, поскольку более одного атрибута могут связывать объект Entra " +"ID с его локальным аналогом, и только администратор знает, какой из них " +"настроена использовать синхронизация каталогов." + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:211 +msgid "" +"Setting this option to <quote>onPremisesImmutableId</quote> is the usual " +"choice for such deployments. Microsoft Entra Connect populates that " +"attribute with the base64-encoded form of the 16-byte Active Directory " +"<quote>objectGUID</quote> when objectGUID is used as the sourceAnchor. SSSD " +"decodes the value and converts the raw bytes with the same conversion used " +"for AD objectGUID attributes, so the result matches the UUID stored in the " +"SSSD cache for the AD user." +msgstr "" +"Установка этого параметра в <quote>onPremisesImmutableId</quote> — обычный " +"выбор для таких развёртываний. Microsoft Entra Connect заполняет этот " +"атрибут представлением 16-байтового Active Directory <quote>objectGUID</" +"quote> в кодировке base64, когда objectGUID используется в качестве " +"sourceAnchor. SSSD декодирует значение и преобразует необработанные байты " +"тем же преобразованием, что и для атрибутов objectGUID AD, поэтому результат " +"совпадает с UUID, хранящимся в кэше SSSD для пользователя AD." + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:224 +msgid "" +"Note that Microsoft Entra Connect 1.1.524.0 and later use <quote>ms-DS-" +"ConsistencyGuid</quote> as the sourceAnchor for user objects instead of " +"<quote>objectGUID</quote>. The value is normally copied from objectGUID for " +"objects that do not have it set yet, in which case the decoded identifier " +"still matches. It does not match if ms-DS-ConsistencyGuid was populated " +"independently, if users were moved between forests or domains, or if a " +"different attribute such as employeeID was selected as the sourceAnchor. See " +"<ulink url=\"https://learn.microsoft.com/en-us/entra/identity/hybrid/connect/" +"plan-connect-design-concepts\"> Microsoft Entra Connect: Design concepts</" +"ulink> for details on sourceAnchor selection." +msgstr "" +"Обратите внимание, что Microsoft Entra Connect 1.1.524.0 и более поздние " +"версии используют <quote>ms-DS-ConsistencyGuid</quote> в качестве " +"sourceAnchor для объектов пользователей вместо <quote>objectGUID</quote>. " +"Обычно значение копируется из objectGUID для объектов, у которых он ещё не " +"установлен, и в этом случае декодированный идентификатор по-прежнему " +"совпадает. Он не совпадает, если ms-DS-ConsistencyGuid был заполнен " +"независимо, если пользователи были перемещены между лесами или доменами, или " +"если в качестве sourceAnchor был выбран другой атрибут, например employeeID. " +"Подробности о выборе sourceAnchor см. в <ulink url=\"https://" +"learn.microsoft.com/en-us/entra/identity/hybrid/connect/plan-connect-design-" +"concepts\"> Microsoft Entra Connect: Design concepts</ulink>." + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:241 +msgid "" +"Microsoft Graph does not return <quote>onPremisesImmutableId</quote> by " +"default. The <quote>idp_userinfo_endpoint</quote> must request it with " +"<quote>$select</quote>, see the example below and <ulink url=\"https://" +"learn.microsoft.com/en-us/graph/api/resources/user\"> the Microsoft Graph " +"user resource type</ulink>." +msgstr "" +"Microsoft Graph по умолчанию не возвращает <quote>onPremisesImmutableId</" +"quote>. Параметр <quote>idp_userinfo_endpoint</quote> должен запрашивать " +"его с помощью <quote>$select</quote>, см. пример ниже и <ulink url=\"https://" +"learn.microsoft.com/en-us/graph/api/resources/user\"> тип ресурса user в " +"Microsoft Graph</ulink>." + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:251 +msgid "" +"If the configured attribute is missing or cannot be decoded (for example " +"cloud-only Entra ID users without <quote>onPremisesImmutableId</quote>), " +"authentication fails. SSSD does not fall back to another attribute when this " +"option is set." +msgstr "" +"Если настроенный атрибут отсутствует или не может быть декодирован " +"(например, облачные пользователи Entra ID без <quote>onPremisesImmutableId</" +"quote>), аутентификация завершается неудачей. SSSD не переключается на " +"другой атрибут, когда этот параметр задан." + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:258 +msgid "" +"Default: not set, <quote>sub</quote> for Keycloak and <quote>id</quote> for " +"other IdP types" +msgstr "" +"По умолчанию: не задано, <quote>sub</quote> для Keycloak и <quote>id</quote> " +"для других типов IdP" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-idp.5.xml:264 msgid "idp_request_timeout (integer)" msgstr "idp_request_timeout (целое число)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:188 +#: sssd-idp.5.xml:267 msgid "Timeout in seconds for an individual request to the IdP." msgstr "Тайм-аут в секундах для отдельного запроса к IdP." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:197 +#: sssd-idp.5.xml:276 +msgid "idp_auto_refresh (boolean)" +msgstr "idp_auto_refresh (логическое значение)" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:279 +msgid "" +"Refresh tokens automatically, after they have reached about half their " +"lifetime." +msgstr "" +"Автоматически обновлять токены после того, как они достигли примерно " +"половины своего срока действия." + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:283 +msgid "" +"Note: Scheduled token refreshes are not preserved across restarts of SSSD." +msgstr "" +"Примечание. Запланированные обновления токенов не сохраняются между " +"перезапусками SSSD." + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-idp.5.xml:292 msgid "idmap_range_min (integer)" msgstr "idmap_range_min (целое число)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:200 +#: sssd-idp.5.xml:295 msgid "" "Specifies the lower (inclusive) bound of the range of POSIX IDs to use for " "mapping IdP users and group to POSIX IDs. It is the first POSIX ID which can " @@ -15846,7 +16384,7 @@ msgstr "" "идентификатор, который может быть использован для сопоставления." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:206 +#: sssd-idp.5.xml:301 msgid "" "The interval between <quote>idmap_range_min</quote> and " "<quote>idmap_range_max</quote> will be split into smaller ranges of size " @@ -15858,18 +16396,18 @@ msgstr "" "quote>, которые будут использоваться отдельным доменом IdP." #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:213 sssd-idp.5.xml:239 include/ldap_id_mapping.xml:139 +#: sssd-idp.5.xml:308 sssd-idp.5.xml:334 include/ldap_id_mapping.xml:139 #: include/ldap_id_mapping.xml:197 msgid "Default: 200000" msgstr "По умолчанию: 200000" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:218 +#: sssd-idp.5.xml:313 msgid "idmap_range_max (integer)" msgstr "idmap_range_max (целое число)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:221 +#: sssd-idp.5.xml:316 msgid "" "Specifies the upper (exclusive) bound of the range of POSIX IDs to use for " "mapping IdP users and groups to POSIX IDs. It is the first POSIX ID which " @@ -15881,58 +16419,101 @@ msgstr "" "идентификатор, который больше не будет использоваться для сопоставления." #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:227 include/ldap_id_mapping.xml:165 +#: sssd-idp.5.xml:322 include/ldap_id_mapping.xml:165 msgid "Default: 2000200000" msgstr "По умолчанию: 2000200000" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:232 +#: sssd-idp.5.xml:327 msgid "idmap_range_size (integer)" msgstr "idmap_range_size (целое число)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:235 +#: sssd-idp.5.xml:330 msgid "Specifies the number of POSIX IDs available for a single IdP domain." msgstr "" "Указывает количество POSIX-идентификаторов, доступных для одного домена IdP." #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-idp.5.xml:251 +#: sssd-idp.5.xml:346 #, no-wrap msgid "" "[domain/entra_id]\n" "id_provider = idp\n" "idp_type = entra_id\n" "idp_client_id = 12345678-abcd-0101-efef-ba9876543210\n" -"idp_client_secret = YOUR-CLIENT-SCERET\n" -"idp_token_endpoint = https://login.microsoftonline.com/TENNANT-ID/oauth2/v2.0/token\n" +"idp_client_secret = YOUR-CLIENT-SECRET\n" +"idp_token_endpoint = https://login.microsoftonline.com/TENANT-ID/oauth2/v2.0/token\n" "idp_userinfo_endpoint = https://graph.microsoft.com/v1.0/me\n" -"idp_device_auth_endpoint = https://login.microsoftonline.com/TENNANT-ID/oauth2/v2.0/devicecode\n" -"idp_id_scope = https%3A%2F%2Fgraph.microsoft.com%2F.default\n" +"idp_device_auth_endpoint = https://login.microsoftonline.com/TENANT-ID/oauth2/v2.0/devicecode\n" +"idp_id_scope = https://graph.microsoft.com/.default\n" "idp_auth_scope = openid profile email\n" msgstr "" "[domain/entra_id]\n" "id_provider = idp\n" "idp_type = entra_id\n" "idp_client_id = 12345678-abcd-0101-efef-ba9876543210\n" -"idp_client_secret = YOUR-CLIENT-SCERET\n" -"idp_token_endpoint = https://login.microsoftonline.com/TENNANT-ID/oauth2/" -"v2.0/token\n" +"idp_client_secret = YOUR-CLIENT-SECRET\n" +"idp_token_endpoint = https://login.microsoftonline.com/TENANT-ID/oauth2/v2.0/" +"token\n" "idp_userinfo_endpoint = https://graph.microsoft.com/v1.0/me\n" -"idp_device_auth_endpoint = https://login.microsoftonline.com/TENNANT-ID/" +"idp_device_auth_endpoint = https://login.microsoftonline.com/TENANT-ID/" +"oauth2/v2.0/devicecode\n" +"idp_id_scope = https://graph.microsoft.com/.default\n" +"idp_auth_scope = openid profile email\n" + +#. type: Content of: <reference><refentry><refsect1><para><programlisting> +#: sssd-idp.5.xml:358 +#, no-wrap +msgid "" +"[domain/ad.example.com]\n" +"id_provider = ad\n" +"auth_provider = idp\n" +"access_provider = permit\n" +"\n" +"ad_domain = ad.example.com\n" +"krb5_realm = AD.EXAMPLE.COM\n" +"\n" +"idp_type = entra_id\n" +"idp_client_id = 12345678-abcd-0101-efef-ba9876543210\n" +"idp_client_secret = YOUR-CLIENT-SECRET\n" +"idp_token_endpoint = https://login.microsoftonline.com/TENANT-ID/oauth2/v2.0/token\n" +"idp_userinfo_endpoint = https://graph.microsoft.com/v1.0/me?$select=id,userPrincipalName,onPremisesImmutableId\n" +"idp_device_auth_endpoint = https://login.microsoftonline.com/TENANT-ID/oauth2/v2.0/devicecode\n" +"idp_id_scope = https://graph.microsoft.com/.default\n" +"idp_auth_scope = openid profile email\n" +"idp_auth_user_identifier_attr = onPremisesImmutableId\n" +msgstr "" +"[domain/ad.example.com]\n" +"id_provider = ad\n" +"auth_provider = idp\n" +"access_provider = permit\n" +"\n" +"ad_domain = ad.example.com\n" +"krb5_realm = AD.EXAMPLE.COM\n" +"\n" +"idp_type = entra_id\n" +"idp_client_id = 12345678-abcd-0101-efef-ba9876543210\n" +"idp_client_secret = YOUR-CLIENT-SECRET\n" +"idp_token_endpoint = https://login.microsoftonline.com/TENANT-ID/oauth2/v2.0/" +"token\n" +"idp_userinfo_endpoint = https://graph.microsoft.com/v1.0/" +"me?$select=id,userPrincipalName,onPremisesImmutableId\n" +"idp_device_auth_endpoint = https://login.microsoftonline.com/TENANT-ID/" "oauth2/v2.0/devicecode\n" -"idp_id_scope = https%3A%2F%2Fgraph.microsoft.com%2F.default\n" +"idp_id_scope = https://graph.microsoft.com/.default\n" "idp_auth_scope = openid profile email\n" +"idp_auth_user_identifier_attr = onPremisesImmutableId\n" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-idp.5.xml:263 +#: sssd-idp.5.xml:377 #, no-wrap msgid "" "[domain/keycloak]\n" "idp_type = keycloak:https://master.keycloak.test:8443/auth/admin/realms/master/\n" "id_provider = idp\n" "idp_client_id = myclient\n" -"idp_client_secret = YOUR-CLIENT-SCERET\n" +"idp_client_secret = YOUR-CLIENT-SECRET\n" "idp_token_endpoint = https://master.keycloak.test:8443/auth/realms/master/protocol/openid-connect/token\n" "idp_userinfo_endpoint = https://master.keycloak.test:8443/auth/realms/master/protocol/openid-connect/userinfo\n" "idp_device_auth_endpoint = https://master.keycloak.test:8443/auth/realms/master/protocol/openid-connect/auth/device\n" @@ -15944,7 +16525,7 @@ msgstr "" "master/\n" "id_provider = idp\n" "idp_client_id = myclient\n" -"idp_client_secret = YOUR-CLIENT-SCERET\n" +"idp_client_secret = YOUR-CLIENT-SECRET\n" "idp_token_endpoint = https://master.keycloak.test:8443/auth/realms/master/" "protocol/openid-connect/token\n" "idp_userinfo_endpoint = https://master.keycloak.test:8443/auth/realms/master/" @@ -15955,13 +16536,32 @@ msgstr "" "idp_auth_scope = openid profile email\n" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-idp.5.xml:250 +#: sssd-idp.5.xml:345 msgid "" "<placeholder type=\"programlisting\" id=\"0\"/> <placeholder " -"type=\"programlisting\" id=\"1\"/>" +"type=\"programlisting\" id=\"1\"/> <placeholder type=\"programlisting\" " +"id=\"2\"/>" msgstr "" "<placeholder type=\"programlisting\" id=\"0\"/> <placeholder " -"type=\"programlisting\" id=\"1\"/>" +"type=\"programlisting\" id=\"1\"/> <placeholder type=\"programlisting\" " +"id=\"2\"/>" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-idp.5.xml:390 +msgid "" +"In the hybrid Active Directory and Entra ID example above, " +"<quote>onPremisesImmutableId</quote> is used during authentication so the " +"IdP result matches the AD objectGUID UUID stored in the SSSD cache. The " +"attribute must be requested via <quote>$select</quote> on the Graph userinfo " +"endpoint and is only populated for users synchronized from Active Directory " +"with objectGUID as the sourceAnchor." +msgstr "" +"В приведённом выше примере гибридного Active Directory и Entra ID <quote>" +"onPremisesImmutableId</quote> используется во время аутентификации, чтобы " +"результат IdP совпадал с UUID objectGUID AD, хранящимся в кэше SSSD. Атрибут " +"должен запрашиваться через <quote>$select</quote> в конечной точке userinfo " +"Graph и заполняется только для пользователей, синхронизированных из Active " +"Directory с objectGUID в качестве sourceAnchor." #. type: Content of: <reference><refentry><refnamediv><refname> #: sssd.8.xml:10 sssd.8.xml:15 @@ -17155,10 +17755,10 @@ msgstr "" #: sssd-krb5.5.xml:291 msgid "" "<emphasis>demand</emphasis> to use FAST. The authentication fails if the " -"server does not require fast." +"server does not support FAST." msgstr "" "<emphasis>demand</emphasis> — требовать использования FAST. Проверка " -"подлинности будет неудачной, если сервер не требует использования FAST." +"подлинности будет неудачной, если сервер не поддерживает FAST." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:296 @@ -18283,7 +18883,7 @@ msgstr "Атрибуты конфигурации" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sss_rpcidmapd.5.xml:69 -msgid "memcache (bool)" +msgid "memcache (boolean)" msgstr "memcache (логическое значение)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> @@ -18355,7 +18955,7 @@ msgstr "" "sss. <placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <refsect1><title> -#: sss_rpcidmapd.5.xml:120 sssd-kcm.8.xml:316 include/seealso.xml:2 +#: sss_rpcidmapd.5.xml:120 sssd-kcm.8.xml:315 include/seealso.xml:2 msgid "SEE ALSO" msgstr "СМ. ТАКЖЕ" @@ -18670,8 +19270,8 @@ msgstr "ПОЛУЧЕНИЕ КЛЮЧЕЙ" #: sss_ssh_knownhosts.1.xml:93 msgid "" "The key lines retrieved from the backend are expected to respect the key " -"format as decribed in the <quote>SSH_KNOWN_HOSTS FILE FORMAT</quote> section " -"of <citerefentry><refentrytitle>sshd</refentrytitle> <manvolnum>8</" +"format as described in the <quote>SSH_KNOWN_HOSTS FILE FORMAT</quote> " +"section of <citerefentry><refentrytitle>sshd</refentrytitle> <manvolnum>8</" "manvolnum></citerefentry>. However, returning only the keytype and the key " "itself is tolerated, in which case, the hostname received as parameter will " "be added before the keytype to output a correctly formatted line. The " @@ -19334,10 +19934,9 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-kcm.8.xml:215 msgid "" -"The KCM service is configured in the <quote>kcm</quote> For a detailed " -"syntax reference, refer to the <quote>FILE FORMAT</quote> section of the " -"<citerefentry> <refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</" -"manvolnum> </citerefentry> manual page." +"For a detailed syntax reference, refer to the <quote>FILE FORMAT</quote> " +"section of the <citerefentry> <refentrytitle>sssd.conf</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry> manual page." msgstr "" "Настройки службы KCM выполняются с помощью <quote>kcm</quote>. Подробные " "сведения о синтаксисе доступны в разделе <quote>ФОРМАТ ФАЙЛА</quote> " @@ -19345,7 +19944,7 @@ msgstr "" "<manvolnum>5</manvolnum> </citerefentry>." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-kcm.8.xml:223 +#: sssd-kcm.8.xml:222 msgid "" "The generic SSSD service options such as <quote>debug_level</quote> or " "<quote>fd_limit</quote> are accepted by the kcm service. Please refer to " @@ -19360,23 +19959,23 @@ msgstr "" "предусмотрено несколько специфичных для KCM параметров." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:234 +#: sssd-kcm.8.xml:233 msgid "socket_path (string)" msgstr "socket_path (строка)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:237 +#: sssd-kcm.8.xml:236 msgid "The socket the KCM service will listen on." msgstr "Сокет, на котором будет ожидать передачи данных служба KCM." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:240 +#: sssd-kcm.8.xml:239 msgid "Default: <replaceable>/var/run/.heim_org.h5l.kcm-socket</replaceable>" msgstr "" "По умолчанию: <replaceable>/var/run/.heim_org.h5l.kcm-socket</replaceable>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:243 +#: sssd-kcm.8.xml:242 msgid "" "<phrase condition=\"have_systemd\"> Note: on platforms where systemd is " "supported, the socket path is overwritten by the one defined in the sssd-" @@ -19387,31 +19986,31 @@ msgstr "" "файле модуля sssd-kcm.socket. </phrase>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:252 +#: sssd-kcm.8.xml:251 msgid "max_ccaches (integer)" msgstr "max_ccaches (целое число)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:255 +#: sssd-kcm.8.xml:254 msgid "How many credential caches does the KCM database allow for all users." msgstr "" "Сколько кэшей учётных данных может содержать база данных KCM для всех " "пользователей." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:259 +#: sssd-kcm.8.xml:258 msgid "Default: 0 (unlimited, only the per-UID quota is enforced)" msgstr "" "По умолчанию: 0 (без ограничений, принудительно применяется только квота для " "отдельного UID)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:264 +#: sssd-kcm.8.xml:263 msgid "max_uid_ccaches (integer)" msgstr "max_uid_ccaches (целое число)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:267 +#: sssd-kcm.8.xml:266 msgid "" "How many credential caches does the KCM database allow per UID. This is " "equivalent to <quote>with how many principals you can kinit</quote>." @@ -19421,63 +20020,63 @@ msgstr "" "выполнить с помощью kinit</quote>." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:272 +#: sssd-kcm.8.xml:271 msgid "Default: 64" msgstr "По умолчанию: 64" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:277 +#: sssd-kcm.8.xml:276 msgid "max_ccache_size (integer)" msgstr "max_ccache_size (целое число)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:280 +#: sssd-kcm.8.xml:279 msgid "" -"How big can a credential cache be per ccache. Each service ticket accounts " -"into this quota." +"How big a credential cache be per ccache. Each service ticket counts toward " +"this quota." msgstr "" -"Максимальный размер кэша учётных данных для отдельного ccache. Эта квота " -"вычисляется сразу для всех билетов служб." +"Максимальный размер кэша учётных данных для отдельного ccache. Каждый билет " +"службы учитывается в этой квоте." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:284 +#: sssd-kcm.8.xml:283 msgid "Default: 65536" msgstr "По умолчанию: 65536" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:289 -msgid "tgt_renewal (bool)" +#: sssd-kcm.8.xml:288 +msgid "tgt_renewal (boolean)" msgstr "tgt_renewal (логическое значение)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:292 +#: sssd-kcm.8.xml:291 msgid "Enables TGT renewals functionality." msgstr "Включает функциональную возможность обновлений TGT." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:295 +#: sssd-kcm.8.xml:294 msgid "Default: False (Automatic renewals disabled)" msgstr "По умолчанию: False (автоматические обновления отключены)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:300 +#: sssd-kcm.8.xml:299 msgid "tgt_renewal_inherit (string)" msgstr "tgt_renewal_inherit (строка)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:303 +#: sssd-kcm.8.xml:302 msgid "Domain to inherit krb5_* options from, for use with TGT renewals." msgstr "" "Домен, от которого наследуются параметры krb5_*, для использования при " "обновлении TGT." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:307 +#: sssd-kcm.8.xml:306 msgid "Default: NULL" msgstr "По умолчанию: NULL" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-kcm.8.xml:318 +#: sssd-kcm.8.xml:317 msgid "" "<citerefentry> <refentrytitle>sssd</refentrytitle><manvolnum>8</manvolnum> </" "citerefentry>, <citerefentry> <refentrytitle>sssd.conf</" @@ -20503,9 +21102,9 @@ msgstr "" "разрешён ли доступ." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap-attributes.5.xml:381 sssd-ldap-attributes.5.xml:395 -msgid "Default: loginDisabled" -msgstr "По умолчанию: loginDisabled" +#: sssd-ldap-attributes.5.xml:381 +msgid "Default: loginDisabled (rfc2307, rfc2307bis and IPA), not set (AD)" +msgstr "По умолчанию: loginDisabled (rfc2307, rfc2307bis и IPA), не задано (AD)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:387 @@ -20521,6 +21120,13 @@ msgstr "" "Если используется ldap_account_expire_policy=nds, этот атрибут определяет, " "до какой даты предоставляется доступ." +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:395 +msgid "" +"Default: loginExpirationTime (rfc2307, rfc2307bis and IPA), not set (AD)" +msgstr "" +"По умолчанию: loginExpirationTime (rfc2307, rfc2307bis и IPA), не задано (AD)" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:401 msgid "ldap_user_nds_login_allowed_time_map (string)" @@ -20537,8 +21143,10 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:409 -msgid "Default: loginAllowedTimeMap" -msgstr "По умолчанию: loginAllowedTimeMap" +msgid "" +"Default: loginAllowedTimeMap (rfc2307, rfc2307bis and IPA), not set (AD)" +msgstr "" +"По умолчанию: loginAllowedTimeMap (rfc2307, rfc2307bis и IPA), не задано (AD)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:415 @@ -21128,9 +21736,9 @@ msgid "The object class of a host entry in LDAP." msgstr "Класс объектов записи узла в LDAP." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap-attributes.5.xml:900 sssd-ldap-attributes.5.xml:997 -msgid "Default: ipService" -msgstr "По умолчанию: ipService" +#: sssd-ldap-attributes.5.xml:900 sssd-ldap-attributes.5.xml:1213 +msgid "Default: ipHost" +msgstr "По умолчанию: ipHost" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:906 @@ -21214,6 +21822,11 @@ msgstr "ldap_service_object_class (строка)" msgid "The object class of a service entry in LDAP." msgstr "Класс объектов записи службы в LDAP." +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:997 +msgid "Default: ipService" +msgstr "По умолчанию: ipService" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1003 msgid "ldap_service_name (string)" @@ -21465,11 +22078,6 @@ msgstr "ldap_iphost_object_class (строка)" msgid "The object class of an iphost entry in LDAP." msgstr "Класс объектов записи IP-узла в LDAP." -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap-attributes.5.xml:1213 -msgid "Default: ipHost" -msgstr "По умолчанию: ipHost" - #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1219 msgid "ldap_iphost_name (string)" @@ -21708,11 +22316,13 @@ msgstr "КОНФИГУРАЦИЯ" msgid "" "[plugins]\n" " localauth = {\n" +" disable = an2ln\n" " module = sssd:/usr/lib64/sssd/modules/sssd_krb5_localauth_plugin.so\n" " }\n" msgstr "" "[plugins]\n" " localauth = {\n" +" disable = an2ln\n" " module = sssd:/usr/lib64/sssd/modules/sssd_krb5_localauth_plugin.so\n" " }\n" @@ -21735,6 +22345,40 @@ msgstr "" "конфигурации SSSD Kerberos. Если этот каталог включен в локальную " "конфигурацию Kerberos, подключаемый модуль будет включен автоматически." +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_localauth_plugin.8.xml:67 +msgid "" +"This configuration snippet also disables the <command>an2ln</command> module " +"provided by MIT Kerberos if SSSD is configured to use the AD or IPA " +"provider. In those environments <command>sssd_krb5_localauth_plugin</" +"command> can reliably map the system user names to Kerberos principals. A " +"fallback to <command>an2ln</command> might cause issues in environments " +"where users have the privilege to create Kerberos principals on their own " +"which might collide with names of other users used in the system. Other " +"modules provided by MIT Kerberos, e.g. <command>k5login</command> are not " +"affected." +msgstr "" +"Этот фрагмент конфигурации также отключает модуль <command>an2ln</command>, " +"предоставляемый MIT Kerberos, если SSSD настроен на использование поставщика " +"AD или IPA. В таких средах <command>sssd_krb5_localauth_plugin</command> " +"может надёжно сопоставлять имена системных пользователей с субъектами " +"Kerberos. Откат к <command>an2ln</command> может вызвать проблемы в средах, " +"где пользователи имеют привилегию самостоятельно создавать субъекты " +"Kerberos, которые могут конфликтовать с именами других пользователей " +"системы. Другие модули, предоставляемые MIT Kerberos, например <command>" +"k5login</command>, не затрагиваются." + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_localauth_plugin.8.xml:79 +msgid "" +"Note: If using <quote>auth_provider = krb5</quote> then " +"<command>sssd_krb5_localauth_plugin</command> is not used, therefore the " +"above text is not applicable." +msgstr "" +"Примечание. Если используется <quote>auth_provider = krb5</quote>, то " +"<command>sssd_krb5_localauth_plugin</command> не используется, поэтому " +"приведённый выше текст неприменим." + #. type: Content of: <variablelist><varlistentry><term> #: include/autofs_attributes.xml:3 msgid "ldap_autofs_map_object_class (string)" @@ -22865,41 +23509,6 @@ msgstr "" "<emphasis>По умолчанию</emphasis>: 0x0070 (то есть фатальные, критические и " "серьёзные ошибки; соответствует указанию значения «2» в десятичной записи)" -#. type: Content of: <refsect1><title> -#: include/local.xml:2 -msgid "THE LOCAL DOMAIN" -msgstr "ЛОКАЛЬНЫЙ ДОМЕН" - -#. type: Content of: <refsect1><para> -#: include/local.xml:4 -msgid "" -"In order to function correctly, a domain with <quote>id_provider=local</" -"quote> must be created and the SSSD must be running." -msgstr "" -"Для корректной работы необходимо создать домен с <quote>id_provider=local</" -"quote> и запустить SSSD." - -#. type: Content of: <refsect1><para> -#: include/local.xml:9 -msgid "" -"The administrator might want to use the SSSD local users instead of " -"traditional UNIX users in cases where the group nesting (see <citerefentry> " -"<refentrytitle>sss_groupadd</refentrytitle> <manvolnum>8</manvolnum> </" -"citerefentry>) is needed. The local users are also useful for testing and " -"development of the SSSD without having to deploy a full remote server. The " -"<command>sss_user*</command> and <command>sss_group*</command> tools use a " -"local LDB storage to store users and groups." -msgstr "" -"Администратор может отдать предпочтение использованию локальных записей " -"пользователей SSSD вместо традиционных записей пользователей UNIX, когда для " -"работы требуется вложенность групп (см. <citerefentry> <refentrytitle>" -"sss_groupadd</refentrytitle> <manvolnum>8</manvolnum> </citerefentry>). " -"Записи локальных пользователей также позволяют выполнить тестирование и " -"разработку SSSD без необходимости развёртывания полного удалённого сервера. " -"Инструменты <command>sss_user*</command> и <command>sss_group*</command> " -"используют локальное хранилище данных LDB для хранения записей пользователей " -"и групп." - #. type: Content of: <refsect1><para> #: include/seealso.xml:4 msgid "" @@ -23649,6 +24258,119 @@ msgstr "" "узла и участника-пользователя. Эта возможность доступна в MIT Kerberos 1.7 и " "выше." +#~ msgid "" +#~ "The data types used are string (no quotes needed), integer and bool (with " +#~ "values of <quote>TRUE/FALSE</quote>)." +#~ msgstr "" +#~ "Используемые типы данных: строка (кавычки не требуются), целое число и " +#~ "логическое значение (возможные значения: <quote>TRUE/FALSE</quote>)." + +#~ msgid "services" +#~ msgstr "services" + +#~ msgid "domains" +#~ msgstr "domains" + +#~ msgid "fd_limit" +#~ msgstr "fd_limit" + +#~ msgid "client_idle_timeout" +#~ msgstr "client_idle_timeout" + +#~ msgid "default_shell" +#~ msgstr "default_shell" + +#~ msgid "" +#~ "Note: This option can also be set per-domain which overwrites the value " +#~ "in [nss] section." +#~ msgstr "" +#~ "Примечание: этот параметр также можно задать для каждого домена отдельно, " +#~ "что будет иметь приоритет над значением в разделе [nss]." + +#~ msgid "These options can be used to configure session recording." +#~ msgstr "Эти параметры можно использовать для настройки записи сеансов." + +#~ msgid "entry_cache_computer_timeout (integer)" +#~ msgstr "entry_cache_computer_timeout (целое число)" + +#~ msgid "" +#~ "How many seconds to keep the local computer entry before asking the " +#~ "backend again" +#~ msgstr "" +#~ "Количество секунд, в течение которого следует хранить запись локального " +#~ "компьютера, прежде чем снова обратиться к внутреннему серверу" + +#~ msgid "" +#~ "Default: <quote>id_provider</quote> is used if it is set and can handle " +#~ "selinux loading requests." +#~ msgstr "" +#~ "По умолчанию: использовать <quote>id_provider</quote>, если этот параметр " +#~ "задан и поддерживает обработку запросов загрузки параметров SELinux." + +#~ msgid "" +#~ "Please see the section <quote>FAILOVER</quote> for more information about " +#~ "the service resolution." +#~ msgstr "" +#~ "Более подробные сведения о разрешении служб доступны в разделе " +#~ "<quote>ОБРАБОТКА ОТКАЗА</quote>." + +#~ msgid "" +#~ "NOTE: On older systems (such as RHEL 5), for this behavior to work " +#~ "reliably, the default Kerberos realm must be set properly in /etc/" +#~ "krb5.conf" +#~ msgstr "" +#~ "ПРИМЕЧАНИЕ: на устаревших системах (например, RHEL 5) для корректной " +#~ "работы в этом режиме необходимо надлежащим образом задать стандартную " +#~ "область Kerberos в /etc/krb5.conf" + +#~ msgid "ipa_hbac_selinux (integer)" +#~ msgstr "ipa_hbac_selinux (целое число)" + +#~ msgid "" +#~ "NOTE: While it is still possible to use the old " +#~ "<emphasis>ipa_dyndns_iface</emphasis> option, users should migrate to " +#~ "using <emphasis>dyndns_iface</emphasis> in their config file." +#~ msgstr "" +#~ "ПРИМЕЧАНИЕ: прежнее имя параметра, <emphasis>ipa_dyndns_iface</emphasis>, " +#~ "всё ещё можно использовать, но пользователям рекомендуется перейти на " +#~ "использование нового имени, <emphasis>dyndns_iface</emphasis>, в файле " +#~ "конфигурации." + +#~ msgid "Default: loginDisabled" +#~ msgstr "По умолчанию: loginDisabled" + +#~ msgid "Default: loginAllowedTimeMap" +#~ msgstr "По умолчанию: loginAllowedTimeMap" + +#~ msgid "THE LOCAL DOMAIN" +#~ msgstr "ЛОКАЛЬНЫЙ ДОМЕН" + +#~ msgid "" +#~ "In order to function correctly, a domain with <quote>id_provider=local</" +#~ "quote> must be created and the SSSD must be running." +#~ msgstr "" +#~ "Для корректной работы необходимо создать домен с " +#~ "<quote>id_provider=local</quote> и запустить SSSD." + +#~ msgid "" +#~ "The administrator might want to use the SSSD local users instead of " +#~ "traditional UNIX users in cases where the group nesting (see " +#~ "<citerefentry> <refentrytitle>sss_groupadd</refentrytitle> <manvolnum>8</" +#~ "manvolnum> </citerefentry>) is needed. The local users are also useful " +#~ "for testing and development of the SSSD without having to deploy a full " +#~ "remote server. The <command>sss_user*</command> and <command>sss_group*</" +#~ "command> tools use a local LDB storage to store users and groups." +#~ msgstr "" +#~ "Администратор может отдать предпочтение использованию локальных записей " +#~ "пользователей SSSD вместо традиционных записей пользователей UNIX, когда " +#~ "для работы требуется вложенность групп (см. <citerefentry> " +#~ "<refentrytitle>sss_groupadd</refentrytitle> <manvolnum>8</manvolnum> </" +#~ "citerefentry>). Записи локальных пользователей также позволяют выполнить " +#~ "тестирование и разработку SSSD без необходимости развёртывания полного " +#~ "удалённого сервера. Инструменты <command>sss_user*</command> и " +#~ "<command>sss_group*</command> используют локальное хранилище данных LDB " +#~ "для хранения записей пользователей и групп." + #~ msgid "subdomain_enumerate (string)" #~ msgstr "subdomain_enumerate (строка)" @@ -24864,9 +25586,6 @@ msgstr "" #~ "Должен ли сертификат узла быть проверенным и действительным, если для " #~ "поставщика данных прокси используется протокол HTTPS." -#~ msgid "verify_host (boolean)" -#~ msgstr "verify_host (логическое значение)" - #~ msgid "" #~ "Whether peer's hostname must match with hostname in its certificate if " #~ "HTTPS protocol is used with the proxy provider." @@ -25133,9 +25852,6 @@ msgstr "" #~ "В следующем примере удаляется секрет с именем «foo». <placeholder " #~ "type=\"programlisting\" id=\"0\"/>" -#~ msgid "EXAMPLE CUSTODIA AND PROXY PROVIDER CONFIGURATION" -#~ msgstr "ПРИМЕР КОНФИГУРАЦИИ CUSTODIA И ПОСТАВЩИКА ДАННЫХ PROXY" - #~ msgid "" #~ "For testing the proxy provider, you need to set up a Custodia server to " #~ "proxy requests to. Please always consult the Custodia documentation, the " diff --git a/src/man/po/sssd-docs.pot b/src/man/po/sssd-docs.pot index 06b02bcf02b..6a9a1bd9083 100644 --- a/src/man/po/sssd-docs.pot +++ b/src/man/po/sssd-docs.pot @@ -6,9 +6,9 @@ #, fuzzy msgid "" msgstr "" -"Project-Id-Version: sssd-docs 2.12.0\n" +"Project-Id-Version: sssd-docs 2.14.0\n" "Report-Msgid-Bugs-To: sssd-devel@redhat.com\n" -"POT-Creation-Date: 2026-01-14 15:00+0000\n" +"POT-Creation-Date: 2026-10-05 16:14+0000\n" "PO-Revision-Date: YEAR-MO-DA HO:MI+ZONE\n" "Last-Translator: FULL NAME <EMAIL@ADDRESS>\n" "Language-Team: LANGUAGE <LL@li.org>\n" @@ -18,7 +18,7 @@ msgstr "" "Content-Transfer-Encoding: 8bit\n" #. type: Content of: <reference><title> -#: sssd.conf.5.xml:8 sssd-ldap.5.xml:5 pam_sss.8.xml:5 pam_sss_gss.8.xml:5 +#: sssd.conf.5.xml:10 sssd-ldap.5.xml:5 pam_sss.8.xml:5 pam_sss_gss.8.xml:5 #: sssd_krb5_locator_plugin.8.xml:5 sssd-simple.5.xml:5 sss-certmap.5.xml:5 #: sssd-ipa.5.xml:5 sssd-ad.5.xml:5 sssd-sudo.5.xml:5 sssd-idp.5.xml:5 #: sssd.8.xml:5 sss_obfuscate.8.xml:5 sss_override.8.xml:5 sssd-krb5.5.xml:5 @@ -31,12 +31,12 @@ msgid "SSSD Manual pages" msgstr "" #. type: Content of: <reference><refentry><refnamediv><refname> -#: sssd.conf.5.xml:13 sssd.conf.5.xml:19 +#: sssd.conf.5.xml:15 sssd.conf.5.xml:21 msgid "sssd.conf" msgstr "" #. type: Content of: <reference><refentry><refmeta><manvolnum> -#: sssd.conf.5.xml:14 sssd-ldap.5.xml:11 sssd-simple.5.xml:11 +#: sssd.conf.5.xml:16 sssd-ldap.5.xml:11 sssd-simple.5.xml:11 #: sss-certmap.5.xml:11 sssd-ipa.5.xml:11 sssd-ad.5.xml:11 sssd-sudo.5.xml:11 #: sssd-idp.5.xml:11 sssd-krb5.5.xml:11 sssd-ifp.5.xml:11 #: sss_rpcidmapd.5.xml:27 sssd-session-recording.5.xml:11 @@ -45,7 +45,7 @@ msgid "5" msgstr "" #. type: Content of: <reference><refentry><refmeta><refmiscinfo> -#: sssd.conf.5.xml:15 sssd-ldap.5.xml:12 sssd-simple.5.xml:12 +#: sssd.conf.5.xml:17 sssd-ldap.5.xml:12 sssd-simple.5.xml:12 #: sss-certmap.5.xml:12 sssd-ipa.5.xml:12 sssd-ad.5.xml:12 sssd-sudo.5.xml:12 #: sssd-idp.5.xml:12 sssd-krb5.5.xml:12 sssd-ifp.5.xml:12 #: sss_rpcidmapd.5.xml:28 sssd-session-recording.5.xml:12 sssd-kcm.8.xml:12 @@ -54,17 +54,17 @@ msgid "File Formats and Conventions" msgstr "" #. type: Content of: <reference><refentry><refnamediv><refpurpose> -#: sssd.conf.5.xml:20 +#: sssd.conf.5.xml:22 msgid "the configuration file for SSSD" msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:24 +#: sssd.conf.5.xml:26 msgid "FILE FORMAT" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd.conf.5.xml:32 +#: sssd.conf.5.xml:34 #, no-wrap msgid "" "<replaceable>[section]</replaceable>\n" @@ -74,7 +74,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:27 +#: sssd.conf.5.xml:29 msgid "" "The file has an ini-style syntax and consists of sections and parameters. A " "section begins with the name of the section in square brackets and continues " @@ -83,47 +83,50 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:39 +#: sssd.conf.5.xml:41 msgid "" -"The data types used are string (no quotes needed), integer and bool (with " -"values of <quote>TRUE/FALSE</quote>)." +"The data types used are string (no quotes needed), integer and boolean (with " +"values of <quote>TRUE/FALSE</quote>). Boolean values are case-insensitive; " +"for example, <quote>TRUE</quote>, <quote>True</quote> and " +"<quote>true</quote> are all equivalent and valid; the same applies to " +"<quote>FALSE</quote>." msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:44 +#: sssd.conf.5.xml:49 msgid "" "A comment line starts with a hash sign (<quote>#</quote>) or a semicolon " "(<quote>;</quote>). Inline comments are not supported." msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:50 +#: sssd.conf.5.xml:55 msgid "" "All sections can have an optional <replaceable>description</replaceable> " "parameter. Its function is only as a label for the section." msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:56 +#: sssd.conf.5.xml:61 msgid "" "<filename>sssd.conf</filename> must be a regular file that is owned, " "readable, and writeable only by 'root'." msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:60 +#: sssd.conf.5.xml:65 msgid "" "<filename>sssd.conf</filename> must be a regular file that is accessible " "only by the user used to run SSSD service or root." msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:66 +#: sssd.conf.5.xml:71 msgid "CONFIGURATION SNIPPETS FROM INCLUDE DIRECTORY" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:69 +#: sssd.conf.5.xml:74 msgid "" "The configuration file <filename>sssd.conf</filename> will include " "configuration snippets using the include directory " @@ -131,7 +134,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:75 +#: sssd.conf.5.xml:80 msgid "" "Any file placed in <filename>conf.d</filename> that ends in " "<quote><filename>.conf</filename></quote> and does not begin with a dot " @@ -140,7 +143,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:83 +#: sssd.conf.5.xml:88 msgid "" "The configuration snippets from <filename>conf.d</filename> have higher " "priority than <filename>sssd.conf</filename> and will override " @@ -153,39 +156,89 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:97 +#: sssd.conf.5.xml:102 msgid "" "The snippet files require the same owner and permissions as " "<filename>sssd.conf</filename>." msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:103 +#: sssd.conf.5.xml:108 +msgid "VENDOR PROVIDED CONFIGURATION" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:111 +msgid "" +"The vendor provided configuration file is installed in " +"<filename>&sssd_vendor_dir;/sssd.conf</filename>, but this file must not be " +"directly edited. It can be completely masked by creating the system specific " +"configuration file <filename>&sssd_conf_dir;/sssd.conf</filename>, or partly " +"overriden by creating config snippets in " +"<filename>&sssd_conf_dir;/conf.d</filename> directory." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><title> +#: sssd.conf.5.xml:120 +msgid "CONFIGURATION FILE HIERARCHY" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:122 +msgid "" +"When sssd reads the configuration it first tries to open the system specific " +"configuration file in <filename>&sssd_conf_dir;/sssd.conf</filename>. If it " +"exists, it is loaded and snippets from " +"<filename>&sssd_conf_dir;/conf.d</filename> are applied. The vendor provided " +"configuration file <filename>&sssd_vendor_dir;/sssd.conf</filename> is " +"completely ignored in this case." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:131 +msgid "" +"If the system specific configuration file " +"<filename>&sssd_conf_dir;/sssd.conf</filename> does not exist, then the " +"vendor configuration file <filename>&sssd_vendor_dir;/sssd.conf</filename> " +"is loaded and snippets from <filename>&sssd_conf_dir;/conf.d</filename> are " +"applied." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd.conf.5.xml:141 msgid "GENERAL OPTIONS" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:105 +#: sssd.conf.5.xml:143 msgid "Following options are usable in more than one configuration sections." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:109 +#: sssd.conf.5.xml:147 msgid "Options usable in all sections" msgstr "" +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:149 +msgid "" +"Note: Below options are ignored in <quote>[session_recording]</quote> " +"section, see <quote>Session recording configuration options</quote> section " +"for more details." +msgstr "" + #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:113 +#: sssd.conf.5.xml:156 msgid "debug_level (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:117 +#: sssd.conf.5.xml:160 msgid "debug (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:120 +#: sssd.conf.5.xml:163 msgid "" "SSSD 1.14 and later also includes the <replaceable>debug</replaceable> alias " "for <replaceable>debug_level</replaceable> as a convenience feature. If both " @@ -194,61 +247,61 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:130 -msgid "debug_timestamps (bool)" +#: sssd.conf.5.xml:173 +msgid "debug_timestamps (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:133 +#: sssd.conf.5.xml:176 msgid "" "Add a timestamp to the debug messages. If journald is enabled for SSSD " "debug logging this option is ignored." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:138 sssd.conf.5.xml:175 sssd.conf.5.xml:337 -#: sssd.conf.5.xml:644 sssd.conf.5.xml:668 sssd.conf.5.xml:875 -#: sssd.conf.5.xml:979 sssd.conf.5.xml:2113 sssd-ldap.5.xml:979 -#: sssd-ldap.5.xml:1134 sssd-ldap.5.xml:1237 sssd-ldap.5.xml:1306 -#: sssd-ldap.5.xml:1714 sssd-ldap.5.xml:1848 sssd-ldap.5.xml:1913 -#: sssd-ipa.5.xml:346 sssd-ad.5.xml:252 sssd-ad.5.xml:367 sssd-ad.5.xml:1180 -#: sssd-ad.5.xml:1382 sssd-krb5.5.xml:358 +#: sssd.conf.5.xml:181 sssd.conf.5.xml:218 sssd.conf.5.xml:380 +#: sssd.conf.5.xml:687 sssd.conf.5.xml:711 sssd.conf.5.xml:827 +#: sssd.conf.5.xml:932 sssd.conf.5.xml:2149 sssd.conf.5.xml:4730 +#: sssd-ldap.5.xml:979 sssd-ldap.5.xml:1134 sssd-ldap.5.xml:1237 +#: sssd-ldap.5.xml:1306 sssd-ldap.5.xml:1714 sssd-ldap.5.xml:1848 +#: sssd-ldap.5.xml:1913 sssd-ipa.5.xml:341 sssd-ad.5.xml:252 sssd-ad.5.xml:367 +#: sssd-ad.5.xml:1180 sssd-ad.5.xml:1375 sssd-krb5.5.xml:358 msgid "Default: true" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:143 -msgid "debug_microseconds (bool)" +#: sssd.conf.5.xml:186 +msgid "debug_microseconds (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:146 +#: sssd.conf.5.xml:189 msgid "" "Add microseconds to the timestamp in debug messages. If journald is enabled " "for SSSD debug logging this option is ignored." msgstr "" #. type: Content of: <variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:151 sssd.conf.5.xml:2040 sssd.conf.5.xml:4158 +#: sssd.conf.5.xml:194 sssd.conf.5.xml:2072 sssd.conf.5.xml:4363 #: sssd-ldap.5.xml:363 sssd-ldap.5.xml:998 sssd-ldap.5.xml:1209 -#: sssd-ldap.5.xml:1663 sssd-ldap.5.xml:1937 sssd-ipa.5.xml:146 -#: sssd-ipa.5.xml:706 sssd-ad.5.xml:1135 sssd-krb5.5.xml:268 +#: sssd-ldap.5.xml:1663 sssd-ldap.5.xml:1937 sssd-ipa.5.xml:141 +#: sssd-ipa.5.xml:701 sssd-ad.5.xml:1140 sssd-idp.5.xml:287 sssd-krb5.5.xml:268 #: sssd-krb5.5.xml:330 sssd-krb5.5.xml:432 include/krb5_options.xml:163 msgid "Default: false" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:156 -msgid "debug_backtrace_enabled (bool)" +#: sssd.conf.5.xml:199 +msgid "debug_backtrace_enabled (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:159 +#: sssd.conf.5.xml:202 msgid "Enable debug backtrace." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:162 +#: sssd.conf.5.xml:205 msgid "" "In case SSSD is run with debug_level less than 9, everything is logged to a " "ring buffer in memory and flushed to a log file on any error up to and " @@ -258,14 +311,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:171 +#: sssd.conf.5.xml:214 msgid "" "Feature is only supported for `logger == files` (i.e. setting doesn't have " "effect for other logger types)." msgstr "" #. type: Content of: outside any tag (error?) -#: sssd.conf.5.xml:111 sssd.conf.5.xml:186 sssd-ldap.5.xml:1754 +#: sssd.conf.5.xml:154 sssd.conf.5.xml:229 sssd-ldap.5.xml:1754 #: sssd-ldap.5.xml:1960 sss-certmap.5.xml:645 sssd-systemtap.5.xml:82 #: sssd-systemtap.5.xml:143 sssd-systemtap.5.xml:236 sssd-systemtap.5.xml:274 #: sssd-systemtap.5.xml:330 sssd-ldap-attributes.5.xml:40 @@ -278,17 +331,17 @@ msgid "<placeholder type=\"variablelist\" id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:184 +#: sssd.conf.5.xml:227 msgid "Options usable in SERVICE and DOMAIN sections" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:188 +#: sssd.conf.5.xml:231 msgid "timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:191 +#: sssd.conf.5.xml:234 msgid "" "Timeout in seconds between heartbeats for this service. This is used to " "ensure that the process is alive and capable of answering requests. Note " @@ -296,34 +349,34 @@ msgid "" msgstr "" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:198 sssd.conf.5.xml:1199 sssd.conf.5.xml:1673 -#: sssd.conf.5.xml:4174 sssd-ldap.5.xml:825 sssd-idp.5.xml:192 +#: sssd.conf.5.xml:241 sssd.conf.5.xml:1155 sssd.conf.5.xml:1665 +#: sssd.conf.5.xml:4379 sssd-ldap.5.xml:825 sssd-idp.5.xml:271 #: include/ldap_id_mapping.xml:270 msgid "Default: 10" msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:208 +#: sssd.conf.5.xml:251 msgid "SPECIAL SECTIONS" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:211 +#: sssd.conf.5.xml:254 msgid "The [sssd] section" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><title> -#: sssd.conf.5.xml:220 +#: sssd.conf.5.xml:263 msgid "Section parameters" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:222 -msgid "services" +#: sssd.conf.5.xml:265 +msgid "services (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:225 +#: sssd.conf.5.xml:268 msgid "" "Comma separated list of services that are started when sssd itself starts. " "<phrase condition=\"have_systemd\"> The services' list is optional on " @@ -332,7 +385,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:234 +#: sssd.conf.5.xml:277 msgid "" "Supported services: nss, pam, ifp <phrase condition=\"with_sudo\">, " "sudo</phrase> <phrase condition=\"with_autofs\">, autofs</phrase> <phrase " @@ -341,20 +394,20 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:241 +#: sssd.conf.5.xml:284 msgid "" "<phrase condition=\"have_systemd\"> By default, all services are disabled " "and the administrator must enable the ones allowed to be used by executing: " "\"systemctl enable sssd-@service@.socket\". </phrase>" msgstr "" -#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:250 -msgid "domains" +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sssd.conf.5.xml:293 sssd.conf.5.xml:4562 +msgid "domains (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:253 +#: sssd.conf.5.xml:296 msgid "" "A domain is a database containing user information. SSSD can use more " "domains at the same time, but at least one must be configured or SSSD won't " @@ -365,19 +418,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:266 sssd.conf.5.xml:3467 +#: sssd.conf.5.xml:309 sssd.conf.5.xml:3598 msgid "re_expression (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:269 +#: sssd.conf.5.xml:312 msgid "" "Default regular expression that describes how to parse the string containing " "user name and domain into these components." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:274 +#: sssd.conf.5.xml:317 msgid "" "Each domain can have an individual regular expression configured. For some " "ID providers there are also default regular expressions. See DOMAIN SECTIONS " @@ -385,12 +438,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:283 sssd.conf.5.xml:3524 +#: sssd.conf.5.xml:326 sssd.conf.5.xml:3655 msgid "full_name_format (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:286 sssd.conf.5.xml:3527 +#: sssd.conf.5.xml:329 sssd.conf.5.xml:3658 msgid "" "A <citerefentry> <refentrytitle>printf</refentrytitle> " "<manvolnum>3</manvolnum> </citerefentry>-compatible format that describes " @@ -399,70 +452,70 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:297 sssd.conf.5.xml:3538 +#: sssd.conf.5.xml:340 sssd.conf.5.xml:3669 msgid "%1$s" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:298 sssd.conf.5.xml:3539 +#: sssd.conf.5.xml:341 sssd.conf.5.xml:3670 msgid "user name" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:301 sssd.conf.5.xml:3542 +#: sssd.conf.5.xml:344 sssd.conf.5.xml:3673 msgid "%2$s" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:304 sssd.conf.5.xml:3545 +#: sssd.conf.5.xml:347 sssd.conf.5.xml:3676 msgid "domain name as specified in the SSSD config file." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:310 sssd.conf.5.xml:3551 +#: sssd.conf.5.xml:353 sssd.conf.5.xml:3682 msgid "%3$s" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:313 sssd.conf.5.xml:3554 +#: sssd.conf.5.xml:356 sssd.conf.5.xml:3685 msgid "" "domain flat name. Mostly usable for Active Directory domains, both directly " "configured or discovered via IPA trusts." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:294 sssd.conf.5.xml:3535 +#: sssd.conf.5.xml:337 sssd.conf.5.xml:3666 msgid "" "The following expansions are supported: <placeholder type=\"variablelist\" " "id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:323 +#: sssd.conf.5.xml:366 msgid "" "Each domain can have an individual format string configured. See DOMAIN " "SECTIONS for more info on this option." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:329 +#: sssd.conf.5.xml:372 msgid "monitor_resolv_conf (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:332 +#: sssd.conf.5.xml:375 msgid "" "Controls if SSSD should monitor the state of resolv.conf to identify when it " "needs to update its internal DNS resolver." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:342 +#: sssd.conf.5.xml:385 msgid "try_inotify (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:345 +#: sssd.conf.5.xml:388 msgid "" "By default, SSSD will attempt to use inotify to monitor configuration files " "changes and will fall back to polling every five seconds if inotify cannot " @@ -470,7 +523,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:351 +#: sssd.conf.5.xml:394 msgid "" "There are some limited situations where it is preferred that we should skip " "even trying to use inotify. In these rare cases, this option should be set " @@ -478,59 +531,59 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:357 +#: sssd.conf.5.xml:400 msgid "" "Default: true on platforms where inotify is supported. False on other " "platforms." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:361 +#: sssd.conf.5.xml:404 msgid "" "Note: this option will have no effect on platforms where inotify is " "unavailable. On these platforms, polling will always be used." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:368 +#: sssd.conf.5.xml:411 msgid "krb5_rcache_dir (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:371 +#: sssd.conf.5.xml:414 msgid "" "Directory on the filesystem where SSSD should store Kerberos replay cache " "files." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:375 +#: sssd.conf.5.xml:418 msgid "" "This option accepts a special value __LIBKRB5_DEFAULTS__ that will instruct " "SSSD to let libkrb5 decide the appropriate location for the replay cache." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:381 +#: sssd.conf.5.xml:424 msgid "" "Default: Distribution-specific and specified at " "build-time. (__LIBKRB5_DEFAULTS__ if not configured)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:388 +#: sssd.conf.5.xml:431 msgid "default_domain_suffix (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:391 +#: sssd.conf.5.xml:434 msgid "" "Please note that this option is deprecated and domain_resolution_order " "should be used." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:395 +#: sssd.conf.5.xml:438 msgid "" "This string will be used as a default domain name for all names without a " "domain name component. The main use case is environments where the primary " @@ -540,7 +593,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:405 +#: sssd.conf.5.xml:448 msgid "" "Please note that if this option is set all users from the primary domain " "have to use their fully qualified name, e.g. user@domain.name, to log " @@ -550,21 +603,21 @@ msgid "" msgstr "" #. type: Content of: <variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:414 sssd-ldap.5.xml:937 sssd-ldap.5.xml:949 -#: sssd-ldap.5.xml:1042 sssd-ad.5.xml:921 sssd-ad.5.xml:996 sssd-krb5.5.xml:468 -#: sssd-ldap-attributes.5.xml:470 sssd-ldap-attributes.5.xml:978 -#: include/ldap_id_mapping.xml:211 include/ldap_id_mapping.xml:222 -#: include/krb5_options.xml:148 +#: sssd.conf.5.xml:457 sssd.conf.5.xml:2006 sssd-ldap.5.xml:937 +#: sssd-ldap.5.xml:949 sssd-ldap.5.xml:1042 sssd-ad.5.xml:926 +#: sssd-ad.5.xml:1001 sssd-krb5.5.xml:468 sssd-ldap-attributes.5.xml:470 +#: sssd-ldap-attributes.5.xml:978 include/ldap_id_mapping.xml:211 +#: include/ldap_id_mapping.xml:222 include/krb5_options.xml:148 msgid "Default: not set" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:419 +#: sssd.conf.5.xml:462 msgid "override_space (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:422 +#: sssd.conf.5.xml:465 msgid "" "This parameter will replace spaces (space bar) with the given character for " "user and group names. e.g. (_). User name "john doe" will be " @@ -574,7 +627,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:431 +#: sssd.conf.5.xml:474 msgid "" "Please note it is a configuration error to use a replacement character that " "might be used in user or group names. If a name contains the replacement " @@ -583,22 +636,22 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:439 +#: sssd.conf.5.xml:482 msgid "Default: not set (spaces will not be replaced)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:444 +#: sssd.conf.5.xml:487 msgid "certificate_verification (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:452 +#: sssd.conf.5.xml:495 msgid "no_ocsp" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:454 +#: sssd.conf.5.xml:497 msgid "" "Disables Online Certificate Status Protocol (OCSP) checks. This might be " "needed if the OCSP servers defined in the certificate are not reachable from " @@ -606,12 +659,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:462 +#: sssd.conf.5.xml:505 msgid "soft_ocsp" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:464 +#: sssd.conf.5.xml:507 msgid "" "If a connection cannot be established to an OCSP responder the OCSP check is " "skipped. This option should be used to allow authentication when the system " @@ -619,61 +672,61 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:474 +#: sssd.conf.5.xml:517 msgid "ocsp_dgst" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:476 +#: sssd.conf.5.xml:519 msgid "" "Digest (hash) function used to create the certificate ID for the OCSP " "request. Allowed values are:" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:480 +#: sssd.conf.5.xml:523 msgid "sha1" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:481 +#: sssd.conf.5.xml:524 msgid "sha256" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:482 +#: sssd.conf.5.xml:525 msgid "sha384" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:483 +#: sssd.conf.5.xml:526 msgid "sha512" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:486 +#: sssd.conf.5.xml:529 msgid "Default: sha1 (to allow compatibility with RFC5019-compliant responder)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:492 +#: sssd.conf.5.xml:535 msgid "no_verification" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:494 +#: sssd.conf.5.xml:537 msgid "" "Disables verification completely. This option should only be used for " "testing." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:500 +#: sssd.conf.5.xml:543 msgid "partial_chain" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:502 +#: sssd.conf.5.xml:545 msgid "" "Allow verification to succeed even if a <replaceable>complete</replaceable> " "chain cannot be built to a self-signed trust-anchor, provided it is possible " @@ -681,12 +734,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:511 +#: sssd.conf.5.xml:554 msgid "ocsp_default_responder=URL" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:513 +#: sssd.conf.5.xml:556 msgid "" "Sets the OCSP default responder which should be used instead of the one " "mentioned in the certificate. URL must be replaced with the URL of the OCSP " @@ -694,24 +747,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:523 +#: sssd.conf.5.xml:566 msgid "ocsp_default_responder_signing_cert=NAME" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:525 +#: sssd.conf.5.xml:568 msgid "" "This option is currently ignored. All needed certificates must be available " "in the PEM file given by pam_cert_db_path." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:533 +#: sssd.conf.5.xml:576 msgid "crl_file=/PATH/TO/CRL/FILE" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:535 +#: sssd.conf.5.xml:578 msgid "" "Use the Certificate Revocation List (CRL) from the given file during the " "verification of the certificate. The CRL must be given in PEM format, see " @@ -720,12 +773,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:548 +#: sssd.conf.5.xml:591 msgid "soft_crl" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:551 +#: sssd.conf.5.xml:594 msgid "" "If a Certificate Revocation List (CRL) is expired ignore the expiration " "time of the CRL and check the related certificates with the expired " @@ -734,7 +787,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:447 +#: sssd.conf.5.xml:490 msgid "" "With this parameter the certificate verification can be tuned with a comma " "separated list of options. Supported options are: <placeholder " @@ -742,46 +795,46 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:564 +#: sssd.conf.5.xml:607 msgid "Unknown options are reported but ignored." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:567 +#: sssd.conf.5.xml:610 msgid "Default: not set, i.e. do not restrict certificate verification" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:573 +#: sssd.conf.5.xml:616 msgid "disable_netlink (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:576 +#: sssd.conf.5.xml:619 msgid "" "SSSD hooks into the netlink interface to monitor changes to routes, " "addresses, links and trigger certain actions." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:581 +#: sssd.conf.5.xml:624 msgid "" "The SSSD state changes caused by netlink events may be undesirable and can " "be disabled by setting this option to 'true'" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:586 +#: sssd.conf.5.xml:629 msgid "Default: false (netlink changes are detected)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:591 -msgid "domain_resolution_order" +#: sssd.conf.5.xml:634 +msgid "domain_resolution_order (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:594 +#: sssd.conf.5.xml:637 msgid "" "Comma separated list of domains and subdomains representing the lookup order " "that will be followed. The list doesn't have to include all possible " @@ -792,7 +845,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:606 +#: sssd.conf.5.xml:649 msgid "" "Please, note that when this option is set the output format of all commands " "is always fully-qualified even when using short names for input. In case " @@ -809,19 +862,20 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:630 sssd.conf.5.xml:1697 sssd.conf.5.xml:4224 -#: sssd-ad.5.xml:187 sssd-ad.5.xml:328 sssd-ad.5.xml:342 sssd-idp.5.xml:108 -#: sssd-idp.5.xml:132 sssd-idp.5.xml:145 sssd-idp.5.xml:159 sssd-idp.5.xml:180 +#: sssd.conf.5.xml:673 sssd.conf.5.xml:1026 sssd.conf.5.xml:1689 +#: sssd.conf.5.xml:4429 sssd-ad.5.xml:187 sssd-ad.5.xml:328 sssd-ad.5.xml:342 +#: sssd-idp.5.xml:112 sssd-idp.5.xml:136 sssd-idp.5.xml:149 sssd-idp.5.xml:167 +#: sssd-idp.5.xml:188 msgid "Default: Not set" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:635 +#: sssd.conf.5.xml:678 msgid "implicit_pac_responder (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:638 +#: sssd.conf.5.xml:681 msgid "" "The PAC responder is enabled automatically for the IPA and AD provider to " "evaluate and check the PAC. If it has to be disabled set this option to " @@ -829,12 +883,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:649 +#: sssd.conf.5.xml:692 msgid "core_dumpable (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:652 +#: sssd.conf.5.xml:695 msgid "" "This option can be used for general system hardening: setting it to 'false' " "forbids core dumps for all SSSD processes to avoid leaking plain text " @@ -843,7 +897,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:660 +#: sssd.conf.5.xml:703 msgid "" "Take a note that this setting has no effect for 'ldap_child', 'krb5_child' " "and 'sssd_pam' as those privileged binaries can have a copy of a host keytab " @@ -852,24 +906,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:673 +#: sssd.conf.5.xml:716 msgid "passkey_verification (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:681 +#: sssd.conf.5.xml:724 msgid "user_verification (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:683 +#: sssd.conf.5.xml:726 msgid "" "Enable or disable the user verification (i.e. PIN, fingerprint) during " "authentication. If enabled, the PIN will always be requested." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:689 +#: sssd.conf.5.xml:732 msgid "" "The default is that the key settings decide what to do. In the IPA or " "kerberos pre-authentication case, this value will be overwritten by the " @@ -877,7 +931,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:676 +#: sssd.conf.5.xml:719 msgid "" "With this parameter the passkey verification can be tuned with a comma " "separated list of options. Supported options are: <placeholder " @@ -885,7 +939,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:213 +#: sssd.conf.5.xml:256 msgid "" "Individual pieces of SSSD functionality are provided by special SSSD " "services that are started and stopped together with SSSD. The services are " @@ -896,12 +950,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:708 +#: sssd.conf.5.xml:751 msgid "SERVICES SECTIONS" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:710 +#: sssd.conf.5.xml:753 msgid "" "Settings that can be used to configure different services are described in " "this section. They should reside in the [<replaceable>$NAME</replaceable>] " @@ -910,42 +964,41 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:717 +#: sssd.conf.5.xml:760 msgid "General service configuration options" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:719 +#: sssd.conf.5.xml:762 msgid "These options can be used to configure any service." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:723 -msgid "fd_limit" +#: sssd.conf.5.xml:766 +msgid "fd_limit (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:726 +#: sssd.conf.5.xml:769 msgid "" "This option specifies the maximum number of file descriptors that may be " -"opened at one time by this SSSD process. On systems where SSSD is granted " -"the CAP_SYS_RESOURCE capability, this will be an absolute setting. On " -"systems without this capability, the resulting value will be the lower value " -"of this or the limits.conf \"hard\" limit." +"opened at one time by this SSSD process. Note this value will be capped by " +"the init system at the startup of SSSD, see e.g. man systemd.exec for " +"details." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:735 +#: sssd.conf.5.xml:776 msgid "Default: 8192 (or limits.conf \"hard\" limit)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:740 -msgid "client_idle_timeout" +#: sssd.conf.5.xml:781 +msgid "client_idle_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:743 +#: sssd.conf.5.xml:784 msgid "" "This option specifies the number of seconds that a client of an SSSD process " "can hold onto a file descriptor without communicating on it. This value is " @@ -955,140 +1008,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:752 +#: sssd.conf.5.xml:793 msgid "Default: 60, KCM: 300" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:757 -msgid "offline_timeout (integer)" +#: sssd.conf.5.xml:798 +msgid "responder_idle_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:760 -msgid "" -"When SSSD switches to offline mode the amount of time before it tries to go " -"back online will increase based upon the time spent disconnected. By " -"default SSSD uses incremental behaviour to calculate delay in between " -"retries. So, the wait time for a given retry will be longer than the wait " -"time for the previous ones. After each unsuccessful attempt to go online, " -"the new interval is recalculated by the following:" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:771 sssd.conf.5.xml:827 -msgid "" -"new_delay = Minimum(old_delay * 2, offline_timeout_max) + " -"random[0...offline_timeout_random_offset]" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:774 -msgid "" -"The offline_timeout default value is 60. The offline_timeout_max default " -"value is 3600. The offline_timeout_random_offset default value is 30. The " -"end result is amount of seconds before next retry." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:780 -msgid "" -"Note that the maximum length of each interval is defined by " -"offline_timeout_max (apart of random part)." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:784 sssd.conf.5.xml:1110 sssd.conf.5.xml:1490 -#: sssd.conf.5.xml:1791 sssd-ldap.5.xml:550 -msgid "Default: 60" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:789 -msgid "offline_timeout_max (integer)" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:792 -msgid "" -"Controls by how much the time between attempts to go online can be " -"incremented following unsuccessful attempts to go online." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:797 -msgid "A value of 0 disables the incrementing behaviour." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:800 -msgid "" -"The value of this parameter should be set in correlation to offline_timeout " -"parameter value." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:804 -msgid "" -"With offline_timeout set to 60 (default value) there is no point in setting " -"offlinet_timeout_max to less than 120 as it will saturate instantly. General " -"rule here should be to set offline_timeout_max to at least 4 times " -"offline_timeout." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:810 -msgid "" -"Although a value between 0 and offline_timeout may be specified, it has the " -"effect of overriding the offline_timeout value so is of little use." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:815 -msgid "Default: 3600" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:820 -msgid "offline_timeout_random_offset (integer)" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:823 -msgid "" -"When SSSD is in offline mode it keeps probing backend servers in specified " -"time intervals:" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:830 -msgid "" -"This parameter controls the value of the random offset used for the above " -"equation. Final random_offset value will be random number in range:" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:835 -msgid "[0 - offline_timeout_random_offset]" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:838 -msgid "A value of 0 disables the random offset addition." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:841 -msgid "Default: 30" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:846 -msgid "responder_idle_timeout" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:849 +#: sssd.conf.5.xml:801 msgid "" "This option specifies the number of seconds that an SSSD responder process " "can be up without being used. This value is limited in order to avoid " @@ -1100,59 +1030,59 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:863 sssd.conf.5.xml:1123 sssd.conf.5.xml:2248 +#: sssd.conf.5.xml:815 sssd.conf.5.xml:1079 sssd.conf.5.xml:2285 #: sssd-ldap.5.xml:377 msgid "Default: 300" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:868 -msgid "cache_first" +#: sssd.conf.5.xml:820 +msgid "cache_first (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:871 +#: sssd.conf.5.xml:823 msgid "" "This option specifies whether the responder should query all caches before " "querying the Data Providers." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:883 +#: sssd.conf.5.xml:835 msgid "NSS configuration options" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:885 +#: sssd.conf.5.xml:837 msgid "" -"These options can be used to configure the Name Service Switch (NSS) " -"service." +"These options can be used to configure the Name Service Switch (NSS) service " +"and should be specified under the <quote>[nss]</quote> section." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:890 +#: sssd.conf.5.xml:843 msgid "enum_cache_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:893 +#: sssd.conf.5.xml:846 msgid "" "How many seconds should nss_sss cache enumerations (requests for info about " "all users)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:897 +#: sssd.conf.5.xml:850 msgid "Default: 120" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:902 +#: sssd.conf.5.xml:855 msgid "entry_cache_nowait_percentage (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:905 +#: sssd.conf.5.xml:858 msgid "" "The entry cache can be set to automatically update entries in the background " "if they are requested beyond a percentage of the entry_cache_timeout value " @@ -1160,7 +1090,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:911 +#: sssd.conf.5.xml:864 msgid "" "For example, if the domain's entry_cache_timeout is set to 30s and " "entry_cache_nowait_percentage is set to 50 (percent), entries that come in " @@ -1170,7 +1100,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:921 +#: sssd.conf.5.xml:874 msgid "" "Valid values for this option are 0-99 and represent a percentage of the " "entry_cache_timeout for each domain. For performance reasons, this " @@ -1179,17 +1109,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:929 sssd.conf.5.xml:2061 +#: sssd.conf.5.xml:882 sssd.conf.5.xml:2093 msgid "Default: 50" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:934 +#: sssd.conf.5.xml:887 msgid "entry_negative_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:937 +#: sssd.conf.5.xml:890 msgid "" "Specifies for how many seconds nss_sss should cache negative cache hits " "(that is, queries for invalid database entries, like nonexistent ones) " @@ -1197,17 +1127,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:943 sssd.conf.5.xml:1685 sssd.conf.5.xml:2085 +#: sssd.conf.5.xml:896 sssd.conf.5.xml:1677 sssd.conf.5.xml:2119 msgid "Default: 15" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:948 +#: sssd.conf.5.xml:901 msgid "filter_users, filter_groups (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:951 +#: sssd.conf.5.xml:904 msgid "" "Exclude certain users or groups from being fetched from the sss NSS " "database. This is particularly useful for system accounts. This option can " @@ -1216,7 +1146,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:959 +#: sssd.conf.5.xml:912 msgid "" "NOTE: The filter_groups option doesn't affect inheritance of nested group " "members, since filtering happens after they are propagated for returning via " @@ -1225,39 +1155,39 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:967 +#: sssd.conf.5.xml:920 msgid "Default: root" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:972 -msgid "filter_users_in_groups (bool)" +#: sssd.conf.5.xml:925 +msgid "filter_users_in_groups (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:975 -msgid "If you want filtered user still be group members set this option to false." +#: sssd.conf.5.xml:928 +msgid "If you want filtered users to remain group members set this option to false" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:986 +#: sssd.conf.5.xml:939 msgid "fallback_homedir (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:989 +#: sssd.conf.5.xml:942 msgid "" "Set a default template for a user's home directory if one is not specified " "explicitly by the domain's data provider." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:994 +#: sssd.conf.5.xml:947 msgid "The available values for this option are the same as for override_homedir." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1000 +#: sssd.conf.5.xml:953 #, no-wrap msgid "" "fallback_homedir = /home/%u\n" @@ -1265,23 +1195,23 @@ msgid "" msgstr "" #. type: Content of: <varlistentry><listitem><para> -#: sssd.conf.5.xml:998 sssd.conf.5.xml:1557 sssd.conf.5.xml:1576 -#: sssd.conf.5.xml:1653 sssd-krb5.5.xml:451 include/override_homedir.xml:78 +#: sssd.conf.5.xml:951 sssd.conf.5.xml:1524 sssd.conf.5.xml:1543 +#: sssd.conf.5.xml:1645 sssd-krb5.5.xml:451 include/override_homedir.xml:78 msgid "example: <placeholder type=\"programlisting\" id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1004 +#: sssd.conf.5.xml:957 msgid "Default: not set (no substitution for unset home directories)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1010 +#: sssd.conf.5.xml:963 msgid "override_shell (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1013 +#: sssd.conf.5.xml:966 msgid "" "Override the login shell for all users. This option supersedes any other " "shell options if it takes effect and can be set either in the [nss] section " @@ -1289,46 +1219,46 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1019 +#: sssd.conf.5.xml:972 msgid "Default: not set (SSSD will use the value retrieved from LDAP)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1025 +#: sssd.conf.5.xml:978 msgid "allowed_shells (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1028 +#: sssd.conf.5.xml:981 msgid "Restrict user shell to one of the listed values. The order of evaluation is:" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1031 +#: sssd.conf.5.xml:984 msgid "1. If the shell is present in <quote>/etc/shells</quote>, it is used." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1035 +#: sssd.conf.5.xml:988 msgid "" "2. If the shell is in the allowed_shells list but not in " "<quote>/etc/shells</quote>, use the value of the shell_fallback parameter." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1040 +#: sssd.conf.5.xml:993 msgid "" "3. If the shell is not in the allowed_shells list and not in " "<quote>/etc/shells</quote>, a nologin shell is used." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1045 +#: sssd.conf.5.xml:998 msgid "The wildcard (*) can be used to allow any shell." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1048 +#: sssd.conf.5.xml:1001 msgid "" "The (*) is useful if you want to use shell_fallback in case that user's " "shell is not in <quote>/etc/shells</quote> and maintaining list of all " @@ -1336,56 +1266,56 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1055 +#: sssd.conf.5.xml:1008 msgid "An empty string for shell is passed as-is to libc." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1058 +#: sssd.conf.5.xml:1011 msgid "" "The <quote>/etc/shells</quote> is only read on SSSD start up, which means " "that a restart of the SSSD is required in case a new shell is installed." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1062 +#: sssd.conf.5.xml:1015 msgid "Default: Not set. The user shell is automatically used." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1067 +#: sssd.conf.5.xml:1020 msgid "vetoed_shells (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1070 +#: sssd.conf.5.xml:1023 msgid "Replace any instance of these shells with the shell_fallback" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1075 +#: sssd.conf.5.xml:1031 msgid "shell_fallback (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1078 +#: sssd.conf.5.xml:1034 msgid "" "The default shell to use if an allowed shell is not installed on the " "machine." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1082 +#: sssd.conf.5.xml:1038 msgid "Default: /bin/sh" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1087 -msgid "default_shell" +#: sssd.conf.5.xml:1043 +msgid "default_shell (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1090 +#: sssd.conf.5.xml:1046 msgid "" "The default shell to use if the provider does not return one during " "lookup. This option can be specified globally in the [nss] section or " @@ -1393,58 +1323,64 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1096 +#: sssd.conf.5.xml:1052 msgid "" "Default: not set (Return NULL if no shell is specified and rely on libc to " "substitute something sensible when necessary, usually /bin/sh)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1103 sssd.conf.5.xml:1483 +#: sssd.conf.5.xml:1059 sssd.conf.5.xml:1450 msgid "get_domains_timeout (int)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1106 sssd.conf.5.xml:1486 +#: sssd.conf.5.xml:1062 sssd.conf.5.xml:1453 msgid "" "Specifies time in seconds for which the list of subdomains will be " "considered valid." msgstr "" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1066 sssd.conf.5.xml:1457 sssd.conf.5.xml:1788 +#: sssd.conf.5.xml:2862 sssd-ldap.5.xml:550 +msgid "Default: 60" +msgstr "" + #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1115 +#: sssd.conf.5.xml:1071 msgid "memcache_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1118 +#: sssd.conf.5.xml:1074 msgid "" "Specifies time in seconds for which records in the in-memory cache will be " "valid. Setting this option to zero will disable the in-memory cache." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1126 +#: sssd.conf.5.xml:1082 msgid "" "WARNING: Disabling the in-memory cache will have significant negative impact " "on SSSD's performance and should only be used for testing." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1132 sssd.conf.5.xml:1157 sssd.conf.5.xml:1182 -#: sssd.conf.5.xml:1207 sssd.conf.5.xml:1234 +#: sssd.conf.5.xml:1088 sssd.conf.5.xml:1113 sssd.conf.5.xml:1138 +#: sssd.conf.5.xml:1163 sssd.conf.5.xml:1190 msgid "" "NOTE: If the environment variable SSS_NSS_USE_MEMCACHE is set to \"NO\", " "client applications will not use the fast in-memory cache." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1140 +#: sssd.conf.5.xml:1096 msgid "memcache_size_passwd (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1143 +#: sssd.conf.5.xml:1099 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for passwd requests. Setting the size to 0 will disable the passwd " @@ -1452,25 +1388,25 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1149 sssd.conf.5.xml:2888 sssd-ldap.5.xml:604 +#: sssd.conf.5.xml:1105 sssd.conf.5.xml:3013 sssd-ldap.5.xml:604 msgid "Default: 8" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1152 sssd.conf.5.xml:1177 sssd.conf.5.xml:1202 -#: sssd.conf.5.xml:1229 +#: sssd.conf.5.xml:1108 sssd.conf.5.xml:1133 sssd.conf.5.xml:1158 +#: sssd.conf.5.xml:1185 msgid "" "WARNING: Disabled or too small in-memory cache can have significant negative " "impact on SSSD's performance." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1165 +#: sssd.conf.5.xml:1121 msgid "memcache_size_group (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1168 +#: sssd.conf.5.xml:1124 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for group requests. Setting the size to 0 will disable the group in-memory " @@ -1478,19 +1414,19 @@ msgid "" msgstr "" #. type: Content of: <variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1174 sssd.conf.5.xml:1226 sssd.conf.5.xml:3656 +#: sssd.conf.5.xml:1130 sssd.conf.5.xml:1182 sssd.conf.5.xml:3835 #: sssd-ldap.5.xml:534 sssd-ldap.5.xml:581 include/failover.xml:116 #: include/krb5_options.xml:11 msgid "Default: 6" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1190 +#: sssd.conf.5.xml:1146 msgid "memcache_size_initgroups (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1193 +#: sssd.conf.5.xml:1149 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for initgroups requests. Setting the size to 0 will disable the initgroups " @@ -1498,12 +1434,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1215 +#: sssd.conf.5.xml:1171 msgid "memcache_size_sid (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1218 +#: sssd.conf.5.xml:1174 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for SID related requests. Only SID-by-ID and ID-by-SID requests are " @@ -1512,12 +1448,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1242 sssd-ifp.5.xml:90 +#: sssd.conf.5.xml:1198 sssd-ifp.5.xml:90 msgid "user_attributes (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1245 +#: sssd.conf.5.xml:1201 msgid "" "Some of the additional NSS responder requests can return more attributes " "than just the POSIX ones defined by the NSS interface. The list of " @@ -1529,103 +1465,110 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1258 +#: sssd.conf.5.xml:1214 msgid "" "To make configuration more easy the NSS responder will check the InfoPipe " "option if it is not set for the NSS responder." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1263 +#: sssd.conf.5.xml:1219 msgid "Default: not set, fallback to InfoPipe option" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1268 +#: sssd.conf.5.xml:1224 msgid "pwfield (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1271 +#: sssd.conf.5.xml:1227 msgid "" "The value that NSS operations that return users or groups will return for " "the <quote>password</quote> field." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1276 -msgid "Default: <quote>*</quote>" +#: sssd.conf.5.xml:1232 +msgid "" +"This option can also be set per-domain, which overwrites the value in the " +"<quote>[nss]</quote> section for that domain. This is particularly useful " +"when using a proxy domain with <option>proxy_lib_name=files</option> and a " +"<option>proxy_pam_target</option> other than " +"<quote>sssd-shadowutils</quote>. In that case, SSSD returns <quote>*</quote> " +"for the password field by default, which causes <command>pam_unix</command> " +"to treat all accounts as locked. Setting <option>pwfield = x</option> in the " +"domain section restores the expected behavior." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1279 -msgid "" -"Note: This option can also be set per-domain which overwrites the value in " -"[nss] section." +#: sssd.conf.5.xml:1246 +msgid "Default: <quote>*</quote>" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1283 +#: sssd.conf.5.xml:1249 msgid "" -"Default: <quote>not set</quote> (remote domains), <quote>x</quote> (proxy " -"domain with nss_files and sssd-shadowutils target)" +"Default (per-domain): <quote>not set</quote> (remote domains), " +"<quote>x</quote> (proxy domain with nss_files and sssd-shadowutils target)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:1292 +#: sssd.conf.5.xml:1258 msgid "PAM configuration options" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:1294 +#: sssd.conf.5.xml:1260 msgid "" "These options can be used to configure the Pluggable Authentication Module " -"(PAM) service." +"(PAM) service and should be specified under the <quote>[pam]</quote> " +"section." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1299 +#: sssd.conf.5.xml:1266 msgid "offline_credentials_expiration (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1302 +#: sssd.conf.5.xml:1269 msgid "" "If the authentication provider is offline, how long should we allow cached " "logins (in days since the last successful online login)." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1307 sssd.conf.5.xml:1320 +#: sssd.conf.5.xml:1274 sssd.conf.5.xml:1287 msgid "Default: 0 (No limit)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1313 +#: sssd.conf.5.xml:1280 msgid "offline_failed_login_attempts (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1316 +#: sssd.conf.5.xml:1283 msgid "" "If the authentication provider is offline, how many failed login attempts " "are allowed." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1326 +#: sssd.conf.5.xml:1293 msgid "offline_failed_login_delay (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1329 +#: sssd.conf.5.xml:1296 msgid "" "The time in minutes which has to pass after offline_failed_login_attempts " "has been reached before a new login attempt is possible." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1334 +#: sssd.conf.5.xml:1301 msgid "" "If set to 0 the user cannot authenticate offline if " "offline_failed_login_attempts has been reached. Only a successful online " @@ -1633,59 +1576,59 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1340 sssd.conf.5.xml:1450 +#: sssd.conf.5.xml:1307 sssd.conf.5.xml:1417 msgid "Default: 5" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1346 +#: sssd.conf.5.xml:1313 msgid "pam_verbosity (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1349 +#: sssd.conf.5.xml:1316 msgid "" "Controls what kind of messages are shown to the user during " "authentication. The higher the number to more messages are displayed." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1354 +#: sssd.conf.5.xml:1321 msgid "Currently sssd supports the following values:" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1357 +#: sssd.conf.5.xml:1324 msgid "<emphasis>0</emphasis>: do not show any message" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1360 +#: sssd.conf.5.xml:1327 msgid "<emphasis>1</emphasis>: show only important messages" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1364 +#: sssd.conf.5.xml:1331 msgid "<emphasis>2</emphasis>: show informational messages" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1367 +#: sssd.conf.5.xml:1334 msgid "<emphasis>3</emphasis>: show all messages and debug information" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1371 sssd.8.xml:63 +#: sssd.conf.5.xml:1338 sssd.8.xml:63 msgid "Default: 1" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1377 +#: sssd.conf.5.xml:1344 msgid "pam_response_filter (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1380 +#: sssd.conf.5.xml:1347 msgid "" "A comma separated list of strings which allows to remove (filter) data sent " "by the PAM responder to pam_sss PAM module. There are different kind of " @@ -1694,51 +1637,51 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1388 +#: sssd.conf.5.xml:1355 msgid "" "While messages already can be controlled with the help of the pam_verbosity " "option this option allows to filter out other kind of responses as well." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1395 +#: sssd.conf.5.xml:1362 msgid "ENV" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1396 +#: sssd.conf.5.xml:1363 msgid "Do not send any environment variables to any service." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1399 +#: sssd.conf.5.xml:1366 msgid "ENV:var_name" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1400 +#: sssd.conf.5.xml:1367 msgid "Do not send environment variable var_name to any service." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1404 +#: sssd.conf.5.xml:1371 msgid "ENV:var_name:service" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1405 +#: sssd.conf.5.xml:1372 msgid "Do not send environment variable var_name to service." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1393 +#: sssd.conf.5.xml:1360 msgid "" "Currently the following filters are supported: <placeholder " "type=\"variablelist\" id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1412 +#: sssd.conf.5.xml:1379 msgid "" "The list of strings can either be the list of filters which would set this " "list of filters and overwrite the defaults. Or each element of the list can " @@ -1749,22 +1692,22 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1423 +#: sssd.conf.5.xml:1390 msgid "Default: ENV:KRB5CCNAME:sudo, ENV:KRB5CCNAME:sudo-i" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1426 +#: sssd.conf.5.xml:1393 msgid "Example: -ENV:KRB5CCNAME:sudo-i will remove the filter from the default list" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1433 +#: sssd.conf.5.xml:1400 msgid "pam_id_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1436 +#: sssd.conf.5.xml:1403 msgid "" "For any PAM request while SSSD is online, the SSSD will attempt to " "immediately update the cached identity information for the user in order to " @@ -1772,7 +1715,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1442 +#: sssd.conf.5.xml:1409 msgid "" "A complete PAM conversation may perform multiple PAM requests, such as " "account management and session opening. This option controls (on a " @@ -1782,17 +1725,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1456 +#: sssd.conf.5.xml:1423 msgid "pam_pwd_expiration_warning (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1459 sssd.conf.5.xml:2912 +#: sssd.conf.5.xml:1426 sssd.conf.5.xml:3037 msgid "Display a warning N days before the password expires." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1462 +#: sssd.conf.5.xml:1429 msgid "" "Please note that the backend server has to provide information about the " "expiration time of the password. If this information is missing, sssd " @@ -1800,7 +1743,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1468 sssd.conf.5.xml:2915 +#: sssd.conf.5.xml:1435 sssd.conf.5.xml:3040 msgid "" "If zero is set, then this filter is not applied, i.e. if the expiration " "warning was received from backend server, it will automatically be " @@ -1808,25 +1751,25 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1473 +#: sssd.conf.5.xml:1440 msgid "" "This setting can be overridden by setting " "<emphasis>pwd_expiration_warning</emphasis> for a particular domain." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1478 sssd.conf.5.xml:3913 sssd-ldap.5.xml:662 +#: sssd.conf.5.xml:1445 sssd.conf.5.xml:4118 sssd-ldap.5.xml:662 #: sssd-ldap.5.xml:1733 sssd.8.xml:79 msgid "Default: 0" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1495 +#: sssd.conf.5.xml:1462 msgid "pam_trusted_users (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1498 +#: sssd.conf.5.xml:1465 msgid "" "Specifies the comma-separated list of UID values or user names that are " "allowed to run PAM conversations against trusted domains. Users not " @@ -1836,73 +1779,73 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1508 +#: sssd.conf.5.xml:1475 msgid "Default: All users are considered trusted by default" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1512 +#: sssd.conf.5.xml:1479 msgid "" "Please note that UID 0 is always allowed to access the PAM responder even in " "case it is not in the pam_trusted_users list." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1519 +#: sssd.conf.5.xml:1486 msgid "pam_public_domains (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1522 +#: sssd.conf.5.xml:1489 msgid "" "Specifies the comma-separated list of domain names that are accessible even " "to untrusted users." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1526 +#: sssd.conf.5.xml:1493 msgid "Two special values for pam_public_domains option are defined:" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1530 +#: sssd.conf.5.xml:1497 msgid "all (Untrusted users are allowed to access all domains in PAM responder.)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1534 +#: sssd.conf.5.xml:1501 msgid "" "none (Untrusted users are not allowed to access any domains PAM in " "responder.)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1538 sssd.conf.5.xml:1563 sssd.conf.5.xml:1582 -#: sssd.conf.5.xml:1824 sssd.conf.5.xml:3842 sssd-ldap.5.xml:1270 +#: sssd.conf.5.xml:1505 sssd.conf.5.xml:1530 sssd.conf.5.xml:1549 +#: sssd.conf.5.xml:1821 sssd.conf.5.xml:4048 sssd-ldap.5.xml:1270 msgid "Default: none" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1543 +#: sssd.conf.5.xml:1510 msgid "pam_account_expired_message (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1546 +#: sssd.conf.5.xml:1513 msgid "" "Allows a custom expiration message to be set, replacing the default " "'Permission denied' message." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1551 +#: sssd.conf.5.xml:1518 msgid "" "Note: Please be aware that message is only printed for the SSH service " "unless pam_verbosity is set to 3 (show all messages and debug information)." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1559 +#: sssd.conf.5.xml:1526 #, no-wrap msgid "" "pam_account_expired_message = Account expired, please contact help desk.\n" @@ -1910,19 +1853,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1568 +#: sssd.conf.5.xml:1535 msgid "pam_account_locked_message (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1571 +#: sssd.conf.5.xml:1538 msgid "" "Allows a custom lockout message to be set, replacing the default 'Permission " "denied' message." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1578 +#: sssd.conf.5.xml:1545 #, no-wrap msgid "" "pam_account_locked_message = Account locked, please contact help desk.\n" @@ -1930,81 +1873,119 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1587 -msgid "pam_passkey_auth (bool)" +#: sssd.conf.5.xml:1554 +msgid "pam_passkey_auth (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1590 +#: sssd.conf.5.xml:1557 msgid "Enable passkey device based authentication." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1593 sssd.conf.5.xml:1910 sssd-ad.5.xml:1286 +#: sssd.conf.5.xml:1560 sssd.conf.5.xml:1907 sssd-ad.5.xml:1279 #: sss_rpcidmapd.5.xml:76 msgid "Default: True" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1598 -msgid "passkey_debug_libfido2 (bool)" +#: sssd.conf.5.xml:1565 +msgid "passkey_debug_libfido2 (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1601 +#: sssd.conf.5.xml:1568 msgid "Enable libfido2 library debug messages." msgstr "" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1604 sssd.conf.5.xml:1618 sssd-ldap.5.xml:727 -#: sssd-ldap.5.xml:752 sssd-ldap.5.xml:848 sssd-ldap.5.xml:1356 -#: sssd-ad.5.xml:506 sssd-ad.5.xml:582 sssd-ad.5.xml:1155 +#: sssd.conf.5.xml:1571 sssd.conf.5.xml:1585 sssd.conf.5.xml:4781 +#: sssd-ldap.5.xml:727 sssd-ldap.5.xml:752 sssd-ldap.5.xml:848 +#: sssd-ldap.5.xml:1356 sssd-ad.5.xml:506 sssd-ad.5.xml:582 sssd-ad.5.xml:1160 #: include/ldap_id_mapping.xml:250 msgid "Default: False" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1609 -msgid "pam_cert_auth (bool)" +#: sssd.conf.5.xml:1576 +msgid "pam_cert_auth (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1612 +#: sssd.conf.5.xml:1579 msgid "" "Enable certificate based Smartcard authentication. Since this requires " "additional communication with the Smartcard which will delay the " "authentication process this option is disabled by default." msgstr "" +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1588 +msgid "" +"Note: In case OpenSC is used for Smartcard access SSSD supports the " +"filesystem caching in OpenSC when enabled in opensc.conf. The cached files " +"are located in a common <quote>opensc</quote> directory in SSSD's state " +"directory. The behaviour can be changed in opensc.conf" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> +#: sssd.conf.5.xml:1597 +#, no-wrap +msgid "" +"app /usr/libexec/sssd/p11_child {\n" +" framework pkcs15 {\n" +" use_file_caching = no;\n" +" }\n" +"}\n" +"app /usr/libexec/sssd/krb5_child {\n" +" framework pkcs15 {\n" +" use_file_caching = no;\n" +" }\n" +"}\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1595 +msgid "Example opensc.conf (*): <placeholder type=\"programlisting\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1610 +msgid "" +"(*) The actual <quote>libexec</quote> directory for p11_child and krb5_child " +"depends on the distribution." +msgstr "" + #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1623 +#: sssd.conf.5.xml:1615 msgid "pam_cert_db_path (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1626 +#: sssd.conf.5.xml:1618 msgid "The path to the certificate database." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1629 sssd.conf.5.xml:2163 sssd.conf.5.xml:4338 +#: sssd.conf.5.xml:1621 sssd.conf.5.xml:2199 sssd.conf.5.xml:4543 msgid "Default:" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1631 sssd.conf.5.xml:2165 +#: sssd.conf.5.xml:1623 sssd.conf.5.xml:2201 msgid "" "/etc/sssd/pki/sssd_auth_ca_db.pem (path to a file with trusted CA " "certificates in PEM format)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1641 +#: sssd.conf.5.xml:1633 msgid "pam_cert_verification (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1644 +#: sssd.conf.5.xml:1636 msgid "" "With this parameter the PAM certificate verification can be tuned with a " "comma separated list of options that override the " @@ -2014,7 +1995,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1655 +#: sssd.conf.5.xml:1647 #, no-wrap msgid "" "pam_cert_verification = partial_chain\n" @@ -2022,58 +2003,58 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1659 +#: sssd.conf.5.xml:1651 msgid "" "Default: not set, i.e. use default <quote>certificate_verification</quote> " "option defined in <quote>[sssd]</quote> section." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1666 +#: sssd.conf.5.xml:1658 msgid "p11_child_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1669 +#: sssd.conf.5.xml:1661 msgid "How many seconds will pam_sss wait for p11_child to finish." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1678 +#: sssd.conf.5.xml:1670 msgid "passkey_child_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1681 +#: sssd.conf.5.xml:1673 msgid "How many seconds will the PAM responder wait for passkey_child to finish." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1690 +#: sssd.conf.5.xml:1682 msgid "pam_app_services (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1693 +#: sssd.conf.5.xml:1685 msgid "" "Which PAM services are permitted to contact domains of type " "<quote>application</quote>" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1702 +#: sssd.conf.5.xml:1694 msgid "pam_p11_allowed_services (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1705 +#: sssd.conf.5.xml:1697 msgid "" "A comma-separated list of PAM service names for which it will be allowed to " "use Smartcards." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1720 +#: sssd.conf.5.xml:1712 #, no-wrap msgid "" "pam_p11_allowed_services = +my_pam_service, -login\n" @@ -2081,7 +2062,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1709 +#: sssd.conf.5.xml:1701 msgid "" "It is possible to add another PAM service name to the default set by using " "<quote>+service_name</quote> or to explicitly remove a PAM service name from " @@ -2093,68 +2074,73 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1724 sssd-ad.5.xml:645 sssd-ad.5.xml:754 sssd-ad.5.xml:812 -#: sssd-ad.5.xml:870 sssd-ad.5.xml:948 +#: sssd.conf.5.xml:1716 sssd-ad.5.xml:645 sssd-ad.5.xml:759 sssd-ad.5.xml:817 +#: sssd-ad.5.xml:875 sssd-ad.5.xml:953 msgid "Default: the default set of PAM service names includes:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1729 sssd-ad.5.xml:649 +#: sssd.conf.5.xml:1721 sssd-ad.5.xml:649 msgid "login" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1734 sssd-ad.5.xml:654 +#: sssd.conf.5.xml:1726 sssd-ad.5.xml:654 msgid "su" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1739 sssd-ad.5.xml:659 +#: sssd.conf.5.xml:1731 sssd-ad.5.xml:659 msgid "su-l" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1744 sssd-ad.5.xml:674 +#: sssd.conf.5.xml:1736 sssd-ad.5.xml:674 msgid "gdm-smartcard" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1749 sssd-ad.5.xml:669 +#: sssd.conf.5.xml:1741 sssd-ad.5.xml:669 msgid "gdm-password" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1754 +#: sssd.conf.5.xml:1746 msgid "gdm-switchable-auth" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1759 sssd-ad.5.xml:679 +#: sssd.conf.5.xml:1751 sssd-ad.5.xml:679 msgid "kdm" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1764 sssd-ad.5.xml:957 +#: sssd.conf.5.xml:1756 sssd-ad.5.xml:694 +msgid "plasmalogin" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:1761 sssd-ad.5.xml:962 msgid "sudo" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1769 sssd-ad.5.xml:962 +#: sssd.conf.5.xml:1766 sssd-ad.5.xml:967 msgid "sudo-i" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1774 +#: sssd.conf.5.xml:1771 msgid "gnome-screensaver" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1782 +#: sssd.conf.5.xml:1779 msgid "p11_wait_for_card_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1785 +#: sssd.conf.5.xml:1782 msgid "" "If Smartcard authentication is required how many extra seconds in addition " "to p11_child_timeout should the PAM responder wait until a Smartcard is " @@ -2162,12 +2148,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1796 +#: sssd.conf.5.xml:1793 msgid "p11_uri (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1799 +#: sssd.conf.5.xml:1796 msgid "" "PKCS#11 URI (see RFC-7512 for details) which can be used to restrict the " "selection of devices used for Smartcard authentication. By default SSSD's " @@ -2178,7 +2164,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1812 +#: sssd.conf.5.xml:1809 #, no-wrap msgid "" "p11_uri = pkcs11:slot-description=My%20Smartcard%20Reader\n" @@ -2186,7 +2172,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1816 +#: sssd.conf.5.xml:1813 #, no-wrap msgid "" "p11_uri = " @@ -2195,7 +2181,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1810 +#: sssd.conf.5.xml:1807 msgid "" "Example: <placeholder type=\"programlisting\" id=\"0\"/> or <placeholder " "type=\"programlisting\" id=\"1\"/> To find suitable URI please check the " @@ -2204,46 +2190,46 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1829 -msgid "pam_initgroups_scheme" +#: sssd.conf.5.xml:1826 +msgid "pam_initgroups_scheme (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1837 +#: sssd.conf.5.xml:1834 msgid "always" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1838 +#: sssd.conf.5.xml:1835 msgid "Always do an online lookup, please note that pam_id_timeout still applies" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1842 +#: sssd.conf.5.xml:1839 msgid "no_session" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1843 +#: sssd.conf.5.xml:1840 msgid "" "Only do an online lookup if there is no active session of the user, i.e. if " "the user is currently not logged in" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1848 sssd-ldap.5.xml:189 +#: sssd.conf.5.xml:1845 sssd-ldap.5.xml:189 msgid "never" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1849 +#: sssd.conf.5.xml:1846 msgid "" "Never force an online lookup, use the data from the cache as long as they " "are not expired" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1832 +#: sssd.conf.5.xml:1829 msgid "" "The PAM responder can force an online lookup to get the current group " "memberships of the user trying to log in. This option controls when this " @@ -2252,31 +2238,31 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1856 +#: sssd.conf.5.xml:1853 msgid "Default: no_session" msgstr "" -#. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:1861 sssd.conf.5.xml:4277 -msgid "pam_gssapi_services" +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1858 +msgid "pam_gssapi_services (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1864 +#: sssd.conf.5.xml:1861 msgid "" "Comma separated list of PAM services that are allowed to try GSSAPI " "authentication using pam_sss_gss.so module." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1869 +#: sssd.conf.5.xml:1866 msgid "" "To disable GSSAPI authentication, set this option to <quote>-</quote> " "(dash)." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1873 sssd.conf.5.xml:1904 sssd.conf.5.xml:1942 +#: sssd.conf.5.xml:1870 sssd.conf.5.xml:1901 sssd.conf.5.xml:1939 msgid "" "Note: This option can also be set per-domain which overwrites the value in " "[pam] section. It can also be set for trusted domain which overwrites the " @@ -2284,7 +2270,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1881 +#: sssd.conf.5.xml:1878 #, no-wrap msgid "" "pam_gssapi_services = sudo, sudo-i\n" @@ -2292,22 +2278,22 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1879 sssd.conf.5.xml:1994 sssd.conf.5.xml:3836 +#: sssd.conf.5.xml:1876 sssd.conf.5.xml:2023 sssd.conf.5.xml:4042 msgid "Example: <placeholder type=\"programlisting\" id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1885 +#: sssd.conf.5.xml:1882 msgid "Default: - (GSSAPI authentication is disabled)" msgstr "" -#. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:1890 sssd.conf.5.xml:4278 -msgid "pam_gssapi_check_upn" +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1887 +msgid "pam_gssapi_check_upn (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1893 +#: sssd.conf.5.xml:1890 msgid "" "If True, SSSD will require that the Kerberos user principal that " "successfully authenticated through GSSAPI can be associated with the user " @@ -2315,19 +2301,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1900 +#: sssd.conf.5.xml:1897 msgid "" -"If False, every user that is able to obtained required service ticket will " +"If False, every user that is able to obtain a required service ticket will " "be authenticated." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1915 -msgid "pam_gssapi_indicators_map" +#: sssd.conf.5.xml:1912 +msgid "pam_gssapi_indicators_map (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1918 +#: sssd.conf.5.xml:1915 msgid "" "Comma separated list of authentication indicators required to be present in " "a Kerberos ticket to access a PAM service that is allowed to try GSSAPI " @@ -2335,7 +2321,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1924 +#: sssd.conf.5.xml:1921 msgid "" "Each element of the list can be either an authentication indicator name or a " "pair <quote>service:indicator</quote>. Indicators not prefixed with the PAM " @@ -2350,7 +2336,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1937 +#: sssd.conf.5.xml:1934 msgid "" "To disable GSSAPI authentication indicator check, set this option to " "<quote>-</quote> (dash). To disable the check for a specific PAM service, " @@ -2358,45 +2344,45 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1948 +#: sssd.conf.5.xml:1945 msgid "" "Following authentication indicators are supported by IPA Kerberos " "deployments:" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1951 +#: sssd.conf.5.xml:1948 msgid "" "pkinit -- pre-authentication using X.509 certificates -- whether stored in " "files or on smart cards." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1954 +#: sssd.conf.5.xml:1951 msgid "" "hardened -- SPAKE pre-authentication or any pre-authentication wrapped in a " "FAST channel." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1957 +#: sssd.conf.5.xml:1954 msgid "radius -- pre-authentication with the help of a RADIUS server." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1960 +#: sssd.conf.5.xml:1957 msgid "" "otp -- pre-authentication using integrated two-factor authentication (2FA or " "one-time password, OTP) in IPA." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1963 +#: sssd.conf.5.xml:1960 msgid "idp -- pre-authentication using external identity provider." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1973 +#: sssd.conf.5.xml:1970 #, no-wrap msgid "" "pam_gssapi_indicators_map = sudo:pkinit, sudo-i:pkinit\n" @@ -2404,7 +2390,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1968 +#: sssd.conf.5.xml:1965 msgid "" "Example: to require access to SUDO services only for users which obtained " "their Kerberos tickets with a X.509 certificate pre-authentication (PKINIT), " @@ -2412,29 +2398,68 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1977 +#: sssd.conf.5.xml:1974 msgid "Default: not set (use of authentication indicators is not required)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1979 +msgid "pam_gssapi_indicators_apply (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1982 +msgid "" +"Comma separated list of triples to assign additional information from the " +"Kerberos ticket, e.g. a SID from the PAC, to authentication indicators." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1988 +msgid "Currently supported is:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:1991 +msgid "SID:S-1-5-[domain]-[RID]:[authentication indicator]" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> +#: sssd.conf.5.xml:2002 +#, no-wrap +msgid "" +"pam_gssapi_indicators_apply = SID:S-1-5-12345-23456-34567-4321:pkinit\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1996 +msgid "" +"Example: To assign a SID, which is e.g. set by Active Directory's " +"Authentication Mechanism Assurance (AMA) if the AD user used a Smartcard for " +"authentication, to the 'pkinit' authentication indicator use: <placeholder " +"type=\"programlisting\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2011 msgid "pam_json_services (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1985 +#: sssd.conf.5.xml:2014 msgid "" "Comma separated list of PAM services which can handle the JSON protocol for " "selecting authentication mechanisms" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1990 +#: sssd.conf.5.xml:2019 msgid "To disable JSON protocol, set this option to <quote>-</quote> (dash)." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1996 +#: sssd.conf.5.xml:2025 #, no-wrap msgid "" "pam_json_services = gdm-switchable-auth\n" @@ -2442,27 +2467,33 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2000 +#: sssd.conf.5.xml:2029 msgid "Default: - (JSON protocol is disabled)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2003 +#: sssd.conf.5.xml:2032 msgid "" "Note: 2-Factor Authentication (2FA) is not supported. If 2FA is required, do " "not activate the JSON protocol." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:2013 +#: sssd.conf.5.xml:2042 msgid "SUDO configuration options" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2015 +#: sssd.conf.5.xml:2044 +msgid "" +"These options can be used to configure the sudo service and should be " +"specified under the <quote>[sudo]</quote> section." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:2048 msgid "" -"These options can be used to configure the sudo service. The detailed " -"instructions for configuration of <citerefentry> " +"The detailed instructions for configuration of <citerefentry> " "<refentrytitle>sudo</refentrytitle> <manvolnum>8</manvolnum> </citerefentry> " "to work with <citerefentry> <refentrytitle>sssd</refentrytitle> " "<manvolnum>8</manvolnum> </citerefentry> are in the manual page " @@ -2471,24 +2502,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2032 -msgid "sudo_timed (bool)" +#: sssd.conf.5.xml:2064 +msgid "sudo_timed (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2035 +#: sssd.conf.5.xml:2067 msgid "" "Whether or not to evaluate the sudoNotBefore and sudoNotAfter attributes " "that implement time-dependent sudoers entries." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2047 +#: sssd.conf.5.xml:2079 msgid "sudo_threshold (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2050 +#: sssd.conf.5.xml:2082 msgid "" "Maximum number of expired rules that can be refreshed at once. If number of " "expired rules is below threshold, those rules are refreshed with " @@ -2499,22 +2530,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:2069 +#: sssd.conf.5.xml:2101 msgid "AUTOFS configuration options" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2071 -msgid "These options can be used to configure the autofs service." +#: sssd.conf.5.xml:2103 +msgid "" +"These options can be used to configure the autofs service and should be " +"specified under the <quote>[autofs]</quote> section." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2075 +#: sssd.conf.5.xml:2109 msgid "autofs_negative_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2078 +#: sssd.conf.5.xml:2112 msgid "" "Specifies for how many seconds should the autofs responder negative cache " "hits (that is, queries for invalid map entries, like nonexistent ones) " @@ -2522,22 +2555,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:2094 +#: sssd.conf.5.xml:2128 msgid "SSH configuration options" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2096 -msgid "These options can be used to configure the SSH service." +#: sssd.conf.5.xml:2130 +msgid "" +"These options can be used to configure the SSH service and should be " +"specified under the <quote>[ssh]</quote> section." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2100 -msgid "ssh_use_certificate_keys (bool)" +#: sssd.conf.5.xml:2136 +msgid "ssh_use_certificate_keys (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2103 +#: sssd.conf.5.xml:2139 msgid "" "If set to true the <command>sss_ssh_authorizedkeys</command> will return ssh " "keys derived from the public key of X.509 certificates stored in the user " @@ -2547,12 +2582,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2118 +#: sssd.conf.5.xml:2154 msgid "ssh_use_certificate_matching_rules (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2121 +#: sssd.conf.5.xml:2157 msgid "" "By default the ssh responder will use all available certificate matching " "rules to filter the certificates so that ssh keys are only derived from the " @@ -2562,7 +2597,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2130 +#: sssd.conf.5.xml:2166 msgid "" "There are two special key words 'all_rules' and 'no_rules' which will enable " "all or no rules, respectively. The latter means that no certificates will be " @@ -2570,7 +2605,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2137 +#: sssd.conf.5.xml:2173 msgid "" "If no rules are configured using 'all_rules' will enable a default rule " "which enables all certificates suitable for client authentication. This is " @@ -2579,38 +2614,38 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2144 +#: sssd.conf.5.xml:2180 msgid "" "A non-existing rule name is considered an error. If as a result no rule is " "selected all certificates will be ignored." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2149 +#: sssd.conf.5.xml:2185 msgid "" "Default: not set, equivalent to 'all_rules', all found rules or the default " "rule are used" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2155 +#: sssd.conf.5.xml:2191 msgid "ca_db (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2158 +#: sssd.conf.5.xml:2194 msgid "" "Path to a storage of trusted CA certificates. The option is used to validate " "user certificates before deriving public ssh keys from them." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:2178 +#: sssd.conf.5.xml:2214 msgid "PAC responder configuration options" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2180 +#: sssd.conf.5.xml:2216 msgid "" "The PAC responder works together with the authorization data plugin for MIT " "Kerberos sssd_pac_plugin.so and a sub-domain provider. The plugin sends the " @@ -2621,7 +2656,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:2189 +#: sssd.conf.5.xml:2225 msgid "" "If the remote user does not exist in the cache, it is created. The UID is " "determined with the help of the SID, trusted domains will have UPGs and the " @@ -2632,24 +2667,26 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:2197 +#: sssd.conf.5.xml:2233 msgid "" "If there are SIDs of groups from domains sssd knows about, the user will be " "added to those groups." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2203 -msgid "These options can be used to configure the PAC responder." +#: sssd.conf.5.xml:2239 +msgid "" +"These options can be used to configure the PAC responder and should be " +"specified under the <quote>[pac]</quote> section." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2207 sssd-ifp.5.xml:66 +#: sssd.conf.5.xml:2244 sssd-ifp.5.xml:66 msgid "allowed_uids (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2210 +#: sssd.conf.5.xml:2247 msgid "" "Specifies the comma-separated list of UID values or user names that are " "allowed to access the PAC responder. User names are resolved to UIDs at " @@ -2657,19 +2694,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2216 +#: sssd.conf.5.xml:2253 msgid "" "Default: 0, &sssd_user_name; (only root and SSSD service users are allowed " "to access the PAC responder)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2220 +#: sssd.conf.5.xml:2257 msgid "Default: 0 (only the root user is allowed to access the PAC responder)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2224 +#: sssd.conf.5.xml:2261 msgid "" "Please note that defaults will be overwritten with this option. If you still " "want to allow the root and/or '&sssd_user_name;' user to access the PAC " @@ -2678,7 +2715,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2231 +#: sssd.conf.5.xml:2268 msgid "" "Please note that although the UID 0 is used as the default it will be " "overwritten with this option. If you still want to allow the root user to " @@ -2687,24 +2724,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2240 +#: sssd.conf.5.xml:2277 msgid "pac_lifetime (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2243 +#: sssd.conf.5.xml:2280 msgid "" "Lifetime of the PAC entry in seconds. As long as the PAC is valid the PAC " "data can be used to determine the group memberships of a user." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2253 +#: sssd.conf.5.xml:2290 msgid "pac_check (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2256 +#: sssd.conf.5.xml:2293 msgid "" "Apply additional checks on the PAC of the Kerberos ticket which is available " "in Active Directory and FreeIPA domains, if configured. Please note that " @@ -2715,7 +2752,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2266 +#: sssd.conf.5.xml:2303 msgid "" "Please note that the checks listed below only apply to PACs issued by Active " "Directory or recent versions of FreeIPA. PACs issued e.g. by a plain MIT " @@ -2723,24 +2760,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2277 +#: sssd.conf.5.xml:2314 msgid "no_check" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2279 +#: sssd.conf.5.xml:2316 msgid "" "The PAC must not be present and even if it is present no additional checks " "will be done." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2285 +#: sssd.conf.5.xml:2322 msgid "pac_present" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2287 +#: sssd.conf.5.xml:2324 msgid "" "The PAC must be present in the service ticket which SSSD will request with " "the help of the user's TGT. If the PAC is not available the authentication " @@ -2748,24 +2785,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2295 +#: sssd.conf.5.xml:2332 msgid "check_upn" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2297 +#: sssd.conf.5.xml:2334 msgid "" "If the PAC is present check if the user principal name (UPN) information is " "consistent." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2303 +#: sssd.conf.5.xml:2340 msgid "check_upn_allow_missing" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2305 +#: sssd.conf.5.xml:2342 msgid "" "This option should be used together with 'check_upn' and handles the case " "where a UPN is set on the server-side but is not read by SSSD. The typical " @@ -2777,7 +2814,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2317 +#: sssd.conf.5.xml:2354 msgid "" "Currently this option is set by default to avoid regressions in such " "environments. A log message will be added to the system log and SSSD's debug " @@ -2788,60 +2825,60 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2331 +#: sssd.conf.5.xml:2368 msgid "upn_dns_info_present" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2333 +#: sssd.conf.5.xml:2370 msgid "The PAC must contain the UPN-DNS-INFO buffer, implies 'check_upn'." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2338 +#: sssd.conf.5.xml:2375 msgid "check_upn_dns_info_ex" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2340 +#: sssd.conf.5.xml:2377 msgid "" "If the PAC is present and the extension to the UPN-DNS-INFO buffer is " "available check if the information in the extension is consistent." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2347 +#: sssd.conf.5.xml:2384 msgid "upn_dns_info_ex_present" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2349 +#: sssd.conf.5.xml:2386 msgid "" "The PAC must contain the extension of the UPN-DNS-INFO buffer, implies " "'check_upn_dns_info_ex', 'upn_dns_info_present' and 'check_upn'." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2273 +#: sssd.conf.5.xml:2310 msgid "" "The following options can be used alone or in a comma-separated list: " "<placeholder type=\"variablelist\" id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2359 +#: sssd.conf.5.xml:2396 msgid "" "Default: no_check (AD and IPA provider 'check_upn, check_upn_allow_missing, " "check_upn_dns_info_ex')" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:2368 +#: sssd.conf.5.xml:2405 msgid "Session recording configuration options" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2370 +#: sssd.conf.5.xml:2407 msgid "" "Session recording works in conjunction with <citerefentry> " "<refentrytitle>tlog-rec-session</refentrytitle> <manvolnum>8</manvolnum> " @@ -2852,66 +2889,78 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2383 -msgid "These options can be used to configure session recording." +#: sssd.conf.5.xml:2420 +msgid "" +"These options can be used to configure session recording and should be " +"specified under the <quote>[session_recording]</quote> section." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:2425 +msgid "" +"Note: Unlike other sections, the <quote>[session_recording]</quote> section " +"ignores <replaceable>debug*</replaceable> options and suitable " +"<replaceable>debug*</replaceable> options must be set in " +"<quote>[pam]</quote>, <quote>[nss]</quote> and " +"<quote>[domain/<replaceable>NAME</replaceable>]</quote> sections." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2387 sssd-session-recording.5.xml:64 +#: sssd.conf.5.xml:2433 sssd-session-recording.5.xml:64 msgid "scope (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2394 sssd-session-recording.5.xml:71 +#: sssd.conf.5.xml:2440 sssd-session-recording.5.xml:71 msgid "\"none\"" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2397 sssd-session-recording.5.xml:74 +#: sssd.conf.5.xml:2443 sssd-session-recording.5.xml:74 msgid "No users are recorded." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2402 sssd-session-recording.5.xml:79 +#: sssd.conf.5.xml:2448 sssd-session-recording.5.xml:79 msgid "\"some\"" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2405 sssd-session-recording.5.xml:82 +#: sssd.conf.5.xml:2451 sssd-session-recording.5.xml:82 msgid "" "Users/groups specified by <replaceable>users</replaceable> and " "<replaceable>groups</replaceable> options are recorded." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2414 sssd-session-recording.5.xml:91 +#: sssd.conf.5.xml:2460 sssd-session-recording.5.xml:91 msgid "\"all\"" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2417 sssd-session-recording.5.xml:94 +#: sssd.conf.5.xml:2463 sssd-session-recording.5.xml:94 msgid "All users are recorded." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2390 sssd-session-recording.5.xml:67 +#: sssd.conf.5.xml:2436 sssd-session-recording.5.xml:67 msgid "" "One of the following strings specifying the scope of session recording: " "<placeholder type=\"variablelist\" id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2424 sssd-session-recording.5.xml:101 +#: sssd.conf.5.xml:2470 sssd-session-recording.5.xml:101 msgid "Default: \"none\"" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2429 sssd-session-recording.5.xml:106 +#: sssd.conf.5.xml:2475 sssd-session-recording.5.xml:106 msgid "users (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2432 sssd-session-recording.5.xml:109 +#: sssd.conf.5.xml:2478 sssd-session-recording.5.xml:109 msgid "" "A comma-separated list of users which should have session recording " "enabled. Matches user names as returned by NSS. I.e. after the possible " @@ -2919,17 +2968,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2438 sssd-session-recording.5.xml:115 +#: sssd.conf.5.xml:2484 sssd-session-recording.5.xml:115 msgid "Default: Empty. Matches no users." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2443 sssd-session-recording.5.xml:120 +#: sssd.conf.5.xml:2489 sssd-session-recording.5.xml:120 msgid "groups (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2446 sssd-session-recording.5.xml:123 +#: sssd.conf.5.xml:2492 sssd-session-recording.5.xml:123 msgid "" "A comma-separated list of groups, members of which should have session " "recording enabled. Matches group names as returned by NSS. I.e. after the " @@ -2937,7 +2986,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2452 sssd.conf.5.xml:2484 sssd-session-recording.5.xml:129 +#: sssd.conf.5.xml:2498 sssd.conf.5.xml:2530 sssd-session-recording.5.xml:129 #: sssd-session-recording.5.xml:161 msgid "" "NOTE: using this option (having it set to anything) has a considerable " @@ -2946,57 +2995,56 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2459 sssd-session-recording.5.xml:136 +#: sssd.conf.5.xml:2505 sssd-session-recording.5.xml:136 msgid "Default: Empty. Matches no groups." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2464 sssd-session-recording.5.xml:141 +#: sssd.conf.5.xml:2510 sssd-session-recording.5.xml:141 msgid "exclude_users (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2467 sssd-session-recording.5.xml:144 +#: sssd.conf.5.xml:2513 sssd-session-recording.5.xml:144 msgid "" "A comma-separated list of users to be excluded from recording, only " "applicable with 'scope=all'." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2471 sssd-session-recording.5.xml:148 +#: sssd.conf.5.xml:2517 sssd-session-recording.5.xml:148 msgid "Default: Empty. No users excluded." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2476 sssd-session-recording.5.xml:153 +#: sssd.conf.5.xml:2522 sssd-session-recording.5.xml:153 msgid "exclude_groups (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2479 sssd-session-recording.5.xml:156 +#: sssd.conf.5.xml:2525 sssd-session-recording.5.xml:156 msgid "" "A comma-separated list of groups, members of which should be excluded from " "recording. Only applicable with 'scope=all'." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2491 sssd-session-recording.5.xml:168 +#: sssd.conf.5.xml:2537 sssd-session-recording.5.xml:168 msgid "Default: Empty. No groups excluded." msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:2501 +#: sssd.conf.5.xml:2547 msgid "DOMAIN SECTIONS" msgstr "" -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry><para> -#: sssd.conf.5.xml:2508 sssd.conf.5.xml:3964 sssd.conf.5.xml:3965 -#: sssd.conf.5.xml:3968 -msgid "enabled" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2554 +msgid "enabled (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2511 +#: sssd.conf.5.xml:2557 msgid "" "Explicitly enable or disable the domain. If <quote>true</quote>, the domain " "is always <quote>enabled</quote>. If <quote>false</quote>, the domain is " @@ -3006,12 +3054,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2523 +#: sssd.conf.5.xml:2569 msgid "domain_type (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2526 +#: sssd.conf.5.xml:2572 msgid "" "Specifies whether the domain is meant to be used by POSIX-aware clients such " "as the Name Service Switch or by applications that do not need POSIX data to " @@ -3020,14 +3068,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2534 +#: sssd.conf.5.xml:2580 msgid "" "Allowed values for this option are <quote>posix</quote> and " "<quote>application</quote>." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2538 +#: sssd.conf.5.xml:2584 msgid "" "POSIX domains are reachable by all services. Application domains are only " "reachable from the InfoPipe responder (see <citerefentry> " @@ -3036,38 +3084,38 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2546 +#: sssd.conf.5.xml:2592 msgid "" "NOTE: The application domains are currently well tested with " "<quote>id_provider=ldap</quote> only." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2550 +#: sssd.conf.5.xml:2596 msgid "" "For an easy way to configure a non-POSIX domains, please see the " "<quote>Application domains</quote> section." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2554 +#: sssd.conf.5.xml:2600 msgid "Default: posix" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2560 +#: sssd.conf.5.xml:2606 msgid "min_id,max_id (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2563 +#: sssd.conf.5.xml:2609 msgid "" "UID and GID limits for the domain. If a domain contains an entry that is " "outside these limits, it is ignored." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2568 +#: sssd.conf.5.xml:2614 msgid "" "For users, this affects the primary GID limit. The user will not be returned " "to NSS if either the UID or the primary GID is outside the range. For " @@ -3076,24 +3124,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2575 +#: sssd.conf.5.xml:2621 msgid "" "These ID limits affect even saving entries to cache, not only returning them " "by name or ID." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2579 +#: sssd.conf.5.xml:2625 msgid "Default: 1 for min_id, 0 (no limit) for max_id" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2585 -msgid "enumerate (bool)" +#: sssd.conf.5.xml:2631 +msgid "enumerate (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2588 +#: sssd.conf.5.xml:2634 msgid "" "Determines if a domain can be enumerated, that is, whether the domain can " "list all the users and group it contains. Note that it is not required to " @@ -3102,36 +3150,36 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2596 +#: sssd.conf.5.xml:2642 msgid "TRUE = Users and groups are enumerated" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2599 +#: sssd.conf.5.xml:2645 msgid "FALSE = No enumerations for this domain" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2602 sssd.conf.5.xml:2867 sssd.conf.5.xml:3044 +#: sssd.conf.5.xml:2648 sssd.conf.5.xml:2992 sssd.conf.5.xml:3174 msgid "Default: FALSE" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2605 +#: sssd.conf.5.xml:2651 msgid "" "Enumerating a domain requires SSSD to download and store ALL user and group " "entries from the remote server." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2610 +#: sssd.conf.5.xml:2656 msgid "" "Feature is only supported for domains with id_provider = ldap or id_provider " "= proxy." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2614 +#: sssd.conf.5.xml:2660 msgid "" "Note: Enabling enumeration has a severe performance impact on SSSD while " "enumeration is running. It may take up to several minutes after SSSD startup " @@ -3145,14 +3193,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2629 +#: sssd.conf.5.xml:2675 msgid "" "While the first enumeration is running, requests for the complete user or " "group lists may return no results until it completes." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2634 +#: sssd.conf.5.xml:2680 msgid "" "Further, enabling enumeration may increase the time necessary to detect " "network disconnection, as longer timeouts are required to ensure that " @@ -3161,14 +3209,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2642 +#: sssd.conf.5.xml:2688 msgid "" "For the reasons cited above, enabling enumeration is not recommended, " "especially in large environments." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2647 +#: sssd.conf.5.xml:2693 msgid "" "Note: the proxy provider is tested with open source modules like " "'libnss_files' and 'libnss_ldap'. 3rd party modules must follow the " @@ -3176,19 +3224,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2656 +#: sssd.conf.5.xml:2702 msgid "entry_cache_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2659 +#: sssd.conf.5.xml:2705 msgid "" "How many seconds should nss_sss consider entries valid before asking the " "backend again" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2663 +#: sssd.conf.5.xml:2709 msgid "" "The cache expiration timestamps are stored as attributes of individual " "objects in the cache. Therefore, changing the cache timeout only has effect " @@ -3199,139 +3247,244 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2676 +#: sssd.conf.5.xml:2722 msgid "Default: 5400" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2682 +#: sssd.conf.5.xml:2728 msgid "entry_cache_user_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2685 +#: sssd.conf.5.xml:2731 msgid "" "How many seconds should nss_sss consider user entries valid before asking " "the backend again" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2689 sssd.conf.5.xml:2702 sssd.conf.5.xml:2715 -#: sssd.conf.5.xml:2728 sssd.conf.5.xml:2742 sssd.conf.5.xml:2755 -#: sssd.conf.5.xml:2769 sssd.conf.5.xml:2783 sssd.conf.5.xml:2796 +#: sssd.conf.5.xml:2735 sssd.conf.5.xml:2748 sssd.conf.5.xml:2761 +#: sssd.conf.5.xml:2774 sssd.conf.5.xml:2788 sssd.conf.5.xml:2801 +#: sssd.conf.5.xml:2815 sssd.conf.5.xml:2829 msgid "Default: entry_cache_timeout" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2695 +#: sssd.conf.5.xml:2741 msgid "entry_cache_group_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2698 +#: sssd.conf.5.xml:2744 msgid "" "How many seconds should nss_sss consider group entries valid before asking " "the backend again" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2708 +#: sssd.conf.5.xml:2754 msgid "entry_cache_netgroup_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2711 +#: sssd.conf.5.xml:2757 msgid "" "How many seconds should nss_sss consider netgroup entries valid before " "asking the backend again" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2721 +#: sssd.conf.5.xml:2767 msgid "entry_cache_service_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2724 +#: sssd.conf.5.xml:2770 msgid "" "How many seconds should nss_sss consider service entries valid before asking " "the backend again" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2734 +#: sssd.conf.5.xml:2780 msgid "entry_cache_resolver_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2737 +#: sssd.conf.5.xml:2783 msgid "" "How many seconds should nss_sss consider hosts and networks entries valid " "before asking the backend again" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2748 +#: sssd.conf.5.xml:2794 msgid "entry_cache_sudo_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2751 +#: sssd.conf.5.xml:2797 msgid "" "How many seconds should sudo consider rules valid before asking the backend " "again" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2761 +#: sssd.conf.5.xml:2807 msgid "entry_cache_autofs_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2764 +#: sssd.conf.5.xml:2810 msgid "" "How many seconds should the autofs service consider automounter maps valid " "before asking the backend again" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2775 +#: sssd.conf.5.xml:2821 msgid "entry_cache_ssh_host_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2778 +#: sssd.conf.5.xml:2824 msgid "" "How many seconds to keep a host ssh key after refresh. IE how long to cache " "the host key for." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2789 -msgid "entry_cache_computer_timeout (integer)" +#: sssd.conf.5.xml:2835 +msgid "offline_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2792 +#: sssd.conf.5.xml:2838 msgid "" -"How many seconds to keep the local computer entry before asking the backend " -"again" +"When SSSD switches to offline mode the amount of time before it tries to go " +"back online will increase based upon the time spent disconnected. By " +"default SSSD uses incremental behaviour to calculate delay in between " +"retries. So, the wait time for a given retry will be longer than the wait " +"time for the previous ones. After each unsuccessful attempt to go online, " +"the new interval is recalculated by the following:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2849 sssd.conf.5.xml:2907 +msgid "" +"new_delay = Minimum(old_delay * 2, offline_timeout_max) + " +"random[0...offline_timeout_random_offset]" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2852 +msgid "" +"The offline_timeout default value is 60. The offline_timeout_max default " +"value is 3600. The offline_timeout_random_offset default value is 30. The " +"end result is the number of seconds before next retry." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2858 +msgid "" +"Note that the maximum length of each interval is defined by " +"offline_timeout_max (apart from the random part)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2868 +msgid "offline_timeout_max (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2871 +msgid "" +"Controls by how much the time between attempts to go online can be " +"incremented following unsuccessful attempts to go online." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2876 +msgid "A value of 0 disables the incrementing behaviour." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2879 +msgid "" +"The value of this parameter should be set in correlation to offline_timeout " +"parameter value." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2883 +msgid "" +"With offline_timeout set to 60 (default value) there is no point in setting " +"offline_timeout_max to less than 120 as it will saturate instantly. General " +"rule here should be to set offline_timeout_max to at least 4 times " +"offline_timeout." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2889 +msgid "" +"Although a value between 0 and offline_timeout may be specified, it has the " +"effect of overriding the offline_timeout value so is of little use." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2894 +msgid "Default: 3600" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2900 +msgid "offline_timeout_random_offset (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2903 +msgid "" +"When SSSD is in offline mode it keeps probing backend servers in specified " +"time intervals:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2910 +msgid "" +"This parameter controls the value of the random offset used for the above " +"equation. Final random_offset value will be random number in range:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2915 +msgid "[0 - offline_timeout_random_offset]" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2918 +msgid "A value of 0 disables the random offset addition." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2921 +msgid "Default: 30" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2802 +#: sssd.conf.5.xml:2927 msgid "refresh_expired_interval (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2805 +#: sssd.conf.5.xml:2930 msgid "" "Specifies how many seconds SSSD has to wait before triggering a background " "refresh task which will refresh all expired or nearly expired records." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2810 +#: sssd.conf.5.xml:2935 msgid "" "The background refresh will process users, groups and netgroups in the " "cache. For users who have performed the initgroups (get group membership for " @@ -3340,17 +3493,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2818 +#: sssd.conf.5.xml:2943 msgid "This option is automatically inherited for all trusted domains." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2822 +#: sssd.conf.5.xml:2947 msgid "You can consider setting this value to 3/4 * entry_cache_timeout." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2826 +#: sssd.conf.5.xml:2951 msgid "" "Cache entry will be refreshed by background task when 2/3 of cache timeout " "has already passed. If there are existing cached entries, the background " @@ -3362,18 +3515,18 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2839 sssd-ldap.5.xml:406 sssd-ldap.5.xml:1834 -#: sssd-ipa.5.xml:255 +#: sssd.conf.5.xml:2964 sssd-ldap.5.xml:406 sssd-ldap.5.xml:1834 +#: sssd-ipa.5.xml:250 msgid "Default: 0 (disabled)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2845 -msgid "cache_credentials (bool)" +#: sssd.conf.5.xml:2970 +msgid "cache_credentials (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2848 +#: sssd.conf.5.xml:2973 msgid "" "Determines if user credentials are also cached in the local LDB cache. The " "cached credentials refer to passwords, which includes the first (long term) " @@ -3384,7 +3537,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2859 +#: sssd.conf.5.xml:2984 msgid "" "Take a note that while credentials are stored as a salted SHA512 hash, this " "still potentially poses some security risk in case an attacker manages to " @@ -3393,12 +3546,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2873 +#: sssd.conf.5.xml:2998 msgid "cache_credentials_minimal_first_factor_length (int)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2876 +#: sssd.conf.5.xml:3001 msgid "" "If 2-Factor-Authentication (2FA) is used and credentials should be saved " "this value determines the minimal length the first authentication factor " @@ -3406,19 +3559,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2883 +#: sssd.conf.5.xml:3008 msgid "" "This should avoid that the short PINs of a PIN based 2FA scheme are saved in " "the cache which would make them easy targets for brute-force attacks." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2894 +#: sssd.conf.5.xml:3019 msgid "account_cache_expiration (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2897 +#: sssd.conf.5.xml:3022 msgid "" "Number of days entries are left in cache after last successful login before " "being removed during a cleanup of the cache. 0 means keep forever. The " @@ -3427,17 +3580,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2904 +#: sssd.conf.5.xml:3029 msgid "Default: 0 (unlimited)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2909 +#: sssd.conf.5.xml:3034 msgid "pwd_expiration_warning (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2920 +#: sssd.conf.5.xml:3045 msgid "" "Please note that the backend server has to provide information about the " "expiration time of the password. If this information is missing, sssd " @@ -3446,29 +3599,29 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2927 +#: sssd.conf.5.xml:3052 msgid "Default: 7 (Kerberos), 0 (LDAP)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2933 +#: sssd.conf.5.xml:3058 msgid "id_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2936 +#: sssd.conf.5.xml:3061 msgid "" "The identification provider used for the domain. Supported ID providers " "are:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2940 +#: sssd.conf.5.xml:3065 msgid "<quote>proxy</quote>: Support a legacy NSS provider." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2943 +#: sssd.conf.5.xml:3068 msgid "" "<quote>ldap</quote>: LDAP provider. See <citerefentry> " "<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> " @@ -3476,8 +3629,8 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2951 sssd.conf.5.xml:3070 sssd.conf.5.xml:3129 -#: sssd.conf.5.xml:3192 +#: sssd.conf.5.xml:3076 sssd.conf.5.xml:3200 sssd.conf.5.xml:3259 +#: sssd.conf.5.xml:3322 msgid "" "<quote>ipa</quote>: FreeIPA and Red Hat Identity Management provider. See " "<citerefentry> <refentrytitle>sssd-ipa</refentrytitle> " @@ -3486,8 +3639,8 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2960 sssd.conf.5.xml:3079 sssd.conf.5.xml:3138 -#: sssd.conf.5.xml:3201 +#: sssd.conf.5.xml:3085 sssd.conf.5.xml:3209 sssd.conf.5.xml:3268 +#: sssd.conf.5.xml:3331 msgid "" "<quote>ad</quote>: Active Directory provider. See <citerefentry> " "<refentrytitle>sssd-ad</refentrytitle> <manvolnum>5</manvolnum> " @@ -3495,27 +3648,34 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2968 +#: sssd.conf.5.xml:3093 msgid "" "<quote>idp</quote>: Provider for OAuth 2.0/OIDC based Identity Providers " "(IdP). See <citerefentry> <refentrytitle>sssd-idp</refentrytitle> " "<manvolnum>5</manvolnum> </citerefentry> for more information." msgstr "" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3101 +msgid "" +"Default: Not set (This is a mandatory setting that must be explicitly " +"defined for each configured domain)." +msgstr "" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2979 -msgid "use_fully_qualified_names (bool)" +#: sssd.conf.5.xml:3109 +msgid "use_fully_qualified_names (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2982 +#: sssd.conf.5.xml:3112 msgid "" "Use the full name and domain (as formatted by the domain's full_name_format) " "as the user's login name reported to NSS." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2987 +#: sssd.conf.5.xml:3117 msgid "" "If set to TRUE, all requests to this domain must use fully qualified " "names. For example, if used in EXAMPLE domain that contains a \"test\" user, " @@ -3524,7 +3684,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2995 +#: sssd.conf.5.xml:3125 msgid "" "NOTE: This option has no effect on netgroup lookups due to their tendency to " "include nested netgroups without qualified names. For netgroups, all domains " @@ -3532,24 +3692,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3002 +#: sssd.conf.5.xml:3132 msgid "" "Default: FALSE (TRUE for trusted domain/sub-domains or if " "default_domain_suffix is used)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3009 -msgid "ignore_group_members (bool)" +#: sssd.conf.5.xml:3139 +msgid "ignore_group_members (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3012 +#: sssd.conf.5.xml:3142 msgid "Do not return group members for group lookups." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3015 +#: sssd.conf.5.xml:3145 msgid "" "If set to TRUE, the group membership attribute is not requested from the " "ldap server, and group members are not returned when processing group lookup " @@ -3561,7 +3721,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3033 +#: sssd.conf.5.xml:3163 msgid "" "Enabling this option can also make access provider checks for group " "membership significantly faster, especially for groups containing many " @@ -3569,7 +3729,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3039 sssd.conf.5.xml:3767 sssd-ldap.5.xml:401 +#: sssd.conf.5.xml:3169 sssd.conf.5.xml:3951 sssd-ldap.5.xml:401 #: sssd-ldap.5.xml:454 sssd-ldap.5.xml:529 sssd-ldap.5.xml:576 #: sssd-ldap.5.xml:599 sssd-ldap.5.xml:638 sssd-ldap.5.xml:657 #: sssd-ldap.5.xml:681 sssd-ldap.5.xml:1114 sssd-ldap.5.xml:1147 @@ -3579,19 +3739,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3049 +#: sssd.conf.5.xml:3179 msgid "auth_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3052 +#: sssd.conf.5.xml:3182 msgid "" "The authentication provider used for the domain. Supported auth providers " "are:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3056 sssd.conf.5.xml:3122 +#: sssd.conf.5.xml:3186 sssd.conf.5.xml:3252 msgid "" "<quote>ldap</quote> for native LDAP authentication. See <citerefentry> " "<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> " @@ -3599,7 +3759,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3063 +#: sssd.conf.5.xml:3193 msgid "" "<quote>krb5</quote> for Kerberos authentication. See <citerefentry> " "<refentrytitle>sssd-krb5</refentrytitle> <manvolnum>5</manvolnum> " @@ -3607,7 +3767,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3087 +#: sssd.conf.5.xml:3217 msgid "" "<quote>idp</quote>: Provider for OAuth 2.0/OIDC based authentication. See " "<citerefentry> <refentrytitle>sssd-idp</refentrytitle> " @@ -3615,29 +3775,29 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3095 +#: sssd.conf.5.xml:3225 msgid "<quote>proxy</quote> for relaying authentication to some other PAM target." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3098 +#: sssd.conf.5.xml:3228 msgid "<quote>none</quote> disables authentication explicitly." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3101 +#: sssd.conf.5.xml:3231 msgid "" "Default: <quote>id_provider</quote> is used if it is set and can handle " "authentication requests." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3107 +#: sssd.conf.5.xml:3237 msgid "access_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3110 +#: sssd.conf.5.xml:3240 msgid "" "The access control provider used for the domain. There are two built-in " "access providers (in addition to any included in installed backends) " @@ -3645,17 +3805,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3116 +#: sssd.conf.5.xml:3246 msgid "<quote>permit</quote> always allow access." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3119 +#: sssd.conf.5.xml:3249 msgid "<quote>deny</quote> always deny access." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3146 +#: sssd.conf.5.xml:3276 msgid "" "<quote>simple</quote> access control based on access or deny lists. See " "<citerefentry> <refentrytitle>sssd-simple</refentrytitle> " @@ -3664,7 +3824,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3153 +#: sssd.conf.5.xml:3283 msgid "" "<quote>krb5</quote>: .k5login based access control. See <citerefentry> " "<refentrytitle>sssd-krb5</refentrytitle> " @@ -3673,29 +3833,29 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3160 +#: sssd.conf.5.xml:3290 msgid "<quote>proxy</quote> for relaying access control to another PAM module." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3163 +#: sssd.conf.5.xml:3293 msgid "Default: <quote>permit</quote>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3168 +#: sssd.conf.5.xml:3298 msgid "chpass_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3171 +#: sssd.conf.5.xml:3301 msgid "" "The provider which should handle change password operations for the domain. " "Supported change password providers are:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3176 +#: sssd.conf.5.xml:3306 msgid "" "<quote>ldap</quote> to change a password stored in a LDAP server. See " "<citerefentry> <refentrytitle>sssd-ldap</refentrytitle> " @@ -3704,7 +3864,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3184 +#: sssd.conf.5.xml:3314 msgid "" "<quote>krb5</quote> to change the Kerberos password. See <citerefentry> " "<refentrytitle>sssd-krb5</refentrytitle> <manvolnum>5</manvolnum> " @@ -3712,34 +3872,34 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3209 +#: sssd.conf.5.xml:3339 msgid "<quote>proxy</quote> for relaying password changes to some other PAM target." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3213 +#: sssd.conf.5.xml:3343 msgid "<quote>none</quote> disallows password changes explicitly." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3216 +#: sssd.conf.5.xml:3346 msgid "" "Default: <quote>auth_provider</quote> is used if it is set and can handle " "change password requests." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3223 +#: sssd.conf.5.xml:3353 msgid "sudo_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3226 +#: sssd.conf.5.xml:3356 msgid "The SUDO provider used for the domain. Supported SUDO providers are:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3230 +#: sssd.conf.5.xml:3360 msgid "" "<quote>ldap</quote> for rules stored in LDAP. See <citerefentry> " "<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> " @@ -3747,33 +3907,33 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3238 +#: sssd.conf.5.xml:3368 msgid "" "<quote>ipa</quote> the same as <quote>ldap</quote> but with IPA default " "settings." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3242 +#: sssd.conf.5.xml:3372 msgid "" "<quote>ad</quote> the same as <quote>ldap</quote> but with AD default " "settings." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3246 +#: sssd.conf.5.xml:3376 msgid "<quote>none</quote> disables SUDO explicitly." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3249 +#: sssd.conf.5.xml:3379 msgid "" "Default: The value of <quote>id_provider</quote> is used if it is set and " "can handle sudo requests." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3253 +#: sssd.conf.5.xml:3383 msgid "" "The detailed instructions for configuration of sudo_provider are in the " "manual page <citerefentry> <refentrytitle>sssd-sudo</refentrytitle> " @@ -3784,7 +3944,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3268 +#: sssd.conf.5.xml:3398 msgid "" "<emphasis>NOTE:</emphasis> Sudo rules are periodically downloaded in the " "background unless the sudo provider is explicitly disabled. Set " @@ -3793,12 +3953,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3278 +#: sssd.conf.5.xml:3408 msgid "selinux_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3281 +#: sssd.conf.5.xml:3411 msgid "" "The provider which should handle loading of selinux settings. Note that this " "provider will be called right after access provider ends. Supported selinux " @@ -3806,7 +3966,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3287 +#: sssd.conf.5.xml:3417 msgid "" "<quote>ipa</quote> to load selinux settings from an IPA server. See " "<citerefentry> <refentrytitle>sssd-ipa</refentrytitle> " @@ -3815,31 +3975,32 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3295 +#: sssd.conf.5.xml:3425 msgid "<quote>none</quote> disallows fetching selinux settings explicitly." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3298 +#: sssd.conf.5.xml:3428 msgid "" -"Default: <quote>id_provider</quote> is used if it is set and can handle " -"selinux loading requests." +"Default: the value of <quote>id_provider</quote> is used if it is set and " +"can handle selinux loading requests. Otherwise the result is the same as if " +"the selinux_provider is set to none." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3304 +#: sssd.conf.5.xml:3435 msgid "subdomains_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3307 +#: sssd.conf.5.xml:3438 msgid "" "The provider which should handle fetching of subdomains. This value should " "be always the same as id_provider. Supported subdomain providers are:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3313 +#: sssd.conf.5.xml:3444 msgid "" "<quote>ipa</quote> to load a list of subdomains from an IPA server. See " "<citerefentry> <refentrytitle>sssd-ipa</refentrytitle> " @@ -3848,7 +4009,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3322 +#: sssd.conf.5.xml:3453 msgid "" "<quote>ad</quote> to load a list of subdomains from an Active Directory " "server. See <citerefentry> <refentrytitle>sssd-ad</refentrytitle> " @@ -3857,24 +4018,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3331 +#: sssd.conf.5.xml:3462 msgid "<quote>none</quote> disallows fetching subdomains explicitly." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3335 +#: sssd.conf.5.xml:3466 msgid "" "Default: The value of <quote>id_provider</quote> is used if it is set and " "can handle subdomain requests." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3341 +#: sssd.conf.5.xml:3472 msgid "session_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3344 +#: sssd.conf.5.xml:3475 msgid "" "The provider which configures and manages user session related tasks. The " "only user session task currently provided is the integration with Fleet " @@ -3882,32 +4043,32 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3351 +#: sssd.conf.5.xml:3482 msgid "<quote>ipa</quote> to allow performing user session related tasks." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3355 +#: sssd.conf.5.xml:3486 msgid "<quote>none</quote> does not perform any kind of user session related tasks." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3359 +#: sssd.conf.5.xml:3490 msgid "Default: <quote>none</quote>." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3365 +#: sssd.conf.5.xml:3496 msgid "autofs_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3368 +#: sssd.conf.5.xml:3499 msgid "The autofs provider used for the domain. Supported autofs providers are:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3372 +#: sssd.conf.5.xml:3503 msgid "" "<quote>ldap</quote> to load maps stored in LDAP. See <citerefentry> " "<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> " @@ -3915,7 +4076,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3379 +#: sssd.conf.5.xml:3510 msgid "" "<quote>ipa</quote> to load maps stored in an IPA server. See <citerefentry> " "<refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</manvolnum> " @@ -3923,7 +4084,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3387 +#: sssd.conf.5.xml:3518 msgid "" "<quote>ad</quote> to load maps stored in an AD server. See <citerefentry> " "<refentrytitle>sssd-ad</refentrytitle> <manvolnum>5</manvolnum> " @@ -3931,31 +4092,31 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3396 +#: sssd.conf.5.xml:3527 msgid "<quote>none</quote> disables autofs explicitly." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3399 +#: sssd.conf.5.xml:3530 msgid "" "Default: The value of <quote>id_provider</quote> is used if it is set and " "can handle autofs requests." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3406 +#: sssd.conf.5.xml:3537 msgid "hostid_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3409 +#: sssd.conf.5.xml:3540 msgid "" "The provider used for retrieving host identity information. Supported " "hostid providers are:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3413 +#: sssd.conf.5.xml:3544 msgid "" "<quote>ipa</quote> to load host identity stored in an IPA server. See " "<citerefentry> <refentrytitle>sssd-ipa</refentrytitle> " @@ -3964,38 +4125,38 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3421 +#: sssd.conf.5.xml:3552 msgid "<quote>none</quote> disables hostid explicitly." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3424 +#: sssd.conf.5.xml:3555 msgid "" "Default: The value of <quote>id_provider</quote> is used if it is set and " "can handle hostid requests." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3431 +#: sssd.conf.5.xml:3562 msgid "resolver_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3434 +#: sssd.conf.5.xml:3565 msgid "" "The provider which should handle hosts and networks lookups. Supported " "resolver providers are:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3438 +#: sssd.conf.5.xml:3569 msgid "" "<quote>proxy</quote> to forward lookups to another NSS library. See " "<quote>proxy_resolver_lib_name</quote>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3442 +#: sssd.conf.5.xml:3573 msgid "" "<quote>ldap</quote> to fetch hosts and networks stored in LDAP. See " "<citerefentry> <refentrytitle>sssd-ldap</refentrytitle> " @@ -4004,7 +4165,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3449 +#: sssd.conf.5.xml:3580 msgid "" "<quote>ad</quote> to fetch hosts and networks stored in AD. See " "<citerefentry> <refentrytitle>sssd-ad</refentrytitle> " @@ -4013,19 +4174,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3457 +#: sssd.conf.5.xml:3588 msgid "<quote>none</quote> disallows fetching hosts and networks explicitly." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3460 +#: sssd.conf.5.xml:3591 msgid "" "Default: The value of <quote>id_provider</quote> is used if it is set and " "can handle resolver requests." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3470 +#: sssd.conf.5.xml:3601 msgid "" "Regular expression for this domain that describes how to parse the string " "containing user name and domain into these components. The \"domain\" can " @@ -4035,7 +4196,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3479 +#: sssd.conf.5.xml:3610 msgid "" "Default: " "<quote>^((?P<name>.+)@(?P<domain>[^@]*)|(?P<name>[^@]+))$</quote> " @@ -4043,17 +4204,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:3484 sssd.conf.5.xml:3498 +#: sssd.conf.5.xml:3615 sssd.conf.5.xml:3629 msgid "username" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:3487 sssd.conf.5.xml:3501 +#: sssd.conf.5.xml:3618 sssd.conf.5.xml:3632 msgid "username@domain.name" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3492 +#: sssd.conf.5.xml:3623 msgid "" "Default for the AD and IPA provider: " "<quote>^(((?P<domain>[^\\\\]+)\\\\(?P<name>.+))|((?P<name>.+)@(?P<domain>[^@]+))|((?P<name>[^@\\\\]+)))$</quote> " @@ -4061,19 +4222,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:3504 +#: sssd.conf.5.xml:3635 msgid "domain\\username" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3507 +#: sssd.conf.5.xml:3638 msgid "" "While the first two correspond to the general default the third one is " "introduced to allow easy integration of users from Windows domains." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3512 +#: sssd.conf.5.xml:3643 msgid "" "The default re_expression uses the <quote>@</quote> character as a separator " "between the name and the domain. As a result of this setting the default " @@ -4083,88 +4244,94 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3564 +#: sssd.conf.5.xml:3695 msgid "Default: <quote>%1$s@%2$s</quote>." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3570 +#: sssd.conf.5.xml:3701 msgid "lookup_family_order (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3573 +#: sssd.conf.5.xml:3704 msgid "" "Provides the ability to select preferred address family to use when " "performing DNS lookups." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3577 +#: sssd.conf.5.xml:3708 msgid "Supported values:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3580 +#: sssd.conf.5.xml:3711 msgid "ipv4_first: Try looking up IPv4 address, if that fails, try IPv6" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3583 +#: sssd.conf.5.xml:3714 msgid "ipv4_only: Only attempt to resolve hostnames to IPv4 addresses." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3586 +#: sssd.conf.5.xml:3717 msgid "ipv6_first: Try looking up IPv6 address, if that fails, try IPv4" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3589 +#: sssd.conf.5.xml:3720 msgid "ipv6_only: Only attempt to resolve hostnames to IPv6 addresses." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3592 +#: sssd.conf.5.xml:3723 msgid "Default: ipv4_first" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3598 +#: sssd.conf.5.xml:3729 msgid "dns_resolver_server_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3601 +#: sssd.conf.5.xml:3732 msgid "" -"Defines the amount of time (in milliseconds) SSSD would try to talk to DNS " -"server before trying next DNS server." +"Defines the timeout duration (in milliseconds) SSSD waits for a DNS server " +"to respond before moving to the next one." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3606 +#: sssd.conf.5.xml:3737 msgid "The AD provider will use this option for the CLDAP ping timeouts as well." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3610 sssd.conf.5.xml:3630 sssd.conf.5.xml:3651 +#: sssd.conf.5.xml:3741 sssd.conf.5.xml:3777 sssd.conf.5.xml:3814 msgid "" -"Please see the section <quote>FAILOVER</quote> for more information about " -"the service resolution." +"Please see the section <quote>FAILOVER</quote> in <citerefentry> " +"<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> " +"</citerefentry>, <citerefentry> <refentrytitle>sssd-krb5</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry>, <citerefentry> " +"<refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</manvolnum> " +"</citerefentry> or <citerefentry> <refentrytitle>sssd-ad</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry> for more information about the " +"service resolution." msgstr "" #. type: Content of: <refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3615 sssd-ldap.5.xml:700 include/failover.xml:84 +#: sssd.conf.5.xml:3762 sssd-ldap.5.xml:700 include/failover.xml:84 msgid "Default: 1000" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3621 +#: sssd.conf.5.xml:3768 msgid "dns_resolver_op_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3624 +#: sssd.conf.5.xml:3771 msgid "" "Defines the amount of time (in seconds) to wait to resolve single DNS query " "(e.g. resolution of a hostname or an SRV record) before trying the next " @@ -4172,17 +4339,17 @@ msgid "" msgstr "" #. type: Content of: <refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3635 include/failover.xml:100 +#: sssd.conf.5.xml:3798 include/failover.xml:100 msgid "Default: 3" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3641 +#: sssd.conf.5.xml:3804 msgid "dns_resolver_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3644 +#: sssd.conf.5.xml:3807 msgid "" "Defines the amount of time (in seconds) to wait for a reply from the " "internal fail over service before assuming that the service is " @@ -4191,12 +4358,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3662 -msgid "dns_resolver_use_search_list (bool)" +#: sssd.conf.5.xml:3841 +msgid "dns_resolver_use_search_list (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3665 +#: sssd.conf.5.xml:3844 msgid "" "Normally, the DNS resolver searches the domain list defined in the " "\"search\" directive from the resolv.conf file. This can lead to delays in " @@ -4204,7 +4371,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3671 +#: sssd.conf.5.xml:3850 msgid "" "If fully qualified domain names (or _srv_) are used in the SSSD " "configuration, setting this option to FALSE can prevent unnecessary DNS " @@ -4212,34 +4379,34 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3677 +#: sssd.conf.5.xml:3856 msgid "Default: TRUE" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3683 +#: sssd.conf.5.xml:3862 msgid "dns_discovery_domain (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3686 +#: sssd.conf.5.xml:3865 msgid "" "If service discovery is used in the back end, specifies the domain part of " "the service discovery DNS query." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3690 +#: sssd.conf.5.xml:3869 msgid "Default: Use the domain part of machine's hostname" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3696 +#: sssd.conf.5.xml:3875 msgid "failover_primary_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3699 +#: sssd.conf.5.xml:3878 msgid "" "When no primary server is available, SSSD fails over to a backup " "server. This option defines the number of seconds SSSD waits before " @@ -4247,57 +4414,66 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3706 +#: sssd.conf.5.xml:3885 msgid "Note: The minimum value is 31." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3709 +#: sssd.conf.5.xml:3888 msgid "Default: 31" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3715 +#: sssd.conf.5.xml:3894 msgid "override_gid (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3718 -msgid "Override the primary GID value with the one specified." +#: sssd.conf.5.xml:3897 +msgid "" +"Override the primary GID value for all users in the domain with specified " +"value." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3901 +msgid "" +"Default: not set (Use the primary GID value retrieved from the identity " +"provider)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3724 +#: sssd.conf.5.xml:3908 msgid "case_sensitive (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3731 +#: sssd.conf.5.xml:3915 msgid "True" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3734 +#: sssd.conf.5.xml:3918 msgid "Case sensitive. This value is invalid for AD provider." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3740 +#: sssd.conf.5.xml:3924 msgid "False" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3742 +#: sssd.conf.5.xml:3926 msgid "Case insensitive." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3746 +#: sssd.conf.5.xml:3930 msgid "Preserving" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3749 +#: sssd.conf.5.xml:3933 msgid "" "Same as False (case insensitive), but does not lowercase names in the result " "of NSS operations. Note that name aliases (and in case of services also " @@ -4305,31 +4481,57 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3757 +#: sssd.conf.5.xml:3941 msgid "" "If you want to set this value for trusted domain with IPA provider, you need " "to set it on both the client and SSSD on the server." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3727 +#: sssd.conf.5.xml:3911 msgid "" "Treat user and group names as case sensitive. Possible option values are: " "<placeholder type=\"variablelist\" id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3772 +#: sssd.conf.5.xml:3956 msgid "Default: True (False for AD provider)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3778 +#: sssd.conf.5.xml:3962 +msgid "avoid_by_id_lookups (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3965 +msgid "" +"If this option is set to 'true' SSSD will try to avoid sending lookups by ID " +"to the backend and will switch to a lookup by name if a cached object with a " +"matching ID can be found." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3971 +msgid "" +"This option can e.g. be used in cases where searches by ID are expensive on " +"the server side because of missing indexes or are not even possible, " +"e.g. due to non-reversible POSIX id-mapping." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3978 +msgid "Default: False (True for IdP provider)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:3984 msgid "subdomain_inherit (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3781 +#: sssd.conf.5.xml:3987 msgid "" "Specifies a list of configuration parameters that should be inherited by a " "subdomain. Please note that only selected parameters can be inherited. " @@ -4337,89 +4539,89 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3787 +#: sssd.conf.5.xml:3993 msgid "ldap_search_timeout" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3790 +#: sssd.conf.5.xml:3996 msgid "ldap_network_timeout" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3793 +#: sssd.conf.5.xml:3999 msgid "ldap_opt_timeout" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3796 +#: sssd.conf.5.xml:4002 msgid "ldap_offline_timeout" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3799 +#: sssd.conf.5.xml:4005 msgid "ldap_purge_cache_timeout" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3802 +#: sssd.conf.5.xml:4008 msgid "ldap_purge_cache_offset" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3805 +#: sssd.conf.5.xml:4011 msgid "" "ldap_krb5_keytab (the value of krb5_keytab will be used if ldap_krb5_keytab " "is not set explicitly)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3809 +#: sssd.conf.5.xml:4015 msgid "ldap_krb5_ticket_lifetime" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3812 +#: sssd.conf.5.xml:4018 msgid "ldap_connection_expire_timeout" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3815 +#: sssd.conf.5.xml:4021 msgid "ldap_connection_expire_offset" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3818 +#: sssd.conf.5.xml:4024 msgid "ldap_connection_idle_timeout" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3821 sssd-ldap.5.xml:446 +#: sssd.conf.5.xml:4027 sssd-ldap.5.xml:446 msgid "ldap_use_tokengroups" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3824 +#: sssd.conf.5.xml:4030 msgid "ldap_user_principal" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3827 +#: sssd.conf.5.xml:4033 msgid "ignore_group_members" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3830 +#: sssd.conf.5.xml:4036 msgid "auto_private_groups" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3833 +#: sssd.conf.5.xml:4039 msgid "case_sensitive" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:3838 +#: sssd.conf.5.xml:4044 #, no-wrap msgid "" "subdomain_inherit = ldap_purge_cache_timeout\n" @@ -4427,27 +4629,27 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3845 +#: sssd.conf.5.xml:4051 msgid "Note: This option only works with the IPA and AD provider." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3852 +#: sssd.conf.5.xml:4058 msgid "subdomain_homedir (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3863 +#: sssd.conf.5.xml:4069 msgid "%F" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3864 +#: sssd.conf.5.xml:4070 msgid "flat (NetBIOS) name of a subdomain." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3855 +#: sssd.conf.5.xml:4061 msgid "" "Use this homedir as default value for all subdomains within this domain in " "IPA AD trust. See <emphasis>override_homedir</emphasis> for info about " @@ -4457,53 +4659,53 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3869 +#: sssd.conf.5.xml:4075 msgid "The value can be overridden by <emphasis>override_homedir</emphasis> option." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3873 +#: sssd.conf.5.xml:4079 msgid "Default: <filename>/home/%d/%u</filename>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3878 +#: sssd.conf.5.xml:4084 msgid "realmd_tags (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3881 +#: sssd.conf.5.xml:4087 msgid "Various tags stored by the realmd configuration service for this domain." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3887 +#: sssd.conf.5.xml:4093 msgid "cached_auth_timeout (int)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3890 +#: sssd.conf.5.xml:4096 msgid "" -"Specifies time in seconds since last successful online authentication for " -"which user will be authenticated using cached credentials while SSSD is in " -"the online mode. If the credentials are incorrect, SSSD falls back to online " -"authentication." +"Specifies the number of seconds since the last successful online " +"authentication during which SSSD will authenticate users via cached " +"credentials, even while online. If the cached authentication fails, SSSD " +"immediately falls back to online authentication." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3898 +#: sssd.conf.5.xml:4103 msgid "" "This option's value is inherited by all trusted domains. At the moment it is " "not possible to set a different value per trusted domain." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3903 +#: sssd.conf.5.xml:4108 msgid "Special value 0 implies that this feature is disabled." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3907 +#: sssd.conf.5.xml:4112 msgid "" "Please note that if <quote>cached_auth_timeout</quote> is longer than " "<quote>pam_id_timeout</quote> then the back end could be called to handle " @@ -4511,12 +4713,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3918 +#: sssd.conf.5.xml:4123 msgid "local_auth_policy (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3921 +#: sssd.conf.5.xml:4126 msgid "" "Local authentication methods policy. Some backends (i.e. LDAP, proxy " "provider) only support a password based authentication, while others can " @@ -4528,7 +4730,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3933 +#: sssd.conf.5.xml:4138 msgid "" "There are three possible values for this option: match, only, " "enable. <quote>match</quote> is used to match offline and online states for " @@ -4540,7 +4742,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3946 +#: sssd.conf.5.xml:4151 msgid "" "The following table shows which authentication methods, if configured " "properly, are currently enabled or disabled for each backend, with the " @@ -4548,42 +4750,47 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> -#: sssd.conf.5.xml:3959 +#: sssd.conf.5.xml:4164 msgid "local_auth_policy = match (default)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> -#: sssd.conf.5.xml:3960 +#: sssd.conf.5.xml:4165 msgid "Passkey" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> -#: sssd.conf.5.xml:3961 +#: sssd.conf.5.xml:4166 msgid "Smartcard" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:3964 sssd-ldap.5.xml:228 +#: sssd.conf.5.xml:4169 sssd-ldap.5.xml:228 msgid "IPA" msgstr "" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry><para> +#: sssd.conf.5.xml:4169 sssd.conf.5.xml:4170 sssd.conf.5.xml:4173 +msgid "enabled" +msgstr "" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:3967 sssd-ldap.5.xml:233 +#: sssd.conf.5.xml:4172 sssd-ldap.5.xml:233 msgid "AD" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry><para> -#: sssd.conf.5.xml:3967 sssd.conf.5.xml:3970 sssd.conf.5.xml:3971 +#: sssd.conf.5.xml:4172 sssd.conf.5.xml:4175 sssd.conf.5.xml:4176 msgid "disabled" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry> -#: sssd.conf.5.xml:3970 +#: sssd.conf.5.xml:4175 msgid "LDAP" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3975 +#: sssd.conf.5.xml:4180 msgid "" "Please note that if local Smartcard authentication is enabled and a " "Smartcard is present, Smartcard authentication will be preferred over the " @@ -4592,7 +4799,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:3987 +#: sssd.conf.5.xml:4192 #, no-wrap msgid "" "[domain/shadowutils]\n" @@ -4603,7 +4810,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3983 +#: sssd.conf.5.xml:4188 msgid "" "The following configuration example allows local users to authenticate " "locally using any enabled method (i.e. smartcard, passkey). <placeholder " @@ -4611,29 +4818,29 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3995 +#: sssd.conf.5.xml:4200 msgid "Default: match" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4000 +#: sssd.conf.5.xml:4205 msgid "auto_private_groups (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4006 +#: sssd.conf.5.xml:4211 msgid "true" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4009 +#: sssd.conf.5.xml:4214 msgid "" "Create user's private group unconditionally from user's UID number. The GID " "number is ignored in this case." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4013 +#: sssd.conf.5.xml:4218 msgid "" "NOTE: Because the GID number and the user private group are inferred from " "the UID number, it is not supported to have multiple entries with the same " @@ -4642,24 +4849,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4022 +#: sssd.conf.5.xml:4227 msgid "false" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4025 +#: sssd.conf.5.xml:4230 msgid "" "Always use the user's primary GID number. The GID number must refer to a " "group object in the LDAP database." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4031 +#: sssd.conf.5.xml:4236 msgid "hybrid" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4034 +#: sssd.conf.5.xml:4239 msgid "" "A primary group is autogenerated for user entries whose UID and GID numbers " "have the same value and at the same time the GID number does not correspond " @@ -4669,14 +4876,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4047 +#: sssd.conf.5.xml:4252 msgid "" "If the UID and GID of a user are different, then the GID must correspond to " "a group entry, otherwise the GID is simply not resolvable." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4054 +#: sssd.conf.5.xml:4259 msgid "" "This feature is useful for environments that wish to stop maintaining a " "separate group objects for the user private groups, but also wish to retain " @@ -4684,14 +4891,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4003 +#: sssd.conf.5.xml:4208 msgid "" "This option takes any of three available values: <placeholder " "type=\"variablelist\" id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4066 +#: sssd.conf.5.xml:4271 msgid "" "For the LDAP based id providers (LDAP, IPA and AD) the default for the " "configured domain is typically False because the sources have the concept of " @@ -4701,14 +4908,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4075 +#: sssd.conf.5.xml:4280 msgid "" "For subdomains, the default value is False for subdomains that use assigned " "POSIX IDs and True for subdomains that use automatic ID-mapping." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:4083 +#: sssd.conf.5.xml:4288 #, no-wrap msgid "" "[domain/forest.domain/sub.domain]\n" @@ -4716,7 +4923,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:4089 +#: sssd.conf.5.xml:4294 #, no-wrap msgid "" "[domain/forest.domain]\n" @@ -4725,7 +4932,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4080 +#: sssd.conf.5.xml:4285 msgid "" "The value of auto_private_groups can either be set per subdomains in a " "subsection, for example: <placeholder type=\"programlisting\" id=\"0\"/> or " @@ -4734,7 +4941,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:2503 +#: sssd.conf.5.xml:2549 msgid "" "These configuration options can be present in a domain configuration " "section, that is, in a section called " @@ -4743,17 +4950,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4104 +#: sssd.conf.5.xml:4309 msgid "proxy_pam_target (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4107 +#: sssd.conf.5.xml:4312 msgid "The proxy target PAM proxies to." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4110 +#: sssd.conf.5.xml:4315 msgid "" "Default: not set by default, you have to take an existing pam configuration " "or create a new one and add the service name here. As an alternative you can " @@ -4761,12 +4968,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4120 +#: sssd.conf.5.xml:4325 msgid "proxy_lib_name (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4123 +#: sssd.conf.5.xml:4328 msgid "" "The name of the NSS library to use in proxy domains. The NSS functions " "searched for in the library are in the form of _nss_$(libName)_$(function), " @@ -4774,12 +4981,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4133 +#: sssd.conf.5.xml:4338 msgid "proxy_resolver_lib_name (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4136 +#: sssd.conf.5.xml:4341 msgid "" "The name of the NSS library to use for hosts and networks lookups in proxy " "domains. The NSS functions searched for in the library are in the form of " @@ -4787,12 +4994,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4147 +#: sssd.conf.5.xml:4352 msgid "proxy_fast_alias (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4150 +#: sssd.conf.5.xml:4355 msgid "" "When a user or group is looked up by name in the proxy provider, a second " "lookup by ID is performed to \"canonicalize\" the name in case the requested " @@ -4801,12 +5008,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4164 +#: sssd.conf.5.xml:4369 msgid "proxy_max_children (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4167 +#: sssd.conf.5.xml:4372 msgid "" "This option specifies the number of pre-forked proxy children. It is useful " "for high-load SSSD environments where sssd may run out of available child " @@ -4814,19 +5021,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4100 +#: sssd.conf.5.xml:4305 msgid "" "Options valid for proxy domains. <placeholder type=\"variablelist\" " "id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:4183 +#: sssd.conf.5.xml:4388 msgid "Application domains" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:4185 +#: sssd.conf.5.xml:4390 msgid "" "SSSD, with its D-Bus interface (see <citerefentry> " "<refentrytitle>sssd-ifp</refentrytitle> <manvolnum>5</manvolnum> " @@ -4844,7 +5051,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:4205 +#: sssd.conf.5.xml:4410 msgid "" "Please note that the application domain must still be explicitly enabled in " "the <quote>domains</quote> parameter so that the lookup order between the " @@ -4852,17 +5059,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><title> -#: sssd.conf.5.xml:4211 +#: sssd.conf.5.xml:4416 msgid "Application domain parameters" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4213 +#: sssd.conf.5.xml:4418 msgid "inherit_from (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4216 +#: sssd.conf.5.xml:4421 msgid "" "The SSSD POSIX-type domain the application domain inherits all settings " "from. The application domain can moreover add its own settings to the " @@ -4871,7 +5078,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:4230 +#: sssd.conf.5.xml:4435 msgid "" "The following example illustrates the use of an application domain. In this " "setup, the POSIX domain is connected to an LDAP server and is used by the OS " @@ -4881,7 +5088,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><programlisting> -#: sssd.conf.5.xml:4238 +#: sssd.conf.5.xml:4443 #, no-wrap msgid "" "[sssd]\n" @@ -4901,12 +5108,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:4258 +#: sssd.conf.5.xml:4463 msgid "TRUSTED DOMAIN SECTION" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4260 +#: sssd.conf.5.xml:4465 msgid "" "Some options used in the domain section can also be used in the trusted " "domain section, that is, in a section called " @@ -4917,69 +5124,79 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4267 +#: sssd.conf.5.xml:4472 msgid "ldap_search_base," msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4268 +#: sssd.conf.5.xml:4473 msgid "ldap_user_search_base," msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4269 +#: sssd.conf.5.xml:4474 msgid "ldap_group_search_base," msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4270 +#: sssd.conf.5.xml:4475 msgid "ldap_netgroup_search_base," msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4271 +#: sssd.conf.5.xml:4476 msgid "ldap_service_search_base," msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4272 +#: sssd.conf.5.xml:4477 msgid "ldap_sasl_mech," msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4273 +#: sssd.conf.5.xml:4478 msgid "ad_server," msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4274 +#: sssd.conf.5.xml:4479 msgid "ad_backup_server," msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4275 +#: sssd.conf.5.xml:4480 msgid "ad_site," msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:4276 sssd-ipa.5.xml:934 +#: sssd.conf.5.xml:4481 sssd-ipa.5.xml:929 msgid "use_fully_qualified_names" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4280 +#: sssd.conf.5.xml:4482 +msgid "pam_gssapi_services" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:4483 +msgid "pam_gssapi_check_upn" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:4485 msgid "" "For more details about these options see their individual description in the " "manual page." msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:4286 +#: sssd.conf.5.xml:4491 msgid "CERTIFICATE MAPPING SECTION" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4288 +#: sssd.conf.5.xml:4493 msgid "" "To allow authentication with Smartcards and certificates SSSD must be able " "to map certificates to users. This can be done by adding the full " @@ -4993,7 +5210,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4302 +#: sssd.conf.5.xml:4507 msgid "" "To make the mapping more flexible mapping and matching rules were added to " "SSSD (see <citerefentry> <refentrytitle>sss-certmap</refentrytitle> " @@ -5001,7 +5218,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4311 +#: sssd.conf.5.xml:4516 msgid "" "A mapping and matching rule can be added to the SSSD configuration in a " "section on its own with a name like " @@ -5010,55 +5227,50 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4318 +#: sssd.conf.5.xml:4523 msgid "matchrule (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4321 +#: sssd.conf.5.xml:4526 msgid "" "Only certificates from the Smartcard which matches this rule will be " "processed, all others are ignored." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4325 +#: sssd.conf.5.xml:4530 msgid "" "Default: KRB5:<EKU>clientAuth, i.e. only certificates which have the " "Extended Key Usage <quote>clientAuth</quote>" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4332 +#: sssd.conf.5.xml:4537 msgid "maprule (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4335 +#: sssd.conf.5.xml:4540 msgid "Defines how the user is found for a given certificate." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:4341 +#: sssd.conf.5.xml:4546 msgid "" "LDAP:(userCertificate;binary={cert!bin}) for LDAP based providers like " "<quote>ldap</quote>, <quote>AD</quote> or <quote>ipa</quote>." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:4347 +#: sssd.conf.5.xml:4552 msgid "" "If maprule is not set and provider is <quote>proxy</quote>, the RULE_NAME " "name is assumed to be the name of the matching user." msgstr "" -#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4357 -msgid "domains (string)" -msgstr "" - #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4360 +#: sssd.conf.5.xml:4565 msgid "" "Comma separated list of domain names the rule should be applied. By default " "a rule is only valid in the domain configured in sssd.conf. If the provider " @@ -5067,17 +5279,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4367 +#: sssd.conf.5.xml:4572 msgid "Default: the configured domain in sssd.conf" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4372 +#: sssd.conf.5.xml:4577 msgid "priority (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4375 +#: sssd.conf.5.xml:4580 msgid "" "Unsigned integer value defining the priority of the rule. The higher the " "number the lower the priority. <quote>0</quote> stands for the highest " @@ -5085,17 +5297,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4381 +#: sssd.conf.5.xml:4586 msgid "Default: the lowest priority" msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:4389 +#: sssd.conf.5.xml:4594 msgid "PROMPTING CONFIGURATION SECTION" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4391 +#: sssd.conf.5.xml:4596 msgid "" "If a special file " "(<filename>/var/lib/sss/pubconf/pam_preauth_available</filename>) exists " @@ -5105,7 +5317,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4399 +#: sssd.conf.5.xml:4604 msgid "" "With the growing number of authentication methods and the possibility that " "there are multiple ones for a single user the heuristic used by pam_sss to " @@ -5114,59 +5326,59 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4411 +#: sssd.conf.5.xml:4616 msgid "[prompting/password]" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4414 +#: sssd.conf.5.xml:4619 msgid "password_prompt" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4415 +#: sssd.conf.5.xml:4620 msgid "to change the string of the password prompt" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4413 +#: sssd.conf.5.xml:4618 msgid "" "to configure password prompting, allowed options are: <placeholder " "type=\"variablelist\" id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4423 +#: sssd.conf.5.xml:4628 msgid "[prompting/2fa]" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4427 +#: sssd.conf.5.xml:4632 msgid "first_prompt" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4428 +#: sssd.conf.5.xml:4633 msgid "to change the string of the prompt for the first factor" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4431 +#: sssd.conf.5.xml:4636 msgid "second_prompt" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4432 +#: sssd.conf.5.xml:4637 msgid "to change the string of the prompt for the second factor" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4435 +#: sssd.conf.5.xml:4640 msgid "single_prompt" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4436 +#: sssd.conf.5.xml:4641 msgid "" "boolean value, if True there will be only a single prompt using the value of " "first_prompt where it is expected that both factors are entered as a single " @@ -5175,7 +5387,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4425 +#: sssd.conf.5.xml:4630 msgid "" "to configure two-factor authentication prompting, allowed options are: " "<placeholder type=\"variablelist\" id=\"0\"/> If the second factor is " @@ -5184,7 +5396,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4449 +#: sssd.conf.5.xml:4654 msgid "" "Some clients, such as SSH with 'PasswordAuthentication yes', generate their " "own prompts and do not use prompts provided by SSSD or other PAM " @@ -5195,17 +5407,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4464 +#: sssd.conf.5.xml:4669 msgid "[prompting/passkey]" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:4470 sssd-ad.5.xml:1022 +#: sssd.conf.5.xml:4675 sssd.conf.5.xml:4719 sssd-ad.5.xml:1027 msgid "interactive" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4472 +#: sssd.conf.5.xml:4677 msgid "" "boolean value, if True prompt a message and wait before testing the presence " "of a passkey device. Recommended if your device doesn’t have a tactile " @@ -5213,55 +5425,131 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4480 +#: sssd.conf.5.xml:4685 sssd.conf.5.xml:4735 msgid "interactive_prompt" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4482 +#: sssd.conf.5.xml:4687 sssd.conf.5.xml:4737 msgid "to change the message of the interactive prompt." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4487 +#: sssd.conf.5.xml:4692 msgid "touch" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4489 +#: sssd.conf.5.xml:4694 msgid "" "boolean value, if True prompt a message to remind the user to touch the " "device." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4495 +#: sssd.conf.5.xml:4700 msgid "touch_prompt" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4497 +#: sssd.conf.5.xml:4702 msgid "to change the message of the touch prompt." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4466 +#: sssd.conf.5.xml:4671 msgid "" "to configure passkey authentication prompting, allowed options are: " "<placeholder type=\"variablelist\" id=\"0\"/>" msgstr "" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4713 +msgid "[prompting/oauth2]" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4721 +msgid "" +"boolean value, if True prompt a message after asking the user to " +"authenticate, and wait before requesting the access token." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4725 +msgid "" +"If False, make sure to set the <quote>idp_request_timeout</quote> " +"sufficiently high, to give the user time to authenticate." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4715 +msgid "" +"to configure OAuth2 authentication prompting, allowed options are: " +"<placeholder type=\"variablelist\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4748 +msgid "[prompting/cert_auth]" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4754 +msgid "pin_prompt" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4756 +msgid "" +"to change the message which asks the user to enter the PIN at the computer " +"keyboard. At the end of the message the token name is printed." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4764 +msgid "keypad_prompt" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4766 +msgid "" +"to change the message which asks the user to enter the PIN at keypad of the " +"Smartcard reader. At the end of the message the token name is printed." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4774 +msgid "user_name_hint" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4776 +msgid "" +"boolean value, if True ask for a user name if no name was given before and " +"the found certificate can be mapped to more than one user." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4750 +msgid "" +"to configure Smartcard authentication prompting, allowed options are: " +"<placeholder type=\"variablelist\" id=\"0\"/>" +msgstr "" + #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4406 +#: sssd.conf.5.xml:4611 msgid "" "Each supported authentication method has its own configuration subsection " "under <quote>[prompting/...]</quote>. Currently there are: <placeholder " "type=\"variablelist\" id=\"0\"/> <placeholder type=\"variablelist\" " -"id=\"1\"/> <placeholder type=\"variablelist\" id=\"2\"/>" +"id=\"1\"/> <placeholder type=\"variablelist\" id=\"2\"/> <placeholder " +"type=\"variablelist\" id=\"3\"/> <placeholder type=\"variablelist\" " +"id=\"4\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4508 +#: sssd.conf.5.xml:4792 msgid "" "It is possible to add a subsection for specific PAM services, " "e.g. <quote>[prompting/password/sshd]</quote> to individual change the " @@ -5269,12 +5557,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:4515 pam_sss_gss.8.xml:157 idmap_sss.8.xml:43 +#: sssd.conf.5.xml:4799 pam_sss_gss.8.xml:157 idmap_sss.8.xml:43 msgid "EXAMPLES" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd.conf.5.xml:4521 +#: sssd.conf.5.xml:4805 #, no-wrap msgid "" "[sssd]\n" @@ -5303,7 +5591,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4517 +#: sssd.conf.5.xml:4801 msgid "" "1. The following example shows a typical SSSD config. It does not describe " "configuration of the domains themselves - refer to documentation on " @@ -5312,7 +5600,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd.conf.5.xml:4553 +#: sssd.conf.5.xml:4837 #, no-wrap msgid "" "[domain/ipa.com/child.ad.com]\n" @@ -5320,7 +5608,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4547 +#: sssd.conf.5.xml:4831 msgid "" "2. The following example shows configuration of IPA AD trust where the AD " "forest consists of two domains in a parent-child structure. Suppose IPA " @@ -5331,7 +5619,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd.conf.5.xml:4564 +#: sssd.conf.5.xml:4848 #, no-wrap msgid "" "[certmap/my.domain/rule_name]\n" @@ -5342,7 +5630,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4558 +#: sssd.conf.5.xml:4842 msgid "" "3. The following example shows the configuration of a certificate mapping " "rule. It is valid for the configured domain <quote>my.domain</quote> and " @@ -5540,7 +5828,7 @@ msgid "" "defaultNamingContext does not exist or has an empty value namingContexts is " "used. The namingContexts attribute must have a single value with the DN of " "the search base of the LDAP server to make this work. Multiple values are " -"are not supported." +"not supported." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> @@ -5842,15 +6130,15 @@ msgid "Optional. Use the given string as search base for host objects." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap.5.xml:472 sssd-ipa.5.xml:506 sssd-ipa.5.xml:525 sssd-ipa.5.xml:544 -#: sssd-ipa.5.xml:563 +#: sssd-ldap.5.xml:472 sssd-ipa.5.xml:501 sssd-ipa.5.xml:520 sssd-ipa.5.xml:539 +#: sssd-ipa.5.xml:558 msgid "" "See <quote>ldap_search_base</quote> for information about configuring " "multiple search bases." msgstr "" #. type: Content of: <listitem><para> -#: sssd-ldap.5.xml:477 sssd-ipa.5.xml:511 include/ldap_search_bases.xml:27 +#: sssd-ldap.5.xml:477 sssd-ipa.5.xml:506 include/ldap_search_bases.xml:27 msgid "Default: the value of <emphasis>ldap_search_base</emphasis>" msgstr "" @@ -5974,7 +6262,7 @@ msgid "" "closed early to ensure that a new query cannot require the connection to " "remain open past its expiration. This implies that connections will always " "be closed immediately and will never be reused if " -"<emphasis>ldap_connection_expire_timeout <= ldap_opt_timout</emphasis>" +"<emphasis>ldap_connection_expire_timeout <= ldap_opt_timeout</emphasis>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> @@ -6157,7 +6445,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:831 -msgid "ldap_ignore_unreadable_references (bool)" +msgid "ldap_ignore_unreadable_references (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> @@ -6483,7 +6771,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap.5.xml:1152 sssd-ad.5.xml:1267 +#: sssd-ldap.5.xml:1152 sssd-ad.5.xml:1260 msgid "Default: 86400 (24 hours)" msgstr "" @@ -6522,7 +6810,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ldap.5.xml:1187 sssd-ipa.5.xml:575 sssd-krb5.5.xml:103 +#: sssd-ldap.5.xml:1187 sssd-ipa.5.xml:570 sssd-krb5.5.xml:103 msgid "krb5_realm (string)" msgstr "" @@ -6680,7 +6968,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1339 -msgid "ldap_chpass_update_last_change (bool)" +msgid "ldap_chpass_update_last_change (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> @@ -6828,7 +7116,7 @@ msgid "ldap_access_order (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap.5.xml:1470 sssd-ipa.5.xml:405 +#: sssd-ldap.5.xml:1470 sssd-ipa.5.xml:400 msgid "Comma separated list of access control options. Allowed values are:" msgstr "" @@ -6874,7 +7162,7 @@ msgid "<emphasis>expire</emphasis>: use ldap_account_expire_policy" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap.5.xml:1515 sssd-ipa.5.xml:413 +#: sssd-ldap.5.xml:1515 sssd-ipa.5.xml:408 msgid "" "<emphasis>pwd_expire_policy_reject, pwd_expire_policy_warn, " "pwd_expire_policy_renew: </emphasis> These options are useful if users are " @@ -6884,24 +7172,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap.5.xml:1525 sssd-ipa.5.xml:423 +#: sssd-ldap.5.xml:1525 sssd-ipa.5.xml:418 msgid "" "The difference between these options is the action taken if user password is " "expired:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ldap.5.xml:1530 sssd-ipa.5.xml:428 +#: sssd-ldap.5.xml:1530 sssd-ipa.5.xml:423 msgid "pwd_expire_policy_reject - user is denied to log in," msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ldap.5.xml:1536 sssd-ipa.5.xml:434 +#: sssd-ldap.5.xml:1536 sssd-ipa.5.xml:429 msgid "pwd_expire_policy_warn - user is still able to log in," msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ldap.5.xml:1542 sssd-ipa.5.xml:440 +#: sssd-ldap.5.xml:1542 sssd-ipa.5.xml:435 msgid "" "pwd_expire_policy_renew - user is prompted to change their password " "immediately." @@ -7437,8 +7725,8 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd-ldap.5.xml:2032 sssd-simple.5.xml:169 sssd-ipa.5.xml:984 -#: sssd-ad.5.xml:1470 sssd-idp.5.xml:248 sssd-krb5.5.xml:483 +#: sssd-ldap.5.xml:2032 sssd-simple.5.xml:169 sssd-ipa.5.xml:979 +#: sssd-ad.5.xml:1463 sssd-idp.5.xml:343 sssd-krb5.5.xml:483 #: sss_rpcidmapd.5.xml:98 sssd-session-recording.5.xml:176 msgid "EXAMPLE" msgstr "" @@ -7466,7 +7754,7 @@ msgstr "" #. type: Content of: <refsect1><refsect2><para> #: sssd-ldap.5.xml:2039 sssd-ldap.5.xml:2057 sssd-simple.5.xml:177 -#: sssd-ipa.5.xml:992 sssd-ad.5.xml:1478 sssd-sudo.5.xml:56 sssd-krb5.5.xml:492 +#: sssd-ipa.5.xml:987 sssd-ad.5.xml:1471 sssd-sudo.5.xml:56 sssd-krb5.5.xml:492 #: sssd-session-recording.5.xml:182 include/ldap_id_mapping.xml:105 msgid "<placeholder type=\"programlisting\" id=\"0\"/>" msgstr "" @@ -7501,7 +7789,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><title> #: sssd-ldap.5.xml:2073 sssd_krb5_locator_plugin.8.xml:83 sssd-simple.5.xml:189 -#: sssd-ad.5.xml:1493 sssd.8.xml:270 sss_seed.8.xml:163 +#: sssd-ad.5.xml:1486 sssd.8.xml:270 sss_seed.8.xml:163 msgid "NOTES" msgstr "" @@ -8011,7 +8299,7 @@ msgstr "" #: pam_sss.8.xml:434 msgid "" "No authentication method was found by Kerberos. This might happen if the " -"user has a Smartcard assigned but the pkint plugin is not available on the " +"user has a Smartcard assigned but the pkinit plugin is not available on the " "client." msgstr "" @@ -8437,6 +8725,23 @@ msgid "" "first DNS resolving failure." msgstr "" +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_locator_plugin.8.xml:106 +msgid "" +"If the environment variable SSSD_KRB5_LOCATOR_KDC_ADDRESS is set to a KDC " +"address the plugin will use this address instead of reading the kdcinfo " +"file. The address format is the same as in the kdcinfo file (see above)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_locator_plugin.8.xml:112 +msgid "" +"If the environment variable SSSD_KRB5_LOCATOR_KPASSWD_ADDRESS is set to a " +"kpasswd server address the plugin will use this address instead of reading " +"the kpasswdinfo file. The address format is the same as in the kpasswdinfo " +"file (see above)." +msgstr "" + #. type: Content of: <reference><refentry><refnamediv><refname> #: sssd-simple.5.xml:10 sssd-simple.5.xml:16 msgid "sssd-simple" @@ -9820,7 +10125,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:129 sssd-ad.5.xml:1161 +#: sssd-ipa.5.xml:129 sssd-ad.5.xml:1166 msgid "dyndns_update (boolean)" msgstr "" @@ -9834,20 +10139,13 @@ msgid "" "<quote>dyndns_iface</quote> option." msgstr "" -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:141 sssd-ad.5.xml:1175 -msgid "" -"NOTE: On older systems (such as RHEL 5), for this behavior to work reliably, " -"the default Kerberos realm must be set properly in /etc/krb5.conf" -msgstr "" - #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:152 sssd-ad.5.xml:1186 +#: sssd-ipa.5.xml:147 sssd-ad.5.xml:1186 msgid "dyndns_ttl (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:155 sssd-ad.5.xml:1189 +#: sssd-ipa.5.xml:150 sssd-ad.5.xml:1189 msgid "" "The TTL to apply to the client DNS record when updating it. If " "dyndns_update is false this has no effect. This will override the TTL " @@ -9855,17 +10153,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:160 +#: sssd-ipa.5.xml:155 msgid "Default: 1200 (seconds)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:166 sssd-ad.5.xml:1200 +#: sssd-ipa.5.xml:161 sssd-ad.5.xml:1200 msgid "dyndns_iface (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:169 sssd-ad.5.xml:1203 +#: sssd-ipa.5.xml:164 sssd-ad.5.xml:1203 msgid "" "Optional. Applicable only when dyndns_update is true. Choose the interface " "or a list of interfaces whose IP addresses should be used for dynamic DNS " @@ -9877,24 +10175,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:182 +#: sssd-ipa.5.xml:177 msgid "" "Default: Use the IP addresses of the interface which is used for IPA LDAP " "connection" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:186 sssd-ad.5.xml:1226 +#: sssd-ipa.5.xml:181 sssd-ad.5.xml:1220 msgid "Example: dyndns_iface = em[12], !vnet1, vnet*" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:192 sssd-ad.5.xml:1232 +#: sssd-ipa.5.xml:187 sssd-ad.5.xml:1226 msgid "dyndns_address (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:195 sssd-ad.5.xml:1235 +#: sssd-ipa.5.xml:190 sssd-ad.5.xml:1229 msgid "" "Optional. Applicable only when <emphasis>dyndns_update</emphasis> is true. " "A list of IP addresses or IP networks to be used for dynamic DNS " @@ -9905,22 +10203,22 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:206 sssd-ad.5.xml:1246 +#: sssd-ipa.5.xml:201 sssd-ad.5.xml:1240 msgid "Default: No filtering of IP addresses." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:209 sssd-ad.5.xml:1249 +#: sssd-ipa.5.xml:204 sssd-ad.5.xml:1243 msgid "Example: dyndns_address = 10.0.0.0/16, !10.0.1.0/24" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:215 sssd-ad.5.xml:1305 +#: sssd-ipa.5.xml:210 sssd-ad.5.xml:1298 msgid "dyndns_auth (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:218 sssd-ad.5.xml:1308 +#: sssd-ipa.5.xml:213 sssd-ad.5.xml:1301 msgid "" "Whether the nsupdate utility should use GSS-TSIG authentication for secure " "updates with the DNS server, insecure updates can be sent by setting this " @@ -9928,17 +10226,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:224 sssd-ad.5.xml:1314 +#: sssd-ipa.5.xml:219 sssd-ad.5.xml:1307 msgid "Default: GSS-TSIG" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:230 sssd-ad.5.xml:1320 +#: sssd-ipa.5.xml:225 sssd-ad.5.xml:1313 msgid "dyndns_auth_ptr (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:233 sssd-ad.5.xml:1323 +#: sssd-ipa.5.xml:228 sssd-ad.5.xml:1316 msgid "" "Whether the nsupdate utility should use GSS-TSIG authentication for secure " "PTR updates with the DNS server, insecure updates can be sent by setting " @@ -9946,17 +10244,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:239 sssd-ad.5.xml:1329 +#: sssd-ipa.5.xml:234 sssd-ad.5.xml:1322 msgid "Default: Same as dyndns_auth" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:245 sssd-ad.5.xml:1255 +#: sssd-ipa.5.xml:240 sssd-ad.5.xml:1249 msgid "dyndns_refresh_interval (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:248 +#: sssd-ipa.5.xml:243 msgid "" "How often should the back end perform periodic DNS update in addition to the " "automatic update performed when the back end goes online. This option is " @@ -9964,74 +10262,74 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:261 sssd-ad.5.xml:1273 -msgid "dyndns_update_ptr (bool)" +#: sssd-ipa.5.xml:256 sssd-ad.5.xml:1266 +msgid "dyndns_update_ptr (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:264 sssd-ad.5.xml:1276 +#: sssd-ipa.5.xml:259 sssd-ad.5.xml:1269 msgid "" "Whether the PTR record should also be explicitly updated when updating the " "client's DNS records. Applicable only when dyndns_update is true." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:269 +#: sssd-ipa.5.xml:264 msgid "" "This option should be False in most IPA deployments as the IPA server " "generates the PTR records automatically when forward records are changed." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:275 sssd-ad.5.xml:1281 +#: sssd-ipa.5.xml:270 sssd-ad.5.xml:1274 msgid "" "Note that <emphasis>dyndns_update_per_family</emphasis> parameter does not " "apply for PTR record updates. Those updates are always sent separately." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:280 +#: sssd-ipa.5.xml:275 msgid "Default: False (disabled)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:286 sssd-ad.5.xml:1292 -msgid "dyndns_force_tcp (bool)" +#: sssd-ipa.5.xml:281 sssd-ad.5.xml:1285 +msgid "dyndns_force_tcp (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:289 sssd-ad.5.xml:1295 +#: sssd-ipa.5.xml:284 sssd-ad.5.xml:1288 msgid "" "Whether the nsupdate utility should default to using TCP for communicating " "with the DNS server." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:293 sssd-ad.5.xml:1299 +#: sssd-ipa.5.xml:288 sssd-ad.5.xml:1292 msgid "Default: False (let nsupdate choose the protocol)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:299 sssd-ad.5.xml:1335 +#: sssd-ipa.5.xml:294 sssd-ad.5.xml:1328 msgid "dyndns_server (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:302 sssd-ad.5.xml:1338 +#: sssd-ipa.5.xml:297 sssd-ad.5.xml:1331 msgid "" "The DNS server to use when performing a DNS update. In most setups, it's " "recommended to leave this option unset." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:307 sssd-ad.5.xml:1343 +#: sssd-ipa.5.xml:302 sssd-ad.5.xml:1336 msgid "" "Setting this option makes sense for environments where the DNS server is " "different from the identity server or when we use encrypted DNS." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:312 sssd-ad.5.xml:1348 +#: sssd-ipa.5.xml:307 sssd-ad.5.xml:1341 msgid "" "The parameter can be a simple string containing DNS name or IP address. It " "can also be an URI. The URI can look like " @@ -10040,7 +10338,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:319 sssd-ad.5.xml:1355 +#: sssd-ipa.5.xml:314 sssd-ad.5.xml:1348 msgid "" "The second example enables DNS-over-TLS protocol for DNS updates. The " "nsupdate utility must support DoT - check the <emphasis>man " @@ -10048,7 +10346,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:325 sssd-ad.5.xml:1361 +#: sssd-ipa.5.xml:320 sssd-ad.5.xml:1354 msgid "" "Please note that this option will be only used in fallback attempt when " "previous attempt using autodetected settings failed or when DNS-over-TLS is " @@ -10056,17 +10354,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:331 sssd-ad.5.xml:1367 +#: sssd-ipa.5.xml:326 sssd-ad.5.xml:1360 msgid "Default: None (let nsupdate choose the server)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:337 sssd-ad.5.xml:1373 +#: sssd-ipa.5.xml:332 sssd-ad.5.xml:1366 msgid "dyndns_update_per_family (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:340 sssd-ad.5.xml:1376 +#: sssd-ipa.5.xml:335 sssd-ad.5.xml:1369 msgid "" "DNS update is by default performed in two steps - IPv4 update and then IPv6 " "update. In some cases it might be desirable to perform IPv4 and IPv6 update " @@ -10074,12 +10372,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:352 sssd-ad.5.xml:1388 +#: sssd-ipa.5.xml:347 sssd-ad.5.xml:1381 msgid "dyndns_dot_cacert (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:355 sssd-ad.5.xml:1391 +#: sssd-ipa.5.xml:350 sssd-ad.5.xml:1384 msgid "" "This option specifies the file of the certificate authorities certificates " "(in PEM format) in order to verify the remote server TLS certificate when " @@ -10087,17 +10385,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:361 sssd-ad.5.xml:1397 +#: sssd-ipa.5.xml:356 sssd-ad.5.xml:1390 msgid "Default: None (use global certificate store)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:367 sssd-ad.5.xml:1403 +#: sssd-ipa.5.xml:362 sssd-ad.5.xml:1396 msgid "dyndns_dot_cert (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:370 sssd-ad.5.xml:1406 +#: sssd-ipa.5.xml:365 sssd-ad.5.xml:1399 msgid "" "This option sets the certificate(s) file for authentication for the DoT " "transport to the remote server. The certificate chain file is expected to be " @@ -10105,7 +10403,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:376 sssd-ad.5.xml:1412 +#: sssd-ipa.5.xml:371 sssd-ad.5.xml:1405 msgid "" "The <emphasis>dyndns_dot_cert</emphasis> and " "<emphasis>dyndns_dot_key</emphasis> options must be both set to achieve " @@ -10113,17 +10411,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:381 sssd-ipa.5.xml:396 sssd-ad.5.xml:1417 sssd-ad.5.xml:1432 +#: sssd-ipa.5.xml:376 sssd-ipa.5.xml:391 sssd-ad.5.xml:1410 sssd-ad.5.xml:1425 msgid "Default: None (Do not use TLS authentication)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:387 sssd-ad.5.xml:1423 +#: sssd-ipa.5.xml:382 sssd-ad.5.xml:1416 msgid "dyndns_dot_key (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:390 sssd-ad.5.xml:1426 +#: sssd-ipa.5.xml:385 sssd-ad.5.xml:1419 msgid "" "This option sets the key file for authenticated encryption for the DoT " "transport to the remote server. The private key file is expected to be in " @@ -10131,169 +10429,169 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:402 +#: sssd-ipa.5.xml:397 msgid "ipa_access_order (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:409 +#: sssd-ipa.5.xml:404 msgid "<emphasis>expire</emphasis>: use IPA's account expiration policy." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:448 +#: sssd-ipa.5.xml:443 msgid "" "Please note that 'access_provider = ipa' must be set for this feature to " "work." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:455 +#: sssd-ipa.5.xml:450 msgid "ipa_deskprofile_search_base (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:458 +#: sssd-ipa.5.xml:453 msgid "" "Optional. Use the given string as search base for Desktop Profile related " "objects." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:462 sssd-ipa.5.xml:484 +#: sssd-ipa.5.xml:457 sssd-ipa.5.xml:479 msgid "Default: Use base DN" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:468 +#: sssd-ipa.5.xml:463 msgid "ipa_subid_ranges_search_base (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:471 +#: sssd-ipa.5.xml:466 msgid "Deprecated. Use ldap_subid_ranges_search_base instead." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:477 +#: sssd-ipa.5.xml:472 msgid "ipa_hbac_search_base (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:480 +#: sssd-ipa.5.xml:475 msgid "Optional. Use the given string as search base for HBAC related objects." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:490 +#: sssd-ipa.5.xml:485 msgid "ipa_host_search_base (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:493 +#: sssd-ipa.5.xml:488 msgid "Deprecated. Use ldap_host_search_base instead." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:499 +#: sssd-ipa.5.xml:494 msgid "ipa_selinux_search_base (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:502 +#: sssd-ipa.5.xml:497 msgid "Optional. Use the given string as search base for SELinux user maps." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:518 +#: sssd-ipa.5.xml:513 msgid "ipa_subdomains_search_base (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:521 +#: sssd-ipa.5.xml:516 msgid "Optional. Use the given string as search base for trusted domains." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:530 +#: sssd-ipa.5.xml:525 msgid "Default: the value of <emphasis>cn=trusts,%basedn</emphasis>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:537 +#: sssd-ipa.5.xml:532 msgid "ipa_master_domain_search_base (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:540 +#: sssd-ipa.5.xml:535 msgid "Optional. Use the given string as search base for master domain object." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:549 +#: sssd-ipa.5.xml:544 msgid "Default: the value of <emphasis>cn=ad,cn=etc,%basedn</emphasis>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:556 +#: sssd-ipa.5.xml:551 msgid "ipa_views_search_base (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:559 +#: sssd-ipa.5.xml:554 msgid "Optional. Use the given string as search base for views containers." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:568 +#: sssd-ipa.5.xml:563 msgid "Default: the value of <emphasis>cn=views,cn=accounts,%basedn</emphasis>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:578 +#: sssd-ipa.5.xml:573 msgid "" "The name of the Kerberos realm. This is optional and defaults to the value " "of <quote>ipa_domain</quote>." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:582 +#: sssd-ipa.5.xml:577 msgid "" "The name of the Kerberos realm has a special meaning in IPA - it is " "converted into the base DN to use for performing LDAP operations." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:590 sssd-ad.5.xml:1441 +#: sssd-ipa.5.xml:585 sssd-ad.5.xml:1434 msgid "krb5_confd_path (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:593 sssd-ad.5.xml:1444 +#: sssd-ipa.5.xml:588 sssd-ad.5.xml:1437 msgid "" "Absolute path of a directory where SSSD should place Kerberos configuration " "snippets." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:597 sssd-ad.5.xml:1448 +#: sssd-ipa.5.xml:592 sssd-ad.5.xml:1441 msgid "" "To disable the creation of the configuration snippets set the parameter to " "'none'." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:601 sssd-ad.5.xml:1452 +#: sssd-ipa.5.xml:596 sssd-ad.5.xml:1445 msgid "Default: not set (krb5.include.d subdirectory of SSSD's pubconf directory)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:608 +#: sssd-ipa.5.xml:603 msgid "ipa_deskprofile_refresh (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:611 +#: sssd-ipa.5.xml:606 msgid "" "The amount of time between lookups of the Desktop Profile rules against the " "IPA server. This will reduce the latency and load on the IPA server if there " @@ -10301,34 +10599,34 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:618 sssd-ipa.5.xml:648 sssd-ipa.5.xml:664 sssd-ad.5.xml:600 +#: sssd-ipa.5.xml:613 sssd-ipa.5.xml:643 sssd-ipa.5.xml:659 sssd-ad.5.xml:600 msgid "Default: 5 (seconds)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:624 +#: sssd-ipa.5.xml:619 msgid "ipa_deskprofile_request_interval (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:627 +#: sssd-ipa.5.xml:622 msgid "" "The amount of time between lookups of the Desktop Profile rules against the " "IPA server in case the last request did not return any rule." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:632 +#: sssd-ipa.5.xml:627 msgid "Default: 60 (minutes)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:638 +#: sssd-ipa.5.xml:633 msgid "ipa_hbac_refresh (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:641 +#: sssd-ipa.5.xml:636 msgid "" "The amount of time between lookups of the HBAC rules against the IPA " "server. This will reduce the latency and load on the IPA server if there are " @@ -10336,12 +10634,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:654 -msgid "ipa_hbac_selinux (integer)" +#: sssd-ipa.5.xml:649 +msgid "ipa_selinux_refresh (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:657 +#: sssd-ipa.5.xml:652 msgid "" "The amount of time between lookups of the SELinux maps against the IPA " "server. This will reduce the latency and load on the IPA server if there are " @@ -10349,33 +10647,33 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:670 +#: sssd-ipa.5.xml:665 msgid "ipa_server_mode (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:673 +#: sssd-ipa.5.xml:668 msgid "" "This option will be set by the IPA installer (ipa-server-install) " "automatically and denotes if SSSD is running on an IPA server or not." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:678 +#: sssd-ipa.5.xml:673 msgid "" "On an IPA server SSSD will lookup users and groups from trusted domains " "directly while on a client it will ask an IPA server." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:683 +#: sssd-ipa.5.xml:678 msgid "" "NOTE: There are currently some assumptions that must be met when SSSD is " "running on an IPA server." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:688 +#: sssd-ipa.5.xml:683 msgid "" "The <quote>ipa_server</quote> option must be configured to point to the IPA " "server itself. This is already the default set by the IPA installer, so no " @@ -10383,59 +10681,59 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:697 +#: sssd-ipa.5.xml:692 msgid "" "The <quote>full_name_format</quote> option must not be tweaked to only print " "short names for users from trusted domains." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:712 +#: sssd-ipa.5.xml:707 msgid "ipa_automount_location (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:715 +#: sssd-ipa.5.xml:710 msgid "The automounter location this IPA client will be using" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:718 +#: sssd-ipa.5.xml:713 msgid "Default: The location named \"default\"" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd-ipa.5.xml:726 +#: sssd-ipa.5.xml:721 msgid "VIEWS AND OVERRIDES" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:735 +#: sssd-ipa.5.xml:730 msgid "ipa_view_class (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:738 +#: sssd-ipa.5.xml:733 msgid "Objectclass of the view container." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:741 +#: sssd-ipa.5.xml:736 msgid "Default: nsContainer" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:747 +#: sssd-ipa.5.xml:742 msgid "ipa_view_name (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:750 +#: sssd-ipa.5.xml:745 msgid "Name of the attribute holding the name of the view." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:754 sssd-ldap-attributes.5.xml:496 +#: sssd-ipa.5.xml:749 sssd-ldap-attributes.5.xml:496 #: sssd-ldap-attributes.5.xml:832 sssd-ldap-attributes.5.xml:913 #: sssd-ldap-attributes.5.xml:1010 sssd-ldap-attributes.5.xml:1068 #: sssd-ldap-attributes.5.xml:1226 sssd-ldap-attributes.5.xml:1271 @@ -10443,128 +10741,128 @@ msgid "Default: cn" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:760 +#: sssd-ipa.5.xml:755 msgid "ipa_override_object_class (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:763 +#: sssd-ipa.5.xml:758 msgid "Objectclass of the override objects." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:766 +#: sssd-ipa.5.xml:761 msgid "Default: ipaOverrideAnchor" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:772 +#: sssd-ipa.5.xml:767 msgid "ipa_anchor_uuid (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:775 +#: sssd-ipa.5.xml:770 msgid "" "Name of the attribute containing the reference to the original object in a " "remote domain." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:779 +#: sssd-ipa.5.xml:774 msgid "Default: ipaAnchorUUID" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:785 +#: sssd-ipa.5.xml:780 msgid "ipa_user_override_object_class (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:788 +#: sssd-ipa.5.xml:783 msgid "" "Name of the objectclass for user overrides. It is used to determine if the " "found override object is related to a user or a group." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:793 +#: sssd-ipa.5.xml:788 msgid "User overrides can contain attributes given by" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:796 +#: sssd-ipa.5.xml:791 msgid "ldap_user_name" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:799 +#: sssd-ipa.5.xml:794 msgid "ldap_user_uid_number" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:802 +#: sssd-ipa.5.xml:797 msgid "ldap_user_gid_number" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:805 +#: sssd-ipa.5.xml:800 msgid "ldap_user_gecos" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:808 +#: sssd-ipa.5.xml:803 msgid "ldap_user_home_directory" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:811 +#: sssd-ipa.5.xml:806 msgid "ldap_user_shell" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:814 +#: sssd-ipa.5.xml:809 msgid "ldap_user_ssh_public_key" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:819 +#: sssd-ipa.5.xml:814 msgid "Default: ipaUserOverride" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:825 +#: sssd-ipa.5.xml:820 msgid "ipa_group_override_object_class (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:828 +#: sssd-ipa.5.xml:823 msgid "" "Name of the objectclass for group overrides. It is used to determine if the " "found override object is related to a user or a group." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:833 +#: sssd-ipa.5.xml:828 msgid "Group overrides can contain attributes given by" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:836 +#: sssd-ipa.5.xml:831 msgid "ldap_group_name" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:839 +#: sssd-ipa.5.xml:834 msgid "ldap_group_gid_number" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:844 +#: sssd-ipa.5.xml:839 msgid "Default: ipaGroupOverride" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:728 +#: sssd-ipa.5.xml:723 msgid "" "SSSD can handle views and overrides which are offered by FreeIPA 4.1 and " "later version. Since all paths and objectclasses are fixed on the server " @@ -10574,19 +10872,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd-ipa.5.xml:856 +#: sssd-ipa.5.xml:851 msgid "SUBDOMAINS PROVIDER" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:858 +#: sssd-ipa.5.xml:853 msgid "" "The IPA subdomains provider behaves slightly differently if it is configured " "explicitly or implicitly." msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:862 +#: sssd-ipa.5.xml:857 msgid "" "If the option 'subdomains_provider = ipa' is found in the domain section of " "sssd.conf, the IPA subdomains provider is configured explicitly, and all " @@ -10594,7 +10892,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:868 +#: sssd-ipa.5.xml:863 msgid "" "If the option 'subdomains_provider' is not set in the domain section of " "sssd.conf but there is the option 'id_provider = ipa', the IPA subdomains " @@ -10606,12 +10904,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd-ipa.5.xml:879 +#: sssd-ipa.5.xml:874 msgid "TRUSTED DOMAINS CONFIGURATION" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-ipa.5.xml:887 +#: sssd-ipa.5.xml:882 #, no-wrap msgid "" "[domain/ipa.domain.com/ad.domain.com]\n" @@ -10619,7 +10917,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:881 +#: sssd-ipa.5.xml:876 msgid "" "Some configuration options can also be set for a trusted domain. A trusted " "domain configuration can be set using the trusted domain subsection as shown " @@ -10629,7 +10927,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:892 +#: sssd-ipa.5.xml:887 msgid "" "For more details, see the <citerefentry> " "<refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</manvolnum> " @@ -10637,90 +10935,90 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:899 +#: sssd-ipa.5.xml:894 msgid "" "Different configuration options are tunable for a trusted domain depending " "on whether you are configuring SSSD on an IPA server or an IPA client." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd-ipa.5.xml:904 +#: sssd-ipa.5.xml:899 msgid "OPTIONS TUNABLE ON IPA MASTERS" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:906 +#: sssd-ipa.5.xml:901 msgid "The following options can be set in a subdomain section on an IPA master:" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:910 sssd-ipa.5.xml:950 +#: sssd-ipa.5.xml:905 sssd-ipa.5.xml:945 msgid "ad_server" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:913 +#: sssd-ipa.5.xml:908 msgid "ad_backup_server" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:916 sssd-ipa.5.xml:953 +#: sssd-ipa.5.xml:911 sssd-ipa.5.xml:948 msgid "ad_site" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:919 +#: sssd-ipa.5.xml:914 msgid "ipa_server" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:922 +#: sssd-ipa.5.xml:917 msgid "ipa_backup_server" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:925 +#: sssd-ipa.5.xml:920 msgid "ldap_search_base" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:928 +#: sssd-ipa.5.xml:923 msgid "ldap_user_search_base" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:931 +#: sssd-ipa.5.xml:926 msgid "ldap_group_search_base" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:939 +#: sssd-ipa.5.xml:934 msgid "" "Options prefixed with 'ad_' or 'ipa_' only apply to their respective " "subdomain type." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd-ipa.5.xml:944 +#: sssd-ipa.5.xml:939 msgid "OPTIONS TUNABLE ON IPA CLIENTS" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:946 +#: sssd-ipa.5.xml:941 msgid "" "The following options can be set in an AD subdomain section on an IPA " "client:" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:958 +#: sssd-ipa.5.xml:953 msgid "" "Note that if both options are set, only <quote>ad_server</quote> is " "evaluated." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:962 +#: sssd-ipa.5.xml:957 msgid "" "Since any request for a user or a group identity from a trusted domain " "triggered from an IPA client is resolved by the IPA server, the " @@ -10735,7 +11033,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:986 +#: sssd-ipa.5.xml:981 msgid "" "The following example assumes that SSSD is correctly configured and " "example.com is one of the domains in the <replaceable>[sssd]</replaceable> " @@ -10743,7 +11041,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-ipa.5.xml:993 +#: sssd-ipa.5.xml:988 #, no-wrap msgid "" "[domain/example.com]\n" @@ -11443,27 +11741,27 @@ msgid "lxdm" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:694 +#: sssd-ad.5.xml:699 msgid "sddm" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:699 +#: sssd-ad.5.xml:704 msgid "unity" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:704 +#: sssd-ad.5.xml:709 msgid "xdm" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:713 +#: sssd-ad.5.xml:718 msgid "ad_gpo_map_remote_interactive (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:716 +#: sssd-ad.5.xml:721 msgid "" "A comma-separated list of PAM service names for which GPO-based access " "control is evaluated based on the RemoteInteractiveLogonRight and " @@ -11479,7 +11777,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:735 +#: sssd-ad.5.xml:740 msgid "" "Note: Using the Group Policy Management Editor this value is called \"Allow " "log on through Remote Desktop Services\" and \"Deny log on through Remote " @@ -11487,7 +11785,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:750 +#: sssd-ad.5.xml:755 #, no-wrap msgid "" "ad_gpo_map_remote_interactive = +my_pam_service, -sshd\n" @@ -11495,7 +11793,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:741 +#: sssd-ad.5.xml:746 msgid "" "It is possible to add another PAM service name to the default set by using " "<quote>+service_name</quote> or to explicitly remove a PAM service name from " @@ -11507,22 +11805,22 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:758 +#: sssd-ad.5.xml:763 msgid "sshd" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:763 +#: sssd-ad.5.xml:768 msgid "cockpit" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:772 +#: sssd-ad.5.xml:777 msgid "ad_gpo_map_network (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:775 +#: sssd-ad.5.xml:780 msgid "" "A comma-separated list of PAM service names for which GPO-based access " "control is evaluated based on the NetworkLogonRight and " @@ -11538,7 +11836,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:793 +#: sssd-ad.5.xml:798 msgid "" "Note: Using the Group Policy Management Editor this value is called \"Access " "this computer from the network\" and \"Deny access to this computer from the " @@ -11546,7 +11844,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:808 +#: sssd-ad.5.xml:813 #, no-wrap msgid "" "ad_gpo_map_network = +my_pam_service, -ftp\n" @@ -11554,7 +11852,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:799 +#: sssd-ad.5.xml:804 msgid "" "It is possible to add another PAM service name to the default set by using " "<quote>+service_name</quote> or to explicitly remove a PAM service name from " @@ -11566,22 +11864,22 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:816 +#: sssd-ad.5.xml:821 msgid "ftp" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:821 +#: sssd-ad.5.xml:826 msgid "samba" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:830 +#: sssd-ad.5.xml:835 msgid "ad_gpo_map_batch (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:833 +#: sssd-ad.5.xml:838 msgid "" "A comma-separated list of PAM service names for which GPO-based access " "control is evaluated based on the BatchLogonRight and DenyBatchLogonRight " @@ -11596,14 +11894,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:851 +#: sssd-ad.5.xml:856 msgid "" "Note: Using the Group Policy Management Editor this value is called \"Allow " "log on as a batch job\" and \"Deny log on as a batch job\"." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:865 +#: sssd-ad.5.xml:870 #, no-wrap msgid "" "ad_gpo_map_batch = +my_pam_service, -crond\n" @@ -11611,7 +11909,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:856 +#: sssd-ad.5.xml:861 msgid "" "It is possible to add another PAM service name to the default set by using " "<quote>+service_name</quote> or to explicitly remove a PAM service name from " @@ -11623,22 +11921,22 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:868 +#: sssd-ad.5.xml:873 msgid "Note: Cron service name may differ depending on Linux distribution used." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:874 +#: sssd-ad.5.xml:879 msgid "crond" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:883 +#: sssd-ad.5.xml:888 msgid "ad_gpo_map_service (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:886 +#: sssd-ad.5.xml:891 msgid "" "A comma-separated list of PAM service names for which GPO-based access " "control is evaluated based on the ServiceLogonRight and " @@ -11654,14 +11952,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:904 +#: sssd-ad.5.xml:909 msgid "" "Note: Using the Group Policy Management Editor this value is called \"Allow " "log on as a service\" and \"Deny log on as a service\"." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:917 +#: sssd-ad.5.xml:922 #, no-wrap msgid "" "ad_gpo_map_service = +my_pam_service\n" @@ -11669,7 +11967,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:909 sssd-ad.5.xml:984 +#: sssd-ad.5.xml:914 sssd-ad.5.xml:989 msgid "" "It is possible to add a PAM service name to the default set by using " "<quote>+service_name</quote>. Since the default set is empty, it is not " @@ -11680,19 +11978,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:927 +#: sssd-ad.5.xml:932 msgid "ad_gpo_map_permit (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:930 +#: sssd-ad.5.xml:935 msgid "" "A comma-separated list of PAM service names for which GPO-based access is " "always granted, regardless of any GPO Logon Rights." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:944 +#: sssd-ad.5.xml:949 #, no-wrap msgid "" "ad_gpo_map_permit = +my_pam_service, -sudo\n" @@ -11700,7 +11998,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:935 +#: sssd-ad.5.xml:940 msgid "" "It is possible to add another PAM service name to the default set by using " "<quote>+service_name</quote> or to explicitly remove a PAM service name from " @@ -11712,29 +12010,29 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:952 +#: sssd-ad.5.xml:957 msgid "polkit-1" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:967 +#: sssd-ad.5.xml:972 msgid "systemd-user" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:976 +#: sssd-ad.5.xml:981 msgid "ad_gpo_map_deny (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:979 +#: sssd-ad.5.xml:984 msgid "" "A comma-separated list of PAM service names for which GPO-based access is " "always denied, regardless of any GPO Logon Rights." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:992 +#: sssd-ad.5.xml:997 #, no-wrap msgid "" "ad_gpo_map_deny = +my_pam_service\n" @@ -11742,12 +12040,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:1002 +#: sssd-ad.5.xml:1007 msgid "ad_gpo_default_right (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1005 +#: sssd-ad.5.xml:1010 msgid "" "This option defines how access control is evaluated for PAM service names " "that are not explicitly listed in one of the ad_gpo_map_* options. This " @@ -11760,52 +12058,52 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1018 +#: sssd-ad.5.xml:1023 msgid "Supported values for this option include:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1027 +#: sssd-ad.5.xml:1032 msgid "remote_interactive" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1032 +#: sssd-ad.5.xml:1037 msgid "network" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1037 +#: sssd-ad.5.xml:1042 msgid "batch" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1042 +#: sssd-ad.5.xml:1047 msgid "service" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1047 +#: sssd-ad.5.xml:1052 msgid "permit" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1052 +#: sssd-ad.5.xml:1057 msgid "deny" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1058 +#: sssd-ad.5.xml:1063 msgid "Default: deny" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:1064 +#: sssd-ad.5.xml:1069 msgid "ad_maximum_machine_account_password_age (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1067 +#: sssd-ad.5.xml:1072 msgid "" "SSSD will check once a day if the machine account password is older than the " "given age in days and try to renew it. A value of 0 will disable the renewal " @@ -11813,17 +12111,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1073 +#: sssd-ad.5.xml:1078 msgid "Default: 30 days" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:1079 +#: sssd-ad.5.xml:1084 msgid "ad_machine_account_password_renewal_opts (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1082 +#: sssd-ad.5.xml:1087 msgid "" "This option should only be used to test the machine account renewal " "task. The option expects 3 integers and a string separated by a colon " @@ -11836,20 +12134,20 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1096 +#: sssd-ad.5.xml:1101 msgid "" "The optional fourth string value identifies the helper binary which should " "be used for the renewal. Currently <command>adcli</command> and " "<command>realm</command> are supported. If this value is missing or empty in " "the value string <command>realm</command> will be used. Since the helper is " "started as the user SSSD is running as there might be the chance that the " -"renewal will fail if this user does not has permissions to modify the keytab " -"file where the machine account credentials are stored. This will typically " -"be the case for <command>adcli</command>." +"renewal will fail if this user does not have permissions to modify the " +"keytab file where the machine account credentials are stored. This will " +"typically be the case for <command>adcli</command>." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1110 +#: sssd-ad.5.xml:1115 msgid "" "<command>realm</command> is not updating the keytab directly but is calling " "the <command>realmd</command> process, which runs as root user, for this " @@ -11859,17 +12157,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1119 +#: sssd-ad.5.xml:1124 msgid "Default: 86400:750:300:realm (24h, 12m30s and 5m)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:1125 +#: sssd-ad.5.xml:1130 msgid "ad_update_samba_machine_account_password (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1128 +#: sssd-ad.5.xml:1133 msgid "" "If enabled, when SSSD renews the machine account password, it will also be " "updated in Samba's database. This prevents Samba's copy of the machine " @@ -11878,23 +12176,23 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:1141 -msgid "ad_use_ldaps (bool)" +#: sssd-ad.5.xml:1146 +msgid "ad_use_ldaps (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1144 +#: sssd-ad.5.xml:1149 msgid "" "By default SSSD uses the plain LDAP port 389 and the Global Catalog port " -"3628. If this option is set to True SSSD will use the LDAPS port 636 and " -"Global Catalog port 3629 with LDAPS protection. Since AD does not allow to " +"3268. If this option is set to True SSSD will use the LDAPS port 636 and " +"Global Catalog port 3269 with LDAPS protection. Since AD does not allow to " "have multiple encryption layers on a single connection and we still want to " "use SASL/GSSAPI or SASL/GSS-SPNEGO for authentication the SASL security " "property maxssf is set to 0 (zero) for those connections." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1164 +#: sssd-ad.5.xml:1169 msgid "" "Optional. This option tells SSSD to automatically update the Active " "Directory DNS server with the IP address of this client. The update is " @@ -11912,30 +12210,21 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:1216 msgid "" -"NOTE: While it is still possible to use the old " -"<emphasis>ipa_dyndns_iface</emphasis> option, users should migrate to using " -"<emphasis>dyndns_iface</emphasis> in their config file." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1222 -msgid "" "Default: Use the IP addresses of the interface which is used for AD LDAP " "connection" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1258 +#: sssd-ad.5.xml:1252 msgid "" "How often should the back end perform periodic DNS update in addition to the " -"automatic update performed when the back end goes online. This option is " -"optional and applicable only when dyndns_update is true. Note that the " -"lowest possible value is 60 seconds in-case if value is provided less than " -"60, parameter will assume lowest value only." +"automatic update performed when the back end goes online. This is optional " +"and applicable only when dyndns_update is true. Note that the minimum value " +"is 60 seconds, any specified value below this threshold will default to 60." msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ad.5.xml:1472 +#: sssd-ad.5.xml:1465 msgid "" "The following example assumes that SSSD is correctly configured and " "example.com is one of the domains in the <replaceable>[sssd]</replaceable> " @@ -11943,7 +12232,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-ad.5.xml:1479 +#: sssd-ad.5.xml:1472 #, no-wrap msgid "" "[domain/EXAMPLE]\n" @@ -11958,7 +12247,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-ad.5.xml:1499 +#: sssd-ad.5.xml:1492 #, no-wrap msgid "" "access_provider = ldap\n" @@ -11967,7 +12256,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ad.5.xml:1495 +#: sssd-ad.5.xml:1488 msgid "" "The AD access control provider checks if the account is expired. It has the " "same effect as the following configuration of the LDAP provider: " @@ -11975,7 +12264,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ad.5.xml:1505 +#: sssd-ad.5.xml:1498 msgid "" "However, unless the <quote>ad</quote> access control provider is explicitly " "configured, the default access provider is <quote>permit</quote>. Please " @@ -11985,7 +12274,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ad.5.xml:1513 +#: sssd-ad.5.xml:1506 msgid "" "When the autofs provider is set to <quote>ad</quote>, the RFC2307 schema " "attribute mapping (nisMap, nisObject, ...) is used, because these attributes " @@ -12139,9 +12428,9 @@ msgstr "" #: sssd-sudo.5.xml:137 msgid "" "The <emphasis>smart refresh</emphasis> periodically downloads rules that are " -"new or were modified after the last update. Its primary goal is to keep the " -"database growing by fetching only small increments that do not generate " -"large amounts of network traffic." +"new or were modified after the last update. Its primary goal is to grow the " +"database incrementally by fetching only small updates, avoiding large " +"amounts of network traffic." msgstr "" #. type: Content of: <reference><refentry><refsect1><para> @@ -12324,22 +12613,25 @@ msgstr "" msgid "" "Depending on the IdP product additional platform specific options might " "follow the name separated by a colon (:). E.g. for Keycloak the base URI for " -"the user and group REST API must be given. For Entra ID this is not needed " -"because there is a generic endpoint for all tenants." +"the user and group REST API must be given. For Entra ID the base URI for the " +"Microsoft Graph API can be given to use sovereign or government cloud " +"endpoints instead of the default (https://graph.microsoft.com/v1.0). E.g. " +"<quote>entra_id:https://graph.microsoft.us/v1.0</quote> for the US " +"government cloud (GCC High)." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:78 sssd-idp.5.xml:94 sssd-idp.5.xml:119 +#: sssd-idp.5.xml:82 sssd-idp.5.xml:98 sssd-idp.5.xml:123 msgid "Default: Not set (Required)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:83 +#: sssd-idp.5.xml:87 msgid "idp_client_id (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:86 +#: sssd-idp.5.xml:90 msgid "" "ID of the IdP client used by SSSD to authenticate users and as a client to " "lookup user and group attributes. This client must offer device " @@ -12348,12 +12640,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:99 +#: sssd-idp.5.xml:103 msgid "idp_client_secret (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:102 +#: sssd-idp.5.xml:106 msgid "" "Password of the IdP client. The password is required for the id_provider. If " "only used as auth_provider it depends on the server side configuration if it " @@ -12361,66 +12653,73 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:113 +#: sssd-idp.5.xml:117 msgid "idp_token_endpoint (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:116 +#: sssd-idp.5.xml:120 msgid "IdP endpoint for requesting access tokens." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:124 +#: sssd-idp.5.xml:128 msgid "idp_device_auth_endpoint (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:127 +#: sssd-idp.5.xml:131 msgid "" "IdP endpoint for device authorization according to RFC-8628. This is " "required for user authentication." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:137 +#: sssd-idp.5.xml:141 msgid "idp_userinfo_endpoint (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:140 +#: sssd-idp.5.xml:144 msgid "" "IdP userinfo endpoint to request user attributes after a successful " "authentication of the user. Required for authentication." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:150 +#: sssd-idp.5.xml:154 msgid "idp_id_scope (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:153 +#: sssd-idp.5.xml:157 msgid "" "Scope required for looking up user and group attributes with the REST " "API. The scopes are used by the server to determine which attributes/claims " "are returned to the caller." msgstr "" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:163 +msgid "" +"Note: In previous versions of SSSD, this option was expected to already be " +"URL-encoded." +msgstr "" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:164 +#: sssd-idp.5.xml:172 msgid "idp_auth_scope (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:167 +#: sssd-idp.5.xml:175 msgid "" "Scope required during authentication. The scopes are used by the server to " "determine which attributes/claims are returned to the caller." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:172 +#: sssd-idp.5.xml:180 msgid "" "Currently the tokens returned during user authentication are not used for " "other purposes hence the only important claim is the subject identifier " @@ -12429,22 +12728,116 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:185 +#: sssd-idp.5.xml:193 +msgid "idp_auth_user_identifier_attr (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:196 +msgid "" +"Attribute used to identify the authenticated user in userinfo data or token " +"claims." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:200 +msgid "" +"For hybrid Active Directory and Entra ID deployments where " +"<quote>id_provider = ad</quote> and <quote>auth_provider = idp</quote>, this " +"option must be set explicitly. No value is derived from the identity " +"provider, because more than one attribute can link an Entra ID object to its " +"on-premises counterpart and only the administrator knows which one the " +"directory synchronization is configured to use." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:211 +msgid "" +"Setting this option to <quote>onPremisesImmutableId</quote> is the usual " +"choice for such deployments. Microsoft Entra Connect populates that " +"attribute with the base64-encoded form of the 16-byte Active Directory " +"<quote>objectGUID</quote> when objectGUID is used as the sourceAnchor. SSSD " +"decodes the value and converts the raw bytes with the same conversion used " +"for AD objectGUID attributes, so the result matches the UUID stored in the " +"SSSD cache for the AD user." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:224 +msgid "" +"Note that Microsoft Entra Connect 1.1.524.0 and later use " +"<quote>ms-DS-ConsistencyGuid</quote> as the sourceAnchor for user objects " +"instead of <quote>objectGUID</quote>. The value is normally copied from " +"objectGUID for objects that do not have it set yet, in which case the " +"decoded identifier still matches. It does not match if ms-DS-ConsistencyGuid " +"was populated independently, if users were moved between forests or domains, " +"or if a different attribute such as employeeID was selected as the " +"sourceAnchor. See <ulink " +"url=\"https://learn.microsoft.com/en-us/entra/identity/hybrid/connect/plan-connect-design-concepts\"> " +"Microsoft Entra Connect: Design concepts</ulink> for details on sourceAnchor " +"selection." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:241 +msgid "" +"Microsoft Graph does not return <quote>onPremisesImmutableId</quote> by " +"default. The <quote>idp_userinfo_endpoint</quote> must request it with " +"<quote>$select</quote>, see the example below and <ulink " +"url=\"https://learn.microsoft.com/en-us/graph/api/resources/user\"> the " +"Microsoft Graph user resource type</ulink>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:251 +msgid "" +"If the configured attribute is missing or cannot be decoded (for example " +"cloud-only Entra ID users without <quote>onPremisesImmutableId</quote>), " +"authentication fails. SSSD does not fall back to another attribute when this " +"option is set." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:258 +msgid "" +"Default: not set, <quote>sub</quote> for Keycloak and <quote>id</quote> for " +"other IdP types" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-idp.5.xml:264 msgid "idp_request_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:188 +#: sssd-idp.5.xml:267 msgid "Timeout in seconds for an individual request to the IdP." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:197 +#: sssd-idp.5.xml:276 +msgid "idp_auto_refresh (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:279 +msgid "" +"Refresh tokens automatically, after they have reached about half their " +"lifetime." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:283 +msgid "Note: Scheduled token refreshes are not preserved across restarts of SSSD." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-idp.5.xml:292 msgid "idmap_range_min (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:200 +#: sssd-idp.5.xml:295 msgid "" "Specifies the lower (inclusive) bound of the range of POSIX IDs to use for " "mapping IdP users and group to POSIX IDs. It is the first POSIX ID which can " @@ -12452,7 +12845,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:206 +#: sssd-idp.5.xml:301 msgid "" "The interval between <quote>idmap_range_min</quote> and " "<quote>idmap_range_max</quote> will be split into smaller ranges of size " @@ -12461,18 +12854,18 @@ msgid "" msgstr "" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:213 sssd-idp.5.xml:239 include/ldap_id_mapping.xml:139 +#: sssd-idp.5.xml:308 sssd-idp.5.xml:334 include/ldap_id_mapping.xml:139 #: include/ldap_id_mapping.xml:197 msgid "Default: 200000" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:218 +#: sssd-idp.5.xml:313 msgid "idmap_range_max (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:221 +#: sssd-idp.5.xml:316 msgid "" "Specifies the upper (exclusive) bound of the range of POSIX IDs to use for " "mapping IdP users and groups to POSIX IDs. It is the first POSIX ID which " @@ -12480,40 +12873,66 @@ msgid "" msgstr "" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:227 include/ldap_id_mapping.xml:165 +#: sssd-idp.5.xml:322 include/ldap_id_mapping.xml:165 msgid "Default: 2000200000" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:232 +#: sssd-idp.5.xml:327 msgid "idmap_range_size (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:235 +#: sssd-idp.5.xml:330 msgid "Specifies the number of POSIX IDs available for a single IdP domain." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-idp.5.xml:251 +#: sssd-idp.5.xml:346 #, no-wrap msgid "" "[domain/entra_id]\n" "id_provider = idp\n" "idp_type = entra_id\n" "idp_client_id = 12345678-abcd-0101-efef-ba9876543210\n" -"idp_client_secret = YOUR-CLIENT-SCERET\n" +"idp_client_secret = YOUR-CLIENT-SECRET\n" "idp_token_endpoint = " -"https://login.microsoftonline.com/TENNANT-ID/oauth2/v2.0/token\n" +"https://login.microsoftonline.com/TENANT-ID/oauth2/v2.0/token\n" "idp_userinfo_endpoint = https://graph.microsoft.com/v1.0/me\n" "idp_device_auth_endpoint = " -"https://login.microsoftonline.com/TENNANT-ID/oauth2/v2.0/devicecode\n" -"idp_id_scope = https%3A%2F%2Fgraph.microsoft.com%2F.default\n" +"https://login.microsoftonline.com/TENANT-ID/oauth2/v2.0/devicecode\n" +"idp_id_scope = https://graph.microsoft.com/.default\n" +"idp_auth_scope = openid profile email\n" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><programlisting> +#: sssd-idp.5.xml:358 +#, no-wrap +msgid "" +"[domain/ad.example.com]\n" +"id_provider = ad\n" +"auth_provider = idp\n" +"access_provider = permit\n" +"\n" +"ad_domain = ad.example.com\n" +"krb5_realm = AD.EXAMPLE.COM\n" +"\n" +"idp_type = entra_id\n" +"idp_client_id = 12345678-abcd-0101-efef-ba9876543210\n" +"idp_client_secret = YOUR-CLIENT-SECRET\n" +"idp_token_endpoint = " +"https://login.microsoftonline.com/TENANT-ID/oauth2/v2.0/token\n" +"idp_userinfo_endpoint = " +"https://graph.microsoft.com/v1.0/me?$select=id,userPrincipalName,onPremisesImmutableId\n" +"idp_device_auth_endpoint = " +"https://login.microsoftonline.com/TENANT-ID/oauth2/v2.0/devicecode\n" +"idp_id_scope = https://graph.microsoft.com/.default\n" "idp_auth_scope = openid profile email\n" +"idp_auth_user_identifier_attr = onPremisesImmutableId\n" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-idp.5.xml:263 +#: sssd-idp.5.xml:377 #, no-wrap msgid "" "[domain/keycloak]\n" @@ -12521,7 +12940,7 @@ msgid "" "keycloak:https://master.keycloak.test:8443/auth/admin/realms/master/\n" "id_provider = idp\n" "idp_client_id = myclient\n" -"idp_client_secret = YOUR-CLIENT-SCERET\n" +"idp_client_secret = YOUR-CLIENT-SECRET\n" "idp_token_endpoint = " "https://master.keycloak.test:8443/auth/realms/master/protocol/openid-connect/token\n" "idp_userinfo_endpoint = " @@ -12533,10 +12952,22 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-idp.5.xml:250 +#: sssd-idp.5.xml:345 msgid "" "<placeholder type=\"programlisting\" id=\"0\"/> <placeholder " -"type=\"programlisting\" id=\"1\"/>" +"type=\"programlisting\" id=\"1\"/> <placeholder type=\"programlisting\" " +"id=\"2\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-idp.5.xml:390 +msgid "" +"In the hybrid Active Directory and Entra ID example above, " +"<quote>onPremisesImmutableId</quote> is used during authentication so the " +"IdP result matches the AD objectGUID UUID stored in the SSSD cache. The " +"attribute must be requested via <quote>$select</quote> on the Graph userinfo " +"endpoint and is only populated for users synchronized from Active Directory " +"with objectGUID as the sourceAnchor." msgstr "" #. type: Content of: <reference><refentry><refnamediv><refname> @@ -13506,7 +13937,7 @@ msgstr "" #: sssd-krb5.5.xml:291 msgid "" "<emphasis>demand</emphasis> to use FAST. The authentication fails if the " -"server does not require fast." +"server does not support FAST." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> @@ -14397,7 +14828,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sss_rpcidmapd.5.xml:69 -msgid "memcache (bool)" +msgid "memcache (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> @@ -14451,7 +14882,7 @@ msgid "" msgstr "" #. type: Content of: <refsect1><title> -#: sss_rpcidmapd.5.xml:120 sssd-kcm.8.xml:316 include/seealso.xml:2 +#: sss_rpcidmapd.5.xml:120 sssd-kcm.8.xml:315 include/seealso.xml:2 msgid "SEE ALSO" msgstr "" @@ -14687,8 +15118,8 @@ msgstr "" #: sss_ssh_knownhosts.1.xml:93 msgid "" "The key lines retrieved from the backend are expected to respect the key " -"format as decribed in the <quote>SSH_KNOWN_HOSTS FILE FORMAT</quote> section " -"of <citerefentry><refentrytitle>sshd</refentrytitle> " +"format as described in the <quote>SSH_KNOWN_HOSTS FILE FORMAT</quote> " +"section of <citerefentry><refentrytitle>sshd</refentrytitle> " "<manvolnum>8</manvolnum></citerefentry>. However, returning only the keytype " "and the key itself is tolerated, in which case, the hostname received as " "parameter will be added before the keytype to output a correctly formatted " @@ -15167,14 +15598,13 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-kcm.8.xml:215 msgid "" -"The KCM service is configured in the <quote>kcm</quote> For a detailed " -"syntax reference, refer to the <quote>FILE FORMAT</quote> section of the " -"<citerefentry> <refentrytitle>sssd.conf</refentrytitle> " +"For a detailed syntax reference, refer to the <quote>FILE FORMAT</quote> " +"section of the <citerefentry> <refentrytitle>sssd.conf</refentrytitle> " "<manvolnum>5</manvolnum> </citerefentry> manual page." msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-kcm.8.xml:223 +#: sssd-kcm.8.xml:222 msgid "" "The generic SSSD service options such as <quote>debug_level</quote> or " "<quote>fd_limit</quote> are accepted by the kcm service. Please refer to " @@ -15184,22 +15614,22 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:234 +#: sssd-kcm.8.xml:233 msgid "socket_path (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:237 +#: sssd-kcm.8.xml:236 msgid "The socket the KCM service will listen on." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:240 +#: sssd-kcm.8.xml:239 msgid "Default: <replaceable>/var/run/.heim_org.h5l.kcm-socket</replaceable>" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:243 +#: sssd-kcm.8.xml:242 msgid "" "<phrase condition=\"have_systemd\"> Note: on platforms where systemd is " "supported, the socket path is overwritten by the one defined in the " @@ -15207,86 +15637,86 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:252 +#: sssd-kcm.8.xml:251 msgid "max_ccaches (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:255 +#: sssd-kcm.8.xml:254 msgid "How many credential caches does the KCM database allow for all users." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:259 +#: sssd-kcm.8.xml:258 msgid "Default: 0 (unlimited, only the per-UID quota is enforced)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:264 +#: sssd-kcm.8.xml:263 msgid "max_uid_ccaches (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:267 +#: sssd-kcm.8.xml:266 msgid "" "How many credential caches does the KCM database allow per UID. This is " "equivalent to <quote>with how many principals you can kinit</quote>." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:272 +#: sssd-kcm.8.xml:271 msgid "Default: 64" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:277 +#: sssd-kcm.8.xml:276 msgid "max_ccache_size (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:280 +#: sssd-kcm.8.xml:279 msgid "" -"How big can a credential cache be per ccache. Each service ticket accounts " -"into this quota." +"How big a credential cache be per ccache. Each service ticket counts toward " +"this quota." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:284 +#: sssd-kcm.8.xml:283 msgid "Default: 65536" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:289 -msgid "tgt_renewal (bool)" +#: sssd-kcm.8.xml:288 +msgid "tgt_renewal (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:292 +#: sssd-kcm.8.xml:291 msgid "Enables TGT renewals functionality." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:295 +#: sssd-kcm.8.xml:294 msgid "Default: False (Automatic renewals disabled)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:300 +#: sssd-kcm.8.xml:299 msgid "tgt_renewal_inherit (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:303 +#: sssd-kcm.8.xml:302 msgid "Domain to inherit krb5_* options from, for use with TGT renewals." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:307 +#: sssd-kcm.8.xml:306 msgid "Default: NULL" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-kcm.8.xml:318 +#: sssd-kcm.8.xml:317 msgid "" "<citerefentry> <refentrytitle>sssd</refentrytitle><manvolnum>8</manvolnum> " "</citerefentry>, <citerefentry> " @@ -16192,8 +16622,8 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap-attributes.5.xml:381 sssd-ldap-attributes.5.xml:395 -msgid "Default: loginDisabled" +#: sssd-ldap-attributes.5.xml:381 +msgid "Default: loginDisabled (rfc2307, rfc2307bis and IPA), not set (AD)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> @@ -16208,6 +16638,11 @@ msgid "" "which date access is granted." msgstr "" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:395 +msgid "Default: loginExpirationTime (rfc2307, rfc2307bis and IPA), not set (AD)" +msgstr "" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:401 msgid "ldap_user_nds_login_allowed_time_map (string)" @@ -16222,7 +16657,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:409 -msgid "Default: loginAllowedTimeMap" +msgid "Default: loginAllowedTimeMap (rfc2307, rfc2307bis and IPA), not set (AD)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> @@ -16736,8 +17171,8 @@ msgid "The object class of a host entry in LDAP." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap-attributes.5.xml:900 sssd-ldap-attributes.5.xml:997 -msgid "Default: ipService" +#: sssd-ldap-attributes.5.xml:900 sssd-ldap-attributes.5.xml:1213 +msgid "Default: ipHost" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> @@ -16822,6 +17257,11 @@ msgstr "" msgid "The object class of a service entry in LDAP." msgstr "" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:997 +msgid "Default: ipService" +msgstr "" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1003 msgid "ldap_service_name (string)" @@ -17061,11 +17501,6 @@ msgstr "" msgid "The object class of an iphost entry in LDAP." msgstr "" -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap-attributes.5.xml:1213 -msgid "Default: ipHost" -msgstr "" - #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1219 msgid "ldap_iphost_name (string)" @@ -17285,6 +17720,7 @@ msgstr "" msgid "" "[plugins]\n" " localauth = {\n" +" disable = an2ln\n" " module = sssd:/usr/lib64/sssd/modules/sssd_krb5_localauth_plugin.so\n" " }\n" msgstr "" @@ -17302,6 +17738,28 @@ msgid "" "automatically." msgstr "" +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_localauth_plugin.8.xml:67 +msgid "" +"This configuration snippet also disables the <command>an2ln</command> module " +"provided by MIT Kerberos if SSSD is configured to use the AD or IPA " +"provider. In those environments " +"<command>sssd_krb5_localauth_plugin</command> can reliably map the system " +"user names to Kerberos principals. A fallback to <command>an2ln</command> " +"might cause issues in environments where users have the privilege to create " +"Kerberos principals on their own which might collide with names of other " +"users used in the system. Other modules provided by MIT Kerberos, e.g. " +"<command>k5login</command> are not affected." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_localauth_plugin.8.xml:79 +msgid "" +"Note: If using <quote>auth_provider = krb5</quote> then " +"<command>sssd_krb5_localauth_plugin</command> is not used, therefore the " +"above text is not applicable." +msgstr "" + #. type: Content of: <variablelist><varlistentry><term> #: include/autofs_attributes.xml:3 msgid "ldap_autofs_map_object_class (string)" @@ -18159,31 +18617,6 @@ msgid "" "failures; corresponds to setting 2 in decimal notation)" msgstr "" -#. type: Content of: <refsect1><title> -#: include/local.xml:2 -msgid "THE LOCAL DOMAIN" -msgstr "" - -#. type: Content of: <refsect1><para> -#: include/local.xml:4 -msgid "" -"In order to function correctly, a domain with " -"<quote>id_provider=local</quote> must be created and the SSSD must be " -"running." -msgstr "" - -#. type: Content of: <refsect1><para> -#: include/local.xml:9 -msgid "" -"The administrator might want to use the SSSD local users instead of " -"traditional UNIX users in cases where the group nesting (see <citerefentry> " -"<refentrytitle>sss_groupadd</refentrytitle> <manvolnum>8</manvolnum> " -"</citerefentry>) is needed. The local users are also useful for testing and " -"development of the SSSD without having to deploy a full remote server. The " -"<command>sss_user*</command> and <command>sss_group*</command> tools use a " -"local LDB storage to store users and groups." -msgstr "" - #. type: Content of: <refsect1><para> #: include/seealso.xml:4 msgid "" diff --git a/src/man/po/sv.po b/src/man/po/sv.po index 0f6fdeb98e1..f8053111bc3 100644 --- a/src/man/po/sv.po +++ b/src/man/po/sv.po @@ -6,8 +6,8 @@ msgid "" msgstr "" "Project-Id-Version: sssd-docs 2.3.0\n" "Report-Msgid-Bugs-To: sssd-devel@redhat.com\n" -"POT-Creation-Date: 2026-01-14 15:00+0000\n" -"PO-Revision-Date: 2026-04-23 16:59+0000\n" +"POT-Creation-Date: 2026-10-05 16:14+0000\n" +"PO-Revision-Date: 2026-10-05 17:06+0000\n" "Last-Translator: Luna Jernberg <bittin@reimu.nl>\n" "Language-Team: Swedish <https://translate.fedoraproject.org/projects/sssd/" "sssd-manpage-master/sv/>\n" @@ -16,10 +16,10 @@ msgstr "" "Content-Type: text/plain; charset=UTF-8\n" "Content-Transfer-Encoding: 8bit\n" "Plural-Forms: nplurals=2; plural=n != 1;\n" -"X-Generator: Weblate 5.17\n" +"X-Generator: Weblate 2026.10\n" #. type: Content of: <reference><title> -#: sssd.conf.5.xml:8 sssd-ldap.5.xml:5 pam_sss.8.xml:5 pam_sss_gss.8.xml:5 +#: sssd.conf.5.xml:10 sssd-ldap.5.xml:5 pam_sss.8.xml:5 pam_sss_gss.8.xml:5 #: sssd_krb5_locator_plugin.8.xml:5 sssd-simple.5.xml:5 sss-certmap.5.xml:5 #: sssd-ipa.5.xml:5 sssd-ad.5.xml:5 sssd-sudo.5.xml:5 sssd-idp.5.xml:5 #: sssd.8.xml:5 sss_obfuscate.8.xml:5 sss_override.8.xml:5 sssd-krb5.5.xml:5 @@ -29,15 +29,15 @@ msgstr "" #: sssd-session-recording.5.xml:5 sssd-kcm.8.xml:5 sssd-systemtap.5.xml:5 #: sssd-ldap-attributes.5.xml:5 sssd_krb5_localauth_plugin.8.xml:5 msgid "SSSD Manual pages" -msgstr "SSSD manualsidor" +msgstr "SSSD-manualsidor" #. type: Content of: <reference><refentry><refnamediv><refname> -#: sssd.conf.5.xml:13 sssd.conf.5.xml:19 +#: sssd.conf.5.xml:15 sssd.conf.5.xml:21 msgid "sssd.conf" msgstr "sssd.conf" #. type: Content of: <reference><refentry><refmeta><manvolnum> -#: sssd.conf.5.xml:14 sssd-ldap.5.xml:11 sssd-simple.5.xml:11 +#: sssd.conf.5.xml:16 sssd-ldap.5.xml:11 sssd-simple.5.xml:11 #: sss-certmap.5.xml:11 sssd-ipa.5.xml:11 sssd-ad.5.xml:11 sssd-sudo.5.xml:11 #: sssd-idp.5.xml:11 sssd-krb5.5.xml:11 sssd-ifp.5.xml:11 #: sss_rpcidmapd.5.xml:27 sssd-session-recording.5.xml:11 @@ -46,7 +46,7 @@ msgid "5" msgstr "5" #. type: Content of: <reference><refentry><refmeta><refmiscinfo> -#: sssd.conf.5.xml:15 sssd-ldap.5.xml:12 sssd-simple.5.xml:12 +#: sssd.conf.5.xml:17 sssd-ldap.5.xml:12 sssd-simple.5.xml:12 #: sss-certmap.5.xml:12 sssd-ipa.5.xml:12 sssd-ad.5.xml:12 sssd-sudo.5.xml:12 #: sssd-idp.5.xml:12 sssd-krb5.5.xml:12 sssd-ifp.5.xml:12 #: sss_rpcidmapd.5.xml:28 sssd-session-recording.5.xml:12 sssd-kcm.8.xml:12 @@ -55,17 +55,17 @@ msgid "File Formats and Conventions" msgstr "Filformat och konventioner" #. type: Content of: <reference><refentry><refnamediv><refpurpose> -#: sssd.conf.5.xml:20 +#: sssd.conf.5.xml:22 msgid "the configuration file for SSSD" msgstr "konfigurationsfilen för SSSD" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:24 +#: sssd.conf.5.xml:26 msgid "FILE FORMAT" msgstr "FILFORMAT" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd.conf.5.xml:32 +#: sssd.conf.5.xml:34 #, no-wrap msgid "" "<replaceable>[section]</replaceable>\n" @@ -73,14 +73,13 @@ msgid "" "<replaceable>key2</replaceable> = <replaceable>value2,value3</replaceable>\n" " " msgstr "" -"<replaceable>[sektion]</replaceable>\n" -"<replaceable>nyckel</replaceable> = <replaceable>värde</replaceable>\n" -"<replaceable>nyckel2</replaceable> = <replaceable>värde2,värde3</replaceable>" -"\n" +"<replaceable>[section]</replaceable>\n" +"<replaceable>key</replaceable> = <replaceable>value</replaceable>\n" +"<replaceable>key2</replaceable> = <replaceable>value2,value3</replaceable>\n" " " #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:27 +#: sssd.conf.5.xml:29 msgid "" "The file has an ini-style syntax and consists of sections and parameters. A " "section begins with the name of the section in square brackets and continues " @@ -93,16 +92,17 @@ msgstr "" "parametrar: <placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:39 +#: sssd.conf.5.xml:41 msgid "" -"The data types used are string (no quotes needed), integer and bool (with " -"values of <quote>TRUE/FALSE</quote>)." +"The data types used are string (no quotes needed), integer and boolean (with " +"values of <quote>TRUE/FALSE</quote>). Boolean values are case-insensitive; " +"for example, <quote>TRUE</quote>, <quote>True</quote> and <quote>true</" +"quote> are all equivalent and valid; the same applies to <quote>FALSE</" +"quote>." msgstr "" -"Datatyperna som används är sträng (inga citationstecken behövs), heltal och " -"bool (med värdena <quote>TRUE/FALSE</quote>)." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:44 +#: sssd.conf.5.xml:49 msgid "" "A comment line starts with a hash sign (<quote>#</quote>) or a semicolon " "(<quote>;</quote>). Inline comments are not supported." @@ -111,7 +111,7 @@ msgstr "" "semikolon (<quote>;</quote>). Kommentarer inom raden stödjs inte." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:50 +#: sssd.conf.5.xml:55 msgid "" "All sections can have an optional <replaceable>description</replaceable> " "parameter. Its function is only as a label for the section." @@ -120,16 +120,16 @@ msgstr "" "replaceable>. Dess funktion är endast som en etikett för sektionen." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:56 +#: sssd.conf.5.xml:61 msgid "" "<filename>sssd.conf</filename> must be a regular file that is owned, " "readable, and writeable only by 'root'." msgstr "" -"<filename>sssd.conf</filename> måste vara en normal fil, som ägs av, är " -"läsbar och skrivbar endast av ”root”." +"<filename>sssd.conf</filename> måste vara en vanlig fil som ägs av och " +"endast är läsbar och skrivbar för 'root'." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:60 +#: sssd.conf.5.xml:65 msgid "" "<filename>sssd.conf</filename> must be a regular file that is accessible " "only by the user used to run SSSD service or root." @@ -138,35 +138,35 @@ msgstr "" "endast av användaren som används för att köra tjänsten SSSD eller root." #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:66 +#: sssd.conf.5.xml:71 msgid "CONFIGURATION SNIPPETS FROM INCLUDE DIRECTORY" msgstr "KONFIGURATIONSSNUTTAR FRÅN EN INCLUDE-KATALOG" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:69 +#: sssd.conf.5.xml:74 msgid "" "The configuration file <filename>sssd.conf</filename> will include " "configuration snippets using the include directory <filename>conf.d</" "filename>." msgstr "" -"Konfigurationsfilen <filename>sssd.conf</filename> kommer inkludera " +"Konfigurationsfilen <filename>sssd.conf</filename> kommer att inkludera " "konfigurationssnuttar från include-katalogen <filename>conf.d</filename>." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:75 +#: sssd.conf.5.xml:80 msgid "" "Any file placed in <filename>conf.d</filename> that ends in " "<quote><filename>.conf</filename></quote> and does not begin with a dot " "(<quote>.</quote>) will be used together with <filename>sssd.conf</filename> " "to configure SSSD." msgstr "" -"Filer lagda i <filename>conf.d</filename> som slutar med <quote><filename>" -".conf</filename></quote> och inte börjar med en punkt (<quote>.</quote>) " -"kommer användas tillsammans med <filename>sssd.conf</filename> för att " +"Alla filer som placeras i <filename>conf.d</filename>, slutar med <quote>" +"<filename>.conf</filename></quote> och inte börjar med en punkt (<quote>.</" +"quote>) används tillsammans med <filename>sssd.conf</filename> för att " "konfigurera SSSD." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:83 +#: sssd.conf.5.xml:88 msgid "" "The configuration snippets from <filename>conf.d</filename> have higher " "priority than <filename>sssd.conf</filename> and will override " @@ -178,16 +178,15 @@ msgid "" "(higher number means higher priority)." msgstr "" "Konfigurationssnuttarna från <filename>conf.d</filename> har högre prioritet " -"än <filename>sssd.conf</filename> och kommer åsidosätta <filename>sssd.conf</" -"filename> när konflikter uppstår. Om flera snuttar finns i <filename>" -"conf.d</filename> inkluderas de i alfabetisk ordning (baserat på lokalen). " -"Filer som inkluderas senare har högre prioritet. Numeriska prefix " -"(<filename>01_snutt.conf</filename>, <filename>02_snutt.conf</filename> " -"etc.) kan hjälpa till att visualisera prioriteten (högre tals betyder högre " -"prioritet)." +"än <filename>sssd.conf</filename> och åsidosätter <filename>sssd.conf</" +"filename> när konflikter uppstår. Om flera snuttar finns i <filename>conf.d</" +"filename> inkluderas de i alfabetisk ordning (enligt språkinställningen). " +"Filer som inkluderas senare har högre prioritet. Numeriska prefix (<filename>" +"01_snippet.conf</filename>, <filename>02_snippet.conf</filename> osv.) kan " +"tydliggöra prioriteten (högre tal betyder högre prioritet)." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:97 +#: sssd.conf.5.xml:102 msgid "" "The snippet files require the same owner and permissions as " "<filename>sssd.conf</filename>." @@ -196,50 +195,105 @@ msgstr "" "filename>." #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:103 +#: sssd.conf.5.xml:108 +#, fuzzy +#| msgid "EXAMPLE CUSTODIA AND PROXY PROVIDER CONFIGURATION" +msgid "VENDOR PROVIDED CONFIGURATION" +msgstr "EXEMPEL PÅ KONFIGURATION AV CUSTODIA- OCH PROXY-LEVERANTÖRER" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:111 +msgid "" +"The vendor provided configuration file is installed in " +"<filename>&sssd_vendor_dir;/sssd.conf</filename>, but this file must not be " +"directly edited. It can be completely masked by creating the system specific " +"configuration file <filename>&sssd_conf_dir;/sssd.conf</filename>, or partly " +"overriden by creating config snippets in <filename>&sssd_conf_dir;/conf.d</" +"filename> directory." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><title> +#: sssd.conf.5.xml:120 +#, fuzzy +#| msgid "CONFIGURATION FILE" +msgid "CONFIGURATION FILE HIERARCHY" +msgstr "KONFIGURATIONSFIL" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:122 +msgid "" +"When sssd reads the configuration it first tries to open the system specific " +"configuration file in <filename>&sssd_conf_dir;/sssd.conf</filename>. If it " +"exists, it is loaded and snippets from <filename>&sssd_conf_dir;/conf.d</" +"filename> are applied. The vendor provided configuration file " +"<filename>&sssd_vendor_dir;/sssd.conf</filename> is completely ignored in " +"this case." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:131 +msgid "" +"If the system specific configuration file <filename>&sssd_conf_dir;/" +"sssd.conf</filename> does not exist, then the vendor configuration file " +"<filename>&sssd_vendor_dir;/sssd.conf</filename> is loaded and snippets from " +"<filename>&sssd_conf_dir;/conf.d</filename> are applied." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd.conf.5.xml:141 msgid "GENERAL OPTIONS" -msgstr "ALLMÄNNA FLAGGOR" +msgstr "ALLMÄNNA ALTERNATIV" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:105 +#: sssd.conf.5.xml:143 msgid "Following options are usable in more than one configuration sections." -msgstr "Följande flaggor är användbara i mer än en konfigurationssektion." +msgstr "Följande alternativ kan användas i mer än en konfigurationssektion." #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:109 +#: sssd.conf.5.xml:147 msgid "Options usable in all sections" -msgstr "Flaggor användbara i alla sektioner" +msgstr "Alternativ som kan användas i alla sektioner" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:149 +msgid "" +"Note: Below options are ignored in <quote>[session_recording]</quote> " +"section, see <quote>Session recording configuration options</quote> section " +"for more details." +msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:113 +#: sssd.conf.5.xml:156 msgid "debug_level (integer)" msgstr "debug_level (heltal)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:117 +#: sssd.conf.5.xml:160 msgid "debug (integer)" msgstr "debug (heltal)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:120 +#: sssd.conf.5.xml:163 msgid "" "SSSD 1.14 and later also includes the <replaceable>debug</replaceable> alias " "for <replaceable>debug_level</replaceable> as a convenience feature. If both " "are specified, the value of <replaceable>debug_level</replaceable> will be " "used." msgstr "" -"SSSD 1.14 och senare inkluderar också aliaset <replaceable>debug</" +"SSSD 1.14 och senare innehåller också aliaset <replaceable>debug</" "replaceable> för <replaceable>debug_level</replaceable> som en " -"bekvämlighetsfiness. Om båda anges kommer värdet på<replaceable>debug_level</" -"replaceable> användas." +"bekvämlighetsfunktion. Om båda anges används värdet för <replaceable>" +"debug_level</replaceable>." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:130 -msgid "debug_timestamps (bool)" +#: sssd.conf.5.xml:173 +#, fuzzy +#| msgid "debug_timestamps (bool)" +msgid "debug_timestamps (boolean)" msgstr "debug_timestamps (bool)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:133 +#: sssd.conf.5.xml:176 msgid "" "Add a timestamp to the debug messages. If journald is enabled for SSSD " "debug logging this option is ignored." @@ -248,51 +302,55 @@ msgstr "" "aktiverat för SSSD-felsökningsloggning ignoreras denna flagga." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:138 sssd.conf.5.xml:175 sssd.conf.5.xml:337 -#: sssd.conf.5.xml:644 sssd.conf.5.xml:668 sssd.conf.5.xml:875 -#: sssd.conf.5.xml:979 sssd.conf.5.xml:2113 sssd-ldap.5.xml:979 -#: sssd-ldap.5.xml:1134 sssd-ldap.5.xml:1237 sssd-ldap.5.xml:1306 -#: sssd-ldap.5.xml:1714 sssd-ldap.5.xml:1848 sssd-ldap.5.xml:1913 -#: sssd-ipa.5.xml:346 sssd-ad.5.xml:252 sssd-ad.5.xml:367 sssd-ad.5.xml:1180 -#: sssd-ad.5.xml:1382 sssd-krb5.5.xml:358 +#: sssd.conf.5.xml:181 sssd.conf.5.xml:218 sssd.conf.5.xml:380 +#: sssd.conf.5.xml:687 sssd.conf.5.xml:711 sssd.conf.5.xml:827 +#: sssd.conf.5.xml:932 sssd.conf.5.xml:2149 sssd.conf.5.xml:4730 +#: sssd-ldap.5.xml:979 sssd-ldap.5.xml:1134 sssd-ldap.5.xml:1237 +#: sssd-ldap.5.xml:1306 sssd-ldap.5.xml:1714 sssd-ldap.5.xml:1848 +#: sssd-ldap.5.xml:1913 sssd-ipa.5.xml:341 sssd-ad.5.xml:252 sssd-ad.5.xml:367 +#: sssd-ad.5.xml:1180 sssd-ad.5.xml:1375 sssd-krb5.5.xml:358 msgid "Default: true" msgstr "Standard: true" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:143 -msgid "debug_microseconds (bool)" +#: sssd.conf.5.xml:186 +#, fuzzy +#| msgid "debug_microseconds (bool)" +msgid "debug_microseconds (boolean)" msgstr "debug_microseconds (bool)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:146 +#: sssd.conf.5.xml:189 msgid "" "Add microseconds to the timestamp in debug messages. If journald is enabled " "for SSSD debug logging this option is ignored." msgstr "" -"Lägg till mikrosekunder till tidsstämpeln till felsökningsmeddelanden. Om " -"journald är aktiverat för SSSD-felsökningsloggning ignoreras denna flagga." +"Lägg till mikrosekunder i tidsstämpeln i felsökningsmeddelanden. Om journald " +"är aktiverat för SSSD-felsökningsloggning ignoreras detta alternativ." #. type: Content of: <variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:151 sssd.conf.5.xml:2040 sssd.conf.5.xml:4158 +#: sssd.conf.5.xml:194 sssd.conf.5.xml:2072 sssd.conf.5.xml:4363 #: sssd-ldap.5.xml:363 sssd-ldap.5.xml:998 sssd-ldap.5.xml:1209 -#: sssd-ldap.5.xml:1663 sssd-ldap.5.xml:1937 sssd-ipa.5.xml:146 -#: sssd-ipa.5.xml:706 sssd-ad.5.xml:1135 sssd-krb5.5.xml:268 +#: sssd-ldap.5.xml:1663 sssd-ldap.5.xml:1937 sssd-ipa.5.xml:141 +#: sssd-ipa.5.xml:701 sssd-ad.5.xml:1140 sssd-idp.5.xml:287 sssd-krb5.5.xml:268 #: sssd-krb5.5.xml:330 sssd-krb5.5.xml:432 include/krb5_options.xml:163 msgid "Default: false" msgstr "Standard: false" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:156 -msgid "debug_backtrace_enabled (bool)" +#: sssd.conf.5.xml:199 +#, fuzzy +#| msgid "debug_backtrace_enabled (bool)" +msgid "debug_backtrace_enabled (boolean)" msgstr "debug_backtrace_enabled (bool)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:159 +#: sssd.conf.5.xml:202 msgid "Enable debug backtrace." msgstr "Aktivera felsökningsspårning." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:162 +#: sssd.conf.5.xml:205 msgid "" "In case SSSD is run with debug_level less than 9, everything is logged to a " "ring buffer in memory and flushed to a log file on any error up to and " @@ -300,23 +358,22 @@ msgid "" "to 0 or 1 then only those error levels will trigger backtrace, otherwise up " "to 2)." msgstr "" -"Ifall SSSD körs med debug_level mindre än 9 loggas allting till en " -"ringbuffert i minnet och skrivs till en loggfil när nägot fel upp till och " -"inklusive ”min(0x0040, debug_level)” (d.v.s. om debug_level uttryckligen är " -"satt till 0 eller 1 kommer endast dessa felnivåer att orsaka en spårning, " -"annars upp till 2)." +"Om SSSD körs med debug_level mindre än 9 loggas allt till en ringbuffert i " +"minnet och skrivs till en loggfil vid varje fel upp till och med `min" +"(0x0040, debug_level)` (dvs. om debug_level uttryckligen sätts till 0 eller " +"1 utlöser endast dessa felnivåer en stackspårning, annars upp till 2)." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:171 +#: sssd.conf.5.xml:214 msgid "" "Feature is only supported for `logger == files` (i.e. setting doesn't have " "effect for other logger types)." msgstr "" -"Funktionen stödjs endast för ”logger == files” (d.v.s. att sätta denna har " -"ingen effekt för andra loggningstyper)." +"Funktionen stöds endast för `logger == files` (dvs. inställningen har ingen " +"effekt för andra loggartyper)." #. type: Content of: outside any tag (error?) -#: sssd.conf.5.xml:111 sssd.conf.5.xml:186 sssd-ldap.5.xml:1754 +#: sssd.conf.5.xml:154 sssd.conf.5.xml:229 sssd-ldap.5.xml:1754 #: sssd-ldap.5.xml:1960 sss-certmap.5.xml:645 sssd-systemtap.5.xml:82 #: sssd-systemtap.5.xml:143 sssd-systemtap.5.xml:236 sssd-systemtap.5.xml:274 #: sssd-systemtap.5.xml:330 sssd-ldap-attributes.5.xml:40 @@ -329,68 +386,70 @@ msgid "<placeholder type=\"variablelist\" id=\"0\"/>" msgstr "<placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:184 +#: sssd.conf.5.xml:227 msgid "Options usable in SERVICE and DOMAIN sections" -msgstr "Flaggor användbara i sektionerna SERVICE och DOMAIN" +msgstr "Alternativ som kan användas i sektionerna SERVICE och DOMAIN" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:188 +#: sssd.conf.5.xml:231 msgid "timeout (integer)" msgstr "timeout (heltal)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:191 +#: sssd.conf.5.xml:234 msgid "" "Timeout in seconds between heartbeats for this service. This is used to " "ensure that the process is alive and capable of answering requests. Note " "that after three missed heartbeats the process will terminate itself." msgstr "" "Tidsgräns i sekunder mellan hjärtslag för denna tjänst. Detta används för " -"att säkerställa att processen lever och kan svara på begäranden. Observera " -"att efter tre missade hjärtslag kommer processen avsluta sig själv." +"att säkerställa att processen kör och kan svara på begäranden. Observera att " +"processen avslutar sig själv efter tre missade hjärtslag." #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:198 sssd.conf.5.xml:1199 sssd.conf.5.xml:1673 -#: sssd.conf.5.xml:4174 sssd-ldap.5.xml:825 sssd-idp.5.xml:192 +#: sssd.conf.5.xml:241 sssd.conf.5.xml:1155 sssd.conf.5.xml:1665 +#: sssd.conf.5.xml:4379 sssd-ldap.5.xml:825 sssd-idp.5.xml:271 #: include/ldap_id_mapping.xml:270 msgid "Default: 10" msgstr "Standard: 10" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:208 +#: sssd.conf.5.xml:251 msgid "SPECIAL SECTIONS" msgstr "SPECIALSEKTIONER" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:211 +#: sssd.conf.5.xml:254 msgid "The [sssd] section" msgstr "Sektionen [sssd]" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><title> -#: sssd.conf.5.xml:220 +#: sssd.conf.5.xml:263 msgid "Section parameters" msgstr "Sektionsparametrar" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:222 -msgid "services" -msgstr "services" +#: sssd.conf.5.xml:265 +#, fuzzy +#| msgid "users (string)" +msgid "services (string)" +msgstr "users (sträng)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:225 +#: sssd.conf.5.xml:268 msgid "" "Comma separated list of services that are started when sssd itself starts. " "<phrase condition=\"have_systemd\"> The services' list is optional on " "platforms where systemd is supported, as they will either be socket or D-Bus " "activated when needed. </phrase>" msgstr "" -"Kommaseparerad lista av tjänster som startas när sssd själv startas. " -"<phrase condition=\"have_systemd\"> Tjänstelistan är frivillig på " -"plattformar där systemd stödjs, eftersom de antingen kommer vara uttags- " -"eller D-Bus-aktiverade vid behov. </phrase>" +"Kommaseparerad lista över tjänster som startas när sssd själv startar. " +"<phrase condition=\"have_systemd\"> Tjänstelistan är valfri på plattformar " +"där systemd stöds, eftersom tjänsterna vid behov antingen socket- eller D-" +"Bus-aktiveras. </phrase>" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:234 +#: sssd.conf.5.xml:277 msgid "" "Supported services: nss, pam, ifp <phrase condition=\"with_sudo\">, sudo</" "phrase> <phrase condition=\"with_autofs\">, autofs</phrase> <phrase " @@ -403,23 +462,23 @@ msgstr "" "condition=\"with_pac_responder\">, pac</phrase>" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:241 +#: sssd.conf.5.xml:284 msgid "" "<phrase condition=\"have_systemd\"> By default, all services are disabled " "and the administrator must enable the ones allowed to be used by executing: " "\"systemctl enable sssd-@service@.socket\". </phrase>" msgstr "" "<phrase condition=\"have_systemd\"> Som standard är alla tjänster " -"avaktiverade och administratören måste aktivera de tillåtna genom att köra: ”" -"systemctl enable sssd-@service@.socket\". </phrase>" +"inaktiverade och administratören måste aktivera de tjänster som får användas " +"genom att köra: \"systemctl enable sssd-@service@.socket\". </phrase>" -#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:250 -msgid "domains" -msgstr "domains" +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sssd.conf.5.xml:293 sssd.conf.5.xml:4562 +msgid "domains (string)" +msgstr "domains (sträng)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:253 +#: sssd.conf.5.xml:296 msgid "" "A domain is a database containing user information. SSSD can use more " "domains at the same time, but at least one must be configured or SSSD won't " @@ -428,29 +487,28 @@ msgid "" "alphanumeric ASCII characters, dashes, dots and underscores. '/' character " "is forbidden." msgstr "" -"En domän är en databas som innehåller användarinformation. SSSD kan använda " -"flera domäner på samma gång, men åtminstone en måste vara konfigurerad, " -"annars kommer inte SSSD starta. Denna parameter beskriver listan av domäner " -"i den ordning du vill att de skall tillfrågas. Ett domännamn rekommenderas " -"endast att bestå av alfanumeriska ASCII-tecken, bindestreck, punkter och " -"understrykningstecken. Tecknet ”/” är förbjudet." +"En domän är en databas som innehåller användarinformation. SSSD kan använda " +"flera domäner samtidigt, men minst en måste konfigureras, annars startar " +"inte SSSD. Denna parameter beskriver listan över domäner i den ordning du " +"vill att de ska frågas. Ett domännamn bör endast innehålla alfanumeriska " +"ASCII-tecken, bindestreck, punkter och understreck. Tecknet '/' är förbjudet." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:266 sssd.conf.5.xml:3467 +#: sssd.conf.5.xml:309 sssd.conf.5.xml:3598 msgid "re_expression (string)" msgstr "re_expression (sträng)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:269 +#: sssd.conf.5.xml:312 msgid "" "Default regular expression that describes how to parse the string containing " "user name and domain into these components." msgstr "" -"Reguljärt standarduttryck som beskriver hur man skall tolka strängen som " -"innehåller användarnamnet och domänen in i dessa komponenter." +"Reguljärt standarduttryck som beskriver hur strängen med användarnamn och " +"domän ska tolkas till dessa komponenter." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:274 +#: sssd.conf.5.xml:317 msgid "" "Each domain can have an individual regular expression configured. For some " "ID providers there are also default regular expressions. See DOMAIN SECTIONS " @@ -461,12 +519,12 @@ msgstr "" "för mer information om dessa reguljära uttryck." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:283 sssd.conf.5.xml:3524 +#: sssd.conf.5.xml:326 sssd.conf.5.xml:3655 msgid "full_name_format (string)" msgstr "full_name_format (sträng)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:286 sssd.conf.5.xml:3527 +#: sssd.conf.5.xml:329 sssd.conf.5.xml:3658 msgid "" "A <citerefentry> <refentrytitle>printf</refentrytitle> <manvolnum>3</" "manvolnum> </citerefentry>-compatible format that describes how to compose a " @@ -477,41 +535,41 @@ msgstr "" "samman ett fullständigt kvalificerat namn från namn- och domänkomponenter." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:297 sssd.conf.5.xml:3538 +#: sssd.conf.5.xml:340 sssd.conf.5.xml:3669 msgid "%1$s" msgstr "%1$s" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:298 sssd.conf.5.xml:3539 +#: sssd.conf.5.xml:341 sssd.conf.5.xml:3670 msgid "user name" msgstr "användarnamn" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:301 sssd.conf.5.xml:3542 +#: sssd.conf.5.xml:344 sssd.conf.5.xml:3673 msgid "%2$s" msgstr "%2$s" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:304 sssd.conf.5.xml:3545 +#: sssd.conf.5.xml:347 sssd.conf.5.xml:3676 msgid "domain name as specified in the SSSD config file." msgstr "domännamn som det anges i SSSD-konfigurationsfilen." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:310 sssd.conf.5.xml:3551 +#: sssd.conf.5.xml:353 sssd.conf.5.xml:3682 msgid "%3$s" msgstr "%3$s" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:313 sssd.conf.5.xml:3554 +#: sssd.conf.5.xml:356 sssd.conf.5.xml:3685 msgid "" "domain flat name. Mostly usable for Active Directory domains, both directly " "configured or discovered via IPA trusts." msgstr "" -"platt domännamn. Huvudsakligen användbart för Active Directory-domäner, både " -"direkt konfigurerade eller hittade via IPA-förtroenden." +"kort domännamn. Används främst för Active Directory-domäner, både direkt " +"konfigurerade och domäner som upptäckts via IPA-förtroenden." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:294 sssd.conf.5.xml:3535 +#: sssd.conf.5.xml:337 sssd.conf.5.xml:3666 msgid "" "The following expansions are supported: <placeholder type=\"variablelist\" " "id=\"0\"/>" @@ -519,98 +577,97 @@ msgstr "" "Följande utvidgningar stödjs: <placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:323 +#: sssd.conf.5.xml:366 msgid "" "Each domain can have an individual format string configured. See DOMAIN " "SECTIONS for more info on this option." msgstr "" -"Varje domän kan ha en egen formatsträng konfigurerad. Se DOMÄNSEKTIONER för " -"mer information om denna flagga." +"Varje domän kan ha en egen formatsträng konfigurerad. Se DOMÄNSEKTIONER för " +"mer information om detta alternativ." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:329 +#: sssd.conf.5.xml:372 msgid "monitor_resolv_conf (boolean)" msgstr "monitor_resolv_conf (boolean)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:332 +#: sssd.conf.5.xml:375 msgid "" "Controls if SSSD should monitor the state of resolv.conf to identify when it " "needs to update its internal DNS resolver." msgstr "" -"Styr om SSSD skall övervaka tillståndet för resolv.conf för att identifiera " -"när den behöver uppdatera sin interna DNS-uppslagare." +"Styr om SSSD ska övervaka tillståndet för resolv.conf för att avgöra när " +"dess interna DNS-uppslagare behöver uppdateras." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:342 +#: sssd.conf.5.xml:385 msgid "try_inotify (boolean)" msgstr "try_inotify (boolean)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:345 +#: sssd.conf.5.xml:388 msgid "" "By default, SSSD will attempt to use inotify to monitor configuration files " "changes and will fall back to polling every five seconds if inotify cannot " "be used." msgstr "" -"Som standard kommer SSSD försöka använda inotify för att övervaka ändringar " -"av konfigurationsfiler och kommer gå tillbaka till att polla var femte " -"sekund om inotify inte kan användas." +"Som standard försöker SSSD använda inotify för att övervaka ändringar i " +"konfigurationsfiler och faller tillbaka till pollning var femte sekund om " +"inotify inte kan användas." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:351 +#: sssd.conf.5.xml:394 msgid "" "There are some limited situations where it is preferred that we should skip " "even trying to use inotify. In these rare cases, this option should be set " "to 'false'" msgstr "" -"Det finns vissa situationer när det är att föredra att vi skall hoppa över " -"att ens försöka att använda inotify. I dessa sällsynta fall skall detta " -"alternativ sättas till ”false”" +"Det finns ett fåtal situationer där det är lämpligt att inte ens försöka " +"använda inotify. I dessa sällsynta fall ska detta alternativ sättas till " +"'false'." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:357 +#: sssd.conf.5.xml:400 msgid "" "Default: true on platforms where inotify is supported. False on other " "platforms." msgstr "" -"Standard: true på plattformar där inotify stödjs. False på andra plattformar." +"Standard: true på plattformar där inotify stöds. false på andra plattformar." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:361 +#: sssd.conf.5.xml:404 msgid "" "Note: this option will have no effect on platforms where inotify is " "unavailable. On these platforms, polling will always be used." msgstr "" -"Obs: detta alternativ kommer inte ha någon effekt på plattformar där inotify " -"inte är tillgängligt. På dessa plattformar kommer pollning alltid användas." +"Obs! Detta alternativ har ingen effekt på plattformar där inotify inte är " +"tillgängligt. På dessa plattformar används alltid pollning." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:368 +#: sssd.conf.5.xml:411 msgid "krb5_rcache_dir (string)" msgstr "krb5_rcache_dir (sträng)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:371 +#: sssd.conf.5.xml:414 msgid "" "Directory on the filesystem where SSSD should store Kerberos replay cache " "files." msgstr "" -"Katalog i filsystemet där SSSD skall spara Kerberos-cachefiler för " -"återuppspelning." +"Katalog i filsystemet där SSSD ska lagra Kerberos omspelningscachefiler." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:375 +#: sssd.conf.5.xml:418 msgid "" "This option accepts a special value __LIBKRB5_DEFAULTS__ that will instruct " "SSSD to let libkrb5 decide the appropriate location for the replay cache." msgstr "" -"Detta alternativ godtar ett specialvärde __LIBKRB5_DEFAULTS__ som kommer " -"instruera SSSD att låta libkrb5 bestämma den lämpliga platsen för " -"cachefilerna för återuppspelning." +"Detta alternativ accepterar specialvärdet __LIBKRB5_DEFAULTS__, vilket " +"instruerar SSSD att låta libkrb5 bestämma lämplig plats för " +"återspelningscachen." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:381 +#: sssd.conf.5.xml:424 msgid "" "Default: Distribution-specific and specified at build-time. " "(__LIBKRB5_DEFAULTS__ if not configured)" @@ -619,12 +676,12 @@ msgstr "" "(__LIBKRB5_DEFAULTS__ om inte konfigurerat)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:388 +#: sssd.conf.5.xml:431 msgid "default_domain_suffix (string)" msgstr "default_domain_suffix (sträng)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:391 +#: sssd.conf.5.xml:434 msgid "" "Please note that this option is deprecated and domain_resolution_order " "should be used." @@ -633,7 +690,7 @@ msgstr "" "användas." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:395 +#: sssd.conf.5.xml:438 msgid "" "This string will be used as a default domain name for all names without a " "domain name component. The main use case is environments where the primary " @@ -641,14 +698,14 @@ msgid "" "trusted domain. The option allows those users to log in just with their " "user name without giving a domain name as well." msgstr "" -"Strängen kommer användas som ett standardnamn för domänen för alla namn utan " -"en domännamnsdel. Det huvudsakliga användningsfallet är miljöer där " -"primärdomänen är avsedd för hantering av värdpolicyer och alla användare är " -"placerade i en betrodd domän. Alternativet låter dessa användare att logga " -"in med bara sitt användarnamn utan att dessutom ange ett domännamn." +"Denna sträng används som standarddomännamn för alla namn utan en " +"domännamnsdel. Det huvudsakliga användningsfallet är miljöer där " +"primärdomänen används för att hantera värdpolicyer och alla användare finns " +"i en betrodd domän. Alternativet låter dessa användare logga in endast med " +"sitt användarnamn utan att även ange ett domännamn." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:405 +#: sssd.conf.5.xml:448 msgid "" "Please note that if this option is set all users from the primary domain " "have to use their fully qualified name, e.g. user@domain.name, to log in. " @@ -656,28 +713,29 @@ msgid "" "is not allowed to use this option together with use_fully_qualified_names " "set to False." msgstr "" -"Observera att om denna flagga är satt måste alla användare från den primära " -"domänen använda sina fullständiga namn, t.ex. användare@domän.namn, för att " -"logga in. Att sätta denna flagga ändrar standardvärdet till " -"use_fully_qualified_names till Sant. Det är inte tillåtet att använda denna " -"flagga tillsammans med use_fully_qualified_names satt till Falskt." +"Observera att om detta alternativ anges måste alla användare från den " +"primära domänen använda sitt fullständigt kvalificerade namn, t.ex. " +"user@domain.name, för att logga in. Om alternativet anges ändras " +"standardvärdet för use_fully_qualified_names till True. Det är inte tillåtet " +"att använda detta alternativ tillsammans med use_fully_qualified_names satt " +"till False." #. type: Content of: <variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:414 sssd-ldap.5.xml:937 sssd-ldap.5.xml:949 -#: sssd-ldap.5.xml:1042 sssd-ad.5.xml:921 sssd-ad.5.xml:996 sssd-krb5.5.xml:468 -#: sssd-ldap-attributes.5.xml:470 sssd-ldap-attributes.5.xml:978 -#: include/ldap_id_mapping.xml:211 include/ldap_id_mapping.xml:222 -#: include/krb5_options.xml:148 +#: sssd.conf.5.xml:457 sssd.conf.5.xml:2006 sssd-ldap.5.xml:937 +#: sssd-ldap.5.xml:949 sssd-ldap.5.xml:1042 sssd-ad.5.xml:926 +#: sssd-ad.5.xml:1001 sssd-krb5.5.xml:468 sssd-ldap-attributes.5.xml:470 +#: sssd-ldap-attributes.5.xml:978 include/ldap_id_mapping.xml:211 +#: include/ldap_id_mapping.xml:222 include/krb5_options.xml:148 msgid "Default: not set" msgstr "Standard: inte satt" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:419 +#: sssd.conf.5.xml:462 msgid "override_space (string)" msgstr "override_space (sträng)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:422 +#: sssd.conf.5.xml:465 msgid "" "This parameter will replace spaces (space bar) with the given character for " "user and group names. e.g. (_). User name "john doe" will be " @@ -685,14 +743,14 @@ msgid "" "scripts that have difficulty handling spaces, due to the default field " "separator in the shell." msgstr "" -"Denna parameter kommer ersätta blanksteg (mellanslag) med det angivna " -"tecknet i användar- och gruppnamn, t.ex. (_). Användarnamnet "sven " -"svensson" blir "sven_svensson" Denna funktion lades till för " -"att hjälpa till med kompatibiliteten med skalskript som har svårigheter att " -"hantera blanka, på grund av att det är standardfältseparatorn i skalet." +"Denna parameter ersätter mellanslag med det angivna tecknet i användar- och " +"gruppnamn, t.ex. (_). Användarnamnet "john doe" blir " +""john_doe". Funktionen lades till för kompatibilitet med " +"skalskript som har svårt att hantera mellanslag på grund av skalets " +"standardfältavgränsare." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:431 +#: sssd.conf.5.xml:474 msgid "" "Please note it is a configuration error to use a replacement character that " "might be used in user or group names. If a name contains the replacement " @@ -705,22 +763,22 @@ msgstr "" "allmänhet är resultatet av en uppslagning odefinierat." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:439 +#: sssd.conf.5.xml:482 msgid "Default: not set (spaces will not be replaced)" -msgstr "Standard: inte satt (blanka kommer inte ersättas)" +msgstr "Standard: inte angivet (mellanslag ersätts inte)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:444 +#: sssd.conf.5.xml:487 msgid "certificate_verification (string)" msgstr "certificate_verification (sträng)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:452 +#: sssd.conf.5.xml:495 msgid "no_ocsp" msgstr "no_ocsp" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:454 +#: sssd.conf.5.xml:497 msgid "" "Disables Online Certificate Status Protocol (OCSP) checks. This might be " "needed if the OCSP servers defined in the certificate are not reachable from " @@ -731,83 +789,83 @@ msgstr "" "nåbara från klienten." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:462 +#: sssd.conf.5.xml:505 msgid "soft_ocsp" msgstr "soft_ocsp" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:464 +#: sssd.conf.5.xml:507 msgid "" "If a connection cannot be established to an OCSP responder the OCSP check is " "skipped. This option should be used to allow authentication when the system " "is offline and the OCSP responder cannot be reached." msgstr "" -"Om en anslutning inte kan etableras till en OCSP-respondent hoppas OCSP-" -"kontrollen över. Denna flagga skall användas för att tillåta autentisering " -"när systemet är frånkopplat och OCSP-respondenten inte kan nås." +"Om en anslutning inte kan upprättas till en OCSP-svarare hoppas OCSP-" +"kontrollen över. Detta alternativ ska användas för att tillåta autentisering " +"när systemet är frånkopplat och OCSP-svararen inte kan nås." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:474 +#: sssd.conf.5.xml:517 msgid "ocsp_dgst" msgstr "ocsp_dgst" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:476 +#: sssd.conf.5.xml:519 msgid "" "Digest (hash) function used to create the certificate ID for the OCSP " "request. Allowed values are:" msgstr "" -"Kontrollsumme- (hash-)funktion som används för att skapa certifikats-ID för " -"OCSP-begäran. Tillåtna värden är:" +"Sammandragsfunktion (hashfunktion) som används för att skapa certifikat-ID " +"för OCSP-begäran. Tillåtna värden är:" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:480 +#: sssd.conf.5.xml:523 msgid "sha1" msgstr "sha1" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:481 +#: sssd.conf.5.xml:524 msgid "sha256" msgstr "sha256" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:482 +#: sssd.conf.5.xml:525 msgid "sha384" msgstr "sha384" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:483 +#: sssd.conf.5.xml:526 msgid "sha512" msgstr "sha512" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:486 +#: sssd.conf.5.xml:529 msgid "Default: sha1 (to allow compatibility with RFC5019-compliant responder)" msgstr "" "Standard: sha1 (för att tillåta kompatibilitet med respondenter som följer " "RFC5019)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:492 +#: sssd.conf.5.xml:535 msgid "no_verification" msgstr "no_verification" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:494 +#: sssd.conf.5.xml:537 msgid "" "Disables verification completely. This option should only be used for " "testing." msgstr "" -"Avaktiverar helt verifiering. Detta alternativ skall endast användas för " +"Inaktiverar verifiering helt. Detta alternativ ska endast användas för " "testning." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:500 +#: sssd.conf.5.xml:543 msgid "partial_chain" msgstr "partial_chain" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:502 +#: sssd.conf.5.xml:545 msgid "" "Allow verification to succeed even if a <replaceable>complete</replaceable> " "chain cannot be built to a self-signed trust-anchor, provided it is possible " @@ -819,28 +877,28 @@ msgstr "" "certifikat som inte behöver vara självsignerat." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:511 +#: sssd.conf.5.xml:554 msgid "ocsp_default_responder=URL" msgstr "ocsp_default_responder=URL" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:513 +#: sssd.conf.5.xml:556 msgid "" "Sets the OCSP default responder which should be used instead of the one " "mentioned in the certificate. URL must be replaced with the URL of the OCSP " "default responder e.g. http://example.com:80/ocsp." msgstr "" -"Anger standard-OCSP-respondent som skall användas istället för den som nämns " -"i certifikatet. URL:en måste ersättas med URL:en till standard-OCSP-" -"respondenten t.ex. http://exempel.se:80/ocsp." +"Anger den standard-OCSP-svarare som ska användas i stället för den som nämns " +"i certifikatet. URL måste ersättas med URL:en till standard-OCSP-svararen, " +"t.ex. http://example.com:80/ocsp." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:523 +#: sssd.conf.5.xml:566 msgid "ocsp_default_responder_signing_cert=NAME" -msgstr "ocsp_default_responder_signing_cert=NAMN" +msgstr "ocsp_default_responder_signing_cert=NAME" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:525 +#: sssd.conf.5.xml:568 msgid "" "This option is currently ignored. All needed certificates must be available " "in the PEM file given by pam_cert_db_path." @@ -849,12 +907,12 @@ msgstr "" "vara tillgängliga i PEM-filen som anges av pam_cert_db_path." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:533 +#: sssd.conf.5.xml:576 msgid "crl_file=/PATH/TO/CRL/FILE" -msgstr "crl_file=/SÖKVÄG/TILL/CRL/FIL" +msgstr "crl_file=/PATH/TO/CRL/FILE" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:535 +#: sssd.conf.5.xml:578 msgid "" "Use the Certificate Revocation List (CRL) from the given file during the " "verification of the certificate. The CRL must be given in PEM format, see " @@ -862,84 +920,86 @@ msgid "" "manvolnum> </citerefentry> for details." msgstr "" "Använd certifikatåterkallelselistan (Certificate Revocation List, CRL) från " -"den givna filen under verifikationen av certifikatet. CRL:en måste ges i PEM-" -"format, se <citerefentry> <refentrytitle>crl</refentrytitle> <manvolnum>" -"1ssl</manvolnum> </citerefentry> för detaljer." +"den angivna filen vid verifiering av certifikatet. CRL:en måste anges i PEM-" +"format. Se <citerefentry> <refentrytitle>crl</refentrytitle> <manvolnum>" +"1ssl</manvolnum> </citerefentry> för mer information." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:548 +#: sssd.conf.5.xml:591 msgid "soft_crl" msgstr "soft_crl" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:551 +#: sssd.conf.5.xml:594 msgid "" "If a Certificate Revocation List (CRL) is expired ignore the expiration " "time of the CRL and check the related certificates with the expired CRL. " "This option should be used to allow authentication when the system is " "offline and the CRL cannot be renewed." msgstr "" -"Om en certifikatåterkalleleselista (CRL) gått ut, ignorera utgångsdatum för " -"CRL:en och kontrollera de relaterade certifikaten med den utgångna CRL:en. " -"Denna flagga skall användas för att tillåta autentisering när systemet är " +"Om en certifikatåterkallelselista (CRL) har löpt ut, ignorera CRL:ens " +"utgångstid och kontrollera de berörda certifikaten med den utgångna CRL:en. " +"Detta alternativ ska användas för att tillåta autentisering när systemet är " "frånkopplat och CRL:en inte kan förnyas." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:447 +#: sssd.conf.5.xml:490 msgid "" "With this parameter the certificate verification can be tuned with a comma " "separated list of options. Supported options are: <placeholder " "type=\"variablelist\" id=\"0\"/>" msgstr "" -"Med denna parameter kan verifieringen av certifikatet justeras med en " -"kommaseparerad lista av alternativ. Alternativ som stödjs är <placeholder " +"Med denna parameter kan certifikatverifieringen justeras med en " +"kommaseparerad lista med alternativ. Följande alternativ stöds: <placeholder " "type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:564 +#: sssd.conf.5.xml:607 msgid "Unknown options are reported but ignored." msgstr "Okända alternativ rapporteras men ignoreras." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:567 +#: sssd.conf.5.xml:610 msgid "Default: not set, i.e. do not restrict certificate verification" -msgstr "Standard: inte satt, d.v.s begränsa inte certifikatverifieringen" +msgstr "Standard: inte angivet, dvs. begränsa inte certifikatverifieringen" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:573 +#: sssd.conf.5.xml:616 msgid "disable_netlink (boolean)" msgstr "disable_netlink (boolean)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:576 +#: sssd.conf.5.xml:619 msgid "" "SSSD hooks into the netlink interface to monitor changes to routes, " "addresses, links and trigger certain actions." msgstr "" -"SSSD-hakar in i netlink-gränssnittet för att övervaka förändringar av " -"rutter, adresser, länkar och utlösa vissa åtgärder." +"SSSD ansluter till netlink-gränssnittet för att övervaka ändringar av " +"rutter, adresser och länkar samt utlösa vissa åtgärder." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:581 +#: sssd.conf.5.xml:624 msgid "" "The SSSD state changes caused by netlink events may be undesirable and can " "be disabled by setting this option to 'true'" msgstr "" -"Förändringar av SSSD-tillståndet från netlink-händelser kan vara opålitliga " -"och kan avaktiveras genom att sätta detta alternativ till ”true”" +"De ändringar av SSSD-tillståndet som orsakas av netlink-händelser kan vara " +"oönskade och kan inaktiveras genom att sätta detta alternativ till 'true'." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:586 +#: sssd.conf.5.xml:629 msgid "Default: false (netlink changes are detected)" msgstr "Standard: false (netlink-förändringar detekteras)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:591 -msgid "domain_resolution_order" +#: sssd.conf.5.xml:634 +#, fuzzy +#| msgid "domain_resolution_order" +msgid "domain_resolution_order (string)" msgstr "domain_resolution_order" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:594 +#: sssd.conf.5.xml:637 msgid "" "Comma separated list of domains and subdomains representing the lookup order " "that will be followed. The list doesn't have to include all possible " @@ -948,15 +1008,15 @@ msgid "" "subdomains which are not listed as part of <quote>lookup_order</quote> will " "be looked up in a random order for each parent domain." msgstr "" -"Kommaseparerad lista av domäner och underdomäner som representerar ordningen " -"av uppslagningar skall följa. Listan behöver inte innehålla alla möjliga " -"domäner eftersom de saknade domänerna kommer slås upp baserat på ordningen " -"de presenteras i konfigurationsalternativet <quote>domains</quote>. " -"Underdomäner som inte är listade som en del av <quote>lookup_order</quote> " -"kommer slås upp i en slumpvis ordning för varje föräldradomän." +"Kommaseparerad lista över domäner och underdomäner som anger den sökordning " +"som följs. Listan behöver inte innehålla alla möjliga domäner, eftersom " +"saknade domäner slås upp i den ordning de presenteras i " +"konfigurationsalternativet <quote>domains</quote>. Underdomäner som inte " +"listas som en del av <quote>lookup_order</quote> slås upp i slumpmässig " +"ordning för varje överordnad domän." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:606 +#: sssd.conf.5.xml:649 msgid "" "Please, note that when this option is set the output format of all commands " "is always fully-qualified even when using short names for input. In case " @@ -970,116 +1030,115 @@ msgid "" "domain which uses shortnames, making this workaround totally not recommended " "in cases where usernames may overlap between domains." msgstr "" -"Observera att när detta alternativ är satt är alltid utmatningsformatet för " -"alla kommandon helt kvalificerat även när kortnamn används för indata. " -"Ifall administratören vill att utdata inte skall vara fullständigt " -"kvalificerat kan alternativet full_name_format anges som visas nedan: <quote>" -"full_name_format=%1$s</quote> Kom dock ihåg att under inloggningen " -"kanoniserar inloggningsprogram ofta användarnamnet genom att anropa " +"Observera att när detta alternativ är angivet är utdataformatet från alla " +"kommandon alltid fullständigt kvalificerat, även när kortnamn används som " +"indata. Om administratören vill att utdata inte ska vara fullständigt " +"kvalificerade kan alternativet full_name_format användas enligt nedan: " +"<quote>full_name_format=%1$s</quote>. Kom dock ihåg att inloggningsprogram " +"under inloggningen ofta kanoniserar användarnamnet genom att anropa " "<citerefentry> <refentrytitle>getpwnam</refentrytitle> <manvolnum>3</" -"manvolnum> </citerefentry> som, om ett kortnamn returneras för en " -"kvalificerad inmatning (vid försök att nå en användare som finns i flera " -"domäner) kan dirigera om inloggningsförsöket till domänen som använder " -"kortnamn, vilket gör att denna metod absolut inte rekommenderas i fall där " -"användarnamn kan överlappa mellan domäner." +"manvolnum> </citerefentry>. Om ett kortnamn returneras för kvalificerad " +"indata när en användare finns i flera domäner, kan det dirigera om " +"inloggningsförsöket till domänen som använder kortnamn. Därför avråds starkt " +"från denna lösning när användarnamn kan överlappa mellan domäner." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:630 sssd.conf.5.xml:1697 sssd.conf.5.xml:4224 -#: sssd-ad.5.xml:187 sssd-ad.5.xml:328 sssd-ad.5.xml:342 sssd-idp.5.xml:108 -#: sssd-idp.5.xml:132 sssd-idp.5.xml:145 sssd-idp.5.xml:159 sssd-idp.5.xml:180 +#: sssd.conf.5.xml:673 sssd.conf.5.xml:1026 sssd.conf.5.xml:1689 +#: sssd.conf.5.xml:4429 sssd-ad.5.xml:187 sssd-ad.5.xml:328 sssd-ad.5.xml:342 +#: sssd-idp.5.xml:112 sssd-idp.5.xml:136 sssd-idp.5.xml:149 sssd-idp.5.xml:167 +#: sssd-idp.5.xml:188 msgid "Default: Not set" msgstr "Standard: inte satt" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:635 +#: sssd.conf.5.xml:678 msgid "implicit_pac_responder (boolean)" msgstr "implicit_pac_responder (boolean)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:638 +#: sssd.conf.5.xml:681 msgid "" "The PAC responder is enabled automatically for the IPA and AD provider to " "evaluate and check the PAC. If it has to be disabled set this option to " "'false'." msgstr "" -"PAC-respondenten aktiveras automatiskt för IPA- och AD-leverantörerna för " -"att utvärdera och kontrollera PAC:en. Om den måste avaktiveras sätt detta " -"alternativ till ”false”." +"PAC-svararen aktiveras automatiskt för IPA- och AD-leverantörerna för att " +"utvärdera och kontrollera PAC. Om den måste inaktiveras, sätt detta " +"alternativ till 'false'." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:649 +#: sssd.conf.5.xml:692 msgid "core_dumpable (boolean)" msgstr "core_dumpable (boolean)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:652 +#: sssd.conf.5.xml:695 msgid "" "This option can be used for general system hardening: setting it to 'false' " "forbids core dumps for all SSSD processes to avoid leaking plain text " "passwords. See man page prctl:PR_SET_DUMPABLE on Linux or " "procctl:PROC_TRACE_CTL on FreeBSD for details." msgstr "" -"Den här flaggan kan användas för allmän systemhärdning: om du ställer in det " -"på ”false” förbjuds kärndumpar för alla SSSD-processer för att undvika " -"läckage av lösenord i klartext. Se man-sidan prctl:PR_SET_DUMPABLE på Linux " -"eller procctl:PROC_TRACE_CTL på FreeBSD för mer information." +"Detta alternativ kan användas för allmän systemhärdning: att sätta det till " +"'false' förbjuder kärndumpar för alla SSSD-processer för att undvika läckage " +"av lösenord i klartext. Se manualsidan prctl:PR_SET_DUMPABLE på Linux eller " +"procctl:PROC_TRACE_CTL på FreeBSD för mer information." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:660 +#: sssd.conf.5.xml:703 msgid "" "Take a note that this setting has no effect for 'ldap_child', 'krb5_child' " "and 'sssd_pam' as those privileged binaries can have a copy of a host keytab " "data in a memory and their behavior in this regards is governed by /proc/sys/" "fs/suid_dumpable system setting." msgstr "" -"Observera att denna inställning inte har någon effekt för ’ldap_child’, ’" -"krb5_child’ och ’sssd_pam’, eftersom dessa privilegierade binärer kan ha en " -"kopia av en värdkeytab-data i minnet och deras beteende i detta avseende " +"Observera att denna inställning inte har någon effekt för 'ldap_child', " +"'krb5_child' och 'sssd_pam', eftersom dessa privilegierade binärfiler kan ha " +"en kopia av värdens keytab-data i minnet och deras beteende i detta avseende " "styrs av systeminställningen /proc/sys/fs/suid_dumpable." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:673 +#: sssd.conf.5.xml:716 msgid "passkey_verification (string)" msgstr "passkey_verification (sträng)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:681 +#: sssd.conf.5.xml:724 msgid "user_verification (boolean)" -msgstr "user_verification (sträng)" +msgstr "user_verification (boolesk)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:683 +#: sssd.conf.5.xml:726 msgid "" "Enable or disable the user verification (i.e. PIN, fingerprint) during " "authentication. If enabled, the PIN will always be requested." msgstr "" -"Aktivera eller avaktivera användarverifiering (d.v.s. PIN, fingeravtryck) " -"under autentisering. Om aktiverat kommer PIN:en alltid att begäras." +"Aktivera eller inaktivera användarverifiering (dvs. PIN-kod, fingeravtryck) " +"under autentisering. Om den aktiveras begärs alltid PIN-koden." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:689 +#: sssd.conf.5.xml:732 msgid "" "The default is that the key settings decide what to do. In the IPA or " "kerberos pre-authentication case, this value will be overwritten by the " "server." msgstr "" -"Standard är att nyckelinställningarna bestämmer vad som skall göras. I " -"fallet IPA och kerberos förautentisering kommer detta värde skrivas över av " -"servern." +"Som standard avgör nyckelinställningarna vad som ska göras. Vid IPA- eller " +"Kerberos-förautentisering skrivs detta värde över av servern." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:676 +#: sssd.conf.5.xml:719 msgid "" "With this parameter the passkey verification can be tuned with a comma " "separated list of options. Supported options are: <placeholder " "type=\"variablelist\" id=\"0\"/>" msgstr "" -"Med denna parameter kan verifieringen av lösennyckeln justeras med en " -"kommaseparerad lista av alternativ. Alternativ som stödjs är <placeholder " +"Med denna parameter kan verifieringen av passnyckeln justeras med en " +"kommaseparerad lista med alternativ. Alternativ som stöds är: <placeholder " "type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:213 +#: sssd.conf.5.xml:256 msgid "" "Individual pieces of SSSD functionality are provided by special SSSD " "services that are started and stopped together with SSSD. The services are " @@ -1096,12 +1155,12 @@ msgstr "" "type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:708 +#: sssd.conf.5.xml:751 msgid "SERVICES SECTIONS" msgstr "TJÄNSTESEKTIONER" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:710 +#: sssd.conf.5.xml:753 msgid "" "Settings that can be used to configure different services are described in " "this section. They should reside in the [<replaceable>$NAME</replaceable>] " @@ -1109,32 +1168,40 @@ msgid "" "quote>" msgstr "" "Inställningar som kan användas för att konfigurera olika tjänster beskrivs i " -"detta avsnitt. De skall ligga i sektionen [<replaceable>$NAME</replaceable>" -"], till exempel, för tjänsten NSS skulle sektionen vara <quote>[nss]</quote>" +"detta avsnitt. De ska finnas i sektionen [<replaceable>$NAME</replaceable>]. " +"För NSS-tjänsten är sektionen till exempel <quote>[nss]</quote>." #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:717 +#: sssd.conf.5.xml:760 msgid "General service configuration options" msgstr "Allmänna alternativ för tjänstekonfiguration" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:719 +#: sssd.conf.5.xml:762 msgid "These options can be used to configure any service." msgstr "Dessa alternativ kan användas för att konfigurera alla tjänster." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:723 -msgid "fd_limit" -msgstr "fd_limit" +#: sssd.conf.5.xml:766 +#, fuzzy +#| msgid "wildcard_limit (integer)" +msgid "fd_limit (integer)" +msgstr "wildcard_limit (heltal)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:726 +#: sssd.conf.5.xml:769 +#, fuzzy +#| msgid "" +#| "This option specifies the maximum number of file descriptors that may be " +#| "opened at one time by this SSSD process. On systems where SSSD is granted " +#| "the CAP_SYS_RESOURCE capability, this will be an absolute setting. On " +#| "systems without this capability, the resulting value will be the lower " +#| "value of this or the limits.conf \"hard\" limit." msgid "" "This option specifies the maximum number of file descriptors that may be " -"opened at one time by this SSSD process. On systems where SSSD is granted " -"the CAP_SYS_RESOURCE capability, this will be an absolute setting. On " -"systems without this capability, the resulting value will be the lower value " -"of this or the limits.conf \"hard\" limit." +"opened at one time by this SSSD process. Note this value will be capped by " +"the init system at the startup of SSSD, see e.g. man systemd.exec for " +"details." msgstr "" "Detta alternativ anger det maximala antalet filbeskrivare som kan öppnas på " "en gång av denna SSSD-process. På system där SSSD ges förmågan " @@ -1143,17 +1210,19 @@ msgstr "" "och den ”hårda” gränsen i limits.conf." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:735 +#: sssd.conf.5.xml:776 msgid "Default: 8192 (or limits.conf \"hard\" limit)" msgstr "Standard: 8192 (eller den ”hårda” gränsen i limits.conf)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:740 -msgid "client_idle_timeout" -msgstr "client_idle_timeout" +#: sssd.conf.5.xml:781 +#, fuzzy +#| msgid "offline_timeout (integer)" +msgid "client_idle_timeout (integer)" +msgstr "offline_timeout (heltal)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:743 +#: sssd.conf.5.xml:784 msgid "" "This option specifies the number of seconds that a client of an SSSD process " "can hold onto a file descriptor without communicating on it. This value is " @@ -1161,175 +1230,25 @@ msgid "" "can't be shorter than 10 seconds. If a lower value is configured, it will be " "adjusted to 10 seconds." msgstr "" -"Detta alternativ anger antalet sekunder som en klient till en SSSD-process " -"kan hålla fast i en filbeskrivare utan att kommunicera över den. Detta värde " -"är begränsat för att undvika att resurserna på systemet tar slut. " -"Tidsgränsen kan inte vara kortare än 10 sekunder. Om ett lägre värde " -"konfigureras kommer det att justeras till 10 sekunder." +"Detta alternativ anger hur många sekunder en klient till en SSSD-process kan " +"behålla en filbeskrivare utan att kommunicera via den. Värdet begränsas för " +"att undvika resursbrist i systemet. Tidsgränsen kan inte vara kortare än 10 " +"sekunder. Om ett lägre värde konfigureras justeras det till 10 sekunder." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:752 +#: sssd.conf.5.xml:793 msgid "Default: 60, KCM: 300" msgstr "Standard: 60, KCM: 300" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:757 -msgid "offline_timeout (integer)" -msgstr "offline_timeout (heltal)" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:760 -msgid "" -"When SSSD switches to offline mode the amount of time before it tries to go " -"back online will increase based upon the time spent disconnected. By " -"default SSSD uses incremental behaviour to calculate delay in between " -"retries. So, the wait time for a given retry will be longer than the wait " -"time for the previous ones. After each unsuccessful attempt to go online, " -"the new interval is recalculated by the following:" -msgstr "" -"När SSSD byter till frånkopplat läge, kommer tiden före den försöker gå " -"tillbaka till uppkopplat läge öka baserat på tiden tillbringad frånkopplad. " -"Som standard använder SSSD ett inkrementellt beteende för att beräkna " -"fördröjningen mellan återförsök. Så, väntetiden för ett givet återförsök " -"kommer vara längre än väntetiden för det föregående. Efter varje misslyckat " -"försök att bli uppkopplat beräknas det nya intervallet om enligt följande:" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:771 sssd.conf.5.xml:827 -msgid "" -"new_delay = Minimum(old_delay * 2, offline_timeout_max) + " -"random[0...offline_timeout_random_offset]" -msgstr "" -"ny_fördröjning = Minimum(gammal_fördröjning * 2, offline_timeout_max) + " -"slumpvärde[0…offline_timeout_random_offset]" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:774 -msgid "" -"The offline_timeout default value is 60. The offline_timeout_max default " -"value is 3600. The offline_timeout_random_offset default value is 30. The " -"end result is amount of seconds before next retry." -msgstr "" -"Standardvärdet för offline_timeout är 60. Standardvärdet på " -"offline_timeout_max är 3600. Standardvärdet på offline_timeout_random_offset " -"är 30. Slutresultatet är antalet sekunder före nästa omförsök." - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:780 -msgid "" -"Note that the maximum length of each interval is defined by " -"offline_timeout_max (apart of random part)." -msgstr "" -"Observera att den maximala längde på varje intervall definieras av " -"offline_timeout_max (förutom slumpdelen)." - -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:784 sssd.conf.5.xml:1110 sssd.conf.5.xml:1490 -#: sssd.conf.5.xml:1791 sssd-ldap.5.xml:550 -msgid "Default: 60" -msgstr "Standard: 60" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:789 -msgid "offline_timeout_max (integer)" -msgstr "offline_timeout_max (heltal)" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:792 -msgid "" -"Controls by how much the time between attempts to go online can be " -"incremented following unsuccessful attempts to go online." -msgstr "" -"Styr med hur mycket tiden mellan försök att ansluta kan ökas efter ett " -"misslyckat försök att koppla upp." - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:797 -msgid "A value of 0 disables the incrementing behaviour." -msgstr "Ett värde på 0 avaktiverar det ökande beteendet." - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:800 -msgid "" -"The value of this parameter should be set in correlation to offline_timeout " -"parameter value." -msgstr "" -"Värdet på denna parameter skall sättas i korrelation med parametervärdet " -"offline_timeout." - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:804 -msgid "" -"With offline_timeout set to 60 (default value) there is no point in setting " -"offlinet_timeout_max to less than 120 as it will saturate instantly. General " -"rule here should be to set offline_timeout_max to at least 4 times " -"offline_timeout." -msgstr "" -"Med offline_timout satt till 60 (standardvärdet) är det ingen poäng i att " -"sätta ofline_timeout_max till mindre än 120 eftersom det kommer mättas " -"omedelbart. En allmän regel här bör vara att sätta offline_timeout_max till " -"åtminstone 4 gånger offline_timeout." - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:810 -msgid "" -"Although a value between 0 and offline_timeout may be specified, it has the " -"effect of overriding the offline_timeout value so is of little use." -msgstr "" -"Även om ett värde mellan 0 och offline_timeout kan anges har det effekten " -"att åsidosätta värdet offline_timeout så det är inte så användbart." - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:815 -msgid "Default: 3600" -msgstr "Standard: 3600" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:820 -msgid "offline_timeout_random_offset (integer)" -msgstr "offline_timeout_random_offset (heltal)" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:823 -msgid "" -"When SSSD is in offline mode it keeps probing backend servers in specified " -"time intervals:" -msgstr "" -"När SSSD är i frånkopplat läge fortsätter den att prova bakändesservrar med " -"angivna tidsintervall:" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:830 -msgid "" -"This parameter controls the value of the random offset used for the above " -"equation. Final random_offset value will be random number in range:" -msgstr "" -"Denna parameter styr värdet på den slumpvisa förskjutningen som används i " -"ovanstående ekvation. Det slutliga random_offset-värdet kommer vara ett " -"slumptal i intervallet:" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:835 -msgid "[0 - offline_timeout_random_offset]" -msgstr "[0 – offline_timeout_random_offset]" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:838 -msgid "A value of 0 disables the random offset addition." -msgstr "Ett värde på 0 avaktiverar tillägget av en slumpfördröjning." - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:841 -msgid "Default: 30" -msgstr "Standard: 30" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:846 -msgid "responder_idle_timeout" +#: sssd.conf.5.xml:798 +#, fuzzy +#| msgid "responder_idle_timeout" +msgid "responder_idle_timeout (integer)" msgstr "responder_idle_timeout" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:849 +#: sssd.conf.5.xml:801 msgid "" "This option specifies the number of seconds that an SSSD responder process " "can be up without being used. This value is limited in order to avoid " @@ -1339,84 +1258,89 @@ msgid "" "built with systemd support and when services are either socket or D-Bus " "activated." msgstr "" -"Detta alternativ anger antalet sekunder som en SSSD-respondentprocess kan " -"vara uppe utan att användas. Detta värde är begränsat för att undvika att " -"resurserna på systemet tar slut. Det minsta acceptabla värdet för detta " -"alternativ är 60 sekunder. Att sätta detta alternativ till 0 (noll) betyder " -"att ingen tidsgräns kommer att sättas av respondenten. Detta alternativ har " -"bara effekt när SSSD är byggt med stöd för systemd och när tjänster är " -"antingen uttags- eller D-Bus-aktiverade." +"Detta alternativ anger hur många sekunder en SSSD-svararprocess kan köras " +"utan att användas. Värdet begränsas för att undvika resursbrist i systemet. " +"Det minsta godtagbara värdet för alternativet är 60 sekunder. Att sätta " +"alternativet till 0 (noll) innebär att ingen tidsgräns anges för svararen. " +"Alternativet har endast effekt när SSSD är byggt med systemd-stöd och " +"tjänsterna är antingen socket- eller D-Bus-aktiverade." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:863 sssd.conf.5.xml:1123 sssd.conf.5.xml:2248 +#: sssd.conf.5.xml:815 sssd.conf.5.xml:1079 sssd.conf.5.xml:2285 #: sssd-ldap.5.xml:377 msgid "Default: 300" msgstr "Standard: 300" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:868 -msgid "cache_first" +#: sssd.conf.5.xml:820 +#, fuzzy +#| msgid "cache_first" +msgid "cache_first (boolean)" msgstr "cache_first" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:871 +#: sssd.conf.5.xml:823 msgid "" "This option specifies whether the responder should query all caches before " "querying the Data Providers." msgstr "" -"Detta alternativ anger huruvida respondenten skall fråga alla cachar före " -"den frågar dataleverantörerna." +"Detta alternativ anger om svararen ska fråga alla cacheminnen innan " +"dataleverantörerna frågas." #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:883 +#: sssd.conf.5.xml:835 msgid "NSS configuration options" msgstr "NSS-konfigurationsalternativ" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:885 +#: sssd.conf.5.xml:837 +#, fuzzy +#| msgid "" +#| "These options can be used to configure the Name Service Switch (NSS) " +#| "service." msgid "" -"These options can be used to configure the Name Service Switch (NSS) service." +"These options can be used to configure the Name Service Switch (NSS) service " +"and should be specified under the <quote>[nss]</quote> section." msgstr "" "Dessa alternativ kan användas för att konfigurera tjänsten Name Service " "Switch (NSS)." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:890 +#: sssd.conf.5.xml:843 msgid "enum_cache_timeout (integer)" msgstr "enum_cache_timeout (heltal)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:893 +#: sssd.conf.5.xml:846 msgid "" "How many seconds should nss_sss cache enumerations (requests for info about " "all users)" msgstr "" -"Hur många sekunder skall nss_sss cacha uppräkningar (begäranden för " +"Hur många sekunder nss_sss ska cachelagra uppräkningar (begäranden om " "information om alla användare)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:897 +#: sssd.conf.5.xml:850 msgid "Default: 120" msgstr "Standard: 120" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:902 +#: sssd.conf.5.xml:855 msgid "entry_cache_nowait_percentage (integer)" msgstr "entry_cache_nowait_percentage (heltal)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:905 +#: sssd.conf.5.xml:858 msgid "" "The entry cache can be set to automatically update entries in the background " "if they are requested beyond a percentage of the entry_cache_timeout value " "for the domain." msgstr "" -"Cachen över poster kan ställas in att automatiskt uppdatera poster i " -"bakgrunden om de begärs utöver en procentsats av värdet entry_cache_timeout " -"för domänen." +"Postcachen kan ställas in att automatiskt uppdatera poster i bakgrunden om " +"de begärs efter en viss procentandel av domänens entry_cache_timeout-värde." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:911 +#: sssd.conf.5.xml:864 msgid "" "For example, if the domain's entry_cache_timeout is set to 30s and " "entry_cache_nowait_percentage is set to 50 (percent), entries that come in " @@ -1424,58 +1348,58 @@ msgid "" "but the SSSD will go and update the cache on its own, so that future " "requests will not need to block waiting for a cache update." msgstr "" -"Till exempel, om domänens entry_cache_timeout är satt till 30 s och " -"entry_cache_nowait_percentage är satt till 50 (procent) kommer poster som " -"kommer in 15 sekunder efter den sista cacheuppdateringen returneras " -"omedelbart, men SSSD kommer att ta och uppdatera cachen på egen hand, så att " -"framtida begäranden kommer behöva blockera i väntan på en cacheuppdatering." +"Om domänens entry_cache_timeout till exempel är satt till 30 s och " +"entry_cache_nowait_percentage är satt till 50 (procent), returneras poster " +"som kommer in 15 sekunder efter den senaste cacheuppdateringen omedelbart. " +"SSSD uppdaterar dock cachen själv, så att framtida begäranden inte behöver " +"blockeras i väntan på en cacheuppdatering." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:921 +#: sssd.conf.5.xml:874 msgid "" "Valid values for this option are 0-99 and represent a percentage of the " "entry_cache_timeout for each domain. For performance reasons, this " "percentage will never reduce the nowait timeout to less than 10 seconds. (0 " "disables this feature)" msgstr "" -"Giltiga värden för detta alternativ är 0-99 och representerar en procentsats " -"av entry_cache_timeout för varje domän. Av prestandaskäl kommer denna " -"procentsats aldrig reducera nowait-tidsgränser till mindre än 10 sekunder. " -"(0 avaktiverar denna funktion)" +"Giltiga värden för detta alternativ är 0–99 och representerar en " +"procentandel av entry_cache_timeout för varje domän. Av prestandaskäl sänker " +"denna procentandel aldrig nowait-tidsgränsen till mindre än 10 sekunder. (0 " +"inaktiverar funktionen.)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:929 sssd.conf.5.xml:2061 +#: sssd.conf.5.xml:882 sssd.conf.5.xml:2093 msgid "Default: 50" msgstr "Standard: 50" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:934 +#: sssd.conf.5.xml:887 msgid "entry_negative_timeout (integer)" msgstr "entry_negative_timeout (heltal)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:937 +#: sssd.conf.5.xml:890 msgid "" "Specifies for how many seconds nss_sss should cache negative cache hits " "(that is, queries for invalid database entries, like nonexistent ones) " "before asking the back end again." msgstr "" -"Anger hur många sekunder nss_sss cachar negativa cacheträffar (det vill " -"säga, frågor om ogiltiga databasposter, som sådana som inte finns) innan " -"bakänden tillfrågas igen." +"Anger hur många sekunder nss_sss ska cachelagra negativa cacheträffar (det " +"vill säga frågor om ogiltiga databasposter, till exempel obefintliga) innan " +"den bakomliggande komponenten frågas igen." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:943 sssd.conf.5.xml:1685 sssd.conf.5.xml:2085 +#: sssd.conf.5.xml:896 sssd.conf.5.xml:1677 sssd.conf.5.xml:2119 msgid "Default: 15" msgstr "Standard: 15" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:948 +#: sssd.conf.5.xml:901 msgid "filter_users, filter_groups (string)" msgstr "filter_users, filter_groups (sträng)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:951 +#: sssd.conf.5.xml:904 msgid "" "Exclude certain users or groups from being fetched from the sss NSS " "database. This is particularly useful for system accounts. This option can " @@ -1483,49 +1407,54 @@ msgid "" "from the particular domain or by a user principal name (UPN)." msgstr "" "Uteslut vissa användare eller grupper från att hämtas från sss NSS-" -"databasen. Detta är särskilt användbart för systemkonton. Detta alternativ " -"kan också anges per domän eller inkludera fullständigt kvalificerade namn " -"för att filtrera endast användare från den angivna domänen eller efter ett " -"användarhuvudmansnamn (UPN)." +"databasen. Detta är särskilt användbart för systemkonton. Alternativet kan " +"även anges per domän eller innehålla fullständigt kvalificerade namn för att " +"endast filtrera användare från den aktuella domänen eller efter ett " +"användarhuvudnamn (UPN)." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:959 +#: sssd.conf.5.xml:912 msgid "" "NOTE: The filter_groups option doesn't affect inheritance of nested group " "members, since filtering happens after they are propagated for returning via " "NSS. E.g. a group having a member group filtered out will still have the " "member users of the latter listed." msgstr "" -"OBS: alternativet filter_groups påverkar inte arvet av nästade " -"gruppmedlemmar, eftersom filtrering sker efter att de propagerats för att " -"returnera via NSS. T.ex. en grupp som har en medlemsgrupp bortfiltrerad " -"kommer fortfarande ha medlemsanvändarna i den senare listade." +"OBS! Alternativet filter_groups påverkar inte arv av nästlade " +"gruppmedlemmar, eftersom filtreringen sker efter att de har spridits för " +"retur via NSS. En grupp vars medlemsgrupp filtreras bort listar till exempel " +"fortfarande den senare gruppens medlemsanvändare." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:967 +#: sssd.conf.5.xml:920 msgid "Default: root" msgstr "Standard: root" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:972 -msgid "filter_users_in_groups (bool)" +#: sssd.conf.5.xml:925 +#, fuzzy +#| msgid "filter_users_in_groups (bool)" +msgid "filter_users_in_groups (boolean)" msgstr "filter_users_in_groups (bool)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:975 +#: sssd.conf.5.xml:928 +#, fuzzy +#| msgid "" +#| "If you want filtered user still be group members set this option to false." msgid "" -"If you want filtered user still be group members set this option to false." +"If you want filtered users to remain group members set this option to false" msgstr "" "Om du vill att filtrerade användare fortfarande skall vara gruppmedlemmar " "sätt då detta alternativ till false." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:986 +#: sssd.conf.5.xml:939 msgid "fallback_homedir (string)" msgstr "fallback_homedir (sträng)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:989 +#: sssd.conf.5.xml:942 msgid "" "Set a default template for a user's home directory if one is not specified " "explicitly by the domain's data provider." @@ -1534,15 +1463,15 @@ msgstr "" "anges av domänens dataleverantör." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:994 +#: sssd.conf.5.xml:947 msgid "" "The available values for this option are the same as for override_homedir." msgstr "" -"De tillgängliga värdena för detta alternativ är samma som för " +"De tillgängliga värdena för detta alternativ är desamma som för " "override_homedir." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1000 +#: sssd.conf.5.xml:953 #, no-wrap msgid "" "fallback_homedir = /home/%u\n" @@ -1552,23 +1481,23 @@ msgstr "" " " #. type: Content of: <varlistentry><listitem><para> -#: sssd.conf.5.xml:998 sssd.conf.5.xml:1557 sssd.conf.5.xml:1576 -#: sssd.conf.5.xml:1653 sssd-krb5.5.xml:451 include/override_homedir.xml:78 +#: sssd.conf.5.xml:951 sssd.conf.5.xml:1524 sssd.conf.5.xml:1543 +#: sssd.conf.5.xml:1645 sssd-krb5.5.xml:451 include/override_homedir.xml:78 msgid "example: <placeholder type=\"programlisting\" id=\"0\"/>" msgstr "exempel: <placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1004 +#: sssd.conf.5.xml:957 msgid "Default: not set (no substitution for unset home directories)" -msgstr "Standard: inte satt (ingen ersättning för ej angivna hemkataloger)" +msgstr "Standard: inte angivet (ingen ersättning för ej angivna hemkataloger)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1010 +#: sssd.conf.5.xml:963 msgid "override_shell (string)" msgstr "override_shell (sträng)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1013 +#: sssd.conf.5.xml:966 msgid "" "Override the login shell for all users. This option supersedes any other " "shell options if it takes effect and can be set either in the [nss] section " @@ -1579,30 +1508,30 @@ msgstr "" "sektionen [nss] eller per domän." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1019 +#: sssd.conf.5.xml:972 msgid "Default: not set (SSSD will use the value retrieved from LDAP)" -msgstr "" -"Standard: inte angivet (SSSD kommer använda värdet som hämtats från LDAP)" +msgstr "Standard: inte angivet (SSSD använder värdet som hämtas från LDAP)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1025 +#: sssd.conf.5.xml:978 msgid "allowed_shells (string)" msgstr "allowed_shells (sträng)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1028 +#: sssd.conf.5.xml:981 msgid "" "Restrict user shell to one of the listed values. The order of evaluation is:" msgstr "" -"Begränsa användarskal till ett av de listade värdena. Beräkningsordningen är:" +"Begränsa användarskalet till ett av de angivna värdena. " +"Utvärderingsordningen är:" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1031 +#: sssd.conf.5.xml:984 msgid "1. If the shell is present in <quote>/etc/shells</quote>, it is used." msgstr "1. Om skalet finns i <quote>/etc/shells</quote> används det." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1035 +#: sssd.conf.5.xml:988 msgid "" "2. If the shell is in the allowed_shells list but not in <quote>/etc/shells</" "quote>, use the value of the shell_fallback parameter." @@ -1611,7 +1540,7 @@ msgstr "" "quote>, använd värdet på parametern shell_fallback." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1040 +#: sssd.conf.5.xml:993 msgid "" "3. If the shell is not in the allowed_shells list and not in <quote>/etc/" "shells</quote>, a nologin shell is used." @@ -1620,57 +1549,57 @@ msgstr "" "shells</quote> används ett nologin-skal." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1045 +#: sssd.conf.5.xml:998 msgid "The wildcard (*) can be used to allow any shell." -msgstr "Jokertecknet (*) kan användas för att tillåta godtyckligt skal." +msgstr "Jokertecknet (*) kan användas för att tillåta valfritt skal." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1048 +#: sssd.conf.5.xml:1001 msgid "" "The (*) is useful if you want to use shell_fallback in case that user's " "shell is not in <quote>/etc/shells</quote> and maintaining list of all " "allowed shells in allowed_shells would be to much overhead." msgstr "" -"(*) är användbart om du vill använda shell_fallback ifall den användarens " -"skal inte finns i <quote>/etc/shells</quote> och att underhålla listan över " -"alla skal i allowed_shells skulle vara för mycket overhead." +"(*) är användbart om du vill använda shell_fallback när användarens skal " +"inte finns i <quote>/etc/shells</quote> och det skulle innebära för mycket " +"underhåll att hålla en lista över alla tillåtna skal i allowed_shells." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1055 +#: sssd.conf.5.xml:1008 msgid "An empty string for shell is passed as-is to libc." msgstr "En tom sträng som skal skickas som den är till libc." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1058 +#: sssd.conf.5.xml:1011 msgid "" "The <quote>/etc/shells</quote> is only read on SSSD start up, which means " "that a restart of the SSSD is required in case a new shell is installed." msgstr "" -"<quote>/etc/shells</quote> läses bara vid uppstart av SSSD, vilket betyder " -"att en omstart av SSSD behövs ifall ett nytt skal installeras." +"<quote>/etc/shells</quote> läses endast vid start av SSSD, vilket innebär " +"att SSSD måste startas om om ett nytt skal installeras." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1062 +#: sssd.conf.5.xml:1015 msgid "Default: Not set. The user shell is automatically used." -msgstr "Standard: inte satt. Användarens skal används automatiskt." +msgstr "Standard: inte angivet. Användarens skal används automatiskt." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1067 +#: sssd.conf.5.xml:1020 msgid "vetoed_shells (string)" msgstr "vetoed_shells (sträng)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1070 +#: sssd.conf.5.xml:1023 msgid "Replace any instance of these shells with the shell_fallback" msgstr "Ersätt alla instanser av dessa skal med shell_fallback" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1075 +#: sssd.conf.5.xml:1031 msgid "shell_fallback (string)" msgstr "shell_fallback (sträng)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1078 +#: sssd.conf.5.xml:1034 msgid "" "The default shell to use if an allowed shell is not installed on the machine." msgstr "" @@ -1678,17 +1607,17 @@ msgstr "" "maskinen." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1082 +#: sssd.conf.5.xml:1038 msgid "Default: /bin/sh" msgstr "Standard: /bin/sh" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1087 -msgid "default_shell" -msgstr "default_shell" +#: sssd.conf.5.xml:1043 +msgid "default_shell (string)" +msgstr "default_shell (sträng)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1090 +#: sssd.conf.5.xml:1046 msgid "" "The default shell to use if the provider does not return one during lookup. " "This option can be specified globally in the [nss] section or per-domain." @@ -1698,157 +1627,160 @@ msgstr "" "per domän." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1096 +#: sssd.conf.5.xml:1052 msgid "" "Default: not set (Return NULL if no shell is specified and rely on libc to " "substitute something sensible when necessary, usually /bin/sh)" msgstr "" -"Standard: inte satt (Returnera NULL om inget skal är angivet och lita på att " -"libc ersätter med något rimligt när nödvändigt, vanligen /bin/sh)" +"Standard: inte angivet (returnera NULL om inget skal anges och förlita dig " +"på att libc ersätter med något lämpligt vid behov, vanligtvis /bin/sh)." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1103 sssd.conf.5.xml:1483 +#: sssd.conf.5.xml:1059 sssd.conf.5.xml:1450 msgid "get_domains_timeout (int)" msgstr "get_domains_timeout (heltal)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1106 sssd.conf.5.xml:1486 +#: sssd.conf.5.xml:1062 sssd.conf.5.xml:1453 msgid "" "Specifies time in seconds for which the list of subdomains will be " "considered valid." -msgstr "" -"Anger tiden i sekunder under vilken listan av underdomäner kommer betraktas " -"som giltiga." +msgstr "Anger hur många sekunder listan över underdomäner betraktas som giltig." + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1066 sssd.conf.5.xml:1457 sssd.conf.5.xml:1788 +#: sssd.conf.5.xml:2862 sssd-ldap.5.xml:550 +msgid "Default: 60" +msgstr "Standard: 60" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1115 +#: sssd.conf.5.xml:1071 msgid "memcache_timeout (integer)" msgstr "memcache_timeout (heltal)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1118 +#: sssd.conf.5.xml:1074 msgid "" "Specifies time in seconds for which records in the in-memory cache will be " "valid. Setting this option to zero will disable the in-memory cache." msgstr "" -"Anger tiden i sekunder under vilken poster i minnescachen kommer vara " -"giltiga. Att sätta detta alternativ till noll kommer avaktivera cachen i " -"minnet." +"Anger hur många sekunder poster i minnescachen är giltiga. Att sätta detta " +"alternativ till noll inaktiverar minnescachen." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1126 +#: sssd.conf.5.xml:1082 msgid "" "WARNING: Disabling the in-memory cache will have significant negative impact " "on SSSD's performance and should only be used for testing." msgstr "" -"VARNING: att avaktivera cachen i minnet kommer ha signifikant negativ " -"påverkan på SSSD:s prestanda och skall bara användas för testning." +"VARNING! Att inaktivera minnescachen påverkar SSSD:s prestanda avsevärt " +"negativt och ska endast användas för testning." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1132 sssd.conf.5.xml:1157 sssd.conf.5.xml:1182 -#: sssd.conf.5.xml:1207 sssd.conf.5.xml:1234 +#: sssd.conf.5.xml:1088 sssd.conf.5.xml:1113 sssd.conf.5.xml:1138 +#: sssd.conf.5.xml:1163 sssd.conf.5.xml:1190 msgid "" "NOTE: If the environment variable SSS_NSS_USE_MEMCACHE is set to \"NO\", " "client applications will not use the fast in-memory cache." msgstr "" -"OBS: om miljövariabeln SSS_NSS_USE_MEMCACHE är satt till ”NO” kommer " -"klientprogram inte använda den snabba cachen i minnet." +"OBS! Om miljövariabeln SSS_NSS_USE_MEMCACHE är satt till \"NO\" använder " +"klientprogram inte den snabba minnescachen." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1140 +#: sssd.conf.5.xml:1096 msgid "memcache_size_passwd (integer)" msgstr "memcache_size_passwd (heltal)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1143 +#: sssd.conf.5.xml:1099 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for passwd requests. Setting the size to 0 will disable the passwd in-" "memory cache." msgstr "" -"Storlek (i megabyte) på datatabellen som allokeras inuti en snabb i-minnes-" -"cache för lösenordsbegäranden. Att sätta storleken till 0 kommer avaktivera " -"lösenords-cachen i minnet." +"Storlek (i megabyte) på datatabellen som allokeras i den snabba minnescachen " +"för passwd-begäranden. Att sätta storleken till 0 inaktiverar passwd-" +"minnescachen." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1149 sssd.conf.5.xml:2888 sssd-ldap.5.xml:604 +#: sssd.conf.5.xml:1105 sssd.conf.5.xml:3013 sssd-ldap.5.xml:604 msgid "Default: 8" msgstr "Standard: 8" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1152 sssd.conf.5.xml:1177 sssd.conf.5.xml:1202 -#: sssd.conf.5.xml:1229 +#: sssd.conf.5.xml:1108 sssd.conf.5.xml:1133 sssd.conf.5.xml:1158 +#: sssd.conf.5.xml:1185 msgid "" "WARNING: Disabled or too small in-memory cache can have significant negative " "impact on SSSD's performance." msgstr "" -"VARNING: en avaktiverad eller för liten cache i minnet kan ha signifikant " -"negativ påverkan på SSSD:s prestanda." +"VARNING! En inaktiverad eller för liten minnescache kan påverka SSSD:s " +"prestanda avsevärt negativt." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1165 +#: sssd.conf.5.xml:1121 msgid "memcache_size_group (integer)" msgstr "memcache_size_group (heltal)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1168 +#: sssd.conf.5.xml:1124 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for group requests. Setting the size to 0 will disable the group in-memory " "cache." msgstr "" -"Storlek (i megabyte) på datatabellen som allokeras inuti en snabb i-minnes-" -"cache för gruppbegäranden. Att sätta storleken till 0 kommer avaktivera " -"grupp-cachen i minnet." +"Storlek (i megabyte) på datatabellen som allokeras i den snabba minnescachen " +"för gruppbegäranden. Att sätta storleken till 0 inaktiverar " +"gruppminnescachen." #. type: Content of: <variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1174 sssd.conf.5.xml:1226 sssd.conf.5.xml:3656 +#: sssd.conf.5.xml:1130 sssd.conf.5.xml:1182 sssd.conf.5.xml:3835 #: sssd-ldap.5.xml:534 sssd-ldap.5.xml:581 include/failover.xml:116 #: include/krb5_options.xml:11 msgid "Default: 6" msgstr "Standard: 6" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1190 +#: sssd.conf.5.xml:1146 msgid "memcache_size_initgroups (integer)" msgstr "memcache_size_initgroups (heltal)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1193 +#: sssd.conf.5.xml:1149 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for initgroups requests. Setting the size to 0 will disable the initgroups " "in-memory cache." msgstr "" -"Storlek (i megabyte) på datatabellen som allokeras inuti en snabb i-minnes-" -"cache för initgruppbegäranden. Att sätta storleken till 0 kommer avaktivera " -"initgrupp-cachen i minnet." +"Storlek (i megabyte) på datatabellen som allokeras i den snabba minnescachen " +"för initgroups-begäranden. Att sätta storleken till 0 inaktiverar initgroups-" +"minnescachen." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1215 +#: sssd.conf.5.xml:1171 msgid "memcache_size_sid (integer)" -msgstr "memcache_size_sid (integer)" +msgstr "memcache_size_sid (heltal)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1218 +#: sssd.conf.5.xml:1174 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for SID related requests. Only SID-by-ID and ID-by-SID requests are " "currently cached in fast in-memory cache. Setting the size to 0 will " "disable the SID in-memory cache." msgstr "" -"Storlek (i megabyte) på datatabellen som allokeras inuti en snabb i-minnes-" -"cache för SID-realterade begäranden. Endast SID-via-ID- och ID-via-SID-" -"begäranden sparas för närvarande i den snabba cachen i minnet. Att sätta " -"storleken till 0 kommer avaktivera SID-cachen i minnet." +"Storlek (i megabyte) på datatabellen som allokeras i den snabba minnescachen " +"för SID-relaterade begäranden. Endast SID-by-ID- och ID-by-SID-begäranden " +"cachelagras för närvarande i den snabba minnescachen. Att sätta storleken " +"till 0 inaktiverar SID-minnescachen." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1242 sssd-ifp.5.xml:90 +#: sssd.conf.5.xml:1198 sssd-ifp.5.xml:90 msgid "user_attributes (string)" msgstr "user_attributes (sträng)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1245 +#: sssd.conf.5.xml:1201 msgid "" "Some of the additional NSS responder requests can return more attributes " "than just the POSIX ones defined by the NSS interface. The list of " @@ -1857,105 +1789,117 @@ msgid "" "<citerefentry> <refentrytitle>sssd-ifp</refentrytitle> <manvolnum>5</" "manvolnum> </citerefentry> for details) but with no default values." msgstr "" -"Några av de ytterligare NSS-respondentbegäranden kan returnera fler attribut " -"än bara de som definieras av POSIX via NSS-gränssnittet. Listan av attribut " -"styrs av detta alternativ. Det hanteras på samma sätt som alternativet " -"<quote>user_attributes</quote> för InfoPipe-respondenten (se <citerefentry> " +"Vissa ytterligare NSS-svararbegäranden kan returnera fler attribut än endast " +"de POSIX-attribut som definieras av NSS-gränssnittet. Attributlistan styrs " +"av detta alternativ. Det hanteras på samma sätt som alternativet <quote>" +"user_attributes</quote> för InfoPipe-svararen (se <citerefentry> " "<refentrytitle>sssd-ifp</refentrytitle> <manvolnum>5</manvolnum> </" -"citerefentry> för detaljer) men utan standardvärden." +"citerefentry> för mer information), men utan standardvärden." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1258 +#: sssd.conf.5.xml:1214 msgid "" "To make configuration more easy the NSS responder will check the InfoPipe " "option if it is not set for the NSS responder." msgstr "" -"För att förenkla konfigurationen kommer NSS-respondenten kontrollera " -"InfoPipe-alternativet om det inte är satt för NSS-respondenten." +"För att förenkla konfigurationen kontrollerar NSS-svararen InfoPipe-" +"alternativet om det inte är angivet för NSS-svararen." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1263 +#: sssd.conf.5.xml:1219 msgid "Default: not set, fallback to InfoPipe option" -msgstr "Standard: inte satt, gå tillbaka till InfoPipe-alternativet" +msgstr "Standard: inte angivet, fall tillbaka till InfoPipe-alternativet" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1268 +#: sssd.conf.5.xml:1224 msgid "pwfield (string)" msgstr "pwfield (sträng)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1271 +#: sssd.conf.5.xml:1227 msgid "" "The value that NSS operations that return users or groups will return for " "the <quote>password</quote> field." msgstr "" -"Värdet som NSS-operationer som returnerar användare eller grupper kommer att " -"returnera i fältet <quote>password</quote>." +"Värdet som NSS-operationer som returnerar användare eller grupper returnerar " +"för fältet <quote>password</quote>." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1276 -msgid "Default: <quote>*</quote>" -msgstr "Standard: <quote>*</quote>" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1279 +#: sssd.conf.5.xml:1232 msgid "" -"Note: This option can also be set per-domain which overwrites the value in " -"[nss] section." +"This option can also be set per-domain, which overwrites the value in the " +"<quote>[nss]</quote> section for that domain. This is particularly useful " +"when using a proxy domain with <option>proxy_lib_name=files</option> and a " +"<option>proxy_pam_target</option> other than <quote>sssd-shadowutils</" +"quote>. In that case, SSSD returns <quote>*</quote> for the password field " +"by default, which causes <command>pam_unix</command> to treat all accounts " +"as locked. Setting <option>pwfield = x</option> in the domain section " +"restores the expected behavior." msgstr "" -"Observera: detta alternativ kan även sättas per domän vilket åsidosätter " -"värdet i [nss]-sektionen." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1283 +#: sssd.conf.5.xml:1246 +msgid "Default: <quote>*</quote>" +msgstr "Standard: <quote>*</quote>" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1249 +#, fuzzy +#| msgid "" +#| "Default: <quote>not set</quote> (remote domains), <quote>x</quote> (proxy " +#| "domain with nss_files and sssd-shadowutils target)" msgid "" -"Default: <quote>not set</quote> (remote domains), <quote>x</quote> (proxy " -"domain with nss_files and sssd-shadowutils target)" +"Default (per-domain): <quote>not set</quote> (remote domains), <quote>x</" +"quote> (proxy domain with nss_files and sssd-shadowutils target)" msgstr "" "Standard: <quote>inte satt</quote> (fjärrdomäner), <quote>x</quote> " "(proxydomän med målet nss_files och sssd-shadowutils)" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:1292 +#: sssd.conf.5.xml:1258 msgid "PAM configuration options" msgstr "PAM-konfigurationsalternativ" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:1294 +#: sssd.conf.5.xml:1260 +#, fuzzy +#| msgid "" +#| "These options can be used to configure the Pluggable Authentication " +#| "Module (PAM) service." msgid "" "These options can be used to configure the Pluggable Authentication Module " -"(PAM) service." +"(PAM) service and should be specified under the <quote>[pam]</quote> section." msgstr "" "Dessa alternativ kan användas för att konfigurera tjänsten Pluggable " "Authentication Module (PAM)." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1299 +#: sssd.conf.5.xml:1266 msgid "offline_credentials_expiration (integer)" msgstr "offline_credentials_expiration (heltal)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1302 +#: sssd.conf.5.xml:1269 msgid "" "If the authentication provider is offline, how long should we allow cached " "logins (in days since the last successful online login)." msgstr "" -"Om autentiseringsleverantören inte är ansluten, hur länge skall vi tillåta " -"cachade inloggningar (i dagar efter den senaste lyckade uppkopplade " -"inloggningen)." +"Om autentiseringsleverantören är frånkopplad, hur länge ska cachade " +"inloggningar tillåtas (i dagar sedan den senaste lyckade inloggningen online)" +"?" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1307 sssd.conf.5.xml:1320 +#: sssd.conf.5.xml:1274 sssd.conf.5.xml:1287 msgid "Default: 0 (No limit)" msgstr "Standard: 0 (ingen gräns)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1313 +#: sssd.conf.5.xml:1280 msgid "offline_failed_login_attempts (integer)" msgstr "offline_failed_login_attempts (heltal)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1316 +#: sssd.conf.5.xml:1283 msgid "" "If the authentication provider is offline, how many failed login attempts " "are allowed." @@ -1964,42 +1908,42 @@ msgstr "" "inloggningsförsök är tillåtna." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1326 +#: sssd.conf.5.xml:1293 msgid "offline_failed_login_delay (integer)" msgstr "offline_failed_login_delay (heltal)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1329 +#: sssd.conf.5.xml:1296 msgid "" "The time in minutes which has to pass after offline_failed_login_attempts " "has been reached before a new login attempt is possible." msgstr "" "Tiden i minuter som måste förflyta efter att offline_failed_login_attempts " -"har nåtts före ett nytt inloggningsförsök är möjligt." +"har uppnåtts innan ett nytt inloggningsförsök är möjligt." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1334 +#: sssd.conf.5.xml:1301 msgid "" "If set to 0 the user cannot authenticate offline if " "offline_failed_login_attempts has been reached. Only a successful online " "authentication can enable offline authentication again." msgstr "" -"Om satt till 0 kan inte användaren autentisera om " -"offline_failed_login_attempts har uppnåtts. Endast en lyckad uppkopplad " -"autentisering kan aktivera autentisering utan uppkoppling igen." +"Om värdet är 0 kan användaren inte autentisera frånkopplad om " +"offline_failed_login_attempts har uppnåtts. Endast en lyckad autentisering " +"online kan aktivera frånkopplad autentisering igen." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1340 sssd.conf.5.xml:1450 +#: sssd.conf.5.xml:1307 sssd.conf.5.xml:1417 msgid "Default: 5" msgstr "Standard: 5" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1346 +#: sssd.conf.5.xml:1313 msgid "pam_verbosity (integer)" msgstr "pam_verbosity (heltal)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1349 +#: sssd.conf.5.xml:1316 msgid "" "Controls what kind of messages are shown to the user during authentication. " "The higher the number to more messages are displayed." @@ -2008,95 +1952,95 @@ msgstr "" "Ju högre tal desto fler meddelanden visas." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1354 +#: sssd.conf.5.xml:1321 msgid "Currently sssd supports the following values:" msgstr "För närvarande stödjs följande värden:" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1357 +#: sssd.conf.5.xml:1324 msgid "<emphasis>0</emphasis>: do not show any message" msgstr "<emphasis>0</emphasis>: visa inte några meddelanden" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1360 +#: sssd.conf.5.xml:1327 msgid "<emphasis>1</emphasis>: show only important messages" msgstr "<emphasis>1</emphasis>: visa endast viktiga meddelanden" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1364 +#: sssd.conf.5.xml:1331 msgid "<emphasis>2</emphasis>: show informational messages" msgstr "<emphasis>2</emphasis>: visa informationsmeddelanden" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1367 +#: sssd.conf.5.xml:1334 msgid "<emphasis>3</emphasis>: show all messages and debug information" msgstr "" "<emphasis>3</emphasis>: visa alla meddelanden och felsökningsinformation" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1371 sssd.8.xml:63 +#: sssd.conf.5.xml:1338 sssd.8.xml:63 msgid "Default: 1" msgstr "Standard: 1" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1377 +#: sssd.conf.5.xml:1344 msgid "pam_response_filter (string)" msgstr "pam_response_filter (sträng)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1380 +#: sssd.conf.5.xml:1347 msgid "" "A comma separated list of strings which allows to remove (filter) data sent " "by the PAM responder to pam_sss PAM module. There are different kind of " "responses sent to pam_sss e.g. messages displayed to the user or environment " "variables which should be set by pam_sss." msgstr "" -"En kommaseparerad lista av strängar som möjliggör att ta bort (filtrera) " -"data skickat av PAM-respondenten till pam_sss-PAM-modulen. Det finns olika " -"sorters svar skickade till pam_sss, t.ex. meddelanden som visas för " -"användaren eller miljövariabler som skall sättas av pam_sss." +"En kommaseparerad lista med strängar som gör det möjligt att ta bort " +"(filtrera) data som PAM-svararen skickar till PAM-modulen pam_sss. Olika " +"typer av svar skickas till pam_sss, till exempel meddelanden som visas för " +"användaren eller miljövariabler som ska anges av pam_sss." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1388 +#: sssd.conf.5.xml:1355 msgid "" "While messages already can be controlled with the help of the pam_verbosity " "option this option allows to filter out other kind of responses as well." msgstr "" -"Medan meddelanden redan kan styras med hjälp av alternativet pam_verbosity " -"gör detta alternativ att man kan filtrera ut andra sorters svar dessutom." +"Meddelanden kan redan styras med alternativet pam_verbosity, men detta " +"alternativ gör det också möjligt att filtrera bort andra typer av svar." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1395 +#: sssd.conf.5.xml:1362 msgid "ENV" msgstr "ENV" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1396 +#: sssd.conf.5.xml:1363 msgid "Do not send any environment variables to any service." msgstr "Skicka inte några miljövariabler till någon tjänst." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1399 +#: sssd.conf.5.xml:1366 msgid "ENV:var_name" -msgstr "ENV:varnamn" +msgstr "ENV:var_name" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1400 +#: sssd.conf.5.xml:1367 msgid "Do not send environment variable var_name to any service." -msgstr "Skicka inte miljövariabeln varnamn till någon tjänst." +msgstr "Skicka inte miljövariabeln var_name till någon tjänst." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1404 +#: sssd.conf.5.xml:1371 msgid "ENV:var_name:service" -msgstr "ENV:varnamn:tjänst" +msgstr "ENV:var_name:service" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1405 +#: sssd.conf.5.xml:1372 msgid "Do not send environment variable var_name to service." -msgstr "Skicka inte miljövariabeln varnamn till tjänst." +msgstr "Skicka inte miljövariabeln var_name till tjänsten service." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1393 +#: sssd.conf.5.xml:1360 msgid "" "Currently the following filters are supported: <placeholder " "type=\"variablelist\" id=\"0\"/>" @@ -2105,7 +2049,7 @@ msgstr "" "id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1412 +#: sssd.conf.5.xml:1379 msgid "" "The list of strings can either be the list of filters which would set this " "list of filters and overwrite the defaults. Or each element of the list can " @@ -2114,87 +2058,86 @@ msgid "" "that either all list elements must have a '+' or '-' prefix or none. It is " "considered as an error to mix both styles." msgstr "" -"Listan av strängar kan antingen vara listan av filter vilka skulle sätta " -"denna lista av filter och åsidosätta standardvärdet. Eller så kan varje " -"element i listan ha ett tecken ”+” eller ”-” som prefix vilket skulle lägga " -"till filtret till det befintliga standardvärdet respektive ta bort det från " -"standardvärdet. Observera att antingen måste alla listelement ha ett ”+” " -"eller ”-” eller inget av dem. Det ses som ett fel att blanda båda sätten." +"Stränglistan kan antingen vara en filterlista som anger denna filterlista " +"och åsidosätter standardvärdena. Alternativt kan varje element i listan " +"föregås av tecknet '+' eller '-', vilket respektive lägger till filtret till " +"befintliga standardvärden eller tar bort det från dem. Observera att " +"antingen måste alla listelement ha prefixet '+' eller '-', eller inget av " +"dem. Det betraktas som ett fel att blanda stilarna." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1423 +#: sssd.conf.5.xml:1390 msgid "Default: ENV:KRB5CCNAME:sudo, ENV:KRB5CCNAME:sudo-i" msgstr "Standard: ENV:KRB5CCNAME:sudo, ENV:KRB5CCNAME:sudo-i" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1426 +#: sssd.conf.5.xml:1393 msgid "" "Example: -ENV:KRB5CCNAME:sudo-i will remove the filter from the default list" -msgstr "" -"Exempel: -ENV:KRB5CCNAME:sudo-i kommer ta bort det filtret från " -"standardlistan" +msgstr "Exempel: -ENV:KRB5CCNAME:sudo-i tar bort filtret från standardlistan." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1433 +#: sssd.conf.5.xml:1400 msgid "pam_id_timeout (integer)" msgstr "pam_id_timeout (heltal)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1436 +#: sssd.conf.5.xml:1403 msgid "" "For any PAM request while SSSD is online, the SSSD will attempt to " "immediately update the cached identity information for the user in order to " "ensure that authentication takes place with the latest information." msgstr "" -"För alla PAM-begäranden när SSSD är uppkopplat kommer SSSD försöka att " -"omedelbart uppdatera cachad identitetsinformation för användaren för att se " -"till att autentisering sker med den senaste informationen." +"Vid varje PAM-begäran när SSSD är anslutet försöker SSSD omedelbart " +"uppdatera den cachelagrade identitetsinformationen för användaren, så att " +"autentiseringen sker med den senaste informationen." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1442 +#: sssd.conf.5.xml:1409 msgid "" "A complete PAM conversation may perform multiple PAM requests, such as " "account management and session opening. This option controls (on a per-" "client-application basis) how long (in seconds) we can cache the identity " "information to avoid excessive round-trips to the identity provider." msgstr "" -"En fullständig PAM-konversation kan utföra flera PAM-begäranden såsom " -"hantering av konto och öppning av en session. Detta alternativ styr (på per-" -"klientprogrambasis) hur länge (i sekunder) vi kan cacha " -"identitetsinformationen för att undvika överdrivna rundturer till " +"En fullständig PAM-konversation kan utföra flera PAM-begäranden, till " +"exempel kontohantering och sessionsöppning. Detta alternativ styr hur länge " +"(i sekunder) identitetsinformationen kan cachelagras för varje " +"klientprogram, för att undvika alltför många tur-och-retur-anrop till " "identitetsleverantören." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1456 +#: sssd.conf.5.xml:1423 msgid "pam_pwd_expiration_warning (integer)" msgstr "pam_pwd_expiration_warning (heltal)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1459 sssd.conf.5.xml:2912 +#: sssd.conf.5.xml:1426 sssd.conf.5.xml:3037 msgid "Display a warning N days before the password expires." msgstr "Visa en varning N dagar före lösenordet går ut." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1462 +#: sssd.conf.5.xml:1429 msgid "" "Please note that the backend server has to provide information about the " "expiration time of the password. If this information is missing, sssd " "cannot display a warning." msgstr "" -"Observera att bakändeservern måste leverera information om utgångstiden för " -"lösenordet. Om denna information saknas kan sssd inte visa någon varning." +"Observera att den bakomliggande servern måste tillhandahålla information om " +"lösenordets utgångstid. Om informationen saknas kan sssd inte visa någon " +"varning." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1468 sssd.conf.5.xml:2915 +#: sssd.conf.5.xml:1435 sssd.conf.5.xml:3040 msgid "" "If zero is set, then this filter is not applied, i.e. if the expiration " "warning was received from backend server, it will automatically be displayed." msgstr "" -"Om noll anges tillämpas inte detta filter, d.v.s. om utgångsvarningen " -"mottogs från bakändeserver kommer den automatiskt visas." +"Om noll anges tillämpas inte detta filter, dvs. om utgångsvarningen mottogs " +"från den bakomliggande servern visas den automatiskt." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1473 +#: sssd.conf.5.xml:1440 msgid "" "This setting can be overridden by setting <emphasis>pwd_expiration_warning</" "emphasis> for a particular domain." @@ -2203,18 +2146,18 @@ msgstr "" "pwd_expiration_warning</emphasis> för en viss domän." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1478 sssd.conf.5.xml:3913 sssd-ldap.5.xml:662 +#: sssd.conf.5.xml:1445 sssd.conf.5.xml:4118 sssd-ldap.5.xml:662 #: sssd-ldap.5.xml:1733 sssd.8.xml:79 msgid "Default: 0" msgstr "Standard: 0" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1495 +#: sssd.conf.5.xml:1462 msgid "pam_trusted_users (string)" msgstr "pam_trusted_users (sträng)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1498 +#: sssd.conf.5.xml:1465 msgid "" "Specifies the comma-separated list of UID values or user names that are " "allowed to run PAM conversations against trusted domains. Users not " @@ -2222,33 +2165,32 @@ msgid "" "<quote>pam_public_domains</quote>. User names are resolved to UIDs at " "startup." msgstr "" -"Anger den kommaseparerade listan av AID-värden eller användarnamn som " -"tillåts köra PAM-konverteringar mot betrodda domäner. Användare som inte är " -"inkluderade i denna lista kan endast komma åt domäner som är markerade som " -"publika med <quote>pam_public_domains</quote>. Användarnamn slås upp till " -"UID vid uppstart." +"Anger den kommaseparerade listan med UID-värden eller användarnamn som får " +"köra PAM-konversationer mot betrodda domäner. Användare som inte finns med i " +"listan kan endast komma åt domäner som är markerade som offentliga med " +"<quote>pam_public_domains</quote>. Användarnamn löses till UID:er vid start." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1508 +#: sssd.conf.5.xml:1475 msgid "Default: All users are considered trusted by default" msgstr "Standard: alla användare betraktas som betrodda som standard" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1512 +#: sssd.conf.5.xml:1479 msgid "" "Please note that UID 0 is always allowed to access the PAM responder even in " "case it is not in the pam_trusted_users list." msgstr "" -"Observera att AID 0 alltid tillåts komma åt PAM-respondenten även ifall den " -"inte är i listan pam_trusted_users." +"Observera att UID 0 alltid får komma åt PAM-svararen, även om den inte finns " +"i listan pam_trusted_users." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1519 +#: sssd.conf.5.xml:1486 msgid "pam_public_domains (string)" msgstr "pam_public_domains (sträng)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1522 +#: sssd.conf.5.xml:1489 msgid "" "Specifies the comma-separated list of domain names that are accessible even " "to untrusted users." @@ -2257,20 +2199,20 @@ msgstr "" "betrodda användare." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1526 +#: sssd.conf.5.xml:1493 msgid "Two special values for pam_public_domains option are defined:" msgstr "" "Två speciella värden för alternativet pam_public_domains är definierade:" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1530 +#: sssd.conf.5.xml:1497 msgid "" "all (Untrusted users are allowed to access all domains in PAM responder.)" msgstr "" "all (Ej betrodda användare tillåts komma åt alla domäner i PAM-respondenten.)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1534 +#: sssd.conf.5.xml:1501 msgid "" "none (Untrusted users are not allowed to access any domains PAM in " "responder.)" @@ -2279,37 +2221,36 @@ msgstr "" "respondenten.)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1538 sssd.conf.5.xml:1563 sssd.conf.5.xml:1582 -#: sssd.conf.5.xml:1824 sssd.conf.5.xml:3842 sssd-ldap.5.xml:1270 +#: sssd.conf.5.xml:1505 sssd.conf.5.xml:1530 sssd.conf.5.xml:1549 +#: sssd.conf.5.xml:1821 sssd.conf.5.xml:4048 sssd-ldap.5.xml:1270 msgid "Default: none" msgstr "Standard: none" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1543 +#: sssd.conf.5.xml:1510 msgid "pam_account_expired_message (string)" msgstr "pam_account_expired_message (sträng)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1546 +#: sssd.conf.5.xml:1513 msgid "" "Allows a custom expiration message to be set, replacing the default " "'Permission denied' message." msgstr "" -"Gör att det går att ange ett anpassat utgångsmeddelande som ersätter " -"standardmeddelandet ”åtkomst nekas”." +"Gör det möjligt att ange ett eget utgångsmeddelande som ersätter " +"standardmeddelandet 'Permission denied'." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1551 +#: sssd.conf.5.xml:1518 msgid "" "Note: Please be aware that message is only printed for the SSH service " "unless pam_verbosity is set to 3 (show all messages and debug information)." msgstr "" -"Observera: var medveten om att meddelandet endast skrivs för tjänsten SSH om " -"inte pam_verbosity är satt till 3 (visa alla meddelanden och " -"felsökningsinformation)." +"Obs! Meddelandet skrivs endast ut för SSH-tjänsten om inte pam_verbosity är " +"satt till 3 (visa alla meddelanden och felsökningsinformation)." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1559 +#: sssd.conf.5.xml:1526 #, no-wrap msgid "" "pam_account_expired_message = Account expired, please contact help desk.\n" @@ -2319,21 +2260,21 @@ msgstr "" " " #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1568 +#: sssd.conf.5.xml:1535 msgid "pam_account_locked_message (string)" msgstr "pam_account_locked_message (sträng)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1571 +#: sssd.conf.5.xml:1538 msgid "" "Allows a custom lockout message to be set, replacing the default 'Permission " "denied' message." msgstr "" -"Gör att det går att ange ett anpassat utlåsningsmeddelande som ersätter " -"standardmeddelandet ”åtkomst nekas”." +"Gör det möjligt att ange ett eget låsningsmeddelande som ersätter " +"standardmeddelandet 'Permission denied'." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1578 +#: sssd.conf.5.xml:1545 #, no-wrap msgid "" "pam_account_locked_message = Account locked, please contact help desk.\n" @@ -2343,72 +2284,119 @@ msgstr "" " " #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1587 -msgid "pam_passkey_auth (bool)" +#: sssd.conf.5.xml:1554 +#, fuzzy +#| msgid "pam_passkey_auth (bool)" +msgid "pam_passkey_auth (boolean)" msgstr "pam_passkey_auth (bool)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1590 +#: sssd.conf.5.xml:1557 msgid "Enable passkey device based authentication." -msgstr "Aktivera autentisering baserad på lösennyckelsenhet." +msgstr "Aktivera autentisering baserad på passnyckelenheter." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1593 sssd.conf.5.xml:1910 sssd-ad.5.xml:1286 +#: sssd.conf.5.xml:1560 sssd.conf.5.xml:1907 sssd-ad.5.xml:1279 #: sss_rpcidmapd.5.xml:76 msgid "Default: True" msgstr "Standard: True" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1598 -msgid "passkey_debug_libfido2 (bool)" +#: sssd.conf.5.xml:1565 +#, fuzzy +#| msgid "passkey_debug_libfido2 (bool)" +msgid "passkey_debug_libfido2 (boolean)" msgstr "passkey_debug_libfido2 (bool)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1601 +#: sssd.conf.5.xml:1568 msgid "Enable libfido2 library debug messages." -msgstr "Aktivera biblioteket libfido2 felsökningsmeddelanden." +msgstr "Aktivera felsökningsmeddelanden från biblioteket libfido2." #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1604 sssd.conf.5.xml:1618 sssd-ldap.5.xml:727 -#: sssd-ldap.5.xml:752 sssd-ldap.5.xml:848 sssd-ldap.5.xml:1356 -#: sssd-ad.5.xml:506 sssd-ad.5.xml:582 sssd-ad.5.xml:1155 +#: sssd.conf.5.xml:1571 sssd.conf.5.xml:1585 sssd.conf.5.xml:4781 +#: sssd-ldap.5.xml:727 sssd-ldap.5.xml:752 sssd-ldap.5.xml:848 +#: sssd-ldap.5.xml:1356 sssd-ad.5.xml:506 sssd-ad.5.xml:582 sssd-ad.5.xml:1160 #: include/ldap_id_mapping.xml:250 msgid "Default: False" msgstr "Standard: False" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1609 -msgid "pam_cert_auth (bool)" +#: sssd.conf.5.xml:1576 +#, fuzzy +#| msgid "pam_cert_auth (bool)" +msgid "pam_cert_auth (boolean)" msgstr "pam_cert_auth (bool)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1612 +#: sssd.conf.5.xml:1579 msgid "" "Enable certificate based Smartcard authentication. Since this requires " "additional communication with the Smartcard which will delay the " "authentication process this option is disabled by default." msgstr "" -"Aktivera certifikatbaserad smartkortsautentisering. Eftersom detta " -"förutsätter ytterligare kommunikation med smartkortet vilket kommer fördröja " -"autentiseringsprocessen är detta alternativ avaktiverat som standard." +"Aktivera certifikatbaserad smartkortsautentisering. Eftersom detta kräver " +"ytterligare kommunikation med smartkortet, vilket fördröjer " +"autentiseringsprocessen, är alternativet inaktiverat som standard." + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1588 +msgid "" +"Note: In case OpenSC is used for Smartcard access SSSD supports the " +"filesystem caching in OpenSC when enabled in opensc.conf. The cached files " +"are located in a common <quote>opensc</quote> directory in SSSD's state " +"directory. The behaviour can be changed in opensc.conf" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> +#: sssd.conf.5.xml:1597 +#, no-wrap +msgid "" +"app /usr/libexec/sssd/p11_child {\n" +" framework pkcs15 {\n" +" use_file_caching = no;\n" +" }\n" +"}\n" +"app /usr/libexec/sssd/krb5_child {\n" +" framework pkcs15 {\n" +" use_file_caching = no;\n" +" }\n" +"}\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1595 +#, fuzzy +#| msgid "Example: <placeholder type=\"programlisting\" id=\"0\"/>" +msgid "" +"Example opensc.conf (*): <placeholder type=\"programlisting\" id=\"0\"/>" +msgstr "Exempel: <placeholder type=\"programlisting\" id=\"0\"/>" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1610 +msgid "" +"(*) The actual <quote>libexec</quote> directory for p11_child and krb5_child " +"depends on the distribution." +msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1623 +#: sssd.conf.5.xml:1615 msgid "pam_cert_db_path (string)" msgstr "pam_cert_db_path (sträng)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1626 +#: sssd.conf.5.xml:1618 msgid "The path to the certificate database." msgstr "Sökvägen till certifikatdatabasen." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1629 sssd.conf.5.xml:2163 sssd.conf.5.xml:4338 +#: sssd.conf.5.xml:1621 sssd.conf.5.xml:2199 sssd.conf.5.xml:4543 msgid "Default:" msgstr "Standard:" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1631 sssd.conf.5.xml:2165 +#: sssd.conf.5.xml:1623 sssd.conf.5.xml:2201 msgid "" "/etc/sssd/pki/sssd_auth_ca_db.pem (path to a file with trusted CA " "certificates in PEM format)" @@ -2417,12 +2405,12 @@ msgstr "" "certifikat i PEM-format)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1641 +#: sssd.conf.5.xml:1633 msgid "pam_cert_verification (string)" msgstr "pam_cert_verification (sträng)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1644 +#: sssd.conf.5.xml:1636 msgid "" "With this parameter the PAM certificate verification can be tuned with a " "comma separated list of options that override the " @@ -2430,13 +2418,14 @@ msgid "" "section. Supported options are the same of <quote>certificate_verification</" "quote>." msgstr "" -"Med denna parameter kan verifieringen av PAM-certifikatet justeras med en " -"kommaseparerad lista av alternativ som åsidosätter värdet på <quote>" -"certificate_verification</quote> i sektionen <quote>[sssd]</quote>. Flaggor " -"som stödjs är samma som för <quote>certificate_verification</quote>." +"Med denna parameter kan PAM-certifikatverifieringen justeras med en " +"kommaseparerad lista med alternativ som åsidosätter värdet <quote>" +"certificate_verification</quote> i sektionen <quote>[sssd]</quote>. " +"Alternativen som stöds är samma som för <quote>certificate_verification</" +"quote>." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1655 +#: sssd.conf.5.xml:1647 #, no-wrap msgid "" "pam_cert_verification = partial_chain\n" @@ -2446,78 +2435,75 @@ msgstr "" " " #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1659 +#: sssd.conf.5.xml:1651 msgid "" "Default: not set, i.e. use default <quote>certificate_verification</quote> " "option defined in <quote>[sssd]</quote> section." msgstr "" -"Standard: inte satt, d.v.s. använd standardvärdet <quote>" -"certificate_verification</quote> definierat i sektionen <quote>[sssd]</quote>" -"." +"Standard: inte angivet, dvs. använd standardalternativet <quote>" +"certificate_verification</quote> som definieras i sektionen <quote>[sssd]</" +"quote>." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1666 +#: sssd.conf.5.xml:1658 msgid "p11_child_timeout (integer)" msgstr "p11_child_timeout (heltal)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1669 +#: sssd.conf.5.xml:1661 msgid "How many seconds will pam_sss wait for p11_child to finish." -msgstr "Hur många sekunder pam_sss kommer vänta på p11_child att avsluta." +msgstr "Hur många sekunder pam_sss väntar på att p11_child ska avslutas." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1678 +#: sssd.conf.5.xml:1670 msgid "passkey_child_timeout (integer)" msgstr "passkey_child_timeout (heltal)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1681 +#: sssd.conf.5.xml:1673 msgid "" "How many seconds will the PAM responder wait for passkey_child to finish." msgstr "" -"Hur många sekunder PAM-respondenten kommer vänta på passkey_child att " -"avsluta." +"Hur många sekunder PAM-svararen väntar på att passkey_child ska avslutas." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1690 +#: sssd.conf.5.xml:1682 msgid "pam_app_services (string)" msgstr "pam_app_services (sträng)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1693 +#: sssd.conf.5.xml:1685 msgid "" "Which PAM services are permitted to contact domains of type " "<quote>application</quote>" msgstr "" -"Vilken PAM-tjänster tillåts att kontakta domäner av typen <quote>" -"application</quote>" +"Vilka PAM-tjänster som tillåts kontakta domäner av typen <quote>application</" +"quote>." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1702 +#: sssd.conf.5.xml:1694 msgid "pam_p11_allowed_services (string)" msgstr "pam_p11_allowed_services (sträng)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1705 +#: sssd.conf.5.xml:1697 msgid "" "A comma-separated list of PAM service names for which it will be allowed to " "use Smartcards." -msgstr "" -"En kommaseparerad lista av PAM-tjänstenamn för vilka det kommer vara " -"tillåtet att använda smarta kort." +msgstr "En kommaseparerad lista med PAM-tjänstenamn som får använda smartkort." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1720 +#: sssd.conf.5.xml:1712 #, no-wrap msgid "" "pam_p11_allowed_services = +my_pam_service, -login\n" " " msgstr "" -"pam_p11_allowed_services = +min_pam-tjänst, -login\n" +"pam_p11_allowed_services = +my_pam_service, -login\n" " " #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1709 +#: sssd.conf.5.xml:1701 msgid "" "It is possible to add another PAM service name to the default set by using " "<quote>+service_name</quote> or to explicitly remove a PAM service name from " @@ -2527,93 +2513,99 @@ msgid "" "<quote>my_pam_service</quote>), you would use the following configuration: " "<placeholder type=\"programlisting\" id=\"0\"/>" msgstr "" -"Det är möjligt att lägga till ett annat PAM-tjänstenamn till " -"standarduppsättningen genom att använda <quote>+tjänstenamn</quote> eller " -"att uttryckligen ta bort ett PAM-tjänstenamn från standarduppsättningen " -"genom att använda <quote>-tjänstenamn</quote>. Till exempel, för att byta ut " -"ett standard-PAM-tjänstenamn för autentisering med smarta kort (t.ex. <quote>" -"login</quote>) mot ett anpassat PAM-tjänstenamn (t.ex. <quote>min_pam-" -"tjänst</quote>) skulle man använda följande konfiguration: <placeholder " -"type=\"programlisting\" id=\"0\"/>" +"Det är möjligt att lägga till ett annat PAM-tjänstenamn i " +"standarduppsättningen med <quote>+service_name</quote>, eller att " +"uttryckligen ta bort ett PAM-tjänstenamn från standarduppsättningen med " +"<quote>-service_name</quote>. Om du till exempel vill ersätta ett standard-" +"PAM-tjänstenamn för autentisering med smartkort (t.ex. <quote>login</quote>) " +"med ett eget PAM-tjänstenamn (t.ex. <quote>my_pam_service</quote>) använder " +"du följande konfiguration: <placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1724 sssd-ad.5.xml:645 sssd-ad.5.xml:754 sssd-ad.5.xml:812 -#: sssd-ad.5.xml:870 sssd-ad.5.xml:948 +#: sssd.conf.5.xml:1716 sssd-ad.5.xml:645 sssd-ad.5.xml:759 sssd-ad.5.xml:817 +#: sssd-ad.5.xml:875 sssd-ad.5.xml:953 msgid "Default: the default set of PAM service names includes:" msgstr "Standard: standarduppsättningen av PAM-tjänstenamn innefattar:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1729 sssd-ad.5.xml:649 +#: sssd.conf.5.xml:1721 sssd-ad.5.xml:649 msgid "login" msgstr "login" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1734 sssd-ad.5.xml:654 +#: sssd.conf.5.xml:1726 sssd-ad.5.xml:654 msgid "su" msgstr "su" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1739 sssd-ad.5.xml:659 +#: sssd.conf.5.xml:1731 sssd-ad.5.xml:659 msgid "su-l" msgstr "su-l" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1744 sssd-ad.5.xml:674 +#: sssd.conf.5.xml:1736 sssd-ad.5.xml:674 msgid "gdm-smartcard" msgstr "gdm-smartcard" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1749 sssd-ad.5.xml:669 +#: sssd.conf.5.xml:1741 sssd-ad.5.xml:669 msgid "gdm-password" msgstr "gdm-password" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1754 +#: sssd.conf.5.xml:1746 msgid "gdm-switchable-auth" msgstr "gdm-switchable-auth" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1759 sssd-ad.5.xml:679 +#: sssd.conf.5.xml:1751 sssd-ad.5.xml:679 msgid "kdm" msgstr "kdm" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1764 sssd-ad.5.xml:957 +#: sssd.conf.5.xml:1756 sssd-ad.5.xml:694 +#, fuzzy +#| msgid "login" +msgid "plasmalogin" +msgstr "login" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:1761 sssd-ad.5.xml:962 msgid "sudo" msgstr "sudo" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1769 sssd-ad.5.xml:962 +#: sssd.conf.5.xml:1766 sssd-ad.5.xml:967 msgid "sudo-i" msgstr "sudo-i" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1774 +#: sssd.conf.5.xml:1771 msgid "gnome-screensaver" msgstr "gnome-screensaver" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1782 +#: sssd.conf.5.xml:1779 msgid "p11_wait_for_card_timeout (integer)" msgstr "p11_wait_for_card_timeout (heltal)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1785 +#: sssd.conf.5.xml:1782 msgid "" "If Smartcard authentication is required how many extra seconds in addition " "to p11_child_timeout should the PAM responder wait until a Smartcard is " "inserted." msgstr "" -"Om smartkortsautentisering krävs hur många extra sekunder utöver " -"p11_child_timeout PAM-respondenten skall vänta på att ett smartkort sätts in." +"Om smartkortsautentisering krävs, hur många extra sekunder utöver " +"p11_child_timeout ska PAM-svararen vänta på att ett smartkort sätts in?" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1796 +#: sssd.conf.5.xml:1793 msgid "p11_uri (string)" msgstr "p11_uri (sträng)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1799 +#: sssd.conf.5.xml:1796 msgid "" "PKCS#11 URI (see RFC-7512 for details) which can be used to restrict the " "selection of devices used for Smartcard authentication. By default SSSD's " @@ -2622,35 +2614,36 @@ msgid "" "first slot found. If multiple readers are connected p11_uri can be used to " "tell p11_child to use a specific reader." msgstr "" -"PKCS#11 URI (se RFC-7512 för detaljer) som kan användas för att begränsa " -"urvalet av enheter som används för smartkortsautentisering. Som standard " -"kommer SSSD:s p11_child söka efter ett PKCS#11-fack (läsare) där flaggan ”" -"removable” är satt och läsa certifikaten från det insatta elementet från det " -"första facket som hittas. Om flera läsare är anslutna kan p11_uri användas " -"för att säga till p11_child att använda en specifik läsare." +"PKCS#11-URI (se RFC-7512 för mer information) som kan användas för att " +"begränsa urvalet av enheter som används för smartkortsautentisering. Som " +"standard söker SSSD:s p11_child efter en PKCS#11-plats (läsare) där flaggan " +"'removable' är satt och läser certifikaten från den isatta tokenen på den " +"första plats som hittas. Om flera läsare är anslutna kan p11_uri användas " +"för att ange att p11_child ska använda en viss läsare." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1812 +#: sssd.conf.5.xml:1809 #, no-wrap msgid "" "p11_uri = pkcs11:slot-description=My%20Smartcard%20Reader\n" " " msgstr "" -"p11_uri = pkcs11:slot-description=Min%20smartkortsläsare\n" +"p11_uri = pkcs11:slot-description=My%20Smartcard%20Reader\n" " " #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1816 +#: sssd.conf.5.xml:1813 #, no-wrap msgid "" "p11_uri = pkcs11:library-description=OpenSC%20smartcard%20framework;slot-id=2\n" " " msgstr "" -"p11_uri = pkcs11:library-description=OpenSC%20smartkortsramverk;slot-id=2\n" +"p11_uri = pkcs11:library-description=OpenSC%20smartcard%20framework;slot-" +"id=2\n" " " #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1810 +#: sssd.conf.5.xml:1807 msgid "" "Example: <placeholder type=\"programlisting\" id=\"0\"/> or <placeholder " "type=\"programlisting\" id=\"1\"/> To find suitable URI please check the " @@ -2658,81 +2651,85 @@ msgid "" "with e.g. the '--list-all' will show PKCS#11 URIs as well." msgstr "" "Exempel: <placeholder type=\"programlisting\" id=\"0\"/> eller <placeholder " -"type=\"programlisting\" id=\"1\"/> För att hitta en lämplig URI, kontrollera " -"felsökningsutdata från p11_child. Som ett alternativ kommer GnuTLS-verktyget " -"”p11tool” med t.ex. ”--list-all” visa även PKCS#11 URI:er." +"type=\"programlisting\" id=\"1\"/>. Kontrollera felsökningsutdata från " +"p11_child för att hitta en lämplig URI. Alternativt visar GnuTLS-verktyget " +"'p11tool' PKCS#11-URI:er med till exempel '--list-all'." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1829 -msgid "pam_initgroups_scheme" +#: sssd.conf.5.xml:1826 +#, fuzzy +#| msgid "pam_initgroups_scheme" +msgid "pam_initgroups_scheme (string)" msgstr "pam_initgroups_scheme" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1837 +#: sssd.conf.5.xml:1834 msgid "always" msgstr "always" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1838 +#: sssd.conf.5.xml:1835 msgid "" "Always do an online lookup, please note that pam_id_timeout still applies" msgstr "" -"Gör alltid en uppkopplad uppslagning, observera att pam_id_timeout " -"fortfarande gäller" +"Gör alltid en uppslagning online. Observera att pam_id_timeout fortfarande " +"gäller." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1842 +#: sssd.conf.5.xml:1839 msgid "no_session" msgstr "no_session" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1843 +#: sssd.conf.5.xml:1840 msgid "" "Only do an online lookup if there is no active session of the user, i.e. if " "the user is currently not logged in" msgstr "" -"Gör bara en uppkopplad uppslagning om det inte finns någon aktiv session för " -"användaren, d.v.s. om användaren inte är inloggad för närvarande" +"Gör endast en uppslagning online om användaren inte har någon aktiv session, " +"dvs. om användaren för närvarande inte är inloggad." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1848 sssd-ldap.5.xml:189 +#: sssd.conf.5.xml:1845 sssd-ldap.5.xml:189 msgid "never" msgstr "never" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1849 +#: sssd.conf.5.xml:1846 msgid "" "Never force an online lookup, use the data from the cache as long as they " "are not expired" msgstr "" -"Gör aldrig uppkopplade uppslagningar, använd data från cachen så länge de " -"inte har gått ut" +"Tvinga aldrig fram en uppslagning online; använd data från cachen så länge " +"de inte har gått ut." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1832 +#: sssd.conf.5.xml:1829 msgid "" "The PAM responder can force an online lookup to get the current group " "memberships of the user trying to log in. This option controls when this " "should be done and the following values are allowed: <placeholder " "type=\"variablelist\" id=\"0\"/>" msgstr "" -"PAM-respondenten kan framtvinga en uppkopplad uppslagning för att ta fram de " -"aktuella gruppmedlemskapen för användaren som försöker logga in. Denna " -"flagga styr när detta skall göras och följande värden är tillåtna: " -"<placeholder type=\"variablelist\" id=\"0\"/>" +"PAM-svararen kan tvinga fram en uppslagning online för att hämta aktuella " +"gruppmedlemskap för användaren som försöker logga in. Detta alternativ styr " +"när detta ska göras, och följande värden tillåts: <placeholder " +"type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1856 +#: sssd.conf.5.xml:1853 msgid "Default: no_session" msgstr "Standard: no_session" -#. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:1861 sssd.conf.5.xml:4277 -msgid "pam_gssapi_services" -msgstr "pam_gssapi_services" +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1858 +#, fuzzy +#| msgid "pam_app_services (string)" +msgid "pam_gssapi_services (string)" +msgstr "pam_app_services (sträng)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1864 +#: sssd.conf.5.xml:1861 msgid "" "Comma separated list of PAM services that are allowed to try GSSAPI " "authentication using pam_sss_gss.so module." @@ -2741,26 +2738,26 @@ msgstr "" "autentisering med modulen pam_sss_gss.so." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1869 +#: sssd.conf.5.xml:1866 msgid "" "To disable GSSAPI authentication, set this option to <quote>-</quote> (dash)." msgstr "" -"För att avaktivera GSSAPI-autentisering, sätt denna lista till <quote>-</" -"quote> (streck)." +"Sätt detta alternativ till <quote>-</quote> (bindestreck) för att inaktivera " +"GSSAPI-autentisering." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1873 sssd.conf.5.xml:1904 sssd.conf.5.xml:1942 +#: sssd.conf.5.xml:1870 sssd.conf.5.xml:1901 sssd.conf.5.xml:1939 msgid "" "Note: This option can also be set per-domain which overwrites the value in " "[pam] section. It can also be set for trusted domain which overwrites the " "value in the domain section." msgstr "" -"Observera: denna flagga kan även sättas per domän vilket skriver över värdet " -"i sektionen [pam]. Det kan också sättas för betrodda domäner vilket skriver " -"över värdet i domänsektionen." +"Obs! Detta alternativ kan även anges per domän, vilket åsidosätter värdet i " +"sektionen [pam]. Det kan även anges för en betrodd domän, vilket åsidosätter " +"värdet i domänsektionen." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1881 +#: sssd.conf.5.xml:1878 #, no-wrap msgid "" "pam_gssapi_services = sudo, sudo-i\n" @@ -2770,47 +2767,55 @@ msgstr "" " " #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1879 sssd.conf.5.xml:1994 sssd.conf.5.xml:3836 +#: sssd.conf.5.xml:1876 sssd.conf.5.xml:2023 sssd.conf.5.xml:4042 msgid "Example: <placeholder type=\"programlisting\" id=\"0\"/>" msgstr "Exempel: <placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1885 +#: sssd.conf.5.xml:1882 msgid "Default: - (GSSAPI authentication is disabled)" msgstr "Standard: - (GSSAPI-autentisering är avaktiverat)" -#. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:1890 sssd.conf.5.xml:4278 -msgid "pam_gssapi_check_upn" +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1887 +#, fuzzy +#| msgid "pam_gssapi_check_upn" +msgid "pam_gssapi_check_upn (boolean)" msgstr "pam_gssapi_check_upn" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1893 +#: sssd.conf.5.xml:1890 msgid "" "If True, SSSD will require that the Kerberos user principal that " "successfully authenticated through GSSAPI can be associated with the user " "who is being authenticated. Authentication will fail if the check fails." msgstr "" -"Om sant kommer SSSD kräva att det Kerberos användarhuvudmansnamn som lyckats " -"autentisera via GSSAPI kan associeras med användaren som autentiseras. " -"Autentisering kommer misslyckas om kontrollen misslyckas." +"Om True kräver SSSD att Kerberos-användarhuvudnamnet som autentiserades via " +"GSSAPI kan kopplas till användaren som autentiseras. Autentiseringen " +"misslyckas om kontrollen misslyckas." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1900 +#: sssd.conf.5.xml:1897 +#, fuzzy +#| msgid "" +#| "If False, every user that is able to obtained required service ticket " +#| "will be authenticated." msgid "" -"If False, every user that is able to obtained required service ticket will " +"If False, every user that is able to obtain a required service ticket will " "be authenticated." msgstr "" "Om falskt kommer varje användare som kan få den begärda biljetten att " "autentiseras." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1915 -msgid "pam_gssapi_indicators_map" +#: sssd.conf.5.xml:1912 +#, fuzzy +#| msgid "pam_gssapi_indicators_map" +msgid "pam_gssapi_indicators_map (string)" msgstr "pam_gssapi_indicators_map" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1918 +#: sssd.conf.5.xml:1915 msgid "" "Comma separated list of authentication indicators required to be present in " "a Kerberos ticket to access a PAM service that is allowed to try GSSAPI " @@ -2821,7 +2826,7 @@ msgstr "" "autentisering med modulen pam_sss_gss.so." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1924 +#: sssd.conf.5.xml:1921 msgid "" "Each element of the list can be either an authentication indicator name or a " "pair <quote>service:indicator</quote>. Indicators not prefixed with the PAM " @@ -2834,31 +2839,30 @@ msgid "" "be denied. If the resulting list of indicators for the PAM service is empty, " "the check will not prevent the access." msgstr "" -"Varje element i listan kan antingen vara ett autentiseringsindikatornamn " -"eller ett par <quote>tjänst:indikator</quote>. Indikatorer som inte har PAM-" -"tjänsten som prefix kommer krävas för att komma åt någon PAM-tjänst alls som " -"är konfigurerad att användas med <option>pam_gssapi_services</option>. En " -"resulterande lista över indikatorer per PAM-tjänst kontrolleras sedan mot " -"indikatorer i Kerberos-biljetten under autentisering via pam_sss_gss.so. Om " -"någon indikator från biljetten matchar den resulterande listan av " -"indikatorer för PAM-tjänsten så ges åtkomst. Om ingen av indikatorerna i " -"listan matchar, kommer åtkomst nekas. Om den resulterande listan av " -"indikatorer för PAM-tjänsten är tom kommer kontrollen inte att förhindra " -"åtkomsten." +"Varje element i listan kan vara antingen ett namn på en " +"autentiseringsindikator eller paret <quote>service:indicator</quote>. " +"Indikatorer utan PAM-tjänstens namn som prefix krävs för åtkomst till alla " +"PAM-tjänster som konfigurerats för användning med <option>" +"pam_gssapi_services</option>. Den resulterande listan med indikatorer för " +"varje PAM-tjänst kontrolleras sedan mot indikatorerna i Kerberos-biljetten " +"vid autentisering med pam_sss_gss.so. En indikator från biljetten som " +"matchar den resulterande indikatorlistan för PAM-tjänsten ger åtkomst. Om " +"ingen indikator i listan matchar nekas åtkomst. Om den resulterande " +"indikatorlistan för PAM-tjänsten är tom hindrar kontrollen inte åtkomst." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1937 +#: sssd.conf.5.xml:1934 msgid "" "To disable GSSAPI authentication indicator check, set this option to <quote>-" "</quote> (dash). To disable the check for a specific PAM service, add " "<quote>service:-</quote>." msgstr "" -"För att avaktivera indikatorkontrollen med GSSAPI-autentisering, sätt denna " -"flagga till <quote>-</quote> (streck). För att avaktivera kontrollen för en " -"specifik PAM-tjänst, lägg till <quote>tjänst:-</quote>." +"Sätt detta alternativ till <quote>-</quote> (bindestreck) för att inaktivera " +"kontrollen av GSSAPI-autentiseringsindikatorer. Lägg till <quote>service:-</" +"quote> för att inaktivera kontrollen för en viss PAM-tjänst." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1948 +#: sssd.conf.5.xml:1945 msgid "" "Following authentication indicators are supported by IPA Kerberos " "deployments:" @@ -2866,7 +2870,7 @@ msgstr "" "Följande autentiseringsindikatorer stödjs av IPA-Kerberosinstallationer:" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1951 +#: sssd.conf.5.xml:1948 msgid "" "pkinit -- pre-authentication using X.509 certificates -- whether stored in " "files or on smart cards." @@ -2875,7 +2879,7 @@ msgstr "" "filer eller på smarta kort." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1954 +#: sssd.conf.5.xml:1951 msgid "" "hardened -- SPAKE pre-authentication or any pre-authentication wrapped in a " "FAST channel." @@ -2884,12 +2888,12 @@ msgstr "" "i en FAST-kanal." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1957 +#: sssd.conf.5.xml:1954 msgid "radius -- pre-authentication with the help of a RADIUS server." msgstr "radius — förautentisering med hjälp av en RADIUS-server." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1960 +#: sssd.conf.5.xml:1957 msgid "" "otp -- pre-authentication using integrated two-factor authentication (2FA or " "one-time password, OTP) in IPA." @@ -2898,12 +2902,12 @@ msgstr "" "(2FA eller engångslösenord, OTP) i IPA." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1963 +#: sssd.conf.5.xml:1960 msgid "idp -- pre-authentication using external identity provider." msgstr "idp — förautentisering med extern identitetsleverantör." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1973 +#: sssd.conf.5.xml:1970 #, no-wrap msgid "" "pam_gssapi_indicators_map = sudo:pkinit, sudo-i:pkinit\n" @@ -2913,29 +2917,77 @@ msgstr "" " " #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1968 +#: sssd.conf.5.xml:1965 msgid "" "Example: to require access to SUDO services only for users which obtained " "their Kerberos tickets with a X.509 certificate pre-authentication (PKINIT), " "set <placeholder type=\"programlisting\" id=\"0\"/>" msgstr "" -"Exempel: för att begära åtkomst till SUDO-tjänster endast för användare som " -"fick sina Kerberos-biljetter med förautentisering med ett X.509-certifikat " -"(PKINIT), sätt <placeholder type=\"programlisting\" id=\"0\"/>" +"Exempel: sätt <placeholder type=\"programlisting\" id=\"0\"/> för att endast " +"kräva åtkomst till SUDO-tjänster för användare som hämtat sina Kerberos-" +"biljetter med X.509-certifikatbaserad förautentisering (PKINIT)." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1977 +#: sssd.conf.5.xml:1974 msgid "Default: not set (use of authentication indicators is not required)" msgstr "" -"Standard: inte satt (användning av autentiseringsindikatorer krävs inte)" +"Standard: inte angivet (användning av autentiseringsindikatorer krävs inte)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1979 +#, fuzzy +#| msgid "pam_gssapi_indicators_map" +msgid "pam_gssapi_indicators_apply (string)" +msgstr "pam_gssapi_indicators_map" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1982 +msgid "" +"Comma separated list of triples to assign additional information from the " +"Kerberos ticket, e.g. a SID from the PAC, to authentication indicators." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1988 +#, fuzzy +#| msgid "Currently supported debug levels:" +msgid "Currently supported is:" +msgstr "Felsökningsnivåer som för närvarande stödjs:" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:1991 +msgid "SID:S-1-5-[domain]-[RID]:[authentication indicator]" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> +#: sssd.conf.5.xml:2002 +#, fuzzy, no-wrap +#| msgid "" +#| "pam_gssapi_indicators_map = sudo:pkinit, sudo-i:pkinit\n" +#| " " +msgid "" +"pam_gssapi_indicators_apply = SID:S-1-5-12345-23456-34567-4321:pkinit\n" +" " +msgstr "" +"pam_gssapi_indicators_map = sudo:pkinit, sudo-i:pkinit\n" +" " + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1996 +msgid "" +"Example: To assign a SID, which is e.g. set by Active Directory's " +"Authentication Mechanism Assurance (AMA) if the AD user used a Smartcard for " +"authentication, to the 'pkinit' authentication indicator use: <placeholder " +"type=\"programlisting\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2011 msgid "pam_json_services (string)" msgstr "pam_json_services (sträng)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1985 +#: sssd.conf.5.xml:2014 msgid "" "Comma separated list of PAM services which can handle the JSON protocol for " "selecting authentication mechanisms" @@ -2944,14 +2996,14 @@ msgstr "" "val av autentiseringsmekanismer" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1990 +#: sssd.conf.5.xml:2019 msgid "To disable JSON protocol, set this option to <quote>-</quote> (dash)." msgstr "" "För att inaktivera JSON-protokollet, ställ in detta alternativ till <quote>-" "</quote> (bindestreck)." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1996 +#: sssd.conf.5.xml:2025 #, no-wrap msgid "" "pam_json_services = gdm-switchable-auth\n" @@ -2961,12 +3013,12 @@ msgstr "" " " #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2000 +#: sssd.conf.5.xml:2029 msgid "Default: - (JSON protocol is disabled)" msgstr "Standard: - (JSON-protokollet är inaktiverat)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2003 +#: sssd.conf.5.xml:2032 msgid "" "Note: 2-Factor Authentication (2FA) is not supported. If 2FA is required, do " "not activate the JSON protocol." @@ -2975,19 +3027,37 @@ msgstr "" "inte aktivera JSON-protokollet." #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:2013 +#: sssd.conf.5.xml:2042 msgid "SUDO configuration options" msgstr "SUDO-konfigurationsalternativ" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2015 +#: sssd.conf.5.xml:2044 +#, fuzzy +#| msgid "These options can be used to configure the session recording." msgid "" -"These options can be used to configure the sudo service. The detailed " -"instructions for configuration of <citerefentry> <refentrytitle>sudo</" -"refentrytitle> <manvolnum>8</manvolnum> </citerefentry> to work with " -"<citerefentry> <refentrytitle>sssd</refentrytitle> <manvolnum>8</manvolnum> " -"</citerefentry> are in the manual page <citerefentry> <refentrytitle>sssd-" -"sudo</refentrytitle> <manvolnum>5</manvolnum> </citerefentry>." +"These options can be used to configure the sudo service and should be " +"specified under the <quote>[sudo]</quote> section." +msgstr "Dessa alternativ kan användas för att konfigurera sessionsinspelning." + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:2048 +#, fuzzy +#| msgid "" +#| "These options can be used to configure the sudo service. The detailed " +#| "instructions for configuration of <citerefentry> <refentrytitle>sudo</" +#| "refentrytitle> <manvolnum>8</manvolnum> </citerefentry> to work with " +#| "<citerefentry> <refentrytitle>sssd</refentrytitle> <manvolnum>8</" +#| "manvolnum> </citerefentry> are in the manual page <citerefentry> " +#| "<refentrytitle>sssd-sudo</refentrytitle> <manvolnum>5</manvolnum> </" +#| "citerefentry>." +msgid "" +"The detailed instructions for configuration of <citerefentry> " +"<refentrytitle>sudo</refentrytitle> <manvolnum>8</manvolnum> </citerefentry> " +"to work with <citerefentry> <refentrytitle>sssd</refentrytitle> " +"<manvolnum>8</manvolnum> </citerefentry> are in the manual page " +"<citerefentry> <refentrytitle>sssd-sudo</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry>." msgstr "" "Dessa alternativ kan användas för att konfigurera tjänsten sudo. De " "detaljerade instruktionerna för konfiguration av <citerefentry> " @@ -2998,26 +3068,28 @@ msgstr "" "citerefentry>." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2032 -msgid "sudo_timed (bool)" +#: sssd.conf.5.xml:2064 +#, fuzzy +#| msgid "sudo_timed (bool)" +msgid "sudo_timed (boolean)" msgstr "sudo_timed (bool)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2035 +#: sssd.conf.5.xml:2067 msgid "" "Whether or not to evaluate the sudoNotBefore and sudoNotAfter attributes " "that implement time-dependent sudoers entries." msgstr "" -"Huruvida attributen sudoNotBefore och sudoNotAfter som implementerar " -"tidsberoende sudoers-poster skall evalueras eller inte." +"Om attributen sudoNotBefore och sudoNotAfter som implementerar tidsberoende " +"sudoers-poster ska utvärderas." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2047 +#: sssd.conf.5.xml:2079 msgid "sudo_threshold (integer)" msgstr "sudo_threshold (heltal)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2050 +#: sssd.conf.5.xml:2082 msgid "" "Maximum number of expired rules that can be refreshed at once. If number of " "expired rules is below threshold, those rules are refreshed with " @@ -3025,74 +3097,84 @@ msgid "" "<quote>full refresh</quote> of sudo rules is triggered instead. This " "threshold number also applies to IPA sudo command and command group searches." msgstr "" -"Maximalt antal utgångna regler som kan uppdateras på en gång. Om antalet " -"utgångna regler är under gränsen uppdateras dessa regler med mekanismen " -"<quote>regeluppdatering</quote>. Om gränsen överskrids triggas en <quote>" -"fullständig uppdatering</quote> av sudo-regler istället. Detta gränsvärde " -"gäller även IPA-sudo-kommandon och kommandogruppsökningar." +"Högsta antal utgångna regler som kan uppdateras samtidigt. Om antalet " +"utgångna regler ligger under tröskelvärdet uppdateras reglerna med " +"mekanismen <quote>rules refresh</quote>. Om tröskelvärdet överskrids utlöses " +"i stället en <quote>full refresh</quote> av sudo-regler. Tröskelvärdet " +"gäller även sökningar efter IPA-sudo-kommandon och kommandogrupper." #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:2069 +#: sssd.conf.5.xml:2101 msgid "AUTOFS configuration options" msgstr "AUTOFS-konfigurationsalternativ" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2071 -msgid "These options can be used to configure the autofs service." +#: sssd.conf.5.xml:2103 +#, fuzzy +#| msgid "These options can be used to configure the autofs service." +msgid "" +"These options can be used to configure the autofs service and should be " +"specified under the <quote>[autofs]</quote> section." msgstr "Dessa alternativ kan användas för att konfigurera tjänsten autofs." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2075 +#: sssd.conf.5.xml:2109 msgid "autofs_negative_timeout (integer)" msgstr "autofs_negative_timeout (heltal)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2078 +#: sssd.conf.5.xml:2112 msgid "" "Specifies for how many seconds should the autofs responder negative cache " "hits (that is, queries for invalid map entries, like nonexistent ones) " "before asking the back end again." msgstr "" -"Anger hur många sekunder autofs-respondenten cachar negativa cacheträffar " -"(det vill säga, frågor om ogiltiga mappningsposter, som sådana som inte " -"finns) innan bakänden tillfrågas igen." +"Anger hur många sekunder autofs-svararen ska cachelagra negativa " +"cacheträffar (det vill säga frågor om ogiltiga mapposter, till exempel " +"obefintliga) innan den bakomliggande komponenten frågas igen." #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:2094 +#: sssd.conf.5.xml:2128 msgid "SSH configuration options" msgstr "SSH-konfigurationsalternativ" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2096 -msgid "These options can be used to configure the SSH service." +#: sssd.conf.5.xml:2130 +#, fuzzy +#| msgid "These options can be used to configure the SSH service." +msgid "" +"These options can be used to configure the SSH service and should be " +"specified under the <quote>[ssh]</quote> section." msgstr "Dessa alternativ kan användas för att konfigurera tjänsten SSH." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2100 -msgid "ssh_use_certificate_keys (bool)" +#: sssd.conf.5.xml:2136 +#, fuzzy +#| msgid "ssh_use_certificate_keys (bool)" +msgid "ssh_use_certificate_keys (boolean)" msgstr "ssh_use_certificate_keys (bool)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2103 +#: sssd.conf.5.xml:2139 msgid "" "If set to true the <command>sss_ssh_authorizedkeys</command> will return ssh " "keys derived from the public key of X.509 certificates stored in the user " "entry as well. See <citerefentry> <refentrytitle>sss_ssh_authorizedkeys</" "refentrytitle> <manvolnum>1</manvolnum> </citerefentry> for details." msgstr "" -"Om satt till true kommer <command>sss_ssh_authorizedkeys</command> returnera " -"ssh-nycklar härledda från den publika nyckeln i X.509-certifikat även " -"lagrade i användarposten. Se <citerefentry> <refentrytitle>" +"Om värdet är true returnerar <command>sss_ssh_authorizedkeys</command> även " +"ssh-nycklar härledda från den offentliga nyckeln i X.509-certifikat som " +"lagrats i användarposten. Se <citerefentry> <refentrytitle>" "sss_ssh_authorizedkeys</refentrytitle> <manvolnum>1</manvolnum> </" -"citerefentry> för detaljer." +"citerefentry> för mer information." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2118 +#: sssd.conf.5.xml:2154 msgid "ssh_use_certificate_matching_rules (string)" msgstr "ssh_use_certificate_matching_rules (sträng)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2121 +#: sssd.conf.5.xml:2157 msgid "" "By default the ssh responder will use all available certificate matching " "rules to filter the certificates so that ssh keys are only derived from the " @@ -3100,76 +3182,76 @@ msgid "" "comma separated list of mapping and matching rule names. All other rules " "will be ignored." msgstr "" -"Som standard kommer ssh-respondenten använda alla tillgängliga " -"certifikatmatchningsregler för att filtrera certifikaten så att ssh-nycklar " -"bara härleds från de matchande. Med denna flagga kan de använda reglerna " -"begränsas med en kommaseparerad lista av avbildningar och matchande " -"regelnamn. Alla andra regler kommer ignoreras." +"Som standard använder ssh-svararen alla tillgängliga " +"certifikatmatchningsregler för att filtrera certifikaten, så att ssh-nycklar " +"endast härleds från matchande certifikat. Med detta alternativ kan de " +"använda reglerna begränsas med en kommaseparerad lista med mappnings- och " +"matchningsregelnamn. Alla övriga regler ignoreras." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2130 +#: sssd.conf.5.xml:2166 msgid "" "There are two special key words 'all_rules' and 'no_rules' which will enable " "all or no rules, respectively. The latter means that no certificates will be " "filtered out and ssh keys will be generated from all valid certificates." msgstr "" -"Det finns två speciella nyckelord ”all_rules” och ”no_rules” som kommer " -"aktivera alla respektive inga regler. Det senare betyder att inga certifikat " -"kommer filtreras ut och att ssh-nycklar kommer genereras från alla giltiga " -"certifikat." +"Det finns två särskilda nyckelord, 'all_rules' och 'no_rules', som aktiverar " +"respektive alla eller inga regler. Det senare innebär att inga certifikat " +"filtreras bort och att ssh-nycklar genereras från alla giltiga certifikat." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2137 +#: sssd.conf.5.xml:2173 msgid "" "If no rules are configured using 'all_rules' will enable a default rule " "which enables all certificates suitable for client authentication. This is " "the same behavior as for the PAM responder if certificate authentication is " "enabled." msgstr "" -"Om inga regler är konfigurerade kommer att använda ”all_rules” aktivera en " -"standardregel som aktiverar alla certifikat som passar " -"klientautentiseringen. Detta är samma beteende som för PAM-respondenten om " -"certifikatautentisering är aktiverat." +"Om inga regler är konfigurerade aktiverar användning av 'all_rules' en " +"standardregel som aktiverar alla certifikat som är lämpliga för " +"klientautentisering. Detta är samma beteende som för PAM-svararen när " +"certifikatautentisering är aktiverad." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2144 +#: sssd.conf.5.xml:2180 msgid "" "A non-existing rule name is considered an error. If as a result no rule is " "selected all certificates will be ignored." msgstr "" -"Ett namn på en regel som inte finns anses som ett fel. Om som ett resultat " -"ingen regel blir vald kommer alla certifikat ignoreras." +"Ett namn på en regel som inte finns betraktas som ett fel. Om ingen regel " +"väljs som följd ignoreras alla certifikat." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2149 +#: sssd.conf.5.xml:2185 msgid "" "Default: not set, equivalent to 'all_rules', all found rules or the default " "rule are used" msgstr "" -"Standard: inte satt, likvärdigt med ”all_rules”, alla regler som finns eller " -"standardregeln används" +"Standard: inte angivet, vilket motsvarar 'all_rules'; alla funna regler " +"eller standardregeln används." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2155 +#: sssd.conf.5.xml:2191 msgid "ca_db (string)" msgstr "ca_db (sträng)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2158 +#: sssd.conf.5.xml:2194 msgid "" "Path to a storage of trusted CA certificates. The option is used to validate " "user certificates before deriving public ssh keys from them." msgstr "" -"Sökväg till lagring av betrodda CA-certifikat. Alternativet används för att " -"validera användarcertifikat före publika ssh-nycklar härleds från dem." +"Sökväg till ett lager med betrodda CA-certifikat. Alternativet används för " +"att validera användarcertifikat innan offentliga ssh-nycklar härleds från " +"dem." #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:2178 +#: sssd.conf.5.xml:2214 msgid "PAC responder configuration options" msgstr "PAC-respondentskonfigurationsalternativ" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2180 +#: sssd.conf.5.xml:2216 msgid "" "The PAC responder works together with the authorization data plugin for MIT " "Kerberos sssd_pac_plugin.so and a sub-domain provider. The plugin sends the " @@ -3178,16 +3260,16 @@ msgid "" "joined to and of remote trusted domains from the local domain controller. If " "the PAC is decoded and evaluated some of the following operations are done:" msgstr "" -"PAC-respondenten fungerar tillsammans med insticksmodulen för " -"auktoriseringsdata för MIT Kerberos sssd_pac_plugin.so och en " -"underdomänsleverantör. Insticksmodulen skickar PAC-data under en GSSAPI-" -"autentisering till PAC-respondenten. Underdomänsleverantören samlar domän-" -"SID och ID-intervall för domänen klienten går med i och från betrodda " -"domäner från den lokala domänhanteraren. Om PAC:en är avkodad och beräknad " -"kommer några av följande operationer att göras:" +"PAC-svararen fungerar tillsammans med insticksmodulen för auktoriseringsdata " +"för MIT Kerberos, sssd_pac_plugin.so, och en underdomänsleverantör. " +"Insticksmodulen skickar PAC-data till PAC-svararen under en GSSAPI-" +"autentisering. Underdomänsleverantören samlar in domän-SID och ID-intervall " +"för den domän som klienten är ansluten till samt för fjärrbetrodda domäner " +"från den lokala domänkontrollanten. Om PAC:en avkodas och utvärderas utförs " +"några av följande åtgärder:" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:2189 +#: sssd.conf.5.xml:2225 msgid "" "If the remote user does not exist in the cache, it is created. The UID is " "determined with the help of the SID, trusted domains will have UPGs and the " @@ -3196,14 +3278,14 @@ msgid "" "the system defaults are used, but can be overwritten with the default_shell " "parameter." msgstr "" -"Om fjärranvändaren inte finns i cachen skapas den. AID:t avgörs med hjälp av " -"SID:t, betrodda domäner kommer ha UPG:er och GID:t kommer ha samma värde som " -"AID:t. Hemkatalogen är satt baserat på parametern subdomain_homedir. Skalet " -"kommer vara tomt som standard, d.v.s. systemstandarden används, men kan " -"skrivas över med parametern default_shell." +"Om fjärranvändaren inte finns i cachen skapas den. UID bestäms med hjälp av " +"SID, betrodda domäner får UPG:er och GID får samma värde som UID. " +"Hemkatalogen anges utifrån parametern subdomain_homedir. Skalet är tomt som " +"standard, dvs. systemstandardvärden används, men kan åsidosättas med " +"parametern default_shell." #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:2197 +#: sssd.conf.5.xml:2233 msgid "" "If there are SIDs of groups from domains sssd knows about, the user will be " "added to those groups." @@ -3212,88 +3294,90 @@ msgstr "" "användaren läggas till i dessa grupper." #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2203 -msgid "These options can be used to configure the PAC responder." +#: sssd.conf.5.xml:2239 +#, fuzzy +#| msgid "These options can be used to configure the PAC responder." +msgid "" +"These options can be used to configure the PAC responder and should be " +"specified under the <quote>[pac]</quote> section." msgstr "Dessa alternativ kan användas för att konfigurera PAC-respondenten." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2207 sssd-ifp.5.xml:66 +#: sssd.conf.5.xml:2244 sssd-ifp.5.xml:66 msgid "allowed_uids (string)" msgstr "allowed_uids (sträng)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2210 +#: sssd.conf.5.xml:2247 msgid "" "Specifies the comma-separated list of UID values or user names that are " "allowed to access the PAC responder. User names are resolved to UIDs at " "startup." msgstr "" -"Anger den kommaseparerade listan av AID-värden eller användarnamn som " -"tillåts använda PAC-respondenten. Användarnamn slås upp till AID:er vid " -"uppstart." +"Anger den kommaseparerade listan med UID-värden eller användarnamn som får " +"komma åt PAC-svararen. Användarnamn löses till UID:er vid start." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2216 +#: sssd.conf.5.xml:2253 msgid "" "Default: 0, &sssd_user_name; (only root and SSSD service users are allowed " "to access the PAC responder)" msgstr "" -"Standard: 0, &sssd_user_name; (endast root och SSSD:s tjänsteanvändaren " -"tillåts komma åt PAC-respondenten)" +"Standard: 0, &sssd_user_name; (endast root och SSSD-tjänstanvändaren får " +"komma åt PAC-svararen)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2220 +#: sssd.conf.5.xml:2257 msgid "Default: 0 (only the root user is allowed to access the PAC responder)" msgstr "Standard: 0 (endast root-användaren tillåts komma åt PAC-respondenten)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2224 +#: sssd.conf.5.xml:2261 msgid "" "Please note that defaults will be overwritten with this option. If you still " "want to allow the root and/or '&sssd_user_name;' user to access the PAC " "responder, which would be the typical case, you have to add those to the " "list of allowed UIDs explicitly." msgstr "" -"Observera att standardvärden kommer det att skrivas över av detta " -"alternativ. Om du fortfarande vill tillåta root- och/eller " -"”&sssd_user_name;”-användaren att komma åt PAC-respondenten, vilket är det " -"typiska fallet, måste man uttryckligen lägga till dessa i listan av tillåtna " -"AID:er." +"Observera att standardvärdena åsidosätts med detta alternativ. Om du ändå " +"vill tillåta att root och/eller användaren '&sssd_user_name;' kommer åt PAC-" +"svararen, vilket är det vanliga fallet, måste du uttryckligen lägga till dem " +"i listan med tillåtna UID:er." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2231 +#: sssd.conf.5.xml:2268 msgid "" "Please note that although the UID 0 is used as the default it will be " "overwritten with this option. If you still want to allow the root user to " "access the PAC responder, which would be the typical case, you have to add 0 " "to the list of allowed UIDs as well." msgstr "" -"Observera att även om AID 0 används som standard kommer det att skrivas över " -"av detta alternativ. Om du fortfarande vill tillåta root-användaren att " -"komma åt PAC-respondenten, vilket man typiskt vill, måste du lägga till även " -"0 i listan av tillåtna AID:er." +"Observera att även om UID 0 används som standard åsidosätts det med detta " +"alternativ. Om du ändå vill tillåta att root-användaren kommer åt PAC-" +"svararen, vilket är det vanliga fallet, måste du även lägga till 0 i listan " +"med tillåtna UID:er." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2240 +#: sssd.conf.5.xml:2277 msgid "pac_lifetime (integer)" msgstr "pac_lifetime (heltal)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2243 +#: sssd.conf.5.xml:2280 msgid "" "Lifetime of the PAC entry in seconds. As long as the PAC is valid the PAC " "data can be used to determine the group memberships of a user." msgstr "" -"Livslängd på PAC-posterna i sekunder. Så länge som PAC:en är giltig kan PAC-" -"datan användas för att avgöra gruppmedlemskap för en användare." +"Livslängd för PAC-posten i sekunder. Så länge PAC:en är giltig kan PAC-data " +"användas för att fastställa en användares gruppmedlemskap." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2253 +#: sssd.conf.5.xml:2290 msgid "pac_check (string)" msgstr "pac_check (sträng)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2256 +#: sssd.conf.5.xml:2293 msgid "" "Apply additional checks on the PAC of the Kerberos ticket which is available " "in Active Directory and FreeIPA domains, if configured. Please note that " @@ -3302,15 +3386,15 @@ msgid "" "IPA and AD provider. If krb5_validate is set to 'False' the PAC checks will " "be skipped." msgstr "" -"Använd ytterligare kontroller på PAC:en i Kerberosbiljetten som är " -"tillgängliga i Active Directory och FreeIPA-domäner, om konfigurerat. " -"Observera att validering av Kerberosbiljetten måste aktiveras för att kunna " -"kontrollera PAC:en, d.v.s. alternativet krb5_validate måste vara satt till ”" -"True” vilket är standardvärdet för leverantörerna IPA och AD. Om " -"krb5_validate är satt till ”False” kommer PAC-kontrollerna hoppas över." +"Utför ytterligare kontroller av PAC:en i Kerberosbiljetten, som finns " +"tillgänglig i Active Directory- och FreeIPA-domäner, om den är konfigurerad. " +"Observera att Kerberosbiljettvalidering måste vara aktiverad för att PAC:en " +"ska kunna kontrolleras, dvs. alternativet krb5_validate måste vara satt till " +"'True', vilket är standard för IPA- och AD-leverantörerna. Om krb5_validate " +"är satt till 'False' hoppas PAC-kontrollerna över." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2266 +#: sssd.conf.5.xml:2303 msgid "" "Please note that the checks listed below only apply to PACs issued by Active " "Directory or recent versions of FreeIPA. PACs issued e.g. by a plain MIT " @@ -3322,12 +3406,12 @@ msgstr "" "krävs för att utföra kontrollerna." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2277 +#: sssd.conf.5.xml:2314 msgid "no_check" msgstr "no_check" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2279 +#: sssd.conf.5.xml:2316 msgid "" "The PAC must not be present and even if it is present no additional checks " "will be done." @@ -3336,12 +3420,12 @@ msgstr "" "kontroller att göras." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2285 +#: sssd.conf.5.xml:2322 msgid "pac_present" msgstr "pac_present" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2287 +#: sssd.conf.5.xml:2324 msgid "" "The PAC must be present in the service ticket which SSSD will request with " "the help of the user's TGT. If the PAC is not available the authentication " @@ -3352,26 +3436,26 @@ msgstr "" "misslyckas." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2295 +#: sssd.conf.5.xml:2332 msgid "check_upn" msgstr "check_upn" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2297 +#: sssd.conf.5.xml:2334 msgid "" "If the PAC is present check if the user principal name (UPN) information is " "consistent." msgstr "" -"Om PAC:en finns kontrollera om informationen om användarens huvudmannanamn " -"(UPN) är konsistent." +"Om PAC:en finns, kontrollera att informationen om användarhuvudnamnet (UPN) " +"är konsekvent." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2303 +#: sssd.conf.5.xml:2340 msgid "check_upn_allow_missing" msgstr "check_upn_allow_missing" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2305 +#: sssd.conf.5.xml:2342 msgid "" "This option should be used together with 'check_upn' and handles the case " "where a UPN is set on the server-side but is not read by SSSD. The typical " @@ -3381,16 +3465,16 @@ msgid "" "time and FreeIPA can handle enterprise principals just fine and there is no " "need anymore to set 'ldap_user_principal'." msgstr "" -"Detta alternativ skall användas tillsammans med ”check_upn” och haterar " -"fallet då en UPN är satt på serversidan men inte läses av SSSD. Det typiska " -"exemplet är en FreeIPA-domän där ”ldap_user_principal” är satt till ett " -"attributnamn som inte finns. Detta gjordes typiskt för att gå runt problem i " -"hanteringen av företagshuvudmän. Men detta är rättat sedan ganska lång tid " -"tillbaka och FreeIPA kan hantera företagshuvudmän utan problem och det finns " -"inte längre någon anledning att sätta ”ldap_user_principal”." +"Alternativet ska användas tillsammans med 'check_upn' och hanterar fallet " +"där en UPN är angiven på serversidan men inte läses av SSSD. Ett typiskt " +"exempel är en FreeIPA-domän där 'ldap_user_principal' är angivet till ett " +"attributnamn som inte finns. Detta gjordes ofta för att kringgå problem vid " +"hantering av enterprise-huvudmän. Problemet har dock varit löst länge, och " +"FreeIPA kan hantera enterprise-huvudmän utan problem. Det finns inte längre " +"någon anledning att ange 'ldap_user_principal'." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2317 +#: sssd.conf.5.xml:2354 msgid "" "Currently this option is set by default to avoid regressions in such " "environments. A log message will be added to the system log and SSSD's debug " @@ -3399,31 +3483,31 @@ msgid "" "can be removed. If this is not possible, removing 'check_upn' will skip the " "test and avoid the log message." msgstr "" -"För närvarande är detta alternativ satt som standard för att undvika " -"regressioner i sådana miljöer. Ett loggmeddelande kommer läggas till i " -"systemloggen och SSSD:s felsökningslogg ifall en UPN finns i PAC:en men " -"inte i SSSD:s cache. För att undvika detta loggmeddelande vore det bäst att " -"avgöra om alternativet ”ldap_user_principal” kan tas bort. Om detta inte är " -"möjligt kommer att ta bort ”check_upn” hoppa över testen och undvika " -"loggmeddelandet." +"För närvarande är detta alternativ standard för att undvika regressioner i " +"sådana miljöer. Ett loggmeddelande läggs till i systemloggen och SSSD:s " +"felsökningslogg om en UPN finns i PAC:en men inte i SSSD:s cache. För att " +"undvika loggmeddelandet är det bäst att utvärdera om alternativet " +"'ldap_user_principal' kan tas bort. Om det inte är möjligt hoppar " +"borttagning av 'check_upn' över testet och undviker loggmeddelandet." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2331 +#: sssd.conf.5.xml:2368 msgid "upn_dns_info_present" msgstr "upn_dns_info_present" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2333 +#: sssd.conf.5.xml:2370 msgid "The PAC must contain the UPN-DNS-INFO buffer, implies 'check_upn'." -msgstr "PAC:en måste innehålla bufferten UPN-DNS-INFO, implicerar ”check_upn”." +msgstr "" +"PAC:en måste innehålla bufferten UPN-DNS-INFO, vilket innebär 'check_upn'." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2338 +#: sssd.conf.5.xml:2375 msgid "check_upn_dns_info_ex" msgstr "check_upn_dns_info_ex" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2340 +#: sssd.conf.5.xml:2377 msgid "" "If the PAC is present and the extension to the UPN-DNS-INFO buffer is " "available check if the information in the extension is consistent." @@ -3432,21 +3516,21 @@ msgstr "" "kontrollera om informationen i utökningen är konsistent." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2347 +#: sssd.conf.5.xml:2384 msgid "upn_dns_info_ex_present" msgstr "upn_dns_info_ex_present" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2349 +#: sssd.conf.5.xml:2386 msgid "" "The PAC must contain the extension of the UPN-DNS-INFO buffer, implies " "'check_upn_dns_info_ex', 'upn_dns_info_present' and 'check_upn'." msgstr "" -"PAC:en måste innehålla utökningen av bufferten UPN-DNS-INFO, implicerar ”" -"check_upn_dns_info_ex”, ”upn_dns_info_present” och ”check_upn”." +"PAC:en måste innehålla utökningen av bufferten UPN-DNS-INFO, vilket innebär " +"'check_upn_dns_info_ex', 'upn_dns_info_present' och 'check_upn'." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2273 +#: sssd.conf.5.xml:2310 msgid "" "The following options can be used alone or in a comma-separated list: " "<placeholder type=\"variablelist\" id=\"0\"/>" @@ -3455,21 +3539,21 @@ msgstr "" "<placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2359 +#: sssd.conf.5.xml:2396 msgid "" "Default: no_check (AD and IPA provider 'check_upn, check_upn_allow_missing, " "check_upn_dns_info_ex')" msgstr "" -"Standard: no_check (AD- och IPA-leverantörerna ”check_upn, " -"check_upn_allow_missing, check_upn_dns_info_ex”)" +"Standard: no_check (AD- och IPA-leverantörerna 'check_upn, " +"check_upn_allow_missing, check_upn_dns_info_ex')" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:2368 +#: sssd.conf.5.xml:2405 msgid "Session recording configuration options" msgstr "Konfigurationsalternativ för inspelning av sessioner" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2370 +#: sssd.conf.5.xml:2407 msgid "" "Session recording works in conjunction with <citerefentry> " "<refentrytitle>tlog-rec-session</refentrytitle> <manvolnum>8</manvolnum> </" @@ -3477,41 +3561,53 @@ msgid "" "they log in on a text terminal. See also <citerefentry> <refentrytitle>sssd-" "session-recording</refentrytitle> <manvolnum>5</manvolnum> </citerefentry>." msgstr "" -"Inspelning av sessioner fungerar tillsammans med <citerefentry> " -"<refentrytitle>tlog-rec-session</refentrytitle> <manvolnum>8</manvolnum> </" -"citerefentry>, en del av paketet tlog, för att logga vad användaren ser och " -"skriver när de är inloggade på en textterminal. Se även <citerefentry> " -"<refentrytitle>sssd-session-recording</refentrytitle> <manvolnum>5</" -"manvolnum> </citerefentry>." +"Sessionsinspelning fungerar tillsammans med <citerefentry> <refentrytitle>" +"tlog-rec-session</refentrytitle> <manvolnum>8</manvolnum> </citerefentry>, " +"en del av paketet tlog, för att logga vad användare ser och skriver när de " +"loggar in på en textterminal. Se även <citerefentry> <refentrytitle>sssd-" +"session-recording</refentrytitle> <manvolnum>5</manvolnum> </citerefentry>." #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2383 -msgid "These options can be used to configure session recording." +#: sssd.conf.5.xml:2420 +#, fuzzy +#| msgid "These options can be used to configure the session recording." +msgid "" +"These options can be used to configure session recording and should be " +"specified under the <quote>[session_recording]</quote> section." +msgstr "Dessa alternativ kan användas för att konfigurera sessionsinspelning." + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:2425 +msgid "" +"Note: Unlike other sections, the <quote>[session_recording]</quote> section " +"ignores <replaceable>debug*</replaceable> options and suitable " +"<replaceable>debug*</replaceable> options must be set in <quote>[pam]</" +"quote>, <quote>[nss]</quote> and <quote>[domain/<replaceable>NAME</" +"replaceable>]</quote> sections." msgstr "" -"Dessa alternativ kan användas för att konfigurera inspelning av sessioner." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2387 sssd-session-recording.5.xml:64 +#: sssd.conf.5.xml:2433 sssd-session-recording.5.xml:64 msgid "scope (string)" msgstr "scope (sträng)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2394 sssd-session-recording.5.xml:71 +#: sssd.conf.5.xml:2440 sssd-session-recording.5.xml:71 msgid "\"none\"" -msgstr "”none”" +msgstr "\"none\"" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2397 sssd-session-recording.5.xml:74 +#: sssd.conf.5.xml:2443 sssd-session-recording.5.xml:74 msgid "No users are recorded." msgstr "Inga användare spelas in." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2402 sssd-session-recording.5.xml:79 +#: sssd.conf.5.xml:2448 sssd-session-recording.5.xml:79 msgid "\"some\"" -msgstr "”some”" +msgstr "\"some\"" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2405 sssd-session-recording.5.xml:82 +#: sssd.conf.5.xml:2451 sssd-session-recording.5.xml:82 msgid "" "Users/groups specified by <replaceable>users</replaceable> and " "<replaceable>groups</replaceable> options are recorded." @@ -3520,109 +3616,109 @@ msgstr "" "och <replaceable>groups</replaceable> spelas in." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2414 sssd-session-recording.5.xml:91 +#: sssd.conf.5.xml:2460 sssd-session-recording.5.xml:91 msgid "\"all\"" -msgstr "”all”" +msgstr "\"all\"" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2417 sssd-session-recording.5.xml:94 +#: sssd.conf.5.xml:2463 sssd-session-recording.5.xml:94 msgid "All users are recorded." msgstr "Alla användare spelas in." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2390 sssd-session-recording.5.xml:67 +#: sssd.conf.5.xml:2436 sssd-session-recording.5.xml:67 msgid "" "One of the following strings specifying the scope of session recording: " "<placeholder type=\"variablelist\" id=\"0\"/>" msgstr "" -"En av följande strängar anger utsträckningen för inspelning av sessioner: " +"En av följande strängar som anger omfattningen av sessionsinspelningen: " "<placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2424 sssd-session-recording.5.xml:101 +#: sssd.conf.5.xml:2470 sssd-session-recording.5.xml:101 msgid "Default: \"none\"" -msgstr "Standard: ”none”" +msgstr "Standard: \"none\"" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2429 sssd-session-recording.5.xml:106 +#: sssd.conf.5.xml:2475 sssd-session-recording.5.xml:106 msgid "users (string)" msgstr "users (sträng)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2432 sssd-session-recording.5.xml:109 +#: sssd.conf.5.xml:2478 sssd-session-recording.5.xml:109 msgid "" "A comma-separated list of users which should have session recording enabled. " "Matches user names as returned by NSS. I.e. after the possible space " "replacement, case changes, etc." msgstr "" -"En kommaseparerad lista över användare vilka skall ha inspelning av " -"sessioner aktiverat. Matchar användarnamn som de returneras av NSS. D.v.s. " -"efter eventuellt utbyte av mellanslag, ändring av skiftläge, etc." +"En kommaseparerad lista med användare som ska ha sessionsinspelning " +"aktiverad. Matchar användarnamn såsom de returneras av NSS, dvs. efter " +"eventuellt mellanslagsbyte, ändring av skiftläge osv." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2438 sssd-session-recording.5.xml:115 +#: sssd.conf.5.xml:2484 sssd-session-recording.5.xml:115 msgid "Default: Empty. Matches no users." msgstr "Standard: Tomt. Matchar inte några användare." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2443 sssd-session-recording.5.xml:120 +#: sssd.conf.5.xml:2489 sssd-session-recording.5.xml:120 msgid "groups (string)" msgstr "groups (sträng)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2446 sssd-session-recording.5.xml:123 +#: sssd.conf.5.xml:2492 sssd-session-recording.5.xml:123 msgid "" "A comma-separated list of groups, members of which should have session " "recording enabled. Matches group names as returned by NSS. I.e. after the " "possible space replacement, case changes, etc." msgstr "" -"En kommaseparerad lista över gruppmedlemmar vilka skall ha inspelning av " -"sessioner aktiverat. Matchar gruppnamn som de returneras av NSS. D.v.s. " -"efter eventuellt utbyte av mellanslag, ändring av skiftläge, etc." +"En kommaseparerad lista med grupper vars medlemmar ska ha sessionsinspelning " +"aktiverad. Matchar gruppnamn såsom de returneras av NSS, dvs. efter " +"eventuellt mellanslagsbyte, ändring av skiftläge osv." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2452 sssd.conf.5.xml:2484 sssd-session-recording.5.xml:129 +#: sssd.conf.5.xml:2498 sssd.conf.5.xml:2530 sssd-session-recording.5.xml:129 #: sssd-session-recording.5.xml:161 msgid "" "NOTE: using this option (having it set to anything) has a considerable " "performance cost, because each uncached request for a user requires " "retrieving and matching the groups the user is member of." msgstr "" -"OBSERVERA: att använda detta alternativ (ha det satt till något) har en " -"betydande prestandakostnad, ty varje begäran som inte cachas för en " -"användare måste hämtas och matchas mot grupperna användaren är en medlem i." +"OBS! Att använda detta alternativ (att sätta det till något värde) medför en " +"betydande prestandakostnad, eftersom varje ocachad begäran om en användare " +"kräver hämtning och matchning av de grupper användaren är medlem i." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2459 sssd-session-recording.5.xml:136 +#: sssd.conf.5.xml:2505 sssd-session-recording.5.xml:136 msgid "Default: Empty. Matches no groups." msgstr "Standard: Tom. Matchar inga grupper." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2464 sssd-session-recording.5.xml:141 +#: sssd.conf.5.xml:2510 sssd-session-recording.5.xml:141 msgid "exclude_users (string)" msgstr "exclude_users (sträng)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2467 sssd-session-recording.5.xml:144 +#: sssd.conf.5.xml:2513 sssd-session-recording.5.xml:144 msgid "" "A comma-separated list of users to be excluded from recording, only " "applicable with 'scope=all'." msgstr "" -"En kommaseparerad lista av användare att undanta från inspelning, endast " -"tillämpligt med ”scope=all”." +"En kommaseparerad lista med användare som ska undantas från inspelning, " +"endast tillämpligt med 'scope=all'." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2471 sssd-session-recording.5.xml:148 +#: sssd.conf.5.xml:2517 sssd-session-recording.5.xml:148 msgid "Default: Empty. No users excluded." msgstr "Standard: Tomt. Inga användare uteslutna." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2476 sssd-session-recording.5.xml:153 +#: sssd.conf.5.xml:2522 sssd-session-recording.5.xml:153 msgid "exclude_groups (string)" msgstr "exclude_groups (sträng)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2479 sssd-session-recording.5.xml:156 +#: sssd.conf.5.xml:2525 sssd-session-recording.5.xml:156 msgid "" "A comma-separated list of groups, members of which should be excluded from " "recording. Only applicable with 'scope=all'." @@ -3631,23 +3727,24 @@ msgstr "" "inspelning. Endast tillämpligt med ”scope=all”." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2491 sssd-session-recording.5.xml:168 +#: sssd.conf.5.xml:2537 sssd-session-recording.5.xml:168 msgid "Default: Empty. No groups excluded." msgstr "Standard: Tom. Inga grupper uteslutna." #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:2501 +#: sssd.conf.5.xml:2547 msgid "DOMAIN SECTIONS" msgstr "DOMÄNSEKTIONER" -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry><para> -#: sssd.conf.5.xml:2508 sssd.conf.5.xml:3964 sssd.conf.5.xml:3965 -#: sssd.conf.5.xml:3968 -msgid "enabled" -msgstr "aktiverat" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2554 +#, fuzzy +#| msgid "ad_enable_gc (boolean)" +msgid "enabled (boolean)" +msgstr "ad_enable_gc (boolean)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2511 +#: sssd.conf.5.xml:2557 msgid "" "Explicitly enable or disable the domain. If <quote>true</quote>, the domain " "is always <quote>enabled</quote>. If <quote>false</quote>, the domain is " @@ -3655,19 +3752,19 @@ msgid "" "enabled only if it is listed in the domains option in the <quote>[sssd]</" "quote> section." msgstr "" -"Aktivera eller avaktivera uttryckligen domänen. Om <quote>true</quote> är " -"domänen alltid <quote>aktiverad</quote>. Om <quote>false</quote> är domänen " -"alltid <quote>avaktiverad</quote>. Om denna flagga inte är satt är domänen " -"aktiverad endast om den är listad i domänflaggan i sektionen <quote>[sssd]</" -"quote>." +"Aktivera eller inaktivera domänen uttryckligen. Om <quote>true</quote> är " +"domänen alltid <quote>enabled</quote>. Om <quote>false</quote> är domänen " +"alltid <quote>disabled</quote>. Om detta alternativ inte är angivet " +"aktiveras domänen endast om den anges i alternativet domains i sektionen " +"<quote>[sssd]</quote>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2523 +#: sssd.conf.5.xml:2569 msgid "domain_type (string)" msgstr "domain_type (sträng)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2526 +#: sssd.conf.5.xml:2572 msgid "" "Specifies whether the domain is meant to be used by POSIX-aware clients such " "as the Name Service Switch or by applications that do not need POSIX data to " @@ -3680,7 +3777,7 @@ msgstr "" "operativsystemets gränssnitt och verktyg." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2534 +#: sssd.conf.5.xml:2580 msgid "" "Allowed values for this option are <quote>posix</quote> and " "<quote>application</quote>." @@ -3689,7 +3786,7 @@ msgstr "" "application</quote>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2538 +#: sssd.conf.5.xml:2584 msgid "" "POSIX domains are reachable by all services. Application domains are only " "reachable from the InfoPipe responder (see <citerefentry> " @@ -3702,7 +3799,7 @@ msgstr "" "respondenten." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2546 +#: sssd.conf.5.xml:2592 msgid "" "NOTE: The application domains are currently well tested with " "<quote>id_provider=ldap</quote> only." @@ -3711,48 +3808,48 @@ msgstr "" "id_provider=ldap</quote>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2550 +#: sssd.conf.5.xml:2596 msgid "" "For an easy way to configure a non-POSIX domains, please see the " "<quote>Application domains</quote> section." msgstr "" -"För ett lätt sätt att konfigurera en icke-POSIX-DOMÄN, se avsnittet <quote>" -"Programdomäner</quote>." +"Se avsnittet <quote>Application domains</quote> för ett enkelt sätt att " +"konfigurera en icke-POSIX-domän." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2554 +#: sssd.conf.5.xml:2600 msgid "Default: posix" msgstr "Standard: posix" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2560 +#: sssd.conf.5.xml:2606 msgid "min_id,max_id (integer)" msgstr "min_id,max_id (heltal)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2563 +#: sssd.conf.5.xml:2609 msgid "" "UID and GID limits for the domain. If a domain contains an entry that is " "outside these limits, it is ignored." msgstr "" -"AID- och GID-gränser för domänen. Om en domän innehåller en post som ligger " -"utanför dessa gränser ignoreras den." +"UID- och GID-gränser för domänen. Om en domän innehåller en post utanför " +"dessa gränser ignoreras den." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2568 +#: sssd.conf.5.xml:2614 msgid "" "For users, this affects the primary GID limit. The user will not be returned " "to NSS if either the UID or the primary GID is outside the range. For non-" "primary group memberships, those that are in range will be reported as " "expected." msgstr "" -"För användare påverkar detta gränsen för det primära GID:t. Användaren " -"kommer inte returneras till NSS om antingen AID:t eller det primära GID:t " -"ligger utanför intervallet. För icke primära gruppmedlemskap kommer de som " -"ligger i intervallet rapporteras som förväntat." +"För användare påverkar detta gränsen för primärt GID. Användaren returneras " +"inte till NSS om antingen UID eller primärt GID ligger utanför intervallet. " +"För sekundära gruppmedlemskap rapporteras de som ligger inom intervallet som " +"förväntat." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2575 +#: sssd.conf.5.xml:2621 msgid "" "These ID limits affect even saving entries to cache, not only returning them " "by name or ID." @@ -3761,45 +3858,47 @@ msgstr "" "när de returneras via namn eller ID." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2579 +#: sssd.conf.5.xml:2625 msgid "Default: 1 for min_id, 0 (no limit) for max_id" msgstr "Standard: 1 för min_id, 0 (ingen gräns) för max_id" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2585 -msgid "enumerate (bool)" +#: sssd.conf.5.xml:2631 +#, fuzzy +#| msgid "enumerate (bool)" +msgid "enumerate (boolean)" msgstr "enumerate (bool)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2588 +#: sssd.conf.5.xml:2634 msgid "" "Determines if a domain can be enumerated, that is, whether the domain can " "list all the users and group it contains. Note that it is not required to " "enable enumeration in order for secondary groups to be displayed. This " "parameter can have one of the following values:" msgstr "" -"Bestämmer om en domän kan räknas upp, det vill säga, huruvida domänen kan " -"lista alla användare och grupper den innehåller. Observera att det inte är " -"nödvändigt att aktivera uppräkning för att sekundära grupper skall visas. " -"Denna parameter kan ha ett av följande värden:" +"Avgör om en domän kan räknas upp, det vill säga om domänen kan lista alla " +"användare och grupper som den innehåller. Observera att uppräkning inte " +"behöver aktiveras för att sekundära grupper ska visas. Parametern kan ha ett " +"av följande värden:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2596 +#: sssd.conf.5.xml:2642 msgid "TRUE = Users and groups are enumerated" msgstr "TRUE = Användare och grupper räknas upp" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2599 +#: sssd.conf.5.xml:2645 msgid "FALSE = No enumerations for this domain" msgstr "FALSE = Inga uppräkningar för denna domän" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2602 sssd.conf.5.xml:2867 sssd.conf.5.xml:3044 +#: sssd.conf.5.xml:2648 sssd.conf.5.xml:2992 sssd.conf.5.xml:3174 msgid "Default: FALSE" msgstr "Standard: FALSE" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2605 +#: sssd.conf.5.xml:2651 msgid "" "Enumerating a domain requires SSSD to download and store ALL user and group " "entries from the remote server." @@ -3808,7 +3907,7 @@ msgstr "" "grupposter från fjärrservern." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2610 +#: sssd.conf.5.xml:2656 msgid "" "Feature is only supported for domains with id_provider = ldap or id_provider " "= proxy." @@ -3817,7 +3916,7 @@ msgstr "" "= proxy." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2614 +#: sssd.conf.5.xml:2660 msgid "" "Note: Enabling enumeration has a severe performance impact on SSSD while " "enumeration is running. It may take up to several minutes after SSSD startup " @@ -3829,18 +3928,18 @@ msgid "" "quote> process becoming unresponsive or even restarted by the internal " "watchdog." msgstr "" -"Obs: att aktivera uppräkning har en kraftig påverkan på prestandan hos SSSD " -"medan uppräkningen pågår. Det kan ta upp till flera minuter efter att SSSD " -"startat upp för att helt fullborda uppräkningar. Under denna tid kommer " -"enskilda begäranden om information att gå direkt till LDAP, fast det kan " -"vara långsamt på grund av den tunga bearbetningen av uppräkningen. Att " -"spara ett stort antal poster i cachen efter att uppräkningen är klar kan " -"också vara CPU-intensivt eftersom medlemskap måste beräknas om. Detta kan " -"leda till att processen <quote>sssd_be</quote> blir oåtkomlig eller till och " -"med startas om av den interna vakthunden." +"Obs! Att aktivera uppräkning påverkar SSSD:s prestanda kraftigt medan " +"uppräkningen pågår. Det kan ta flera minuter efter start av SSSD innan " +"uppräkningen är helt klar. Under denna tid går enskilda " +"informationsbegäranden direkt till LDAP, vilket kan vara långsamt på grund " +"av den tunga uppräkningsbearbetningen. Att spara ett stort antal poster i " +"cachen när uppräkningen har slutförts kan också vara CPU-intensivt eftersom " +"medlemskap måste beräknas om. Detta kan leda till att processen <quote>" +"sssd_be</quote> slutar svara eller till och med startas om av den interna " +"vakthunden." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2629 +#: sssd.conf.5.xml:2675 msgid "" "While the first enumeration is running, requests for the complete user or " "group lists may return no results until it completes." @@ -3849,20 +3948,20 @@ msgstr "" "användar- eller grupplistan returnera utan resultat tills den är färdig." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2634 +#: sssd.conf.5.xml:2680 msgid "" "Further, enabling enumeration may increase the time necessary to detect " "network disconnection, as longer timeouts are required to ensure that " "enumeration lookups are completed successfully. For more information, refer " "to the man pages for the specific id_provider in use." msgstr "" -"Vidare, att aktivera uppräkning kan öka tiden som behövs för att upptäcka " -"urkoppling av nätverk, eftersom längre tidsgränser behövs för att " -"säkerställa att uppräkningsuppslagningarna blir klara som de skall. För mer " -"information, se manualsidorna för den specifika id-leverantören som används." +"Att aktivera uppräkning kan dessutom öka tiden det tar att upptäcka " +"frånkoppling från nätverket, eftersom längre tidsgränser krävs för att " +"säkerställa att uppräkningsuppslagningar slutförs. Mer information finns i " +"manualsidorna för den specifika id_provider som används." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2642 +#: sssd.conf.5.xml:2688 msgid "" "For the reasons cited above, enabling enumeration is not recommended, " "especially in large environments." @@ -3871,33 +3970,33 @@ msgstr "" "stora miljöer." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2647 +#: sssd.conf.5.xml:2693 msgid "" "Note: the proxy provider is tested with open source modules like " "'libnss_files' and 'libnss_ldap'. 3rd party modules must follow the " "documented behavior of nss modules to be used in this configuration." msgstr "" -"Observera: proxyleverantören testas med moduler i öppen källkod som ”" -"libnss_file” och ”libnss_ldap”. 3:e-partsmoduler måste följa det " -"dokumenterade beteendet hos nss-moduler för att användas i denna " +"Obs! Proxyleverantören har testats med öppen källkodsmoduler som " +"'libnss_files' och 'libnss_ldap'. Tredjepartsmoduler måste följa det " +"dokumenterade beteendet för nss-moduler för att kunna användas i denna " "konfiguration." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2656 +#: sssd.conf.5.xml:2702 msgid "entry_cache_timeout (integer)" msgstr "entry_cache_timeout (heltal)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2659 +#: sssd.conf.5.xml:2705 msgid "" "How many seconds should nss_sss consider entries valid before asking the " "backend again" msgstr "" -"Hur många sekunder nss_sss skall anse poster giltiga före den frågar " -"bakänden igen" +"Hur många sekunder nss_sss ska betrakta poster som giltiga innan den " +"bakomliggande komponenten frågas igen" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2663 +#: sssd.conf.5.xml:2709 msgid "" "The cache expiration timestamps are stored as attributes of individual " "objects in the cache. Therefore, changing the cache timeout only has effect " @@ -3906,168 +4005,313 @@ msgid "" "citerefentry> tool in order to force refresh of entries that have already " "been cached." msgstr "" -"Tidsstämplarna för när cachen går ut lagras som attribut på de enskilda " -"objekten i cachen. Därför har ändringar av tidsgränsen för cachen endast " -"effekt för nyligen tillagda eller utgångna poster. Du skall köra verktyget " -"<citerefentry> <refentrytitle>sss_cache</refentrytitle> <manvolnum>8</" -"manvolnum> </citerefentry> för att tvinga fram en uppdatering av poster som " -"redan har cachats." +"Tidsstämplarna för cacheutgång lagras som attribut för enskilda objekt i " +"cachen. Därför påverkar en ändring av cachetidsgränsen endast nyligen " +"tillagda eller utgångna poster. Kör verktyget <citerefentry> <refentrytitle>" +"sss_cache</refentrytitle> <manvolnum>8</manvolnum> </citerefentry> för att " +"tvinga fram uppdatering av poster som redan har cachelagrats." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2676 +#: sssd.conf.5.xml:2722 msgid "Default: 5400" msgstr "Standard: 5400" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2682 +#: sssd.conf.5.xml:2728 msgid "entry_cache_user_timeout (integer)" msgstr "entry_cache_user_timeout (heltal)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2685 +#: sssd.conf.5.xml:2731 msgid "" "How many seconds should nss_sss consider user entries valid before asking " "the backend again" msgstr "" -"Hur många sekunder nss_sss skall anse användarposter giltiga före den frågar " -"bakänden igen" +"Hur många sekunder nss_sss ska betrakta användarposter som giltiga innan den " +"bakomliggande komponenten frågas igen" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2689 sssd.conf.5.xml:2702 sssd.conf.5.xml:2715 -#: sssd.conf.5.xml:2728 sssd.conf.5.xml:2742 sssd.conf.5.xml:2755 -#: sssd.conf.5.xml:2769 sssd.conf.5.xml:2783 sssd.conf.5.xml:2796 +#: sssd.conf.5.xml:2735 sssd.conf.5.xml:2748 sssd.conf.5.xml:2761 +#: sssd.conf.5.xml:2774 sssd.conf.5.xml:2788 sssd.conf.5.xml:2801 +#: sssd.conf.5.xml:2815 sssd.conf.5.xml:2829 msgid "Default: entry_cache_timeout" msgstr "Standard: entry_cache_timeout" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2695 +#: sssd.conf.5.xml:2741 msgid "entry_cache_group_timeout (integer)" msgstr "entry_cache_group_timeout (heltal)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2698 +#: sssd.conf.5.xml:2744 msgid "" "How many seconds should nss_sss consider group entries valid before asking " "the backend again" msgstr "" -"Hur många sekunder nss_sss skall anse grupposter giltiga före den frågar " -"bakänden igen" +"Hur många sekunder nss_sss ska betrakta grupposter som giltiga innan den " +"bakomliggande komponenten frågas igen" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2708 +#: sssd.conf.5.xml:2754 msgid "entry_cache_netgroup_timeout (integer)" msgstr "entry_cache_netgroup_timeout (heltal)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2711 +#: sssd.conf.5.xml:2757 msgid "" "How many seconds should nss_sss consider netgroup entries valid before " "asking the backend again" msgstr "" -"Hur många sekunder nss_sss skall anse nätgruppsposter giltiga före den " -"frågar bakänden igen" +"Hur många sekunder nss_sss ska betrakta nätgruppsposter som giltiga innan " +"den bakomliggande komponenten frågas igen" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2721 +#: sssd.conf.5.xml:2767 msgid "entry_cache_service_timeout (integer)" msgstr "entry_cache_service_timeout (heltal)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2724 +#: sssd.conf.5.xml:2770 msgid "" "How many seconds should nss_sss consider service entries valid before asking " "the backend again" msgstr "" -"Hur många sekunder nss_sss skall anse tjänsteposter giltiga före den frågar " -"bakänden igen" +"Hur många sekunder nss_sss ska betrakta tjänsteposter som giltiga innan den " +"bakomliggande komponenten frågas igen" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2734 +#: sssd.conf.5.xml:2780 msgid "entry_cache_resolver_timeout (integer)" msgstr "entry_cache_resolver_timeout (heltal)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2737 +#: sssd.conf.5.xml:2783 msgid "" "How many seconds should nss_sss consider hosts and networks entries valid " "before asking the backend again" msgstr "" -"Hur många sekunder nss_sss skall anse värd- och nätgruppsposter giltiga före " -"den frågar bakänden igen" +"Hur många sekunder nss_sss ska betrakta värd- och nätverksposter som giltiga " +"innan den bakomliggande komponenten frågas igen" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2748 +#: sssd.conf.5.xml:2794 msgid "entry_cache_sudo_timeout (integer)" msgstr "entry_cache_sudo_timeout (heltal)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2751 -msgid "" -"How many seconds should sudo consider rules valid before asking the backend " -"again" -msgstr "" -"Hur många sekunder sudo skall anse regler giltiga före den frågar bakänden " -"igen" +#: sssd.conf.5.xml:2797 +msgid "" +"How many seconds should sudo consider rules valid before asking the backend " +"again" +msgstr "" +"Hur många sekunder sudo ska betrakta regler som giltiga innan den " +"bakomliggande komponenten frågas igen" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2807 +msgid "entry_cache_autofs_timeout (integer)" +msgstr "entry_cache_autofs_timeout (heltal)" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2810 +msgid "" +"How many seconds should the autofs service consider automounter maps valid " +"before asking the backend again" +msgstr "" +"Hur många sekunder autofs-tjänsten ska betrakta automonteringskartor som " +"giltiga innan den bakomliggande komponenten frågas igen" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2821 +msgid "entry_cache_ssh_host_timeout (integer)" +msgstr "entry_cache_ssh_host_timeout (heltal)" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2824 +msgid "" +"How many seconds to keep a host ssh key after refresh. IE how long to cache " +"the host key for." +msgstr "" +"Hur länge en värds SSH-nyckel ska behållas efter uppdatering, dvs. hur länge " +"värdnyckeln ska cachelagras." + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2835 +msgid "offline_timeout (integer)" +msgstr "offline_timeout (heltal)" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2838 +msgid "" +"When SSSD switches to offline mode the amount of time before it tries to go " +"back online will increase based upon the time spent disconnected. By " +"default SSSD uses incremental behaviour to calculate delay in between " +"retries. So, the wait time for a given retry will be longer than the wait " +"time for the previous ones. After each unsuccessful attempt to go online, " +"the new interval is recalculated by the following:" +msgstr "" +"När SSSD växlar till frånkopplat läge ökar tiden innan det försöker ansluta " +"igen beroende på hur länge det varit frånkopplat. Som standard använder SSSD " +"stegvis ökning för att beräkna fördröjningen mellan återförsök. Väntetiden " +"för ett visst återförsök blir alltså längre än väntetiden för det " +"föregående. Efter varje misslyckat anslutningsförsök beräknas det nya " +"intervallet enligt följande:" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2849 sssd.conf.5.xml:2907 +msgid "" +"new_delay = Minimum(old_delay * 2, offline_timeout_max) + " +"random[0...offline_timeout_random_offset]" +msgstr "" +"new_delay = Minimum(old_delay * 2, offline_timeout_max) + " +"random[0...offline_timeout_random_offset]" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2852 +#, fuzzy +#| msgid "" +#| "The offline_timeout default value is 60. The offline_timeout_max default " +#| "value is 3600. The offline_timeout_random_offset default value is 30. " +#| "The end result is amount of seconds before next retry." +msgid "" +"The offline_timeout default value is 60. The offline_timeout_max default " +"value is 3600. The offline_timeout_random_offset default value is 30. The " +"end result is the number of seconds before next retry." +msgstr "" +"Standardvärdet för offline_timeout är 60. Standardvärdet på " +"offline_timeout_max är 3600. Standardvärdet på offline_timeout_random_offset " +"är 30. Slutresultatet är antalet sekunder före nästa omförsök." + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2858 +#, fuzzy +#| msgid "" +#| "Note that the maximum length of each interval is defined by " +#| "offline_timeout_max (apart of random part)." +msgid "" +"Note that the maximum length of each interval is defined by " +"offline_timeout_max (apart from the random part)." +msgstr "" +"Observera att den maximala längde på varje intervall definieras av " +"offline_timeout_max (förutom slumpdelen)." + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2868 +msgid "offline_timeout_max (integer)" +msgstr "offline_timeout_max (heltal)" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2871 +msgid "" +"Controls by how much the time between attempts to go online can be " +"incremented following unsuccessful attempts to go online." +msgstr "" +"Styr hur mycket tiden mellan försök att ansluta kan ökas efter misslyckade " +"anslutningsförsök." + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2876 +msgid "A value of 0 disables the incrementing behaviour." +msgstr "Ett värde på 0 avaktiverar det ökande beteendet." + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2879 +msgid "" +"The value of this parameter should be set in correlation to offline_timeout " +"parameter value." +msgstr "" +"Värdet för denna parameter ska sättas i relation till värdet för parametern " +"offline_timeout." + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2883 +#, fuzzy +#| msgid "" +#| "With offline_timeout set to 60 (default value) there is no point in " +#| "setting offlinet_timeout_max to less than 120 as it will saturate " +#| "instantly. General rule here should be to set offline_timeout_max to at " +#| "least 4 times offline_timeout." +msgid "" +"With offline_timeout set to 60 (default value) there is no point in setting " +"offline_timeout_max to less than 120 as it will saturate instantly. General " +"rule here should be to set offline_timeout_max to at least 4 times " +"offline_timeout." +msgstr "" +"Med offline_timout satt till 60 (standardvärdet) är det ingen poäng i att " +"sätta ofline_timeout_max till mindre än 120 eftersom det kommer mättas " +"omedelbart. En allmän regel här bör vara att sätta offline_timeout_max till " +"åtminstone 4 gånger offline_timeout." + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2889 +msgid "" +"Although a value between 0 and offline_timeout may be specified, it has the " +"effect of overriding the offline_timeout value so is of little use." +msgstr "" +"Även om ett värde mellan 0 och offline_timeout kan anges har det effekten " +"att åsidosätta värdet offline_timeout så det är inte så användbart." + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2894 +msgid "Default: 3600" +msgstr "Standard: 3600" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2761 -msgid "entry_cache_autofs_timeout (integer)" -msgstr "entry_cache_autofs_timeout (heltal)" +#: sssd.conf.5.xml:2900 +msgid "offline_timeout_random_offset (integer)" +msgstr "offline_timeout_random_offset (heltal)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2764 +#: sssd.conf.5.xml:2903 msgid "" -"How many seconds should the autofs service consider automounter maps valid " -"before asking the backend again" +"When SSSD is in offline mode it keeps probing backend servers in specified " +"time intervals:" msgstr "" -"Hur många sekunder tjänsten autofs skall anse automatmonteringskartor " -"giltiga före den frågar bakänden igen" - -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2775 -msgid "entry_cache_ssh_host_timeout (integer)" -msgstr "entry_cache_ssh_host_timeout (heltal)" +"När SSSD är i frånkopplat läge fortsätter det att kontrollera bakomliggande " +"servrar med angivna tidsintervall:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2778 +#: sssd.conf.5.xml:2910 msgid "" -"How many seconds to keep a host ssh key after refresh. IE how long to cache " -"the host key for." +"This parameter controls the value of the random offset used for the above " +"equation. Final random_offset value will be random number in range:" msgstr "" -"Hur många sekunder en värds ssh-nyckel behålls efter en uppdatering. D.v.s. " -"hur länge värdnyckeln skall cachas." +"Denna parameter styr värdet på den slumpvisa förskjutningen som används i " +"ovanstående ekvation. Det slutliga random_offset-värdet kommer vara ett " +"slumptal i intervallet:" -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2789 -msgid "entry_cache_computer_timeout (integer)" -msgstr "entry_cache_computer_timeout (heltal)" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2915 +msgid "[0 - offline_timeout_random_offset]" +msgstr "[0 - offline_timeout_random_offset]" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2792 -msgid "" -"How many seconds to keep the local computer entry before asking the backend " -"again" -msgstr "" -"Hur många sekunder som den lokala datorns post sparas före bakänden frågas " -"igen" +#: sssd.conf.5.xml:2918 +msgid "A value of 0 disables the random offset addition." +msgstr "Ett värde på 0 avaktiverar tillägget av en slumpfördröjning." + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2921 +msgid "Default: 30" +msgstr "Standard: 30" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2802 +#: sssd.conf.5.xml:2927 msgid "refresh_expired_interval (integer)" msgstr "refresh_expired_interval (heltal)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2805 +#: sssd.conf.5.xml:2930 msgid "" "Specifies how many seconds SSSD has to wait before triggering a background " "refresh task which will refresh all expired or nearly expired records." msgstr "" -"Anger hur många sekunder SSSD måste vänta före en uppdateringsuppgift " -"startas i bakgrunden som kommer uppdatera alla utgångna eller nästan " -"utgångna poster." +"Anger hur många sekunder SSSD ska vänta innan en bakgrundsuppgift för " +"uppdatering utlöses, som uppdaterar alla utgångna eller nästan utgångna " +"poster." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2810 +#: sssd.conf.5.xml:2935 msgid "" "The background refresh will process users, groups and netgroups in the " "cache. For users who have performed the initgroups (get group membership for " @@ -4080,17 +4324,17 @@ msgstr "" "uppdateras både användarposten och gruppmedlemskapet." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2818 +#: sssd.conf.5.xml:2943 msgid "This option is automatically inherited for all trusted domains." -msgstr "Denna flagga ärvs automatiskt för alla betrodda domäner." +msgstr "Detta alternativ ärvs automatiskt av alla betrodda domäner." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2822 +#: sssd.conf.5.xml:2947 msgid "You can consider setting this value to 3/4 * entry_cache_timeout." -msgstr "Du kan överväga att sätta detta värde till ¾ · entry_cache_timeout." +msgstr "Du kan överväga att sätta detta värde till 3/4 * entry_cache_timeout." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2826 +#: sssd.conf.5.xml:2951 msgid "" "Cache entry will be refreshed by background task when 2/3 of cache timeout " "has already passed. If there are existing cached entries, the background " @@ -4100,28 +4344,30 @@ msgid "" "offline mode operation and reuse of existing valid cache entries. To make " "this change instant the user may want to manually invalidate existing cache." msgstr "" -"Cacheposter kommer uppdateras av ett bakgrundsjobb när ⅔ av cachetidsgränsen " -"redan har gått. Om det finns cachade poster kommer bakgrundsjobbet referera " -"till deras urpsprungliga cachetidsgränsvärden istället för det aktuella " -"konfiguartionsvärdet. Detta kan leda till en situation där " -"bakgrundsuppdateringsjobbet förefaller inte fungera. Detta är gjort med " -"avsikt för att förbättra funktionen i frånkopplat läge och återanvändning av " -"giltiga cacheposter. För att göra denna ändring omedelbart kan användaren " -"vilja manuellt invalidera den befintliga cachen." +"Cacheposter uppdateras av bakgrundsuppgiften när 2/3 av cachetidsgränsen har " +"gått. Om det finns befintliga cachelagrade poster använder " +"bakgrundsuppgiften deras ursprungliga cachetidsgränsvärden i stället för det " +"aktuella konfigurationsvärdet. Detta kan ge intrycket att bakgrundsuppgiften " +"inte fungerar. Det är avsiktligt för att förbättra funktionen i frånkopplat " +"läge och återanvändningen av befintliga giltiga cacheposter. För att " +"ändringen ska slå igenom direkt kan användaren manuellt ogiltigförklara den " +"befintliga cachen." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2839 sssd-ldap.5.xml:406 sssd-ldap.5.xml:1834 -#: sssd-ipa.5.xml:255 +#: sssd.conf.5.xml:2964 sssd-ldap.5.xml:406 sssd-ldap.5.xml:1834 +#: sssd-ipa.5.xml:250 msgid "Default: 0 (disabled)" msgstr "Standard: 0 (avaktiverat)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2845 -msgid "cache_credentials (bool)" +#: sssd.conf.5.xml:2970 +#, fuzzy +#| msgid "cache_credentials (bool)" +msgid "cache_credentials (boolean)" msgstr "cache_credentials (bool)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2848 +#: sssd.conf.5.xml:2973 msgid "" "Determines if user credentials are also cached in the local LDB cache. The " "cached credentials refer to passwords, which includes the first (long term) " @@ -4130,59 +4376,59 @@ msgid "" "as a successful online authentication is recorded in the cache without " "additional configuration." msgstr "" -"Avgör huruvida användarkreditiv även cachas i den lokala LDB-cachen. Cachade " -"kreditiv avser lösenord, vilket inkluderar den första (långlivade) faktorn i " -"tvåfaktorautentisering, inte andra autentiseringsmekanismer. Autentiseringar " -"med lösenfraser och smarta kort förväntas fungera frånkopplade så länge som " -"en lyckad uppkopplad autentisering är registrerad i cachen utan ytterligare " -"konfiguration." +"Avgör om användarautentiseringsuppgifter även cachelagras i den lokala LDB-" +"cachen. De cachelagrade uppgifterna avser lösenord, vilket omfattar den " +"första (långsiktiga) faktorn i tvåfaktorsautentisering, men inte andra " +"autentiseringsmekanismer. Passnyckel- och smartkortsautentisering förväntas " +"fungera frånkopplade så länge en lyckad autentisering online har " +"registrerats i cachen utan ytterligare konfiguration." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2859 +#: sssd.conf.5.xml:2984 msgid "" "Take a note that while credentials are stored as a salted SHA512 hash, this " "still potentially poses some security risk in case an attacker manages to " "get access to a cache file (normally requires privileged access) and to " "break a password using brute force attack." msgstr "" -"Ta i beaktande att medan kreditiv sparas som en saltad SHA512-kontrollsumma " -"medför detta ändå potentiellt en viss säkerhetsrisk ifall en angripare " -"lyckas få åtkomst till en cache-fil (kräver normalt privilegierad åtkomst) " -"och att knäcka ett lösenord med en råstyrkeattack." +"Observera att även om autentiseringsuppgifter lagras som ett saltat SHA512-" +"hashvärde, innebär detta fortfarande en möjlig säkerhetsrisk om en angripare " +"får åtkomst till en cachefil (vilket normalt kräver privilegierad åtkomst) " +"och lyckas knäcka ett lösenord med en råstyrkeattack." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2873 +#: sssd.conf.5.xml:2998 msgid "cache_credentials_minimal_first_factor_length (int)" msgstr "cache_credentials_minimal_first_factor_length (heltal)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2876 +#: sssd.conf.5.xml:3001 msgid "" "If 2-Factor-Authentication (2FA) is used and credentials should be saved " "this value determines the minimal length the first authentication factor " "(long term password) must have to be saved as SHA512 hash into the cache." msgstr "" -"Om 2-faktorautentisering (2FA) används och kreditiv skall sparas avgör detta " -"värde den minsta längden den första autentiseringsfaktorn (långvarigt " -"lösenord) måste ha för att sparas som en SHA512-kontrollsumma i cachen." +"Om tvåfaktorsautentisering (2FA) används och autentiseringsuppgifter ska " +"sparas anger detta värde den minsta längd som den första " +"autentiseringsfaktorn (långsiktigt lösenord) måste ha för att kunna sparas " +"som ett SHA512-hashvärde i cachen." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2883 +#: sssd.conf.5.xml:3008 msgid "" "This should avoid that the short PINs of a PIN based 2FA scheme are saved in " "the cache which would make them easy targets for brute-force attacks." msgstr "" -"Detta skall undvika att de korta PIN:arna i ett PIN-baserat 2FA-arrangemang " -"sparas i cachen vilket skulle gjort dem till lätta mål för uttömmande " -"attacker." +"Detta ska hindra att korta PIN-koder i ett PIN-baserat 2FA-system sparas i " +"cachen, vilket skulle göra dem till lätta mål för råstyrkeattacker." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2894 +#: sssd.conf.5.xml:3019 msgid "account_cache_expiration (integer)" msgstr "account_cache_expiration (heltal)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2897 +#: sssd.conf.5.xml:3022 msgid "" "Number of days entries are left in cache after last successful login before " "being removed during a cleanup of the cache. 0 means keep forever. The " @@ -4195,52 +4441,53 @@ msgstr "" "offline_credentials_expiration." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2904 +#: sssd.conf.5.xml:3029 msgid "Default: 0 (unlimited)" msgstr "Standard: 0 (obegränsat)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2909 +#: sssd.conf.5.xml:3034 msgid "pwd_expiration_warning (integer)" msgstr "pwd_expiration_warning (heltal)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2920 +#: sssd.conf.5.xml:3045 msgid "" "Please note that the backend server has to provide information about the " "expiration time of the password. If this information is missing, sssd " "cannot display a warning. Also an auth provider has to be configured for the " "backend." msgstr "" -"Observera att bakändeservern måste leverera information om utgångstiden för " -"lösenordet. Om denna information saknas kan sssd inte visa någon varning. " -"Dessutom måste en autentiseringsleverantör ha konfigurerats för bakänden." +"Observera att den bakomliggande servern måste tillhandahålla information om " +"lösenordets utgångstid. Om informationen saknas kan sssd inte visa någon " +"varning. En autentiseringsleverantör måste också konfigureras för den " +"bakomliggande komponenten." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2927 +#: sssd.conf.5.xml:3052 msgid "Default: 7 (Kerberos), 0 (LDAP)" msgstr "Standard: 7 (Kerberos), 0 (LDAP)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2933 +#: sssd.conf.5.xml:3058 msgid "id_provider (string)" msgstr "id_provider (sträng)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2936 +#: sssd.conf.5.xml:3061 msgid "" "The identification provider used for the domain. Supported ID providers are:" msgstr "" -"Identifikationsleverantören som används för domänen. ID-leverantörer som " -"stödjs är:" +"Identitetsleverantören som används för domänen. Följande ID-leverantörer " +"stöds:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2940 +#: sssd.conf.5.xml:3065 msgid "<quote>proxy</quote>: Support a legacy NSS provider." -msgstr "<quote>proxy</quote>: Stöd en tidigare NSS-leverantör." +msgstr "<quote>proxy</quote>: Stöd för en äldre NSS-leverantör." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2943 +#: sssd.conf.5.xml:3068 msgid "" "<quote>ldap</quote>: LDAP provider. See <citerefentry> <refentrytitle>sssd-" "ldap</refentrytitle> <manvolnum>5</manvolnum> </citerefentry> for more " @@ -4251,20 +4498,20 @@ msgstr "" "information om att konfigurera LDAP." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2951 sssd.conf.5.xml:3070 sssd.conf.5.xml:3129 -#: sssd.conf.5.xml:3192 +#: sssd.conf.5.xml:3076 sssd.conf.5.xml:3200 sssd.conf.5.xml:3259 +#: sssd.conf.5.xml:3322 msgid "" "<quote>ipa</quote>: FreeIPA and Red Hat Identity Management provider. See " "<citerefentry> <refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</" "manvolnum> </citerefentry> for more information on configuring FreeIPA." msgstr "" -"<quote>ipa</quote>: Leverantören FreeIPA och Red Hat Identity Management. Se " -"<citerefentry> <refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</" -"manvolnum> </citerefentry> för mer information om att konfigurera FreeIPA." +"<quote>ipa</quote>: Leverantör för FreeIPA och Red Hat Identity Management. " +"Se <citerefentry> <refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry> för mer information om hur FreeIPA konfigureras." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2960 sssd.conf.5.xml:3079 sssd.conf.5.xml:3138 -#: sssd.conf.5.xml:3201 +#: sssd.conf.5.xml:3085 sssd.conf.5.xml:3209 sssd.conf.5.xml:3268 +#: sssd.conf.5.xml:3331 msgid "" "<quote>ad</quote>: Active Directory provider. See <citerefentry> " "<refentrytitle>sssd-ad</refentrytitle> <manvolnum>5</manvolnum> </" @@ -4275,7 +4522,7 @@ msgstr "" "citerefentry> för mer information om att konfigurera Active Directory." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2968 +#: sssd.conf.5.xml:3093 msgid "" "<quote>idp</quote>: Provider for OAuth 2.0/OIDC based Identity Providers " "(IdP). See <citerefentry> <refentrytitle>sssd-idp</refentrytitle> " @@ -4285,13 +4532,22 @@ msgstr "" "identitetsleverantörer (IdP). Se <citerefentry> <refentrytitle>sssd-idp</" "refentrytitle> <manvolnum>5</manvolnum> </citerefentry> för mer information." +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3101 +msgid "" +"Default: Not set (This is a mandatory setting that must be explicitly " +"defined for each configured domain)." +msgstr "" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2979 -msgid "use_fully_qualified_names (bool)" +#: sssd.conf.5.xml:3109 +#, fuzzy +#| msgid "use_fully_qualified_names (bool)" +msgid "use_fully_qualified_names (boolean)" msgstr "use_fully_qualified_names (bool)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2982 +#: sssd.conf.5.xml:3112 msgid "" "Use the full name and domain (as formatted by the domain's full_name_format) " "as the user's login name reported to NSS." @@ -4300,21 +4556,21 @@ msgstr "" "full_name_format) som användarens inloggningsnamn rapporterat till NSS." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2987 +#: sssd.conf.5.xml:3117 msgid "" "If set to TRUE, all requests to this domain must use fully qualified names. " "For example, if used in EXAMPLE domain that contains a \"test\" user, " "<command>getent passwd test</command> wouldn't find the user while " "<command>getent passwd test@EXAMPLE</command> would." msgstr "" -"Om inställt på TRUE måste alla förfrågningar till denna domän använda " +"Om värdet är TRUE måste alla begäranden till denna domän använda " "fullständigt kvalificerade namn. Om det till exempel används i domänen " -"EXEMPEL som innehåller en användare med namnet \"test\", skulle <command>" -"getent passwd test</command> inte hitta användaren, medan <command>getent " -"passwd test@EXEMPEL</command> skulle göra det." +"EXAMPLE som innehåller användaren \"test\", hittar <command>getent passwd " +"test</command> inte användaren, medan <command>getent passwd test@EXAMPLE</" +"command> gör det." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2995 +#: sssd.conf.5.xml:3125 msgid "" "NOTE: This option has no effect on netgroup lookups due to their tendency to " "include nested netgroups without qualified names. For netgroups, all domains " @@ -4326,7 +4582,7 @@ msgstr "" "namn begärs." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3002 +#: sssd.conf.5.xml:3132 msgid "" "Default: FALSE (TRUE for trusted domain/sub-domains or if " "default_domain_suffix is used)" @@ -4335,17 +4591,19 @@ msgstr "" "default_domain_suffix används)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3009 -msgid "ignore_group_members (bool)" +#: sssd.conf.5.xml:3139 +#, fuzzy +#| msgid "ignore_group_members (bool)" +msgid "ignore_group_members (boolean)" msgstr "ignore_group_members (bool)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3012 +#: sssd.conf.5.xml:3142 msgid "Do not return group members for group lookups." msgstr "Returnera inte gruppmedlemmar för gruppuppslagningar." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3015 +#: sssd.conf.5.xml:3145 msgid "" "If set to TRUE, the group membership attribute is not requested from the " "ldap server, and group members are not returned when processing group lookup " @@ -4364,7 +4622,7 @@ msgstr "" "som om den vore tom." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3033 +#: sssd.conf.5.xml:3163 msgid "" "Enabling this option can also make access provider checks for group " "membership significantly faster, especially for groups containing many " @@ -4375,7 +4633,7 @@ msgstr "" "innehåller många medlemmar." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3039 sssd.conf.5.xml:3767 sssd-ldap.5.xml:401 +#: sssd.conf.5.xml:3169 sssd.conf.5.xml:3951 sssd-ldap.5.xml:401 #: sssd-ldap.5.xml:454 sssd-ldap.5.xml:529 sssd-ldap.5.xml:576 #: sssd-ldap.5.xml:599 sssd-ldap.5.xml:638 sssd-ldap.5.xml:657 #: sssd-ldap.5.xml:681 sssd-ldap.5.xml:1114 sssd-ldap.5.xml:1147 @@ -4383,25 +4641,25 @@ msgid "" "This option can be also set per subdomain or inherited via " "<emphasis>subdomain_inherit</emphasis>." msgstr "" -"Detta alternativ kan även sättas per underdomän eller ärvt via <emphasis>" +"Detta alternativ kan också anges per underdomän eller ärvas via <emphasis>" "subdomain_inherit</emphasis>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3049 +#: sssd.conf.5.xml:3179 msgid "auth_provider (string)" msgstr "auth_provider (sträng)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3052 +#: sssd.conf.5.xml:3182 msgid "" "The authentication provider used for the domain. Supported auth providers " "are:" msgstr "" -"Autentiseringsleverantören som används för domänen. Leverantörer som stödjs " -"är:" +"Autentiseringsleverantören som används för domänen. Följande " +"autentiseringsleverantörer stöds:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3056 sssd.conf.5.xml:3122 +#: sssd.conf.5.xml:3186 sssd.conf.5.xml:3252 msgid "" "<quote>ldap</quote> for native LDAP authentication. See <citerefentry> " "<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> </" @@ -4412,7 +4670,7 @@ msgstr "" "citerefentry> för mer information om att konfigurera LDAP." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3063 +#: sssd.conf.5.xml:3193 msgid "" "<quote>krb5</quote> for Kerberos authentication. See <citerefentry> " "<refentrytitle>sssd-krb5</refentrytitle> <manvolnum>5</manvolnum> </" @@ -4423,7 +4681,7 @@ msgstr "" "citerefentry> för mer information om att konfigurera Kerberos." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3087 +#: sssd.conf.5.xml:3217 msgid "" "<quote>idp</quote>: Provider for OAuth 2.0/OIDC based authentication. See " "<citerefentry> <refentrytitle>sssd-idp</refentrytitle> <manvolnum>5</" @@ -4434,7 +4692,7 @@ msgstr "" "manvolnum> </citerefentry> för mer information." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3095 +#: sssd.conf.5.xml:3225 msgid "" "<quote>proxy</quote> for relaying authentication to some other PAM target." msgstr "" @@ -4442,12 +4700,12 @@ msgstr "" "PAM-mål." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3098 +#: sssd.conf.5.xml:3228 msgid "<quote>none</quote> disables authentication explicitly." -msgstr "<quote>none</quote> avaktiverar explicit autentisering." +msgstr "<quote>none</quote> inaktiverar autentisering uttryckligen." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3101 +#: sssd.conf.5.xml:3231 msgid "" "Default: <quote>id_provider</quote> is used if it is set and can handle " "authentication requests." @@ -4456,46 +4714,46 @@ msgstr "" "autentiseringsbegäranden." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3107 +#: sssd.conf.5.xml:3237 msgid "access_provider (string)" msgstr "access_provider (sträng)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3110 +#: sssd.conf.5.xml:3240 msgid "" "The access control provider used for the domain. There are two built-in " "access providers (in addition to any included in installed backends) " "Internal special providers are:" msgstr "" -"Leverantören av åtkomstkontroll för domänen. Det finns två inbyggda " -"åtkomstleverantörer (utöver alla inkluderade i installerade bakändar). " -"Interna specialleverantörer är:" +"Åtkomstkontrollleverantören som används för domänen. Det finns två inbyggda " +"åtkomstleverantörer, utöver eventuella leverantörer i installerade " +"bakomliggande komponenter. Interna specialleverantörer är:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3116 +#: sssd.conf.5.xml:3246 msgid "<quote>permit</quote> always allow access." -msgstr "<quote>permit</quote> alltid tillåter åtkomst." +msgstr "<quote>permit</quote> tillåter alltid åtkomst." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3119 +#: sssd.conf.5.xml:3249 msgid "<quote>deny</quote> always deny access." -msgstr "<quote>deny</quote> neka alltid åtkomst." +msgstr "<quote>deny</quote> nekar alltid åtkomst." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3146 +#: sssd.conf.5.xml:3276 msgid "" "<quote>simple</quote> access control based on access or deny lists. See " "<citerefentry> <refentrytitle>sssd-simple</refentrytitle> <manvolnum>5</" "manvolnum></citerefentry> for more information on configuring the simple " "access module." msgstr "" -"<quote>simple</quote> åtkomstkontroll baserat på åtkomst- eller " +"<quote>simple</quote> åtkomstkontroll baserad på tillåtelse- eller " "nekandelistor. Se <citerefentry> <refentrytitle>sssd-simple</refentrytitle> " -"<manvolnum>5</manvolnum></citerefentry> för mer information om att " -"konfigurera åtkomstmodulen simple." +"<manvolnum>5</manvolnum></citerefentry> för mer information om hur " +"åtkomstmodulen simple konfigureras." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3153 +#: sssd.conf.5.xml:3283 msgid "" "<quote>krb5</quote>: .k5login based access control. See <citerefentry> " "<refentrytitle>sssd-krb5</refentrytitle> <manvolnum>5</manvolnum></" @@ -4506,33 +4764,33 @@ msgstr "" "citerefentry> för mer information om att konfigurera Kerberos." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3160 +#: sssd.conf.5.xml:3290 msgid "<quote>proxy</quote> for relaying access control to another PAM module." msgstr "" "<quote>proxy</quote> för att skicka vidare åtkomstkontroll till någon annan " "PAM-modul." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3163 +#: sssd.conf.5.xml:3293 msgid "Default: <quote>permit</quote>" msgstr "Standard: <quote>permit</quote>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3168 +#: sssd.conf.5.xml:3298 msgid "chpass_provider (string)" msgstr "chpass_provider (sträng)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3171 +#: sssd.conf.5.xml:3301 msgid "" "The provider which should handle change password operations for the domain. " "Supported change password providers are:" msgstr "" -"Leverantören som skall hantera lösenordsändringar för domänen. Leverantörer " -"av lösenordsändring som stödjs är:" +"Leverantören som ska hantera lösenordsändringar för domänen. Följande " +"leverantörer för lösenordsändringar stöds:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3176 +#: sssd.conf.5.xml:3306 msgid "" "<quote>ldap</quote> to change a password stored in a LDAP server. See " "<citerefentry> <refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</" @@ -4543,7 +4801,7 @@ msgstr "" "manvolnum> </citerefentry> för mer information om att konfigurera LDAP." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3184 +#: sssd.conf.5.xml:3314 msgid "" "<quote>krb5</quote> to change the Kerberos password. See <citerefentry> " "<refentrytitle>sssd-krb5</refentrytitle> <manvolnum>5</manvolnum> </" @@ -4554,7 +4812,7 @@ msgstr "" "citerefentry> för mer information om att konfigurera Kerberos." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3209 +#: sssd.conf.5.xml:3339 msgid "" "<quote>proxy</quote> for relaying password changes to some other PAM target." msgstr "" @@ -4562,12 +4820,12 @@ msgstr "" "annat PAM-mål." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3213 +#: sssd.conf.5.xml:3343 msgid "<quote>none</quote> disallows password changes explicitly." msgstr "<quote>none</quote> tillåter uttryckligen inte lösenordsändringar." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3216 +#: sssd.conf.5.xml:3346 msgid "" "Default: <quote>auth_provider</quote> is used if it is set and can handle " "change password requests." @@ -4576,18 +4834,18 @@ msgstr "" "hantera begäranden om ändring av lösenord." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3223 +#: sssd.conf.5.xml:3353 msgid "sudo_provider (string)" msgstr "sudo_provider (sträng)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3226 +#: sssd.conf.5.xml:3356 msgid "The SUDO provider used for the domain. Supported SUDO providers are:" msgstr "" "SUDO-leverantören som används för domänen. SUDO-leverantörer som stödjs är:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3230 +#: sssd.conf.5.xml:3360 msgid "" "<quote>ldap</quote> for rules stored in LDAP. See <citerefentry> " "<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> </" @@ -4598,30 +4856,30 @@ msgstr "" "citerefentry> för mer information om att konfigurera LDAP." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3238 +#: sssd.conf.5.xml:3368 msgid "" "<quote>ipa</quote> the same as <quote>ldap</quote> but with IPA default " "settings." msgstr "" -"<quote>ipa</quote> samma som <quote>ldap</quote> men med " -"standardsinställningar för IPA." +"<quote>ipa</quote> är samma som <quote>ldap</quote>, men med IPA-" +"standardinställningar." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3242 +#: sssd.conf.5.xml:3372 msgid "" "<quote>ad</quote> the same as <quote>ldap</quote> but with AD default " "settings." msgstr "" -"<quote>ad</quote> samma som <quote>ldap</quote> men med " -"standardsinställningar för AD." +"<quote>ad</quote> är samma som <quote>ldap</quote>, men med AD-" +"standardinställningar." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3246 +#: sssd.conf.5.xml:3376 msgid "<quote>none</quote> disables SUDO explicitly." -msgstr "<quote>none</quote> avaktiverar explicit SUDO." +msgstr "<quote>none</quote> inaktiverar SUDO uttryckligen." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3249 +#: sssd.conf.5.xml:3379 msgid "" "Default: The value of <quote>id_provider</quote> is used if it is set and " "can handle sudo requests." @@ -4630,7 +4888,7 @@ msgstr "" "och kan hantera sudo-förfrågningar." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3253 +#: sssd.conf.5.xml:3383 msgid "" "The detailed instructions for configuration of sudo_provider are in the " "manual page <citerefentry> <refentrytitle>sssd-sudo</refentrytitle> " @@ -4647,7 +4905,7 @@ msgstr "" "<manvolnum>5</manvolnum> </citerefentry>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3268 +#: sssd.conf.5.xml:3398 msgid "" "<emphasis>NOTE:</emphasis> Sudo rules are periodically downloaded in the " "background unless the sudo provider is explicitly disabled. Set " @@ -4660,23 +4918,23 @@ msgstr "" "aktivitet i SSSD om du inte vill använda sudo med SSSD alls." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3278 +#: sssd.conf.5.xml:3408 msgid "selinux_provider (string)" msgstr "selinux_provider (sträng)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3281 +#: sssd.conf.5.xml:3411 msgid "" "The provider which should handle loading of selinux settings. Note that this " "provider will be called right after access provider ends. Supported selinux " "providers are:" msgstr "" -"Leverantören som skall hantera inläsning av selinux-inställningar. " -"Observera att denna leverantör kommer anropas direkt efter att " -"åtkomstleverantören avslutar. Selinux-leverantörer som stödjs är:" +"Leverantören som ska hantera inläsning av selinux-inställningar. Observera " +"att leverantören anropas direkt efter att åtkomstleverantören har avslutats. " +"Följande selinux-leverantörer stöds:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3287 +#: sssd.conf.5.xml:3417 msgid "" "<quote>ipa</quote> to load selinux settings from an IPA server. See " "<citerefentry> <refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</" @@ -4687,37 +4945,41 @@ msgstr "" "manvolnum> </citerefentry> för mer information om att konfigurera IPA." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3295 +#: sssd.conf.5.xml:3425 msgid "<quote>none</quote> disallows fetching selinux settings explicitly." msgstr "" -"<quote>none</quote> tillåter uttryckligen inte att hämta selinux-" -"inställningar." +"<quote>none</quote> hindrar uttryckligen hämtning av selinux-inställningar." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3298 +#: sssd.conf.5.xml:3428 +#, fuzzy +#| msgid "" +#| "Default: The value of <quote>id_provider</quote> is used if it is set and " +#| "can handle subdomain requests." msgid "" -"Default: <quote>id_provider</quote> is used if it is set and can handle " -"selinux loading requests." +"Default: the value of <quote>id_provider</quote> is used if it is set and " +"can handle selinux loading requests. Otherwise the result is the same as if " +"the selinux_provider is set to none." msgstr "" -"Standard: <quote>id_provider</quote> används om det är satt och kan hantera " -"begäranden om inläsning av selinux." +"Standard: Värdet för <quote>id_provider</quote> används om det är inställt " +"och kan hantera underdomänsförfrågningar." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3304 +#: sssd.conf.5.xml:3435 msgid "subdomains_provider (string)" msgstr "subdomains_provider (sträng)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3307 +#: sssd.conf.5.xml:3438 msgid "" "The provider which should handle fetching of subdomains. This value should " "be always the same as id_provider. Supported subdomain providers are:" msgstr "" -"Leverantören som skall hantera hämtandet av underdomäner. Detta värde skall " -"alltid vara samma som id_provider. Underdomänsleverantörer som stödjs är:" +"Leverantören som ska hantera hämtning av underdomäner. Detta värde ska " +"alltid vara samma som id_provider. Följande underdomänsleverantörer stöds:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3313 +#: sssd.conf.5.xml:3444 msgid "" "<quote>ipa</quote> to load a list of subdomains from an IPA server. See " "<citerefentry> <refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</" @@ -4728,7 +4990,7 @@ msgstr "" "5</manvolnum> </citerefentry> för mer information om att konfigurera IPA." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3322 +#: sssd.conf.5.xml:3453 msgid "" "<quote>ad</quote> to load a list of subdomains from an Active Directory " "server. See <citerefentry> <refentrytitle>sssd-ad</refentrytitle> " @@ -4741,12 +5003,12 @@ msgstr "" "konfigurera AD-leverantören." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3331 +#: sssd.conf.5.xml:3462 msgid "<quote>none</quote> disallows fetching subdomains explicitly." -msgstr "<quote>none</quote> tillåter uttryckligen inte att hämta underdomäner." +msgstr "<quote>none</quote> hindrar uttryckligen hämtning av underdomäner." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3335 +#: sssd.conf.5.xml:3466 msgid "" "Default: The value of <quote>id_provider</quote> is used if it is set and " "can handle subdomain requests." @@ -4755,96 +5017,95 @@ msgstr "" "och kan hantera underdomänsförfrågningar." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3341 +#: sssd.conf.5.xml:3472 msgid "session_provider (string)" msgstr "session_provider (sträng)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3344 +#: sssd.conf.5.xml:3475 msgid "" "The provider which configures and manages user session related tasks. The " "only user session task currently provided is the integration with Fleet " "Commander, which works only with IPA. Supported session providers are:" msgstr "" "Leverantören som konfigurerar och hanterar uppgifter relaterade till " -"användarsessioner. De enda användarsessionsuppgifter som för närvarande " -"tillhandahålls är integration med Fleet Commander, vilket fungerar endast " -"med IPA. Sessionsleverantörer som stödjs är:" +"användarsessioner. Den enda sessionsuppgift som för närvarande " +"tillhandahålls är integrationen med Fleet Commander, som endast fungerar med " +"IPA. Följande sessionsleverantörer stöds:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3351 +#: sssd.conf.5.xml:3482 msgid "<quote>ipa</quote> to allow performing user session related tasks." msgstr "" -"<quote>ipa</quote> för att utföra uppgifter relaterade till " +"<quote>ipa</quote> för att tillåta utförande av uppgifter relaterade till " "användarsessioner." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3355 +#: sssd.conf.5.xml:3486 msgid "" "<quote>none</quote> does not perform any kind of user session related tasks." msgstr "" -"<quote>none</quote> utför inte någon sorts uppgifter relaterade till " -"användarsessioner." +"<quote>none</quote> utför inga uppgifter relaterade till användarsessioner." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3359 +#: sssd.conf.5.xml:3490 msgid "Default: <quote>none</quote>." msgstr "Standard: <quote>none</quote>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3365 +#: sssd.conf.5.xml:3496 msgid "autofs_provider (string)" msgstr "autofs_provider (sträng)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3368 +#: sssd.conf.5.xml:3499 msgid "" "The autofs provider used for the domain. Supported autofs providers are:" msgstr "" -"Autofs-leverantören som används för domänen. Autofs-leverantörer som stödjs " -"är:" +"Autofs-leverantören som används för domänen. Följande autofs-leverantörer " +"stöds:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3372 +#: sssd.conf.5.xml:3503 msgid "" "<quote>ldap</quote> to load maps stored in LDAP. See <citerefentry> " "<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> </" "citerefentry> for more information on configuring LDAP." msgstr "" -"<quote>ldap</quote> för att läsa mappar lagrade i LDAP. Se <citerefentry> " -"<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> </" -"citerefentry> för mer information om att konfigurera LDAP." +"<quote>ldap</quote> för att läsa in kartor som lagras i LDAP. Se " +"<citerefentry> <refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry> för mer information om hur LDAP konfigureras." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3379 +#: sssd.conf.5.xml:3510 msgid "" "<quote>ipa</quote> to load maps stored in an IPA server. See <citerefentry> " "<refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</manvolnum> </" "citerefentry> for more information on configuring IPA." msgstr "" -"<quote>ipa</quote> för att läsa mappar lagrade i en IPA-server. Se " +"<quote>ipa</quote> för att läsa in kartor som lagras på en IPA-server. Se " "<citerefentry> <refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</" -"manvolnum> </citerefentry> för mer information om att konfigurera IPA." +"manvolnum> </citerefentry> för mer information om hur IPA konfigureras." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3387 +#: sssd.conf.5.xml:3518 msgid "" "<quote>ad</quote> to load maps stored in an AD server. See <citerefentry> " "<refentrytitle>sssd-ad</refentrytitle> <manvolnum>5</manvolnum> </" "citerefentry> for more information on configuring the AD provider." msgstr "" -"<quote>ad</quote> för att läsa mappar lagrade i en AD-server. Se " +"<quote>ad</quote> för att läsa in kartor som lagras på en AD-server. Se " "<citerefentry> <refentrytitle>sssd-ad</refentrytitle> <manvolnum>5</" -"manvolnum> </citerefentry> för mer information om att konfigurera AD-" -"leverantören." +"manvolnum> </citerefentry> för mer information om hur AD-leverantören " +"konfigureras." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3396 +#: sssd.conf.5.xml:3527 msgid "<quote>none</quote> disables autofs explicitly." -msgstr "<quote>none</quote> avaktiverar explicit autofs." +msgstr "<quote>none</quote> inaktiverar autofs uttryckligen." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3399 +#: sssd.conf.5.xml:3530 msgid "" "Default: The value of <quote>id_provider</quote> is used if it is set and " "can handle autofs requests." @@ -4853,37 +5114,37 @@ msgstr "" "och kan hantera autofs-förfrågningar." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3406 +#: sssd.conf.5.xml:3537 msgid "hostid_provider (string)" msgstr "hostid_provider (sträng)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3409 +#: sssd.conf.5.xml:3540 msgid "" "The provider used for retrieving host identity information. Supported " "hostid providers are:" msgstr "" -"Leverantören som används för att hämta värdidentitetsinformation. Värd-id-" -"leverantörer som stödjs är:" +"Leverantören som används för att hämta värdidentitetsinformation. Följande " +"hostid-leverantörer stöds:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3413 +#: sssd.conf.5.xml:3544 msgid "" "<quote>ipa</quote> to load host identity stored in an IPA server. See " "<citerefentry> <refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</" "manvolnum> </citerefentry> for more information on configuring IPA." msgstr "" -"<quote>ipa</quote> för att läsa värdidentiteter lagrade i en IPA-server. Se " -"<citerefentry> <refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</" -"manvolnum> </citerefentry> för mer information om att konfigurera IPA." +"<quote>ipa</quote> för att läsa in värdidentitet som lagras på en IPA-" +"server. Se <citerefentry> <refentrytitle>sssd-ipa</refentrytitle> <manvolnum>" +"5</manvolnum> </citerefentry> för mer information om hur IPA konfigureras." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3421 +#: sssd.conf.5.xml:3552 msgid "<quote>none</quote> disables hostid explicitly." -msgstr "<quote>none</quote> avaktiverar explicit värd-id:n." +msgstr "<quote>none</quote> inaktiverar hostid uttryckligen." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3424 +#: sssd.conf.5.xml:3555 msgid "" "Default: The value of <quote>id_provider</quote> is used if it is set and " "can handle hostid requests." @@ -4892,21 +5153,21 @@ msgstr "" "och kan hantera hostid-förfrågningar." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3431 +#: sssd.conf.5.xml:3562 msgid "resolver_provider (string)" msgstr "resolver_provider (sträng)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3434 +#: sssd.conf.5.xml:3565 msgid "" "The provider which should handle hosts and networks lookups. Supported " "resolver providers are:" msgstr "" -"Leverantören som skall hantera värd- och nätverksuppslagningar. " -"Uppslagsleverantörer som stödjs är:" +"Leverantören som ska hantera uppslagningar av värdar och nätverk. Följande " +"uppslagsleverantörer stöds:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3438 +#: sssd.conf.5.xml:3569 msgid "" "<quote>proxy</quote> to forward lookups to another NSS library. See " "<quote>proxy_resolver_lib_name</quote>" @@ -4915,7 +5176,7 @@ msgstr "" "bibliotek. Se <quote>proxy_resolver_lib_name</quote>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3442 +#: sssd.conf.5.xml:3573 msgid "" "<quote>ldap</quote> to fetch hosts and networks stored in LDAP. See " "<citerefentry> <refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</" @@ -4926,26 +5187,26 @@ msgstr "" "manvolnum> </citerefentry> för mer information om att konfigurera LDAP." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3449 +#: sssd.conf.5.xml:3580 msgid "" "<quote>ad</quote> to fetch hosts and networks stored in AD. See " "<citerefentry> <refentrytitle>sssd-ad</refentrytitle> <manvolnum>5</" "manvolnum> </citerefentry> for more information on configuring the AD " "provider." msgstr "" -"<quote>ldap</quote> för att hämta värdar och nätverk lagrade i AD. Se " +"<quote>ad</quote> för att hämta värdar och nätverk som lagras i AD. Se " "<citerefentry> <refentrytitle>sssd-ad</refentrytitle> <manvolnum>5</" -"manvolnum> </citerefentry> för mer information om att konfigurera AD-" -"leverantören." +"manvolnum> </citerefentry> för mer information om hur AD-leverantören " +"konfigureras." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3457 +#: sssd.conf.5.xml:3588 msgid "<quote>none</quote> disallows fetching hosts and networks explicitly." msgstr "" -"<quote>none</quote> tillåter uttryckligen inte att hämta värdar och nätverk." +"<quote>none</quote> hindrar uttryckligen hämtning av värdar och nätverk." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3460 +#: sssd.conf.5.xml:3591 msgid "" "Default: The value of <quote>id_provider</quote> is used if it is set and " "can handle resolver requests." @@ -4954,7 +5215,7 @@ msgstr "" "och kan hantera resolver-förfrågningar." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3470 +#: sssd.conf.5.xml:3601 msgid "" "Regular expression for this domain that describes how to parse the string " "containing user name and domain into these components. The \"domain\" can " @@ -4962,34 +5223,33 @@ msgid "" "trust subdomains and Active Directory domains, the flat (NetBIOS) name of " "the domain." msgstr "" -"Reguljärt uttryck för denna domän som beskriver hur man skall tolka strängen " -"som innehåller användarnamnet och domänen in i dessa komponenter. Domänen " -"kan matcha antingen domännamnet i SSSD-konfigurationen eller, i fallet med " -"betrodda underdomäner i IPA och Active Directory-domäner, det platta " -"(NetBIOS) namnet på domänen." +"Reguljärt uttryck för denna domän som beskriver hur strängen med " +"användarnamn och domän tolkas till dessa komponenter. \"domain\" kan matcha " +"antingen domännamnet i SSSD-konfigurationen eller, för IPA-betrodda " +"underdomäner och Active Directory-domäner, domänens korta (NetBIOS-)namn." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3479 +#: sssd.conf.5.xml:3610 msgid "" "Default: <quote>^((?P<name>.+)@(?P<domain>[^@]*)|(?P<name>" "[^@]+))$</quote> which allows two different styles for user names:" msgstr "" -"Standard: <quote>^((?P<name>+)@(?P<domain>[^@]*)|(^" -"(?P<name>[^@]+))$</quote> vilket tillåter två olika stilar av " +"Standard: <quote>^((?P<name>.+)@(?P<domain>[^@]*)|" +"(?P<name>[^@]+))$</quote>, vilket tillåter två olika former av " "användarnamn:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:3484 sssd.conf.5.xml:3498 +#: sssd.conf.5.xml:3615 sssd.conf.5.xml:3629 msgid "username" -msgstr "användarnamn" +msgstr "username" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:3487 sssd.conf.5.xml:3501 +#: sssd.conf.5.xml:3618 sssd.conf.5.xml:3632 msgid "username@domain.name" -msgstr "användarnamn@domän.namn" +msgstr "username@domain.name" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3492 +#: sssd.conf.5.xml:3623 msgid "" "Default for the AD and IPA provider: <quote>^(((?P<domain>[^\\\\]+)\\\\" "(?P<name>.+))|((?P<name>.+)@(?P<domain>[^@]+))|((?" @@ -5002,21 +5262,21 @@ msgstr "" "användarnamn:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:3504 +#: sssd.conf.5.xml:3635 msgid "domain\\username" -msgstr "domän\\användarnamn" +msgstr "domain\\username" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3507 +#: sssd.conf.5.xml:3638 msgid "" "While the first two correspond to the general default the third one is " "introduced to allow easy integration of users from Windows domains." msgstr "" -"Medan de första två motsvarar det allmänna standardfallet introduceras den " -"tredje för att tillåta enkel integration av användare från Windows-domäner." +"De första två motsvarar den allmänna standardinställningen, medan den tredje " +"har införts för att förenkla integrering av användare från Windows-domäner." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3512 +#: sssd.conf.5.xml:3643 msgid "" "The default re_expression uses the <quote>@</quote> character as a separator " "between the name and the domain. As a result of this setting the default " @@ -5024,152 +5284,178 @@ msgid "" "allowed in Windows group names). If a user wishes to use short names with " "<quote>@</quote> they must create their own re_expression." msgstr "" -"Standard re_expression använder tecknet <quote>@</quote> som en separator " -"mellan namnet och domänen. På grund av denna inställning accepterar inte " -"standardinställningen tecknet <quote>@</quote> i korta namn (så som det " -"tillåts i Windows gruppnamn). Om en användare vill använda korta namn med " -"<quote>@</quote> måste de skapa sin egen re_expression." +"Standardvärdet för re_expression använder tecknet <quote>@</quote> som " +"avgränsare mellan namnet och domänen. Därför accepterar standardvärdet inte " +"tecknet <quote>@</quote> i korta namn (trots att det tillåts i Windows-" +"gruppnamn). Om en användare vill använda korta namn med <quote>@</quote> " +"måste användaren skapa ett eget re_expression." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3564 +#: sssd.conf.5.xml:3695 msgid "Default: <quote>%1$s@%2$s</quote>." msgstr "Standard: <quote>%1$s@%2$s</quote>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3570 +#: sssd.conf.5.xml:3701 msgid "lookup_family_order (string)" msgstr "lookup_family_order (sträng)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3573 +#: sssd.conf.5.xml:3704 msgid "" "Provides the ability to select preferred address family to use when " "performing DNS lookups." msgstr "" -"Ger möjligheten att välja föredragen adressfamilj att använda vid DNS-" +"Gör det möjligt att välja vilken adressfamilj som ska föredras vid DNS-" "uppslagningar." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3577 +#: sssd.conf.5.xml:3708 msgid "Supported values:" msgstr "Värden som stödjs:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3580 +#: sssd.conf.5.xml:3711 msgid "ipv4_first: Try looking up IPv4 address, if that fails, try IPv6" -msgstr "ipv4_first: Försök slå upp IPv4-adresser, om det misslyckas, prova IPv6" +msgstr "" +"ipv4_first: Försök slå upp en IPv4-adress; om det misslyckas, prova IPv6." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3583 +#: sssd.conf.5.xml:3714 msgid "ipv4_only: Only attempt to resolve hostnames to IPv4 addresses." -msgstr "ipv4_only: Försök endast slå upp värdnamn som IPv4-adresser." +msgstr "ipv4_only: Försök endast lösa värdnamn till IPv4-adresser." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3586 +#: sssd.conf.5.xml:3717 msgid "ipv6_first: Try looking up IPv6 address, if that fails, try IPv4" -msgstr "ipv6_first: Försök slå upp IPv6-adresser, om det misslyckas, prova IPv4" +msgstr "" +"ipv6_first: Försök slå upp en IPv6-adress; om det misslyckas, prova IPv4." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3589 +#: sssd.conf.5.xml:3720 msgid "ipv6_only: Only attempt to resolve hostnames to IPv6 addresses." -msgstr "ipv6_only: Försök endast slå upp värdnamn som IPv6-adresser." +msgstr "ipv6_only: Försök endast lösa värdnamn till IPv6-adresser." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3592 +#: sssd.conf.5.xml:3723 msgid "Default: ipv4_first" msgstr "Standard: ipv4_first" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3598 +#: sssd.conf.5.xml:3729 msgid "dns_resolver_server_timeout (integer)" msgstr "dns_resolver_server_timeout (heltal)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3601 +#: sssd.conf.5.xml:3732 +#, fuzzy +#| msgid "" +#| "Defines the amount of time (in milliseconds) SSSD would try to talk to " +#| "DNS server before trying next DNS server." msgid "" -"Defines the amount of time (in milliseconds) SSSD would try to talk to DNS " -"server before trying next DNS server." +"Defines the timeout duration (in milliseconds) SSSD waits for a DNS server " +"to respond before moving to the next one." msgstr "" "Definierar mängden tid (i millisekunder) SSSD skall försöka att tala med en " "DNS-server före den provar nästa DNS-server." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3606 +#: sssd.conf.5.xml:3737 msgid "" "The AD provider will use this option for the CLDAP ping timeouts as well." msgstr "" -"AD-leverantören kommer även att använda detta alternativ för CLDAP-" -"pingtidsgränsen." +"AD-leverantören använder även detta alternativ för tidsgränser för CLDAP-" +"ping." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3610 sssd.conf.5.xml:3630 sssd.conf.5.xml:3651 +#: sssd.conf.5.xml:3741 sssd.conf.5.xml:3777 sssd.conf.5.xml:3814 +#, fuzzy +#| msgid "" +#| "Specifies the timeout (in seconds) after which the <citerefentry> " +#| "<refentrytitle>poll</refentrytitle> <manvolnum>2</manvolnum> </" +#| "citerefentry>/<citerefentry> <refentrytitle>select</refentrytitle> " +#| "<manvolnum>2</manvolnum> </citerefentry> following a <citerefentry> " +#| "<refentrytitle>connect</refentrytitle> <manvolnum>2</manvolnum> </" +#| "citerefentry> returns in case of no activity." msgid "" -"Please see the section <quote>FAILOVER</quote> for more information about " -"the service resolution." +"Please see the section <quote>FAILOVER</quote> in <citerefentry> " +"<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> </" +"citerefentry>, <citerefentry> <refentrytitle>sssd-krb5</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry>, <citerefentry> <refentrytitle>sssd-" +"ipa</refentrytitle> <manvolnum>5</manvolnum> </citerefentry> or " +"<citerefentry> <refentrytitle>sssd-ad</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry> for more information about the service resolution." msgstr "" -"Se avsnittet <quote>RESERVER</quote> för mer information om tjänstevalet." +"Anger tidsgränsen (i sekunder) efter vilken <citerefentry> " +"<refentrytitle>poll</refentrytitle> <manvolnum>2</manvolnum> </citerefentry>/" +"<citerefentry> <refentrytitle>select</refentrytitle> <manvolnum>2</" +"manvolnum> </citerefentry> som följer efter en <citerefentry> " +"<refentrytitle>connect</refentrytitle> <manvolnum>2</manvolnum> </" +"citerefentry> returnerar om inget händer." #. type: Content of: <refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3615 sssd-ldap.5.xml:700 include/failover.xml:84 +#: sssd.conf.5.xml:3762 sssd-ldap.5.xml:700 include/failover.xml:84 msgid "Default: 1000" msgstr "Standard: 1000" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3621 +#: sssd.conf.5.xml:3768 msgid "dns_resolver_op_timeout (integer)" msgstr "dns_resolver_op_timeout (heltal)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3624 +#: sssd.conf.5.xml:3771 msgid "" "Defines the amount of time (in seconds) to wait to resolve single DNS query " "(e.g. resolution of a hostname or an SRV record) before trying the next " "hostname or DNS discovery." msgstr "" -"Definierar mängden tid (i sekunder) att vänta på att slå upp en viss DNS-" -"fråga (t.ex. uppslagning av ett värdnamn eller en SRV-post) före den provar " -"nästa värdnamn eller DNS-upptäckt." +"Anger hur länge (i sekunder) en enskild DNS-fråga får vänta på att lösas " +"(t.ex. uppslagning av ett värdnamn eller en SRV-post) innan nästa värdnamn " +"eller DNS-upptäckt provas." #. type: Content of: <refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3635 include/failover.xml:100 +#: sssd.conf.5.xml:3798 include/failover.xml:100 msgid "Default: 3" msgstr "Standard: 3" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3641 +#: sssd.conf.5.xml:3804 msgid "dns_resolver_timeout (integer)" msgstr "dns_resolver_timeout (heltal)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3644 +#: sssd.conf.5.xml:3807 msgid "" "Defines the amount of time (in seconds) to wait for a reply from the " "internal fail over service before assuming that the service is unreachable. " "If this timeout is reached, the domain will continue to operate in offline " "mode." msgstr "" -"Definierar tiden (i sekunder) att vänta på ett svar från den interna " -"reservtjänsten före man antar att tjänsten inte kan nås. Om denna tidsgräns " -"nås kommer domänen fortsätta att fungera i frånkopplat läge." +"Anger hur länge (i sekunder) ett svar från den interna failover-tjänsten " +"inväntas innan tjänsten antas vara onåbar. Om tidsgränsen nås fortsätter " +"domänen att fungera i frånkopplat läge." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3662 -msgid "dns_resolver_use_search_list (bool)" +#: sssd.conf.5.xml:3841 +#, fuzzy +#| msgid "dns_resolver_use_search_list (bool)" +msgid "dns_resolver_use_search_list (boolean)" msgstr "dns_resolver_use_search_list (bool)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3665 +#: sssd.conf.5.xml:3844 msgid "" "Normally, the DNS resolver searches the domain list defined in the " "\"search\" directive from the resolv.conf file. This can lead to delays in " "environments with improperly configured DNS." msgstr "" -"Normalt söker DNS-uppslagaren domänlistan som är definierad i direktivet ”" -"search” från filen resolv.conf. Detta kan leda till fördröjningar i miljöer " +"Normalt söker DNS-uppslagaren i domänlistan som definieras av direktivet " +"\"search\" i filen resolv.conf. Detta kan leda till fördröjningar i miljöer " "med felaktigt konfigurerad DNS." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3671 +#: sssd.conf.5.xml:3850 msgid "" "If fully qualified domain names (or _srv_) are used in the SSSD " "configuration, setting this option to FALSE can prevent unnecessary DNS " @@ -5180,108 +5466,122 @@ msgstr "" "DNS-uppslagningar i sådana miljöer." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3677 +#: sssd.conf.5.xml:3856 msgid "Default: TRUE" msgstr "Standard: TRUE" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3683 +#: sssd.conf.5.xml:3862 msgid "dns_discovery_domain (string)" msgstr "dns_discovery_domain (sträng)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3686 +#: sssd.conf.5.xml:3865 msgid "" "If service discovery is used in the back end, specifies the domain part of " "the service discovery DNS query." msgstr "" -"Om tjänsteupptäckt används i bakänden anger domändelen av tjänstens DNS-" -"fråga om tjänsteupptäckt." +"Om tjänsteupptäckt används i den bakomliggande komponenten anger detta " +"domändelen av DNS-frågan för tjänsteupptäckt." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3690 +#: sssd.conf.5.xml:3869 msgid "Default: Use the domain part of machine's hostname" msgstr "Standard: använd domändelen av maskinens värdnamn" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3696 +#: sssd.conf.5.xml:3875 msgid "failover_primary_timeout (integer)" msgstr "failover_primary_timeout (heltal)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3699 +#: sssd.conf.5.xml:3878 msgid "" "When no primary server is available, SSSD fails over to a backup server. " "This option defines the number of seconds SSSD waits before attempting to " "reconnect to the primary server." msgstr "" -"När ingen primärserver är tillgänglig faller SSSD tillbaka på en " -"reservserver. Detta alternativ definierar antalet sekunder SSSD väntar före " -"den försöker återansluta till primärservern." +"När ingen primär server är tillgänglig växlar SSSD över till en " +"reservserver. Detta alternativ anger hur många sekunder SSSD väntar innan " +"det försöker återansluta till den primära servern." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3706 +#: sssd.conf.5.xml:3885 msgid "Note: The minimum value is 31." msgstr "Observera: minimivärdet är 31." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3709 +#: sssd.conf.5.xml:3888 msgid "Default: 31" msgstr "Standard: 31" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3715 +#: sssd.conf.5.xml:3894 msgid "override_gid (integer)" msgstr "override_gid (heltal)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3718 -msgid "Override the primary GID value with the one specified." +#: sssd.conf.5.xml:3897 +#, fuzzy +#| msgid "Override the primary GID value with the one specified." +msgid "" +"Override the primary GID value for all users in the domain with specified " +"value." msgstr "Ersätt det primära GID-värdet med det angivna." +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3901 +#, fuzzy +#| msgid "Default: not set (SSSD will use the value retrieved from LDAP)" +msgid "" +"Default: not set (Use the primary GID value retrieved from the identity " +"provider)" +msgstr "" +"Standard: inte angivet (SSSD kommer använda värdet som hämtats från LDAP)" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3724 +#: sssd.conf.5.xml:3908 msgid "case_sensitive (string)" msgstr "case_sensitive (sträng)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3731 +#: sssd.conf.5.xml:3915 msgid "True" msgstr "True" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3734 +#: sssd.conf.5.xml:3918 msgid "Case sensitive. This value is invalid for AD provider." msgstr "Skiftlägeskänsligt. Detta värde är inte giltigt för AD-leverantörer." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3740 +#: sssd.conf.5.xml:3924 msgid "False" msgstr "False" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3742 +#: sssd.conf.5.xml:3926 msgid "Case insensitive." msgstr "Skiftlägesokänsligt." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3746 +#: sssd.conf.5.xml:3930 msgid "Preserving" msgstr "Preserving" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3749 +#: sssd.conf.5.xml:3933 msgid "" "Same as False (case insensitive), but does not lowercase names in the result " "of NSS operations. Note that name aliases (and in case of services also " "protocol names) are still lowercased in the output." msgstr "" -"Samma som False (skiftlägesokänsligt), men skiftar inte ner namn i " -"resultaten från NSS-operationer. Observera att namnalias (och i fallet med " -"tjänster även protokollnamn) fortfarande skiftas ner i utdata." +"Samma som False (skiftlägesokänsligt), men omvandlar inte namn till gemener " +"i resultatet från NSS-operationer. Observera att namnalias och, för " +"tjänster, även protokollnamn fortfarande omvandlas till gemener i utdata." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3757 +#: sssd.conf.5.xml:3941 msgid "" "If you want to set this value for trusted domain with IPA provider, you need " "to set it on both the client and SSSD on the server." @@ -5290,121 +5590,151 @@ msgstr "" "du sätta det på både klienten och SSSD på servern." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3727 +#: sssd.conf.5.xml:3911 msgid "" "Treat user and group names as case sensitive. Possible option values are: " "<placeholder type=\"variablelist\" id=\"0\"/>" msgstr "" -"Behandla användar- och gruppnamn som skiftlägeskänsliga. De tillgängliga " -"värdena på alternativen är: <placeholder type=\"variablelist\" id=\"0\"/>" +"Behandla användar- och gruppnamn som skiftlägeskänsliga. Möjliga värden för " +"alternativet är: <placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3772 +#: sssd.conf.5.xml:3956 msgid "Default: True (False for AD provider)" msgstr "Standard: True (False för AD-leverantören)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3778 +#: sssd.conf.5.xml:3962 +#, fuzzy +#| msgid "verify_host (boolean)" +msgid "avoid_by_id_lookups (boolean)" +msgstr "verify_host (boolean)" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3965 +msgid "" +"If this option is set to 'true' SSSD will try to avoid sending lookups by ID " +"to the backend and will switch to a lookup by name if a cached object with a " +"matching ID can be found." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3971 +msgid "" +"This option can e.g. be used in cases where searches by ID are expensive on " +"the server side because of missing indexes or are not even possible, e.g. " +"due to non-reversible POSIX id-mapping." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3978 +#, fuzzy +#| msgid "Default: True (False for AD provider)" +msgid "Default: False (True for IdP provider)" +msgstr "Standard: True (False för AD-leverantören)" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:3984 msgid "subdomain_inherit (string)" msgstr "subdomain_inherit (sträng)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3781 +#: sssd.conf.5.xml:3987 msgid "" "Specifies a list of configuration parameters that should be inherited by a " "subdomain. Please note that only selected parameters can be inherited. " "Currently the following options can be inherited:" msgstr "" -"Anger en lista av konfigurationsparametrar som skall ärvas av underdomänen. " -"Observera att endast valda parametrar kan ärvas. För närvarande kan " +"Anger en lista med konfigurationsparametrar som ska ärvas av en underdomän. " +"Observera att endast utvalda parametrar kan ärvas. För närvarande kan " "följande alternativ ärvas:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3787 +#: sssd.conf.5.xml:3993 msgid "ldap_search_timeout" msgstr "ldap_search_timeout" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3790 +#: sssd.conf.5.xml:3996 msgid "ldap_network_timeout" msgstr "ldap_network_timeout" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3793 +#: sssd.conf.5.xml:3999 msgid "ldap_opt_timeout" msgstr "ldap_opt_timeout" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3796 +#: sssd.conf.5.xml:4002 msgid "ldap_offline_timeout" msgstr "ldap_offline_timeout" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3799 +#: sssd.conf.5.xml:4005 msgid "ldap_purge_cache_timeout" msgstr "ldap_purge_cache_timeout" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3802 +#: sssd.conf.5.xml:4008 msgid "ldap_purge_cache_offset" msgstr "ldap_purge_cache_offset" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3805 +#: sssd.conf.5.xml:4011 msgid "" "ldap_krb5_keytab (the value of krb5_keytab will be used if ldap_krb5_keytab " "is not set explicitly)" msgstr "" -"ldap_krb5_keytab (värdet på krb5_keytab kommer användas om inte " -"ldap_krb5_keytab sätts särskilt)" +"ldap_krb5_keytab (värdet för krb5_keytab används om ldap_krb5_keytab inte " +"uttryckligen anges)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3809 +#: sssd.conf.5.xml:4015 msgid "ldap_krb5_ticket_lifetime" msgstr "ldap_krb5_ticket_lifetime" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3812 +#: sssd.conf.5.xml:4018 msgid "ldap_connection_expire_timeout" msgstr "ldap_connection_expire_timeout" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3815 +#: sssd.conf.5.xml:4021 msgid "ldap_connection_expire_offset" msgstr "ldap_connection_expire_offset" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3818 +#: sssd.conf.5.xml:4024 msgid "ldap_connection_idle_timeout" msgstr "ldap_connection_idle_timeout" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3821 sssd-ldap.5.xml:446 +#: sssd.conf.5.xml:4027 sssd-ldap.5.xml:446 msgid "ldap_use_tokengroups" msgstr "ldap_use_tokengroups" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3824 +#: sssd.conf.5.xml:4030 msgid "ldap_user_principal" msgstr "ldap_user_principal" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3827 +#: sssd.conf.5.xml:4033 msgid "ignore_group_members" msgstr "ignore_group_members" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3830 +#: sssd.conf.5.xml:4036 msgid "auto_private_groups" msgstr "auto_private_groups" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3833 +#: sssd.conf.5.xml:4039 msgid "case_sensitive" msgstr "case_sensitive" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:3838 +#: sssd.conf.5.xml:4044 #, no-wrap msgid "" "subdomain_inherit = ldap_purge_cache_timeout\n" @@ -5414,28 +5744,28 @@ msgstr "" " " #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3845 +#: sssd.conf.5.xml:4051 msgid "Note: This option only works with the IPA and AD provider." msgstr "" "Observera: detta alternativ fungerar endast med leverantörerna IPA och AD." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3852 +#: sssd.conf.5.xml:4058 msgid "subdomain_homedir (string)" msgstr "subdomain_homedir (sträng)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3863 +#: sssd.conf.5.xml:4069 msgid "%F" msgstr "%F" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3864 +#: sssd.conf.5.xml:4070 msgid "flat (NetBIOS) name of a subdomain." -msgstr "platt (NetBIOS) namn på en underdomän." +msgstr "kort (NetBIOS-)namn för en underdomän." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3855 +#: sssd.conf.5.xml:4061 msgid "" "Use this homedir as default value for all subdomains within this domain in " "IPA AD trust. See <emphasis>override_homedir</emphasis> for info about " @@ -5444,47 +5774,53 @@ msgid "" "type=\"variablelist\" id=\"0\"/>" msgstr "" "Använd denna hemkatalog som standardvärde för alla underdomäner inom denna " -"domän i IPA AD-förtroende. Se <emphasis>override_homedir</emphasis> för " -"information om möjliga värden. Utöver dessa kan expansionen nedan endast " -"användas med <emphasis>subdomain_homedir</emphasis>. <placeholder " +"domän i ett IPA–AD-förtroende. Se <emphasis>override_homedir</emphasis> för " +"information om möjliga värden. Utöver dessa kan expansionen nedan endast " +"användas med <emphasis>subdomain_homedir</emphasis>. <placeholder " "type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3869 +#: sssd.conf.5.xml:4075 msgid "" "The value can be overridden by <emphasis>override_homedir</emphasis> option." msgstr "" "Värdet kan åsidosättas av alternativet <emphasis>override_homedir</emphasis>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3873 +#: sssd.conf.5.xml:4079 msgid "Default: <filename>/home/%d/%u</filename>" msgstr "Standard: <filename>/home/%d/%u</filename>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3878 +#: sssd.conf.5.xml:4084 msgid "realmd_tags (string)" msgstr "realmd_tags (sträng)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3881 +#: sssd.conf.5.xml:4087 msgid "" "Various tags stored by the realmd configuration service for this domain." msgstr "" -"Diverse taggar lagrade av realmd-konfigurationstjänsten för denna domän." +"Olika taggar som lagras av realmd-konfigurationstjänsten för denna domän." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3887 +#: sssd.conf.5.xml:4093 msgid "cached_auth_timeout (int)" msgstr "cached_auth_timeout (heltal)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3890 +#: sssd.conf.5.xml:4096 +#, fuzzy +#| msgid "" +#| "Specifies time in seconds since last successful online authentication for " +#| "which user will be authenticated using cached credentials while SSSD is " +#| "in the online mode. If the credentials are incorrect, SSSD falls back to " +#| "online authentication." msgid "" -"Specifies time in seconds since last successful online authentication for " -"which user will be authenticated using cached credentials while SSSD is in " -"the online mode. If the credentials are incorrect, SSSD falls back to online " -"authentication." +"Specifies the number of seconds since the last successful online " +"authentication during which SSSD will authenticate users via cached " +"credentials, even while online. If the cached authentication fails, SSSD " +"immediately falls back to online authentication." msgstr "" "Anger tiden i sekunder sedan senaste lyckade uppkopplade autentisering under " "vilka användaren kommer autentiseras med cachade kreditiv medan SSSD är i " @@ -5492,7 +5828,7 @@ msgstr "" "uppkopplad autentisering." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3898 +#: sssd.conf.5.xml:4103 msgid "" "This option's value is inherited by all trusted domains. At the moment it is " "not possible to set a different value per trusted domain." @@ -5501,28 +5837,28 @@ msgstr "" "inte möjligt att ange olika värden för varje betrodd domän." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3903 +#: sssd.conf.5.xml:4108 msgid "Special value 0 implies that this feature is disabled." msgstr "Specialvärdet 0 betyder att denna funktion är avaktiverad." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3907 +#: sssd.conf.5.xml:4112 msgid "" "Please note that if <quote>cached_auth_timeout</quote> is longer than " "<quote>pam_id_timeout</quote> then the back end could be called to handle " "<quote>initgroups.</quote>" msgstr "" "Observera att om <quote>cached_auth_timeout</quote> är längre än <quote>" -"pam_id_timeout</quote> kan bakänden anropas för att hantera <quote>" -"initgroups.</quote>" +"pam_id_timeout</quote> kan den bakomliggande komponenten anropas för att " +"hantera <quote>initgroups.</quote>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3918 +#: sssd.conf.5.xml:4123 msgid "local_auth_policy (string)" msgstr "local_auth_policy (sträng)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3921 +#: sssd.conf.5.xml:4126 msgid "" "Local authentication methods policy. Some backends (i.e. LDAP, proxy " "provider) only support a password based authentication, while others can " @@ -5532,16 +5868,17 @@ msgid "" "supported by the backend. With this option additional methods can be enabled " "which are evaluated and checked locally." msgstr "" -"Lokal policy för autentiseringsmetoder. Några bakändar (d.v.s. LDAP, proxy-" -"leverantör) stödjer endast en lösenordsbaserad autentisering, medan andra " -"kan hantera PKINIT-baserad smart-kort-autentisering (AD, IPA), " -"tvåfaktorsautentisering (IPA) eller andra metoder mot en central instans. " -"Som standard utförs i sådana fall autentiseringen endast med metoderna som " -"stödjs av bakänden. Med detta alternativ kan ytterligare metoder aktiveras " -"vilka utvärderas och kontrolleras lokalt." +"Policy för lokala autentiseringsmetoder. Vissa bakomliggande komponenter " +"(dvs. LDAP och proxyleverantören) stöder endast lösenordsbaserad " +"autentisering, medan andra kan hantera PKINIT-baserad " +"smartkortsautentisering (AD, IPA), tvåfaktorsautentisering (IPA) eller andra " +"metoder mot en central instans. Som standard utförs autentisering i sådana " +"fall endast med metoder som stöds av den bakomliggande komponenten. Med " +"detta alternativ kan ytterligare metoder aktiveras, vilka utvärderas och " +"kontrolleras lokalt." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3933 +#: sssd.conf.5.xml:4138 msgid "" "There are three possible values for this option: match, only, enable. " "<quote>match</quote> is used to match offline and online states for Kerberos " @@ -5551,76 +5888,82 @@ msgid "" "passkey for local authentication. Multiple enable values should be comma-" "separated, such as <quote>enable:passkey, enable:smartcard</quote>" msgstr "" -"Den finns tre möjliga värden för denna flagga: match, only, enable. <quote>" -"match</quote> används för att matcha frånkopplade och uppkopplade tillstånd " -"för Kerberosmetoder. <quote>only</quote> ignorerar de uppkopplade metoderna " -"och erbuder endast de lokala. enable tillåter explicit definition av " -"metoderna för lokal autentisering. Till exempel aktiverar <quote>" -"enable:passkey</quote> endast passkey för lokal autentisering. Flera enable-" -"värden skall vara kommaseparerade, såsom <quote>" -"enable:passkey,enable:smartcard</quote>" +"Det finns tre möjliga värden för detta alternativ: match, only och enable. " +"<quote>match</quote> används för att matcha frånkopplade och uppkopplade " +"tillstånd för Kerberosmetoder. <quote>only</quote> ignorerar onlinemetoderna " +"och erbjuder endast de lokala. enable gör det möjligt att uttryckligen ange " +"metoderna för lokal autentisering. <quote>enable:passkey</quote> aktiverar " +"till exempel endast passkey för lokal autentisering. Flera enable-värden ska " +"vara kommaseparerade, till exempel <quote>enable:passkey, enable:smartcard</" +"quote>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3946 +#: sssd.conf.5.xml:4151 msgid "" "The following table shows which authentication methods, if configured " "properly, are currently enabled or disabled for each backend, with the " "default local_auth_policy: <quote>match</quote>" msgstr "" -"Följande tabell visar vilka autentiseringsmetoder, om rätt konfigurerade, " -"som för närvarande är tillgängliga eller otillgängliga för varje bakände, " -"med standard local_auth_policy: <quote>match</quote>" +"Följande tabell visar vilka autentiseringsmetoder som, om de är korrekt " +"konfigurerade, för närvarande är aktiverade eller inaktiverade för varje " +"bakomliggande komponent med standardvärdet local_auth_policy: <quote>match</" +"quote>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> -#: sssd.conf.5.xml:3959 +#: sssd.conf.5.xml:4164 msgid "local_auth_policy = match (default)" -msgstr "local_auth_policy = match (standard)" +msgstr "local_auth_policy = match (default)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> -#: sssd.conf.5.xml:3960 +#: sssd.conf.5.xml:4165 msgid "Passkey" -msgstr "Lösennyckel" +msgstr "Passnyckel" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> -#: sssd.conf.5.xml:3961 +#: sssd.conf.5.xml:4166 msgid "Smartcard" msgstr "Smartkort" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:3964 sssd-ldap.5.xml:228 +#: sssd.conf.5.xml:4169 sssd-ldap.5.xml:228 msgid "IPA" msgstr "IPA" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry><para> +#: sssd.conf.5.xml:4169 sssd.conf.5.xml:4170 sssd.conf.5.xml:4173 +msgid "enabled" +msgstr "enabled" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:3967 sssd-ldap.5.xml:233 +#: sssd.conf.5.xml:4172 sssd-ldap.5.xml:233 msgid "AD" msgstr "AD" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry><para> -#: sssd.conf.5.xml:3967 sssd.conf.5.xml:3970 sssd.conf.5.xml:3971 +#: sssd.conf.5.xml:4172 sssd.conf.5.xml:4175 sssd.conf.5.xml:4176 msgid "disabled" -msgstr "avaktiverad" +msgstr "disabled" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry> -#: sssd.conf.5.xml:3970 +#: sssd.conf.5.xml:4175 msgid "LDAP" msgstr "LDAP" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3975 +#: sssd.conf.5.xml:4180 msgid "" "Please note that if local Smartcard authentication is enabled and a " "Smartcard is present, Smartcard authentication will be preferred over the " "authentication methods supported by the backend. I.e. there will be a PIN " "prompt instead of e.g. a password prompt." msgstr "" -"Observera att om lokal smart-korts-autentisering är aktiverat och ett smart-" -"kort finns tillgängligt kommer smart-korts-autentisering att föredras " -"framför autentiseringsmetoderna som stödjs av bakänden. D.v.s. det kommer " -"vara en PIN-prompt istället för t.ex. en lösenordsprompt." +"Observera att om lokal smartkortsautentisering är aktiverad och ett " +"smartkort finns tillgängligt, föredras smartkortsautentisering framför " +"autentiseringsmetoder som stöds av den bakomliggande komponenten. Det visas " +"alltså en PIN-kodsprompt i stället för exempelvis en lösenordsprompt." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:3987 +#: sssd.conf.5.xml:4192 #, no-wrap msgid "" "[domain/shadowutils]\n" @@ -5636,60 +5979,60 @@ msgstr "" "local_auth_policy = only\n" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3983 +#: sssd.conf.5.xml:4188 msgid "" "The following configuration example allows local users to authenticate " "locally using any enabled method (i.e. smartcard, passkey). <placeholder " "type=\"programlisting\" id=\"0\"/>" msgstr "" "Följande konfigurationsexempel tillåter lokala användare att autentisera " -"lokalt med alla aktiverade metoder (d.v.s. smartkard, passkey). <placeholder " -"type=\"programlisting\" id=\"0\"/>" +"lokalt med alla aktiverade metoder (dvs. smartkort och passkey). " +"<placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3995 +#: sssd.conf.5.xml:4200 msgid "Default: match" msgstr "Standard: match" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4000 +#: sssd.conf.5.xml:4205 msgid "auto_private_groups (string)" msgstr "auto_private_groups (sträng)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4006 +#: sssd.conf.5.xml:4211 msgid "true" msgstr "true" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4009 +#: sssd.conf.5.xml:4214 msgid "" "Create user's private group unconditionally from user's UID number. The GID " "number is ignored in this case." msgstr "" -"Skapa användares privata grupp ovillkorligt från användarens AID-nummer. " -"GID-numret ignoreras i detta läge." +"Skapa användarens privata grupp ovillkorligen från användarens UID-nummer. " +"GID-numret ignoreras i detta fall." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4013 +#: sssd.conf.5.xml:4218 msgid "" "NOTE: Because the GID number and the user private group are inferred from " "the UID number, it is not supported to have multiple entries with the same " "UID or GID number with this option. In other words, enabling this option " "enforces uniqueness across the ID space." msgstr "" -"OBSERVERA: Eftersom GID-numret och användarens privata grupp härleds från " -"AID-numret stödjs det inte att ha flera poster med samma AID- eller GID-" -"nummer med detta alternativ. Med andra ord, att aktivera detta alternativ " -"framtvingar unika nummer över hela ID-rymden." +"OBS! Eftersom GID-numret och användarens privata grupp härleds från UID-" +"numret stöds inte flera poster med samma UID- eller GID-nummer när detta " +"alternativ används. Med andra ord kräver aktivering av alternativet unika " +"värden i hela ID-rymden." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4022 +#: sssd.conf.5.xml:4227 msgid "false" msgstr "false" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4025 +#: sssd.conf.5.xml:4230 msgid "" "Always use the user's primary GID number. The GID number must refer to a " "group object in the LDAP database." @@ -5698,12 +6041,12 @@ msgstr "" "ett gruppobjekt i LDAP-databasen." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4031 +#: sssd.conf.5.xml:4236 msgid "hybrid" msgstr "hybrid" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4034 +#: sssd.conf.5.xml:4239 msgid "" "A primary group is autogenerated for user entries whose UID and GID numbers " "have the same value and at the same time the GID number does not correspond " @@ -5711,43 +6054,43 @@ msgid "" "GID in the user entry is also used by a group object, the primary GID of the " "user resolves to that group object." msgstr "" -"En primär grupp autogenereras för användarposter vars AID- och GID-nummer " -"har samma värde och GID-numret på samma gång inte motsvarar ett verkligt " -"gruppobjekt i LDAP. Om värdena är samma, men det primära GID:t i " -"användarposten även används av ett gruppobjekt slås användarens primära GID " -"upp till det gruppobjektet." +"En primär grupp genereras automatiskt för användarposter vars UID- och GID-" +"nummer har samma värde och där GID-numret samtidigt inte motsvarar ett " +"verkligt gruppobjekt i LDAP. Om värdena är samma men det primära GID:t i " +"användarposten även används av ett gruppobjekt, löses användarens primära " +"GID till det gruppobjektet." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4047 +#: sssd.conf.5.xml:4252 msgid "" "If the UID and GID of a user are different, then the GID must correspond to " "a group entry, otherwise the GID is simply not resolvable." msgstr "" -"Om användarens AID och GID är olika måste GID:t motsvara en gruppost, annars " -"kan GID:t helt enkelt inte slås upp." +"Om en användares UID och GID skiljer sig åt måste GID motsvara en gruppost, " +"annars kan GID helt enkelt inte lösas." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4054 +#: sssd.conf.5.xml:4259 msgid "" "This feature is useful for environments that wish to stop maintaining a " "separate group objects for the user private groups, but also wish to retain " "the existing user private groups." msgstr "" -"Denna funktion är användbar i miljöer som vill sluta underhålla separata " -"gruppobjekt för användares privata grupper, men även vill behålla de " -"befintliga användarnas privata grupper." +"Funktionen är användbar i miljöer som vill sluta underhålla separata " +"gruppobjekt för användarnas privata grupper men ändå behålla befintliga " +"privata användargrupper." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4003 +#: sssd.conf.5.xml:4208 msgid "" "This option takes any of three available values: <placeholder " "type=\"variablelist\" id=\"0\"/>" msgstr "" -"Detta alternativ tar något av tre tillgängliga värden: <placeholder " +"Detta alternativ kan ha ett av tre tillgängliga värden: <placeholder " "type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4066 +#: sssd.conf.5.xml:4271 msgid "" "For the LDAP based id providers (LDAP, IPA and AD) the default for the " "configured domain is typically False because the sources have the concept of " @@ -5757,12 +6100,12 @@ msgid "" msgstr "" "För LDAP-baserade ID-leverantörer (LDAP, IPA och AD) är " "standardinställningen för den konfigurerade domänen vanligtvis False, " -"eftersom källorna har begreppet primär grupp. <phrase " +"eftersom källorna har begreppet primär grupp. <phrase " "condition=\"with_idp_provider\"> IdP-ID-leverantören använder True eftersom " "IdP:er vanligtvis inte har primära grupper.</phrase>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4075 +#: sssd.conf.5.xml:4280 msgid "" "For subdomains, the default value is False for subdomains that use assigned " "POSIX IDs and True for subdomains that use automatic ID-mapping." @@ -5772,7 +6115,7 @@ msgstr "" "översättning." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:4083 +#: sssd.conf.5.xml:4288 #, no-wrap msgid "" "[domain/forest.domain/sub.domain]\n" @@ -5782,7 +6125,7 @@ msgstr "" "auto_private_groups = false\n" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:4089 +#: sssd.conf.5.xml:4294 #, no-wrap msgid "" "[domain/forest.domain]\n" @@ -5794,7 +6137,7 @@ msgstr "" "auto_private_groups = false\n" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4080 +#: sssd.conf.5.xml:4285 msgid "" "The value of auto_private_groups can either be set per subdomains in a " "subsection, for example: <placeholder type=\"programlisting\" id=\"0\"/> or " @@ -5808,44 +6151,44 @@ msgstr "" "id=\"1\"/>" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:2503 +#: sssd.conf.5.xml:2549 msgid "" "These configuration options can be present in a domain configuration " "section, that is, in a section called <quote>[domain/<replaceable>NAME</" "replaceable>]</quote> <placeholder type=\"variablelist\" id=\"0\"/>" msgstr "" "Dessa konfigurationsalternativ kan finnas i en domänkonfigurationssektion, " -"det vill säga en sektion som heter <quote>[domain/<replaceable>NAMN</" -"replaceable>]</quote> <placeholder type=\"variablelist\" id=\"0\"/>" +"det vill säga en sektion med namnet <quote>[domain/<replaceable>NAME</" +"replaceable>]</quote>. <placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4104 +#: sssd.conf.5.xml:4309 msgid "proxy_pam_target (string)" msgstr "proxy_pam_target (sträng)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4107 +#: sssd.conf.5.xml:4312 msgid "The proxy target PAM proxies to." -msgstr "Proxymålet PAM är en proxy för." +msgstr "PAM-målet som proxyn vidarebefordrar till." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4110 +#: sssd.conf.5.xml:4315 msgid "" "Default: not set by default, you have to take an existing pam configuration " "or create a new one and add the service name here. As an alternative you can " "enable local authentication with the local_auth_policy option." msgstr "" -"Standard: inte satt som standard, du måste ta en befintlig pam-konfiguration " -"eller skapa en ny och lägga till tjänstenamnet här. Som ett alternativ kan " -"man aktivera lokal autentisering med alternativet local_auth_policy." +"Standard: inte angivet. Du måste använda en befintlig pam-konfiguration " +"eller skapa en ny och lägga till tjänstenamnet här. Alternativt kan du " +"aktivera lokal autentisering med alternativet local_auth_policy." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4120 +#: sssd.conf.5.xml:4325 msgid "proxy_lib_name (string)" msgstr "proxy_lib_name (sträng)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4123 +#: sssd.conf.5.xml:4328 msgid "" "The name of the NSS library to use in proxy domains. The NSS functions " "searched for in the library are in the form of _nss_$(libName)_$(function), " @@ -5856,12 +6199,12 @@ msgstr "" "exempel _nss_files_getpwent." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4133 +#: sssd.conf.5.xml:4338 msgid "proxy_resolver_lib_name (string)" msgstr "proxy_resolver_lib_name (sträng)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4136 +#: sssd.conf.5.xml:4341 msgid "" "The name of the NSS library to use for hosts and networks lookups in proxy " "domains. The NSS functions searched for in the library are in the form of " @@ -5872,42 +6215,42 @@ msgstr "" "_nss_$(libName)_$(function), till exempel _nss_dns_gethostbyname2_r." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4147 +#: sssd.conf.5.xml:4352 msgid "proxy_fast_alias (boolean)" msgstr "proxy_fast_alias (boolean)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4150 +#: sssd.conf.5.xml:4355 msgid "" "When a user or group is looked up by name in the proxy provider, a second " "lookup by ID is performed to \"canonicalize\" the name in case the requested " "name was an alias. Setting this option to true would cause the SSSD to " "perform the ID lookup from cache for performance reasons." msgstr "" -"När en användare eller grupp slås upp efter namn i proxy-leverantören görs " -"en andra uppslagning efter ID för att \"kanonisera\" namnet i händelse det " -"begärda namnet var ett alias. Att sätta detta alternativ till sant skulle få " -"SSSD att utföra ID-uppslagningen från cachen av prestandaskäl." +"När en användare eller grupp slås upp efter namn i proxyleverantören görs en " +"andra uppslagning efter ID för att ”kanonisera” namnet om det begärda namnet " +"var ett alias. Att sätta detta alternativ till true gör att SSSD utför ID-" +"uppslagningen från cachen av prestandaskäl." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4164 +#: sssd.conf.5.xml:4369 msgid "proxy_max_children (integer)" msgstr "proxy_max_children (heltal)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4167 +#: sssd.conf.5.xml:4372 msgid "" "This option specifies the number of pre-forked proxy children. It is useful " "for high-load SSSD environments where sssd may run out of available child " "slots, which would cause some issues due to the requests being queued." msgstr "" -"Detta alternativ anger antalet i förhand avgrenade proxy-barn. Det är " -"användbart för SSSD-miljöer med hög last där sssd kan få slut på " -"tillgängliga barnfack, vilket skulle orsaka problem på grund av att " -"begäranden skulle köas upp." +"Detta alternativ anger antalet förgrenade proxy-barnprocesser. Det är " +"användbart i SSSD-miljöer med hög belastning där sssd kan få slut på " +"tillgängliga barnprocessplatser, vilket kan orsaka problem eftersom " +"begäranden köas." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4100 +#: sssd.conf.5.xml:4305 msgid "" "Options valid for proxy domains. <placeholder type=\"variablelist\" " "id=\"0\"/>" @@ -5916,12 +6259,12 @@ msgstr "" "id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:4183 +#: sssd.conf.5.xml:4388 msgid "Application domains" msgstr "Programdomäner" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:4185 +#: sssd.conf.5.xml:4390 msgid "" "SSSD, with its D-Bus interface (see <citerefentry> <refentrytitle>sssd-ifp</" "refentrytitle> <manvolnum>5</manvolnum> </citerefentry>) is appealing to " @@ -5936,21 +6279,20 @@ msgid "" "<quote>application</quote> optionally inherits settings from a tradition " "SSSD domain." msgstr "" -"SSSD, med sitt D-Bus-gränssnitt (se <citerefentry> <refentrytitle>sssd-ifp</" -"refentrytitle> <manvolnum>5</manvolnum> </citerefentry>) är tilltalande för " -"program som en portgång till en LDAP-katalog där användare och grupper " -"lagras. Dock, tvärtemot den traditionella SSSD-installationen där alla " -"användare och grupper antingen har POSIX-attribut eller så kan dessa " -"attribut härledas Windows-SID:arna, har i många fall användarna och " -"grupperna i programstödsscenariot inga POSIX-attribut. Istället för att " -"göra en sektion <quote>[domain/<replaceable>NAMN</replaceable>]</quote> kan " -"administratören skapa en sektion <quote>[application/<replaceable>NAMN</" -"replaceable>]</quote> som internt representerar en domän med typen <quote>" -"application</quote> och eventuellt ärver inställningar från en traditionell " -"SSSD-domän." +"SSSD med sitt D-Bus-gränssnitt (se <citerefentry> <refentrytitle>sssd-ifp</" +"refentrytitle> <manvolnum>5</manvolnum> </citerefentry>) är användbart för " +"program som en gateway till en LDAP-katalog där användare och grupper " +"lagras. Till skillnad från en traditionell SSSD-installation, där alla " +"användare och grupper antingen har POSIX-attribut eller kan få dem härledda " +"från Windows-SID:er, saknar användare och grupper i programscenariot ofta " +"POSIX-attribut. I stället för en sektion <quote>[domain/<replaceable>NAME</" +"replaceable>]</quote> kan administratören skapa en sektion <quote>" +"[application/<replaceable>NAME</replaceable>]</quote> som internt " +"representerar en domän av typen <quote>application</quote> och som valfritt " +"ärver inställningar från en traditionell SSSD-domän." #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:4205 +#: sssd.conf.5.xml:4410 msgid "" "Please note that the application domain must still be explicitly enabled in " "the <quote>domains</quote> parameter so that the lookup order between the " @@ -5961,17 +6303,17 @@ msgstr "" "programdomänen och dess POSIX-syskondomän sätts korrekt." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><title> -#: sssd.conf.5.xml:4211 +#: sssd.conf.5.xml:4416 msgid "Application domain parameters" msgstr "Programdomänparametrar" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4213 +#: sssd.conf.5.xml:4418 msgid "inherit_from (string)" msgstr "inherit_from (sträng)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4216 +#: sssd.conf.5.xml:4421 msgid "" "The SSSD POSIX-type domain the application domain inherits all settings " "from. The application domain can moreover add its own settings to the " @@ -5979,12 +6321,12 @@ msgid "" "domain settings." msgstr "" "Den SSSD-domän av POSIX-typ som programdomänen ärver alla inställningar " -"ifrån. Programdomänen kan dessutom lägga till sina egna inställningar till " -"programinställningarna som kompletterar eller åsidosätter <quote>syskon</" -"quote>domänens inställningar." +"från. Programdomänen kan dessutom lägga till egna inställningar till " +"programinställningarna, vilka kompletterar eller åsidosätter inställningarna " +"för domänen <quote>sibling</quote>." #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:4230 +#: sssd.conf.5.xml:4435 msgid "" "The following example illustrates the use of an application domain. In this " "setup, the POSIX domain is connected to an LDAP server and is used by the OS " @@ -5999,7 +6341,7 @@ msgstr "" "attributet telefon nåbart via D-Bus-gränssnittet." #. type: Content of: <reference><refentry><refsect1><refsect2><programlisting> -#: sssd.conf.5.xml:4238 +#: sssd.conf.5.xml:4443 #, no-wrap msgid "" "[sssd]\n" @@ -6018,27 +6360,27 @@ msgid "" "ldap_user_extra_attrs = phone:telephoneNumber\n" msgstr "" "[sssd]\n" -"domains = progdom, posixdom\n" +"domains = appdom, posixdom\n" "\n" "[ifp]\n" -"user_attributes = +telefon\n" +"user_attributes = +phone\n" "\n" "[domain/posixdom]\n" "id_provider = ldap\n" -"ldap_uri = ldap://ldap.exempel.se\n" +"ldap_uri = ldap://ldap.example.com\n" "ldap_search_base = dc=example,dc=com\n" "\n" -"[application/progdom]\n" +"[application/appdom]\n" "inherit_from = posixdom\n" -"ldap_user_extra_attrs = telefon:telephoneNumber\n" +"ldap_user_extra_attrs = phone:telephoneNumber\n" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:4258 +#: sssd.conf.5.xml:4463 msgid "TRUSTED DOMAIN SECTION" msgstr "SEKTIONEN BETRODDA DOMÄNER" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4260 +#: sssd.conf.5.xml:4465 msgid "" "Some options used in the domain section can also be used in the trusted " "domain section, that is, in a section called <quote>[domain/" @@ -6047,65 +6389,75 @@ msgid "" "domain. Please refer to examples below for explanation. Currently supported " "options in the trusted domain section are:" msgstr "" -"Några alternativ som används i domänsektionen kan även användas i sektionen " -"för betrodda domäner, det vill säga, i en sektion som heter <quote>[domain/" -"<replaceable>DOMÄNNAMN</replaceable>/<replaceable>NAMN_PÅ_BETRODD_DOMÄN</" -"replaceable>]</quote>. Där DOMÄNNAMN är den aktuella basdomänen som " -"anslutits till. Se exempel nedan för förklaring. För närvarande stödda " -"alternativ i sektionen för betrodda domäner är:" +"Vissa alternativ som används i domänsektionen kan även användas i sektionen " +"för betrodda domäner, det vill säga i en sektion med namnet <quote>[domain/" +"<replaceable>DOMAIN_NAME</replaceable>/<replaceable>TRUSTED_DOMAIN_NAME</" +"replaceable>]</quote>. DOMAIN_NAME är den faktiska basdomän som anslutits " +"till. Se exemplen nedan för förklaring. För närvarande stöds följande " +"alternativ i sektionen för betrodda domäner:" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4267 +#: sssd.conf.5.xml:4472 msgid "ldap_search_base," msgstr "ldap_search_base," #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4268 +#: sssd.conf.5.xml:4473 msgid "ldap_user_search_base," msgstr "ldap_user_search_base," #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4269 +#: sssd.conf.5.xml:4474 msgid "ldap_group_search_base," msgstr "ldap_group_search_base," #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4270 +#: sssd.conf.5.xml:4475 msgid "ldap_netgroup_search_base," msgstr "ldap_netgroup_search_base," #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4271 +#: sssd.conf.5.xml:4476 msgid "ldap_service_search_base," msgstr "ldap_service_search_base," #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4272 +#: sssd.conf.5.xml:4477 msgid "ldap_sasl_mech," msgstr "ldap_sasl_mech," #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4273 +#: sssd.conf.5.xml:4478 msgid "ad_server," msgstr "ad_server," #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4274 +#: sssd.conf.5.xml:4479 msgid "ad_backup_server," msgstr "ad_backup_server," #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4275 +#: sssd.conf.5.xml:4480 msgid "ad_site," msgstr "ad_site," #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:4276 sssd-ipa.5.xml:934 +#: sssd.conf.5.xml:4481 sssd-ipa.5.xml:929 msgid "use_fully_qualified_names" msgstr "use_fully_qualified_names" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4280 +#: sssd.conf.5.xml:4482 +msgid "pam_gssapi_services" +msgstr "pam_gssapi_services" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:4483 +msgid "pam_gssapi_check_upn" +msgstr "pam_gssapi_check_upn" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:4485 msgid "" "For more details about these options see their individual description in the " "manual page." @@ -6114,12 +6466,12 @@ msgstr "" "manualsidan." #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:4286 +#: sssd.conf.5.xml:4491 msgid "CERTIFICATE MAPPING SECTION" msgstr "CERTIFIKATSMAPPNINGSSEKTION" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4288 +#: sssd.conf.5.xml:4493 msgid "" "To allow authentication with Smartcards and certificates SSSD must be able " "to map certificates to users. This can be done by adding the full " @@ -6131,75 +6483,73 @@ msgid "" "where local services use PAM for authentication." msgstr "" "För att tillåta autentisering med smartkort och certifikat måste SSSD kunna " -"översätta certifikat till användare. Detta kan göras genom att lägga till " -"det fullständiga certifikatet till användarens LDAP-objekt eller till en " -"lokal ersättning. Medan det krävs att man använder det fullständiga " -"certifikatet för att använda funktionen smartkortsautentisering i SSH (se " -"<citerefentry> <refentrytitle>sss_ssh_authorizedkeys</refentrytitle> " -"<manvolnum>8</manvolnum> </citerefentry> för detaljer) kan det vara " -"besvärligt eller kanske inte ens möjligt att använda detta i det allmänna " -"fallet när lokala tjänster använder PAM för autentisering." +"mappa certifikat till användare. Detta kan göras genom att lägga till hela " +"certifikatet i användarens LDAP-objekt eller i en lokal åsidosättning. Att " +"använda hela certifikatet krävs för SSH:s smartkortsautentiseringsfunktion " +"(se <citerefentry> <refentrytitle>sss_ssh_authorizedkeys</refentrytitle> " +"<manvolnum>8</manvolnum> </citerefentry> för mer information), men kan vara " +"besvärligt eller till och med omöjligt i det allmänna fallet där lokala " +"tjänster använder PAM för autentisering." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4302 +#: sssd.conf.5.xml:4507 msgid "" "To make the mapping more flexible mapping and matching rules were added to " "SSSD (see <citerefentry> <refentrytitle>sss-certmap</refentrytitle> " "<manvolnum>5</manvolnum> </citerefentry> for details)." msgstr "" -"För att göra översättningen mer flexibel lades översättnings- och " -"matchningsregler till till SSSD (se <citerefentry> <refentrytitle>sss-" -"certmap</refentrytitle> <manvolnum>5</manvolnum> </citerefentry> för " -"detaljer)." +"För att göra mappningen mer flexibel har mappnings- och matchningsregler " +"lagts till i SSSD (se <citerefentry> <refentrytitle>sss-certmap</" +"refentrytitle> <manvolnum>5</manvolnum> </citerefentry> för mer information)." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4311 +#: sssd.conf.5.xml:4516 msgid "" "A mapping and matching rule can be added to the SSSD configuration in a " "section on its own with a name like <quote>[certmap/" "<replaceable>DOMAIN_NAME</replaceable>/<replaceable>RULE_NAME</" "replaceable>]</quote>. In this section the following options are allowed:" msgstr "" -"En översättnings- och matchningsregel kan läggas till till SSSD-" -"konfigurationen i en egen sektion för sig själv med ett namn som <quote>" -"[certmap/<replaceable>DOMÄNNAMN</replaceable>/<replaceable>REGELNAMN</" -"replaceable>]</quote>. I denna sektion är följande alternativ tillåtna:" +"En mappnings- och matchningsregel kan läggas till i SSSD-konfigurationen i " +"en egen sektion med ett namn som <quote>[certmap/<replaceable>DOMAIN_NAME</" +"replaceable>/<replaceable>RULE_NAME</replaceable>]</quote>. I denna sektion " +"är följande alternativ tillåtna:" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4318 +#: sssd.conf.5.xml:4523 msgid "matchrule (string)" msgstr "matchrule (sträng)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4321 +#: sssd.conf.5.xml:4526 msgid "" "Only certificates from the Smartcard which matches this rule will be " "processed, all others are ignored." msgstr "" -"Endast certifikat från smartkort som matchar denna regel kommer bearbetas, " -"alla andra ignoreras." +"Endast certifikat från smartkortet som matchar denna regel behandlas; alla " +"andra ignoreras." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4325 +#: sssd.conf.5.xml:4530 msgid "" "Default: KRB5:<EKU>clientAuth, i.e. only certificates which have the " "Extended Key Usage <quote>clientAuth</quote>" msgstr "" -"Standard: KRB5:<EKU>clientAuth, d.v.s. endast certifikat som har " -"Extended Key Usage <quote>clientAuth</quote>" +"Standard: KRB5:<EKU>clientAuth, dvs. endast certifikat som har " +"Extended Key Usage <quote>clientAuth</quote>." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4332 +#: sssd.conf.5.xml:4537 msgid "maprule (string)" msgstr "maprule (sträng)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4335 +#: sssd.conf.5.xml:4540 msgid "Defines how the user is found for a given certificate." msgstr "Definierar hur användaren hittas för ett givet certifikat." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:4341 +#: sssd.conf.5.xml:4546 msgid "" "LDAP:(userCertificate;binary={cert!bin}) for LDAP based providers like " "<quote>ldap</quote>, <quote>AD</quote> or <quote>ipa</quote>." @@ -6208,44 +6558,39 @@ msgstr "" "<quote>ldap</quote>, <quote>AD</quote> eller <quote>ipa</quote>." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:4347 +#: sssd.conf.5.xml:4552 msgid "" "If maprule is not set and provider is <quote>proxy</quote>, the RULE_NAME " "name is assumed to be the name of the matching user." msgstr "" -"Om maprule inte är inställt och provider är <quote>proxy</quote>, antas " -"REGELNAMN-namnet vara namnet på den matchande användaren." - -#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4357 -msgid "domains (string)" -msgstr "domains (sträng)" +"Om maprule inte är angivet och provider är <quote>proxy</quote>, antas " +"namnet RULE_NAME vara namnet på den matchande användaren." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4360 +#: sssd.conf.5.xml:4565 msgid "" "Comma separated list of domain names the rule should be applied. By default " "a rule is only valid in the domain configured in sssd.conf. If the provider " "supports subdomains this option can be used to add the rule to subdomains as " "well." msgstr "" -"Kommaseparerad lista av domännamn regeln skall användas på. Som standard är " -"endast en regel giltig i domänen där den är konfigurerad i sssd.conf. Om " -"leverantören stödjer underdomäner kan detta alternativ användas för att " -"lägga till regeln till underdomäner också." +"Kommaseparerad lista med domännamn som regeln ska tillämpas på. Som standard " +"är en regel endast giltig i domänen som konfigurerats i sssd.conf. Om " +"leverantören stöder underdomäner kan detta alternativ även användas för att " +"lägga till regeln i underdomäner." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4367 +#: sssd.conf.5.xml:4572 msgid "Default: the configured domain in sssd.conf" msgstr "Standard: den konfigurerade domänen i sssd.conf" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4372 +#: sssd.conf.5.xml:4577 msgid "priority (integer)" msgstr "priority (heltal)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4375 +#: sssd.conf.5.xml:4580 msgid "" "Unsigned integer value defining the priority of the rule. The higher the " "number the lower the priority. <quote>0</quote> stands for the highest " @@ -6256,17 +6601,17 @@ msgstr "" "prioriteten medan <quote>4294967295</quote> är den lägsta." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4381 +#: sssd.conf.5.xml:4586 msgid "Default: the lowest priority" msgstr "Standard: den lägsta prioriteten" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:4389 +#: sssd.conf.5.xml:4594 msgid "PROMPTING CONFIGURATION SECTION" msgstr "SEKTIONEN FÖR FRÅGEKONFIGURATION" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4391 +#: sssd.conf.5.xml:4596 msgid "" "If a special file (<filename>/var/lib/sss/pubconf/pam_preauth_available</" "filename>) exists SSSD's PAM module pam_sss will ask SSSD to figure out " @@ -6275,41 +6620,41 @@ msgid "" "credentials." msgstr "" "Om en särskild fil (<filename>/var/lib/sss/pubconf/pam_preauth_available</" -"filename>) finns kommer SSSD:s PAM-modul pam_sss be SSSD att ta reda på " -"vilka autentiseringsmetoder som är tillgängliga för användaren som försöker " -"logga in. Baserat på resultatet kommer pam_sss fråga användaren efter " -"tillämpliga kreditiv." +"filename>) finns ber SSSD:s PAM-modul pam_sss SSSD att avgöra vilka " +"autentiseringsmetoder som är tillgängliga för användaren som försöker logga " +"in. Utifrån resultatet frågar pam_sss användaren efter lämpliga " +"autentiseringsuppgifter." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4399 +#: sssd.conf.5.xml:4604 msgid "" "With the growing number of authentication methods and the possibility that " "there are multiple ones for a single user the heuristic used by pam_sss to " "select the prompting might not be suitable for all use cases. The following " "options should provide a better flexibility here." msgstr "" -"Med det växande antalet autentiseringsmetoder och möjligheten att det finns " -"flera olika för en enskild användare kan det hända att heuristiken som " -"används av pam_sss för att välja fråga inte är lämplig för alla " -"användarfall. Följande alternativ bör ge en bättre flexibilitet här." +"Med det växande antalet autentiseringsmetoder och möjligheten att flera " +"metoder finns för en enskild användare kanske heuristiken som pam_sss " +"använder för att välja fråga inte passar alla användningsfall. Följande " +"alternativ ger bättre flexibilitet." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4411 +#: sssd.conf.5.xml:4616 msgid "[prompting/password]" msgstr "[prompting/password]" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4414 +#: sssd.conf.5.xml:4619 msgid "password_prompt" msgstr "password_prompt" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4415 +#: sssd.conf.5.xml:4620 msgid "to change the string of the password prompt" msgstr "för att ändra strängen i lösenordsfrågan" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4413 +#: sssd.conf.5.xml:4618 msgid "" "to configure password prompting, allowed options are: <placeholder " "type=\"variablelist\" id=\"0\"/>" @@ -6318,63 +6663,63 @@ msgstr "" "type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4423 +#: sssd.conf.5.xml:4628 msgid "[prompting/2fa]" msgstr "[prompting/2fa]" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4427 +#: sssd.conf.5.xml:4632 msgid "first_prompt" msgstr "first_prompt" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4428 +#: sssd.conf.5.xml:4633 msgid "to change the string of the prompt for the first factor" msgstr "för att ändra strängen som frågar efter den första faktorn" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4431 +#: sssd.conf.5.xml:4636 msgid "second_prompt" msgstr "second_prompt" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4432 +#: sssd.conf.5.xml:4637 msgid "to change the string of the prompt for the second factor" msgstr "för att ändra strängen som frågar efter den andra faktorn" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4435 +#: sssd.conf.5.xml:4640 msgid "single_prompt" msgstr "single_prompt" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4436 +#: sssd.conf.5.xml:4641 msgid "" "boolean value, if True there will be only a single prompt using the value of " "first_prompt where it is expected that both factors are entered as a single " "string. Please note that both factors have to be entered here, even if the " "second factor is optional." msgstr "" -"booleskt värde, om True kommer det bara vara en fråga som använder värdet på " -"first_prompt där det förväntas att båda faktorerna matas in som en enda " -"sträng. Observera att båda faktorerna måste anges här, även om den andra " -"faktorn är frivillig." +"Booleskt värde. Om True visas endast en fråga som använder värdet för " +"first_prompt, och båda faktorerna förväntas anges som en enda sträng. " +"Observera att båda faktorerna måste anges här, även om den andra faktorn är " +"valfri." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4425 +#: sssd.conf.5.xml:4630 msgid "" "to configure two-factor authentication prompting, allowed options are: " "<placeholder type=\"variablelist\" id=\"0\"/> If the second factor is " "optional and it should be possible to log in either only with the password " "or with both factors two-step prompting has to be used." msgstr "" -"för att konfigurera efterfrågan av tvåfaktorautentisering är de tillåtna " -"flaggorna: <placeholder type=\"variablelist\" id=\"0\"/> Om den andra " -"faktorn är frivillig och det skall vara möjligt att logga in antingen edast " -"med lösenordet eller med båda faktorerna måste tvåstegsförfrågan användas." +"för att konfigurera frågor för tvåfaktorsautentisering. Tillåtna alternativ " +"är: <placeholder type=\"variablelist\" id=\"0\"/>. Om den andra faktorn är " +"valfri och det ska vara möjligt att logga in antingen endast med lösenordet " +"eller med båda faktorerna måste tvåstegsfråga användas." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4449 +#: sssd.conf.5.xml:4654 msgid "" "Some clients, such as SSH with 'PasswordAuthentication yes', generate their " "own prompts and do not use prompts provided by SSSD or other PAM modules. " @@ -6383,108 +6728,218 @@ msgid "" "the user at the SSH password prompt will always be the two factors in a " "single string, even if two-factor authentication is optional." msgstr "" -"Några klienter, såsom SSH med ”PasswordAuthentication yes”, skapar sina egna " -"prompter och använder inte prompten som ges av SSSD eller andra PAM-moduler. " -"Vidare, för SSH med PasswordAuthentication, om tvåfaktorsautentisering är " -"tillgängligt förväntar sig SSSD att kreditiven som anges av användaren fid " -"SSH-lösenordsprompten alltid kommer vara de två faktorerna som en enda " -"sträng, även om tvåfaktorsautentisering är frivillig." +"Vissa klienter, till exempel SSH med 'PasswordAuthentication yes', genererar " +"egna frågor och använder inte frågor från SSSD eller andra PAM-moduler. Om " +"tvåfaktorsautentisering är tillgänglig förväntar sig SSSD dessutom, vid SSH " +"med PasswordAuthentication, att autentiseringsuppgifterna som användaren " +"anger vid SSH-lösenordsfrågan alltid består av de två faktorerna i en enda " +"sträng, även om tvåfaktorsautentisering är valfri." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4464 +#: sssd.conf.5.xml:4669 msgid "[prompting/passkey]" msgstr "[prompting/passkey]" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:4470 sssd-ad.5.xml:1022 +#: sssd.conf.5.xml:4675 sssd.conf.5.xml:4719 sssd-ad.5.xml:1027 msgid "interactive" msgstr "interactive" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4472 +#: sssd.conf.5.xml:4677 msgid "" "boolean value, if True prompt a message and wait before testing the presence " "of a passkey device. Recommended if your device doesn’t have a tactile " "trigger." msgstr "" -"booleskt värde, om True skriv ett meddelande och vänta före test av närvaron " -"av en lösennyckelsenhet. Rekommenderas om enheten inte har en taktil " +"Booleskt värde. Om True, visa ett meddelande och vänta innan förekomsten av " +"en passnyckelenhet kontrolleras. Rekommenderas om enheten saknar en taktil " "utlösare." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4480 +#: sssd.conf.5.xml:4685 sssd.conf.5.xml:4735 msgid "interactive_prompt" msgstr "interactive_prompt" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4482 +#: sssd.conf.5.xml:4687 sssd.conf.5.xml:4737 msgid "to change the message of the interactive prompt." msgstr "för att ändra meddelandet i den interaktiva frågan." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4487 +#: sssd.conf.5.xml:4692 msgid "touch" msgstr "touch" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4489 +#: sssd.conf.5.xml:4694 msgid "" "boolean value, if True prompt a message to remind the user to touch the " "device." msgstr "" -"booleskt värde, om sant skriv ett meddelande och påminn användaren att röra " -"enheten." +"Booleskt värde. Om True, visa ett meddelande som påminner användaren om att " +"vidröra enheten." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4495 +#: sssd.conf.5.xml:4700 msgid "touch_prompt" msgstr "touch_prompt" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4497 +#: sssd.conf.5.xml:4702 msgid "to change the message of the touch prompt." -msgstr "för att ändra meddelandet i begäran om beröring." +msgstr "för att ändra meddelandet i beröringsfrågan." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4466 +#: sssd.conf.5.xml:4671 msgid "" "to configure passkey authentication prompting, allowed options are: " "<placeholder type=\"variablelist\" id=\"0\"/>" msgstr "" +"för att konfigurera frågor för passnyckelautentisering. Tillåtna alternativ " +"är: <placeholder type=\"variablelist\" id=\"0\"/>." + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4713 +#, fuzzy +#| msgid "[prompting/2fa]" +msgid "[prompting/oauth2]" +msgstr "[prompting/2fa]" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4721 +#, fuzzy +#| msgid "" +#| "boolean value, if True prompt a message to remind the user to touch the " +#| "device." +msgid "" +"boolean value, if True prompt a message after asking the user to " +"authenticate, and wait before requesting the access token." +msgstr "" +"booleskt värde, om sant skriv ett meddelande och påminn användaren att röra " +"enheten." + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4725 +msgid "" +"If False, make sure to set the <quote>idp_request_timeout</quote> " +"sufficiently high, to give the user time to authenticate." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4715 +#, fuzzy +#| msgid "" +#| "to configure passkey authentication prompting, allowed options are: " +#| "<placeholder type=\"variablelist\" id=\"0\"/>" +msgid "" +"to configure OAuth2 authentication prompting, allowed options are: " +"<placeholder type=\"variablelist\" id=\"0\"/>" +msgstr "" +"för att konfigurera frågor för lösennyckelsautentisering är de tillåtna " +"alternativen: <placeholder type=\"variablelist\" id=\"0\"/>" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4748 +#, fuzzy +#| msgid "[prompting/2fa]" +msgid "[prompting/cert_auth]" +msgstr "[prompting/2fa]" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4754 +#, fuzzy +#| msgid "single_prompt" +msgid "pin_prompt" +msgstr "single_prompt" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4756 +msgid "" +"to change the message which asks the user to enter the PIN at the computer " +"keyboard. At the end of the message the token name is printed." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4764 +#, fuzzy +#| msgid "password_prompt" +msgid "keypad_prompt" +msgstr "password_prompt" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4766 +msgid "" +"to change the message which asks the user to enter the PIN at keypad of the " +"Smartcard reader. At the end of the message the token name is printed." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4774 +#, fuzzy +#| msgid "username" +msgid "user_name_hint" +msgstr "användarnamn" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4776 +msgid "" +"boolean value, if True ask for a user name if no name was given before and " +"the found certificate can be mapped to more than one user." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4750 +#, fuzzy +#| msgid "" +#| "to configure passkey authentication prompting, allowed options are: " +#| "<placeholder type=\"variablelist\" id=\"0\"/>" +msgid "" +"to configure Smartcard authentication prompting, allowed options are: " +"<placeholder type=\"variablelist\" id=\"0\"/>" +msgstr "" "för att konfigurera frågor för lösennyckelsautentisering är de tillåtna " "alternativen: <placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4406 +#: sssd.conf.5.xml:4611 +#, fuzzy +#| msgid "" +#| "Each supported authentication method has its own configuration subsection " +#| "under <quote>[prompting/...]</quote>. Currently there are: <placeholder " +#| "type=\"variablelist\" id=\"0\"/> <placeholder type=\"variablelist\" " +#| "id=\"1\"/> <placeholder type=\"variablelist\" id=\"2\"/>" msgid "" "Each supported authentication method has its own configuration subsection " "under <quote>[prompting/...]</quote>. Currently there are: <placeholder " "type=\"variablelist\" id=\"0\"/> <placeholder type=\"variablelist\" id=\"1\"/" -"> <placeholder type=\"variablelist\" id=\"2\"/>" +"> <placeholder type=\"variablelist\" id=\"2\"/> <placeholder " +"type=\"variablelist\" id=\"3\"/> <placeholder type=\"variablelist\" id=\"4\"/" +">" msgstr "" "Varje autentiseringsmetod som stödjs har sin egen konfigurationsundersektion " "under <quote>[prompting/…]</quote>. För närvarande finns det: <placeholder " -"type=\"variablelist\" id=\"0\"/> <placeholder type=\"variablelist\" " -"id=\"1\"/> <placeholder type=\"variablelist\" id=\"2\"/>" +"type=\"variablelist\" id=\"0\"/> <placeholder type=\"variablelist\" id=\"1\"/" +"> <placeholder type=\"variablelist\" id=\"2\"/>" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4508 +#: sssd.conf.5.xml:4792 msgid "" "It is possible to add a subsection for specific PAM services, e.g. " "<quote>[prompting/password/sshd]</quote> to individual change the prompting " "for this service." msgstr "" -"Det är möjligt att lägga till en undersektion för specifika PAM-tjänster som " -"t.ex. <quote>[prompting/password/sshd]</quote> för att ändra frågorna " -"enskilt för denna tjänst." +"Det går att lägga till en undersektion för specifika PAM-tjänster, till " +"exempel <quote>[prompting/password/sshd]</quote>, för att ändra frågan " +"individuellt för tjänsten." #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:4515 pam_sss_gss.8.xml:157 idmap_sss.8.xml:43 +#: sssd.conf.5.xml:4799 pam_sss_gss.8.xml:157 idmap_sss.8.xml:43 msgid "EXAMPLES" msgstr "EXEMPEL" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd.conf.5.xml:4521 +#: sssd.conf.5.xml:4805 #, no-wrap msgid "" "[sssd]\n" @@ -6523,12 +6978,12 @@ msgstr "" "\n" "[domain/LDAP]\n" "id_provider = ldap\n" -"ldap_uri = ldap://ldap.exempel.se\n" -"ldap_search_base = dc=exempel,dc=se\n" +"ldap_uri = ldap://ldap.example.com\n" +"ldap_search_base = dc=example,dc=com\n" "\n" "auth_provider = krb5\n" -"krb5_server = kerberos.exempel.se\n" -"krb5_realm = EXEMPEL.SE\n" +"krb5_server = kerberos.example.com\n" +"krb5_realm = EXAMPLE.COM\n" "cache_credentials = true\n" "\n" "min_id = 10000\n" @@ -6536,7 +6991,7 @@ msgstr "" "enumerate = False\n" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4517 +#: sssd.conf.5.xml:4801 msgid "" "1. The following example shows a typical SSSD config. It does not describe " "configuration of the domains themselves - refer to documentation on " @@ -6548,17 +7003,17 @@ msgstr "" "domäner för fler detaljer. <placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd.conf.5.xml:4553 +#: sssd.conf.5.xml:4837 #, no-wrap msgid "" "[domain/ipa.com/child.ad.com]\n" "use_fully_qualified_names = false\n" msgstr "" -"[domain/ipa.se/barn.ad.se]\n" +"[domain/ipa.com/child.ad.com]\n" "use_fully_qualified_names = false\n" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4547 +#: sssd.conf.5.xml:4831 msgid "" "2. The following example shows configuration of IPA AD trust where the AD " "forest consists of two domains in a parent-child structure. Suppose IPA " @@ -6567,14 +7022,14 @@ msgid "" "configuration should be used. <placeholder type=\"programlisting\" id=\"0\"/" ">" msgstr "" -"2. Följande exempel visar konfigurationen av IPA AD-förtroende i en förälder-" -"barn-struktur. Anta att IPA-domänen (ipa.se) har förtroende för AD-domänen " -"(ad.se). ad.se har en barndomän (barn.ad.se). För att aktivera kortnamn i " -"barndomänen skall följande konfiguration användas. <placeholder " -"type=\"programlisting\" id=\"0\"/>" +"2. Följande exempel visar konfigurationen av ett IPA–AD-förtroende där AD-" +"skogen består av två domäner i en överordnad–underordnad struktur. Anta att " +"IPA-domänen (ipa.com) har ett förtroende med AD-domänen (ad.com). ad.com har " +"underdomänen (child.ad.com). Använd följande konfiguration för att aktivera " +"kortnamn i underdomänen. <placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd.conf.5.xml:4564 +#: sssd.conf.5.xml:4848 #, no-wrap msgid "" "[certmap/my.domain/rule_name]\n" @@ -6583,14 +7038,14 @@ msgid "" "domains = my.domain, your.domain\n" "priority = 10\n" msgstr "" -"[certmap/min.domän/rule_name]\n" -"matchrule = <ISSUER>^CN=My-CA,DC=MIN,DC=DOMÄN$\n" +"[certmap/my.domain/rule_name]\n" +"matchrule = <ISSUER>^CN=My-CA,DC=MY,DC=DOMAIN$\n" "maprule = (userCertificate;binary={cert!bin})\n" -"domains = min.domän, din.domän\n" +"domains = my.domain, your.domain\n" "priority = 10\n" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4558 +#: sssd.conf.5.xml:4842 msgid "" "3. The following example shows the configuration of a certificate mapping " "rule. It is valid for the configured domain <quote>my.domain</quote> and " @@ -6598,11 +7053,10 @@ msgid "" "certificate in the search filter. <placeholder type=\"programlisting\" " "id=\"0\"/>" msgstr "" -"3. Följande exempel visar konfigurationen för en certifikatavbildningsregel. " -"Den är giltig för den konfigurerade domänen <quote>min.domän</quote> och " -"dessutom för underdomänerna <quote>din.domän</quote> och använder det " -"fullständiga certifikatet i sökfiltret. <placeholder type=\"programlisting\" " -"id=\"0\"/>" +"3. Följande exempel visar konfigurationen av en certifikatmappningsregel. " +"Den gäller för den konfigurerade domänen <quote>my.domain</quote>, dessutom " +"för underdomänen <quote>your.domain</quote>, och använder hela certifikatet " +"i sökfiltret. <placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refnamediv><refname> #: sssd-ldap.5.xml:10 sssd-ldap.5.xml:16 @@ -6658,13 +7112,13 @@ msgid "" "refer to the <quote>ldap_access_filter</quote> config option for more " "information about using LDAP as an access provider." msgstr "" -"LDAP-bakändar stödjer leverantörer av id, autentisering, åtkomst och " -"lösenordsändring. Om du vill autentisera mot en LDAP-server krävs antingen " -"TLS/SSL eller LDAPS. <command>sssd</command> stödjer <emphasis>inte</" -"emphasis> autentisering över en okrypterad kanal. Även om LDAP-servern " -"används endast som en identitetsleverantör rekommenderas starkt en krypterad " -"kanal. Se konfigurationsalternativet <quote>ldap_access_filter</quote> för " -"mer information om att använda LDAP som en åtkomstleverantör." +"LDAP-bakänden stöder id-, auth-, access- och chpass-leverantörer. Om du vill " +"autentisera mot en LDAP-server krävs antingen TLS/SSL eller LDAPS. <command>" +"sssd</command> stöder <emphasis>inte</emphasis> autentisering över en " +"okrypterad kanal. Även om LDAP-servern endast används som " +"identitetsleverantör rekommenderas starkt en krypterad kanal. Se " +"konfigurationsalternativet <quote>ldap_access_filter</quote> för mer " +"information om hur LDAP används som åtkomstleverantör." #. type: Content of: <reference><refentry><refsect1><title> #: sssd-ldap.5.xml:50 sssd-simple.5.xml:82 sssd-ipa.5.xml:82 sssd-ad.5.xml:130 @@ -6687,11 +7141,11 @@ msgid "" "neither option is specified, service discovery is enabled. For more " "information, refer to the <quote>SERVICE DISCOVERY</quote> section." msgstr "" -"Anger en kommaseparerad lista av URI:er till LDAP-servrar till vilka SSSD " -"skall ansluta i prioritetsordning. Se avsnittet <quote>RESERVER</quote> för " -"mer information om reserver och serverredundans. Om ingendera alternativ är " -"angivet kommer tjänsteupptäckt användas. För mer information, se avsnittet " -"<quote>TJÄNSTEUPPTÄCKT</quote>." +"Anger en kommaseparerad lista med URI:er till LDAP-servrar som SSSD ska " +"ansluta till i prioritetsordning. Se avsnittet <quote>FAILOVER</quote> för " +"mer information om failover och serverredundans. Om inget av alternativen " +"anges aktiveras tjänsteupptäckt. Se avsnittet <quote>SERVICE DISCOVERY</" +"quote> för mer information." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:77 @@ -6701,7 +7155,7 @@ msgstr "Formatet på URI:n måste stämma med formatet som definieras i RFC 2732 #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:80 msgid "ldap[s]://<host>[:port]" -msgstr "ldap[s]://<värd>[:port]" +msgstr "ldap[s]://<host>[:port]" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:83 @@ -6729,9 +7183,9 @@ msgid "" "Refer to the <quote>FAILOVER</quote> section for more information on " "failover and server redundancy." msgstr "" -"Anger en kommaseparerad lista av URI:er till LDAP-servrar till vilka SSSD " -"skall ansluta i prioritetsordning för att ändra lösenordet för en användare. " -"Se avsnittet <quote>RESERVER</quote> för mer information om reserver och " +"Anger en kommaseparerad lista med URI:er till LDAP-servrar som SSSD ska " +"ansluta till i prioritetsordning för att ändra en användares lösenord. Se " +"avsnittet <quote>FAILOVER</quote> för mer information om failover och " "serverredundans." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> @@ -6754,21 +7208,19 @@ msgstr "ldap_search_base (sträng)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:115 msgid "The default base DN to use for performing LDAP user operations." -msgstr "Standard bas-DN att använda för att utföra LDAP-användaroperationer." +msgstr "Standardbas-DN som används för LDAP-användaråtgärder." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:119 msgid "" "Starting with SSSD 1.7.0, SSSD supports multiple search bases using the " "syntax:" -msgstr "" -"Med början med SSSD 1.7.0 stödjer SSSD flera sökbaser genom att använda " -"syntaxen:" +msgstr "Från och med SSSD 1.7.0 stöder SSSD flera sökbaser med syntaxen:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:123 msgid "search_base[?scope?[filter][?search_base?scope?[filter]]*]" -msgstr "sökbas[?räckvidd?[filter][?sökbas?räckvidd?[filter]]*]" +msgstr "search_base[?scope?[filter][?search_base?scope?[filter]]*]" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:126 @@ -6796,8 +7248,8 @@ msgid "" "ldap_search_base = dc=example,dc=com (which is equivalent to) " "ldap_search_base = dc=example,dc=com?subtree?" msgstr "" -"ldap_search_base = dc=example,dc=com (vilket är ekvivalent med) " -"ldap_search_base = dc=example,dc=com?subtree?" +"ldap_search_base = dc=example,dc=com (vilket motsvarar) ldap_search_base = " +"dc=example,dc=com?subtree?" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:141 @@ -6806,7 +7258,7 @@ msgid "" "(host=thishost)?dc=example.com?subtree?" msgstr "" "ldap_search_base = cn=host_specific,dc=example,dc=com?subtree?(host=thishost)" -"?dc=exempel.se?subtree?" +"?dc=example.com?subtree?" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:144 @@ -6816,19 +7268,27 @@ msgid "" "different search bases). This will lead to unpredictable behavior on client " "machines." msgstr "" -"Observera: det stödjs inte att ha flera sökbaser som refererar identiskt " -"namngivna objekt (till exempel, grupper med samma namn i två olika sökbaser)" -". Detta kommer medföra oförutsägbart beteende på klientmaskinerna." +"Obs! Det stöds inte att ha flera sökbaser som refererar till objekt med " +"identiska namn (till exempel grupper med samma namn i två olika sökbaser). " +"Detta leder till oförutsägbart beteende på klientdatorer." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:151 +#, fuzzy +#| msgid "" +#| "Default: If not set, the value of the defaultNamingContext or " +#| "namingContexts attribute from the RootDSE of the LDAP server is used. If " +#| "defaultNamingContext does not exist or has an empty value namingContexts " +#| "is used. The namingContexts attribute must have a single value with the " +#| "DN of the search base of the LDAP server to make this work. Multiple " +#| "values are are not supported." msgid "" "Default: If not set, the value of the defaultNamingContext or namingContexts " "attribute from the RootDSE of the LDAP server is used. If " "defaultNamingContext does not exist or has an empty value namingContexts is " "used. The namingContexts attribute must have a single value with the DN of " "the search base of the LDAP server to make this work. Multiple values are " -"are not supported." +"not supported." msgstr "" "Standard: om inte satt används värdet från attributet defaultNamingContext " "eller namingContexts från RootDSE:n hos LDAP-servern. Om " @@ -6895,9 +7355,9 @@ msgid "" "the selected schema, the default attribute names retrieved from the servers " "may vary. The way that some attributes are handled may also differ." msgstr "" -"Anger schematypen som används på mål-LDAP-servern. Beroende på det valda " -"schemat kan standardattributnamnen som hämtas från servrarna variera. " -"Sättet som en del attribut hanteras kan också skilja." +"Anger den schematyp som används på mål-LDAP-servern. Beroende på det valda " +"schemat kan standardnamnen för attribut som hämtas från servrarna variera. " +"Sättet som vissa attribut hanteras på kan också skilja sig." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:214 @@ -6925,11 +7385,11 @@ msgid "" "Directory 2008r2 values." msgstr "" "Den huvudsakliga skillnaden mellan dessa schematyper är hur gruppmedlemskap " -"lagras i servern. Med rfc2307 listas gruppmedlemskap med namn i attributet " -"<emphasis>memberUid</emphasis>. Med rfc2307bis och IPA listas " -"gruppmedlemskap av DN och lagras i attributet <emphasis>member</emphasis>. " -"AD-schematypen sätter attributen till att motsvara Active Directory 2008r2-" -"värden." +"registreras på servern. Med rfc2307 listas gruppmedlemmar efter namn i " +"attributet <emphasis>memberUid</emphasis>. Med rfc2307bis och IPA listas " +"gruppmedlemmar efter DN och lagras i attributet <emphasis>member</emphasis>. " +"AD-schematypen anger attribut som motsvarar värdena i Active Directory " +"2008r2." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:249 @@ -7010,7 +7470,7 @@ msgstr "ldap_default_authtok_type (sträng)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:317 msgid "The type of the authentication token of the default bind DN." -msgstr "Typen på autentiseringstecknet hos standardbindnings-DN." +msgstr "Typen av autentiseringstoken för standardbindnings-DN." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:321 @@ -7038,7 +7498,7 @@ msgid "" "See the <citerefentry> <refentrytitle>sss_obfuscate</refentrytitle> " "<manvolnum>8</manvolnum> </citerefentry> manual page for more information." msgstr "" -"Se manualsidan <citerefentry> <refentrytitle>sss_obvuscate</refentrytitle> " +"Se manualsidan <citerefentry> <refentrytitle>sss_obfuscate</refentrytitle> " "<manvolnum>8</manvolnum> </citerefentry> för mer information." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> @@ -7064,10 +7524,10 @@ msgid "" "fail. Set this option to a non-zero value if you want to use an upper-case " "realm." msgstr "" -"Några katalogservrar, till exempel Active Directory, kan leverera delen rike " -"av UPN:en i gemener, vilket kan få autentiseringen att misslyckas. Sätt " -"detta alternativ till ett värde skilt från noll ifall du vill använda ett " -"rike i versaler." +"Vissa katalogservrar, till exempel Active Directory, kan leverera domändelen " +"av UPN i gemener, vilket kan göra att autentiseringen misslyckas. Sätt detta " +"alternativ till ett värde skilt från noll om du vill använda en domändel med " +"versaler." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:369 @@ -7080,8 +7540,8 @@ msgid "" "Specifies how many seconds SSSD has to wait before refreshing its cache of " "enumerated records." msgstr "" -"Anger hur många sekunder SSSD måste vänta före den uppdaterar sin cache av " -"uppräknade poster." +"Anger hur många sekunder SSSD ska vänta innan dess cache med uppräknade " +"poster uppdateras." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:383 @@ -7095,9 +7555,9 @@ msgid "" "with no members and users who have never logged in) and remove them to save " "space." msgstr "" -"Bestäm hur ofta cachen skall kontrolleras för inaktiva poster (såsom grupper " -"utan medlemmar och användare som aldrig har loggat in) och ta bort dem för " -"att spara utrymme." +"Anger hur ofta cachen ska kontrolleras efter inaktiva poster (såsom grupper " +"utan medlemmar och användare som aldrig har loggat in) och hur de ska tas " +"bort för att spara utrymme." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:392 @@ -7107,10 +7567,11 @@ msgid "" "to detect entries removed from the server and can't be disabled. By default, " "the cleanup task will run every 3 hours with enumeration enabled." msgstr "" -"Att sätta detta alternativ till noll kommer avaktivera rensningsoperationen " -"för cachen. Observera att om uppräkning är aktiverat krävs rensningsjobbet " -"för att upptäcka poster som tas bort från servern och inte kan avaktiveras. " -"Som standard kör rensningsjobbet var 3:e timma när uppräkning är aktiverat." +"Att sätta detta alternativ till noll inaktiverar cache-rensningen. Observera " +"att rensningsuppgiften krävs om uppräkning är aktiverad för att upptäcka " +"poster som tagits bort från servern, och den kan då inte inaktiveras. Som " +"standard körs rensningsuppgiften var tredje timme när uppräkning är " +"aktiverad." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:412 @@ -7124,9 +7585,9 @@ msgid "" "RFC2307bis), then this option controls how many levels of nesting SSSD will " "follow. This option has no effect on the RFC2307 schema." msgstr "" -"Om ldap_schema är satt till ett schemaformat som stödjer nästade grupper " -"(t.ex. RFC2307bis), då styr detta alternativ hur många nivåer av nästning " -"SSSD kommer följa. Detta alternativ har ingen effekt på schemat RFC2307." +"Om ldap_schema är satt till ett schemaformat som stöder nästlade grupper " +"(t.ex. RFC2307bis) styr detta alternativ hur många nästlingsnivåer SSSD " +"följer. Alternativet har ingen effekt på RFC2307-schemat." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:422 @@ -7137,12 +7598,12 @@ msgid "" "the deeper nesting levels. Also, subsequent lookups for other groups may " "enlarge the result set for original lookup if re-queried." msgstr "" -"Obs: detta alternativ anger den garanterade nivån av nästade grupper som " -"skall bearbetas för en godtycklig uppslagning. Dock <emphasis>kan</" -"emphasis> nästade grupper utöver denna gräns returneras om tidigare " -"uppslagningar redan har slagit upp de djupare nästningsnivåerna. Följande " -"uppslagningar för andra grupper kan också utöka resultatmängden för den " -"ursprungliga uppslagningen om den slås upp igen." +"Obs! Detta alternativ anger den garanterade nivån av nästlade grupper som " +"bearbetas vid varje uppslagning. Nästlade grupper bortom gränsen <emphasis>" +"kan</emphasis> dock returneras om tidigare uppslagningar redan har löst de " +"djupare nästlingsnivåerna. Efterföljande uppslagningar av andra grupper kan " +"också utöka resultatmängden för den ursprungliga uppslagningen om den görs " +"igen." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:431 @@ -7153,11 +7614,11 @@ msgid "" "usage of Token-Groups by setting ldap_use_tokengroups to false in order to " "restrict group nesting." msgstr "" -"Om ldap_group_nesting_level sätts till 0 bearbetas inga nästade grupper " -"alls. Dock krävs det dessutom att användningen av Token-Groups avaktiveras " -"vid anslutning till Active-Directory Server 2008 och senare vid användning " -"av <quote>id_provider=ad</quote> genom att sätta ldap_use_tokengroups till " -"false för att begränsa gruppnästning." +"Om ldap_group_nesting_level sätts till 0 bearbetas inga nästlade grupper " +"alls. Vid anslutning till Active Directory Server 2008 och senare med <quote>" +"id_provider=ad</quote> krävs dessutom att användningen av Token-Groups " +"inaktiveras genom att sätta ldap_use_tokengroups till false för att begränsa " +"gruppnästling." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:440 @@ -7177,7 +7638,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:459 msgid "Default: True for AD and IPA otherwise False." -msgstr "Standard: true för AD och IPA annars false." +msgstr "Standard: True för AD och IPA, annars False." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:465 @@ -7187,20 +7648,20 @@ msgstr "ldap_host_search_base (sträng)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:468 msgid "Optional. Use the given string as search base for host objects." -msgstr "Frivillig. Använd den givna strängen som en sökbas för värdobjekt." +msgstr "Valfritt. Använd den angivna strängen som sökbas för värdobjekt." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap.5.xml:472 sssd-ipa.5.xml:506 sssd-ipa.5.xml:525 sssd-ipa.5.xml:544 -#: sssd-ipa.5.xml:563 +#: sssd-ldap.5.xml:472 sssd-ipa.5.xml:501 sssd-ipa.5.xml:520 sssd-ipa.5.xml:539 +#: sssd-ipa.5.xml:558 msgid "" "See <quote>ldap_search_base</quote> for information about configuring " "multiple search bases." msgstr "" -"Se <quote>ldap_search_base</quote> för information om konfiguration av " -"multipla sökbaser." +"Se <quote>ldap_search_base</quote> för information om hur flera sökbaser " +"konfigureras." #. type: Content of: <listitem><para> -#: sssd-ldap.5.xml:477 sssd-ipa.5.xml:511 include/ldap_search_bases.xml:27 +#: sssd-ldap.5.xml:477 sssd-ipa.5.xml:506 include/ldap_search_bases.xml:27 msgid "Default: the value of <emphasis>ldap_search_base</emphasis>" msgstr "Standard: värdet på <emphasis>ldap_search_base</emphasis>" @@ -7215,8 +7676,8 @@ msgid "" "Optional. Use the given string as search base for subordinate ranges related " "objects." msgstr "" -"Frivillig. Använd den givna strängen som sökbas för " -"underordningsintervallsrelaterade objekt." +"Valfritt. Använd den angivna strängen som sökbas för objekt som rör " +"underordnade intervall." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:491 @@ -7254,8 +7715,8 @@ msgid "" "before they are cancelled and cached results are returned (and offline mode " "is entered)" msgstr "" -"Anger tiden (i sekunder) som ldap-sökningar tillåts köra före de annulleras " -"och cachade resultat returneras (och går in i frånkopplat läge)" +"Anger tidsgränsen (i sekunder) som LDAP-sökningar får köras innan de avbryts " +"och cachelagrade resultat returneras (och frånkopplat läge aktiveras)." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:523 @@ -7264,9 +7725,9 @@ msgid "" "will likely be replaced at some point by a series of timeouts for specific " "lookup types." msgstr "" -"Obs: detta alternativ kan komma att ändras i framtida versioner av SSSD. Det " -"kommer sannolikt ersättas vid någon tidpunkt med en serie tidsgränser för " -"specifika uppslagningstyper." +"Obs! Detta alternativ kan ändras i framtida versioner av SSSD. Det ersätts " +"sannolikt så småningom av en serie tidsgränser för specifika typer av " +"uppslagningar." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:540 @@ -7280,9 +7741,9 @@ msgid "" "enumerations are allowed to run before they are cancelled and cached results " "are returned (and offline mode is entered)" msgstr "" -"Anger tiden (i sekunder) som ldap-sökningar för användar- och " -"gruppuppräkningar tillåts köra före de annulleras och cachade resultat " -"returneras (och går in i frånkopplat läge)" +"Anger tidsgränsen (i sekunder) som LDAP-sökningar efter användar- och " +"gruppuppräkningar får köras innan de avbryts och cachelagrade resultat " +"returneras (och frånkopplat läge aktiveras)." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:556 @@ -7302,9 +7763,9 @@ msgstr "" "Anger tidsgränsen (i sekunder) efter vilken <citerefentry> <refentrytitle>" "poll</refentrytitle> <manvolnum>2</manvolnum> </citerefentry>/<citerefentry> " "<refentrytitle>select</refentrytitle> <manvolnum>2</manvolnum> </" -"citerefentry> som följer efter en <citerefentry> <refentrytitle>connect</" -"refentrytitle> <manvolnum>2</manvolnum> </citerefentry> returnerar om inget " -"händer." +"citerefentry>, efter en <citerefentry> <refentrytitle>connect</" +"refentrytitle> <manvolnum>2</manvolnum> </citerefentry>, returnerar om ingen " +"aktivitet sker." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:587 @@ -7319,11 +7780,10 @@ msgid "" "communicating with the KDC in case of SASL bind, the timeout of an LDAP bind " "operation, password change extended operation and the StartTLS operation." msgstr "" -"Anger en tid (i sekunder) efter vilken anrop till synkrona LDAP API:er " -"kommer avbrytas om det inte kommer något svar. Styr även tidsgränsen vid " -"kommunikation med KDC:n i fallet SASL-bindningar, tidsgränsen för en LDAP-" -"bindningsoperation, utökad operation för lösenordsändring och StartTLS-" -"operationen." +"Anger en tidsgräns (i sekunder) efter vilken anrop till synkrona LDAP-API:er " +"avbryts om inget svar tas emot. Styr även tidsgränsen vid kommunikation med " +"KDC vid SASL-bindning, tidsgränsen för en LDAP-bindningsoperation, " +"lösenordsändringens utökade operation och StartTLS-operationen." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:610 @@ -7338,27 +7798,36 @@ msgid "" "in parallel with SASL/GSSAPI, the sooner of the two values (this value vs. " "the TGT lifetime) will be used." msgstr "" -"Anger en tidsgräns (i sekunder) som en förbindelse med en LDAP-server kommer " -"underhållas. Efter den tiden kommer förbindelsen återetableras. Om den " -"används parallellt med SASL/GSSAPI kommer det tidigare av de två värdena " -"(detta värde eller TGT-livslängden) användas." +"Anger hur länge (i sekunder) en anslutning till en LDAP-server upprätthålls. " +"Efter denna tid återupprättas anslutningen. Om alternativet används " +"parallellt med SASL/GSSAPI används det tidigare av de två värdena (detta " +"värde eller TGT-livslängden)." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:621 +#, fuzzy +#| msgid "" +#| "If the connection is idle (not actively running an operation) within " +#| "<emphasis>ldap_opt_timeout</emphasis> seconds of expiration, then it will " +#| "be closed early to ensure that a new query cannot require the connection " +#| "to remain open past its expiration. This implies that connections will " +#| "always be closed immediately and will never be reused if " +#| "<emphasis>ldap_connection_expire_timeout <= ldap_opt_timout</emphasis>" msgid "" "If the connection is idle (not actively running an operation) within " "<emphasis>ldap_opt_timeout</emphasis> seconds of expiration, then it will be " "closed early to ensure that a new query cannot require the connection to " "remain open past its expiration. This implies that connections will always " "be closed immediately and will never be reused if " -"<emphasis>ldap_connection_expire_timeout <= ldap_opt_timout</emphasis>" -msgstr "" -"Om anslutningen är inaktiv (inte aktivt kör en åtgärd) under <emphasis>" -"ldap_opt_timeout</emphasis> sekunders utgångstid, då kommer den att stängas " -"i förväg för att säkerställa att en ny begäran inte kan kräva att " -"förbindelsen skall hållas öppen utöver dess utgångstid. Detta implicerar att " -"anslutningar alltid kommer stängas omedelbart och aldrig kommer återanvändas " -"om <emphasis>ldap_connection_expire_timoute ≤ ldap_opt_timeout</emphasis>" +"<emphasis>ldap_connection_expire_timeout <= ldap_opt_timeout</emphasis>" +msgstr "" +"Om anslutningen är inaktiv (inte aktivt kör en åtgärd) under " +"<emphasis>ldap_opt_timeout</emphasis> sekunders utgångstid, då kommer den " +"att stängas i förväg för att säkerställa att en ny begäran inte kan kräva " +"att förbindelsen skall hållas öppen utöver dess utgångstid. Detta implicerar " +"att anslutningar alltid kommer stängas omedelbart och aldrig kommer " +"återanvändas om <emphasis>ldap_connection_expire_timoute ≤ ldap_opt_timeout</" +"emphasis>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:633 @@ -7366,8 +7835,8 @@ msgid "" "This timeout can be extended of a random value specified by " "<emphasis>ldap_connection_expire_offset</emphasis>" msgstr "" -"Tidsgränsen kan utökas med ett slumpvärde angivet av <emphasis>" -"ldap_connection_expire_offset</emphasis>" +"Tidsgränsen kan utökas med ett slumpvärde som anges av <emphasis>" +"ldap_connection_expire_offset</emphasis>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:643 sssd-ldap.5.xml:686 sssd-ldap.5.xml:1809 @@ -7385,8 +7854,8 @@ msgid "" "Random offset between 0 and configured value is added to " "<emphasis>ldap_connection_expire_timeout</emphasis>." msgstr "" -"En slumptillägg mellan 0 och ett konfigurerat värde läggs till till<emphasis>" -"ldap_connection_expire_timeout</emphasis>." +"Ett slumpmässigt tillägg mellan 0 och det konfigurerade värdet läggs till i " +"<emphasis>ldap_connection_expire_timeout</emphasis>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:668 @@ -7420,8 +7889,8 @@ msgid "" "Specify the number of records to retrieve from LDAP in a single request. " "Some LDAP servers enforce a maximum limit per-request." msgstr "" -"Ange antalet poster som skall hämtas från LDAP i en enskild begäran. Några " -"LDAP-servrar framtvingar en maximal gräns per begäran." +"Ange antalet poster som ska hämtas från LDAP i en enda begäran. Vissa LDAP-" +"servrar tillämpar en maximal gräns per begäran." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:706 @@ -7435,9 +7904,9 @@ msgid "" "server reports that it supports the LDAP paging control in its RootDSE but " "it is not enabled or does not behave properly." msgstr "" -"Avaktivera flödesstyrningen (paging) av LDAP. Detta alternativ bör användas " -"om LDAP-servern rapporterar att den stödjer LDAP-flödesstyrning i sin " -"RootDSE men det inte är aktiverat eller inte fungerar som det skall." +"Inaktivera LDAP:s sidindelningskontroll. Detta alternativ ska användas om " +"LDAP-servern rapporterar att den stöder sidindelningskontrollen i sin " +"RootDSE, men den inte är aktiverad eller inte fungerar korrekt." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:715 @@ -7445,9 +7914,8 @@ msgid "" "Example: OpenLDAP servers with the paging control module installed on the " "server but not enabled will report it in the RootDSE but be unable to use it." msgstr "" -"Exempel: OpenLDAP-servrar med flödesstyrningsmodulen installerad på servern " -"men inte aktiverad kommer rapportera det i RootDSE:n men inte kunna använda " -"den." +"Exempel: OpenLDAP-servrar med modulen för sidindelningskontroll installerad " +"men inte aktiverad rapporterar den i RootDSE, men kan inte använda den." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:721 @@ -7456,9 +7924,9 @@ msgid "" "a time on a single connection. On busy clients, this can result in some " "requests being denied." msgstr "" -"Exempel: 389 DS har ett fel där den endast kan stödja en flödesstyrning åt " -"gången på en enskild förbindelse. På aktiva klienter kan detta resultera i " -"att några begäranden nekas." +"Exempel: 389 DS har ett fel där det endast kan stödja en " +"sidindelningskontroll åt gången på en enda anslutning. På hårt belastade " +"klienter kan detta leda till att vissa begäranden nekas." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:733 @@ -7504,9 +7972,9 @@ msgid "" "security level necessary to establish the connection. The values of this " "option are defined by OpenLDAP." msgstr "" -"Vid kommunikation med en LDAP-server med SASL, ange den minsta " -"säkerhetsnivån som är nödvändig för att etablera förbindelsen. Värdet på " -"detta alternativ är definierat av OpenLDAP." +"Ange den lägsta säkerhetsnivå som krävs för att upprätta anslutningen vid " +"kommunikation med en LDAP-server via SASL. Värdena för detta alternativ " +"definieras av OpenLDAP." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:767 sssd-ldap.5.xml:783 @@ -7525,9 +7993,9 @@ msgid "" "security level necessary to establish the connection. The values of this " "option are defined by OpenLDAP." msgstr "" -"Vid kommunikation med en LDAP-server med SASL, ange den masimala " -"säkerhetsnivån som är nödvändig för att etablera förbindelsen. Värdet på " -"detta alternativ är definierat av OpenLDAP." +"Ange den högsta säkerhetsnivå som krävs för att upprätta anslutningen vid " +"kommunikation med en LDAP-server via SASL. Värdena för detta alternativ " +"definieras av OpenLDAP." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:790 @@ -7541,8 +8009,8 @@ msgid "" "cache in order to trigger a dereference lookup. If less members are missing, " "they are looked up individually." msgstr "" -"Ange antalet gruppmedlemmar som måste saknas i den interna cachen för att " -"orsaka en derefereringsuppslagning. Om färre medlemmar saknas slås de upp " +"Ange hur många gruppmedlemmar som måste saknas i den interna cachen för att " +"utlösa en dereferensuppslagning. Om färre medlemmar saknas slås de upp " "individuellt." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> @@ -7555,12 +8023,11 @@ msgid "" "the server supports it and advertises the dereference control in the rootDSE " "object." msgstr "" -"Du kan slå av derefereringsuppslagningar helt genom att sätta värdet till 0. " -"Observera att det finns några kodvägar i SSSD, som IPA HBAC-leverantören, " -"som endast är implementerade med derefereringsanropet, så att även med " -"dereferens uttryckligen avaktiverat kommer dessa delar ändå använda " -"dereferenser om servern stödjer det och annonserar derefereringsstyrning i " -"rootDSE-objektet." +"Du kan stänga av dereferensuppslagningar helt genom att sätta värdet till 0. " +"Observera att vissa kodvägar i SSSD, till exempel IPA HBAC-leverantören, " +"endast är implementerade med dereferensanropet. Även om dereferens " +"uttryckligen inaktiveras använder dessa delar därför fortfarande dereferens " +"om servern stöder det och annonserar dereferenskontrollen i rootDSE-objektet." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:810 @@ -7582,13 +8049,15 @@ msgid "" "filter, then the dereference lookup performance enhancement will be disabled " "regardless of this setting." msgstr "" -"<emphasis>Obs:</emphasis> om någon av sökbaserna anger ett sökfilter, då " -"kommer prestandaförbättringen med derefereringsuppslagningar avaktiveras " -"oavsett denna inställning." +"<emphasis>Obs:</emphasis> Om någon av sökbaserna anger ett sökfilter " +"inaktiveras prestandaförbättringen för dereferensuppslagningar oavsett denna " +"inställning." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:831 -msgid "ldap_ignore_unreadable_references (bool)" +#, fuzzy +#| msgid "ldap_ignore_unreadable_references (bool)" +msgid "ldap_ignore_unreadable_references (boolean)" msgstr "ldap_ignore_unreadable_references (bool)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> @@ -7598,9 +8067,9 @@ msgid "" "this parameter is set to false an error will be returned and the operation " "will fail instead of just ignoring the unreadable entry." msgstr "" -"Ignorera oläsbara LDAP-poster refererade i gruppens medlemsattribut. Om " -"denna parameter sätts till falskt kommer ett fel returneras och åtgärden " -"misslyckas istället för att den oläsbara posten bara ignoreras." +"Ignorera oläsbara LDAP-poster som refereras i gruppens medlemsattribut. Om " +"parametern sätts till false returneras ett fel och åtgärden misslyckas i " +"stället för att den oläsbara posten bara ignoreras." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:841 @@ -7609,9 +8078,9 @@ msgid "" "account that sssd uses to connect to AD does not have access to a particular " "entry or LDAP sub-tree for security reasons." msgstr "" -"Denna parameter kan vara användbar när man använder AD-leverantören och " -"datorkontot som sssd använder för att ansluta till AD inte har tillgång till " -"en viss post eller ett visst LDAP-underträd av säkerhetsskäl." +"Denna parameter kan vara användbar när AD-leverantören används och det " +"datorkonto som sssd använder för att ansluta till AD av säkerhetsskäl inte " +"har åtkomst till en viss post eller ett LDAP-underträd." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:854 @@ -7624,8 +8093,8 @@ msgid "" "Specifies what checks to perform on server certificates in a TLS session, if " "any. It can be specified as one of the following values:" msgstr "" -"Anger vilka kontroller som utförs av servercertifikat i en TLS-session, om " -"några. Det kan anges som ett av följande värden:" +"Anger vilka kontroller som ska utföras på servercertifikat i en TLS-session, " +"om några. Det kan anges som ett av följande värden:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:863 @@ -7690,8 +8159,8 @@ msgid "" "Specifies the file that contains certificates for all of the Certificate " "Authorities that <command>sssd</command> will recognize." msgstr "" -"Anger filen som innehåller certifikat för alla Certifikatauktoriteterna som " -"<command>sssd</command> kommer godkänna." +"Anger filen som innehåller certifikat för alla certifikatutfärdare som " +"<command>sssd</command> känner igen." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:904 sssd-ldap.5.xml:923 sssd-ldap.5.xml:964 @@ -7699,8 +8168,8 @@ msgid "" "Default: use OpenLDAP defaults, typically in <filename>/etc/openldap/" "ldap.conf</filename>" msgstr "" -"Standard: använd standardvärden för OpenLDAP, typiskt i <filename>/etc/" -"openldap/ldap.conf</filename>" +"Standard: använd standardvärden för OpenLDAP, vanligtvis i <filename>/etc/" +"openldap/ldap.conf</filename>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:911 @@ -7716,11 +8185,11 @@ msgid "" "<command>openssl rehash</command> or <command>c_rehash</command> can be used " "to create the correct names." msgstr "" -"Anger sökvägen till en katalog som innehåller certifikat för " -"Certifikatauktoriteter i individuella filer. Typiskt måste filnamnen vara " -"kontrollsummor av certifikaten följda av ”.0”. Om det är tillgängligt kan " -"<command>openssl rehash</command> or <command>c_rehash</command> användas " -"för att skapa de korrekta namnen." +"Anger sökvägen till en katalog som innehåller certifikat från " +"certifikatutfärdare i separata filer. Vanligtvis ska filnamnen vara " +"certifikatets hash följt av '.0'. Om de är tillgängliga kan <command>openssl " +"rehash</command> eller <command>c_rehash</command> användas för att skapa " +"korrekta namn." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:930 @@ -7786,9 +8255,9 @@ msgid "" "ldap_user_objectsid and ldap_group_objectsid attributes instead of relying " "on ldap_user_uid_number and ldap_group_gid_number." msgstr "" -"Anger att SSSD skall försöka översätta användar- och grupp-ID:n från " -"attributen ldap_user_objectsid och ldap_group_objectsid istället för att " -"förlita sig på ldap_user_uid_number och ldap_group_gid_number." +"Anger att SSSD ska försöka mappa användar- och grupp-ID:n från attributen " +"ldap_user_objectsid och ldap_group_objectsid i stället för att förlita sig " +"på ldap_user_uid_number och ldap_group_gid_number." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:994 @@ -7810,13 +8279,13 @@ msgid "" "can be set to restrict the allowed range for the IDs which are read directly " "from the server. Sub-domains can then pick other ranges to map IDs." msgstr "" -"I kontrast mot den SID-baserade ID-översättningen som används om " -"ldap_id_mapping är satt till sant är det tillåtna ID-intervallet för " -"ldap_user_uid_number och ldap_group_gid_number obegränsat. I en uppsättning " -"med underdomäner/betrodda domäner kan detta leda till ID-kollisioner. För " -"att undvika kollisioner kan ldap_min_id och ldap_max_id sättas till att " -"begränsa det tillåtna intervallet för ID:na som läses direkt från servern. " -"Underdomäner kan sedan välja andra intervall för att översätta ID:n." +"Till skillnad från den SID-baserade ID-mappning som används om " +"ldap_id_mapping är satt till true är det tillåtna ID-intervallet för " +"ldap_user_uid_number och ldap_group_gid_number obegränsat. I en " +"konfiguration med underdomäner/betrodda domäner kan detta leda till ID-" +"kollisioner. För att undvika kollisioner kan ldap_min_id och ldap_max_id " +"sättas för att begränsa intervallet för ID:n som läses direkt från servern. " +"Underdomäner kan sedan välja andra intervall för att mappa ID:n." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1019 @@ -7847,12 +8316,12 @@ msgid "" "<citerefentry><refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</" "manvolnum></citerefentry> for details." msgstr "" -"Om bakänden stödjer underdomäner ärvs automatiskt värdet av ldap_sasl_mech " -"till underdomänerna. Om ett annat värde behövs för en underdomän kan det " -"skrivas över genom att sätta ldap_sasl_mech för denna underdomän explicit. " -"Se avsnittet SEKTIONEN BETRODDA DOMÄNER i <citerefentry><refentrytitle>" -"sssd.conf</refentrytitle> <manvolnum>5</manvolnum></citerefentry> för " -"detaljer." +"Om den bakomliggande komponenten stöder underdomäner ärvs värdet för " +"ldap_sasl_mech automatiskt av underdomänerna. Om ett annat värde behövs för " +"en underdomän kan det åsidosättas genom att ldap_sasl_mech uttryckligen " +"anges för underdomänen. Se TRUSTED DOMAIN SECTION i <citerefentry>" +"<refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</manvolnum></" +"citerefentry> för mer information." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1048 @@ -7872,13 +8341,13 @@ msgid "" "host/*\n" " " msgstr "" -"värdnamn@REALM\n" -"netbiosnamn$@REALM\n" -"värd/värdnamn@REALM\n" +"hostname@REALM\n" +"netbiosname$@REALM\n" +"host/hostname@REALM\n" "*$@REALM\n" -"värd/*@REALM\n" -"netbiosnamn$@*\n" -"värd/*\n" +"host/*@REALM\n" +"netbiosname$@*\n" +"host/*\n" " " #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> @@ -7892,19 +8361,18 @@ msgid "" "used: <placeholder type=\"programlisting\" id=\"0\"/> If none of them are " "found, the first principal in keytab is returned." msgstr "" -"Ange SASL-auktoriserings-id:t att använda. När GSSAPI/GSS-SPNEGO används " -"representerar detta Kerberos-huvudmannen som används för autentisering till " -"katalogen. Detta alternativ kan antingen innehålla den fullständiga " -"huvudmannen (till exempel host/minvärd@EXEMPEL.COM) eller bara " -"huvudmannanamnet (till exempel host/minvärd). Som standard är värdet inte " -"satt och följande huvudmän används: <placeholder type=\"programlisting\" " -"id=\"0\"/> Om ingen av dem kan hittas returneras den första huvudmannen i " -"keytab." +"Ange vilket SASL-auktoriserings-ID som ska användas. När GSSAPI/GSS-SPNEGO " +"används representerar det Kerberos-huvudnamnet som används för autentisering " +"mot katalogen. Alternativet kan innehålla antingen hela huvudnamnet (till " +"exempel host/myhost@EXAMPLE.COM) eller endast huvudnamnet (till exempel host/" +"myhost). Som standard är värdet inte angivet och följande huvudnamn används: " +"<placeholder type=\"programlisting\" id=\"0\"/>. Om inget av dem hittas " +"returneras det första huvudnamnet i keytab." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1072 msgid "Default: host/hostname@REALM" -msgstr "Standard: host/värdnamn@RIKE" +msgstr "Standard: host/hostname@REALM" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1078 @@ -7918,9 +8386,9 @@ msgid "" "the value of krb5_realm. If the ldap_sasl_authid contains the realm as " "well, this option is ignored." msgstr "" -"Ange SASL-riket att använda. När det inte anges får detta alternativ " -"standardvärdet från krb5_realm. Om ldap_sasl_authid också innehåller riket " -"ignoreras detta alternativ." +"Ange vilken SASL-realm som ska användas. När alternativet inte anges är " +"standardvärdet krb5_realm. Om ldap_sasl_authid också innehåller realmen " +"ignoreras alternativet." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1087 @@ -7938,8 +8406,8 @@ msgid "" "If set to true, the LDAP library would perform a reverse lookup to " "canonicalize the host name during a SASL bind." msgstr "" -"Om satt till sant kommer LDAP-biblioteket utföra en omvänd uppslagning för " -"att ta fram värdnamnets kanoniska form under en SASL-bindning." +"Om värdet är true utför LDAP-biblioteket en omvänd uppslagning för att " +"kanonisera värdnamnet vid en SASL-bindning." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1101 @@ -7954,8 +8422,7 @@ msgstr "ldap_krb5_keytab (sträng)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1110 msgid "Specify the keytab to use when using SASL/GSSAPI/GSS-SPNEGO." -msgstr "" -"Ange den keytab som skall användas vid användning av SASL/GSSAPI/GSS-SPNEGO." +msgstr "Ange vilken keytab som ska användas med SASL/GSSAPI/GSS-SPNEGO." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1119 sssd-krb5.5.xml:247 @@ -7975,8 +8442,8 @@ msgid "" "action is performed only if SASL is used and the mechanism selected is " "GSSAPI or GSS-SPNEGO." msgstr "" -"Anger att id-leverantören skall initiera Kerberoskreditiv (TGT). Denna " -"åtgärd utförs endast om SASL används och den valda mekanismen är GSSAPI " +"Anger att id_provider ska initiera Kerberos-autentiseringsuppgifter (TGT). " +"Åtgärden utförs endast om SASL används och den valda mekanismen är GSSAPI " "eller GSS-SPNEGO." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> @@ -7992,7 +8459,7 @@ msgstr "" "Anger livslängden i sekunder på TGT:n om GSSAPI eller GSS-SPNEGO används." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap.5.xml:1152 sssd-ad.5.xml:1267 +#: sssd-ldap.5.xml:1152 sssd-ad.5.xml:1260 msgid "Default: 86400 (24 hours)" msgstr "Standard: 86400 (24 timmar)" @@ -8012,12 +8479,12 @@ msgid "" "discovery is enabled - for more information, refer to the <quote>SERVICE " "DISCOVERY</quote> section." msgstr "" -"Anger en kommaseparerad lista av IP-adresser eller värdnamn till " -"Kerberosservrar till vilka SSSD skall ansluta i prioritetsordning. För mer " -"information om reserver och serverredundans se avsnittet <quote>RESERVER</" -"quote>. Ett frivilligt portnummer (föregånget av ett kolon) kan läggas till " -"till adresserna eller värdnamnen. Om tomt aktiveras tjänsteupptäckt – för " -"mer information, se avsnittet <quote>TJÄNSTEUPPTÄCKT</quote>." +"Anger en kommaseparerad lista med IP-adresser eller värdnamn till Kerberos-" +"servrar som SSSD ska ansluta till i prioritetsordning. Se avsnittet <quote>" +"FAILOVER</quote> för mer information om failover och serverredundans. Ett " +"valfritt portnummer (föregånget av kolon) kan läggas till adresserna eller " +"värdnamnen. Om värdet är tomt aktiveras tjänsteupptäckt; se avsnittet <quote>" +"SERVICE DISCOVERY</quote> för mer information." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1173 sssd-krb5.5.xml:89 @@ -8037,20 +8504,19 @@ msgid "" "While the legacy name is recognized for the time being, users are advised to " "migrate their config files to use <quote>krb5_server</quote> instead." msgstr "" -"Detta alternativ hade namnet <quote>krb5_kdcip</quote> i tidigare utgåvor av " -"SSSD. Medan det äldre namnet känns igen tills vidare rekommenderas användare " -"att migrera sina konfigurationsfiler till att använda <quote>krb5_server</" -"quote> istället." +"Detta alternativ hette <quote>krb5_kdcip</quote> i tidigare SSSD-versioner. " +"Det äldre namnet känns igen tills vidare, men användare rekommenderas att " +"migrera sina konfigurationsfiler till <quote>krb5_server</quote>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ldap.5.xml:1187 sssd-ipa.5.xml:575 sssd-krb5.5.xml:103 +#: sssd-ldap.5.xml:1187 sssd-ipa.5.xml:570 sssd-krb5.5.xml:103 msgid "krb5_realm (string)" msgstr "krb5_realm (sträng)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1190 msgid "Specify the Kerberos REALM (for SASL/GSSAPI/GSS-SPNEGO auth)." -msgstr "Ange Kerberos-RIKE (för SASL/GSSAPI/GSS-SPNEGO aut)." +msgstr "Ange Kerberos REALM (för SASL/GSSAPI/GSS-SPNEGO-autentisering)." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1194 @@ -8068,8 +8534,8 @@ msgid "" "Specifies if the host principal should be canonicalized when connecting to " "LDAP server. This feature is available with MIT Kerberos >= 1.7" msgstr "" -"Anger om värdens huvudman skall göras kanonisk vid anslutning till LDAP-" -"servern. Denna funktion är tillgänglig med MIT Kerberos ≥ 1.7" +"Anger om värdhuvudnamnet ska kanoniseras vid anslutning till en LDAP-server. " +"Funktionen är tillgänglig med MIT Kerberos >= 1.7." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1215 sssd-krb5.5.xml:336 @@ -8085,9 +8551,9 @@ msgid "" "<refentrytitle>krb5.conf</refentrytitle> <manvolnum>5</manvolnum> </" "citerefentry> configuration file." msgstr "" -"Anger om SSSD skall instruera Kerberos-biblioteken om vilket rike och vilka " -"KDC:er som skall användas. Detta alternativ är på som standard, om du " -"avaktiverar det behöver du konfigurera Kerberos-biblioteket i " +"Anger om SSSD ska instruera Kerberos-biblioteken om vilken realm och vilka " +"KDC:er som ska användas. Alternativet är aktiverat som standard. Om du " +"inaktiverar det måste Kerberos-biblioteket konfigureras med " "konfigurationsfilen <citerefentry> <refentrytitle>krb5.conf</refentrytitle> " "<manvolnum>5</manvolnum> </citerefentry>." @@ -8113,7 +8579,7 @@ msgid "" "Select the policy to evaluate the password expiration on the client side. " "The following values are allowed:" msgstr "" -"Välj policyn för att utvärdera utgång av lösenord på klientsidan. Följande " +"Välj policy för att utvärdera lösenordets utgång på klientsidan. Följande " "värden är tillåtna:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> @@ -8155,8 +8621,8 @@ msgid "" "<emphasis>Note</emphasis>: if a password policy is configured on server " "side, it always takes precedence over policy set with this option." msgstr "" -"<emphasis>Obs</emphasis>: om en lösenordspolicy konfigureras på serversidan " -"kommer den alltid gå före framför policyn som sätts med detta alternativ." +"<emphasis>Obs</emphasis>: Om en lösenordspolicy konfigureras på serversidan " +"har den alltid företräde framför den policy som sätts med detta alternativ." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1281 @@ -8189,14 +8655,13 @@ msgid "" "able to follow the referral to a different AD DC no additional data would be " "available." msgstr "" -"Att följa upp referenser kan orsaka en prestandaförlust i miljöer som " -"använder dem mycket, ett notabelt exempel är Microsoft Active Directory. Om " -"din uppsättning inte faktiskt behöver använda referenser kan att sätta detta " -"alternativ till falskt medföra en märkbar prestandaförbättring. Att sätta " -"denna flagga till falskt rekommenderas därför ifall SSSD LDAP-leverantören " -"används tillsammans med Microsoft Active Directory som bakände. Även om SSSD " -"skulle kunna följa referensen till en annan AD DC skulle inga ytterligare " -"data vara tillgängliga." +"Att följa referenser kan försämra prestandan i miljöer där de används " +"mycket; Microsoft Active Directory är ett tydligt exempel. Om din " +"konfiguration inte behöver använda referenser kan det ge en märkbar " +"prestandaförbättring att ställa det här alternativet till false. Därför " +"rekommenderas false när SSSD:s LDAP-leverantör används tillsammans med " +"Microsoft Active Directory som bakomliggande komponent. Även om SSSD kan " +"följa referensen till en annan AD DC blir inga ytterligare data tillgängliga." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1312 @@ -8207,7 +8672,7 @@ msgstr "ldap_dns_service_name (sträng)" #: sssd-ldap.5.xml:1315 msgid "Specifies the service name to use when service discovery is enabled." msgstr "" -"Anger tjänstenamnet som skall användas när tjänsteupptäckt är aktiverat." +"Anger det tjänstenamn som ska användas när tjänsteupptäckt är aktiverad." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1319 @@ -8231,11 +8696,13 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1333 msgid "Default: not set, i.e. service discovery is disabled" -msgstr "Standard: inte satt, d.v.s. tjänsteupptäckt är avaktiverat" +msgstr "Standard: inte angivet, dvs. tjänsteupptäckt är inaktiverad" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1339 -msgid "ldap_chpass_update_last_change (bool)" +#, fuzzy +#| msgid "ldap_chpass_update_last_change (bool)" +msgid "ldap_chpass_update_last_change (boolean)" msgstr "ldap_chpass_update_last_change (boolean)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> @@ -8244,8 +8711,8 @@ msgid "" "Specifies whether to update the ldap_user_shadow_last_change attribute with " "days since the Epoch after a password change operation." msgstr "" -"Anger huruvida attributet ldap_user_shadow_last_change skall uppdateras med " -"dagar sedan epoken efter en ändring av lösenord." +"Anger om attributet ldap_user_shadow_last_change ska uppdateras med antal " +"dagar sedan epoken efter en lösenordsändring." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1348 @@ -8255,10 +8722,10 @@ msgid "" "shadowLastChange LDAP attribute automatically after a password change or if " "SSSD has to update it." msgstr "" -"Det rekommenderas att ställa in detta alternativ explicit om " -"\"ldap_pwd_policy = shadow\" används för att låta SSSD veta om LDAP-servern " -"kommer att uppdatera LDAP-attributet shadowLastChange automatiskt efter ett " -"lösenordsbyte eller om SSSD måste uppdatera det." +"Det rekommenderas att uttryckligen ställa in det här alternativet om " +"\"ldap_pwd_policy = shadow\" används, så att SSSD vet om LDAP-servern " +"automatiskt uppdaterar LDAP-attributet shadowLastChange efter en " +"lösenordsändring eller om SSSD måste uppdatera det." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1362 @@ -8280,18 +8747,17 @@ msgid "" "<citerefentry> <refentrytitle>sssd-simple</refentrytitle><manvolnum>5</" "manvolnum> </citerefentry>." msgstr "" -"Om man använder access_provider = ldap och ldap_access_order = filter " -"(standard) är detta alternativ nödvändigt. Det anger ett LDAP-" -"sökfilterkriterium som måste uppfyllas för att användaren skall ges åtkomst " -"till denna värd. Om access_provider = ldap, ldap_access_order = filter och " -"detta alternativ inte är satt kommer det resultera i att alla användare " -"nekas åtkomst. Använd access_provider = permit för att ändra detta " -"standardbeteende. Observera att detta filter endast tillämpas på LDAP-" -"användarposten och därmed filter baserade på nästade grupper kanske inte " -"fungerar (t.ex. attributet memberOf i AD-poster pekar endast på direkta " -"föräldrar). Om filtrering baserad på nästade grupper behövs, se " -"<citerefentry> <refentrytitle>sssd-simple</refentrytitle><manvolnum>5</" -"manvolnum> </citerefentry>." +"Om access_provider = ldap och ldap_access_order = filter (standard) används " +"är det här alternativet obligatoriskt. Det anger ett LDAP-sökfilter som " +"måste matcha för att användaren ska få åtkomst till den här värden. Om " +"access_provider = ldap, ldap_access_order = filter och det här alternativet " +"inte är angivet nekas alla användare åtkomst. Använd access_provider = " +"permit för att ändra standardbeteendet. Observera att filtret endast " +"tillämpas på LDAP-användarposten och att filtrering baserad på nästlade " +"grupper därför kanske inte fungerar (attributet memberOf i AD-poster pekar " +"till exempel endast på direkta överordnade). Om filtrering baserad på " +"nästlade grupper krävs, se <citerefentry> <refentrytitle>sssd-simple</" +"refentrytitle><manvolnum>5</manvolnum> </citerefentry>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1385 @@ -8316,8 +8782,8 @@ msgid "" "This example means that access to this host is restricted to users whose " "employeeType attribute is set to \"admin\"." msgstr "" -"Detta exempel betyder att åtkomst till denna värd är begränsad till " -"användare vars attribut employeeType är satt till ”admin”." +"Det här exemplet innebär att åtkomsten till den här värden begränsas till " +"användare vars attribut employeeType är satt till \"admin\"." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1397 @@ -8327,10 +8793,10 @@ msgid "" "access during their last login, they will continue to be granted access " "while offline and vice versa." msgstr "" -"Frånkopplad cachning för denna funktion är begränsad till att avgöra " -"huruvida användarens senaste uppkopplade inloggning tilläts " -"åtkomsträttigheter. Om de tilläts vid senaste inloggningen kommer de " -"fortsätta ges åtkomst under frånkoppling, och vice versa." +"Frånkopplad cachelagring för den här funktionen är begränsad till att avgöra " +"om användarens senaste onlineinloggning beviljades åtkomst. Om användaren " +"beviljades åtkomst vid sin senaste inloggning fortsätter den att beviljas " +"när användaren är frånkopplad, och omvänt." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1405 sssd-ldap.5.xml:1461 @@ -8348,8 +8814,8 @@ msgid "" "With this option a client side evaluation of access control attributes can " "be enabled." msgstr "" -"Med detta alternativ kan en utvärdering på klientsidan av " -"åtkomststyrningsattribut aktiveras." +"Med det här alternativet kan en utvärdering av åtkomststyrningsattribut på " +"klientsidan aktiveras." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1418 @@ -8358,9 +8824,9 @@ msgid "" "i.e. the LDAP server should deny the bind request with a suitable error code " "even if the password is correct." msgstr "" -"Observera att det alltid är rekommenderat att använda åtkomstkontroll på " -"serversidan, d.v.s. LDAP-servern skall neka bindningsbegäran med en passande " -"felkod även om lösenordet är korrekt." +"Observera att åtkomststyrning på serversidan alltid rekommenderas, dvs. LDAP-" +"servern ska avslå bindningsbegäran med en lämplig felkod även om lösenordet " +"är korrekt." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1425 @@ -8373,8 +8839,8 @@ msgid "" "<emphasis>shadow</emphasis>: use the value of ldap_user_shadow_expire to " "determine if the account is expired." msgstr "" -"<emphasis>shadow</emphasis>: använd värdet på ldap_user_shadow_expire för " -"att avgöra om kontot har gått ut." +"<emphasis>shadow</emphasis>: använd värdet för ldap_user_shadow_expire för " +"att avgöra om kontot har löpt ut." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1433 @@ -8429,7 +8895,7 @@ msgid "ldap_access_order (string)" msgstr "ldap_access_order (sträng)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap.5.xml:1470 sssd-ipa.5.xml:405 +#: sssd-ldap.5.xml:1470 sssd-ipa.5.xml:400 msgid "Comma separated list of access control options. Allowed values are:" msgstr "" "Kommaseparerad lista över åtkomststyrningsalternativ. Tillåtna värden är:" @@ -8448,10 +8914,10 @@ msgid "" "Please note that 'access_provider = ldap' must be set for this feature to " "work." msgstr "" -"<emphasis>lockout</emphasis>: använd kontolåsning. Om satt nekar detta " -"alternativ åtkomst ifall ldap-attributet ”pwdAccountLockedTime” finns och " -"har värdet ”000001010000Z”. Se alternativet ldap_pwdlockout_dn. Observera " -"att ”access_provider = ldap” måste vara satt för att denna funktion skall " +"<emphasis>lockout</emphasis>: använd kontolåsning. Om alternativet är " +"angivet nekas åtkomst om LDAP-attributet 'pwdAccountLockedTime' finns och " +"har värdet '000001010000Z'. Se alternativet ldap_pwdlockout_dn. Observera " +"att 'access_provider = ldap' måste vara angivet för att funktionen ska " "fungera." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> @@ -8461,7 +8927,7 @@ msgid "" "quote> option and might be removed in a future release. </emphasis>" msgstr "" "<emphasis>Observera att detta alternativ ersätts av alternativet <quote>" -"ppolicy</quote> och kan komma att tas bort i en framtida utgåva.</emphasis>" +"ppolicy</quote> och kan komma att tas bort i en framtida utgåva. </emphasis>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1494 @@ -8475,14 +8941,14 @@ msgid "" "the option ldap_pwdlockout_dn. Please note that 'access_provider = ldap' " "must be set for this feature to work." msgstr "" -"<emphasis>ppolicy</emphasis>: använd kontolåsning. Om satt nekar detta " -"alternativ åtkomst ifall ldap-attributet ”pwdAccountLockedTime” finns och " -"har värdet ”000001010000Z” eller representerar en tidpunkt i det förgångna. " -"Värdet på attributet ”pwdAccountLockedTime” måste sluta med ”Z”, som " -"markerar tidszonen UTC. Andra tidszoner stödjs för närvarande inte och " -"kommer resultera i ”access-denied” när användare försöker logga in. Se " -"alternativet ldap_pwdlockout_dn. Observera att ”access_provider = ldap” " -"måste vara satt för att denna funktion skall fungera." +"<emphasis>ppolicy</emphasis>: använd kontolåsning. Om alternativet är " +"angivet nekas åtkomst om LDAP-attributet 'pwdAccountLockedTime' finns och " +"har värdet '000001010000Z' eller representerar en tidpunkt i det förflutna. " +"Värdet för attributet 'pwdAccountLockedTime' måste sluta med 'Z', som anger " +"tidszonen UTC. Andra tidszoner stöds för närvarande inte och resulterar i " +"\"access-denied\" när användare försöker logga in. Se alternativet " +"ldap_pwdlockout_dn. Observera att 'access_provider = ldap' måste vara " +"angivet för att funktionen ska fungera." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1511 @@ -8490,7 +8956,7 @@ msgid "<emphasis>expire</emphasis>: use ldap_account_expire_policy" msgstr "<emphasis>expire</emphasis>: använd ldap_account_expire_policy" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap.5.xml:1515 sssd-ipa.5.xml:413 +#: sssd-ldap.5.xml:1515 sssd-ipa.5.xml:408 msgid "" "<emphasis>pwd_expire_policy_reject, pwd_expire_policy_warn, " "pwd_expire_policy_renew: </emphasis> These options are useful if users are " @@ -8499,37 +8965,36 @@ msgid "" "example SSH keys." msgstr "" "<emphasis>pwd_expire_policy_reject, pwd_expire_policy_warn, " -"pwd_expire_policy_renew: </emphasis> Dessa alternativ är användbara om " -"användare vill bli varnade att lösenordet är på gång att gå ut och " -"autentisering är baserat på användning av en annan metod än lösenord – till " -"exempel SSH-nycklar." +"pwd_expire_policy_renew: </emphasis> De här alternativen är användbara för " +"användare som vill varnas när lösenordet snart löper ut och autentiseringen " +"bygger på en annan metod än lösenord, till exempel SSH-nycklar." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap.5.xml:1525 sssd-ipa.5.xml:423 +#: sssd-ldap.5.xml:1525 sssd-ipa.5.xml:418 msgid "" "The difference between these options is the action taken if user password is " "expired:" msgstr "" -"Skillnaden mellan dessa alternativ är åtgärden som vidtas om användarens " -"lösenord gått ut:" +"Skillnaden mellan de här alternativen är vilken åtgärd som vidtas om " +"användarens lösenord har löpt ut:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ldap.5.xml:1530 sssd-ipa.5.xml:428 +#: sssd-ldap.5.xml:1530 sssd-ipa.5.xml:423 msgid "pwd_expire_policy_reject - user is denied to log in," -msgstr "pwd_expire_policy_reject — användaren nekas att logga in," +msgstr "pwd_expire_policy_reject – användaren nekas inloggning," #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ldap.5.xml:1536 sssd-ipa.5.xml:434 +#: sssd-ldap.5.xml:1536 sssd-ipa.5.xml:429 msgid "pwd_expire_policy_warn - user is still able to log in," -msgstr "pwd_expire_policy_warn — användaren kan fortfarande logga in," +msgstr "pwd_expire_policy_warn – användaren kan fortfarande logga in," #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ldap.5.xml:1542 sssd-ipa.5.xml:440 +#: sssd-ldap.5.xml:1542 sssd-ipa.5.xml:435 msgid "" "pwd_expire_policy_renew - user is prompted to change their password " "immediately." msgstr "" -"pwd_expire_policy_renew — användaren ombeds att ändra sitt lösenord " +"pwd_expire_policy_renew – användaren uppmanas att ändra sitt lösenord " "omedelbart." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> @@ -8539,9 +9004,9 @@ msgid "" "work. Also 'ldap_pwd_policy' must be set to shadow or mit_kerberos, these " "options do not work with server-side password policies." msgstr "" -"Observera att ”access_provider = ldap” måste vara satt för att denna " -"funktion skall fungera. ”ldap_pwd_policy” måste också vara satt till shadow " -"eller mit_kerberos, dessa alternativ fungerar inte med lösenordspolicy på " +"Observera att 'access_provider = ldap' måste vara angivet för att funktionen " +"ska fungera. 'ldap_pwd_policy' måste också vara angivet som shadow eller " +"mit_kerberos; de här alternativen fungerar inte med lösenordspolicyer på " "serversidan." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> @@ -8551,13 +9016,14 @@ msgid "" "to determine access" msgstr "" "<emphasis>authorized_service</emphasis>: använd attributet authorizedService " -"för att avgöra åtkomst" +"för att avgöra om åtkomst ska beviljas" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1561 msgid "<emphasis>host</emphasis>: use the host attribute to determine access" msgstr "" -"<emphasis>host</emphasis>: använd attributet host för att avgöra åtkomst" +"<emphasis>host</emphasis>: använd attributet host för att avgöra om åtkomst " +"ska beviljas" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1565 @@ -8565,8 +9031,8 @@ msgid "" "<emphasis>rhost</emphasis>: use the rhost attribute to determine whether " "remote host can access" msgstr "" -"<emphasis>rhost</emphasis>: använd attributet rhost för att avgöra huruvida " -"fjärrvärdar kan få åtkomst" +"<emphasis>rhost</emphasis>: använd attributet rhost för att avgöra om " +"fjärrvärden kan få åtkomst" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1569 @@ -8574,9 +9040,9 @@ msgid "" "Please note, rhost field in pam is set by application, it is better to check " "what the application sends to pam, before enabling this access control option" msgstr "" -"Observera, rhost-fältet i pam sätts av programmet, det är bättre att " -"kontrollera vad programmet skickar till pam, före detta alternativ för " -"åtkomstkontroll aktiveras" +"Observera att fältet rhost i PAM sätts av programmet. Kontrollera därför vad " +"programmet skickar till PAM innan det här åtkomststyrningsalternativet " +"aktiveras." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1574 @@ -8605,10 +9071,10 @@ msgid "" "lockout checking will yield access denied as ppolicy attributes on LDAP " "server cannot be checked properly." msgstr "" -"Detta alternativ anger DN för lösenordspolicyposten på LDAP-servern. Notera " -"att frånvaro av detta alternativ i sssd.conf när kontroll av kontolåsning är " -"aktiverat kommer att resultera i nekad åtkomst eftersom ppolicy-attribut på " -"LDAP-servern inte kan kontrolleras ordentligt." +"Det här alternativet anger DN för lösenordspolicyposten på LDAP-servern. Om " +"alternativet saknas i sssd.conf när kontroll av kontolåsning är aktiverad " +"nekas åtkomst, eftersom ppolicy-attribut på LDAP-servern då inte kan " +"kontrolleras korrekt." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1595 @@ -8631,13 +9097,12 @@ msgid "" "Specifies how alias dereferencing is done when performing a search. The " "following options are allowed:" msgstr "" -"Anger hur dereferering av alias görs när sökningar utförs. Följande " -"alternativ är tillåtna:" +"Anger hur alias derefereras vid sökning. Följande alternativ är tillåtna:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1612 msgid "<emphasis>never</emphasis>: Aliases are never dereferenced." -msgstr "<emphasis>never</emphasis>: Alias är aldrig derefererade." +msgstr "<emphasis>never</emphasis>: Alias derefereras aldrig." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1616 @@ -8645,8 +9110,8 @@ msgid "" "<emphasis>searching</emphasis>: Aliases are dereferenced in subordinates of " "the base object, but not in locating the base object of the search." msgstr "" -"<emphasis>searching</emphasis>: Alias derefereras i underordnade till " -"basobjektet, men inte vid lokalisering av basobjektet för sökningen." +"<emphasis>searching</emphasis>: Alias derefereras i objekt som är " +"underordnade basobjektet, men inte när sökningens basobjekt hittas." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1621 @@ -8654,8 +9119,8 @@ msgid "" "<emphasis>finding</emphasis>: Aliases are only dereferenced when locating " "the base object of the search." msgstr "" -"<emphasis>finding</emphasis>: Alias derefereras endast vid lokalisering av " -"basobjektet för sökningen." +"<emphasis>finding</emphasis>: Alias derefereras endast när sökningens " +"basobjekt hittas." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1626 @@ -8663,8 +9128,8 @@ msgid "" "<emphasis>always</emphasis>: Aliases are dereferenced both in searching and " "in locating the base object of the search." msgstr "" -"<emphasis>always</emphasis>: Alias derefereras både i sökning och i " -"lokalisering av basobjektet för sökningen." +"<emphasis>always</emphasis>: Alias derefereras både vid sökning och när " +"sökningens basobjekt hittas." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1631 @@ -8672,13 +9137,13 @@ msgid "" "Default: Empty (this is handled as <emphasis>never</emphasis> by the LDAP " "client libraries)" msgstr "" -"Standard: Tomt (detta hanteras som <emphasis>never</emphasis> av LDAP-" +"Standard: tomt (detta hanteras som <emphasis>never</emphasis> av LDAP-" "klientbiblioteken)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1639 msgid "ldap_rfc2307_fallback_to_local_users (boolean)" -msgstr "ldap_rfc2307_fallback_to_local_users (boolean)" +msgstr "ldap_rfc2307_fallback_to_local_users (boolesk)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1642 @@ -8686,8 +9151,8 @@ msgid "" "Allows to retain local users as members of an LDAP group for servers that " "use the RFC2307 schema." msgstr "" -"Tillåter att behålla lokala användare som medlemmar i en LDAP-grupp för " -"servrar som använder schemat RFC2307." +"Gör det möjligt att behålla lokala användare som medlemmar i en LDAP-grupp " +"på servrar som använder RFC2307-schemat." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1646 @@ -8699,12 +9164,12 @@ msgid "" "memberships as soon as nsswitch tries to fetch information about the user " "via getpw*() or initgroups() calls." msgstr "" -"I en del miljöer där schemat RFC2307 används görs lokala användare till " -"medlemmar i LDAP-grupper genom att lägga till deras namn till attributet " -"memberUid. Den interna konsistensen i domänen bryts när detta görs, så SSSD " -"skulle normalt ta bort de ”saknade” användarna från de cachade " -"gruppmedlemskapen så fort nsswitch försöker hämta information om användaren " -"via anrop av getpw*() eller initgroups()." +"I vissa miljöer där RFC2307-schemat används görs lokala användare till " +"medlemmar i LDAP-grupper genom att deras namn läggs till i attributet " +"memberUid. Domänens interna konsekvens äventyras då, så SSSD tar normalt " +"bort de \"saknade\" användarna från de cachade gruppmedlemskapen så snart " +"nsswitch försöker hämta information om användaren via anrop till getpw*() " +"eller initgroups()." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1657 @@ -8713,9 +9178,9 @@ msgid "" "them so that later initgroups() calls will augment the local users with the " "additional LDAP groups." msgstr "" -"Detta alternativ faller tillbaka på att kontrollera om lokala användare är " -"refererade, och cachar dem så att senare anrop av initgroups() kommer utöka " -"de lokala användarna med de extra LDAP-grupperna." +"Det här alternativet återgår till att kontrollera om lokala användare " +"refereras och cachar dem, så att senare anrop till initgroups() utökar de " +"lokala användarnas grupper med ytterligare LDAP-grupper." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1669 sssd-ifp.5.xml:158 @@ -8734,7 +9199,9 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1676 msgid "At the moment, only the InfoPipe responder supports wildcard lookups." -msgstr "För närvarande stödjer endast respondenten InfoPipe jokeruppslagningar." +msgstr "" +"För närvarande är det endast svarsprogrammet InfoPipe som stöder " +"jokerteckenuppslagningar." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1680 @@ -8752,8 +9219,8 @@ msgid "" "Switches on libldap debugging with the given level. The libldap debug " "messages will be written independent of the general debug_level." msgstr "" -"Slår på libldap-felsökning med den angivna nivån. Libldap-felmeddelanden " -"kommer skrivas oberoende av den allmänna debug_level." +"Aktiverar libldap-felsökning med den angivna nivån. Libldap-" +"felsökningsmeddelandena skrivs oberoende av den allmänna debug_level." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1694 @@ -8761,18 +9228,18 @@ msgid "" "OpenLDAP uses a bitmap to enable debugging for specific components, -1 will " "enable full debug output." msgstr "" -"OpenLDAP använder en bitavbildning för att aktivera felsökning för specifika " -"komponenter, -1 kommer aktivera fullständig felsökningsutmatning." +"OpenLDAP använder en bitmapp för att aktivera felsökning av specifika " +"komponenter. -1 aktiverar fullständig felsökningsutdata." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1699 msgid "Default: 0 (libldap debugging disabled)" -msgstr "Standard: 0 (libldap-felsökning avaktiverat)" +msgstr "Standard: 0 (libldap-felsökning inaktiverad)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1705 msgid "ldap_use_ppolicy (boolean)" -msgstr "ldap_use_ppolicy (boolean)" +msgstr "ldap_use_ppolicy (boolesk)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1708 @@ -8781,9 +9248,9 @@ msgid "" "Disabling this allows interacting with services which send back invalid " "ppolicy extension." msgstr "" -"Slår på begäran av och förlitan på serversidans kontroller av " -"lösenordspolicy. Avaktivering av detta möjliggör interaktion med tjänster " -"vilka skickar tillbaka felaktiga ppolicy-utökningar." +"Aktiverar användning av lösenordspolicykontroller på serversidan. Om " +"alternativet inaktiveras kan tjänster som skickar tillbaka ett ogiltigt " +"ppolicy-tillägg användas." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1720 @@ -8800,12 +9267,12 @@ msgid "" "logins, one to verify the current password and a second one to perform the " "password change." msgstr "" -"Framtvingar en lösenordsändring när serversidans policystyrning är aktiverad " -"och den återstående fristen av inloggningar som returneras av servern efter " -"att autenticeringen når eller går nedanför tröskelvärdet. Observera att det " -"minsta användbara värdet är 2, eftersom att ändra lösenordet förbrukar 2 " -"ytterligar inloggningar från fristen, en för att verifiera det aktuella " -"lösenordet och en andra för att utföra lösenordsbytet." +"Tvingar fram en lösenordsändring när lösenordspolicykontroller på " +"serversidan är aktiverade och antalet återstående fristinloggningar som " +"servern returnerar efter autentiseringen når eller understiger " +"tröskelvärdet. Observera att det minsta användbara värdet är 2, eftersom en " +"lösenordsändring förbrukar ytterligare 2 fristinloggningar: en för att " +"verifiera det aktuella lösenordet och en för att utföra lösenordsändringen." #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ldap.5.xml:52 @@ -8818,14 +9285,13 @@ msgid "" "<refentrytitle>sssd-ldap-attributes</refentrytitle> <manvolnum>5</manvolnum> " "</citerefentry> manual page. <placeholder type=\"variablelist\" id=\"0\"/>" msgstr "" -"Alla de vanliga konfigurationsflaggorna som gäller för SSSD-domäner gäller " -"även för LDAP-domäner. Se avsnittet <quote>DOMÄNSEKTIONER</quote> i " -"manualsidan <citerefentry> <refentrytitle>sssd.conf</refentrytitle> " -"<manvolnum>5</manvolnum> </citerefentry> för fullständiga detaljer. " -"Observera att SSSD LDAP-avbildningsattribut beskrivs i manualsidan " -"<citerefentry> <refentrytitle>sssd-ldap-attributes</refentrytitle> " -"<manvolnum>5</manvolnum> </citerefentry>. <placeholder type=\"variablelist\" " -"id=\"0\"/>" +"Alla vanliga konfigurationsalternativ som gäller för SSSD-domäner gäller " +"även för LDAP-domäner. Fullständig information finns i avsnittet <quote>" +"DOMÄNAVSNITT</quote> på manualsidan <citerefentry> <refentrytitle>sssd.conf</" +"refentrytitle> <manvolnum>5</manvolnum> </citerefentry>. Observera att " +"SSSD:s LDAP-mappningsattribut beskrivs på manualsidan <citerefentry> " +"<refentrytitle>sssd-ldap-attributes</refentrytitle> <manvolnum>5</manvolnum> " +"</citerefentry>. <placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><title> #: sssd-ldap.5.xml:1743 @@ -8839,7 +9305,7 @@ msgid "" "manual page <citerefentry> <refentrytitle>sssd-sudo</refentrytitle> " "<manvolnum>5</manvolnum> </citerefentry>." msgstr "" -"De detaljerade instruktionerna för att konfigurera sudo-leverantören finns i " +"Detaljerade instruktioner för att konfigurera sudo_provider finns på " "manualsidan <citerefentry> <refentrytitle>sssd-sudo</refentrytitle> " "<manvolnum>5</manvolnum> </citerefentry>." @@ -8854,9 +9320,8 @@ msgid "" "How many seconds SSSD will wait between executing a full refresh of sudo " "rules (which downloads all rules that are stored on the server)." msgstr "" -"Hur många sekunder SSSD kommer vänta mellan körningar av fullständiga " -"uppdateringar av sudo-regler (som hämtar alla regler som är lagrade på " -"servern)." +"Anger hur många sekunder SSSD väntar mellan fullständiga uppdateringar av " +"sudo-reglerna (som hämtar alla regler som lagras på servern)." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1764 @@ -8873,8 +9338,9 @@ msgid "" "You can disable full refresh by setting this option to 0. However, either " "smart or full refresh must be enabled." msgstr "" -"Man kan avaktivera fullständig uppdatering genom att sätta denna flagga till " -"0. Dock måste antingen smart eller fullständig uppdatering aktiveras." +"Du kan inaktivera fullständig uppdatering genom att ställa det här " +"alternativet till 0. Antingen smart eller fullständig uppdatering måste dock " +"vara aktiverad." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1774 @@ -8893,9 +9359,9 @@ msgid "" "rules (which downloads all rules that have USN higher than the highest " "server USN value that is currently known by SSSD)." msgstr "" -"Hur många sekunder SSSD måste vänta mellan körningar av en smart uppdatering " -"av sudo-regler (som hämtar alla regler som har USN högre än serverns högsta " -"USN-värde som för närvarande är känt av SSSD)." +"Anger hur många sekunder SSSD måste vänta innan en smart uppdatering av sudo-" +"reglerna utförs (den hämtar alla regler med ett USN som är högre än det " +"högsta server-USN som SSSD för närvarande känner till)." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1789 @@ -8903,8 +9369,8 @@ msgid "" "If USN attributes are not supported by the server, the modifyTimestamp " "attribute is used instead." msgstr "" -"Om USN-attribut inte stödjs av servern används attributet modifyTimestamp " -"istället." +"Om servern inte stöder USN-attribut används attributet modifyTimestamp i " +"stället." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1793 @@ -8915,11 +9381,11 @@ msgid "" "found) and 3) by reconnecting to the server (by default every 15 minutes, " "see <emphasis>ldap_connection_expire_timeout</emphasis>)." msgstr "" -"<emphasis>Obs:</emphasis> det högsta USN-värdet kan uppdateras av tre " -"uppgifter: 1) Genom fullständig och smart sudo-uppdatering (om det finns " -"uppdaterade regler), 2) genom uppräkning av användare och grupper (om det " -"finns aktiverade och uppdaterade användare eller grupper) och 3) genom att " -"återansluta till servern (som standard var 15:e minut, se <emphasis>" +"<emphasis>Obs:</emphasis> Det högsta USN-värdet kan uppdateras av tre " +"åtgärder: 1) genom fullständig eller smart sudo-uppdatering (om uppdaterade " +"regler hittas), 2) genom uppräkning av användare och grupper (om funktionen " +"är aktiverad och uppdaterade användare eller grupper hittas) och 3) genom " +"återanslutning till servern (som standard var 15:e minut; se <emphasis>" "ldap_connection_expire_timeout</emphasis>)." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> @@ -8928,8 +9394,9 @@ msgid "" "You can disable smart refresh by setting this option to 0. However, either " "smart or full refresh must be enabled." msgstr "" -"Man kan avaktivera smart uppdatering genom att sätta denna flagga till 0. " -"Dock måste antingen smart eller fullständig uppdatering aktiveras." +"Du kan inaktivera smart uppdatering genom att ställa det här alternativet " +"till 0. Antingen smart eller fullständig uppdatering måste dock vara " +"aktiverad." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1815 @@ -8943,9 +9410,9 @@ msgid "" "refresh periods each time the periodic task is scheduled. The value is in " "seconds." msgstr "" -"En slumptillägg mellan 0 och ett konfigurerat värde läggs till till smart " -"och fullständig uppdateringsperioder varje gång den periodiska uppgiften " -"schemaläggs. Värdet är i sekunder." +"En slumpmässig förskjutning mellan 0 och det konfigurerade värdet läggs till " +"i intervallen för smart och fullständig uppdatering varje gång den " +"periodiska uppgiften schemaläggs. Värdet anges i sekunder." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1824 @@ -8954,19 +9421,20 @@ msgid "" "delays the first sudo rules refresh. This prolongs the time when the sudo " "rules are not available for use." msgstr "" -"Observera att detta slumpvisa tilläg även används på den första SSSD-starten " -"vilked fördröjer den första uppdateringen av sudo-regler. Detta förlänger " -"tiden under vilken sudo-reglerna inte är tillgängliga för användning." +"Observera att den slumpmässiga förskjutningen även tillämpas vid den första " +"starten av SSSD, vilket fördröjer den första uppdateringen av sudo-reglerna. " +"Detta förlänger tiden då sudo-reglerna inte är tillgängliga." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1830 msgid "You can disable this offset by setting the value to 0." -msgstr "Man kan avaktivera denna fördröjning genom att sätta värdet till 0." +msgstr "" +"Du kan inaktivera den här förskjutningen genom att ställa värdet till 0." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1840 msgid "ldap_sudo_use_host_filter (boolean)" -msgstr "ldap_sudo_use_host_filter (boolean)" +msgstr "ldap_sudo_use_host_filter (boolesk)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1843 @@ -8974,8 +9442,8 @@ msgid "" "If true, SSSD will download only rules that are applicable to this machine " "(using the IPv4 or IPv6 host/network addresses and hostnames)." msgstr "" -"Om sann kommer SSSD hämta endast regler som är tillämpliga för denna maskin " -"(genom användning av IPv4- och IPv6-värd-/-nätverksadresser och värdnamn)." +"Om true hämtar SSSD endast regler som gäller för den här datorn (med IPv4- " +"eller IPv6-adresser för värdar och nätverk samt värdnamn)." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1854 @@ -8988,8 +9456,8 @@ msgid "" "Space separated list of hostnames or fully qualified domain names that " "should be used to filter the rules." msgstr "" -"Mellanrumsseparerad lista över värdnamn eller fullständigt kvalificerade " -"domännamn som skall användas för att filtrera reglerna." +"Mellanslagsseparerad lista med värdnamn eller fullständigt kvalificerade " +"domännamn som ska användas för att filtrera reglerna." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1862 @@ -8997,8 +9465,8 @@ msgid "" "If this option is empty, SSSD will try to discover the hostname and the " "fully qualified domain name automatically." msgstr "" -"Om detta alternativ är tomt kommer SSSD försöka upptäcka värdnamnet och det " -"fullständigt kvalificerade domännamnet automatiskt." +"Om det här alternativet är tomt försöker SSSD automatiskt identifiera " +"värdnamnet och det fullständigt kvalificerade domännamnet." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1867 sssd-ldap.5.xml:1890 sssd-ldap.5.xml:1908 @@ -9026,8 +9494,8 @@ msgid "" "Space separated list of IPv4 or IPv6 host/network addresses that should be " "used to filter the rules." msgstr "" -"Mellanrumsseparerad lista över IPv4- eller IPv6 värd-/nätverksadresser som " -"skall användas för att filtrera reglerna." +"Mellanslagsseparerad lista med IPv4- eller IPv6-adresser för värdar och " +"nätverk som ska användas för att filtrera reglerna." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1886 @@ -9035,13 +9503,13 @@ msgid "" "If this option is empty, SSSD will try to discover the addresses " "automatically." msgstr "" -"Om detta alternativ är tomt kommer SSSD försöka upptäcka adresser " -"automatiskt." +"Om det här alternativet är tomt försöker SSSD automatiskt identifiera " +"adresserna." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1901 msgid "ldap_sudo_include_netgroups (boolean)" -msgstr "ldap_sudo_include_netgroups (boolean)" +msgstr "ldap_sudo_include_netgroups (boolesk)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1904 @@ -9049,13 +9517,13 @@ msgid "" "If true then SSSD will download every rule that contains a netgroup in " "sudoHost attribute." msgstr "" -"Om sant kommer SSSD hämta varje regel som innehåller en nätgrupp i " -"attributet sudoHost." +"Om true hämtar SSSD alla regler som innehåller en nätgrupp i attributet " +"sudoHost." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1919 msgid "ldap_sudo_include_regexp (boolean)" -msgstr "ldap_sudo_include_regexp (boolean)" +msgstr "ldap_sudo_include_regexp (boolesk)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1922 @@ -9063,8 +9531,8 @@ msgid "" "If true then SSSD will download every rule that contains a wildcard in " "sudoHost attribute." msgstr "" -"Om sant kommer SSSD hämta varje regel som innehåller ett jokertecken i " -"attributet sudoHost." +"Om true hämtar SSSD alla regler som innehåller ett jokertecken i attributet " +"sudoHost." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><note><para> #: sssd-ldap.5.xml:1932 @@ -9072,8 +9540,8 @@ msgid "" "Using wildcard is an operation that is very costly to evaluate on the LDAP " "server side!" msgstr "" -"Att använda jokertecken är en operation som är väldigt dyr att evaluera på " -"LDAP-serversidan!" +"Att använda jokertecken är en åtgärd som är mycket kostsam att utvärdera på " +"LDAP-servern!" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ldap.5.xml:1944 @@ -9083,10 +9551,10 @@ msgid "" "<refentrytitle>sudoers.ldap</refentrytitle><manvolnum>5</manvolnum> </" "citerefentry>" msgstr "" -"Denna manualsida beskriver endast attributnamnsöversättningar. För " -"detaljerade beskrivningar av semantiken hos sudo-relaterade attribut, se " -"<citerefentry> <refentrytitle>sudoers.ldap</refentrytitle><manvolnum>5</" -"manvolnum> </citerefentry>" +"Den här manualsidan beskriver endast mappning av attributnamn. En detaljerad " +"förklaring av semantiken för sudo-relaterade attribut finns i <citerefentry> " +"<refentrytitle>sudoers.ldap</refentrytitle><manvolnum>5</manvolnum> </" +"citerefentry>" #. type: Content of: <reference><refentry><refsect1><title> #: sssd-ldap.5.xml:1954 @@ -9098,8 +9566,7 @@ msgstr "AUTOFSALTERNATIV" msgid "" "Some of the defaults for the parameters below are dependent on the LDAP " "schema." -msgstr "" -"Några av standardvärdena för parametrar nedan är beroende på LDAP-schemat." +msgstr "Vissa standardvärden för parametrarna nedan beror på LDAP-schemat." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1962 @@ -9109,7 +9576,7 @@ msgstr "ldap_autofs_map_master_name (sträng)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1965 msgid "The name of the automount master map in LDAP." -msgstr "Namnet på automount master-kartan i LDAP." +msgstr "Namnet på huvudkartan för automatmontering i LDAP." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1968 @@ -9149,10 +9616,10 @@ msgid "" "memberships, even with no GID mapping. It is recommended to disable this " "feature, if group names are not being displayed correctly." msgstr "" -"Om alternativet <quote>ldap_use_tokengroups</quote> är aktiverat kommer " -"sökningarna i Active Directory inte vara begränsade och returnera alla " -"gruppmedlemskap, även utan någon GID-översättning. Det rekommenderas att " -"avaktivera denna funktion om gruppnamn inte visas korrekt." +"Om alternativet <quote>ldap_use_tokengroups</quote> är aktiverat begränsas " +"inte sökningarna i Active Directory och alla gruppmedlemskap returneras, " +"även om någon GID-mappning saknas. Det rekommenderas att inaktivera " +"funktionen om gruppnamnen inte visas korrekt." #. type: Content of: <reference><refentry><refsect1><para><variablelist> #: sssd-ldap.5.xml:2010 @@ -9177,14 +9644,14 @@ msgid "" "are doing. <placeholder type=\"variablelist\" id=\"0\"/> <placeholder " "type=\"variablelist\" id=\"1\"/>" msgstr "" -"Dessa flaggor stöds av LDAP-domäner, men de skall användas med " -"försiktighet. Inkludera dem endast i din konfiguration om du vet vad du " -"gör. <placeholder type=\"variablelist\" id=\"0\"/> <placeholder " +"De här alternativen stöds av LDAP-domäner, men ska användas med " +"försiktighet. Ta endast med dem i konfigurationen om du vet vad du gör. " +"<placeholder type=\"variablelist\" id=\"0\"/> <placeholder " "type=\"variablelist\" id=\"1\"/>" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd-ldap.5.xml:2032 sssd-simple.5.xml:169 sssd-ipa.5.xml:984 -#: sssd-ad.5.xml:1470 sssd-idp.5.xml:248 sssd-krb5.5.xml:483 +#: sssd-ldap.5.xml:2032 sssd-simple.5.xml:169 sssd-ipa.5.xml:979 +#: sssd-ad.5.xml:1463 sssd-idp.5.xml:343 sssd-krb5.5.xml:483 #: sss_rpcidmapd.5.xml:98 sssd-session-recording.5.xml:176 msgid "EXAMPLE" msgstr "EXEMPEL" @@ -9196,8 +9663,9 @@ msgid "" "set to one of the domains in the <replaceable>[domains]</replaceable> " "section." msgstr "" -"Följande exempel antar att SSSD är korrekt konfigurerat och att LDAP är satt " -"till en av domänerna i avsnittet <replaceable>[domains]</replaceable>." +"Följande exempel förutsätter att SSSD är korrekt konfigurerat och att LDAP " +"har angetts som en av domänerna i avsnittet <replaceable>[domains]</" +"replaceable>." #. type: Content of: <reference><refentry><refsect1><para><programlisting> #: sssd-ldap.5.xml:2040 @@ -9214,14 +9682,14 @@ msgstr "" "[domain/LDAP]\n" "id_provider = ldap\n" "auth_provider = ldap\n" -"ldap_uri = ldap://ldap.mindomän.se\n" -"ldap_search_base = dc=mindomän,dc=se\n" +"ldap_uri = ldap://ldap.mydomain.org\n" +"ldap_search_base = dc=mydomain,dc=org\n" "ldap_tls_reqcert = demand\n" "cache_credentials = true\n" #. type: Content of: <refsect1><refsect2><para> #: sssd-ldap.5.xml:2039 sssd-ldap.5.xml:2057 sssd-simple.5.xml:177 -#: sssd-ipa.5.xml:992 sssd-ad.5.xml:1478 sssd-sudo.5.xml:56 sssd-krb5.5.xml:492 +#: sssd-ipa.5.xml:987 sssd-ad.5.xml:1471 sssd-sudo.5.xml:56 sssd-krb5.5.xml:492 #: sssd-session-recording.5.xml:182 include/ldap_id_mapping.xml:105 msgid "<placeholder type=\"programlisting\" id=\"0\"/>" msgstr "<placeholder type=\"programlisting\" id=\"0\"/>" @@ -9237,8 +9705,8 @@ msgid "" "The following example assumes that SSSD is correctly configured and to use " "the ldap_access_order=lockout." msgstr "" -"Följande exempel antar att SSSD är korrekt konfigurerat och att " -"ldap_access_order=lockout används." +"Följande exempel förutsätter att SSSD är korrekt konfigurerat för att " +"använda ldap_access_order=lockout." #. type: Content of: <reference><refentry><refsect1><para><programlisting> #: sssd-ldap.5.xml:2058 @@ -9260,17 +9728,17 @@ msgstr "" "auth_provider = ldap\n" "access_provider = ldap\n" "ldap_access_order = lockout\n" -"ldap_pwdlockout_dn = cn=ppolicy,ou=policies,dc=mindomän,dc=se\n" -"ldap_uri = ldap://ldap.mindomän.se\n" -"ldap_search_base = dc=mindomän,dc=se\n" +"ldap_pwdlockout_dn = cn=ppolicy,ou=policies,dc=mydomain,dc=org\n" +"ldap_uri = ldap://ldap.mydomain.org\n" +"ldap_search_base = dc=mydomain,dc=org\n" "ldap_tls_reqcert = demand\n" "cache_credentials = true\n" #. type: Content of: <reference><refentry><refsect1><title> #: sssd-ldap.5.xml:2073 sssd_krb5_locator_plugin.8.xml:83 sssd-simple.5.xml:189 -#: sssd-ad.5.xml:1493 sssd.8.xml:270 sss_seed.8.xml:163 +#: sssd-ad.5.xml:1486 sssd.8.xml:270 sss_seed.8.xml:163 msgid "NOTES" -msgstr "NOTER" +msgstr "ANMÄRKNINGAR" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ldap.5.xml:2075 @@ -9280,10 +9748,10 @@ msgid "" "<manvolnum>5</manvolnum> </citerefentry> manual page from the OpenLDAP 2.4 " "distribution." msgstr "" -"Beskrivningarna av en del konfigurationflaggor i denna manualsida är " -"baserade på manualsidan <citerefentry> <refentrytitle>ldap.conf</" -"refentrytitle> <manvolnum>5</manvolnum> </citerefentry> från distributionen " -"OpenLDAP 2.4." +"Beskrivningarna av några av konfigurationsalternativen på den här " +"manualsidan bygger på manualsidan <citerefentry> <refentrytitle>ldap.conf</" +"refentrytitle> <manvolnum>5</manvolnum> </citerefentry> från OpenLDAP 2.4-" +"distributionen." #. type: Content of: <reference><refentry><refnamediv><refname> #: pam_sss.8.xml:11 pam_sss.8.xml:16 @@ -9342,16 +9810,16 @@ msgid "" "Services daemon (SSSD). Errors and results are logged through " "<command>syslog(3)</command> with the LOG_AUTHPRIV facility." msgstr "" -"<command>pam_sss.so</command> är PAM-gränssnittet till System Security " -"Services daemon (SSSD). Fel och resultat loggas via <command>syslog(3)</" -"command> med funktionen LOG_AUTHPRIV." +"<command>pam_sss.so</command> är PAM-gränssnittet till bakgrundsprocessen " +"System Security Services (SSSD). Fel och resultat loggas via <command>syslog" +"(3)</command> med faciliteten LOG_AUTHPRIV." #. type: Content of: <reference><refentry><refsect1><title> #: pam_sss.8.xml:73 pam_sss_gss.8.xml:89 sssd.8.xml:42 sss_obfuscate.8.xml:58 #: sss_cache.8.xml:39 sss_seed.8.xml:42 sss_ssh_authorizedkeys.1.xml:123 #: sss_ssh_knownhosts.1.xml:59 msgid "OPTIONS" -msgstr "FLAGGOR" +msgstr "ALTERNATIV" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:77 @@ -9374,8 +9842,8 @@ msgid "" "If <option>forward_pass</option> is set the entered password is put on the " "stack for other PAM modules to use." msgstr "" -"Om <option>forward_pass</option> är satt läggs det inskrivna lösenordet på " -"stacken så att andra PAM-moduler kan använda det." +"Om <option>forward_pass</option> är angivet läggs det inskrivna lösenordet " +"på stacken så att andra PAM-moduler kan använda det." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:95 @@ -9389,9 +9857,9 @@ msgid "" "modules password and will never prompt the user - if no password is " "available or the password is not appropriate, the user will be denied access." msgstr "" -"Argumentet use_first_pass tvingar modulen att använda tidigare stackade " -"modulers lösenord och kommer aldrig fråga användaren – om inget lösenord är " -"tillgängligt eller lösenordet inte stämmer kommer användaren nekas åtkomst." +"Argumentet use_first_pass tvingar modulen att använda lösenordet från en " +"tidigare staplad modul och frågar aldrig användaren. Om inget lösenord är " +"tillgängligt eller lösenordet inte är lämpligt nekas användaren åtkomst." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:106 @@ -9404,8 +9872,8 @@ msgid "" "When password changing enforce the module to set the new password to the one " "provided by a previously stacked password module." msgstr "" -"Vid lösenordsändring tvinga modulen till att sätta det nya lösenordet till " -"det som gavs av en tidigare stackad lösenordsmodul." +"Vid lösenordsändring tvingas modulen att sätta det nya lösenordet till det " +"som har lämnats av en tidigare staplad lösenordsmodul." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:116 @@ -9418,8 +9886,8 @@ msgid "" "If specified the user is asked another N times for a password if " "authentication fails. Default is 0." msgstr "" -"Om angivet frågas användaren ytterligare N gånger om ett lösenord ifall " -"autentiseringen misslyckas. Standard är 0." +"Om alternativet är angivet uppmanas användaren ytterligare N gånger att ange " +"ett lösenord om autentiseringen misslyckas. Standardvärdet är 0." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:121 @@ -9428,8 +9896,8 @@ msgid "" "calling PAM handles the user dialog on its own. A typical example is " "<command>sshd</command> with <option>PasswordAuthentication</option>." msgstr "" -"Observera att denna flagga kanske inte fungerar som förväntat ifall " -"programmet som anropar PAM hanterar användardialogen själv. Ett typiskt " +"Observera att det här alternativet kanske inte fungerar som förväntat om " +"programmet som anropar PAM själv hanterar användardialogen. Ett typiskt " "exempel är <command>sshd</command> med <option>PasswordAuthentication</" "option>." @@ -9444,8 +9912,8 @@ msgid "" "If this option is specified and the user does not exist, the PAM module will " "return PAM_IGNORE. This causes the PAM framework to ignore this module." msgstr "" -"Om denna flagga anges och användaren inte finns kommer PAM-modulen returnera " -"PAM_IGNORE. Detta får PAM-ramverket att ignorera denna modul." +"Om det här alternativet är angivet och användaren inte finns returnerar PAM-" +"modulen PAM_IGNORE. Det gör att PAM-ramverket ignorerar modulen." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:140 @@ -9458,8 +9926,8 @@ msgid "" "Specifies that the PAM module should return PAM_IGNORE if it cannot contact " "the SSSD daemon. This causes the PAM framework to ignore this module." msgstr "" -"Anger att PAM-modulen skall returnera PAM_IGNORE om det inte kan kontakta " -"SSSD-demonen. Detta får PAM-ramverket att ignorera denna modul." +"Anger att PAM-modulen ska returnera PAM_IGNORE om den inte kan kontakta SSSD-" +"bakgrundsprocessen. Det gör att PAM-ramverket ignorerar modulen." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:151 @@ -9473,9 +9941,9 @@ msgid "" "allowed to authenticate against. The format is a comma-separated list of " "SSSD domain names, as specified in the sssd.conf file." msgstr "" -"Tillåter administratören att begränsa domänerna en viss PAM-tjänst tillåts " -"autentisera emot. Formatet är en kommaseparerad lista över SSSD-domännamn " -"som de specificeras i filen sssd.conf." +"Gör det möjligt för administratören att begränsa vilka domäner en viss PAM-" +"tjänst får autentisera mot. Formatet är en kommaseparerad lista med SSSD-" +"domännamn enligt uppgifterna i filen sssd.conf." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:161 @@ -9487,12 +9955,12 @@ msgid "" "manvolnum> </citerefentry> manual page for more information on these two PAM " "responder options." msgstr "" -"OBS: om detta används för en tjänst som inte kör som root-användaren, t.ex. " -"en webb-server, måste det användas tillsammans med flaggorna <quote>" -"pam_trusted_users</quote> och <quote>pam_public_domains</quote>. Se " +"OBS: Om detta används för en tjänst som inte körs som root, till exempel en " +"webbserver, måste det användas tillsammans med alternativen <quote>" +"pam_trusted_users</quote> och <quote>pam_public_domains</quote>. Mer " +"information om dessa två alternativ för PAM-svarskomponenten finns på " "manualsidan <citerefentry> <refentrytitle>sssd.conf</refentrytitle> " -"<manvolnum>5</manvolnum> </citerefentry> för mer information om dessa två " -"PAM-respondentalternativ." +"<manvolnum>5</manvolnum> </citerefentry>." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:176 @@ -9505,8 +9973,9 @@ msgid "" "The main purpose of this option is to let SSSD determine the user name based " "on additional information, e.g. the certificate from a Smartcard." msgstr "" -"Huvudsyftet med denna flagga är att låta SSSD avgöra användarnamnet baserat " -"på ytterligare information, t.ex. certifikatet från ett smartkort." +"Huvudsyftet med det här alternativet är att låta SSSD fastställa " +"användarnamnet utifrån ytterligare information, till exempel certifikatet på " +"ett smartkort." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><programlisting> #: pam_sss.8.xml:190 @@ -9529,11 +9998,11 @@ msgid "" "it on the PAM stack." msgstr "" "Det aktuella användningsfallet är inloggningshanterare som kan övervaka en " -"smartkortläsare om korthändelser. Ifall en smartkort sätts in kommer " -"inloggningshanteraren anropa en PAM-stack som innehåller en rad som " -"<placeholder type=\"programlisting\" id=\"0\"/> I detta fall kommer SSSD " -"försöka avgöra användarnamnet baserat på innehållet på smartkortet, " -"returnerar det till pam_sss som slutligen kommer lägga det på PAM-stacken." +"smartkortsläsare med avseende på korthändelser. Om ett smartkort sätts in " +"anropar inloggningshanteraren en PAM-stack som innehåller en rad som " +"<placeholder type=\"programlisting\" id=\"0\"/> I det här fallet försöker " +"SSSD fastställa användarnamnet utifrån smartkortets innehåll, returnerar det " +"till pam_sss, som slutligen lägger det på PAM-stacken." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:200 @@ -9549,11 +10018,12 @@ msgid "" "SSSD pam_sss might prompt for a password, a Smartcard PIN or other " "credentials." msgstr "" -"Fråga alltid användaren om kreditiv. Med denna flagga kommer kreditiv " -"begärda av andra PAM-moduler, typiskt ett lösenord, ignoreras och pam_sss " -"kommer fråga efter kreditiv igen. Baserat på förautentiseringssvaret från " -"SSSD kan pam_sss komma att fråga efter ett lösenord, ett smartkorts-PIN " -"eller andra kreditiv." +"Fråga alltid användaren efter autentiseringsuppgifter. Med det här " +"alternativet ignoreras autentiseringsuppgifter som begärs av andra PAM-" +"moduler, vanligen ett lösenord, och pam_sss frågar efter " +"autentiseringsuppgifter på nytt. Baserat på SSSD:s svar före autentisering " +"kan pam_sss fråga efter ett lösenord, en PIN-kod för smartkort eller andra " +"autentiseringsuppgifter." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:215 @@ -9568,10 +10038,10 @@ msgid "" "allowed for Smartcard authentication the user will be prompted for a PIN and " "the certificate based authentication will continue" msgstr "" -"Försök använda certifikatbaserad smartkortsautentisering, d.v.s. " -"autentisering med smartkort eller liknande enheter. Om ett smartkort är " -"tillgängligt och tjänsten tillåter smartkortsautentisering kommer användaren " -"frågas om ett PIN och certifikatbaserad autentisering kommer fortsätta" +"Försök använda certifikatbaserad autentisering, dvs. autentisering med ett " +"smartkort eller liknande enheter. Om ett smartkort är tillgängligt och " +"tjänsten tillåter smartkortsautentisering uppmanas användaren att ange en " +"PIN-kod och den certifikatbaserade autentiseringen fortsätter." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:227 @@ -9597,12 +10067,12 @@ msgid "" "<citerefentry><refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</" "manvolnum></citerefentry> for details." msgstr "" -"Använd certifikatbaserad autentisering, d.v.s. autentisering med smartkort " -"eller liknande enheter. Om ett smartkort inte är tillgängligt ombeds " -"användaren att sätta in ett. SSSD kommer att vänta på ett smartkort tills " -"tidsgränsen definierad av p11_wait_for_card_timeout har passerats, se " -"<citerefentry><refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</" -"manvolnum></citerefentry> för detaljer." +"Utför certifikatbaserad autentisering, dvs. autentisering med ett smartkort " +"eller liknande enheter. Om ett smartkort inte är tillgängligt uppmanas " +"användaren att sätta in ett. SSSD väntar på ett smartkort tills den " +"tidsgräns som anges av p11_wait_for_card_timeout löper ut. Mer information " +"finns i <citerefentry><refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</" +"manvolnum></citerefentry>." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:249 @@ -9626,8 +10096,8 @@ msgid "" "By default the chauthtok PAM action will short-circuit to returning " "PAM_SUCCESS when pam_sss.so is invoked by root user." msgstr "" -"Som standard kommer chauthtok PAM-åtgärden att kortsluta till att returnera " -"PAM_SUCCESS när pam_sss.so anropas av root-användaren." +"Som standard avslutas PAM-åtgärden chauthtok direkt med PAM_SUCCESS när " +"pam_sss.so anropas av root." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:266 @@ -9635,8 +10105,8 @@ msgid "" "This option disables this behavior allowing to change auth tokens when " "running as root." msgstr "" -"Det här alternativet inaktiverar det här beteendet och gör det möjligt att " -"ändra autentiseringstoken när du kör som root." +"Det här alternativet inaktiverar beteendet och gör det möjligt att ändra " +"autentiseringstoken vid körning som root." #. type: Content of: <reference><refentry><refsect1><title> #: pam_sss.8.xml:275 pam_sss_gss.8.xml:103 @@ -9660,10 +10130,10 @@ msgid "" "<option>account</option> module to avoid issues with users from other " "sources during access control." msgstr "" -"Om SSSD:s PAM-respondent inte kör, t.ex. om PAM-respondentens uttag (socket) " -"inte är tillgängligt kommer pam_sss returnera PAM_USER_UNKNOWN när det " -"anropas som modulen <option>account</option> för att undvika problem med " -"användare från andra källor under åtkomstkontroll." +"Om SSSD:s PAM-svarskomponent inte körs, till exempel om dess uttag inte är " +"tillgängligt, returnerar pam_sss PAM_USER_UNKNOWN när den anropas som " +"<option>account</option>-modul. Det undviker problem med användare från " +"andra källor vid åtkomststyrning." #. type: Content of: <reference><refentry><refsect1><title> #: pam_sss.8.xml:286 pam_sss_gss.8.xml:108 @@ -9719,7 +10189,7 @@ msgid "" "Permission denied. The SSSD log files may contain additional information " "about the error." msgstr "" -"Åtkomst nekas. SSSD-loggfilerna kan innehålla ytterligare information om " +"Behörighet nekas. SSSD-loggfilerna kan innehålla ytterligare information om " "felet." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> @@ -9733,7 +10203,7 @@ msgid "" "See options <option>ignore_unknown_user</option> and " "<option>ignore_authinfo_unavail</option>." msgstr "" -"Se flaggorna <option>ignore_unknown_user</option> och <option>" +"Se alternativen <option>ignore_unknown_user</option> och <option>" "ignore_authinfo_unavail</option>." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> @@ -9749,10 +10219,10 @@ msgid "" "available, but the installed version of GDM does not support selection from " "multiple certificates." msgstr "" -"Kan inte hämta det nya autentiseringstecknet. Kan också returneras när " -"användaren autentiserar med certifikat och flera certifikat är tillgängliga, " -"men den installerade versionen av GDM inte stödjer val bland flera " -"certifikat." +"Det går inte att hämta den nya autentiseringstoken. Detta kan också " +"returneras när användaren autentiserar med certifikat och flera certifikat " +"är tillgängliga, men den installerade versionen av GDM inte stöder val " +"mellan flera certifikat." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:344 pam_sss_gss.8.xml:136 @@ -9780,9 +10250,9 @@ msgid "" "or use_authtok were set, but no password was found from the previously " "stacked PAM module." msgstr "" -"Ett minnesfel uppstod. Kan också returneras när flagga use_first_pass eller " -"use_authtok är satt, men inget lösenord hittades från den tidigare stackade " -"PAM-modulen." +"Ett minnesfel uppstod. Detta kan också returneras när alternativen " +"use_first_pass eller use_authtok har angetts men inget lösenord hittades " +"från den tidigare staplade PAM-modulen." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:363 pam_sss_gss.8.xml:145 @@ -9806,7 +10276,7 @@ msgstr "PAM_CRED_ERR" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:375 msgid "Unable to set the credentials of the user." -msgstr "Kan inte sätta kreditiv för användaren." +msgstr "Det går inte att ange användarens autentiseringsuppgifter." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:380 @@ -9820,9 +10290,9 @@ msgid "" "user. For example, missing PIN during smartcard authentication or missing " "factor during two-factor authentication." msgstr "" -"Programmet har inte tillräckliga kreditiv för att autentisera användaren. " -"Till exempel saknas PIN under smartkortsautentisering eller en saknad faktor " -"under tvåfaktorautentisering." +"Programmet har inte tillräckliga autentiseringsuppgifter för att autentisera " +"användaren. Det kan till exempel saknas en PIN-kod vid " +"smartkortsautentisering eller en faktor vid tvåfaktorsautentisering." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:391 @@ -9832,7 +10302,7 @@ msgstr "PAM_SERVICE_ERR" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:394 msgid "Error in service module." -msgstr "Fel i tjänstemodul." +msgstr "Fel i tjänstemodulen." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:399 @@ -9842,7 +10312,7 @@ msgstr "PAM_NEW_AUTHTOK_REQD" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:402 msgid "The user's authentication token has expired." -msgstr "Användarens autentiseringstecken har gått ut." +msgstr "Användarens autentiseringstoken har löpt ut." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:407 @@ -9852,7 +10322,7 @@ msgstr "PAM_ACCT_EXPIRED" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:410 msgid "The user account has expired." -msgstr "Användarkontot har gått ut." +msgstr "Användarkontot har löpt ut." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:415 @@ -9862,7 +10332,9 @@ msgstr "PAM_SESSION_ERR" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:418 msgid "Unable to fetch IPA Desktop Profile rules or user info." -msgstr "Kan inte hämta IPA-skrivbordsprofilsregler eller -användarinformation." +msgstr "" +"Det går inte att hämta regler för IPA-skrivbordsprofil eller " +"användarinformation." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:423 @@ -9872,7 +10344,7 @@ msgstr "PAM_CRED_UNAVAIL" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:426 msgid "Unable to retrieve Kerberos user credentials." -msgstr "Kan inte hämta Kerberos-användarkreditiv." +msgstr "Det går inte att hämta Kerberos-autentiseringsuppgifter för användaren." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:431 @@ -9881,9 +10353,14 @@ msgstr "PAM_NO_MODULE_DATA" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:434 +#, fuzzy +#| msgid "" +#| "No authentication method was found by Kerberos. This might happen if the " +#| "user has a Smartcard assigned but the pkint plugin is not available on " +#| "the client." msgid "" "No authentication method was found by Kerberos. This might happen if the " -"user has a Smartcard assigned but the pkint plugin is not available on the " +"user has a Smartcard assigned but the pkinit plugin is not available on the " "client." msgstr "" "Ingen autentiseringsmetod hittades av Kerberos. Detta kan inträffa om " @@ -9938,7 +10415,8 @@ msgstr "PAM_BAD_ITEM" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:476 msgid "The authentication module cannot handle Smartcard credentials." -msgstr "Autentiseringsmodulen kan inte hantera smartkortskreditiv." +msgstr "" +"Autentiseringsmodulen kan inte hantera autentiseringsuppgifter för smartkort." #. type: Content of: <reference><refentry><refsect1><title> #: pam_sss.8.xml:484 @@ -9952,10 +10430,10 @@ msgid "" "does not support password resets, an individual message can be displayed. " "This message can e.g. contain instructions about how to reset a password." msgstr "" -"Om en återställning av lösenord av root misslyckas, för att motsvarande SSSD-" -"leverantör inte stödjer återställning av lösenord, kan ett individuellt " -"meddelande visas. Detta meddelande kan t.ex. innehålla instruktioner hur man " -"återställer ett lösenord." +"Om en lösenordsåterställning som utförs av root misslyckas därför att " +"motsvarande SSSD-leverantör inte stöder lösenordsåterställning, kan ett " +"anpassat meddelande visas. Meddelandet kan till exempel innehålla " +"instruktioner om hur ett lösenord återställs." #. type: Content of: <reference><refentry><refsect1><para> #: pam_sss.8.xml:490 @@ -9968,13 +10446,13 @@ msgid "" "the owner of the files and only root may have read and write permissions " "while all other users must have only read permissions." msgstr "" -"Meddelandet läses från filen <filename>pam_sss_pw_reset_message.LOK</" -"filename> där LOK står för en lokalsträng som den returneras av " -"<citerefentry> <refentrytitle>setlocale</refentrytitle><manvolnum>3</" -"manvolnum> </citerefentry>. Om det inte finns någon matchande fil visas " -"innehållet i <filename>pam_sss_pw_reset_message.txt</filename>. Root måste " -"vara ägaren av filerna och endast root får ha läs- och skrivrättigheter " -"medan alla andra användare endast får ha läsrättigheter." +"Meddelandet läses från filen <filename>pam_sss_pw_reset_message.LOC</" +"filename>, där LOC står för en lokalsträng som returneras av <citerefentry> " +"<refentrytitle>setlocale</refentrytitle><manvolnum>3</manvolnum> </" +"citerefentry>. Om det inte finns någon matchande fil visas innehållet i " +"<filename>pam_sss_pw_reset_message.txt</filename>. Root måste äga filerna " +"och endast root får ha läs- och skrivbehörighet, medan alla andra användare " +"endast får ha läsbehörighet." #. type: Content of: <reference><refentry><refsect1><para> #: pam_sss.8.xml:500 @@ -9983,8 +10461,8 @@ msgid "" "DOMAIN_NAME/</filename>. If no matching file is present a generic message is " "displayed." msgstr "" -"Dessa filer söks efter i katalogen <filename>/etc/sssd/customize/DOMÄNNAMN/</" -"filename>. Om ingen matchande fil finns visas ett allmänt meddelande." +"Dessa filer söks i katalogen <filename>/etc/sssd/customize/DOMAIN_NAME/</" +"filename>. Om ingen matchande fil finns visas ett generellt meddelande." #. type: Content of: <reference><refentry><refnamediv><refname> #: pam_sss_gss.8.xml:11 pam_sss_gss.8.xml:16 @@ -10002,8 +10480,8 @@ msgid "" "<command>pam_sss_gss.so</command> <arg choice='opt'> <replaceable>debug</" "replaceable> </arg>" msgstr "" -"<command>pam_sss_gss.so</command> <arg choice='opt'> <replaceable>" -"felsökning</replaceable> </arg>" +"<command>pam_sss_gss.so</command> <arg choice='opt'> <replaceable>debug</" +"replaceable> </arg>" #. type: Content of: <reference><refentry><refsect1><para> #: pam_sss_gss.8.xml:32 @@ -10011,7 +10489,7 @@ msgid "" "<command>pam_sss_gss.so</command> authenticates user over GSSAPI in " "cooperation with SSSD." msgstr "" -"<command>pam_sss_gss.so</command> autentiserar användaren över GSSAPI i " +"<command>pam_sss_gss.so</command> autentiserar användaren via GSSAPI i " "samarbete med SSSD." #. type: Content of: <reference><refentry><refsect1><para> @@ -10023,11 +10501,11 @@ msgid "" "name is derived by Kerberos internal mechanisms and it can be set explicitly " "in configuration of [domain_realm] section in /etc/krb5.conf." msgstr "" -"Denna modul kommer försöka autentisera användaren med det värdbaserade " -"GSSAPI-tjänstenamnet värd@värdnamn vilket översätts till Kerberos-" -"huvudmannen värd/värdnamn@RIKE. Delen <emphasis>RIKE</emphasis> av Kerberos-" -"huvudmannanamnet härleds av Kerberos interna mekanismer och det kan sättas " -"uttryckligen i konfigurationen av sektionen [domain_realm] i /etc/krb5.conf." +"Modulen försöker autentisera användaren med det värdbaserade GSSAPI-" +"tjänstenamnet host@hostname, vilket motsvarar Kerberos-huvudmannen host/" +"hostname@REALM. Delen <emphasis>REALM</emphasis> av Kerberos-" +"huvudmannanamnet härleds av Kerberos interna mekanismer och kan anges " +"uttryckligen i konfigurationen i avsnittet [domain_realm] i /etc/krb5.conf." #. type: Content of: <reference><refentry><refsect1><para> #: pam_sss_gss.8.xml:44 @@ -10037,11 +10515,11 @@ msgid "" "the Kerberos credentials cache or if user's ticket granting ticket can be " "used to get the correct service ticket then the user will be authenticated." msgstr "" -"SSSD används för att tillhandahålla det önskade tjänstenamnet och för att " -"validera användarens kreditiv med GSSAPI-anrop. Om tjänstebiljetten redan är " -"tillgänglig i Kerberos kreditiv-cache eller om användarens " -"biljettgivarbiljett kan användas för att få det korrekta tjänstebiljetten, i " -"så fall kommer användaren autentiseras." +"SSSD används för att tillhandahålla önskat tjänstenamn och för att verifiera " +"användarens autentiseringsuppgifter med GSSAPI-anrop. Om tjänstebiljetten " +"redan finns i Kerberos cache för autentiseringsuppgifter eller om " +"användarens biljettutfärdande biljett kan användas för att hämta rätt " +"tjänstebiljett autentiseras användaren." #. type: Content of: <reference><refentry><refsect1><para> #: pam_sss_gss.8.xml:51 @@ -10052,10 +10530,11 @@ msgid "" "Kerberos credentials must match with the user principal name as defined in " "LDAP." msgstr "" -"Om <option>pam_gssapi_check_upn</option> är sant (standard) kräver SSSD att " -"kreditiven som använts till att få denna tjänstebiljett kan associeras med " -"användaren. Detta betydera tt huvudmannen som äger Kerberos-kreditiven måste " -"stämma med användarens huvudmannanamn så som det definieras i LDAP." +"Om <option>pam_gssapi_check_upn</option> är True (standard) kräver SSSD att " +"de autentiseringsuppgifter som används för att hämta tjänstebiljetterna kan " +"kopplas till användaren. Det innebär att den huvudman som äger Kerberos-" +"autentiseringsuppgifterna måste stämma överens med användarens huvudnamn " +"enligt LDAP." #. type: Content of: <reference><refentry><refsect1><para> #: pam_sss_gss.8.xml:58 @@ -10069,14 +10548,14 @@ msgid "" "citerefentry> and <citerefentry> <refentrytitle>sssd-krb5</refentrytitle> " "<manvolnum>5</manvolnum> </citerefentry> for more details on these options." msgstr "" -"För att aktivera GSSAPI-autentisering i SSSD, sätt alternativet <option>" -"pam_gssapi_services</option> i [pam] eller domänsektionen i sssd.conf. " -"Tjänstekreditiven behöver lagras i SSSD:s keytab (de finns där redan om man " -"använder leverantören ipa eller ad). Keytab-platsen kan anges med " -"alternativet <option>krb5_keytab</option>. Se <citerefentry> <refentrytitle>" -"sssd.conf</refentrytitle> <manvolnum>5</manvolnum> </citerefentry> och " -"<citerefentry> <refentrytitle>sssd-krb5</refentrytitle> <manvolnum>5</" -"manvolnum> </citerefentry> för fler detaljer om dessa alternativ." +"För att aktivera GSSAPI-autentisering i SSSD anger du alternativet <option>" +"pam_gssapi_services</option> i avsnittet [pam] eller en domän i sssd.conf. " +"Tjänstens autentiseringsuppgifter måste lagras i SSSD:s keytab (den finns " +"redan om du använder leverantören ipa eller ad). Platsen för keytab kan " +"anges med alternativet <option>krb5_keytab</option>. Mer information om " +"alternativen finns i <citerefentry> <refentrytitle>sssd.conf</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry> och <citerefentry> <refentrytitle>" +"sssd-krb5</refentrytitle> <manvolnum>5</manvolnum> </citerefentry>." #. type: Content of: <reference><refentry><refsect1><para> #: pam_sss_gss.8.xml:74 @@ -10087,11 +10566,11 @@ msgid "" "presence of authentication indicators in the service tickets before a " "particular PAM service can be accessed." msgstr "" -"Några Kerberos-installationer tillåter associationen av " -"autentiseringsindikatorer med en viss förautentiseringsmetod använd för att " -"hämta biljettgivarbiljetten av användaren. <command>pam_sss_gss.so</command> " -"gör att man kan kräva närvaron av autentiseringsindikatorer i " -"tjänstebiljetten för en viss PAM-tjänst kan nås." +"Vissa Kerberos-installationer gör det möjligt att koppla " +"autentiseringsindikatorer till en viss förautentiseringsmetod som användaren " +"använder för att hämta den biljettutfärdande biljetten. <command>" +"pam_sss_gss.so</command> kan kräva att autentiseringsindikatorer finns i " +"tjänstebiljetterna innan en viss PAM-tjänst kan nås." #. type: Content of: <reference><refentry><refsect1><para> #: pam_sss_gss.8.xml:82 @@ -10100,9 +10579,9 @@ msgid "" "section of sssd.conf, then SSSD will perform a check of the presence of any " "configured indicators in the service ticket." msgstr "" -"Om <option>pam_gssapi_indicators_map</option> är satt i sektionen [pam] " -"eller domänsektionen i sssd.conf kommer SSSD utföra en kontroll av närvaron " -"av några konfigurerade indikatorer i tjänstebiljetten." +"Om <option>pam_gssapi_indicators_map</option> anges i avsnittet [pam] eller " +"en domän i sssd.conf kontrollerar SSSD om någon av de konfigurerade " +"indikatorerna finns i tjänstebiljetten." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss_gss.8.xml:93 @@ -10140,9 +10619,9 @@ msgid "" "without the need to disable authentication completely. To achieve this, " "first enable GSSAPI authentication for sudo in sssd.conf:" msgstr "" -"Det huvudsakliga användningsfallet är att tillhandahålla lösenordsfri " -"autentisering i sudo men utan behovet av att avaktivera autentisering helt. " -"För att uppnå detta, aktivera först GSSAPI-autentisering av sudo i sssd.conf:" +"Det huvudsakliga användningsfallet är att tillhandahålla lösenordslös " +"autentisering i sudo utan att behöva inaktivera autentiseringen helt. " +"Aktivera först GSSAPI-autentisering för sudo i sssd.conf:" #. type: Content of: <reference><refentry><refsect1><programlisting> #: pam_sss_gss.8.xml:165 @@ -10152,7 +10631,7 @@ msgid "" "pam_gssapi_services = sudo, sudo-i\n" " " msgstr "" -"[domain/MINDOMÄN]\n" +"[domain/MYDOMAIN]\n" "pam_gssapi_services = sudo, sudo-i\n" " " @@ -10162,8 +10641,8 @@ msgid "" "And then enable the module in desired PAM stack (e.g. /etc/pam.d/sudo and /" "etc/pam.d/sudo-i)." msgstr "" -"Aktivera sedan modulen i den önskande PAM-stacken (t.ex. /etc/pam.d/sudo " -"och /etc/pam.d/sudo-i)." +"Aktivera sedan modulen i den önskade PAM-stacken (till exempel /etc/pam.d/" +"sudo och /etc/pam.d/sudo-i)." #. type: Content of: <reference><refentry><refsect1><programlisting> #: pam_sss_gss.8.xml:173 @@ -10174,9 +10653,9 @@ msgid "" "...\n" " " msgstr "" -"…\n" +"...\n" "auth sufficient pam_sss_gss.so\n" -"…\n" +"...\n" " " #. type: Content of: <reference><refentry><refsect1><title> @@ -10190,7 +10669,7 @@ msgid "" "SSSD logs, pam_sss_gss debug output and syslog may contain helpful " "information about the error. Here are some common issues:" msgstr "" -"SSSD-loggar, pam_sss_gss felsökningsutmatning och syslog kan innehålla " +"SSSD-loggarna, felsökningsutdata från pam_sss_gss och syslog kan innehålla " "användbar information om felet. Här är några vanliga problem:" #. type: Content of: <reference><refentry><refsect1><para> @@ -10202,11 +10681,10 @@ msgid "" "<option>env_keep</option> in /etc/sudoers or in your LDAP sudo rules default " "options." msgstr "" -"1. Jag har miljövariabeln KRB5CCNAME satt och autentiseringen fungerar inte: " -"beroende på din sudo-versionär det möjligt att sudo inte skickar denna " -"variabel till PAM-miljön. Försök lägga till KRB5CCNAME till <option>" -"env_keep</option> i /etc/sudoers eller i dina LDAP-sudo-reglers " -"standardalternativ." +"1. Jag har miljövariabeln KRB5CCNAME angiven och autentiseringen fungerar " +"inte: Beroende på sudo-versionen kanske sudo inte skickar variabeln till PAM-" +"miljön. Försök lägga till KRB5CCNAME i <option>env_keep</option> i /etc/" +"sudoers eller i standardalternativen för dina LDAP-sudo-regler." #. type: Content of: <reference><refentry><refsect1><para> #: pam_sss_gss.8.xml:193 @@ -10216,11 +10694,10 @@ msgid "" "for the service ticket based on the hostname. Try adding the hostname " "directly to <option>[domain_realm]</option> in /etc/krb5.conf like so:" msgstr "" -"2. Autentiseringen fungerar inte och syslog innehåller ”Server not found in " -"Kerberos database”: Kerberos kan förmodligen inte lösa upp det korrekta " -"riket för tjänstebiljetten baserat på värdnamnet. Försök att lägga till " -"värdnamnet direk till <option>[domain_realm[</option> i /etc/krb5.conf så " -"här:" +"2. Autentiseringen fungerar inte och syslog innehåller \"Server not found in " +"Kerberos database\": Kerberos kan sannolikt inte fastställa rätt realm för " +"tjänstebiljetten utifrån värdnamnet. Försök lägga till värdnamnet direkt i " +"<option>[domain_realm]</option> i /etc/krb5.conf så här:" #. type: Content of: <reference><refentry><refsect1><para> #: pam_sss_gss.8.xml:200 @@ -10230,10 +10707,10 @@ msgid "" "obtain the required service ticket. Use kinit or authenticate over SSSD to " "acquire those credentials." msgstr "" -"3. Autentiseringen fungerar inte och syslog innehåller ”No Kerberos " -"credentials available”: du har inte några kreditiv som kan användas för att " -"få den önskade tjänstebiljetten. Använd kinit eller autentisera över SSSD " -"för att få dessa kreditiv." +"3. Autentiseringen fungerar inte och syslog innehåller \"No Kerberos " +"credentials available\": Du har inga autentiseringsuppgifter som kan " +"användas för att hämta den begärda tjänstebiljetten. Använd kinit eller " +"autentisera via SSSD för att hämta dessa autentiseringsuppgifter." #. type: Content of: <reference><refentry><refsect1><para> #: pam_sss_gss.8.xml:206 @@ -10245,12 +10722,12 @@ msgid "" "principal, make sure you authenticated with SSSD or consider disabling " "<option>pam_gssapi_check_upn</option>." msgstr "" -"4. Autentisering fungerar inte och SSSD sssd-pam-loggen innehåller ”User " -"with UPN [$UPN] was not found.” eller ”UPN [$UPN] does not match target user " -"[$username].”: du använder kreditiv som inte kan kopplas till användaren som " -"autentiseras. Försök att använda kswitch för att välja en annan huvudman, se " -"till att du autentiserade med SSSD eller överväg att avaktivera <option>" -"pam_gssapi_check_upn</option>." +"4. Autentiseringen fungerar inte och SSSD:s sssd-pam-logg innehåller \"User " +"with UPN [$UPN] was not found.\" eller \"UPN [$UPN] does not match target " +"user [$username].\": Du använder autentiseringsuppgifter som inte kan mappas " +"till den användare som autentiseras. Försök använda kswitch för att välja en " +"annan huvudman, kontrollera att du har autentiserat med SSSD eller överväg " +"att inaktivera <option>pam_gssapi_check_upn</option>." #. type: Content of: <reference><refentry><refsect1><programlisting> #: pam_sss_gss.8.xml:214 @@ -10261,7 +10738,7 @@ msgid "" " " msgstr "" "[domain_realm]\n" -".myhostname = MITTRIKE\n" +".myhostname = MYREALM\n" " " #. type: Content of: <reference><refentry><refnamediv><refname> @@ -10272,7 +10749,7 @@ msgstr "sssd_krb5_locator_plugin" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sssd_krb5_locator_plugin.8.xml:16 msgid "Kerberos locator plugin" -msgstr "Kerberos lokaliseringsinsticksmodul" +msgstr "Lokaliseringsinsticksmodul för Kerberos" #. type: Content of: <reference><refentry><refsect1><para> #: sssd_krb5_locator_plugin.8.xml:22 @@ -10286,15 +10763,15 @@ msgid "" "unexpected authentication failures and maybe even account lockings it would " "be good to talk to a single KDC as long as possible." msgstr "" -"Kerberos lokaliseringsinsticksmodul <command>sssd_krb5_locator_plugin</" -"command> används av libkrb5 för att hitta KDC:er för ett givet Kerberos-" -"rike. SSSD tillhandahåller en sådan insticksmodul för att styra alla " -"Kerberos-klienter på ett system till en ensam KDC. I allmänhet skall det " -"inte ha någon betydelse vilken KDC en klientprocess pratar med. Men det " -"finns fall, t.ex. efter en lösenordsändring, då inte alla KDC:er är i samma " -"tillstånd för att den nya datan måste spridas först. För att undvika " -"oväntade autentiseringsfel och kanske även kontolåsningar kan det vara bra " -"att prata med en enskild KDC så länge som möjligt." +"Lokaliseringsinsticksmodulen för Kerberos <command>sssd_krb5_locator_plugin</" +"command> används av libkrb5 för att hitta KDC:er för ett visst Kerberos-" +"realm. SSSD tillhandahåller en sådan insticksmodul för att styra alla " +"Kerberos-klienter på ett system till en enda KDC. I allmänhet bör det inte " +"spela någon roll vilken KDC en klientprocess ansluter till. Men det finns " +"fall, till exempel efter en lösenordsändring, där inte alla KDC:er är i " +"samma tillstånd eftersom de nya uppgifterna först måste replikeras. För att " +"undvika oväntade autentiseringsfel och kanske även kontolåsning är det bra " +"att ansluta till en och samma KDC så länge som möjligt." #. type: Content of: <reference><refentry><refsect1><para> #: sssd_krb5_locator_plugin.8.xml:34 @@ -10310,18 +10787,18 @@ msgid "" "plugin. With this the plugin is still called but will provide no data to the " "caller so that libkrb5 can fall back to other methods defined in krb5.conf." msgstr "" -"libkrb5 kommer söka efter lokaliseringsinsticksmodulen i underkatalogen " -"libkrb5 till Kerberos katalog för insticksmoduler, se plugin_base_dir i " -"<citerefentry> <refentrytitle>krb5.conf</refentrytitle> <manvolnum>5</" -"manvolnum> </citerefentry> för detaljer. Insticksmodulen kan endast " -"avaktiveras genom att ta bort filen med insticksmodulen. Det finns ingen " -"möjlighet att avaktivera den i Kerberos konfiguration. Men miljövariabeln " -"SSSD_KRB5_LOCATOR_DISABLE kan användas för att avaktivera insticksmodulen " -"för individuella kommandon. Alternativt kan SSSD-alternativet " -"krb5_use_kdcinfo=False användas för att inte generera de data som behövs av " -"insticksmodulen. Med denna anropas fortfarande insticksmodulen men den " -"tillhandahåller inga data till anroparen så att libkrb5 kan falla tillbaka " -"på andra metoder som är definierade i krb5.conf." +"libkrb5 söker efter lokaliseringsinsticksmodulen i underkatalogen libkrb5 i " +"katalogen för Kerberos-insticksmoduler. Mer information finns under " +"plugin_base_dir i <citerefentry> <refentrytitle>krb5.conf</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry>. Insticksmodulen kan endast " +"inaktiveras genom att insticksmodulfilen tas bort. Det finns inget " +"alternativ i Kerberos-konfigurationen för att inaktivera den. Miljövariabeln " +"SSSD_KRB5_LOCATOR_DISABLE kan dock användas för att inaktivera " +"insticksmodulen för enskilda kommandon. Alternativt kan SSSD-alternativet " +"krb5_use_kdcinfo=False användas för att inte generera de data som " +"insticksmodulen behöver. Då anropas insticksmodulen fortfarande, men lämnar " +"inga data till anroparen, så att libkrb5 kan falla tillbaka till andra " +"metoder som definieras i krb5.conf." #. type: Content of: <reference><refentry><refsect1><para> #: sssd_krb5_locator_plugin.8.xml:50 @@ -10333,22 +10810,22 @@ msgid "" "separated with a colon, the IPv6 address has to be enclosed in squared " "brackets in this case as usual. Valid entries are:" msgstr "" -"Insticksmodulen läser information om KDC:erna för ett givet rike från en fil " -"som heter <filename>kdcinfo.RIKE</filename>. Filen skall innehålla ett " -"eller flera DNS-namn eller IP-adresser antingen i punktad decimal IPv4-" -"notation eller den hexadecimala IPv6-notationen. Ett frivilligt portnummer " -"kan läggas till på slutet separerat av ett kolon, IPv6-adressen måste " -"inneslutas i hakparenteser i detta fall som vanligt. Giltiga poster är:" +"Insticksmodulen läser information om KDC:erna för ett visst realm från en " +"fil med namnet <filename>kdcinfo.REALM</filename>. Filen ska innehålla ett " +"eller flera DNS-namn eller IP-adresser, antingen i IPv4-notation med punkter " +"och decimaler eller i hexadecimal IPv6-notation. Ett valfritt portnummer kan " +"läggas till i slutet och avgränsas med ett kolon. I så fall måste IPv6-" +"adressen, som vanligt, omslutas av hakparenteser. Giltiga poster är:" #. type: Content of: <reference><refentry><refsect1><para><itemizedlist><listitem><para> #: sssd_krb5_locator_plugin.8.xml:58 msgid "kdc.example.com" -msgstr "kdc.exempel.se" +msgstr "kdc.example.com" #. type: Content of: <reference><refentry><refsect1><para><itemizedlist><listitem><para> #: sssd_krb5_locator_plugin.8.xml:59 msgid "kdc.example.com:321" -msgstr "kdc.exempel.se:321" +msgstr "kdc.example.com:321" #. type: Content of: <reference><refentry><refsect1><para><itemizedlist><listitem><para> #: sssd_krb5_locator_plugin.8.xml:60 @@ -10377,9 +10854,9 @@ msgid "" "adds the address of the current KDC or domain controller SSSD is using to " "this file." msgstr "" -"SSSD:s krb5-autentiseringsleverantör som också används av IPA- och AD-" -"leverantörerna lägger till adresser till den aktuella KDC- eller " -"domänkontrollern SSSD använder till denna fil." +"SSSD:s autentiseringsleverantör krb5, som även används av leverantörerna IPA " +"och AD, lägger till adressen till den KDC eller domänkontrollant som SSSD " +"för närvarande använder i den här filen." #. type: Content of: <reference><refentry><refsect1><para> #: sssd_krb5_locator_plugin.8.xml:70 @@ -10393,16 +10870,15 @@ msgid "" "MIT Kerberos specific master KDC. If the address contains a port number the " "default KDC port 88 will be used for the latter." msgstr "" -"I miljöer med KDC:er som endast är för läsning och för läsning och skrivning " -"där klienter förväntas använda instanser endast för läsning för allmänna " -"operationer och endast KDC:n för läsning och skrivning för " -"konfigurationsändringar som lösenordsändringar används även en <filename>" -"kpasswdinfo.RIKE</filename> för att identifiera KDC:er för läsning och " -"skrivning. Om denna fil finns för det givna riket kommer innehållet användas " -"av insticksmodulen för att svara på begäranden om en kpasswd- eller kadmin-" -"server eller om huvud-KDC:n specifik för MIT Kerberos. Om adressen " -"innehåller ett portnummer kommer standard-KDC-porten 88 användas för det " -"senare." +"I miljöer med skrivskyddade KDC:er och KDC:er med läs- och skrivåtkomst " +"förväntas klienter använda de skrivskyddade instanserna för vanliga åtgärder " +"och endast KDC:n med läs- och skrivåtkomst för konfigurationsändringar, till " +"exempel lösenordsändringar. Då används även <filename>kpasswdinfo.REALM</" +"filename> för att identifiera KDC:er med läs- och skrivåtkomst. Om filen " +"finns för det aktuella realmet använder insticksmodulen dess innehåll för " +"att besvara begäranden om en kpasswd- eller kadmin-server eller en huvud-KDC " +"som är specifik för MIT Kerberos. Om adressen innehåller ett portnummer " +"används standard-KDC-porten 88 för det sistnämnda." #. type: Content of: <reference><refentry><refsect1><para> #: sssd_krb5_locator_plugin.8.xml:85 @@ -10411,10 +10887,9 @@ msgid "" "<command>sssd_krb5_locator_plugin</command> is not available on your system " "you have to edit /etc/krb5.conf to reflect your Kerberos setup." msgstr "" -"Inte alla Kerberosimplementationer stödjer användningen av insticksmoduler. " -"Om <command>sssd_krb5_locator_plugin</command> inte är tillgänglig på ditt " -"system måste du redigera /etc/krb5.conf för att avspegla din " -"Kerberosuppsättning." +"Alla Kerberos-implementationer stöder inte insticksmoduler. Om <command>" +"sssd_krb5_locator_plugin</command> inte är tillgänglig på systemet måste du " +"redigera /etc/krb5.conf så att filen motsvarar Kerberos-konfigurationen." #. type: Content of: <reference><refentry><refsect1><para> #: sssd_krb5_locator_plugin.8.xml:91 @@ -10422,8 +10897,8 @@ msgid "" "If the environment variable SSSD_KRB5_LOCATOR_DEBUG is set to any value " "debug messages will be sent to stderr." msgstr "" -"Om miljövariabeln SSSD_KRB5_LOCATOR_DEBUG är satt till något värde kommer " -"felsökningsmeddelanden skrivas till standard fel." +"Om miljövariabeln SSSD_KRB5_LOCATOR_DEBUG har något värde skrivs " +"felsökningsmeddelanden till stderr." #. type: Content of: <reference><refentry><refsect1><para> #: sssd_krb5_locator_plugin.8.xml:95 @@ -10432,9 +10907,8 @@ msgid "" "the plugin is disabled and will just return KRB5_PLUGIN_NO_HANDLE to the " "caller." msgstr "" -"Om miljövariabeln SSSD_KRB5_LOCATOR_DISABLE är satt till något värde " -"avaktiveras insticksmodulen och kommer bara returnera KRB5_PLUGIN_NO_HANDLE " -"till anroparen." +"Om miljövariabeln SSSD_KRB5_LOCATOR_DISABLE har något värde inaktiveras " +"insticksmodulen och returnerar endast KRB5_PLUGIN_NO_HANDLE till anroparen." #. type: Content of: <reference><refentry><refsect1><para> #: sssd_krb5_locator_plugin.8.xml:100 @@ -10444,10 +10918,27 @@ msgid "" "default plugin returns KRB5_PLUGIN_NO_HANDLE to the caller immediately on " "first DNS resolving failure." msgstr "" -"Om miljövariabeln SSSD_KRB5_LOCATOR_IGNORE_DNS_FAILURES är satt till något " -"värde kommer insticksmodulen försöka slå upp alla DNS-namn i filen kdcinfo. " -"Som standard returneras KRB5_PLUGIN_NO_HANDLE till anroparen omedelbart vid " -"den första misslyckade DNS-uppslagningen." +"Om miljövariabeln SSSD_KRB5_LOCATOR_IGNORE_DNS_FAILURES har något värde " +"försöker insticksmodulen slå upp alla DNS-namn i filen kdcinfo. Som standard " +"returnerar insticksmodulen omedelbart KRB5_PLUGIN_NO_HANDLE till anroparen " +"vid det första misslyckade DNS-uppslaget." + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_locator_plugin.8.xml:106 +msgid "" +"If the environment variable SSSD_KRB5_LOCATOR_KDC_ADDRESS is set to a KDC " +"address the plugin will use this address instead of reading the kdcinfo " +"file. The address format is the same as in the kdcinfo file (see above)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_locator_plugin.8.xml:112 +msgid "" +"If the environment variable SSSD_KRB5_LOCATOR_KPASSWD_ADDRESS is set to a " +"kpasswd server address the plugin will use this address instead of reading " +"the kpasswdinfo file. The address format is the same as in the kpasswdinfo " +"file (see above)." +msgstr "" #. type: Content of: <reference><refentry><refnamediv><refname> #: sssd-simple.5.xml:10 sssd-simple.5.xml:16 @@ -10457,7 +10948,7 @@ msgstr "sssd-simple" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sssd-simple.5.xml:17 msgid "the configuration file for SSSD's 'simple' access-control provider" -msgstr "konfigurationsfilen för SSSD:s åtkomststyrningsleverantör ”simple”" +msgstr "konfigurationsfilen för SSSD:s åtkomststyrningsleverantör 'simple'" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-simple.5.xml:24 @@ -10469,12 +10960,12 @@ msgid "" "<refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</manvolnum> </" "citerefentry> manual page." msgstr "" -"Denna manualsida beskriver konfigurationen av åtkomststyrningsleverantören " -"simple till <citerefentry> <refentrytitle>sssd</refentrytitle> <manvolnum>8</" -"manvolnum> </citerefentry>. För en detaljerad referens om syntaxen, se " -"avsnittet <quote>FILFORMAT</quote> i manualsidan <citerefentry> " -"<refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</manvolnum> </" -"citerefentry>." +"Den här manualsidan beskriver konfigurationen av " +"åtkomststyrningsleverantören simple för <citerefentry> <refentrytitle>sssd</" +"refentrytitle> <manvolnum>8</manvolnum> </citerefentry>. En detaljerad " +"syntaxreferens finns i avsnittet <quote>FILFORMAT</quote> på manualsidan " +"<citerefentry> <refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry>." #. type: Content of: <reference><refentry><refsect1><para> #: sssd-simple.5.xml:38 @@ -10482,8 +10973,8 @@ msgid "" "The simple access provider grants or denies access based on an access or " "deny list of user or group names." msgstr "" -"Den enkla åtkomstleverantören beviljar eller nekar åtkomst baserat på en " -"lista över användar- eller gruppnamn som har åtkomst eller nekas åtkomst." +"Åtkomstleverantören simple beviljar eller nekar åtkomst utifrån listor över " +"användar- eller gruppnamn som tillåts eller nekas." #. type: Content of: <reference><refentry><refsect1><para> #: sssd-simple.5.xml:42 @@ -10492,9 +10983,9 @@ msgid "" "provider is used there as well, and groups managed outside of SSSD are not " "evaluated." msgstr "" -"Grupper från andra domäner som konfigurerats i sssd.conf, även om den enkla " -"åtkomstleverantören används även där, och grupper som hanteras utanför SSSD " -"utvärderas inte." +"Grupper från andra domäner som är konfigurerade i sssd.conf utvärderas inte, " +"även om åtkomstleverantören simple också används där. Grupper som hanteras " +"utanför SSSD utvärderas inte heller." #. type: Content of: <reference><refentry><refsect1><para> #: sssd-simple.5.xml:47 @@ -10518,8 +11009,8 @@ msgid "" "If any list is provided, the order of evaluation is: allow → deny. This " "means that any matching deny rule will supersede any matched allow rule." msgstr "" -"Om någon lista tillhandahålls är utvärderingsordningen: tillåt → neka. Detta " -"innebär att alla matchande neka-regler ersätter alla matchande tillåt-regler." +"Om någon lista anges är utvärderingsordningen: allow → deny. Det innebär att " +"en matchande deny-regel har företräde framför en matchande allow-regel." #. type: Content of: <reference><refentry><refsect1><para><itemizedlist><listitem><para> #: sssd-simple.5.xml:65 @@ -10527,8 +11018,8 @@ msgid "" "If either or both \"allow\" lists are provided, all users are denied unless " "they appear in at least one of these lists (OR condition)." msgstr "" -"Om någon av eller båda \"allow\"-listorna anges, nekas alla användare " -"åtkomst om de inte finns med på minst en av dessa listor (ELLER-villkor)." +"Om en eller båda \"allow\"-listorna anges nekas alla användare åtkomst om de " +"inte finns i minst en av listorna (ELLER-villkor)." #. type: Content of: <reference><refentry><refsect1><para><itemizedlist><listitem><para> #: sssd-simple.5.xml:72 @@ -10536,8 +11027,8 @@ msgid "" "If either or both \"deny\" lists are provided, all users are granted access " "unless they appear in at least one of these lists (OR condition)." msgstr "" -"Om någon av eller båda \"deny\"-listorna anges, beviljas alla användare " -"åtkomst såvida de inte förekommer i minst en av dessa listor (ELLER-villkor)." +"Om en eller båda \"deny\"-listorna anges beviljas alla användare åtkomst om " +"de inte finns i minst en av listorna (ELLER-villkor)." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-simple.5.xml:91 @@ -10551,9 +11042,9 @@ msgid "" "specified, all other users are denied unless they are members of groups " "listed in`simple_allow_groups`." msgstr "" -"Kommaseparerad lista över användare som har tillåtelse att logga in. Om " -"detta alternativ anges nekas alla andra användare åtkomst, såvida de inte är " -"medlemmar i grupper som anges i `simple_allow_groups`." +"Kommaseparerad lista med användare som får logga in. Om det här alternativet " +"anges nekas alla andra användare åtkomst, om de inte är medlemmar i grupper " +"som anges i `simple_allow_groups`." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-simple.5.xml:103 @@ -10578,8 +11069,8 @@ msgid "" "`simple_deny_users` or if they are a member of a group in " "`simple_deny_groups`." msgstr "" -"ELLER-logik gäller: En användare nekas åtkomst om de finns med i " -"`simple_deny_users` eller om de är medlem i en grupp i `simple_deny_groups`." +"ELLER-logik gäller: En användare nekas åtkomst om användaren finns i " +"`simple_deny_users` eller är medlem i en grupp i `simple_deny_groups`." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-simple.5.xml:120 @@ -10593,9 +11084,9 @@ msgid "" "specified, all other users are denied unless they are explicitly listed in " "`simple_allow_users`." msgstr "" -"Kommaseparerad lista över grupper som har tillåtelse att logga in. Om detta " -"alternativ anges nekas alla andra användare åtkomst, såvida de inte " -"uttryckligen anges i `simple_allow_users`." +"Kommaseparerad lista med grupper som får logga in. Om det här alternativet " +"anges nekas alla andra användare åtkomst, om de inte uttryckligen anges i " +"`simple_allow_users`." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-simple.5.xml:129 @@ -10603,8 +11094,8 @@ msgid "" "OR Logic Applies: A user can log in if they are listed in " "`simple_allow_users` or if they belong to a group in `simple_allow_groups`." msgstr "" -"ELLER-logik gäller: En användare kan logga in om de finns med i " -"`simple_allow_users` eller om de tillhör en grupp i `simple_allow_groups`." +"ELLER-logik gäller: En användare kan logga in om användaren finns i " +"`simple_allow_users` eller tillhör en grupp i `simple_allow_groups`." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-simple.5.xml:134 sssd-simple.5.xml:154 @@ -10637,9 +11128,8 @@ msgid "" "`simple_deny_users` or if they are a member of any group in " "`simple_deny_groups`." msgstr "" -"ELLER-logik gäller: En användare nekas åtkomst om de finns med i " -"`simple_deny_users` eller om de är medlem i någon grupp i " -"`simple_deny_groups`." +"ELLER-logik gäller: En användare nekas åtkomst om användaren finns i " +"`simple_deny_users` eller är medlem i någon grupp i `simple_deny_groups`." #. type: Content of: <reference><refentry><refsect1><para> #: sssd-simple.5.xml:83 sssd-ipa.5.xml:83 sssd-ad.5.xml:131 sssd-idp.5.xml:55 @@ -10649,9 +11139,9 @@ msgid "" "citerefentry> manual page for details on the configuration of an SSSD " "domain. <placeholder type=\"variablelist\" id=\"0\"/>" msgstr "" -"Se <quote>DOMÄNSEKTIONER</quote> i manualsidan <citerefentry> <refentrytitle>" -"sssd.conf</refentrytitle> <manvolnum>5</manvolnum> </citerefentry> för " -"detaljer om konfigurationen av en SSSD-domän. <placeholder " +"Mer information om konfigurationen av en SSSD-domän finns i avsnittet <quote>" +"DOMÄNAVSNITT</quote> på manualsidan <citerefentry> <refentrytitle>sssd.conf</" +"refentrytitle> <manvolnum>5</manvolnum> </citerefentry>. <placeholder " "type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para> @@ -10661,9 +11151,9 @@ msgid "" "entirely. Beware of this while generating parameters for the simple provider " "using automated scripts." msgstr "" -"Att inte ange några värden för någon av listorna är likvärdigt med att hoppa " -"över det helt. Var medveten om detta när parametrar genereras för " -"leverantören simple med automatiserade skript." +"Att inte ange värden i någon av listorna motsvarar att helt utelämna listan. " +"Var uppmärksam på detta när parametrar för leverantören simple genereras med " +"automatiserade skript." #. type: Content of: <reference><refentry><refsect1><para> #: sssd-simple.5.xml:171 @@ -10673,8 +11163,9 @@ msgid "" "section. This example shows only the simple access provider-specific options." msgstr "" "Följande exempel förutsätter att SSSD är korrekt konfigurerat och att " -"exempel.se är en av domänerna i avsnittet <replaceable>[sssd]</replaceable>. " -"Detta exempel visar endast de enkla leverantörsspecifika alternativen." +"example.com är en av domänerna i avsnittet <replaceable>[sssd]</replaceable>" +". Exemplet visar endast alternativ som är specifika för åtkomstleverantören " +"simple." #. type: Content of: <reference><refentry><refsect1><para><programlisting> #: sssd-simple.5.xml:178 @@ -10687,12 +11178,12 @@ msgid "" "simple_allow_groups = allowed_group1\n" "simple_deny_groups = denied_group1\n" msgstr "" -"[domain/exempel.se]\n" +"[domain/example.com]\n" "access_provider = simple\n" -"simple_allow_users = användare1, användare2\n" -"simple_deny_users = användare3, användare4\n" -"simple_allow_groups = tillåten_grupp1\n" -"simple_deny_groups = nekad_grupp1\n" +"simple_allow_users = user1, user2\n" +"simple_deny_users = user3, user4\n" +"simple_allow_groups = allowed_group1\n" +"simple_deny_groups = denied_group1\n" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-simple.5.xml:191 @@ -10704,12 +11195,11 @@ msgid "" "<refentrytitle>sssd-ldap</refentrytitle><manvolnum>5</manvolnum> </" "citerefentry>) option." msgstr "" -"Den fullständiga gruppmedlemskapshierarkin löses upp före åtkomstkontrollen, " -"alltså kan även nästade grupper inkluderas i åtkomstlistorna. Var medveten " -"om att alternativet <quote>ldap_group_nesting_level</quote> kan påverka " -"resultaten och skall sättas till ett tillräckligt värde. (<citerefentry> " -"<refentrytitle>sssd-ldap</refentrytitle><manvolnum>5</manvolnum> </" -"citerefentry>)." +"Den fullständiga gruppmedlemshierarkin löses upp före åtkomstkontrollen, så " +"även nästlade grupper kan ingå i åtkomstlistorna. Observera att alternativet " +"<quote>ldap_group_nesting_level</quote> kan påverka resultatet och bör anges " +"med ett tillräckligt högt värde. Se <citerefentry> <refentrytitle>sssd-ldap</" +"refentrytitle><manvolnum>5</manvolnum> </citerefentry>." #. type: Content of: <reference><refentry><refnamediv><refname> #: sss-certmap.5.xml:10 sss-certmap.5.xml:16 @@ -10719,7 +11209,7 @@ msgstr "sss-certmap" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sss-certmap.5.xml:17 msgid "SSSD Certificate Matching and Mapping Rules" -msgstr "SSSD:s certifikatmatchnings- och -mappningsregler" +msgstr "Regler för SSSD:s certifikatmatchning och -mappning" #. type: Content of: <reference><refentry><refsect1><para> #: sss-certmap.5.xml:23 @@ -10727,8 +11217,8 @@ msgid "" "The manual page describes the rules which can be used by SSSD and other " "components to match X.509 certificates and map them to accounts." msgstr "" -"Manualsidan beskriver reglerna som kan användas av SSSD och andra " -"komponenter för att matcha X.509-certifikat och koppla dem till konton." +"Manualsidan beskriver regler som SSSD och andra komponenter kan använda för " +"att matcha X.509-certifikat och mappa dem till konton." #. type: Content of: <reference><refentry><refsect1><para> #: sss-certmap.5.xml:28 @@ -10743,15 +11233,15 @@ msgid "" "encoded binary. If no domains are given only the local domain will be " "searched." msgstr "" -"Varje regel har fyra komponenter, en <quote>prioritet</quote>, en <quote>" +"Varje regel har fyra komponenter: en <quote>prioritet</quote>, en <quote>" "matchningsregel</quote>, en <quote>mappningsregel</quote> och en <quote>" -"domänlista</quote>. Alla komponenter är frivilliga. En saknad <quote>" -"prioritet</quote> kommer lägga till regeln med den lägsta prioriteten. " -"Standard-<quote>matchningsregeln</quote> kommer matcha certifikat med " -"digitalSignature-nyckelanvändning och clientAuth-utökadnyckelanvändning. Om " -"<quote>mappningsregeln</quote> är tom kommer certifikaten sökas efter i " -"attributet userCertificate som DER-kodade binärer. Om inga domäner anges " -"kommer endast den lokala domänen sökas." +"domänlista</quote>. Alla komponenter är valfria. Om <quote>prioritet</quote> " +"saknas läggs regeln till med lägst prioritet. Standard-<quote>" +"matchningsregeln</quote> matchar certifikat med nyckelanvändningen " +"digitalSignature och den utökade nyckelanvändningen clientAuth. Om <quote>" +"mappningsregeln</quote> är tom söks certifikaten i attributet " +"userCertificate som DER-kodade binärdata. Om inga domäner anges söks endast " +"den lokala domänen." #. type: Content of: <reference><refentry><refsect1><para> #: sss-certmap.5.xml:39 @@ -10763,12 +11253,11 @@ msgid "" "the default type will be used which is 'KRB5' for the matching rules and " "'LDAP' for the mapping rules." msgstr "" -"För att tillåta utökningar eller helt annorluda regelstil kan <quote>" -"mapping</quote> och <quote>matching rules</quote> innehålla ett prefix " -"separerat med ett ”:” från huvuddelen av regeln. Prefixet får bara innehålla " -"versala ASCII-bokstäver och siffror. Om prefixet utelämnas kommer " -"standardtypen användas vilken är ”KRB5” för matchningsregler och ”LDAP” för " -"avbildningsregler." +"För att tillåta utökningar eller helt andra regelstilar kan <quote>" +"mappningsregler</quote> och <quote>matchningsregler</quote> innehålla ett " +"prefix som avgränsas från regelns huvuddel med ':'. Prefixet får endast " +"innehålla versala ASCII-bokstäver och siffror. Om prefixet utelämnas används " +"standardtypen: 'KRB5' för matchningsregler och 'LDAP' för mappningsregler." #. type: Content of: <reference><refentry><refsect1><para> #: sss-certmap.5.xml:48 @@ -10777,9 +11266,9 @@ msgid "" "given certificate matches a matching rules and how the output of a mapping " "rule would look like." msgstr "" -"Verktyget ”sssctl” tillhandahåller kommandot ”cert-eval-rule” för att " -"kontrollera om ett givet certifikat stämmer med en matchningsregel och hur " -"utdata från en avbildningsregel skulle se ut." +"Verktyget 'sssctl' tillhandahåller kommandot 'cert-eval-rule' för att " +"kontrollera om ett visst certifikat matchar en matchningsregel och hur " +"utdata från en mappningsregel skulle se ut." #. type: Content of: <reference><refentry><refsect1><title> #: sss-certmap.5.xml:55 @@ -10799,10 +11288,10 @@ msgid "" "missing value indicates the lowest priority. The rules processing is stopped " "when a matched rule is found and no further rules are checked." msgstr "" -"Reglerna bearbetas i prioritetsordning där ”0” (noll) indikerar den högsta " -"prioriteten. Ju högre talet är desto lägre är prioriteten. Ett saknat " -"värde indikerar den lägsta prioriteten. Regelbearbetningen stoppas när en " -"regel som matchar hittas och inga ytterligare regler kontrolleras." +"Reglerna bearbetas efter prioritet, där talet '0' (noll) anger högst " +"prioritet. Ju högre tal, desto lägre prioritet. Ett saknat värde anger lägst " +"prioritet. Regelbearbetningen stoppas när en matchande regel hittas och inga " +"ytterligare regler kontrolleras." #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sss-certmap.5.xml:66 @@ -10810,8 +11299,8 @@ msgid "" "Internally the priority is treated as unsigned 32bit integer, using a " "priority value larger than 4294967295 will cause an error." msgstr "" -"Internt behandlas prioriteten som teckenlösa 32-bitars heltal, att använda " -"ett prioritetsvärde större än 4294967295 kommer orsaka ett fel." +"Internt behandlas prioriteten som ett teckenlöst 32-bitarsheltal. Ett " +"prioritetsvärde större än 4294967295 orsakar ett fel." #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sss-certmap.5.xml:70 @@ -10823,12 +11312,12 @@ msgid "" "or make the matching rules more specific e.g. by using distinct " "<ISSUER> patterns." msgstr "" -"Om flera regler har samma prioritet och bara en av de relaterade " -"matchningsreglerna gäller kommer denna regel att väljas. Om det finns flera " -"regler med samma prioritet som matchar väljs en men vilken av den är " -"odefinierat. För att undvika detta beteende, använd antingen olika " -"prioriteter eller gör matchningsregeln mer specifik, t.ex. genom att använda " -"olika <ISSUER>-mönster." +"Om flera regler har samma prioritet och endast en av de tillhörande " +"matchningsreglerna gäller väljs den regeln. Om flera regler med samma " +"prioritet matchar väljs en av dem, men vilken är inte definierat. Undvik det " +"odefinierade beteendet genom att använda olika prioriteter eller göra " +"matchningsreglerna mer specifika, till exempel med olika <ISSUER>-" +"mönster." #. type: Content of: <reference><refentry><refsect1><refsect2><title> #: sss-certmap.5.xml:79 @@ -10846,13 +11335,13 @@ msgid "" "Multiple keyword pattern pairs can be either joined with '&&' (and) " "or '||' (or)." msgstr "" -"Matchningsregeln används för att välja ett certifikat som " -"översättningsregeln skall tillämpas på. Det använder ett system liknande det " -"som används av alternativet <quote>pkinit_cert_match</quote> i MIT Kerberos. " -"Det består av ett nyckelord omgivet av ”<” och ”>” som identifierar en " -"specifik del av certifikatet och ett mönster som skall finnas för att regeln " -"skall matcha. Flera nyckelord/mönster-par kan antingen sammanfogas med " -"”&&” (och) eller ”||” (eller)." +"Matchningsregeln används för att välja ett certifikat som mappningsregeln " +"ska tillämpas på. Den använder ett system som liknar det för alternativet " +"<quote>pkinit_cert_match</quote> i MIT Kerberos. Den består av ett nyckelord " +"mellan '<' och '>', som identifierar en viss del av certifikatet, och " +"ett mönster som måste hittas för att regeln ska matcha. Flera nyckelords- " +"och mönsterpar kan sammanfogas med '&&' (och) eller '||' " +"(eller)." #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sss-certmap.5.xml:90 @@ -10862,15 +11351,15 @@ msgid "" "quote> so that \"<SUBJECT>.*,DC=MY,DC=DOMAIN\" and " "\"KRB5:<SUBJECT>.*,DC=MY,DC=DOMAIN\" are equivalent." msgstr "" -"Givet likheten med MIT Kerberos är typprefixet för denna regel ”KRB5”. Men ”" -"KRB5” kommer även vara standardvärdet för <quote>matching rules</quote> så " -"att ”<SUBJEKT>.*,DC=MIN,DC=DOMÄN” och ”" -"KRB5:<SUBJEKT>.*,DC=MIN,DC=DOMÄN” är likvärdiga." +"Med tanke på likheten med MIT Kerberos är typprefixet för den här regeln " +"'KRB5'. 'KRB5' är även standard för <quote>matchningsregler</quote>, så " +"\"<SUBJECT>.*,DC=MY,DC=DOMAIN\" och " +"\"KRB5:<SUBJECT>.*,DC=MY,DC=DOMAIN\" är likvärdiga." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:99 msgid "<SUBJECT>regular-expression" -msgstr "<SUBJECT>reguljärt-uttryck" +msgstr "<SUBJECT>regular-expression" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:102 @@ -10879,9 +11368,9 @@ msgid "" "matched. For the matching POSIX Extended Regular Expression syntax is used, " "see regex(7) for details." msgstr "" -"Med denna kan en del eller hela certifikatets subject-namn matchas. För " -"matchningen används POSIX syntax för utökade reguljära uttryck, se regex(7) " -"för detaljer." +"Med detta kan en del av eller hela certifikatets subject-namn matchas. " +"Matchningen använder syntaxen för utökade reguljära uttryck i POSIX. Mer " +"information finns i regex(7)." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:108 @@ -10895,19 +11384,18 @@ msgid "" "confusion those attribute names are best not used or covered by a suitable " "regular-expression." msgstr "" -"För matchningen konverteras subject-namnet lagrat i certifikatet i DER-kodad " -"ASN.1 till en sträng i enlighet med RFC 4514. Detta betyder att den mest " -"specifika namnkomponenten kommer först. Observera att inte alla möjliga " -"attributnamn täcks av RFC 4514. De inkluderade namnen är ”CN”, ”L”, ”ST”, ”O" -"”, ”OU”, ”C”, ”STREET”, ”DC” och ”UID”. Andra attributnamn kan visas olika " -"på olika plattformar och av olika verktyg. För att undvika förvirring är det " -"bäst att dessa attributnamn inte används eller täcks av ett lämpligt " -"reguljärt uttryck." +"Vid matchning konverteras subject-namnet, som lagras i certifikatet som DER-" +"kodad ASN.1, till en sträng enligt RFC 4514. Det innebär att den mest " +"specifika namnkomponenten står först. Observera att RFC 4514 inte omfattar " +"alla möjliga attributnamn. Namnen som ingår är 'CN', 'L', 'ST', 'O', 'OU', " +"'C', 'STREET', 'DC' och 'UID'. Andra attributnamn kan visas olika på olika " +"plattformar och av olika verktyg. Undvik förvirring genom att inte använda " +"sådana attributnamn eller täck dem med ett lämpligt reguljärt uttryck." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:121 msgid "Example: <SUBJECT>.*,DC=MY,DC=DOMAIN" -msgstr "Exempel: <SUBJECT>.*,DC=MIN,DC=DOMÄN" +msgstr "Exempel: <SUBJECT>.*,DC=MY,DC=DOMAIN" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:124 @@ -10916,19 +11404,19 @@ msgid "" "regular expressions and must be escaped with the help of the '\\' character " "so that they are matched as ordinary characters." msgstr "" -"Observera att tecknen ”^.[$()|*+?{\\” har en särskild betydelse i reguljära " -"uttryck och måste skyddas med hjälp av tecknet ”\\” så att de kan matchas " -"som vanliga tecken." +"Observera att tecknen \"^.[$()|*+?{\\\" har en särskild betydelse i " +"reguljära uttryck och måste undantas med tecknet '\\' för att matchas som " +"vanliga tecken." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:130 msgid "Example: <SUBJECT>^CN=.* \\(Admin\\),DC=MY,DC=DOMAIN$" -msgstr "Exempel: <SUBJECT>^CN=.* \\(Admin\\),DC=MIN,DC=DOMÄN$" +msgstr "Exempel: <SUBJECT>^CN=.* \\(Admin\\),DC=MY,DC=DOMAIN$" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:135 msgid "<ISSUER>regular-expression" -msgstr "<ISSUER>reguljärt-uttryck" +msgstr "<ISSUER>regular-expression" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:138 @@ -10936,13 +11424,13 @@ msgid "" "With this a part or the whole issuer name of the certificate can be matched. " "All comments for <SUBJECT> apply her as well." msgstr "" -"Med denna kan en del eller hela certifikatets issuer-namn matchas. Alla " -"kommentarer för <SUBJECT> är tillämpliga här också." +"Med detta kan en del av eller hela certifikatets issuer-namn matchas. Alla " +"anmärkningar för <SUBJECT> gäller även här." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:143 msgid "Example: <ISSUER>^CN=My-CA,DC=MY,DC=DOMAIN$" -msgstr "Exempel: <ISSUER>^CN=Min-CA,DC=MIN,DC=DOMÄN$" +msgstr "Exempel: <ISSUER>^CN=My-CA,DC=MY,DC=DOMAIN$" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:148 @@ -10955,9 +11443,8 @@ msgid "" "This option can be used to specify which key usage values the certificate " "should have. The following values can be used in a comma separated list:" msgstr "" -"Detta alternativ kan användas för att specificera vilka " -"nyckelanvändningsvärden certifikatet skall ha. Följande värden kan användas " -"i en kommaseparerad lista:" +"Det här alternativet kan användas för att ange vilka nyckelanvändningsvärden " +"certifikatet ska ha. Följande värden kan användas i en kommaseparerad lista:" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sss-certmap.5.xml:155 @@ -11010,8 +11497,8 @@ msgid "" "A numerical value in the range of a 32bit unsigned integer can be used as " "well to cover special use cases." msgstr "" -"Ett numeriskt värde i intervallet hos ett 32-bitars teckenlöst heltal kan " -"användas också för att täcka speciella användningsfall." +"Ett numeriskt värde inom intervallet för ett teckenlöst 32-bitarsheltal kan " +"också användas för särskilda användningsfall." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:171 @@ -11021,7 +11508,7 @@ msgstr "Exempel: <KU>digitalSignature,keyEncipherment" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:176 msgid "<EKU>extended-key-usage" -msgstr "<EKU>utökad-nyckel-användning" +msgstr "<EKU>extended-key-usage" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:179 @@ -11029,8 +11516,8 @@ msgid "" "This option can be used to specify which extended key usage the certificate " "should have. The following value can be used in a comma separated list:" msgstr "" -"Detta alternativ kan användas för att specificera vilka utökade-nyckel-" -"användningsvärden certifikatet skall ha. Följande värden kan användas i en " +"Det här alternativet kan användas för att ange vilka värden för utökad " +"nyckelanvändning certifikatet ska ha. Följande värden kan användas i en " "kommaseparerad lista:" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> @@ -11084,8 +11571,8 @@ msgid "" "Extended key usages which are not listed above can be specified with their " "OID in dotted-decimal notation." msgstr "" -"Användningar av utökade nycklar som inte listas ovanför kan specificeras med " -"sina OID:er i punktad decimal notation." +"Utökade nyckelanvändningar som inte listas ovan kan anges med sina OID:er i " +"punktdecimalnotation." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:199 @@ -11095,7 +11582,7 @@ msgstr "Exempel: <EKU>clientAuth,1.3.6.1.5.2.3.4" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:204 msgid "<SAN>regular-expression" -msgstr "<SAN>reguljärt-uttryck" +msgstr "<SAN>regular-expression" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:207 @@ -11104,19 +11591,19 @@ msgid "" "Kerberos principals in the PKINIT or AD NT Principal SAN as " "<SAN:Principal> does." msgstr "" -"För att vara kompatibel med användningen av MIT Kerberos kommer detta " -"alternativ matcha Kerberos-huvudmän i PKINIT eller AD NT-Principal SAN som " -"<SAN:Principal> gör." +"För att vara kompatibelt med användningen i MIT Kerberos matchar det här " +"alternativet Kerberos-huvudmän i PKINIT- eller AD NT Principal-SAN på samma " +"sätt som <SAN:Principal>." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:212 msgid "Example: <SAN>.*@MY\\.REALM" -msgstr "Exempel: <SAN>.*@MITT\\.RIKE" +msgstr "Exempel: <SAN>.*@MY\\.REALM" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:217 msgid "<SAN:Principal>regular-expression" -msgstr "<SAN:Principal>reguljärt-uttryck" +msgstr "<SAN:Principal>regular-expression" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:220 @@ -11126,12 +11613,12 @@ msgstr "Matcha Kerberos-huvudmännen i PKINIT eller AD NT Principal SAN." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:224 msgid "Example: <SAN:Principal>.*@MY\\.REALM" -msgstr "Exempel: <SAN:Principal>.*@MITT\\.RIKE" +msgstr "Exempel: <SAN:Principal>.*@MY\\.REALM" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:229 msgid "<SAN:ntPrincipalName>regular-expression" -msgstr "<SAN:ntPrincipalName>reguljärt-uttryck" +msgstr "<SAN:ntPrincipalName>regular-expression" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:232 @@ -11141,12 +11628,12 @@ msgstr "Matcha Kerberos-huvudmän från AD NT Principal SAN." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:236 msgid "Example: <SAN:ntPrincipalName>.*@MY.AD.REALM" -msgstr "Exempel: <SAN:ntPrincipalName>.*@MITT.AD.RIKE" +msgstr "Exempel: <SAN:ntPrincipalName>.*@MY.AD.REALM" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:241 msgid "<SAN:pkinit>regular-expression" -msgstr "<SAN:pkinit>reguljärt-uttryck" +msgstr "<SAN:pkinit>regular-expression" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:244 @@ -11156,12 +11643,12 @@ msgstr "Matcha Kerberos-huvudmän från PKINIT SAN." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:247 msgid "Example: <SAN:ntPrincipalName>.*@MY\\.PKINIT\\.REALM" -msgstr "Exempel: <SAN:ntPrincipalName>.*@MITT\\.PKINIT\\.RIKE" +msgstr "Exempel: <SAN:ntPrincipalName>.*@MY\\.PKINIT\\.REALM" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:252 msgid "<SAN:dotted-decimal-oid>regular-expression" -msgstr "<SAN:dotted-decimal-oid>reguljärt-uttryck" +msgstr "<SAN:dotted-decimal-oid>regular-expression" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:255 @@ -11170,8 +11657,8 @@ msgid "" "decimal notation, interpret it as string and try to match it against the " "regular expression." msgstr "" -"Ta värdet från otherName SAN-komponenten som anges av OID:n i punktad " -"decimal notation, tolka den som en sträng och försök att matcha den mot det " +"Hämta värdet för otherName-SAN-komponenten som anges av OID:n i " +"punktdecimalnotation, tolka det som en sträng och försök matcha det mot det " "reguljära uttrycket." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> @@ -11182,7 +11669,7 @@ msgstr "Exempel: <SAN:1.2.3.4>test" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:266 msgid "<SAN:otherName>base64-string" -msgstr "<SAN:otherName>base64-sträng" +msgstr "<SAN:otherName>base64-string" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:269 @@ -11192,9 +11679,9 @@ msgid "" "otherName components with special encodings which could not be treated as " "strings." msgstr "" -"Gör en binär matchning med den base64-kodade klicken mot alla otherName SAN-" -"komponenter. Med detta alternativ är det möjligt att matcha mot anpassade " -"otherName-komponenter med speciella kodningar som inte kan hanteras som " +"Gör en binär matchning av den base64-kodade binärdatan mot alla otherName-" +"SAN-komponenter. Med det här alternativet går det att matcha anpassade " +"otherName-komponenter med särskilda kodningar som inte kan behandlas som " "strängar." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> @@ -11205,7 +11692,7 @@ msgstr "Exempel: <SAN:otherName>MTIz" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:281 msgid "<SAN:rfc822Name>regular-expression" -msgstr "<SAN:rfc822Name>reguljärt-uttryck" +msgstr "<SAN:rfc822Name>regular-expression" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:284 @@ -11215,12 +11702,12 @@ msgstr "Matcha värdet på rfc822Name SAN." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:287 msgid "Example: <SAN:rfc822Name>.*@email\\.domain" -msgstr "Exempel: <SAN:rfc822Name>.*@epost\\.domän" +msgstr "Exempel: <SAN:rfc822Name>.*@email\\.domain" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:292 msgid "<SAN:dNSName>regular-expression" -msgstr "<SAN:dNSName>reguljärt-uttryck" +msgstr "<SAN:dNSName>regular-expression" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:295 @@ -11230,12 +11717,12 @@ msgstr "Matcha värdet på dNSName SAN." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:298 msgid "Example: <SAN:dNSName>.*\\.my\\.dns\\.domain" -msgstr "Exempel: <SAN:dNSName>.*\\.min\\.dns\\.domän" +msgstr "Exempel: <SAN:dNSName>.*\\.my\\.dns\\.domain" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:303 msgid "<SAN:x400Address>base64-string" -msgstr "<SAN:x400Address>base64-sträng" +msgstr "<SAN:x400Address>base64-string" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:306 @@ -11250,7 +11737,7 @@ msgstr "Exempel: <SAN:x400Address>MTIz" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:314 msgid "<SAN:directoryName>regular-expression" -msgstr "<SAN:directoryName>reguljärt-uttryck" +msgstr "<SAN:directoryName>regular-expression" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:317 @@ -11258,8 +11745,8 @@ msgid "" "Match the value of the directoryName SAN. The same comments as given for " "<ISSUER> and <SUBJECT> apply here as well." msgstr "" -"Matcha värdet på directoryName SAN. Samma kommentarer som gavs för " -"<ISSUER> och <SUBJECT> gäller här också." +"Matcha värdet för directoryName-SAN. Samma anmärkningar som för " +"<ISSUER> och <SUBJECT> gäller även här." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:322 @@ -11269,7 +11756,7 @@ msgstr "Exempel: <SAN:directoryName>.*,DC=com" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:327 msgid "<SAN:ediPartyName>base64-string" -msgstr "<SAN:ediPartyName>base64-sträng" +msgstr "<SAN:ediPartyName>base64-string" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:330 @@ -11284,7 +11771,7 @@ msgstr "Exempel: <SAN:ediPartyName>MTIz" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:338 msgid "<SAN:uniformResourceIdentifier>regular-expression" -msgstr "<SAN:uniformResourceIdentifier>reguljärt-uttryck" +msgstr "<SAN:uniformResourceIdentifier>regular-expression" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:341 @@ -11299,7 +11786,7 @@ msgstr "Exempel: <SAN:uniformResourceIdentifier>URN:.*" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:349 msgid "<SAN:iPAddress>regular-expression" -msgstr "<SAN:iPAddress>reguljärt-uttryck" +msgstr "<SAN:iPAddress>regular-expression" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:352 @@ -11314,12 +11801,12 @@ msgstr "Exempel: <SAN:iPAddress>192\\.168\\..*" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:360 msgid "<SAN:registeredID>regular-expression" -msgstr "<SAN:registeredID>reguljärt-uttryck" +msgstr "<SAN:registeredID>regular-expression" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:363 msgid "Match the value of the registeredID SAN as dotted-decimal string." -msgstr "Matcha värdet på registeredID SAN som punktad decimal sträng." +msgstr "Matcha värdet för registeredID-SAN som punktdecimalsträng." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:367 @@ -11346,9 +11833,9 @@ msgid "" "accounts. A Smartcard with the certificate and the matching private key can " "then be used to authenticate as one of those accounts." msgstr "" -"Mappningsregeln används för att koppla ett certifikat med ett eller flera " -"konton. Ett smartkort med certifikat och den matchande privata nyckeln kan " -"då användas för autentisering som ett av dessa konton." +"Mappningsregeln används för att koppla ett certifikat till ett eller flera " +"konton. Ett smartkort med certifikatet och den matchande privata nyckeln kan " +"sedan användas för att autentisera som ett av dessa konton." #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sss-certmap.5.xml:382 @@ -11361,14 +11848,13 @@ msgid "" "caller will embed it in another filter to do the actual search. Because of " "this the filter string should start and stop with '(' and ')' respectively." msgstr "" -"För närvarande stödjer SSSD egentligen bara LDAP för att slå upp " -"användarinformation (undantaget är proxy-leverantören som inte är relevant " -"här. På grund av detta är mappningsregeln baserad på syntaxen för LDAP-" -"sökfilter med mallar för att lägga till certifikatinnehåll till filtret. " -"Det antas att filtret endast kommer innehålla de specifika data som behövs " -"för mappningen och att anroparen kommer bädda in dem i ett annat filter för " -"att göra den egentliga sökningen. Därför skall filtersträngen börja och " -"sluta med ”(” respektive ”)”." +"För närvarande stöder SSSD i praktiken endast LDAP för att slå upp " +"användarinformation (undantaget är proxy-leverantören, som inte är relevant " +"här). Därför bygger mappningsregeln på syntaxen för LDAP-sökfilter, med " +"mallar för att lägga till certifikatinnehåll i filtret. Filtret förväntas " +"endast innehålla de specifika data som behövs för mappningen, och anroparen " +"bäddar in det i ett annat filter för att utföra den faktiska sökningen. " +"Därför ska filtersträngen börja med '(' och sluta med ')'." #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sss-certmap.5.xml:392 @@ -11378,10 +11864,10 @@ msgid "" "'altSecurityIdentities' attribute in AD or the 'ipaCertMapData' attribute " "for IPA can be used." msgstr "" -"I allmänhet rekommenderas det att använda attribut från certifikatet och " -"lägga till dem till speciella attribut till LDAP-användarobjektet. T.ex. " -"kan attributet ”altSecurityIdentities” i AD eller attributet ”ipaCertMapData" -"” i IPA användas." +"I allmänhet rekommenderas att använda attribut från certifikatet och lägga " +"till dem i särskilda attribut i LDAP-användarobjektet. Exempelvis kan " +"attributet 'altSecurityIdentities' i AD eller attributet 'ipaCertMapData' " +"för IPA användas." #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sss-certmap.5.xml:398 @@ -11392,11 +11878,11 @@ msgid "" "would break the mapping. On the other hand it would be hard to break the " "mapping on purpose for a specific user." msgstr "" -"Detta bör hellre användas än att läsa användarspecifik data från " -"certifikatet som t.ex. en e-postadress och söka efter den i LDAP-servern. " -"Anledningen är att användarspecifika data i LDAP kan ändras av olika " -"anledningar vilket skulle göra sönder mappningen. Å andra sidan skulle det " -"vara svårt att bryta mappningen avsiktligt för en specifik användare." +"Detta bör föredras framför att läsa användarspecifika data från " +"certifikatet, till exempel en e-postadress, och söka efter dem på LDAP-" +"servern. Anledningen är att användarspecifika data i LDAP kan ändras av " +"olika skäl, vilket skulle bryta mappningen. Å andra sidan skulle det vara " +"svårt att avsiktligt bryta mappningen för en viss användare." #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sss-certmap.5.xml:406 @@ -11410,14 +11896,14 @@ msgid "" "fail with a parsing error. The new templates are described in section <xref " "linkend=\"map_ldapu1\"/>." msgstr "" -"Standardtypen för <quote>mapping rule</quote> är ”LDAP” vilket kan läggas " -"till som ett prefix till en regel som t.ex. ”LDAP:(userCertificate;binary=" -"{cert!bin})”. Det finns en utökning som heter ”LDAPU1” som erbjuder fler " -"mallar för mer flexibilitet. För att tillåta äldre versioner av detta " -"bibliotek att ignorera utökningen måste prefixet ”LDAPU1” användas när de " -"nya mallarna i en <quote>mapping rule</quote> används annars kommer den " -"gamla versionen av biblioteket misslyckas med ett tolkningsfel. Den nya " -"mallarna beskrivs i avsnittet <xref linkend=\"map_ldapu1\"/>." +"Standardtypen för <quote>mappningsregel</quote> är 'LDAP', som kan läggas " +"till som prefix till en regel, till exempel 'LDAP:(userCertificate;binary=" +"{cert!bin})'. Det finns ett tillägg med namnet 'LDAPU1' som erbjuder fler " +"mallar för större flexibilitet. För att äldre versioner av biblioteket ska " +"kunna ignorera tillägget måste prefixet 'LDAPU1' användas när de nya " +"mallarna används i en <quote>mappningsregel</quote>. Annars misslyckas den " +"äldre biblioteksversionen med ett tolkningsfel. De nya mallarna beskrivs i " +"avsnitt <xref linkend=\"map_ldapu1\"/>." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:424 @@ -11431,9 +11917,9 @@ msgid "" "RFC 4514. If X.500 ordering (most specific RDN comes last) an option with " "the '_x500' prefix should be used." msgstr "" -"Mallen kommer lägga till den fullständiga utgivar-DN:en konverterad till en " -"sträng enligt RFC 4514. Om X.500-ordning (mest specifik RDN kommer sist) " -"skall ett alternativ med prefixet ”_x500” användas." +"Mallen lägger till hela utfärdar-DN:t, konverterat till en sträng enligt RFC " +"4514. Vid X.500-ordning (den mest specifika RDN:en kommer sist) ska ett " +"alternativ med prefixet '_x500' användas." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:433 sss-certmap.5.xml:459 @@ -11441,8 +11927,8 @@ msgid "" "The conversion options starting with 'ad_' will use attribute names as used " "by AD, e.g. 'S' instead of 'ST'." msgstr "" -"Konverteringsalternativen som börjar med ”ad_” kommer använda attribut som " -"de används av AD, t.ex. ”S” istället för ”ST”." +"Konverteringsalternativ som börjar med 'ad_' använder attributnamn enligt " +"AD, till exempel 'S' i stället för 'ST'." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:437 sss-certmap.5.xml:463 @@ -11450,8 +11936,8 @@ msgid "" "The conversion options starting with 'nss_' will use attribute names as used " "by NSS." msgstr "" -"Konverteringsalternativen som börjar med ”nss_” kommer använda attributnamn " -"som de används av NSS." +"Konverteringsalternativ som börjar med 'nss_' använder attributnamn enligt " +"NSS." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:441 sss-certmap.5.xml:467 @@ -11459,8 +11945,8 @@ msgid "" "The default conversion option is 'nss', i.e. attribute names according to " "NSS and LDAP/RFC 4514 ordering." msgstr "" -"Standard för konverteringsalternativ är ”nss”, d.v.s. attributnamn enligt " -"NSS och LDAP/RFC 4514-ordning." +"Standardalternativet för konvertering är 'nss', dvs. attributnamn enligt NSS " +"och LDAP/RFC 4514-ordning." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:445 @@ -11483,9 +11969,9 @@ msgid "" "RFC 4514. If X.500 ordering (most specific RDN comes last) an option with " "the '_x500' prefix should be used." msgstr "" -"Mallen kommer lägga till den fullständiga subjekt-DN:en konverterad till en " -"sträng enligt RFC 4514. Om X.500-ordning (mest specifik RDN kommer sist) " -"skall ett alternativ med prefixet ”_x500” användas." +"Mallen lägger till hela subject-DN:t, konverterat till en sträng enligt RFC " +"4514. Vid X.500-ordning (den mest specifika RDN:en kommer sist) ska ett " +"alternativ med prefixet '_x500' användas." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:471 @@ -11510,11 +11996,11 @@ msgid "" "hex sequence is the default and can e.g. be used with the LDAP attribute " "'userCertificate;binary'." msgstr "" -"Denna mall kommer lägga till hela det DER-kodade certifikatet som än sträng " -"till sökfiltret. Beroende på konverteringsalternativen konverteras antingen " -"certifikatet till en hex-sekvens med styrtecken ”\\xx” eller till base64. " -"Hex-strängen med styrtecken är standard och kan t.ex. användas med LDAP-" -"attributet ”userCertificate;binary”." +"Mallen lägger till hela det DER-kodade certifikatet som en sträng i " +"sökfiltret. Beroende på konverteringsalternativet konverteras det binära " +"certifikatet antingen till en undantagen hexsekvens '\\xx' eller base64. Den " +"undantagna hexsekvensen är standard och kan till exempel användas med LDAP-" +"attributet 'userCertificate;binary'." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:487 @@ -11533,9 +12019,9 @@ msgid "" "SAN used by pkinit or the one used by AD. The 'short_name' component " "represents the first part of the principal before the '@' sign." msgstr "" -"Denna mall kommer lägga till Kerberos-huvudmannen som hämtas antingen från " -"den SAN som används av pkinit eller den som används av AD. Komponenten ”" -"short_name” representerar första delen av huvudmannen före tecknet ”@”." +"Mallen lägger till Kerberos-huvudmannen som hämtas antingen från det SAN som " +"används av pkinit eller det som används av AD. Komponenten 'short_name' " +"representerar huvudmannens första del före tecknet '@'." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:501 @@ -11558,9 +12044,9 @@ msgid "" "by pkinit. The 'short_name' component represents the first part of the " "principal before the '@' sign." msgstr "" -"Denna mall kommer lägga till Kerberos-huvudmannen som hämtas från den SAN " -"som används av pkinit. Komponenten ”short_name” representerar första delen " -"av huvudmannen före tecknet ”@”." +"Mallen lägger till Kerberos-huvudmannen som anges av det SAN som används av " +"pkinit. Komponenten 'short_name' representerar huvudmannens första del före " +"tecknet '@'." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:515 @@ -11583,9 +12069,9 @@ msgid "" "by AD. The 'short_name' component represent the first part of the principal " "before the '@' sign." msgstr "" -"Denna mall kommer lägga till Kerberos-huvudmannen som hämtas från den SAN " -"som används av AD. Komponenten ”short_name” representerar första delen av " -"huvudmannen före tecknet ”@”." +"Mallen lägger till Kerberos-huvudmannen som anges av det SAN som används av " +"AD. Komponenten 'short_name' representerar huvudmannens första del före " +"tecknet '@'." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:529 @@ -11608,9 +12094,9 @@ msgid "" "component of the SAN, typically an email address. The 'short_name' component " "represents the first part of the address before the '@' sign." msgstr "" -"Denna mall kommer lägga till strängen som lagras i komponenten rfc822Name i " -"SAN:en, normalt en e-postadress. Komponenten ”short_name” representerar " -"första delen av huvudmannen före tecknet ”@”." +"Mallen lägger till strängen som lagras i komponenten rfc822Name i SAN, " +"vanligen en e-postadress. Komponenten 'short_name' representerar adressens " +"första del före tecknet '@'." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:543 @@ -11633,10 +12119,9 @@ msgid "" "of the SAN, typically a fully-qualified host name. The 'short_name' " "component represents the first part of the name before the first '.' sign." msgstr "" -"Denna mall kommer lägga till strängen som lagras i komponenten dNSName i " -"SAN:en, normalt ett fullständigt kvalificerat värdnamn. Komponenten ”" -"short_name” representerar första delen av huvudmannen före det första ”.”-" -"tecknet." +"Mallen lägger till strängen som lagras i komponenten dNSName i SAN, vanligen " +"ett fullständigt kvalificerat värdnamn. Komponenten 'short_name' " +"representerar namnets första del före det första tecknet '.'." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:557 @@ -11656,8 +12141,8 @@ msgid "" "This template will add the string which is stored in the " "uniformResourceIdentifier component of the SAN." msgstr "" -"Denna mall kommer lägga till strängen som lagras i komponenten " -"uniformResourceIdentifier i SAN:en." +"Mallen lägger till strängen som lagras i komponenten " +"uniformResourceIdentifier i SAN." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:569 @@ -11674,9 +12159,7 @@ msgstr "{subject_ip_address}" msgid "" "This template will add the string which is stored in the iPAddress component " "of the SAN." -msgstr "" -"Denna mall kommer lägga till strängen som lagras i komponenten iPAddress i " -"SAN:en." +msgstr "Mallen lägger till strängen som lagras i komponenten iPAddress i SAN." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:581 @@ -11694,8 +12177,8 @@ msgid "" "This template will add the value which is stored in the x400Address " "component of the SAN as escaped hex sequence." msgstr "" -"Denna mall kommer lägga till värdet som lagras i komponenten x400Address i " -"SAN:en som en hex-sekvens med styrtecken." +"Mallen lägger till värdet som lagras i komponenten x400Address i SAN som en " +"undantagen hexsekvens." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:594 @@ -11715,8 +12198,8 @@ msgid "" "This template will add the DN string of the value which is stored in the " "directoryName component of the SAN." msgstr "" -"Denna mall kommer lägga till DN-strängen för värdet som lagras i komponenten " -"directoryName i SAN:en." +"Mallen lägger till DN-strängen för värdet som lagras i komponenten " +"directoryName i SAN." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:606 @@ -11734,8 +12217,8 @@ msgid "" "This template will add the value which is stored in the ediPartyName " "component of the SAN as escaped hex sequence." msgstr "" -"Denna mall kommer lägga till värdet som lagras i komponenten ediPartyName i " -"SAN:en som en hex-sekvens med styrtecken." +"Mallen lägger till värdet som lagras i komponenten ediPartyName i SAN som en " +"undantagen hexsekvens." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:619 @@ -11753,8 +12236,8 @@ msgid "" "This template will add the OID which is stored in the registeredID component " "of the SAN as a dotted-decimal string." msgstr "" -"Denna mall kommer lägga till OID:n som lagras i komponenten registeredID i " -"SAN:en som en punktad decimal sträng." +"Mallen lägger till OID:n som lagras i komponenten registeredID i SAN som en " +"punktdecimalsträng." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:632 @@ -11770,22 +12253,23 @@ msgid "" "conversion/formatting option separated by a '!'. Allowed values are: " "<placeholder type=\"variablelist\" id=\"0\"/>" msgstr "" -"Mallarna för att lägga till certifikatdata till sökfiltret baseras på " -"formateringssträngar i Python-stil. De består av ett nyckelord i " -"krullparenteser med en valfri underkomponentspecificerare separerad av en " -"”.” eller ett valfritt konverterings-/formateringsalternativ separerat av " -"ett ”!”. Tillåtna värden är: <placeholder type=\"variablelist\" id=\"0\"/>" +"Mallarna för att lägga till certifikatdata i sökfiltret bygger på " +"formateringssträngar i Python-stil. De består av ett nyckelord inom " +"klammerparenteser med en valfri underkomponentspecificerare som avgränsas " +"med '.' eller ett valfritt konverterings-/formateringsalternativ som " +"avgränsas med '!'. Tillåtna värden är: <placeholder type=\"variablelist\" " +"id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><title> #: sss-certmap.5.xml:639 msgid "LDAPU1 extension" -msgstr "LDAPU1-utvidgningen" +msgstr "LDAPU1-tillägget" #. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para> #: sss-certmap.5.xml:641 msgid "" "The following templates are available when using the 'LDAPU1' extension:" -msgstr "Följande mallar är tillgängliga när du använder tillägget \"LDAPU1\":" +msgstr "Följande mallar är tillgängliga när tillägget 'LDAPU1' används:" #. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:647 @@ -11798,8 +12282,8 @@ msgid "" "This template will add the serial number of the certificate. By default it " "will be printed as a hexadecimal number with lower-case letters." msgstr "" -"Denna mall kommer lägga till certifikatets serienummer. Som standard kommer " -"det skrivas som ett hexadecimalt tal med gemena bokstäver." +"Mallen lägger till certifikatets serienummer. Som standard skrivs det ut som " +"ett hexadecimalt tal med gemena bokstäver." #. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:655 @@ -11811,12 +12295,12 @@ msgid "" "be combined so that e.g. '!hex_uc' will produce a colon-separated " "hexadecimal string with upper-case letters." msgstr "" -"Med formateringsalternativet ”!dec” kommer numret skrivas som en decimal " -"sträng. Den exadecimala utdatan kan skrivas med versala bokstäver (”!hex_u”)" -", med ett kolon som separator mellan hexadecimala byte (”!hex_c”) eller med " -"de hexadecimala byten i omvänd ordning (”!hex_r”). Postfixbokstäverna kan " -"kombineras så att t.ex. ”!hex_uc\" kommer producera en kolonseparerad " -"hexadecimal sträng med versaler." +"Med formateringsalternativet '!dec' skrivs talet ut som en decimalsträng. De " +"hexadecimala utdata kan skrivas ut med versala bokstäver ('!hex_u'), med ett " +"kolon mellan de hexadecimala byte ('!hex_c') eller med de hexadecimala byten " +"i omvänd ordning ('!hex_r'). Postfixbokstäverna kan kombineras så att till " +"exempel '!hex_uc' ger en kolonseparerad hexadecimal sträng med versala " +"bokstäver." #. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:665 @@ -11834,8 +12318,8 @@ msgid "" "This template will add the subject key id of the certificate. By default it " "will be printed as a hexadecimal number with lower-case letters." msgstr "" -"Denna mall kommer lägga till certifikatets subjektnyckel-id. Som standard " -"kommer det skrivas som ett hexadecimalt tal med gemena bokstäver." +"Mallen lägger till certifikatets subject key ID. Som standard skrivs det ut " +"som ett hexadecimalt tal med gemena bokstäver." #. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:679 @@ -11846,11 +12330,11 @@ msgid "" "combined so that e.g. '!hex_uc' will produce a colon-separated hexadecimal " "string with upper-case letters." msgstr "" -"Den hexadecimala utdatan kan skrivas med versala bokstäver (”!hex_u”), med " -"ett kolon som separator mellan hexadecimala byte (”!hex_c”) eller med de " -"hexadecimala byten i omvänd ordning (”!hex_r”). Postfixbokstäverna kan " -"kombineras så att t.ex. ”!hex_uc\" kommer producera en kolonseparerad " -"hexadecimal sträng med versaler." +"De hexadecimala utdata kan skrivas ut med versala bokstäver ('!hex_u'), med " +"ett kolon mellan de hexadecimala byte ('!hex_c') eller med de hexadecimala " +"byten i omvänd ordning ('!hex_r'). Postfixbokstäverna kan kombineras så att " +"till exempel '!hex_uc' ger en kolonseparerad hexadecimal sträng med versala " +"bokstäver." #. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:688 @@ -11860,7 +12344,7 @@ msgstr "Exempel: LDAPU1:(ski={subject_key_id})" #. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:694 msgid "{cert[!DIGEST[_ucr]]}" -msgstr "{cert[!KONTROLLSUMMA[_ucr]]}" +msgstr "{cert[!DIGEST[_ucr]]}" #. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:697 @@ -11869,9 +12353,9 @@ msgid "" "DIGEST must be replaced with the name of a digest/hash function supported by " "OpenSSL, e.g. 'sha512'." msgstr "" -"Denna mall kommer läga till certifikatets hexadecimala kontrollsumma/hash " -"där KONTROLLSUMMA måste ersättas med namnet på en kontrollsumme-/hash-" -"funktion som stödjs av OpenSSL, t.ex. ”sha512”." +"Mallen lägger till certifikatets hexadecimala digest/hash, där DIGEST måste " +"ersättas med namnet på en digest/hash-funktion som stöds av OpenSSL, till " +"exempel 'sha512'." #. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:703 @@ -11882,11 +12366,11 @@ msgid "" "combined so that e.g. '!sha512_uc' will produce a colon-separated " "hexadecimal string with upper-case letters." msgstr "" -"Den hexadecimala utdatan kan skrivas med versala bokstäver (”!sha512_u”), " -"med ett kolon som separator mellan hexadecimala byte (”!sha512_c”) eller med " -"de hexadecimala byten i omvänd ordning (”!sha512_r”). Postfixbokstäverna kan " -"kombineras så att t.ex. ”!sha512_uc\" kommer producera en kolonseparerad " -"hexadecimal sträng med versaler." +"De hexadecimala utdata kan skrivas ut med versala bokstäver ('!sha512_u'), " +"med ett kolon mellan de hexadecimala byte ('!sha512_c') eller med de " +"hexadecimala byten i omvänd ordning ('!sha512_r'). Postfixbokstäverna kan " +"kombineras så att till exempel '!sha512_uc' ger en kolonseparerad " +"hexadecimal sträng med versala bokstäver." #. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:712 @@ -11904,8 +12388,8 @@ msgid "" "This template will add an attribute value of a component of the subject DN, " "by default the value of the most specific component." msgstr "" -"Denna mall kommer lägga till ett av komponentens attributvärden från subjekt-" -"DN, som standard värdet på den mest specifika komponenten." +"Mallen lägger till attributvärdet för en komponent i subject-DN:t, som " +"standard värdet för den mest specifika komponenten." #. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:726 @@ -11917,13 +12401,12 @@ msgid "" "name and the position can be combined as e.g. {subject_dn_component.uid[2]} " "which means that the name of the second component must be 'uid'." msgstr "" -"En annan komponent kan väljas antingen genom attributnamn, t.ex. " -"{subject_dn_component.uid}, eller genom position, t.ex. " -"{subject_dn_component.[2]}, där positiva tal börjar räknas från den mest " -"specifika komponenten och negativa tal börjar räknas från den minst " -"specifika komponenten. Attributnamn och position kan kombineras, t.ex. " -"{subject_dn_component.uid[2]}, vilket innebär att namnet på den andra " -"komponenten måste vara ”uid”." +"En annan komponent kan väljas antingen med attributnamn, till exempel " +"{subject_dn_component.uid}, eller efter position, till exempel " +"{subject_dn_component.[2]}. Positiva tal räknas från den mest specifika " +"komponenten och negativa tal från den minst specifika. Attributnamn och " +"position kan kombineras, till exempel {subject_dn_component.uid[2]}, vilket " +"innebär att namnet på den andra komponenten måste vara 'uid'." #. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:737 @@ -11933,7 +12416,7 @@ msgstr "Exempel: LDAPU1:(uid={subject_dn_component.uid})" #. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:743 msgid "{issuer_dn_component[(.attr_name|[number]]}" -msgstr "{issuer_dn_component[(.attr_namn|[tal]]}" +msgstr "{issuer_dn_component[(.attr_name|[number]]}" #. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:746 @@ -11941,8 +12424,8 @@ msgid "" "This template will add an attribute value of a component of the issuer DN, " "by default the value of the most specific component." msgstr "" -"Denna mall kommer lägga till ett av komponentens attributvärden från utgivar-" -"DN, som standard värdet på den mest specifika komponenten." +"Mallen lägger till attributvärdet för en komponent i utfärdar-DN:t, som " +"standard värdet för den mest specifika komponenten." #. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:751 @@ -11950,8 +12433,8 @@ msgid "" "See 'subject_dn_component' for details about the attribute name and position " "specifiers." msgstr "" -"Se ”subject_dn_component” för detaljer om attributnamn och " -"positionsangivelser." +"Mer information om attributnamn och positionsangivelser finns under " +"'subject_dn_component'." #. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:755 @@ -11974,10 +12457,9 @@ msgid "" "Microsoft with the OID 1.3.6.1.4.1.311.25.2 is available. With the '.rid' " "selector only the last component, i.e. the RID, will be added." msgstr "" -"Denna mall kommer lägga till SID:n om den motsvarande utökningen " -"introducerad av Microsoft med OID 1.3.6.1.4.1.311.25.2 är tillgänglig. Med " -"selektorn ”.rid” kommer endast den sista komponenten, d.v.s RID:n, att " -"läggas till." +"Mallen lägger till SID:t om motsvarande tillägg, som Microsoft introducerade " +"med OID:n 1.3.6.1.4.1.311.25.2, är tillgängligt. Med väljaren '.rid' läggs " +"endast den sista komponenten, dvs. RID:t, till." #. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:770 @@ -11996,9 +12478,9 @@ msgid "" "only searched in the local domain but in the listed domains as well as long " "as they are know by SSSD. Domains not know to SSSD will be ignored." msgstr "" -"Om domänlistan inte är tom söks användare mappade till ett givet certifikat " -"inte bara i den lokala domänen utan i de listade domänerna också förutsatt " -"att de är kända av SSSD. Domäner som SSSD inte känner till kommer ignoreras." +"Om domänlistan inte är tom söks användare som har mappats till ett visst " +"certifikat inte bara i den lokala domänen, utan även i de listade domänerna, " +"så länge SSSD känner till dem. Domäner som SSSD inte känner till ignoreras." #. type: Content of: <reference><refentry><refnamediv><refname> #: sssd-ipa.5.xml:10 sssd-ipa.5.xml:16 @@ -12019,11 +12501,11 @@ msgid "" "FORMAT</quote> section of the <citerefentry> <refentrytitle>sssd.conf</" "refentrytitle> <manvolnum>5</manvolnum> </citerefentry> manual page." msgstr "" -"Denna manualsida beskriver konfigurationen av leverantören IPA till " +"Den här manualsidan beskriver konfigurationen av IPA-leverantören för " "<citerefentry> <refentrytitle>sssd</refentrytitle> <manvolnum>8</manvolnum> " -"</citerefentry>. För en detaljerad referens om syntaxen, se avsnittet " -"<quote>FILFORMAT</quote> i manualsidan <citerefentry> <refentrytitle>" -"sssd.conf</refentrytitle> <manvolnum>5</manvolnum> </citerefentry>." +"</citerefentry>. En detaljerad syntaxreferens finns i avsnittet <quote>" +"FILFORMAT</quote> på manualsidan <citerefentry> <refentrytitle>sssd.conf</" +"refentrytitle> <manvolnum>5</manvolnum> </citerefentry>." #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ipa.5.xml:36 @@ -12033,10 +12515,10 @@ msgid "" "requires that the machine be joined to the IPA domain; configuration is " "almost entirely self-discovered and obtained directly from the server." msgstr "" -"IPA-leverantören är en bakände som används för att ansluta till en IPA-" -"server. (Se webbsidan freeipa.org för information om IPA-servrar.) " -"Leverantören förutsätter att maskinen är inlagt i IPA-domänen; " -"konfigurationen är nästan helt självupptäckande och hämtas direkt från " +"IPA-leverantören är en bakomliggande komponent som används för att ansluta " +"till en IPA-server. (Information om IPA-servrar finns på webbplatsen " +"freeipa.org.) Leverantören kräver att datorn har anslutits till IPA-domänen. " +"Konfigurationen identifieras nästan helt automatiskt och hämtas direkt från " "servern." #. type: Content of: <reference><refentry><refsect1><para> @@ -12050,14 +12532,14 @@ msgid "" "options used by the sssd-ldap and sssd-krb5 providers with some exceptions. " "However, it is neither necessary nor recommended to set these options." msgstr "" -"IPA-leverantören gör att SSSD kan använda identitetsleverantören " +"IPA-leverantören gör det möjligt för SSSD att använda identitetsleverantören " "<citerefentry> <refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</" "manvolnum> </citerefentry> och autentiseringsleverantören <citerefentry> " "<refentrytitle>sssd-krb5</refentrytitle> <manvolnum>5</manvolnum> </" -"citerefentry> med optimeringar för IPA-miljöer. IPA-leverantören tar samma " -"alternativ som används av leverantörerna sssd-ldap och sssd-krb5 med några " -"undantag. Dock är det varken nödvändigt eller lämpligt att sätta dessa " -"alternativ." +"citerefentry> med optimeringar för IPA-miljöer. IPA-leverantören accepterar, " +"med några undantag, samma alternativ som leverantörerna sssd-ldap och sssd-" +"krb5 använder. Det är dock varken nödvändigt eller rekommenderat att ange " +"alternativen." #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ipa.5.xml:57 @@ -12066,9 +12548,9 @@ msgid "" "default options with some exceptions, the differences are listed in the " "<quote>MODIFIED DEFAULT OPTIONS</quote> section." msgstr "" -"IPA-leverantören kopierar i huvudsak standardalternativen för de " -"traditionella leverantörerna ldap och krb5 med några undantag. Skillnaderna " -"listas i avsnittet <quote>ÄNDRADE STANDARDINSTÄLLNINGAR</quote>." +"IPA-leverantören använder huvudsakligen standardalternativen för de " +"traditionella leverantörerna ldap och krb5, med några undantag. Skillnaderna " +"listas i avsnittet <quote>ÄNDRADE STANDARDALTERNATIV</quote>." #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ipa.5.xml:62 @@ -12077,10 +12559,10 @@ msgid "" "<quote>ipa_access_order</quote>) as it mainly uses HBAC (host-based access " "control) rules. Please refer to freeipa.org for more information about HBAC." msgstr "" -"Som en åtkomstleverantör har leverantören IPA en minimal konfiguration (se " -"<quote>ipa_access_order</quote>) eftersom den huvudsakligen använder HBAC-" -"regler (host-based access control, värdbaserad åtkomstkontroll). Se " -"freeipa.org för mer information om HBAC." +"Som åtkomstleverantör har IPA-leverantören en minimal konfiguration (se " +"<quote>ipa_access_order</quote>), eftersom den huvudsakligen använder HBAC-" +"regler (värdbaserad åtkomststyrning). Mer information om HBAC finns på " +"freeipa.org." #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ipa.5.xml:68 @@ -12090,8 +12572,7 @@ msgid "" "quote>." msgstr "" "Om <quote>auth_provider=ipa</quote> eller <quote>access_provider=ipa</quote> " -"konfigureras i sssd.conf måste id-leverantören också sättas till <quote>ipa</" -"quote>." +"konfigureras i sssd.conf måste även id_provider anges som <quote>ipa</quote>." #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ipa.5.xml:74 @@ -12100,10 +12581,10 @@ msgid "" "from trusted realms contain a PAC. To make configuration easier the PAC " "responder is started automatically if the IPA ID provider is configured." msgstr "" -"IPA-leverantörer kommer använda PAC-respondenten om Kerberos-biljetter för " -"användare för betrodda riken innehåller en PAC. För att göra " -"konfigurationen enklare startas PAC-respondenten automatiskt om ID-" -"leverantören IPA är konfigurerad." +"IPA-leverantören använder PAC-svarskomponenten om Kerberos-biljetter för " +"användare från betrodda realmer innehåller en PAC. För att förenkla " +"konfigurationen startas PAC-svarskomponenten automatiskt om IPA-" +"identitetsleverantören är konfigurerad." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:90 @@ -12133,11 +12614,12 @@ msgid "" "This is optional if autodiscovery is enabled. For more information on " "service discovery, refer to the <quote>SERVICE DISCOVERY</quote> section." msgstr "" -"Den kommaseparerade listan av IP-adresser eller värdnamn till IPA-servrar " -"till vilka SSSD skall ansluta i prioritetsordning. För mer information om " -"reserver och serverredundans se avsnittet <quote>RESERVER</quote>. Detta är " -"frivilligt om automatupptäckt är aktiverat. För mer information om " -"tjänsteupptäckt, se avsnittet <quote>TJÄNSTEUPPTÄCKT</quote>." +"Den kommaseparerade listan med IP-adresser eller värdnamn för IPA-servrar " +"som SSSD ska ansluta till i prioritetsordning. Mer information om " +"reservväxling och serverredundans finns i avsnittet <quote>RESERVVÄXLING</" +"quote>. Detta är valfritt om automatisk identifiering är aktiverad. Mer " +"information om tjänsteidentifiering finns i avsnittet <quote>" +"TJÄNSTEIDENTIFIERING</quote>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:117 @@ -12156,9 +12638,9 @@ msgstr "" "identifiera denna värd. Värdnamnet måste vara fullständigt kvalificerat." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:129 sssd-ad.5.xml:1161 +#: sssd-ipa.5.xml:129 sssd-ad.5.xml:1166 msgid "dyndns_update (boolean)" -msgstr "dyndns_update (boolean)" +msgstr "dyndns_update (boolesk)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:132 @@ -12169,49 +12651,40 @@ msgid "" "updates, if it is not otherwise specified by using the <quote>dyndns_iface</" "quote> option." msgstr "" -"Valfritt. Detta alternativ säger till SSSD att automatiskt uppdatera DNS-" -"servern som är inbyggd i FreeIPA med IP-adressen för denna klient. " -"Uppdateringen säkras med GSS-TSIG. IP-adressen för IPA-LDAP-förbindelsen " -"används för uppdateringar, om det inte specificeras på annat sätt med " -"alternativet <quote>dyndns_iface</quote>." - -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:141 sssd-ad.5.xml:1175 -msgid "" -"NOTE: On older systems (such as RHEL 5), for this behavior to work reliably, " -"the default Kerberos realm must be set properly in /etc/krb5.conf" -msgstr "" -"OBS: på äldre system (såsom RHEL 5) måste standardriket för Kerberos sättas " -"i /etc/krb5.conf för att detta beteende skall fungera pålitligt" +"Valfritt. Det här alternativet instruerar SSSD att automatiskt uppdatera DNS-" +"servern som ingår i FreeIPA med klientens IP-adress. Uppdateringen säkras " +"med GSS-TSIG. IP-adressen för IPA-LDAP-anslutningen används för " +"uppdateringarna, om inget annat anges med alternativet <quote>dyndns_iface</" +"quote>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:152 sssd-ad.5.xml:1186 +#: sssd-ipa.5.xml:147 sssd-ad.5.xml:1186 msgid "dyndns_ttl (integer)" msgstr "dyndns_ttl (heltal)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:155 sssd-ad.5.xml:1189 +#: sssd-ipa.5.xml:150 sssd-ad.5.xml:1189 msgid "" "The TTL to apply to the client DNS record when updating it. If " "dyndns_update is false this has no effect. This will override the TTL " "serverside if set by an administrator." msgstr "" -"TTL:en att använda för klientens DNS-post vid uppdatering. Om dyndns_update " -"är falsk har detta ingen effekt. Detta kommer åsidosätta TTL på serversidan " -"om det är satt av en administratör." +"TTL-värdet som används för klientens DNS-post vid uppdatering. Om " +"dyndns_update är false har detta ingen effekt. Det åsidosätter TTL-värdet på " +"serversidan om en administratör har angett det." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:160 +#: sssd-ipa.5.xml:155 msgid "Default: 1200 (seconds)" msgstr "Standard: 1200 (sekunder)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:166 sssd-ad.5.xml:1200 +#: sssd-ipa.5.xml:161 sssd-ad.5.xml:1200 msgid "dyndns_iface (string)" msgstr "dyndns_iface (sträng)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:169 sssd-ad.5.xml:1203 +#: sssd-ipa.5.xml:164 sssd-ad.5.xml:1203 msgid "" "Optional. Applicable only when dyndns_update is true. Choose the interface " "or a list of interfaces whose IP addresses should be used for dynamic DNS " @@ -12221,36 +12694,36 @@ msgid "" "use all interfaces except <emphasis>eth1</emphasis>. See <emphasis>man 7 " "glob</emphasis> for details about patterns." msgstr "" -"Valfritt. Gäller endast när dyndns_update är sant. Välj gränssnittet eller " +"Valfritt. Gäller endast när dyndns_update är true. Välj gränssnittet eller " "en lista över gränssnitt vars IP-adresser ska användas för dynamiska DNS-" -"uppdateringar. Namnet på gränssnittet kan vara ett jokerteckenmönster med " -"prefixet <emphasis>!</emphasis> för gränssnitt som ska exkluderas. Första " -"träffen avbryter utvärderingen. Till exempel list <emphasis>!eth1, *</" -"emphasis> instruerar SSSD att använda alla gränssnitt utom <emphasis>eth1</" -"emphasis>. Se <emphasis>man 7 glob</emphasis> för mer information om " -"mönster." +"uppdateringar. Gränssnittets namn kan vara ett jokerteckenmönster med " +"prefixet <emphasis>!</emphasis> för att exkludera gränssnitt. Den första " +"matchningen avslutar utvärderingen. Listan <emphasis>!eth1, *</emphasis> " +"instruerar till exempel SSSD att använda alla gränssnitt utom <emphasis>" +"eth1</emphasis>. Mer information om mönster finns i <emphasis>man 7 glob</" +"emphasis>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:182 +#: sssd-ipa.5.xml:177 msgid "" "Default: Use the IP addresses of the interface which is used for IPA LDAP " "connection" msgstr "" -"Standard: använd IP-adresser för gränssnittet som används för IPA LDAP-" -"förbindelsen" +"Standard: Använd IP-adresserna för gränssnittet som används för IPA-LDAP-" +"anslutningen" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:186 sssd-ad.5.xml:1226 +#: sssd-ipa.5.xml:181 sssd-ad.5.xml:1220 msgid "Example: dyndns_iface = em[12], !vnet1, vnet*" msgstr "Exempel: dyndns_iface = em[12], !vnet1, vnet*" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:192 sssd-ad.5.xml:1232 +#: sssd-ipa.5.xml:187 sssd-ad.5.xml:1226 msgid "dyndns_address (string)" msgstr "dyndns_address (sträng)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:195 sssd-ad.5.xml:1235 +#: sssd-ipa.5.xml:190 sssd-ad.5.xml:1229 msgid "" "Optional. Applicable only when <emphasis>dyndns_update</emphasis> is true. " "A list of IP addresses or IP networks to be used for dynamic DNS updates. " @@ -12259,106 +12732,109 @@ msgid "" "emphasis> is used to determine whether an address is included or excluded " "(i.e., a longer prefix takes precedence)." msgstr "" -"Valfritt. Gäller endast när <emphasis>dyndns_update</emphasis> är sant. En " -"lista över IP-adresser eller IP-nätverk som ska användas för dynamiska DNS-" -"uppdateringar. Nätverksadresser måste vara i CIDR-format. En post kan " -"prefixeras med <emphasis>!</emphasis> för att ange undantag. Den <emphasis>" -"bästa matchningen</emphasis> används för att avgöra om en adress ska " -"inkluderas eller exkluderas (dvs. ett längre prefix har företräde)." +"Valfritt. Gäller endast när <emphasis>dyndns_update</emphasis> är true. En " +"lista med IP-adresser eller IP-nätverk som ska användas för dynamiska DNS-" +"uppdateringar. Nätverksadresser måste vara i CIDR-format. En post kan ha " +"prefixet <emphasis>!</emphasis> för att ange undantag. Den <emphasis>bästa " +"matchningen</emphasis> avgör om en adress inkluderas eller exkluderas (dvs. " +"ett längre prefix har företräde)." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:206 sssd-ad.5.xml:1246 +#: sssd-ipa.5.xml:201 sssd-ad.5.xml:1240 msgid "Default: No filtering of IP addresses." msgstr "Standard: Ingen filtrering av IP-adresser." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:209 sssd-ad.5.xml:1249 +#: sssd-ipa.5.xml:204 sssd-ad.5.xml:1243 msgid "Example: dyndns_address = 10.0.0.0/16, !10.0.1.0/24" msgstr "Exempel: dyndns_address = 10.0.0.0/16, !10.0.1.0/24" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:215 sssd-ad.5.xml:1305 +#: sssd-ipa.5.xml:210 sssd-ad.5.xml:1298 msgid "dyndns_auth (string)" msgstr "dyndns_auth (sträng)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:218 sssd-ad.5.xml:1308 +#: sssd-ipa.5.xml:213 sssd-ad.5.xml:1301 msgid "" "Whether the nsupdate utility should use GSS-TSIG authentication for secure " "updates with the DNS server, insecure updates can be sent by setting this " "option to 'none'." msgstr "" -"Huruvida verktyget nsupdate skall använda GSS-TSIG-autentisering för säkra " -"uppdateringar av DNS-servern, osäkra uppdateringar kan skickas genom att " -"sätta detta alternativ till ”none”." +"Anger om verktyget nsupdate ska använda GSS-TSIG-autentisering för säkra " +"uppdateringar med DNS-servern. Osäkra uppdateringar kan skickas genom att " +"ange alternativet som 'none'." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:224 sssd-ad.5.xml:1314 +#: sssd-ipa.5.xml:219 sssd-ad.5.xml:1307 msgid "Default: GSS-TSIG" msgstr "Standard: GSS-TSIG" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:230 sssd-ad.5.xml:1320 +#: sssd-ipa.5.xml:225 sssd-ad.5.xml:1313 msgid "dyndns_auth_ptr (string)" msgstr "dyndns_auth_ptr (sträng)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:233 sssd-ad.5.xml:1323 +#: sssd-ipa.5.xml:228 sssd-ad.5.xml:1316 msgid "" "Whether the nsupdate utility should use GSS-TSIG authentication for secure " "PTR updates with the DNS server, insecure updates can be sent by setting " "this option to 'none'." msgstr "" -"Huruvida verktyget nsupdate skall använda GSS-TSIG-autentisering för säkra " -"PTR-uppdateringar av DNS-servern, osäkra uppdateringar kan skickas genom att " -"sätta detta alternativ till ”none”." +"Anger om verktyget nsupdate ska använda GSS-TSIG-autentisering för säkra PTR-" +"uppdateringar med DNS-servern. Osäkra uppdateringar kan skickas genom att " +"ange alternativet som 'none'." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:239 sssd-ad.5.xml:1329 +#: sssd-ipa.5.xml:234 sssd-ad.5.xml:1322 msgid "Default: Same as dyndns_auth" msgstr "Standard: samma som dyndns_auth" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:245 sssd-ad.5.xml:1255 +#: sssd-ipa.5.xml:240 sssd-ad.5.xml:1249 msgid "dyndns_refresh_interval (integer)" msgstr "dyndns_refresh_interval (heltal)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:248 +#: sssd-ipa.5.xml:243 msgid "" "How often should the back end perform periodic DNS update in addition to the " "automatic update performed when the back end goes online. This option is " "optional and applicable only when dyndns_update is true." msgstr "" -"Hur ofta bakänden skall utföra periodiska DNS-uppdateringar utöver den " -"automatiska uppdateringen som utförs när bakänden kopplar upp. Detta " -"alternativ är valfritt och tillämpligt endast när dyndns_update är sann." +"Anger hur ofta den bakomliggande komponenten ska utföra periodiska DNS-" +"uppdateringar utöver den automatiska uppdatering som utförs när komponenten " +"ansluter. Alternativet är valfritt och gäller endast när dyndns_update är " +"true." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:261 sssd-ad.5.xml:1273 -msgid "dyndns_update_ptr (bool)" +#: sssd-ipa.5.xml:256 sssd-ad.5.xml:1266 +#, fuzzy +#| msgid "dyndns_update_ptr (bool)" +msgid "dyndns_update_ptr (boolean)" msgstr "dyndns_update_ptr (bool)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:264 sssd-ad.5.xml:1276 +#: sssd-ipa.5.xml:259 sssd-ad.5.xml:1269 msgid "" "Whether the PTR record should also be explicitly updated when updating the " "client's DNS records. Applicable only when dyndns_update is true." msgstr "" -"Huruvida PTR-posten också skall uppdateras explicit när klientens DNS-post " -"uppdateras. Tillämpligt endast när dyndns_update är sann." +"Anger om PTR-posten också ska uppdateras uttryckligen när klientens DNS-" +"poster uppdateras. Gäller endast när dyndns_update är true." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:269 +#: sssd-ipa.5.xml:264 msgid "" "This option should be False in most IPA deployments as the IPA server " "generates the PTR records automatically when forward records are changed." msgstr "" -"Detta alternativ är False i de flesta IPA-installationer eftersom IPA-" -"servern genererar PTR-posterna automatiskt när framåtposterna ändras." +"Det här alternativet bör vara False i de flesta IPA-installationer, eftersom " +"IPA-servern automatiskt genererar PTR-poster när framåtposter ändras." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:275 sssd-ad.5.xml:1281 +#: sssd-ipa.5.xml:270 sssd-ad.5.xml:1274 msgid "" "Note that <emphasis>dyndns_update_per_family</emphasis> parameter does not " "apply for PTR record updates. Those updates are always sent separately." @@ -12368,45 +12844,47 @@ msgstr "" "separat." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:280 +#: sssd-ipa.5.xml:275 msgid "Default: False (disabled)" msgstr "Standard: False (avaktiverat)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:286 sssd-ad.5.xml:1292 -msgid "dyndns_force_tcp (bool)" +#: sssd-ipa.5.xml:281 sssd-ad.5.xml:1285 +#, fuzzy +#| msgid "dyndns_force_tcp (bool)" +msgid "dyndns_force_tcp (boolean)" msgstr "dyndns_force_tcp (bool)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:289 sssd-ad.5.xml:1295 +#: sssd-ipa.5.xml:284 sssd-ad.5.xml:1288 msgid "" "Whether the nsupdate utility should default to using TCP for communicating " "with the DNS server." msgstr "" -"Huruvida nsupdate-verktyget som standard skall använda TCP för kommunikation " +"Anger om verktyget nsupdate som standard ska använda TCP för kommunikation " "med DNS-servern." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:293 sssd-ad.5.xml:1299 +#: sssd-ipa.5.xml:288 sssd-ad.5.xml:1292 msgid "Default: False (let nsupdate choose the protocol)" msgstr "Standard: False (låt nsupdate välja protokollet)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:299 sssd-ad.5.xml:1335 +#: sssd-ipa.5.xml:294 sssd-ad.5.xml:1328 msgid "dyndns_server (string)" msgstr "dyndns_server (sträng)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:302 sssd-ad.5.xml:1338 +#: sssd-ipa.5.xml:297 sssd-ad.5.xml:1331 msgid "" "The DNS server to use when performing a DNS update. In most setups, it's " "recommended to leave this option unset." msgstr "" -"DNS-servern som skall användas när en uppdatering av DNS utförs. I de " -"flesta uppsättningar rekommenderas det att låta detta alternativ vara osatt." +"DNS-servern som ska användas vid en DNS-uppdatering. I de flesta " +"konfigurationer rekommenderas att låta alternativet vara oangivet." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:307 sssd-ad.5.xml:1343 +#: sssd-ipa.5.xml:302 sssd-ad.5.xml:1336 msgid "" "Setting this option makes sense for environments where the DNS server is " "different from the identity server or when we use encrypted DNS." @@ -12415,18 +12893,19 @@ msgstr "" "skiljer sig från identitetsservern eller när vi använder krypterad DNS." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:312 sssd-ad.5.xml:1348 +#: sssd-ipa.5.xml:307 sssd-ad.5.xml:1341 msgid "" "The parameter can be a simple string containing DNS name or IP address. It " "can also be an URI. The URI can look like <emphasis>dns://servername/</" "emphasis> or <emphasis>dns+tls://1.2.3.4:853#servername/</emphasis>." msgstr "" -"Parametern kan vara en enkel sträng som innehåller DNS-namn eller IP-adress. " -"Den kan också vara en URI. URI kan se ut som <emphasis>dns://servernamn/</" -"emphasis> eller <emphasis>dns+tls://1.2.3.4:853#servernamn/.</emphasis>." +"Parametern kan vara en enkel sträng som innehåller ett DNS-namn eller en IP-" +"adress. Den kan också vara en URI. URI:n kan se ut som <emphasis>dns://" +"servername/</emphasis> eller <emphasis>dns+tls://1.2.3.4:853#servername/</" +"emphasis>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:319 sssd-ad.5.xml:1355 +#: sssd-ipa.5.xml:314 sssd-ad.5.xml:1348 msgid "" "The second example enables DNS-over-TLS protocol for DNS updates. The " "nsupdate utility must support DoT - check the <emphasis>man nsupdate</" @@ -12437,44 +12916,44 @@ msgstr "" "emphasis> innan du aktiverar det i SSSD." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:325 sssd-ad.5.xml:1361 +#: sssd-ipa.5.xml:320 sssd-ad.5.xml:1354 msgid "" "Please note that this option will be only used in fallback attempt when " "previous attempt using autodetected settings failed or when DNS-over-TLS is " "enabled." msgstr "" -"Observera att detta alternativ endast kommer att användas som reservlösning " -"när tidigare försök med automatiskt identifierade inställningar misslyckats " +"Observera att alternativet endast används vid ett reservförsök när ett " +"tidigare försök med automatiskt identifierade inställningar har misslyckats " "eller när DNS-over-TLS är aktiverat." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:331 sssd-ad.5.xml:1367 +#: sssd-ipa.5.xml:326 sssd-ad.5.xml:1360 msgid "Default: None (let nsupdate choose the server)" -msgstr "Standard: Ingen (låt nsupdate välja servern)" +msgstr "Standard: None (låt nsupdate välja server)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:337 sssd-ad.5.xml:1373 +#: sssd-ipa.5.xml:332 sssd-ad.5.xml:1366 msgid "dyndns_update_per_family (boolean)" -msgstr "dyndns_update_per_family (boolean)" +msgstr "dyndns_update_per_family (boolesk)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:340 sssd-ad.5.xml:1376 +#: sssd-ipa.5.xml:335 sssd-ad.5.xml:1369 msgid "" "DNS update is by default performed in two steps - IPv4 update and then IPv6 " "update. In some cases it might be desirable to perform IPv4 and IPv6 update " "in single step." msgstr "" -"DNS-uppdateringar utförs som standard i två steg – IPv4-uppdatering och " -"sedan IPv6-uppdatering. I några fall kan det vara önskvärt att utföra IPv4- " -"och IPv6-uppdateringar i ett enda steg." +"DNS-uppdatering utförs som standard i två steg: först IPv4-uppdatering och " +"sedan IPv6-uppdatering. I vissa fall kan det vara önskvärt att utföra IPv4- " +"och IPv6-uppdateringen i ett enda steg." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:352 sssd-ad.5.xml:1388 +#: sssd-ipa.5.xml:347 sssd-ad.5.xml:1381 msgid "dyndns_dot_cacert (string)" msgstr "dyndns_dot_cacert (sträng)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:355 sssd-ad.5.xml:1391 +#: sssd-ipa.5.xml:350 sssd-ad.5.xml:1384 msgid "" "This option specifies the file of the certificate authorities certificates " "(in PEM format) in order to verify the remote server TLS certificate when " @@ -12484,28 +12963,28 @@ msgstr "" "format) för att verifiera fjärrserverns TLS-certifikat när DoT används." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:361 sssd-ad.5.xml:1397 +#: sssd-ipa.5.xml:356 sssd-ad.5.xml:1390 msgid "Default: None (use global certificate store)" -msgstr "Standard: Ingen (använd globalt certifikatlager)" +msgstr "Standard: None (använd globalt certifikatlager)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:367 sssd-ad.5.xml:1403 +#: sssd-ipa.5.xml:362 sssd-ad.5.xml:1396 msgid "dyndns_dot_cert (string)" msgstr "dyndns_dot_cert (sträng)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:370 sssd-ad.5.xml:1406 +#: sssd-ipa.5.xml:365 sssd-ad.5.xml:1399 msgid "" "This option sets the certificate(s) file for authentication for the DoT " "transport to the remote server. The certificate chain file is expected to be " "in PEM format." msgstr "" -"Det här alternativet ställer in certifikatfilen eller certifikatfilerna för " -"autentisering för DoT-transporten till fjärrservern. Certifikatkedjefilen " -"förväntas vara i PEM-format." +"Alternativet anger certifikatfilen eller certifikatfilerna för autentisering " +"av DoT-transporten till fjärrservern. Certifikatkedjefilen förväntas vara i " +"PEM-format." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:376 sssd-ad.5.xml:1412 +#: sssd-ipa.5.xml:371 sssd-ad.5.xml:1405 msgid "" "The <emphasis>dyndns_dot_cert</emphasis> and <emphasis>dyndns_dot_key</" "emphasis> options must be both set to achieve mutual TLS authentication." @@ -12515,17 +12994,17 @@ msgstr "" "autentisering ska fungera." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:381 sssd-ipa.5.xml:396 sssd-ad.5.xml:1417 sssd-ad.5.xml:1432 +#: sssd-ipa.5.xml:376 sssd-ipa.5.xml:391 sssd-ad.5.xml:1410 sssd-ad.5.xml:1425 msgid "Default: None (Do not use TLS authentication)" -msgstr "Standard: Ingen (Använd inte TLS-autentisering)" +msgstr "Standard: None (använd inte TLS-autentisering)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:387 sssd-ad.5.xml:1423 +#: sssd-ipa.5.xml:382 sssd-ad.5.xml:1416 msgid "dyndns_dot_key (string)" msgstr "dyndns_dot_key (sträng)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:390 sssd-ad.5.xml:1426 +#: sssd-ipa.5.xml:385 sssd-ad.5.xml:1419 msgid "" "This option sets the key file for authenticated encryption for the DoT " "transport to the remote server. The private key file is expected to be in " @@ -12536,279 +13015,281 @@ msgstr "" "PEM-format." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:402 +#: sssd-ipa.5.xml:397 msgid "ipa_access_order (string)" msgstr "ipa_access_order (sträng)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:409 +#: sssd-ipa.5.xml:404 msgid "<emphasis>expire</emphasis>: use IPA's account expiration policy." -msgstr "<emphasis>expire</emphasis>: använd IPA:s policy för konton som går ut." +msgstr "<emphasis>expire</emphasis>: använd IPA:s policy för kontoutgång." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:448 +#: sssd-ipa.5.xml:443 msgid "" "Please note that 'access_provider = ipa' must be set for this feature to " "work." msgstr "" -"Observera att ”access_provider = ipa” måste vara satt för att denna funktion " -"skall fungera." +"Observera att 'access_provider = ipa' måste vara angivet för att funktionen " +"ska fungera." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:455 +#: sssd-ipa.5.xml:450 msgid "ipa_deskprofile_search_base (string)" msgstr "ipa_deskprofile_search_base (sträng)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:458 +#: sssd-ipa.5.xml:453 msgid "" "Optional. Use the given string as search base for Desktop Profile related " "objects." msgstr "" -"Frivillig. Använd den givna strängen som sökbas för " -"skrivbordsprofilrelaterade objekt." +"Valfritt. Använd den angivna strängen som sökbas för objekt som är " +"relaterade till skrivbordsprofiler." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:462 sssd-ipa.5.xml:484 +#: sssd-ipa.5.xml:457 sssd-ipa.5.xml:479 msgid "Default: Use base DN" msgstr "Standard: använd bas-DN" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:468 +#: sssd-ipa.5.xml:463 msgid "ipa_subid_ranges_search_base (string)" msgstr "ipa_subid_ranges_search_base (sträng)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:471 +#: sssd-ipa.5.xml:466 msgid "Deprecated. Use ldap_subid_ranges_search_base instead." -msgstr "Föråldrad. Använd ldap_subid_ranges_search_base istället." +msgstr "Föråldrat. Använd ldap_subid_ranges_search_base i stället." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:477 +#: sssd-ipa.5.xml:472 msgid "ipa_hbac_search_base (string)" msgstr "ipa_hbac_search_base (sträng)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:480 +#: sssd-ipa.5.xml:475 msgid "Optional. Use the given string as search base for HBAC related objects." msgstr "" -"Frivillig. Använd den givna strängen som sökbas för HBAC-relaterade objekt." +"Valfritt. Använd den angivna strängen som sökbas för HBAC-relaterade objekt." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:490 +#: sssd-ipa.5.xml:485 msgid "ipa_host_search_base (string)" msgstr "ipa_host_search_base (sträng)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:493 +#: sssd-ipa.5.xml:488 msgid "Deprecated. Use ldap_host_search_base instead." -msgstr "Undanbedes. Använd ldap_host_search_base istället." +msgstr "Föråldrat. Använd ldap_host_search_base i stället." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:499 +#: sssd-ipa.5.xml:494 msgid "ipa_selinux_search_base (string)" msgstr "ipa_selinux_search_base (sträng)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:502 +#: sssd-ipa.5.xml:497 msgid "Optional. Use the given string as search base for SELinux user maps." msgstr "" -"Frivillig. Använd den givna strängen som en sökbas för SELinux-" -"användaröversättningar." +"Valfritt. Använd den angivna strängen som sökbas för SELinux-" +"användarmappningar." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:518 +#: sssd-ipa.5.xml:513 msgid "ipa_subdomains_search_base (string)" msgstr "ipa_subdomains_search_base (sträng)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:521 +#: sssd-ipa.5.xml:516 msgid "Optional. Use the given string as search base for trusted domains." -msgstr "" -"Frivillig. Använd den givna strängen som en sökbas för betrodda domäner." +msgstr "Valfritt. Använd den angivna strängen som sökbas för betrodda domäner." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:530 +#: sssd-ipa.5.xml:525 msgid "Default: the value of <emphasis>cn=trusts,%basedn</emphasis>" msgstr "Standard: värdet på <emphasis>cn=trusts,%basedn</emphasis>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:537 +#: sssd-ipa.5.xml:532 msgid "ipa_master_domain_search_base (string)" msgstr "ipa_master_domain_search_base (sträng)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:540 +#: sssd-ipa.5.xml:535 msgid "Optional. Use the given string as search base for master domain object." msgstr "" -"Frivillig. Använd den givna strängen som en sökbas för huvuddomänobjekt." +"Valfritt. Använd den angivna strängen som sökbas för huvuddomänobjektet." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:549 +#: sssd-ipa.5.xml:544 msgid "Default: the value of <emphasis>cn=ad,cn=etc,%basedn</emphasis>" msgstr "Standard: värdet av <emphasis>cn=ad,cn=etc,%basedn</emphasis>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:556 +#: sssd-ipa.5.xml:551 msgid "ipa_views_search_base (string)" msgstr "ipa_views_search_base (sträng)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:559 +#: sssd-ipa.5.xml:554 msgid "Optional. Use the given string as search base for views containers." -msgstr "Frivillig. Använd den givna strängen som en sökbas för vybehållare." +msgstr "" +"Valfritt. Använd den angivna strängen som sökbas för behållare för vyer." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:568 +#: sssd-ipa.5.xml:563 msgid "Default: the value of <emphasis>cn=views,cn=accounts,%basedn</emphasis>" msgstr "Standard: värdet av <emphasis>cn=views,cn=accounts,%basedn</emphasis>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:578 +#: sssd-ipa.5.xml:573 msgid "" "The name of the Kerberos realm. This is optional and defaults to the value " "of <quote>ipa_domain</quote>." msgstr "" -"Namnet på Kerberos-riket. Detta är frivilligt och som standard blir det " -"värdet av <quote>ipa_domain</quote>." +"Namnet på Kerberos-realmet. Detta är valfritt och är som standard värdet för " +"<quote>ipa_domain</quote>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:582 +#: sssd-ipa.5.xml:577 msgid "" "The name of the Kerberos realm has a special meaning in IPA - it is " "converted into the base DN to use for performing LDAP operations." msgstr "" -"Namnet på Kerberos-riket har en speciell betydelse i IPA – det konverteras " -"till bas-DN:en för att användas när LDAP-operationer utförs." +"Namnet på Kerberos-realmet har en särskild betydelse i IPA: det konverteras " +"till den bas-DN som används för LDAP-åtgärder." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:590 sssd-ad.5.xml:1441 +#: sssd-ipa.5.xml:585 sssd-ad.5.xml:1434 msgid "krb5_confd_path (string)" msgstr "krb5_confd_path (sträng)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:593 sssd-ad.5.xml:1444 +#: sssd-ipa.5.xml:588 sssd-ad.5.xml:1437 msgid "" "Absolute path of a directory where SSSD should place Kerberos configuration " "snippets." msgstr "" -"Absolut sökväg till en katalog där SSSD skall placera konfigurationsstycken " -"för Kerberos." +"Absolut sökväg till en katalog där SSSD ska placera Kerberos-" +"konfigurationsfragment." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:597 sssd-ad.5.xml:1448 +#: sssd-ipa.5.xml:592 sssd-ad.5.xml:1441 msgid "" "To disable the creation of the configuration snippets set the parameter to " "'none'." msgstr "" -"För att förhindra att konfigurationsstycken skapas, sätt parametern till ”" -"none”." +"Ange parametern som 'none' för att inaktivera skapandet av " +"konfigurationsfragment." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:601 sssd-ad.5.xml:1452 +#: sssd-ipa.5.xml:596 sssd-ad.5.xml:1445 msgid "" "Default: not set (krb5.include.d subdirectory of SSSD's pubconf directory)" msgstr "" -"Standard: inte satt (underkatalogen krb5.include.d till SSSD:s pubconf-" +"Standard: inte angivet (underkatalogen krb5.include.d i SSSD:s pubconf-" "katalog)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:608 +#: sssd-ipa.5.xml:603 msgid "ipa_deskprofile_refresh (integer)" msgstr "ipa_deskprofile_refresh (heltal)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:611 +#: sssd-ipa.5.xml:606 msgid "" "The amount of time between lookups of the Desktop Profile rules against the " "IPA server. This will reduce the latency and load on the IPA server if there " "are many desktop profiles requests made in a short period." msgstr "" -"Tiden mellan uppslagningar av skrivbordsprofilsregler mot IPA-servern. " -"Detta kommer reducera tidsfördröjningen och lasten på IPA-servern om det " -"görs många begäranden om skrivbordsprofiler under en kort tid." +"Tiden mellan uppslagningar av skrivbordsprofilsregler på IPA-servern. Detta " +"minskar fördröjningen och belastningen på IPA-servern om många begäranden om " +"skrivbordsprofiler görs under en kort period." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:618 sssd-ipa.5.xml:648 sssd-ipa.5.xml:664 sssd-ad.5.xml:600 +#: sssd-ipa.5.xml:613 sssd-ipa.5.xml:643 sssd-ipa.5.xml:659 sssd-ad.5.xml:600 msgid "Default: 5 (seconds)" msgstr "Standard: 5 (sekunder)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:624 +#: sssd-ipa.5.xml:619 msgid "ipa_deskprofile_request_interval (integer)" msgstr "ipa_deskprofile_request_interval (heltal)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:627 +#: sssd-ipa.5.xml:622 msgid "" "The amount of time between lookups of the Desktop Profile rules against the " "IPA server in case the last request did not return any rule." msgstr "" -"Tiden mellan uppslagningar av skrivbordsprofilsregler mot IPA-servern ifall " -"den senaste förfrågan inte returnerade någon regel." +"Tiden mellan uppslagningar av skrivbordsprofilsregler på IPA-servern om den " +"senaste begäran inte returnerade någon regel." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:632 +#: sssd-ipa.5.xml:627 msgid "Default: 60 (minutes)" msgstr "Standard: 60 (minuter)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:638 +#: sssd-ipa.5.xml:633 msgid "ipa_hbac_refresh (integer)" msgstr "ipa_hbac_refresh (heltal)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:641 +#: sssd-ipa.5.xml:636 msgid "" "The amount of time between lookups of the HBAC rules against the IPA server. " "This will reduce the latency and load on the IPA server if there are many " "access-control requests made in a short period." msgstr "" -"Tiden mellan uppslagningar av HBAC-regler mot IPA-servern. Detta kommer " -"reducera tidsfördröjningen och lasten på IPA-servern om det görs många " -"begäranden om åtkomstkontroll under en kort tid." +"Tiden mellan uppslagningar av HBAC-regler på IPA-servern. Detta minskar " +"fördröjningen och belastningen på IPA-servern om många begäranden om " +"åtkomststyrning görs under en kort period." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:654 -msgid "ipa_hbac_selinux (integer)" -msgstr "ipa_hbac_selinux (heltal)" +#: sssd-ipa.5.xml:649 +#, fuzzy +#| msgid "ipa_hbac_refresh (integer)" +msgid "ipa_selinux_refresh (integer)" +msgstr "ipa_hbac_refresh (heltal)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:657 +#: sssd-ipa.5.xml:652 msgid "" "The amount of time between lookups of the SELinux maps against the IPA " "server. This will reduce the latency and load on the IPA server if there are " "many user login requests made in a short period." msgstr "" -"Tiden mellan uppslagningar av SELinux-översättningar mot IPA-servern. Detta " -"kommer reducera tidsfördröjningen och lasten på IPA-servern om det görs " -"många begäranden om användarinloggningar under en kort tid." +"Tiden mellan uppslagningar av SELinux-mappningar på IPA-servern. Detta " +"minskar fördröjningen och belastningen på IPA-servern om många begäranden om " +"användarinloggning görs under en kort period." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:670 +#: sssd-ipa.5.xml:665 msgid "ipa_server_mode (boolean)" -msgstr "ipa_server_mode (boolean)" +msgstr "ipa_server_mode (boolesk)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:673 +#: sssd-ipa.5.xml:668 msgid "" "This option will be set by the IPA installer (ipa-server-install) " "automatically and denotes if SSSD is running on an IPA server or not." msgstr "" -"Detta alternativ sätts automatiskt av IPA-installeraren (ipa-server-install) " -"och markerar om SSSD kör på en IPA-server eller inte." +"Det här alternativet anges automatiskt av IPA-installeraren (ipa-server-" +"install) och anger om SSSD körs på en IPA-server." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:678 +#: sssd-ipa.5.xml:673 msgid "" "On an IPA server SSSD will lookup users and groups from trusted domains " "directly while on a client it will ask an IPA server." msgstr "" -"På en IPA-server kommer SSSD slå upp användare och grupper från betrodda " -"domäner direkt medan på en klient kommer den att fråga en IPA-server." +"På en IPA-server slår SSSD upp användare och grupper från betrodda domäner " +"direkt, medan den på en klient frågar en IPA-server." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:683 +#: sssd-ipa.5.xml:678 msgid "" "NOTE: There are currently some assumptions that must be met when SSSD is " "running on an IPA server." @@ -12817,72 +13298,72 @@ msgstr "" "kör på en IPA-server." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:688 +#: sssd-ipa.5.xml:683 msgid "" "The <quote>ipa_server</quote> option must be configured to point to the IPA " "server itself. This is already the default set by the IPA installer, so no " "manual change is required." msgstr "" -"Alternativet <quote>ipa_server</quote> måste konfigureras till att peka på " -"själva IPA-servern. Detta är redan standardvärdet som sätts av IPA-" -"installeraren, så det behövs inga manuella ändringar." +"Alternativet <quote>ipa_server</quote> måste konfigureras för att peka på " +"IPA-servern själv. Detta är redan standardvärdet som IPA-installeraren " +"anger, så ingen manuell ändring krävs." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:697 +#: sssd-ipa.5.xml:692 msgid "" "The <quote>full_name_format</quote> option must not be tweaked to only print " "short names for users from trusted domains." msgstr "" -"Alternativet <quote>full_name_format</quote> får inte ändras till att bara " -"skriva korta namn på användare från betrodda domäner." +"Alternativet <quote>full_name_format</quote> får inte justeras till att " +"endast skriva ut korta namn för användare från betrodda domäner." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:712 +#: sssd-ipa.5.xml:707 msgid "ipa_automount_location (string)" msgstr "ipa_automount_location (sträng)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:715 +#: sssd-ipa.5.xml:710 msgid "The automounter location this IPA client will be using" -msgstr "Automonteringsplatsen denna IPA-klient kommer använda" +msgstr "Platsen för automatisk montering som IPA-klienten använder" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:718 +#: sssd-ipa.5.xml:713 msgid "Default: The location named \"default\"" -msgstr "Standard: platsen som heter ”default”" +msgstr "Standard: Platsen med namnet \"default\"" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd-ipa.5.xml:726 +#: sssd-ipa.5.xml:721 msgid "VIEWS AND OVERRIDES" msgstr "VYER OCH ÅSIDOSÄTTANDEN" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:735 +#: sssd-ipa.5.xml:730 msgid "ipa_view_class (string)" msgstr "ipa_view_class (sträng)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:738 +#: sssd-ipa.5.xml:733 msgid "Objectclass of the view container." msgstr "Objektklass för vybehållaren." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:741 +#: sssd-ipa.5.xml:736 msgid "Default: nsContainer" msgstr "Standard: nsContainer" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:747 +#: sssd-ipa.5.xml:742 msgid "ipa_view_name (string)" msgstr "ipa_view_name (sträng)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:750 +#: sssd-ipa.5.xml:745 msgid "Name of the attribute holding the name of the view." -msgstr "Namn på attributet som har namnet på vyn." +msgstr "Namnet på attributet som innehåller namnet på vyn." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:754 sssd-ldap-attributes.5.xml:496 +#: sssd-ipa.5.xml:749 sssd-ldap-attributes.5.xml:496 #: sssd-ldap-attributes.5.xml:832 sssd-ldap-attributes.5.xml:913 #: sssd-ldap-attributes.5.xml:1010 sssd-ldap-attributes.5.xml:1068 #: sssd-ldap-attributes.5.xml:1226 sssd-ldap-attributes.5.xml:1271 @@ -12890,27 +13371,27 @@ msgid "Default: cn" msgstr "Standard: cn" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:760 +#: sssd-ipa.5.xml:755 msgid "ipa_override_object_class (string)" msgstr "ipa_override_object_class (sträng)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:763 +#: sssd-ipa.5.xml:758 msgid "Objectclass of the override objects." -msgstr "Objektklass för åsidosättande objekt." +msgstr "Objektklass för åsidosättningsobjekten." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:766 +#: sssd-ipa.5.xml:761 msgid "Default: ipaOverrideAnchor" msgstr "Standard: ipaOverrideAnchor" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:772 +#: sssd-ipa.5.xml:767 msgid "ipa_anchor_uuid (string)" msgstr "ipa_anchor_uuid (sträng)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:775 +#: sssd-ipa.5.xml:770 msgid "" "Name of the attribute containing the reference to the original object in a " "remote domain." @@ -12919,107 +13400,107 @@ msgstr "" "fjärrdomän." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:779 +#: sssd-ipa.5.xml:774 msgid "Default: ipaAnchorUUID" msgstr "Standard: ipaAnchorUUID" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:785 +#: sssd-ipa.5.xml:780 msgid "ipa_user_override_object_class (string)" msgstr "ipa_user_override_object_class (sträng)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:788 +#: sssd-ipa.5.xml:783 msgid "" "Name of the objectclass for user overrides. It is used to determine if the " "found override object is related to a user or a group." msgstr "" -"Namn på objektklassen för användaråsidosättanden. Det används för att " -"avgöra om det funna åsidosättande objektet är relaterat till en användare " -"eller en grupp." +"Namnet på objektklassen för åsidosättningar av användare. Den används för " +"att avgöra om det hittade åsidosättningsobjektet gäller en användare eller " +"en grupp." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:793 +#: sssd-ipa.5.xml:788 msgid "User overrides can contain attributes given by" -msgstr "Användaråsidosättanden kan innehålla attribut givna av" +msgstr "Åsidosättningar av användare kan innehålla attribut som anges av" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:796 +#: sssd-ipa.5.xml:791 msgid "ldap_user_name" msgstr "ldap_user_name" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:799 +#: sssd-ipa.5.xml:794 msgid "ldap_user_uid_number" msgstr "ldap_user_uid_number" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:802 +#: sssd-ipa.5.xml:797 msgid "ldap_user_gid_number" msgstr "ldap_user_gid_number" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:805 +#: sssd-ipa.5.xml:800 msgid "ldap_user_gecos" msgstr "ldap_user_gecos" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:808 +#: sssd-ipa.5.xml:803 msgid "ldap_user_home_directory" msgstr "ldap_user_home_directory" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:811 +#: sssd-ipa.5.xml:806 msgid "ldap_user_shell" msgstr "ldap_user_shell" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:814 +#: sssd-ipa.5.xml:809 msgid "ldap_user_ssh_public_key" msgstr "ldap_user_ssh_public_key" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:819 +#: sssd-ipa.5.xml:814 msgid "Default: ipaUserOverride" msgstr "Standard: ipaUserOverride" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:825 +#: sssd-ipa.5.xml:820 msgid "ipa_group_override_object_class (string)" msgstr "ipa_group_override_object_class (sträng)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:828 +#: sssd-ipa.5.xml:823 msgid "" "Name of the objectclass for group overrides. It is used to determine if the " "found override object is related to a user or a group." msgstr "" -"Namn på objektklassen för gruppåsidosättanden. Det används för att avgöra " -"om det funna åsidosättandeobjektet är relaterat till en användare eller en " +"Namnet på objektklassen för åsidosättningar av grupper. Den används för att " +"avgöra om det hittade åsidosättningsobjektet gäller en användare eller en " "grupp." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:833 +#: sssd-ipa.5.xml:828 msgid "Group overrides can contain attributes given by" -msgstr "Gruppåsidosättanden kan innehålla attribut givna av" +msgstr "Åsidosättningar av grupper kan innehålla attribut som anges av" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:836 +#: sssd-ipa.5.xml:831 msgid "ldap_group_name" msgstr "ldap_group_name" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:839 +#: sssd-ipa.5.xml:834 msgid "ldap_group_gid_number" msgstr "ldap_group_gid_number" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:844 +#: sssd-ipa.5.xml:839 msgid "Default: ipaGroupOverride" msgstr "Standard: ipaGroupOverride" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:728 +#: sssd-ipa.5.xml:723 msgid "" "SSSD can handle views and overrides which are offered by FreeIPA 4.1 and " "later version. Since all paths and objectclasses are fixed on the server " @@ -13027,39 +13508,39 @@ msgid "" "related options are listed here with their default values. <placeholder " "type=\"variablelist\" id=\"0\"/>" msgstr "" -"SSSD kan hantera vyer och åsidosättanden som erbjuds av FreeIPA 4.1 och " -"senare versioner. Eftersom alla sökvägar och objektklasser är fasta på " -"serversidan finns det egentligen inget behov av att konfigurera något. För " -"fullständighets skull är de tillhörande alternativen listade här med sina " -"standardvärden. <placeholder type=\"variablelist\" id=\"0\"/>" +"SSSD kan hantera vyer och åsidosättningar som erbjuds av FreeIPA 4.1 och " +"senare versioner. Eftersom alla sökvägar och objektklasser är fasta på " +"serversidan finns det i praktiken inget behov av att konfigurera något. För " +"fullständighetens skull listas de relaterade alternativen här med sina " +"standardvärden. <placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd-ipa.5.xml:856 +#: sssd-ipa.5.xml:851 msgid "SUBDOMAINS PROVIDER" msgstr "UNDERDOMÄNSLEVERANTÖR" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:858 +#: sssd-ipa.5.xml:853 msgid "" "The IPA subdomains provider behaves slightly differently if it is configured " "explicitly or implicitly." msgstr "" -"IPA-underdomänsleverantören beter sig något annorlunda om den konfigureras " -"explicit eller implicit." +"IPA-underdomänsleverantören beter sig något olika beroende på om den " +"konfigureras uttryckligen eller underförstått." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:862 +#: sssd-ipa.5.xml:857 msgid "" "If the option 'subdomains_provider = ipa' is found in the domain section of " "sssd.conf, the IPA subdomains provider is configured explicitly, and all " "subdomain requests are sent to the IPA server if necessary." msgstr "" -"Om alternativet ”subdomains_provider = ipa” finns i domänavsnittet i " -"sssd.conf konfigureras IPA-underdomänsleverantören explicit, och alla " -"begäranden av underdomäner skickas till IPA-servern om nödvändigt." +"Om alternativet 'subdomains_provider = ipa' finns i domänavsnittet i " +"sssd.conf konfigureras IPA-underdomänsleverantören uttryckligen, och alla " +"underdomänsbegäranden skickas vid behov till IPA-servern." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:868 +#: sssd-ipa.5.xml:863 msgid "" "If the option 'subdomains_provider' is not set in the domain section of " "sssd.conf but there is the option 'id_provider = ipa', the IPA subdomains " @@ -13069,21 +13550,21 @@ msgid "" "hour or after the IPA provider goes online, the subdomains provider is " "enabled again." msgstr "" -"Om alternativet ”subdomains_provider” inte är satt i domänavsnittet av " -"sssd.conf men alternativet ”id_provider = ipa” finns konfigureras IPA-" -"underdomänsleverantören implicit. I det fallet, om en underdomänsbegäran " -"misslyckas och indikerar att servern inte stödjer underdomäner, d.v.s. den " -"är inte konfigurerad för förtroenden, avaktiveras IPA-" -"underdomänsleverantören. Efter en timma eller efter att IPA-leverantören " -"blir uppkopplad aktiveras underdomänsleverantören igen." +"Om alternativet 'subdomains_provider' inte är angivet i domänavsnittet i " +"sssd.conf, men alternativet 'id_provider = ipa' finns, konfigureras IPA-" +"underdomänsleverantören underförstått. Om en underdomänsbegäran då " +"misslyckas och visar att servern inte stöder underdomäner, dvs. inte är " +"konfigurerad för förtroenden, inaktiveras IPA-underdomänsleverantören. Efter " +"en timme eller när IPA-leverantören ansluter igen aktiveras " +"underdomänsleverantören på nytt." #. type: Content of: <reference><refentry><refsect1><title> -#: sssd-ipa.5.xml:879 +#: sssd-ipa.5.xml:874 msgid "TRUSTED DOMAINS CONFIGURATION" msgstr "KONFIGURATION AV BETRODDA DOMÄNER" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-ipa.5.xml:887 +#: sssd-ipa.5.xml:882 #, no-wrap msgid "" "[domain/ipa.domain.com/ad.domain.com]\n" @@ -13093,7 +13574,7 @@ msgstr "" "ad_server = dc.ad.domain.com\n" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:881 +#: sssd-ipa.5.xml:876 msgid "" "Some configuration options can also be set for a trusted domain. A trusted " "domain configuration can be set using the trusted domain subsection as shown " @@ -13101,84 +13582,84 @@ msgid "" "option can be used in the parent domain. <placeholder " "type=\"programlisting\" id=\"0\"/>" msgstr "" -"Några konfigurationflaggor kan även sättas för betrodda domäner. En betrodd " -"domämns konfiguration kan sättas med den betrodda domänens undersektion som " -"visas i exemplet nedan. Alternativt kan flaggan <quote>subdomain_inherit</" -"quote> användas i föräldradomänen. <placeholder type=\"programlisting\" " +"Vissa konfigurationsalternativ kan även anges för en betrodd domän. En " +"konfiguration för en betrodd domän kan anges med underavsnittet för betrodda " +"domäner, som i exemplet nedan. Alternativt kan <quote>subdomain_inherit</" +"quote> användas i överordnad domän. <placeholder type=\"programlisting\" " "id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:892 +#: sssd-ipa.5.xml:887 msgid "" "For more details, see the <citerefentry> <refentrytitle>sssd.conf</" "refentrytitle> <manvolnum>5</manvolnum> </citerefentry> manual page." msgstr "" -"För fler detaljer, se manualsidan <citerefentry> <refentrytitle>sssd.conf</" -"refentrytitle> <manvolnum>5</manvolnum> </citerefentry>." +"Mer information finns på manualsidan <citerefentry> <refentrytitle>" +"sssd.conf</refentrytitle> <manvolnum>5</manvolnum> </citerefentry>." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:899 +#: sssd-ipa.5.xml:894 msgid "" "Different configuration options are tunable for a trusted domain depending " "on whether you are configuring SSSD on an IPA server or an IPA client." msgstr "" "Olika konfigurationsalternativ kan ställas in för en betrodd domän beroende " -"på huruvida man konfigurerar SSSD på en IPA-server eller en IPA-klient." +"på om SSSD konfigureras på en IPA-server eller en IPA-klient." #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd-ipa.5.xml:904 +#: sssd-ipa.5.xml:899 msgid "OPTIONS TUNABLE ON IPA MASTERS" msgstr "ALTERNATIV ATT STÄLLA IN PÅ IPA-MASTRAR" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:906 +#: sssd-ipa.5.xml:901 msgid "" "The following options can be set in a subdomain section on an IPA master:" msgstr "" "Följande alternativ kan sättas i ett underdomänsavsnitt på en IPA-master:" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:910 sssd-ipa.5.xml:950 +#: sssd-ipa.5.xml:905 sssd-ipa.5.xml:945 msgid "ad_server" msgstr "ad_server" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:913 +#: sssd-ipa.5.xml:908 msgid "ad_backup_server" msgstr "ad_backup_server" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:916 sssd-ipa.5.xml:953 +#: sssd-ipa.5.xml:911 sssd-ipa.5.xml:948 msgid "ad_site" msgstr "ad_site" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:919 +#: sssd-ipa.5.xml:914 msgid "ipa_server" msgstr "ipa_server" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:922 +#: sssd-ipa.5.xml:917 msgid "ipa_backup_server" msgstr "ipa_backup_server" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:925 +#: sssd-ipa.5.xml:920 msgid "ldap_search_base" msgstr "ldap_search_base" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:928 +#: sssd-ipa.5.xml:923 msgid "ldap_user_search_base" msgstr "ldap_user_search_base" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:931 +#: sssd-ipa.5.xml:926 msgid "ldap_group_search_base" msgstr "ldap_group_search_base" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:939 +#: sssd-ipa.5.xml:934 msgid "" "Options prefixed with 'ad_' or 'ipa_' only apply to their respective " "subdomain type." @@ -13187,12 +13668,12 @@ msgstr "" "underdomäntyp." #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd-ipa.5.xml:944 +#: sssd-ipa.5.xml:939 msgid "OPTIONS TUNABLE ON IPA CLIENTS" msgstr "ALTERNATIV ATT STÄLLA IN PÅ IPA-KLIENTER" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:946 +#: sssd-ipa.5.xml:941 msgid "" "The following options can be set in an AD subdomain section on an IPA client:" msgstr "" @@ -13200,16 +13681,16 @@ msgstr "" "klient:" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:958 +#: sssd-ipa.5.xml:953 msgid "" "Note that if both options are set, only <quote>ad_server</quote> is " "evaluated." msgstr "" -"Observera att om båda alternativen sätts evalueras endast <quote>ad_server</" -"quote>." +"Observera att endast <quote>ad_server</quote> utvärderas om båda " +"alternativen är angivna." #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:962 +#: sssd-ipa.5.xml:957 msgid "" "Since any request for a user or a group identity from a trusted domain " "triggered from an IPA client is resolved by the IPA server, the " @@ -13221,29 +13702,28 @@ msgid "" "<manvolnum>8</manvolnum> </citerefentry> manual page for more details on the " "Kerberos locator plugin." msgstr "" -"Eftersom alla begäranden om en användar- eller en gruppidentitet från en " -"betrodd domän startad från en IPA-klient löses upp av IPA-servern, påverkar " -"alternativen <quote>ad_server</quote> och <quote>ad_site</quote> bara vilken " -"AD DC autentiseringen kommer utföras emot. I synnerhet kommer adresserna " -"som löses upp från dessa listor att skrivas till <quote>kdcinfo</quote>-" -"filer som läses av Kerberos-lokaliseringsinsticksmodulen. För fler detaljer " -"om Kerberos-lokaliseringsinsticksmodulen hänvisas till manualsidan " -"<citerefentry> <refentrytitle>sssd_krb5_locator_plugin</refentrytitle> " -"<manvolnum>8</manvolnum> </citerefentry>." +"Eftersom IPA-servern löser varje begäran om en användar- eller " +"gruppidentitet från en betrodd domän som initieras från en IPA-klient, " +"påverkar alternativen <quote>ad_server</quote> och <quote>ad_site</quote> " +"endast vilken AD DC autentiseringen utförs mot. Adresserna som löses från " +"dessa listor skrivs särskilt till <quote>kdcinfo</quote>-filer som Kerberos-" +"lokaliseringsinsticksmodulen läser. Mer information om insticksmodulen finns " +"på manualsidan <citerefentry> <refentrytitle>sssd_krb5_locator_plugin</" +"refentrytitle> <manvolnum>8</manvolnum> </citerefentry>." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:986 +#: sssd-ipa.5.xml:981 msgid "" "The following example assumes that SSSD is correctly configured and " "example.com is one of the domains in the <replaceable>[sssd]</replaceable> " "section. This examples shows only the ipa provider-specific options." msgstr "" -"Följande exempel antar att SSSD är korrekt konfigurerat och att exempel.se " -"är en av domänerna i avsnittet <replaceable>[sssd]</replaceable>. Dessa " -"exempel visar endast alternativ som är specifika för leverantören ipa." +"Följande exempel förutsätter att SSSD är korrekt konfigurerat och att " +"example.com är en av domänerna i avsnittet <replaceable>[sssd]</replaceable>" +". Exemplet visar endast alternativ som är specifika för IPA-leverantören." #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-ipa.5.xml:993 +#: sssd-ipa.5.xml:988 #, no-wrap msgid "" "[domain/example.com]\n" @@ -13251,10 +13731,10 @@ msgid "" "ipa_server = ipaserver.example.com\n" "ipa_hostname = myhost.example.com\n" msgstr "" -"[domain/exempel.se]\n" +"[domain/example.com]\n" "id_provider = ipa\n" -"ipa_server = ipaserver.exempel.se\n" -"ipa_hostname = minvärd.exempel.se\n" +"ipa_server = ipaserver.example.com\n" +"ipa_hostname = myhost.example.com\n" #. type: Content of: <reference><refentry><refnamediv><refname> #: sssd-ad.5.xml:10 sssd-ad.5.xml:16 @@ -13275,11 +13755,11 @@ msgid "" "FORMAT</quote> section of the <citerefentry> <refentrytitle>sssd.conf</" "refentrytitle> <manvolnum>5</manvolnum> </citerefentry> manual page." msgstr "" -"Denna manualsida beskriver konfigurationen av leverantören AD till " +"Den här manualsidan beskriver konfigurationen av AD-leverantören för " "<citerefentry> <refentrytitle>sssd</refentrytitle> <manvolnum>8</manvolnum> " -"</citerefentry>. För en detaljerad referens om syntaxen, se avsnittet " -"<quote>FILFORMAT</quote> i manualsidan <citerefentry> <refentrytitle>" -"sssd.conf</refentrytitle> <manvolnum>5</manvolnum> </citerefentry>." +"</citerefentry>. En detaljerad syntaxreferens finns i avsnittet <quote>" +"FILFORMAT</quote> på manualsidan <citerefentry> <refentrytitle>sssd.conf</" +"refentrytitle> <manvolnum>5</manvolnum> </citerefentry>." #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ad.5.xml:36 @@ -13290,11 +13770,12 @@ msgid "" "channel, SSL/TLS options should not be used with the AD provider and will be " "superseded by Kerberos usage." msgstr "" -"Leverantören AD är en bakände som används för att ansluta till en Active " -"Directory-server. Leverantören kräver att maskinen läggs in i AD-domänen " -"och att en keytab är tillgänglig. Bakändekommunikationen sker över en " -"GSSAPI-krypterad kanal, SSL/TLS-alternativ skall inte användas tillsammans " -"med AD-leverantören och kommer ersättas av Kerberos-användning." +"AD-leverantören är en bakomliggande komponent som används för att ansluta " +"till en Active Directory-server. Leverantören kräver att datorn har " +"anslutits till AD-domänen och att en keytab finns tillgänglig. Kommunikation " +"med den bakomliggande komponenten sker över en GSSAPI-krypterad kanal. SSL/" +"TLS-alternativ ska inte användas med AD-leverantören och ersätts av " +"användning av Kerberos." #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ad.5.xml:44 @@ -13302,8 +13783,8 @@ msgid "" "The AD provider supports connecting to Active Directory 2008 R2 or later. " "Earlier versions may work, but are unsupported." msgstr "" -"AD-leverantören stödjer anslutning till Active Directory 2008 R2 eller " -"senare. Tidigare versioner kan fungera, men stödjs inte." +"AD-leverantören stöder anslutning till Active Directory 2008 R2 eller " +"senare. Tidigare versioner kan fungera, men stöds inte." #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ad.5.xml:48 @@ -13313,10 +13794,10 @@ msgid "" "recognized. In addition servers from trusted domains are always auto-" "discovered." msgstr "" -"AD-leverantören kan användas för att få användarinformation och autentisera " -"användare från betrodda domäner. För närvarande känns endast betrodda " -"domäner i samma skog igen. Dessutom automatupptäcks alltid servrar från " -"betrodda domäner." +"AD-leverantören kan användas för att hämta användarinformation och " +"autentisera användare från betrodda domäner. För närvarande identifieras " +"endast betrodda domäner i samma skog. Dessutom identifieras alltid servrar " +"från betrodda domäner automatiskt." #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ad.5.xml:54 @@ -13330,14 +13811,14 @@ msgid "" "exceptions. However, it is neither necessary nor recommended to set these " "options." msgstr "" -"AD-leverantören gör att SSSD kan använda identitetsleverantören " +"AD-leverantören gör det möjligt för SSSD att använda identitetsleverantören " "<citerefentry> <refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</" "manvolnum> </citerefentry> och autentiseringsleverantören <citerefentry> " "<refentrytitle>sssd-krb5</refentrytitle> <manvolnum>5</manvolnum> </" -"citerefentry> med optimeringar för Active Directory-miljöer. AD-" -"leverantören tar samma alternativ som används av leverantörerna sssd-ldap " -"och sssd-krb5 med några undantag. Dock är det varken nödvändigt eller " -"lämpligt att sätta dessa alternativ." +"citerefentry> med optimeringar för Active Directory-miljöer. AD-leverantören " +"accepterar, med några undantag, samma alternativ som leverantörerna sssd-" +"ldap och sssd-krb5 använder. Det är dock varken nödvändigt eller " +"rekommenderat att ange alternativen." #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ad.5.xml:69 @@ -13346,9 +13827,9 @@ msgid "" "default options with some exceptions, the differences are listed in the " "<quote>MODIFIED DEFAULT OPTIONS</quote> section." msgstr "" -"AD-leverantören kopierar i huvudsak standardalternativen för de " -"traditionella leverantörerna ldap och krb5 med några undantag. Skillnaderna " -"listas i avsnittet <quote>ÄNDRADE STANDARDINSTÄLLNINGAR</quote>." +"AD-leverantören använder huvudsakligen standardalternativen för de " +"traditionella leverantörerna ldap och krb5, med några undantag. Skillnaderna " +"listas i avsnittet <quote>ÄNDRADE STANDARDALTERNATIV</quote>." #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ad.5.xml:74 @@ -13369,8 +13850,7 @@ msgid "" "quote>." msgstr "" "Om <quote>auth_provider=ad</quote> eller <quote>access_provider=ad</quote> " -"konfigureras i sssd.conf måste id-leverantören också sättas till <quote>ad</" -"quote>." +"konfigureras i sssd.conf måste även id_provider anges som <quote>ad</quote>." #. type: Content of: <reference><refentry><refsect1><para><programlisting> #: sssd-ad.5.xml:91 @@ -13401,21 +13881,20 @@ msgid "" "present in the Global Catalog, the non-replicated attributes are currently " "not read from the LDAP port." msgstr "" -"Som standard kommer AD-leverantören översätta AID- och GID-värden från " -"parametern objectSID i Active Directory. För detaljer om detta se avsnittet " -"<quote>ID-ÖVERSÄTTNING</quote> nedan. Om du vill avaktivera ID-översättning " -"och istället lita på POSIX-attribut definierade i Active Directory skall du " -"sätta <placeholder type=\"programlisting\" id=\"0\"/>. Om POSIX-attribut " -"skall användas rekommenderas det av prestandaskäl att attributen även " -"replikeras till den globala katalogen. Om POSIX-attribut replikeras kommer " -"SSSD försöka att hitta domänen för den begärda numeriska ID:n med hjälp av " -"den globala katalogen och endast söka i den domänen. Om POSIX-attribut " -"däremot inte replikeras till den globala katalogen måste SSSD söka i alla " -"domänerna i skogen sekventiellt. Observera att alternativet <quote>" -"cache_first</quote> också kan vara till hjälp för att snabba upp domänlösa " -"sökningar. Observera att om endast en delmängd av POSIX-attributen finns i " -"den globala katalogen läses för närvarande inte de attribut som inte " -"replikeras från LDAP-porten." +"Som standard mappar AD-leverantören UID- och GID-värden från parametern " +"objectSID i Active Directory. Mer information finns i avsnittet <quote>ID-" +"MAPPNING</quote> nedan. Om du vill inaktivera ID-mappning och i stället " +"använda POSIX-attribut som definieras i Active Directory ska du ange " +"<placeholder type=\"programlisting\" id=\"0\"/> Om POSIX-attribut används " +"rekommenderas det av prestandaskäl att attributen även replikeras till den " +"globala katalogen. Om POSIX-attribut replikeras försöker SSSD hitta domänen " +"för ett begärt numeriskt ID med hjälp av den globala katalogen och söker " +"endast i den domänen. Om POSIX-attribut däremot inte replikeras till den " +"globala katalogen måste SSSD söka igenom alla domäner i skogen sekventiellt. " +"Alternativet <quote>cache_first</quote> kan också bidra till snabbare " +"domänlösa sökningar. Om endast en delmängd av POSIX-attributen finns i den " +"globala katalogen läses de attribut som inte replikerats för närvarande inte " +"från LDAP-porten." #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ad.5.xml:108 @@ -13424,9 +13903,9 @@ msgid "" "insensitive in the AD provider for compatibility with Active Directory's " "LDAP implementation." msgstr "" -"Användare, grupper och andra enheter som servas av SSSD behandlas alltid som " -"skiftlägesokänsliga i AD-leverantören för kompatibilitet med Active " -"Directorys LDAP-implementation." +"Användare, grupper och andra entiteter som tillhandahålls av SSSD behandlas " +"alltid som skiftlägesokänsliga av AD-leverantören för kompatibilitet med " +"Active Directorys LDAP-implementation." #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ad.5.xml:113 @@ -13436,10 +13915,10 @@ msgid "" "windows-server/identity/ad-ds/manage/understand-security-groups\"> Active " "Directory security groups</ulink>" msgstr "" -"SSSD slår endast up Active Directory Security Groups. För mer information om " -"AD-grupptyper se: <ulink url=\"https://docs.microsoft.com/en-us/windows-" +"SSSD löser endast upp Active Directory-säkerhetsgrupper. Mer information om " +"AD-grupptyper finns i: <ulink url=\"https://docs.microsoft.com/en-us/windows-" "server/identity/ad-ds/manage/understand-security-groups\">Active Directory " -"security grouips</ulink>" +"security groups</ulink>" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ad.5.xml:120 @@ -13451,11 +13930,12 @@ msgid "" "assignment which can be seen in the PAC of the Kerberos ticket of a user " "issued by Active Directory." msgstr "" -"SSSD filtrerar ut domänlokala grupper från fjärrdomäner i AD-skogen. Som " -"standard filtreras de ut t.ex. när man följer en nästad grupphierarki i " -"fjärrdomäner för att de inte är giltiga i den lokala domänen. Detta görs för " -"att stämma med Active Directorys gruppmedlemskapstilldelning vilken kan ses " -"i Kerberosbiljettens PAC för en användare utgiven av Active Directory." +"SSSD filtrerar bort Domain Local-grupper från fjärrdomäner i AD-skogen. Som " +"standard filtreras de bort, till exempel när en nästlad grupphierarki följs " +"i fjärrdomäner, eftersom de inte är giltiga i den lokala domänen. Det görs " +"för att överensstämma med Active Directorys tilldelning av gruppmedlemskap, " +"som kan ses i PAC för den Kerberos-biljett som Active Directory utfärdar " +"till en användare." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:138 @@ -13477,8 +13957,8 @@ msgid "" "For proper operation, this option should be specified as the lower-case " "version of the long version of the Active Directory domain." msgstr "" -"För att fungera ordentligt skall detta alternativ anges som den gemena " -"versionen av den långa versionen av Active Directorys domän." +"För korrekt funktion ska det här alternativet anges som gemen version av " +"Active Directory-domänens långa namn." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:151 @@ -13486,8 +13966,8 @@ msgid "" "The short domain name (also known as the NetBIOS or the flat name) is " "autodetected by the SSSD." msgstr "" -"Det korta domännamnet (även känt som NetBIOS-namnet eller det platta namnet) " -"detekteras automatiskt av SSSD." +"Det korta domännamnet (även kallat NetBIOS-namnet eller det platta namnet) " +"identifieras automatiskt av SSSD." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:158 @@ -13501,10 +13981,9 @@ msgid "" "SSSD will ignore any domains not listed in this option. If left unset, all " "discovered domains from the AD forest will be available." msgstr "" -"En kommaseparerad lista av aktiverade Active Directory-domäner. Om det " -"tillhandahålls kommer SSSD ignorera eventuella domäner som inte räknas upp i " -"detta alternativ. Om det lämnas osatt kommer alla upptäckta domäner från AD-" -"skogen vara tillgängliga." +"En kommaseparerad lista med aktiverade Active Directory-domäner. Om listan " +"anges ignorerar SSSD alla domäner som inte finns i alternativet. Om den " +"lämnas oangiven blir alla identifierade domäner i AD-skogen tillgängliga." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:168 @@ -13514,10 +13993,9 @@ msgid "" "are not trusted. If ad_enabled_domains is set, SSSD will try to enable all " "listed domains." msgstr "" -"När den letar efter domänerna kommer SSSD filtrera ut några domäner vars " -"flaggor eller attribut indikerar att de inte tillhör den lokala skogen eller " -"inte är betrodda. Om ad_enabled_domains är satt kommer SSSD försöka aktivera " -"alla listade domäner." +"När domäner identifieras filtrerar SSSD bort domäner vars flaggor eller " +"attribut visar att de inte tillhör den lokala skogen eller inte är betrodda. " +"Om ad_enabled_domains är angivet försöker SSSD aktivera alla listade domäner." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> #: sssd-ad.5.xml:179 @@ -13526,7 +14004,7 @@ msgid "" "ad_enabled_domains = sales.example.com, eng.example.com\n" " " msgstr "" -"ad_enabled_domains = marknad.exempel.se, tekn.exempel.se\n" +"ad_enabled_domains = sales.example.com, eng.example.com\n" " " #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> @@ -13536,9 +14014,9 @@ msgid "" "the fully qualified domain name of the Active Directory domain. For example: " "<placeholder type=\"programlisting\" id=\"0\"/>" msgstr "" -"För att fungera ordentligt bör detta alternativ anges helt i gemener och som " -"det fullständigt kvalificerade namnet på Active Directory-domänen. Till " -"exempel: <placeholder type=\"programlisting\" id=\"0\"/>" +"För korrekt funktion måste det här alternativet anges helt med gemener och " +"som det fullständigt kvalificerade domännamnet för Active Directory-domänen. " +"Till exempel: <placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:183 @@ -13546,8 +14024,8 @@ msgid "" "The short domain name (also known as the NetBIOS or the flat name) will be " "autodetected by SSSD." msgstr "" -"Det korta domännamnet (även känt som NetBIOS-namnet eller det platta namnet) " -"kommer detekteras automatiskt av SSSD." +"Det korta domännamnet (även kallat NetBIOS-namnet eller det platta namnet) " +"identifieras automatiskt av SSSD." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:193 @@ -13561,9 +14039,9 @@ msgid "" "connect in order of preference. For more information on failover and server " "redundancy, see the <quote>FAILOVER</quote> section." msgstr "" -"Den kommaseparerade listan av värdnamn till AD-servrar till vilka SSSD skall " -"ansluta i prioritetsordning. För mer information om reserver och " -"serverredundans se avsnittet <quote>RESERVER</quote>." +"Den kommaseparerade listan med värdnamn för AD-servrar som SSSD ska ansluta " +"till i prioritetsordning. Mer information om reservväxling och " +"serverredundans finns i avsnittet <quote>RESERVVÄXLING</quote>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:203 @@ -13571,8 +14049,9 @@ msgid "" "This is optional if autodiscovery is enabled. For more information on " "service discovery, refer to the <quote>SERVICE DISCOVERY</quote> section." msgstr "" -"Detta är frivilligt om automatupptäckt är aktiverat. För mer information om " -"tjänsteupptäckt se avsnittet <quote>TJÄNSTEUPPTÄCKT</quote>." +"Detta är valfritt om automatisk identifiering är aktiverad. Mer information " +"om tjänsteidentifiering finns i avsnittet <quote>TJÄNSTEIDENTIFIERING</quote>" +"." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:208 @@ -13580,8 +14059,8 @@ msgid "" "Note: Trusted domains will always auto-discover servers even if the primary " "server is explicitly defined in the ad_server option." msgstr "" -"Observera: betrodda domäner kommer alltid automatiskt upptäcka servrar även " -"om den primära servern definieras uttryckligen i alternativet ad_server." +"Observera: Betrodda domäner identifierar alltid servrar automatiskt, även om " +"den primära servern uttryckligen anges i alternativet ad_server." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:216 @@ -13596,10 +14075,10 @@ msgid "" "possible or the short name should be really used instead, set this parameter " "explicitly." msgstr "" -"Valfri. På maskiner där hostname(5) inte avspeglar det fullständigt " -"kvalificerade namnet kommer sssd försöka expandera det korta namnet. Om det " -"inte är möjligt eller det korta namnet verkligen skall användas istället, " -"sätt då denna parameter uttryckligen." +"Valfritt. På datorer där hostname(5) inte motsvarar det fullständigt " +"kvalificerade namnet försöker sssd utöka det korta namnet. Om detta inte är " +"möjligt, eller om det korta namnet faktiskt ska användas, anger du " +"parametern uttryckligen." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:226 @@ -13608,19 +14087,19 @@ msgid "" "to perform dynamic DNS updates. It must match the hostname for which the " "keytab was issued." msgstr "" -"Detta fält används för att avgöra värd-huvudmannen som används i keytab:en " -"och utföra dynamiska DNS-uppdateringar. Det måste stämma med värdnamnet som " -"keytab:en gavs ut för." +"Fältet används för att fastställa den värdhuvudman som används i keytab och " +"för att utföra dynamiska DNS-uppdateringar. Det måste stämma med det " +"värdnamn som keytab utfärdades för." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:235 msgid "ad_enable_dns_sites (boolean)" -msgstr "ad_enable_dns_sites (boolean)" +msgstr "ad_enable_dns_sites (boolesk)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:238 msgid "Enables DNS sites - location based service discovery." -msgstr "Aktiverar DNS-sajter – platsbaserat tjänsteupptäckt." +msgstr "Aktiverar DNS-platser, det vill säga platsbaserad tjänsteidentifiering." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:242 @@ -13632,12 +14111,12 @@ msgid "" "DNS SRV configuration, including the discovery domain, is used during site " "discovery as well." msgstr "" -"Om sant och tjänsteupptäckt (se stycket Tjänsteupptäckt i slutet av " -"manualsidan) är aktiverat kommer SSSD först att försöka hitta en Active " -"Directory-server att ansluta till med Active Directory Site Discovery och " -"sedan falla tillbaka på traditionell SRV-upptäckt om ingen AD-sajt hittas. " -"Konfigurationen av DNS SRV, inklusive upptäcktsdomänen, används också under " -"sajtupptäckten." +"Om true och tjänsteidentifiering (se stycket Tjänsteidentifiering längst ned " +"på manualsidan) är aktiverade försöker SSSD först identifiera den Active " +"Directory-server som den ska ansluta till med Active Directory Site " +"Discovery. Om ingen AD-plats hittas används DNS SRV-posterna i stället. DNS " +"SRV-konfigurationen, inklusive identifieringsdomänen, används även vid " +"platsidentifiering." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:258 @@ -13654,12 +14133,12 @@ msgid "" "disable GPO based access control (see option <quote>ad_gpo_access_control</" "quote> for details)." msgstr "" -"Anger et filter för LDAP-åtkomstkontroll som en användare måste matcha för " -"att få åtkomst. Alternativet <quote>access_provider</quote> måste vara " -"uttryckligen satt till <quote>ad</quote> för att detta alternativ skall ha " -"någon verkan. Om man vill använda <quote>ad_access_filter</quote> som det " -"enda åtkomstkontrollschemat måste man avaktivera GPO-baserad åtkomstkontroll " -"(se alternativet <quote>ad_gpo_access_control</quote> för detaljer)." +"Anger ett LDAP-filter för åtkomststyrning som en användare måste matcha för " +"att få åtkomst. Alternativet <quote>access_provider</quote> måste " +"uttryckligen anges som <quote>ad</quote> för att alternativet ska gälla. Om " +"du vill använda <quote>ad_access_filter</quote> som enda " +"åtkomststyrningsschema måste GPO-baserad åtkomststyrning inaktiveras (mer " +"information finns i <quote>ad_gpo_access_control</quote>)." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:270 @@ -13669,10 +14148,9 @@ msgid "" "The keyword can be either <quote>DOM</quote>, <quote>FOREST</quote> or " "missing." msgstr "" -"Alternativet stödjer också att ange olika filter per domän eller skog. " -"Detta utökade filter skulle bestå av: <quote>NYCKELORD:NAMN:FILTER</quote>. " -"Nyckelordet kan vara antingen <quote>DOM</quote>, <quote>FOREST</quote> " -"eller utelämnas." +"Alternativet stöder även olika filter per domän eller skog. Det utökade " +"filtret består av <quote>KEYWORD:NAME:FILTER</quote>. Nyckelordet kan vara " +"<quote>DOM</quote>, <quote>FOREST</quote> eller utelämnas." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:278 @@ -13682,10 +14160,10 @@ msgid "" "keyword equals to <quote>FOREST</quote>, then the filter equals to all " "domains from the forest specified by <quote>NAME</quote>." msgstr "" -"Om nyckelordet är lika med <quote>DOM</quote> eller saknas anger <quote>" -"NAMN</quote> domänen eller underdomänen filtret gäller för. Om nyckelordet " -"är lika med <quote>FOREST</quote> är filtret lika för alla domäner från " -"skogen som anges av <quote>NAMN</quote>." +"Om nyckelordet är <quote>DOM</quote> eller utelämnas anger <quote>NAME</" +"quote> den domän eller underdomän som filtret gäller för. Om nyckelordet är " +"<quote>FOREST</quote> gäller filtret för alla domäner i den skog som <quote>" +"NAME</quote> anger." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:286 @@ -13708,14 +14186,13 @@ msgid "" "url=\"https://msdn.microsoft.com/en-us/library/cc223367.aspx\"> [MS-ADTS] " "section LDAP extensions</ulink>" msgstr "" -"Nästade gruppmedlemskap måste sökas efter med en speciell OID <quote>" -":1.2.840.113556.1.4.1941:</quote> utöver den fullständiga syntaxen " -"DOM:domän.exempel.se: för att säkerställa att tolken inte försöker tolka " -"kolontecknen som hör till OID:n. Om man inte använder denna OID kommer " -"nästade gruppmedlemskap inte slås upp. Se användningsexempel nedan och se " -"här för ytterligare information om OID:n: <ulink url=\"https://" -"msdn.microsoft.com/en-us/library/cc223367.aspx\"> [MS-ADTS] avsnittet LDAP-" -"utökningar</ulink>" +"Nästat gruppmedlemskap måste sökas med den särskilda OID:n <quote>" +":1.2.840.113556.1.4.1941:</quote>, utöver den fullständiga syntaxen " +"DOM:domain.example.org:, för att tolken inte ska försöka tolka kolon som hör " +"till OID:n. Om denna OID inte används löses nästat gruppmedlemskap inte upp. " +"Ett användningsexempel finns nedan. Mer information om OID:n finns här: " +"<ulink url=\"https://msdn.microsoft.com/en-us/library/cc223367.aspx\">[MS-" +"ADTS] section LDAP extensions</ulink>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:304 @@ -13747,16 +14224,16 @@ msgid "" "DOM:dom1:(memberOf:1.2.840.113556.1.4.1941:=cn=nestedgroup,ou=groups,dc=example,dc=com)\n" " " msgstr "" -"# tillämpa endast filtret på en domän som heter dom1:\n" +"# apply filter on domain called dom1 only:\n" "dom1:(memberOf=cn=admins,ou=groups,dc=dom1,dc=com)\n" "\n" -"# tillämpa endast filtret på en domän som heter dom2:\n" +"# apply filter on domain called dom2 only:\n" "DOM:dom2:(memberOf=cn=admins,ou=groups,dc=dom2,dc=com)\n" "\n" -"# tillämpa endast filtret på en skog som heter EXEMPEL.COM:\n" -"FOREST:EXEMPEL.COM:(memberOf=cn=admins,ou=groups,dc=example,dc=com)\n" +"# apply filter on forest called EXAMPLE.COM only:\n" +"FOREST:EXAMPLE.COM:(memberOf=cn=admins,ou=groups,dc=example,dc=com)\n" "\n" -"# tillämpa filtret på en medlem av en nästad grupp i dom1:\n" +"# apply filter for a member of a nested group in dom1:\n" "DOM:dom1:" "(memberOf:1.2.840.113556.1.4.1941:=cn=nestedgroup,ou=groups,dc=example,dc=com)" "\n" @@ -13773,13 +14250,13 @@ msgid "" "Specify AD site to which client should try to connect. If this option is " "not provided, the AD site will be auto-discovered." msgstr "" -"Ange en AD-sajt som klienten skall försöka ansluta till. Om detta " -"alternativ inte anges kommer AD-sajten att automatupptäckas." +"Ange den AD-plats som klienten ska försöka ansluta till. Om alternativet " +"inte anges identifieras AD-platsen automatiskt." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:348 msgid "ad_enable_gc (boolean)" -msgstr "ad_enable_gc (boolean)" +msgstr "ad_enable_gc (boolesk)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:351 @@ -13789,10 +14266,10 @@ msgid "" "as a fallback. Disabling this option makes the SSSD only connect to the LDAP " "port of the current AD server." msgstr "" -"Som standard ansluter SSSD till den globala katalogen först för att hämta " +"Som standard ansluter SSSD först till den globala katalogen för att hämta " "användare från betrodda domäner och använder LDAP-porten för att hämta " -"gruppmedlemskap som en reserv. Att avaktivera detta alternativ gör att SSSD " -"endast ansluter till LDAP-porten på den aktuella AD-servern." +"gruppmedlemskap eller som reserv. Om detta alternativ inaktiveras ansluter " +"SSSD endast till LDAP-porten på den aktuella AD-servern." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:359 @@ -13802,10 +14279,10 @@ msgid "" "port of trusted domains instead. However, Global Catalog must be used in " "order to resolve cross-domain group memberships." msgstr "" -"Observera att att avaktivera stöd för den globala katalogen inte avaktiverar " -"att hämta användare från betrodda domäner. SSSD skulle ansluta till LDAP-" -"porten på den betrodda domänen istället. Dock måste den globala katalogen " -"användas för att slå upp gruppmedlemskap över domäner." +"Observera att inaktivering av stöd för den globala katalogen inte " +"inaktiverar hämtning av användare från betrodda domäner. SSSD ansluter då " +"till LDAP-porten för de betrodda domänerna i stället. Den globala katalogen " +"måste dock användas för att lösa upp gruppmedlemskap mellan domäner." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:373 @@ -13821,11 +14298,10 @@ msgid "" "must be explicitly set to <quote>ad</quote> in order for this option to have " "an effect." msgstr "" -"Detta alternativ anger arbetsläget för GPO-baserad " -"åtkomstkontrollsfunktionalitet: huruvida det arbetar i avaktiverat läge, " -"tvingande läge eller tillåtande läge. Observera att alternativet <quote>" -"access_provider</quote> måste vara uttryckligen satt till <quote>ad</quote> " -"för att detta alternativ skall ha någon effekt." +"Det här alternativet anger driftläget för GPO-baserad åtkomststyrning: " +"disabled, enforcing eller permissive. Observera att <quote>access_provider</" +"quote> uttryckligen måste anges som <quote>ad</quote> för att alternativet " +"ska gälla." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:385 @@ -13835,10 +14311,9 @@ msgid "" "information on the supported policy settings please refer to the " "<quote>ad_gpo_map</quote> options." msgstr "" -"Funktionalitet för GPO-baserad åtkomststyrning använder GPO-" -"policyinställningar för att avgöra huruvida en viss användare tillåts logga " -"in på värden eller inte. För mer information om de stödda " -"policyinställningarna se flaggan <quote>ad_gpo_map</quote>." +"GPO-baserad åtkomststyrning använder GPO-policyinställningar för att avgöra " +"om en viss användare får logga in på värden. Mer information om de " +"policyinställningar som stöds finns under <quote>ad_gpo_map</quote>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:393 @@ -13848,10 +14323,10 @@ msgid "" "S-1-5-32-544) in GPO access control rules will be ignored by SSSD. See " "upstream issue tracker https://github.com/SSSD/sssd/issues/5063 ." msgstr "" -"Observera att den aktuella versionen av SSSD inte stöjder Active Directorys " -"inbyggda grupper. Inbyggda grupper (såsom administratörer med SID S-1-5-32-" -"544) i GPO-åtkomststyrningsregler kommer ignoreras av SSSD. Se uppströms " -"ärendehanterare https://github.com/SSSD/sssd/issues/5063 ." +"Observera att den aktuella versionen av SSSD inte stöder Active Directorys " +"inbyggda grupper. Inbyggda grupper (som Administrators med SID S-1-5-32-544) " +"i GPO-regler för åtkomststyrning ignoreras av SSSD. Se felhanteringen " +"uppströms: https://github.com/SSSD/sssd/issues/5063." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:402 @@ -13862,11 +14337,11 @@ msgid "" "a user, the user or at least one of the groups to which it belongs must have " "following permissions on the GPO:" msgstr "" -"Före åtkomstkontroll utförs tillämpar SSSD säkerhetsfiltrering enligt " -"gruppolicy på GPO:erna. För varje enskild användares inloggning kontrolleras " -"tillämpligheten av GPO:erna som är länkade till värden. För att en GPO skall " -"vara tillämplig på en användare måste användaren eller åtminstone en av de " -"grupper den tillhör ha följande rättigheter på GPO:n:" +"Före åtkomststyrning tillämpar SSSD gruppolicybaserad säkerhetsfiltrering på " +"GPO:erna. Vid varje användarinloggning kontrolleras om GPO:erna som är " +"länkade till värden gäller. För att en GPO ska gälla för en användare måste " +"användaren eller minst en av grupperna som användaren tillhör ha följande " +"behörigheter för GPO:n:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ad.5.xml:412 @@ -13874,8 +14349,8 @@ msgid "" "Read: The user or one of its groups must have read access to the properties " "of the GPO (RIGHT_DS_READ_PROPERTY)" msgstr "" -"Läs: användaren eller en av dess grupper måste ha läsrättigheter till " -"egenskaperna hos GPO:n (RIGHT_DS_READ_PROPERTY)" +"Read: Användaren eller en av användarens grupper måste ha läsbehörighet till " +"egenskaperna för GPO:n (RIGHT_DS_READ_PROPERTY)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ad.5.xml:419 @@ -13883,8 +14358,8 @@ msgid "" "Apply Group Policy: The user or at least one of its groups must be allowed " "to apply the GPO (RIGHT_DS_CONTROL_ACCESS)." msgstr "" -"Verkställ gruppolicy: användaren eller åtminstone en av dess grupper måste " -"ha tillåtelse att verkställa GPO:n (RIGHT_DS_CONTROL_ACCESS)." +"Apply Group Policy: Användaren eller minst en av användarens grupper måste " +"få tillämpa GPO:n (RIGHT_DS_CONTROL_ACCESS)." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:427 @@ -13895,11 +14370,11 @@ msgid "" "and access control are started, the Authenticated Users group permissions on " "the GPO always apply also to the user." msgstr "" -"Som standard fins en autentiserad användares grupp på en GPO och denna grupp " -"har både Läs- och Verkställ gruppolicy-åtkomsträttigheter. Eftersom " -"autentisering av en användare måste ha fullgjorts framgångsrikt före GPO-" -"säkerhetsfiltrering och åtkomstkontroll börjar gäller alltid även den " -"autentiserade användarens grupprättigheter på GPO:n för användaren." +"Som standard finns gruppen Authenticated Users i en GPO och gruppen har " +"åtkomsträttigheterna Read och Apply Group Policy. Eftersom en användare " +"måste ha autentiserats innan GPO-säkerhetsfiltrering och åtkomststyrning " +"startar, gäller behörigheterna för Authenticated Users på GPO:n alltid även " +"användaren." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:436 @@ -13915,35 +14390,34 @@ msgid "" "functions' is required (see <citerefentry> <refentrytitle>sssctl</" "refentrytitle> <manvolnum>8</manvolnum> </citerefentry> manual page)." msgstr "" -"OBS: Om åtgärdsläget är satt till tvingande är det möjligt att användarna " -"som tidigare var tillåtna inloggningsåtkomst nu kommer nekast " -"inloggningsåtkomst (som det dikteras av GPO-policyinställningar). För att " -"möjliggöra en smidig övergång för administratörer finns ett tillåtande läge " -"tillgängligt som inte kommer genomdriva åtkomststyrningsreglerna, utan " -"kommer beräkna deom och skriva ut ett syslog-meddelande om åtkomst skulle ha " -"nekats. Genom att granska loggarna kan administratörer sedan göra de " -"nödvändiga ändringarna före läget ställs in som tvingande. För att logga " -"felsökningsnivå av GPO-baserad åtkomstkontroll krävs ”trace functions” (se " -"manualsidan <citerefentry><refentrytitle>sssctl</refentrytitle> <manvolnum>" -"8</manvolnum></citerefentry>)." +"OBS: Om driftläget är enforcing kan användare som tidigare fick logga in nu " +"nekas inloggning, enligt GPO-policyinställningarna. För att underlätta " +"övergången för administratörer finns läget permissive. Det tillämpar inte " +"åtkomststyrningsreglerna, men utvärderar dem och skriver ett syslog-" +"meddelande om åtkomst skulle ha nekats. Genom att granska loggarna kan " +"administratörer göra nödvändiga ändringar innan läget sätts till enforcing. " +"För loggning av GPO-baserad åtkomststyrning krävs felsökningsnivån 'trace " +"functions' (se manualsidan <citerefentry> <refentrytitle>sssctl</" +"refentrytitle> <manvolnum>8</manvolnum> </citerefentry>)." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:455 msgid "There are three supported values for this option:" -msgstr "Det finns tre stödda värden för detta alternativ:" +msgstr "Det finns tre värden som stöds för alternativet:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ad.5.xml:459 msgid "" "disabled: GPO-based access control rules are neither evaluated nor enforced." msgstr "" -"disabled: GPO-baserade åtkomstkontrollsregler varken evalueras eller " -"påtvingas." +"disabled: GPO-baserade regler för åtkomststyrning utvärderas eller tillämpas " +"inte." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ad.5.xml:465 msgid "enforcing: GPO-based access control rules are evaluated and enforced." -msgstr "enforcing: GPO-baserade åtkomstkontrollregler evalueras och påtvingas." +msgstr "" +"enforcing: GPO-baserade regler för åtkomststyrning utvärderas och tillämpas." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ad.5.xml:471 @@ -13952,10 +14426,9 @@ msgid "" "Instead, a syslog message will be emitted indicating that the user would " "have been denied access if this option's value were set to enforcing." msgstr "" -"permissive: GPO-baserade åtkomstkontrollregler evalueras men påtvingas " -"inte. Istället skickas ett syslog-meddelande ut som indikerar att " -"användaren skulle ha nekats åtkomst om detta alternativs värde vore satt " -"till enforcing." +"permissive: GPO-baserade regler för åtkomststyrning utvärderas, men " +"tillämpas inte. I stället skrivs ett syslog-meddelande som anger att " +"användaren skulle ha nekats åtkomst om alternativets värde var enforcing." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:482 @@ -13970,7 +14443,7 @@ msgstr "Standard: enforcing" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:491 msgid "ad_gpo_implicit_deny (boolean)" -msgstr "ad_gpo_implicit_deny (boolean)" +msgstr "ad_gpo_implicit_deny (boolesk)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:494 @@ -13982,13 +14455,12 @@ msgid "" "because it can deny access even to users in the built-in Administrators " "group if no GPO rules apply to them." msgstr "" -"Normalt när inga tillämpliga GPO:er finns tillåts användarna åtkomst. När " -"detta alternativ är satt till True kommer användare att tillåtas åtkomst " -"endast när det uttryckligen tillåts av en GPO-regel. Annars kommer " -"användare nekas åtkomst. Detta kan användas för att stärka säkerheten men " -"var försiktig när detta alternativ används för det kan neka åtkomst även " -"till användare i den inbyggda administratörsgruppen om inga GPO-regler är " -"tillämpliga på dem." +"Normalt beviljas användarna åtkomst när inga tillämpliga GPO:er hittas. När " +"alternativet är True beviljas användare åtkomst endast om en GPO-regel " +"uttryckligen tillåter det. Annars nekas användarna åtkomst. Detta kan " +"användas för att stärka säkerheten, men var försiktig: alternativet kan neka " +"åtkomst även till användare i den inbyggda gruppen Administrators om inga " +"GPO-regler gäller dem." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:510 @@ -13997,9 +14469,9 @@ msgid "" "based on the allow and deny login rights defined on the server-side and the " "setting of ad_gpo_implicit_deny." msgstr "" -"Följande 2 tabeller bör illustrera när en användare tillåts eller nekas " -"baserat på de tillåtande eller nekande inloggningsrättigheterna definierade " -"på serversidan och inställningen av ad_gpo_implicit_deny." +"Följande två tabeller visar när en användare tillåts eller nekas utifrån de " +"tillåtande och nekande inloggningsrättigheter som är definierade på " +"serversidan och inställningen för ad_gpo_implicit_deny." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> #: sssd-ad.5.xml:522 @@ -14051,7 +14523,9 @@ msgstr "endast användare i tillåtelseregler tillåts" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry><para> #: sssd-ad.5.xml:537 sssd-ad.5.xml:563 msgid "only users in allow-rules and not in deny-rules are allowed" -msgstr "endast användare i tillåtelse och inte i nekanderegler tillåts" +msgstr "" +"endast användare som finns i tillåtelseregler och inte i nekanderegler " +"tillåts" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> #: sssd-ad.5.xml:548 @@ -14066,7 +14540,7 @@ msgstr "inga användare tillåts" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:570 msgid "ad_gpo_ignore_unreadable (boolean)" -msgstr "ad_gpo_ignore_unreadable (boolean)" +msgstr "ad_gpo_ignore_unreadable (boolesk)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:573 @@ -14077,11 +14551,10 @@ msgid "" "policies if their attributes in group policy containers are not readable for " "SSSD." msgstr "" -"Normalt när några gruppolicybehållare (AD-objekt) av några tillämpliga " -"gruppolicyobjekt inte är läsbara av SSSD så nekas användare åtkomst. Detta " -"alternativ tillåter att man ignorerar gruppolicybehållare och med dem " -"tillhörande policyer om deras attribut i gruppolicybehållare inte är läsbara " -"för SSSD." +"Normalt nekas användare åtkomst när SSSD inte kan läsa vissa " +"gruppolicybehållare, AD-objekt, för tillämpliga gruppolicyobjekt. " +"Alternativet gör det möjligt att ignorera gruppolicybehållare och de " +"policyer som hör till dem om SSSD inte kan läsa deras attribut." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:590 @@ -14095,9 +14568,9 @@ msgid "" "server. This will reduce the latency and load on the AD server if there are " "many access-control requests made in a short period." msgstr "" -"Tiden mellan uppslagningar av GPO-policyfiler mot AD-servern. Detta kommer " -"reducera tidsfördröjningen och lasten på AD-servern om det görs många " -"begäranden om åtkomstkontroll under en kort tid." +"Tiden mellan uppslagningar av GPO-policyfiler på AD-servern. Detta minskar " +"fördröjningen och belastningen på AD-servern om många begäranden om " +"åtkomststyrning görs under en kort period." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:606 @@ -14119,18 +14592,17 @@ msgid "" "local access only, if it or at least one of its groups is part of the policy " "settings." msgstr "" -"En kommaseparerad lista av PAM-tjänstenamn för vilka GPO-baserad " -"åtkomstkontroll beräknas baserat på policyinställningarna " -"InteractiveLogonRight och DenyInteractiveLogonRight. Endast de GPO:er " -"beräknas för vilka användaren har Läs- eller Verkställ gruppolicy-" -"rättigheter (se flaggan <quote>ad_gpo_access_control</quote>). Om en " -"beräknad GPO innehåller inställningen neka interaktiv inloggning för " -"användaren eller en av dess grupper nekas användaren lokal åtkomst. Om ingen " -"av de evaluerade GPO:erna har en interaktiv inloggningsrättighet definierad " -"ges användaren lokal åtkomst. Om åtminstone en beräknad GPO innehåller " -"inställningen interaktiv inloggningsrättighet ges användaren lokal åtkomst " -"endast om denne eller åtminstone en av dess grupper är del av den " -"policyinställningen." +"En kommaseparerad lista med PAM-tjänstenamn där GPO-baserad åtkomststyrning " +"utvärderas enligt principinställningarna InteractiveLogonRight och " +"DenyInteractiveLogonRight. Endast GPO:er där användaren har behörigheten " +"Read och Apply Group Policy utvärderas (se <quote>ad_gpo_access_control</" +"quote>). Om en utvärderad GPO innehåller inställningen för att neka " +"interaktiv inloggning för användaren eller någon av användarens grupper " +"nekas användaren lokal åtkomst. Om ingen utvärderad GPO anger interaktiv " +"inloggningsrätt beviljas användaren lokal åtkomst. Om minst en utvärderad " +"GPO anger interaktiv inloggningsrätt beviljas användaren lokal åtkomst " +"endast om användaren eller någon av användarens grupper ingår i " +"principinställningen." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:627 @@ -14148,7 +14620,7 @@ msgid "" "ad_gpo_map_interactive = +my_pam_service, -login\n" " " msgstr "" -"ad_gpo_map_interactive = +min_pam-tjänst, -login\n" +"ad_gpo_map_interactive = +my_pam_service, -login\n" " " #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> @@ -14162,14 +14634,13 @@ msgid "" "<quote>my_pam_service</quote>), you would use the following configuration: " "<placeholder type=\"programlisting\" id=\"0\"/>" msgstr "" -"Det är möjligt att lägga till ett annat PAM-tjänstenamn till " -"standarduppsättningen genom att använda <quote>+tjänstenamn</quote> eller " -"att uttryckligen ta bort ett PAM-tjänstenamn från standarduppsättningen " -"genom att använda <quote>-tjänstenamn</quote>. Till exempel, för att byta " -"ut ett standard-PAM-tjänstenamn för denna inloggningsrätt (t.ex. <quote>" -"login</quote>) mot ett anpassat PAM-tjänstenamn (t.ex. <quote>min_pam-" -"tjänst</quote>) skulle man använda följande konfiguration: <placeholder " -"type=\"programlisting\" id=\"0\"/>" +"Du kan lägga till ett PAM-tjänstenamn i standarduppsättningen med <quote>" +"+service_name</quote> eller uttryckligen ta bort ett med <quote>-" +"service_name</quote>. Om du till exempel vill ersätta standardnamnet för den " +"här inloggningsrättigheten (till exempel <quote>login</quote>) med ett " +"anpassat PAM-tjänstenamn (till exempel <quote>my_pam_service</quote>) " +"använder du följande konfiguration: <placeholder type=\"programlisting\" " +"id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ad.5.xml:664 @@ -14187,27 +14658,27 @@ msgid "lxdm" msgstr "lxdm" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:694 +#: sssd-ad.5.xml:699 msgid "sddm" msgstr "sddm" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:699 +#: sssd-ad.5.xml:704 msgid "unity" msgstr "unity" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:704 +#: sssd-ad.5.xml:709 msgid "xdm" msgstr "xdm" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:713 +#: sssd-ad.5.xml:718 msgid "ad_gpo_map_remote_interactive (string)" msgstr "ad_gpo_map_remote_interactive (sträng)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:716 +#: sssd-ad.5.xml:721 msgid "" "A comma-separated list of PAM service names for which GPO-based access " "control is evaluated based on the RemoteInteractiveLogonRight and " @@ -14221,42 +14692,41 @@ msgid "" "settings, the user is granted remote access only, if it or at least one of " "its groups is part of the policy settings." msgstr "" -"En kommaseparerad lista av PAM-tjänstenamn för vilka GPO-baserad " -"åtkomstkontroll beräknas baserat på policyinställningarna " -"RemoteInteractiveLogonRight och DenyRemoteInteractiveLogonRight. Endast de " -"GPO:er beräknas för vilka användaren har Läs- eller Verkställ gruppolicy-" -"rättigheter (se flaggan <quote>ad_gpo_access_control</quote>). Om en " -"beräknad GPO innehåller inställningen neka fjärrinloggning för användaren " -"eller en av dess grupper nekas användaren interaktiv fjärråtkomst. Om ingen " -"av de evaluerade GPO:erna har en interaktiv inloggningsrättighet definierad " -"ges användaren interaktiv fjärråtkomst. Om åtminstone en beräknad GPO " -"innehåller inställningen interaktiv fjärrinloggningsrättighet ges användaren " -"fjärråtkomst endast om denne eller åtminstone en av dess grupper är del av " -"den policyinställningen." +"En kommaseparerad lista med PAM-tjänstenamn där GPO-baserad åtkomststyrning " +"utvärderas enligt principinställningarna RemoteInteractiveLogonRight och " +"DenyRemoteInteractiveLogonRight. Endast GPO:er där användaren har " +"behörigheten Read och Apply Group Policy utvärderas (se <quote>" +"ad_gpo_access_control</quote>). Om en utvärderad GPO innehåller " +"inställningen för att neka fjärrinloggning för användaren eller någon av " +"användarens grupper nekas användaren interaktiv fjärråtkomst. Om ingen " +"utvärderad GPO anger interaktiv fjärrinloggningsrätt beviljas användaren " +"fjärråtkomst. Om minst en utvärderad GPO anger interaktiv " +"fjärrinloggningsrätt beviljas användaren fjärråtkomst endast om användaren " +"eller någon av användarens grupper ingår i principinställningen." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:735 +#: sssd-ad.5.xml:740 msgid "" "Note: Using the Group Policy Management Editor this value is called \"Allow " "log on through Remote Desktop Services\" and \"Deny log on through Remote " "Desktop Services\"." msgstr "" -"Obs: när man använder gruppolicyhanteringsredigeraren kallas detta värde ”" -"Tillåt inloggning via fjärrskrivbordstjänster” och ”Neka inloggning via " -"fjärrinloggningstjänster”." +"Obs: I Group Policy Management Editor kallas värdet \"Allow log on through " +"Remote Desktop Services\" och \"Deny log on through Remote Desktop " +"Services\"." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:750 +#: sssd-ad.5.xml:755 #, no-wrap msgid "" "ad_gpo_map_remote_interactive = +my_pam_service, -sshd\n" " " msgstr "" -"ad_gpo_map_remote_interactive = +min_pam-tjänst, -sshd\n" +"ad_gpo_map_remote_interactive = +my_pam_service, -sshd\n" " " #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:741 +#: sssd-ad.5.xml:746 msgid "" "It is possible to add another PAM service name to the default set by using " "<quote>+service_name</quote> or to explicitly remove a PAM service name from " @@ -14266,32 +14736,31 @@ msgid "" "<quote>my_pam_service</quote>), you would use the following configuration: " "<placeholder type=\"programlisting\" id=\"0\"/>" msgstr "" -"Det är möjligt att lägga till ett annat PAM-tjänstenamn till " -"standarduppsättningen genom att använda <quote>+tjänstenamn</quote> eller " -"att uttryckligen ta bort ett PAM-tjänstenamn från standarduppsättningen " -"genom att använda <quote>-tjänstenamn</quote>. Till exempel, för att byta " -"ut ett standard-PAM-tjänstenamn för denna inloggningsrätt (t.ex. <quote>" -"sshd</quote>) mot ett anpassat PAM-tjänstenamn (t.ex. <quote>min_pam-tjänst</" -"quote>) skulle man använda följande konfiguration: <placeholder " -"type=\"programlisting\" id=\"0\"/>" +"Du kan lägga till ett PAM-tjänstenamn i standarduppsättningen med <quote>" +"+service_name</quote> eller uttryckligen ta bort ett med <quote>-" +"service_name</quote>. Om du till exempel vill ersätta standardnamnet för den " +"här inloggningsrättigheten (till exempel <quote>sshd</quote>) med ett " +"anpassat PAM-tjänstenamn (till exempel <quote>my_pam_service</quote>) " +"använder du följande konfiguration: <placeholder type=\"programlisting\" " +"id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:758 +#: sssd-ad.5.xml:763 msgid "sshd" msgstr "sshd" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:763 +#: sssd-ad.5.xml:768 msgid "cockpit" msgstr "cockpit" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:772 +#: sssd-ad.5.xml:777 msgid "ad_gpo_map_network (string)" msgstr "ad_gpo_map_network (sträng)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:775 +#: sssd-ad.5.xml:780 msgid "" "A comma-separated list of PAM service names for which GPO-based access " "control is evaluated based on the NetworkLogonRight and " @@ -14305,20 +14774,20 @@ msgid "" "logon access only, if it or at least one of its groups is part of the policy " "settings." msgstr "" -"En kommaseparerad lista av PAM-tjänstenamn för vilka GPO-baserad " -"åtkomstkontroll beräknas baserat på policyinställningarna NetworkLogonRight " -"och DenyNetworkLogonRight. Endast de GPO:er beräknas för vilka användaren " -"har Läs- eller Verkställ gruppolicy-rättigheter (se flaggan <quote>" -"ad_gpo_access_control</quote>). Om en beräknad GPO innehåller inställningen " -"neka nätverksinloggning för användaren eller en av dess grupper nekas " -"användaren nätverksåtkomst. Om ingen av de evaluerade GPO:erna har en " -"nätverksinloggningsrättighet definierad ges användaren inloggningsåtkomst. " -"Om åtminstone en beräknad GPO innehåller inställningen " -"nätverksinloggningsrättighet ges användaren inloggningsåtkomst endast om " -"denne eller åtminstone en av dess grupper är del av den policyinställningen." +"En kommaseparerad lista med PAM-tjänstenamn där GPO-baserad åtkomststyrning " +"utvärderas enligt principinställningarna NetworkLogonRight och " +"DenyNetworkLogonRight. Endast GPO:er där användaren har behörigheten Read " +"och Apply Group Policy utvärderas (se <quote>ad_gpo_access_control</quote>). " +"Om en utvärderad GPO innehåller inställningen för att neka " +"nätverksinloggning för användaren eller någon av användarens grupper nekas " +"användaren nätverksinloggning. Om ingen utvärderad GPO anger " +"nätverksinloggningsrätt beviljas användaren inloggning. Om minst en " +"utvärderad GPO anger nätverksinloggningsrätt beviljas användaren inloggning " +"endast om användaren eller någon av användarens grupper ingår i " +"principinställningen." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:793 +#: sssd-ad.5.xml:798 msgid "" "Note: Using the Group Policy Management Editor this value is called \"Access " "this computer from the network\" and \"Deny access to this computer from the " @@ -14329,17 +14798,17 @@ msgstr "" "nätverket”." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:808 +#: sssd-ad.5.xml:813 #, no-wrap msgid "" "ad_gpo_map_network = +my_pam_service, -ftp\n" " " msgstr "" -"ad_gpo_map_network = +min_pam-tjänst, -ftp\n" +"ad_gpo_map_network = +my_pam_service, -ftp\n" " " #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:799 +#: sssd-ad.5.xml:804 msgid "" "It is possible to add another PAM service name to the default set by using " "<quote>+service_name</quote> or to explicitly remove a PAM service name from " @@ -14349,32 +14818,31 @@ msgid "" "<quote>my_pam_service</quote>), you would use the following configuration: " "<placeholder type=\"programlisting\" id=\"0\"/>" msgstr "" -"Det är möjligt att lägga till ett annat PAM-tjänstenamn till " -"standarduppsättningen genom att använda <quote>+tjänstenamn</quote> eller " -"att uttryckligen ta bort ett PAM-tjänstenamn från standarduppsättningen " -"genom att använda <quote>-tjänstenamn</quote>. Till exempel, för att byta " -"ut ett standard-PAM-tjänstenamn för denna inloggningsrätt (t.ex. <quote>ftp</" -"quote>) mot ett anpassat PAM-tjänstenamn (t.ex. <quote>min_pam-tjänst</" -"quote>) skulle man använda följande konfiguration: <placeholder " -"type=\"programlisting\" id=\"0\"/>" +"Du kan lägga till ett PAM-tjänstenamn i standarduppsättningen med <quote>" +"+service_name</quote> eller uttryckligen ta bort ett med <quote>-" +"service_name</quote>. Om du till exempel vill ersätta standardnamnet för den " +"här inloggningsrättigheten (till exempel <quote>ftp</quote>) med ett " +"anpassat PAM-tjänstenamn (till exempel <quote>my_pam_service</quote>) " +"använder du följande konfiguration: <placeholder type=\"programlisting\" " +"id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:816 +#: sssd-ad.5.xml:821 msgid "ftp" msgstr "ftp" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:821 +#: sssd-ad.5.xml:826 msgid "samba" msgstr "samba" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:830 +#: sssd-ad.5.xml:835 msgid "ad_gpo_map_batch (string)" msgstr "ad_gpo_map_batch (sträng)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:833 +#: sssd-ad.5.xml:838 msgid "" "A comma-separated list of PAM service names for which GPO-based access " "control is evaluated based on the BatchLogonRight and DenyBatchLogonRight " @@ -14387,20 +14855,19 @@ msgid "" "settings, the user is granted logon access only, if it or at least one of " "its groups is part of the policy settings." msgstr "" -"En kommaseparerad lista av PAM-tjänstenamn för vilka GPO-baserad " -"åtkomstkontroll beräknas baserat på policyinställningarna BatchLogonRight " -"och DenyBatchLogonRight. Endast de GPO:er beräknas för vilka användaren har " -"Läs- eller Verkställ gruppolicy-rättigheter (se flaggan <quote>" -"ad_gpo_access_control</quote>). Om en beräknad GPO innehåller inställningen " -"neka satsvis inloggning för användaren eller en av dess grupper nekas " -"användaren satsvis inloggningsåtkomst. Om ingen av de evaluerade GPO:erna " -"har en satsvis inloggningsrättighet definierad ges användaren " -"inloggningsåtkomst. Om åtminstone en beräknad GPO innehåller inställningen " -"satsvis inloggningsrättighet ges användaren inloggningsåtkomst endast om " -"denne eller åtminstone en av dess grupper är del av den policyinställningen." +"En kommaseparerad lista med PAM-tjänstenamn där GPO-baserad åtkomststyrning " +"utvärderas enligt principinställningarna BatchLogonRight och " +"DenyBatchLogonRight. Endast GPO:er där användaren har behörigheten Read och " +"Apply Group Policy utvärderas (se <quote>ad_gpo_access_control</quote>). Om " +"en utvärderad GPO innehåller inställningen för att neka batchinloggning för " +"användaren eller någon av användarens grupper nekas användaren " +"batchinloggning. Om ingen utvärderad GPO anger batchinloggningsrätt beviljas " +"användaren inloggning. Om minst en utvärderad GPO anger batchinloggningsrätt " +"beviljas användaren inloggning endast om användaren eller någon av " +"användarens grupper ingår i principinställningen." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:851 +#: sssd-ad.5.xml:856 msgid "" "Note: Using the Group Policy Management Editor this value is called \"Allow " "log on as a batch job\" and \"Deny log on as a batch job\"." @@ -14410,17 +14877,17 @@ msgstr "" "”." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:865 +#: sssd-ad.5.xml:870 #, no-wrap msgid "" "ad_gpo_map_batch = +my_pam_service, -crond\n" " " msgstr "" -"ad_gpo_map_batch = +min_pam-tjänst, -crond\n" +"ad_gpo_map_batch = +my_pam_service, -crond\n" " " #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:856 +#: sssd-ad.5.xml:861 msgid "" "It is possible to add another PAM service name to the default set by using " "<quote>+service_name</quote> or to explicitly remove a PAM service name from " @@ -14430,35 +14897,34 @@ msgid "" "<quote>my_pam_service</quote>), you would use the following configuration: " "<placeholder type=\"programlisting\" id=\"0\"/>" msgstr "" -"Det är möjligt att lägga till ett annat PAM-tjänstenamn till " -"standarduppsättningen genom att använda <quote>+tjänstenamn</quote> eller " -"att uttryckligen ta bort ett PAM-tjänstenamn från standarduppsättningen " -"genom att använda <quote>-tjänstenamn</quote>. Till exempel, för att byta " -"ut ett standard-PAM-tjänstenamn för denna inloggningsrätt (t.ex. <quote>" -"crond</quote>) mot ett anpassat PAM-tjänstenamn (t.ex. <quote>min_pam-" -"tjänst</quote>) skulle man använda följande konfiguration: <placeholder " -"type=\"programlisting\" id=\"0\"/>" +"Du kan lägga till ett PAM-tjänstenamn i standarduppsättningen med <quote>" +"+service_name</quote> eller uttryckligen ta bort ett med <quote>-" +"service_name</quote>. Om du till exempel vill ersätta standardnamnet för den " +"här inloggningsrättigheten (till exempel <quote>crond</quote>) med ett " +"anpassat PAM-tjänstenamn (till exempel <quote>my_pam_service</quote>) " +"använder du följande konfiguration: <placeholder type=\"programlisting\" " +"id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:868 +#: sssd-ad.5.xml:873 msgid "" "Note: Cron service name may differ depending on Linux distribution used." msgstr "" -"Obs: cron-tjänstenamn kan skilja beroende på vilken Linuxdistribution som " -"används." +"Obs: Tjänstenamnet för cron kan skilja sig beroende på vilken Linux-" +"distribution som används." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:874 +#: sssd-ad.5.xml:879 msgid "crond" msgstr "crond" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:883 +#: sssd-ad.5.xml:888 msgid "ad_gpo_map_service (string)" msgstr "ad_gpo_map_service (sträng)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:886 +#: sssd-ad.5.xml:891 msgid "" "A comma-separated list of PAM service names for which GPO-based access " "control is evaluated based on the ServiceLogonRight and " @@ -14472,20 +14938,19 @@ msgid "" "logon access only, if it or at least one of its groups is part of the policy " "settings." msgstr "" -"En kommaseparerad lista av PAM-tjänstenamn för vilka GPO-baserad " -"åtkomstkontroll beräknas baserat på policyinställningarna ServiceLogonRight " -"och DenyServiceLogonRight. Endast de GPO:er beräknas för vilka användaren " -"har Läs- eller Verkställ gruppolicy-rättigheter (se flaggan <quote>" -"ad_gpo_access_control</quote>). Om en beräknad GPO innehåller inställningen " -"neka tjänsteinloggning för användaren eller en av dess grupper nekas " -"användaren tjänsteinloggningsåtkomst. Om ingen av de evaluerade GPO:erna har " -"en tjänsteinloggningsrättighet definierad ges användaren inloggningsåtkomst. " -"Om åtminstone en beräknad GPO innehåller inställningen " -"tjänsteinloggningsrättighet ges användaren inloggningsåtkomst endast om " -"denne eller åtminstone en av dess grupper är del av den policyinställningen." +"En kommaseparerad lista med PAM-tjänstenamn där GPO-baserad åtkomststyrning " +"utvärderas enligt principinställningarna ServiceLogonRight och " +"DenyServiceLogonRight. Endast GPO:er där användaren har behörigheten Read " +"och Apply Group Policy utvärderas (se <quote>ad_gpo_access_control</quote>). " +"Om en utvärderad GPO innehåller inställningen för att neka tjänsteinloggning " +"för användaren eller någon av användarens grupper nekas användaren " +"tjänsteinloggning. Om ingen utvärderad GPO anger tjänsteinloggningsrätt " +"beviljas användaren inloggning. Om minst en utvärderad GPO anger " +"tjänsteinloggningsrätt beviljas användaren inloggning endast om användaren " +"eller någon av användarens grupper ingår i principinställningen." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:904 +#: sssd-ad.5.xml:909 msgid "" "Note: Using the Group Policy Management Editor this value is called \"Allow " "log on as a service\" and \"Deny log on as a service\"." @@ -14494,17 +14959,17 @@ msgstr "" "Tillåt inloggning som en tjänst” och ”Neka inloggning som en tjänst”." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:917 +#: sssd-ad.5.xml:922 #, no-wrap msgid "" "ad_gpo_map_service = +my_pam_service\n" " " msgstr "" -"ad_gpo_map_service = +min_pam-tjänst\n" +"ad_gpo_map_service = +my_pam_service\n" " " #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:909 sssd-ad.5.xml:984 +#: sssd-ad.5.xml:914 sssd-ad.5.xml:989 msgid "" "It is possible to add a PAM service name to the default set by using " "<quote>+service_name</quote>. Since the default set is empty, it is not " @@ -14513,40 +14978,39 @@ msgid "" "you would use the following configuration: <placeholder " "type=\"programlisting\" id=\"0\"/>" msgstr "" -"Det är möjligt att lägga till ett PAM-tjänstenamn till standarduppsättningen " -"genom att använda <quote>+tjänstenamn</quote>. Eftersom " -"standarduppsättningen är tom är det inte möjligt att ta bort ett PAM-" -"tjänstenamn från standarduppsättningen. Till exempel, för att lägga till " -"ett anpassat PAM-tjänstenamn (t.ex. <quote>min_pam-tjänst</quote>) skulle " -"man använda följande konfiguration: <placeholder type=\"programlisting\" " +"Du kan lägga till ett PAM-tjänstenamn i standarduppsättningen med <quote>" +"+service_name</quote>. Eftersom standarduppsättningen är tom går det inte " +"att ta bort ett PAM-tjänstenamn från den. Om du till exempel vill lägga till " +"ett anpassat PAM-tjänstenamn (till exempel <quote>my_pam_service</quote>) " +"använder du följande konfiguration: <placeholder type=\"programlisting\" " "id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:927 +#: sssd-ad.5.xml:932 msgid "ad_gpo_map_permit (string)" msgstr "ad_gpo_map_permit (sträng)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:930 +#: sssd-ad.5.xml:935 msgid "" "A comma-separated list of PAM service names for which GPO-based access is " "always granted, regardless of any GPO Logon Rights." msgstr "" -"En kommaseparerad lista av PAM-tjänstenamn för vilka GPO-baserad åtkomst " -"alltid tillåts, oavsett några andra GPO-inloggningsrättigheter." +"En kommaseparerad lista med PAM-tjänstenamn där GPO-baserad åtkomst alltid " +"beviljas, oavsett GPO-inloggningsrättigheter." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:944 +#: sssd-ad.5.xml:949 #, no-wrap msgid "" "ad_gpo_map_permit = +my_pam_service, -sudo\n" " " msgstr "" -"ad_gpo_map_permit = +min_pam-tjänst, -sudo\n" +"ad_gpo_map_permit = +my_pam_service, -sudo\n" " " #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:935 +#: sssd-ad.5.xml:940 msgid "" "It is possible to add another PAM service name to the default set by using " "<quote>+service_name</quote> or to explicitly remove a PAM service name from " @@ -14556,56 +15020,55 @@ msgid "" "<quote>my_pam_service</quote>), you would use the following configuration: " "<placeholder type=\"programlisting\" id=\"0\"/>" msgstr "" -"Det är möjligt att lägga till ett annat PAM-tjänstenamn till " -"standarduppsättningen genom att använda <quote>+tjänstenamn</quote> eller " -"att uttryckligen ta bort ett PAM-tjänstenamn från standarduppsättningen " -"genom att använda <quote>-tjänstenamn</quote>. Till exempel, för att byta " -"ut ett standard-PAM-tjänstenamn för ovillkorligt tillåten åtkomst (t.ex. " -"<quote>sudo</quote>) mot ett anpassat PAM-tjänstenamn (t.ex. <quote>min_pam-" -"tjänst</quote>) skulle man använda följande konfiguration: <placeholder " -"type=\"programlisting\" id=\"0\"/>" +"Du kan lägga till ett PAM-tjänstenamn i standarduppsättningen med <quote>" +"+service_name</quote> eller uttryckligen ta bort ett med <quote>-" +"service_name</quote>. Om du till exempel vill ersätta standardnamnet för " +"villkorslöst tillåten åtkomst (till exempel <quote>sudo</quote>) med ett " +"anpassat PAM-tjänstenamn (till exempel <quote>my_pam_service</quote>) " +"använder du följande konfiguration: <placeholder type=\"programlisting\" " +"id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:952 +#: sssd-ad.5.xml:957 msgid "polkit-1" msgstr "polkit-1" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:967 +#: sssd-ad.5.xml:972 msgid "systemd-user" msgstr "systemd-user" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:976 +#: sssd-ad.5.xml:981 msgid "ad_gpo_map_deny (string)" msgstr "ad_gpo_map_deny (sträng)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:979 +#: sssd-ad.5.xml:984 msgid "" "A comma-separated list of PAM service names for which GPO-based access is " "always denied, regardless of any GPO Logon Rights." msgstr "" -"En kommaseparerad lista av PAM-tjänstenamn för vilka GPO-baserad åtkomst " -"alltid nekas, oavsett några andra GPO-inloggningsrättigheter." +"En kommaseparerad lista med PAM-tjänstenamn där GPO-baserad åtkomst alltid " +"nekas, oavsett GPO-inloggningsrättigheter." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:992 +#: sssd-ad.5.xml:997 #, no-wrap msgid "" "ad_gpo_map_deny = +my_pam_service\n" " " msgstr "" -"ad_gpo_map_deny = +min_pam-tjänst\n" +"ad_gpo_map_deny = +my_pam_service\n" " " #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:1002 +#: sssd-ad.5.xml:1007 msgid "ad_gpo_default_right (string)" msgstr "ad_gpo_default_right (sträng)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1005 +#: sssd-ad.5.xml:1010 msgid "" "This option defines how access control is evaluated for PAM service names " "that are not explicitly listed in one of the ad_gpo_map_* options. This " @@ -14616,84 +15079,83 @@ msgid "" "settings. Alternatively, this option can be set to either always permit or " "always deny access for unmapped PAM service names." msgstr "" -"Detta alternativ definierar hur åtkomstkontroll beräknas för PAM-tjänstenamn " -"som inte är uttryckligen listade i en av alternativen ad_gpo_map_*. Detta " -"alternativ kan anges på två olika sätt. Antingen kan detta alternativ " -"sättas till att ange standardinloggningsrättigheter. Till exempel, om detta " -"alternativ är satt till ”interactive” betyder det att omappade PAM-" -"tjänstenamn kommer bearbetas baserat på policyinställningarna " -"InteractiveLogonRight och DenyInteractiveLogonRight. Alternativt kan detta " -"alternativ sättas till att antingen alltid tillåta eller alltid neka åtkomst " -"för omappade PAM-tjänstenamn." +"Det här alternativet anger hur åtkomststyrning utvärderas för PAM-" +"tjänstenamn som inte uttryckligen listas i något av alternativen " +"ad_gpo_map_*. Alternativet kan anges på två sätt. För det första kan det " +"anges att använda en standardinloggningsrätt. Om alternativet till exempel " +"anges som 'interactive' behandlas omappade PAM-tjänstenamn enligt " +"principinställningarna InteractiveLogonRight och DenyInteractiveLogonRight. " +"Alternativt kan det ange att åtkomst alltid ska beviljas eller nekas för " +"omappade PAM-tjänstenamn." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1018 +#: sssd-ad.5.xml:1023 msgid "Supported values for this option include:" msgstr "Värden som stödjs för detta alternativ inkluderar:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1027 +#: sssd-ad.5.xml:1032 msgid "remote_interactive" msgstr "remote_interactive" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1032 +#: sssd-ad.5.xml:1037 msgid "network" msgstr "network" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1037 +#: sssd-ad.5.xml:1042 msgid "batch" msgstr "batch" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1042 +#: sssd-ad.5.xml:1047 msgid "service" msgstr "service" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1047 +#: sssd-ad.5.xml:1052 msgid "permit" msgstr "permit" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1052 +#: sssd-ad.5.xml:1057 msgid "deny" msgstr "deny" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1058 +#: sssd-ad.5.xml:1063 msgid "Default: deny" msgstr "Standard: deny" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:1064 +#: sssd-ad.5.xml:1069 msgid "ad_maximum_machine_account_password_age (integer)" msgstr "ad_maximum_machine_account_password_age (heltal)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1067 +#: sssd-ad.5.xml:1072 msgid "" "SSSD will check once a day if the machine account password is older than the " "given age in days and try to renew it. A value of 0 will disable the renewal " "attempt." msgstr "" -"SSSD kommer en gång om dagen kontrollera om maskinkontolösenordet är äldre " -"än den givna åldern i dagar och försöka förnya det. Ett värde på 0 kommer " -"förhindra förnyelseförsöket." +"SSSD kontrollerar en gång om dagen om maskinkontots lösenord är äldre än " +"angivet antal dagar och försöker förnya det. Värdet 0 inaktiverar " +"förnyelseförsöket." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1073 +#: sssd-ad.5.xml:1078 msgid "Default: 30 days" msgstr "Standard: 30 dagar" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:1079 +#: sssd-ad.5.xml:1084 msgid "ad_machine_account_password_renewal_opts (string)" msgstr "ad_machine_account_password_renewal_opts (sträng)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1082 +#: sssd-ad.5.xml:1087 msgid "" "This option should only be used to test the machine account renewal task. " "The option expects 3 integers and a string separated by a colon (':'). The " @@ -14704,27 +15166,36 @@ msgid "" "the same time (\"thundering herd problem\"). If this value is missing or " "empty in the value string '0' will be used." msgstr "" -"Det här alternativet ska endast användas för att testa uppgiften för " -"förnyelse av maskinkonto. Alternativet förväntar sig tre heltal och en " -"sträng separerade med kolon (':'). Det första heltalet definierar " -"intervallet i sekunder för hur ofta uppgiften ska köras. Det andra anger den " -"initiala tidsgränsen i sekunder innan uppgiften körs för första gången efter " -"start. Det valfria tredje värdet anger en maximal slumpmässig förskjutning " -"från de två föregående värdena för att undvika uppdateringar av många värdar " -"samtidigt (\"thundering herd-problemet\"). Om detta värde saknas eller är " -"tomt i värdesträngen används '0'." - -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1096 +"Det här alternativet ska endast användas för att testa uppgiften som förnyar " +"maskinkonton. Alternativet förväntar sig tre heltal och en sträng som " +"avgränsas med ett kolon (':'). Det första heltalet anger intervallet i " +"sekunder mellan körningarna. Det andra anger den inledande tidsgränsen i " +"sekunder före den första körningen efter start. Det valfria tredje värdet " +"anger en maximal slumpmässig förskjutning av de två föregående värdena för " +"att undvika att många värdar uppdateras samtidigt (\"thundering herd " +"problem\"). Om värdet saknas eller är tomt i värdesträngen används '0'." + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:1101 +#, fuzzy +#| msgid "" +#| "The optional fourth string value identifies the helper binary which " +#| "should be used for the renewal. Currently <command>adcli</command> and " +#| "<command>realm</command> are supported. If this value is missing or empty " +#| "in the value string <command>realm</command> will be used. Since the " +#| "helper is started as the user SSSD is running as there might be the " +#| "chance that the renewal will fail if this user does not has permissions " +#| "to modify the keytab file where the machine account credentials are " +#| "stored. This will typically be the case for <command>adcli</command>." msgid "" "The optional fourth string value identifies the helper binary which should " "be used for the renewal. Currently <command>adcli</command> and " "<command>realm</command> are supported. If this value is missing or empty in " "the value string <command>realm</command> will be used. Since the helper is " "started as the user SSSD is running as there might be the chance that the " -"renewal will fail if this user does not has permissions to modify the keytab " -"file where the machine account credentials are stored. This will typically " -"be the case for <command>adcli</command>." +"renewal will fail if this user does not have permissions to modify the " +"keytab file where the machine account credentials are stored. This will " +"typically be the case for <command>adcli</command>." msgstr "" "Det valfria fjärde strängvärdet identifierar hjälpprogrammet som ska " "användas för förnyelsen. För närvarande stöds <command>adcli</command> och " @@ -14736,7 +15207,7 @@ msgstr "" "för <command>adcli</command>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1110 +#: sssd-ad.5.xml:1115 msgid "" "<command>realm</command> is not updating the keytab directly but is calling " "the <command>realmd</command> process, which runs as root user, for this " @@ -14744,46 +15215,56 @@ msgid "" "with the help of PolicyKit and by default SSSD provides suitable rules for " "the user SSSD is running as." msgstr "" -"<command>realm</command> uppdaterar inte keytab direkt utan anropar <command>" -"realmd</command>-processen, som körs som root-användare, för denna uppgift. " -"<command>realmd</command> kan tillåta åtkomst för icke-privilegierade " -"användare med hjälp av PolicyKit och som standard tillhandahåller SSSD " -"lämpliga regler för den användare som SSSD körs som." +"<command>realm</command> uppdaterar inte keytab-filen direkt utan anropar " +"processen <command>realmd</command>, som körs som root, för uppgiften. " +"<command>realmd</command> kan tillåta åtkomst för oprivilegierade användare " +"med hjälp av PolicyKit, och SSSD tillhandahåller som standard lämpliga " +"regler för den användare som SSSD körs som." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1119 +#: sssd-ad.5.xml:1124 msgid "Default: 86400:750:300:realm (24h, 12m30s and 5m)" msgstr "Standard: 86400:750:300:realm (24h, 12m30s och 5m)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:1125 +#: sssd-ad.5.xml:1130 msgid "ad_update_samba_machine_account_password (boolean)" -msgstr "ad_update_samba_machine_account_password (boolean)" +msgstr "ad_update_samba_machine_account_password (boolesk)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1128 +#: sssd-ad.5.xml:1133 msgid "" "If enabled, when SSSD renews the machine account password, it will also be " "updated in Samba's database. This prevents Samba's copy of the machine " "account password from getting out of date when it is set up to use AD for " "authentication." msgstr "" -"Om aktiverat kommer lösenordet i Sambas databas också uppdateras när SSSD " -"förnyar maskinkontolösenordet. Detta förhindrar Sambas exemplar av " -"maskinkontolösenordet från att bli inaktuellt när det är uppsatt att använda " -"AD för autentisering." +"Om alternativet är aktiverat uppdateras lösenordet även i Sambas databas när " +"SSSD förnyar maskinkontots lösenord. Det hindrar Sambas kopia av lösenordet " +"från att bli inaktuell när Samba har konfigurerats för att använda AD till " +"autentisering." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:1141 -msgid "ad_use_ldaps (bool)" +#: sssd-ad.5.xml:1146 +#, fuzzy +#| msgid "ad_use_ldaps (bool)" +msgid "ad_use_ldaps (boolean)" msgstr "ad_use_ldaps (bool)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1144 +#: sssd-ad.5.xml:1149 +#, fuzzy +#| msgid "" +#| "By default SSSD uses the plain LDAP port 389 and the Global Catalog port " +#| "3628. If this option is set to True SSSD will use the LDAPS port 636 and " +#| "Global Catalog port 3629 with LDAPS protection. Since AD does not allow " +#| "to have multiple encryption layers on a single connection and we still " +#| "want to use SASL/GSSAPI or SASL/GSS-SPNEGO for authentication the SASL " +#| "security property maxssf is set to 0 (zero) for those connections." msgid "" "By default SSSD uses the plain LDAP port 389 and the Global Catalog port " -"3628. If this option is set to True SSSD will use the LDAPS port 636 and " -"Global Catalog port 3629 with LDAPS protection. Since AD does not allow to " +"3268. If this option is set to True SSSD will use the LDAPS port 636 and " +"Global Catalog port 3269 with LDAPS protection. Since AD does not allow to " "have multiple encryption layers on a single connection and we still want to " "use SASL/GSSAPI or SASL/GSS-SPNEGO for authentication the SASL security " "property maxssf is set to 0 (zero) for those connections." @@ -14797,7 +15278,7 @@ msgstr "" "(noll) för dessa förbindelser." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1164 +#: sssd-ad.5.xml:1169 msgid "" "Optional. This option tells SSSD to automatically update the Active " "Directory DNS server with the IP address of this client. The update is " @@ -14806,12 +15287,12 @@ msgid "" "AD LDAP connection is used for the updates, if it is not otherwise specified " "by using the <quote>dyndns_iface</quote> option." msgstr "" -"Valfritt. Detta alternativ säger till SSSD att automatiskt uppdatera DNS-" -"servern i Active Directory med IP-adressen för denna klient. Uppdateringen " -"säkras med GSS-TSIG. Som en konsekvens av det behöver Active Directory-" -"administratören bara tillåta säkra uppdateringar för DNS-zonen. IP-adressen " -"för AD-LDAP-förbindelsen används för uppdateringar, om det inte specificeras " -"på annat sätt med alternativet <quote>dyndns_iface</quote>." +"Valfritt. Det här alternativet instruerar SSSD att automatiskt uppdatera " +"Active Directory-DNS-servern med klientens IP-adress. Uppdateringen säkras " +"med GSS-TSIG. Därför behöver Active Directory-administratören endast tillåta " +"säkra uppdateringar för DNS-zonen. IP-adressen för AD-LDAP-anslutningen " +"används för uppdateringarna, om inget annat anges med alternativet <quote>" +"dyndns_iface</quote>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:1194 @@ -14821,31 +15302,26 @@ msgstr "Standard: 3600 (sekunder)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:1216 msgid "" -"NOTE: While it is still possible to use the old <emphasis>ipa_dyndns_iface</" -"emphasis> option, users should migrate to using <emphasis>dyndns_iface</" -"emphasis> in their config file." -msgstr "" -"OBS: även om det fortfarande är möjligt att använda det gamla alternativet " -"<emphasis>ipa_dyndns_iface</emphasis> bör användare migrera till att använda " -"<emphasis>dyndns_iface</emphasis> i sin konfigurationsfil." - -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1222 -msgid "" "Default: Use the IP addresses of the interface which is used for AD LDAP " "connection" msgstr "" -"Standard: använd IP-adresser för gränssnittet som används för AD LDAP-" -"förbindelsen" +"Standard: Använd IP-adresserna för gränssnittet som används för AD-LDAP-" +"anslutningen" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1258 +#: sssd-ad.5.xml:1252 +#, fuzzy +#| msgid "" +#| "How often should the back end perform periodic DNS update in addition to " +#| "the automatic update performed when the back end goes online. This " +#| "option is optional and applicable only when dyndns_update is true. Note " +#| "that the lowest possible value is 60 seconds in-case if value is provided " +#| "less than 60, parameter will assume lowest value only." msgid "" "How often should the back end perform periodic DNS update in addition to the " -"automatic update performed when the back end goes online. This option is " -"optional and applicable only when dyndns_update is true. Note that the " -"lowest possible value is 60 seconds in-case if value is provided less than " -"60, parameter will assume lowest value only." +"automatic update performed when the back end goes online. This is optional " +"and applicable only when dyndns_update is true. Note that the minimum value " +"is 60 seconds, any specified value below this threshold will default to 60." msgstr "" "Hur ofta bakänden skall utföra periodiska DNS-uppdateringar utöver den " "automatiska uppdateringen som utförs när bakänden kopplar upp. Detta " @@ -14854,18 +15330,18 @@ msgstr "" "mindre än 60 ges kommer parametern endast anta det lägsta värdet." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ad.5.xml:1472 +#: sssd-ad.5.xml:1465 msgid "" "The following example assumes that SSSD is correctly configured and " "example.com is one of the domains in the <replaceable>[sssd]</replaceable> " "section. This example shows only the AD provider-specific options." msgstr "" -"Följande exempel antar att SSSD är korrekt konfigurerat och att exempel.se " -"är en av domänerna i avsnittet <replaceable>[sssd]</replaceable>. Detta " -"exempel visar endast alternativ som är specifika för leverantören AD." +"Följande exempel förutsätter att SSSD är korrekt konfigurerat och att " +"example.com är en av domänerna i avsnittet <replaceable>[sssd]</replaceable>" +". Exemplet visar endast alternativ som är specifika för AD-leverantören." #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-ad.5.xml:1479 +#: sssd-ad.5.xml:1472 #, no-wrap msgid "" "[domain/EXAMPLE]\n" @@ -14878,18 +15354,18 @@ msgid "" "ad_hostname = client.example.com\n" "ad_domain = example.com\n" msgstr "" -"[domain/EXEMPEL]\n" +"[domain/EXAMPLE]\n" "id_provider = ad\n" "auth_provider = ad\n" "access_provider = ad\n" "chpass_provider = ad\n" "\n" -"ad_server = dc1.exempel.se\n" -"ad_hostname = client.exempel.se\n" -"ad_domain = exempel.se\n" +"ad_server = dc1.example.com\n" +"ad_hostname = client.example.com\n" +"ad_domain = example.com\n" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-ad.5.xml:1499 +#: sssd-ad.5.xml:1492 #, no-wrap msgid "" "access_provider = ldap\n" @@ -14901,18 +15377,18 @@ msgstr "" "ldap_account_expire_policy = ad\n" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ad.5.xml:1495 +#: sssd-ad.5.xml:1488 msgid "" "The AD access control provider checks if the account is expired. It has the " "same effect as the following configuration of the LDAP provider: " "<placeholder type=\"programlisting\" id=\"0\"/>" msgstr "" -"Leverantören AD av åtkomstkontroll kontrollerar om kontot har gått ut. Det " +"AD-leverantören för åtkomststyrning kontrollerar om kontot har löpt ut. Den " "har samma effekt som följande konfiguration av LDAP-leverantören: " "<placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ad.5.xml:1505 +#: sssd-ad.5.xml:1498 msgid "" "However, unless the <quote>ad</quote> access control provider is explicitly " "configured, the default access provider is <quote>permit</quote>. Please " @@ -14920,22 +15396,22 @@ msgid "" "you need to set all the connection parameters (such as LDAP URIs and " "encryption details) manually." msgstr "" -"Dock, om inte åtkomstleverantören <quote>ad</quote> är konfigurerad explicit " -"är standardåtkomstleverantören <quote>permit</quote>. Observera att om man " -"konfigurerar en annan åtkomstleverantör än <quote>ad</quote> behöver man " -"sätta alla anslutningsparametrarna (såsom LDAP URI:er och " -"krypteringsdetaljer) manuellt." +"Om inte åtkomststyrningsleverantören <quote>ad</quote> uttryckligen " +"konfigureras är dock standardleverantören <quote>permit</quote>. Observera " +"att om du konfigurerar en annan åtkomstleverantör än <quote>ad</quote> måste " +"alla anslutningsparametrar (som LDAP-URI:er och krypteringsdetaljer) anges " +"manuellt." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ad.5.xml:1513 +#: sssd-ad.5.xml:1506 msgid "" "When the autofs provider is set to <quote>ad</quote>, the RFC2307 schema " "attribute mapping (nisMap, nisObject, ...) is used, because these attributes " "are included in the default Active Directory schema." msgstr "" -"När autofs-leverantören är satt till <quote>ad</quote> används " -"översättningen av schemaattribut enligt RFC2307 (nisMap, nisObject, …), för " -"att dessa attribut inkluderas i standardschemat för Active Directory." +"När autofs-leverantören anges som <quote>ad</quote> används RFC2307-" +"schemaattributmappningen (nisMap, nisObject, ...), eftersom dessa attribut " +"ingår i Active Directorys standardschema." #. type: Content of: <reference><refentry><refnamediv><refname> #: sssd-sudo.5.xml:10 sssd-sudo.5.xml:16 @@ -14945,7 +15421,7 @@ msgstr "sssd-sudo" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sssd-sudo.5.xml:17 msgid "Configuring sudo with the SSSD back end" -msgstr "Konfigurera sudo med SSSD-bakänden" +msgstr "Konfigurera sudo med SSSD:s bakomliggande komponent" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-sudo.5.xml:23 @@ -14955,15 +15431,15 @@ msgid "" "to work with <citerefentry> <refentrytitle>sssd</refentrytitle> " "<manvolnum>8</manvolnum> </citerefentry> and how SSSD caches sudo rules." msgstr "" -"Denna manualsida beskriver hur man konfigurerar <citerefentry> " -"<refentrytitle>sudo</refentrytitle> <manvolnum>8</manvolnum> </citerefentry> " -"till att fungera med <citerefentry> <refentrytitle>sssd</refentrytitle> " -"<manvolnum>8</manvolnum> </citerefentry> och hur SSSD cachar sudo-regler." +"Den här manualsidan beskriver hur <citerefentry> <refentrytitle>sudo</" +"refentrytitle> <manvolnum>8</manvolnum> </citerefentry> konfigureras för att " +"fungera med <citerefentry> <refentrytitle>sssd</refentrytitle> <manvolnum>8</" +"manvolnum> </citerefentry> och hur SSSD cachar sudo-regler." #. type: Content of: <reference><refentry><refsect1><title> #: sssd-sudo.5.xml:36 msgid "Configuring sudo to cooperate with SSSD" -msgstr "Konfigurera sudo att samarbeta med SSSD" +msgstr "Konfigurera sudo för samverkan med SSSD" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-sudo.5.xml:38 @@ -14973,10 +15449,9 @@ msgid "" "<refentrytitle>nsswitch.conf</refentrytitle> <manvolnum>5</manvolnum> </" "citerefentry>." msgstr "" -"För att aktivera SSSD som en källa för sudo-regler, lägg till <emphasis>sss</" -"emphasis> till posten <emphasis>sudoers</emphasis> i <citerefentry> " -"<refentrytitle>nsswitch.conf</refentrytitle> <manvolnum>5</manvolnum> </" -"citerefentry>." +"Lägg till <emphasis>sss</emphasis> i posten <emphasis>sudoers</emphasis> i " +"<citerefentry> <refentrytitle>nsswitch.conf</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry> för att aktivera SSSD som källa för sudo-regler." #. type: Content of: <reference><refentry><refsect1><para> #: sssd-sudo.5.xml:47 @@ -15031,7 +15506,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><title> #: sssd-sudo.5.xml:82 msgid "Configuring SSSD to fetch sudo rules" -msgstr "Konfigurera SSSD till att hämta sudo-regler" +msgstr "Konfigurera SSSD för att hämta sudo-regler" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-sudo.5.xml:84 @@ -15043,12 +15518,11 @@ msgid "" "search base for sudo rules using <emphasis>ldap_sudo_search_base</emphasis> " "option." msgstr "" -"All konfiguration som behövs på SSSD-sidan är att utöka listan över " -"<emphasis>tjänster</emphasis> med ”sudo” i avsnittet [sssd] i <citerefentry> " -"<refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</manvolnum> </" -"citerefentry>. För att snabba upp LDAP-uppslagningarna kan man även sätta " -"sökbasen för sudo-regler med alternativet <emphasis>ldap_sudo_search_base</" -"emphasis>." +"Den enda konfiguration som behövs på SSSD-sidan är att utöka listan " +"<emphasis>services</emphasis> med \"sudo\" i avsnittet [sssd] i " +"<citerefentry> <refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry>. Du kan även ange sökbasen för sudo-regler med " +"<emphasis>ldap_sudo_search_base</emphasis> för att snabba upp LDAP-uppslagen." #. type: Content of: <reference><refentry><refsect1><para> #: sssd-sudo.5.xml:94 @@ -15075,13 +15549,13 @@ msgid "" msgstr "" "[sssd]\n" "services = nss, pam, sudo\n" -"domains = EXEMPEL\n" +"domains = EXAMPLE\n" "\n" -"[domain/EXEMPEL]\n" +"[domain/EXAMPLE]\n" "id_provider = ldap\n" "sudo_provider = ldap\n" -"ldap_uri = ldap://exempel.se\n" -"ldap_sudo_search_base = ou=sudoers,dc=exempel,dc=se\n" +"ldap_uri = ldap://example.com\n" +"ldap_sudo_search_base = ou=sudoers,dc=example,dc=com\n" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-sudo.5.xml:98 @@ -15093,10 +15567,9 @@ msgid "" "enabled instead. </phrase>" msgstr "" "<placeholder type=\"programlisting\" id=\"0\"/> <phrase " -"condition=\"have_systemd\"> Det är viktigt att observera att på plattformar " -"där systemd stödjs finns det inget behov av att lägga till ”sudo”-" -"leverantören till listan av tjänster, eftersom det blev frivilligt. Dock " -"måste sssd-sudo.socket vara aktiverat istället. </phrase>" +"condition=\"have_systemd\"> Observera att det på plattformar med stöd för " +"systemd inte behövs någon sudo-leverantör i listan services, eftersom den är " +"valfri. I stället måste sssd-sudo.socket vara aktiverad. </phrase>" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-sudo.5.xml:117 @@ -15107,16 +15580,16 @@ msgid "" "sssd.conf, this value will be used instead. The compat tree (ou=sudoers," "$SUFFIX) is no longer required for IPA sudo functionality." msgstr "" -"När SSSD är konfigurerat till att använda IPA som ID-leverantör aktiveras " -"sudo-leverantören automatiskt. Sudo-sökbasen konfigureras till att använda " -"IPA:s egna LDAP-träd (cn=sudo,$SUFFIX). Om någon annan sökbas är definierad " -"i sssd.conf kommer detta värde användas istället. Kompatibilitetsträdet " -"(ou=sudoers,$SUFFIX) behövs inte längre för IPA-sudo-funktionalitet." +"När SSSD konfigureras med IPA som ID-leverantör aktiveras sudo-leverantören " +"automatiskt. Sudo-sökbasen konfigureras för att använda IPA:s inbyggda LDAP-" +"träd (cn=sudo,$SUFFIX). Om någon annan sökbas anges i sssd.conf används den " +"i stället. Kompatibilitetsträdet (ou=sudoers,$SUFFIX) behövs inte längre för " +"IPA:s sudo-funktionalitet." #. type: Content of: <reference><refentry><refsect1><title> #: sssd-sudo.5.xml:127 msgid "The SUDO rule caching mechanism" -msgstr "Cachnings-mekanismen för SUDO-regler" +msgstr "Cachningsmekanismen för SUDO-regler" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-sudo.5.xml:129 @@ -15129,19 +15602,24 @@ msgid "" "refresh." msgstr "" "Den största utmaningen vid utvecklingen av stöd för sudo i SSSD var att " -"säkerställa att köra sudo med SSSD som datakälla ger samma " -"användarupplevelse och är lika snabbt som sudo men tillhandahåller de " -"senaste reglerna så mycket som möjligt. För att uppfylla dessa krav " -"använder SSSD tre sorters uppdateringar. De refereras till som fullständig " -"uppdatering, smart uppdatering och regeluppdatering." +"säkerställa att sudo med SSSD som datakälla ger samma användarupplevelse och " +"är lika snabbt som sudo, samtidigt som reglerna hålls så aktuella som " +"möjligt. För att uppfylla kraven använder SSSD tre typer av uppdatering: " +"fullständig uppdatering, smart uppdatering och regeluppdatering." #. type: Content of: <reference><refentry><refsect1><para> #: sssd-sudo.5.xml:137 +#, fuzzy +#| msgid "" +#| "The <emphasis>smart refresh</emphasis> periodically downloads rules that " +#| "are new or were modified after the last update. Its primary goal is to " +#| "keep the database growing by fetching only small increments that do not " +#| "generate large amounts of network traffic." msgid "" "The <emphasis>smart refresh</emphasis> periodically downloads rules that are " -"new or were modified after the last update. Its primary goal is to keep the " -"database growing by fetching only small increments that do not generate " -"large amounts of network traffic." +"new or were modified after the last update. Its primary goal is to grow the " +"database incrementally by fetching only small updates, avoiding large " +"amounts of network traffic." msgstr "" "Den <emphasis>smarta uppdateringen</emphasis> hämtar periodiskt regler som " "är nya eller ändrades efter den senaste uppdateringen. Dess primära mål är " @@ -15158,12 +15636,11 @@ msgid "" "and thus it should be run only occasionally depending on the size and " "stability of the sudo rules." msgstr "" -"Den <emphasis>fullständiga uppdateringen</emphasis> raderar helt enkelt alla " -"sudo-regler som är lagrade i cachen och ersätter dem med alla regler som är " -"sparade på servern. Detta används för att hålla cachen konsistent genom att " -"ta bort varje regel som var raderad från servern. Dock kan en fullständig " -"uppdatering skapa mycket trafik och den bör alltså bara köras ibland " -"beroende på storleken och stabiliteten hos sudo-reglerna." +"Den <emphasis>fullständiga uppdateringen</emphasis> tar bort alla sudo-" +"regler i cachen och ersätter dem med alla regler på servern. Den håller " +"cachen konsekvent genom att ta bort varje regel som har raderats från " +"servern. En fullständig uppdatering kan dock skapa mycket trafik och bör " +"därför bara köras ibland, beroende på sudo-reglernas storlek och stabilitet." #. type: Content of: <reference><refentry><refsect1><para> #: sssd-sudo.5.xml:151 @@ -15175,13 +15652,13 @@ msgid "" "these rules are missing on the server, the SSSD will do an out of band full " "refresh because more rules (that apply to other users) may have been deleted." msgstr "" -"<emphasis>Regeluppdateringen</emphasis> säkerställer att vi inte ger " -"användaren fler rättigheter än definierat. Den triggas varje gång " -"användaren kör sudo. Regeluppdateringen kommer hitta alla regler som är " -"tillämpliga på den användaren, kontrollera deras utgångstidpunkt och hämta " -"om dem om de gått ut. Ifall att någon av dessa regler saknas på servern " -"kommer SSSD göra en fullständig uppdatering vid sidan av för att fler regler " -"(som är tillämpliga på andra användare) kan ha raderats." +"<emphasis>Regeluppdateringen</emphasis> säkerställer att användaren inte " +"beviljas mer behörighet än vad som definierats. Den utlöses varje gång " +"användaren kör sudo. Regeluppdateringen hittar alla regler som gäller " +"användaren, kontrollerar deras utgångstid och hämtar dem igen om de har löpt " +"ut. Om någon av reglerna saknas på servern utför SSSD en fullständig " +"uppdatering utanför ordinarie flöde, eftersom fler regler som gäller andra " +"användare kan ha raderats." #. type: Content of: <reference><refentry><refsect1><para> #: sssd-sudo.5.xml:160 @@ -15190,8 +15667,8 @@ msgid "" "This means rules that contain one of the following values in " "<emphasis>sudoHost</emphasis> attribute:" msgstr "" -"Om aktiverat kommer SSSD endast lagra regler som kan tillämpas på denna " -"maskin. Detta betyder att regler som innehåller ett av följande värden i " +"Om alternativet är aktiverat lagrar SSSD endast regler som kan tillämpas på " +"datorn. Det innebär regler som innehåller något av följande värden i " "attributet <emphasis>sudoHost</emphasis>:" #. type: Content of: <reference><refentry><refsect1><itemizedlist><listitem><para> @@ -15202,12 +15679,12 @@ msgstr "nyckelordet ALL" #. type: Content of: <reference><refentry><refsect1><itemizedlist><listitem><para> #: sssd-sudo.5.xml:172 msgid "wildcard" -msgstr "jokertecken (wildcard)" +msgstr "jokertecken" #. type: Content of: <reference><refentry><refsect1><itemizedlist><listitem><para> #: sssd-sudo.5.xml:177 msgid "netgroup (in the form \"+netgroup\")" -msgstr "nätgrupp (i formen ”+nätgrupp”)" +msgstr "nätgrupp (i formen \"+netgroup\")" #. type: Content of: <reference><refentry><refsect1><itemizedlist><listitem><para> #: sssd-sudo.5.xml:182 @@ -15222,7 +15699,7 @@ msgstr "en av IP-adresserna till denna maskin" #. type: Content of: <reference><refentry><refsect1><itemizedlist><listitem><para> #: sssd-sudo.5.xml:192 msgid "one of the IP addresses of the network (in the form \"address/mask\")" -msgstr "en av IP-adresserna till nätverket (på formen ”adress/mask”)" +msgstr "en av nätverkets IP-adresser (i formen \"address/mask\")" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-sudo.5.xml:198 @@ -15233,16 +15710,16 @@ msgid "" "citerefentry> and \"sudo_*\" in <citerefentry> <refentrytitle>sssd.conf</" "refentrytitle> <manvolnum>5</manvolnum> </citerefentry>." msgstr "" -"Det finns många konfigurationsalternativ som kan användas för att justera " -"beteendet. Se ”ldap_sudo_*” i <citerefentry> <refentrytitle>sssd-ldap</" -"refentrytitle> <manvolnum>5</manvolnum> </citerefentry> och ”sudo_*” i " -"<citerefentry> <refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</" -"manvolnum> </citerefentry>." +"Det finns många konfigurationsalternativ för att justera beteendet. Se " +"\"ldap_sudo_*\" i <citerefentry> <refentrytitle>sssd-ldap</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry> och \"sudo_*\" i <citerefentry> " +"<refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</manvolnum> </" +"citerefentry>." #. type: Content of: <reference><refentry><refsect1><title> #: sssd-sudo.5.xml:212 msgid "Tuning the performance" -msgstr "Trimning av prestandan" +msgstr "Prestandajustering" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-sudo.5.xml:214 @@ -15254,10 +15731,9 @@ msgid "" "requirements." msgstr "" "SSSD använder olika mekanismer med mer eller mindre komplexa LDAP-filter för " -"att hålla de cachade sudo-reglerna uppdaterade. Standardkonfigurationen är " -"satt till värden som skall passa de flesta av våra användare, men följande " -"stycken innehåller några tips om hur man kan finjustera konfigurationen för " -"sina behov." +"att hålla de cachade sudo-reglerna aktuella. Standardkonfigurationen är " +"inställd på värden som bör passa de flesta användare, men följande stycken " +"innehåller några tips om hur du finjusterar konfigurationen efter dina behov." #. type: Content of: <reference><refentry><refsect1><para> #: sssd-sudo.5.xml:221 @@ -15274,9 +15750,9 @@ msgid "" "2. <emphasis>Set ldap_sudo_search_base</emphasis>. Set the search base to " "the container that holds the sudo rules to limit the scope of the lookup." msgstr "" -"2. <emphasis>Sätt ldap_sudo_search_base</emphasis>. Sätt sökbasen till den " -"behållare som innehåller sudo-reglerna för att begränsa räckvidden för " -"uppslagningen." +"2. <emphasis>Ange ldap_sudo_search_base</emphasis>. Ange sökbasen som den " +"behållare som innehåller sudo-reglerna för att begränsa uppslagningens " +"omfattning." #. type: Content of: <reference><refentry><refsect1><para> #: sssd-sudo.5.xml:231 @@ -15289,12 +15765,12 @@ msgid "" "disabling the smart refresh by setting " "<emphasis>ldap_sudo_smart_refresh_interval = 0</emphasis>." msgstr "" -"3. <emphasis>Sätt fullt och smart uppdateringsintervall</emphasis>. Om ens " -"sudo-regler inte ändras ofta och man inte behöver snabba uppdateringar av " -"cachade regler på sina klienter kan man avsevärt öka <emphasis>" +"3. <emphasis>Ange intervall för fullständig och smart uppdatering</emphasis>" +". Om sudo-reglerna inte ändras ofta och du inte behöver snabba uppdateringar " +"av cachade regler på klienterna kan du överväga att öka <emphasis>" "ldap_sudo_full_refresh_interval</emphasis> och <emphasis>" -"ldap_sudo_smart_refresh_interval</emphasis>. Man kan också överväga att " -"avaktivera den smarta uppdateringen genom att sätta <emphasis>" +"ldap_sudo_smart_refresh_interval</emphasis>. Du kan också överväga att " +"inaktivera smart uppdatering genom att ange <emphasis>" "ldap_sudo_smart_refresh_interval = 0</emphasis>." #. type: Content of: <reference><refentry><refsect1><para> @@ -15304,9 +15780,9 @@ msgid "" "value of <emphasis>ldap_sudo_random_offset</emphasis> to distribute the load " "on the server better." msgstr "" -"4. Om man har ett stort antal klienter kan man överväga att öka värdet på " -"<emphasis>ldap_sudo_random_offset</emphasis> för att fördela lasten på " -"servern bättre." +"4. Om du har många klienter kan du överväga att öka värdet för <emphasis>" +"ldap_sudo_random_offset</emphasis> för att fördela belastningen bättre på " +"servern." #. type: Content of: <reference><refentry><refnamediv><refname> #: sssd-idp.5.xml:10 sssd-idp.5.xml:16 @@ -15327,10 +15803,10 @@ msgid "" "FORMAT</quote> section of the <citerefentry> <refentrytitle>sssd.conf</" "refentrytitle> <manvolnum>5</manvolnum> </citerefentry> manual page." msgstr "" -"Denna manual beskriver konfigurationen av IdP-leverantören för " +"Den här manualsidan beskriver konfigurationen av IdP-leverantören för " "<citerefentry> <refentrytitle>sssd</refentrytitle> <manvolnum>8</manvolnum> " -"</citerefentry>. För en detaljerad syntaxreferens, se avsnittet <quote>" -"FILFORMAT</quote> i manualen för <citerefentry> <refentrytitle>sssd.conf</" +"</citerefentry>. En detaljerad syntaxreferens finns i avsnittet <quote>" +"FILFORMAT</quote> på manualsidan <citerefentry> <refentrytitle>sssd.conf</" "refentrytitle> <manvolnum>5</manvolnum> </citerefentry>." #. type: Content of: <reference><refentry><refsect1><para> @@ -15342,11 +15818,11 @@ msgid "" "dedicated code might be required, see the <quote>idp_type</quote> option for " "details." msgstr "" -"IdP-leverantören är en bakände som används för att ansluta till en OAuth " -"2.0- och REST-baserad identitetsleverantör (IdP). Eftersom produkter kan ha " -"individuell implementering av REST API för att söka efter användar- och " -"gruppattribut kan särskild kod krävas. Se alternativet <quote>idp_type</" -"quote> för mer information." +"IdP-leverantören är en bakomliggande komponent som används för att ansluta " +"till en OAuth 2.0- och REST-baserad identitetsleverantör (IdP). Eftersom " +"produkter kan ha egna implementationer av REST API för uppslagning av " +"användar- och gruppattribut kan särskild kod krävas. Mer information finns i " +"<quote>idp_type</quote>." #. type: Content of: <reference><refentry><refsect1><para> #: sssd-idp.5.xml:43 @@ -15381,11 +15857,20 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-idp.5.xml:70 +#, fuzzy +#| msgid "" +#| "Depending on the IdP product additional platform specific options might " +#| "follow the name separated by a colon (:). E.g. for Keycloak the base URI " +#| "for the user and group REST API must be given. For Entra ID this is not " +#| "needed because there is a generic endpoint for all tenants." msgid "" "Depending on the IdP product additional platform specific options might " "follow the name separated by a colon (:). E.g. for Keycloak the base URI for " -"the user and group REST API must be given. For Entra ID this is not needed " -"because there is a generic endpoint for all tenants." +"the user and group REST API must be given. For Entra ID the base URI for the " +"Microsoft Graph API can be given to use sovereign or government cloud " +"endpoints instead of the default (https://graph.microsoft.com/v1.0). E.g. " +"<quote>entra_id:https://graph.microsoft.us/v1.0</quote> for the US " +"government cloud (GCC High)." msgstr "" "Beroende på IdP-produkten kan ytterligare plattformsspecifika alternativ " "följa efter namnet, åtskilda med ett kolon (:). För Keycloak måste till " @@ -15393,17 +15878,17 @@ msgstr "" "detta inte eftersom det finns en generisk slutpunkt för alla hyresgäster." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:78 sssd-idp.5.xml:94 sssd-idp.5.xml:119 +#: sssd-idp.5.xml:82 sssd-idp.5.xml:98 sssd-idp.5.xml:123 msgid "Default: Not set (Required)" -msgstr "Standard: Inte inställt (obligatoriskt)" +msgstr "Standard: Inte angivet (obligatoriskt)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:83 +#: sssd-idp.5.xml:87 msgid "idp_client_id (string)" msgstr "idp_client_id (sträng)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:86 +#: sssd-idp.5.xml:90 msgid "" "ID of the IdP client used by SSSD to authenticate users and as a client to " "lookup user and group attributes. This client must offer device " @@ -15416,12 +15901,12 @@ msgstr "" "att söka och läsa användar- och gruppattribut." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:99 +#: sssd-idp.5.xml:103 msgid "idp_client_secret (string)" msgstr "idp_client_secret (sträng)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:102 +#: sssd-idp.5.xml:106 msgid "" "Password of the IdP client. The password is required for the id_provider. If " "only used as auth_provider it depends on the server side configuration if it " @@ -15432,22 +15917,22 @@ msgstr "" "krävs eller inte." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:113 +#: sssd-idp.5.xml:117 msgid "idp_token_endpoint (string)" msgstr "idp_token_endpoint (sträng)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:116 +#: sssd-idp.5.xml:120 msgid "IdP endpoint for requesting access tokens." msgstr "IdP-slutpunkt för att begära åtkomsttoken." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:124 +#: sssd-idp.5.xml:128 msgid "idp_device_auth_endpoint (string)" msgstr "idp_device_auth_endpoint (sträng)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:127 +#: sssd-idp.5.xml:131 msgid "" "IdP endpoint for device authorization according to RFC-8628. This is " "required for user authentication." @@ -15456,92 +15941,195 @@ msgstr "" "användarautentisering." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:137 +#: sssd-idp.5.xml:141 msgid "idp_userinfo_endpoint (string)" msgstr "idp_userinfo_endpoint (sträng)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:140 +#: sssd-idp.5.xml:144 msgid "" "IdP userinfo endpoint to request user attributes after a successful " "authentication of the user. Required for authentication." msgstr "" -"Slutpunkt för IdP-användarinformation för att begära användarattribut efter " -"en lyckad autentisering av användaren. Krävs för autentisering." +"IdP-userinfo-slutpunkt för att begära användarattribut efter att användaren " +"har autentiserats. Krävs för autentisering." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:150 +#: sssd-idp.5.xml:154 msgid "idp_id_scope (string)" msgstr "idp_id_scope (sträng)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:153 +#: sssd-idp.5.xml:157 msgid "" "Scope required for looking up user and group attributes with the REST API. " "The scopes are used by the server to determine which attributes/claims are " "returned to the caller." msgstr "" -"Omfattning som krävs för att söka efter användar- och gruppattribut med REST " -"API. Omfattningarna används av servern för att avgöra vilka attribut/anspråk " -"som ska returneras till den som gör anropet." +"Scope som krävs för att slå upp användar- och gruppattribut med REST API. " +"Scope används av servern för att avgöra vilka attribut/claims som returneras " +"till anroparen." + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:163 +msgid "" +"Note: In previous versions of SSSD, this option was expected to already be " +"URL-encoded." +msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:164 +#: sssd-idp.5.xml:172 msgid "idp_auth_scope (string)" msgstr "idp_auth_scope (sträng)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:167 +#: sssd-idp.5.xml:175 msgid "" "Scope required during authentication. The scopes are used by the server to " "determine which attributes/claims are returned to the caller." msgstr "" -"Omfattning som krävs vid autentisering. Omfattningarna används av servern " -"för att avgöra vilka attribut/anspråk som ska returneras till den som " -"anropar." +"Scope som krävs vid autentisering. Scope används av servern för att avgöra " +"vilka attribut/claims som returneras till anroparen." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:172 +#: sssd-idp.5.xml:180 msgid "" "Currently the tokens returned during user authentication are not used for " "other purposes hence the only important claim is the subject identifier " "'sub' which is used to check if the authenticated user is the one trying to " "log in. This might change in future." msgstr "" -"För närvarande används inte de tokens som returneras under " -"användarautentisering för andra ändamål, varför det enda viktiga kravet är " -"ämnesidentifieraren \"sub\", som används för att kontrollera om den " -"autentiserade användaren är den som försöker logga in. Detta kan komma att " -"ändras i framtiden." +"För närvarande används token som returneras vid användarautentisering inte " +"för andra syften. Därför är det enda viktiga anspråket subject identifier " +"'sub', som används för att kontrollera att den autentiserade användaren är " +"den som försöker logga in. Detta kan ändras i framtiden." + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-idp.5.xml:193 +#, fuzzy +#| msgid "ldap_user_extra_attrs (string)" +msgid "idp_auth_user_identifier_attr (string)" +msgstr "ldap_user_extra_attrs (sträng)" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:196 +msgid "" +"Attribute used to identify the authenticated user in userinfo data or token " +"claims." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:200 +msgid "" +"For hybrid Active Directory and Entra ID deployments where " +"<quote>id_provider = ad</quote> and <quote>auth_provider = idp</quote>, this " +"option must be set explicitly. No value is derived from the identity " +"provider, because more than one attribute can link an Entra ID object to its " +"on-premises counterpart and only the administrator knows which one the " +"directory synchronization is configured to use." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:211 +msgid "" +"Setting this option to <quote>onPremisesImmutableId</quote> is the usual " +"choice for such deployments. Microsoft Entra Connect populates that " +"attribute with the base64-encoded form of the 16-byte Active Directory " +"<quote>objectGUID</quote> when objectGUID is used as the sourceAnchor. SSSD " +"decodes the value and converts the raw bytes with the same conversion used " +"for AD objectGUID attributes, so the result matches the UUID stored in the " +"SSSD cache for the AD user." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:224 +msgid "" +"Note that Microsoft Entra Connect 1.1.524.0 and later use <quote>ms-DS-" +"ConsistencyGuid</quote> as the sourceAnchor for user objects instead of " +"<quote>objectGUID</quote>. The value is normally copied from objectGUID for " +"objects that do not have it set yet, in which case the decoded identifier " +"still matches. It does not match if ms-DS-ConsistencyGuid was populated " +"independently, if users were moved between forests or domains, or if a " +"different attribute such as employeeID was selected as the sourceAnchor. See " +"<ulink url=\"https://learn.microsoft.com/en-us/entra/identity/hybrid/connect/" +"plan-connect-design-concepts\"> Microsoft Entra Connect: Design concepts</" +"ulink> for details on sourceAnchor selection." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:241 +msgid "" +"Microsoft Graph does not return <quote>onPremisesImmutableId</quote> by " +"default. The <quote>idp_userinfo_endpoint</quote> must request it with " +"<quote>$select</quote>, see the example below and <ulink url=\"https://" +"learn.microsoft.com/en-us/graph/api/resources/user\"> the Microsoft Graph " +"user resource type</ulink>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:251 +msgid "" +"If the configured attribute is missing or cannot be decoded (for example " +"cloud-only Entra ID users without <quote>onPremisesImmutableId</quote>), " +"authentication fails. SSSD does not fall back to another attribute when this " +"option is set." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:258 +msgid "" +"Default: not set, <quote>sub</quote> for Keycloak and <quote>id</quote> for " +"other IdP types" +msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:185 +#: sssd-idp.5.xml:264 msgid "idp_request_timeout (integer)" msgstr "idp_request_timeout (heltal)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:188 +#: sssd-idp.5.xml:267 msgid "Timeout in seconds for an individual request to the IdP." msgstr "Tidsgräns i sekunder för en enskild begäran till IdP." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:197 +#: sssd-idp.5.xml:276 +#, fuzzy +#| msgid "ldap_referrals (boolean)" +msgid "idp_auto_refresh (boolean)" +msgstr "ldap_referrals (boolean)" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:279 +msgid "" +"Refresh tokens automatically, after they have reached about half their " +"lifetime." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:283 +msgid "" +"Note: Scheduled token refreshes are not preserved across restarts of SSSD." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-idp.5.xml:292 msgid "idmap_range_min (integer)" msgstr "idmap_range_min (heltal)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:200 +#: sssd-idp.5.xml:295 msgid "" "Specifies the lower (inclusive) bound of the range of POSIX IDs to use for " "mapping IdP users and group to POSIX IDs. It is the first POSIX ID which can " "be used for the mapping." msgstr "" -"Anger den nedre (inklusive) gränsen för intervallet av POSIX-ID som ska " -"användas för att mappa IdP-användare och -grupper till POSIX-ID. Det är det " -"första POSIX-ID som kan användas för mappningen." +"Anger den nedre, inklusive gränsen för intervallet med POSIX-ID:n som " +"används för att mappa IdP-användare och -grupper till POSIX-ID:n. Det är det " +"första POSIX-ID:t som kan användas för mappningen." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:206 +#: sssd-idp.5.xml:301 msgid "" "The interval between <quote>idmap_range_min</quote> and " "<quote>idmap_range_max</quote> will be split into smaller ranges of size " @@ -15553,79 +16141,143 @@ msgstr "" "idmap_range_size</quote> som kommer att användas av en enskild IdP-domän." #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:213 sssd-idp.5.xml:239 include/ldap_id_mapping.xml:139 +#: sssd-idp.5.xml:308 sssd-idp.5.xml:334 include/ldap_id_mapping.xml:139 #: include/ldap_id_mapping.xml:197 msgid "Default: 200000" msgstr "Standard: 200000" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:218 +#: sssd-idp.5.xml:313 msgid "idmap_range_max (integer)" msgstr "idmap_range_max (heltal)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:221 +#: sssd-idp.5.xml:316 msgid "" "Specifies the upper (exclusive) bound of the range of POSIX IDs to use for " "mapping IdP users and groups to POSIX IDs. It is the first POSIX ID which " "will not be used for POSIX ID-mapping anymore." msgstr "" -"Anger den övre (exklusiva) gränsen för intervallet av POSIX-ID som ska " -"användas för att mappa IdP-användare och -grupper till POSIX-ID. Det är det " -"första POSIX-ID som inte längre kommer att användas för POSIX-ID-mappning." +"Anger den övre, exklusive gränsen för intervallet med POSIX-ID:n som används " +"för att mappa IdP-användare och -grupper till POSIX-ID:n. Det är det första " +"POSIX-ID:t som inte längre används för POSIX-ID-mappning." #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:227 include/ldap_id_mapping.xml:165 +#: sssd-idp.5.xml:322 include/ldap_id_mapping.xml:165 msgid "Default: 2000200000" msgstr "Standard: 2000200000" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:232 +#: sssd-idp.5.xml:327 msgid "idmap_range_size (integer)" msgstr "idmap_range_size (heltal)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:235 +#: sssd-idp.5.xml:330 msgid "Specifies the number of POSIX IDs available for a single IdP domain." msgstr "Anger antalet POSIX-ID som är tillgängliga för en enskild IdP-domän." #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-idp.5.xml:251 -#, no-wrap +#: sssd-idp.5.xml:346 +#, fuzzy, no-wrap +#| msgid "" +#| "[domain/entra_id]\n" +#| "id_provider = idp\n" +#| "idp_type = entra_id\n" +#| "idp_client_id = 12345678-abcd-0101-efef-ba9876543210\n" +#| "idp_client_secret = YOUR-CLIENT-SCERET\n" +#| "idp_token_endpoint = https://login.microsoftonline.com/TENNANT-ID/oauth2/v2.0/token\n" +#| "idp_userinfo_endpoint = https://graph.microsoft.com/v1.0/me\n" +#| "idp_device_auth_endpoint = https://login.microsoftonline.com/TENNANT-ID/oauth2/v2.0/devicecode\n" +#| "idp_id_scope = https%3A%2F%2Fgraph.microsoft.com%2F.default\n" +#| "idp_auth_scope = openid profile email\n" msgid "" "[domain/entra_id]\n" "id_provider = idp\n" "idp_type = entra_id\n" "idp_client_id = 12345678-abcd-0101-efef-ba9876543210\n" -"idp_client_secret = YOUR-CLIENT-SCERET\n" +"idp_client_secret = YOUR-CLIENT-SECRET\n" +"idp_token_endpoint = https://login.microsoftonline.com/TENANT-ID/oauth2/v2.0/token\n" +"idp_userinfo_endpoint = https://graph.microsoft.com/v1.0/me\n" +"idp_device_auth_endpoint = https://login.microsoftonline.com/TENANT-ID/oauth2/v2.0/devicecode\n" +"idp_id_scope = https://graph.microsoft.com/.default\n" +"idp_auth_scope = openid profile email\n" +msgstr "" +"[domain/entra_id]\n" +"id_provider = idp\n" +"idp_type = entra_id\n" +"idp_client_id = 12345678-abcd-0101-efef-ba9876543210\n" +"idp_client_secret = DIN-KLIENTHEMLIGHET\n" "idp_token_endpoint = https://login.microsoftonline.com/TENNANT-ID/oauth2/v2.0/token\n" "idp_userinfo_endpoint = https://graph.microsoft.com/v1.0/me\n" "idp_device_auth_endpoint = https://login.microsoftonline.com/TENNANT-ID/oauth2/v2.0/devicecode\n" "idp_id_scope = https%3A%2F%2Fgraph.microsoft.com%2F.default\n" "idp_auth_scope = openid profile email\n" + +#. type: Content of: <reference><refentry><refsect1><para><programlisting> +#: sssd-idp.5.xml:358 +#, fuzzy, no-wrap +#| msgid "" +#| "[domain/entra_id]\n" +#| "id_provider = idp\n" +#| "idp_type = entra_id\n" +#| "idp_client_id = 12345678-abcd-0101-efef-ba9876543210\n" +#| "idp_client_secret = YOUR-CLIENT-SCERET\n" +#| "idp_token_endpoint = https://login.microsoftonline.com/TENNANT-ID/oauth2/v2.0/token\n" +#| "idp_userinfo_endpoint = https://graph.microsoft.com/v1.0/me\n" +#| "idp_device_auth_endpoint = https://login.microsoftonline.com/TENNANT-ID/oauth2/v2.0/devicecode\n" +#| "idp_id_scope = https%3A%2F%2Fgraph.microsoft.com%2F.default\n" +#| "idp_auth_scope = openid profile email\n" +msgid "" +"[domain/ad.example.com]\n" +"id_provider = ad\n" +"auth_provider = idp\n" +"access_provider = permit\n" +"\n" +"ad_domain = ad.example.com\n" +"krb5_realm = AD.EXAMPLE.COM\n" +"\n" +"idp_type = entra_id\n" +"idp_client_id = 12345678-abcd-0101-efef-ba9876543210\n" +"idp_client_secret = YOUR-CLIENT-SECRET\n" +"idp_token_endpoint = https://login.microsoftonline.com/TENANT-ID/oauth2/v2.0/token\n" +"idp_userinfo_endpoint = https://graph.microsoft.com/v1.0/me?$select=id,userPrincipalName,onPremisesImmutableId\n" +"idp_device_auth_endpoint = https://login.microsoftonline.com/TENANT-ID/oauth2/v2.0/devicecode\n" +"idp_id_scope = https://graph.microsoft.com/.default\n" +"idp_auth_scope = openid profile email\n" +"idp_auth_user_identifier_attr = onPremisesImmutableId\n" msgstr "" "[domain/entra_id]\n" "id_provider = idp\n" "idp_type = entra_id\n" "idp_client_id = 12345678-abcd-0101-efef-ba9876543210\n" "idp_client_secret = DIN-KLIENTHEMLIGHET\n" -"idp_token_endpoint = https://login.microsoftonline.com/TENNANT-ID/oauth2/" -"v2.0/token\n" +"idp_token_endpoint = https://login.microsoftonline.com/TENNANT-ID/oauth2/v2.0/token\n" "idp_userinfo_endpoint = https://graph.microsoft.com/v1.0/me\n" -"idp_device_auth_endpoint = https://login.microsoftonline.com/TENNANT-ID/" -"oauth2/v2.0/devicecode\n" +"idp_device_auth_endpoint = https://login.microsoftonline.com/TENNANT-ID/oauth2/v2.0/devicecode\n" "idp_id_scope = https%3A%2F%2Fgraph.microsoft.com%2F.default\n" "idp_auth_scope = openid profile email\n" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-idp.5.xml:263 -#, no-wrap +#: sssd-idp.5.xml:377 +#, fuzzy, no-wrap +#| msgid "" +#| "[domain/keycloak]\n" +#| "idp_type = keycloak:https://master.keycloak.test:8443/auth/admin/realms/master/\n" +#| "id_provider = idp\n" +#| "idp_client_id = myclient\n" +#| "idp_client_secret = YOUR-CLIENT-SCERET\n" +#| "idp_token_endpoint = https://master.keycloak.test:8443/auth/realms/master/protocol/openid-connect/token\n" +#| "idp_userinfo_endpoint = https://master.keycloak.test:8443/auth/realms/master/protocol/openid-connect/userinfo\n" +#| "idp_device_auth_endpoint = https://master.keycloak.test:8443/auth/realms/master/protocol/openid-connect/auth/device\n" +#| "idp_id_scope = profile\n" +#| "idp_auth_scope = openid profile email\n" msgid "" "[domain/keycloak]\n" "idp_type = keycloak:https://master.keycloak.test:8443/auth/admin/realms/master/\n" "id_provider = idp\n" "idp_client_id = myclient\n" -"idp_client_secret = YOUR-CLIENT-SCERET\n" +"idp_client_secret = YOUR-CLIENT-SECRET\n" "idp_token_endpoint = https://master.keycloak.test:8443/auth/realms/master/protocol/openid-connect/token\n" "idp_userinfo_endpoint = https://master.keycloak.test:8443/auth/realms/master/protocol/openid-connect/userinfo\n" "idp_device_auth_endpoint = https://master.keycloak.test:8443/auth/realms/master/protocol/openid-connect/auth/device\n" @@ -15633,29 +16285,41 @@ msgid "" "idp_auth_scope = openid profile email\n" msgstr "" "[domain/keycloak]\n" -"idp_type = keycloak:https://master.keycloak.test:8443/auth/admin/realms/" -"master/\n" +"idp_type = keycloak:https://master.keycloak.test:8443/auth/admin/realms/master/\n" "id_provider = idp\n" "idp_client_id = myclient\n" "idp_client_secret = DIN-KLIENTHEMLIGHET\n" -"idp_token_endpoint = https://master.keycloak.test:8443/auth/realms/master/" -"protocol/openid-connect/token\n" -"idp_userinfo_endpoint = https://master.keycloak.test:8443/auth/realms/master/" -"protocol/openid-connect/userinfo\n" -"idp_device_auth_endpoint = https://master.keycloak.test:8443/auth/realms/" -"master/protocol/openid-connect/auth/device\n" +"idp_token_endpoint = https://master.keycloak.test:8443/auth/realms/master/protocol/openid-connect/token\n" +"idp_userinfo_endpoint = https://master.keycloak.test:8443/auth/realms/master/protocol/openid-connect/userinfo\n" +"idp_device_auth_endpoint = https://master.keycloak.test:8443/auth/realms/master/protocol/openid-connect/auth/device\n" "idp_id_scope = profile\n" "idp_auth_scope = openid profile email\n" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-idp.5.xml:250 +#: sssd-idp.5.xml:345 +#, fuzzy +#| msgid "" +#| "<placeholder type=\"programlisting\" id=\"0\"/> <placeholder " +#| "type=\"programlisting\" id=\"1\"/>" msgid "" "<placeholder type=\"programlisting\" id=\"0\"/> <placeholder " -"type=\"programlisting\" id=\"1\"/>" +"type=\"programlisting\" id=\"1\"/> <placeholder type=\"programlisting\" " +"id=\"2\"/>" msgstr "" "<placeholder type=\"programlisting\" id=\"0\"/> <placeholder " "type=\"programlisting\" id=\"1\"/>" +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-idp.5.xml:390 +msgid "" +"In the hybrid Active Directory and Entra ID example above, " +"<quote>onPremisesImmutableId</quote> is used during authentication so the " +"IdP result matches the AD objectGUID UUID stored in the SSSD cache. The " +"attribute must be requested via <quote>$select</quote> on the Graph userinfo " +"endpoint and is only populated for users synchronized from Active Directory " +"with objectGUID as the sourceAnchor." +msgstr "" + #. type: Content of: <reference><refentry><refnamediv><refname> #: sssd.8.xml:10 sssd.8.xml:15 msgid "sssd" @@ -15664,7 +16328,7 @@ msgstr "sssd" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sssd.8.xml:16 msgid "System Security Services Daemon" -msgstr "Demonen för systemsäkerhetstjänster" +msgstr "Bakgrundsprocessen System Security Services" #. type: Content of: <reference><refentry><refsynopsisdiv><cmdsynopsis> #: sssd.8.xml:21 @@ -15672,7 +16336,7 @@ msgid "" "<command>sssd</command> <arg choice='opt'> <replaceable>options</" "replaceable> </arg>" msgstr "" -"<command>sssd</command> <arg choice='opt'> <replaceable>flaggor</" +"<command>sssd</command> <arg choice='opt'> <replaceable>options</" "replaceable> </arg>" #. type: Content of: <reference><refentry><refsect1><para> @@ -15686,14 +16350,14 @@ msgid "" "FreeIPA. It provides a more robust database to store local users as well as " "extended user data." msgstr "" -"<command>SSSD</command> tillhandahåller en uppsättning demoner för att " -"hantera åtkomst till fjärrkataloger och autentiseringsmekanismer. Det " -"tillhandahåller ett NSS- och PAM-gränssnitt mot systemet och ett system med " -"insticksmoduler till bakänden för att ansluta till flera olika kontokällor, " -"såväl som ett D-Bus-gränssnitt. Det är också basen för att tillhandahålla " -"klientgranskning och policytjänster för projekt som FreeIPA. Det " -"tillhandahåller en mer robust databas att spara lokala användare såväl som " -"utökade användardata." +"<command>SSSD</command> tillhandahåller en uppsättning bakgrundsprocesser " +"för att hantera åtkomst till fjärrkataloger och autentiseringsmekanismer. " +"Den tillhandahåller ett NSS- och PAM-gränssnitt mot systemet, ett " +"insticksbart system för bakomliggande komponenter som ansluter till flera " +"olika kontokällor samt ett D-Bus-gränssnitt. Den är också grunden för " +"gransknings- och principtjänster på klientsidan i projekt som FreeIPA. Den " +"tillhandahåller en robust databas för att lagra lokala användare och utökade " +"användardata." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.8.xml:46 @@ -15701,13 +16365,13 @@ msgid "" "<option>-d</option>,<option>--debug-level</option> <replaceable>LEVEL</" "replaceable>" msgstr "" -"<option>-d</option>,<option>--debug-level</option> <replaceable>NIVÅ</" +"<option>-d</option>,<option>--debug-level</option> <replaceable>LEVEL</" "replaceable>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.8.xml:53 msgid "<option>--debug-timestamps=</option><replaceable>mode</replaceable>" -msgstr "<option>--debug-timestamps=</option><replaceable>läge</replaceable>" +msgstr "<option>--debug-timestamps=</option><replaceable>mode</replaceable>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.8.xml:57 @@ -15719,12 +16383,12 @@ msgstr "" #: sssd.8.xml:60 msgid "<emphasis>0</emphasis>: Disable timestamp in the debug messages" msgstr "" -"<emphasis>0</emphasis>: Avaktivera tidsstämpeln i felsökningsmeddelanden" +"<emphasis>0</emphasis>: Inaktivera tidsstämpel i felsökningsmeddelandena" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.8.xml:69 msgid "<option>--debug-microseconds=</option><replaceable>mode</replaceable>" -msgstr "<option>--debug-microseconds=</option><replaceable>läge</replaceable>" +msgstr "<option>--debug-microseconds=</option><replaceable>mode</replaceable>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.8.xml:73 @@ -15737,17 +16401,17 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.8.xml:76 msgid "<emphasis>0</emphasis>: Disable microseconds in timestamp" -msgstr "<emphasis>0</emphasis>: Avaktivera mikrosekunder i tidsstämpeln" +msgstr "<emphasis>0</emphasis>: Inaktivera mikrosekunder i tidsstämpeln" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.8.xml:85 msgid "<option>--logger=</option><replaceable>value</replaceable>" -msgstr "<option>--logger=</option><replaceable>värde</replaceable>" +msgstr "<option>--logger=</option><replaceable>value</replaceable>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.8.xml:89 msgid "Location where SSSD will send log messages." -msgstr "Platsen dit SSSD kommer skicka loggmeddelanden." +msgstr "Plats dit SSSD skickar loggmeddelanden." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.8.xml:92 @@ -15755,8 +16419,8 @@ msgid "" "<emphasis>stderr</emphasis>: Redirect debug messages to standard error " "output." msgstr "" -"<emphasis>stderr</emphasis>: Omdirigera felmeddelanden till standard fel-" -"utmatning." +"<emphasis>stderr</emphasis>: Omdirigera felsökningsmeddelanden till " +"standardfelutmatningen." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.8.xml:96 @@ -15782,8 +16446,8 @@ msgstr "" msgid "" "Default: not set (fall back to journald if available, otherwise to stderr)" msgstr "" -"Standard: inte satt (fall tillbaka på journald om den är tillgänglig, annars " -"standard fel)" +"Standard: inte angivet (använd journald om det är tillgängligt, annars " +"stderr)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.8.xml:113 @@ -15793,7 +16457,7 @@ msgstr "<option>-D</option>,<option>--daemon</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.8.xml:117 msgid "Become a daemon after starting up." -msgstr "Bli en demon efter att ha startat upp." +msgstr "Kör som bakgrundsprocess efter start." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.8.xml:123 sss_seed.8.xml:136 @@ -15803,7 +16467,7 @@ msgstr "<option>-i</option>,<option>--interactive</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.8.xml:127 msgid "Run in the foreground, don't become a daemon." -msgstr "Kör i förgrunden, bli inte en demon." +msgstr "Kör i förgrunden, inte som bakgrundsprocess." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.8.xml:133 @@ -15818,10 +16482,11 @@ msgid "" "consult the <citerefentry> <refentrytitle>sssd.conf</refentrytitle> " "<manvolnum>5</manvolnum> </citerefentry> manual page." msgstr "" -"Ange en annan konfigurationsfil än standard. Standard är <filename>/etc/" -"sssd/sssd.conf</filename>. För referens till konfigurationsfilsyntaxen och -" -"alternativ, konsultera manualsidan <citerefentry> <refentrytitle>sssd.conf</" -"refentrytitle> <manvolnum>5</manvolnum> </citerefentry>." +"Ange en konfigurationsfil som inte är standardfilen. Standardfilen är " +"<filename>/etc/sssd/sssd.conf</filename>. Information om " +"konfigurationsfilens syntax och alternativ finns på manualsidan " +"<citerefentry> <refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry>." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.8.xml:151 @@ -15849,8 +16514,8 @@ msgid "" "Informs the SSSD to gracefully terminate all of its child processes and then " "shut down the monitor." msgstr "" -"Säger till SSSD att snyggt avsluta alla dess barnprocesser och sedan stänga " -"av monitorn." +"Instruerar SSSD att avsluta alla barnprocesser ordnat och sedan stänga av " +"övervakaren." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.8.xml:175 @@ -15864,9 +16529,9 @@ msgid "" "close and reopen them. This is meant to facilitate log rolling with programs " "like logrotate." msgstr "" -"Säger till SSSD att sluta skriva till dess aktuella felsökningsfilbeskrivare " -"och stänga och öppna om dem. Detta är tänkt att möjliggöra loggrullning med " -"program som logrotate." +"Instruerar SSSD att sluta skriva till de aktuella filbeskrivarna för " +"felsökning, stänga dem och öppna dem igen. Detta underlättar loggrotation " +"med program som logrotate." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.8.xml:186 @@ -15881,10 +16546,10 @@ msgid "" "signal can be sent to either the sssd process or any sssd_be process " "directly." msgstr "" -"Säger till SSSD att simulera frånkopplad funktion under tiden hos parametern " -"<quote>offline_timeout</quote>. Detta är användbart för att testa. " -"Signalen kan skickas antingen till sssd-processen eller direkt till någon " -"sssd_be-process." +"Instruerar SSSD att simulera frånkopplad drift under den tid som anges av " +"parametern <quote>offline_timeout</quote>. Detta är användbart för testning. " +"Signalen kan skickas direkt till sssd-processen eller en valfri sssd_be-" +"process." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.8.xml:198 @@ -15898,9 +16563,9 @@ msgid "" "signal can be sent to either the sssd process or any sssd_be process " "directly." msgstr "" -"Säger till SSSD att gå till uppkopplat läge omedelbart. Detta är användbart " -"för att testa. Signalen kan skickas antingen till sssd-processen eller " -"direkt till någon sssd_be-process." +"Instruerar SSSD att omedelbart ansluta. Detta är användbart för testning. " +"Signalen kan skickas direkt till sssd-processen eller en valfri sssd_be-" +"process." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.8.xml:208 @@ -15914,9 +16579,9 @@ msgid "" "this signal to the providers when a clock shift is detected although it can " "be sent to any sssd_be process directly." msgstr "" -"Säger till SSSD:n att schemalägga om de periodiska uppgifterna. Den interna " -"vakthunde skickar denna signal till leverantörerna när en klockförändring " -"upptäcks även om den kan skickas direkt till en sssd_be-process." +"Instruerar SSSD att schemalägga om de periodiska uppgifterna. Den interna " +"vakthunden skickar signalen till leverantörerna när en klockändring " +"upptäcks, men den kan även skickas direkt till en valfri sssd_be-process." #. type: Content of: <reference><refentry><refsect1><title> #: sssd.8.xml:223 sss_ssh_authorizedkeys.1.xml:141 sss_ssh_knownhosts.1.xml:116 @@ -15931,7 +16596,7 @@ msgstr "0" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.8.xml:229 msgid "SSSD was shutdown gracefully." -msgstr "SSSD stängdes av snyggt." +msgstr "SSSD stängdes av ordnat." #. type: Content of: <reference><refentry><refmeta><manvolnum> #: sssd.8.xml:234 sss_ssh_authorizedkeys.1.xml:11 sss_ssh_knownhosts.1.xml:11 @@ -15974,8 +16639,8 @@ msgid "" "Other codes denote different errors, most probably about missing required " "access rights. See SSSD and system logs for details." msgstr "" -"Andra koder markerar andra olika fel, sannolikt om saknade nödvändiga " -"åtkomsträttigheter. Se SSSD:s och systemets loggar för detaljer." +"Andra koder anger olika fel, troligen om nödvändiga åtkomsträttigheter " +"saknas. Mer information finns i SSSD:s och systemets loggar." #. type: Content of: <reference><refentry><refsect1><para> #: sssd.8.xml:272 @@ -15983,8 +16648,8 @@ msgid "" "If the environment variable SSS_NSS_USE_MEMCACHE is set to \"NO\", client " "applications will not use the fast in-memory cache." msgstr "" -"Om miljövariabeln SSS_NSS_USE_MEMCACHE är satt till ”NO” kommer " -"klientprogram inte använda den snabba cachen i minnet." +"Om miljövariabeln SSS_NSS_USE_MEMCACHE anges som \"NO\" använder " +"klientprogrammen inte den snabba minnescachen." #. type: Content of: <reference><refentry><refsect1><para> #: sssd.8.xml:276 @@ -15992,8 +16657,8 @@ msgid "" "If the environment variable SSS_LOCKFREE is set to \"NO\", requests from " "multiple threads of a single application will be serialized." msgstr "" -"Om miljövariabeln SSS_LOCKFREE är satt till ”NO” kommer begäranden från " -"multipla trådar i ett enskilt program att seriaaliseras." +"Om miljövariabeln SSS_LOCKFREE anges som \"NO\" serialiseras begäranden från " +"flera trådar i ett och samma program." #. type: Content of: <reference><refentry><refnamediv><refname> #: sss_obfuscate.8.xml:10 sss_obfuscate.8.xml:15 @@ -16003,7 +16668,7 @@ msgstr "sss_obfuscate" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sss_obfuscate.8.xml:16 msgid "obfuscate a clear text password" -msgstr "fördunkla ett klartextlösenord" +msgstr "maskera ett klartextlösenord" #. type: Content of: <reference><refentry><refsynopsisdiv><cmdsynopsis> #: sss_obfuscate.8.xml:21 @@ -16012,8 +16677,8 @@ msgid "" "replaceable> </arg> <arg choice='plain'><replaceable>[PASSWORD]</" "replaceable></arg>" msgstr "" -"<command>sss_obfuscate</command> <arg choice='opt'> <replaceable>flaggor</" -"replaceable> </arg> <arg choice='plain'><replaceable>[LÖSENORD]</replaceable>" +"<command>sss_obfuscate</command> <arg choice='opt'> <replaceable>options</" +"replaceable> </arg> <arg choice='plain'><replaceable>[PASSWORD]</replaceable>" "</arg>" #. type: Content of: <reference><refentry><refsect1><para> @@ -16023,9 +16688,9 @@ msgid "" "unreadable format and places it into appropriate domain section of the SSSD " "config file." msgstr "" -"<command>sss_obfuscate</command> konverterar ett givet lösenord till ett " -"format oläsbart för människor och placerar det i det passande domänavsnittet " -"av SSSD-konfigurationsfilen." +"<command>sss_obfuscate</command> konverterar ett angivet lösenord till ett " +"format som inte kan läsas av människor och placerar det i rätt domänavsnitt " +"i SSSD-konfigurationsfilen." #. type: Content of: <reference><refentry><refsect1><para> #: sss_obfuscate.8.xml:37 @@ -16038,13 +16703,13 @@ msgid "" "<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> </" "citerefentry> for more details on these parameters." msgstr "" -"Klartextlösenordet läses från standard in eller skrivs interaktivt. Det " -"fördunklade lösenordet läggs in i parametern <quote>ldap_default_authtok</" -"quote> av en given SSSD-domän och parametern <quote>" -"ldap_default_authtok_type</quote> sätts till <quote>obfuscated_password</" -"quote>. Se <citerefentry> <refentrytitle>sssd-ldap</refentrytitle> " -"<manvolnum>5</manvolnum> </citerefentry> för fler detaljer om dessa " -"parametrar." +"Klartextlösenordet läses från standardindata eller anges interaktivt. Det " +"maskerade lösenordet placeras i parametern <quote>ldap_default_authtok</" +"quote> för en angiven SSSD-domän och parametern <quote>" +"ldap_default_authtok_type</quote> anges som <quote>obfuscated_password</" +"quote>. Mer information om parametrarna finns i <citerefentry> " +"<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> </" +"citerefentry>." #. type: Content of: <reference><refentry><refsect1><para> #: sss_obfuscate.8.xml:49 @@ -16055,11 +16720,10 @@ msgid "" "such as client side certificates or GSSAPI is <emphasis>strongly</emphasis> " "advised." msgstr "" -"Observera att fördunklandet av lösenord ger <emphasis>ingen riktigt " -"säkerhetsförbättring</emphasis> eftersom det fortfarande är möjligt för en " -"anfallare att återskapa lösenordet. Det rekommenderas <emphasis>starkt</" -"emphasis> att använda en bättre autentiseringsmekanism såsom " -"klientsidecertifikat eller GSSAPI." +"Observera att maskering av lösenordet <emphasis>inte ger någon verklig " +"säkerhetsfördel</emphasis>, eftersom en angripare fortfarande kan återskapa " +"lösenordet. Bättre autentiseringsmekanismer, som certifikat på klientsidan " +"eller GSSAPI, rekommenderas <emphasis>starkt</emphasis>." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_obfuscate.8.xml:63 @@ -16069,7 +16733,7 @@ msgstr "<option>-s</option>,<option>--stdin</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_obfuscate.8.xml:67 msgid "The password to obfuscate will be read from standard input." -msgstr "Lösenordet att fördunkla kommer läsas från standard in." +msgstr "Lösenordet som ska maskeras läses från standardindata." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_obfuscate.8.xml:74 sss_ssh_authorizedkeys.1.xml:127 @@ -16087,7 +16751,7 @@ msgid "" "The SSSD domain to use the password in. The default name is <quote>default</" "quote>." msgstr "" -"SSSD-domäner att använda lösenordet i. Standardnamnet är <quote>default</" +"SSSD-domänen där lösenordet ska användas. Standardnamnet är <quote>default</" "quote>." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> @@ -16124,8 +16788,8 @@ msgid "" "replaceable></arg> <arg choice='opt'> <replaceable>options</replaceable> </" "arg>" msgstr "" -"<command>sss_override</command> <arg choice='plain'><replaceable>KOMMANDO</" -"replaceable></arg> <arg choice='opt'> <replaceable>flaggor</replaceable> </" +"<command>sss_override</command> <arg choice='plain'><replaceable>COMMAND</" +"replaceable></arg> <arg choice='opt'> <replaceable>options</replaceable> </" "arg>" #. type: Content of: <reference><refentry><refsect1><para> @@ -16135,9 +16799,9 @@ msgid "" "allows to change selected values of specific user and groups. This change " "takes effect only on local machine." msgstr "" -"<command>sss_override</command> gör det möjligt att skapa en klientsidevy " -"och tillåter att man ändrar valda värden på specifika användare och " -"grupper. Denna ändring gäller endast på den lokala maskinen." +"<command>sss_override</command> gör det möjligt att skapa en vy på " +"klientsidan och ändra valda värden för specifika användare och grupper. " +"Ändringen gäller endast på den lokala datorn." #. type: Content of: <reference><refentry><refsect1><para> #: sss_override.8.xml:37 @@ -16150,13 +16814,12 @@ msgid "" "take effect. <emphasis>sss_override</emphasis> prints message when a " "restart is required." msgstr "" -"Data om åsidosättanden lagras i SSSD-cachen. Om cachen raderas förloras " -"alla lokala åsidosättanden. Observera att efter det första åsidosättandet " -"har skapats med något av följande kommandon <emphasis>user-add</emphasis>, " -"<emphasis>group-add</emphasis>, <emphasis>user-import</emphasis> eller " -"<emphasis>group-import</emphasis> behöver SSSD startas om för att det skall " -"få effekt. <emphasis>sss_override</emphasis> skriver ett meddelande när en " -"omstart behövs." +"Data om åsidosättningar lagras i SSSD-cachen. Om cachen raderas förloras " +"alla lokala åsidosättningar. Observera att SSSD måste startas om efter att " +"den första åsidosättningen skapats med något av kommandona <emphasis>user-" +"add</emphasis>, <emphasis>group-add</emphasis>, <emphasis>user-import</" +"emphasis> eller <emphasis>group-import</emphasis>. <emphasis>sss_override</" +"emphasis> skriver ett meddelande när en omstart krävs." #. type: Content of: <reference><refentry><refsect1><para> #: sss_override.8.xml:48 @@ -16165,9 +16828,9 @@ msgid "" "with <quote>ldap</quote> and <quote>AD</quote> <quote> id_provider</quote>. " "IPA overrides can be managed centrally on the IPA server." msgstr "" -"<emphasis>OBSERVERA:</emphasis> alternativen som ges i denna manualsida " -"fungerar endast med <quote>id_provider</quote> <quote>ldap</quote> och " -"<quote>AD</quote>. IPA-åsidosättanden kan hanteras centralt på IPA-servern." +"<emphasis>OBS:</emphasis> Alternativen på den här manualsidan fungerar " +"endast med <quote>ldap</quote> och <quote>AD</quote> <quote> id_provider</" +"quote>. IPA-åsidosättningar kan hanteras centralt på IPA-servern." #. type: Content of: <reference><refentry><refsect1><title> #: sss_override.8.xml:56 sssctl.8.xml:41 @@ -16181,9 +16844,9 @@ msgid "" "commands. It is not possible to override <emphasis>uid</emphasis> or " "<emphasis>gid</emphasis> to 0." msgstr "" -"Argumentet <emphasis>NAMN</emphasis> är namnet på originalobjektet i alla " -"kommandon. Det är inte möjligt att åsidosätta <emphasis>uid</emphasis> " -"eller <emphasis>gid</emphasis> till 0." +"Argumentet <emphasis>NAME</emphasis> är namnet på originalobjektet i alla " +"kommandon. Det går inte att åsidosätta <emphasis>uid</emphasis> eller " +"<emphasis>gid</emphasis> med 0." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_override.8.xml:65 @@ -16196,13 +16859,13 @@ msgid "" "optional> <optional><option>-x,--certificate</option> BASE64 ENCODED " "CERTIFICATE</optional>" msgstr "" -"<option>user-add</option> <emphasis>NAMN</emphasis> <optional><option>-n,--" -"name</option> NAMN</optional> <optional><option>-u,--uid</option> AID</" +"<option>user-add</option> <emphasis>NAME</emphasis> <optional><option>-n,--" +"name</option> NAME</optional> <optional><option>-u,--uid</option> UID</" "optional> <optional><option>-g,--gid</option> GID</optional> <optional>" -"<option>-h,--home</option> HEM</optional> <optional><option>-s,--shell</" -"option> SKAL</optional> <optional><option>-c,--gecos</option> GECOS</" -"optional> <optional><option>-x,--certificate</option> BASE64-KODAT " -"CERTIFIKAT</optional>" +"<option>-h,--home</option> HOME</optional> <optional><option>-s,--shell</" +"option> SHELL</optional> <optional><option>-c,--gecos</option> GECOS</" +"optional> <optional><option>-x,--certificate</option> BASE64 ENCODED " +"CERTIFICATE</optional>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_override.8.xml:78 @@ -16210,14 +16873,13 @@ msgid "" "Override attributes of an user. Please be aware that calling this command " "will replace any previous override for the (NAMEd) user." msgstr "" -"Åsidosätt attribut på en användare. Var medveten om att anropa detta " -"kommando kommer ersätta eventuella tidigare åsidosättanden för (den " -"NAMNgivna) användaren." +"Åsidosätt attribut för en användare. Observera att detta kommando ersätter " +"en tidigare åsidosättning för användaren som anges med NAME." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_override.8.xml:86 msgid "<option>user-del</option> <emphasis>NAME</emphasis>" -msgstr "<option>user-del</option> <emphasis>NAMN</emphasis>" +msgstr "<option>user-del</option> <emphasis>NAME</emphasis>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_override.8.xml:91 @@ -16226,9 +16888,9 @@ msgid "" "returned from memory cache. Please see SSSD option " "<emphasis>memcache_timeout</emphasis> for more details." msgstr "" -"Ta bort användaråsidosättanden. Var dock medveten om att åsidosatta " -"attribut kan returneras från minnescachen. Se SSSD-alternativet <emphasis>" -"memcache_timeout</emphasis> för fler detaljer." +"Ta bort åsidosättningar av användare. Observera dock att åsidosatta attribut " +"kan returneras från minnescachen. Mer information finns i SSSD-alternativet " +"<emphasis>memcache_timeout</emphasis>." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_override.8.xml:100 @@ -16236,7 +16898,7 @@ msgid "" "<option>user-find</option> <optional><option>-d,--domain</option> DOMAIN</" "optional>" msgstr "" -"<option>user-find</option> <optional><option>-d,--domain</option> DOMÄN</" +"<option>user-find</option> <optional><option>-d,--domain</option> DOMAIN</" "optional>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> @@ -16245,13 +16907,13 @@ msgid "" "List all users with set overrides. If <emphasis>DOMAIN</emphasis> parameter " "is set, only users from the domain are listed." msgstr "" -"Lista alla användare med satta åsidosättanden. Om parametern <emphasis>" -"DOMÄN</emphasis> är satt listas endast användare från den domänen." +"Lista alla användare med angivna åsidosättningar. Om parametern <emphasis>" +"DOMAIN</emphasis> anges listas endast användare från domänen." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_override.8.xml:113 msgid "<option>user-show</option> <emphasis>NAME</emphasis>" -msgstr "<option>user-show</option> <emphasis>NAMN</emphasis>" +msgstr "<option>user-show</option> <emphasis>NAME</emphasis>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_override.8.xml:118 @@ -16261,7 +16923,7 @@ msgstr "Visa användaråsidosättanden." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_override.8.xml:124 msgid "<option>user-import</option> <emphasis>FILE</emphasis>" -msgstr "<option>user-import</option> <emphasis>FIL</emphasis>" +msgstr "<option>user-import</option> <emphasis>FILE</emphasis>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_override.8.xml:129 @@ -16269,13 +16931,13 @@ msgid "" "Import user overrides from <emphasis>FILE</emphasis>. Data format is " "similar to standard passwd file. The format is:" msgstr "" -"Importera användaråsidosättanden från <emphasis>FIL</emphasis>. " -"Dataformatet liknar den vanliga passwd-filen. Formatet är:" +"Importera åsidosättningar av användare från <emphasis>FILE</emphasis>. " +"Dataformatet liknar standardfilen passwd. Formatet är:" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_override.8.xml:134 msgid "original_name:name:uid:gid:gecos:home:shell:base64_encoded_certificate" -msgstr "ursprungligt_namn:namn:aid:gid:gecos:hem:skal:bas64-kodat_certifikat" +msgstr "original_name:name:uid:gid:gecos:home:shell:base64_encoded_certificate" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_override.8.xml:137 @@ -16284,24 +16946,24 @@ msgid "" "overridden. The rest of fields correspond to new values. You can omit a " "value simply by leaving corresponding field empty." msgstr "" -"där ursprungligt_namn är användarens originalnamn vars attribut skall " -"åsidosättas. Resten av fälten motsvarar nya värden. Man kan utelämna ett " -"värde helt enkelt genom att lämna motsvarande fält tomt." +"där original_name är originalnamnet på användaren vars attribut ska " +"åsidosättas. Övriga fält motsvarar nya värden. Du kan utelämna ett värde " +"genom att lämna motsvarande fält tomt." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_override.8.xml:146 msgid "ckent:superman::::::" -msgstr "kwalker:fantomen::::::" +msgstr "ckent:superman::::::" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_override.8.xml:149 msgid "ckent@krypton.com::501:501:Superman:/home/earth:/bin/bash:" -msgstr "kwalker@bangalla.com::501:501:Fantomen:/home/bangalla:/bin/bash:" +msgstr "ckent@krypton.com::501:501:Superman:/home/earth:/bin/bash:" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_override.8.xml:155 msgid "<option>user-export</option> <emphasis>FILE</emphasis>" -msgstr "<option>user-export</option> <emphasis>FIL</emphasis>" +msgstr "<option>user-export</option> <emphasis>FILE</emphasis>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_override.8.xml:160 @@ -16309,8 +16971,8 @@ msgid "" "Export all overridden attributes and store them in <emphasis>FILE</" "emphasis>. See <emphasis>user-import</emphasis> for data format." msgstr "" -"Exportera alla åsidosatta attribut och spara dem i <emphasis>FIL</emphasis>" -". Se <emphasis>user-import</emphasis> för dataformatet." +"Exportera alla åsidosatta attribut och lagra dem i <emphasis>FILE</emphasis>" +". Se <emphasis>user-import</emphasis> för dataformatet." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_override.8.xml:168 @@ -16319,8 +16981,8 @@ msgid "" "name</option> NAME</optional> <optional><option>-g,--gid</option> GID</" "optional>" msgstr "" -"<option>group-add</option> <emphasis>NAMN</emphasis> <optional><option>-n,--" -"name</option> NAMN</optional> <optional><option>-g,--gid</option> GID</" +"<option>group-add</option> <emphasis>NAME</emphasis> <optional><option>-n,--" +"name</option> NAME</optional> <optional><option>-g,--gid</option> GID</" "optional>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> @@ -16329,14 +16991,13 @@ msgid "" "Override attributes of a group. Please be aware that calling this command " "will replace any previous override for the (NAMEd) group." msgstr "" -"Åsidosätt attribut på en grupp. Var medveten om att anropa detta kommando " -"kommer ersätta eventuella tidigare åsidosättanden för (den NAMNgivna) " -"gruppen." +"Åsidosätt attribut för en grupp. Observera att kommandot ersätter en " +"tidigare åsidosättning för gruppen som anges med NAME." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_override.8.xml:183 msgid "<option>group-del</option> <emphasis>NAME</emphasis>" -msgstr "<option>group-del</option> <emphasis>NAMN</emphasis>" +msgstr "<option>group-del</option> <emphasis>NAME</emphasis>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_override.8.xml:188 @@ -16345,9 +17006,9 @@ msgid "" "returned from memory cache. Please see SSSD option " "<emphasis>memcache_timeout</emphasis> for more details." msgstr "" -"Ta bort gruppåsidosättanden. Var dock medveten om att åsidosatta attribut " -"kan returneras från minnescachen. Se SSSD-alternativet <emphasis>" -"memcache_timeout</emphasis> för fler detaljer." +"Ta bort åsidosättningar av grupper. Observera dock att åsidosatta attribut " +"kan returneras från minnescachen. Mer information finns i SSSD-alternativet " +"<emphasis>memcache_timeout</emphasis>." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_override.8.xml:197 @@ -16355,7 +17016,7 @@ msgid "" "<option>group-find</option> <optional><option>-d,--domain</option> DOMAIN</" "optional>" msgstr "" -"<option>group-find</option> <optional><option>-d,--domain</option> DOMÄN</" +"<option>group-find</option> <optional><option>-d,--domain</option> DOMAIN</" "optional>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> @@ -16364,13 +17025,13 @@ msgid "" "List all groups with set overrides. If <emphasis>DOMAIN</emphasis> " "parameter is set, only groups from the domain are listed." msgstr "" -"Lista alla grupper med satta åsidosättanden. Om parametern <emphasis>DOMÄN</" -"emphasis> är satt listas endast grupper från den domänen." +"Lista alla grupper med angivna åsidosättningar. Om parametern <emphasis>" +"DOMAIN</emphasis> anges listas endast grupper från domänen." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_override.8.xml:210 msgid "<option>group-show</option> <emphasis>NAME</emphasis>" -msgstr "<option>group-show</option> <emphasis>NAMN</emphasis>" +msgstr "<option>group-show</option> <emphasis>NAME</emphasis>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_override.8.xml:215 @@ -16380,7 +17041,7 @@ msgstr "Visa gruppåsidosättanden." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_override.8.xml:221 msgid "<option>group-import</option> <emphasis>FILE</emphasis>" -msgstr "<option>grupp-import</option> <emphasis>FIL</emphasis>" +msgstr "<option>group-import</option> <emphasis>FILE</emphasis>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_override.8.xml:226 @@ -16388,13 +17049,13 @@ msgid "" "Import group overrides from <emphasis>FILE</emphasis>. Data format is " "similar to standard group file. The format is:" msgstr "" -"Importera gruppåsidosättanden från <emphasis>FIL</emphasis>. Dataformatet " -"liknar den vanliga group-filen. Formatet är:" +"Importera åsidosättningar av grupper från <emphasis>FILE</emphasis>. " +"Dataformatet liknar standardfilen group. Formatet är:" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_override.8.xml:231 msgid "original_name:name:gid" -msgstr "ursprungligt_namn:namn:gid" +msgstr "original_name:name:gid" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_override.8.xml:234 @@ -16403,14 +17064,14 @@ msgid "" "overridden. The rest of fields correspond to new values. You can omit a " "value simply by leaving corresponding field empty." msgstr "" -"där ursprungligt_namn är gruppens originalnamn vars attribut skall " -"åsidosättas. Resten av fälten motsvarar nya värden. Man kan utelämna ett " -"värde helt enkelt genom att lämna motsvarande fält tomt." +"där original_name är originalnamnet på gruppen vars attribut ska " +"åsidosättas. Övriga fält motsvarar nya värden. Du kan utelämna ett värde " +"genom att lämna motsvarande fält tomt." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_override.8.xml:243 msgid "admins:administrators:" -msgstr "admin:administratorer:" +msgstr "admins:administrators:" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_override.8.xml:246 @@ -16420,7 +17081,7 @@ msgstr "Domain Users:Users:501" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_override.8.xml:252 msgid "<option>group-export</option> <emphasis>FILE</emphasis>" -msgstr "<option>group-export</option> <emphasis>FIL</emphasis>" +msgstr "<option>group-export</option> <emphasis>FILE</emphasis>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_override.8.xml:257 @@ -16428,23 +17089,23 @@ msgid "" "Export all overridden attributes and store them in <emphasis>FILE</" "emphasis>. See <emphasis>group-import</emphasis> for data format." msgstr "" -"Exportera alla åsidosatta attribut och spara dem i <emphasis>FIL</emphasis>" -". Se <emphasis>group-import</emphasis> för dataformatet." +"Exportera alla åsidosatta attribut och lagra dem i <emphasis>FILE</emphasis>" +". Se <emphasis>group-import</emphasis> för dataformatet." #. type: Content of: <reference><refentry><refsect1><title> #: sss_override.8.xml:267 sssctl.8.xml:50 msgid "COMMON OPTIONS" -msgstr "GEMENSAMMA FLAGGOR" +msgstr "GEMENSAMMA ALTERNATIV" #. type: Content of: <reference><refentry><refsect1><para> #: sss_override.8.xml:269 sssctl.8.xml:52 msgid "Those options are available with all commands." -msgstr "Dessa flaggor är tillgängliga med alla kommandon." +msgstr "Dessa alternativ är tillgängliga för alla kommandon." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_override.8.xml:274 sssctl.8.xml:57 msgid "<option>--debug</option> <replaceable>LEVEL</replaceable>" -msgstr "<option>--debug</option> <replaceable>NIVÅ</replaceable>" +msgstr "<option>--debug</option> <replaceable>LEVEL</replaceable>" #. type: Content of: <reference><refentry><refnamediv><refname> #: sssd-krb5.5.xml:10 sssd-krb5.5.xml:16 @@ -16466,12 +17127,12 @@ msgid "" "the <citerefentry> <refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</" "manvolnum> </citerefentry> manual page." msgstr "" -"Denna manualsida beskriver konfigurationen av bakänden för Kerberos 5-" -"autentisering för <citerefentry> <refentrytitle>sssd</refentrytitle> " -"<manvolnum>8</manvolnum> </citerefentry>. För en detaljerad syntaxreferens, " -"se avsnittet <quote>FILFORMAT</quote> i manualsidan <citerefentry> " -"<refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</manvolnum> </" -"citerefentry>." +"Den här manualsidan beskriver konfigurationen av den bakomliggande " +"komponenten för Kerberos 5-autentisering för <citerefentry> <refentrytitle>" +"sssd</refentrytitle> <manvolnum>8</manvolnum> </citerefentry>. En detaljerad " +"syntaxreferens finns i avsnittet <quote>FILFORMAT</quote> på manualsidan " +"<citerefentry> <refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry>." #. type: Content of: <reference><refentry><refsect1><para> #: sssd-krb5.5.xml:36 @@ -16485,14 +17146,14 @@ msgid "" "page for the applicable identity provider for details on how to configure " "this." msgstr "" -"Kerberos 5-autentiseringsbakänden innehåller auth- och chpass-leverantörer. " -"Den måste paras ihop med en identitetsleverantör för att fungera korrekt " -"(till exempel, id_provider = ldap). En del information krävs av Kerberos 5-" -"autentiseringsbakänden måste tillhandahållas av identitetsleverantören, " -"såsom användarens Kerberos huvudmannanamn (UPN). Konfigurationen av " -"identitetsleverantören skall ha en post för att ange UPN:en. Se manualsidan " -"för den tillämpliga identitetsleverantören för detaljer om hur man " -"konfigurerar detta." +"Den bakomliggande komponenten för Kerberos 5-autentisering innehåller " +"leverantörerna auth och chpass. Den måste paras ihop med en " +"identitetsleverantör för att fungera korrekt (till exempel id_provider = " +"ldap). Identitetsleverantören måste tillhandahålla viss information som " +"behövs för Kerberos 5-autentisering, till exempel användarens Kerberos " +"Principal Name (UPN). Identitetsleverantörens konfiguration ska innehålla en " +"post som anger UPN. Mer information finns på manualsidan för den aktuella " +"identitetsleverantören." #. type: Content of: <reference><refentry><refsect1><para> #: sssd-krb5.5.xml:47 @@ -16504,12 +17165,12 @@ msgid "" "To activate this feature, use 'access_provider = krb5' in your SSSD " "configuration." msgstr "" -"Denna bakände tillhandahåller även åtkomstkontroll baserad på filen .k5login " -"i användarens hemkatalog Se <citerefentry> <refentrytitle>k5login</" -"refentrytitle><manvolnum>5</manvolnum> </citerefentry> för mer detaljer. " -"Observera att en tom .k5login-fil kommer neka all åtkomst till denna " -"användare. För att aktivera denna funktion, använd ”access_provider = krb5” " -"i din SSSD-konfiguration." +"Den bakomliggande komponenten tillhandahåller även åtkomststyrning baserad " +"på filen .k5login i användarens hemkatalog. Mer information finns i " +"<citerefentry> <refentrytitle>k5login</refentrytitle><manvolnum>5</" +"manvolnum> </citerefentry>. Observera att en tom .k5login-fil nekar " +"användaren all åtkomst. Använd 'access_provider = krb5' i SSSD-" +"konfigurationen för att aktivera funktionen." #. type: Content of: <reference><refentry><refsect1><para> #: sssd-krb5.5.xml:55 @@ -16533,12 +17194,12 @@ msgid "" "discovery is enabled; for more information, refer to the <quote>SERVICE " "DISCOVERY</quote> section." msgstr "" -"Anger en kommaseparerad lista av IP-adresser eller värdnamn till " -"Kerberosservrar till vilka SSSD skall ansluta, i prioritetsordning. För mer " -"information om reserver och serverredundans se avsnittet <quote>RESERVER</" -"quote>. Ett frivilligt portnummer (föregånget av ett kolon) kan läggas till " -"till adresserna eller värdnamnen. Om tomt aktiveras tjänsteupptäckt; för " -"mer information, se avsnittet <quote>TJÄNSTEUPPTÄCKT</quote>." +"Anger den kommaseparerade listan med IP-adresser eller värdnamn för Kerberos-" +"servrar som SSSD ska ansluta till i prioritetsordning. Mer information om " +"reservväxling och serverredundans finns i avsnittet <quote>RESERVVÄXLING</" +"quote>. Ett valfritt portnummer, föregånget av kolon, kan läggas till efter " +"adresser eller värdnamn. Om listan är tom aktiveras tjänsteidentifiering; " +"mer information finns i avsnittet <quote>TJÄNSTEIDENTIFIERING</quote>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:106 @@ -16572,10 +17233,10 @@ msgid "" "servers to try, the backend is not switched to operate offline if " "authentication against the KDC is still possible." msgstr "" -"För mer information om reserver och serverredundans se avsnittet <quote>" -"RESERVER</quote>. OBSERVERA: även om det inte finns några fler kpasswd-" -"servrar att försöka med byter inte bakänden till att köra frånkopplat om " -"autentisering mot KDC:n fortfarande är möjligt." +"Mer information om reservväxling och serverredundans finns i avsnittet " +"<quote>RESERVVÄXLING</quote>. OBS: Även om det inte finns fler kpasswd-" +"servrar att prova växlar den bakomliggande komponenten inte till frånkopplad " +"drift om autentisering mot KDC:n fortfarande är möjlig." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:129 @@ -16594,9 +17255,9 @@ msgid "" "krb5_ccname_template can be used here, too, except %d and %P. The directory " "is created as private and owned by the user, with permissions set to 0700." msgstr "" -"Katalog att lagra kreditiv-cachar i. Alla substitutionssekvenserna i " -"krb5_ccname_template kan användas här också, utom %d och %P. Katalogen " -"skapas som privat och ägd av användaren, med rättigheterna satta till 0700." +"Katalog där cacheminnen för autentiseringsuppgifter lagras. Alla " +"ersättningssekvenser i krb5_ccname_template kan användas här utom %d och %P. " +"Katalogen skapas privat, ägs av användaren och får behörigheterna 0700." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:145 @@ -16626,7 +17287,7 @@ msgstr "%U" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:170 msgid "login UID" -msgstr "inloggnings-AID" +msgstr "inloggnings-UID" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd-krb5.5.xml:173 @@ -16646,7 +17307,7 @@ msgstr "%r" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:179 msgid "realm name" -msgstr "namn på rike" +msgstr "realmnamn" #. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd-krb5.5.xml:182 include/override_homedir.xml:53 @@ -16686,7 +17347,7 @@ msgstr "%%" #. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:200 include/override_homedir.xml:69 msgid "a literal '%'" -msgstr "ett bokstavligt ”%”" +msgstr "ett bokstavligt '%'" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:154 @@ -16700,13 +17361,14 @@ msgid "" "the template ends with 'XXXXXX' mkstemp(3) is used to create a unique " "filename in a safe way." msgstr "" -"Platsen för användarens kreditiv-cache. Tre typer av kreditiv-cachar stödjs " -"för närvarande: <quote>FILE</quote>, <quote>DIR</quote> och <quote>" -"KEYRING:persistent</quote>. Cachen kan anges antingen som <replaceable>" -"TYP:ÅTERSTOD</replaceable>, eller som en absolut sökväg, vilket implicerar " -"typen <quote>FILE</quote>. I mallen ersätts följande sekvenser: " -"<placeholder type=\"variablelist\" id=\"0\"/> Om mallen slutar med ”XXXXXX” " -"används mkstemp(3) för att skapa ett unikt filnamn på ett säkert sätt." +"Platsen för användarens cache för autentiseringsuppgifter. Tre typer av " +"cache för autentiseringsuppgifter stöds för närvarande: <quote>FILE</quote>, " +"<quote>DIR</quote> och <quote>KEYRING:persistent</quote>. Cachen kan anges " +"antingen som <replaceable>TYPE:RESIDUAL</replaceable> eller som en absolut " +"sökväg, vilket innebär typen <quote>FILE</quote>. I mallen ersätts följande " +"sekvenser: <placeholder type=\"variablelist\" id=\"0\"/> Om mallen slutar " +"med 'XXXXXX' används mkstemp(3) för att skapa ett unikt filnamn på ett " +"säkert sätt." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:208 @@ -16716,10 +17378,10 @@ msgid "" "store credentials on a per-UID basis. This is also the recommended choice, " "as it is the most secure and predictable method." msgstr "" -"När KEYRING-typer används är den enda mekanismen som stödjs <quote>" -"KEYRING:persistent:%U</quote>, vilket använder Linuxkärnans nyckelring för " -"att lagra kreditiv på per-AID-bas. Detta är också det rekommenderade valet, " -"eftersom det är den säkraste och mest förutsägbara metoden." +"När KEYRING-typer används är den enda mekanism som stöds <quote>" +"KEYRING:persistent:%U</quote>, vilken använder Linuxkärnans nyckelring för " +"att lagra autentiseringsuppgifter per UID. Detta är också det rekommenderade " +"valet, eftersom det är den säkraste och mest förutsägbara metoden." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:216 @@ -16730,11 +17392,11 @@ msgid "" "PARAMETER EXPANSION paragraph for additional information on the expansion " "format defined by krb5.conf." msgstr "" -"Standardvärdet för namnet på kreditiv-cachen läses från profilen som fil " -"sparad i den systemtäckande konfigurationsfilen krb5.conf i avsnittet " -"[libdefaults]. Alternativnamnet är default_ccache_name. Se krb5.conf(5)s " -"avsnitt PARAMETEREXPANSION för mer information om expansionsformatet som " -"definieras av krb5.conf." +"Standardvärdet för namnet på cachen för autentiseringsuppgifter hämtas från " +"profilen i den systemomfattande konfigurationsfilen krb5.conf, i avsnittet " +"[libdefaults]. Alternativet heter default_ccache_name. Se avsnittet " +"PARAMETER EXPANSION i krb5.conf(5) för mer information om det " +"expansionsformat som definieras av krb5.conf." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:225 @@ -16763,13 +17425,13 @@ msgid "" "The location of the keytab to use when validating credentials obtained from " "KDCs." msgstr "" -"Platsen där keytab:en som skall användas för validering av kreditiv som tas " -"emot från KDC:er finns." +"Platsen för den keytab som används för att validera autentiseringsuppgifter " +"från KDC:er." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-krb5.5.xml:253 msgid "krb5_store_password_if_offline (boolean)" -msgstr "krb5_store_password_if_offline (boolean)" +msgstr "krb5_store_password_if_offline (boolesk)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:256 @@ -16777,8 +17439,8 @@ msgid "" "Store the password of the user if the provider is offline and use it to " "request a TGT when the provider comes online again." msgstr "" -"Spara lösenordet för användaren om leverantören är frånkopplad och använd " -"det för att begära en TGT när leverantören blir uppkopplad igen." +"Spara användarens lösenord om leverantören är frånkopplad och använd det för " +"att begära en TGT när leverantören ansluter igen." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:261 @@ -16826,9 +17488,13 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:291 +#, fuzzy +#| msgid "" +#| "<emphasis>demand</emphasis> to use FAST. The authentication fails if the " +#| "server does not require fast." msgid "" "<emphasis>demand</emphasis> to use FAST. The authentication fails if the " -"server does not require fast." +"server does not support FAST." msgstr "" "<emphasis>demand</emphasis> kräv användning av FAST. Autentiseringen " "misslyckas om servern inte begär fast." @@ -16836,7 +17502,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:296 msgid "Default: not set, i.e. FAST is not used." -msgstr "Standard: inte satt, d.v.s. FAST används inte." +msgstr "Standard: inte angivet, dvs. FAST används inte." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:299 @@ -16868,7 +17534,7 @@ msgstr "Anger serverhuvudmannen att använda för FAST." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-krb5.5.xml:321 msgid "krb5_fast_use_anonymous_pkinit (boolean)" -msgstr "krb5_fast_use_anonymous_pkinit (boolean)" +msgstr "krb5_fast_use_anonymous_pkinit (boolesk)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:324 @@ -16877,9 +17543,9 @@ msgid "" "required credential for FAST. The krb5_fast_principal options is ignored in " "this case." msgstr "" -"Om satt till sant, försök använda anonym PKINIT istället för en keytab för " -"att få de begärda kreditiven för FAST. Alternativet krb5_fast_prinicpal " -"ignoreras i detta fall." +"Om värdet är true, försök använda anonym PKINIT i stället för en keytab för " +"att hämta den autentiseringsuppgift som krävs för FAST. Alternativet " +"krb5_fast_principal ignoreras i detta fall." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-krb5.5.xml:364 @@ -16894,11 +17560,10 @@ msgid "" "refentrytitle> <manvolnum>8</manvolnum> </citerefentry>. This might be " "helpful when there are too many servers discovered using SRV record." msgstr "" -"När krb5_use_kdcinfo är satt till true kan man begränsa mängden servrar som " -"skickas till <citerefentry> <refentrytitle>sssd_krb5_locator_plugin</" -"refentrytitle> <manvolnum>8</manvolnum> </citerefentry>. Detta kan vara " -"användbart när det finns för många servrar som upptäcks med hjälp av SRV-" -"poster." +"När krb5_use_kdcinfo är satt till true kan antalet servrar som skickas till " +"<citerefentry> <refentrytitle>sssd_krb5_locator_plugin</refentrytitle> " +"<manvolnum>8</manvolnum> </citerefentry> begränsas. Detta kan vara " +"användbart när för många servrar upptäcks med SRV-poster." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:377 @@ -16920,8 +17585,8 @@ msgid "" "servers." msgstr "" "Till exempel betyder <emphasis>10:0</emphasis> att upp till 10 primärservrar " -"kommer lämnas till <citerefentry> <refentrytitle>sssd_krb5_locator_plugin</" -"refentrytitle> <manvolnum>8</manvolnum> </citerefentry> men inga " +"skickas till <citerefentry> <refentrytitle>sssd_krb5_locator_plugin</" +"refentrytitle> <manvolnum>8</manvolnum> </citerefentry>, men inga " "reservservrar." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> @@ -16932,7 +17597,7 @@ msgstr "Standard: 3:1" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-krb5.5.xml:398 msgid "krb5_use_enterprise_principal (boolean)" -msgstr "krb5_use_enterprise_principal (boolean)" +msgstr "krb5_use_enterprise_principal (boolesk)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:401 @@ -16940,8 +17605,8 @@ msgid "" "Specifies if the user principal should be treated as enterprise principal. " "See section 5 of RFC 6806 for more details about enterprise principals." msgstr "" -"Anger om användarens huvudman skall behandlas som företagshuvudman. Se " -"avsnitt 5 i RFC 6806 för mer detaljer om företagshuvudmän." +"Anger om användarens huvudman ska behandlas som en enterprise-huvudman. Se " +"avsnitt 5 i RFC 6806 för mer information om enterprise-huvudmän." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:407 @@ -16955,14 +17620,14 @@ msgid "" "is capable of handling enterprise principals and the option is not set " "explicitly in the config file." msgstr "" -"IPA-leverantören kommer sätta detta alternativ till ”true” om den upptäcker " -"att servern klarar av att hantera företagshuvudmän och alternativet inte är " -"uttryckligen satt i konfigurationsfilen." +"IPA-leverantören sätter alternativet till 'true' om den upptäcker att " +"servern kan hantera enterprise-huvudmän och alternativet inte har angetts " +"uttryckligen i konfigurationsfilen." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-krb5.5.xml:419 msgid "krb5_use_subdomain_realm (boolean)" -msgstr "krb5_use_subdomain_realm (boolean)" +msgstr "krb5_use_subdomain_realm (boolesk)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:422 @@ -16973,12 +17638,11 @@ msgid "" "the option is set to 'true' SSSD will try to send the request directly to a " "KDC of the trusted domain the user is coming from." msgstr "" -"Anger att använda underdomänriken för autentiseringen av användare från " -"betrodda domäner. Detta alternativ kan sättas till ”sant” om " -"företagshuvudmän används med upnSuffixes vilka inte är kända av " -"föräldradomänens KDC:er. Om alternativet sätts till ”sant” kommer SSSD " -"försöka skicka begäran direkt till en KDC för den betrodda domänen " -"användaren kommer ifrån." +"Anger att underdomänsrealmer ska användas för autentisering av användare " +"från betrodda domäner. Alternativet kan sättas till 'true' om enterprise-" +"huvudmän används med upnSuffixes som inte är kända av KDC:erna i den " +"överordnade domänen. Om alternativet sätts till 'true' försöker SSSD skicka " +"begäran direkt till en KDC i den betrodda domän som användaren kommer från." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-krb5.5.xml:438 @@ -16994,11 +17658,11 @@ msgid "" "mapping is used when user is authenticating using <quote>auth_provider = " "krb5</quote>." msgstr "" -"Listan av mappningar anges som en kommaseparerad lista av par <quote>" -"användarnamn:primär</quote> där <quote>användarnamn</quote> är ett UNIX-" -"användarnamn och <quote>primär</quote> är en användardel av en " -"kerberoshuvudman. Denna mappning används när användaren autentiserar med " -"<quote>auth_provider = krb5</quote>." +"Listan över mappningar anges som en kommaseparerad lista med paren <quote>" +"username:primary</quote>, där <quote>username</quote> är ett UNIX-" +"användarnamn och <quote>primary</quote> är användardelen av en Kerberos-" +"huvudman. Mappningen används när användaren autentiserar med <quote>" +"auth_provider = krb5</quote>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> #: sssd-krb5.5.xml:453 @@ -17007,8 +17671,8 @@ msgid "" "krb5_realm = REALM\n" "krb5_map_user = joe:juser,dick:richard\n" msgstr "" -"krb5_realm = RIKE\n" -"krb5_map_user = maria:manvnd,hasse:hans\n" +"krb5_realm = REALM\n" +"krb5_map_user = joe:juser,dick:richard\n" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:458 @@ -17019,11 +17683,11 @@ msgid "" "try to kinit as <quote>juser@REALM</quote> resp. <quote>richard@REALM</" "quote>." msgstr "" -"<quote>maria</quote> och <quote>hasse</quote> är UNIX-användarnamn och " -"<quote>manvnd</quote> och <quote>hans</quote> är primärer i " -"kerberoshuvudmän. För användaren <quote>maria</quote> resp. <quote>hasse</" -"quote> kommer SSSD försöka att göra kinit som <quote>manvnd@RIKE</quote> " -"resp. <quote>hans@RIKE</quote>." +"<quote>joe</quote> och <quote>dick</quote> är UNIX-användarnamn och <quote>" +"juser</quote> och <quote>richard</quote> är primärer i Kerberos-huvudmän. " +"För användaren <quote>joe</quote> respektive <quote>dick</quote> försöker " +"SSSD köra kinit som <quote>juser@REALM</quote> respektive <quote>" +"richard@REALM</quote>." #. type: Content of: <reference><refentry><refsect1><para> #: sssd-krb5.5.xml:65 @@ -17035,10 +17699,10 @@ msgid "" "domain. <placeholder type=\"variablelist\" id=\"0\"/>" msgstr "" "Om autentiseringsmodulen krb5 används i en SSSD-domän måste följande " -"alternativ användas. Se manualsidan <citerefentry> <refentrytitle>" -"sssd.conf</refentrytitle> <manvolnum>5</manvolnum> </citerefentry>, " -"avsnittet <quote>DOMÄNSEKTIONER</quote> för detaljer om konfigurationen av " -"en SSSD-domän. <placeholder type=\"variablelist\" id=\"0\"/>" +"alternativ användas. Se manualsidan <citerefentry> <refentrytitle>sssd.conf</" +"refentrytitle> <manvolnum>5</manvolnum> </citerefentry>, avsnittet <quote>" +"DOMAIN SECTIONS</quote>, för information om hur en SSSD-domän konfigureras. " +"<placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-krb5.5.xml:485 @@ -17048,10 +17712,10 @@ msgid "" "example shows only configuration of Kerberos authentication; it does not " "include any identity provider." msgstr "" -"Följande exempel antar att SSSD är korrekt konfigurerad och att APA är en av " -"domänerna i avsnittet <replaceable>[sssd]</replaceable>. Detta exempel " -"visar endast konfigurationen av Kerberosautentisering; det inkluderar inte " -"någon identitetsleverantör." +"Följande exempel förutsätter att SSSD är korrekt konfigurerat och att FOO är " +"en av domänerna i avsnittet <replaceable>[sssd]</replaceable>. Exemplet " +"visar endast konfiguration av Kerberos-autentisering och omfattar ingen " +"identitetsleverantör." #. type: Content of: <reference><refentry><refsect1><para><programlisting> #: sssd-krb5.5.xml:493 @@ -17062,10 +17726,10 @@ msgid "" "krb5_server = 192.168.1.1\n" "krb5_realm = EXAMPLE.COM\n" msgstr "" -"[domain/APA]\n" +"[domain/FOO]\n" "auth_provider = krb5\n" "krb5_server = 192.168.1.1\n" -"krb5_realm = EXEMPEL.COM\n" +"krb5_realm = EXAMPLE.COM\n" #. type: Content of: <reference><refentry><refnamediv><refname> #: sss_cache.8.xml:10 sss_cache.8.xml:15 @@ -17083,7 +17747,7 @@ msgid "" "<command>sss_cache</command> <arg choice='opt'> <replaceable>options</" "replaceable> </arg>" msgstr "" -"<command>sss_cache</command> <arg choice='opt'> <replaceable>flaggor</" +"<command>sss_cache</command> <arg choice='opt'> <replaceable>options</" "replaceable> </arg>" #. type: Content of: <reference><refentry><refsect1><para> @@ -17094,10 +17758,10 @@ msgid "" "backend is online. Options that invalidate a single object only accept a " "single provided argument." msgstr "" -"<command>sss_cache</command> invaliderar poster i SSSD-cachen. Invaliderade " -"poster måste hämtas om från servern så fort den tillhörande SSSD-bakänden är " -"ansluten. Flaggor som invaliderar ett enstaka objekt tar bara ett ensamt " -"argument." +"<command>sss_cache</command> invaliderar poster i SSSD-cachen. Invaliderade " +"poster läses in på nytt från servern så snart den berörda SSSD-bakomliggande " +"komponenten är ansluten. Alternativ som invaliderar ett enskilt objekt tar " +"endast ett angivet argument." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_cache.8.xml:43 @@ -17114,8 +17778,7 @@ msgstr "Invalidera alla cachade poster." msgid "" "<option>-u</option>,<option>--user</option> <replaceable>login</replaceable>" msgstr "" -"<option>-u</option>,<option>--user</option> <replaceable>inloggning</" -"replaceable>" +"<option>-u</option>,<option>--user</option> <replaceable>login</replaceable>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_cache.8.xml:58 @@ -17141,7 +17804,7 @@ msgstr "" msgid "" "<option>-g</option>,<option>--group</option> <replaceable>group</replaceable>" msgstr "" -"<option>-g</option>,<option>--group</option> <replaceable>grupp</replaceable>" +"<option>-g</option>,<option>--group</option> <replaceable>group</replaceable>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_cache.8.xml:80 @@ -17168,7 +17831,7 @@ msgid "" "<option>-n</option>,<option>--netgroup</option> <replaceable>netgroup</" "replaceable>" msgstr "" -"<option>-n</option>,<option>--netgroup</option> <replaceable>nätgrupp</" +"<option>-n</option>,<option>--netgroup</option> <replaceable>netgroup</" "replaceable>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> @@ -17196,7 +17859,7 @@ msgid "" "<option>-s</option>,<option>--service</option> <replaceable>service</" "replaceable>" msgstr "" -"<option>-s</option>,<option>--service</option> <replaceable>tjänst</" +"<option>-s</option>,<option>--service</option> <replaceable>service</" "replaceable>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> @@ -17224,13 +17887,13 @@ msgid "" "<option>-a</option>,<option>--autofs-map</option> <replaceable>autofs-map</" "replaceable>" msgstr "" -"<option>-a</option>,<option>--autofs-map</option> <replaceable>autofs-" -"översättning</replaceable>" +"<option>-a</option>,<option>--autofs-map</option> <replaceable>autofs-map</" +"replaceable>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_cache.8.xml:146 msgid "Invalidate specific autofs maps." -msgstr "Invalidera specifika autofs-översättningar." +msgstr "Invalidera vissa autofs-kartor." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_cache.8.xml:152 @@ -17243,8 +17906,8 @@ msgid "" "Invalidate all autofs maps. This option overrides invalidation of specific " "map if it was also set." msgstr "" -"Invalidera alla autofs-översättningar. Detta alternativ åsidosätter " -"invalidering av en viss översättning om det också angavs." +"Invalidera alla autofs-kartor. Detta alternativ åsidosätter invalidering av " +"en viss karta om det också har angetts." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_cache.8.xml:163 @@ -17252,7 +17915,7 @@ msgid "" "<option>-h</option>,<option>--ssh-host</option> <replaceable>hostname</" "replaceable>" msgstr "" -"<option>-h</option>,<option>--ssh-host</option> <replaceable>värdnamn</" +"<option>-h</option>,<option>--ssh-host</option> <replaceable>hostname</" "replaceable>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> @@ -17280,7 +17943,7 @@ msgid "" "<option>-r</option>,<option>--sudo-rule</option> <replaceable>rule</" "replaceable>" msgstr "" -"<option>-r</option>,<option>--sudo-rule</option> <replaceable>regel</" +"<option>-r</option>,<option>--sudo-rule</option> <replaceable>rule</" "replaceable>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> @@ -17308,7 +17971,7 @@ msgid "" "<option>-d</option>,<option>--domain</option> <replaceable>domain</" "replaceable>" msgstr "" -"<option>-d</option>,<option>--domain</option> <replaceable>domän</" +"<option>-d</option>,<option>--domain</option> <replaceable>domain</" "replaceable>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> @@ -17337,16 +18000,15 @@ msgid "" "finally removed completely." msgstr "" "<command>sss_cache</command> invaliderar även minnescachen. Eftersom " -"minnescachen är en fil som avbildas in i minnet för varje process som " -"anropar SSSD för att slå upp användare eller grupper kan filen inte huggas " -"av. En speciell flagga sätts i huvudet på filen för att indikera att " -"innehållet är ogiltigt och sedan tas länken bort av SSSD:s NSS-respondent " -"och en ny cache-fil skapas. När än en process nu gör en ny uppslagning av en " -"användare eller en grupp kommer den att se flaggan, stänga den gamla " -"minnescachfilen och avbilda in den ny in i sitt minne. När alla processer " -"som har öppnat den gamla minnescachefilen har stängt den under uppslagning " -"av en användare eller grupp kan kärnan släppa det använda diskutrymmet och " -"den gamla minnescachefilen är slutligen helt borttagen." +"minnescachen är en fil som minnesmappas av varje process som anropar SSSD " +"för att slå upp användare eller grupper, kan filen inte trunkeras. En " +"särskild flagga sätts i filens huvud för att ange att innehållet är " +"ogiltigt. SSSD:s NSS-svarare avlänkar sedan filen och skapar en ny cachefil. " +"När en process därefter gör en ny uppslagning av en användare eller grupp " +"ser den flaggan, stänger den gamla minnescachefilen och minnesmappar den nya " +"filen. När alla processer som öppnat den gamla minnescachefilen har stängt " +"den vid uppslagning av en användare eller grupp kan kärnan frigöra det " +"upptagna diskutrymmet och den gamla minnescachefilen tas slutligen bort helt." #. type: Content of: <reference><refentry><refsect1><para> #: sss_cache.8.xml:240 @@ -17361,16 +18023,15 @@ msgid "" "disk usage because old memory cache files cannot be removed from the disk " "because they are still mapped by long running processes." msgstr "" -"Ett särskilt fall är långlivade processer som gör användar- eller " -"gruppuppslagningar endast vid uppstart, t.ex. för att avgöra namnet på " -"användaren processen kör som. För dessa uppslagningar är minnescachfilen " -"avbildad in i processens minne. Men eftersom det inte kommer vara några " -"ytterligare uppslagningar skulle dessa processer aldrig upptäcka om " -"minnescachefilen invalideras och därmed kommer den hållas kvar i minnet och " -"kommer den att använda diskutrymme tills processen slutar. Som ett resultat " -"kan att anropa <command>sss_cache</command> öka diskanvändningen eftersom " -"gamla minnescachefiler inte kan tas bort från disken eftersom de fortfarande " -"är avbildade av långlivade processer." +"Ett specialfall är långvariga processer som endast gör användar- eller " +"gruppuppslagningar vid uppstart, till exempel för att fastställa namnet på " +"den användare som processen kör som. För sådana uppslagningar minnesmappas " +"minnescachefilen av processen. Eftersom inga fler uppslagningar görs kan " +"processen aldrig upptäcka att minnescachefilen har invaliderats. Den behålls " +"därför i minnet och upptar diskutrymme tills processen avslutas. Att anropa " +"<command>sss_cache</command> kan därför öka diskanvändningen, eftersom gamla " +"minnescachefiler inte kan tas bort från disken medan de fortfarande är " +"minnesmappade av långvariga processer." #. type: Content of: <reference><refentry><refsect1><para> #: sss_cache.8.xml:252 @@ -17383,13 +18044,12 @@ msgid "" "so that they meet the local expectations and calling <command>sss_cache</" "command> is not needed." msgstr "" -"Ett möjligt sätt att gå runt problemet för långlivade processer som slår upp " -"användare och grupper endast vid uppstart eller väldigt sällan är att köra " -"dem med miljövariabeln SSS_NSS_USE_MEMCACHE satt till ”NO” så att de inte " -"kommer använda minnescachen alls och inte avbilda minnescachefilen in i " -"minnet. I allmänhet är en bättre lösning att trimma parametrarna för cachens " -"tidsgräns så att de stämmer med lokala förväntningar och det inte är " -"nödvändigt att anropa <command>sss_cache</command>." +"En möjlig lösning för långvariga processer som slår upp användare och " +"grupper endast vid uppstart eller mycket sällan är att köra dem med " +"miljövariabeln SSS_NSS_USE_MEMCACHE satt till \"NO\". Då använder de inte " +"minnescachen och minnesmappar inte minnescachefilen. I allmänhet är det " +"bättre att justera cachens tidsgränsparametrar så att de motsvarar de lokala " +"kraven och det inte behövs något anrop till <command>sss_cache</command>." #. type: Content of: <reference><refentry><refnamediv><refname> #: sss_debuglevel.8.xml:10 sss_debuglevel.8.xml:15 @@ -17408,8 +18068,8 @@ msgid "" "replaceable> </arg> <arg choice='plain'><replaceable>NEW_DEBUG_LEVEL</" "replaceable></arg>" msgstr "" -"<command>sss_debuglevel</command> <arg choice='opt'> <replaceable>flaggor</" -"replaceable> </arg> <arg choice='plain'><replaceable>NY_FELSÖKNINGSNIVÅ</" +"<command>sss_debuglevel</command> <arg choice='opt'> <replaceable>options</" +"replaceable> </arg> <arg choice='plain'><replaceable>NEW_DEBUG_LEVEL</" "replaceable></arg>" #. type: Content of: <reference><refentry><refsect1><para> @@ -17431,7 +18091,7 @@ msgstr "sss_seed" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sss_seed.8.xml:16 msgid "seed the SSSD cache with a user" -msgstr "initiera SSSD-cachen med en användare" +msgstr "fyll SSSD-cachen med en användare" #. type: Content of: <reference><refentry><refsynopsisdiv><cmdsynopsis> #: sss_seed.8.xml:21 @@ -17441,9 +18101,9 @@ msgid "" "replaceable></arg> <arg choice='plain'>-n <replaceable>USER</replaceable></" "arg>" msgstr "" -"<command>sss_seed</command> <arg choice='opt'> <replaceable>flaggor</" -"replaceable> </arg> <arg choice='plain'>-D <replaceable>DOMÄN</replaceable></" -"arg> <arg choice='plain'>-n <replaceable>ANVÄNDARE</replaceable></arg>" +"<command>sss_seed</command> <arg choice='opt'> <replaceable>options</" +"replaceable> </arg> <arg choice='plain'>-D <replaceable>DOMAIN</replaceable>" +"</arg> <arg choice='plain'>-n <replaceable>USER</replaceable></arg>" #. type: Content of: <reference><refentry><refsect1><para> #: sss_seed.8.xml:33 @@ -17452,9 +18112,9 @@ msgid "" "temporary password. If a user entry is already present in the SSSD cache " "then the entry is updated with the temporary password." msgstr "" -"<command>sss_seed</command> initierar SSSD-cachen med en användarpost och " -"tillfälligt lösenord. Om en användarpost redan finns i SSSD-cachen " -"uppdateras den posten med det tillfälliga lösenordet." +"<command>sss_seed</command> fyller SSSD-cachen med en användarpost och ett " +"tillfälligt lösenord. Om en användarpost redan finns i SSSD-cachen " +"uppdateras posten med det tillfälliga lösenordet." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_seed.8.xml:46 @@ -17462,7 +18122,7 @@ msgid "" "<option>-D</option>,<option>--domain</option> <replaceable>DOMAIN</" "replaceable>" msgstr "" -"<option>-D</option>,<option>--domain</option> <replaceable>DOMÄN</" +"<option>-D</option>,<option>--domain</option> <replaceable>DOMAIN</" "replaceable>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> @@ -17474,10 +18134,10 @@ msgid "" "Information retrieved from the domain overrides what is provided in the " "options." msgstr "" -"Ange namnet på domänen i vilken användaren är en medlem. Domänen används " -"också för att hämta användarinformation. Domänen måste vara konfigurerad i " -"sssd.conf. Alternativet <replaceable>DOMÄN</replaceable> måste anges. " -"Information som hämtas från domänen åsidosätter vad som anges i flaggorna." +"Ange namnet på den domän som användaren är medlem i. Domänen används också " +"för att hämta användarinformation. Den måste vara konfigurerad i sssd.conf. " +"Alternativet <replaceable>DOMAIN</replaceable> måste anges. Information som " +"hämtas från domänen åsidosätter det som anges i alternativen." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_seed.8.xml:63 @@ -17485,7 +18145,7 @@ msgid "" "<option>-n</option>,<option>--username</option> <replaceable>USER</" "replaceable>" msgstr "" -"<option>-n</option>,<option>--username</option> <replaceable>ANVÄNDARE</" +"<option>-n</option>,<option>--username</option> <replaceable>USER</" "replaceable>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> @@ -17494,15 +18154,15 @@ msgid "" "The username of the entry to be created or modified in the cache. The " "<replaceable>USER</replaceable> option must be provided." msgstr "" -"Användarnamnet på posten som skall skapas eller ändras i cachen. Flaggan " -"<replaceable>ANVÄNDARE</replaceable> måste anges." +"Användarnamnet för den post som ska skapas eller ändras i cachen. " +"Alternativet <replaceable>USER</replaceable> måste anges." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_seed.8.xml:76 msgid "" "<option>-u</option>,<option>--uid</option> <replaceable>UID</replaceable>" msgstr "" -"<option>-u</option>,<option>--uid</option> <replaceable>AID</replaceable>" +"<option>-u</option>,<option>--uid</option> <replaceable>UID</replaceable>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_seed.8.xml:81 @@ -17527,7 +18187,7 @@ msgid "" "<option>-c</option>,<option>--gecos</option> <replaceable>COMMENT</" "replaceable>" msgstr "" -"<option>-c</option>,<option>--gecos</option> <replaceable>KOMMENTAR</" +"<option>-c</option>,<option>--gecos</option> <replaceable>COMMENT</" "replaceable>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> @@ -17536,8 +18196,8 @@ msgid "" "Any text string describing the user. Often used as the field for the user's " "full name." msgstr "" -"Godtycklig textsträng som beskriver användaren. Ofta använt som ett fält " -"för användarens fullständiga namn." +"En godtycklig textsträng som beskriver användaren. Används ofta som fält för " +"användarens fullständiga namn." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_seed.8.xml:112 @@ -17545,26 +18205,26 @@ msgid "" "<option>-h</option>,<option>--home</option> <replaceable>HOME_DIR</" "replaceable>" msgstr "" -"<option>-h</option>,<option>--home</option> <replaceable>HEMKATALOG</" +"<option>-h</option>,<option>--home</option> <replaceable>HOME_DIR</" "replaceable>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_seed.8.xml:117 msgid "" "Set the home directory of the user to <replaceable>HOME_DIR</replaceable>." -msgstr "Sätt användarens hemkatalog till <replaceable>HEMKAT</replaceable>." +msgstr "Sätt användarens hemkatalog till <replaceable>HOME_DIR</replaceable>." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_seed.8.xml:124 msgid "" "<option>-s</option>,<option>--shell</option> <replaceable>SHELL</replaceable>" msgstr "" -"<option>-s</option>,<option>--shell</option> <replaceable>SKAL</replaceable>" +"<option>-s</option>,<option>--shell</option> <replaceable>SHELL</replaceable>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_seed.8.xml:129 msgid "Set the login shell of the user to <replaceable>SHELL</replaceable>." -msgstr "Sätt användarens inloggningsskal till <replaceable>SKAL</replaceable>." +msgstr "Sätt användarens inloggningsskal till <replaceable>SHELL</replaceable>." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_seed.8.xml:140 @@ -17572,8 +18232,8 @@ msgid "" "Interactive mode for entering user information. This option will only prompt " "for information not provided in the options or retrieved from the domain." msgstr "" -"Interaktivt läge för att ange användarinformation. Detta alternativ kommer " -"bara att fråga efter information som inte angavs med flaggor eller hämtades " +"Interaktivt läge för att ange användarinformation. Alternativet frågar " +"endast efter information som inte har angetts i alternativen eller hämtats " "från domänen." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> @@ -17582,7 +18242,7 @@ msgid "" "<option>-p</option>,<option>--password-file</option> <replaceable>PASS_FILE</" "replaceable>" msgstr "" -"<option>-p</option>,<option>--password-file</option> <replaceable>LÖSENFIL</" +"<option>-p</option>,<option>--password-file</option> <replaceable>PASS_FILE</" "replaceable>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> @@ -17591,8 +18251,8 @@ msgid "" "Specify file to read user's password from. (if not specified password is " "prompted for)" msgstr "" -"Ange filen att läsa användarnas lösenord ifrån. (om inte angivet " -"efterfrågas lösenord)" +"Ange den fil som användarens lösenord ska läsas från. (Om den inte anges " +"efterfrågas lösenordet.)" #. type: Content of: <reference><refentry><refsect1><para> #: sss_seed.8.xml:165 @@ -17601,8 +18261,8 @@ msgid "" "password-file option) must be less than or equal to PASS_MAX bytes (64 bytes " "on systems with no globally-defined PASS_MAX value)." msgstr "" -"Längden på lösenordet (eller storleken på filen som anges med flaggan -p " -"eller --password-file) måste vara mindre eller lika med PASS_MAX byte (64 " +"Lösenordets längd, eller storleken på filen som anges med alternativet -p " +"eller --password-file, måste vara mindre än eller lika med PASS_MAX byte (64 " "byte på system utan något globalt definierat PASS_MAX-värde)." #. type: Content of: <reference><refentry><refnamediv><refname> @@ -17613,7 +18273,7 @@ msgstr "sssd-ifp" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sssd-ifp.5.xml:17 msgid "SSSD InfoPipe responder" -msgstr "SSSD InfoPipe-respondent" +msgstr "SSSD InfoPipe-svarare" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ifp.5.xml:23 @@ -17624,11 +18284,11 @@ msgid "" "FORMAT</quote> section of the <citerefentry> <refentrytitle>sssd.conf</" "refentrytitle> <manvolnum>5</manvolnum> </citerefentry> manual page." msgstr "" -"Denna manualsida beskriver konfigurationen av InfoPipe-respondenten till " +"Denna manualsida beskriver konfigurationen av InfoPipe-svararen för " "<citerefentry> <refentrytitle>sssd</refentrytitle> <manvolnum>8</manvolnum> " -"</citerefentry>. För en detaljerad referens om syntaxen, se avsnittet " -"<quote>FILFORMAT</quote> i manualsidan <citerefentry> <refentrytitle>" -"sssd.conf</refentrytitle> <manvolnum>5</manvolnum> </citerefentry>." +"</citerefentry>. En detaljerad syntaxreferens finns i avsnittet <quote>FILE " +"FORMAT</quote> i manualsidan <citerefentry> <refentrytitle>sssd.conf</" +"refentrytitle> <manvolnum>5</manvolnum> </citerefentry>." #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ifp.5.xml:36 @@ -17637,9 +18297,9 @@ msgid "" "system bus. The interface allows the user to query information about remote " "users and groups over the system bus." msgstr "" -"InfoPipe-respondenten tillhandahåller ett publikt D-Bus-gränssnitt åtkomligt " -"över systembussen. Gränssnittet låter användaren att fråga efter " -"information om fjärranvändare och -grupper över systembussen." +"InfoPipe-svararen tillhandahåller ett offentligt D-Bus-gränssnitt som är " +"åtkomligt via systembussen. Gränssnittet låter användaren fråga efter " +"information om fjärranvändare och fjärrgrupper via systembussen." #. type: Content of: <reference><refentry><refsect1><refsect2><title> #: sssd-ifp.5.xml:43 @@ -17677,7 +18337,7 @@ msgid "" "<citerefentry><refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</" "manvolnum></citerefentry>." msgstr "" -"För fler detaljer om alternativet, se <citerefentry><refentrytitle>" +"Mer information om alternativen finns i <citerefentry><refentrytitle>" "sssd.conf</refentrytitle> <manvolnum>5</manvolnum></citerefentry>." #. type: Content of: <reference><refentry><refsect1><para> @@ -17693,16 +18353,14 @@ msgid "" "allowed to access the InfoPipe responder. User names are resolved to UIDs at " "startup." msgstr "" -"Anger den kommaseparerade listan av AID-värden eller användarnamn som " -"tillåts använda InfoPipe-respondenten. Användarnamn slås upp till AID:er " -"vid uppstart." +"Anger den kommaseparerade listan med UID-värden eller användarnamn som har " +"åtkomst till InfoPipe-svararen. Användarnamn löses till UID:er vid uppstart." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd-ifp.5.xml:75 msgid "" "Default: 0 (only the root user is allowed to access the InfoPipe responder)" -msgstr "" -"Standard: 0 (endast root-användaren tillåts komma åt InfoPipe-respondenten)" +msgstr "Standard: 0 (endast root-användaren har åtkomst till InfoPipe-svararen)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd-ifp.5.xml:79 @@ -17712,10 +18370,10 @@ msgid "" "access the InfoPipe responder, which would be the typical case, you have to " "add 0 to the list of allowed UIDs as well." msgstr "" -"Observera att även om AID 0 används som standard kommer det att skrivas över " -"av detta alternativ. Om du fortfarande vill tillåta root-användaren att " -"komma åt InfoPipe-respondenten, vilket man typiskt vill, måste du lägga till " -"även 0 i listan av tillåtna AID:er." +"Observera att även om UID 0 används som standard skrivs det över av detta " +"alternativ. Om root-användaren fortfarande ska ha åtkomst till InfoPipe-" +"svararen, vilket är det vanliga, måste även 0 läggas till i listan över " +"tillåtna UID:er." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd-ifp.5.xml:93 @@ -17725,10 +18383,10 @@ msgid "" "<quote>GetUserAttr</quote> interface does not utilize this option, it allows " "any attribute requested." msgstr "" -"Anger en kommaseparerad lista över attribut som finns på vit- eller " -"svartlistan. Det här alternativet gäller endast <quote>användar</quote> " -"gränssnittet. Det föråldrade gränssnittet <quote>GetUserAttr</quote> " -"använder inte det här alternativet, utan tillåter alla attribut som begärs." +"Anger den kommaseparerade listan med vit- eller svartlistade attribut. " +"Alternativet gäller endast gränssnittet <quote>Users</quote>. Det föråldrade " +"gränssnittet <quote>GetUserAttr</quote> använder inte alternativet utan " +"tillåter alla begärda attribut." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd-ifp.5.xml:111 @@ -17758,7 +18416,7 @@ msgstr "gidNumber" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd-ifp.5.xml:120 msgid "primary group ID" -msgstr "primär grupps ID" +msgstr "primärgruppens ID" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd-ifp.5.xml:123 @@ -17794,10 +18452,10 @@ msgid "" "<manvolnum>3</manvolnum> </citerefentry> and includes: <placeholder " "type=\"variablelist\" id=\"0\"/>" msgstr "" -"Som standard tillåter InfoPipe-svararen `/Users`-gränssnittet endast att " -"standarduppsättningen av POSIX-attribut begärs. Denna uppsättning är " -"densamma som den som returneras av <citerefentry> <refentrytitle>getpwnam</" -"refentrytitle> <manvolnum>3</manvolnum> </citerefentry> och innehåller: " +"Som standard tillåter InfoPipe-svararens gränssnitt `/Users` endast att " +"standarduppsättningen av POSIX-attribut begärs. Uppsättningen är densamma " +"som den som returneras av <citerefentry> <refentrytitle>getpwnam</" +"refentrytitle> <manvolnum>3</manvolnum> </citerefentry> och omfattar: " "<placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><programlisting> @@ -17821,12 +18479,11 @@ msgid "" "use the following configuration: <placeholder type=\"programlisting\" " "id=\"0\"/>" msgstr "" -"Det är möjligt att lägga till ytterligare ett attribut till denna " -"uppsättning genom att använda <quote>+attr_name</quote> eller uttryckligen " -"ta bort ett attribut med <quote>-attr_name</quote>. Tillagda attribut kommer " -"att göras tillgängliga i <quote>extraAttributes-matrisen</quote>. För att " -"till exempel tillåta <quote>telephoneNumber</quote> men neka <quote>" -"loginShell</quote> skulle du använda följande konfiguration: <placeholder " +"Det går att lägga till ett attribut i uppsättningen med <quote>+attr_name</" +"quote> eller uttryckligen ta bort ett attribut med <quote>-attr_name</quote>" +". Tillagda attribut blir tillgängliga i matrisen <quote>extraAttributes</" +"quote>. Om till exempel <quote>telephoneNumber</quote> ska tillåtas och " +"<quote>loginShell</quote> nekas används följande konfiguration: <placeholder " "type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> @@ -17875,7 +18532,7 @@ msgstr "sss_rpcidmapd" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sss_rpcidmapd.5.xml:33 msgid "sss plugin configuration directives for rpc.idmapd" -msgstr "sss insticksmoduls konfigurationsdirektiv för rpc.idmapd" +msgstr "konfigurationsdirektiv för sss-insticksmodulen till rpc.idmapd" #. type: Content of: <reference><refentry><refsect1><title> #: sss_rpcidmapd.5.xml:37 @@ -17889,19 +18546,20 @@ msgid "" "idmapd.conf</emphasis>. See <citerefentry> <refentrytitle>idmapd.conf</" "refentrytitle> <manvolnum>5</manvolnum> </citerefentry> for more information." msgstr "" -"rpc.idmapd konfigurationsfil finns vanligen som <emphasis>/etc/idmapd.conf</" -"emphasis>. Se <citerefentry> <refentrytitle>idmapd.conf</refentrytitle> " -"<manvolnum>5</manvolnum> </citerefentry> för mer information." +"Konfigurationsfilen för rpc.idmapd finns vanligen på <emphasis>/etc/" +"idmapd.conf</emphasis>. Mer information finns i <citerefentry> " +"<refentrytitle>idmapd.conf</refentrytitle> <manvolnum>5</manvolnum> </" +"citerefentry>." #. type: Content of: <reference><refentry><refsect1><title> #: sss_rpcidmapd.5.xml:49 msgid "SSS CONFIGURATION EXTENSION" -msgstr "SSS-KONFIGURATIONSUTVIDGNING" +msgstr "UTÖKNING AV SSS-KONFIGURATIONEN" #. type: Content of: <reference><refentry><refsect1><refsect2><title> #: sss_rpcidmapd.5.xml:51 msgid "Enable SSS plugin" -msgstr "Aktivera SSS-insticksmodul" +msgstr "Aktivera SSS-insticksmodulen" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sss_rpcidmapd.5.xml:53 @@ -17909,8 +18567,8 @@ msgid "" "In section <quote>[Translation]</quote>, modify/set <quote>Method</quote> " "attribute to contain <emphasis>sss</emphasis>." msgstr "" -"I avsnittet <quote>[Translation]</quote>, ändra/sätt attributet <quote>" -"Method</quote> till att innehålla <emphasis>sss</emphasis>." +"I avsnittet <quote>[Translation]</quote> ska attributet <quote>Method</" +"quote> ändras eller anges till <emphasis>sss</emphasis>." #. type: Content of: <reference><refentry><refsect1><refsect2><title> #: sss_rpcidmapd.5.xml:59 @@ -17924,9 +18582,9 @@ msgid "" "<emphasis>sss</emphasis> plugin listed below you will need to create a " "config section for it, named <quote>[sss]</quote>." msgstr "" -"För att ändra standardvärdet på ett av konfigurationsattributen för " -"insticksmodulen <emphasis>sss</emphasis> som räknas upp nedan behöver man " -"skapa ett konfigurationsavsnitt för den, med namnet <quote>[sss]</quote>." +"För att ändra standardvärdet för något av konfigurationsattributen för " +"insticksmodulen <emphasis>sss</emphasis> nedan måste du skapa ett " +"konfigurationsavsnitt med namnet <quote>[sss]</quote>." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><title> #: sss_rpcidmapd.5.xml:67 @@ -17935,7 +18593,9 @@ msgstr "Konfigurationsattribut" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sss_rpcidmapd.5.xml:69 -msgid "memcache (bool)" +#, fuzzy +#| msgid "memcache (bool)" +msgid "memcache (boolean)" msgstr "memcache (bool)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> @@ -17955,7 +18615,7 @@ msgid "" "The sss plugin requires the <emphasis>NSS Responder</emphasis> to be enabled " "in sssd." msgstr "" -"Insticksmodulen sss kräver att <emphasis>NSS-respondenten</emphasis> är " +"Insticksmodulen sss kräver att <emphasis>NSS Responder</emphasis> är " "aktiverad i sssd." #. type: Content of: <reference><refentry><refsect1><para> @@ -17967,7 +18627,7 @@ msgid "" msgstr "" "Attributet <quote>use_fully_qualified_names</quote> måste aktiveras i alla " "domäner (NFSv4-klienter förväntar sig att ett fullständigt kvalificerat namn " -"skickas över tråden)." +"skickas över nätverket)." #. type: Content of: <reference><refentry><refsect1><para><programlisting> #: sss_rpcidmapd.5.xml:103 @@ -17988,8 +18648,8 @@ msgid "" msgstr "" "[General]\n" "Verbosity = 2\n" -"# domänen måste synkroniseras mellan NFSv4-servern och -klienter\n" -"# Solaris/Illumos/AIX använder \"localdomain\" som standard!\n" +"# domain must be synced between NFSv4 server and clients\n" +"# Solaris/Illumos/AIX use \"localdomain\" as default!\n" "Domain = default\n" "\n" "[Mapping]\n" @@ -18009,7 +18669,7 @@ msgstr "" "sss. <placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <refsect1><title> -#: sss_rpcidmapd.5.xml:120 sssd-kcm.8.xml:316 include/seealso.xml:2 +#: sss_rpcidmapd.5.xml:120 sssd-kcm.8.xml:315 include/seealso.xml:2 msgid "SEE ALSO" msgstr "SE ÄVEN" @@ -18042,7 +18702,7 @@ msgid "" "choice='plain'><replaceable>USER</replaceable></arg>" msgstr "" "<command>sss_ssh_authorizedkeys</command> <arg choice='opt'> <replaceable>" -"flaggor</replaceable> </arg> <arg choice='plain'><replaceable>ANVÄNDARE</" +"options</replaceable> </arg> <arg choice='plain'><replaceable>USER</" "replaceable></arg>" #. type: Content of: <reference><refentry><refsect1><para> @@ -18055,10 +18715,10 @@ msgid "" "citerefentry> for more information)." msgstr "" "<command>sss_ssh_authorizedkeys</command> hämtar publika SSH-nycklar för " -"användaren <replaceable>ANVÄNDARE</replaceable> och skriver ut dem i " -"formatet för OpenSSH authorized_keys (se avsnittet <quote>AUTHORIZED_KEYS-" -"FILFORMAT</quote> i <citerefentry><refentrytitle>sshd</refentrytitle> " -"<manvolnum>8</manvolnum></citerefentry> för mer information)." +"användaren <replaceable>USER</replaceable> och skriver ut dem i OpenSSH-" +"formatet authorized_keys (mer information finns i avsnittet <quote>" +"AUTHORIZED_KEYS FILE FORMAT</quote> i <citerefentry><refentrytitle>sshd</" +"refentrytitle> <manvolnum>8</manvolnum></citerefentry>)." #. type: Content of: <reference><refentry><refsect1><para> #: sss_ssh_authorizedkeys.1.xml:41 @@ -18071,12 +18731,12 @@ msgid "" "manvolnum></citerefentry> man page for more details about this option." msgstr "" "<citerefentry><refentrytitle>sshd</refentrytitle> <manvolnum>8</manvolnum></" -"citerefentry> kan konfigureras till att använda <command>" -"sss_ssh_authorizedkeys</command> för autentisering med användares publika " -"nyckel om den är kompilerad med stöd för alternativet <quote>" -"AuthorizedKeysCommand</quote>. Se manualsidan <citerefentry> <refentrytitle>" -"sshd_config</refentrytitle> <manvolnum>5</manvolnum></citerefentry> för mer " -"detaljer om detta alternativ." +"citerefentry> kan konfigureras för att använda <command>" +"sss_ssh_authorizedkeys</command> för autentisering av användare med publika " +"nycklar, om den har kompilerats med stöd för alternativet <quote>" +"AuthorizedKeysCommand</quote>. Mer information om alternativet finns i " +"manualsidan <citerefentry> <refentrytitle>sshd_config</refentrytitle> " +"<manvolnum>5</manvolnum></citerefentry>." #. type: Content of: <reference><refentry><refsect1><para><programlisting> #: sss_ssh_authorizedkeys.1.xml:59 @@ -18098,9 +18758,9 @@ msgid "" "<manvolnum>5</manvolnum></citerefentry>: <placeholder " "type=\"programlisting\" id=\"0\"/>" msgstr "" -"Om <quote>AuthorizedKeysCommand</quote> stödjs kan <citerefentry>" +"Om <quote>AuthorizedKeysCommand</quote> stöds kan <citerefentry>" "<refentrytitle>sshd</refentrytitle> <manvolnum>8</manvolnum></citerefentry> " -"konfigureras för att använda den genom att lägga in följande direktiv " +"konfigureras för att använda det genom att lägga följande direktiv i " "<citerefentry> <refentrytitle>sshd_config</refentrytitle> <manvolnum>5</" "manvolnum></citerefentry>: <placeholder type=\"programlisting\" id=\"0\"/>" @@ -18116,9 +18776,9 @@ msgid "" "<command>sss_ssh_authorizedkeys</command> can return public SSH keys derived " "from the public key of a X.509 certificate as well." msgstr "" -"Utöver de publika SSH-nycklarna för användaren <replaceable>ANVÄNDARE</" -"replaceable> kan <command>sss_ssh_authorizedkeys</command> även returnera " -"publika SSH-nycklar härledda från den publika nyckeln i ett X.509-certifikat." +"Utöver användarens publika SSH-nycklar <replaceable>USER</replaceable> kan " +"<command>sss_ssh_authorizedkeys</command> även returnera publika SSH-nycklar " +"som har härletts från den publika nyckeln i ett X.509-certifikat." #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sss_ssh_authorizedkeys.1.xml:73 @@ -18136,16 +18796,15 @@ msgid "" "and convert it into the format expected by sshd." msgstr "" "För att aktivera detta måste alternativet <quote>ssh_use_certificate_keys</" -"quote> sättas till true (standard) i avsnittet [ssh] av <filename>sssd.conf</" -"filename>. Om användarposten innehåller certifikat (se <quote>" +"quote> sättas till true (standard) i avsnittet [ssh] i <filename>sssd.conf</" +"filename>. Om användarposten innehåller certifikat, se <quote>" "ldap_user_certificate</quote> i <citerefentry><refentrytitle>sssd-ldap</" -"refentrytitle> <manvolnum>5</manvolnum></citerefentry> för detaljer) eller " -"det finns ett certifikat i en åsidosättande post för användaren (se " -"<citerefentry><refentrytitle>sss_override</refentrytitle> <manvolnum>8</" -"manvolnum></citerefentry> eller <citerefentry><refentrytitle>sssd-ipa</" -"refentrytitle> <manvolnum>5</manvolnum></citerefentry> för detaljer) och " -"certifikatet är giltigt kommer SSSD extrahera den publika nyckeln från " -"certifikatet och konvertera den till formatet som sshd förväntar sig." +"refentrytitle> <manvolnum>5</manvolnum></citerefentry>, eller om ett giltigt " +"certifikat finns i en åsidosättandepost för användaren, se <citerefentry>" +"<refentrytitle>sss_override</refentrytitle> <manvolnum>8</manvolnum></" +"citerefentry> eller <citerefentry><refentrytitle>sssd-ipa</refentrytitle> " +"<manvolnum>5</manvolnum></citerefentry>, extraherar SSSD den publika nyckeln " +"ur certifikatet och konverterar den till det format som sshd förväntar sig." #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sss_ssh_authorizedkeys.1.xml:90 @@ -18176,16 +18835,15 @@ msgid "" "already expired because neither <command>ssh</command> nor <command>sshd</" "command> will look at the certificate at all." msgstr "" -"Valideringen är fördelen med att använda X.509-certifikat istället för att " -"använda SSH-nycklar direkt för att det t.ex. ger en bättre kontroll över " -"livslängden hos nycklarna. När ssh-klienten är konfigurerad att använda de " -"privata nycklarna från ett smartkort med hjälp av det delade PKCS#11-" -"biblioteket (se <citerefentry><refentrytitle>ssh</refentrytitle> <manvolnum>" -"1</manvolnum></citerefentry> för detaljer) kan det vara irriterande att " -"autentiseringen fortfarande fungerar även om det tillhörande X.509-" -"certifikatet på smartkortet redan har gått ut eftersom varken <command>ssh</" -"command> eller <command>sshd</command> kommer titta på certifikatet över " -"huvud taget." +"Valideringen är fördelen med att använda X.509-certifikat i stället för SSH-" +"nycklar direkt, eftersom den till exempel ger bättre kontroll över " +"nycklarnas livslängd. När ssh-klienten är konfigurerad för att använda " +"privata nycklar från ett smartkort med hjälp av ett delat PKCS#11-bibliotek, " +"se <citerefentry><refentrytitle>ssh</refentrytitle> <manvolnum>1</manvolnum>" +"</citerefentry>, kan det vara förvirrande att autentiseringen fortfarande " +"fungerar trots att det tillhörande X.509-certifikatet på smartkortet har " +"gått ut. Varken <command>ssh</command> eller <command>sshd</command> " +"granskar nämligen certifikatet." #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sss_ssh_authorizedkeys.1.xml:114 @@ -18195,17 +18853,17 @@ msgid "" "certificate validation if the <command>sshd</command> configuration permits " "this." msgstr "" -"Det måste påpekas att den härledda publika SSH-nyckeln fortfarande kan " -"läggas till i användarens fil <filename>authorized_keys</filename> för att " -"gå runt certifikatvalideringen om konfigurationen av <command>sshd</command> " -"tillåter detta." +"Observera att den härledda publika SSH-nyckeln fortfarande kan läggas till i " +"användarens fil <filename>authorized_keys</filename> för att kringgå " +"certifikatvalideringen, om konfigurationen för <command>sshd</command> " +"tillåter det." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_ssh_authorizedkeys.1.xml:132 msgid "" "Search for user public keys in SSSD domain <replaceable>DOMAIN</replaceable>." msgstr "" -"Sök efter användares publika nycklar i SSSD-domänen <replaceable>DOMÄN</" +"Sök efter användares publika nycklar i SSSD-domänen <replaceable>DOMAIN</" "replaceable>." #. type: Content of: <reference><refentry><refsect1><para> @@ -18222,7 +18880,7 @@ msgstr "sss_ssh_knownhosts" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sss_ssh_knownhosts.1.xml:16 msgid "get OpenSSH known hosts public keys" -msgstr "hämta OpenSSH kända värdars publika nycklar" +msgstr "hämta publika nycklar för OpenSSH known_hosts" #. type: Content of: <reference><refentry><refsynopsisdiv><cmdsynopsis> #: sss_ssh_knownhosts.1.xml:21 @@ -18231,8 +18889,9 @@ msgid "" "<replaceable>options</replaceable> </arg> <arg " "choice='plain'><replaceable>HOST</replaceable></arg>" msgstr "" -"<command>sss_knownhosts</command> <arg choice='opt'> <replaceable>flaggor</" -"replaceable> </arg> <arg choice='plain'><replaceable>VÄRD</replaceable></arg>" +"<command>sss_ssh_knownhosts</command> <arg choice='opt'> <replaceable>" +"options</replaceable> </arg> <arg choice='plain'><replaceable>HOST</" +"replaceable></arg>" #. type: Content of: <reference><refentry><refsect1><para> #: sss_ssh_knownhosts.1.xml:32 @@ -18244,10 +18903,10 @@ msgid "" "citerefentry> for more information)." msgstr "" "<command>sss_ssh_knownhosts</command> hämtar publika SSH-nycklar för värden " -"<replaceable>VÄRD</replaceable> och skriver ut dem i formatet för OpenSSH:s " -"known_hosts-nycklar (se avsnittet <quote>SSH_KNOWN_HOSTS-FILFORMAT</quote> i " -"<citerefentry><refentrytitle>sshd</refentrytitle> <manvolnum>8</manvolnum></" -"citerefentry> för mer information)." +"<replaceable>HOST</replaceable> och skriver ut dem i OpenSSH-nyckelformatet " +"known_hosts (mer information finns i avsnittet <quote>SSH_KNOWN_HOSTS FILE " +"FORMAT</quote> i <citerefentry><refentrytitle>sshd</refentrytitle> " +"<manvolnum>8</manvolnum></citerefentry>)." #. type: Content of: <reference><refentry><refsect1><para><programlisting> #: sss_ssh_knownhosts.1.xml:47 @@ -18270,12 +18929,12 @@ msgid "" "manvolnum> </citerefentry> man page for more details about this option." msgstr "" "<citerefentry><refentrytitle>ssh</refentrytitle> <manvolnum>1</manvolnum></" -"citerefentry> kan konfigureras till att använda <command>sss_ssh_knownhosts</" -"command> för autentisering med värdens publika nyckel med alternativet " -"<quote>KnownHostsCommand</quote>: <placeholder type=\"programlisting\" " -"id=\"0\"/> Se manualsidan <citerefentry> <refentrytitle>ssh_config</" -"refentrytitle> <manvolnum>5</manvolnum> </citerefentry> för mer detaljer om " -"detta alternativ." +"citerefentry> kan konfigureras för värdautentisering med publika nycklar med " +"alternativet <quote>KnownHostsCommand</quote> och <command>" +"sss_ssh_knownhosts</command>: <placeholder type=\"programlisting\" " +"id=\"0\"/> Mer information om alternativet finns i manualsidan " +"<citerefentry> <refentrytitle>ssh_config</refentrytitle><manvolnum>5</" +"manvolnum> </citerefentry>." #. type: Content of: <reference><refentry><refsect1><para> #: sss_ssh_knownhosts.1.xml:54 @@ -18289,7 +18948,7 @@ msgstr "" msgid "" "Search for host public keys in SSSD domain <replaceable>DOMAIN</replaceable>." msgstr "" -"Sök efter värdars publika nycklar i SSSD-domänen <replaceable>DOMÄN</" +"Sök efter värdars publika nycklar i SSSD-domänen <replaceable>DOMAIN</" "replaceable>." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> @@ -18304,10 +18963,10 @@ msgid "" "tool will add the unmodified hostname as provided by the caller. If this " "flag is set, only the hostname (no port number) will be added to the keys." msgstr "" -"När nycklarna hämtas från en bakände, inkludera då inte värdnamnet, detta " -"verktyg kommer lägga till det omodifierade värdnamnet som det ges av " -"anroparen. Om denna flagga är satt kommer bara värdnamnet (inget portnummer) " -"läggas till till nycklarna." +"När nycklarna som hämtas från den bakomliggande komponenten inte innehåller " +"värdnamnet lägger verktyget till det oförändrade värdnamn som anges av " +"anroparen. Om denna flagga anges läggs endast värdnamnet, utan portnummer, " +"till i nycklarna." #. type: Content of: <reference><refentry><refsect1><title> #: sss_ssh_knownhosts.1.xml:91 @@ -18316,10 +18975,21 @@ msgstr "NYCKELHÄMTNING" #. type: Content of: <reference><refentry><refsect1><para> #: sss_ssh_knownhosts.1.xml:93 +#, fuzzy +#| msgid "" +#| "The key lines retrieved from the backend are expected to respect the key " +#| "format as decribed in the <quote>SSH_KNOWN_HOSTS FILE FORMAT</quote> " +#| "section of <citerefentry><refentrytitle>sshd</refentrytitle> " +#| "<manvolnum>8</manvolnum></citerefentry>. However, returning only the " +#| "keytype and the key itself is tolerated, in which case, the hostname " +#| "received as parameter will be added before the keytype to output a " +#| "correctly formatted line. The hostname will be added unmodified or just " +#| "the hostname (no port number), depending on whether the <option>-o</" +#| "option>,<option>--only-host-name</option> option was provided." msgid "" "The key lines retrieved from the backend are expected to respect the key " -"format as decribed in the <quote>SSH_KNOWN_HOSTS FILE FORMAT</quote> section " -"of <citerefentry><refentrytitle>sshd</refentrytitle> <manvolnum>8</" +"format as described in the <quote>SSH_KNOWN_HOSTS FILE FORMAT</quote> " +"section of <citerefentry><refentrytitle>sshd</refentrytitle> <manvolnum>8</" "manvolnum></citerefentry>. However, returning only the keytype and the key " "itself is tolerated, in which case, the hostname received as parameter will " "be added before the keytype to output a correctly formatted line. The " @@ -18344,8 +19014,8 @@ msgid "" " [canonical.host.name]:2222 <keytype> <base64-encoded key>\n" " " msgstr "" -" [kanoniskt.värdnamn]:2222 <nyckeltyp> <base64-kodad " -"nyckel>\n" +" [canonical.host.name]:2222 <keytype> <base64-" +"encoded key>\n" " " #. type: Content of: <reference><refentry><refsect1><para> @@ -18356,10 +19026,10 @@ msgid "" "position as part of the key line. For example, the minimal key line would " "be: <placeholder type=\"programlisting\" id=\"0\"/>" msgstr "" -"När SSH-servern lyssnar på en annan port än standardporten MÅSTE bakänden " -"tillhandahålla värdnamnet inklusive portnumret i korrekt format och position " -"som en del av nyckelraden. Till exempel skulle den minimala nyckelraden " -"vara:<placeholder type=\"programlisting\" id=\"0\"/>" +"När SSH-servern lyssnar på en annan port än standardporten MÅSTE den " +"bakomliggande komponenten ange värdnamnet, inklusive portnumret, i rätt " +"format och på rätt plats som en del av nyckelraden. Den minsta nyckelraden " +"skulle till exempel vara: <placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para> #: sss_ssh_knownhosts.1.xml:118 @@ -18368,8 +19038,9 @@ msgid "" "if the ssh responder could not be contacted, 0 is returned. 1 is returned " "in case of any other error." msgstr "" -"Vid lyckad körning returneras 0 även om ingen nyckel hittades för den värden " -"eller om ssh-svararen inte kunde kontaktas. 1 returneras vid alla andra fel." +"Vid lyckad körning returneras 0, även om ingen nyckel hittades för den " +"värden eller om ssh-svararen inte kunde kontaktas. Vid alla andra fel " +"returneras 1." #. type: Content of: <reference><refentry><refnamediv><refname> #: idmap_sss.8.xml:10 idmap_sss.8.xml:15 @@ -18387,9 +19058,9 @@ msgid "" "The idmap_sss module provides a way to call SSSD to map UIDs/GIDs and SIDs. " "No database is required in this case as the mapping is done by SSSD." msgstr "" -"Modulen idmap_sss tillhandahåller ett sätt att anropa SSSD för att översätta " -"AID:er/GID:er och SID:er. Ingen databas behövs i detta fall eftersom " -"översättningen görs av SSSD." +"Modulen idmap_sss tillhandahåller ett sätt att anropa SSSD för att mappa " +"UID:er/GID:er och SID:er. Ingen databas krävs i detta fall eftersom " +"mappningen utförs av SSSD." #. type: Content of: <reference><refentry><refsect1><title> #: idmap_sss.8.xml:29 @@ -18399,7 +19070,7 @@ msgstr "IDMAP-ALTERNATIV" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: idmap_sss.8.xml:33 msgid "range = low - high" -msgstr "range = låg - hög" +msgstr "range = low - high" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: idmap_sss.8.xml:35 @@ -18407,8 +19078,8 @@ msgid "" "Defines the available matching UID and GID range for which the backend is " "authoritative." msgstr "" -"Definierar de tillgängliga matchnings-UID- och GID-intervallen som bakänden " -"är auktoritativ för." +"Definierar det tillgängliga matchande UID- och GID-intervall som den " +"bakomliggande komponenten är auktoritativ för." #. type: Content of: <reference><refentry><refsect1><para> #: idmap_sss.8.xml:45 @@ -18435,10 +19106,11 @@ msgid "" msgstr "" "[global]\n" "security = ads\n" -"workgroup = <AD-DOMÄNKORTNAMN>\n" +"workgroup = <AD-DOMAIN-SHORTNAME>\n" "\n" -"idmap config <AD-DOMÄNKORTNAMN> : backend = sss\n" -"idmap config <AD-DOMÄNKORTNAMN> : range = 200000-2147483647\n" +"idmap config <AD-DOMAIN-SHORTNAME> : backend = sss\n" +"idmap config <AD-DOMAIN-SHORTNAME> : range = 200000-" +"2147483647\n" "\n" "idmap config * : backend = tdb\n" "idmap config * : range = 100000-199999\n" @@ -18452,10 +19124,10 @@ msgid "" "<literal>idmap config</literal> line with <literal>backend = sss</literal> " "and a line with a suitable <literal>range</literal>." msgstr "" -"Ersätt <AD-DOMÄNKORTNAMN> med NetBIOS-domännamnet för AD-domänen. Om " -"flera AD-domäner skall användas behöver varje domän en <literal>idmap " -"config</literal>-rad med <literal>backend = sss</literal> och en rad med ett " -"lämpligt <literal>range</literal>." +"Ersätt <AD-DOMAIN-SHORTNAME> med NetBIOS-domännamnet för AD-domänen. " +"Om flera AD-domäner ska användas behöver varje domän en rad med <literal>" +"idmap config</literal> och <literal>backend = sss</literal>, samt en rad med " +"ett lämpligt <literal>range</literal>." #. type: Content of: <reference><refentry><refsect1><para> #: idmap_sss.8.xml:69 @@ -18483,8 +19155,8 @@ msgid "" "replaceable></arg> <arg choice='opt'> <replaceable>options</replaceable> </" "arg>" msgstr "" -"<command>sssctl</command> <arg choice='plain'><replaceable>KOMMANDO</" -"replaceable></arg> <arg choice='opt'> <replaceable>flaggor</replaceable> </" +"<command>sssctl</command> <arg choice='plain'><replaceable>COMMAND</" +"replaceable></arg> <arg choice='opt'> <replaceable>options</replaceable> </" "arg>" #. type: Content of: <reference><refentry><refsect1><para> @@ -18509,9 +19181,9 @@ msgid "" "parameters. To print help for selected command run <command>sssctl COMMAND --" "help</command>." msgstr "" -"För att lista alla tillgängliga kommandon, kör <command>sssctl</command> " -"utan några parametrar. För att skriva ut hjälp om ett valt kommando, kör " -"<command>sssctl KOMMANDO --help</command>." +"Kör <command>sssctl</command> utan parametrar för att lista alla " +"tillgängliga kommandon. Kör <command>sssctl COMMAND --help</command> för att " +"visa hjälp för ett valt kommando." #. type: Content of: <reference><refentry><refnamediv><refname> #: sssd-session-recording.5.xml:10 sssd-session-recording.5.xml:16 @@ -18535,15 +19207,14 @@ msgid "" "section of the <citerefentry> <refentrytitle>sssd.conf</refentrytitle> " "<manvolnum>5</manvolnum> </citerefentry> manual page." msgstr "" -"Denna manualsida beskriver hur man konfigurerar <citerefentry> " -"<refentrytitle>sssd</refentrytitle> <manvolnum>8</manvolnum> </citerefentry> " -"att fungera med <citerefentry> <refentrytitle>tlog-rec-session</" -"refentrytitle> <manvolnum>8</manvolnum> </citerefentry>, en del av paketet " -"tlog, för att implementera inspelning av användarsessioner på en " -"textterminal. För en detaljerad referens till konfigurationssyntaxen, se " -"avsnittet <quote>FILE FORMAT</quote> av manualsidan <citerefentry> " -"<refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</manvolnum> </" -"citerefentry>." +"Denna manualsida beskriver hur <citerefentry> <refentrytitle>sssd</" +"refentrytitle> <manvolnum>8</manvolnum> </citerefentry> konfigureras för att " +"fungera med <citerefentry> <refentrytitle>tlog-rec-session</refentrytitle> " +"<manvolnum>8</manvolnum> </citerefentry>, en del av paketet tlog, för att " +"spela in användarsessioner på textterminaler. En detaljerad syntaxreferens " +"för konfigurationen finns i avsnittet <quote>FILE FORMAT</quote> i " +"manualsidan <citerefentry> <refentrytitle>sssd.conf</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry>." #. type: Content of: <reference><refentry><refsect1><para> #: sssd-session-recording.5.xml:41 @@ -18554,11 +19225,11 @@ msgid "" "tlog-rec-session is started upon user login, so it can record according to " "its configuration." msgstr "" -"SSSD kan sättas upp för att möjliggöra inspelning av allting specifika " -"användare ser eller skriver under sina sessioner på en textterminal. T.ex., " -"när användare loggar in på konsolen, eller via SSH. SSSD själv spelar inte " -"in någonting, men ser till att tlog-rec-session startas när användaren " -"loggar in, så att den kan spela in enligt sin konfiguration." +"SSSD kan konfigureras för att spela in allt som vissa användare ser eller " +"skriver under sina sessioner på textterminaler, till exempel när de loggar " +"in på konsolen eller via SSH. SSSD spelar inte in något självt utan ser till " +"att tlog-rec-session startas när användaren loggar in, så att den kan spela " +"in enligt sin konfiguration." #. type: Content of: <reference><refentry><refsect1><para> #: sssd-session-recording.5.xml:48 @@ -18569,12 +19240,11 @@ msgid "" "tlog-rec-session can be started in place of the user shell, and know which " "actual shell to start, once it set up the recording." msgstr "" -"För användare med sessionsinspelning aktiverad ersätter SSSD användarens " -"skal med tlog-rec-session i NSS-svar, och lägger till en variabel som anger " -"det ursprungliga skalet till användarens miljö när PAM sätter upp " -"sessionen. På detta sätt kan tlog-rec-session startas istället för " -"användarens skal, och veta vilket faktiskt skal som skall startas när den " -"satt upp inspelningen." +"För användare med aktiverad sessionsinspelning ersätter SSSD användarens " +"skal med tlog-rec-session i NSS-svar och lägger till en variabel som anger " +"det ursprungliga skalet i användarens miljö vid PAM-sessionsinställningen. " +"På så sätt kan tlog-rec-session startas i stället för användarens skal och " +"veta vilket verkligt skal som ska startas när inspelningen har ställts in." #. type: Content of: <reference><refentry><refsect1><para> #: sssd-session-recording.5.xml:60 @@ -18587,8 +19257,8 @@ msgid "" "The following snippet of sssd.conf enables session recording for users " "\"contractor1\" and \"contractor2\", and group \"students\"." msgstr "" -"Följande snutt från sssd.conf gör det möjligt att spela in sessioner för " -"användarna ”konsult1” och ”konsult2” och gruppen ”studenter”." +"Följande utdrag ur sssd.conf aktiverar sessionsinspelning för användarna " +"\"contractor1\" och \"contractor2\" samt gruppen \"students\"." #. type: Content of: <reference><refentry><refsect1><para><programlisting> #: sssd-session-recording.5.xml:183 @@ -18601,8 +19271,8 @@ msgid "" msgstr "" "[session_recording]\n" "scope = some\n" -"users = konsult1,konsult2\n" -"groups = studenter\n" +"users = contractor1, contractor2\n" +"groups = students\n" #. type: Content of: <reference><refentry><refnamediv><refname> #: sssd-kcm.8.xml:10 sssd-kcm.8.xml:16 @@ -18612,7 +19282,7 @@ msgstr "sssd-kcm" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sssd-kcm.8.xml:17 msgid "SSSD Kerberos Cache Manager" -msgstr "SSSD Kerberos cache-hanterare" +msgstr "SSSD Kerberos cachehanterare" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-kcm.8.xml:23 @@ -18623,11 +19293,11 @@ msgid "" "the MIT Kerberos library also provides client side (more details on that " "below) support for the KCM credential cache." msgstr "" -"Denna manualsida beskriver konfigurationen av SSSD:s Kerberos cache-" -"hanterare (KCM). KCM är en process som lagrar, spårar och hanterar " -"Kerberoskreditiv-cachar. Det kommer från projektet Heimdal Kerberos, fast " -"biblioteket MIT Kerberos tillhandahåller även stöd för klientsidan (mer " -"detaljer om det nedan) av KCM-kreditiv-cachen." +"Denna manualsida beskriver konfigurationen av SSSD Kerberos cachehanterare " +"(KCM). KCM är en process som lagrar, spårar och hanterar Kerberos-cachar för " +"autentiseringsuppgifter. Den kommer från projektet Heimdal Kerberos, även om " +"biblioteket MIT Kerberos också tillhandahåller stöd på klientsidan för KCM-" +"cachen för autentiseringsuppgifter (mer information nedan)." #. type: Content of: <reference><refentry><refsect1><para> #: sssd-kcm.8.xml:31 @@ -18639,11 +19309,11 @@ msgid "" "being referred to as a <quote>\"KCM server\"</quote>. The client and server " "communicate over a UNIX socket." msgstr "" -"I en uppsättning där Kerberos cachar hanteras av KCM är Kerberosbiblioteket " -"(typiskt använt via ett program, som t.ex., <citerefentry> <refentrytitle>" -"kinit</refentrytitle><manvolnum>1</manvolnum> </citerefentry>, en <quote>”" -"KCM-klient\"</quote> och KCMdemonen refereras till som en <quote>”KCM-" -"server\"</quote>. Klienten och servern kommunicerar via ett UNIX-uttag." +"I en miljö där Kerberos-cachar hanteras av KCM är Kerberos-biblioteket, som " +"vanligen används via ett program som <citerefentry> <refentrytitle>kinit</" +"refentrytitle><manvolnum>1</manvolnum> </citerefentry>, en <quote>\"KCM " +"client\"</quote>, och KCM-bakgrundsprocessen kallas <quote>\"KCM server\"</" +"quote>. Klienten och servern kommunicerar via ett UNIX-uttag." #. type: Content of: <reference><refentry><refsect1><para> #: sssd-kcm.8.xml:42 @@ -18657,7 +19327,8 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-kcm.8.xml:47 msgid "The KCM credential cache has several interesting properties:" -msgstr "KCM-kreditiv-cachen har flera intressanta egenskaper:" +msgstr "" +"KCM-cachen för autentiseringsuppgifter har flera intressanta egenskaper:" #. type: Content of: <reference><refentry><refsect1><para><itemizedlist><listitem><para> #: sssd-kcm.8.xml:51 @@ -18665,8 +19336,8 @@ msgid "" "since the process runs in userspace, it is subject to UID namespacing, " "unlike the kernel keyring" msgstr "" -"eftersom processen kör i användarrymden är den föremål för AID-namnrymder, " -"till skillnad mot kärnans nyckelring" +"eftersom processen körs i användarrymden omfattas den av UID-namnområden, " +"till skillnad från kärnans nyckelring" #. type: Content of: <reference><refentry><refsect1><para><itemizedlist><listitem><para> #: sssd-kcm.8.xml:56 @@ -18686,9 +19357,9 @@ msgid "" "at <replaceable>/var/lib/sss/secrets</replaceable> allowing the ccaches to " "survive KCM server restarts or machine reboots." msgstr "" -"SSSD-implementationen sparar ccaches i en databas, vanligen placerad i " -"<replaceable>/var/lib/sss/secrets</replaceable>, vilket gör att ccaches kan " -"överleva att KCM-servern eller hela maskinen startas om." +"SSSD-implementeringen lagrar ccachar i en databas, som vanligen finns på " +"<replaceable>/var/lib/sss/secrets</replaceable>. Därmed överlever ccacharna " +"om KCM-servern eller maskinen startas om." #. type: Content of: <reference><refentry><refsect1><para> #: sssd-kcm.8.xml:67 @@ -18697,9 +19368,9 @@ msgid "" "the credential cache between some or no containers by bind-mounting the " "socket." msgstr "" -"Detta gör att systemet kan använda en samlingsmedveten kreditiv-cache, och " -"ändå dela kreditivcachen mellan några eller inga behållare genom " -"bindmontering av uttaget." +"Detta gör att systemet kan använda en samlingsmedveten cache för " +"autentiseringsuppgifter och ändå dela den mellan vissa eller inga behållare " +"genom att bindmontera uttaget." #. type: Content of: <reference><refentry><refsect1><para> #: sssd-kcm.8.xml:72 @@ -18713,7 +19384,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><title> #: sssd-kcm.8.xml:78 msgid "USING THE KCM CREDENTIAL CACHE" -msgstr "ATT ANVÄNDA KCM-KREDITIV-CACHEN" +msgstr "ANVÄNDA KCM-CACHEN FÖR AUTENTISERINGSUPPGIFTER" #. type: Content of: <reference><refentry><refsect1><para><programlisting> #: sssd-kcm.8.xml:88 @@ -18736,11 +19407,12 @@ msgid "" "cache name must be only <quote>KCM:</quote> without any template " "expansions. For example: <placeholder type=\"programlisting\" id=\"0\"/>" msgstr "" -"För att använda KCM-kreditiv-cachen måste den väljas som " -"standardkreditivtypen i <citerefentry> <refentrytitle>krb5.conf</" -"refentrytitle><manvolnum>5</manvolnum> </citerefentry>. Kreditiv-cachens " -"namn skall bara vara <quote>KCM:</quote> utan några mallexpansioner. Till " -"exempel: <placeholder type=\"programlisting\" id=\"0\"/>" +"För att använda KCM-cachen för autentiseringsuppgifter måste den väljas som " +"standardtyp för autentiseringsuppgifter i <citerefentry> <refentrytitle>" +"krb5.conf</refentrytitle><manvolnum>5</manvolnum> </citerefentry>. Cachens " +"namn för autentiseringsuppgifter får endast vara <quote>KCM:</quote>, utan " +"mallexpansioner. Till exempel: <placeholder type=\"programlisting\" " +"id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-kcm.8.xml:93 @@ -18782,18 +19454,18 @@ msgid "" "id=\"0\"/> Please note your distribution may already configure the units for " "you." msgstr "" -"Se slutligen till att SSSD KCM-servern kan kontaktas. KCM-tjänsten är " -"normalt uttagsaktiverad av <citerefentry> <refentrytitle>systemd</" -"refentrytitle> <manvolnum>1</manvolnum> </citerefentry>. Till skillnad mot " -"andra SSSD-tjänster kan den inte startas genom att lägga till strängen " -"<quote>kcm</quote> till direktivet <quote>service</quote>. <placeholder " -"type=\"programlisting\" id=\"0\"/> Observera att din distribution kanske " -"redan konfigurerar enheterna åt dig." +"Kontrollera slutligen att SSSD KCM-servern kan kontaktas. KCM-tjänsten " +"socketaktiveras vanligen av <citerefentry> <refentrytitle>systemd</" +"refentrytitle> <manvolnum>1</manvolnum> </citerefentry>. Till skillnad från " +"andra SSSD-tjänster kan den inte startas genom att strängen <quote>kcm</" +"quote> läggs till i direktivet <quote>service</quote>. <placeholder " +"type=\"programlisting\" id=\"0\"/> Distributionen kan redan ha konfigurerat " +"enheterna åt dig." #. type: Content of: <reference><refentry><refsect1><title> #: sssd-kcm.8.xml:124 msgid "THE CREDENTIAL CACHE STORAGE" -msgstr "KREDITIV-CACHE-LAGRINGEN" +msgstr "LAGRING AV CACHAR FÖR AUTENTISERINGSUPPGIFTER" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-kcm.8.xml:126 @@ -18802,9 +19474,9 @@ msgid "" "or group entries. The database is typically located at <quote>/var/lib/sss/" "secrets</quote>." msgstr "" -"Kreditiv-cachen lagras i en databas, snarlikt hur SSSD cachar användar- " -"eller grupposter. Databasen finns normalt i <quote>/var/lib/sss/secrets</" -"quote>." +"Cacharna för autentiseringsuppgifter lagras i en databas, på samma sätt som " +"SSSD cachar användar- och grupposter. Databasen finns vanligen på <quote>/" +"var/lib/sss/secrets</quote>." #. type: Content of: <reference><refentry><refsect1><title> #: sssd-kcm.8.xml:133 @@ -18848,18 +19520,16 @@ msgid "" "logs when you no longer need the debugging to be enabled as the sssd-kcm " "service can generate quite a large amount of debugging information." msgstr "" -"Tjänsten sssd-kcm är normalt uttagsaktiverad av <citerefentry> " -"<refentrytitle>systemd</refentrytitle> <manvolnum>1</manvolnum> </" -"citerefentry>. För att skapa felsökningsloggar, lägg till följande antingen " -"direkt till filen <filename>/etc/sssd/sssd.conf</filename> eller som en " -"konfigurationssnutt till katalogen <filename>/etc/sssd/conf.d/</filename>: " -"<placeholder type=\"programlisting\" id=\"0\"/> Starta sedan om tjänsten " -"sssd-kcm: <placeholder type=\"programlisting\" id=\"1\"/> Kör slutligen det " -"användningsfall som inte fungerar. KCM-loggarna kommer skapas i <filename>/" -"var/log/sssd/sssd_kcm.log</filename>. Det rekommenderas att avaktivera " -"felsökningsloggarna när man inte längre behöver informationen aktiverad " -"eftersom tjänsten sssd-kcm kan skapa en ganska stor mängd " -"felsökningsinformation." +"Tjänsten sssd-kcm socketaktiveras vanligen av <citerefentry> <refentrytitle>" +"systemd</refentrytitle> <manvolnum>1</manvolnum> </citerefentry>. Lägg till " +"följande direkt i filen <filename>/etc/sssd/sssd.conf</filename> eller som " +"ett konfigurationsutdrag i katalogen <filename>/etc/sssd/conf.d/</filename> " +"för att skapa felsökningsloggar: <placeholder type=\"programlisting\" " +"id=\"0\"/> Starta sedan om tjänsten sssd-kcm: <placeholder " +"type=\"programlisting\" id=\"1\"/> Kör slutligen det användningsfall som " +"inte fungerar. KCM-loggarna skapas i <filename>/var/log/sssd/sssd_kcm.log</" +"filename>. Inaktivera felsökningsloggarna när felsökning inte längre behövs, " +"eftersom sssd-kcm-tjänsten kan skapa stora mängder felsökningsinformation." #. type: Content of: <reference><refentry><refsect1><para> #: sssd-kcm.8.xml:159 @@ -18898,11 +19568,10 @@ msgid "" "following options are set in the [kcm] section: <placeholder " "type=\"programlisting\" id=\"0\"/>" msgstr "" -"Tjänsten sssd-kcm kan konfigureras till att försöka göra TGT-förnyelser med " -"förnybara TGT:er lagrade i KCM-ccachen. Förnyelseförsök görs bara när halva " -"biljettens livstid har uppnåtts. KCM-förnyelser konfigureras när följande " -"alternativ sätts i sektionen [kcm]: <placeholder type=\"programlisting\" " -"id=\"0\"/>" +"Tjänsten sssd-kcm kan konfigureras för att försöka förnya förnybara TGT:er " +"som lagras i KCM-ccachen. Förnyelseförsök görs endast när halva biljettens " +"livslängd har förflutit. KCM-förnyelser konfigureras när följande alternativ " +"anges i avsnittet [kcm]: <placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-kcm.8.xml:179 @@ -18920,7 +19589,7 @@ msgid "" " " msgstr "" "tgt_renewal = true\n" -"tgt_renewal_inherit = domännamn\n" +"tgt_renewal_inherit = domain-name\n" " " #. type: Content of: <reference><refentry><refsect1><para><programlisting> @@ -18950,8 +19619,8 @@ msgid "" "renewal behavior, these options are described in detail below <placeholder " "type=\"programlisting\" id=\"0\"/>" msgstr "" -"Följande krb5-alternativ kan konfigureras i sektionen [kcm] för att styra " -"förnyelsebeteendet, dessa alternativ beskrivs i detalj nedan <placeholder " +"Följande krb5-alternativ kan konfigureras i avsnittet [kcm] för att styra " +"förnyelsebeteendet. Alternativen beskrivs närmare nedan: <placeholder " "type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para> @@ -18963,19 +19632,24 @@ msgid "" "after changing options in the <quote>kcm</quote> section of sssd.conf: " "<placeholder type=\"programlisting\" id=\"0\"/>" msgstr "" -"Tjänsten KCM är konfigurerad i sektionen <quote>kcm</quote> av filen " -"sssd.conf. Observera att eftersom tjänsten KCM typiskt är uttagsaktiverad är " -"det tillräckligt att bara starta om tjänsten <quote>sssd-kcm</quote> efter " -"att ha ändrat flaggorna i sektionen <quote>kcm</quote> av sssd.conf: " -"<placeholder type=\"programlisting\" id=\"0\"/>" +"KCM-tjänsten konfigureras i avsnittet <quote>kcm</quote> i filen sssd.conf. " +"Observera att eftersom KCM-tjänsten vanligen är socketaktiverad räcker det " +"att starta om tjänsten <quote>sssd-kcm</quote> efter att alternativ i " +"avsnittet <quote>kcm</quote> i sssd.conf har ändrats: <placeholder " +"type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-kcm.8.xml:215 -msgid "" -"The KCM service is configured in the <quote>kcm</quote> For a detailed " -"syntax reference, refer to the <quote>FILE FORMAT</quote> section of the " -"<citerefentry> <refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</" -"manvolnum> </citerefentry> manual page." +#, fuzzy +#| msgid "" +#| "The KCM service is configured in the <quote>kcm</quote> For a detailed " +#| "syntax reference, refer to the <quote>FILE FORMAT</quote> section of the " +#| "<citerefentry> <refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</" +#| "manvolnum> </citerefentry> manual page." +msgid "" +"For a detailed syntax reference, refer to the <quote>FILE FORMAT</quote> " +"section of the <citerefentry> <refentrytitle>sssd.conf</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry> manual page." msgstr "" "Tjänsten KCM konfigureras i <quote>kcm</quote> För en detaljeras " "syntaxreferens, se avsnittet <quote>FILFORMAT</quote> i manualsidan " @@ -18983,7 +19657,7 @@ msgstr "" "manvolnum> </citerefentry>." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-kcm.8.xml:223 +#: sssd-kcm.8.xml:222 msgid "" "The generic SSSD service options such as <quote>debug_level</quote> or " "<quote>fd_limit</quote> are accepted by the kcm service. Please refer to " @@ -18998,117 +19672,125 @@ msgstr "" "några KCM-specifika alternativ också." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:234 +#: sssd-kcm.8.xml:233 msgid "socket_path (string)" msgstr "socket_path (sträng)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:237 +#: sssd-kcm.8.xml:236 msgid "The socket the KCM service will listen on." -msgstr "Uttaget tjänsten KCM kommer lyssna på." +msgstr "Det uttag som KCM-tjänsten lyssnar på." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:240 +#: sssd-kcm.8.xml:239 msgid "Default: <replaceable>/var/run/.heim_org.h5l.kcm-socket</replaceable>" msgstr "Standard: <replaceable>/var/run/.heim_org.h5l.kcm-socket</replaceable>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:243 +#: sssd-kcm.8.xml:242 msgid "" "<phrase condition=\"have_systemd\"> Note: on platforms where systemd is " "supported, the socket path is overwritten by the one defined in the sssd-" "kcm.socket unit file. </phrase>" msgstr "" -"<phrase condition=\"have_systemd\"> Observera: på plattformar där systemd " -"stödjs skrivs uttagssökvägen över av den som definieras i enhetsfilen sssd-" -"kcm.socket. </phrase>" +"<phrase condition=\"have_systemd\"> Observera: På plattformar där systemd " +"stöds skrivs sökvägen till uttaget över av den som definieras i enhetsfilen " +"sssd-kcm.socket. </phrase>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:252 +#: sssd-kcm.8.xml:251 msgid "max_ccaches (integer)" msgstr "max_ccaches (heltal)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:255 +#: sssd-kcm.8.xml:254 msgid "How many credential caches does the KCM database allow for all users." -msgstr "Hur många kreditivcacher KCM-databasen tillåter för alla användare." +msgstr "" +"Antalet cachar för autentiseringsuppgifter som KCM-databasen tillåter för " +"alla användare." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:259 +#: sssd-kcm.8.xml:258 msgid "Default: 0 (unlimited, only the per-UID quota is enforced)" -msgstr "Standard: 0 (obegränsad, endast kvot per AID upprätthålls)" +msgstr "Standard: 0 (obegränsat; endast kvoten per UID tillämpas)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:264 +#: sssd-kcm.8.xml:263 msgid "max_uid_ccaches (integer)" msgstr "max_uid_ccaches (heltal)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:267 +#: sssd-kcm.8.xml:266 msgid "" "How many credential caches does the KCM database allow per UID. This is " "equivalent to <quote>with how many principals you can kinit</quote>." msgstr "" -"Hur många kreditiv-cachningar KCM-databasen tillåter per AID. Detta är " -"ekvivalent med <quote>med hur många huvudmän man kan kinit:a</quote>." +"Antalet cachar för autentiseringsuppgifter som KCM-databasen tillåter per " +"UID. Detta motsvarar <quote>with how many principals you can kinit</quote>." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:272 +#: sssd-kcm.8.xml:271 msgid "Default: 64" msgstr "Standard: 64" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:277 +#: sssd-kcm.8.xml:276 msgid "max_ccache_size (integer)" msgstr "max_ccache_size (heltal)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:280 +#: sssd-kcm.8.xml:279 +#, fuzzy +#| msgid "" +#| "How big can a credential cache be per ccache. Each service ticket " +#| "accounts into this quota." msgid "" -"How big can a credential cache be per ccache. Each service ticket accounts " -"into this quota." +"How big a credential cache be per ccache. Each service ticket counts toward " +"this quota." msgstr "" "Hor stor kan en kreditivcach vara per ccache. Varje tjänsteärende räknas in " "i denna kvot." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:284 +#: sssd-kcm.8.xml:283 msgid "Default: 65536" msgstr "Standard: 65536" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:289 -msgid "tgt_renewal (bool)" +#: sssd-kcm.8.xml:288 +#, fuzzy +#| msgid "tgt_renewal (bool)" +msgid "tgt_renewal (boolean)" msgstr "tgt_renewal (bool)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:292 +#: sssd-kcm.8.xml:291 msgid "Enables TGT renewals functionality." -msgstr "Aktiverar TGT-förnyelsefunktionalitet." +msgstr "Aktiverar funktionen för TGT-förnyelser." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:295 +#: sssd-kcm.8.xml:294 msgid "Default: False (Automatic renewals disabled)" -msgstr "Standard: False (Automatiska förnyelser avaktiverade)" +msgstr "Standard: False (automatiska förnyelser inaktiverade)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:300 +#: sssd-kcm.8.xml:299 msgid "tgt_renewal_inherit (string)" msgstr "tgt_renewal_inherit (sträng)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:303 +#: sssd-kcm.8.xml:302 msgid "Domain to inherit krb5_* options from, for use with TGT renewals." msgstr "" -"Domän att ärva krb5_*-alternativ ifrån, att användas med TGT-förnyelser." +"Domän att ärva krb5_*-alternativ från för användning med TGT-förnyelser." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:307 +#: sssd-kcm.8.xml:306 msgid "Default: NULL" msgstr "Standard: NULL" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-kcm.8.xml:318 +#: sssd-kcm.8.xml:317 msgid "" "<citerefentry> <refentrytitle>sssd</refentrytitle><manvolnum>8</manvolnum> </" "citerefentry>, <citerefentry> <refentrytitle>sssd.conf</" @@ -19126,7 +19808,7 @@ msgstr "sssd-systemtap" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sssd-systemtap.5.xml:17 msgid "SSSD systemtap information" -msgstr "SSSD systemtap-information" +msgstr "SystemTap-information för SSSD" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-systemtap.5.xml:23 @@ -19145,8 +19827,8 @@ msgid "" "SystemTap Probe points have been added into various locations in SSSD code " "to assist in troubleshooting and analyzing performance related issues." msgstr "" -"SystemTap-testpunkter har lagts till på diverse platser i SSSD-koden för att " -"hjälpa till i felsökning och analys av prestandarelaterade problem." +"SystemTap-testpunkter har lagts till på olika platser i SSSD-koden för att " +"underlätta felsökning och analys av prestandarelaterade problem." #. type: Content of: <reference><refentry><refsect1><para><itemizedlist><listitem><para> #: sssd-systemtap.5.xml:40 @@ -19197,10 +19879,10 @@ msgid "" "...\n" " " msgstr "" -"variabel1:datatyp\n" -"variabel2:datatyp\n" -"variabel3:datatyp\n" -"…\n" +"variable1:datatype\n" +"variable2:datatype\n" +"variable3:datatype\n" +"...\n" " " #. type: Content of: <reference><refentry><refsect1><refsect2><title> @@ -19230,8 +19912,8 @@ msgid "" "probestr:string\n" " " msgstr "" -"nesting:heltal\n" -"probestr:sträng\n" +"nesting:integer\n" +"probestr:string\n" " " #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> @@ -19294,11 +19976,11 @@ msgid "" "probestr:string\n" " " msgstr "" -"base:sträng\n" -"scope:heltal\n" -"filter:sträng\n" -"attrs:sträng\n" -"probestr:sträng\n" +"base:string\n" +"scope:integer\n" +"filter:string\n" +"attrs:string\n" +"probestr:string\n" " " #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> @@ -19321,10 +20003,10 @@ msgid "" "probestr:string\n" " " msgstr "" -"base:sträng\n" -"scope:heltal\n" -"filter:sträng\n" -"probestr:sträng\n" +"base:string\n" +"scope:integer\n" +"filter:string\n" +"probestr:string\n" " " #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> @@ -19338,8 +20020,8 @@ msgid "" "Probes the sdap_parse_entry() function. It is called repeatedly with every " "received attribute." msgstr "" -"Känner av funktionen sdap_parse_entry(). Den anropas upprepat för varje " -"mottaget attribut." +"Avsöker funktionen sdap_parse_entry(). Den anropas upprepade gånger för " +"varje mottaget attribut." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><programlisting> #: sssd-systemtap.5.xml:184 @@ -19349,8 +20031,8 @@ msgid "" "value:string\n" " " msgstr "" -"attr:sträng\n" -"value:sträng\n" +"attr:string\n" +"value:string\n" " " #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> @@ -19364,8 +20046,8 @@ msgid "" "Probes the sdap_parse_entry() function. It is called when parsing of " "received object is finished." msgstr "" -"Känner av funktionen sdap_parse_entry(). Den anropas när tolkning av " -"mottagna objekt är klar." +"Avsöker funktionen sdap_parse_entry(). Den anropas när tolkningen av det " +"mottagna objektet är klar." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd-systemtap.5.xml:201 @@ -19386,9 +20068,9 @@ msgid "" "probestr:string\n" " " msgstr "" -"base_dn:sträng\n" -"deref_attr:sträng\n" -"probestr:sträng\n" +"base_dn:string\n" +"deref_attr:string\n" +"probestr:string\n" " " #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> @@ -19404,7 +20086,7 @@ msgstr "Känner av funktionen sdap_deref_search_recv()." #. type: Content of: <reference><refentry><refsect1><refsect2><title> #: sssd-systemtap.5.xml:234 msgid "LDAP Account Request Probes" -msgstr "Testpunkter av LDAP-kontobegäranden" +msgstr "LDAP-TESTPUNKTER FÖR KONTOBEGÄRANDEN" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd-systemtap.5.xml:238 @@ -19426,10 +20108,10 @@ msgid "" "extra_value:string\n" " " msgstr "" -"entry_type:heltal\n" -"filter_type:heltal\n" -"filter_value:sträng\n" -"extra_value:sträng\n" +"entry_type:int\n" +"filter_type:int\n" +"filter_value:string\n" +"extra_value:string\n" " " #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> @@ -19445,7 +20127,7 @@ msgstr "Känner av funktionen sdap_acct_req_recv()." #. type: Content of: <reference><refentry><refsect1><refsect2><title> #: sssd-systemtap.5.xml:272 msgid "LDAP User Search Probes" -msgstr "Testpunkter av LDAP-användarsökningar" +msgstr "LDAP-TESTPUNKTER FÖR ANVÄNDARSÖKNINGAR" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd-systemtap.5.xml:276 @@ -19465,7 +20147,7 @@ msgid "" "filter:string\n" " " msgstr "" -"filter:sträng\n" +"filter:string\n" " " #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> @@ -19501,7 +20183,7 @@ msgstr "Känner av funktionen sdap_search_user_save_end()." #. type: Content of: <reference><refentry><refsect1><refsect2><title> #: sssd-systemtap.5.xml:328 msgid "Data Provider Request Probes" -msgstr "Testpunkter av dataleverantörsbegäranden" +msgstr "TESTPUNKTER FÖR BEGÄRANDEN TILL DATALEVERANTÖREN" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd-systemtap.5.xml:332 @@ -19511,7 +20193,7 @@ msgstr "probe dp_req_send" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd-systemtap.5.xml:335 msgid "A Data Provider request is submitted." -msgstr "En dataleverantörsbegäran skickas." +msgstr "En begäran till dataleverantören skickas." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><programlisting> #: sssd-systemtap.5.xml:338 @@ -19523,10 +20205,10 @@ msgid "" "dp_req_method:int\n" " " msgstr "" -"dp_req_domain:sträng\n" -"dp_req_name:sträng\n" -"dp_req_target:heltal\n" -"dp_req_method:heltal\n" +"dp_req_domain:string\n" +"dp_req_name:string\n" +"dp_req_target:int\n" +"dp_req_method:int\n" " " #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> @@ -19537,7 +20219,7 @@ msgstr "probe dp_req_done" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd-systemtap.5.xml:349 msgid "A Data Provider request is completed." -msgstr "En dataleverantörsbegäran avslutas." +msgstr "En begäran till dataleverantören slutförs." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><programlisting> #: sssd-systemtap.5.xml:352 @@ -19550,11 +20232,11 @@ msgid "" "dp_errorstr:string\n" " " msgstr "" -"dp_req_name:sträng\n" -"dp_req_target:heltal\n" -"dp_req_method:heltal\n" -"dp_ret:heltal\n" -"dp_errorstr:sträng\n" +"dp_req_name:string\n" +"dp_req_target:int\n" +"dp_req_method:int\n" +"dp_ret:int\n" +"dp_errorstr:string\n" " " #. type: Content of: <reference><refentry><refsect1><refsect2><title> @@ -19565,12 +20247,12 @@ msgstr "DIVERSE FUNKTIONER" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd-systemtap.5.xml:372 msgid "function acct_req_desc(entry_type)" -msgstr "funktionen acct_req_desc(posttyp)" +msgstr "function acct_req_desc(entry_type)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd-systemtap.5.xml:375 msgid "Convert entry_type to string and return string" -msgstr "Konvertera posttyp till en sträng och returnera strängen" +msgstr "Konvertera entry_type till en sträng och returnera strängen" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd-systemtap.5.xml:380 @@ -19578,18 +20260,18 @@ msgid "" "function sssd_acct_req_probestr(fc_name, entry_type, filter_type, " "filter_value, extra_value)" msgstr "" -"function sssd_acct_req_probestr(fc_namn, posttyp, filtertyp, filtervärde, " -"extravärde)" +"function sssd_acct_req_probestr(fc_name, entry_type, filter_type, " +"filter_value, extra_value)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd-systemtap.5.xml:384 msgid "Create probe string based on filter type" -msgstr "Skapa testpunktsträng baserad på filtertyp" +msgstr "Skapa en testpunktssträng utifrån filtertypen" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd-systemtap.5.xml:389 msgid "function dp_target_str(target)" -msgstr "funktionen dp_target_str(mål)" +msgstr "function dp_target_str(target)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd-systemtap.5.xml:392 @@ -19599,7 +20281,7 @@ msgstr "Konvertera målet till en sträng och returnera strängen" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd-systemtap.5.xml:397 msgid "function dp_method_str(target)" -msgstr "funktionen dp_method_str(mål)" +msgstr "function dp_method_str(target)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd-systemtap.5.xml:400 @@ -19619,13 +20301,13 @@ msgid "" "the script will collect information from probes." msgstr "" "Starta SystemTap-skriptet (<command>stap /usr/share/sssd/systemtap/" -"<skriptnamn>.stp</command>), utför sedan en identitetsåtgärd och " -"skriptet kommer samla information från sonder." +"<script_name>.stp</command>), utför sedan en identitetsåtgärd så " +"samlar skriptet in information från testpunkterna." #. type: Content of: <reference><refentry><refsect1><para> #: sssd-systemtap.5.xml:418 msgid "Provided SystemTap scripts are:" -msgstr "Levererade SystemTap-skript är:" +msgstr "De medföljande SystemTap-skripten är:" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd-systemtap.5.xml:422 @@ -19635,7 +20317,7 @@ msgstr "dp_request.stp" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd-systemtap.5.xml:425 msgid "Monitoring of data provider request performance." -msgstr "Övervakning av prestanda hos dataleverantörbegäranden." +msgstr "Övervakning av prestandan för begäranden till dataleverantören." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd-systemtap.5.xml:430 @@ -19655,7 +20337,7 @@ msgstr "ldap_perf.stp" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd-systemtap.5.xml:442 msgid "Monitoring of LDAP queries." -msgstr "Övervakning av LDAP-begäranden." +msgstr "Övervakning av LDAP-frågor." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd-systemtap.5.xml:447 @@ -19665,7 +20347,7 @@ msgstr "nested_group_perf.stp" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd-systemtap.5.xml:450 msgid "Performance of nested groups resolving." -msgstr "Prestanda vid uppslagning av nästade grupper." +msgstr "Prestanda vid upplösning av nästade grupper." #. type: Content of: <reference><refentry><refnamediv><refname> #: sssd-ldap-attributes.5.xml:10 sssd-ldap-attributes.5.xml:16 @@ -19675,7 +20357,7 @@ msgstr "sssd-ldap-attributes" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sssd-ldap-attributes.5.xml:17 msgid "SSSD LDAP Provider: Mapping Attributes" -msgstr "SSSD LDAP-leverantör: Avbildningsattribut" +msgstr "SSSD LDAP-leverantör: Mappningsattribut" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ldap-attributes.5.xml:23 @@ -19686,11 +20368,12 @@ msgid "" "ldap</refentrytitle> <manvolnum>5</manvolnum> </citerefentry> manual page " "for full details about SSSD LDAP provider configuration options." msgstr "" -"Denna manualsida beskriver avbildningsattributen till SSSD LDAP-leverantören " +"Denna manualsida beskriver mappningsattributen för SSSD LDAP-leverantören " +"<citerefentry> <refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry>. Fullständig information om " +"konfigurationsalternativen för SSSD LDAP-leverantören finns i manualsidan " "<citerefentry> <refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</" -"manvolnum> </citerefentry>. Se manualsidan <citerefentry> <refentrytitle>" -"sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> </citerefentry> för " -"fullständiga detaljer om SSSD LDAP-leverantörens konfigurationsflaggor." +"manvolnum> </citerefentry>." #. type: Content of: <reference><refentry><refsect1><title> #: sssd-ldap-attributes.5.xml:38 @@ -19735,7 +20418,7 @@ msgstr "ldap_user_uid_number (sträng)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:71 msgid "The LDAP attribute that corresponds to the user's id." -msgstr "LDAP-attributet som motsvarar användarens id." +msgstr "LDAP-attributet som motsvarar användarens ID." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:75 @@ -19750,7 +20433,7 @@ msgstr "ldap_user_gid_number (sträng)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:84 msgid "The LDAP attribute that corresponds to the user's primary group id." -msgstr "LDAP-attributet som motsvarar användarens primära grupp-id." +msgstr "LDAP-attributet som motsvarar användarens primärgrupps-ID." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:88 sssd-ldap-attributes.5.xml:700 @@ -19769,9 +20452,9 @@ msgid "" "attribute should only be set manually if you are running the <quote>ldap</" "quote> provider with ID mapping." msgstr "" -"Active Directorys primära gruppattribut för ID-mappning. Observera att " -"detta attribut skall bara sättas manuellt om du kör <quote>ldap</quote>-" -"leverantören med ID-mappning." +"Active Directorys primärgruppsattribut för ID-mappning. Observera att " +"attributet endast ska anges manuellt om du kör leverantören <quote>ldap</" +"quote> med ID-mappning." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:103 @@ -19853,13 +20536,14 @@ msgid "" "The LDAP attribute that contains the objectSID of an LDAP user object. This " "is usually only necessary for ActiveDirectory servers." msgstr "" -"LDAP-attributet som innehåller objectSID för ett LDAP-användarobjekt. Detta " -"är normalt bara nödvändigt för Active Directory-servrar." +"LDAP-attributet som innehåller objectSID för ett LDAP-användarobjekt. Detta " +"behövs vanligen endast för Active Directory-servrar." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:170 sssd-ldap-attributes.5.xml:741 msgid "Default: objectSid for ActiveDirectory, not set for other servers." -msgstr "Standard: objectSid för Active Directory, inte satt för andra servrar." +msgstr "" +"Standard: objectSid för Active Directory, inte angivet för andra servrar." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:177 @@ -20010,10 +20694,10 @@ msgid "" "<citerefentry> <refentrytitle>shadow</refentrytitle> <manvolnum>5</" "manvolnum> </citerefentry> counterpart (account expiration date)." msgstr "" -"När ldap_pwd_policy=shadow används innehåller denna parameter namnet på ett " -"LDAP-attribut som utgör dess motsvarighet i <citerefentry> <refentrytitle>" -"shadow</refentrytitle> <manvolnum>5</manvolnum> </citerefentry> (tid då " -"kontot går ut)." +"När ldap_pwd_policy=shadow eller ldap_account_expire_policy=shadow används " +"innehåller denna parameter namnet på ett LDAP-attribut som motsvarar dess " +"motsvarighet i <citerefentry> <refentrytitle>shadow</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry> (kontots utgångsdatum)." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:296 @@ -20033,8 +20717,8 @@ msgid "" "kerberos." msgstr "" "När ldap_pwd_policy=mit_kerberos används innehåller denna parameter namnet " -"på ett LDAP-attribut som lagrar dag och tid för senaste lösenordsändring i " -"kerberos." +"på ett LDAP-attribut som lagrar datum och tid för den senaste " +"lösenordsändringen i Kerberos." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:311 @@ -20092,7 +20776,7 @@ msgid "" "of an LDAP attribute storing the user account control bit field." msgstr "" "När ldap_account_expire_policy=ad används innehåller denna parameter namnet " -"på ett LDAP-attribut som lagrar användarkontots styrbitfält." +"på ett LDAP-attribut som lagrar bitfältet för styrning av användarkonton." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:354 @@ -20133,9 +20817,11 @@ msgstr "" "skall tillåtas eller inte." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap-attributes.5.xml:381 sssd-ldap-attributes.5.xml:395 -msgid "Default: loginDisabled" -msgstr "Standard: loginDisabled" +#: sssd-ldap-attributes.5.xml:381 +#, fuzzy +#| msgid "Default: uid (rfc2307, rfc2307bis and IPA), sAMAccountName (AD)" +msgid "Default: loginDisabled (rfc2307, rfc2307bis and IPA), not set (AD)" +msgstr "Standard: uid (rfc2307, rfc2307bis och IPA), sAMAccountName (AD)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:387 @@ -20151,6 +20837,14 @@ msgstr "" "När ldap_account_expire_policy=nds används avgör detta attribut till vilket " "datum åtkomst tillåts." +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:395 +#, fuzzy +#| msgid "Default: cn (rfc2307, rfc2307bis and IPA), sAMAccountName (AD)" +msgid "" +"Default: loginExpirationTime (rfc2307, rfc2307bis and IPA), not set (AD)" +msgstr "Standard: cn (rfc2307, rfc2307bis och IPA), sAMAccountName (AD)" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:401 msgid "ldap_user_nds_login_allowed_time_map (string)" @@ -20162,13 +20856,16 @@ msgid "" "When using ldap_account_expire_policy=nds, this attribute determines the " "hours of a day in a week when access is granted." msgstr "" -"När ldap_account_expire_policy=nds används avgör detta attribut vilka timmar " -"på dagen i en vecka åtkomst tillåts." +"När ldap_account_expire_policy=nds används avgör detta attribut under vilka " +"timmar på veckans dagar åtkomst tillåts." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:409 -msgid "Default: loginAllowedTimeMap" -msgstr "Standard: loginAllowedTimeMap" +#, fuzzy +#| msgid "Default: uid (rfc2307, rfc2307bis and IPA), sAMAccountName (AD)" +msgid "" +"Default: loginAllowedTimeMap (rfc2307, rfc2307bis and IPA), not set (AD)" +msgstr "Standard: uid (rfc2307, rfc2307bis och IPA), sAMAccountName (AD)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:415 @@ -20181,8 +20878,8 @@ msgid "" "The LDAP attribute that contains the user's Kerberos User Principal Name " "(UPN)." msgstr "" -"LDAP-attributet som innehåller användarens användarhuvudmansnamn i Kerberos " -"(UPN)." +"LDAP-attributet som innehåller användarens Kerberos User Principal Name (UPN)" +"." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:422 @@ -20200,8 +20897,8 @@ msgid "" "Comma-separated list of LDAP attributes that SSSD would fetch along with the " "usual set of user attributes." msgstr "" -"Kommaseparerad lista av LDAP-attribut som SSSD skall hämta tillsammans med " -"den vanliga uppsättningen av användarattribut." +"Kommaseparerad lista med LDAP-attribut som SSSD hämtar tillsammans med den " +"vanliga uppsättningen användarattribut." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:436 @@ -20212,11 +20909,11 @@ msgid "" "verbatim. Using a custom SSSD attribute name might be required by " "environments that configure several SSSD domains with different LDAP schemas." msgstr "" -"Listan kan antingen innehålla endast LDAP-attributnamn, eller " -"kolonseparerade tupler av SSSD-cacheattribut och LDAP-attributnamn. Ifall " -"endast LDAP-attributnamn anges sparas attributet i cachen ordagrant. Att " -"använda ett anpassat SSSD-attributnamn kan vara nödvändigt i miljöer som " -"konfigurerar flera SSSD-domäner med olika LDAP-scheman." +"Listan kan antingen innehålla endast LDAP-attributnamn eller kolonseparerade " +"tupler med SSSD-cacheattributnamn och LDAP-attributnamn. Om endast LDAP-" +"attributnamnet anges sparas attributet ordagrant i cachen. Ett anpassat SSSD-" +"attributnamn kan krävas i miljöer som konfigurerar flera SSSD-domäner med " +"olika LDAP-scheman." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:446 @@ -20225,9 +20922,9 @@ msgid "" "<quote>name</quote> attribute. SSSD would report an error if any of the " "reserved attribute names is used as an extra attribute name." msgstr "" -"Observera att flera attributnamn är reserverade av SSSD, speciellt " -"attributet <quote>name</quote>. SSSD rapporterar ett fel om något av de " -"reserverade attributnamnen används som ett extra attributnamn." +"Observera att flera attributnamn är reserverade av SSSD, framför allt " +"attributet <quote>name</quote>. SSSD rapporterar ett fel om något av de " +"reserverade attributnamnen används som namn på ett extra attribut." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:456 @@ -20309,9 +21006,9 @@ msgid "" "use the presence of the authorizedService attribute in the user's LDAP entry " "to determine access privilege." msgstr "" -"Om access_provider=ldap och ldap_access_order=authorized_service kommer SSSD " -"använda förekomsten av attributet authorizedService i användarens LDAP-post " -"för att avgöra åtkomstprivilegier." +"Om access_provider=ldap och ldap_access_order=authorized_service används " +"använder SSSD förekomsten av attributet authorizedService i användarens LDAP-" +"post för att avgöra åtkomstbehörigheten." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:525 @@ -20319,8 +21016,8 @@ msgid "" "An explicit deny (!svc) is resolved first. Second, SSSD searches for " "explicit allow (svc) and finally for allow_all (*)." msgstr "" -"Ett explicit nekande (!svc) avgörs först. Därefter söker SSSD efter " -"explicit tillåtelse (svc) och slutligen efter allow_all (*)." +"Ett uttryckligt nekande (!svc) avgörs först. Därefter söker SSSD efter " +"uttryckligt tillåtande (svc) och slutligen efter allow_all (*)." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:530 @@ -20341,10 +21038,10 @@ msgid "" "Therefore when using service-based access control, the <quote>systemd-user</" "quote> service might need to be added to the list of allowed services." msgstr "" -"Några distributioner (såsom Fedora-29+ eller RHEL-8) inkluderar alltid PAM-" +"Vissa distributioner, såsom Fedora-29+ eller RHEL-8, inkluderar alltid PAM-" "tjänsten <quote>systemd-user</quote> som en del av inloggningsprocessen. " -"Därför kan när tjänstebaserad åtkomstkontroll används tjänsten <quote>" -"systemd-user</quote> behöva läggas till till listan av tillåtna tjänster." +"Därför kan tjänsten <quote>systemd-user</quote> behöva läggas till i listan " +"över tillåtna tjänster vid tjänstebaserad åtkomstkontroll." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:545 @@ -20363,9 +21060,9 @@ msgid "" "presence of the host attribute in the user's LDAP entry to determine access " "privilege." msgstr "" -"Om access_provider=ldap och ldap_access_order=host kommer SSSD använda " +"Om access_provider=ldap och ldap_access_order=host används använder SSSD " "förekomsten av attributet host i användarens LDAP-post för att avgöra " -"åtkomstprivilegier." +"åtkomstbehörigheten." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:560 @@ -20373,8 +21070,8 @@ msgid "" "An explicit deny (!host) is resolved first. Second, SSSD searches for " "explicit allow (host) and finally for allow_all (*)." msgstr "" -"Ett explicit nekande (!host) avgörs först. Därefter söker SSSD efter " -"explicit tillåtelse (host) och slutligen efter allow_all (*)." +"Ett uttryckligt nekande (!host) avgörs först. Därefter söker SSSD efter " +"uttryckligt tillåtande (host) och slutligen efter allow_all (*)." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:565 @@ -20404,9 +21101,9 @@ msgid "" "presence of the rhost attribute in the user's LDAP entry to determine access " "privilege. Similarly to host verification process." msgstr "" -"Om access_provider=ldap och ldap_access_order=rhost kommer SSSD använda " +"Om access_provider=ldap och ldap_access_order=rhost används använder SSSD " "förekomsten av attributet rhost i användarens LDAP-post för att avgöra " -"åtkomstprivilegier. Liknande värdverifieringsprocessen." +"åtkomstbehörigheten, på samma sätt som vid host-verifiering." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:588 @@ -20414,8 +21111,8 @@ msgid "" "An explicit deny (!rhost) is resolved first. Second, SSSD searches for " "explicit allow (rhost) and finally for allow_all (*)." msgstr "" -"Ett explicit nekande (!rhost) avgörs först. Därefter söker SSSD efter " -"explicit tillåtelse (rhost) och slutligen efter allow_all (*)." +"Ett uttryckligt nekande (!rhost) avgörs först. Därefter söker SSSD efter " +"uttryckligt tillåtande (rhost) och slutligen efter allow_all (*)." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:593 @@ -20468,13 +21165,13 @@ msgid "" "address then set this option to a nonexistent attribute name in order to " "disable user lookup/login by email." msgstr "" -"Observera: om en e-postadress för användaren står i konflikt med en e-" -"postadress eller fullt kvalificerat namn för en annan användare, då kommer " -"SSSD inte kunna serva dessa användare ordentligt. Detta alternativ gör att " -"användare kan logga in med (1) användarnamn och (2) e-postadress. Om flera " -"användare av något skäl behöver dela samma e-postadress, sätt då detta " -"attributnamn till ett som inte finns för att avaktivera uppslagning/" -"inloggning av användare via e-post." +"Observera: Om en användares e-postadress står i konflikt med en annan " +"användares e-postadress eller fullständigt kvalificerade namn kan SSSD inte " +"hantera dessa användare korrekt. Alternativet låter användare logga in med " +"(1) användarnamn och (2) e-postadress. Om flera användare av något skäl " +"behöver dela samma e-postadress, ställ in alternativet till namnet på ett " +"attribut som inte finns för att inaktivera användaruppslagning och " +"inloggning via e-post." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:637 @@ -20491,8 +21188,8 @@ msgstr "ldap_user_passkey (sträng)" msgid "" "Name of the LDAP attribute containing the passkey mapping data of the user." msgstr "" -"Namnet på LDAP-attributet som innehåller användarens avbildningsdata för " -"lösennyckel." +"Namnet på LDAP-attributet som innehåller användarens mappningsdata för " +"passnycklar." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:649 @@ -20533,8 +21230,8 @@ msgid "" "of nested groups." msgstr "" "LDAP-attributet som motsvarar gruppnamnet. I en miljö med nästade grupper " -"måste detta värde vara ett LDAP-attribut vilket har ett unikt namn för varje " -"grupp. Detta krav inkluderar icke-POSIX-grupper i trädet av nästade grupper." +"måste värdet vara ett LDAP-attribut med ett unikt namn för varje grupp. " +"Kravet omfattar även icke-POSIX-grupper i trädet med nästade grupper." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:686 @@ -20549,7 +21246,7 @@ msgstr "ldap_group_gid_number (sträng)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:696 msgid "The LDAP attribute that corresponds to the group's id." -msgstr "LDAP-attributet som motsvarar gruppens id." +msgstr "LDAP-attributet som motsvarar gruppens ID." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:706 @@ -20606,8 +21303,8 @@ msgid "" "The LDAP attribute that contains an integer value indicating the type of the " "group and maybe other flags." msgstr "" -"LDAP-attributet som innehåller ett heltalsvärde som indikerar grupptypen och " -"kanske andra flaggor." +"LDAP-attributet som innehåller ett heltalsvärde som anger grupptypen och " +"eventuellt andra flaggor." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:769 @@ -20636,8 +21333,8 @@ msgid "" "The LDAP attribute that references group members that are defined in an " "external domain. At the moment, only IPA's external members are supported." msgstr "" -"LDAP-attributet som refererar gruppmedlemmar som är definierade i en extern " -"domän. För närvarande stödjs endast IPA:s externa medlemmar." +"LDAP-attributet som refererar till gruppmedlemmar som är definierade i en " +"extern domän. För närvarande stöds endast IPA:s externa medlemmar." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:791 @@ -20662,7 +21359,7 @@ msgstr "Objektklassen hos en nätgruppspost i LDAP." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:811 msgid "In IPA provider, ipa_netgroup_object_class should be used instead." -msgstr "I IPA-leverantören skall ipa_netgroup_object_class användas istället." +msgstr "I IPA-leverantören ska ipa_netgroup_object_class användas i stället." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:815 @@ -20682,7 +21379,7 @@ msgstr "LDAP-attributet som motsvarar nätgruppnamnet." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:828 msgid "In IPA provider, ipa_netgroup_name should be used instead." -msgstr "I IPA-leverantören skall ipa_netgroup_name användas istället." +msgstr "I IPA-leverantören ska ipa_netgroup_name användas i stället." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:838 @@ -20697,7 +21394,7 @@ msgstr "LDAP-attributet som innehåller namnen på nätgruppens medlemmar." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:845 msgid "In IPA provider, ipa_netgroup_member should be used instead." -msgstr "I IPA-leverantören skall ipa_netgroup_member användas istället." +msgstr "I IPA-leverantören ska ipa_netgroup_member användas i stället." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:849 @@ -20714,7 +21411,8 @@ msgstr "ldap_netgroup_triple (sträng)" msgid "" "The LDAP attribute that contains the (host, user, domain) netgroup triples." msgstr "" -"LDAP-attributet som innehåller nätgrupptrippeln (värd, användare, domän)." +"LDAP-attributet som innehåller nätgruppstriplettarna (värd, användare, domän)" +"." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:862 sssd-ldap-attributes.5.xml:878 @@ -20747,9 +21445,9 @@ msgid "The object class of a host entry in LDAP." msgstr "Objektklassen hos en värdpost i LDAP." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap-attributes.5.xml:900 sssd-ldap-attributes.5.xml:997 -msgid "Default: ipService" -msgstr "Standard: ipService" +#: sssd-ldap-attributes.5.xml:900 sssd-ldap-attributes.5.xml:1213 +msgid "Default: ipHost" +msgstr "Standard: ipHost" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:906 @@ -20832,7 +21530,12 @@ msgstr "ldap_service_object_class (sträng)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:994 msgid "The object class of a service entry in LDAP." -msgstr "Objektklassen hos en servicepost i LDAP." +msgstr "Objektklassen hos en tjänstepost i LDAP." + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:997 +msgid "Default: ipService" +msgstr "Standard: ipService" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1003 @@ -20845,7 +21548,7 @@ msgid "" "The LDAP attribute that contains the name of service attributes and their " "aliases." msgstr "" -"LDAP-attributet som innehåller namnet på tjänsteattribut och deras alias." +"LDAP-attributet som innehåller namnet på tjänsteattributen och deras alias." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1016 @@ -20871,7 +21574,7 @@ msgstr "ldap_service_proto (sträng)" #: sssd-ldap-attributes.5.xml:1032 msgid "" "The LDAP attribute that contains the protocols understood by this service." -msgstr "LDAP-attributet som innehåller protokollen som denna tjänst förstår." +msgstr "LDAP-attributet som innehåller de protokoll som tjänsten stöder." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1036 @@ -20934,8 +21637,8 @@ msgid "" "The LDAP attribute that corresponds to the host name (or host IP address, " "host IP network, or host netgroup)" msgstr "" -"LDAP-attributet som motsvarar värdnamnet (eller värdens IP-adress, värdens " -"IP-nätverk eller värdens nätgrupp)" +"LDAP-attributet som motsvarar värdnamnet, eller värdens IP-adress, IP-" +"nätverk eller nätgrupp" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1095 @@ -20953,8 +21656,8 @@ msgid "" "The LDAP attribute that corresponds to the user name (or UID, group name or " "user's netgroup)" msgstr "" -"LDAP-attributet som motsvarar användarnamnet (eller AID, gruppnamnet eller " -"användarens nätgrupp)" +"LDAP-attributet som motsvarar användarnamnet, eller UID, gruppnamnet eller " +"användarens nätgrupp" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1108 @@ -20987,7 +21690,7 @@ msgid "" "The LDAP attribute that corresponds to the user name that commands may be " "run as." msgstr "" -"LDAP-attributet som motsvarar användarnamnet som kommandon får köras som." +"LDAP-attributet som motsvarar det användarnamn som kommandon kan köras som." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1134 @@ -21005,8 +21708,8 @@ msgid "" "The LDAP attribute that corresponds to the group name or group GID that " "commands may be run as." msgstr "" -"LDAP-attributet som motsvarar gruppnamnet eller grupp-GID:t som kommandon " -"får köras som." +"LDAP-attributet som motsvarar det gruppnamn eller den grupp-GID som " +"kommandon kan köras som." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1147 @@ -21024,7 +21727,8 @@ msgid "" "The LDAP attribute that corresponds to the start date/time for when the sudo " "rule is valid." msgstr "" -"LDAP-attributet som motsvarar startdagen/-tiden då sudo-regeln är giltig." +"LDAP-attributet som motsvarar startdatum och -tidpunkt då sudo-regeln är " +"giltig." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1160 @@ -21042,8 +21746,8 @@ msgid "" "The LDAP attribute that corresponds to the expiration date/time, after which " "the sudo rule will no longer be valid." msgstr "" -"LDAP-attributet som motsvarar utgångsdagen/-tiden då sudo-regeln inte längre " -"är giltig." +"LDAP-attributet som motsvarar utgångsdatum och -tidpunkt, varefter sudo-" +"regeln inte längre är giltig." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1174 @@ -21085,11 +21789,6 @@ msgstr "ldap_iphost_object_class (sträng)" msgid "The object class of an iphost entry in LDAP." msgstr "Objektklassen för en iphost-post i LDAP." -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap-attributes.5.xml:1213 -msgid "Default: ipHost" -msgstr "Standard: ipHost" - #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1219 msgid "ldap_iphost_name (string)" @@ -21195,7 +21894,7 @@ msgstr "ldap_subuid_count (sträng)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1312 msgid "Subordinate user ID count (range size)" -msgstr "Antal underordnade användar-ID (intervallstorlek)" +msgstr "Antal underordnade användar-ID:n (intervallstorlek)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1315 @@ -21210,7 +21909,7 @@ msgstr "ldap_subgid_count (sträng)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1324 msgid "Subordinate group ID count (range size)" -msgstr "Antal underordnade grupp-ID (intervallstorlek)" +msgstr "Antal underordnade grupp-ID:n (intervallstorlek)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1327 @@ -21270,7 +21969,7 @@ msgstr "sssd_krb5_localauth_plugin" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sssd_krb5_localauth_plugin.8.xml:16 msgid "Kerberos local authorization plugin" -msgstr "Kerberos lokala auktoriseringsinsticksmodul" +msgstr "Insticksmodul för lokal Kerberos-auktorisering" #. type: Content of: <reference><refentry><refsect1><para> #: sssd_krb5_localauth_plugin.8.xml:22 @@ -21280,11 +21979,10 @@ msgid "" "Kerberos principal or to check if a given local name and a given Kerberos " "principal relate to each other." msgstr "" -"Kerberos lokala auktoriseringsinsticksmodul <command>" +"Insticksmodulen för lokal Kerberos-auktorisering <command>" "sssd_krb5_localauth_plugin</command> används av libkrb5 för att antingen " -"hitta det lokala namnet för en given Kerberoshuvudman eller för att " -"kontrollera om ett givet lokalt namn och en given Kerberoshuvudman relaterar " -"till varandra." +"hitta det lokala namnet för en viss Kerberos-huvudman eller kontrollera om " +"ett visst lokalt namn och en viss Kerberos-huvudman hör ihop." #. type: Content of: <reference><refentry><refsect1><para> #: sssd_krb5_localauth_plugin.8.xml:29 @@ -21294,10 +21992,10 @@ msgid "" "information SSSD can easily handle the mappings mentioned above even if the " "local name and the Kerberos principal differ considerably." msgstr "" -"SSSD hanterar de lokala namnen för användare från fjärrkällor och kan även " -"läsa från Kerberos användarhuvudmannanamn från fjärrkällor. Med denna " -"information kan SSSD enkelt hantera avbildningarna nämnda ovan även om det " -"lokala namnet och Kerberoshuvudmannen skiljer avsevärt." +"SSSD hanterar lokala namn för användare från en fjärrkälla och kan även läsa " +"Kerberos User Principal Name från fjärrkällan. Med denna information kan " +"SSSD enkelt hantera de ovan nämnda mappningarna, även om det lokala namnet " +"och Kerberos-huvudmannen skiljer sig avsevärt." #. type: Content of: <reference><refentry><refsect1><para> #: sssd_krb5_localauth_plugin.8.xml:36 @@ -21309,12 +22007,11 @@ msgid "" "principal to get the local name which would lead to wrong mappings in this " "case." msgstr "" -"Dessutom kan SSSD med informationen som lästs från fjärrkällor hjälpa till " -"att förhindra oväntade eller oönskade avbildningar ifall användardelen av " -"Kerberoshuvudmannen oavsiktligt motsvarar ett lokalt namn på en annan " -"användare. Som standard kan libkrb5 bara plocka bort delen rike från " -"Kerberoshuvudmannen för att få det lokala namnet vilket skulle leda till " -"felaktiga avbildningar i detta fall." +"Med informationen från fjärrkällan kan SSSD dessutom förhindra oväntade " +"eller oönskade mappningar om användardelen av Kerberos-huvudmannen av " +"misstag motsvarar en annan användares lokala namn. Som standard kan libkrb5 " +"helt enkelt ta bort realmdelen av Kerberos-huvudmannen för att få det lokala " +"namnet, vilket i detta fall skulle leda till felaktiga mappningar." #. type: Content of: <reference><refentry><refsect1><title> #: sssd_krb5_localauth_plugin.8.xml:46 @@ -21323,10 +22020,16 @@ msgstr "KONFIGURATION" #. type: Content of: <reference><refentry><refsect1><para><programlisting> #: sssd_krb5_localauth_plugin.8.xml:56 -#, no-wrap +#, fuzzy, no-wrap +#| msgid "" +#| "[plugins]\n" +#| " localauth = {\n" +#| " module = sssd:/usr/lib64/sssd/modules/sssd_krb5_localauth_plugin.so\n" +#| " }\n" msgid "" "[plugins]\n" " localauth = {\n" +" disable = an2ln\n" " module = sssd:/usr/lib64/sssd/modules/sssd_krb5_localauth_plugin.so\n" " }\n" msgstr "" @@ -21346,13 +22049,35 @@ msgid "" "Kerberos configuration snippet directory. If this directory is included in " "the local Kerberos configuration the plugin will be enabled automatically." msgstr "" -"Kerberos lokala auktoriseringsinsticksmodul måste aktiveras explicit i " -"Kerberoskonfigurationen, se <citerefentry> <refentrytitle>krb5.conf</" -"refentrytitle> <manvolnum>5</manvolnum> </citerefentry>. SSSD kommer " -"automatiskt skapa en konfigurationssnutt med innehållet som t.ex. " -"<placeholder type=\"programlisting\" id=\"0\"/> i SSSD:s publika katalog med " -"Kerberoskonfigurationssnuttar. Om denna katalog är inkluderad i den lokala " -"Kerberoskonfigurationen kommer insticksmodulen automatiskt aktiveras." +"Insticksmodulen för lokal Kerberos-auktorisering måste aktiveras " +"uttryckligen i Kerberos-konfigurationen, se <citerefentry> <refentrytitle>" +"krb5.conf</refentrytitle> <manvolnum>5</manvolnum> </citerefentry>. SSSD " +"skapar automatiskt ett konfigurationsutdrag med exempelvis följande innehåll " +"i sin publika katalog för Kerberos-konfigurationsutdrag: <placeholder " +"type=\"programlisting\" id=\"0\"/> Om katalogen ingår i den lokala Kerberos-" +"konfigurationen aktiveras insticksmodulen automatiskt." + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_localauth_plugin.8.xml:67 +msgid "" +"This configuration snippet also disables the <command>an2ln</command> module " +"provided by MIT Kerberos if SSSD is configured to use the AD or IPA " +"provider. In those environments <command>sssd_krb5_localauth_plugin</" +"command> can reliably map the system user names to Kerberos principals. A " +"fallback to <command>an2ln</command> might cause issues in environments " +"where users have the privilege to create Kerberos principals on their own " +"which might collide with names of other users used in the system. Other " +"modules provided by MIT Kerberos, e.g. <command>k5login</command> are not " +"affected." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_localauth_plugin.8.xml:79 +msgid "" +"Note: If using <quote>auth_provider = krb5</quote> then " +"<command>sssd_krb5_localauth_plugin</command> is not used, therefore the " +"above text is not applicable." +msgstr "" #. type: Content of: <variablelist><varlistentry><term> #: include/autofs_attributes.xml:3 @@ -21362,7 +22087,7 @@ msgstr "ldap_autofs_map_object_class (sträng)" #. type: Content of: <variablelist><varlistentry><listitem><para> #: include/autofs_attributes.xml:6 msgid "The object class of an automount map entry in LDAP." -msgstr "Objektklassen hos en automatmonteringskartepost i LDAP." +msgstr "Objektklassen hos en automonteringskartpost i LDAP." #. type: Content of: <variablelist><varlistentry><listitem><para> #: include/autofs_attributes.xml:9 @@ -21377,7 +22102,7 @@ msgstr "ldap_autofs_map_name (sträng)" #. type: Content of: <variablelist><varlistentry><listitem><para> #: include/autofs_attributes.xml:19 msgid "The name of an automount map entry in LDAP." -msgstr "Namnet på en automatmonteringskartepost i LDAP." +msgstr "Namnet på en automonteringskartpost i LDAP." #. type: Content of: <variablelist><varlistentry><listitem><para> #: include/autofs_attributes.xml:22 @@ -21441,7 +22166,7 @@ msgstr "" #. type: Content of: <refsect1><title> #: include/service_discovery.xml:2 msgid "SERVICE DISCOVERY" -msgstr "TJÄNSTEUPPTÄCKT" +msgstr "TJÄNSTUPPTÄCKT" #. type: Content of: <refsect1><para> #: include/service_discovery.xml:4 @@ -21450,9 +22175,9 @@ msgid "" "appropriate servers to connect to using a special DNS query. This feature is " "not supported for backup servers." msgstr "" -"Tjänsteupptäcktsfunktionen gör att bakändar automatiskt kan hitta en lämplig " -"server att ansluta till med en speciell DNS-fråga. Denna funktion stödjs " -"inte för backup-servrar." +"Funktionen för tjänstupptäckt låter bakomliggande komponenter automatiskt " +"hitta lämpliga servrar att ansluta till med en särskild DNS-fråga. " +"Funktionen stöds inte för reservservrar." #. type: Content of: <refsect1><refsect2><title> #: include/service_discovery.xml:9 include/ldap_id_mapping.xml:99 @@ -21470,13 +22195,13 @@ msgid "" "prefers to use service discovery whenever possible, and fall back to a " "specific server when no servers can be discovered using DNS." msgstr "" -"Om inga servrar anges använder bakänden automatiskt tjänsteupptäckt för att " -"försöka hitta en server. Användaren kan om så önskas välja att använda både " -"en bestämd serveradress och tjänsteupptäckt genom att infoga ett speciellt " -"nyckelord, <quote>_srv_</quote>, i listan av servrar. Preferensordningen " -"bibehålls. Denna funktion är användbar om, till exempel, användaren " -"föredrar att använda tjänsteupptäckt närhelst det är möjligt, och falla " -"tillbaka på en specifik server när inga servrar kan upptäckas med DNS." +"Om inga servrar anges använder den bakomliggande komponenten automatiskt " +"tjänstupptäckt för att försöka hitta en server. Användaren kan välja att " +"använda både fasta serveradresser och tjänstupptäckt genom att infoga det " +"särskilda nyckelordet <quote>_srv_</quote> i serverlistan. " +"Preferensordningen behålls. Funktionen är användbar om användaren till " +"exempel föredrar tjänstupptäckt när det är möjligt och vill falla tillbaka " +"till en specifik server när inga servrar kan upptäckas med DNS." #. type: Content of: <refsect1><refsect2><title> #: include/service_discovery.xml:23 @@ -21525,8 +22250,8 @@ msgid "" "<productname>SSSD</productname> <orgname>The SSSD upstream - https://" "github.com/SSSD/sssd/</orgname>" msgstr "" -"<productname>SSSD</productname> <orgname>SSSD uppströms – https://github.com/" -"SSSD/sssd/</orgname>" +"<productname>SSSD</productname> <orgname>SSSD:s uppströmsprojekt – https://" +"github.com/SSSD/sssd/</orgname>" #. type: Content of: outside any tag (error?) #: include/upstream.xml:1 @@ -21536,7 +22261,7 @@ msgstr "<placeholder type=\"refentryinfo\" id=\"0\"/>" #. type: Content of: <refsect1><title> #: include/failover.xml:2 msgid "FAILOVER" -msgstr "RESERVER" +msgstr "REDUNDANS" #. type: Content of: <refsect1><para> #: include/failover.xml:4 @@ -21544,13 +22269,13 @@ msgid "" "The failover feature allows back ends to automatically switch to a different " "server if the current server fails." msgstr "" -"Reservfunktionen gör att bakändar automatiskt kan byta till en annan server " -"om den nuvarande servern slutar fungera." +"Redundansfunktionen låter bakomliggande komponenter automatiskt byta till en " +"annan server om den aktuella servern slutar fungera." #. type: Content of: <refsect1><refsect2><title> #: include/failover.xml:8 msgid "Failover Syntax" -msgstr "Reservsyntax" +msgstr "REDUNDANSSYNTAX" #. type: Content of: <refsect1><refsect2><para> #: include/failover.xml:10 @@ -21574,18 +22299,17 @@ msgid "" "periodically try to reconnect to one of the primary servers. If it succeeds, " "it will replace the current active (backup) server." msgstr "" -"För varje reservaktiverat konfigurationsalternativ finns det två varianter: " -"<emphasis>primary</emphasis> och <emphasis>backup</emphasis>. Tanken är att " -"servrar i den primära listan föredras och backup-servrar bara provas om inga " -"primära servrar kan nås. Om en backup-server väljs sätts en tidsgräns på 31 " -"sekunder. Efter denna tidsgräns kommer SSSD periodiskt att försöka " -"återansluta till en av de primära servrarna. Om det lyckas kommer den " -"ersätta den nu aktiva (backup-)servern." +"För varje redundansaktiverat konfigurationsalternativ finns två varianter: " +"<emphasis>primary</emphasis> och <emphasis>backup</emphasis>. Servrarna i " +"den primära listan föredras och reservservrar används endast om inga primära " +"servrar kan nås. Om en reservserver väljs anges en tidsgräns på 31 sekunder. " +"Efter tidsgränsen försöker SSSD regelbundet återansluta till en av de " +"primära servrarna. Om det lyckas ersätter den den aktiva reservservern." #. type: Content of: <refsect1><refsect2><title> #: include/failover.xml:27 msgid "The Failover Mechanism" -msgstr "Reservmekanismen" +msgstr "REDUNDANSMEKANISMEN" #. type: Content of: <refsect1><refsect2><para> #: include/failover.xml:29 @@ -21600,15 +22324,15 @@ msgid "" "switches over to the next service. The machine is still considered online " "and might still be tried for another service." msgstr "" -"Reservmekanismen gör skillnad mellan en maskin och en tjänst. Bakänden " -"försöker först att slå upp värdnamnet för en given maskin; om denna " -"uppslagning misslyckas antas maskinen vara bortkopplad. Inga ytterligare " -"försök görs att ansluta till denna maskin för någon annan tjänst. Om " -"uppslagningsförsöket lyckas försöker bakänden ansluta till en tjänst på " -"denna maskin. Om tjänsteanslutningen misslyckas anses bara just denna " -"tjänst frånkopplad och bakänden byter automatiskt till nästa tjänst. " -"Maskinen betraktas fortfarande som uppkopplad och kan användas vid försök " -"att nå en annan tjänst." +"Redundansmekanismen skiljer mellan en maskin och en tjänst. Den " +"bakomliggande komponenten försöker först slå upp värdnamnet för en viss " +"maskin; om uppslaget misslyckas betraktas maskinen som frånkopplad och inga " +"fler anslutningsförsök görs till den för andra tjänster. Om uppslaget lyckas " +"försöker den bakomliggande komponenten ansluta till en tjänst på maskinen. " +"Om anslutningsförsöket misslyckas betraktas endast den aktuella tjänsten som " +"frånkopplad och komponenten växlar automatiskt till nästa tjänst. Maskinen " +"betraktas fortfarande som ansluten och kan fortfarande provas för en annan " +"tjänst." #. type: Content of: <refsect1><refsect2><para> #: include/failover.xml:42 @@ -21617,8 +22341,8 @@ msgid "" "offline after a specified period of time; this is currently hard coded to 30 " "seconds." msgstr "" -"Ytterligare försök att ansluta görs till maskiner eller tjänster som " -"markerats som frånkopplade efter en viss tidsperiod, detta är för närvarande " +"Ytterligare anslutningsförsök görs till maskiner eller tjänster som har " +"markerats som frånkopplade efter en angiven tid; detta är för närvarande " "hårdkodat till 30 sekunder." #. type: Content of: <refsect1><refsect2><para> @@ -21627,13 +22351,14 @@ msgid "" "If there are no more machines to try, the back end as a whole switches to " "offline mode, and then attempts to reconnect every 30 seconds." msgstr "" -"Om det inte finns några fler maskiner att prova byter bakänden i sin helhet " -"till frånkopplat läge, och försöker sedan återansluta var 30:e sekund." +"Om det inte finns fler maskiner att prova växlar den bakomliggande " +"komponenten som helhet till frånkopplat läge och försöker sedan återansluta " +"var 30:e sekund." #. type: Content of: <refsect1><refsect2><title> #: include/failover.xml:53 msgid "Failover time outs and tuning" -msgstr "Tidsgränser och trimning av reservfunktioner" +msgstr "REDUNDANSTIDSGRÄNSER OCH INSTÄLLNING" #. type: Content of: <refsect1><refsect2><para> #: include/failover.xml:55 @@ -21648,15 +22373,14 @@ msgid "" "timing out before a live server is contacted, you can consider changing the " "time outs." msgstr "" -"Att slå upp en server att ansluta till kan vara så enkelt som att göra en " -"enstaka DNS-fråga eller kan innebära flera steg, såsom att hitta den rätta " -"sajten eller försöka med flera värdnamn ifall några av de konfigurerade " -"servrarna inte kan nås. De mer komplexa scenariona kan ta en stund och SSSD " -"behöver balansera mellan att tillhandahålla tillräckligt med tid för att " -"färdigställa upplösningsprocessen men å andra sidan inte försöka för länge " -"före den faller tillbaka på frånkopplat läge. Om SSSD:s felsökningsloggar " -"visar att serverns upplösning överskrider tidsgränsen före en aktiv server " -"nås kan du överväga att ändra tidsgränserna." +"Att slå upp en server att ansluta till kan vara så enkelt som en enda DNS-" +"fråga, men kan också omfatta flera steg, till exempel att hitta rätt plats " +"eller prova flera värdnamn om vissa konfigurerade servrar inte kan nås. De " +"mer komplexa scenarierna kan ta tid, och SSSD måste balansera mellan att ge " +"tillräckligt med tid för att slutföra uppslaget och att inte försöka för " +"länge innan frånkopplat läge används. Om SSSD:s felsökningsloggar visar att " +"serveruppslaget når tidsgränsen innan en aktiv server kontaktas kan du " +"överväga att ändra tidsgränserna." #. type: Content of: <refsect1><refsect2><para><variablelist><varlistentry><term> #: include/failover.xml:76 @@ -21669,8 +22393,8 @@ msgid "" "Time in milliseconds that sets how long would SSSD talk to a single DNS " "server before trying next one." msgstr "" -"Tid i millisekunder som anger hur länge SSSD skall tala med en viss DNS-" -"server före den provar nästa." +"Tid i millisekunder som anger hur länge SSSD försöker kommunicera med en DNS-" +"server innan nästa provas." #. type: Content of: <refsect1><refsect2><para><variablelist><varlistentry><term> #: include/failover.xml:90 @@ -21684,9 +22408,9 @@ msgid "" "(e.g. resolution of a hostname or an SRV record) before trying the next " "hostname or discovery domain." msgstr "" -"Tid i sekunder hur länge SSSD skall försöka slå upp en viss DNS-fråga (t.ex. " -"uppslagning av ett värdnamn eller en SRV-post) före den provar nästa " -"värdnamn eller upptäcktsdomän." +"Tid i sekunder som anger hur länge SSSD försöker slå upp en enskild DNS-" +"fråga, till exempel ett värdnamn eller en SRV-post, innan nästa värdnamn " +"eller upptäcktsdomän provas." #. type: Content of: <refsect1><refsect2><para><variablelist><varlistentry><term> #: include/failover.xml:106 @@ -21700,9 +22424,9 @@ msgid "" "resolution internally might include several steps, such as resolving DNS SRV " "queries or locating the site." msgstr "" -"Hur länge skall SSSD försöka slå upp en reservtjänst. Denna " -"tjänsteuppslagning kan internt bestå av flera steg, såsom att slå upp DNS " -"SRV-frågor och lokalisera sajten." +"Hur länge SSSD försöker slå upp en redundanstjänst. Tjänsteuppslaget kan " +"internt omfatta flera steg, till exempel att slå upp DNS SRV-frågor eller " +"hitta platsen." #. type: Content of: <refsect1><refsect2><para> #: include/failover.xml:67 @@ -21712,9 +22436,9 @@ msgid "" "manvolnum> </citerefentry>, manual page. <placeholder type=\"variablelist\" " "id=\"0\"/>" msgstr "" -"Detta avsnitt listar tillgängliga trimningsvariabler. Se deras beskrivning " -"i manualsidan <citerefentry> <refentrytitle>sssd.conf</refentrytitle>" -"<manvolnum>5</manvolnum> </citerefentry>. <placeholder " +"Detta avsnitt listar de tillgängliga inställningsbara parametrarna. Deras " +"beskrivningar finns i manualsidan <citerefentry> <refentrytitle>sssd.conf</" +"refentrytitle><manvolnum>5</manvolnum> </citerefentry>. <placeholder " "type=\"variablelist\" id=\"0\"/>" #. type: Content of: <refsect1><refsect2><para> @@ -21776,15 +22500,15 @@ msgid "" "<refentrytitle>sss_cache</refentrytitle> <manvolnum>8</manvolnum> </" "citerefentry> to remove the database, rather the process consists of:" msgstr "" -"Observera att byte av ID-mappnings relaterade konfigurationsalternativ " -"kommer få användar- och grupp-ID:n att ändras. För närvarande stödjer inte " -"SSSD byte av ID:n, så SSSD-databasen måste tas bort. Eftersom cachade " -"lösenord också lagras i databasen skall databasen bara tas bort när " -"autentiseringsservrarna kan nås, annars kan användare låsas ute. För att " -"cacha lösenordet måste en autentisering göras. Det är inte tillräckligt att " -"använda <citerefentry> <refentrytitle>sss_cache</refentrytitle> <manvolnum>" -"8</manvolnum> </citerefentry> för att ta bort databasen, istället består " -"processen av:" +"Observera att ändringar i de konfigurationsalternativ som rör ID-mappning " +"gör att användar- och grupp-ID:n ändras. SSSD har för närvarande inte stöd " +"för att ändra ID:n, så SSSD-databasen måste tas bort. Eftersom cachade " +"lösenord också lagras i databasen bör den endast tas bort när " +"autentiseringsservrarna kan nås, annars kan användare låsas ute. En " +"autentisering måste genomföras för att lösenordet ska cachas. Det räcker " +"inte att använda <citerefentry> <refentrytitle>sss_cache</refentrytitle> " +"<manvolnum>8</manvolnum> </citerefentry> för att ta bort databasen. " +"Processen består i stället av:" #. type: Content of: <refsect1><para><itemizedlist><listitem><para> #: include/ldap_id_mapping.xml:33 @@ -21813,14 +22537,14 @@ msgid "" "system properties such as file and directory ownership, it's advisable to " "plan ahead and test the ID mapping configuration thoroughly." msgstr "" -"Dessutom, eftersom ändringen av ID:n kan göra det nödvändigt att justera " -"andra systemegenskaper såsom ägare av filer och kataloger, är det lämpligt " -"att planera i förväg och testa konfigurationen av ID-översättningar noggrant." +"Eftersom ändringen av ID:n kan kräva justering av andra systemegenskaper, " +"såsom ägarskap för filer och kataloger, är det lämpligt att planera i förväg " +"och testa ID-mappningskonfigurationen noggrant." #. type: Content of: <refsect1><refsect2><title> #: include/ldap_id_mapping.xml:59 msgid "Mapping Algorithm" -msgstr "Översättningsalgoritm" +msgstr "MAPPNINGSALGORITM" #. type: Content of: <refsect1><refsect2><para> #: include/ldap_id_mapping.xml:61 @@ -21842,8 +22566,8 @@ msgid "" "into equally-sized component sections - called \"slices\". Each slice " "represents the space available to an Active Directory domain." msgstr "" -"SSSD ID-mappningsalgoritmen tar ett intervall av tillgängliga UID:er och " -"delar upp det i lika stora komponenter, så kallade \"slices\". Varje slice " +"SSSD:s ID-mappningsalgoritm tar ett intervall av tillgängliga UID:er och " +"delar det i lika stora delar, kallade \"segment\". Varje segment " "representerar det utrymme som är tillgängligt för en Active Directory-domän." #. type: Content of: <refsect1><refsect2><para> @@ -21855,9 +22579,9 @@ msgid "" "machines, we select the slice based on the following algorithm:" msgstr "" "När en användar- eller gruppost för en viss domän påträffas för första " -"gången allokerar SSSD en av de tillgängliga skivorna för den domänen. För " -"att göra denna skivtilldelning upprepbar på olika klientmaskiner väljer vi " -"skivan baserat på följande algoritm:" +"gången tilldelar SSSD ett av de tillgängliga segmenten till den domänen. För " +"att tilldelningen ska kunna upprepas på olika klientmaskiner väljs segmentet " +"enligt följande algoritm:" #. type: Content of: <refsect1><refsect2><para> #: include/ldap_id_mapping.xml:80 @@ -21866,9 +22590,9 @@ msgid "" "a 32-bit hashed value. We then take the modulus of this value with the total " "number of available slices to pick the slice." msgstr "" -"SID-strängen skickas genom algoritmen murmurhash3 för att konvertera den " -"till ett 32-bitars hash-värde. Vi tar sedan modulo på detta värde med det " -"totala antalet tillgängliga skivor och väljer den skivan." +"SID-strängen skickas genom algoritmen murmurhash3 för att omvandla den till " +"ett 32-bitars hashvärde. Därefter beräknas värdet modulo det totala antalet " +"tillgängliga segment för att välja segmentet." #. type: Content of: <refsect1><refsect2><para> #: include/ldap_id_mapping.xml:86 @@ -21882,21 +22606,20 @@ msgid "" "configure a default domain to guarantee that at least one is always " "consistent. See <quote>Configuration</quote> for details." msgstr "" -"OBSERVERA: Det är möjligt att träffa på kollisioner i hash:en och den " -"påföljande moduloberäkningen. I dessa situationer kommer vi välja nästa " -"tillgängliga skiva, men det är kanske inte möjligt att reproducera exakt " -"samma uppsättning av skivor på andra maskiner (eftersom ordningen som de " -"påträffas kommer avgöra deras skiva). I den här situationen rekommenderas " -"det att antingen byta till att använda explicita POSIX-attribut i Active " -"Directory (avaktivera ID-mappningen) eller konfigurera en standarddomän för " -"att garantera att åtminstone en alltid är konsistent. Se <quote>" -"Konfiguration</quote> för detaljer." +"OBSERVERA: Kollisioner kan uppstå i hashen och den efterföljande " +"moduloberäkningen. I dessa fall väljs nästa tillgängliga segment, men samma " +"exakta uppsättning segment kan kanske inte återskapas på andra maskiner, " +"eftersom ordningen i vilken de påträffas avgör deras segment. I den " +"situationen rekommenderas antingen att byta till explicita POSIX-attribut i " +"Active Directory, vilket inaktiverar ID-mappning, eller att konfigurera en " +"standarddomän för att garantera att minst en alltid är konsekvent. Se <quote>" +"Configuration</quote> för detaljer." #. type: Content of: <refsect1><refsect2><para> #: include/ldap_id_mapping.xml:101 msgid "" "Minimum configuration (in the <quote>[domain/DOMAINNAME]</quote> section):" -msgstr "Minimikonfiguration (i avsnittet <quote>[domain/DOMÄNNAMN]</quote>):" +msgstr "Minimikonfiguration (i avsnittet <quote>[domain/DOMAINNAME]</quote>):" #. type: Content of: <refsect1><refsect2><para><programlisting> #: include/ldap_id_mapping.xml:106 @@ -21937,9 +22660,9 @@ msgid "" "mapping Active Directory user and group SIDs. It is the first POSIX ID which " "can be used for the mapping." msgstr "" -"Anger den lägre (inklusiva) gränsen för intervallet av POSIX ID:n att " -"använda för översättning av användar- och grupp-SID:n från Active Directory. " -"Det är det första POSIX-ID:t som kan användas för översättning." +"Anger den undre, inklusive, gränsen för intervallet av POSIX-ID:n som " +"används för att mappa användar- och grupp-SID:er i Active Directory. Det är " +"det första POSIX-ID som kan användas för mappningen." #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> #: include/ldap_id_mapping.xml:129 @@ -21950,12 +22673,11 @@ msgid "" "distinction, but the good general advice would be to have <quote>min_id</" "quote> be less-than or equal to <quote>ldap_idmap_range_min</quote>" msgstr "" -"OBSERVERA: Detta alternativ är inte detsamma som <quote>min_id</quote> " -"eftersom <quote>min_id</quote> fungerar som ett filter av utmatade " -"begäranden till denna domän, medan detta alternativ styr intervallet av ID-" -"tilldelningen. Detta är en subtil distinktion, men det allmänna goda rådet " -"skulle vara att ha <quote>min_id</quote> mindre än eller lika med <quote>" -"ldap_idmap_range_min</quote>" +"OBSERVERA: Detta alternativ skiljer sig från <quote>min_id</quote> genom att " +"<quote>min_id</quote> filtrerar resultatet av begäranden till domänen, medan " +"detta alternativ styr intervallet för ID-tilldelning. Skillnaden är liten, " +"men det generella rådet är att <quote>min_id</quote> ska vara mindre än " +"eller lika med <quote>ldap_idmap_range_min</quote>" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><term> #: include/ldap_id_mapping.xml:144 @@ -21970,10 +22692,10 @@ msgid "" "cannot be used for the mapping anymore, i.e. one larger than the last one " "which can be used for the mapping." msgstr "" -"Anger den övre (exklusiva) gränsen för intervallet av POSIX ID:n att använda " -"för översättning av användar- och grupp-SID:n från Active Directory. Det är " -"det första POSIX-ID:t som inte kan användas för översättning längre, d.v.s. " -"ett mer än det sista som kan användas för översättningen." +"Anger den övre, exklusive, gränsen för intervallet av POSIX-ID:n som används " +"för att mappa användar- och grupp-SID:er i Active Directory. Det är det " +"första POSIX-ID som inte längre kan användas för mappningen, det vill säga " +"ett större än det sista som kan användas." #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> #: include/ldap_id_mapping.xml:155 @@ -21984,12 +22706,11 @@ msgid "" "distinction, but the good general advice would be to have <quote>max_id</" "quote> be greater-than or equal to <quote>ldap_idmap_range_max</quote>" msgstr "" -"OBSERVERA: Detta alternativ är inte detsamma som <quote>max_id</quote> " -"eftersom <quote>max_id</quote> fungerar som ett filter av utmatade " -"begäranden till denna domän, medan detta alternativ styr intervallet av ID-" -"tilldelningen. Detta är en subtil distinktion, men det allmänna goda rådet " -"skulle vara att ha <quote>max_id</quote> större än eller lika med <quote>" -"ldap_idmap_range_max</quote>" +"OBSERVERA: Detta alternativ skiljer sig från <quote>max_id</quote> genom att " +"<quote>max_id</quote> filtrerar resultatet av begäranden till domänen, medan " +"detta alternativ styr intervallet för ID-tilldelning. Skillnaden är liten, " +"men det generella rådet är att <quote>max_id</quote> ska vara större än " +"eller lika med <quote>ldap_idmap_range_max</quote>" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><term> #: include/ldap_id_mapping.xml:170 @@ -22003,9 +22724,9 @@ msgid "" "does not divide evenly into the min and max values, it will create as many " "complete slices as it can." msgstr "" -"Anger antalet ID:n som är tillgängliga för varje skiva. Om storleken på " -"intervallet inte delas jämnt mellan min- och maxvärdena kommer den skapa så " -"många fullständiga skivor den kan." +"Anger antalet ID:n som är tillgängliga för varje segment. Om " +"intervallstorleken inte går jämnt upp i minimi- och maximivärdena skapas så " +"många fullständiga segment som möjligt." #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> #: include/ldap_id_mapping.xml:179 @@ -22014,10 +22735,10 @@ msgid "" "RID planned for use on the Active Directory server. User lookups and login " "will fail for any user whose RID is greater than this value." msgstr "" -"OBSERVERA: Värdet på detta alternativ måste vara åtminstone så stort som den " -"högsta RID som planeras användas i Active Directory-servern. " -"Användaruppslagningar och inloggningar kommer misslyckas för eventuella " -"användare vars RID är större än detta värde." +"OBSERVERA: Värdet för detta alternativ måste vara minst lika stort som den " +"högsta användar-RID som planeras användas på Active Directory-servern. " +"Användaruppslagningar och inloggningar misslyckas för användare vars RID är " +"större än värdet." #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> #: include/ldap_id_mapping.xml:185 @@ -22040,10 +22761,9 @@ msgid "" "will result in changing all of the ID mappings on the system, leading to " "users with different local IDs than they previously had." msgstr "" -"Det är viktigt att planera i förväg för framtida expansioner, eftersom " -"ändring av detta värde skulle resultera i att ändra alla ID-översättningar " -"på systemet, vilket skulle leda till användare med andra lokala ID:n än de " -"tidigare hade." +"Det är viktigt att planera för framtida utökning, eftersom en ändring av " +"värdet ändrar alla ID-mappningar i systemet och gör att användare får andra " +"lokala ID:n än tidigare." #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><term> #: include/ldap_id_mapping.xml:202 @@ -22057,9 +22777,9 @@ msgid "" "domain will always be assigned to slice zero in the ID map, bypassing the " "murmurhash algorithm described above." msgstr "" -"Ange domän-SID:n för standarddomänen. Detta kommer garantera att denna " -"domän alltid kommer tilldelas till skiva noll i ID-översättningen, och " -"undviker murmurhash-algoritmen som beskrivs ovan." +"Ange domän-SID för standarddomänen. Det garanterar att domänen alltid " +"tilldelas segment noll i ID-mappningen och kringgår murmurhash-algoritmen " +"som beskrivs ovan." #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><term> #: include/ldap_id_mapping.xml:216 @@ -22074,7 +22794,7 @@ msgstr "Ange namnet på standarddomänen." #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><term> #: include/ldap_id_mapping.xml:227 msgid "ldap_idmap_autorid_compat (boolean)" -msgstr "ldap_idmap_autorid_compat (boolean)" +msgstr "ldap_idmap_autorid_compat (boolesk)" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> #: include/ldap_id_mapping.xml:230 @@ -22082,8 +22802,8 @@ msgid "" "Changes the behavior of the ID-mapping algorithm to behave more similarly to " "winbind's <quote>idmap_autorid</quote> algorithm." msgstr "" -"Ändrar beteendet på ID-översättningsalgoritmen till att bete sig mer likt " -"winbind:s <quote>idmap_autorid</quote>-algoritm." +"Ändrar ID-mappningsalgoritmens beteende så att det mer liknar winbinds " +"algoritm <quote>idmap_autorid</quote>." #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> #: include/ldap_id_mapping.xml:235 @@ -22091,8 +22811,8 @@ msgid "" "When this option is configured, domains will be allocated starting with " "slice zero and increasing monotonically with each additional domain." msgstr "" -"När detta alternativ konfigureras kommer domäner allokeras med början med " -"skiva noll och ökar monotont med varje ytterligare domän." +"När alternativet konfigureras tilldelas domäner från segment noll och ökar " +"monotont för varje ytterligare domän." #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> #: include/ldap_id_mapping.xml:240 @@ -22103,11 +22823,11 @@ msgid "" "<quote>ldap_idmap_default_domain_sid</quote> option to guarantee that at " "least one domain is consistently allocated to slice zero." msgstr "" -"OBSERVERA: Denna algoritm är inte deterministisk (den beror på ordningen som " -"användare och grupper efterfrågas). Om detta läge krävs för kompatibilitet " -"med maskiner som kör winbind rekommenderas det att även använda alternativet " -"<quote>ldap_idmap_default_domain_sid</quote> för att garantera att " -"åtminstone en domän är konsekvent allokerat till skiva noll." +"OBSERVERA: Algoritmen är icke-deterministisk, eftersom den beror på i vilken " +"ordning användare och grupper efterfrågas. Om läget krävs för kompatibilitet " +"med maskiner som kör winbind rekommenderas även alternativet <quote>" +"ldap_idmap_default_domain_sid</quote>, så att minst en domän alltid " +"tilldelas segment noll konsekvent." #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><term> #: include/ldap_id_mapping.xml:255 @@ -22120,8 +22840,8 @@ msgid "" "Maximal number of secondary slices that is tried when performing mapping " "from UNIX id to SID." msgstr "" -"Maximalt antal sekundära skivor som provas när mappningen från UNIX id till " -"SID utförs." +"Maximalt antal sekundära segment som provas vid mappning från UNIX-ID till " +"SID." #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> #: include/ldap_id_mapping.xml:262 @@ -22131,10 +22851,10 @@ msgid "" "generated so far. If value of ldap_idmap_helper_table_size is equal to 0 " "then no additional secondary slices are generated." msgstr "" -"Observera: ytterligare sekundära skivor kan genereras när en SID översätts " -"till UNIX-id och RID-delen av SID:n är utanför intervallet för sekundära " -"skivor som genererats hittills. Om värdet på ldap_idmap_helper_table_size " -"är lika med 0 genereras inga ytterligare sekundära skivor." +"Observera: Ytterligare sekundära segment kan genereras när en SID mappas " +"till UNIX-ID och SID:ens RID-del ligger utanför intervallet för hittills " +"genererade sekundära segment. Om värdet för ldap_idmap_helper_table_size är " +"0 genereras inga ytterligare sekundära segment." #. type: Content of: <refsect1><refsect2><title> #: include/ldap_id_mapping.xml:279 @@ -22149,10 +22869,10 @@ msgid "" "those Well-Known SIDs have no equivalent in a Linux/UNIX environment no " "POSIX IDs are available for those objects." msgstr "" -"SSSD stödjer uppslagning av namnen på välkända SID:er, d.v.s. SID:er med en " -"speciell hårdkodad betydelse. Eftersom de allmänna användarna och grupperna " -"relaterade till dessa välkända SID:er inte har någon motsvarighet i en " -"Linux-/UNIX-miljö är inga POSIX-ID:n tillgängliga för dessa objekt." +"SSSD har stöd för att slå upp namnen på välkända SID:er, det vill säga " +"SID:er med en särskild hårdkodad betydelse. Eftersom de generiska användare " +"och grupper som hör till dessa välkända SID:er saknar motsvarighet i en " +"Linux/UNIX-miljö finns inga POSIX-ID:n för objekten." #. type: Content of: <refsect1><refsect2><para> #: include/ldap_id_mapping.xml:287 @@ -22209,8 +22929,8 @@ msgid "" "The capitalized version of these names are used as domain names when " "returning the fully qualified name of a Well-Known SID." msgstr "" -"Den versala versionen av dessa namn används som domännamn när det " -"fullständigt kvalificerade namnet på en välkänd SID returneras." +"Den versala formen av dessa namn används som domännamn när det fullständigt " +"kvalificerade namnet på en välkänd SID returneras." #. type: Content of: <refsect1><refsect2><para> #: include/ldap_id_mapping.xml:303 @@ -22225,16 +22945,16 @@ msgid "" "quote>, <quote>NT AUTHORITY</quote> and <quote>BUILTIN</quote> should not be " "used as domain names in <filename>sssd.conf</filename>." msgstr "" -"Eftersom några verktyg tillåter att man ändrar SID-baserad " -"åtkomststyrningsinformation med hjälp av ett namn istället för att använda " -"SID:en direkt stödjer SSSD uppslagning av SID:en med detta namn också. För " -"att undvika kollisioner kan bara de fullständigt kvalificerade namnen " -"användas för att slå upp välkända SID:er. Som ett resultat skall domännamnen " -"<quote>NULL AUTHORITY</quote>, <quote>WORLD AUTHORITY</quote>, <quote>LOCAL " -"AUTHORITY</quote>, <quote>CREATOR AUTHORITY</quote>, <quote>MANDATORY LABEL " -"AUTHORITY</quote>, <quote>AUTHENTICATION AUTHORITY</quote>, <quote>NT " -"AUTHORITY</quote> och <quote>BUILTIN</quote> inte användas som domännamn i " -"<filename>sssd.conf</filename>." +"Eftersom vissa verktyg låter dig ändra SID-baserad " +"åtkomstkontrollinformation med ett namn i stället för att använda SID:en " +"direkt, har SSSD även stöd för att slå upp SID:en efter namn. För att " +"undvika kollisioner kan endast fullständigt kvalificerade namn användas för " +"att slå upp välkända SID:er. Domännamnen <quote>NULL AUTHORITY</quote>, " +"<quote>WORLD AUTHORITY</quote>, <quote>LOCAL AUTHORITY</quote>, <quote>" +"CREATOR AUTHORITY</quote>, <quote>MANDATORY LABEL AUTHORITY</quote>, <quote>" +"AUTHENTICATION AUTHORITY</quote>, <quote>NT AUTHORITY</quote> och <quote>" +"BUILTIN</quote> bör därför inte användas som domännamn i <filename>" +"sssd.conf</filename>." #. type: Content of: <varlistentry><term> #: include/param_help.xml:3 @@ -22260,12 +22980,11 @@ msgid "" "is to specify a hexadecimal bitmask to enable or disable specific levels " "(such as if you wish to suppress a level)." msgstr "" -"SSSD stödjer två representationer för att ange felsökningsnivå. Det " -"enklaste är att ange ett decimalt värde från 0-9 som representerar " -"aktivering av den nivån och alla lägre nivåer av felsökningsmeddelanden. " -"Det mer fullständiga alternativet är att ange en hexadecimal bitmask för att " -"aktivera eller avaktivera specifika nivåer (såsom om du önskar undertrycka " -"en nivå)." +"SSSD har två sätt att ange felsökningsnivån. Det enklaste är ett " +"decimalvärde från 0 till 9, vilket aktiverar den nivån och alla " +"felsökningsmeddelanden på lägre nivåer. Det mer omfattande alternativet är " +"att ange en hexadecimal bitmask för att aktivera eller inaktivera specifika " +"nivåer, till exempel för att undertrycka en nivå." #. type: Content of: <listitem><para> #: include/debug_levels.xml:10 @@ -22276,12 +22995,11 @@ msgid "" "responder or provider processes. The <quote>debug_level</quote> parameter " "should be added to all sections that you wish to produce debug logs from." msgstr "" -"Observera att varje SSSD-tjänst loggar till sin egen loggfil. Observera " -"också att aktivering av <quote>debug_level</quote> i avsnittet <quote>" -"[sssd]</quote> bara aktiverar felsökning just för själva sssd-processen, " -"inte för respondent- eller leverantörsprocesser. Parametern <quote>" -"debug_level</quote> skall läggas till i alla sektioner som man vill " -"producera felsökningsloggar ifrån." +"Observera att varje SSSD-tjänst loggar till sin egen loggfil. Att aktivera " +"<quote>debug_level</quote> i avsnittet <quote>[sssd]</quote> aktiverar " +"endast felsökning för själva sssd-processen, inte för svars- eller " +"leverantörsprocesserna. Parametern <quote>debug_level</quote> bör läggas " +"till i alla avsnitt som ska producera felsökningsloggar." #. type: Content of: <listitem><para> #: include/debug_levels.xml:18 @@ -22292,11 +23010,10 @@ msgid "" "<citerefentry> <refentrytitle>sss_debuglevel</refentrytitle> <manvolnum>8</" "manvolnum> </citerefentry> tool." msgstr "" -"Utöver att ändra loggnivån i konfigurationsfilen med parametern <quote>" -"debug_level</quote>, som är bestående, men kräver omstart av SSSD, är det " -"även möjligt att ändra felsökningsnivån i farten med verktyget " -"<citerefentry> <refentrytitle>sss_debuglevel</refentrytitle> <manvolnum>8</" -"manvolnum> </citerefentry>." +"Utöver att ändra loggnivån beständigt i konfigurationsfilen med parametern " +"<quote>debug_level</quote>, vilket kräver omstart av SSSD, går det att ändra " +"felsökningsnivån under drift med verktyget <citerefentry> <refentrytitle>" +"sss_debuglevel</refentrytitle> <manvolnum>8</manvolnum> </citerefentry>." #. type: Content of: <listitem><para> #: include/debug_levels.xml:29 include/debug_levels_tools.xml:10 @@ -22310,8 +23027,8 @@ msgid "" "Anything that would prevent SSSD from starting up or causes it to cease " "running." msgstr "" -"<emphasis>0</emphasis>, <emphasis>0x0010</emphasis>: Ödesdigra fel. Allt " -"som skulle hindra SSSD från att starta upp eller får den att sluta köra." +"<emphasis>0</emphasis>, <emphasis>0x0010</emphasis>: Fatala fel. Allt som " +"hindrar SSSD från att starta eller får den att sluta köras." #. type: Content of: <listitem><para> #: include/debug_levels.xml:38 include/debug_levels_tools.xml:19 @@ -22320,9 +23037,9 @@ msgid "" "error that doesn't kill SSSD, but one that indicates that at least one major " "feature is not going to work properly." msgstr "" -"<emphasis>1</emphasis>, <emphasis>0x0020</emphasis>: Kritiska fel. Ett fel " -"som inte dödar SSSD, men ett som indikerar att åtminstone en viktig funktion " -"inte kommer fungera korrekt." +"<emphasis>1</emphasis>, <emphasis>0x0020</emphasis>: Kritiska fel. Ett fel " +"som inte avslutar SSSD men visar att minst en viktig funktion inte kommer " +"att fungera korrekt." #. type: Content of: <listitem><para> #: include/debug_levels.xml:45 include/debug_levels_tools.xml:26 @@ -22339,8 +23056,8 @@ msgid "" "<emphasis>3</emphasis>, <emphasis>0x0080</emphasis>: Minor failures. These " "are the errors that would percolate down to cause the operation failure of 2." msgstr "" -"<emphasis>3</emphasis>, <emphasis>0x0080</emphasis>: Smärre fel. Detta är " -"fel som skulle kunna bubbla ner till att orsaka funktionsfelet 2." +"<emphasis>3</emphasis>, <emphasis>0x0080</emphasis>: Mindre fel. Dessa fel " +"kan fortplanta sig och orsaka det åtgärdsfel som anges på nivå 2." #. type: Content of: <listitem><para> #: include/debug_levels.xml:55 include/debug_levels_tools.xml:36 @@ -22399,10 +23116,9 @@ msgid "" "internally the logged execution time of a request might be longer than it " "actually was." msgstr "" -"<emphasis>9</emphasis>,<emphasis>0x20000</emphasis>: Prestanda och " -"statistiska data, observera att på grund av hur förfrågningar behandlas " -"internt kan den loggade exekveringstiden för en förfrågan vara längre än den " -"faktiskt var." +"<emphasis>9</emphasis>, <emphasis>0x20000</emphasis>: Prestanda- och " +"statistikdata. Observera att en begärans loggade körtid kan vara längre än " +"den faktiska, på grund av hur begäranden bearbetas internt." #. type: Content of: <listitem><para> #: include/debug_levels.xml:88 include/debug_levels_tools.xml:62 @@ -22410,8 +23126,8 @@ msgid "" "<emphasis>10</emphasis>, <emphasis>0x10000</emphasis>: Even more low-level " "libldb tracing information. Almost never really required." msgstr "" -"<emphasis>10</emphasis>, <emphasis>0x10000</emphasis>: Ännu mer lågnivå " -"spårningsinformation om libldb. Det behövs nästan aldrig." +"<emphasis>10</emphasis>, <emphasis>0x10000</emphasis>: Spårningsinformation " +"om libldb på ännu lägre nivå. Behövs nästan aldrig." #. type: Content of: <listitem><para> #: include/debug_levels.xml:93 include/debug_levels_tools.xml:67 @@ -22419,8 +23135,8 @@ msgid "" "To log required bitmask debug levels, simply add their numbers together as " "shown in following examples:" msgstr "" -"För att logga begärda bitmaskfelsökningsnivåer, lägg helt enkelt ihop deras " -"tal som visas i följande exempel:" +"För att logga önskade felsökningsnivåer i bitmaskform lägger du ihop deras " +"tal, som i följande exempel:" #. type: Content of: <listitem><para> #: include/debug_levels.xml:97 include/debug_levels_tools.xml:71 @@ -22428,8 +23144,8 @@ msgid "" "<emphasis>Example</emphasis>: To log fatal failures, critical failures, " "serious failures and function data use 0x0270." msgstr "" -"<emphasis>Exempel</emphasis>: För att logga ödesdigra fel, kritiska fel, " -"allvarliga fel och funktionsdata, använd 0x0270." +"<emphasis>Exempel</emphasis>: Använd 0x0270 för att logga fatala, kritiska " +"och allvarliga fel samt funktionsdata." #. type: Content of: <listitem><para> #: include/debug_levels.xml:101 include/debug_levels_tools.xml:75 @@ -22437,9 +23153,9 @@ msgid "" "<emphasis>Example</emphasis>: To log fatal failures, configuration settings, " "function data, trace messages for internal control functions use 0x1310." msgstr "" -"<emphasis>Exempel</emphasis>: För att logga ödesdigra fel, " +"<emphasis>Exempel</emphasis>: Använd 0x1310 för att logga fatala fel, " "konfigurationsinställningar, funktionsdata och spårmeddelanden för interna " -"styrfunktioner, använd 0x1310." +"styrfunktioner." #. type: Content of: <listitem><para> #: include/debug_levels.xml:106 include/debug_levels_tools.xml:80 @@ -22447,8 +23163,8 @@ msgid "" "<emphasis>Note</emphasis>: The bitmask format of debug levels was introduced " "in 1.7.0." msgstr "" -"<emphasis>Observera</emphasis>: bitmaskformatet för felsökningsnivåer " -"introducerades i 1.7.0." +"<emphasis>Observera</emphasis>: Bitmaskformatet för felsökningsnivåer " +"infördes i 1.7.0." #. type: Content of: <listitem><para> #: include/debug_levels.xml:110 include/debug_levels_tools.xml:84 @@ -22456,42 +23172,8 @@ msgid "" "<emphasis>Default</emphasis>: 0x0070 (i.e. fatal, critical and serious " "failures; corresponds to setting 2 in decimal notation)" msgstr "" -"<emphasis>Standard</emphasis>: 0x0070 (d.v.s. ödesdigra, kritiska och " -"allvarliga fel; motsvarar inställningen 2 i decimal notation)" - -#. type: Content of: <refsect1><title> -#: include/local.xml:2 -msgid "THE LOCAL DOMAIN" -msgstr "DEN LOKALA DOMÄNEN" - -#. type: Content of: <refsect1><para> -#: include/local.xml:4 -msgid "" -"In order to function correctly, a domain with <quote>id_provider=local</" -"quote> must be created and the SSSD must be running." -msgstr "" -"För att fungera korrekt måste en domän med <quote>id_provider=local</quote> " -"skapas och SSSD måste köra." - -#. type: Content of: <refsect1><para> -#: include/local.xml:9 -msgid "" -"The administrator might want to use the SSSD local users instead of " -"traditional UNIX users in cases where the group nesting (see <citerefentry> " -"<refentrytitle>sss_groupadd</refentrytitle> <manvolnum>8</manvolnum> </" -"citerefentry>) is needed. The local users are also useful for testing and " -"development of the SSSD without having to deploy a full remote server. The " -"<command>sss_user*</command> and <command>sss_group*</command> tools use a " -"local LDB storage to store users and groups." -msgstr "" -"Administratören kan vilja använda SSSD:s lokala användare istället för " -"traditionella UNIX-användare i fall när nästning av grupper (se " -"<citerefentry> <refentrytitle>sss_groupadd</refentrytitle> <manvolnum>8</" -"manvolnum> </citerefentry>) behövs. De lokala användarna är också " -"användbara för att testa och utveckla SSSD utan att behöva installera en " -"fullständig fjärrserver. Verktygen <command>sss_user*</command> och " -"<command>sss_group*</command> använder en lokal LDB-lagring för att lagra " -"användare och grupper." +"<emphasis>Standard</emphasis>: 0x0070 (det vill säga fatala, kritiska och " +"allvarliga fel; motsvarar inställning 2 i decimalnotation)" #. type: Content of: <refsect1><para> #: include/seealso.xml:4 @@ -22575,14 +23257,14 @@ msgid "" "An optional base DN, search scope and LDAP filter to restrict LDAP searches " "for this attribute type." msgstr "" -"En valfri bas-DN, sökräckvidd och LDAP-filter för att begränsa LDAP-" +"En valfri bas-DN, sökomfång och ett LDAP-filter för att begränsa LDAP-" "sökningar för denna attributtyp." #. type: Content of: <listitem><para><programlisting> #: include/ldap_search_bases.xml:9 #, no-wrap msgid "search_base[?scope?[filter][?search_base?scope?[filter]]*]\n" -msgstr "search_base[?räckvidd?[filter][?search_base?räckvidd?[filter]]*]\n" +msgstr "search_base[?scope?[filter][?search_base?scope?[filter]]*]\n" #. type: Content of: <listitem><para> #: include/ldap_search_bases.xml:7 @@ -22596,9 +23278,8 @@ msgid "" "functions as specified in section 4.5.1.2 of http://tools.ietf.org/html/" "rfc4511" msgstr "" -"Räckvidden kan vara en av ”base”, ”onelevel” eller ”subtree”. " -"Räckviddsfunktionerna beskrivs i avsnitt 4.5.1.2 av http://tools.ietf.org/" -"html/rfc4511" +"Sökomfånget kan vara \"base\", \"onelevel\" eller \"subtree\". Det fungerar " +"enligt beskrivningen i avsnitt 4.5.1.2 i http://tools.ietf.org/html/rfc4511" #. type: Content of: <listitem><para> #: include/ldap_search_bases.xml:23 @@ -22606,7 +23287,7 @@ msgid "" "For examples of this syntax, please refer to the <quote>ldap_search_base</" "quote> examples section." msgstr "" -"För exempel på denna syntax, se exempelsektionen av <quote>ldap_search_base</" +"Exempel på syntaxen finns i exempelavsnittet för <quote>ldap_search_base</" "quote>." #. type: Content of: <listitem><para> @@ -22616,9 +23297,9 @@ msgid "" "against an Active Directory Server that might yield a large number of " "results and trigger the Range Retrieval extension in the response." msgstr "" -"Observera att angivelse av räckvidd eller filter inte stödjs för sökningar i " -"en Active Directory-server som kan resultera i ett stort antal resultat och " -"trigga utökningen Range Retrieval i svaret." +"Observera att det inte går att ange sökomfång eller filter för sökningar mot " +"en Active Directory-server som kan ge många resultat och utlösa Range " +"Retrieval-utökningen i svaret." #. type: Content of: <para> #: include/autofs_restart.xml:2 @@ -22627,9 +23308,10 @@ msgid "" "any autofs-related changes are made to the sssd.conf, you typically also " "need to restart the automounter daemon after restarting the SSSD." msgstr "" -"Observera att automounter:n bara läser master-kartan vid uppstart, så om " -"några autofs-relaterade ändringar görs av sssd.conf behöver du normalt även " -"starta om automounter-demonen efter att ha startat om SSSD." +"Observera att automonteraren endast läser huvudkartan vid uppstart. Om " +"autofs-relaterade ändringar görs i sssd.conf behöver du därför vanligtvis " +"även starta om automonterarens bakgrundsprocess efter att SSSD har startats " +"om." #. type: Content of: <varlistentry><term> #: include/override_homedir.xml:2 @@ -22639,7 +23321,7 @@ msgstr "override_homedir (sträng)" #. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: include/override_homedir.xml:16 msgid "UID number" -msgstr "AID-nummer" +msgstr "UID-nummer" #. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: include/override_homedir.xml:20 @@ -22654,7 +23336,7 @@ msgstr "%f" #. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: include/override_homedir.xml:24 msgid "fully qualified user name (user@domain)" -msgstr "fullständigt kvalificerat användarnamn (användare@domän)" +msgstr "fullständigt kvalificerat användarnamn (user@domain)" #. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><term> #: include/override_homedir.xml:27 @@ -22669,7 +23351,7 @@ msgstr "Första bokstaven i inloggningsnamnet." #. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: include/override_homedir.xml:32 msgid "UPN - User Principal Name (name@REALM)" -msgstr "UPN – Användarens Huvudmansnamn (namn@RIKE)" +msgstr "UPN – User Principal Name (name@REALM)" #. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><term> #: include/override_homedir.xml:35 @@ -22748,7 +23430,7 @@ msgstr "" #. type: Content of: <varlistentry><listitem><para> #: include/override_homedir.xml:84 msgid "Default: Not set (SSSD will use the value retrieved from LDAP)" -msgstr "Standard: Inte satt (SSSD kommer använda värdet som hämtas från LDAP)" +msgstr "Standard: inte angivet (SSSD använder värdet som hämtas från LDAP)" #. type: Content of: <varlistentry><listitem><para> #: include/override_homedir.xml:88 @@ -22759,11 +23441,11 @@ msgid "" "IPA id-overrides, has a higher precedence and will be used instead of the " "value given by override_homedir." msgstr "" -"Observera att hemkatalog från ett specifikt åsidosättande för användaren, " -"antingen lokalt (se <citerefentry><refentrytitle>sss_override</" -"refentrytitle> <manvolnum>8</manvolnum></citerefentry>) eller centralt " -"hanterat IPA-id-åsidosättande, har en högre precedens och kommer användas " -"istället för värdet gom ges av override_homedir." +"Observera att hemkatalogen från ett specifikt användaråsidosättande, " +"antingen lokalt, se <citerefentry><refentrytitle>sss_override</" +"refentrytitle> <manvolnum>8</manvolnum></citerefentry>, eller från centralt " +"hanterade IPA ID-åsidosättanden, har högre prioritet och används i stället " +"för värdet från override_homedir." #. type: Content of: <varlistentry><term> #: include/homedir_substring.xml:2 @@ -22781,13 +23463,12 @@ msgid "" "per-domain or globally in the [nss] section. A value specified in a domain " "section will override one set in the [nss] section." msgstr "" -"Värdet på detta alternativ kommer användas i expansionen av alternativet " -"<emphasis>override_homedir</emphasis> om mallen innehåller formatsträngen " -"<emphasis>%H</emphasis>. En LDAP-katalogpost kan innehålla denna mall " -"direkt så att detta alternativ kan användas för att expandera sökvägen till " -"hemkatalogen för varje klientmaskin (eller operativsystem). Den kan sättas " -"per domän eller globalt i avsnittet [nss]. Ett värde som anges i ett " -"domänavsnitt kommer åsidosätta ett som är satt i avsnittet [nss]." +"Värdet för alternativet används vid expansion av <emphasis>override_homedir</" +"emphasis> om mallen innehåller formatsträngen <emphasis>%H</emphasis>. En " +"LDAP-katalogpost kan innehålla mallen direkt, så att alternativet kan " +"användas för att expandera hemkatalogsökvägen för varje klientmaskin eller " +"operativsystem. Det kan anges per domän eller globalt i avsnittet [nss]. Ett " +"värde i ett domänavsnitt åsidosätter ett värde i avsnittet [nss]." #. type: Content of: <varlistentry><listitem><para> #: include/homedir_substring.xml:15 @@ -22806,9 +23487,9 @@ msgid "" "defaults, these option names and AD provider-specific defaults are listed " "below:" msgstr "" -"Vissa alternativs standardvärde stämmer inte med deras respektive bakändars " -"standardvärden, dessa alternativnamn och AD-leverantörspecifika " -"standardvärden är uppräknade nedan:" +"Vissa alternativs standardvärden stämmer inte överens med standardvärdena " +"hos deras respektive bakomliggande komponenter. Dessa alternativnamn och AD-" +"leverantörsspecifika standardvärden listas nedan:" #. type: Content of: <refsect1><refsect2><title> #: include/ad_modified_defaults.xml:9 include/ipa_modified_defaults.xml:9 @@ -22868,7 +23549,7 @@ msgstr "ldap_use_tokengroups = true" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ad_modified_defaults.xml:63 msgid "ldap_sasl_authid = sAMAccountName@REALM (typically SHORTNAME$@REALM)" -msgstr "ldap_sasl_authid = sAMAccountName@RIKE (typiskt KORTNAMN$@RIKE)" +msgstr "ldap_sasl_authid = sAMAccountName@REALM (typically SHORTNAME$@REALM)" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ad_modified_defaults.xml:66 @@ -22881,13 +23562,13 @@ msgid "" "known host/hostname@REALM principal is a Service Principal and thus cannot " "be used to get a TGT with." msgstr "" -"AD-leverantören letar efter en annan huvudman än LDAP-leverantören som " -"standard, eftersom huvudmännen i en Active Directory-miljö är uppdelade i " -"två grupper – användarhuvudmän och tjänstehuvudmän. Endast " -"användarhuvudmannen kan användas för att hämta en TGT och som standard är " -"datorobjekts huvudman konstruerade från dess sAMAccountName och AD-riket. " -"Den välkända huvudmannen för värd/värdnamn@RIKE är en tjänstehuvudman och " -"kan därmed inte användas för att hämta en TGT." +"AD-leverantören söker som standard efter en annan huvudman än LDAP-" +"leverantören, eftersom huvudmännen i en Active Directory-miljö delas in i " +"två grupper: User Principals och Service Principals. Endast en User " +"Principal kan användas för att hämta en TGT. Som standard konstrueras " +"datorobjektets huvudman av dess sAMAccountName och AD-realmet. Den välkända " +"huvudmannen host/hostname@REALM är en Service Principal och kan därför inte " +"användas för att hämta en TGT." #. type: Content of: <refsect1><refsect2><title> #: include/ad_modified_defaults.xml:80 @@ -22908,11 +23589,11 @@ msgid "" "and you want to avoid this fallback behavior, you can explicitly set " "\"fallback_homedir = %o\"." msgstr "" -"AD-leverantören sätter automatiskt ”fallback_homedir = /home/%d/%u” för att " +"AD-leverantören anger automatiskt \"fallback_homedir = /home/%d/%u\" för att " "tillhandahålla personliga hemkataloger för användare utan attributet " -"homeDirectory. Om ens AD-domän är vederbörligen populerad med Posix-" -"attribut, och man vill undvika att falla tillbaka på detta beteende, kan man " -"uttryckligen sätta ”fallback_homedir = %o”." +"homeDirectory. Om AD-domänen har fyllts i korrekt med POSIX-attribut och du " +"vill undvika detta reservbeteende kan du uttryckligen ange " +"\"fallback_homedir = %o\"." #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ad_modified_defaults.xml:96 @@ -22921,9 +23602,9 @@ msgid "" "If you decide to use a different directory structure, some other parts of " "your system may need adjustments." msgstr "" -"Observera att systemet typiskt förväntar sig en hemkatalog i mappen /home/" -"%u. Om man bestämmer sig för att använda en annan katalogstruktur kan några " -"andra delar av ens system behöva justeras." +"Observera att systemet vanligen förväntar sig en hemkatalog i katalogen /" +"home/%u. Om du väljer en annan katalogstruktur kan andra delar av systemet " +"behöva justeras." #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ad_modified_defaults.xml:102 @@ -22932,9 +23613,9 @@ msgid "" "selinux requires selinux adjustment, otherwise the home directory will be " "created with wrong selinux context." msgstr "" -"Till exempel kräver automatiserat skapande av hemkataloger i kombination med " -"selinux anpassningar av selinux, annars kommer hemkatalogen skapas med fel " -"selinux-kontext." +"Automatiskt skapande av hemkataloger tillsammans med SELinux kräver till " +"exempel anpassning av SELinux, annars skapas hemkatalogen med fel SELinux-" +"kontext." #. type: Content of: <refsect1><para> #: include/ipa_modified_defaults.xml:4 @@ -22943,9 +23624,9 @@ msgid "" "defaults, these option names and IPA provider-specific defaults are listed " "below:" msgstr "" -"Vissa alternativs standardvärde stämmer inte med deras respektive bakändars " -"standardvärden, dessa alternativnamn och IPA-leverantörspecifika " -"standardvärden är uppräknade nedan:" +"Vissa alternativs standardvärden stämmer inte överens med standardvärdena " +"hos deras respektive bakomliggande komponenter. Dessa alternativnamn och IPA-" +"leverantörsspecifika standardvärden listas nedan:" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ipa_modified_defaults.xml:18 @@ -23054,14 +23735,14 @@ msgid "" "request is aborted. If possible, the authentication request is continued " "offline." msgstr "" -"Tidsgräns i sekunder efter vilken en uppkopplad begäran om autentisering " -"eller begäran om lösenordsändring avbryts. Om möjligt fortsätts begäran om " -"autentisering frånkopplat." +"Tidsgräns i sekunder efter vilken en autentiseringsbegäran när ansluten, " +"eller en begäran om lösenordsändring, avbryts. Om möjligt fortsätter " +"autentiseringsbegäran frånkopplad." #. type: Content of: <variablelist><varlistentry><term> #: include/krb5_options.xml:17 msgid "krb5_validate (boolean)" -msgstr "krb5_validate (boolean)" +msgstr "krb5_validate (boolesk)" #. type: Content of: <variablelist><varlistentry><listitem><para> #: include/krb5_options.xml:20 @@ -23073,13 +23754,13 @@ msgid "" "environments using cross-realm trust by placing the appropriate keytab entry " "as the last entry or the only entry in the keytab file." msgstr "" -"Verifiera med hjälp av krb5_keytab att den TGT om hämtats inte har " -"förfalskats. I keytab:en kontrolleras poster sekventiellt, och den första " -"posten med ett matchande rike används för validering. Om ingen post matchar " -"riket används den sista posten i keytab:en. Denna process kan användas för " -"att validera miljöer genom att använda förtroenden mellan riken genom att " -"placera den motsvarande keytab-posten som sista post eller den enda posten i " -"keytab-filen." +"Verifiera med hjälp av krb5_keytab att den hämtade TGT:n inte har " +"förfalskats. Keytab-filen kontrolleras sekventiellt, och den första posten " +"med ett matchande realm används för validering. Om ingen post matchar " +"realmet används den sista posten i keytab-filen. Processen kan användas för " +"att validera miljöer som använder förtroenderelationer mellan realmer genom " +"att placera lämplig keytab-post som den sista, eller enda, posten i keytab-" +"filen." #. type: Content of: <variablelist><varlistentry><listitem><para> #: include/krb5_options.xml:29 @@ -23112,8 +23793,8 @@ msgid "" "Request a renewable ticket with a total lifetime, given as an integer " "immediately followed by a time unit:" msgstr "" -"Begär en förnybar biljett med en total livslängd, given som ett heltal " -"omedelbart följd av en tidsenhet:" +"Begär en förnybar biljett med en total livslängd, angiven som ett heltal " +"omedelbart följt av en tidsenhet:" #. type: Content of: <variablelist><varlistentry><listitem><para> #: include/krb5_options.xml:52 include/krb5_options.xml:86 @@ -23150,14 +23831,13 @@ msgid "" "NOTE: It is not possible to mix units. To set the renewable lifetime to one " "and a half hours, use '90m' instead of '1h30m'." msgstr "" -"OBSERVERA: det är inte möjligt att blanda enheter. För att sätta den " -"förnybara livslängden till en och en halv timma, använd ”90m” istället för ”" -"1h30m”." +"OBSERVERA: Det går inte att blanda enheter. Använd '90m' i stället för " +"'1h30m' för att sätta den förnybara livslängden till en och en halv timme." #. type: Content of: <variablelist><varlistentry><listitem><para> #: include/krb5_options.xml:73 msgid "Default: not set, i.e. the TGT is not renewable" -msgstr "Standard: inte satt, d.v.s. TGT:en är inte förnybar" +msgstr "Standard: inte angivet, dvs. TGT:n är inte förnybar" #. type: Content of: <variablelist><varlistentry><term> #: include/krb5_options.xml:79 @@ -23170,8 +23850,8 @@ msgid "" "Request ticket with a lifetime, given as an integer immediately followed by " "a time unit:" msgstr "" -"Begär en biljett med en livslängd, given som ett heltal omedelbart följd av " -"en tidsenhet:" +"Begär en biljett med en livslängd, angiven som ett heltal omedelbart följt " +"av en tidsenhet:" #. type: Content of: <variablelist><varlistentry><listitem><para> #: include/krb5_options.xml:98 @@ -23184,16 +23864,16 @@ msgid "" "NOTE: It is not possible to mix units. To set the lifetime to one and a " "half hours please use '90m' instead of '1h30m'." msgstr "" -"OBSERVERA: det är inte möjligt att blanda enheter. För att sätta " -"livslängden till en och en halv timma, använd ”90m” istället för ”1h30m”." +"OBSERVERA: Det går inte att blanda enheter. Använd '90m' i stället för " +"'1h30m' för att sätta livslängden till en och en halv timme." #. type: Content of: <variablelist><varlistentry><listitem><para> #: include/krb5_options.xml:107 msgid "" "Default: not set, i.e. the default ticket lifetime configured on the KDC." msgstr "" -"Standard: inte satt, d.v.s. biljettens standardlivslängd konfigurerad på " -"KDC:n." +"Standard: inte angivet, dvs. den standardlivslängd för biljetter som är " +"konfigurerad på KDC:n." #. type: Content of: <variablelist><varlistentry><term> #: include/krb5_options.xml:114 @@ -23207,16 +23887,15 @@ msgid "" "are renewed if about half of their lifetime is exceeded, given as an integer " "immediately followed by a time unit:" msgstr "" -"Tiden i sekunder mellan två kontroller om TGT:en skall förnyas. TGT:er " -"förnyas om ungefär halva deras livstid har överskridits, givet som ett " +"Tiden i sekunder mellan två kontroller av om TGT:n ska förnyas. TGT:er " +"förnyas när ungefär hälften av deras livstid har passerat, angivet som ett " "heltal omedelbart följt av en tidsenhet:" #. type: Content of: <variablelist><varlistentry><listitem><para> #: include/krb5_options.xml:144 msgid "If this option is not set or is 0 the automatic renewal is disabled." msgstr "" -"Om detta alternativ inte är satt eller är 0 är den automatiska förnyelsen " -"avaktiverad." +"Om alternativet inte är angivet eller är 0 inaktiveras automatisk förnyelse." #. type: Content of: <variablelist><varlistentry><listitem><para> #: include/krb5_options.xml:157 @@ -23224,8 +23903,119 @@ msgid "" "Specifies if the host and user principal should be canonicalized. This " "feature is available with MIT Kerberos 1.7 and later versions." msgstr "" -"Anger om värdens och användarens huvudman skall göras kanonisk. Denna " -"funktion är tillgänglig med MIT Kerberos 1.7 och senare versioner." +"Anger om värdens och användarens huvudmän ska kanoniseras. Funktionen är " +"tillgänglig i MIT Kerberos 1.7 och senare versioner." + +#~ msgid "" +#~ "The data types used are string (no quotes needed), integer and bool (with " +#~ "values of <quote>TRUE/FALSE</quote>)." +#~ msgstr "" +#~ "Datatyperna som används är sträng (inga citationstecken behövs), heltal " +#~ "och bool (med värdena <quote>TRUE/FALSE</quote>)." + +#~ msgid "services" +#~ msgstr "services" + +#~ msgid "domains" +#~ msgstr "domains" + +#~ msgid "fd_limit" +#~ msgstr "fd_limit" + +#~ msgid "client_idle_timeout" +#~ msgstr "client_idle_timeout" + +#~ msgid "default_shell" +#~ msgstr "default_shell" + +#~ msgid "" +#~ "Note: This option can also be set per-domain which overwrites the value " +#~ "in [nss] section." +#~ msgstr "" +#~ "Observera: detta alternativ kan även sättas per domän vilket åsidosätter " +#~ "värdet i [nss]-sektionen." + +#~ msgid "These options can be used to configure session recording." +#~ msgstr "" +#~ "Dessa alternativ kan användas för att konfigurera inspelning av sessioner." + +#~ msgid "entry_cache_computer_timeout (integer)" +#~ msgstr "entry_cache_computer_timeout (heltal)" + +#~ msgid "" +#~ "How many seconds to keep the local computer entry before asking the " +#~ "backend again" +#~ msgstr "" +#~ "Hur många sekunder som den lokala datorns post sparas före bakänden " +#~ "frågas igen" + +#~ msgid "" +#~ "Default: <quote>id_provider</quote> is used if it is set and can handle " +#~ "selinux loading requests." +#~ msgstr "" +#~ "Standard: <quote>id_provider</quote> används om det är satt och kan " +#~ "hantera begäranden om inläsning av selinux." + +#~ msgid "" +#~ "Please see the section <quote>FAILOVER</quote> for more information about " +#~ "the service resolution." +#~ msgstr "" +#~ "Se avsnittet <quote>RESERVER</quote> för mer information om tjänstevalet." + +#~ msgid "" +#~ "NOTE: On older systems (such as RHEL 5), for this behavior to work " +#~ "reliably, the default Kerberos realm must be set properly in /etc/" +#~ "krb5.conf" +#~ msgstr "" +#~ "OBS: på äldre system (såsom RHEL 5) måste standardriket för Kerberos " +#~ "sättas i /etc/krb5.conf för att detta beteende skall fungera pålitligt" + +#~ msgid "ipa_hbac_selinux (integer)" +#~ msgstr "ipa_hbac_selinux (heltal)" + +#~ msgid "" +#~ "NOTE: While it is still possible to use the old " +#~ "<emphasis>ipa_dyndns_iface</emphasis> option, users should migrate to " +#~ "using <emphasis>dyndns_iface</emphasis> in their config file." +#~ msgstr "" +#~ "OBS: även om det fortfarande är möjligt att använda det gamla " +#~ "alternativet <emphasis>ipa_dyndns_iface</emphasis> bör användare migrera " +#~ "till att använda <emphasis>dyndns_iface</emphasis> i sin " +#~ "konfigurationsfil." + +#~ msgid "Default: loginDisabled" +#~ msgstr "Standard: loginDisabled" + +#~ msgid "Default: loginAllowedTimeMap" +#~ msgstr "Standard: loginAllowedTimeMap" + +#~ msgid "THE LOCAL DOMAIN" +#~ msgstr "DEN LOKALA DOMÄNEN" + +#~ msgid "" +#~ "In order to function correctly, a domain with <quote>id_provider=local</" +#~ "quote> must be created and the SSSD must be running." +#~ msgstr "" +#~ "För att fungera korrekt måste en domän med <quote>id_provider=local</" +#~ "quote> skapas och SSSD måste köra." + +#~ msgid "" +#~ "The administrator might want to use the SSSD local users instead of " +#~ "traditional UNIX users in cases where the group nesting (see " +#~ "<citerefentry> <refentrytitle>sss_groupadd</refentrytitle> <manvolnum>8</" +#~ "manvolnum> </citerefentry>) is needed. The local users are also useful " +#~ "for testing and development of the SSSD without having to deploy a full " +#~ "remote server. The <command>sss_user*</command> and <command>sss_group*</" +#~ "command> tools use a local LDB storage to store users and groups." +#~ msgstr "" +#~ "Administratören kan vilja använda SSSD:s lokala användare istället för " +#~ "traditionella UNIX-användare i fall när nästning av grupper (se " +#~ "<citerefentry> <refentrytitle>sss_groupadd</refentrytitle> <manvolnum>8</" +#~ "manvolnum> </citerefentry>) behövs. De lokala användarna är också " +#~ "användbara för att testa och utveckla SSSD utan att behöva installera en " +#~ "fullständig fjärrserver. Verktygen <command>sss_user*</command> och " +#~ "<command>sss_group*</command> använder en lokal LDB-lagring för att lagra " +#~ "användare och grupper." #~ msgid "subdomain_enumerate (string)" #~ msgstr "subdomain_enumerate (sträng)" @@ -24413,9 +25203,6 @@ msgstr "" #~ "Huruvida motpartens certifikat skall verifieras och vara giltigt om HTTPS-" #~ "protokollet används med proxy-leverantören." -#~ msgid "verify_host (boolean)" -#~ msgstr "verify_host (boolean)" - #~ msgid "" #~ "Whether peer's hostname must match with hostname in its certificate if " #~ "HTTPS protocol is used with the proxy provider." @@ -24682,9 +25469,6 @@ msgstr "" #~ "Följande exempel raderar en hemlighet som heter ”apa”:<placeholder " #~ "type=\"programlisting\" id=\"0\"/>" -#~ msgid "EXAMPLE CUSTODIA AND PROXY PROVIDER CONFIGURATION" -#~ msgstr "EXEMPEL PÅ KONFIGURATION AV CUSTODIA- OCH PROXY-LEVERANTÖRER" - #~ msgid "" #~ "For testing the proxy provider, you need to set up a Custodia server to " #~ "proxy requests to. Please always consult the Custodia documentation, the " @@ -24891,9 +25675,6 @@ msgstr "" #~ "och grupper i SSSD:s egna databas, det vill säga, en domän som använder " #~ "<replaceable>id_provider=local</replaceable>." -#~ msgid "default_shell (string)" -#~ msgstr "default_shell (sträng)" - #~ msgid "The default shell for users created with SSSD userspace tools." #~ msgstr "" #~ "Standardskalet för användare som skapas med SSSD:s verktyg för " diff --git a/src/man/po/tg.po b/src/man/po/tg.po index 7eda506893f..d45a8e4e7cc 100644 --- a/src/man/po/tg.po +++ b/src/man/po/tg.po @@ -7,8 +7,8 @@ msgid "" msgstr "" "Project-Id-Version: sssd-docs 2.3.0\n" "Report-Msgid-Bugs-To: sssd-devel@redhat.com\n" -"POT-Creation-Date: 2026-01-14 15:00+0000\n" -"PO-Revision-Date: 2026-04-23 16:50+0000\n" +"POT-Creation-Date: 2026-10-05 16:14+0000\n" +"PO-Revision-Date: 2026-10-05 17:07+0000\n" "Last-Translator: Anonymous <noreply@weblate.org>\n" "Language-Team: Tajik <https://translate.fedoraproject.org/projects/sssd/sssd-" "manpage-master/tg/>\n" @@ -17,10 +17,10 @@ msgstr "" "Content-Type: text/plain; charset=UTF-8\n" "Content-Transfer-Encoding: 8bit\n" "Plural-Forms: nplurals=2; plural=(n != 1);\n" -"X-Generator: Weblate 5.17\n" +"X-Generator: Weblate 2026.10\n" #. type: Content of: <reference><title> -#: sssd.conf.5.xml:8 sssd-ldap.5.xml:5 pam_sss.8.xml:5 pam_sss_gss.8.xml:5 +#: sssd.conf.5.xml:10 sssd-ldap.5.xml:5 pam_sss.8.xml:5 pam_sss_gss.8.xml:5 #: sssd_krb5_locator_plugin.8.xml:5 sssd-simple.5.xml:5 sss-certmap.5.xml:5 #: sssd-ipa.5.xml:5 sssd-ad.5.xml:5 sssd-sudo.5.xml:5 sssd-idp.5.xml:5 #: sssd.8.xml:5 sss_obfuscate.8.xml:5 sss_override.8.xml:5 sssd-krb5.5.xml:5 @@ -33,12 +33,12 @@ msgid "SSSD Manual pages" msgstr "" #. type: Content of: <reference><refentry><refnamediv><refname> -#: sssd.conf.5.xml:13 sssd.conf.5.xml:19 +#: sssd.conf.5.xml:15 sssd.conf.5.xml:21 msgid "sssd.conf" msgstr "" #. type: Content of: <reference><refentry><refmeta><manvolnum> -#: sssd.conf.5.xml:14 sssd-ldap.5.xml:11 sssd-simple.5.xml:11 +#: sssd.conf.5.xml:16 sssd-ldap.5.xml:11 sssd-simple.5.xml:11 #: sss-certmap.5.xml:11 sssd-ipa.5.xml:11 sssd-ad.5.xml:11 sssd-sudo.5.xml:11 #: sssd-idp.5.xml:11 sssd-krb5.5.xml:11 sssd-ifp.5.xml:11 #: sss_rpcidmapd.5.xml:27 sssd-session-recording.5.xml:11 @@ -47,7 +47,7 @@ msgid "5" msgstr "5" #. type: Content of: <reference><refentry><refmeta><refmiscinfo> -#: sssd.conf.5.xml:15 sssd-ldap.5.xml:12 sssd-simple.5.xml:12 +#: sssd.conf.5.xml:17 sssd-ldap.5.xml:12 sssd-simple.5.xml:12 #: sss-certmap.5.xml:12 sssd-ipa.5.xml:12 sssd-ad.5.xml:12 sssd-sudo.5.xml:12 #: sssd-idp.5.xml:12 sssd-krb5.5.xml:12 sssd-ifp.5.xml:12 #: sss_rpcidmapd.5.xml:28 sssd-session-recording.5.xml:12 sssd-kcm.8.xml:12 @@ -56,17 +56,17 @@ msgid "File Formats and Conventions" msgstr "" #. type: Content of: <reference><refentry><refnamediv><refpurpose> -#: sssd.conf.5.xml:20 +#: sssd.conf.5.xml:22 msgid "the configuration file for SSSD" msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:24 +#: sssd.conf.5.xml:26 msgid "FILE FORMAT" msgstr "Формати файл" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd.conf.5.xml:32 +#: sssd.conf.5.xml:34 #, no-wrap msgid "" "<replaceable>[section]</replaceable>\n" @@ -76,7 +76,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:27 +#: sssd.conf.5.xml:29 msgid "" "The file has an ini-style syntax and consists of sections and parameters. A " "section begins with the name of the section in square brackets and continues " @@ -85,47 +85,50 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:39 +#: sssd.conf.5.xml:41 msgid "" -"The data types used are string (no quotes needed), integer and bool (with " -"values of <quote>TRUE/FALSE</quote>)." +"The data types used are string (no quotes needed), integer and boolean (with " +"values of <quote>TRUE/FALSE</quote>). Boolean values are case-insensitive; " +"for example, <quote>TRUE</quote>, <quote>True</quote> and <quote>true</" +"quote> are all equivalent and valid; the same applies to <quote>FALSE</" +"quote>." msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:44 +#: sssd.conf.5.xml:49 msgid "" "A comment line starts with a hash sign (<quote>#</quote>) or a semicolon " "(<quote>;</quote>). Inline comments are not supported." msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:50 +#: sssd.conf.5.xml:55 msgid "" "All sections can have an optional <replaceable>description</replaceable> " "parameter. Its function is only as a label for the section." msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:56 +#: sssd.conf.5.xml:61 msgid "" "<filename>sssd.conf</filename> must be a regular file that is owned, " "readable, and writeable only by 'root'." msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:60 +#: sssd.conf.5.xml:65 msgid "" "<filename>sssd.conf</filename> must be a regular file that is accessible " "only by the user used to run SSSD service or root." msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:66 +#: sssd.conf.5.xml:71 msgid "CONFIGURATION SNIPPETS FROM INCLUDE DIRECTORY" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:69 +#: sssd.conf.5.xml:74 msgid "" "The configuration file <filename>sssd.conf</filename> will include " "configuration snippets using the include directory <filename>conf.d</" @@ -133,7 +136,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:75 +#: sssd.conf.5.xml:80 msgid "" "Any file placed in <filename>conf.d</filename> that ends in " "<quote><filename>.conf</filename></quote> and does not begin with a dot " @@ -142,7 +145,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:83 +#: sssd.conf.5.xml:88 msgid "" "The configuration snippets from <filename>conf.d</filename> have higher " "priority than <filename>sssd.conf</filename> and will override " @@ -155,39 +158,88 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:97 +#: sssd.conf.5.xml:102 msgid "" "The snippet files require the same owner and permissions as " "<filename>sssd.conf</filename>." msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:103 +#: sssd.conf.5.xml:108 +msgid "VENDOR PROVIDED CONFIGURATION" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:111 +msgid "" +"The vendor provided configuration file is installed in " +"<filename>&sssd_vendor_dir;/sssd.conf</filename>, but this file must not be " +"directly edited. It can be completely masked by creating the system specific " +"configuration file <filename>&sssd_conf_dir;/sssd.conf</filename>, or partly " +"overriden by creating config snippets in <filename>&sssd_conf_dir;/conf.d</" +"filename> directory." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><title> +#: sssd.conf.5.xml:120 +msgid "CONFIGURATION FILE HIERARCHY" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:122 +msgid "" +"When sssd reads the configuration it first tries to open the system specific " +"configuration file in <filename>&sssd_conf_dir;/sssd.conf</filename>. If it " +"exists, it is loaded and snippets from <filename>&sssd_conf_dir;/conf.d</" +"filename> are applied. The vendor provided configuration file " +"<filename>&sssd_vendor_dir;/sssd.conf</filename> is completely ignored in " +"this case." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:131 +msgid "" +"If the system specific configuration file <filename>&sssd_conf_dir;/" +"sssd.conf</filename> does not exist, then the vendor configuration file " +"<filename>&sssd_vendor_dir;/sssd.conf</filename> is loaded and snippets from " +"<filename>&sssd_conf_dir;/conf.d</filename> are applied." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd.conf.5.xml:141 msgid "GENERAL OPTIONS" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:105 +#: sssd.conf.5.xml:143 msgid "Following options are usable in more than one configuration sections." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:109 +#: sssd.conf.5.xml:147 msgid "Options usable in all sections" msgstr "" +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:149 +msgid "" +"Note: Below options are ignored in <quote>[session_recording]</quote> " +"section, see <quote>Session recording configuration options</quote> section " +"for more details." +msgstr "" + #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:113 +#: sssd.conf.5.xml:156 msgid "debug_level (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:117 +#: sssd.conf.5.xml:160 msgid "debug (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:120 +#: sssd.conf.5.xml:163 msgid "" "SSSD 1.14 and later also includes the <replaceable>debug</replaceable> alias " "for <replaceable>debug_level</replaceable> as a convenience feature. If both " @@ -196,61 +248,61 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:130 -msgid "debug_timestamps (bool)" +#: sssd.conf.5.xml:173 +msgid "debug_timestamps (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:133 +#: sssd.conf.5.xml:176 msgid "" "Add a timestamp to the debug messages. If journald is enabled for SSSD " "debug logging this option is ignored." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:138 sssd.conf.5.xml:175 sssd.conf.5.xml:337 -#: sssd.conf.5.xml:644 sssd.conf.5.xml:668 sssd.conf.5.xml:875 -#: sssd.conf.5.xml:979 sssd.conf.5.xml:2113 sssd-ldap.5.xml:979 -#: sssd-ldap.5.xml:1134 sssd-ldap.5.xml:1237 sssd-ldap.5.xml:1306 -#: sssd-ldap.5.xml:1714 sssd-ldap.5.xml:1848 sssd-ldap.5.xml:1913 -#: sssd-ipa.5.xml:346 sssd-ad.5.xml:252 sssd-ad.5.xml:367 sssd-ad.5.xml:1180 -#: sssd-ad.5.xml:1382 sssd-krb5.5.xml:358 +#: sssd.conf.5.xml:181 sssd.conf.5.xml:218 sssd.conf.5.xml:380 +#: sssd.conf.5.xml:687 sssd.conf.5.xml:711 sssd.conf.5.xml:827 +#: sssd.conf.5.xml:932 sssd.conf.5.xml:2149 sssd.conf.5.xml:4730 +#: sssd-ldap.5.xml:979 sssd-ldap.5.xml:1134 sssd-ldap.5.xml:1237 +#: sssd-ldap.5.xml:1306 sssd-ldap.5.xml:1714 sssd-ldap.5.xml:1848 +#: sssd-ldap.5.xml:1913 sssd-ipa.5.xml:341 sssd-ad.5.xml:252 sssd-ad.5.xml:367 +#: sssd-ad.5.xml:1180 sssd-ad.5.xml:1375 sssd-krb5.5.xml:358 msgid "Default: true" msgstr "Пешфарз: true" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:143 -msgid "debug_microseconds (bool)" +#: sssd.conf.5.xml:186 +msgid "debug_microseconds (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:146 +#: sssd.conf.5.xml:189 msgid "" "Add microseconds to the timestamp in debug messages. If journald is enabled " "for SSSD debug logging this option is ignored." msgstr "" #. type: Content of: <variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:151 sssd.conf.5.xml:2040 sssd.conf.5.xml:4158 +#: sssd.conf.5.xml:194 sssd.conf.5.xml:2072 sssd.conf.5.xml:4363 #: sssd-ldap.5.xml:363 sssd-ldap.5.xml:998 sssd-ldap.5.xml:1209 -#: sssd-ldap.5.xml:1663 sssd-ldap.5.xml:1937 sssd-ipa.5.xml:146 -#: sssd-ipa.5.xml:706 sssd-ad.5.xml:1135 sssd-krb5.5.xml:268 +#: sssd-ldap.5.xml:1663 sssd-ldap.5.xml:1937 sssd-ipa.5.xml:141 +#: sssd-ipa.5.xml:701 sssd-ad.5.xml:1140 sssd-idp.5.xml:287 sssd-krb5.5.xml:268 #: sssd-krb5.5.xml:330 sssd-krb5.5.xml:432 include/krb5_options.xml:163 msgid "Default: false" msgstr "Пешфарз: false" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:156 -msgid "debug_backtrace_enabled (bool)" +#: sssd.conf.5.xml:199 +msgid "debug_backtrace_enabled (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:159 +#: sssd.conf.5.xml:202 msgid "Enable debug backtrace." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:162 +#: sssd.conf.5.xml:205 msgid "" "In case SSSD is run with debug_level less than 9, everything is logged to a " "ring buffer in memory and flushed to a log file on any error up to and " @@ -260,14 +312,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:171 +#: sssd.conf.5.xml:214 msgid "" "Feature is only supported for `logger == files` (i.e. setting doesn't have " "effect for other logger types)." msgstr "" #. type: Content of: outside any tag (error?) -#: sssd.conf.5.xml:111 sssd.conf.5.xml:186 sssd-ldap.5.xml:1754 +#: sssd.conf.5.xml:154 sssd.conf.5.xml:229 sssd-ldap.5.xml:1754 #: sssd-ldap.5.xml:1960 sss-certmap.5.xml:645 sssd-systemtap.5.xml:82 #: sssd-systemtap.5.xml:143 sssd-systemtap.5.xml:236 sssd-systemtap.5.xml:274 #: sssd-systemtap.5.xml:330 sssd-ldap-attributes.5.xml:40 @@ -280,17 +332,17 @@ msgid "<placeholder type=\"variablelist\" id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:184 +#: sssd.conf.5.xml:227 msgid "Options usable in SERVICE and DOMAIN sections" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:188 +#: sssd.conf.5.xml:231 msgid "timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:191 +#: sssd.conf.5.xml:234 msgid "" "Timeout in seconds between heartbeats for this service. This is used to " "ensure that the process is alive and capable of answering requests. Note " @@ -298,34 +350,34 @@ msgid "" msgstr "" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:198 sssd.conf.5.xml:1199 sssd.conf.5.xml:1673 -#: sssd.conf.5.xml:4174 sssd-ldap.5.xml:825 sssd-idp.5.xml:192 +#: sssd.conf.5.xml:241 sssd.conf.5.xml:1155 sssd.conf.5.xml:1665 +#: sssd.conf.5.xml:4379 sssd-ldap.5.xml:825 sssd-idp.5.xml:271 #: include/ldap_id_mapping.xml:270 msgid "Default: 10" msgstr "Пешфарз: 10" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:208 +#: sssd.conf.5.xml:251 msgid "SPECIAL SECTIONS" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:211 +#: sssd.conf.5.xml:254 msgid "The [sssd] section" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><title> -#: sssd.conf.5.xml:220 +#: sssd.conf.5.xml:263 msgid "Section parameters" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:222 -msgid "services" +#: sssd.conf.5.xml:265 +msgid "services (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:225 +#: sssd.conf.5.xml:268 msgid "" "Comma separated list of services that are started when sssd itself starts. " "<phrase condition=\"have_systemd\"> The services' list is optional on " @@ -334,7 +386,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:234 +#: sssd.conf.5.xml:277 msgid "" "Supported services: nss, pam, ifp <phrase condition=\"with_sudo\">, sudo</" "phrase> <phrase condition=\"with_autofs\">, autofs</phrase> <phrase " @@ -343,20 +395,20 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:241 +#: sssd.conf.5.xml:284 msgid "" "<phrase condition=\"have_systemd\"> By default, all services are disabled " "and the administrator must enable the ones allowed to be used by executing: " "\"systemctl enable sssd-@service@.socket\". </phrase>" msgstr "" -#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:250 -msgid "domains" +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sssd.conf.5.xml:293 sssd.conf.5.xml:4562 +msgid "domains (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:253 +#: sssd.conf.5.xml:296 msgid "" "A domain is a database containing user information. SSSD can use more " "domains at the same time, but at least one must be configured or SSSD won't " @@ -367,19 +419,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:266 sssd.conf.5.xml:3467 +#: sssd.conf.5.xml:309 sssd.conf.5.xml:3598 msgid "re_expression (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:269 +#: sssd.conf.5.xml:312 msgid "" "Default regular expression that describes how to parse the string containing " "user name and domain into these components." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:274 +#: sssd.conf.5.xml:317 msgid "" "Each domain can have an individual regular expression configured. For some " "ID providers there are also default regular expressions. See DOMAIN SECTIONS " @@ -387,12 +439,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:283 sssd.conf.5.xml:3524 +#: sssd.conf.5.xml:326 sssd.conf.5.xml:3655 msgid "full_name_format (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:286 sssd.conf.5.xml:3527 +#: sssd.conf.5.xml:329 sssd.conf.5.xml:3658 msgid "" "A <citerefentry> <refentrytitle>printf</refentrytitle> <manvolnum>3</" "manvolnum> </citerefentry>-compatible format that describes how to compose a " @@ -400,70 +452,70 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:297 sssd.conf.5.xml:3538 +#: sssd.conf.5.xml:340 sssd.conf.5.xml:3669 msgid "%1$s" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:298 sssd.conf.5.xml:3539 +#: sssd.conf.5.xml:341 sssd.conf.5.xml:3670 msgid "user name" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:301 sssd.conf.5.xml:3542 +#: sssd.conf.5.xml:344 sssd.conf.5.xml:3673 msgid "%2$s" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:304 sssd.conf.5.xml:3545 +#: sssd.conf.5.xml:347 sssd.conf.5.xml:3676 msgid "domain name as specified in the SSSD config file." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:310 sssd.conf.5.xml:3551 +#: sssd.conf.5.xml:353 sssd.conf.5.xml:3682 msgid "%3$s" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:313 sssd.conf.5.xml:3554 +#: sssd.conf.5.xml:356 sssd.conf.5.xml:3685 msgid "" "domain flat name. Mostly usable for Active Directory domains, both directly " "configured or discovered via IPA trusts." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:294 sssd.conf.5.xml:3535 +#: sssd.conf.5.xml:337 sssd.conf.5.xml:3666 msgid "" "The following expansions are supported: <placeholder type=\"variablelist\" " "id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:323 +#: sssd.conf.5.xml:366 msgid "" "Each domain can have an individual format string configured. See DOMAIN " "SECTIONS for more info on this option." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:329 +#: sssd.conf.5.xml:372 msgid "monitor_resolv_conf (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:332 +#: sssd.conf.5.xml:375 msgid "" "Controls if SSSD should monitor the state of resolv.conf to identify when it " "needs to update its internal DNS resolver." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:342 +#: sssd.conf.5.xml:385 msgid "try_inotify (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:345 +#: sssd.conf.5.xml:388 msgid "" "By default, SSSD will attempt to use inotify to monitor configuration files " "changes and will fall back to polling every five seconds if inotify cannot " @@ -471,7 +523,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:351 +#: sssd.conf.5.xml:394 msgid "" "There are some limited situations where it is preferred that we should skip " "even trying to use inotify. In these rare cases, this option should be set " @@ -479,59 +531,59 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:357 +#: sssd.conf.5.xml:400 msgid "" "Default: true on platforms where inotify is supported. False on other " "platforms." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:361 +#: sssd.conf.5.xml:404 msgid "" "Note: this option will have no effect on platforms where inotify is " "unavailable. On these platforms, polling will always be used." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:368 +#: sssd.conf.5.xml:411 msgid "krb5_rcache_dir (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:371 +#: sssd.conf.5.xml:414 msgid "" "Directory on the filesystem where SSSD should store Kerberos replay cache " "files." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:375 +#: sssd.conf.5.xml:418 msgid "" "This option accepts a special value __LIBKRB5_DEFAULTS__ that will instruct " "SSSD to let libkrb5 decide the appropriate location for the replay cache." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:381 +#: sssd.conf.5.xml:424 msgid "" "Default: Distribution-specific and specified at build-time. " "(__LIBKRB5_DEFAULTS__ if not configured)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:388 +#: sssd.conf.5.xml:431 msgid "default_domain_suffix (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:391 +#: sssd.conf.5.xml:434 msgid "" "Please note that this option is deprecated and domain_resolution_order " "should be used." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:395 +#: sssd.conf.5.xml:438 msgid "" "This string will be used as a default domain name for all names without a " "domain name component. The main use case is environments where the primary " @@ -541,7 +593,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:405 +#: sssd.conf.5.xml:448 msgid "" "Please note that if this option is set all users from the primary domain " "have to use their fully qualified name, e.g. user@domain.name, to log in. " @@ -551,21 +603,21 @@ msgid "" msgstr "" #. type: Content of: <variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:414 sssd-ldap.5.xml:937 sssd-ldap.5.xml:949 -#: sssd-ldap.5.xml:1042 sssd-ad.5.xml:921 sssd-ad.5.xml:996 sssd-krb5.5.xml:468 -#: sssd-ldap-attributes.5.xml:470 sssd-ldap-attributes.5.xml:978 -#: include/ldap_id_mapping.xml:211 include/ldap_id_mapping.xml:222 -#: include/krb5_options.xml:148 +#: sssd.conf.5.xml:457 sssd.conf.5.xml:2006 sssd-ldap.5.xml:937 +#: sssd-ldap.5.xml:949 sssd-ldap.5.xml:1042 sssd-ad.5.xml:926 +#: sssd-ad.5.xml:1001 sssd-krb5.5.xml:468 sssd-ldap-attributes.5.xml:470 +#: sssd-ldap-attributes.5.xml:978 include/ldap_id_mapping.xml:211 +#: include/ldap_id_mapping.xml:222 include/krb5_options.xml:148 msgid "Default: not set" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:419 +#: sssd.conf.5.xml:462 msgid "override_space (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:422 +#: sssd.conf.5.xml:465 msgid "" "This parameter will replace spaces (space bar) with the given character for " "user and group names. e.g. (_). User name "john doe" will be " @@ -575,7 +627,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:431 +#: sssd.conf.5.xml:474 msgid "" "Please note it is a configuration error to use a replacement character that " "might be used in user or group names. If a name contains the replacement " @@ -584,22 +636,22 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:439 +#: sssd.conf.5.xml:482 msgid "Default: not set (spaces will not be replaced)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:444 +#: sssd.conf.5.xml:487 msgid "certificate_verification (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:452 +#: sssd.conf.5.xml:495 msgid "no_ocsp" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:454 +#: sssd.conf.5.xml:497 msgid "" "Disables Online Certificate Status Protocol (OCSP) checks. This might be " "needed if the OCSP servers defined in the certificate are not reachable from " @@ -607,12 +659,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:462 +#: sssd.conf.5.xml:505 msgid "soft_ocsp" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:464 +#: sssd.conf.5.xml:507 msgid "" "If a connection cannot be established to an OCSP responder the OCSP check is " "skipped. This option should be used to allow authentication when the system " @@ -620,61 +672,61 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:474 +#: sssd.conf.5.xml:517 msgid "ocsp_dgst" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:476 +#: sssd.conf.5.xml:519 msgid "" "Digest (hash) function used to create the certificate ID for the OCSP " "request. Allowed values are:" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:480 +#: sssd.conf.5.xml:523 msgid "sha1" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:481 +#: sssd.conf.5.xml:524 msgid "sha256" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:482 +#: sssd.conf.5.xml:525 msgid "sha384" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:483 +#: sssd.conf.5.xml:526 msgid "sha512" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:486 +#: sssd.conf.5.xml:529 msgid "Default: sha1 (to allow compatibility with RFC5019-compliant responder)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:492 +#: sssd.conf.5.xml:535 msgid "no_verification" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:494 +#: sssd.conf.5.xml:537 msgid "" "Disables verification completely. This option should only be used for " "testing." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:500 +#: sssd.conf.5.xml:543 msgid "partial_chain" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:502 +#: sssd.conf.5.xml:545 msgid "" "Allow verification to succeed even if a <replaceable>complete</replaceable> " "chain cannot be built to a self-signed trust-anchor, provided it is possible " @@ -682,12 +734,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:511 +#: sssd.conf.5.xml:554 msgid "ocsp_default_responder=URL" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:513 +#: sssd.conf.5.xml:556 msgid "" "Sets the OCSP default responder which should be used instead of the one " "mentioned in the certificate. URL must be replaced with the URL of the OCSP " @@ -695,24 +747,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:523 +#: sssd.conf.5.xml:566 msgid "ocsp_default_responder_signing_cert=NAME" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:525 +#: sssd.conf.5.xml:568 msgid "" "This option is currently ignored. All needed certificates must be available " "in the PEM file given by pam_cert_db_path." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:533 +#: sssd.conf.5.xml:576 msgid "crl_file=/PATH/TO/CRL/FILE" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:535 +#: sssd.conf.5.xml:578 msgid "" "Use the Certificate Revocation List (CRL) from the given file during the " "verification of the certificate. The CRL must be given in PEM format, see " @@ -721,12 +773,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:548 +#: sssd.conf.5.xml:591 msgid "soft_crl" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:551 +#: sssd.conf.5.xml:594 msgid "" "If a Certificate Revocation List (CRL) is expired ignore the expiration " "time of the CRL and check the related certificates with the expired CRL. " @@ -735,7 +787,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:447 +#: sssd.conf.5.xml:490 msgid "" "With this parameter the certificate verification can be tuned with a comma " "separated list of options. Supported options are: <placeholder " @@ -743,46 +795,46 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:564 +#: sssd.conf.5.xml:607 msgid "Unknown options are reported but ignored." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:567 +#: sssd.conf.5.xml:610 msgid "Default: not set, i.e. do not restrict certificate verification" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:573 +#: sssd.conf.5.xml:616 msgid "disable_netlink (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:576 +#: sssd.conf.5.xml:619 msgid "" "SSSD hooks into the netlink interface to monitor changes to routes, " "addresses, links and trigger certain actions." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:581 +#: sssd.conf.5.xml:624 msgid "" "The SSSD state changes caused by netlink events may be undesirable and can " "be disabled by setting this option to 'true'" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:586 +#: sssd.conf.5.xml:629 msgid "Default: false (netlink changes are detected)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:591 -msgid "domain_resolution_order" +#: sssd.conf.5.xml:634 +msgid "domain_resolution_order (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:594 +#: sssd.conf.5.xml:637 msgid "" "Comma separated list of domains and subdomains representing the lookup order " "that will be followed. The list doesn't have to include all possible " @@ -793,7 +845,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:606 +#: sssd.conf.5.xml:649 msgid "" "Please, note that when this option is set the output format of all commands " "is always fully-qualified even when using short names for input. In case " @@ -809,19 +861,20 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:630 sssd.conf.5.xml:1697 sssd.conf.5.xml:4224 -#: sssd-ad.5.xml:187 sssd-ad.5.xml:328 sssd-ad.5.xml:342 sssd-idp.5.xml:108 -#: sssd-idp.5.xml:132 sssd-idp.5.xml:145 sssd-idp.5.xml:159 sssd-idp.5.xml:180 +#: sssd.conf.5.xml:673 sssd.conf.5.xml:1026 sssd.conf.5.xml:1689 +#: sssd.conf.5.xml:4429 sssd-ad.5.xml:187 sssd-ad.5.xml:328 sssd-ad.5.xml:342 +#: sssd-idp.5.xml:112 sssd-idp.5.xml:136 sssd-idp.5.xml:149 sssd-idp.5.xml:167 +#: sssd-idp.5.xml:188 msgid "Default: Not set" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:635 +#: sssd.conf.5.xml:678 msgid "implicit_pac_responder (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:638 +#: sssd.conf.5.xml:681 msgid "" "The PAC responder is enabled automatically for the IPA and AD provider to " "evaluate and check the PAC. If it has to be disabled set this option to " @@ -829,12 +882,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:649 +#: sssd.conf.5.xml:692 msgid "core_dumpable (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:652 +#: sssd.conf.5.xml:695 msgid "" "This option can be used for general system hardening: setting it to 'false' " "forbids core dumps for all SSSD processes to avoid leaking plain text " @@ -843,7 +896,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:660 +#: sssd.conf.5.xml:703 msgid "" "Take a note that this setting has no effect for 'ldap_child', 'krb5_child' " "and 'sssd_pam' as those privileged binaries can have a copy of a host keytab " @@ -852,24 +905,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:673 +#: sssd.conf.5.xml:716 msgid "passkey_verification (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:681 +#: sssd.conf.5.xml:724 msgid "user_verification (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:683 +#: sssd.conf.5.xml:726 msgid "" "Enable or disable the user verification (i.e. PIN, fingerprint) during " "authentication. If enabled, the PIN will always be requested." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:689 +#: sssd.conf.5.xml:732 msgid "" "The default is that the key settings decide what to do. In the IPA or " "kerberos pre-authentication case, this value will be overwritten by the " @@ -877,7 +930,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:676 +#: sssd.conf.5.xml:719 msgid "" "With this parameter the passkey verification can be tuned with a comma " "separated list of options. Supported options are: <placeholder " @@ -885,7 +938,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:213 +#: sssd.conf.5.xml:256 msgid "" "Individual pieces of SSSD functionality are provided by special SSSD " "services that are started and stopped together with SSSD. The services are " @@ -896,12 +949,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:708 +#: sssd.conf.5.xml:751 msgid "SERVICES SECTIONS" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:710 +#: sssd.conf.5.xml:753 msgid "" "Settings that can be used to configure different services are described in " "this section. They should reside in the [<replaceable>$NAME</replaceable>] " @@ -910,42 +963,41 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:717 +#: sssd.conf.5.xml:760 msgid "General service configuration options" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:719 +#: sssd.conf.5.xml:762 msgid "These options can be used to configure any service." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:723 -msgid "fd_limit" +#: sssd.conf.5.xml:766 +msgid "fd_limit (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:726 +#: sssd.conf.5.xml:769 msgid "" "This option specifies the maximum number of file descriptors that may be " -"opened at one time by this SSSD process. On systems where SSSD is granted " -"the CAP_SYS_RESOURCE capability, this will be an absolute setting. On " -"systems without this capability, the resulting value will be the lower value " -"of this or the limits.conf \"hard\" limit." +"opened at one time by this SSSD process. Note this value will be capped by " +"the init system at the startup of SSSD, see e.g. man systemd.exec for " +"details." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:735 +#: sssd.conf.5.xml:776 msgid "Default: 8192 (or limits.conf \"hard\" limit)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:740 -msgid "client_idle_timeout" +#: sssd.conf.5.xml:781 +msgid "client_idle_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:743 +#: sssd.conf.5.xml:784 msgid "" "This option specifies the number of seconds that a client of an SSSD process " "can hold onto a file descriptor without communicating on it. This value is " @@ -955,146 +1007,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:752 +#: sssd.conf.5.xml:793 #, fuzzy #| msgid "Default: 5400" msgid "Default: 60, KCM: 300" msgstr "Пешфарз: 5400" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:757 -msgid "offline_timeout (integer)" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:760 -msgid "" -"When SSSD switches to offline mode the amount of time before it tries to go " -"back online will increase based upon the time spent disconnected. By " -"default SSSD uses incremental behaviour to calculate delay in between " -"retries. So, the wait time for a given retry will be longer than the wait " -"time for the previous ones. After each unsuccessful attempt to go online, " -"the new interval is recalculated by the following:" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:771 sssd.conf.5.xml:827 -msgid "" -"new_delay = Minimum(old_delay * 2, offline_timeout_max) + " -"random[0...offline_timeout_random_offset]" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:774 -msgid "" -"The offline_timeout default value is 60. The offline_timeout_max default " -"value is 3600. The offline_timeout_random_offset default value is 30. The " -"end result is amount of seconds before next retry." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:780 -msgid "" -"Note that the maximum length of each interval is defined by " -"offline_timeout_max (apart of random part)." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:784 sssd.conf.5.xml:1110 sssd.conf.5.xml:1490 -#: sssd.conf.5.xml:1791 sssd-ldap.5.xml:550 -msgid "Default: 60" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:789 -msgid "offline_timeout_max (integer)" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:792 -msgid "" -"Controls by how much the time between attempts to go online can be " -"incremented following unsuccessful attempts to go online." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:797 -msgid "A value of 0 disables the incrementing behaviour." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:800 -msgid "" -"The value of this parameter should be set in correlation to offline_timeout " -"parameter value." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:804 -msgid "" -"With offline_timeout set to 60 (default value) there is no point in setting " -"offlinet_timeout_max to less than 120 as it will saturate instantly. General " -"rule here should be to set offline_timeout_max to at least 4 times " -"offline_timeout." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:810 -msgid "" -"Although a value between 0 and offline_timeout may be specified, it has the " -"effect of overriding the offline_timeout value so is of little use." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:815 -#, fuzzy -#| msgid "Default: 3" -msgid "Default: 3600" -msgstr "Пешфарз: 3" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:820 -msgid "offline_timeout_random_offset (integer)" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:823 -msgid "" -"When SSSD is in offline mode it keeps probing backend servers in specified " -"time intervals:" +#: sssd.conf.5.xml:798 +msgid "responder_idle_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:830 -msgid "" -"This parameter controls the value of the random offset used for the above " -"equation. Final random_offset value will be random number in range:" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:835 -msgid "[0 - offline_timeout_random_offset]" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:838 -msgid "A value of 0 disables the random offset addition." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:841 -#, fuzzy -#| msgid "Default: 3" -msgid "Default: 30" -msgstr "Пешфарз: 3" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:846 -msgid "responder_idle_timeout" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:849 +#: sssd.conf.5.xml:801 msgid "" "This option specifies the number of seconds that an SSSD responder process " "can be up without being used. This value is limited in order to avoid " @@ -1106,58 +1031,59 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:863 sssd.conf.5.xml:1123 sssd.conf.5.xml:2248 +#: sssd.conf.5.xml:815 sssd.conf.5.xml:1079 sssd.conf.5.xml:2285 #: sssd-ldap.5.xml:377 msgid "Default: 300" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:868 -msgid "cache_first" +#: sssd.conf.5.xml:820 +msgid "cache_first (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:871 +#: sssd.conf.5.xml:823 msgid "" "This option specifies whether the responder should query all caches before " "querying the Data Providers." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:883 +#: sssd.conf.5.xml:835 msgid "NSS configuration options" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:885 +#: sssd.conf.5.xml:837 msgid "" -"These options can be used to configure the Name Service Switch (NSS) service." +"These options can be used to configure the Name Service Switch (NSS) service " +"and should be specified under the <quote>[nss]</quote> section." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:890 +#: sssd.conf.5.xml:843 msgid "enum_cache_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:893 +#: sssd.conf.5.xml:846 msgid "" "How many seconds should nss_sss cache enumerations (requests for info about " "all users)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:897 +#: sssd.conf.5.xml:850 msgid "Default: 120" msgstr "Пешфарз: 120" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:902 +#: sssd.conf.5.xml:855 msgid "entry_cache_nowait_percentage (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:905 +#: sssd.conf.5.xml:858 msgid "" "The entry cache can be set to automatically update entries in the background " "if they are requested beyond a percentage of the entry_cache_timeout value " @@ -1165,7 +1091,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:911 +#: sssd.conf.5.xml:864 msgid "" "For example, if the domain's entry_cache_timeout is set to 30s and " "entry_cache_nowait_percentage is set to 50 (percent), entries that come in " @@ -1175,7 +1101,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:921 +#: sssd.conf.5.xml:874 msgid "" "Valid values for this option are 0-99 and represent a percentage of the " "entry_cache_timeout for each domain. For performance reasons, this " @@ -1184,17 +1110,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:929 sssd.conf.5.xml:2061 +#: sssd.conf.5.xml:882 sssd.conf.5.xml:2093 msgid "Default: 50" msgstr "Пешфарз: 50" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:934 +#: sssd.conf.5.xml:887 msgid "entry_negative_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:937 +#: sssd.conf.5.xml:890 msgid "" "Specifies for how many seconds nss_sss should cache negative cache hits " "(that is, queries for invalid database entries, like nonexistent ones) " @@ -1202,17 +1128,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:943 sssd.conf.5.xml:1685 sssd.conf.5.xml:2085 +#: sssd.conf.5.xml:896 sssd.conf.5.xml:1677 sssd.conf.5.xml:2119 msgid "Default: 15" msgstr "Пешфарз: 15" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:948 +#: sssd.conf.5.xml:901 msgid "filter_users, filter_groups (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:951 +#: sssd.conf.5.xml:904 msgid "" "Exclude certain users or groups from being fetched from the sss NSS " "database. This is particularly useful for system accounts. This option can " @@ -1221,7 +1147,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:959 +#: sssd.conf.5.xml:912 msgid "" "NOTE: The filter_groups option doesn't affect inheritance of nested group " "members, since filtering happens after they are propagated for returning via " @@ -1230,41 +1156,41 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:967 +#: sssd.conf.5.xml:920 msgid "Default: root" msgstr "Пешфарз: root" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:972 -msgid "filter_users_in_groups (bool)" +#: sssd.conf.5.xml:925 +msgid "filter_users_in_groups (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:975 +#: sssd.conf.5.xml:928 msgid "" -"If you want filtered user still be group members set this option to false." +"If you want filtered users to remain group members set this option to false" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:986 +#: sssd.conf.5.xml:939 msgid "fallback_homedir (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:989 +#: sssd.conf.5.xml:942 msgid "" "Set a default template for a user's home directory if one is not specified " "explicitly by the domain's data provider." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:994 +#: sssd.conf.5.xml:947 msgid "" "The available values for this option are the same as for override_homedir." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1000 +#: sssd.conf.5.xml:953 #, no-wrap msgid "" "fallback_homedir = /home/%u\n" @@ -1272,23 +1198,23 @@ msgid "" msgstr "" #. type: Content of: <varlistentry><listitem><para> -#: sssd.conf.5.xml:998 sssd.conf.5.xml:1557 sssd.conf.5.xml:1576 -#: sssd.conf.5.xml:1653 sssd-krb5.5.xml:451 include/override_homedir.xml:78 +#: sssd.conf.5.xml:951 sssd.conf.5.xml:1524 sssd.conf.5.xml:1543 +#: sssd.conf.5.xml:1645 sssd-krb5.5.xml:451 include/override_homedir.xml:78 msgid "example: <placeholder type=\"programlisting\" id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1004 +#: sssd.conf.5.xml:957 msgid "Default: not set (no substitution for unset home directories)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1010 +#: sssd.conf.5.xml:963 msgid "override_shell (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1013 +#: sssd.conf.5.xml:966 msgid "" "Override the login shell for all users. This option supersedes any other " "shell options if it takes effect and can be set either in the [nss] section " @@ -1296,47 +1222,47 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1019 +#: sssd.conf.5.xml:972 msgid "Default: not set (SSSD will use the value retrieved from LDAP)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1025 +#: sssd.conf.5.xml:978 msgid "allowed_shells (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1028 +#: sssd.conf.5.xml:981 msgid "" "Restrict user shell to one of the listed values. The order of evaluation is:" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1031 +#: sssd.conf.5.xml:984 msgid "1. If the shell is present in <quote>/etc/shells</quote>, it is used." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1035 +#: sssd.conf.5.xml:988 msgid "" "2. If the shell is in the allowed_shells list but not in <quote>/etc/shells</" "quote>, use the value of the shell_fallback parameter." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1040 +#: sssd.conf.5.xml:993 msgid "" "3. If the shell is not in the allowed_shells list and not in <quote>/etc/" "shells</quote>, a nologin shell is used." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1045 +#: sssd.conf.5.xml:998 msgid "The wildcard (*) can be used to allow any shell." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1048 +#: sssd.conf.5.xml:1001 msgid "" "The (*) is useful if you want to use shell_fallback in case that user's " "shell is not in <quote>/etc/shells</quote> and maintaining list of all " @@ -1344,113 +1270,119 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1055 +#: sssd.conf.5.xml:1008 msgid "An empty string for shell is passed as-is to libc." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1058 +#: sssd.conf.5.xml:1011 msgid "" "The <quote>/etc/shells</quote> is only read on SSSD start up, which means " "that a restart of the SSSD is required in case a new shell is installed." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1062 +#: sssd.conf.5.xml:1015 msgid "Default: Not set. The user shell is automatically used." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1067 +#: sssd.conf.5.xml:1020 msgid "vetoed_shells (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1070 +#: sssd.conf.5.xml:1023 msgid "Replace any instance of these shells with the shell_fallback" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1075 +#: sssd.conf.5.xml:1031 msgid "shell_fallback (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1078 +#: sssd.conf.5.xml:1034 msgid "" "The default shell to use if an allowed shell is not installed on the machine." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1082 +#: sssd.conf.5.xml:1038 msgid "Default: /bin/sh" msgstr "Пешфарз: /bin/sh" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1087 -msgid "default_shell" +#: sssd.conf.5.xml:1043 +msgid "default_shell (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1090 +#: sssd.conf.5.xml:1046 msgid "" "The default shell to use if the provider does not return one during lookup. " "This option can be specified globally in the [nss] section or per-domain." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1096 +#: sssd.conf.5.xml:1052 msgid "" "Default: not set (Return NULL if no shell is specified and rely on libc to " "substitute something sensible when necessary, usually /bin/sh)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1103 sssd.conf.5.xml:1483 +#: sssd.conf.5.xml:1059 sssd.conf.5.xml:1450 msgid "get_domains_timeout (int)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1106 sssd.conf.5.xml:1486 +#: sssd.conf.5.xml:1062 sssd.conf.5.xml:1453 msgid "" "Specifies time in seconds for which the list of subdomains will be " "considered valid." msgstr "" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1066 sssd.conf.5.xml:1457 sssd.conf.5.xml:1788 +#: sssd.conf.5.xml:2862 sssd-ldap.5.xml:550 +msgid "Default: 60" +msgstr "" + #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1115 +#: sssd.conf.5.xml:1071 msgid "memcache_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1118 +#: sssd.conf.5.xml:1074 msgid "" "Specifies time in seconds for which records in the in-memory cache will be " "valid. Setting this option to zero will disable the in-memory cache." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1126 +#: sssd.conf.5.xml:1082 msgid "" "WARNING: Disabling the in-memory cache will have significant negative impact " "on SSSD's performance and should only be used for testing." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1132 sssd.conf.5.xml:1157 sssd.conf.5.xml:1182 -#: sssd.conf.5.xml:1207 sssd.conf.5.xml:1234 +#: sssd.conf.5.xml:1088 sssd.conf.5.xml:1113 sssd.conf.5.xml:1138 +#: sssd.conf.5.xml:1163 sssd.conf.5.xml:1190 msgid "" "NOTE: If the environment variable SSS_NSS_USE_MEMCACHE is set to \"NO\", " "client applications will not use the fast in-memory cache." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1140 +#: sssd.conf.5.xml:1096 msgid "memcache_size_passwd (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1143 +#: sssd.conf.5.xml:1099 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for passwd requests. Setting the size to 0 will disable the passwd in-" @@ -1458,25 +1390,25 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1149 sssd.conf.5.xml:2888 sssd-ldap.5.xml:604 +#: sssd.conf.5.xml:1105 sssd.conf.5.xml:3013 sssd-ldap.5.xml:604 msgid "Default: 8" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1152 sssd.conf.5.xml:1177 sssd.conf.5.xml:1202 -#: sssd.conf.5.xml:1229 +#: sssd.conf.5.xml:1108 sssd.conf.5.xml:1133 sssd.conf.5.xml:1158 +#: sssd.conf.5.xml:1185 msgid "" "WARNING: Disabled or too small in-memory cache can have significant negative " "impact on SSSD's performance." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1165 +#: sssd.conf.5.xml:1121 msgid "memcache_size_group (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1168 +#: sssd.conf.5.xml:1124 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for group requests. Setting the size to 0 will disable the group in-memory " @@ -1484,19 +1416,19 @@ msgid "" msgstr "" #. type: Content of: <variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1174 sssd.conf.5.xml:1226 sssd.conf.5.xml:3656 +#: sssd.conf.5.xml:1130 sssd.conf.5.xml:1182 sssd.conf.5.xml:3835 #: sssd-ldap.5.xml:534 sssd-ldap.5.xml:581 include/failover.xml:116 #: include/krb5_options.xml:11 msgid "Default: 6" msgstr "Пешфарз: 6" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1190 +#: sssd.conf.5.xml:1146 msgid "memcache_size_initgroups (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1193 +#: sssd.conf.5.xml:1149 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for initgroups requests. Setting the size to 0 will disable the initgroups " @@ -1504,12 +1436,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1215 +#: sssd.conf.5.xml:1171 msgid "memcache_size_sid (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1218 +#: sssd.conf.5.xml:1174 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for SID related requests. Only SID-by-ID and ID-by-SID requests are " @@ -1518,12 +1450,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1242 sssd-ifp.5.xml:90 +#: sssd.conf.5.xml:1198 sssd-ifp.5.xml:90 msgid "user_attributes (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1245 +#: sssd.conf.5.xml:1201 msgid "" "Some of the additional NSS responder requests can return more attributes " "than just the POSIX ones defined by the NSS interface. The list of " @@ -1534,105 +1466,111 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1258 +#: sssd.conf.5.xml:1214 msgid "" "To make configuration more easy the NSS responder will check the InfoPipe " "option if it is not set for the NSS responder." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1263 +#: sssd.conf.5.xml:1219 msgid "Default: not set, fallback to InfoPipe option" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1268 +#: sssd.conf.5.xml:1224 msgid "pwfield (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1271 +#: sssd.conf.5.xml:1227 msgid "" "The value that NSS operations that return users or groups will return for " "the <quote>password</quote> field." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1276 +#: sssd.conf.5.xml:1232 +msgid "" +"This option can also be set per-domain, which overwrites the value in the " +"<quote>[nss]</quote> section for that domain. This is particularly useful " +"when using a proxy domain with <option>proxy_lib_name=files</option> and a " +"<option>proxy_pam_target</option> other than <quote>sssd-shadowutils</" +"quote>. In that case, SSSD returns <quote>*</quote> for the password field " +"by default, which causes <command>pam_unix</command> to treat all accounts " +"as locked. Setting <option>pwfield = x</option> in the domain section " +"restores the expected behavior." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1246 #, fuzzy #| msgid "Default: true" msgid "Default: <quote>*</quote>" msgstr "Пешфарз: true" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1279 +#: sssd.conf.5.xml:1249 msgid "" -"Note: This option can also be set per-domain which overwrites the value in " -"[nss] section." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1283 -msgid "" -"Default: <quote>not set</quote> (remote domains), <quote>x</quote> (proxy " -"domain with nss_files and sssd-shadowutils target)" +"Default (per-domain): <quote>not set</quote> (remote domains), <quote>x</" +"quote> (proxy domain with nss_files and sssd-shadowutils target)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:1292 +#: sssd.conf.5.xml:1258 msgid "PAM configuration options" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:1294 +#: sssd.conf.5.xml:1260 msgid "" "These options can be used to configure the Pluggable Authentication Module " -"(PAM) service." +"(PAM) service and should be specified under the <quote>[pam]</quote> section." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1299 +#: sssd.conf.5.xml:1266 msgid "offline_credentials_expiration (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1302 +#: sssd.conf.5.xml:1269 msgid "" "If the authentication provider is offline, how long should we allow cached " "logins (in days since the last successful online login)." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1307 sssd.conf.5.xml:1320 +#: sssd.conf.5.xml:1274 sssd.conf.5.xml:1287 msgid "Default: 0 (No limit)" msgstr "Пешфарз: 0 (Номаҳдуд)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1313 +#: sssd.conf.5.xml:1280 msgid "offline_failed_login_attempts (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1316 +#: sssd.conf.5.xml:1283 msgid "" "If the authentication provider is offline, how many failed login attempts " "are allowed." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1326 +#: sssd.conf.5.xml:1293 msgid "offline_failed_login_delay (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1329 +#: sssd.conf.5.xml:1296 msgid "" "The time in minutes which has to pass after offline_failed_login_attempts " "has been reached before a new login attempt is possible." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1334 +#: sssd.conf.5.xml:1301 msgid "" "If set to 0 the user cannot authenticate offline if " "offline_failed_login_attempts has been reached. Only a successful online " @@ -1640,59 +1578,59 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1340 sssd.conf.5.xml:1450 +#: sssd.conf.5.xml:1307 sssd.conf.5.xml:1417 msgid "Default: 5" msgstr "Пешфарз: 5" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1346 +#: sssd.conf.5.xml:1313 msgid "pam_verbosity (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1349 +#: sssd.conf.5.xml:1316 msgid "" "Controls what kind of messages are shown to the user during authentication. " "The higher the number to more messages are displayed." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1354 +#: sssd.conf.5.xml:1321 msgid "Currently sssd supports the following values:" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1357 +#: sssd.conf.5.xml:1324 msgid "<emphasis>0</emphasis>: do not show any message" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1360 +#: sssd.conf.5.xml:1327 msgid "<emphasis>1</emphasis>: show only important messages" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1364 +#: sssd.conf.5.xml:1331 msgid "<emphasis>2</emphasis>: show informational messages" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1367 +#: sssd.conf.5.xml:1334 msgid "<emphasis>3</emphasis>: show all messages and debug information" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1371 sssd.8.xml:63 +#: sssd.conf.5.xml:1338 sssd.8.xml:63 msgid "Default: 1" msgstr "Пешфарз: 1" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1377 +#: sssd.conf.5.xml:1344 msgid "pam_response_filter (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1380 +#: sssd.conf.5.xml:1347 msgid "" "A comma separated list of strings which allows to remove (filter) data sent " "by the PAM responder to pam_sss PAM module. There are different kind of " @@ -1701,51 +1639,51 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1388 +#: sssd.conf.5.xml:1355 msgid "" "While messages already can be controlled with the help of the pam_verbosity " "option this option allows to filter out other kind of responses as well." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1395 +#: sssd.conf.5.xml:1362 msgid "ENV" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1396 +#: sssd.conf.5.xml:1363 msgid "Do not send any environment variables to any service." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1399 +#: sssd.conf.5.xml:1366 msgid "ENV:var_name" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1400 +#: sssd.conf.5.xml:1367 msgid "Do not send environment variable var_name to any service." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1404 +#: sssd.conf.5.xml:1371 msgid "ENV:var_name:service" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1405 +#: sssd.conf.5.xml:1372 msgid "Do not send environment variable var_name to service." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1393 +#: sssd.conf.5.xml:1360 msgid "" "Currently the following filters are supported: <placeholder " "type=\"variablelist\" id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1412 +#: sssd.conf.5.xml:1379 msgid "" "The list of strings can either be the list of filters which would set this " "list of filters and overwrite the defaults. Or each element of the list can " @@ -1756,23 +1694,23 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1423 +#: sssd.conf.5.xml:1390 msgid "Default: ENV:KRB5CCNAME:sudo, ENV:KRB5CCNAME:sudo-i" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1426 +#: sssd.conf.5.xml:1393 msgid "" "Example: -ENV:KRB5CCNAME:sudo-i will remove the filter from the default list" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1433 +#: sssd.conf.5.xml:1400 msgid "pam_id_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1436 +#: sssd.conf.5.xml:1403 msgid "" "For any PAM request while SSSD is online, the SSSD will attempt to " "immediately update the cached identity information for the user in order to " @@ -1780,7 +1718,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1442 +#: sssd.conf.5.xml:1409 msgid "" "A complete PAM conversation may perform multiple PAM requests, such as " "account management and session opening. This option controls (on a per-" @@ -1789,17 +1727,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1456 +#: sssd.conf.5.xml:1423 msgid "pam_pwd_expiration_warning (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1459 sssd.conf.5.xml:2912 +#: sssd.conf.5.xml:1426 sssd.conf.5.xml:3037 msgid "Display a warning N days before the password expires." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1462 +#: sssd.conf.5.xml:1429 msgid "" "Please note that the backend server has to provide information about the " "expiration time of the password. If this information is missing, sssd " @@ -1807,32 +1745,32 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1468 sssd.conf.5.xml:2915 +#: sssd.conf.5.xml:1435 sssd.conf.5.xml:3040 msgid "" "If zero is set, then this filter is not applied, i.e. if the expiration " "warning was received from backend server, it will automatically be displayed." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1473 +#: sssd.conf.5.xml:1440 msgid "" "This setting can be overridden by setting <emphasis>pwd_expiration_warning</" "emphasis> for a particular domain." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1478 sssd.conf.5.xml:3913 sssd-ldap.5.xml:662 +#: sssd.conf.5.xml:1445 sssd.conf.5.xml:4118 sssd-ldap.5.xml:662 #: sssd-ldap.5.xml:1733 sssd.8.xml:79 msgid "Default: 0" msgstr "Пешфарз: 0" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1495 +#: sssd.conf.5.xml:1462 msgid "pam_trusted_users (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1498 +#: sssd.conf.5.xml:1465 msgid "" "Specifies the comma-separated list of UID values or user names that are " "allowed to run PAM conversations against trusted domains. Users not " @@ -1842,74 +1780,74 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1508 +#: sssd.conf.5.xml:1475 msgid "Default: All users are considered trusted by default" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1512 +#: sssd.conf.5.xml:1479 msgid "" "Please note that UID 0 is always allowed to access the PAM responder even in " "case it is not in the pam_trusted_users list." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1519 +#: sssd.conf.5.xml:1486 msgid "pam_public_domains (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1522 +#: sssd.conf.5.xml:1489 msgid "" "Specifies the comma-separated list of domain names that are accessible even " "to untrusted users." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1526 +#: sssd.conf.5.xml:1493 msgid "Two special values for pam_public_domains option are defined:" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1530 +#: sssd.conf.5.xml:1497 msgid "" "all (Untrusted users are allowed to access all domains in PAM responder.)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1534 +#: sssd.conf.5.xml:1501 msgid "" "none (Untrusted users are not allowed to access any domains PAM in " "responder.)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1538 sssd.conf.5.xml:1563 sssd.conf.5.xml:1582 -#: sssd.conf.5.xml:1824 sssd.conf.5.xml:3842 sssd-ldap.5.xml:1270 +#: sssd.conf.5.xml:1505 sssd.conf.5.xml:1530 sssd.conf.5.xml:1549 +#: sssd.conf.5.xml:1821 sssd.conf.5.xml:4048 sssd-ldap.5.xml:1270 msgid "Default: none" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1543 +#: sssd.conf.5.xml:1510 msgid "pam_account_expired_message (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1546 +#: sssd.conf.5.xml:1513 msgid "" "Allows a custom expiration message to be set, replacing the default " "'Permission denied' message." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1551 +#: sssd.conf.5.xml:1518 msgid "" "Note: Please be aware that message is only printed for the SSH service " "unless pam_verbosity is set to 3 (show all messages and debug information)." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1559 +#: sssd.conf.5.xml:1526 #, no-wrap msgid "" "pam_account_expired_message = Account expired, please contact help desk.\n" @@ -1917,19 +1855,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1568 +#: sssd.conf.5.xml:1535 msgid "pam_account_locked_message (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1571 +#: sssd.conf.5.xml:1538 msgid "" "Allows a custom lockout message to be set, replacing the default 'Permission " "denied' message." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1578 +#: sssd.conf.5.xml:1545 #, no-wrap msgid "" "pam_account_locked_message = Account locked, please contact help desk.\n" @@ -1937,81 +1875,120 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1587 -msgid "pam_passkey_auth (bool)" +#: sssd.conf.5.xml:1554 +msgid "pam_passkey_auth (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1590 +#: sssd.conf.5.xml:1557 msgid "Enable passkey device based authentication." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1593 sssd.conf.5.xml:1910 sssd-ad.5.xml:1286 +#: sssd.conf.5.xml:1560 sssd.conf.5.xml:1907 sssd-ad.5.xml:1279 #: sss_rpcidmapd.5.xml:76 msgid "Default: True" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1598 -msgid "passkey_debug_libfido2 (bool)" +#: sssd.conf.5.xml:1565 +msgid "passkey_debug_libfido2 (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1601 +#: sssd.conf.5.xml:1568 msgid "Enable libfido2 library debug messages." msgstr "" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1604 sssd.conf.5.xml:1618 sssd-ldap.5.xml:727 -#: sssd-ldap.5.xml:752 sssd-ldap.5.xml:848 sssd-ldap.5.xml:1356 -#: sssd-ad.5.xml:506 sssd-ad.5.xml:582 sssd-ad.5.xml:1155 +#: sssd.conf.5.xml:1571 sssd.conf.5.xml:1585 sssd.conf.5.xml:4781 +#: sssd-ldap.5.xml:727 sssd-ldap.5.xml:752 sssd-ldap.5.xml:848 +#: sssd-ldap.5.xml:1356 sssd-ad.5.xml:506 sssd-ad.5.xml:582 sssd-ad.5.xml:1160 #: include/ldap_id_mapping.xml:250 msgid "Default: False" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1609 -msgid "pam_cert_auth (bool)" +#: sssd.conf.5.xml:1576 +msgid "pam_cert_auth (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1612 +#: sssd.conf.5.xml:1579 msgid "" "Enable certificate based Smartcard authentication. Since this requires " "additional communication with the Smartcard which will delay the " "authentication process this option is disabled by default." msgstr "" +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1588 +msgid "" +"Note: In case OpenSC is used for Smartcard access SSSD supports the " +"filesystem caching in OpenSC when enabled in opensc.conf. The cached files " +"are located in a common <quote>opensc</quote> directory in SSSD's state " +"directory. The behaviour can be changed in opensc.conf" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> +#: sssd.conf.5.xml:1597 +#, no-wrap +msgid "" +"app /usr/libexec/sssd/p11_child {\n" +" framework pkcs15 {\n" +" use_file_caching = no;\n" +" }\n" +"}\n" +"app /usr/libexec/sssd/krb5_child {\n" +" framework pkcs15 {\n" +" use_file_caching = no;\n" +" }\n" +"}\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1595 +msgid "" +"Example opensc.conf (*): <placeholder type=\"programlisting\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1610 +msgid "" +"(*) The actual <quote>libexec</quote> directory for p11_child and krb5_child " +"depends on the distribution." +msgstr "" + #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1623 +#: sssd.conf.5.xml:1615 msgid "pam_cert_db_path (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1626 +#: sssd.conf.5.xml:1618 msgid "The path to the certificate database." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1629 sssd.conf.5.xml:2163 sssd.conf.5.xml:4338 +#: sssd.conf.5.xml:1621 sssd.conf.5.xml:2199 sssd.conf.5.xml:4543 msgid "Default:" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1631 sssd.conf.5.xml:2165 +#: sssd.conf.5.xml:1623 sssd.conf.5.xml:2201 msgid "" "/etc/sssd/pki/sssd_auth_ca_db.pem (path to a file with trusted CA " "certificates in PEM format)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1641 +#: sssd.conf.5.xml:1633 msgid "pam_cert_verification (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1644 +#: sssd.conf.5.xml:1636 msgid "" "With this parameter the PAM certificate verification can be tuned with a " "comma separated list of options that override the " @@ -2021,7 +1998,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1655 +#: sssd.conf.5.xml:1647 #, no-wrap msgid "" "pam_cert_verification = partial_chain\n" @@ -2029,59 +2006,59 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1659 +#: sssd.conf.5.xml:1651 msgid "" "Default: not set, i.e. use default <quote>certificate_verification</quote> " "option defined in <quote>[sssd]</quote> section." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1666 +#: sssd.conf.5.xml:1658 msgid "p11_child_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1669 +#: sssd.conf.5.xml:1661 msgid "How many seconds will pam_sss wait for p11_child to finish." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1678 +#: sssd.conf.5.xml:1670 msgid "passkey_child_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1681 +#: sssd.conf.5.xml:1673 msgid "" "How many seconds will the PAM responder wait for passkey_child to finish." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1690 +#: sssd.conf.5.xml:1682 msgid "pam_app_services (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1693 +#: sssd.conf.5.xml:1685 msgid "" "Which PAM services are permitted to contact domains of type " "<quote>application</quote>" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1702 +#: sssd.conf.5.xml:1694 msgid "pam_p11_allowed_services (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1705 +#: sssd.conf.5.xml:1697 msgid "" "A comma-separated list of PAM service names for which it will be allowed to " "use Smartcards." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1720 +#: sssd.conf.5.xml:1712 #, no-wrap msgid "" "pam_p11_allowed_services = +my_pam_service, -login\n" @@ -2089,7 +2066,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1709 +#: sssd.conf.5.xml:1701 msgid "" "It is possible to add another PAM service name to the default set by using " "<quote>+service_name</quote> or to explicitly remove a PAM service name from " @@ -2101,68 +2078,73 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1724 sssd-ad.5.xml:645 sssd-ad.5.xml:754 sssd-ad.5.xml:812 -#: sssd-ad.5.xml:870 sssd-ad.5.xml:948 +#: sssd.conf.5.xml:1716 sssd-ad.5.xml:645 sssd-ad.5.xml:759 sssd-ad.5.xml:817 +#: sssd-ad.5.xml:875 sssd-ad.5.xml:953 msgid "Default: the default set of PAM service names includes:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1729 sssd-ad.5.xml:649 +#: sssd.conf.5.xml:1721 sssd-ad.5.xml:649 msgid "login" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1734 sssd-ad.5.xml:654 +#: sssd.conf.5.xml:1726 sssd-ad.5.xml:654 msgid "su" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1739 sssd-ad.5.xml:659 +#: sssd.conf.5.xml:1731 sssd-ad.5.xml:659 msgid "su-l" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1744 sssd-ad.5.xml:674 +#: sssd.conf.5.xml:1736 sssd-ad.5.xml:674 msgid "gdm-smartcard" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1749 sssd-ad.5.xml:669 +#: sssd.conf.5.xml:1741 sssd-ad.5.xml:669 msgid "gdm-password" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1754 +#: sssd.conf.5.xml:1746 msgid "gdm-switchable-auth" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1759 sssd-ad.5.xml:679 +#: sssd.conf.5.xml:1751 sssd-ad.5.xml:679 msgid "kdm" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1764 sssd-ad.5.xml:957 +#: sssd.conf.5.xml:1756 sssd-ad.5.xml:694 +msgid "plasmalogin" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:1761 sssd-ad.5.xml:962 msgid "sudo" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1769 sssd-ad.5.xml:962 +#: sssd.conf.5.xml:1766 sssd-ad.5.xml:967 msgid "sudo-i" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1774 +#: sssd.conf.5.xml:1771 msgid "gnome-screensaver" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1782 +#: sssd.conf.5.xml:1779 msgid "p11_wait_for_card_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1785 +#: sssd.conf.5.xml:1782 msgid "" "If Smartcard authentication is required how many extra seconds in addition " "to p11_child_timeout should the PAM responder wait until a Smartcard is " @@ -2170,12 +2152,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1796 +#: sssd.conf.5.xml:1793 msgid "p11_uri (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1799 +#: sssd.conf.5.xml:1796 msgid "" "PKCS#11 URI (see RFC-7512 for details) which can be used to restrict the " "selection of devices used for Smartcard authentication. By default SSSD's " @@ -2186,7 +2168,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1812 +#: sssd.conf.5.xml:1809 #, no-wrap msgid "" "p11_uri = pkcs11:slot-description=My%20Smartcard%20Reader\n" @@ -2194,7 +2176,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1816 +#: sssd.conf.5.xml:1813 #, no-wrap msgid "" "p11_uri = pkcs11:library-description=OpenSC%20smartcard%20framework;slot-id=2\n" @@ -2202,7 +2184,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1810 +#: sssd.conf.5.xml:1807 msgid "" "Example: <placeholder type=\"programlisting\" id=\"0\"/> or <placeholder " "type=\"programlisting\" id=\"1\"/> To find suitable URI please check the " @@ -2211,47 +2193,47 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1829 -msgid "pam_initgroups_scheme" +#: sssd.conf.5.xml:1826 +msgid "pam_initgroups_scheme (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1837 +#: sssd.conf.5.xml:1834 msgid "always" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1838 +#: sssd.conf.5.xml:1835 msgid "" "Always do an online lookup, please note that pam_id_timeout still applies" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1842 +#: sssd.conf.5.xml:1839 msgid "no_session" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1843 +#: sssd.conf.5.xml:1840 msgid "" "Only do an online lookup if there is no active session of the user, i.e. if " "the user is currently not logged in" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1848 sssd-ldap.5.xml:189 +#: sssd.conf.5.xml:1845 sssd-ldap.5.xml:189 msgid "never" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1849 +#: sssd.conf.5.xml:1846 msgid "" "Never force an online lookup, use the data from the cache as long as they " "are not expired" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1832 +#: sssd.conf.5.xml:1829 msgid "" "The PAM responder can force an online lookup to get the current group " "memberships of the user trying to log in. This option controls when this " @@ -2260,30 +2242,30 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1856 +#: sssd.conf.5.xml:1853 msgid "Default: no_session" msgstr "" -#. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:1861 sssd.conf.5.xml:4277 -msgid "pam_gssapi_services" +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1858 +msgid "pam_gssapi_services (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1864 +#: sssd.conf.5.xml:1861 msgid "" "Comma separated list of PAM services that are allowed to try GSSAPI " "authentication using pam_sss_gss.so module." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1869 +#: sssd.conf.5.xml:1866 msgid "" "To disable GSSAPI authentication, set this option to <quote>-</quote> (dash)." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1873 sssd.conf.5.xml:1904 sssd.conf.5.xml:1942 +#: sssd.conf.5.xml:1870 sssd.conf.5.xml:1901 sssd.conf.5.xml:1939 msgid "" "Note: This option can also be set per-domain which overwrites the value in " "[pam] section. It can also be set for trusted domain which overwrites the " @@ -2291,7 +2273,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1881 +#: sssd.conf.5.xml:1878 #, no-wrap msgid "" "pam_gssapi_services = sudo, sudo-i\n" @@ -2299,22 +2281,22 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1879 sssd.conf.5.xml:1994 sssd.conf.5.xml:3836 +#: sssd.conf.5.xml:1876 sssd.conf.5.xml:2023 sssd.conf.5.xml:4042 msgid "Example: <placeholder type=\"programlisting\" id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1885 +#: sssd.conf.5.xml:1882 msgid "Default: - (GSSAPI authentication is disabled)" msgstr "" -#. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:1890 sssd.conf.5.xml:4278 -msgid "pam_gssapi_check_upn" +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1887 +msgid "pam_gssapi_check_upn (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1893 +#: sssd.conf.5.xml:1890 msgid "" "If True, SSSD will require that the Kerberos user principal that " "successfully authenticated through GSSAPI can be associated with the user " @@ -2322,19 +2304,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1900 +#: sssd.conf.5.xml:1897 msgid "" -"If False, every user that is able to obtained required service ticket will " +"If False, every user that is able to obtain a required service ticket will " "be authenticated." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1915 -msgid "pam_gssapi_indicators_map" +#: sssd.conf.5.xml:1912 +msgid "pam_gssapi_indicators_map (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1918 +#: sssd.conf.5.xml:1915 msgid "" "Comma separated list of authentication indicators required to be present in " "a Kerberos ticket to access a PAM service that is allowed to try GSSAPI " @@ -2342,7 +2324,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1924 +#: sssd.conf.5.xml:1921 msgid "" "Each element of the list can be either an authentication indicator name or a " "pair <quote>service:indicator</quote>. Indicators not prefixed with the PAM " @@ -2357,7 +2339,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1937 +#: sssd.conf.5.xml:1934 msgid "" "To disable GSSAPI authentication indicator check, set this option to <quote>-" "</quote> (dash). To disable the check for a specific PAM service, add " @@ -2365,83 +2347,122 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1948 +#: sssd.conf.5.xml:1945 msgid "" "Following authentication indicators are supported by IPA Kerberos " "deployments:" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1951 +#: sssd.conf.5.xml:1948 msgid "" "pkinit -- pre-authentication using X.509 certificates -- whether stored in " "files or on smart cards." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1954 +#: sssd.conf.5.xml:1951 msgid "" "hardened -- SPAKE pre-authentication or any pre-authentication wrapped in a " "FAST channel." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1957 +#: sssd.conf.5.xml:1954 msgid "radius -- pre-authentication with the help of a RADIUS server." msgstr "" -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1960 +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:1957 +msgid "" +"otp -- pre-authentication using integrated two-factor authentication (2FA or " +"one-time password, OTP) in IPA." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:1960 +msgid "idp -- pre-authentication using external identity provider." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> +#: sssd.conf.5.xml:1970 +#, no-wrap +msgid "" +"pam_gssapi_indicators_map = sudo:pkinit, sudo-i:pkinit\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1965 +msgid "" +"Example: to require access to SUDO services only for users which obtained " +"their Kerberos tickets with a X.509 certificate pre-authentication (PKINIT), " +"set <placeholder type=\"programlisting\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1974 +msgid "Default: not set (use of authentication indicators is not required)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1979 +msgid "pam_gssapi_indicators_apply (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1982 msgid "" -"otp -- pre-authentication using integrated two-factor authentication (2FA or " -"one-time password, OTP) in IPA." +"Comma separated list of triples to assign additional information from the " +"Kerberos ticket, e.g. a SID from the PAC, to authentication indicators." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1988 +msgid "Currently supported is:" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1963 -msgid "idp -- pre-authentication using external identity provider." +#: sssd.conf.5.xml:1991 +msgid "SID:S-1-5-[domain]-[RID]:[authentication indicator]" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1973 +#: sssd.conf.5.xml:2002 #, no-wrap msgid "" -"pam_gssapi_indicators_map = sudo:pkinit, sudo-i:pkinit\n" +"pam_gssapi_indicators_apply = SID:S-1-5-12345-23456-34567-4321:pkinit\n" " " msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1968 +#: sssd.conf.5.xml:1996 msgid "" -"Example: to require access to SUDO services only for users which obtained " -"their Kerberos tickets with a X.509 certificate pre-authentication (PKINIT), " -"set <placeholder type=\"programlisting\" id=\"0\"/>" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1977 -msgid "Default: not set (use of authentication indicators is not required)" +"Example: To assign a SID, which is e.g. set by Active Directory's " +"Authentication Mechanism Assurance (AMA) if the AD user used a Smartcard for " +"authentication, to the 'pkinit' authentication indicator use: <placeholder " +"type=\"programlisting\" id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1982 +#: sssd.conf.5.xml:2011 msgid "pam_json_services (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1985 +#: sssd.conf.5.xml:2014 msgid "" "Comma separated list of PAM services which can handle the JSON protocol for " "selecting authentication mechanisms" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1990 +#: sssd.conf.5.xml:2019 msgid "To disable JSON protocol, set this option to <quote>-</quote> (dash)." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1996 +#: sssd.conf.5.xml:2025 #, no-wrap msgid "" "pam_json_services = gdm-switchable-auth\n" @@ -2449,52 +2470,59 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2000 +#: sssd.conf.5.xml:2029 msgid "Default: - (JSON protocol is disabled)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2003 +#: sssd.conf.5.xml:2032 msgid "" "Note: 2-Factor Authentication (2FA) is not supported. If 2FA is required, do " "not activate the JSON protocol." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:2013 +#: sssd.conf.5.xml:2042 msgid "SUDO configuration options" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2015 +#: sssd.conf.5.xml:2044 msgid "" -"These options can be used to configure the sudo service. The detailed " -"instructions for configuration of <citerefentry> <refentrytitle>sudo</" -"refentrytitle> <manvolnum>8</manvolnum> </citerefentry> to work with " -"<citerefentry> <refentrytitle>sssd</refentrytitle> <manvolnum>8</manvolnum> " -"</citerefentry> are in the manual page <citerefentry> <refentrytitle>sssd-" -"sudo</refentrytitle> <manvolnum>5</manvolnum> </citerefentry>." +"These options can be used to configure the sudo service and should be " +"specified under the <quote>[sudo]</quote> section." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:2048 +msgid "" +"The detailed instructions for configuration of <citerefentry> " +"<refentrytitle>sudo</refentrytitle> <manvolnum>8</manvolnum> </citerefentry> " +"to work with <citerefentry> <refentrytitle>sssd</refentrytitle> " +"<manvolnum>8</manvolnum> </citerefentry> are in the manual page " +"<citerefentry> <refentrytitle>sssd-sudo</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry>." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2032 -msgid "sudo_timed (bool)" +#: sssd.conf.5.xml:2064 +msgid "sudo_timed (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2035 +#: sssd.conf.5.xml:2067 msgid "" "Whether or not to evaluate the sudoNotBefore and sudoNotAfter attributes " "that implement time-dependent sudoers entries." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2047 +#: sssd.conf.5.xml:2079 msgid "sudo_threshold (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2050 +#: sssd.conf.5.xml:2082 msgid "" "Maximum number of expired rules that can be refreshed at once. If number of " "expired rules is below threshold, those rules are refreshed with " @@ -2504,22 +2532,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:2069 +#: sssd.conf.5.xml:2101 msgid "AUTOFS configuration options" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2071 -msgid "These options can be used to configure the autofs service." +#: sssd.conf.5.xml:2103 +msgid "" +"These options can be used to configure the autofs service and should be " +"specified under the <quote>[autofs]</quote> section." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2075 +#: sssd.conf.5.xml:2109 msgid "autofs_negative_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2078 +#: sssd.conf.5.xml:2112 msgid "" "Specifies for how many seconds should the autofs responder negative cache " "hits (that is, queries for invalid map entries, like nonexistent ones) " @@ -2527,22 +2557,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:2094 +#: sssd.conf.5.xml:2128 msgid "SSH configuration options" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2096 -msgid "These options can be used to configure the SSH service." +#: sssd.conf.5.xml:2130 +msgid "" +"These options can be used to configure the SSH service and should be " +"specified under the <quote>[ssh]</quote> section." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2100 -msgid "ssh_use_certificate_keys (bool)" +#: sssd.conf.5.xml:2136 +msgid "ssh_use_certificate_keys (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2103 +#: sssd.conf.5.xml:2139 msgid "" "If set to true the <command>sss_ssh_authorizedkeys</command> will return ssh " "keys derived from the public key of X.509 certificates stored in the user " @@ -2551,12 +2583,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2118 +#: sssd.conf.5.xml:2154 msgid "ssh_use_certificate_matching_rules (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2121 +#: sssd.conf.5.xml:2157 msgid "" "By default the ssh responder will use all available certificate matching " "rules to filter the certificates so that ssh keys are only derived from the " @@ -2566,7 +2598,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2130 +#: sssd.conf.5.xml:2166 msgid "" "There are two special key words 'all_rules' and 'no_rules' which will enable " "all or no rules, respectively. The latter means that no certificates will be " @@ -2574,7 +2606,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2137 +#: sssd.conf.5.xml:2173 msgid "" "If no rules are configured using 'all_rules' will enable a default rule " "which enables all certificates suitable for client authentication. This is " @@ -2583,38 +2615,38 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2144 +#: sssd.conf.5.xml:2180 msgid "" "A non-existing rule name is considered an error. If as a result no rule is " "selected all certificates will be ignored." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2149 +#: sssd.conf.5.xml:2185 msgid "" "Default: not set, equivalent to 'all_rules', all found rules or the default " "rule are used" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2155 +#: sssd.conf.5.xml:2191 msgid "ca_db (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2158 +#: sssd.conf.5.xml:2194 msgid "" "Path to a storage of trusted CA certificates. The option is used to validate " "user certificates before deriving public ssh keys from them." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:2178 +#: sssd.conf.5.xml:2214 msgid "PAC responder configuration options" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2180 +#: sssd.conf.5.xml:2216 msgid "" "The PAC responder works together with the authorization data plugin for MIT " "Kerberos sssd_pac_plugin.so and a sub-domain provider. The plugin sends the " @@ -2625,7 +2657,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:2189 +#: sssd.conf.5.xml:2225 msgid "" "If the remote user does not exist in the cache, it is created. The UID is " "determined with the help of the SID, trusted domains will have UPGs and the " @@ -2636,24 +2668,26 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:2197 +#: sssd.conf.5.xml:2233 msgid "" "If there are SIDs of groups from domains sssd knows about, the user will be " "added to those groups." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2203 -msgid "These options can be used to configure the PAC responder." +#: sssd.conf.5.xml:2239 +msgid "" +"These options can be used to configure the PAC responder and should be " +"specified under the <quote>[pac]</quote> section." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2207 sssd-ifp.5.xml:66 +#: sssd.conf.5.xml:2244 sssd-ifp.5.xml:66 msgid "allowed_uids (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2210 +#: sssd.conf.5.xml:2247 msgid "" "Specifies the comma-separated list of UID values or user names that are " "allowed to access the PAC responder. User names are resolved to UIDs at " @@ -2661,19 +2695,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2216 +#: sssd.conf.5.xml:2253 msgid "" "Default: 0, &sssd_user_name; (only root and SSSD service users are allowed " "to access the PAC responder)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2220 +#: sssd.conf.5.xml:2257 msgid "Default: 0 (only the root user is allowed to access the PAC responder)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2224 +#: sssd.conf.5.xml:2261 msgid "" "Please note that defaults will be overwritten with this option. If you still " "want to allow the root and/or '&sssd_user_name;' user to access the PAC " @@ -2682,7 +2716,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2231 +#: sssd.conf.5.xml:2268 msgid "" "Please note that although the UID 0 is used as the default it will be " "overwritten with this option. If you still want to allow the root user to " @@ -2691,24 +2725,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2240 +#: sssd.conf.5.xml:2277 msgid "pac_lifetime (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2243 +#: sssd.conf.5.xml:2280 msgid "" "Lifetime of the PAC entry in seconds. As long as the PAC is valid the PAC " "data can be used to determine the group memberships of a user." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2253 +#: sssd.conf.5.xml:2290 msgid "pac_check (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2256 +#: sssd.conf.5.xml:2293 msgid "" "Apply additional checks on the PAC of the Kerberos ticket which is available " "in Active Directory and FreeIPA domains, if configured. Please note that " @@ -2719,7 +2753,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2266 +#: sssd.conf.5.xml:2303 msgid "" "Please note that the checks listed below only apply to PACs issued by Active " "Directory or recent versions of FreeIPA. PACs issued e.g. by a plain MIT " @@ -2727,24 +2761,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2277 +#: sssd.conf.5.xml:2314 msgid "no_check" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2279 +#: sssd.conf.5.xml:2316 msgid "" "The PAC must not be present and even if it is present no additional checks " "will be done." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2285 +#: sssd.conf.5.xml:2322 msgid "pac_present" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2287 +#: sssd.conf.5.xml:2324 msgid "" "The PAC must be present in the service ticket which SSSD will request with " "the help of the user's TGT. If the PAC is not available the authentication " @@ -2752,24 +2786,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2295 +#: sssd.conf.5.xml:2332 msgid "check_upn" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2297 +#: sssd.conf.5.xml:2334 msgid "" "If the PAC is present check if the user principal name (UPN) information is " "consistent." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2303 +#: sssd.conf.5.xml:2340 msgid "check_upn_allow_missing" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2305 +#: sssd.conf.5.xml:2342 msgid "" "This option should be used together with 'check_upn' and handles the case " "where a UPN is set on the server-side but is not read by SSSD. The typical " @@ -2781,7 +2815,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2317 +#: sssd.conf.5.xml:2354 msgid "" "Currently this option is set by default to avoid regressions in such " "environments. A log message will be added to the system log and SSSD's debug " @@ -2792,60 +2826,60 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2331 +#: sssd.conf.5.xml:2368 msgid "upn_dns_info_present" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2333 +#: sssd.conf.5.xml:2370 msgid "The PAC must contain the UPN-DNS-INFO buffer, implies 'check_upn'." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2338 +#: sssd.conf.5.xml:2375 msgid "check_upn_dns_info_ex" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2340 +#: sssd.conf.5.xml:2377 msgid "" "If the PAC is present and the extension to the UPN-DNS-INFO buffer is " "available check if the information in the extension is consistent." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2347 +#: sssd.conf.5.xml:2384 msgid "upn_dns_info_ex_present" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2349 +#: sssd.conf.5.xml:2386 msgid "" "The PAC must contain the extension of the UPN-DNS-INFO buffer, implies " "'check_upn_dns_info_ex', 'upn_dns_info_present' and 'check_upn'." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2273 +#: sssd.conf.5.xml:2310 msgid "" "The following options can be used alone or in a comma-separated list: " "<placeholder type=\"variablelist\" id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2359 +#: sssd.conf.5.xml:2396 msgid "" "Default: no_check (AD and IPA provider 'check_upn, check_upn_allow_missing, " "check_upn_dns_info_ex')" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:2368 +#: sssd.conf.5.xml:2405 msgid "Session recording configuration options" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2370 +#: sssd.conf.5.xml:2407 msgid "" "Session recording works in conjunction with <citerefentry> " "<refentrytitle>tlog-rec-session</refentrytitle> <manvolnum>8</manvolnum> </" @@ -2855,66 +2889,78 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2383 -msgid "These options can be used to configure session recording." +#: sssd.conf.5.xml:2420 +msgid "" +"These options can be used to configure session recording and should be " +"specified under the <quote>[session_recording]</quote> section." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:2425 +msgid "" +"Note: Unlike other sections, the <quote>[session_recording]</quote> section " +"ignores <replaceable>debug*</replaceable> options and suitable " +"<replaceable>debug*</replaceable> options must be set in <quote>[pam]</" +"quote>, <quote>[nss]</quote> and <quote>[domain/<replaceable>NAME</" +"replaceable>]</quote> sections." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2387 sssd-session-recording.5.xml:64 +#: sssd.conf.5.xml:2433 sssd-session-recording.5.xml:64 msgid "scope (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2394 sssd-session-recording.5.xml:71 +#: sssd.conf.5.xml:2440 sssd-session-recording.5.xml:71 msgid "\"none\"" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2397 sssd-session-recording.5.xml:74 +#: sssd.conf.5.xml:2443 sssd-session-recording.5.xml:74 msgid "No users are recorded." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2402 sssd-session-recording.5.xml:79 +#: sssd.conf.5.xml:2448 sssd-session-recording.5.xml:79 msgid "\"some\"" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2405 sssd-session-recording.5.xml:82 +#: sssd.conf.5.xml:2451 sssd-session-recording.5.xml:82 msgid "" "Users/groups specified by <replaceable>users</replaceable> and " "<replaceable>groups</replaceable> options are recorded." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2414 sssd-session-recording.5.xml:91 +#: sssd.conf.5.xml:2460 sssd-session-recording.5.xml:91 msgid "\"all\"" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2417 sssd-session-recording.5.xml:94 +#: sssd.conf.5.xml:2463 sssd-session-recording.5.xml:94 msgid "All users are recorded." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2390 sssd-session-recording.5.xml:67 +#: sssd.conf.5.xml:2436 sssd-session-recording.5.xml:67 msgid "" "One of the following strings specifying the scope of session recording: " "<placeholder type=\"variablelist\" id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2424 sssd-session-recording.5.xml:101 +#: sssd.conf.5.xml:2470 sssd-session-recording.5.xml:101 msgid "Default: \"none\"" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2429 sssd-session-recording.5.xml:106 +#: sssd.conf.5.xml:2475 sssd-session-recording.5.xml:106 msgid "users (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2432 sssd-session-recording.5.xml:109 +#: sssd.conf.5.xml:2478 sssd-session-recording.5.xml:109 msgid "" "A comma-separated list of users which should have session recording enabled. " "Matches user names as returned by NSS. I.e. after the possible space " @@ -2922,17 +2968,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2438 sssd-session-recording.5.xml:115 +#: sssd.conf.5.xml:2484 sssd-session-recording.5.xml:115 msgid "Default: Empty. Matches no users." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2443 sssd-session-recording.5.xml:120 +#: sssd.conf.5.xml:2489 sssd-session-recording.5.xml:120 msgid "groups (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2446 sssd-session-recording.5.xml:123 +#: sssd.conf.5.xml:2492 sssd-session-recording.5.xml:123 msgid "" "A comma-separated list of groups, members of which should have session " "recording enabled. Matches group names as returned by NSS. I.e. after the " @@ -2940,7 +2986,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2452 sssd.conf.5.xml:2484 sssd-session-recording.5.xml:129 +#: sssd.conf.5.xml:2498 sssd.conf.5.xml:2530 sssd-session-recording.5.xml:129 #: sssd-session-recording.5.xml:161 msgid "" "NOTE: using this option (having it set to anything) has a considerable " @@ -2949,57 +2995,56 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2459 sssd-session-recording.5.xml:136 +#: sssd.conf.5.xml:2505 sssd-session-recording.5.xml:136 msgid "Default: Empty. Matches no groups." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2464 sssd-session-recording.5.xml:141 +#: sssd.conf.5.xml:2510 sssd-session-recording.5.xml:141 msgid "exclude_users (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2467 sssd-session-recording.5.xml:144 +#: sssd.conf.5.xml:2513 sssd-session-recording.5.xml:144 msgid "" "A comma-separated list of users to be excluded from recording, only " "applicable with 'scope=all'." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2471 sssd-session-recording.5.xml:148 +#: sssd.conf.5.xml:2517 sssd-session-recording.5.xml:148 msgid "Default: Empty. No users excluded." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2476 sssd-session-recording.5.xml:153 +#: sssd.conf.5.xml:2522 sssd-session-recording.5.xml:153 msgid "exclude_groups (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2479 sssd-session-recording.5.xml:156 +#: sssd.conf.5.xml:2525 sssd-session-recording.5.xml:156 msgid "" "A comma-separated list of groups, members of which should be excluded from " "recording. Only applicable with 'scope=all'." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2491 sssd-session-recording.5.xml:168 +#: sssd.conf.5.xml:2537 sssd-session-recording.5.xml:168 msgid "Default: Empty. No groups excluded." msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:2501 +#: sssd.conf.5.xml:2547 msgid "DOMAIN SECTIONS" msgstr "" -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry><para> -#: sssd.conf.5.xml:2508 sssd.conf.5.xml:3964 sssd.conf.5.xml:3965 -#: sssd.conf.5.xml:3968 -msgid "enabled" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2554 +msgid "enabled (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2511 +#: sssd.conf.5.xml:2557 msgid "" "Explicitly enable or disable the domain. If <quote>true</quote>, the domain " "is always <quote>enabled</quote>. If <quote>false</quote>, the domain is " @@ -3009,12 +3054,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2523 +#: sssd.conf.5.xml:2569 msgid "domain_type (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2526 +#: sssd.conf.5.xml:2572 msgid "" "Specifies whether the domain is meant to be used by POSIX-aware clients such " "as the Name Service Switch or by applications that do not need POSIX data to " @@ -3023,14 +3068,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2534 +#: sssd.conf.5.xml:2580 msgid "" "Allowed values for this option are <quote>posix</quote> and " "<quote>application</quote>." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2538 +#: sssd.conf.5.xml:2584 msgid "" "POSIX domains are reachable by all services. Application domains are only " "reachable from the InfoPipe responder (see <citerefentry> " @@ -3039,38 +3084,38 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2546 +#: sssd.conf.5.xml:2592 msgid "" "NOTE: The application domains are currently well tested with " "<quote>id_provider=ldap</quote> only." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2550 +#: sssd.conf.5.xml:2596 msgid "" "For an easy way to configure a non-POSIX domains, please see the " "<quote>Application domains</quote> section." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2554 +#: sssd.conf.5.xml:2600 msgid "Default: posix" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2560 +#: sssd.conf.5.xml:2606 msgid "min_id,max_id (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2563 +#: sssd.conf.5.xml:2609 msgid "" "UID and GID limits for the domain. If a domain contains an entry that is " "outside these limits, it is ignored." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2568 +#: sssd.conf.5.xml:2614 msgid "" "For users, this affects the primary GID limit. The user will not be returned " "to NSS if either the UID or the primary GID is outside the range. For non-" @@ -3079,24 +3124,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2575 +#: sssd.conf.5.xml:2621 msgid "" "These ID limits affect even saving entries to cache, not only returning them " "by name or ID." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2579 +#: sssd.conf.5.xml:2625 msgid "Default: 1 for min_id, 0 (no limit) for max_id" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2585 -msgid "enumerate (bool)" +#: sssd.conf.5.xml:2631 +msgid "enumerate (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2588 +#: sssd.conf.5.xml:2634 msgid "" "Determines if a domain can be enumerated, that is, whether the domain can " "list all the users and group it contains. Note that it is not required to " @@ -3105,36 +3150,36 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2596 +#: sssd.conf.5.xml:2642 msgid "TRUE = Users and groups are enumerated" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2599 +#: sssd.conf.5.xml:2645 msgid "FALSE = No enumerations for this domain" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2602 sssd.conf.5.xml:2867 sssd.conf.5.xml:3044 +#: sssd.conf.5.xml:2648 sssd.conf.5.xml:2992 sssd.conf.5.xml:3174 msgid "Default: FALSE" msgstr "Пешфарз: FALSE" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2605 +#: sssd.conf.5.xml:2651 msgid "" "Enumerating a domain requires SSSD to download and store ALL user and group " "entries from the remote server." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2610 +#: sssd.conf.5.xml:2656 msgid "" "Feature is only supported for domains with id_provider = ldap or id_provider " "= proxy." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2614 +#: sssd.conf.5.xml:2660 msgid "" "Note: Enabling enumeration has a severe performance impact on SSSD while " "enumeration is running. It may take up to several minutes after SSSD startup " @@ -3148,14 +3193,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2629 +#: sssd.conf.5.xml:2675 msgid "" "While the first enumeration is running, requests for the complete user or " "group lists may return no results until it completes." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2634 +#: sssd.conf.5.xml:2680 msgid "" "Further, enabling enumeration may increase the time necessary to detect " "network disconnection, as longer timeouts are required to ensure that " @@ -3164,14 +3209,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2642 +#: sssd.conf.5.xml:2688 msgid "" "For the reasons cited above, enabling enumeration is not recommended, " "especially in large environments." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2647 +#: sssd.conf.5.xml:2693 msgid "" "Note: the proxy provider is tested with open source modules like " "'libnss_files' and 'libnss_ldap'. 3rd party modules must follow the " @@ -3179,19 +3224,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2656 +#: sssd.conf.5.xml:2702 msgid "entry_cache_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2659 +#: sssd.conf.5.xml:2705 msgid "" "How many seconds should nss_sss consider entries valid before asking the " "backend again" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2663 +#: sssd.conf.5.xml:2709 msgid "" "The cache expiration timestamps are stored as attributes of individual " "objects in the cache. Therefore, changing the cache timeout only has effect " @@ -3202,139 +3247,248 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2676 +#: sssd.conf.5.xml:2722 msgid "Default: 5400" msgstr "Пешфарз: 5400" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2682 +#: sssd.conf.5.xml:2728 msgid "entry_cache_user_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2685 +#: sssd.conf.5.xml:2731 msgid "" "How many seconds should nss_sss consider user entries valid before asking " "the backend again" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2689 sssd.conf.5.xml:2702 sssd.conf.5.xml:2715 -#: sssd.conf.5.xml:2728 sssd.conf.5.xml:2742 sssd.conf.5.xml:2755 -#: sssd.conf.5.xml:2769 sssd.conf.5.xml:2783 sssd.conf.5.xml:2796 +#: sssd.conf.5.xml:2735 sssd.conf.5.xml:2748 sssd.conf.5.xml:2761 +#: sssd.conf.5.xml:2774 sssd.conf.5.xml:2788 sssd.conf.5.xml:2801 +#: sssd.conf.5.xml:2815 sssd.conf.5.xml:2829 msgid "Default: entry_cache_timeout" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2695 +#: sssd.conf.5.xml:2741 msgid "entry_cache_group_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2698 +#: sssd.conf.5.xml:2744 msgid "" "How many seconds should nss_sss consider group entries valid before asking " "the backend again" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2708 +#: sssd.conf.5.xml:2754 msgid "entry_cache_netgroup_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2711 +#: sssd.conf.5.xml:2757 msgid "" "How many seconds should nss_sss consider netgroup entries valid before " "asking the backend again" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2721 +#: sssd.conf.5.xml:2767 msgid "entry_cache_service_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2724 +#: sssd.conf.5.xml:2770 msgid "" "How many seconds should nss_sss consider service entries valid before asking " "the backend again" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2734 +#: sssd.conf.5.xml:2780 msgid "entry_cache_resolver_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2737 +#: sssd.conf.5.xml:2783 msgid "" "How many seconds should nss_sss consider hosts and networks entries valid " "before asking the backend again" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2748 +#: sssd.conf.5.xml:2794 msgid "entry_cache_sudo_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2751 +#: sssd.conf.5.xml:2797 msgid "" "How many seconds should sudo consider rules valid before asking the backend " "again" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2761 +#: sssd.conf.5.xml:2807 msgid "entry_cache_autofs_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2764 +#: sssd.conf.5.xml:2810 msgid "" "How many seconds should the autofs service consider automounter maps valid " "before asking the backend again" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2775 +#: sssd.conf.5.xml:2821 msgid "entry_cache_ssh_host_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2778 +#: sssd.conf.5.xml:2824 msgid "" "How many seconds to keep a host ssh key after refresh. IE how long to cache " "the host key for." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2789 -msgid "entry_cache_computer_timeout (integer)" +#: sssd.conf.5.xml:2835 +msgid "offline_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2792 +#: sssd.conf.5.xml:2838 msgid "" -"How many seconds to keep the local computer entry before asking the backend " -"again" +"When SSSD switches to offline mode the amount of time before it tries to go " +"back online will increase based upon the time spent disconnected. By " +"default SSSD uses incremental behaviour to calculate delay in between " +"retries. So, the wait time for a given retry will be longer than the wait " +"time for the previous ones. After each unsuccessful attempt to go online, " +"the new interval is recalculated by the following:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2849 sssd.conf.5.xml:2907 +msgid "" +"new_delay = Minimum(old_delay * 2, offline_timeout_max) + " +"random[0...offline_timeout_random_offset]" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2852 +msgid "" +"The offline_timeout default value is 60. The offline_timeout_max default " +"value is 3600. The offline_timeout_random_offset default value is 30. The " +"end result is the number of seconds before next retry." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2858 +msgid "" +"Note that the maximum length of each interval is defined by " +"offline_timeout_max (apart from the random part)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2868 +msgid "offline_timeout_max (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2871 +msgid "" +"Controls by how much the time between attempts to go online can be " +"incremented following unsuccessful attempts to go online." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2876 +msgid "A value of 0 disables the incrementing behaviour." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2879 +msgid "" +"The value of this parameter should be set in correlation to offline_timeout " +"parameter value." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2883 +msgid "" +"With offline_timeout set to 60 (default value) there is no point in setting " +"offline_timeout_max to less than 120 as it will saturate instantly. General " +"rule here should be to set offline_timeout_max to at least 4 times " +"offline_timeout." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2889 +msgid "" +"Although a value between 0 and offline_timeout may be specified, it has the " +"effect of overriding the offline_timeout value so is of little use." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2894 +#, fuzzy +#| msgid "Default: 3" +msgid "Default: 3600" +msgstr "Пешфарз: 3" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2900 +msgid "offline_timeout_random_offset (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2903 +msgid "" +"When SSSD is in offline mode it keeps probing backend servers in specified " +"time intervals:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2910 +msgid "" +"This parameter controls the value of the random offset used for the above " +"equation. Final random_offset value will be random number in range:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2915 +msgid "[0 - offline_timeout_random_offset]" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2918 +msgid "A value of 0 disables the random offset addition." msgstr "" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2921 +#, fuzzy +#| msgid "Default: 3" +msgid "Default: 30" +msgstr "Пешфарз: 3" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2802 +#: sssd.conf.5.xml:2927 msgid "refresh_expired_interval (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2805 +#: sssd.conf.5.xml:2930 msgid "" "Specifies how many seconds SSSD has to wait before triggering a background " "refresh task which will refresh all expired or nearly expired records." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2810 +#: sssd.conf.5.xml:2935 msgid "" "The background refresh will process users, groups and netgroups in the " "cache. For users who have performed the initgroups (get group membership for " @@ -3343,17 +3497,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2818 +#: sssd.conf.5.xml:2943 msgid "This option is automatically inherited for all trusted domains." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2822 +#: sssd.conf.5.xml:2947 msgid "You can consider setting this value to 3/4 * entry_cache_timeout." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2826 +#: sssd.conf.5.xml:2951 msgid "" "Cache entry will be refreshed by background task when 2/3 of cache timeout " "has already passed. If there are existing cached entries, the background " @@ -3365,18 +3519,18 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2839 sssd-ldap.5.xml:406 sssd-ldap.5.xml:1834 -#: sssd-ipa.5.xml:255 +#: sssd.conf.5.xml:2964 sssd-ldap.5.xml:406 sssd-ldap.5.xml:1834 +#: sssd-ipa.5.xml:250 msgid "Default: 0 (disabled)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2845 -msgid "cache_credentials (bool)" +#: sssd.conf.5.xml:2970 +msgid "cache_credentials (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2848 +#: sssd.conf.5.xml:2973 msgid "" "Determines if user credentials are also cached in the local LDB cache. The " "cached credentials refer to passwords, which includes the first (long term) " @@ -3387,7 +3541,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2859 +#: sssd.conf.5.xml:2984 msgid "" "Take a note that while credentials are stored as a salted SHA512 hash, this " "still potentially poses some security risk in case an attacker manages to " @@ -3396,12 +3550,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2873 +#: sssd.conf.5.xml:2998 msgid "cache_credentials_minimal_first_factor_length (int)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2876 +#: sssd.conf.5.xml:3001 msgid "" "If 2-Factor-Authentication (2FA) is used and credentials should be saved " "this value determines the minimal length the first authentication factor " @@ -3409,19 +3563,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2883 +#: sssd.conf.5.xml:3008 msgid "" "This should avoid that the short PINs of a PIN based 2FA scheme are saved in " "the cache which would make them easy targets for brute-force attacks." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2894 +#: sssd.conf.5.xml:3019 msgid "account_cache_expiration (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2897 +#: sssd.conf.5.xml:3022 msgid "" "Number of days entries are left in cache after last successful login before " "being removed during a cleanup of the cache. 0 means keep forever. The " @@ -3430,17 +3584,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2904 +#: sssd.conf.5.xml:3029 msgid "Default: 0 (unlimited)" msgstr "Пешфарз: 0 (номаҳдуд)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2909 +#: sssd.conf.5.xml:3034 msgid "pwd_expiration_warning (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2920 +#: sssd.conf.5.xml:3045 msgid "" "Please note that the backend server has to provide information about the " "expiration time of the password. If this information is missing, sssd " @@ -3449,28 +3603,28 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2927 +#: sssd.conf.5.xml:3052 msgid "Default: 7 (Kerberos), 0 (LDAP)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2933 +#: sssd.conf.5.xml:3058 msgid "id_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2936 +#: sssd.conf.5.xml:3061 msgid "" "The identification provider used for the domain. Supported ID providers are:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2940 +#: sssd.conf.5.xml:3065 msgid "<quote>proxy</quote>: Support a legacy NSS provider." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2943 +#: sssd.conf.5.xml:3068 msgid "" "<quote>ldap</quote>: LDAP provider. See <citerefentry> <refentrytitle>sssd-" "ldap</refentrytitle> <manvolnum>5</manvolnum> </citerefentry> for more " @@ -3478,8 +3632,8 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2951 sssd.conf.5.xml:3070 sssd.conf.5.xml:3129 -#: sssd.conf.5.xml:3192 +#: sssd.conf.5.xml:3076 sssd.conf.5.xml:3200 sssd.conf.5.xml:3259 +#: sssd.conf.5.xml:3322 msgid "" "<quote>ipa</quote>: FreeIPA and Red Hat Identity Management provider. See " "<citerefentry> <refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</" @@ -3487,8 +3641,8 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2960 sssd.conf.5.xml:3079 sssd.conf.5.xml:3138 -#: sssd.conf.5.xml:3201 +#: sssd.conf.5.xml:3085 sssd.conf.5.xml:3209 sssd.conf.5.xml:3268 +#: sssd.conf.5.xml:3331 msgid "" "<quote>ad</quote>: Active Directory provider. See <citerefentry> " "<refentrytitle>sssd-ad</refentrytitle> <manvolnum>5</manvolnum> </" @@ -3496,27 +3650,34 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2968 +#: sssd.conf.5.xml:3093 msgid "" "<quote>idp</quote>: Provider for OAuth 2.0/OIDC based Identity Providers " "(IdP). See <citerefentry> <refentrytitle>sssd-idp</refentrytitle> " "<manvolnum>5</manvolnum> </citerefentry> for more information." msgstr "" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3101 +msgid "" +"Default: Not set (This is a mandatory setting that must be explicitly " +"defined for each configured domain)." +msgstr "" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2979 -msgid "use_fully_qualified_names (bool)" +#: sssd.conf.5.xml:3109 +msgid "use_fully_qualified_names (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2982 +#: sssd.conf.5.xml:3112 msgid "" "Use the full name and domain (as formatted by the domain's full_name_format) " "as the user's login name reported to NSS." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2987 +#: sssd.conf.5.xml:3117 msgid "" "If set to TRUE, all requests to this domain must use fully qualified names. " "For example, if used in EXAMPLE domain that contains a \"test\" user, " @@ -3525,7 +3686,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2995 +#: sssd.conf.5.xml:3125 msgid "" "NOTE: This option has no effect on netgroup lookups due to their tendency to " "include nested netgroups without qualified names. For netgroups, all domains " @@ -3533,24 +3694,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3002 +#: sssd.conf.5.xml:3132 msgid "" "Default: FALSE (TRUE for trusted domain/sub-domains or if " "default_domain_suffix is used)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3009 -msgid "ignore_group_members (bool)" +#: sssd.conf.5.xml:3139 +msgid "ignore_group_members (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3012 +#: sssd.conf.5.xml:3142 msgid "Do not return group members for group lookups." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3015 +#: sssd.conf.5.xml:3145 msgid "" "If set to TRUE, the group membership attribute is not requested from the " "ldap server, and group members are not returned when processing group lookup " @@ -3562,7 +3723,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3033 +#: sssd.conf.5.xml:3163 msgid "" "Enabling this option can also make access provider checks for group " "membership significantly faster, especially for groups containing many " @@ -3570,7 +3731,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3039 sssd.conf.5.xml:3767 sssd-ldap.5.xml:401 +#: sssd.conf.5.xml:3169 sssd.conf.5.xml:3951 sssd-ldap.5.xml:401 #: sssd-ldap.5.xml:454 sssd-ldap.5.xml:529 sssd-ldap.5.xml:576 #: sssd-ldap.5.xml:599 sssd-ldap.5.xml:638 sssd-ldap.5.xml:657 #: sssd-ldap.5.xml:681 sssd-ldap.5.xml:1114 sssd-ldap.5.xml:1147 @@ -3580,19 +3741,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3049 +#: sssd.conf.5.xml:3179 msgid "auth_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3052 +#: sssd.conf.5.xml:3182 msgid "" "The authentication provider used for the domain. Supported auth providers " "are:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3056 sssd.conf.5.xml:3122 +#: sssd.conf.5.xml:3186 sssd.conf.5.xml:3252 msgid "" "<quote>ldap</quote> for native LDAP authentication. See <citerefentry> " "<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> </" @@ -3600,7 +3761,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3063 +#: sssd.conf.5.xml:3193 msgid "" "<quote>krb5</quote> for Kerberos authentication. See <citerefentry> " "<refentrytitle>sssd-krb5</refentrytitle> <manvolnum>5</manvolnum> </" @@ -3608,7 +3769,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3087 +#: sssd.conf.5.xml:3217 msgid "" "<quote>idp</quote>: Provider for OAuth 2.0/OIDC based authentication. See " "<citerefentry> <refentrytitle>sssd-idp</refentrytitle> <manvolnum>5</" @@ -3616,30 +3777,30 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3095 +#: sssd.conf.5.xml:3225 msgid "" "<quote>proxy</quote> for relaying authentication to some other PAM target." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3098 +#: sssd.conf.5.xml:3228 msgid "<quote>none</quote> disables authentication explicitly." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3101 +#: sssd.conf.5.xml:3231 msgid "" "Default: <quote>id_provider</quote> is used if it is set and can handle " "authentication requests." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3107 +#: sssd.conf.5.xml:3237 msgid "access_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3110 +#: sssd.conf.5.xml:3240 msgid "" "The access control provider used for the domain. There are two built-in " "access providers (in addition to any included in installed backends) " @@ -3647,17 +3808,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3116 +#: sssd.conf.5.xml:3246 msgid "<quote>permit</quote> always allow access." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3119 +#: sssd.conf.5.xml:3249 msgid "<quote>deny</quote> always deny access." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3146 +#: sssd.conf.5.xml:3276 msgid "" "<quote>simple</quote> access control based on access or deny lists. See " "<citerefentry> <refentrytitle>sssd-simple</refentrytitle> <manvolnum>5</" @@ -3666,7 +3827,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3153 +#: sssd.conf.5.xml:3283 msgid "" "<quote>krb5</quote>: .k5login based access control. See <citerefentry> " "<refentrytitle>sssd-krb5</refentrytitle> <manvolnum>5</manvolnum></" @@ -3674,29 +3835,29 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3160 +#: sssd.conf.5.xml:3290 msgid "<quote>proxy</quote> for relaying access control to another PAM module." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3163 +#: sssd.conf.5.xml:3293 msgid "Default: <quote>permit</quote>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3168 +#: sssd.conf.5.xml:3298 msgid "chpass_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3171 +#: sssd.conf.5.xml:3301 msgid "" "The provider which should handle change password operations for the domain. " "Supported change password providers are:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3176 +#: sssd.conf.5.xml:3306 msgid "" "<quote>ldap</quote> to change a password stored in a LDAP server. See " "<citerefentry> <refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</" @@ -3704,7 +3865,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3184 +#: sssd.conf.5.xml:3314 msgid "" "<quote>krb5</quote> to change the Kerberos password. See <citerefentry> " "<refentrytitle>sssd-krb5</refentrytitle> <manvolnum>5</manvolnum> </" @@ -3712,35 +3873,35 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3209 +#: sssd.conf.5.xml:3339 msgid "" "<quote>proxy</quote> for relaying password changes to some other PAM target." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3213 +#: sssd.conf.5.xml:3343 msgid "<quote>none</quote> disallows password changes explicitly." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3216 +#: sssd.conf.5.xml:3346 msgid "" "Default: <quote>auth_provider</quote> is used if it is set and can handle " "change password requests." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3223 +#: sssd.conf.5.xml:3353 msgid "sudo_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3226 +#: sssd.conf.5.xml:3356 msgid "The SUDO provider used for the domain. Supported SUDO providers are:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3230 +#: sssd.conf.5.xml:3360 msgid "" "<quote>ldap</quote> for rules stored in LDAP. See <citerefentry> " "<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> </" @@ -3748,33 +3909,33 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3238 +#: sssd.conf.5.xml:3368 msgid "" "<quote>ipa</quote> the same as <quote>ldap</quote> but with IPA default " "settings." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3242 +#: sssd.conf.5.xml:3372 msgid "" "<quote>ad</quote> the same as <quote>ldap</quote> but with AD default " "settings." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3246 +#: sssd.conf.5.xml:3376 msgid "<quote>none</quote> disables SUDO explicitly." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3249 +#: sssd.conf.5.xml:3379 msgid "" "Default: The value of <quote>id_provider</quote> is used if it is set and " "can handle sudo requests." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3253 +#: sssd.conf.5.xml:3383 msgid "" "The detailed instructions for configuration of sudo_provider are in the " "manual page <citerefentry> <refentrytitle>sssd-sudo</refentrytitle> " @@ -3785,7 +3946,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3268 +#: sssd.conf.5.xml:3398 msgid "" "<emphasis>NOTE:</emphasis> Sudo rules are periodically downloaded in the " "background unless the sudo provider is explicitly disabled. Set " @@ -3794,12 +3955,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3278 +#: sssd.conf.5.xml:3408 msgid "selinux_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3281 +#: sssd.conf.5.xml:3411 msgid "" "The provider which should handle loading of selinux settings. Note that this " "provider will be called right after access provider ends. Supported selinux " @@ -3807,7 +3968,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3287 +#: sssd.conf.5.xml:3417 msgid "" "<quote>ipa</quote> to load selinux settings from an IPA server. See " "<citerefentry> <refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</" @@ -3815,31 +3976,32 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3295 +#: sssd.conf.5.xml:3425 msgid "<quote>none</quote> disallows fetching selinux settings explicitly." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3298 +#: sssd.conf.5.xml:3428 msgid "" -"Default: <quote>id_provider</quote> is used if it is set and can handle " -"selinux loading requests." +"Default: the value of <quote>id_provider</quote> is used if it is set and " +"can handle selinux loading requests. Otherwise the result is the same as if " +"the selinux_provider is set to none." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3304 +#: sssd.conf.5.xml:3435 msgid "subdomains_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3307 +#: sssd.conf.5.xml:3438 msgid "" "The provider which should handle fetching of subdomains. This value should " "be always the same as id_provider. Supported subdomain providers are:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3313 +#: sssd.conf.5.xml:3444 msgid "" "<quote>ipa</quote> to load a list of subdomains from an IPA server. See " "<citerefentry> <refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</" @@ -3847,7 +4009,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3322 +#: sssd.conf.5.xml:3453 msgid "" "<quote>ad</quote> to load a list of subdomains from an Active Directory " "server. See <citerefentry> <refentrytitle>sssd-ad</refentrytitle> " @@ -3856,24 +4018,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3331 +#: sssd.conf.5.xml:3462 msgid "<quote>none</quote> disallows fetching subdomains explicitly." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3335 +#: sssd.conf.5.xml:3466 msgid "" "Default: The value of <quote>id_provider</quote> is used if it is set and " "can handle subdomain requests." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3341 +#: sssd.conf.5.xml:3472 msgid "session_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3344 +#: sssd.conf.5.xml:3475 msgid "" "The provider which configures and manages user session related tasks. The " "only user session task currently provided is the integration with Fleet " @@ -3881,36 +4043,36 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3351 +#: sssd.conf.5.xml:3482 msgid "<quote>ipa</quote> to allow performing user session related tasks." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3355 +#: sssd.conf.5.xml:3486 msgid "" "<quote>none</quote> does not perform any kind of user session related tasks." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3359 +#: sssd.conf.5.xml:3490 #, fuzzy #| msgid "Default: true" msgid "Default: <quote>none</quote>." msgstr "Пешфарз: true" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3365 +#: sssd.conf.5.xml:3496 msgid "autofs_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3368 +#: sssd.conf.5.xml:3499 msgid "" "The autofs provider used for the domain. Supported autofs providers are:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3372 +#: sssd.conf.5.xml:3503 msgid "" "<quote>ldap</quote> to load maps stored in LDAP. See <citerefentry> " "<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> </" @@ -3918,7 +4080,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3379 +#: sssd.conf.5.xml:3510 msgid "" "<quote>ipa</quote> to load maps stored in an IPA server. See <citerefentry> " "<refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</manvolnum> </" @@ -3926,7 +4088,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3387 +#: sssd.conf.5.xml:3518 msgid "" "<quote>ad</quote> to load maps stored in an AD server. See <citerefentry> " "<refentrytitle>sssd-ad</refentrytitle> <manvolnum>5</manvolnum> </" @@ -3934,31 +4096,31 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3396 +#: sssd.conf.5.xml:3527 msgid "<quote>none</quote> disables autofs explicitly." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3399 +#: sssd.conf.5.xml:3530 msgid "" "Default: The value of <quote>id_provider</quote> is used if it is set and " "can handle autofs requests." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3406 +#: sssd.conf.5.xml:3537 msgid "hostid_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3409 +#: sssd.conf.5.xml:3540 msgid "" "The provider used for retrieving host identity information. Supported " "hostid providers are:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3413 +#: sssd.conf.5.xml:3544 msgid "" "<quote>ipa</quote> to load host identity stored in an IPA server. See " "<citerefentry> <refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</" @@ -3966,38 +4128,38 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3421 +#: sssd.conf.5.xml:3552 msgid "<quote>none</quote> disables hostid explicitly." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3424 +#: sssd.conf.5.xml:3555 msgid "" "Default: The value of <quote>id_provider</quote> is used if it is set and " "can handle hostid requests." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3431 +#: sssd.conf.5.xml:3562 msgid "resolver_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3434 +#: sssd.conf.5.xml:3565 msgid "" "The provider which should handle hosts and networks lookups. Supported " "resolver providers are:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3438 +#: sssd.conf.5.xml:3569 msgid "" "<quote>proxy</quote> to forward lookups to another NSS library. See " "<quote>proxy_resolver_lib_name</quote>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3442 +#: sssd.conf.5.xml:3573 msgid "" "<quote>ldap</quote> to fetch hosts and networks stored in LDAP. See " "<citerefentry> <refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</" @@ -4005,7 +4167,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3449 +#: sssd.conf.5.xml:3580 msgid "" "<quote>ad</quote> to fetch hosts and networks stored in AD. See " "<citerefentry> <refentrytitle>sssd-ad</refentrytitle> <manvolnum>5</" @@ -4014,19 +4176,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3457 +#: sssd.conf.5.xml:3588 msgid "<quote>none</quote> disallows fetching hosts and networks explicitly." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3460 +#: sssd.conf.5.xml:3591 msgid "" "Default: The value of <quote>id_provider</quote> is used if it is set and " "can handle resolver requests." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3470 +#: sssd.conf.5.xml:3601 msgid "" "Regular expression for this domain that describes how to parse the string " "containing user name and domain into these components. The \"domain\" can " @@ -4036,24 +4198,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3479 +#: sssd.conf.5.xml:3610 msgid "" "Default: <quote>^((?P<name>.+)@(?P<domain>[^@]*)|(?P<name>" "[^@]+))$</quote> which allows two different styles for user names:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:3484 sssd.conf.5.xml:3498 +#: sssd.conf.5.xml:3615 sssd.conf.5.xml:3629 msgid "username" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:3487 sssd.conf.5.xml:3501 +#: sssd.conf.5.xml:3618 sssd.conf.5.xml:3632 msgid "username@domain.name" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3492 +#: sssd.conf.5.xml:3623 msgid "" "Default for the AD and IPA provider: <quote>^(((?P<domain>[^\\\\]+)\\\\" "(?P<name>.+))|((?P<name>.+)@(?P<domain>[^@]+))|((?" @@ -4062,19 +4224,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:3504 +#: sssd.conf.5.xml:3635 msgid "domain\\username" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3507 +#: sssd.conf.5.xml:3638 msgid "" "While the first two correspond to the general default the third one is " "introduced to allow easy integration of users from Windows domains." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3512 +#: sssd.conf.5.xml:3643 msgid "" "The default re_expression uses the <quote>@</quote> character as a separator " "between the name and the domain. As a result of this setting the default " @@ -4084,89 +4246,94 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3564 +#: sssd.conf.5.xml:3695 msgid "Default: <quote>%1$s@%2$s</quote>." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3570 +#: sssd.conf.5.xml:3701 msgid "lookup_family_order (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3573 +#: sssd.conf.5.xml:3704 msgid "" "Provides the ability to select preferred address family to use when " "performing DNS lookups." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3577 +#: sssd.conf.5.xml:3708 msgid "Supported values:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3580 +#: sssd.conf.5.xml:3711 msgid "ipv4_first: Try looking up IPv4 address, if that fails, try IPv6" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3583 +#: sssd.conf.5.xml:3714 msgid "ipv4_only: Only attempt to resolve hostnames to IPv4 addresses." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3586 +#: sssd.conf.5.xml:3717 msgid "ipv6_first: Try looking up IPv6 address, if that fails, try IPv4" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3589 +#: sssd.conf.5.xml:3720 msgid "ipv6_only: Only attempt to resolve hostnames to IPv6 addresses." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3592 +#: sssd.conf.5.xml:3723 msgid "Default: ipv4_first" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3598 +#: sssd.conf.5.xml:3729 msgid "dns_resolver_server_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3601 +#: sssd.conf.5.xml:3732 msgid "" -"Defines the amount of time (in milliseconds) SSSD would try to talk to DNS " -"server before trying next DNS server." +"Defines the timeout duration (in milliseconds) SSSD waits for a DNS server " +"to respond before moving to the next one." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3606 +#: sssd.conf.5.xml:3737 msgid "" "The AD provider will use this option for the CLDAP ping timeouts as well." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3610 sssd.conf.5.xml:3630 sssd.conf.5.xml:3651 +#: sssd.conf.5.xml:3741 sssd.conf.5.xml:3777 sssd.conf.5.xml:3814 msgid "" -"Please see the section <quote>FAILOVER</quote> for more information about " -"the service resolution." +"Please see the section <quote>FAILOVER</quote> in <citerefentry> " +"<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> </" +"citerefentry>, <citerefentry> <refentrytitle>sssd-krb5</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry>, <citerefentry> <refentrytitle>sssd-" +"ipa</refentrytitle> <manvolnum>5</manvolnum> </citerefentry> or " +"<citerefentry> <refentrytitle>sssd-ad</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry> for more information about the service resolution." msgstr "" #. type: Content of: <refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3615 sssd-ldap.5.xml:700 include/failover.xml:84 +#: sssd.conf.5.xml:3762 sssd-ldap.5.xml:700 include/failover.xml:84 msgid "Default: 1000" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3621 +#: sssd.conf.5.xml:3768 msgid "dns_resolver_op_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3624 +#: sssd.conf.5.xml:3771 msgid "" "Defines the amount of time (in seconds) to wait to resolve single DNS query " "(e.g. resolution of a hostname or an SRV record) before trying the next " @@ -4174,17 +4341,17 @@ msgid "" msgstr "" #. type: Content of: <refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3635 include/failover.xml:100 +#: sssd.conf.5.xml:3798 include/failover.xml:100 msgid "Default: 3" msgstr "Пешфарз: 3" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3641 +#: sssd.conf.5.xml:3804 msgid "dns_resolver_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3644 +#: sssd.conf.5.xml:3807 msgid "" "Defines the amount of time (in seconds) to wait for a reply from the " "internal fail over service before assuming that the service is unreachable. " @@ -4193,12 +4360,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3662 -msgid "dns_resolver_use_search_list (bool)" +#: sssd.conf.5.xml:3841 +msgid "dns_resolver_use_search_list (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3665 +#: sssd.conf.5.xml:3844 msgid "" "Normally, the DNS resolver searches the domain list defined in the " "\"search\" directive from the resolv.conf file. This can lead to delays in " @@ -4206,7 +4373,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3671 +#: sssd.conf.5.xml:3850 msgid "" "If fully qualified domain names (or _srv_) are used in the SSSD " "configuration, setting this option to FALSE can prevent unnecessary DNS " @@ -4214,34 +4381,34 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3677 +#: sssd.conf.5.xml:3856 msgid "Default: TRUE" msgstr "Пешфарз: TRUE" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3683 +#: sssd.conf.5.xml:3862 msgid "dns_discovery_domain (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3686 +#: sssd.conf.5.xml:3865 msgid "" "If service discovery is used in the back end, specifies the domain part of " "the service discovery DNS query." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3690 +#: sssd.conf.5.xml:3869 msgid "Default: Use the domain part of machine's hostname" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3696 +#: sssd.conf.5.xml:3875 msgid "failover_primary_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3699 +#: sssd.conf.5.xml:3878 msgid "" "When no primary server is available, SSSD fails over to a backup server. " "This option defines the number of seconds SSSD waits before attempting to " @@ -4249,59 +4416,68 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3706 +#: sssd.conf.5.xml:3885 msgid "Note: The minimum value is 31." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3709 +#: sssd.conf.5.xml:3888 #, fuzzy #| msgid "Default: 3" msgid "Default: 31" msgstr "Пешфарз: 3" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3715 +#: sssd.conf.5.xml:3894 msgid "override_gid (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3718 -msgid "Override the primary GID value with the one specified." +#: sssd.conf.5.xml:3897 +msgid "" +"Override the primary GID value for all users in the domain with specified " +"value." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3901 +msgid "" +"Default: not set (Use the primary GID value retrieved from the identity " +"provider)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3724 +#: sssd.conf.5.xml:3908 msgid "case_sensitive (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3731 +#: sssd.conf.5.xml:3915 msgid "True" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3734 +#: sssd.conf.5.xml:3918 msgid "Case sensitive. This value is invalid for AD provider." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3740 +#: sssd.conf.5.xml:3924 msgid "False" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3742 +#: sssd.conf.5.xml:3926 msgid "Case insensitive." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3746 +#: sssd.conf.5.xml:3930 msgid "Preserving" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3749 +#: sssd.conf.5.xml:3933 msgid "" "Same as False (case insensitive), but does not lowercase names in the result " "of NSS operations. Note that name aliases (and in case of services also " @@ -4309,31 +4485,57 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3757 +#: sssd.conf.5.xml:3941 msgid "" "If you want to set this value for trusted domain with IPA provider, you need " "to set it on both the client and SSSD on the server." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3727 +#: sssd.conf.5.xml:3911 msgid "" "Treat user and group names as case sensitive. Possible option values are: " "<placeholder type=\"variablelist\" id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3772 +#: sssd.conf.5.xml:3956 msgid "Default: True (False for AD provider)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3778 +#: sssd.conf.5.xml:3962 +msgid "avoid_by_id_lookups (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3965 +msgid "" +"If this option is set to 'true' SSSD will try to avoid sending lookups by ID " +"to the backend and will switch to a lookup by name if a cached object with a " +"matching ID can be found." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3971 +msgid "" +"This option can e.g. be used in cases where searches by ID are expensive on " +"the server side because of missing indexes or are not even possible, e.g. " +"due to non-reversible POSIX id-mapping." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3978 +msgid "Default: False (True for IdP provider)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:3984 msgid "subdomain_inherit (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3781 +#: sssd.conf.5.xml:3987 msgid "" "Specifies a list of configuration parameters that should be inherited by a " "subdomain. Please note that only selected parameters can be inherited. " @@ -4341,89 +4543,89 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3787 +#: sssd.conf.5.xml:3993 msgid "ldap_search_timeout" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3790 +#: sssd.conf.5.xml:3996 msgid "ldap_network_timeout" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3793 +#: sssd.conf.5.xml:3999 msgid "ldap_opt_timeout" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3796 +#: sssd.conf.5.xml:4002 msgid "ldap_offline_timeout" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3799 +#: sssd.conf.5.xml:4005 msgid "ldap_purge_cache_timeout" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3802 +#: sssd.conf.5.xml:4008 msgid "ldap_purge_cache_offset" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3805 +#: sssd.conf.5.xml:4011 msgid "" "ldap_krb5_keytab (the value of krb5_keytab will be used if ldap_krb5_keytab " "is not set explicitly)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3809 +#: sssd.conf.5.xml:4015 msgid "ldap_krb5_ticket_lifetime" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3812 +#: sssd.conf.5.xml:4018 msgid "ldap_connection_expire_timeout" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3815 +#: sssd.conf.5.xml:4021 msgid "ldap_connection_expire_offset" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3818 +#: sssd.conf.5.xml:4024 msgid "ldap_connection_idle_timeout" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3821 sssd-ldap.5.xml:446 +#: sssd.conf.5.xml:4027 sssd-ldap.5.xml:446 msgid "ldap_use_tokengroups" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3824 +#: sssd.conf.5.xml:4030 msgid "ldap_user_principal" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3827 +#: sssd.conf.5.xml:4033 msgid "ignore_group_members" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3830 +#: sssd.conf.5.xml:4036 msgid "auto_private_groups" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3833 +#: sssd.conf.5.xml:4039 msgid "case_sensitive" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:3838 +#: sssd.conf.5.xml:4044 #, no-wrap msgid "" "subdomain_inherit = ldap_purge_cache_timeout\n" @@ -4431,27 +4633,27 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3845 +#: sssd.conf.5.xml:4051 msgid "Note: This option only works with the IPA and AD provider." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3852 +#: sssd.conf.5.xml:4058 msgid "subdomain_homedir (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3863 +#: sssd.conf.5.xml:4069 msgid "%F" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3864 +#: sssd.conf.5.xml:4070 msgid "flat (NetBIOS) name of a subdomain." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3855 +#: sssd.conf.5.xml:4061 msgid "" "Use this homedir as default value for all subdomains within this domain in " "IPA AD trust. See <emphasis>override_homedir</emphasis> for info about " @@ -4461,55 +4663,55 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3869 +#: sssd.conf.5.xml:4075 msgid "" "The value can be overridden by <emphasis>override_homedir</emphasis> option." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3873 +#: sssd.conf.5.xml:4079 msgid "Default: <filename>/home/%d/%u</filename>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3878 +#: sssd.conf.5.xml:4084 msgid "realmd_tags (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3881 +#: sssd.conf.5.xml:4087 msgid "" "Various tags stored by the realmd configuration service for this domain." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3887 +#: sssd.conf.5.xml:4093 msgid "cached_auth_timeout (int)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3890 +#: sssd.conf.5.xml:4096 msgid "" -"Specifies time in seconds since last successful online authentication for " -"which user will be authenticated using cached credentials while SSSD is in " -"the online mode. If the credentials are incorrect, SSSD falls back to online " -"authentication." +"Specifies the number of seconds since the last successful online " +"authentication during which SSSD will authenticate users via cached " +"credentials, even while online. If the cached authentication fails, SSSD " +"immediately falls back to online authentication." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3898 +#: sssd.conf.5.xml:4103 msgid "" "This option's value is inherited by all trusted domains. At the moment it is " "not possible to set a different value per trusted domain." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3903 +#: sssd.conf.5.xml:4108 msgid "Special value 0 implies that this feature is disabled." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3907 +#: sssd.conf.5.xml:4112 msgid "" "Please note that if <quote>cached_auth_timeout</quote> is longer than " "<quote>pam_id_timeout</quote> then the back end could be called to handle " @@ -4517,12 +4719,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3918 +#: sssd.conf.5.xml:4123 msgid "local_auth_policy (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3921 +#: sssd.conf.5.xml:4126 msgid "" "Local authentication methods policy. Some backends (i.e. LDAP, proxy " "provider) only support a password based authentication, while others can " @@ -4534,7 +4736,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3933 +#: sssd.conf.5.xml:4138 msgid "" "There are three possible values for this option: match, only, enable. " "<quote>match</quote> is used to match offline and online states for Kerberos " @@ -4546,7 +4748,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3946 +#: sssd.conf.5.xml:4151 msgid "" "The following table shows which authentication methods, if configured " "properly, are currently enabled or disabled for each backend, with the " @@ -4554,42 +4756,47 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> -#: sssd.conf.5.xml:3959 +#: sssd.conf.5.xml:4164 msgid "local_auth_policy = match (default)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> -#: sssd.conf.5.xml:3960 +#: sssd.conf.5.xml:4165 msgid "Passkey" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> -#: sssd.conf.5.xml:3961 +#: sssd.conf.5.xml:4166 msgid "Smartcard" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:3964 sssd-ldap.5.xml:228 +#: sssd.conf.5.xml:4169 sssd-ldap.5.xml:228 msgid "IPA" msgstr "" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry><para> +#: sssd.conf.5.xml:4169 sssd.conf.5.xml:4170 sssd.conf.5.xml:4173 +msgid "enabled" +msgstr "" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:3967 sssd-ldap.5.xml:233 +#: sssd.conf.5.xml:4172 sssd-ldap.5.xml:233 msgid "AD" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry><para> -#: sssd.conf.5.xml:3967 sssd.conf.5.xml:3970 sssd.conf.5.xml:3971 +#: sssd.conf.5.xml:4172 sssd.conf.5.xml:4175 sssd.conf.5.xml:4176 msgid "disabled" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry> -#: sssd.conf.5.xml:3970 +#: sssd.conf.5.xml:4175 msgid "LDAP" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3975 +#: sssd.conf.5.xml:4180 msgid "" "Please note that if local Smartcard authentication is enabled and a " "Smartcard is present, Smartcard authentication will be preferred over the " @@ -4598,7 +4805,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:3987 +#: sssd.conf.5.xml:4192 #, no-wrap msgid "" "[domain/shadowutils]\n" @@ -4609,7 +4816,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3983 +#: sssd.conf.5.xml:4188 msgid "" "The following configuration example allows local users to authenticate " "locally using any enabled method (i.e. smartcard, passkey). <placeholder " @@ -4617,31 +4824,31 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3995 +#: sssd.conf.5.xml:4200 #, fuzzy #| msgid "Default: 3" msgid "Default: match" msgstr "Пешфарз: 3" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4000 +#: sssd.conf.5.xml:4205 msgid "auto_private_groups (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4006 +#: sssd.conf.5.xml:4211 msgid "true" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4009 +#: sssd.conf.5.xml:4214 msgid "" "Create user's private group unconditionally from user's UID number. The GID " "number is ignored in this case." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4013 +#: sssd.conf.5.xml:4218 msgid "" "NOTE: Because the GID number and the user private group are inferred from " "the UID number, it is not supported to have multiple entries with the same " @@ -4650,24 +4857,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4022 +#: sssd.conf.5.xml:4227 msgid "false" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4025 +#: sssd.conf.5.xml:4230 msgid "" "Always use the user's primary GID number. The GID number must refer to a " "group object in the LDAP database." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4031 +#: sssd.conf.5.xml:4236 msgid "hybrid" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4034 +#: sssd.conf.5.xml:4239 msgid "" "A primary group is autogenerated for user entries whose UID and GID numbers " "have the same value and at the same time the GID number does not correspond " @@ -4677,14 +4884,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4047 +#: sssd.conf.5.xml:4252 msgid "" "If the UID and GID of a user are different, then the GID must correspond to " "a group entry, otherwise the GID is simply not resolvable." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4054 +#: sssd.conf.5.xml:4259 msgid "" "This feature is useful for environments that wish to stop maintaining a " "separate group objects for the user private groups, but also wish to retain " @@ -4692,14 +4899,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4003 +#: sssd.conf.5.xml:4208 msgid "" "This option takes any of three available values: <placeholder " "type=\"variablelist\" id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4066 +#: sssd.conf.5.xml:4271 msgid "" "For the LDAP based id providers (LDAP, IPA and AD) the default for the " "configured domain is typically False because the sources have the concept of " @@ -4709,14 +4916,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4075 +#: sssd.conf.5.xml:4280 msgid "" "For subdomains, the default value is False for subdomains that use assigned " "POSIX IDs and True for subdomains that use automatic ID-mapping." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:4083 +#: sssd.conf.5.xml:4288 #, no-wrap msgid "" "[domain/forest.domain/sub.domain]\n" @@ -4724,7 +4931,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:4089 +#: sssd.conf.5.xml:4294 #, no-wrap msgid "" "[domain/forest.domain]\n" @@ -4733,7 +4940,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4080 +#: sssd.conf.5.xml:4285 msgid "" "The value of auto_private_groups can either be set per subdomains in a " "subsection, for example: <placeholder type=\"programlisting\" id=\"0\"/> or " @@ -4742,7 +4949,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:2503 +#: sssd.conf.5.xml:2549 msgid "" "These configuration options can be present in a domain configuration " "section, that is, in a section called <quote>[domain/<replaceable>NAME</" @@ -4750,17 +4957,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4104 +#: sssd.conf.5.xml:4309 msgid "proxy_pam_target (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4107 +#: sssd.conf.5.xml:4312 msgid "The proxy target PAM proxies to." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4110 +#: sssd.conf.5.xml:4315 msgid "" "Default: not set by default, you have to take an existing pam configuration " "or create a new one and add the service name here. As an alternative you can " @@ -4768,12 +4975,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4120 +#: sssd.conf.5.xml:4325 msgid "proxy_lib_name (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4123 +#: sssd.conf.5.xml:4328 msgid "" "The name of the NSS library to use in proxy domains. The NSS functions " "searched for in the library are in the form of _nss_$(libName)_$(function), " @@ -4781,12 +4988,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4133 +#: sssd.conf.5.xml:4338 msgid "proxy_resolver_lib_name (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4136 +#: sssd.conf.5.xml:4341 msgid "" "The name of the NSS library to use for hosts and networks lookups in proxy " "domains. The NSS functions searched for in the library are in the form of " @@ -4794,12 +5001,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4147 +#: sssd.conf.5.xml:4352 msgid "proxy_fast_alias (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4150 +#: sssd.conf.5.xml:4355 msgid "" "When a user or group is looked up by name in the proxy provider, a second " "lookup by ID is performed to \"canonicalize\" the name in case the requested " @@ -4808,12 +5015,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4164 +#: sssd.conf.5.xml:4369 msgid "proxy_max_children (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4167 +#: sssd.conf.5.xml:4372 msgid "" "This option specifies the number of pre-forked proxy children. It is useful " "for high-load SSSD environments where sssd may run out of available child " @@ -4821,19 +5028,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4100 +#: sssd.conf.5.xml:4305 msgid "" "Options valid for proxy domains. <placeholder type=\"variablelist\" " "id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:4183 +#: sssd.conf.5.xml:4388 msgid "Application domains" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:4185 +#: sssd.conf.5.xml:4390 msgid "" "SSSD, with its D-Bus interface (see <citerefentry> <refentrytitle>sssd-ifp</" "refentrytitle> <manvolnum>5</manvolnum> </citerefentry>) is appealing to " @@ -4850,7 +5057,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:4205 +#: sssd.conf.5.xml:4410 msgid "" "Please note that the application domain must still be explicitly enabled in " "the <quote>domains</quote> parameter so that the lookup order between the " @@ -4858,17 +5065,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><title> -#: sssd.conf.5.xml:4211 +#: sssd.conf.5.xml:4416 msgid "Application domain parameters" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4213 +#: sssd.conf.5.xml:4418 msgid "inherit_from (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4216 +#: sssd.conf.5.xml:4421 msgid "" "The SSSD POSIX-type domain the application domain inherits all settings " "from. The application domain can moreover add its own settings to the " @@ -4877,7 +5084,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:4230 +#: sssd.conf.5.xml:4435 msgid "" "The following example illustrates the use of an application domain. In this " "setup, the POSIX domain is connected to an LDAP server and is used by the OS " @@ -4887,7 +5094,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><programlisting> -#: sssd.conf.5.xml:4238 +#: sssd.conf.5.xml:4443 #, no-wrap msgid "" "[sssd]\n" @@ -4907,12 +5114,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:4258 +#: sssd.conf.5.xml:4463 msgid "TRUSTED DOMAIN SECTION" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4260 +#: sssd.conf.5.xml:4465 msgid "" "Some options used in the domain section can also be used in the trusted " "domain section, that is, in a section called <quote>[domain/" @@ -4923,69 +5130,79 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4267 +#: sssd.conf.5.xml:4472 msgid "ldap_search_base," msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4268 +#: sssd.conf.5.xml:4473 msgid "ldap_user_search_base," msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4269 +#: sssd.conf.5.xml:4474 msgid "ldap_group_search_base," msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4270 +#: sssd.conf.5.xml:4475 msgid "ldap_netgroup_search_base," msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4271 +#: sssd.conf.5.xml:4476 msgid "ldap_service_search_base," msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4272 +#: sssd.conf.5.xml:4477 msgid "ldap_sasl_mech," msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4273 +#: sssd.conf.5.xml:4478 msgid "ad_server," msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4274 +#: sssd.conf.5.xml:4479 msgid "ad_backup_server," msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4275 +#: sssd.conf.5.xml:4480 msgid "ad_site," msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:4276 sssd-ipa.5.xml:934 +#: sssd.conf.5.xml:4481 sssd-ipa.5.xml:929 msgid "use_fully_qualified_names" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4280 +#: sssd.conf.5.xml:4482 +msgid "pam_gssapi_services" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:4483 +msgid "pam_gssapi_check_upn" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:4485 msgid "" "For more details about these options see their individual description in the " "manual page." msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:4286 +#: sssd.conf.5.xml:4491 msgid "CERTIFICATE MAPPING SECTION" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4288 +#: sssd.conf.5.xml:4493 msgid "" "To allow authentication with Smartcards and certificates SSSD must be able " "to map certificates to users. This can be done by adding the full " @@ -4998,7 +5215,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4302 +#: sssd.conf.5.xml:4507 msgid "" "To make the mapping more flexible mapping and matching rules were added to " "SSSD (see <citerefentry> <refentrytitle>sss-certmap</refentrytitle> " @@ -5006,7 +5223,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4311 +#: sssd.conf.5.xml:4516 msgid "" "A mapping and matching rule can be added to the SSSD configuration in a " "section on its own with a name like <quote>[certmap/" @@ -5015,55 +5232,50 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4318 +#: sssd.conf.5.xml:4523 msgid "matchrule (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4321 +#: sssd.conf.5.xml:4526 msgid "" "Only certificates from the Smartcard which matches this rule will be " "processed, all others are ignored." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4325 +#: sssd.conf.5.xml:4530 msgid "" "Default: KRB5:<EKU>clientAuth, i.e. only certificates which have the " "Extended Key Usage <quote>clientAuth</quote>" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4332 +#: sssd.conf.5.xml:4537 msgid "maprule (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4335 +#: sssd.conf.5.xml:4540 msgid "Defines how the user is found for a given certificate." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:4341 +#: sssd.conf.5.xml:4546 msgid "" "LDAP:(userCertificate;binary={cert!bin}) for LDAP based providers like " "<quote>ldap</quote>, <quote>AD</quote> or <quote>ipa</quote>." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:4347 +#: sssd.conf.5.xml:4552 msgid "" "If maprule is not set and provider is <quote>proxy</quote>, the RULE_NAME " "name is assumed to be the name of the matching user." msgstr "" -#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4357 -msgid "domains (string)" -msgstr "" - #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4360 +#: sssd.conf.5.xml:4565 msgid "" "Comma separated list of domain names the rule should be applied. By default " "a rule is only valid in the domain configured in sssd.conf. If the provider " @@ -5072,17 +5284,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4367 +#: sssd.conf.5.xml:4572 msgid "Default: the configured domain in sssd.conf" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4372 +#: sssd.conf.5.xml:4577 msgid "priority (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4375 +#: sssd.conf.5.xml:4580 msgid "" "Unsigned integer value defining the priority of the rule. The higher the " "number the lower the priority. <quote>0</quote> stands for the highest " @@ -5090,17 +5302,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4381 +#: sssd.conf.5.xml:4586 msgid "Default: the lowest priority" msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:4389 +#: sssd.conf.5.xml:4594 msgid "PROMPTING CONFIGURATION SECTION" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4391 +#: sssd.conf.5.xml:4596 msgid "" "If a special file (<filename>/var/lib/sss/pubconf/pam_preauth_available</" "filename>) exists SSSD's PAM module pam_sss will ask SSSD to figure out " @@ -5110,7 +5322,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4399 +#: sssd.conf.5.xml:4604 msgid "" "With the growing number of authentication methods and the possibility that " "there are multiple ones for a single user the heuristic used by pam_sss to " @@ -5119,59 +5331,59 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4411 +#: sssd.conf.5.xml:4616 msgid "[prompting/password]" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4414 +#: sssd.conf.5.xml:4619 msgid "password_prompt" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4415 +#: sssd.conf.5.xml:4620 msgid "to change the string of the password prompt" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4413 +#: sssd.conf.5.xml:4618 msgid "" "to configure password prompting, allowed options are: <placeholder " "type=\"variablelist\" id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4423 +#: sssd.conf.5.xml:4628 msgid "[prompting/2fa]" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4427 +#: sssd.conf.5.xml:4632 msgid "first_prompt" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4428 +#: sssd.conf.5.xml:4633 msgid "to change the string of the prompt for the first factor" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4431 +#: sssd.conf.5.xml:4636 msgid "second_prompt" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4432 +#: sssd.conf.5.xml:4637 msgid "to change the string of the prompt for the second factor" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4435 +#: sssd.conf.5.xml:4640 msgid "single_prompt" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4436 +#: sssd.conf.5.xml:4641 msgid "" "boolean value, if True there will be only a single prompt using the value of " "first_prompt where it is expected that both factors are entered as a single " @@ -5180,7 +5392,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4425 +#: sssd.conf.5.xml:4630 msgid "" "to configure two-factor authentication prompting, allowed options are: " "<placeholder type=\"variablelist\" id=\"0\"/> If the second factor is " @@ -5189,7 +5401,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4449 +#: sssd.conf.5.xml:4654 msgid "" "Some clients, such as SSH with 'PasswordAuthentication yes', generate their " "own prompts and do not use prompts provided by SSSD or other PAM modules. " @@ -5200,17 +5412,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4464 +#: sssd.conf.5.xml:4669 msgid "[prompting/passkey]" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:4470 sssd-ad.5.xml:1022 +#: sssd.conf.5.xml:4675 sssd.conf.5.xml:4719 sssd-ad.5.xml:1027 msgid "interactive" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4472 +#: sssd.conf.5.xml:4677 msgid "" "boolean value, if True prompt a message and wait before testing the presence " "of a passkey device. Recommended if your device doesn’t have a tactile " @@ -5218,55 +5430,131 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4480 +#: sssd.conf.5.xml:4685 sssd.conf.5.xml:4735 msgid "interactive_prompt" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4482 +#: sssd.conf.5.xml:4687 sssd.conf.5.xml:4737 msgid "to change the message of the interactive prompt." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4487 +#: sssd.conf.5.xml:4692 msgid "touch" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4489 +#: sssd.conf.5.xml:4694 msgid "" "boolean value, if True prompt a message to remind the user to touch the " "device." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4495 +#: sssd.conf.5.xml:4700 msgid "touch_prompt" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4497 +#: sssd.conf.5.xml:4702 msgid "to change the message of the touch prompt." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4466 +#: sssd.conf.5.xml:4671 msgid "" "to configure passkey authentication prompting, allowed options are: " "<placeholder type=\"variablelist\" id=\"0\"/>" msgstr "" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4713 +msgid "[prompting/oauth2]" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4721 +msgid "" +"boolean value, if True prompt a message after asking the user to " +"authenticate, and wait before requesting the access token." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4725 +msgid "" +"If False, make sure to set the <quote>idp_request_timeout</quote> " +"sufficiently high, to give the user time to authenticate." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4715 +msgid "" +"to configure OAuth2 authentication prompting, allowed options are: " +"<placeholder type=\"variablelist\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4748 +msgid "[prompting/cert_auth]" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4754 +msgid "pin_prompt" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4756 +msgid "" +"to change the message which asks the user to enter the PIN at the computer " +"keyboard. At the end of the message the token name is printed." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4764 +msgid "keypad_prompt" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4766 +msgid "" +"to change the message which asks the user to enter the PIN at keypad of the " +"Smartcard reader. At the end of the message the token name is printed." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4774 +msgid "user_name_hint" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4776 +msgid "" +"boolean value, if True ask for a user name if no name was given before and " +"the found certificate can be mapped to more than one user." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4750 +msgid "" +"to configure Smartcard authentication prompting, allowed options are: " +"<placeholder type=\"variablelist\" id=\"0\"/>" +msgstr "" + #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4406 +#: sssd.conf.5.xml:4611 msgid "" "Each supported authentication method has its own configuration subsection " "under <quote>[prompting/...]</quote>. Currently there are: <placeholder " "type=\"variablelist\" id=\"0\"/> <placeholder type=\"variablelist\" id=\"1\"/" -"> <placeholder type=\"variablelist\" id=\"2\"/>" +"> <placeholder type=\"variablelist\" id=\"2\"/> <placeholder " +"type=\"variablelist\" id=\"3\"/> <placeholder type=\"variablelist\" id=\"4\"/" +">" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4508 +#: sssd.conf.5.xml:4792 msgid "" "It is possible to add a subsection for specific PAM services, e.g. " "<quote>[prompting/password/sshd]</quote> to individual change the prompting " @@ -5274,12 +5562,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:4515 pam_sss_gss.8.xml:157 idmap_sss.8.xml:43 +#: sssd.conf.5.xml:4799 pam_sss_gss.8.xml:157 idmap_sss.8.xml:43 msgid "EXAMPLES" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd.conf.5.xml:4521 +#: sssd.conf.5.xml:4805 #, no-wrap msgid "" "[sssd]\n" @@ -5308,7 +5596,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4517 +#: sssd.conf.5.xml:4801 msgid "" "1. The following example shows a typical SSSD config. It does not describe " "configuration of the domains themselves - refer to documentation on " @@ -5317,7 +5605,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd.conf.5.xml:4553 +#: sssd.conf.5.xml:4837 #, no-wrap msgid "" "[domain/ipa.com/child.ad.com]\n" @@ -5325,7 +5613,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4547 +#: sssd.conf.5.xml:4831 msgid "" "2. The following example shows configuration of IPA AD trust where the AD " "forest consists of two domains in a parent-child structure. Suppose IPA " @@ -5336,7 +5624,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd.conf.5.xml:4564 +#: sssd.conf.5.xml:4848 #, no-wrap msgid "" "[certmap/my.domain/rule_name]\n" @@ -5347,7 +5635,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4558 +#: sssd.conf.5.xml:4842 msgid "" "3. The following example shows the configuration of a certificate mapping " "rule. It is valid for the configured domain <quote>my.domain</quote> and " @@ -5544,7 +5832,7 @@ msgid "" "defaultNamingContext does not exist or has an empty value namingContexts is " "used. The namingContexts attribute must have a single value with the DN of " "the search base of the LDAP server to make this work. Multiple values are " -"are not supported." +"not supported." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> @@ -5847,15 +6135,15 @@ msgid "Optional. Use the given string as search base for host objects." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap.5.xml:472 sssd-ipa.5.xml:506 sssd-ipa.5.xml:525 sssd-ipa.5.xml:544 -#: sssd-ipa.5.xml:563 +#: sssd-ldap.5.xml:472 sssd-ipa.5.xml:501 sssd-ipa.5.xml:520 sssd-ipa.5.xml:539 +#: sssd-ipa.5.xml:558 msgid "" "See <quote>ldap_search_base</quote> for information about configuring " "multiple search bases." msgstr "" #. type: Content of: <listitem><para> -#: sssd-ldap.5.xml:477 sssd-ipa.5.xml:511 include/ldap_search_bases.xml:27 +#: sssd-ldap.5.xml:477 sssd-ipa.5.xml:506 include/ldap_search_bases.xml:27 msgid "Default: the value of <emphasis>ldap_search_base</emphasis>" msgstr "" @@ -5979,7 +6267,7 @@ msgid "" "closed early to ensure that a new query cannot require the connection to " "remain open past its expiration. This implies that connections will always " "be closed immediately and will never be reused if " -"<emphasis>ldap_connection_expire_timeout <= ldap_opt_timout</emphasis>" +"<emphasis>ldap_connection_expire_timeout <= ldap_opt_timeout</emphasis>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> @@ -6161,7 +6449,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:831 -msgid "ldap_ignore_unreadable_references (bool)" +msgid "ldap_ignore_unreadable_references (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> @@ -6486,7 +6774,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap.5.xml:1152 sssd-ad.5.xml:1267 +#: sssd-ldap.5.xml:1152 sssd-ad.5.xml:1260 msgid "Default: 86400 (24 hours)" msgstr "" @@ -6524,7 +6812,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ldap.5.xml:1187 sssd-ipa.5.xml:575 sssd-krb5.5.xml:103 +#: sssd-ldap.5.xml:1187 sssd-ipa.5.xml:570 sssd-krb5.5.xml:103 msgid "krb5_realm (string)" msgstr "" @@ -6680,7 +6968,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1339 -msgid "ldap_chpass_update_last_change (bool)" +msgid "ldap_chpass_update_last_change (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> @@ -6827,7 +7115,7 @@ msgid "ldap_access_order (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap.5.xml:1470 sssd-ipa.5.xml:405 +#: sssd-ldap.5.xml:1470 sssd-ipa.5.xml:400 msgid "Comma separated list of access control options. Allowed values are:" msgstr "" @@ -6872,7 +7160,7 @@ msgid "<emphasis>expire</emphasis>: use ldap_account_expire_policy" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap.5.xml:1515 sssd-ipa.5.xml:413 +#: sssd-ldap.5.xml:1515 sssd-ipa.5.xml:408 msgid "" "<emphasis>pwd_expire_policy_reject, pwd_expire_policy_warn, " "pwd_expire_policy_renew: </emphasis> These options are useful if users are " @@ -6882,24 +7170,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap.5.xml:1525 sssd-ipa.5.xml:423 +#: sssd-ldap.5.xml:1525 sssd-ipa.5.xml:418 msgid "" "The difference between these options is the action taken if user password is " "expired:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ldap.5.xml:1530 sssd-ipa.5.xml:428 +#: sssd-ldap.5.xml:1530 sssd-ipa.5.xml:423 msgid "pwd_expire_policy_reject - user is denied to log in," msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ldap.5.xml:1536 sssd-ipa.5.xml:434 +#: sssd-ldap.5.xml:1536 sssd-ipa.5.xml:429 msgid "pwd_expire_policy_warn - user is still able to log in," msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ldap.5.xml:1542 sssd-ipa.5.xml:440 +#: sssd-ldap.5.xml:1542 sssd-ipa.5.xml:435 msgid "" "pwd_expire_policy_renew - user is prompted to change their password " "immediately." @@ -7434,8 +7722,8 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd-ldap.5.xml:2032 sssd-simple.5.xml:169 sssd-ipa.5.xml:984 -#: sssd-ad.5.xml:1470 sssd-idp.5.xml:248 sssd-krb5.5.xml:483 +#: sssd-ldap.5.xml:2032 sssd-simple.5.xml:169 sssd-ipa.5.xml:979 +#: sssd-ad.5.xml:1463 sssd-idp.5.xml:343 sssd-krb5.5.xml:483 #: sss_rpcidmapd.5.xml:98 sssd-session-recording.5.xml:176 msgid "EXAMPLE" msgstr "НАМУНА" @@ -7463,7 +7751,7 @@ msgstr "" #. type: Content of: <refsect1><refsect2><para> #: sssd-ldap.5.xml:2039 sssd-ldap.5.xml:2057 sssd-simple.5.xml:177 -#: sssd-ipa.5.xml:992 sssd-ad.5.xml:1478 sssd-sudo.5.xml:56 sssd-krb5.5.xml:492 +#: sssd-ipa.5.xml:987 sssd-ad.5.xml:1471 sssd-sudo.5.xml:56 sssd-krb5.5.xml:492 #: sssd-session-recording.5.xml:182 include/ldap_id_mapping.xml:105 msgid "<placeholder type=\"programlisting\" id=\"0\"/>" msgstr "" @@ -7498,7 +7786,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><title> #: sssd-ldap.5.xml:2073 sssd_krb5_locator_plugin.8.xml:83 sssd-simple.5.xml:189 -#: sssd-ad.5.xml:1493 sssd.8.xml:270 sss_seed.8.xml:163 +#: sssd-ad.5.xml:1486 sssd.8.xml:270 sss_seed.8.xml:163 msgid "NOTES" msgstr "ЭЗОҲҲО" @@ -8005,7 +8293,7 @@ msgstr "" #: pam_sss.8.xml:434 msgid "" "No authentication method was found by Kerberos. This might happen if the " -"user has a Smartcard assigned but the pkint plugin is not available on the " +"user has a Smartcard assigned but the pkinit plugin is not available on the " "client." msgstr "" @@ -8429,6 +8717,23 @@ msgid "" "first DNS resolving failure." msgstr "" +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_locator_plugin.8.xml:106 +msgid "" +"If the environment variable SSSD_KRB5_LOCATOR_KDC_ADDRESS is set to a KDC " +"address the plugin will use this address instead of reading the kdcinfo " +"file. The address format is the same as in the kdcinfo file (see above)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_locator_plugin.8.xml:112 +msgid "" +"If the environment variable SSSD_KRB5_LOCATOR_KPASSWD_ADDRESS is set to a " +"kpasswd server address the plugin will use this address instead of reading " +"the kpasswdinfo file. The address format is the same as in the kpasswdinfo " +"file (see above)." +msgstr "" + #. type: Content of: <reference><refentry><refnamediv><refname> #: sssd-simple.5.xml:10 sssd-simple.5.xml:16 msgid "sssd-simple" @@ -9812,7 +10117,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:129 sssd-ad.5.xml:1161 +#: sssd-ipa.5.xml:129 sssd-ad.5.xml:1166 msgid "dyndns_update (boolean)" msgstr "" @@ -9826,20 +10131,13 @@ msgid "" "quote> option." msgstr "" -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:141 sssd-ad.5.xml:1175 -msgid "" -"NOTE: On older systems (such as RHEL 5), for this behavior to work reliably, " -"the default Kerberos realm must be set properly in /etc/krb5.conf" -msgstr "" - #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:152 sssd-ad.5.xml:1186 +#: sssd-ipa.5.xml:147 sssd-ad.5.xml:1186 msgid "dyndns_ttl (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:155 sssd-ad.5.xml:1189 +#: sssd-ipa.5.xml:150 sssd-ad.5.xml:1189 msgid "" "The TTL to apply to the client DNS record when updating it. If " "dyndns_update is false this has no effect. This will override the TTL " @@ -9847,17 +10145,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:160 +#: sssd-ipa.5.xml:155 msgid "Default: 1200 (seconds)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:166 sssd-ad.5.xml:1200 +#: sssd-ipa.5.xml:161 sssd-ad.5.xml:1200 msgid "dyndns_iface (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:169 sssd-ad.5.xml:1203 +#: sssd-ipa.5.xml:164 sssd-ad.5.xml:1203 msgid "" "Optional. Applicable only when dyndns_update is true. Choose the interface " "or a list of interfaces whose IP addresses should be used for dynamic DNS " @@ -9869,24 +10167,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:182 +#: sssd-ipa.5.xml:177 msgid "" "Default: Use the IP addresses of the interface which is used for IPA LDAP " "connection" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:186 sssd-ad.5.xml:1226 +#: sssd-ipa.5.xml:181 sssd-ad.5.xml:1220 msgid "Example: dyndns_iface = em[12], !vnet1, vnet*" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:192 sssd-ad.5.xml:1232 +#: sssd-ipa.5.xml:187 sssd-ad.5.xml:1226 msgid "dyndns_address (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:195 sssd-ad.5.xml:1235 +#: sssd-ipa.5.xml:190 sssd-ad.5.xml:1229 msgid "" "Optional. Applicable only when <emphasis>dyndns_update</emphasis> is true. " "A list of IP addresses or IP networks to be used for dynamic DNS updates. " @@ -9897,22 +10195,22 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:206 sssd-ad.5.xml:1246 +#: sssd-ipa.5.xml:201 sssd-ad.5.xml:1240 msgid "Default: No filtering of IP addresses." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:209 sssd-ad.5.xml:1249 +#: sssd-ipa.5.xml:204 sssd-ad.5.xml:1243 msgid "Example: dyndns_address = 10.0.0.0/16, !10.0.1.0/24" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:215 sssd-ad.5.xml:1305 +#: sssd-ipa.5.xml:210 sssd-ad.5.xml:1298 msgid "dyndns_auth (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:218 sssd-ad.5.xml:1308 +#: sssd-ipa.5.xml:213 sssd-ad.5.xml:1301 msgid "" "Whether the nsupdate utility should use GSS-TSIG authentication for secure " "updates with the DNS server, insecure updates can be sent by setting this " @@ -9920,17 +10218,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:224 sssd-ad.5.xml:1314 +#: sssd-ipa.5.xml:219 sssd-ad.5.xml:1307 msgid "Default: GSS-TSIG" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:230 sssd-ad.5.xml:1320 +#: sssd-ipa.5.xml:225 sssd-ad.5.xml:1313 msgid "dyndns_auth_ptr (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:233 sssd-ad.5.xml:1323 +#: sssd-ipa.5.xml:228 sssd-ad.5.xml:1316 msgid "" "Whether the nsupdate utility should use GSS-TSIG authentication for secure " "PTR updates with the DNS server, insecure updates can be sent by setting " @@ -9938,17 +10236,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:239 sssd-ad.5.xml:1329 +#: sssd-ipa.5.xml:234 sssd-ad.5.xml:1322 msgid "Default: Same as dyndns_auth" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:245 sssd-ad.5.xml:1255 +#: sssd-ipa.5.xml:240 sssd-ad.5.xml:1249 msgid "dyndns_refresh_interval (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:248 +#: sssd-ipa.5.xml:243 msgid "" "How often should the back end perform periodic DNS update in addition to the " "automatic update performed when the back end goes online. This option is " @@ -9956,74 +10254,74 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:261 sssd-ad.5.xml:1273 -msgid "dyndns_update_ptr (bool)" +#: sssd-ipa.5.xml:256 sssd-ad.5.xml:1266 +msgid "dyndns_update_ptr (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:264 sssd-ad.5.xml:1276 +#: sssd-ipa.5.xml:259 sssd-ad.5.xml:1269 msgid "" "Whether the PTR record should also be explicitly updated when updating the " "client's DNS records. Applicable only when dyndns_update is true." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:269 +#: sssd-ipa.5.xml:264 msgid "" "This option should be False in most IPA deployments as the IPA server " "generates the PTR records automatically when forward records are changed." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:275 sssd-ad.5.xml:1281 +#: sssd-ipa.5.xml:270 sssd-ad.5.xml:1274 msgid "" "Note that <emphasis>dyndns_update_per_family</emphasis> parameter does not " "apply for PTR record updates. Those updates are always sent separately." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:280 +#: sssd-ipa.5.xml:275 msgid "Default: False (disabled)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:286 sssd-ad.5.xml:1292 -msgid "dyndns_force_tcp (bool)" +#: sssd-ipa.5.xml:281 sssd-ad.5.xml:1285 +msgid "dyndns_force_tcp (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:289 sssd-ad.5.xml:1295 +#: sssd-ipa.5.xml:284 sssd-ad.5.xml:1288 msgid "" "Whether the nsupdate utility should default to using TCP for communicating " "with the DNS server." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:293 sssd-ad.5.xml:1299 +#: sssd-ipa.5.xml:288 sssd-ad.5.xml:1292 msgid "Default: False (let nsupdate choose the protocol)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:299 sssd-ad.5.xml:1335 +#: sssd-ipa.5.xml:294 sssd-ad.5.xml:1328 msgid "dyndns_server (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:302 sssd-ad.5.xml:1338 +#: sssd-ipa.5.xml:297 sssd-ad.5.xml:1331 msgid "" "The DNS server to use when performing a DNS update. In most setups, it's " "recommended to leave this option unset." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:307 sssd-ad.5.xml:1343 +#: sssd-ipa.5.xml:302 sssd-ad.5.xml:1336 msgid "" "Setting this option makes sense for environments where the DNS server is " "different from the identity server or when we use encrypted DNS." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:312 sssd-ad.5.xml:1348 +#: sssd-ipa.5.xml:307 sssd-ad.5.xml:1341 msgid "" "The parameter can be a simple string containing DNS name or IP address. It " "can also be an URI. The URI can look like <emphasis>dns://servername/</" @@ -10031,7 +10329,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:319 sssd-ad.5.xml:1355 +#: sssd-ipa.5.xml:314 sssd-ad.5.xml:1348 msgid "" "The second example enables DNS-over-TLS protocol for DNS updates. The " "nsupdate utility must support DoT - check the <emphasis>man nsupdate</" @@ -10039,7 +10337,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:325 sssd-ad.5.xml:1361 +#: sssd-ipa.5.xml:320 sssd-ad.5.xml:1354 msgid "" "Please note that this option will be only used in fallback attempt when " "previous attempt using autodetected settings failed or when DNS-over-TLS is " @@ -10047,17 +10345,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:331 sssd-ad.5.xml:1367 +#: sssd-ipa.5.xml:326 sssd-ad.5.xml:1360 msgid "Default: None (let nsupdate choose the server)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:337 sssd-ad.5.xml:1373 +#: sssd-ipa.5.xml:332 sssd-ad.5.xml:1366 msgid "dyndns_update_per_family (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:340 sssd-ad.5.xml:1376 +#: sssd-ipa.5.xml:335 sssd-ad.5.xml:1369 msgid "" "DNS update is by default performed in two steps - IPv4 update and then IPv6 " "update. In some cases it might be desirable to perform IPv4 and IPv6 update " @@ -10065,12 +10363,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:352 sssd-ad.5.xml:1388 +#: sssd-ipa.5.xml:347 sssd-ad.5.xml:1381 msgid "dyndns_dot_cacert (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:355 sssd-ad.5.xml:1391 +#: sssd-ipa.5.xml:350 sssd-ad.5.xml:1384 msgid "" "This option specifies the file of the certificate authorities certificates " "(in PEM format) in order to verify the remote server TLS certificate when " @@ -10078,17 +10376,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:361 sssd-ad.5.xml:1397 +#: sssd-ipa.5.xml:356 sssd-ad.5.xml:1390 msgid "Default: None (use global certificate store)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:367 sssd-ad.5.xml:1403 +#: sssd-ipa.5.xml:362 sssd-ad.5.xml:1396 msgid "dyndns_dot_cert (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:370 sssd-ad.5.xml:1406 +#: sssd-ipa.5.xml:365 sssd-ad.5.xml:1399 msgid "" "This option sets the certificate(s) file for authentication for the DoT " "transport to the remote server. The certificate chain file is expected to be " @@ -10096,24 +10394,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:376 sssd-ad.5.xml:1412 +#: sssd-ipa.5.xml:371 sssd-ad.5.xml:1405 msgid "" "The <emphasis>dyndns_dot_cert</emphasis> and <emphasis>dyndns_dot_key</" "emphasis> options must be both set to achieve mutual TLS authentication." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:381 sssd-ipa.5.xml:396 sssd-ad.5.xml:1417 sssd-ad.5.xml:1432 +#: sssd-ipa.5.xml:376 sssd-ipa.5.xml:391 sssd-ad.5.xml:1410 sssd-ad.5.xml:1425 msgid "Default: None (Do not use TLS authentication)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:387 sssd-ad.5.xml:1423 +#: sssd-ipa.5.xml:382 sssd-ad.5.xml:1416 msgid "dyndns_dot_key (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:390 sssd-ad.5.xml:1426 +#: sssd-ipa.5.xml:385 sssd-ad.5.xml:1419 msgid "" "This option sets the key file for authenticated encryption for the DoT " "transport to the remote server. The private key file is expected to be in " @@ -10121,170 +10419,170 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:402 +#: sssd-ipa.5.xml:397 msgid "ipa_access_order (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:409 +#: sssd-ipa.5.xml:404 msgid "<emphasis>expire</emphasis>: use IPA's account expiration policy." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:448 +#: sssd-ipa.5.xml:443 msgid "" "Please note that 'access_provider = ipa' must be set for this feature to " "work." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:455 +#: sssd-ipa.5.xml:450 msgid "ipa_deskprofile_search_base (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:458 +#: sssd-ipa.5.xml:453 msgid "" "Optional. Use the given string as search base for Desktop Profile related " "objects." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:462 sssd-ipa.5.xml:484 +#: sssd-ipa.5.xml:457 sssd-ipa.5.xml:479 msgid "Default: Use base DN" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:468 +#: sssd-ipa.5.xml:463 msgid "ipa_subid_ranges_search_base (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:471 +#: sssd-ipa.5.xml:466 msgid "Deprecated. Use ldap_subid_ranges_search_base instead." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:477 +#: sssd-ipa.5.xml:472 msgid "ipa_hbac_search_base (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:480 +#: sssd-ipa.5.xml:475 msgid "Optional. Use the given string as search base for HBAC related objects." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:490 +#: sssd-ipa.5.xml:485 msgid "ipa_host_search_base (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:493 +#: sssd-ipa.5.xml:488 msgid "Deprecated. Use ldap_host_search_base instead." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:499 +#: sssd-ipa.5.xml:494 msgid "ipa_selinux_search_base (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:502 +#: sssd-ipa.5.xml:497 msgid "Optional. Use the given string as search base for SELinux user maps." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:518 +#: sssd-ipa.5.xml:513 msgid "ipa_subdomains_search_base (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:521 +#: sssd-ipa.5.xml:516 msgid "Optional. Use the given string as search base for trusted domains." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:530 +#: sssd-ipa.5.xml:525 msgid "Default: the value of <emphasis>cn=trusts,%basedn</emphasis>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:537 +#: sssd-ipa.5.xml:532 msgid "ipa_master_domain_search_base (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:540 +#: sssd-ipa.5.xml:535 msgid "Optional. Use the given string as search base for master domain object." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:549 +#: sssd-ipa.5.xml:544 msgid "Default: the value of <emphasis>cn=ad,cn=etc,%basedn</emphasis>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:556 +#: sssd-ipa.5.xml:551 msgid "ipa_views_search_base (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:559 +#: sssd-ipa.5.xml:554 msgid "Optional. Use the given string as search base for views containers." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:568 +#: sssd-ipa.5.xml:563 msgid "Default: the value of <emphasis>cn=views,cn=accounts,%basedn</emphasis>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:578 +#: sssd-ipa.5.xml:573 msgid "" "The name of the Kerberos realm. This is optional and defaults to the value " "of <quote>ipa_domain</quote>." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:582 +#: sssd-ipa.5.xml:577 msgid "" "The name of the Kerberos realm has a special meaning in IPA - it is " "converted into the base DN to use for performing LDAP operations." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:590 sssd-ad.5.xml:1441 +#: sssd-ipa.5.xml:585 sssd-ad.5.xml:1434 msgid "krb5_confd_path (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:593 sssd-ad.5.xml:1444 +#: sssd-ipa.5.xml:588 sssd-ad.5.xml:1437 msgid "" "Absolute path of a directory where SSSD should place Kerberos configuration " "snippets." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:597 sssd-ad.5.xml:1448 +#: sssd-ipa.5.xml:592 sssd-ad.5.xml:1441 msgid "" "To disable the creation of the configuration snippets set the parameter to " "'none'." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:601 sssd-ad.5.xml:1452 +#: sssd-ipa.5.xml:596 sssd-ad.5.xml:1445 msgid "" "Default: not set (krb5.include.d subdirectory of SSSD's pubconf directory)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:608 +#: sssd-ipa.5.xml:603 msgid "ipa_deskprofile_refresh (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:611 +#: sssd-ipa.5.xml:606 msgid "" "The amount of time between lookups of the Desktop Profile rules against the " "IPA server. This will reduce the latency and load on the IPA server if there " @@ -10292,34 +10590,34 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:618 sssd-ipa.5.xml:648 sssd-ipa.5.xml:664 sssd-ad.5.xml:600 +#: sssd-ipa.5.xml:613 sssd-ipa.5.xml:643 sssd-ipa.5.xml:659 sssd-ad.5.xml:600 msgid "Default: 5 (seconds)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:624 +#: sssd-ipa.5.xml:619 msgid "ipa_deskprofile_request_interval (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:627 +#: sssd-ipa.5.xml:622 msgid "" "The amount of time between lookups of the Desktop Profile rules against the " "IPA server in case the last request did not return any rule." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:632 +#: sssd-ipa.5.xml:627 msgid "Default: 60 (minutes)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:638 +#: sssd-ipa.5.xml:633 msgid "ipa_hbac_refresh (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:641 +#: sssd-ipa.5.xml:636 msgid "" "The amount of time between lookups of the HBAC rules against the IPA server. " "This will reduce the latency and load on the IPA server if there are many " @@ -10327,12 +10625,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:654 -msgid "ipa_hbac_selinux (integer)" +#: sssd-ipa.5.xml:649 +msgid "ipa_selinux_refresh (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:657 +#: sssd-ipa.5.xml:652 msgid "" "The amount of time between lookups of the SELinux maps against the IPA " "server. This will reduce the latency and load on the IPA server if there are " @@ -10340,33 +10638,33 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:670 +#: sssd-ipa.5.xml:665 msgid "ipa_server_mode (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:673 +#: sssd-ipa.5.xml:668 msgid "" "This option will be set by the IPA installer (ipa-server-install) " "automatically and denotes if SSSD is running on an IPA server or not." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:678 +#: sssd-ipa.5.xml:673 msgid "" "On an IPA server SSSD will lookup users and groups from trusted domains " "directly while on a client it will ask an IPA server." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:683 +#: sssd-ipa.5.xml:678 msgid "" "NOTE: There are currently some assumptions that must be met when SSSD is " "running on an IPA server." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:688 +#: sssd-ipa.5.xml:683 msgid "" "The <quote>ipa_server</quote> option must be configured to point to the IPA " "server itself. This is already the default set by the IPA installer, so no " @@ -10374,59 +10672,59 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:697 +#: sssd-ipa.5.xml:692 msgid "" "The <quote>full_name_format</quote> option must not be tweaked to only print " "short names for users from trusted domains." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:712 +#: sssd-ipa.5.xml:707 msgid "ipa_automount_location (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:715 +#: sssd-ipa.5.xml:710 msgid "The automounter location this IPA client will be using" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:718 +#: sssd-ipa.5.xml:713 msgid "Default: The location named \"default\"" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd-ipa.5.xml:726 +#: sssd-ipa.5.xml:721 msgid "VIEWS AND OVERRIDES" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:735 +#: sssd-ipa.5.xml:730 msgid "ipa_view_class (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:738 +#: sssd-ipa.5.xml:733 msgid "Objectclass of the view container." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:741 +#: sssd-ipa.5.xml:736 msgid "Default: nsContainer" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:747 +#: sssd-ipa.5.xml:742 msgid "ipa_view_name (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:750 +#: sssd-ipa.5.xml:745 msgid "Name of the attribute holding the name of the view." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:754 sssd-ldap-attributes.5.xml:496 +#: sssd-ipa.5.xml:749 sssd-ldap-attributes.5.xml:496 #: sssd-ldap-attributes.5.xml:832 sssd-ldap-attributes.5.xml:913 #: sssd-ldap-attributes.5.xml:1010 sssd-ldap-attributes.5.xml:1068 #: sssd-ldap-attributes.5.xml:1226 sssd-ldap-attributes.5.xml:1271 @@ -10434,128 +10732,128 @@ msgid "Default: cn" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:760 +#: sssd-ipa.5.xml:755 msgid "ipa_override_object_class (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:763 +#: sssd-ipa.5.xml:758 msgid "Objectclass of the override objects." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:766 +#: sssd-ipa.5.xml:761 msgid "Default: ipaOverrideAnchor" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:772 +#: sssd-ipa.5.xml:767 msgid "ipa_anchor_uuid (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:775 +#: sssd-ipa.5.xml:770 msgid "" "Name of the attribute containing the reference to the original object in a " "remote domain." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:779 +#: sssd-ipa.5.xml:774 msgid "Default: ipaAnchorUUID" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:785 +#: sssd-ipa.5.xml:780 msgid "ipa_user_override_object_class (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:788 +#: sssd-ipa.5.xml:783 msgid "" "Name of the objectclass for user overrides. It is used to determine if the " "found override object is related to a user or a group." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:793 +#: sssd-ipa.5.xml:788 msgid "User overrides can contain attributes given by" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:796 +#: sssd-ipa.5.xml:791 msgid "ldap_user_name" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:799 +#: sssd-ipa.5.xml:794 msgid "ldap_user_uid_number" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:802 +#: sssd-ipa.5.xml:797 msgid "ldap_user_gid_number" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:805 +#: sssd-ipa.5.xml:800 msgid "ldap_user_gecos" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:808 +#: sssd-ipa.5.xml:803 msgid "ldap_user_home_directory" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:811 +#: sssd-ipa.5.xml:806 msgid "ldap_user_shell" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:814 +#: sssd-ipa.5.xml:809 msgid "ldap_user_ssh_public_key" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:819 +#: sssd-ipa.5.xml:814 msgid "Default: ipaUserOverride" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:825 +#: sssd-ipa.5.xml:820 msgid "ipa_group_override_object_class (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:828 +#: sssd-ipa.5.xml:823 msgid "" "Name of the objectclass for group overrides. It is used to determine if the " "found override object is related to a user or a group." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:833 +#: sssd-ipa.5.xml:828 msgid "Group overrides can contain attributes given by" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:836 +#: sssd-ipa.5.xml:831 msgid "ldap_group_name" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:839 +#: sssd-ipa.5.xml:834 msgid "ldap_group_gid_number" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:844 +#: sssd-ipa.5.xml:839 msgid "Default: ipaGroupOverride" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:728 +#: sssd-ipa.5.xml:723 msgid "" "SSSD can handle views and overrides which are offered by FreeIPA 4.1 and " "later version. Since all paths and objectclasses are fixed on the server " @@ -10565,19 +10863,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd-ipa.5.xml:856 +#: sssd-ipa.5.xml:851 msgid "SUBDOMAINS PROVIDER" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:858 +#: sssd-ipa.5.xml:853 msgid "" "The IPA subdomains provider behaves slightly differently if it is configured " "explicitly or implicitly." msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:862 +#: sssd-ipa.5.xml:857 msgid "" "If the option 'subdomains_provider = ipa' is found in the domain section of " "sssd.conf, the IPA subdomains provider is configured explicitly, and all " @@ -10585,7 +10883,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:868 +#: sssd-ipa.5.xml:863 msgid "" "If the option 'subdomains_provider' is not set in the domain section of " "sssd.conf but there is the option 'id_provider = ipa', the IPA subdomains " @@ -10597,12 +10895,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd-ipa.5.xml:879 +#: sssd-ipa.5.xml:874 msgid "TRUSTED DOMAINS CONFIGURATION" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-ipa.5.xml:887 +#: sssd-ipa.5.xml:882 #, no-wrap msgid "" "[domain/ipa.domain.com/ad.domain.com]\n" @@ -10610,7 +10908,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:881 +#: sssd-ipa.5.xml:876 msgid "" "Some configuration options can also be set for a trusted domain. A trusted " "domain configuration can be set using the trusted domain subsection as shown " @@ -10620,97 +10918,97 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:892 +#: sssd-ipa.5.xml:887 msgid "" "For more details, see the <citerefentry> <refentrytitle>sssd.conf</" "refentrytitle> <manvolnum>5</manvolnum> </citerefentry> manual page." msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:899 +#: sssd-ipa.5.xml:894 msgid "" "Different configuration options are tunable for a trusted domain depending " "on whether you are configuring SSSD on an IPA server or an IPA client." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd-ipa.5.xml:904 +#: sssd-ipa.5.xml:899 msgid "OPTIONS TUNABLE ON IPA MASTERS" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:906 +#: sssd-ipa.5.xml:901 msgid "" "The following options can be set in a subdomain section on an IPA master:" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:910 sssd-ipa.5.xml:950 +#: sssd-ipa.5.xml:905 sssd-ipa.5.xml:945 msgid "ad_server" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:913 +#: sssd-ipa.5.xml:908 msgid "ad_backup_server" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:916 sssd-ipa.5.xml:953 +#: sssd-ipa.5.xml:911 sssd-ipa.5.xml:948 msgid "ad_site" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:919 +#: sssd-ipa.5.xml:914 msgid "ipa_server" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:922 +#: sssd-ipa.5.xml:917 msgid "ipa_backup_server" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:925 +#: sssd-ipa.5.xml:920 msgid "ldap_search_base" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:928 +#: sssd-ipa.5.xml:923 msgid "ldap_user_search_base" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:931 +#: sssd-ipa.5.xml:926 msgid "ldap_group_search_base" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:939 +#: sssd-ipa.5.xml:934 msgid "" "Options prefixed with 'ad_' or 'ipa_' only apply to their respective " "subdomain type." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd-ipa.5.xml:944 +#: sssd-ipa.5.xml:939 msgid "OPTIONS TUNABLE ON IPA CLIENTS" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:946 +#: sssd-ipa.5.xml:941 msgid "" "The following options can be set in an AD subdomain section on an IPA client:" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:958 +#: sssd-ipa.5.xml:953 msgid "" "Note that if both options are set, only <quote>ad_server</quote> is " "evaluated." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:962 +#: sssd-ipa.5.xml:957 msgid "" "Since any request for a user or a group identity from a trusted domain " "triggered from an IPA client is resolved by the IPA server, the " @@ -10724,7 +11022,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:986 +#: sssd-ipa.5.xml:981 msgid "" "The following example assumes that SSSD is correctly configured and " "example.com is one of the domains in the <replaceable>[sssd]</replaceable> " @@ -10732,7 +11030,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-ipa.5.xml:993 +#: sssd-ipa.5.xml:988 #, no-wrap msgid "" "[domain/example.com]\n" @@ -11431,27 +11729,27 @@ msgid "lxdm" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:694 +#: sssd-ad.5.xml:699 msgid "sddm" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:699 +#: sssd-ad.5.xml:704 msgid "unity" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:704 +#: sssd-ad.5.xml:709 msgid "xdm" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:713 +#: sssd-ad.5.xml:718 msgid "ad_gpo_map_remote_interactive (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:716 +#: sssd-ad.5.xml:721 msgid "" "A comma-separated list of PAM service names for which GPO-based access " "control is evaluated based on the RemoteInteractiveLogonRight and " @@ -11467,7 +11765,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:735 +#: sssd-ad.5.xml:740 msgid "" "Note: Using the Group Policy Management Editor this value is called \"Allow " "log on through Remote Desktop Services\" and \"Deny log on through Remote " @@ -11475,7 +11773,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:750 +#: sssd-ad.5.xml:755 #, no-wrap msgid "" "ad_gpo_map_remote_interactive = +my_pam_service, -sshd\n" @@ -11483,7 +11781,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:741 +#: sssd-ad.5.xml:746 msgid "" "It is possible to add another PAM service name to the default set by using " "<quote>+service_name</quote> or to explicitly remove a PAM service name from " @@ -11495,22 +11793,22 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:758 +#: sssd-ad.5.xml:763 msgid "sshd" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:763 +#: sssd-ad.5.xml:768 msgid "cockpit" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:772 +#: sssd-ad.5.xml:777 msgid "ad_gpo_map_network (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:775 +#: sssd-ad.5.xml:780 msgid "" "A comma-separated list of PAM service names for which GPO-based access " "control is evaluated based on the NetworkLogonRight and " @@ -11526,7 +11824,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:793 +#: sssd-ad.5.xml:798 msgid "" "Note: Using the Group Policy Management Editor this value is called \"Access " "this computer from the network\" and \"Deny access to this computer from the " @@ -11534,7 +11832,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:808 +#: sssd-ad.5.xml:813 #, no-wrap msgid "" "ad_gpo_map_network = +my_pam_service, -ftp\n" @@ -11542,7 +11840,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:799 +#: sssd-ad.5.xml:804 msgid "" "It is possible to add another PAM service name to the default set by using " "<quote>+service_name</quote> or to explicitly remove a PAM service name from " @@ -11554,22 +11852,22 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:816 +#: sssd-ad.5.xml:821 msgid "ftp" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:821 +#: sssd-ad.5.xml:826 msgid "samba" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:830 +#: sssd-ad.5.xml:835 msgid "ad_gpo_map_batch (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:833 +#: sssd-ad.5.xml:838 msgid "" "A comma-separated list of PAM service names for which GPO-based access " "control is evaluated based on the BatchLogonRight and DenyBatchLogonRight " @@ -11584,14 +11882,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:851 +#: sssd-ad.5.xml:856 msgid "" "Note: Using the Group Policy Management Editor this value is called \"Allow " "log on as a batch job\" and \"Deny log on as a batch job\"." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:865 +#: sssd-ad.5.xml:870 #, no-wrap msgid "" "ad_gpo_map_batch = +my_pam_service, -crond\n" @@ -11599,7 +11897,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:856 +#: sssd-ad.5.xml:861 msgid "" "It is possible to add another PAM service name to the default set by using " "<quote>+service_name</quote> or to explicitly remove a PAM service name from " @@ -11611,23 +11909,23 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:868 +#: sssd-ad.5.xml:873 msgid "" "Note: Cron service name may differ depending on Linux distribution used." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:874 +#: sssd-ad.5.xml:879 msgid "crond" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:883 +#: sssd-ad.5.xml:888 msgid "ad_gpo_map_service (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:886 +#: sssd-ad.5.xml:891 msgid "" "A comma-separated list of PAM service names for which GPO-based access " "control is evaluated based on the ServiceLogonRight and " @@ -11643,14 +11941,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:904 +#: sssd-ad.5.xml:909 msgid "" "Note: Using the Group Policy Management Editor this value is called \"Allow " "log on as a service\" and \"Deny log on as a service\"." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:917 +#: sssd-ad.5.xml:922 #, no-wrap msgid "" "ad_gpo_map_service = +my_pam_service\n" @@ -11658,7 +11956,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:909 sssd-ad.5.xml:984 +#: sssd-ad.5.xml:914 sssd-ad.5.xml:989 msgid "" "It is possible to add a PAM service name to the default set by using " "<quote>+service_name</quote>. Since the default set is empty, it is not " @@ -11669,19 +11967,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:927 +#: sssd-ad.5.xml:932 msgid "ad_gpo_map_permit (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:930 +#: sssd-ad.5.xml:935 msgid "" "A comma-separated list of PAM service names for which GPO-based access is " "always granted, regardless of any GPO Logon Rights." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:944 +#: sssd-ad.5.xml:949 #, no-wrap msgid "" "ad_gpo_map_permit = +my_pam_service, -sudo\n" @@ -11689,7 +11987,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:935 +#: sssd-ad.5.xml:940 msgid "" "It is possible to add another PAM service name to the default set by using " "<quote>+service_name</quote> or to explicitly remove a PAM service name from " @@ -11701,29 +11999,29 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:952 +#: sssd-ad.5.xml:957 msgid "polkit-1" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:967 +#: sssd-ad.5.xml:972 msgid "systemd-user" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:976 +#: sssd-ad.5.xml:981 msgid "ad_gpo_map_deny (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:979 +#: sssd-ad.5.xml:984 msgid "" "A comma-separated list of PAM service names for which GPO-based access is " "always denied, regardless of any GPO Logon Rights." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:992 +#: sssd-ad.5.xml:997 #, no-wrap msgid "" "ad_gpo_map_deny = +my_pam_service\n" @@ -11731,12 +12029,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:1002 +#: sssd-ad.5.xml:1007 msgid "ad_gpo_default_right (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1005 +#: sssd-ad.5.xml:1010 msgid "" "This option defines how access control is evaluated for PAM service names " "that are not explicitly listed in one of the ad_gpo_map_* options. This " @@ -11749,52 +12047,52 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1018 +#: sssd-ad.5.xml:1023 msgid "Supported values for this option include:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1027 +#: sssd-ad.5.xml:1032 msgid "remote_interactive" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1032 +#: sssd-ad.5.xml:1037 msgid "network" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1037 +#: sssd-ad.5.xml:1042 msgid "batch" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1042 +#: sssd-ad.5.xml:1047 msgid "service" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1047 +#: sssd-ad.5.xml:1052 msgid "permit" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1052 +#: sssd-ad.5.xml:1057 msgid "deny" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1058 +#: sssd-ad.5.xml:1063 msgid "Default: deny" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:1064 +#: sssd-ad.5.xml:1069 msgid "ad_maximum_machine_account_password_age (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1067 +#: sssd-ad.5.xml:1072 msgid "" "SSSD will check once a day if the machine account password is older than the " "given age in days and try to renew it. A value of 0 will disable the renewal " @@ -11802,17 +12100,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1073 +#: sssd-ad.5.xml:1078 msgid "Default: 30 days" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:1079 +#: sssd-ad.5.xml:1084 msgid "ad_machine_account_password_renewal_opts (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1082 +#: sssd-ad.5.xml:1087 msgid "" "This option should only be used to test the machine account renewal task. " "The option expects 3 integers and a string separated by a colon (':'). The " @@ -11825,20 +12123,20 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1096 +#: sssd-ad.5.xml:1101 msgid "" "The optional fourth string value identifies the helper binary which should " "be used for the renewal. Currently <command>adcli</command> and " "<command>realm</command> are supported. If this value is missing or empty in " "the value string <command>realm</command> will be used. Since the helper is " "started as the user SSSD is running as there might be the chance that the " -"renewal will fail if this user does not has permissions to modify the keytab " -"file where the machine account credentials are stored. This will typically " -"be the case for <command>adcli</command>." +"renewal will fail if this user does not have permissions to modify the " +"keytab file where the machine account credentials are stored. This will " +"typically be the case for <command>adcli</command>." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1110 +#: sssd-ad.5.xml:1115 msgid "" "<command>realm</command> is not updating the keytab directly but is calling " "the <command>realmd</command> process, which runs as root user, for this " @@ -11848,17 +12146,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1119 +#: sssd-ad.5.xml:1124 msgid "Default: 86400:750:300:realm (24h, 12m30s and 5m)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:1125 +#: sssd-ad.5.xml:1130 msgid "ad_update_samba_machine_account_password (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1128 +#: sssd-ad.5.xml:1133 msgid "" "If enabled, when SSSD renews the machine account password, it will also be " "updated in Samba's database. This prevents Samba's copy of the machine " @@ -11867,23 +12165,23 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:1141 -msgid "ad_use_ldaps (bool)" +#: sssd-ad.5.xml:1146 +msgid "ad_use_ldaps (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1144 +#: sssd-ad.5.xml:1149 msgid "" "By default SSSD uses the plain LDAP port 389 and the Global Catalog port " -"3628. If this option is set to True SSSD will use the LDAPS port 636 and " -"Global Catalog port 3629 with LDAPS protection. Since AD does not allow to " +"3268. If this option is set to True SSSD will use the LDAPS port 636 and " +"Global Catalog port 3269 with LDAPS protection. Since AD does not allow to " "have multiple encryption layers on a single connection and we still want to " "use SASL/GSSAPI or SASL/GSS-SPNEGO for authentication the SASL security " "property maxssf is set to 0 (zero) for those connections." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1164 +#: sssd-ad.5.xml:1169 msgid "" "Optional. This option tells SSSD to automatically update the Active " "Directory DNS server with the IP address of this client. The update is " @@ -11901,30 +12199,21 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:1216 msgid "" -"NOTE: While it is still possible to use the old <emphasis>ipa_dyndns_iface</" -"emphasis> option, users should migrate to using <emphasis>dyndns_iface</" -"emphasis> in their config file." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1222 -msgid "" "Default: Use the IP addresses of the interface which is used for AD LDAP " "connection" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1258 +#: sssd-ad.5.xml:1252 msgid "" "How often should the back end perform periodic DNS update in addition to the " -"automatic update performed when the back end goes online. This option is " -"optional and applicable only when dyndns_update is true. Note that the " -"lowest possible value is 60 seconds in-case if value is provided less than " -"60, parameter will assume lowest value only." +"automatic update performed when the back end goes online. This is optional " +"and applicable only when dyndns_update is true. Note that the minimum value " +"is 60 seconds, any specified value below this threshold will default to 60." msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ad.5.xml:1472 +#: sssd-ad.5.xml:1465 msgid "" "The following example assumes that SSSD is correctly configured and " "example.com is one of the domains in the <replaceable>[sssd]</replaceable> " @@ -11932,7 +12221,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-ad.5.xml:1479 +#: sssd-ad.5.xml:1472 #, no-wrap msgid "" "[domain/EXAMPLE]\n" @@ -11947,7 +12236,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-ad.5.xml:1499 +#: sssd-ad.5.xml:1492 #, no-wrap msgid "" "access_provider = ldap\n" @@ -11956,7 +12245,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ad.5.xml:1495 +#: sssd-ad.5.xml:1488 msgid "" "The AD access control provider checks if the account is expired. It has the " "same effect as the following configuration of the LDAP provider: " @@ -11964,7 +12253,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ad.5.xml:1505 +#: sssd-ad.5.xml:1498 msgid "" "However, unless the <quote>ad</quote> access control provider is explicitly " "configured, the default access provider is <quote>permit</quote>. Please " @@ -11974,7 +12263,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ad.5.xml:1513 +#: sssd-ad.5.xml:1506 msgid "" "When the autofs provider is set to <quote>ad</quote>, the RFC2307 schema " "attribute mapping (nisMap, nisObject, ...) is used, because these attributes " @@ -12128,9 +12417,9 @@ msgstr "" #: sssd-sudo.5.xml:137 msgid "" "The <emphasis>smart refresh</emphasis> periodically downloads rules that are " -"new or were modified after the last update. Its primary goal is to keep the " -"database growing by fetching only small increments that do not generate " -"large amounts of network traffic." +"new or were modified after the last update. Its primary goal is to grow the " +"database incrementally by fetching only small updates, avoiding large " +"amounts of network traffic." msgstr "" #. type: Content of: <reference><refentry><refsect1><para> @@ -12310,24 +12599,27 @@ msgstr "" msgid "" "Depending on the IdP product additional platform specific options might " "follow the name separated by a colon (:). E.g. for Keycloak the base URI for " -"the user and group REST API must be given. For Entra ID this is not needed " -"because there is a generic endpoint for all tenants." +"the user and group REST API must be given. For Entra ID the base URI for the " +"Microsoft Graph API can be given to use sovereign or government cloud " +"endpoints instead of the default (https://graph.microsoft.com/v1.0). E.g. " +"<quote>entra_id:https://graph.microsoft.us/v1.0</quote> for the US " +"government cloud (GCC High)." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:78 sssd-idp.5.xml:94 sssd-idp.5.xml:119 +#: sssd-idp.5.xml:82 sssd-idp.5.xml:98 sssd-idp.5.xml:123 #, fuzzy #| msgid "Default: 0 (unlimited)" msgid "Default: Not set (Required)" msgstr "Пешфарз: 0 (номаҳдуд)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:83 +#: sssd-idp.5.xml:87 msgid "idp_client_id (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:86 +#: sssd-idp.5.xml:90 msgid "" "ID of the IdP client used by SSSD to authenticate users and as a client to " "lookup user and group attributes. This client must offer device " @@ -12336,12 +12628,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:99 +#: sssd-idp.5.xml:103 msgid "idp_client_secret (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:102 +#: sssd-idp.5.xml:106 msgid "" "Password of the IdP client. The password is required for the id_provider. If " "only used as auth_provider it depends on the server side configuration if it " @@ -12349,66 +12641,73 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:113 +#: sssd-idp.5.xml:117 msgid "idp_token_endpoint (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:116 +#: sssd-idp.5.xml:120 msgid "IdP endpoint for requesting access tokens." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:124 +#: sssd-idp.5.xml:128 msgid "idp_device_auth_endpoint (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:127 +#: sssd-idp.5.xml:131 msgid "" "IdP endpoint for device authorization according to RFC-8628. This is " "required for user authentication." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:137 +#: sssd-idp.5.xml:141 msgid "idp_userinfo_endpoint (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:140 +#: sssd-idp.5.xml:144 msgid "" "IdP userinfo endpoint to request user attributes after a successful " "authentication of the user. Required for authentication." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:150 +#: sssd-idp.5.xml:154 msgid "idp_id_scope (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:153 +#: sssd-idp.5.xml:157 msgid "" "Scope required for looking up user and group attributes with the REST API. " "The scopes are used by the server to determine which attributes/claims are " "returned to the caller." msgstr "" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:163 +msgid "" +"Note: In previous versions of SSSD, this option was expected to already be " +"URL-encoded." +msgstr "" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:164 +#: sssd-idp.5.xml:172 msgid "idp_auth_scope (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:167 +#: sssd-idp.5.xml:175 msgid "" "Scope required during authentication. The scopes are used by the server to " "determine which attributes/claims are returned to the caller." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:172 +#: sssd-idp.5.xml:180 msgid "" "Currently the tokens returned during user authentication are not used for " "other purposes hence the only important claim is the subject identifier " @@ -12417,22 +12716,116 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:185 +#: sssd-idp.5.xml:193 +msgid "idp_auth_user_identifier_attr (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:196 +msgid "" +"Attribute used to identify the authenticated user in userinfo data or token " +"claims." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:200 +msgid "" +"For hybrid Active Directory and Entra ID deployments where " +"<quote>id_provider = ad</quote> and <quote>auth_provider = idp</quote>, this " +"option must be set explicitly. No value is derived from the identity " +"provider, because more than one attribute can link an Entra ID object to its " +"on-premises counterpart and only the administrator knows which one the " +"directory synchronization is configured to use." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:211 +msgid "" +"Setting this option to <quote>onPremisesImmutableId</quote> is the usual " +"choice for such deployments. Microsoft Entra Connect populates that " +"attribute with the base64-encoded form of the 16-byte Active Directory " +"<quote>objectGUID</quote> when objectGUID is used as the sourceAnchor. SSSD " +"decodes the value and converts the raw bytes with the same conversion used " +"for AD objectGUID attributes, so the result matches the UUID stored in the " +"SSSD cache for the AD user." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:224 +msgid "" +"Note that Microsoft Entra Connect 1.1.524.0 and later use <quote>ms-DS-" +"ConsistencyGuid</quote> as the sourceAnchor for user objects instead of " +"<quote>objectGUID</quote>. The value is normally copied from objectGUID for " +"objects that do not have it set yet, in which case the decoded identifier " +"still matches. It does not match if ms-DS-ConsistencyGuid was populated " +"independently, if users were moved between forests or domains, or if a " +"different attribute such as employeeID was selected as the sourceAnchor. See " +"<ulink url=\"https://learn.microsoft.com/en-us/entra/identity/hybrid/connect/" +"plan-connect-design-concepts\"> Microsoft Entra Connect: Design concepts</" +"ulink> for details on sourceAnchor selection." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:241 +msgid "" +"Microsoft Graph does not return <quote>onPremisesImmutableId</quote> by " +"default. The <quote>idp_userinfo_endpoint</quote> must request it with " +"<quote>$select</quote>, see the example below and <ulink url=\"https://" +"learn.microsoft.com/en-us/graph/api/resources/user\"> the Microsoft Graph " +"user resource type</ulink>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:251 +msgid "" +"If the configured attribute is missing or cannot be decoded (for example " +"cloud-only Entra ID users without <quote>onPremisesImmutableId</quote>), " +"authentication fails. SSSD does not fall back to another attribute when this " +"option is set." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:258 +msgid "" +"Default: not set, <quote>sub</quote> for Keycloak and <quote>id</quote> for " +"other IdP types" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-idp.5.xml:264 msgid "idp_request_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:188 +#: sssd-idp.5.xml:267 msgid "Timeout in seconds for an individual request to the IdP." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:197 +#: sssd-idp.5.xml:276 +msgid "idp_auto_refresh (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:279 +msgid "" +"Refresh tokens automatically, after they have reached about half their " +"lifetime." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:283 +msgid "" +"Note: Scheduled token refreshes are not preserved across restarts of SSSD." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-idp.5.xml:292 msgid "idmap_range_min (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:200 +#: sssd-idp.5.xml:295 msgid "" "Specifies the lower (inclusive) bound of the range of POSIX IDs to use for " "mapping IdP users and group to POSIX IDs. It is the first POSIX ID which can " @@ -12440,7 +12833,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:206 +#: sssd-idp.5.xml:301 msgid "" "The interval between <quote>idmap_range_min</quote> and " "<quote>idmap_range_max</quote> will be split into smaller ranges of size " @@ -12449,18 +12842,18 @@ msgid "" msgstr "" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:213 sssd-idp.5.xml:239 include/ldap_id_mapping.xml:139 +#: sssd-idp.5.xml:308 sssd-idp.5.xml:334 include/ldap_id_mapping.xml:139 #: include/ldap_id_mapping.xml:197 msgid "Default: 200000" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:218 +#: sssd-idp.5.xml:313 msgid "idmap_range_max (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:221 +#: sssd-idp.5.xml:316 msgid "" "Specifies the upper (exclusive) bound of the range of POSIX IDs to use for " "mapping IdP users and groups to POSIX IDs. It is the first POSIX ID which " @@ -12468,45 +12861,68 @@ msgid "" msgstr "" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:227 include/ldap_id_mapping.xml:165 +#: sssd-idp.5.xml:322 include/ldap_id_mapping.xml:165 msgid "Default: 2000200000" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:232 +#: sssd-idp.5.xml:327 msgid "idmap_range_size (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:235 +#: sssd-idp.5.xml:330 msgid "Specifies the number of POSIX IDs available for a single IdP domain." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-idp.5.xml:251 +#: sssd-idp.5.xml:346 #, no-wrap msgid "" "[domain/entra_id]\n" "id_provider = idp\n" "idp_type = entra_id\n" "idp_client_id = 12345678-abcd-0101-efef-ba9876543210\n" -"idp_client_secret = YOUR-CLIENT-SCERET\n" -"idp_token_endpoint = https://login.microsoftonline.com/TENNANT-ID/oauth2/v2.0/token\n" +"idp_client_secret = YOUR-CLIENT-SECRET\n" +"idp_token_endpoint = https://login.microsoftonline.com/TENANT-ID/oauth2/v2.0/token\n" "idp_userinfo_endpoint = https://graph.microsoft.com/v1.0/me\n" -"idp_device_auth_endpoint = https://login.microsoftonline.com/TENNANT-ID/oauth2/v2.0/devicecode\n" -"idp_id_scope = https%3A%2F%2Fgraph.microsoft.com%2F.default\n" +"idp_device_auth_endpoint = https://login.microsoftonline.com/TENANT-ID/oauth2/v2.0/devicecode\n" +"idp_id_scope = https://graph.microsoft.com/.default\n" +"idp_auth_scope = openid profile email\n" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><programlisting> +#: sssd-idp.5.xml:358 +#, no-wrap +msgid "" +"[domain/ad.example.com]\n" +"id_provider = ad\n" +"auth_provider = idp\n" +"access_provider = permit\n" +"\n" +"ad_domain = ad.example.com\n" +"krb5_realm = AD.EXAMPLE.COM\n" +"\n" +"idp_type = entra_id\n" +"idp_client_id = 12345678-abcd-0101-efef-ba9876543210\n" +"idp_client_secret = YOUR-CLIENT-SECRET\n" +"idp_token_endpoint = https://login.microsoftonline.com/TENANT-ID/oauth2/v2.0/token\n" +"idp_userinfo_endpoint = https://graph.microsoft.com/v1.0/me?$select=id,userPrincipalName,onPremisesImmutableId\n" +"idp_device_auth_endpoint = https://login.microsoftonline.com/TENANT-ID/oauth2/v2.0/devicecode\n" +"idp_id_scope = https://graph.microsoft.com/.default\n" "idp_auth_scope = openid profile email\n" +"idp_auth_user_identifier_attr = onPremisesImmutableId\n" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-idp.5.xml:263 +#: sssd-idp.5.xml:377 #, no-wrap msgid "" "[domain/keycloak]\n" "idp_type = keycloak:https://master.keycloak.test:8443/auth/admin/realms/master/\n" "id_provider = idp\n" "idp_client_id = myclient\n" -"idp_client_secret = YOUR-CLIENT-SCERET\n" +"idp_client_secret = YOUR-CLIENT-SECRET\n" "idp_token_endpoint = https://master.keycloak.test:8443/auth/realms/master/protocol/openid-connect/token\n" "idp_userinfo_endpoint = https://master.keycloak.test:8443/auth/realms/master/protocol/openid-connect/userinfo\n" "idp_device_auth_endpoint = https://master.keycloak.test:8443/auth/realms/master/protocol/openid-connect/auth/device\n" @@ -12515,10 +12931,22 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-idp.5.xml:250 +#: sssd-idp.5.xml:345 msgid "" "<placeholder type=\"programlisting\" id=\"0\"/> <placeholder " -"type=\"programlisting\" id=\"1\"/>" +"type=\"programlisting\" id=\"1\"/> <placeholder type=\"programlisting\" " +"id=\"2\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-idp.5.xml:390 +msgid "" +"In the hybrid Active Directory and Entra ID example above, " +"<quote>onPremisesImmutableId</quote> is used during authentication so the " +"IdP result matches the AD objectGUID UUID stored in the SSSD cache. The " +"attribute must be requested via <quote>$select</quote> on the Graph userinfo " +"endpoint and is only populated for users synchronized from Active Directory " +"with objectGUID as the sourceAnchor." msgstr "" #. type: Content of: <reference><refentry><refnamediv><refname> @@ -13484,7 +13912,7 @@ msgstr "" #: sssd-krb5.5.xml:291 msgid "" "<emphasis>demand</emphasis> to use FAST. The authentication fails if the " -"server does not require fast." +"server does not support FAST." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> @@ -14373,7 +14801,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sss_rpcidmapd.5.xml:69 -msgid "memcache (bool)" +msgid "memcache (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> @@ -14427,7 +14855,7 @@ msgid "" msgstr "" #. type: Content of: <refsect1><title> -#: sss_rpcidmapd.5.xml:120 sssd-kcm.8.xml:316 include/seealso.xml:2 +#: sss_rpcidmapd.5.xml:120 sssd-kcm.8.xml:315 include/seealso.xml:2 msgid "SEE ALSO" msgstr "" @@ -14654,8 +15082,8 @@ msgstr "" #: sss_ssh_knownhosts.1.xml:93 msgid "" "The key lines retrieved from the backend are expected to respect the key " -"format as decribed in the <quote>SSH_KNOWN_HOSTS FILE FORMAT</quote> section " -"of <citerefentry><refentrytitle>sshd</refentrytitle> <manvolnum>8</" +"format as described in the <quote>SSH_KNOWN_HOSTS FILE FORMAT</quote> " +"section of <citerefentry><refentrytitle>sshd</refentrytitle> <manvolnum>8</" "manvolnum></citerefentry>. However, returning only the keytype and the key " "itself is tolerated, in which case, the hostname received as parameter will " "be added before the keytype to output a correctly formatted line. The " @@ -15131,14 +15559,13 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-kcm.8.xml:215 msgid "" -"The KCM service is configured in the <quote>kcm</quote> For a detailed " -"syntax reference, refer to the <quote>FILE FORMAT</quote> section of the " -"<citerefentry> <refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</" -"manvolnum> </citerefentry> manual page." +"For a detailed syntax reference, refer to the <quote>FILE FORMAT</quote> " +"section of the <citerefentry> <refentrytitle>sssd.conf</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry> manual page." msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-kcm.8.xml:223 +#: sssd-kcm.8.xml:222 msgid "" "The generic SSSD service options such as <quote>debug_level</quote> or " "<quote>fd_limit</quote> are accepted by the kcm service. Please refer to " @@ -15148,22 +15575,22 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:234 +#: sssd-kcm.8.xml:233 msgid "socket_path (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:237 +#: sssd-kcm.8.xml:236 msgid "The socket the KCM service will listen on." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:240 +#: sssd-kcm.8.xml:239 msgid "Default: <replaceable>/var/run/.heim_org.h5l.kcm-socket</replaceable>" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:243 +#: sssd-kcm.8.xml:242 msgid "" "<phrase condition=\"have_systemd\"> Note: on platforms where systemd is " "supported, the socket path is overwritten by the one defined in the sssd-" @@ -15171,88 +15598,88 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:252 +#: sssd-kcm.8.xml:251 msgid "max_ccaches (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:255 +#: sssd-kcm.8.xml:254 msgid "How many credential caches does the KCM database allow for all users." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:259 +#: sssd-kcm.8.xml:258 msgid "Default: 0 (unlimited, only the per-UID quota is enforced)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:264 +#: sssd-kcm.8.xml:263 msgid "max_uid_ccaches (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:267 +#: sssd-kcm.8.xml:266 msgid "" "How many credential caches does the KCM database allow per UID. This is " "equivalent to <quote>with how many principals you can kinit</quote>." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:272 +#: sssd-kcm.8.xml:271 msgid "Default: 64" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:277 +#: sssd-kcm.8.xml:276 msgid "max_ccache_size (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:280 +#: sssd-kcm.8.xml:279 msgid "" -"How big can a credential cache be per ccache. Each service ticket accounts " -"into this quota." +"How big a credential cache be per ccache. Each service ticket counts toward " +"this quota." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:284 +#: sssd-kcm.8.xml:283 msgid "Default: 65536" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:289 -msgid "tgt_renewal (bool)" +#: sssd-kcm.8.xml:288 +msgid "tgt_renewal (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:292 +#: sssd-kcm.8.xml:291 msgid "Enables TGT renewals functionality." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:295 +#: sssd-kcm.8.xml:294 msgid "Default: False (Automatic renewals disabled)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:300 +#: sssd-kcm.8.xml:299 msgid "tgt_renewal_inherit (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:303 +#: sssd-kcm.8.xml:302 msgid "Domain to inherit krb5_* options from, for use with TGT renewals." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:307 +#: sssd-kcm.8.xml:306 #, fuzzy #| msgid "Default: 3" msgid "Default: NULL" msgstr "Пешфарз: 3" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-kcm.8.xml:318 +#: sssd-kcm.8.xml:317 msgid "" "<citerefentry> <refentrytitle>sssd</refentrytitle><manvolnum>8</manvolnum> </" "citerefentry>, <citerefentry> <refentrytitle>sssd.conf</" @@ -16156,8 +16583,8 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap-attributes.5.xml:381 sssd-ldap-attributes.5.xml:395 -msgid "Default: loginDisabled" +#: sssd-ldap-attributes.5.xml:381 +msgid "Default: loginDisabled (rfc2307, rfc2307bis and IPA), not set (AD)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> @@ -16172,6 +16599,12 @@ msgid "" "which date access is granted." msgstr "" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:395 +msgid "" +"Default: loginExpirationTime (rfc2307, rfc2307bis and IPA), not set (AD)" +msgstr "" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:401 msgid "ldap_user_nds_login_allowed_time_map (string)" @@ -16186,7 +16619,8 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:409 -msgid "Default: loginAllowedTimeMap" +msgid "" +"Default: loginAllowedTimeMap (rfc2307, rfc2307bis and IPA), not set (AD)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> @@ -16700,8 +17134,8 @@ msgid "The object class of a host entry in LDAP." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap-attributes.5.xml:900 sssd-ldap-attributes.5.xml:997 -msgid "Default: ipService" +#: sssd-ldap-attributes.5.xml:900 sssd-ldap-attributes.5.xml:1213 +msgid "Default: ipHost" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> @@ -16786,6 +17220,11 @@ msgstr "" msgid "The object class of a service entry in LDAP." msgstr "" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:997 +msgid "Default: ipService" +msgstr "" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1003 msgid "ldap_service_name (string)" @@ -17026,11 +17465,6 @@ msgstr "" msgid "The object class of an iphost entry in LDAP." msgstr "" -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap-attributes.5.xml:1213 -msgid "Default: ipHost" -msgstr "" - #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1219 msgid "ldap_iphost_name (string)" @@ -17260,6 +17694,7 @@ msgstr "" msgid "" "[plugins]\n" " localauth = {\n" +" disable = an2ln\n" " module = sssd:/usr/lib64/sssd/modules/sssd_krb5_localauth_plugin.so\n" " }\n" msgstr "" @@ -17276,6 +17711,28 @@ msgid "" "the local Kerberos configuration the plugin will be enabled automatically." msgstr "" +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_localauth_plugin.8.xml:67 +msgid "" +"This configuration snippet also disables the <command>an2ln</command> module " +"provided by MIT Kerberos if SSSD is configured to use the AD or IPA " +"provider. In those environments <command>sssd_krb5_localauth_plugin</" +"command> can reliably map the system user names to Kerberos principals. A " +"fallback to <command>an2ln</command> might cause issues in environments " +"where users have the privilege to create Kerberos principals on their own " +"which might collide with names of other users used in the system. Other " +"modules provided by MIT Kerberos, e.g. <command>k5login</command> are not " +"affected." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_localauth_plugin.8.xml:79 +msgid "" +"Note: If using <quote>auth_provider = krb5</quote> then " +"<command>sssd_krb5_localauth_plugin</command> is not used, therefore the " +"above text is not applicable." +msgstr "" + #. type: Content of: <variablelist><varlistentry><term> #: include/autofs_attributes.xml:3 msgid "ldap_autofs_map_object_class (string)" @@ -18132,30 +18589,6 @@ msgid "" "failures; corresponds to setting 2 in decimal notation)" msgstr "" -#. type: Content of: <refsect1><title> -#: include/local.xml:2 -msgid "THE LOCAL DOMAIN" -msgstr "" - -#. type: Content of: <refsect1><para> -#: include/local.xml:4 -msgid "" -"In order to function correctly, a domain with <quote>id_provider=local</" -"quote> must be created and the SSSD must be running." -msgstr "" - -#. type: Content of: <refsect1><para> -#: include/local.xml:9 -msgid "" -"The administrator might want to use the SSSD local users instead of " -"traditional UNIX users in cases where the group nesting (see <citerefentry> " -"<refentrytitle>sss_groupadd</refentrytitle> <manvolnum>8</manvolnum> </" -"citerefentry>) is needed. The local users are also useful for testing and " -"development of the SSSD without having to deploy a full remote server. The " -"<command>sss_user*</command> and <command>sss_group*</command> tools use a " -"local LDB storage to store users and groups." -msgstr "" - #. type: Content of: <refsect1><para> #: include/seealso.xml:4 msgid "" diff --git a/src/man/po/tr.po b/src/man/po/tr.po index b8a585deed9..533084df653 100644 --- a/src/man/po/tr.po +++ b/src/man/po/tr.po @@ -8,7 +8,7 @@ msgstr "" "Project-Id-Version: sssd-docs 2.12.0\n" "Report-Msgid-Bugs-To: sssd-devel@redhat.com\n" "POT-Creation-Date: 2026-01-14 15:00+0000\n" -"PO-Revision-Date: 2026-04-23 16:41+0000\n" +"PO-Revision-Date: 2026-10-05 17:26+0000\n" "Last-Translator: Anonymous <noreply@weblate.org>\n" "Language-Team: Turkish <https://translate.fedoraproject.org/projects/sssd/" "sssd-manpage-master/tr/>\n" @@ -17,7 +17,7 @@ msgstr "" "Content-Type: text/plain; charset=UTF-8\n" "Content-Transfer-Encoding: 8bit\n" "Plural-Forms: nplurals=2; plural=n != 1;\n" -"X-Generator: Weblate 5.17\n" +"X-Generator: Weblate 2026.10\n" #. type: Content of: <reference><title> #: sssd.conf.5.xml:8 sssd-ldap.5.xml:5 pam_sss.8.xml:5 pam_sss_gss.8.xml:5 diff --git a/src/man/po/uk.po b/src/man/po/uk.po index 76ecb77013e..096d3466f6a 100644 --- a/src/man/po/uk.po +++ b/src/man/po/uk.po @@ -15,8 +15,8 @@ msgid "" msgstr "" "Project-Id-Version: sssd-docs 2.3.0\n" "Report-Msgid-Bugs-To: sssd-devel@redhat.com\n" -"POT-Creation-Date: 2026-01-14 15:00+0000\n" -"PO-Revision-Date: 2026-04-23 16:32+0000\n" +"POT-Creation-Date: 2026-10-05 16:14+0000\n" +"PO-Revision-Date: 2026-10-05 17:09+0000\n" "Last-Translator: Yuri Chornoivan <yurchor@ukr.net>\n" "Language-Team: Ukrainian <https://translate.fedoraproject.org/projects/sssd/" "sssd-manpage-master/uk/>\n" @@ -26,10 +26,10 @@ msgstr "" "Content-Transfer-Encoding: 8bit\n" "Plural-Forms: nplurals=3; plural=n%10==1 && n%100!=11 ? 0 : n%10>=2 && " "n%10<=4 && (n%100<10 || n%100>=20) ? 1 : 2;\n" -"X-Generator: Weblate 5.17\n" +"X-Generator: Weblate 2026.10\n" #. type: Content of: <reference><title> -#: sssd.conf.5.xml:8 sssd-ldap.5.xml:5 pam_sss.8.xml:5 pam_sss_gss.8.xml:5 +#: sssd.conf.5.xml:10 sssd-ldap.5.xml:5 pam_sss.8.xml:5 pam_sss_gss.8.xml:5 #: sssd_krb5_locator_plugin.8.xml:5 sssd-simple.5.xml:5 sss-certmap.5.xml:5 #: sssd-ipa.5.xml:5 sssd-ad.5.xml:5 sssd-sudo.5.xml:5 sssd-idp.5.xml:5 #: sssd.8.xml:5 sss_obfuscate.8.xml:5 sss_override.8.xml:5 sssd-krb5.5.xml:5 @@ -42,12 +42,12 @@ msgid "SSSD Manual pages" msgstr "Сторінки підручника SSSD" #. type: Content of: <reference><refentry><refnamediv><refname> -#: sssd.conf.5.xml:13 sssd.conf.5.xml:19 +#: sssd.conf.5.xml:15 sssd.conf.5.xml:21 msgid "sssd.conf" msgstr "sssd.conf" #. type: Content of: <reference><refentry><refmeta><manvolnum> -#: sssd.conf.5.xml:14 sssd-ldap.5.xml:11 sssd-simple.5.xml:11 +#: sssd.conf.5.xml:16 sssd-ldap.5.xml:11 sssd-simple.5.xml:11 #: sss-certmap.5.xml:11 sssd-ipa.5.xml:11 sssd-ad.5.xml:11 sssd-sudo.5.xml:11 #: sssd-idp.5.xml:11 sssd-krb5.5.xml:11 sssd-ifp.5.xml:11 #: sss_rpcidmapd.5.xml:27 sssd-session-recording.5.xml:11 @@ -56,7 +56,7 @@ msgid "5" msgstr "5" #. type: Content of: <reference><refentry><refmeta><refmiscinfo> -#: sssd.conf.5.xml:15 sssd-ldap.5.xml:12 sssd-simple.5.xml:12 +#: sssd.conf.5.xml:17 sssd-ldap.5.xml:12 sssd-simple.5.xml:12 #: sss-certmap.5.xml:12 sssd-ipa.5.xml:12 sssd-ad.5.xml:12 sssd-sudo.5.xml:12 #: sssd-idp.5.xml:12 sssd-krb5.5.xml:12 sssd-ifp.5.xml:12 #: sss_rpcidmapd.5.xml:28 sssd-session-recording.5.xml:12 sssd-kcm.8.xml:12 @@ -65,17 +65,17 @@ msgid "File Formats and Conventions" msgstr "Формати файлів та правила" #. type: Content of: <reference><refentry><refnamediv><refpurpose> -#: sssd.conf.5.xml:20 +#: sssd.conf.5.xml:22 msgid "the configuration file for SSSD" msgstr "файл налаштування SSSD" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:24 +#: sssd.conf.5.xml:26 msgid "FILE FORMAT" msgstr "ФОРМАТ ФАЙЛА" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd.conf.5.xml:32 +#: sssd.conf.5.xml:34 #, no-wrap msgid "" "<replaceable>[section]</replaceable>\n" @@ -90,7 +90,7 @@ msgstr "" " " #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:27 +#: sssd.conf.5.xml:29 msgid "" "The file has an ini-style syntax and consists of sections and parameters. A " "section begins with the name of the section in square brackets and continues " @@ -104,16 +104,17 @@ msgstr "" "<placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:39 +#: sssd.conf.5.xml:41 msgid "" -"The data types used are string (no quotes needed), integer and bool (with " -"values of <quote>TRUE/FALSE</quote>)." +"The data types used are string (no quotes needed), integer and boolean (with " +"values of <quote>TRUE/FALSE</quote>). Boolean values are case-insensitive; " +"for example, <quote>TRUE</quote>, <quote>True</quote> and <quote>true</" +"quote> are all equivalent and valid; the same applies to <quote>FALSE</" +"quote>." msgstr "" -"Типами даних є рядок (без символів лапок), ціле число і булеве значення " -"(можливі два значення — <quote>TRUE</quote> і <quote>FALSE</quote>)." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:44 +#: sssd.conf.5.xml:49 msgid "" "A comment line starts with a hash sign (<quote>#</quote>) or a semicolon " "(<quote>;</quote>). Inline comments are not supported." @@ -122,7 +123,7 @@ msgstr "" "з комою (<quote>;</quote>). Підтримки вбудованих коментарів не передбачено." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:50 +#: sssd.conf.5.xml:55 msgid "" "All sections can have an optional <replaceable>description</replaceable> " "parameter. Its function is only as a label for the section." @@ -131,7 +132,7 @@ msgstr "" "replaceable>. Його призначено лише для позначення розділу." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:56 +#: sssd.conf.5.xml:61 msgid "" "<filename>sssd.conf</filename> must be a regular file that is owned, " "readable, and writeable only by 'root'." @@ -141,7 +142,7 @@ msgstr "" "лише користувач root." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:60 +#: sssd.conf.5.xml:65 msgid "" "<filename>sssd.conf</filename> must be a regular file that is accessible " "only by the user used to run SSSD service or root." @@ -151,12 +152,12 @@ msgstr "" "root." #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:66 +#: sssd.conf.5.xml:71 msgid "CONFIGURATION SNIPPETS FROM INCLUDE DIRECTORY" msgstr "ФРАГМЕНТИ НАЛАШТУВАНЬ З КАТАЛОГУ ВКЛЮЧЕННЯ" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:69 +#: sssd.conf.5.xml:74 msgid "" "The configuration file <filename>sssd.conf</filename> will include " "configuration snippets using the include directory <filename>conf.d</" @@ -166,7 +167,7 @@ msgstr "" "налаштувань з каталогу <filename>conf.d</filename>." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:75 +#: sssd.conf.5.xml:80 msgid "" "Any file placed in <filename>conf.d</filename> that ends in " "<quote><filename>.conf</filename></quote> and does not begin with a dot " @@ -179,7 +180,7 @@ msgstr "" "filename> для налаштовування SSSD." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:83 +#: sssd.conf.5.xml:88 msgid "" "The configuration snippets from <filename>conf.d</filename> have higher " "priority than <filename>sssd.conf</filename> and will override " @@ -200,7 +201,7 @@ msgstr "" "пріоритетності (більше число означає вищу пріоритетність)." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:97 +#: sssd.conf.5.xml:102 msgid "" "The snippet files require the same owner and permissions as " "<filename>sssd.conf</filename>." @@ -209,34 +210,87 @@ msgstr "" "доступу із файлом <filename>sssd.conf</filename>." #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:103 +#: sssd.conf.5.xml:108 +#, fuzzy +#| msgid "EXAMPLE CUSTODIA AND PROXY PROVIDER CONFIGURATION" +msgid "VENDOR PROVIDED CONFIGURATION" +msgstr "ПРИКЛАД НАЛАШТОВУВАННЯ МОДУЛІВ НАДАННЯ ДАНИХ CUSTODIA І ПРОКСІ" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:111 +msgid "" +"The vendor provided configuration file is installed in " +"<filename>&sssd_vendor_dir;/sssd.conf</filename>, but this file must not be " +"directly edited. It can be completely masked by creating the system specific " +"configuration file <filename>&sssd_conf_dir;/sssd.conf</filename>, or partly " +"overriden by creating config snippets in <filename>&sssd_conf_dir;/conf.d</" +"filename> directory." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><title> +#: sssd.conf.5.xml:120 +#, fuzzy +#| msgid "CONFIGURATION FILE" +msgid "CONFIGURATION FILE HIERARCHY" +msgstr "ФАЙЛ НАЛАШТУВАНЬ" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:122 +msgid "" +"When sssd reads the configuration it first tries to open the system specific " +"configuration file in <filename>&sssd_conf_dir;/sssd.conf</filename>. If it " +"exists, it is loaded and snippets from <filename>&sssd_conf_dir;/conf.d</" +"filename> are applied. The vendor provided configuration file " +"<filename>&sssd_vendor_dir;/sssd.conf</filename> is completely ignored in " +"this case." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:131 +msgid "" +"If the system specific configuration file <filename>&sssd_conf_dir;/" +"sssd.conf</filename> does not exist, then the vendor configuration file " +"<filename>&sssd_vendor_dir;/sssd.conf</filename> is loaded and snippets from " +"<filename>&sssd_conf_dir;/conf.d</filename> are applied." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd.conf.5.xml:141 msgid "GENERAL OPTIONS" msgstr "ЗАГАЛЬНІ ПАРАМЕТРИ" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:105 +#: sssd.conf.5.xml:143 msgid "Following options are usable in more than one configuration sections." msgstr "" "Нижче наведено параметри, які можна використовувати у декількох розділах " "налаштувань." #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:109 +#: sssd.conf.5.xml:147 msgid "Options usable in all sections" msgstr "Параметри, які можна використовувати у всіх розділах" +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:149 +msgid "" +"Note: Below options are ignored in <quote>[session_recording]</quote> " +"section, see <quote>Session recording configuration options</quote> section " +"for more details." +msgstr "" + #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:113 +#: sssd.conf.5.xml:156 msgid "debug_level (integer)" msgstr "debug_level (ціле число)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:117 +#: sssd.conf.5.xml:160 msgid "debug (integer)" msgstr "debug (ціле число)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:120 +#: sssd.conf.5.xml:163 msgid "" "SSSD 1.14 and later also includes the <replaceable>debug</replaceable> alias " "for <replaceable>debug_level</replaceable> as a convenience feature. If both " @@ -249,12 +303,14 @@ msgstr "" "використано варіант <replaceable>debug_level</replaceable>." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:130 -msgid "debug_timestamps (bool)" +#: sssd.conf.5.xml:173 +#, fuzzy +#| msgid "debug_timestamps (bool)" +msgid "debug_timestamps (boolean)" msgstr "debug_timestamps (булеве значення)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:133 +#: sssd.conf.5.xml:176 msgid "" "Add a timestamp to the debug messages. If journald is enabled for SSSD " "debug logging this option is ignored." @@ -264,23 +320,25 @@ msgstr "" "проігноровано." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:138 sssd.conf.5.xml:175 sssd.conf.5.xml:337 -#: sssd.conf.5.xml:644 sssd.conf.5.xml:668 sssd.conf.5.xml:875 -#: sssd.conf.5.xml:979 sssd.conf.5.xml:2113 sssd-ldap.5.xml:979 -#: sssd-ldap.5.xml:1134 sssd-ldap.5.xml:1237 sssd-ldap.5.xml:1306 -#: sssd-ldap.5.xml:1714 sssd-ldap.5.xml:1848 sssd-ldap.5.xml:1913 -#: sssd-ipa.5.xml:346 sssd-ad.5.xml:252 sssd-ad.5.xml:367 sssd-ad.5.xml:1180 -#: sssd-ad.5.xml:1382 sssd-krb5.5.xml:358 +#: sssd.conf.5.xml:181 sssd.conf.5.xml:218 sssd.conf.5.xml:380 +#: sssd.conf.5.xml:687 sssd.conf.5.xml:711 sssd.conf.5.xml:827 +#: sssd.conf.5.xml:932 sssd.conf.5.xml:2149 sssd.conf.5.xml:4730 +#: sssd-ldap.5.xml:979 sssd-ldap.5.xml:1134 sssd-ldap.5.xml:1237 +#: sssd-ldap.5.xml:1306 sssd-ldap.5.xml:1714 sssd-ldap.5.xml:1848 +#: sssd-ldap.5.xml:1913 sssd-ipa.5.xml:341 sssd-ad.5.xml:252 sssd-ad.5.xml:367 +#: sssd-ad.5.xml:1180 sssd-ad.5.xml:1375 sssd-krb5.5.xml:358 msgid "Default: true" msgstr "Типове значення: true" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:143 -msgid "debug_microseconds (bool)" +#: sssd.conf.5.xml:186 +#, fuzzy +#| msgid "debug_microseconds (bool)" +msgid "debug_microseconds (boolean)" msgstr "debug_microseconds (булеве значення)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:146 +#: sssd.conf.5.xml:189 msgid "" "Add microseconds to the timestamp in debug messages. If journald is enabled " "for SSSD debug logging this option is ignored." @@ -290,26 +348,28 @@ msgstr "" "journald, цей параметр буде проігноровано." #. type: Content of: <variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:151 sssd.conf.5.xml:2040 sssd.conf.5.xml:4158 +#: sssd.conf.5.xml:194 sssd.conf.5.xml:2072 sssd.conf.5.xml:4363 #: sssd-ldap.5.xml:363 sssd-ldap.5.xml:998 sssd-ldap.5.xml:1209 -#: sssd-ldap.5.xml:1663 sssd-ldap.5.xml:1937 sssd-ipa.5.xml:146 -#: sssd-ipa.5.xml:706 sssd-ad.5.xml:1135 sssd-krb5.5.xml:268 +#: sssd-ldap.5.xml:1663 sssd-ldap.5.xml:1937 sssd-ipa.5.xml:141 +#: sssd-ipa.5.xml:701 sssd-ad.5.xml:1140 sssd-idp.5.xml:287 sssd-krb5.5.xml:268 #: sssd-krb5.5.xml:330 sssd-krb5.5.xml:432 include/krb5_options.xml:163 msgid "Default: false" msgstr "Типове значення: false" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:156 -msgid "debug_backtrace_enabled (bool)" +#: sssd.conf.5.xml:199 +#, fuzzy +#| msgid "debug_backtrace_enabled (bool)" +msgid "debug_backtrace_enabled (boolean)" msgstr "debug_backtrace_enabled (булеве значення)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:159 +#: sssd.conf.5.xml:202 msgid "Enable debug backtrace." msgstr "Увімкнути діагностичне зворотне трасування." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:162 +#: sssd.conf.5.xml:205 msgid "" "In case SSSD is run with debug_level less than 9, everything is logged to a " "ring buffer in memory and flushed to a log file on any error up to and " @@ -325,7 +385,7 @@ msgstr "" "помилки рівнів до 2)." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:171 +#: sssd.conf.5.xml:214 msgid "" "Feature is only supported for `logger == files` (i.e. setting doesn't have " "effect for other logger types)." @@ -334,7 +394,7 @@ msgstr "" "встановлення цього значення не впливає на інші типи журналювання)." #. type: Content of: outside any tag (error?) -#: sssd.conf.5.xml:111 sssd.conf.5.xml:186 sssd-ldap.5.xml:1754 +#: sssd.conf.5.xml:154 sssd.conf.5.xml:229 sssd-ldap.5.xml:1754 #: sssd-ldap.5.xml:1960 sss-certmap.5.xml:645 sssd-systemtap.5.xml:82 #: sssd-systemtap.5.xml:143 sssd-systemtap.5.xml:236 sssd-systemtap.5.xml:274 #: sssd-systemtap.5.xml:330 sssd-ldap-attributes.5.xml:40 @@ -347,17 +407,17 @@ msgid "<placeholder type=\"variablelist\" id=\"0\"/>" msgstr "<placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:184 +#: sssd.conf.5.xml:227 msgid "Options usable in SERVICE and DOMAIN sections" msgstr "Параметри які можна використовувати у розділах SERVICE та DOMAIN" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:188 +#: sssd.conf.5.xml:231 msgid "timeout (integer)" msgstr "timeout (ціле число)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:191 +#: sssd.conf.5.xml:234 msgid "" "Timeout in seconds between heartbeats for this service. This is used to " "ensure that the process is alive and capable of answering requests. Note " @@ -369,34 +429,36 @@ msgstr "" "самостійно." #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:198 sssd.conf.5.xml:1199 sssd.conf.5.xml:1673 -#: sssd.conf.5.xml:4174 sssd-ldap.5.xml:825 sssd-idp.5.xml:192 +#: sssd.conf.5.xml:241 sssd.conf.5.xml:1155 sssd.conf.5.xml:1665 +#: sssd.conf.5.xml:4379 sssd-ldap.5.xml:825 sssd-idp.5.xml:271 #: include/ldap_id_mapping.xml:270 msgid "Default: 10" msgstr "Типове значення: 10" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:208 +#: sssd.conf.5.xml:251 msgid "SPECIAL SECTIONS" msgstr "ОСОБЛИВІ РОЗДІЛИ" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:211 +#: sssd.conf.5.xml:254 msgid "The [sssd] section" msgstr "Розділ [sssd]" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><title> -#: sssd.conf.5.xml:220 +#: sssd.conf.5.xml:263 msgid "Section parameters" msgstr "Параметри розділу" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:222 -msgid "services" -msgstr "services" +#: sssd.conf.5.xml:265 +#, fuzzy +#| msgid "users (string)" +msgid "services (string)" +msgstr "users (рядок)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:225 +#: sssd.conf.5.xml:268 msgid "" "Comma separated list of services that are started when sssd itself starts. " "<phrase condition=\"have_systemd\"> The services' list is optional on " @@ -409,7 +471,7 @@ msgstr "" "допомогою сокетів або D-Bus.</phrase>" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:234 +#: sssd.conf.5.xml:277 msgid "" "Supported services: nss, pam, ifp <phrase condition=\"with_sudo\">, sudo</" "phrase> <phrase condition=\"with_autofs\">, autofs</phrase> <phrase " @@ -422,7 +484,7 @@ msgstr "" "condition=\"with_pac_responder\">, pac</phrase>" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:241 +#: sssd.conf.5.xml:284 msgid "" "<phrase condition=\"have_systemd\"> By default, all services are disabled " "and the administrator must enable the ones allowed to be used by executing: " @@ -432,13 +494,13 @@ msgstr "" "має увімкнути дозволені до використання служби за допомогою такої команди: " "\"systemctl enable sssd-@service@.socket\". </phrase>" -#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:250 -msgid "domains" -msgstr "domains" +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sssd.conf.5.xml:293 sssd.conf.5.xml:4562 +msgid "domains (string)" +msgstr "domains (рядок)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:253 +#: sssd.conf.5.xml:296 msgid "" "A domain is a database containing user information. SSSD can use more " "domains at the same time, but at least one must be configured or SSSD won't " @@ -456,12 +518,12 @@ msgstr "" "використовувати символ «/»." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:266 sssd.conf.5.xml:3467 +#: sssd.conf.5.xml:309 sssd.conf.5.xml:3598 msgid "re_expression (string)" msgstr "re_expression (рядок)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:269 +#: sssd.conf.5.xml:312 msgid "" "Default regular expression that describes how to parse the string containing " "user name and domain into these components." @@ -470,7 +532,7 @@ msgstr "" "користувача і доменом на його частини." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:274 +#: sssd.conf.5.xml:317 msgid "" "Each domain can have an individual regular expression configured. For some " "ID providers there are also default regular expressions. See DOMAIN SECTIONS " @@ -482,12 +544,12 @@ msgstr "" "ДОМЕНІВ." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:283 sssd.conf.5.xml:3524 +#: sssd.conf.5.xml:326 sssd.conf.5.xml:3655 msgid "full_name_format (string)" msgstr "full_name_format (рядок)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:286 sssd.conf.5.xml:3527 +#: sssd.conf.5.xml:329 sssd.conf.5.xml:3658 msgid "" "A <citerefentry> <refentrytitle>printf</refentrytitle> <manvolnum>3</" "manvolnum> </citerefentry>-compatible format that describes how to compose a " @@ -498,32 +560,32 @@ msgstr "" "імені на основі імені користувача та компонентів назви домену." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:297 sssd.conf.5.xml:3538 +#: sssd.conf.5.xml:340 sssd.conf.5.xml:3669 msgid "%1$s" msgstr "%1$s" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:298 sssd.conf.5.xml:3539 +#: sssd.conf.5.xml:341 sssd.conf.5.xml:3670 msgid "user name" msgstr "ім’я користувача" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:301 sssd.conf.5.xml:3542 +#: sssd.conf.5.xml:344 sssd.conf.5.xml:3673 msgid "%2$s" msgstr "%2$s" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:304 sssd.conf.5.xml:3545 +#: sssd.conf.5.xml:347 sssd.conf.5.xml:3676 msgid "domain name as specified in the SSSD config file." msgstr "назва домену у форматі, вказаному у файлі налаштувань SSSD." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:310 sssd.conf.5.xml:3551 +#: sssd.conf.5.xml:353 sssd.conf.5.xml:3682 msgid "%3$s" msgstr "%3$s" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:313 sssd.conf.5.xml:3554 +#: sssd.conf.5.xml:356 sssd.conf.5.xml:3685 msgid "" "domain flat name. Mostly usable for Active Directory domains, both directly " "configured or discovered via IPA trusts." @@ -532,7 +594,7 @@ msgstr "" "Directory, налаштованих та автоматично виявлених за зв’язками довіри IPA." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:294 sssd.conf.5.xml:3535 +#: sssd.conf.5.xml:337 sssd.conf.5.xml:3666 msgid "" "The following expansions are supported: <placeholder type=\"variablelist\" " "id=\"0\"/>" @@ -541,7 +603,7 @@ msgstr "" "type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:323 +#: sssd.conf.5.xml:366 msgid "" "Each domain can have an individual format string configured. See DOMAIN " "SECTIONS for more info on this option." @@ -550,12 +612,12 @@ msgstr "" "про ці рядки можна дізнатися з довідки до РОЗДІЛІВ ДОМЕНІВ." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:329 +#: sssd.conf.5.xml:372 msgid "monitor_resolv_conf (boolean)" msgstr "monitor_resolv_conf (булеве значення)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:332 +#: sssd.conf.5.xml:375 msgid "" "Controls if SSSD should monitor the state of resolv.conf to identify when it " "needs to update its internal DNS resolver." @@ -564,12 +626,12 @@ msgstr "" "моменту, коли слід оновити дані вбудованого інструмента визначення DNS." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:342 +#: sssd.conf.5.xml:385 msgid "try_inotify (boolean)" msgstr "try_inotify (булеве значення)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:345 +#: sssd.conf.5.xml:388 msgid "" "By default, SSSD will attempt to use inotify to monitor configuration files " "changes and will fall back to polling every five seconds if inotify cannot " @@ -580,7 +642,7 @@ msgstr "" "виконуватиметься опитування resolv.conf кожні п’ять секунд." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:351 +#: sssd.conf.5.xml:394 msgid "" "There are some limited situations where it is preferred that we should skip " "even trying to use inotify. In these rare cases, this option should be set " @@ -590,7 +652,7 @@ msgstr "" "рідкісних випадках слід встановити для цього параметра значення «false»." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:357 +#: sssd.conf.5.xml:400 msgid "" "Default: true on platforms where inotify is supported. False on other " "platforms." @@ -599,7 +661,7 @@ msgstr "" "інших платформах." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:361 +#: sssd.conf.5.xml:404 msgid "" "Note: this option will have no effect on platforms where inotify is " "unavailable. On these platforms, polling will always be used." @@ -609,12 +671,12 @@ msgstr "" "опитування файла." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:368 +#: sssd.conf.5.xml:411 msgid "krb5_rcache_dir (string)" msgstr "krb5_rcache_dir (рядок)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:371 +#: sssd.conf.5.xml:414 msgid "" "Directory on the filesystem where SSSD should store Kerberos replay cache " "files." @@ -623,7 +685,7 @@ msgstr "" "Kerberos." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:375 +#: sssd.conf.5.xml:418 msgid "" "This option accepts a special value __LIBKRB5_DEFAULTS__ that will instruct " "SSSD to let libkrb5 decide the appropriate location for the replay cache." @@ -633,7 +695,7 @@ msgstr "" "для кешу відтворення." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:381 +#: sssd.conf.5.xml:424 msgid "" "Default: Distribution-specific and specified at build-time. " "(__LIBKRB5_DEFAULTS__ if not configured)" @@ -642,12 +704,12 @@ msgstr "" "(__LIBKRB5_DEFAULTS__, якщо не вказано)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:388 +#: sssd.conf.5.xml:431 msgid "default_domain_suffix (string)" msgstr "default_domain_suffix (рядок)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:391 +#: sssd.conf.5.xml:434 msgid "" "Please note that this option is deprecated and domain_resolution_order " "should be used." @@ -656,7 +718,7 @@ msgstr "" "замість нього domain_resolution_order." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:395 +#: sssd.conf.5.xml:438 msgid "" "This string will be used as a default domain name for all names without a " "domain name component. The main use case is environments where the primary " @@ -672,7 +734,7 @@ msgstr "" "лише імені користувача без додавання до нього назви домену." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:405 +#: sssd.conf.5.xml:448 msgid "" "Please note that if this option is set all users from the primary domain " "have to use their fully qualified name, e.g. user@domain.name, to log in. " @@ -688,21 +750,21 @@ msgstr "" "use_fully_qualified_names значення False." #. type: Content of: <variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:414 sssd-ldap.5.xml:937 sssd-ldap.5.xml:949 -#: sssd-ldap.5.xml:1042 sssd-ad.5.xml:921 sssd-ad.5.xml:996 sssd-krb5.5.xml:468 -#: sssd-ldap-attributes.5.xml:470 sssd-ldap-attributes.5.xml:978 -#: include/ldap_id_mapping.xml:211 include/ldap_id_mapping.xml:222 -#: include/krb5_options.xml:148 +#: sssd.conf.5.xml:457 sssd.conf.5.xml:2006 sssd-ldap.5.xml:937 +#: sssd-ldap.5.xml:949 sssd-ldap.5.xml:1042 sssd-ad.5.xml:926 +#: sssd-ad.5.xml:1001 sssd-krb5.5.xml:468 sssd-ldap-attributes.5.xml:470 +#: sssd-ldap-attributes.5.xml:978 include/ldap_id_mapping.xml:211 +#: include/ldap_id_mapping.xml:222 include/krb5_options.xml:148 msgid "Default: not set" msgstr "Типове значення: not set" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:419 +#: sssd.conf.5.xml:462 msgid "override_space (string)" msgstr "override_space (рядок)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:422 +#: sssd.conf.5.xml:465 msgid "" "This parameter will replace spaces (space bar) with the given character for " "user and group names. e.g. (_). User name "john doe" will be " @@ -717,7 +779,7 @@ msgstr "" "через типовий роздільник полів у оболонці." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:431 +#: sssd.conf.5.xml:474 msgid "" "Please note it is a configuration error to use a replacement character that " "might be used in user or group names. If a name contains the replacement " @@ -730,22 +792,22 @@ msgstr "" "але, загалом, результат пошуку буде невизначеним." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:439 +#: sssd.conf.5.xml:482 msgid "Default: not set (spaces will not be replaced)" msgstr "Типове значення: не встановлено (пробіли не замінятимуться)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:444 +#: sssd.conf.5.xml:487 msgid "certificate_verification (string)" msgstr "certificate_verification (рядок)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:452 +#: sssd.conf.5.xml:495 msgid "no_ocsp" msgstr "no_ocsp" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:454 +#: sssd.conf.5.xml:497 msgid "" "Disables Online Certificate Status Protocol (OCSP) checks. This might be " "needed if the OCSP servers defined in the certificate are not reachable from " @@ -756,12 +818,12 @@ msgstr "" "у сертифікаті, є недоступними з клієнта." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:462 +#: sssd.conf.5.xml:505 msgid "soft_ocsp" msgstr "soft_ocsp" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:464 +#: sssd.conf.5.xml:507 msgid "" "If a connection cannot be established to an OCSP responder the OCSP check is " "skipped. This option should be used to allow authentication when the system " @@ -773,12 +835,12 @@ msgstr "" "недоступним." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:474 +#: sssd.conf.5.xml:517 msgid "ocsp_dgst" msgstr "ocsp_dgst" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:476 +#: sssd.conf.5.xml:519 msgid "" "Digest (hash) function used to create the certificate ID for the OCSP " "request. Allowed values are:" @@ -787,39 +849,39 @@ msgstr "" "створення ідентифікатора сертифіката для запиту OCSP. Можливі значення:" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:480 +#: sssd.conf.5.xml:523 msgid "sha1" msgstr "sha1" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:481 +#: sssd.conf.5.xml:524 msgid "sha256" msgstr "sha256" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:482 +#: sssd.conf.5.xml:525 msgid "sha384" msgstr "sha384" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:483 +#: sssd.conf.5.xml:526 msgid "sha512" msgstr "sha512" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:486 +#: sssd.conf.5.xml:529 msgid "Default: sha1 (to allow compatibility with RFC5019-compliant responder)" msgstr "" "Типове значення: sha1 (для уможливлення сумісності із відповідачем, який є " "сумісним із RFC5019)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:492 +#: sssd.conf.5.xml:535 msgid "no_verification" msgstr "no_verification" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:494 +#: sssd.conf.5.xml:537 msgid "" "Disables verification completely. This option should only be used for " "testing." @@ -828,12 +890,12 @@ msgstr "" "тестування." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:500 +#: sssd.conf.5.xml:543 msgid "partial_chain" msgstr "partial_chain" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:502 +#: sssd.conf.5.xml:545 msgid "" "Allow verification to succeed even if a <replaceable>complete</replaceable> " "chain cannot be built to a self-signed trust-anchor, provided it is possible " @@ -845,12 +907,12 @@ msgstr "" "бути не самопідписаним." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:511 +#: sssd.conf.5.xml:554 msgid "ocsp_default_responder=URL" msgstr "ocsp_default_responder=URL" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:513 +#: sssd.conf.5.xml:556 msgid "" "Sets the OCSP default responder which should be used instead of the one " "mentioned in the certificate. URL must be replaced with the URL of the OCSP " @@ -861,12 +923,12 @@ msgstr "" "відповідача, наприклад http://example.com:80/ocsp." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:523 +#: sssd.conf.5.xml:566 msgid "ocsp_default_responder_signing_cert=NAME" msgstr "ocsp_default_responder_signing_cert=НАЗВА" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:525 +#: sssd.conf.5.xml:568 msgid "" "This option is currently ignored. All needed certificates must be available " "in the PEM file given by pam_cert_db_path." @@ -875,12 +937,12 @@ msgstr "" "мають бути у файлі PEM, який вказано параметром pam_cert_db_path." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:533 +#: sssd.conf.5.xml:576 msgid "crl_file=/PATH/TO/CRL/FILE" msgstr "crl_file=/ШЛЯХ/ДО/ФАЙЛА/CRL" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:535 +#: sssd.conf.5.xml:578 msgid "" "Use the Certificate Revocation List (CRL) from the given file during the " "verification of the certificate. The CRL must be given in PEM format, see " @@ -893,12 +955,12 @@ msgstr "" "manvolnum> </citerefentry>, щоб дізнатися більше." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:548 +#: sssd.conf.5.xml:591 msgid "soft_crl" msgstr "soft_crl" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:551 +#: sssd.conf.5.xml:594 msgid "" "If a Certificate Revocation List (CRL) is expired ignore the expiration " "time of the CRL and check the related certificates with the expired CRL. " @@ -911,7 +973,7 @@ msgstr "" "автономному режимі, коли оновлення CRL є неможливим." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:447 +#: sssd.conf.5.xml:490 msgid "" "With this parameter the certificate verification can be tuned with a comma " "separated list of options. Supported options are: <placeholder " @@ -922,26 +984,26 @@ msgstr "" "параметри: <placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:564 +#: sssd.conf.5.xml:607 msgid "Unknown options are reported but ignored." msgstr "" "Обробник параметрів повідомлятиме про невідомі параметри і просто " "ігноруватиме їх." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:567 +#: sssd.conf.5.xml:610 msgid "Default: not set, i.e. do not restrict certificate verification" msgstr "" "Типове значення: не встановлено, тобто перевірка сертифікатів нічим не " "обмежуватиметься" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:573 +#: sssd.conf.5.xml:616 msgid "disable_netlink (boolean)" msgstr "disable_netlink (булеве значення)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:576 +#: sssd.conf.5.xml:619 msgid "" "SSSD hooks into the netlink interface to monitor changes to routes, " "addresses, links and trigger certain actions." @@ -950,7 +1012,7 @@ msgstr "" "адресах, посилання та виконання певних дій." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:581 +#: sssd.conf.5.xml:624 msgid "" "The SSSD state changes caused by netlink events may be undesirable and can " "be disabled by setting this option to 'true'" @@ -959,17 +1021,19 @@ msgstr "" "можна вимкнути встановленням для цього параметра значення «true»" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:586 +#: sssd.conf.5.xml:629 msgid "Default: false (netlink changes are detected)" msgstr "Типове значення: false (виявлення змін у netlink)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:591 -msgid "domain_resolution_order" +#: sssd.conf.5.xml:634 +#, fuzzy +#| msgid "domain_resolution_order" +msgid "domain_resolution_order (string)" msgstr "domain_resolution_order" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:594 +#: sssd.conf.5.xml:637 msgid "" "Comma separated list of domains and subdomains representing the lookup order " "that will be followed. The list doesn't have to include all possible " @@ -986,7 +1050,7 @@ msgstr "" "відбуватиметься у випадковому порядку для кожного батьківського домену." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:606 +#: sssd.conf.5.xml:649 msgid "" "Please, note that when this option is set the output format of all commands " "is always fully-qualified even when using short names for input. In case " @@ -1015,19 +1079,20 @@ msgstr "" "різних доменах можуть бути однаковими." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:630 sssd.conf.5.xml:1697 sssd.conf.5.xml:4224 -#: sssd-ad.5.xml:187 sssd-ad.5.xml:328 sssd-ad.5.xml:342 sssd-idp.5.xml:108 -#: sssd-idp.5.xml:132 sssd-idp.5.xml:145 sssd-idp.5.xml:159 sssd-idp.5.xml:180 +#: sssd.conf.5.xml:673 sssd.conf.5.xml:1026 sssd.conf.5.xml:1689 +#: sssd.conf.5.xml:4429 sssd-ad.5.xml:187 sssd-ad.5.xml:328 sssd-ad.5.xml:342 +#: sssd-idp.5.xml:112 sssd-idp.5.xml:136 sssd-idp.5.xml:149 sssd-idp.5.xml:167 +#: sssd-idp.5.xml:188 msgid "Default: Not set" msgstr "Типове значення: не встановлено" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:635 +#: sssd.conf.5.xml:678 msgid "implicit_pac_responder (boolean)" msgstr "implicit_pac_responder (булеве значення)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:638 +#: sssd.conf.5.xml:681 msgid "" "The PAC responder is enabled automatically for the IPA and AD provider to " "evaluate and check the PAC. If it has to be disabled set this option to " @@ -1038,12 +1103,12 @@ msgstr "" "цього параметра значення «false»." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:649 +#: sssd.conf.5.xml:692 msgid "core_dumpable (boolean)" msgstr "core_dumpable (булеве значення)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:652 +#: sssd.conf.5.xml:695 msgid "" "This option can be used for general system hardening: setting it to 'false' " "forbids core dumps for all SSSD processes to avoid leaking plain text " @@ -1057,7 +1122,7 @@ msgstr "" "procctl:PROC_TRACE_CTL у FreeBSD, щоб дізнатися більше." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:660 +#: sssd.conf.5.xml:703 msgid "" "Take a note that this setting has no effect for 'ldap_child', 'krb5_child' " "and 'sssd_pam' as those privileged binaries can have a copy of a host keytab " @@ -1070,17 +1135,17 @@ msgstr "" "визначається системним параметром /proc/sys/fs/suid_dumpable." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:673 +#: sssd.conf.5.xml:716 msgid "passkey_verification (string)" msgstr "passkey_verification (рядок)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:681 +#: sssd.conf.5.xml:724 msgid "user_verification (boolean)" msgstr "user_verification (булеве значення)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:683 +#: sssd.conf.5.xml:726 msgid "" "Enable or disable the user verification (i.e. PIN, fingerprint) during " "authentication. If enabled, the PIN will always be requested." @@ -1089,7 +1154,7 @@ msgstr "" "розпізнавання. Якщо увімкнено, програма завжди надсилатиме запит щодо PIN." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:689 +#: sssd.conf.5.xml:732 msgid "" "The default is that the key settings decide what to do. In the IPA or " "kerberos pre-authentication case, this value will be overwritten by the " @@ -1100,7 +1165,7 @@ msgstr "" "перезаписано сервером." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:676 +#: sssd.conf.5.xml:719 msgid "" "With this parameter the passkey verification can be tuned with a comma " "separated list of options. Supported options are: <placeholder " @@ -1111,7 +1176,7 @@ msgstr "" "параметри: <placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:213 +#: sssd.conf.5.xml:256 msgid "" "Individual pieces of SSSD functionality are provided by special SSSD " "services that are started and stopped together with SSSD. The services are " @@ -1127,12 +1192,12 @@ msgstr "" "профілів. <placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:708 +#: sssd.conf.5.xml:751 msgid "SERVICES SECTIONS" msgstr "РОЗДІЛИ СЛУЖБ" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:710 +#: sssd.conf.5.xml:753 msgid "" "Settings that can be used to configure different services are described in " "this section. They should reside in the [<replaceable>$NAME</replaceable>] " @@ -1145,28 +1210,36 @@ msgstr "" "у розділі <quote>[nss]</quote>" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:717 +#: sssd.conf.5.xml:760 msgid "General service configuration options" msgstr "Загальні параметри налаштування служб" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:719 +#: sssd.conf.5.xml:762 msgid "These options can be used to configure any service." msgstr "Цими параметрами можна скористатися для налаштування будь-яких служб." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:723 -msgid "fd_limit" -msgstr "fd_limit" +#: sssd.conf.5.xml:766 +#, fuzzy +#| msgid "wildcard_limit (integer)" +msgid "fd_limit (integer)" +msgstr "wildcard_limit (ціле число)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:726 +#: sssd.conf.5.xml:769 +#, fuzzy +#| msgid "" +#| "This option specifies the maximum number of file descriptors that may be " +#| "opened at one time by this SSSD process. On systems where SSSD is granted " +#| "the CAP_SYS_RESOURCE capability, this will be an absolute setting. On " +#| "systems without this capability, the resulting value will be the lower " +#| "value of this or the limits.conf \"hard\" limit." msgid "" "This option specifies the maximum number of file descriptors that may be " -"opened at one time by this SSSD process. On systems where SSSD is granted " -"the CAP_SYS_RESOURCE capability, this will be an absolute setting. On " -"systems without this capability, the resulting value will be the lower value " -"of this or the limits.conf \"hard\" limit." +"opened at one time by this SSSD process. Note this value will be capped by " +"the init system at the startup of SSSD, see e.g. man systemd.exec for " +"details." msgstr "" "За допомогою цього параметра можна визначити максимальну кількість " "дескрипторів файлів, які одночасно може бути відкрито цим процесом SSSD. У " @@ -1176,17 +1249,19 @@ msgstr "" "цього параметра і обмеженням \"hard\" у limits.conf." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:735 +#: sssd.conf.5.xml:776 msgid "Default: 8192 (or limits.conf \"hard\" limit)" msgstr "Типове значення: 8192 (або обмеження у limits.conf \"hard\")" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:740 -msgid "client_idle_timeout" -msgstr "client_idle_timeout" +#: sssd.conf.5.xml:781 +#, fuzzy +#| msgid "offline_timeout (integer)" +msgid "client_idle_timeout (integer)" +msgstr "offline_timeout (ціле число)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:743 +#: sssd.conf.5.xml:784 msgid "" "This option specifies the number of seconds that a client of an SSSD process " "can hold onto a file descriptor without communicating on it. This value is " @@ -1202,170 +1277,19 @@ msgstr "" "до 10 секунд." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:752 +#: sssd.conf.5.xml:793 msgid "Default: 60, KCM: 300" msgstr "Типове значення: 60, KCM: 300" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:757 -msgid "offline_timeout (integer)" -msgstr "offline_timeout (ціле число)" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:760 -msgid "" -"When SSSD switches to offline mode the amount of time before it tries to go " -"back online will increase based upon the time spent disconnected. By " -"default SSSD uses incremental behaviour to calculate delay in between " -"retries. So, the wait time for a given retry will be longer than the wait " -"time for the previous ones. After each unsuccessful attempt to go online, " -"the new interval is recalculated by the following:" -msgstr "" -"Коли SSSD перемикається на автономний режим роботи, час, який має минути, " -"перш ніж буде здійснено спробу повернутися до режиму у мережі, " -"збільшуватиметься, відповідно до часу, проведеного у режимі від’єднання. " -"Типово, SSSD використовує нарощувальну поведінку для обчислення затримки між " -"повторними спробами. Тому час очікування для повторної спроби буде довшим за " -"час очікування попередньої спроби. Після кожної невдалої спроби з'єднатися " -"із мережею нове значення обчислюється за такою формулою:" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:771 sssd.conf.5.xml:827 -msgid "" -"new_delay = Minimum(old_delay * 2, offline_timeout_max) + " -"random[0...offline_timeout_random_offset]" -msgstr "" -"new_delay = Minimum(old_delay * 2, offline_timeout_max) + " -"random[0...offline_timeout_random_offset]" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:774 -msgid "" -"The offline_timeout default value is 60. The offline_timeout_max default " -"value is 3600. The offline_timeout_random_offset default value is 30. The " -"end result is amount of seconds before next retry." -msgstr "" -"Типовим значенням offline_timeout є 60. Типовим значенням " -"offline_timeout_max є 3600. Типовим значенням offline_timeout_random_offset " -"є 30. Кінцевий результат є кількістю секунд до наступної повторної спроби." - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:780 -msgid "" -"Note that the maximum length of each interval is defined by " -"offline_timeout_max (apart of random part)." -msgstr "" -"Зауважте, що максимальна тривалість кожного з інтервалів визначається " -"offline_timeout_max (окрім випадкової частини)." - -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:784 sssd.conf.5.xml:1110 sssd.conf.5.xml:1490 -#: sssd.conf.5.xml:1791 sssd-ldap.5.xml:550 -msgid "Default: 60" -msgstr "Типове значення: 60" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:789 -msgid "offline_timeout_max (integer)" -msgstr "offline_timeout_max (ціле число)" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:792 -msgid "" -"Controls by how much the time between attempts to go online can be " -"incremented following unsuccessful attempts to go online." -msgstr "" -"Керує тим, на скільки можна збільшувати проміжок часу між спробами відновити " -"з'єднання із мережею після неуспішних спроби відновити з'єднання." - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:797 -msgid "A value of 0 disables the incrementing behaviour." -msgstr "Значення 0 вимикає збільшення проміжку часу." - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:800 -msgid "" -"The value of this parameter should be set in correlation to offline_timeout " -"parameter value." -msgstr "" -"Значення цього параметра слід встановлювати у поєднанні зі значенням " -"параметра offline_timeout." - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:804 -msgid "" -"With offline_timeout set to 60 (default value) there is no point in setting " -"offlinet_timeout_max to less than 120 as it will saturate instantly. General " -"rule here should be to set offline_timeout_max to at least 4 times " -"offline_timeout." -msgstr "" -"Якщо для offline_timeout встановлено значення 60 (типове значення), немає " -"сенсу встановлювати для offlinet_timeout_max значення, яке є меншим за 120, " -"оскільки перший же крок збільшення призведе до перевищення максимального " -"значення. Загальним правилом у цьому випадку має бути встановлення значення " -"offline_timeout_max, яке є принаймні учетверо більшим за offline_timeout." - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:810 -msgid "" -"Although a value between 0 and offline_timeout may be specified, it has the " -"effect of overriding the offline_timeout value so is of little use." -msgstr "" -"Хоча можна вказати будь-яке значення від 0 до offline_timeout, результатом " -"стане перевизначення значення offline_timeout, тому не варто цього робити." - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:815 -msgid "Default: 3600" -msgstr "Типове значення: 3600" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:820 -msgid "offline_timeout_random_offset (integer)" -msgstr "offline_timeout_random_offset (ціле число)" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:823 -msgid "" -"When SSSD is in offline mode it keeps probing backend servers in specified " -"time intervals:" -msgstr "" -"Якщо SSSD працює в автономному режимі, програма виконує зондування серверів-" -"обробників із вказаними інтервалами часу:" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:830 -msgid "" -"This parameter controls the value of the random offset used for the above " -"equation. Final random_offset value will be random number in range:" -msgstr "" -"Цей параметр керує значенням випадкового зсуву, яке буде використано у " -"наведеному вище рівнянні. Остаточне значення random_offset буде випадковим " -"числом у такому діапазоні:" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:835 -msgid "[0 - offline_timeout_random_offset]" -msgstr "[0 - offline_timeout_random_offset]" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:838 -msgid "A value of 0 disables the random offset addition." -msgstr "Значення 0 призводить до вимикання додавання випадкового зсуву." - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:841 -msgid "Default: 30" -msgstr "Типове значення: 30" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:846 -msgid "responder_idle_timeout" +#: sssd.conf.5.xml:798 +#, fuzzy +#| msgid "responder_idle_timeout" +msgid "responder_idle_timeout (integer)" msgstr "responder_idle_timeout" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:849 +#: sssd.conf.5.xml:801 msgid "" "This option specifies the number of seconds that an SSSD responder process " "can be up without being used. This value is limited in order to avoid " @@ -1384,18 +1308,20 @@ msgstr "" "і якщо служби активуються за допомогою або сокетів або D-Bus." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:863 sssd.conf.5.xml:1123 sssd.conf.5.xml:2248 +#: sssd.conf.5.xml:815 sssd.conf.5.xml:1079 sssd.conf.5.xml:2285 #: sssd-ldap.5.xml:377 msgid "Default: 300" msgstr "Типове значення: 300" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:868 -msgid "cache_first" +#: sssd.conf.5.xml:820 +#, fuzzy +#| msgid "cache_first" +msgid "cache_first (boolean)" msgstr "cache_first" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:871 +#: sssd.conf.5.xml:823 msgid "" "This option specifies whether the responder should query all caches before " "querying the Data Providers." @@ -1404,25 +1330,30 @@ msgstr "" "запису до модулів засобів надання даних." #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:883 +#: sssd.conf.5.xml:835 msgid "NSS configuration options" msgstr "Параметри налаштування NSS" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:885 +#: sssd.conf.5.xml:837 +#, fuzzy +#| msgid "" +#| "These options can be used to configure the Name Service Switch (NSS) " +#| "service." msgid "" -"These options can be used to configure the Name Service Switch (NSS) service." +"These options can be used to configure the Name Service Switch (NSS) service " +"and should be specified under the <quote>[nss]</quote> section." msgstr "" "Цими параметрами можна скористатися для налаштування служби Name Service " "Switch (NSS або перемикання служби визначення назв)." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:890 +#: sssd.conf.5.xml:843 msgid "enum_cache_timeout (integer)" msgstr "enum_cache_timeout (ціле число)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:893 +#: sssd.conf.5.xml:846 msgid "" "How many seconds should nss_sss cache enumerations (requests for info about " "all users)" @@ -1431,17 +1362,17 @@ msgstr "" "кеші nss_sss у секундах" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:897 +#: sssd.conf.5.xml:850 msgid "Default: 120" msgstr "Типове значення: 120" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:902 +#: sssd.conf.5.xml:855 msgid "entry_cache_nowait_percentage (integer)" msgstr "entry_cache_nowait_percentage (ціле число)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:905 +#: sssd.conf.5.xml:858 msgid "" "The entry cache can be set to automatically update entries in the background " "if they are requested beyond a percentage of the entry_cache_timeout value " @@ -1452,7 +1383,7 @@ msgstr "" "entry_cache_timeout для домену період часу." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:911 +#: sssd.conf.5.xml:864 msgid "" "For example, if the domain's entry_cache_timeout is set to 30s and " "entry_cache_nowait_percentage is set to 50 (percent), entries that come in " @@ -1467,7 +1398,7 @@ msgstr "" "розблокування після оновлення кешу." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:921 +#: sssd.conf.5.xml:874 msgid "" "Valid values for this option are 0-99 and represent a percentage of the " "entry_cache_timeout for each domain. For performance reasons, this " @@ -1481,17 +1412,17 @@ msgstr "" "можливість." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:929 sssd.conf.5.xml:2061 +#: sssd.conf.5.xml:882 sssd.conf.5.xml:2093 msgid "Default: 50" msgstr "Типове значення: 50" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:934 +#: sssd.conf.5.xml:887 msgid "entry_negative_timeout (integer)" msgstr "entry_negative_timeout (ціле число)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:937 +#: sssd.conf.5.xml:890 msgid "" "Specifies for how many seconds nss_sss should cache negative cache hits " "(that is, queries for invalid database entries, like nonexistent ones) " @@ -1502,17 +1433,17 @@ msgstr "" "даних, зокрема неіснуючих) перед повторним запитом до сервера обробки." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:943 sssd.conf.5.xml:1685 sssd.conf.5.xml:2085 +#: sssd.conf.5.xml:896 sssd.conf.5.xml:1677 sssd.conf.5.xml:2119 msgid "Default: 15" msgstr "Типове значення: 15" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:948 +#: sssd.conf.5.xml:901 msgid "filter_users, filter_groups (string)" msgstr "filter_users, filter_groups (рядок)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:951 +#: sssd.conf.5.xml:904 msgid "" "Exclude certain users or groups from being fetched from the sss NSS " "database. This is particularly useful for system accounts. This option can " @@ -1527,7 +1458,7 @@ msgstr "" "реєстраційного запису користувача (UPN)." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:959 +#: sssd.conf.5.xml:912 msgid "" "NOTE: The filter_groups option doesn't affect inheritance of nested group " "members, since filtering happens after they are propagated for returning via " @@ -1541,30 +1472,35 @@ msgstr "" "відфільтрованої групи." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:967 +#: sssd.conf.5.xml:920 msgid "Default: root" msgstr "Типове значення: root" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:972 -msgid "filter_users_in_groups (bool)" +#: sssd.conf.5.xml:925 +#, fuzzy +#| msgid "filter_users_in_groups (bool)" +msgid "filter_users_in_groups (boolean)" msgstr "filter_users_in_groups (булеве значення)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:975 +#: sssd.conf.5.xml:928 +#, fuzzy +#| msgid "" +#| "If you want filtered user still be group members set this option to false." msgid "" -"If you want filtered user still be group members set this option to false." +"If you want filtered users to remain group members set this option to false" msgstr "" "Якщо ви хочете, щоб фільтровані користувачі залишалися учасниками груп, " "встановіть для цього параметра значення «false»." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:986 +#: sssd.conf.5.xml:939 msgid "fallback_homedir (string)" msgstr "fallback_homedir (рядок)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:989 +#: sssd.conf.5.xml:942 msgid "" "Set a default template for a user's home directory if one is not specified " "explicitly by the domain's data provider." @@ -1573,7 +1509,7 @@ msgstr "" "каталог не вказано явним чином засобом надання даних домену." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:994 +#: sssd.conf.5.xml:947 msgid "" "The available values for this option are the same as for override_homedir." msgstr "" @@ -1581,7 +1517,7 @@ msgstr "" "для параметра override_homedir." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1000 +#: sssd.conf.5.xml:953 #, no-wrap msgid "" "fallback_homedir = /home/%u\n" @@ -1591,25 +1527,25 @@ msgstr "" " " #. type: Content of: <varlistentry><listitem><para> -#: sssd.conf.5.xml:998 sssd.conf.5.xml:1557 sssd.conf.5.xml:1576 -#: sssd.conf.5.xml:1653 sssd-krb5.5.xml:451 include/override_homedir.xml:78 +#: sssd.conf.5.xml:951 sssd.conf.5.xml:1524 sssd.conf.5.xml:1543 +#: sssd.conf.5.xml:1645 sssd-krb5.5.xml:451 include/override_homedir.xml:78 msgid "example: <placeholder type=\"programlisting\" id=\"0\"/>" msgstr "приклад: <placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1004 +#: sssd.conf.5.xml:957 msgid "Default: not set (no substitution for unset home directories)" msgstr "" "Типове значення: не встановлено (без замін для невстановлених домашніх " "каталогів)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1010 +#: sssd.conf.5.xml:963 msgid "override_shell (string)" msgstr "override_shell (рядок)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1013 +#: sssd.conf.5.xml:966 msgid "" "Override the login shell for all users. This option supersedes any other " "shell options if it takes effect and can be set either in the [nss] section " @@ -1621,19 +1557,19 @@ msgstr "" "або для кожного з доменів окремо." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1019 +#: sssd.conf.5.xml:972 msgid "Default: not set (SSSD will use the value retrieved from LDAP)" msgstr "" "Типове значення: не встановлено (SSSD використовуватиме значення, отримане " "від LDAP)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1025 +#: sssd.conf.5.xml:978 msgid "allowed_shells (string)" msgstr "allowed_shells (рядок)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1028 +#: sssd.conf.5.xml:981 msgid "" "Restrict user shell to one of the listed values. The order of evaluation is:" msgstr "" @@ -1641,13 +1577,13 @@ msgstr "" "визначення оболонки є таким:" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1031 +#: sssd.conf.5.xml:984 msgid "1. If the shell is present in <quote>/etc/shells</quote>, it is used." msgstr "" "1. Якщо оболонку вказано у <quote>/etc/shells</quote>, її буде використано." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1035 +#: sssd.conf.5.xml:988 msgid "" "2. If the shell is in the allowed_shells list but not in <quote>/etc/shells</" "quote>, use the value of the shell_fallback parameter." @@ -1657,7 +1593,7 @@ msgstr "" "shell_fallback." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1040 +#: sssd.conf.5.xml:993 msgid "" "3. If the shell is not in the allowed_shells list and not in <quote>/etc/" "shells</quote>, a nologin shell is used." @@ -1666,14 +1602,14 @@ msgstr "" "<quote>/etc/shells</quote>, буде використано оболонку nologin." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1045 +#: sssd.conf.5.xml:998 msgid "The wildcard (*) can be used to allow any shell." msgstr "" "Для визначення будь-якої командної оболонки можна скористатися шаблоном " "заміни (*)." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1048 +#: sssd.conf.5.xml:1001 msgid "" "The (*) is useful if you want to use shell_fallback in case that user's " "shell is not in <quote>/etc/shells</quote> and maintaining list of all " @@ -1685,12 +1621,12 @@ msgstr "" "справою." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1055 +#: sssd.conf.5.xml:1008 msgid "An empty string for shell is passed as-is to libc." msgstr "Порожній рядок оболонки буде передано без обробки до libc." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1058 +#: sssd.conf.5.xml:1011 msgid "" "The <quote>/etc/shells</quote> is only read on SSSD start up, which means " "that a restart of the SSSD is required in case a new shell is installed." @@ -1699,29 +1635,29 @@ msgstr "" "тобто у разі встановлення нової оболонки слід перезапустити SSSD." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1062 +#: sssd.conf.5.xml:1015 msgid "Default: Not set. The user shell is automatically used." msgstr "" "Типове значення: не встановлено. Автоматично використовується оболонка " "користувача." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1067 +#: sssd.conf.5.xml:1020 msgid "vetoed_shells (string)" msgstr "vetoed_shells (рядок)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1070 +#: sssd.conf.5.xml:1023 msgid "Replace any instance of these shells with the shell_fallback" msgstr "Замінити всі записи цих оболонок на shell_fallback" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1075 +#: sssd.conf.5.xml:1031 msgid "shell_fallback (string)" msgstr "shell_fallback (рядок)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1078 +#: sssd.conf.5.xml:1034 msgid "" "The default shell to use if an allowed shell is not installed on the machine." msgstr "" @@ -1729,17 +1665,17 @@ msgstr "" "системі не встановлено." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1082 +#: sssd.conf.5.xml:1038 msgid "Default: /bin/sh" msgstr "Типове значення: /bin/sh" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1087 -msgid "default_shell" -msgstr "default_shell" +#: sssd.conf.5.xml:1043 +msgid "default_shell (string)" +msgstr "default_shell (рядок)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1090 +#: sssd.conf.5.xml:1046 msgid "" "The default shell to use if the provider does not return one during lookup. " "This option can be specified globally in the [nss] section or per-domain." @@ -1749,7 +1685,7 @@ msgstr "" "або на загальному рівні у розділі [nss], або окремо для кожного з доменів." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1096 +#: sssd.conf.5.xml:1052 msgid "" "Default: not set (Return NULL if no shell is specified and rely on libc to " "substitute something sensible when necessary, usually /bin/sh)" @@ -1759,12 +1695,12 @@ msgstr "" "зазвичай /bin/sh)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1103 sssd.conf.5.xml:1483 +#: sssd.conf.5.xml:1059 sssd.conf.5.xml:1450 msgid "get_domains_timeout (int)" msgstr "get_domains_timeout (ціле число)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1106 sssd.conf.5.xml:1486 +#: sssd.conf.5.xml:1062 sssd.conf.5.xml:1453 msgid "" "Specifies time in seconds for which the list of subdomains will be " "considered valid." @@ -1772,13 +1708,19 @@ msgstr "" "Визначає час у секундах, протягом якого список піддоменів вважатиметься " "чинним." +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1066 sssd.conf.5.xml:1457 sssd.conf.5.xml:1788 +#: sssd.conf.5.xml:2862 sssd-ldap.5.xml:550 +msgid "Default: 60" +msgstr "Типове значення: 60" + #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1115 +#: sssd.conf.5.xml:1071 msgid "memcache_timeout (integer)" msgstr "memcache_timeout (ціле число)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1118 +#: sssd.conf.5.xml:1074 msgid "" "Specifies time in seconds for which records in the in-memory cache will be " "valid. Setting this option to zero will disable the in-memory cache." @@ -1788,7 +1730,7 @@ msgstr "" "пам'яті." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1126 +#: sssd.conf.5.xml:1082 msgid "" "WARNING: Disabling the in-memory cache will have significant negative impact " "on SSSD's performance and should only be used for testing." @@ -1797,8 +1739,8 @@ msgstr "" "варто користуватися лише для тестування." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1132 sssd.conf.5.xml:1157 sssd.conf.5.xml:1182 -#: sssd.conf.5.xml:1207 sssd.conf.5.xml:1234 +#: sssd.conf.5.xml:1088 sssd.conf.5.xml:1113 sssd.conf.5.xml:1138 +#: sssd.conf.5.xml:1163 sssd.conf.5.xml:1190 msgid "" "NOTE: If the environment variable SSS_NSS_USE_MEMCACHE is set to \"NO\", " "client applications will not use the fast in-memory cache." @@ -1808,12 +1750,12 @@ msgstr "" "пам’яті." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1140 +#: sssd.conf.5.xml:1096 msgid "memcache_size_passwd (integer)" msgstr "memcache_size_passwd (ціле число)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1143 +#: sssd.conf.5.xml:1099 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for passwd requests. Setting the size to 0 will disable the passwd in-" @@ -1823,13 +1765,13 @@ msgstr "" "для запитів passwd. Встановлення розміру 0 вимкне кеш у пам'яті для passwd." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1149 sssd.conf.5.xml:2888 sssd-ldap.5.xml:604 +#: sssd.conf.5.xml:1105 sssd.conf.5.xml:3013 sssd-ldap.5.xml:604 msgid "Default: 8" msgstr "Типове значення: 8" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1152 sssd.conf.5.xml:1177 sssd.conf.5.xml:1202 -#: sssd.conf.5.xml:1229 +#: sssd.conf.5.xml:1108 sssd.conf.5.xml:1133 sssd.conf.5.xml:1158 +#: sssd.conf.5.xml:1185 msgid "" "WARNING: Disabled or too small in-memory cache can have significant negative " "impact on SSSD's performance." @@ -1838,12 +1780,12 @@ msgstr "" "значно погіршити швидкодію SSSD." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1165 +#: sssd.conf.5.xml:1121 msgid "memcache_size_group (integer)" msgstr "memcache_size_group (ціле число)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1168 +#: sssd.conf.5.xml:1124 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for group requests. Setting the size to 0 will disable the group in-memory " @@ -1853,19 +1795,19 @@ msgstr "" "для запитів group. Встановлення розміру 0 вимкне кеш у пам'яті для group." #. type: Content of: <variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1174 sssd.conf.5.xml:1226 sssd.conf.5.xml:3656 +#: sssd.conf.5.xml:1130 sssd.conf.5.xml:1182 sssd.conf.5.xml:3835 #: sssd-ldap.5.xml:534 sssd-ldap.5.xml:581 include/failover.xml:116 #: include/krb5_options.xml:11 msgid "Default: 6" msgstr "Типове значення: 6" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1190 +#: sssd.conf.5.xml:1146 msgid "memcache_size_initgroups (integer)" msgstr "memcache_size_initgroups (ціле число)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1193 +#: sssd.conf.5.xml:1149 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for initgroups requests. Setting the size to 0 will disable the initgroups " @@ -1876,12 +1818,12 @@ msgstr "" "initgroups." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1215 +#: sssd.conf.5.xml:1171 msgid "memcache_size_sid (integer)" msgstr "memcache_size_sid (ціле число)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1218 +#: sssd.conf.5.xml:1174 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for SID related requests. Only SID-by-ID and ID-by-SID requests are " @@ -1894,12 +1836,12 @@ msgstr "" "0 вимкне кеш у пам'яті для SID." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1242 sssd-ifp.5.xml:90 +#: sssd.conf.5.xml:1198 sssd-ifp.5.xml:90 msgid "user_attributes (string)" msgstr "user_attributes (рядок)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1245 +#: sssd.conf.5.xml:1201 msgid "" "Some of the additional NSS responder requests can return more attributes " "than just the POSIX ones defined by the NSS interface. The list of " @@ -1916,7 +1858,7 @@ msgstr "" "manvolnum> </citerefentry>, щоб дізнатися більше), але без типових значень." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1258 +#: sssd.conf.5.xml:1214 msgid "" "To make configuration more easy the NSS responder will check the InfoPipe " "option if it is not set for the NSS responder." @@ -1925,19 +1867,19 @@ msgstr "" "на те, чи не встановлено його для відповідача NSS." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1263 +#: sssd.conf.5.xml:1219 msgid "Default: not set, fallback to InfoPipe option" msgstr "" "Типове значення: не встановлено, резервне значення визначається за " "параметром InfoPipe" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1268 +#: sssd.conf.5.xml:1224 msgid "pwfield (string)" msgstr "pwfield (рядок)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1271 +#: sssd.conf.5.xml:1227 msgid "" "The value that NSS operations that return users or groups will return for " "the <quote>password</quote> field." @@ -1946,50 +1888,61 @@ msgstr "" "груп, для поля <quote>password</quote>." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1276 +#: sssd.conf.5.xml:1232 +msgid "" +"This option can also be set per-domain, which overwrites the value in the " +"<quote>[nss]</quote> section for that domain. This is particularly useful " +"when using a proxy domain with <option>proxy_lib_name=files</option> and a " +"<option>proxy_pam_target</option> other than <quote>sssd-shadowutils</" +"quote>. In that case, SSSD returns <quote>*</quote> for the password field " +"by default, which causes <command>pam_unix</command> to treat all accounts " +"as locked. Setting <option>pwfield = x</option> in the domain section " +"restores the expected behavior." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1246 msgid "Default: <quote>*</quote>" msgstr "Типове значення: <quote>*</quote>" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1279 +#: sssd.conf.5.xml:1249 +#, fuzzy +#| msgid "" +#| "Default: <quote>not set</quote> (remote domains), <quote>x</quote> (proxy " +#| "domain with nss_files and sssd-shadowutils target)" msgid "" -"Note: This option can also be set per-domain which overwrites the value in " -"[nss] section." +"Default (per-domain): <quote>not set</quote> (remote domains), <quote>x</" +"quote> (proxy domain with nss_files and sssd-shadowutils target)" msgstr "" -"Зауваження: значення цього параметра можна встановлювати для кожного з " -"доменів окремо. При цьому це значення матиме вищий пріоритет за значення у " -"розділі [nss]." - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1283 -msgid "" -"Default: <quote>not set</quote> (remote domains), <quote>x</quote> (proxy " -"domain with nss_files and sssd-shadowutils target)" -msgstr "" -"Типове значення: <quote>не встановлено</quote> (віддалені домени), <quote>x</" -"quote> (проміжний домен із цілі nss_files і sssd-shadowutils)" +"Типове значення: <quote>не встановлено</quote> (віддалені домени), <quote>x</" +"quote> (проміжний домен із цілі nss_files і sssd-shadowutils)" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:1292 +#: sssd.conf.5.xml:1258 msgid "PAM configuration options" msgstr "Параметри налаштування PAM" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:1294 +#: sssd.conf.5.xml:1260 +#, fuzzy +#| msgid "" +#| "These options can be used to configure the Pluggable Authentication " +#| "Module (PAM) service." msgid "" "These options can be used to configure the Pluggable Authentication Module " -"(PAM) service." +"(PAM) service and should be specified under the <quote>[pam]</quote> section." msgstr "" "Цими параметрами можна скористатися для налаштування служби Pluggable " "Authentication Module (PAM або блокового модуля розпізнавання)." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1299 +#: sssd.conf.5.xml:1266 msgid "offline_credentials_expiration (integer)" msgstr "offline_credentials_expiration (ціле число)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1302 +#: sssd.conf.5.xml:1269 msgid "" "If the authentication provider is offline, how long should we allow cached " "logins (in days since the last successful online login)." @@ -1999,17 +1952,17 @@ msgstr "" "входу до системи)." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1307 sssd.conf.5.xml:1320 +#: sssd.conf.5.xml:1274 sssd.conf.5.xml:1287 msgid "Default: 0 (No limit)" msgstr "Типове значення: 0 (без обмежень)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1313 +#: sssd.conf.5.xml:1280 msgid "offline_failed_login_attempts (integer)" msgstr "offline_failed_login_attempts (ціле число)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1316 +#: sssd.conf.5.xml:1283 msgid "" "If the authentication provider is offline, how many failed login attempts " "are allowed." @@ -2018,12 +1971,12 @@ msgstr "" "дозволену кількість спроб входу з визначенням помилкового пароля." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1326 +#: sssd.conf.5.xml:1293 msgid "offline_failed_login_delay (integer)" msgstr "offline_failed_login_delay (ціле число)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1329 +#: sssd.conf.5.xml:1296 msgid "" "The time in minutes which has to pass after offline_failed_login_attempts " "has been reached before a new login attempt is possible." @@ -2033,7 +1986,7 @@ msgstr "" "системи." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1334 +#: sssd.conf.5.xml:1301 msgid "" "If set to 0 the user cannot authenticate offline if " "offline_failed_login_attempts has been reached. Only a successful online " @@ -2045,17 +1998,17 @@ msgstr "" "увімкнути можливість автономного розпізнавання." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1340 sssd.conf.5.xml:1450 +#: sssd.conf.5.xml:1307 sssd.conf.5.xml:1417 msgid "Default: 5" msgstr "Типове значення: 5" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1346 +#: sssd.conf.5.xml:1313 msgid "pam_verbosity (integer)" msgstr "pam_verbosity (ціле число)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1349 +#: sssd.conf.5.xml:1316 msgid "" "Controls what kind of messages are shown to the user during authentication. " "The higher the number to more messages are displayed." @@ -2064,43 +2017,43 @@ msgstr "" "розпізнавання. Чим більшим є значення, тим більше повідомлень буде показано." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1354 +#: sssd.conf.5.xml:1321 msgid "Currently sssd supports the following values:" msgstr "У поточній версії sssd передбачено підтримку таких значень:" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1357 +#: sssd.conf.5.xml:1324 msgid "<emphasis>0</emphasis>: do not show any message" msgstr "<emphasis>0</emphasis>: не показувати жодних повідомлень" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1360 +#: sssd.conf.5.xml:1327 msgid "<emphasis>1</emphasis>: show only important messages" msgstr "<emphasis>1</emphasis>: показувати лише важливі повідомлення" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1364 +#: sssd.conf.5.xml:1331 msgid "<emphasis>2</emphasis>: show informational messages" msgstr "<emphasis>2</emphasis>: показувати всі інформаційні повідомлення" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1367 +#: sssd.conf.5.xml:1334 msgid "<emphasis>3</emphasis>: show all messages and debug information" msgstr "" "<emphasis>3</emphasis>: показувати всі повідомлення та діагностичні дані" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1371 sssd.8.xml:63 +#: sssd.conf.5.xml:1338 sssd.8.xml:63 msgid "Default: 1" msgstr "Типове значення: 1" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1377 +#: sssd.conf.5.xml:1344 msgid "pam_response_filter (string)" msgstr "pam_response_filter (рядок)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1380 +#: sssd.conf.5.xml:1347 msgid "" "A comma separated list of strings which allows to remove (filter) data sent " "by the PAM responder to pam_sss PAM module. There are different kind of " @@ -2114,7 +2067,7 @@ msgstr "" "встановлювати за допомогою pam_sss." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1388 +#: sssd.conf.5.xml:1355 msgid "" "While messages already can be controlled with the help of the pam_verbosity " "option this option allows to filter out other kind of responses as well." @@ -2124,37 +2077,37 @@ msgstr "" "повідомлень." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1395 +#: sssd.conf.5.xml:1362 msgid "ENV" msgstr "ENV" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1396 +#: sssd.conf.5.xml:1363 msgid "Do not send any environment variables to any service." msgstr "Не надсилати жодних змінних середовища до жодної служби." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1399 +#: sssd.conf.5.xml:1366 msgid "ENV:var_name" msgstr "ENV:назва_змінної" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1400 +#: sssd.conf.5.xml:1367 msgid "Do not send environment variable var_name to any service." msgstr "Не надсилати змінної середовища назва_змінної до жодної служби." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1404 +#: sssd.conf.5.xml:1371 msgid "ENV:var_name:service" msgstr "ENV:назва_змінної:служба" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1405 +#: sssd.conf.5.xml:1372 msgid "Do not send environment variable var_name to service." msgstr "Не надсилати змінної середовища назва_змінної до вказаної служби." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1393 +#: sssd.conf.5.xml:1360 msgid "" "Currently the following filters are supported: <placeholder " "type=\"variablelist\" id=\"0\"/>" @@ -2163,7 +2116,7 @@ msgstr "" "type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1412 +#: sssd.conf.5.xml:1379 msgid "" "The list of strings can either be the list of filters which would set this " "list of filters and overwrite the defaults. Or each element of the list can " @@ -2181,23 +2134,23 @@ msgstr "" "Змішування стилів вважається помилкою." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1423 +#: sssd.conf.5.xml:1390 msgid "Default: ENV:KRB5CCNAME:sudo, ENV:KRB5CCNAME:sudo-i" msgstr "Типове значення: ENV:KRB5CCNAME:sudo, ENV:KRB5CCNAME:sudo-i" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1426 +#: sssd.conf.5.xml:1393 msgid "" "Example: -ENV:KRB5CCNAME:sudo-i will remove the filter from the default list" msgstr "Приклад: -ENV:KRB5CCNAME:sudo-i вилучає фільтр зі списку типових" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1433 +#: sssd.conf.5.xml:1400 msgid "pam_id_timeout (integer)" msgstr "pam_id_timeout (ціле число)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1436 +#: sssd.conf.5.xml:1403 msgid "" "For any PAM request while SSSD is online, the SSSD will attempt to " "immediately update the cached identity information for the user in order to " @@ -2208,7 +2161,7 @@ msgstr "" "що розпізнавання виконується на основі найсвіжіших даних." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1442 +#: sssd.conf.5.xml:1409 msgid "" "A complete PAM conversation may perform multiple PAM requests, such as " "account management and session opening. This option controls (on a per-" @@ -2222,18 +2175,18 @@ msgstr "" "надання даних профілів." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1456 +#: sssd.conf.5.xml:1423 msgid "pam_pwd_expiration_warning (integer)" msgstr "pam_pwd_expiration_warning (ціле число)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1459 sssd.conf.5.xml:2912 +#: sssd.conf.5.xml:1426 sssd.conf.5.xml:3037 msgid "Display a warning N days before the password expires." msgstr "" "Показати попередження за вказану кількість днів перед завершенням дії пароля." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1462 +#: sssd.conf.5.xml:1429 msgid "" "Please note that the backend server has to provide information about the " "expiration time of the password. If this information is missing, sssd " @@ -2244,7 +2197,7 @@ msgstr "" "попередження." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1468 sssd.conf.5.xml:2915 +#: sssd.conf.5.xml:1435 sssd.conf.5.xml:3040 msgid "" "If zero is set, then this filter is not applied, i.e. if the expiration " "warning was received from backend server, it will automatically be displayed." @@ -2254,7 +2207,7 @@ msgstr "" "буде автоматично показано." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1473 +#: sssd.conf.5.xml:1440 msgid "" "This setting can be overridden by setting <emphasis>pwd_expiration_warning</" "emphasis> for a particular domain." @@ -2263,18 +2216,18 @@ msgstr "" "pwd_expiration_warning</emphasis> для окремого домену." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1478 sssd.conf.5.xml:3913 sssd-ldap.5.xml:662 +#: sssd.conf.5.xml:1445 sssd.conf.5.xml:4118 sssd-ldap.5.xml:662 #: sssd-ldap.5.xml:1733 sssd.8.xml:79 msgid "Default: 0" msgstr "Типове значення: 0" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1495 +#: sssd.conf.5.xml:1462 msgid "pam_trusted_users (string)" msgstr "pam_trusted_users (рядок)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1498 +#: sssd.conf.5.xml:1465 msgid "" "Specifies the comma-separated list of UID values or user names that are " "allowed to run PAM conversations against trusted domains. Users not " @@ -2290,13 +2243,13 @@ msgstr "" "запуску системи." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1508 +#: sssd.conf.5.xml:1475 msgid "Default: All users are considered trusted by default" msgstr "" "Типове значення: типово усі користувачі вважаються надійними (довіреними)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1512 +#: sssd.conf.5.xml:1479 msgid "" "Please note that UID 0 is always allowed to access the PAM responder even in " "case it is not in the pam_trusted_users list." @@ -2305,12 +2258,12 @@ msgstr "" "відповідача PAM, навіть якщо користувача немає у списку pam_trusted_users." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1519 +#: sssd.conf.5.xml:1486 msgid "pam_public_domains (string)" msgstr "pam_public_domains (рядок)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1522 +#: sssd.conf.5.xml:1489 msgid "" "Specifies the comma-separated list of domain names that are accessible even " "to untrusted users." @@ -2319,12 +2272,12 @@ msgstr "" "отримувати навіть ненадійні користувачі." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1526 +#: sssd.conf.5.xml:1493 msgid "Two special values for pam_public_domains option are defined:" msgstr "Визначено два спеціальних значення параметра pam_public_domains:" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1530 +#: sssd.conf.5.xml:1497 msgid "" "all (Untrusted users are allowed to access all domains in PAM responder.)" msgstr "" @@ -2332,7 +2285,7 @@ msgstr "" "PAM.)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1534 +#: sssd.conf.5.xml:1501 msgid "" "none (Untrusted users are not allowed to access any domains PAM in " "responder.)" @@ -2341,18 +2294,18 @@ msgstr "" "відповідачі.)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1538 sssd.conf.5.xml:1563 sssd.conf.5.xml:1582 -#: sssd.conf.5.xml:1824 sssd.conf.5.xml:3842 sssd-ldap.5.xml:1270 +#: sssd.conf.5.xml:1505 sssd.conf.5.xml:1530 sssd.conf.5.xml:1549 +#: sssd.conf.5.xml:1821 sssd.conf.5.xml:4048 sssd-ldap.5.xml:1270 msgid "Default: none" msgstr "Типове значення: none" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1543 +#: sssd.conf.5.xml:1510 msgid "pam_account_expired_message (string)" msgstr "pam_account_expired_message (рядок)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1546 +#: sssd.conf.5.xml:1513 msgid "" "Allows a custom expiration message to be set, replacing the default " "'Permission denied' message." @@ -2361,7 +2314,7 @@ msgstr "" "замінити типове повідомлення «Доступ заборонено» («Permission denied»)." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1551 +#: sssd.conf.5.xml:1518 msgid "" "Note: Please be aware that message is only printed for the SSH service " "unless pam_verbosity is set to 3 (show all messages and debug information)." @@ -2371,7 +2324,7 @@ msgstr "" "(показувати усі повідомлення і діагностичні дані)." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1559 +#: sssd.conf.5.xml:1526 #, no-wrap msgid "" "pam_account_expired_message = Account expired, please contact help desk.\n" @@ -2381,12 +2334,12 @@ msgstr "" " " #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1568 +#: sssd.conf.5.xml:1535 msgid "pam_account_locked_message (string)" msgstr "pam_account_locked_message (рядок)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1571 +#: sssd.conf.5.xml:1538 msgid "" "Allows a custom lockout message to be set, replacing the default 'Permission " "denied' message." @@ -2395,7 +2348,7 @@ msgstr "" "типове повідомлення «Доступ заборонено» («Permission denied»)." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1578 +#: sssd.conf.5.xml:1545 #, no-wrap msgid "" "pam_account_locked_message = Account locked, please contact help desk.\n" @@ -2405,46 +2358,52 @@ msgstr "" " " #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1587 -msgid "pam_passkey_auth (bool)" +#: sssd.conf.5.xml:1554 +#, fuzzy +#| msgid "pam_passkey_auth (bool)" +msgid "pam_passkey_auth (boolean)" msgstr "pam_passkey_auth (булеве значення)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1590 +#: sssd.conf.5.xml:1557 msgid "Enable passkey device based authentication." msgstr "Увімкнути розпізнавання на основі пристрою ключа." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1593 sssd.conf.5.xml:1910 sssd-ad.5.xml:1286 +#: sssd.conf.5.xml:1560 sssd.conf.5.xml:1907 sssd-ad.5.xml:1279 #: sss_rpcidmapd.5.xml:76 msgid "Default: True" msgstr "Типове значення: True" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1598 -msgid "passkey_debug_libfido2 (bool)" +#: sssd.conf.5.xml:1565 +#, fuzzy +#| msgid "passkey_debug_libfido2 (bool)" +msgid "passkey_debug_libfido2 (boolean)" msgstr "passkey_debug_libfido2 (булеве значення)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1601 +#: sssd.conf.5.xml:1568 msgid "Enable libfido2 library debug messages." msgstr "Увімкнути діагностичні повідомлення бібліотеки libfido2." #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1604 sssd.conf.5.xml:1618 sssd-ldap.5.xml:727 -#: sssd-ldap.5.xml:752 sssd-ldap.5.xml:848 sssd-ldap.5.xml:1356 -#: sssd-ad.5.xml:506 sssd-ad.5.xml:582 sssd-ad.5.xml:1155 +#: sssd.conf.5.xml:1571 sssd.conf.5.xml:1585 sssd.conf.5.xml:4781 +#: sssd-ldap.5.xml:727 sssd-ldap.5.xml:752 sssd-ldap.5.xml:848 +#: sssd-ldap.5.xml:1356 sssd-ad.5.xml:506 sssd-ad.5.xml:582 sssd-ad.5.xml:1160 #: include/ldap_id_mapping.xml:250 msgid "Default: False" msgstr "Типове значення: False" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1609 -msgid "pam_cert_auth (bool)" +#: sssd.conf.5.xml:1576 +#, fuzzy +#| msgid "pam_cert_auth (bool)" +msgid "pam_cert_auth (boolean)" msgstr "pam_cert_auth (булеве значення)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1612 +#: sssd.conf.5.xml:1579 msgid "" "Enable certificate based Smartcard authentication. Since this requires " "additional communication with the Smartcard which will delay the " @@ -2454,23 +2413,64 @@ msgstr "" "потребує додаткового обміну даним із смарткарткою, що затримує процес " "розпізнавання, типово таку сертифікацію вимкнено." +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1588 +msgid "" +"Note: In case OpenSC is used for Smartcard access SSSD supports the " +"filesystem caching in OpenSC when enabled in opensc.conf. The cached files " +"are located in a common <quote>opensc</quote> directory in SSSD's state " +"directory. The behaviour can be changed in opensc.conf" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> +#: sssd.conf.5.xml:1597 +#, no-wrap +msgid "" +"app /usr/libexec/sssd/p11_child {\n" +" framework pkcs15 {\n" +" use_file_caching = no;\n" +" }\n" +"}\n" +"app /usr/libexec/sssd/krb5_child {\n" +" framework pkcs15 {\n" +" use_file_caching = no;\n" +" }\n" +"}\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1595 +#, fuzzy +#| msgid "Example: <placeholder type=\"programlisting\" id=\"0\"/>" +msgid "" +"Example opensc.conf (*): <placeholder type=\"programlisting\" id=\"0\"/>" +msgstr "Приклад: <placeholder type=\"programlisting\" id=\"0\"/>" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1610 +msgid "" +"(*) The actual <quote>libexec</quote> directory for p11_child and krb5_child " +"depends on the distribution." +msgstr "" + #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1623 +#: sssd.conf.5.xml:1615 msgid "pam_cert_db_path (string)" msgstr "pam_cert_db_path (рядок)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1626 +#: sssd.conf.5.xml:1618 msgid "The path to the certificate database." msgstr "Шлях до бази даних сертифікатів." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1629 sssd.conf.5.xml:2163 sssd.conf.5.xml:4338 +#: sssd.conf.5.xml:1621 sssd.conf.5.xml:2199 sssd.conf.5.xml:4543 msgid "Default:" msgstr "Типове значення:" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1631 sssd.conf.5.xml:2165 +#: sssd.conf.5.xml:1623 sssd.conf.5.xml:2201 msgid "" "/etc/sssd/pki/sssd_auth_ca_db.pem (path to a file with trusted CA " "certificates in PEM format)" @@ -2479,12 +2479,12 @@ msgstr "" "служб сертифікації у форматі PEM)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1641 +#: sssd.conf.5.xml:1633 msgid "pam_cert_verification (string)" msgstr "pam_cert_verification (рядок)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1644 +#: sssd.conf.5.xml:1636 msgid "" "With this parameter the PAM certificate verification can be tuned with a " "comma separated list of options that override the " @@ -2499,7 +2499,7 @@ msgstr "" "<quote>certificate_verification</quote>." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1655 +#: sssd.conf.5.xml:1647 #, no-wrap msgid "" "pam_cert_verification = partial_chain\n" @@ -2509,7 +2509,7 @@ msgstr "" " " #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1659 +#: sssd.conf.5.xml:1651 msgid "" "Default: not set, i.e. use default <quote>certificate_verification</quote> " "option defined in <quote>[sssd]</quote> section." @@ -2519,24 +2519,24 @@ msgstr "" "[sssd]</quote>." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1666 +#: sssd.conf.5.xml:1658 msgid "p11_child_timeout (integer)" msgstr "p11_child_timeout (ціле число)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1669 +#: sssd.conf.5.xml:1661 msgid "How many seconds will pam_sss wait for p11_child to finish." msgstr "" "Час у секундах, протягом якого pam_sss очікуватиме на завершення роботи " "p11_child." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1678 +#: sssd.conf.5.xml:1670 msgid "passkey_child_timeout (integer)" msgstr "passkey_child_timeout (ціле число)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1681 +#: sssd.conf.5.xml:1673 msgid "" "How many seconds will the PAM responder wait for passkey_child to finish." msgstr "" @@ -2544,12 +2544,12 @@ msgstr "" "роботи passkey_child." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1690 +#: sssd.conf.5.xml:1682 msgid "pam_app_services (string)" msgstr "pam_app_services (рядок)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1693 +#: sssd.conf.5.xml:1685 msgid "" "Which PAM services are permitted to contact domains of type " "<quote>application</quote>" @@ -2558,12 +2558,12 @@ msgstr "" "типу <quote>application</quote>" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1702 +#: sssd.conf.5.xml:1694 msgid "pam_p11_allowed_services (string)" msgstr "pam_p11_allowed_services (рядок)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1705 +#: sssd.conf.5.xml:1697 msgid "" "A comma-separated list of PAM service names for which it will be allowed to " "use Smartcards." @@ -2572,7 +2572,7 @@ msgstr "" "використання смарткарток." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1720 +#: sssd.conf.5.xml:1712 #, no-wrap msgid "" "pam_p11_allowed_services = +my_pam_service, -login\n" @@ -2582,7 +2582,7 @@ msgstr "" " " #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1709 +#: sssd.conf.5.xml:1701 msgid "" "It is possible to add another PAM service name to the default set by using " "<quote>+service_name</quote> or to explicitly remove a PAM service name from " @@ -2601,69 +2601,76 @@ msgstr "" "type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1724 sssd-ad.5.xml:645 sssd-ad.5.xml:754 sssd-ad.5.xml:812 -#: sssd-ad.5.xml:870 sssd-ad.5.xml:948 +#: sssd.conf.5.xml:1716 sssd-ad.5.xml:645 sssd-ad.5.xml:759 sssd-ad.5.xml:817 +#: sssd-ad.5.xml:875 sssd-ad.5.xml:953 msgid "Default: the default set of PAM service names includes:" msgstr "" "Типове значення: типовий набір назв служб PAM складається з таких значень:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1729 sssd-ad.5.xml:649 +#: sssd.conf.5.xml:1721 sssd-ad.5.xml:649 msgid "login" msgstr "login" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1734 sssd-ad.5.xml:654 +#: sssd.conf.5.xml:1726 sssd-ad.5.xml:654 msgid "su" msgstr "su" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1739 sssd-ad.5.xml:659 +#: sssd.conf.5.xml:1731 sssd-ad.5.xml:659 msgid "su-l" msgstr "su-l" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1744 sssd-ad.5.xml:674 +#: sssd.conf.5.xml:1736 sssd-ad.5.xml:674 msgid "gdm-smartcard" msgstr "gdm-smartcard" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1749 sssd-ad.5.xml:669 +#: sssd.conf.5.xml:1741 sssd-ad.5.xml:669 msgid "gdm-password" msgstr "gdm-password" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1754 +#: sssd.conf.5.xml:1746 msgid "gdm-switchable-auth" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1759 sssd-ad.5.xml:679 +#: sssd.conf.5.xml:1751 sssd-ad.5.xml:679 msgid "kdm" msgstr "kdm" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1764 sssd-ad.5.xml:957 +#: sssd.conf.5.xml:1756 sssd-ad.5.xml:694 +#, fuzzy +#| msgid "login" +msgid "plasmalogin" +msgstr "login" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:1761 sssd-ad.5.xml:962 msgid "sudo" msgstr "sudo" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1769 sssd-ad.5.xml:962 +#: sssd.conf.5.xml:1766 sssd-ad.5.xml:967 msgid "sudo-i" msgstr "sudo-i" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1774 +#: sssd.conf.5.xml:1771 msgid "gnome-screensaver" msgstr "gnome-screensaver" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1782 +#: sssd.conf.5.xml:1779 msgid "p11_wait_for_card_timeout (integer)" msgstr "p11_wait_for_card_timeout (ціле число)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1785 +#: sssd.conf.5.xml:1782 msgid "" "If Smartcard authentication is required how many extra seconds in addition " "to p11_child_timeout should the PAM responder wait until a Smartcard is " @@ -2674,12 +2681,12 @@ msgstr "" "має чекати на вставлення смарткартки." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1796 +#: sssd.conf.5.xml:1793 msgid "p11_uri (string)" msgstr "p11_uri (рядок)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1799 +#: sssd.conf.5.xml:1796 msgid "" "PKCS#11 URI (see RFC-7512 for details) which can be used to restrict the " "selection of devices used for Smartcard authentication. By default SSSD's " @@ -2698,7 +2705,7 @@ msgstr "" "слід використовувати вказаний зчитувач." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1812 +#: sssd.conf.5.xml:1809 #, no-wrap msgid "" "p11_uri = pkcs11:slot-description=My%20Smartcard%20Reader\n" @@ -2708,7 +2715,7 @@ msgstr "" " " #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1816 +#: sssd.conf.5.xml:1813 #, no-wrap msgid "" "p11_uri = pkcs11:library-description=OpenSC%20smartcard%20framework;slot-id=2\n" @@ -2719,7 +2726,7 @@ msgstr "" " " #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1810 +#: sssd.conf.5.xml:1807 msgid "" "Example: <placeholder type=\"programlisting\" id=\"0\"/> or <placeholder " "type=\"programlisting\" id=\"1\"/> To find suitable URI please check the " @@ -2733,17 +2740,19 @@ msgstr "" "який покаже і адреси PKCS#11." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1829 -msgid "pam_initgroups_scheme" +#: sssd.conf.5.xml:1826 +#, fuzzy +#| msgid "pam_initgroups_scheme" +msgid "pam_initgroups_scheme (string)" msgstr "pam_initgroups_scheme" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1837 +#: sssd.conf.5.xml:1834 msgid "always" msgstr "always" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1838 +#: sssd.conf.5.xml:1835 msgid "" "Always do an online lookup, please note that pam_id_timeout still applies" msgstr "" @@ -2751,12 +2760,12 @@ msgstr "" "буде все одно застосовано" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1842 +#: sssd.conf.5.xml:1839 msgid "no_session" msgstr "no_session" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1843 +#: sssd.conf.5.xml:1840 msgid "" "Only do an online lookup if there is no active session of the user, i.e. if " "the user is currently not logged in" @@ -2765,12 +2774,12 @@ msgstr "" "тобто якщо користувач не працює у системі" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1848 sssd-ldap.5.xml:189 +#: sssd.conf.5.xml:1845 sssd-ldap.5.xml:189 msgid "never" msgstr "never" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1849 +#: sssd.conf.5.xml:1846 msgid "" "Never force an online lookup, use the data from the cache as long as they " "are not expired" @@ -2779,7 +2788,7 @@ msgstr "" "аж доки вони не застаріють" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1832 +#: sssd.conf.5.xml:1829 msgid "" "The PAM responder can force an online lookup to get the current group " "memberships of the user trying to log in. This option controls when this " @@ -2792,17 +2801,19 @@ msgstr "" "таких значень: <placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1856 +#: sssd.conf.5.xml:1853 msgid "Default: no_session" msgstr "Типове значення: no_session" -#. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:1861 sssd.conf.5.xml:4277 -msgid "pam_gssapi_services" -msgstr "pam_gssapi_services" +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1858 +#, fuzzy +#| msgid "pam_app_services (string)" +msgid "pam_gssapi_services (string)" +msgstr "pam_app_services (рядок)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1864 +#: sssd.conf.5.xml:1861 msgid "" "Comma separated list of PAM services that are allowed to try GSSAPI " "authentication using pam_sss_gss.so module." @@ -2811,7 +2822,7 @@ msgstr "" "розпізнавання за GSSAPI за допомогою модуля pam_sss_gss.so." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1869 +#: sssd.conf.5.xml:1866 msgid "" "To disable GSSAPI authentication, set this option to <quote>-</quote> (dash)." msgstr "" @@ -2819,7 +2830,7 @@ msgstr "" "значення <quote>-</quote> (дефіс)." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1873 sssd.conf.5.xml:1904 sssd.conf.5.xml:1942 +#: sssd.conf.5.xml:1870 sssd.conf.5.xml:1901 sssd.conf.5.xml:1939 msgid "" "Note: This option can also be set per-domain which overwrites the value in " "[pam] section. It can also be set for trusted domain which overwrites the " @@ -2831,7 +2842,7 @@ msgstr "" "вищий пріоритет за значення у розділі домену." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1881 +#: sssd.conf.5.xml:1878 #, no-wrap msgid "" "pam_gssapi_services = sudo, sudo-i\n" @@ -2841,22 +2852,24 @@ msgstr "" " " #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1879 sssd.conf.5.xml:1994 sssd.conf.5.xml:3836 +#: sssd.conf.5.xml:1876 sssd.conf.5.xml:2023 sssd.conf.5.xml:4042 msgid "Example: <placeholder type=\"programlisting\" id=\"0\"/>" msgstr "Приклад: <placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1885 +#: sssd.conf.5.xml:1882 msgid "Default: - (GSSAPI authentication is disabled)" msgstr "Типове значення: - (розпізнавання за GSSAPI вимкнено)" -#. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:1890 sssd.conf.5.xml:4278 -msgid "pam_gssapi_check_upn" +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1887 +#, fuzzy +#| msgid "pam_gssapi_check_upn" +msgid "pam_gssapi_check_upn (boolean)" msgstr "pam_gssapi_check_upn" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1893 +#: sssd.conf.5.xml:1890 msgid "" "If True, SSSD will require that the Kerberos user principal that " "successfully authenticated through GSSAPI can be associated with the user " @@ -2868,21 +2881,27 @@ msgstr "" "вважатиметься неуспішним, якщо перевірку не буде пройдено." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1900 +#: sssd.conf.5.xml:1897 +#, fuzzy +#| msgid "" +#| "If False, every user that is able to obtained required service ticket " +#| "will be authenticated." msgid "" -"If False, every user that is able to obtained required service ticket will " +"If False, every user that is able to obtain a required service ticket will " "be authenticated." msgstr "" "Якщо має значення False, розпізнаними вважатимуться усі користувачі, які " "зможуть отримати бажаний квиток служби." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1915 -msgid "pam_gssapi_indicators_map" +#: sssd.conf.5.xml:1912 +#, fuzzy +#| msgid "pam_gssapi_indicators_map" +msgid "pam_gssapi_indicators_map (string)" msgstr "pam_gssapi_indicators_map" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1918 +#: sssd.conf.5.xml:1915 msgid "" "Comma separated list of authentication indicators required to be present in " "a Kerberos ticket to access a PAM service that is allowed to try GSSAPI " @@ -2893,7 +2912,7 @@ msgstr "" "відокремлених комами індикаторів розпізнавання." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1924 +#: sssd.conf.5.xml:1921 msgid "" "Each element of the list can be either an authentication indicator name or a " "pair <quote>service:indicator</quote>. Indicators not prefixed with the PAM " @@ -2918,7 +2937,7 @@ msgstr "" "служби PAM є порожнім, перевірка не закриватиме доступ для жодного запису." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1937 +#: sssd.conf.5.xml:1934 msgid "" "To disable GSSAPI authentication indicator check, set this option to <quote>-" "</quote> (dash). To disable the check for a specific PAM service, add " @@ -2929,7 +2948,7 @@ msgstr "" "вимкнути перевірку для певної служби PAM, додайте <quote>служба:-</quote>." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1948 +#: sssd.conf.5.xml:1945 msgid "" "Following authentication indicators are supported by IPA Kerberos " "deployments:" @@ -2938,7 +2957,7 @@ msgstr "" "індикаторів розпізнавання:" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1951 +#: sssd.conf.5.xml:1948 msgid "" "pkinit -- pre-authentication using X.509 certificates -- whether stored in " "files or on smart cards." @@ -2947,7 +2966,7 @@ msgstr "" "зберігаються у файлах або на смарткартках." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1954 +#: sssd.conf.5.xml:1951 msgid "" "hardened -- SPAKE pre-authentication or any pre-authentication wrapped in a " "FAST channel." @@ -2956,12 +2975,12 @@ msgstr "" "розпізнавання у обгортці каналу FAST." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1957 +#: sssd.conf.5.xml:1954 msgid "radius -- pre-authentication with the help of a RADIUS server." msgstr "radius — попереднє розпізнавання за допомогою сервера RADIUS." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1960 +#: sssd.conf.5.xml:1957 msgid "" "otp -- pre-authentication using integrated two-factor authentication (2FA or " "one-time password, OTP) in IPA." @@ -2970,14 +2989,14 @@ msgstr "" "розпізнавання (2FA або одноразовий пароль, OTP) в IPA." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1963 +#: sssd.conf.5.xml:1960 msgid "idp -- pre-authentication using external identity provider." msgstr "" "idp — попереднє розпізнавання за допомогою зовнішнього надавача даних " "профілів." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1973 +#: sssd.conf.5.xml:1970 #, no-wrap msgid "" "pam_gssapi_indicators_map = sudo:pkinit, sudo-i:pkinit\n" @@ -2987,7 +3006,7 @@ msgstr "" " " #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1968 +#: sssd.conf.5.xml:1965 msgid "" "Example: to require access to SUDO services only for users which obtained " "their Kerberos tickets with a X.509 certificate pre-authentication (PKINIT), " @@ -2999,21 +3018,69 @@ msgstr "" "id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1977 +#: sssd.conf.5.xml:1974 msgid "Default: not set (use of authentication indicators is not required)" msgstr "" "Типове значення: не встановлено (немає потреби у використанні індикаторів " "розпізнавання)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1979 +#, fuzzy +#| msgid "pam_gssapi_indicators_map" +msgid "pam_gssapi_indicators_apply (string)" +msgstr "pam_gssapi_indicators_map" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1982 +msgid "" +"Comma separated list of triples to assign additional information from the " +"Kerberos ticket, e.g. a SID from the PAC, to authentication indicators." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1988 +#, fuzzy +#| msgid "Currently supported debug levels:" +msgid "Currently supported is:" +msgstr "Рівні діагностики, передбачені у поточній версії:" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:1991 +msgid "SID:S-1-5-[domain]-[RID]:[authentication indicator]" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> +#: sssd.conf.5.xml:2002 +#, fuzzy, no-wrap +#| msgid "" +#| "pam_gssapi_indicators_map = sudo:pkinit, sudo-i:pkinit\n" +#| " " +msgid "" +"pam_gssapi_indicators_apply = SID:S-1-5-12345-23456-34567-4321:pkinit\n" +" " +msgstr "" +"pam_gssapi_indicators_map = sudo:pkinit, sudo-i:pkinit\n" +" " + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1996 +msgid "" +"Example: To assign a SID, which is e.g. set by Active Directory's " +"Authentication Mechanism Assurance (AMA) if the AD user used a Smartcard for " +"authentication, to the 'pkinit' authentication indicator use: <placeholder " +"type=\"programlisting\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2011 #, fuzzy #| msgid "pam_app_services (string)" msgid "pam_json_services (string)" msgstr "pam_app_services (рядок)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1985 +#: sssd.conf.5.xml:2014 #, fuzzy #| msgid "" #| "Comma separated list of PAM services that are allowed to try GSSAPI " @@ -3026,7 +3093,7 @@ msgstr "" "розпізнавання за GSSAPI за допомогою модуля pam_sss_gss.so." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1990 +#: sssd.conf.5.xml:2019 #, fuzzy #| msgid "" #| "To disable GSSAPI authentication, set this option to <quote>-</quote> " @@ -3037,7 +3104,7 @@ msgstr "" "значення <quote>-</quote> (дефіс)." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1996 +#: sssd.conf.5.xml:2025 #, fuzzy, no-wrap #| msgid "" #| "pam_gssapi_services = sudo, sudo-i\n" @@ -3050,33 +3117,51 @@ msgstr "" " " #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2000 +#: sssd.conf.5.xml:2029 #, fuzzy #| msgid "Default: - (GSSAPI authentication is disabled)" msgid "Default: - (JSON protocol is disabled)" msgstr "Типове значення: - (розпізнавання за GSSAPI вимкнено)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2003 +#: sssd.conf.5.xml:2032 msgid "" "Note: 2-Factor Authentication (2FA) is not supported. If 2FA is required, do " "not activate the JSON protocol." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:2013 +#: sssd.conf.5.xml:2042 msgid "SUDO configuration options" msgstr "Параметри налаштування SUDO" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2015 +#: sssd.conf.5.xml:2044 +#, fuzzy +#| msgid "These options can be used to configure the session recording." msgid "" -"These options can be used to configure the sudo service. The detailed " -"instructions for configuration of <citerefentry> <refentrytitle>sudo</" -"refentrytitle> <manvolnum>8</manvolnum> </citerefentry> to work with " -"<citerefentry> <refentrytitle>sssd</refentrytitle> <manvolnum>8</manvolnum> " -"</citerefentry> are in the manual page <citerefentry> <refentrytitle>sssd-" -"sudo</refentrytitle> <manvolnum>5</manvolnum> </citerefentry>." +"These options can be used to configure the sudo service and should be " +"specified under the <quote>[sudo]</quote> section." +msgstr "Цими параметрами можна скористатися для налаштовування запису сеансів." + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:2048 +#, fuzzy +#| msgid "" +#| "These options can be used to configure the sudo service. The detailed " +#| "instructions for configuration of <citerefentry> <refentrytitle>sudo</" +#| "refentrytitle> <manvolnum>8</manvolnum> </citerefentry> to work with " +#| "<citerefentry> <refentrytitle>sssd</refentrytitle> <manvolnum>8</" +#| "manvolnum> </citerefentry> are in the manual page <citerefentry> " +#| "<refentrytitle>sssd-sudo</refentrytitle> <manvolnum>5</manvolnum> </" +#| "citerefentry>." +msgid "" +"The detailed instructions for configuration of <citerefentry> " +"<refentrytitle>sudo</refentrytitle> <manvolnum>8</manvolnum> </citerefentry> " +"to work with <citerefentry> <refentrytitle>sssd</refentrytitle> " +"<manvolnum>8</manvolnum> </citerefentry> are in the manual page " +"<citerefentry> <refentrytitle>sssd-sudo</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry>." msgstr "" "Цими параметрами можна скористатися для налаштовування служби sudo. Докладні " "настанови щодо налаштовування <citerefentry> <refentrytitle>sudo</" @@ -3087,12 +3172,14 @@ msgstr "" "citerefentry>." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2032 -msgid "sudo_timed (bool)" +#: sssd.conf.5.xml:2064 +#, fuzzy +#| msgid "sudo_timed (bool)" +msgid "sudo_timed (boolean)" msgstr "sudo_timed (булеве значення)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2035 +#: sssd.conf.5.xml:2067 msgid "" "Whether or not to evaluate the sudoNotBefore and sudoNotAfter attributes " "that implement time-dependent sudoers entries." @@ -3101,12 +3188,12 @@ msgstr "" "призначені для визначення часових обмежень для записів sudoers." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2047 +#: sssd.conf.5.xml:2079 msgid "sudo_threshold (integer)" msgstr "sudo_threshold (ціле число)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2050 +#: sssd.conf.5.xml:2082 msgid "" "Maximum number of expired rules that can be refreshed at once. If number of " "expired rules is below threshold, those rules are refreshed with " @@ -3122,22 +3209,26 @@ msgstr "" "sudo IPA та групових пошуків команд." #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:2069 +#: sssd.conf.5.xml:2101 msgid "AUTOFS configuration options" msgstr "Параметри налаштування AUTOFS" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2071 -msgid "These options can be used to configure the autofs service." +#: sssd.conf.5.xml:2103 +#, fuzzy +#| msgid "These options can be used to configure the autofs service." +msgid "" +"These options can be used to configure the autofs service and should be " +"specified under the <quote>[autofs]</quote> section." msgstr "Цими параметрами можна скористатися для налаштування служби autofs." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2075 +#: sssd.conf.5.xml:2109 msgid "autofs_negative_timeout (integer)" msgstr "autofs_negative_timeout (ціле число)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2078 +#: sssd.conf.5.xml:2112 msgid "" "Specifies for how many seconds should the autofs responder negative cache " "hits (that is, queries for invalid map entries, like nonexistent ones) " @@ -3148,22 +3239,28 @@ msgstr "" "базі даних, зокрема неіснуючих) перед повторним запитом до сервера обробки." #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:2094 +#: sssd.conf.5.xml:2128 msgid "SSH configuration options" msgstr "Параметри налаштувань SSH" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2096 -msgid "These options can be used to configure the SSH service." +#: sssd.conf.5.xml:2130 +#, fuzzy +#| msgid "These options can be used to configure the SSH service." +msgid "" +"These options can be used to configure the SSH service and should be " +"specified under the <quote>[ssh]</quote> section." msgstr "Цими параметрами можна скористатися для налаштування служби SSH." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2100 -msgid "ssh_use_certificate_keys (bool)" +#: sssd.conf.5.xml:2136 +#, fuzzy +#| msgid "ssh_use_certificate_keys (bool)" +msgid "ssh_use_certificate_keys (boolean)" msgstr "ssh_use_certificate_keys (булеве значення)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2103 +#: sssd.conf.5.xml:2139 msgid "" "If set to true the <command>sss_ssh_authorizedkeys</command> will return ssh " "keys derived from the public key of X.509 certificates stored in the user " @@ -3177,12 +3274,12 @@ msgstr "" "refentrytitle> <manvolnum>1</manvolnum> </citerefentry>." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2118 +#: sssd.conf.5.xml:2154 msgid "ssh_use_certificate_matching_rules (string)" msgstr "ssh_use_certificate_matching_rules (рядок)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2121 +#: sssd.conf.5.xml:2157 msgid "" "By default the ssh responder will use all available certificate matching " "rules to filter the certificates so that ssh keys are only derived from the " @@ -3198,7 +3295,7 @@ msgstr "" "відокремлених комами. Усі інші правила буде проігноровано." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2130 +#: sssd.conf.5.xml:2166 msgid "" "There are two special key words 'all_rules' and 'no_rules' which will enable " "all or no rules, respectively. The latter means that no certificates will be " @@ -3210,7 +3307,7 @@ msgstr "" "сертифікатів." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2137 +#: sssd.conf.5.xml:2173 msgid "" "If no rules are configured using 'all_rules' will enable a default rule " "which enables all certificates suitable for client authentication. This is " @@ -3223,7 +3320,7 @@ msgstr "" "розпізнавання за сертифікатом." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2144 +#: sssd.conf.5.xml:2180 msgid "" "A non-existing rule name is considered an error. If as a result no rule is " "selected all certificates will be ignored." @@ -3233,7 +3330,7 @@ msgstr "" "проігноровано." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2149 +#: sssd.conf.5.xml:2185 msgid "" "Default: not set, equivalent to 'all_rules', all found rules or the default " "rule are used" @@ -3242,12 +3339,12 @@ msgstr "" "використано усі знайдені правила або типове правило" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2155 +#: sssd.conf.5.xml:2191 msgid "ca_db (string)" msgstr "ca_db (рядок)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2158 +#: sssd.conf.5.xml:2194 msgid "" "Path to a storage of trusted CA certificates. The option is used to validate " "user certificates before deriving public ssh keys from them." @@ -3256,12 +3353,12 @@ msgstr "" "перевірки сертифікатів користувачів до отримання з них відкритих ключів ssh." #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:2178 +#: sssd.conf.5.xml:2214 msgid "PAC responder configuration options" msgstr "Параметри налаштування відповідача PAC" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2180 +#: sssd.conf.5.xml:2216 msgid "" "The PAC responder works together with the authorization data plugin for MIT " "Kerberos sssd_pac_plugin.so and a sub-domain provider. The plugin sends the " @@ -3279,7 +3376,7 @@ msgstr "" "декодовано і визначено, виконуються деякі з таких дій:" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:2189 +#: sssd.conf.5.xml:2225 msgid "" "If the remote user does not exist in the cache, it is created. The UID is " "determined with the help of the SID, trusted domains will have UPGs and the " @@ -3297,7 +3394,7 @@ msgstr "" "параметра default_shell." #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:2197 +#: sssd.conf.5.xml:2233 msgid "" "If there are SIDs of groups from domains sssd knows about, the user will be " "added to those groups." @@ -3306,17 +3403,22 @@ msgstr "" "додано до цих груп." #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2203 -msgid "These options can be used to configure the PAC responder." -msgstr "Цими параметрами можна скористатися для налаштовування відповідача PAC." +#: sssd.conf.5.xml:2239 +#, fuzzy +#| msgid "These options can be used to configure the PAC responder." +msgid "" +"These options can be used to configure the PAC responder and should be " +"specified under the <quote>[pac]</quote> section." +msgstr "" +"Цими параметрами можна скористатися для налаштовування відповідача PAC." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2207 sssd-ifp.5.xml:66 +#: sssd.conf.5.xml:2244 sssd-ifp.5.xml:66 msgid "allowed_uids (string)" msgstr "allowed_uids (рядок)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2210 +#: sssd.conf.5.xml:2247 msgid "" "Specifies the comma-separated list of UID values or user names that are " "allowed to access the PAC responder. User names are resolved to UIDs at " @@ -3327,7 +3429,7 @@ msgstr "" "іменами користувачів визначатимуться під час запуску." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2216 +#: sssd.conf.5.xml:2253 msgid "" "Default: 0, &sssd_user_name; (only root and SSSD service users are allowed " "to access the PAC responder)" @@ -3336,14 +3438,14 @@ msgstr "" "root і користувачі служб SSSD)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2220 +#: sssd.conf.5.xml:2257 msgid "Default: 0 (only the root user is allowed to access the PAC responder)" msgstr "" "Типове значення: 0 (доступ до відповідача PAC має лише адміністративний " "користувач (root))" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2224 +#: sssd.conf.5.xml:2261 msgid "" "Please note that defaults will be overwritten with this option. If you still " "want to allow the root and/or '&sssd_user_name;' user to access the PAC " @@ -3357,7 +3459,7 @@ msgstr "" "відповідні записи явно." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2231 +#: sssd.conf.5.xml:2268 msgid "" "Please note that although the UID 0 is used as the default it will be " "overwritten with this option. If you still want to allow the root user to " @@ -3371,12 +3473,12 @@ msgstr "" "запис 0." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2240 +#: sssd.conf.5.xml:2277 msgid "pac_lifetime (integer)" msgstr "pac_lifetime (ціле число)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2243 +#: sssd.conf.5.xml:2280 msgid "" "Lifetime of the PAC entry in seconds. As long as the PAC is valid the PAC " "data can be used to determine the group memberships of a user." @@ -3385,12 +3487,12 @@ msgstr "" "використовувати для визначення членства користувача у групі." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2253 +#: sssd.conf.5.xml:2290 msgid "pac_check (string)" msgstr "pac_check (рядок)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2256 +#: sssd.conf.5.xml:2293 msgid "" "Apply additional checks on the PAC of the Kerberos ticket which is available " "in Active Directory and FreeIPA domains, if configured. Please note that " @@ -3407,7 +3509,7 @@ msgstr "" "krb5_validate встановлено значення «False», перевірки PAC буде пропущено." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2266 +#: sssd.conf.5.xml:2303 msgid "" "Please note that the checks listed below only apply to PACs issued by Active " "Directory or recent versions of FreeIPA. PACs issued e.g. by a plain MIT " @@ -3415,12 +3517,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2277 +#: sssd.conf.5.xml:2314 msgid "no_check" msgstr "no_check" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2279 +#: sssd.conf.5.xml:2316 msgid "" "The PAC must not be present and even if it is present no additional checks " "will be done." @@ -3429,12 +3531,12 @@ msgstr "" "виконано не буде." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2285 +#: sssd.conf.5.xml:2322 msgid "pac_present" msgstr "pac_present" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2287 +#: sssd.conf.5.xml:2324 msgid "" "The PAC must be present in the service ticket which SSSD will request with " "the help of the user's TGT. If the PAC is not available the authentication " @@ -3445,12 +3547,12 @@ msgstr "" "зазнає невдачі." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2295 +#: sssd.conf.5.xml:2332 msgid "check_upn" msgstr "check_upn" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2297 +#: sssd.conf.5.xml:2334 msgid "" "If the PAC is present check if the user principal name (UPN) information is " "consistent." @@ -3459,12 +3561,12 @@ msgstr "" "користувача (UPN)." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2303 +#: sssd.conf.5.xml:2340 msgid "check_upn_allow_missing" msgstr "check_upn_allow_missing" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2305 +#: sssd.conf.5.xml:2342 msgid "" "This option should be used together with 'check_upn' and handles the case " "where a UPN is set on the server-side but is not read by SSSD. The typical " @@ -3484,7 +3586,7 @@ msgstr "" "потреби." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2317 +#: sssd.conf.5.xml:2354 msgid "" "Currently this option is set by default to avoid regressions in such " "environments. A log message will be added to the system log and SSSD's debug " @@ -3501,23 +3603,23 @@ msgstr "" "призведе до пропускання перевірки, і повідомлення зникне з журналу." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2331 +#: sssd.conf.5.xml:2368 msgid "upn_dns_info_present" msgstr "upn_dns_info_present" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2333 +#: sssd.conf.5.xml:2370 msgid "The PAC must contain the UPN-DNS-INFO buffer, implies 'check_upn'." msgstr "" "PAC має містити буфер UPN-DNS-INFO; неявним чином встановлює «check_upn»." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2338 +#: sssd.conf.5.xml:2375 msgid "check_upn_dns_info_ex" msgstr "check_upn_dns_info_ex" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2340 +#: sssd.conf.5.xml:2377 msgid "" "If the PAC is present and the extension to the UPN-DNS-INFO buffer is " "available check if the information in the extension is consistent." @@ -3526,12 +3628,12 @@ msgstr "" "узгодженими дані у розширенні." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2347 +#: sssd.conf.5.xml:2384 msgid "upn_dns_info_ex_present" msgstr "upn_dns_info_ex_present" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2349 +#: sssd.conf.5.xml:2386 msgid "" "The PAC must contain the extension of the UPN-DNS-INFO buffer, implies " "'check_upn_dns_info_ex', 'upn_dns_info_present' and 'check_upn'." @@ -3540,7 +3642,7 @@ msgstr "" "check_upn_dns_info_ex», «upn_dns_info_present» і «check_upn»." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2273 +#: sssd.conf.5.xml:2310 msgid "" "The following options can be used alone or in a comma-separated list: " "<placeholder type=\"variablelist\" id=\"0\"/>" @@ -3549,7 +3651,7 @@ msgstr "" "відокремлених комами значень: <placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2359 +#: sssd.conf.5.xml:2396 msgid "" "Default: no_check (AD and IPA provider 'check_upn, check_upn_allow_missing, " "check_upn_dns_info_ex')" @@ -3558,12 +3660,12 @@ msgstr "" "check_upn_allow_missing, check_upn_dns_info_ex»)" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:2368 +#: sssd.conf.5.xml:2405 msgid "Session recording configuration options" msgstr "Параметри налаштовування запису сеансів" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2370 +#: sssd.conf.5.xml:2407 msgid "" "Session recording works in conjunction with <citerefentry> " "<refentrytitle>tlog-rec-session</refentrytitle> <manvolnum>8</manvolnum> </" @@ -3578,32 +3680,46 @@ msgstr "" "session-recording</refentrytitle> <manvolnum>5</manvolnum> </citerefentry>." #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2383 -msgid "These options can be used to configure session recording." +#: sssd.conf.5.xml:2420 +#, fuzzy +#| msgid "These options can be used to configure the session recording." +msgid "" +"These options can be used to configure session recording and should be " +"specified under the <quote>[session_recording]</quote> section." msgstr "Цими параметрами можна скористатися для налаштовування запису сеансів." +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:2425 +msgid "" +"Note: Unlike other sections, the <quote>[session_recording]</quote> section " +"ignores <replaceable>debug*</replaceable> options and suitable " +"<replaceable>debug*</replaceable> options must be set in <quote>[pam]</" +"quote>, <quote>[nss]</quote> and <quote>[domain/<replaceable>NAME</" +"replaceable>]</quote> sections." +msgstr "" + #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2387 sssd-session-recording.5.xml:64 +#: sssd.conf.5.xml:2433 sssd-session-recording.5.xml:64 msgid "scope (string)" msgstr "scope (рядок)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2394 sssd-session-recording.5.xml:71 +#: sssd.conf.5.xml:2440 sssd-session-recording.5.xml:71 msgid "\"none\"" msgstr "\"none\"" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2397 sssd-session-recording.5.xml:74 +#: sssd.conf.5.xml:2443 sssd-session-recording.5.xml:74 msgid "No users are recorded." msgstr "Користувачі не записуються." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2402 sssd-session-recording.5.xml:79 +#: sssd.conf.5.xml:2448 sssd-session-recording.5.xml:79 msgid "\"some\"" msgstr "\"some\"" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2405 sssd-session-recording.5.xml:82 +#: sssd.conf.5.xml:2451 sssd-session-recording.5.xml:82 msgid "" "Users/groups specified by <replaceable>users</replaceable> and " "<replaceable>groups</replaceable> options are recorded." @@ -3612,17 +3728,17 @@ msgstr "" "користувачі</replaceable> і <replaceable>групи</replaceable>." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2414 sssd-session-recording.5.xml:91 +#: sssd.conf.5.xml:2460 sssd-session-recording.5.xml:91 msgid "\"all\"" msgstr "\"all\"" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2417 sssd-session-recording.5.xml:94 +#: sssd.conf.5.xml:2463 sssd-session-recording.5.xml:94 msgid "All users are recorded." msgstr "Усі користувачі записуються." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2390 sssd-session-recording.5.xml:67 +#: sssd.conf.5.xml:2436 sssd-session-recording.5.xml:67 msgid "" "One of the following strings specifying the scope of session recording: " "<placeholder type=\"variablelist\" id=\"0\"/>" @@ -3631,17 +3747,17 @@ msgstr "" "<placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2424 sssd-session-recording.5.xml:101 +#: sssd.conf.5.xml:2470 sssd-session-recording.5.xml:101 msgid "Default: \"none\"" msgstr "Типове значення: none" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2429 sssd-session-recording.5.xml:106 +#: sssd.conf.5.xml:2475 sssd-session-recording.5.xml:106 msgid "users (string)" msgstr "users (рядок)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2432 sssd-session-recording.5.xml:109 +#: sssd.conf.5.xml:2478 sssd-session-recording.5.xml:109 msgid "" "A comma-separated list of users which should have session recording enabled. " "Matches user names as returned by NSS. I.e. after the possible space " @@ -3653,17 +3769,17 @@ msgstr "" "тощо." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2438 sssd-session-recording.5.xml:115 +#: sssd.conf.5.xml:2484 sssd-session-recording.5.xml:115 msgid "Default: Empty. Matches no users." msgstr "Типове значення: порожнє. Не відповідає жодному користувачу." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2443 sssd-session-recording.5.xml:120 +#: sssd.conf.5.xml:2489 sssd-session-recording.5.xml:120 msgid "groups (string)" msgstr "groups (рядок)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2446 sssd-session-recording.5.xml:123 +#: sssd.conf.5.xml:2492 sssd-session-recording.5.xml:123 msgid "" "A comma-separated list of groups, members of which should have session " "recording enabled. Matches group names as returned by NSS. I.e. after the " @@ -3675,7 +3791,7 @@ msgstr "" "символів тощо." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2452 sssd.conf.5.xml:2484 sssd-session-recording.5.xml:129 +#: sssd.conf.5.xml:2498 sssd.conf.5.xml:2530 sssd-session-recording.5.xml:129 #: sssd-session-recording.5.xml:161 msgid "" "NOTE: using this option (having it set to anything) has a considerable " @@ -3688,17 +3804,17 @@ msgstr "" "належить користувач." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2459 sssd-session-recording.5.xml:136 +#: sssd.conf.5.xml:2505 sssd-session-recording.5.xml:136 msgid "Default: Empty. Matches no groups." msgstr "Типове значення: порожнє. Не відповідає жодній групі." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2464 sssd-session-recording.5.xml:141 +#: sssd.conf.5.xml:2510 sssd-session-recording.5.xml:141 msgid "exclude_users (string)" msgstr "exclude_users (рядок)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2467 sssd-session-recording.5.xml:144 +#: sssd.conf.5.xml:2513 sssd-session-recording.5.xml:144 msgid "" "A comma-separated list of users to be excluded from recording, only " "applicable with 'scope=all'." @@ -3707,17 +3823,17 @@ msgstr "" "записування. Може бути застосовано лише разом із «scope=all»." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2471 sssd-session-recording.5.xml:148 +#: sssd.conf.5.xml:2517 sssd-session-recording.5.xml:148 msgid "Default: Empty. No users excluded." msgstr "Типове значення: порожнє. Не виключати жодного користувача." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2476 sssd-session-recording.5.xml:153 +#: sssd.conf.5.xml:2522 sssd-session-recording.5.xml:153 msgid "exclude_groups (string)" msgstr "exclude_groups (рядок)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2479 sssd-session-recording.5.xml:156 +#: sssd.conf.5.xml:2525 sssd-session-recording.5.xml:156 msgid "" "A comma-separated list of groups, members of which should be excluded from " "recording. Only applicable with 'scope=all'." @@ -3726,23 +3842,24 @@ msgstr "" "із записування. Може бути застосовано лише разом із «scope=all»." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2491 sssd-session-recording.5.xml:168 +#: sssd.conf.5.xml:2537 sssd-session-recording.5.xml:168 msgid "Default: Empty. No groups excluded." msgstr "Типове значення: порожнє. Не виключати жодної групи." #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:2501 +#: sssd.conf.5.xml:2547 msgid "DOMAIN SECTIONS" msgstr "РОЗДІЛИ ДОМЕНІВ" -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry><para> -#: sssd.conf.5.xml:2508 sssd.conf.5.xml:3964 sssd.conf.5.xml:3965 -#: sssd.conf.5.xml:3968 -msgid "enabled" -msgstr "enabled" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2554 +#, fuzzy +#| msgid "ad_enable_gc (boolean)" +msgid "enabled (boolean)" +msgstr "ad_enable_gc (булеве значення)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2511 +#: sssd.conf.5.xml:2557 msgid "" "Explicitly enable or disable the domain. If <quote>true</quote>, the domain " "is always <quote>enabled</quote>. If <quote>false</quote>, the domain is " @@ -3757,12 +3874,12 @@ msgstr "" "параметрі доменів у розділі <quote>[sssd]</quote>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2523 +#: sssd.conf.5.xml:2569 msgid "domain_type (string)" msgstr "domain_type (рядок)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2526 +#: sssd.conf.5.xml:2572 msgid "" "Specifies whether the domain is meant to be used by POSIX-aware clients such " "as the Name Service Switch or by applications that do not need POSIX data to " @@ -3775,7 +3892,7 @@ msgstr "" "з доменів POSIX." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2534 +#: sssd.conf.5.xml:2580 msgid "" "Allowed values for this option are <quote>posix</quote> and " "<quote>application</quote>." @@ -3784,7 +3901,7 @@ msgstr "" "application</quote>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2538 +#: sssd.conf.5.xml:2584 msgid "" "POSIX domains are reachable by all services. Application domains are only " "reachable from the InfoPipe responder (see <citerefentry> " @@ -3796,7 +3913,7 @@ msgstr "" "refentrytitle> <manvolnum>5</manvolnum> </citerefentry>) і відповідача PAM." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2546 +#: sssd.conf.5.xml:2592 msgid "" "NOTE: The application domains are currently well tested with " "<quote>id_provider=ldap</quote> only." @@ -3805,7 +3922,7 @@ msgstr "" "application з <quote>id_provider=ldap</quote>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2550 +#: sssd.conf.5.xml:2596 msgid "" "For an easy way to configure a non-POSIX domains, please see the " "<quote>Application domains</quote> section." @@ -3814,17 +3931,17 @@ msgstr "" "ласка, ознайомтеся із розділом <quote>Домени програм</quote>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2554 +#: sssd.conf.5.xml:2600 msgid "Default: posix" msgstr "Типове значення: posix" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2560 +#: sssd.conf.5.xml:2606 msgid "min_id,max_id (integer)" msgstr "min_id,max_id (ціле значення)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2563 +#: sssd.conf.5.xml:2609 msgid "" "UID and GID limits for the domain. If a domain contains an entry that is " "outside these limits, it is ignored." @@ -3833,7 +3950,7 @@ msgstr "" "відповідає цим обмеженням, його буде проігноровано." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2568 +#: sssd.conf.5.xml:2614 msgid "" "For users, this affects the primary GID limit. The user will not be returned " "to NSS if either the UID or the primary GID is outside the range. For non-" @@ -3846,7 +3963,7 @@ msgstr "" "основної групи і належать діапазону, буде виведено у звичайному режимі." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2575 +#: sssd.conf.5.xml:2621 msgid "" "These ID limits affect even saving entries to cache, not only returning them " "by name or ID." @@ -3855,17 +3972,19 @@ msgstr "" "лише повернення записів за назвою або ідентифікатором." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2579 +#: sssd.conf.5.xml:2625 msgid "Default: 1 for min_id, 0 (no limit) for max_id" msgstr "Типові значення: 1 для min_id, 0 (без обмежень) для max_id" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2585 -msgid "enumerate (bool)" +#: sssd.conf.5.xml:2631 +#, fuzzy +#| msgid "enumerate (bool)" +msgid "enumerate (boolean)" msgstr "enumerate (булеве значення)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2588 +#: sssd.conf.5.xml:2634 msgid "" "Determines if a domain can be enumerated, that is, whether the domain can " "list all the users and group it contains. Note that it is not required to " @@ -3878,22 +3997,22 @@ msgstr "" "мати такі значення:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2596 +#: sssd.conf.5.xml:2642 msgid "TRUE = Users and groups are enumerated" msgstr "TRUE = користувачі і групи нумеруються" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2599 +#: sssd.conf.5.xml:2645 msgid "FALSE = No enumerations for this domain" msgstr "FALSE = не використовувати нумерацію для цього домену" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2602 sssd.conf.5.xml:2867 sssd.conf.5.xml:3044 +#: sssd.conf.5.xml:2648 sssd.conf.5.xml:2992 sssd.conf.5.xml:3174 msgid "Default: FALSE" msgstr "Типове значення: FALSE" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2605 +#: sssd.conf.5.xml:2651 msgid "" "Enumerating a domain requires SSSD to download and store ALL user and group " "entries from the remote server." @@ -3902,7 +4021,7 @@ msgstr "" "користувачів і груп із віддаленого сервера." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2610 +#: sssd.conf.5.xml:2656 msgid "" "Feature is only supported for domains with id_provider = ldap or id_provider " "= proxy." @@ -3911,7 +4030,7 @@ msgstr "" "id_provider = proxy." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2614 +#: sssd.conf.5.xml:2660 msgid "" "Note: Enabling enumeration has a severe performance impact on SSSD while " "enumeration is running. It may take up to several minutes after SSSD startup " @@ -3934,7 +4053,7 @@ msgstr "" "sssd_be</quote> або навіть перезапуску усього засобу стеження." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2629 +#: sssd.conf.5.xml:2675 msgid "" "While the first enumeration is running, requests for the complete user or " "group lists may return no results until it completes." @@ -3944,7 +4063,7 @@ msgstr "" "завершено." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2634 +#: sssd.conf.5.xml:2680 msgid "" "Further, enabling enumeration may increase the time necessary to detect " "network disconnection, as longer timeouts are required to ensure that " @@ -3958,7 +4077,7 @@ msgstr "" "відповідного використаного засобу обробки ідентифікаторів (id_provider)." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2642 +#: sssd.conf.5.xml:2688 msgid "" "For the reasons cited above, enabling enumeration is not recommended, " "especially in large environments." @@ -3967,7 +4086,7 @@ msgstr "" "об’ємних середовищах." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2647 +#: sssd.conf.5.xml:2693 msgid "" "Note: the proxy provider is tested with open source modules like " "'libnss_files' and 'libnss_ldap'. 3rd party modules must follow the " @@ -3979,12 +4098,12 @@ msgstr "" "використано у цій конфігурації." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2656 +#: sssd.conf.5.xml:2702 msgid "entry_cache_timeout (integer)" msgstr "entry_cache_timeout (ціле число)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2659 +#: sssd.conf.5.xml:2705 msgid "" "How many seconds should nss_sss consider entries valid before asking the " "backend again" @@ -3993,7 +4112,7 @@ msgstr "" "надсилати повторний запит до сервера" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2663 +#: sssd.conf.5.xml:2709 msgid "" "The cache expiration timestamps are stored as attributes of individual " "objects in the cache. Therefore, changing the cache timeout only has effect " @@ -4010,17 +4129,17 @@ msgstr "" "8</manvolnum> </citerefentry>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2676 +#: sssd.conf.5.xml:2722 msgid "Default: 5400" msgstr "Типове значення: 5400" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2682 +#: sssd.conf.5.xml:2728 msgid "entry_cache_user_timeout (integer)" msgstr "entry_cache_user_timeout (ціле число)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2685 +#: sssd.conf.5.xml:2731 msgid "" "How many seconds should nss_sss consider user entries valid before asking " "the backend again" @@ -4029,19 +4148,19 @@ msgstr "" "чинними, перш ніж надсилати повторний запит до сервера" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2689 sssd.conf.5.xml:2702 sssd.conf.5.xml:2715 -#: sssd.conf.5.xml:2728 sssd.conf.5.xml:2742 sssd.conf.5.xml:2755 -#: sssd.conf.5.xml:2769 sssd.conf.5.xml:2783 sssd.conf.5.xml:2796 +#: sssd.conf.5.xml:2735 sssd.conf.5.xml:2748 sssd.conf.5.xml:2761 +#: sssd.conf.5.xml:2774 sssd.conf.5.xml:2788 sssd.conf.5.xml:2801 +#: sssd.conf.5.xml:2815 sssd.conf.5.xml:2829 msgid "Default: entry_cache_timeout" msgstr "Типове значення: entry_cache_timeout" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2695 +#: sssd.conf.5.xml:2741 msgid "entry_cache_group_timeout (integer)" msgstr "entry_cache_group_timeout (ціле число)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2698 +#: sssd.conf.5.xml:2744 msgid "" "How many seconds should nss_sss consider group entries valid before asking " "the backend again" @@ -4050,12 +4169,12 @@ msgstr "" "ніж надсилати повторний запит до сервера" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2708 +#: sssd.conf.5.xml:2754 msgid "entry_cache_netgroup_timeout (integer)" msgstr "entry_cache_netgroup_timeout (ціле число)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2711 +#: sssd.conf.5.xml:2757 msgid "" "How many seconds should nss_sss consider netgroup entries valid before " "asking the backend again" @@ -4064,12 +4183,12 @@ msgstr "" "чинними, перш ніж надсилати повторний запит до сервера" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2721 +#: sssd.conf.5.xml:2767 msgid "entry_cache_service_timeout (integer)" msgstr "entry_cache_service_timeout (ціле число)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2724 +#: sssd.conf.5.xml:2770 msgid "" "How many seconds should nss_sss consider service entries valid before asking " "the backend again" @@ -4078,12 +4197,12 @@ msgstr "" "ніж надсилати повторний запит до сервера" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2734 +#: sssd.conf.5.xml:2780 msgid "entry_cache_resolver_timeout (integer)" msgstr "entry_cache_resolver_timeout (ціле число)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2737 +#: sssd.conf.5.xml:2783 msgid "" "How many seconds should nss_sss consider hosts and networks entries valid " "before asking the backend again" @@ -4092,12 +4211,12 @@ msgstr "" "чинними, перш ніж надсилати повторний запит до сервера" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2748 +#: sssd.conf.5.xml:2794 msgid "entry_cache_sudo_timeout (integer)" msgstr "entry_cache_sudo_timeout (ціле число)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2751 +#: sssd.conf.5.xml:2797 msgid "" "How many seconds should sudo consider rules valid before asking the backend " "again" @@ -4106,12 +4225,12 @@ msgstr "" "надсилати повторний запит до сервера" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2761 +#: sssd.conf.5.xml:2807 msgid "entry_cache_autofs_timeout (integer)" msgstr "entry_cache_autofs_timeout (ціле число)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2764 +#: sssd.conf.5.xml:2810 msgid "" "How many seconds should the autofs service consider automounter maps valid " "before asking the backend again" @@ -4120,12 +4239,12 @@ msgstr "" "чинними, перш ніж надсилати повторний запит до сервера" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2775 +#: sssd.conf.5.xml:2821 msgid "entry_cache_ssh_host_timeout (integer)" msgstr "entry_cache_ssh_host_timeout (ціле число)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2778 +#: sssd.conf.5.xml:2824 msgid "" "How many seconds to keep a host ssh key after refresh. IE how long to cache " "the host key for." @@ -4134,27 +4253,175 @@ msgstr "" "оновлення. Іншими словами, параметр визначає тривалість зберігання ключа " "вузла у кеші." -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2789 -msgid "entry_cache_computer_timeout (integer)" -msgstr "entry_cache_computer_timeout (ціле число)" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2835 +msgid "offline_timeout (integer)" +msgstr "offline_timeout (ціле число)" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2838 +msgid "" +"When SSSD switches to offline mode the amount of time before it tries to go " +"back online will increase based upon the time spent disconnected. By " +"default SSSD uses incremental behaviour to calculate delay in between " +"retries. So, the wait time for a given retry will be longer than the wait " +"time for the previous ones. After each unsuccessful attempt to go online, " +"the new interval is recalculated by the following:" +msgstr "" +"Коли SSSD перемикається на автономний режим роботи, час, який має минути, " +"перш ніж буде здійснено спробу повернутися до режиму у мережі, " +"збільшуватиметься, відповідно до часу, проведеного у режимі від’єднання. " +"Типово, SSSD використовує нарощувальну поведінку для обчислення затримки між " +"повторними спробами. Тому час очікування для повторної спроби буде довшим за " +"час очікування попередньої спроби. Після кожної невдалої спроби з'єднатися " +"із мережею нове значення обчислюється за такою формулою:" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2849 sssd.conf.5.xml:2907 +msgid "" +"new_delay = Minimum(old_delay * 2, offline_timeout_max) + " +"random[0...offline_timeout_random_offset]" +msgstr "" +"new_delay = Minimum(old_delay * 2, offline_timeout_max) + " +"random[0...offline_timeout_random_offset]" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2852 +#, fuzzy +#| msgid "" +#| "The offline_timeout default value is 60. The offline_timeout_max default " +#| "value is 3600. The offline_timeout_random_offset default value is 30. " +#| "The end result is amount of seconds before next retry." +msgid "" +"The offline_timeout default value is 60. The offline_timeout_max default " +"value is 3600. The offline_timeout_random_offset default value is 30. The " +"end result is the number of seconds before next retry." +msgstr "" +"Типовим значенням offline_timeout є 60. Типовим значенням " +"offline_timeout_max є 3600. Типовим значенням offline_timeout_random_offset " +"є 30. Кінцевий результат є кількістю секунд до наступної повторної спроби." + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2858 +#, fuzzy +#| msgid "" +#| "Note that the maximum length of each interval is defined by " +#| "offline_timeout_max (apart of random part)." +msgid "" +"Note that the maximum length of each interval is defined by " +"offline_timeout_max (apart from the random part)." +msgstr "" +"Зауважте, що максимальна тривалість кожного з інтервалів визначається " +"offline_timeout_max (окрім випадкової частини)." + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2868 +msgid "offline_timeout_max (integer)" +msgstr "offline_timeout_max (ціле число)" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2871 +msgid "" +"Controls by how much the time between attempts to go online can be " +"incremented following unsuccessful attempts to go online." +msgstr "" +"Керує тим, на скільки можна збільшувати проміжок часу між спробами відновити " +"з'єднання із мережею після неуспішних спроби відновити з'єднання." + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2876 +msgid "A value of 0 disables the incrementing behaviour." +msgstr "Значення 0 вимикає збільшення проміжку часу." + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2879 +msgid "" +"The value of this parameter should be set in correlation to offline_timeout " +"parameter value." +msgstr "" +"Значення цього параметра слід встановлювати у поєднанні зі значенням " +"параметра offline_timeout." + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2883 +#, fuzzy +#| msgid "" +#| "With offline_timeout set to 60 (default value) there is no point in " +#| "setting offlinet_timeout_max to less than 120 as it will saturate " +#| "instantly. General rule here should be to set offline_timeout_max to at " +#| "least 4 times offline_timeout." +msgid "" +"With offline_timeout set to 60 (default value) there is no point in setting " +"offline_timeout_max to less than 120 as it will saturate instantly. General " +"rule here should be to set offline_timeout_max to at least 4 times " +"offline_timeout." +msgstr "" +"Якщо для offline_timeout встановлено значення 60 (типове значення), немає " +"сенсу встановлювати для offlinet_timeout_max значення, яке є меншим за 120, " +"оскільки перший же крок збільшення призведе до перевищення максимального " +"значення. Загальним правилом у цьому випадку має бути встановлення значення " +"offline_timeout_max, яке є принаймні учетверо більшим за offline_timeout." + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2889 +msgid "" +"Although a value between 0 and offline_timeout may be specified, it has the " +"effect of overriding the offline_timeout value so is of little use." +msgstr "" +"Хоча можна вказати будь-яке значення від 0 до offline_timeout, результатом " +"стане перевизначення значення offline_timeout, тому не варто цього робити." + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2894 +msgid "Default: 3600" +msgstr "Типове значення: 3600" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2900 +msgid "offline_timeout_random_offset (integer)" +msgstr "offline_timeout_random_offset (ціле число)" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2903 +msgid "" +"When SSSD is in offline mode it keeps probing backend servers in specified " +"time intervals:" +msgstr "" +"Якщо SSSD працює в автономному режимі, програма виконує зондування серверів-" +"обробників із вказаними інтервалами часу:" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2910 +msgid "" +"This parameter controls the value of the random offset used for the above " +"equation. Final random_offset value will be random number in range:" +msgstr "" +"Цей параметр керує значенням випадкового зсуву, яке буде використано у " +"наведеному вище рівнянні. Остаточне значення random_offset буде випадковим " +"числом у такому діапазоні:" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2915 +msgid "[0 - offline_timeout_random_offset]" +msgstr "[0 - offline_timeout_random_offset]" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2792 -msgid "" -"How many seconds to keep the local computer entry before asking the backend " -"again" -msgstr "" -"Кількість секунд, протягом яких слід зберігати запис локального комп'ютера, " -"перш ніж надсилати запит до модуля обробки даних знову" +#: sssd.conf.5.xml:2918 +msgid "A value of 0 disables the random offset addition." +msgstr "Значення 0 призводить до вимикання додавання випадкового зсуву." + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2921 +msgid "Default: 30" +msgstr "Типове значення: 30" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2802 +#: sssd.conf.5.xml:2927 msgid "refresh_expired_interval (integer)" msgstr "refresh_expired_interval (ціле число)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2805 +#: sssd.conf.5.xml:2930 msgid "" "Specifies how many seconds SSSD has to wait before triggering a background " "refresh task which will refresh all expired or nearly expired records." @@ -4164,7 +4431,7 @@ msgstr "" "вичерпано або майже вичерпано." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2810 +#: sssd.conf.5.xml:2935 msgid "" "The background refresh will process users, groups and netgroups in the " "cache. For users who have performed the initgroups (get group membership for " @@ -4178,17 +4445,17 @@ msgstr "" "запис користувача, і дані щодо участі у групах." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2818 +#: sssd.conf.5.xml:2943 msgid "This option is automatically inherited for all trusted domains." msgstr "Цей параметр автоматично успадковується для усіх довірених доменів." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2822 +#: sssd.conf.5.xml:2947 msgid "You can consider setting this value to 3/4 * entry_cache_timeout." msgstr "Варто визначити для цього параметра значення 3/4 * entry_cache_timeout." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2826 +#: sssd.conf.5.xml:2951 msgid "" "Cache entry will be refreshed by background task when 2/3 of cache timeout " "has already passed. If there are existing cached entries, the background " @@ -4209,18 +4476,20 @@ msgstr "" "чинність наявного кешу." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2839 sssd-ldap.5.xml:406 sssd-ldap.5.xml:1834 -#: sssd-ipa.5.xml:255 +#: sssd.conf.5.xml:2964 sssd-ldap.5.xml:406 sssd-ldap.5.xml:1834 +#: sssd-ipa.5.xml:250 msgid "Default: 0 (disabled)" msgstr "Типове значення: 0 (вимкнено)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2845 -msgid "cache_credentials (bool)" +#: sssd.conf.5.xml:2970 +#, fuzzy +#| msgid "cache_credentials (bool)" +msgid "cache_credentials (boolean)" msgstr "cache_credentials (булеве значення)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2848 +#: sssd.conf.5.xml:2973 msgid "" "Determines if user credentials are also cached in the local LDB cache. The " "cached credentials refer to passwords, which includes the first (long term) " @@ -4237,7 +4506,7 @@ msgstr "" "мережеве розпізнавання було записано до кешу." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2859 +#: sssd.conf.5.xml:2984 msgid "" "Take a note that while credentials are stored as a salted SHA512 hash, this " "still potentially poses some security risk in case an attacker manages to " @@ -4250,12 +4519,12 @@ msgstr "" "додаткових прав доступу) і визначить пароль за допомогою простого перебору." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2873 +#: sssd.conf.5.xml:2998 msgid "cache_credentials_minimal_first_factor_length (int)" msgstr "cache_credentials_minimal_first_factor_length (ціле число)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2876 +#: sssd.conf.5.xml:3001 msgid "" "If 2-Factor-Authentication (2FA) is used and credentials should be saved " "this value determines the minimal length the first authentication factor " @@ -4267,7 +4536,7 @@ msgstr "" "контрольної суми SHA512 у кеші." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2883 +#: sssd.conf.5.xml:3008 msgid "" "This should avoid that the short PINs of a PIN based 2FA scheme are saved in " "the cache which would make them easy targets for brute-force attacks." @@ -4277,12 +4546,12 @@ msgstr "" "мішенню атак із перебиранням паролів." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2894 +#: sssd.conf.5.xml:3019 msgid "account_cache_expiration (integer)" msgstr "account_cache_expiration (ціле число)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2897 +#: sssd.conf.5.xml:3022 msgid "" "Number of days entries are left in cache after last successful login before " "being removed during a cleanup of the cache. 0 means keep forever. The " @@ -4295,17 +4564,17 @@ msgstr "" "offline_credentials_expiration." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2904 +#: sssd.conf.5.xml:3029 msgid "Default: 0 (unlimited)" msgstr "Типове значення: 0 (без обмежень)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2909 +#: sssd.conf.5.xml:3034 msgid "pwd_expiration_warning (integer)" msgstr "pwd_expiration_warning (ціле число)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2920 +#: sssd.conf.5.xml:3045 msgid "" "Please note that the backend server has to provide information about the " "expiration time of the password. If this information is missing, sssd " @@ -4318,17 +4587,17 @@ msgstr "" "даних розпізнавання." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2927 +#: sssd.conf.5.xml:3052 msgid "Default: 7 (Kerberos), 0 (LDAP)" msgstr "Типове значення: 7 (Kerberos), 0 (LDAP)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2933 +#: sssd.conf.5.xml:3058 msgid "id_provider (string)" msgstr "id_provider (рядок)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2936 +#: sssd.conf.5.xml:3061 msgid "" "The identification provider used for the domain. Supported ID providers are:" msgstr "" @@ -4336,12 +4605,12 @@ msgstr "" "Серед підтримуваних засобів такі:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2940 +#: sssd.conf.5.xml:3065 msgid "<quote>proxy</quote>: Support a legacy NSS provider." msgstr "«proxy»: підтримка застарілого модуля надання даних NSS." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2943 +#: sssd.conf.5.xml:3068 msgid "" "<quote>ldap</quote>: LDAP provider. See <citerefentry> <refentrytitle>sssd-" "ldap</refentrytitle> <manvolnum>5</manvolnum> </citerefentry> for more " @@ -4352,8 +4621,8 @@ msgstr "" "refentrytitle> <manvolnum>5</manvolnum> </citerefentry>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2951 sssd.conf.5.xml:3070 sssd.conf.5.xml:3129 -#: sssd.conf.5.xml:3192 +#: sssd.conf.5.xml:3076 sssd.conf.5.xml:3200 sssd.conf.5.xml:3259 +#: sssd.conf.5.xml:3322 msgid "" "<quote>ipa</quote>: FreeIPA and Red Hat Identity Management provider. See " "<citerefentry> <refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</" @@ -4365,8 +4634,8 @@ msgstr "" "citerefentry>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2960 sssd.conf.5.xml:3079 sssd.conf.5.xml:3138 -#: sssd.conf.5.xml:3201 +#: sssd.conf.5.xml:3085 sssd.conf.5.xml:3209 sssd.conf.5.xml:3268 +#: sssd.conf.5.xml:3331 msgid "" "<quote>ad</quote>: Active Directory provider. See <citerefentry> " "<refentrytitle>sssd-ad</refentrytitle> <manvolnum>5</manvolnum> </" @@ -4378,7 +4647,7 @@ msgstr "" "citerefentry>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2968 +#: sssd.conf.5.xml:3093 msgid "" "<quote>idp</quote>: Provider for OAuth 2.0/OIDC based Identity Providers " "(IdP). See <citerefentry> <refentrytitle>sssd-idp</refentrytitle> " @@ -4389,13 +4658,22 @@ msgstr "" "refentrytitle> <manvolnum>5</manvolnum> </citerefentry>, щоб дізнатися " "більше." +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3101 +msgid "" +"Default: Not set (This is a mandatory setting that must be explicitly " +"defined for each configured domain)." +msgstr "" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2979 -msgid "use_fully_qualified_names (bool)" +#: sssd.conf.5.xml:3109 +#, fuzzy +#| msgid "use_fully_qualified_names (bool)" +msgid "use_fully_qualified_names (boolean)" msgstr "use_fully_qualified_names (булеве значення)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2982 +#: sssd.conf.5.xml:3112 msgid "" "Use the full name and domain (as formatted by the domain's full_name_format) " "as the user's login name reported to NSS." @@ -4405,7 +4683,7 @@ msgstr "" "NSS." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2987 +#: sssd.conf.5.xml:3117 msgid "" "If set to TRUE, all requests to this domain must use fully qualified names. " "For example, if used in EXAMPLE domain that contains a \"test\" user, " @@ -4419,7 +4697,7 @@ msgstr "" "покаже." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2995 +#: sssd.conf.5.xml:3125 msgid "" "NOTE: This option has no effect on netgroup lookups due to their tendency to " "include nested netgroups without qualified names. For netgroups, all domains " @@ -4430,7 +4708,7 @@ msgstr "" "груп, якщо задано неповну назву, буде виконано пошук у всіх доменах." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3002 +#: sssd.conf.5.xml:3132 msgid "" "Default: FALSE (TRUE for trusted domain/sub-domains or if " "default_domain_suffix is used)" @@ -4439,17 +4717,19 @@ msgstr "" "використано default_domain_suffix)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3009 -msgid "ignore_group_members (bool)" +#: sssd.conf.5.xml:3139 +#, fuzzy +#| msgid "ignore_group_members (bool)" +msgid "ignore_group_members (boolean)" msgstr "ignore_group_members (булеве значення)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3012 +#: sssd.conf.5.xml:3142 msgid "Do not return group members for group lookups." msgstr "Не повертати записи учасників груп для пошуків груп." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3015 +#: sssd.conf.5.xml:3145 msgid "" "If set to TRUE, the group membership attribute is not requested from the " "ldap server, and group members are not returned when processing group lookup " @@ -4468,7 +4748,7 @@ msgstr "" "поверне запитану групу так, наче вона була порожня." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3033 +#: sssd.conf.5.xml:3163 msgid "" "Enabling this option can also make access provider checks for group " "membership significantly faster, especially for groups containing many " @@ -4479,7 +4759,7 @@ msgstr "" "учасників." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3039 sssd.conf.5.xml:3767 sssd-ldap.5.xml:401 +#: sssd.conf.5.xml:3169 sssd.conf.5.xml:3951 sssd-ldap.5.xml:401 #: sssd-ldap.5.xml:454 sssd-ldap.5.xml:529 sssd-ldap.5.xml:576 #: sssd-ldap.5.xml:599 sssd-ldap.5.xml:638 sssd-ldap.5.xml:657 #: sssd-ldap.5.xml:681 sssd-ldap.5.xml:1114 sssd-ldap.5.xml:1147 @@ -4491,12 +4771,12 @@ msgstr "" "успадковано за допомогою <emphasis>subdomain_inherit</emphasis>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3049 +#: sssd.conf.5.xml:3179 msgid "auth_provider (string)" msgstr "auth_provider (рядок)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3052 +#: sssd.conf.5.xml:3182 msgid "" "The authentication provider used for the domain. Supported auth providers " "are:" @@ -4505,7 +4785,7 @@ msgstr "" "служб розпізнавання:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3056 sssd.conf.5.xml:3122 +#: sssd.conf.5.xml:3186 sssd.conf.5.xml:3252 msgid "" "<quote>ldap</quote> for native LDAP authentication. See <citerefentry> " "<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> </" @@ -4517,7 +4797,7 @@ msgstr "" "citerefentry>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3063 +#: sssd.conf.5.xml:3193 msgid "" "<quote>krb5</quote> for Kerberos authentication. See <citerefentry> " "<refentrytitle>sssd-krb5</refentrytitle> <manvolnum>5</manvolnum> </" @@ -4529,7 +4809,7 @@ msgstr "" "citerefentry>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3087 +#: sssd.conf.5.xml:3217 msgid "" "<quote>idp</quote>: Provider for OAuth 2.0/OIDC based authentication. See " "<citerefentry> <refentrytitle>sssd-idp</refentrytitle> <manvolnum>5</" @@ -4540,18 +4820,18 @@ msgstr "" "<manvolnum>5</manvolnum> </citerefentry>, щоб дізнатися більше." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3095 +#: sssd.conf.5.xml:3225 msgid "" "<quote>proxy</quote> for relaying authentication to some other PAM target." msgstr "<quote>proxy</quote> — трансльоване розпізнавання у іншій системі PAM." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3098 +#: sssd.conf.5.xml:3228 msgid "<quote>none</quote> disables authentication explicitly." msgstr "<quote>none</quote> — вимкнути розпізнавання повністю." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3101 +#: sssd.conf.5.xml:3231 msgid "" "Default: <quote>id_provider</quote> is used if it is set and can handle " "authentication requests." @@ -4560,12 +4840,12 @@ msgstr "" "спосіб встановлено і можлива обробка запитів щодо розпізнавання." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3107 +#: sssd.conf.5.xml:3237 msgid "access_provider (string)" msgstr "access_provider (рядок)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3110 +#: sssd.conf.5.xml:3240 msgid "" "The access control provider used for the domain. There are two built-in " "access providers (in addition to any included in installed backends) " @@ -4576,17 +4856,17 @@ msgstr "" "Вбудованими програмами є:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3116 +#: sssd.conf.5.xml:3246 msgid "<quote>permit</quote> always allow access." msgstr "<quote>permit</quote> завжди дозволяти доступ." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3119 +#: sssd.conf.5.xml:3249 msgid "<quote>deny</quote> always deny access." msgstr "<quote>deny</quote> — завжди забороняти доступ." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3146 +#: sssd.conf.5.xml:3276 msgid "" "<quote>simple</quote> access control based on access or deny lists. See " "<citerefentry> <refentrytitle>sssd-simple</refentrytitle> <manvolnum>5</" @@ -4599,7 +4879,7 @@ msgstr "" "refentrytitle> <manvolnum>5</manvolnum></citerefentry>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3153 +#: sssd.conf.5.xml:3283 msgid "" "<quote>krb5</quote>: .k5login based access control. See <citerefentry> " "<refentrytitle>sssd-krb5</refentrytitle> <manvolnum>5</manvolnum></" @@ -4611,24 +4891,24 @@ msgstr "" "manvolnum> </citerefentry>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3160 +#: sssd.conf.5.xml:3290 msgid "<quote>proxy</quote> for relaying access control to another PAM module." msgstr "" "<quote>proxy</quote> — для трансляції керування доступом до іншого модуля " "PAM." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3163 +#: sssd.conf.5.xml:3293 msgid "Default: <quote>permit</quote>" msgstr "Типове значення: <quote>permit</quote>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3168 +#: sssd.conf.5.xml:3298 msgid "chpass_provider (string)" msgstr "chpass_provider (рядок)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3171 +#: sssd.conf.5.xml:3301 msgid "" "The provider which should handle change password operations for the domain. " "Supported change password providers are:" @@ -4637,7 +4917,7 @@ msgstr "" "підтримку таких систем зміни паролів:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3176 +#: sssd.conf.5.xml:3306 msgid "" "<quote>ldap</quote> to change a password stored in a LDAP server. See " "<citerefentry> <refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</" @@ -4649,7 +4929,7 @@ msgstr "" "manvolnum> </citerefentry>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3184 +#: sssd.conf.5.xml:3314 msgid "" "<quote>krb5</quote> to change the Kerberos password. See <citerefentry> " "<refentrytitle>sssd-krb5</refentrytitle> <manvolnum>5</manvolnum> </" @@ -4661,18 +4941,18 @@ msgstr "" "citerefentry>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3209 +#: sssd.conf.5.xml:3339 msgid "" "<quote>proxy</quote> for relaying password changes to some other PAM target." msgstr "<quote>proxy</quote> — трансльована зміна пароля у іншій системі PAM." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3213 +#: sssd.conf.5.xml:3343 msgid "<quote>none</quote> disallows password changes explicitly." msgstr "<quote>none</quote> — явно вимкнути можливість зміни пароля." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3216 +#: sssd.conf.5.xml:3346 msgid "" "Default: <quote>auth_provider</quote> is used if it is set and can handle " "change password requests." @@ -4681,19 +4961,19 @@ msgstr "" "цього параметра і якщо система здатна обробляти запити щодо паролів." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3223 +#: sssd.conf.5.xml:3353 msgid "sudo_provider (string)" msgstr "sudo_provider (рядок)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3226 +#: sssd.conf.5.xml:3356 msgid "The SUDO provider used for the domain. Supported SUDO providers are:" msgstr "" "Служба SUDO, яку використано для цього домену. Серед підтримуваних служб " "SUDO:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3230 +#: sssd.conf.5.xml:3360 msgid "" "<quote>ldap</quote> for rules stored in LDAP. See <citerefentry> " "<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> </" @@ -4705,7 +4985,7 @@ msgstr "" "citerefentry>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3238 +#: sssd.conf.5.xml:3368 msgid "" "<quote>ipa</quote> the same as <quote>ldap</quote> but with IPA default " "settings." @@ -4714,7 +4994,7 @@ msgstr "" "параметрами IPA." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3242 +#: sssd.conf.5.xml:3372 msgid "" "<quote>ad</quote> the same as <quote>ldap</quote> but with AD default " "settings." @@ -4723,12 +5003,12 @@ msgstr "" "параметрами AD." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3246 +#: sssd.conf.5.xml:3376 msgid "<quote>none</quote> disables SUDO explicitly." msgstr "<quote>none</quote> явним чином вимикає SUDO." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3249 +#: sssd.conf.5.xml:3379 msgid "" "Default: The value of <quote>id_provider</quote> is used if it is set and " "can handle sudo requests." @@ -4737,7 +5017,7 @@ msgstr "" "його встановлено, і можлива обробка запитів щодо sudo." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3253 +#: sssd.conf.5.xml:3383 msgid "" "The detailed instructions for configuration of sudo_provider are in the " "manual page <citerefentry> <refentrytitle>sssd-sudo</refentrytitle> " @@ -4756,7 +5036,7 @@ msgstr "" "citerefentry>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3268 +#: sssd.conf.5.xml:3398 msgid "" "<emphasis>NOTE:</emphasis> Sudo rules are periodically downloaded in the " "background unless the sudo provider is explicitly disabled. Set " @@ -4770,12 +5050,12 @@ msgstr "" "sudo у SSSD." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3278 +#: sssd.conf.5.xml:3408 msgid "selinux_provider (string)" msgstr "selinux_provider (рядок)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3281 +#: sssd.conf.5.xml:3411 msgid "" "The provider which should handle loading of selinux settings. Note that this " "provider will be called right after access provider ends. Supported selinux " @@ -4786,7 +5066,7 @@ msgstr "" "доступу. Передбачено підтримку таких засобів надання даних SELinux:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3287 +#: sssd.conf.5.xml:3417 msgid "" "<quote>ipa</quote> to load selinux settings from an IPA server. See " "<citerefentry> <refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</" @@ -4798,28 +5078,33 @@ msgstr "" "manvolnum> </citerefentry>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3295 +#: sssd.conf.5.xml:3425 msgid "<quote>none</quote> disallows fetching selinux settings explicitly." msgstr "" "<quote>none</quote> явним чином забороняє отримання даних щодо параметрів " "SELinux." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3298 +#: sssd.conf.5.xml:3428 +#, fuzzy +#| msgid "" +#| "Default: The value of <quote>id_provider</quote> is used if it is set and " +#| "can handle subdomain requests." msgid "" -"Default: <quote>id_provider</quote> is used if it is set and can handle " -"selinux loading requests." +"Default: the value of <quote>id_provider</quote> is used if it is set and " +"can handle selinux loading requests. Otherwise the result is the same as if " +"the selinux_provider is set to none." msgstr "" -"Типове значення: буде використано <quote>id_provider</quote>, якщо цей " -"спосіб встановлено і можлива обробка запитів щодо завантаження SELinux." +"Типове значення: буде використано значення <quote>id_provider</quote>, якщо " +"його встановлено, і можлива обробка запитів щодо піддоменів." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3304 +#: sssd.conf.5.xml:3435 msgid "subdomains_provider (string)" msgstr "subdomains_provider (рядок)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3307 +#: sssd.conf.5.xml:3438 msgid "" "The provider which should handle fetching of subdomains. This value should " "be always the same as id_provider. Supported subdomain providers are:" @@ -4829,7 +5114,7 @@ msgstr "" "підтримку таких засобів надання даних піддоменів:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3313 +#: sssd.conf.5.xml:3444 msgid "" "<quote>ipa</quote> to load a list of subdomains from an IPA server. See " "<citerefentry> <refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</" @@ -4841,7 +5126,7 @@ msgstr "" "manvolnum> </citerefentry>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3322 +#: sssd.conf.5.xml:3453 msgid "" "<quote>ad</quote> to load a list of subdomains from an Active Directory " "server. See <citerefentry> <refentrytitle>sssd-ad</refentrytitle> " @@ -4854,12 +5139,12 @@ msgstr "" "налаштовування засобу надання даних AD." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3331 +#: sssd.conf.5.xml:3462 msgid "<quote>none</quote> disallows fetching subdomains explicitly." msgstr "<quote>none</quote> забороняє ячним чином отримання даних піддоменів." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3335 +#: sssd.conf.5.xml:3466 msgid "" "Default: The value of <quote>id_provider</quote> is used if it is set and " "can handle subdomain requests." @@ -4868,12 +5153,12 @@ msgstr "" "його встановлено, і можлива обробка запитів щодо піддоменів." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3341 +#: sssd.conf.5.xml:3472 msgid "session_provider (string)" msgstr "session_provider (рядок)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3344 +#: sssd.conf.5.xml:3475 msgid "" "The provider which configures and manages user session related tasks. The " "only user session task currently provided is the integration with Fleet " @@ -4885,14 +5170,14 @@ msgstr "" "постачальники даних сеансів:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3351 +#: sssd.conf.5.xml:3482 msgid "<quote>ipa</quote> to allow performing user session related tasks." msgstr "" "<quote>ipa</quote>, щоб дозволити пов'язані із сеансами користувачів " "завдання." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3355 +#: sssd.conf.5.xml:3486 msgid "" "<quote>none</quote> does not perform any kind of user session related tasks." msgstr "" @@ -4900,19 +5185,19 @@ msgstr "" "користувачів завдань." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3359 +#: sssd.conf.5.xml:3490 #, fuzzy #| msgid "Default: <quote>*</quote>" msgid "Default: <quote>none</quote>." msgstr "Типове значення: <quote>*</quote>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3365 +#: sssd.conf.5.xml:3496 msgid "autofs_provider (string)" msgstr "autofs_provider (рядок)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3368 +#: sssd.conf.5.xml:3499 msgid "" "The autofs provider used for the domain. Supported autofs providers are:" msgstr "" @@ -4920,7 +5205,7 @@ msgstr "" "autofs:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3372 +#: sssd.conf.5.xml:3503 msgid "" "<quote>ldap</quote> to load maps stored in LDAP. See <citerefentry> " "<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> </" @@ -4932,7 +5217,7 @@ msgstr "" "citerefentry>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3379 +#: sssd.conf.5.xml:3510 msgid "" "<quote>ipa</quote> to load maps stored in an IPA server. See <citerefentry> " "<refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</manvolnum> </" @@ -4944,7 +5229,7 @@ msgstr "" "manvolnum> </citerefentry>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3387 +#: sssd.conf.5.xml:3518 msgid "" "<quote>ad</quote> to load maps stored in an AD server. See <citerefentry> " "<refentrytitle>sssd-ad</refentrytitle> <manvolnum>5</manvolnum> </" @@ -4956,12 +5241,12 @@ msgstr "" "надання даних AD." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3396 +#: sssd.conf.5.xml:3527 msgid "<quote>none</quote> disables autofs explicitly." msgstr "<quote>none</quote> вимикає autofs повністю." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3399 +#: sssd.conf.5.xml:3530 msgid "" "Default: The value of <quote>id_provider</quote> is used if it is set and " "can handle autofs requests." @@ -4970,12 +5255,12 @@ msgstr "" "його встановлено, і можлива обробка запитів щодо autofs." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3406 +#: sssd.conf.5.xml:3537 msgid "hostid_provider (string)" msgstr "hostid_provider (рядок)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3409 +#: sssd.conf.5.xml:3540 msgid "" "The provider used for retrieving host identity information. Supported " "hostid providers are:" @@ -4984,7 +5269,7 @@ msgstr "" "вузла. Серед підтримуваних засобів надання hostid:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3413 +#: sssd.conf.5.xml:3544 msgid "" "<quote>ipa</quote> to load host identity stored in an IPA server. See " "<citerefentry> <refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</" @@ -4996,12 +5281,12 @@ msgstr "" "manvolnum> </citerefentry>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3421 +#: sssd.conf.5.xml:3552 msgid "<quote>none</quote> disables hostid explicitly." msgstr "<quote>none</quote> вимикає hostid повністю." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3424 +#: sssd.conf.5.xml:3555 msgid "" "Default: The value of <quote>id_provider</quote> is used if it is set and " "can handle hostid requests." @@ -5010,12 +5295,12 @@ msgstr "" "його встановлено, і можлива обробка запитів щодо hostid." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3431 +#: sssd.conf.5.xml:3562 msgid "resolver_provider (string)" msgstr "resolver_provider (рядок)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3434 +#: sssd.conf.5.xml:3565 msgid "" "The provider which should handle hosts and networks lookups. Supported " "resolver providers are:" @@ -5024,7 +5309,7 @@ msgstr "" "підтримку таких надавачів даних для визначення:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3438 +#: sssd.conf.5.xml:3569 msgid "" "<quote>proxy</quote> to forward lookups to another NSS library. See " "<quote>proxy_resolver_lib_name</quote>" @@ -5033,7 +5318,7 @@ msgstr "" "Див. <quote>proxy_resolver_lib_name</quote>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3442 +#: sssd.conf.5.xml:3573 msgid "" "<quote>ldap</quote> to fetch hosts and networks stored in LDAP. See " "<citerefentry> <refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</" @@ -5045,7 +5330,7 @@ msgstr "" "manvolnum> </citerefentry>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3449 +#: sssd.conf.5.xml:3580 msgid "" "<quote>ad</quote> to fetch hosts and networks stored in AD. See " "<citerefentry> <refentrytitle>sssd-ad</refentrytitle> <manvolnum>5</" @@ -5058,13 +5343,13 @@ msgstr "" "налаштовування засобу надання даних AD." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3457 +#: sssd.conf.5.xml:3588 msgid "<quote>none</quote> disallows fetching hosts and networks explicitly." msgstr "" "<quote>none</quote> забороняє ячним чином отримання даних вузлів і мереж." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3460 +#: sssd.conf.5.xml:3591 msgid "" "Default: The value of <quote>id_provider</quote> is used if it is set and " "can handle resolver requests." @@ -5073,7 +5358,7 @@ msgstr "" "його встановлено, і можлива обробка запитів щодо розв'язувача." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3470 +#: sssd.conf.5.xml:3601 msgid "" "Regular expression for this domain that describes how to parse the string " "containing user name and domain into these components. The \"domain\" can " @@ -5087,7 +5372,7 @@ msgstr "" "IPA та доменів Active Directory, простій назві (NetBIOS) домену." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3479 +#: sssd.conf.5.xml:3610 msgid "" "Default: <quote>^((?P<name>.+)@(?P<domain>[^@]*)|(?P<name>" "[^@]+))$</quote> which allows two different styles for user names:" @@ -5097,17 +5382,17 @@ msgstr "" "користувачів:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:3484 sssd.conf.5.xml:3498 +#: sssd.conf.5.xml:3615 sssd.conf.5.xml:3629 msgid "username" msgstr "користувач" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:3487 sssd.conf.5.xml:3501 +#: sssd.conf.5.xml:3618 sssd.conf.5.xml:3632 msgid "username@domain.name" msgstr "користувач@назва.домену" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3492 +#: sssd.conf.5.xml:3623 msgid "" "Default for the AD and IPA provider: <quote>^(((?P<domain>[^\\\\]+)\\\\" "(?P<name>.+))|((?P<name>.+)@(?P<domain>[^@]+))|((?" @@ -5120,12 +5405,12 @@ msgstr "" "різні стилі запису імен користувачів:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:3504 +#: sssd.conf.5.xml:3635 msgid "domain\\username" msgstr "домен\\користувач" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3507 +#: sssd.conf.5.xml:3638 msgid "" "While the first two correspond to the general default the third one is " "introduced to allow easy integration of users from Windows domains." @@ -5134,7 +5419,7 @@ msgstr "" "того, щоб полегшити інтеграцію користувачів з доменів Windows." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3512 +#: sssd.conf.5.xml:3643 msgid "" "The default re_expression uses the <quote>@</quote> character as a separator " "between the name and the domain. As a result of this setting the default " @@ -5149,17 +5434,17 @@ msgstr "" "ім'я з <quote>@</quote>, йому слід скорити власний re_expression." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3564 +#: sssd.conf.5.xml:3695 msgid "Default: <quote>%1$s@%2$s</quote>." msgstr "Типове значення: <quote>%1$s@%2$s</quote>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3570 +#: sssd.conf.5.xml:3701 msgid "lookup_family_order (string)" msgstr "lookup_family_order (рядок)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3573 +#: sssd.conf.5.xml:3704 msgid "" "Provides the ability to select preferred address family to use when " "performing DNS lookups." @@ -5168,55 +5453,59 @@ msgstr "" "під час виконання пошуків у DNS." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3577 +#: sssd.conf.5.xml:3708 msgid "Supported values:" msgstr "Передбачено підтримку таких значень:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3580 +#: sssd.conf.5.xml:3711 msgid "ipv4_first: Try looking up IPv4 address, if that fails, try IPv6" msgstr "" "ipv4_first: спробувати визначити адресу у форматі IPv4, у разі невдачі " "спробувати формат IPv6" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3583 +#: sssd.conf.5.xml:3714 msgid "ipv4_only: Only attempt to resolve hostnames to IPv4 addresses." msgstr "ipv4_only: намагатися визначити назви вузлів лише у форматі адрес IPv4." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3586 +#: sssd.conf.5.xml:3717 msgid "ipv6_first: Try looking up IPv6 address, if that fails, try IPv4" msgstr "" "ipv6_first: спробувати визначити адресу у форматі IPv6, у разі невдачі " "спробувати формат IPv4" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3589 +#: sssd.conf.5.xml:3720 msgid "ipv6_only: Only attempt to resolve hostnames to IPv6 addresses." msgstr "ipv6_only: намагатися визначити назви вузлів лише у форматі адрес IPv6." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3592 +#: sssd.conf.5.xml:3723 msgid "Default: ipv4_first" msgstr "Типове значення: ipv4_first" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3598 +#: sssd.conf.5.xml:3729 msgid "dns_resolver_server_timeout (integer)" msgstr "dns_resolver_server_timeout (ціле число)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3601 +#: sssd.conf.5.xml:3732 +#, fuzzy +#| msgid "" +#| "Defines the amount of time (in milliseconds) SSSD would try to talk to " +#| "DNS server before trying next DNS server." msgid "" -"Defines the amount of time (in milliseconds) SSSD would try to talk to DNS " -"server before trying next DNS server." +"Defines the timeout duration (in milliseconds) SSSD waits for a DNS server " +"to respond before moving to the next one." msgstr "" "Визначає проміжок часу (у мілісекундах), протягом якого SSSD намагатиметься " "обмінятися даними із сервером DNS, перш ніж пробувати наступний сервер DNS." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3606 +#: sssd.conf.5.xml:3737 msgid "" "The AD provider will use this option for the CLDAP ping timeouts as well." msgstr "" @@ -5224,26 +5513,43 @@ msgstr "" "очікування на відгук на луна-імпульс CLDAP." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3610 sssd.conf.5.xml:3630 sssd.conf.5.xml:3651 -msgid "" -"Please see the section <quote>FAILOVER</quote> for more information about " -"the service resolution." +#: sssd.conf.5.xml:3741 sssd.conf.5.xml:3777 sssd.conf.5.xml:3814 +#, fuzzy +#| msgid "" +#| "Specifies the timeout (in seconds) after which the <citerefentry> " +#| "<refentrytitle>poll</refentrytitle> <manvolnum>2</manvolnum> </" +#| "citerefentry>/<citerefentry> <refentrytitle>select</refentrytitle> " +#| "<manvolnum>2</manvolnum> </citerefentry> following a <citerefentry> " +#| "<refentrytitle>connect</refentrytitle> <manvolnum>2</manvolnum> </" +#| "citerefentry> returns in case of no activity." +msgid "" +"Please see the section <quote>FAILOVER</quote> in <citerefentry> " +"<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> </" +"citerefentry>, <citerefentry> <refentrytitle>sssd-krb5</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry>, <citerefentry> <refentrytitle>sssd-" +"ipa</refentrytitle> <manvolnum>5</manvolnum> </citerefentry> or " +"<citerefentry> <refentrytitle>sssd-ad</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry> for more information about the service resolution." msgstr "" -"Будь ласка, ознайомтеся із розділом <quote>РЕЗЕРВ</quote>, щоб дізнатися " -"більше про розв'язування питань, пов'язаних із службами." +"Визначає час очікування (у секундах), після завершення якого <citerefentry> " +"<refentrytitle>poll</refentrytitle> <manvolnum>2</manvolnum> </citerefentry>/" +"<citerefentry> <refentrytitle>select</refentrytitle> <manvolnum>2</" +"manvolnum> </citerefentry> з наступним <citerefentry> " +"<refentrytitle>connect</refentrytitle> <manvolnum>2</manvolnum> </" +"citerefentry> повертається до стану бездіяльності." #. type: Content of: <refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3615 sssd-ldap.5.xml:700 include/failover.xml:84 +#: sssd.conf.5.xml:3762 sssd-ldap.5.xml:700 include/failover.xml:84 msgid "Default: 1000" msgstr "Типове значення: 1000" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3621 +#: sssd.conf.5.xml:3768 msgid "dns_resolver_op_timeout (integer)" msgstr "dns_resolver_op_timeout (ціле число)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3624 +#: sssd.conf.5.xml:3771 msgid "" "Defines the amount of time (in seconds) to wait to resolve single DNS query " "(e.g. resolution of a hostname or an SRV record) before trying the next " @@ -5255,17 +5561,17 @@ msgstr "" "наступного DNS." #. type: Content of: <refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3635 include/failover.xml:100 +#: sssd.conf.5.xml:3798 include/failover.xml:100 msgid "Default: 3" msgstr "Типове значення: 3" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3641 +#: sssd.conf.5.xml:3804 msgid "dns_resolver_timeout (integer)" msgstr "dns_resolver_timeout (ціле число)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3644 +#: sssd.conf.5.xml:3807 msgid "" "Defines the amount of time (in seconds) to wait for a reply from the " "internal fail over service before assuming that the service is unreachable. " @@ -5278,12 +5584,14 @@ msgstr "" "роботу у автономному режимі." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3662 -msgid "dns_resolver_use_search_list (bool)" +#: sssd.conf.5.xml:3841 +#, fuzzy +#| msgid "dns_resolver_use_search_list (bool)" +msgid "dns_resolver_use_search_list (boolean)" msgstr "dns_resolver_use_search_list (булеве значення)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3665 +#: sssd.conf.5.xml:3844 msgid "" "Normally, the DNS resolver searches the domain list defined in the " "\"search\" directive from the resolv.conf file. This can lead to delays in " @@ -5294,7 +5602,7 @@ msgstr "" "затримок у середовищах, де DNS не налаштовано належним чином." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3671 +#: sssd.conf.5.xml:3850 msgid "" "If fully qualified domain names (or _srv_) are used in the SSSD " "configuration, setting this option to FALSE can prevent unnecessary DNS " @@ -5305,17 +5613,17 @@ msgstr "" "пошукам DNS у таких середовищах." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3677 +#: sssd.conf.5.xml:3856 msgid "Default: TRUE" msgstr "Типове значення: TRUE" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3683 +#: sssd.conf.5.xml:3862 msgid "dns_discovery_domain (string)" msgstr "dns_discovery_domain (рядок)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3686 +#: sssd.conf.5.xml:3865 msgid "" "If service discovery is used in the back end, specifies the domain part of " "the service discovery DNS query." @@ -5324,18 +5632,18 @@ msgstr "" "частину запиту визначення служб DNS." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3690 +#: sssd.conf.5.xml:3869 msgid "Default: Use the domain part of machine's hostname" msgstr "" "Типова поведінка: використовувати назву домену з назви вузла комп’ютера." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3696 +#: sssd.conf.5.xml:3875 msgid "failover_primary_timeout (integer)" msgstr "failover_primary_timeout (ціле число)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3699 +#: sssd.conf.5.xml:3878 msgid "" "When no primary server is available, SSSD fails over to a backup server. " "This option defines the number of seconds SSSD waits before attempting to " @@ -5346,58 +5654,73 @@ msgstr "" "встановити з'єднання із основним сервером." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3706 +#: sssd.conf.5.xml:3885 msgid "Note: The minimum value is 31." msgstr "Зауваження: мінімальним значенням є 31." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3709 +#: sssd.conf.5.xml:3888 msgid "Default: 31" msgstr "Типове значення: 31" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3715 +#: sssd.conf.5.xml:3894 msgid "override_gid (integer)" msgstr "override_gid (ціле число)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3718 -msgid "Override the primary GID value with the one specified." +#: sssd.conf.5.xml:3897 +#, fuzzy +#| msgid "Override the primary GID value with the one specified." +msgid "" +"Override the primary GID value for all users in the domain with specified " +"value." msgstr "Замірити значення основного GID на вказане." +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3901 +#, fuzzy +#| msgid "Default: not set (SSSD will use the value retrieved from LDAP)" +msgid "" +"Default: not set (Use the primary GID value retrieved from the identity " +"provider)" +msgstr "" +"Типове значення: не встановлено (SSSD використовуватиме значення, отримане " +"від LDAP)" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3724 +#: sssd.conf.5.xml:3908 msgid "case_sensitive (string)" msgstr "case_sensitive (рядок)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3731 +#: sssd.conf.5.xml:3915 msgid "True" msgstr "True" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3734 +#: sssd.conf.5.xml:3918 msgid "Case sensitive. This value is invalid for AD provider." msgstr "" "Враховується регістр. Це значення є некоректним для засобу надання даних AD." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3740 +#: sssd.conf.5.xml:3924 msgid "False" msgstr "False" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3742 +#: sssd.conf.5.xml:3926 msgid "Case insensitive." msgstr "Без врахування регістру." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3746 +#: sssd.conf.5.xml:3930 msgid "Preserving" msgstr "Preserving" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3749 +#: sssd.conf.5.xml:3933 msgid "" "Same as False (case insensitive), but does not lowercase names in the result " "of NSS operations. Note that name aliases (and in case of services also " @@ -5409,7 +5732,7 @@ msgstr "" "буде переведено у нижній регістр." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3757 +#: sssd.conf.5.xml:3941 msgid "" "If you want to set this value for trusted domain with IPA provider, you need " "to set it on both the client and SSSD on the server." @@ -5418,7 +5741,7 @@ msgstr "" "даних IPA, вам доведеться встановити його на боці клієнта і SSSD на сервері." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3727 +#: sssd.conf.5.xml:3911 msgid "" "Treat user and group names as case sensitive. Possible option values are: " "<placeholder type=\"variablelist\" id=\"0\"/>" @@ -5427,17 +5750,47 @@ msgstr "" "значення: <placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3772 +#: sssd.conf.5.xml:3956 msgid "Default: True (False for AD provider)" msgstr "Типове значення: True (False для засобу надання даних AD)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3778 +#: sssd.conf.5.xml:3962 +#, fuzzy +#| msgid "verify_host (boolean)" +msgid "avoid_by_id_lookups (boolean)" +msgstr "verify_host (булеве значення)" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3965 +msgid "" +"If this option is set to 'true' SSSD will try to avoid sending lookups by ID " +"to the backend and will switch to a lookup by name if a cached object with a " +"matching ID can be found." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3971 +msgid "" +"This option can e.g. be used in cases where searches by ID are expensive on " +"the server side because of missing indexes or are not even possible, e.g. " +"due to non-reversible POSIX id-mapping." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3978 +#, fuzzy +#| msgid "Default: True (False for AD provider)" +msgid "Default: False (True for IdP provider)" +msgstr "Типове значення: True (False для засобу надання даних AD)" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:3984 msgid "subdomain_inherit (string)" msgstr "subdomain_inherit (рядок)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3781 +#: sssd.conf.5.xml:3987 msgid "" "Specifies a list of configuration parameters that should be inherited by a " "subdomain. Please note that only selected parameters can be inherited. " @@ -5449,37 +5802,37 @@ msgstr "" "параметрів:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3787 +#: sssd.conf.5.xml:3993 msgid "ldap_search_timeout" msgstr "ldap_search_timeout" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3790 +#: sssd.conf.5.xml:3996 msgid "ldap_network_timeout" msgstr "ldap_network_timeout" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3793 +#: sssd.conf.5.xml:3999 msgid "ldap_opt_timeout" msgstr "ldap_opt_timeout" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3796 +#: sssd.conf.5.xml:4002 msgid "ldap_offline_timeout" msgstr "ldap_offline_timeout" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3799 +#: sssd.conf.5.xml:4005 msgid "ldap_purge_cache_timeout" msgstr "ldap_purge_cache_timeout" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3802 +#: sssd.conf.5.xml:4008 msgid "ldap_purge_cache_offset" msgstr "ldap_purge_cache_offset" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3805 +#: sssd.conf.5.xml:4011 msgid "" "ldap_krb5_keytab (the value of krb5_keytab will be used if ldap_krb5_keytab " "is not set explicitly)" @@ -5488,52 +5841,52 @@ msgstr "" "ldap_krb5_keytab не встановлено явним чином)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3809 +#: sssd.conf.5.xml:4015 msgid "ldap_krb5_ticket_lifetime" msgstr "ldap_krb5_ticket_lifetime" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3812 +#: sssd.conf.5.xml:4018 msgid "ldap_connection_expire_timeout" msgstr "ldap_connection_expire_timeout" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3815 +#: sssd.conf.5.xml:4021 msgid "ldap_connection_expire_offset" msgstr "ldap_connection_expire_offset" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3818 +#: sssd.conf.5.xml:4024 msgid "ldap_connection_idle_timeout" msgstr "ldap_connection_idle_timeout" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3821 sssd-ldap.5.xml:446 +#: sssd.conf.5.xml:4027 sssd-ldap.5.xml:446 msgid "ldap_use_tokengroups" msgstr "ldap_use_tokengroups" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3824 +#: sssd.conf.5.xml:4030 msgid "ldap_user_principal" msgstr "ldap_user_principal" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3827 +#: sssd.conf.5.xml:4033 msgid "ignore_group_members" msgstr "ignore_group_members" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3830 +#: sssd.conf.5.xml:4036 msgid "auto_private_groups" msgstr "auto_private_groups" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3833 +#: sssd.conf.5.xml:4039 msgid "case_sensitive" msgstr "case_sensitive" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:3838 +#: sssd.conf.5.xml:4044 #, no-wrap msgid "" "subdomain_inherit = ldap_purge_cache_timeout\n" @@ -5543,28 +5896,28 @@ msgstr "" " " #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3845 +#: sssd.conf.5.xml:4051 msgid "Note: This option only works with the IPA and AD provider." msgstr "" "Зауваження: цей параметр працює лише для засобів надання даних IPA і AD." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3852 +#: sssd.conf.5.xml:4058 msgid "subdomain_homedir (string)" msgstr "subdomain_homedir (рядок)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3863 +#: sssd.conf.5.xml:4069 msgid "%F" msgstr "%F" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3864 +#: sssd.conf.5.xml:4070 msgid "flat (NetBIOS) name of a subdomain." msgstr "спрощена (NetBIOS) назва піддомену." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3855 +#: sssd.conf.5.xml:4061 msgid "" "Use this homedir as default value for all subdomains within this domain in " "IPA AD trust. See <emphasis>override_homedir</emphasis> for info about " @@ -5579,7 +5932,7 @@ msgstr "" "emphasis>. <placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3869 +#: sssd.conf.5.xml:4075 msgid "" "The value can be overridden by <emphasis>override_homedir</emphasis> option." msgstr "" @@ -5587,17 +5940,17 @@ msgstr "" "emphasis>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3873 +#: sssd.conf.5.xml:4079 msgid "Default: <filename>/home/%d/%u</filename>" msgstr "Типове значення: <filename>/home/%d/%u</filename>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3878 +#: sssd.conf.5.xml:4084 msgid "realmd_tags (string)" msgstr "realmd_tags (рядок)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3881 +#: sssd.conf.5.xml:4087 msgid "" "Various tags stored by the realmd configuration service for this domain." msgstr "" @@ -5605,17 +5958,23 @@ msgstr "" "домену." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3887 +#: sssd.conf.5.xml:4093 msgid "cached_auth_timeout (int)" msgstr "cached_auth_timeout (ціле число)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3890 +#: sssd.conf.5.xml:4096 +#, fuzzy +#| msgid "" +#| "Specifies time in seconds since last successful online authentication for " +#| "which user will be authenticated using cached credentials while SSSD is " +#| "in the online mode. If the credentials are incorrect, SSSD falls back to " +#| "online authentication." msgid "" -"Specifies time in seconds since last successful online authentication for " -"which user will be authenticated using cached credentials while SSSD is in " -"the online mode. If the credentials are incorrect, SSSD falls back to online " -"authentication." +"Specifies the number of seconds since the last successful online " +"authentication during which SSSD will authenticate users via cached " +"credentials, even while online. If the cached authentication fails, SSSD " +"immediately falls back to online authentication." msgstr "" "Визначає час у секундах з моменту останнього успішного розпізнавання у " "мережі, для якого користувача буде розпізнано за допомогою кешованих " @@ -5624,7 +5983,7 @@ msgstr "" "розпізнавання." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3898 +#: sssd.conf.5.xml:4103 msgid "" "This option's value is inherited by all trusted domains. At the moment it is " "not possible to set a different value per trusted domain." @@ -5634,12 +5993,12 @@ msgstr "" "значення для різних довірених доменів." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3903 +#: sssd.conf.5.xml:4108 msgid "Special value 0 implies that this feature is disabled." msgstr "Спеціальне значення 0 означає, що цю можливість вимкнено." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3907 +#: sssd.conf.5.xml:4112 msgid "" "Please note that if <quote>cached_auth_timeout</quote> is longer than " "<quote>pam_id_timeout</quote> then the back end could be called to handle " @@ -5650,12 +6009,12 @@ msgstr "" "обробки <quote>initgroups</quote>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3918 +#: sssd.conf.5.xml:4123 msgid "local_auth_policy (string)" msgstr "local_auth_policy (рядок)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3921 +#: sssd.conf.5.xml:4126 msgid "" "Local authentication methods policy. Some backends (i.e. LDAP, proxy " "provider) only support a password based authentication, while others can " @@ -5675,7 +6034,7 @@ msgstr "" "методи, обробка і перевірка у яких відбуватиметься локально." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3933 +#: sssd.conf.5.xml:4138 msgid "" "There are three possible values for this option: match, only, enable. " "<quote>match</quote> is used to match offline and online states for Kerberos " @@ -5695,7 +6054,7 @@ msgstr "" "enable:passkey, enable:smartcard</quote>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3946 +#: sssd.conf.5.xml:4151 msgid "" "The following table shows which authentication methods, if configured " "properly, are currently enabled or disabled for each backend, with the " @@ -5706,42 +6065,47 @@ msgstr "" "при типовому значенні local_auth_policy: <quote>match</quote>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> -#: sssd.conf.5.xml:3959 +#: sssd.conf.5.xml:4164 msgid "local_auth_policy = match (default)" msgstr "local_auth_policy = match (типове значення)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> -#: sssd.conf.5.xml:3960 +#: sssd.conf.5.xml:4165 msgid "Passkey" msgstr "Ключ" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> -#: sssd.conf.5.xml:3961 +#: sssd.conf.5.xml:4166 msgid "Smartcard" msgstr "Картка пам'яті" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:3964 sssd-ldap.5.xml:228 +#: sssd.conf.5.xml:4169 sssd-ldap.5.xml:228 msgid "IPA" msgstr "IPA" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry><para> +#: sssd.conf.5.xml:4169 sssd.conf.5.xml:4170 sssd.conf.5.xml:4173 +msgid "enabled" +msgstr "enabled" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:3967 sssd-ldap.5.xml:233 +#: sssd.conf.5.xml:4172 sssd-ldap.5.xml:233 msgid "AD" msgstr "AD" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry><para> -#: sssd.conf.5.xml:3967 sssd.conf.5.xml:3970 sssd.conf.5.xml:3971 +#: sssd.conf.5.xml:4172 sssd.conf.5.xml:4175 sssd.conf.5.xml:4176 msgid "disabled" msgstr "вимкнено" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry> -#: sssd.conf.5.xml:3970 +#: sssd.conf.5.xml:4175 msgid "LDAP" msgstr "LDAP" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3975 +#: sssd.conf.5.xml:4180 msgid "" "Please note that if local Smartcard authentication is enabled and a " "Smartcard is present, Smartcard authentication will be preferred over the " @@ -5755,7 +6119,7 @@ msgstr "" "наприклад, запиту щодо пароля." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:3987 +#: sssd.conf.5.xml:4192 #, no-wrap msgid "" "[domain/shadowutils]\n" @@ -5771,7 +6135,7 @@ msgstr "" "local_auth_policy = only\n" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3983 +#: sssd.conf.5.xml:4188 msgid "" "The following configuration example allows local users to authenticate " "locally using any enabled method (i.e. smartcard, passkey). <placeholder " @@ -5782,22 +6146,22 @@ msgstr "" "smartcard, passkey). <placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3995 +#: sssd.conf.5.xml:4200 msgid "Default: match" msgstr "Типове значення: match" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4000 +#: sssd.conf.5.xml:4205 msgid "auto_private_groups (string)" msgstr "auto_private_groups (рядок)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4006 +#: sssd.conf.5.xml:4211 msgid "true" msgstr "true" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4009 +#: sssd.conf.5.xml:4214 msgid "" "Create user's private group unconditionally from user's UID number. The GID " "number is ignored in this case." @@ -5806,7 +6170,7 @@ msgstr "" "користувача. У цьому випадку номер GID буде проігноровано." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4013 +#: sssd.conf.5.xml:4218 msgid "" "NOTE: Because the GID number and the user private group are inferred from " "the UID number, it is not supported to have multiple entries with the same " @@ -5819,12 +6183,12 @@ msgstr "" "примусово встановлює унікальність записів у просторі ідентифікаторів." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4022 +#: sssd.conf.5.xml:4227 msgid "false" msgstr "false" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4025 +#: sssd.conf.5.xml:4230 msgid "" "Always use the user's primary GID number. The GID number must refer to a " "group object in the LDAP database." @@ -5833,12 +6197,12 @@ msgstr "" "вказувати на об'єкт групи у базі даних LDAP." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4031 +#: sssd.conf.5.xml:4236 msgid "hybrid" msgstr "hybrid" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4034 +#: sssd.conf.5.xml:4239 msgid "" "A primary group is autogenerated for user entries whose UID and GID numbers " "have the same value and at the same time the GID number does not correspond " @@ -5853,7 +6217,7 @@ msgstr "" "цього користувача визначатиме цей об'єкт групи." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4047 +#: sssd.conf.5.xml:4252 msgid "" "If the UID and GID of a user are different, then the GID must correspond to " "a group entry, otherwise the GID is simply not resolvable." @@ -5862,7 +6226,7 @@ msgstr "" "групи, інакше надійне визначення GID буде просто неможливим." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4054 +#: sssd.conf.5.xml:4259 msgid "" "This feature is useful for environments that wish to stop maintaining a " "separate group objects for the user private groups, but also wish to retain " @@ -5873,7 +6237,7 @@ msgstr "" "збереженням наявних приватних груп для користувачів." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4003 +#: sssd.conf.5.xml:4208 msgid "" "This option takes any of three available values: <placeholder " "type=\"variablelist\" id=\"0\"/>" @@ -5882,7 +6246,7 @@ msgstr "" "type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4066 +#: sssd.conf.5.xml:4271 msgid "" "For the LDAP based id providers (LDAP, IPA and AD) the default for the " "configured domain is typically False because the sources have the concept of " @@ -5897,7 +6261,7 @@ msgstr "" "немає первинних груп.</phrase>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4075 +#: sssd.conf.5.xml:4280 msgid "" "For subdomains, the default value is False for subdomains that use assigned " "POSIX IDs and True for subdomains that use automatic ID-mapping." @@ -5907,7 +6271,7 @@ msgstr "" "використовується автоматична прив'язка до ідентифікаторів." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:4083 +#: sssd.conf.5.xml:4288 #, no-wrap msgid "" "[domain/forest.domain/sub.domain]\n" @@ -5917,7 +6281,7 @@ msgstr "" "auto_private_groups = false\n" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:4089 +#: sssd.conf.5.xml:4294 #, no-wrap msgid "" "[domain/forest.domain]\n" @@ -5929,7 +6293,7 @@ msgstr "" "auto_private_groups = false\n" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4080 +#: sssd.conf.5.xml:4285 msgid "" "The value of auto_private_groups can either be set per subdomains in a " "subsection, for example: <placeholder type=\"programlisting\" id=\"0\"/> or " @@ -5943,7 +6307,7 @@ msgstr "" "subdomain_inherit: <placeholder type=\"programlisting\" id=\"1\"/>" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:2503 +#: sssd.conf.5.xml:2549 msgid "" "These configuration options can be present in a domain configuration " "section, that is, in a section called <quote>[domain/<replaceable>NAME</" @@ -5954,17 +6318,17 @@ msgstr "" "quote> <placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4104 +#: sssd.conf.5.xml:4309 msgid "proxy_pam_target (string)" msgstr "proxy_pam_target (рядок)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4107 +#: sssd.conf.5.xml:4312 msgid "The proxy target PAM proxies to." msgstr "Комп’ютер, для якого виконує проксі-сервер PAM." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4110 +#: sssd.conf.5.xml:4315 msgid "" "Default: not set by default, you have to take an existing pam configuration " "or create a new one and add the service name here. As an alternative you can " @@ -5976,12 +6340,12 @@ msgstr "" "local_auth_policy." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4120 +#: sssd.conf.5.xml:4325 msgid "proxy_lib_name (string)" msgstr "proxy_lib_name (рядок)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4123 +#: sssd.conf.5.xml:4328 msgid "" "The name of the NSS library to use in proxy domains. The NSS functions " "searched for in the library are in the form of _nss_$(libName)_$(function), " @@ -5992,12 +6356,12 @@ msgstr "" "наприклад _nss_files_getpwent." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4133 +#: sssd.conf.5.xml:4338 msgid "proxy_resolver_lib_name (string)" msgstr "proxy_resolver_lib_name (рядок)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4136 +#: sssd.conf.5.xml:4341 msgid "" "The name of the NSS library to use for hosts and networks lookups in proxy " "domains. The NSS functions searched for in the library are in the form of " @@ -6008,12 +6372,12 @@ msgstr "" "(назва_бібліотеки)_$(функція), наприклад _nss_dns_gethostbyname2_r." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4147 +#: sssd.conf.5.xml:4352 msgid "proxy_fast_alias (boolean)" msgstr "proxy_fast_alias (булеве значення)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4150 +#: sssd.conf.5.xml:4355 msgid "" "When a user or group is looked up by name in the proxy provider, a second " "lookup by ID is performed to \"canonicalize\" the name in case the requested " @@ -6028,12 +6392,12 @@ msgstr "" "у кеші, щоб пришвидшити надання результатів." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4164 +#: sssd.conf.5.xml:4369 msgid "proxy_max_children (integer)" msgstr "proxy_max_children (ціле число)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4167 +#: sssd.conf.5.xml:4372 msgid "" "This option specifies the number of pre-forked proxy children. It is useful " "for high-load SSSD environments where sssd may run out of available child " @@ -6045,7 +6409,7 @@ msgstr "" "використання черги запитів." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4100 +#: sssd.conf.5.xml:4305 msgid "" "Options valid for proxy domains. <placeholder type=\"variablelist\" " "id=\"0\"/>" @@ -6054,12 +6418,12 @@ msgstr "" "type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:4183 +#: sssd.conf.5.xml:4388 msgid "Application domains" msgstr "Домени програм (application)" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:4185 +#: sssd.conf.5.xml:4390 msgid "" "SSSD, with its D-Bus interface (see <citerefentry> <refentrytitle>sssd-ifp</" "refentrytitle> <manvolnum>5</manvolnum> </citerefentry>) is appealing to " @@ -6087,7 +6451,7 @@ msgstr "" "який може успадковувати параметр з традиційного домену SSSD." #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:4205 +#: sssd.conf.5.xml:4410 msgid "" "Please note that the application domain must still be explicitly enabled in " "the <quote>domains</quote> parameter so that the lookup order between the " @@ -6098,17 +6462,17 @@ msgstr "" "його доменом-близнюком у POSIX має бути встановлено належним чином." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><title> -#: sssd.conf.5.xml:4211 +#: sssd.conf.5.xml:4416 msgid "Application domain parameters" msgstr "Параметри доменів програм" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4213 +#: sssd.conf.5.xml:4418 msgid "inherit_from (string)" msgstr "inherit_from (рядок)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4216 +#: sssd.conf.5.xml:4421 msgid "" "The SSSD POSIX-type domain the application domain inherits all settings " "from. The application domain can moreover add its own settings to the " @@ -6120,7 +6484,7 @@ msgstr "" "розширюють або перевизначають параметри домену-<quote>близнюка</quote>." #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:4230 +#: sssd.conf.5.xml:4435 msgid "" "The following example illustrates the use of an application domain. In this " "setup, the POSIX domain is connected to an LDAP server and is used by the OS " @@ -6135,7 +6499,7 @@ msgstr "" "у кеші і робить атрибут phone доступним через інтерфейс D-Bus." #. type: Content of: <reference><refentry><refsect1><refsect2><programlisting> -#: sssd.conf.5.xml:4238 +#: sssd.conf.5.xml:4443 #, no-wrap msgid "" "[sssd]\n" @@ -6169,12 +6533,12 @@ msgstr "" "ldap_user_extra_attrs = phone:telephoneNumber\n" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:4258 +#: sssd.conf.5.xml:4463 msgid "TRUSTED DOMAIN SECTION" msgstr "РОЗДІЛ ДОВІРЕНИХ ДОМЕНІВ" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4260 +#: sssd.conf.5.xml:4465 msgid "" "Some options used in the domain section can also be used in the trusted " "domain section, that is, in a section called <quote>[domain/" @@ -6192,57 +6556,67 @@ msgstr "" "такі параметри:" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4267 +#: sssd.conf.5.xml:4472 msgid "ldap_search_base," msgstr "ldap_search_base," #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4268 +#: sssd.conf.5.xml:4473 msgid "ldap_user_search_base," msgstr "ldap_user_search_base," #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4269 +#: sssd.conf.5.xml:4474 msgid "ldap_group_search_base," msgstr "ldap_group_search_base," #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4270 +#: sssd.conf.5.xml:4475 msgid "ldap_netgroup_search_base," msgstr "ldap_netgroup_search_base," #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4271 +#: sssd.conf.5.xml:4476 msgid "ldap_service_search_base," msgstr "ldap_service_search_base," #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4272 +#: sssd.conf.5.xml:4477 msgid "ldap_sasl_mech," msgstr "ldap_sasl_mech," #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4273 +#: sssd.conf.5.xml:4478 msgid "ad_server," msgstr "ad_server," #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4274 +#: sssd.conf.5.xml:4479 msgid "ad_backup_server," msgstr "ad_backup_server," #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4275 +#: sssd.conf.5.xml:4480 msgid "ad_site," msgstr "ad_site," #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:4276 sssd-ipa.5.xml:934 +#: sssd.conf.5.xml:4481 sssd-ipa.5.xml:929 msgid "use_fully_qualified_names" msgstr "use_fully_qualified_names" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4280 +#: sssd.conf.5.xml:4482 +msgid "pam_gssapi_services" +msgstr "pam_gssapi_services" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:4483 +msgid "pam_gssapi_check_upn" +msgstr "pam_gssapi_check_upn" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:4485 msgid "" "For more details about these options see their individual description in the " "manual page." @@ -6251,12 +6625,12 @@ msgstr "" "підручника." #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:4286 +#: sssd.conf.5.xml:4491 msgid "CERTIFICATE MAPPING SECTION" msgstr "РОЗДІЛ ПРИВ'ЯЗКИ СЕРТИФІКАТІВ" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4288 +#: sssd.conf.5.xml:4493 msgid "" "To allow authentication with Smartcards and certificates SSSD must be able " "to map certificates to users. This can be done by adding the full " @@ -6279,7 +6653,7 @@ msgstr "" "використовують для розпізнавання PAM." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4302 +#: sssd.conf.5.xml:4507 msgid "" "To make the mapping more flexible mapping and matching rules were added to " "SSSD (see <citerefentry> <refentrytitle>sss-certmap</refentrytitle> " @@ -6291,7 +6665,7 @@ msgstr "" "citerefentry>)." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4311 +#: sssd.conf.5.xml:4516 msgid "" "A mapping and matching rule can be added to the SSSD configuration in a " "section on its own with a name like <quote>[certmap/" @@ -6304,12 +6678,12 @@ msgstr "" ". У цьому розділі можна використовувати такі параметри:" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4318 +#: sssd.conf.5.xml:4523 msgid "matchrule (string)" msgstr "matchrule (рядок)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4321 +#: sssd.conf.5.xml:4526 msgid "" "Only certificates from the Smartcard which matches this rule will be " "processed, all others are ignored." @@ -6318,7 +6692,7 @@ msgstr "" "цьому правилу. Усі інші сертифікати буде проігноровано." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4325 +#: sssd.conf.5.xml:4530 msgid "" "Default: KRB5:<EKU>clientAuth, i.e. only certificates which have the " "Extended Key Usage <quote>clientAuth</quote>" @@ -6328,17 +6702,17 @@ msgstr "" "clientAuth</quote>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4332 +#: sssd.conf.5.xml:4537 msgid "maprule (string)" msgstr "maprule (рядок)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4335 +#: sssd.conf.5.xml:4540 msgid "Defines how the user is found for a given certificate." msgstr "Визначає спосіб пошуку користувача для вказаного сертифіката." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:4341 +#: sssd.conf.5.xml:4546 msgid "" "LDAP:(userCertificate;binary={cert!bin}) for LDAP based providers like " "<quote>ldap</quote>, <quote>AD</quote> or <quote>ipa</quote>." @@ -6347,7 +6721,7 @@ msgstr "" "даних, зокрема <quote>ldap</quote>, <quote>AD</quote> та <quote>ipa</quote>." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:4347 +#: sssd.conf.5.xml:4552 msgid "" "If maprule is not set and provider is <quote>proxy</quote>, the RULE_NAME " "name is assumed to be the name of the matching user." @@ -6356,13 +6730,8 @@ msgstr "" "припускається, що значенням RULE_NAME є назва відповідного облікового запису " "користувача." -#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4357 -msgid "domains (string)" -msgstr "domains (рядок)" - #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4360 +#: sssd.conf.5.xml:4565 msgid "" "Comma separated list of domain names the rule should be applied. By default " "a rule is only valid in the domain configured in sssd.conf. If the provider " @@ -6375,17 +6744,17 @@ msgstr "" "параметр можна використати і для додавання правила до піддоменів." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4367 +#: sssd.conf.5.xml:4572 msgid "Default: the configured domain in sssd.conf" msgstr "Типове значення: домен, який налаштовано у sssd.conf" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4372 +#: sssd.conf.5.xml:4577 msgid "priority (integer)" msgstr "priority (ціле число)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4375 +#: sssd.conf.5.xml:4580 msgid "" "Unsigned integer value defining the priority of the rule. The higher the " "number the lower the priority. <quote>0</quote> stands for the highest " @@ -6396,17 +6765,17 @@ msgstr "" "пріоритетність, а <quote>4294967295</quote> — найнижча." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4381 +#: sssd.conf.5.xml:4586 msgid "Default: the lowest priority" msgstr "Типове значення: найнижча пріоритетність" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:4389 +#: sssd.conf.5.xml:4594 msgid "PROMPTING CONFIGURATION SECTION" msgstr "РОЗДІЛ НАЛАШТОВУВАННЯ ЗАПИТІВ" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4391 +#: sssd.conf.5.xml:4596 msgid "" "If a special file (<filename>/var/lib/sss/pubconf/pam_preauth_available</" "filename>) exists SSSD's PAM module pam_sss will ask SSSD to figure out " @@ -6422,7 +6791,7 @@ msgstr "" "реєстраційних даних." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4399 +#: sssd.conf.5.xml:4604 msgid "" "With the growing number of authentication methods and the possibility that " "there are multiple ones for a single user the heuristic used by pam_sss to " @@ -6436,22 +6805,22 @@ msgstr "" "випадках мають забезпечити описані нижче параметри." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4411 +#: sssd.conf.5.xml:4616 msgid "[prompting/password]" msgstr "[prompting/password]" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4414 +#: sssd.conf.5.xml:4619 msgid "password_prompt" msgstr "password_prompt" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4415 +#: sssd.conf.5.xml:4620 msgid "to change the string of the password prompt" msgstr "для зміни рядка запиту пароля" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4413 +#: sssd.conf.5.xml:4618 msgid "" "to configure password prompting, allowed options are: <placeholder " "type=\"variablelist\" id=\"0\"/>" @@ -6460,37 +6829,37 @@ msgstr "" "type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4423 +#: sssd.conf.5.xml:4628 msgid "[prompting/2fa]" msgstr "[prompting/2fa]" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4427 +#: sssd.conf.5.xml:4632 msgid "first_prompt" msgstr "first_prompt" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4428 +#: sssd.conf.5.xml:4633 msgid "to change the string of the prompt for the first factor" msgstr "для зміни рядка запиту для першого фактора" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4431 +#: sssd.conf.5.xml:4636 msgid "second_prompt" msgstr "second_prompt" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4432 +#: sssd.conf.5.xml:4637 msgid "to change the string of the prompt for the second factor" msgstr "для зміни рядка запиту для другого фактора" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4435 +#: sssd.conf.5.xml:4640 msgid "single_prompt" msgstr "single_prompt" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4436 +#: sssd.conf.5.xml:4641 msgid "" "boolean value, if True there will be only a single prompt using the value of " "first_prompt where it is expected that both factors are entered as a single " @@ -6503,7 +6872,7 @@ msgstr "" "якщо другий фактор не є обов'язковим." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4425 +#: sssd.conf.5.xml:4630 msgid "" "to configure two-factor authentication prompting, allowed options are: " "<placeholder type=\"variablelist\" id=\"0\"/> If the second factor is " @@ -6516,7 +6885,7 @@ msgstr "" "паролем, або за двома факторами, має бути використано двокроковий запит." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4449 +#: sssd.conf.5.xml:4654 msgid "" "Some clients, such as SSH with 'PasswordAuthentication yes', generate their " "own prompts and do not use prompts provided by SSSD or other PAM modules. " @@ -6533,17 +6902,17 @@ msgstr "" "якщо двофакторне розпізнавання не є обов'язковим." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4464 +#: sssd.conf.5.xml:4669 msgid "[prompting/passkey]" msgstr "[prompting/passkey]" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:4470 sssd-ad.5.xml:1022 +#: sssd.conf.5.xml:4675 sssd.conf.5.xml:4719 sssd-ad.5.xml:1027 msgid "interactive" msgstr "interactive" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4472 +#: sssd.conf.5.xml:4677 msgid "" "boolean value, if True prompt a message and wait before testing the presence " "of a passkey device. Recommended if your device doesn’t have a tactile " @@ -6554,22 +6923,22 @@ msgstr "" "тактильного перемикача." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4480 +#: sssd.conf.5.xml:4685 sssd.conf.5.xml:4735 msgid "interactive_prompt" msgstr "interactive_prompt" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4482 +#: sssd.conf.5.xml:4687 sssd.conf.5.xml:4737 msgid "to change the message of the interactive prompt." msgstr "для зміни повідомлення інтерактивного запиту." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4487 +#: sssd.conf.5.xml:4692 msgid "touch" msgstr "touch" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4489 +#: sssd.conf.5.xml:4694 msgid "" "boolean value, if True prompt a message to remind the user to touch the " "device." @@ -6578,17 +6947,17 @@ msgstr "" "користувачеві щодо потреби торкнутися пристрою." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4495 +#: sssd.conf.5.xml:4700 msgid "touch_prompt" msgstr "touch_prompt" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4497 +#: sssd.conf.5.xml:4702 msgid "to change the message of the touch prompt." msgstr "для зміни повідомлення запиту щодо торкання." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4466 +#: sssd.conf.5.xml:4671 msgid "" "to configure passkey authentication prompting, allowed options are: " "<placeholder type=\"variablelist\" id=\"0\"/>" @@ -6596,13 +6965,123 @@ msgstr "" "для налаштовування запиту щодо розпізнавання за ключем; дозволені параметри: " "<placeholder type=\"variablelist\" id=\"0\"/>" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4713 +#, fuzzy +#| msgid "[prompting/2fa]" +msgid "[prompting/oauth2]" +msgstr "[prompting/2fa]" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4721 +#, fuzzy +#| msgid "" +#| "boolean value, if True prompt a message to remind the user to touch the " +#| "device." +msgid "" +"boolean value, if True prompt a message after asking the user to " +"authenticate, and wait before requesting the access token." +msgstr "" +"булеве значення, якщо True, надіслати повідомлення для нагадування " +"користувачеві щодо потреби торкнутися пристрою." + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4725 +msgid "" +"If False, make sure to set the <quote>idp_request_timeout</quote> " +"sufficiently high, to give the user time to authenticate." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4715 +#, fuzzy +#| msgid "" +#| "to configure passkey authentication prompting, allowed options are: " +#| "<placeholder type=\"variablelist\" id=\"0\"/>" +msgid "" +"to configure OAuth2 authentication prompting, allowed options are: " +"<placeholder type=\"variablelist\" id=\"0\"/>" +msgstr "" +"для налаштовування запиту щодо розпізнавання за ключем; дозволені параметри: " +"<placeholder type=\"variablelist\" id=\"0\"/>" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4748 +#, fuzzy +#| msgid "[prompting/2fa]" +msgid "[prompting/cert_auth]" +msgstr "[prompting/2fa]" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4754 +#, fuzzy +#| msgid "single_prompt" +msgid "pin_prompt" +msgstr "single_prompt" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4756 +msgid "" +"to change the message which asks the user to enter the PIN at the computer " +"keyboard. At the end of the message the token name is printed." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4764 +#, fuzzy +#| msgid "password_prompt" +msgid "keypad_prompt" +msgstr "password_prompt" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4766 +msgid "" +"to change the message which asks the user to enter the PIN at keypad of the " +"Smartcard reader. At the end of the message the token name is printed." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4774 +#, fuzzy +#| msgid "username" +msgid "user_name_hint" +msgstr "користувач" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4776 +msgid "" +"boolean value, if True ask for a user name if no name was given before and " +"the found certificate can be mapped to more than one user." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4750 +#, fuzzy +#| msgid "" +#| "to configure passkey authentication prompting, allowed options are: " +#| "<placeholder type=\"variablelist\" id=\"0\"/>" +msgid "" +"to configure Smartcard authentication prompting, allowed options are: " +"<placeholder type=\"variablelist\" id=\"0\"/>" +msgstr "" +"для налаштовування запиту щодо розпізнавання за ключем; дозволені параметри: " +"<placeholder type=\"variablelist\" id=\"0\"/>" + #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4406 +#: sssd.conf.5.xml:4611 +#, fuzzy +#| msgid "" +#| "Each supported authentication method has its own configuration subsection " +#| "under <quote>[prompting/...]</quote>. Currently there are: <placeholder " +#| "type=\"variablelist\" id=\"0\"/> <placeholder type=\"variablelist\" " +#| "id=\"1\"/> <placeholder type=\"variablelist\" id=\"2\"/>" msgid "" "Each supported authentication method has its own configuration subsection " "under <quote>[prompting/...]</quote>. Currently there are: <placeholder " "type=\"variablelist\" id=\"0\"/> <placeholder type=\"variablelist\" id=\"1\"/" -"> <placeholder type=\"variablelist\" id=\"2\"/>" +"> <placeholder type=\"variablelist\" id=\"2\"/> <placeholder " +"type=\"variablelist\" id=\"3\"/> <placeholder type=\"variablelist\" id=\"4\"/" +">" msgstr "" "У кожного з підтримуваних способів розпізнавання є власний підрозділ " "налаштувань у <quote>[prompting/...]</quote>. У поточній версії це: " @@ -6610,7 +7089,7 @@ msgstr "" "type=\"variablelist\" id=\"1\"/><placeholder type=\"variablelist\" id=\"2\"/>" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4508 +#: sssd.conf.5.xml:4792 msgid "" "It is possible to add a subsection for specific PAM services, e.g. " "<quote>[prompting/password/sshd]</quote> to individual change the prompting " @@ -6621,12 +7100,12 @@ msgstr "" "для цієї служби." #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:4515 pam_sss_gss.8.xml:157 idmap_sss.8.xml:43 +#: sssd.conf.5.xml:4799 pam_sss_gss.8.xml:157 idmap_sss.8.xml:43 msgid "EXAMPLES" msgstr "ПРИКЛАДИ" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd.conf.5.xml:4521 +#: sssd.conf.5.xml:4805 #, no-wrap msgid "" "[sssd]\n" @@ -6678,7 +7157,7 @@ msgstr "" "enumerate = False\n" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4517 +#: sssd.conf.5.xml:4801 msgid "" "1. The following example shows a typical SSSD config. It does not describe " "configuration of the domains themselves - refer to documentation on " @@ -6691,7 +7170,7 @@ msgstr "" "type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd.conf.5.xml:4553 +#: sssd.conf.5.xml:4837 #, no-wrap msgid "" "[domain/ipa.com/child.ad.com]\n" @@ -6701,7 +7180,7 @@ msgstr "" "use_fully_qualified_names = false\n" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4547 +#: sssd.conf.5.xml:4831 msgid "" "2. The following example shows configuration of IPA AD trust where the AD " "forest consists of two domains in a parent-child structure. Suppose IPA " @@ -6718,7 +7197,7 @@ msgstr "" "type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd.conf.5.xml:4564 +#: sssd.conf.5.xml:4848 #, no-wrap msgid "" "[certmap/my.domain/rule_name]\n" @@ -6734,7 +7213,7 @@ msgstr "" "priority = 10\n" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4558 +#: sssd.conf.5.xml:4842 msgid "" "3. The following example shows the configuration of a certificate mapping " "rule. It is valid for the configured domain <quote>my.domain</quote> and " @@ -6973,13 +7452,21 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:151 +#, fuzzy +#| msgid "" +#| "Default: If not set, the value of the defaultNamingContext or " +#| "namingContexts attribute from the RootDSE of the LDAP server is used. If " +#| "defaultNamingContext does not exist or has an empty value namingContexts " +#| "is used. The namingContexts attribute must have a single value with the " +#| "DN of the search base of the LDAP server to make this work. Multiple " +#| "values are are not supported." msgid "" "Default: If not set, the value of the defaultNamingContext or namingContexts " "attribute from the RootDSE of the LDAP server is used. If " "defaultNamingContext does not exist or has an empty value namingContexts is " "used. The namingContexts attribute must have a single value with the DN of " "the search base of the LDAP server to make this work. Multiple values are " -"are not supported." +"not supported." msgstr "" "Типове значення: якщо значення не встановлено, буде використано значення " "атрибута defaultNamingContext або namingContexts з RootDSE сервера LDAP. " @@ -7353,8 +7840,8 @@ msgstr "" "Необов’язковий. Використати вказаний рядок як основу пошуку об’єктів вузлів." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap.5.xml:472 sssd-ipa.5.xml:506 sssd-ipa.5.xml:525 sssd-ipa.5.xml:544 -#: sssd-ipa.5.xml:563 +#: sssd-ldap.5.xml:472 sssd-ipa.5.xml:501 sssd-ipa.5.xml:520 sssd-ipa.5.xml:539 +#: sssd-ipa.5.xml:558 msgid "" "See <quote>ldap_search_base</quote> for information about configuring " "multiple search bases." @@ -7363,7 +7850,7 @@ msgstr "" "налаштування декількох основ пошуку." #. type: Content of: <listitem><para> -#: sssd-ldap.5.xml:477 sssd-ipa.5.xml:511 include/ldap_search_bases.xml:27 +#: sssd-ldap.5.xml:477 sssd-ipa.5.xml:506 include/ldap_search_bases.xml:27 msgid "Default: the value of <emphasis>ldap_search_base</emphasis>" msgstr "Типове значення: значення <emphasis>ldap_search_base</emphasis>" @@ -7512,21 +7999,29 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:621 +#, fuzzy +#| msgid "" +#| "If the connection is idle (not actively running an operation) within " +#| "<emphasis>ldap_opt_timeout</emphasis> seconds of expiration, then it will " +#| "be closed early to ensure that a new query cannot require the connection " +#| "to remain open past its expiration. This implies that connections will " +#| "always be closed immediately and will never be reused if " +#| "<emphasis>ldap_connection_expire_timeout <= ldap_opt_timout</emphasis>" msgid "" "If the connection is idle (not actively running an operation) within " "<emphasis>ldap_opt_timeout</emphasis> seconds of expiration, then it will be " "closed early to ensure that a new query cannot require the connection to " "remain open past its expiration. This implies that connections will always " "be closed immediately and will never be reused if " -"<emphasis>ldap_connection_expire_timeout <= ldap_opt_timout</emphasis>" +"<emphasis>ldap_connection_expire_timeout <= ldap_opt_timeout</emphasis>" msgstr "" "Якщо з'єднання є бездіяльним (жодна дія у ньому не виконується активно) " "протягом <emphasis>ldap_opt_timeout</emphasis> секунд завершення строку дії, " "його буде передчасно розірвано, щоб новий запит не міг потребувати, щоб " "з'єднання лишалося відкритим після завершення його строку дії. Неявним " "чином, це означає, що з'єднання завжди розриватимуться негайно і не " -"використовуватимуться повторно, якщо <emphasis>" -"ldap_connection_expire_timeout <= ldap_opt_timout</emphasis>" +"використовуватимуться повторно, якщо " +"<emphasis>ldap_connection_expire_timeout <= ldap_opt_timout</emphasis>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:633 @@ -7760,7 +8255,9 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:831 -msgid "ldap_ignore_unreadable_references (bool)" +#, fuzzy +#| msgid "ldap_ignore_unreadable_references (bool)" +msgid "ldap_ignore_unreadable_references (boolean)" msgstr "ldap_ignore_unreadable_references (булеве значення)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> @@ -8189,7 +8686,7 @@ msgstr "" "SPNEGO." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap.5.xml:1152 sssd-ad.5.xml:1267 +#: sssd-ldap.5.xml:1152 sssd-ad.5.xml:1260 msgid "Default: 86400 (24 hours)" msgstr "Типове значення: 86400 (24 години)" @@ -8241,7 +8738,7 @@ msgstr "" "варто перейти на використання «krb5_server» у файлах налаштувань." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ldap.5.xml:1187 sssd-ipa.5.xml:575 sssd-krb5.5.xml:103 +#: sssd-ldap.5.xml:1187 sssd-ipa.5.xml:570 sssd-krb5.5.xml:103 msgid "krb5_realm (string)" msgstr "krb5_realm (рядок)" @@ -8438,7 +8935,9 @@ msgstr "Типове значення: не встановлено, тобто #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1339 -msgid "ldap_chpass_update_last_change (bool)" +#, fuzzy +#| msgid "ldap_chpass_update_last_change (bool)" +msgid "ldap_chpass_update_last_change (boolean)" msgstr "ldap_chpass_update_last_change (булеве значення)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> @@ -8641,7 +9140,7 @@ msgid "ldap_access_order (string)" msgstr "ldap_access_order (рядок)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap.5.xml:1470 sssd-ipa.5.xml:405 +#: sssd-ldap.5.xml:1470 sssd-ipa.5.xml:400 msgid "Comma separated list of access control options. Allowed values are:" msgstr "" "Список відокремлених комами параметрів керування доступом. Можливі значення " @@ -8706,7 +9205,7 @@ msgid "<emphasis>expire</emphasis>: use ldap_account_expire_policy" msgstr "<emphasis>expire</emphasis>: використовувати ldap_account_expire_policy" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap.5.xml:1515 sssd-ipa.5.xml:413 +#: sssd-ldap.5.xml:1515 sssd-ipa.5.xml:408 msgid "" "<emphasis>pwd_expire_policy_reject, pwd_expire_policy_warn, " "pwd_expire_policy_renew: </emphasis> These options are useful if users are " @@ -8721,7 +9220,7 @@ msgstr "" "наприклад на ключах SSH." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap.5.xml:1525 sssd-ipa.5.xml:423 +#: sssd-ldap.5.xml:1525 sssd-ipa.5.xml:418 msgid "" "The difference between these options is the action taken if user password is " "expired:" @@ -8730,17 +9229,17 @@ msgstr "" "дії пароля буде вичерпано:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ldap.5.xml:1530 sssd-ipa.5.xml:428 +#: sssd-ldap.5.xml:1530 sssd-ipa.5.xml:423 msgid "pwd_expire_policy_reject - user is denied to log in," msgstr "pwd_expire_policy_reject — користувачу заборонено входити," #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ldap.5.xml:1536 sssd-ipa.5.xml:434 +#: sssd-ldap.5.xml:1536 sssd-ipa.5.xml:429 msgid "pwd_expire_policy_warn - user is still able to log in," msgstr "pwd_expire_policy_warn — користувачу можна входити," #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ldap.5.xml:1542 sssd-ipa.5.xml:440 +#: sssd-ldap.5.xml:1542 sssd-ipa.5.xml:435 msgid "" "pwd_expire_policy_renew - user is prompted to change their password " "immediately." @@ -9411,8 +9910,8 @@ msgstr "" "<placeholder type=\"variablelist\" id=\"1\"/>" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd-ldap.5.xml:2032 sssd-simple.5.xml:169 sssd-ipa.5.xml:984 -#: sssd-ad.5.xml:1470 sssd-idp.5.xml:248 sssd-krb5.5.xml:483 +#: sssd-ldap.5.xml:2032 sssd-simple.5.xml:169 sssd-ipa.5.xml:979 +#: sssd-ad.5.xml:1463 sssd-idp.5.xml:343 sssd-krb5.5.xml:483 #: sss_rpcidmapd.5.xml:98 sssd-session-recording.5.xml:176 msgid "EXAMPLE" msgstr "ПРИКЛАД" @@ -9450,7 +9949,7 @@ msgstr "" #. type: Content of: <refsect1><refsect2><para> #: sssd-ldap.5.xml:2039 sssd-ldap.5.xml:2057 sssd-simple.5.xml:177 -#: sssd-ipa.5.xml:992 sssd-ad.5.xml:1478 sssd-sudo.5.xml:56 sssd-krb5.5.xml:492 +#: sssd-ipa.5.xml:987 sssd-ad.5.xml:1471 sssd-sudo.5.xml:56 sssd-krb5.5.xml:492 #: sssd-session-recording.5.xml:182 include/ldap_id_mapping.xml:105 msgid "<placeholder type=\"programlisting\" id=\"0\"/>" msgstr "<placeholder type=\"programlisting\" id=\"0\"/>" @@ -9497,7 +9996,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><title> #: sssd-ldap.5.xml:2073 sssd_krb5_locator_plugin.8.xml:83 sssd-simple.5.xml:189 -#: sssd-ad.5.xml:1493 sssd.8.xml:270 sss_seed.8.xml:163 +#: sssd-ad.5.xml:1486 sssd.8.xml:270 sss_seed.8.xml:163 msgid "NOTES" msgstr "ЗАУВАЖЕННЯ" @@ -10117,9 +10616,14 @@ msgstr "PAM_NO_MODULE_DATA" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:434 +#, fuzzy +#| msgid "" +#| "No authentication method was found by Kerberos. This might happen if the " +#| "user has a Smartcard assigned but the pkint plugin is not available on " +#| "the client." msgid "" "No authentication method was found by Kerberos. This might happen if the " -"user has a Smartcard assigned but the pkint plugin is not available on the " +"user has a Smartcard assigned but the pkinit plugin is not available on the " "client." msgstr "" "Kerberos не вдалося знайти метод розпізнавання. Таке може трапитися, якщо із " @@ -10695,6 +11199,23 @@ msgstr "" "DNS у файлі kdcinfo. Типово, додаток повертає функції виклику " "KRB5_PLUGIN_NO_HANDLE негайно після першої ж невдалої спроби визначення DNS." +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_locator_plugin.8.xml:106 +msgid "" +"If the environment variable SSSD_KRB5_LOCATOR_KDC_ADDRESS is set to a KDC " +"address the plugin will use this address instead of reading the kdcinfo " +"file. The address format is the same as in the kdcinfo file (see above)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_locator_plugin.8.xml:112 +msgid "" +"If the environment variable SSSD_KRB5_LOCATOR_KPASSWD_ADDRESS is set to a " +"kpasswd server address the plugin will use this address instead of reading " +"the kpasswdinfo file. The address format is the same as in the kpasswdinfo " +"file (see above)." +msgstr "" + #. type: Content of: <reference><refentry><refnamediv><refname> #: sssd-simple.5.xml:10 sssd-simple.5.xml:16 msgid "sssd-simple" @@ -12439,7 +12960,7 @@ msgstr "" "цього вузла. Назву вузла слід вказувати повністю." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:129 sssd-ad.5.xml:1161 +#: sssd-ipa.5.xml:129 sssd-ad.5.xml:1166 msgid "dyndns_update (boolean)" msgstr "dyndns_update (булеве значення)" @@ -12458,23 +12979,13 @@ msgstr "" "використано IP-адресу з’єднання LDAP IPA, якщо не вказано іншу адресу за " "допомогою параметра «dyndns_iface»." -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:141 sssd-ad.5.xml:1175 -msgid "" -"NOTE: On older systems (such as RHEL 5), for this behavior to work reliably, " -"the default Kerberos realm must be set properly in /etc/krb5.conf" -msgstr "" -"ЗАУВАЖЕННЯ: на застарілих системах (зокрема RHEL 5) для надійної роботи у " -"цьому режимі типову область дії Kerberos має бути належним чином визначено " -"у /etc/krb5.conf" - #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:152 sssd-ad.5.xml:1186 +#: sssd-ipa.5.xml:147 sssd-ad.5.xml:1186 msgid "dyndns_ttl (integer)" msgstr "dyndns_ttl (ціле число)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:155 sssd-ad.5.xml:1189 +#: sssd-ipa.5.xml:150 sssd-ad.5.xml:1189 msgid "" "The TTL to apply to the client DNS record when updating it. If " "dyndns_update is false this has no effect. This will override the TTL " @@ -12485,17 +12996,17 @@ msgstr "" "Перевизначає TTL на боці сервера, якщо встановлено адміністратором." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:160 +#: sssd-ipa.5.xml:155 msgid "Default: 1200 (seconds)" msgstr "Типове значення: 1200 (секунд)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:166 sssd-ad.5.xml:1200 +#: sssd-ipa.5.xml:161 sssd-ad.5.xml:1200 msgid "dyndns_iface (string)" msgstr "dyndns_iface (рядок)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:169 sssd-ad.5.xml:1203 +#: sssd-ipa.5.xml:164 sssd-ad.5.xml:1203 #, fuzzy #| msgid "" #| "Optional. Applicable only when dyndns_update is true. Choose the " @@ -12518,7 +13029,7 @@ msgstr "" "дізнатися більше про взірці." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:182 +#: sssd-ipa.5.xml:177 msgid "" "Default: Use the IP addresses of the interface which is used for IPA LDAP " "connection" @@ -12527,21 +13038,21 @@ msgstr "" "для з’єднання LDAP IPA" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:186 sssd-ad.5.xml:1226 +#: sssd-ipa.5.xml:181 sssd-ad.5.xml:1220 #, fuzzy #| msgid "Example: dyndns_iface = em1, vnet1, vnet2" msgid "Example: dyndns_iface = em[12], !vnet1, vnet*" msgstr "Приклад: dyndns_iface = em1, vnet1, vnet2" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:192 sssd-ad.5.xml:1232 +#: sssd-ipa.5.xml:187 sssd-ad.5.xml:1226 #, fuzzy #| msgid "dyndns_iface (string)" msgid "dyndns_address (string)" msgstr "dyndns_iface (рядок)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:195 sssd-ad.5.xml:1235 +#: sssd-ipa.5.xml:190 sssd-ad.5.xml:1229 msgid "" "Optional. Applicable only when <emphasis>dyndns_update</emphasis> is true. " "A list of IP addresses or IP networks to be used for dynamic DNS updates. " @@ -12552,22 +13063,22 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:206 sssd-ad.5.xml:1246 +#: sssd-ipa.5.xml:201 sssd-ad.5.xml:1240 msgid "Default: No filtering of IP addresses." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:209 sssd-ad.5.xml:1249 +#: sssd-ipa.5.xml:204 sssd-ad.5.xml:1243 msgid "Example: dyndns_address = 10.0.0.0/16, !10.0.1.0/24" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:215 sssd-ad.5.xml:1305 +#: sssd-ipa.5.xml:210 sssd-ad.5.xml:1298 msgid "dyndns_auth (string)" msgstr "dyndns_auth (рядок)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:218 sssd-ad.5.xml:1308 +#: sssd-ipa.5.xml:213 sssd-ad.5.xml:1301 msgid "" "Whether the nsupdate utility should use GSS-TSIG authentication for secure " "updates with the DNS server, insecure updates can be sent by setting this " @@ -12578,17 +13089,17 @@ msgstr "" "можна надсилати встановленням для цього параметра значення «none»." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:224 sssd-ad.5.xml:1314 +#: sssd-ipa.5.xml:219 sssd-ad.5.xml:1307 msgid "Default: GSS-TSIG" msgstr "Типове значення: GSS-TSIG" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:230 sssd-ad.5.xml:1320 +#: sssd-ipa.5.xml:225 sssd-ad.5.xml:1313 msgid "dyndns_auth_ptr (string)" msgstr "dyndns_auth_ptr (рядок)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:233 sssd-ad.5.xml:1323 +#: sssd-ipa.5.xml:228 sssd-ad.5.xml:1316 msgid "" "Whether the nsupdate utility should use GSS-TSIG authentication for secure " "PTR updates with the DNS server, insecure updates can be sent by setting " @@ -12599,17 +13110,17 @@ msgstr "" "оновлення можна надсилати встановленням для цього параметра значення «none»." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:239 sssd-ad.5.xml:1329 +#: sssd-ipa.5.xml:234 sssd-ad.5.xml:1322 msgid "Default: Same as dyndns_auth" msgstr "Типове значення: те саме, що і dyndns_auth" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:245 sssd-ad.5.xml:1255 +#: sssd-ipa.5.xml:240 sssd-ad.5.xml:1249 msgid "dyndns_refresh_interval (integer)" msgstr "dyndns_refresh_interval (ціле число)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:248 +#: sssd-ipa.5.xml:243 msgid "" "How often should the back end perform periodic DNS update in addition to the " "automatic update performed when the back end goes online. This option is " @@ -12621,12 +13132,14 @@ msgstr "" "є обов’язкоми, його застосовують, лише якщо dyndns_update має значення true." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:261 sssd-ad.5.xml:1273 -msgid "dyndns_update_ptr (bool)" +#: sssd-ipa.5.xml:256 sssd-ad.5.xml:1266 +#, fuzzy +#| msgid "dyndns_update_ptr (bool)" +msgid "dyndns_update_ptr (boolean)" msgstr "dyndns_update_ptr (булеве значення)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:264 sssd-ad.5.xml:1276 +#: sssd-ipa.5.xml:259 sssd-ad.5.xml:1269 msgid "" "Whether the PTR record should also be explicitly updated when updating the " "client's DNS records. Applicable only when dyndns_update is true." @@ -12635,7 +13148,7 @@ msgstr "" "DNS клієнта. Застосовується, лише якщо значенням dyndns_update буде true." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:269 +#: sssd-ipa.5.xml:264 msgid "" "This option should be False in most IPA deployments as the IPA server " "generates the PTR records automatically when forward records are changed." @@ -12645,7 +13158,7 @@ msgstr "" "переспрямовування." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:275 sssd-ad.5.xml:1281 +#: sssd-ipa.5.xml:270 sssd-ad.5.xml:1274 msgid "" "Note that <emphasis>dyndns_update_per_family</emphasis> parameter does not " "apply for PTR record updates. Those updates are always sent separately." @@ -12655,17 +13168,19 @@ msgstr "" "окремо." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:280 +#: sssd-ipa.5.xml:275 msgid "Default: False (disabled)" msgstr "Типове значення: False (вимкнено)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:286 sssd-ad.5.xml:1292 -msgid "dyndns_force_tcp (bool)" +#: sssd-ipa.5.xml:281 sssd-ad.5.xml:1285 +#, fuzzy +#| msgid "dyndns_force_tcp (bool)" +msgid "dyndns_force_tcp (boolean)" msgstr "dyndns_force_tcp (булеве значення)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:289 sssd-ad.5.xml:1295 +#: sssd-ipa.5.xml:284 sssd-ad.5.xml:1288 msgid "" "Whether the nsupdate utility should default to using TCP for communicating " "with the DNS server." @@ -12674,17 +13189,17 @@ msgstr "" "даними з сервером DNS." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:293 sssd-ad.5.xml:1299 +#: sssd-ipa.5.xml:288 sssd-ad.5.xml:1292 msgid "Default: False (let nsupdate choose the protocol)" msgstr "Типове значення: False (надати змогу nsupdate вибирати протокол)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:299 sssd-ad.5.xml:1335 +#: sssd-ipa.5.xml:294 sssd-ad.5.xml:1328 msgid "dyndns_server (string)" msgstr "dyndns_server (рядок)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:302 sssd-ad.5.xml:1338 +#: sssd-ipa.5.xml:297 sssd-ad.5.xml:1331 msgid "" "The DNS server to use when performing a DNS update. In most setups, it's " "recommended to leave this option unset." @@ -12694,7 +13209,7 @@ msgstr "" "параметра." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:307 sssd-ad.5.xml:1343 +#: sssd-ipa.5.xml:302 sssd-ad.5.xml:1336 msgid "" "Setting this option makes sense for environments where the DNS server is " "different from the identity server or when we use encrypted DNS." @@ -12704,7 +13219,7 @@ msgstr "" "шифрований DNS." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:312 sssd-ad.5.xml:1348 +#: sssd-ipa.5.xml:307 sssd-ad.5.xml:1341 msgid "" "The parameter can be a simple string containing DNS name or IP address. It " "can also be an URI. The URI can look like <emphasis>dns://servername/</" @@ -12716,7 +13231,7 @@ msgstr "" "</emphasis>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:319 sssd-ad.5.xml:1355 +#: sssd-ipa.5.xml:314 sssd-ad.5.xml:1348 msgid "" "The second example enables DNS-over-TLS protocol for DNS updates. The " "nsupdate utility must support DoT - check the <emphasis>man nsupdate</" @@ -12727,7 +13242,7 @@ msgstr "" "man nsupdate</emphasis> перед її увімкненням у SSSD." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:325 sssd-ad.5.xml:1361 +#: sssd-ipa.5.xml:320 sssd-ad.5.xml:1354 msgid "" "Please note that this option will be only used in fallback attempt when " "previous attempt using autodetected settings failed or when DNS-over-TLS is " @@ -12738,17 +13253,17 @@ msgstr "" "невдало або якщо увімкнено DNS-через-TLS." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:331 sssd-ad.5.xml:1367 +#: sssd-ipa.5.xml:326 sssd-ad.5.xml:1360 msgid "Default: None (let nsupdate choose the server)" msgstr "Типове значення: немає (надати nsupdate змогу вибирати сервер)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:337 sssd-ad.5.xml:1373 +#: sssd-ipa.5.xml:332 sssd-ad.5.xml:1366 msgid "dyndns_update_per_family (boolean)" msgstr "dyndns_update_per_family (булеве значення)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:340 sssd-ad.5.xml:1376 +#: sssd-ipa.5.xml:335 sssd-ad.5.xml:1369 msgid "" "DNS update is by default performed in two steps - IPv4 update and then IPv6 " "update. In some cases it might be desirable to perform IPv4 and IPv6 update " @@ -12758,12 +13273,12 @@ msgstr "" "оновлення IPv6. Іноді бажаним є виконання оновлення IPv4 і IPv6 за один крок." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:352 sssd-ad.5.xml:1388 +#: sssd-ipa.5.xml:347 sssd-ad.5.xml:1381 msgid "dyndns_dot_cacert (string)" msgstr "dyndns_dot_cacert (рядок)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:355 sssd-ad.5.xml:1391 +#: sssd-ipa.5.xml:350 sssd-ad.5.xml:1384 msgid "" "This option specifies the file of the certificate authorities certificates " "(in PEM format) in order to verify the remote server TLS certificate when " @@ -12773,17 +13288,17 @@ msgstr "" "перевірки TLS-сертифіката віддаленого сервера при використанні DoT." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:361 sssd-ad.5.xml:1397 +#: sssd-ipa.5.xml:356 sssd-ad.5.xml:1390 msgid "Default: None (use global certificate store)" msgstr "Типове значення: немає (використовувати загальне сховище сертифікатів)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:367 sssd-ad.5.xml:1403 +#: sssd-ipa.5.xml:362 sssd-ad.5.xml:1396 msgid "dyndns_dot_cert (string)" msgstr "dyndns_dot_cert (рядок)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:370 sssd-ad.5.xml:1406 +#: sssd-ipa.5.xml:365 sssd-ad.5.xml:1399 msgid "" "This option sets the certificate(s) file for authentication for the DoT " "transport to the remote server. The certificate chain file is expected to be " @@ -12794,7 +13309,7 @@ msgstr "" "форматування PEM." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:376 sssd-ad.5.xml:1412 +#: sssd-ipa.5.xml:371 sssd-ad.5.xml:1405 msgid "" "The <emphasis>dyndns_dot_cert</emphasis> and <emphasis>dyndns_dot_key</" "emphasis> options must be both set to achieve mutual TLS authentication." @@ -12804,18 +13319,18 @@ msgstr "" "dyndns_dot_key</emphasis>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:381 sssd-ipa.5.xml:396 sssd-ad.5.xml:1417 sssd-ad.5.xml:1432 +#: sssd-ipa.5.xml:376 sssd-ipa.5.xml:391 sssd-ad.5.xml:1410 sssd-ad.5.xml:1425 msgid "Default: None (Do not use TLS authentication)" msgstr "" "Типове значення: немає (не використовувати розпізнавання за допомогою TLS)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:387 sssd-ad.5.xml:1423 +#: sssd-ipa.5.xml:382 sssd-ad.5.xml:1416 msgid "dyndns_dot_key (string)" msgstr "dyndns_dot_key (рядок)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:390 sssd-ad.5.xml:1426 +#: sssd-ipa.5.xml:385 sssd-ad.5.xml:1419 msgid "" "This option sets the key file for authenticated encryption for the DoT " "transport to the remote server. The private key file is expected to be in " @@ -12826,19 +13341,19 @@ msgstr "" "записано у форматі PEM." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:402 +#: sssd-ipa.5.xml:397 msgid "ipa_access_order (string)" msgstr "ipa_access_order (рядок)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:409 +#: sssd-ipa.5.xml:404 msgid "<emphasis>expire</emphasis>: use IPA's account expiration policy." msgstr "" "<emphasis>expire</emphasis>: використовувати правила строку дії облікового " "запису IPA." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:448 +#: sssd-ipa.5.xml:443 msgid "" "Please note that 'access_provider = ipa' must be set for this feature to " "work." @@ -12847,12 +13362,12 @@ msgstr "" "встановити «access_provider = ipa»." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:455 +#: sssd-ipa.5.xml:450 msgid "ipa_deskprofile_search_base (string)" msgstr "ipa_deskprofile_search_base (рядок)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:458 +#: sssd-ipa.5.xml:453 msgid "" "Optional. Use the given string as search base for Desktop Profile related " "objects." @@ -12861,110 +13376,110 @@ msgstr "" "профілями станції (Desktop Profile) об’єктів." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:462 sssd-ipa.5.xml:484 +#: sssd-ipa.5.xml:457 sssd-ipa.5.xml:479 msgid "Default: Use base DN" msgstr "Типове значення: використання базової назви домену" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:468 +#: sssd-ipa.5.xml:463 msgid "ipa_subid_ranges_search_base (string)" msgstr "ipa_subid_ranges_search_base (рядок)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:471 +#: sssd-ipa.5.xml:466 #, fuzzy #| msgid "Deprecated. Use ldap_host_search_base instead." msgid "Deprecated. Use ldap_subid_ranges_search_base instead." msgstr "Застарілий. Скористайтеся замість нього ldap_host_search_base." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:477 +#: sssd-ipa.5.xml:472 msgid "ipa_hbac_search_base (string)" msgstr "ipa_hbac_search_base (рядок)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:480 +#: sssd-ipa.5.xml:475 msgid "Optional. Use the given string as search base for HBAC related objects." msgstr "" "Необов’язковий. Використати вказаний рядок як основу пошуку пов’язаних з " "HBAC об’єктів." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:490 +#: sssd-ipa.5.xml:485 msgid "ipa_host_search_base (string)" msgstr "ipa_host_search_base (рядок)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:493 +#: sssd-ipa.5.xml:488 msgid "Deprecated. Use ldap_host_search_base instead." msgstr "Застарілий. Скористайтеся замість нього ldap_host_search_base." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:499 +#: sssd-ipa.5.xml:494 msgid "ipa_selinux_search_base (string)" msgstr "ipa_selinux_search_base (рядок)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:502 +#: sssd-ipa.5.xml:497 msgid "Optional. Use the given string as search base for SELinux user maps." msgstr "" "Необов’язковий. Використати вказаний рядок як основу пошуку карт " "користувачів SELinux." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:518 +#: sssd-ipa.5.xml:513 msgid "ipa_subdomains_search_base (string)" msgstr "ipa_subdomains_search_base (рядок)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:521 +#: sssd-ipa.5.xml:516 msgid "Optional. Use the given string as search base for trusted domains." msgstr "" "Необов’язковий. Використати вказаний рядок як основу пошуку надійних доменів." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:530 +#: sssd-ipa.5.xml:525 msgid "Default: the value of <emphasis>cn=trusts,%basedn</emphasis>" msgstr "Типове значення: значення <emphasis>cn=trusts,%basedn</emphasis>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:537 +#: sssd-ipa.5.xml:532 msgid "ipa_master_domain_search_base (string)" msgstr "ipa_master_domain_search_base (рядок)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:540 +#: sssd-ipa.5.xml:535 msgid "Optional. Use the given string as search base for master domain object." msgstr "" "Необов’язковий. Використати вказаний рядок як основу пошуку основного " "об’єкта домену." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:549 +#: sssd-ipa.5.xml:544 msgid "Default: the value of <emphasis>cn=ad,cn=etc,%basedn</emphasis>" msgstr "" "Типове значення: значення виразу <emphasis>cn=ad,cn=etc,%basedn</emphasis>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:556 +#: sssd-ipa.5.xml:551 msgid "ipa_views_search_base (string)" msgstr "ipa_views_search_base (рядок)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:559 +#: sssd-ipa.5.xml:554 msgid "Optional. Use the given string as search base for views containers." msgstr "" "Необов’язковий. Використати вказаний рядок як основу пошуку контейнерів " "перегляду." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:568 +#: sssd-ipa.5.xml:563 msgid "Default: the value of <emphasis>cn=views,cn=accounts,%basedn</emphasis>" msgstr "" "Типове значення: значення <emphasis>cn=views,cn=accounts,%basedn</emphasis>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:578 +#: sssd-ipa.5.xml:573 msgid "" "The name of the Kerberos realm. This is optional and defaults to the value " "of <quote>ipa_domain</quote>." @@ -12973,7 +13488,7 @@ msgstr "" "ipa_domain»." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:582 +#: sssd-ipa.5.xml:577 msgid "" "The name of the Kerberos realm has a special meaning in IPA - it is " "converted into the base DN to use for performing LDAP operations." @@ -12982,12 +13497,12 @@ msgstr "" "перетворено у основний DN для виконання дій LDAP." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:590 sssd-ad.5.xml:1441 +#: sssd-ipa.5.xml:585 sssd-ad.5.xml:1434 msgid "krb5_confd_path (string)" msgstr "krb5_confd_path (рядок)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:593 sssd-ad.5.xml:1444 +#: sssd-ipa.5.xml:588 sssd-ad.5.xml:1437 msgid "" "Absolute path of a directory where SSSD should place Kerberos configuration " "snippets." @@ -12996,7 +13511,7 @@ msgstr "" "налаштувань Kerberos." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:597 sssd-ad.5.xml:1448 +#: sssd-ipa.5.xml:592 sssd-ad.5.xml:1441 msgid "" "To disable the creation of the configuration snippets set the parameter to " "'none'." @@ -13005,7 +13520,7 @@ msgstr "" "значення «none»." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:601 sssd-ad.5.xml:1452 +#: sssd-ipa.5.xml:596 sssd-ad.5.xml:1445 msgid "" "Default: not set (krb5.include.d subdirectory of SSSD's pubconf directory)" msgstr "" @@ -13013,12 +13528,12 @@ msgstr "" "SSSD)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:608 +#: sssd-ipa.5.xml:603 msgid "ipa_deskprofile_refresh (integer)" msgstr "ipa_deskprofile_refresh (ціле число)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:611 +#: sssd-ipa.5.xml:606 msgid "" "The amount of time between lookups of the Desktop Profile rules against the " "IPA server. This will reduce the latency and load on the IPA server if there " @@ -13030,17 +13545,17 @@ msgstr "" "щодо профілів станції." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:618 sssd-ipa.5.xml:648 sssd-ipa.5.xml:664 sssd-ad.5.xml:600 +#: sssd-ipa.5.xml:613 sssd-ipa.5.xml:643 sssd-ipa.5.xml:659 sssd-ad.5.xml:600 msgid "Default: 5 (seconds)" msgstr "Типове значення: 5 (секунд)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:624 +#: sssd-ipa.5.xml:619 msgid "ipa_deskprofile_request_interval (integer)" msgstr "ipa_deskprofile_request_interval (ціле число)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:627 +#: sssd-ipa.5.xml:622 msgid "" "The amount of time between lookups of the Desktop Profile rules against the " "IPA server in case the last request did not return any rule." @@ -13049,17 +13564,17 @@ msgstr "" "останнім запитом не повернуто жодного правила." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:632 +#: sssd-ipa.5.xml:627 msgid "Default: 60 (minutes)" msgstr "Типове значення: 60 (хвилин)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:638 +#: sssd-ipa.5.xml:633 msgid "ipa_hbac_refresh (integer)" msgstr "ipa_hbac_refresh (ціле число)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:641 +#: sssd-ipa.5.xml:636 msgid "" "The amount of time between lookups of the HBAC rules against the IPA server. " "This will reduce the latency and load on the IPA server if there are many " @@ -13070,12 +13585,14 @@ msgstr "" "короткого періоду часу надходить багато запитів щодо керування доступом." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:654 -msgid "ipa_hbac_selinux (integer)" -msgstr "ipa_hbac_selinux (ціле число)" +#: sssd-ipa.5.xml:649 +#, fuzzy +#| msgid "ipa_hbac_refresh (integer)" +msgid "ipa_selinux_refresh (integer)" +msgstr "ipa_hbac_refresh (ціле число)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:657 +#: sssd-ipa.5.xml:652 msgid "" "The amount of time between lookups of the SELinux maps against the IPA " "server. This will reduce the latency and load on the IPA server if there are " @@ -13087,12 +13604,12 @@ msgstr "" "користувача до системи." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:670 +#: sssd-ipa.5.xml:665 msgid "ipa_server_mode (boolean)" msgstr "ipa_server_mode (булеве значення)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:673 +#: sssd-ipa.5.xml:668 msgid "" "This option will be set by the IPA installer (ipa-server-install) " "automatically and denotes if SSSD is running on an IPA server or not." @@ -13101,7 +13618,7 @@ msgstr "" "автоматично, він визначає, чи запущено SSSD на сервері IPA." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:678 +#: sssd-ipa.5.xml:673 msgid "" "On an IPA server SSSD will lookup users and groups from trusted domains " "directly while on a client it will ask an IPA server." @@ -13110,7 +13627,7 @@ msgstr "" "безпосередньо, хоча на клієнті SSSD надсилатиме запит на сервер IPA." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:683 +#: sssd-ipa.5.xml:678 msgid "" "NOTE: There are currently some assumptions that must be met when SSSD is " "running on an IPA server." @@ -13119,7 +13636,7 @@ msgstr "" "працює на сервері IPA." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:688 +#: sssd-ipa.5.xml:683 msgid "" "The <quote>ipa_server</quote> option must be configured to point to the IPA " "server itself. This is already the default set by the IPA installer, so no " @@ -13130,7 +13647,7 @@ msgstr "" "зміни вручну є зайвими." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:697 +#: sssd-ipa.5.xml:692 msgid "" "The <quote>full_name_format</quote> option must not be tweaked to only print " "short names for users from trusted domains." @@ -13139,53 +13656,53 @@ msgstr "" "того, щоб лише виводити короткі імена користувачів з довірених доменів." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:712 +#: sssd-ipa.5.xml:707 msgid "ipa_automount_location (string)" msgstr "ipa_automount_location (рядок)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:715 +#: sssd-ipa.5.xml:710 msgid "The automounter location this IPA client will be using" msgstr "" "Адреса автоматичного монтування, яку буде використовувати цей клієнт IPA" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:718 +#: sssd-ipa.5.xml:713 msgid "Default: The location named \"default\"" msgstr "Типове значення: адреса з назвою \"default\"" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd-ipa.5.xml:726 +#: sssd-ipa.5.xml:721 msgid "VIEWS AND OVERRIDES" msgstr "ПЕРЕГЛЯДИ і ПЕРЕВИЗНАЧЕННЯ" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:735 +#: sssd-ipa.5.xml:730 msgid "ipa_view_class (string)" msgstr "ipa_view_class (рядок)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:738 +#: sssd-ipa.5.xml:733 msgid "Objectclass of the view container." msgstr "Клас об’єктів для контейнерів перегляду." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:741 +#: sssd-ipa.5.xml:736 msgid "Default: nsContainer" msgstr "Типове значення: nsContainer" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:747 +#: sssd-ipa.5.xml:742 msgid "ipa_view_name (string)" msgstr "ipa_view_name (рядок)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:750 +#: sssd-ipa.5.xml:745 msgid "Name of the attribute holding the name of the view." msgstr "Назва атрибута, у якому зберігається назва перегляду." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:754 sssd-ldap-attributes.5.xml:496 +#: sssd-ipa.5.xml:749 sssd-ldap-attributes.5.xml:496 #: sssd-ldap-attributes.5.xml:832 sssd-ldap-attributes.5.xml:913 #: sssd-ldap-attributes.5.xml:1010 sssd-ldap-attributes.5.xml:1068 #: sssd-ldap-attributes.5.xml:1226 sssd-ldap-attributes.5.xml:1271 @@ -13193,27 +13710,27 @@ msgid "Default: cn" msgstr "Типове значення: cn" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:760 +#: sssd-ipa.5.xml:755 msgid "ipa_override_object_class (string)" msgstr "ipa_override_object_class (рядок)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:763 +#: sssd-ipa.5.xml:758 msgid "Objectclass of the override objects." msgstr "Клас об’єктів для об’єктів перевизначення" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:766 +#: sssd-ipa.5.xml:761 msgid "Default: ipaOverrideAnchor" msgstr "Типове значення: ipaOverrideAnchor" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:772 +#: sssd-ipa.5.xml:767 msgid "ipa_anchor_uuid (string)" msgstr "ipa_anchor_uuid (рядок)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:775 +#: sssd-ipa.5.xml:770 msgid "" "Name of the attribute containing the reference to the original object in a " "remote domain." @@ -13222,17 +13739,17 @@ msgstr "" "віддаленому домені." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:779 +#: sssd-ipa.5.xml:774 msgid "Default: ipaAnchorUUID" msgstr "Типове значення: ipaAnchorUUID" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:785 +#: sssd-ipa.5.xml:780 msgid "ipa_user_override_object_class (string)" msgstr "ipa_user_override_object_class (рядок)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:788 +#: sssd-ipa.5.xml:783 msgid "" "Name of the objectclass for user overrides. It is used to determine if the " "found override object is related to a user or a group." @@ -13242,57 +13759,57 @@ msgstr "" "або групою." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:793 +#: sssd-ipa.5.xml:788 msgid "User overrides can contain attributes given by" msgstr "Перевизначення користувачів можуть містити атрибути, задані" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:796 +#: sssd-ipa.5.xml:791 msgid "ldap_user_name" msgstr "ldap_user_name" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:799 +#: sssd-ipa.5.xml:794 msgid "ldap_user_uid_number" msgstr "ldap_user_uid_number" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:802 +#: sssd-ipa.5.xml:797 msgid "ldap_user_gid_number" msgstr "ldap_user_gid_number" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:805 +#: sssd-ipa.5.xml:800 msgid "ldap_user_gecos" msgstr "ldap_user_gecos" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:808 +#: sssd-ipa.5.xml:803 msgid "ldap_user_home_directory" msgstr "ldap_user_home_directory" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:811 +#: sssd-ipa.5.xml:806 msgid "ldap_user_shell" msgstr "ldap_user_shell" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:814 +#: sssd-ipa.5.xml:809 msgid "ldap_user_ssh_public_key" msgstr "ldap_user_ssh_public_key" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:819 +#: sssd-ipa.5.xml:814 msgid "Default: ipaUserOverride" msgstr "Типове значення: ipaUserOverride" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:825 +#: sssd-ipa.5.xml:820 msgid "ipa_group_override_object_class (string)" msgstr "ipa_group_override_object_class (рядок)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:828 +#: sssd-ipa.5.xml:823 msgid "" "Name of the objectclass for group overrides. It is used to determine if the " "found override object is related to a user or a group." @@ -13301,27 +13818,27 @@ msgstr "" "того, чи знайдений об’єкт перевизначення пов’язано з користувачем або групою." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:833 +#: sssd-ipa.5.xml:828 msgid "Group overrides can contain attributes given by" msgstr "Перевизначення груп можуть містити атрибути, задані" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:836 +#: sssd-ipa.5.xml:831 msgid "ldap_group_name" msgstr "ldap_group_name" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:839 +#: sssd-ipa.5.xml:834 msgid "ldap_group_gid_number" msgstr "ldap_group_gid_number" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:844 +#: sssd-ipa.5.xml:839 msgid "Default: ipaGroupOverride" msgstr "Типове значення: ipaGroupOverride" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:728 +#: sssd-ipa.5.xml:723 msgid "" "SSSD can handle views and overrides which are offered by FreeIPA 4.1 and " "later version. Since all paths and objectclasses are fixed on the server " @@ -13336,12 +13853,12 @@ msgstr "" "значеннями. <placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd-ipa.5.xml:856 +#: sssd-ipa.5.xml:851 msgid "SUBDOMAINS PROVIDER" msgstr "СЛУЖБА ПІДДОМЕНІВ" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:858 +#: sssd-ipa.5.xml:853 msgid "" "The IPA subdomains provider behaves slightly differently if it is configured " "explicitly or implicitly." @@ -13350,7 +13867,7 @@ msgstr "" "спосіб його налаштовано: явний чи неявний." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:862 +#: sssd-ipa.5.xml:857 msgid "" "If the option 'subdomains_provider = ipa' is found in the domain section of " "sssd.conf, the IPA subdomains provider is configured explicitly, and all " @@ -13362,7 +13879,7 @@ msgstr "" "якщо це потрібно." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:868 +#: sssd-ipa.5.xml:863 msgid "" "If the option 'subdomains_provider' is not set in the domain section of " "sssd.conf but there is the option 'id_provider = ipa', the IPA subdomains " @@ -13382,12 +13899,12 @@ msgstr "" "знову увімкнено." #. type: Content of: <reference><refentry><refsect1><title> -#: sssd-ipa.5.xml:879 +#: sssd-ipa.5.xml:874 msgid "TRUSTED DOMAINS CONFIGURATION" msgstr "НАЛАШТОВУВАННЯ ДОВІРЕНИХ ДОМЕНІВ" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-ipa.5.xml:887 +#: sssd-ipa.5.xml:882 #, no-wrap msgid "" "[domain/ipa.domain.com/ad.domain.com]\n" @@ -13397,7 +13914,7 @@ msgstr "" "ad_server = dc.ad.domain.com\n" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:881 +#: sssd-ipa.5.xml:876 msgid "" "Some configuration options can also be set for a trusted domain. A trusted " "domain configuration can be set using the trusted domain subsection as shown " @@ -13412,7 +13929,7 @@ msgstr "" "батьківському домені. <placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:892 +#: sssd-ipa.5.xml:887 msgid "" "For more details, see the <citerefentry> <refentrytitle>sssd.conf</" "refentrytitle> <manvolnum>5</manvolnum> </citerefentry> manual page." @@ -13422,7 +13939,7 @@ msgstr "" "manvolnum> </citerefentry>." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:899 +#: sssd-ipa.5.xml:894 msgid "" "Different configuration options are tunable for a trusted domain depending " "on whether you are configuring SSSD on an IPA server or an IPA client." @@ -13431,59 +13948,59 @@ msgstr "" "як ви налаштували SSSD на сервері IPA або клієнт IPA." #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd-ipa.5.xml:904 +#: sssd-ipa.5.xml:899 msgid "OPTIONS TUNABLE ON IPA MASTERS" msgstr "ПАРАМЕТРИ, ЯКІ МОЖНА НАЛАШТУВАТИ НА ОСНОВНИХ СЕРВЕРАХ IPA" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:906 +#: sssd-ipa.5.xml:901 msgid "" "The following options can be set in a subdomain section on an IPA master:" msgstr "" "У розділі піддомену на основному сервері IPA можна вказати такі параметри:" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:910 sssd-ipa.5.xml:950 +#: sssd-ipa.5.xml:905 sssd-ipa.5.xml:945 msgid "ad_server" msgstr "ad_server" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:913 +#: sssd-ipa.5.xml:908 msgid "ad_backup_server" msgstr "ad_backup_server" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:916 sssd-ipa.5.xml:953 +#: sssd-ipa.5.xml:911 sssd-ipa.5.xml:948 msgid "ad_site" msgstr "ad_site" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:919 +#: sssd-ipa.5.xml:914 msgid "ipa_server" msgstr "ipa_server" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:922 +#: sssd-ipa.5.xml:917 msgid "ipa_backup_server" msgstr "ipa_backup_server" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:925 +#: sssd-ipa.5.xml:920 msgid "ldap_search_base" msgstr "ldap_search_base" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:928 +#: sssd-ipa.5.xml:923 msgid "ldap_user_search_base" msgstr "ldap_user_search_base" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:931 +#: sssd-ipa.5.xml:926 msgid "ldap_group_search_base" msgstr "ldap_group_search_base" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:939 +#: sssd-ipa.5.xml:934 msgid "" "Options prefixed with 'ad_' or 'ipa_' only apply to their respective " "subdomain type." @@ -13492,18 +14009,18 @@ msgstr "" "типу піддоменів." #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd-ipa.5.xml:944 +#: sssd-ipa.5.xml:939 msgid "OPTIONS TUNABLE ON IPA CLIENTS" msgstr "ПАРАМЕТРИ, ЯКІ МОЖНА НАЛАШТУВАТИ НА КЛІЄНТАХ IPA" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:946 +#: sssd-ipa.5.xml:941 msgid "" "The following options can be set in an AD subdomain section on an IPA client:" msgstr "У розділі піддомену AD на клієнті IPA можна вказати такі параметри:" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:958 +#: sssd-ipa.5.xml:953 msgid "" "Note that if both options are set, only <quote>ad_server</quote> is " "evaluated." @@ -13512,7 +14029,7 @@ msgstr "" "ad_server</quote>." #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:962 +#: sssd-ipa.5.xml:957 msgid "" "Since any request for a user or a group identity from a trusted domain " "triggered from an IPA client is resolved by the IPA server, the " @@ -13535,7 +14052,7 @@ msgstr "" "manvolnum> </citerefentry>, щоб дізнатися більше про додаток пошуку Kerberos." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:986 +#: sssd-ipa.5.xml:981 msgid "" "The following example assumes that SSSD is correctly configured and " "example.com is one of the domains in the <replaceable>[sssd]</replaceable> " @@ -13547,7 +14064,7 @@ msgstr "" "ipa." #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-ipa.5.xml:993 +#: sssd-ipa.5.xml:988 #, no-wrap msgid "" "[domain/example.com]\n" @@ -14518,27 +15035,27 @@ msgid "lxdm" msgstr "lxdm" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:694 +#: sssd-ad.5.xml:699 msgid "sddm" msgstr "sddm" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:699 +#: sssd-ad.5.xml:704 msgid "unity" msgstr "unity" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:704 +#: sssd-ad.5.xml:709 msgid "xdm" msgstr "xdm" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:713 +#: sssd-ad.5.xml:718 msgid "ad_gpo_map_remote_interactive (string)" msgstr "ad_gpo_map_remote_interactive (рядок)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:716 +#: sssd-ad.5.xml:721 msgid "" "A comma-separated list of PAM service names for which GPO-based access " "control is evaluated based on the RemoteInteractiveLogonRight and " @@ -14567,7 +15084,7 @@ msgstr "" "одна з його груп є частиною параметрів правила." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:735 +#: sssd-ad.5.xml:740 msgid "" "Note: Using the Group Policy Management Editor this value is called \"Allow " "log on through Remote Desktop Services\" and \"Deny log on through Remote " @@ -14579,7 +15096,7 @@ msgstr "" "служб віддаленої стільниці» («Deny log on through Remote Desktop Services»)." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:750 +#: sssd-ad.5.xml:755 #, no-wrap msgid "" "ad_gpo_map_remote_interactive = +my_pam_service, -sshd\n" @@ -14589,7 +15106,7 @@ msgstr "" " " #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:741 +#: sssd-ad.5.xml:746 msgid "" "It is possible to add another PAM service name to the default set by using " "<quote>+service_name</quote> or to explicitly remove a PAM service name from " @@ -14608,22 +15125,22 @@ msgstr "" "id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:758 +#: sssd-ad.5.xml:763 msgid "sshd" msgstr "sshd" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:763 +#: sssd-ad.5.xml:768 msgid "cockpit" msgstr "cockpit" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:772 +#: sssd-ad.5.xml:777 msgid "ad_gpo_map_network (string)" msgstr "ad_gpo_map_network (рядок)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:775 +#: sssd-ad.5.xml:780 msgid "" "A comma-separated list of PAM service names for which GPO-based access " "control is evaluated based on the NetworkLogonRight and " @@ -14652,7 +15169,7 @@ msgstr "" "правила." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:793 +#: sssd-ad.5.xml:798 msgid "" "Note: Using the Group Policy Management Editor this value is called \"Access " "this computer from the network\" and \"Deny access to this computer from the " @@ -14664,7 +15181,7 @@ msgstr "" "мережі» (Deny access to this computer from the network»)." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:808 +#: sssd-ad.5.xml:813 #, no-wrap msgid "" "ad_gpo_map_network = +my_pam_service, -ftp\n" @@ -14674,7 +15191,7 @@ msgstr "" " " #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:799 +#: sssd-ad.5.xml:804 msgid "" "It is possible to add another PAM service name to the default set by using " "<quote>+service_name</quote> or to explicitly remove a PAM service name from " @@ -14693,22 +15210,22 @@ msgstr "" "id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:816 +#: sssd-ad.5.xml:821 msgid "ftp" msgstr "ftp" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:821 +#: sssd-ad.5.xml:826 msgid "samba" msgstr "samba" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:830 +#: sssd-ad.5.xml:835 msgid "ad_gpo_map_batch (string)" msgstr "ad_gpo_map_batch (рядок)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:833 +#: sssd-ad.5.xml:838 msgid "" "A comma-separated list of PAM service names for which GPO-based access " "control is evaluated based on the BatchLogonRight and DenyBatchLogonRight " @@ -14736,7 +15253,7 @@ msgstr "" "правила." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:851 +#: sssd-ad.5.xml:856 msgid "" "Note: Using the Group Policy Management Editor this value is called \"Allow " "log on as a batch job\" and \"Deny log on as a batch job\"." @@ -14746,7 +15263,7 @@ msgstr "" "job») і «Заборонити вхід як пакетне завдання» («Deny log on as a batch job»)." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:865 +#: sssd-ad.5.xml:870 #, no-wrap msgid "" "ad_gpo_map_batch = +my_pam_service, -crond\n" @@ -14756,7 +15273,7 @@ msgstr "" " " #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:856 +#: sssd-ad.5.xml:861 msgid "" "It is possible to add another PAM service name to the default set by using " "<quote>+service_name</quote> or to explicitly remove a PAM service name from " @@ -14775,24 +15292,24 @@ msgstr "" "id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:868 +#: sssd-ad.5.xml:873 msgid "" "Note: Cron service name may differ depending on Linux distribution used." msgstr "" "Зауваження: назва служби cron у різних дистрибутивах Linux може бути різною." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:874 +#: sssd-ad.5.xml:879 msgid "crond" msgstr "crond" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:883 +#: sssd-ad.5.xml:888 msgid "ad_gpo_map_service (string)" msgstr "ad_gpo_map_service (рядок)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:886 +#: sssd-ad.5.xml:891 msgid "" "A comma-separated list of PAM service names for which GPO-based access " "control is evaluated based on the ServiceLogonRight and " @@ -14821,7 +15338,7 @@ msgstr "" "принаймні одна з його груп є частиною параметрів правила." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:904 +#: sssd-ad.5.xml:909 msgid "" "Note: Using the Group Policy Management Editor this value is called \"Allow " "log on as a service\" and \"Deny log on as a service\"." @@ -14831,7 +15348,7 @@ msgstr "" "Заборонити вхід як службу» («Deny log on as a service»)." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:917 +#: sssd-ad.5.xml:922 #, no-wrap msgid "" "ad_gpo_map_service = +my_pam_service\n" @@ -14841,7 +15358,7 @@ msgstr "" " " #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:909 sssd-ad.5.xml:984 +#: sssd-ad.5.xml:914 sssd-ad.5.xml:989 msgid "" "It is possible to add a PAM service name to the default set by using " "<quote>+service_name</quote>. Since the default set is empty, it is not " @@ -14858,12 +15375,12 @@ msgstr "" "id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:927 +#: sssd-ad.5.xml:932 msgid "ad_gpo_map_permit (string)" msgstr "ad_gpo_map_permit (рядок)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:930 +#: sssd-ad.5.xml:935 msgid "" "A comma-separated list of PAM service names for which GPO-based access is " "always granted, regardless of any GPO Logon Rights." @@ -14872,7 +15389,7 @@ msgstr "" "основі GPO, незалежно від будь-яких прав входу GPO." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:944 +#: sssd-ad.5.xml:949 #, no-wrap msgid "" "ad_gpo_map_permit = +my_pam_service, -sudo\n" @@ -14882,7 +15399,7 @@ msgstr "" " " #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:935 +#: sssd-ad.5.xml:940 msgid "" "It is possible to add another PAM service name to the default set by using " "<quote>+service_name</quote> or to explicitly remove a PAM service name from " @@ -14901,22 +15418,22 @@ msgstr "" "type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:952 +#: sssd-ad.5.xml:957 msgid "polkit-1" msgstr "polkit-1" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:967 +#: sssd-ad.5.xml:972 msgid "systemd-user" msgstr "systemd-user" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:976 +#: sssd-ad.5.xml:981 msgid "ad_gpo_map_deny (string)" msgstr "ad_gpo_map_deny (рядок)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:979 +#: sssd-ad.5.xml:984 msgid "" "A comma-separated list of PAM service names for which GPO-based access is " "always denied, regardless of any GPO Logon Rights." @@ -14925,7 +15442,7 @@ msgstr "" "на основі GPO, незалежно від будь-яких прав входу GPO." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:992 +#: sssd-ad.5.xml:997 #, no-wrap msgid "" "ad_gpo_map_deny = +my_pam_service\n" @@ -14935,12 +15452,12 @@ msgstr "" " " #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:1002 +#: sssd-ad.5.xml:1007 msgid "ad_gpo_default_right (string)" msgstr "ad_gpo_default_right (рядок)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1005 +#: sssd-ad.5.xml:1010 msgid "" "This option defines how access control is evaluated for PAM service names " "that are not explicitly listed in one of the ad_gpo_map_* options. This " @@ -14962,52 +15479,52 @@ msgstr "" "забороняла доступ для непов’язаних назв служб PAM." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1018 +#: sssd-ad.5.xml:1023 msgid "Supported values for this option include:" msgstr "Передбачені значення для цього параметра:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1027 +#: sssd-ad.5.xml:1032 msgid "remote_interactive" msgstr "remote_interactive" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1032 +#: sssd-ad.5.xml:1037 msgid "network" msgstr "network" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1037 +#: sssd-ad.5.xml:1042 msgid "batch" msgstr "batch" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1042 +#: sssd-ad.5.xml:1047 msgid "service" msgstr "service" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1047 +#: sssd-ad.5.xml:1052 msgid "permit" msgstr "permit" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1052 +#: sssd-ad.5.xml:1057 msgid "deny" msgstr "deny" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1058 +#: sssd-ad.5.xml:1063 msgid "Default: deny" msgstr "Типове значення: deny" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:1064 +#: sssd-ad.5.xml:1069 msgid "ad_maximum_machine_account_password_age (integer)" msgstr "ad_maximum_machine_account_password_age (ціле число)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1067 +#: sssd-ad.5.xml:1072 msgid "" "SSSD will check once a day if the machine account password is older than the " "given age in days and try to renew it. A value of 0 will disable the renewal " @@ -15018,17 +15535,17 @@ msgstr "" "Значення 0 вимкне спроби оновлення." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1073 +#: sssd-ad.5.xml:1078 msgid "Default: 30 days" msgstr "Типове значення: 30 днів" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:1079 +#: sssd-ad.5.xml:1084 msgid "ad_machine_account_password_renewal_opts (string)" msgstr "ad_machine_account_password_renewal_opts (рядок)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1082 +#: sssd-ad.5.xml:1087 msgid "" "This option should only be used to test the machine account renewal task. " "The option expects 3 integers and a string separated by a colon (':'). The " @@ -15050,16 +15567,26 @@ msgstr "" "значенні, буде використано рядок '0'." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1096 +#: sssd-ad.5.xml:1101 +#, fuzzy +#| msgid "" +#| "The optional fourth string value identifies the helper binary which " +#| "should be used for the renewal. Currently <command>adcli</command> and " +#| "<command>realm</command> are supported. If this value is missing or empty " +#| "in the value string <command>realm</command> will be used. Since the " +#| "helper is started as the user SSSD is running as there might be the " +#| "chance that the renewal will fail if this user does not has permissions " +#| "to modify the keytab file where the machine account credentials are " +#| "stored. This will typically be the case for <command>adcli</command>." msgid "" "The optional fourth string value identifies the helper binary which should " "be used for the renewal. Currently <command>adcli</command> and " "<command>realm</command> are supported. If this value is missing or empty in " "the value string <command>realm</command> will be used. Since the helper is " "started as the user SSSD is running as there might be the chance that the " -"renewal will fail if this user does not has permissions to modify the keytab " -"file where the machine account credentials are stored. This will typically " -"be the case for <command>adcli</command>." +"renewal will fail if this user does not have permissions to modify the " +"keytab file where the machine account credentials are stored. This will " +"typically be the case for <command>adcli</command>." msgstr "" "Значення необов'язкового четвертого рядка визначає допоміжний двійковий " "файл, який слід використовувати для оновлення. Наразі передбачено підтримку " @@ -15068,11 +15595,11 @@ msgstr "" "Оскільки допоміжний файл запущено від імені користувача, SSSD працює, " "оскільки існує ймовірність того, що оновлення завершиться невдало, якщо цей " "користувач не має дозволів на зміну файла keytab, де зберігаються " -"реєстраційні дані облікового запису машини. Зазвичай це стосується <command>" -"adcli</command>." +"реєстраційні дані облікового запису машини. Зазвичай це стосується " +"<command>adcli</command>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1110 +#: sssd-ad.5.xml:1115 msgid "" "<command>realm</command> is not updating the keytab directly but is calling " "the <command>realmd</command> process, which runs as root user, for this " @@ -15087,19 +15614,19 @@ msgstr "" "відповідні правила для користувача, від імені якого працює SSSD." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1119 +#: sssd-ad.5.xml:1124 msgid "Default: 86400:750:300:realm (24h, 12m30s and 5m)" msgstr "" "Типове значення: 86400:750:300:realm (24 години, 12 хвилин 30 секунд і 5 " "хвилин)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:1125 +#: sssd-ad.5.xml:1130 msgid "ad_update_samba_machine_account_password (boolean)" msgstr "ad_update_samba_machine_account_password (булеве значення)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1128 +#: sssd-ad.5.xml:1133 msgid "" "If enabled, when SSSD renews the machine account password, it will also be " "updated in Samba's database. This prevents Samba's copy of the machine " @@ -15112,16 +15639,26 @@ msgstr "" "налаштовано на використання AD для розпізнавання." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:1141 -msgid "ad_use_ldaps (bool)" +#: sssd-ad.5.xml:1146 +#, fuzzy +#| msgid "ad_use_ldaps (bool)" +msgid "ad_use_ldaps (boolean)" msgstr "ad_use_ldaps (булеве значення)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1144 +#: sssd-ad.5.xml:1149 +#, fuzzy +#| msgid "" +#| "By default SSSD uses the plain LDAP port 389 and the Global Catalog port " +#| "3628. If this option is set to True SSSD will use the LDAPS port 636 and " +#| "Global Catalog port 3629 with LDAPS protection. Since AD does not allow " +#| "to have multiple encryption layers on a single connection and we still " +#| "want to use SASL/GSSAPI or SASL/GSS-SPNEGO for authentication the SASL " +#| "security property maxssf is set to 0 (zero) for those connections." msgid "" "By default SSSD uses the plain LDAP port 389 and the Global Catalog port " -"3628. If this option is set to True SSSD will use the LDAPS port 636 and " -"Global Catalog port 3629 with LDAPS protection. Since AD does not allow to " +"3268. If this option is set to True SSSD will use the LDAPS port 636 and " +"Global Catalog port 3269 with LDAPS protection. Since AD does not allow to " "have multiple encryption layers on a single connection and we still want to " "use SASL/GSSAPI or SASL/GSS-SPNEGO for authentication the SASL security " "property maxssf is set to 0 (zero) for those connections." @@ -15135,7 +15672,7 @@ msgstr "" "з'єднань буде встановлено у значення 0 (нуль)." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1164 +#: sssd-ad.5.xml:1169 msgid "" "Optional. This option tells SSSD to automatically update the Active " "Directory DNS server with the IP address of this client. The update is " @@ -15159,17 +15696,6 @@ msgstr "Типове значення: 3600 (секунд)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:1216 msgid "" -"NOTE: While it is still possible to use the old <emphasis>ipa_dyndns_iface</" -"emphasis> option, users should migrate to using <emphasis>dyndns_iface</" -"emphasis> in their config file." -msgstr "" -"ЗАУВАЖЕННЯ: хоча можна використовувати і попередню назву параметра, " -"<emphasis>ipa_dyndns_iface</emphasis>, користувачам слід переходити на нову " -"назву, <emphasis>dyndns_iface</emphasis>, у файлі налаштувань." - -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1222 -msgid "" "Default: Use the IP addresses of the interface which is used for AD LDAP " "connection" msgstr "" @@ -15177,13 +15703,19 @@ msgstr "" "для з’єднання LDAP AD" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1258 +#: sssd-ad.5.xml:1252 +#, fuzzy +#| msgid "" +#| "How often should the back end perform periodic DNS update in addition to " +#| "the automatic update performed when the back end goes online. This " +#| "option is optional and applicable only when dyndns_update is true. Note " +#| "that the lowest possible value is 60 seconds in-case if value is provided " +#| "less than 60, parameter will assume lowest value only." msgid "" "How often should the back end perform periodic DNS update in addition to the " -"automatic update performed when the back end goes online. This option is " -"optional and applicable only when dyndns_update is true. Note that the " -"lowest possible value is 60 seconds in-case if value is provided less than " -"60, parameter will assume lowest value only." +"automatic update performed when the back end goes online. This is optional " +"and applicable only when dyndns_update is true. Note that the minimum value " +"is 60 seconds, any specified value below this threshold will default to 60." msgstr "" "Визначає, наскільки часто серверний модуль має виконувати періодичні " "оновлення DNS на додачу до автоматичного оновлення, яке виконується під час " @@ -15194,7 +15726,7 @@ msgstr "" "значення." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ad.5.xml:1472 +#: sssd-ad.5.xml:1465 msgid "" "The following example assumes that SSSD is correctly configured and " "example.com is one of the domains in the <replaceable>[sssd]</replaceable> " @@ -15205,7 +15737,7 @@ msgstr "" "У прикладі продемонстровано лише параметри доступу, специфічні для засобу AD." #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-ad.5.xml:1479 +#: sssd-ad.5.xml:1472 #, no-wrap msgid "" "[domain/EXAMPLE]\n" @@ -15229,7 +15761,7 @@ msgstr "" "ad_domain = example.com\n" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-ad.5.xml:1499 +#: sssd-ad.5.xml:1492 #, no-wrap msgid "" "access_provider = ldap\n" @@ -15241,7 +15773,7 @@ msgstr "" "ldap_account_expire_policy = ad\n" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ad.5.xml:1495 +#: sssd-ad.5.xml:1488 msgid "" "The AD access control provider checks if the account is expired. It has the " "same effect as the following configuration of the LDAP provider: " @@ -15253,7 +15785,7 @@ msgstr "" "id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ad.5.xml:1505 +#: sssd-ad.5.xml:1498 msgid "" "However, unless the <quote>ad</quote> access control provider is explicitly " "configured, the default access provider is <quote>permit</quote>. Please " @@ -15268,7 +15800,7 @@ msgstr "" "шифрування) вручну." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ad.5.xml:1513 +#: sssd-ad.5.xml:1506 msgid "" "When the autofs provider is set to <quote>ad</quote>, the RFC2307 schema " "attribute mapping (nisMap, nisObject, ...) is used, because these attributes " @@ -15482,11 +16014,17 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-sudo.5.xml:137 +#, fuzzy +#| msgid "" +#| "The <emphasis>smart refresh</emphasis> periodically downloads rules that " +#| "are new or were modified after the last update. Its primary goal is to " +#| "keep the database growing by fetching only small increments that do not " +#| "generate large amounts of network traffic." msgid "" "The <emphasis>smart refresh</emphasis> periodically downloads rules that are " -"new or were modified after the last update. Its primary goal is to keep the " -"database growing by fetching only small increments that do not generate " -"large amounts of network traffic." +"new or were modified after the last update. Its primary goal is to grow the " +"database incrementally by fetching only small updates, avoiding large " +"amounts of network traffic." msgstr "" "Використання типу <emphasis>інтелектуального оновлення</emphasis> полягає у " "отриманні правил, які було додано або змінено з часу попереднього оновлення. " @@ -15735,11 +16273,20 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-idp.5.xml:70 +#, fuzzy +#| msgid "" +#| "Depending on the IdP product additional platform specific options might " +#| "follow the name separated by a colon (:). E.g. for Keycloak the base URI " +#| "for the user and group REST API must be given. For Entra ID this is not " +#| "needed because there is a generic endpoint for all tenants." msgid "" "Depending on the IdP product additional platform specific options might " "follow the name separated by a colon (:). E.g. for Keycloak the base URI for " -"the user and group REST API must be given. For Entra ID this is not needed " -"because there is a generic endpoint for all tenants." +"the user and group REST API must be given. For Entra ID the base URI for the " +"Microsoft Graph API can be given to use sovereign or government cloud " +"endpoints instead of the default (https://graph.microsoft.com/v1.0). E.g. " +"<quote>entra_id:https://graph.microsoft.us/v1.0</quote> for the US " +"government cloud (GCC High)." msgstr "" "Залежно від продукту IdP, додаткові параметри, специфічні для платформи, " "можуть йти після назви, з відокремленням двокрапкою (:). Наприклад, для " @@ -15748,17 +16295,17 @@ msgstr "" "оскільки існує загальна кінцева точка для всіх викликів." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:78 sssd-idp.5.xml:94 sssd-idp.5.xml:119 +#: sssd-idp.5.xml:82 sssd-idp.5.xml:98 sssd-idp.5.xml:123 msgid "Default: Not set (Required)" msgstr "Типове значення: не встановлено (обов'язкове)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:83 +#: sssd-idp.5.xml:87 msgid "idp_client_id (string)" msgstr "idp_client_id (рядок)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:86 +#: sssd-idp.5.xml:90 msgid "" "ID of the IdP client used by SSSD to authenticate users and as a client to " "lookup user and group attributes. This client must offer device " @@ -15771,12 +16318,12 @@ msgstr "" "повинен мати дозволи на пошук і читання атрибутів користувачів і груп." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:99 +#: sssd-idp.5.xml:103 msgid "idp_client_secret (string)" msgstr "idp_client_secret (рядок)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:102 +#: sssd-idp.5.xml:106 msgid "" "Password of the IdP client. The password is required for the id_provider. If " "only used as auth_provider it depends on the server side configuration if it " @@ -15787,22 +16334,22 @@ msgstr "" "налаштувань сервера." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:113 +#: sssd-idp.5.xml:117 msgid "idp_token_endpoint (string)" msgstr "idp_token_endpoint (рядок)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:116 +#: sssd-idp.5.xml:120 msgid "IdP endpoint for requesting access tokens." msgstr "Кінцева точки IdP для запиту щодо жетоні доступу." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:124 +#: sssd-idp.5.xml:128 msgid "idp_device_auth_endpoint (string)" msgstr "idp_device_auth_endpoint (рядок)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:127 +#: sssd-idp.5.xml:131 msgid "" "IdP endpoint for device authorization according to RFC-8628. This is " "required for user authentication." @@ -15811,12 +16358,12 @@ msgstr "" "необхідно для розпізнавання користувача." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:137 +#: sssd-idp.5.xml:141 msgid "idp_userinfo_endpoint (string)" msgstr "idp_userinfo_endpoint (рядок)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:140 +#: sssd-idp.5.xml:144 msgid "" "IdP userinfo endpoint to request user attributes after a successful " "authentication of the user. Required for authentication." @@ -15825,12 +16372,12 @@ msgstr "" "розпізнавання користувача. Обов'язкова для розпізнавання." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:150 +#: sssd-idp.5.xml:154 msgid "idp_id_scope (string)" msgstr "idp_id_scope (рядок)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:153 +#: sssd-idp.5.xml:157 msgid "" "Scope required for looking up user and group attributes with the REST API. " "The scopes are used by the server to determine which attributes/claims are " @@ -15841,13 +16388,20 @@ msgstr "" "визначення того, які атрибути/інструкції слід повертати стороні, з боку якої " "відбувся виклик." +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:163 +msgid "" +"Note: In previous versions of SSSD, this option was expected to already be " +"URL-encoded." +msgstr "" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:164 +#: sssd-idp.5.xml:172 msgid "idp_auth_scope (string)" msgstr "idp_auth_scope (рядок)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:167 +#: sssd-idp.5.xml:175 msgid "" "Scope required during authentication. The scopes are used by the server to " "determine which attributes/claims are returned to the caller." @@ -15857,7 +16411,7 @@ msgstr "" "процесу, яким було здійснено виклик." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:172 +#: sssd-idp.5.xml:180 msgid "" "Currently the tokens returned during user authentication are not used for " "other purposes hence the only important claim is the subject identifier " @@ -15871,22 +16425,120 @@ msgstr "" "майбутніх версіях." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:185 +#: sssd-idp.5.xml:193 +#, fuzzy +#| msgid "ldap_user_extra_attrs (string)" +msgid "idp_auth_user_identifier_attr (string)" +msgstr "ldap_user_extra_attrs (рядок)" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:196 +msgid "" +"Attribute used to identify the authenticated user in userinfo data or token " +"claims." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:200 +msgid "" +"For hybrid Active Directory and Entra ID deployments where " +"<quote>id_provider = ad</quote> and <quote>auth_provider = idp</quote>, this " +"option must be set explicitly. No value is derived from the identity " +"provider, because more than one attribute can link an Entra ID object to its " +"on-premises counterpart and only the administrator knows which one the " +"directory synchronization is configured to use." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:211 +msgid "" +"Setting this option to <quote>onPremisesImmutableId</quote> is the usual " +"choice for such deployments. Microsoft Entra Connect populates that " +"attribute with the base64-encoded form of the 16-byte Active Directory " +"<quote>objectGUID</quote> when objectGUID is used as the sourceAnchor. SSSD " +"decodes the value and converts the raw bytes with the same conversion used " +"for AD objectGUID attributes, so the result matches the UUID stored in the " +"SSSD cache for the AD user." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:224 +msgid "" +"Note that Microsoft Entra Connect 1.1.524.0 and later use <quote>ms-DS-" +"ConsistencyGuid</quote> as the sourceAnchor for user objects instead of " +"<quote>objectGUID</quote>. The value is normally copied from objectGUID for " +"objects that do not have it set yet, in which case the decoded identifier " +"still matches. It does not match if ms-DS-ConsistencyGuid was populated " +"independently, if users were moved between forests or domains, or if a " +"different attribute such as employeeID was selected as the sourceAnchor. See " +"<ulink url=\"https://learn.microsoft.com/en-us/entra/identity/hybrid/connect/" +"plan-connect-design-concepts\"> Microsoft Entra Connect: Design concepts</" +"ulink> for details on sourceAnchor selection." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:241 +msgid "" +"Microsoft Graph does not return <quote>onPremisesImmutableId</quote> by " +"default. The <quote>idp_userinfo_endpoint</quote> must request it with " +"<quote>$select</quote>, see the example below and <ulink url=\"https://" +"learn.microsoft.com/en-us/graph/api/resources/user\"> the Microsoft Graph " +"user resource type</ulink>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:251 +msgid "" +"If the configured attribute is missing or cannot be decoded (for example " +"cloud-only Entra ID users without <quote>onPremisesImmutableId</quote>), " +"authentication fails. SSSD does not fall back to another attribute when this " +"option is set." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:258 +msgid "" +"Default: not set, <quote>sub</quote> for Keycloak and <quote>id</quote> for " +"other IdP types" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-idp.5.xml:264 msgid "idp_request_timeout (integer)" msgstr "idp_request_timeout (ціле число)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:188 +#: sssd-idp.5.xml:267 msgid "Timeout in seconds for an individual request to the IdP." msgstr "Час очікування на відповідь у секундах для окремого запиту до IdP." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:197 +#: sssd-idp.5.xml:276 +#, fuzzy +#| msgid "ldap_referrals (boolean)" +msgid "idp_auto_refresh (boolean)" +msgstr "ldap_referrals (булеве значення)" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:279 +msgid "" +"Refresh tokens automatically, after they have reached about half their " +"lifetime." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:283 +msgid "" +"Note: Scheduled token refreshes are not preserved across restarts of SSSD." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-idp.5.xml:292 msgid "idmap_range_min (integer)" msgstr "idmap_range_min (ціле число)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:200 +#: sssd-idp.5.xml:295 msgid "" "Specifies the lower (inclusive) bound of the range of POSIX IDs to use for " "mapping IdP users and group to POSIX IDs. It is the first POSIX ID which can " @@ -15898,7 +16550,7 @@ msgstr "" "прив'язки." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:206 +#: sssd-idp.5.xml:301 #, fuzzy #| msgid "" #| "The interval between <quote>idmap_range_min</quote> and " @@ -15916,18 +16568,18 @@ msgstr "" "quote>, які використовуватимуться окремим доменом idP." #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:213 sssd-idp.5.xml:239 include/ldap_id_mapping.xml:139 +#: sssd-idp.5.xml:308 sssd-idp.5.xml:334 include/ldap_id_mapping.xml:139 #: include/ldap_id_mapping.xml:197 msgid "Default: 200000" msgstr "Типове значення: 200000" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:218 +#: sssd-idp.5.xml:313 msgid "idmap_range_max (integer)" msgstr "idmap_range_max (ціле число)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:221 +#: sssd-idp.5.xml:316 msgid "" "Specifies the upper (exclusive) bound of the range of POSIX IDs to use for " "mapping IdP users and groups to POSIX IDs. It is the first POSIX ID which " @@ -15939,59 +16591,123 @@ msgstr "" "використано для прив'язки до ID POSIX." #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:227 include/ldap_id_mapping.xml:165 +#: sssd-idp.5.xml:322 include/ldap_id_mapping.xml:165 msgid "Default: 2000200000" msgstr "Типове значення: 2000200000" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:232 +#: sssd-idp.5.xml:327 msgid "idmap_range_size (integer)" msgstr "idmap_range_size (ціле число)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:235 +#: sssd-idp.5.xml:330 msgid "Specifies the number of POSIX IDs available for a single IdP domain." msgstr "" "Визначає кількість ідентифікаторів POSIX, які є доступними для окремого " "домену IdP." #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-idp.5.xml:251 -#, no-wrap +#: sssd-idp.5.xml:346 +#, fuzzy, no-wrap +#| msgid "" +#| "[domain/entra_id]\n" +#| "id_provider = idp\n" +#| "idp_type = entra_id\n" +#| "idp_client_id = 12345678-abcd-0101-efef-ba9876543210\n" +#| "idp_client_secret = YOUR-CLIENT-SCERET\n" +#| "idp_token_endpoint = https://login.microsoftonline.com/TENNANT-ID/oauth2/v2.0/token\n" +#| "idp_userinfo_endpoint = https://graph.microsoft.com/v1.0/me\n" +#| "idp_device_auth_endpoint = https://login.microsoftonline.com/TENNANT-ID/oauth2/v2.0/devicecode\n" +#| "idp_id_scope = https%3A%2F%2Fgraph.microsoft.com%2F.default\n" +#| "idp_auth_scope = openid profile email\n" msgid "" "[domain/entra_id]\n" "id_provider = idp\n" "idp_type = entra_id\n" "idp_client_id = 12345678-abcd-0101-efef-ba9876543210\n" +"idp_client_secret = YOUR-CLIENT-SECRET\n" +"idp_token_endpoint = https://login.microsoftonline.com/TENANT-ID/oauth2/v2.0/token\n" +"idp_userinfo_endpoint = https://graph.microsoft.com/v1.0/me\n" +"idp_device_auth_endpoint = https://login.microsoftonline.com/TENANT-ID/oauth2/v2.0/devicecode\n" +"idp_id_scope = https://graph.microsoft.com/.default\n" +"idp_auth_scope = openid profile email\n" +msgstr "" +"[domain/entra_id]\n" +"id_provider = idp\n" +"idp_type = entra_id\n" +"idp_client_id = 12345678-abcd-0101-efef-ba9876543210\n" "idp_client_secret = YOUR-CLIENT-SCERET\n" "idp_token_endpoint = https://login.microsoftonline.com/TENNANT-ID/oauth2/v2.0/token\n" "idp_userinfo_endpoint = https://graph.microsoft.com/v1.0/me\n" "idp_device_auth_endpoint = https://login.microsoftonline.com/TENNANT-ID/oauth2/v2.0/devicecode\n" "idp_id_scope = https%3A%2F%2Fgraph.microsoft.com%2F.default\n" "idp_auth_scope = openid profile email\n" + +#. type: Content of: <reference><refentry><refsect1><para><programlisting> +#: sssd-idp.5.xml:358 +#, fuzzy, no-wrap +#| msgid "" +#| "[domain/entra_id]\n" +#| "id_provider = idp\n" +#| "idp_type = entra_id\n" +#| "idp_client_id = 12345678-abcd-0101-efef-ba9876543210\n" +#| "idp_client_secret = YOUR-CLIENT-SCERET\n" +#| "idp_token_endpoint = https://login.microsoftonline.com/TENNANT-ID/oauth2/v2.0/token\n" +#| "idp_userinfo_endpoint = https://graph.microsoft.com/v1.0/me\n" +#| "idp_device_auth_endpoint = https://login.microsoftonline.com/TENNANT-ID/oauth2/v2.0/devicecode\n" +#| "idp_id_scope = https%3A%2F%2Fgraph.microsoft.com%2F.default\n" +#| "idp_auth_scope = openid profile email\n" +msgid "" +"[domain/ad.example.com]\n" +"id_provider = ad\n" +"auth_provider = idp\n" +"access_provider = permit\n" +"\n" +"ad_domain = ad.example.com\n" +"krb5_realm = AD.EXAMPLE.COM\n" +"\n" +"idp_type = entra_id\n" +"idp_client_id = 12345678-abcd-0101-efef-ba9876543210\n" +"idp_client_secret = YOUR-CLIENT-SECRET\n" +"idp_token_endpoint = https://login.microsoftonline.com/TENANT-ID/oauth2/v2.0/token\n" +"idp_userinfo_endpoint = https://graph.microsoft.com/v1.0/me?$select=id,userPrincipalName,onPremisesImmutableId\n" +"idp_device_auth_endpoint = https://login.microsoftonline.com/TENANT-ID/oauth2/v2.0/devicecode\n" +"idp_id_scope = https://graph.microsoft.com/.default\n" +"idp_auth_scope = openid profile email\n" +"idp_auth_user_identifier_attr = onPremisesImmutableId\n" msgstr "" "[domain/entra_id]\n" "id_provider = idp\n" "idp_type = entra_id\n" "idp_client_id = 12345678-abcd-0101-efef-ba9876543210\n" "idp_client_secret = YOUR-CLIENT-SCERET\n" -"idp_token_endpoint = https://login.microsoftonline.com/TENNANT-ID/oauth2/" -"v2.0/token\n" +"idp_token_endpoint = https://login.microsoftonline.com/TENNANT-ID/oauth2/v2.0/token\n" "idp_userinfo_endpoint = https://graph.microsoft.com/v1.0/me\n" -"idp_device_auth_endpoint = https://login.microsoftonline.com/TENNANT-ID/" -"oauth2/v2.0/devicecode\n" +"idp_device_auth_endpoint = https://login.microsoftonline.com/TENNANT-ID/oauth2/v2.0/devicecode\n" "idp_id_scope = https%3A%2F%2Fgraph.microsoft.com%2F.default\n" "idp_auth_scope = openid profile email\n" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-idp.5.xml:263 -#, no-wrap +#: sssd-idp.5.xml:377 +#, fuzzy, no-wrap +#| msgid "" +#| "[domain/keycloak]\n" +#| "idp_type = keycloak:https://master.keycloak.test:8443/auth/admin/realms/master/\n" +#| "id_provider = idp\n" +#| "idp_client_id = myclient\n" +#| "idp_client_secret = YOUR-CLIENT-SCERET\n" +#| "idp_token_endpoint = https://master.keycloak.test:8443/auth/realms/master/protocol/openid-connect/token\n" +#| "idp_userinfo_endpoint = https://master.keycloak.test:8443/auth/realms/master/protocol/openid-connect/userinfo\n" +#| "idp_device_auth_endpoint = https://master.keycloak.test:8443/auth/realms/master/protocol/openid-connect/auth/device\n" +#| "idp_id_scope = profile\n" +#| "idp_auth_scope = openid profile email\n" msgid "" "[domain/keycloak]\n" "idp_type = keycloak:https://master.keycloak.test:8443/auth/admin/realms/master/\n" "id_provider = idp\n" "idp_client_id = myclient\n" -"idp_client_secret = YOUR-CLIENT-SCERET\n" +"idp_client_secret = YOUR-CLIENT-SECRET\n" "idp_token_endpoint = https://master.keycloak.test:8443/auth/realms/master/protocol/openid-connect/token\n" "idp_userinfo_endpoint = https://master.keycloak.test:8443/auth/realms/master/protocol/openid-connect/userinfo\n" "idp_device_auth_endpoint = https://master.keycloak.test:8443/auth/realms/master/protocol/openid-connect/auth/device\n" @@ -15999,29 +16715,41 @@ msgid "" "idp_auth_scope = openid profile email\n" msgstr "" "[domain/keycloak]\n" -"idp_type = keycloak:https://master.keycloak.test:8443/auth/admin/realms/" -"master/\n" +"idp_type = keycloak:https://master.keycloak.test:8443/auth/admin/realms/master/\n" "id_provider = idp\n" "idp_client_id = myclient\n" "idp_client_secret = YOUR-CLIENT-SCERET\n" -"idp_token_endpoint = https://master.keycloak.test:8443/auth/realms/master/" -"protocol/openid-connect/token\n" -"idp_userinfo_endpoint = https://master.keycloak.test:8443/auth/realms/master/" -"protocol/openid-connect/userinfo\n" -"idp_device_auth_endpoint = https://master.keycloak.test:8443/auth/realms/" -"master/protocol/openid-connect/auth/device\n" +"idp_token_endpoint = https://master.keycloak.test:8443/auth/realms/master/protocol/openid-connect/token\n" +"idp_userinfo_endpoint = https://master.keycloak.test:8443/auth/realms/master/protocol/openid-connect/userinfo\n" +"idp_device_auth_endpoint = https://master.keycloak.test:8443/auth/realms/master/protocol/openid-connect/auth/device\n" "idp_id_scope = profile\n" "idp_auth_scope = openid profile email\n" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-idp.5.xml:250 +#: sssd-idp.5.xml:345 +#, fuzzy +#| msgid "" +#| "<placeholder type=\"programlisting\" id=\"0\"/> <placeholder " +#| "type=\"programlisting\" id=\"1\"/>" msgid "" "<placeholder type=\"programlisting\" id=\"0\"/> <placeholder " -"type=\"programlisting\" id=\"1\"/>" +"type=\"programlisting\" id=\"1\"/> <placeholder type=\"programlisting\" " +"id=\"2\"/>" msgstr "" "<placeholder type=\"programlisting\" id=\"0\"/> <placeholder " "type=\"programlisting\" id=\"1\"/>" +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-idp.5.xml:390 +msgid "" +"In the hybrid Active Directory and Entra ID example above, " +"<quote>onPremisesImmutableId</quote> is used during authentication so the " +"IdP result matches the AD objectGUID UUID stored in the SSSD cache. The " +"attribute must be requested via <quote>$select</quote> on the Graph userinfo " +"endpoint and is only populated for users synchronized from Active Directory " +"with objectGUID as the sourceAnchor." +msgstr "" + #. type: Content of: <reference><refentry><refnamediv><refname> #: sssd.8.xml:10 sssd.8.xml:15 msgid "sssd" @@ -17223,9 +17951,13 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:291 +#, fuzzy +#| msgid "" +#| "<emphasis>demand</emphasis> to use FAST. The authentication fails if the " +#| "server does not require fast." msgid "" "<emphasis>demand</emphasis> to use FAST. The authentication fails if the " -"server does not require fast." +"server does not support FAST." msgstr "" "<emphasis>demand</emphasis> — використовувати FAST. Якщо на сервері не " "передбачено підтримки FAST, спроба розпізнавання зазнає невдачі." @@ -18367,7 +19099,9 @@ msgstr "Атрибути налаштувань" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sss_rpcidmapd.5.xml:69 -msgid "memcache (bool)" +#, fuzzy +#| msgid "memcache (bool)" +msgid "memcache (boolean)" msgstr "memcache (булеве значення)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> @@ -18439,7 +19173,7 @@ msgstr "" "id=\"0\"/>" #. type: Content of: <refsect1><title> -#: sss_rpcidmapd.5.xml:120 sssd-kcm.8.xml:316 include/seealso.xml:2 +#: sss_rpcidmapd.5.xml:120 sssd-kcm.8.xml:315 include/seealso.xml:2 msgid "SEE ALSO" msgstr "ТАКОЖ ПЕРЕГЛЯНЬТЕ" @@ -18752,10 +19486,21 @@ msgstr "ОТРИМАННЯ КЛЮЧІВ" #. type: Content of: <reference><refentry><refsect1><para> #: sss_ssh_knownhosts.1.xml:93 +#, fuzzy +#| msgid "" +#| "The key lines retrieved from the backend are expected to respect the key " +#| "format as decribed in the <quote>SSH_KNOWN_HOSTS FILE FORMAT</quote> " +#| "section of <citerefentry><refentrytitle>sshd</refentrytitle> " +#| "<manvolnum>8</manvolnum></citerefentry>. However, returning only the " +#| "keytype and the key itself is tolerated, in which case, the hostname " +#| "received as parameter will be added before the keytype to output a " +#| "correctly formatted line. The hostname will be added unmodified or just " +#| "the hostname (no port number), depending on whether the <option>-o</" +#| "option>,<option>--only-host-name</option> option was provided." msgid "" "The key lines retrieved from the backend are expected to respect the key " -"format as decribed in the <quote>SSH_KNOWN_HOSTS FILE FORMAT</quote> section " -"of <citerefentry><refentrytitle>sshd</refentrytitle> <manvolnum>8</" +"format as described in the <quote>SSH_KNOWN_HOSTS FILE FORMAT</quote> " +"section of <citerefentry><refentrytitle>sshd</refentrytitle> <manvolnum>8</" "manvolnum></citerefentry>. However, returning only the keytype and the key " "itself is tolerated, in which case, the hostname received as parameter will " "be added before the keytype to output a correctly formatted line. The " @@ -19423,19 +20168,25 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-kcm.8.xml:215 +#, fuzzy +#| msgid "" +#| "The KCM service is configured in the <quote>kcm</quote> For a detailed " +#| "syntax reference, refer to the <quote>FILE FORMAT</quote> section of the " +#| "<citerefentry> <refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</" +#| "manvolnum> </citerefentry> manual page." msgid "" -"The KCM service is configured in the <quote>kcm</quote> For a detailed " -"syntax reference, refer to the <quote>FILE FORMAT</quote> section of the " -"<citerefentry> <refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</" -"manvolnum> </citerefentry> manual page." +"For a detailed syntax reference, refer to the <quote>FILE FORMAT</quote> " +"section of the <citerefentry> <refentrytitle>sssd.conf</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry> manual page." msgstr "" "Налаштування служби KCM виконують за допомогою <quote>kcm</quote>. Докладний " "опис синтаксичних конструкцій налаштувань наведено у розділі <quote>ФОРМАТ " -"ФАЙЛА</quote> сторінки підручника щодо <citerefentry> <refentrytitle>" -"sssd.conf</refentrytitle> <manvolnum>5</manvolnum> </citerefentry>." +"ФАЙЛА</quote> сторінки підручника щодо <citerefentry> " +"<refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</manvolnum> </" +"citerefentry>." #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-kcm.8.xml:223 +#: sssd-kcm.8.xml:222 msgid "" "The generic SSSD service options such as <quote>debug_level</quote> or " "<quote>fd_limit</quote> are accepted by the kcm service. Please refer to " @@ -19450,23 +20201,23 @@ msgstr "" "того, передбачено декілька специфічних для KCM параметрів." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:234 +#: sssd-kcm.8.xml:233 msgid "socket_path (string)" msgstr "socket_path (рядок)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:237 +#: sssd-kcm.8.xml:236 msgid "The socket the KCM service will listen on." msgstr "Сокет, на якому очікуватиме на з'єднання служба KCM." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:240 +#: sssd-kcm.8.xml:239 msgid "Default: <replaceable>/var/run/.heim_org.h5l.kcm-socket</replaceable>" msgstr "" "Типове значення: <replaceable>/var/run/.heim_org.h5l.kcm-socket</replaceable>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:243 +#: sssd-kcm.8.xml:242 msgid "" "<phrase condition=\"have_systemd\"> Note: on platforms where systemd is " "supported, the socket path is overwritten by the one defined in the sssd-" @@ -19477,31 +20228,31 @@ msgstr "" "визначено у файлі модуля sssd-kcm.socket. </phrase>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:252 +#: sssd-kcm.8.xml:251 msgid "max_ccaches (integer)" msgstr "max_ccaches (ціле число)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:255 +#: sssd-kcm.8.xml:254 msgid "How many credential caches does the KCM database allow for all users." msgstr "" "Скільки кешів реєстраційних може мати даних база даних KCM для усіх " "користувачів." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:259 +#: sssd-kcm.8.xml:258 msgid "Default: 0 (unlimited, only the per-UID quota is enforced)" msgstr "" "Типове значення: 0 (без обмежень, застосовується лише квота на кількість " "кешів на UID)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:264 +#: sssd-kcm.8.xml:263 msgid "max_uid_ccaches (integer)" msgstr "max_uid_ccaches (ціле число)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:267 +#: sssd-kcm.8.xml:266 msgid "" "How many credential caches does the KCM database allow per UID. This is " "equivalent to <quote>with how many principals you can kinit</quote>." @@ -19511,63 +20262,69 @@ msgstr "" "ініціювати за допомогою kinit</quote>." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:272 +#: sssd-kcm.8.xml:271 msgid "Default: 64" msgstr "Типове значення: 64" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:277 +#: sssd-kcm.8.xml:276 msgid "max_ccache_size (integer)" msgstr "max_ccache_size (ціле число)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:280 +#: sssd-kcm.8.xml:279 +#, fuzzy +#| msgid "" +#| "How big can a credential cache be per ccache. Each service ticket " +#| "accounts into this quota." msgid "" -"How big can a credential cache be per ccache. Each service ticket accounts " -"into this quota." +"How big a credential cache be per ccache. Each service ticket counts toward " +"this quota." msgstr "" "Наскільки великим може бути кеш реєстраційних даних окремого ccache. Ця " "квота обчислюється для усіх квитків служб разом." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:284 +#: sssd-kcm.8.xml:283 msgid "Default: 65536" msgstr "Типове значення: 65536" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:289 -msgid "tgt_renewal (bool)" +#: sssd-kcm.8.xml:288 +#, fuzzy +#| msgid "tgt_renewal (bool)" +msgid "tgt_renewal (boolean)" msgstr "tgt_renewal (булеве значення)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:292 +#: sssd-kcm.8.xml:291 msgid "Enables TGT renewals functionality." msgstr "Вмикає функціональні можливості поновлень TGT." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:295 +#: sssd-kcm.8.xml:294 msgid "Default: False (Automatic renewals disabled)" msgstr "Типове значення: False (автоматичні поновлення вимкнено)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:300 +#: sssd-kcm.8.xml:299 msgid "tgt_renewal_inherit (string)" msgstr "tgt_renewal_inherit (рядок)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:303 +#: sssd-kcm.8.xml:302 msgid "Domain to inherit krb5_* options from, for use with TGT renewals." msgstr "" "Домен, з якого слід успадковувати параметри krb5_*, для використання із " "поновленнями TGT." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:307 +#: sssd-kcm.8.xml:306 msgid "Default: NULL" msgstr "Типове значення: NULL" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-kcm.8.xml:318 +#: sssd-kcm.8.xml:317 msgid "" "<citerefentry> <refentrytitle>sssd</refentrytitle><manvolnum>8</manvolnum> </" "citerefentry>, <citerefentry> <refentrytitle>sssd.conf</" @@ -20598,9 +21355,11 @@ msgstr "" "чи заборонено доступ." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap-attributes.5.xml:381 sssd-ldap-attributes.5.xml:395 -msgid "Default: loginDisabled" -msgstr "Типове значення: loginDisabled" +#: sssd-ldap-attributes.5.xml:381 +#, fuzzy +#| msgid "Default: uid (rfc2307, rfc2307bis and IPA), sAMAccountName (AD)" +msgid "Default: loginDisabled (rfc2307, rfc2307bis and IPA), not set (AD)" +msgstr "Типове значення: uid (rfc2307, rfc2307bis і IPA), sAMAccountName (AD)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:387 @@ -20616,6 +21375,14 @@ msgstr "" "Якщо вказано ldap_account_expire_policy=nds, цей атрибут визначає дату, до " "якої надано доступ." +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:395 +#, fuzzy +#| msgid "Default: cn (rfc2307, rfc2307bis and IPA), sAMAccountName (AD)" +msgid "" +"Default: loginExpirationTime (rfc2307, rfc2307bis and IPA), not set (AD)" +msgstr "Типове значення: cn (rfc2307, rfc2307bis і IPA), sAMAccountName (AD)" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:401 msgid "ldap_user_nds_login_allowed_time_map (string)" @@ -20632,8 +21399,11 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:409 -msgid "Default: loginAllowedTimeMap" -msgstr "Типове значення: loginAllowedTimeMap" +#, fuzzy +#| msgid "Default: uid (rfc2307, rfc2307bis and IPA), sAMAccountName (AD)" +msgid "" +"Default: loginAllowedTimeMap (rfc2307, rfc2307bis and IPA), not set (AD)" +msgstr "Типове значення: uid (rfc2307, rfc2307bis і IPA), sAMAccountName (AD)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:415 @@ -21213,9 +21983,9 @@ msgid "The object class of a host entry in LDAP." msgstr "Клас об’єктів запису вузла у LDAP." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap-attributes.5.xml:900 sssd-ldap-attributes.5.xml:997 -msgid "Default: ipService" -msgstr "Типове значення: ipService" +#: sssd-ldap-attributes.5.xml:900 sssd-ldap-attributes.5.xml:1213 +msgid "Default: ipHost" +msgstr "Типове значення: ipHost" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:906 @@ -21299,6 +22069,11 @@ msgstr "ldap_service_object_class (рядок)" msgid "The object class of a service entry in LDAP." msgstr "Клас об’єктів запису служби у LDAP." +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:997 +msgid "Default: ipService" +msgstr "Типове значення: ipService" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1003 msgid "ldap_service_name (string)" @@ -21548,11 +22323,6 @@ msgstr "ldap_iphost_object_class (рядок)" msgid "The object class of an iphost entry in LDAP." msgstr "Клас об'єктів запису iphost у LDAP." -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap-attributes.5.xml:1213 -msgid "Default: ipHost" -msgstr "Типове значення: ipHost" - #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1219 msgid "ldap_iphost_name (string)" @@ -21817,10 +22587,16 @@ msgstr "НАЛАШТУВАННЯ" #. type: Content of: <reference><refentry><refsect1><para><programlisting> #: sssd_krb5_localauth_plugin.8.xml:56 -#, no-wrap +#, fuzzy, no-wrap +#| msgid "" +#| "[plugins]\n" +#| " localauth = {\n" +#| " module = sssd:/usr/lib64/sssd/modules/sssd_krb5_localauth_plugin.so\n" +#| " }\n" msgid "" "[plugins]\n" " localauth = {\n" +" disable = an2ln\n" " module = sssd:/usr/lib64/sssd/modules/sssd_krb5_localauth_plugin.so\n" " }\n" msgstr "" @@ -21848,6 +22624,28 @@ msgstr "" "налаштувань SSSD Kerberos. Якщо цей каталог включено до локальних " "налаштувань Kerberos, додаток буде увімкнено автоматично." +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_localauth_plugin.8.xml:67 +msgid "" +"This configuration snippet also disables the <command>an2ln</command> module " +"provided by MIT Kerberos if SSSD is configured to use the AD or IPA " +"provider. In those environments <command>sssd_krb5_localauth_plugin</" +"command> can reliably map the system user names to Kerberos principals. A " +"fallback to <command>an2ln</command> might cause issues in environments " +"where users have the privilege to create Kerberos principals on their own " +"which might collide with names of other users used in the system. Other " +"modules provided by MIT Kerberos, e.g. <command>k5login</command> are not " +"affected." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_localauth_plugin.8.xml:79 +msgid "" +"Note: If using <quote>auth_provider = krb5</quote> then " +"<command>sssd_krb5_localauth_plugin</command> is not used, therefore the " +"above text is not applicable." +msgstr "" + #. type: Content of: <variablelist><varlistentry><term> #: include/autofs_attributes.xml:3 msgid "ldap_autofs_map_object_class (string)" @@ -22984,41 +23782,6 @@ msgstr "" "<emphasis>Типове значення</emphasis>: 0x0070 (тобто фатальні, критичні та " "серйозні помилки; відповідає встановленню значення 2 у десятковому записі)" -#. type: Content of: <refsect1><title> -#: include/local.xml:2 -msgid "THE LOCAL DOMAIN" -msgstr "ЛОКАЛЬНИЙ ДОМЕН" - -#. type: Content of: <refsect1><para> -#: include/local.xml:4 -msgid "" -"In order to function correctly, a domain with <quote>id_provider=local</" -"quote> must be created and the SSSD must be running." -msgstr "" -"З метою забезпечення належної роботи слід створити домен з <quote>" -"id_provider=local</quote> та запустити SSSD." - -#. type: Content of: <refsect1><para> -#: include/local.xml:9 -msgid "" -"The administrator might want to use the SSSD local users instead of " -"traditional UNIX users in cases where the group nesting (see <citerefentry> " -"<refentrytitle>sss_groupadd</refentrytitle> <manvolnum>8</manvolnum> </" -"citerefentry>) is needed. The local users are also useful for testing and " -"development of the SSSD without having to deploy a full remote server. The " -"<command>sss_user*</command> and <command>sss_group*</command> tools use a " -"local LDB storage to store users and groups." -msgstr "" -"Адміністратор може надати перевагу використанню локальних записів " -"користувачів SSSD замість традиційних записів користувачів UNIX, якщо для " -"роботи потрібна вкладеність груп (див. <citerefentry> <refentrytitle>" -"sss_groupadd</refentrytitle> <manvolnum>8</manvolnum> </citerefentry>). " -"Використання локальних записів може також бути корисним для тестування та " -"розробки програмного забезпечення з підтримкою SSSD (у такому разі не " -"потрібно розгортати повноцінний віддалений сервер). Інструменти <command>" -"sss_user*</command> та <command>sss_group*</command> використовують для " -"зберігання записів користувачів і груп локальне сховище даних LDB." - #. type: Content of: <refsect1><para> #: include/seealso.xml:4 msgid "" @@ -23770,6 +24533,121 @@ msgstr "" "Визначає, чи слід перетворювати реєстраційний запис вузла і користувача у " "канонічну форму. Цю можливість передбачено з версії MIT Kerberos 1.7." +#~ msgid "" +#~ "The data types used are string (no quotes needed), integer and bool (with " +#~ "values of <quote>TRUE/FALSE</quote>)." +#~ msgstr "" +#~ "Типами даних є рядок (без символів лапок), ціле число і булеве значення " +#~ "(можливі два значення — <quote>TRUE</quote> і <quote>FALSE</quote>)." + +#~ msgid "services" +#~ msgstr "services" + +#~ msgid "domains" +#~ msgstr "domains" + +#~ msgid "fd_limit" +#~ msgstr "fd_limit" + +#~ msgid "client_idle_timeout" +#~ msgstr "client_idle_timeout" + +#~ msgid "default_shell" +#~ msgstr "default_shell" + +#~ msgid "" +#~ "Note: This option can also be set per-domain which overwrites the value " +#~ "in [nss] section." +#~ msgstr "" +#~ "Зауваження: значення цього параметра можна встановлювати для кожного з " +#~ "доменів окремо. При цьому це значення матиме вищий пріоритет за значення " +#~ "у розділі [nss]." + +#~ msgid "These options can be used to configure session recording." +#~ msgstr "" +#~ "Цими параметрами можна скористатися для налаштовування запису сеансів." + +#~ msgid "entry_cache_computer_timeout (integer)" +#~ msgstr "entry_cache_computer_timeout (ціле число)" + +#~ msgid "" +#~ "How many seconds to keep the local computer entry before asking the " +#~ "backend again" +#~ msgstr "" +#~ "Кількість секунд, протягом яких слід зберігати запис локального " +#~ "комп'ютера, перш ніж надсилати запит до модуля обробки даних знову" + +#~ msgid "" +#~ "Default: <quote>id_provider</quote> is used if it is set and can handle " +#~ "selinux loading requests." +#~ msgstr "" +#~ "Типове значення: буде використано <quote>id_provider</quote>, якщо цей " +#~ "спосіб встановлено і можлива обробка запитів щодо завантаження SELinux." + +#~ msgid "" +#~ "Please see the section <quote>FAILOVER</quote> for more information about " +#~ "the service resolution." +#~ msgstr "" +#~ "Будь ласка, ознайомтеся із розділом <quote>РЕЗЕРВ</quote>, щоб дізнатися " +#~ "більше про розв'язування питань, пов'язаних із службами." + +#~ msgid "" +#~ "NOTE: On older systems (such as RHEL 5), for this behavior to work " +#~ "reliably, the default Kerberos realm must be set properly in /etc/" +#~ "krb5.conf" +#~ msgstr "" +#~ "ЗАУВАЖЕННЯ: на застарілих системах (зокрема RHEL 5) для надійної роботи у " +#~ "цьому режимі типову область дії Kerberos має бути належним чином " +#~ "визначено у /etc/krb5.conf" + +#~ msgid "ipa_hbac_selinux (integer)" +#~ msgstr "ipa_hbac_selinux (ціле число)" + +#~ msgid "" +#~ "NOTE: While it is still possible to use the old " +#~ "<emphasis>ipa_dyndns_iface</emphasis> option, users should migrate to " +#~ "using <emphasis>dyndns_iface</emphasis> in their config file." +#~ msgstr "" +#~ "ЗАУВАЖЕННЯ: хоча можна використовувати і попередню назву параметра, " +#~ "<emphasis>ipa_dyndns_iface</emphasis>, користувачам слід переходити на " +#~ "нову назву, <emphasis>dyndns_iface</emphasis>, у файлі налаштувань." + +#~ msgid "Default: loginDisabled" +#~ msgstr "Типове значення: loginDisabled" + +#~ msgid "Default: loginAllowedTimeMap" +#~ msgstr "Типове значення: loginAllowedTimeMap" + +#~ msgid "THE LOCAL DOMAIN" +#~ msgstr "ЛОКАЛЬНИЙ ДОМЕН" + +#~ msgid "" +#~ "In order to function correctly, a domain with <quote>id_provider=local</" +#~ "quote> must be created and the SSSD must be running." +#~ msgstr "" +#~ "З метою забезпечення належної роботи слід створити домен з " +#~ "<quote>id_provider=local</quote> та запустити SSSD." + +#~ msgid "" +#~ "The administrator might want to use the SSSD local users instead of " +#~ "traditional UNIX users in cases where the group nesting (see " +#~ "<citerefentry> <refentrytitle>sss_groupadd</refentrytitle> <manvolnum>8</" +#~ "manvolnum> </citerefentry>) is needed. The local users are also useful " +#~ "for testing and development of the SSSD without having to deploy a full " +#~ "remote server. The <command>sss_user*</command> and <command>sss_group*</" +#~ "command> tools use a local LDB storage to store users and groups." +#~ msgstr "" +#~ "Адміністратор може надати перевагу використанню локальних записів " +#~ "користувачів SSSD замість традиційних записів користувачів UNIX, якщо для " +#~ "роботи потрібна вкладеність груп (див. <citerefentry> " +#~ "<refentrytitle>sss_groupadd</refentrytitle> <manvolnum>8</manvolnum> </" +#~ "citerefentry>). Використання локальних записів може також бути корисним " +#~ "для тестування та розробки програмного забезпечення з підтримкою SSSD (у " +#~ "такому разі не потрібно розгортати повноцінний віддалений сервер). " +#~ "Інструменти <command>sss_user*</command> та <command>sss_group*</command> " +#~ "використовують для зберігання записів користувачів і груп локальне " +#~ "сховище даних LDB." + #~ msgid "subdomain_enumerate (string)" #~ msgstr "subdomain_enumerate (рядок)" @@ -25004,9 +25882,6 @@ msgstr "" #~ "Визначає, чи слід перевіряти сертифікат вузла і чи слід вважати його " #~ "чинним, якщо для засобу надання даних проксі використано протокол HTTPS." -#~ msgid "verify_host (boolean)" -#~ msgstr "verify_host (булеве значення)" - #~ msgid "" #~ "Whether peer's hostname must match with hostname in its certificate if " #~ "HTTPS protocol is used with the proxy provider." @@ -25278,9 +26153,6 @@ msgstr "" #~ "У наведеному нижче прикладі ми вилучимо реєстраційні дані для запису " #~ "«foo». <placeholder type=\"programlisting\" id=\"0\"/>" -#~ msgid "EXAMPLE CUSTODIA AND PROXY PROVIDER CONFIGURATION" -#~ msgstr "ПРИКЛАД НАЛАШТОВУВАННЯ МОДУЛІВ НАДАННЯ ДАНИХ CUSTODIA І ПРОКСІ" - #~ msgid "" #~ "For testing the proxy provider, you need to set up a Custodia server to " #~ "proxy requests to. Please always consult the Custodia documentation, the " @@ -25487,9 +26359,6 @@ msgstr "" #~ "користувачів і груп у вбудованій базі даних SSSD, тобто домену, який " #~ "використовує <replaceable>id_provider=local</replaceable>." -#~ msgid "default_shell (string)" -#~ msgstr "default_shell (рядок)" - #~ msgid "The default shell for users created with SSSD userspace tools." #~ msgstr "" #~ "Типова оболонка для записів користувачів, створених за допомогою " diff --git a/src/man/po/zh_CN.po b/src/man/po/zh_CN.po index de6e1ef776f..5b1d2d016e8 100644 --- a/src/man/po/zh_CN.po +++ b/src/man/po/zh_CN.po @@ -9,8 +9,8 @@ msgid "" msgstr "" "Project-Id-Version: sssd-docs 2.3.0\n" "Report-Msgid-Bugs-To: sssd-devel@redhat.com\n" -"POT-Creation-Date: 2026-01-14 15:00+0000\n" -"PO-Revision-Date: 2026-04-23 16:53+0000\n" +"POT-Creation-Date: 2026-10-05 16:14+0000\n" +"PO-Revision-Date: 2026-10-05 17:10+0000\n" "Last-Translator: Anonymous <noreply@weblate.org>\n" "Language-Team: Chinese (Simplified) <https://translate.fedoraproject.org/" "projects/sssd/sssd-manpage-master/zh_CN/>\n" @@ -19,10 +19,10 @@ msgstr "" "Content-Type: text/plain; charset=UTF-8\n" "Content-Transfer-Encoding: 8bit\n" "Plural-Forms: nplurals=1; plural=0;\n" -"X-Generator: Weblate 5.17\n" +"X-Generator: Weblate 2026.10\n" #. type: Content of: <reference><title> -#: sssd.conf.5.xml:8 sssd-ldap.5.xml:5 pam_sss.8.xml:5 pam_sss_gss.8.xml:5 +#: sssd.conf.5.xml:10 sssd-ldap.5.xml:5 pam_sss.8.xml:5 pam_sss_gss.8.xml:5 #: sssd_krb5_locator_plugin.8.xml:5 sssd-simple.5.xml:5 sss-certmap.5.xml:5 #: sssd-ipa.5.xml:5 sssd-ad.5.xml:5 sssd-sudo.5.xml:5 sssd-idp.5.xml:5 #: sssd.8.xml:5 sss_obfuscate.8.xml:5 sss_override.8.xml:5 sssd-krb5.5.xml:5 @@ -35,12 +35,12 @@ msgid "SSSD Manual pages" msgstr "SSSD 手册页面" #. type: Content of: <reference><refentry><refnamediv><refname> -#: sssd.conf.5.xml:13 sssd.conf.5.xml:19 +#: sssd.conf.5.xml:15 sssd.conf.5.xml:21 msgid "sssd.conf" msgstr "sssd.conf" #. type: Content of: <reference><refentry><refmeta><manvolnum> -#: sssd.conf.5.xml:14 sssd-ldap.5.xml:11 sssd-simple.5.xml:11 +#: sssd.conf.5.xml:16 sssd-ldap.5.xml:11 sssd-simple.5.xml:11 #: sss-certmap.5.xml:11 sssd-ipa.5.xml:11 sssd-ad.5.xml:11 sssd-sudo.5.xml:11 #: sssd-idp.5.xml:11 sssd-krb5.5.xml:11 sssd-ifp.5.xml:11 #: sss_rpcidmapd.5.xml:27 sssd-session-recording.5.xml:11 @@ -49,7 +49,7 @@ msgid "5" msgstr "5" #. type: Content of: <reference><refentry><refmeta><refmiscinfo> -#: sssd.conf.5.xml:15 sssd-ldap.5.xml:12 sssd-simple.5.xml:12 +#: sssd.conf.5.xml:17 sssd-ldap.5.xml:12 sssd-simple.5.xml:12 #: sss-certmap.5.xml:12 sssd-ipa.5.xml:12 sssd-ad.5.xml:12 sssd-sudo.5.xml:12 #: sssd-idp.5.xml:12 sssd-krb5.5.xml:12 sssd-ifp.5.xml:12 #: sss_rpcidmapd.5.xml:28 sssd-session-recording.5.xml:12 sssd-kcm.8.xml:12 @@ -58,17 +58,17 @@ msgid "File Formats and Conventions" msgstr "" #. type: Content of: <reference><refentry><refnamediv><refpurpose> -#: sssd.conf.5.xml:20 +#: sssd.conf.5.xml:22 msgid "the configuration file for SSSD" msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:24 +#: sssd.conf.5.xml:26 msgid "FILE FORMAT" msgstr "文件格式" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd.conf.5.xml:32 +#: sssd.conf.5.xml:34 #, no-wrap msgid "" "<replaceable>[section]</replaceable>\n" @@ -78,7 +78,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:27 +#: sssd.conf.5.xml:29 msgid "" "The file has an ini-style syntax and consists of sections and parameters. A " "section begins with the name of the section in square brackets and continues " @@ -87,47 +87,50 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:39 +#: sssd.conf.5.xml:41 msgid "" -"The data types used are string (no quotes needed), integer and bool (with " -"values of <quote>TRUE/FALSE</quote>)." +"The data types used are string (no quotes needed), integer and boolean (with " +"values of <quote>TRUE/FALSE</quote>). Boolean values are case-insensitive; " +"for example, <quote>TRUE</quote>, <quote>True</quote> and <quote>true</" +"quote> are all equivalent and valid; the same applies to <quote>FALSE</" +"quote>." msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:44 +#: sssd.conf.5.xml:49 msgid "" "A comment line starts with a hash sign (<quote>#</quote>) or a semicolon " "(<quote>;</quote>). Inline comments are not supported." msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:50 +#: sssd.conf.5.xml:55 msgid "" "All sections can have an optional <replaceable>description</replaceable> " "parameter. Its function is only as a label for the section." msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:56 +#: sssd.conf.5.xml:61 msgid "" "<filename>sssd.conf</filename> must be a regular file that is owned, " "readable, and writeable only by 'root'." msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:60 +#: sssd.conf.5.xml:65 msgid "" "<filename>sssd.conf</filename> must be a regular file that is accessible " "only by the user used to run SSSD service or root." msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:66 +#: sssd.conf.5.xml:71 msgid "CONFIGURATION SNIPPETS FROM INCLUDE DIRECTORY" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:69 +#: sssd.conf.5.xml:74 msgid "" "The configuration file <filename>sssd.conf</filename> will include " "configuration snippets using the include directory <filename>conf.d</" @@ -135,7 +138,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:75 +#: sssd.conf.5.xml:80 msgid "" "Any file placed in <filename>conf.d</filename> that ends in " "<quote><filename>.conf</filename></quote> and does not begin with a dot " @@ -144,7 +147,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:83 +#: sssd.conf.5.xml:88 msgid "" "The configuration snippets from <filename>conf.d</filename> have higher " "priority than <filename>sssd.conf</filename> and will override " @@ -157,39 +160,88 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:97 +#: sssd.conf.5.xml:102 msgid "" "The snippet files require the same owner and permissions as " "<filename>sssd.conf</filename>." msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:103 +#: sssd.conf.5.xml:108 +msgid "VENDOR PROVIDED CONFIGURATION" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:111 +msgid "" +"The vendor provided configuration file is installed in " +"<filename>&sssd_vendor_dir;/sssd.conf</filename>, but this file must not be " +"directly edited. It can be completely masked by creating the system specific " +"configuration file <filename>&sssd_conf_dir;/sssd.conf</filename>, or partly " +"overriden by creating config snippets in <filename>&sssd_conf_dir;/conf.d</" +"filename> directory." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><title> +#: sssd.conf.5.xml:120 +msgid "CONFIGURATION FILE HIERARCHY" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:122 +msgid "" +"When sssd reads the configuration it first tries to open the system specific " +"configuration file in <filename>&sssd_conf_dir;/sssd.conf</filename>. If it " +"exists, it is loaded and snippets from <filename>&sssd_conf_dir;/conf.d</" +"filename> are applied. The vendor provided configuration file " +"<filename>&sssd_vendor_dir;/sssd.conf</filename> is completely ignored in " +"this case." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:131 +msgid "" +"If the system specific configuration file <filename>&sssd_conf_dir;/" +"sssd.conf</filename> does not exist, then the vendor configuration file " +"<filename>&sssd_vendor_dir;/sssd.conf</filename> is loaded and snippets from " +"<filename>&sssd_conf_dir;/conf.d</filename> are applied." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd.conf.5.xml:141 msgid "GENERAL OPTIONS" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:105 +#: sssd.conf.5.xml:143 msgid "Following options are usable in more than one configuration sections." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:109 +#: sssd.conf.5.xml:147 msgid "Options usable in all sections" msgstr "" +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:149 +msgid "" +"Note: Below options are ignored in <quote>[session_recording]</quote> " +"section, see <quote>Session recording configuration options</quote> section " +"for more details." +msgstr "" + #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:113 +#: sssd.conf.5.xml:156 msgid "debug_level (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:117 +#: sssd.conf.5.xml:160 msgid "debug (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:120 +#: sssd.conf.5.xml:163 msgid "" "SSSD 1.14 and later also includes the <replaceable>debug</replaceable> alias " "for <replaceable>debug_level</replaceable> as a convenience feature. If both " @@ -198,61 +250,61 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:130 -msgid "debug_timestamps (bool)" +#: sssd.conf.5.xml:173 +msgid "debug_timestamps (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:133 +#: sssd.conf.5.xml:176 msgid "" "Add a timestamp to the debug messages. If journald is enabled for SSSD " "debug logging this option is ignored." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:138 sssd.conf.5.xml:175 sssd.conf.5.xml:337 -#: sssd.conf.5.xml:644 sssd.conf.5.xml:668 sssd.conf.5.xml:875 -#: sssd.conf.5.xml:979 sssd.conf.5.xml:2113 sssd-ldap.5.xml:979 -#: sssd-ldap.5.xml:1134 sssd-ldap.5.xml:1237 sssd-ldap.5.xml:1306 -#: sssd-ldap.5.xml:1714 sssd-ldap.5.xml:1848 sssd-ldap.5.xml:1913 -#: sssd-ipa.5.xml:346 sssd-ad.5.xml:252 sssd-ad.5.xml:367 sssd-ad.5.xml:1180 -#: sssd-ad.5.xml:1382 sssd-krb5.5.xml:358 +#: sssd.conf.5.xml:181 sssd.conf.5.xml:218 sssd.conf.5.xml:380 +#: sssd.conf.5.xml:687 sssd.conf.5.xml:711 sssd.conf.5.xml:827 +#: sssd.conf.5.xml:932 sssd.conf.5.xml:2149 sssd.conf.5.xml:4730 +#: sssd-ldap.5.xml:979 sssd-ldap.5.xml:1134 sssd-ldap.5.xml:1237 +#: sssd-ldap.5.xml:1306 sssd-ldap.5.xml:1714 sssd-ldap.5.xml:1848 +#: sssd-ldap.5.xml:1913 sssd-ipa.5.xml:341 sssd-ad.5.xml:252 sssd-ad.5.xml:367 +#: sssd-ad.5.xml:1180 sssd-ad.5.xml:1375 sssd-krb5.5.xml:358 msgid "Default: true" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:143 -msgid "debug_microseconds (bool)" +#: sssd.conf.5.xml:186 +msgid "debug_microseconds (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:146 +#: sssd.conf.5.xml:189 msgid "" "Add microseconds to the timestamp in debug messages. If journald is enabled " "for SSSD debug logging this option is ignored." msgstr "" #. type: Content of: <variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:151 sssd.conf.5.xml:2040 sssd.conf.5.xml:4158 +#: sssd.conf.5.xml:194 sssd.conf.5.xml:2072 sssd.conf.5.xml:4363 #: sssd-ldap.5.xml:363 sssd-ldap.5.xml:998 sssd-ldap.5.xml:1209 -#: sssd-ldap.5.xml:1663 sssd-ldap.5.xml:1937 sssd-ipa.5.xml:146 -#: sssd-ipa.5.xml:706 sssd-ad.5.xml:1135 sssd-krb5.5.xml:268 +#: sssd-ldap.5.xml:1663 sssd-ldap.5.xml:1937 sssd-ipa.5.xml:141 +#: sssd-ipa.5.xml:701 sssd-ad.5.xml:1140 sssd-idp.5.xml:287 sssd-krb5.5.xml:268 #: sssd-krb5.5.xml:330 sssd-krb5.5.xml:432 include/krb5_options.xml:163 msgid "Default: false" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:156 -msgid "debug_backtrace_enabled (bool)" +#: sssd.conf.5.xml:199 +msgid "debug_backtrace_enabled (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:159 +#: sssd.conf.5.xml:202 msgid "Enable debug backtrace." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:162 +#: sssd.conf.5.xml:205 msgid "" "In case SSSD is run with debug_level less than 9, everything is logged to a " "ring buffer in memory and flushed to a log file on any error up to and " @@ -262,14 +314,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:171 +#: sssd.conf.5.xml:214 msgid "" "Feature is only supported for `logger == files` (i.e. setting doesn't have " "effect for other logger types)." msgstr "" #. type: Content of: outside any tag (error?) -#: sssd.conf.5.xml:111 sssd.conf.5.xml:186 sssd-ldap.5.xml:1754 +#: sssd.conf.5.xml:154 sssd.conf.5.xml:229 sssd-ldap.5.xml:1754 #: sssd-ldap.5.xml:1960 sss-certmap.5.xml:645 sssd-systemtap.5.xml:82 #: sssd-systemtap.5.xml:143 sssd-systemtap.5.xml:236 sssd-systemtap.5.xml:274 #: sssd-systemtap.5.xml:330 sssd-ldap-attributes.5.xml:40 @@ -282,17 +334,17 @@ msgid "<placeholder type=\"variablelist\" id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:184 +#: sssd.conf.5.xml:227 msgid "Options usable in SERVICE and DOMAIN sections" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:188 +#: sssd.conf.5.xml:231 msgid "timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:191 +#: sssd.conf.5.xml:234 msgid "" "Timeout in seconds between heartbeats for this service. This is used to " "ensure that the process is alive and capable of answering requests. Note " @@ -300,34 +352,36 @@ msgid "" msgstr "" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:198 sssd.conf.5.xml:1199 sssd.conf.5.xml:1673 -#: sssd.conf.5.xml:4174 sssd-ldap.5.xml:825 sssd-idp.5.xml:192 +#: sssd.conf.5.xml:241 sssd.conf.5.xml:1155 sssd.conf.5.xml:1665 +#: sssd.conf.5.xml:4379 sssd-ldap.5.xml:825 sssd-idp.5.xml:271 #: include/ldap_id_mapping.xml:270 msgid "Default: 10" msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:208 +#: sssd.conf.5.xml:251 msgid "SPECIAL SECTIONS" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:211 +#: sssd.conf.5.xml:254 msgid "The [sssd] section" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><title> -#: sssd.conf.5.xml:220 +#: sssd.conf.5.xml:263 msgid "Section parameters" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:222 -msgid "services" +#: sssd.conf.5.xml:265 +#, fuzzy +#| msgid "services" +msgid "services (string)" msgstr "服务" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:225 +#: sssd.conf.5.xml:268 msgid "" "Comma separated list of services that are started when sssd itself starts. " "<phrase condition=\"have_systemd\"> The services' list is optional on " @@ -336,7 +390,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:234 +#: sssd.conf.5.xml:277 msgid "" "Supported services: nss, pam, ifp <phrase condition=\"with_sudo\">, sudo</" "phrase> <phrase condition=\"with_autofs\">, autofs</phrase> <phrase " @@ -345,20 +399,20 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:241 +#: sssd.conf.5.xml:284 msgid "" "<phrase condition=\"have_systemd\"> By default, all services are disabled " "and the administrator must enable the ones allowed to be used by executing: " "\"systemctl enable sssd-@service@.socket\". </phrase>" msgstr "" -#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:250 -msgid "domains" +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sssd.conf.5.xml:293 sssd.conf.5.xml:4562 +msgid "domains (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:253 +#: sssd.conf.5.xml:296 msgid "" "A domain is a database containing user information. SSSD can use more " "domains at the same time, but at least one must be configured or SSSD won't " @@ -369,19 +423,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:266 sssd.conf.5.xml:3467 +#: sssd.conf.5.xml:309 sssd.conf.5.xml:3598 msgid "re_expression (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:269 +#: sssd.conf.5.xml:312 msgid "" "Default regular expression that describes how to parse the string containing " "user name and domain into these components." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:274 +#: sssd.conf.5.xml:317 msgid "" "Each domain can have an individual regular expression configured. For some " "ID providers there are also default regular expressions. See DOMAIN SECTIONS " @@ -389,12 +443,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:283 sssd.conf.5.xml:3524 +#: sssd.conf.5.xml:326 sssd.conf.5.xml:3655 msgid "full_name_format (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:286 sssd.conf.5.xml:3527 +#: sssd.conf.5.xml:329 sssd.conf.5.xml:3658 msgid "" "A <citerefentry> <refentrytitle>printf</refentrytitle> <manvolnum>3</" "manvolnum> </citerefentry>-compatible format that describes how to compose a " @@ -402,70 +456,70 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:297 sssd.conf.5.xml:3538 +#: sssd.conf.5.xml:340 sssd.conf.5.xml:3669 msgid "%1$s" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:298 sssd.conf.5.xml:3539 +#: sssd.conf.5.xml:341 sssd.conf.5.xml:3670 msgid "user name" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:301 sssd.conf.5.xml:3542 +#: sssd.conf.5.xml:344 sssd.conf.5.xml:3673 msgid "%2$s" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:304 sssd.conf.5.xml:3545 +#: sssd.conf.5.xml:347 sssd.conf.5.xml:3676 msgid "domain name as specified in the SSSD config file." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:310 sssd.conf.5.xml:3551 +#: sssd.conf.5.xml:353 sssd.conf.5.xml:3682 msgid "%3$s" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:313 sssd.conf.5.xml:3554 +#: sssd.conf.5.xml:356 sssd.conf.5.xml:3685 msgid "" "domain flat name. Mostly usable for Active Directory domains, both directly " "configured or discovered via IPA trusts." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:294 sssd.conf.5.xml:3535 +#: sssd.conf.5.xml:337 sssd.conf.5.xml:3666 msgid "" "The following expansions are supported: <placeholder type=\"variablelist\" " "id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:323 +#: sssd.conf.5.xml:366 msgid "" "Each domain can have an individual format string configured. See DOMAIN " "SECTIONS for more info on this option." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:329 +#: sssd.conf.5.xml:372 msgid "monitor_resolv_conf (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:332 +#: sssd.conf.5.xml:375 msgid "" "Controls if SSSD should monitor the state of resolv.conf to identify when it " "needs to update its internal DNS resolver." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:342 +#: sssd.conf.5.xml:385 msgid "try_inotify (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:345 +#: sssd.conf.5.xml:388 msgid "" "By default, SSSD will attempt to use inotify to monitor configuration files " "changes and will fall back to polling every five seconds if inotify cannot " @@ -473,7 +527,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:351 +#: sssd.conf.5.xml:394 msgid "" "There are some limited situations where it is preferred that we should skip " "even trying to use inotify. In these rare cases, this option should be set " @@ -481,59 +535,59 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:357 +#: sssd.conf.5.xml:400 msgid "" "Default: true on platforms where inotify is supported. False on other " "platforms." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:361 +#: sssd.conf.5.xml:404 msgid "" "Note: this option will have no effect on platforms where inotify is " "unavailable. On these platforms, polling will always be used." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:368 +#: sssd.conf.5.xml:411 msgid "krb5_rcache_dir (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:371 +#: sssd.conf.5.xml:414 msgid "" "Directory on the filesystem where SSSD should store Kerberos replay cache " "files." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:375 +#: sssd.conf.5.xml:418 msgid "" "This option accepts a special value __LIBKRB5_DEFAULTS__ that will instruct " "SSSD to let libkrb5 decide the appropriate location for the replay cache." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:381 +#: sssd.conf.5.xml:424 msgid "" "Default: Distribution-specific and specified at build-time. " "(__LIBKRB5_DEFAULTS__ if not configured)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:388 +#: sssd.conf.5.xml:431 msgid "default_domain_suffix (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:391 +#: sssd.conf.5.xml:434 msgid "" "Please note that this option is deprecated and domain_resolution_order " "should be used." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:395 +#: sssd.conf.5.xml:438 msgid "" "This string will be used as a default domain name for all names without a " "domain name component. The main use case is environments where the primary " @@ -543,7 +597,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:405 +#: sssd.conf.5.xml:448 msgid "" "Please note that if this option is set all users from the primary domain " "have to use their fully qualified name, e.g. user@domain.name, to log in. " @@ -553,21 +607,21 @@ msgid "" msgstr "" #. type: Content of: <variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:414 sssd-ldap.5.xml:937 sssd-ldap.5.xml:949 -#: sssd-ldap.5.xml:1042 sssd-ad.5.xml:921 sssd-ad.5.xml:996 sssd-krb5.5.xml:468 -#: sssd-ldap-attributes.5.xml:470 sssd-ldap-attributes.5.xml:978 -#: include/ldap_id_mapping.xml:211 include/ldap_id_mapping.xml:222 -#: include/krb5_options.xml:148 +#: sssd.conf.5.xml:457 sssd.conf.5.xml:2006 sssd-ldap.5.xml:937 +#: sssd-ldap.5.xml:949 sssd-ldap.5.xml:1042 sssd-ad.5.xml:926 +#: sssd-ad.5.xml:1001 sssd-krb5.5.xml:468 sssd-ldap-attributes.5.xml:470 +#: sssd-ldap-attributes.5.xml:978 include/ldap_id_mapping.xml:211 +#: include/ldap_id_mapping.xml:222 include/krb5_options.xml:148 msgid "Default: not set" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:419 +#: sssd.conf.5.xml:462 msgid "override_space (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:422 +#: sssd.conf.5.xml:465 msgid "" "This parameter will replace spaces (space bar) with the given character for " "user and group names. e.g. (_). User name "john doe" will be " @@ -577,7 +631,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:431 +#: sssd.conf.5.xml:474 msgid "" "Please note it is a configuration error to use a replacement character that " "might be used in user or group names. If a name contains the replacement " @@ -586,22 +640,22 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:439 +#: sssd.conf.5.xml:482 msgid "Default: not set (spaces will not be replaced)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:444 +#: sssd.conf.5.xml:487 msgid "certificate_verification (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:452 +#: sssd.conf.5.xml:495 msgid "no_ocsp" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:454 +#: sssd.conf.5.xml:497 msgid "" "Disables Online Certificate Status Protocol (OCSP) checks. This might be " "needed if the OCSP servers defined in the certificate are not reachable from " @@ -609,12 +663,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:462 +#: sssd.conf.5.xml:505 msgid "soft_ocsp" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:464 +#: sssd.conf.5.xml:507 msgid "" "If a connection cannot be established to an OCSP responder the OCSP check is " "skipped. This option should be used to allow authentication when the system " @@ -622,61 +676,61 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:474 +#: sssd.conf.5.xml:517 msgid "ocsp_dgst" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:476 +#: sssd.conf.5.xml:519 msgid "" "Digest (hash) function used to create the certificate ID for the OCSP " "request. Allowed values are:" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:480 +#: sssd.conf.5.xml:523 msgid "sha1" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:481 +#: sssd.conf.5.xml:524 msgid "sha256" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:482 +#: sssd.conf.5.xml:525 msgid "sha384" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:483 +#: sssd.conf.5.xml:526 msgid "sha512" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:486 +#: sssd.conf.5.xml:529 msgid "Default: sha1 (to allow compatibility with RFC5019-compliant responder)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:492 +#: sssd.conf.5.xml:535 msgid "no_verification" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:494 +#: sssd.conf.5.xml:537 msgid "" "Disables verification completely. This option should only be used for " "testing." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:500 +#: sssd.conf.5.xml:543 msgid "partial_chain" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:502 +#: sssd.conf.5.xml:545 msgid "" "Allow verification to succeed even if a <replaceable>complete</replaceable> " "chain cannot be built to a self-signed trust-anchor, provided it is possible " @@ -684,12 +738,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:511 +#: sssd.conf.5.xml:554 msgid "ocsp_default_responder=URL" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:513 +#: sssd.conf.5.xml:556 msgid "" "Sets the OCSP default responder which should be used instead of the one " "mentioned in the certificate. URL must be replaced with the URL of the OCSP " @@ -697,24 +751,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:523 +#: sssd.conf.5.xml:566 msgid "ocsp_default_responder_signing_cert=NAME" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:525 +#: sssd.conf.5.xml:568 msgid "" "This option is currently ignored. All needed certificates must be available " "in the PEM file given by pam_cert_db_path." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:533 +#: sssd.conf.5.xml:576 msgid "crl_file=/PATH/TO/CRL/FILE" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:535 +#: sssd.conf.5.xml:578 msgid "" "Use the Certificate Revocation List (CRL) from the given file during the " "verification of the certificate. The CRL must be given in PEM format, see " @@ -723,12 +777,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:548 +#: sssd.conf.5.xml:591 msgid "soft_crl" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:551 +#: sssd.conf.5.xml:594 msgid "" "If a Certificate Revocation List (CRL) is expired ignore the expiration " "time of the CRL and check the related certificates with the expired CRL. " @@ -737,7 +791,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:447 +#: sssd.conf.5.xml:490 msgid "" "With this parameter the certificate verification can be tuned with a comma " "separated list of options. Supported options are: <placeholder " @@ -745,46 +799,46 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:564 +#: sssd.conf.5.xml:607 msgid "Unknown options are reported but ignored." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:567 +#: sssd.conf.5.xml:610 msgid "Default: not set, i.e. do not restrict certificate verification" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:573 +#: sssd.conf.5.xml:616 msgid "disable_netlink (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:576 +#: sssd.conf.5.xml:619 msgid "" "SSSD hooks into the netlink interface to monitor changes to routes, " "addresses, links and trigger certain actions." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:581 +#: sssd.conf.5.xml:624 msgid "" "The SSSD state changes caused by netlink events may be undesirable and can " "be disabled by setting this option to 'true'" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:586 +#: sssd.conf.5.xml:629 msgid "Default: false (netlink changes are detected)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:591 -msgid "domain_resolution_order" +#: sssd.conf.5.xml:634 +msgid "domain_resolution_order (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:594 +#: sssd.conf.5.xml:637 msgid "" "Comma separated list of domains and subdomains representing the lookup order " "that will be followed. The list doesn't have to include all possible " @@ -795,7 +849,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:606 +#: sssd.conf.5.xml:649 msgid "" "Please, note that when this option is set the output format of all commands " "is always fully-qualified even when using short names for input. In case " @@ -811,19 +865,20 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:630 sssd.conf.5.xml:1697 sssd.conf.5.xml:4224 -#: sssd-ad.5.xml:187 sssd-ad.5.xml:328 sssd-ad.5.xml:342 sssd-idp.5.xml:108 -#: sssd-idp.5.xml:132 sssd-idp.5.xml:145 sssd-idp.5.xml:159 sssd-idp.5.xml:180 +#: sssd.conf.5.xml:673 sssd.conf.5.xml:1026 sssd.conf.5.xml:1689 +#: sssd.conf.5.xml:4429 sssd-ad.5.xml:187 sssd-ad.5.xml:328 sssd-ad.5.xml:342 +#: sssd-idp.5.xml:112 sssd-idp.5.xml:136 sssd-idp.5.xml:149 sssd-idp.5.xml:167 +#: sssd-idp.5.xml:188 msgid "Default: Not set" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:635 +#: sssd.conf.5.xml:678 msgid "implicit_pac_responder (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:638 +#: sssd.conf.5.xml:681 msgid "" "The PAC responder is enabled automatically for the IPA and AD provider to " "evaluate and check the PAC. If it has to be disabled set this option to " @@ -831,12 +886,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:649 +#: sssd.conf.5.xml:692 msgid "core_dumpable (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:652 +#: sssd.conf.5.xml:695 msgid "" "This option can be used for general system hardening: setting it to 'false' " "forbids core dumps for all SSSD processes to avoid leaking plain text " @@ -845,7 +900,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:660 +#: sssd.conf.5.xml:703 msgid "" "Take a note that this setting has no effect for 'ldap_child', 'krb5_child' " "and 'sssd_pam' as those privileged binaries can have a copy of a host keytab " @@ -854,24 +909,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:673 +#: sssd.conf.5.xml:716 msgid "passkey_verification (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:681 +#: sssd.conf.5.xml:724 msgid "user_verification (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:683 +#: sssd.conf.5.xml:726 msgid "" "Enable or disable the user verification (i.e. PIN, fingerprint) during " "authentication. If enabled, the PIN will always be requested." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:689 +#: sssd.conf.5.xml:732 msgid "" "The default is that the key settings decide what to do. In the IPA or " "kerberos pre-authentication case, this value will be overwritten by the " @@ -879,7 +934,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:676 +#: sssd.conf.5.xml:719 msgid "" "With this parameter the passkey verification can be tuned with a comma " "separated list of options. Supported options are: <placeholder " @@ -887,7 +942,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:213 +#: sssd.conf.5.xml:256 msgid "" "Individual pieces of SSSD functionality are provided by special SSSD " "services that are started and stopped together with SSSD. The services are " @@ -898,12 +953,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:708 +#: sssd.conf.5.xml:751 msgid "SERVICES SECTIONS" msgstr "服务部分" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:710 +#: sssd.conf.5.xml:753 msgid "" "Settings that can be used to configure different services are described in " "this section. They should reside in the [<replaceable>$NAME</replaceable>] " @@ -912,42 +967,41 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:717 +#: sssd.conf.5.xml:760 msgid "General service configuration options" msgstr "基本服务配置选项" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:719 +#: sssd.conf.5.xml:762 msgid "These options can be used to configure any service." msgstr "这些选项可被用于配置任何服务。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:723 -msgid "fd_limit" +#: sssd.conf.5.xml:766 +msgid "fd_limit (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:726 +#: sssd.conf.5.xml:769 msgid "" "This option specifies the maximum number of file descriptors that may be " -"opened at one time by this SSSD process. On systems where SSSD is granted " -"the CAP_SYS_RESOURCE capability, this will be an absolute setting. On " -"systems without this capability, the resulting value will be the lower value " -"of this or the limits.conf \"hard\" limit." +"opened at one time by this SSSD process. Note this value will be capped by " +"the init system at the startup of SSSD, see e.g. man systemd.exec for " +"details." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:735 +#: sssd.conf.5.xml:776 msgid "Default: 8192 (or limits.conf \"hard\" limit)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:740 -msgid "client_idle_timeout" +#: sssd.conf.5.xml:781 +msgid "client_idle_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:743 +#: sssd.conf.5.xml:784 msgid "" "This option specifies the number of seconds that a client of an SSSD process " "can hold onto a file descriptor without communicating on it. This value is " @@ -957,146 +1011,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:752 +#: sssd.conf.5.xml:793 #, fuzzy #| msgid "Default: 3" msgid "Default: 60, KCM: 300" msgstr "默认: 3" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:757 -msgid "offline_timeout (integer)" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:760 -msgid "" -"When SSSD switches to offline mode the amount of time before it tries to go " -"back online will increase based upon the time spent disconnected. By " -"default SSSD uses incremental behaviour to calculate delay in between " -"retries. So, the wait time for a given retry will be longer than the wait " -"time for the previous ones. After each unsuccessful attempt to go online, " -"the new interval is recalculated by the following:" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:771 sssd.conf.5.xml:827 -msgid "" -"new_delay = Minimum(old_delay * 2, offline_timeout_max) + " -"random[0...offline_timeout_random_offset]" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:774 -msgid "" -"The offline_timeout default value is 60. The offline_timeout_max default " -"value is 3600. The offline_timeout_random_offset default value is 30. The " -"end result is amount of seconds before next retry." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:780 -msgid "" -"Note that the maximum length of each interval is defined by " -"offline_timeout_max (apart of random part)." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:784 sssd.conf.5.xml:1110 sssd.conf.5.xml:1490 -#: sssd.conf.5.xml:1791 sssd-ldap.5.xml:550 -msgid "Default: 60" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:789 -msgid "offline_timeout_max (integer)" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:792 -msgid "" -"Controls by how much the time between attempts to go online can be " -"incremented following unsuccessful attempts to go online." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:797 -msgid "A value of 0 disables the incrementing behaviour." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:800 -msgid "" -"The value of this parameter should be set in correlation to offline_timeout " -"parameter value." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:804 -msgid "" -"With offline_timeout set to 60 (default value) there is no point in setting " -"offlinet_timeout_max to less than 120 as it will saturate instantly. General " -"rule here should be to set offline_timeout_max to at least 4 times " -"offline_timeout." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:810 -msgid "" -"Although a value between 0 and offline_timeout may be specified, it has the " -"effect of overriding the offline_timeout value so is of little use." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:815 -#, fuzzy -#| msgid "Default: 3" -msgid "Default: 3600" -msgstr "默认: 3" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:820 -msgid "offline_timeout_random_offset (integer)" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:823 -msgid "" -"When SSSD is in offline mode it keeps probing backend servers in specified " -"time intervals:" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:830 -msgid "" -"This parameter controls the value of the random offset used for the above " -"equation. Final random_offset value will be random number in range:" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:835 -msgid "[0 - offline_timeout_random_offset]" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:838 -msgid "A value of 0 disables the random offset addition." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:841 -#, fuzzy -#| msgid "Default: 3" -msgid "Default: 30" -msgstr "默认: 3" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:846 -msgid "responder_idle_timeout" +#: sssd.conf.5.xml:798 +msgid "responder_idle_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:849 +#: sssd.conf.5.xml:801 msgid "" "This option specifies the number of seconds that an SSSD responder process " "can be up without being used. This value is limited in order to avoid " @@ -1108,58 +1035,59 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:863 sssd.conf.5.xml:1123 sssd.conf.5.xml:2248 +#: sssd.conf.5.xml:815 sssd.conf.5.xml:1079 sssd.conf.5.xml:2285 #: sssd-ldap.5.xml:377 msgid "Default: 300" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:868 -msgid "cache_first" +#: sssd.conf.5.xml:820 +msgid "cache_first (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:871 +#: sssd.conf.5.xml:823 msgid "" "This option specifies whether the responder should query all caches before " "querying the Data Providers." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:883 +#: sssd.conf.5.xml:835 msgid "NSS configuration options" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:885 +#: sssd.conf.5.xml:837 msgid "" -"These options can be used to configure the Name Service Switch (NSS) service." +"These options can be used to configure the Name Service Switch (NSS) service " +"and should be specified under the <quote>[nss]</quote> section." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:890 +#: sssd.conf.5.xml:843 msgid "enum_cache_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:893 +#: sssd.conf.5.xml:846 msgid "" "How many seconds should nss_sss cache enumerations (requests for info about " "all users)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:897 +#: sssd.conf.5.xml:850 msgid "Default: 120" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:902 +#: sssd.conf.5.xml:855 msgid "entry_cache_nowait_percentage (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:905 +#: sssd.conf.5.xml:858 msgid "" "The entry cache can be set to automatically update entries in the background " "if they are requested beyond a percentage of the entry_cache_timeout value " @@ -1167,7 +1095,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:911 +#: sssd.conf.5.xml:864 msgid "" "For example, if the domain's entry_cache_timeout is set to 30s and " "entry_cache_nowait_percentage is set to 50 (percent), entries that come in " @@ -1177,7 +1105,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:921 +#: sssd.conf.5.xml:874 msgid "" "Valid values for this option are 0-99 and represent a percentage of the " "entry_cache_timeout for each domain. For performance reasons, this " @@ -1186,17 +1114,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:929 sssd.conf.5.xml:2061 +#: sssd.conf.5.xml:882 sssd.conf.5.xml:2093 msgid "Default: 50" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:934 +#: sssd.conf.5.xml:887 msgid "entry_negative_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:937 +#: sssd.conf.5.xml:890 msgid "" "Specifies for how many seconds nss_sss should cache negative cache hits " "(that is, queries for invalid database entries, like nonexistent ones) " @@ -1204,17 +1132,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:943 sssd.conf.5.xml:1685 sssd.conf.5.xml:2085 +#: sssd.conf.5.xml:896 sssd.conf.5.xml:1677 sssd.conf.5.xml:2119 msgid "Default: 15" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:948 +#: sssd.conf.5.xml:901 msgid "filter_users, filter_groups (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:951 +#: sssd.conf.5.xml:904 msgid "" "Exclude certain users or groups from being fetched from the sss NSS " "database. This is particularly useful for system accounts. This option can " @@ -1223,7 +1151,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:959 +#: sssd.conf.5.xml:912 msgid "" "NOTE: The filter_groups option doesn't affect inheritance of nested group " "members, since filtering happens after they are propagated for returning via " @@ -1232,41 +1160,41 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:967 +#: sssd.conf.5.xml:920 msgid "Default: root" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:972 -msgid "filter_users_in_groups (bool)" +#: sssd.conf.5.xml:925 +msgid "filter_users_in_groups (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:975 +#: sssd.conf.5.xml:928 msgid "" -"If you want filtered user still be group members set this option to false." +"If you want filtered users to remain group members set this option to false" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:986 +#: sssd.conf.5.xml:939 msgid "fallback_homedir (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:989 +#: sssd.conf.5.xml:942 msgid "" "Set a default template for a user's home directory if one is not specified " "explicitly by the domain's data provider." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:994 +#: sssd.conf.5.xml:947 msgid "" "The available values for this option are the same as for override_homedir." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1000 +#: sssd.conf.5.xml:953 #, no-wrap msgid "" "fallback_homedir = /home/%u\n" @@ -1274,23 +1202,23 @@ msgid "" msgstr "" #. type: Content of: <varlistentry><listitem><para> -#: sssd.conf.5.xml:998 sssd.conf.5.xml:1557 sssd.conf.5.xml:1576 -#: sssd.conf.5.xml:1653 sssd-krb5.5.xml:451 include/override_homedir.xml:78 +#: sssd.conf.5.xml:951 sssd.conf.5.xml:1524 sssd.conf.5.xml:1543 +#: sssd.conf.5.xml:1645 sssd-krb5.5.xml:451 include/override_homedir.xml:78 msgid "example: <placeholder type=\"programlisting\" id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1004 +#: sssd.conf.5.xml:957 msgid "Default: not set (no substitution for unset home directories)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1010 +#: sssd.conf.5.xml:963 msgid "override_shell (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1013 +#: sssd.conf.5.xml:966 msgid "" "Override the login shell for all users. This option supersedes any other " "shell options if it takes effect and can be set either in the [nss] section " @@ -1298,47 +1226,47 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1019 +#: sssd.conf.5.xml:972 msgid "Default: not set (SSSD will use the value retrieved from LDAP)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1025 +#: sssd.conf.5.xml:978 msgid "allowed_shells (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1028 +#: sssd.conf.5.xml:981 msgid "" "Restrict user shell to one of the listed values. The order of evaluation is:" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1031 +#: sssd.conf.5.xml:984 msgid "1. If the shell is present in <quote>/etc/shells</quote>, it is used." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1035 +#: sssd.conf.5.xml:988 msgid "" "2. If the shell is in the allowed_shells list but not in <quote>/etc/shells</" "quote>, use the value of the shell_fallback parameter." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1040 +#: sssd.conf.5.xml:993 msgid "" "3. If the shell is not in the allowed_shells list and not in <quote>/etc/" "shells</quote>, a nologin shell is used." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1045 +#: sssd.conf.5.xml:998 msgid "The wildcard (*) can be used to allow any shell." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1048 +#: sssd.conf.5.xml:1001 msgid "" "The (*) is useful if you want to use shell_fallback in case that user's " "shell is not in <quote>/etc/shells</quote> and maintaining list of all " @@ -1346,113 +1274,119 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1055 +#: sssd.conf.5.xml:1008 msgid "An empty string for shell is passed as-is to libc." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1058 +#: sssd.conf.5.xml:1011 msgid "" "The <quote>/etc/shells</quote> is only read on SSSD start up, which means " "that a restart of the SSSD is required in case a new shell is installed." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1062 +#: sssd.conf.5.xml:1015 msgid "Default: Not set. The user shell is automatically used." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1067 +#: sssd.conf.5.xml:1020 msgid "vetoed_shells (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1070 +#: sssd.conf.5.xml:1023 msgid "Replace any instance of these shells with the shell_fallback" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1075 +#: sssd.conf.5.xml:1031 msgid "shell_fallback (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1078 +#: sssd.conf.5.xml:1034 msgid "" "The default shell to use if an allowed shell is not installed on the machine." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1082 +#: sssd.conf.5.xml:1038 msgid "Default: /bin/sh" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1087 -msgid "default_shell" +#: sssd.conf.5.xml:1043 +msgid "default_shell (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1090 +#: sssd.conf.5.xml:1046 msgid "" "The default shell to use if the provider does not return one during lookup. " "This option can be specified globally in the [nss] section or per-domain." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1096 +#: sssd.conf.5.xml:1052 msgid "" "Default: not set (Return NULL if no shell is specified and rely on libc to " "substitute something sensible when necessary, usually /bin/sh)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1103 sssd.conf.5.xml:1483 +#: sssd.conf.5.xml:1059 sssd.conf.5.xml:1450 msgid "get_domains_timeout (int)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1106 sssd.conf.5.xml:1486 +#: sssd.conf.5.xml:1062 sssd.conf.5.xml:1453 msgid "" "Specifies time in seconds for which the list of subdomains will be " "considered valid." msgstr "" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1066 sssd.conf.5.xml:1457 sssd.conf.5.xml:1788 +#: sssd.conf.5.xml:2862 sssd-ldap.5.xml:550 +msgid "Default: 60" +msgstr "" + #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1115 +#: sssd.conf.5.xml:1071 msgid "memcache_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1118 +#: sssd.conf.5.xml:1074 msgid "" "Specifies time in seconds for which records in the in-memory cache will be " "valid. Setting this option to zero will disable the in-memory cache." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1126 +#: sssd.conf.5.xml:1082 msgid "" "WARNING: Disabling the in-memory cache will have significant negative impact " "on SSSD's performance and should only be used for testing." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1132 sssd.conf.5.xml:1157 sssd.conf.5.xml:1182 -#: sssd.conf.5.xml:1207 sssd.conf.5.xml:1234 +#: sssd.conf.5.xml:1088 sssd.conf.5.xml:1113 sssd.conf.5.xml:1138 +#: sssd.conf.5.xml:1163 sssd.conf.5.xml:1190 msgid "" "NOTE: If the environment variable SSS_NSS_USE_MEMCACHE is set to \"NO\", " "client applications will not use the fast in-memory cache." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1140 +#: sssd.conf.5.xml:1096 msgid "memcache_size_passwd (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1143 +#: sssd.conf.5.xml:1099 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for passwd requests. Setting the size to 0 will disable the passwd in-" @@ -1460,25 +1394,25 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1149 sssd.conf.5.xml:2888 sssd-ldap.5.xml:604 +#: sssd.conf.5.xml:1105 sssd.conf.5.xml:3013 sssd-ldap.5.xml:604 msgid "Default: 8" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1152 sssd.conf.5.xml:1177 sssd.conf.5.xml:1202 -#: sssd.conf.5.xml:1229 +#: sssd.conf.5.xml:1108 sssd.conf.5.xml:1133 sssd.conf.5.xml:1158 +#: sssd.conf.5.xml:1185 msgid "" "WARNING: Disabled or too small in-memory cache can have significant negative " "impact on SSSD's performance." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1165 +#: sssd.conf.5.xml:1121 msgid "memcache_size_group (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1168 +#: sssd.conf.5.xml:1124 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for group requests. Setting the size to 0 will disable the group in-memory " @@ -1486,19 +1420,19 @@ msgid "" msgstr "" #. type: Content of: <variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1174 sssd.conf.5.xml:1226 sssd.conf.5.xml:3656 +#: sssd.conf.5.xml:1130 sssd.conf.5.xml:1182 sssd.conf.5.xml:3835 #: sssd-ldap.5.xml:534 sssd-ldap.5.xml:581 include/failover.xml:116 #: include/krb5_options.xml:11 msgid "Default: 6" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1190 +#: sssd.conf.5.xml:1146 msgid "memcache_size_initgroups (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1193 +#: sssd.conf.5.xml:1149 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for initgroups requests. Setting the size to 0 will disable the initgroups " @@ -1506,12 +1440,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1215 +#: sssd.conf.5.xml:1171 msgid "memcache_size_sid (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1218 +#: sssd.conf.5.xml:1174 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for SID related requests. Only SID-by-ID and ID-by-SID requests are " @@ -1520,12 +1454,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1242 sssd-ifp.5.xml:90 +#: sssd.conf.5.xml:1198 sssd-ifp.5.xml:90 msgid "user_attributes (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1245 +#: sssd.conf.5.xml:1201 msgid "" "Some of the additional NSS responder requests can return more attributes " "than just the POSIX ones defined by the NSS interface. The list of " @@ -1536,103 +1470,109 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1258 +#: sssd.conf.5.xml:1214 msgid "" "To make configuration more easy the NSS responder will check the InfoPipe " "option if it is not set for the NSS responder." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1263 +#: sssd.conf.5.xml:1219 msgid "Default: not set, fallback to InfoPipe option" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1268 +#: sssd.conf.5.xml:1224 msgid "pwfield (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1271 +#: sssd.conf.5.xml:1227 msgid "" "The value that NSS operations that return users or groups will return for " "the <quote>password</quote> field." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1276 -msgid "Default: <quote>*</quote>" +#: sssd.conf.5.xml:1232 +msgid "" +"This option can also be set per-domain, which overwrites the value in the " +"<quote>[nss]</quote> section for that domain. This is particularly useful " +"when using a proxy domain with <option>proxy_lib_name=files</option> and a " +"<option>proxy_pam_target</option> other than <quote>sssd-shadowutils</" +"quote>. In that case, SSSD returns <quote>*</quote> for the password field " +"by default, which causes <command>pam_unix</command> to treat all accounts " +"as locked. Setting <option>pwfield = x</option> in the domain section " +"restores the expected behavior." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1279 -msgid "" -"Note: This option can also be set per-domain which overwrites the value in " -"[nss] section." +#: sssd.conf.5.xml:1246 +msgid "Default: <quote>*</quote>" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1283 +#: sssd.conf.5.xml:1249 msgid "" -"Default: <quote>not set</quote> (remote domains), <quote>x</quote> (proxy " -"domain with nss_files and sssd-shadowutils target)" +"Default (per-domain): <quote>not set</quote> (remote domains), <quote>x</" +"quote> (proxy domain with nss_files and sssd-shadowutils target)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:1292 +#: sssd.conf.5.xml:1258 msgid "PAM configuration options" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:1294 +#: sssd.conf.5.xml:1260 msgid "" "These options can be used to configure the Pluggable Authentication Module " -"(PAM) service." +"(PAM) service and should be specified under the <quote>[pam]</quote> section." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1299 +#: sssd.conf.5.xml:1266 msgid "offline_credentials_expiration (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1302 +#: sssd.conf.5.xml:1269 msgid "" "If the authentication provider is offline, how long should we allow cached " "logins (in days since the last successful online login)." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1307 sssd.conf.5.xml:1320 +#: sssd.conf.5.xml:1274 sssd.conf.5.xml:1287 msgid "Default: 0 (No limit)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1313 +#: sssd.conf.5.xml:1280 msgid "offline_failed_login_attempts (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1316 +#: sssd.conf.5.xml:1283 msgid "" "If the authentication provider is offline, how many failed login attempts " "are allowed." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1326 +#: sssd.conf.5.xml:1293 msgid "offline_failed_login_delay (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1329 +#: sssd.conf.5.xml:1296 msgid "" "The time in minutes which has to pass after offline_failed_login_attempts " "has been reached before a new login attempt is possible." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1334 +#: sssd.conf.5.xml:1301 msgid "" "If set to 0 the user cannot authenticate offline if " "offline_failed_login_attempts has been reached. Only a successful online " @@ -1640,59 +1580,59 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1340 sssd.conf.5.xml:1450 +#: sssd.conf.5.xml:1307 sssd.conf.5.xml:1417 msgid "Default: 5" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1346 +#: sssd.conf.5.xml:1313 msgid "pam_verbosity (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1349 +#: sssd.conf.5.xml:1316 msgid "" "Controls what kind of messages are shown to the user during authentication. " "The higher the number to more messages are displayed." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1354 +#: sssd.conf.5.xml:1321 msgid "Currently sssd supports the following values:" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1357 +#: sssd.conf.5.xml:1324 msgid "<emphasis>0</emphasis>: do not show any message" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1360 +#: sssd.conf.5.xml:1327 msgid "<emphasis>1</emphasis>: show only important messages" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1364 +#: sssd.conf.5.xml:1331 msgid "<emphasis>2</emphasis>: show informational messages" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1367 +#: sssd.conf.5.xml:1334 msgid "<emphasis>3</emphasis>: show all messages and debug information" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1371 sssd.8.xml:63 +#: sssd.conf.5.xml:1338 sssd.8.xml:63 msgid "Default: 1" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1377 +#: sssd.conf.5.xml:1344 msgid "pam_response_filter (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1380 +#: sssd.conf.5.xml:1347 msgid "" "A comma separated list of strings which allows to remove (filter) data sent " "by the PAM responder to pam_sss PAM module. There are different kind of " @@ -1701,51 +1641,51 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1388 +#: sssd.conf.5.xml:1355 msgid "" "While messages already can be controlled with the help of the pam_verbosity " "option this option allows to filter out other kind of responses as well." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1395 +#: sssd.conf.5.xml:1362 msgid "ENV" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1396 +#: sssd.conf.5.xml:1363 msgid "Do not send any environment variables to any service." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1399 +#: sssd.conf.5.xml:1366 msgid "ENV:var_name" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1400 +#: sssd.conf.5.xml:1367 msgid "Do not send environment variable var_name to any service." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1404 +#: sssd.conf.5.xml:1371 msgid "ENV:var_name:service" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1405 +#: sssd.conf.5.xml:1372 msgid "Do not send environment variable var_name to service." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1393 +#: sssd.conf.5.xml:1360 msgid "" "Currently the following filters are supported: <placeholder " "type=\"variablelist\" id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1412 +#: sssd.conf.5.xml:1379 msgid "" "The list of strings can either be the list of filters which would set this " "list of filters and overwrite the defaults. Or each element of the list can " @@ -1756,23 +1696,23 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1423 +#: sssd.conf.5.xml:1390 msgid "Default: ENV:KRB5CCNAME:sudo, ENV:KRB5CCNAME:sudo-i" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1426 +#: sssd.conf.5.xml:1393 msgid "" "Example: -ENV:KRB5CCNAME:sudo-i will remove the filter from the default list" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1433 +#: sssd.conf.5.xml:1400 msgid "pam_id_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1436 +#: sssd.conf.5.xml:1403 msgid "" "For any PAM request while SSSD is online, the SSSD will attempt to " "immediately update the cached identity information for the user in order to " @@ -1780,7 +1720,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1442 +#: sssd.conf.5.xml:1409 msgid "" "A complete PAM conversation may perform multiple PAM requests, such as " "account management and session opening. This option controls (on a per-" @@ -1789,17 +1729,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1456 +#: sssd.conf.5.xml:1423 msgid "pam_pwd_expiration_warning (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1459 sssd.conf.5.xml:2912 +#: sssd.conf.5.xml:1426 sssd.conf.5.xml:3037 msgid "Display a warning N days before the password expires." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1462 +#: sssd.conf.5.xml:1429 msgid "" "Please note that the backend server has to provide information about the " "expiration time of the password. If this information is missing, sssd " @@ -1807,32 +1747,32 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1468 sssd.conf.5.xml:2915 +#: sssd.conf.5.xml:1435 sssd.conf.5.xml:3040 msgid "" "If zero is set, then this filter is not applied, i.e. if the expiration " "warning was received from backend server, it will automatically be displayed." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1473 +#: sssd.conf.5.xml:1440 msgid "" "This setting can be overridden by setting <emphasis>pwd_expiration_warning</" "emphasis> for a particular domain." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1478 sssd.conf.5.xml:3913 sssd-ldap.5.xml:662 +#: sssd.conf.5.xml:1445 sssd.conf.5.xml:4118 sssd-ldap.5.xml:662 #: sssd-ldap.5.xml:1733 sssd.8.xml:79 msgid "Default: 0" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1495 +#: sssd.conf.5.xml:1462 msgid "pam_trusted_users (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1498 +#: sssd.conf.5.xml:1465 msgid "" "Specifies the comma-separated list of UID values or user names that are " "allowed to run PAM conversations against trusted domains. Users not " @@ -1842,74 +1782,74 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1508 +#: sssd.conf.5.xml:1475 msgid "Default: All users are considered trusted by default" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1512 +#: sssd.conf.5.xml:1479 msgid "" "Please note that UID 0 is always allowed to access the PAM responder even in " "case it is not in the pam_trusted_users list." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1519 +#: sssd.conf.5.xml:1486 msgid "pam_public_domains (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1522 +#: sssd.conf.5.xml:1489 msgid "" "Specifies the comma-separated list of domain names that are accessible even " "to untrusted users." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1526 +#: sssd.conf.5.xml:1493 msgid "Two special values for pam_public_domains option are defined:" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1530 +#: sssd.conf.5.xml:1497 msgid "" "all (Untrusted users are allowed to access all domains in PAM responder.)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1534 +#: sssd.conf.5.xml:1501 msgid "" "none (Untrusted users are not allowed to access any domains PAM in " "responder.)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1538 sssd.conf.5.xml:1563 sssd.conf.5.xml:1582 -#: sssd.conf.5.xml:1824 sssd.conf.5.xml:3842 sssd-ldap.5.xml:1270 +#: sssd.conf.5.xml:1505 sssd.conf.5.xml:1530 sssd.conf.5.xml:1549 +#: sssd.conf.5.xml:1821 sssd.conf.5.xml:4048 sssd-ldap.5.xml:1270 msgid "Default: none" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1543 +#: sssd.conf.5.xml:1510 msgid "pam_account_expired_message (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1546 +#: sssd.conf.5.xml:1513 msgid "" "Allows a custom expiration message to be set, replacing the default " "'Permission denied' message." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1551 +#: sssd.conf.5.xml:1518 msgid "" "Note: Please be aware that message is only printed for the SSH service " "unless pam_verbosity is set to 3 (show all messages and debug information)." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1559 +#: sssd.conf.5.xml:1526 #, no-wrap msgid "" "pam_account_expired_message = Account expired, please contact help desk.\n" @@ -1917,19 +1857,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1568 +#: sssd.conf.5.xml:1535 msgid "pam_account_locked_message (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1571 +#: sssd.conf.5.xml:1538 msgid "" "Allows a custom lockout message to be set, replacing the default 'Permission " "denied' message." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1578 +#: sssd.conf.5.xml:1545 #, no-wrap msgid "" "pam_account_locked_message = Account locked, please contact help desk.\n" @@ -1937,81 +1877,120 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1587 -msgid "pam_passkey_auth (bool)" +#: sssd.conf.5.xml:1554 +msgid "pam_passkey_auth (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1590 +#: sssd.conf.5.xml:1557 msgid "Enable passkey device based authentication." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1593 sssd.conf.5.xml:1910 sssd-ad.5.xml:1286 +#: sssd.conf.5.xml:1560 sssd.conf.5.xml:1907 sssd-ad.5.xml:1279 #: sss_rpcidmapd.5.xml:76 msgid "Default: True" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1598 -msgid "passkey_debug_libfido2 (bool)" +#: sssd.conf.5.xml:1565 +msgid "passkey_debug_libfido2 (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1601 +#: sssd.conf.5.xml:1568 msgid "Enable libfido2 library debug messages." msgstr "" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1604 sssd.conf.5.xml:1618 sssd-ldap.5.xml:727 -#: sssd-ldap.5.xml:752 sssd-ldap.5.xml:848 sssd-ldap.5.xml:1356 -#: sssd-ad.5.xml:506 sssd-ad.5.xml:582 sssd-ad.5.xml:1155 +#: sssd.conf.5.xml:1571 sssd.conf.5.xml:1585 sssd.conf.5.xml:4781 +#: sssd-ldap.5.xml:727 sssd-ldap.5.xml:752 sssd-ldap.5.xml:848 +#: sssd-ldap.5.xml:1356 sssd-ad.5.xml:506 sssd-ad.5.xml:582 sssd-ad.5.xml:1160 #: include/ldap_id_mapping.xml:250 msgid "Default: False" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1609 -msgid "pam_cert_auth (bool)" +#: sssd.conf.5.xml:1576 +msgid "pam_cert_auth (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1612 +#: sssd.conf.5.xml:1579 msgid "" "Enable certificate based Smartcard authentication. Since this requires " "additional communication with the Smartcard which will delay the " "authentication process this option is disabled by default." msgstr "" +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1588 +msgid "" +"Note: In case OpenSC is used for Smartcard access SSSD supports the " +"filesystem caching in OpenSC when enabled in opensc.conf. The cached files " +"are located in a common <quote>opensc</quote> directory in SSSD's state " +"directory. The behaviour can be changed in opensc.conf" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> +#: sssd.conf.5.xml:1597 +#, no-wrap +msgid "" +"app /usr/libexec/sssd/p11_child {\n" +" framework pkcs15 {\n" +" use_file_caching = no;\n" +" }\n" +"}\n" +"app /usr/libexec/sssd/krb5_child {\n" +" framework pkcs15 {\n" +" use_file_caching = no;\n" +" }\n" +"}\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1595 +msgid "" +"Example opensc.conf (*): <placeholder type=\"programlisting\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1610 +msgid "" +"(*) The actual <quote>libexec</quote> directory for p11_child and krb5_child " +"depends on the distribution." +msgstr "" + #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1623 +#: sssd.conf.5.xml:1615 msgid "pam_cert_db_path (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1626 +#: sssd.conf.5.xml:1618 msgid "The path to the certificate database." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1629 sssd.conf.5.xml:2163 sssd.conf.5.xml:4338 +#: sssd.conf.5.xml:1621 sssd.conf.5.xml:2199 sssd.conf.5.xml:4543 msgid "Default:" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1631 sssd.conf.5.xml:2165 +#: sssd.conf.5.xml:1623 sssd.conf.5.xml:2201 msgid "" "/etc/sssd/pki/sssd_auth_ca_db.pem (path to a file with trusted CA " "certificates in PEM format)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1641 +#: sssd.conf.5.xml:1633 msgid "pam_cert_verification (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1644 +#: sssd.conf.5.xml:1636 msgid "" "With this parameter the PAM certificate verification can be tuned with a " "comma separated list of options that override the " @@ -2021,7 +2000,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1655 +#: sssd.conf.5.xml:1647 #, no-wrap msgid "" "pam_cert_verification = partial_chain\n" @@ -2029,59 +2008,59 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1659 +#: sssd.conf.5.xml:1651 msgid "" "Default: not set, i.e. use default <quote>certificate_verification</quote> " "option defined in <quote>[sssd]</quote> section." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1666 +#: sssd.conf.5.xml:1658 msgid "p11_child_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1669 +#: sssd.conf.5.xml:1661 msgid "How many seconds will pam_sss wait for p11_child to finish." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1678 +#: sssd.conf.5.xml:1670 msgid "passkey_child_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1681 +#: sssd.conf.5.xml:1673 msgid "" "How many seconds will the PAM responder wait for passkey_child to finish." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1690 +#: sssd.conf.5.xml:1682 msgid "pam_app_services (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1693 +#: sssd.conf.5.xml:1685 msgid "" "Which PAM services are permitted to contact domains of type " "<quote>application</quote>" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1702 +#: sssd.conf.5.xml:1694 msgid "pam_p11_allowed_services (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1705 +#: sssd.conf.5.xml:1697 msgid "" "A comma-separated list of PAM service names for which it will be allowed to " "use Smartcards." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1720 +#: sssd.conf.5.xml:1712 #, no-wrap msgid "" "pam_p11_allowed_services = +my_pam_service, -login\n" @@ -2089,7 +2068,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1709 +#: sssd.conf.5.xml:1701 msgid "" "It is possible to add another PAM service name to the default set by using " "<quote>+service_name</quote> or to explicitly remove a PAM service name from " @@ -2101,68 +2080,73 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1724 sssd-ad.5.xml:645 sssd-ad.5.xml:754 sssd-ad.5.xml:812 -#: sssd-ad.5.xml:870 sssd-ad.5.xml:948 +#: sssd.conf.5.xml:1716 sssd-ad.5.xml:645 sssd-ad.5.xml:759 sssd-ad.5.xml:817 +#: sssd-ad.5.xml:875 sssd-ad.5.xml:953 msgid "Default: the default set of PAM service names includes:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1729 sssd-ad.5.xml:649 +#: sssd.conf.5.xml:1721 sssd-ad.5.xml:649 msgid "login" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1734 sssd-ad.5.xml:654 +#: sssd.conf.5.xml:1726 sssd-ad.5.xml:654 msgid "su" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1739 sssd-ad.5.xml:659 +#: sssd.conf.5.xml:1731 sssd-ad.5.xml:659 msgid "su-l" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1744 sssd-ad.5.xml:674 +#: sssd.conf.5.xml:1736 sssd-ad.5.xml:674 msgid "gdm-smartcard" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1749 sssd-ad.5.xml:669 +#: sssd.conf.5.xml:1741 sssd-ad.5.xml:669 msgid "gdm-password" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1754 +#: sssd.conf.5.xml:1746 msgid "gdm-switchable-auth" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1759 sssd-ad.5.xml:679 +#: sssd.conf.5.xml:1751 sssd-ad.5.xml:679 msgid "kdm" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1764 sssd-ad.5.xml:957 +#: sssd.conf.5.xml:1756 sssd-ad.5.xml:694 +msgid "plasmalogin" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:1761 sssd-ad.5.xml:962 msgid "sudo" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1769 sssd-ad.5.xml:962 +#: sssd.conf.5.xml:1766 sssd-ad.5.xml:967 msgid "sudo-i" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1774 +#: sssd.conf.5.xml:1771 msgid "gnome-screensaver" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1782 +#: sssd.conf.5.xml:1779 msgid "p11_wait_for_card_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1785 +#: sssd.conf.5.xml:1782 msgid "" "If Smartcard authentication is required how many extra seconds in addition " "to p11_child_timeout should the PAM responder wait until a Smartcard is " @@ -2170,12 +2154,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1796 +#: sssd.conf.5.xml:1793 msgid "p11_uri (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1799 +#: sssd.conf.5.xml:1796 msgid "" "PKCS#11 URI (see RFC-7512 for details) which can be used to restrict the " "selection of devices used for Smartcard authentication. By default SSSD's " @@ -2186,7 +2170,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1812 +#: sssd.conf.5.xml:1809 #, no-wrap msgid "" "p11_uri = pkcs11:slot-description=My%20Smartcard%20Reader\n" @@ -2194,7 +2178,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1816 +#: sssd.conf.5.xml:1813 #, no-wrap msgid "" "p11_uri = pkcs11:library-description=OpenSC%20smartcard%20framework;slot-id=2\n" @@ -2202,7 +2186,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1810 +#: sssd.conf.5.xml:1807 msgid "" "Example: <placeholder type=\"programlisting\" id=\"0\"/> or <placeholder " "type=\"programlisting\" id=\"1\"/> To find suitable URI please check the " @@ -2211,47 +2195,47 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1829 -msgid "pam_initgroups_scheme" +#: sssd.conf.5.xml:1826 +msgid "pam_initgroups_scheme (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1837 +#: sssd.conf.5.xml:1834 msgid "always" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1838 +#: sssd.conf.5.xml:1835 msgid "" "Always do an online lookup, please note that pam_id_timeout still applies" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1842 +#: sssd.conf.5.xml:1839 msgid "no_session" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1843 +#: sssd.conf.5.xml:1840 msgid "" "Only do an online lookup if there is no active session of the user, i.e. if " "the user is currently not logged in" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1848 sssd-ldap.5.xml:189 +#: sssd.conf.5.xml:1845 sssd-ldap.5.xml:189 msgid "never" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1849 +#: sssd.conf.5.xml:1846 msgid "" "Never force an online lookup, use the data from the cache as long as they " "are not expired" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1832 +#: sssd.conf.5.xml:1829 msgid "" "The PAM responder can force an online lookup to get the current group " "memberships of the user trying to log in. This option controls when this " @@ -2260,30 +2244,30 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1856 +#: sssd.conf.5.xml:1853 msgid "Default: no_session" msgstr "" -#. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:1861 sssd.conf.5.xml:4277 -msgid "pam_gssapi_services" +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1858 +msgid "pam_gssapi_services (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1864 +#: sssd.conf.5.xml:1861 msgid "" "Comma separated list of PAM services that are allowed to try GSSAPI " "authentication using pam_sss_gss.so module." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1869 +#: sssd.conf.5.xml:1866 msgid "" "To disable GSSAPI authentication, set this option to <quote>-</quote> (dash)." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1873 sssd.conf.5.xml:1904 sssd.conf.5.xml:1942 +#: sssd.conf.5.xml:1870 sssd.conf.5.xml:1901 sssd.conf.5.xml:1939 msgid "" "Note: This option can also be set per-domain which overwrites the value in " "[pam] section. It can also be set for trusted domain which overwrites the " @@ -2291,7 +2275,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1881 +#: sssd.conf.5.xml:1878 #, no-wrap msgid "" "pam_gssapi_services = sudo, sudo-i\n" @@ -2299,22 +2283,22 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1879 sssd.conf.5.xml:1994 sssd.conf.5.xml:3836 +#: sssd.conf.5.xml:1876 sssd.conf.5.xml:2023 sssd.conf.5.xml:4042 msgid "Example: <placeholder type=\"programlisting\" id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1885 +#: sssd.conf.5.xml:1882 msgid "Default: - (GSSAPI authentication is disabled)" msgstr "" -#. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:1890 sssd.conf.5.xml:4278 -msgid "pam_gssapi_check_upn" +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1887 +msgid "pam_gssapi_check_upn (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1893 +#: sssd.conf.5.xml:1890 msgid "" "If True, SSSD will require that the Kerberos user principal that " "successfully authenticated through GSSAPI can be associated with the user " @@ -2322,19 +2306,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1900 +#: sssd.conf.5.xml:1897 msgid "" -"If False, every user that is able to obtained required service ticket will " +"If False, every user that is able to obtain a required service ticket will " "be authenticated." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1915 -msgid "pam_gssapi_indicators_map" +#: sssd.conf.5.xml:1912 +msgid "pam_gssapi_indicators_map (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1918 +#: sssd.conf.5.xml:1915 msgid "" "Comma separated list of authentication indicators required to be present in " "a Kerberos ticket to access a PAM service that is allowed to try GSSAPI " @@ -2342,7 +2326,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1924 +#: sssd.conf.5.xml:1921 msgid "" "Each element of the list can be either an authentication indicator name or a " "pair <quote>service:indicator</quote>. Indicators not prefixed with the PAM " @@ -2357,7 +2341,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1937 +#: sssd.conf.5.xml:1934 msgid "" "To disable GSSAPI authentication indicator check, set this option to <quote>-" "</quote> (dash). To disable the check for a specific PAM service, add " @@ -2365,83 +2349,122 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1948 +#: sssd.conf.5.xml:1945 msgid "" "Following authentication indicators are supported by IPA Kerberos " "deployments:" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1951 +#: sssd.conf.5.xml:1948 msgid "" "pkinit -- pre-authentication using X.509 certificates -- whether stored in " "files or on smart cards." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1954 +#: sssd.conf.5.xml:1951 msgid "" "hardened -- SPAKE pre-authentication or any pre-authentication wrapped in a " "FAST channel." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1957 +#: sssd.conf.5.xml:1954 msgid "radius -- pre-authentication with the help of a RADIUS server." msgstr "" -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1960 +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:1957 +msgid "" +"otp -- pre-authentication using integrated two-factor authentication (2FA or " +"one-time password, OTP) in IPA." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:1960 +msgid "idp -- pre-authentication using external identity provider." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> +#: sssd.conf.5.xml:1970 +#, no-wrap +msgid "" +"pam_gssapi_indicators_map = sudo:pkinit, sudo-i:pkinit\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1965 +msgid "" +"Example: to require access to SUDO services only for users which obtained " +"their Kerberos tickets with a X.509 certificate pre-authentication (PKINIT), " +"set <placeholder type=\"programlisting\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1974 +msgid "Default: not set (use of authentication indicators is not required)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1979 +msgid "pam_gssapi_indicators_apply (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1982 msgid "" -"otp -- pre-authentication using integrated two-factor authentication (2FA or " -"one-time password, OTP) in IPA." +"Comma separated list of triples to assign additional information from the " +"Kerberos ticket, e.g. a SID from the PAC, to authentication indicators." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1988 +msgid "Currently supported is:" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:1963 -msgid "idp -- pre-authentication using external identity provider." +#: sssd.conf.5.xml:1991 +msgid "SID:S-1-5-[domain]-[RID]:[authentication indicator]" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1973 +#: sssd.conf.5.xml:2002 #, no-wrap msgid "" -"pam_gssapi_indicators_map = sudo:pkinit, sudo-i:pkinit\n" +"pam_gssapi_indicators_apply = SID:S-1-5-12345-23456-34567-4321:pkinit\n" " " msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1968 +#: sssd.conf.5.xml:1996 msgid "" -"Example: to require access to SUDO services only for users which obtained " -"their Kerberos tickets with a X.509 certificate pre-authentication (PKINIT), " -"set <placeholder type=\"programlisting\" id=\"0\"/>" -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1977 -msgid "Default: not set (use of authentication indicators is not required)" +"Example: To assign a SID, which is e.g. set by Active Directory's " +"Authentication Mechanism Assurance (AMA) if the AD user used a Smartcard for " +"authentication, to the 'pkinit' authentication indicator use: <placeholder " +"type=\"programlisting\" id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:1982 +#: sssd.conf.5.xml:2011 msgid "pam_json_services (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1985 +#: sssd.conf.5.xml:2014 msgid "" "Comma separated list of PAM services which can handle the JSON protocol for " "selecting authentication mechanisms" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:1990 +#: sssd.conf.5.xml:2019 msgid "To disable JSON protocol, set this option to <quote>-</quote> (dash)." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:1996 +#: sssd.conf.5.xml:2025 #, no-wrap msgid "" "pam_json_services = gdm-switchable-auth\n" @@ -2449,52 +2472,59 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2000 +#: sssd.conf.5.xml:2029 msgid "Default: - (JSON protocol is disabled)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2003 +#: sssd.conf.5.xml:2032 msgid "" "Note: 2-Factor Authentication (2FA) is not supported. If 2FA is required, do " "not activate the JSON protocol." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:2013 +#: sssd.conf.5.xml:2042 msgid "SUDO configuration options" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2015 +#: sssd.conf.5.xml:2044 msgid "" -"These options can be used to configure the sudo service. The detailed " -"instructions for configuration of <citerefentry> <refentrytitle>sudo</" -"refentrytitle> <manvolnum>8</manvolnum> </citerefentry> to work with " -"<citerefentry> <refentrytitle>sssd</refentrytitle> <manvolnum>8</manvolnum> " -"</citerefentry> are in the manual page <citerefentry> <refentrytitle>sssd-" -"sudo</refentrytitle> <manvolnum>5</manvolnum> </citerefentry>." +"These options can be used to configure the sudo service and should be " +"specified under the <quote>[sudo]</quote> section." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:2048 +msgid "" +"The detailed instructions for configuration of <citerefentry> " +"<refentrytitle>sudo</refentrytitle> <manvolnum>8</manvolnum> </citerefentry> " +"to work with <citerefentry> <refentrytitle>sssd</refentrytitle> " +"<manvolnum>8</manvolnum> </citerefentry> are in the manual page " +"<citerefentry> <refentrytitle>sssd-sudo</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry>." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2032 -msgid "sudo_timed (bool)" +#: sssd.conf.5.xml:2064 +msgid "sudo_timed (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2035 +#: sssd.conf.5.xml:2067 msgid "" "Whether or not to evaluate the sudoNotBefore and sudoNotAfter attributes " "that implement time-dependent sudoers entries." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2047 +#: sssd.conf.5.xml:2079 msgid "sudo_threshold (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2050 +#: sssd.conf.5.xml:2082 msgid "" "Maximum number of expired rules that can be refreshed at once. If number of " "expired rules is below threshold, those rules are refreshed with " @@ -2504,22 +2534,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:2069 +#: sssd.conf.5.xml:2101 msgid "AUTOFS configuration options" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2071 -msgid "These options can be used to configure the autofs service." +#: sssd.conf.5.xml:2103 +msgid "" +"These options can be used to configure the autofs service and should be " +"specified under the <quote>[autofs]</quote> section." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2075 +#: sssd.conf.5.xml:2109 msgid "autofs_negative_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2078 +#: sssd.conf.5.xml:2112 msgid "" "Specifies for how many seconds should the autofs responder negative cache " "hits (that is, queries for invalid map entries, like nonexistent ones) " @@ -2527,22 +2559,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:2094 +#: sssd.conf.5.xml:2128 msgid "SSH configuration options" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2096 -msgid "These options can be used to configure the SSH service." +#: sssd.conf.5.xml:2130 +msgid "" +"These options can be used to configure the SSH service and should be " +"specified under the <quote>[ssh]</quote> section." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2100 -msgid "ssh_use_certificate_keys (bool)" +#: sssd.conf.5.xml:2136 +msgid "ssh_use_certificate_keys (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2103 +#: sssd.conf.5.xml:2139 msgid "" "If set to true the <command>sss_ssh_authorizedkeys</command> will return ssh " "keys derived from the public key of X.509 certificates stored in the user " @@ -2551,12 +2585,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2118 +#: sssd.conf.5.xml:2154 msgid "ssh_use_certificate_matching_rules (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2121 +#: sssd.conf.5.xml:2157 msgid "" "By default the ssh responder will use all available certificate matching " "rules to filter the certificates so that ssh keys are only derived from the " @@ -2566,7 +2600,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2130 +#: sssd.conf.5.xml:2166 msgid "" "There are two special key words 'all_rules' and 'no_rules' which will enable " "all or no rules, respectively. The latter means that no certificates will be " @@ -2574,7 +2608,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2137 +#: sssd.conf.5.xml:2173 msgid "" "If no rules are configured using 'all_rules' will enable a default rule " "which enables all certificates suitable for client authentication. This is " @@ -2583,38 +2617,38 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2144 +#: sssd.conf.5.xml:2180 msgid "" "A non-existing rule name is considered an error. If as a result no rule is " "selected all certificates will be ignored." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2149 +#: sssd.conf.5.xml:2185 msgid "" "Default: not set, equivalent to 'all_rules', all found rules or the default " "rule are used" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2155 +#: sssd.conf.5.xml:2191 msgid "ca_db (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2158 +#: sssd.conf.5.xml:2194 msgid "" "Path to a storage of trusted CA certificates. The option is used to validate " "user certificates before deriving public ssh keys from them." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:2178 +#: sssd.conf.5.xml:2214 msgid "PAC responder configuration options" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2180 +#: sssd.conf.5.xml:2216 msgid "" "The PAC responder works together with the authorization data plugin for MIT " "Kerberos sssd_pac_plugin.so and a sub-domain provider. The plugin sends the " @@ -2625,7 +2659,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:2189 +#: sssd.conf.5.xml:2225 msgid "" "If the remote user does not exist in the cache, it is created. The UID is " "determined with the help of the SID, trusted domains will have UPGs and the " @@ -2636,24 +2670,26 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:2197 +#: sssd.conf.5.xml:2233 msgid "" "If there are SIDs of groups from domains sssd knows about, the user will be " "added to those groups." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2203 -msgid "These options can be used to configure the PAC responder." +#: sssd.conf.5.xml:2239 +msgid "" +"These options can be used to configure the PAC responder and should be " +"specified under the <quote>[pac]</quote> section." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2207 sssd-ifp.5.xml:66 +#: sssd.conf.5.xml:2244 sssd-ifp.5.xml:66 msgid "allowed_uids (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2210 +#: sssd.conf.5.xml:2247 msgid "" "Specifies the comma-separated list of UID values or user names that are " "allowed to access the PAC responder. User names are resolved to UIDs at " @@ -2661,19 +2697,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2216 +#: sssd.conf.5.xml:2253 msgid "" "Default: 0, &sssd_user_name; (only root and SSSD service users are allowed " "to access the PAC responder)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2220 +#: sssd.conf.5.xml:2257 msgid "Default: 0 (only the root user is allowed to access the PAC responder)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2224 +#: sssd.conf.5.xml:2261 msgid "" "Please note that defaults will be overwritten with this option. If you still " "want to allow the root and/or '&sssd_user_name;' user to access the PAC " @@ -2682,7 +2718,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2231 +#: sssd.conf.5.xml:2268 msgid "" "Please note that although the UID 0 is used as the default it will be " "overwritten with this option. If you still want to allow the root user to " @@ -2691,24 +2727,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2240 +#: sssd.conf.5.xml:2277 msgid "pac_lifetime (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2243 +#: sssd.conf.5.xml:2280 msgid "" "Lifetime of the PAC entry in seconds. As long as the PAC is valid the PAC " "data can be used to determine the group memberships of a user." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2253 +#: sssd.conf.5.xml:2290 msgid "pac_check (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2256 +#: sssd.conf.5.xml:2293 msgid "" "Apply additional checks on the PAC of the Kerberos ticket which is available " "in Active Directory and FreeIPA domains, if configured. Please note that " @@ -2719,7 +2755,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2266 +#: sssd.conf.5.xml:2303 msgid "" "Please note that the checks listed below only apply to PACs issued by Active " "Directory or recent versions of FreeIPA. PACs issued e.g. by a plain MIT " @@ -2727,24 +2763,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2277 +#: sssd.conf.5.xml:2314 msgid "no_check" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2279 +#: sssd.conf.5.xml:2316 msgid "" "The PAC must not be present and even if it is present no additional checks " "will be done." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2285 +#: sssd.conf.5.xml:2322 msgid "pac_present" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2287 +#: sssd.conf.5.xml:2324 msgid "" "The PAC must be present in the service ticket which SSSD will request with " "the help of the user's TGT. If the PAC is not available the authentication " @@ -2752,24 +2788,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2295 +#: sssd.conf.5.xml:2332 msgid "check_upn" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2297 +#: sssd.conf.5.xml:2334 msgid "" "If the PAC is present check if the user principal name (UPN) information is " "consistent." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2303 +#: sssd.conf.5.xml:2340 msgid "check_upn_allow_missing" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2305 +#: sssd.conf.5.xml:2342 msgid "" "This option should be used together with 'check_upn' and handles the case " "where a UPN is set on the server-side but is not read by SSSD. The typical " @@ -2781,7 +2817,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2317 +#: sssd.conf.5.xml:2354 msgid "" "Currently this option is set by default to avoid regressions in such " "environments. A log message will be added to the system log and SSSD's debug " @@ -2792,60 +2828,60 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2331 +#: sssd.conf.5.xml:2368 msgid "upn_dns_info_present" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2333 +#: sssd.conf.5.xml:2370 msgid "The PAC must contain the UPN-DNS-INFO buffer, implies 'check_upn'." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2338 +#: sssd.conf.5.xml:2375 msgid "check_upn_dns_info_ex" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2340 +#: sssd.conf.5.xml:2377 msgid "" "If the PAC is present and the extension to the UPN-DNS-INFO buffer is " "available check if the information in the extension is consistent." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2347 +#: sssd.conf.5.xml:2384 msgid "upn_dns_info_ex_present" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2349 +#: sssd.conf.5.xml:2386 msgid "" "The PAC must contain the extension of the UPN-DNS-INFO buffer, implies " "'check_upn_dns_info_ex', 'upn_dns_info_present' and 'check_upn'." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2273 +#: sssd.conf.5.xml:2310 msgid "" "The following options can be used alone or in a comma-separated list: " "<placeholder type=\"variablelist\" id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2359 +#: sssd.conf.5.xml:2396 msgid "" "Default: no_check (AD and IPA provider 'check_upn, check_upn_allow_missing, " "check_upn_dns_info_ex')" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:2368 +#: sssd.conf.5.xml:2405 msgid "Session recording configuration options" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2370 +#: sssd.conf.5.xml:2407 msgid "" "Session recording works in conjunction with <citerefentry> " "<refentrytitle>tlog-rec-session</refentrytitle> <manvolnum>8</manvolnum> </" @@ -2855,66 +2891,78 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:2383 -msgid "These options can be used to configure session recording." +#: sssd.conf.5.xml:2420 +msgid "" +"These options can be used to configure session recording and should be " +"specified under the <quote>[session_recording]</quote> section." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:2425 +msgid "" +"Note: Unlike other sections, the <quote>[session_recording]</quote> section " +"ignores <replaceable>debug*</replaceable> options and suitable " +"<replaceable>debug*</replaceable> options must be set in <quote>[pam]</" +"quote>, <quote>[nss]</quote> and <quote>[domain/<replaceable>NAME</" +"replaceable>]</quote> sections." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2387 sssd-session-recording.5.xml:64 +#: sssd.conf.5.xml:2433 sssd-session-recording.5.xml:64 msgid "scope (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2394 sssd-session-recording.5.xml:71 +#: sssd.conf.5.xml:2440 sssd-session-recording.5.xml:71 msgid "\"none\"" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2397 sssd-session-recording.5.xml:74 +#: sssd.conf.5.xml:2443 sssd-session-recording.5.xml:74 msgid "No users are recorded." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2402 sssd-session-recording.5.xml:79 +#: sssd.conf.5.xml:2448 sssd-session-recording.5.xml:79 msgid "\"some\"" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2405 sssd-session-recording.5.xml:82 +#: sssd.conf.5.xml:2451 sssd-session-recording.5.xml:82 msgid "" "Users/groups specified by <replaceable>users</replaceable> and " "<replaceable>groups</replaceable> options are recorded." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2414 sssd-session-recording.5.xml:91 +#: sssd.conf.5.xml:2460 sssd-session-recording.5.xml:91 msgid "\"all\"" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2417 sssd-session-recording.5.xml:94 +#: sssd.conf.5.xml:2463 sssd-session-recording.5.xml:94 msgid "All users are recorded." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2390 sssd-session-recording.5.xml:67 +#: sssd.conf.5.xml:2436 sssd-session-recording.5.xml:67 msgid "" "One of the following strings specifying the scope of session recording: " "<placeholder type=\"variablelist\" id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2424 sssd-session-recording.5.xml:101 +#: sssd.conf.5.xml:2470 sssd-session-recording.5.xml:101 msgid "Default: \"none\"" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2429 sssd-session-recording.5.xml:106 +#: sssd.conf.5.xml:2475 sssd-session-recording.5.xml:106 msgid "users (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2432 sssd-session-recording.5.xml:109 +#: sssd.conf.5.xml:2478 sssd-session-recording.5.xml:109 msgid "" "A comma-separated list of users which should have session recording enabled. " "Matches user names as returned by NSS. I.e. after the possible space " @@ -2922,17 +2970,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2438 sssd-session-recording.5.xml:115 +#: sssd.conf.5.xml:2484 sssd-session-recording.5.xml:115 msgid "Default: Empty. Matches no users." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2443 sssd-session-recording.5.xml:120 +#: sssd.conf.5.xml:2489 sssd-session-recording.5.xml:120 msgid "groups (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2446 sssd-session-recording.5.xml:123 +#: sssd.conf.5.xml:2492 sssd-session-recording.5.xml:123 msgid "" "A comma-separated list of groups, members of which should have session " "recording enabled. Matches group names as returned by NSS. I.e. after the " @@ -2940,7 +2988,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2452 sssd.conf.5.xml:2484 sssd-session-recording.5.xml:129 +#: sssd.conf.5.xml:2498 sssd.conf.5.xml:2530 sssd-session-recording.5.xml:129 #: sssd-session-recording.5.xml:161 msgid "" "NOTE: using this option (having it set to anything) has a considerable " @@ -2949,57 +2997,56 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2459 sssd-session-recording.5.xml:136 +#: sssd.conf.5.xml:2505 sssd-session-recording.5.xml:136 msgid "Default: Empty. Matches no groups." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2464 sssd-session-recording.5.xml:141 +#: sssd.conf.5.xml:2510 sssd-session-recording.5.xml:141 msgid "exclude_users (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2467 sssd-session-recording.5.xml:144 +#: sssd.conf.5.xml:2513 sssd-session-recording.5.xml:144 msgid "" "A comma-separated list of users to be excluded from recording, only " "applicable with 'scope=all'." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2471 sssd-session-recording.5.xml:148 +#: sssd.conf.5.xml:2517 sssd-session-recording.5.xml:148 msgid "Default: Empty. No users excluded." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2476 sssd-session-recording.5.xml:153 +#: sssd.conf.5.xml:2522 sssd-session-recording.5.xml:153 msgid "exclude_groups (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2479 sssd-session-recording.5.xml:156 +#: sssd.conf.5.xml:2525 sssd-session-recording.5.xml:156 msgid "" "A comma-separated list of groups, members of which should be excluded from " "recording. Only applicable with 'scope=all'." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2491 sssd-session-recording.5.xml:168 +#: sssd.conf.5.xml:2537 sssd-session-recording.5.xml:168 msgid "Default: Empty. No groups excluded." msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:2501 +#: sssd.conf.5.xml:2547 msgid "DOMAIN SECTIONS" msgstr "" -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry><para> -#: sssd.conf.5.xml:2508 sssd.conf.5.xml:3964 sssd.conf.5.xml:3965 -#: sssd.conf.5.xml:3968 -msgid "enabled" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2554 +msgid "enabled (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2511 +#: sssd.conf.5.xml:2557 msgid "" "Explicitly enable or disable the domain. If <quote>true</quote>, the domain " "is always <quote>enabled</quote>. If <quote>false</quote>, the domain is " @@ -3009,12 +3056,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2523 +#: sssd.conf.5.xml:2569 msgid "domain_type (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2526 +#: sssd.conf.5.xml:2572 msgid "" "Specifies whether the domain is meant to be used by POSIX-aware clients such " "as the Name Service Switch or by applications that do not need POSIX data to " @@ -3023,14 +3070,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2534 +#: sssd.conf.5.xml:2580 msgid "" "Allowed values for this option are <quote>posix</quote> and " "<quote>application</quote>." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2538 +#: sssd.conf.5.xml:2584 msgid "" "POSIX domains are reachable by all services. Application domains are only " "reachable from the InfoPipe responder (see <citerefentry> " @@ -3039,38 +3086,38 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2546 +#: sssd.conf.5.xml:2592 msgid "" "NOTE: The application domains are currently well tested with " "<quote>id_provider=ldap</quote> only." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2550 +#: sssd.conf.5.xml:2596 msgid "" "For an easy way to configure a non-POSIX domains, please see the " "<quote>Application domains</quote> section." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2554 +#: sssd.conf.5.xml:2600 msgid "Default: posix" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2560 +#: sssd.conf.5.xml:2606 msgid "min_id,max_id (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2563 +#: sssd.conf.5.xml:2609 msgid "" "UID and GID limits for the domain. If a domain contains an entry that is " "outside these limits, it is ignored." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2568 +#: sssd.conf.5.xml:2614 msgid "" "For users, this affects the primary GID limit. The user will not be returned " "to NSS if either the UID or the primary GID is outside the range. For non-" @@ -3079,24 +3126,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2575 +#: sssd.conf.5.xml:2621 msgid "" "These ID limits affect even saving entries to cache, not only returning them " "by name or ID." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2579 +#: sssd.conf.5.xml:2625 msgid "Default: 1 for min_id, 0 (no limit) for max_id" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2585 -msgid "enumerate (bool)" +#: sssd.conf.5.xml:2631 +msgid "enumerate (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2588 +#: sssd.conf.5.xml:2634 msgid "" "Determines if a domain can be enumerated, that is, whether the domain can " "list all the users and group it contains. Note that it is not required to " @@ -3105,36 +3152,36 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2596 +#: sssd.conf.5.xml:2642 msgid "TRUE = Users and groups are enumerated" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2599 +#: sssd.conf.5.xml:2645 msgid "FALSE = No enumerations for this domain" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2602 sssd.conf.5.xml:2867 sssd.conf.5.xml:3044 +#: sssd.conf.5.xml:2648 sssd.conf.5.xml:2992 sssd.conf.5.xml:3174 msgid "Default: FALSE" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2605 +#: sssd.conf.5.xml:2651 msgid "" "Enumerating a domain requires SSSD to download and store ALL user and group " "entries from the remote server." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2610 +#: sssd.conf.5.xml:2656 msgid "" "Feature is only supported for domains with id_provider = ldap or id_provider " "= proxy." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2614 +#: sssd.conf.5.xml:2660 msgid "" "Note: Enabling enumeration has a severe performance impact on SSSD while " "enumeration is running. It may take up to several minutes after SSSD startup " @@ -3148,14 +3195,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2629 +#: sssd.conf.5.xml:2675 msgid "" "While the first enumeration is running, requests for the complete user or " "group lists may return no results until it completes." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2634 +#: sssd.conf.5.xml:2680 msgid "" "Further, enabling enumeration may increase the time necessary to detect " "network disconnection, as longer timeouts are required to ensure that " @@ -3164,14 +3211,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2642 +#: sssd.conf.5.xml:2688 msgid "" "For the reasons cited above, enabling enumeration is not recommended, " "especially in large environments." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2647 +#: sssd.conf.5.xml:2693 msgid "" "Note: the proxy provider is tested with open source modules like " "'libnss_files' and 'libnss_ldap'. 3rd party modules must follow the " @@ -3179,19 +3226,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2656 +#: sssd.conf.5.xml:2702 msgid "entry_cache_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2659 +#: sssd.conf.5.xml:2705 msgid "" "How many seconds should nss_sss consider entries valid before asking the " "backend again" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2663 +#: sssd.conf.5.xml:2709 msgid "" "The cache expiration timestamps are stored as attributes of individual " "objects in the cache. Therefore, changing the cache timeout only has effect " @@ -3202,139 +3249,248 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2676 +#: sssd.conf.5.xml:2722 msgid "Default: 5400" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2682 +#: sssd.conf.5.xml:2728 msgid "entry_cache_user_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2685 +#: sssd.conf.5.xml:2731 msgid "" "How many seconds should nss_sss consider user entries valid before asking " "the backend again" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2689 sssd.conf.5.xml:2702 sssd.conf.5.xml:2715 -#: sssd.conf.5.xml:2728 sssd.conf.5.xml:2742 sssd.conf.5.xml:2755 -#: sssd.conf.5.xml:2769 sssd.conf.5.xml:2783 sssd.conf.5.xml:2796 +#: sssd.conf.5.xml:2735 sssd.conf.5.xml:2748 sssd.conf.5.xml:2761 +#: sssd.conf.5.xml:2774 sssd.conf.5.xml:2788 sssd.conf.5.xml:2801 +#: sssd.conf.5.xml:2815 sssd.conf.5.xml:2829 msgid "Default: entry_cache_timeout" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2695 +#: sssd.conf.5.xml:2741 msgid "entry_cache_group_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2698 +#: sssd.conf.5.xml:2744 msgid "" "How many seconds should nss_sss consider group entries valid before asking " "the backend again" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2708 +#: sssd.conf.5.xml:2754 msgid "entry_cache_netgroup_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2711 +#: sssd.conf.5.xml:2757 msgid "" "How many seconds should nss_sss consider netgroup entries valid before " "asking the backend again" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2721 +#: sssd.conf.5.xml:2767 msgid "entry_cache_service_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2724 +#: sssd.conf.5.xml:2770 msgid "" "How many seconds should nss_sss consider service entries valid before asking " "the backend again" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2734 +#: sssd.conf.5.xml:2780 msgid "entry_cache_resolver_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2737 +#: sssd.conf.5.xml:2783 msgid "" "How many seconds should nss_sss consider hosts and networks entries valid " "before asking the backend again" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2748 +#: sssd.conf.5.xml:2794 msgid "entry_cache_sudo_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2751 +#: sssd.conf.5.xml:2797 msgid "" "How many seconds should sudo consider rules valid before asking the backend " "again" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2761 +#: sssd.conf.5.xml:2807 msgid "entry_cache_autofs_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2764 +#: sssd.conf.5.xml:2810 msgid "" "How many seconds should the autofs service consider automounter maps valid " "before asking the backend again" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2775 +#: sssd.conf.5.xml:2821 msgid "entry_cache_ssh_host_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2778 +#: sssd.conf.5.xml:2824 msgid "" "How many seconds to keep a host ssh key after refresh. IE how long to cache " "the host key for." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2789 -msgid "entry_cache_computer_timeout (integer)" +#: sssd.conf.5.xml:2835 +msgid "offline_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2792 +#: sssd.conf.5.xml:2838 msgid "" -"How many seconds to keep the local computer entry before asking the backend " -"again" +"When SSSD switches to offline mode the amount of time before it tries to go " +"back online will increase based upon the time spent disconnected. By " +"default SSSD uses incremental behaviour to calculate delay in between " +"retries. So, the wait time for a given retry will be longer than the wait " +"time for the previous ones. After each unsuccessful attempt to go online, " +"the new interval is recalculated by the following:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2849 sssd.conf.5.xml:2907 +msgid "" +"new_delay = Minimum(old_delay * 2, offline_timeout_max) + " +"random[0...offline_timeout_random_offset]" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2852 +msgid "" +"The offline_timeout default value is 60. The offline_timeout_max default " +"value is 3600. The offline_timeout_random_offset default value is 30. The " +"end result is the number of seconds before next retry." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2858 +msgid "" +"Note that the maximum length of each interval is defined by " +"offline_timeout_max (apart from the random part)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2868 +msgid "offline_timeout_max (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2871 +msgid "" +"Controls by how much the time between attempts to go online can be " +"incremented following unsuccessful attempts to go online." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2876 +msgid "A value of 0 disables the incrementing behaviour." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2879 +msgid "" +"The value of this parameter should be set in correlation to offline_timeout " +"parameter value." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2883 +msgid "" +"With offline_timeout set to 60 (default value) there is no point in setting " +"offline_timeout_max to less than 120 as it will saturate instantly. General " +"rule here should be to set offline_timeout_max to at least 4 times " +"offline_timeout." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2889 +msgid "" +"Although a value between 0 and offline_timeout may be specified, it has the " +"effect of overriding the offline_timeout value so is of little use." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2894 +#, fuzzy +#| msgid "Default: 3" +msgid "Default: 3600" +msgstr "默认: 3" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2900 +msgid "offline_timeout_random_offset (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2903 +msgid "" +"When SSSD is in offline mode it keeps probing backend servers in specified " +"time intervals:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2910 +msgid "" +"This parameter controls the value of the random offset used for the above " +"equation. Final random_offset value will be random number in range:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2915 +msgid "[0 - offline_timeout_random_offset]" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2918 +msgid "A value of 0 disables the random offset addition." msgstr "" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2921 +#, fuzzy +#| msgid "Default: 3" +msgid "Default: 30" +msgstr "默认: 3" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2802 +#: sssd.conf.5.xml:2927 msgid "refresh_expired_interval (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2805 +#: sssd.conf.5.xml:2930 msgid "" "Specifies how many seconds SSSD has to wait before triggering a background " "refresh task which will refresh all expired or nearly expired records." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2810 +#: sssd.conf.5.xml:2935 msgid "" "The background refresh will process users, groups and netgroups in the " "cache. For users who have performed the initgroups (get group membership for " @@ -3343,17 +3499,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2818 +#: sssd.conf.5.xml:2943 msgid "This option is automatically inherited for all trusted domains." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2822 +#: sssd.conf.5.xml:2947 msgid "You can consider setting this value to 3/4 * entry_cache_timeout." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2826 +#: sssd.conf.5.xml:2951 msgid "" "Cache entry will be refreshed by background task when 2/3 of cache timeout " "has already passed. If there are existing cached entries, the background " @@ -3365,18 +3521,18 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2839 sssd-ldap.5.xml:406 sssd-ldap.5.xml:1834 -#: sssd-ipa.5.xml:255 +#: sssd.conf.5.xml:2964 sssd-ldap.5.xml:406 sssd-ldap.5.xml:1834 +#: sssd-ipa.5.xml:250 msgid "Default: 0 (disabled)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2845 -msgid "cache_credentials (bool)" +#: sssd.conf.5.xml:2970 +msgid "cache_credentials (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2848 +#: sssd.conf.5.xml:2973 msgid "" "Determines if user credentials are also cached in the local LDB cache. The " "cached credentials refer to passwords, which includes the first (long term) " @@ -3387,7 +3543,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2859 +#: sssd.conf.5.xml:2984 msgid "" "Take a note that while credentials are stored as a salted SHA512 hash, this " "still potentially poses some security risk in case an attacker manages to " @@ -3396,12 +3552,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2873 +#: sssd.conf.5.xml:2998 msgid "cache_credentials_minimal_first_factor_length (int)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2876 +#: sssd.conf.5.xml:3001 msgid "" "If 2-Factor-Authentication (2FA) is used and credentials should be saved " "this value determines the minimal length the first authentication factor " @@ -3409,19 +3565,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2883 +#: sssd.conf.5.xml:3008 msgid "" "This should avoid that the short PINs of a PIN based 2FA scheme are saved in " "the cache which would make them easy targets for brute-force attacks." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2894 +#: sssd.conf.5.xml:3019 msgid "account_cache_expiration (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2897 +#: sssd.conf.5.xml:3022 msgid "" "Number of days entries are left in cache after last successful login before " "being removed during a cleanup of the cache. 0 means keep forever. The " @@ -3430,17 +3586,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2904 +#: sssd.conf.5.xml:3029 msgid "Default: 0 (unlimited)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2909 +#: sssd.conf.5.xml:3034 msgid "pwd_expiration_warning (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2920 +#: sssd.conf.5.xml:3045 msgid "" "Please note that the backend server has to provide information about the " "expiration time of the password. If this information is missing, sssd " @@ -3449,28 +3605,28 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2927 +#: sssd.conf.5.xml:3052 msgid "Default: 7 (Kerberos), 0 (LDAP)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2933 +#: sssd.conf.5.xml:3058 msgid "id_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2936 +#: sssd.conf.5.xml:3061 msgid "" "The identification provider used for the domain. Supported ID providers are:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2940 +#: sssd.conf.5.xml:3065 msgid "<quote>proxy</quote>: Support a legacy NSS provider." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2943 +#: sssd.conf.5.xml:3068 msgid "" "<quote>ldap</quote>: LDAP provider. See <citerefentry> <refentrytitle>sssd-" "ldap</refentrytitle> <manvolnum>5</manvolnum> </citerefentry> for more " @@ -3478,8 +3634,8 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2951 sssd.conf.5.xml:3070 sssd.conf.5.xml:3129 -#: sssd.conf.5.xml:3192 +#: sssd.conf.5.xml:3076 sssd.conf.5.xml:3200 sssd.conf.5.xml:3259 +#: sssd.conf.5.xml:3322 msgid "" "<quote>ipa</quote>: FreeIPA and Red Hat Identity Management provider. See " "<citerefentry> <refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</" @@ -3487,8 +3643,8 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2960 sssd.conf.5.xml:3079 sssd.conf.5.xml:3138 -#: sssd.conf.5.xml:3201 +#: sssd.conf.5.xml:3085 sssd.conf.5.xml:3209 sssd.conf.5.xml:3268 +#: sssd.conf.5.xml:3331 msgid "" "<quote>ad</quote>: Active Directory provider. See <citerefentry> " "<refentrytitle>sssd-ad</refentrytitle> <manvolnum>5</manvolnum> </" @@ -3496,27 +3652,34 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2968 +#: sssd.conf.5.xml:3093 msgid "" "<quote>idp</quote>: Provider for OAuth 2.0/OIDC based Identity Providers " "(IdP). See <citerefentry> <refentrytitle>sssd-idp</refentrytitle> " "<manvolnum>5</manvolnum> </citerefentry> for more information." msgstr "" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3101 +msgid "" +"Default: Not set (This is a mandatory setting that must be explicitly " +"defined for each configured domain)." +msgstr "" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:2979 -msgid "use_fully_qualified_names (bool)" +#: sssd.conf.5.xml:3109 +msgid "use_fully_qualified_names (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2982 +#: sssd.conf.5.xml:3112 msgid "" "Use the full name and domain (as formatted by the domain's full_name_format) " "as the user's login name reported to NSS." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2987 +#: sssd.conf.5.xml:3117 msgid "" "If set to TRUE, all requests to this domain must use fully qualified names. " "For example, if used in EXAMPLE domain that contains a \"test\" user, " @@ -3525,7 +3688,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:2995 +#: sssd.conf.5.xml:3125 msgid "" "NOTE: This option has no effect on netgroup lookups due to their tendency to " "include nested netgroups without qualified names. For netgroups, all domains " @@ -3533,24 +3696,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3002 +#: sssd.conf.5.xml:3132 msgid "" "Default: FALSE (TRUE for trusted domain/sub-domains or if " "default_domain_suffix is used)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3009 -msgid "ignore_group_members (bool)" +#: sssd.conf.5.xml:3139 +msgid "ignore_group_members (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3012 +#: sssd.conf.5.xml:3142 msgid "Do not return group members for group lookups." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3015 +#: sssd.conf.5.xml:3145 msgid "" "If set to TRUE, the group membership attribute is not requested from the " "ldap server, and group members are not returned when processing group lookup " @@ -3562,7 +3725,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3033 +#: sssd.conf.5.xml:3163 msgid "" "Enabling this option can also make access provider checks for group " "membership significantly faster, especially for groups containing many " @@ -3570,7 +3733,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3039 sssd.conf.5.xml:3767 sssd-ldap.5.xml:401 +#: sssd.conf.5.xml:3169 sssd.conf.5.xml:3951 sssd-ldap.5.xml:401 #: sssd-ldap.5.xml:454 sssd-ldap.5.xml:529 sssd-ldap.5.xml:576 #: sssd-ldap.5.xml:599 sssd-ldap.5.xml:638 sssd-ldap.5.xml:657 #: sssd-ldap.5.xml:681 sssd-ldap.5.xml:1114 sssd-ldap.5.xml:1147 @@ -3580,19 +3743,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3049 +#: sssd.conf.5.xml:3179 msgid "auth_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3052 +#: sssd.conf.5.xml:3182 msgid "" "The authentication provider used for the domain. Supported auth providers " "are:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3056 sssd.conf.5.xml:3122 +#: sssd.conf.5.xml:3186 sssd.conf.5.xml:3252 msgid "" "<quote>ldap</quote> for native LDAP authentication. See <citerefentry> " "<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> </" @@ -3600,7 +3763,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3063 +#: sssd.conf.5.xml:3193 msgid "" "<quote>krb5</quote> for Kerberos authentication. See <citerefentry> " "<refentrytitle>sssd-krb5</refentrytitle> <manvolnum>5</manvolnum> </" @@ -3608,7 +3771,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3087 +#: sssd.conf.5.xml:3217 msgid "" "<quote>idp</quote>: Provider for OAuth 2.0/OIDC based authentication. See " "<citerefentry> <refentrytitle>sssd-idp</refentrytitle> <manvolnum>5</" @@ -3616,30 +3779,30 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3095 +#: sssd.conf.5.xml:3225 msgid "" "<quote>proxy</quote> for relaying authentication to some other PAM target." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3098 +#: sssd.conf.5.xml:3228 msgid "<quote>none</quote> disables authentication explicitly." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3101 +#: sssd.conf.5.xml:3231 msgid "" "Default: <quote>id_provider</quote> is used if it is set and can handle " "authentication requests." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3107 +#: sssd.conf.5.xml:3237 msgid "access_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3110 +#: sssd.conf.5.xml:3240 msgid "" "The access control provider used for the domain. There are two built-in " "access providers (in addition to any included in installed backends) " @@ -3647,17 +3810,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3116 +#: sssd.conf.5.xml:3246 msgid "<quote>permit</quote> always allow access." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3119 +#: sssd.conf.5.xml:3249 msgid "<quote>deny</quote> always deny access." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3146 +#: sssd.conf.5.xml:3276 msgid "" "<quote>simple</quote> access control based on access or deny lists. See " "<citerefentry> <refentrytitle>sssd-simple</refentrytitle> <manvolnum>5</" @@ -3666,7 +3829,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3153 +#: sssd.conf.5.xml:3283 msgid "" "<quote>krb5</quote>: .k5login based access control. See <citerefentry> " "<refentrytitle>sssd-krb5</refentrytitle> <manvolnum>5</manvolnum></" @@ -3674,29 +3837,29 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3160 +#: sssd.conf.5.xml:3290 msgid "<quote>proxy</quote> for relaying access control to another PAM module." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3163 +#: sssd.conf.5.xml:3293 msgid "Default: <quote>permit</quote>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3168 +#: sssd.conf.5.xml:3298 msgid "chpass_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3171 +#: sssd.conf.5.xml:3301 msgid "" "The provider which should handle change password operations for the domain. " "Supported change password providers are:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3176 +#: sssd.conf.5.xml:3306 msgid "" "<quote>ldap</quote> to change a password stored in a LDAP server. See " "<citerefentry> <refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</" @@ -3704,7 +3867,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3184 +#: sssd.conf.5.xml:3314 msgid "" "<quote>krb5</quote> to change the Kerberos password. See <citerefentry> " "<refentrytitle>sssd-krb5</refentrytitle> <manvolnum>5</manvolnum> </" @@ -3712,35 +3875,35 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3209 +#: sssd.conf.5.xml:3339 msgid "" "<quote>proxy</quote> for relaying password changes to some other PAM target." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3213 +#: sssd.conf.5.xml:3343 msgid "<quote>none</quote> disallows password changes explicitly." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3216 +#: sssd.conf.5.xml:3346 msgid "" "Default: <quote>auth_provider</quote> is used if it is set and can handle " "change password requests." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3223 +#: sssd.conf.5.xml:3353 msgid "sudo_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3226 +#: sssd.conf.5.xml:3356 msgid "The SUDO provider used for the domain. Supported SUDO providers are:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3230 +#: sssd.conf.5.xml:3360 msgid "" "<quote>ldap</quote> for rules stored in LDAP. See <citerefentry> " "<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> </" @@ -3748,33 +3911,33 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3238 +#: sssd.conf.5.xml:3368 msgid "" "<quote>ipa</quote> the same as <quote>ldap</quote> but with IPA default " "settings." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3242 +#: sssd.conf.5.xml:3372 msgid "" "<quote>ad</quote> the same as <quote>ldap</quote> but with AD default " "settings." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3246 +#: sssd.conf.5.xml:3376 msgid "<quote>none</quote> disables SUDO explicitly." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3249 +#: sssd.conf.5.xml:3379 msgid "" "Default: The value of <quote>id_provider</quote> is used if it is set and " "can handle sudo requests." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3253 +#: sssd.conf.5.xml:3383 msgid "" "The detailed instructions for configuration of sudo_provider are in the " "manual page <citerefentry> <refentrytitle>sssd-sudo</refentrytitle> " @@ -3785,7 +3948,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3268 +#: sssd.conf.5.xml:3398 msgid "" "<emphasis>NOTE:</emphasis> Sudo rules are periodically downloaded in the " "background unless the sudo provider is explicitly disabled. Set " @@ -3794,12 +3957,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3278 +#: sssd.conf.5.xml:3408 msgid "selinux_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3281 +#: sssd.conf.5.xml:3411 msgid "" "The provider which should handle loading of selinux settings. Note that this " "provider will be called right after access provider ends. Supported selinux " @@ -3807,7 +3970,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3287 +#: sssd.conf.5.xml:3417 msgid "" "<quote>ipa</quote> to load selinux settings from an IPA server. See " "<citerefentry> <refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</" @@ -3815,31 +3978,32 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3295 +#: sssd.conf.5.xml:3425 msgid "<quote>none</quote> disallows fetching selinux settings explicitly." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3298 +#: sssd.conf.5.xml:3428 msgid "" -"Default: <quote>id_provider</quote> is used if it is set and can handle " -"selinux loading requests." +"Default: the value of <quote>id_provider</quote> is used if it is set and " +"can handle selinux loading requests. Otherwise the result is the same as if " +"the selinux_provider is set to none." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3304 +#: sssd.conf.5.xml:3435 msgid "subdomains_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3307 +#: sssd.conf.5.xml:3438 msgid "" "The provider which should handle fetching of subdomains. This value should " "be always the same as id_provider. Supported subdomain providers are:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3313 +#: sssd.conf.5.xml:3444 msgid "" "<quote>ipa</quote> to load a list of subdomains from an IPA server. See " "<citerefentry> <refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</" @@ -3847,7 +4011,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3322 +#: sssd.conf.5.xml:3453 msgid "" "<quote>ad</quote> to load a list of subdomains from an Active Directory " "server. See <citerefentry> <refentrytitle>sssd-ad</refentrytitle> " @@ -3856,24 +4020,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3331 +#: sssd.conf.5.xml:3462 msgid "<quote>none</quote> disallows fetching subdomains explicitly." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3335 +#: sssd.conf.5.xml:3466 msgid "" "Default: The value of <quote>id_provider</quote> is used if it is set and " "can handle subdomain requests." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3341 +#: sssd.conf.5.xml:3472 msgid "session_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3344 +#: sssd.conf.5.xml:3475 msgid "" "The provider which configures and manages user session related tasks. The " "only user session task currently provided is the integration with Fleet " @@ -3881,34 +4045,34 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3351 +#: sssd.conf.5.xml:3482 msgid "<quote>ipa</quote> to allow performing user session related tasks." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3355 +#: sssd.conf.5.xml:3486 msgid "" "<quote>none</quote> does not perform any kind of user session related tasks." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3359 +#: sssd.conf.5.xml:3490 msgid "Default: <quote>none</quote>." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3365 +#: sssd.conf.5.xml:3496 msgid "autofs_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3368 +#: sssd.conf.5.xml:3499 msgid "" "The autofs provider used for the domain. Supported autofs providers are:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3372 +#: sssd.conf.5.xml:3503 msgid "" "<quote>ldap</quote> to load maps stored in LDAP. See <citerefentry> " "<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> </" @@ -3916,7 +4080,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3379 +#: sssd.conf.5.xml:3510 msgid "" "<quote>ipa</quote> to load maps stored in an IPA server. See <citerefentry> " "<refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</manvolnum> </" @@ -3924,7 +4088,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3387 +#: sssd.conf.5.xml:3518 msgid "" "<quote>ad</quote> to load maps stored in an AD server. See <citerefentry> " "<refentrytitle>sssd-ad</refentrytitle> <manvolnum>5</manvolnum> </" @@ -3932,31 +4096,31 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3396 +#: sssd.conf.5.xml:3527 msgid "<quote>none</quote> disables autofs explicitly." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3399 +#: sssd.conf.5.xml:3530 msgid "" "Default: The value of <quote>id_provider</quote> is used if it is set and " "can handle autofs requests." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3406 +#: sssd.conf.5.xml:3537 msgid "hostid_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3409 +#: sssd.conf.5.xml:3540 msgid "" "The provider used for retrieving host identity information. Supported " "hostid providers are:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3413 +#: sssd.conf.5.xml:3544 msgid "" "<quote>ipa</quote> to load host identity stored in an IPA server. See " "<citerefentry> <refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</" @@ -3964,38 +4128,38 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3421 +#: sssd.conf.5.xml:3552 msgid "<quote>none</quote> disables hostid explicitly." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3424 +#: sssd.conf.5.xml:3555 msgid "" "Default: The value of <quote>id_provider</quote> is used if it is set and " "can handle hostid requests." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3431 +#: sssd.conf.5.xml:3562 msgid "resolver_provider (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3434 +#: sssd.conf.5.xml:3565 msgid "" "The provider which should handle hosts and networks lookups. Supported " "resolver providers are:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3438 +#: sssd.conf.5.xml:3569 msgid "" "<quote>proxy</quote> to forward lookups to another NSS library. See " "<quote>proxy_resolver_lib_name</quote>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3442 +#: sssd.conf.5.xml:3573 msgid "" "<quote>ldap</quote> to fetch hosts and networks stored in LDAP. See " "<citerefentry> <refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</" @@ -4003,7 +4167,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3449 +#: sssd.conf.5.xml:3580 msgid "" "<quote>ad</quote> to fetch hosts and networks stored in AD. See " "<citerefentry> <refentrytitle>sssd-ad</refentrytitle> <manvolnum>5</" @@ -4012,19 +4176,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3457 +#: sssd.conf.5.xml:3588 msgid "<quote>none</quote> disallows fetching hosts and networks explicitly." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3460 +#: sssd.conf.5.xml:3591 msgid "" "Default: The value of <quote>id_provider</quote> is used if it is set and " "can handle resolver requests." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3470 +#: sssd.conf.5.xml:3601 msgid "" "Regular expression for this domain that describes how to parse the string " "containing user name and domain into these components. The \"domain\" can " @@ -4034,24 +4198,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3479 +#: sssd.conf.5.xml:3610 msgid "" "Default: <quote>^((?P<name>.+)@(?P<domain>[^@]*)|(?P<name>" "[^@]+))$</quote> which allows two different styles for user names:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:3484 sssd.conf.5.xml:3498 +#: sssd.conf.5.xml:3615 sssd.conf.5.xml:3629 msgid "username" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:3487 sssd.conf.5.xml:3501 +#: sssd.conf.5.xml:3618 sssd.conf.5.xml:3632 msgid "username@domain.name" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3492 +#: sssd.conf.5.xml:3623 msgid "" "Default for the AD and IPA provider: <quote>^(((?P<domain>[^\\\\]+)\\\\" "(?P<name>.+))|((?P<name>.+)@(?P<domain>[^@]+))|((?" @@ -4060,19 +4224,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:3504 +#: sssd.conf.5.xml:3635 msgid "domain\\username" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3507 +#: sssd.conf.5.xml:3638 msgid "" "While the first two correspond to the general default the third one is " "introduced to allow easy integration of users from Windows domains." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3512 +#: sssd.conf.5.xml:3643 msgid "" "The default re_expression uses the <quote>@</quote> character as a separator " "between the name and the domain. As a result of this setting the default " @@ -4082,89 +4246,94 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3564 +#: sssd.conf.5.xml:3695 msgid "Default: <quote>%1$s@%2$s</quote>." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3570 +#: sssd.conf.5.xml:3701 msgid "lookup_family_order (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3573 +#: sssd.conf.5.xml:3704 msgid "" "Provides the ability to select preferred address family to use when " "performing DNS lookups." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3577 +#: sssd.conf.5.xml:3708 msgid "Supported values:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3580 +#: sssd.conf.5.xml:3711 msgid "ipv4_first: Try looking up IPv4 address, if that fails, try IPv6" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3583 +#: sssd.conf.5.xml:3714 msgid "ipv4_only: Only attempt to resolve hostnames to IPv4 addresses." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3586 +#: sssd.conf.5.xml:3717 msgid "ipv6_first: Try looking up IPv6 address, if that fails, try IPv4" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3589 +#: sssd.conf.5.xml:3720 msgid "ipv6_only: Only attempt to resolve hostnames to IPv6 addresses." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3592 +#: sssd.conf.5.xml:3723 msgid "Default: ipv4_first" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3598 +#: sssd.conf.5.xml:3729 msgid "dns_resolver_server_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3601 +#: sssd.conf.5.xml:3732 msgid "" -"Defines the amount of time (in milliseconds) SSSD would try to talk to DNS " -"server before trying next DNS server." +"Defines the timeout duration (in milliseconds) SSSD waits for a DNS server " +"to respond before moving to the next one." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3606 +#: sssd.conf.5.xml:3737 msgid "" "The AD provider will use this option for the CLDAP ping timeouts as well." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3610 sssd.conf.5.xml:3630 sssd.conf.5.xml:3651 +#: sssd.conf.5.xml:3741 sssd.conf.5.xml:3777 sssd.conf.5.xml:3814 msgid "" -"Please see the section <quote>FAILOVER</quote> for more information about " -"the service resolution." +"Please see the section <quote>FAILOVER</quote> in <citerefentry> " +"<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> </" +"citerefentry>, <citerefentry> <refentrytitle>sssd-krb5</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry>, <citerefentry> <refentrytitle>sssd-" +"ipa</refentrytitle> <manvolnum>5</manvolnum> </citerefentry> or " +"<citerefentry> <refentrytitle>sssd-ad</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry> for more information about the service resolution." msgstr "" #. type: Content of: <refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3615 sssd-ldap.5.xml:700 include/failover.xml:84 +#: sssd.conf.5.xml:3762 sssd-ldap.5.xml:700 include/failover.xml:84 msgid "Default: 1000" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3621 +#: sssd.conf.5.xml:3768 msgid "dns_resolver_op_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3624 +#: sssd.conf.5.xml:3771 msgid "" "Defines the amount of time (in seconds) to wait to resolve single DNS query " "(e.g. resolution of a hostname or an SRV record) before trying the next " @@ -4172,17 +4341,17 @@ msgid "" msgstr "" #. type: Content of: <refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3635 include/failover.xml:100 +#: sssd.conf.5.xml:3798 include/failover.xml:100 msgid "Default: 3" msgstr "默认: 3" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3641 +#: sssd.conf.5.xml:3804 msgid "dns_resolver_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3644 +#: sssd.conf.5.xml:3807 msgid "" "Defines the amount of time (in seconds) to wait for a reply from the " "internal fail over service before assuming that the service is unreachable. " @@ -4191,12 +4360,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3662 -msgid "dns_resolver_use_search_list (bool)" +#: sssd.conf.5.xml:3841 +msgid "dns_resolver_use_search_list (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3665 +#: sssd.conf.5.xml:3844 msgid "" "Normally, the DNS resolver searches the domain list defined in the " "\"search\" directive from the resolv.conf file. This can lead to delays in " @@ -4204,7 +4373,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3671 +#: sssd.conf.5.xml:3850 msgid "" "If fully qualified domain names (or _srv_) are used in the SSSD " "configuration, setting this option to FALSE can prevent unnecessary DNS " @@ -4212,36 +4381,36 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3677 +#: sssd.conf.5.xml:3856 #, fuzzy #| msgid "Default: 3" msgid "Default: TRUE" msgstr "默认: 3" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3683 +#: sssd.conf.5.xml:3862 msgid "dns_discovery_domain (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3686 +#: sssd.conf.5.xml:3865 msgid "" "If service discovery is used in the back end, specifies the domain part of " "the service discovery DNS query." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3690 +#: sssd.conf.5.xml:3869 msgid "Default: Use the domain part of machine's hostname" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3696 +#: sssd.conf.5.xml:3875 msgid "failover_primary_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3699 +#: sssd.conf.5.xml:3878 msgid "" "When no primary server is available, SSSD fails over to a backup server. " "This option defines the number of seconds SSSD waits before attempting to " @@ -4249,59 +4418,68 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3706 +#: sssd.conf.5.xml:3885 msgid "Note: The minimum value is 31." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3709 +#: sssd.conf.5.xml:3888 #, fuzzy #| msgid "Default: 3" msgid "Default: 31" msgstr "默认: 3" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3715 +#: sssd.conf.5.xml:3894 msgid "override_gid (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3718 -msgid "Override the primary GID value with the one specified." +#: sssd.conf.5.xml:3897 +msgid "" +"Override the primary GID value for all users in the domain with specified " +"value." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3901 +msgid "" +"Default: not set (Use the primary GID value retrieved from the identity " +"provider)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3724 +#: sssd.conf.5.xml:3908 msgid "case_sensitive (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3731 +#: sssd.conf.5.xml:3915 msgid "True" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3734 +#: sssd.conf.5.xml:3918 msgid "Case sensitive. This value is invalid for AD provider." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3740 +#: sssd.conf.5.xml:3924 msgid "False" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3742 +#: sssd.conf.5.xml:3926 msgid "Case insensitive." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3746 +#: sssd.conf.5.xml:3930 msgid "Preserving" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3749 +#: sssd.conf.5.xml:3933 msgid "" "Same as False (case insensitive), but does not lowercase names in the result " "of NSS operations. Note that name aliases (and in case of services also " @@ -4309,31 +4487,57 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3757 +#: sssd.conf.5.xml:3941 msgid "" "If you want to set this value for trusted domain with IPA provider, you need " "to set it on both the client and SSSD on the server." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3727 +#: sssd.conf.5.xml:3911 msgid "" "Treat user and group names as case sensitive. Possible option values are: " "<placeholder type=\"variablelist\" id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3772 +#: sssd.conf.5.xml:3956 msgid "Default: True (False for AD provider)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3778 +#: sssd.conf.5.xml:3962 +msgid "avoid_by_id_lookups (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3965 +msgid "" +"If this option is set to 'true' SSSD will try to avoid sending lookups by ID " +"to the backend and will switch to a lookup by name if a cached object with a " +"matching ID can be found." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3971 +msgid "" +"This option can e.g. be used in cases where searches by ID are expensive on " +"the server side because of missing indexes or are not even possible, e.g. " +"due to non-reversible POSIX id-mapping." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3978 +msgid "Default: False (True for IdP provider)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:3984 msgid "subdomain_inherit (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3781 +#: sssd.conf.5.xml:3987 msgid "" "Specifies a list of configuration parameters that should be inherited by a " "subdomain. Please note that only selected parameters can be inherited. " @@ -4341,89 +4545,89 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3787 +#: sssd.conf.5.xml:3993 msgid "ldap_search_timeout" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3790 +#: sssd.conf.5.xml:3996 msgid "ldap_network_timeout" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3793 +#: sssd.conf.5.xml:3999 msgid "ldap_opt_timeout" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3796 +#: sssd.conf.5.xml:4002 msgid "ldap_offline_timeout" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3799 +#: sssd.conf.5.xml:4005 msgid "ldap_purge_cache_timeout" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3802 +#: sssd.conf.5.xml:4008 msgid "ldap_purge_cache_offset" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3805 +#: sssd.conf.5.xml:4011 msgid "" "ldap_krb5_keytab (the value of krb5_keytab will be used if ldap_krb5_keytab " "is not set explicitly)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3809 +#: sssd.conf.5.xml:4015 msgid "ldap_krb5_ticket_lifetime" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3812 +#: sssd.conf.5.xml:4018 msgid "ldap_connection_expire_timeout" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3815 +#: sssd.conf.5.xml:4021 msgid "ldap_connection_expire_offset" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3818 +#: sssd.conf.5.xml:4024 msgid "ldap_connection_idle_timeout" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3821 sssd-ldap.5.xml:446 +#: sssd.conf.5.xml:4027 sssd-ldap.5.xml:446 msgid "ldap_use_tokengroups" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3824 +#: sssd.conf.5.xml:4030 msgid "ldap_user_principal" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3827 +#: sssd.conf.5.xml:4033 msgid "ignore_group_members" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3830 +#: sssd.conf.5.xml:4036 msgid "auto_private_groups" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3833 +#: sssd.conf.5.xml:4039 msgid "case_sensitive" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:3838 +#: sssd.conf.5.xml:4044 #, no-wrap msgid "" "subdomain_inherit = ldap_purge_cache_timeout\n" @@ -4431,27 +4635,27 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3845 +#: sssd.conf.5.xml:4051 msgid "Note: This option only works with the IPA and AD provider." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3852 +#: sssd.conf.5.xml:4058 msgid "subdomain_homedir (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3863 +#: sssd.conf.5.xml:4069 msgid "%F" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3864 +#: sssd.conf.5.xml:4070 msgid "flat (NetBIOS) name of a subdomain." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3855 +#: sssd.conf.5.xml:4061 msgid "" "Use this homedir as default value for all subdomains within this domain in " "IPA AD trust. See <emphasis>override_homedir</emphasis> for info about " @@ -4461,55 +4665,55 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3869 +#: sssd.conf.5.xml:4075 msgid "" "The value can be overridden by <emphasis>override_homedir</emphasis> option." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3873 +#: sssd.conf.5.xml:4079 msgid "Default: <filename>/home/%d/%u</filename>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3878 +#: sssd.conf.5.xml:4084 msgid "realmd_tags (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3881 +#: sssd.conf.5.xml:4087 msgid "" "Various tags stored by the realmd configuration service for this domain." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3887 +#: sssd.conf.5.xml:4093 msgid "cached_auth_timeout (int)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3890 +#: sssd.conf.5.xml:4096 msgid "" -"Specifies time in seconds since last successful online authentication for " -"which user will be authenticated using cached credentials while SSSD is in " -"the online mode. If the credentials are incorrect, SSSD falls back to online " -"authentication." +"Specifies the number of seconds since the last successful online " +"authentication during which SSSD will authenticate users via cached " +"credentials, even while online. If the cached authentication fails, SSSD " +"immediately falls back to online authentication." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3898 +#: sssd.conf.5.xml:4103 msgid "" "This option's value is inherited by all trusted domains. At the moment it is " "not possible to set a different value per trusted domain." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3903 +#: sssd.conf.5.xml:4108 msgid "Special value 0 implies that this feature is disabled." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3907 +#: sssd.conf.5.xml:4112 msgid "" "Please note that if <quote>cached_auth_timeout</quote> is longer than " "<quote>pam_id_timeout</quote> then the back end could be called to handle " @@ -4517,12 +4721,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:3918 +#: sssd.conf.5.xml:4123 msgid "local_auth_policy (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3921 +#: sssd.conf.5.xml:4126 msgid "" "Local authentication methods policy. Some backends (i.e. LDAP, proxy " "provider) only support a password based authentication, while others can " @@ -4534,7 +4738,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3933 +#: sssd.conf.5.xml:4138 msgid "" "There are three possible values for this option: match, only, enable. " "<quote>match</quote> is used to match offline and online states for Kerberos " @@ -4546,7 +4750,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3946 +#: sssd.conf.5.xml:4151 msgid "" "The following table shows which authentication methods, if configured " "properly, are currently enabled or disabled for each backend, with the " @@ -4554,42 +4758,47 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> -#: sssd.conf.5.xml:3959 +#: sssd.conf.5.xml:4164 msgid "local_auth_policy = match (default)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> -#: sssd.conf.5.xml:3960 +#: sssd.conf.5.xml:4165 msgid "Passkey" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> -#: sssd.conf.5.xml:3961 +#: sssd.conf.5.xml:4166 msgid "Smartcard" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:3964 sssd-ldap.5.xml:228 +#: sssd.conf.5.xml:4169 sssd-ldap.5.xml:228 msgid "IPA" msgstr "" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry><para> +#: sssd.conf.5.xml:4169 sssd.conf.5.xml:4170 sssd.conf.5.xml:4173 +msgid "enabled" +msgstr "" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:3967 sssd-ldap.5.xml:233 +#: sssd.conf.5.xml:4172 sssd-ldap.5.xml:233 msgid "AD" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry><para> -#: sssd.conf.5.xml:3967 sssd.conf.5.xml:3970 sssd.conf.5.xml:3971 +#: sssd.conf.5.xml:4172 sssd.conf.5.xml:4175 sssd.conf.5.xml:4176 msgid "disabled" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry> -#: sssd.conf.5.xml:3970 +#: sssd.conf.5.xml:4175 msgid "LDAP" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3975 +#: sssd.conf.5.xml:4180 msgid "" "Please note that if local Smartcard authentication is enabled and a " "Smartcard is present, Smartcard authentication will be preferred over the " @@ -4598,7 +4807,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:3987 +#: sssd.conf.5.xml:4192 #, no-wrap msgid "" "[domain/shadowutils]\n" @@ -4609,7 +4818,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3983 +#: sssd.conf.5.xml:4188 msgid "" "The following configuration example allows local users to authenticate " "locally using any enabled method (i.e. smartcard, passkey). <placeholder " @@ -4617,31 +4826,31 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:3995 +#: sssd.conf.5.xml:4200 #, fuzzy #| msgid "Default: 3" msgid "Default: match" msgstr "默认: 3" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4000 +#: sssd.conf.5.xml:4205 msgid "auto_private_groups (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4006 +#: sssd.conf.5.xml:4211 msgid "true" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4009 +#: sssd.conf.5.xml:4214 msgid "" "Create user's private group unconditionally from user's UID number. The GID " "number is ignored in this case." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4013 +#: sssd.conf.5.xml:4218 msgid "" "NOTE: Because the GID number and the user private group are inferred from " "the UID number, it is not supported to have multiple entries with the same " @@ -4650,24 +4859,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4022 +#: sssd.conf.5.xml:4227 msgid "false" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4025 +#: sssd.conf.5.xml:4230 msgid "" "Always use the user's primary GID number. The GID number must refer to a " "group object in the LDAP database." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4031 +#: sssd.conf.5.xml:4236 msgid "hybrid" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4034 +#: sssd.conf.5.xml:4239 msgid "" "A primary group is autogenerated for user entries whose UID and GID numbers " "have the same value and at the same time the GID number does not correspond " @@ -4677,14 +4886,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4047 +#: sssd.conf.5.xml:4252 msgid "" "If the UID and GID of a user are different, then the GID must correspond to " "a group entry, otherwise the GID is simply not resolvable." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4054 +#: sssd.conf.5.xml:4259 msgid "" "This feature is useful for environments that wish to stop maintaining a " "separate group objects for the user private groups, but also wish to retain " @@ -4692,14 +4901,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4003 +#: sssd.conf.5.xml:4208 msgid "" "This option takes any of three available values: <placeholder " "type=\"variablelist\" id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4066 +#: sssd.conf.5.xml:4271 msgid "" "For the LDAP based id providers (LDAP, IPA and AD) the default for the " "configured domain is typically False because the sources have the concept of " @@ -4709,14 +4918,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4075 +#: sssd.conf.5.xml:4280 msgid "" "For subdomains, the default value is False for subdomains that use assigned " "POSIX IDs and True for subdomains that use automatic ID-mapping." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:4083 +#: sssd.conf.5.xml:4288 #, no-wrap msgid "" "[domain/forest.domain/sub.domain]\n" @@ -4724,7 +4933,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd.conf.5.xml:4089 +#: sssd.conf.5.xml:4294 #, no-wrap msgid "" "[domain/forest.domain]\n" @@ -4733,7 +4942,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4080 +#: sssd.conf.5.xml:4285 msgid "" "The value of auto_private_groups can either be set per subdomains in a " "subsection, for example: <placeholder type=\"programlisting\" id=\"0\"/> or " @@ -4742,7 +4951,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:2503 +#: sssd.conf.5.xml:2549 msgid "" "These configuration options can be present in a domain configuration " "section, that is, in a section called <quote>[domain/<replaceable>NAME</" @@ -4750,17 +4959,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4104 +#: sssd.conf.5.xml:4309 msgid "proxy_pam_target (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4107 +#: sssd.conf.5.xml:4312 msgid "The proxy target PAM proxies to." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4110 +#: sssd.conf.5.xml:4315 msgid "" "Default: not set by default, you have to take an existing pam configuration " "or create a new one and add the service name here. As an alternative you can " @@ -4768,12 +4977,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4120 +#: sssd.conf.5.xml:4325 msgid "proxy_lib_name (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4123 +#: sssd.conf.5.xml:4328 msgid "" "The name of the NSS library to use in proxy domains. The NSS functions " "searched for in the library are in the form of _nss_$(libName)_$(function), " @@ -4781,12 +4990,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4133 +#: sssd.conf.5.xml:4338 msgid "proxy_resolver_lib_name (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4136 +#: sssd.conf.5.xml:4341 msgid "" "The name of the NSS library to use for hosts and networks lookups in proxy " "domains. The NSS functions searched for in the library are in the form of " @@ -4794,12 +5003,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4147 +#: sssd.conf.5.xml:4352 msgid "proxy_fast_alias (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4150 +#: sssd.conf.5.xml:4355 msgid "" "When a user or group is looked up by name in the proxy provider, a second " "lookup by ID is performed to \"canonicalize\" the name in case the requested " @@ -4808,12 +5017,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4164 +#: sssd.conf.5.xml:4369 msgid "proxy_max_children (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4167 +#: sssd.conf.5.xml:4372 msgid "" "This option specifies the number of pre-forked proxy children. It is useful " "for high-load SSSD environments where sssd may run out of available child " @@ -4821,19 +5030,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4100 +#: sssd.conf.5.xml:4305 msgid "" "Options valid for proxy domains. <placeholder type=\"variablelist\" " "id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd.conf.5.xml:4183 +#: sssd.conf.5.xml:4388 msgid "Application domains" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:4185 +#: sssd.conf.5.xml:4390 msgid "" "SSSD, with its D-Bus interface (see <citerefentry> <refentrytitle>sssd-ifp</" "refentrytitle> <manvolnum>5</manvolnum> </citerefentry>) is appealing to " @@ -4850,7 +5059,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:4205 +#: sssd.conf.5.xml:4410 msgid "" "Please note that the application domain must still be explicitly enabled in " "the <quote>domains</quote> parameter so that the lookup order between the " @@ -4858,17 +5067,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><title> -#: sssd.conf.5.xml:4211 +#: sssd.conf.5.xml:4416 msgid "Application domain parameters" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4213 +#: sssd.conf.5.xml:4418 msgid "inherit_from (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4216 +#: sssd.conf.5.xml:4421 msgid "" "The SSSD POSIX-type domain the application domain inherits all settings " "from. The application domain can moreover add its own settings to the " @@ -4877,7 +5086,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd.conf.5.xml:4230 +#: sssd.conf.5.xml:4435 msgid "" "The following example illustrates the use of an application domain. In this " "setup, the POSIX domain is connected to an LDAP server and is used by the OS " @@ -4887,7 +5096,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><programlisting> -#: sssd.conf.5.xml:4238 +#: sssd.conf.5.xml:4443 #, no-wrap msgid "" "[sssd]\n" @@ -4907,12 +5116,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:4258 +#: sssd.conf.5.xml:4463 msgid "TRUSTED DOMAIN SECTION" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4260 +#: sssd.conf.5.xml:4465 msgid "" "Some options used in the domain section can also be used in the trusted " "domain section, that is, in a section called <quote>[domain/" @@ -4923,69 +5132,79 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4267 +#: sssd.conf.5.xml:4472 msgid "ldap_search_base," msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4268 +#: sssd.conf.5.xml:4473 msgid "ldap_user_search_base," msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4269 +#: sssd.conf.5.xml:4474 msgid "ldap_group_search_base," msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4270 +#: sssd.conf.5.xml:4475 msgid "ldap_netgroup_search_base," msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4271 +#: sssd.conf.5.xml:4476 msgid "ldap_service_search_base," msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4272 +#: sssd.conf.5.xml:4477 msgid "ldap_sasl_mech," msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4273 +#: sssd.conf.5.xml:4478 msgid "ad_server," msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4274 +#: sssd.conf.5.xml:4479 msgid "ad_backup_server," msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4275 +#: sssd.conf.5.xml:4480 msgid "ad_site," msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:4276 sssd-ipa.5.xml:934 +#: sssd.conf.5.xml:4481 sssd-ipa.5.xml:929 msgid "use_fully_qualified_names" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4280 +#: sssd.conf.5.xml:4482 +msgid "pam_gssapi_services" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:4483 +msgid "pam_gssapi_check_upn" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:4485 msgid "" "For more details about these options see their individual description in the " "manual page." msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:4286 +#: sssd.conf.5.xml:4491 msgid "CERTIFICATE MAPPING SECTION" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4288 +#: sssd.conf.5.xml:4493 msgid "" "To allow authentication with Smartcards and certificates SSSD must be able " "to map certificates to users. This can be done by adding the full " @@ -4998,7 +5217,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4302 +#: sssd.conf.5.xml:4507 msgid "" "To make the mapping more flexible mapping and matching rules were added to " "SSSD (see <citerefentry> <refentrytitle>sss-certmap</refentrytitle> " @@ -5006,7 +5225,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4311 +#: sssd.conf.5.xml:4516 msgid "" "A mapping and matching rule can be added to the SSSD configuration in a " "section on its own with a name like <quote>[certmap/" @@ -5015,55 +5234,50 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4318 +#: sssd.conf.5.xml:4523 msgid "matchrule (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4321 +#: sssd.conf.5.xml:4526 msgid "" "Only certificates from the Smartcard which matches this rule will be " "processed, all others are ignored." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4325 +#: sssd.conf.5.xml:4530 msgid "" "Default: KRB5:<EKU>clientAuth, i.e. only certificates which have the " "Extended Key Usage <quote>clientAuth</quote>" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4332 +#: sssd.conf.5.xml:4537 msgid "maprule (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4335 +#: sssd.conf.5.xml:4540 msgid "Defines how the user is found for a given certificate." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:4341 +#: sssd.conf.5.xml:4546 msgid "" "LDAP:(userCertificate;binary={cert!bin}) for LDAP based providers like " "<quote>ldap</quote>, <quote>AD</quote> or <quote>ipa</quote>." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:4347 +#: sssd.conf.5.xml:4552 msgid "" "If maprule is not set and provider is <quote>proxy</quote>, the RULE_NAME " "name is assumed to be the name of the matching user." msgstr "" -#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4357 -msgid "domains (string)" -msgstr "" - #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4360 +#: sssd.conf.5.xml:4565 msgid "" "Comma separated list of domain names the rule should be applied. By default " "a rule is only valid in the domain configured in sssd.conf. If the provider " @@ -5072,17 +5286,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4367 +#: sssd.conf.5.xml:4572 msgid "Default: the configured domain in sssd.conf" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4372 +#: sssd.conf.5.xml:4577 msgid "priority (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4375 +#: sssd.conf.5.xml:4580 msgid "" "Unsigned integer value defining the priority of the rule. The higher the " "number the lower the priority. <quote>0</quote> stands for the highest " @@ -5090,17 +5304,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4381 +#: sssd.conf.5.xml:4586 msgid "Default: the lowest priority" msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:4389 +#: sssd.conf.5.xml:4594 msgid "PROMPTING CONFIGURATION SECTION" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4391 +#: sssd.conf.5.xml:4596 msgid "" "If a special file (<filename>/var/lib/sss/pubconf/pam_preauth_available</" "filename>) exists SSSD's PAM module pam_sss will ask SSSD to figure out " @@ -5110,7 +5324,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4399 +#: sssd.conf.5.xml:4604 msgid "" "With the growing number of authentication methods and the possibility that " "there are multiple ones for a single user the heuristic used by pam_sss to " @@ -5119,59 +5333,59 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4411 +#: sssd.conf.5.xml:4616 msgid "[prompting/password]" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4414 +#: sssd.conf.5.xml:4619 msgid "password_prompt" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4415 +#: sssd.conf.5.xml:4620 msgid "to change the string of the password prompt" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4413 +#: sssd.conf.5.xml:4618 msgid "" "to configure password prompting, allowed options are: <placeholder " "type=\"variablelist\" id=\"0\"/>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4423 +#: sssd.conf.5.xml:4628 msgid "[prompting/2fa]" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4427 +#: sssd.conf.5.xml:4632 msgid "first_prompt" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4428 +#: sssd.conf.5.xml:4633 msgid "to change the string of the prompt for the first factor" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4431 +#: sssd.conf.5.xml:4636 msgid "second_prompt" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4432 +#: sssd.conf.5.xml:4637 msgid "to change the string of the prompt for the second factor" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4435 +#: sssd.conf.5.xml:4640 msgid "single_prompt" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4436 +#: sssd.conf.5.xml:4641 msgid "" "boolean value, if True there will be only a single prompt using the value of " "first_prompt where it is expected that both factors are entered as a single " @@ -5180,7 +5394,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4425 +#: sssd.conf.5.xml:4630 msgid "" "to configure two-factor authentication prompting, allowed options are: " "<placeholder type=\"variablelist\" id=\"0\"/> If the second factor is " @@ -5189,7 +5403,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4449 +#: sssd.conf.5.xml:4654 msgid "" "Some clients, such as SSH with 'PasswordAuthentication yes', generate their " "own prompts and do not use prompts provided by SSSD or other PAM modules. " @@ -5200,17 +5414,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4464 +#: sssd.conf.5.xml:4669 msgid "[prompting/passkey]" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd.conf.5.xml:4470 sssd-ad.5.xml:1022 +#: sssd.conf.5.xml:4675 sssd.conf.5.xml:4719 sssd-ad.5.xml:1027 msgid "interactive" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4472 +#: sssd.conf.5.xml:4677 msgid "" "boolean value, if True prompt a message and wait before testing the presence " "of a passkey device. Recommended if your device doesn’t have a tactile " @@ -5218,55 +5432,131 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4480 +#: sssd.conf.5.xml:4685 sssd.conf.5.xml:4735 msgid "interactive_prompt" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4482 +#: sssd.conf.5.xml:4687 sssd.conf.5.xml:4737 msgid "to change the message of the interactive prompt." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4487 +#: sssd.conf.5.xml:4692 msgid "touch" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4489 +#: sssd.conf.5.xml:4694 msgid "" "boolean value, if True prompt a message to remind the user to touch the " "device." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> -#: sssd.conf.5.xml:4495 +#: sssd.conf.5.xml:4700 msgid "touch_prompt" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4497 +#: sssd.conf.5.xml:4702 msgid "to change the message of the touch prompt." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd.conf.5.xml:4466 +#: sssd.conf.5.xml:4671 msgid "" "to configure passkey authentication prompting, allowed options are: " "<placeholder type=\"variablelist\" id=\"0\"/>" msgstr "" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4713 +msgid "[prompting/oauth2]" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4721 +msgid "" +"boolean value, if True prompt a message after asking the user to " +"authenticate, and wait before requesting the access token." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4725 +msgid "" +"If False, make sure to set the <quote>idp_request_timeout</quote> " +"sufficiently high, to give the user time to authenticate." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4715 +msgid "" +"to configure OAuth2 authentication prompting, allowed options are: " +"<placeholder type=\"variablelist\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4748 +msgid "[prompting/cert_auth]" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4754 +msgid "pin_prompt" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4756 +msgid "" +"to change the message which asks the user to enter the PIN at the computer " +"keyboard. At the end of the message the token name is printed." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4764 +msgid "keypad_prompt" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4766 +msgid "" +"to change the message which asks the user to enter the PIN at keypad of the " +"Smartcard reader. At the end of the message the token name is printed." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4774 +msgid "user_name_hint" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4776 +msgid "" +"boolean value, if True ask for a user name if no name was given before and " +"the found certificate can be mapped to more than one user." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4750 +msgid "" +"to configure Smartcard authentication prompting, allowed options are: " +"<placeholder type=\"variablelist\" id=\"0\"/>" +msgstr "" + #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4406 +#: sssd.conf.5.xml:4611 msgid "" "Each supported authentication method has its own configuration subsection " "under <quote>[prompting/...]</quote>. Currently there are: <placeholder " "type=\"variablelist\" id=\"0\"/> <placeholder type=\"variablelist\" id=\"1\"/" -"> <placeholder type=\"variablelist\" id=\"2\"/>" +"> <placeholder type=\"variablelist\" id=\"2\"/> <placeholder " +"type=\"variablelist\" id=\"3\"/> <placeholder type=\"variablelist\" id=\"4\"/" +">" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4508 +#: sssd.conf.5.xml:4792 msgid "" "It is possible to add a subsection for specific PAM services, e.g. " "<quote>[prompting/password/sshd]</quote> to individual change the prompting " @@ -5274,12 +5564,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd.conf.5.xml:4515 pam_sss_gss.8.xml:157 idmap_sss.8.xml:43 +#: sssd.conf.5.xml:4799 pam_sss_gss.8.xml:157 idmap_sss.8.xml:43 msgid "EXAMPLES" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd.conf.5.xml:4521 +#: sssd.conf.5.xml:4805 #, no-wrap msgid "" "[sssd]\n" @@ -5308,7 +5598,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4517 +#: sssd.conf.5.xml:4801 msgid "" "1. The following example shows a typical SSSD config. It does not describe " "configuration of the domains themselves - refer to documentation on " @@ -5317,7 +5607,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd.conf.5.xml:4553 +#: sssd.conf.5.xml:4837 #, no-wrap msgid "" "[domain/ipa.com/child.ad.com]\n" @@ -5325,7 +5615,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4547 +#: sssd.conf.5.xml:4831 msgid "" "2. The following example shows configuration of IPA AD trust where the AD " "forest consists of two domains in a parent-child structure. Suppose IPA " @@ -5336,7 +5626,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd.conf.5.xml:4564 +#: sssd.conf.5.xml:4848 #, no-wrap msgid "" "[certmap/my.domain/rule_name]\n" @@ -5347,7 +5637,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd.conf.5.xml:4558 +#: sssd.conf.5.xml:4842 msgid "" "3. The following example shows the configuration of a certificate mapping " "rule. It is valid for the configured domain <quote>my.domain</quote> and " @@ -5544,7 +5834,7 @@ msgid "" "defaultNamingContext does not exist or has an empty value namingContexts is " "used. The namingContexts attribute must have a single value with the DN of " "the search base of the LDAP server to make this work. Multiple values are " -"are not supported." +"not supported." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> @@ -5847,15 +6137,15 @@ msgid "Optional. Use the given string as search base for host objects." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap.5.xml:472 sssd-ipa.5.xml:506 sssd-ipa.5.xml:525 sssd-ipa.5.xml:544 -#: sssd-ipa.5.xml:563 +#: sssd-ldap.5.xml:472 sssd-ipa.5.xml:501 sssd-ipa.5.xml:520 sssd-ipa.5.xml:539 +#: sssd-ipa.5.xml:558 msgid "" "See <quote>ldap_search_base</quote> for information about configuring " "multiple search bases." msgstr "" #. type: Content of: <listitem><para> -#: sssd-ldap.5.xml:477 sssd-ipa.5.xml:511 include/ldap_search_bases.xml:27 +#: sssd-ldap.5.xml:477 sssd-ipa.5.xml:506 include/ldap_search_bases.xml:27 msgid "Default: the value of <emphasis>ldap_search_base</emphasis>" msgstr "" @@ -5979,7 +6269,7 @@ msgid "" "closed early to ensure that a new query cannot require the connection to " "remain open past its expiration. This implies that connections will always " "be closed immediately and will never be reused if " -"<emphasis>ldap_connection_expire_timeout <= ldap_opt_timout</emphasis>" +"<emphasis>ldap_connection_expire_timeout <= ldap_opt_timeout</emphasis>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> @@ -6161,7 +6451,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:831 -msgid "ldap_ignore_unreadable_references (bool)" +msgid "ldap_ignore_unreadable_references (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> @@ -6486,7 +6776,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap.5.xml:1152 sssd-ad.5.xml:1267 +#: sssd-ldap.5.xml:1152 sssd-ad.5.xml:1260 msgid "Default: 86400 (24 hours)" msgstr "" @@ -6524,7 +6814,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ldap.5.xml:1187 sssd-ipa.5.xml:575 sssd-krb5.5.xml:103 +#: sssd-ldap.5.xml:1187 sssd-ipa.5.xml:570 sssd-krb5.5.xml:103 msgid "krb5_realm (string)" msgstr "" @@ -6680,7 +6970,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1339 -msgid "ldap_chpass_update_last_change (bool)" +msgid "ldap_chpass_update_last_change (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> @@ -6827,7 +7117,7 @@ msgid "ldap_access_order (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap.5.xml:1470 sssd-ipa.5.xml:405 +#: sssd-ldap.5.xml:1470 sssd-ipa.5.xml:400 msgid "Comma separated list of access control options. Allowed values are:" msgstr "" @@ -6872,7 +7162,7 @@ msgid "<emphasis>expire</emphasis>: use ldap_account_expire_policy" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap.5.xml:1515 sssd-ipa.5.xml:413 +#: sssd-ldap.5.xml:1515 sssd-ipa.5.xml:408 msgid "" "<emphasis>pwd_expire_policy_reject, pwd_expire_policy_warn, " "pwd_expire_policy_renew: </emphasis> These options are useful if users are " @@ -6882,24 +7172,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap.5.xml:1525 sssd-ipa.5.xml:423 +#: sssd-ldap.5.xml:1525 sssd-ipa.5.xml:418 msgid "" "The difference between these options is the action taken if user password is " "expired:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ldap.5.xml:1530 sssd-ipa.5.xml:428 +#: sssd-ldap.5.xml:1530 sssd-ipa.5.xml:423 msgid "pwd_expire_policy_reject - user is denied to log in," msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ldap.5.xml:1536 sssd-ipa.5.xml:434 +#: sssd-ldap.5.xml:1536 sssd-ipa.5.xml:429 msgid "pwd_expire_policy_warn - user is still able to log in," msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ldap.5.xml:1542 sssd-ipa.5.xml:440 +#: sssd-ldap.5.xml:1542 sssd-ipa.5.xml:435 msgid "" "pwd_expire_policy_renew - user is prompted to change their password " "immediately." @@ -7434,8 +7724,8 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd-ldap.5.xml:2032 sssd-simple.5.xml:169 sssd-ipa.5.xml:984 -#: sssd-ad.5.xml:1470 sssd-idp.5.xml:248 sssd-krb5.5.xml:483 +#: sssd-ldap.5.xml:2032 sssd-simple.5.xml:169 sssd-ipa.5.xml:979 +#: sssd-ad.5.xml:1463 sssd-idp.5.xml:343 sssd-krb5.5.xml:483 #: sss_rpcidmapd.5.xml:98 sssd-session-recording.5.xml:176 msgid "EXAMPLE" msgstr "" @@ -7463,7 +7753,7 @@ msgstr "" #. type: Content of: <refsect1><refsect2><para> #: sssd-ldap.5.xml:2039 sssd-ldap.5.xml:2057 sssd-simple.5.xml:177 -#: sssd-ipa.5.xml:992 sssd-ad.5.xml:1478 sssd-sudo.5.xml:56 sssd-krb5.5.xml:492 +#: sssd-ipa.5.xml:987 sssd-ad.5.xml:1471 sssd-sudo.5.xml:56 sssd-krb5.5.xml:492 #: sssd-session-recording.5.xml:182 include/ldap_id_mapping.xml:105 msgid "<placeholder type=\"programlisting\" id=\"0\"/>" msgstr "" @@ -7498,7 +7788,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><title> #: sssd-ldap.5.xml:2073 sssd_krb5_locator_plugin.8.xml:83 sssd-simple.5.xml:189 -#: sssd-ad.5.xml:1493 sssd.8.xml:270 sss_seed.8.xml:163 +#: sssd-ad.5.xml:1486 sssd.8.xml:270 sss_seed.8.xml:163 msgid "NOTES" msgstr "" @@ -8005,7 +8295,7 @@ msgstr "" #: pam_sss.8.xml:434 msgid "" "No authentication method was found by Kerberos. This might happen if the " -"user has a Smartcard assigned but the pkint plugin is not available on the " +"user has a Smartcard assigned but the pkinit plugin is not available on the " "client." msgstr "" @@ -8429,6 +8719,23 @@ msgid "" "first DNS resolving failure." msgstr "" +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_locator_plugin.8.xml:106 +msgid "" +"If the environment variable SSSD_KRB5_LOCATOR_KDC_ADDRESS is set to a KDC " +"address the plugin will use this address instead of reading the kdcinfo " +"file. The address format is the same as in the kdcinfo file (see above)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_locator_plugin.8.xml:112 +msgid "" +"If the environment variable SSSD_KRB5_LOCATOR_KPASSWD_ADDRESS is set to a " +"kpasswd server address the plugin will use this address instead of reading " +"the kpasswdinfo file. The address format is the same as in the kpasswdinfo " +"file (see above)." +msgstr "" + #. type: Content of: <reference><refentry><refnamediv><refname> #: sssd-simple.5.xml:10 sssd-simple.5.xml:16 msgid "sssd-simple" @@ -9812,7 +10119,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:129 sssd-ad.5.xml:1161 +#: sssd-ipa.5.xml:129 sssd-ad.5.xml:1166 msgid "dyndns_update (boolean)" msgstr "" @@ -9826,20 +10133,13 @@ msgid "" "quote> option." msgstr "" -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:141 sssd-ad.5.xml:1175 -msgid "" -"NOTE: On older systems (such as RHEL 5), for this behavior to work reliably, " -"the default Kerberos realm must be set properly in /etc/krb5.conf" -msgstr "" - #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:152 sssd-ad.5.xml:1186 +#: sssd-ipa.5.xml:147 sssd-ad.5.xml:1186 msgid "dyndns_ttl (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:155 sssd-ad.5.xml:1189 +#: sssd-ipa.5.xml:150 sssd-ad.5.xml:1189 msgid "" "The TTL to apply to the client DNS record when updating it. If " "dyndns_update is false this has no effect. This will override the TTL " @@ -9847,17 +10147,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:160 +#: sssd-ipa.5.xml:155 msgid "Default: 1200 (seconds)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:166 sssd-ad.5.xml:1200 +#: sssd-ipa.5.xml:161 sssd-ad.5.xml:1200 msgid "dyndns_iface (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:169 sssd-ad.5.xml:1203 +#: sssd-ipa.5.xml:164 sssd-ad.5.xml:1203 msgid "" "Optional. Applicable only when dyndns_update is true. Choose the interface " "or a list of interfaces whose IP addresses should be used for dynamic DNS " @@ -9869,24 +10169,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:182 +#: sssd-ipa.5.xml:177 msgid "" "Default: Use the IP addresses of the interface which is used for IPA LDAP " "connection" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:186 sssd-ad.5.xml:1226 +#: sssd-ipa.5.xml:181 sssd-ad.5.xml:1220 msgid "Example: dyndns_iface = em[12], !vnet1, vnet*" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:192 sssd-ad.5.xml:1232 +#: sssd-ipa.5.xml:187 sssd-ad.5.xml:1226 msgid "dyndns_address (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:195 sssd-ad.5.xml:1235 +#: sssd-ipa.5.xml:190 sssd-ad.5.xml:1229 msgid "" "Optional. Applicable only when <emphasis>dyndns_update</emphasis> is true. " "A list of IP addresses or IP networks to be used for dynamic DNS updates. " @@ -9897,22 +10197,22 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:206 sssd-ad.5.xml:1246 +#: sssd-ipa.5.xml:201 sssd-ad.5.xml:1240 msgid "Default: No filtering of IP addresses." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:209 sssd-ad.5.xml:1249 +#: sssd-ipa.5.xml:204 sssd-ad.5.xml:1243 msgid "Example: dyndns_address = 10.0.0.0/16, !10.0.1.0/24" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:215 sssd-ad.5.xml:1305 +#: sssd-ipa.5.xml:210 sssd-ad.5.xml:1298 msgid "dyndns_auth (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:218 sssd-ad.5.xml:1308 +#: sssd-ipa.5.xml:213 sssd-ad.5.xml:1301 msgid "" "Whether the nsupdate utility should use GSS-TSIG authentication for secure " "updates with the DNS server, insecure updates can be sent by setting this " @@ -9920,17 +10220,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:224 sssd-ad.5.xml:1314 +#: sssd-ipa.5.xml:219 sssd-ad.5.xml:1307 msgid "Default: GSS-TSIG" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:230 sssd-ad.5.xml:1320 +#: sssd-ipa.5.xml:225 sssd-ad.5.xml:1313 msgid "dyndns_auth_ptr (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:233 sssd-ad.5.xml:1323 +#: sssd-ipa.5.xml:228 sssd-ad.5.xml:1316 msgid "" "Whether the nsupdate utility should use GSS-TSIG authentication for secure " "PTR updates with the DNS server, insecure updates can be sent by setting " @@ -9938,17 +10238,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:239 sssd-ad.5.xml:1329 +#: sssd-ipa.5.xml:234 sssd-ad.5.xml:1322 msgid "Default: Same as dyndns_auth" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:245 sssd-ad.5.xml:1255 +#: sssd-ipa.5.xml:240 sssd-ad.5.xml:1249 msgid "dyndns_refresh_interval (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:248 +#: sssd-ipa.5.xml:243 msgid "" "How often should the back end perform periodic DNS update in addition to the " "automatic update performed when the back end goes online. This option is " @@ -9956,74 +10256,74 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:261 sssd-ad.5.xml:1273 -msgid "dyndns_update_ptr (bool)" +#: sssd-ipa.5.xml:256 sssd-ad.5.xml:1266 +msgid "dyndns_update_ptr (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:264 sssd-ad.5.xml:1276 +#: sssd-ipa.5.xml:259 sssd-ad.5.xml:1269 msgid "" "Whether the PTR record should also be explicitly updated when updating the " "client's DNS records. Applicable only when dyndns_update is true." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:269 +#: sssd-ipa.5.xml:264 msgid "" "This option should be False in most IPA deployments as the IPA server " "generates the PTR records automatically when forward records are changed." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:275 sssd-ad.5.xml:1281 +#: sssd-ipa.5.xml:270 sssd-ad.5.xml:1274 msgid "" "Note that <emphasis>dyndns_update_per_family</emphasis> parameter does not " "apply for PTR record updates. Those updates are always sent separately." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:280 +#: sssd-ipa.5.xml:275 msgid "Default: False (disabled)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:286 sssd-ad.5.xml:1292 -msgid "dyndns_force_tcp (bool)" +#: sssd-ipa.5.xml:281 sssd-ad.5.xml:1285 +msgid "dyndns_force_tcp (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:289 sssd-ad.5.xml:1295 +#: sssd-ipa.5.xml:284 sssd-ad.5.xml:1288 msgid "" "Whether the nsupdate utility should default to using TCP for communicating " "with the DNS server." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:293 sssd-ad.5.xml:1299 +#: sssd-ipa.5.xml:288 sssd-ad.5.xml:1292 msgid "Default: False (let nsupdate choose the protocol)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:299 sssd-ad.5.xml:1335 +#: sssd-ipa.5.xml:294 sssd-ad.5.xml:1328 msgid "dyndns_server (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:302 sssd-ad.5.xml:1338 +#: sssd-ipa.5.xml:297 sssd-ad.5.xml:1331 msgid "" "The DNS server to use when performing a DNS update. In most setups, it's " "recommended to leave this option unset." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:307 sssd-ad.5.xml:1343 +#: sssd-ipa.5.xml:302 sssd-ad.5.xml:1336 msgid "" "Setting this option makes sense for environments where the DNS server is " "different from the identity server or when we use encrypted DNS." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:312 sssd-ad.5.xml:1348 +#: sssd-ipa.5.xml:307 sssd-ad.5.xml:1341 msgid "" "The parameter can be a simple string containing DNS name or IP address. It " "can also be an URI. The URI can look like <emphasis>dns://servername/</" @@ -10031,7 +10331,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:319 sssd-ad.5.xml:1355 +#: sssd-ipa.5.xml:314 sssd-ad.5.xml:1348 msgid "" "The second example enables DNS-over-TLS protocol for DNS updates. The " "nsupdate utility must support DoT - check the <emphasis>man nsupdate</" @@ -10039,7 +10339,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:325 sssd-ad.5.xml:1361 +#: sssd-ipa.5.xml:320 sssd-ad.5.xml:1354 msgid "" "Please note that this option will be only used in fallback attempt when " "previous attempt using autodetected settings failed or when DNS-over-TLS is " @@ -10047,17 +10347,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:331 sssd-ad.5.xml:1367 +#: sssd-ipa.5.xml:326 sssd-ad.5.xml:1360 msgid "Default: None (let nsupdate choose the server)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:337 sssd-ad.5.xml:1373 +#: sssd-ipa.5.xml:332 sssd-ad.5.xml:1366 msgid "dyndns_update_per_family (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:340 sssd-ad.5.xml:1376 +#: sssd-ipa.5.xml:335 sssd-ad.5.xml:1369 msgid "" "DNS update is by default performed in two steps - IPv4 update and then IPv6 " "update. In some cases it might be desirable to perform IPv4 and IPv6 update " @@ -10065,12 +10365,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:352 sssd-ad.5.xml:1388 +#: sssd-ipa.5.xml:347 sssd-ad.5.xml:1381 msgid "dyndns_dot_cacert (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:355 sssd-ad.5.xml:1391 +#: sssd-ipa.5.xml:350 sssd-ad.5.xml:1384 msgid "" "This option specifies the file of the certificate authorities certificates " "(in PEM format) in order to verify the remote server TLS certificate when " @@ -10078,17 +10378,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:361 sssd-ad.5.xml:1397 +#: sssd-ipa.5.xml:356 sssd-ad.5.xml:1390 msgid "Default: None (use global certificate store)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:367 sssd-ad.5.xml:1403 +#: sssd-ipa.5.xml:362 sssd-ad.5.xml:1396 msgid "dyndns_dot_cert (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:370 sssd-ad.5.xml:1406 +#: sssd-ipa.5.xml:365 sssd-ad.5.xml:1399 msgid "" "This option sets the certificate(s) file for authentication for the DoT " "transport to the remote server. The certificate chain file is expected to be " @@ -10096,24 +10396,24 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:376 sssd-ad.5.xml:1412 +#: sssd-ipa.5.xml:371 sssd-ad.5.xml:1405 msgid "" "The <emphasis>dyndns_dot_cert</emphasis> and <emphasis>dyndns_dot_key</" "emphasis> options must be both set to achieve mutual TLS authentication." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:381 sssd-ipa.5.xml:396 sssd-ad.5.xml:1417 sssd-ad.5.xml:1432 +#: sssd-ipa.5.xml:376 sssd-ipa.5.xml:391 sssd-ad.5.xml:1410 sssd-ad.5.xml:1425 msgid "Default: None (Do not use TLS authentication)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:387 sssd-ad.5.xml:1423 +#: sssd-ipa.5.xml:382 sssd-ad.5.xml:1416 msgid "dyndns_dot_key (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:390 sssd-ad.5.xml:1426 +#: sssd-ipa.5.xml:385 sssd-ad.5.xml:1419 msgid "" "This option sets the key file for authenticated encryption for the DoT " "transport to the remote server. The private key file is expected to be in " @@ -10121,170 +10421,170 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:402 +#: sssd-ipa.5.xml:397 msgid "ipa_access_order (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:409 +#: sssd-ipa.5.xml:404 msgid "<emphasis>expire</emphasis>: use IPA's account expiration policy." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:448 +#: sssd-ipa.5.xml:443 msgid "" "Please note that 'access_provider = ipa' must be set for this feature to " "work." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:455 +#: sssd-ipa.5.xml:450 msgid "ipa_deskprofile_search_base (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:458 +#: sssd-ipa.5.xml:453 msgid "" "Optional. Use the given string as search base for Desktop Profile related " "objects." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:462 sssd-ipa.5.xml:484 +#: sssd-ipa.5.xml:457 sssd-ipa.5.xml:479 msgid "Default: Use base DN" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:468 +#: sssd-ipa.5.xml:463 msgid "ipa_subid_ranges_search_base (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:471 +#: sssd-ipa.5.xml:466 msgid "Deprecated. Use ldap_subid_ranges_search_base instead." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:477 +#: sssd-ipa.5.xml:472 msgid "ipa_hbac_search_base (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:480 +#: sssd-ipa.5.xml:475 msgid "Optional. Use the given string as search base for HBAC related objects." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:490 +#: sssd-ipa.5.xml:485 msgid "ipa_host_search_base (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:493 +#: sssd-ipa.5.xml:488 msgid "Deprecated. Use ldap_host_search_base instead." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:499 +#: sssd-ipa.5.xml:494 msgid "ipa_selinux_search_base (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:502 +#: sssd-ipa.5.xml:497 msgid "Optional. Use the given string as search base for SELinux user maps." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:518 +#: sssd-ipa.5.xml:513 msgid "ipa_subdomains_search_base (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:521 +#: sssd-ipa.5.xml:516 msgid "Optional. Use the given string as search base for trusted domains." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:530 +#: sssd-ipa.5.xml:525 msgid "Default: the value of <emphasis>cn=trusts,%basedn</emphasis>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:537 +#: sssd-ipa.5.xml:532 msgid "ipa_master_domain_search_base (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:540 +#: sssd-ipa.5.xml:535 msgid "Optional. Use the given string as search base for master domain object." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:549 +#: sssd-ipa.5.xml:544 msgid "Default: the value of <emphasis>cn=ad,cn=etc,%basedn</emphasis>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:556 +#: sssd-ipa.5.xml:551 msgid "ipa_views_search_base (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:559 +#: sssd-ipa.5.xml:554 msgid "Optional. Use the given string as search base for views containers." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:568 +#: sssd-ipa.5.xml:563 msgid "Default: the value of <emphasis>cn=views,cn=accounts,%basedn</emphasis>" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:578 +#: sssd-ipa.5.xml:573 msgid "" "The name of the Kerberos realm. This is optional and defaults to the value " "of <quote>ipa_domain</quote>." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:582 +#: sssd-ipa.5.xml:577 msgid "" "The name of the Kerberos realm has a special meaning in IPA - it is " "converted into the base DN to use for performing LDAP operations." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:590 sssd-ad.5.xml:1441 +#: sssd-ipa.5.xml:585 sssd-ad.5.xml:1434 msgid "krb5_confd_path (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:593 sssd-ad.5.xml:1444 +#: sssd-ipa.5.xml:588 sssd-ad.5.xml:1437 msgid "" "Absolute path of a directory where SSSD should place Kerberos configuration " "snippets." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:597 sssd-ad.5.xml:1448 +#: sssd-ipa.5.xml:592 sssd-ad.5.xml:1441 msgid "" "To disable the creation of the configuration snippets set the parameter to " "'none'." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:601 sssd-ad.5.xml:1452 +#: sssd-ipa.5.xml:596 sssd-ad.5.xml:1445 msgid "" "Default: not set (krb5.include.d subdirectory of SSSD's pubconf directory)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:608 +#: sssd-ipa.5.xml:603 msgid "ipa_deskprofile_refresh (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:611 +#: sssd-ipa.5.xml:606 msgid "" "The amount of time between lookups of the Desktop Profile rules against the " "IPA server. This will reduce the latency and load on the IPA server if there " @@ -10292,34 +10592,34 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:618 sssd-ipa.5.xml:648 sssd-ipa.5.xml:664 sssd-ad.5.xml:600 +#: sssd-ipa.5.xml:613 sssd-ipa.5.xml:643 sssd-ipa.5.xml:659 sssd-ad.5.xml:600 msgid "Default: 5 (seconds)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:624 +#: sssd-ipa.5.xml:619 msgid "ipa_deskprofile_request_interval (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:627 +#: sssd-ipa.5.xml:622 msgid "" "The amount of time between lookups of the Desktop Profile rules against the " "IPA server in case the last request did not return any rule." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:632 +#: sssd-ipa.5.xml:627 msgid "Default: 60 (minutes)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:638 +#: sssd-ipa.5.xml:633 msgid "ipa_hbac_refresh (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:641 +#: sssd-ipa.5.xml:636 msgid "" "The amount of time between lookups of the HBAC rules against the IPA server. " "This will reduce the latency and load on the IPA server if there are many " @@ -10327,12 +10627,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:654 -msgid "ipa_hbac_selinux (integer)" +#: sssd-ipa.5.xml:649 +msgid "ipa_selinux_refresh (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:657 +#: sssd-ipa.5.xml:652 msgid "" "The amount of time between lookups of the SELinux maps against the IPA " "server. This will reduce the latency and load on the IPA server if there are " @@ -10340,33 +10640,33 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:670 +#: sssd-ipa.5.xml:665 msgid "ipa_server_mode (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:673 +#: sssd-ipa.5.xml:668 msgid "" "This option will be set by the IPA installer (ipa-server-install) " "automatically and denotes if SSSD is running on an IPA server or not." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:678 +#: sssd-ipa.5.xml:673 msgid "" "On an IPA server SSSD will lookup users and groups from trusted domains " "directly while on a client it will ask an IPA server." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:683 +#: sssd-ipa.5.xml:678 msgid "" "NOTE: There are currently some assumptions that must be met when SSSD is " "running on an IPA server." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:688 +#: sssd-ipa.5.xml:683 msgid "" "The <quote>ipa_server</quote> option must be configured to point to the IPA " "server itself. This is already the default set by the IPA installer, so no " @@ -10374,59 +10674,59 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:697 +#: sssd-ipa.5.xml:692 msgid "" "The <quote>full_name_format</quote> option must not be tweaked to only print " "short names for users from trusted domains." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:712 +#: sssd-ipa.5.xml:707 msgid "ipa_automount_location (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:715 +#: sssd-ipa.5.xml:710 msgid "The automounter location this IPA client will be using" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:718 +#: sssd-ipa.5.xml:713 msgid "Default: The location named \"default\"" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd-ipa.5.xml:726 +#: sssd-ipa.5.xml:721 msgid "VIEWS AND OVERRIDES" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:735 +#: sssd-ipa.5.xml:730 msgid "ipa_view_class (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:738 +#: sssd-ipa.5.xml:733 msgid "Objectclass of the view container." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:741 +#: sssd-ipa.5.xml:736 msgid "Default: nsContainer" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:747 +#: sssd-ipa.5.xml:742 msgid "ipa_view_name (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:750 +#: sssd-ipa.5.xml:745 msgid "Name of the attribute holding the name of the view." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:754 sssd-ldap-attributes.5.xml:496 +#: sssd-ipa.5.xml:749 sssd-ldap-attributes.5.xml:496 #: sssd-ldap-attributes.5.xml:832 sssd-ldap-attributes.5.xml:913 #: sssd-ldap-attributes.5.xml:1010 sssd-ldap-attributes.5.xml:1068 #: sssd-ldap-attributes.5.xml:1226 sssd-ldap-attributes.5.xml:1271 @@ -10434,128 +10734,128 @@ msgid "Default: cn" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:760 +#: sssd-ipa.5.xml:755 msgid "ipa_override_object_class (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:763 +#: sssd-ipa.5.xml:758 msgid "Objectclass of the override objects." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:766 +#: sssd-ipa.5.xml:761 msgid "Default: ipaOverrideAnchor" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:772 +#: sssd-ipa.5.xml:767 msgid "ipa_anchor_uuid (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:775 +#: sssd-ipa.5.xml:770 msgid "" "Name of the attribute containing the reference to the original object in a " "remote domain." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:779 +#: sssd-ipa.5.xml:774 msgid "Default: ipaAnchorUUID" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:785 +#: sssd-ipa.5.xml:780 msgid "ipa_user_override_object_class (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:788 +#: sssd-ipa.5.xml:783 msgid "" "Name of the objectclass for user overrides. It is used to determine if the " "found override object is related to a user or a group." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:793 +#: sssd-ipa.5.xml:788 msgid "User overrides can contain attributes given by" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:796 +#: sssd-ipa.5.xml:791 msgid "ldap_user_name" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:799 +#: sssd-ipa.5.xml:794 msgid "ldap_user_uid_number" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:802 +#: sssd-ipa.5.xml:797 msgid "ldap_user_gid_number" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:805 +#: sssd-ipa.5.xml:800 msgid "ldap_user_gecos" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:808 +#: sssd-ipa.5.xml:803 msgid "ldap_user_home_directory" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:811 +#: sssd-ipa.5.xml:806 msgid "ldap_user_shell" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:814 +#: sssd-ipa.5.xml:809 msgid "ldap_user_ssh_public_key" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:819 +#: sssd-ipa.5.xml:814 msgid "Default: ipaUserOverride" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> -#: sssd-ipa.5.xml:825 +#: sssd-ipa.5.xml:820 msgid "ipa_group_override_object_class (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:828 +#: sssd-ipa.5.xml:823 msgid "" "Name of the objectclass for group overrides. It is used to determine if the " "found override object is related to a user or a group." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:833 +#: sssd-ipa.5.xml:828 msgid "Group overrides can contain attributes given by" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:836 +#: sssd-ipa.5.xml:831 msgid "ldap_group_name" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:839 +#: sssd-ipa.5.xml:834 msgid "ldap_group_gid_number" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> -#: sssd-ipa.5.xml:844 +#: sssd-ipa.5.xml:839 msgid "Default: ipaGroupOverride" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:728 +#: sssd-ipa.5.xml:723 msgid "" "SSSD can handle views and overrides which are offered by FreeIPA 4.1 and " "later version. Since all paths and objectclasses are fixed on the server " @@ -10565,19 +10865,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd-ipa.5.xml:856 +#: sssd-ipa.5.xml:851 msgid "SUBDOMAINS PROVIDER" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:858 +#: sssd-ipa.5.xml:853 msgid "" "The IPA subdomains provider behaves slightly differently if it is configured " "explicitly or implicitly." msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:862 +#: sssd-ipa.5.xml:857 msgid "" "If the option 'subdomains_provider = ipa' is found in the domain section of " "sssd.conf, the IPA subdomains provider is configured explicitly, and all " @@ -10585,7 +10885,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:868 +#: sssd-ipa.5.xml:863 msgid "" "If the option 'subdomains_provider' is not set in the domain section of " "sssd.conf but there is the option 'id_provider = ipa', the IPA subdomains " @@ -10597,12 +10897,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><title> -#: sssd-ipa.5.xml:879 +#: sssd-ipa.5.xml:874 msgid "TRUSTED DOMAINS CONFIGURATION" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-ipa.5.xml:887 +#: sssd-ipa.5.xml:882 #, no-wrap msgid "" "[domain/ipa.domain.com/ad.domain.com]\n" @@ -10610,7 +10910,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:881 +#: sssd-ipa.5.xml:876 msgid "" "Some configuration options can also be set for a trusted domain. A trusted " "domain configuration can be set using the trusted domain subsection as shown " @@ -10620,97 +10920,97 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:892 +#: sssd-ipa.5.xml:887 msgid "" "For more details, see the <citerefentry> <refentrytitle>sssd.conf</" "refentrytitle> <manvolnum>5</manvolnum> </citerefentry> manual page." msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:899 +#: sssd-ipa.5.xml:894 msgid "" "Different configuration options are tunable for a trusted domain depending " "on whether you are configuring SSSD on an IPA server or an IPA client." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd-ipa.5.xml:904 +#: sssd-ipa.5.xml:899 msgid "OPTIONS TUNABLE ON IPA MASTERS" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:906 +#: sssd-ipa.5.xml:901 msgid "" "The following options can be set in a subdomain section on an IPA master:" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:910 sssd-ipa.5.xml:950 +#: sssd-ipa.5.xml:905 sssd-ipa.5.xml:945 msgid "ad_server" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:913 +#: sssd-ipa.5.xml:908 msgid "ad_backup_server" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:916 sssd-ipa.5.xml:953 +#: sssd-ipa.5.xml:911 sssd-ipa.5.xml:948 msgid "ad_site" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:919 +#: sssd-ipa.5.xml:914 msgid "ipa_server" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:922 +#: sssd-ipa.5.xml:917 msgid "ipa_backup_server" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:925 +#: sssd-ipa.5.xml:920 msgid "ldap_search_base" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:928 +#: sssd-ipa.5.xml:923 msgid "ldap_user_search_base" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> -#: sssd-ipa.5.xml:931 +#: sssd-ipa.5.xml:926 msgid "ldap_group_search_base" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:939 +#: sssd-ipa.5.xml:934 msgid "" "Options prefixed with 'ad_' or 'ipa_' only apply to their respective " "subdomain type." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> -#: sssd-ipa.5.xml:944 +#: sssd-ipa.5.xml:939 msgid "OPTIONS TUNABLE ON IPA CLIENTS" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:946 +#: sssd-ipa.5.xml:941 msgid "" "The following options can be set in an AD subdomain section on an IPA client:" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:958 +#: sssd-ipa.5.xml:953 msgid "" "Note that if both options are set, only <quote>ad_server</quote> is " "evaluated." msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para> -#: sssd-ipa.5.xml:962 +#: sssd-ipa.5.xml:957 msgid "" "Since any request for a user or a group identity from a trusted domain " "triggered from an IPA client is resolved by the IPA server, the " @@ -10724,7 +11024,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ipa.5.xml:986 +#: sssd-ipa.5.xml:981 msgid "" "The following example assumes that SSSD is correctly configured and " "example.com is one of the domains in the <replaceable>[sssd]</replaceable> " @@ -10732,7 +11032,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-ipa.5.xml:993 +#: sssd-ipa.5.xml:988 #, no-wrap msgid "" "[domain/example.com]\n" @@ -11431,27 +11731,27 @@ msgid "lxdm" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:694 +#: sssd-ad.5.xml:699 msgid "sddm" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:699 +#: sssd-ad.5.xml:704 msgid "unity" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:704 +#: sssd-ad.5.xml:709 msgid "xdm" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:713 +#: sssd-ad.5.xml:718 msgid "ad_gpo_map_remote_interactive (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:716 +#: sssd-ad.5.xml:721 msgid "" "A comma-separated list of PAM service names for which GPO-based access " "control is evaluated based on the RemoteInteractiveLogonRight and " @@ -11467,7 +11767,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:735 +#: sssd-ad.5.xml:740 msgid "" "Note: Using the Group Policy Management Editor this value is called \"Allow " "log on through Remote Desktop Services\" and \"Deny log on through Remote " @@ -11475,7 +11775,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:750 +#: sssd-ad.5.xml:755 #, no-wrap msgid "" "ad_gpo_map_remote_interactive = +my_pam_service, -sshd\n" @@ -11483,7 +11783,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:741 +#: sssd-ad.5.xml:746 msgid "" "It is possible to add another PAM service name to the default set by using " "<quote>+service_name</quote> or to explicitly remove a PAM service name from " @@ -11495,22 +11795,22 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:758 +#: sssd-ad.5.xml:763 msgid "sshd" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:763 +#: sssd-ad.5.xml:768 msgid "cockpit" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:772 +#: sssd-ad.5.xml:777 msgid "ad_gpo_map_network (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:775 +#: sssd-ad.5.xml:780 msgid "" "A comma-separated list of PAM service names for which GPO-based access " "control is evaluated based on the NetworkLogonRight and " @@ -11526,7 +11826,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:793 +#: sssd-ad.5.xml:798 msgid "" "Note: Using the Group Policy Management Editor this value is called \"Access " "this computer from the network\" and \"Deny access to this computer from the " @@ -11534,7 +11834,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:808 +#: sssd-ad.5.xml:813 #, no-wrap msgid "" "ad_gpo_map_network = +my_pam_service, -ftp\n" @@ -11542,7 +11842,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:799 +#: sssd-ad.5.xml:804 msgid "" "It is possible to add another PAM service name to the default set by using " "<quote>+service_name</quote> or to explicitly remove a PAM service name from " @@ -11554,22 +11854,22 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:816 +#: sssd-ad.5.xml:821 msgid "ftp" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:821 +#: sssd-ad.5.xml:826 msgid "samba" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:830 +#: sssd-ad.5.xml:835 msgid "ad_gpo_map_batch (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:833 +#: sssd-ad.5.xml:838 msgid "" "A comma-separated list of PAM service names for which GPO-based access " "control is evaluated based on the BatchLogonRight and DenyBatchLogonRight " @@ -11584,14 +11884,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:851 +#: sssd-ad.5.xml:856 msgid "" "Note: Using the Group Policy Management Editor this value is called \"Allow " "log on as a batch job\" and \"Deny log on as a batch job\"." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:865 +#: sssd-ad.5.xml:870 #, no-wrap msgid "" "ad_gpo_map_batch = +my_pam_service, -crond\n" @@ -11599,7 +11899,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:856 +#: sssd-ad.5.xml:861 msgid "" "It is possible to add another PAM service name to the default set by using " "<quote>+service_name</quote> or to explicitly remove a PAM service name from " @@ -11611,23 +11911,23 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:868 +#: sssd-ad.5.xml:873 msgid "" "Note: Cron service name may differ depending on Linux distribution used." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:874 +#: sssd-ad.5.xml:879 msgid "crond" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:883 +#: sssd-ad.5.xml:888 msgid "ad_gpo_map_service (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:886 +#: sssd-ad.5.xml:891 msgid "" "A comma-separated list of PAM service names for which GPO-based access " "control is evaluated based on the ServiceLogonRight and " @@ -11643,14 +11943,14 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:904 +#: sssd-ad.5.xml:909 msgid "" "Note: Using the Group Policy Management Editor this value is called \"Allow " "log on as a service\" and \"Deny log on as a service\"." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:917 +#: sssd-ad.5.xml:922 #, no-wrap msgid "" "ad_gpo_map_service = +my_pam_service\n" @@ -11658,7 +11958,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:909 sssd-ad.5.xml:984 +#: sssd-ad.5.xml:914 sssd-ad.5.xml:989 msgid "" "It is possible to add a PAM service name to the default set by using " "<quote>+service_name</quote>. Since the default set is empty, it is not " @@ -11669,19 +11969,19 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:927 +#: sssd-ad.5.xml:932 msgid "ad_gpo_map_permit (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:930 +#: sssd-ad.5.xml:935 msgid "" "A comma-separated list of PAM service names for which GPO-based access is " "always granted, regardless of any GPO Logon Rights." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:944 +#: sssd-ad.5.xml:949 #, no-wrap msgid "" "ad_gpo_map_permit = +my_pam_service, -sudo\n" @@ -11689,7 +11989,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:935 +#: sssd-ad.5.xml:940 msgid "" "It is possible to add another PAM service name to the default set by using " "<quote>+service_name</quote> or to explicitly remove a PAM service name from " @@ -11701,29 +12001,29 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:952 +#: sssd-ad.5.xml:957 msgid "polkit-1" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:967 +#: sssd-ad.5.xml:972 msgid "systemd-user" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:976 +#: sssd-ad.5.xml:981 msgid "ad_gpo_map_deny (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:979 +#: sssd-ad.5.xml:984 msgid "" "A comma-separated list of PAM service names for which GPO-based access is " "always denied, regardless of any GPO Logon Rights." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> -#: sssd-ad.5.xml:992 +#: sssd-ad.5.xml:997 #, no-wrap msgid "" "ad_gpo_map_deny = +my_pam_service\n" @@ -11731,12 +12031,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:1002 +#: sssd-ad.5.xml:1007 msgid "ad_gpo_default_right (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1005 +#: sssd-ad.5.xml:1010 msgid "" "This option defines how access control is evaluated for PAM service names " "that are not explicitly listed in one of the ad_gpo_map_* options. This " @@ -11749,52 +12049,52 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1018 +#: sssd-ad.5.xml:1023 msgid "Supported values for this option include:" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1027 +#: sssd-ad.5.xml:1032 msgid "remote_interactive" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1032 +#: sssd-ad.5.xml:1037 msgid "network" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1037 +#: sssd-ad.5.xml:1042 msgid "batch" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1042 +#: sssd-ad.5.xml:1047 msgid "service" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1047 +#: sssd-ad.5.xml:1052 msgid "permit" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> -#: sssd-ad.5.xml:1052 +#: sssd-ad.5.xml:1057 msgid "deny" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1058 +#: sssd-ad.5.xml:1063 msgid "Default: deny" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:1064 +#: sssd-ad.5.xml:1069 msgid "ad_maximum_machine_account_password_age (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1067 +#: sssd-ad.5.xml:1072 msgid "" "SSSD will check once a day if the machine account password is older than the " "given age in days and try to renew it. A value of 0 will disable the renewal " @@ -11802,17 +12102,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1073 +#: sssd-ad.5.xml:1078 msgid "Default: 30 days" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:1079 +#: sssd-ad.5.xml:1084 msgid "ad_machine_account_password_renewal_opts (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1082 +#: sssd-ad.5.xml:1087 msgid "" "This option should only be used to test the machine account renewal task. " "The option expects 3 integers and a string separated by a colon (':'). The " @@ -11825,20 +12125,20 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1096 +#: sssd-ad.5.xml:1101 msgid "" "The optional fourth string value identifies the helper binary which should " "be used for the renewal. Currently <command>adcli</command> and " "<command>realm</command> are supported. If this value is missing or empty in " "the value string <command>realm</command> will be used. Since the helper is " "started as the user SSSD is running as there might be the chance that the " -"renewal will fail if this user does not has permissions to modify the keytab " -"file where the machine account credentials are stored. This will typically " -"be the case for <command>adcli</command>." +"renewal will fail if this user does not have permissions to modify the " +"keytab file where the machine account credentials are stored. This will " +"typically be the case for <command>adcli</command>." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1110 +#: sssd-ad.5.xml:1115 msgid "" "<command>realm</command> is not updating the keytab directly but is calling " "the <command>realmd</command> process, which runs as root user, for this " @@ -11848,17 +12148,17 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1119 +#: sssd-ad.5.xml:1124 msgid "Default: 86400:750:300:realm (24h, 12m30s and 5m)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:1125 +#: sssd-ad.5.xml:1130 msgid "ad_update_samba_machine_account_password (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1128 +#: sssd-ad.5.xml:1133 msgid "" "If enabled, when SSSD renews the machine account password, it will also be " "updated in Samba's database. This prevents Samba's copy of the machine " @@ -11867,23 +12167,23 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-ad.5.xml:1141 -msgid "ad_use_ldaps (bool)" +#: sssd-ad.5.xml:1146 +msgid "ad_use_ldaps (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1144 +#: sssd-ad.5.xml:1149 msgid "" "By default SSSD uses the plain LDAP port 389 and the Global Catalog port " -"3628. If this option is set to True SSSD will use the LDAPS port 636 and " -"Global Catalog port 3629 with LDAPS protection. Since AD does not allow to " +"3268. If this option is set to True SSSD will use the LDAPS port 636 and " +"Global Catalog port 3269 with LDAPS protection. Since AD does not allow to " "have multiple encryption layers on a single connection and we still want to " "use SASL/GSSAPI or SASL/GSS-SPNEGO for authentication the SASL security " "property maxssf is set to 0 (zero) for those connections." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1164 +#: sssd-ad.5.xml:1169 msgid "" "Optional. This option tells SSSD to automatically update the Active " "Directory DNS server with the IP address of this client. The update is " @@ -11901,30 +12201,21 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:1216 msgid "" -"NOTE: While it is still possible to use the old <emphasis>ipa_dyndns_iface</" -"emphasis> option, users should migrate to using <emphasis>dyndns_iface</" -"emphasis> in their config file." -msgstr "" - -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1222 -msgid "" "Default: Use the IP addresses of the interface which is used for AD LDAP " "connection" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ad.5.xml:1258 +#: sssd-ad.5.xml:1252 msgid "" "How often should the back end perform periodic DNS update in addition to the " -"automatic update performed when the back end goes online. This option is " -"optional and applicable only when dyndns_update is true. Note that the " -"lowest possible value is 60 seconds in-case if value is provided less than " -"60, parameter will assume lowest value only." +"automatic update performed when the back end goes online. This is optional " +"and applicable only when dyndns_update is true. Note that the minimum value " +"is 60 seconds, any specified value below this threshold will default to 60." msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ad.5.xml:1472 +#: sssd-ad.5.xml:1465 msgid "" "The following example assumes that SSSD is correctly configured and " "example.com is one of the domains in the <replaceable>[sssd]</replaceable> " @@ -11932,7 +12223,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-ad.5.xml:1479 +#: sssd-ad.5.xml:1472 #, no-wrap msgid "" "[domain/EXAMPLE]\n" @@ -11947,7 +12238,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-ad.5.xml:1499 +#: sssd-ad.5.xml:1492 #, no-wrap msgid "" "access_provider = ldap\n" @@ -11956,7 +12247,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ad.5.xml:1495 +#: sssd-ad.5.xml:1488 msgid "" "The AD access control provider checks if the account is expired. It has the " "same effect as the following configuration of the LDAP provider: " @@ -11964,7 +12255,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ad.5.xml:1505 +#: sssd-ad.5.xml:1498 msgid "" "However, unless the <quote>ad</quote> access control provider is explicitly " "configured, the default access provider is <quote>permit</quote>. Please " @@ -11974,7 +12265,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-ad.5.xml:1513 +#: sssd-ad.5.xml:1506 msgid "" "When the autofs provider is set to <quote>ad</quote>, the RFC2307 schema " "attribute mapping (nisMap, nisObject, ...) is used, because these attributes " @@ -12128,9 +12419,9 @@ msgstr "" #: sssd-sudo.5.xml:137 msgid "" "The <emphasis>smart refresh</emphasis> periodically downloads rules that are " -"new or were modified after the last update. Its primary goal is to keep the " -"database growing by fetching only small increments that do not generate " -"large amounts of network traffic." +"new or were modified after the last update. Its primary goal is to grow the " +"database incrementally by fetching only small updates, avoiding large " +"amounts of network traffic." msgstr "" #. type: Content of: <reference><refentry><refsect1><para> @@ -12310,22 +12601,25 @@ msgstr "" msgid "" "Depending on the IdP product additional platform specific options might " "follow the name separated by a colon (:). E.g. for Keycloak the base URI for " -"the user and group REST API must be given. For Entra ID this is not needed " -"because there is a generic endpoint for all tenants." +"the user and group REST API must be given. For Entra ID the base URI for the " +"Microsoft Graph API can be given to use sovereign or government cloud " +"endpoints instead of the default (https://graph.microsoft.com/v1.0). E.g. " +"<quote>entra_id:https://graph.microsoft.us/v1.0</quote> for the US " +"government cloud (GCC High)." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:78 sssd-idp.5.xml:94 sssd-idp.5.xml:119 +#: sssd-idp.5.xml:82 sssd-idp.5.xml:98 sssd-idp.5.xml:123 msgid "Default: Not set (Required)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:83 +#: sssd-idp.5.xml:87 msgid "idp_client_id (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:86 +#: sssd-idp.5.xml:90 msgid "" "ID of the IdP client used by SSSD to authenticate users and as a client to " "lookup user and group attributes. This client must offer device " @@ -12334,12 +12628,12 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:99 +#: sssd-idp.5.xml:103 msgid "idp_client_secret (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:102 +#: sssd-idp.5.xml:106 msgid "" "Password of the IdP client. The password is required for the id_provider. If " "only used as auth_provider it depends on the server side configuration if it " @@ -12347,66 +12641,73 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:113 +#: sssd-idp.5.xml:117 msgid "idp_token_endpoint (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:116 +#: sssd-idp.5.xml:120 msgid "IdP endpoint for requesting access tokens." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:124 +#: sssd-idp.5.xml:128 msgid "idp_device_auth_endpoint (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:127 +#: sssd-idp.5.xml:131 msgid "" "IdP endpoint for device authorization according to RFC-8628. This is " "required for user authentication." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:137 +#: sssd-idp.5.xml:141 msgid "idp_userinfo_endpoint (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:140 +#: sssd-idp.5.xml:144 msgid "" "IdP userinfo endpoint to request user attributes after a successful " "authentication of the user. Required for authentication." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:150 +#: sssd-idp.5.xml:154 msgid "idp_id_scope (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:153 +#: sssd-idp.5.xml:157 msgid "" "Scope required for looking up user and group attributes with the REST API. " "The scopes are used by the server to determine which attributes/claims are " "returned to the caller." msgstr "" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:163 +msgid "" +"Note: In previous versions of SSSD, this option was expected to already be " +"URL-encoded." +msgstr "" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:164 +#: sssd-idp.5.xml:172 msgid "idp_auth_scope (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:167 +#: sssd-idp.5.xml:175 msgid "" "Scope required during authentication. The scopes are used by the server to " "determine which attributes/claims are returned to the caller." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:172 +#: sssd-idp.5.xml:180 msgid "" "Currently the tokens returned during user authentication are not used for " "other purposes hence the only important claim is the subject identifier " @@ -12415,22 +12716,116 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:185 +#: sssd-idp.5.xml:193 +msgid "idp_auth_user_identifier_attr (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:196 +msgid "" +"Attribute used to identify the authenticated user in userinfo data or token " +"claims." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:200 +msgid "" +"For hybrid Active Directory and Entra ID deployments where " +"<quote>id_provider = ad</quote> and <quote>auth_provider = idp</quote>, this " +"option must be set explicitly. No value is derived from the identity " +"provider, because more than one attribute can link an Entra ID object to its " +"on-premises counterpart and only the administrator knows which one the " +"directory synchronization is configured to use." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:211 +msgid "" +"Setting this option to <quote>onPremisesImmutableId</quote> is the usual " +"choice for such deployments. Microsoft Entra Connect populates that " +"attribute with the base64-encoded form of the 16-byte Active Directory " +"<quote>objectGUID</quote> when objectGUID is used as the sourceAnchor. SSSD " +"decodes the value and converts the raw bytes with the same conversion used " +"for AD objectGUID attributes, so the result matches the UUID stored in the " +"SSSD cache for the AD user." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:224 +msgid "" +"Note that Microsoft Entra Connect 1.1.524.0 and later use <quote>ms-DS-" +"ConsistencyGuid</quote> as the sourceAnchor for user objects instead of " +"<quote>objectGUID</quote>. The value is normally copied from objectGUID for " +"objects that do not have it set yet, in which case the decoded identifier " +"still matches. It does not match if ms-DS-ConsistencyGuid was populated " +"independently, if users were moved between forests or domains, or if a " +"different attribute such as employeeID was selected as the sourceAnchor. See " +"<ulink url=\"https://learn.microsoft.com/en-us/entra/identity/hybrid/connect/" +"plan-connect-design-concepts\"> Microsoft Entra Connect: Design concepts</" +"ulink> for details on sourceAnchor selection." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:241 +msgid "" +"Microsoft Graph does not return <quote>onPremisesImmutableId</quote> by " +"default. The <quote>idp_userinfo_endpoint</quote> must request it with " +"<quote>$select</quote>, see the example below and <ulink url=\"https://" +"learn.microsoft.com/en-us/graph/api/resources/user\"> the Microsoft Graph " +"user resource type</ulink>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:251 +msgid "" +"If the configured attribute is missing or cannot be decoded (for example " +"cloud-only Entra ID users without <quote>onPremisesImmutableId</quote>), " +"authentication fails. SSSD does not fall back to another attribute when this " +"option is set." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:258 +msgid "" +"Default: not set, <quote>sub</quote> for Keycloak and <quote>id</quote> for " +"other IdP types" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-idp.5.xml:264 msgid "idp_request_timeout (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:188 +#: sssd-idp.5.xml:267 msgid "Timeout in seconds for an individual request to the IdP." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:197 +#: sssd-idp.5.xml:276 +msgid "idp_auto_refresh (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:279 +msgid "" +"Refresh tokens automatically, after they have reached about half their " +"lifetime." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:283 +msgid "" +"Note: Scheduled token refreshes are not preserved across restarts of SSSD." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-idp.5.xml:292 msgid "idmap_range_min (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:200 +#: sssd-idp.5.xml:295 msgid "" "Specifies the lower (inclusive) bound of the range of POSIX IDs to use for " "mapping IdP users and group to POSIX IDs. It is the first POSIX ID which can " @@ -12438,7 +12833,7 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:206 +#: sssd-idp.5.xml:301 msgid "" "The interval between <quote>idmap_range_min</quote> and " "<quote>idmap_range_max</quote> will be split into smaller ranges of size " @@ -12447,18 +12842,18 @@ msgid "" msgstr "" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:213 sssd-idp.5.xml:239 include/ldap_id_mapping.xml:139 +#: sssd-idp.5.xml:308 sssd-idp.5.xml:334 include/ldap_id_mapping.xml:139 #: include/ldap_id_mapping.xml:197 msgid "Default: 200000" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:218 +#: sssd-idp.5.xml:313 msgid "idmap_range_max (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:221 +#: sssd-idp.5.xml:316 msgid "" "Specifies the upper (exclusive) bound of the range of POSIX IDs to use for " "mapping IdP users and groups to POSIX IDs. It is the first POSIX ID which " @@ -12466,45 +12861,68 @@ msgid "" msgstr "" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:227 include/ldap_id_mapping.xml:165 +#: sssd-idp.5.xml:322 include/ldap_id_mapping.xml:165 msgid "Default: 2000200000" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> -#: sssd-idp.5.xml:232 +#: sssd-idp.5.xml:327 msgid "idmap_range_size (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-idp.5.xml:235 +#: sssd-idp.5.xml:330 msgid "Specifies the number of POSIX IDs available for a single IdP domain." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-idp.5.xml:251 +#: sssd-idp.5.xml:346 #, no-wrap msgid "" "[domain/entra_id]\n" "id_provider = idp\n" "idp_type = entra_id\n" "idp_client_id = 12345678-abcd-0101-efef-ba9876543210\n" -"idp_client_secret = YOUR-CLIENT-SCERET\n" -"idp_token_endpoint = https://login.microsoftonline.com/TENNANT-ID/oauth2/v2.0/token\n" +"idp_client_secret = YOUR-CLIENT-SECRET\n" +"idp_token_endpoint = https://login.microsoftonline.com/TENANT-ID/oauth2/v2.0/token\n" "idp_userinfo_endpoint = https://graph.microsoft.com/v1.0/me\n" -"idp_device_auth_endpoint = https://login.microsoftonline.com/TENNANT-ID/oauth2/v2.0/devicecode\n" -"idp_id_scope = https%3A%2F%2Fgraph.microsoft.com%2F.default\n" +"idp_device_auth_endpoint = https://login.microsoftonline.com/TENANT-ID/oauth2/v2.0/devicecode\n" +"idp_id_scope = https://graph.microsoft.com/.default\n" +"idp_auth_scope = openid profile email\n" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><programlisting> +#: sssd-idp.5.xml:358 +#, no-wrap +msgid "" +"[domain/ad.example.com]\n" +"id_provider = ad\n" +"auth_provider = idp\n" +"access_provider = permit\n" +"\n" +"ad_domain = ad.example.com\n" +"krb5_realm = AD.EXAMPLE.COM\n" +"\n" +"idp_type = entra_id\n" +"idp_client_id = 12345678-abcd-0101-efef-ba9876543210\n" +"idp_client_secret = YOUR-CLIENT-SECRET\n" +"idp_token_endpoint = https://login.microsoftonline.com/TENANT-ID/oauth2/v2.0/token\n" +"idp_userinfo_endpoint = https://graph.microsoft.com/v1.0/me?$select=id,userPrincipalName,onPremisesImmutableId\n" +"idp_device_auth_endpoint = https://login.microsoftonline.com/TENANT-ID/oauth2/v2.0/devicecode\n" +"idp_id_scope = https://graph.microsoft.com/.default\n" "idp_auth_scope = openid profile email\n" +"idp_auth_user_identifier_attr = onPremisesImmutableId\n" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><programlisting> -#: sssd-idp.5.xml:263 +#: sssd-idp.5.xml:377 #, no-wrap msgid "" "[domain/keycloak]\n" "idp_type = keycloak:https://master.keycloak.test:8443/auth/admin/realms/master/\n" "id_provider = idp\n" "idp_client_id = myclient\n" -"idp_client_secret = YOUR-CLIENT-SCERET\n" +"idp_client_secret = YOUR-CLIENT-SECRET\n" "idp_token_endpoint = https://master.keycloak.test:8443/auth/realms/master/protocol/openid-connect/token\n" "idp_userinfo_endpoint = https://master.keycloak.test:8443/auth/realms/master/protocol/openid-connect/userinfo\n" "idp_device_auth_endpoint = https://master.keycloak.test:8443/auth/realms/master/protocol/openid-connect/auth/device\n" @@ -12513,10 +12931,22 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-idp.5.xml:250 +#: sssd-idp.5.xml:345 msgid "" "<placeholder type=\"programlisting\" id=\"0\"/> <placeholder " -"type=\"programlisting\" id=\"1\"/>" +"type=\"programlisting\" id=\"1\"/> <placeholder type=\"programlisting\" " +"id=\"2\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-idp.5.xml:390 +msgid "" +"In the hybrid Active Directory and Entra ID example above, " +"<quote>onPremisesImmutableId</quote> is used during authentication so the " +"IdP result matches the AD objectGUID UUID stored in the SSSD cache. The " +"attribute must be requested via <quote>$select</quote> on the Graph userinfo " +"endpoint and is only populated for users synchronized from Active Directory " +"with objectGUID as the sourceAnchor." msgstr "" #. type: Content of: <reference><refentry><refnamediv><refname> @@ -13482,7 +13912,7 @@ msgstr "" #: sssd-krb5.5.xml:291 msgid "" "<emphasis>demand</emphasis> to use FAST. The authentication fails if the " -"server does not require fast." +"server does not support FAST." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> @@ -14371,7 +14801,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sss_rpcidmapd.5.xml:69 -msgid "memcache (bool)" +msgid "memcache (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> @@ -14425,7 +14855,7 @@ msgid "" msgstr "" #. type: Content of: <refsect1><title> -#: sss_rpcidmapd.5.xml:120 sssd-kcm.8.xml:316 include/seealso.xml:2 +#: sss_rpcidmapd.5.xml:120 sssd-kcm.8.xml:315 include/seealso.xml:2 msgid "SEE ALSO" msgstr "另见" @@ -14652,8 +15082,8 @@ msgstr "" #: sss_ssh_knownhosts.1.xml:93 msgid "" "The key lines retrieved from the backend are expected to respect the key " -"format as decribed in the <quote>SSH_KNOWN_HOSTS FILE FORMAT</quote> section " -"of <citerefentry><refentrytitle>sshd</refentrytitle> <manvolnum>8</" +"format as described in the <quote>SSH_KNOWN_HOSTS FILE FORMAT</quote> " +"section of <citerefentry><refentrytitle>sshd</refentrytitle> <manvolnum>8</" "manvolnum></citerefentry>. However, returning only the keytype and the key " "itself is tolerated, in which case, the hostname received as parameter will " "be added before the keytype to output a correctly formatted line. The " @@ -15129,14 +15559,13 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-kcm.8.xml:215 msgid "" -"The KCM service is configured in the <quote>kcm</quote> For a detailed " -"syntax reference, refer to the <quote>FILE FORMAT</quote> section of the " -"<citerefentry> <refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</" -"manvolnum> </citerefentry> manual page." +"For a detailed syntax reference, refer to the <quote>FILE FORMAT</quote> " +"section of the <citerefentry> <refentrytitle>sssd.conf</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry> manual page." msgstr "" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-kcm.8.xml:223 +#: sssd-kcm.8.xml:222 msgid "" "The generic SSSD service options such as <quote>debug_level</quote> or " "<quote>fd_limit</quote> are accepted by the kcm service. Please refer to " @@ -15146,22 +15575,22 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:234 +#: sssd-kcm.8.xml:233 msgid "socket_path (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:237 +#: sssd-kcm.8.xml:236 msgid "The socket the KCM service will listen on." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:240 +#: sssd-kcm.8.xml:239 msgid "Default: <replaceable>/var/run/.heim_org.h5l.kcm-socket</replaceable>" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:243 +#: sssd-kcm.8.xml:242 msgid "" "<phrase condition=\"have_systemd\"> Note: on platforms where systemd is " "supported, the socket path is overwritten by the one defined in the sssd-" @@ -15169,88 +15598,88 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:252 +#: sssd-kcm.8.xml:251 msgid "max_ccaches (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:255 +#: sssd-kcm.8.xml:254 msgid "How many credential caches does the KCM database allow for all users." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:259 +#: sssd-kcm.8.xml:258 msgid "Default: 0 (unlimited, only the per-UID quota is enforced)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:264 +#: sssd-kcm.8.xml:263 msgid "max_uid_ccaches (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:267 +#: sssd-kcm.8.xml:266 msgid "" "How many credential caches does the KCM database allow per UID. This is " "equivalent to <quote>with how many principals you can kinit</quote>." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:272 +#: sssd-kcm.8.xml:271 msgid "Default: 64" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:277 +#: sssd-kcm.8.xml:276 msgid "max_ccache_size (integer)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:280 +#: sssd-kcm.8.xml:279 msgid "" -"How big can a credential cache be per ccache. Each service ticket accounts " -"into this quota." +"How big a credential cache be per ccache. Each service ticket counts toward " +"this quota." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:284 +#: sssd-kcm.8.xml:283 msgid "Default: 65536" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:289 -msgid "tgt_renewal (bool)" +#: sssd-kcm.8.xml:288 +msgid "tgt_renewal (boolean)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:292 +#: sssd-kcm.8.xml:291 msgid "Enables TGT renewals functionality." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:295 +#: sssd-kcm.8.xml:294 msgid "Default: False (Automatic renewals disabled)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> -#: sssd-kcm.8.xml:300 +#: sssd-kcm.8.xml:299 msgid "tgt_renewal_inherit (string)" msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:303 +#: sssd-kcm.8.xml:302 msgid "Domain to inherit krb5_* options from, for use with TGT renewals." msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> -#: sssd-kcm.8.xml:307 +#: sssd-kcm.8.xml:306 #, fuzzy #| msgid "Default: 3" msgid "Default: NULL" msgstr "默认: 3" #. type: Content of: <reference><refentry><refsect1><para> -#: sssd-kcm.8.xml:318 +#: sssd-kcm.8.xml:317 msgid "" "<citerefentry> <refentrytitle>sssd</refentrytitle><manvolnum>8</manvolnum> </" "citerefentry>, <citerefentry> <refentrytitle>sssd.conf</" @@ -16154,8 +16583,8 @@ msgid "" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap-attributes.5.xml:381 sssd-ldap-attributes.5.xml:395 -msgid "Default: loginDisabled" +#: sssd-ldap-attributes.5.xml:381 +msgid "Default: loginDisabled (rfc2307, rfc2307bis and IPA), not set (AD)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> @@ -16170,6 +16599,12 @@ msgid "" "which date access is granted." msgstr "" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:395 +msgid "" +"Default: loginExpirationTime (rfc2307, rfc2307bis and IPA), not set (AD)" +msgstr "" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:401 msgid "ldap_user_nds_login_allowed_time_map (string)" @@ -16184,7 +16619,8 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:409 -msgid "Default: loginAllowedTimeMap" +msgid "" +"Default: loginAllowedTimeMap (rfc2307, rfc2307bis and IPA), not set (AD)" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> @@ -16698,8 +17134,8 @@ msgid "The object class of a host entry in LDAP." msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap-attributes.5.xml:900 sssd-ldap-attributes.5.xml:997 -msgid "Default: ipService" +#: sssd-ldap-attributes.5.xml:900 sssd-ldap-attributes.5.xml:1213 +msgid "Default: ipHost" msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> @@ -16784,6 +17220,11 @@ msgstr "" msgid "The object class of a service entry in LDAP." msgstr "" +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:997 +msgid "Default: ipService" +msgstr "" + #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1003 msgid "ldap_service_name (string)" @@ -17024,11 +17465,6 @@ msgstr "" msgid "The object class of an iphost entry in LDAP." msgstr "" -#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> -#: sssd-ldap-attributes.5.xml:1213 -msgid "Default: ipHost" -msgstr "" - #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1219 msgid "ldap_iphost_name (string)" @@ -17252,6 +17688,7 @@ msgstr "" msgid "" "[plugins]\n" " localauth = {\n" +" disable = an2ln\n" " module = sssd:/usr/lib64/sssd/modules/sssd_krb5_localauth_plugin.so\n" " }\n" msgstr "" @@ -17268,6 +17705,28 @@ msgid "" "the local Kerberos configuration the plugin will be enabled automatically." msgstr "" +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_localauth_plugin.8.xml:67 +msgid "" +"This configuration snippet also disables the <command>an2ln</command> module " +"provided by MIT Kerberos if SSSD is configured to use the AD or IPA " +"provider. In those environments <command>sssd_krb5_localauth_plugin</" +"command> can reliably map the system user names to Kerberos principals. A " +"fallback to <command>an2ln</command> might cause issues in environments " +"where users have the privilege to create Kerberos principals on their own " +"which might collide with names of other users used in the system. Other " +"modules provided by MIT Kerberos, e.g. <command>k5login</command> are not " +"affected." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_localauth_plugin.8.xml:79 +msgid "" +"Note: If using <quote>auth_provider = krb5</quote> then " +"<command>sssd_krb5_localauth_plugin</command> is not used, therefore the " +"above text is not applicable." +msgstr "" + #. type: Content of: <variablelist><varlistentry><term> #: include/autofs_attributes.xml:3 msgid "ldap_autofs_map_object_class (string)" @@ -18124,30 +18583,6 @@ msgid "" "failures; corresponds to setting 2 in decimal notation)" msgstr "" -#. type: Content of: <refsect1><title> -#: include/local.xml:2 -msgid "THE LOCAL DOMAIN" -msgstr "" - -#. type: Content of: <refsect1><para> -#: include/local.xml:4 -msgid "" -"In order to function correctly, a domain with <quote>id_provider=local</" -"quote> must be created and the SSSD must be running." -msgstr "" - -#. type: Content of: <refsect1><para> -#: include/local.xml:9 -msgid "" -"The administrator might want to use the SSSD local users instead of " -"traditional UNIX users in cases where the group nesting (see <citerefentry> " -"<refentrytitle>sss_groupadd</refentrytitle> <manvolnum>8</manvolnum> </" -"citerefentry>) is needed. The local users are also useful for testing and " -"development of the SSSD without having to deploy a full remote server. The " -"<command>sss_user*</command> and <command>sss_group*</command> tools use a " -"local LDB storage to store users and groups." -msgstr "" - #. type: Content of: <refsect1><para> #: include/seealso.xml:4 msgid "" diff --git a/src/man/po/zh_TW.po b/src/man/po/zh_TW.po index 7945abf7e50..e8dc70fd8ce 100644 --- a/src/man/po/zh_TW.po +++ b/src/man/po/zh_TW.po @@ -8,7 +8,7 @@ msgstr "" "Project-Id-Version: sssd-docs 2.10.0\n" "Report-Msgid-Bugs-To: sssd-devel@redhat.com\n" "POT-Creation-Date: 2024-10-15 11:44+0200\n" -"PO-Revision-Date: 2026-04-23 16:49+0000\n" +"PO-Revision-Date: 2026-10-05 17:16+0000\n" "Last-Translator: hsu zangmen <chzang55@gmail.com>\n" "Language-Team: Chinese (Traditional) <https://translate.fedoraproject.org/" "projects/sssd/sssd-manpage-master/zh_TW/>\n" @@ -17,7 +17,7 @@ msgstr "" "Content-Type: text/plain; charset=UTF-8\n" "Content-Transfer-Encoding: 8bit\n" "Plural-Forms: nplurals=1; plural=0;\n" -"X-Generator: Weblate 5.17\n" +"X-Generator: Weblate 2026.10\n" #. type: Content of: <reference><title> #: sssd.conf.5.xml:8 sssd-ldap.5.xml:5 pam_sss.8.xml:5 pam_sss_gss.8.xml:5 @@ -31,11 +31,10 @@ msgstr "" #: sssd-kcm.8.xml:5 sssd-systemtap.5.xml:5 sssd-ldap-attributes.5.xml:5 #: sssd_krb5_localauth_plugin.8.xml:5 msgid "SSSD Manual pages" -msgstr "SSSD 手冊主頁" +msgstr "SSSD 手冊頁" #. type: Content of: <reference><refentry><refnamediv><refname> #: sssd.conf.5.xml:13 sssd.conf.5.xml:19 -#, fuzzy msgid "sssd.conf" msgstr "sssd.conf" @@ -45,7 +44,6 @@ msgstr "sssd.conf" #: sssd-krb5.5.xml:11 sssd-ifp.5.xml:11 sss_rpcidmapd.5.xml:27 #: sssd-files.5.xml:11 sssd-session-recording.5.xml:11 sssd-systemtap.5.xml:11 #: sssd-ldap-attributes.5.xml:11 -#, fuzzy msgid "5" msgstr "5" @@ -70,7 +68,7 @@ msgstr "檔案格式" #. type: Content of: <reference><refentry><refsect1><para><programlisting> #: sssd.conf.5.xml:32 -#, fuzzy, no-wrap +#, no-wrap msgid "" "<replaceable>[section]</replaceable>\n" "<replaceable>key</replaceable> = <replaceable>value</replaceable>\n" @@ -90,8 +88,8 @@ msgid "" "until the next section begins. An example of section with single and " "multi-valued parameters: <placeholder type=\"programlisting\" id=\"0\"/>" msgstr "" -"檔案採用 ini-style 語法,由區段和參數組成。一節以方括號中的節名開始,一直到下" -"一節開始為止。包含單值和多值參數的節範例: <placeholder " +"檔案採用 ini-style 語法,由區段和參數組成。一個區段以方括號中的區段名稱開始," +"一直持續到下一區段開始。包含單值和多值參數的節範例: <placeholder " "type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para> @@ -100,7 +98,7 @@ msgid "" "The data types used are string (no quotes needed), integer and bool (with " "values of <quote>TRUE/FALSE</quote>)." msgstr "" -"使用的資料類型為字串 (不需要引號)、整數和布林值 (值為 <quote>TRUE/FALSE</" +"使用的資料類型為字串 (不需要引號)、整數與布林值 (值為 <quote>TRUE/FALSE</" "quote>)。" #. type: Content of: <reference><refentry><refsect1><para> @@ -109,6 +107,8 @@ msgid "" "A comment line starts with a hash sign (<quote>#</quote>) or a semicolon " "(<quote>;</quote>). Inline comments are not supported." msgstr "" +"註解行以井字號 (<quote>#</quote>) 或分號 (<quote>;</quote>) 開頭。不支援行內" +"註解。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:50 @@ -116,6 +116,8 @@ msgid "" "All sections can have an optional <replaceable>description</replaceable> " "parameter. Its function is only as a label for the section." msgstr "" +"所有區段都可以有選擇性的 <replaceable>description</replaceable> 參數,其作用" +"僅為該區段的標籤。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:56 @@ -123,6 +125,8 @@ msgid "" "<filename>sssd.conf</filename> must be a regular file that is owned, " "readable, and writeable only by 'root'." msgstr "" +"<filename>sssd.conf</filename> 必須是一般檔案,且僅由 'root' 擁有、可讀且可寫" +"。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:60 @@ -130,11 +134,13 @@ msgid "" "<filename>sssd.conf</filename> must be a regular file that is owned, " "readable, and writeable by the same user as configured to run SSSD service." msgstr "" +"<filename>sssd.conf</filename> 必須是一般檔案,且由設定為執行 SSSD 服務的同一" +"使用者擁有、可讀且可寫。" #. type: Content of: <reference><refentry><refsect1><title> #: sssd.conf.5.xml:67 msgid "CONFIGURATION SNIPPETS FROM INCLUDE DIRECTORY" -msgstr "" +msgstr "來自 INCLUDE 目錄的設定片段" #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:70 @@ -143,6 +149,8 @@ msgid "" "configuration snippets using the include directory " "<filename>conf.d</filename>." msgstr "" +"設定檔 <filename>sssd.conf</filename> 會透過 include 目錄 <filename>conf.d</" +"filename> 納入設定片段。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:76 @@ -152,6 +160,9 @@ msgid "" "(<quote>.</quote>) will be used together with <filename>sssd.conf</filename> " "to configure SSSD." msgstr "" +"置於 <filename>conf.d</filename> 中、以 <quote><filename>.conf</filename></" +"quote> 結尾且不以點號 (<quote>.</quote>) 開頭的任何檔案,都會與 <filename>" +"sssd.conf</filename> 一起用來設定 SSSD。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:84 @@ -165,38 +176,43 @@ msgid "" "<filename>02_snippet.conf</filename> etc.) can help visualize the priority " "(higher number means higher priority)." msgstr "" +"來自 <filename>conf.d</filename> 的設定片段優先順序高於 <filename>sssd.conf</" +"filename>,發生衝突時會覆寫 <filename>sssd.conf</filename>。若 <filename>" +"conf.d</filename> 中有多個片段,則會依字母順序(依語言環境)納入。越晚納入的" +"檔案優先順序越高。數字前綴(<filename>01_snippet.conf</filename>、<filename>" +"02_snippet.conf</filename> 等)有助於看出優先順序(數字越大優先順序越高)。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:98 msgid "" "The snippet files require the same owner and permissions as " "<filename>sssd.conf</filename>." -msgstr "" +msgstr "片段檔需要與 <filename>sssd.conf</filename> 相同的擁有者與權限。" #. type: Content of: <reference><refentry><refsect1><title> #: sssd.conf.5.xml:104 msgid "GENERAL OPTIONS" -msgstr "" +msgstr "一般選項" #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:106 msgid "Following options are usable in more than one configuration sections." -msgstr "" +msgstr "下列選項可用於多個設定區段。" #. type: Content of: <reference><refentry><refsect1><refsect2><title> #: sssd.conf.5.xml:110 msgid "Options usable in all sections" -msgstr "" +msgstr "可用於所有區段的選項" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:114 msgid "debug_level (integer)" -msgstr "" +msgstr "debug_level (integer)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:118 msgid "debug (integer)" -msgstr "" +msgstr "debug (integer)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:121 @@ -206,18 +222,21 @@ msgid "" "are specified, the value of <replaceable>debug_level</replaceable> will be " "used." msgstr "" +"SSSD 1.14 起也提供 <replaceable>debug</replaceable> 作為 <replaceable>" +"debug_level</replaceable> 的別名,以方便使用。若同時指定兩者,將採用 " +"<replaceable>debug_level</replaceable> 的值。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:131 msgid "debug_timestamps (bool)" -msgstr "" +msgstr "debug_timestamps (bool)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:134 msgid "" "Add a timestamp to the debug messages. If journald is enabled for SSSD " "debug logging this option is ignored." -msgstr "" +msgstr "在除錯訊息中加入時間戳記。若 SSSD 除錯記錄已啟用 journald,此選項會被忽略。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:139 sssd.conf.5.xml:176 sssd.conf.5.xml:338 @@ -228,12 +247,12 @@ msgstr "" #: sssd-ipa.5.xml:347 sssd-ad.5.xml:252 sssd-ad.5.xml:367 sssd-ad.5.xml:1201 #: sssd-ad.5.xml:1354 sssd-krb5.5.xml:358 msgid "Default: true" -msgstr "" +msgstr "預設:true" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:144 msgid "debug_microseconds (bool)" -msgstr "" +msgstr "debug_microseconds (bool)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:147 @@ -241,6 +260,8 @@ msgid "" "Add microseconds to the timestamp in debug messages. If journald is enabled " "for SSSD debug logging this option is ignored." msgstr "" +"在除錯訊息的時間戳記中加入微秒。若 SSSD 除錯記錄已啟用 journald,此選項會被忽" +"略。" #. type: Content of: <variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:152 sssd.conf.5.xml:636 sssd.conf.5.xml:920 @@ -250,17 +271,17 @@ msgstr "" #: sssd-ipa.5.xml:254 sssd-ipa.5.xml:662 sssd-ad.5.xml:1107 sssd-krb5.5.xml:268 #: sssd-krb5.5.xml:330 sssd-krb5.5.xml:432 include/krb5_options.xml:163 msgid "Default: false" -msgstr "" +msgstr "預設:false" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:157 msgid "debug_backtrace_enabled (bool)" -msgstr "" +msgstr "debug_backtrace_enabled (bool)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:160 msgid "Enable debug backtrace." -msgstr "" +msgstr "啟用除錯回溯。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:163 @@ -271,13 +292,17 @@ msgid "" "to 0 or 1 then only those error levels will trigger backtrace, otherwise up " "to 2)." msgstr "" +"若 SSSD 以低於 9 的 debug_level 執行,所有內容都會記錄到記憶體中的環形緩衝區" +",並在任何錯誤發生時(直到且包含 `min(0x0040, debug_level)`)寫入記錄檔(亦即" +",若 debug_level 明確設為 0 或 1,只有那些錯誤層級會觸發回溯,否則最多到 2)" +"。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:172 msgid "" "Feature is only supported for `logger == files` (i.e. setting doesn't have " "effect for other logger types)." -msgstr "" +msgstr "此功能僅支援 `logger == files`(亦即此設定對其他記錄器類型無效)。" #. type: Content of: outside any tag (error?) #: sssd.conf.5.xml:112 sssd.conf.5.xml:187 sssd-ldap.5.xml:1694 @@ -290,17 +315,17 @@ msgstr "" #: sssd-ldap-attributes.5.xml:1250 include/autofs_attributes.xml:1 #: include/krb5_options.xml:1 msgid "<placeholder type=\"variablelist\" id=\"0\"/>" -msgstr "" +msgstr "<placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><title> #: sssd.conf.5.xml:185 msgid "Options usable in SERVICE and DOMAIN sections" -msgstr "" +msgstr "可用於 SERVICE 與 DOMAIN 區段的選項" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:189 msgid "timeout (integer)" -msgstr "" +msgstr "timeout (integer)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:192 @@ -309,32 +334,34 @@ msgid "" "ensure that the process is alive and capable of answering requests. Note " "that after three missed heartbeats the process will terminate itself." msgstr "" +"此服務心跳之間的時間(秒)。此值用來確保程序仍在執行且能回應要求。請注意,連" +"續三次錯過心跳後,程序會自行終止。" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:199 sssd.conf.5.xml:1261 sssd.conf.5.xml:1738 #: sssd.conf.5.xml:4247 sssd-ldap.5.xml:766 include/ldap_id_mapping.xml:270 msgid "Default: 10" -msgstr "" +msgstr "預設:10" #. type: Content of: <reference><refentry><refsect1><title> #: sssd.conf.5.xml:209 msgid "SPECIAL SECTIONS" -msgstr "" +msgstr "特殊區段" #. type: Content of: <reference><refentry><refsect1><refsect2><title> #: sssd.conf.5.xml:212 msgid "The [sssd] section" -msgstr "" +msgstr "[sssd] 區段" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><title> #: sssd.conf.5.xml:221 msgid "Section parameters" -msgstr "" +msgstr "區段參數" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:223 msgid "services" -msgstr "" +msgstr "services" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:226 @@ -344,6 +371,9 @@ msgid "" "platforms where systemd is supported, as they will either be socket or D-Bus " "activated when needed. </phrase>" msgstr "" +"以逗號分隔的服務清單,列出 sssd 本身啟動時會啟動的服務。<phrase " +"condition=\"have_systemd\"> 在支援 systemd 的平台上,服務清單為選擇性,因為需" +"要時它們會以 socket 或 D-Bus 方式啟動。</phrase>" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:235 @@ -353,6 +383,10 @@ msgid "" "condition=\"with_ssh\">, ssh</phrase> <phrase " "condition=\"with_pac_responder\">, pac</phrase>" msgstr "" +"支援的服務:nss、pam、ifp<phrase condition=\"with_sudo\">、sudo</phrase> " +"<phrase condition=\"with_autofs\">、autofs</phrase> <phrase " +"condition=\"with_ssh\">、ssh</phrase> <phrase " +"condition=\"with_pac_responder\">、pac</phrase>" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:242 @@ -361,11 +395,14 @@ msgid "" "and the administrator must enable the ones allowed to be used by executing: " "\"systemctl enable sssd-@service@.socket\". </phrase>" msgstr "" +"<phrase condition=\"have_systemd\"> 依預設所有服務都是停用的,管理員必須執行" +"下列指令來啟用允許使用的服務:\"systemctl enable sssd-@service@.socket\"。</" +"phrase>" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:251 msgid "domains" -msgstr "" +msgstr "domains" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:254 @@ -377,18 +414,21 @@ msgid "" "alphanumeric ASCII characters, dashes, dots and underscores. '/' character " "is forbidden." msgstr "" +"網域是包含使用者資訊的資料庫。SSSD 可以同時使用多個網域,但至少必須設定一個," +"否則 SSSD 不會啟動。此參數以您希望查詢的順序描述網域清單。建議網域名稱只包含 " +"ASCII 字母數字、連字號、句點與底線。禁止使用 '/' 字元。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:267 sssd.conf.5.xml:3535 msgid "re_expression (string)" -msgstr "" +msgstr "re_expression (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:270 msgid "" "Default regular expression that describes how to parse the string containing " "user name and domain into these components." -msgstr "" +msgstr "預設的正規表示式,描述如何將包含使用者名稱與網域的字串剖析為這些組成部分。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:275 @@ -397,11 +437,13 @@ msgid "" "ID providers there are also default regular expressions. See DOMAIN SECTIONS " "for more info on these regular expressions." msgstr "" +"每個網域都可以設定各自的正規表示式。某些 ID 提供者也有預設的正規表示式。有關" +"這些正規表示式的更多資訊,請參閱 DOMAIN SECTIONS。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:284 sssd.conf.5.xml:3592 msgid "full_name_format (string)" -msgstr "" +msgstr "full_name_format (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:287 sssd.conf.5.xml:3595 @@ -411,31 +453,34 @@ msgid "" "how to compose a fully qualified name from user name and domain name " "components." msgstr "" +"一種與 <citerefentry> <refentrytitle>printf</refentrytitle> <manvolnum>3</" +"manvolnum> </citerefentry> 相容的格式,描述如何從使用者名稱與網域名稱組成部分" +"構成完整名稱。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:298 sssd.conf.5.xml:3606 msgid "%1$s" -msgstr "" +msgstr "%1$s" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:299 sssd.conf.5.xml:3607 msgid "user name" -msgstr "" +msgstr "使用者名稱" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:302 sssd.conf.5.xml:3610 msgid "%2$s" -msgstr "" +msgstr "%2$s" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:305 sssd.conf.5.xml:3613 msgid "domain name as specified in the SSSD config file." -msgstr "" +msgstr "SSSD 設定檔中指定的網域名稱。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:311 sssd.conf.5.xml:3619 msgid "%3$s" -msgstr "" +msgstr "%3$s" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:314 sssd.conf.5.xml:3622 @@ -443,13 +488,15 @@ msgid "" "domain flat name. Mostly usable for Active Directory domains, both directly " "configured or discovered via IPA trusts." msgstr "" +"網域簡短名稱。主要用於 Active Directory 網域,無論是直接設定或透過 IPA 信任探" +"索到的。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:295 sssd.conf.5.xml:3603 msgid "" "The following expansions are supported: <placeholder type=\"variablelist\" " "id=\"0\"/>" -msgstr "" +msgstr "支援下列展開:<placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:324 @@ -457,11 +504,13 @@ msgid "" "Each domain can have an individual format string configured. See DOMAIN " "SECTIONS for more info on this option." msgstr "" +"每個網域都可以設定各自的格式字串。有關此選項的更多資訊,請參閱 DOMAIN " +"SECTIONS。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:330 msgid "monitor_resolv_conf (boolean)" -msgstr "" +msgstr "monitor_resolv_conf (boolean)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:333 @@ -469,11 +518,13 @@ msgid "" "Controls if SSSD should monitor the state of resolv.conf to identify when it " "needs to update its internal DNS resolver." msgstr "" +"控制 SSSD 是否應監控 resolv.conf 的狀態,以判斷何時需要更新其內部的 DNS 解析" +"器。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:343 msgid "try_inotify (boolean)" -msgstr "" +msgstr "try_inotify (boolean)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:346 @@ -482,6 +533,8 @@ msgid "" "changes and will fall back to polling every five seconds if inotify cannot " "be used." msgstr "" +"依預設,SSSD 會嘗試使用 inotify 監控設定檔的變更;若無法使用 inotify,則會退" +"回每五秒輪詢一次。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:352 @@ -490,32 +543,34 @@ msgid "" "even trying to use inotify. In these rare cases, this option should be set " "to 'false'" msgstr "" +"有些少數情況最好連嘗試使用 inotify 都省略。在這些罕見情況下,應將此選項設為 " +"'false'" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:358 msgid "" "Default: true on platforms where inotify is supported. False on other " "platforms." -msgstr "" +msgstr "預設:在支援 inotify 的平台上為 true,其他平台為 false。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:362 msgid "" "Note: this option will have no effect on platforms where inotify is " "unavailable. On these platforms, polling will always be used." -msgstr "" +msgstr "注意:在無法使用 inotify 的平台上,此選項沒有效果。這些平台一律會使用輪詢。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:369 msgid "krb5_rcache_dir (string)" -msgstr "" +msgstr "krb5_rcache_dir (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:372 msgid "" "Directory on the filesystem where SSSD should store Kerberos replay cache " "files." -msgstr "" +msgstr "SSSD 應在檔案系統上儲存 Kerberos 重播快取檔案的目錄。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:376 @@ -523,18 +578,20 @@ msgid "" "This option accepts a special value __LIBKRB5_DEFAULTS__ that will instruct " "SSSD to let libkrb5 decide the appropriate location for the replay cache." msgstr "" +"此選項接受特殊值 __LIBKRB5_DEFAULTS__,指示 SSSD 讓 libkrb5 決定重播快取的適" +"當位置。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:382 msgid "" "Default: Distribution-specific and specified at " "build-time. (__LIBKRB5_DEFAULTS__ if not configured)" -msgstr "" +msgstr "預設:依發行版而異,於建置時指定。(若未設定則為 __LIBKRB5_DEFAULTS__)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:389 msgid "user (string)" -msgstr "" +msgstr "user (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:392 @@ -543,13 +600,15 @@ msgid "" "where appropriate to avoid running as the root user. The only supported " "value is '&sssd_user_name;'." msgstr "" +"設定在適當時機放棄權限的使用者之傳統(已棄用)方法,以避免以 root 使用者執行" +"。唯一支援的值是 '&sssd_user_name;'。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:399 msgid "" "This option is ignored if main SSSD process is started under non-root user " "initially (preferred method)." -msgstr "" +msgstr "若主要 SSSD 程序最初以非 root 使用者啟動(建議方式),此選項會被忽略。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:404 @@ -560,16 +619,19 @@ msgid "" "general isn't supported: everything should be configured to run either under " "'&sssd_user_name;' or 'root'." msgstr "" +"此選項不適用於 socket 啟動的服務,因為在這種情況下,執行程序的使用者是在 " +"systemd 服務檔中設定的。請注意,一般來說不支援對不同 SSSD 元件使用不同的服務" +"使用者:所有元件都應設定為在 '&sssd_user_name;' 或 'root' 下執行。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:415 msgid "Default: not set, process will run as root" -msgstr "" +msgstr "預設:未設定,程序會以 root 執行" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:420 msgid "default_domain_suffix (string)" -msgstr "" +msgstr "default_domain_suffix (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:423 @@ -580,6 +642,9 @@ msgid "" "trusted domain. The option allows those users to log in just with their " "user name without giving a domain name as well." msgstr "" +"此字串會用作所有沒有網域名稱組成部分之名稱的預設網域名稱。主要使用案例是主要" +"網域用於管理主機原則、而所有使用者都位於受信任網域的環境。此選項也允許這些使" +"用者只輸入使用者名稱登入,而不需要提供網域名稱。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:433 @@ -594,6 +659,12 @@ msgid "" "of nss_files and therefore their output is not qualified even when the " "default_domain_suffix option is used. </phrase>" msgstr "" +"請注意,若設定此選項,主要網域的所有使用者都必須使用完整名稱(例如 " +"user@domain.name)登入。設定此選項會將 use_fully_qualified_names 的預設值改" +"為 True。不允許將此選項與設為 False 的 use_fully_qualified_names 一起使用" +"。<phrase condition=\"with_files_provider\"> 此規則的唯一例外是使用 <quote>" +"id_provider=files</quote> 的網域,這些網域一律嘗試比照 nss_files 的行為,因此" +"即使使用 default_domain_suffix 選項,其輸出也不會限定。</phrase>" #. type: Content of: <variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:450 sssd-ldap.5.xml:878 sssd-ldap.5.xml:890 @@ -602,12 +673,12 @@ msgstr "" #: include/ldap_id_mapping.xml:211 include/ldap_id_mapping.xml:222 #: include/krb5_options.xml:148 msgid "Default: not set" -msgstr "" +msgstr "預設:未設定" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:455 msgid "override_space (string)" -msgstr "" +msgstr "override_space (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:458 @@ -618,6 +689,9 @@ msgid "" "scripts that have difficulty handling spaces, due to the default field " "separator in the shell." msgstr "" +"此參數會以給定的字元取代使用者與群組名稱中的空格。例如 (_)。使用者名稱 " +""john doe" 會變成 "john_doe"。新增此功能是為了與難以處理" +"空格的 shell 指令碼相容,因為 shell 的預設欄位分隔符為空格。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:467 @@ -627,21 +701,23 @@ msgid "" "character SSSD tries to return the unmodified name but in general the result " "of a lookup is undefined." msgstr "" +"請注意,使用可能出現在使用者或群組名稱中的取代字元屬於設定錯誤。若名稱包含取" +"代字元,SSSD 會嘗試傳回未修改的名稱,但一般來說查詢結果是未定義的。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:475 msgid "Default: not set (spaces will not be replaced)" -msgstr "" +msgstr "預設:未設定(不會取代空格)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:480 msgid "certificate_verification (string)" -msgstr "" +msgstr "certificate_verification (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:488 msgid "no_ocsp" -msgstr "" +msgstr "no_ocsp" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:490 @@ -650,11 +726,13 @@ msgid "" "needed if the OCSP servers defined in the certificate are not reachable from " "the client." msgstr "" +"停用線上憑證狀態協定 (OCSP) 檢查。若憑證中定義的 OCSP 伺服器無法從用戶端連線" +",可能需要此選項。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:498 msgid "soft_ocsp" -msgstr "" +msgstr "soft_ocsp" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:500 @@ -663,60 +741,62 @@ msgid "" "skipped. This option should be used to allow authentication when the system " "is offline and the OCSP responder cannot be reached." msgstr "" +"若無法與 OCSP 回應器建立連線,則會略過 OCSP 檢查。當系統離線且無法連線 OCSP " +"回應器時,應使用此選項允許驗證。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:510 msgid "ocsp_dgst" -msgstr "" +msgstr "ocsp_dgst" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:512 msgid "" "Digest (hash) function used to create the certificate ID for the OCSP " "request. Allowed values are:" -msgstr "" +msgstr "用來建立 OCSP 要求憑證 ID 的摘要(雜湊)函式。允許的值有:" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:516 msgid "sha1" -msgstr "" +msgstr "sha1" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:517 msgid "sha256" -msgstr "" +msgstr "sha256" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:518 msgid "sha384" -msgstr "" +msgstr "sha384" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:519 msgid "sha512" -msgstr "" +msgstr "sha512" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:522 msgid "Default: sha1 (to allow compatibility with RFC5019-compliant responder)" -msgstr "" +msgstr "預設:sha1(以相容於符合 RFC5019 的回應器)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:528 msgid "no_verification" -msgstr "" +msgstr "no_verification" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:530 msgid "" "Disables verification completely. This option should only be used for " "testing." -msgstr "" +msgstr "完全停用驗證。此選項只應用於測試。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:536 msgid "partial_chain" -msgstr "" +msgstr "partial_chain" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:538 @@ -725,11 +805,13 @@ msgid "" "chain cannot be built to a self-signed trust-anchor, provided it is possible " "to construct a chain to a trusted certificate that might not be self-signed." msgstr "" +"即使無法建立到自簽信任錨點的<replaceable>完整</replaceable>鏈結,只要可以建立" +"到受信任憑證(可能不是自簽)的鏈結,就允許驗證成功。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:547 msgid "ocsp_default_responder=URL" -msgstr "" +msgstr "ocsp_default_responder=URL" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:549 @@ -738,11 +820,13 @@ msgid "" "mentioned in the certificate. URL must be replaced with the URL of the OCSP " "default responder e.g. http://example.com:80/ocsp." msgstr "" +"設定應取代憑證中所提及回應器的 OCSP 預設回應器。URL 必須替換為 OCSP 預設回應" +"器的 URL,例如 http://example.com:80/ocsp。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:559 msgid "ocsp_default_responder_signing_cert=NAME" -msgstr "" +msgstr "ocsp_default_responder_signing_cert=NAME" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:561 @@ -750,11 +834,13 @@ msgid "" "This option is currently ignored. All needed certificates must be available " "in the PEM file given by pam_cert_db_path." msgstr "" +"此選項目前會被忽略。所有需要的憑證都必須存在於 pam_cert_db_path 指定的 PEM 檔" +"案中。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:569 msgid "crl_file=/PATH/TO/CRL/FILE" -msgstr "" +msgstr "crl_file=/PATH/TO/CRL/FILE" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:571 @@ -764,11 +850,14 @@ msgid "" "<citerefentry> <refentrytitle>crl</refentrytitle> " "<manvolnum>1ssl</manvolnum> </citerefentry> for details." msgstr "" +"驗證憑證時,使用指定檔案中的憑證撤銷清單 (CRL)。CRL 必須以 PEM 格式提供,詳情" +"請參閱 <citerefentry> <refentrytitle>crl</refentrytitle> <manvolnum>1ssl</" +"manvolnum> </citerefentry>。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:584 msgid "soft_crl" -msgstr "" +msgstr "soft_crl" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:587 @@ -778,6 +867,8 @@ msgid "" "CRL. This option should be used to allow authentication when the system is " "offline and the CRL cannot be renewed." msgstr "" +"若憑證撤銷清單 (CRL) 已過期,則忽略 CRL 的到期時間,並使用已過期的 CRL 檢查相" +"關憑證。當系統離線且無法更新 CRL 時,應使用此選項允許驗證。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:483 @@ -786,45 +877,47 @@ msgid "" "separated list of options. Supported options are: <placeholder " "type=\"variablelist\" id=\"0\"/>" msgstr "" +"使用此參數可以透過逗號分隔的選項清單調整憑證驗證。支援的選項有:<placeholder " +"type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:600 msgid "Unknown options are reported but ignored." -msgstr "" +msgstr "未知選項會被回報但予以忽略。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:603 msgid "Default: not set, i.e. do not restrict certificate verification" -msgstr "" +msgstr "預設:未設定,亦即不限制憑證驗證" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:609 msgid "disable_netlink (boolean)" -msgstr "" +msgstr "disable_netlink (boolean)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:612 msgid "" "SSSD hooks into the netlink interface to monitor changes to routes, " "addresses, links and trigger certain actions." -msgstr "" +msgstr "SSSD 掛接至 netlink 介面,以監控路由、位址、連結的變更並觸發特定動作。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:617 msgid "" "The SSSD state changes caused by netlink events may be undesirable and can " "be disabled by setting this option to 'true'" -msgstr "" +msgstr "由 netlink 事件造成的 SSSD 狀態變更可能不受歡迎,可將此選項設為 'true' 來停用" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:622 msgid "Default: false (netlink changes are detected)" -msgstr "" +msgstr "預設:false(會偵測 netlink 變更)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:627 msgid "enable_files_domain (boolean)" -msgstr "" +msgstr "enable_files_domain (boolean)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:630 @@ -832,11 +925,13 @@ msgid "" "When this option is enabled, SSSD prepends an implicit domain with " "<quote>id_provider=files</quote> before any explicitly configured domains." msgstr "" +"啟用此選項時,SSSD 會在任何明確設定的網域之前加上具有 <quote>" +"id_provider=files</quote> 的隱含網域。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:641 msgid "domain_resolution_order" -msgstr "" +msgstr "domain_resolution_order" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:644 @@ -848,6 +943,10 @@ msgid "" "subdomains which are not listed as part of <quote>lookup_order</quote> will " "be looked up in a random order for each parent domain." msgstr "" +"以逗號分隔的網域與子網域清單,代表將遵循的查詢順序。此清單不必包含所有可能的" +"網域,因為遺漏的網域會依 <quote>domains</quote> 設定選項中呈現的順序查詢。未" +"列為 <quote>lookup_order</quote> 一部分的子網域,會以隨機順序對每個父網域查詢" +"。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:656 @@ -866,17 +965,26 @@ msgid "" "shortnames, making this workaround totally not recommended in cases where " "usernames may overlap between domains." msgstr "" +"請注意,設定此選項時,所有指令的輸出格式一律為完整名稱,即使輸入使用簡短名稱" +"亦然<phrase condition=\"with_files_provider\">,但由 files 提供者管理的使用者" +"除外</phrase>。若管理員不希望輸出為完整名稱,可以使用 full_name_format 選項," +"如下所示:<quote>full_name_format=%1$s</quote> 不過請記住,登入時登入應用程式" +"常會呼叫 <citerefentry> <refentrytitle>getpwnam</refentrytitle> <manvolnum>" +"3</manvolnum> </citerefentry> 來正規化使用者名稱;若完整名稱的輸入傳回了簡短" +"名稱(在嘗試存取存在於多個網域的使用者時),可能會將登入嘗試重新導向到使用簡" +"短名稱的網域,因此在網域之間使用者名稱可能重疊的情況下,完全不建議使用此變通" +"方式。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:684 sssd.conf.5.xml:1762 sssd.conf.5.xml:4297 #: sssd-ad.5.xml:187 sssd-ad.5.xml:328 sssd-ad.5.xml:342 msgid "Default: Not set" -msgstr "" +msgstr "預設:未設定" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:689 msgid "implicit_pac_responder (boolean)" -msgstr "" +msgstr "implicit_pac_responder (boolean)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:692 @@ -885,11 +993,13 @@ msgid "" "evaluate and check the PAC. If it has to be disabled set this option to " "'false'." msgstr "" +"PAC 回應器會為 IPA 與 AD 提供者自動啟用,以評估與檢查 PAC。若必須停用,請將此" +"選項設為 'false'。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:703 msgid "core_dumpable (boolean)" -msgstr "" +msgstr "core_dumpable (boolean)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:706 @@ -898,16 +1008,18 @@ msgid "" "forbids core dumps for all SSSD processes to avoid leaking plain text " "passwords. See man page prctl:PR_SET_DUMPABLE for details." msgstr "" +"此選項可用於一般系統強化:設為 'false' 會禁止所有 SSSD 程序傾印 core,以避免" +"洩漏明文密碼。詳情請參閱 prctl:PR_SET_DUMPABLE 手冊頁。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:718 msgid "passkey_verification (string)" -msgstr "" +msgstr "passkey_verification (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:726 msgid "user_verification (boolean)" -msgstr "" +msgstr "user_verification (boolean)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:728 @@ -915,6 +1027,8 @@ msgid "" "Enable or disable the user verification (i.e. PIN, fingerprint) during " "authentication. If enabled, the PIN will always be requested." msgstr "" +"啟用或停用驗證期間的使用者驗證(例如 PIN、指紋)。若啟用,一律會要求輸入 PIN" +"。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:734 @@ -923,6 +1037,8 @@ msgid "" "kerberos pre-authentication case, this value will be overwritten by the " "server." msgstr "" +"預設行為是由金鑰設定決定如何處理。在 IPA 或 kerberos 預先驗證的情況下,此值會" +"被伺服器覆寫。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:721 @@ -931,6 +1047,8 @@ msgid "" "separated list of options. Supported options are: <placeholder " "type=\"variablelist\" id=\"0\"/>" msgstr "" +"使用此參數可以透過逗號分隔的選項清單調整 passkey 驗證。支援的選項有" +":<placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sssd.conf.5.xml:214 @@ -942,11 +1060,15 @@ msgid "" "some other important options like the identity domains. <placeholder " "type=\"variablelist\" id=\"0\"/>" msgstr "" +"SSSD 的各項功能由特殊的 SSSD 服務提供,這些服務會與 SSSD 一同啟動與停止。服務" +"由一個通常稱為 <quote>monitor</quote> 的特殊服務管理。<quote>[sssd]</quote> " +"區段用來設定 monitor,以及身分網域等其他重要選項。<placeholder " +"type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><title> #: sssd.conf.5.xml:753 msgid "SERVICES SECTIONS" -msgstr "" +msgstr "服務區段" #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:755 @@ -956,21 +1078,23 @@ msgid "" "section, for example, for NSS service, the section would be " "<quote>[nss]</quote>" msgstr "" +"本節說明可用來設定不同服務的設定。這些設定應位於 [<replaceable>$NAME</" +"replaceable>] 區段,例如 NSS 服務的區段為 <quote>[nss]</quote>" #. type: Content of: <reference><refentry><refsect1><refsect2><title> #: sssd.conf.5.xml:762 msgid "General service configuration options" -msgstr "" +msgstr "一般服務設定選項" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sssd.conf.5.xml:764 msgid "These options can be used to configure any service." -msgstr "" +msgstr "這些選項可用來設定任何服務。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:768 msgid "fd_limit" -msgstr "" +msgstr "fd_limit" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:771 @@ -981,16 +1105,19 @@ msgid "" "systems without this capability, the resulting value will be the lower value " "of this or the limits.conf \"hard\" limit." msgstr "" +"此選項指定此 SSSD 程序一次可以開啟的檔案描述符數目上限。在授予 SSSD " +"CAP_SYS_RESOURCE 能力的系統上,此為絕對設定。在沒有此能力的系統上,最終值會取" +"此值與 limits.conf \"hard\" 限制中的較低者。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:780 msgid "Default: 8192 (or limits.conf \"hard\" limit)" -msgstr "" +msgstr "預設:8192(或 limits.conf \"hard\" 限制)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:785 msgid "client_idle_timeout" -msgstr "" +msgstr "client_idle_timeout" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:788 @@ -1001,16 +1128,19 @@ msgid "" "can't be shorter than 10 seconds. If a lower value is configured, it will be " "adjusted to 10 seconds." msgstr "" +"此選項指定 SSSD 程序的用戶端可以在不進行通訊的情況下持有檔案描述符的秒數。限" +"制此值是為了避免系統資源耗盡。此逾時不能短於 10 秒。若設定了更低的值,會調整" +"為 10 秒。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:797 msgid "Default: 60, KCM: 300" -msgstr "" +msgstr "預設:60,KCM:300" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:802 msgid "offline_timeout (integer)" -msgstr "" +msgstr "offline_timeout (integer)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:805 @@ -1022,6 +1152,9 @@ msgid "" "time for the previous ones. After each unsuccessful attempt to go online, " "the new interval is recalculated by the following:" msgstr "" +"當 SSSD 切換到離線模式時,嘗試恢復上線之前的時間會依離線時間的長短而增加。依" +"預設,SSSD 使用遞增行為計算重試之間的延遲。因此,某次重試的等待時間會比先前幾" +"次更長。每次嘗試上線失敗後,會依下列方式重新計算新的間隔:" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:816 sssd.conf.5.xml:872 @@ -1029,6 +1162,8 @@ msgid "" "new_delay = Minimum(old_delay * 2, offline_timeout_max) + " "random[0...offline_timeout_random_offset]" msgstr "" +"new_delay = Minimum(old_delay * 2, offline_timeout_max) + " +"random[0...offline_timeout_random_offset]" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:819 @@ -1037,43 +1172,45 @@ msgid "" "value is 3600. The offline_timeout_random_offset default value is 30. The " "end result is amount of seconds before next retry." msgstr "" +"offline_timeout 的預設值為 60。offline_timeout_max 的預設值為 3600。" +"offline_timeout_random_offset 的預設值為 30。最終結果是下一次重試前的秒數。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:825 msgid "" "Note that the maximum length of each interval is defined by " "offline_timeout_max (apart of random part)." -msgstr "" +msgstr "請注意,每個間隔的最大長度由 offline_timeout_max 定義(隨機部分除外)。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:829 sssd.conf.5.xml:1172 sssd.conf.5.xml:1555 #: sssd.conf.5.xml:1851 sssd-ldap.5.xml:495 msgid "Default: 60" -msgstr "" +msgstr "預設:60" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:834 msgid "offline_timeout_max (integer)" -msgstr "" +msgstr "offline_timeout_max (integer)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:837 msgid "" "Controls by how much the time between attempts to go online can be " "incremented following unsuccessful attempts to go online." -msgstr "" +msgstr "控制嘗試上線失敗後,每次嘗試上線之間的時間可以增加多少。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:842 msgid "A value of 0 disables the incrementing behaviour." -msgstr "" +msgstr "值為 0 會停用遞增行為。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:845 msgid "" "The value of this parameter should be set in correlation to offline_timeout " "parameter value." -msgstr "" +msgstr "此參數的值應與 offline_timeout 參數的值相關聯地設定。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:849 @@ -1083,6 +1220,9 @@ msgid "" "rule here should be to set offline_timeout_max to at least 4 times " "offline_timeout." msgstr "" +"當 offline_timeout 設為 60(預設值)時,將 offlinet_timeout_max 設為低於 120 " +"沒有意義,因為它會立即飽和。這裡的一般規則應該是將 offline_timeout_max 設為至" +"少 offline_timeout 的 4 倍。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:855 @@ -1090,23 +1230,25 @@ msgid "" "Although a value between 0 and offline_timeout may be specified, it has the " "effect of overriding the offline_timeout value so is of little use." msgstr "" +"雖然可以指定介於 0 與 offline_timeout 之間的值,但此值的效果是覆寫 " +"offline_timeout 的值,因此用處不大。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:860 msgid "Default: 3600" -msgstr "" +msgstr "預設:3600" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:865 msgid "offline_timeout_random_offset (integer)" -msgstr "" +msgstr "offline_timeout_random_offset (integer)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:868 msgid "" "When SSSD is in offline mode it keeps probing backend servers in specified " "time intervals:" -msgstr "" +msgstr "當 SSSD 處於離線模式時,它會以指定的時間間隔持續探測後端伺服器:" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:875 @@ -1114,26 +1256,28 @@ msgid "" "This parameter controls the value of the random offset used for the above " "equation. Final random_offset value will be random number in range:" msgstr "" +"此參數控制上述公式所使用的隨機偏移值。最終的 random_offset 值會是下列範圍內的" +"隨機數:" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:880 msgid "[0 - offline_timeout_random_offset]" -msgstr "" +msgstr "[0 - offline_timeout_random_offset]" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:883 msgid "A value of 0 disables the random offset addition." -msgstr "" +msgstr "值為 0 會停用隨機偏移的加成。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:886 msgid "Default: 30" -msgstr "" +msgstr "預設:30" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:891 msgid "responder_idle_timeout" -msgstr "" +msgstr "responder_idle_timeout" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:894 @@ -1146,58 +1290,62 @@ msgid "" "built with systemd support and when services are either socket or D-Bus " "activated." msgstr "" +"此選項指定 SSSD 回應器程序在未使用的情況下可以運作的秒數。限制此值是為了避免" +"系統資源耗盡。此選項可接受的最小值為 60 秒。將此選項設為 0(零)表示不會對回" +"應器設定逾時。此選項只有在 SSSD 以 systemd 支援建置,且服務以 socket 或 D-" +"Bus 方式啟動時才有效。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:908 sssd.conf.5.xml:1185 sssd.conf.5.xml:2304 #: sssd-ldap.5.xml:332 msgid "Default: 300" -msgstr "" +msgstr "預設:300" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:913 msgid "cache_first" -msgstr "" +msgstr "cache_first" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:916 msgid "" "This option specifies whether the responder should query all caches before " "querying the Data Providers." -msgstr "" +msgstr "此選項指定回應器在查詢資料提供者之前,是否應先查詢所有快取。" #. type: Content of: <reference><refentry><refsect1><refsect2><title> #: sssd.conf.5.xml:931 msgid "NSS configuration options" -msgstr "" +msgstr "NSS 設定選項" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sssd.conf.5.xml:933 msgid "" "These options can be used to configure the Name Service Switch (NSS) " "service." -msgstr "" +msgstr "這些選項可用來設定名稱服務切換 (NSS) 服務。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:938 msgid "enum_cache_timeout (integer)" -msgstr "" +msgstr "enum_cache_timeout (integer)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:941 msgid "" "How many seconds should nss_sss cache enumerations (requests for info about " "all users)" -msgstr "" +msgstr "nss_sss 應該快取列舉(關於所有使用者的資訊要求)多少秒" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:945 msgid "Default: 120" -msgstr "" +msgstr "預設:120" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:950 msgid "entry_cache_nowait_percentage (integer)" -msgstr "" +msgstr "entry_cache_nowait_percentage (integer)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:953 @@ -1206,6 +1354,8 @@ msgid "" "if they are requested beyond a percentage of the entry_cache_timeout value " "for the domain." msgstr "" +"若項目在超過網域的 entry_cache_timeout 值一定百分比後仍被請求,可設定項目快取" +"在背景自動更新項目。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:959 @@ -1216,6 +1366,10 @@ msgid "" "but the SSSD will go and update the cache on its own, so that future " "requests will not need to block waiting for a cache update." msgstr "" +"例如,若網域的 entry_cache_timeout 設為 30 秒,且 " +"entry_cache_nowait_percentage 設為 50(百分比),則在最後一次快取更新 15 秒後" +"進入的項目會立即傳回,但 SSSD 會自行更新快取,因此未來的要求不需要為了等待快" +"取更新而阻塞。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:969 @@ -1225,16 +1379,18 @@ msgid "" "percentage will never reduce the nowait timeout to less than 10 seconds. (0 " "disables this feature)" msgstr "" +"此選項的有效值為 0-99,代表每個網域 entry_cache_timeout 的百分比。基於效能考" +"量,此百分比絕不會將 nowait 逾時降到低於 10 秒。(0 會停用此功能)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:977 sssd.conf.5.xml:2093 msgid "Default: 50" -msgstr "" +msgstr "預設:50" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:982 msgid "entry_negative_timeout (integer)" -msgstr "" +msgstr "entry_negative_timeout (integer)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:985 @@ -1243,16 +1399,18 @@ msgid "" "(that is, queries for invalid database entries, like nonexistent ones) " "before asking the back end again." msgstr "" +"指定 nss_sss 在再次詢問後端之前,應該快取負面快取命中(亦即對無效資料庫項目的" +"查詢,例如不存在的項目)多少秒。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:991 sssd.conf.5.xml:1750 sssd.conf.5.xml:2117 msgid "Default: 15" -msgstr "" +msgstr "預設:15" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:996 msgid "local_negative_timeout (integer)" -msgstr "" +msgstr "local_negative_timeout (integer)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:999 @@ -1261,16 +1419,18 @@ msgid "" "negative cache before trying to look it up in the back end again. Setting " "the option to 0 disables this feature." msgstr "" +"指定 nss_sss 在再次嘗試於後端查詢本機使用者與群組之前,應該將它們保留在負面快" +"取中多少秒。將此選項設為 0 會停用此功能。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1005 msgid "Default: 14400 (4 hours)" -msgstr "" +msgstr "預設:14400(4 小時)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1010 msgid "filter_users, filter_groups (string)" -msgstr "" +msgstr "filter_users, filter_groups (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1013 @@ -1280,6 +1440,9 @@ msgid "" "also be set per-domain or include fully-qualified names to filter only users " "from the particular domain or by a user principal name (UPN)." msgstr "" +"排除從 sss NSS 資料庫取回的特定使用者或群組。這對系統帳戶特別有用。此選項也可" +"以逐網域設定,或包含完整名稱,以只過濾特定網域的使用者,或依使用者主體名稱 " +"(UPN) 過濾。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1021 @@ -1289,38 +1452,40 @@ msgid "" "NSS. E.g. a group having a member group filtered out will still have the " "member users of the latter listed." msgstr "" +"注意:filter_groups 選項不影響巢狀群組成員的繼承,因為過濾發生在成員透過 NSS " +"傳播傳回之後。例如,某個群組的成員群組被過濾掉時,後者的成員使用者仍會列出。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1029 msgid "Default: root" -msgstr "" +msgstr "預設:root" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1034 msgid "filter_users_in_groups (bool)" -msgstr "" +msgstr "filter_users_in_groups (bool)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1037 msgid "If you want filtered user still be group members set this option to false." -msgstr "" +msgstr "若您希望被過濾的使用者仍然是群組成員,請將此選項設為 false。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1048 msgid "fallback_homedir (string)" -msgstr "" +msgstr "fallback_homedir (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1051 msgid "" "Set a default template for a user's home directory if one is not specified " "explicitly by the domain's data provider." -msgstr "" +msgstr "若網域的資料提供者沒有明確指定使用者的家目錄,請設定預設範本。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1056 msgid "The available values for this option are the same as for override_homedir." -msgstr "" +msgstr "此選項可用的值與 override_homedir 相同。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> #: sssd.conf.5.xml:1062 @@ -1329,22 +1494,24 @@ msgid "" "fallback_homedir = /home/%u\n" " " msgstr "" +"fallback_homedir = /home/%u\n" +" " #. type: Content of: <varlistentry><listitem><para> #: sssd.conf.5.xml:1060 sssd.conf.5.xml:1622 sssd.conf.5.xml:1641 #: sssd.conf.5.xml:1718 sssd-krb5.5.xml:451 include/override_homedir.xml:66 msgid "example: <placeholder type=\"programlisting\" id=\"0\"/>" -msgstr "" +msgstr "範例:<placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1066 msgid "Default: not set (no substitution for unset home directories)" -msgstr "" +msgstr "預設:未設定(未設定的家目錄不會替換)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1072 msgid "override_shell (string)" -msgstr "" +msgstr "override_shell (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1075 @@ -1353,26 +1520,28 @@ msgid "" "shell options if it takes effect and can be set either in the [nss] section " "or per-domain." msgstr "" +"覆寫所有使用者的登入 shell。若此選項生效,會取代任何其他 shell 選項,且可以" +"在 [nss] 區段或逐網域設定。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1081 msgid "Default: not set (SSSD will use the value retrieved from LDAP)" -msgstr "" +msgstr "預設:未設定(SSSD 會使用從 LDAP 取回的值)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1087 msgid "allowed_shells (string)" -msgstr "" +msgstr "allowed_shells (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1090 msgid "Restrict user shell to one of the listed values. The order of evaluation is:" -msgstr "" +msgstr "將使用者 shell 限制為列出的值之一。評估順序為:" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1093 msgid "1. If the shell is present in <quote>/etc/shells</quote>, it is used." -msgstr "" +msgstr "1. 若 shell 存在於 <quote>/etc/shells</quote>,則使用它。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1097 @@ -1380,6 +1549,8 @@ msgid "" "2. If the shell is in the allowed_shells list but not in " "<quote>/etc/shells</quote>, use the value of the shell_fallback parameter." msgstr "" +"2. 若 shell 在 allowed_shells 清單中但不在 <quote>/etc/shells</quote>,使用 " +"shell_fallback 參數的值。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1102 @@ -1387,11 +1558,13 @@ msgid "" "3. If the shell is not in the allowed_shells list and not in " "<quote>/etc/shells</quote>, a nologin shell is used." msgstr "" +"3. 若 shell 不在 allowed_shells 清單中且不在 <quote>/etc/shells</quote>,使" +"用 nologin shell。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1107 msgid "The wildcard (*) can be used to allow any shell." -msgstr "" +msgstr "可以使用萬用字元 (*) 允許任何 shell。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1110 @@ -1400,11 +1573,13 @@ msgid "" "shell is not in <quote>/etc/shells</quote> and maintaining list of all " "allowed shells in allowed_shells would be to much overhead." msgstr "" +"若您希望在使用者 shell 不在 <quote>/etc/shells</quote> 時使用 shell_fallback" +",且維護 allowed_shells 中所有允許 shell 的清單負擔過重,(*) 就很有用。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1117 msgid "An empty string for shell is passed as-is to libc." -msgstr "" +msgstr "shell 的空字串會原樣傳給 libc。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1120 @@ -1412,43 +1587,45 @@ msgid "" "The <quote>/etc/shells</quote> is only read on SSSD start up, which means " "that a restart of the SSSD is required in case a new shell is installed." msgstr "" +"<quote>/etc/shells</quote> 只在 SSSD 啟動時讀取,這表示安裝新 shell 後需要重" +"新啟動 SSSD。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1124 msgid "Default: Not set. The user shell is automatically used." -msgstr "" +msgstr "預設:未設定。會自動使用使用者 shell。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1129 msgid "vetoed_shells (string)" -msgstr "" +msgstr "vetoed_shells (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1132 msgid "Replace any instance of these shells with the shell_fallback" -msgstr "" +msgstr "以 shell_fallback 取代這些 shell 的任何實例" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1137 msgid "shell_fallback (string)" -msgstr "" +msgstr "shell_fallback (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1140 msgid "" "The default shell to use if an allowed shell is not installed on the " "machine." -msgstr "" +msgstr "若允許的 shell 未安裝在機器上時要使用的預設 shell。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1144 msgid "Default: /bin/sh" -msgstr "" +msgstr "預設:/bin/sh" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1149 msgid "default_shell" -msgstr "" +msgstr "default_shell" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1152 @@ -1457,6 +1634,8 @@ msgid "" "lookup. This option can be specified globally in the [nss] section or " "per-domain." msgstr "" +"若提供者在查詢時沒有傳回 shell,則使用的預設 shell。此選項可以在 [nss] 區段全" +"域指定,或逐網域指定。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1158 @@ -1464,37 +1643,39 @@ msgid "" "Default: not set (Return NULL if no shell is specified and rely on libc to " "substitute something sensible when necessary, usually /bin/sh)" msgstr "" +"預設:未設定(若未指定 shell 則傳回 NULL,必要時依賴 libc 替換為合理的值,通" +"常是 /bin/sh)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1165 sssd.conf.5.xml:1548 msgid "get_domains_timeout (int)" -msgstr "" +msgstr "get_domains_timeout (int)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1168 sssd.conf.5.xml:1551 msgid "" "Specifies time in seconds for which the list of subdomains will be " "considered valid." -msgstr "" +msgstr "指定子網域清單被視為有效的時間(秒)。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1177 msgid "memcache_timeout (integer)" -msgstr "" +msgstr "memcache_timeout (integer)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1180 msgid "" "Specifies time in seconds for which records in the in-memory cache will be " "valid. Setting this option to zero will disable the in-memory cache." -msgstr "" +msgstr "指定記憶體快取中的記錄有效的秒數。將此選項設為零會停用記憶體快取。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1188 msgid "" "WARNING: Disabling the in-memory cache will have significant negative impact " "on SSSD's performance and should only be used for testing." -msgstr "" +msgstr "警告:停用記憶體快取會對 SSSD 的效能造成重大負面影響,只應用於測試。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1194 sssd.conf.5.xml:1219 sssd.conf.5.xml:1244 @@ -1503,11 +1684,13 @@ msgid "" "NOTE: If the environment variable SSS_NSS_USE_MEMCACHE is set to \"NO\", " "client applications will not use the fast in-memory cache." msgstr "" +"注意:若環境變數 SSS_NSS_USE_MEMCACHE 設為 \"NO\",用戶端應用程式不會使用快速" +"的記憶體快取。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1202 msgid "memcache_size_passwd (integer)" -msgstr "" +msgstr "memcache_size_passwd (integer)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1205 @@ -1516,11 +1699,13 @@ msgid "" "for passwd requests. Setting the size to 0 will disable the passwd " "in-memory cache." msgstr "" +"快速記憶體快取內為 passwd 要求配置的資料表大小(以 MB 為單位)。將大小設為 0 " +"會停用 passwd 記憶體快取。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1211 sssd.conf.5.xml:2963 sssd-ldap.5.xml:549 msgid "Default: 8" -msgstr "" +msgstr "預設:8" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1214 sssd.conf.5.xml:1239 sssd.conf.5.xml:1264 @@ -1528,12 +1713,12 @@ msgstr "" msgid "" "WARNING: Disabled or too small in-memory cache can have significant negative " "impact on SSSD's performance." -msgstr "" +msgstr "警告:停用或太小的記憶體快取會對 SSSD 的效能造成重大負面影響。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1227 msgid "memcache_size_group (integer)" -msgstr "" +msgstr "memcache_size_group (integer)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1230 @@ -1542,18 +1727,20 @@ msgid "" "for group requests. Setting the size to 0 will disable the group in-memory " "cache." msgstr "" +"快速記憶體快取內為群組要求配置的資料表大小(以 MB 為單位)。將大小設為 0 會停" +"用群組記憶體快取。" #. type: Content of: <variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1236 sssd.conf.5.xml:1288 sssd.conf.5.xml:3724 #: sssd-ldap.5.xml:474 sssd-ldap.5.xml:526 include/failover.xml:116 #: include/krb5_options.xml:11 msgid "Default: 6" -msgstr "" +msgstr "預設:6" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1252 msgid "memcache_size_initgroups (integer)" -msgstr "" +msgstr "memcache_size_initgroups (integer)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1255 @@ -1562,11 +1749,13 @@ msgid "" "for initgroups requests. Setting the size to 0 will disable the initgroups " "in-memory cache." msgstr "" +"快速記憶體快取內為 initgroups 要求配置的資料表大小(以 MB 為單位)。將大小設" +"為 0 會停用 initgroups 記憶體快取。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1277 msgid "memcache_size_sid (integer)" -msgstr "" +msgstr "memcache_size_sid (integer)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1280 @@ -1576,11 +1765,14 @@ msgid "" "currently cached in fast in-memory cache. Setting the size to 0 will " "disable the SID in-memory cache." msgstr "" +"快速記憶體快取內為 SID 相關要求配置的資料表大小(以 MB 為單位)。目前只有 " +"SID-by-ID 與 ID-by-SID 要求會快取在快速記憶體快取中。將大小設為 0 會停用 SID " +"記憶體快取。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.conf.5.xml:1304 sssd-ifp.5.xml:90 msgid "user_attributes (string)" -msgstr "" +msgstr "user_attributes (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1307 @@ -1593,6 +1785,10 @@ msgid "" "<manvolnum>5</manvolnum> </citerefentry> for details) but with no default " "values." msgstr "" +"部分額外的 NSS 回應器要求可以傳回比 NSS 介面定義的 POSIX 屬性更多的屬性。屬性" +"清單由此選項控制。其處理方式與 InfoPipe 回應器的 <quote>user_attributes</" +"quote> 選項相同(詳情請參閱 <citerefentry> <refentrytitle>sssd-ifp</" +"refentrytitle> <manvolnum>5</manvolnum> </citerefentry>),但沒有預設值。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1320 @@ -1600,35 +1796,37 @@ msgid "" "To make configuration more easy the NSS responder will check the InfoPipe " "option if it is not set for the NSS responder." msgstr "" +"為了讓設定更容易,若 NSS 回應器沒有設定 InfoPipe 選項,NSS 回應器會檢查該選項" +"。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1325 msgid "Default: not set, fallback to InfoPipe option" -msgstr "" +msgstr "預設:未設定,退回 InfoPipe 選項" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1330 msgid "pwfield (string)" -msgstr "" +msgstr "pwfield (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1333 msgid "" "The value that NSS operations that return users or groups will return for " "the <quote>password</quote> field." -msgstr "" +msgstr "傳回使用者或群組的 NSS 作業會為 <quote>password</quote> 欄位傳回的值。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1338 msgid "Default: <quote>*</quote>" -msgstr "" +msgstr "預設:<quote>*</quote>" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1341 msgid "" "Note: This option can also be set per-domain which overwrites the value in " "[nss] section." -msgstr "" +msgstr "注意:此選項也可以逐網域設定,會覆寫 [nss] 區段中的值。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1345 @@ -1638,52 +1836,55 @@ msgid "" "</phrase> <quote>x</quote> (proxy domain with nss_files and sssd-shadowutils " "target)" msgstr "" +"預設:<quote>未設定</quote>(遠端網域),<phrase " +"condition=\"with_files_provider\"> <quote>x</quote>(files 網域),</phrase> " +"<quote>x</quote>(以 nss_files 與 sssd-shadowutils 為目標的 proxy 網域)" #. type: Content of: <reference><refentry><refsect1><refsect2><title> #: sssd.conf.5.xml:1357 msgid "PAM configuration options" -msgstr "" +msgstr "PAM 設定選項" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sssd.conf.5.xml:1359 msgid "" "These options can be used to configure the Pluggable Authentication Module " "(PAM) service." -msgstr "" +msgstr "這些選項可用來設定可插拔驗證模組 (PAM) 服務。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1364 msgid "offline_credentials_expiration (integer)" -msgstr "" +msgstr "offline_credentials_expiration (integer)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1367 msgid "" "If the authentication provider is offline, how long should we allow cached " "logins (in days since the last successful online login)." -msgstr "" +msgstr "若驗證提供者離線,允許快取登入多久(以自上次成功線上登入起的天數計)。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1372 sssd.conf.5.xml:1385 msgid "Default: 0 (No limit)" -msgstr "" +msgstr "預設:0(無限制)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1378 msgid "offline_failed_login_attempts (integer)" -msgstr "" +msgstr "offline_failed_login_attempts (integer)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1381 msgid "" "If the authentication provider is offline, how many failed login attempts " "are allowed." -msgstr "" +msgstr "若驗證提供者離線,允許多少次失敗的登入嘗試。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1391 msgid "offline_failed_login_delay (integer)" -msgstr "" +msgstr "offline_failed_login_delay (integer)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1394 @@ -1691,6 +1892,8 @@ msgid "" "The time in minutes which has to pass after offline_failed_login_attempts " "has been reached before a new login attempt is possible." msgstr "" +"在達到 offline_failed_login_attempts 之後、可以再次嘗試登入之前,必須經過的時" +"間(分鐘)。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1399 @@ -1699,58 +1902,60 @@ msgid "" "offline_failed_login_attempts has been reached. Only a successful online " "authentication can enable offline authentication again." msgstr "" +"若設為 0,當 offline_failed_login_attempts 已達上限時,使用者無法離線驗證。只" +"有成功的線上驗證才能再次啟用離線驗證。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1405 sssd.conf.5.xml:1515 msgid "Default: 5" -msgstr "" +msgstr "預設:5" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1411 msgid "pam_verbosity (integer)" -msgstr "" +msgstr "pam_verbosity (integer)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1414 msgid "" "Controls what kind of messages are shown to the user during " "authentication. The higher the number to more messages are displayed." -msgstr "" +msgstr "控制驗證期間會向使用者顯示哪種訊息。數字越高,顯示的訊息越多。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1419 msgid "Currently sssd supports the following values:" -msgstr "" +msgstr "目前 sssd 支援下列值:" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1422 msgid "<emphasis>0</emphasis>: do not show any message" -msgstr "" +msgstr "<emphasis>0</emphasis>:不顯示任何訊息" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1425 msgid "<emphasis>1</emphasis>: show only important messages" -msgstr "" +msgstr "<emphasis>1</emphasis>:只顯示重要訊息" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1429 msgid "<emphasis>2</emphasis>: show informational messages" -msgstr "" +msgstr "<emphasis>2</emphasis>:顯示資訊訊息" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1432 msgid "<emphasis>3</emphasis>: show all messages and debug information" -msgstr "" +msgstr "<emphasis>3</emphasis>:顯示所有訊息與除錯資訊" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1436 sssd.8.xml:63 msgid "Default: 1" -msgstr "" +msgstr "預設:1" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1442 msgid "pam_response_filter (string)" -msgstr "" +msgstr "pam_response_filter (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1445 @@ -1760,6 +1965,9 @@ msgid "" "responses sent to pam_sss e.g. messages displayed to the user or environment " "variables which should be set by pam_sss." msgstr "" +"以逗號分隔的字串清單,允許移除(過濾)PAM 回應器傳送給 pam_sss PAM 模組的資料" +"。傳送給 pam_sss 的回應有不同種類,例如顯示給使用者的訊息或應由 pam_sss 設定" +"的環境變數。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1453 @@ -1767,43 +1975,45 @@ msgid "" "While messages already can be controlled with the help of the pam_verbosity " "option this option allows to filter out other kind of responses as well." msgstr "" +"雖然訊息已經可以透過 pam_verbosity 選項控制,此選項也允許過濾掉其他種類的回應" +"。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:1460 msgid "ENV" -msgstr "" +msgstr "ENV" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1461 msgid "Do not send any environment variables to any service." -msgstr "" +msgstr "不將任何環境變數傳送給任何服務。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:1464 msgid "ENV:var_name" -msgstr "" +msgstr "ENV:var_name" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1465 msgid "Do not send environment variable var_name to any service." -msgstr "" +msgstr "不將環境變數 var_name 傳送給任何服務。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:1469 msgid "ENV:var_name:service" -msgstr "" +msgstr "ENV:var_name:service" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1470 msgid "Do not send environment variable var_name to service." -msgstr "" +msgstr "不將環境變數 var_name 傳送給 service。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1458 msgid "" "Currently the following filters are supported: <placeholder " "type=\"variablelist\" id=\"0\"/>" -msgstr "" +msgstr "目前支援下列過濾器:<placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1477 @@ -1815,21 +2025,25 @@ msgid "" "that either all list elements must have a '+' or '-' prefix or none. It is " "considered as an error to mix both styles." msgstr "" +"字串清單可以是過濾器清單,設定此過濾器清單並覆寫預設值;或者清單的每個元素可" +"以加上 '+' 或 '-' 字元前綴,分別將過濾器加入現有預設值或從預設值移除。請注意" +",清單元素必須全部加上 '+' 或 '-' 前綴,或全部不加。混用兩種樣式會被視為錯誤" +"。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1488 msgid "Default: ENV:KRB5CCNAME:sudo, ENV:KRB5CCNAME:sudo-i" -msgstr "" +msgstr "預設:ENV:KRB5CCNAME:sudo、ENV:KRB5CCNAME:sudo-i" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1491 msgid "Example: -ENV:KRB5CCNAME:sudo-i will remove the filter from the default list" -msgstr "" +msgstr "範例:-ENV:KRB5CCNAME:sudo-i 會從預設清單移除該過濾器" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1498 msgid "pam_id_timeout (integer)" -msgstr "" +msgstr "pam_id_timeout (integer)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1501 @@ -1838,6 +2052,8 @@ msgid "" "immediately update the cached identity information for the user in order to " "ensure that authentication takes place with the latest information." msgstr "" +"SSSD 在線上時,對於任何 PAM 要求,SSSD 都會嘗試立即更新使用者的快取身分資訊," +"以確保驗證使用最新的資訊進行。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1507 @@ -1848,16 +2064,19 @@ msgid "" "identity information to avoid excessive round-trips to the identity " "provider." msgstr "" +"完整的 PAM 對話可能執行多個 PAM 要求,例如帳戶管理與開啟工作階段。此選項控制" +"(以每個用戶端應用程式為單位)可以快取身分資訊多久(秒),以避免過度往返身分" +"提供者。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1521 msgid "pam_pwd_expiration_warning (integer)" -msgstr "" +msgstr "pam_pwd_expiration_warning (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1524 sssd.conf.5.xml:2987 msgid "Display a warning N days before the password expires." -msgstr "" +msgstr "在密碼到期前 N 天顯示警告。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1527 @@ -1866,6 +2085,8 @@ msgid "" "expiration time of the password. If this information is missing, sssd " "cannot display a warning." msgstr "" +"請注意,後端伺服器必須提供密碼到期時間的資訊。若缺少此資訊,sssd 無法顯示警告" +"。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1533 sssd.conf.5.xml:2990 @@ -1873,25 +2094,25 @@ msgid "" "If zero is set, then this filter is not applied, i.e. if the expiration " "warning was received from backend server, it will automatically be " "displayed." -msgstr "" +msgstr "若設為零,則不套用此過濾器,亦即若收到來自後端伺服器的到期警告,會自動顯示。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1538 msgid "" "This setting can be overridden by setting " "<emphasis>pwd_expiration_warning</emphasis> for a particular domain." -msgstr "" +msgstr "可以為特定網域設定 <emphasis>pwd_expiration_warning</emphasis> 來覆寫此設定。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1543 sssd.conf.5.xml:3990 sssd-ldap.5.xml:607 #: sssd-ldap.5.xml:1673 sssd.8.xml:79 msgid "Default: 0" -msgstr "" +msgstr "預設:0" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1560 msgid "pam_trusted_users (string)" -msgstr "" +msgstr "pam_trusted_users (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1563 @@ -1902,11 +2123,14 @@ msgid "" "<quote>pam_public_domains</quote>. User names are resolved to UIDs at " "startup." msgstr "" +"指定允許對受信任網域執行 PAM 對話的 UID 值或使用者名稱清單(以逗號分隔)。未" +"包含在此清單中的使用者只能存取以 <quote>pam_public_domains</quote> 標記為公開" +"的網域。使用者名稱會在啟動時解析為 UID。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1573 msgid "Default: All users are considered trusted by default" -msgstr "" +msgstr "預設:依預設所有使用者都被視為受信任" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1577 @@ -1914,54 +2138,56 @@ msgid "" "Please note that UID 0 is always allowed to access the PAM responder even in " "case it is not in the pam_trusted_users list." msgstr "" +"請注意,UID 0 一律允許存取 PAM 回應器,即使它不在 pam_trusted_users 清單中亦" +"然。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1584 msgid "pam_public_domains (string)" -msgstr "" +msgstr "pam_public_domains (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1587 msgid "" "Specifies the comma-separated list of domain names that are accessible even " "to untrusted users." -msgstr "" +msgstr "指定即使是不受信任的使用者也可以存取的網域名稱清單(以逗號分隔)。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1591 msgid "Two special values for pam_public_domains option are defined:" -msgstr "" +msgstr "定義了 pam_public_domains 選項的兩個特殊值:" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1595 msgid "all (Untrusted users are allowed to access all domains in PAM responder.)" -msgstr "" +msgstr "all(允許不受信任的使用者存取 PAM 回應器中的所有網域。)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1599 msgid "" "none (Untrusted users are not allowed to access any domains PAM in " "responder.)" -msgstr "" +msgstr "none(不允許不受信任的使用者存取回應器中的任何 PAM 網域。)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1603 sssd.conf.5.xml:1628 sssd.conf.5.xml:1647 #: sssd.conf.5.xml:1884 sssd.conf.5.xml:2725 sssd.conf.5.xml:3919 #: sssd-ldap.5.xml:1210 msgid "Default: none" -msgstr "" +msgstr "預設:none" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1608 msgid "pam_account_expired_message (string)" -msgstr "" +msgstr "pam_account_expired_message (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1611 msgid "" "Allows a custom expiration message to be set, replacing the default " "'Permission denied' message." -msgstr "" +msgstr "允許設定自訂的到期訊息,取代預設的 'Permission denied' 訊息。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1616 @@ -1969,6 +2195,8 @@ msgid "" "Note: Please be aware that message is only printed for the SSH service " "unless pam_verbosity is set to 3 (show all messages and debug information)." msgstr "" +"注意:除非 pam_verbosity 設為 3(顯示所有訊息與除錯資訊),否則此訊息只會為 " +"SSH 服務顯示。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> #: sssd.conf.5.xml:1624 @@ -1977,18 +2205,20 @@ msgid "" "pam_account_expired_message = Account expired, please contact help desk.\n" " " msgstr "" +"pam_account_expired_message = Account expired, please contact help desk.\n" +" " #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1633 msgid "pam_account_locked_message (string)" -msgstr "" +msgstr "pam_account_locked_message (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1636 msgid "" "Allows a custom lockout message to be set, replacing the default 'Permission " "denied' message." -msgstr "" +msgstr "允許設定自訂的鎖定訊息,取代預設的 'Permission denied' 訊息。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> #: sssd.conf.5.xml:1643 @@ -1997,32 +2227,34 @@ msgid "" "pam_account_locked_message = Account locked, please contact help desk.\n" " " msgstr "" +"pam_account_locked_message = Account locked, please contact help desk.\n" +" " #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1652 msgid "pam_passkey_auth (bool)" -msgstr "" +msgstr "pam_passkey_auth (bool)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1655 msgid "Enable passkey device based authentication." -msgstr "" +msgstr "啟用以 passkey 裝置為基礎的驗證。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1658 sssd.conf.5.xml:1970 sssd-ad.5.xml:1272 #: sss_rpcidmapd.5.xml:76 sssd-files.5.xml:145 msgid "Default: True" -msgstr "" +msgstr "預設:True" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1663 msgid "passkey_debug_libfido2 (bool)" -msgstr "" +msgstr "passkey_debug_libfido2 (bool)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1666 msgid "Enable libfido2 library debug messages." -msgstr "" +msgstr "啟用 libfido2 程式庫的除錯訊息。" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1669 sssd.conf.5.xml:1683 sssd-ldap.5.xml:672 @@ -2030,12 +2262,12 @@ msgstr "" #: sssd-ad.5.xml:506 sssd-ad.5.xml:582 sssd-ad.5.xml:1127 sssd-ad.5.xml:1176 #: include/ldap_id_mapping.xml:250 msgid "Default: False" -msgstr "" +msgstr "預設:False" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1674 msgid "pam_cert_auth (bool)" -msgstr "" +msgstr "pam_cert_auth (bool)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1677 @@ -2044,33 +2276,35 @@ msgid "" "additional communication with the Smartcard which will delay the " "authentication process this option is disabled by default." msgstr "" +"啟用以憑證為基礎的智慧卡驗證。由於這需要與智慧卡進行額外通訊,會延遲驗證流程" +",因此此選項依預設停用。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1688 msgid "pam_cert_db_path (string)" -msgstr "" +msgstr "pam_cert_db_path (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1691 msgid "The path to the certificate database." -msgstr "" +msgstr "憑證資料庫的路徑。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1694 sssd.conf.5.xml:2219 sssd.conf.5.xml:4411 msgid "Default:" -msgstr "" +msgstr "預設:" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:1696 sssd.conf.5.xml:2221 msgid "" "/etc/sssd/pki/sssd_auth_ca_db.pem (path to a file with trusted CA " "certificates in PEM format)" -msgstr "" +msgstr "/etc/sssd/pki/sssd_auth_ca_db.pem(包含 PEM 格式受信任 CA 憑證之檔案的路徑)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1706 msgid "pam_cert_verification (string)" -msgstr "" +msgstr "pam_cert_verification (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1709 @@ -2081,6 +2315,9 @@ msgid "" "section. Supported options are the same of " "<quote>certificate_verification</quote>." msgstr "" +"使用此參數可以透過逗號分隔的選項清單調整 PAM 憑證驗證,這些選項會覆寫 <quote>" +"[sssd]</quote> 區段中的 <quote>certificate_verification</quote> 值。支援的選" +"項與 <quote>certificate_verification</quote> 相同。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> #: sssd.conf.5.xml:1720 @@ -2089,6 +2326,8 @@ msgid "" "pam_cert_verification = partial_chain\n" " " msgstr "" +"pam_cert_verification = partial_chain\n" +" " #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1724 @@ -2096,50 +2335,52 @@ msgid "" "Default: not set, i.e. use default <quote>certificate_verification</quote> " "option defined in <quote>[sssd]</quote> section." msgstr "" +"預設:未設定,亦即使用 <quote>[sssd]</quote> 區段中定義的預設 <quote>" +"certificate_verification</quote> 選項。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1731 msgid "p11_child_timeout (integer)" -msgstr "" +msgstr "p11_child_timeout (integer)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1734 msgid "How many seconds will pam_sss wait for p11_child to finish." -msgstr "" +msgstr "pam_sss 會等待 p11_child 完成多少秒。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1743 msgid "passkey_child_timeout (integer)" -msgstr "" +msgstr "passkey_child_timeout (integer)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1746 msgid "How many seconds will the PAM responder wait for passkey_child to finish." -msgstr "" +msgstr "PAM 回應器會等待 passkey_child 完成多少秒。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1755 msgid "pam_app_services (string)" -msgstr "" +msgstr "pam_app_services (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1758 msgid "" "Which PAM services are permitted to contact domains of type " "<quote>application</quote>" -msgstr "" +msgstr "允許哪些 PAM 服務聯絡 <quote>application</quote> 類型的網域" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1767 msgid "pam_p11_allowed_services (string)" -msgstr "" +msgstr "pam_p11_allowed_services (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1770 msgid "" "A comma-separated list of PAM service names for which it will be allowed to " "use Smartcards." -msgstr "" +msgstr "允許使用智慧卡的 PAM 服務名稱清單(以逗號分隔)。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> #: sssd.conf.5.xml:1785 @@ -2148,6 +2389,8 @@ msgid "" "pam_p11_allowed_services = +my_pam_service, -login\n" " " msgstr "" +"pam_p11_allowed_services = +my_pam_service, -login\n" +" " #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1774 @@ -2160,62 +2403,67 @@ msgid "" "(e.g. <quote>my_pam_service</quote>), you would use the following " "configuration: <placeholder type=\"programlisting\" id=\"0\"/>" msgstr "" +"可以使用 <quote>+service_name</quote> 將另一個 PAM 服務名稱加入預設集合,或使" +"用 <quote>-service_name</quote> 明確地從預設集合移除某個 PAM 服務名稱。例如," +"若要將智慧卡驗證的預設 PAM 服務名稱(例如 <quote>login</quote>)替換為自訂的 " +"PAM 服務名稱(例如 <quote>my_pam_service</quote>),請使用下列設定" +":<placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1789 sssd-ad.5.xml:645 sssd-ad.5.xml:754 sssd-ad.5.xml:812 #: sssd-ad.5.xml:870 sssd-ad.5.xml:948 msgid "Default: the default set of PAM service names includes:" -msgstr "" +msgstr "預設:預設的 PAM 服務名稱集合包含:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:1794 sssd-ad.5.xml:649 msgid "login" -msgstr "" +msgstr "login" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:1799 sssd-ad.5.xml:654 msgid "su" -msgstr "" +msgstr "su" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:1804 sssd-ad.5.xml:659 msgid "su-l" -msgstr "" +msgstr "su-l" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:1809 sssd-ad.5.xml:674 msgid "gdm-smartcard" -msgstr "" +msgstr "gdm-smartcard" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:1814 sssd-ad.5.xml:669 msgid "gdm-password" -msgstr "" +msgstr "gdm-password" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:1819 sssd-ad.5.xml:679 msgid "kdm" -msgstr "" +msgstr "kdm" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:1824 sssd-ad.5.xml:957 msgid "sudo" -msgstr "" +msgstr "sudo" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:1829 sssd-ad.5.xml:962 msgid "sudo-i" -msgstr "" +msgstr "sudo-i" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:1834 msgid "gnome-screensaver" -msgstr "" +msgstr "gnome-screensaver" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1842 msgid "p11_wait_for_card_timeout (integer)" -msgstr "" +msgstr "p11_wait_for_card_timeout (integer)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1845 @@ -2224,11 +2472,13 @@ msgid "" "to p11_child_timeout should the PAM responder wait until a Smartcard is " "inserted." msgstr "" +"若需要智慧卡驗證,PAM 回應器在 p11_child_timeout 之外,還應該多等待多少秒直到" +"插入智慧卡。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1856 msgid "p11_uri (string)" -msgstr "" +msgstr "p11_uri (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1859 @@ -2240,6 +2490,10 @@ msgid "" "first slot found. If multiple readers are connected p11_uri can be used to " "tell p11_child to use a specific reader." msgstr "" +"PKCS#11 URI(詳情請參閱 RFC-7512),可用來限制智慧卡驗證所使用的裝置選擇。依" +"預設,SSSD 的 p11_child 會搜尋設定 'removable' 旗標的 PKCS#11 插槽(讀卡機)" +",並從找到的第一個插槽讀取已插入權杖中的憑證。若連接了多台讀卡機,可以使用 " +"p11_uri 告訴 p11_child 使用特定的讀卡機。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> #: sssd.conf.5.xml:1872 @@ -2248,6 +2502,8 @@ msgid "" "p11_uri = pkcs11:slot-description=My%20Smartcard%20Reader\n" " " msgstr "" +"p11_uri = pkcs11:slot-description=My%20Smartcard%20Reader\n" +" " #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> #: sssd.conf.5.xml:1876 @@ -2257,6 +2513,9 @@ msgid "" "pkcs11:library-description=OpenSC%20smartcard%20framework;slot-id=2\n" " " msgstr "" +"p11_uri = pkcs11:library-description=OpenSC%20smartcard%20framework;slot-" +"id=2\n" +" " #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1870 @@ -2266,45 +2525,49 @@ msgid "" "debug output of p11_child. As an alternative the GnuTLS utility 'p11tool' " "with e.g. the '--list-all' will show PKCS#11 URIs as well." msgstr "" +"範例:<placeholder type=\"programlisting\" id=\"0\"/> 或 <placeholder " +"type=\"programlisting\" id=\"1\"/> 若要尋找合適的 URI,請檢查 p11_child 的除" +"錯輸出。或者,GnuTLS 工具程式 'p11tool'(例如搭配 '--list-all')也會顯示 " +"PKCS#11 URI。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1889 msgid "pam_initgroups_scheme" -msgstr "" +msgstr "pam_initgroups_scheme" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:1897 msgid "always" -msgstr "" +msgstr "always" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1898 msgid "Always do an online lookup, please note that pam_id_timeout still applies" -msgstr "" +msgstr "一律執行線上查詢,請注意 pam_id_timeout 仍然適用" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:1902 msgid "no_session" -msgstr "" +msgstr "no_session" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1903 msgid "" "Only do an online lookup if there is no active session of the user, i.e. if " "the user is currently not logged in" -msgstr "" +msgstr "只有在使用者沒有作用中的工作階段(亦即使用者目前未登入)時才執行線上查詢" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:1908 msgid "never" -msgstr "" +msgstr "never" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1909 msgid "" "Never force an online lookup, use the data from the cache as long as they " "are not expired" -msgstr "" +msgstr "絕不強制執行線上查詢,只要快取中的資料尚未到期就使用它們" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1892 @@ -2314,30 +2577,33 @@ msgid "" "should be done and the following values are allowed: <placeholder " "type=\"variablelist\" id=\"0\"/>" msgstr "" +"PAM 回應器可以強制執行線上查詢,以取得嘗試登入之使用者目前的群組成員資格。此" +"選項控制何時應執行此動作,允許下列值:<placeholder type=\"variablelist\" " +"id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1916 msgid "Default: no_session" -msgstr "" +msgstr "預設:no_session" #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:1921 sssd.conf.5.xml:4350 msgid "pam_gssapi_services" -msgstr "" +msgstr "pam_gssapi_services" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1924 msgid "" "Comma separated list of PAM services that are allowed to try GSSAPI " "authentication using pam_sss_gss.so module." -msgstr "" +msgstr "允許使用 pam_sss_gss.so 模組嘗試 GSSAPI 驗證的 PAM 服務清單(以逗號分隔)。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1929 msgid "" "To disable GSSAPI authentication, set this option to <quote>-</quote> " "(dash)." -msgstr "" +msgstr "若要停用 GSSAPI 驗證,請將此選項設為 <quote>-</quote>(破折號)。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1933 sssd.conf.5.xml:1964 sssd.conf.5.xml:2002 @@ -2346,6 +2612,8 @@ msgid "" "[pam] section. It can also be set for trusted domain which overwrites the " "value in the domain section." msgstr "" +"注意:此選項也可以逐網域設定,會覆寫 [pam] 區段中的值。也可以為受信任網域設定" +",會覆寫網域區段中的值。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> #: sssd.conf.5.xml:1941 @@ -2354,21 +2622,23 @@ msgid "" "pam_gssapi_services = sudo, sudo-i\n" " " msgstr "" +"pam_gssapi_services = sudo, sudo-i\n" +" " #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1939 sssd.conf.5.xml:3913 msgid "Example: <placeholder type=\"programlisting\" id=\"0\"/>" -msgstr "" +msgstr "範例:<placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1945 msgid "Default: - (GSSAPI authentication is disabled)" -msgstr "" +msgstr "預設:-(GSSAPI 驗證已停用)" #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:1950 sssd.conf.5.xml:4351 msgid "pam_gssapi_check_upn" -msgstr "" +msgstr "pam_gssapi_check_upn" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1953 @@ -2377,18 +2647,20 @@ msgid "" "successfully authenticated through GSSAPI can be associated with the user " "who is being authenticated. Authentication will fail if the check fails." msgstr "" +"若為 True,SSSD 會要求透過 GSSAPI 成功驗證的 Kerberos 使用者主體可以與正在驗" +"證的使用者關聯。若檢查失敗,驗證會失敗。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1960 msgid "" "If False, every user that is able to obtained required service ticket will " "be authenticated." -msgstr "" +msgstr "若為 False,任何能夠取得所需服務票證的使用者都會被驗證。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1975 msgid "pam_gssapi_indicators_map" -msgstr "" +msgstr "pam_gssapi_indicators_map" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1978 @@ -2397,6 +2669,8 @@ msgid "" "a Kerberos ticket to access a PAM service that is allowed to try GSSAPI " "authentication using pam_sss_gss.so module." msgstr "" +"要存取允許使用 pam_sss_gss.so 模組嘗試 GSSAPI 驗證的 PAM 服務,Kerberos 票證" +"中必須包含的驗證指示器清單(以逗號分隔)。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1984 @@ -2412,6 +2686,13 @@ msgid "" "be denied. If the resulting list of indicators for the PAM service is empty, " "the check will not prevent the access." msgstr "" +"清單的每個元素可以是驗證指示器名稱,或 <quote>service:indicator</quote> 配對" +"。未加上 PAM 服務名稱前綴的指示器,會是存取任何設定搭配 <option>" +"pam_gssapi_services</option> 使用的 PAM 服務所必需的。接著,pam_sss_gss.so 會" +"在驗證期間,將每個 PAM 服務產生的指示器清單與 Kerberos 票證中的指示器比對。票" +"證中任何與該 PAM 服務產生之指示器清單相符的指示器都會授予存取權。若清單中的指" +"示器都沒有相符,則會拒絕存取。若該 PAM 服務產生的指示器清單為空,此檢查不會阻" +"止存取。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1997 @@ -2420,44 +2701,46 @@ msgid "" "<quote>-</quote> (dash). To disable the check for a specific PAM service, " "add <quote>service:-</quote>." msgstr "" +"若要停用 GSSAPI 驗證指示器檢查,請將此選項設為 <quote>-</quote>(破折號)。若" +"要為特定 PAM 服務停用檢查,請加入 <quote>service:-</quote>。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2008 msgid "" "Following authentication indicators are supported by IPA Kerberos " "deployments:" -msgstr "" +msgstr "IPA Kerberos 部署支援下列驗證指示器:" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:2011 msgid "" "pkinit -- pre-authentication using X.509 certificates -- whether stored in " "files or on smart cards." -msgstr "" +msgstr "pkinit -- 使用 X.509 憑證進行預先驗證(無論是儲存在檔案中或智慧卡上)。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:2014 msgid "" "hardened -- SPAKE pre-authentication or any pre-authentication wrapped in a " "FAST channel." -msgstr "" +msgstr "hardened -- SPAKE 預先驗證,或任何包裝在 FAST 通道中的預先驗證。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:2017 msgid "radius -- pre-authentication with the help of a RADIUS server." -msgstr "" +msgstr "radius -- 借助 RADIUS 伺服器的預先驗證。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:2020 msgid "" "otp -- pre-authentication using integrated two-factor authentication (2FA or " "one-time password, OTP) in IPA." -msgstr "" +msgstr "otp -- 在 IPA 中使用整合式雙重因素驗證(2FA 或一次性密碼,OTP)進行預先驗證。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:2023 msgid "idp -- pre-authentication using external identity provider." -msgstr "" +msgstr "idp -- 使用外部身分提供者的預先驗證。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> #: sssd.conf.5.xml:2033 @@ -2466,6 +2749,8 @@ msgid "" "pam_gssapi_indicators_map = sudo:pkinit, sudo-i:pkinit\n" " " msgstr "" +"pam_gssapi_indicators_map = sudo:pkinit, sudo-i:pkinit\n" +" " #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2028 @@ -2474,16 +2759,18 @@ msgid "" "their Kerberos tickets with a X.509 certificate pre-authentication (PKINIT), " "set <placeholder type=\"programlisting\" id=\"0\"/>" msgstr "" +"範例:若只要讓以 X.509 憑證預先驗證(PKINIT)取得 Kerberos 票證的使用者存取 " +"SUDO 服務,請設定 <placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2037 msgid "Default: not set (use of authentication indicators is not required)" -msgstr "" +msgstr "預設:未設定(不要求使用驗證指示器)" #. type: Content of: <reference><refentry><refsect1><refsect2><title> #: sssd.conf.5.xml:2045 msgid "SUDO configuration options" -msgstr "" +msgstr "SUDO 設定選項" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sssd.conf.5.xml:2047 @@ -2496,23 +2783,28 @@ msgid "" "<citerefentry> <refentrytitle>sssd-sudo</refentrytitle> " "<manvolnum>5</manvolnum> </citerefentry>." msgstr "" +"這些選項可用來設定 sudo 服務。<citerefentry> <refentrytitle>sudo</" +"refentrytitle> <manvolnum>8</manvolnum> </citerefentry> 與 <citerefentry> " +"<refentrytitle>sssd</refentrytitle> <manvolnum>8</manvolnum> </citerefentry> " +"搭配使用的詳細設定說明,請參閱手冊頁 <citerefentry> <refentrytitle>sssd-" +"sudo</refentrytitle> <manvolnum>5</manvolnum> </citerefentry>。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:2064 msgid "sudo_timed (bool)" -msgstr "" +msgstr "sudo_timed (bool)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2067 msgid "" "Whether or not to evaluate the sudoNotBefore and sudoNotAfter attributes " "that implement time-dependent sudoers entries." -msgstr "" +msgstr "是否評估實作時間相依 sudoers 項目的 sudoNotBefore 與 sudoNotAfter 屬性。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:2079 msgid "sudo_threshold (integer)" -msgstr "" +msgstr "sudo_threshold (integer)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2082 @@ -2524,21 +2816,25 @@ msgid "" "threshold number also applies to IPA sudo command and command group " "searches." msgstr "" +"一次可以重新整理的過期規則數目上限。若過期規則數目低於門檻值,這些規則會透過 " +"<quote>rules refresh</quote> 機制重新整理。若超過門檻值,則會改為觸發 sudo 規" +"則的 <quote>full refresh</quote>。此門檻值也適用於 IPA sudo 指令與指令群組搜" +"尋。" #. type: Content of: <reference><refentry><refsect1><refsect2><title> #: sssd.conf.5.xml:2101 msgid "AUTOFS configuration options" -msgstr "" +msgstr "AUTOFS 設定選項" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sssd.conf.5.xml:2103 msgid "These options can be used to configure the autofs service." -msgstr "" +msgstr "這些選項可用來設定 autofs 服務。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:2107 msgid "autofs_negative_timeout (integer)" -msgstr "" +msgstr "autofs_negative_timeout (integer)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2110 @@ -2547,50 +2843,52 @@ msgid "" "hits (that is, queries for invalid map entries, like nonexistent ones) " "before asking the back end again." msgstr "" +"指定 autofs 回應器在再次詢問後端之前,應該將負面快取命中(亦即對無效對應表項" +"目的查詢,例如不存在的項目)保留多少秒。" #. type: Content of: <reference><refentry><refsect1><refsect2><title> #: sssd.conf.5.xml:2126 msgid "SSH configuration options" -msgstr "" +msgstr "SSH 設定選項" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sssd.conf.5.xml:2128 msgid "These options can be used to configure the SSH service." -msgstr "" +msgstr "這些選項可用來設定 SSH 服務。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:2132 msgid "ssh_hash_known_hosts (bool)" -msgstr "" +msgstr "ssh_hash_known_hosts (bool)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2135 msgid "" "Whether or not to hash host names and addresses in the managed known_hosts " "file." -msgstr "" +msgstr "是否對受管理的 known_hosts 檔案中的主機名稱與位址進行雜湊。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:2144 msgid "ssh_known_hosts_timeout (integer)" -msgstr "" +msgstr "ssh_known_hosts_timeout (integer)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2147 msgid "" "How many seconds to keep a host in the managed known_hosts file after its " "host keys were requested." -msgstr "" +msgstr "主機金鑰被要求之後,將主機保留在受管理的 known_hosts 檔案中的秒數。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2151 msgid "Default: 180" -msgstr "" +msgstr "預設:180" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:2156 msgid "ssh_use_certificate_keys (bool)" -msgstr "" +msgstr "ssh_use_certificate_keys (bool)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2159 @@ -2601,11 +2899,15 @@ msgid "" "<refentrytitle>sss_ssh_authorizedkeys</refentrytitle> " "<manvolnum>1</manvolnum> </citerefentry> for details." msgstr "" +"若設為 true,<command>sss_ssh_authorizedkeys</command> 也會傳回從儲存在使用者" +"項目中之 X.509 憑證公開金鑰衍生的 ssh 金鑰。詳情請參閱 <citerefentry> " +"<refentrytitle>sss_ssh_authorizedkeys</refentrytitle> <manvolnum>1</" +"manvolnum> </citerefentry>。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:2174 msgid "ssh_use_certificate_matching_rules (string)" -msgstr "" +msgstr "ssh_use_certificate_matching_rules (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2177 @@ -2616,6 +2918,9 @@ msgid "" "comma separated list of mapping and matching rule names. All other rules " "will be ignored." msgstr "" +"依預設,ssh 回應器會使用所有可用的憑證比對規則來過濾憑證,因此 ssh 金鑰只會從" +"相符的憑證衍生。使用此選項可以透過以逗號分隔的對應與比對規則名稱清單限制使用" +"的規則。其他所有規則都會被忽略。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2186 @@ -2624,6 +2929,8 @@ msgid "" "all or no rules, respectively. The latter means that no certificates will be " "filtered out and ssh keys will be generated from all valid certificates." msgstr "" +"有兩個特殊關鍵字 'all_rules' 與 'no_rules',分別啟用所有規則或停用所有規則。" +"後者表示不會過濾掉任何憑證,且會從所有有效憑證產生 ssh 金鑰。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2193 @@ -2633,25 +2940,27 @@ msgid "" "the same behavior as for the PAM responder if certificate authentication is " "enabled." msgstr "" +"若未設定任何規則,使用 'all_rules' 會啟用預設規則,啟用所有適合用戶端驗證的憑" +"證。這與啟用憑證驗證時 PAM 回應器的行為相同。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2200 msgid "" "A non-existing rule name is considered an error. If as a result no rule is " "selected all certificates will be ignored." -msgstr "" +msgstr "不存在的規則名稱會被視為錯誤。若因此沒有選取任何規則,所有憑證都會被忽略。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2205 msgid "" "Default: not set, equivalent to 'all_rules', all found rules or the default " "rule are used" -msgstr "" +msgstr "預設:未設定,等同於 'all_rules',會使用所有找到的規則或預設規則" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:2211 msgid "ca_db (string)" -msgstr "" +msgstr "ca_db (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2214 @@ -2659,11 +2968,13 @@ msgid "" "Path to a storage of trusted CA certificates. The option is used to validate " "user certificates before deriving public ssh keys from them." msgstr "" +"受信任 CA 憑證儲存區的路徑。此選項用來在從使用者憑證衍生公開 ssh 金鑰之前驗證" +"這些憑證。" #. type: Content of: <reference><refentry><refsect1><refsect2><title> #: sssd.conf.5.xml:2234 msgid "PAC responder configuration options" -msgstr "" +msgstr "PAC 回應器設定選項" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sssd.conf.5.xml:2236 @@ -2675,6 +2986,10 @@ msgid "" "joined to and of remote trusted domains from the local domain controller. If " "the PAC is decoded and evaluated some of the following operations are done:" msgstr "" +"PAC 回應器與 MIT Kerberos sssd_pac_plugin.so 的授權資料外掛程式及子網域提供者" +"搭配運作。外掛程式會在 GSSAPI 驗證期間將 PAC 資料傳送給 PAC 回應器。子網域提" +"供者會從本機網域控制站收集用戶端所加入網域及遠端受信任網域的網域 SID 與 ID 範" +"圍。若 PAC 被解碼並評估,會執行下列部分作業:" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:2245 @@ -2686,23 +3001,26 @@ msgid "" "i.e. the system defaults are used, but can be overwritten with the " "default_shell parameter." msgstr "" +"若遠端使用者不存在於快取中,則會建立。UID 借助 SID 決定,受信任網域會有 UPG," +"且 GID 會與 UID 有相同的值。家目錄依 subdomain_homedir 參數設定。shell 依預設" +"為空,亦即使用系統預設值,但可以使用 default_shell 參數覆寫。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:2253 msgid "" "If there are SIDs of groups from domains sssd knows about, the user will be " "added to those groups." -msgstr "" +msgstr "若存在 sssd 所知網域的群組 SID,使用者會加入那些群組。" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sssd.conf.5.xml:2259 msgid "These options can be used to configure the PAC responder." -msgstr "" +msgstr "這些選項可用來設定 PAC 回應器。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.conf.5.xml:2263 sssd-ifp.5.xml:66 msgid "allowed_uids (string)" -msgstr "" +msgstr "allowed_uids (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2266 @@ -2711,18 +3029,20 @@ msgid "" "allowed to access the PAC responder. User names are resolved to UIDs at " "startup." msgstr "" +"指定允許存取 PAC 回應器的 UID 值或使用者名稱清單(以逗號分隔)。使用者名稱會" +"在啟動時解析為 UID。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2272 msgid "" "Default: 0, &sssd_user_name; (only root and SSSD service users are allowed " "to access the PAC responder)" -msgstr "" +msgstr "預設:0、&sssd_user_name;(只允許 root 與 SSSD 服務使用者存取 PAC 回應器)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2276 msgid "Default: 0 (only the root user is allowed to access the PAC responder)" -msgstr "" +msgstr "預設:0(只允許 root 使用者存取 PAC 回應器)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2280 @@ -2732,6 +3052,9 @@ msgid "" "responder, which would be the typical case, you have to add those to the " "list of allowed UIDs explicitly." msgstr "" +"請注意,設定此選項會覆寫預設值。若您仍然希望允許 root 與/或 " +"'&sssd_user_name;' 使用者存取 PAC 回應器(這是一般情況),您必須明確地將它們" +"加入允許的 UID 清單。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2287 @@ -2741,11 +3064,13 @@ msgid "" "access the PAC responder, which would be the typical case, you have to add 0 " "to the list of allowed UIDs as well." msgstr "" +"請注意,雖然預設使用 UID 0,設定此選項會覆寫它。若您仍然希望允許 root 使用者" +"存取 PAC 回應器(這是一般情況),您也必須將 0 加入允許的 UID 清單。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:2296 msgid "pac_lifetime (integer)" -msgstr "" +msgstr "pac_lifetime (integer)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2299 @@ -2753,11 +3078,13 @@ msgid "" "Lifetime of the PAC entry in seconds. As long as the PAC is valid the PAC " "data can be used to determine the group memberships of a user." msgstr "" +"PAC 項目的存留時間(秒)。只要 PAC 有效,就可以使用 PAC 資料判斷使用者的群組" +"成員資格。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:2309 msgid "pac_check (string)" -msgstr "" +msgstr "pac_check (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2312 @@ -2769,23 +3096,27 @@ msgid "" "the IPA and AD provider. If krb5_validate is set to 'False' the PAC checks " "will be skipped." msgstr "" +"若已設定,對 Active Directory 與 FreeIPA 網域中可用的 Kerberos 票證 PAC 套用" +"額外檢查。請注意,必須啟用 Kerberos 票證驗證才能檢查 PAC,亦即必須將 " +"krb5_validate 選項設為 'True',這是 IPA 與 AD 提供者的預設值。若 " +"krb5_validate 設為 'False',則會略過 PAC 檢查。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2326 msgid "no_check" -msgstr "" +msgstr "no_check" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2328 msgid "" "The PAC must not be present and even if it is present no additional checks " "will be done." -msgstr "" +msgstr "PAC 不得存在,即使存在也不會執行任何額外檢查。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2334 msgid "pac_present" -msgstr "" +msgstr "pac_present" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2336 @@ -2794,23 +3125,25 @@ msgid "" "the help of the user's TGT. If the PAC is not available the authentication " "will fail." msgstr "" +"SSSD 借助使用者的 TGT 要求的服務票證中必須存在 PAC。若 PAC 不可用,驗證會失敗" +"。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2344 msgid "check_upn" -msgstr "" +msgstr "check_upn" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2346 msgid "" "If the PAC is present check if the user principal name (UPN) information is " "consistent." -msgstr "" +msgstr "若 PAC 存在,檢查使用者主體名稱 (UPN) 資訊是否一致。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2352 msgid "check_upn_allow_missing" -msgstr "" +msgstr "check_upn_allow_missing" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2354 @@ -2823,6 +3156,10 @@ msgid "" "time and FreeIPA can handle enterprise principals just fine and there is no " "need anymore to set 'ldap_user_principal'." msgstr "" +"此選項應與 'check_upn' 一起使用,處理伺服器端設定了 UPN 但 SSSD 沒有讀取的情" +"況。典型的例子是 'ldap_user_principal' 設為不存在之屬性名稱的 FreeIPA 網域。" +"這通常是為了繞過企業主體處理上的問題。但這個問題早已修正,FreeIPA 可以正常處" +"理企業主體,不再需要設定 'ldap_user_principal'。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2366 @@ -2834,21 +3171,25 @@ msgid "" "can be removed. If this is not possible, removing 'check_upn' will skip the " "test and avoid the log message." msgstr "" +"目前此選項依預設啟用,以避免在這種環境中發生回歸。若在 PAC 中找到 UPN 但不在 " +"SSSD 的快取中,會將記錄訊息加入系統記錄檔與 SSSD 的除錯記錄檔。若要避免這則記" +"錄訊息,最好評估是否可以移除 'ldap_user_principal' 選項。若無法移除,移除 " +"'check_upn' 會略過測試並避免記錄訊息。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2380 msgid "upn_dns_info_present" -msgstr "" +msgstr "upn_dns_info_present" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2382 msgid "The PAC must contain the UPN-DNS-INFO buffer, implies 'check_upn'." -msgstr "" +msgstr "PAC 必須包含 UPN-DNS-INFO 緩衝區,隱含 'check_upn'。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2387 msgid "check_upn_dns_info_ex" -msgstr "" +msgstr "check_upn_dns_info_ex" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2389 @@ -2856,11 +3197,13 @@ msgid "" "If the PAC is present and the extension to the UPN-DNS-INFO buffer is " "available check if the information in the extension is consistent." msgstr "" +"若 PAC 存在且 UPN-DNS-INFO 緩衝區的延伸部分可用,檢查延伸部分中的資訊是否一致" +"。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2396 msgid "upn_dns_info_ex_present" -msgstr "" +msgstr "upn_dns_info_ex_present" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2398 @@ -2868,6 +3211,8 @@ msgid "" "The PAC must contain the extension of the UPN-DNS-INFO buffer, implies " "'check_upn_dns_info_ex', 'upn_dns_info_present' and 'check_upn'." msgstr "" +"PAC 必須包含 UPN-DNS-INFO 緩衝區的延伸部分,隱含 " +"'check_upn_dns_info_ex'、'upn_dns_info_present' 與 'check_upn'。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2322 @@ -2875,6 +3220,8 @@ msgid "" "The following options can be used alone or in a comma-separated list: " "<placeholder type=\"variablelist\" id=\"0\"/>" msgstr "" +"下列選項可以單獨使用,或用在逗號分隔的清單中:<placeholder " +"type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2408 @@ -2882,11 +3229,13 @@ msgid "" "Default: no_check (AD and IPA provider 'check_upn, check_upn_allow_missing, " "check_upn_dns_info_ex')" msgstr "" +"預設:no_check(AD 與 IPA 提供者為 'check_upn、check_upn_allow_missing、" +"check_upn_dns_info_ex')" #. type: Content of: <reference><refentry><refsect1><refsect2><title> #: sssd.conf.5.xml:2417 msgid "Session recording configuration options" -msgstr "" +msgstr "工作階段錄製設定選項" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sssd.conf.5.xml:2419 @@ -2898,31 +3247,36 @@ msgid "" "<refentrytitle>sssd-session-recording</refentrytitle> " "<manvolnum>5</manvolnum> </citerefentry>." msgstr "" +"工作階段錄製與 tlog 套件的一部分 <citerefentry> <refentrytitle>tlog-rec-" +"session</refentrytitle> <manvolnum>8</manvolnum> </citerefentry> 搭配運作,記" +"錄使用者在文字終端機登入時看到與輸入的內容。另請參閱 <citerefentry> " +"<refentrytitle>sssd-session-recording</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry>。" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sssd.conf.5.xml:2432 msgid "These options can be used to configure session recording." -msgstr "" +msgstr "這些選項可用來設定工作階段錄製。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.conf.5.xml:2436 sssd-session-recording.5.xml:64 msgid "scope (string)" -msgstr "" +msgstr "scope (string)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2443 sssd-session-recording.5.xml:71 msgid "\"none\"" -msgstr "" +msgstr "\"none\"" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2446 sssd-session-recording.5.xml:74 msgid "No users are recorded." -msgstr "" +msgstr "不錄製任何使用者。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2451 sssd-session-recording.5.xml:79 msgid "\"some\"" -msgstr "" +msgstr "\"some\"" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2454 sssd-session-recording.5.xml:82 @@ -2930,16 +3284,18 @@ msgid "" "Users/groups specified by <replaceable>users</replaceable> and " "<replaceable>groups</replaceable> options are recorded." msgstr "" +"會錄製 <replaceable>users</replaceable> 與 <replaceable>groups</replaceable> " +"選項指定的使用者/群組。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2463 sssd-session-recording.5.xml:91 msgid "\"all\"" -msgstr "" +msgstr "\"all\"" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2466 sssd-session-recording.5.xml:94 msgid "All users are recorded." -msgstr "" +msgstr "錄製所有使用者。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2439 sssd-session-recording.5.xml:67 @@ -2947,16 +3303,18 @@ msgid "" "One of the following strings specifying the scope of session recording: " "<placeholder type=\"variablelist\" id=\"0\"/>" msgstr "" +"下列其中一個字串,指定工作階段錄製的範圍:<placeholder type=\"variablelist\" " +"id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2473 sssd-session-recording.5.xml:101 msgid "Default: \"none\"" -msgstr "" +msgstr "預設:\"none\"" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.conf.5.xml:2478 sssd-session-recording.5.xml:106 msgid "users (string)" -msgstr "" +msgstr "users (string)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2481 sssd-session-recording.5.xml:109 @@ -2965,16 +3323,18 @@ msgid "" "enabled. Matches user names as returned by NSS. I.e. after the possible " "space replacement, case changes, etc." msgstr "" +"應啟用工作階段錄製的使用者清單,以逗號分隔。比對 NSS 回傳的使用者名稱,亦即經" +"過可能的空格取代、大小寫變更等處理之後的名稱。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2487 sssd-session-recording.5.xml:115 msgid "Default: Empty. Matches no users." -msgstr "" +msgstr "預設:空。不匹配任何使用者。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.conf.5.xml:2492 sssd-session-recording.5.xml:120 msgid "groups (string)" -msgstr "" +msgstr "groups (string)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2495 sssd-session-recording.5.xml:123 @@ -2983,6 +3343,8 @@ msgid "" "recording enabled. Matches group names as returned by NSS. I.e. after the " "possible space replacement, case changes, etc." msgstr "" +"成員應啟用工作階段錄製的群組清單,以逗號分隔。比對 NSS 回傳的群組名稱,亦即經" +"過可能的空格取代、大小寫變更等處理之後的名稱。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2501 sssd.conf.5.xml:2533 sssd-session-recording.5.xml:129 @@ -2992,56 +3354,58 @@ msgid "" "performance cost, because each uncached request for a user requires " "retrieving and matching the groups the user is member of." msgstr "" +"注意:使用此選項(將其設為任何值)會有可觀的效能成本,因為每個未快取的使用者" +"要求都需要取回並比對使用者所屬的群組。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2508 sssd-session-recording.5.xml:136 msgid "Default: Empty. Matches no groups." -msgstr "" +msgstr "預設:空。不匹配任何群組。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.conf.5.xml:2513 sssd-session-recording.5.xml:141 msgid "exclude_users (string)" -msgstr "" +msgstr "exclude_users (string)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2516 sssd-session-recording.5.xml:144 msgid "" "A comma-separated list of users to be excluded from recording, only " "applicable with 'scope=all'." -msgstr "" +msgstr "要從錄製中排除的使用者清單(以逗號分隔),只適用於 'scope=all'。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2520 sssd-session-recording.5.xml:148 msgid "Default: Empty. No users excluded." -msgstr "" +msgstr "預設:空。不排除任何使用者。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.conf.5.xml:2525 sssd-session-recording.5.xml:153 msgid "exclude_groups (string)" -msgstr "" +msgstr "exclude_groups (string)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2528 sssd-session-recording.5.xml:156 msgid "" "A comma-separated list of groups, members of which should be excluded from " "recording. Only applicable with 'scope=all'." -msgstr "" +msgstr "成員應從錄製中排除的群組清單(以逗號分隔)。只適用於 'scope=all'。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2540 sssd-session-recording.5.xml:168 msgid "Default: Empty. No groups excluded." -msgstr "" +msgstr "預設:空。不排除任何群組。" #. type: Content of: <reference><refentry><refsect1><title> #: sssd.conf.5.xml:2550 msgid "DOMAIN SECTIONS" -msgstr "" +msgstr "DOMAIN 區段" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry><para> #: sssd.conf.5.xml:2557 sssd.conf.5.xml:4041 sssd.conf.5.xml:4042 #: sssd.conf.5.xml:4045 msgid "enabled" -msgstr "" +msgstr "enabled" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2560 @@ -3052,11 +3416,14 @@ msgid "" "enabled only if it is listed in the domains option in the " "<quote>[sssd]</quote> section." msgstr "" +"明確地啟用或停用網域。若為 <quote>true</quote>,網域一律<quote>啟用</quote>。" +"若為 <quote>false</quote>,網域一律<quote>停用</quote>。若未設定此選項,只有" +"當網域列在 <quote>[sssd]</quote> 區段的 domains 選項中時才會啟用。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2572 msgid "domain_type (string)" -msgstr "" +msgstr "domain_type (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2575 @@ -3066,13 +3433,16 @@ msgid "" "be present or generated. Only objects from POSIX domains are available to " "the operating system interfaces and utilities." msgstr "" +"指定網域是要供了解 POSIX 的用戶端(例如名稱服務切換)使用,還是供不需要存在或" +"產生 POSIX 資料的應用程式使用。只有 POSIX 網域的物件可供作業系統介面與工具程" +"式使用。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2583 msgid "" "Allowed values for this option are <quote>posix</quote> and " "<quote>application</quote>." -msgstr "" +msgstr "此選項允許的值為 <quote>posix</quote> 與 <quote>application</quote>。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2587 @@ -3082,37 +3452,40 @@ msgid "" "<refentrytitle>sssd-ifp</refentrytitle> <manvolnum>5</manvolnum> " "</citerefentry>) and the PAM responder." msgstr "" +"所有服務都可以連線 POSIX 網域。Application 網域只能從 InfoPipe 回應器(詳情請" +"參閱 <citerefentry> <refentrytitle>sssd-ifp</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry>)與 PAM 回應器連線。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2595 msgid "" "NOTE: The application domains are currently well tested with " "<quote>id_provider=ldap</quote> only." -msgstr "" +msgstr "注意:application 網域目前只與 <quote>id_provider=ldap</quote> 做了完整測試。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2599 msgid "" "For an easy way to configure a non-POSIX domains, please see the " "<quote>Application domains</quote> section." -msgstr "" +msgstr "若要簡單地設定非 POSIX 網域,請參閱 <quote>Application domains</quote> 一節。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2603 msgid "Default: posix" -msgstr "" +msgstr "預設:posix" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2609 msgid "min_id,max_id (integer)" -msgstr "" +msgstr "min_id,max_id (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2612 msgid "" "UID and GID limits for the domain. If a domain contains an entry that is " "outside these limits, it is ignored." -msgstr "" +msgstr "網域的 UID 與 GID 限制。若網域包含超出這些限制的項目,該項目會被忽略。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2617 @@ -3122,23 +3495,25 @@ msgid "" "non-primary group memberships, those that are in range will be reported as " "expected." msgstr "" +"對使用者而言,這會影響主要 GID 的限制。若 UID 或主要 GID 任一超出範圍,該使用" +"者就不會傳回給 NSS。對於非主要的群組成員資格,範圍內的成員資格會如預期回報。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2624 msgid "" "These ID limits affect even saving entries to cache, not only returning them " "by name or ID." -msgstr "" +msgstr "這些 ID 限制甚至會影響項目儲存到快取,而不只是依名稱或 ID 傳回項目。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2628 msgid "Default: 1 for min_id, 0 (no limit) for max_id" -msgstr "" +msgstr "預設:min_id 為 1,max_id 為 0(無限制)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2634 msgid "enumerate (bool)" -msgstr "" +msgstr "enumerate (bool)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2637 @@ -3148,35 +3523,37 @@ msgid "" "enable enumeration in order for secondary groups to be displayed. This " "parameter can have one of the following values:" msgstr "" +"決定網域是否可以被列舉,亦即網域是否可以列出其包含的所有使用者與群組。請注意" +",要顯示次要群組不需要啟用列舉。此參數可以有下列其中一個值:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2645 msgid "TRUE = Users and groups are enumerated" -msgstr "" +msgstr "TRUE = 列舉使用者與群組" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2648 msgid "FALSE = No enumerations for this domain" -msgstr "" +msgstr "FALSE = 不列舉此網域" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2651 sssd.conf.5.xml:2942 sssd.conf.5.xml:3119 msgid "Default: FALSE" -msgstr "" +msgstr "預設:FALSE" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2654 msgid "" "Enumerating a domain requires SSSD to download and store ALL user and group " "entries from the remote server." -msgstr "" +msgstr "列舉網域需要 SSSD 從遠端伺服器下載並儲存所有使用者與群組項目。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2659 msgid "" "Feature is only supported for domains with id_provider = ldap or id_provider " "= proxy." -msgstr "" +msgstr "此功能只支援 id_provider = ldap 或 id_provider = proxy 的網域。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2663 @@ -3191,6 +3568,11 @@ msgid "" "<quote>sssd_be</quote> process becoming unresponsive or even restarted by " "the internal watchdog." msgstr "" +"注意:啟用列舉會在列舉執行期間對 SSSD 造成嚴重的效能影響。SSSD 啟動後可能需要" +"數分鐘才能完整完成列舉。在此期間,個別的資訊要求會直接送到 LDAP,但由於列舉處" +"理負擔沉重,可能會很慢。列舉完成後將大量項目儲存到快取也可能耗費大量 CPU,因" +"為必須重新計算成員資格。這可能導致 <quote>sssd_be</quote> 程序無回應,甚至被" +"內部看門狗重新啟動。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2678 @@ -3198,6 +3580,8 @@ msgid "" "While the first enumeration is running, requests for the complete user or " "group lists may return no results until it completes." msgstr "" +"第一次列舉執行期間,要求完整使用者或群組清單可能不會傳回任何結果,直到列舉完" +"成。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2683 @@ -3207,13 +3591,15 @@ msgid "" "enumeration lookups are completed successfully. For more information, refer " "to the man pages for the specific id_provider in use." msgstr "" +"此外,啟用列舉可能會增加偵測網路斷線所需的時間,因為需要較長的逾時來確保列舉" +"查詢成功完成。更多資訊請參閱所使用 id_provider 的手冊頁。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2691 msgid "" "For the reasons cited above, enabling enumeration is not recommended, " "especially in large environments." -msgstr "" +msgstr "基於上述原因,不建議啟用列舉,尤其是在大型環境中。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2696 @@ -3222,31 +3608,33 @@ msgid "" "'libnss_files' and 'libnss_ldap'. 3rd party modules must follow the " "documented behavior of nss modules to be used in this configuration." msgstr "" +"注意:proxy 提供者已與 'libnss_files' 與 'libnss_ldap' 等開放原始碼模組測試。" +"協力廠商模組必須遵循 nss 模組記載的行為,才能用於此設定。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2705 msgid "subdomain_enumerate (string)" -msgstr "" +msgstr "subdomain_enumerate (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2712 msgid "all" -msgstr "" +msgstr "all" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2713 msgid "All discovered trusted domains will be enumerated" -msgstr "" +msgstr "所有探索到的受信任網域都會被列舉" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2716 msgid "none" -msgstr "" +msgstr "none" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2717 msgid "No discovered trusted domains will be enumerated" -msgstr "" +msgstr "不會列舉任何探索到的受信任網域" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2708 @@ -3256,18 +3644,21 @@ msgid "" "Optionally, a list of one or more domain names can enable enumeration just " "for these trusted domains." msgstr "" +"是否應列舉任何自動偵測到的受信任網域。支援的值有:<placeholder " +"type=\"variablelist\" id=\"0\"/> 也可以選擇性地提供一個或多個網域名稱的清單," +"只為這些受信任網域啟用列舉。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2731 msgid "entry_cache_timeout (integer)" -msgstr "" +msgstr "entry_cache_timeout (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2734 msgid "" "How many seconds should nss_sss consider entries valid before asking the " "backend again" -msgstr "" +msgstr "nss_sss 在再次詢問後端之前,應該將項目視為有效的秒數" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2738 @@ -3279,131 +3670,135 @@ msgid "" "</citerefentry> tool in order to force refresh of entries that have already " "been cached." msgstr "" +"快取到期時間戳記會儲存為快取中各個物件的屬性。因此,變更快取逾時只對新加入或" +"已到期的項目有效。您應該執行 <citerefentry> <refentrytitle>sss_cache</" +"refentrytitle> <manvolnum>8</manvolnum> </citerefentry> 工具,以強制重新整理" +"已快取的項目。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2751 msgid "Default: 5400" -msgstr "" +msgstr "預設:5400" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2757 msgid "entry_cache_user_timeout (integer)" -msgstr "" +msgstr "entry_cache_user_timeout (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2760 msgid "" "How many seconds should nss_sss consider user entries valid before asking " "the backend again" -msgstr "" +msgstr "nss_sss 在再次詢問後端之前,應該將使用者項目視為有效的秒數" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2764 sssd.conf.5.xml:2777 sssd.conf.5.xml:2790 #: sssd.conf.5.xml:2803 sssd.conf.5.xml:2817 sssd.conf.5.xml:2830 #: sssd.conf.5.xml:2844 sssd.conf.5.xml:2858 sssd.conf.5.xml:2871 msgid "Default: entry_cache_timeout" -msgstr "" +msgstr "預設:entry_cache_timeout" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2770 msgid "entry_cache_group_timeout (integer)" -msgstr "" +msgstr "entry_cache_group_timeout (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2773 msgid "" "How many seconds should nss_sss consider group entries valid before asking " "the backend again" -msgstr "" +msgstr "nss_sss 在再次詢問後端之前,應該將群組項目視為有效的秒數" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2783 msgid "entry_cache_netgroup_timeout (integer)" -msgstr "" +msgstr "entry_cache_netgroup_timeout (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2786 msgid "" "How many seconds should nss_sss consider netgroup entries valid before " "asking the backend again" -msgstr "" +msgstr "nss_sss 在再次詢問後端之前,應該將網路群組項目視為有效的秒數" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2796 msgid "entry_cache_service_timeout (integer)" -msgstr "" +msgstr "entry_cache_service_timeout (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2799 msgid "" "How many seconds should nss_sss consider service entries valid before asking " "the backend again" -msgstr "" +msgstr "nss_sss 在再次詢問後端之前,應該將服務項目視為有效的秒數" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2809 msgid "entry_cache_resolver_timeout (integer)" -msgstr "" +msgstr "entry_cache_resolver_timeout (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2812 msgid "" "How many seconds should nss_sss consider hosts and networks entries valid " "before asking the backend again" -msgstr "" +msgstr "nss_sss 在再次詢問後端之前,應該將主機與網路項目視為有效的秒數" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2823 msgid "entry_cache_sudo_timeout (integer)" -msgstr "" +msgstr "entry_cache_sudo_timeout (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2826 msgid "" "How many seconds should sudo consider rules valid before asking the backend " "again" -msgstr "" +msgstr "sudo 在再次詢問後端之前,應該將規則視為有效的秒數" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2836 msgid "entry_cache_autofs_timeout (integer)" -msgstr "" +msgstr "entry_cache_autofs_timeout (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2839 msgid "" "How many seconds should the autofs service consider automounter maps valid " "before asking the backend again" -msgstr "" +msgstr "autofs 服務在再次詢問後端之前,應該將自動掛載對應表視為有效的秒數" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2850 msgid "entry_cache_ssh_host_timeout (integer)" -msgstr "" +msgstr "entry_cache_ssh_host_timeout (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2853 msgid "" "How many seconds to keep a host ssh key after refresh. IE how long to cache " "the host key for." -msgstr "" +msgstr "重新整理後保留主機 ssh 金鑰的秒數。亦即主機金鑰的快取時間。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2864 msgid "entry_cache_computer_timeout (integer)" -msgstr "" +msgstr "entry_cache_computer_timeout (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2867 msgid "" "How many seconds to keep the local computer entry before asking the backend " "again" -msgstr "" +msgstr "在再次詢問後端之前,保留本機電腦項目的秒數" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2877 msgid "refresh_expired_interval (integer)" -msgstr "" +msgstr "refresh_expired_interval (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2880 @@ -3411,6 +3806,8 @@ msgid "" "Specifies how many seconds SSSD has to wait before triggering a background " "refresh task which will refresh all expired or nearly expired records." msgstr "" +"指定 SSSD 在觸發背景重新整理工作之前必須等待的秒數,該工作會重新整理所有已到" +"期或即將到期的記錄。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2885 @@ -3420,16 +3817,19 @@ msgid "" "user, typically ran at login) operation in the past, both the user entry " "and the group membership are updated." msgstr "" +"背景重新整理會處理快取中的使用者、群組與網路群組。對於過去執行過 initgroups(" +"取得使用者的群組成員資格,通常在登入時執行)作業的使用者,使用者項目與群組成" +"員資格都會更新。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2893 msgid "This option is automatically inherited for all trusted domains." -msgstr "" +msgstr "此選項會自動繼承到所有受信任網域。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2897 msgid "You can consider setting this value to 3/4 * entry_cache_timeout." -msgstr "" +msgstr "您可以考慮將此值設為 entry_cache_timeout 的 3/4。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2901 @@ -3442,17 +3842,21 @@ msgid "" "offline mode operation and reuse of existing valid cache entries. To make " "this change instant the user may want to manually invalidate existing cache." msgstr "" +"快取逾時已過 2/3 時,背景工作會重新整理快取項目。若已有快取項目,背景工作會參" +"照它們原本的快取逾時值,而不是目前的設定值。這可能導致背景重新整理工作看起來" +"沒有作用的情況。這是刻意設計,目的是改善離線模式運作並重複使用現有的有效快取" +"項目。若要讓此變更立即生效,使用者可能想要手動使現有快取失效。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2914 sssd-ldap.5.xml:361 sssd-ldap.5.xml:1774 #: sssd-ipa.5.xml:270 msgid "Default: 0 (disabled)" -msgstr "" +msgstr "預設:0(停用)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2920 msgid "cache_credentials (bool)" -msgstr "" +msgstr "cache_credentials (bool)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2923 @@ -3464,6 +3868,9 @@ msgid "" "offline as long as a successful online authentication is recorded in the " "cache without additional configuration." msgstr "" +"決定使用者憑證是否也快取在本機 LDB 快取中。快取的憑證指密碼,包含雙重因素驗證" +"的第一(長期)因素,不包含其他驗證機制。只要快取中記錄了成功的線上驗證," +"Passkey 與智慧卡驗證預期可以在沒有額外設定的情況下離線運作。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2934 @@ -3473,11 +3880,13 @@ msgid "" "get access to a cache file (normally requires privileged access) and to " "break a password using brute force attack." msgstr "" +"請注意,雖然憑證以加鹽的 SHA512 雜湊儲存,若攻擊者設法取得快取檔案的存取權(" +"通常需要特權存取)並以暴力破解攻擊破解密碼,這仍然可能構成一些安全風險。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2948 msgid "cache_credentials_minimal_first_factor_length (int)" -msgstr "" +msgstr "cache_credentials_minimal_first_factor_length (int)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2951 @@ -3486,6 +3895,8 @@ msgid "" "this value determines the minimal length the first authentication factor " "(long term password) must have to be saved as SHA512 hash into the cache." msgstr "" +"若使用雙因素認證 (2FA) 且應儲存憑證,此值決定第一個認證因素(長期密碼)要存入" +"快取作為 SHA512 雜湊所需的最短長度。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2958 @@ -3493,11 +3904,13 @@ msgid "" "This should avoid that the short PINs of a PIN based 2FA scheme are saved in " "the cache which would make them easy targets for brute-force attacks." msgstr "" +"這可以避免以 PIN 為基礎之 2FA 方案的短 PIN 被儲存到快取中,因為那會讓它們成為" +"暴力破解攻擊的容易目標。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2969 msgid "account_cache_expiration (integer)" -msgstr "" +msgstr "account_cache_expiration (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2972 @@ -3507,16 +3920,18 @@ msgid "" "value of this parameter must be greater than or equal to " "offline_credentials_expiration." msgstr "" +"在最後一次成功登入後,項目留在快取中、直到快取清理時被移除的天數。0 表示永久" +"保留。此參數的值必須大於或等於 offline_credentials_expiration。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2979 msgid "Default: 0 (unlimited)" -msgstr "" +msgstr "預設:0(無限制)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2984 msgid "pwd_expiration_warning (integer)" -msgstr "" +msgstr "pwd_expiration_warning (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2995 @@ -3526,28 +3941,30 @@ msgid "" "cannot display a warning. Also an auth provider has to be configured for the " "backend." msgstr "" +"請注意,後端伺服器必須提供密碼到期時間的資訊。若缺少此資訊,sssd 無法顯示警告" +"。後端也必須設定 auth 提供者。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3002 msgid "Default: 7 (Kerberos), 0 (LDAP)" -msgstr "" +msgstr "預設:7(Kerberos),0(LDAP)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3008 msgid "id_provider (string)" -msgstr "" +msgstr "id_provider (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3011 msgid "" "The identification provider used for the domain. Supported ID providers " "are:" -msgstr "" +msgstr "網域使用的身分提供者。支援的 ID 提供者有:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3015 msgid "<quote>proxy</quote>: Support a legacy NSS provider." -msgstr "" +msgstr "<quote>proxy</quote>:支援傳統的 NSS 提供者。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3018 @@ -3557,6 +3974,9 @@ msgid "" "</citerefentry> for more information on how to mirror local users and groups " "into SSSD." msgstr "" +"<quote>files</quote>:FILES 提供者。如何將本機使用者與群組鏡像到 SSSD 的更多" +"資訊,請參閱 <citerefentry> <refentrytitle>sssd-files</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry>。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3026 @@ -3565,6 +3985,9 @@ msgid "" "<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> " "</citerefentry> for more information on configuring LDAP." msgstr "" +"<quote>ldap</quote>:LDAP 提供者。設定 LDAP 的更多資訊,請參閱 " +"<citerefentry> <refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry>。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3034 sssd.conf.5.xml:3145 sssd.conf.5.xml:3196 @@ -3575,6 +3998,9 @@ msgid "" "<manvolnum>5</manvolnum> </citerefentry> for more information on configuring " "FreeIPA." msgstr "" +"<quote>ipa</quote>:FreeIPA 與 Red Hat Identity Management 提供者。設定 " +"FreeIPA 的更多資訊,請參閱 <citerefentry> <refentrytitle>sssd-ipa</" +"refentrytitle> <manvolnum>5</manvolnum> </citerefentry>。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3043 sssd.conf.5.xml:3154 sssd.conf.5.xml:3205 @@ -3584,11 +4010,14 @@ msgid "" "<refentrytitle>sssd-ad</refentrytitle> <manvolnum>5</manvolnum> " "</citerefentry> for more information on configuring Active Directory." msgstr "" +"<quote>ad</quote>:Active Directory 提供者。設定 Active Directory 的更多資訊" +",請參閱 <citerefentry> <refentrytitle>sssd-ad</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry>。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3054 msgid "use_fully_qualified_names (bool)" -msgstr "" +msgstr "use_fully_qualified_names (bool)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3057 @@ -3596,6 +4025,8 @@ msgid "" "Use the full name and domain (as formatted by the domain's full_name_format) " "as the user's login name reported to NSS." msgstr "" +"使用完整名稱與網域(依網域的 full_name_format 格式化)作為回報給 NSS 的使用者" +"登入名稱。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3062 @@ -3605,6 +4036,9 @@ msgid "" "<command>getent passwd test</command> wouldn't find the user while " "<command>getent passwd test@LOCAL</command> would." msgstr "" +"若設為 TRUE,對此網域的所有要求都必須使用完整名稱。例如,若用於包含 \"test\" " +"使用者的 LOCAL 網域,<command>getent passwd test</command> 找不到該使用者," +"而 <command>getent passwd test@LOCAL</command> 可以。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3070 @@ -3613,23 +4047,25 @@ msgid "" "include nested netgroups without qualified names. For netgroups, all domains " "will be searched when an unqualified name is requested." msgstr "" +"注意:此選項對網路群組查詢沒有效果,因為網路群組往往包含沒有完整名稱的巢狀網" +"路群組。對網路群組而言,要求未限定名稱時會搜尋所有網域。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3077 msgid "" "Default: FALSE (TRUE for trusted domain/sub-domains or if " "default_domain_suffix is used)" -msgstr "" +msgstr "預設:FALSE(受信任網域/子網域或使用 default_domain_suffix 時為 TRUE)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3084 msgid "ignore_group_members (bool)" -msgstr "" +msgstr "ignore_group_members (bool)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3087 msgid "Do not return group members for group lookups." -msgstr "" +msgstr "群組查詢不傳回群組成員。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3090 @@ -3642,6 +4078,12 @@ msgid "" "</citerefentry>. As an effect, <quote>getent group $groupname</quote> would " "return the requested group as if it was empty." msgstr "" +"若設為 TRUE,不會向 ldap 伺服器要求群組成員資格屬性,處理群組查詢呼叫(例如 " +"<citerefentry> <refentrytitle>getgrnam</refentrytitle> <manvolnum>3</" +"manvolnum> </citerefentry> 或 <citerefentry> <refentrytitle>getgrgid</" +"refentrytitle> <manvolnum>3</manvolnum> </citerefentry>)時也不會傳回群組成員" +"。結果是 <quote>getent group $groupname</quote> 會傳回所要求的群組,彷彿它是" +"空的。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3108 @@ -3650,6 +4092,8 @@ msgid "" "membership significantly faster, especially for groups containing many " "members." msgstr "" +"啟用此選項也可以讓 access 提供者的群組成員資格檢查明顯更快,尤其是成員眾多的" +"群組。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3114 sssd.conf.5.xml:3835 sssd-ldap.5.xml:327 @@ -3661,18 +4105,20 @@ msgid "" "This option can be also set per subdomain or inherited via " "<emphasis>subdomain_inherit</emphasis>." msgstr "" +"此選項也可以逐子網域設定,或透過 <emphasis>subdomain_inherit</emphasis> 繼承" +"。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3124 msgid "auth_provider (string)" -msgstr "" +msgstr "auth_provider (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3127 msgid "" "The authentication provider used for the domain. Supported auth providers " "are:" -msgstr "" +msgstr "網域使用的驗證提供者。支援的 auth 提供者有:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3131 sssd.conf.5.xml:3189 @@ -3681,6 +4127,9 @@ msgid "" "<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> " "</citerefentry> for more information on configuring LDAP." msgstr "" +"<quote>ldap</quote>:用於原生 LDAP 驗證。設定 LDAP 的更多資訊,請參閱 " +"<citerefentry> <refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry>。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3138 @@ -3689,28 +4138,31 @@ msgid "" "<refentrytitle>sssd-krb5</refentrytitle> <manvolnum>5</manvolnum> " "</citerefentry> for more information on configuring Kerberos." msgstr "" +"<quote>krb5</quote>:用於 Kerberos 驗證。設定 Kerberos 的更多資訊,請參閱 " +"<citerefentry> <refentrytitle>sssd-krb5</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry>。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3162 msgid "<quote>proxy</quote> for relaying authentication to some other PAM target." -msgstr "" +msgstr "<quote>proxy</quote>:將驗證轉送給其他 PAM 目標。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3165 msgid "<quote>none</quote> disables authentication explicitly." -msgstr "" +msgstr "<quote>none</quote>:明確地停用驗證。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3168 msgid "" "Default: <quote>id_provider</quote> is used if it is set and can handle " "authentication requests." -msgstr "" +msgstr "預設:若已設定 <quote>id_provider</quote> 且可以處理驗證要求,則使用它。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3174 msgid "access_provider (string)" -msgstr "" +msgstr "access_provider (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3177 @@ -3719,18 +4171,20 @@ msgid "" "access providers (in addition to any included in installed backends) " "Internal special providers are:" msgstr "" +"網域使用的存取控制提供者。有兩個內建的 access 提供者(除了已安裝後端中包含的" +"以外)。內部的特殊提供者有:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3183 msgid "" "<quote>permit</quote> always allow access. It's the only permitted access " "provider for a local domain." -msgstr "" +msgstr "<quote>permit</quote>:一律允許存取。這是本機網域唯一允許的 access 提供者。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3186 msgid "<quote>deny</quote> always deny access." -msgstr "" +msgstr "<quote>deny</quote>:一律拒絕存取。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3213 @@ -3740,6 +4194,9 @@ msgid "" "<manvolnum>5</manvolnum></citerefentry> for more information on configuring " "the simple access module." msgstr "" +"<quote>simple</quote>:以允許或拒絕清單為基礎的存取控制。設定 simple access " +"模組的更多資訊,請參閱 <citerefentry> <refentrytitle>sssd-simple</" +"refentrytitle> <manvolnum>5</manvolnum></citerefentry>。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3220 @@ -3749,28 +4206,31 @@ msgid "" "<manvolnum>5</manvolnum></citerefentry> for more information on configuring " "Kerberos." msgstr "" +"<quote>krb5</quote>:以 .k5login 為基礎的存取控制。設定 Kerberos 的更多資訊," +"請參閱 <citerefentry> <refentrytitle>sssd-krb5</refentrytitle> <manvolnum>5</" +"manvolnum></citerefentry>。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3227 msgid "<quote>proxy</quote> for relaying access control to another PAM module." -msgstr "" +msgstr "<quote>proxy</quote>:將存取控制轉送給另一個 PAM 模組。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3230 msgid "Default: <quote>permit</quote>" -msgstr "" +msgstr "預設:<quote>permit</quote>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3235 msgid "chpass_provider (string)" -msgstr "" +msgstr "chpass_provider (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3238 msgid "" "The provider which should handle change password operations for the domain. " "Supported change password providers are:" -msgstr "" +msgstr "應處理網域變更密碼作業的提供者。支援的變更密碼提供者有:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3243 @@ -3780,6 +4240,9 @@ msgid "" "<manvolnum>5</manvolnum> </citerefentry> for more information on configuring " "LDAP." msgstr "" +"<quote>ldap</quote>:變更儲存在 LDAP 伺服器中的密碼。設定 LDAP 的更多資訊,請" +"參閱 <citerefentry> <refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry>。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3251 @@ -3788,16 +4251,19 @@ msgid "" "<refentrytitle>sssd-krb5</refentrytitle> <manvolnum>5</manvolnum> " "</citerefentry> for more information on configuring Kerberos." msgstr "" +"<quote>krb5</quote>:變更 Kerberos 密碼。設定 Kerberos 的更多資訊,請參閱 " +"<citerefentry> <refentrytitle>sssd-krb5</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry>。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3276 msgid "<quote>proxy</quote> for relaying password changes to some other PAM target." -msgstr "" +msgstr "<quote>proxy</quote>:將密碼變更轉送給其他 PAM 目標。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3280 msgid "<quote>none</quote> disallows password changes explicitly." -msgstr "" +msgstr "<quote>none</quote>:明確地禁止變更密碼。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3283 @@ -3805,16 +4271,18 @@ msgid "" "Default: <quote>auth_provider</quote> is used if it is set and can handle " "change password requests." msgstr "" +"預設:若已設定 <quote>auth_provider</quote> 且可以處理變更密碼要求,則使用它" +"。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3290 msgid "sudo_provider (string)" -msgstr "" +msgstr "sudo_provider (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3293 msgid "The SUDO provider used for the domain. Supported SUDO providers are:" -msgstr "" +msgstr "網域使用的 SUDO 提供者。支援的 SUDO 提供者有:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3297 @@ -3823,31 +4291,34 @@ msgid "" "<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> " "</citerefentry> for more information on configuring LDAP." msgstr "" +"<quote>ldap</quote>:規則儲存在 LDAP 中。設定 LDAP 的更多資訊,請參閱 " +"<citerefentry> <refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry>。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3305 msgid "" "<quote>ipa</quote> the same as <quote>ldap</quote> but with IPA default " "settings." -msgstr "" +msgstr "<quote>ipa</quote>:與 <quote>ldap</quote> 相同,但使用 IPA 預設設定。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3309 msgid "" "<quote>ad</quote> the same as <quote>ldap</quote> but with AD default " "settings." -msgstr "" +msgstr "<quote>ad</quote>:與 <quote>ldap</quote> 相同,但使用 AD 預設設定。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3313 msgid "<quote>none</quote> disables SUDO explicitly." -msgstr "" +msgstr "<quote>none</quote>:明確地停用 SUDO。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3316 sssd.conf.5.xml:3402 sssd.conf.5.xml:3467 #: sssd.conf.5.xml:3492 sssd.conf.5.xml:3528 msgid "Default: The value of <quote>id_provider</quote> is used if it is set." -msgstr "" +msgstr "預設:若已設定 <quote>id_provider</quote>,則使用它的值。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3320 @@ -3859,6 +4330,11 @@ msgid "" "\"ldap_sudo_*\" in <citerefentry> <refentrytitle>sssd-ldap</refentrytitle> " "<manvolnum>5</manvolnum> </citerefentry>." msgstr "" +"sudo_provider 設定的詳細說明請參閱手冊頁 <citerefentry> <refentrytitle>sssd-" +"sudo</refentrytitle> <manvolnum>5</manvolnum> </citerefentry>。有許多設定選項" +"可以用來調整行為。請參閱 <citerefentry> <refentrytitle>sssd-ldap</" +"refentrytitle> <manvolnum>5</manvolnum> </citerefentry> 中的 " +"\"ldap_sudo_*\"。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3335 @@ -3868,11 +4344,14 @@ msgid "" "<emphasis>sudo_provider = None</emphasis> to disable all sudo-related " "activity in SSSD if you do not want to use sudo with SSSD at all." msgstr "" +"<emphasis>注意:</emphasis>除非明確停用 sudo 提供者,否則 Sudo 規則會定期在背" +"景中下載。若您完全不打算將 sudo 與 SSSD 一起使用,請設定 <emphasis>" +"sudo_provider = None</emphasis>,以停用 SSSD 中所有與 sudo 相關的活動。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3345 msgid "selinux_provider (string)" -msgstr "" +msgstr "selinux_provider (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3348 @@ -3881,6 +4360,8 @@ msgid "" "provider will be called right after access provider ends. Supported selinux " "providers are:" msgstr "" +"應處理載入 selinux 設定的提供者。請注意,此提供者會在 access 提供者結束後立即" +"被呼叫。支援的 selinux 提供者有:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3354 @@ -3890,11 +4371,14 @@ msgid "" "<manvolnum>5</manvolnum> </citerefentry> for more information on configuring " "IPA." msgstr "" +"<quote>ipa</quote>:從 IPA 伺服器載入 selinux 設定。IPA 的更多設定資訊,請參" +"閱 <citerefentry> <refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry>。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3362 msgid "<quote>none</quote> disallows fetching selinux settings explicitly." -msgstr "" +msgstr "<quote>none</quote>:明確地禁止取回 selinux 設定。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3365 @@ -3902,11 +4386,13 @@ msgid "" "Default: <quote>id_provider</quote> is used if it is set and can handle " "selinux loading requests." msgstr "" +"預設:若已設定 <quote>id_provider</quote> 且可以處理 selinux 載入要求,則使用" +"它。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3371 msgid "subdomains_provider (string)" -msgstr "" +msgstr "subdomains_provider (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3374 @@ -3914,6 +4400,8 @@ msgid "" "The provider which should handle fetching of subdomains. This value should " "be always the same as id_provider. Supported subdomain providers are:" msgstr "" +"應處理取回子網域的提供者。此值應一律與 id_provider 相同。支援的子網域提供者有" +":" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3380 @@ -3923,6 +4411,9 @@ msgid "" "<manvolnum>5</manvolnum> </citerefentry> for more information on configuring " "IPA." msgstr "" +"<quote>ipa</quote>:從 IPA 伺服器載入子網域清單。設定 IPA 的更多資訊,請參閱 " +"<citerefentry> <refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry>。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3389 @@ -3932,16 +4423,19 @@ msgid "" "<manvolnum>5</manvolnum> </citerefentry> for more information on configuring " "the AD provider." msgstr "" +"<quote>ad</quote>:從 Active Directory 伺服器載入子網域清單。設定 AD 提供者的" +"更多資訊,請參閱 <citerefentry> <refentrytitle>sssd-ad</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry>。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3398 msgid "<quote>none</quote> disallows fetching subdomains explicitly." -msgstr "" +msgstr "<quote>none</quote>:明確地禁止取回子網域。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3408 msgid "session_provider (string)" -msgstr "" +msgstr "session_provider (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3411 @@ -3950,16 +4444,18 @@ msgid "" "only user session task currently provided is the integration with Fleet " "Commander, which works only with IPA. Supported session providers are:" msgstr "" +"設定與管理使用者工作階段相關工作的提供者。目前提供的唯一使用者工作階段工作是" +"與 Fleet Commander 的整合,這只適用於 IPA。支援的 session 提供者有:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3418 msgid "<quote>ipa</quote> to allow performing user session related tasks." -msgstr "" +msgstr "<quote>ipa</quote>:允許執行與使用者工作階段相關的工作。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3422 msgid "<quote>none</quote> does not perform any kind of user session related tasks." -msgstr "" +msgstr "<quote>none</quote>:不執行任何與使用者工作階段相關的工作。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3426 @@ -3967,16 +4463,18 @@ msgid "" "Default: <quote>id_provider</quote> is used if it is set and can perform " "session related tasks." msgstr "" +"預設:若已設定 <quote>id_provider</quote> 且可以執行與工作階段相關的工作,則" +"使用它。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3433 msgid "autofs_provider (string)" -msgstr "" +msgstr "autofs_provider (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3436 msgid "The autofs provider used for the domain. Supported autofs providers are:" -msgstr "" +msgstr "網域使用的 autofs 提供者。支援的 autofs 提供者有:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3440 @@ -3985,6 +4483,9 @@ msgid "" "<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> " "</citerefentry> for more information on configuring LDAP." msgstr "" +"<quote>ldap</quote>:載入儲存在 LDAP 中的對應表。設定 LDAP 的更多資訊,請參" +"閱 <citerefentry> <refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry>。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3447 @@ -3993,6 +4494,9 @@ msgid "" "<refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</manvolnum> " "</citerefentry> for more information on configuring IPA." msgstr "" +"<quote>ipa</quote>:載入儲存在 IPA 伺服器中的對應表。設定 IPA 的更多資訊,請" +"參閱 <citerefentry> <refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry>。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3455 @@ -4001,23 +4505,26 @@ msgid "" "<refentrytitle>sssd-ad</refentrytitle> <manvolnum>5</manvolnum> " "</citerefentry> for more information on configuring the AD provider." msgstr "" +"<quote>ad</quote>:載入儲存在 AD 伺服器中的對應表。設定 AD 提供者的更多資訊," +"請參閱 <citerefentry> <refentrytitle>sssd-ad</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry>。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3464 msgid "<quote>none</quote> disables autofs explicitly." -msgstr "" +msgstr "<quote>none</quote>:明確地停用 autofs。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3474 msgid "hostid_provider (string)" -msgstr "" +msgstr "hostid_provider (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3477 msgid "" "The provider used for retrieving host identity information. Supported " "hostid providers are:" -msgstr "" +msgstr "用來取回主機身分資訊的提供者。支援的 hostid 提供者有:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3481 @@ -4027,23 +4534,26 @@ msgid "" "<manvolnum>5</manvolnum> </citerefentry> for more information on configuring " "IPA." msgstr "" +"<quote>ipa</quote>:載入儲存在 IPA 伺服器中的主機身分。設定 IPA 的更多資訊," +"請參閱 <citerefentry> <refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry>。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3489 msgid "<quote>none</quote> disables hostid explicitly." -msgstr "" +msgstr "<quote>none</quote>:明確地停用 hostid。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3499 msgid "resolver_provider (string)" -msgstr "" +msgstr "resolver_provider (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3502 msgid "" "The provider which should handle hosts and networks lookups. Supported " "resolver providers are:" -msgstr "" +msgstr "應處理主機與網路查詢的提供者。支援的 resolver 提供者有:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3506 @@ -4051,6 +4561,8 @@ msgid "" "<quote>proxy</quote> to forward lookups to another NSS library. See " "<quote>proxy_resolver_lib_name</quote>" msgstr "" +"<quote>proxy</quote>:將查詢轉送給另一個 NSS 程式庫。請參閱 <quote>" +"proxy_resolver_lib_name</quote>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3510 @@ -4060,6 +4572,9 @@ msgid "" "<manvolnum>5</manvolnum> </citerefentry> for more information on configuring " "LDAP." msgstr "" +"<quote>ldap</quote>:取回儲存在 LDAP 中的主機與網路。設定 LDAP 的更多資訊,請" +"參閱 <citerefentry> <refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry>。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3517 @@ -4069,11 +4584,14 @@ msgid "" "<manvolnum>5</manvolnum> </citerefentry> for more information on configuring " "the AD provider." msgstr "" +"<quote>ad</quote>:取回儲存在 AD 中的主機與網路。設定 AD 提供者的更多資訊,請" +"參閱 <citerefentry> <refentrytitle>sssd-ad</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry>。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3525 msgid "<quote>none</quote> disallows fetching hosts and networks explicitly." -msgstr "" +msgstr "<quote>none</quote>:明確地禁止取回主機與網路。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3538 @@ -4084,6 +4602,9 @@ msgid "" "trust subdomains and Active Directory domains, the flat (NetBIOS) name of " "the domain." msgstr "" +"此網域的正規表示式,描述如何將包含使用者名稱與網域的字串剖析為這些組成部分" +"。\"domain\" 可以匹配 SSSD 設定網域名稱,或是在 IPA 信任子網域與 Active " +"Directory 網域的情況下,匹配網域的簡短 (NetBIOS) 名稱。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3547 @@ -4092,16 +4613,18 @@ msgid "" "<quote>^((?P<name>.+)@(?P<domain>[^@]*)|(?P<name>[^@]+))$</quote> " "which allows two different styles for user names:" msgstr "" +"預設:<quote>^((?P<name>.+)@(?P<domain>[^@]*)|" +"(?P<name>[^@]+))$</quote>,允許兩種不同的使用者名稱樣式:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:3552 sssd.conf.5.xml:3566 msgid "username" -msgstr "" +msgstr "username" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:3555 sssd.conf.5.xml:3569 msgid "username@domain.name" -msgstr "" +msgstr "username@domain.name" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3560 @@ -4110,11 +4633,14 @@ msgid "" "<quote>^(((?P<domain>[^\\\\]+)\\\\(?P<name>.+))|((?P<name>.+)@(?P<domain>[^@]+))|((?P<name>[^@\\\\]+)))$</quote> " "which allows three different styles for user names:" msgstr "" +"AD 與 IPA 提供者的預設值:<quote>^(((?P<domain>[^\\\\]+)\\\\" +"(?P<name>.+))|((?P<name>.+)@(?P<domain>[^@]+))|(" +"(?P<name>[^@\\\\]+)))$</quote>,允許三種不同的使用者名稱樣式:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:3572 msgid "domain\\username" -msgstr "" +msgstr "domain\\username" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3575 @@ -4122,6 +4648,8 @@ msgid "" "While the first two correspond to the general default the third one is " "introduced to allow easy integration of users from Windows domains." msgstr "" +"前兩種對應到一般預設值,第三種是為了讓來自 Windows 網域的使用者容易整合而引入" +"。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3580 @@ -4132,87 +4660,90 @@ msgid "" "allowed in Windows group names). If a user wishes to use short names with " "<quote>@</quote> they must create their own re_expression." msgstr "" +"預設的 re_expression 使用 <quote>@</quote> 字元作為名稱與網域之間的分隔符。因" +"此,預設不接受簡短名稱中的 <quote>@</quote> 字元(Windows 群組名稱允許)。若" +"使用者希望使用帶有 <quote>@</quote> 的簡短名稱,必須自行建立 re_expression。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3632 msgid "Default: <quote>%1$s@%2$s</quote>." -msgstr "" +msgstr "預設:<quote>%1$s@%2$s</quote>。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3638 msgid "lookup_family_order (string)" -msgstr "" +msgstr "lookup_family_order (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3641 msgid "" "Provides the ability to select preferred address family to use when " "performing DNS lookups." -msgstr "" +msgstr "提供選擇執行 DNS 查詢時使用之慣用位址系列的能力。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3645 msgid "Supported values:" -msgstr "" +msgstr "支援的值:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3648 msgid "ipv4_first: Try looking up IPv4 address, if that fails, try IPv6" -msgstr "" +msgstr "ipv4_first:嘗試查詢 IPv4 位址,若失敗再嘗試 IPv6" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3651 msgid "ipv4_only: Only attempt to resolve hostnames to IPv4 addresses." -msgstr "" +msgstr "ipv4_only:只嘗試將主機名稱解析為 IPv4 位址。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3654 msgid "ipv6_first: Try looking up IPv6 address, if that fails, try IPv4" -msgstr "" +msgstr "ipv6_first:嘗試查詢 IPv6 位址,若失敗再嘗試 IPv4" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3657 msgid "ipv6_only: Only attempt to resolve hostnames to IPv6 addresses." -msgstr "" +msgstr "ipv6_only:只嘗試將主機名稱解析為 IPv6 位址。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3660 msgid "Default: ipv4_first" -msgstr "" +msgstr "預設:ipv4_first" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3666 msgid "dns_resolver_server_timeout (integer)" -msgstr "" +msgstr "dns_resolver_server_timeout (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3669 msgid "" "Defines the amount of time (in milliseconds) SSSD would try to talk to DNS " "server before trying next DNS server." -msgstr "" +msgstr "定義 SSSD 在嘗試下一個 DNS 伺服器之前,嘗試與 DNS 伺服器通訊的時間(毫秒)。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3674 msgid "The AD provider will use this option for the CLDAP ping timeouts as well." -msgstr "" +msgstr "AD 提供者也會將此選項用於 CLDAP ping 逾時。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3678 sssd.conf.5.xml:3698 sssd.conf.5.xml:3719 msgid "" "Please see the section <quote>FAILOVER</quote> for more information about " "the service resolution." -msgstr "" +msgstr "有關服務解析的更多資訊,請參閱 <quote>FAILOVER</quote> 一節。" #. type: Content of: <refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3683 sssd-ldap.5.xml:645 include/failover.xml:84 msgid "Default: 1000" -msgstr "" +msgstr "預設:1000" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3689 msgid "dns_resolver_op_timeout (integer)" -msgstr "" +msgstr "dns_resolver_op_timeout (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3692 @@ -4221,16 +4752,18 @@ msgid "" "(e.g. resolution of a hostname or an SRV record) before trying the next " "hostname or DNS discovery." msgstr "" +"定義在嘗試下一個主機名稱或 DNS 探索之前,等待解析單一 DNS 查詢(例如解析主機" +"名稱或 SRV 記錄)的時間(秒)。" #. type: Content of: <refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3703 include/failover.xml:100 msgid "Default: 3" -msgstr "" +msgstr "預設:3" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3709 msgid "dns_resolver_timeout (integer)" -msgstr "" +msgstr "dns_resolver_timeout (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3712 @@ -4240,11 +4773,13 @@ msgid "" "unreachable. If this timeout is reached, the domain will continue to operate " "in offline mode." msgstr "" +"定義在假設服務無法連線之前,等待內部故障轉移服務回覆的時間(秒)。若達到此逾" +"時,網域會繼續以離線模式運作。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3730 msgid "dns_resolver_use_search_list (bool)" -msgstr "" +msgstr "dns_resolver_use_search_list (bool)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3733 @@ -4253,6 +4788,8 @@ msgid "" "\"search\" directive from the resolv.conf file. This can lead to delays in " "environments with improperly configured DNS." msgstr "" +"一般來說,DNS 解析器會搜尋 resolv.conf 檔案中 \"search\" 指令定義的網域清單。" +"在 DNS 設定不當的環境中,這可能導致延遲。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3739 @@ -4261,33 +4798,35 @@ msgid "" "configuration, setting this option to FALSE can prevent unnecessary DNS " "lookups in such environments." msgstr "" +"若 SSSD 設定中使用完整網域名稱(或 _srv_),將此選項設為 FALSE 可以防止在這種" +"環境中進行不必要的 DNS 查詢。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3745 msgid "Default: TRUE" -msgstr "" +msgstr "預設:TRUE" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3751 msgid "dns_discovery_domain (string)" -msgstr "" +msgstr "dns_discovery_domain (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3754 msgid "" "If service discovery is used in the back end, specifies the domain part of " "the service discovery DNS query." -msgstr "" +msgstr "若後端使用服務探索,指定服務探索 DNS 查詢的網域部分。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3758 msgid "Default: Use the domain part of machine's hostname" -msgstr "" +msgstr "預設:使用機器主機名稱的網域部分" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3764 msgid "failover_primary_timeout (integer)" -msgstr "" +msgstr "failover_primary_timeout (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3767 @@ -4296,56 +4835,58 @@ msgid "" "server. This option defines the number of seconds SSSD waits before " "attempting to reconnect to the primary server." msgstr "" +"當沒有可用的主要伺服器時,SSSD 會故障轉移到備份伺服器。此選項定義 SSSD 在嘗試" +"重新連線主要伺服器之前等待的秒數。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3774 msgid "Note: The minimum value is 31." -msgstr "" +msgstr "注意:最小值為 31。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3777 msgid "Default: 31" -msgstr "" +msgstr "預設:31" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3783 msgid "override_gid (integer)" -msgstr "" +msgstr "override_gid (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3786 msgid "Override the primary GID value with the one specified." -msgstr "" +msgstr "以指定的值覆寫主要 GID 值。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3792 msgid "case_sensitive (string)" -msgstr "" +msgstr "case_sensitive (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3799 msgid "True" -msgstr "" +msgstr "True" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3802 msgid "Case sensitive. This value is invalid for AD provider." -msgstr "" +msgstr "區分大小寫。此值對 AD 提供者無效。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3808 msgid "False" -msgstr "" +msgstr "False" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3810 msgid "Case insensitive." -msgstr "" +msgstr "不區分大小寫。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3814 msgid "Preserving" -msgstr "" +msgstr "Preserving" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3817 @@ -4354,6 +4895,8 @@ msgid "" "of NSS operations. Note that name aliases (and in case of services also " "protocol names) are still lowercased in the output." msgstr "" +"與 False(不區分大小寫)相同,但不會將 NSS 作業結果中的名稱轉為小寫。請注意," +"輸出中的名稱別名(服務的話還包含協定名稱)仍會轉為小寫。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3825 @@ -4361,6 +4904,8 @@ msgid "" "If you want to set this value for trusted domain with IPA provider, you need " "to set it on both the client and SSSD on the server." msgstr "" +"若您想為使用 IPA 提供者的受信任網域設定此值,需要在用戶端與伺服器上的 SSSD 兩" +"邊都設定。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3795 @@ -4368,16 +4913,18 @@ msgid "" "Treat user and group names as case sensitive. Possible option values are: " "<placeholder type=\"variablelist\" id=\"0\"/>" msgstr "" +"將使用者與群組名稱視為區分大小寫。可能的選項值有:<placeholder " +"type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3840 msgid "Default: True (False for AD provider)" -msgstr "" +msgstr "預設:True(AD 提供者為 False)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3846 msgid "subdomain_inherit (string)" -msgstr "" +msgstr "subdomain_inherit (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3849 @@ -4386,103 +4933,105 @@ msgid "" "subdomain. Please note that only selected parameters can be inherited. " "Currently the following options can be inherited:" msgstr "" +"指定應由子網域繼承的設定參數清單。請注意,只有選定的參數可以繼承。目前可以繼" +"承下列選項:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3855 msgid "ldap_search_timeout" -msgstr "" +msgstr "ldap_search_timeout" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3858 msgid "ldap_network_timeout" -msgstr "" +msgstr "ldap_network_timeout" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3861 msgid "ldap_opt_timeout" -msgstr "" +msgstr "ldap_opt_timeout" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3864 msgid "ldap_offline_timeout" -msgstr "" +msgstr "ldap_offline_timeout" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3867 msgid "ldap_enumeration_refresh_timeout" -msgstr "" +msgstr "ldap_enumeration_refresh_timeout" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3870 msgid "ldap_enumeration_refresh_offset" -msgstr "" +msgstr "ldap_enumeration_refresh_offset" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3873 msgid "ldap_purge_cache_timeout" -msgstr "" +msgstr "ldap_purge_cache_timeout" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3876 msgid "ldap_purge_cache_offset" -msgstr "" +msgstr "ldap_purge_cache_offset" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3879 msgid "" "ldap_krb5_keytab (the value of krb5_keytab will be used if ldap_krb5_keytab " "is not set explicitly)" -msgstr "" +msgstr "ldap_krb5_keytab(若未明確設定 ldap_krb5_keytab,則使用 krb5_keytab 的值)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3883 msgid "ldap_krb5_ticket_lifetime" -msgstr "" +msgstr "ldap_krb5_ticket_lifetime" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3886 msgid "ldap_enumeration_search_timeout" -msgstr "" +msgstr "ldap_enumeration_search_timeout" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3889 msgid "ldap_connection_expire_timeout" -msgstr "" +msgstr "ldap_connection_expire_timeout" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3892 msgid "ldap_connection_expire_offset" -msgstr "" +msgstr "ldap_connection_expire_offset" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3895 msgid "ldap_connection_idle_timeout" -msgstr "" +msgstr "ldap_connection_idle_timeout" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3898 sssd-ldap.5.xml:401 msgid "ldap_use_tokengroups" -msgstr "" +msgstr "ldap_use_tokengroups" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3901 msgid "ldap_user_principal" -msgstr "" +msgstr "ldap_user_principal" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3904 msgid "ignore_group_members" -msgstr "" +msgstr "ignore_group_members" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3907 msgid "auto_private_groups" -msgstr "" +msgstr "auto_private_groups" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3910 msgid "case_sensitive" -msgstr "" +msgstr "case_sensitive" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> #: sssd.conf.5.xml:3915 @@ -4491,26 +5040,28 @@ msgid "" "subdomain_inherit = ldap_purge_cache_timeout\n" " " msgstr "" +"subdomain_inherit = ldap_purge_cache_timeout\n" +" " #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3922 msgid "Note: This option only works with the IPA and AD provider." -msgstr "" +msgstr "注意:此選項只適用於 IPA 與 AD 提供者。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3929 msgid "subdomain_homedir (string)" -msgstr "" +msgstr "subdomain_homedir (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3940 msgid "%F" -msgstr "" +msgstr "%F" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3941 msgid "flat (NetBIOS) name of a subdomain." -msgstr "" +msgstr "子網域的簡短 (NetBIOS) 名稱。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3932 @@ -4521,31 +5072,35 @@ msgid "" "with <emphasis>subdomain_homedir</emphasis>. <placeholder " "type=\"variablelist\" id=\"0\"/>" msgstr "" +"在 IPA AD 信任中,將此家目錄用作此網域內所有子網域的預設值。可能值的相關資訊" +"請參閱 <emphasis>override_homedir</emphasis>。除此之外,下列展開只能與 " +"<emphasis>subdomain_homedir</emphasis> 一起使用。<placeholder " +"type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3946 msgid "The value can be overridden by <emphasis>override_homedir</emphasis> option." -msgstr "" +msgstr "此值可以被 <emphasis>override_homedir</emphasis> 選項覆寫。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3950 msgid "Default: <filename>/home/%d/%u</filename>" -msgstr "" +msgstr "預設:<filename>/home/%d/%u</filename>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3955 msgid "realmd_tags (string)" -msgstr "" +msgstr "realmd_tags (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3958 msgid "Various tags stored by the realmd configuration service for this domain." -msgstr "" +msgstr "realmd 設定服務為此網域儲存的各種標籤。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3964 msgid "cached_auth_timeout (int)" -msgstr "" +msgstr "cached_auth_timeout (int)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3967 @@ -4555,18 +5110,20 @@ msgid "" "the online mode. If the credentials are incorrect, SSSD falls back to online " "authentication." msgstr "" +"指定自最後一次成功線上驗證以來,SSSD 處於線上模式時使用者將使用快取憑證進行驗" +"證的時間(秒)。若憑證不正確,SSSD 會退回線上驗證。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3975 msgid "" "This option's value is inherited by all trusted domains. At the moment it is " "not possible to set a different value per trusted domain." -msgstr "" +msgstr "此選項的值會由所有受信任網域繼承。目前無法為每個受信任網域設定不同的值。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3980 msgid "Special value 0 implies that this feature is disabled." -msgstr "" +msgstr "特殊值 0 表示停用此功能。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3984 @@ -4575,11 +5132,13 @@ msgid "" "<quote>pam_id_timeout</quote> then the back end could be called to handle " "<quote>initgroups.</quote>" msgstr "" +"請注意,若 <quote>cached_auth_timeout</quote> 比 <quote>pam_id_timeout</" +"quote> 長,則可能呼叫後端處理 <quote>initgroups。</quote>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3995 msgid "local_auth_policy (string)" -msgstr "" +msgstr "local_auth_policy (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3998 @@ -4592,6 +5151,10 @@ msgid "" "supported by the backend. With this option additional methods can be enabled " "which are evaluated and checked locally." msgstr "" +"本機驗證方法原則。某些後端(例如 LDAP、proxy 提供者)只支援以密碼為基礎的驗證" +",而其他後端可以處理以 PKINIT 為基礎的 Smartcard 驗證(AD、IPA)、雙因素驗證" +"(IPA)或針對中央實例的其他方法。預設情況下,這種情況只會使用後端支援的方法進" +"行驗證。透過此選項,可以啟用在本機評估與檢查的其他方法。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4010 @@ -4604,6 +5167,11 @@ msgid "" "enables passkey for local authentication. Multiple enable values should be " "comma-separated, such as <quote>enable:passkey, enable:smartcard</quote>" msgstr "" +"此選項有三個可能的值:match、only、enable。<quote>match</quote> 用於匹配 " +"Kerberos 方法的離線與線上狀態。<quote>only</quote> 忽略線上方法,只提供本機方" +"法。enable 允許明確定義用於本機驗證的方法。例如,<quote>enable:passkey</" +"quote> 只為本機驗證啟用 passkey。多個 enable 值應以逗號分隔,例如 <quote>" +"enable:passkey, enable:smartcard</quote>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4023 @@ -4612,41 +5180,43 @@ msgid "" "properly, are currently enabled or disabled for each backend, with the " "default local_auth_policy: <quote>match</quote>" msgstr "" +"下表顯示在設定正確的情況下,每個後端目前啟用或停用的驗證方法,預設的 " +"local_auth_policy 為:<quote>match</quote>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> #: sssd.conf.5.xml:4036 msgid "local_auth_policy = match (default)" -msgstr "" +msgstr "local_auth_policy = match (default)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> #: sssd.conf.5.xml:4037 msgid "Passkey" -msgstr "" +msgstr "Passkey" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> #: sssd.conf.5.xml:4038 msgid "Smartcard" -msgstr "" +msgstr "Smartcard" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:4041 sssd-ldap.5.xml:189 msgid "IPA" -msgstr "" +msgstr "IPA" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:4044 sssd-ldap.5.xml:194 msgid "AD" -msgstr "" +msgstr "AD" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry><para> #: sssd.conf.5.xml:4044 sssd.conf.5.xml:4047 sssd.conf.5.xml:4048 msgid "disabled" -msgstr "" +msgstr "停用" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry> #: sssd.conf.5.xml:4047 msgid "LDAP" -msgstr "" +msgstr "LDAP" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4052 @@ -4656,6 +5226,8 @@ msgid "" "authentication methods supported by the backend. I.e. there will be a PIN " "prompt instead of e.g. a password prompt." msgstr "" +"請注意,若已啟用本機 Smartcard 驗證且存在 Smartcard,則 Smartcard 驗證會優先" +"於後端支援的驗證方法。也就是說,會出現 PIN 提示,而不是例如密碼提示。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> #: sssd.conf.5.xml:4064 @@ -4667,6 +5239,11 @@ msgid "" "auth_provider = none\n" "local_auth_policy = only\n" msgstr "" +"[domain/shadowutils]\n" +"id_provider = proxy\n" +"proxy_lib_name = files\n" +"auth_provider = none\n" +"local_auth_policy = only\n" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4060 @@ -4675,6 +5252,8 @@ msgid "" "locally using any enabled method (i.e. smartcard, passkey). <placeholder " "type=\"programlisting\" id=\"0\"/>" msgstr "" +"下列設定範例允許本機使用者使用任何已啟用的方法(例如 smartcard、passkey)在本" +"機驗證。<placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4072 @@ -4682,28 +5261,30 @@ msgid "" "It is expected that the <quote>files</quote> provider ignores the " "local_auth_policy option and supports Smartcard authentication by default." msgstr "" +"預期 <quote>files</quote> 提供者會忽略 local_auth_policy 選項,並預設支援 " +"Smartcard 驗證。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4077 msgid "Default: match" -msgstr "" +msgstr "預設:match" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:4082 msgid "auto_private_groups (string)" -msgstr "" +msgstr "auto_private_groups (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:4088 msgid "true" -msgstr "" +msgstr "true" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4091 msgid "" "Create user's private group unconditionally from user's UID number. The GID " "number is ignored in this case." -msgstr "" +msgstr "一律依使用者的 UID 編號建立使用者的私人群組。在此情況下會忽略 GID 編號。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4095 @@ -4713,23 +5294,26 @@ msgid "" "UID or GID number with this option. In other words, enabling this option " "enforces uniqueness across the ID space." msgstr "" +"注意:由於 GID 編號與使用者私人群組是從 UID 編號推斷出來的,因此此選項不支援" +"多個具有相同 UID 或 GID 編號的項目。換句話說,啟用此選項會強制整個 ID 空間的" +"唯一性。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:4104 msgid "false" -msgstr "" +msgstr "false" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4107 msgid "" "Always use the user's primary GID number. The GID number must refer to a " "group object in the LDAP database." -msgstr "" +msgstr "一律使用使用者的主要 GID 編號。GID 編號必須指向 LDAP 資料庫中的群組物件。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:4113 msgid "hybrid" -msgstr "" +msgstr "hybrid" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4116 @@ -4740,13 +5324,16 @@ msgid "" "GID in the user entry is also used by a group object, the primary GID of the " "user resolves to that group object." msgstr "" +"對於 UID 與 GID 編號值相同、且 GID 編號不對應 LDAP 中任何真實群組物件的使用者" +"項目,會自動產生主要群組。若兩者值相同,但使用者項目中的主要 GID 也被群組物件" +"使用,則使用者的主要 GID 會解析為該群組物件。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4129 msgid "" "If the UID and GID of a user are different, then the GID must correspond to " "a group entry, otherwise the GID is simply not resolvable." -msgstr "" +msgstr "若使用者的 UID 與 GID 不同,則 GID 必須對應群組項目,否則 GID 根本無法解析。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4136 @@ -4755,6 +5342,8 @@ msgid "" "separate group objects for the user private groups, but also wish to retain " "the existing user private groups." msgstr "" +"此功能對希望停止為使用者私人群組維護個別群組物件、但也希望保留現有使用者私人" +"群組的環境很有用。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4085 @@ -4762,6 +5351,8 @@ msgid "" "This option takes any of three available values: <placeholder " "type=\"variablelist\" id=\"0\"/>" msgstr "" +"此選項接受三個可用值中的任何一個:<placeholder type=\"variablelist\" " +"id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4148 @@ -4769,6 +5360,8 @@ msgid "" "For subdomains, the default value is False for subdomains that use assigned " "POSIX IDs and True for subdomains that use automatic ID-mapping." msgstr "" +"對於子網域,使用指派 POSIX ID 的子網域預設值為 False,使用自動 ID 對應的子網" +"域預設值為 True。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> #: sssd.conf.5.xml:4156 @@ -4777,6 +5370,8 @@ msgid "" "[domain/forest.domain/sub.domain]\n" "auto_private_groups = false\n" msgstr "" +"[domain/forest.domain/sub.domain]\n" +"auto_private_groups = false\n" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> #: sssd.conf.5.xml:4162 @@ -4786,6 +5381,9 @@ msgid "" "subdomain_inherit = auto_private_groups\n" "auto_private_groups = false\n" msgstr "" +"[domain/forest.domain]\n" +"subdomain_inherit = auto_private_groups\n" +"auto_private_groups = false\n" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4153 @@ -4795,6 +5393,9 @@ msgid "" "globally for all subdomains in the main domain section using the " "subdomain_inherit option: <placeholder type=\"programlisting\" id=\"1\"/>" msgstr "" +"auto_private_groups 的值可以在子區段中逐子網域設定,例如:<placeholder " +"type=\"programlisting\" id=\"0\"/>,或使用 subdomain_inherit 選項在主網域區段" +"中為所有子網域全域設定:<placeholder type=\"programlisting\" id=\"1\"/>" #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:2552 @@ -4804,16 +5405,19 @@ msgid "" "<quote>[domain/<replaceable>NAME</replaceable>]</quote> <placeholder " "type=\"variablelist\" id=\"0\"/>" msgstr "" +"這些設定選項可以出現在網域設定區段中,也就是名為 <quote>[domain/<replaceable>" +"NAME</replaceable>]</quote> 的區段中 <placeholder type=\"variablelist\" " +"id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:4177 msgid "proxy_pam_target (string)" -msgstr "" +msgstr "proxy_pam_target (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4180 msgid "The proxy target PAM proxies to." -msgstr "" +msgstr "proxy 轉送到的 PAM 目標。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4183 @@ -4822,11 +5426,13 @@ msgid "" "or create a new one and add the service name here. As an alternative you can " "enable local authentication with the local_auth_policy option." msgstr "" +"預設:預設未設定,您必須採用現有的 pam 設定或建立新的設定,並在此加入服務名稱" +"。另一種做法是使用 local_auth_policy 選項啟用本機驗證。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:4193 msgid "proxy_lib_name (string)" -msgstr "" +msgstr "proxy_lib_name (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4196 @@ -4835,11 +5441,13 @@ msgid "" "searched for in the library are in the form of _nss_$(libName)_$(function), " "for example _nss_files_getpwent." msgstr "" +"在 proxy 網域中使用的 NSS 程式庫名稱。在程式庫中搜尋的 NSS 函式形式為 _nss_$" +"(libName)_$(function),例如 _nss_files_getpwent。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:4206 msgid "proxy_resolver_lib_name (string)" -msgstr "" +msgstr "proxy_resolver_lib_name (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4209 @@ -4848,11 +5456,13 @@ msgid "" "domains. The NSS functions searched for in the library are in the form of " "_nss_$(libName)_$(function), for example _nss_dns_gethostbyname2_r." msgstr "" +"在 proxy 網域中用於主機與網路查詢的 NSS 程式庫名稱。在程式庫中搜尋的 NSS 函式" +"形式為 _nss_$(libName)_$(function),例如 _nss_dns_gethostbyname2_r。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:4220 msgid "proxy_fast_alias (boolean)" -msgstr "" +msgstr "proxy_fast_alias (boolean)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4223 @@ -4862,11 +5472,14 @@ msgid "" "name was an alias. Setting this option to true would cause the SSSD to " "perform the ID lookup from cache for performance reasons." msgstr "" +"在 proxy 提供者中依名稱查詢使用者或群組時,會再依 ID 進行第二次查詢,以「正規" +"化」名稱,以防要求的名稱是別名。將此選項設為 true 會讓 SSSD 基於效能考量從快" +"取執行 ID 查詢。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:4237 msgid "proxy_max_children (integer)" -msgstr "" +msgstr "proxy_max_children (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4240 @@ -4875,18 +5488,20 @@ msgid "" "for high-load SSSD environments where sssd may run out of available child " "slots, which would cause some issues due to the requests being queued." msgstr "" +"此選項指定預先分叉的 proxy 子程序數目。這對高負載的 SSSD 環境很有用,在這種環" +"境中 sssd 可能會用完可用的子程序位置,導致要求排隊而產生一些問題。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:4173 msgid "" "Options valid for proxy domains. <placeholder type=\"variablelist\" " "id=\"0\"/>" -msgstr "" +msgstr "適用於 proxy 網域的選項。<placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><title> #: sssd.conf.5.xml:4256 msgid "Application domains" -msgstr "" +msgstr "應用程式網域" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sssd.conf.5.xml:4258 @@ -4905,6 +5520,15 @@ msgid "" "internally represents a domain with type <quote>application</quote> " "optionally inherits settings from a tradition SSSD domain." msgstr "" +"SSSD 憑藉其 D-Bus 介面(請參閱 <citerefentry> <refentrytitle>sssd-ifp</" +"refentrytitle> <manvolnum>5</manvolnum> </citerefentry>),作為通往儲存使用者" +"與群組之 LDAP 目錄的閘道,對應用程式很有吸引力。然而,與傳統 SSSD 部署(所有" +"使用者與群組都擁有 POSIX 屬性,或可以從 Windows SID 推斷這些屬性)相反,在許" +"多情況下,應用程式支援情境中的使用者與群組沒有 POSIX 屬性。管理員可以不必設" +"定 <quote>[domain/<replaceable>NAME</replaceable>]</quote> 區段,而改為設定 " +"<quote>[application/<replaceable>NAME</replaceable>]</quote> 區段,該區段在內" +"部代表類型為 <quote>application</quote> 的網域,並可選擇性地從傳統 SSSD 網域" +"繼承設定。" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sssd.conf.5.xml:4278 @@ -4913,16 +5537,18 @@ msgid "" "the <quote>domains</quote> parameter so that the lookup order between the " "application domain and its POSIX sibling domain is set correctly." msgstr "" +"請注意,應用程式網域仍必須在 <quote>domains</quote> 參數中明確啟用,才能正確" +"設定應用程式網域與其 POSIX 對應網域之間的查詢順序。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><title> #: sssd.conf.5.xml:4284 msgid "Application domain parameters" -msgstr "" +msgstr "應用程式網域參數" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:4286 msgid "inherit_from (string)" -msgstr "" +msgstr "inherit_from (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4289 @@ -4932,6 +5558,8 @@ msgid "" "application settings that augment or override the <quote>sibling</quote> " "domain settings." msgstr "" +"應用程式網域從中繼承所有設定的 SSSD POSIX 類型網域。此外,應用程式網域可以在" +"應用程式設定中加入自己的設定,以擴充或覆寫<quote>對應</quote>網域的設定。" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sssd.conf.5.xml:4303 @@ -4942,6 +5570,10 @@ msgid "" "the telephoneNumber attribute, stores it as the phone attribute in the cache " "and makes the phone attribute reachable through the D-Bus interface." msgstr "" +"下列範例說明應用程式網域的用法。在此設定中,POSIX 網域連線到 LDAP 伺服器,並" +"由作業系統透過 NSS responder 使用。此外,應用程式網域也會要求 " +"telephoneNumber 屬性,將其儲存為快取中的 phone 屬性,並讓 phone 屬性可透過 D-" +"Bus 介面存取。" #. type: Content of: <reference><refentry><refsect1><refsect2><programlisting> #: sssd.conf.5.xml:4311 @@ -4962,11 +5594,25 @@ msgid "" "inherit_from = posixdom\n" "ldap_user_extra_attrs = phone:telephoneNumber\n" msgstr "" +"[sssd]\n" +"domains = appdom, posixdom\n" +"\n" +"[ifp]\n" +"user_attributes = +phone\n" +"\n" +"[domain/posixdom]\n" +"id_provider = ldap\n" +"ldap_uri = ldap://ldap.example.com\n" +"ldap_search_base = dc=example,dc=com\n" +"\n" +"[application/appdom]\n" +"inherit_from = posixdom\n" +"ldap_user_extra_attrs = phone:telephoneNumber\n" #. type: Content of: <reference><refentry><refsect1><title> #: sssd.conf.5.xml:4331 msgid "TRUSTED DOMAIN SECTION" -msgstr "" +msgstr "受信任網域區段" #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:4333 @@ -4978,68 +5624,72 @@ msgid "" "examples below for explanation. Currently supported options in the trusted " "domain section are:" msgstr "" +"網域區段中使用的一些選項也可以在受信任網域區段中使用,也就是名為 <quote>" +"[domain/<replaceable>DOMAIN_NAME</replaceable>/<replaceable>" +"TRUSTED_DOMAIN_NAME</replaceable>]</quote> 的區段。其中 DOMAIN_NAME 是實際加" +"入的基礎網域。請參閱下列範例以了解說明。目前受信任網域區段支援的選項有:" #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:4340 msgid "ldap_search_base," -msgstr "" +msgstr "ldap_search_base," #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:4341 msgid "ldap_user_search_base," -msgstr "" +msgstr "ldap_user_search_base," #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:4342 msgid "ldap_group_search_base," -msgstr "" +msgstr "ldap_group_search_base," #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:4343 msgid "ldap_netgroup_search_base," -msgstr "" +msgstr "ldap_netgroup_search_base," #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:4344 msgid "ldap_service_search_base," -msgstr "" +msgstr "ldap_service_search_base," #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:4345 msgid "ldap_sasl_mech," -msgstr "" +msgstr "ldap_sasl_mech," #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:4346 msgid "ad_server," -msgstr "" +msgstr "ad_server," #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:4347 msgid "ad_backup_server," -msgstr "" +msgstr "ad_backup_server," #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:4348 msgid "ad_site," -msgstr "" +msgstr "ad_site," #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:4349 sssd-ipa.5.xml:884 msgid "use_fully_qualified_names" -msgstr "" +msgstr "use_fully_qualified_names" #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:4353 msgid "" "For more details about these options see their individual description in the " "manual page." -msgstr "" +msgstr "關於這些選項的更多詳細資料,請參閱手冊頁中各選項的個別說明。" #. type: Content of: <reference><refentry><refsect1><title> #: sssd.conf.5.xml:4359 msgid "CERTIFICATE MAPPING SECTION" -msgstr "" +msgstr "憑證對應區段" #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:4361 @@ -5054,6 +5704,12 @@ msgid "" "or not even possible to do this for the general case where local services " "use PAM for authentication." msgstr "" +"若要允許使用 Smartcard 與憑證進行驗證,SSSD 必須能夠將憑證對應到使用者。這可" +"以透過將完整憑證加入使用者的 LDAP 物件或本機覆寫來完成。雖然使用完整憑證是使" +"用 SSH 之 Smartcard 驗證功能所必需的(詳情請參閱 <citerefentry> " +"<refentrytitle>sss_ssh_authorizedkeys</refentrytitle> <manvolnum>8</" +"manvolnum> </citerefentry>),但對於本機服務使用 PAM 進行驗證的一般情況來說," +"這樣做可能很麻煩,甚至不可能。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:4375 @@ -5062,6 +5718,9 @@ msgid "" "SSSD (see <citerefentry> <refentrytitle>sss-certmap</refentrytitle> " "<manvolnum>5</manvolnum> </citerefentry> for details)." msgstr "" +"為了讓對應更有彈性,SSSD 加入了對應與匹配規則(詳情請參閱 <citerefentry> " +"<refentrytitle>sss-certmap</refentrytitle> <manvolnum>5</manvolnum> </" +"citerefentry>)。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:4384 @@ -5071,18 +5730,21 @@ msgid "" "<quote>[certmap/<replaceable>DOMAIN_NAME</replaceable>/<replaceable>RULE_NAME</replaceable>]</quote>. " "In this section the following options are allowed:" msgstr "" +"可以在 SSSD 設定中新增對應與匹配規則,使用名稱類似 <quote>[certmap/" +"<replaceable>DOMAIN_NAME</replaceable>/<replaceable>RULE_NAME</replaceable>" +"]</quote> 的獨立區段。此區段允許下列選項:" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.conf.5.xml:4391 msgid "matchrule (string)" -msgstr "" +msgstr "matchrule (string)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4394 msgid "" "Only certificates from the Smartcard which matches this rule will be " "processed, all others are ignored." -msgstr "" +msgstr "只會處理 Smartcard 中符合此規則的憑證,其他憑證都會被忽略。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4398 @@ -5090,16 +5752,18 @@ msgid "" "Default: KRB5:<EKU>clientAuth, i.e. only certificates which have the " "Extended Key Usage <quote>clientAuth</quote>" msgstr "" +"預設:KRB5:<EKU>clientAuth,也就是只有具有擴充金鑰用法 <quote>" +"clientAuth</quote> 的憑證" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.conf.5.xml:4405 msgid "maprule (string)" -msgstr "" +msgstr "maprule (string)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4408 msgid "Defines how the user is found for a given certificate." -msgstr "" +msgstr "定義如何為給定的憑證找到使用者。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:4414 @@ -5107,18 +5771,20 @@ msgid "" "LDAP:(userCertificate;binary={cert!bin}) for LDAP based providers like " "<quote>ldap</quote>, <quote>AD</quote> or <quote>ipa</quote>." msgstr "" +"LDAP:(userCertificate;binary={cert!bin}):用於以 LDAP 為基礎的提供者,例如 " +"<quote>ldap</quote>、<quote>AD</quote> 或 <quote>ipa</quote>。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:4420 msgid "" "The RULE_NAME for the <quote>files</quote> provider which tries to find a " "user with the same name." -msgstr "" +msgstr "RULE_NAME 用於 <quote>files</quote> 提供者,會嘗試找到具有相同名稱的使用者。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.conf.5.xml:4429 msgid "domains (string)" -msgstr "" +msgstr "domains (string)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4432 @@ -5128,16 +5794,18 @@ msgid "" "supports subdomains this option can be used to add the rule to subdomains as " "well." msgstr "" +"套用規則的網域名稱逗號分隔清單。預設情況下,規則只在 sssd.conf 中設定的網域有" +"效。若提供者支援子網域,此選項也可以用來將規則加入子網域。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4439 msgid "Default: the configured domain in sssd.conf" -msgstr "" +msgstr "預設:sssd.conf 中設定的網域" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.conf.5.xml:4444 msgid "priority (integer)" -msgstr "" +msgstr "priority (integer)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4447 @@ -5146,11 +5814,13 @@ msgid "" "number the lower the priority. <quote>0</quote> stands for the highest " "priority while <quote>4294967295</quote> is the lowest." msgstr "" +"定義規則優先順序的無符號整數值。數字越大優先順序越低。<quote>0</quote> 代表最" +"高優先順序,<quote>4294967295</quote> 代表最低。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4453 msgid "Default: the lowest priority" -msgstr "" +msgstr "預設:最低優先順序" #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:4459 @@ -5158,13 +5828,15 @@ msgid "" "To make the configuration simple and reduce the amount of configuration " "options the <quote>files</quote> provider has some special properties:" msgstr "" +"為了讓設定更簡單並減少設定選項的數量,<quote>files</quote> 提供者有一些特殊屬" +"性:" #. type: Content of: <reference><refentry><refsect1><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:4465 msgid "" "if maprule is not set the RULE_NAME name is assumed to be the name of the " "matching user" -msgstr "" +msgstr "若未設定 maprule,RULE_NAME 名稱會被視為匹配使用者的名稱" #. type: Content of: <reference><refentry><refsect1><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:4471 @@ -5174,16 +5846,19 @@ msgid "" "e.g. <quote>(username)</quote> or " "<quote>({subject_rfc822_name.short_name})</quote>" msgstr "" +"若使用 maprule,單一使用者名稱或像是 <quote>{subject_rfc822_name.short_name}" +"</quote> 的範本都必須放在大括號中,例如 <quote>(username)</quote> 或 <quote>(" +"{subject_rfc822_name.short_name})</quote>" #. type: Content of: <reference><refentry><refsect1><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:4480 msgid "the <quote>domains</quote> option is ignored" -msgstr "" +msgstr "<quote>domains</quote> 選項會被忽略" #. type: Content of: <reference><refentry><refsect1><title> #: sssd.conf.5.xml:4488 msgid "PROMPTING CONFIGURATION SECTION" -msgstr "" +msgstr "提示設定區段" #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:4490 @@ -5194,6 +5869,9 @@ msgid "" "methods are available for the user trying to log in. Based on the results " "pam_sss will prompt the user for appropriate credentials." msgstr "" +"若存在特殊檔案(<filename>/var/lib/sss/pubconf/pam_preauth_available</" +"filename>),SSSD 的 PAM 模組 pam_sss 會要求 SSSD 找出嘗試登入的使用者可以使" +"用哪些驗證方法。根據結果,pam_sss 會提示使用者輸入適當的憑證。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:4498 @@ -5203,58 +5881,61 @@ msgid "" "select the prompting might not be suitable for all use cases. The following " "options should provide a better flexibility here." msgstr "" +"隨著驗證方法的數量增加,以及單一使用者可能有多種驗證方法,pam_sss 用來選擇提" +"示方式的啟發式演算法可能不適合所有使用案例。下列選項應該能在這裡提供更好的彈" +"性。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:4510 msgid "[prompting/password]" -msgstr "" +msgstr "[prompting/password]" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:4513 msgid "password_prompt" -msgstr "" +msgstr "password_prompt" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4514 msgid "to change the string of the password prompt" -msgstr "" +msgstr "變更密碼提示的字串" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4512 msgid "" "to configure password prompting, allowed options are: <placeholder " "type=\"variablelist\" id=\"0\"/>" -msgstr "" +msgstr "設定密碼提示,允許的選項有:<placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:4522 msgid "[prompting/2fa]" -msgstr "" +msgstr "[prompting/2fa]" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:4526 msgid "first_prompt" -msgstr "" +msgstr "first_prompt" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4527 msgid "to change the string of the prompt for the first factor" -msgstr "" +msgstr "變更第一個因素的提示字串" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:4530 msgid "second_prompt" -msgstr "" +msgstr "second_prompt" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4531 msgid "to change the string of the prompt for the second factor" -msgstr "" +msgstr "變更第二個因素的提示字串" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:4534 msgid "single_prompt" -msgstr "" +msgstr "single_prompt" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4535 @@ -5264,6 +5945,8 @@ msgid "" "string. Please note that both factors have to be entered here, even if the " "second factor is optional." msgstr "" +"布林值,若為 True,則只會出現單一提示,使用 first_prompt 的值,預期兩個因素會" +"以單一字串輸入。請注意,即使第二個因素是選用的,兩個因素都必須在此輸入。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4524 @@ -5273,6 +5956,9 @@ msgid "" "optional and it should be possible to log in either only with the password " "or with both factors two-step prompting has to be used." msgstr "" +"設定雙因素驗證提示,允許的選項有:<placeholder type=\"variablelist\" " +"id=\"0\"/> 若第二個因素是選用的,且應該可以只使用密碼或使用兩個因素登入,則必" +"須使用兩步驟提示。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4548 @@ -5284,16 +5970,20 @@ msgid "" "the user at the SSH password prompt will always be the two factors in a " "single string, even if two-factor authentication is optional." msgstr "" +"某些用戶端(例如啟用 'PasswordAuthentication yes' 的 SSH)會產生自己的提示," +"不使用 SSSD 或其他 PAM 模組提供的提示。此外,對於使用 PasswordAuthentication " +"的 SSH,若可以使用雙因素驗證,SSSD 預期使用者在 SSH 密碼提示輸入的憑證一律是" +"以單一字串呈現的兩個因素,即使雙因素驗證是選用的。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:4563 msgid "[prompting/passkey]" -msgstr "" +msgstr "[prompting/passkey]" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:4569 sssd-ad.5.xml:1022 msgid "interactive" -msgstr "" +msgstr "interactive" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4571 @@ -5302,38 +5992,40 @@ msgid "" "of a passkey device. Recommended if your device doesn’t have a tactile " "trigger." msgstr "" +"布林值,若為 True,則在測試 passkey 裝置是否存在之前,先顯示訊息並等待。若您" +"的裝置沒有觸覺觸發器,建議使用此選項。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:4579 msgid "interactive_prompt" -msgstr "" +msgstr "interactive_prompt" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4581 msgid "to change the message of the interactive prompt." -msgstr "" +msgstr "變更互動提示的訊息。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:4586 msgid "touch" -msgstr "" +msgstr "touch" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4588 msgid "" "boolean value, if True prompt a message to remind the user to touch the " "device." -msgstr "" +msgstr "布林值,若為 True,則顯示訊息提醒使用者觸碰裝置。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:4594 msgid "touch_prompt" -msgstr "" +msgstr "touch_prompt" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4596 msgid "to change the message of the touch prompt." -msgstr "" +msgstr "變更觸碰提示的訊息。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4565 @@ -5341,6 +6033,8 @@ msgid "" "to configure passkey authentication prompting, allowed options are: " "<placeholder type=\"variablelist\" id=\"0\"/>" msgstr "" +"設定 passkey 驗證提示,允許的選項有:<placeholder type=\"variablelist\" " +"id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:4505 @@ -5350,6 +6044,10 @@ msgid "" "type=\"variablelist\" id=\"0\"/> <placeholder type=\"variablelist\" " "id=\"1\"/> <placeholder type=\"variablelist\" id=\"2\"/>" msgstr "" +"每個支援的驗證方法在 <quote>[prompting/...]</quote> 下都有自己的設定子區段。" +"目前有:<placeholder type=\"variablelist\" id=\"0\"/> <placeholder " +"type=\"variablelist\" id=\"1\"/> <placeholder type=\"variablelist\" " +"id=\"2\"/>" #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:4607 @@ -5358,11 +6056,13 @@ msgid "" "e.g. <quote>[prompting/password/sshd]</quote> to individual change the " "prompting for this service." msgstr "" +"可以為特定的 PAM 服務加入子區段,例如 <quote>[prompting/password/sshd]</" +"quote>,以個別變更此服務的提示。" #. type: Content of: <reference><refentry><refsect1><title> #: sssd.conf.5.xml:4614 pam_sss_gss.8.xml:157 idmap_sss.8.xml:43 msgid "EXAMPLES" -msgstr "" +msgstr "範例" #. type: Content of: <reference><refentry><refsect1><para><programlisting> #: sssd.conf.5.xml:4620 @@ -5392,6 +6092,29 @@ msgid "" "max_id = 20000\n" "enumerate = False\n" msgstr "" +"[sssd]\n" +"domains = LDAP\n" +"services = nss, pam\n" +"\n" +"[nss]\n" +"filter_groups = root\n" +"filter_users = root\n" +"\n" +"[pam]\n" +"\n" +"[domain/LDAP]\n" +"id_provider = ldap\n" +"ldap_uri = ldap://ldap.example.com\n" +"ldap_search_base = dc=example,dc=com\n" +"\n" +"auth_provider = krb5\n" +"krb5_server = kerberos.example.com\n" +"krb5_realm = EXAMPLE.COM\n" +"cache_credentials = true\n" +"\n" +"min_id = 10000\n" +"max_id = 20000\n" +"enumerate = False\n" #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:4616 @@ -5401,6 +6124,8 @@ msgid "" "configuring domains for more details. <placeholder type=\"programlisting\" " "id=\"0\"/>" msgstr "" +"1. 下列範例顯示典型的 SSSD 設定。它沒有描述網域本身的設定——關於設定網域的更多" +"詳細資料,請參閱相關文件。<placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><programlisting> #: sssd.conf.5.xml:4652 @@ -5409,6 +6134,8 @@ msgid "" "[domain/ipa.com/child.ad.com]\n" "use_fully_qualified_names = false\n" msgstr "" +"[domain/ipa.com/child.ad.com]\n" +"use_fully_qualified_names = false\n" #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:4646 @@ -5420,6 +6147,10 @@ msgid "" "configuration should be used. <placeholder type=\"programlisting\" " "id=\"0\"/>" msgstr "" +"2. 下列範例顯示 IPA AD 信任的設定,其中 AD 樹系由兩個以父子結構組成的網域構成" +"。假設 IPA 網域 (ipa.com) 與 AD 網域 (ad.com) 有信任關係。ad.com 有子網域 " +"(child.ad.com)。若要在子網域啟用簡短名稱,應使用下列設定。<placeholder " +"type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><programlisting> #: sssd.conf.5.xml:4663 @@ -5431,6 +6162,11 @@ msgid "" "domains = my.domain, your.domain\n" "priority = 10\n" msgstr "" +"[certmap/my.domain/rule_name]\n" +"matchrule = <ISSUER>^CN=My-CA,DC=MY,DC=DOMAIN$\n" +"maprule = (userCertificate;binary={cert!bin})\n" +"domains = my.domain, your.domain\n" +"priority = 10\n" #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:4657 @@ -5441,16 +6177,19 @@ msgid "" "certificate in the search filter. <placeholder type=\"programlisting\" " "id=\"0\"/>" msgstr "" +"3. 下列範例顯示憑證對應規則的設定。它適用於設定的網域 <quote>my.domain</" +"quote>,也適用於子網域 <quote>your.domain</quote>,並在搜尋篩選器中使用完整憑" +"證。<placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refnamediv><refname> #: sssd-ldap.5.xml:10 sssd-ldap.5.xml:16 msgid "sssd-ldap" -msgstr "" +msgstr "sssd-ldap" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sssd-ldap.5.xml:17 msgid "SSSD LDAP provider" -msgstr "" +msgstr "SSSD LDAP 提供者" #. type: Content of: <reference><refentry><refsect1><title> #: sssd-ldap.5.xml:21 pam_sss.8.xml:63 pam_sss_gss.8.xml:30 @@ -5464,7 +6203,7 @@ msgstr "" #: sssd-session-recording.5.xml:21 sssd-kcm.8.xml:21 sssd-systemtap.5.xml:21 #: sssd-ldap-attributes.5.xml:21 sssd_krb5_localauth_plugin.8.xml:20 msgid "DESCRIPTION" -msgstr "" +msgstr "說明" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ldap.5.xml:23 @@ -5476,11 +6215,15 @@ msgid "" "<manvolnum>5</manvolnum> </citerefentry> manual page for detailed syntax " "information." msgstr "" +"本手冊頁說明 <citerefentry> <refentrytitle>sssd</refentrytitle> <manvolnum>" +"8</manvolnum> </citerefentry> 之 LDAP 網域的設定。詳細的語法資訊請參閱 " +"<citerefentry> <refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry> 手冊頁的 <quote>FILE FORMAT</quote> 一節。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ldap.5.xml:35 msgid "You can configure SSSD to use more than one LDAP domain." -msgstr "" +msgstr "您可以設定 SSSD 使用多個 LDAP 網域。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ldap.5.xml:38 @@ -5493,18 +6236,23 @@ msgid "" "recommended. Please refer to the <quote>ldap_access_filter</quote> config " "option for more information about using LDAP as an access provider." msgstr "" +"LDAP 後端支援 id、auth、access 與 chpass 提供者。若您想針對 LDAP 伺服器進行驗" +"證,需要 TLS/SSL 或 LDAPS。<command>sssd</command> <emphasis>不</emphasis>支" +"援透過未加密通道進行驗證。即使 LDAP 伺服器只用來當作身分提供者,也強烈建議使" +"用加密通道。有關將 LDAP 用作 access 提供者的更多資訊,請參閱 <quote>" +"ldap_access_filter</quote> 設定選項。" #. type: Content of: <reference><refentry><refsect1><title> #: sssd-ldap.5.xml:50 sssd-simple.5.xml:69 sssd-ipa.5.xml:82 sssd-ad.5.xml:130 #: sssd-krb5.5.xml:63 sssd-ifp.5.xml:60 sssd-files.5.xml:77 #: sssd-session-recording.5.xml:58 sssd-kcm.8.xml:202 msgid "CONFIGURATION OPTIONS" -msgstr "" +msgstr "設定選項" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:67 msgid "ldap_uri, ldap_backup_uri (string)" -msgstr "" +msgstr "ldap_uri, ldap_backup_uri (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:70 @@ -5516,31 +6264,34 @@ msgid "" "enabled. For more information, refer to the <quote>SERVICE DISCOVERY</quote> " "section." msgstr "" +"指定 SSSD 應依偏好順序連線之 LDAP 伺服器的 URI 逗號分隔清單。有關故障轉移與伺" +"服器備援的更多資訊,請參閱 <quote>FAILOVER</quote> 一節。若兩個選項都未指定," +"則啟用服務探索。更多資訊請參閱 <quote>SERVICE DISCOVERY</quote> 一節。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:77 msgid "The format of the URI must match the format defined in RFC 2732:" -msgstr "" +msgstr "URI 的格式必須符合 RFC 2732 定義的格式:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:80 msgid "ldap[s]://<host>[:port]" -msgstr "" +msgstr "ldap[s]://<host>[:port]" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:83 msgid "For explicit IPv6 addresses, <host> must be enclosed in brackets []" -msgstr "" +msgstr "對於明確的 IPv6 位址,<host> 必須以方括號 [] 括起來" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:86 msgid "example: ldap://[fc00::126:25]:389" -msgstr "" +msgstr "example: ldap://[fc00::126:25]:389" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:92 msgid "ldap_chpass_uri, ldap_chpass_backup_uri (string)" -msgstr "" +msgstr "ldap_chpass_uri, ldap_chpass_backup_uri (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:95 @@ -5550,56 +6301,58 @@ msgid "" "user. Refer to the <quote>FAILOVER</quote> section for more information on " "failover and server redundancy." msgstr "" +"指定 SSSD 應依偏好順序連線以變更使用者密碼之 LDAP 伺服器的 URI 逗號分隔清單。" +"有關故障轉移與伺服器備援的更多資訊,請參閱 <quote>FAILOVER</quote> 一節。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:102 msgid "To enable service discovery ldap_chpass_dns_service_name must be set." -msgstr "" +msgstr "若要啟用服務探索,必須設定 ldap_chpass_dns_service_name。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:106 msgid "Default: empty, i.e. ldap_uri is used." -msgstr "" +msgstr "預設:空白,也就是使用 ldap_uri。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:112 msgid "ldap_search_base (string)" -msgstr "" +msgstr "ldap_search_base (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:115 msgid "The default base DN to use for performing LDAP user operations." -msgstr "" +msgstr "執行 LDAP 使用者作業時使用的預設基礎 DN。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:119 msgid "" "Starting with SSSD 1.7.0, SSSD supports multiple search bases using the " "syntax:" -msgstr "" +msgstr "從 SSSD 1.7.0 開始,SSSD 支援使用下列語法的多個搜尋基礎:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:123 msgid "search_base[?scope?[filter][?search_base?scope?[filter]]*]" -msgstr "" +msgstr "search_base[?scope?[filter][?search_base?scope?[filter]]*]" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:126 msgid "The scope can be one of \"base\", \"onelevel\" or \"subtree\"." -msgstr "" +msgstr "scope 可以是 \"base\"、\"onelevel\" 或 \"subtree\" 之一。" #. type: Content of: <listitem><para> #: sssd-ldap.5.xml:129 include/ldap_search_bases.xml:18 msgid "" "The filter must be a valid LDAP search filter as specified by " "http://www.ietf.org/rfc/rfc2254.txt" -msgstr "" +msgstr "filter 必須是 http://www.ietf.org/rfc/rfc2254.txt 指定的有效 LDAP 搜尋篩選器" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:133 sssd-ad.5.xml:312 sss_override.8.xml:143 #: sss_override.8.xml:240 sssd-ldap-attributes.5.xml:453 msgid "Examples:" -msgstr "" +msgstr "範例:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:136 @@ -5607,6 +6360,8 @@ msgid "" "ldap_search_base = dc=example,dc=com (which is equivalent to) " "ldap_search_base = dc=example,dc=com?subtree?" msgstr "" +"ldap_search_base = dc=example,dc=com(等同於) ldap_search_base = " +"dc=example,dc=com?subtree?" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:141 @@ -5614,6 +6369,8 @@ msgid "" "ldap_search_base = " "cn=host_specific,dc=example,dc=com?subtree?(host=thishost)?dc=example.com?subtree?" msgstr "" +"ldap_search_base = cn=host_specific,dc=example,dc=com?subtree?(host=thishost)" +"?dc=example.com?subtree?" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:144 @@ -5623,6 +6380,8 @@ msgid "" "different search bases). This will lead to unpredictable behavior on client " "machines." msgstr "" +"注意:不支援多個搜尋基礎參照同名物件(例如,兩個不同搜尋基礎中名稱相同的群組" +")。這會導致用戶端機器上出現不可預期的行為。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:151 @@ -5634,11 +6393,15 @@ msgid "" "the search base of the LDAP server to make this work. Multiple values are " "are not supported." msgstr "" +"預設:若未設定,則使用 LDAP 伺服器 RootDSE 中 defaultNamingContext 或 " +"namingContexts 屬性的值。若 defaultNamingContext 不存在或值為空白,則使用 " +"namingContexts。要讓此功能運作,namingContexts 屬性必須有單一值,即 LDAP 伺服" +"器搜尋基礎的 DN。不支援多個值。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:165 msgid "ldap_schema (string)" -msgstr "" +msgstr "ldap_schema (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:168 @@ -5647,21 +6410,23 @@ msgid "" "the selected schema, the default attribute names retrieved from the servers " "may vary. The way that some attributes are handled may also differ." msgstr "" +"指定目標 LDAP 伺服器使用的綱要類型。視選取的綱要而定,從伺服器取回的預設屬性" +"名稱可能會有所不同。某些屬性的處理方式也可能不同。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:175 msgid "Four schema types are currently supported:" -msgstr "" +msgstr "目前支援四種綱要類型:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ldap.5.xml:179 msgid "rfc2307" -msgstr "" +msgstr "rfc2307" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ldap.5.xml:184 msgid "rfc2307bis" -msgstr "" +msgstr "rfc2307bis" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:200 @@ -5673,36 +6438,40 @@ msgid "" "attribute. The AD schema type sets the attributes to correspond with Active " "Directory 2008r2 values." msgstr "" +"這些綱要類型之間的主要差異在於群組成員在伺服器中的記錄方式。使用 rfc2307 時," +"群組成員依名稱列在 <emphasis>memberUid</emphasis> 屬性中。使用 rfc2307bis 與 " +"IPA 時,群組成員依 DN 列出並儲存在 <emphasis>member</emphasis> 屬性中。AD 綱" +"要類型會將屬性設為對應 Active Directory 2008r2 的值。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:210 msgid "Default: rfc2307" -msgstr "" +msgstr "預設:rfc2307" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:216 msgid "ldap_pwmodify_mode (string)" -msgstr "" +msgstr "ldap_pwmodify_mode (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:219 msgid "Specify the operation that is used to modify user password." -msgstr "" +msgstr "指定用來修改使用者密碼的作業。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:223 msgid "Two modes are currently supported:" -msgstr "" +msgstr "目前支援兩種模式:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ldap.5.xml:227 msgid "exop - Password Modify Extended Operation (RFC 3062)" -msgstr "" +msgstr "exop - 密碼修改延伸作業 (RFC 3062)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ldap.5.xml:233 msgid "ldap_modify - Direct modification of userPassword (not recommended)." -msgstr "" +msgstr "ldap_modify - 直接修改 userPassword(不建議)。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:240 @@ -5712,51 +6481,54 @@ msgid "" "connection is used to change the password therefore the user must have write " "access to userPassword attribute." msgstr "" +"注意:首先,會建立新連線,以要求變更密碼的使用者身分繫結來驗證目前的密碼。若" +"成功,此連線會用來變更密碼,因此使用者必須具有 userPassword 屬性的寫入存取權" +"。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:248 msgid "Default: exop" -msgstr "" +msgstr "預設:exop" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:254 msgid "ldap_default_bind_dn (string)" -msgstr "" +msgstr "ldap_default_bind_dn (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:257 msgid "The default bind DN to use for performing LDAP operations." -msgstr "" +msgstr "執行 LDAP 作業時使用的預設繫結 DN。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:264 msgid "ldap_default_authtok_type (string)" -msgstr "" +msgstr "ldap_default_authtok_type (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:267 msgid "The type of the authentication token of the default bind DN." -msgstr "" +msgstr "預設繫結 DN 的驗證權杖類型。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:271 msgid "The two mechanisms currently supported are:" -msgstr "" +msgstr "目前支援的兩種機制是:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:274 msgid "password" -msgstr "" +msgstr "password" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:277 msgid "obfuscated_password" -msgstr "" +msgstr "obfuscated_password" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:280 msgid "Default: password" -msgstr "" +msgstr "預設:password" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:283 @@ -5764,21 +6536,23 @@ msgid "" "See the <citerefentry> <refentrytitle>sss_obfuscate</refentrytitle> " "<manvolnum>8</manvolnum> </citerefentry> manual page for more information." msgstr "" +"更多資訊請參閱 <citerefentry> <refentrytitle>sss_obfuscate</refentrytitle> " +"<manvolnum>8</manvolnum> </citerefentry> 手冊頁。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:294 msgid "ldap_default_authtok (string)" -msgstr "" +msgstr "ldap_default_authtok (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:297 msgid "The authentication token of the default bind DN." -msgstr "" +msgstr "預設繫結 DN 的驗證權杖。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:303 msgid "ldap_force_upper_case_realm (boolean)" -msgstr "" +msgstr "ldap_force_upper_case_realm (boolean)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:306 @@ -5788,23 +6562,25 @@ msgid "" "fail. Set this option to a non-zero value if you want to use an upper-case " "realm." msgstr "" +"某些目錄伺服器(例如 Active Directory)可能以小寫傳送 UPN 的 realm 部分,這可" +"能導致驗證失敗。若您想使用大寫的 realm,請將此選項設為非零值。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:319 msgid "ldap_enumeration_refresh_timeout (integer)" -msgstr "" +msgstr "ldap_enumeration_refresh_timeout (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:322 msgid "" "Specifies how many seconds SSSD has to wait before refreshing its cache of " "enumerated records." -msgstr "" +msgstr "指定 SSSD 在重新整理列舉記錄快取之前必須等待的秒數。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:338 msgid "ldap_purge_cache_timeout (integer)" -msgstr "" +msgstr "ldap_purge_cache_timeout (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:341 @@ -5813,6 +6589,8 @@ msgid "" "with no members and users who have never logged in) and remove them to save " "space." msgstr "" +"決定多久檢查一次快取中的非使用中項目(例如沒有成員的群組與從未登入的使用者)" +",並移除它們以節省空間。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:347 @@ -5822,11 +6600,14 @@ msgid "" "to detect entries removed from the server and can't be disabled. By default, " "the cleanup task will run every 3 hours with enumeration enabled." msgstr "" +"將此選項設為零會停用快取清理作業。請注意,若啟用列舉,則需要清理工作才能偵測" +"已從伺服器移除的項目,且無法停用。預設情況下,啟用列舉時,清理工作每 3 小時執" +"行一次。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:367 msgid "ldap_group_nesting_level (integer)" -msgstr "" +msgstr "ldap_group_nesting_level (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:370 @@ -5835,6 +6616,8 @@ msgid "" "(e.g. RFC2307bis), then this option controls how many levels of nesting SSSD " "will follow. This option has no effect on the RFC2307 schema." msgstr "" +"若 ldap_schema 設為支援巢狀群組的綱要格式(例如 RFC2307bis),則此選項控制 " +"SSSD 會追蹤多少層巢狀。此選項對 RFC2307 綱要沒有影響。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:377 @@ -5845,6 +6628,9 @@ msgid "" "the deeper nesting levels. Also, subsequent lookups for other groups may " "enlarge the result set for original lookup if re-queried." msgstr "" +"注意:此選項指定任何查詢都會處理的保證巢狀群組層級。不過,若先前的查詢已經解" +"析較深的巢狀層級,超過此限制的巢狀群組<emphasis>可能</emphasis>會被傳回。此外" +",若重新查詢,對其他群組的後續查詢可能擴大原始查詢的結果集。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:386 @@ -5855,11 +6641,15 @@ msgid "" "usage of Token-Groups by setting ldap_use_tokengroups to false in order to " "restrict group nesting." msgstr "" +"若 ldap_group_nesting_level 設為 0,則完全不會處理巢狀群組。不過,使用 " +"<quote>id_provider=ad</quote> 連線到 Active Directory Server 2008 及更新版本" +"時,還需要將 ldap_use_tokengroups 設為 false 來停用 Token-Groups 的使用,以限" +"制群組巢狀。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:395 msgid "Default: 2" -msgstr "" +msgstr "預設:2" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:404 @@ -5867,21 +6657,23 @@ msgid "" "This options enables or disables use of Token-Groups attribute when " "performing initgroup for users from Active Directory Server 2008 and later." msgstr "" +"此選項啟用或停用在對 Active Directory Server 2008 及更新版本的使用者執行 " +"initgroup 時對 Token-Groups 屬性的使用。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:414 msgid "Default: True for AD and IPA otherwise False." -msgstr "" +msgstr "預設:AD 與 IPA 為 True,其他情況為 False。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:420 msgid "ldap_host_search_base (string)" -msgstr "" +msgstr "ldap_host_search_base (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:423 msgid "Optional. Use the given string as search base for host objects." -msgstr "" +msgstr "選用。使用指定的字串作為主機物件的搜尋基礎。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:427 sssd-ipa.5.xml:462 sssd-ipa.5.xml:481 sssd-ipa.5.xml:500 @@ -5889,32 +6681,32 @@ msgstr "" msgid "" "See <quote>ldap_search_base</quote> for information about configuring " "multiple search bases." -msgstr "" +msgstr "有關設定多個搜尋基礎的資訊,請參閱 <quote>ldap_search_base</quote>。" #. type: Content of: <listitem><para> #: sssd-ldap.5.xml:432 sssd-ipa.5.xml:467 include/ldap_search_bases.xml:27 msgid "Default: the value of <emphasis>ldap_search_base</emphasis>" -msgstr "" +msgstr "預設:<emphasis>ldap_search_base</emphasis> 的值" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:439 msgid "ldap_service_search_base (string)" -msgstr "" +msgstr "ldap_service_search_base (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:444 msgid "ldap_iphost_search_base (string)" -msgstr "" +msgstr "ldap_iphost_search_base (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:449 msgid "ldap_ipnetwork_search_base (string)" -msgstr "" +msgstr "ldap_ipnetwork_search_base (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:454 msgid "ldap_search_timeout (integer)" -msgstr "" +msgstr "ldap_search_timeout (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:457 @@ -5922,7 +6714,7 @@ msgid "" "Specifies the timeout (in seconds) that ldap searches are allowed to run " "before they are cancelled and cached results are returned (and offline mode " "is entered)" -msgstr "" +msgstr "指定 LDAP 搜尋在取消並傳回快取結果(並進入離線模式)之前允許執行的逾時(秒)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:463 @@ -5931,11 +6723,13 @@ msgid "" "will likely be replaced at some point by a series of timeouts for specific " "lookup types." msgstr "" +"注意:此選項在 SSSD 未來的版本中可能會變更。未來某個時間點它可能會被一系列針" +"對特定查詢類型的逾時取代。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:480 msgid "ldap_enumeration_search_timeout (integer)" -msgstr "" +msgstr "ldap_enumeration_search_timeout (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:483 @@ -5944,11 +6738,13 @@ msgid "" "enumerations are allowed to run before they are cancelled and cached results " "are returned (and offline mode is entered)" msgstr "" +"指定使用者與群組列舉的 LDAP 搜尋在取消並傳回快取結果(並進入離線模式)之前允" +"許執行的逾時(秒)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:501 msgid "ldap_network_timeout (integer)" -msgstr "" +msgstr "ldap_network_timeout (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:504 @@ -5960,11 +6756,16 @@ msgid "" "<refentrytitle>connect</refentrytitle> <manvolnum>2</manvolnum> " "</citerefentry> returns in case of no activity." msgstr "" +"指定逾時(秒),超過此時間後,若沒有活動,<citerefentry> <refentrytitle>" +"connect</refentrytitle> <manvolnum>2</manvolnum> </citerefentry> 之後的 " +"<citerefentry> <refentrytitle>poll</refentrytitle> <manvolnum>2</manvolnum> " +"</citerefentry>/<citerefentry> <refentrytitle>select</refentrytitle> " +"<manvolnum>2</manvolnum> </citerefentry> 會傳回。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:532 msgid "ldap_opt_timeout (integer)" -msgstr "" +msgstr "ldap_opt_timeout (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:535 @@ -5974,11 +6775,14 @@ msgid "" "communicating with the KDC in case of SASL bind, the timeout of an LDAP bind " "operation, password change extended operation and the StartTLS operation." msgstr "" +"指定逾時(秒),超過此時間後,若沒有收到回應,對同步 LDAP API 的呼叫會中止。" +"也控制 SASL 繫結時與 KDC 通訊的逾時、LDAP 繫結作業的逾時、密碼變更延伸作業與 " +"StartTLS 作業的逾時。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:555 msgid "ldap_connection_expire_timeout (integer)" -msgstr "" +msgstr "ldap_connection_expire_timeout (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:558 @@ -5988,6 +6792,8 @@ msgid "" "in parallel with SASL/GSSAPI, the sooner of the two values (this value " "vs. the TGT lifetime) will be used." msgstr "" +"指定 LDAP 伺服器連線將維持的逾時(秒)。超過此時間後,會重新建立連線。若與 " +"SASL/GSSAPI 並行使用,會採用兩個值(此值與 TGT 存留時間)中較早的一個。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:566 @@ -5999,6 +6805,10 @@ msgid "" "be closed immediately and will never be reused if " "<emphasis>ldap_connection_expire_timeout <= ldap_opt_timout</emphasis>" msgstr "" +"若連線在到期前的 <emphasis>ldap_opt_timeout</emphasis> 秒內處於閒置狀態(未在" +"執行作業),則會提早關閉,以確保新查詢無法要求連線在到期後仍保持開啟。這表示" +"若 <emphasis>ldap_connection_expire_timeout <= ldap_opt_timout</emphasis>" +",連線一律會立即關閉,且絕不會重複使用。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:578 @@ -6006,16 +6816,18 @@ msgid "" "This timeout can be extended of a random value specified by " "<emphasis>ldap_connection_expire_offset</emphasis>" msgstr "" +"此逾時可以延長 <emphasis>ldap_connection_expire_offset</emphasis> 指定的隨機" +"值" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:588 sssd-ldap.5.xml:631 sssd-ldap.5.xml:1749 msgid "Default: 900 (15 minutes)" -msgstr "" +msgstr "預設:900(15 分鐘)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:594 msgid "ldap_connection_expire_offset (integer)" -msgstr "" +msgstr "ldap_connection_expire_offset (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:597 @@ -6023,11 +6835,13 @@ msgid "" "Random offset between 0 and configured value is added to " "<emphasis>ldap_connection_expire_timeout</emphasis>." msgstr "" +"會將介於 0 與設定值之間的隨機偏移加到 <emphasis>" +"ldap_connection_expire_timeout</emphasis>。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:613 msgid "ldap_connection_idle_timeout (integer)" -msgstr "" +msgstr "ldap_connection_idle_timeout (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:616 @@ -6036,28 +6850,30 @@ msgid "" "will be maintained. If the connection is idle for more than this time then " "the connection will be closed." msgstr "" +"指定 LDAP 伺服器閒置連線將維持的逾時(秒)。若連線閒置超過此時間,則連線會關" +"閉。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:622 msgid "You can disable this timeout by setting the value to 0." -msgstr "" +msgstr "您可以將值設為 0 來停用此逾時。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:637 msgid "ldap_page_size (integer)" -msgstr "" +msgstr "ldap_page_size (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:640 msgid "" "Specify the number of records to retrieve from LDAP in a single " "request. Some LDAP servers enforce a maximum limit per-request." -msgstr "" +msgstr "指定單一要求中從 LDAP 取回的記錄數目。某些 LDAP 伺服器會強制每個要求的上限。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:651 msgid "ldap_disable_paging (boolean)" -msgstr "" +msgstr "ldap_disable_paging (boolean)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:654 @@ -6066,6 +6882,8 @@ msgid "" "server reports that it supports the LDAP paging control in its RootDSE but " "it is not enabled or does not behave properly." msgstr "" +"停用 LDAP 分頁控制。若 LDAP 伺服器在其 RootDSE 中回報支援 LDAP 分頁控制,但未" +"啟用或行為不正常,應使用此選項。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:660 @@ -6074,6 +6892,8 @@ msgid "" "server but not enabled will report it in the RootDSE but be unable to use " "it." msgstr "" +"範例:伺服器上安裝了分頁控制模組但未啟用的 OpenLDAP 伺服器,會在 RootDSE 中回" +"報該模組,但無法使用它。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:666 @@ -6082,16 +6902,18 @@ msgid "" "a time on a single connection. On busy clients, this can result in some " "requests being denied." msgstr "" +"範例:389 DS 有一個錯誤,在單一連線上一次只能支援一個分頁控制。在忙碌的用戶端" +"上,這可能導致部分要求被拒絕。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:678 msgid "ldap_disable_range_retrieval (boolean)" -msgstr "" +msgstr "ldap_disable_range_retrieval (boolean)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:681 msgid "Disable Active Directory range retrieval." -msgstr "" +msgstr "停用 Active Directory 範圍取回。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:684 @@ -6102,11 +6924,14 @@ msgid "" "extension. This option disables parsing of the range extension, therefore " "large groups will appear as having no members." msgstr "" +"Active Directory 使用 MaxValRange 原則(預設為 1500 個成員)限制單一查詢中取" +"回的成員數目。若群組包含更多成員,回覆會包含 AD 特定的範圍延伸。此選項停用範" +"圍延伸的剖析,因此大型群組看起來會像是沒有成員。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:699 msgid "ldap_sasl_minssf (integer)" -msgstr "" +msgstr "ldap_sasl_minssf (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:702 @@ -6115,16 +6940,18 @@ msgid "" "security level necessary to establish the connection. The values of this " "option are defined by OpenLDAP." msgstr "" +"使用 SASL 與 LDAP 伺服器通訊時,指定建立連線所需的最低安全性層級。此選項的值" +"由 OpenLDAP 定義。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:708 sssd-ldap.5.xml:724 msgid "Default: Use the system default (usually specified by ldap.conf)" -msgstr "" +msgstr "預設:使用系統預設值(通常由 ldap.conf 指定)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:715 msgid "ldap_sasl_maxssf (integer)" -msgstr "" +msgstr "ldap_sasl_maxssf (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:718 @@ -6133,11 +6960,13 @@ msgid "" "security level necessary to establish the connection. The values of this " "option are defined by OpenLDAP." msgstr "" +"使用 SASL 與 LDAP 伺服器通訊時,指定建立連線所需的最大安全性層級。此選項的值" +"由 OpenLDAP 定義。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:731 msgid "ldap_deref_threshold (integer)" -msgstr "" +msgstr "ldap_deref_threshold (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:734 @@ -6146,6 +6975,8 @@ msgid "" "cache in order to trigger a dereference lookup. If less members are missing, " "they are looked up individually." msgstr "" +"指定要觸發解除參照查詢時,內部快取中必須缺少的群組成員數目。若缺少的成員較少" +",則會個別查詢它們。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:740 @@ -6157,6 +6988,9 @@ msgid "" "the server supports it and advertises the dereference control in the rootDSE " "object." msgstr "" +"您可以將值設為 0 來完全關閉解除參照查詢。請注意,SSSD 中有些程式碼路徑(例如 " +"IPA HBAC 提供者)只使用解除參照呼叫來實作,因此即使明確停用解除參照,若伺服器" +"支援且在 rootDSE 物件中公告解除參照控制,這些部分仍會使用解除參照。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:751 @@ -6166,6 +7000,9 @@ msgid "" "methods. The currently supported servers are 389/RHDS, OpenLDAP and Active " "Directory." msgstr "" +"解除參照查詢是在單一 LDAP 呼叫中取回所有群組成員的方法。不同的 LDAP 伺服器可" +"能實作不同的解除參照方法。目前支援的伺服器是 389/RHDS、OpenLDAP 與 Active " +"Directory。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:759 @@ -6174,11 +7011,13 @@ msgid "" "filter, then the dereference lookup performance enhancement will be disabled " "regardless of this setting." msgstr "" +"<emphasis>注意:</emphasis>若任何搜尋基礎指定了搜尋篩選器,則無論此設定為何," +"解除參照查詢效能增強都會被停用。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:772 msgid "ldap_ignore_unreadable_references (bool)" -msgstr "" +msgstr "ldap_ignore_unreadable_references (bool)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:775 @@ -6187,6 +7026,8 @@ msgid "" "this parameter is set to false an error will be returned and the operation " "will fail instead of just ignoring the unreadable entry." msgstr "" +"忽略群組 member 屬性中參照的無法讀取 LDAP 項目。若此參數設為 false,會傳回錯" +"誤且作業會失敗,而不是只忽略無法讀取的項目。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:782 @@ -6195,25 +7036,27 @@ msgid "" "account that sssd uses to connect to AD does not have access to a particular " "entry or LDAP sub-tree for security reasons." msgstr "" +"當使用 AD 提供者,且 sssd 用來連線到 AD 的電腦帳戶基於安全性考量沒有特定項目" +"或 LDAP 子樹的存取權時,此參數可能很有用。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:795 msgid "ldap_tls_reqcert (string)" -msgstr "" +msgstr "ldap_tls_reqcert (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:798 msgid "" "Specifies what checks to perform on server certificates in a TLS session, if " "any. It can be specified as one of the following values:" -msgstr "" +msgstr "指定在 TLS 工作階段中對伺服器憑證執行哪些檢查(若有)。可以指定為下列值之一:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:804 msgid "" "<emphasis>never</emphasis> = The client will not request or check any server " "certificate." -msgstr "" +msgstr "<emphasis>never</emphasis> = 用戶端不會要求或檢查任何伺服器憑證。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:808 @@ -6222,6 +7065,8 @@ msgid "" "certificate is provided, the session proceeds normally. If a bad certificate " "is provided, it will be ignored and the session proceeds normally." msgstr "" +"<emphasis>allow</emphasis> = 會要求伺服器憑證。若未提供憑證,工作階段會正常繼" +"續。若提供的憑證不良,它會被忽略,工作階段會正常繼續。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:815 @@ -6230,6 +7075,8 @@ msgid "" "certificate is provided, the session proceeds normally. If a bad certificate " "is provided, the session is immediately terminated." msgstr "" +"<emphasis>try</emphasis> = 會要求伺服器憑證。若未提供憑證,工作階段會正常繼續" +"。若提供的憑證不良,工作階段會立即終止。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:821 @@ -6238,28 +7085,30 @@ msgid "" "certificate is provided, or a bad certificate is provided, the session is " "immediately terminated." msgstr "" +"<emphasis>demand</emphasis> = 會要求伺服器憑證。若未提供憑證,或提供的憑證不" +"良,工作階段會立即終止。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:827 msgid "<emphasis>hard</emphasis> = Same as <quote>demand</quote>" -msgstr "" +msgstr "<emphasis>hard</emphasis> = 與 <quote>demand</quote> 相同" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:831 msgid "Default: hard" -msgstr "" +msgstr "預設:hard" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:837 msgid "ldap_tls_cacert (string)" -msgstr "" +msgstr "ldap_tls_cacert (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:840 msgid "" "Specifies the file that contains certificates for all of the Certificate " "Authorities that <command>sssd</command> will recognize." -msgstr "" +msgstr "指定包含 <command>sssd</command> 會識別之所有憑證授權單位憑證的檔案。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:845 sssd-ldap.5.xml:864 sssd-ldap.5.xml:905 @@ -6267,11 +7116,13 @@ msgid "" "Default: use OpenLDAP defaults, typically in " "<filename>/etc/openldap/ldap.conf</filename>" msgstr "" +"預設:使用 OpenLDAP 預設值,通常在 <filename>/etc/openldap/ldap.conf</" +"filename>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:852 msgid "ldap_tls_cacertdir (string)" -msgstr "" +msgstr "ldap_tls_cacertdir (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:855 @@ -6282,31 +7133,34 @@ msgid "" "<command>openssl rehash</command> or <command>c_rehash</command> can be used " "to create the correct names." msgstr "" +"指定包含個別憑證授權單位憑證檔案的目錄路徑。通常檔案名稱必須是憑證的雜湊值後" +"接 '.0'。若可用,可以使用 <command>openssl rehash</command> 或 <command>" +"c_rehash</command> 建立正確的名稱。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:871 msgid "ldap_tls_cert (string)" -msgstr "" +msgstr "ldap_tls_cert (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:874 msgid "Specifies the file that contains the certificate for the client's key." -msgstr "" +msgstr "指定包含用戶端金鑰憑證的檔案。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:884 msgid "ldap_tls_key (string)" -msgstr "" +msgstr "ldap_tls_key (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:887 msgid "Specifies the file that contains the client's key." -msgstr "" +msgstr "指定包含用戶端金鑰的檔案。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:896 msgid "ldap_tls_cipher_suite (string)" -msgstr "" +msgstr "ldap_tls_cipher_suite (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:899 @@ -6315,11 +7169,14 @@ msgid "" "list. See <citerefentry><refentrytitle>ldap.conf</refentrytitle> " "<manvolnum>5</manvolnum></citerefentry> for format." msgstr "" +"指定可接受的加密套件。通常是以冒號分隔的清單。格式請參閱 <citerefentry>" +"<refentrytitle>ldap.conf</refentrytitle> <manvolnum>5</manvolnum></" +"citerefentry>。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:912 msgid "ldap_id_use_start_tls (boolean)" -msgstr "" +msgstr "ldap_id_use_start_tls (boolean)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:915 @@ -6328,11 +7185,14 @@ msgid "" "class=\"protocol\">tls</systemitem> to protect the channel. " "<emphasis>true</emphasis> is strongly recommended for security reasons." msgstr "" +"指定 id_provider 連線也必須使用 <systemitem class=\"protocol\">tls</" +"systemitem> 來保護通道。基於安全性考量,強烈建議使用 <emphasis>true</" +"emphasis>。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:926 msgid "ldap_id_mapping (boolean)" -msgstr "" +msgstr "ldap_id_mapping (boolean)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:929 @@ -6341,16 +7201,18 @@ msgid "" "ldap_user_objectsid and ldap_group_objectsid attributes instead of relying " "on ldap_user_uid_number and ldap_group_gid_number." msgstr "" +"指定 SSSD 應嘗試從 ldap_user_objectsid 與 ldap_group_objectsid 屬性對應使用者" +"與群組 ID,而不是依賴 ldap_user_uid_number 與 ldap_group_gid_number。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:935 msgid "Currently this feature supports only ActiveDirectory objectSID mapping." -msgstr "" +msgstr "目前此功能只支援 ActiveDirectory objectSID 對應。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:945 msgid "ldap_min_id, ldap_max_id (integer)" -msgstr "" +msgstr "ldap_min_id, ldap_max_id (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:948 @@ -6362,23 +7224,28 @@ msgid "" "can be set to restrict the allowed range for the IDs which are read directly " "from the server. Sub-domains can then pick other ranges to map IDs." msgstr "" +"與 ldap_id_mapping 設為 true 時使用的 SID 型 ID 對應相反," +"ldap_user_uid_number 與 ldap_group_gid_number 允許的 ID 範圍是無限制的。在具" +"有子網域/受信任網域的設定中,這可能導致 ID 衝突。為避免衝突,可以設定 " +"ldap_min_id 與 ldap_max_id 來限制直接從伺服器讀取之 ID 的允許範圍。子網域隨後" +"可以選擇其他範圍來對應 ID。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:960 msgid "Default: not set (both options are set to 0)" -msgstr "" +msgstr "預設:未設定(兩個選項都設為 0)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:966 msgid "ldap_sasl_mech (string)" -msgstr "" +msgstr "ldap_sasl_mech (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:969 msgid "" "Specify the SASL mechanism to use. Currently only GSSAPI and GSS-SPNEGO are " "tested and supported." -msgstr "" +msgstr "指定要使用的 SASL 機制。目前只測試並支援 GSSAPI 與 GSS-SPNEGO。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:973 @@ -6390,11 +7257,15 @@ msgid "" "<citerefentry><refentrytitle>sssd.conf</refentrytitle> " "<manvolnum>5</manvolnum></citerefentry> for details." msgstr "" +"若後端支援子網域,ldap_sasl_mech 的值會自動繼承到子網域。若子網域需要不同的值" +",可以明確為此子網域設定 ldap_sasl_mech 來覆寫。詳情請參閱 <citerefentry>" +"<refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</manvolnum></" +"citerefentry> 中的受信任網域區段。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:989 msgid "ldap_sasl_authid (string)" -msgstr "" +msgstr "ldap_sasl_authid (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> #: sssd-ldap.5.xml:1001 @@ -6408,6 +7279,13 @@ msgid "" "host/*\n" " " msgstr "" +"hostname@REALM\n" +"netbiosname$@REALM\n" +"host/hostname@REALM\n" +"*$@REALM\n" +"host/*@REALM\n" +"host/*\n" +" " #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:992 @@ -6420,16 +7298,21 @@ msgid "" "are used: <placeholder type=\"programlisting\" id=\"0\"/> If none of them " "are found, the first principal in keytab is returned." msgstr "" +"指定要使用的 SASL 授權 ID。使用 GSSAPI/GSS-SPNEGO 時,這代表用於向目錄驗證的 " +"Kerberos principal。此選項可以包含完整的 principal(例如 host/" +"myhost@EXAMPLE.COM)或只包含 principal 名稱(例如 host/myhost)。預設情況下," +"值未設定,會使用下列 principal:<placeholder type=\"programlisting\" " +"id=\"0\"/> 若找不到任何一個,則會傳回 keytab 中的第一個 principal。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1012 msgid "Default: host/hostname@REALM" -msgstr "" +msgstr "預設:host/hostname@REALM" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1018 msgid "ldap_sasl_realm (string)" -msgstr "" +msgstr "ldap_sasl_realm (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1021 @@ -6438,48 +7321,50 @@ msgid "" "the value of krb5_realm. If the ldap_sasl_authid contains the realm as " "well, this option is ignored." msgstr "" +"指定要使用的 SASL realm。若未指定,此選項預設為 krb5_realm 的值。若 " +"ldap_sasl_authid 也包含 realm,則會忽略此選項。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1027 msgid "Default: the value of krb5_realm." -msgstr "" +msgstr "預設:krb5_realm 的值。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1033 msgid "ldap_sasl_canonicalize (boolean)" -msgstr "" +msgstr "ldap_sasl_canonicalize (boolean)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1036 msgid "" "If set to true, the LDAP library would perform a reverse lookup to " "canonicalize the host name during a SASL bind." -msgstr "" +msgstr "若設為 true,LDAP 程式庫會在 SASL 繫結期間執行反向查詢來正規化主機名稱。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1041 msgid "Default: false;" -msgstr "" +msgstr "預設:false;" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1047 msgid "ldap_krb5_keytab (string)" -msgstr "" +msgstr "ldap_krb5_keytab (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1050 msgid "Specify the keytab to use when using SASL/GSSAPI/GSS-SPNEGO." -msgstr "" +msgstr "指定使用 SASL/GSSAPI/GSS-SPNEGO 時要使用的 keytab。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1059 sssd-krb5.5.xml:247 msgid "Default: System keytab, normally <filename>/etc/krb5.keytab</filename>" -msgstr "" +msgstr "預設:系統 keytab,通常是 <filename>/etc/krb5.keytab</filename>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1065 msgid "ldap_krb5_init_creds (boolean)" -msgstr "" +msgstr "ldap_krb5_init_creds (boolean)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1068 @@ -6488,28 +7373,30 @@ msgid "" "action is performed only if SASL is used and the mechanism selected is " "GSSAPI or GSS-SPNEGO." msgstr "" +"指定 id_provider 應初始化 Kerberos 憑證 (TGT)。只有在使用 SASL 且選取的機制" +"是 GSSAPI 或 GSS-SPNEGO 時,才會執行此動作。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1080 msgid "ldap_krb5_ticket_lifetime (integer)" -msgstr "" +msgstr "ldap_krb5_ticket_lifetime (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1083 msgid "" "Specifies the lifetime in seconds of the TGT if GSSAPI or GSS-SPNEGO is " "used." -msgstr "" +msgstr "若使用 GSSAPI 或 GSS-SPNEGO,指定 TGT 的存留時間(秒)。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1092 sssd-ad.5.xml:1253 msgid "Default: 86400 (24 hours)" -msgstr "" +msgstr "預設:86400(24 小時)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1098 sssd-krb5.5.xml:74 msgid "krb5_server, krb5_backup_server (string)" -msgstr "" +msgstr "krb5_server, krb5_backup_server (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1101 @@ -6522,6 +7409,10 @@ msgid "" "discovery is enabled - for more information, refer to the <quote>SERVICE " "DISCOVERY</quote> section." msgstr "" +"指定 SSSD 應依偏好順序連線之 Kerberos 伺服器的 IP 位址或主機名稱逗號分隔清單" +"。有關故障轉移與伺服器備援的更多資訊,請參閱 <quote>FAILOVER</quote> 一節。可" +"以在位址或主機名稱後面附加選用的連接埠號碼(前面加上冒號)。若為空白,則啟用" +"服務探索——更多資訊請參閱 <quote>SERVICE DISCOVERY</quote> 一節。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1113 sssd-krb5.5.xml:89 @@ -6530,6 +7421,8 @@ msgid "" "for DNS entries that specify _udp as the protocol and falls back to _tcp if " "none are found." msgstr "" +"對 KDC 或 kpasswd 伺服器使用服務探索時,SSSD 會先搜尋指定 _udp 為協定的 DNS " +"項目,若找不到,則退回 _tcp。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1118 sssd-krb5.5.xml:94 @@ -6539,26 +7432,28 @@ msgid "" "advised to migrate their config files to use <quote>krb5_server</quote> " "instead." msgstr "" +"此選項在 SSSD 的早期版本中名為 <quote>krb5_kdcip</quote>。雖然暫時仍會識別舊" +"名稱,但建議使用者將設定檔遷移為改用 <quote>krb5_server</quote>。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1127 sssd-ipa.5.xml:531 sssd-krb5.5.xml:103 msgid "krb5_realm (string)" -msgstr "" +msgstr "krb5_realm (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1130 msgid "Specify the Kerberos REALM (for SASL/GSSAPI/GSS-SPNEGO auth)." -msgstr "" +msgstr "指定 Kerberos REALM(用於 SASL/GSSAPI/GSS-SPNEGO 驗證)。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1134 msgid "Default: System defaults, see <filename>/etc/krb5.conf</filename>" -msgstr "" +msgstr "預設:系統預設值,請參閱 <filename>/etc/krb5.conf</filename>" #. type: Content of: <variablelist><varlistentry><term> #: sssd-ldap.5.xml:1140 include/krb5_options.xml:154 msgid "krb5_canonicalize (boolean)" -msgstr "" +msgstr "krb5_canonicalize (boolean)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1143 @@ -6566,11 +7461,13 @@ msgid "" "Specifies if the host principal should be canonicalized when connecting to " "LDAP server. This feature is available with MIT Kerberos >= 1.7" msgstr "" +"指定連線到 LDAP 伺服器時是否應正規化主機 principal。MIT Kerberos >= 1.7 提供" +"此功能" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1155 sssd-krb5.5.xml:336 msgid "krb5_use_kdcinfo (boolean)" -msgstr "" +msgstr "krb5_use_kdcinfo (boolean)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1158 sssd-krb5.5.xml:339 @@ -6581,6 +7478,10 @@ msgid "" "<refentrytitle>krb5.conf</refentrytitle> <manvolnum>5</manvolnum> " "</citerefentry> configuration file." msgstr "" +"指定 SSSD 是否應告知 Kerberos 程式庫要使用哪個 realm 與哪些 KDC。此選項預設為" +"開啟,若您停用它,需要使用 <citerefentry> <refentrytitle>krb5.conf</" +"refentrytitle> <manvolnum>5</manvolnum> </citerefentry> 設定檔來設定 " +"Kerberos 程式庫。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1169 sssd-krb5.5.xml:350 @@ -6590,25 +7491,28 @@ msgid "" "<manvolnum>8</manvolnum> </citerefentry> manual page for more information on " "the locator plugin." msgstr "" +"有關 locator 外掛程式的更多資訊,請參閱 <citerefentry> <refentrytitle>" +"sssd_krb5_locator_plugin</refentrytitle> <manvolnum>8</manvolnum> </" +"citerefentry> 手冊頁。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1183 msgid "ldap_pwd_policy (string)" -msgstr "" +msgstr "ldap_pwd_policy (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1186 msgid "" "Select the policy to evaluate the password expiration on the client " "side. The following values are allowed:" -msgstr "" +msgstr "選取要在用戶端評估密碼到期日的原則。允許下列值:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1191 msgid "" "<emphasis>none</emphasis> - No evaluation on the client side. This option " "cannot disable server-side password policies." -msgstr "" +msgstr "<emphasis>none</emphasis> - 不在用戶端評估。此選項無法停用伺服器端密碼原則。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1196 @@ -6619,6 +7523,9 @@ msgid "" "password has expired. Please see option \"ldap_chpass_update_last_change\" " "as well." msgstr "" +"<emphasis>shadow</emphasis> - 使用 <citerefentry><refentrytitle>shadow</" +"refentrytitle> <manvolnum>5</manvolnum></citerefentry> 樣式屬性評估密碼是否已" +"到期。也請參閱 \"ldap_chpass_update_last_change\" 選項。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1204 @@ -6627,6 +7534,8 @@ msgid "" "to determine if the password has expired. Use chpass_provider=krb5 to update " "these attributes when the password is changed." msgstr "" +"<emphasis>mit_kerberos</emphasis> - 使用 MIT Kerberos 使用的屬性判斷密碼是否" +"已到期。密碼變更時,使用 chpass_provider=krb5 更新這些屬性。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1213 @@ -6634,23 +7543,25 @@ msgid "" "<emphasis>Note</emphasis>: if a password policy is configured on server " "side, it always takes precedence over policy set with this option." msgstr "" +"<emphasis>注意</emphasis>:若在伺服器端設定了密碼原則,它一律優先於使用此選項" +"設定的原則。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1221 msgid "ldap_referrals (boolean)" -msgstr "" +msgstr "ldap_referrals (boolean)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1224 msgid "Specifies whether automatic referral chasing should be enabled." -msgstr "" +msgstr "指定是否應啟用自動追蹤轉介。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1228 msgid "" "Please note that sssd only supports referral chasing when it is compiled " "with OpenLDAP version 2.4.13 or higher." -msgstr "" +msgstr "請注意,只有使用 OpenLDAP 2.4.13 或更高版本編譯時,sssd 才支援追蹤轉介。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1233 @@ -6664,43 +7575,48 @@ msgid "" "able to follow the referral to a different AD DC no additional data would be " "available." msgstr "" +"在大量使用轉介的環境中,追蹤轉介可能造成效能損失,一個明顯的例子是 Microsoft " +"Active Directory。若您的設定實際上不需要使用轉介,將此選項設為 false 可能帶來" +"明顯的效能改善。因此,若 SSSD LDAP 提供者與 Microsoft Active Directory 一起作" +"為後端使用,建議將此選項設為 false。即使 SSSD 可以沿著轉介追蹤到不同的 AD DC" +",也不會有額外的資料可用。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1252 msgid "ldap_dns_service_name (string)" -msgstr "" +msgstr "ldap_dns_service_name (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1255 msgid "Specifies the service name to use when service discovery is enabled." -msgstr "" +msgstr "指定啟用服務探索時要使用的服務名稱。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1259 msgid "Default: ldap" -msgstr "" +msgstr "預設:ldap" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1265 msgid "ldap_chpass_dns_service_name (string)" -msgstr "" +msgstr "ldap_chpass_dns_service_name (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1268 msgid "" "Specifies the service name to use to find an LDAP server which allows " "password changes when service discovery is enabled." -msgstr "" +msgstr "指定啟用服務探索時,用來尋找允許變更密碼之 LDAP 伺服器的服務名稱。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1273 msgid "Default: not set, i.e. service discovery is disabled" -msgstr "" +msgstr "預設:未設定,也就是停用服務探索" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1279 msgid "ldap_chpass_update_last_change (bool)" -msgstr "" +msgstr "ldap_chpass_update_last_change (bool)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1282 @@ -6708,6 +7624,8 @@ msgid "" "Specifies whether to update the ldap_user_shadow_last_change attribute with " "days since the Epoch after a password change operation." msgstr "" +"指定在密碼變更作業之後,是否以自 Epoch 以來的天數更新 " +"ldap_user_shadow_last_change 屬性。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1288 @@ -6717,11 +7635,13 @@ msgid "" "shadowLastChange LDAP attribute automatically after a password change or if " "SSSD has to update it." msgstr "" +"若使用 \"ldap_pwd_policy = shadow\",建議明確設定此選項,讓 SSSD 知道 LDAP 伺" +"服器會在密碼變更後自動更新 shadowLastChange LDAP 屬性,還是必須由 SSSD 更新。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1302 msgid "ldap_access_filter (string)" -msgstr "" +msgstr "ldap_access_filter (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1305 @@ -6739,11 +7659,19 @@ msgid "" "<refentrytitle>sssd-simple</refentrytitle><manvolnum>5</manvolnum> " "</citerefentry>." msgstr "" +"若使用 access_provider = ldap 與 ldap_access_order = filter(預設),此選項是" +"必要的。它指定使用者必須符合才會被授予此主機存取權的 LDAP 搜尋篩選器準則。若 " +"access_provider = ldap、ldap_access_order = filter 且未設定此選項,會導致所有" +"使用者都被拒絕存取。使用 access_provider = permit 可以變更此預設行為。請注意" +",此篩選器只套用於 LDAP 使用者項目,因此以巢狀群組為基礎的篩選可能無法運作(" +"例如 AD 項目上的 memberOf 屬性只指向直接父群組)。若需要以巢狀群組為基礎的篩" +"選,請參閱 <citerefentry> <refentrytitle>sssd-simple</refentrytitle>" +"<manvolnum>5</manvolnum> </citerefentry>。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1325 msgid "Example:" -msgstr "" +msgstr "範例:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><programlisting> #: sssd-ldap.5.xml:1328 @@ -6753,13 +7681,16 @@ msgid "" "ldap_access_filter = (employeeType=admin)\n" " " msgstr "" +"access_provider = ldap\n" +"ldap_access_filter = (employeeType=admin)\n" +" " #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1332 msgid "" "This example means that access to this host is restricted to users whose " "employeeType attribute is set to \"admin\"." -msgstr "" +msgstr "此範例表示此主機的存取權限限於 employeeType 屬性設為 \"admin\" 的使用者。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1337 @@ -6769,23 +7700,25 @@ msgid "" "access during their last login, they will continue to be granted access " "while offline and vice versa." msgstr "" +"此功能的離線快取只限於判斷使用者最後一次線上登入是否被授予存取權限。若他們在" +"最後一次登入時被授予存取權,則在離線時會繼續被授予存取權,反之亦然。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1345 sssd-ldap.5.xml:1401 msgid "Default: Empty" -msgstr "" +msgstr "預設:空白" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1351 msgid "ldap_account_expire_policy (string)" -msgstr "" +msgstr "ldap_account_expire_policy (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1354 msgid "" "With this option a client side evaluation of access control attributes can " "be enabled." -msgstr "" +msgstr "使用此選項可以啟用存取控制屬性的用戶端評估。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1358 @@ -6794,11 +7727,13 @@ msgid "" "i.e. the LDAP server should deny the bind request with a suitable error code " "even if the password is correct." msgstr "" +"請注意,一律建議使用伺服器端存取控制,也就是即使密碼正確,LDAP 伺服器也應以適" +"當的錯誤碼拒絕繫結要求。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1365 msgid "The following values are allowed:" -msgstr "" +msgstr "允許下列值:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1368 @@ -6806,6 +7741,8 @@ msgid "" "<emphasis>shadow</emphasis>: use the value of ldap_user_shadow_expire to " "determine if the account is expired." msgstr "" +"<emphasis>shadow</emphasis>:使用 ldap_user_shadow_expire 的值判斷帳戶是否已" +"到期。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1373 @@ -6815,6 +7752,9 @@ msgid "" "set. If the attribute is missing access is granted. Also the expiration time " "of the account is checked." msgstr "" +"<emphasis>ad</emphasis>:使用 32 位元欄位 ldap_user_ad_user_account_control " +"的值,若第二個位元未設定,則允許存取。若屬性不存在,則授予存取權。也會檢查帳" +"戶的到期時間。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1380 @@ -6823,6 +7763,8 @@ msgid "" "<emphasis>389ds</emphasis>: use the value of ldap_ns_account_lock to check " "if access is allowed or not." msgstr "" +"<emphasis>rhds</emphasis>、<emphasis>ipa</emphasis>、<emphasis>389ds</" +"emphasis>:使用 ldap_ns_account_lock 的值檢查是否允許存取。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1386 @@ -6832,6 +7774,9 @@ msgid "" "ldap_user_nds_login_expiration_time are used to check if access is " "allowed. If both attributes are missing access is granted." msgstr "" +"<emphasis>nds</emphasis>:使用 ldap_user_nds_login_allowed_time_map、" +"ldap_user_nds_login_disabled 與 ldap_user_nds_login_expiration_time 的值檢查" +"是否允許存取。若兩個屬性都不存在,則授予存取權。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1394 @@ -6840,21 +7785,23 @@ msgid "" "<emphasis>must</emphasis> include <quote>expire</quote> in order for the " "ldap_account_expire_policy option to work." msgstr "" +"請注意,ldap_access_order 設定選項<emphasis>必須</emphasis>包含 <quote>" +"expire</quote>,ldap_account_expire_policy 選項才能運作。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1407 msgid "ldap_access_order (string)" -msgstr "" +msgstr "ldap_access_order (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1410 sssd-ipa.5.xml:356 msgid "Comma separated list of access control options. Allowed values are:" -msgstr "" +msgstr "存取控制選項的逗號分隔清單。允許的值有:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1414 msgid "<emphasis>filter</emphasis>: use ldap_access_filter" -msgstr "" +msgstr "<emphasis>filter</emphasis>:使用 ldap_access_filter" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1417 @@ -6865,6 +7812,10 @@ msgid "" "Please note that 'access_provider = ldap' must be set for this feature to " "work." msgstr "" +"<emphasis>lockout</emphasis>:使用帳戶鎖定。若設定,此選項會在 LDAP 屬性 " +"'pwdAccountLockedTime' 存在且值為 '000001010000Z' 時拒絕存取。請參閱 " +"ldap_pwdlockout_dn 選項。請注意,此功能要運作必須設定 'access_provider = " +"ldap'。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1427 @@ -6873,6 +7824,8 @@ msgid "" "<quote>ppolicy</quote> option and might be removed in a future release. " "</emphasis>" msgstr "" +"<emphasis> 請注意,此選項已被 <quote>ppolicy</quote> 選項取代,未來版本可能會" +"移除。 </emphasis>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1434 @@ -6886,11 +7839,17 @@ msgid "" "the option ldap_pwdlockout_dn. Please note that 'access_provider = ldap' " "must be set for this feature to work." msgstr "" +"<emphasis>ppolicy</emphasis>:使用帳戶鎖定。若設定,此選項會在 LDAP 屬性 " +"'pwdAccountLockedTime' 存在且值為 '000001010000Z' 或代表過去任何時間時拒絕存" +"取。'pwdAccountLockedTime' 屬性的值必須以 'Z' 結尾,這表示 UTC 時區。目前不支" +"援其他時區,使用者嘗試登入時會導致 \"access-denied\"。請參閱 " +"ldap_pwdlockout_dn 選項。請注意,此功能要運作必須設定 'access_provider = " +"ldap'。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1451 msgid "<emphasis>expire</emphasis>: use ldap_account_expire_policy" -msgstr "" +msgstr "<emphasis>expire</emphasis>:使用 ldap_account_expire_policy" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1455 sssd-ipa.5.xml:364 @@ -6901,30 +7860,33 @@ msgid "" "authentication is based on using a different method than passwords - for " "example SSH keys." msgstr "" +"<emphasis>pwd_expire_policy_reject、pwd_expire_policy_warn、" +"pwd_expire_policy_renew:</emphasis>若使用者希望收到密碼即將到期的警告,且驗" +"證是基於密碼以外的方法(例如 SSH 金鑰),這些選項很有用。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1465 sssd-ipa.5.xml:374 msgid "" "The difference between these options is the action taken if user password is " "expired:" -msgstr "" +msgstr "這些選項之間的差異在於使用者密碼到期時採取的動作:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ldap.5.xml:1470 sssd-ipa.5.xml:379 msgid "pwd_expire_policy_reject - user is denied to log in," -msgstr "" +msgstr "pwd_expire_policy_reject - 拒絕使用者登入," #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ldap.5.xml:1476 sssd-ipa.5.xml:385 msgid "pwd_expire_policy_warn - user is still able to log in," -msgstr "" +msgstr "pwd_expire_policy_warn - 使用者仍可以登入," #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ldap.5.xml:1482 sssd-ipa.5.xml:391 msgid "" "pwd_expire_policy_renew - user is prompted to change their password " "immediately." -msgstr "" +msgstr "pwd_expire_policy_renew - 提示使用者立即變更密碼。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1490 @@ -6933,6 +7895,8 @@ msgid "" "work. Also 'ldap_pwd_policy' must be set to shadow or mit_kerberos, these " "options do not work with server-side password policies." msgstr "" +"請注意,此功能要運作必須設定 'access_provider = ldap'。'ldap_pwd_policy' 也必" +"須設為 shadow 或 mit_kerberos,這些選項不適用於伺服器端密碼原則。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1496 @@ -6940,18 +7904,20 @@ msgid "" "<emphasis>authorized_service</emphasis>: use the authorizedService attribute " "to determine access" msgstr "" +"<emphasis>authorized_service</emphasis>:使用 authorizedService 屬性判斷存取" +"權" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1501 msgid "<emphasis>host</emphasis>: use the host attribute to determine access" -msgstr "" +msgstr "<emphasis>host</emphasis>:使用 host 屬性判斷存取權" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1505 msgid "" "<emphasis>rhost</emphasis>: use the rhost attribute to determine whether " "remote host can access" -msgstr "" +msgstr "<emphasis>rhost</emphasis>:使用 rhost 屬性判斷遠端主機是否可以存取" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1509 @@ -6960,23 +7926,25 @@ msgid "" "what the application sends to pam, before enabling this access control " "option" msgstr "" +"請注意,pam 中的 rhost 欄位由應用程式設定,在啟用此存取控制選項之前,最好先檢" +"查應用程式傳送給 pam 的內容" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1514 msgid "Default: filter" -msgstr "" +msgstr "預設:filter" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1517 msgid "" "Please note that it is a configuration error if a value is used more than " "once." -msgstr "" +msgstr "請注意,若一個值使用超過一次,就是設定錯誤。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1524 msgid "ldap_pwdlockout_dn (string)" -msgstr "" +msgstr "ldap_pwdlockout_dn (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1527 @@ -6986,33 +7954,36 @@ msgid "" "lockout checking will yield access denied as ppolicy attributes on LDAP " "server cannot be checked properly." msgstr "" +"此選項指定 LDAP 伺服器上密碼原則項目的 DN。請注意,若啟用帳戶鎖定檢查,而 " +"sssd.conf 中沒有此選項,會導致拒絕存取,因為無法正確檢查 LDAP 伺服器上的 " +"ppolicy 屬性。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1535 msgid "Example: cn=ppolicy,ou=policies,dc=example,dc=com" -msgstr "" +msgstr "範例:cn=ppolicy,ou=policies,dc=example,dc=com" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1538 msgid "Default: cn=ppolicy,ou=policies,$ldap_search_base" -msgstr "" +msgstr "預設:cn=ppolicy,ou=policies,$ldap_search_base" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1544 msgid "ldap_deref (string)" -msgstr "" +msgstr "ldap_deref (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1547 msgid "" "Specifies how alias dereferencing is done when performing a search. The " "following options are allowed:" -msgstr "" +msgstr "指定執行搜尋時如何解除別名參照。允許下列選項:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1552 msgid "<emphasis>never</emphasis>: Aliases are never dereferenced." -msgstr "" +msgstr "<emphasis>never</emphasis>:永遠不解除別名參照。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1556 @@ -7020,39 +7991,41 @@ msgid "" "<emphasis>searching</emphasis>: Aliases are dereferenced in subordinates of " "the base object, but not in locating the base object of the search." msgstr "" +"<emphasis>searching</emphasis>:會解除基礎物件下屬中的別名參照,但在定位搜尋" +"的基礎物件時不會。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1561 msgid "" "<emphasis>finding</emphasis>: Aliases are only dereferenced when locating " "the base object of the search." -msgstr "" +msgstr "<emphasis>finding</emphasis>:只在定位搜尋的基礎物件時解除別名參照。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1566 msgid "" "<emphasis>always</emphasis>: Aliases are dereferenced both in searching and " "in locating the base object of the search." -msgstr "" +msgstr "<emphasis>always</emphasis>:在搜尋與定位搜尋的基礎物件時都會解除別名參照。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1571 msgid "" "Default: Empty (this is handled as <emphasis>never</emphasis> by the LDAP " "client libraries)" -msgstr "" +msgstr "預設:空白(LDAP 用戶端程式庫會將此視為 <emphasis>never</emphasis> 處理)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1579 msgid "ldap_rfc2307_fallback_to_local_users (boolean)" -msgstr "" +msgstr "ldap_rfc2307_fallback_to_local_users (boolean)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1582 msgid "" "Allows to retain local users as members of an LDAP group for servers that " "use the RFC2307 schema." -msgstr "" +msgstr "允許對使用 RFC2307 架構的伺服器保留本機使用者作為 LDAP 群組的成員。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1586 @@ -7064,6 +8037,10 @@ msgid "" "memberships as soon as nsswitch tries to fetch information about the user " "via getpw*() or initgroups() calls." msgstr "" +"在某些使用 RFC2307 綱要的環境中,會透過將本機使用者的名稱加入 memberUid 屬性" +",讓本機使用者成為 LDAP 群組的成員。這樣做會破壞網域的自洽性,因此只要 " +"nsswitch 嘗試透過 getpw*() 或 initgroups() 呼叫取回使用者資訊,SSSD 通常就會" +"從快取的群組成員中移除「遺失」的使用者。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1597 @@ -7072,33 +8049,35 @@ msgid "" "them so that later initgroups() calls will augment the local users with the " "additional LDAP groups." msgstr "" +"此選項會退回檢查本機使用者是否被參照,並快取他們,讓之後的 initgroups() 呼叫" +"會以額外的 LDAP 群組擴充本機使用者。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1609 sssd-ifp.5.xml:152 msgid "wildcard_limit (integer)" -msgstr "" +msgstr "wildcard_limit (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1612 msgid "" "Specifies an upper limit on the number of entries that are downloaded during " "a wildcard lookup." -msgstr "" +msgstr "指定萬用字元查詢期間下載項目數目的上限。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1616 msgid "At the moment, only the InfoPipe responder supports wildcard lookups." -msgstr "" +msgstr "目前只有 InfoPipe responder 支援萬用字元查詢。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1620 msgid "Default: 1000 (often the size of one page)" -msgstr "" +msgstr "預設:1000(通常是一頁的大小)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1626 msgid "ldap_library_debug_level (integer)" -msgstr "" +msgstr "ldap_library_debug_level (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1629 @@ -7106,23 +8085,25 @@ msgid "" "Switches on libldap debugging with the given level. The libldap debug " "messages will be written independent of the general debug_level." msgstr "" +"以指定的層級開啟 libldap 除錯。libldap 除錯訊息會獨立於一般 debug_level 寫入" +"。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1634 msgid "" "OpenLDAP uses a bitmap to enable debugging for specific components, -1 will " "enable full debug output." -msgstr "" +msgstr "OpenLDAP 使用點陣圖來啟用特定元件的除錯,-1 會啟用完整的除錯輸出。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1639 msgid "Default: 0 (libldap debugging disabled)" -msgstr "" +msgstr "預設:0(停用 libldap 除錯)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1645 msgid "ldap_use_ppolicy (boolean)" -msgstr "" +msgstr "ldap_use_ppolicy (boolean)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1648 @@ -7131,11 +8112,13 @@ msgid "" "controls. Disabling this allows interacting with services which send back " "invalid ppolicy extension." msgstr "" +"開啟要求並依賴伺服器端密碼原則控制。停用此選項可以與回傳無效 ppolicy 延伸的服" +"務互動。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1660 msgid "ldap_ppolicy_pwd_change_threshold (integer)" -msgstr "" +msgstr "ldap_ppolicy_pwd_change_threshold (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1663 @@ -7147,6 +8130,9 @@ msgid "" "logins, one to verify the current password and a second one to perform the " "password change." msgstr "" +"當啟用伺服器端密碼原則控制,且伺服器在驗證後傳回的剩餘寬限登入次數達到或低於" +"門檻時,強制變更密碼。請注意,有用的最小值是 2,因為變更密碼會消耗 2 次額外的" +"寬限登入,一次用於驗證目前的密碼,第二次用於執行密碼變更。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ldap.5.xml:52 @@ -7159,11 +8145,17 @@ msgid "" "<refentrytitle>sssd-ldap-attributes</refentrytitle> <manvolnum>5</manvolnum> " "</citerefentry> manual page. <placeholder type=\"variablelist\" id=\"0\"/>" msgstr "" +"適用於 SSSD 網域的所有一般設定選項也適用於 LDAP 網域。完整詳細資料請參閱 " +"<citerefentry> <refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry> 手冊頁的 <quote>DOMAIN SECTIONS</quote> 一節。請注" +"意,SSSD LDAP 對應屬性說明於 <citerefentry> <refentrytitle>sssd-ldap-" +"attributes</refentrytitle> <manvolnum>5</manvolnum> </citerefentry> 手冊頁" +"。<placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><title> #: sssd-ldap.5.xml:1683 msgid "SUDO OPTIONS" -msgstr "" +msgstr "SUDO 選項" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ldap.5.xml:1685 @@ -7172,11 +8164,13 @@ msgid "" "manual page <citerefentry> <refentrytitle>sssd-sudo</refentrytitle> " "<manvolnum>5</manvolnum> </citerefentry>." msgstr "" +"sudo_provider 設定的詳細說明請參閱手冊頁 <citerefentry> <refentrytitle>sssd-" +"sudo</refentrytitle> <manvolnum>5</manvolnum> </citerefentry>。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1696 msgid "ldap_sudo_full_refresh_interval (integer)" -msgstr "" +msgstr "ldap_sudo_full_refresh_interval (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1699 @@ -7184,13 +8178,15 @@ msgid "" "How many seconds SSSD will wait between executing a full refresh of sudo " "rules (which downloads all rules that are stored on the server)." msgstr "" +"SSSD 在執行 sudo 規則完整重新整理(會下載伺服器上儲存的所有規則)之間會等待多" +"少秒。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1704 msgid "" "The value must be greater than <emphasis>ldap_sudo_smart_refresh_interval " "</emphasis>" -msgstr "" +msgstr "此值必須大於 <emphasis>ldap_sudo_smart_refresh_interval </emphasis>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1709 @@ -7198,16 +8194,18 @@ msgid "" "You can disable full refresh by setting this option to 0. However, either " "smart or full refresh must be enabled." msgstr "" +"您可以將此選項設為 0 來停用完整重新整理。不過,智慧型或完整重新整理必須啟用其" +"中一個。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1714 msgid "Default: 21600 (6 hours)" -msgstr "" +msgstr "預設:21600(6 小時)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1720 msgid "ldap_sudo_smart_refresh_interval (integer)" -msgstr "" +msgstr "ldap_sudo_smart_refresh_interval (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1723 @@ -7216,13 +8214,15 @@ msgid "" "rules (which downloads all rules that have USN higher than the highest " "server USN value that is currently known by SSSD)." msgstr "" +"指定 SSSD 在執行 sudo 規則智慧型重新整理(會下載所有 USN 高於 SSSD 目前已知之" +"伺服器最高 USN 值的規則)之前必須等待的秒數。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1729 msgid "" "If USN attributes are not supported by the server, the modifyTimestamp " "attribute is used instead." -msgstr "" +msgstr "若伺服器不支援 USN 屬性,則改用 modifyTimestamp 屬性。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1733 @@ -7233,6 +8233,10 @@ msgid "" "found) and 3) by reconnecting to the server (by default every 15 minutes, " "see <emphasis>ldap_connection_expire_timeout</emphasis>)." msgstr "" +"<emphasis>注意:</emphasis>最高 USN 值可以由三個工作更新:1) sudo 完整與智慧" +"型重新整理(若找到更新的規則),2) 使用者與群組列舉(若啟用且找到更新的使用者" +"或群組),3) 重新連線到伺服器(預設每 15 分鐘,請參閱 <emphasis>" +"ldap_connection_expire_timeout</emphasis>)。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1744 @@ -7240,11 +8244,13 @@ msgid "" "You can disable smart refresh by setting this option to 0. However, either " "smart or full refresh must be enabled." msgstr "" +"您可以將此選項設為 0 來停用智慧型重新整理。不過,智慧型或完整重新整理必須啟用" +"其中一個。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1755 msgid "ldap_sudo_random_offset (integer)" -msgstr "" +msgstr "ldap_sudo_random_offset (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1758 @@ -7253,6 +8259,8 @@ msgid "" "refresh periods each time the periodic task is scheduled. The value is in " "seconds." msgstr "" +"每次排定週期性工作時,會將介於 0 與設定值之間的隨機偏移加到智慧型與完整重新整" +"理週期。值以秒為單位。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1764 @@ -7261,16 +8269,18 @@ msgid "" "delays the first sudo rules refresh. This prolongs the time when the sudo " "rules are not available for use." msgstr "" +"請注意,此隨機偏移也會套用於 SSSD 第一次啟動,這會延遲第一次的 sudo 規則重新" +"整理。這會延長 sudo 規則無法使用的時間。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1770 msgid "You can disable this offset by setting the value to 0." -msgstr "" +msgstr "您可以將值設為 0 來停用此偏移。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1780 msgid "ldap_sudo_use_host_filter (boolean)" -msgstr "" +msgstr "ldap_sudo_use_host_filter (boolean)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1783 @@ -7278,25 +8288,27 @@ msgid "" "If true, SSSD will download only rules that are applicable to this machine " "(using the IPv4 or IPv6 host/network addresses and hostnames)." msgstr "" +"若為 true,SSSD 只會下載適用於此機器的規則(使用 IPv4 或 IPv6 主機/網路位址與" +"主機名稱)。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1794 msgid "ldap_sudo_hostnames (string)" -msgstr "" +msgstr "ldap_sudo_hostnames (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1797 msgid "" "Space separated list of hostnames or fully qualified domain names that " "should be used to filter the rules." -msgstr "" +msgstr "應該用來篩選規則的主機名稱或完整網域名稱空格分隔清單。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1802 msgid "" "If this option is empty, SSSD will try to discover the hostname and the " "fully qualified domain name automatically." -msgstr "" +msgstr "若此選項為空白,SSSD 會嘗試自動探索主機名稱與完整網域名稱。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1807 sssd-ldap.5.xml:1830 sssd-ldap.5.xml:1848 @@ -7305,61 +8317,63 @@ msgid "" "If <emphasis>ldap_sudo_use_host_filter</emphasis> is " "<emphasis>false</emphasis> then this option has no effect." msgstr "" +"若 <emphasis>ldap_sudo_use_host_filter</emphasis> 為 <emphasis>false</" +"emphasis>,則此選項沒有作用。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1812 sssd-ldap.5.xml:1835 msgid "Default: not specified" -msgstr "" +msgstr "預設:未指定" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1818 msgid "ldap_sudo_ip (string)" -msgstr "" +msgstr "ldap_sudo_ip (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1821 msgid "" "Space separated list of IPv4 or IPv6 host/network addresses that should be " "used to filter the rules." -msgstr "" +msgstr "應該用來篩選規則的 IPv4 或 IPv6 主機/網路位址空格分隔清單。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1826 msgid "" "If this option is empty, SSSD will try to discover the addresses " "automatically." -msgstr "" +msgstr "若此選項為空白,SSSD 會嘗試自動探索位址。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1841 msgid "ldap_sudo_include_netgroups (boolean)" -msgstr "" +msgstr "ldap_sudo_include_netgroups (boolean)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1844 msgid "" "If true then SSSD will download every rule that contains a netgroup in " "sudoHost attribute." -msgstr "" +msgstr "若為 true,SSSD 會下載 sudoHost 屬性中包含 netgroup 的每個規則。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1859 msgid "ldap_sudo_include_regexp (boolean)" -msgstr "" +msgstr "ldap_sudo_include_regexp (boolean)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1862 msgid "" "If true then SSSD will download every rule that contains a wildcard in " "sudoHost attribute." -msgstr "" +msgstr "若為 true,SSSD 會下載 sudoHost 屬性中包含萬用字元的每個規則。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><note><para> #: sssd-ldap.5.xml:1872 msgid "" "Using wildcard is an operation that is very costly to evaluate on the LDAP " "server side!" -msgstr "" +msgstr "使用萬用字元是在 LDAP 伺服器端評估成本非常高的作業!" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ldap.5.xml:1884 @@ -7369,58 +8383,61 @@ msgid "" "<refentrytitle>sudoers.ldap</refentrytitle><manvolnum>5</manvolnum> " "</citerefentry>" msgstr "" +"本手冊頁只描述屬性名稱對應。sudo 相關屬性語意的詳細說明,請參閱 " +"<citerefentry> <refentrytitle>sudoers.ldap</refentrytitle><manvolnum>5</" +"manvolnum> </citerefentry>" #. type: Content of: <reference><refentry><refsect1><title> #: sssd-ldap.5.xml:1894 msgid "AUTOFS OPTIONS" -msgstr "" +msgstr "AUTOFS 選項" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ldap.5.xml:1896 msgid "" "Some of the defaults for the parameters below are dependent on the LDAP " "schema." -msgstr "" +msgstr "下列參數的部分預設值取決於 LDAP 綱要。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1902 msgid "ldap_autofs_map_master_name (string)" -msgstr "" +msgstr "ldap_autofs_map_master_name (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1905 msgid "The name of the automount master map in LDAP." -msgstr "" +msgstr "LDAP 中自動掛載主對應表的名稱。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1908 msgid "Default: auto.master" -msgstr "" +msgstr "預設:auto.master" #. type: Content of: <reference><refentry><refsect1><title> #: sssd-ldap.5.xml:1919 msgid "ADVANCED OPTIONS" -msgstr "" +msgstr "進階選項" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1926 msgid "ldap_netgroup_search_base (string)" -msgstr "" +msgstr "ldap_netgroup_search_base (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1931 msgid "ldap_user_search_base (string)" -msgstr "" +msgstr "ldap_user_search_base (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1936 msgid "ldap_group_search_base (string)" -msgstr "" +msgstr "ldap_group_search_base (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><note> #: sssd-ldap.5.xml:1941 msgid "<note>" -msgstr "" +msgstr "<note>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><note><para> #: sssd-ldap.5.xml:1943 @@ -7430,21 +8447,24 @@ msgid "" "memberships, even with no GID mapping. It is recommended to disable this " "feature, if group names are not being displayed correctly." msgstr "" +"若啟用 <quote>ldap_use_tokengroups</quote> 選項,對 Active Directory 的搜尋不" +"會受到限制,會傳回所有群組成員資格,即使沒有 GID 對應。若群組名稱顯示不正確," +"建議停用此功能。" #. type: Content of: <reference><refentry><refsect1><para><variablelist> #: sssd-ldap.5.xml:1950 msgid "</note>" -msgstr "" +msgstr "</note>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1952 msgid "ldap_sudo_search_base (string)" -msgstr "" +msgstr "ldap_sudo_search_base (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1957 msgid "ldap_autofs_search_base (string)" -msgstr "" +msgstr "ldap_autofs_search_base (string)" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ldap.5.xml:1921 @@ -7454,13 +8474,16 @@ msgid "" "are doing. <placeholder type=\"variablelist\" id=\"0\"/> <placeholder " "type=\"variablelist\" id=\"1\"/>" msgstr "" +"LDAP 網域支援這些選項,但應謹慎使用。請只在您知道自己在做什麼的情況下,才將它" +"們納入設定。<placeholder type=\"variablelist\" id=\"0\"/> <placeholder " +"type=\"variablelist\" id=\"1\"/>" #. type: Content of: <reference><refentry><refsect1><title> #: sssd-ldap.5.xml:1972 sssd-simple.5.xml:131 sssd-ipa.5.xml:930 #: sssd-ad.5.xml:1392 sssd-krb5.5.xml:483 sss_rpcidmapd.5.xml:98 #: sssd-files.5.xml:155 sssd-session-recording.5.xml:176 msgid "EXAMPLE" -msgstr "" +msgstr "範例" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ldap.5.xml:1974 @@ -7469,6 +8492,8 @@ msgid "" "set to one of the domains in the <replaceable>[domains]</replaceable> " "section." msgstr "" +"下列範例假設 SSSD 已正確設定,且 LDAP 設為 <replaceable>[domains]</" +"replaceable> 區段中的其中一個網域。" #. type: Content of: <reference><refentry><refsect1><para><programlisting> #: sssd-ldap.5.xml:1980 @@ -7482,6 +8507,13 @@ msgid "" "ldap_tls_reqcert = demand\n" "cache_credentials = true\n" msgstr "" +"[domain/LDAP]\n" +"id_provider = ldap\n" +"auth_provider = ldap\n" +"ldap_uri = ldap://ldap.mydomain.org\n" +"ldap_search_base = dc=mydomain,dc=org\n" +"ldap_tls_reqcert = demand\n" +"cache_credentials = true\n" #. type: Content of: <refsect1><refsect2><para> #: sssd-ldap.5.xml:1979 sssd-ldap.5.xml:1997 sssd-simple.5.xml:139 @@ -7489,19 +8521,19 @@ msgstr "" #: sssd-files.5.xml:162 sssd-files.5.xml:173 sssd-session-recording.5.xml:182 #: include/ldap_id_mapping.xml:105 msgid "<placeholder type=\"programlisting\" id=\"0\"/>" -msgstr "" +msgstr "<placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><title> #: sssd-ldap.5.xml:1991 msgid "LDAP ACCESS FILTER EXAMPLE" -msgstr "" +msgstr "LDAP 存取篩選器範例" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ldap.5.xml:1993 msgid "" "The following example assumes that SSSD is correctly configured and to use " "the ldap_access_order=lockout." -msgstr "" +msgstr "下列範例假設 SSSD 已正確設定,且使用 ldap_access_order=lockout。" #. type: Content of: <reference><refentry><refsect1><para><programlisting> #: sssd-ldap.5.xml:1998 @@ -7518,12 +8550,22 @@ msgid "" "ldap_tls_reqcert = demand\n" "cache_credentials = true\n" msgstr "" +"[domain/LDAP]\n" +"id_provider = ldap\n" +"auth_provider = ldap\n" +"access_provider = ldap\n" +"ldap_access_order = lockout\n" +"ldap_pwdlockout_dn = cn=ppolicy,ou=policies,dc=mydomain,dc=org\n" +"ldap_uri = ldap://ldap.mydomain.org\n" +"ldap_search_base = dc=mydomain,dc=org\n" +"ldap_tls_reqcert = demand\n" +"cache_credentials = true\n" #. type: Content of: <reference><refentry><refsect1><title> #: sssd-ldap.5.xml:2013 sssd_krb5_locator_plugin.8.xml:83 sssd-simple.5.xml:148 #: sssd-ad.5.xml:1415 sssd.8.xml:270 sss_seed.8.xml:163 msgid "NOTES" -msgstr "" +msgstr "注意事項" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ldap.5.xml:2015 @@ -7533,11 +8575,14 @@ msgid "" "<manvolnum>5</manvolnum> </citerefentry> manual page from the OpenLDAP 2.4 " "distribution." msgstr "" +"本手冊頁中部分設定選項的說明是以 OpenLDAP 2.4 發行版中的 <citerefentry> " +"<refentrytitle>ldap.conf</refentrytitle> <manvolnum>5</manvolnum> </" +"citerefentry> 手冊頁為基礎。" #. type: Content of: <reference><refentry><refnamediv><refname> #: pam_sss.8.xml:11 pam_sss.8.xml:16 msgid "pam_sss" -msgstr "" +msgstr "pam_sss" #. type: Content of: <reference><refentry><refmeta><manvolnum> #: pam_sss.8.xml:12 pam_sss_gss.8.xml:12 sssd_krb5_locator_plugin.8.xml:11 @@ -7546,12 +8591,12 @@ msgstr "" #: idmap_sss.8.xml:11 sssctl.8.xml:11 sssd-kcm.8.xml:11 #: sssd_krb5_localauth_plugin.8.xml:11 msgid "8" -msgstr "" +msgstr "8" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: pam_sss.8.xml:17 msgid "PAM module for SSSD" -msgstr "" +msgstr "SSSD 的 PAM 模組" #. type: Content of: <reference><refentry><refsynopsisdiv><cmdsynopsis> #: pam_sss.8.xml:22 @@ -7570,6 +8615,18 @@ msgid "" "<replaceable>try_cert_auth</replaceable> </arg> <arg choice='opt'> " "<replaceable>require_cert_auth</replaceable> </arg>" msgstr "" +"<command>pam_sss.so</command> <arg choice='opt'> <replaceable>quiet</" +"replaceable> </arg> <arg choice='opt'> <replaceable>forward_pass</" +"replaceable> </arg> <arg choice='opt'> <replaceable>use_first_pass</" +"replaceable> </arg> <arg choice='opt'> <replaceable>use_authtok</" +"replaceable> </arg> <arg choice='opt'> <replaceable>retry=N</replaceable> </" +"arg> <arg choice='opt'> <replaceable>ignore_unknown_user</replaceable> </" +"arg> <arg choice='opt'> <replaceable>ignore_authinfo_unavail</replaceable> </" +"arg> <arg choice='opt'> <replaceable>domains=X</replaceable> </arg> <arg " +"choice='opt'> <replaceable>allow_missing_name</replaceable> </arg> <arg " +"choice='opt'> <replaceable>prompt_always</replaceable> </arg> <arg " +"choice='opt'> <replaceable>try_cert_auth</replaceable> </arg> <arg " +"choice='opt'> <replaceable>require_cert_auth</replaceable> </arg>" #. type: Content of: <reference><refentry><refsect1><para> #: pam_sss.8.xml:64 @@ -7578,28 +8635,30 @@ msgid "" "Services daemon (SSSD). Errors and results are logged through " "<command>syslog(3)</command> with the LOG_AUTHPRIV facility." msgstr "" +"<command>pam_sss.so</command> 是系統安全服務精靈 (SSSD) 的 PAM 介面。錯誤與結" +"果會透過 <command>syslog(3)</command> 以 LOG_AUTHPRIV 設施記錄。" #. type: Content of: <reference><refentry><refsect1><title> #: pam_sss.8.xml:70 pam_sss_gss.8.xml:89 sssd.8.xml:42 sss_obfuscate.8.xml:58 #: sss_cache.8.xml:39 sss_seed.8.xml:42 sss_ssh_authorizedkeys.1.xml:123 #: sss_ssh_knownhosts.1.xml:56 sss_ssh_knownhostsproxy.1.xml:72 msgid "OPTIONS" -msgstr "" +msgstr "選項" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:74 msgid "<option>quiet</option>" -msgstr "" +msgstr "<option>quiet</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:77 msgid "Suppress log messages for unknown users." -msgstr "" +msgstr "抑制未知使用者的記錄訊息。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:82 msgid "<option>forward_pass</option>" -msgstr "" +msgstr "<option>forward_pass</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:85 @@ -7607,11 +8666,13 @@ msgid "" "If <option>forward_pass</option> is set the entered password is put on the " "stack for other PAM modules to use." msgstr "" +"若設定 <option>forward_pass</option>,輸入的密碼會放到堆疊上供其他 PAM 模組使" +"用。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:92 msgid "<option>use_first_pass</option>" -msgstr "" +msgstr "<option>use_first_pass</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:95 @@ -7621,30 +8682,32 @@ msgid "" "available or the password is not appropriate, the user will be denied " "access." msgstr "" +"use_first_pass 參數會強制模組使用先前堆疊模組的密碼,而且絕不會提示使用者——若" +"沒有可用的密碼或密碼不適當,使用者會被拒絕存取。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:103 msgid "<option>use_authtok</option>" -msgstr "" +msgstr "<option>use_authtok</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:106 msgid "" "When password changing enforce the module to set the new password to the one " "provided by a previously stacked password module." -msgstr "" +msgstr "變更密碼時,強制模組將新密碼設為先前堆疊的密碼模組提供的密碼。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:113 msgid "<option>retry=N</option>" -msgstr "" +msgstr "<option>retry=N</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:116 msgid "" "If specified the user is asked another N times for a password if " "authentication fails. Default is 0." -msgstr "" +msgstr "若指定,驗證失敗時會再詢問使用者 N 次密碼。預設為 0。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:118 @@ -7653,11 +8716,14 @@ msgid "" "calling PAM handles the user dialog on its own. A typical example is " "<command>sshd</command> with <option>PasswordAuthentication</option>." msgstr "" +"請注意,若呼叫 PAM 的應用程式自行處理使用者對話,此選項可能無法如預期運作。典" +"型的例子是使用 <option>PasswordAuthentication</option> 的 <command>sshd</" +"command>。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:127 msgid "<option>ignore_unknown_user</option>" -msgstr "" +msgstr "<option>ignore_unknown_user</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:130 @@ -7665,11 +8731,13 @@ msgid "" "If this option is specified and the user does not exist, the PAM module will " "return PAM_IGNORE. This causes the PAM framework to ignore this module." msgstr "" +"若指定此選項且使用者不存在,PAM 模組會傳回 PAM_IGNORE。這會讓 PAM 架構忽略此" +"模組。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:137 msgid "<option>ignore_authinfo_unavail</option>" -msgstr "" +msgstr "<option>ignore_authinfo_unavail</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:141 @@ -7677,11 +8745,13 @@ msgid "" "Specifies that the PAM module should return PAM_IGNORE if it cannot contact " "the SSSD daemon. This causes the PAM framework to ignore this module." msgstr "" +"指定 PAM 模組在無法連絡 SSSD 精靈時應傳回 PAM_IGNORE。這會讓 PAM 架構忽略此模" +"組。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:148 msgid "<option>domains</option>" -msgstr "" +msgstr "<option>domains</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:152 @@ -7690,6 +8760,8 @@ msgid "" "allowed to authenticate against. The format is a comma-separated list of " "SSSD domain names, as specified in the sssd.conf file." msgstr "" +"允許管理員限制特定 PAM 服務可以驗證的網域。格式是 SSSD 網域名稱的逗號分隔清單" +",如 sssd.conf 檔案中所指定。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:158 @@ -7702,11 +8774,16 @@ msgid "" "</citerefentry> manual page for more information on these two PAM responder " "options." msgstr "" +"注意:若這是用於不是以 root 使用者執行的服務(例如網頁伺服器),必須與 " +"<quote>pam_trusted_users</quote> 與 <quote>pam_public_domains</quote> 選項一" +"起使用。有關這兩個 PAM responder 選項的更多資訊,請參閱 <citerefentry> " +"<refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</manvolnum> </" +"citerefentry> 手冊頁。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:173 msgid "<option>allow_missing_name</option>" -msgstr "" +msgstr "<option>allow_missing_name</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:177 @@ -7714,6 +8791,8 @@ msgid "" "The main purpose of this option is to let SSSD determine the user name based " "on additional information, e.g. the certificate from a Smartcard." msgstr "" +"此選項的主要目的是讓 SSSD 根據其他資訊(例如 Smartcard 的憑證)判斷使用者名稱" +"。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><programlisting> #: pam_sss.8.xml:187 @@ -7722,6 +8801,8 @@ msgid "" "auth sufficient pam_sss.so allow_missing_name\n" " " msgstr "" +"auth sufficient pam_sss.so allow_missing_name\n" +" " #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:182 @@ -7733,11 +8814,15 @@ msgid "" "the content of the Smartcard, returns it to pam_sss which will finally put " "it on the PAM stack." msgstr "" +"目前的使用案例是能夠監控 Smartcard 讀卡機卡片事件的登入管理員。若插入 " +"Smartcard,登入管理員會呼叫包含類似 <placeholder type=\"programlisting\" " +"id=\"0\"/> 這一行內容的 PAM 堆疊。在此情況下,SSSD 會嘗試根據 Smartcard 的內" +"容判斷使用者名稱,將它傳回 pam_sss,最後由 pam_sss 放到 PAM 堆疊上。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:197 msgid "<option>prompt_always</option>" -msgstr "" +msgstr "<option>prompt_always</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:201 @@ -7748,11 +8833,14 @@ msgid "" "SSSD pam_sss might prompt for a password, a Smartcard PIN or other " "credentials." msgstr "" +"一律提示使用者輸入憑證。使用此選項時,其他 PAM 模組要求的憑證(通常是密碼)會" +"被忽略,pam_sss 會再次提示輸入憑證。根據 SSSD 的預先驗證回覆,pam_sss 可能會" +"提示輸入密碼、Smartcard PIN 或其他憑證。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:212 msgid "<option>try_cert_auth</option>" -msgstr "" +msgstr "<option>try_cert_auth</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:216 @@ -7762,6 +8850,9 @@ msgid "" "allowed for Smartcard authentication the user will be prompted for a PIN and " "the certificate based authentication will continue" msgstr "" +"嘗試使用以憑證為基礎的驗證,也就是使用 Smartcard 或類似裝置驗證。若 " +"Smartcard 可用且服務允許 Smartcard 驗證,會提示使用者輸入 PIN,並繼續以憑證為" +"基礎的驗證" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:224 @@ -7769,11 +8860,13 @@ msgid "" "If no Smartcard is available or certificate based authentication is not " "allowed for the current service PAM_AUTHINFO_UNAVAIL is returned." msgstr "" +"若沒有可用的 Smartcard,或目前的服務不允許以憑證為基礎的驗證,會傳回 " +"PAM_AUTHINFO_UNAVAIL。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:232 msgid "<option>require_cert_auth</option>" -msgstr "" +msgstr "<option>require_cert_auth</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:236 @@ -7785,6 +8878,11 @@ msgid "" "<citerefentry><refentrytitle>sssd.conf</refentrytitle> " "<manvolnum>5</manvolnum></citerefentry> for details." msgstr "" +"執行以憑證為基礎的驗證,也就是使用 Smartcard 或類似裝置驗證。若沒有可用的 " +"Smartcard,會提示使用者插入一張。SSSD 會等待 Smartcard,直到 " +"p11_wait_for_card_timeout 定義的逾時過去,詳情請參閱 <citerefentry>" +"<refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</manvolnum></" +"citerefentry>。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:246 @@ -7793,11 +8891,13 @@ msgid "" "authentication is not allowed for the current service PAM_AUTHINFO_UNAVAIL " "is returned." msgstr "" +"若逾時後仍沒有可用的 Smartcard,或目前的服務不允許以憑證為基礎的驗證,會傳回 " +"PAM_AUTHINFO_UNAVAIL。" #. type: Content of: <reference><refentry><refsect1><title> #: pam_sss.8.xml:256 pam_sss_gss.8.xml:103 msgid "MODULE TYPES PROVIDED" -msgstr "" +msgstr "提供的模組類型" #. type: Content of: <reference><refentry><refsect1><para> #: pam_sss.8.xml:257 @@ -7805,6 +8905,8 @@ msgid "" "All module types (<option>account</option>, <option>auth</option>, " "<option>password</option> and <option>session</option>) are provided." msgstr "" +"提供所有模組類型(<option>account</option>、<option>auth</option>、<option>" +"password</option> 與 <option>session</option>)。" #. type: Content of: <reference><refentry><refsect1><para> #: pam_sss.8.xml:260 @@ -7814,62 +8916,65 @@ msgid "" "<option>account</option> module to avoid issues with users from other " "sources during access control." msgstr "" +"若 SSSD 的 PAM responder 未執行(例如 PAM responder 通訊端無法使用)," +"pam_sss 以 <option>account</option> 模組呼叫時會傳回 PAM_USER_UNKNOWN,以避免" +"存取控制期間其他來源的使用者發生問題。" #. type: Content of: <reference><refentry><refsect1><title> #: pam_sss.8.xml:267 pam_sss_gss.8.xml:108 msgid "RETURN VALUES" -msgstr "" +msgstr "傳回值" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:270 pam_sss_gss.8.xml:111 msgid "PAM_SUCCESS" -msgstr "" +msgstr "PAM_SUCCESS" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:273 pam_sss_gss.8.xml:114 msgid "The PAM operation finished successfully." -msgstr "" +msgstr "PAM 作業成功完成。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:278 pam_sss_gss.8.xml:119 msgid "PAM_USER_UNKNOWN" -msgstr "" +msgstr "PAM_USER_UNKNOWN" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:281 msgid "" "The user is not known to the authentication service or the SSSD's PAM " "responder is not running." -msgstr "" +msgstr "驗證服務不認識此使用者,或 SSSD 的 PAM responder 未執行。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:287 pam_sss_gss.8.xml:128 msgid "PAM_AUTH_ERR" -msgstr "" +msgstr "PAM_AUTH_ERR" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:290 msgid "" "Authentication failure. Also, could be returned when there is a problem with " "getting the certificate." -msgstr "" +msgstr "驗證失敗。取得憑證時發生問題,也可能傳回此值。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:296 msgid "PAM_PERM_DENIED" -msgstr "" +msgstr "PAM_PERM_DENIED" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:299 msgid "" "Permission denied. The SSSD log files may contain additional information " "about the error." -msgstr "" +msgstr "拒絕存取。SSSD 記錄檔可能包含此錯誤的其他資訊。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:305 msgid "PAM_IGNORE" -msgstr "" +msgstr "PAM_IGNORE" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:308 @@ -7877,11 +8982,13 @@ msgid "" "See options <option>ignore_unknown_user</option> and " "<option>ignore_authinfo_unavail</option>." msgstr "" +"請參閱 <option>ignore_unknown_user</option> 與 <option>" +"ignore_authinfo_unavail</option> 選項。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:314 msgid "PAM_AUTHTOK_ERR" -msgstr "" +msgstr "PAM_AUTHTOK_ERR" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:317 @@ -7891,23 +8998,25 @@ msgid "" "available, but the installed version of GDM does not support selection from " "multiple certificates." msgstr "" +"無法取得新的驗證權杖。使用者以憑證驗證且有多個憑證可用,但安裝的 GDM 版本不支" +"援從多個憑證中選擇時,也可能傳回此值。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:325 pam_sss_gss.8.xml:136 msgid "PAM_AUTHINFO_UNAVAIL" -msgstr "" +msgstr "PAM_AUTHINFO_UNAVAIL" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:328 pam_sss_gss.8.xml:139 msgid "" "Unable to access the authentication information. This might be due to a " "network or hardware failure." -msgstr "" +msgstr "無法存取驗證資訊。這可能是由於網路或硬體故障。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:334 msgid "PAM_BUF_ERR" -msgstr "" +msgstr "PAM_BUF_ERR" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:337 @@ -7916,33 +9025,35 @@ msgid "" "or use_authtok were set, but no password was found from the previously " "stacked PAM module." msgstr "" +"發生記憶體錯誤。設定了 use_first_pass 或 use_authtok 選項,但從先前堆疊的 " +"PAM 模組找不到密碼時,也可能傳回此值。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:344 pam_sss_gss.8.xml:145 msgid "PAM_SYSTEM_ERR" -msgstr "" +msgstr "PAM_SYSTEM_ERR" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:347 pam_sss_gss.8.xml:148 msgid "" "A system error occurred. The SSSD log files may contain additional " "information about the error." -msgstr "" +msgstr "發生系統錯誤。SSSD 記錄檔可能包含此錯誤的其他資訊。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:353 msgid "PAM_CRED_ERR" -msgstr "" +msgstr "PAM_CRED_ERR" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:356 msgid "Unable to set the credentials of the user." -msgstr "" +msgstr "無法設定使用者的憑證。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:361 msgid "PAM_CRED_INSUFFICIENT" -msgstr "" +msgstr "PAM_CRED_INSUFFICIENT" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:364 @@ -7951,61 +9062,63 @@ msgid "" "user. For example, missing PIN during smartcard authentication or missing " "factor during two-factor authentication." msgstr "" +"應用程式沒有足夠的憑證可以驗證使用者。例如,smartcard 驗證期間缺少 PIN,或雙" +"因素驗證期間缺少因素。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:372 msgid "PAM_SERVICE_ERR" -msgstr "" +msgstr "PAM_SERVICE_ERR" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:375 msgid "Error in service module." -msgstr "" +msgstr "服務模組發生錯誤。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:380 msgid "PAM_NEW_AUTHTOK_REQD" -msgstr "" +msgstr "PAM_NEW_AUTHTOK_REQD" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:383 msgid "The user's authentication token has expired." -msgstr "" +msgstr "使用者的驗證權杖已到期。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:388 msgid "PAM_ACCT_EXPIRED" -msgstr "" +msgstr "PAM_ACCT_EXPIRED" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:391 msgid "The user account has expired." -msgstr "" +msgstr "使用者帳戶已到期。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:396 msgid "PAM_SESSION_ERR" -msgstr "" +msgstr "PAM_SESSION_ERR" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:399 msgid "Unable to fetch IPA Desktop Profile rules or user info." -msgstr "" +msgstr "無法取回 IPA 桌面設定檔規則或使用者資訊。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:404 msgid "PAM_CRED_UNAVAIL" -msgstr "" +msgstr "PAM_CRED_UNAVAIL" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:407 msgid "Unable to retrieve Kerberos user credentials." -msgstr "" +msgstr "無法取回 Kerberos 使用者憑證。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:412 msgid "PAM_NO_MODULE_DATA" -msgstr "" +msgstr "PAM_NO_MODULE_DATA" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:415 @@ -8014,61 +9127,63 @@ msgid "" "user has a Smartcard assigned but the pkint plugin is not available on the " "client." msgstr "" +"Kerberos 找不到任何驗證方法。若使用者已指派 Smartcard,但用戶端沒有可用的 " +"pkint 外掛程式,就可能發生這種情況。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:422 msgid "PAM_CONV_ERR" -msgstr "" +msgstr "PAM_CONV_ERR" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:425 msgid "Conversation failure." -msgstr "" +msgstr "交談失敗。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:430 msgid "PAM_AUTHTOK_LOCK_BUSY" -msgstr "" +msgstr "PAM_AUTHTOK_LOCK_BUSY" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:433 msgid "No KDC suitable for password change is available." -msgstr "" +msgstr "沒有可用於變更密碼的合適 KDC。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:438 msgid "PAM_ABORT" -msgstr "" +msgstr "PAM_ABORT" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:441 msgid "Unknown PAM call." -msgstr "" +msgstr "未知的 PAM 呼叫。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:446 msgid "PAM_MODULE_UNKNOWN" -msgstr "" +msgstr "PAM_MODULE_UNKNOWN" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:449 msgid "Unsupported PAM task or command." -msgstr "" +msgstr "不支援的 PAM 工作或指令。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:454 msgid "PAM_BAD_ITEM" -msgstr "" +msgstr "PAM_BAD_ITEM" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:457 msgid "The authentication module cannot handle Smartcard credentials." -msgstr "" +msgstr "驗證模組無法處理 Smartcard 憑證。" #. type: Content of: <reference><refentry><refsect1><title> #: pam_sss.8.xml:465 msgid "FILES" -msgstr "" +msgstr "檔案" #. type: Content of: <reference><refentry><refsect1><para> #: pam_sss.8.xml:466 @@ -8078,6 +9193,8 @@ msgid "" "displayed. This message can e.g. contain instructions about how to reset a " "password." msgstr "" +"若 root 重設密碼失敗(因為對應的 SSSD 提供者不支援密碼重設),可以顯示個別訊" +"息。此訊息可以例如包含如何重設密碼的說明。" #. type: Content of: <reference><refentry><refsect1><para> #: pam_sss.8.xml:471 @@ -8091,6 +9208,11 @@ msgid "" "the owner of the files and only root may have read and write permissions " "while all other users must have only read permissions." msgstr "" +"訊息從檔案 <filename>pam_sss_pw_reset_message.LOC</filename> 讀取,其中 LOC " +"代表 <citerefentry> <refentrytitle>setlocale</refentrytitle><manvolnum>3</" +"manvolnum> </citerefentry> 傳回的地區設定字串。若沒有相符的檔案,則顯示 " +"<filename>pam_sss_pw_reset_message.txt</filename> 的內容。root 必須是這些檔案" +"的所有者,而且只有 root 可以有讀寫權限,其他所有使用者只能有讀取權限。" #. type: Content of: <reference><refentry><refsect1><para> #: pam_sss.8.xml:481 @@ -8099,16 +9221,18 @@ msgid "" "<filename>/etc/sssd/customize/DOMAIN_NAME/</filename>. If no matching file " "is present a generic message is displayed." msgstr "" +"這些檔案會在目錄 <filename>/etc/sssd/customize/DOMAIN_NAME/</filename> 中搜尋" +"。若沒有相符的檔案,會顯示一般訊息。" #. type: Content of: <reference><refentry><refnamediv><refname> #: pam_sss_gss.8.xml:11 pam_sss_gss.8.xml:16 msgid "pam_sss_gss" -msgstr "" +msgstr "pam_sss_gss" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: pam_sss_gss.8.xml:17 msgid "PAM module for SSSD GSSAPI authentication" -msgstr "" +msgstr "SSSD GSSAPI 驗證的 PAM 模組" #. type: Content of: <reference><refentry><refsynopsisdiv><cmdsynopsis> #: pam_sss_gss.8.xml:22 @@ -8116,13 +9240,15 @@ msgid "" "<command>pam_sss_gss.so</command> <arg choice='opt'> " "<replaceable>debug</replaceable> </arg>" msgstr "" +"<command>pam_sss_gss.so</command> <arg choice='opt'> <replaceable>debug</" +"replaceable> </arg>" #. type: Content of: <reference><refentry><refsect1><para> #: pam_sss_gss.8.xml:32 msgid "" "<command>pam_sss_gss.so</command> authenticates user over GSSAPI in " "cooperation with SSSD." -msgstr "" +msgstr "<command>pam_sss_gss.so</command> 與 SSSD 合作,透過 GSSAPI 驗證使用者。" #. type: Content of: <reference><refentry><refsect1><para> #: pam_sss_gss.8.xml:36 @@ -8133,6 +9259,10 @@ msgid "" "name is derived by Kerberos internal mechanisms and it can be set explicitly " "in configuration of [domain_realm] section in /etc/krb5.conf." msgstr "" +"此模組會嘗試使用 GSSAPI 主機型服務名稱 host@hostname(會轉譯為 host/" +"hostname@REALM Kerberos principal)驗證使用者。Kerberos principal 名稱的 " +"<emphasis>REALM</emphasis> 部分由 Kerberos 內部機制推導,也可以在 /etc/" +"krb5.conf 的 [domain_realm] 區段設定中明確設定。" #. type: Content of: <reference><refentry><refsect1><para> #: pam_sss_gss.8.xml:44 @@ -8142,6 +9272,9 @@ msgid "" "the Kerberos credentials cache or if user's ticket granting ticket can be " "used to get the correct service ticket then the user will be authenticated." msgstr "" +"SSSD 用於提供所需的服務名稱,並使用 GSSAPI 呼叫驗證使用者的憑證。若服務票證已" +"存在於 Kerberos 憑證快取中,或可以使用使用者的票證授予票證取得正確的服務票證" +",則使用者會被驗證。" #. type: Content of: <reference><refentry><refsect1><para> #: pam_sss_gss.8.xml:51 @@ -8152,6 +9285,9 @@ msgid "" "Kerberos credentials must match with the user principal name as defined in " "LDAP." msgstr "" +"若 <option>pam_gssapi_check_upn</option> 為 True(預設),SSSD 會要求取得服務" +"票證所用的憑證可以與使用者關聯。這表示擁有 Kerberos 憑證的 principal 必須與 " +"LDAP 中定義的使用者 principal 名稱相符。" #. type: Content of: <reference><refentry><refsect1><para> #: pam_sss_gss.8.xml:58 @@ -8165,6 +9301,13 @@ msgid "" "</citerefentry> and <citerefentry> <refentrytitle>sssd-krb5</refentrytitle> " "<manvolnum>5</manvolnum> </citerefentry> for more details on these options." msgstr "" +"若要在 SSSD 中啟用 GSSAPI 驗證,請在 sssd.conf 的 [pam] 或網域區段設定 " +"<option>pam_gssapi_services</option> 選項。服務憑證需要儲存在 SSSD 的 keytab " +"中(若您使用 ipa 或 ad 提供者,keytab 已存在)。keytab 位置可以使用 <option>" +"krb5_keytab</option> 選項設定。這些選項的更多詳細資料請參閱 <citerefentry> " +"<refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</manvolnum> </" +"citerefentry> 與 <citerefentry> <refentrytitle>sssd-krb5</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry>。" #. type: Content of: <reference><refentry><refsect1><para> #: pam_sss_gss.8.xml:74 @@ -8175,6 +9318,9 @@ msgid "" "presence of authentication indicators in the service tickets before a " "particular PAM service can be accessed." msgstr "" +"某些 Kerberos 部署允許將驗證指標與使用者取得票證授予票證所使用的特定預先驗證" +"方法關聯。<command>pam_sss_gss.so</command> 允許在存取特定 PAM 服務之前,強制" +"服務票證中存在驗證指標。" #. type: Content of: <reference><refentry><refsect1><para> #: pam_sss_gss.8.xml:82 @@ -8183,33 +9329,35 @@ msgid "" "section of sssd.conf, then SSSD will perform a check of the presence of any " "configured indicators in the service ticket." msgstr "" +"若在 sssd.conf 的 [pam] 或網域區段設定 <option>pam_gssapi_indicators_map</" +"option>,SSSD 會檢查服務票證中是否存在任何已設定的指標。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss_gss.8.xml:93 msgid "<option>debug</option>" -msgstr "" +msgstr "<option>debug</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss_gss.8.xml:96 msgid "Print debugging information." -msgstr "" +msgstr "列印除錯資訊。" #. type: Content of: <reference><refentry><refsect1><para> #: pam_sss_gss.8.xml:104 msgid "Only the <option>auth</option> module type is provided." -msgstr "" +msgstr "只提供 <option>auth</option> 模組類型。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss_gss.8.xml:122 msgid "" "The user is not known to the authentication service or the GSSAPI " "authentication is not supported." -msgstr "" +msgstr "驗證服務不認識此使用者,或不支援 GSSAPI 驗證。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss_gss.8.xml:131 msgid "Authentication failure." -msgstr "" +msgstr "驗證失敗。" #. type: Content of: <reference><refentry><refsect1><para> #: pam_sss_gss.8.xml:159 @@ -8218,6 +9366,8 @@ msgid "" "without the need to disable authentication completely. To achieve this, " "first enable GSSAPI authentication for sudo in sssd.conf:" msgstr "" +"主要使用案例是在 sudo 中提供免密碼驗證,但不需要完全停用驗證。要做到這點,請" +"先在 sssd.conf 中為 sudo 啟用 GSSAPI 驗證:" #. type: Content of: <reference><refentry><refsect1><programlisting> #: pam_sss_gss.8.xml:165 @@ -8227,6 +9377,9 @@ msgid "" "pam_gssapi_services = sudo, sudo-i\n" " " msgstr "" +"[domain/MYDOMAIN]\n" +"pam_gssapi_services = sudo, sudo-i\n" +" " #. type: Content of: <reference><refentry><refsect1><para> #: pam_sss_gss.8.xml:169 @@ -8234,6 +9387,8 @@ msgid "" "And then enable the module in desired PAM stack (e.g. /etc/pam.d/sudo and " "/etc/pam.d/sudo-i)." msgstr "" +"然後在所需的 PAM 堆疊中啟用此模組(例如 /etc/pam.d/sudo 與 /etc/pam.d/sudo-i" +")。" #. type: Content of: <reference><refentry><refsect1><programlisting> #: pam_sss_gss.8.xml:173 @@ -8244,11 +9399,15 @@ msgid "" "...\n" " " msgstr "" +"...\n" +"auth sufficient pam_sss_gss.so\n" +"...\n" +" " #. type: Content of: <reference><refentry><refsect1><title> #: pam_sss_gss.8.xml:180 msgid "TROUBLESHOOTING" -msgstr "" +msgstr "疑難排解" #. type: Content of: <reference><refentry><refsect1><para> #: pam_sss_gss.8.xml:182 @@ -8256,6 +9415,8 @@ msgid "" "SSSD logs, pam_sss_gss debug output and syslog may contain helpful " "information about the error. Here are some common issues:" msgstr "" +"SSSD 記錄、pam_sss_gss 除錯輸出與 syslog 可能包含此錯誤的實用資訊。以下是一些" +"常見問題:" #. type: Content of: <reference><refentry><refsect1><para> #: pam_sss_gss.8.xml:186 @@ -8266,6 +9427,9 @@ msgid "" "<option>env_keep</option> in /etc/sudoers or in your LDAP sudo rules default " "options." msgstr "" +"1. 我已設定 KRB5CCNAME 環境變數,但驗證無法運作:視您的 sudo 版本而定,sudo " +"可能不會將此變數傳遞給 PAM 環境。請嘗試在 /etc/sudoers 或 LDAP sudo 規則的預" +"設選項中,將 KRB5CCNAME 加入 <option>env_keep</option>。" #. type: Content of: <reference><refentry><refsect1><para> #: pam_sss_gss.8.xml:193 @@ -8275,6 +9439,9 @@ msgid "" "for the service ticket based on the hostname. Try adding the hostname " "directly to <option>[domain_realm]</option> in /etc/krb5.conf like so:" msgstr "" +"2. 驗證無法運作,且 syslog 包含 \"Server not found in Kerberos database\":" +"Kerberos 可能無法根據主機名稱解析服務票證的正確 realm。請嘗試像這樣直接將主機" +"名稱加入 /etc/krb5.conf 中的 <option>[domain_realm]</option>:" #. type: Content of: <reference><refentry><refsect1><para> #: pam_sss_gss.8.xml:200 @@ -8284,6 +9451,9 @@ msgid "" "obtain the required service ticket. Use kinit or authenticate over SSSD to " "acquire those credentials." msgstr "" +"3. 驗證無法運作,且 syslog 包含 \"No Kerberos credentials available\":您沒有" +"任何可以用來取得所需服務票證的憑證。請使用 kinit 或透過 SSSD 驗證來取得這些憑" +"證。" #. type: Content of: <reference><refentry><refsect1><para> #: pam_sss_gss.8.xml:206 @@ -8295,6 +9465,10 @@ msgid "" "principal, make sure you authenticated with SSSD or consider disabling " "<option>pam_gssapi_check_upn</option>." msgstr "" +"4. 驗證無法運作,且 SSSD sssd-pam 記錄包含 \"User with UPN [$UPN] was not " +"found.\" 或 \"UPN [$UPN] does not match target user [$username].\":您使用的" +"憑證無法對應到正在驗證的使用者。請嘗試使用 kswitch 選取不同的 principal,確認" +"您是透過 SSSD 驗證,或考慮停用 <option>pam_gssapi_check_upn</option>。" #. type: Content of: <reference><refentry><refsect1><programlisting> #: pam_sss_gss.8.xml:214 @@ -8304,16 +9478,19 @@ msgid "" ".myhostname = MYREALM\n" " " msgstr "" +"[domain_realm]\n" +".myhostname = MYREALM\n" +" " #. type: Content of: <reference><refentry><refnamediv><refname> #: sssd_krb5_locator_plugin.8.xml:10 sssd_krb5_locator_plugin.8.xml:15 msgid "sssd_krb5_locator_plugin" -msgstr "" +msgstr "sssd_krb5_locator_plugin" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sssd_krb5_locator_plugin.8.xml:16 msgid "Kerberos locator plugin" -msgstr "" +msgstr "Kerberos locator 外掛程式" #. type: Content of: <reference><refentry><refsect1><para> #: sssd_krb5_locator_plugin.8.xml:22 @@ -8327,6 +9504,11 @@ msgid "" "unexpected authentication failures and maybe even account lockings it would " "be good to talk to a single KDC as long as possible." msgstr "" +"Kerberos locator 外掛程式 <command>sssd_krb5_locator_plugin</command> 由 " +"libkrb5 用來尋找給定 Kerberos realm 的 KDC。SSSD 提供這種外掛程式,將系統上的" +"所有 Kerberos 用戶端引導到單一 KDC。一般來說,用戶端程序與哪個 KDC 通訊並不重" +"要。但在某些情況下(例如密碼變更之後),由於新資料必須先複寫,並非所有 KDC 都" +"處於相同狀態。為避免意外的驗證失敗,甚至帳戶鎖定,最好盡可能與單一 KDC 通訊。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd_krb5_locator_plugin.8.xml:34 @@ -8342,6 +9524,14 @@ msgid "" "plugin. With this the plugin is still called but will provide no data to the " "caller so that libkrb5 can fall back to other methods defined in krb5.conf." msgstr "" +"libkrb5 會在 Kerberos 外掛程式目錄的 libkrb5 子目錄中搜尋 locator 外掛程式," +"詳情請參閱 <citerefentry> <refentrytitle>krb5.conf</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry> 中的 plugin_base_dir。外掛程式只能透" +"過移除外掛程式檔案來停用。Kerberos 設定中沒有可以停用它的選項。但可以使用 " +"SSSD_KRB5_LOCATOR_DISABLE 環境變數為個別指令停用外掛程式。另一種做法是使用 " +"SSSD 選項 krb5_use_kdcinfo=False,不要產生外掛程式需要的資料。這樣外掛程式仍" +"然會被呼叫,但不會提供任何資料給呼叫端,libkrb5 因此可以退回 krb5.conf 中定義" +"的其他方法。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd_krb5_locator_plugin.8.xml:50 @@ -8353,36 +9543,40 @@ msgid "" "separated with a colon, the IPv6 address has to be enclosed in squared " "brackets in this case as usual. Valid entries are:" msgstr "" +"外掛程式會從名為 <filename>kdcinfo.REALM</filename> 的檔案讀取給定 realm 的 " +"KDC 資訊。檔案應包含一個或多個 DNS 名稱或 IP 位址,使用點十進位 IPv4 表示法或" +"十六進位 IPv6 表示法。可以將選用的連接埠號碼以冒號分隔加在結尾,這種情況下 " +"IPv6 位址必須照慣例以方括號括起來。有效的項目有:" #. type: Content of: <reference><refentry><refsect1><para><itemizedlist><listitem><para> #: sssd_krb5_locator_plugin.8.xml:58 msgid "kdc.example.com" -msgstr "" +msgstr "kdc.example.com" #. type: Content of: <reference><refentry><refsect1><para><itemizedlist><listitem><para> #: sssd_krb5_locator_plugin.8.xml:59 msgid "kdc.example.com:321" -msgstr "" +msgstr "kdc.example.com:321" #. type: Content of: <reference><refentry><refsect1><para><itemizedlist><listitem><para> #: sssd_krb5_locator_plugin.8.xml:60 msgid "1.2.3.4" -msgstr "" +msgstr "1.2.3.4" #. type: Content of: <reference><refentry><refsect1><para><itemizedlist><listitem><para> #: sssd_krb5_locator_plugin.8.xml:61 msgid "5.6.7.8:99" -msgstr "" +msgstr "5.6.7.8:99" #. type: Content of: <reference><refentry><refsect1><para><itemizedlist><listitem><para> #: sssd_krb5_locator_plugin.8.xml:62 msgid "2001:db8:85a3::8a2e:370:7334" -msgstr "" +msgstr "2001:db8:85a3::8a2e:370:7334" #. type: Content of: <reference><refentry><refsect1><para><itemizedlist><listitem><para> #: sssd_krb5_locator_plugin.8.xml:63 msgid "[2001:db8:85a3::8a2e:370:7334]:321" -msgstr "" +msgstr "[2001:db8:85a3::8a2e:370:7334]:321" #. type: Content of: <reference><refentry><refsect1><para> #: sssd_krb5_locator_plugin.8.xml:65 @@ -8391,6 +9585,8 @@ msgid "" "adds the address of the current KDC or domain controller SSSD is using to " "this file." msgstr "" +"SSSD 的 krb5 auth-provider(IPA 與 AD 提供者也使用)會將 SSSD 目前使用的 KDC " +"或網域控制站位址加入此檔案。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd_krb5_locator_plugin.8.xml:70 @@ -8404,6 +9600,11 @@ msgid "" "for the MIT Kerberos specific master KDC. If the address contains a port " "number the default KDC port 88 will be used for the latter." msgstr "" +"在同時具有唯讀與讀寫 KDC 的環境中(預期用戶端對一般作業使用唯讀執行個體,只對" +"密碼變更之類的設定變更使用讀寫 KDC),也會使用 <filename>kpasswdinfo.REALM</" +"filename> 來識別讀寫 KDC。若給定 realm 存在此檔案,外掛程式會使用其內容回覆 " +"kpasswd 或 kadmin 伺服器,或 MIT Kerberos 特定 master KDC 的要求。若位址包含" +"連接埠號碼,後者會使用預設的 KDC 連接埠 88。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd_krb5_locator_plugin.8.xml:85 @@ -8412,13 +9613,16 @@ msgid "" "<command>sssd_krb5_locator_plugin</command> is not available on your system " "you have to edit /etc/krb5.conf to reflect your Kerberos setup." msgstr "" +"並非所有 Kerberos 實作都支援使用外掛程式。若您的系統沒有 <command>" +"sssd_krb5_locator_plugin</command>,您必須編輯 /etc/krb5.conf 以反映您的 " +"Kerberos 設定。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd_krb5_locator_plugin.8.xml:91 msgid "" "If the environment variable SSSD_KRB5_LOCATOR_DEBUG is set to any value " "debug messages will be sent to stderr." -msgstr "" +msgstr "若 SSSD_KRB5_LOCATOR_DEBUG 環境變數設為任何值,除錯訊息會傳送到 stderr。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd_krb5_locator_plugin.8.xml:95 @@ -8427,6 +9631,8 @@ msgid "" "the plugin is disabled and will just return KRB5_PLUGIN_NO_HANDLE to the " "caller." msgstr "" +"若 SSSD_KRB5_LOCATOR_DISABLE 環境變數設為任何值,外掛程式會被停用,只會向呼叫" +"端傳回 KRB5_PLUGIN_NO_HANDLE。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd_krb5_locator_plugin.8.xml:100 @@ -8436,16 +9642,19 @@ msgid "" "default plugin returns KRB5_PLUGIN_NO_HANDLE to the caller immediately on " "first DNS resolving failure." msgstr "" +"若 SSSD_KRB5_LOCATOR_IGNORE_DNS_FAILURES 環境變數設為任何值,外掛程式會嘗試解" +"析 kdcinfo 檔案中的所有 DNS 名稱。預設情況下,外掛程式在第一次 DNS 解析失敗時" +"會立即向呼叫端傳回 KRB5_PLUGIN_NO_HANDLE。" #. type: Content of: <reference><refentry><refnamediv><refname> #: sssd-simple.5.xml:10 sssd-simple.5.xml:16 msgid "sssd-simple" -msgstr "" +msgstr "sssd-simple" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sssd-simple.5.xml:17 msgid "the configuration file for SSSD's 'simple' access-control provider" -msgstr "" +msgstr "SSSD 'simple' 存取控制提供者的設定檔" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-simple.5.xml:24 @@ -8457,6 +9666,10 @@ msgid "" "<refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</manvolnum> " "</citerefentry> manual page." msgstr "" +"本手冊頁說明 <citerefentry> <refentrytitle>sssd</refentrytitle> <manvolnum>" +"8</manvolnum> </citerefentry> 之 simple 存取控制提供者的設定。詳細的語法參考" +"請參閱 <citerefentry> <refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry> 手冊頁的 <quote>FILE FORMAT</quote> 一節。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-simple.5.xml:38 @@ -8464,11 +9677,13 @@ msgid "" "The simple access provider grants or denies access based on an access or " "deny list of user or group names. The following rules apply:" msgstr "" +"simple access 提供者根據使用者或群組名稱的允許或拒絕清單授予或拒絕存取。適用" +"下列規則:" #. type: Content of: <reference><refentry><refsect1><para><itemizedlist><listitem><para> #: sssd-simple.5.xml:43 msgid "If all lists are empty, access is granted" -msgstr "" +msgstr "若所有清單都是空的,則授予存取權" #. type: Content of: <reference><refentry><refsect1><para><itemizedlist><listitem><para> #: sssd-simple.5.xml:47 @@ -8476,6 +9691,8 @@ msgid "" "If any list is provided, the order of evaluation is allow,deny. This means " "that any matching deny rule will supersede any matched allow rule." msgstr "" +"若提供了任何清單,評估順序為 allow、deny。這表示任何相符的 deny 規則都會取代" +"任何相符的 allow 規則。" #. type: Content of: <reference><refentry><refsect1><para><itemizedlist><listitem><para> #: sssd-simple.5.xml:54 @@ -8483,38 +9700,40 @@ msgid "" "If either or both \"allow\" lists are provided, all users are denied unless " "they appear in the list." msgstr "" +"若提供了其中一個或兩個 \"allow\" 清單,則所有使用者都會被拒絕,除非他們出現在" +"清單中。" #. type: Content of: <reference><refentry><refsect1><para><itemizedlist><listitem><para> #: sssd-simple.5.xml:60 msgid "" "If only \"deny\" lists are provided, all users are granted access unless " "they appear in the list." -msgstr "" +msgstr "若只提供 \"deny\" 清單,則所有使用者都會被授予存取權,除非他們出現在清單中。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-simple.5.xml:78 msgid "simple_allow_users (string)" -msgstr "" +msgstr "simple_allow_users (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-simple.5.xml:81 msgid "Comma separated list of users who are allowed to log in." -msgstr "" +msgstr "允許登入之使用者的逗號分隔清單。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-simple.5.xml:88 msgid "simple_deny_users (string)" -msgstr "" +msgstr "simple_deny_users (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-simple.5.xml:91 msgid "Comma separated list of users who are explicitly denied access." -msgstr "" +msgstr "被明確拒絕存取之使用者的逗號分隔清單。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-simple.5.xml:97 msgid "simple_allow_groups (string)" -msgstr "" +msgstr "simple_allow_groups (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-simple.5.xml:100 @@ -8522,11 +9741,13 @@ msgid "" "Comma separated list of groups that are allowed to log in. This applies only " "to groups within this SSSD domain. Local groups are not evaluated." msgstr "" +"允許登入的群組清單,以逗號分隔。此設定僅適用於此 SSSD 網域內的群組。本機群組" +"不予評估。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-simple.5.xml:108 msgid "simple_deny_groups (string)" -msgstr "" +msgstr "simple_deny_groups (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-simple.5.xml:111 @@ -8535,6 +9756,8 @@ msgid "" "applies only to groups within this SSSD domain. Local groups are not " "evaluated." msgstr "" +"明確拒絕存取的群組清單,以逗號分隔。此設定僅適用於此 SSSD 網域內的群組。本機" +"群組不予評估。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-simple.5.xml:70 sssd-ipa.5.xml:83 sssd-ad.5.xml:131 @@ -8544,6 +9767,9 @@ msgid "" "</citerefentry> manual page for details on the configuration of an SSSD " "domain. <placeholder type=\"variablelist\" id=\"0\"/>" msgstr "" +"SSSD 網域設定的詳細資料請參閱 <citerefentry> <refentrytitle>sssd.conf</" +"refentrytitle> <manvolnum>5</manvolnum> </citerefentry> 手冊頁的 <quote>" +"DOMAIN SECTIONS</quote> 一節。<placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-simple.5.xml:120 @@ -8552,13 +9778,15 @@ msgid "" "entirely. Beware of this while generating parameters for the simple provider " "using automated scripts." msgstr "" +"不為任何清單指定值等同於完全跳過它。使用自動化指令碼為 simple 提供者產生參數" +"時,請注意這一點。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-simple.5.xml:125 msgid "" "Please note that it is an configuration error if both, simple_allow_users " "and simple_deny_users, are defined." -msgstr "" +msgstr "請注意,若同時定義 simple_allow_users 與 simple_deny_users,就是設定錯誤。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-simple.5.xml:133 @@ -8568,6 +9796,9 @@ msgid "" "section. This examples shows only the simple access provider-specific " "options." msgstr "" +"下列範例假設 SSSD 已正確設定,且 example.com 是 <replaceable>[sssd]</" +"replaceable> 區段中的其中一個網域。此範例只顯示 simple access 提供者專屬的選" +"項。" #. type: Content of: <reference><refentry><refsect1><para><programlisting> #: sssd-simple.5.xml:140 @@ -8577,6 +9808,9 @@ msgid "" "access_provider = simple\n" "simple_allow_users = user1, user2\n" msgstr "" +"[domain/example.com]\n" +"access_provider = simple\n" +"simple_allow_users = user1, user2\n" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-simple.5.xml:150 @@ -8588,23 +9822,27 @@ msgid "" "<refentrytitle>sssd-ldap</refentrytitle><manvolnum>5</manvolnum> " "</citerefentry>) option." msgstr "" +"完整的群組成員階層會在存取檢查之前解析,因此即使是巢狀群組也可以包含在存取清" +"單中。請注意,<quote>ldap_group_nesting_level</quote> 選項可能影響結果,應設" +"為足夠的值。(<citerefentry> <refentrytitle>sssd-ldap</refentrytitle>" +"<manvolnum>5</manvolnum> </citerefentry>) 選項。" #. type: Content of: <reference><refentry><refnamediv><refname> #: sss-certmap.5.xml:10 sss-certmap.5.xml:16 msgid "sss-certmap" -msgstr "" +msgstr "sss-certmap" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sss-certmap.5.xml:17 msgid "SSSD Certificate Matching and Mapping Rules" -msgstr "" +msgstr "SSSD 憑證匹配與對應規則" #. type: Content of: <reference><refentry><refsect1><para> #: sss-certmap.5.xml:23 msgid "" "The manual page describes the rules which can be used by SSSD and other " "components to match X.509 certificates and map them to accounts." -msgstr "" +msgstr "本手冊頁說明 SSSD 與其他元件可以用來匹配 X.509 憑證並將它們對應到帳戶的規則。" #. type: Content of: <reference><refentry><refsect1><para> #: sss-certmap.5.xml:28 @@ -8619,6 +9857,13 @@ msgid "" "encoded binary. If no domains are given only the local domain will be " "searched." msgstr "" +"每個規則有四個組成部分:<quote>priority</quote>(優先順序)、<quote>matching " +"rule</quote>(匹配規則)、<quote>mapping rule</quote>(對應規則)與 <quote>" +"domain list</quote>(網域清單)。所有組成部分都是選用的。缺少 <quote>" +"priority</quote> 會以最低優先順序加入規則。預設的 <quote>matching rule</" +"quote> 會匹配具有 digitalSignature 金鑰用法與 clientAuth 擴充金鑰用法的憑證。" +"若 <quote>mapping rule</quote> 為空,會在 userCertificate 屬性中以 DER 編碼二" +"進位搜尋憑證。若未指定網域,只會搜尋本機網域。" #. type: Content of: <reference><refentry><refsect1><para> #: sss-certmap.5.xml:39 @@ -8630,6 +9875,10 @@ msgid "" "the default type will be used which is 'KRB5' for the matching rules and " "'LDAP' for the mapping rules." msgstr "" +"為了允許延伸或完全不同的規則樣式,<quote>mapping</quote> 與 <quote>matching " +"rules</quote> 可以包含一個前綴,以 ':' 與規則的主要部分分隔。前綴只能包含大" +"寫 ASCII 字母與數字。若省略前綴,會使用預設類型,即 matching rules 使用 " +"'KRB5'、mapping rules 使用 'LDAP'。" #. type: Content of: <reference><refentry><refsect1><para> #: sss-certmap.5.xml:48 @@ -8638,16 +9887,18 @@ msgid "" "given certificate matches a matching rules and how the output of a mapping " "rule would look like." msgstr "" +"'sssctl' 工具提供 'cert-eval-rule' 指令,可以檢查給定的憑證是否符合匹配規則," +"以及對應規則的輸出看起來如何。" #. type: Content of: <reference><refentry><refsect1><title> #: sss-certmap.5.xml:55 msgid "RULE COMPONENTS" -msgstr "" +msgstr "規則組成部分" #. type: Content of: <reference><refentry><refsect1><refsect2><title> #: sss-certmap.5.xml:57 msgid "PRIORITY" -msgstr "" +msgstr "優先順序" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sss-certmap.5.xml:59 @@ -8657,6 +9908,8 @@ msgid "" "missing value indicates the lowest priority. The rules processing is stopped " "when a matched rule is found and no further rules are checked." msgstr "" +"規則依優先順序處理,數字 '0'(零)表示最高優先順序。數字越大優先順序越低。缺" +"少值表示最低優先順序。找到相符的規則時,規則處理會停止,不再檢查其他規則。" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sss-certmap.5.xml:66 @@ -8664,6 +9917,8 @@ msgid "" "Internally the priority is treated as unsigned 32bit integer, using a " "priority value larger than 4294967295 will cause an error." msgstr "" +"內部會將優先順序視為無符號 32 位元整數,使用大於 4294967295 的優先順序值會導" +"致錯誤。" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sss-certmap.5.xml:70 @@ -8675,11 +9930,15 @@ msgid "" "or make the matching rules more specific e.g. by using distinct " "<ISSUER> patterns." msgstr "" +"若多個規則具有相同的優先順序,且只有其中一個相關匹配規則適用,則會選擇此規則" +"。若有多個相同優先順序的規則都匹配,會選擇其中一個,但選中哪一個未定義。為避" +"免這種未定義行為,請使用不同的優先順序,或讓匹配規則更具體,例如使用不同的 " +"<ISSUER> 模式。" #. type: Content of: <reference><refentry><refsect1><refsect2><title> #: sss-certmap.5.xml:79 msgid "MATCHING RULE" -msgstr "" +msgstr "匹配規則" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sss-certmap.5.xml:81 @@ -8692,6 +9951,10 @@ msgid "" "match. Multiple keyword pattern pairs can be either joined with '&&' " "(and) or '||' (or)." msgstr "" +"匹配規則用於選取應套用對應規則的憑證。它使用的系統類似 MIT Kerberos 的 " +"<quote>pkinit_cert_match</quote> 選項使用的系統。它由以 '<' 與 '>' 括起" +"來的關鍵字(識別憑證的特定部分)與模式(規則要匹配必須找到的內容)組成。多個" +"關鍵字模式配對可以以 '&&'(且)或 '||'(或)連接。" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sss-certmap.5.xml:90 @@ -8701,11 +9964,15 @@ msgid "" "rules</quote> so that \"<SUBJECT>.*,DC=MY,DC=DOMAIN\" and " "\"KRB5:<SUBJECT>.*,DC=MY,DC=DOMAIN\" are equivalent." msgstr "" +"鑑於與 MIT Kerberos 的相似性,此規則的類型前綴是 'KRB5'。但 'KRB5' 也會是 " +"<quote>matching rules</quote> 的預設值,因此 " +"\"<SUBJECT>.*,DC=MY,DC=DOMAIN\" 與 " +"\"KRB5:<SUBJECT>.*,DC=MY,DC=DOMAIN\" 是等價的。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:99 msgid "<SUBJECT>regular-expression" -msgstr "" +msgstr "<SUBJECT>regular-expression" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:102 @@ -8714,6 +9981,8 @@ msgid "" "matched. For the matching POSIX Extended Regular Expression syntax is used, " "see regex(7) for details." msgstr "" +"使用這個可以匹配憑證主旨名稱的一部分或全部。匹配使用 POSIX 延伸正規表示式語法" +",詳情請參閱 regex(7)。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:108 @@ -8727,11 +9996,16 @@ msgid "" "confusion those attribute names are best not used or covered by a suitable " "regular-expression." msgstr "" +"進行匹配時,儲存在憑證中 DER 編碼 ASN.1 的主旨名稱會依照 RFC 4514 轉換為字串" +"。這表示最具體的名稱組成部分會排在前面。請注意,RFC 4514 並未涵蓋所有可能的屬" +"性名稱。包含的名稱有 'CN'、'L'、'ST'、'O'、'OU'、'C'、'STREET'、'DC' 與 " +"'UID'。其他屬性名稱在不同平台與不同工具上可能顯示不同。為避免混淆,最好不要使" +"用這些屬性名稱,或使用合適的正規表示式涵蓋它們。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:121 msgid "Example: <SUBJECT>.*,DC=MY,DC=DOMAIN" -msgstr "" +msgstr "範例:<SUBJECT>.*,DC=MY,DC=DOMAIN" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:124 @@ -8740,16 +10014,18 @@ msgid "" "regular expressions and must be escaped with the help of the '\\' character " "so that they are matched as ordinary characters." msgstr "" +"請注意,\"^.[$()|*+?{\\\" 這些字元在正規表示式中有特殊意義,必須借助 '\\' 字" +"元逸出,才能當作一般字元匹配。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:130 msgid "Example: <SUBJECT>^CN=.* \\(Admin\\),DC=MY,DC=DOMAIN$" -msgstr "" +msgstr "範例:<SUBJECT>^CN=.* \\(Admin\\),DC=MY,DC=DOMAIN$" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:135 msgid "<ISSUER>regular-expression" -msgstr "" +msgstr "<ISSUER>regular-expression" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:138 @@ -8757,85 +10033,87 @@ msgid "" "With this a part or the whole issuer name of the certificate can be " "matched. All comments for <SUBJECT> apply her as well." msgstr "" +"使用這個可以匹配憑證簽發者名稱的一部分或全部。所有針對 <SUBJECT> 的註解" +"也適用於此。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:143 msgid "Example: <ISSUER>^CN=My-CA,DC=MY,DC=DOMAIN$" -msgstr "" +msgstr "範例:<ISSUER>^CN=My-CA,DC=MY,DC=DOMAIN$" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:148 msgid "<KU>key-usage" -msgstr "" +msgstr "<KU>key-usage" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:151 msgid "" "This option can be used to specify which key usage values the certificate " "should have. The following values can be used in a comma separated list:" -msgstr "" +msgstr "此選項可以用來指定憑證應具有哪些金鑰用法值。可以在逗號分隔清單中使用下列值:" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sss-certmap.5.xml:155 msgid "digitalSignature" -msgstr "" +msgstr "digitalSignature" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sss-certmap.5.xml:156 msgid "nonRepudiation" -msgstr "" +msgstr "nonRepudiation" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sss-certmap.5.xml:157 msgid "keyEncipherment" -msgstr "" +msgstr "keyEncipherment" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sss-certmap.5.xml:158 msgid "dataEncipherment" -msgstr "" +msgstr "dataEncipherment" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sss-certmap.5.xml:159 msgid "keyAgreement" -msgstr "" +msgstr "keyAgreement" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sss-certmap.5.xml:160 msgid "keyCertSign" -msgstr "" +msgstr "keyCertSign" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sss-certmap.5.xml:161 msgid "cRLSign" -msgstr "" +msgstr "cRLSign" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sss-certmap.5.xml:162 msgid "encipherOnly" -msgstr "" +msgstr "encipherOnly" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sss-certmap.5.xml:163 msgid "decipherOnly" -msgstr "" +msgstr "decipherOnly" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:167 msgid "" "A numerical value in the range of a 32bit unsigned integer can be used as " "well to cover special use cases." -msgstr "" +msgstr "也可以使用 32 位元無符號整數範圍內的數值,以涵蓋特殊使用案例。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:171 msgid "Example: <KU>digitalSignature,keyEncipherment" -msgstr "" +msgstr "範例:<KU>digitalSignature,keyEncipherment" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:176 msgid "<EKU>extended-key-usage" -msgstr "" +msgstr "<EKU>extended-key-usage" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:179 @@ -8843,68 +10121,70 @@ msgid "" "This option can be used to specify which extended key usage the certificate " "should have. The following value can be used in a comma separated list:" msgstr "" +"此選項可以用來指定憑證應具有哪些擴充金鑰用法。可以在逗號分隔清單中使用下列值" +":" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sss-certmap.5.xml:183 msgid "serverAuth" -msgstr "" +msgstr "serverAuth" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sss-certmap.5.xml:184 msgid "clientAuth" -msgstr "" +msgstr "clientAuth" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sss-certmap.5.xml:185 msgid "codeSigning" -msgstr "" +msgstr "codeSigning" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sss-certmap.5.xml:186 msgid "emailProtection" -msgstr "" +msgstr "emailProtection" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sss-certmap.5.xml:187 msgid "timeStamping" -msgstr "" +msgstr "timeStamping" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sss-certmap.5.xml:188 msgid "OCSPSigning" -msgstr "" +msgstr "OCSPSigning" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sss-certmap.5.xml:189 msgid "KPClientAuth" -msgstr "" +msgstr "KPClientAuth" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sss-certmap.5.xml:190 msgid "pkinit" -msgstr "" +msgstr "pkinit" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sss-certmap.5.xml:191 msgid "msScLogin" -msgstr "" +msgstr "msScLogin" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:195 msgid "" "Extended key usages which are not listed above can be specified with their " "OID in dotted-decimal notation." -msgstr "" +msgstr "未列於上方的擴充金鑰用法可以使用其 OID 以點十進位表示法指定。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:199 msgid "Example: <EKU>clientAuth,1.3.6.1.5.2.3.4" -msgstr "" +msgstr "範例:<EKU>clientAuth,1.3.6.1.5.2.3.4" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:204 msgid "<SAN>regular-expression" -msgstr "" +msgstr "<SAN>regular-expression" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:207 @@ -8913,61 +10193,63 @@ msgid "" "Kerberos principals in the PKINIT or AD NT Principal SAN as " "<SAN:Principal> does." msgstr "" +"為了與 MIT Kerberos 的用法相容,此選項會像 <SAN:Principal> 一樣匹配 " +"PKINIT 或 AD NT Principal SAN 中的 Kerberos principal。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:212 msgid "Example: <SAN>.*@MY\\.REALM" -msgstr "" +msgstr "範例:<SAN>.*@MY\\.REALM" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:217 msgid "<SAN:Principal>regular-expression" -msgstr "" +msgstr "<SAN:Principal>regular-expression" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:220 msgid "Match the Kerberos principals in the PKINIT or AD NT Principal SAN." -msgstr "" +msgstr "匹配 PKINIT 或 AD NT Principal SAN 中的 Kerberos principal。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:224 msgid "Example: <SAN:Principal>.*@MY\\.REALM" -msgstr "" +msgstr "範例:<SAN:Principal>.*@MY\\.REALM" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:229 msgid "<SAN:ntPrincipalName>regular-expression" -msgstr "" +msgstr "<SAN:ntPrincipalName>regular-expression" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:232 msgid "Match the Kerberos principals from the AD NT Principal SAN." -msgstr "" +msgstr "匹配 AD NT Principal SAN 中的 Kerberos principal。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:236 msgid "Example: <SAN:ntPrincipalName>.*@MY.AD.REALM" -msgstr "" +msgstr "範例:<SAN:ntPrincipalName>.*@MY.AD.REALM" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:241 msgid "<SAN:pkinit>regular-expression" -msgstr "" +msgstr "<SAN:pkinit>regular-expression" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:244 msgid "Match the Kerberos principals from the PKINIT SAN." -msgstr "" +msgstr "匹配 PKINIT SAN 中的 Kerberos principal。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:247 msgid "Example: <SAN:ntPrincipalName>.*@MY\\.PKINIT\\.REALM" -msgstr "" +msgstr "範例:<SAN:ntPrincipalName>.*@MY\\.PKINIT\\.REALM" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:252 msgid "<SAN:dotted-decimal-oid>regular-expression" -msgstr "" +msgstr "<SAN:dotted-decimal-oid>regular-expression" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:255 @@ -8976,16 +10258,18 @@ msgid "" "dotted-decimal notation, interpret it as string and try to match it against " "the regular expression." msgstr "" +"取以點十進位表示法之 OID 指定的 otherName SAN 組成部分值,將其解讀為字串,並" +"嘗試以正規表示式匹配它。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:261 msgid "Example: <SAN:1.2.3.4>test" -msgstr "" +msgstr "範例:<SAN:1.2.3.4>test" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:266 msgid "<SAN:otherName>base64-string" -msgstr "" +msgstr "<SAN:otherName>base64-string" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:269 @@ -8995,61 +10279,63 @@ msgid "" "otherName components with special encodings which could not be treated as " "strings." msgstr "" +"以 base64 編碼的 blob 對所有 otherName SAN 組成部分執行二進位匹配。使用此選項" +"可以匹配無法當作字串處理、具有特殊編碼的自訂 otherName 組成部分。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:276 msgid "Example: <SAN:otherName>MTIz" -msgstr "" +msgstr "範例:<SAN:otherName>MTIz" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:281 msgid "<SAN:rfc822Name>regular-expression" -msgstr "" +msgstr "<SAN:rfc822Name>regular-expression" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:284 msgid "Match the value of the rfc822Name SAN." -msgstr "" +msgstr "匹配 rfc822Name SAN 的值。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:287 msgid "Example: <SAN:rfc822Name>.*@email\\.domain" -msgstr "" +msgstr "範例:<SAN:rfc822Name>.*@email\\.domain" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:292 msgid "<SAN:dNSName>regular-expression" -msgstr "" +msgstr "<SAN:dNSName>regular-expression" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:295 msgid "Match the value of the dNSName SAN." -msgstr "" +msgstr "匹配 dNSName SAN 的值。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:298 msgid "Example: <SAN:dNSName>.*\\.my\\.dns\\.domain" -msgstr "" +msgstr "範例:<SAN:dNSName>.*\\.my\\.dns\\.domain" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:303 msgid "<SAN:x400Address>base64-string" -msgstr "" +msgstr "<SAN:x400Address>base64-string" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:306 msgid "Binary match the value of the x400Address SAN." -msgstr "" +msgstr "對 x400Address SAN 的值執行二進位匹配。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:309 msgid "Example: <SAN:x400Address>MTIz" -msgstr "" +msgstr "範例:<SAN:x400Address>MTIz" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:314 msgid "<SAN:directoryName>regular-expression" -msgstr "" +msgstr "<SAN:directoryName>regular-expression" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:317 @@ -9057,81 +10343,83 @@ msgid "" "Match the value of the directoryName SAN. The same comments as given for " "<ISSUER> and <SUBJECT> apply here as well." msgstr "" +"匹配 directoryName SAN 的值。針對 <ISSUER> 與 <SUBJECT> 提供的註" +"解也適用於此。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:322 msgid "Example: <SAN:directoryName>.*,DC=com" -msgstr "" +msgstr "範例:<SAN:directoryName>.*,DC=com" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:327 msgid "<SAN:ediPartyName>base64-string" -msgstr "" +msgstr "<SAN:ediPartyName>base64-string" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:330 msgid "Binary match the value of the ediPartyName SAN." -msgstr "" +msgstr "對 ediPartyName SAN 的值執行二進位匹配。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:333 msgid "Example: <SAN:ediPartyName>MTIz" -msgstr "" +msgstr "範例:<SAN:ediPartyName>MTIz" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:338 msgid "<SAN:uniformResourceIdentifier>regular-expression" -msgstr "" +msgstr "<SAN:uniformResourceIdentifier>regular-expression" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:341 msgid "Match the value of the uniformResourceIdentifier SAN." -msgstr "" +msgstr "匹配 uniformResourceIdentifier SAN 的值。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:344 msgid "Example: <SAN:uniformResourceIdentifier>URN:.*" -msgstr "" +msgstr "範例:<SAN:uniformResourceIdentifier>URN:.*" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:349 msgid "<SAN:iPAddress>regular-expression" -msgstr "" +msgstr "<SAN:iPAddress>regular-expression" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:352 msgid "Match the value of the iPAddress SAN." -msgstr "" +msgstr "匹配 iPAddress SAN 的值。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:355 msgid "Example: <SAN:iPAddress>192\\.168\\..*" -msgstr "" +msgstr "範例:<SAN:iPAddress>192\\.168\\..*" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:360 msgid "<SAN:registeredID>regular-expression" -msgstr "" +msgstr "<SAN:registeredID>regular-expression" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:363 msgid "Match the value of the registeredID SAN as dotted-decimal string." -msgstr "" +msgstr "以點十進位字串匹配 registeredID SAN 的值。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:367 msgid "Example: <SAN:registeredID>1\\.2\\.3\\..*" -msgstr "" +msgstr "範例:<SAN:registeredID>1\\.2\\.3\\..*" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sss-certmap.5.xml:96 msgid "The available options are: <placeholder type=\"variablelist\" id=\"0\"/>" -msgstr "" +msgstr "可用的選項有:<placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><title> #: sss-certmap.5.xml:375 msgid "MAPPING RULE" -msgstr "" +msgstr "對應規則" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sss-certmap.5.xml:377 @@ -9140,6 +10428,8 @@ msgid "" "accounts. A Smartcard with the certificate and the matching private key can " "then be used to authenticate as one of those accounts." msgstr "" +"對應規則用於將憑證與一個或多個帳戶關聯。之後可以使用包含憑證與相符私密金鑰的 " +"Smartcard,以其中一個帳戶身分驗證。" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sss-certmap.5.xml:382 @@ -9152,6 +10442,10 @@ msgid "" "caller will embed it in another filter to do the actual search. Because of " "this the filter string should start and stop with '(' and ')' respectively." msgstr "" +"目前 SSSD 基本上只支援使用 LDAP 查詢使用者資訊(例外是 proxy 提供者,但與此無" +"關)。因此,對應規則以 LDAP 搜尋篩選器語法為基礎,使用範本將憑證內容加入篩選" +"器。預期篩選器只會包含對應所需的特定資料,呼叫端會將它嵌入另一個篩選器來執行" +"實際搜尋。因此,篩選器字串應分別以 '(' 開始、以 ')' 結束。" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sss-certmap.5.xml:392 @@ -9161,6 +10455,8 @@ msgid "" "'altSecurityIdentities' attribute in AD or the 'ipaCertMapData' attribute " "for IPA can be used." msgstr "" +"一般建議使用憑證中的屬性,並將它們加入 LDAP 使用者物件的特殊屬性。例如可以使" +"用 AD 中的 'altSecurityIdentities' 屬性,或 IPA 的 'ipaCertMapData' 屬性。" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sss-certmap.5.xml:398 @@ -9171,6 +10467,9 @@ msgid "" "would break the mapping. On the other hand it would be hard to break the " "mapping on purpose for a specific user." msgstr "" +"這應該優先於從憑證讀取使用者特定資料(例如電子郵件地址)並在 LDAP 伺服器中搜" +"尋它。原因是 LDAP 中的使用者特定資料可能因為各種原因而變更,這會破壞對應。另" +"一方面,很難刻意為特定使用者破壞對應。" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sss-certmap.5.xml:406 @@ -9184,11 +10483,16 @@ msgid "" "the old version of this library will fail with a parsing error. The new " "templates are described in section <xref linkend=\"map_ldapu1\"/>." msgstr "" +"預設的 <quote>mapping rule</quote> 類型是 'LDAP',可以作為前綴加入規則,例如 " +"'LDAP:(userCertificate;binary={cert!bin})'。有一個名為 'LDAPU1' 的延伸提供更" +"多範本,以增加彈性。為了讓此程式庫的舊版本可以忽略此延伸,在 <quote>mapping " +"rule</quote> 中使用新範本時必須使用 'LDAPU1' 前綴,否則此程式庫的舊版本會以剖" +"析錯誤失敗。新範本說明於 <xref linkend=\"map_ldapu1\"/> 一節。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:424 msgid "{issuer_dn[!((ad|ad_x500)|ad_ldap|nss_x500|(nss|nss_ldap))]}" -msgstr "" +msgstr "{issuer_dn[!((ad|ad_x500)|ad_ldap|nss_x500|(nss|nss_ldap))]}" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:427 @@ -9197,27 +10501,29 @@ msgid "" "RFC 4514. If X.500 ordering (most specific RDN comes last) an option with " "the '_x500' prefix should be used." msgstr "" +"此範本會加入依照 RFC 4514 轉換為字串的完整簽發者 DN。若使用 X.500 排序(最具" +"體的 RDN 在最後),應使用帶有 '_x500' 前綴的選項。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:433 sss-certmap.5.xml:459 msgid "" "The conversion options starting with 'ad_' will use attribute names as used " "by AD, e.g. 'S' instead of 'ST'." -msgstr "" +msgstr "以 'ad_' 開頭的轉換選項會使用 AD 使用的屬性名稱,例如用 'S' 取代 'ST'。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:437 sss-certmap.5.xml:463 msgid "" "The conversion options starting with 'nss_' will use attribute names as used " "by NSS." -msgstr "" +msgstr "以 'nss_' 開頭的轉換選項會使用 NSS 使用的屬性名稱。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:441 sss-certmap.5.xml:467 msgid "" "The default conversion option is 'nss', i.e. attribute names according to " "NSS and LDAP/RFC 4514 ordering." -msgstr "" +msgstr "預設的轉換選項是 'nss',也就是依照 NSS 的屬性名稱與 LDAP/RFC 4514 排序。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:445 @@ -9225,11 +10531,12 @@ msgid "" "Example: " "(ipacertmapdata=X509:<I>{issuer_dn!ad}<S>{subject_dn!ad})" msgstr "" +"範例:(ipacertmapdata=X509:<I>{issuer_dn!ad}<S>{subject_dn!ad})" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:450 msgid "{subject_dn[!((ad|ad_x500)|ad_ldap|nss_x500|(nss|nss_ldap))]}" -msgstr "" +msgstr "{subject_dn[!((ad|ad_x500)|ad_ldap|nss_x500|(nss|nss_ldap))]}" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:453 @@ -9238,6 +10545,8 @@ msgid "" "RFC 4514. If X.500 ordering (most specific RDN comes last) an option with " "the '_x500' prefix should be used." msgstr "" +"此範本會加入依照 RFC 4514 轉換為字串的完整主旨 DN。若使用 X.500 排序(最具體" +"的 RDN 在最後),應使用帶有 '_x500' 前綴的選項。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:471 @@ -9245,11 +10554,13 @@ msgid "" "Example: " "(ipacertmapdata=X509:<I>{issuer_dn!nss_x500}<S>{subject_dn!nss_x500})" msgstr "" +"範例:(ipacertmapdata=X509:<I>{issuer_dn!nss_x500}<S>" +"{subject_dn!nss_x500})" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:476 msgid "{cert[!(bin|base64)]}" -msgstr "" +msgstr "{cert[!(bin|base64)]}" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:479 @@ -9260,16 +10571,19 @@ msgid "" "hex sequence is the default and can e.g. be used with the LDAP attribute " "'userCertificate;binary'." msgstr "" +"此範本會將整個 DER 編碼憑證以字串形式加入搜尋篩選器。視轉換選項而定,二進位憑" +"證會轉換為逸出十六進位序列 '\\xx' 或 base64。逸出十六進位序列是預設值,例如可" +"以與 LDAP 屬性 'userCertificate;binary' 一起使用。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:487 msgid "Example: (userCertificate;binary={cert!bin})" -msgstr "" +msgstr "範例:(userCertificate;binary={cert!bin})" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:492 msgid "{subject_principal[.short_name]}" -msgstr "" +msgstr "{subject_principal[.short_name]}" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:495 @@ -9278,6 +10592,8 @@ msgid "" "SAN used by pkinit or the one used by AD. The 'short_name' component " "represents the first part of the principal before the '@' sign." msgstr "" +"此範本會加入從 pkinit 使用的 SAN 或 AD 使用的 SAN 取得的 Kerberos principal" +"。'short_name' 組成部分代表 principal 在 '@' 符號之前的第一部分。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:501 @@ -9285,11 +10601,13 @@ msgid "" "Example: " "(|(userPrincipal={subject_principal})(samAccountName={subject_principal.short_name}))" msgstr "" +"範例:(|(userPrincipal={subject_principal})(samAccountName=" +"{subject_principal.short_name}))" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:506 msgid "{subject_pkinit_principal[.short_name]}" -msgstr "" +msgstr "{subject_pkinit_principal[.short_name]}" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:509 @@ -9298,6 +10616,8 @@ msgid "" "by pkinit. The 'short_name' component represents the first part of the " "principal before the '@' sign." msgstr "" +"此範本會加入由 pkinit 使用的 SAN 提供的 Kerberos principal。'short_name' 組成" +"部分代表 principal 在 '@' 符號之前的第一部分。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:515 @@ -9305,11 +10625,13 @@ msgid "" "Example: " "(|(userPrincipal={subject_pkinit_principal})(uid={subject_pkinit_principal.short_name}))" msgstr "" +"範例:(|(userPrincipal={subject_pkinit_principal})(uid=" +"{subject_pkinit_principal.short_name}))" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:520 msgid "{subject_nt_principal[.short_name]}" -msgstr "" +msgstr "{subject_nt_principal[.short_name]}" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:523 @@ -9318,6 +10640,8 @@ msgid "" "by AD. The 'short_name' component represent the first part of the principal " "before the '@' sign." msgstr "" +"此範本會加入由 AD 使用的 SAN 提供的 Kerberos principal。'short_name' 組成部分" +"代表 principal 在 '@' 符號之前的第一部分。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:529 @@ -9325,11 +10649,13 @@ msgid "" "Example: " "(|(userPrincipalName={subject_nt_principal})(samAccountName={subject_nt_principal.short_name}))" msgstr "" +"範例:(|(userPrincipalName={subject_nt_principal})(samAccountName=" +"{subject_nt_principal.short_name}))" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:534 msgid "{subject_rfc822_name[.short_name]}" -msgstr "" +msgstr "{subject_rfc822_name[.short_name]}" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:537 @@ -9338,6 +10664,8 @@ msgid "" "component of the SAN, typically an email address. The 'short_name' component " "represents the first part of the address before the '@' sign." msgstr "" +"此範本會加入儲存在 SAN 之 rfc822Name 組成部分中的字串,通常是電子郵件地址" +"。'short_name' 組成部分代表地址在 '@' 符號之前的第一部分。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:543 @@ -9345,11 +10673,12 @@ msgid "" "Example: " "(|(mail={subject_rfc822_name})(uid={subject_rfc822_name.short_name}))" msgstr "" +"範例:(|(mail={subject_rfc822_name})(uid={subject_rfc822_name.short_name}))" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:548 msgid "{subject_dns_name[.short_name]}" -msgstr "" +msgstr "{subject_dns_name[.short_name]}" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:551 @@ -9358,113 +10687,116 @@ msgid "" "of the SAN, typically a fully-qualified host name. The 'short_name' " "component represents the first part of the name before the first '.' sign." msgstr "" +"此範本會加入儲存在 SAN 之 dNSName 組成部分中的字串,通常是完整主機名稱" +"。'short_name' 組成部分代表名稱在第一個 '.' 符號之前的第一部分。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:557 msgid "Example: (|(fqdn={subject_dns_name})(host={subject_dns_name.short_name}))" -msgstr "" +msgstr "範例:(|(fqdn={subject_dns_name})(host={subject_dns_name.short_name}))" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:562 msgid "{subject_uri}" -msgstr "" +msgstr "{subject_uri}" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:565 msgid "" "This template will add the string which is stored in the " "uniformResourceIdentifier component of the SAN." -msgstr "" +msgstr "此範本會加入儲存在 SAN 之 uniformResourceIdentifier 組成部分中的字串。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:569 msgid "Example: (uri={subject_uri})" -msgstr "" +msgstr "範例:(uri={subject_uri})" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:574 msgid "{subject_ip_address}" -msgstr "" +msgstr "{subject_ip_address}" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:577 msgid "" "This template will add the string which is stored in the iPAddress component " "of the SAN." -msgstr "" +msgstr "此範本會加入儲存在 SAN 之 iPAddress 組成部分中的字串。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:581 msgid "Example: (ip={subject_ip_address})" -msgstr "" +msgstr "範例:(ip={subject_ip_address})" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:586 msgid "{subject_x400_address}" -msgstr "" +msgstr "{subject_x400_address}" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:589 msgid "" "This template will add the value which is stored in the x400Address " "component of the SAN as escaped hex sequence." -msgstr "" +msgstr "此範本會將儲存在 SAN 之 x400Address 組成部分中的值以逸出十六進位序列加入。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:594 msgid "Example: (attr:binary={subject_x400_address})" -msgstr "" +msgstr "範例:(attr:binary={subject_x400_address})" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:599 msgid "{subject_directory_name[!((ad|ad_x500)|ad_ldap|nss_x500|(nss|nss_ldap))]}" msgstr "" +"{subject_directory_name[!((ad|ad_x500)|ad_ldap|nss_x500|(nss|nss_ldap))]}" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:602 msgid "" "This template will add the DN string of the value which is stored in the " "directoryName component of the SAN." -msgstr "" +msgstr "此範本會加入儲存在 SAN 之 directoryName 組成部分中值的 DN 字串。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:606 msgid "Example: (orig_dn={subject_directory_name})" -msgstr "" +msgstr "範例:(orig_dn={subject_directory_name})" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:611 msgid "{subject_ediparty_name}" -msgstr "" +msgstr "{subject_ediparty_name}" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:614 msgid "" "This template will add the value which is stored in the ediPartyName " "component of the SAN as escaped hex sequence." -msgstr "" +msgstr "此範本會將儲存在 SAN 之 ediPartyName 組成部分中的值以逸出十六進位序列加入。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:619 msgid "Example: (attr:binary={subject_ediparty_name})" -msgstr "" +msgstr "範例:(attr:binary={subject_ediparty_name})" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:624 msgid "{subject_registered_id}" -msgstr "" +msgstr "{subject_registered_id}" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:627 msgid "" "This template will add the OID which is stored in the registeredID component " "of the SAN as a dotted-decimal string." -msgstr "" +msgstr "此範本會將儲存在 SAN 之 registeredID 組成部分中的 OID 以點十進位字串加入。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:632 msgid "Example: (oid={subject_registered_id})" -msgstr "" +msgstr "範例:(oid={subject_registered_id})" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sss-certmap.5.xml:417 @@ -9475,28 +10807,31 @@ msgid "" "conversion/formatting option separated by a '!'. Allowed values are: " "<placeholder type=\"variablelist\" id=\"0\"/>" msgstr "" +"用來將憑證資料加入搜尋篩選器的範本以 Python 樣式格式化字串為基礎。它們由大括" +"號中的關鍵字組成,並帶有以 '.' 分隔的選用子組成部分指定符,或以 '!' 分隔的選" +"用轉換/格式化選項。允許的值有:<placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><title> #: sss-certmap.5.xml:639 msgid "LDAPU1 extension" -msgstr "" +msgstr "LDAPU1 延伸" #. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para> #: sss-certmap.5.xml:641 msgid "The following template are available when using the 'LDAPU1' extension:" -msgstr "" +msgstr "使用 'LDAPU1' 延伸時,可以使用下列範本:" #. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:647 msgid "{serial_number[!(dec|hex[_ucr])]}" -msgstr "" +msgstr "{serial_number[!(dec|hex[_ucr])]}" #. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:650 msgid "" "This template will add the serial number of the certificate. By default it " "will be printed as a hexadecimal number with lower-case letters." -msgstr "" +msgstr "此範本會加入憑證的序號。預設會以小寫字母的十六進位數字列印。" #. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:655 @@ -9508,23 +10843,27 @@ msgid "" "be combined so that e.g. '!hex_uc' will produce a colon-separated " "hexadecimal string with upper-case letters." msgstr "" +"使用 '!dec' 格式化選項時,數字會以十進位字串列印。十六進位輸出可以以大寫字母 " +"('!hex_u')、以冒號分隔十六進位位元組 ('!hex_c') 或十六進位位元組反序 " +"('!hex_r') 列印。後綴字母可以組合,例如 '!hex_uc' 會產生以大寫字母呈現、冒號" +"分隔的十六進位字串。" #. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:665 msgid "Example: LDAPU1:(serial={serial_number})" -msgstr "" +msgstr "範例:LDAPU1:(serial={serial_number})" #. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:671 msgid "{subject_key_id[!hex[_ucr]]}" -msgstr "" +msgstr "{subject_key_id[!hex[_ucr]]}" #. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:674 msgid "" "This template will add the subject key id of the certificate. By default it " "will be printed as a hexadecimal number with lower-case letters." -msgstr "" +msgstr "此範本會加入憑證的主旨金鑰 ID。預設會以小寫字母的十六進位數字印出。" #. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:679 @@ -9535,16 +10874,19 @@ msgid "" "combined so that e.g. '!hex_uc' will produce a colon-separated hexadecimal " "string with upper-case letters." msgstr "" +"十六進位輸出可以以大寫字母 ('!hex_u')、以冒號分隔十六進位位元組 ('!hex_c') 或" +"十六進位位元組反序 ('!hex_r') 列印。後綴字母可以組合,例如 '!hex_uc' 會產生以" +"大寫字母呈現、冒號分隔的十六進位字串。" #. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:688 msgid "Example: LDAPU1:(ski={subject_key_id})" -msgstr "" +msgstr "範例:LDAPU1:(ski={subject_key_id})" #. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:694 msgid "{cert[!DIGEST[_ucr]]}" -msgstr "" +msgstr "{cert[!DIGEST[_ucr]]}" #. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:697 @@ -9553,6 +10895,8 @@ msgid "" "DIGEST must be replaced with the name of a digest/hash function supported by " "OpenSSL, e.g. 'sha512'." msgstr "" +"此範本會加入憑證的十六進位摘要/雜湊,其中 DIGEST 必須替換為 OpenSSL 支援之摘" +"要/雜湊函式的名稱,例如 'sha512'。" #. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:703 @@ -9563,23 +10907,26 @@ msgid "" "combined so that e.g. '!sha512_uc' will produce a colon-separated " "hexadecimal string with upper-case letters." msgstr "" +"十六進位輸出可以以大寫字母 ('!sha512_u')、以冒號分隔十六進位位元組 " +"('!sha512_c') 或十六進位位元組反序 ('!sha512_r') 列印。後綴字母可以組合,例" +"如 '!sha512_uc' 會產生以大寫字母呈現、冒號分隔的十六進位字串。" #. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:712 msgid "Example: LDAPU1:(dgst={cert!sha256})" -msgstr "" +msgstr "範例:LDAPU1:(dgst={cert!sha256})" #. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:718 msgid "{subject_dn_component[(.attr_name|[number]]}" -msgstr "" +msgstr "{subject_dn_component[(.attr_name|[number]]}" #. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:721 msgid "" "This template will add an attribute value of a component of the subject DN, " "by default the value of the most specific component." -msgstr "" +msgstr "此範本會加入主旨 DN 某個組成部分的屬性值,預設為最具體組成部分的值。" #. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:726 @@ -9592,30 +10939,34 @@ msgid "" "e.g. {subject_dn_component.uid[2]} which means that the name of the second " "component must be 'uid'." msgstr "" +"可以依屬性名稱選取不同的組成部分,例如 {subject_dn_component.uid},或依位置選" +"取,例如 {subject_dn_component.[2]},其中正數從最具體的組成部分開始計算,負數" +"從最不具體的組成部分開始計算。屬性名稱與位置可以組合,例如 " +"{subject_dn_component.uid[2]},表示第二個組成部分的名稱必須是 'uid'。" #. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:737 msgid "Example: LDAPU1:(uid={subject_dn_component.uid})" -msgstr "" +msgstr "範例:LDAPU1:(uid={subject_dn_component.uid})" #. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:743 msgid "{issuer_dn_component[(.attr_name|[number]]}" -msgstr "" +msgstr "{issuer_dn_component[(.attr_name|[number]]}" #. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:746 msgid "" "This template will add an attribute value of a component of the issuer DN, " "by default the value of the most specific component." -msgstr "" +msgstr "此範本會加入簽發者 DN 某個組成部分的屬性值,預設為最具體組成部分的值。" #. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:751 msgid "" "See 'subject_dn_component' for details about the attribute name and position " "specifiers." -msgstr "" +msgstr "屬性名稱與位置指定符的詳細資料請參閱 'subject_dn_component'。" #. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:755 @@ -9623,11 +10974,12 @@ msgid "" "Example: " "LDAPU1:(domain={issuer_dn_component.[-2]}.{issuer_dn_component.dc[-1]})" msgstr "" +"範例:LDAPU1:(domain={issuer_dn_component.[-2]}.{issuer_dn_component.dc[-1]})" #. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:760 msgid "{sid[.rid]}" -msgstr "" +msgstr "{sid[.rid]}" #. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:763 @@ -9636,16 +10988,18 @@ msgid "" "Microsoft with the OID 1.3.6.1.4.1.311.25.2 is available. With the '.rid' " "selector only the last component, i.e. the RID, will be added." msgstr "" +"若 Microsoft 以 OID 1.3.6.1.4.1.311.25.2 引入的對應延伸可用,此範本會加入 SID" +"。使用 '.rid' 選取器時,只會加入最後一個組成部分,也就是 RID。" #. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:770 msgid "Example: LDAPU1:(objectsid={sid})" -msgstr "" +msgstr "範例:LDAPU1:(objectsid={sid})" #. type: Content of: <reference><refentry><refsect1><refsect2><title> #: sss-certmap.5.xml:779 msgid "DOMAIN LIST" -msgstr "" +msgstr "網域清單" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sss-certmap.5.xml:781 @@ -9654,16 +11008,18 @@ msgid "" "only searched in the local domain but in the listed domains as well as long " "as they are know by SSSD. Domains not know to SSSD will be ignored." msgstr "" +"若網域清單不是空的,對應到給定憑證的使用者不只會在網域本機中搜尋,只要 SSSD " +"知道列出的網域,也會在這些網域中搜尋。SSSD 不知道的網域會被忽略。" #. type: Content of: <reference><refentry><refnamediv><refname> #: sssd-ipa.5.xml:10 sssd-ipa.5.xml:16 msgid "sssd-ipa" -msgstr "" +msgstr "sssd-ipa" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sssd-ipa.5.xml:17 msgid "SSSD IPA provider" -msgstr "" +msgstr "SSSD IPA 提供者" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ipa.5.xml:23 @@ -9675,6 +11031,10 @@ msgid "" "<refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</manvolnum> " "</citerefentry> manual page." msgstr "" +"本手冊頁說明 <citerefentry> <refentrytitle>sssd</refentrytitle> <manvolnum>" +"8</manvolnum> </citerefentry> 之 IPA 提供者的設定。詳細的語法參考請參閱 " +"<citerefentry> <refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry> 手冊頁的 <quote>FILE FORMAT</quote> 一節。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ipa.5.xml:36 @@ -9684,6 +11044,9 @@ msgid "" "requires that the machine be joined to the IPA domain; configuration is " "almost entirely self-discovered and obtained directly from the server." msgstr "" +"IPA 提供者是用來連線到 IPA 伺服器的後端。(IPA 伺服器的相關資訊請參閱 " +"freeipa.org 網站。)此提供者要求機器加入 IPA 網域;設定幾乎完全自動探索,並直" +"接從伺服器取得。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ipa.5.xml:43 @@ -9697,6 +11060,12 @@ msgid "" "sssd-ldap and sssd-krb5 providers with some exceptions. However, it is " "neither necessary nor recommended to set these options." msgstr "" +"IPA 提供者讓 SSSD 可以使用 <citerefentry> <refentrytitle>sssd-ldap</" +"refentrytitle> <manvolnum>5</manvolnum> </citerefentry> 身分提供者與 " +"<citerefentry> <refentrytitle>sssd-krb5</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry> 驗證提供者,並針對 IPA 環境最佳化。IPA 提供者接受 " +"sssd-ldap 與 sssd-krb5 提供者使用的相同選項,但有一些例外。不過,設定這些選項" +"既非必要也不建議。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ipa.5.xml:57 @@ -9705,6 +11074,8 @@ msgid "" "default options with some exceptions, the differences are listed in the " "<quote>MODIFIED DEFAULT OPTIONS</quote> section." msgstr "" +"IPA 提供者主要複製傳統 ldap 與 krb5 提供者的預設選項,但有一些例外,差異列於 " +"<quote>MODIFIED DEFAULT OPTIONS</quote> 一節。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ipa.5.xml:62 @@ -9713,6 +11084,9 @@ msgid "" "<quote>ipa_access_order</quote>) as it mainly uses HBAC (host-based access " "control) rules. Please refer to freeipa.org for more information about HBAC." msgstr "" +"作為 access 提供者,IPA 提供者的設定最少(請參閱 <quote>ipa_access_order</" +"quote>),因為它主要使用 HBAC(主機型存取控制)規則。HBAC 的更多資訊請參閱 " +"freeipa.org。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ipa.5.xml:68 @@ -9721,6 +11095,8 @@ msgid "" "configured in sssd.conf then the id_provider must also be set to " "<quote>ipa</quote>." msgstr "" +"若在 sssd.conf 中設定 <quote>auth_provider=ipa</quote> 或 <quote>" +"access_provider=ipa</quote>,則 id_provider 也必須設為 <quote>ipa</quote>。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ipa.5.xml:74 @@ -9729,23 +11105,25 @@ msgid "" "from trusted realms contain a PAC. To make configuration easier the PAC " "responder is started automatically if the IPA ID provider is configured." msgstr "" +"若來自受信任 realm 之使用者的 Kerberos 票證包含 PAC,IPA 提供者會使用 PAC " +"responder。為簡化設定,若設定了 IPA ID 提供者,PAC responder 會自動啟動。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:90 msgid "ipa_domain (string)" -msgstr "" +msgstr "ipa_domain (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:93 msgid "" "Specifies the name of the IPA domain. This is optional. If not provided, " "the configuration domain name is used." -msgstr "" +msgstr "指定 IPA 網域名稱。這是選用的。若未提供,則使用設定網域名稱。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:101 msgid "ipa_server, ipa_backup_server (string)" -msgstr "" +msgstr "ipa_server, ipa_backup_server (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:104 @@ -9756,11 +11134,15 @@ msgid "" "This is optional if autodiscovery is enabled. For more information on " "service discovery, refer to the <quote>SERVICE DISCOVERY</quote> section." msgstr "" +"SSSD 應依偏好順序連線之 IPA 伺服器的 IP 位址或主機名稱逗號分隔清單。有關故障" +"轉移與伺服器備援的更多資訊,請參閱 <quote>FAILOVER</quote> 一節。若啟用自動探" +"索,此選項是選用的。服務探索的更多資訊請參閱 <quote>SERVICE DISCOVERY</" +"quote> 一節。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:117 msgid "ipa_hostname (string)" -msgstr "" +msgstr "ipa_hostname (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:120 @@ -9769,11 +11151,13 @@ msgid "" "fully qualified name used in the IPA domain to identify this host. The " "hostname must be fully qualified." msgstr "" +"選用。可以設定在主機名稱 (hostname(5)) 未反映 IPA 網域中用來識別此主機之完整" +"名稱的機器上。主機名稱必須是完整的。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:129 sssd-ad.5.xml:1182 msgid "dyndns_update (boolean)" -msgstr "" +msgstr "dyndns_update (boolean)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:132 @@ -9784,6 +11168,9 @@ msgid "" "updates, if it is not otherwise specified by using the " "<quote>dyndns_iface</quote> option." msgstr "" +"選用。此選項告訴 SSSD 自動以本用戶端的 IP 位址更新 FreeIPA 內建的 DNS 伺服器" +"。更新使用 GSS-TSIG 保護。若未使用 <quote>dyndns_iface</quote> 選項另行指定," +"則使用 IPA LDAP 連線的 IP 位址進行更新。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:141 sssd-ad.5.xml:1196 @@ -9791,6 +11178,8 @@ msgid "" "NOTE: On older systems (such as RHEL 5), for this behavior to work reliably, " "the default Kerberos realm must be set properly in /etc/krb5.conf" msgstr "" +"注意:在較舊的系統(例如 RHEL 5)上,此行為要可靠運作,必須在 /etc/krb5.conf " +"中正確設定預設的 Kerberos realm" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:146 @@ -9799,11 +11188,13 @@ msgid "" "<emphasis>ipa_dyndns_update</emphasis> option, users should migrate to using " "<emphasis>dyndns_update</emphasis> in their config file." msgstr "" +"注意:雖然仍然可以使用舊的 <emphasis>ipa_dyndns_update</emphasis> 選項,但使" +"用者應在設定檔中遷移為使用 <emphasis>dyndns_update</emphasis>。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:158 sssd-ad.5.xml:1207 msgid "dyndns_ttl (integer)" -msgstr "" +msgstr "dyndns_ttl (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:161 sssd-ad.5.xml:1210 @@ -9812,6 +11203,8 @@ msgid "" "dyndns_update is false this has no effect. This will override the TTL " "serverside if set by an administrator." msgstr "" +"更新用戶端 DNS 記錄時套用的 TTL。若 dyndns_update 為 false,這沒有作用。若管" +"理員設定了伺服器端 TTL,此值會覆寫它。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:166 @@ -9820,16 +11213,18 @@ msgid "" "<emphasis>ipa_dyndns_ttl</emphasis> option, users should migrate to using " "<emphasis>dyndns_ttl</emphasis> in their config file." msgstr "" +"注意:雖然仍然可以使用舊的 <emphasis>ipa_dyndns_ttl</emphasis> 選項,但使用者" +"應在設定檔中遷移為使用 <emphasis>dyndns_ttl</emphasis>。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:172 msgid "Default: 1200 (seconds)" -msgstr "" +msgstr "預設:1200(秒)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:178 sssd-ad.5.xml:1221 msgid "dyndns_iface (string)" -msgstr "" +msgstr "dyndns_iface (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:181 sssd-ad.5.xml:1224 @@ -9839,6 +11234,8 @@ msgid "" "updates. Special value <quote>*</quote> implies that IPs from all interfaces " "should be used." msgstr "" +"選用。只在 dyndns_update 為 true 時適用。選擇其 IP 位址應用於動態 DNS 更新的" +"介面或介面清單。特殊值 <quote>*</quote> 表示應使用所有介面的 IP。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:188 @@ -9847,23 +11244,25 @@ msgid "" "<emphasis>ipa_dyndns_iface</emphasis> option, users should migrate to using " "<emphasis>dyndns_iface</emphasis> in their config file." msgstr "" +"注意:雖然仍然可以使用舊的 <emphasis>ipa_dyndns_iface</emphasis> 選項,但使用" +"者應在設定檔中遷移為使用 <emphasis>dyndns_iface</emphasis>。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:194 msgid "" "Default: Use the IP addresses of the interface which is used for IPA LDAP " "connection" -msgstr "" +msgstr "預設:使用用於 IPA LDAP 連線之介面的 IP 位址" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:198 sssd-ad.5.xml:1235 msgid "Example: dyndns_iface = em1, vnet1, vnet2" -msgstr "" +msgstr "範例:dyndns_iface = em1, vnet1, vnet2" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:204 sssd-ad.5.xml:1291 msgid "dyndns_auth (string)" -msgstr "" +msgstr "dyndns_auth (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:207 sssd-ad.5.xml:1294 @@ -9872,16 +11271,18 @@ msgid "" "updates with the DNS server, insecure updates can be sent by setting this " "option to 'none'." msgstr "" +"nsupdate 工具是否應使用 GSS-TSIG 驗證與 DNS 伺服器進行安全更新,可以將此選項" +"設為 'none' 來傳送不安全的更新。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:213 sssd-ad.5.xml:1300 msgid "Default: GSS-TSIG" -msgstr "" +msgstr "預設:GSS-TSIG" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:219 sssd-ad.5.xml:1306 msgid "dyndns_auth_ptr (string)" -msgstr "" +msgstr "dyndns_auth_ptr (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:222 sssd-ad.5.xml:1309 @@ -9890,21 +11291,23 @@ msgid "" "PTR updates with the DNS server, insecure updates can be sent by setting " "this option to 'none'." msgstr "" +"nsupdate 工具是否應使用 GSS-TSIG 驗證與 DNS 伺服器進行安全 PTR 更新,可以將此" +"選項設為 'none' 來傳送不安全的更新。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:228 sssd-ad.5.xml:1315 msgid "Default: Same as dyndns_auth" -msgstr "" +msgstr "預設:與 dyndns_auth 相同" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:234 msgid "ipa_enable_dns_sites (boolean)" -msgstr "" +msgstr "ipa_enable_dns_sites (boolean)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:237 sssd-ad.5.xml:238 msgid "Enables DNS sites - location based service discovery." -msgstr "" +msgstr "啟用 DNS sites - 以位置為基礎的服務探索。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:241 @@ -9918,11 +11321,16 @@ msgid "" "servers located using the traditional SRV discovery are used as back up " "servers" msgstr "" +"若為 true 且啟用服務探索(請參閱手冊頁底部的 Service Discovery 段落),SSSD " +"會先嘗試使用包含 \"_location.hostname.example.com\" 的查詢進行以位置為基礎的" +"探索,然後退回傳統的 SRV 探索。若以位置為基礎的探索成功,以位置為基礎的探索找" +"到的 IPA 伺服器會被視為主要伺服器,使用傳統 SRV 探索找到的 IPA 伺服器會被用作" +"備份伺服器" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:260 sssd-ad.5.xml:1241 msgid "dyndns_refresh_interval (integer)" -msgstr "" +msgstr "dyndns_refresh_interval (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:263 @@ -9931,11 +11339,13 @@ msgid "" "automatic update performed when the back end goes online. This option is " "optional and applicable only when dyndns_update is true." msgstr "" +"除了後端上線時執行的自動更新之外,後端應多久執行一次週期性 DNS 更新。此選項是" +"選用的,只在 dyndns_update 為 true 時適用。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:276 sssd-ad.5.xml:1259 msgid "dyndns_update_ptr (bool)" -msgstr "" +msgstr "dyndns_update_ptr (bool)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:279 sssd-ad.5.xml:1262 @@ -9943,6 +11353,8 @@ msgid "" "Whether the PTR record should also be explicitly updated when updating the " "client's DNS records. Applicable only when dyndns_update is true." msgstr "" +"更新用戶端的 DNS 記錄時,是否也應明確更新 PTR 記錄。只在 dyndns_update 為 " +"true 時適用。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:284 @@ -9950,6 +11362,8 @@ msgid "" "This option should be False in most IPA deployments as the IPA server " "generates the PTR records automatically when forward records are changed." msgstr "" +"在大多數 IPA 部署中,此選項應為 False,因為 IPA 伺服器會在正向記錄變更時自動" +"產生 PTR 記錄。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:290 sssd-ad.5.xml:1267 @@ -9957,64 +11371,66 @@ msgid "" "Note that <emphasis>dyndns_update_per_family</emphasis> parameter does not " "apply for PTR record updates. Those updates are always sent separately." msgstr "" +"請注意,<emphasis>dyndns_update_per_family</emphasis> 參數不適用於 PTR 記錄更" +"新。這些更新一律分別傳送。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:295 msgid "Default: False (disabled)" -msgstr "" +msgstr "預設:False(停用)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:301 sssd-ad.5.xml:1278 msgid "dyndns_force_tcp (bool)" -msgstr "" +msgstr "dyndns_force_tcp (bool)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:304 sssd-ad.5.xml:1281 msgid "" "Whether the nsupdate utility should default to using TCP for communicating " "with the DNS server." -msgstr "" +msgstr "nsupdate 工具是否應預設使用 TCP 與 DNS 伺服器通訊。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:308 sssd-ad.5.xml:1285 msgid "Default: False (let nsupdate choose the protocol)" -msgstr "" +msgstr "預設:False(讓 nsupdate 選擇協定)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:314 sssd-ad.5.xml:1321 msgid "dyndns_server (string)" -msgstr "" +msgstr "dyndns_server (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:317 sssd-ad.5.xml:1324 msgid "" "The DNS server to use when performing a DNS update. In most setups, it's " "recommended to leave this option unset." -msgstr "" +msgstr "執行 DNS 更新時使用的 DNS 伺服器。在大多數設定中,建議讓此選項保持未設定。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:322 sssd-ad.5.xml:1329 msgid "" "Setting this option makes sense for environments where the DNS server is " "different from the identity server." -msgstr "" +msgstr "在 DNS 伺服器與身分伺服器不同的環境中,設定此選項才有意義。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:327 sssd-ad.5.xml:1334 msgid "" "Please note that this option will be only used in fallback attempt when " "previous attempt using autodetected settings failed." -msgstr "" +msgstr "請注意,此選項只會在先前使用自動偵測設定的嘗試失敗時,用於退回嘗試。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:332 sssd-ad.5.xml:1339 msgid "Default: None (let nsupdate choose the server)" -msgstr "" +msgstr "預設:None(讓 nsupdate 選擇伺服器)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:338 sssd-ad.5.xml:1345 msgid "dyndns_update_per_family (boolean)" -msgstr "" +msgstr "dyndns_update_per_family (boolean)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:341 sssd-ad.5.xml:1348 @@ -10023,139 +11439,141 @@ msgid "" "update. In some cases it might be desirable to perform IPv4 and IPv6 update " "in single step." msgstr "" +"DNS 更新預設分兩個步驟執行 - 先 IPv4 更新,再 IPv6 更新。在某些情況下,可能希" +"望單一步驟執行 IPv4 與 IPv6 更新。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:353 msgid "ipa_access_order (string)" -msgstr "" +msgstr "ipa_access_order (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:360 msgid "<emphasis>expire</emphasis>: use IPA's account expiration policy." -msgstr "" +msgstr "<emphasis>expire</emphasis>:使用 IPA 的帳戶到期原則。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:399 msgid "" "Please note that 'access_provider = ipa' must be set for this feature to " "work." -msgstr "" +msgstr "請注意,此功能要運作必須設定 'access_provider = ipa'。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:406 msgid "ipa_deskprofile_search_base (string)" -msgstr "" +msgstr "ipa_deskprofile_search_base (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:409 msgid "" "Optional. Use the given string as search base for Desktop Profile related " "objects." -msgstr "" +msgstr "選用。使用指定的字串作為桌面設定檔相關物件的搜尋基礎。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:413 sssd-ipa.5.xml:440 msgid "Default: Use base DN" -msgstr "" +msgstr "預設:使用基礎 DN" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:419 msgid "ipa_subid_ranges_search_base (string)" -msgstr "" +msgstr "ipa_subid_ranges_search_base (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:422 msgid "" "Optional. Use the given string as search base for subordinate ranges related " "objects." -msgstr "" +msgstr "選用。使用指定的字串作為下屬範圍相關物件的搜尋基礎。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:426 msgid "Default: the value of <emphasis>cn=subids,%basedn</emphasis>" -msgstr "" +msgstr "預設:<emphasis>cn=subids,%basedn</emphasis> 的值" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:433 msgid "ipa_hbac_search_base (string)" -msgstr "" +msgstr "ipa_hbac_search_base (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:436 msgid "Optional. Use the given string as search base for HBAC related objects." -msgstr "" +msgstr "選用。使用指定的字串作為 HBAC 相關物件的搜尋基礎。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:446 msgid "ipa_host_search_base (string)" -msgstr "" +msgstr "ipa_host_search_base (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:449 msgid "Deprecated. Use ldap_host_search_base instead." -msgstr "" +msgstr "已棄用。請改用 ldap_host_search_base。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:455 msgid "ipa_selinux_search_base (string)" -msgstr "" +msgstr "ipa_selinux_search_base (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:458 msgid "Optional. Use the given string as search base for SELinux user maps." -msgstr "" +msgstr "選用。使用指定的字串作為 SELinux 使用者對應表的搜尋基礎。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:474 msgid "ipa_subdomains_search_base (string)" -msgstr "" +msgstr "ipa_subdomains_search_base (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:477 msgid "Optional. Use the given string as search base for trusted domains." -msgstr "" +msgstr "選用。使用指定的字串作為受信任網域的搜尋基礎。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:486 msgid "Default: the value of <emphasis>cn=trusts,%basedn</emphasis>" -msgstr "" +msgstr "預設:<emphasis>cn=trusts,%basedn</emphasis> 的值" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:493 msgid "ipa_master_domain_search_base (string)" -msgstr "" +msgstr "ipa_master_domain_search_base (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:496 msgid "Optional. Use the given string as search base for master domain object." -msgstr "" +msgstr "選用。使用指定的字串作為主網域物件的搜尋基礎。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:505 msgid "Default: the value of <emphasis>cn=ad,cn=etc,%basedn</emphasis>" -msgstr "" +msgstr "預設:<emphasis>cn=ad,cn=etc,%basedn</emphasis> 的值" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:512 msgid "ipa_views_search_base (string)" -msgstr "" +msgstr "ipa_views_search_base (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:515 msgid "Optional. Use the given string as search base for views containers." -msgstr "" +msgstr "選用。使用指定的字串作為檢視容器的搜尋基礎。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:524 msgid "Default: the value of <emphasis>cn=views,cn=accounts,%basedn</emphasis>" -msgstr "" +msgstr "預設:<emphasis>cn=views,cn=accounts,%basedn</emphasis> 的值" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:534 msgid "" "The name of the Kerberos realm. This is optional and defaults to the value " "of <quote>ipa_domain</quote>." -msgstr "" +msgstr "Kerberos realm 的名稱。這是選用的,預設為 <quote>ipa_domain</quote> 的值。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:538 @@ -10163,35 +11581,37 @@ msgid "" "The name of the Kerberos realm has a special meaning in IPA - it is " "converted into the base DN to use for performing LDAP operations." msgstr "" +"Kerberos realm 的名稱在 IPA 中有特殊意義 - 它會轉換為執行 LDAP 作業時使用的基" +"礎 DN。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:546 sssd-ad.5.xml:1363 msgid "krb5_confd_path (string)" -msgstr "" +msgstr "krb5_confd_path (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:549 sssd-ad.5.xml:1366 msgid "" "Absolute path of a directory where SSSD should place Kerberos configuration " "snippets." -msgstr "" +msgstr "SSSD 應放置 Kerberos 設定片段之目錄的絕對路徑。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:553 sssd-ad.5.xml:1370 msgid "" "To disable the creation of the configuration snippets set the parameter to " "'none'." -msgstr "" +msgstr "若要停用設定片段的建立,請將參數設為 'none'。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:557 sssd-ad.5.xml:1374 msgid "Default: not set (krb5.include.d subdirectory of SSSD's pubconf directory)" -msgstr "" +msgstr "預設:未設定(SSSD pubconf 目錄的 krb5.include.d 子目錄)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:564 msgid "ipa_deskprofile_refresh (integer)" -msgstr "" +msgstr "ipa_deskprofile_refresh (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:567 @@ -10200,33 +11620,35 @@ msgid "" "IPA server. This will reduce the latency and load on the IPA server if there " "are many desktop profiles requests made in a short period." msgstr "" +"對 IPA 伺服器查詢桌面設定檔規則之間的時間量。若在短期內發出許多桌面設定檔要求" +",這會降低 IPA 伺服器的延遲與負載。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:574 sssd-ipa.5.xml:604 sssd-ipa.5.xml:620 sssd-ad.5.xml:600 msgid "Default: 5 (seconds)" -msgstr "" +msgstr "預設:5(秒)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:580 msgid "ipa_deskprofile_request_interval (integer)" -msgstr "" +msgstr "ipa_deskprofile_request_interval (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:583 msgid "" "The amount of time between lookups of the Desktop Profile rules against the " "IPA server in case the last request did not return any rule." -msgstr "" +msgstr "若上次要求沒有傳回任何規則,對 IPA 伺服器查詢桌面設定檔規則之間的時間量。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:588 msgid "Default: 60 (minutes)" -msgstr "" +msgstr "預設:60(分鐘)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:594 msgid "ipa_hbac_refresh (integer)" -msgstr "" +msgstr "ipa_hbac_refresh (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:597 @@ -10235,11 +11657,13 @@ msgid "" "server. This will reduce the latency and load on the IPA server if there are " "many access-control requests made in a short period." msgstr "" +"對 IPA 伺服器查詢 HBAC 規則之間的時間量。若在短期內發出許多存取控制要求,這會" +"降低 IPA 伺服器的延遲與負載。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:610 msgid "ipa_hbac_selinux (integer)" -msgstr "" +msgstr "ipa_hbac_selinux (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:613 @@ -10248,11 +11672,13 @@ msgid "" "server. This will reduce the latency and load on the IPA server if there are " "many user login requests made in a short period." msgstr "" +"對 IPA 伺服器查詢 SELinux 對應表之間的時間量。若在短期內發出許多使用者登入要" +"求,這會降低 IPA 伺服器的延遲與負載。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:626 msgid "ipa_server_mode (boolean)" -msgstr "" +msgstr "ipa_server_mode (boolean)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:629 @@ -10260,6 +11686,8 @@ msgid "" "This option will be set by the IPA installer (ipa-server-install) " "automatically and denotes if SSSD is running on an IPA server or not." msgstr "" +"此選項會由 IPA 安裝程式 (ipa-server-install) 自動設定,表示 SSSD 是否在 IPA " +"伺服器上執行。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:634 @@ -10267,13 +11695,15 @@ msgid "" "On an IPA server SSSD will lookup users and groups from trusted domains " "directly while on a client it will ask an IPA server." msgstr "" +"在 IPA 伺服器上,SSSD 會直接查詢受信任網域的使用者與群組,而在用戶端上,它會" +"詢問 IPA 伺服器。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:639 msgid "" "NOTE: There are currently some assumptions that must be met when SSSD is " "running on an IPA server." -msgstr "" +msgstr "注意:SSSD 在 IPA 伺服器上執行時,目前必須滿足一些假設。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ipa.5.xml:644 @@ -10282,6 +11712,8 @@ msgid "" "server itself. This is already the default set by the IPA installer, so no " "manual change is required." msgstr "" +"<quote>ipa_server</quote> 選項必須設定為指向 IPA 伺服器本身。這已經是 IPA 安" +"裝程式設定的預設值,因此不需要手動變更。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ipa.5.xml:653 @@ -10289,51 +11721,53 @@ msgid "" "The <quote>full_name_format</quote> option must not be tweaked to only print " "short names for users from trusted domains." msgstr "" +"<quote>full_name_format</quote> 選項不得調整為只對受信任網域的使用者列印簡短" +"名稱。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:668 msgid "ipa_automount_location (string)" -msgstr "" +msgstr "ipa_automount_location (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:671 msgid "The automounter location this IPA client will be using" -msgstr "" +msgstr "此 IPA 用戶端將使用的自動掛載程式位置" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:674 msgid "Default: The location named \"default\"" -msgstr "" +msgstr "預設:名為 \"default\" 的位置" #. type: Content of: <reference><refentry><refsect1><refsect2><title> #: sssd-ipa.5.xml:682 msgid "VIEWS AND OVERRIDES" -msgstr "" +msgstr "檢視與覆寫" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:691 msgid "ipa_view_class (string)" -msgstr "" +msgstr "ipa_view_class (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:694 msgid "Objectclass of the view container." -msgstr "" +msgstr "檢視容器的物件類別。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:697 msgid "Default: nsContainer" -msgstr "" +msgstr "預設:nsContainer" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:703 msgid "ipa_view_name (string)" -msgstr "" +msgstr "ipa_view_name (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:706 msgid "Name of the attribute holding the name of the view." -msgstr "" +msgstr "保存檢視名稱的屬性名稱。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:710 sssd-ldap-attributes.5.xml:496 @@ -10341,128 +11775,128 @@ msgstr "" #: sssd-ldap-attributes.5.xml:1010 sssd-ldap-attributes.5.xml:1068 #: sssd-ldap-attributes.5.xml:1226 sssd-ldap-attributes.5.xml:1271 msgid "Default: cn" -msgstr "" +msgstr "預設:cn" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:716 msgid "ipa_override_object_class (string)" -msgstr "" +msgstr "ipa_override_object_class (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:719 msgid "Objectclass of the override objects." -msgstr "" +msgstr "覆寫物件的物件類別。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:722 msgid "Default: ipaOverrideAnchor" -msgstr "" +msgstr "預設:ipaOverrideAnchor" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:728 msgid "ipa_anchor_uuid (string)" -msgstr "" +msgstr "ipa_anchor_uuid (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:731 msgid "" "Name of the attribute containing the reference to the original object in a " "remote domain." -msgstr "" +msgstr "包含遠端網域中原始物件參照的屬性名稱。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:735 msgid "Default: ipaAnchorUUID" -msgstr "" +msgstr "預設:ipaAnchorUUID" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:741 msgid "ipa_user_override_object_class (string)" -msgstr "" +msgstr "ipa_user_override_object_class (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:744 msgid "" "Name of the objectclass for user overrides. It is used to determine if the " "found override object is related to a user or a group." -msgstr "" +msgstr "使用者覆寫的物件類別名稱。它用來判斷找到的覆寫物件是與使用者還是群組相關。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:749 msgid "User overrides can contain attributes given by" -msgstr "" +msgstr "使用者覆寫可以包含下列屬性:" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ipa.5.xml:752 msgid "ldap_user_name" -msgstr "" +msgstr "ldap_user_name" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ipa.5.xml:755 msgid "ldap_user_uid_number" -msgstr "" +msgstr "ldap_user_uid_number" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ipa.5.xml:758 msgid "ldap_user_gid_number" -msgstr "" +msgstr "ldap_user_gid_number" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ipa.5.xml:761 msgid "ldap_user_gecos" -msgstr "" +msgstr "ldap_user_gecos" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ipa.5.xml:764 msgid "ldap_user_home_directory" -msgstr "" +msgstr "ldap_user_home_directory" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ipa.5.xml:767 msgid "ldap_user_shell" -msgstr "" +msgstr "ldap_user_shell" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ipa.5.xml:770 msgid "ldap_user_ssh_public_key" -msgstr "" +msgstr "ldap_user_ssh_public_key" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:775 msgid "Default: ipaUserOverride" -msgstr "" +msgstr "預設:ipaUserOverride" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:781 msgid "ipa_group_override_object_class (string)" -msgstr "" +msgstr "ipa_group_override_object_class (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:784 msgid "" "Name of the objectclass for group overrides. It is used to determine if the " "found override object is related to a user or a group." -msgstr "" +msgstr "群組覆寫的物件類別名稱。它用來判斷找到的覆寫物件是與使用者還是群組相關。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:789 msgid "Group overrides can contain attributes given by" -msgstr "" +msgstr "群組覆寫可以包含下列屬性:" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ipa.5.xml:792 msgid "ldap_group_name" -msgstr "" +msgstr "ldap_group_name" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ipa.5.xml:795 msgid "ldap_group_gid_number" -msgstr "" +msgstr "ldap_group_gid_number" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:800 msgid "Default: ipaGroupOverride" -msgstr "" +msgstr "預設:ipaGroupOverride" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sssd-ipa.5.xml:684 @@ -10473,18 +11907,21 @@ msgid "" "related options are listed here with their default values. <placeholder " "type=\"variablelist\" id=\"0\"/>" msgstr "" +"SSSD 可以處理 FreeIPA 4.1 及更新版本提供的檢視與覆寫。由於所有路徑與物件類別" +"在伺服器端都是固定的,基本上不需要設定任何內容。為求完整,相關選項在此列出並" +"附上預設值。<placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><title> #: sssd-ipa.5.xml:812 msgid "SUBDOMAINS PROVIDER" -msgstr "" +msgstr "子網域提供者" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ipa.5.xml:814 msgid "" "The IPA subdomains provider behaves slightly differently if it is configured " "explicitly or implicitly." -msgstr "" +msgstr "IPA 子網域提供者在明確或隱含設定時,行為略有不同。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ipa.5.xml:818 @@ -10493,6 +11930,8 @@ msgid "" "sssd.conf, the IPA subdomains provider is configured explicitly, and all " "subdomain requests are sent to the IPA server if necessary." msgstr "" +"若在 sssd.conf 的網域區段中找到 'subdomains_provider = ipa' 選項,IPA 子網域" +"提供者會被明確設定,必要時所有子網域要求都會傳送到 IPA 伺服器。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ipa.5.xml:824 @@ -10505,11 +11944,15 @@ msgid "" "hour or after the IPA provider goes online, the subdomains provider is " "enabled again." msgstr "" +"若 sssd.conf 的網域區段中未設定 'subdomains_provider' 選項,但有 " +"'id_provider = ipa' 選項,IPA 子網域提供者會被隱含設定。這種情況下,若子網域" +"要求失敗並表示伺服器不支援子網域(也就是未設定信任),IPA 子網域提供者會被停" +"用。一小時後或 IPA 提供者上線後,子網域提供者會再次啟用。" #. type: Content of: <reference><refentry><refsect1><title> #: sssd-ipa.5.xml:835 msgid "TRUSTED DOMAINS CONFIGURATION" -msgstr "" +msgstr "受信任網域設定" #. type: Content of: <reference><refentry><refsect1><para><programlisting> #: sssd-ipa.5.xml:843 @@ -10518,6 +11961,8 @@ msgid "" "[domain/ipa.domain.com/ad.domain.com]\n" "ad_server = dc.ad.domain.com\n" msgstr "" +"[domain/ipa.domain.com/ad.domain.com]\n" +"ad_server = dc.ad.domain.com\n" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ipa.5.xml:837 @@ -10528,6 +11973,10 @@ msgid "" "option can be used in the parent domain. <placeholder " "type=\"programlisting\" id=\"0\"/>" msgstr "" +"某些設定選項也可以為受信任網域設定。可以使用如下列範例所示的受信任網域子區段" +"來設定受信任網域設定。另一種做法是,可以在父網域中使用 <quote>" +"subdomain_inherit</quote> 選項。<placeholder type=\"programlisting\" " +"id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ipa.5.xml:848 @@ -10536,6 +11985,8 @@ msgid "" "<refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</manvolnum> " "</citerefentry> manual page." msgstr "" +"更多詳細資料請參閱 <citerefentry> <refentrytitle>sssd.conf</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry> 手冊頁。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ipa.5.xml:855 @@ -10543,63 +11994,65 @@ msgid "" "Different configuration options are tunable for a trusted domain depending " "on whether you are configuring SSSD on an IPA server or an IPA client." msgstr "" +"可以在 IPA 伺服器還是 IPA 用戶端上設定 SSSD,決定了受信任網域可以調整哪些設定" +"選項。" #. type: Content of: <reference><refentry><refsect1><refsect2><title> #: sssd-ipa.5.xml:860 msgid "OPTIONS TUNABLE ON IPA MASTERS" -msgstr "" +msgstr "可在 IPA 主伺服器上調整的選項" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sssd-ipa.5.xml:862 msgid "The following options can be set in a subdomain section on an IPA master:" -msgstr "" +msgstr "可以在 IPA 主伺服器的子網域區段中設定下列選項:" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> #: sssd-ipa.5.xml:866 sssd-ipa.5.xml:896 msgid "ad_server" -msgstr "" +msgstr "ad_server" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> #: sssd-ipa.5.xml:869 msgid "ad_backup_server" -msgstr "" +msgstr "ad_backup_server" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> #: sssd-ipa.5.xml:872 sssd-ipa.5.xml:899 msgid "ad_site" -msgstr "" +msgstr "ad_site" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> #: sssd-ipa.5.xml:875 msgid "ldap_search_base" -msgstr "" +msgstr "ldap_search_base" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> #: sssd-ipa.5.xml:878 msgid "ldap_user_search_base" -msgstr "" +msgstr "ldap_user_search_base" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> #: sssd-ipa.5.xml:881 msgid "ldap_group_search_base" -msgstr "" +msgstr "ldap_group_search_base" #. type: Content of: <reference><refentry><refsect1><refsect2><title> #: sssd-ipa.5.xml:890 msgid "OPTIONS TUNABLE ON IPA CLIENTS" -msgstr "" +msgstr "可在 IPA 用戶端上調整的選項" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sssd-ipa.5.xml:892 msgid "The following options can be set in a subdomain section on an IPA client:" -msgstr "" +msgstr "可以在 IPA 用戶端的子網域區段中設定下列選項:" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sssd-ipa.5.xml:904 msgid "" "Note that if both options are set, only <quote>ad_server</quote> is " "evaluated." -msgstr "" +msgstr "請注意,若同時設定兩個選項,只會評估 <quote>ad_server</quote>。" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sssd-ipa.5.xml:908 @@ -10615,6 +12068,12 @@ msgid "" "<manvolnum>8</manvolnum> </citerefentry> manual page for more details on the " "Kerberos locator plugin." msgstr "" +"由於從 IPA 用戶端觸發、針對受信任網域之使用者或群組身分的任何要求都由 IPA 伺" +"服器解析,<quote>ad_server</quote> 與 <quote>ad_site</quote> 選項只會影響將針" +"對哪個 AD DC 執行驗證。特別的是,從這些清單解析出的位址會寫入 Kerberos " +"locator 外掛程式讀取的 <quote>kdcinfo</quote> 檔案。Kerberos locator 外掛程式" +"的更多詳細資料請參閱 <citerefentry> <refentrytitle>sssd_krb5_locator_plugin</" +"refentrytitle> <manvolnum>8</manvolnum> </citerefentry> 手冊頁。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ipa.5.xml:932 @@ -10623,6 +12082,8 @@ msgid "" "example.com is one of the domains in the <replaceable>[sssd]</replaceable> " "section. This examples shows only the ipa provider-specific options." msgstr "" +"下列範例假設 SSSD 已正確設定,且 example.com 是 <replaceable>[sssd]</" +"replaceable> 區段中的其中一個網域。此範例只顯示 ipa 提供者專屬的選項。" #. type: Content of: <reference><refentry><refsect1><para><programlisting> #: sssd-ipa.5.xml:939 @@ -10633,16 +12094,20 @@ msgid "" "ipa_server = ipaserver.example.com\n" "ipa_hostname = myhost.example.com\n" msgstr "" +"[domain/example.com]\n" +"id_provider = ipa\n" +"ipa_server = ipaserver.example.com\n" +"ipa_hostname = myhost.example.com\n" #. type: Content of: <reference><refentry><refnamediv><refname> #: sssd-ad.5.xml:10 sssd-ad.5.xml:16 msgid "sssd-ad" -msgstr "" +msgstr "sssd-ad" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sssd-ad.5.xml:17 msgid "SSSD Active Directory provider" -msgstr "" +msgstr "SSSD Active Directory 提供者" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ad.5.xml:23 @@ -10654,6 +12119,10 @@ msgid "" "<refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</manvolnum> " "</citerefentry> manual page." msgstr "" +"本手冊頁說明 <citerefentry> <refentrytitle>sssd</refentrytitle> <manvolnum>" +"8</manvolnum> </citerefentry> 之 AD 提供者的設定。詳細的語法參考請參閱 " +"<citerefentry> <refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry> 手冊頁的 <quote>FILE FORMAT</quote> 一節。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ad.5.xml:36 @@ -10664,6 +12133,9 @@ msgid "" "GSSAPI-encrypted channel, SSL/TLS options should not be used with the AD " "provider and will be superseded by Kerberos usage." msgstr "" +"AD 提供者是用來連線到 Active Directory 伺服器的後端。此提供者要求機器加入 AD " +"網域,且必須有可用的 keytab。後端通訊透過 GSSAPI 加密通道進行,不應將 SSL/" +"TLS 選項與 AD 提供者一起使用,這些選項會被 Kerberos 的使用取代。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ad.5.xml:44 @@ -10671,6 +12143,8 @@ msgid "" "The AD provider supports connecting to Active Directory 2008 R2 or " "later. Earlier versions may work, but are unsupported." msgstr "" +"AD 提供者支援連線到 Active Directory 2008 R2 或更新版本。較舊的版本可能可以運" +"作,但不受支援。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ad.5.xml:48 @@ -10680,6 +12154,8 @@ msgid "" "recognized. In addition servers from trusted domains are always " "auto-discovered." msgstr "" +"AD 提供者可以用來取得受信任網域的使用者資訊並驗證使用者。目前只識別相同樹系中" +"的受信任網域。此外,來自受信任網域的伺服器一律會自動探索。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ad.5.xml:54 @@ -10693,6 +12169,12 @@ msgid "" "sssd-ldap and sssd-krb5 providers with some exceptions. However, it is " "neither necessary nor recommended to set these options." msgstr "" +"AD 提供者讓 SSSD 可以使用 <citerefentry> <refentrytitle>sssd-ldap</" +"refentrytitle> <manvolnum>5</manvolnum> </citerefentry> 身分提供者與 " +"<citerefentry> <refentrytitle>sssd-krb5</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry> 驗證提供者,並針對 Active Directory 環境最佳化。" +"AD 提供者接受 sssd-ldap 與 sssd-krb5 提供者使用的相同選項,但有一些例外。不過" +",設定這些選項既非必要也不建議。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ad.5.xml:69 @@ -10701,6 +12183,8 @@ msgid "" "default options with some exceptions, the differences are listed in the " "<quote>MODIFIED DEFAULT OPTIONS</quote> section." msgstr "" +"AD 提供者主要複製傳統 ldap 與 krb5 提供者的預設選項,但有一些例外,差異列於 " +"<quote>MODIFIED DEFAULT OPTIONS</quote> 一節。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ad.5.xml:74 @@ -10709,6 +12193,8 @@ msgid "" "provider. No configuration of the access provider is required on the client " "side." msgstr "" +"AD 提供者也可以用作 access、chpass、sudo 與 autofs 提供者。用戶端不需要設定 " +"access 提供者。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ad.5.xml:79 @@ -10717,6 +12203,8 @@ msgid "" "configured in sssd.conf then the id_provider must also be set to " "<quote>ad</quote>." msgstr "" +"若在 sssd.conf 中設定 <quote>auth_provider=ad</quote> 或 <quote>" +"access_provider=ad</quote>,則 id_provider 也必須設為 <quote>ad</quote>。" #. type: Content of: <reference><refentry><refsect1><para><programlisting> #: sssd-ad.5.xml:91 @@ -10725,6 +12213,8 @@ msgid "" "ldap_id_mapping = False\n" " " msgstr "" +"ldap_id_mapping = False\n" +" " #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ad.5.xml:85 @@ -10745,6 +12235,15 @@ msgid "" "present in the Global Catalog, the non-replicated attributes are currently " "not read from the LDAP port." msgstr "" +"預設情況下,AD 提供者會從 Active Directory 中的 objectSID 參數對應 UID 與 " +"GID 值。詳細資料請參閱下方 <quote>ID MAPPING</quote> 一節。若您想停用 ID 對應" +",改為依賴 Active Directory 中定義的 POSIX 屬性,應設定 <placeholder " +"type=\"programlisting\" id=\"0\"/> 若應使用 POSIX 屬性,基於效能考量,建議也" +"將屬性複寫到全域目錄。若複寫了 POSIX 屬性,SSSD 會嘗試借助全域目錄定位要求之" +"數值 ID 的網域,並只搜尋該網域。相反地,若 POSIX 屬性未複寫到全域目錄,SSSD " +"必須依序搜尋樹系中的所有網域。請注意,<quote>cache_first</quote> 選項可能也有" +"助於加速無網域搜尋。請注意,若全域目錄中只有部分 POSIX 屬性,目前不會從 LDAP " +"連接埠讀取未複寫的屬性。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ad.5.xml:108 @@ -10753,6 +12252,8 @@ msgid "" "case-insensitive in the AD provider for compatibility with Active " "Directory's LDAP implementation." msgstr "" +"為了與 Active Directory 的 LDAP 實作相容,SSSD 服務的使用者、群組與其他實體" +"在 AD 提供者中一律視為不區分大小寫。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ad.5.xml:113 @@ -10762,6 +12263,9 @@ msgid "" "url=\"https://docs.microsoft.com/en-us/windows-server/identity/ad-ds/manage/understand-security-groups\"> " "Active Directory security groups</ulink>" msgstr "" +"SSSD 只解析 Active Directory 安全性群組。AD 群組類型的更多資訊請參閱:<ulink " +"url=\"https://docs.microsoft.com/en-us/windows-server/identity/ad-ds/manage/" +"understand-security-groups\"> Active Directory security groups</ulink>" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ad.5.xml:120 @@ -10773,37 +12277,41 @@ msgid "" "group-membership assignment which can be seen in the PAC of the Kerberos " "ticket of a user issued by Active Directory." msgstr "" +"SSSD 會過濾掉 AD 樹系中遠端網域的網域本機群組。預設會將它們過濾掉,例如追蹤遠" +"端網域中的巢狀群組階層時,因為它們在網域本機中無效。這樣做是為了與 Active " +"Directory 的群組成員資格指派一致,可以在 Active Directory 發行之使用者 " +"Kerberos 票證的 PAC 中看到。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:138 msgid "ad_domain (string)" -msgstr "" +msgstr "ad_domain (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:141 msgid "" "Specifies the name of the Active Directory domain. This is optional. If not " "provided, the configuration domain name is used." -msgstr "" +msgstr "指定 Active Directory 網域名稱。這是選用的。若未提供,則使用設定網域名稱。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:146 msgid "" "For proper operation, this option should be specified as the lower-case " "version of the long version of the Active Directory domain." -msgstr "" +msgstr "為求正常運作,此選項應指定為 Active Directory 網域長名稱的小寫版本。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:151 msgid "" "The short domain name (also known as the NetBIOS or the flat name) is " "autodetected by the SSSD." -msgstr "" +msgstr "簡短網域名稱(也稱為 NetBIOS 或 flat 名稱)會由 SSSD 自動偵測。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:158 msgid "ad_enabled_domains (string)" -msgstr "" +msgstr "ad_enabled_domains (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:161 @@ -10812,6 +12320,8 @@ msgid "" "SSSD will ignore any domains not listed in this option. If left unset, all " "discovered domains from the AD forest will be available." msgstr "" +"已啟用 Active Directory 網域的逗號分隔清單。若提供,SSSD 會忽略未列在此選項中" +"的任何網域。若保持未設定,AD 樹系中探索到的所有網域都會可用。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:168 @@ -10821,6 +12331,8 @@ msgid "" "are not trusted. If ad_enabled_domains is set, SSSD will try to enable all " "listed domains." msgstr "" +"在網域探索期間,SSSD 會過濾掉一些旗標或屬性表示它們不屬於本機樹系或不受信任的" +"網域。若設定了 ad_enabled_domains,SSSD 會嘗試啟用所有列出的網域。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> #: sssd-ad.5.xml:179 @@ -10829,6 +12341,8 @@ msgid "" "ad_enabled_domains = sales.example.com, eng.example.com\n" " " msgstr "" +"ad_enabled_domains = sales.example.com, eng.example.com\n" +" " #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:175 @@ -10837,18 +12351,20 @@ msgid "" "the fully qualified domain name of the Active Directory domain. For example: " "<placeholder type=\"programlisting\" id=\"0\"/>" msgstr "" +"為求正常運作,此選項必須以全小寫指定,並使用 Active Directory 網域的完整網域" +"名稱。例如:<placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:183 msgid "" "The short domain name (also known as the NetBIOS or the flat name) will be " "autodetected by SSSD." -msgstr "" +msgstr "簡短網域名稱(也稱為 NetBIOS 或 flat 名稱)會由 SSSD 自動偵測。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:193 msgid "ad_server, ad_backup_server (string)" -msgstr "" +msgstr "ad_server, ad_backup_server (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:196 @@ -10857,6 +12373,8 @@ msgid "" "connect in order of preference. For more information on failover and server " "redundancy, see the <quote>FAILOVER</quote> section." msgstr "" +"SSSD 應依偏好順序連線之 AD 伺服器的主機名稱逗號分隔清單。有關故障轉移與伺服器" +"備援的更多資訊,請參閱 <quote>FAILOVER</quote> 一節。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:203 @@ -10864,6 +12382,8 @@ msgid "" "This is optional if autodiscovery is enabled. For more information on " "service discovery, refer to the <quote>SERVICE DISCOVERY</quote> section." msgstr "" +"若啟用自動探索,此選項是選用的。服務探索的更多資訊請參閱 <quote>SERVICE " +"DISCOVERY</quote> 一節。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:208 @@ -10871,11 +12391,13 @@ msgid "" "Note: Trusted domains will always auto-discover servers even if the primary " "server is explicitly defined in the ad_server option." msgstr "" +"注意:即使主要伺服器已在 ad_server 選項中明確定義,受信任網域一律會自動探索伺" +"服器。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:216 msgid "ad_hostname (string)" -msgstr "" +msgstr "ad_hostname (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:219 @@ -10885,6 +12407,8 @@ msgid "" "possible or the short name should be really used instead, set this parameter " "explicitly." msgstr "" +"選用。在 hostname(5) 未反映完整名稱的機器上,sssd 會嘗試展開簡短名稱。若無法" +"展開或確實應改用簡短名稱,請明確設定此參數。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:226 @@ -10893,11 +12417,13 @@ msgid "" "to perform dynamic DNS updates. It must match the hostname for which the " "keytab was issued." msgstr "" +"此欄位用來判斷 keytab 中使用的主機 principal,並執行動態 DNS 更新。它必須符合" +"簽發 keytab 時的主機名稱。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:235 msgid "ad_enable_dns_sites (boolean)" -msgstr "" +msgstr "ad_enable_dns_sites (boolean)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:242 @@ -10909,11 +12435,15 @@ msgid "" "DNS SRV configuration, including the discovery domain, is used during site " "discovery as well." msgstr "" +"若為 true 且啟用服務探索(請參閱手冊頁底部的 Service Discovery 段落),SSSD " +"會先嘗試使用 Active Directory Site Discovery 探索要連線的 Active Directory 伺" +"服器,若找不到 AD site,則退回 DNS SRV 記錄。DNS SRV 設定(包括探索網域)也會" +"在 site 探索期間使用。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:258 msgid "ad_access_filter (string)" -msgstr "" +msgstr "ad_access_filter (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:261 @@ -10925,6 +12455,10 @@ msgid "" "disable GPO based access control (see option " "<quote>ad_gpo_access_control</quote> for details)." msgstr "" +"指定使用者必須符合才能獲得存取權的 LDAP 存取控制篩選器。此選項要生效,<quote>" +"access_provider</quote> 選項必須明確設為 <quote>ad</quote>。若您想使用 " +"<quote>ad_access_filter</quote> 作為唯一的存取控制機制,必須停用以 GPO 為基礎" +"的存取控制(詳情請參閱 <quote>ad_gpo_access_control</quote> 選項)。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:270 @@ -10934,6 +12468,9 @@ msgid "" "<quote>KEYWORD:NAME:FILTER</quote>. The keyword can be either " "<quote>DOM</quote>, <quote>FOREST</quote> or missing." msgstr "" +"此選項也支援依網域或樹系指定不同的篩選器。這種延伸篩選器由 <quote>" +"KEYWORD:NAME:FILTER</quote> 組成。關鍵字可以是 <quote>DOM</quote>、<quote>" +"FOREST</quote> 或省略。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:278 @@ -10943,13 +12480,16 @@ msgid "" "to. If the keyword equals to <quote>FOREST</quote>, then the filter equals " "to all domains from the forest specified by <quote>NAME</quote>." msgstr "" +"若關鍵字等於 <quote>DOM</quote> 或省略,則 <quote>NAME</quote> 指定篩選器適用" +"的網域或子網域。若關鍵字等於 <quote>FOREST</quote>,則篩選器等於 <quote>" +"NAME</quote> 指定之樹系中的所有網域。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:286 msgid "" "Multiple filters can be separated with the <quote>?</quote> character, " "similarly to how search bases work." -msgstr "" +msgstr "多個篩選器可以像搜尋基礎一樣,以 <quote>?</quote> 字元分隔。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:291 @@ -10963,6 +12503,12 @@ msgid "" "url=\"https://msdn.microsoft.com/en-us/library/cc223367.aspx\"> [MS-ADTS] " "section LDAP extensions</ulink>" msgstr "" +"巢狀群組成員資格必須使用特殊 OID <quote>:1.2.840.113556.1.4.1941:</quote> 搜" +"尋,另外還要使用完整的 DOM:domain.example.org: 語法,以確保剖析器不會嘗試解讀" +"與 OID 關聯的冒號字元。若您不使用此 OID,巢狀群組成員資格將無法解析。請參閱下" +"方的使用範例,並在此參考有關此 OID 的進一步資訊:<ulink url=\"https://" +"msdn.microsoft.com/en-us/library/cc223367.aspx\"> [MS-ADTS] section LDAP " +"extensions</ulink>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:304 @@ -10972,6 +12518,8 @@ msgid "" "per-domain filter would be applied. If there are more matches with the same " "specification, the first one is used." msgstr "" +"一律使用最具體的匹配。例如,若選項同時指定了使用者所屬網域的篩選器與全域篩選" +"器,則會套用逐網域篩選器。若有多個規格相同的匹配,則使用第一個。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><programlisting> #: sssd-ad.5.xml:315 @@ -10990,23 +12538,37 @@ msgid "" "DOM:dom1:(memberOf:1.2.840.113556.1.4.1941:=cn=nestedgroup,ou=groups,dc=example,dc=com)\n" " " msgstr "" +"# apply filter on domain called dom1 only:\n" +"dom1:(memberOf=cn=admins,ou=groups,dc=dom1,dc=com)\n" +"\n" +"# apply filter on domain called dom2 only:\n" +"DOM:dom2:(memberOf=cn=admins,ou=groups,dc=dom2,dc=com)\n" +"\n" +"# apply filter on forest called EXAMPLE.COM only:\n" +"FOREST:EXAMPLE.COM:(memberOf=cn=admins,ou=groups,dc=example,dc=com)\n" +"\n" +"# apply filter for a member of a nested group in dom1:\n" +"DOM:dom1:" +"(memberOf:1.2.840.113556.1.4.1941:=cn=nestedgroup,ou=groups,dc=example,dc=com)" +"\n" +" " #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:334 msgid "ad_site (string)" -msgstr "" +msgstr "ad_site (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:337 msgid "" "Specify AD site to which client should try to connect. If this option is " "not provided, the AD site will be auto-discovered." -msgstr "" +msgstr "指定用戶端應嘗試連線的 AD site。若未提供此選項,AD site 會自動探索。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:348 msgid "ad_enable_gc (boolean)" -msgstr "" +msgstr "ad_enable_gc (boolean)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:351 @@ -11016,6 +12578,9 @@ msgid "" "as a fallback. Disabling this option makes the SSSD only connect to the LDAP " "port of the current AD server." msgstr "" +"預設情況下,SSSD 會先連線到全域目錄,從受信任網域取回使用者,並使用 LDAP 連接" +"埠取回群組成員資格或作為退回。停用此選項會讓 SSSD 只連線到目前 AD 伺服器的 " +"LDAP 連接埠。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:359 @@ -11025,11 +12590,13 @@ msgid "" "port of trusted domains instead. However, Global Catalog must be used in " "order to resolve cross-domain group memberships." msgstr "" +"請注意,停用全域目錄支援不會停用從受信任網域取回使用者。SSSD 會改為連線到受信" +"任網域的 LDAP 連接埠。不過,要解析跨網域群組成員資格,必須使用全域目錄。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:373 msgid "ad_gpo_access_control (string)" -msgstr "" +msgstr "ad_gpo_access_control (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:376 @@ -11040,6 +12607,9 @@ msgid "" "must be explicitly set to <quote>ad</quote> in order for this option to have " "an effect." msgstr "" +"此選項指定 GPO 型存取控制功能的作業模式:以停用模式、強制模式或寬鬆模式運作。" +"請注意,此選項要生效,<quote>access_provider</quote> 選項必須明確設為 <quote>" +"ad</quote>。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:385 @@ -11049,6 +12619,8 @@ msgid "" "information on the supported policy settings please refer to the " "<quote>ad_gpo_map</quote> options." msgstr "" +"GPO 型存取控制功能使用 GPO 原則設定,判斷特定使用者是否允許登入主機。支援之原" +"則設定的更多資訊請參閱 <quote>ad_gpo_map</quote> 選項。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:393 @@ -11058,6 +12630,9 @@ msgid "" "S-1-5-32-544) in GPO access control rules will be ignored by SSSD. See " "upstream issue tracker https://github.com/SSSD/sssd/issues/5063 ." msgstr "" +"請注意,目前版本的 SSSD 不支援 Active Directory 的內建群組。GPO 存取控制規則" +"中的內建群組(例如 SID 為 S-1-5-32-544 的 Administrators)會被 SSSD 忽略。請" +"參閱上游問題追蹤器 https://github.com/SSSD/sssd/issues/5063。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:402 @@ -11068,6 +12643,9 @@ msgid "" "a user, the user or at least one of the groups to which it belongs must have " "following permissions on the GPO:" msgstr "" +"執行存取控制之前,SSSD 會對 GPO 套用群組原則安全性篩選。每次使用者登入時,都" +"會檢查連結到主機之 GPO 的適用性。GPO 要套用於使用者,使用者或其所屬的至少一個" +"群組必須對 GPO 具有下列權限:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ad.5.xml:412 @@ -11075,6 +12653,8 @@ msgid "" "Read: The user or one of its groups must have read access to the properties " "of the GPO (RIGHT_DS_READ_PROPERTY)" msgstr "" +"讀取:使用者或其其中一個群組必須對 GPO 的屬性具有讀取存取權 " +"(RIGHT_DS_READ_PROPERTY)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ad.5.xml:419 @@ -11082,6 +12662,8 @@ msgid "" "Apply Group Policy: The user or at least one of its groups must be allowed " "to apply the GPO (RIGHT_DS_CONTROL_ACCESS)." msgstr "" +"套用群組原則:使用者或其至少一個群組必須被允許套用 GPO " +"(RIGHT_DS_CONTROL_ACCESS)。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:427 @@ -11092,6 +12674,9 @@ msgid "" "and access control are started, the Authenticated Users group permissions on " "the GPO always apply also to the user." msgstr "" +"預設情況下,GPO 上會有 Authenticated Users 群組,此群組同時具有讀取與套用群組" +"原則存取權。由於必須先成功完成使用者驗證,才會開始 GPO 安全性篩選與存取控制," +"因此 GPO 上的 Authenticated Users 群組權限一律也適用於使用者。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:436 @@ -11108,21 +12693,27 @@ msgid "" "<refentrytitle>sssctl</refentrytitle> <manvolnum>8</manvolnum> " "</citerefentry> manual page)." msgstr "" +"注意:若作業模式設為強制,先前允許登入存取權的使用者現在可能會被拒絕登入存取" +"權(由 GPO 原則設定決定)。為方便管理員順利轉換,提供寬鬆模式,不會強制執行存" +"取控制規則,但會評估規則,若存取會被拒絕,則輸出 syslog 訊息。管理員檢查記錄" +"後,可以在將模式設為強制之前進行必要的變更。要記錄 GPO 型存取控制,需要 " +"'trace functions' 除錯層級(請參閱 <citerefentry> <refentrytitle>sssctl</" +"refentrytitle> <manvolnum>8</manvolnum> </citerefentry> 手冊頁)。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:455 msgid "There are three supported values for this option:" -msgstr "" +msgstr "此選項支援三個值:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ad.5.xml:459 msgid "disabled: GPO-based access control rules are neither evaluated nor enforced." -msgstr "" +msgstr "disabled:GPO 型存取控制規則既不會評估也不會強制執行。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ad.5.xml:465 msgid "enforcing: GPO-based access control rules are evaluated and enforced." -msgstr "" +msgstr "enforcing:GPO 型存取控制規則會評估並強制執行。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ad.5.xml:471 @@ -11131,21 +12722,23 @@ msgid "" "Instead, a syslog message will be emitted indicating that the user would " "have been denied access if this option's value were set to enforcing." msgstr "" +"permissive:GPO 型存取控制規則會評估,但不會強制執行。取而代之的是,會發出 " +"syslog 訊息,表示若此選項的值設為 enforcing,使用者就會被拒絕存取。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:482 msgid "Default: permissive" -msgstr "" +msgstr "預設:permissive" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:485 msgid "Default: enforcing" -msgstr "" +msgstr "預設:enforcing" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:491 msgid "ad_gpo_implicit_deny (boolean)" -msgstr "" +msgstr "ad_gpo_implicit_deny (boolean)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:494 @@ -11157,6 +12750,10 @@ msgid "" "option because it can deny access even to users in the built-in " "Administrators group if no GPO rules apply to them." msgstr "" +"一般來說,找不到適用的 GPO 時,使用者會被允許存取。當此選項設為 True 時,只" +"有 GPO 規則明確允許時,使用者才會被允許存取。否則使用者會被拒絕存取。這可以用" +"來強化安全性,但使用此選項時要小心,因為若沒有 GPO 規則適用於內建 " +"Administrators 群組中的使用者,它甚至可能拒絕他們存取。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:510 @@ -11165,73 +12762,75 @@ msgid "" "based on the allow and deny login rights defined on the server-side and the " "setting of ad_gpo_implicit_deny." msgstr "" +"下列 2 個表格說明根據伺服器端定義的允許與拒絕登入權限,以及 " +"ad_gpo_implicit_deny 的設定,使用者何時會被允許或拒絕。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> #: sssd-ad.5.xml:522 msgid "ad_gpo_implicit_deny = False (default)" -msgstr "" +msgstr "ad_gpo_implicit_deny = False(預設)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> #: sssd-ad.5.xml:523 sssd-ad.5.xml:549 msgid "allow-rules" -msgstr "" +msgstr "allow-rules" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> #: sssd-ad.5.xml:523 sssd-ad.5.xml:549 msgid "deny-rules" -msgstr "" +msgstr "deny-rules" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> #: sssd-ad.5.xml:524 sssd-ad.5.xml:550 msgid "results" -msgstr "" +msgstr "結果" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry> #: sssd-ad.5.xml:527 sssd-ad.5.xml:530 sssd-ad.5.xml:533 sssd-ad.5.xml:553 #: sssd-ad.5.xml:556 sssd-ad.5.xml:559 msgid "missing" -msgstr "" +msgstr "不存在" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry><para> #: sssd-ad.5.xml:528 msgid "all users are allowed" -msgstr "" +msgstr "允許所有使用者" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry> #: sssd-ad.5.xml:530 sssd-ad.5.xml:533 sssd-ad.5.xml:536 sssd-ad.5.xml:556 #: sssd-ad.5.xml:559 sssd-ad.5.xml:562 msgid "present" -msgstr "" +msgstr "存在" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry><para> #: sssd-ad.5.xml:531 msgid "only users not in deny-rules are allowed" -msgstr "" +msgstr "只允許不在 deny-rules 中的使用者" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry><para> #: sssd-ad.5.xml:534 sssd-ad.5.xml:560 msgid "only users in allow-rules are allowed" -msgstr "" +msgstr "只允許在 allow-rules 中的使用者" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry><para> #: sssd-ad.5.xml:537 sssd-ad.5.xml:563 msgid "only users in allow-rules and not in deny-rules are allowed" -msgstr "" +msgstr "只允許在 allow-rules 中且不在 deny-rules 中的使用者" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> #: sssd-ad.5.xml:548 msgid "ad_gpo_implicit_deny = True" -msgstr "" +msgstr "ad_gpo_implicit_deny = True" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry><para> #: sssd-ad.5.xml:554 sssd-ad.5.xml:557 msgid "no users are allowed" -msgstr "" +msgstr "不允許任何使用者" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:570 msgid "ad_gpo_ignore_unreadable (boolean)" -msgstr "" +msgstr "ad_gpo_ignore_unreadable (boolean)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:573 @@ -11242,11 +12841,14 @@ msgid "" "policies if their attributes in group policy containers are not readable for " "SSSD." msgstr "" +"一般來說,當適用之群組原則物件的某些群組原則容器(AD 物件)無法被 SSSD 讀取時" +",使用者會被拒絕存取。此選項允許忽略群組原則容器及其關聯的原則(若其在群組原" +"則容器中的屬性無法被 SSSD 讀取)。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:590 msgid "ad_gpo_cache_timeout (integer)" -msgstr "" +msgstr "ad_gpo_cache_timeout (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:593 @@ -11255,11 +12857,13 @@ msgid "" "server. This will reduce the latency and load on the AD server if there are " "many access-control requests made in a short period." msgstr "" +"對 AD 伺服器查詢 GPO 原則檔案之間的時間量。若在短期內發出許多存取控制要求,這" +"會降低 AD 伺服器的延遲與負載。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:606 msgid "ad_gpo_map_interactive (string)" -msgstr "" +msgstr "ad_gpo_map_interactive (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:609 @@ -11276,6 +12880,13 @@ msgid "" "local access only, if it or at least one of its groups is part of the policy " "settings." msgstr "" +"以 InteractiveLogonRight 與 DenyInteractiveLogonRight 原則設定評估 GPO 型存取" +"控制的 PAM 服務名稱逗號分隔清單。只會評估使用者具有讀取與套用群組原則權限的 " +"GPO(請參閱 <quote>ad_gpo_access_control</quote> 選項)。若評估的 GPO 包含針" +"對使用者或其其中一個群組的拒絕互動式登入設定,使用者會被拒絕本機存取。若評估" +"的 GPO 中沒有定義互動式登入權限,使用者會被授予本機存取。若至少一個評估的 " +"GPO 包含互動式登入權限設定,則只有使用者或其至少一個群組屬於原則設定的一部分" +"時,使用者才會被授予本機存取。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:627 @@ -11283,6 +12894,8 @@ msgid "" "Note: Using the Group Policy Management Editor this value is called \"Allow " "log on locally\" and \"Deny log on locally\"." msgstr "" +"注意:使用群組原則管理編輯器時,此值稱為 \"Allow log on locally\" 與 \"Deny " +"log on locally\"。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> #: sssd-ad.5.xml:641 @@ -11291,6 +12904,8 @@ msgid "" "ad_gpo_map_interactive = +my_pam_service, -login\n" " " msgstr "" +"ad_gpo_map_interactive = +my_pam_service, -login\n" +" " #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:632 @@ -11303,41 +12918,46 @@ msgid "" "(e.g. <quote>my_pam_service</quote>), you would use the following " "configuration: <placeholder type=\"programlisting\" id=\"0\"/>" msgstr "" +"可以使用 <quote>+service_name</quote> 將另一個 PAM 服務名稱加入預設集合,或使" +"用 <quote>-service_name</quote> 明確地從預設集合移除 PAM 服務名稱。例如,若要" +"將此登入權限的預設 PAM 服務名稱(例如 <quote>login</quote>)取代為自訂 pam 服" +"務名稱(例如 <quote>my_pam_service</quote>),您可以使用下列設定" +":<placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ad.5.xml:664 msgid "gdm-fingerprint" -msgstr "" +msgstr "gdm-fingerprint" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ad.5.xml:684 msgid "lightdm" -msgstr "" +msgstr "lightdm" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ad.5.xml:689 msgid "lxdm" -msgstr "" +msgstr "lxdm" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ad.5.xml:694 msgid "sddm" -msgstr "" +msgstr "sddm" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ad.5.xml:699 msgid "unity" -msgstr "" +msgstr "unity" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ad.5.xml:704 msgid "xdm" -msgstr "" +msgstr "xdm" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:713 msgid "ad_gpo_map_remote_interactive (string)" -msgstr "" +msgstr "ad_gpo_map_remote_interactive (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:716 @@ -11354,6 +12974,13 @@ msgid "" "right settings, the user is granted remote access only, if it or at least " "one of its groups is part of the policy settings." msgstr "" +"以 RemoteInteractiveLogonRight 與 DenyRemoteInteractiveLogonRight 原則設定評" +"估 GPO 型存取控制的 PAM 服務名稱逗號分隔清單。只會評估使用者具有讀取與套用群" +"組原則權限的 GPO(請參閱 <quote>ad_gpo_access_control</quote> 選項)。若評估" +"的 GPO 包含針對使用者或其其中一個群組的拒絕遠端登入設定,使用者會被拒絕遠端互" +"動式存取。若評估的 GPO 中沒有定義遠端互動式登入權限,使用者會被授予遠端存取。" +"若至少一個評估的 GPO 包含遠端互動式登入權限設定,則只有使用者或其至少一個群組" +"屬於原則設定的一部分時,使用者才會被授予遠端存取。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:735 @@ -11362,6 +12989,8 @@ msgid "" "log on through Remote Desktop Services\" and \"Deny log on through Remote " "Desktop Services\"." msgstr "" +"注意:使用群組原則管理編輯器時,此值稱為 \"Allow log on through Remote " +"Desktop Services\" 與 \"Deny log on through Remote Desktop Services\"。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> #: sssd-ad.5.xml:750 @@ -11370,6 +12999,8 @@ msgid "" "ad_gpo_map_remote_interactive = +my_pam_service, -sshd\n" " " msgstr "" +"ad_gpo_map_remote_interactive = +my_pam_service, -sshd\n" +" " #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:741 @@ -11382,21 +13013,26 @@ msgid "" "(e.g. <quote>my_pam_service</quote>), you would use the following " "configuration: <placeholder type=\"programlisting\" id=\"0\"/>" msgstr "" +"可以使用 <quote>+service_name</quote> 將另一個 PAM 服務名稱加入預設集合,或使" +"用 <quote>-service_name</quote> 明確地從預設集合移除 PAM 服務名稱。例如,若要" +"將此登入權限的預設 PAM 服務名稱(例如 <quote>sshd</quote>)取代為自訂 pam 服" +"務名稱(例如 <quote>my_pam_service</quote>),您可以使用下列設定" +":<placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ad.5.xml:758 msgid "sshd" -msgstr "" +msgstr "sshd" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ad.5.xml:763 msgid "cockpit" -msgstr "" +msgstr "cockpit" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:772 msgid "ad_gpo_map_network (string)" -msgstr "" +msgstr "ad_gpo_map_network (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:775 @@ -11413,6 +13049,13 @@ msgid "" "logon access only, if it or at least one of its groups is part of the policy " "settings." msgstr "" +"以 NetworkLogonRight 與 DenyNetworkLogonRight 原則設定評估 GPO 型存取控制的 " +"PAM 服務名稱逗號分隔清單。只會評估使用者具有讀取與套用群組原則權限的 GPO(請" +"參閱 <quote>ad_gpo_access_control</quote> 選項)。若評估的 GPO 包含針對使用者" +"或其其中一個群組的拒絕網路登入設定,使用者會被拒絕網路登入存取。若評估的 GPO " +"中沒有定義網路登入權限,使用者會被授予登入存取。若至少一個評估的 GPO 包含網路" +"登入權限設定,則只有使用者或其至少一個群組屬於原則設定的一部分時,使用者才會" +"被授予登入存取。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:793 @@ -11421,6 +13064,8 @@ msgid "" "this computer from the network\" and \"Deny access to this computer from the " "network\"." msgstr "" +"注意:使用群組原則管理編輯器時,此值稱為 \"Access this computer from the " +"network\" 與 \"Deny access to this computer from the network\"。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> #: sssd-ad.5.xml:808 @@ -11429,6 +13074,8 @@ msgid "" "ad_gpo_map_network = +my_pam_service, -ftp\n" " " msgstr "" +"ad_gpo_map_network = +my_pam_service, -ftp\n" +" " #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:799 @@ -11441,21 +13088,26 @@ msgid "" "(e.g. <quote>my_pam_service</quote>), you would use the following " "configuration: <placeholder type=\"programlisting\" id=\"0\"/>" msgstr "" +"可以使用 <quote>+service_name</quote> 將另一個 PAM 服務名稱加入預設集合,或使" +"用 <quote>-service_name</quote> 明確地從預設集合移除 PAM 服務名稱。例如,若要" +"將此登入權限的預設 PAM 服務名稱(例如 <quote>ftp</quote>)取代為自訂 pam 服務" +"名稱(例如 <quote>my_pam_service</quote>),您可以使用下列設定:<placeholder " +"type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ad.5.xml:816 msgid "ftp" -msgstr "" +msgstr "ftp" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ad.5.xml:821 msgid "samba" -msgstr "" +msgstr "samba" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:830 msgid "ad_gpo_map_batch (string)" -msgstr "" +msgstr "ad_gpo_map_batch (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:833 @@ -11471,6 +13123,13 @@ msgid "" "GPO contains batch logon right settings, the user is granted logon access " "only, if it or at least one of its groups is part of the policy settings." msgstr "" +"以 BatchLogonRight 與 DenyBatchLogonRight 原則設定評估 GPO 型存取控制的 PAM " +"服務名稱逗號分隔清單。只會評估使用者具有讀取與套用群組原則權限的 GPO(請參閱 " +"<quote>ad_gpo_access_control</quote> 選項)。若評估的 GPO 包含針對使用者或其" +"其中一個群組的拒絕批次登入設定,使用者會被拒絕批次登入存取。若評估的 GPO 中沒" +"有定義批次登入權限,使用者會被授予登入存取。若至少一個評估的 GPO 包含批次登入" +"權限設定,則只有使用者或其至少一個群組屬於原則設定的一部分時,使用者才會被授" +"予登入存取。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:851 @@ -11478,6 +13137,8 @@ msgid "" "Note: Using the Group Policy Management Editor this value is called \"Allow " "log on as a batch job\" and \"Deny log on as a batch job\"." msgstr "" +"注意:使用群組原則管理編輯器時,此值稱為 \"Allow log on as a batch job\" 與 " +"\"Deny log on as a batch job\"。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> #: sssd-ad.5.xml:865 @@ -11486,6 +13147,8 @@ msgid "" "ad_gpo_map_batch = +my_pam_service, -crond\n" " " msgstr "" +"ad_gpo_map_batch = +my_pam_service, -crond\n" +" " #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:856 @@ -11498,21 +13161,26 @@ msgid "" "(e.g. <quote>my_pam_service</quote>), you would use the following " "configuration: <placeholder type=\"programlisting\" id=\"0\"/>" msgstr "" +"可以使用 <quote>+service_name</quote> 將另一個 PAM 服務名稱加入預設集合,或使" +"用 <quote>-service_name</quote> 明確地從預設集合移除 PAM 服務名稱。例如,若要" +"將此登入權限的預設 PAM 服務名稱(例如 <quote>crond</quote>)取代為自訂 pam 服" +"務名稱(例如 <quote>my_pam_service</quote>),您可以使用下列設定" +":<placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:868 msgid "Note: Cron service name may differ depending on Linux distribution used." -msgstr "" +msgstr "注意:Cron 服務名稱可能因使用的 Linux 發行版而異。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ad.5.xml:874 msgid "crond" -msgstr "" +msgstr "crond" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:883 msgid "ad_gpo_map_service (string)" -msgstr "" +msgstr "ad_gpo_map_service (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:886 @@ -11529,6 +13197,13 @@ msgid "" "logon access only, if it or at least one of its groups is part of the policy " "settings." msgstr "" +"以 ServiceLogonRight 與 DenyServiceLogonRight 原則設定評估 GPO 型存取控制的 " +"PAM 服務名稱逗號分隔清單。只會評估使用者具有讀取與套用群組原則權限的 GPO(請" +"參閱 <quote>ad_gpo_access_control</quote> 選項)。若評估的 GPO 包含針對使用者" +"或其其中一個群組的拒絕服務登入設定,使用者會被拒絕服務登入存取。若評估的 GPO " +"中沒有定義服務登入權限,使用者會被授予登入存取。若至少一個評估的 GPO 包含服務" +"登入權限設定,則只有使用者或其至少一個群組屬於原則設定的一部分時,使用者才會" +"被授予登入存取。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:904 @@ -11536,6 +13211,8 @@ msgid "" "Note: Using the Group Policy Management Editor this value is called \"Allow " "log on as a service\" and \"Deny log on as a service\"." msgstr "" +"注意:使用群組原則管理編輯器時,此值稱為 \"Allow log on as a service\" 與 " +"\"Deny log on as a service\"。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> #: sssd-ad.5.xml:917 @@ -11544,6 +13221,8 @@ msgid "" "ad_gpo_map_service = +my_pam_service\n" " " msgstr "" +"ad_gpo_map_service = +my_pam_service\n" +" " #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:909 sssd-ad.5.xml:984 @@ -11555,18 +13234,22 @@ msgid "" "you would use the following configuration: <placeholder " "type=\"programlisting\" id=\"0\"/>" msgstr "" +"可以使用 <quote>+service_name</quote> 將 PAM 服務名稱加入預設集合。由於預設集" +"合是空的,無法從預設集合移除 PAM 服務名稱。例如,若要加入自訂 pam 服務名稱(" +"例如 <quote>my_pam_service</quote>),您可以使用下列設定:<placeholder " +"type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:927 msgid "ad_gpo_map_permit (string)" -msgstr "" +msgstr "ad_gpo_map_permit (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:930 msgid "" "A comma-separated list of PAM service names for which GPO-based access is " "always granted, regardless of any GPO Logon Rights." -msgstr "" +msgstr "無論任何 GPO 登入權限為何,一律授予 GPO 型存取的 PAM 服務名稱逗號分隔清單。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> #: sssd-ad.5.xml:944 @@ -11575,6 +13258,8 @@ msgid "" "ad_gpo_map_permit = +my_pam_service, -sudo\n" " " msgstr "" +"ad_gpo_map_permit = +my_pam_service, -sudo\n" +" " #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:935 @@ -11587,28 +13272,33 @@ msgid "" "(e.g. <quote>my_pam_service</quote>), you would use the following " "configuration: <placeholder type=\"programlisting\" id=\"0\"/>" msgstr "" +"可以使用 <quote>+service_name</quote> 將另一個 PAM 服務名稱加入預設集合,或使" +"用 <quote>-service_name</quote> 明確地從預設集合移除 PAM 服務名稱。例如,若要" +"將無條件允許存取的預設 PAM 服務名稱(例如 <quote>sudo</quote>)取代為自訂 " +"pam 服務名稱(例如 <quote>my_pam_service</quote>),您可以使用下列設定" +":<placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ad.5.xml:952 msgid "polkit-1" -msgstr "" +msgstr "polkit-1" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ad.5.xml:967 msgid "systemd-user" -msgstr "" +msgstr "systemd-user" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:976 msgid "ad_gpo_map_deny (string)" -msgstr "" +msgstr "ad_gpo_map_deny (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:979 msgid "" "A comma-separated list of PAM service names for which GPO-based access is " "always denied, regardless of any GPO Logon Rights." -msgstr "" +msgstr "無論任何 GPO 登入權限為何,一律拒絕 GPO 型存取的 PAM 服務名稱逗號分隔清單。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> #: sssd-ad.5.xml:992 @@ -11617,11 +13307,13 @@ msgid "" "ad_gpo_map_deny = +my_pam_service\n" " " msgstr "" +"ad_gpo_map_deny = +my_pam_service\n" +" " #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:1002 msgid "ad_gpo_default_right (string)" -msgstr "" +msgstr "ad_gpo_default_right (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:1005 @@ -11635,51 +13327,56 @@ msgid "" "settings. Alternatively, this option can be set to either always permit or " "always deny access for unmapped PAM service names." msgstr "" +"此選項定義如何為未明確列在任何 ad_gpo_map_* 選項中的 PAM 服務名稱評估存取控制" +"。此選項可以以兩種不同的方式設定。首先,此選項可以設為使用預設登入權限。例如" +",若此選項設為 'interactive',表示未對應的 PAM 服務名稱會根據 " +"InteractiveLogonRight 與 DenyInteractiveLogonRight 原則設定處理。另一種做法是" +",此選項可以設為一律允許或一律拒絕未對應 PAM 服務名稱的存取。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:1018 msgid "Supported values for this option include:" -msgstr "" +msgstr "此選項支援的值包括:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ad.5.xml:1027 msgid "remote_interactive" -msgstr "" +msgstr "remote_interactive" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ad.5.xml:1032 msgid "network" -msgstr "" +msgstr "network" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ad.5.xml:1037 msgid "batch" -msgstr "" +msgstr "batch" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ad.5.xml:1042 msgid "service" -msgstr "" +msgstr "service" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ad.5.xml:1047 msgid "permit" -msgstr "" +msgstr "permit" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ad.5.xml:1052 msgid "deny" -msgstr "" +msgstr "deny" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:1058 msgid "Default: deny" -msgstr "" +msgstr "預設:deny" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:1064 msgid "ad_maximum_machine_account_password_age (integer)" -msgstr "" +msgstr "ad_maximum_machine_account_password_age (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:1067 @@ -11688,16 +13385,18 @@ msgid "" "given age in days and try to renew it. A value of 0 will disable the renewal " "attempt." msgstr "" +"SSSD 每天會檢查一次電腦帳戶密碼是否超過指定的天數,並嘗試更新它。值 0 會停用" +"更新嘗試。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:1073 msgid "Default: 30 days" -msgstr "" +msgstr "預設:30 天" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:1079 msgid "ad_machine_account_password_renewal_opts (string)" -msgstr "" +msgstr "ad_machine_account_password_renewal_opts (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:1082 @@ -11708,16 +13407,19 @@ msgid "" "second specifies the initial timeout in seconds before the task is run for " "the first time after startup." msgstr "" +"此選項只應用於測試電腦帳戶更新工作。此選項預期 2 個以冒號 (':') 分隔的整數。" +"第一個整數定義工作執行的間隔(秒)。第二個指定啟動後第一次執行工作之前的初始" +"逾時(秒)。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:1091 msgid "Default: 86400:750 (24h and 15m)" -msgstr "" +msgstr "預設:86400:750(24 小時與 15 分鐘)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:1097 msgid "ad_update_samba_machine_account_password (boolean)" -msgstr "" +msgstr "ad_update_samba_machine_account_password (boolean)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:1100 @@ -11727,11 +13429,13 @@ msgid "" "account password from getting out of date when it is set up to use AD for " "authentication." msgstr "" +"若啟用,SSSD 更新電腦帳戶密碼時,也會更新 Samba 資料庫中的密碼。這可以防止設" +"定為使用 AD 驗證時,Samba 的電腦帳戶密碼副本過期。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:1113 msgid "ad_use_ldaps (bool)" -msgstr "" +msgstr "ad_use_ldaps (bool)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:1116 @@ -11743,11 +13447,15 @@ msgid "" "use SASL/GSSAPI or SASL/GSS-SPNEGO for authentication the SASL security " "property maxssf is set to 0 (zero) for those connections." msgstr "" +"預設情況下,SSSD 使用純文字 LDAP 連接埠 389 與全域目錄連接埠 3628。若此選項設" +"為 True,SSSD 會使用具有 LDAPS 保護的 LDAPS 連接埠 636 與全域目錄連接埠 3629" +"。由於 AD 不允許在單一連線上有多層加密,而我們仍希望使用 SASL/GSSAPI 或 SASL/" +"GSS-SPNEGO 進行驗證,因此這些連線的 SASL 安全性屬性 maxssf 會設為 0(零)。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:1133 msgid "ad_allow_remote_domain_local_groups (boolean)" -msgstr "" +msgstr "ad_allow_remote_domain_local_groups (boolean)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:1136 @@ -11759,6 +13467,10 @@ msgid "" "solutions which make AD users and groups available on Linux client this " "option was added." msgstr "" +"若此選項設為 <quote>true</quote>,SSSD 不會過濾掉 AD 樹系中遠端網域的網域本機" +"群組。預設會將它們過濾掉,例如追蹤遠端網域中的巢狀群組階層時,因為它們在網域" +"本機中無效。為了與其他讓 AD 使用者與群組在 Linux 用戶端上可用的解決方案相容," +"加入了此選項。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:1146 @@ -11774,6 +13486,12 @@ msgid "" "the Kerberos ticket for a local service or in tokenGroups requests where " "remote Domain Local groups are missing as well." msgstr "" +"請注意,將此選項設為 <quote>true</quote> 會違背 Active Directory 中網域本機群" +"組的用意,<emphasis>只應用於促成從其他解決方案遷移</emphasis>。雖然群組存在且" +"使用者可以是群組的成員,但用意是群組只應在其定義的網域中使用,而不應在其他網" +"域中使用。由於只有一種 POSIX 群組類型,要在 Linux 端達成這一點,唯一的方法是" +"忽略這些群組。Active Directory 也是這樣做的,這可以從本機服務 Kerberos 票證" +"的 PAC 中看到,或從 tokenGroups 要求中看到,其中也缺少遠端網域本機群組。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:1162 @@ -11787,6 +13505,12 @@ msgid "" "<quote>ldap_group_nesting_level</quote> if the remote Domain Local groups " "can only be found with a deeper nesting level." msgstr "" +"鑑於上述註解,若此選項設為 <quote>true</quote>,必須將 <quote>" +"ldap_use_tokengroups</quote> 設為 <quote>false</quote> 來停用 tokenGroups 要" +"求,才能取得一致的使用者群組成員資格。此外,也應將 <quote>ad_enable_gc</" +"quote> 設為 <quote>false</quote> 跳過全域目錄查詢。最後,若遠端網域本機群組只" +"能用更深的巢狀層級找到,可能有必要修改 <quote>ldap_group_nesting_level</" +"quote>。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:1185 @@ -11798,18 +13522,22 @@ msgid "" "AD LDAP connection is used for the updates, if it is not otherwise specified " "by using the <quote>dyndns_iface</quote> option." msgstr "" +"選用。此選項告訴 SSSD 自動以本用戶端的 IP 位址更新 Active Directory DNS 伺服" +"器。更新使用 GSS-TSIG 保護。因此,Active Directory 管理員只需要允許 DNS 區域" +"的安全更新。若未使用 <quote>dyndns_iface</quote> 選項另行指定,則使用 AD " +"LDAP 連線的 IP 位址進行更新。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:1215 msgid "Default: 3600 (seconds)" -msgstr "" +msgstr "預設:3600(秒)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:1231 msgid "" "Default: Use the IP addresses of the interface which is used for AD LDAP " "connection" -msgstr "" +msgstr "預設:使用用於 AD LDAP 連線之介面的 IP 位址" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:1244 @@ -11820,6 +13548,9 @@ msgid "" "lowest possible value is 60 seconds in-case if value is provided less than " "60, parameter will assume lowest value only." msgstr "" +"除了後端上線時執行的自動更新之外,後端應多久執行一次週期性 DNS 更新。此選項是" +"選用的,只在 dyndns_update 為 true 時適用。請注意,可能的最低值是 60 秒,若提" +"供的值低於 60,參數只會採用最低值。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ad.5.xml:1394 @@ -11828,6 +13559,8 @@ msgid "" "example.com is one of the domains in the <replaceable>[sssd]</replaceable> " "section. This example shows only the AD provider-specific options." msgstr "" +"下列範例假設 SSSD 已正確設定,且 example.com 是 <replaceable>[sssd]</" +"replaceable> 區段中的其中一個網域。此範例只顯示 AD 提供者專屬的選項。" #. type: Content of: <reference><refentry><refsect1><para><programlisting> #: sssd-ad.5.xml:1401 @@ -11843,6 +13576,15 @@ msgid "" "ad_hostname = client.example.com\n" "ad_domain = example.com\n" msgstr "" +"[domain/EXAMPLE]\n" +"id_provider = ad\n" +"auth_provider = ad\n" +"access_provider = ad\n" +"chpass_provider = ad\n" +"\n" +"ad_server = dc1.example.com\n" +"ad_hostname = client.example.com\n" +"ad_domain = example.com\n" #. type: Content of: <reference><refentry><refsect1><para><programlisting> #: sssd-ad.5.xml:1421 @@ -11852,6 +13594,9 @@ msgid "" "ldap_access_order = expire\n" "ldap_account_expire_policy = ad\n" msgstr "" +"access_provider = ldap\n" +"ldap_access_order = expire\n" +"ldap_account_expire_policy = ad\n" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ad.5.xml:1417 @@ -11860,6 +13605,8 @@ msgid "" "same effect as the following configuration of the LDAP provider: " "<placeholder type=\"programlisting\" id=\"0\"/>" msgstr "" +"AD 存取控制提供者檢查帳戶是否已到期。它與 LDAP 提供者的下列設定有相同的效果" +":<placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ad.5.xml:1427 @@ -11870,6 +13617,9 @@ msgid "" "you need to set all the connection parameters (such as LDAP URIs and " "encryption details) manually." msgstr "" +"不過,除非明確設定 <quote>ad</quote> 存取控制提供者,否則預設的 access 提供者" +"是 <quote>permit</quote>。請注意,若您設定 <quote>ad</quote> 以外的 access 提" +"供者,需要手動設定所有連線參數(例如 LDAP URI 與加密詳細資料)。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ad.5.xml:1435 @@ -11878,16 +13628,18 @@ msgid "" "attribute mapping (nisMap, nisObject, ...) is used, because these attributes " "are included in the default Active Directory schema." msgstr "" +"當 autofs 提供者設為 <quote>ad</quote> 時,會使用 RFC2307 綱要屬性對應(" +"nisMap、nisObject、...),因為這些屬性包含在預設的 Active Directory 綱要中。" #. type: Content of: <reference><refentry><refnamediv><refname> #: sssd-sudo.5.xml:10 sssd-sudo.5.xml:16 msgid "sssd-sudo" -msgstr "" +msgstr "sssd-sudo" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sssd-sudo.5.xml:17 msgid "Configuring sudo with the SSSD back end" -msgstr "" +msgstr "使用 SSSD 後端設定 sudo" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-sudo.5.xml:23 @@ -11897,11 +13649,15 @@ msgid "" "to work with <citerefentry> <refentrytitle>sssd</refentrytitle> " "<manvolnum>8</manvolnum> </citerefentry> and how SSSD caches sudo rules." msgstr "" +"本手冊頁說明如何設定 <citerefentry> <refentrytitle>sudo</refentrytitle> " +"<manvolnum>8</manvolnum> </citerefentry> 與 <citerefentry> <refentrytitle>" +"sssd</refentrytitle> <manvolnum>8</manvolnum> </citerefentry> 一起運作,以及 " +"SSSD 如何快取 sudo 規則。" #. type: Content of: <reference><refentry><refsect1><title> #: sssd-sudo.5.xml:36 msgid "Configuring sudo to cooperate with SSSD" -msgstr "" +msgstr "設定 sudo 與 SSSD 合作" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-sudo.5.xml:38 @@ -11911,6 +13667,9 @@ msgid "" "<refentrytitle>nsswitch.conf</refentrytitle> <manvolnum>5</manvolnum> " "</citerefentry>." msgstr "" +"若要啟用 SSSD 作為 sudo 規則的來源,請在 <citerefentry> <refentrytitle>" +"nsswitch.conf</refentrytitle> <manvolnum>5</manvolnum> </citerefentry> 中將 " +"<emphasis>sss</emphasis> 加入 <emphasis>sudoers</emphasis> 項目。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-sudo.5.xml:47 @@ -11921,12 +13680,16 @@ msgid "" "that apply to local users) and then in SSSD, the nsswitch.conf file should " "contain the following line:" msgstr "" +"例如,若要設定 sudo 先在標準 <citerefentry> <refentrytitle>sudoers</" +"refentrytitle> <manvolnum>5</manvolnum> </citerefentry> 檔案(應包含適用於本" +"機使用者的規則)中查詢規則,然後再在 SSSD 中查詢,nsswitch.conf 檔案應包含下" +"列這一行:" #. type: Content of: <reference><refentry><refsect1><para><programlisting> #: sssd-sudo.5.xml:57 #, no-wrap msgid "sudoers: files sss\n" -msgstr "" +msgstr "sudoers: files sss\n" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-sudo.5.xml:61 @@ -11937,6 +13700,10 @@ msgid "" "<refentrytitle>sudoers.ldap</refentrytitle> <manvolnum>5</manvolnum> " "</citerefentry>." msgstr "" +"有關從 nsswitch.conf 檔案設定 sudoers 搜尋順序的更多資訊,以及用於在目錄中儲" +"存 sudo 規則之 LDAP 綱要的資訊,可以在 <citerefentry> <refentrytitle>" +"sudoers.ldap</refentrytitle> <manvolnum>5</manvolnum> </citerefentry> 中找到" +"。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-sudo.5.xml:70 @@ -11947,11 +13714,15 @@ msgid "" "</citerefentry> to your NIS domain name (which equals to IPA domain name " "when using hostgroups)." msgstr "" +"<emphasis>注意</emphasis>:若要在 sudo 規則中使用 netgroup 或 IPA hostgroup," +"您還需要將 <citerefentry> <refentrytitle>nisdomainname</refentrytitle> " +"<manvolnum>1</manvolnum> </citerefentry> 正確設為您的 NIS 網域名稱(使用 " +"hostgroup 時等於 IPA 網域名稱)。" #. type: Content of: <reference><refentry><refsect1><title> #: sssd-sudo.5.xml:82 msgid "Configuring SSSD to fetch sudo rules" -msgstr "" +msgstr "設定 SSSD 取回 sudo 規則" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-sudo.5.xml:84 @@ -11963,13 +13734,18 @@ msgid "" "can also set search base for sudo rules using " "<emphasis>ldap_sudo_search_base</emphasis> option." msgstr "" +"SSSD 端需要的所有設定,就是在 <citerefentry> <refentrytitle>sssd.conf</" +"refentrytitle> <manvolnum>5</manvolnum> </citerefentry> 的 [sssd] 區段中,以 " +"\"sudo\" 擴充 <emphasis>services</emphasis> 清單。若要加速 LDAP 查詢,您也可" +"以使用 <emphasis>ldap_sudo_search_base</emphasis> 選項設定 sudo 規則的搜尋基" +"礎。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-sudo.5.xml:94 msgid "" "The following example shows how to configure SSSD to download sudo rules " "from an LDAP server." -msgstr "" +msgstr "下列範例顯示如何設定 SSSD 從 LDAP 伺服器下載 sudo 規則。" #. type: Content of: <reference><refentry><refsect1><para><programlisting> #: sssd-sudo.5.xml:99 @@ -11985,6 +13761,15 @@ msgid "" "ldap_uri = ldap://example.com\n" "ldap_sudo_search_base = ou=sudoers,dc=example,dc=com\n" msgstr "" +"[sssd]\n" +"services = nss, pam, sudo\n" +"domains = EXAMPLE\n" +"\n" +"[domain/EXAMPLE]\n" +"id_provider = ldap\n" +"sudo_provider = ldap\n" +"ldap_uri = ldap://example.com\n" +"ldap_sudo_search_base = ou=sudoers,dc=example,dc=com\n" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-sudo.5.xml:98 @@ -11995,6 +13780,10 @@ msgid "" "list of services, as it became optional. However, sssd-sudo.socket must be " "enabled instead. </phrase>" msgstr "" +"<placeholder type=\"programlisting\" id=\"0\"/> <phrase " +"condition=\"have_systemd\"> 請務必注意,在支援 systemd 的平台上,不需要將 " +"\"sudo\" 提供者加入服務清單,因為它已變成選用的。不過,必須改為啟用 sssd-" +"sudo.socket。 </phrase>" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-sudo.5.xml:117 @@ -12005,11 +13794,15 @@ msgid "" "sssd.conf, this value will be used instead. The compat tree " "(ou=sudoers,$SUFFIX) is no longer required for IPA sudo functionality." msgstr "" +"當 SSSD 設定為使用 IPA 作為 ID 提供者時,sudo 提供者會自動啟用。sudo 搜尋基礎" +"設定為使用 IPA 原生 LDAP 樹 (cn=sudo,$SUFFIX)。若在 sssd.conf 中定義了任何其" +"他搜尋基礎,則改用該值。IPA sudo 功能不再需要 compat 樹 (ou=sudoers,$SUFFIX)" +"。" #. type: Content of: <reference><refentry><refsect1><title> #: sssd-sudo.5.xml:127 msgid "The SUDO rule caching mechanism" -msgstr "" +msgstr "SUDO 規則快取機制" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-sudo.5.xml:129 @@ -12021,6 +13814,10 @@ msgid "" "of updates. They are referred to as full refresh, smart refresh and rules " "refresh." msgstr "" +"在 SSSD 中開發 sudo 支援時最大的挑戰,是確保以 SSSD 作為資料來源執行 sudo 時" +",提供與 sudo 相同的使用者體驗與速度,同時盡可能持續提供最新的規則集。為滿足" +"這些要求,SSSD 使用三種更新。它們被稱為完整重新整理、智慧型重新整理與規則重新" +"整理。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-sudo.5.xml:137 @@ -12030,6 +13827,8 @@ msgid "" "database growing by fetching only small increments that do not generate " "large amounts of network traffic." msgstr "" +"<emphasis>智慧型重新整理</emphasis>會定期下載新的或上次更新後修改過的規則。它" +"的主要目標是只取回不會產生大量網路流量的少量增量,讓資料庫持續成長。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-sudo.5.xml:143 @@ -12041,6 +13840,10 @@ msgid "" "of traffic and thus it should be run only occasionally depending on the size " "and stability of the sudo rules." msgstr "" +"<emphasis>完整重新整理</emphasis>只會刪除快取中儲存的所有 sudo 規則,並以伺服" +"器上儲存的所有規則取代。這用來移除每個已從伺服器刪除的規則,以保持快取一致。" +"不過,完整重新整理可能產生大量流量,因此視 sudo 規則的大小與穩定性,應該只偶" +"爾執行。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-sudo.5.xml:151 @@ -12053,6 +13856,10 @@ msgid "" "refresh because more rules (that apply to other users) may have been " "deleted." msgstr "" +"<emphasis>規則重新整理</emphasis>確保我們不會授予使用者超出定義的權限。它會在" +"使用者每次執行 sudo 時觸發。規則重新整理會找出適用於此使用者的所有規則,檢查" +"它們的到期時間,若已到期則重新下載。若其中任何規則在伺服器上遺失,SSSD 會執行" +"帶外完整重新整理,因為可能有更多規則(適用於其他使用者的規則)已被刪除。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-sudo.5.xml:160 @@ -12061,36 +13868,38 @@ msgid "" "machine. This means rules that contain one of the following values in " "<emphasis>sudoHost</emphasis> attribute:" msgstr "" +"若啟用,SSSD 只會儲存可以套用於此機器的規則。這表示 <emphasis>sudoHost</" +"emphasis> 屬性中包含下列值之一的規則:" #. type: Content of: <reference><refentry><refsect1><itemizedlist><listitem><para> #: sssd-sudo.5.xml:167 msgid "keyword ALL" -msgstr "" +msgstr "關鍵字 ALL" #. type: Content of: <reference><refentry><refsect1><itemizedlist><listitem><para> #: sssd-sudo.5.xml:172 msgid "wildcard" -msgstr "" +msgstr "萬用字元" #. type: Content of: <reference><refentry><refsect1><itemizedlist><listitem><para> #: sssd-sudo.5.xml:177 msgid "netgroup (in the form \"+netgroup\")" -msgstr "" +msgstr "netgroup(形式為 \"+netgroup\")" #. type: Content of: <reference><refentry><refsect1><itemizedlist><listitem><para> #: sssd-sudo.5.xml:182 msgid "hostname or fully qualified domain name of this machine" -msgstr "" +msgstr "此機器的主機名稱或完整網域名稱" #. type: Content of: <reference><refentry><refsect1><itemizedlist><listitem><para> #: sssd-sudo.5.xml:187 msgid "one of the IP addresses of this machine" -msgstr "" +msgstr "此機器的其中一個 IP 位址" #. type: Content of: <reference><refentry><refsect1><itemizedlist><listitem><para> #: sssd-sudo.5.xml:192 msgid "one of the IP addresses of the network (in the form \"address/mask\")" -msgstr "" +msgstr "網路的其中一個 IP 位址(形式為 \"address/mask\")" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-sudo.5.xml:198 @@ -12102,11 +13911,15 @@ msgid "" "<refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</manvolnum> " "</citerefentry>." msgstr "" +"有許多設定選項可以用來調整行為。請參閱 <citerefentry> <refentrytitle>sssd-" +"ldap</refentrytitle> <manvolnum>5</manvolnum> </citerefentry> 中的 " +"\"ldap_sudo_*\" 與 <citerefentry> <refentrytitle>sssd.conf</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry> 中的 \"sudo_*\"。" #. type: Content of: <reference><refentry><refsect1><title> #: sssd-sudo.5.xml:212 msgid "Tuning the performance" -msgstr "" +msgstr "調整效能" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-sudo.5.xml:214 @@ -12117,6 +13930,9 @@ msgid "" "paragraphs contain few tips on how to fine- tune the configuration to your " "requirements." msgstr "" +"SSSD 使用不同種類、複雜度不一的 LDAP 篩選器機制來保持快取的 sudo 規則為最新。" +"預設設定為應能滿足大多數使用者的值,但下列段落包含一些如何將設定微調為符合您" +"需求的秘訣。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-sudo.5.xml:221 @@ -12124,6 +13940,8 @@ msgid "" "1. <emphasis>Index LDAP attributes</emphasis>. Make sure that following LDAP " "attributes are indexed: objectClass, cn, entryUSN or modifyTimestamp." msgstr "" +"1. <emphasis>為 LDAP 屬性建立索引</emphasis>。請確定下列 LDAP 屬性已建立索引" +":objectClass、cn、entryUSN 或 modifyTimestamp。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-sudo.5.xml:226 @@ -12131,6 +13949,8 @@ msgid "" "2. <emphasis>Set ldap_sudo_search_base</emphasis>. Set the search base to " "the container that holds the sudo rules to limit the scope of the lookup." msgstr "" +"2. <emphasis>設定 ldap_sudo_search_base</emphasis>。將搜尋基礎設為保存 sudo " +"規則的容器,以限制查詢的範圍。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-sudo.5.xml:231 @@ -12143,6 +13963,11 @@ msgid "" "disabling the smart refresh by setting " "<emphasis>ldap_sudo_smart_refresh_interval = 0</emphasis>." msgstr "" +"3. <emphasis>設定完整與智慧型重新整理間隔</emphasis>。若您的 sudo 規則不常變" +"更,且不需要用戶端上的快取規則快速更新,可以考慮增加 <emphasis>" +"ldap_sudo_full_refresh_interval</emphasis> 與 <emphasis>" +"ldap_sudo_smart_refresh_interval</emphasis>。也可以考慮將 <emphasis>" +"ldap_sudo_smart_refresh_interval = 0</emphasis> 來停用智慧型重新整理。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-sudo.5.xml:240 @@ -12151,16 +13976,18 @@ msgid "" "value of <emphasis>ldap_sudo_random_offset</emphasis> to distribute the load " "on the server better." msgstr "" +"4. 若您有大量的用戶端,可以考慮增加 <emphasis>ldap_sudo_random_offset</" +"emphasis> 的值,以更均勻地分散伺服器上的負載。" #. type: Content of: <reference><refentry><refnamediv><refname> #: sssd.8.xml:10 sssd.8.xml:15 msgid "sssd" -msgstr "" +msgstr "sssd" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sssd.8.xml:16 msgid "System Security Services Daemon" -msgstr "" +msgstr "系統安全服務精靈" #. type: Content of: <reference><refentry><refsynopsisdiv><cmdsynopsis> #: sssd.8.xml:21 @@ -12168,6 +13995,8 @@ msgid "" "<command>sssd</command> <arg choice='opt'> " "<replaceable>options</replaceable> </arg>" msgstr "" +"<command>sssd</command> <arg choice='opt'> <replaceable>options</" +"replaceable> </arg>" #. type: Content of: <reference><refentry><refsect1><para> #: sssd.8.xml:31 @@ -12180,6 +14009,10 @@ msgid "" "FreeIPA. It provides a more robust database to store local users as well as " "extended user data." msgstr "" +"<command>SSSD</command> 提供一組精靈來管理對遠端目錄與驗證機制的存取。它向系" +"統提供 NSS 與 PAM 介面,以及連線到多個不同帳戶來源的可插拔後端系統,還有 D-" +"Bus 介面。它也是為 FreeIPA 之類的專案提供用戶端稽核與原則服務的基礎。它提供更" +"穩固的資料庫來儲存本機使用者與延伸使用者資料。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.8.xml:46 @@ -12187,53 +14020,55 @@ msgid "" "<option>-d</option>,<option>--debug-level</option> " "<replaceable>LEVEL</replaceable>" msgstr "" +"<option>-d</option>,<option>--debug-level</option> <replaceable>LEVEL</" +"replaceable>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.8.xml:53 msgid "<option>--debug-timestamps=</option><replaceable>mode</replaceable>" -msgstr "" +msgstr "<option>--debug-timestamps=</option><replaceable>mode</replaceable>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.8.xml:57 msgid "<emphasis>1</emphasis>: Add a timestamp to the debug messages" -msgstr "" +msgstr "<emphasis>1</emphasis>:在除錯訊息中加入時間戳記" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.8.xml:60 msgid "<emphasis>0</emphasis>: Disable timestamp in the debug messages" -msgstr "" +msgstr "<emphasis>0</emphasis>:停用除錯訊息中的時間戳記" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.8.xml:69 msgid "<option>--debug-microseconds=</option><replaceable>mode</replaceable>" -msgstr "" +msgstr "<option>--debug-microseconds=</option><replaceable>mode</replaceable>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.8.xml:73 msgid "<emphasis>1</emphasis>: Add microseconds to the timestamp in debug messages" -msgstr "" +msgstr "<emphasis>1</emphasis>:在除錯訊息中的時間戳記加入微秒" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.8.xml:76 msgid "<emphasis>0</emphasis>: Disable microseconds in timestamp" -msgstr "" +msgstr "<emphasis>0</emphasis>:停用時間戳記中的微秒" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.8.xml:85 msgid "<option>--logger=</option><replaceable>value</replaceable>" -msgstr "" +msgstr "<option>--logger=</option><replaceable>value</replaceable>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.8.xml:89 msgid "Location where SSSD will send log messages." -msgstr "" +msgstr "SSSD 傳送記錄訊息的位置。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.8.xml:92 msgid "" "<emphasis>stderr</emphasis>: Redirect debug messages to standard error " "output." -msgstr "" +msgstr "<emphasis>stderr</emphasis>:將除錯訊息重新導向到標準錯誤輸出。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.8.xml:96 @@ -12242,41 +14077,44 @@ msgid "" "default, the log files are stored in <filename>/var/log/sssd</filename> and " "there are separate log files for every SSSD service and domain." msgstr "" +"<emphasis>files</emphasis>:將除錯訊息重新導向到記錄檔。預設情況下,記錄檔儲" +"存在 <filename>/var/log/sssd</filename>,每個 SSSD 服務與網域都有各自的記錄檔" +"。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.8.xml:102 msgid "<emphasis>journald</emphasis>: Redirect debug messages to systemd-journald" -msgstr "" +msgstr "<emphasis>journald</emphasis>:將除錯訊息重新導向到 systemd-journald" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.8.xml:106 msgid "Default: not set (fall back to journald if available, otherwise to stderr)" -msgstr "" +msgstr "預設:未設定(若可用則退回 journald,否則退回 stderr)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.8.xml:113 msgid "<option>-D</option>,<option>--daemon</option>" -msgstr "" +msgstr "<option>-D</option>,<option>--daemon</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.8.xml:117 msgid "Become a daemon after starting up." -msgstr "" +msgstr "啟動後變成精靈。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.8.xml:123 sss_seed.8.xml:136 msgid "<option>-i</option>,<option>--interactive</option>" -msgstr "" +msgstr "<option>-i</option>,<option>--interactive</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.8.xml:127 msgid "Run in the foreground, don't become a daemon." -msgstr "" +msgstr "在前景執行,不要變成精靈。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.8.xml:133 msgid "<option>-c</option>,<option>--config</option>" -msgstr "" +msgstr "<option>-c</option>,<option>--config</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.8.xml:137 @@ -12287,38 +14125,41 @@ msgid "" "<refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</manvolnum> " "</citerefentry> manual page." msgstr "" +"指定非預設的設定檔。預設為 <filename>/etc/sssd/sssd.conf</filename>。設定檔語" +"法與選項的參考請參閱 <citerefentry> <refentrytitle>sssd.conf</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry> 手冊頁。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.8.xml:151 msgid "<option>--version</option>" -msgstr "" +msgstr "<option>--version</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.8.xml:155 msgid "Print version number and exit." -msgstr "" +msgstr "列印版本號碼並結束。" #. type: Content of: <reference><refentry><refsect1><title> #: sssd.8.xml:163 msgid "Signals" -msgstr "" +msgstr "訊號" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.8.xml:166 msgid "SIGTERM/SIGINT" -msgstr "" +msgstr "SIGTERM/SIGINT" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.8.xml:169 msgid "" "Informs the SSSD to gracefully terminate all of its child processes and then " "shut down the monitor." -msgstr "" +msgstr "告知 SSSD 正常終止其所有子程序,然後關閉監控器。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.8.xml:175 msgid "SIGHUP" -msgstr "" +msgstr "SIGHUP" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.8.xml:178 @@ -12327,11 +14168,13 @@ msgid "" "close and reopen them. This is meant to facilitate log rolling with programs " "like logrotate." msgstr "" +"告訴 SSSD 停止寫入目前的除錯檔案描述符,並關閉與重新開啟它們。這是為了方便使" +"用 logrotate 之類的程式進行記錄輪替。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.8.xml:186 msgid "SIGUSR1" -msgstr "" +msgstr "SIGUSR1" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.8.xml:189 @@ -12341,11 +14184,13 @@ msgid "" "signal can be sent to either the sssd process or any sssd_be process " "directly." msgstr "" +"告訴 SSSD 在 <quote>offline_timeout</quote> 參數的期間模擬離線作業。這對測試" +"很有用。此訊號可以直接傳送到 sssd 程序或任何 sssd_be 程序。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.8.xml:198 msgid "SIGUSR2" -msgstr "" +msgstr "SIGUSR2" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.8.xml:201 @@ -12354,11 +14199,13 @@ msgid "" "signal can be sent to either the sssd process or any sssd_be process " "directly." msgstr "" +"告訴 SSSD 立即上線。這對測試很有用。此訊號可以直接傳送到 sssd 程序或任何 " +"sssd_be 程序。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.8.xml:208 msgid "SIGRTMIN+1" -msgstr "" +msgstr "SIGRTMIN+1" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.8.xml:211 @@ -12367,58 +14214,60 @@ msgid "" "this signal to the providers when a clock shift is detected although it can " "be sent to any sssd_be process directly." msgstr "" +"告訴 SSSD 重新排定週期性工作。內部監看程式在偵測到時鐘偏移時會將此訊號傳送給" +"提供者,雖然它可以直接傳送到任何 sssd_be 程序。" #. type: Content of: <reference><refentry><refsect1><title> #: sssd.8.xml:223 sss_ssh_authorizedkeys.1.xml:141 sss_ssh_knownhosts.1.xml:113 #: sss_ssh_knownhostsproxy.1.xml:112 msgid "EXIT STATUS" -msgstr "" +msgstr "結束狀態" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.8.xml:226 msgid "0" -msgstr "" +msgstr "0" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.8.xml:229 msgid "SSSD was shutdown gracefully." -msgstr "" +msgstr "SSSD 已正常關閉。" #. type: Content of: <reference><refentry><refmeta><manvolnum> #: sssd.8.xml:234 sss_ssh_authorizedkeys.1.xml:11 sss_ssh_knownhosts.1.xml:11 #: sss_ssh_knownhostsproxy.1.xml:11 msgid "1" -msgstr "" +msgstr "1" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.8.xml:237 msgid "Bad configuration or command line option." -msgstr "" +msgstr "設定或命令列選項不正確。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.8.xml:242 msgid "2" -msgstr "" +msgstr "2" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.8.xml:245 msgid "Memory allocation error." -msgstr "" +msgstr "記憶體配置錯誤。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.8.xml:250 msgid "6" -msgstr "" +msgstr "6" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.8.xml:253 msgid "SSSD is already running." -msgstr "" +msgstr "SSSD 已在執行。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.8.xml:258 msgid "Other codes" -msgstr "" +msgstr "其他代碼" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.8.xml:261 @@ -12426,6 +14275,8 @@ msgid "" "Other codes denote different errors, most probably about missing required " "access rights. See SSSD and system logs for details." msgstr "" +"其他代碼表示不同的錯誤,最可能與缺少所需的存取權限有關。詳情請參閱 SSSD 與系" +"統記錄。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd.8.xml:272 @@ -12433,23 +14284,25 @@ msgid "" "If the environment variable SSS_NSS_USE_MEMCACHE is set to \"NO\", client " "applications will not use the fast in-memory cache." msgstr "" +"若 SSS_NSS_USE_MEMCACHE 環境變數設為 \"NO\",用戶端應用程式將不會使用快速的記" +"憶體內快取。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd.8.xml:276 msgid "" "If the environment variable SSS_LOCKFREE is set to \"NO\", requests from " "multiple threads of a single application will be serialized." -msgstr "" +msgstr "若 SSS_LOCKFREE 環境變數設為 \"NO\",單一應用程式多個執行緒的要求會被序列化。" #. type: Content of: <reference><refentry><refnamediv><refname> #: sss_obfuscate.8.xml:10 sss_obfuscate.8.xml:15 msgid "sss_obfuscate" -msgstr "" +msgstr "sss_obfuscate" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sss_obfuscate.8.xml:16 msgid "obfuscate a clear text password" -msgstr "" +msgstr "混淆明文密碼" #. type: Content of: <reference><refentry><refsynopsisdiv><cmdsynopsis> #: sss_obfuscate.8.xml:21 @@ -12458,6 +14311,9 @@ msgid "" "<replaceable>options</replaceable> </arg> <arg " "choice='plain'><replaceable>[PASSWORD]</replaceable></arg>" msgstr "" +"<command>sss_obfuscate</command> <arg choice='opt'> <replaceable>options</" +"replaceable> </arg> <arg choice='plain'><replaceable>[PASSWORD]</replaceable>" +"</arg>" #. type: Content of: <reference><refentry><refsect1><para> #: sss_obfuscate.8.xml:32 @@ -12466,6 +14322,8 @@ msgid "" "human-unreadable format and places it into appropriate domain section of the " "SSSD config file." msgstr "" +"<command>sss_obfuscate</command> 將給定的密碼轉換為人類無法閱讀的格式,並將它" +"放入 SSSD 設定檔的適當網域區段。" #. type: Content of: <reference><refentry><refsect1><para> #: sss_obfuscate.8.xml:37 @@ -12478,6 +14336,11 @@ msgid "" "<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> " "</citerefentry> for more details on these parameters." msgstr "" +"明文密碼從標準輸入讀取或以互動方式輸入。混淆的密碼會放入給定 SSSD 網域的 " +"<quote>ldap_default_authtok</quote> 參數,且 <quote>" +"ldap_default_authtok_type</quote> 參數會設為 <quote>obfuscated_password</" +"quote>。這些參數的更多詳細資料請參閱 <citerefentry> <refentrytitle>sssd-" +"ldap</refentrytitle> <manvolnum>5</manvolnum> </citerefentry>。" #. type: Content of: <reference><refentry><refsect1><para> #: sss_obfuscate.8.xml:49 @@ -12488,16 +14351,19 @@ msgid "" "such as client side certificates or GSSAPI is <emphasis>strongly</emphasis> " "advised." msgstr "" +"請注意,混淆密碼<emphasis>沒有真正的安全性效益</emphasis>,因為攻擊者仍然可以" +"逆向工程還原密碼。<emphasis>強烈</emphasis>建議使用更好的驗證機制,例如用戶端" +"憑證或 GSSAPI。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_obfuscate.8.xml:63 msgid "<option>-s</option>,<option>--stdin</option>" -msgstr "" +msgstr "<option>-s</option>,<option>--stdin</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_obfuscate.8.xml:67 msgid "The password to obfuscate will be read from standard input." -msgstr "" +msgstr "要混淆的密碼會從標準輸入讀取。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_obfuscate.8.xml:74 sss_ssh_authorizedkeys.1.xml:127 @@ -12506,38 +14372,41 @@ msgid "" "<option>-d</option>,<option>--domain</option> " "<replaceable>DOMAIN</replaceable>" msgstr "" +"<option>-d</option>,<option>--domain</option> <replaceable>DOMAIN</" +"replaceable>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_obfuscate.8.xml:79 msgid "" "The SSSD domain to use the password in. The default name is " "<quote>default</quote>." -msgstr "" +msgstr "要使用密碼的 SSSD 網域。預設名稱為 <quote>default</quote>。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_obfuscate.8.xml:86 msgid "<option>-f</option>,<option>--file</option> <replaceable>FILE</replaceable>" msgstr "" +"<option>-f</option>,<option>--file</option> <replaceable>FILE</replaceable>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_obfuscate.8.xml:91 msgid "Read the config file specified by the positional parameter." -msgstr "" +msgstr "讀取位置參數指定的設定檔。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_obfuscate.8.xml:95 msgid "Default: <filename>/etc/sssd/sssd.conf</filename>" -msgstr "" +msgstr "預設:<filename>/etc/sssd/sssd.conf</filename>" #. type: Content of: <reference><refentry><refnamediv><refname> #: sss_override.8.xml:10 sss_override.8.xml:15 msgid "sss_override" -msgstr "" +msgstr "sss_override" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sss_override.8.xml:16 msgid "create local overrides of user and group attributes" -msgstr "" +msgstr "建立使用者與群組屬性的本機覆寫" #. type: Content of: <reference><refentry><refsynopsisdiv><cmdsynopsis> #: sss_override.8.xml:21 @@ -12546,6 +14415,9 @@ msgid "" "choice='plain'><replaceable>COMMAND</replaceable></arg> <arg choice='opt'> " "<replaceable>options</replaceable> </arg>" msgstr "" +"<command>sss_override</command> <arg choice='plain'><replaceable>COMMAND</" +"replaceable></arg> <arg choice='opt'> <replaceable>options</replaceable> </" +"arg>" #. type: Content of: <reference><refentry><refsect1><para> #: sss_override.8.xml:32 @@ -12554,6 +14426,8 @@ msgid "" "allows to change selected values of specific user and groups. This change " "takes effect only on local machine." msgstr "" +"<command>sss_override</command> 可以建立用戶端檢視,並允許變更特定使用者與群" +"組的選定值。此變更只在本機機器上生效。" #. type: Content of: <reference><refentry><refsect1><para> #: sss_override.8.xml:37 @@ -12566,6 +14440,11 @@ msgid "" "take effect. <emphasis>sss_override</emphasis> prints message when a " "restart is required." msgstr "" +"覆寫資料儲存在 SSSD 快取中。若刪除快取,所有本機覆寫都會遺失。請注意,使用下" +"列任何指令 <emphasis>user-add</emphasis>、<emphasis>group-add</emphasis>" +"、<emphasis>user-import</emphasis> 或 <emphasis>group-import</emphasis> 建立" +"第一個覆寫之後,SSSD 需要重新啟動才會生效。<emphasis>sss_override</emphasis> " +"在需要重新啟動時會列印訊息。" #. type: Content of: <reference><refentry><refsect1><para> #: sss_override.8.xml:48 @@ -12575,11 +14454,14 @@ msgid "" "id_provider</quote>. IPA overrides can be managed centrally on the IPA " "server." msgstr "" +"<emphasis>注意:</emphasis>本手冊頁提供的選項只適用於 <quote>ldap</quote> 與 " +"<quote>AD</quote> <quote> id_provider</quote>。IPA 覆寫可以在 IPA 伺服器上集" +"中管理。" #. type: Content of: <reference><refentry><refsect1><title> #: sss_override.8.xml:56 sssctl.8.xml:41 msgid "AVAILABLE COMMANDS" -msgstr "" +msgstr "可用的指令" #. type: Content of: <reference><refentry><refsect1><para> #: sss_override.8.xml:58 @@ -12588,6 +14470,8 @@ msgid "" "commands. It is not possible to override <emphasis>uid</emphasis> or " "<emphasis>gid</emphasis> to 0." msgstr "" +"在所有指令中,<emphasis>NAME</emphasis> 參數是原始物件的名稱。無法將 " +"<emphasis>uid</emphasis> 或 <emphasis>gid</emphasis> 覆寫為 0。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_override.8.xml:65 @@ -12602,18 +14486,25 @@ msgid "" "<optional><option>-x,--certificate</option> BASE64 ENCODED " "CERTIFICATE</optional>" msgstr "" +"<option>user-add</option> <emphasis>NAME</emphasis> <optional><option>-n,--" +"name</option> NAME</optional> <optional><option>-u,--uid</option> UID</" +"optional> <optional><option>-g,--gid</option> GID</optional> <optional>" +"<option>-h,--home</option> HOME</optional> <optional><option>-s,--shell</" +"option> SHELL</optional> <optional><option>-c,--gecos</option> GECOS</" +"optional> <optional><option>-x,--certificate</option> BASE64 ENCODED " +"CERTIFICATE</optional>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_override.8.xml:78 msgid "" "Override attributes of an user. Please be aware that calling this command " "will replace any previous override for the (NAMEd) user." -msgstr "" +msgstr "覆寫使用者的屬性。請注意,呼叫此指令會取代 (NAMEd) 使用者先前任何的覆寫。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_override.8.xml:86 msgid "<option>user-del</option> <emphasis>NAME</emphasis>" -msgstr "" +msgstr "<option>user-del</option> <emphasis>NAME</emphasis>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_override.8.xml:91 @@ -12622,6 +14513,8 @@ msgid "" "returned from memory cache. Please see SSSD option " "<emphasis>memcache_timeout</emphasis> for more details." msgstr "" +"移除使用者覆寫。不過請注意,記憶體快取可能仍會傳回已覆寫的屬性。更多詳細資料" +"請參閱 SSSD 選項 <emphasis>memcache_timeout</emphasis>。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_override.8.xml:100 @@ -12629,6 +14522,8 @@ msgid "" "<option>user-find</option> <optional><option>-d,--domain</option> " "DOMAIN</optional>" msgstr "" +"<option>user-find</option> <optional><option>-d,--domain</option> DOMAIN</" +"optional>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_override.8.xml:105 @@ -12636,21 +14531,23 @@ msgid "" "List all users with set overrides. If <emphasis>DOMAIN</emphasis> parameter " "is set, only users from the domain are listed." msgstr "" +"列出所有已設定覆寫的使用者。若設定 <emphasis>DOMAIN</emphasis> 參數,只會列出" +"該網域的使用者。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_override.8.xml:113 msgid "<option>user-show</option> <emphasis>NAME</emphasis>" -msgstr "" +msgstr "<option>user-show</option> <emphasis>NAME</emphasis>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_override.8.xml:118 msgid "Show user overrides." -msgstr "" +msgstr "顯示使用者覆寫。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_override.8.xml:124 msgid "<option>user-import</option> <emphasis>FILE</emphasis>" -msgstr "" +msgstr "<option>user-import</option> <emphasis>FILE</emphasis>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_override.8.xml:129 @@ -12658,11 +14555,13 @@ msgid "" "Import user overrides from <emphasis>FILE</emphasis>. Data format is " "similar to standard passwd file. The format is:" msgstr "" +"從 <emphasis>FILE</emphasis> 匯入使用者覆寫。資料格式類似標準 passwd 檔案。格" +"式為:" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_override.8.xml:134 msgid "original_name:name:uid:gid:gecos:home:shell:base64_encoded_certificate" -msgstr "" +msgstr "original_name:name:uid:gid:gecos:home:shell:base64_encoded_certificate" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_override.8.xml:137 @@ -12671,21 +14570,23 @@ msgid "" "overridden. The rest of fields correspond to new values. You can omit a " "value simply by leaving corresponding field empty." msgstr "" +"其中 original_name 是要覆寫屬性之使用者的原始名稱。其餘欄位對應新值。您可以直" +"接留空對應欄位來省略值。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_override.8.xml:146 msgid "ckent:superman::::::" -msgstr "" +msgstr "ckent:superman::::::" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_override.8.xml:149 msgid "ckent@krypton.com::501:501:Superman:/home/earth:/bin/bash:" -msgstr "" +msgstr "ckent@krypton.com::501:501:Superman:/home/earth:/bin/bash:" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_override.8.xml:155 msgid "<option>user-export</option> <emphasis>FILE</emphasis>" -msgstr "" +msgstr "<option>user-export</option> <emphasis>FILE</emphasis>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_override.8.xml:160 @@ -12694,6 +14595,8 @@ msgid "" "<emphasis>FILE</emphasis>. See <emphasis>user-import</emphasis> for data " "format." msgstr "" +"匯出所有已覆寫的屬性,並將它們儲存在 <emphasis>FILE</emphasis>。資料格式請參" +"閱 <emphasis>user-import</emphasis>。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_override.8.xml:168 @@ -12702,18 +14605,21 @@ msgid "" "<optional><option>-n,--name</option> NAME</optional> " "<optional><option>-g,--gid</option> GID</optional>" msgstr "" +"<option>group-add</option> <emphasis>NAME</emphasis> <optional><option>-n,--" +"name</option> NAME</optional> <optional><option>-g,--gid</option> GID</" +"optional>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_override.8.xml:175 msgid "" "Override attributes of a group. Please be aware that calling this command " "will replace any previous override for the (NAMEd) group." -msgstr "" +msgstr "覆寫群組的屬性。請注意,呼叫此指令會取代 (NAMEd) 群組先前任何的覆寫。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_override.8.xml:183 msgid "<option>group-del</option> <emphasis>NAME</emphasis>" -msgstr "" +msgstr "<option>group-del</option> <emphasis>NAME</emphasis>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_override.8.xml:188 @@ -12722,6 +14628,8 @@ msgid "" "returned from memory cache. Please see SSSD option " "<emphasis>memcache_timeout</emphasis> for more details." msgstr "" +"移除群組覆寫。不過請注意,記憶體快取可能仍會傳回已覆寫的屬性。更多詳細資料請" +"參閱 SSSD 選項 <emphasis>memcache_timeout</emphasis>。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_override.8.xml:197 @@ -12729,6 +14637,8 @@ msgid "" "<option>group-find</option> <optional><option>-d,--domain</option> " "DOMAIN</optional>" msgstr "" +"<option>group-find</option> <optional><option>-d,--domain</option> DOMAIN</" +"optional>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_override.8.xml:202 @@ -12736,21 +14646,23 @@ msgid "" "List all groups with set overrides. If <emphasis>DOMAIN</emphasis> " "parameter is set, only groups from the domain are listed." msgstr "" +"列出所有已設定覆寫的群組。若設定 <emphasis>DOMAIN</emphasis> 參數,只會列出該" +"網域的群組。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_override.8.xml:210 msgid "<option>group-show</option> <emphasis>NAME</emphasis>" -msgstr "" +msgstr "<option>group-show</option> <emphasis>NAME</emphasis>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_override.8.xml:215 msgid "Show group overrides." -msgstr "" +msgstr "顯示群組覆寫。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_override.8.xml:221 msgid "<option>group-import</option> <emphasis>FILE</emphasis>" -msgstr "" +msgstr "<option>group-import</option> <emphasis>FILE</emphasis>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_override.8.xml:226 @@ -12758,11 +14670,13 @@ msgid "" "Import group overrides from <emphasis>FILE</emphasis>. Data format is " "similar to standard group file. The format is:" msgstr "" +"從 <emphasis>FILE</emphasis> 匯入群組覆寫。資料格式類似標準 group 檔案。格式" +"為:" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_override.8.xml:231 msgid "original_name:name:gid" -msgstr "" +msgstr "original_name:name:gid" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_override.8.xml:234 @@ -12771,21 +14685,23 @@ msgid "" "overridden. The rest of fields correspond to new values. You can omit a " "value simply by leaving corresponding field empty." msgstr "" +"其中 original_name 是要覆寫屬性之群組的原始名稱。其餘欄位對應新值。您可以直接" +"留空對應欄位來省略值。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_override.8.xml:243 msgid "admins:administrators:" -msgstr "" +msgstr "admins:administrators:" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_override.8.xml:246 msgid "Domain Users:Users:501" -msgstr "" +msgstr "Domain Users:Users:501" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_override.8.xml:252 msgid "<option>group-export</option> <emphasis>FILE</emphasis>" -msgstr "" +msgstr "<option>group-export</option> <emphasis>FILE</emphasis>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_override.8.xml:257 @@ -12794,31 +14710,33 @@ msgid "" "<emphasis>FILE</emphasis>. See <emphasis>group-import</emphasis> for data " "format." msgstr "" +"匯出所有已覆寫的屬性,並將它們儲存在 <emphasis>FILE</emphasis>。資料格式請參" +"閱 <emphasis>group-import</emphasis>。" #. type: Content of: <reference><refentry><refsect1><title> #: sss_override.8.xml:267 sssctl.8.xml:50 msgid "COMMON OPTIONS" -msgstr "" +msgstr "一般選項" #. type: Content of: <reference><refentry><refsect1><para> #: sss_override.8.xml:269 sssctl.8.xml:52 msgid "Those options are available with all commands." -msgstr "" +msgstr "這些選項適用於所有指令。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_override.8.xml:274 sssctl.8.xml:57 msgid "<option>--debug</option> <replaceable>LEVEL</replaceable>" -msgstr "" +msgstr "<option>--debug</option> <replaceable>LEVEL</replaceable>" #. type: Content of: <reference><refentry><refnamediv><refname> #: sssd-krb5.5.xml:10 sssd-krb5.5.xml:16 msgid "sssd-krb5" -msgstr "" +msgstr "sssd-krb5" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sssd-krb5.5.xml:17 msgid "SSSD Kerberos provider" -msgstr "" +msgstr "SSSD Kerberos 提供者" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-krb5.5.xml:23 @@ -12831,6 +14749,10 @@ msgid "" "<refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</manvolnum> " "</citerefentry> manual page." msgstr "" +"本手冊頁說明 <citerefentry> <refentrytitle>sssd</refentrytitle> <manvolnum>" +"8</manvolnum> </citerefentry> 之 Kerberos 5 驗證後端的設定。詳細的語法參考請" +"參閱 <citerefentry> <refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry> 手冊頁的 <quote>FILE FORMAT</quote> 一節。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-krb5.5.xml:36 @@ -12844,6 +14766,10 @@ msgid "" "page for the applicable identity provider for details on how to configure " "this." msgstr "" +"Kerberos 5 驗證後端包含 auth 與 chpass 提供者。它必須與身分提供者配對才能正常" +"運作(例如 id_provider = ldap)。Kerberos 5 驗證後端所需的某些資訊必須由身分" +"提供者提供,例如使用者的 Kerberos Principal Name (UPN)。身分提供者的設定應有" +"指定 UPN 的項目。如何設定的詳細資料請參閱適用身分提供者的手冊頁。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-krb5.5.xml:47 @@ -12855,6 +14781,10 @@ msgid "" "will deny all access to this user. To activate this feature, use " "'access_provider = krb5' in your SSSD configuration." msgstr "" +"此後端也提供以使用者家目錄中 .k5login 檔案為基礎的存取控制。更多詳細資料請參" +"閱 <citerefentry> <refentrytitle>k5login</refentrytitle><manvolnum>5</" +"manvolnum> </citerefentry>。請注意,空的 .k5login 檔案會拒絕此使用者的所有存" +"取。若要啟動此功能,請在 SSSD 設定中使用 'access_provider = krb5'。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-krb5.5.xml:55 @@ -12863,6 +14793,8 @@ msgid "" "<command>sssd</command> will construct a UPN using the format " "<replaceable>username</replaceable>@<replaceable>krb5_realm</replaceable>." msgstr "" +"若身分後端中沒有可用的 UPN,<command>sssd</command> 會使用 <replaceable>" +"username</replaceable>@<replaceable>krb5_realm</replaceable> 格式建構 UPN。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:77 @@ -12875,18 +14807,22 @@ msgid "" "discovery is enabled; for more information, refer to the <quote>SERVICE " "DISCOVERY</quote> section." msgstr "" +"指定 SSSD 應依偏好順序連線之 Kerberos 伺服器的 IP 位址或主機名稱逗號分隔清單" +"。有關故障轉移與伺服器備援的更多資訊,請參閱 <quote>FAILOVER</quote> 一節。可" +"以在位址或主機名稱後面附加選用的連接埠號碼(前面加上冒號)。若為空白,則啟用" +"服務探索;更多資訊請參閱 <quote>SERVICE DISCOVERY</quote> 一節。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:106 msgid "" "The name of the Kerberos realm. This option is required and must be " "specified." -msgstr "" +msgstr "Kerberos realm 的名稱。此選項是必要的,必須指定。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-krb5.5.xml:113 msgid "krb5_kpasswd, krb5_backup_kpasswd (string)" -msgstr "" +msgstr "krb5_kpasswd, krb5_backup_kpasswd (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:116 @@ -12895,6 +14831,8 @@ msgid "" "servers can be defined here. An optional port number (preceded by a colon) " "may be appended to the addresses or hostnames." msgstr "" +"若變更密碼服務未在 KDC 上執行,可以在這裡定義替代伺服器。可以在位址或主機名稱" +"後面附加選用的連接埠號碼(前面加上冒號)。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:122 @@ -12904,16 +14842,19 @@ msgid "" "servers to try, the backend is not switched to operate offline if " "authentication against the KDC is still possible." msgstr "" +"有關故障轉移與伺服器備援的更多資訊,請參閱 <quote>FAILOVER</quote> 一節。注意" +":即使沒有更多可以嘗試的 kpasswd 伺服器,只要仍可以針對 KDC 驗證,後端就不會" +"切換為離線運作。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:129 msgid "Default: Use the KDC" -msgstr "" +msgstr "預設:使用 KDC" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-krb5.5.xml:135 msgid "krb5_ccachedir (string)" -msgstr "" +msgstr "krb5_ccachedir (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:138 @@ -12922,96 +14863,98 @@ msgid "" "krb5_ccname_template can be used here, too, except %d and %P. The directory " "is created as private and owned by the user, with permissions set to 0700." msgstr "" +"儲存憑證快取的目錄。除了 %d 與 %P 之外,krb5_ccname_template 的所有替換序列也" +"可以在這裡使用。此目錄會以私人權限建立並由使用者擁有,權限設為 0700。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:145 msgid "Default: /tmp" -msgstr "" +msgstr "預設:/tmp" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-krb5.5.xml:151 msgid "krb5_ccname_template (string)" -msgstr "" +msgstr "krb5_ccname_template (string)" #. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd-krb5.5.xml:165 include/override_homedir.xml:11 msgid "%u" -msgstr "" +msgstr "%u" #. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:166 include/override_homedir.xml:12 msgid "login name" -msgstr "" +msgstr "登入名稱" #. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd-krb5.5.xml:169 include/override_homedir.xml:15 msgid "%U" -msgstr "" +msgstr "%U" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:170 msgid "login UID" -msgstr "" +msgstr "登入 UID" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd-krb5.5.xml:173 msgid "%p" -msgstr "" +msgstr "%p" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:174 msgid "principal name" -msgstr "" +msgstr "principal 名稱" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd-krb5.5.xml:178 msgid "%r" -msgstr "" +msgstr "%r" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:179 msgid "realm name" -msgstr "" +msgstr "realm 名稱" #. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd-krb5.5.xml:182 include/override_homedir.xml:42 msgid "%h" -msgstr "" +msgstr "%h" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:183 sssd-ifp.5.xml:124 msgid "home directory" -msgstr "" +msgstr "家目錄" #. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd-krb5.5.xml:187 include/override_homedir.xml:19 msgid "%d" -msgstr "" +msgstr "%d" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:188 msgid "value of krb5_ccachedir" -msgstr "" +msgstr "krb5_ccachedir 的值" #. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd-krb5.5.xml:193 include/override_homedir.xml:31 msgid "%P" -msgstr "" +msgstr "%P" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:194 msgid "the process ID of the SSSD client" -msgstr "" +msgstr "SSSD 用戶端的程序 ID" #. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd-krb5.5.xml:199 include/override_homedir.xml:56 msgid "%%" -msgstr "" +msgstr "%%" #. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:200 include/override_homedir.xml:57 msgid "a literal '%'" -msgstr "" +msgstr "字面上的 '%'" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:154 @@ -13025,6 +14968,12 @@ msgid "" "the template ends with 'XXXXXX' mkstemp(3) is used to create a unique " "filename in a safe way." msgstr "" +"使用者憑證快取的位置。目前支援三種憑證快取類型:<quote>FILE</quote>、<quote>" +"DIR</quote> 與 <quote>KEYRING:persistent</quote>。快取可以指定為 " +"<replaceable>TYPE:RESIDUAL</replaceable>,或指定為絕對路徑(表示 <quote>" +"FILE</quote> 類型)。在範本中,會替換下列序列:<placeholder " +"type=\"variablelist\" id=\"0\"/> 若範本以 'XXXXXX' 結尾,會使用 mkstemp(3) 以" +"安全的方式建立唯一的檔案名稱。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:208 @@ -13034,6 +14983,9 @@ msgid "" "store credentials on a per-UID basis. This is also the recommended choice, " "as it is the most secure and predictable method." msgstr "" +"使用 KEYRING 類型時,唯一支援的機制是 <quote>KEYRING:persistent:%U</quote>," +"它使用 Linux 核心 keyring 以每個 UID 為基礎儲存憑證。這也是最推薦的選擇,因為" +"它是最安全且可預期的方法。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:216 @@ -13044,6 +14996,9 @@ msgid "" "PARAMETER EXPANSION paragraph for additional information on the expansion " "format defined by krb5.conf." msgstr "" +"憑證快取名稱的預設值來自儲存在全系統 krb5.conf 設定檔 [libdefaults] 區段中的" +"設定檔。選項名稱是 default_ccache_name。krb5.conf 定義之展開格式的其他資訊請" +"參閱 krb5.conf(5) 的 PARAMETER EXPANSION 段落。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:225 @@ -13053,35 +15008,38 @@ msgid "" "<manvolnum>5</manvolnum> </citerefentry> uses different expansion sequences " "than SSSD." msgstr "" +"注意:請注意,<citerefentry> <refentrytitle>krb5.conf</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry> 的 libkrb5 ccache 展開範本使用與 " +"SSSD 不同的展開序列。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:234 msgid "Default: (from libkrb5)" -msgstr "" +msgstr "預設:(來自 libkrb5)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-krb5.5.xml:240 msgid "krb5_keytab (string)" -msgstr "" +msgstr "krb5_keytab (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:243 msgid "" "The location of the keytab to use when validating credentials obtained from " "KDCs." -msgstr "" +msgstr "驗證從 KDC 取得的憑證時使用的 keytab 位置。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-krb5.5.xml:253 msgid "krb5_store_password_if_offline (boolean)" -msgstr "" +msgstr "krb5_store_password_if_offline (boolean)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:256 msgid "" "Store the password of the user if the provider is offline and use it to " "request a TGT when the provider comes online again." -msgstr "" +msgstr "若提供者離線,儲存使用者的密碼,並在提供者再次上線時使用它要求 TGT。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:261 @@ -13090,25 +15048,27 @@ msgid "" "are kept in plaintext in the kernel keyring and are potentially accessible " "by the root user (with difficulty)." msgstr "" +"注意:此功能只適用於 Linux。以這種方式儲存的密碼會以明文保存在核心 keyring 中" +",root 使用者有可能(困難地)存取。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-krb5.5.xml:274 msgid "krb5_use_fast (string)" -msgstr "" +msgstr "krb5_use_fast (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:277 msgid "" "Enables flexible authentication secure tunneling (FAST) for Kerberos " "pre-authentication. The following options are supported:" -msgstr "" +msgstr "啟用 Kerberos 預先驗證的彈性驗證安全通道 (FAST)。支援下列選項:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:282 msgid "" "<emphasis>never</emphasis> use FAST. This is equivalent to not setting this " "option at all." -msgstr "" +msgstr "<emphasis>never</emphasis>:不使用 FAST。這等同於完全不設定此選項。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:286 @@ -13116,23 +15076,25 @@ msgid "" "<emphasis>try</emphasis> to use FAST. If the server does not support FAST, " "continue the authentication without it." msgstr "" +"<emphasis>try</emphasis>:嘗試使用 FAST。若伺服器不支援 FAST,則在沒有 FAST " +"的情況下繼續驗證。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:291 msgid "" "<emphasis>demand</emphasis> to use FAST. The authentication fails if the " "server does not require fast." -msgstr "" +msgstr "<emphasis>demand</emphasis>:必須使用 FAST。若伺服器不需要 FAST,驗證會失敗。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:296 msgid "Default: not set, i.e. FAST is not used." -msgstr "" +msgstr "預設:未設定,也就是不使用 FAST。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:299 msgid "NOTE: a keytab or support for anonymous PKINIT is required to use FAST." -msgstr "" +msgstr "注意:使用 FAST 需要 keytab 或對匿名 PKINIT 的支援。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:303 @@ -13141,21 +15103,23 @@ msgid "" "SSSD is used with an older version of MIT Kerberos, using this option is a " "configuration error." msgstr "" +"注意:SSSD 只支援 MIT Kerberos 1.8 及更新版本的 FAST。若 SSSD 與較舊版本的 " +"MIT Kerberos 一起使用,使用此選項是設定錯誤。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-krb5.5.xml:312 msgid "krb5_fast_principal (string)" -msgstr "" +msgstr "krb5_fast_principal (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:315 msgid "Specifies the server principal to use for FAST." -msgstr "" +msgstr "指定用於 FAST 的伺服器 principal。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-krb5.5.xml:321 msgid "krb5_fast_use_anonymous_pkinit (boolean)" -msgstr "" +msgstr "krb5_fast_use_anonymous_pkinit (boolean)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:324 @@ -13164,11 +15128,13 @@ msgid "" "required credential for FAST. The krb5_fast_principal options is ignored in " "this case." msgstr "" +"若設為 true,嘗試使用匿名 PKINIT 而不是 keytab 取得 FAST 所需的憑證。這種情況" +"下會忽略 krb5_fast_principal 選項。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-krb5.5.xml:364 msgid "krb5_kdcinfo_lookahead (string)" -msgstr "" +msgstr "krb5_kdcinfo_lookahead (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:367 @@ -13179,6 +15145,10 @@ msgid "" "<manvolnum>8</manvolnum> </citerefentry>. This might be helpful when there " "are too many servers discovered using SRV record." msgstr "" +"當 krb5_use_kdcinfo 設為 true 時,您可以限制交給 <citerefentry> " +"<refentrytitle>sssd_krb5_locator_plugin</refentrytitle> <manvolnum>8</" +"manvolnum> </citerefentry> 的伺服器數量。當使用 SRV 記錄探索到太多伺服器時," +"這可能很有幫助。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:377 @@ -13187,6 +15157,8 @@ msgid "" "colon. The first number represents number of primary servers used and the " "second number specifies the number of backup servers." msgstr "" +"krb5_kdcinfo_lookahead 選項包含兩個以冒號分隔的數字。第一個數字代表使用的主要" +"伺服器數目,第二個數字指定備份伺服器的數目。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:383 @@ -13196,16 +15168,19 @@ msgid "" "<refentrytitle>sssd_krb5_locator_plugin</refentrytitle> " "<manvolnum>8</manvolnum> </citerefentry> but no backup servers." msgstr "" +"例如 <emphasis>10:0</emphasis> 表示最多 10 個主要伺服器會交給 <citerefentry> " +"<refentrytitle>sssd_krb5_locator_plugin</refentrytitle> <manvolnum>8</" +"manvolnum> </citerefentry>,但沒有備份伺服器。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:392 msgid "Default: 3:1" -msgstr "" +msgstr "預設:3:1" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-krb5.5.xml:398 msgid "krb5_use_enterprise_principal (boolean)" -msgstr "" +msgstr "krb5_use_enterprise_principal (boolean)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:401 @@ -13214,11 +15189,13 @@ msgid "" "principal. See section 5 of RFC 6806 for more details about enterprise " "principals." msgstr "" +"指定是否應將使用者 principal 視為 enterprise principal。enterprise principal " +"的更多詳細資料請參閱 RFC 6806 第 5 節。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:407 msgid "Default: false (AD provider: true)" -msgstr "" +msgstr "預設:false(AD 提供者:true)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:410 @@ -13227,11 +15204,13 @@ msgid "" "is capable of handling enterprise principals and the option is not set " "explicitly in the config file." msgstr "" +"若 IPA 提供者偵測到伺服器能夠處理 enterprise principal,且設定檔中未明確設定" +"此選項,則會將此選項設為 'true'。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-krb5.5.xml:419 msgid "krb5_use_subdomain_realm (boolean)" -msgstr "" +msgstr "krb5_use_subdomain_realm (boolean)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:422 @@ -13242,11 +15221,14 @@ msgid "" "the option is set to 'true' SSSD will try to send the request directly to a " "KDC of the trusted domain the user is coming from." msgstr "" +"指定對受信任網域的使用者驗證時使用子網域 realm。若 enterprise principal 使用" +"父網域 KDC 不知道的 upnSuffix,可以將此選項設為 'true'。若此選項設為 'true'," +"SSSD 會嘗試直接將要求傳送到使用者來源之受信任網域的 KDC。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-krb5.5.xml:438 msgid "krb5_map_user (string)" -msgstr "" +msgstr "krb5_map_user (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:441 @@ -13257,6 +15239,10 @@ msgid "" "mapping is used when user is authenticating using <quote>auth_provider = " "krb5</quote>." msgstr "" +"對應清單以配對 <quote>username:primary</quote> 的逗號分隔清單給出,其中 " +"<quote>username</quote> 是 UNIX 使用者名稱,<quote>primary</quote> 是 " +"kerberos principal 的使用者部分。此對應在使用者使用 <quote>auth_provider = " +"krb5</quote> 驗證時使用。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> #: sssd-krb5.5.xml:453 @@ -13265,6 +15251,8 @@ msgid "" "krb5_realm = REALM\n" "krb5_map_user = joe:juser,dick:richard\n" msgstr "" +"krb5_realm = REALM\n" +"krb5_map_user = joe:juser,dick:richard\n" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:458 @@ -13275,6 +15263,10 @@ msgid "" "try to kinit as <quote>juser@REALM</quote> resp. " "<quote>richard@REALM</quote>." msgstr "" +"<quote>joe</quote> 與 <quote>dick</quote> 是 UNIX 使用者名稱,<quote>juser</" +"quote> 與 <quote>richard</quote> 是 kerberos principal 的主要部分。對使用者 " +"<quote>joe</quote>(或 <quote>dick</quote>),SSSD 會嘗試以 <quote>" +"juser@REALM</quote>(或 <quote>richard@REALM</quote>)執行 kinit。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-krb5.5.xml:65 @@ -13286,6 +15278,10 @@ msgid "" "details on the configuration of an SSSD domain. <placeholder " "type=\"variablelist\" id=\"0\"/>" msgstr "" +"若在 SSSD 網域中使用 auth 模組 krb5,必須使用下列選項。SSSD 網域設定的詳細資" +"料請參閱 <citerefentry> <refentrytitle>sssd.conf</refentrytitle> <manvolnum>" +"5</manvolnum> </citerefentry> 手冊頁的 <quote>DOMAIN SECTIONS</quote> 一節" +"。<placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-krb5.5.xml:485 @@ -13295,6 +15291,9 @@ msgid "" "example shows only configuration of Kerberos authentication; it does not " "include any identity provider." msgstr "" +"下列範例假設 SSSD 已正確設定,且 FOO 是 <replaceable>[sssd]</replaceable> 區" +"段中的其中一個網域。此範例只顯示 Kerberos 驗證的設定;它不包含任何身分提供者" +"。" #. type: Content of: <reference><refentry><refsect1><para><programlisting> #: sssd-krb5.5.xml:493 @@ -13305,16 +15304,20 @@ msgid "" "krb5_server = 192.168.1.1\n" "krb5_realm = EXAMPLE.COM\n" msgstr "" +"[domain/FOO]\n" +"auth_provider = krb5\n" +"krb5_server = 192.168.1.1\n" +"krb5_realm = EXAMPLE.COM\n" #. type: Content of: <reference><refentry><refnamediv><refname> #: sss_cache.8.xml:10 sss_cache.8.xml:15 msgid "sss_cache" -msgstr "" +msgstr "sss_cache" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sss_cache.8.xml:16 msgid "perform cache cleanup" -msgstr "" +msgstr "執行快取清理" #. type: Content of: <reference><refentry><refsynopsisdiv><cmdsynopsis> #: sss_cache.8.xml:21 @@ -13322,6 +15325,8 @@ msgid "" "<command>sss_cache</command> <arg choice='opt'> " "<replaceable>options</replaceable> </arg>" msgstr "" +"<command>sss_cache</command> <arg choice='opt'> <replaceable>options</" +"replaceable> </arg>" #. type: Content of: <reference><refentry><refsect1><para> #: sss_cache.8.xml:31 @@ -13331,38 +15336,42 @@ msgid "" "backend is online. Options that invalidate a single object only accept a " "single provided argument." msgstr "" +"<command>sss_cache</command> 使 SSSD 快取中的記錄失效。失效的記錄會在相關 " +"SSSD 後端上線時,被迫從伺服器重新載入。使單一物件失效的選項只接受單一提供的參" +"數。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_cache.8.xml:43 msgid "<option>-E</option>,<option>--everything</option>" -msgstr "" +msgstr "<option>-E</option>,<option>--everything</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_cache.8.xml:47 msgid "Invalidate all cached entries." -msgstr "" +msgstr "使所有快取的項目失效。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_cache.8.xml:53 msgid "<option>-u</option>,<option>--user</option> <replaceable>login</replaceable>" msgstr "" +"<option>-u</option>,<option>--user</option> <replaceable>login</replaceable>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_cache.8.xml:58 msgid "Invalidate specific user." -msgstr "" +msgstr "使特定使用者失效。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_cache.8.xml:64 msgid "<option>-U</option>,<option>--users</option>" -msgstr "" +msgstr "<option>-U</option>,<option>--users</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_cache.8.xml:68 msgid "" "Invalidate all user records. This option overrides invalidation of specific " "user if it was also set." -msgstr "" +msgstr "使所有使用者記錄失效。若也設定了特定使用者的失效,此選項會覆寫它。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_cache.8.xml:75 @@ -13370,23 +15379,24 @@ msgid "" "<option>-g</option>,<option>--group</option> " "<replaceable>group</replaceable>" msgstr "" +"<option>-g</option>,<option>--group</option> <replaceable>group</replaceable>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_cache.8.xml:80 msgid "Invalidate specific group." -msgstr "" +msgstr "使特定群組失效。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_cache.8.xml:86 msgid "<option>-G</option>,<option>--groups</option>" -msgstr "" +msgstr "<option>-G</option>,<option>--groups</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_cache.8.xml:90 msgid "" "Invalidate all group records. This option overrides invalidation of specific " "group if it was also set." -msgstr "" +msgstr "使所有群組記錄失效。若也設定了特定群組的失效,此選項會覆寫它。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_cache.8.xml:97 @@ -13394,23 +15404,25 @@ msgid "" "<option>-n</option>,<option>--netgroup</option> " "<replaceable>netgroup</replaceable>" msgstr "" +"<option>-n</option>,<option>--netgroup</option> <replaceable>netgroup</" +"replaceable>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_cache.8.xml:102 msgid "Invalidate specific netgroup." -msgstr "" +msgstr "使特定 netgroup 失效。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_cache.8.xml:108 msgid "<option>-N</option>,<option>--netgroups</option>" -msgstr "" +msgstr "<option>-N</option>,<option>--netgroups</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_cache.8.xml:112 msgid "" "Invalidate all netgroup records. This option overrides invalidation of " "specific netgroup if it was also set." -msgstr "" +msgstr "使所有 netgroup 記錄失效。若也設定了特定 netgroup 的失效,此選項會覆寫它。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_cache.8.xml:119 @@ -13418,23 +15430,25 @@ msgid "" "<option>-s</option>,<option>--service</option> " "<replaceable>service</replaceable>" msgstr "" +"<option>-s</option>,<option>--service</option> <replaceable>service</" +"replaceable>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_cache.8.xml:124 msgid "Invalidate specific service." -msgstr "" +msgstr "使特定服務失效。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_cache.8.xml:130 msgid "<option>-S</option>,<option>--services</option>" -msgstr "" +msgstr "<option>-S</option>,<option>--services</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_cache.8.xml:134 msgid "" "Invalidate all service records. This option overrides invalidation of " "specific service if it was also set." -msgstr "" +msgstr "使所有服務記錄失效。若也設定了特定服務的失效,此選項會覆寫它。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_cache.8.xml:141 @@ -13442,23 +15456,25 @@ msgid "" "<option>-a</option>,<option>--autofs-map</option> " "<replaceable>autofs-map</replaceable>" msgstr "" +"<option>-a</option>,<option>--autofs-map</option> <replaceable>autofs-map</" +"replaceable>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_cache.8.xml:146 msgid "Invalidate specific autofs maps." -msgstr "" +msgstr "使特定 autofs 對應失效。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_cache.8.xml:152 msgid "<option>-A</option>,<option>--autofs-maps</option>" -msgstr "" +msgstr "<option>-A</option>,<option>--autofs-maps</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_cache.8.xml:156 msgid "" "Invalidate all autofs maps. This option overrides invalidation of specific " "map if it was also set." -msgstr "" +msgstr "使所有 autofs 對應失效。若也設定了特定對應的失效,此選項會覆寫它。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_cache.8.xml:163 @@ -13466,16 +15482,18 @@ msgid "" "<option>-h</option>,<option>--ssh-host</option> " "<replaceable>hostname</replaceable>" msgstr "" +"<option>-h</option>,<option>--ssh-host</option> <replaceable>hostname</" +"replaceable>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_cache.8.xml:168 msgid "Invalidate SSH public keys of a specific host." -msgstr "" +msgstr "使特定主機的 SSH 公開金鑰失效。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_cache.8.xml:174 msgid "<option>-H</option>,<option>--ssh-hosts</option>" -msgstr "" +msgstr "<option>-H</option>,<option>--ssh-hosts</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_cache.8.xml:178 @@ -13483,6 +15501,8 @@ msgid "" "Invalidate SSH public keys of all hosts. This option overrides invalidation " "of SSH public keys of specific host if it was also set." msgstr "" +"使所有主機的 SSH 公開金鑰失效。若也設定了特定主機之 SSH 公開金鑰的失效,此選" +"項會覆寫它。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_cache.8.xml:186 @@ -13490,23 +15510,25 @@ msgid "" "<option>-r</option>,<option>--sudo-rule</option> " "<replaceable>rule</replaceable>" msgstr "" +"<option>-r</option>,<option>--sudo-rule</option> <replaceable>rule</" +"replaceable>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_cache.8.xml:191 msgid "Invalidate particular sudo rule." -msgstr "" +msgstr "使特定 sudo 規則失效。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_cache.8.xml:197 msgid "<option>-R</option>,<option>--sudo-rules</option>" -msgstr "" +msgstr "<option>-R</option>,<option>--sudo-rules</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_cache.8.xml:201 msgid "" "Invalidate all cached sudo rules. This option overrides invalidation of " "specific sudo rule if it was also set." -msgstr "" +msgstr "使所有快取的 sudo 規則失效。若也設定了特定 sudo 規則的失效,此選項會覆寫它。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_cache.8.xml:209 @@ -13514,16 +15536,18 @@ msgid "" "<option>-d</option>,<option>--domain</option> " "<replaceable>domain</replaceable>" msgstr "" +"<option>-d</option>,<option>--domain</option> <replaceable>domain</" +"replaceable>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_cache.8.xml:214 msgid "Restrict invalidation process only to a particular domain." -msgstr "" +msgstr "只將失效程序限制在特定網域。" #. type: Content of: <reference><refentry><refsect1><title> #: sss_cache.8.xml:224 msgid "EFFECTS ON THE FAST MEMORY CACHE" -msgstr "" +msgstr "對快速記憶體快取的影響" #. type: Content of: <reference><refentry><refsect1><para> #: sss_cache.8.xml:226 @@ -13540,6 +15564,13 @@ msgid "" "kernel can release the occupied disk space and the old memory cache file is " "finally removed completely." msgstr "" +"<command>sss_cache</command> 也會使記憶體快取失效。由於記憶體快取是對應到每個" +"呼叫 SSSD 解析使用者或群組之程序的記憶體中的檔案,因此該檔案無法截斷。檔案標" +"頭中會設定特殊旗標以表示內容無效,然後 SSSD 的 NSS responder 會取消連結該檔案" +"並建立新的快取檔案。每當程序對使用者或群組進行新的查詢時,它會看到旗標、關閉" +"舊的記憶體快取檔案並將新的對應到記憶體中。當所有開啟舊記憶體快取檔案的程序在" +"查詢使用者或群組時關閉它之後,核心就能釋放佔用的磁碟空間,舊的記憶體快取檔案" +"最後會完全移除。" #. type: Content of: <reference><refentry><refsect1><para> #: sss_cache.8.xml:240 @@ -13554,6 +15585,12 @@ msgid "" "disk usage because old memory cache files cannot be removed from the disk " "because they are still mapped by long running processes." msgstr "" +"一個特殊情況是只在啟動時執行使用者或群組查詢的長時間執行程序,例如確定程序執" +"行之使用者的名稱。對這些查詢,記憶體快取檔案會對應到程序的記憶體中。但由於不" +"會再有進一步的查詢,此程序永遠不會偵測到記憶體快取檔案是否已失效,因此它會保" +"留在記憶體中並佔用磁碟空間,直到程序停止。因此呼叫 <command>sss_cache</" +"command> 可能會增加磁碟使用量,因為舊的記憶體快取檔案仍被長時間執行的程序對應" +",無法從磁碟移除。" #. type: Content of: <reference><refentry><refsect1><para> #: sss_cache.8.xml:252 @@ -13566,16 +15603,20 @@ msgid "" "so that they meet the local expectations and calling " "<command>sss_cache</command> is not needed." msgstr "" +"對只在啟動時或極少查詢使用者與群組的長時間執行程序,一個可行的解決方法是將環" +"境變數 SSS_NSS_USE_MEMCACHE 設為 \"NO\" 執行它們,這樣它們完全不會使用記憶體" +"快取,也不會將記憶體快取檔案對應到記憶體中。一般來說,更好的解決方案是調整快" +"取逾時參數以符合本機預期,就不需要呼叫 <command>sss_cache</command>。" #. type: Content of: <reference><refentry><refnamediv><refname> #: sss_debuglevel.8.xml:10 sss_debuglevel.8.xml:15 msgid "sss_debuglevel" -msgstr "" +msgstr "sss_debuglevel" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sss_debuglevel.8.xml:16 msgid "[DEPRECATED] change debug level while SSSD is running" -msgstr "" +msgstr "[已棄用] 在 SSSD 執行期間變更除錯層級" #. type: Content of: <reference><refentry><refsynopsisdiv><cmdsynopsis> #: sss_debuglevel.8.xml:21 @@ -13584,6 +15625,9 @@ msgid "" "<replaceable>options</replaceable> </arg> <arg " "choice='plain'><replaceable>NEW_DEBUG_LEVEL</replaceable></arg>" msgstr "" +"<command>sss_debuglevel</command> <arg choice='opt'> <replaceable>options</" +"replaceable> </arg> <arg choice='plain'><replaceable>NEW_DEBUG_LEVEL</" +"replaceable></arg>" #. type: Content of: <reference><refentry><refsect1><para> #: sss_debuglevel.8.xml:32 @@ -13592,16 +15636,18 @@ msgid "" "debug-level command. Please refer to the <command>sssctl</command> man page " "for more information on sssctl usage." msgstr "" +"<command>sss_debuglevel</command> 已棄用,改由 sssctl debug-level 指令取代。" +"sssctl 用法的更多資訊請參閱 <command>sssctl</command> 手冊頁。" #. type: Content of: <reference><refentry><refnamediv><refname> #: sss_seed.8.xml:10 sss_seed.8.xml:15 msgid "sss_seed" -msgstr "" +msgstr "sss_seed" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sss_seed.8.xml:16 msgid "seed the SSSD cache with a user" -msgstr "" +msgstr "以使用者為 SSSD 快取播種" #. type: Content of: <reference><refentry><refsynopsisdiv><cmdsynopsis> #: sss_seed.8.xml:21 @@ -13611,6 +15657,9 @@ msgid "" "<replaceable>DOMAIN</replaceable></arg> <arg choice='plain'>-n " "<replaceable>USER</replaceable></arg>" msgstr "" +"<command>sss_seed</command> <arg choice='opt'> <replaceable>options</" +"replaceable> </arg> <arg choice='plain'>-D <replaceable>DOMAIN</replaceable>" +"</arg> <arg choice='plain'>-n <replaceable>USER</replaceable></arg>" #. type: Content of: <reference><refentry><refsect1><para> #: sss_seed.8.xml:33 @@ -13619,6 +15668,8 @@ msgid "" "temporary password. If a user entry is already present in the SSSD cache " "then the entry is updated with the temporary password." msgstr "" +"<command>sss_seed</command> 以使用者項目與暫時密碼為 SSSD 快取播種。若 SSSD " +"快取中已有使用者項目,則會以暫時密碼更新該項目。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_seed.8.xml:46 @@ -13626,6 +15677,8 @@ msgid "" "<option>-D</option>,<option>--domain</option> " "<replaceable>DOMAIN</replaceable>" msgstr "" +"<option>-D</option>,<option>--domain</option> <replaceable>DOMAIN</" +"replaceable>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_seed.8.xml:51 @@ -13636,6 +15689,9 @@ msgid "" "Information retrieved from the domain overrides what is provided in the " "options." msgstr "" +"提供使用者所屬網域的名稱。該網域也用於擷取使用者資訊。網域必須在 sssd.conf 中" +"設定。<replaceable>DOMAIN</replaceable> 選項必須提供。從網域擷取的資訊會覆寫" +"選項中提供的內容。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_seed.8.xml:63 @@ -13643,6 +15699,8 @@ msgid "" "<option>-n</option>,<option>--username</option> " "<replaceable>USER</replaceable>" msgstr "" +"<option>-n</option>,<option>--username</option> <replaceable>USER</" +"replaceable>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_seed.8.xml:68 @@ -13650,26 +15708,30 @@ msgid "" "The username of the entry to be created or modified in the cache. The " "<replaceable>USER</replaceable> option must be provided." msgstr "" +"要在快取中建立或修改之項目的使用者名稱。<replaceable>USER</replaceable> 選項" +"必須提供。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_seed.8.xml:76 msgid "<option>-u</option>,<option>--uid</option> <replaceable>UID</replaceable>" msgstr "" +"<option>-u</option>,<option>--uid</option> <replaceable>UID</replaceable>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_seed.8.xml:81 msgid "Set the UID of the user to <replaceable>UID</replaceable>." -msgstr "" +msgstr "將使用者的 UID 設為 <replaceable>UID</replaceable>。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_seed.8.xml:88 msgid "<option>-g</option>,<option>--gid</option> <replaceable>GID</replaceable>" msgstr "" +"<option>-g</option>,<option>--gid</option> <replaceable>GID</replaceable>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_seed.8.xml:93 msgid "Set the GID of the user to <replaceable>GID</replaceable>." -msgstr "" +msgstr "將使用者的 GID 設為 <replaceable>GID</replaceable>。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_seed.8.xml:100 @@ -13677,13 +15739,15 @@ msgid "" "<option>-c</option>,<option>--gecos</option> " "<replaceable>COMMENT</replaceable>" msgstr "" +"<option>-c</option>,<option>--gecos</option> <replaceable>COMMENT</" +"replaceable>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_seed.8.xml:105 msgid "" "Any text string describing the user. Often used as the field for the user's " "full name." -msgstr "" +msgstr "任何描述使用者的文字字串。常用於使用者全名的欄位。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_seed.8.xml:112 @@ -13691,11 +15755,13 @@ msgid "" "<option>-h</option>,<option>--home</option> " "<replaceable>HOME_DIR</replaceable>" msgstr "" +"<option>-h</option>,<option>--home</option> <replaceable>HOME_DIR</" +"replaceable>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_seed.8.xml:117 msgid "Set the home directory of the user to <replaceable>HOME_DIR</replaceable>." -msgstr "" +msgstr "將使用者的家目錄設為 <replaceable>HOME_DIR</replaceable>。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_seed.8.xml:124 @@ -13703,18 +15769,19 @@ msgid "" "<option>-s</option>,<option>--shell</option> " "<replaceable>SHELL</replaceable>" msgstr "" +"<option>-s</option>,<option>--shell</option> <replaceable>SHELL</replaceable>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_seed.8.xml:129 msgid "Set the login shell of the user to <replaceable>SHELL</replaceable>." -msgstr "" +msgstr "將使用者的登入 shell 設為 <replaceable>SHELL</replaceable>。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_seed.8.xml:140 msgid "" "Interactive mode for entering user information. This option will only prompt " "for information not provided in the options or retrieved from the domain." -msgstr "" +msgstr "輸入使用者資訊的互動模式。此選項只會提示未在選項中提供或未從網域擷取的資訊。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_seed.8.xml:148 @@ -13722,13 +15789,15 @@ msgid "" "<option>-p</option>,<option>--password-file</option> " "<replaceable>PASS_FILE</replaceable>" msgstr "" +"<option>-p</option>,<option>--password-file</option> <replaceable>PASS_FILE</" +"replaceable>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_seed.8.xml:153 msgid "" "Specify file to read user's password from. (if not specified password is " "prompted for)" -msgstr "" +msgstr "指定從中讀取使用者密碼的檔案。(若未指定,會提示輸入密碼)" #. type: Content of: <reference><refentry><refsect1><para> #: sss_seed.8.xml:165 @@ -13737,16 +15806,18 @@ msgid "" "--password-file option) must be less than or equal to PASS_MAX bytes (64 " "bytes on systems with no globally-defined PASS_MAX value)." msgstr "" +"密碼長度(或以 -p 或 --password-file 選項指定之檔案的大小)必須小於或等於 " +"PASS_MAX 位元組(在沒有全域定義 PASS_MAX 值的系統上為 64 位元組)。" #. type: Content of: <reference><refentry><refnamediv><refname> #: sssd-ifp.5.xml:10 sssd-ifp.5.xml:16 msgid "sssd-ifp" -msgstr "" +msgstr "sssd-ifp" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sssd-ifp.5.xml:17 msgid "SSSD InfoPipe responder" -msgstr "" +msgstr "SSSD InfoPipe responder" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ifp.5.xml:23 @@ -13758,6 +15829,10 @@ msgid "" "<refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</manvolnum> " "</citerefentry> manual page." msgstr "" +"本手冊頁說明 <citerefentry> <refentrytitle>sssd</refentrytitle> <manvolnum>" +"8</manvolnum> </citerefentry> 之 InfoPipe responder 的設定。詳細的語法參考請" +"參閱 <citerefentry> <refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry> 手冊頁的 <quote>FILE FORMAT</quote> 一節。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ifp.5.xml:36 @@ -13766,33 +15841,35 @@ msgid "" "system bus. The interface allows the user to query information about remote " "users and groups over the system bus." msgstr "" +"InfoPipe responder 提供可透過系統匯流排存取的公開 D-Bus 介面。此介面允許使用" +"者透過系統匯流排查詢遠端使用者與群組的資訊。" #. type: Content of: <reference><refentry><refsect1><refsect2><title> #: sssd-ifp.5.xml:43 msgid "FIND BY VALID CERTIFICATE" -msgstr "" +msgstr "依有效憑證尋找" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sssd-ifp.5.xml:45 msgid "" "The following options can be used to control how the certificates are " "validated when using the FindByValidCertificate() API:" -msgstr "" +msgstr "使用 FindByValidCertificate() API 時,可以使用下列選項控制憑證的驗證方式:" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> #: sssd-ifp.5.xml:48 sss_ssh_authorizedkeys.1.xml:92 msgid "ca_db" -msgstr "" +msgstr "ca_db" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> #: sssd-ifp.5.xml:49 sss_ssh_authorizedkeys.1.xml:93 msgid "p11_child_timeout" -msgstr "" +msgstr "p11_child_timeout" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> #: sssd-ifp.5.xml:50 sss_ssh_authorizedkeys.1.xml:94 msgid "certificate_verification" -msgstr "" +msgstr "certificate_verification" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sssd-ifp.5.xml:52 @@ -13801,11 +15878,13 @@ msgid "" "<citerefentry><refentrytitle>sssd.conf</refentrytitle> " "<manvolnum>5</manvolnum></citerefentry>." msgstr "" +"這些選項的更多詳細資料請參閱 <citerefentry><refentrytitle>sssd.conf</" +"refentrytitle> <manvolnum>5</manvolnum></citerefentry>。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ifp.5.xml:62 msgid "These options can be used to configure the InfoPipe responder." -msgstr "" +msgstr "這些選項可用於設定 InfoPipe responder。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd-ifp.5.xml:69 @@ -13814,11 +15893,13 @@ msgid "" "allowed to access the InfoPipe responder. User names are resolved to UIDs at " "startup." msgstr "" +"指定允許存取 InfoPipe responder 的 UID 值或使用者名稱逗號分隔清單。使用者名稱" +"會在啟動時解析為 UID。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd-ifp.5.xml:75 msgid "Default: 0 (only the root user is allowed to access the InfoPipe responder)" -msgstr "" +msgstr "預設:0(只允許 root 使用者存取 InfoPipe responder)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd-ifp.5.xml:79 @@ -13828,66 +15909,68 @@ msgid "" "access the InfoPipe responder, which would be the typical case, you have to " "add 0 to the list of allowed UIDs as well." msgstr "" +"請注意,雖然 UID 0 用作預設值,它會被此選項覆寫。若您仍然想要允許 root 使用者" +"存取 InfoPipe responder(這是典型情況),您也必須將 0 加入允許的 UID 清單。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd-ifp.5.xml:93 msgid "Specifies the comma-separated list of white or blacklisted attributes." -msgstr "" +msgstr "指定白名單或黑名單屬性的逗號分隔清單。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd-ifp.5.xml:107 msgid "name" -msgstr "" +msgstr "name" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd-ifp.5.xml:108 msgid "user's login name" -msgstr "" +msgstr "使用者的登入名稱" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd-ifp.5.xml:111 msgid "uidNumber" -msgstr "" +msgstr "uidNumber" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd-ifp.5.xml:112 msgid "user ID" -msgstr "" +msgstr "使用者 ID" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd-ifp.5.xml:115 msgid "gidNumber" -msgstr "" +msgstr "gidNumber" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd-ifp.5.xml:116 msgid "primary group ID" -msgstr "" +msgstr "主要群組 ID" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd-ifp.5.xml:119 msgid "gecos" -msgstr "" +msgstr "gecos" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd-ifp.5.xml:120 msgid "user information, typically full name" -msgstr "" +msgstr "使用者資訊,通常是全名" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd-ifp.5.xml:123 msgid "homeDirectory" -msgstr "" +msgstr "homeDirectory" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd-ifp.5.xml:127 msgid "loginShell" -msgstr "" +msgstr "loginShell" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd-ifp.5.xml:128 msgid "user shell" -msgstr "" +msgstr "使用者 shell" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd-ifp.5.xml:97 @@ -13898,6 +15981,10 @@ msgid "" "<manvolnum>3</manvolnum> </citerefentry> and includes: <placeholder " "type=\"variablelist\" id=\"0\"/>" msgstr "" +"依預設,InfoPipe responder 只允許要求預設的 POSIX 屬性集。此集合與 " +"<citerefentry> <refentrytitle>getpwnam</refentrytitle> <manvolnum>3</" +"manvolnum> </citerefentry> 傳回的相同,包括:<placeholder " +"type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><programlisting> #: sssd-ifp.5.xml:141 @@ -13906,6 +15993,8 @@ msgid "" "user_attributes = +telephoneNumber, -loginShell\n" " " msgstr "" +"user_attributes = +telephoneNumber, -loginShell\n" +" " #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd-ifp.5.xml:133 @@ -13917,23 +16006,27 @@ msgid "" "use the following configuration: <placeholder type=\"programlisting\" " "id=\"0\"/>" msgstr "" +"可以使用 <quote>+attr_name</quote> 將另一個屬性加入此集合,或使用 <quote>-" +"attr_name</quote> 明確移除屬性。例如,要允許 <quote>telephoneNumber</quote> " +"但拒絕 <quote>loginShell</quote>,您可以使用下列設定:<placeholder " +"type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd-ifp.5.xml:145 msgid "Default: not set. Only the default set of POSIX attributes is allowed." -msgstr "" +msgstr "預設:未設定。只允許預設的 POSIX 屬性集。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd-ifp.5.xml:155 msgid "" "Specifies an upper limit on the number of entries that are downloaded during " "a wildcard lookup that overrides caller-supplied limit." -msgstr "" +msgstr "指定萬用字元查詢期間下載的項目數目上限,此上限會覆寫呼叫者提供的限制。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd-ifp.5.xml:160 msgid "Default: 0 (let the caller set an upper limit)" -msgstr "" +msgstr "預設:0(讓呼叫者設定上限)" #. type: Content of: <reference><refentry><refentryinfo> #: sss_rpcidmapd.5.xml:8 @@ -13945,21 +16038,27 @@ msgid "" "<surname>Meltzer</surname> <contrib>Developer (2014-)</contrib> " "<email>tsnoam@gmail.com</email> </author>" msgstr "" +"<productname>sss rpc.idmapd plugin</productname> <author> <firstname>Noam</" +"firstname> <surname>Meltzer</surname> <affiliation> <orgname>Primary Data " +"Inc.</orgname> </affiliation> <contrib>Developer (2013-2014)</contrib> </" +"author> <author> <firstname>Noam</firstname> <surname>Meltzer</surname> " +"<contrib>Developer (2014-)</contrib> <email>tsnoam@gmail.com</email> </" +"author>" #. type: Content of: <reference><refentry><refnamediv><refname> #: sss_rpcidmapd.5.xml:26 sss_rpcidmapd.5.xml:32 msgid "sss_rpcidmapd" -msgstr "" +msgstr "sss_rpcidmapd" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sss_rpcidmapd.5.xml:33 msgid "sss plugin configuration directives for rpc.idmapd" -msgstr "" +msgstr "rpc.idmapd 的 sss 外掛程式設定指示" #. type: Content of: <reference><refentry><refsect1><title> #: sss_rpcidmapd.5.xml:37 msgid "CONFIGURATION FILE" -msgstr "" +msgstr "設定檔" #. type: Content of: <reference><refentry><refsect1><para> #: sss_rpcidmapd.5.xml:39 @@ -13969,16 +16068,19 @@ msgid "" "<refentrytitle>idmapd.conf</refentrytitle> <manvolnum>5</manvolnum> " "</citerefentry> for more information." msgstr "" +"rpc.idmapd 設定檔通常位於 <emphasis>/etc/idmapd.conf</emphasis>。更多資訊請參" +"閱 <citerefentry> <refentrytitle>idmapd.conf</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry>。" #. type: Content of: <reference><refentry><refsect1><title> #: sss_rpcidmapd.5.xml:49 msgid "SSS CONFIGURATION EXTENSION" -msgstr "" +msgstr "SSS 設定延伸" #. type: Content of: <reference><refentry><refsect1><refsect2><title> #: sss_rpcidmapd.5.xml:51 msgid "Enable SSS plugin" -msgstr "" +msgstr "啟用 SSS 外掛程式" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sss_rpcidmapd.5.xml:53 @@ -13986,11 +16088,13 @@ msgid "" "In section <quote>[Translation]</quote>, modify/set <quote>Method</quote> " "attribute to contain <emphasis>sss</emphasis>." msgstr "" +"在 <quote>[Translation]</quote> 區段中,將 <quote>Method</quote> 屬性修改/設" +"定為包含 <emphasis>sss</emphasis>。" #. type: Content of: <reference><refentry><refsect1><refsect2><title> #: sss_rpcidmapd.5.xml:59 msgid "[sss] config section" -msgstr "" +msgstr "[sss] 設定區段" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sss_rpcidmapd.5.xml:61 @@ -13999,33 +16103,35 @@ msgid "" "<emphasis>sss</emphasis> plugin listed below you will need to create a " "config section for it, named <quote>[sss]</quote>." msgstr "" +"若要變更下列列出之 <emphasis>sss</emphasis> 外掛程式其中一個設定屬性的預設值" +",您需要為它建立名為 <quote>[sss]</quote> 的設定區段。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><title> #: sss_rpcidmapd.5.xml:67 msgid "Configuration attributes" -msgstr "" +msgstr "設定屬性" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sss_rpcidmapd.5.xml:69 msgid "memcache (bool)" -msgstr "" +msgstr "memcache (bool)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sss_rpcidmapd.5.xml:72 msgid "Indicates whether or not to use memcache optimisation technique." -msgstr "" +msgstr "指出是否使用 memcache 最佳化技術。" #. type: Content of: <reference><refentry><refsect1><title> #: sss_rpcidmapd.5.xml:85 msgid "SSSD INTEGRATION" -msgstr "" +msgstr "SSSD 整合" #. type: Content of: <reference><refentry><refsect1><para> #: sss_rpcidmapd.5.xml:87 msgid "" "The sss plugin requires the <emphasis>NSS Responder</emphasis> to be enabled " "in sssd." -msgstr "" +msgstr "sss 外掛程式要求 sssd 中啟用 <emphasis>NSS Responder</emphasis>。" #. type: Content of: <reference><refentry><refsect1><para> #: sss_rpcidmapd.5.xml:91 @@ -14034,6 +16140,8 @@ msgid "" "all domains (NFSv4 clients expect a fully qualified name to be sent on the " "wire)." msgstr "" +"所有網域都必須啟用 <quote>use_fully_qualified_names</quote> 屬性(NFSv4 用戶" +"端預期在線路上傳送完整限定名稱)。" #. type: Content of: <reference><refentry><refsect1><para><programlisting> #: sss_rpcidmapd.5.xml:103 @@ -14052,6 +16160,18 @@ msgid "" "[Translation]\n" "Method = sss\n" msgstr "" +"[General]\n" +"Verbosity = 2\n" +"# domain must be synced between NFSv4 server and clients\n" +"# Solaris/Illumos/AIX use \"localdomain\" as default!\n" +"Domain = default\n" +"\n" +"[Mapping]\n" +"Nobody-User = nfsnobody\n" +"Nobody-Group = nfsnobody\n" +"\n" +"[Translation]\n" +"Method = sss\n" #. type: Content of: <reference><refentry><refsect1><para> #: sss_rpcidmapd.5.xml:100 @@ -14059,11 +16179,13 @@ msgid "" "The following example shows a minimal idmapd.conf which makes use of the sss " "plugin. <placeholder type=\"programlisting\" id=\"0\"/>" msgstr "" +"下列範例顯示使用 sss 外掛程式的最小 idmapd.conf。<placeholder " +"type=\"programlisting\" id=\"0\"/>" #. type: Content of: <refsect1><title> #: sss_rpcidmapd.5.xml:120 sssd-kcm.8.xml:316 include/seealso.xml:2 msgid "SEE ALSO" -msgstr "" +msgstr "另請參閱" #. type: Content of: <reference><refentry><refsect1><para> #: sss_rpcidmapd.5.xml:122 @@ -14072,16 +16194,19 @@ msgid "" "</citerefentry>, <citerefentry> <refentrytitle>idmapd.conf</refentrytitle> " "<manvolnum>5</manvolnum> </citerefentry>" msgstr "" +"<citerefentry> <refentrytitle>sssd</refentrytitle><manvolnum>8</manvolnum> </" +"citerefentry>, <citerefentry> <refentrytitle>idmapd.conf</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry>" #. type: Content of: <reference><refentry><refnamediv><refname> #: sss_ssh_authorizedkeys.1.xml:10 sss_ssh_authorizedkeys.1.xml:15 msgid "sss_ssh_authorizedkeys" -msgstr "" +msgstr "sss_ssh_authorizedkeys" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sss_ssh_authorizedkeys.1.xml:16 msgid "get OpenSSH authorized keys" -msgstr "" +msgstr "取得 OpenSSH 授權金鑰" #. type: Content of: <reference><refentry><refsynopsisdiv><cmdsynopsis> #: sss_ssh_authorizedkeys.1.xml:21 @@ -14090,6 +16215,9 @@ msgid "" "<replaceable>options</replaceable> </arg> <arg " "choice='plain'><replaceable>USER</replaceable></arg>" msgstr "" +"<command>sss_ssh_authorizedkeys</command> <arg choice='opt'> <replaceable>" +"options</replaceable> </arg> <arg choice='plain'><replaceable>USER</" +"replaceable></arg>" #. type: Content of: <reference><refentry><refsect1><para> #: sss_ssh_authorizedkeys.1.xml:32 @@ -14100,6 +16228,11 @@ msgid "" "<citerefentry><refentrytitle>sshd</refentrytitle> " "<manvolnum>8</manvolnum></citerefentry> for more information)." msgstr "" +"<command>sss_ssh_authorizedkeys</command> 取得使用者 <replaceable>USER</" +"replaceable> 的 SSH 公開金鑰,並以 OpenSSH authorized_keys 格式輸出(更多資訊" +"請參閱 <citerefentry><refentrytitle>sshd</refentrytitle> <manvolnum>8</" +"manvolnum></citerefentry> 的 <quote>AUTHORIZED_KEYS FILE FORMAT</quote> 一節" +")。" #. type: Content of: <reference><refentry><refsect1><para> #: sss_ssh_authorizedkeys.1.xml:41 @@ -14113,6 +16246,11 @@ msgid "" "<manvolnum>5</manvolnum></citerefentry> man page for more details about this " "option." msgstr "" +"若 <citerefentry><refentrytitle>sshd</refentrytitle> <manvolnum>8</manvolnum>" +"</citerefentry> 編譯時支援 <quote>AuthorizedKeysCommand</quote> 選項,它可以" +"設定為使用 <command>sss_ssh_authorizedkeys</command> 進行公開金鑰使用者驗證。" +"此選項的更多詳細資料請參閱 <citerefentry> <refentrytitle>sshd_config</" +"refentrytitle> <manvolnum>5</manvolnum></citerefentry> 手冊頁。" #. type: Content of: <reference><refentry><refsect1><para><programlisting> #: sss_ssh_authorizedkeys.1.xml:59 @@ -14121,6 +16259,8 @@ msgid "" " AuthorizedKeysCommand /usr/bin/sss_ssh_authorizedkeys\n" " AuthorizedKeysCommandUser nobody\n" msgstr "" +" AuthorizedKeysCommand /usr/bin/sss_ssh_authorizedkeys\n" +" AuthorizedKeysCommandUser nobody\n" #. type: Content of: <reference><refentry><refsect1><para> #: sss_ssh_authorizedkeys.1.xml:52 @@ -14133,11 +16273,16 @@ msgid "" "<manvolnum>5</manvolnum></citerefentry>: <placeholder " "type=\"programlisting\" id=\"0\"/>" msgstr "" +"若支援 <quote>AuthorizedKeysCommand</quote>,可以將下列指示放在 " +"<citerefentry> <refentrytitle>sshd_config</refentrytitle> <manvolnum>5</" +"manvolnum></citerefentry> 中,設定 <citerefentry><refentrytitle>sshd</" +"refentrytitle> <manvolnum>8</manvolnum></citerefentry> 使用它:<placeholder " +"type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><title> #: sss_ssh_authorizedkeys.1.xml:65 msgid "KEYS FROM CERTIFICATES" -msgstr "" +msgstr "來自憑證的金鑰" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sss_ssh_authorizedkeys.1.xml:67 @@ -14146,6 +16291,9 @@ msgid "" "<command>sss_ssh_authorizedkeys</command> can return public SSH keys derived " "from the public key of a X.509 certificate as well." msgstr "" +"除了使用者 <replaceable>USER</replaceable> 的公開 SSH 金鑰之外,<command>" +"sss_ssh_authorizedkeys</command> 也可以傳回從 X.509 憑證公開金鑰衍生的公開 " +"SSH 金鑰。" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sss_ssh_authorizedkeys.1.xml:73 @@ -14164,11 +16312,20 @@ msgid "" "valid SSSD will extract the public key from the certificate and convert it " "into the format expected by sshd." msgstr "" +"要啟用此功能,<filename>sssd.conf</filename> 的 [ssh] 區段中必須將 <quote>" +"ssh_use_certificate_keys</quote> 選項設為 true(預設)。若使用者項目包含憑證" +"(詳細資料請參閱 <citerefentry><refentrytitle>sssd-ldap</refentrytitle> " +"<manvolnum>5</manvolnum></citerefentry> 中的 <quote>ldap_user_certificate</" +"quote>)或使用者的覆寫項目中有憑證(詳細資料請參閱 <citerefentry>" +"<refentrytitle>sss_override</refentrytitle> <manvolnum>8</manvolnum></" +"citerefentry> 或 <citerefentry><refentrytitle>sssd-ipa</refentrytitle> " +"<manvolnum>5</manvolnum></citerefentry>),且憑證有效,SSSD 會從憑證擷取公開" +"金鑰並轉換成 sshd 預期的格式。" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sss_ssh_authorizedkeys.1.xml:90 msgid "Besides <quote>ssh_use_certificate_keys</quote> the options" -msgstr "" +msgstr "除了 <quote>ssh_use_certificate_keys</quote> 之外,選項" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sss_ssh_authorizedkeys.1.xml:96 @@ -14177,6 +16334,8 @@ msgid "" "<citerefentry><refentrytitle>sssd.conf</refentrytitle> " "<manvolnum>5</manvolnum></citerefentry> for details)." msgstr "" +"可以用來控制憑證的驗證方式(詳細資料請參閱 <citerefentry><refentrytitle>" +"sssd.conf</refentrytitle> <manvolnum>5</manvolnum></citerefentry>)。" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sss_ssh_authorizedkeys.1.xml:101 @@ -14191,6 +16350,12 @@ msgid "" "on the Smartcard is already expired because neither <command>ssh</command> " "nor <command>sshd</command> will look at the certificate at all." msgstr "" +"驗證是使用 X.509 憑證而非直接使用 SSH 金鑰的好處,例如它提供對金鑰生命週期更" +"好的控制。當 ssh 用戶端在 PKCS#11 共用程式庫的協助下設定為使用 Smartcard 的私" +"密金鑰(詳細資料請參閱 <citerefentry><refentrytitle>ssh</refentrytitle> " +"<manvolnum>1</manvolnum></citerefentry>)時,即使 Smartcard 上的相關 X.509 憑" +"證已過期,驗證仍然有效,這可能令人困擾,因為 <command>ssh</command> 與 " +"<command>sshd</command> 都不會檢視憑證。" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sss_ssh_authorizedkeys.1.xml:114 @@ -14200,30 +16365,32 @@ msgid "" "certificate validation if the <command>sshd</command> configuration permits " "this." msgstr "" +"必須注意,若 <command>sshd</command> 設定允許,衍生的公開 SSH 金鑰仍然可以加" +"入使用者的 <filename>authorized_keys</filename> 檔案以略過憑證驗證。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_ssh_authorizedkeys.1.xml:132 msgid "" "Search for user public keys in SSSD domain " "<replaceable>DOMAIN</replaceable>." -msgstr "" +msgstr "在 SSSD 網域 <replaceable>DOMAIN</replaceable> 中搜尋使用者公開金鑰。" #. type: Content of: <reference><refentry><refsect1><para> #: sss_ssh_authorizedkeys.1.xml:143 sss_ssh_knownhostsproxy.1.xml:114 msgid "" "In case of success, an exit value of 0 is returned. Otherwise, 1 is " "returned." -msgstr "" +msgstr "成功時傳回退出值 0。否則傳回 1。" #. type: Content of: <reference><refentry><refnamediv><refname> #: sss_ssh_knownhosts.1.xml:10 sss_ssh_knownhosts.1.xml:15 msgid "sss_ssh_knownhosts" -msgstr "" +msgstr "sss_ssh_knownhosts" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sss_ssh_knownhosts.1.xml:16 msgid "get OpenSSH known hosts public keys" -msgstr "" +msgstr "取得 OpenSSH 已知主機的公開金鑰" #. type: Content of: <reference><refentry><refsynopsisdiv><cmdsynopsis> #: sss_ssh_knownhosts.1.xml:21 @@ -14232,6 +16399,9 @@ msgid "" "<replaceable>options</replaceable> </arg> <arg " "choice='plain'><replaceable>HOST</replaceable></arg>" msgstr "" +"<command>sss_ssh_knownhosts</command> <arg choice='opt'> <replaceable>" +"options</replaceable> </arg> <arg choice='plain'><replaceable>HOST</" +"replaceable></arg>" #. type: Content of: <reference><refentry><refsect1><para> #: sss_ssh_knownhosts.1.xml:32 @@ -14242,6 +16412,11 @@ msgid "" "<citerefentry><refentrytitle>sshd</refentrytitle> " "<manvolnum>8</manvolnum></citerefentry> for more information)." msgstr "" +"<command>sss_ssh_knownhosts</command> 取得主機 <replaceable>HOST</" +"replaceable> 的 SSH 公開金鑰,並以 OpenSSH known_hosts 金鑰格式輸出(更多資訊" +"請參閱 <citerefentry><refentrytitle>sshd</refentrytitle> <manvolnum>8</" +"manvolnum></citerefentry> 的 <quote>SSH_KNOWN_HOSTS FILE FORMAT</quote> 一節" +")。" #. type: Content of: <reference><refentry><refsect1><para><programlisting> #: sss_ssh_knownhosts.1.xml:47 @@ -14250,6 +16425,8 @@ msgid "" " KnownHostsCommand /usr/bin/sss_ssh_knownhosts %H\n" " " msgstr "" +" KnownHostsCommand /usr/bin/sss_ssh_knownhosts %H\n" +" " #. type: Content of: <reference><refentry><refsect1><para> #: sss_ssh_knownhosts.1.xml:41 @@ -14262,18 +16439,24 @@ msgid "" "<refentrytitle>ssh_config</refentrytitle><manvolnum>5</manvolnum> " "</citerefentry> man page for more details about this option." msgstr "" +"使用 <quote>KnownHostsCommand</quote> 選項,可以設定 <citerefentry>" +"<refentrytitle>ssh</refentrytitle> <manvolnum>1</manvolnum></citerefentry> 使" +"用 <command>sss_ssh_knownhosts</command> 進行公開金鑰主機驗證:<placeholder " +"type=\"programlisting\" id=\"0\"/> 此選項的更多詳細資料請參閱 <citerefentry> " +"<refentrytitle>ssh_config</refentrytitle><manvolnum>5</manvolnum> </" +"citerefentry> 手冊頁。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_ssh_knownhosts.1.xml:65 sss_ssh_knownhostsproxy.1.xml:93 msgid "" "Search for host public keys in SSSD domain " "<replaceable>DOMAIN</replaceable>." -msgstr "" +msgstr "在 SSSD 網域 <replaceable>DOMAIN</replaceable> 中搜尋主機公開金鑰。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_ssh_knownhosts.1.xml:72 msgid "<option>-o</option>,<option>--only-host-name</option>" -msgstr "" +msgstr "<option>-o</option>,<option>--only-host-name</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_ssh_knownhosts.1.xml:76 @@ -14282,11 +16465,13 @@ msgid "" "tool will add the unmodified hostname as provided by the caller. If this " "flag is set, only the hostname (no port number) will be added to the keys." msgstr "" +"當從後端擷取的金鑰不包含主機名稱時,此工具會加入呼叫者提供的未修改主機名稱。" +"若設定此旗標,只會將主機名稱(沒有連接埠號碼)加入金鑰。" #. type: Content of: <reference><refentry><refsect1><title> #: sss_ssh_knownhosts.1.xml:88 msgid "KEY RETRIEVAL" -msgstr "" +msgstr "金鑰擷取" #. type: Content of: <reference><refentry><refsect1><para> #: sss_ssh_knownhosts.1.xml:90 @@ -14301,6 +16486,12 @@ msgid "" "number), depending on whether the " "<option>-o</option>,<option>--only-host-name</option> option was provided." msgstr "" +"從後端擷取的金鑰行預期遵循 <citerefentry><refentrytitle>sshd</refentrytitle> " +"<manvolnum>8</manvolnum></citerefentry> 之 <quote>SSH_KNOWN_HOSTS FILE " +"FORMAT</quote> 一節所述的金鑰格式。不過,只傳回金鑰類型與金鑰本身也可接受,這" +"種情況下,作為參數收到的主機名稱會加在金鑰類型前面,以輸出格式正確的行。主機" +"名稱會以未修改的形式加入,或只加入主機名稱(沒有連接埠號碼),視是否提供 " +"<option>-o</option>,<option>--only-host-name</option> 選項而定。" #. type: Content of: <reference><refentry><refsect1><para><programlisting> #: sss_ssh_knownhosts.1.xml:107 @@ -14310,6 +16501,9 @@ msgid "" "<base64-encoded key>\n" " " msgstr "" +" [canonical.host.name]:2222 <keytype> <base64-" +"encoded key>\n" +" " #. type: Content of: <reference><refentry><refsect1><para> #: sss_ssh_knownhosts.1.xml:102 @@ -14319,23 +16513,26 @@ msgid "" "position as part of the key line. For example, the minimal key line would " "be: <placeholder type=\"programlisting\" id=\"0\"/>" msgstr "" +"當 SSH 伺服器監聽非預設連接埠時,後端必須以正確的格式與位置提供包含連接埠號碼" +"的主機名稱,作為金鑰行的一部分。例如,最小的金鑰行會是:<placeholder " +"type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para> #: sss_ssh_knownhosts.1.xml:115 msgid "" "In case of successful execution, even if no key was found, 0 is returned. 1 " "is returned in case of error." -msgstr "" +msgstr "執行成功時,即使沒有找到金鑰,也會傳回 0。發生錯誤時傳回 1。" #. type: Content of: <reference><refentry><refnamediv><refname> #: sss_ssh_knownhostsproxy.1.xml:10 sss_ssh_knownhostsproxy.1.xml:15 msgid "sss_ssh_knownhostsproxy" -msgstr "" +msgstr "sss_ssh_knownhostsproxy" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sss_ssh_knownhostsproxy.1.xml:16 msgid "get OpenSSH host keys" -msgstr "" +msgstr "取得 OpenSSH 主機金鑰" #. type: Content of: <reference><refentry><refsynopsisdiv><cmdsynopsis> #: sss_ssh_knownhostsproxy.1.xml:21 @@ -14345,11 +16542,15 @@ msgid "" "choice='plain'><replaceable>HOST</replaceable></arg> <arg " "choice='opt'><replaceable>PROXY_COMMAND</replaceable></arg>" msgstr "" +"<command>sss_ssh_knownhostsproxy</command> <arg choice='opt'> <replaceable>" +"options</replaceable> </arg> <arg choice='plain'><replaceable>HOST</" +"replaceable></arg> <arg choice='opt'><replaceable>PROXY_COMMAND</replaceable>" +"</arg>" #. type: Content of: <reference><refentry><refsect1><title> #: sss_ssh_knownhostsproxy.1.xml:31 msgid "LIFE-CYCLE" -msgstr "" +msgstr "生命週期" #. type: Content of: <reference><refentry><refsect1><para> #: sss_ssh_knownhostsproxy.1.xml:33 @@ -14357,6 +16558,8 @@ msgid "" "This tool is deprecated and will be removed in the future. Consider using " "the more reliable <command>sss_ssh_knownhosts</command> instead." msgstr "" +"此工具已棄用,未來將移除。請考慮改用更可靠的 <command>sss_ssh_knownhosts</" +"command>。" #. type: Content of: <reference><refentry><refsect1><para> #: sss_ssh_knownhostsproxy.1.xml:43 @@ -14369,6 +16572,12 @@ msgid "" "<filename>/var/lib/sss/pubconf/known_hosts</filename> and establishes the " "connection to the host." msgstr "" +"<command>sss_ssh_knownhostsproxy</command> 取得主機 <replaceable>HOST</" +"replaceable> 的 SSH 主機公開金鑰,將它們儲存在自訂的 OpenSSH known_hosts 檔" +"案 <filename>/var/lib/sss/pubconf/known_hosts</filename>(更多資訊請參閱 " +"<citerefentry><refentrytitle>sshd</refentrytitle> <manvolnum>8</manvolnum></" +"citerefentry> 的 <quote>SSH_KNOWN_HOSTS FILE FORMAT</quote> 一節),並與主機" +"建立連線。" #. type: Content of: <reference><refentry><refsect1><para> #: sss_ssh_knownhostsproxy.1.xml:53 @@ -14376,6 +16585,8 @@ msgid "" "If <replaceable>PROXY_COMMAND</replaceable> is specified, it is used to " "create the connection to the host instead of opening a socket." msgstr "" +"若指定 <replaceable>PROXY_COMMAND</replaceable>,會使用它建立與主機的連線,而" +"不是開啟 socket。" #. type: Content of: <reference><refentry><refsect1><para><programlisting> #: sss_ssh_knownhostsproxy.1.xml:65 @@ -14384,6 +16595,8 @@ msgid "" "ProxyCommand /usr/bin/sss_ssh_knownhostsproxy -p %p %h\n" "GlobalKnownHostsFile /var/lib/sss/pubconf/known_hosts\n" msgstr "" +"ProxyCommand /usr/bin/sss_ssh_knownhostsproxy -p %p %h\n" +"GlobalKnownHostsFile /var/lib/sss/pubconf/known_hosts\n" #. type: Content of: <reference><refentry><refsect1><para> #: sss_ssh_knownhostsproxy.1.xml:58 @@ -14396,38 +16609,44 @@ msgid "" "<manvolnum>1</manvolnum></citerefentry> configuration: <placeholder " "type=\"programlisting\" id=\"0\"/>" msgstr "" +"使用下列 <citerefentry><refentrytitle>ssh</refentrytitle> <manvolnum>1</" +"manvolnum></citerefentry> 設定指示,可以設定 <citerefentry><refentrytitle>" +"ssh</refentrytitle> <manvolnum>1</manvolnum></citerefentry> 使用 <command>" +"sss_ssh_knownhostsproxy</command> 進行主機金鑰驗證:<placeholder " +"type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_ssh_knownhostsproxy.1.xml:76 msgid "<option>-p</option>,<option>--port</option> <replaceable>PORT</replaceable>" msgstr "" +"<option>-p</option>,<option>--port</option> <replaceable>PORT</replaceable>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_ssh_knownhostsproxy.1.xml:81 msgid "" "Use port <replaceable>PORT</replaceable> to connect to the host. By " "default, port 22 is used." -msgstr "" +msgstr "使用連接埠 <replaceable>PORT</replaceable> 連線到主機。依預設使用連接埠 22。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_ssh_knownhostsproxy.1.xml:99 msgid "<option>-k</option>,<option>--pubkey</option>" -msgstr "" +msgstr "<option>-k</option>,<option>--pubkey</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_ssh_knownhostsproxy.1.xml:103 msgid "Print the host ssh public keys for host <replaceable>HOST</replaceable>." -msgstr "" +msgstr "列印主機 <replaceable>HOST</replaceable> 的主機 SSH 公開金鑰。" #. type: Content of: <reference><refentry><refnamediv><refname> #: idmap_sss.8.xml:10 idmap_sss.8.xml:15 msgid "idmap_sss" -msgstr "" +msgstr "idmap_sss" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: idmap_sss.8.xml:16 msgid "SSSD's idmap_sss Backend for Winbind" -msgstr "" +msgstr "用於 Winbind 的 SSSD idmap_sss 後端" #. type: Content of: <reference><refentry><refsect1><para> #: idmap_sss.8.xml:22 @@ -14435,28 +16654,30 @@ msgid "" "The idmap_sss module provides a way to call SSSD to map UIDs/GIDs and " "SIDs. No database is required in this case as the mapping is done by SSSD." msgstr "" +"idmap_sss 模組提供呼叫 SSSD 對應 UID/GID 與 SID 的方式。這種情況下不需要資料" +"庫,因為對應由 SSSD 執行。" #. type: Content of: <reference><refentry><refsect1><title> #: idmap_sss.8.xml:29 msgid "IDMAP OPTIONS" -msgstr "" +msgstr "IDMAP 選項" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: idmap_sss.8.xml:33 msgid "range = low - high" -msgstr "" +msgstr "range = low - high" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: idmap_sss.8.xml:35 msgid "" "Defines the available matching UID and GID range for which the backend is " "authoritative." -msgstr "" +msgstr "定義後端具有權威性的可用符合 UID 與 GID 範圍。" #. type: Content of: <reference><refentry><refsect1><para> #: idmap_sss.8.xml:45 msgid "This example shows how to configure idmap_sss as the default mapping module." -msgstr "" +msgstr "此範例顯示如何將 idmap_sss 設定為預設對應模組。" #. type: Content of: <reference><refentry><refsect1><programlisting> #: idmap_sss.8.xml:50 @@ -14474,6 +16695,17 @@ msgid "" "idmap config * : range = 100000-199999\n" " " msgstr "" +"[global]\n" +"security = ads\n" +"workgroup = <AD-DOMAIN-SHORTNAME>\n" +"\n" +"idmap config <AD-DOMAIN-SHORTNAME> : backend = sss\n" +"idmap config <AD-DOMAIN-SHORTNAME> : range = 200000-" +"2147483647\n" +"\n" +"idmap config * : backend = tdb\n" +"idmap config * : range = 100000-199999\n" +" " #. type: Content of: <reference><refentry><refsect1><para> #: idmap_sss.8.xml:62 @@ -14483,6 +16715,9 @@ msgid "" "<literal>idmap config</literal> line with <literal>backend = sss</literal> " "and a line with a suitable <literal>range</literal>." msgstr "" +"請將 <AD-DOMAIN-SHORTNAME> 取代為 AD 網域的 NetBIOS 網域名稱。若應該使" +"用多個 AD 網域,每個網域都需要一行 <literal>idmap config</literal>,其中包含 " +"<literal>backend = sss</literal>,以及一行合適的 <literal>range</literal>。" #. type: Content of: <reference><refentry><refsect1><para> #: idmap_sss.8.xml:69 @@ -14490,16 +16725,18 @@ msgid "" "Since Winbind requires a writeable default backend and idmap_sss is " "read-only the example includes <literal>backend = tdb</literal> as default." msgstr "" +"由於 Winbind 需要可寫入的預設後端,而 idmap_sss 是唯讀的,範例包含 <literal>" +"backend = tdb</literal> 作為預設。" #. type: Content of: <reference><refentry><refnamediv><refname> #: sssctl.8.xml:10 sssctl.8.xml:15 msgid "sssctl" -msgstr "" +msgstr "sssctl" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sssctl.8.xml:16 msgid "SSSD control and status utility" -msgstr "" +msgstr "SSSD 控制與狀態公用程式" #. type: Content of: <reference><refentry><refsynopsisdiv><cmdsynopsis> #: sssctl.8.xml:21 @@ -14508,6 +16745,9 @@ msgid "" "choice='plain'><replaceable>COMMAND</replaceable></arg> <arg choice='opt'> " "<replaceable>options</replaceable> </arg>" msgstr "" +"<command>sssctl</command> <arg choice='plain'><replaceable>COMMAND</" +"replaceable></arg> <arg choice='opt'> <replaceable>options</replaceable> </" +"arg>" #. type: Content of: <reference><refentry><refsect1><para> #: sssctl.8.xml:32 @@ -14518,6 +16758,9 @@ msgid "" "files for troubleshooting in such a way that is safe to manipulate while " "SSSD is running." msgstr "" +"<command>sssctl</command> 提供取得 SSSD 狀態資訊(例如作用中伺服器、自動探索" +"的伺服器、網域與快取物件)的簡單統一方式。此外,它可以管理 SSSD 資料檔案以進" +"行疑難排解,而且這種方式在 SSSD 執行期間操作是安全的。" #. type: Content of: <reference><refentry><refsect1><para> #: sssctl.8.xml:43 @@ -14526,16 +16769,18 @@ msgid "" "parameters. To print help for selected command run <command>sssctl COMMAND " "--help</command>." msgstr "" +"要列出所有可用的指令,請在沒有任何參數的情況下執行 <command>sssctl</command>" +"。要列印所選指令的說明,請執行 <command>sssctl COMMAND --help</command>。" #. type: Content of: <reference><refentry><refnamediv><refname> #: sssd-files.5.xml:10 sssd-files.5.xml:16 msgid "sssd-files" -msgstr "" +msgstr "sssd-files" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sssd-files.5.xml:17 msgid "SSSD files provider" -msgstr "" +msgstr "SSSD files 提供者" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-files.5.xml:23 @@ -14547,6 +16792,10 @@ msgid "" "<refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</manvolnum> " "</citerefentry> manual page." msgstr "" +"本手冊頁說明 <citerefentry> <refentrytitle>sssd</refentrytitle> <manvolnum>" +"8</manvolnum> </citerefentry> 的 files 提供者。詳細的語法參考請參閱 " +"<citerefentry> <refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry> 手冊頁的 <quote>FILE FORMAT</quote> 一節。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-files.5.xml:36 @@ -14560,11 +16809,17 @@ msgid "" "<citerefentry> <refentrytitle>sssd-ifp</refentrytitle> " "<manvolnum>5</manvolnum> </citerefentry>." msgstr "" +"files 提供者鏡像 <citerefentry> <refentrytitle>passwd</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry> 與 <citerefentry> <refentrytitle>" +"group</refentrytitle> <manvolnum>5</manvolnum> </citerefentry> 檔案的內容。" +"files 提供者的目的是讓傳統上只能透過 NSS 介面存取的使用者與群組,也能透過 " +"SSSD 介面(例如 <citerefentry> <refentrytitle>sssd-ifp</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry>)存取。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-files.5.xml:55 msgid "Another reason is to provide efficient caching of local users and groups." -msgstr "" +msgstr "另一個原因是提供本機使用者與群組的有效率快取。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-files.5.xml:58 @@ -14574,6 +16829,9 @@ msgid "" "<citerefentry> <refentrytitle>sssd.conf</refentrytitle> " "<manvolnum>5</manvolnum> </citerefentry> for details." msgstr "" +"請注意,除了明確的網域定義之外,files 提供者也可以使用 'enable_files_domain' " +"選項隱式設定。詳細資料請參閱 <citerefentry> <refentrytitle>sssd.conf</" +"refentrytitle> <manvolnum>5</manvolnum> </citerefentry>。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-files.5.xml:66 @@ -14582,6 +16840,8 @@ msgid "" "UID/GID 0 is not handled by SSSD. Such requests are passed to next NSS " "module (usually files)." msgstr "" +"SSSD 永遠不處理使用者/群組 \"root\" 的解析。SSSD 也不處理 UID/GID 0 的解析。" +"這類要求會傳給下一個 NSS 模組(通常是 files)。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-files.5.xml:71 @@ -14589,11 +16849,13 @@ msgid "" "When SSSD is not running or responding, nss_sss returns the UNAVAIL code " "which causes the request to be passed to the next module." msgstr "" +"當 SSSD 未執行或未回應時,nss_sss 會傳回 UNAVAIL 代碼,導致要求傳給下一個模組" +"。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-files.5.xml:95 msgid "passwd_files (string)" -msgstr "" +msgstr "passwd_files (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-files.5.xml:98 @@ -14602,16 +16864,18 @@ msgid "" "enumerated by the files provider, inotify monitor watches will be set on " "each file to detect changes dynamically." msgstr "" +"要由 files 提供者讀取與列舉之一個或多個密碼檔名稱的逗號分隔清單,每個檔案上都" +"會設定 inotify 監視器以動態偵測變更。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-files.5.xml:104 msgid "Default: /etc/passwd" -msgstr "" +msgstr "預設:/etc/passwd" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-files.5.xml:110 msgid "group_files (string)" -msgstr "" +msgstr "group_files (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-files.5.xml:113 @@ -14620,16 +16884,18 @@ msgid "" "enumerated by the files provider, inotify monitor watches will be set on " "each file to detect changes dynamically." msgstr "" +"要由 files 提供者讀取與列舉之一個或多個群組檔名稱的逗號分隔清單,每個檔案上都" +"會設定 inotify 監視器以動態偵測變更。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-files.5.xml:119 msgid "Default: /etc/group" -msgstr "" +msgstr "預設:/etc/group" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-files.5.xml:125 msgid "fallback_to_nss (boolean)" -msgstr "" +msgstr "fallback_to_nss (boolean)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-files.5.xml:128 @@ -14640,6 +16906,10 @@ msgid "" "<filename>/etc/group</filename> and the NSS configuration has 'sss' before " "'files' for the 'passwd' and 'group' maps." msgstr "" +"在更新內部資料時,SSSD 會傳回錯誤並讓用戶端繼續使用下一個 NSS 模組。當使用預" +"設系統檔案 <filename>/etc/passwd</filename> 與 <filename>/etc/group</" +"filename>,且 NSS 設定在 'passwd' 與 'group' 對應中將 'sss' 放在 'files' 前面" +"時,這有助於避免延遲。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-files.5.xml:138 @@ -14648,6 +16918,8 @@ msgid "" "set this option to 'False' to avoid inconsistent behavior because in general " "there would be no other NSS module which can be used as a fallback." msgstr "" +"若 files 提供者設定為監視其他檔案,將此選項設為 'False' 以避免不一致的行為是" +"合理的,因為一般來說沒有其他 NSS 模組可以作為退回使用。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-files.5.xml:79 @@ -14664,6 +16936,13 @@ msgid "" "domain unless explicitly specified per-domain. <placeholder " "type=\"variablelist\" id=\"0\"/>" msgstr "" +"除了下列列出的選項之外,可以在適用的地方設定一般 SSSD 網域選項。SSSD 網域設定" +"的詳細資料請參閱 <citerefentry> <refentrytitle>sssd.conf</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry> 手冊頁的 <quote>DOMAIN SECTIONS</" +"quote> 一節。但 files 提供者的目的是透過 SSSD 介面公開與 UNIX 檔案相同的資料" +"。因此並非所有一般網域選項都支援。同樣地,某些全域選項(例如在 <quote>nss</" +"quote> 區段中為所有網域覆寫 shell)對 files 網域沒有影響,除非明確按網域指定" +"。<placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-files.5.xml:157 @@ -14671,6 +16950,8 @@ msgid "" "The following example assumes that SSSD is correctly configured and files is " "one of the domains in the <replaceable>[sssd]</replaceable> section." msgstr "" +"下列範例假設 SSSD 已正確設定,且 files 是 <replaceable>[sssd]</replaceable> " +"區段中的其中一個網域。" #. type: Content of: <reference><refentry><refsect1><para><programlisting> #: sssd-files.5.xml:163 @@ -14679,6 +16960,8 @@ msgid "" "[domain/files]\n" "id_provider = files\n" msgstr "" +"[domain/files]\n" +"id_provider = files\n" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-files.5.xml:168 @@ -14686,6 +16969,8 @@ msgid "" "To leverage caching of local users and groups by SSSD nss_sss module must be " "listed before nss_files module in /etc/nsswitch.conf." msgstr "" +"要充分運用 SSSD 對本機使用者與群組的快取,/etc/nsswitch.conf 中 nss_sss 模組" +"必須列在 nss_files 模組前面。" #. type: Content of: <reference><refentry><refsect1><para><programlisting> #: sssd-files.5.xml:174 @@ -14694,16 +16979,18 @@ msgid "" "passwd: sss files\n" "group: sss files\n" msgstr "" +"passwd: sss files\n" +"group: sss files\n" #. type: Content of: <reference><refentry><refnamediv><refname> #: sssd-session-recording.5.xml:10 sssd-session-recording.5.xml:16 msgid "sssd-session-recording" -msgstr "" +msgstr "sssd-session-recording" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sssd-session-recording.5.xml:17 msgid "Configuring session recording with SSSD" -msgstr "" +msgstr "使用 SSSD 設定工作階段錄製" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-session-recording.5.xml:23 @@ -14717,6 +17004,13 @@ msgid "" "section of the <citerefentry> <refentrytitle>sssd.conf</refentrytitle> " "<manvolnum>5</manvolnum> </citerefentry> manual page." msgstr "" +"本手冊頁說明如何設定 <citerefentry> <refentrytitle>sssd</refentrytitle> " +"<manvolnum>8</manvolnum> </citerefentry> 與 tlog 套件的 <citerefentry> " +"<refentrytitle>tlog-rec-session</refentrytitle> <manvolnum>8</manvolnum> </" +"citerefentry> 搭配運作,以在文字終端機上實作使用者工作階段錄製。詳細的設定語" +"法參考請參閱 <citerefentry> <refentrytitle>sssd.conf</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry> 手冊頁的 <quote>FILE FORMAT</quote> " +"一節。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-session-recording.5.xml:41 @@ -14727,6 +17021,9 @@ msgid "" "tlog-rec-session is started upon user login, so it can record according to " "its configuration." msgstr "" +"SSSD 可以設定為啟用特定使用者在文字終端機工作階段期間看到或輸入的一切內容的錄" +"製。例如使用者透過主控台或 SSH 登入時。SSSD 本身不錄製任何內容,但確保使用者" +"在登入時啟動 tlog-rec-session,以便它根據其設定進行錄製。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-session-recording.5.xml:48 @@ -14737,11 +17034,15 @@ msgid "" "tlog-rec-session can be started in place of the user shell, and know which " "actual shell to start, once it set up the recording." msgstr "" +"對啟用工作階段錄製的使用者,SSSD 在 NSS 回應中將使用者 shell 取代為 tlog-rec-" +"session,並在 PAM 工作階段設定時,將指定原始 shell 的變數加入使用者環境。這" +"樣 tlog-rec-session 可以取代使用者 shell 啟動,並在設定好錄製後知道要啟動哪個" +"實際的 shell。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-session-recording.5.xml:60 msgid "These options can be used to configure the session recording." -msgstr "" +msgstr "這些選項可用於設定工作階段錄製。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-session-recording.5.xml:178 @@ -14749,6 +17050,8 @@ msgid "" "The following snippet of sssd.conf enables session recording for users " "\"contractor1\" and \"contractor2\", and group \"students\"." msgstr "" +"下列 sssd.conf 片段為使用者 \"contractor1\" 與 \"contractor2\",以及群組 " +"\"students\" 啟用工作階段錄製。" #. type: Content of: <reference><refentry><refsect1><para><programlisting> #: sssd-session-recording.5.xml:183 @@ -14759,16 +17062,20 @@ msgid "" "users = contractor1, contractor2\n" "groups = students\n" msgstr "" +"[session_recording]\n" +"scope = some\n" +"users = contractor1, contractor2\n" +"groups = students\n" #. type: Content of: <reference><refentry><refnamediv><refname> #: sssd-kcm.8.xml:10 sssd-kcm.8.xml:16 msgid "sssd-kcm" -msgstr "" +msgstr "sssd-kcm" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sssd-kcm.8.xml:17 msgid "SSSD Kerberos Cache Manager" -msgstr "" +msgstr "SSSD Kerberos 快取管理員" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-kcm.8.xml:23 @@ -14779,6 +17086,9 @@ msgid "" "the MIT Kerberos library also provides client side (more details on that " "below) support for the KCM credential cache." msgstr "" +"本手冊頁說明 SSSD Kerberos 快取管理員 (KCM) 的設定。KCM 是儲存、追蹤與管理 " +"Kerberos 憑證快取的程序。它起源於 Heimdal Kerberos 專案,不過 MIT Kerberos 程" +"式庫也提供 KCM 憑證快取的用戶端(下面有更多詳細資料)支援。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-kcm.8.xml:31 @@ -14790,6 +17100,10 @@ msgid "" "being referred to as a <quote>\"KCM server\"</quote>. The client and server " "communicate over a UNIX socket." msgstr "" +"在由 KCM 管理 Kerberos 快取的設定中,Kerberos 程式庫(通常透過應用程式使用," +"例如 <citerefentry> <refentrytitle>kinit</refentrytitle><manvolnum>1</" +"manvolnum> </citerefentry>)是 <quote>\"KCM client\"</quote>,KCM 常駐程式被" +"稱為 <quote>\"KCM server\"</quote>。用戶端與伺服器透過 UNIX socket 通訊。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-kcm.8.xml:42 @@ -14798,18 +17112,20 @@ msgid "" "access check control based on the UID and GID of the KCM client. The root " "user has access to all credential caches." msgstr "" +"KCM 伺服器追蹤每個憑證快取的所有者,並根據 KCM 用戶端的 UID 與 GID 執行存取檢" +"查控制。root 使用者可以存取所有憑證快取。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-kcm.8.xml:47 msgid "The KCM credential cache has several interesting properties:" -msgstr "" +msgstr "KCM 憑證快取有幾個有趣的屬性:" #. type: Content of: <reference><refentry><refsect1><para><itemizedlist><listitem><para> #: sssd-kcm.8.xml:51 msgid "" "since the process runs in userspace, it is subject to UID namespacing, " "unlike the kernel keyring" -msgstr "" +msgstr "由於程序在使用者空間執行,它受 UID 命名空間影響,不像核心 keyring" #. type: Content of: <reference><refentry><refsect1><para><itemizedlist><listitem><para> #: sssd-kcm.8.xml:56 @@ -14818,6 +17134,8 @@ msgid "" "containers, the KCM server is a separate process whose entry point is a UNIX " "socket" msgstr "" +"不像在所有容器之間共用的核心 keyring 型快取,KCM 伺服器是獨立的程序,其進入點" +"是 UNIX socket" #. type: Content of: <reference><refentry><refsect1><para><itemizedlist><listitem><para> #: sssd-kcm.8.xml:61 @@ -14826,6 +17144,9 @@ msgid "" "at <replaceable>/var/lib/sss/secrets</replaceable> allowing the ccaches to " "survive KCM server restarts or machine reboots." msgstr "" +"SSSD 實作將 ccache 儲存在資料庫中,通常位於 <replaceable>/var/lib/sss/" +"secrets</replaceable>,讓 ccache 在 KCM 伺服器重新啟動或機器重新開機後仍能保" +"存。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-kcm.8.xml:67 @@ -14834,6 +17155,8 @@ msgid "" "the credential cache between some or no containers by bind-mounting the " "socket." msgstr "" +"這允許系統使用可感知集合的憑證快取,並透過 bind-mount socket 在部分或沒有容器" +"之間共用憑證快取。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-kcm.8.xml:72 @@ -14841,11 +17164,13 @@ msgid "" "The KCM default client idle timeout is 5 minutes, this allows more time for " "user interaction with command line tools such as kinit." msgstr "" +"KCM 預設用戶端閒置逾時為 5 分鐘,這允許更多時間讓使用者與 kinit 等命令列工具" +"互動。" #. type: Content of: <reference><refentry><refsect1><title> #: sssd-kcm.8.xml:78 msgid "USING THE KCM CREDENTIAL CACHE" -msgstr "" +msgstr "使用 KCM 憑證快取" #. type: Content of: <reference><refentry><refsect1><para><programlisting> #: sssd-kcm.8.xml:88 @@ -14855,6 +17180,9 @@ msgid "" " default_ccache_name = KCM:\n" " " msgstr "" +"[libdefaults]\n" +" default_ccache_name = KCM:\n" +" " #. type: Content of: <reference><refentry><refsect1><para> #: sssd-kcm.8.xml:80 @@ -14866,6 +17194,10 @@ msgid "" "without any template expansions. For example: <placeholder " "type=\"programlisting\" id=\"0\"/>" msgstr "" +"要使用 KCM 憑證快取,必須在 <citerefentry> <refentrytitle>krb5.conf</" +"refentrytitle><manvolnum>5</manvolnum> </citerefentry> 中將它選為預設憑證類型" +"。憑證快取名稱必須只有 <quote>KCM:</quote>,沒有任何範本展開。例如" +":<placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-kcm.8.xml:93 @@ -14878,6 +17210,11 @@ msgid "" "<refentrytitle>krb5.conf</refentrytitle><manvolnum>5</manvolnum> " "</citerefentry> manual page." msgstr "" +"接下來,確保 Kerberos 用戶端程式庫與 KCM 伺服器在 UNIX socket 路徑上必須一致" +"。依預設,兩者都使用相同的路徑 <replaceable>/var/run/.heim_org.h5l.kcm-" +"socket</replaceable>。若要設定 Kerberos 程式庫,請變更其 <quote>kcm_socket</" +"quote> 選項,該選項在 <citerefentry> <refentrytitle>krb5.conf</refentrytitle>" +"<manvolnum>5</manvolnum> </citerefentry> 手冊頁中有說明。" #. type: Content of: <reference><refentry><refsect1><para><programlisting> #: sssd-kcm.8.xml:115 @@ -14887,6 +17224,9 @@ msgid "" "systemctl enable sssd-kcm.socket\n" " " msgstr "" +"systemctl start sssd-kcm.socket\n" +"systemctl enable sssd-kcm.socket\n" +" " #. type: Content of: <reference><refentry><refsect1><para> #: sssd-kcm.8.xml:104 @@ -14899,11 +17239,17 @@ msgid "" "<placeholder type=\"programlisting\" id=\"0\"/> Please note your " "distribution may already configure the units for you." msgstr "" +"最後,確保可以連絡 SSSD KCM 伺服器。KCM 服務通常由 <citerefentry> " +"<refentrytitle>systemd</refentrytitle> <manvolnum>1</manvolnum> </" +"citerefentry> 以 socket 啟動。與其他 SSSD 服務不同,它不能透過將 <quote>kcm</" +"quote> 字串加入 <quote>service</quote> 指示來啟動。<placeholder " +"type=\"programlisting\" id=\"0\"/> 請注意,您的發行版可能已為您設定好這些 " +"unit。" #. type: Content of: <reference><refentry><refsect1><title> #: sssd-kcm.8.xml:124 msgid "THE CREDENTIAL CACHE STORAGE" -msgstr "" +msgstr "憑證快取儲存" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-kcm.8.xml:126 @@ -14912,11 +17258,13 @@ msgid "" "or group entries. The database is typically located at " "<quote>/var/lib/sss/secrets</quote>." msgstr "" +"憑證快取儲存在資料庫中,很像 SSSD 快取使用者或群組項目。資料庫通常位於 " +"<quote>/var/lib/sss/secrets</quote>。" #. type: Content of: <reference><refentry><refsect1><title> #: sssd-kcm.8.xml:133 msgid "OBTAINING DEBUG LOGS" -msgstr "" +msgstr "取得除錯記錄" #. type: Content of: <reference><refentry><refsect1><para><programlisting> #: sssd-kcm.8.xml:144 @@ -14926,6 +17274,9 @@ msgid "" "debug_level = 10\n" " " msgstr "" +"[kcm]\n" +"debug_level = 10\n" +" " #. type: Content of: <reference><refentry><refsect1><para><programlisting> #: sssd-kcm.8.xml:149 sssd-kcm.8.xml:211 @@ -14934,6 +17285,8 @@ msgid "" "systemctl restart sssd-kcm.service\n" " " msgstr "" +"systemctl restart sssd-kcm.service\n" +" " #. type: Content of: <reference><refentry><refsect1><para> #: sssd-kcm.8.xml:135 @@ -14951,6 +17304,14 @@ msgid "" "as the sssd-kcm service can generate quite a large amount of debugging " "information." msgstr "" +"sssd-kcm 服務通常由 <citerefentry> <refentrytitle>systemd</refentrytitle> " +"<manvolnum>1</manvolnum> </citerefentry> 以 socket 啟動。要產生除錯記錄,請將" +"下列內容直接加入 <filename>/etc/sssd/sssd.conf</filename> 檔案,或作為設定片" +"段加入 <filename>/etc/sssd/conf.d/</filename> 目錄:<placeholder " +"type=\"programlisting\" id=\"0\"/> 然後重新啟動 sssd-kcm 服務:<placeholder " +"type=\"programlisting\" id=\"1\"/> 最後,執行對您來說無法運作的任何使用案例。" +"KCM 記錄會在 <filename>/var/log/sssd/sssd_kcm.log</filename> 產生。建議在不再" +"需要除錯時停用除錯記錄,因為 sssd-kcm 服務可能產生相當大量的除錯資訊。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-kcm.8.xml:159 @@ -14959,11 +17320,13 @@ msgid "" "if the main configuration file at <filename>/etc/sssd/sssd.conf</filename> " "exists at all." msgstr "" +"請注意,目前只有在主要設定檔 <filename>/etc/sssd/sssd.conf</filename> 存在時" +",才會處理設定片段。" #. type: Content of: <reference><refentry><refsect1><title> #: sssd-kcm.8.xml:166 msgid "RENEWALS" -msgstr "" +msgstr "續約" #. type: Content of: <reference><refentry><refsect1><para><programlisting> #: sssd-kcm.8.xml:174 @@ -14973,6 +17336,9 @@ msgid "" "krb5_renew_interval = 60m\n" " " msgstr "" +"tgt_renewal = true\n" +"krb5_renew_interval = 60m\n" +" " #. type: Content of: <reference><refentry><refsect1><para> #: sssd-kcm.8.xml:168 @@ -14983,11 +17349,14 @@ msgid "" "following options are set in the [kcm] section: <placeholder " "type=\"programlisting\" id=\"0\"/>" msgstr "" +"sssd-kcm 服務可以設定為對儲存在 KCM ccache 中可續約的 TGT 嘗試 TGT 續約。只有" +"在票證生命週期過半時才會嘗試續約。在 [kcm] 區段中設定下列選項時,即設定 KCM " +"續約:<placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-kcm.8.xml:179 msgid "SSSD can also inherit krb5 options for renewals from an existing domain." -msgstr "" +msgstr "SSSD 也可以從現有的網域繼承用於續約的 krb5 選項。" #. type: Content of: <reference><refentry><refsect1><programlisting> #: sssd-kcm.8.xml:183 @@ -14997,6 +17366,9 @@ msgid "" "tgt_renewal_inherit = domain-name\n" " " msgstr "" +"tgt_renewal = true\n" +"tgt_renewal_inherit = domain-name\n" +" " #. type: Content of: <reference><refentry><refsect1><para><programlisting> #: sssd-kcm.8.xml:191 @@ -15010,6 +17382,13 @@ msgid "" "krb5_auth_timeout\n" " " msgstr "" +"krb5_renew_interval\n" +"krb5_renewable_lifetime\n" +"krb5_lifetime\n" +"krb5_validate\n" +"krb5_canonicalize\n" +"krb5_auth_timeout\n" +" " #. type: Content of: <reference><refentry><refsect1><para> #: sssd-kcm.8.xml:187 @@ -15018,6 +17397,8 @@ msgid "" "renewal behavior, these options are described in detail below <placeholder " "type=\"programlisting\" id=\"0\"/>" msgstr "" +"可以在 [kcm] 區段中設定下列 krb5 選項以控制續約行為,這些選項在下面詳細說明 " +"<placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-kcm.8.xml:204 @@ -15028,6 +17409,10 @@ msgid "" "service after changing options in the <quote>kcm</quote> section of " "sssd.conf: <placeholder type=\"programlisting\" id=\"0\"/>" msgstr "" +"KCM 服務在 sssd.conf 檔案的 <quote>kcm</quote> 區段中設定。請注意,由於 KCM " +"服務通常以 socket 啟動,變更 sssd.conf 之 <quote>kcm</quote> 區段中的選項後," +"只要重新啟動 <quote>sssd-kcm</quote> 服務即可:<placeholder " +"type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-kcm.8.xml:215 @@ -15037,6 +17422,9 @@ msgid "" "<citerefentry> <refentrytitle>sssd.conf</refentrytitle> " "<manvolnum>5</manvolnum> </citerefentry> manual page." msgstr "" +"KCM 服務在 <quote>kcm</quote> 中設定。詳細的語法參考請參閱 <citerefentry> " +"<refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</manvolnum> </" +"citerefentry> 手冊頁的 <quote>FILE FORMAT</quote> 一節。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-kcm.8.xml:223 @@ -15047,21 +17435,25 @@ msgid "" "<manvolnum>5</manvolnum> </citerefentry> manual page for a complete list. In " "addition, there are some KCM-specific options as well." msgstr "" +"kcm 服務接受 <quote>debug_level</quote> 或 <quote>fd_limit</quote> 等一般 " +"SSSD 服務選項。完整清單請參閱 <citerefentry> <refentrytitle>sssd.conf</" +"refentrytitle> <manvolnum>5</manvolnum> </citerefentry> 手冊頁。此外,也有一" +"些 KCM 專用選項。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd-kcm.8.xml:234 msgid "socket_path (string)" -msgstr "" +msgstr "socket_path (string)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd-kcm.8.xml:237 msgid "The socket the KCM service will listen on." -msgstr "" +msgstr "KCM 服務將在上面監聽的 socket。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd-kcm.8.xml:240 msgid "Default: <replaceable>/var/run/.heim_org.h5l.kcm-socket</replaceable>" -msgstr "" +msgstr "預設:<replaceable>/var/run/.heim_org.h5l.kcm-socket</replaceable>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd-kcm.8.xml:243 @@ -15070,26 +17462,28 @@ msgid "" "supported, the socket path is overwritten by the one defined in the " "sssd-kcm.socket unit file. </phrase>" msgstr "" +"<phrase condition=\"have_systemd\"> 注意:在支援 systemd 的平台上,socket 路" +"徑會被 sssd-kcm.socket unit 檔案中定義的路徑覆寫。 </phrase>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd-kcm.8.xml:252 msgid "max_ccaches (integer)" -msgstr "" +msgstr "max_ccaches (integer)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd-kcm.8.xml:255 msgid "How many credential caches does the KCM database allow for all users." -msgstr "" +msgstr "KCM 資料庫允許所有使用者擁有多少個憑證快取。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd-kcm.8.xml:259 msgid "Default: 0 (unlimited, only the per-UID quota is enforced)" -msgstr "" +msgstr "預設:0(無限制,只執行每個 UID 的配額)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd-kcm.8.xml:264 msgid "max_uid_ccaches (integer)" -msgstr "" +msgstr "max_uid_ccaches (integer)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd-kcm.8.xml:267 @@ -15097,58 +17491,60 @@ msgid "" "How many credential caches does the KCM database allow per UID. This is " "equivalent to <quote>with how many principals you can kinit</quote>." msgstr "" +"KCM 資料庫允許每個 UID 擁有多少個憑證快取。這等同於 <quote>您可以對多少個 " +"principal 執行 kinit</quote>。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd-kcm.8.xml:272 msgid "Default: 64" -msgstr "" +msgstr "預設:64" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd-kcm.8.xml:277 msgid "max_ccache_size (integer)" -msgstr "" +msgstr "max_ccache_size (integer)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd-kcm.8.xml:280 msgid "" "How big can a credential cache be per ccache. Each service ticket accounts " "into this quota." -msgstr "" +msgstr "每個 ccache 的憑證快取可以多大。每個服務票證都會計入此配額。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd-kcm.8.xml:284 msgid "Default: 65536" -msgstr "" +msgstr "預設:65536" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd-kcm.8.xml:289 msgid "tgt_renewal (bool)" -msgstr "" +msgstr "tgt_renewal (bool)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd-kcm.8.xml:292 msgid "Enables TGT renewals functionality." -msgstr "" +msgstr "啟用 TGT 續約功能。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd-kcm.8.xml:295 msgid "Default: False (Automatic renewals disabled)" -msgstr "" +msgstr "預設:False(停用自動續約)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd-kcm.8.xml:300 msgid "tgt_renewal_inherit (string)" -msgstr "" +msgstr "tgt_renewal_inherit (string)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd-kcm.8.xml:303 msgid "Domain to inherit krb5_* options from, for use with TGT renewals." -msgstr "" +msgstr "從中繼承 krb5_* 選項以用於 TGT 續約的網域。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd-kcm.8.xml:307 msgid "Default: NULL" -msgstr "" +msgstr "預設:NULL" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-kcm.8.xml:318 @@ -15158,16 +17554,19 @@ msgid "" "<refentrytitle>sssd.conf</refentrytitle><manvolnum>5</manvolnum> " "</citerefentry>," msgstr "" +"<citerefentry> <refentrytitle>sssd</refentrytitle><manvolnum>8</manvolnum> </" +"citerefentry>, <citerefentry> <refentrytitle>sssd.conf</refentrytitle>" +"<manvolnum>5</manvolnum> </citerefentry>," #. type: Content of: <reference><refentry><refnamediv><refname> #: sssd-systemtap.5.xml:10 sssd-systemtap.5.xml:16 msgid "sssd-systemtap" -msgstr "" +msgstr "sssd-systemtap" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sssd-systemtap.5.xml:17 msgid "SSSD systemtap information" -msgstr "" +msgstr "SSSD systemtap 資訊" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-systemtap.5.xml:23 @@ -15176,6 +17575,8 @@ msgid "" "<citerefentry> <refentrytitle>sssd</refentrytitle> <manvolnum>8</manvolnum> " "</citerefentry>." msgstr "" +"本手冊頁提供 <citerefentry> <refentrytitle>sssd</refentrytitle> <manvolnum>" +"8</manvolnum> </citerefentry> 中 systemtap 功能的資訊。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-systemtap.5.xml:32 @@ -15183,11 +17584,13 @@ msgid "" "SystemTap Probe points have been added into various locations in SSSD code " "to assist in troubleshooting and analyzing performance related issues." msgstr "" +"SSSD 程式碼的各種位置已加入 SystemTap 探測點,以協助疑難排解與分析與效能相關" +"的問題。" #. type: Content of: <reference><refentry><refsect1><para><itemizedlist><listitem><para> #: sssd-systemtap.5.xml:40 msgid "Sample SystemTap scripts are provided in /usr/share/sssd/systemtap/" -msgstr "" +msgstr "範例 SystemTap 腳本位於 /usr/share/sssd/systemtap/" #. type: Content of: <reference><refentry><refsect1><para><itemizedlist><listitem><para> #: sssd-systemtap.5.xml:46 @@ -15196,28 +17599,30 @@ msgid "" "/usr/share/systemtap/tapset/sssd.stp and " "/usr/share/systemtap/tapset/sssd_functions.stp respectively." msgstr "" +"探測與各種函式分別在 /usr/share/systemtap/tapset/sssd.stp 與 /usr/share/" +"systemtap/tapset/sssd_functions.stp 中定義。" #. type: Content of: <reference><refentry><refsect1><title> #: sssd-systemtap.5.xml:57 msgid "PROBE POINTS" -msgstr "" +msgstr "探測點" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sssd-systemtap.5.xml:59 sssd-systemtap.5.xml:367 msgid "" "The information below lists the probe points and arguments available in the " "following format:" -msgstr "" +msgstr "下列資訊以以下格式列出可用的探測點與引數:" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd-systemtap.5.xml:64 msgid "probe $name" -msgstr "" +msgstr "probe $name" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd-systemtap.5.xml:67 msgid "Description of probe point" -msgstr "" +msgstr "探測點的說明" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><programlisting> #: sssd-systemtap.5.xml:70 @@ -15229,21 +17634,26 @@ msgid "" "...\n" " " msgstr "" +"variable1:datatype\n" +"variable2:datatype\n" +"variable3:datatype\n" +"...\n" +" " #. type: Content of: <reference><refentry><refsect1><refsect2><title> #: sssd-systemtap.5.xml:80 msgid "Database Transaction Probes" -msgstr "" +msgstr "資料庫交易探測" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd-systemtap.5.xml:84 msgid "probe sssd_transaction_start" -msgstr "" +msgstr "probe sssd_transaction_start" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd-systemtap.5.xml:87 msgid "Start of a sysdb transaction, probes the sysdb_transaction_start() function." -msgstr "" +msgstr "sysdb 交易的開始,探測 sysdb_transaction_start() 函式。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><programlisting> #: sssd-systemtap.5.xml:91 sssd-systemtap.5.xml:105 sssd-systemtap.5.xml:118 @@ -15254,53 +17664,56 @@ msgid "" "probestr:string\n" " " msgstr "" +"nesting:integer\n" +"probestr:string\n" +" " #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd-systemtap.5.xml:97 msgid "probe sssd_transaction_cancel" -msgstr "" +msgstr "probe sssd_transaction_cancel" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd-systemtap.5.xml:100 msgid "" "Cancellation of a sysdb transaction, probes the sysdb_transaction_cancel() " "function." -msgstr "" +msgstr "sysdb 交易的取消,探測 sysdb_transaction_cancel() 函式。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd-systemtap.5.xml:111 msgid "probe sssd_transaction_commit_before" -msgstr "" +msgstr "probe sssd_transaction_commit_before" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd-systemtap.5.xml:114 msgid "Probes the sysdb_transaction_commit_before() function." -msgstr "" +msgstr "探測 sysdb_transaction_commit_before() 函式。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd-systemtap.5.xml:124 msgid "probe sssd_transaction_commit_after" -msgstr "" +msgstr "probe sssd_transaction_commit_after" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd-systemtap.5.xml:127 msgid "Probes the sysdb_transaction_commit_after() function." -msgstr "" +msgstr "探測 sysdb_transaction_commit_after() 函式。" #. type: Content of: <reference><refentry><refsect1><refsect2><title> #: sssd-systemtap.5.xml:141 msgid "LDAP Search Probes" -msgstr "" +msgstr "LDAP 搜尋探測" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd-systemtap.5.xml:145 msgid "probe sdap_search_send" -msgstr "" +msgstr "probe sdap_search_send" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd-systemtap.5.xml:148 msgid "Probes the sdap_get_generic_ext_send() function." -msgstr "" +msgstr "探測 sdap_get_generic_ext_send() 函式。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><programlisting> #: sssd-systemtap.5.xml:152 @@ -15313,16 +17726,22 @@ msgid "" "probestr:string\n" " " msgstr "" +"base:string\n" +"scope:integer\n" +"filter:string\n" +"attrs:string\n" +"probestr:string\n" +" " #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd-systemtap.5.xml:161 msgid "probe sdap_search_recv" -msgstr "" +msgstr "probe sdap_search_recv" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd-systemtap.5.xml:164 msgid "Probes the sdap_get_generic_ext_recv() function." -msgstr "" +msgstr "探測 sdap_get_generic_ext_recv() 函式。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><programlisting> #: sssd-systemtap.5.xml:168 sssd-systemtap.5.xml:222 @@ -15334,18 +17753,23 @@ msgid "" "probestr:string\n" " " msgstr "" +"base:string\n" +"scope:integer\n" +"filter:string\n" +"probestr:string\n" +" " #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd-systemtap.5.xml:176 msgid "probe sdap_parse_entry" -msgstr "" +msgstr "probe sdap_parse_entry" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd-systemtap.5.xml:179 msgid "" "Probes the sdap_parse_entry() function. It is called repeatedly with every " "received attribute." -msgstr "" +msgstr "探測 sdap_parse_entry() 函式。每收到一個屬性就會重複呼叫它。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><programlisting> #: sssd-systemtap.5.xml:184 @@ -15355,28 +17779,31 @@ msgid "" "value:string\n" " " msgstr "" +"attr:string\n" +"value:string\n" +" " #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd-systemtap.5.xml:190 msgid "probe sdap_parse_entry_done" -msgstr "" +msgstr "probe sdap_parse_entry_done" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd-systemtap.5.xml:193 msgid "" "Probes the sdap_parse_entry() function. It is called when parsing of " "received object is finished." -msgstr "" +msgstr "探測 sdap_parse_entry() 函式。收到物件的剖析完成時呼叫它。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd-systemtap.5.xml:201 msgid "probe sdap_deref_send" -msgstr "" +msgstr "probe sdap_deref_send" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd-systemtap.5.xml:204 msgid "Probes the sdap_deref_search_send() function." -msgstr "" +msgstr "探測 sdap_deref_search_send() 函式。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><programlisting> #: sssd-systemtap.5.xml:208 @@ -15387,31 +17814,35 @@ msgid "" "probestr:string\n" " " msgstr "" +"base_dn:string\n" +"deref_attr:string\n" +"probestr:string\n" +" " #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd-systemtap.5.xml:215 msgid "probe sdap_deref_recv" -msgstr "" +msgstr "probe sdap_deref_recv" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd-systemtap.5.xml:218 msgid "Probes the sdap_deref_search_recv() function." -msgstr "" +msgstr "探測 sdap_deref_search_recv() 函式。" #. type: Content of: <reference><refentry><refsect1><refsect2><title> #: sssd-systemtap.5.xml:234 msgid "LDAP Account Request Probes" -msgstr "" +msgstr "LDAP 帳戶要求探測" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd-systemtap.5.xml:238 msgid "probe sdap_acct_req_send" -msgstr "" +msgstr "probe sdap_acct_req_send" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd-systemtap.5.xml:241 msgid "Probes the sdap_acct_req_send() function." -msgstr "" +msgstr "探測 sdap_acct_req_send() 函式。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><programlisting> #: sssd-systemtap.5.xml:245 sssd-systemtap.5.xml:260 @@ -15423,31 +17854,36 @@ msgid "" "extra_value:string\n" " " msgstr "" +"entry_type:int\n" +"filter_type:int\n" +"filter_value:string\n" +"extra_value:string\n" +" " #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd-systemtap.5.xml:253 msgid "probe sdap_acct_req_recv" -msgstr "" +msgstr "probe sdap_acct_req_recv" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd-systemtap.5.xml:256 msgid "Probes the sdap_acct_req_recv() function." -msgstr "" +msgstr "探測 sdap_acct_req_recv() 函式。" #. type: Content of: <reference><refentry><refsect1><refsect2><title> #: sssd-systemtap.5.xml:272 msgid "LDAP User Search Probes" -msgstr "" +msgstr "LDAP 使用者搜尋探測" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd-systemtap.5.xml:276 msgid "probe sdap_search_user_send" -msgstr "" +msgstr "probe sdap_search_user_send" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd-systemtap.5.xml:279 msgid "Probes the sdap_search_user_send() function." -msgstr "" +msgstr "探測 sdap_search_user_send() 函式。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><programlisting> #: sssd-systemtap.5.xml:283 sssd-systemtap.5.xml:295 sssd-systemtap.5.xml:307 @@ -15457,51 +17893,53 @@ msgid "" "filter:string\n" " " msgstr "" +"filter:string\n" +" " #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd-systemtap.5.xml:288 msgid "probe sdap_search_user_recv" -msgstr "" +msgstr "probe sdap_search_user_recv" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd-systemtap.5.xml:291 msgid "Probes the sdap_search_user_recv() function." -msgstr "" +msgstr "探測 sdap_search_user_recv() 函式。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd-systemtap.5.xml:300 msgid "probe sdap_search_user_save_begin" -msgstr "" +msgstr "probe sdap_search_user_save_begin" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd-systemtap.5.xml:303 msgid "Probes the sdap_search_user_save_begin() function." -msgstr "" +msgstr "探測 sdap_search_user_save_begin() 函式。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd-systemtap.5.xml:312 msgid "probe sdap_search_user_save_end" -msgstr "" +msgstr "probe sdap_search_user_save_end" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd-systemtap.5.xml:315 msgid "Probes the sdap_search_user_save_end() function." -msgstr "" +msgstr "探測 sdap_search_user_save_end() 函式。" #. type: Content of: <reference><refentry><refsect1><refsect2><title> #: sssd-systemtap.5.xml:328 msgid "Data Provider Request Probes" -msgstr "" +msgstr "資料提供者要求探測" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd-systemtap.5.xml:332 msgid "probe dp_req_send" -msgstr "" +msgstr "probe dp_req_send" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd-systemtap.5.xml:335 msgid "A Data Provider request is submitted." -msgstr "" +msgstr "提交資料提供者要求。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><programlisting> #: sssd-systemtap.5.xml:338 @@ -15513,16 +17951,21 @@ msgid "" "dp_req_method:int\n" " " msgstr "" +"dp_req_domain:string\n" +"dp_req_name:string\n" +"dp_req_target:int\n" +"dp_req_method:int\n" +" " #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd-systemtap.5.xml:346 msgid "probe dp_req_done" -msgstr "" +msgstr "probe dp_req_done" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd-systemtap.5.xml:349 msgid "A Data Provider request is completed." -msgstr "" +msgstr "資料提供者要求完成。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><programlisting> #: sssd-systemtap.5.xml:352 @@ -15535,21 +17978,27 @@ msgid "" "dp_errorstr:string\n" " " msgstr "" +"dp_req_name:string\n" +"dp_req_target:int\n" +"dp_req_method:int\n" +"dp_ret:int\n" +"dp_errorstr:string\n" +" " #. type: Content of: <reference><refentry><refsect1><refsect2><title> #: sssd-systemtap.5.xml:365 msgid "MISCELLANEOUS FUNCTIONS" -msgstr "" +msgstr "其他函式" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd-systemtap.5.xml:372 msgid "function acct_req_desc(entry_type)" -msgstr "" +msgstr "function acct_req_desc(entry_type)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd-systemtap.5.xml:375 msgid "Convert entry_type to string and return string" -msgstr "" +msgstr "將 entry_type 轉換為字串並傳回字串" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd-systemtap.5.xml:380 @@ -15557,36 +18006,38 @@ msgid "" "function sssd_acct_req_probestr(fc_name, entry_type, filter_type, " "filter_value, extra_value)" msgstr "" +"function sssd_acct_req_probestr(fc_name, entry_type, filter_type, " +"filter_value, extra_value)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd-systemtap.5.xml:384 msgid "Create probe string based on filter type" -msgstr "" +msgstr "根據篩選器類型建立探測字串" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd-systemtap.5.xml:389 msgid "function dp_target_str(target)" -msgstr "" +msgstr "function dp_target_str(target)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd-systemtap.5.xml:392 msgid "Convert target to string and return string" -msgstr "" +msgstr "將 target 轉換為字串並傳回字串" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd-systemtap.5.xml:397 msgid "function dp_method_str(target)" -msgstr "" +msgstr "function dp_method_str(target)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd-systemtap.5.xml:400 msgid "Convert method to string and return string" -msgstr "" +msgstr "將 method 轉換為字串並傳回字串" #. type: Content of: <reference><refentry><refsect1><title> #: sssd-systemtap.5.xml:410 msgid "SAMPLE SYSTEMTAP SCRIPTS" -msgstr "" +msgstr "SYSTEMTAP 範例腳本" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-systemtap.5.xml:412 @@ -15595,61 +18046,63 @@ msgid "" "/usr/share/sssd/systemtap/<script_name>.stp</command>), then perform " "an identity operation and the script will collect information from probes." msgstr "" +"啟動 SystemTap 腳本(<command>stap /usr/share/sssd/systemtap/" +"<script_name>.stp</command>),然後執行身分操作,腳本會從探測收集資訊。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-systemtap.5.xml:418 msgid "Provided SystemTap scripts are:" -msgstr "" +msgstr "提供的 SystemTap 腳本有:" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd-systemtap.5.xml:422 msgid "dp_request.stp" -msgstr "" +msgstr "dp_request.stp" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd-systemtap.5.xml:425 msgid "Monitoring of data provider request performance." -msgstr "" +msgstr "監視資料提供者要求的效能。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd-systemtap.5.xml:430 msgid "id_perf.stp" -msgstr "" +msgstr "id_perf.stp" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd-systemtap.5.xml:433 msgid "Monitoring of <command>id</command> command performance." -msgstr "" +msgstr "監視 <command>id</command> 指令的效能。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd-systemtap.5.xml:439 msgid "ldap_perf.stp" -msgstr "" +msgstr "ldap_perf.stp" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd-systemtap.5.xml:442 msgid "Monitoring of LDAP queries." -msgstr "" +msgstr "監視 LDAP 查詢。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd-systemtap.5.xml:447 msgid "nested_group_perf.stp" -msgstr "" +msgstr "nested_group_perf.stp" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd-systemtap.5.xml:450 msgid "Performance of nested groups resolving." -msgstr "" +msgstr "巢狀群組解析的效能。" #. type: Content of: <reference><refentry><refnamediv><refname> #: sssd-ldap-attributes.5.xml:10 sssd-ldap-attributes.5.xml:16 msgid "sssd-ldap-attributes" -msgstr "" +msgstr "sssd-ldap-attributes" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sssd-ldap-attributes.5.xml:17 msgid "SSSD LDAP Provider: Mapping Attributes" -msgstr "" +msgstr "SSSD LDAP 提供者:對應屬性" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ldap-attributes.5.xml:23 @@ -15661,76 +18114,80 @@ msgid "" "</citerefentry> manual page for full details about SSSD LDAP provider " "configuration options." msgstr "" +"本手冊頁說明 SSSD LDAP 提供者 <citerefentry> <refentrytitle>sssd-ldap</" +"refentrytitle> <manvolnum>5</manvolnum> </citerefentry> 的對應屬性。SSSD " +"LDAP 提供者設定選項的完整詳細資料請參閱 <citerefentry> <refentrytitle>sssd-" +"ldap</refentrytitle> <manvolnum>5</manvolnum> </citerefentry> 手冊頁。" #. type: Content of: <reference><refentry><refsect1><title> #: sssd-ldap-attributes.5.xml:38 msgid "USER ATTRIBUTES" -msgstr "" +msgstr "使用者屬性" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:42 msgid "ldap_user_object_class (string)" -msgstr "" +msgstr "ldap_user_object_class (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:45 msgid "The object class of a user entry in LDAP." -msgstr "" +msgstr "LDAP 中使用者項目的物件類別。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:48 msgid "Default: posixAccount" -msgstr "" +msgstr "預設:posixAccount" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:54 msgid "ldap_user_name (string)" -msgstr "" +msgstr "ldap_user_name (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:57 msgid "The LDAP attribute that corresponds to the user's login name." -msgstr "" +msgstr "對應使用者登入名稱的 LDAP 屬性。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:61 msgid "Default: uid (rfc2307, rfc2307bis and IPA), sAMAccountName (AD)" -msgstr "" +msgstr "預設:uid(rfc2307、rfc2307bis 與 IPA)、sAMAccountName(AD)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:68 msgid "ldap_user_uid_number (string)" -msgstr "" +msgstr "ldap_user_uid_number (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:71 msgid "The LDAP attribute that corresponds to the user's id." -msgstr "" +msgstr "對應使用者 id 的 LDAP 屬性。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:75 msgid "Default: uidNumber" -msgstr "" +msgstr "預設:uidNumber" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:81 msgid "ldap_user_gid_number (string)" -msgstr "" +msgstr "ldap_user_gid_number (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:84 msgid "The LDAP attribute that corresponds to the user's primary group id." -msgstr "" +msgstr "對應使用者主要群組 id 的 LDAP 屬性。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:88 sssd-ldap-attributes.5.xml:700 msgid "Default: gidNumber" -msgstr "" +msgstr "預設:gidNumber" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:94 msgid "ldap_user_primary_group (string)" -msgstr "" +msgstr "ldap_user_primary_group (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:97 @@ -15739,78 +18196,80 @@ msgid "" "attribute should only be set manually if you are running the " "<quote>ldap</quote> provider with ID mapping." msgstr "" +"用於 ID 對應的 Active Directory 主要群組屬性。請注意,只有在搭配 ID 對應執行 " +"<quote>ldap</quote> 提供者時,才應手動設定此屬性。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:103 msgid "Default: unset (LDAP), primaryGroupID (AD)" -msgstr "" +msgstr "預設:未設定(LDAP)、primaryGroupID(AD)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:109 msgid "ldap_user_gecos (string)" -msgstr "" +msgstr "ldap_user_gecos (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:112 msgid "The LDAP attribute that corresponds to the user's gecos field." -msgstr "" +msgstr "對應使用者 gecos 欄位的 LDAP 屬性。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:116 msgid "Default: gecos" -msgstr "" +msgstr "預設:gecos" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:122 msgid "ldap_user_home_directory (string)" -msgstr "" +msgstr "ldap_user_home_directory (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:125 msgid "The LDAP attribute that contains the name of the user's home directory." -msgstr "" +msgstr "包含使用者家目錄名稱的 LDAP 屬性。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:129 msgid "Default: homeDirectory (LDAP and IPA), unixHomeDirectory (AD)" -msgstr "" +msgstr "預設:homeDirectory(LDAP 與 IPA)、unixHomeDirectory(AD)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:135 msgid "ldap_user_shell (string)" -msgstr "" +msgstr "ldap_user_shell (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:138 msgid "The LDAP attribute that contains the path to the user's default shell." -msgstr "" +msgstr "包含使用者預設 shell 路徑的 LDAP 屬性。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:142 msgid "Default: loginShell" -msgstr "" +msgstr "預設:loginShell" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:148 msgid "ldap_user_uuid (string)" -msgstr "" +msgstr "ldap_user_uuid (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:151 msgid "The LDAP attribute that contains the UUID/GUID of an LDAP user object." -msgstr "" +msgstr "包含 LDAP 使用者物件之 UUID/GUID 的 LDAP 屬性。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:155 sssd-ldap-attributes.5.xml:726 msgid "" "Default: not set in the general case, objectGUID for AD and ipaUniqueID for " "IPA" -msgstr "" +msgstr "預設:一般情況下未設定,AD 為 objectGUID,IPA 為 ipaUniqueID" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:162 msgid "ldap_user_objectsid (string)" -msgstr "" +msgstr "ldap_user_objectsid (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:165 @@ -15818,16 +18277,18 @@ msgid "" "The LDAP attribute that contains the objectSID of an LDAP user object. This " "is usually only necessary for ActiveDirectory servers." msgstr "" +"包含 LDAP 使用者物件之 objectSID 的 LDAP 屬性。這通常只在 ActiveDirectory 伺" +"服器上需要。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:170 sssd-ldap-attributes.5.xml:741 msgid "Default: objectSid for ActiveDirectory, not set for other servers." -msgstr "" +msgstr "預設:ActiveDirectory 為 objectSid,其他伺服器未設定。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:177 msgid "ldap_user_modify_timestamp (string)" -msgstr "" +msgstr "ldap_user_modify_timestamp (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:180 sssd-ldap-attributes.5.xml:751 @@ -15835,18 +18296,18 @@ msgstr "" msgid "" "The LDAP attribute that contains timestamp of the last modification of the " "parent object." -msgstr "" +msgstr "包含父物件上次修改時間戳記的 LDAP 屬性。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:184 sssd-ldap-attributes.5.xml:755 #: sssd-ldap-attributes.5.xml:881 msgid "Default: modifyTimestamp" -msgstr "" +msgstr "預設:modifyTimestamp" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:190 msgid "ldap_user_shadow_last_change (string)" -msgstr "" +msgstr "ldap_user_shadow_last_change (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:193 @@ -15856,16 +18317,19 @@ msgid "" "<refentrytitle>shadow</refentrytitle> <manvolnum>5</manvolnum> " "</citerefentry> counterpart (date of the last password change)." msgstr "" +"使用 ldap_pwd_policy=shadow 時,此參數包含對應其 <citerefentry> " +"<refentrytitle>shadow</refentrytitle> <manvolnum>5</manvolnum> </" +"citerefentry> 相對項(上次密碼變更日期)的 LDAP 屬性名稱。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:203 msgid "Default: shadowLastChange" -msgstr "" +msgstr "預設:shadowLastChange" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:209 msgid "ldap_user_shadow_min (string)" -msgstr "" +msgstr "ldap_user_shadow_min (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:212 @@ -15875,16 +18339,19 @@ msgid "" "<refentrytitle>shadow</refentrytitle> <manvolnum>5</manvolnum> " "</citerefentry> counterpart (minimum password age)." msgstr "" +"使用 ldap_pwd_policy=shadow 時,此參數包含對應其 <citerefentry> " +"<refentrytitle>shadow</refentrytitle> <manvolnum>5</manvolnum> </" +"citerefentry> 相對項(最小密碼年齡)的 LDAP 屬性名稱。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:221 msgid "Default: shadowMin" -msgstr "" +msgstr "預設:shadowMin" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:227 msgid "ldap_user_shadow_max (string)" -msgstr "" +msgstr "ldap_user_shadow_max (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:230 @@ -15894,16 +18361,19 @@ msgid "" "<refentrytitle>shadow</refentrytitle> <manvolnum>5</manvolnum> " "</citerefentry> counterpart (maximum password age)." msgstr "" +"使用 ldap_pwd_policy=shadow 時,此參數包含對應其 <citerefentry> " +"<refentrytitle>shadow</refentrytitle> <manvolnum>5</manvolnum> </" +"citerefentry> 相對項(最大密碼年齡)的 LDAP 屬性名稱。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:239 msgid "Default: shadowMax" -msgstr "" +msgstr "預設:shadowMax" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:245 msgid "ldap_user_shadow_warning (string)" -msgstr "" +msgstr "ldap_user_shadow_warning (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:248 @@ -15913,16 +18383,19 @@ msgid "" "<refentrytitle>shadow</refentrytitle> <manvolnum>5</manvolnum> " "</citerefentry> counterpart (password warning period)." msgstr "" +"使用 ldap_pwd_policy=shadow 時,此參數包含對應其 <citerefentry> " +"<refentrytitle>shadow</refentrytitle> <manvolnum>5</manvolnum> </" +"citerefentry> 相對項(密碼警告期限)的 LDAP 屬性名稱。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:258 msgid "Default: shadowWarning" -msgstr "" +msgstr "預設:shadowWarning" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:264 msgid "ldap_user_shadow_inactive (string)" -msgstr "" +msgstr "ldap_user_shadow_inactive (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:267 @@ -15932,16 +18405,19 @@ msgid "" "<refentrytitle>shadow</refentrytitle> <manvolnum>5</manvolnum> " "</citerefentry> counterpart (password inactivity period)." msgstr "" +"使用 ldap_pwd_policy=shadow 時,此參數包含對應其 <citerefentry> " +"<refentrytitle>shadow</refentrytitle> <manvolnum>5</manvolnum> </" +"citerefentry> 相對項(密碼閒置期限)的 LDAP 屬性名稱。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:277 msgid "Default: shadowInactive" -msgstr "" +msgstr "預設:shadowInactive" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:283 msgid "ldap_user_shadow_expire (string)" -msgstr "" +msgstr "ldap_user_shadow_expire (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:286 @@ -15952,16 +18428,19 @@ msgid "" "<manvolnum>5</manvolnum> </citerefentry> counterpart (account expiration " "date)." msgstr "" +"使用 ldap_pwd_policy=shadow 或 ldap_account_expire_policy=shadow 時,此參數包" +"含對應其 <citerefentry> <refentrytitle>shadow</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry> 相對項(帳戶到期日)的 LDAP 屬性名稱。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:296 msgid "Default: shadowExpire" -msgstr "" +msgstr "預設:shadowExpire" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:302 msgid "ldap_user_krb_last_pwd_change (string)" -msgstr "" +msgstr "ldap_user_krb_last_pwd_change (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:305 @@ -15970,16 +18449,18 @@ msgid "" "an LDAP attribute storing the date and time of last password change in " "kerberos." msgstr "" +"使用 ldap_pwd_policy=mit_kerberos 時,此參數包含在 kerberos 中儲存上次密碼變" +"更日期與時間的 LDAP 屬性名稱。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:311 msgid "Default: krbLastPwdChange" -msgstr "" +msgstr "預設:krbLastPwdChange" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:317 msgid "ldap_user_krb_password_expiration (string)" -msgstr "" +msgstr "ldap_user_krb_password_expiration (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:320 @@ -15987,16 +18468,18 @@ msgid "" "When using ldap_pwd_policy=mit_kerberos, this parameter contains the name of " "an LDAP attribute storing the date and time when current password expires." msgstr "" +"使用 ldap_pwd_policy=mit_kerberos 時,此參數包含儲存目前密碼到期日期與時間的 " +"LDAP 屬性名稱。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:326 msgid "Default: krbPasswordExpiration" -msgstr "" +msgstr "預設:krbPasswordExpiration" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:332 msgid "ldap_user_ad_account_expires (string)" -msgstr "" +msgstr "ldap_user_ad_account_expires (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:335 @@ -16004,16 +18487,18 @@ msgid "" "When using ldap_account_expire_policy=ad, this parameter contains the name " "of an LDAP attribute storing the expiration time of the account." msgstr "" +"使用 ldap_account_expire_policy=ad 時,此參數包含儲存帳戶到期時間的 LDAP 屬性" +"名稱。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:340 msgid "Default: accountExpires" -msgstr "" +msgstr "預設:accountExpires" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:346 msgid "ldap_user_ad_user_account_control (string)" -msgstr "" +msgstr "ldap_user_ad_user_account_control (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:349 @@ -16021,103 +18506,105 @@ msgid "" "When using ldap_account_expire_policy=ad, this parameter contains the name " "of an LDAP attribute storing the user account control bit field." msgstr "" +"使用 ldap_account_expire_policy=ad 時,此參數包含儲存使用者帳戶控制位元欄位" +"的 LDAP 屬性名稱。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:354 msgid "Default: userAccountControl" -msgstr "" +msgstr "預設:userAccountControl" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:360 msgid "ldap_ns_account_lock (string)" -msgstr "" +msgstr "ldap_ns_account_lock (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:363 msgid "" "When using ldap_account_expire_policy=rhds or equivalent, this parameter " "determines if access is allowed or not." -msgstr "" +msgstr "使用 ldap_account_expire_policy=rhds 或等效策略時,此參數決定是否允許存取。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:368 msgid "Default: nsAccountLock" -msgstr "" +msgstr "預設:nsAccountLock" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:374 msgid "ldap_user_nds_login_disabled (string)" -msgstr "" +msgstr "ldap_user_nds_login_disabled (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:377 msgid "" "When using ldap_account_expire_policy=nds, this attribute determines if " "access is allowed or not." -msgstr "" +msgstr "使用 ldap_account_expire_policy=nds 時,此屬性決定是否允許存取。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:381 sssd-ldap-attributes.5.xml:395 msgid "Default: loginDisabled" -msgstr "" +msgstr "預設:loginDisabled" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:387 msgid "ldap_user_nds_login_expiration_time (string)" -msgstr "" +msgstr "ldap_user_nds_login_expiration_time (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:390 msgid "" "When using ldap_account_expire_policy=nds, this attribute determines until " "which date access is granted." -msgstr "" +msgstr "使用 ldap_account_expire_policy=nds 時,此屬性決定授權存取的截止日期。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:401 msgid "ldap_user_nds_login_allowed_time_map (string)" -msgstr "" +msgstr "ldap_user_nds_login_allowed_time_map (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:404 msgid "" "When using ldap_account_expire_policy=nds, this attribute determines the " "hours of a day in a week when access is granted." -msgstr "" +msgstr "使用 ldap_account_expire_policy=nds 時,此屬性決定一週中每天允許存取的時段。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:409 msgid "Default: loginAllowedTimeMap" -msgstr "" +msgstr "預設:loginAllowedTimeMap" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:415 msgid "ldap_user_principal (string)" -msgstr "" +msgstr "ldap_user_principal (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:418 msgid "" "The LDAP attribute that contains the user's Kerberos User Principal Name " "(UPN)." -msgstr "" +msgstr "包含使用者 Kerberos User Principal Name (UPN) 的 LDAP 屬性。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:422 msgid "Default: krbPrincipalName" -msgstr "" +msgstr "預設:krbPrincipalName" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:428 msgid "ldap_user_extra_attrs (string)" -msgstr "" +msgstr "ldap_user_extra_attrs (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:431 msgid "" "Comma-separated list of LDAP attributes that SSSD would fetch along with the " "usual set of user attributes." -msgstr "" +msgstr "SSSD 會與一般使用者屬性集一起擷取的 LDAP 屬性逗號分隔清單。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:436 @@ -16129,6 +18616,9 @@ msgid "" "environments that configure several SSSD domains with different LDAP " "schemas." msgstr "" +"清單可以只包含 LDAP 屬性名稱,或包含 SSSD 快取屬性名稱與 LDAP 屬性名稱的冒號" +"分隔 tuple。若只指定 LDAP 屬性名稱,屬性會原樣儲存到快取。設定具有不同 LDAP " +"schema 之多個 SSSD 網域的環境可能需要使用自訂的 SSSD 屬性名稱。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:446 @@ -16137,11 +18627,13 @@ msgid "" "<quote>name</quote> attribute. SSSD would report an error if any of the " "reserved attribute names is used as an extra attribute name." msgstr "" +"請注意,SSSD 保留幾個屬性名稱,特別是 <quote>name</quote> 屬性。若任何保留屬" +"性名稱被用作額外屬性名稱,SSSD 會回報錯誤。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:456 msgid "ldap_user_extra_attrs = telephoneNumber" -msgstr "" +msgstr "ldap_user_extra_attrs = telephoneNumber" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:459 @@ -16149,11 +18641,13 @@ msgid "" "Save the <quote>telephoneNumber</quote> attribute from LDAP as " "<quote>telephoneNumber</quote> to the cache." msgstr "" +"將 LDAP 的 <quote>telephoneNumber</quote> 屬性以 <quote>telephoneNumber</" +"quote> 名稱儲存到快取。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:463 msgid "ldap_user_extra_attrs = phone:telephoneNumber" -msgstr "" +msgstr "ldap_user_extra_attrs = phone:telephoneNumber" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:466 @@ -16161,51 +18655,53 @@ msgid "" "Save the <quote>telephoneNumber</quote> attribute from LDAP as " "<quote>phone</quote> to the cache." msgstr "" +"將 LDAP 的 <quote>telephoneNumber</quote> 屬性以 <quote>phone</quote> 名稱儲" +"存到快取。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:476 msgid "ldap_user_ssh_public_key (string)" -msgstr "" +msgstr "ldap_user_ssh_public_key (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:479 msgid "The LDAP attribute that contains the user's SSH public keys." -msgstr "" +msgstr "包含使用者 SSH 公開金鑰的 LDAP 屬性。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:483 sssd-ldap-attributes.5.xml:965 msgid "Default: sshPublicKey" -msgstr "" +msgstr "預設:sshPublicKey" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:489 msgid "ldap_user_fullname (string)" -msgstr "" +msgstr "ldap_user_fullname (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:492 msgid "The LDAP attribute that corresponds to the user's full name." -msgstr "" +msgstr "對應使用者全名的 LDAP 屬性。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:502 msgid "ldap_user_member_of (string)" -msgstr "" +msgstr "ldap_user_member_of (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:505 msgid "The LDAP attribute that lists the user's group memberships." -msgstr "" +msgstr "列出使用者群組成員資格的 LDAP 屬性。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:509 sssd-ldap-attributes.5.xml:952 msgid "Default: memberOf" -msgstr "" +msgstr "預設:memberOf" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:515 msgid "ldap_user_authorized_service (string)" -msgstr "" +msgstr "ldap_user_authorized_service (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:518 @@ -16214,13 +18710,15 @@ msgid "" "use the presence of the authorizedService attribute in the user's LDAP entry " "to determine access privilege." msgstr "" +"若 access_provider=ldap 且 ldap_access_order=authorized_service,SSSD 會使用" +"使用者 LDAP 項目中 authorizedService 屬性的存在與否決定存取權限。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:525 msgid "" "An explicit deny (!svc) is resolved first. Second, SSSD searches for " "explicit allow (svc) and finally for allow_all (*)." -msgstr "" +msgstr "先解析明確拒絕 (!svc)。接著 SSSD 搜尋明確允許 (svc),最後搜尋 allow_all (*)。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:530 @@ -16229,6 +18727,8 @@ msgid "" "<emphasis>must</emphasis> include <quote>authorized_service</quote> in order " "for the ldap_user_authorized_service option to work." msgstr "" +"請注意,ldap_user_authorized_service 選項要能運作,ldap_access_order 設定選" +"項<emphasis>必須</emphasis>包含 <quote>authorized_service</quote>。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:537 @@ -16239,16 +18739,19 @@ msgid "" "<quote>systemd-user</quote> service might need to be added to the list of " "allowed services." msgstr "" +"某些發行版(例如 Fedora-29+ 或 RHEL-8)一律將 <quote>systemd-user</quote> " +"PAM 服務包含為登入程序的一部分。因此使用以服務為基礎的存取控制時,可能需要將 " +"<quote>systemd-user</quote> 服務加入允許的服務清單。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:545 msgid "Default: authorizedService" -msgstr "" +msgstr "預設:authorizedService" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:551 msgid "ldap_user_authorized_host (string)" -msgstr "" +msgstr "ldap_user_authorized_host (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:554 @@ -16257,6 +18760,8 @@ msgid "" "presence of the host attribute in the user's LDAP entry to determine access " "privilege." msgstr "" +"若 access_provider=ldap 且 ldap_access_order=host,SSSD 會使用使用者 LDAP 項" +"目中 host 屬性的存在與否決定存取權限。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:560 @@ -16264,6 +18769,8 @@ msgid "" "An explicit deny (!host) is resolved first. Second, SSSD searches for " "explicit allow (host) and finally for allow_all (*)." msgstr "" +"先解析明確拒絕 (!host)。接著 SSSD 搜尋明確允許 (host),最後搜尋 allow_all (*)" +"。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:565 @@ -16272,16 +18779,18 @@ msgid "" "<emphasis>must</emphasis> include <quote>host</quote> in order for the " "ldap_user_authorized_host option to work." msgstr "" +"請注意,ldap_user_authorized_host 選項要能運作,ldap_access_order 設定選" +"項<emphasis>必須</emphasis>包含 <quote>host</quote>。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:572 msgid "Default: host" -msgstr "" +msgstr "預設:host" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:578 msgid "ldap_user_authorized_rhost (string)" -msgstr "" +msgstr "ldap_user_authorized_rhost (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:581 @@ -16290,6 +18799,8 @@ msgid "" "presence of the rhost attribute in the user's LDAP entry to determine access " "privilege. Similarly to host verification process." msgstr "" +"若 access_provider=ldap 且 ldap_access_order=rhost,SSSD 會使用使用者 LDAP 項" +"目中 rhost 屬性的存在與否決定存取權限。與 host 驗證程序類似。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:588 @@ -16297,6 +18808,8 @@ msgid "" "An explicit deny (!rhost) is resolved first. Second, SSSD searches for " "explicit allow (rhost) and finally for allow_all (*)." msgstr "" +"先解析明確拒絕 (!rhost)。接著 SSSD 搜尋明確允許 (rhost),最後搜尋 allow_all " +"(*)。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:593 @@ -16305,36 +18818,38 @@ msgid "" "<emphasis>must</emphasis> include <quote>rhost</quote> in order for the " "ldap_user_authorized_rhost option to work." msgstr "" +"請注意,ldap_user_authorized_rhost 選項要能運作,ldap_access_order 設定選" +"項<emphasis>必須</emphasis>包含 <quote>rhost</quote>。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:600 msgid "Default: rhost" -msgstr "" +msgstr "預設:rhost" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:606 msgid "ldap_user_certificate (string)" -msgstr "" +msgstr "ldap_user_certificate (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:609 msgid "Name of the LDAP attribute containing the X509 certificate of the user." -msgstr "" +msgstr "包含使用者 X509 憑證的 LDAP 屬性名稱。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:613 msgid "Default: userCertificate;binary" -msgstr "" +msgstr "預設:userCertificate;binary" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:619 msgid "ldap_user_email (string)" -msgstr "" +msgstr "ldap_user_email (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:622 msgid "Name of the LDAP attribute containing the email address of the user." -msgstr "" +msgstr "包含使用者電子郵件地址的 LDAP 屬性名稱。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:626 @@ -16346,51 +18861,55 @@ msgid "" "email address then set this option to a nonexistent attribute name in order " "to disable user lookup/login by email." msgstr "" +"注意:若使用者的電子郵件地址與另一位使用者的電子郵件地址或完整限定名稱衝突," +"SSSD 將無法正常提供這些使用者服務。此選項允許使用者以 (1) 使用者名稱與 (2) 電" +"子郵件地址登入。若由於某些原因幾個使用者需要共用相同的電子郵件地址,請將此選" +"項設為不存在的屬性名稱,以停用依電子郵件進行的使用者查詢/登入。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:637 msgid "Default: mail" -msgstr "" +msgstr "預設:mail" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:642 msgid "ldap_user_passkey (string)" -msgstr "" +msgstr "ldap_user_passkey (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:645 msgid "Name of the LDAP attribute containing the passkey mapping data of the user." -msgstr "" +msgstr "包含使用者 passkey 對應資料的 LDAP 屬性名稱。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:649 msgid "Default: passkey (LDAP), ipaPassKey (IPA), altSecurityIdentities (AD)" -msgstr "" +msgstr "預設:passkey(LDAP)、ipaPassKey(IPA)、altSecurityIdentities(AD)" #. type: Content of: <reference><refentry><refsect1><title> #: sssd-ldap-attributes.5.xml:659 msgid "GROUP ATTRIBUTES" -msgstr "" +msgstr "群組屬性" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:663 msgid "ldap_group_object_class (string)" -msgstr "" +msgstr "ldap_group_object_class (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:666 msgid "The object class of a group entry in LDAP." -msgstr "" +msgstr "LDAP 中群組項目的物件類別。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:669 msgid "Default: posixGroup" -msgstr "" +msgstr "預設:posixGroup" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:675 msgid "ldap_group_name (string)" -msgstr "" +msgstr "ldap_group_name (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:678 @@ -16400,51 +18919,53 @@ msgid "" "name for every group. This requirement includes non-POSIX groups in the tree " "of nested groups." msgstr "" +"對應群組名稱的 LDAP 屬性。在具有巢狀群組的環境中,此值必須是對每個群組都有唯" +"一名稱的 LDAP 屬性。此要求包括巢狀群組樹中的非 POSIX 群組。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:686 msgid "Default: cn (rfc2307, rfc2307bis and IPA), sAMAccountName (AD)" -msgstr "" +msgstr "預設:cn(rfc2307、rfc2307bis 與 IPA)、sAMAccountName(AD)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:693 msgid "ldap_group_gid_number (string)" -msgstr "" +msgstr "ldap_group_gid_number (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:696 msgid "The LDAP attribute that corresponds to the group's id." -msgstr "" +msgstr "對應群組 id 的 LDAP 屬性。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:706 msgid "ldap_group_member (string)" -msgstr "" +msgstr "ldap_group_member (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:709 msgid "The LDAP attribute that contains the names of the group's members." -msgstr "" +msgstr "包含群組成員名稱的 LDAP 屬性。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:713 msgid "Default: memberuid (rfc2307) / member (rfc2307bis)" -msgstr "" +msgstr "預設:memberuid(rfc2307)/ member(rfc2307bis)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:719 msgid "ldap_group_uuid (string)" -msgstr "" +msgstr "ldap_group_uuid (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:722 msgid "The LDAP attribute that contains the UUID/GUID of an LDAP group object." -msgstr "" +msgstr "包含 LDAP 群組物件之 UUID/GUID 的 LDAP 屬性。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:733 msgid "ldap_group_objectsid (string)" -msgstr "" +msgstr "ldap_group_objectsid (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:736 @@ -16452,23 +18973,25 @@ msgid "" "The LDAP attribute that contains the objectSID of an LDAP group object. This " "is usually only necessary for ActiveDirectory servers." msgstr "" +"包含 LDAP 群組物件之 objectSID 的 LDAP 屬性。這通常只在 ActiveDirectory 伺服" +"器上需要。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:748 msgid "ldap_group_modify_timestamp (string)" -msgstr "" +msgstr "ldap_group_modify_timestamp (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:761 msgid "ldap_group_type (string)" -msgstr "" +msgstr "ldap_group_type (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:764 msgid "" "The LDAP attribute that contains an integer value indicating the type of the " "group and maybe other flags." -msgstr "" +msgstr "包含指出群組類型及可能其他旗標之整數值的 LDAP 屬性。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:769 @@ -16477,543 +19000,545 @@ msgid "" "group is a domain local groups and has to be filtered out for trusted " "domains." msgstr "" +"此屬性目前只由 AD 提供者用來判斷群組是否為網域本機群組,以及是否必須為受信任" +"網域篩除。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:775 msgid "Default: groupType in the AD provider, otherwise not set" -msgstr "" +msgstr "預設:AD 提供者中為 groupType,否則未設定" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:782 msgid "ldap_group_external_member (string)" -msgstr "" +msgstr "ldap_group_external_member (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:785 msgid "" "The LDAP attribute that references group members that are defined in an " "external domain. At the moment, only IPA's external members are supported." -msgstr "" +msgstr "參照在外部網域中定義之群組成員的 LDAP 屬性。目前只支援 IPA 的外部成員。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:791 msgid "Default: ipaExternalMember in the IPA provider, otherwise unset." -msgstr "" +msgstr "預設:IPA 提供者中為 ipaExternalMember,否則未設定。" #. type: Content of: <reference><refentry><refsect1><title> #: sssd-ldap-attributes.5.xml:801 msgid "NETGROUP ATTRIBUTES" -msgstr "" +msgstr "NETGROUP 屬性" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:805 msgid "ldap_netgroup_object_class (string)" -msgstr "" +msgstr "ldap_netgroup_object_class (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:808 msgid "The object class of a netgroup entry in LDAP." -msgstr "" +msgstr "LDAP 中網路群組項目的物件類別。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:811 msgid "In IPA provider, ipa_netgroup_object_class should be used instead." -msgstr "" +msgstr "在 IPA 提供者中,應改用 ipa_netgroup_object_class。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:815 msgid "Default: nisNetgroup" -msgstr "" +msgstr "預設:nisNetgroup" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:821 msgid "ldap_netgroup_name (string)" -msgstr "" +msgstr "ldap_netgroup_name (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:824 msgid "The LDAP attribute that corresponds to the netgroup name." -msgstr "" +msgstr "對應網路群組名稱的 LDAP 屬性。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:828 msgid "In IPA provider, ipa_netgroup_name should be used instead." -msgstr "" +msgstr "在 IPA 提供者中,應改用 ipa_netgroup_name。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:838 msgid "ldap_netgroup_member (string)" -msgstr "" +msgstr "ldap_netgroup_member (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:841 msgid "The LDAP attribute that contains the names of the netgroup's members." -msgstr "" +msgstr "包含網路群組成員名稱的 LDAP 屬性。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:845 msgid "In IPA provider, ipa_netgroup_member should be used instead." -msgstr "" +msgstr "在 IPA 提供者中,應改用 ipa_netgroup_member。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:849 msgid "Default: memberNisNetgroup" -msgstr "" +msgstr "預設:memberNisNetgroup" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:855 msgid "ldap_netgroup_triple (string)" -msgstr "" +msgstr "ldap_netgroup_triple (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:858 msgid "The LDAP attribute that contains the (host, user, domain) netgroup triples." -msgstr "" +msgstr "包含 (host, user, domain) netgroup 三元組的 LDAP 屬性。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:862 sssd-ldap-attributes.5.xml:878 msgid "This option is not available in IPA provider." -msgstr "" +msgstr "此選項在 IPA 提供者中不可用。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:865 msgid "Default: nisNetgroupTriple" -msgstr "" +msgstr "預設:nisNetgroupTriple" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:871 msgid "ldap_netgroup_modify_timestamp (string)" -msgstr "" +msgstr "ldap_netgroup_modify_timestamp (string)" #. type: Content of: <reference><refentry><refsect1><title> #: sssd-ldap-attributes.5.xml:890 msgid "HOST ATTRIBUTES" -msgstr "" +msgstr "主機屬性" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:894 msgid "ldap_host_object_class (string)" -msgstr "" +msgstr "ldap_host_object_class (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:897 msgid "The object class of a host entry in LDAP." -msgstr "" +msgstr "LDAP 中主機項目的物件類別。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:900 sssd-ldap-attributes.5.xml:997 msgid "Default: ipService" -msgstr "" +msgstr "預設:ipService" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:906 msgid "ldap_host_name (string)" -msgstr "" +msgstr "ldap_host_name (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:909 sssd-ldap-attributes.5.xml:935 msgid "The LDAP attribute that corresponds to the host's name." -msgstr "" +msgstr "對應主機名稱的 LDAP 屬性。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:919 msgid "ldap_host_fqdn (string)" -msgstr "" +msgstr "ldap_host_fqdn (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:922 msgid "" "The LDAP attribute that corresponds to the host's fully-qualified domain " "name." -msgstr "" +msgstr "對應主機完整限定網域名稱的 LDAP 屬性。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:926 msgid "Default: fqdn" -msgstr "" +msgstr "預設:fqdn" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:932 msgid "ldap_host_serverhostname (string)" -msgstr "" +msgstr "ldap_host_serverhostname (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:939 msgid "Default: serverHostname" -msgstr "" +msgstr "預設:serverHostname" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:945 msgid "ldap_host_member_of (string)" -msgstr "" +msgstr "ldap_host_member_of (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:948 msgid "The LDAP attribute that lists the host's group memberships." -msgstr "" +msgstr "列出主機群組成員資格的 LDAP 屬性。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:958 msgid "ldap_host_ssh_public_key (string)" -msgstr "" +msgstr "ldap_host_ssh_public_key (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:961 msgid "The LDAP attribute that contains the host's SSH public keys." -msgstr "" +msgstr "包含主機 SSH 公開金鑰的 LDAP 屬性。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:971 msgid "ldap_host_uuid (string)" -msgstr "" +msgstr "ldap_host_uuid (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:974 msgid "The LDAP attribute that contains the UUID/GUID of an LDAP host object." -msgstr "" +msgstr "包含 LDAP 主機物件之 UUID/GUID 的 LDAP 屬性。" #. type: Content of: <reference><refentry><refsect1><title> #: sssd-ldap-attributes.5.xml:987 msgid "SERVICE ATTRIBUTES" -msgstr "" +msgstr "服務屬性" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:991 msgid "ldap_service_object_class (string)" -msgstr "" +msgstr "ldap_service_object_class (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:994 msgid "The object class of a service entry in LDAP." -msgstr "" +msgstr "LDAP 中服務項目的物件類別。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1003 msgid "ldap_service_name (string)" -msgstr "" +msgstr "ldap_service_name (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1006 msgid "" "The LDAP attribute that contains the name of service attributes and their " "aliases." -msgstr "" +msgstr "包含服務屬性名稱及其別名的 LDAP 屬性。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1016 msgid "ldap_service_port (string)" -msgstr "" +msgstr "ldap_service_port (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1019 msgid "The LDAP attribute that contains the port managed by this service." -msgstr "" +msgstr "包含此服務管理之連接埠的 LDAP 屬性。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1023 msgid "Default: ipServicePort" -msgstr "" +msgstr "預設:ipServicePort" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1029 msgid "ldap_service_proto (string)" -msgstr "" +msgstr "ldap_service_proto (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1032 msgid "The LDAP attribute that contains the protocols understood by this service." -msgstr "" +msgstr "包含此服務可理解的協定的 LDAP 屬性。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1036 msgid "Default: ipServiceProtocol" -msgstr "" +msgstr "預設:ipServiceProtocol" #. type: Content of: <reference><refentry><refsect1><title> #: sssd-ldap-attributes.5.xml:1045 msgid "SUDO ATTRIBUTES" -msgstr "" +msgstr "SUDO 屬性" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1049 msgid "ldap_sudorule_object_class (string)" -msgstr "" +msgstr "ldap_sudorule_object_class (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1052 msgid "The object class of a sudo rule entry in LDAP." -msgstr "" +msgstr "LDAP 中 sudo 規則項目的物件類別。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1055 msgid "Default: sudoRole" -msgstr "" +msgstr "預設:sudoRole" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1061 msgid "ldap_sudorule_name (string)" -msgstr "" +msgstr "ldap_sudorule_name (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1064 msgid "The LDAP attribute that corresponds to the sudo rule name." -msgstr "" +msgstr "對應 sudo 規則名稱的 LDAP 屬性。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1074 msgid "ldap_sudorule_command (string)" -msgstr "" +msgstr "ldap_sudorule_command (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1077 msgid "The LDAP attribute that corresponds to the command name." -msgstr "" +msgstr "對應指令名稱的 LDAP 屬性。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1081 msgid "Default: sudoCommand" -msgstr "" +msgstr "預設:sudoCommand" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1087 msgid "ldap_sudorule_host (string)" -msgstr "" +msgstr "ldap_sudorule_host (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1090 msgid "" "The LDAP attribute that corresponds to the host name (or host IP address, " "host IP network, or host netgroup)" -msgstr "" +msgstr "對應主機名稱(或主機 IP 位址、主機 IP 網路或主機 netgroup)的 LDAP 屬性" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1095 msgid "Default: sudoHost" -msgstr "" +msgstr "預設:sudoHost" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1101 msgid "ldap_sudorule_user (string)" -msgstr "" +msgstr "ldap_sudorule_user (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1104 msgid "" "The LDAP attribute that corresponds to the user name (or UID, group name or " "user's netgroup)" -msgstr "" +msgstr "對應使用者名稱(或 UID、群組名稱或使用者的 netgroup)的 LDAP 屬性" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1108 msgid "Default: sudoUser" -msgstr "" +msgstr "預設:sudoUser" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1114 msgid "ldap_sudorule_option (string)" -msgstr "" +msgstr "ldap_sudorule_option (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1117 msgid "The LDAP attribute that corresponds to the sudo options." -msgstr "" +msgstr "對應 sudo 選項的 LDAP 屬性。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1121 msgid "Default: sudoOption" -msgstr "" +msgstr "預設:sudoOption" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1127 msgid "ldap_sudorule_runasuser (string)" -msgstr "" +msgstr "ldap_sudorule_runasuser (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1130 msgid "" "The LDAP attribute that corresponds to the user name that commands may be " "run as." -msgstr "" +msgstr "對應指令可以以其執行之使用者名稱的 LDAP 屬性。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1134 msgid "Default: sudoRunAsUser" -msgstr "" +msgstr "預設:sudoRunAsUser" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1140 msgid "ldap_sudorule_runasgroup (string)" -msgstr "" +msgstr "ldap_sudorule_runasgroup (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1143 msgid "" "The LDAP attribute that corresponds to the group name or group GID that " "commands may be run as." -msgstr "" +msgstr "對應指令可以以其執行之群組名稱或群組 GID 的 LDAP 屬性。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1147 msgid "Default: sudoRunAsGroup" -msgstr "" +msgstr "預設:sudoRunAsGroup" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1153 msgid "ldap_sudorule_notbefore (string)" -msgstr "" +msgstr "ldap_sudorule_notbefore (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1156 msgid "" "The LDAP attribute that corresponds to the start date/time for when the sudo " "rule is valid." -msgstr "" +msgstr "對應 sudo 規則開始有效之日期/時間的 LDAP 屬性。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1160 msgid "Default: sudoNotBefore" -msgstr "" +msgstr "預設:sudoNotBefore" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1166 msgid "ldap_sudorule_notafter (string)" -msgstr "" +msgstr "ldap_sudorule_notafter (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1169 msgid "" "The LDAP attribute that corresponds to the expiration date/time, after which " "the sudo rule will no longer be valid." -msgstr "" +msgstr "對應到期日期/時間(之後 sudo 規則不再有效)的 LDAP 屬性。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1174 msgid "Default: sudoNotAfter" -msgstr "" +msgstr "預設:sudoNotAfter" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1180 msgid "ldap_sudorule_order (string)" -msgstr "" +msgstr "ldap_sudorule_order (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1183 msgid "The LDAP attribute that corresponds to the ordering index of the rule." -msgstr "" +msgstr "對應規則排序索引的 LDAP 屬性。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1187 msgid "Default: sudoOrder" -msgstr "" +msgstr "預設:sudoOrder" #. type: Content of: <reference><refentry><refsect1><title> #: sssd-ldap-attributes.5.xml:1196 msgid "AUTOFS ATTRIBUTES" -msgstr "" +msgstr "AUTOFS 屬性" #. type: Content of: <reference><refentry><refsect1><title> #: sssd-ldap-attributes.5.xml:1203 msgid "IP HOST ATTRIBUTES" -msgstr "" +msgstr "IP HOST 屬性" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1207 msgid "ldap_iphost_object_class (string)" -msgstr "" +msgstr "ldap_iphost_object_class (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1210 msgid "The object class of an iphost entry in LDAP." -msgstr "" +msgstr "LDAP 中 iphost 項目的物件類別。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1213 msgid "Default: ipHost" -msgstr "" +msgstr "預設:ipHost" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1219 msgid "ldap_iphost_name (string)" -msgstr "" +msgstr "ldap_iphost_name (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1222 msgid "" "The LDAP attribute that contains the name of the IP host attributes and " "their aliases." -msgstr "" +msgstr "包含 IP 主機屬性名稱及其別名的 LDAP 屬性。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1232 msgid "ldap_iphost_number (string)" -msgstr "" +msgstr "ldap_iphost_number (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1235 msgid "The LDAP attribute that contains the IP host address." -msgstr "" +msgstr "包含 IP 主機位址的 LDAP 屬性。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1239 msgid "Default: ipHostNumber" -msgstr "" +msgstr "預設:ipHostNumber" #. type: Content of: <reference><refentry><refsect1><title> #: sssd-ldap-attributes.5.xml:1248 msgid "IP NETWORK ATTRIBUTES" -msgstr "" +msgstr "IP 網路屬性" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1252 msgid "ldap_ipnetwork_object_class (string)" -msgstr "" +msgstr "ldap_ipnetwork_object_class (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1255 msgid "The object class of an ipnetwork entry in LDAP." -msgstr "" +msgstr "LDAP 中 ipnetwork 項目的物件類別。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1258 msgid "Default: ipNetwork" -msgstr "" +msgstr "預設:ipNetwork" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1264 msgid "ldap_ipnetwork_name (string)" -msgstr "" +msgstr "ldap_ipnetwork_name (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1267 msgid "" "The LDAP attribute that contains the name of the IP network attributes and " "their aliases." -msgstr "" +msgstr "包含 IP 網路屬性名稱及其別名的 LDAP 屬性。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1277 msgid "ldap_ipnetwork_number (string)" -msgstr "" +msgstr "ldap_ipnetwork_number (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1280 msgid "The LDAP attribute that contains the IP network address." -msgstr "" +msgstr "包含 IP 網路位址的 LDAP 屬性。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1284 msgid "Default: ipNetworkNumber" -msgstr "" +msgstr "預設:ipNetworkNumber" #. type: Content of: <reference><refentry><refnamediv><refname> #: sssd_krb5_localauth_plugin.8.xml:10 sssd_krb5_localauth_plugin.8.xml:15 msgid "sssd_krb5_localauth_plugin" -msgstr "" +msgstr "sssd_krb5_localauth_plugin" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sssd_krb5_localauth_plugin.8.xml:16 msgid "Kerberos local authorization plugin" -msgstr "" +msgstr "Kerberos 本機授權外掛程式" #. type: Content of: <reference><refentry><refsect1><para> #: sssd_krb5_localauth_plugin.8.xml:22 @@ -17023,6 +19548,9 @@ msgid "" "find the local name for a given Kerberos principal or to check if a given " "local name and a given Kerberos principal relate to each other." msgstr "" +"libkrb5 使用 Kerberos 本機授權外掛程式 <command>sssd_krb5_localauth_plugin</" +"command> 來尋找指定 Kerberos principal 的本機名稱,或檢查指定的本機名稱與指定" +"的 Kerberos principal 是否彼此相關。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd_krb5_localauth_plugin.8.xml:29 @@ -17032,6 +19560,9 @@ msgid "" "information SSSD can easily handle the mappings mentioned above even if the " "local name and the Kerberos principal differ considerably." msgstr "" +"SSSD 處理來自遠端來源之使用者的本機名稱,也可以從遠端來源讀取 Kerberos 使用" +"者 principal 名稱。有了這些資訊,即使本機名稱與 Kerberos principal 差異很大," +"SSSD 也能輕鬆處理上述對應。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd_krb5_localauth_plugin.8.xml:36 @@ -17043,11 +19574,15 @@ msgid "" "principal to get the local name which would lead to wrong mappings in this " "case." msgstr "" +"此外,借助從遠端來源讀取的資訊,SSSD 可以協助防止在 Kerberos principal 的使用" +"者部分意外對應到不同使用者本機名稱時,產生非預期或不想要的對應。依預設," +"libkrb5 可能只是剝除 Kerberos principal 的 realm 部分來取得本機名稱,這種情況" +"下會導致錯誤的對應。" #. type: Content of: <reference><refentry><refsect1><title> #: sssd_krb5_localauth_plugin.8.xml:46 msgid "CONFIGURATION" -msgstr "" +msgstr "設定" #. type: Content of: <reference><refentry><refsect1><para><programlisting> #: sssd_krb5_localauth_plugin.8.xml:56 @@ -17058,6 +19593,10 @@ msgid "" " module = sssd:/usr/lib64/sssd/modules/sssd_krb5_localauth_plugin.so\n" " }\n" msgstr "" +"[plugins]\n" +" localauth = {\n" +" module = sssd:/usr/lib64/sssd/modules/sssd_krb5_localauth_plugin.so\n" +" }\n" #. type: Content of: <reference><refentry><refsect1><para> #: sssd_krb5_localauth_plugin.8.xml:48 @@ -17071,89 +19610,94 @@ msgid "" "included in the local Kerberos configuration the plugin will be enabled " "automatically." msgstr "" +"必須在 Kerberos 設定中明確啟用 Kerberos 本機授權外掛程式,請參閱 " +"<citerefentry> <refentrytitle>krb5.conf</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry>。SSSD 會自動在 SSSD 的公開 Kerberos 設定片段目錄中" +"建立內容例如 <placeholder type=\"programlisting\" id=\"0\"/> 的設定片段。若本" +"機 Kerberos 設定包含此目錄,外掛程式會自動啟用。" #. type: Content of: <variablelist><varlistentry><term> #: include/autofs_attributes.xml:3 msgid "ldap_autofs_map_object_class (string)" -msgstr "" +msgstr "ldap_autofs_map_object_class (string)" #. type: Content of: <variablelist><varlistentry><listitem><para> #: include/autofs_attributes.xml:6 msgid "The object class of an automount map entry in LDAP." -msgstr "" +msgstr "LDAP 中 automount 對應項目的物件類別。" #. type: Content of: <variablelist><varlistentry><listitem><para> #: include/autofs_attributes.xml:9 msgid "Default: nisMap (rfc2307, autofs_provider=ad), otherwise automountMap" -msgstr "" +msgstr "預設:nisMap(rfc2307、autofs_provider=ad),否則為 automountMap" #. type: Content of: <variablelist><varlistentry><term> #: include/autofs_attributes.xml:16 msgid "ldap_autofs_map_name (string)" -msgstr "" +msgstr "ldap_autofs_map_name (string)" #. type: Content of: <variablelist><varlistentry><listitem><para> #: include/autofs_attributes.xml:19 msgid "The name of an automount map entry in LDAP." -msgstr "" +msgstr "LDAP 中 automount 對應項目的名稱。" #. type: Content of: <variablelist><varlistentry><listitem><para> #: include/autofs_attributes.xml:22 msgid "" "Default: nisMapName (rfc2307, autofs_provider=ad), otherwise " "automountMapName" -msgstr "" +msgstr "預設:nisMapName(rfc2307、autofs_provider=ad),否則為 automountMapName" #. type: Content of: <variablelist><varlistentry><term> #: include/autofs_attributes.xml:29 msgid "ldap_autofs_entry_object_class (string)" -msgstr "" +msgstr "ldap_autofs_entry_object_class (string)" #. type: Content of: <variablelist><varlistentry><listitem><para> #: include/autofs_attributes.xml:32 msgid "" "The object class of an automount entry in LDAP. The entry usually " "corresponds to a mount point." -msgstr "" +msgstr "LDAP 中 automount 項目的物件類別。該項目通常對應掛載點。" #. type: Content of: <variablelist><varlistentry><listitem><para> #: include/autofs_attributes.xml:37 msgid "Default: nisObject (rfc2307, autofs_provider=ad), otherwise automount" -msgstr "" +msgstr "預設:nisObject(rfc2307、autofs_provider=ad),否則為 automount" #. type: Content of: <variablelist><varlistentry><term> #: include/autofs_attributes.xml:44 msgid "ldap_autofs_entry_key (string)" -msgstr "" +msgstr "ldap_autofs_entry_key (string)" #. type: Content of: <variablelist><varlistentry><listitem><para> #: include/autofs_attributes.xml:47 include/autofs_attributes.xml:61 msgid "" "The key of an automount entry in LDAP. The entry usually corresponds to a " "mount point." -msgstr "" +msgstr "LDAP 中 automount 項目的索引鍵。該項目通常對應掛載點。" #. type: Content of: <variablelist><varlistentry><listitem><para> #: include/autofs_attributes.xml:51 msgid "Default: cn (rfc2307, autofs_provider=ad), otherwise automountKey" -msgstr "" +msgstr "預設:cn(rfc2307、autofs_provider=ad),否則為 automountKey" #. type: Content of: <variablelist><varlistentry><term> #: include/autofs_attributes.xml:58 msgid "ldap_autofs_entry_value (string)" -msgstr "" +msgstr "ldap_autofs_entry_value (string)" #. type: Content of: <variablelist><varlistentry><listitem><para> #: include/autofs_attributes.xml:65 msgid "" "Default: nisMapEntry (rfc2307, autofs_provider=ad), otherwise " "automountInformation" -msgstr "" +msgstr "預設:nisMapEntry(rfc2307、autofs_provider=ad),否則為 automountInformation" #. type: Content of: <refsect1><title> #: include/service_discovery.xml:2 msgid "SERVICE DISCOVERY" -msgstr "" +msgstr "服務探索" #. type: Content of: <refsect1><para> #: include/service_discovery.xml:4 @@ -17162,11 +19706,13 @@ msgid "" "appropriate servers to connect to using a special DNS query. This feature is " "not supported for backup servers." msgstr "" +"服務探索功能允許後端使用特殊的 DNS 查詢自動尋找要連線的適當伺服器。此功能不支" +"援備份伺服器。" #. type: Content of: <refsect1><refsect2><title> #: include/service_discovery.xml:9 include/ldap_id_mapping.xml:99 msgid "Configuration" -msgstr "" +msgstr "設定" #. type: Content of: <refsect1><refsect2><para> #: include/service_discovery.xml:11 @@ -17179,11 +19725,15 @@ msgid "" "prefers to use service discovery whenever possible, and fall back to a " "specific server when no servers can be discovered using DNS." msgstr "" +"若未指定伺服器,後端會自動使用服務探索嘗試尋找伺服器。使用者也可以選擇在伺服" +"器清單中插入特殊關鍵字 <quote>_srv_</quote>,同時使用固定的伺服器位址與服務探" +"索。偏好順序會維持。例如,若使用者偏好盡可能使用服務探索,並在無法使用 DNS 探" +"索到任何伺服器時回到特定伺服器,此功能就很有用。" #. type: Content of: <refsect1><refsect2><title> #: include/service_discovery.xml:23 msgid "The domain name" -msgstr "" +msgstr "網域名稱" #. type: Content of: <refsect1><refsect2><para> #: include/service_discovery.xml:25 @@ -17192,28 +19742,31 @@ msgid "" "<citerefentry> <refentrytitle>sssd.conf</refentrytitle> " "<manvolnum>5</manvolnum> </citerefentry> manual page for more details." msgstr "" +"更多詳細資料請參閱 <citerefentry> <refentrytitle>sssd.conf</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry> 手冊頁中的 <quote>" +"dns_discovery_domain</quote> 參數。" #. type: Content of: <refsect1><refsect2><title> #: include/service_discovery.xml:35 msgid "The protocol" -msgstr "" +msgstr "協定" #. type: Content of: <refsect1><refsect2><para> #: include/service_discovery.xml:37 msgid "" "The queries usually specify _tcp as the protocol. Exceptions are documented " "in respective option description." -msgstr "" +msgstr "查詢通常指定 _tcp 作為協定。例外情況在各自的選項說明中有記載。" #. type: Content of: <refsect1><refsect2><title> #: include/service_discovery.xml:42 msgid "See Also" -msgstr "" +msgstr "另請參閱" #. type: Content of: <refsect1><refsect2><para> #: include/service_discovery.xml:44 msgid "For more information on the service discovery mechanism, refer to RFC 2782." -msgstr "" +msgstr "服務探索機制的更多資訊請參閱 RFC 2782。" #. type: Content of: <refentryinfo> #: include/upstream.xml:2 @@ -17221,28 +19774,30 @@ msgid "" "<productname>SSSD</productname> <orgname>The SSSD upstream - " "https://github.com/SSSD/sssd/</orgname>" msgstr "" +"<productname>SSSD</productname> <orgname>The SSSD upstream - https://" +"github.com/SSSD/sssd/</orgname>" #. type: Content of: outside any tag (error?) #: include/upstream.xml:1 msgid "<placeholder type=\"refentryinfo\" id=\"0\"/>" -msgstr "" +msgstr "<placeholder type=\"refentryinfo\" id=\"0\"/>" #. type: Content of: <refsect1><title> #: include/failover.xml:2 msgid "FAILOVER" -msgstr "" +msgstr "故障轉移" #. type: Content of: <refsect1><para> #: include/failover.xml:4 msgid "" "The failover feature allows back ends to automatically switch to a different " "server if the current server fails." -msgstr "" +msgstr "故障轉移功能允許後端在目前伺服器失敗時自動切換到不同的伺服器。" #. type: Content of: <refsect1><refsect2><title> #: include/failover.xml:8 msgid "Failover Syntax" -msgstr "" +msgstr "故障轉移語法" #. type: Content of: <refsect1><refsect2><para> #: include/failover.xml:10 @@ -17251,6 +19806,8 @@ msgid "" "is allowed around the comma. The servers are listed in order of " "preference. The list can contain any number of servers." msgstr "" +"伺服器清單以逗號分隔清單給出;逗號周圍允許任意數量的空格。伺服器依偏好順序列" +"出。清單可以包含任意數量的伺服器。" #. type: Content of: <refsect1><refsect2><para> #: include/failover.xml:16 @@ -17263,11 +19820,16 @@ msgid "" "periodically try to reconnect to one of the primary servers. If it succeeds, " "it will replace the current active (backup) server." msgstr "" +"每個啟用故障轉移的設定選項都有兩個變體:<emphasis>primary</emphasis> 與 " +"<emphasis>backup</emphasis>。概念是主要清單中的伺服器優先,只有無法連到任何主" +"要伺服器時才會搜尋備份伺服器。若選取備份伺服器,會設定 31 秒的逾時。此逾時之" +"後,SSSD 會定期嘗試重新連線到其中一個主要伺服器。若成功,它會取代目前作用中(" +"備份)的伺服器。" #. type: Content of: <refsect1><refsect2><title> #: include/failover.xml:27 msgid "The Failover Mechanism" -msgstr "" +msgstr "故障轉移機制" #. type: Content of: <refsect1><refsect2><para> #: include/failover.xml:29 @@ -17282,6 +19844,11 @@ msgid "" "switches over to the next service. The machine is still considered online " "and might still be tried for another service." msgstr "" +"故障轉移機制區分機器與服務。後端先嘗試解析指定機器的主機名稱;若此解析嘗試失" +"敗,該機器會被視為離線。不會再嘗試為任何其他服務連線到這台機器。若解析嘗試成" +"功,後端會嘗試連線到這台機器上的服務。若服務連線嘗試失敗,只會將這個特定服務" +"視為離線,後端會自動切換到下一個服務。該機器仍被視為線上,可能仍會為另一個服" +"務嘗試。" #. type: Content of: <refsect1><refsect2><para> #: include/failover.xml:42 @@ -17290,6 +19857,8 @@ msgid "" "offline after a specified period of time; this is currently hard coded to 30 " "seconds." msgstr "" +"經過指定的一段時間後,會再次嘗試連線標記為離線的機器或服務;目前這是硬編碼的 " +"30 秒。" #. type: Content of: <refsect1><refsect2><para> #: include/failover.xml:47 @@ -17297,11 +19866,13 @@ msgid "" "If there are no more machines to try, the back end as a whole switches to " "offline mode, and then attempts to reconnect every 30 seconds." msgstr "" +"若沒有更多可以嘗試的機器,整個後端會切換到離線模式,然後每 30 秒嘗試重新連線" +"。" #. type: Content of: <refsect1><refsect2><title> #: include/failover.xml:53 msgid "Failover time outs and tuning" -msgstr "" +msgstr "故障轉移逾時與調整" #. type: Content of: <refsect1><refsect2><para> #: include/failover.xml:55 @@ -17316,11 +19887,16 @@ msgid "" "timing out before a live server is contacted, you can consider changing the " "time outs." msgstr "" +"解析要連線的伺服器可以簡單到只執行單一 DNS 查詢,也可能涉及多個步驟,例如尋找" +"正確的站台,或在某些設定的伺服器無法連到時嘗試多個主機名稱。較複雜的情境可能" +"需要一些時間,SSSD 需要在提供足夠時間完成解析程序,與在進入離線模式前不要嘗試" +"太久之間取得平衡。若 SSSD 除錯記錄顯示伺服器解析在連到實際伺服器之前就逾時," +"您可以考慮變更逾時。" #. type: Content of: <refsect1><refsect2><para><variablelist><varlistentry><term> #: include/failover.xml:76 msgid "dns_resolver_server_timeout" -msgstr "" +msgstr "dns_resolver_server_timeout" #. type: Content of: <refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: include/failover.xml:80 @@ -17328,11 +19904,13 @@ msgid "" "Time in milliseconds that sets how long would SSSD talk to a single DNS " "server before trying next one." msgstr "" +"設定 SSSD 在嘗試下一個 DNS 伺服器之前與單一 DNS 伺服器通話多久的時間(毫秒)" +"。" #. type: Content of: <refsect1><refsect2><para><variablelist><varlistentry><term> #: include/failover.xml:90 msgid "dns_resolver_op_timeout" -msgstr "" +msgstr "dns_resolver_op_timeout" #. type: Content of: <refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: include/failover.xml:94 @@ -17341,11 +19919,13 @@ msgid "" "(e.g. resolution of a hostname or an SRV record) before trying the next " "hostname or discovery domain." msgstr "" +"告訴 SSSD 在嘗試下一個主機名稱或探索網域之前,會嘗試解析單一 DNS 查詢(例如主" +"機名稱或 SRV 記錄的解析)多久的時間(秒)。" #. type: Content of: <refsect1><refsect2><para><variablelist><varlistentry><term> #: include/failover.xml:106 msgid "dns_resolver_timeout" -msgstr "" +msgstr "dns_resolver_timeout" #. type: Content of: <refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: include/failover.xml:110 @@ -17354,6 +19934,8 @@ msgid "" "resolution internally might include several steps, such as resolving DNS SRV " "queries or locating the site." msgstr "" +"SSSD 會嘗試解析故障轉移服務多久。此服務解析內部可能包括幾個步驟,例如解析 " +"DNS SRV 查詢或找出站台位置。" #. type: Content of: <refsect1><refsect2><para> #: include/failover.xml:67 @@ -17363,6 +19945,9 @@ msgid "" "<refentrytitle>sssd.conf</refentrytitle><manvolnum>5</manvolnum> " "</citerefentry>, manual page. <placeholder type=\"variablelist\" id=\"0\"/>" msgstr "" +"本節列出可用的可調整參數。請參閱 <citerefentry> <refentrytitle>sssd.conf</" +"refentrytitle><manvolnum>5</manvolnum> </citerefentry> 手冊頁中它們的說明" +"。<placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <refsect1><refsect2><para> #: include/failover.xml:123 @@ -17374,11 +19959,16 @@ msgid "" "value than <quote>dns_resolver_op_timeout</quote> which should be larger " "than <quote>dns_resolver_server_timeout</quote>." msgstr "" +"對以 LDAP 為基礎的提供者,解析操作是 LDAP 連線操作的一部分。因此,<quote>" +"ldap_opt_timeout</quote> 逾時也應設定為比 <quote>dns_resolver_timeout</" +"quote> 更大的值,而 <quote>dns_resolver_timeout</quote> 又應設定為比 <quote>" +"dns_resolver_op_timeout</quote> 更大的值,<quote>dns_resolver_op_timeout</" +"quote> 應大於 <quote>dns_resolver_server_timeout</quote>。" #. type: Content of: <refsect1><title> #: include/ldap_id_mapping.xml:2 msgid "ID MAPPING" -msgstr "" +msgstr "ID 對應" #. type: Content of: <refsect1><para> #: include/ldap_id_mapping.xml:4 @@ -17387,6 +19977,8 @@ msgid "" "without requiring administrators to extend user attributes to support POSIX " "attributes for user and group identifiers." msgstr "" +"ID 對應功能允許 SSSD 作為 Active Directory 的用戶端,不需要管理員擴充使用者屬" +"性以支援使用者與群組識別碼的 POSIX 屬性。" #. type: Content of: <refsect1><para> #: include/ldap_id_mapping.xml:9 @@ -17396,6 +19988,9 @@ msgid "" "automatically-assigned and manually-assigned values. If you need to use " "manually-assigned values, ALL values must be manually-assigned." msgstr "" +"注意:啟用 ID 對應時,會忽略 uidNumber 與 gidNumber 屬性。這是為了避免自動指" +"派與手動指派的值之間發生衝突的可能性。若您需要使用手動指派的值,所有值都必須" +"手動指派。" #. type: Content of: <refsect1><para> #: include/ldap_id_mapping.xml:16 @@ -17410,26 +20005,31 @@ msgid "" "<refentrytitle>sss_cache</refentrytitle> <manvolnum>8</manvolnum> " "</citerefentry> to remove the database, rather the process consists of:" msgstr "" +"請注意,變更與 ID 對應相關的設定選項會導致使用者與群組 ID 變更。目前 SSSD 不" +"支援變更 ID,因此必須移除 SSSD 資料庫。由於快取的密碼也儲存在資料庫中,只應在" +"驗證伺服器可連到時執行移除資料庫,否則使用者可能會被鎖定。要快取密碼,必須執" +"行驗證。使用 <citerefentry> <refentrytitle>sss_cache</refentrytitle> " +"<manvolnum>8</manvolnum> </citerefentry> 移除資料庫是不夠的,程序包括:" #. type: Content of: <refsect1><para><itemizedlist><listitem><para> #: include/ldap_id_mapping.xml:33 msgid "Making sure the remote servers are reachable" -msgstr "" +msgstr "確保遠端伺服器可連到" #. type: Content of: <refsect1><para><itemizedlist><listitem><para> #: include/ldap_id_mapping.xml:38 msgid "Stopping the SSSD service" -msgstr "" +msgstr "停止 SSSD 服務" #. type: Content of: <refsect1><para><itemizedlist><listitem><para> #: include/ldap_id_mapping.xml:43 msgid "Removing the database" -msgstr "" +msgstr "移除資料庫" #. type: Content of: <refsect1><para><itemizedlist><listitem><para> #: include/ldap_id_mapping.xml:48 msgid "Starting the SSSD service" -msgstr "" +msgstr "啟動 SSSD 服務" #. type: Content of: <refsect1><para> #: include/ldap_id_mapping.xml:52 @@ -17438,11 +20038,13 @@ msgid "" "system properties such as file and directory ownership, it's advisable to " "plan ahead and test the ID mapping configuration thoroughly." msgstr "" +"此外,由於 ID 的變更可能需要調整其他系統屬性(例如檔案與目錄的擁有權),建議" +"事先規劃並徹底測試 ID 對應設定。" #. type: Content of: <refsect1><refsect2><title> #: include/ldap_id_mapping.xml:59 msgid "Mapping Algorithm" -msgstr "" +msgstr "對應演算法" #. type: Content of: <refsect1><refsect2><para> #: include/ldap_id_mapping.xml:61 @@ -17452,6 +20054,9 @@ msgid "" "represent the Active Directory domain identity and the relative identifier " "(RID) of the user or group object." msgstr "" +"Active Directory 為目錄中的每個使用者與群組物件提供 objectSID。此 objectSID " +"可以分解為代表 Active Directory 網域身分與使用者或群組物件相對識別碼 (RID) 的" +"元件。" #. type: Content of: <refsect1><refsect2><para> #: include/ldap_id_mapping.xml:67 @@ -17460,6 +20065,8 @@ msgid "" "into equally-sized component sections - called \"slices\"-. Each slice " "represents the space available to an Active Directory domain." msgstr "" +"SSSD ID 對應演算法取一個可用的 UID 範圍,並將它分成大小相等的組成區段,稱為「" +"slices」。每個 slice 代表可供 Active Directory 網域使用的空間。" #. type: Content of: <refsect1><refsect2><para> #: include/ldap_id_mapping.xml:73 @@ -17469,6 +20076,8 @@ msgid "" "domain. In order to make this slice-assignment repeatable on different " "client machines, we select the slice based on the following algorithm:" msgstr "" +"當第一次遇到特定網域的使用者或群組項目時,SSSD 會為該網域配置一個可用的 slice" +"。為了讓此 slice 指派在不同用戶端機器上可重現,我們根據下列演算法選取 slice:" #. type: Content of: <refsect1><refsect2><para> #: include/ldap_id_mapping.xml:80 @@ -17477,6 +20086,8 @@ msgid "" "a 32-bit hashed value. We then take the modulus of this value with the total " "number of available slices to pick the slice." msgstr "" +"SID 字串會通過 murmurhash3 演算法轉換為 32 位元的雜湊值。然後我們對這個值取可" +"用 slice 總數的模數來選取 slice。" #. type: Content of: <refsect1><refsect2><para> #: include/ldap_id_mapping.xml:86 @@ -17490,11 +20101,16 @@ msgid "" "configure a default domain to guarantee that at least one is always " "consistent. See <quote>Configuration</quote> for details." msgstr "" +"注意:在雜湊與後續模數中可能會遇到衝突。在這些情況下,我們會選取下一個可用的 " +"slice,但可能無法在其他機器上重現完全相同的 slice 集合(因為它們被遇到的順序" +"會決定它們的 slice)。這種情況下,建議改用 Active Directory 中的明確 POSIX 屬" +"性(停用 ID 對應),或設定預設網域以保證至少一個永遠一致。詳細資料請參閱 " +"<quote>Configuration</quote>。" #. type: Content of: <refsect1><refsect2><para> #: include/ldap_id_mapping.xml:101 msgid "Minimum configuration (in the <quote>[domain/DOMAINNAME]</quote> section):" -msgstr "" +msgstr "最低設定(在 <quote>[domain/DOMAINNAME]</quote> 區段中):" #. type: Content of: <refsect1><refsect2><para><programlisting> #: include/ldap_id_mapping.xml:106 @@ -17503,6 +20119,8 @@ msgid "" "ldap_id_mapping = True\n" "ldap_schema = ad\n" msgstr "" +"ldap_id_mapping = True\n" +"ldap_schema = ad\n" #. type: Content of: <refsect1><refsect2><para> #: include/ldap_id_mapping.xml:111 @@ -17511,16 +20129,18 @@ msgid "" "of holding up to 200,000 IDs, starting from 200,000 and going up to " "2,000,200,000. This should be sufficient for most deployments." msgstr "" +"預設設定會設定 10,000 個 slice,每個最多容納 200,000 個 ID,從 200,000 開始一" +"直到 2,000,200,000。這對大多數部署應該足夠。" #. type: Content of: <refsect1><refsect2><refsect3><title> #: include/ldap_id_mapping.xml:117 msgid "Advanced Configuration" -msgstr "" +msgstr "進階設定" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><term> #: include/ldap_id_mapping.xml:120 msgid "ldap_idmap_range_min (integer)" -msgstr "" +msgstr "ldap_idmap_range_min (integer)" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> #: include/ldap_id_mapping.xml:123 @@ -17529,6 +20149,8 @@ msgid "" "mapping Active Directory user and group SIDs. It is the first POSIX ID which " "can be used for the mapping." msgstr "" +"指定用於對應 Active Directory 使用者與群組 SID 之 POSIX ID 範圍的下限(含)。" +"它是第一個可用於對應的 POSIX ID。" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> #: include/ldap_id_mapping.xml:129 @@ -17540,16 +20162,19 @@ msgid "" "<quote>min_id</quote> be less-than or equal to " "<quote>ldap_idmap_range_min</quote>" msgstr "" +"注意:此選項與 <quote>min_id</quote> 不同,<quote>min_id</quote> 用於篩選對此" +"網域要求的輸出,而此選項控制 ID 指派的範圍。這是很細微的區別,但一般好的建議" +"是讓 <quote>min_id</quote> 小於或等於 <quote>ldap_idmap_range_min</quote>" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> #: include/ldap_id_mapping.xml:139 include/ldap_id_mapping.xml:197 msgid "Default: 200000" -msgstr "" +msgstr "預設:200000" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><term> #: include/ldap_id_mapping.xml:144 msgid "ldap_idmap_range_max (integer)" -msgstr "" +msgstr "ldap_idmap_range_max (integer)" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> #: include/ldap_id_mapping.xml:147 @@ -17559,6 +20184,9 @@ msgid "" "cannot be used for the mapping anymore, i.e. one larger than the last one " "which can be used for the mapping." msgstr "" +"指定用於對應 Active Directory 使用者與群組 SID 之 POSIX ID 範圍的上限(不含)" +"。它是第一個不能再用作對應的 POSIX ID,也就是比最後一個可用於對應的 ID 大一個" +"。" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> #: include/ldap_id_mapping.xml:155 @@ -17570,16 +20198,19 @@ msgid "" "<quote>max_id</quote> be greater-than or equal to " "<quote>ldap_idmap_range_max</quote>" msgstr "" +"注意:此選項與 <quote>max_id</quote> 不同,<quote>max_id</quote> 用於篩選對此" +"網域要求的輸出,而此選項控制 ID 指派的範圍。這是很細微的區別,但一般好的建議" +"是讓 <quote>max_id</quote> 大於或等於 <quote>ldap_idmap_range_max</quote>" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> #: include/ldap_id_mapping.xml:165 msgid "Default: 2000200000" -msgstr "" +msgstr "預設:2000200000" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><term> #: include/ldap_id_mapping.xml:170 msgid "ldap_idmap_range_size (integer)" -msgstr "" +msgstr "ldap_idmap_range_size (integer)" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> #: include/ldap_id_mapping.xml:173 @@ -17588,6 +20219,8 @@ msgid "" "does not divide evenly into the min and max values, it will create as many " "complete slices as it can." msgstr "" +"指定每個 slice 可用的 ID 數目。若範圍大小無法平均除入最小與最大值,它會建立盡" +"可能多的完整 slice。" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> #: include/ldap_id_mapping.xml:179 @@ -17596,6 +20229,8 @@ msgid "" "RID planned for use on the Active Directory server. User lookups and login " "will fail for any user whose RID is greater than this value." msgstr "" +"注意:此選項的值至少必須與 Active Directory 伺服器上計畫使用的最高使用者 RID " +"一樣大。RID 大於此值的任何使用者的查詢與登入都會失敗。" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> #: include/ldap_id_mapping.xml:185 @@ -17605,6 +20240,10 @@ msgid "" "<quote>ldap_idmap_range_size</quote> must be at least 1108 as range size is " "equal to maximal SID minus minimal SID plus one (e.g. 1108 = 1107 - 0 + 1)." msgstr "" +"例如,若您最近新增的 Active Directory 使用者具有 objectSid=S-1-5-21-" +"2153326666-2176343378-3404031434-1107,<quote>ldap_idmap_range_size</quote> " +"至少必須為 1108,因為範圍大小等於最大 SID 減最小 SID 再加一(例如 1108 = " +"1107 - 0 + 1)。" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> #: include/ldap_id_mapping.xml:192 @@ -17613,11 +20252,13 @@ msgid "" "will result in changing all of the ID mappings on the system, leading to " "users with different local IDs than they previously had." msgstr "" +"事先規劃未來的擴充很重要,因為變更此值會導致系統上所有的 ID 對應變更,使使用" +"者擁有與之前不同的本機 ID。" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><term> #: include/ldap_id_mapping.xml:202 msgid "ldap_idmap_default_domain_sid (string)" -msgstr "" +msgstr "ldap_idmap_default_domain_sid (string)" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> #: include/ldap_id_mapping.xml:205 @@ -17626,21 +20267,23 @@ msgid "" "domain will always be assigned to slice zero in the ID map, bypassing the " "murmurhash algorithm described above." msgstr "" +"指定預設網域的網域 SID。這會保證此網域永遠被指派到 ID 對應中的第零個 slice," +"略過上述 murmurhash 演算法。" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><term> #: include/ldap_id_mapping.xml:216 msgid "ldap_idmap_default_domain (string)" -msgstr "" +msgstr "ldap_idmap_default_domain (string)" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> #: include/ldap_id_mapping.xml:219 msgid "Specify the name of the default domain." -msgstr "" +msgstr "指定預設網域的名稱。" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><term> #: include/ldap_id_mapping.xml:227 msgid "ldap_idmap_autorid_compat (boolean)" -msgstr "" +msgstr "ldap_idmap_autorid_compat (boolean)" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> #: include/ldap_id_mapping.xml:230 @@ -17648,13 +20291,15 @@ msgid "" "Changes the behavior of the ID-mapping algorithm to behave more similarly to " "winbind's <quote>idmap_autorid</quote> algorithm." msgstr "" +"變更 ID 對應演算法的行為,使其更像 winbind 的 <quote>idmap_autorid</quote> 演" +"算法。" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> #: include/ldap_id_mapping.xml:235 msgid "" "When this option is configured, domains will be allocated starting with " "slice zero and increasing monotonically with each additional domain." -msgstr "" +msgstr "設定此選項時,網域會從第零個 slice 開始配置,並隨每個額外的網域單調遞增。" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> #: include/ldap_id_mapping.xml:240 @@ -17665,18 +20310,22 @@ msgid "" "<quote>ldap_idmap_default_domain_sid</quote> option to guarantee that at " "least one domain is consistently allocated to slice zero." msgstr "" +"注意:此演算法是非確定性的(它取決於使用者與群組被要求的順序)。若為了與執行 " +"winbind 的機器相容而需要此模式,建議同時使用 <quote>" +"ldap_idmap_default_domain_sid</quote> 選項,保證至少有一個網域一致地配置到第" +"零個 slice。" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><term> #: include/ldap_id_mapping.xml:255 msgid "ldap_idmap_helper_table_size (integer)" -msgstr "" +msgstr "ldap_idmap_helper_table_size (integer)" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> #: include/ldap_id_mapping.xml:258 msgid "" "Maximal number of secondary slices that is tried when performing mapping " "from UNIX id to SID." -msgstr "" +msgstr "執行從 UNIX id 到 SID 的對應時嘗試的次要 slice 最大數目。" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> #: include/ldap_id_mapping.xml:262 @@ -17686,11 +20335,14 @@ msgid "" "generated so far. If value of ldap_idmap_helper_table_size is equal to 0 " "then no additional secondary slices are generated." msgstr "" +"注意:當 SID 對應到 UNIX id,且 SID 的 RID 部分超出目前已產生之次要 slice 的" +"範圍時,可能會產生額外的次要 slice。若 ldap_idmap_helper_table_size 的值等於 " +"0,則不會產生額外的次要 slice。" #. type: Content of: <refsect1><refsect2><title> #: include/ldap_id_mapping.xml:279 msgid "Well-Known SIDs" -msgstr "" +msgstr "眾所周知的 SID" #. type: Content of: <refsect1><refsect2><para> #: include/ldap_id_mapping.xml:281 @@ -17700,60 +20352,63 @@ msgid "" "those Well-Known SIDs have no equivalent in a Linux/UNIX environment no " "POSIX IDs are available for those objects." msgstr "" +"SSSD 支援查詢 Well-Known SID(即具有特殊硬編碼意義的 SID)的名稱。由於與這些 " +"Well-Known SID 相關的一般使用者與群組在 Linux/UNIX 環境中沒有對應物,這些物件" +"沒有可用的 POSIX ID。" #. type: Content of: <refsect1><refsect2><para> #: include/ldap_id_mapping.xml:287 msgid "" "The SID name space is organized in authorities which can be seen as " "different domains. The authorities for the Well-Known SIDs are" -msgstr "" +msgstr "SID 名稱空間以可視為不同網域的權威機構組織。Well-Known SID 的權威機構是" #. type: Content of: <refsect1><refsect2><para><itemizedlist><listitem><para> #: include/ldap_id_mapping.xml:290 msgid "Null Authority" -msgstr "" +msgstr "Null Authority" #. type: Content of: <refsect1><refsect2><para><itemizedlist><listitem><para> #: include/ldap_id_mapping.xml:291 msgid "World Authority" -msgstr "" +msgstr "World Authority" #. type: Content of: <refsect1><refsect2><para><itemizedlist><listitem><para> #: include/ldap_id_mapping.xml:292 msgid "Local Authority" -msgstr "" +msgstr "Local Authority" #. type: Content of: <refsect1><refsect2><para><itemizedlist><listitem><para> #: include/ldap_id_mapping.xml:293 msgid "Creator Authority" -msgstr "" +msgstr "Creator Authority" #. type: Content of: <refsect1><refsect2><para><itemizedlist><listitem><para> #: include/ldap_id_mapping.xml:294 msgid "Mandatory Label Authority" -msgstr "" +msgstr "Mandatory Label Authority" #. type: Content of: <refsect1><refsect2><para><itemizedlist><listitem><para> #: include/ldap_id_mapping.xml:295 msgid "Authentication Authority" -msgstr "" +msgstr "Authentication Authority" #. type: Content of: <refsect1><refsect2><para><itemizedlist><listitem><para> #: include/ldap_id_mapping.xml:296 msgid "NT Authority" -msgstr "" +msgstr "NT Authority" #. type: Content of: <refsect1><refsect2><para><itemizedlist><listitem><para> #: include/ldap_id_mapping.xml:297 msgid "Built-in" -msgstr "" +msgstr "Built-in" #. type: Content of: <refsect1><refsect2><para> #: include/ldap_id_mapping.xml:299 msgid "" "The capitalized version of these names are used as domain names when " "returning the fully qualified name of a Well-Known SID." -msgstr "" +msgstr "傳回 Well-Known SID 的完整限定名稱時,這些名稱的大寫版本用作網域名稱。" #. type: Content of: <refsect1><refsect2><para> #: include/ldap_id_mapping.xml:303 @@ -17768,21 +20423,28 @@ msgid "" "AUTHORITY</quote>, <quote>NT AUTHORITY</quote> and <quote>BUILTIN</quote> " "should not be used as domain names in <filename>sssd.conf</filename>." msgstr "" +"由於某些公用程式允許借助名稱修改以 SID 為基礎的存取控制資訊,而不是直接使用 " +"SID,SSSD 也支援依名稱查詢 SID。為避免衝突,只能使用完整限定名稱查詢 Well-" +"Known SID。因此,<quote>NULL AUTHORITY</quote>、<quote>WORLD AUTHORITY</" +"quote>、<quote>LOCAL AUTHORITY</quote>、<quote>CREATOR AUTHORITY</quote>" +"、<quote>MANDATORY LABEL AUTHORITY</quote>、<quote>AUTHENTICATION AUTHORITY</" +"quote>、<quote>NT AUTHORITY</quote> 與 <quote>BUILTIN</quote> 網域名稱不應用" +"作 <filename>sssd.conf</filename> 中的網域名稱。" #. type: Content of: <varlistentry><term> #: include/param_help.xml:3 msgid "<option>-?</option>,<option>--help</option>" -msgstr "" +msgstr "<option>-?</option>,<option>--help</option>" #. type: Content of: <varlistentry><listitem><para> #: include/param_help.xml:7 include/param_help_py.xml:7 msgid "Display help message and exit." -msgstr "" +msgstr "顯示說明訊息並結束。" #. type: Content of: <varlistentry><term> #: include/param_help_py.xml:3 msgid "<option>-h</option>,<option>--help</option>" -msgstr "" +msgstr "<option>-h</option>,<option>--help</option>" #. type: Content of: <listitem><para> #: include/debug_levels.xml:3 include/debug_levels_tools.xml:3 @@ -17793,6 +20455,9 @@ msgid "" "is to specify a hexadecimal bitmask to enable or disable specific levels " "(such as if you wish to suppress a level)." msgstr "" +"SSSD 支援兩種指定除錯層級的方式。最簡單的是指定 0-9 的十進位值,代表啟用該層" +"級與所有較低層級的除錯訊息。更全面的選項是指定十六進位位元遮罩以啟用或停用特" +"定層級(例如若您想要抑制某個層級)。" #. type: Content of: <listitem><para> #: include/debug_levels.xml:10 @@ -17803,6 +20468,10 @@ msgid "" "responder or provider processes. The <quote>debug_level</quote> parameter " "should be added to all sections that you wish to produce debug logs from." msgstr "" +"請注意,每個 SSSD 服務都記錄到自己的記錄檔。也請注意,在 <quote>[sssd]</" +"quote> 區段中啟用 <quote>debug_level</quote> 只會為 sssd 程序本身啟用除錯,不" +"會為 responder 或提供者程序啟用。<quote>debug_level</quote> 參數應加入所有您" +"希望產生除錯記錄的區段。" #. type: Content of: <listitem><para> #: include/debug_levels.xml:18 @@ -17813,11 +20482,15 @@ msgid "" "<citerefentry> <refentrytitle>sss_debuglevel</refentrytitle> " "<manvolnum>8</manvolnum> </citerefentry> tool." msgstr "" +"除了使用 <quote>debug_level</quote> 參數在設定檔中變更記錄層級(這是持久的," +"但需要重新啟動 SSSD)之外,也可以使用 <citerefentry> <refentrytitle>" +"sss_debuglevel</refentrytitle> <manvolnum>8</manvolnum> </citerefentry> 工具" +"即時變更除錯層級。" #. type: Content of: <listitem><para> #: include/debug_levels.xml:29 include/debug_levels_tools.xml:10 msgid "Currently supported debug levels:" -msgstr "" +msgstr "目前支援的除錯層級:" #. type: Content of: <listitem><para> #: include/debug_levels.xml:32 include/debug_levels_tools.xml:13 @@ -17826,6 +20499,8 @@ msgid "" "failures. Anything that would prevent SSSD from starting up or causes it to " "cease running." msgstr "" +"<emphasis>0</emphasis>, <emphasis>0x0010</emphasis>:致命失敗。任何會阻止 " +"SSSD 啟動或導致它停止執行的情況。" #. type: Content of: <listitem><para> #: include/debug_levels.xml:38 include/debug_levels_tools.xml:19 @@ -17834,6 +20509,8 @@ msgid "" "error that doesn't kill SSSD, but one that indicates that at least one major " "feature is not going to work properly." msgstr "" +"<emphasis>1</emphasis>, <emphasis>0x0020</emphasis>:嚴重失敗。不會終止 SSSD" +",但表示至少有一個主要功能無法正常運作的錯誤。" #. type: Content of: <listitem><para> #: include/debug_levels.xml:45 include/debug_levels_tools.xml:26 @@ -17841,6 +20518,8 @@ msgid "" "<emphasis>2</emphasis>, <emphasis>0x0040</emphasis>: Serious failures. An " "error announcing that a particular request or operation has failed." msgstr "" +"<emphasis>2</emphasis>, <emphasis>0x0040</emphasis>:重大失敗。宣佈特定要求或" +"操作已失敗的錯誤。" #. type: Content of: <listitem><para> #: include/debug_levels.xml:50 include/debug_levels_tools.xml:31 @@ -17849,30 +20528,32 @@ msgid "" "are the errors that would percolate down to cause the operation failure of " "2." msgstr "" +"<emphasis>3</emphasis>, <emphasis>0x0080</emphasis>:輕微失敗。這些是會滲透下" +"去導致第 2 層級操作失敗的錯誤。" #. type: Content of: <listitem><para> #: include/debug_levels.xml:55 include/debug_levels_tools.xml:36 msgid "<emphasis>4</emphasis>, <emphasis>0x0100</emphasis>: Configuration settings." -msgstr "" +msgstr "<emphasis>4</emphasis>, <emphasis>0x0100</emphasis>:設定設定。" #. type: Content of: <listitem><para> #: include/debug_levels.xml:59 include/debug_levels_tools.xml:40 msgid "<emphasis>5</emphasis>, <emphasis>0x0200</emphasis>: Function data." -msgstr "" +msgstr "<emphasis>5</emphasis>, <emphasis>0x0200</emphasis>:函式資料。" #. type: Content of: <listitem><para> #: include/debug_levels.xml:63 include/debug_levels_tools.xml:44 msgid "" "<emphasis>6</emphasis>, <emphasis>0x0400</emphasis>: Trace messages for " "operation functions." -msgstr "" +msgstr "<emphasis>6</emphasis>, <emphasis>0x0400</emphasis>:操作函式的追蹤訊息。" #. type: Content of: <listitem><para> #: include/debug_levels.xml:67 include/debug_levels_tools.xml:48 msgid "" "<emphasis>7</emphasis>, <emphasis>0x1000</emphasis>: Trace messages for " "internal control functions." -msgstr "" +msgstr "<emphasis>7</emphasis>, <emphasis>0x1000</emphasis>:內部控制函式的追蹤訊息。" #. type: Content of: <listitem><para> #: include/debug_levels.xml:72 include/debug_levels_tools.xml:53 @@ -17880,13 +20561,15 @@ msgid "" "<emphasis>8</emphasis>, <emphasis>0x2000</emphasis>: Contents of " "function-internal variables that may be interesting." msgstr "" +"<emphasis>8</emphasis>, <emphasis>0x2000</emphasis>:可能有趣的函式內部變數內" +"容。" #. type: Content of: <listitem><para> #: include/debug_levels.xml:77 include/debug_levels_tools.xml:58 msgid "" "<emphasis>9</emphasis>, <emphasis>0x4000</emphasis>: Extremely low-level " "tracing information." -msgstr "" +msgstr "<emphasis>9</emphasis>, <emphasis>0x4000</emphasis>:極低階的追蹤資訊。" #. type: Content of: <listitem><para> #: include/debug_levels.xml:81 @@ -17896,6 +20579,8 @@ msgid "" "internally the logged execution time of a request might be longer than it " "actually was." msgstr "" +"<emphasis>9</emphasis>, <emphasis>0x20000</emphasis>:效能與統計資料,請注意" +"由於要求內部處理的方式,記錄的要求執行時間可能比實際時間長。" #. type: Content of: <listitem><para> #: include/debug_levels.xml:88 include/debug_levels_tools.xml:62 @@ -17903,13 +20588,15 @@ msgid "" "<emphasis>10</emphasis>, <emphasis>0x10000</emphasis>: Even more low-level " "libldb tracing information. Almost never really required." msgstr "" +"<emphasis>10</emphasis>, <emphasis>0x10000</emphasis>:更底層的 libldb 追蹤資" +"訊。幾乎從不真正需要。" #. type: Content of: <listitem><para> #: include/debug_levels.xml:93 include/debug_levels_tools.xml:67 msgid "" "To log required bitmask debug levels, simply add their numbers together as " "shown in following examples:" -msgstr "" +msgstr "要記錄所需的位元遮罩除錯層級,只需將它們的數字相加,如下列範例所示:" #. type: Content of: <listitem><para> #: include/debug_levels.xml:97 include/debug_levels_tools.xml:71 @@ -17917,6 +20604,8 @@ msgid "" "<emphasis>Example</emphasis>: To log fatal failures, critical failures, " "serious failures and function data use 0x0270." msgstr "" +"<emphasis>範例</emphasis>:要記錄致命失敗、嚴重失敗、重大失敗與函式資料,請使" +"用 0x0270。" #. type: Content of: <listitem><para> #: include/debug_levels.xml:101 include/debug_levels_tools.xml:75 @@ -17924,13 +20613,15 @@ msgid "" "<emphasis>Example</emphasis>: To log fatal failures, configuration settings, " "function data, trace messages for internal control functions use 0x1310." msgstr "" +"<emphasis>範例</emphasis>:要記錄致命失敗、設定設定、函式資料、內部控制函式的" +"追蹤訊息,請使用 0x1310。" #. type: Content of: <listitem><para> #: include/debug_levels.xml:106 include/debug_levels_tools.xml:80 msgid "" "<emphasis>Note</emphasis>: The bitmask format of debug levels was introduced " "in 1.7.0." -msgstr "" +msgstr "<emphasis>注意</emphasis>:位元遮罩格式的除錯層級是在 1.7.0 中引入。" #. type: Content of: <listitem><para> #: include/debug_levels.xml:110 include/debug_levels_tools.xml:84 @@ -17938,11 +20629,13 @@ msgid "" "<emphasis>Default</emphasis>: 0x0070 (i.e. fatal, critical and serious " "failures; corresponds to setting 2 in decimal notation)" msgstr "" +"<emphasis>預設</emphasis>:0x0070(也就是致命、嚴重與重大失敗;對應十進位記法" +"的設定 2)" #. type: Content of: <refsect1><title> #: include/local.xml:2 msgid "THE LOCAL DOMAIN" -msgstr "" +msgstr "本機網域" #. type: Content of: <refsect1><para> #: include/local.xml:4 @@ -17951,6 +20644,8 @@ msgid "" "<quote>id_provider=local</quote> must be created and the SSSD must be " "running." msgstr "" +"要正常運作,必須建立具有 <quote>id_provider=local</quote> 的網域,且 SSSD 必" +"須執行中。" #. type: Content of: <refsect1><para> #: include/local.xml:9 @@ -17963,6 +20658,11 @@ msgid "" "<command>sss_user*</command> and <command>sss_group*</command> tools use a " "local LDB storage to store users and groups." msgstr "" +"在需要群組巢狀(請參閱 <citerefentry> <refentrytitle>sss_groupadd</" +"refentrytitle> <manvolnum>8</manvolnum> </citerefentry>)的情況下,管理員可能" +"想要使用 SSSD 本機使用者而不是傳統 UNIX 使用者。本機使用者對於不需部署完整遠" +"端伺服器的 SSSD 測試與開發也很有用。<command>sss_user*</command> 與 <command>" +"sss_group*</command> 工具使用本機 LDB 儲存來儲存使用者與群組。" #. type: Content of: <refsect1><para> #: include/seealso.xml:4 @@ -18012,24 +20712,59 @@ msgid "" "<refentrytitle>sssd-systemtap</refentrytitle> <manvolnum>5</manvolnum> " "</citerefentry> </phrase>" msgstr "" +"<citerefentry> <refentrytitle>sssd</refentrytitle><manvolnum>8</manvolnum> </" +"citerefentry>, <citerefentry> <refentrytitle>sssd.conf</refentrytitle>" +"<manvolnum>5</manvolnum> </citerefentry>, <citerefentry> <refentrytitle>sssd-" +"ldap</refentrytitle><manvolnum>5</manvolnum> </citerefentry>, <citerefentry> " +"<refentrytitle>sssd-ldap-attributes</refentrytitle><manvolnum>5</manvolnum> " +"</citerefentry>, <citerefentry> <refentrytitle>sssd-krb5</refentrytitle>" +"<manvolnum>5</manvolnum> </citerefentry>, <citerefentry> <refentrytitle>sssd-" +"simple</refentrytitle><manvolnum>5</manvolnum> </citerefentry>, " +"<citerefentry> <refentrytitle>sssd-ipa</refentrytitle><manvolnum>5</" +"manvolnum> </citerefentry>, <citerefentry> <refentrytitle>sssd-ad</" +"refentrytitle><manvolnum>5</manvolnum> </citerefentry>, <phrase " +"condition=\"with_files_provider\"> <citerefentry> <refentrytitle>sssd-files</" +"refentrytitle><manvolnum>5</manvolnum> </citerefentry>, </phrase> <phrase " +"condition=\"with_sudo\"> <citerefentry> <refentrytitle>sssd-sudo</" +"refentrytitle> <manvolnum>5</manvolnum> </citerefentry>, </phrase> " +"<citerefentry> <refentrytitle>sssd-session-recording</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry>, <citerefentry> <refentrytitle>" +"sss_cache</refentrytitle><manvolnum>8</manvolnum> </citerefentry>, " +"<citerefentry> <refentrytitle>sss_debuglevel</refentrytitle><manvolnum>8</" +"manvolnum> </citerefentry>, <citerefentry> <refentrytitle>sss_obfuscate</" +"refentrytitle><manvolnum>8</manvolnum> </citerefentry>, <citerefentry> " +"<refentrytitle>sss_seed</refentrytitle><manvolnum>8</manvolnum> </" +"citerefentry>, <citerefentry> <refentrytitle>sssd_krb5_locator_plugin</" +"refentrytitle><manvolnum>8</manvolnum> </citerefentry>, <phrase " +"condition=\"with_ssh\"> <citerefentry> <refentrytitle>" +"sss_ssh_authorizedkeys</refentrytitle> <manvolnum>1</manvolnum> </" +"citerefentry>, <citerefentry> <refentrytitle>sss_ssh_knownhosts</" +"refentrytitle> <manvolnum>1</manvolnum> </citerefentry>, </phrase> " +"<citerefentry> <refentrytitle>sssd-ifp</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry>, <citerefentry> <refentrytitle>pam_sss</" +"refentrytitle><manvolnum>8</manvolnum> </citerefentry>. <citerefentry> " +"<refentrytitle>sss_rpcidmapd</refentrytitle> <manvolnum>5</manvolnum> </" +"citerefentry> <phrase condition=\"with_stap\"> <citerefentry> <refentrytitle>" +"sssd-systemtap</refentrytitle> <manvolnum>5</manvolnum> </citerefentry> </" +"phrase>" #. type: Content of: <listitem><para> #: include/ldap_search_bases.xml:3 msgid "" "An optional base DN, search scope and LDAP filter to restrict LDAP searches " "for this attribute type." -msgstr "" +msgstr "限制此屬性類型之 LDAP 搜尋的選用基礎 DN、搜尋範圍與 LDAP 篩選器。" #. type: Content of: <listitem><para><programlisting> #: include/ldap_search_bases.xml:9 #, no-wrap msgid "search_base[?scope?[filter][?search_base?scope?[filter]]*]\n" -msgstr "" +msgstr "search_base[?scope?[filter][?search_base?scope?[filter]]*]\n" #. type: Content of: <listitem><para> #: include/ldap_search_bases.xml:7 msgid "syntax: <placeholder type=\"programlisting\" id=\"0\"/>" -msgstr "" +msgstr "語法:<placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <listitem><para> #: include/ldap_search_bases.xml:13 @@ -18038,13 +20773,15 @@ msgid "" "functions as specified in section 4.5.1.2 of " "http://tools.ietf.org/html/rfc4511" msgstr "" +"範圍可以是 \"base\"、\"onelevel\" 或 \"subtree\" 之一。範圍的功能如 http://" +"tools.ietf.org/html/rfc4511 第 4.5.1.2 節所指定" #. type: Content of: <listitem><para> #: include/ldap_search_bases.xml:23 msgid "" "For examples of this syntax, please refer to the " "<quote>ldap_search_base</quote> examples section." -msgstr "" +msgstr "此語法的範例請參閱 <quote>ldap_search_base</quote> 範例一節。" #. type: Content of: <listitem><para> #: include/ldap_search_bases.xml:31 @@ -18053,6 +20790,8 @@ msgid "" "against an Active Directory Server that might yield a large number of " "results and trigger the Range Retrieval extension in the response." msgstr "" +"請注意,對可能產生大量結果並在回應中觸發 Range Retrieval 延伸的 Active " +"Directory Server 搜尋,不支援指定範圍或篩選器。" #. type: Content of: <para> #: include/autofs_restart.xml:2 @@ -18061,73 +20800,76 @@ msgid "" "any autofs-related changes are made to the sssd.conf, you typically also " "need to restart the automounter daemon after restarting the SSSD." msgstr "" +"請注意,automounter 只在啟動時讀取主對應,因此若對 sssd.conf 做了任何與 " +"autofs 相關的變更,您通常也需要在重新啟動 SSSD 後重新啟動 automounter 常駐程" +"式。" #. type: Content of: <varlistentry><term> #: include/override_homedir.xml:2 msgid "override_homedir (string)" -msgstr "" +msgstr "override_homedir (string)" #. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: include/override_homedir.xml:16 msgid "UID number" -msgstr "" +msgstr "UID 號碼" #. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: include/override_homedir.xml:20 msgid "domain name" -msgstr "" +msgstr "網域名稱" #. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><term> #: include/override_homedir.xml:23 msgid "%f" -msgstr "" +msgstr "%f" #. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: include/override_homedir.xml:24 msgid "fully qualified user name (user@domain)" -msgstr "" +msgstr "完整限定使用者名稱(user@domain)" #. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><term> #: include/override_homedir.xml:27 msgid "%l" -msgstr "" +msgstr "%l" #. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: include/override_homedir.xml:28 msgid "The first letter of the login name." -msgstr "" +msgstr "登入名稱的第一個字母。" #. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: include/override_homedir.xml:32 msgid "UPN - User Principal Name (name@REALM)" -msgstr "" +msgstr "UPN - User Principal Name(name@REALM)" #. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><term> #: include/override_homedir.xml:35 msgid "%o" -msgstr "" +msgstr "%o" #. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: include/override_homedir.xml:37 msgid "The original home directory retrieved from the identity provider." -msgstr "" +msgstr "從身分提供者擷取的原始家目錄。" #. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: include/override_homedir.xml:44 msgid "" "The original home directory retrieved from the identity provider, but in " "lower case." -msgstr "" +msgstr "從身分提供者擷取的原始家目錄,但改為小寫。" #. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><term> #: include/override_homedir.xml:49 msgid "%H" -msgstr "" +msgstr "%H" #. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: include/override_homedir.xml:51 msgid "The value of configure option <emphasis>homedir_substring</emphasis>." -msgstr "" +msgstr "設定選項 <emphasis>homedir_substring</emphasis> 的值。" #. type: Content of: <varlistentry><listitem><para> #: include/override_homedir.xml:5 @@ -18136,11 +20878,13 @@ msgid "" "or a template. In the template, the following sequences are substituted: " "<placeholder type=\"variablelist\" id=\"0\"/>" msgstr "" +"覆寫使用者的家目錄。您可以提供絕對值或範本。在範本中,會替換下列序列" +":<placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <varlistentry><listitem><para> #: include/override_homedir.xml:63 msgid "This option can also be set per-domain." -msgstr "" +msgstr "此選項也可以按網域設定。" #. type: Content of: <varlistentry><listitem><para><programlisting> #: include/override_homedir.xml:68 @@ -18149,11 +20893,13 @@ msgid "" "override_homedir = /home/%u\n" " " msgstr "" +"override_homedir = /home/%u\n" +" " #. type: Content of: <varlistentry><listitem><para> #: include/override_homedir.xml:72 msgid "Default: Not set (SSSD will use the value retrieved from LDAP)" -msgstr "" +msgstr "預設:未設定(SSSD 將使用從 LDAP 擷取的值)" #. type: Content of: <varlistentry><listitem><para> #: include/override_homedir.xml:76 @@ -18165,11 +20911,15 @@ msgid "" "id-overrides, has a higher precedence and will be used instead of the value " "given by override_homedir." msgstr "" +"請注意,使用者特定覆寫的家目錄(無論是本機(請參閱 <citerefentry>" +"<refentrytitle>sss_override</refentrytitle> <manvolnum>8</manvolnum></" +"citerefentry>)或集中管理的 IPA id-overrides)具有較高的優先順序,將被使用而" +"不是 override_homedir 給定的值。" #. type: Content of: <varlistentry><term> #: include/homedir_substring.xml:2 msgid "homedir_substring (string)" -msgstr "" +msgstr "homedir_substring (string)" #. type: Content of: <varlistentry><listitem><para> #: include/homedir_substring.xml:5 @@ -18182,16 +20932,21 @@ msgid "" "per-domain or globally in the [nss] section. A value specified in a domain " "section will override one set in the [nss] section." msgstr "" +"若範本包含格式字串 <emphasis>%H</emphasis>,此選項的值將用於 <emphasis>" +"override_homedir</emphasis> 選項的展開。LDAP 目錄項目可以直接包含此範本,因此" +"此選項可以用來為每個用戶端機器(或作業系統)展開家目錄路徑。它可以按網域設定" +",或在 [nss] 區段中全域設定。在網域區段中指定的值會覆寫 [nss] 區段中設定的值" +"。" #. type: Content of: <varlistentry><listitem><para> #: include/homedir_substring.xml:15 msgid "Default: /home" -msgstr "" +msgstr "預設:/home" #. type: Content of: <refsect1><title> #: include/ad_modified_defaults.xml:2 include/ipa_modified_defaults.xml:2 msgid "MODIFIED DEFAULT OPTIONS" -msgstr "" +msgstr "已修改的預設選項" #. type: Content of: <refsect1><para> #: include/ad_modified_defaults.xml:4 @@ -18200,66 +20955,68 @@ msgid "" "defaults, these option names and AD provider-specific defaults are listed " "below:" msgstr "" +"某些選項的預設值與其各自後端提供者的預設值不符,下列列出這些選項名稱與 AD 提" +"供者特定的預設值:" #. type: Content of: <refsect1><refsect2><title> #: include/ad_modified_defaults.xml:9 include/ipa_modified_defaults.xml:9 msgid "KRB5 Provider" -msgstr "" +msgstr "KRB5 提供者" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ad_modified_defaults.xml:13 include/ipa_modified_defaults.xml:13 msgid "krb5_validate = true" -msgstr "" +msgstr "krb5_validate = true" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ad_modified_defaults.xml:18 msgid "krb5_use_enterprise_principal = true" -msgstr "" +msgstr "krb5_use_enterprise_principal = true" #. type: Content of: <refsect1><refsect2><title> #: include/ad_modified_defaults.xml:24 msgid "LDAP Provider" -msgstr "" +msgstr "LDAP 提供者" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ad_modified_defaults.xml:28 msgid "ldap_schema = ad" -msgstr "" +msgstr "ldap_schema = ad" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ad_modified_defaults.xml:33 include/ipa_modified_defaults.xml:38 msgid "ldap_force_upper_case_realm = true" -msgstr "" +msgstr "ldap_force_upper_case_realm = true" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ad_modified_defaults.xml:38 msgid "ldap_id_mapping = true" -msgstr "" +msgstr "ldap_id_mapping = true" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ad_modified_defaults.xml:43 msgid "ldap_sasl_mech = GSS-SPNEGO" -msgstr "" +msgstr "ldap_sasl_mech = GSS-SPNEGO" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ad_modified_defaults.xml:48 msgid "ldap_referrals = false" -msgstr "" +msgstr "ldap_referrals = false" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ad_modified_defaults.xml:53 msgid "ldap_account_expire_policy = ad" -msgstr "" +msgstr "ldap_account_expire_policy = ad" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ad_modified_defaults.xml:58 include/ipa_modified_defaults.xml:58 msgid "ldap_use_tokengroups = true" -msgstr "" +msgstr "ldap_use_tokengroups = true" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ad_modified_defaults.xml:63 msgid "ldap_sasl_authid = sAMAccountName@REALM (typically SHORTNAME$@REALM)" -msgstr "" +msgstr "ldap_sasl_authid = sAMAccountName@REALM(通常是 SHORTNAME$@REALM)" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ad_modified_defaults.xml:66 @@ -18272,16 +21029,21 @@ msgid "" "well-known host/hostname@REALM principal is a Service Principal and thus " "cannot be used to get a TGT with." msgstr "" +"依預設,AD 提供者尋找的 principal 與 LDAP 提供者不同,因為在 Active " +"Directory 環境中,principal 分為兩組:User Principal 與 Service Principal。只" +"有 User Principal 可以用來取得 TGT,依預設,電腦物件的 principal 是由其 " +"sAMAccountName 與 AD realm 建構。眾所周知的 host/hostname@REALM principal 是 " +"Service Principal,因此不能用它取得 TGT。" #. type: Content of: <refsect1><refsect2><title> #: include/ad_modified_defaults.xml:80 msgid "NSS configuration" -msgstr "" +msgstr "NSS 設定" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ad_modified_defaults.xml:84 msgid "fallback_homedir = /home/%d/%u" -msgstr "" +msgstr "fallback_homedir = /home/%d/%u" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ad_modified_defaults.xml:87 @@ -18292,6 +21054,9 @@ msgid "" "and you want to avoid this fallback behavior, you can explicitly set " "\"fallback_homedir = %o\"." msgstr "" +"AD 提供者自動設定 \"fallback_homedir = /home/%d/%u\",為沒有 homeDirectory 屬" +"性的使用者提供個人家目錄。若您的 AD 網域已正確填入 Posix 屬性,且您想要避免此" +"退回行為,您可以明確設定 \"fallback_homedir = %o\"。" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ad_modified_defaults.xml:96 @@ -18300,6 +21065,8 @@ msgid "" "folder. If you decide to use a different directory structure, some other " "parts of your system may need adjustments." msgstr "" +"請注意,系統通常預期家目錄在 /home/%u 資料夾中。若您決定使用不同的目錄結構," +"系統的其他部分可能需要調整。" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ad_modified_defaults.xml:102 @@ -18308,6 +21075,8 @@ msgid "" "selinux requires selinux adjustment, otherwise the home directory will be " "created with wrong selinux context." msgstr "" +"例如,與 selinux 搭配的自動建立家目錄需要調整 selinux,否則家目錄會以錯誤的 " +"selinux context 建立。" #. type: Content of: <refsect1><para> #: include/ipa_modified_defaults.xml:4 @@ -18316,106 +21085,108 @@ msgid "" "defaults, these option names and IPA provider-specific defaults are listed " "below:" msgstr "" +"某些選項的預設值與其各自後端提供者的預設值不符,下列列出這些選項名稱與 IPA 提" +"供者特定的預設值:" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ipa_modified_defaults.xml:18 msgid "krb5_use_fast = try" -msgstr "" +msgstr "krb5_use_fast = try" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ipa_modified_defaults.xml:23 msgid "krb5_canonicalize = true" -msgstr "" +msgstr "krb5_canonicalize = true" #. type: Content of: <refsect1><refsect2><title> #: include/ipa_modified_defaults.xml:29 msgid "LDAP Provider - General" -msgstr "" +msgstr "LDAP 提供者 - 一般" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ipa_modified_defaults.xml:33 msgid "ldap_schema = ipa_v1" -msgstr "" +msgstr "ldap_schema = ipa_v1" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ipa_modified_defaults.xml:43 msgid "ldap_sasl_mech = GSSAPI" -msgstr "" +msgstr "ldap_sasl_mech = GSSAPI" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ipa_modified_defaults.xml:48 msgid "ldap_sasl_minssf = 56" -msgstr "" +msgstr "ldap_sasl_minssf = 56" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ipa_modified_defaults.xml:53 msgid "ldap_account_expire_policy = ipa" -msgstr "" +msgstr "ldap_account_expire_policy = ipa" #. type: Content of: <refsect1><refsect2><title> #: include/ipa_modified_defaults.xml:64 msgid "LDAP Provider - User options" -msgstr "" +msgstr "LDAP 提供者 - 使用者選項" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ipa_modified_defaults.xml:68 msgid "ldap_user_member_of = memberOf" -msgstr "" +msgstr "ldap_user_member_of = memberOf" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ipa_modified_defaults.xml:73 msgid "ldap_user_uuid = ipaUniqueID" -msgstr "" +msgstr "ldap_user_uuid = ipaUniqueID" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ipa_modified_defaults.xml:78 msgid "ldap_user_ssh_public_key = ipaSshPubKey" -msgstr "" +msgstr "ldap_user_ssh_public_key = ipaSshPubKey" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ipa_modified_defaults.xml:83 msgid "ldap_user_auth_type = ipaUserAuthType" -msgstr "" +msgstr "ldap_user_auth_type = ipaUserAuthType" #. type: Content of: <refsect1><refsect2><title> #: include/ipa_modified_defaults.xml:89 msgid "LDAP Provider - Group options" -msgstr "" +msgstr "LDAP 提供者 - 群組選項" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ipa_modified_defaults.xml:93 msgid "ldap_group_object_class = ipaUserGroup" -msgstr "" +msgstr "ldap_group_object_class = ipaUserGroup" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ipa_modified_defaults.xml:98 msgid "ldap_group_object_class_alt = posixGroup" -msgstr "" +msgstr "ldap_group_object_class_alt = posixGroup" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ipa_modified_defaults.xml:103 msgid "ldap_group_member = member" -msgstr "" +msgstr "ldap_group_member = member" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ipa_modified_defaults.xml:108 msgid "ldap_group_uuid = ipaUniqueID" -msgstr "" +msgstr "ldap_group_uuid = ipaUniqueID" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ipa_modified_defaults.xml:113 msgid "ldap_group_objectsid = ipaNTSecurityIdentifier" -msgstr "" +msgstr "ldap_group_objectsid = ipaNTSecurityIdentifier" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ipa_modified_defaults.xml:118 msgid "ldap_group_external_member = ipaExternalMember" -msgstr "" +msgstr "ldap_group_external_member = ipaExternalMember" #. type: Content of: <variablelist><varlistentry><term> #: include/krb5_options.xml:3 msgid "krb5_auth_timeout (integer)" -msgstr "" +msgstr "krb5_auth_timeout (integer)" #. type: Content of: <variablelist><varlistentry><listitem><para> #: include/krb5_options.xml:6 @@ -18423,12 +21194,12 @@ msgid "" "Timeout in seconds after an online authentication request or change password " "request is aborted. If possible, the authentication request is continued " "offline." -msgstr "" +msgstr "線上驗證要求或變更密碼要求中止之前的逾時(秒)。若可能,驗證要求會離線繼續。" #. type: Content of: <variablelist><varlistentry><term> #: include/krb5_options.xml:17 msgid "krb5_validate (boolean)" -msgstr "" +msgstr "krb5_validate (boolean)" #. type: Content of: <variablelist><varlistentry><listitem><para> #: include/krb5_options.xml:20 @@ -18440,11 +21211,15 @@ msgid "" "environments using cross-realm trust by placing the appropriate keytab entry " "as the last entry or the only entry in the keytab file." msgstr "" +"在 krb5_keytab 的協助下驗證取得的 TGT 沒有被偽造。keytab 會依序檢查項目,第一" +"個具有相符 realm 的項目用於驗證。若沒有項目符合 realm,會使用 keytab 中的最後" +"一個項目。此程序可以透過將適當的 keytab 項目放在 keytab 檔案的最後一個項目或" +"唯一項目,用於驗證使用跨 realm 信任的環境。" #. type: Content of: <variablelist><varlistentry><listitem><para> #: include/krb5_options.xml:29 msgid "Default: false (IPA and AD provider: true)" -msgstr "" +msgstr "預設:false(IPA 與 AD 提供者:true)" #. type: Content of: <variablelist><varlistentry><listitem><para> #: include/krb5_options.xml:32 @@ -18455,47 +21230,50 @@ msgid "" "</citerefentry> manual page for details). If ticket validation is disabled " "the PAC checks will be skipped as well." msgstr "" +"請注意,票證驗證是檢查 PAC 時的第一步(詳細資料請參閱 <citerefentry> " +"<refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</manvolnum> </" +"citerefentry> 手冊頁中的 'pac_check')。若停用票證驗證,PAC 檢查也會被略過。" #. type: Content of: <variablelist><varlistentry><term> #: include/krb5_options.xml:44 msgid "krb5_renewable_lifetime (string)" -msgstr "" +msgstr "krb5_renewable_lifetime (string)" #. type: Content of: <variablelist><varlistentry><listitem><para> #: include/krb5_options.xml:47 msgid "" "Request a renewable ticket with a total lifetime, given as an integer " "immediately followed by a time unit:" -msgstr "" +msgstr "要求總生命週期的可續約票證,以整數緊接著時間單位給出:" #. type: Content of: <variablelist><varlistentry><listitem><para> #: include/krb5_options.xml:52 include/krb5_options.xml:86 #: include/krb5_options.xml:123 msgid "<emphasis>s</emphasis> for seconds" -msgstr "" +msgstr "<emphasis>s</emphasis>:秒" #. type: Content of: <variablelist><varlistentry><listitem><para> #: include/krb5_options.xml:55 include/krb5_options.xml:89 #: include/krb5_options.xml:126 msgid "<emphasis>m</emphasis> for minutes" -msgstr "" +msgstr "<emphasis>m</emphasis>:分鐘" #. type: Content of: <variablelist><varlistentry><listitem><para> #: include/krb5_options.xml:58 include/krb5_options.xml:92 #: include/krb5_options.xml:129 msgid "<emphasis>h</emphasis> for hours" -msgstr "" +msgstr "<emphasis>h</emphasis>:小時" #. type: Content of: <variablelist><varlistentry><listitem><para> #: include/krb5_options.xml:61 include/krb5_options.xml:95 #: include/krb5_options.xml:132 msgid "<emphasis>d</emphasis> for days." -msgstr "" +msgstr "<emphasis>d</emphasis>:天。" #. type: Content of: <variablelist><varlistentry><listitem><para> #: include/krb5_options.xml:64 include/krb5_options.xml:135 msgid "If there is no unit given, <emphasis>s</emphasis> is assumed." -msgstr "" +msgstr "若沒有給定單位,假設為 <emphasis>s</emphasis>。" #. type: Content of: <variablelist><varlistentry><listitem><para> #: include/krb5_options.xml:68 include/krb5_options.xml:139 @@ -18503,45 +21281,47 @@ msgid "" "NOTE: It is not possible to mix units. To set the renewable lifetime to one " "and a half hours, use '90m' instead of '1h30m'." msgstr "" +"注意:無法混合單位。要將可續約生命週期設為一個半小時,請使用 '90m' 而不是 " +"'1h30m'。" #. type: Content of: <variablelist><varlistentry><listitem><para> #: include/krb5_options.xml:73 msgid "Default: not set, i.e. the TGT is not renewable" -msgstr "" +msgstr "預設:未設定,也就是 TGT 不可續約" #. type: Content of: <variablelist><varlistentry><term> #: include/krb5_options.xml:79 msgid "krb5_lifetime (string)" -msgstr "" +msgstr "krb5_lifetime (string)" #. type: Content of: <variablelist><varlistentry><listitem><para> #: include/krb5_options.xml:82 msgid "" "Request ticket with a lifetime, given as an integer immediately followed by " "a time unit:" -msgstr "" +msgstr "要求具有生命週期的票證,以整數緊接著時間單位給出:" #. type: Content of: <variablelist><varlistentry><listitem><para> #: include/krb5_options.xml:98 msgid "If there is no unit given <emphasis>s</emphasis> is assumed." -msgstr "" +msgstr "若沒有給定單位,假設為 <emphasis>s</emphasis>。" #. type: Content of: <variablelist><varlistentry><listitem><para> #: include/krb5_options.xml:102 msgid "" "NOTE: It is not possible to mix units. To set the lifetime to one and a " "half hours please use '90m' instead of '1h30m'." -msgstr "" +msgstr "注意:無法混合單位。要將生命週期設為一個半小時,請使用 '90m' 而不是 '1h30m'。" #. type: Content of: <variablelist><varlistentry><listitem><para> #: include/krb5_options.xml:107 msgid "Default: not set, i.e. the default ticket lifetime configured on the KDC." -msgstr "" +msgstr "預設:未設定,也就是 KDC 上設定的預設票證生命週期。" #. type: Content of: <variablelist><varlistentry><term> #: include/krb5_options.xml:114 msgid "krb5_renew_interval (string)" -msgstr "" +msgstr "krb5_renew_interval (string)" #. type: Content of: <variablelist><varlistentry><listitem><para> #: include/krb5_options.xml:117 @@ -18550,11 +21330,13 @@ msgid "" "are renewed if about half of their lifetime is exceeded, given as an integer " "immediately followed by a time unit:" msgstr "" +"兩次檢查 TGT 是否應續約之間的時間(秒)。當 TGT 生命週期約過半時會續約,以整" +"數緊接著時間單位給出:" #. type: Content of: <variablelist><varlistentry><listitem><para> #: include/krb5_options.xml:144 msgid "If this option is not set or is 0 the automatic renewal is disabled." -msgstr "" +msgstr "若未設定此選項或為 0,自動續約會停用。" #. type: Content of: <variablelist><varlistentry><listitem><para> #: include/krb5_options.xml:157 @@ -18562,3 +21344,5 @@ msgid "" "Specifies if the host and user principal should be canonicalized. This " "feature is available with MIT Kerberos 1.7 and later versions." msgstr "" +"指定是否應正規化主機與使用者 principal。此功能在 MIT Kerberos 1.7 及更新版本" +"中可用。" diff --git a/version.m4 b/version.m4 index e05ce25ab50..2f0927ba279 100644 --- a/version.m4 +++ b/version.m4 @@ -1,5 +1,5 @@ # Primary version number -m4_define([VERSION_NUMBER], [2.14.0]) +m4_define([VERSION_NUMBER], [2-14-beta1]) # If the PRERELEASE_VERSION_NUMBER is set, we'll append # it to the release tag when creating an RPM or SRPM